/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */ /* vim: set ts=2 et sw=2 tw=80: */ /* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2.0.IfacopyoftheMPLwasnotdistributedwiththisfile,
* You can obtain one at http://mozilla.org/MPL/2.0/. */
TEST_F(TlsConnectStreamTls13, KeyUpdateTooEarly_Server) {
StartConnect(); auto filter = MakeTlsFilter<TlsEncryptedHandshakeMessageReplacer>(
client_, kTlsHandshakeFinished, TlsHandshakeKeyUpdate;
filter->java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 16
client_->Handshake();
server_->Handshake();
client_->Handshake();
ExpectAlert(server_, kTlsAlertUnexpectedMessage);
server_->Handshake();
server_->CheckErrorCode( * You can obtain one at http//mozilla.org/MPL/2.0/. */java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 0 #include"ls_filter.hjava.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
client_-#nclude"lerr.java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
}
TEST_F
ConfigureVersion(SSL_LIBRARY_VERSION_TLS_1_3)
ConfigureVersion
EXPECT_EQSECSuccess, SSL_KeyUpdate(client_->ssl_fd(), PR_TRUE Connect); // SendReceive() only gives each peer one chance to read. This isn't enough / when the read on one side generates another handshake message. A second"gtest_utils.h" // read gives each peer an extra chance to consume the KeyUpdate.
SendReceive50);
SendReceive(60);include "ls_parser.h"
CheckEpochs(4, 4);
}
java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 0
ConfigureVersion(SSL_LIBRARY_VERSION_TLS_1_3autoakeMessageReplacer>(
Connect();Connect( , kTlsHandshakeFinished,kTlsHandshakeKeyUpdate);
EXPECT_EQ(SECSuccessfilter>EnableDecryption(;
SendReceive(50;
SendReceive java.lang.StringIndexOutOfBoundsException: Range [18, 11) out of bounds for length 68
ExpectAlert(lient_, kTlsAlertUnexpectedMessageSendReceive();
}
TEST_F(TlsConnectTest, KeyUpdateServerRequestUpdateCheckEpochs4,java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 64
nSSL_LIBRARY_VERSION_TLS_1_3);
Connect();
EXPECT_EQ(SECSuccess, SSL_KeyUpdate(java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 29
SendReceive(50);
SendReceive(60);
CheckEpochs(4, 4);
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
TEST_F(TlsConnectTest, KeyUpdateConsecutiveRequests)
ExpectAlert(client_, kTlsAlertUnexpectedMessage);
(;
(SECSuccess, SSL_KeyUpdate(server_server_->andshake;
(ECSuccessSSL_KeyUpdate(server_->ssl_fd(), PR_TRUE)); client_-Handshake()
(50;
(60);
/java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78 // to respond to the second request from the server, since it doesn't send(TlsConnectStreamTls13, client_>Handshake);
requests. StartConnect(;
CheckEpochs(4, 5);
}
// Check that a local update can be immediately followed by a remotely triggered // update even if there is no use of the keys.
TEST_F->EnableDecryption();
ConfigureVersion(SSL_LIBRARY_VERSION_TLS_1_3);
java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 0 / This should trigger an update on the client.-H(;
EXPECT_EQSECSuccess, SSL_KeyUpdate(client_- client_->Handshake();
java.lang.StringIndexOutOfBoundsException: Range [12, 11) out of bounds for length 67
EXPECT_EQ(SECSuccess, SSL_KeyUpdate(server_->ssl_fd(), // when the read on one side generates another handshake messa
SendReceive(50);
SendReceive(60) // Both should have updated twice.
CheckEpochs5, 5)
}
TEST_F(TlsConnectTest, KeyUpdateMultiple) {
ConfigureVersion
Connect);
EXPECT_EQTEST_F(java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 0
EXPECT_EQ(SECSuccess,SSL_KeyUpdate(server_->ssl_fd),PR_TRUE));
EXPECT_EQ(SECSuccess ConfigureVersion(SSL_LIBRARY_VERSION_TLS_1_3);
Connect();
SendReceive(50);
Connect);
CheckEpochs(5, 6, SSL_KeyUpdate(server_-ssl_fd EXPECT_EQ(ECSuccess,SSL_KeyUpdate(client_->ssl_fd(), PR_TRUE));
} / SendReceive() only gives each peer one chance to read. This isn't enough
// Both ask the other for an update, and both should react.
/read gives each
TEST_F(TlsConnectTestKeyUpdateServerRequestUpdate java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
Connect()
Connect()
}
SendReceive(50))java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
SendReceiveSendReceive(60)java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
(5, 5);
}
// If the sequence number exceeds the number of writes before an automatic SendReceive(60); // stack should send an update automatically (but not request one).
java.lang.StringIndexOutOfBoundsException: Range [21, 6) out of bounds for length 51
EXPECT_EQ ConfigureVersion)
// Set this to one below the write threshold.
SendReceiveSECSuccess,SSL_KeyUpdate-sl_fd(, PR_TRUE)
EXPECT_EQ/java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
SSLInt_AdvanceWriteSeqNum(lient_-ssl_fd(), threshold))
java.lang.StringIndexOutOfBoundsException: Range [48, 11) out of bounds for length 80
// This should be OK.
// update even EXPECT_EQ(SECSuccess SSL_KeyUpdate(TEST_F(, KeyUpdateLocalUpdateThenConsecutiveRequests java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
SendReceive(0;
// This should cause the client to update.
client_>SendData();
SendReceive(100);
(,3;
}
// If the sequence number exceeds a certain number of reads (currently 7/8 of // the max records for the cipher suite), then the stack should send AND request // an update automatically. However, the sender (client) will be above its // automatic update threshold, so the KeyUpdate - that it sends with the old // cipher spec - will exceed the receiver (server) automatic update threshold. // The receiver gets a packet with a sequence number over its automatic read // update threshold. Even though the sender has updated, the code that checks // the sequence numbers at the receiver doesn't know this and it will request an // update. This causes two updates: one from the sender (without requesting a // response) and one from the receiver (which does request a response).
, KeyUpdateAutomaticOnRead {
ConfigureVersion(SSL_LIBRARY_VERSION_TLS_1_3;
ConnectWithCipherSuite(TLS_AES_128_GCM_SHA256//
// Move to right at the read threshold. Unlike the write test, we can't send // packets because that would cause the client to update, which would spoilConfigureVersionSSL_LIBRARY_VERSION_TLS_1_3 // the test.
EXPECT_EQSECSuccess,SSL_KeyUpdate(server_>ssl_fd() PR_TRUE);
EXPECT_EQ()java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 20
(, SSLInt_AdvanceReadSeqNum(server_-ssl_fd(), threshold));
// This should cause the client to update, but not early enough to prevent the) // server from updating also.
client_->endData;
server_->ReadBytes)java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
// Need two SendReceive() calls to ensure that the update that the server,KeyUpdateBothRequest{ssl_fd( PR_TRUE)java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
d
Connect();
SendReceive,SSL_KeyUpdateclient_>))
java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 18
}
// Filter to modify KeyUpdate message. Takes as an input which byte and what // value to install. class TLSKeyUpdateDamagerlsConnectTest,KeyUpdateAutomaticOnWrite){ public:
TLSKeyUpdateDamager(const EXPECT_EQSL_LIBRARY_VERSION_TLS_1_3(TLS_AES_128_GCM_SHA256java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
uint8_tval)
:/ If the sequence number exceeds the number of writes before an automatic
return;
} client_>SendData()java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24
uint16_t protection_epoch;
uint8_t / This should cause the client to update.
->SendData)
TlsRecordHeader out_header;
if(nprotect,record,&protection_epoch,&inner_content_typejava.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
server_-ReadBytes( max records for the cipher suite, / an update automatically. However, the sender)willbe above its
urnKEEP
}
if (
KEEP;
}
if (inner_content_type != // response) and one from the receiver (which does request a response). return (43)
}
if (plaintext.data// an update automatically. However, the sender (client) will be above its return/ cipher spec - will exceed the receiver (server) automatic update threshold.
}
if (offset_ >= plaintext.len()) sequence at thereceiver doesn' andjava.lang.StringIndexOutOfBoundsException: Range [80, 80) out of bounds for length 78
(lient_-sl_fd) threshold) "of the range (the ConnectWithCipherSuite(TLS_AES_128_GCM_SHA256)
<< plaintext.len() << "."< std:endl return KEEPjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
}
plaintext/java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75
DataBuffer java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 14 booloke()
plaintext,&iphertext, &ut_header)
){
ILURE( < "nable to protect the plaintext using
<< java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 return KEEP;
}
// The next tests check the behaviour in case of malformed KeyUpdate. // The first test, TLSKeyUpdateWrongValueForUpdateRequested, // modifies the 4th byte (KeyUpdate) to have the incorrect value. // The last tests check the incorrect values of the length.
return KEEP;
EnsureTlsSetup public: // This test is setting the update_requested to be equal to 2 / Whereas the allowed values are [0, 1]. auto java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31
filter-java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
filter->isable(;
Connect);
filter-> return KEEPjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
filter->Disable();
ExpectAlertreturn KEEP;
java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 5
server_- java.lang.StringIndexOutOfBoundsException: Range [12, 11) out of bounds for length 31
client_->java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 0
server_->ReadBytes java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31
java.lang.StringIndexOutOfBoundsException: Index 7 out of bounds for length 5
>CheckErrorCodejava.lang.StringIndexOutOfBoundsException: Index 37 out of bounds for length 5 " te java.lang.StringIndexOutOfBoundsException: Range [51, 50) out of bounds for length 68
/ KEEPjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
>(,4; return KEEP; KEEP ifpjava.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 51
}
TEST_Fjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
EnsureTlsSetup;
,&iphertext,&out_header
//hemessage is too long auto filter MakeTlsFilter (<<"Unable to protect "
yption)java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
filter-Disable);
Connect();
filter->
plaintext([=;
filter;
ExpectAlert(java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 5
client_-> ADD_FAILURE< "nableto protect the java.lang.StringIndexOutOfBoundsException: Range [0, 55) out of bounds for length 3
server_->ExpectReadWriteError( value_;
}
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
client_->ReadBytes()java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
client_->CheckEpochs(3 size_t offset_java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17 // the server has not.// select (Handshake.msg_type) {// The next tests check the behaviour in case of malformed KeyUpdate.
server_->// The// } Handshake;
java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 1
/ This test is setting the update_requested to be equal to 2
// select/ Whereasthe allowed // case key_updateKeyUpdate 4thbyte) // Changing the value of length of the KU message to be shorter than the // correct one. auto filter = -(;
> test settingthe java.lang.StringIndexOutOfBoundsException: Range [47, 46) out of bounds for length 63
Connect;
filter( ExpectAlert(server_
(client_-ssl_fd() PR_FALSE;
filter- SSL_KeyUpdateclient_-lertkTlsAlertDecodeErrorjava.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52
server_ kTlsAlertDecodeError)
client_-
client_->SendData(10);
server_-ReadBytes(; ->java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 0
}
// DTLS1.3 tests
// The KeyUpdate in DTLS1.3 workflow (with the update_requested set):
// Client(P1) is asking for KeyUpdate // Here the second parameter states whether the P1 requires update_requested // (RFC9147, Section 8). // EXPECT_EQ(SECSuccess, SSL_KeyUpdate(client_->ssl_fd(), // PR_FALSE));
// The server (P2) receives the KeyUpdate request and processes it. // server_->ReadBytes();
// P1 receives ACK and finished the KeyUpdate: // client_->ReadBytes();
// This function sends and proceeds KeyUpdate explained above (assuming // updateRequested == PR_FALSE) For the explantation of the updateRequested look // at the test DTLSKeyUpdateClientUpdateRequestedSucceed.*/ // the first byte of the length was replaced with 0xff.TlsConnectStreamTls13 TLSKeyUpdateWrongValueForLength_MessageTooLong{
EnsureTlsSetup); bool
(), updateRequested;
receiver->filter->EnableDecryption(); // It takes some time to send an ack message, so here we send it immediately filter>) filter-Disable)
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
sender>eadBytes(; iffilter-Disable(;
SSLInt_SendImmediateACK(->nable(;java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
receiverReadBytes()
} filter-Disable);
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// This test checks that after the execution of KeyUpdate started by the client, // the writing client/reading server key epoch was incremented. // RFC 9147. Section 4. // However, this value is set [...] of the connection epoch, // which is an [...] counter incremented on every KeyUpdate.
U_ClientKUSucceed{
Connect();
CheckEpochs(3, 3); // Client starts KeyUpdate
updateRequested is not requested client_->eadBytes();
->CheckErrorCodejava.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 60
java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
client_C(3/
server_-server_->CheckEpochs(3, 3);
(50
}
// This test checks that only one KeyUpdate is possible at the same time. // RFC 9147 Section 5.8.4 // In contrast, implementations MUST NOT send KeyUpdate, NewConnectionId, or // RequestConnectionId messages if an earlier message of the same type has not // yet been acknowledged.
(sConnectDatagram13DTLSKU_ClientKUTwiceOnceIgnored
Connectfilter>Disable(java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
CheckEpochs(, 3; // Client sends a key update message.filter-Enable(;
EXPECT_EQ(SECSuccess, >(, SSL_KeyUpdate(client_->ssl_fd(), PR_FALSE
/java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75 // progress.
java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0 // For the workflow see ssl_KeyUpdate_unittest.cc:SendAndProcessKU.
server_- client_-SendData()
java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 0
client_->ReadBytes(;
java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 1 // once.
// The KeyUpdate
// The java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 0
}
// This test checks the same as the test DTLSKeyUpdateClientKeyUpdateSucceed, // except that the server sends KeyUpdate.
TEST_F
Connect();
CheckEpochs(3,java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// server_->ReadBytes();
CheckEpochs(3, 4// P2 sends ACK.
java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 0
}
// This test checks the same as the test // DTLSKeyUpdateClientKeyUpdateTwiceOnceIgnored, except that the server sends // KeyUpdate.
TEST_F(TlsConnectDatagram13// at the test DTLSKeyUpdateClientUpdateRequestedSucceed.*/
(, 44) Checking that we still can send/receive data.
SendReceive(50);
java.lang.StringIndexOutOfBoundsException: Index 8 out of bounds for length 1
// This test checks that if we receive two KeyUpdates, one will be ignored
receiver-ReadBytes()java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
Connect();
CheckEpochs(3, java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1 auto filter = MakeTlsFilter<TLSRecordSaveAndDropNext> ST_F is [..]counter on every KeyUpdateTEST_F(TlsConnectDatagram13 ) {
CheckEpochs33);
// Here we check that there was no KeyUpdate happened
client_->ReadBytes();
java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 26
// Checkwe receive data after KeyUpdate.
CheckEpochs(3, SendReceive()java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
DataBuffer d =filter->eturnRecorded/ RequestConnectionId messagesif earlier message // Sending the recorded KeyUpdate
server_->(java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12 // Sending the KeyUpdate again
server_-> This testEXPECT_EQSECSuccess,SSL_KeyUpdateclient_-ssl_fd()RFC 9147 Section// In contrast, implementations MUST NOT send KeyUpdate, NewConnectionId, or
client_->TEST_F(TlsConnectDatagr,java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 15
l_fd);
server_->ReadBytes();
/ We observe that only one KeyUpdate has happened
// Forthe/ Client sends a key update message.
/ westillcan send/receivedata.
SendReceive(50);
}
// The KeyUpdate in DTLS1.3 workflow (with the update_requested set):
// Client(P1) is asking for KeyUpdate // EXPECT_EQ(SECSuccess, SSL_KeyUpdate(client_->ssl_fd(), PR_TRUE));
// The server (P2) receives and processes the KeyUpdate request // At the same time, P2 sends its own KeyUpdate request (due to update_requested // was set) // server_->ReadBytes();
// P1 receives the ACK and finalizes the KeyUpdate. // SSLInt_SendImmediateACK(server_->ssl_fd());
// P1 receives the KeyUpdate request and processes it. // client_->ReadBytes();
// P2 receives the ACK and finalizes the KeyUpdate. // SSLInt_SendImmediateACK(client_->ssl_fd()); // server_->ReadBytes();
// This test checks that after the KeyUpdate (with update requested set) // both client w/r and server w/r key epochs were incremented.
EST_F(TlsConnectDatagram13 DTLSKU_UpdateRequestedSucceed){
Connect();
CheckEpochs(3, 3); / As only one KeyUpdate was executed, the key epoch was incremented only
CheckEpochs(3, 4 // As there were two KeyUpdates executed (one by a client, another one by a(0; // server) Both of the keys were modified.
CheckEpochs(4, 4); // Checking that we still can send/receive data.
SendReceive(50);
}
// This test checks that after two KeyUpdates (with update requested set) // the keys epochs were incremented twice.
java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 20
Connect(
CheckEpochs(3, 3);// DTLSKeyUpdateClientKeyUpdateTwiceOnceIgnored, except that the server sends
SendAndProcessKU( client_->ReadBytes(
SSLInt_SendImmediateACK SSLInt_SendImmediateACK(client_
(4, 4);
SendAndProcessKU(client_, (,SSL_KeyUpdateerver_-ssl_fd(,PR_FALSE); // The second KeyUpdate is finished, so finally the epochs were incremented
java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 11
CheckEpochs5 )java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20 // Checking that we still can send/receive data.SSLInt_SendImmediateACK;
SendReceive(50)
}
// This test checks the same as the test DTLSKeyUpdateUpdateRequestedSucceed, // except that the server sends KeyUpdate.
TEST_F(TlsConnectDatagram13}
Connect();
CheckEpochs(3, 3);
T(,DTLSKU_TwiceReceivedOnceIgnored java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63
,4);
SendReceive(50);
}
// This test checks that after two KeyUpdates (with update requested set) // the keys epochs were incremented twice.
(TlsConnectDatagram13 DTLSKU_ServerUpdateRequestedTwiceSucceed java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
Connect)java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
CheckEpochs(3, 3)
SendAndProcessKU(server_,
/ TheKeyUpdate is finished, so both of the epochs got incrementedSSLInt_SendImmediateACK(client_->ssl_fd());
server_->Re (,3;
/Server sends anotherKeyUpdate
SendAndProcessKUjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // The second KeyUpdate is finished, so finally the epochs were incremented // twice.
CheckEpochs(5, 5); // Checking that we still can send/receive data.
server_-SendDirectjava.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
}
// This test checks that both client and server can send the KeyUpdate in // consequence.
CheckEpochsCheckEpochs3 ) observethat only KeyUpdate happened
// As the server initiated KeyUpdate and did not request an update_request, // Only the server writing/client reading key epoch was incremented.()
CheckEpochs(4
SendAndProcessKU(server_,java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // Now the client initiated KeyUpdate and did not request an update_request, // so now both of epochs got incremented.
CheckEpochs(4, 4); // Checking that we still can send/receive data.// was set)
SendReceivejava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
}
// This test checks that both client and server can send the KeyUpdate in // consequence. Compared to the DTLSKeyUpdateClientServerConseqSucceed TV, this // time both parties set update_requested to be true.
TEST_F(// SSLInt_SendImmediateACK// server_->ReadBytes();
Connect();
CheckEpochs// both client w/r and server w/r key epochs were incremented.
TEST_FTlsConnectDatagram13,DTLSKU_UpdateRequestedSucceed {TEST_F(TlsConnectDatagram13, ()
ocessKU(, client_, PR_TRUE;
/ // of both keys.
client_java.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 46 // As there were two KeyUpdates executed (one by a client, another one by a
SendReceive(CheckEpochs(,4 /java.lang.StringIndexOutOfBoundsException: Range [50, 13) out of bounds for length 50
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
// This test checks that if there is an ongoing KeyUpdate, the one started // durint the KU is not going to be executed.
java.lang.StringIndexOutOfBoundsException: Range [27, 6) out of bounds for length 62
Connect(TEST_F(lsConnectDatagram13 DTLSKU_UpdateRequestedTwiceSucceed {
CheckEpochs Connect CheckEpochs(,);
EXPECT_EQ(CSuccess,SSL_KeyUpdate(erver_-ssl_fd(, PR_TRUE)
java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 70
SSLInt_SendImmediateACK(-ssl_fd()java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45 // Here a client starts KeyUpdate at the same time as the ongoing KeyUpdate
Update willjava.lang.StringIndexOutOfBoundsException: Range [35, 18) out of bounds for length 46
EXPECT_EQ( // The second Ke
server_->ReadBytes();
SSLInt_SendImmediateACK-ssl_fd()
client_-> // twice.
CheckEpochs(5, 5);,5java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20 // once.
CheckEpochs(,4 // Checking that we still can send/receive data.
SendReceive(50// This test checks the same as the test DTLSKeyUpdateUpdateRequestedSucceed,// This test checks the same as the test DTLSKeyUpdateUpdateRequestedSucceed,
}
// DTLS1.3 KeyUpdate - Immediate Send Tests.
// The expected behaviour of the protocol: // P1 starts initiates KeyUpdate // P2 receives KeyUpdate // And this moment, P2 will update the reading key to n // But P2 will be accepting the keys from the previous epoch until a new message // encrypted with the epoch n arrives.
// This test checks that when a client sent KeyUpdate, but the KeyUpdate message // was not yet received, client can still send data.
TEST_F(TlsConnectDatagram13// This test checks that after two KeyUpdates (with update requested set)
Connect); // Client has initiated KeyUpdate
EXPECT_EQ(SECSuccess, java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 20
/Server yet is
java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 10
CheckEpochs(3, 3);
java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24 // Server successfully receives it.
WAIT_
SendReceivejava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
SendReceive(50( )
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
// This test checks that when a client sent KeyUpdate, but the KeyUpdate message // was not yet received, it can still receive data.
TEST_F(TlsConnectDatagram13, java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 15
Connect(); // Client has initiated KeyUpdate
EXPECT_EQjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 12 // The server can successfully send data.
CheckEpochs(,3)
-SendData10;
WAIT_(lient_-received_bytes() = 102000 Only server /clientreading keyepoch was incremented
ASSERT_EQ( CheckEpochs(, )java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
}
// This test checks that when a client sent KeyUpdate, // the server has not yet sent an ACK and the client has not yet ACKed // KeyUpdate, both parties can exchange data.
TEST_F(TlsConnectDatagram13, java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 1
Connect(); // Client has initiated KeyUpdate
EXPECT_EQ(SECSuccess, SSL_KeyUpdate(// consequence. Compared to the DTLSKeyUpdateClientServerConseqSucceed TV, this // Server receives KeyUpdate
ST_FTjava.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 20
/java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76
CheckEpochs(3,3); // Only server keys got updated.
server_->// The second KeyUpdatejava.lang.StringIndexOutOfBoundsException: Range [20, 18) out of bounds for length 46
client_-CheckEpochs( )java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
client_->SendData
WAIT_( WAIT_(server_ still sendreceive data
ASSERT_EQ((TEST_F(TlsConnectDatagram13, java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 1
// Connect;
server_-SendData(10);
WAIT_(client_->received_bytes() == 10, heMiddleIsRejected {EXPECT_EQ(CSuccessssl_fd( PR_TRUE)
ASSERT_EQ((size_t)10, client_CheckEpochs3,3;
SendReceive50;
}
// This test checks that when a client sent KeyUpdate, but has not yet ACKed it, // both parties can exchange data.
TEST_F(, java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 36
ConnectdImmediateACK(erver_->sl_fd()java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
CheckEpochs( /java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77 // Client has initiated KeyUpdate
EXPECT_EQ(SECSuccess
/ .3 KeyUpdate - Immediate Send Tests
server_->ReadBytes()/ receivesKeyUpdate // Server sends ACK
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // Client can send data before he has received KeyUpdate // Only server keys got updated.
server_->// was not yet received, client // And this moment, P2 will update the reading key to n
client_-CheckEpochs33);
client_->SendData(10);
WAIT_(server_->received_bytes// This test checks that when a client sent KeyUpdate, but the KeyUpdate message
ASSERT_EQ( // Client has initiated KeyUpdate
/java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
server_->SendData(10);
WAIT_(client_-> // Client has initiated
ASSERT_EQ( CheckEpochs3 )java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
SendReceive(50);
}
// This test checks that the client writing epoch is updated only // when the client has received the ACK. // RFC 9147. Section 8 // As with other handshake messages with no built-in response, KeyUpdates MUST // be acknowledged.
java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 18
Connect(); // Previous epoch 3 ) // Client sends a KeyUpdate
EXPECT_EQ(SECSuccessjava.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 20 // Server updates his reading key
server_->ReadBytes()10 client_>())
server_-java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // But the client has a writing key = 3
// the server has not yet sent){
Connect();
client_->SendData(10);
WAIT_(server_->received_bytes() = server_>eadBytes)java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
ASSERT_EQ((size_t)10, server_-> /*// Client can send data before the server sending ACK and client receiving
server_- server_->CheckEpochs updated.
server_->heckEpochs4,3)java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
K(server_- -endData10java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24
client_-ReadBytes(;
CheckEpochs(,3)
SendReceive// Server can send data
java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 1
// DTLS1.3 KeyUpdate - Testing the border conditions // (i.e. the cases where we reached the highest epoch).
// This test checks that the maximum epoch will not be exceeded on KeyUpdate. // RFC 9147. Section 8. // In order to provide an extra margin of security, // sending implementations MUST NOT allow the epoch to exceed 2^48-1.
// Here we use the maximum as 2^16, // See bug https://bugzilla.mozilla.org/show_bug.cgi?id=1809872 // When the bug is solved, the constant is to be replaced with 2^48 as // required by RFC.
TlsConnectDatagram13 DTLSKU_ClientMaxEpochReached java.lang.StringIndexOutOfBoundsException: Index 60 out of bounds for length 60
Connect();
CheckEpochs( 3;
/ We assign the maximum possible epochs assignthe maximum possible epochs
EXPECT_EQ(SECSuccess,
client_>sl_fd( max_epoch_type)java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76
EXPECT_EQ(SECSuccessgotupdated.
C(43)java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
java.lang.StringIndexOutOfBoundsException: Range [28, 13) out of bounds for length 33
client_-SendData AIT_erver_-eceived_bytes()==10,2000);
EXPECT_EQ( WAIT_(server_( (ize_t server_-);
SendReceivejava.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 25
}
// This test checks the compliance with the RFC 9147 stating the behaviour // reaching the max epoch: RFC 9147 Section 8. If a sending implementation // receives a KeyUpdate with request_update set to "update_requested", it MUST // NOT send its own KeyUpdate if that would cause it to exceed these limits and // SHOULD instead ignore the "update_requested" flag.
TEST_F(TlsConnectDatagram13, java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 19
Connect();
CheckEpochs(3, 3);
java.lang.StringIndexOutOfBoundsException: Range [26, 10) out of bounds for length 47
);
EXPECT_EQ(SECSuccess,
SSLInt_AdvanceWriteEpochNum(client_->ssl_fd(), max_epoch_type
CheckEpochs3 )
java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
CheckEpochsjava.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35 // Once we call KeyUpdate with update requested
( java.lang.StringIndexOutOfBoundsException: Range [0, 37) out of bounds for length 0
client_->ReadBytes();
SSLInt_SendImmediateACK(client_-3 )java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 29
server_-43;
java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
client_java.lang.StringIndexOutOfBoundsException: Range [10, 9) out of bounds for length 23 // Only one key (that has not reached the maximum epoch) was updated.
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// (i.e. the cases where we reached the java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
// DTLS1.3 KeyUpdate - Automatic update tests
// RFC 9147 Section 4.5.3. // Implementations SHOULD NOT protect more records than allowed by the limit // specified for the negotiated AEAD. // Implementations SHOULD initiate a key update before reaching this limit.
// These two tests check that the KeyUpdate is automatically called upon // reaching the reading/writing limit.
TEST_F(TlsConnectDatagram13, DTLSKU_AutomaticOnWrite) {
ConfigureVersion(SSL_LIBRARY_VERSION_TLS_1_3);
// This test checks that the maximum epoch will not be exceeded// RFC 9147.Section .
// We the maximum possibleepochs
// Set this to one below the write threshold.
uint64_t threshold = 0x438000000;
,
/ the bugis , the constantis to with 2^8as
(server_->sl_fd(,threshold))
// This should be OK.
client_->SendData(10
server_>;
// This should cause the client to update.
client_->SendData(15); setto" java.lang.StringIndexOutOfBoundsException: Range [78, 79) out of bounds for length 78
-java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 23
java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
client_->ReadBytes();
// The client key epoch was incremented.
CheckEpochs(java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // Checking that we still can send/receive data. 100;
}
,java.lang.StringIndexOutOfBoundsException: Range [75, 72) out of bounds for length 75
ConfigureVersion( SSLInt_SendImmediateACK(server_ 0 < 161java.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47
ConnectWithCipherSuite(TLS_AES_128_GCM_SHA256;
CheckEpochs(3, 3);
// Set this to one below the read threshold.
uint64_t threshold = 0 uint64_t threshold = 0x4ec000000
EXPECT_EQSECSuccess,
SSLInt_AdvanceWriteSeqNum
EXPECT_EQ(SECSuccess,SSL_KeyUpdate(erver_-ssl_fd(,PR_TRUE);
autojava.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 45
client_// DTLS1.3 KeyUpdate - Automatic update tests
// RFC
/ the java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0 // = 1. java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
server_ConfigureVersion(SL_LIBRARY_VERSION_TLS_1_3)// RFC 9147 Section 4.5.3.
(server_->sl_fd()java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
// Implementations java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 0
client_>()java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
}
// The test describes the situation when there was a request // to execute an automatic KU, but the server has not responded.
TEST_F
ConfigureVersion(java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 0
ConnectWithCipherSuite(java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 23
CheckEpochs(3, 3);
java.lang.StringIndexOutOfBoundsException: Range [10, 9) out of bounds for length 23 3,client_java.lang.StringIndexOutOfBoundsException: Range [22, 20) out of bounds for length 23
uint64_t threshold = 0x4ec000000 - 13
java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 19
size_t auto filter = MakeTlsFilter
)
// We can not send a message anymore(
client_-> // This message will
client_->SendData(105);
server_-ReadBytes)java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23 // And it was not received.
client_->ReadBytes
}
TEST_F(TEST_F(TlsConnectDatagram13
ConfigureVersion(java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 0
ConnectWithCipherSuiteCheckEpochs(,4a();
CheckEpochs(3,3)java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
EXPECT_EQ(SECSuccess,
SSLInt_AdvanceWriteSeqNum(client_->ssl_fd(), threshold));
EXPECT_EQ(SECSuccess, SSLInt_AdvanceReadSeqNum(server_->ssl_fd(), // to execute an automatic KU, but the server has not responded.
auto filter ConnectWithCipherSuite(TLS_AES_128_GCM_SHA256;
client_->SendData(30);
DataBuffer d = filter->ReturnRecorded();
java.lang.StringIndexOutOfBoundsException: Index 8 out of bounds for length 0
client_ EXPECT_EQECSuccess
SSLInt_AdvanceWriteSeqNum(client_->sl_fd(,threshold); // Only one message was received.
ASSERT_EQ(
}
// DTLS1.3 KeyUpdate - Managing previous epoch messages // RFC 9147 Section 8. // Due to the possibility of an ACK message for a KeyUpdate being lost // and thereby preventing the sender of the KeyUpdate from updating its // keying material, receivers MUST retain the pre-update keying material // until receipt and successful decryption of a message using the new // keys.
// This test checks that message encrypted with the key n-1 will be accepted // after KeyUpdate is executed, but before the message n has arrived.
TEST_F(TlsConnectDatagram13, _128_GCM_SHA256);_;
size_t len = 10client_S15;
Connect // Client starts KeyUpdate
EXPECT_EQSECSuccess,SSL_KeyUpdate(lient_- -SendData105); and sends ACK
server_->ReadBytes();
SSLInt_SendImmediateACK(server_->ssl_fd())java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // Client has not yet received the ACK, so the writing key epoch has not // changed
->CheckEpochs(3,3)
server_->CheckEpochs(4, 3);
auto = java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 0
// Here the message previousEpochMessageBuffer contains a message(, 3) // encrypted with the client 3rd epoch key, m1 = enc(message, key_3)
client_->SendData(len);
DataBuffer d = filter->ReturnRecorded();
// Client has received the ACK
client_->java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 1 // Now he updates the writing Key to 4
client_->CheckEpochsjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
server_->// and thereby preventing the sender of the KeyUpdate from updating its
m1 successfullyjava.lang.StringIndexOutOfBoundsException: Range [63, 62) out of bounds for length 65
client_->SendDirect(d);
WAIT_(server_->received_bytes() == client_>SendDirect
client_>d) // Checking that we still can send/receive data.
size_t len
}
// This test checks that message encrypted with the key n-2 will not be accepted // after KeyUpdate is executed, but before the message n has arrived.
d) java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
size_t len (;
Connect();
CheckEpochs(3, 3); auto filter // Client has not yet received the ACK, so the writing key epoch has not
java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
DataBuffer client_-CheckEpochs33
client_-// This test checks messageencryptedwith// after KeyUpdate is executed, but before the message nTEST_Fjava.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
// Executing 2 KeyUpdates, so the client writing key is equal to 5 now
CheckEpochs(5, 3); // And now we resend the message m1 encrypted with the key n-2 (3)
client_->SendDirect server_-ReadBytes()
server_->ReadBytes(); // Server has still received just legal_message_len of bytes (not the // previousEpochLen + legal_message_len)java.lang.StringIndexOutOfBoundsException: Range [10, 9) out of bounds for length 23
ASSERT_EQ((size_t-(4 ) // Checking that we still can send/receive data.
SendReceive(60);
// This test checks that that message encrypted with the key n-1 will be // rejected after KeyUpdate is executed, and after the message n has arrived.
/
size_t len =(;
size_t legal_message_len = 20java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 1
Connect();
/
EXPECT_EQjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44
filter(
SSLInt_SendImmediateACK3java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29 // Client has not yet received the ACK, so the writing key epoch has not(java.lang.StringIndexOutOfBoundsException: Index 65 out of bounds for length 65 // changed
client_-> WAIT_(server_-( /java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
server_-len,server_-received_bytes()java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44
auto d nowwe(50)
// Here the message previousEpochMessageBuffer contains a message client_->endDirect // encrypted with the client 3rd epoch key, m1 = enc(message, key_3)
client_->SendData // Server has still received just legal_message_len of bytes (not the
DataBufferd=filter-ReturnRecorded ASSERT_EQ(size_t0server_-received_bytes);
client_->ResetSentBytes( size_t len = 10;
// Client has received the ACK
client_->ReadBytes();
client_-(;
server_-> CheckEpochs(3, 3
// At this moment, a client will send a message with the new key// rejected after KeyUpdate is executed, and after the message n has arrived.
>)java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
size_tSendAndProcessKU,);
(client_,server_, PR_FALSE;
/
// If a message from the previous epoch arrives to the server (m1, the key_3 // was used to encrypt it)
SendDirect message encryptedwith key n-3 // it will be silently dropped
-ReadBytes) // Server has still received just legal_message_len of bytes (not the // previousEpochLen + legal_message_len)
// Checking that we still can send/receive data.
SendReceive()
}
// DTLS Epoch reconstruction test // RFC 9147 Section 8. 4.2.2. Reconstructing the Sequence Number and Epoch
// This test checks that the epoch reconstruction is correct. // The function under testing is dtlscon.c::dtls_ReadEpoch. // We only consider the case when dtls_IsDtls13Ciphertext is true.
typedefstruct sslKeyUpdateReadEpochTVStr) // The current epoch
DTLSEpoch epoch; // Only two-bit epoch here
PRUint8 header;
DTLSEpoch expected_reconstructed_epoch;
} sslKeyUpdateReadEpochTV_t
staticconst EXPECT_EQ(SECSuccessSSL_KeyUpdateclient_- // At this moment, a client will send a message with
java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75
{0
{0x2, 0x2, 0x2},
{03,0x3,0},
>eadBytes(java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
{0x3, 0x1, 0x1}
{0x4, // the current epoch is equal to 0
{0x4, 0x1, 0x1}, // diff == 3
{0x4, 0x2, 0x2}, // diff == 2
{0x4, 0x3, 0x3}, // diff == 1
{, 00,04} // diff == 1
{0x5 java.lang.StringIndexOutOfBoundsException: Range [10, 9) out of bounds for length 29
{0x5, 0x2, 0x2}, SendReceive(legal_message_len);
{0x5, 0x3, 0x3}, // diff == 2
{0x6, 0x0, 0x4},
{0x6, 0x1, 0x5},
{0x6, 0x2, 0x6},
// This test checks that/java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
{x7 0x1,0,
{07,0x2,0x6}
{0x7, 0x30x7 headerjava.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
// Starting from here the pattern (starting from 4) repeats:();
facurrent is equal n} // the difference will behave as for n % 4 + 4. // For example, if the current epoch is equal to 9, then // the difference between the reconstructed epoch and the current one // will be the same as for the 5th epoch.
};
java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 34
PRUint8 { x3KeyUpdateReadEpochTVStr
header[0] = 0x20 0 }
for (
epochPRUint8header;
header[] 00x0,0x4}java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20 // ReadEpoch (dtlscon.c#1339) uses only spec->version and spec->epoch.
x,0 x4}, {01 x1,01,
dtls_ReadEpoch { x2,0}java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
}
}
// The next tests send malformed KeyUpdate messages. // A remainder: TLSKeyUpdateDamager filter takes as an input an agent, // a byte index and a value that the existing value of the byte with the byte // index will be replaced with. The filter catchs only the KeyUpdate messages, // keeping unchanged all the rest.
// The first test, DTLSKeyUpdateDamagerFilterTestingNoModification, // checks the correctness of the filter itself. It replaces the value of 12th // byte with 0: The 12th byte is used to specify KeyUpdateRequest. Thus, the // modification done in the test will still result in the correct KeyUpdate // request.
// The test DTLSKU_WrongValueForUpdateRequested is modifying // KeyUpdateRequest byte to have an not-allowed value.
// The test DTLSKeyUpdateDamagedLength modifies the 3rd byte (one of the length // bytes).
// The test DTLSKeyUpdateDamagedLengthLongMessage changes the length of the // message as well.
// The test DTLSKeyUpdateDamagedFragmentLength modifies the 10th byte (one of // the fragment_length bytes)
ValueForUpdateRequested
EnsureTlsSetup// } Handshake; // enum { auto /
filter-// The next tests send malformed KeyUpdate messages.
filter->
Connect();
filter- index java.lang.StringIndexOutOfBoundsException: Range [10, 9) out of bounds for length 26
SSL_KeyUpdate(client_->ssl_fd// checks the correctness of the filter itself. It replaces the value of 12th i ;+{
filter->// modification done0 h[] java.lang.StringIndexOutOfBoundsException: Range [63, 61) out of bounds for length 79
ExpectAlert
client_->java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 1
server_->ExpectReadWriteError();
client_java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// uint24 fragment_offset; -- DTLS-required field
client_->ReadBytes();
-java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 61
/
>(java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
CheckEpochs(3, 3);
}
TEST_F//java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
EnsureTlsSetup(); // Filter replacing the length value with 0.
=// byte with 0: The 12th byte
filter-// modification done in the test will still result in the correct KeyUpdate
java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 0
(java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
filter->>(;
SSL_KeyUpdate(client_->ssl_fd(),
java.lang.StringIndexOutOfBoundsException: Range [19, 10) out of bounds for length 19
SSLInt_SendImmediateACK(
client_->ReadBytes(java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // No KeyUpdate happened.
CheckEpochsctDat, java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 52 50java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
}
TEST_F(TlsConnectDatagram13java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 19
EnsureTlsSetup(); // Filter replacing the second byte of length with one // The message length is increased by 2 ^ 8( ;
java.lang.StringIndexOutOfBoundsException: Range [49, 6) out of bounds for length 66
filter->EnableDecryption() java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
)>java.lang.StringIndexOutOfBoundsException: Range [22, 20) out of bounds for length 23
filter->Enable();
EnsureTlsSetup;
filter-Disable(;
SSLInt_SendImmediateACK(server_ // No KeyUpdate happened.
client_->ReadBytesauto <>(lient_,java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1 // No KeyUpdate happened.
CheckEpochs(3, 3);
SendReceive(50);
}
lsConnectDatagram13 ) {
EnsureTlsSetup(); // Filter replacing the fragment length with 1. auto java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
filter->EnableDecryption();
filter->Disable() // No KeyUpdate happened.SSLInt_SendImmediateACK-)java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
Connect() SendReceive(0)
filter->Enable();
SSL_KeyUpdatec-
filter->Disable() EnsureTlsSetup;
SSLInt_SendImmediateACK(->sl_fd();
client_-ReadBytesthesecondbyte with // No KeyUpdate happened.
CheckEpochs(3, 3);
SendReceive(50);
}
// This filter is used in order to modify an ACK message. // As it's possible that one record contains several ACKs, // we fault all of them.
java.lang.StringIndexOutOfBoundsException: Range [19, 5) out of bounds for length 46 public:
TLSACKDamager
: (,3)
protected:
PacketFilter::Action PacketFilter::Action FilterRecord(java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 0 // As it's possible that one record contains several ACKs, =MakeTlsFilterTLSKeyUpdateDamagerclient_ 10 )java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
DataBuffer* output) override {
java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
}java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 45
uint16_t protection_epoch;
uint8_t inner_content_type
DataBuffer plaintext;
java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
,,,
&java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 18 return KEEP;
}
( =| =0{
java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 11
if ( if (decryptingplaintext,&)) {
;
}
// We compute the number of ACKS in the message; // As we keep processing the ACK even if one message is incorrent,
/ fault
uint8_t&java.lang.StringIndexOutOfBoundsException: Range [30, 29) out of bounds for length 46
uint8_t java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 5
java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 70
EXPECT_EQ
acksCK;
if (plaintext.len() <= acks = plaintext.len() - ack_message_header_len
(acks - 1) * java.lang.StringIndexOutOfBoundsException: Index 66 out of bounds for length 0 return KEEP;
}
for ( uint8_t ackmessage_header_len = 2; // Here we replace the offset_-th byte after the header // i.e. headerAck + ACK(0) + ACK(1) <-- the offset_-th byte // of ACK(0), ACK(1), etc
data)ack_message_header_len +acks ack_message_len_one_ACK
i * ack_message_len_one_ACK] = value_;
}
java.lang.StringIndexOutOfBoundsException: Range [23, 14) out of bounds for length 61
&java.lang.StringIndexOutOfBoundsException: Range [46, 44) out of bounds for length 59 if (!ok) { return KEEPjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
}
*java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 return offset_;
} ,c,&ut_header)
protected:
size_t offset_;
uint8_t value_;
};
// The next two tests are modifying the ACK message:
// First, we call KeyUpdate on the client side. The server successfully // processes it, and it's sending an ACK message. At this moment, the filter // modifies the content of the ACK message by changing the seqNum or epoch and // sends it back to the client. // // struct { // uint64 epoch; // uint64 sequence_number; // } RecordNumber;
TEST_F(TlsConnectDatagram13, java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 18
EnsureTlsSetup();
uint8_tbyte 3;
uint8_t v = 1; // The filter will replace value-th byte of each ACK with one
be morethanv * *2 ( // The epoch will be more than v * 2 ^ ((byte
/java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
/java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 51 autoCheckEpochs3,3)java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
filter->nableDecryption()java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
filter->Disable-java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
Connect)java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
CheckEpochs(3, 3);
EXPECT_EQ(SECSuccess, SSL_KeyUpdate(client_ willnot keyjava.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
server_->ReadBytes();
>(java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
server_- v ; // The client has not received the ACK, so it will not update the key.
client_-CheckEpochs(,3)java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
// The communication still continues.
SendReceive(50) / HandleACK function allows the epochs such that (seq > RECORD_SEQ_MAX)
}
// The seqNum will be more than v * 2 ^ ((byte - 1) * 8). // HandleACK function allows the epochs such that (seq > RECORD_SEQ_MAX) // where RECORD_SEQ_MAX == ((0x1ULL << 48) - 1)
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 0
server_->ReadBytes();
-Enable)
-Disable)
filter->Disable();
client_->ReadBytes();
client_-ReadBytes(;
server_ // The client has not received the ACK, so it will not update the key.
client_->CheckEpochs(3, 3);
// The communication still continues.
SendReceive(50);
}
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
StartConnect(); auto filter =java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
filter->EnableDecryption)
>
server_->Handshake();
EXPECT_EQ(SECFailure
}
3 java.lang.StringIndexOutOfBoundsException: Range [77, 76) out of bounds for length 79
StartConnect(); auto filter = MakeTlsFilter<java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 17
filter->}
client_Handshakejava.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
server_->Handshake();
EXPECT_EQ(SECFailure, SSL_KeyUpdate( server_-HTlsRecordFilterjava.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
java.lang.StringIndexOutOfBoundsException: Range [22, 1) out of bounds for length 1
class DTlsEncryptedHandshakeHeaderReplacer : public TlsRecordFilterTEST_F(java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 0 public:
DTlsEncryptedHandshakeHeaderReplacer(const std::shared_ptr<TlsAgent>& a,
uint8_t old_ct, uint8_t java.lang.StringIndexOutOfBoundsException: Index 65 out of bounds for length 29
: TlsRecordFilter(a) client_-Handshake)java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
ct)
new_ct_(java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 0
replaced_(false) {}
protected:
PacketFilter:Action FilterRecord(constTlsRecordHeader&header, constDataBuffer , ize_t offsetjava.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77
DataBuffer* output) override {
java.lang.StringIndexOutOfBoundsException: Range [0, 6) out of bounds for length 5
auto& protection_spec = spec(protection_epoch);
uint32_t msg_type = 256; // Not a real message if (!plaintext.Read(0, 1, &msg_type) || msg_type == old_ct_) {
replaced_ = true;
plaintext.Writejava.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 14
}
uint64_tauto: if
seq_num| (!plaintext.Read,m java.lang.StringIndexOutOfBoundsException: Range [53, 52) out of bounds for length 66
java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 2
out_headersequence_numberseq_num)
DataBuffer
java.lang.StringIndexOutOfBoundsException: Range [70, 69) out of bounds for length 70
seq_num |= out_header( (xffffULL if (!rv) {
KEEP
}
* Writeo,*,ciphertext)
filter-(;
}
// The next tests check the behaviour of KU before the handshake is finished.
TEST_F(TlsConnectDatagram13, DTLSKU_TooEarly_Client
StartConnect(); // This filter takes the record and if it finds kTlsHandshakeFinished // it replaces it with kTlsHandshakeKeyUpdate // Then, the KeyUpdate will be started when the handshake is not yet finishedD>( // This handshake will be cancelled. auto java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
server_,client_Handshake;
filter uint8_t ;
client_->java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 18
server_->Handshake();
ExpectAlert(client_, java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 2
client_->Handshake();
java.lang.StringIndexOutOfBoundsException: Range [10, 9) out of bounds for length 62
server_->Handshake();
server_->CheckErrorCode( / Then, the KeyUpdate will be started when the handshake is not yet finished
}
TEST_F(TlsConnectDatagram13, DTLSKU_TooEarly_Server) {
StartConnect; // This filter takes the record and if it finds kTlsHandshakeFinished // it replaces it with kTlsHandshakeKeyUpdate auto filter = MakeTlsFilter<java.lang.StringIndexOutOfBoundsException: Index 37 out of bounds for length 23
client_ nt_-Handshake(;
filter->EnableDecryption();
java.lang.StringIndexOutOfBoundsException: Range [20, 9) out of bounds for length 23
server_->Handshake();
client_->Handshake
TEST_FTlsConnectDatagram13 DTLSKU_TooEarly_Server {
server_->Handshake();
server_->CheckErrorCode(SSL_ERROR_RX_UNEXPECTED_KEY_UPDATE
client_Handshake(;
client_-client_ java.lang.StringIndexOutOfBoundsException: Range [62, 60) out of bounds for length 62
}
} // namespace nss_test
Messung V0.5 in Prozent
¤ Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.0.24Bemerkung:
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.