Commit ae6309aede for openssl.org

commit ae6309aede393e2891036c5da50baa55e2c5e5a5
Author: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Date:   Tue Jul 14 19:20:43 2026 +0200

    apps: test pkcs8 -nocrypt reading a PKCS#8 PEM

    Reading an unencrypted PKCS#8 (PrivateKeyInfo) in PEM form with -nocrypt
    was not exercised by any test; the existing round-trip test only read the
    DER form via -inform DER, hitting d2i_PKCS8_PRIV_KEY_INFO_bio(). The PEM
    branch in apps/pkcs8.c (the informat == FORMAT_PEM || FORMAT_UNDEF case
    calling PEM_read_bio_PKCS8_PRIV_KEY_INFO()) was left uncovered.

    Add a subtest that writes an unencrypted PKCS#8 PEM and reads it back
    with -nocrypt from PEM, exercising PEM_read_bio_PKCS8_PRIV_KEY_INFO(),
    and checks the recovered key matches the original.

    Assisted-by: Claude:claude-opus-4-8

    Reviewed-by: Paul Dale <paul.dale@oracle.com>
    Reviewed-by: Andrew Dinh <andrewd@openssl.org>
    Reviewed-by: Matt Caswell <matt@openssl.foundation>
    MergeDate: Mon Jul 27 09:10:45 2026
    (Merged from https://github.com/openssl/openssl/pull/31955)

diff --git a/test/recipes/25-test_pkcs8.t b/test/recipes/25-test_pkcs8.t
index bd7224459b..cc49d096d8 100644
--- a/test/recipes/25-test_pkcs8.t
+++ b/test/recipes/25-test_pkcs8.t
@@ -16,7 +16,7 @@ use OpenSSL::Test qw/:DEFAULT srctop_file ok_nofips is_nofips/;

 setup("test_pkcs8");

-plan tests => 19;
+plan tests => 20;

 my $pc5_key = srctop_file('test', 'certs', 'pc5-key.pem');

@@ -160,6 +160,23 @@ subtest 'PKCS#8 DER inform/outform round trip' => sub {
        "read encrypted PKCS#8 from DER form");
 };

+subtest 'PKCS#8 -nocrypt reads an unencrypted PKCS#8 PEM' => sub {
+    plan tests => 3;
+
+    # Write an unencrypted PKCS#8 (PrivateKeyInfo) in PEM form.
+    my $p8_pem = 'p8-nocrypt-pem.pem';
+    ok(run(app(['openssl', 'pkcs8', '-topk8', '-nocrypt',
+                '-in', $pc5_key, '-out', $p8_pem])),
+       "write unencrypted PKCS#8 in PEM form");
+    # Read it back with -nocrypt from PEM (the default input format).
+    my $recovered = 'p8-nocrypt-pem-read.pem';
+    ok(run(app(['openssl', 'pkcs8', '-nocrypt',
+                '-in', $p8_pem, '-out', $recovered])),
+       "read unencrypted PKCS#8 from PEM form");
+    is(compare_text($pc5_key, $recovered), 0,
+       "recovered key matches the original");
+};
+
 SKIP: {
     skip "SM2, SM3 or SM4 is not supported by this OpenSSL build", 3
         if disabled("sm2") || disabled("sm3") || disabled("sm4");