mirror of
https://github.com/ipxe/ipxe
synced 2026-10-07 15:05:42 +03:00
[test] Ensure that all TLS structure descriptor mappings are valid
Constructing exhaustive standalone tests for all TLS structures is time-consuming and of limited value, since there would be no guarantee that the construction logic used in the test case matched the construction logic matched in the real TLS protocol engine. We already exercise each failure path that can be triggered by genuine runtime errors (e.g. malformed received data, or transmit data that is too large to fit within the relevant length field). This leaves untested the other major class of errors: an invalid structure descriptor mapping (e.g. a missing field description) that would render the structure impossible to parse or build. Exercise the parser and builder for every structure type by creating an all-zero descriptor (which is always permitted), sizing and building the empty structure, and then parsing that structure. This ensures that the parser and builder are both satisfied that the descriptor mapping is valid, since the validity of the mapping is independent of the data being built or parsed. Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
@@ -331,6 +331,38 @@ union tlsfmt_test_data {
|
||||
uint8_t tls13_client_hello[ sizeof ( tls13_client_hello ) ];
|
||||
};
|
||||
|
||||
/**
|
||||
* Report a mapping validity test result
|
||||
*
|
||||
* @v type Descriptor structure name
|
||||
* @v version Protocol version
|
||||
*/
|
||||
#define map_version_ok( type, version ) do { \
|
||||
struct tls_cursor cursor; \
|
||||
struct type desc; \
|
||||
void *empty; \
|
||||
\
|
||||
memset ( &desc, 0, sizeof ( desc ) ); \
|
||||
ok ( tls_size ( type, version, &desc, &cursor ) == 0 ); \
|
||||
empty = zalloc ( cursor.len ); \
|
||||
ok ( empty != NULL ); \
|
||||
cursor.data = empty; \
|
||||
ok ( tls_build ( type, version, &desc, &cursor ) == 0 ); \
|
||||
ok ( tls_parse ( type, version, &cursor, &desc ) == 0 ); \
|
||||
free ( empty ); \
|
||||
} while ( 0 )
|
||||
|
||||
/**
|
||||
* Report a mapping validity test result
|
||||
*
|
||||
* @v type Descriptor structure name
|
||||
*/
|
||||
#define map_ok( type ) do { \
|
||||
map_version_ok ( type, TLS_VERSION_TLS_1_1 ); \
|
||||
map_version_ok ( type, TLS_VERSION_TLS_1_2 ); \
|
||||
map_version_ok ( type, TLS_VERSION_TLS_1_3 ); \
|
||||
} while ( 0 )
|
||||
|
||||
/**
|
||||
* Report a cursor comparison test result
|
||||
*
|
||||
@@ -406,6 +438,33 @@ static void tlsfmt_test_exec ( void ) {
|
||||
uint16_t record;
|
||||
uint8_t empty[0];
|
||||
|
||||
/* Check validity of all mappings */
|
||||
map_ok ( tls_certificate );
|
||||
map_ok ( tls_certificate_entry );
|
||||
map_ok ( tls_client_hello );
|
||||
map_ok ( tls_client_key_exchange_dhe );
|
||||
map_ok ( tls_client_key_exchange_ecdhe );
|
||||
map_ok ( tls_client_key_exchange_pubkey );
|
||||
map_ok ( tls_digitally_signed );
|
||||
map_ok ( tls_extension );
|
||||
map_ok ( tls_hello_request );
|
||||
map_ok ( tls_key_share_client_hello );
|
||||
map_ok ( tls_key_share_entry );
|
||||
map_ok ( tls_max_fragment_length );
|
||||
map_ok ( tls_named_group_list );
|
||||
map_ok ( tls_new_session_ticket );
|
||||
map_ok ( tls_psk_key_exchange_modes );
|
||||
map_ok ( tls_renegotiation_info );
|
||||
map_ok ( tls_server_hello );
|
||||
map_ok ( tls_server_hello_done );
|
||||
map_ok ( tls_server_key_exchange_dhe );
|
||||
map_ok ( tls_server_key_exchange_ecdhe );
|
||||
map_ok ( tls_server_name );
|
||||
map_ok ( tls_server_name_list );
|
||||
map_ok ( tls_signature_scheme_list );
|
||||
map_ok ( tls_supported_version );
|
||||
map_ok ( tls_supported_versions );
|
||||
|
||||
/* Well-formed TLSv1.3 ServerHello */
|
||||
memset ( u.tls13_server_hello, 0xaa, sizeof ( u.tls13_server_hello ) );
|
||||
memcpy ( u.tls13_server_hello, tls13_server_hello,
|
||||
|
||||
Reference in New Issue
Block a user