Attention is currently required from: jolly, pespin.
Hello Jenkins Builder, jolly,
I'd like you to reexamine a change. Please visit
https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/43144?usp=email
to look at the new patch set (#5).
The following approvals got outdated and were removed:
Verified+1 by Jenkins Builder
Change subject: library/euicc: add ESipa JSON encoder/decoder module
......................................................................
library/euicc: add ESipa JSON encoder/decoder module
In order to test an eIM (or IPAd), which uses the JSON ESipa bindings
instead of the ASN.1 ESipa bindings a set of encoder/decoder functions
is needed to generate/parse the JSON messages exchanged on the ESipa
interface
Change-Id: I8b6a87f39ca23658d980d19cf257b8994ea1cecb
Related: SYS#8100
---
M eim/eIM_Tests.cfg
M eim/eIM_Tests.ttcn
M eim/gen_links.sh
M library/euicc/RSPDefinitions_Types.ttcn
M library/euicc/SGP32Definitions_Types.ttcn
A library/euicc/esipa_Types_JSON.ttcn
6 files changed, 705 insertions(+), 43 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/osmo-ttcn3-hacks refs/changes/44/43144/5
--
To view, visit https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/43144?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newpatchset
Gerrit-Project: osmo-ttcn3-hacks
Gerrit-Branch: master
Gerrit-Change-Id: I8b6a87f39ca23658d980d19cf257b8994ea1cecb
Gerrit-Change-Number: 43144
Gerrit-PatchSet: 5
Gerrit-Owner: dexter <pmaier(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: jolly <andreas(a)eversberg.eu>
Gerrit-CC: pespin <pespin(a)sysmocom.de>
Gerrit-Attention: jolly <andreas(a)eversberg.eu>
Gerrit-Attention: pespin <pespin(a)sysmocom.de>
Attention is currently required from: dexter.
Hello Jenkins Builder, laforge, pespin,
I'd like you to reexamine a change. Please visit
https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/43182?usp=email
to look at the new patch set (#2).
The following approvals got outdated and were removed:
Verified+1 by Jenkins Builder
The change is no longer submittable: Verified is unsatisfied now.
Change subject: eim_Tests: Add testcase to test ESipa/ES9+: CancelSession
......................................................................
eim_Tests: Add testcase to test ESipa/ES9+: CancelSession
The testsuite never sends or receives any messages related to ESipa/ES9+
CancelSession, let's implement a varinat of the "Cancel Session Procedure
for Indirect Profile Download" as described in SGP.32 section 3.2.3.3 to
increase the coverage accordingly.
Related: SYS#8100
Change-Id: Iadc9010fcf08de98f7d8c2a5c68bb5ff71bfb1f6
---
M eim/eIM_Tests.ttcn
1 file changed, 59 insertions(+), 0 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/osmo-ttcn3-hacks refs/changes/82/43182/2
--
To view, visit https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/43182?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newpatchset
Gerrit-Project: osmo-ttcn3-hacks
Gerrit-Branch: master
Gerrit-Change-Id: Iadc9010fcf08de98f7d8c2a5c68bb5ff71bfb1f6
Gerrit-Change-Number: 43182
Gerrit-PatchSet: 2
Gerrit-Owner: dexter <pmaier(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-Reviewer: pespin <pespin(a)sysmocom.de>
Gerrit-Attention: dexter <pmaier(a)sysmocom.de>
osmith has submitted this change. ( https://gerrit.osmocom.org/c/osmo-ci/+/43198?usp=email )
Change subject: jenkins-gerrit/comment_generate: fail on 0 passed
......................................................................
jenkins-gerrit/comment_generate: fail on 0 passed
Don't print the success message when zero jobs has passed. If this
happens, we have an internal error somewhere.
Change-Id: I1317f14c2f3f55f2a9b6581372c80edba33528db
---
M scripts/jenkins-gerrit/comment_generate.py
1 file changed, 3 insertions(+), 1 deletion(-)
Approvals:
pespin: Looks good to me, but someone else must approve
fixeria: Looks good to me, approved
Jenkins Builder: Verified
diff --git a/scripts/jenkins-gerrit/comment_generate.py b/scripts/jenkins-gerrit/comment_generate.py
index fc8a8b1..1b3bfcd 100755
--- a/scripts/jenkins-gerrit/comment_generate.py
+++ b/scripts/jenkins-gerrit/comment_generate.py
@@ -212,6 +212,8 @@
summary += f"{len(jobs['passed'])} passed:\n"
summary += get_jobs_list_str(jobs["passed"])
+ if not jobs['passed']:
+ summary += "Zero jobs passed, internal script error?\n"
if "build" in pipeline and "deb" in pipeline and "rpm" in pipeline and \
not pipeline["build"]["passed"] and pipeline["deb"]["passed"] \
@@ -227,7 +229,7 @@
summary += "https://osmocom.org/projects/cellular-infrastructure/wiki/Linting\n"
summary += "\n"
- if jobs["failed"]:
+ if jobs["failed"] or not jobs['passed']:
summary += "Build Failed\n"
summary += "\n"
summary += f"Find the Retrigger button here:\n{build_url}\n"
--
To view, visit https://gerrit.osmocom.org/c/osmo-ci/+/43198?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: merged
Gerrit-Project: osmo-ci
Gerrit-Branch: master
Gerrit-Change-Id: I1317f14c2f3f55f2a9b6581372c80edba33528db
Gerrit-Change-Number: 43198
Gerrit-PatchSet: 1
Gerrit-Owner: osmith <osmith(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: osmith <osmith(a)sysmocom.de>
Gerrit-Reviewer: pespin <pespin(a)sysmocom.de>
Hoernchen has uploaded a new patch set (#2). ( https://gerrit.osmocom.org/c/pysim/+/43200?usp=email )
Change subject: GP: fix kcb for non block aligned keys
......................................................................
GP: fix kcb for non block aligned keys
how encrypt_key() pads a kcv:
len(key) % blocksize bytes
what it should do to actually do it right:
blocksize - len(key) % blocksize
so the plaintext handed to the cipher was only block aligned by luck as
long as the key length happened to be a multiple of half the block size.
And of course decrypt_key() did not invert encrypt_key() at all,
the clear text length of GP CardSpec v2.3 Table 11-70 precedes the
ENCRYPTED kcv, but it was parsed out of the DECRYPTED data, and the
length byte itself was fed to the cipher along with the cryptogram.
Fix this up with a helper and tests so it is actually usable.
Change-Id: I02b4f2ed948c31e1741e40f0226fb49757fa2570
---
M pySim/global_platform/scp.py
M tests/unittests/test_globalplatform.py
2 files changed, 48 insertions(+), 6 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/pysim refs/changes/00/43200/2
--
To view, visit https://gerrit.osmocom.org/c/pysim/+/43200?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newpatchset
Gerrit-Project: pysim
Gerrit-Branch: master
Gerrit-Change-Id: I02b4f2ed948c31e1741e40f0226fb49757fa2570
Gerrit-Change-Number: 43200
Gerrit-PatchSet: 2
Gerrit-Owner: Hoernchen <ewild(a)sysmocom.de>
Gerrit-CC: Jenkins Builder
Attention is currently required from: dexter, laforge.
Hoernchen has posted comments on this change by Hoernchen. ( https://gerrit.osmocom.org/c/pysim/+/43172?usp=email )
Change subject: GP: LOAD/STORE DATA chunk size from SCP overhead
......................................................................
Set Ready For Review
--
To view, visit https://gerrit.osmocom.org/c/pysim/+/43172?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: comment
Gerrit-Project: pysim
Gerrit-Branch: master
Gerrit-Change-Id: Ic208f3959a38896f64fb6ccefb24cc360a3ac3a2
Gerrit-Change-Number: 43172
Gerrit-PatchSet: 3
Gerrit-Owner: Hoernchen <ewild(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: dexter <pmaier(a)sysmocom.de>
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-Attention: laforge <laforge(a)osmocom.org>
Gerrit-Attention: dexter <pmaier(a)sysmocom.de>
Gerrit-Comment-Date: Mon, 10 Aug 2026 18:44:58 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: No
Hoernchen has uploaded this change for review. ( https://gerrit.osmocom.org/c/pysim/+/43200?usp=email )
Change subject: GP: fix kcb for non block aligned keys
......................................................................
GP: fix kcb for non block aligned keys
how encrypt_key() pads a kcv:
len(key) % blocksize bytes
what it should do to actually do it right:
blocksize - len(key) % blocksize
so the plaintext handed to the cipher was only block aligned by luck as
long as the key length happened to be a multiple of half the block size.
And of course decrypt_key() did not invert encrypt_key() at all,
the clear text length of Table 11-70 precedes the ENCRYPTED kcv,
but it was parsed out of the DECRYPTED data, and the length byte itself
was fed to the cipher along with the cryptogram.
Fix this up with a helper and tests so it is actually usable.
Change-Id: I02b4f2ed948c31e1741e40f0226fb49757fa2570
---
M pySim/global_platform/scp.py
M tests/unittests/test_globalplatform.py
2 files changed, 48 insertions(+), 6 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/pysim refs/changes/00/43200/1
diff --git a/pySim/global_platform/scp.py b/pySim/global_platform/scp.py
index a5fcf51..a50b17e 100644
--- a/pySim/global_platform/scp.py
+++ b/pySim/global_platform/scp.py
@@ -215,11 +215,19 @@
def gen_ext_auth_apdu(self, security_level: int = 0x01) -> bytes:
pass
+ def pad_to_blocksize(self, data: bytes) -> bytes:
+ """Right pad the data with zero bytes to a multiple of the DEK cipher block size."""
+ if len(data) % self.sk.blocksize:
+ data += b'\x00' * (self.sk.blocksize - len(data) % self.sk.blocksize)
+ return data
+
def encrypt_key(self, key: bytes) -> bytes:
"""Encrypt a key with the DEK."""
- num_pad = len(key) % self.sk.blocksize
- if num_pad:
- return bertlv_encode_len(len(key)) + self.dek_encrypt(key + b'\x00'*num_pad)
+ if len(key) % self.sk.blocksize:
+ # The kcv is right padded before encryption and the kcb
+ # is formatted as described in Table 11-70: preceded by the actual length of the
+ # clear text kcv.
+ return bertlv_encode_len(len(key)) + self.dek_encrypt(self.pad_to_blocksize(key))
return self.dek_encrypt(key)
def decrypt_key(self, encrypted_key:bytes) -> bytes:
@@ -232,9 +240,8 @@
# Block provides the actual length of the key component value, which allows recovering the
# clear-text key component value after decryption of the encrypted key component value and removal
# of padding bytes.
- decrypted = self.dek_decrypt(encrypted_key)
- key_len, remainder = bertlv_parse_len(decrypted)
- return remainder[:key_len]
+ key_len, remainder = bertlv_parse_len(encrypted_key)
+ return self.dek_decrypt(remainder)[:key_len]
else:
# If the length of the Key Component Block is a multiple of the block size of the encryption
# algorithm (i.e. 8 bytes for DES, 16 bytes for AES), then it shall be assumed that no padding
diff --git a/tests/unittests/test_globalplatform.py b/tests/unittests/test_globalplatform.py
index 8698470..576407d 100644
--- a/tests/unittests/test_globalplatform.py
+++ b/tests/unittests/test_globalplatform.py
@@ -283,6 +283,41 @@
# FIXME: test auth with random (0x60) vs pseudo-random (0x70) challenge
+class KeyComponentBlock_Test(unittest.TestCase):
+ """Tests for the kcb of GP CardSpec v2.3
+ - Table 11-70 kcv that required padding, preceded by its clear-text length
+ - Table 11-71 no padding required"""
+
+ def setUp(self):
+ # SCP02 (3DES DEK, 8 byte blocks), same vectors as SCP02_Test
+ self.scp02 = SCP02(card_keys=ck_3des_70)
+ self.scp02.gen_init_update_apdu(host_challenge=h2b('40A62C37FA6304F8'))
+ self.scp02.parse_init_update_resp(h2b('00000000000000000000700200016B4524ABEE7CF32EA3838BC148F3'))
+ self.scp02.gen_ext_auth_apdu()
+ # SCP03 (AES DEK, 16 byte blocks), same vectors as SCP03_Test_AES128_11
+ self.scp03 = SCP03(card_keys=KEYSET_AES128)
+ self.scp03.gen_init_update_apdu(h2b('b13e5f938fc108c4'))
+ self.scp03.parse_init_update_resp(h2b('000000000000000000003003703eb51047495b249f66c484c1d2ef1948000002'))
+ self.scp03.gen_ext_auth_apdu(0x11)
+
+ def test_encrypt_decrypt_key(self):
+ for scp in (self.scp02, self.scp03):
+ bs = scp.sk.blocksize
+ for keylen in range(1, 3 * bs + 1):
+ with self.subTest(scp=type(scp).__name__, keylen=keylen):
+ key = bytes(range(keylen))
+ kcb = scp.encrypt_key(key)
+ if keylen % bs:
+ # Table 11-70: <length of clear key component> || <encrypted padded value>
+ self.assertEqual(kcb[0], keylen)
+ self.assertEqual((len(kcb) - 1) % bs, 0)
+ self.assertEqual(len(kcb) - 1, keylen + (bs - keylen % bs))
+ else:
+ # Table 11-71: only the encrypted key component value
+ self.assertEqual(len(kcb), keylen)
+ self.assertEqual(scp.decrypt_key(kcb), key)
+
+
class SCP03_KCV_Test(unittest.TestCase):
def test_kcv(self):
self.assertEqual(compute_kcv('aes', KEYSET_AES128.enc), h2b('C35280'))
--
To view, visit https://gerrit.osmocom.org/c/pysim/+/43200?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newchange
Gerrit-Project: pysim
Gerrit-Branch: master
Gerrit-Change-Id: I02b4f2ed948c31e1741e40f0226fb49757fa2570
Gerrit-Change-Number: 43200
Gerrit-PatchSet: 1
Gerrit-Owner: Hoernchen <ewild(a)sysmocom.de>