Commit 851a95ccfb for openssl.org
commit 851a95ccfbcaf17eb84b4d63f107c76ec55c513b
Author: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Date: Wed Jul 22 00:11:29 2026 +0200
apps: test skeyutl -skeyopt handling
Cover the -skeyopt option of skeyutl using the fake cipher provider: a
key name passed as a key option shows up in the reported key id, while
an option unknown to the key management and an option missing the
opt:value separator both make the command fail.
Assisted-by: Claude:claude-opus-4-8
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
MergeDate: Mon Jul 27 09:06:06 2026
(Merged from https://github.com/openssl/openssl/pull/32036)
diff --git a/test/recipes/20-test_skeyutl.t b/test/recipes/20-test_skeyutl.t
index 1c69935cac..f37be39d89 100644
--- a/test/recipes/20-test_skeyutl.t
+++ b/test/recipes/20-test_skeyutl.t
@@ -18,7 +18,7 @@ setup("test_skeyutl");
# when module support is enabled.
my $fake_cipher = !disabled('module');
-plan tests => 14 + ($fake_cipher ? 2 : 0);
+plan tests => 14 + ($fake_cipher ? 8 : 0);
# Helper: run skeyutl expecting a non-zero (failure) exit code, and optionally
# check that stderr matches a regular expression.
@@ -96,4 +96,29 @@ if ($fake_cipher) {
ok($status, "skeyutl -genkey with fake-cipher provider succeeds");
ok(grep(/opaque key/, @out),
"skeyutl -genkey reports the generated opaque key");
+
+ # -skeyopt values are passed to the key generation. The fake-cipher
+ # provider names the generated key after its key_name parameter, so the
+ # option shows up in the reported key id.
+ my $rawopt = 'hexraw-bytes:00112233445566778899aabbccddeeff';
+ @out = run(app(['openssl', 'skeyutl', @prov, '-genkey',
+ '-skeymgmt', 'fake_cipher',
+ '-skeyopt', 'key_name:testkey',
+ '-skeyopt', $rawopt]),
+ capture => 1, statusvar => \$status);
+ ok($status, "skeyutl -genkey with -skeyopt succeeds");
+ ok(grep(/opaque key identified by testkey/, @out),
+ "skeyutl -genkey applies the -skeyopt key name");
+
+ # An option not settable by the key management is rejected
+ skeyutl_fails("skeyutl -genkey with an unknown -skeyopt fails",
+ qr/Parameter unknown 'nosuchopt:1'/,
+ @prov, '-genkey', '-skeymgmt', 'fake_cipher',
+ '-skeyopt', 'nosuchopt:1');
+
+ # A -skeyopt without the opt:value separator is rejected
+ skeyutl_fails("skeyutl -genkey with a malformed -skeyopt fails",
+ qr/Parameter error 'key_name'/,
+ @prov, '-genkey', '-skeymgmt', 'fake_cipher',
+ '-skeyopt', 'key_name');
}