Repository navigation
fs,crypto: AAD decryption of fs stream > 32768 bytes fails #31733
Copy link
Copy link
Closed
Labels
confirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.cryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.fsIssues and PRs related to file-system APIs and the fs module.Issues and PRs related to file-system APIs and the fs module.streamIssues and PRs related to Node.js streams.Issues and PRs related to Node.js streams.
Description
Activity
See here - the maximum message size is a function of the IV size. Make it bigger and it'll work.
@bnoordhuis Thx guy, but I have read this article and tried it before. And It doesn't work even if I increase the length of IV to 13 bytes, which is the maximum length of CCM IV.
const iv = $Crypto.randomBytes(13);
- addedcryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.fsIssues and PRs related to file-system APIs and the fs module.Issues and PRs related to file-system APIs and the fs module.streamIssues and PRs related to Node.js streams.Issues and PRs related to Node.js streams.
on Feb 11, 2020 I'm moving this to nodejs/node because this looks like a timing related bug with fs streams. I can reproduce what you're describing but also observe that AAD decryption works with other stream types.
I don't have time to investigate right now but I've opened #31734 with a known issues test as a starting point for others.
- addedconfirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.
on Feb 11, 2020 - changed the title
[-]Why AES-128-CCM decipher failed when message larger than 32768 bytes[/-][+]fs,crypto: AAD decryption of fs stream > 32768 bytes fails[/+]on Feb 11, 2020 @bnoordhuis Okay, Thanks.
- added a commit that references this issue
on Feb 18, 2020 - added a commit that references this issue
on Apr 2, 2020 - added a commit that references this issue
on Apr 7, 2020 - added a commit that references this issue
on Apr 12, 2020 - added a commit that references this issue
on Apr 22, 2020 This might be fixed through #33981
- added a commit that references this issue
on Jun 20, 2020 - added 2 commits that reference this issue
on Apr 25, 2021 - added a commit that references this issue
on Jul 27, 2026
Metadata
Metadata
Assignees
Labels
confirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.cryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.fsIssues and PRs related to file-system APIs and the fs module.Issues and PRs related to file-system APIs and the fs module.streamIssues and PRs related to Node.js streams.Issues and PRs related to Node.js streams.
With a 32768 bytes message, the AES-128-CCM cipher and decipher both work well.
With a 32769 bytes message, the AES-128-CCM cipher works well, but the decipher failed with a message:
I can't understand why. Whatever I change the AAD/IV/authTagLength, it can‘t work.
Here is my code: