Commit 7e9b10a8c0 for openssl.org

commit 7e9b10a8c0cd02861a1f81865ab226ccbba3518b
Author: Tomas Mraz <tomas@openssl.foundation>
Date:   Tue Oct 6 09:52:00 2026 +0200

    test_cipher_reinit(): Reinit is not supported with CCM on old providers

    Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
    Reviewed-by: Neil Horman <nhorman@openssl.org>
    Merge-date: Tue Oct  6 08:58:57 2026
    Merged-from: https://github.com/openssl/openssl/pull/33114

diff --git a/test/evp_libctx_test.c b/test/evp_libctx_test.c
index c4be6bf27c..522cb5e353 100644
--- a/test/evp_libctx_test.c
+++ b/test/evp_libctx_test.c
@@ -377,13 +377,19 @@ static int test_cipher_reinit(int test_id)
     };
     const char *name = sk_OPENSSL_STRING_value(cipher_names, test_id);

-    if (!TEST_ptr(ctx = EVP_CIPHER_CTX_new()))
-        goto err;
-
     TEST_note("Fetching %s\n", name);
     if (!TEST_ptr(cipher = EVP_CIPHER_fetch(libctx, name, NULL)))
         goto err;

+    if (fips_provider_version_match(libctx, "<4.2.0")
+        && EVP_CIPHER_get_mode(cipher) == EVP_CIPH_CCM_MODE) {
+        EVP_CIPHER_free(cipher);
+        return TEST_skip("CCM modes do not support reinit with old providers");
+    }
+
+    if (!TEST_ptr(ctx = EVP_CIPHER_CTX_new()))
+        goto err;
+
     /* siv cannot be called with NULL key as the iv is irrelevant */
     siv = (EVP_CIPHER_get_mode(cipher) == EVP_CIPH_SIV_MODE);