From f9d37d626c858f5772fea73e4124ab4fe2899858 Mon Sep 17 00:00:00 2001 From: Diggory Hardy Date: Wed, 3 Sep 2025 09:27:06 +0100 Subject: [PATCH 1/6] StdRng: test state after construction --- src/rngs/std.rs | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/src/rngs/std.rs b/src/rngs/std.rs index 6e1658e7453..2e5a3f0efc0 100644 --- a/src/rngs/std.rs +++ b/src/rngs/std.rs @@ -103,6 +103,24 @@ mod test { use crate::rngs::StdRng; use crate::{RngCore, SeedableRng}; + // Get ChaCha state, omitting the constants + fn rng_state(rng: &StdRng) -> &[u32; 12] { + use core::mem::{size_of, transmute}; + + // Experimentally this matches the size and layout of rand_core::ChaCha12Rng + struct State { + _results: [u32; 64], + _index: usize, + #[cfg(target_pointer_width = "64")] + _pad: usize, + state: [u32; 12], + } + assert_eq!(size_of::(), size_of::()); + + let state: &State = unsafe { transmute(rng) }; + &state.state + } + #[test] fn test_stdrng_construction() { // Test value-stability of StdRng. This is expected to break any time @@ -114,11 +132,21 @@ mod test { let target = [10719222850664546238, 14064965282130556830]; let mut rng0 = StdRng::from_seed(seed); + + let expected = [1, 23, 456, 7890, 0, 0, 0, 0, 0, 0, 0, 0]; + assert_eq!(rng_state(&rng0), &expected); + let x0 = rng0.next_u64(); let mut rng1 = StdRng::from_rng(&mut rng0); let x1 = rng1.next_u64(); + let expected = [ + 0x98c064cf, 0x42da2de, 0xb7949e00, 0xf46bfbdb, 0x7e3b786e, 0xaaddd44f, 0xf7a37c04, + 0x8255c7e9, 4, 0, 0, 0, + ]; + assert_eq!(rng_state(&rng1), &expected); + assert_eq!([x0, x1], target); } } From 37d5ad2829e1f7dc2f2fa68d1ee6e77c71176e21 Mon Sep 17 00:00:00 2001 From: Helge Penne Date: Sat, 14 Jun 2025 19:52:30 +0200 Subject: [PATCH 2/6] Added test vectors for StdRng (Strombergson 2013) --- src/rngs/std.rs | 199 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 199 insertions(+) diff --git a/src/rngs/std.rs b/src/rngs/std.rs index 2e5a3f0efc0..64020e2e586 100644 --- a/src/rngs/std.rs +++ b/src/rngs/std.rs @@ -149,4 +149,203 @@ mod test { assert_eq!([x0, x1], target); } + + #[test] + fn test_chacha_true_values_1() { + // Source: Test Vectors for the Stream Cipher ChaCha + // draft-strombergson-chacha-test-vectors-01 + // https://datatracker.ietf.org/doc/html/draft-strombergson-chacha-test-vectors-01 + // TC: all zero key and IV, rounds 12, 256-bit key + + let seed = [0u8; 32]; + let mut rng = StdRng::from_seed(seed); + + assert_eq!(rng_state(&rng), &[0u32; 12]); + + let mut results = [0u8; 64]; + rng.fill_bytes(&mut results); + #[rustfmt::skip] + let expected = [ + 0x9b, 0xf4, 0x9a, 0x6a, 0x07, 0x55, 0xf9, 0x53, + 0x81, 0x1f, 0xce, 0x12, 0x5f, 0x26, 0x83, 0xd5, + 0x04, 0x29, 0xc3, 0xbb, 0x49, 0xe0, 0x74, 0x14, + 0x7e, 0x00, 0x89, 0xa5, 0x2e, 0xae, 0x15, 0x5f, + 0x05, 0x64, 0xf8, 0x79, 0xd2, 0x7a, 0xe3, 0xc0, + 0x2c, 0xe8, 0x28, 0x34, 0xac, 0xfa, 0x8c, 0x79, + 0x3a, 0x62, 0x9f, 0x2c, 0xa0, 0xde, 0x69, 0x19, + 0x61, 0x0b, 0xe8, 0x2f, 0x41, 0x13, 0x26, 0xbe, + ]; + assert_eq!(results, expected); + + rng.fill_bytes(&mut results); + #[rustfmt::skip] + let expected = [ + 0x0b, 0xd5, 0x88, 0x41, 0x20, 0x3e, 0x74, 0xfe, + 0x86, 0xfc, 0x71, 0x33, 0x8c, 0xe0, 0x17, 0x3d, + 0xc6, 0x28, 0xeb, 0xb7, 0x19, 0xbd, 0xcb, 0xcc, + 0x15, 0x15, 0x85, 0x21, 0x4c, 0xc0, 0x89, 0xb4, + 0x42, 0x25, 0x8d, 0xcd, 0xa1, 0x4c, 0xf1, 0x11, + 0xc6, 0x02, 0xb8, 0x97, 0x1b, 0x8c, 0xc8, 0x43, + 0xe9, 0x1e, 0x46, 0xca, 0x90, 0x51, 0x51, 0xc0, + 0x27, 0x44, 0xa6, 0xb0, 0x17, 0xe6, 0x93, 0x16, + ]; + assert_eq!(results, expected); + + assert_eq!(rng.0.get_word_pos(), 32); + } + + #[test] + fn test_chacha_true_values_2() { + // Source: Test Vectors for the Stream Cipher ChaCha + // draft-strombergson-chacha-test-vectors-01 + // https://datatracker.ietf.org/doc/html/draft-strombergson-chacha-test-vectors-01 + // TC2: single bit set in key, all zero IV, rounds 12, 256-bit key + + let mut seed = [0u8; 32]; + seed[0] = 1; + let mut rng = StdRng::from_seed(seed); + + let mut expected = [0u32; 12]; + expected[0] = 1; + assert_eq!(rng_state(&rng), &expected); + + let mut results = [0u8; 64]; + rng.fill_bytes(&mut results); + #[rustfmt::skip] + let expected = [ + 0x12, 0x05, 0x6e, 0x59, 0x5d, 0x56, 0xb0, 0xf6, + 0xee, 0xf0, 0x90, 0xf0, 0xcd, 0x25, 0xa2, 0x09, + 0x49, 0x24, 0x8c, 0x27, 0x90, 0x52, 0x5d, 0x0f, + 0x93, 0x02, 0x18, 0xff, 0x0b, 0x4d, 0xdd, 0x10, + 0xa6, 0x00, 0x22, 0x39, 0xd9, 0xa4, 0x54, 0xe2, + 0x9e, 0x10, 0x7a, 0x7d, 0x06, 0xfe, 0xfd, 0xfe, + 0xf0, 0x21, 0x0f, 0xeb, 0xa0, 0x44, 0xf9, 0xf2, + 0x9b, 0x17, 0x72, 0xc9, 0x60, 0xdc, 0x29, 0xc0, + ]; + assert_eq!(results, expected); + + rng.fill_bytes(&mut results); + #[rustfmt::skip] + let expected = [ + 0x0c, 0x73, 0x66, 0xc5, 0xcb, 0xc6, 0x04, 0x24, + 0x0e, 0x66, 0x5e, 0xb0, 0x2a, 0x69, 0x37, 0x2a, + 0x7a, 0xf9, 0x79, 0xb2, 0x6f, 0xbb, 0x78, 0x09, + 0x2a, 0xc7, 0xc4, 0xb8, 0x80, 0x29, 0xa7, 0xc8, + 0x54, 0x51, 0x3b, 0xc2, 0x17, 0xbb, 0xfc, 0x7d, + 0x90, 0x43, 0x2e, 0x30, 0x8e, 0xba, 0x15, 0xaf, + 0xc6, 0x5a, 0xeb, 0x48, 0xef, 0x10, 0x0d, 0x56, + 0x01, 0xe6, 0xaf, 0xba, 0x25, 0x71, 0x17, 0xa9, + ]; + assert_eq!(results, expected); + + assert_eq!(rng.0.get_word_pos(), 32); + } + + #[test] + fn test_chacha_true_values_3() { + // Source: Test Vectors for the Stream Cipher ChaCha + // draft-strombergson-chacha-test-vectors-01 + // https://datatracker.ietf.org/doc/html/draft-strombergson-chacha-test-vectors-01 + // TC3: all zero key, single bit set in IV, rounds 12, 256-bit key + + let seed = [0u8; 32]; + let mut rng = StdRng::from_seed(seed); + rng.0.set_stream(1); + + let mut expected = [0u32; 12]; + expected[10] = 1; + assert_eq!(rng_state(&rng), &expected); + + let mut results = [0u8; 64]; + rng.fill_bytes(&mut results); + #[rustfmt::skip] + let expected = [ + 0x64, 0xb8, 0xbd, 0xf8, 0x7b, 0x82, 0x8c, 0x4b, + 0x6d, 0xba, 0xf7, 0xef, 0x69, 0x8d, 0xe0, 0x3d, + 0xf8, 0xb3, 0x3f, 0x63, 0x57, 0x14, 0x41, 0x8f, + 0x98, 0x36, 0xad, 0xe5, 0x9b, 0xe1, 0x29, 0x69, + 0x46, 0xc9, 0x53, 0xa0, 0xf3, 0x8e, 0xcf, 0xfc, + 0x9e, 0xcb, 0x98, 0xe8, 0x1d, 0x5d, 0x99, 0xa5, + 0xed, 0xfc, 0x8f, 0x9a, 0x0a, 0x45, 0xb9, 0xe4, + 0x1e, 0xf3, 0xb3, 0x1f, 0x02, 0x8f, 0x1d, 0x0f, + ]; + assert_eq!(results, expected); + + rng.fill_bytes(&mut results); + #[rustfmt::skip] + let expected = [ + 0x55, 0x9d, 0xb4, 0xa7, 0xf2, 0x22, 0xc4, 0x42, + 0xfe, 0x23, 0xb9, 0xa2, 0x59, 0x6a, 0x88, 0x28, + 0x51, 0x22, 0xee, 0x4f, 0x13, 0x63, 0x89, 0x6e, + 0xa7, 0x7c, 0xa1, 0x50, 0x91, 0x2a, 0xc7, 0x23, + 0xbf, 0xf0, 0x4b, 0x02, 0x6a, 0x2f, 0x80, 0x7e, + 0x03, 0xb2, 0x9c, 0x02, 0x07, 0x7d, 0x7b, 0x06, + 0xfc, 0x1a, 0xb9, 0x82, 0x7c, 0x13, 0xc8, 0x01, + 0x3a, 0x6d, 0x83, 0xbd, 0x3b, 0x52, 0xa2, 0x6f, + ]; + assert_eq!(results, expected); + + assert_eq!(rng.0.get_word_pos(), 32); + } + + #[test] + fn test_chacha_true_values_8() { + // Source: Test Vectors for the Stream Cipher ChaCha + // draft-strombergson-chacha-test-vectors-01 + // https://datatracker.ietf.org/doc/html/draft-strombergson-chacha-test-vectors-01 + // TC8: key: 'All your base are belong to us!', IV: IETF2013, rounds 12, 256-bit key + + #[rustfmt::skip] + let seed = [ + 0xc4, 0x6e, 0xc1, 0xb1, 0x8c, 0xe8, 0xa8, 0x78, + 0x72, 0x5a, 0x37, 0xe7, 0x80, 0xdf, 0xb7, 0x35, + 0x1f, 0x68, 0xed, 0x2e, 0x19, 0x4c, 0x79, 0xfb, + 0xc6, 0xae, 0xbe, 0xe1, 0xa6, 0x67, 0x97, 0x5d, + ]; + let iv = [0x1a, 0xda, 0x31, 0xd5, 0xcf, 0x68, 0x82, 0x21]; + let mut rng = StdRng::from_seed(seed); + rng.0.set_stream(u64::from_le_bytes(iv)); + + #[rustfmt::skip] + let expected = [ + 0xb1c16ec4, 0x78a8e88c, + 0xe7375a72, 0x35b7df80, + 0x2eed681f, 0xfb794c19, + 0xe1beaec6, 0x5d9767a6, + 0x00000000, 0x00000000, + 0xd531da1a, 0x218268cf, + ]; + assert_eq!(rng_state(&rng), &expected); + + let mut results = [0u8; 64]; + rng.fill_bytes(&mut results); + #[rustfmt::skip] + let expected = [ + 0x14, 0x82, 0x07, 0x27, 0x84, 0xbc, 0x6d, 0x06, + 0xb4, 0xe7, 0x3b, 0xdc, 0x11, 0x8b, 0xc0, 0x10, + 0x3c, 0x79, 0x76, 0x78, 0x6c, 0xa9, 0x18, 0xe0, + 0x69, 0x86, 0xaa, 0x25, 0x1f, 0x7e, 0x9c, 0xc1, + 0xb2, 0x74, 0x9a, 0x0a, 0x16, 0xee, 0x83, 0xb4, + 0x24, 0x2d, 0x2e, 0x99, 0xb0, 0x8d, 0x7c, 0x20, + 0x09, 0x2b, 0x80, 0xbc, 0x46, 0x6c, 0x87, 0x28, + 0x3b, 0x61, 0xb1, 0xb3, 0x9d, 0x0f, 0xfb, 0xab, + ]; + assert_eq!(results, expected); + + rng.fill_bytes(&mut results); + #[rustfmt::skip] + let expected = [ + 0xd9, 0x4b, 0x11, 0x6b, 0xc1, 0xeb, 0xdb, 0x32, + 0x9b, 0x9e, 0x4f, 0x62, 0x0d, 0xb6, 0x95, 0x54, + 0x4a, 0x8e, 0x3d, 0x9b, 0x68, 0x47, 0x3d, 0x0c, + 0x97, 0x5a, 0x46, 0xad, 0x96, 0x6e, 0xd6, 0x31, + 0xe4, 0x2a, 0xff, 0x53, 0x0a, 0xd5, 0xea, 0xc7, + 0xd8, 0x04, 0x7a, 0xdf, 0xa1, 0xe5, 0x11, 0x3c, + 0x91, 0xf3, 0xe3, 0xb8, 0x83, 0xf1, 0xd1, 0x89, + 0xac, 0x1c, 0x8f, 0xe0, 0x7b, 0xa5, 0xa4, 0x2b, + ]; + assert_eq!(results, expected); + + assert_eq!(rng.0.get_word_pos(), 32); + } } From 75c06da1afe867db4a5090163387381c43c57694 Mon Sep 17 00:00:00 2001 From: Diggory Hardy Date: Wed, 3 Sep 2025 11:14:36 +0100 Subject: [PATCH 3/6] Add StdRng test setting the counter --- src/rngs/std.rs | 49 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 49 insertions(+) diff --git a/src/rngs/std.rs b/src/rngs/std.rs index 64020e2e586..ff2739e0056 100644 --- a/src/rngs/std.rs +++ b/src/rngs/std.rs @@ -348,4 +348,53 @@ mod test { assert_eq!(rng.0.get_word_pos(), 32); } + + #[test] + fn test_chacha_counter() { + // Source: none + // Test: all zero key and IV, block set to u32::MAX, rounds 12, 256-bit key + + let seed = [0u8; 32]; + let mut rng = StdRng::from_seed(seed); + let block = u32::MAX; + let words_per_block = 16; + rng.0.set_word_pos((block as u128) * words_per_block); + + let mut expected = [0u32; 12]; + // Note: four blocks get generated by set_word_pos + expected[8] = block.wrapping_add(4); + expected[9] = 1; + assert_eq!(rng_state(&rng), &expected); + + let mut results = [0u8; 64]; + rng.fill_bytes(&mut results); + #[rustfmt::skip] + let expected = [ + 0xd7, 0xa6, 0xaf, 0x50, 0xf1, 0xc9, 0x2a, 0x29, + 0x48, 0x42, 0x52, 0xbb, 0xfc, 0xe2, 0x06, 0xf1, + 0x7d, 0x01, 0xdd, 0x13, 0x95, 0x30, 0xa3, 0x83, + 0x0a, 0xb5, 0x83, 0xc1, 0xf6, 0x2e, 0x03, 0x12, + 0x82, 0x93, 0x61, 0xa1, 0x9a, 0x8a, 0x95, 0x6c, + 0xed, 0xea, 0x38, 0x04, 0x30, 0xff, 0x93, 0x2c, + 0xd0, 0x52, 0xdb, 0x5e, 0x94, 0x77, 0x83, 0x50, + 0x58, 0xb8, 0x0a, 0x27, 0x24, 0x06, 0xfc, 0x74, + ]; + assert_eq!(results, expected); + + rng.fill_bytes(&mut results); + #[rustfmt::skip] + let expected = [ + 0xcc, 0x7b, 0x53, 0xdc, 0x11, 0x89, 0x4d, 0x26, + 0x24, 0x05, 0x81, 0xb8, 0xa8, 0xf4, 0xf4, 0xe5, + 0xaf, 0x40, 0x67, 0x05, 0x80, 0x12, 0x23, 0xb1, + 0x3f, 0x82, 0x1f, 0xdc, 0xcb, 0xa6, 0xa6, 0x18, + 0x8a, 0x63, 0xf8, 0xd3, 0xdc, 0x83, 0xcc, 0xbc, + 0xed, 0x45, 0x1f, 0x4b, 0xa4, 0xe0, 0xda, 0xab, + 0x22, 0x8a, 0xbb, 0x0d, 0x74, 0x39, 0xcc, 0x67, + 0xe5, 0x0d, 0xf7, 0x12, 0x9f, 0x64, 0x6b, 0xad, + ]; + assert_eq!(results, expected); + + assert_eq!(rng.0.get_word_pos(), (block as u128) * words_per_block + 32); + } } From 0c53ff545bc205f2d6826fe565dc61af36736f45 Mon Sep 17 00:00:00 2001 From: Diggory Hardy Date: Wed, 3 Sep 2025 11:25:41 +0100 Subject: [PATCH 4/6] Remove rng_state test --- src/rngs/std.rs | 54 ------------------------------------------------- 1 file changed, 54 deletions(-) diff --git a/src/rngs/std.rs b/src/rngs/std.rs index ff2739e0056..a2c5aa3ee68 100644 --- a/src/rngs/std.rs +++ b/src/rngs/std.rs @@ -103,24 +103,6 @@ mod test { use crate::rngs::StdRng; use crate::{RngCore, SeedableRng}; - // Get ChaCha state, omitting the constants - fn rng_state(rng: &StdRng) -> &[u32; 12] { - use core::mem::{size_of, transmute}; - - // Experimentally this matches the size and layout of rand_core::ChaCha12Rng - struct State { - _results: [u32; 64], - _index: usize, - #[cfg(target_pointer_width = "64")] - _pad: usize, - state: [u32; 12], - } - assert_eq!(size_of::(), size_of::()); - - let state: &State = unsafe { transmute(rng) }; - &state.state - } - #[test] fn test_stdrng_construction() { // Test value-stability of StdRng. This is expected to break any time @@ -133,20 +115,11 @@ mod test { let mut rng0 = StdRng::from_seed(seed); - let expected = [1, 23, 456, 7890, 0, 0, 0, 0, 0, 0, 0, 0]; - assert_eq!(rng_state(&rng0), &expected); - let x0 = rng0.next_u64(); let mut rng1 = StdRng::from_rng(&mut rng0); let x1 = rng1.next_u64(); - let expected = [ - 0x98c064cf, 0x42da2de, 0xb7949e00, 0xf46bfbdb, 0x7e3b786e, 0xaaddd44f, 0xf7a37c04, - 0x8255c7e9, 4, 0, 0, 0, - ]; - assert_eq!(rng_state(&rng1), &expected); - assert_eq!([x0, x1], target); } @@ -160,8 +133,6 @@ mod test { let seed = [0u8; 32]; let mut rng = StdRng::from_seed(seed); - assert_eq!(rng_state(&rng), &[0u32; 12]); - let mut results = [0u8; 64]; rng.fill_bytes(&mut results); #[rustfmt::skip] @@ -205,10 +176,6 @@ mod test { seed[0] = 1; let mut rng = StdRng::from_seed(seed); - let mut expected = [0u32; 12]; - expected[0] = 1; - assert_eq!(rng_state(&rng), &expected); - let mut results = [0u8; 64]; rng.fill_bytes(&mut results); #[rustfmt::skip] @@ -252,10 +219,6 @@ mod test { let mut rng = StdRng::from_seed(seed); rng.0.set_stream(1); - let mut expected = [0u32; 12]; - expected[10] = 1; - assert_eq!(rng_state(&rng), &expected); - let mut results = [0u8; 64]; rng.fill_bytes(&mut results); #[rustfmt::skip] @@ -306,17 +269,6 @@ mod test { let mut rng = StdRng::from_seed(seed); rng.0.set_stream(u64::from_le_bytes(iv)); - #[rustfmt::skip] - let expected = [ - 0xb1c16ec4, 0x78a8e88c, - 0xe7375a72, 0x35b7df80, - 0x2eed681f, 0xfb794c19, - 0xe1beaec6, 0x5d9767a6, - 0x00000000, 0x00000000, - 0xd531da1a, 0x218268cf, - ]; - assert_eq!(rng_state(&rng), &expected); - let mut results = [0u8; 64]; rng.fill_bytes(&mut results); #[rustfmt::skip] @@ -360,12 +312,6 @@ mod test { let words_per_block = 16; rng.0.set_word_pos((block as u128) * words_per_block); - let mut expected = [0u32; 12]; - // Note: four blocks get generated by set_word_pos - expected[8] = block.wrapping_add(4); - expected[9] = 1; - assert_eq!(rng_state(&rng), &expected); - let mut results = [0u8; 64]; rng.fill_bytes(&mut results); #[rustfmt::skip] From 2f688d409c6b1c8dabf21c2961d06fabcb590dcf Mon Sep 17 00:00:00 2001 From: Diggory Hardy Date: Thu, 4 Sep 2025 09:03:06 +0100 Subject: [PATCH 5/6] Convert test vectors to u128 arrays --- src/rngs/std.rs | 194 ++++++++++++++---------------------------------- 1 file changed, 57 insertions(+), 137 deletions(-) diff --git a/src/rngs/std.rs b/src/rngs/std.rs index a2c5aa3ee68..59933150a14 100644 --- a/src/rngs/std.rs +++ b/src/rngs/std.rs @@ -101,7 +101,7 @@ impl CryptoRng for StdRng {} #[cfg(test)] mod test { use crate::rngs::StdRng; - use crate::{RngCore, SeedableRng}; + use crate::{Rng, RngCore, SeedableRng}; #[test] fn test_stdrng_construction() { @@ -125,40 +125,26 @@ mod test { #[test] fn test_chacha_true_values_1() { - // Source: Test Vectors for the Stream Cipher ChaCha + // Source: Strombergson 2013, Test Vectors for the Stream Cipher ChaCha // draft-strombergson-chacha-test-vectors-01 // https://datatracker.ietf.org/doc/html/draft-strombergson-chacha-test-vectors-01 + // Converted to LE u128 form (four u128 to one block). // TC: all zero key and IV, rounds 12, 256-bit key let seed = [0u8; 32]; let mut rng = StdRng::from_seed(seed); - let mut results = [0u8; 64]; - rng.fill_bytes(&mut results); - #[rustfmt::skip] + let mut results = [0u128; 8]; + rng.fill(&mut results); let expected = [ - 0x9b, 0xf4, 0x9a, 0x6a, 0x07, 0x55, 0xf9, 0x53, - 0x81, 0x1f, 0xce, 0x12, 0x5f, 0x26, 0x83, 0xd5, - 0x04, 0x29, 0xc3, 0xbb, 0x49, 0xe0, 0x74, 0x14, - 0x7e, 0x00, 0x89, 0xa5, 0x2e, 0xae, 0x15, 0x5f, - 0x05, 0x64, 0xf8, 0x79, 0xd2, 0x7a, 0xe3, 0xc0, - 0x2c, 0xe8, 0x28, 0x34, 0xac, 0xfa, 0x8c, 0x79, - 0x3a, 0x62, 0x9f, 0x2c, 0xa0, 0xde, 0x69, 0x19, - 0x61, 0x0b, 0xe8, 0x2f, 0x41, 0x13, 0x26, 0xbe, - ]; - assert_eq!(results, expected); - - rng.fill_bytes(&mut results); - #[rustfmt::skip] - let expected = [ - 0x0b, 0xd5, 0x88, 0x41, 0x20, 0x3e, 0x74, 0xfe, - 0x86, 0xfc, 0x71, 0x33, 0x8c, 0xe0, 0x17, 0x3d, - 0xc6, 0x28, 0xeb, 0xb7, 0x19, 0xbd, 0xcb, 0xcc, - 0x15, 0x15, 0x85, 0x21, 0x4c, 0xc0, 0x89, 0xb4, - 0x42, 0x25, 0x8d, 0xcd, 0xa1, 0x4c, 0xf1, 0x11, - 0xc6, 0x02, 0xb8, 0x97, 0x1b, 0x8c, 0xc8, 0x43, - 0xe9, 0x1e, 0x46, 0xca, 0x90, 0x51, 0x51, 0xc0, - 0x27, 0x44, 0xa6, 0xb0, 0x17, 0xe6, 0x93, 0x16, + 0xd583265f12ce1f8153f955076a9af49b, + 0x5f15ae2ea589007e1474e049bbc32904, + 0x798cfaac3428e82cc0e37ad279f86405, + 0xbe2613412fe80b611969dea02c9f623a, + 0x3d17e08c3371fc86fe743e204188d50b, + 0xb489c04c21851515cccbbd19b7eb28c6, + 0x43c88c1b97b802c611f14ca1cd8d2542, + 0x1693e617b0a64427c0515190ca461ee9, ]; assert_eq!(results, expected); @@ -167,41 +153,24 @@ mod test { #[test] fn test_chacha_true_values_2() { - // Source: Test Vectors for the Stream Cipher ChaCha - // draft-strombergson-chacha-test-vectors-01 - // https://datatracker.ietf.org/doc/html/draft-strombergson-chacha-test-vectors-01 + // Source: Strombergson 2013, Test Vectors for the Stream Cipher ChaCha // TC2: single bit set in key, all zero IV, rounds 12, 256-bit key let mut seed = [0u8; 32]; seed[0] = 1; let mut rng = StdRng::from_seed(seed); - let mut results = [0u8; 64]; - rng.fill_bytes(&mut results); - #[rustfmt::skip] - let expected = [ - 0x12, 0x05, 0x6e, 0x59, 0x5d, 0x56, 0xb0, 0xf6, - 0xee, 0xf0, 0x90, 0xf0, 0xcd, 0x25, 0xa2, 0x09, - 0x49, 0x24, 0x8c, 0x27, 0x90, 0x52, 0x5d, 0x0f, - 0x93, 0x02, 0x18, 0xff, 0x0b, 0x4d, 0xdd, 0x10, - 0xa6, 0x00, 0x22, 0x39, 0xd9, 0xa4, 0x54, 0xe2, - 0x9e, 0x10, 0x7a, 0x7d, 0x06, 0xfe, 0xfd, 0xfe, - 0xf0, 0x21, 0x0f, 0xeb, 0xa0, 0x44, 0xf9, 0xf2, - 0x9b, 0x17, 0x72, 0xc9, 0x60, 0xdc, 0x29, 0xc0, - ]; - assert_eq!(results, expected); - - rng.fill_bytes(&mut results); - #[rustfmt::skip] + let mut results = [0u128; 8]; + rng.fill(&mut results); let expected = [ - 0x0c, 0x73, 0x66, 0xc5, 0xcb, 0xc6, 0x04, 0x24, - 0x0e, 0x66, 0x5e, 0xb0, 0x2a, 0x69, 0x37, 0x2a, - 0x7a, 0xf9, 0x79, 0xb2, 0x6f, 0xbb, 0x78, 0x09, - 0x2a, 0xc7, 0xc4, 0xb8, 0x80, 0x29, 0xa7, 0xc8, - 0x54, 0x51, 0x3b, 0xc2, 0x17, 0xbb, 0xfc, 0x7d, - 0x90, 0x43, 0x2e, 0x30, 0x8e, 0xba, 0x15, 0xaf, - 0xc6, 0x5a, 0xeb, 0x48, 0xef, 0x10, 0x0d, 0x56, - 0x01, 0xe6, 0xaf, 0xba, 0x25, 0x71, 0x17, 0xa9, + 0x9a225cdf090f0eef6b0565d596e0512, + 0x10dd4d0bff1802930f5d5290278c2449, + 0xfefdfe067d7a109ee254a4d9392200a6, + 0xc029dc60c972179bf2f944a0eb0f21f0, + 0x2a37692ab05e660e2404c6cbc566730c, + 0xc8a72980b8c4c72a0978bb6fb279f97a, + 0xaf15ba8e302e43907dfcbb17c23b5154, + 0xa9177125baafe601560d10ef48eb5ac6, ]; assert_eq!(results, expected); @@ -210,41 +179,24 @@ mod test { #[test] fn test_chacha_true_values_3() { - // Source: Test Vectors for the Stream Cipher ChaCha - // draft-strombergson-chacha-test-vectors-01 - // https://datatracker.ietf.org/doc/html/draft-strombergson-chacha-test-vectors-01 + // Source: Strombergson 2013, Test Vectors for the Stream Cipher ChaCha // TC3: all zero key, single bit set in IV, rounds 12, 256-bit key let seed = [0u8; 32]; let mut rng = StdRng::from_seed(seed); rng.0.set_stream(1); - let mut results = [0u8; 64]; - rng.fill_bytes(&mut results); - #[rustfmt::skip] - let expected = [ - 0x64, 0xb8, 0xbd, 0xf8, 0x7b, 0x82, 0x8c, 0x4b, - 0x6d, 0xba, 0xf7, 0xef, 0x69, 0x8d, 0xe0, 0x3d, - 0xf8, 0xb3, 0x3f, 0x63, 0x57, 0x14, 0x41, 0x8f, - 0x98, 0x36, 0xad, 0xe5, 0x9b, 0xe1, 0x29, 0x69, - 0x46, 0xc9, 0x53, 0xa0, 0xf3, 0x8e, 0xcf, 0xfc, - 0x9e, 0xcb, 0x98, 0xe8, 0x1d, 0x5d, 0x99, 0xa5, - 0xed, 0xfc, 0x8f, 0x9a, 0x0a, 0x45, 0xb9, 0xe4, - 0x1e, 0xf3, 0xb3, 0x1f, 0x02, 0x8f, 0x1d, 0x0f, - ]; - assert_eq!(results, expected); - - rng.fill_bytes(&mut results); - #[rustfmt::skip] + let mut results = [0u128; 8]; + rng.fill(&mut results); let expected = [ - 0x55, 0x9d, 0xb4, 0xa7, 0xf2, 0x22, 0xc4, 0x42, - 0xfe, 0x23, 0xb9, 0xa2, 0x59, 0x6a, 0x88, 0x28, - 0x51, 0x22, 0xee, 0x4f, 0x13, 0x63, 0x89, 0x6e, - 0xa7, 0x7c, 0xa1, 0x50, 0x91, 0x2a, 0xc7, 0x23, - 0xbf, 0xf0, 0x4b, 0x02, 0x6a, 0x2f, 0x80, 0x7e, - 0x03, 0xb2, 0x9c, 0x02, 0x07, 0x7d, 0x7b, 0x06, - 0xfc, 0x1a, 0xb9, 0x82, 0x7c, 0x13, 0xc8, 0x01, - 0x3a, 0x6d, 0x83, 0xbd, 0x3b, 0x52, 0xa2, 0x6f, + 0x3de08d69eff7ba6d4b8c827bf8bdb864, + 0x6929e19be5ad36988f411457633fb3f8, + 0xa5995d1de898cb9efccf8ef3a053c946, + 0xf1d8f021fb3f31ee4b9450a9a8ffced, + 0x28886a59a2b923fe42c422f2a7b49d55, + 0x23c72a9150a17ca76e8963134fee2251, + 0x67b7d07029cb2037e802f6a024bf0bf, + 0x6fa2523bbd836d3a01c8137c82b91afc, ]; assert_eq!(results, expected); @@ -253,9 +205,7 @@ mod test { #[test] fn test_chacha_true_values_8() { - // Source: Test Vectors for the Stream Cipher ChaCha - // draft-strombergson-chacha-test-vectors-01 - // https://datatracker.ietf.org/doc/html/draft-strombergson-chacha-test-vectors-01 + // Source: Strombergson 2013, Test Vectors for the Stream Cipher ChaCha // TC8: key: 'All your base are belong to us!', IV: IETF2013, rounds 12, 256-bit key #[rustfmt::skip] @@ -269,32 +219,17 @@ mod test { let mut rng = StdRng::from_seed(seed); rng.0.set_stream(u64::from_le_bytes(iv)); - let mut results = [0u8; 64]; - rng.fill_bytes(&mut results); - #[rustfmt::skip] - let expected = [ - 0x14, 0x82, 0x07, 0x27, 0x84, 0xbc, 0x6d, 0x06, - 0xb4, 0xe7, 0x3b, 0xdc, 0x11, 0x8b, 0xc0, 0x10, - 0x3c, 0x79, 0x76, 0x78, 0x6c, 0xa9, 0x18, 0xe0, - 0x69, 0x86, 0xaa, 0x25, 0x1f, 0x7e, 0x9c, 0xc1, - 0xb2, 0x74, 0x9a, 0x0a, 0x16, 0xee, 0x83, 0xb4, - 0x24, 0x2d, 0x2e, 0x99, 0xb0, 0x8d, 0x7c, 0x20, - 0x09, 0x2b, 0x80, 0xbc, 0x46, 0x6c, 0x87, 0x28, - 0x3b, 0x61, 0xb1, 0xb3, 0x9d, 0x0f, 0xfb, 0xab, - ]; - assert_eq!(results, expected); - - rng.fill_bytes(&mut results); - #[rustfmt::skip] + let mut results = [0u128; 8]; + rng.fill(&mut results); let expected = [ - 0xd9, 0x4b, 0x11, 0x6b, 0xc1, 0xeb, 0xdb, 0x32, - 0x9b, 0x9e, 0x4f, 0x62, 0x0d, 0xb6, 0x95, 0x54, - 0x4a, 0x8e, 0x3d, 0x9b, 0x68, 0x47, 0x3d, 0x0c, - 0x97, 0x5a, 0x46, 0xad, 0x96, 0x6e, 0xd6, 0x31, - 0xe4, 0x2a, 0xff, 0x53, 0x0a, 0xd5, 0xea, 0xc7, - 0xd8, 0x04, 0x7a, 0xdf, 0xa1, 0xe5, 0x11, 0x3c, - 0x91, 0xf3, 0xe3, 0xb8, 0x83, 0xf1, 0xd1, 0x89, - 0xac, 0x1c, 0x8f, 0xe0, 0x7b, 0xa5, 0xa4, 0x2b, + 0x10c08b11dc3be7b4066dbc8427078214, + 0xc19c7e1f25aa8669e018a96c7876793c, + 0x207c8db0992e2d24b483ee160a9a74b2, + 0xabfb0f9db3b1613b28876c46bc802b09, + 0x5495b60d624f9e9b32dbebc16b114bd9, + 0x31d66e96ad465a970c3d47689b3d8e4a, + 0x3c11e5a1df7a04d8c7ead50a53ff2ae4, + 0x2ba4a57be08f1cac89d1f183b8e3f391, ]; assert_eq!(results, expected); @@ -303,7 +238,7 @@ mod test { #[test] fn test_chacha_counter() { - // Source: none + // Source: rand_chacha implementation // Test: all zero key and IV, block set to u32::MAX, rounds 12, 256-bit key let seed = [0u8; 32]; @@ -312,32 +247,17 @@ mod test { let words_per_block = 16; rng.0.set_word_pos((block as u128) * words_per_block); - let mut results = [0u8; 64]; - rng.fill_bytes(&mut results); - #[rustfmt::skip] - let expected = [ - 0xd7, 0xa6, 0xaf, 0x50, 0xf1, 0xc9, 0x2a, 0x29, - 0x48, 0x42, 0x52, 0xbb, 0xfc, 0xe2, 0x06, 0xf1, - 0x7d, 0x01, 0xdd, 0x13, 0x95, 0x30, 0xa3, 0x83, - 0x0a, 0xb5, 0x83, 0xc1, 0xf6, 0x2e, 0x03, 0x12, - 0x82, 0x93, 0x61, 0xa1, 0x9a, 0x8a, 0x95, 0x6c, - 0xed, 0xea, 0x38, 0x04, 0x30, 0xff, 0x93, 0x2c, - 0xd0, 0x52, 0xdb, 0x5e, 0x94, 0x77, 0x83, 0x50, - 0x58, 0xb8, 0x0a, 0x27, 0x24, 0x06, 0xfc, 0x74, - ]; - assert_eq!(results, expected); - - rng.fill_bytes(&mut results); - #[rustfmt::skip] + let mut results = [0u128; 8]; + rng.fill(&mut results); let expected = [ - 0xcc, 0x7b, 0x53, 0xdc, 0x11, 0x89, 0x4d, 0x26, - 0x24, 0x05, 0x81, 0xb8, 0xa8, 0xf4, 0xf4, 0xe5, - 0xaf, 0x40, 0x67, 0x05, 0x80, 0x12, 0x23, 0xb1, - 0x3f, 0x82, 0x1f, 0xdc, 0xcb, 0xa6, 0xa6, 0x18, - 0x8a, 0x63, 0xf8, 0xd3, 0xdc, 0x83, 0xcc, 0xbc, - 0xed, 0x45, 0x1f, 0x4b, 0xa4, 0xe0, 0xda, 0xab, - 0x22, 0x8a, 0xbb, 0x0d, 0x74, 0x39, 0xcc, 0x67, - 0xe5, 0x0d, 0xf7, 0x12, 0x9f, 0x64, 0x6b, 0xad, + 0xf106e2fcbb524248292ac9f150afa6d7, + 0x12032ef6c183b50a83a3309513dd017d, + 0x2c93ff300438eaed6c958a9aa1619382, + 0x74fc0624270ab858508377945edb52d0, + 0xe5f4f4a8b8810524264d8911dc537bcc, + 0x18a6a6cbdc1f823fb1231280056740af, + 0xabdae0a44b1f45edbccc83dcd3f8638a, + 0xad6b649f12f70de567cc39740dbb8a22, ]; assert_eq!(results, expected); From ff5e2b40286e9424260bd5752a466dbec2073d8b Mon Sep 17 00:00:00 2001 From: Diggory Hardy Date: Thu, 4 Sep 2025 09:13:45 +0100 Subject: [PATCH 6/6] Extend counter wrap test --- src/rngs/std.rs | 23 +++++++++++++++++++++-- 1 file changed, 21 insertions(+), 2 deletions(-) diff --git a/src/rngs/std.rs b/src/rngs/std.rs index 59933150a14..328e57d5c7c 100644 --- a/src/rngs/std.rs +++ b/src/rngs/std.rs @@ -239,6 +239,9 @@ mod test { #[test] fn test_chacha_counter() { // Source: rand_chacha implementation + // We test six blocks: counter=u32::MAX, four blocks from 2^32 (backends + // which yield four blocks at a time may need to handle this specially) + // and the first block after this wrap-logic completes. // Test: all zero key and IV, block set to u32::MAX, rounds 12, 256-bit key let seed = [0u8; 32]; @@ -247,7 +250,7 @@ mod test { let words_per_block = 16; rng.0.set_word_pos((block as u128) * words_per_block); - let mut results = [0u128; 8]; + let mut results = [0u128; 4 * 6]; rng.fill(&mut results); let expected = [ 0xf106e2fcbb524248292ac9f150afa6d7, @@ -258,9 +261,25 @@ mod test { 0x18a6a6cbdc1f823fb1231280056740af, 0xabdae0a44b1f45edbccc83dcd3f8638a, 0xad6b649f12f70de567cc39740dbb8a22, + 0x37512785327825dc30ecfaf37a38f5a0, + 0x5af852d2df0dc286c2dd19af39b54e39, + 0xb04dc185c27497ac9f4a4f6769d1b5d, + 0x816492be66439cecd2498c9865284377, + 0x724fe95e0b6cbb8a55b707c06166147f, + 0xe3e7cda19d92b5318024abb34aa31329, + 0x1a3594d7283c077017cd511144bf3db3, + 0x99ab26cf14f38b11d78e413bdce6424c, + 0x553deaed89d3bf630de05408c0f655e8, + 0x86c46a5676fef18f0dc0dff3ee16507c, + 0xd33d6cf5ade97b000b29e3ce614faf51, + 0x5b62dcc48c0fc60326afc5783c40d40c, + 0x44eedc777ed030f43d382d4921eba244, + 0xa2d66a5893ade34a0d17c706e8d89dba, + 0xd229d1f3a07526e47cabd035135012fd, + 0xefae0722059b654dea6945547e535052, ]; assert_eq!(results, expected); - assert_eq!(rng.0.get_word_pos(), (block as u128) * words_per_block + 32); + assert_eq!(rng.0.get_word_pos(), (block as u128) * words_per_block + 96); } }