Brief summary
When crypto.subtle.generateKey generates a key pair and none of the requested usages apply to the private key, k6 returns a private key with an empty usages list. The specification requires a SyntaxError in that case.
k6 version
v2.3.0 (latest release). The affected code is unchanged on master as of 2026-09-30 (2a83804).
OS
macOS (darwin/arm64). Not OS-specific.
Docker version and image (if applicable)
No response
Steps to reproduce the problem
export default async function () {
const kp = await crypto.subtle.generateKey({ name: "ECDSA", namedCurve: "P-256" }, true, ["verify"]);
console.log(JSON.stringify(kp.privateKey.usages));
}
Expected behaviour
The promise rejects with a SyntaxError.
ECDSA's generate key operation gives the private key only the sign usage, so requesting ["verify"] leaves it with none:
Set the [[usages]] internal slot of privateKey to be the usage intersection of usages and [ "sign" ].
generateKey, step 9 then requires an error:
If result is a CryptoKeyPair object: If the [[usages]] internal slot of the privateKey attribute of result is the empty sequence, then throw a SyntaxError.
Actual behaviour
Actual behaviour
The key pair is returned, and the private key can't be used for anything:
Cause and possible fix
GenerateKey applies the empty-usages check only to single keys, and returns key pairs before reaching it (subtle_crypto.go#L526). Checking the private key's usages in the key-pair branch would fix it for all key pair algorithms.
I'm happy to open a PR for this.
Brief summary
When
crypto.subtle.generateKeygenerates a key pair and none of the requested usages apply to the private key, k6 returns a private key with an emptyusageslist. The specification requires aSyntaxErrorin that case.k6 version
v2.3.0 (latest release). The affected code is unchanged on master as of 2026-09-30 (2a83804).
OS
macOS (darwin/arm64). Not OS-specific.
Docker version and image (if applicable)
No response
Steps to reproduce the problem
Expected behaviour
The promise rejects with a
SyntaxError.ECDSA's generate key operation gives the private key only the
signusage, so requesting["verify"]leaves it with none:generateKey, step 9 then requires an error:Actual behaviour
Actual behaviour
The key pair is returned, and the private key can't be used for anything:
Cause and possible fix
GenerateKeyapplies the empty-usages check only to single keys, and returns key pairs before reaching it (subtle_crypto.go#L526). Checking the private key's usages in the key-pair branch would fix it for all key pair algorithms.I'm happy to open a PR for this.