openssl/test
Matt Caswell f315b66571 Add tests for version/ciphersuite sanity checks
The previous commits added sanity checks for where the max enabled protocol
version does not have any configured ciphersuites. We should check that we
fail in those circumstances.

Reviewed-by: Rich Salz <rsalz@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/3334)
2017-05-04 11:49:20 +01:00
..
certs Add test for -nameout output 2017-03-14 15:18:07 -04:00
ct Verify SCT signatures 2016-03-01 11:59:28 -05:00
d2i-tests add test for CVE-2016-7053 2016-11-10 13:04:11 +00:00
ocsp-tests
ossl_shim Re-enable some BoringSSL tests 2017-03-14 23:15:21 +00:00
recipes Add a ciphersuite config sanity check for servers 2017-05-04 11:49:19 +01:00
smime-certs spelling fixes, just comments and readme. 2016-08-05 19:07:30 -04:00
ssl-tests Add tests for version/ciphersuite sanity checks 2017-05-04 11:49:20 +01:00
testlib Update the kex modes tests to check various HRR scenarios 2017-02-14 13:14:25 +00:00
aborttest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
afalgtest.c Handle inability to create AFALG socket 2016-06-13 17:28:40 +01:00
asn1_internal_test.c Add main() test methods to reduce test boilerplate. 2016-11-09 16:07:16 +01:00
asynciotest.c Let test handshakes stop on certain errors 2017-02-23 19:40:27 +01:00
asynctest.c Add test to show wrong behavior of ASYNC_WAIT_CTX 2017-02-13 15:29:42 +00:00
bad_dtls_test.c Solution proposal for issue #1647. 2016-11-12 22:26:20 -05:00
bftest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
bio_enc_test.c Fix bio_enc_test 2016-08-23 09:24:29 +01:00
bioprinttest.c Whitespace cleanup in apps 2016-06-29 09:56:39 -04:00
bntest.c bntest: do not stop on first fautl encountered 2017-02-01 02:03:29 +01:00
bntests.pl Make bntest be (mostly) file-based. 2016-11-28 12:26:05 -05:00
bntests.txt bntests.txt: add a couple of checks of possibly negative zero 2017-02-01 02:03:29 +01:00
build.info Unit tests for crypto/stack. 2017-03-15 14:15:08 +01:00
CAss.cnf RT3809: basicConstraints is critical 2016-06-13 09:18:22 -04:00
CAssdh.cnf
CAssdsa.cnf
CAssrsa.cnf
casttest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
CAtsa.cnf Use better defaults for TSA. 2015-11-20 13:40:53 +00:00
chacha_internal_test.c test: add chacha_internal_test. 2017-03-07 10:56:07 +01:00
cipher_overhead_test.c Add unit test for ssl_cipher_get_overhead() 2016-11-02 14:00:11 +00:00
cipherbytes_test.c Tests for SSL_bytes_to_cipher_list() 2017-02-23 19:40:25 +01:00
cipherlist_test.c update test 2017-02-08 02:16:28 +00:00
clienthellotest.c Fix a warning about an uninit var 2016-11-24 18:02:43 +00:00
cms-examples.pl Copyright consolidation: perl files 2016-04-20 09:45:40 -04:00
constant_time_test.c constant time test: include our internal/numbers.h rather than limits.h 2016-11-05 11:38:29 +01:00
crltest.c GH2176: Add X509_VERIFY_PARAM_get_time 2017-01-12 09:54:09 -05:00
ct_test.c Make sure things get deleted when test setup fails in ct_test.c 2016-11-16 13:54:17 +00:00
d2i_test.c Add main() test methods to reduce test boilerplate. 2016-11-09 16:07:16 +01:00
danetest.c Fix some -Wshadow warnings 2017-03-14 11:44:31 -05:00
danetest.in Perform DANE-EE(3) name checks by default 2016-07-12 10:16:34 -04:00
danetest.pem DANE support for X509_verify_cert() 2016-01-07 13:48:59 -05:00
destest.c spelling fixes, just comments and readme. 2016-08-05 19:07:30 -04:00
dhtest.c Fix the build and tests following constification of DH, DSA, RSA 2016-06-16 13:34:44 +01:00
dsatest.c Fix the build and tests following constification of DH, DSA, RSA 2016-06-16 13:34:44 +01:00
dtls_mtu_test.c Let test handshakes stop on certain errors 2017-02-23 19:40:27 +01:00
dtlstest.c Let test handshakes stop on certain errors 2017-02-23 19:40:27 +01:00
dtlsv1listentest.c Simplify and rename SSL_set_rbio() and SSL_set_wbio() 2016-07-29 14:09:57 +01:00
ecdhtest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
ecdhtest_cavs.h Whitespace cleanup in apps 2016-06-29 09:56:39 -04:00
ecdsatest.c spelling fixes, just comments and readme. 2016-08-05 19:07:30 -04:00
ectest.c Remove some obsolete/obscure internal define switches: 2017-03-01 10:44:49 +01:00
enginetest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
evp_extra_test.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
evp_test.c Avoid buffer underflow in evp_test. 2017-02-28 09:14:50 -05:00
evptests.txt Add additional RSA-PSS and RSA-OAEP tests. 2017-03-15 00:04:44 +00:00
exdatatest.c Exdata test was never enabled. 2017-02-28 13:50:40 -05:00
exptest.c Change callers to use the new constants. 2016-08-10 10:07:37 -04:00
generate_buildtest.pl Move the building of test/buildtest_*. to be done unconditionally 2016-08-05 21:17:05 +02:00
generate_ssl_tests.pl Reorganize SSL test structures 2016-08-08 12:06:26 +02:00
gmdifftest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
handshake_helper.c Port SRP tests to the new test framework 2017-03-14 15:07:50 +01:00
handshake_helper.h Use the built in boolean type for CompressionExpected 2017-03-02 16:49:28 +00:00
hmactest.c Fix hmac test case 6 2016-06-30 08:52:37 -04:00
ideatest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
igetest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
md2test.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
mdc2_internal_test.c Add main() test methods to reduce test boilerplate. 2016-11-09 16:07:16 +01:00
mdc2test.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
memleaktest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
modes_internal_test.c Add main() test methods to reduce test boilerplate. 2016-11-09 16:07:16 +01:00
P1ss.cnf Use 2K RSA and SHA256 in tests 2015-04-20 07:23:04 -04:00
P2ss.cnf Use 2K RSA and SHA256 in tests 2015-04-20 07:23:04 -04:00
packettest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
pbelutest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
pkcs7-1.pem
pkcs7.pem
pkey_meth_test.c Add test to check EVP_PKEY method ordering. 2016-11-20 00:22:02 +00:00
pkits-test.pl Remove trailing whitespace from some files. 2016-10-10 23:36:21 +01:00
poly1305_internal_test.c Add main() test methods to reduce test boilerplate. 2016-11-09 16:07:16 +01:00
randtest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
rc2test.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
rc4test.c Revert rc4test removal, it performs additional tests not in evptests.txt 2017-02-28 16:08:42 +00:00
rc5test.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
README test/README: clarify last test number group 2017-02-17 20:58:04 +01:00
README.external Add Python Cryptography.io external test suite 2017-03-15 01:26:36 +01:00
README.ssltest.md Port SRP tests to the new test framework 2017-03-14 15:07:50 +01:00
recordlentest.c Fix no-comp 2017-03-08 11:03:37 +00:00
rsa_test.c Remove some obsolete/obscure internal define switches: 2017-03-01 10:44:49 +01:00
run_tests.pl Make it possible to select or deselect test groups by number 2017-03-10 00:54:57 +01:00
sanitytest.c Platform sanity test 2016-07-08 15:56:55 -04:00
secmemtest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
serverinfo.pem
sha1test.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
sha256t.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
sha512t.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
shibboleth.pfx Add PKCS#12 UTF-8 interoperability test. 2016-08-22 13:52:51 +02:00
shlibloadtest.c Fix no-dso (shlibloadtest) 2016-11-10 10:12:00 +00:00
siphash_internal_test.c Add support for parameterized SipHash 2017-02-01 14:14:36 -05:00
smcont.txt test/smcont.txt: trigger assertion in bio_enc.c. 2016-07-31 17:03:17 +02:00
srptest.c Add SRP test vectors from RFC5054 2016-10-01 13:46:54 +01:00
ssl_test.c Use the built in boolean type for CompressionExpected 2017-03-02 16:49:28 +00:00
ssl_test.tmpl test/ssl_test.tmpl: make it work with elderly perl. 2016-08-16 12:43:44 +02:00
ssl_test_ctx.c Port SRP tests to the new test framework 2017-03-14 15:07:50 +01:00
ssl_test_ctx.h Port SRP tests to the new test framework 2017-03-14 15:07:50 +01:00
ssl_test_ctx_test.c Use the built in boolean type for CompressionExpected 2017-03-02 16:49:28 +00:00
ssl_test_ctx_test.conf Add compression tests 2017-03-02 16:49:28 +00:00
sslapitest.c Update early data API for writing to unauthenticated clients 2017-03-02 17:44:16 +00:00
sslcorrupttest.c Let test handshakes stop on certain errors 2017-02-23 19:40:27 +01:00
ssltest_old.c Port SRP tests to the new test framework 2017-03-14 15:07:50 +01:00
ssltestlib.c Let test handshakes stop on certain errors 2017-02-23 19:40:27 +01:00
ssltestlib.h Let test handshakes stop on certain errors 2017-02-23 19:40:27 +01:00
Sssdsa.cnf
Sssrsa.cnf
stack_test.c Unit tests for crypto/stack. 2017-03-15 14:15:08 +01:00
test.cnf Use 2K RSA and SHA256 in tests 2015-04-20 07:23:04 -04:00
test_main.c Add main() test methods to reduce test boilerplate. 2016-11-09 16:07:16 +01:00
test_main.h Add main() test methods to reduce test boilerplate. 2016-11-09 16:07:16 +01:00
test_main_custom.c Add main() test methods to reduce test boilerplate. 2016-11-09 16:07:16 +01:00
test_main_custom.h Add main() test methods to reduce test boilerplate. 2016-11-09 16:07:16 +01:00
testcrl.pem
testdsa.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testdsapub.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testec-p256.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testecpub-p256.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testp7.pem
testreq2.pem
testrsa.pem
testrsapub.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testsid.pem Remove SSLv2 support 2014-12-04 11:55:03 +01:00
testutil.c Add main() test methods to reduce test boilerplate. 2016-11-09 16:07:16 +01:00
testutil.h Add -Wundef to --strict-warnings options. 2017-02-24 09:21:59 +01:00
testx509.pem
threadstest.c include/openssl: don't include <windows.h> in public headers. 2016-07-08 11:49:44 +02:00
tls13encryptiontest.c Fix crash in tls13_enc 2017-02-08 11:41:45 +00:00
tls13secretstest.c Implement the early data changes required in tls13_change_cipher_state() 2017-03-02 17:44:15 +00:00
uitest.c UI: fix uitest for VMS 2017-01-12 15:23:15 +01:00
Uss.cnf Create DSA and ECDSA certificates. 2015-09-02 21:22:44 +01:00
v3-cert1.pem
v3-cert2.pem
v3ext.c Add some accessor API's 2016-06-08 11:37:06 -04:00
v3nametest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
verify_extra_test.c Fix some extra or missing whitespaces... 2017-01-25 09:06:34 +00:00
wpackettest.c Add a test for WPACKET_fill_lengths() 2017-01-30 10:18:24 +00:00
x509_internal_test.c Add main() test methods to reduce test boilerplate. 2016-11-09 16:07:16 +01:00
x509_time_test.c X509 time: tighten validation per RFC 5280 2017-02-24 17:37:08 +01:00
x509aux.c test/x509aux.c: Fix argv loop 2016-09-21 16:19:22 +02:00

How to add recipes
==================

For any test that you want to perform, you write a script located in
test/recipes/, named {nn}-test_{name}.t, where {nn} is a two digit number and
{name} is a unique name of your choice.

Please note that if a test involves a new testing executable, you will need to
do some additions in test/Makefile.  More on this later.


Naming conventions
=================

A test executable is named test/{name}test.c

A test recipe is named test/recipes/{nn}-test_{name}.t, where {nn} is a two
digit number and {name} is a unique name of your choice.

The number {nn} is (somewhat loosely) grouped as follows:

00-04  sanity, internal and essential API tests
05-09  individual symmetric cipher algorithms
10-14  math (bignum)
15-19  individual asymmetric cipher algorithms
20-24  openssl commands (some otherwise not tested)
25-29  certificate forms, generation and verification
30-35  engine and evp
60-79  APIs
   70  PACKET layer
80-89  "larger" protocols (CA, CMS, OCSP, SSL, TSA)
90-98  misc
99     most time consuming tests [such as test_fuzz]


A recipe that just runs a test executable
=========================================

A script that just runs a program looks like this:

    #! /usr/bin/perl
    
    use OpenSSL::Test::Simple;
    
    simple_test("test_{name}", "{name}test", "{name}");

{name} is the unique name you have chosen for your test.

The second argument to `simple_test' is the test executable, and `simple_test'
expects it to be located in test/

For documentation on OpenSSL::Test::Simple, do
`perldoc test/testlib/OpenSSL/Test/Simple.pm'.


A recipe that runs a more complex test
======================================

For more complex tests, you will need to read up on Test::More and
OpenSSL::Test.  Test::More is normally preinstalled, do `man Test::More' for
documentation.  For OpenSSL::Test, do `perldoc test/testlib/OpenSSL/Test.pm'.

A script to start from could be this:

    #! /usr/bin/perl
    
    use strict;
    use warnings;
    use OpenSSL::Test;
    
    setup("test_{name}");
    
    plan tests => 2;                # The number of tests being performed
    
    ok(test1, "test1");
    ok(test2, "test1");
    
    sub test1
    {
        # test feature 1
    }
    
    sub test2
    {
        # test feature 2
    }
    

Changes to test/Makefile
========================

Whenever a new test involves a new test executable you need to do the
following (at all times, replace {NAME} and {name} with the name of your
test):

* among the variables for test executables at the beginning, add a line like
  this:

    {NAME}TEST= {name}test

* add `$({NAME}TEST)$(EXE_EXT)' to the assignment of EXE:

* add `$({NAME}TEST).o' to the assignment of OBJ:

* add `$({NAME}TEST).c' to the assignment of SRC:

* add the following lines for building the executable:

    $({NAME}TEST)$(EXE_EXT): $({NAME}TEST).o $(DLIBCRYPTO)
           @target=$({NAME}TEST); $(BUILD_CMD)