Commit 475c8031e2 for openssl.org

commit 475c8031e2c16aa825edb4e1f638e18405e7f826
Author: Billy Brumley <bbb@iki.fi>
Date:   Tue Sep 15 01:10:33 2026 -0400

    Report the default tag length for ChaCha20-Poly1305

    Querying OSSL_CIPHER_PARAM_AEAD_TAGLEN before a tag has been set
    returned zero, which is reserved for ciphers without a tag. Report the
    Poly1305 default instead, matching the other AEAD ciphers and the
    EVP_CIPHER_CTX_get_tag_length() documentation.

    Assisted-by: Claude:claude-fable-5-1
    Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
    Reviewed-by: Neil Horman <nhorman@openssl.org>
    Merge-date: Thu Oct  1 14:56:43 2026
    Merged-from: https://github.com/openssl/openssl/pull/32833

diff --git a/providers/implementations/ciphers/cipher_chacha20_poly1305.c b/providers/implementations/ciphers/cipher_chacha20_poly1305.c
index 45032d86ad..c8d4bd84a1 100644
--- a/providers/implementations/ciphers/cipher_chacha20_poly1305.c
+++ b/providers/implementations/ciphers/cipher_chacha20_poly1305.c
@@ -114,8 +114,10 @@ static int chacha20_poly1305_get_ctx_params(void *vctx, OSSL_PARAM params[])
         return 0;
     }

+    /* tag_len == 0 means no tag set yet, report the default */
     if (p.taglen != NULL
-        && !OSSL_PARAM_set_size_t(p.taglen, ctx->tag_len)) {
+        && !OSSL_PARAM_set_size_t(p.taglen,
+            ctx->tag_len == 0 ? POLY1305_BLOCK_SIZE : ctx->tag_len)) {
         ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_SET_PARAMETER);
         return 0;
     }