| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
…t (type 34) rather than the AEAD ciphersuites subpacket (type 39), relates to github #2489.
|
Thanks for the PR! Now merged and up on https://www.bouncycastle.org/betas |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
On main, PGPSignatureSubpacketVector.getPreferredLibrePgpEncryptionModes() (pg/src/main/java/org/bouncycastle/openpgp/PGPSignatureSubpacketVector.java:332) should read the LibrePGP Preferred Encryption Modes subpacket, type 34 (SignatureSubpacketTags.java:33), but looks up PREFERRED_AEAD_ALGORITHMS (:334), which is 39, the RFC 9580 Preferred AEAD Ciphersuites subpacket, and casts the result to LibrePGPPreferredEncryptionModes (:340). The parser builds a PreferredAEADCiphersuites for type 39 and a LibrePGPPreferredEncryptionModes for type 34 (SignatureSubpacketInputStream.java:165-168), so the getter never returns the modes: a signature carrying type 39 makes it throw ClassCastException, and one carrying only type 34 gives null.
Its javadoc notes LibrePGP asks for this subpacket to be ignored, so the practical effect is mostly the exception. Type 39 is on the direct-key self-signature of keys from OpenPGPApi.generateKey() with default preferences (AbstractOpenPGPKeySignatureGenerator.java:137, applying :20-31).
Reproduced on the released bcpg-jdk18on-1.86.jar: the direct-key signature of a re-imported v6 ed25519x25519 key from the openpgp.api generator throws ClassCastException (PreferredAEADCiphersuites cannot be cast to LibrePGPPreferredEncryptionModes), as do a v4 key from generateKey(4) and the RFC 9580 sample certificate in OpenPGPTestKeys.V6_CERT, while the LibrePGP v5 sample certificate in PGPv5KeyTest, which carries type 34 with modes 2, 1, gives null. Current main has the same source, unchanged since 1.79, and the 1.87-SNAPSHOT beta (1.87.0.20730) ships a class byte-identical to 1.86's and reproduces both.
This change:
Both fail without the change, on the null and on the ClassCastException respectively, and pass with it. On the 1.87.0.20730 jars with only this class replaced, the openpgp and openpgp.api RegressionTest suites, the bcpg packet tests and the openpgp.test.AllTests JUnit classes go from 117 of 120 class runs passing to 120 of 120, the three being the runs of the two classes that hold the new tests; PGPGeneralTest, which asserts the null case at :2129, passes either way. :pg:checkstyleMain is clean.
Base tree only: no overlay copy, no module-info or OSGi change. A release-note entry is included, happy to move it to another block.