Skip to content

PKCS7: only wait for an 00 00 ending on indefinite EncryptedContentInfo - #11616

Merged
dgarske merged 1 commit into
wolfSSL:masterfrom
padelsbach:pkcs7-shorttag-ccm
Sep 30, 2026
Merged

dgarske merged 1 commit into
wolfSSL:masterfrom
padelsbach:pkcs7-shorttag-ccm

Conversation

@padelsbach

Copy link
Copy Markdown
Contributor

Description

This fixes a CI failure on master following merge of #11490 and #11554.

ERROR - tests/api/test_pkcs7.c line 4668 failed with:
    expected: pkcs7_decodeShortTag(enveloped, encSz) == (ASN_PARSE_E)
    result:   -270 != -140

Change is to use the indefEci flag to decide whether to look for the two trailing bytes.

Testing

CI

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

Copilot AI balanced review requested due to automatic review settings September 30, 2026 22:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused change correctly distinguishes definite and indefinite encodings and addresses the existing regression test.

Review effort: Balanced
Findings: None

What changed in this PR

Fixes PKCS#7 streaming decode of definite-length EncryptedContentInfo by avoiding an erroneous wait for an end-of-contents marker.

Changes:

  • Adds EOC lookahead only when indefEci is set.
  • Restores expected short-tag validation behavior.
File Description
wolfcrypt/​src/​pkcs7.c Makes stream buffering conditional on indefinite-length encoding.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@dgarske

dgarske commented Sep 30, 2026

Copy link
Copy Markdown
Member

Merging early to unblock CI

@dgarske
dgarske merged commit 03044f7 into wolfSSL:master Sep 30, 2026
420 of 421 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants