Skip to content

webcrypto: generateKey returns a key pair whose private key has no usages #6524

Description

@BlairCurrey

Brief summary

When crypto.subtle.generateKey generates a key pair and none of the requested usages apply to the private key, k6 returns a private key with an empty usages list. The specification requires a SyntaxError in that case.

k6 version

v2.3.0 (latest release). The affected code is unchanged on master as of 2026-09-30 (2a83804).

OS

macOS (darwin/arm64). Not OS-specific.

Docker version and image (if applicable)

No response

Steps to reproduce the problem

export default async function () {
  const kp = await crypto.subtle.generateKey({ name: "ECDSA", namedCurve: "P-256" }, true, ["verify"]);
  console.log(JSON.stringify(kp.privateKey.usages));
}

Expected behaviour

The promise rejects with a SyntaxError.

ECDSA's generate key operation gives the private key only the sign usage, so requesting ["verify"] leaves it with none:

Set the [[usages]] internal slot of privateKey to be the usage intersection of usages and [ "sign" ].

generateKey, step 9 then requires an error:

If result is a CryptoKeyPair object: If the [[usages]] internal slot of the privateKey attribute of result is the empty sequence, then throw a SyntaxError.

Actual behaviour

Actual behaviour

The key pair is returned, and the private key can't be used for anything:

[]

Cause and possible fix

GenerateKey applies the empty-usages check only to single keys, and returns key pairs before reaching it (subtle_crypto.go#L526). Checking the private key's usages in the key-pair branch would fix it for all key pair algorithms.

I'm happy to open a PR for this.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions