openssl/test
Matt Caswell bd990e2535 Don't allow fragmented alerts
An alert message is 2 bytes long. In theory it is permissible in SSLv3 -
TLSv1.2 to fragment such alerts across multiple records (some of which
could be empty). In practice it make no sense to send an empty alert
record, or to fragment one. TLSv1.3 prohibts this altogether and other
libraries (BoringSSL, NSS) do not support this at all. Supporting it adds
significant complexity to the record layer, and its removal is unlikely
to cause inter-operability issues.

The DTLS code for this never worked anyway and it is not supported at a
protocol level for DTLS. Similarly fragmented DTLS handshake records only
work at a protocol level where at least the handshake message header
exists within the record. DTLS code existed for trying to handle fragmented
handshake records smaller than this size. This code didn't work either so
has also been removed.

Reviewed-by: Rich Salz <rsalz@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/3476)
2017-05-17 10:40:04 +01:00
..
certs Add certificates with PSS signatures 2017-04-25 22:12:34 +01:00
ct Verify SCT signatures 2016-03-01 11:59:28 -05:00
d2i-tests add test for CVE-2016-7053 2016-11-10 13:04:11 +00:00
ocsp-tests Fix OCSP checking. 2012-12-07 18:47:47 +00:00
ossl_shim More typo fixes 2017-03-29 07:14:29 +02:00
recipes Don't allow fragmented alerts 2017-05-17 10:40:04 +01:00
smime-certs spelling fixes, just comments and readme. 2016-08-05 19:07:30 -04:00
ssl-tests TLS1.3 Padding 2017-05-02 09:44:43 +01:00
testlib Add a test for supported_groups in the EE message 2017-05-08 11:09:02 +01:00
testutil Randomise the ordering of the C unit tests. 2017-05-15 14:47:51 +02:00
aborttest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
afalgtest.c [squash]Build works with/out NO_ENGINE and NO_AFALG 2017-04-16 21:57:22 -04:00
asn1_encode_test.c test/asn1_encode_test.c: test "next negative minimum" corner case. 2017-04-30 15:18:47 +02:00
asn1_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
asynciotest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
asynctest.c asynctest: don't depend on apps 2017-03-28 14:40:25 +02:00
bad_dtls_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
bftest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
bio_enc_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
bioprinttest.c Randomise the ordering of the C unit tests. 2017-05-15 14:47:51 +02:00
bnexp.txt Use BIO not FILE for test file 2017-05-15 20:39:15 -04:00
bnmod.txt Use BIO not FILE for test file 2017-05-15 20:39:15 -04:00
bnmul.txt Use BIO not FILE for test file 2017-05-15 20:39:15 -04:00
bnshift.txt Use BIO not FILE for test file 2017-05-15 20:39:15 -04:00
bnsum.txt Use BIO not FILE for test file 2017-05-15 20:39:15 -04:00
bntest.c Use BIO not FILE for test file 2017-05-15 20:39:15 -04:00
bntests.pl Make bntest be (mostly) file-based. 2016-11-28 12:26:05 -05:00
build.info Convert shlibloadtest to new framework 2017-05-12 14:30:08 -04:00
CAss.cnf RT3809: basicConstraints is critical 2016-06-13 09:18:22 -04:00
CAssdh.cnf Import of old SSLeay release: SSLeay 0.9.0b 1998-12-21 10:56:39 +00:00
CAssdsa.cnf Import of old SSLeay release: SSLeay 0.9.0b 1998-12-21 10:56:39 +00:00
CAssrsa.cnf Import of old SSLeay release: SSLeay 0.9.0b 1998-12-21 10:56:39 +00:00
casttest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
CAtsa.cnf Added support for ESSCertIDv2 2017-05-03 09:04:23 +02:00
chacha_internal_test.c Address some -Wold-style-declaration warnings 2017-05-01 14:23:28 -04:00
cipher_overhead_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
cipherbytes_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
cipherlist_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
clienthellotest.c Fix a pedantic gcc-7 warning. 2017-04-28 15:04:08 +02:00
cms-examples.pl Copyright consolidation: perl files 2016-04-20 09:45:40 -04:00
constant_time_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
crltest.c Refactor crltest.c to separate the test cases into individual functions. 2017-04-28 16:03:35 +02:00
ct_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
d2i_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
danetest.c Convert danetest, ssl_test_ctx_test 2017-05-02 08:32:26 -04:00
danetest.in Perform DANE-EE(3) name checks by default 2016-07-12 10:16:34 -04:00
danetest.pem DANE support for X509_verify_cert() 2016-01-07 13:48:59 -05:00
destest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
dhtest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
dsatest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
dtls_mtu_test.c Convert dtls_mtu_test, dtlsv1listentest 2017-04-26 12:20:44 -04:00
dtlstest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
dtlsv1listentest.c Convert dtls_mtu_test, dtlsv1listentest 2017-04-26 12:20:44 -04:00
ecdsatest.c Add BN support to the test infrastructure. 2017-05-09 21:30:29 +02:00
ectest.c Add BN support to the test infrastructure. 2017-05-09 21:30:29 +02:00
enginetest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
evp_extra_test.c Fix no-ec 2017-04-26 17:12:23 +01:00
evp_test.c Add "Title" directive to evp_test 2017-05-12 14:20:01 -04:00
evpciph.txt Add "Title" directive to evp_test 2017-05-12 14:20:01 -04:00
evpdigest.txt Add "Title" directive to evp_test 2017-05-12 14:20:01 -04:00
evpencod.txt Add "Title" directive to evp_test 2017-05-12 14:20:01 -04:00
evpkdf.txt Add "Title" directive to evp_test 2017-05-12 14:20:01 -04:00
evpmac.txt Add "Title" directive to evp_test 2017-05-12 14:20:01 -04:00
evppbe.txt Add "Title" directive to evp_test 2017-05-12 14:20:01 -04:00
evppkey.txt Add "Title" directive to evp_test 2017-05-12 14:20:01 -04:00
exdatatest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
exptest.c Add BN support to the test infrastructure. 2017-05-09 21:30:29 +02:00
generate_buildtest.pl Move the building of test/buildtest_*. to be done unconditionally 2016-08-05 21:17:05 +02:00
generate_ssl_tests.pl Reorganize SSL test structures 2016-08-08 12:06:26 +02:00
gmdifftest.c TAPify testutil 2017-04-25 15:43:04 +02:00
handshake_helper.c Address review feedback for the SCTP changes 2017-04-25 11:13:39 +01:00
handshake_helper.h Add ExpectedServerCANames 2017-04-03 23:47:22 +01:00
hmactest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
ideatest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
igetest.c Fix an uninit read in igetest 2017-05-04 15:43:25 +01:00
lhash_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
md2test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
mdc2_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
mdc2test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
memleaktest.c Update secmemtest and memeleaktest to use the test infrastructure. 2017-04-12 10:59:53 +01:00
modes_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
P1ss.cnf Use 2K RSA and SHA256 in tests 2015-04-20 07:23:04 -04:00
P2ss.cnf Use 2K RSA and SHA256 in tests 2015-04-20 07:23:04 -04:00
packettest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
pbelutest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
pemtest.c Add unit test for PEM_FLAG_ONLY_B64 2017-05-08 21:20:32 +02:00
pkcs7-1.pem
pkcs7.pem
pkey_meth_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
pkits-test.pl Remove trailing whitespace from some files. 2016-10-10 23:36:21 +01:00
poly1305_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
randtest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
rc2test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
rc4test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
rc5test.c Fix tests of TEST tests, as it were 2017-05-04 12:08:48 -04:00
README Refactor the test framework testutil 2017-04-24 18:09:01 +02:00
README.external Fix formatting of PYCA external test instructions 2017-04-18 19:10:25 +02:00
README.ssltest.md Add ExpectedServerCANames 2017-04-03 23:47:22 +01:00
recordlentest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
rsa_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
run_tests.pl Prefer TAP::Harness over Test::Harness 2017-05-10 12:58:36 +02:00
sanitytest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
secmemtest.c Fix infinite loops in secure memory allocation. 2017-05-11 22:35:21 +02:00
serverinfo.pem Require ServerInfo PEMs to be named "BEGIN SERVERINFO FOR"... 2013-09-13 19:32:55 -07:00
serverinfo2.pem Add a SERVERINFOV2 format test file 2017-05-03 14:37:42 +01:00
session.pem Add tests for the padding extension 2017-03-16 15:37:41 +00:00
sha1test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
sha256t.c Adapt all test programs 2017-04-24 18:09:01 +02:00
sha512t.c Adapt all test programs 2017-04-24 18:09:01 +02:00
shibboleth.pfx Add PKCS#12 UTF-8 interoperability test. 2016-08-22 13:52:51 +02:00
shlibloadtest.c Review feedback; use single main, #ifdef ADD_TEST 2017-05-12 14:30:08 -04:00
siphash_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
smcont.txt test/smcont.txt: trigger assertion in bio_enc.c. 2016-07-31 17:03:17 +02:00
srptest.c Add BN support to the test infrastructure. 2017-05-09 21:30:29 +02:00
ssl_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
ssl_test.tmpl test/ssl_test.tmpl: make it work with elderly perl. 2016-08-16 12:43:44 +02:00
ssl_test_ctx.c Add support to test_ssl_new for testing with DTLS over SCTP 2017-04-25 11:13:39 +01:00
ssl_test_ctx.h Add support to test_ssl_new for testing with DTLS over SCTP 2017-04-25 11:13:39 +01:00
ssl_test_ctx_test.c Convert danetest, ssl_test_ctx_test 2017-05-02 08:32:26 -04:00
ssl_test_ctx_test.conf Add compression tests 2017-03-02 16:49:28 +00:00
sslapitest.c Fix gcc-7 warnings. 2017-05-11 19:39:38 +02:00
sslcorrupttest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
ssltest_old.c More typo fixes 2017-03-29 07:14:29 +02:00
ssltestlib.c Add a test for SNI in conjunction with custom extensions 2017-05-10 16:49:00 +01:00
ssltestlib.h Let test handshakes stop on certain errors 2017-02-23 19:40:27 +01:00
Sssdsa.cnf Import of old SSLeay release: SSLeay 0.9.0b 1998-12-21 10:56:39 +00:00
Sssrsa.cnf Import of old SSLeay release: SSLeay 0.9.0b 1998-12-21 10:56:39 +00:00
stack_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
test.cnf Use 2K RSA and SHA256 in tests 2015-04-20 07:23:04 -04:00
test_test.c Add test_test tests for bignums. 2017-05-09 21:30:29 +02:00
testcrl.pem
testdsa.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testdsapub.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testec-p256.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testecpub-p256.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testp7.pem Change PKCS#7 test data to take account of removal of 2000-08-25 01:29:41 +00:00
testreq2.pem
testrsa.pem
testrsapub.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testsid.pem Remove SSLv2 support 2014-12-04 11:55:03 +01:00
testutil.h testutil: add the possibility to set the current test title 2017-05-11 20:40:23 +02:00
testx509.pem
threadstest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
time_offset_test.c Fix time offset calculation. 2017-05-02 10:38:54 +02:00
tls13encryptiontest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
tls13secretstest.c Update tls13secretstest test vectors for TLSv1.3 draft-20 2017-05-03 17:23:02 +01:00
uitest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
Uss.cnf Create DSA and ECDSA certificates. 2015-09-02 21:22:44 +01:00
v3-cert1.pem
v3-cert2.pem
v3ext.c Adapt all test programs 2017-04-24 18:09:01 +02:00
v3nametest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
verify_extra_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
wpackettest.c Address some -Wold-style-declaration warnings 2017-05-01 14:23:28 -04:00
x509_dup_cert_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
x509_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
x509_time_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
x509aux.c Adapt all test programs 2017-04-24 18:09:01 +02:00

How to add recipes
==================

For any test that you want to perform, you write a script located in
test/recipes/, named {nn}-test_{name}.t, where {nn} is a two digit number and
{name} is a unique name of your choice.

Please note that if a test involves a new testing executable, you will need to
do some additions in test/Makefile.  More on this later.


Naming conventions
=================

A test executable is named test/{name}test.c

A test recipe is named test/recipes/{nn}-test_{name}.t, where {nn} is a two
digit number and {name} is a unique name of your choice.

The number {nn} is (somewhat loosely) grouped as follows:

00-04  sanity, internal and essential API tests
05-09  individual symmetric cipher algorithms
10-14  math (bignum)
15-19  individual asymmetric cipher algorithms
20-24  openssl commands (some otherwise not tested)
25-29  certificate forms, generation and verification
30-35  engine and evp
60-79  APIs
   70  PACKET layer
80-89  "larger" protocols (CA, CMS, OCSP, SSL, TSA)
90-98  misc
99     most time consuming tests [such as test_fuzz]


A recipe that just runs a test executable
=========================================

A script that just runs a program looks like this:

    #! /usr/bin/perl
    
    use OpenSSL::Test::Simple;
    
    simple_test("test_{name}", "{name}test", "{name}");

{name} is the unique name you have chosen for your test.

The second argument to `simple_test' is the test executable, and `simple_test'
expects it to be located in test/

For documentation on OpenSSL::Test::Simple, do
`perldoc test/testlib/OpenSSL/Test/Simple.pm'.


A recipe that runs a more complex test
======================================

For more complex tests, you will need to read up on Test::More and
OpenSSL::Test.  Test::More is normally preinstalled, do `man Test::More' for
documentation.  For OpenSSL::Test, do `perldoc test/testlib/OpenSSL/Test.pm'.

A script to start from could be this:

    #! /usr/bin/perl
    
    use strict;
    use warnings;
    use OpenSSL::Test;
    
    setup("test_{name}");
    
    plan tests => 2;                # The number of tests being performed
    
    ok(test1, "test1");
    ok(test2, "test1");
    
    sub test1
    {
        # test feature 1
    }
    
    sub test2
    {
        # test feature 2
    }
    

Changes to test/build.info
==========================

Whenever a new test involves a new test executable you need to do the
following (at all times, replace {NAME} and {name} with the name of your
test):

* add {name} to the list of programs under PROGRAMS_NO_INST

* create a three line description of how to build the test, you will have
to modify the include paths and source files if you don't want to use the
basic test framework:

    SOURCE[{name}]={name}.c
    INCLUDE[{name}]=.. ../include
    DEPEND[{name}]=../libcrypto libtestutil.a

Generic form of C test executables
==================================

    #include "testutil.h"

    static int my_test(void)
    {
        int testresult = 0;                 /* Assume the test will fail    */
        int observed;

        observed = function();              /* Call the code under test     */
        if (!TEST_int_equal(observed, 2))   /* Check the result is correct  */
            goto end;                       /* Exit on failure - optional   */

        testresult = 1;                     /* Mark the test case a success */
    end:
        cleanup();                          /* Any cleanup you require      */
        return testresult;
    }

    void register_tests(void)
    {
        ADD_TEST(my_test);                  /* Add each test separately     */
    }

You should use the TEST_xxx macros provided by testutil.h to test all failure
conditions.  These macros produce an error message in a standard format if the
condition is not met (and nothing if the condition is met).  Additional
information can be presented with the TEST_info macro that takes a printf
format string and arguments.  TEST_error is useful for complicated conditions,
it also takes a printf format string and argument.  In all cases the TEST_xxx
macros are guaranteed to evaluate their arguments exactly once.  This means
that expressions with side effects are allowed as parameters.  Thus,

    if (!TEST_ptr(ptr = OPENSSL_malloc(..)))

works fine and can be used in place of:

    ptr = OPENSSL_malloc(..);
    if (!TEST_ptr(ptr))

The former produces a more meaningful message on failure than the latter.