Conversation
Follow-up to PR MHumm#102 (points 1, 3, 5, 6). Reading CalculatedAuthenticationTag before Done now raises EDECCipherException. Protected EncodeGCM/EncodeCCM are unified as EncodeAuthenticated (Decode counterpart too). CCM materializes the authentication tag in Done so GCM and CCM share one lifecycle. Modes without prescribed tag lengths document returning an empty array. Co-authored-by: Olaf Monien <omonien@users.noreply.github.com>
Owner
Author
|
Opened upstream as MHumm#105 — closing this fork listing as duplicate. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #102, split as requested (“Gerne in 2 PR”).
Companion PR: CCM multi-chunk / spec (points 2 and 4).
Please merge this PR against
MHumm/DelphiEncryptionCompendium:developmentasomonien:cursor/feat-aead-lifecycle-api-2915. This listing is on the fork because the agent token cannot open PRs onMHumm.This PR covers Markus’s lifecycle/API points from MHumm#102:
CalculatedAuthenticationTag/CalculatedAuthenticationResultbeforeDonemust raise a clear exception (hard check, notAssert)TAuthenticatedCipherModesBasegetter raisesEDECCipherExceptionuntilDoneEncodeGCM/EncodeCCMtowardEncodeAuthenticatedEncodeAuthenticated/DecodeAuthenticated; all call sites updated (including empty-buffer GCM/CCM inDECCipherFormats). Public API unchangedDonelike GCMT XOR S_0) is materialized inTCCM.DoneGetStandardAuthenticationTagBitLengths: no prescribed lengths → empty array, documented in XMLDOC[]; XMLDOC now states that. Non-authenticated modes onTDECCipherModesstill return[0](existing public contract)Lifecycle (now shared by GCM and CCM)
Doneraises (educates callers).Doneis idempotent.Doneraises untilInit.Tests
TestCalculatedAuthenticationResultBeforeDoneRaisesTestEncodeAfterDoneRejected,TestDoneIdempotentDonebefore reading the tagOut of scope
InitMode128-bit spec discussion (PR 11)