Commit f7db0e6d62 for openssl.org

commit f7db0e6d62827d1309a3833f79cbd77a9bec32ed
Author: Billy Brumley <bbb@iki.fi>
Date:   Thu Sep 17 18:49:54 2026 -0400

    ASCON: reject AEAD Update and Final on a finished context

    The context was never marked finished after Final, so it kept accepting
    data and would issue a tag for it. Mark it finished once the tag has been
    computed or verified, matching the other AEADs.

    Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
    Reviewed-by: Neil Horman <nhorman@openssl.org>
    Reviewed-by: Paul Dale <paul.dale@oracle.com>
    Merge-date: Thu Oct  1 19:07:28 2026
    Merged-from: https://github.com/openssl/openssl/pull/32875

diff --git a/providers/implementations/ciphers/cipher_ascon_aead128.c b/providers/implementations/ciphers/cipher_ascon_aead128.c
index be28b49a7d..281c5c2ca7 100644
--- a/providers/implementations/ciphers/cipher_ascon_aead128.c
+++ b/providers/implementations/ciphers/cipher_ascon_aead128.c
@@ -337,6 +337,7 @@ static int ascon_aead128_final(void *vctx, unsigned char *out, size_t *outl, siz
             ciphertext, tag, tag_len);
         *outl = ret;
         ctx->is_tag_set = 1;
+        ctx->is_ongoing = 0; /* finished: no further update/final on this IV */

         return 1;
     } else if (ctx->direction == DECRYPTION) {
@@ -352,6 +353,7 @@ static int ascon_aead128_final(void *vctx, unsigned char *out, size_t *outl, siz
                 plaintext, &is_tag_valid,
                 expected_tag,
                 expected_tag_len);
+            ctx->is_ongoing = 0; /* finished, whatever the verdict */

             if (is_tag_valid) {
                 *outl = ret;