openssl/test
Matt Caswell 975922fd0c Add tests for version/ciphersuite sanity checks
The previous commits added sanity checks for where the max enabled protocol
version does not have any configured ciphersuites. We should check that we
fail in those circumstances.

Reviewed-by: Richard Levitte <levitte@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/3316)
2017-04-26 14:31:00 +01:00
..
certs Add certificates with PSS signatures 2017-04-25 22:12:34 +01:00
ct Verify SCT signatures 2016-03-01 11:59:28 -05:00
d2i-tests add test for CVE-2016-7053 2016-11-10 13:04:11 +00:00
ocsp-tests Fix OCSP checking. 2012-12-07 18:47:47 +00:00
ossl_shim More typo fixes 2017-03-29 07:14:29 +02:00
recipes Add a ciphersuite config sanity check for servers 2017-04-26 14:31:00 +01:00
smime-certs spelling fixes, just comments and readme. 2016-08-05 19:07:30 -04:00
ssl-tests Add tests for version/ciphersuite sanity checks 2017-04-26 14:31:00 +01:00
testlib TAPify testutil 2017-04-25 15:43:04 +02:00
testutil test: don't make it more complicated than necessary. 2017-04-25 23:26:51 +02:00
aborttest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
afalgtest.c [squash]Build works with/out NO_ENGINE and NO_AFALG 2017-04-16 21:57:22 -04:00
asn1_encode_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
asn1_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
asynciotest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
asynctest.c asynctest: don't depend on apps 2017-03-28 14:40:25 +02:00
bad_dtls_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
bftest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
bio_enc_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
bioprinttest.c test: don't make it more complicated than necessary. 2017-04-25 23:26:51 +02:00
bntest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
bntests.pl Make bntest be (mostly) file-based. 2016-11-28 12:26:05 -05:00
bntests.txt bntests.txt: add a couple of checks of possibly negative zero 2017-02-01 02:03:29 +01:00
build.info Add include path '..' for libtestutil 2017-04-25 18:59:50 +02:00
CAss.cnf RT3809: basicConstraints is critical 2016-06-13 09:18:22 -04:00
CAssdh.cnf
CAssdsa.cnf
CAssrsa.cnf
casttest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
CAtsa.cnf Use better defaults for TSA. 2015-11-20 13:40:53 +00:00
chacha_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
cipher_overhead_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
cipherbytes_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
cipherlist_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
clienthellotest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
cms-examples.pl Copyright consolidation: perl files 2016-04-20 09:45:40 -04:00
constant_time_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
crltest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
ct_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
d2i_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
danetest.c Fix some -Wshadow warnings 2017-03-14 11:44:31 -05:00
danetest.in Perform DANE-EE(3) name checks by default 2016-07-12 10:16:34 -04:00
danetest.pem DANE support for X509_verify_cert() 2016-01-07 13:48:59 -05:00
destest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
dhtest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
dsatest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
dtls_mtu_test.c Let test handshakes stop on certain errors 2017-02-23 19:40:27 +01:00
dtlstest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
dtlsv1listentest.c Correct some badly formated preprocessor lines 2017-04-25 15:44:48 +02:00
ecdsatest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
ectest.c Remove some obsolete/obscure internal define switches: 2017-03-01 10:44:49 +01:00
enginetest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
evp_extra_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
evp_test.c evp_test.c: Add PrivPubKeyPair tests 2017-04-25 21:00:48 -04:00
evptests.txt evp_test.c: Add PrivPubKeyPair tests 2017-04-25 21:00:48 -04:00
exdatatest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
exptest.c Change callers to use the new constants. 2016-08-10 10:07:37 -04:00
generate_buildtest.pl Move the building of test/buildtest_*. to be done unconditionally 2016-08-05 21:17:05 +02:00
generate_ssl_tests.pl Reorganize SSL test structures 2016-08-08 12:06:26 +02:00
gmdifftest.c TAPify testutil 2017-04-25 15:43:04 +02:00
handshake_helper.c Address review feedback for the SCTP changes 2017-04-25 11:13:39 +01:00
handshake_helper.h Add ExpectedServerCANames 2017-04-03 23:47:22 +01:00
hmactest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
ideatest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
igetest.c Copyright consolidation 02/10 2016-05-17 14:20:27 -04:00
lhash_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
md2test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
mdc2_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
mdc2test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
memleaktest.c Update secmemtest and memeleaktest to use the test infrastructure. 2017-04-12 10:59:53 +01:00
modes_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
P1ss.cnf Use 2K RSA and SHA256 in tests 2015-04-20 07:23:04 -04:00
P2ss.cnf Use 2K RSA and SHA256 in tests 2015-04-20 07:23:04 -04:00
packettest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
pbelutest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
pkcs7-1.pem
pkcs7.pem
pkey_meth_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
pkits-test.pl Remove trailing whitespace from some files. 2016-10-10 23:36:21 +01:00
poly1305_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
randtest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
rc2test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
rc4test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
rc5test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
README Refactor the test framework testutil 2017-04-24 18:09:01 +02:00
README.external Fix formatting of PYCA external test instructions 2017-04-18 19:10:25 +02:00
README.ssltest.md Add ExpectedServerCANames 2017-04-03 23:47:22 +01:00
recordlentest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
rsa_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
run_tests.pl Make it possible to select or deselect test groups by number 2017-03-10 00:54:57 +01:00
sanitytest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
secmemtest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
serverinfo.pem Require ServerInfo PEMs to be named "BEGIN SERVERINFO FOR"... 2013-09-13 19:32:55 -07:00
session.pem Add tests for the padding extension 2017-03-16 15:37:41 +00:00
sha1test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
sha256t.c Adapt all test programs 2017-04-24 18:09:01 +02:00
sha512t.c Adapt all test programs 2017-04-24 18:09:01 +02:00
shibboleth.pfx Add PKCS#12 UTF-8 interoperability test. 2016-08-22 13:52:51 +02:00
shlibloadtest.c Fix no-dso (shlibloadtest) 2016-11-10 10:12:00 +00:00
siphash_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
smcont.txt test/smcont.txt: trigger assertion in bio_enc.c. 2016-07-31 17:03:17 +02:00
srptest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
ssl_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
ssl_test.tmpl test/ssl_test.tmpl: make it work with elderly perl. 2016-08-16 12:43:44 +02:00
ssl_test_ctx.c Add support to test_ssl_new for testing with DTLS over SCTP 2017-04-25 11:13:39 +01:00
ssl_test_ctx.h Add support to test_ssl_new for testing with DTLS over SCTP 2017-04-25 11:13:39 +01:00
ssl_test_ctx_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
ssl_test_ctx_test.conf Add compression tests 2017-03-02 16:49:28 +00:00
sslapitest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
sslcorrupttest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
ssltest_old.c More typo fixes 2017-03-29 07:14:29 +02:00
ssltestlib.c Move PRIu64, OSSLzu to e_os.h 2017-03-28 08:43:48 -04:00
ssltestlib.h Let test handshakes stop on certain errors 2017-02-23 19:40:27 +01:00
Sssdsa.cnf
Sssrsa.cnf
stack_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
test.cnf Use 2K RSA and SHA256 in tests 2015-04-20 07:23:04 -04:00
test_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
testcrl.pem
testdsa.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testdsapub.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testec-p256.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testecpub-p256.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testp7.pem
testreq2.pem
testrsa.pem
testrsapub.pem Add private/public key conversion tests 2015-03-29 03:26:12 +01:00
testsid.pem Remove SSLv2 support 2014-12-04 11:55:03 +01:00
testutil.h TAPify testutil 2017-04-25 15:43:04 +02:00
testx509.pem
threadstest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
tls13encryptiontest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
tls13secretstest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
uitest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
Uss.cnf Create DSA and ECDSA certificates. 2015-09-02 21:22:44 +01:00
v3-cert1.pem
v3-cert2.pem
v3ext.c Adapt all test programs 2017-04-24 18:09:01 +02:00
v3nametest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
verify_extra_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
wpackettest.c Adapt all test programs 2017-04-24 18:09:01 +02:00
x509_dup_cert_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
x509_internal_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
x509_time_test.c Adapt all test programs 2017-04-24 18:09:01 +02:00
x509aux.c Adapt all test programs 2017-04-24 18:09:01 +02:00

How to add recipes
==================

For any test that you want to perform, you write a script located in
test/recipes/, named {nn}-test_{name}.t, where {nn} is a two digit number and
{name} is a unique name of your choice.

Please note that if a test involves a new testing executable, you will need to
do some additions in test/Makefile.  More on this later.


Naming conventions
=================

A test executable is named test/{name}test.c

A test recipe is named test/recipes/{nn}-test_{name}.t, where {nn} is a two
digit number and {name} is a unique name of your choice.

The number {nn} is (somewhat loosely) grouped as follows:

00-04  sanity, internal and essential API tests
05-09  individual symmetric cipher algorithms
10-14  math (bignum)
15-19  individual asymmetric cipher algorithms
20-24  openssl commands (some otherwise not tested)
25-29  certificate forms, generation and verification
30-35  engine and evp
60-79  APIs
   70  PACKET layer
80-89  "larger" protocols (CA, CMS, OCSP, SSL, TSA)
90-98  misc
99     most time consuming tests [such as test_fuzz]


A recipe that just runs a test executable
=========================================

A script that just runs a program looks like this:

    #! /usr/bin/perl
    
    use OpenSSL::Test::Simple;
    
    simple_test("test_{name}", "{name}test", "{name}");

{name} is the unique name you have chosen for your test.

The second argument to `simple_test' is the test executable, and `simple_test'
expects it to be located in test/

For documentation on OpenSSL::Test::Simple, do
`perldoc test/testlib/OpenSSL/Test/Simple.pm'.


A recipe that runs a more complex test
======================================

For more complex tests, you will need to read up on Test::More and
OpenSSL::Test.  Test::More is normally preinstalled, do `man Test::More' for
documentation.  For OpenSSL::Test, do `perldoc test/testlib/OpenSSL/Test.pm'.

A script to start from could be this:

    #! /usr/bin/perl
    
    use strict;
    use warnings;
    use OpenSSL::Test;
    
    setup("test_{name}");
    
    plan tests => 2;                # The number of tests being performed
    
    ok(test1, "test1");
    ok(test2, "test1");
    
    sub test1
    {
        # test feature 1
    }
    
    sub test2
    {
        # test feature 2
    }
    

Changes to test/build.info
==========================

Whenever a new test involves a new test executable you need to do the
following (at all times, replace {NAME} and {name} with the name of your
test):

* add {name} to the list of programs under PROGRAMS_NO_INST

* create a three line description of how to build the test, you will have
to modify the include paths and source files if you don't want to use the
basic test framework:

    SOURCE[{name}]={name}.c
    INCLUDE[{name}]=.. ../include
    DEPEND[{name}]=../libcrypto libtestutil.a

Generic form of C test executables
==================================

    #include "testutil.h"

    static int my_test(void)
    {
        int testresult = 0;                 /* Assume the test will fail    */
        int observed;

        observed = function();              /* Call the code under test     */
        if (!TEST_int_equal(observed, 2))   /* Check the result is correct  */
            goto end;                       /* Exit on failure - optional   */

        testresult = 1;                     /* Mark the test case a success */
    end:
        cleanup();                          /* Any cleanup you require      */
        return testresult;
    }

    void register_tests(void)
    {
        ADD_TEST(my_test);                  /* Add each test separately     */
    }

You should use the TEST_xxx macros provided by testutil.h to test all failure
conditions.  These macros produce an error message in a standard format if the
condition is not met (and nothing if the condition is met).  Additional
information can be presented with the TEST_info macro that takes a printf
format string and arguments.  TEST_error is useful for complicated conditions,
it also takes a printf format string and argument.  In all cases the TEST_xxx
macros are guaranteed to evaluate their arguments exactly once.  This means
that expressions with side effects are allowed as parameters.  Thus,

    if (!TEST_ptr(ptr = OPENSSL_malloc(..)))

works fine and can be used in place of:

    ptr = OPENSSL_malloc(..);
    if (!TEST_ptr(ptr))

The former produces a more meaningful message on failure than the latter.