Skip to content

Parameterize the negative encryption tests across all ML-KEM parameter sets - #3

Merged
ffang merged 1 commit into
ffang:PQC-ENCRYPTIONfrom
Arpan0995:pqc-encryption-negative-tests
Aug 21, 2026
Merged

Parameterize the negative encryption tests across all ML-KEM parameter sets#3
ffang merged 1 commit into
ffang:PQC-ENCRYPTIONfrom
Arpan0995:pqc-encryption-negative-tests

Conversation

@Arpan0995

Copy link
Copy Markdown

As discussed on apache#645: this converts the wrong-recipient-key and truncated-encapsulation tests on both the DOM and StAX paths to @ParameterizedTest/@CsvSource across ML-KEM-512/768/1024, in the same style as the existing encrypt-decrypt tests. The encryptToRecipient helpers now take the key encapsulation algorithm as a parameter instead of hardcoding ML-KEM-768. The happy-path tests are untouched.

The truncate-to-half corruption stays shorter than encapsulationSize() for every parameter set (404/564/804 bytes against 768/1088/1568), so the length check in KeyUtils#kemDecapsulate is exercised by all three cases.

Verified locally on this branch:

  • mvn test -Dtest=XMLEncryptionMLKEMTest,StaxMLKEMEncryptionTest -P bouncycastle: 9 + 12 executions, 0 failures
  • same command without the bouncycastle profile: compiles and all 21 executions skip via the existing assumeTrue guards

…r sets

Converts the wrong-recipient-key and truncated-encapsulation rejection
tests on both the DOM and StAX paths from single hardcoded ML-KEM-768
cases to @ParameterizedTest/@CsvSource across ML-KEM-512/768/1024,
matching the style of the existing encrypt-decrypt tests. The
encryptToRecipient helpers take the key encapsulation algorithm as a
parameter instead of hardcoding ML-KEM-768.
@ffang

ffang commented Aug 21, 2026

Copy link
Copy Markdown
Owner

Thanks @Arpan0995 !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants