[test] Ensure that all TLS structure descriptor mappings are valid

Constructing exhaustive standalone tests for all TLS structures is
time-consuming and of limited value, since there would be no guarantee
that the construction logic used in the test case matched the
construction logic matched in the real TLS protocol engine.

We already exercise each failure path that can be triggered by genuine
runtime errors (e.g. malformed received data, or transmit data that is
too large to fit within the relevant length field).  This leaves
untested the other major class of errors: an invalid structure
descriptor mapping (e.g. a missing field description) that would
render the structure impossible to parse or build.

Exercise the parser and builder for every structure type by creating
an all-zero descriptor (which is always permitted), sizing and
building the empty structure, and then parsing that structure.  This
ensures that the parser and builder are both satisfied that the
descriptor mapping is valid, since the validity of the mapping is
independent of the data being built or parsed.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
Michael Brown
2026-09-22 10:35:08 +01:00
parent 2b6bd7660b
commit 0367d09926
+59
View File
@@ -331,6 +331,38 @@ union tlsfmt_test_data {
uint8_t tls13_client_hello[ sizeof ( tls13_client_hello ) ];
};
/**
* Report a mapping validity test result
*
* @v type Descriptor structure name
* @v version Protocol version
*/
#define map_version_ok( type, version ) do { \
struct tls_cursor cursor; \
struct type desc; \
void *empty; \
\
memset ( &desc, 0, sizeof ( desc ) ); \
ok ( tls_size ( type, version, &desc, &cursor ) == 0 ); \
empty = zalloc ( cursor.len ); \
ok ( empty != NULL ); \
cursor.data = empty; \
ok ( tls_build ( type, version, &desc, &cursor ) == 0 ); \
ok ( tls_parse ( type, version, &cursor, &desc ) == 0 ); \
free ( empty ); \
} while ( 0 )
/**
* Report a mapping validity test result
*
* @v type Descriptor structure name
*/
#define map_ok( type ) do { \
map_version_ok ( type, TLS_VERSION_TLS_1_1 ); \
map_version_ok ( type, TLS_VERSION_TLS_1_2 ); \
map_version_ok ( type, TLS_VERSION_TLS_1_3 ); \
} while ( 0 )
/**
* Report a cursor comparison test result
*
@@ -406,6 +438,33 @@ static void tlsfmt_test_exec ( void ) {
uint16_t record;
uint8_t empty[0];
/* Check validity of all mappings */
map_ok ( tls_certificate );
map_ok ( tls_certificate_entry );
map_ok ( tls_client_hello );
map_ok ( tls_client_key_exchange_dhe );
map_ok ( tls_client_key_exchange_ecdhe );
map_ok ( tls_client_key_exchange_pubkey );
map_ok ( tls_digitally_signed );
map_ok ( tls_extension );
map_ok ( tls_hello_request );
map_ok ( tls_key_share_client_hello );
map_ok ( tls_key_share_entry );
map_ok ( tls_max_fragment_length );
map_ok ( tls_named_group_list );
map_ok ( tls_new_session_ticket );
map_ok ( tls_psk_key_exchange_modes );
map_ok ( tls_renegotiation_info );
map_ok ( tls_server_hello );
map_ok ( tls_server_hello_done );
map_ok ( tls_server_key_exchange_dhe );
map_ok ( tls_server_key_exchange_ecdhe );
map_ok ( tls_server_name );
map_ok ( tls_server_name_list );
map_ok ( tls_signature_scheme_list );
map_ok ( tls_supported_version );
map_ok ( tls_supported_versions );
/* Well-formed TLSv1.3 ServerHello */
memset ( u.tls13_server_hello, 0xaa, sizeof ( u.tls13_server_hello ) );
memcpy ( u.tls13_server_hello, tls13_server_hello,