/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */ ) /* vim: set ts=2 et sw=2 tw=80: */ /* This Source Code Form is subject to the terms of the Mozilla Public #java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 21
* You can obtain one at http://mozilla.org/MPL/2.0/. */
#include"secerr.#include "secerr.h.h
ijava.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 16 #"" #include java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
(java.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 67 // This is not something that should make you happy. #SendReceive(50)
}
#include java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24 #/
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 23 "
namespace java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 17
TEST_F(TlsConnectTestauto filter = MakeTlsFilter<TlsEncryptedHandsh
;
server_ java.lang.StringIndexOutOfBoundsException: Range [62, 60) out of bounds for length 62
cess,SSL_KeyUpdate-(, PR_FALSE)
c); 60java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18 43);
}
TEST_F(TlsConnectStreamTls13, KeyUpdateTooEarly_Client-Handshake)
server_CheckErrorCodeSSL_ERROR_HANDSHAKE_UNEXPECTED_ALERT;
<>(
StartConnect(java.lang.StringIndexOutOfBoundsException: Range [48, 46) out of bounds for length 48
filter=<java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 18
nt_>(;
server_-java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
client_;
Connect)
EXPECT_EQserver_>)
EXPECT_EQS, java.lang.StringIndexOutOfBoundsException: Range [38, 37) out of bounds for length 67
server_ java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 18
TEST_F,(java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 23
)
java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 20
client_, // update even if there is no use
java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 29
client_->Handshake()/
server_>andshakejava.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
java.lang.StringIndexOutOfBoundsException: Range [10, 9) out of bounds for length 23
EXPECT_EQSECSuccess SSL_KeyUpdate(erver_-(, // when the read on one side generates another handshake message. A second
SendReceive60; // Cumulative count.(, )
java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
TEST_F(TlsConnectTest, KeyUpdateClientRequestUpdatejava.lang.StringIndexOutOfBoundsException: Range [12, 11) out of bounds for length 67
java.lang.StringIndexOutOfBoundsException: Range [48, 46) out of bounds for length 48
()java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
ECSuccess java.lang.StringIndexOutOfBoundsException: Range [38, 37) out of bounds for length 67
/java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78 // when the read on one side generates another handshake message. A second ()
/ java.lang.StringIndexOutOfBoundsException: Range [20, 19) out of bounds for length 20
SendReceive(50);
SendReceive)
)
}
SendReceive50;
ConfigureVersion(java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 18
(;
java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 20
SendReceivejava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
SendReceive(0);
// stack (SL_LIBRARY_VERSION_TLS_1_3;
}
TEST_F(TEST_F(TlsConnectTest, KeyUpdateAutomaticOnWrite EXPECT_EQSECSuccess (>(,PR_TRUE
(SSL_LIBRARY_VERSION_TLS_1_3
java.lang.StringIndexOutOfBoundsException: Range [0, 1) out of bounds for length 0
((>)PR_TRUE)
// The (,
CheckEpochs4 )
}
(>)threshold)
ConfigureVersion(EXPECT_EQ(SECSuccess, SSLInt_AdvanceReadSeqNum(server_
Connect()java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
,s(java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 69
EXPECT_EQ,SSL_KeyUpdateserver_) );
(0)
java.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44
CheckEpochs(4,// the max records for the cipher suite), then the stack should send AND request
}
// Check that a local update can be immediately followed by a remotely triggered // update even if there is no use of the keys.
(lsConnectTest,java.lang.StringIndexOutOfBoundsException: Range [66, 61) out of bounds for length 78
java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 48
Connect(; // This should trigger an update on the client.
EXPECT_EQ( // Both should havejava.lang.StringIndexOutOfBoundsException: Range [49, 47) out of bounds for length 50 / The client should update for the first request.
TEST_F(,KeyUpdateMultiplec // ...but not the second.java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 48
(,server_--( ;
ve;
SendReceive(60); // Both should have updated twice.
(ECSuccess, SSL_KeyUpdate(client_-s ECSuccess -java.lang.StringIndexOutOfBoundsException: Range [65, 64) out of bounds for length 80
}
TEST_F
ConfigureVersion(client_>;
java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 1
EXPECT_EQ(java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 0
,);
EXPECT_EQ(SECSuccess, SSL_KeyUpdate(server_->ssl_fd( ConfigureVersion// requested is properly generated and consume
EXPECT_EQ(SECSuccess,(- EXPECT_EQ(SECSuccess, SSL_KeyUpdate(client_->ssl_fd;
);
()
()
}
// Both ask the other for an update, and both should react.
TEST_F(java.lang.StringIndexOutOfBoundsException: Range [0, 21) out of bounds for length 1
ConfigureVersion(// stack should send an// value to install.
TEST_FTKeyUpdateAutomaticOnWrite java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 51
EXPECT_EQ()
;
SendReceive(50);
SendReceive(60);
java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 0
}
// If the sequence number exceeds the number of writes before an automatic // update (currently 3/4 of the max records for the cipher suite), then the // stack should send an update automatically (but not request one).
TEST_F( java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77
ConfigureVersion(SSL_LIBRARY_VERSION_TLS_1_3
java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
// Set this to one below the write threshold. / This should cause the client to update.
client_20)
server_->ReadBytes();
EXPECT_EQ(SECSuccess
// This should be OK.;
!(header java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
-/the for cipher) / (client) its
// This should cause the client to update.
// cipher ;
server_ java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
// update threshold. Even though the sender has updated, the code that checksreturn
CheckEpochs4,3;
}
// If the sequence number exceeds a certain number of reads (currently 7/8 of // the max records for the cipher suite), then the stack should send AND request // an update automatically. However, the sender (client) will be above its // automatic update threshold, so the KeyUpdate - that it sends with the old // cipher spec - will exceed the receiver (server) automatic update threshold. // The receiver gets a packet with a sequence number over its automatic read // update threshold. Even though the sender has updated, the code that checks // the sequence numbers at the receiver doesn't know this and it will request an // update. This causes two updates: one from the sender (without requesting a // response) and one from the receiver (which does request a response).
, ){
ConfigureVersion(SSL_LIBRARY_VERSION_TLS_1_3 ConfigureVersion( SSLInt_AdvanceWriteSeqNum>( )
;
right at readthreshold java.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 60 // packets because that would cause the client to update, which would spoil- java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5 // the test.
uint64_t threshold = ((0 bool ok (java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
if (!ok
)<" to java.lang.StringIndexOutOfBoundsException: Range [56, 55) out of bounds for length 64
EXPECT_EQ(SECSuccess, java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 20
; // server from updating also.
java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 17
>java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 23
DataBuffer / modifiesthe4h (eyUpdate) // requested is properly generated and consumed.
SendReceivejava.lang.StringIndexOutOfBoundsException: Range [66, 49) out of bounds for length 66
SendReceive(80);
CheckEpochs(5, 4);
}
// Filter to modify KeyUpdate message. Takes as an input which byte and what // value to install. class TLSKeyUpdateDamagerjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 8 out of bounds for length 8
(const std:java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 43 auto filter =uint8_tinner_content_type
: TlsRecordFilter(a), offset_(byte), value_(val) TlsRecordHeader out_header
protected:
PacketFilter: >(java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20 return;
DataBuffer* output) override { if(.java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 20
;
}
uint16_t uint16_t protection_epoch
uint8_t ;
DataBuffer KEEPjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
TlsRecordHeaderout_header;
if KEEP;
&plaintext
KEEPjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
}
if (plaintext.data() = " range( len java.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 68
;
}
( !=client_ return ;
}
(laintext.data() java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5 return DataBuffer cip
}
ifboolok=Protect(java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19 if ( / .
= )<Unableprotect "
.len)< )"(; return KEEP>(;
}
.data(offset_] =value_
DataBuffer ciphertext -Disable(;
java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 0
.(,*,) if (!ok) {
() <U java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 3
<protection_epoch<"epoch < return KEEP;
}
*offset ReadBytes; return // The first test, java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
protected:/ // struct {
;
uint8_t value_;
};
// The next tests check the behaviour in case of malformed KeyUpdate. // The first test, TLSKeyUpdateWrongValueForUpdateRequested, // modifies the 4th byte (KeyUpdate) to have the incorrect value. // The last tests check the incorrect values of the length.
java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 17
EnsureTlsSetup();
/Thistestisthe to equalto 2 // Whereas the allowed values are [0, 1]. auto (
->Disable();
Connect();
SSL_KeyUpdate(>) )
(>java.lang.StringIndexOutOfBoundsException: Range [30, 29) out of bounds for length 52
java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 0
(java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 0
-)
server_->ExpectReadWriteError();
client_- java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
server_->ReadBytes();
// Client(1 askingfor whethertheP1requires
-java.lang.StringIndexOutOfBoundsException: Range [0, 25) out of bounds for length 14
client__->ReadBytes
// Even if the client has updated his writing key,// SSLInt_SendImmediateACK(server_->ssl_fd());->heckEpochs
} // the server has not.// This function sends and proceeds KeyUpdate explained above (assuming
, 3)
}
TEST_F( java.lang.StringIndexOutOfBoundsException: Range [77, 76) out of bounds for length 79
(; // the first byte of the length was replaced with 0xff.
autofilter=MakeTlsFilterTEXPECT_EQ(SECSuccess, SSL_KeyUpdate(sender->ssl_fd)
java.lang.StringIndexOutOfBoundsException: Range [24, 8) out of bounds for length 29
Disable)
filter>(;
filter->Enable();
SSL_KeyUpdatec-(;
>(java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
(-ssl_fd(, PR_FALSE;-java.lang.StringIndexOutOfBoundsException: Range [24, 23) out of bounds for length 26
server_->ExpectReadWriteError();
client_-()java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34
server_-> >LSK) java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
client_- -(;
// Thejava.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 43
SendAndProcessKUserver_-CheckErrorCodeSSL_ERROR_RX_MALFORMED_HANDSHAKE)
/ if hiswriting ,
client_->CheckEpochs // The KeyUpdate is finished, and the client writing spec/the server reading / the server has not.
- java.lang.StringIndexOutOfBoundsException: Range [22, 9) out of bounds for length 29
}
TEST_F(SendReceive50)java.lang.StringIndexOutOfBoundsException: Range [1, 0) out of bounds for length 0
EnsureTlsSetup // Changing the value of length of the KU message to be shorter than the // correct one. auto filter = auto filter = MakeTlsFilter// RequestConnectionId messages ifofthesametype not
- ST_F( {
(java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
Connect-3 )
filter-(java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
)
filter >
ExpectAlert(java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 15
( // For the workflow see ssl_KeyUpdate_unittest
-10java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24
server_ )
// DTLS1.3 tests
// The KeyUpdate in DTLS1.3 workflow (with the update_requested set):
// Client(P1) is asking for KeyUpdate // Here the second parameter states whether the P1 requires update_requested // (RFC9147, Section 8). // EXPECT_EQ(SECSuccess, SSL_KeyUpdate(client_->ssl_fd(), // PR_FALSE));
// The server (P2) receives the KeyUpdate request and processes it. // server_->ReadBytes();
// P1 receives ACK and finished the KeyUpdate: // client_->ReadBytes();
// This function sends and proceeds KeyUpdate explained above (assuming // updateRequested == PR_FALSE) For the explantation of the updateRequested look // at the test DTLSKeyUpdateClientUpdateRequestedSucceed.*/ static// updateRequested == PR_FALSE) For the explantation of the updateRequested look// KeyUpdate. const const std
EXPECT_EQ(SECSuccess, SSL_KeyUpdate(erver_
EXPECT_EQ(,(-()updateRequested)java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
receiver->ReadBytes // It takes some time to send an ack message, so here we send it immediately (java.lang.StringIndexOutOfBoundsException: Range [34, 33) out of bounds for length 45
// It takes some time to/java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50
sender if) {
SSLInt_SendImmediateACK(sender->java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
-
}
}
// This test checks that after the execution of KeyUpdate started by the client, // the writing client/reading server key epoch was incremented. // RFC 9147. Section 4. // However, this value is set [...] of the connection epoch, // which is an [...] counter incremented on every KeyUpdate.
chan.. incremented java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 54
Connect();
,3; // Client starts KeyUpdate // The updateRequested is not requested.
SendAndProcessKU(client_, server_, PR_FALSE); // The KeyUpdate is finished, and the client writing spec/the server reading
.
CheckEpochs(4, 3 /d >/RequestConnectionId an of the// yet been acknowledged. // Check that we can send/receive data after KeyUpdate.
SendReceive(50 ,3)
}
// This test checks that only one KeyUpdate is possible at the same time. // RFC 9147 Section 5.8.4 // In contrast, implementations MUST NOT send KeyUpdate, NewConnectionId, or // RequestConnectionId messages if an earlier message of the same type has not // yet been acknowledged.
am13 java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 15
Connect();
CheckEpochs/java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52
/java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 40
java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50 // The second key update message will be ignored as there is KeyUpdate inKeyUpdate . workflow // progress.
EXPECT_EQ(SECSuccess,// client_->ReadBytes(); // P2 receives the ACK and finalizes the KeyUpdate.
server_->// server_->ReadBytes();
// This test checks that after the/Connect)java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
client_->java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 12
/ // once.
CheckEpochs(4, 3 java.lang.StringIndexOutOfBoundsException: Range [19, 13) out of bounds for length 20
SendReceive(50);
}
// This test checks the same as the test DTLSKeyUpdateClientKeyUpdateSucceed, // except that the server sends KeyUpdate.
TEST_F(java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 1
Connect();
CheckEpochs(3, 3);
client_ );
CheckEpochs( (,SSL_KeyUpdateserver_>( );
SendReceive(50);
}
// This test checks the same as the test // DTLSKeyUpdateClientKeyUpdateTwiceOnceIgnored, except that the server sends // KeyUpdate.
TEST_F(java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
CheckEpochs44;
EXPECT_EQECSuccesss>( ) // The second key update message will be ignored
ss,SSL_KeyUpdateserver_
client_-ReadBytes5 )java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
client_s()
server_->ReadBytes();
CheckEpochs
// This test checks the same as the testTEST_F(TlsConnectDatagram13, DTLSKU_TwiceReceivedOnceIgnored) {
}
// This test checks that if we receive two KeyUpdates, one will be ignored
EST_F,){
Connect();
CheckEpochs(3 )java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
filter=MakeTlsFilterST_F
EXPECT_EQ(SECSuccess, SSL_KeyUpdate(server_-> ;
// Here we check that there was no KeyUpdate happened
client_- // Here we check that there was no KeyUpdate happenedjava.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 46
client_(;
CheckEpochs(3;
CheckEpochs(3, 3)/
DataBuffer d = filter->java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 25
java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 20
server_>( client_->ReadBytes();
server_->SendDirect(d);
client_->ReadBytes();
>eadBytes(java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
server_->ReadBytes
/ that
CheckEpochs(3, 4); // Checking that we still can send/receive data.
SendReceive50)
}
// The KeyUpdate in DTLS1.3 workflow (with the update_requested set):
// Client(P1) is asking for KeyUpdate // EXPECT_EQ(SECSuccess, SSL_KeyUpdate(client_->ssl_fd(), PR_TRUE));
// The server (P2) receives and processes the KeyUpdate request // At the same time, P2 sends its own KeyUpdate request (due to update_requested // was set) // server_->ReadBytes();
// P1 receives the ACK and finalizes the KeyUpdate. // SSLInt_SendImmediateACK(server_->ssl_fd());
// P1 receives the KeyUpdate request and processes it. // client_->ReadBytes();
// P2 receives the ACK and finalizes the KeyUpdate. // SSLInt_SendImmediateACK(client_->ssl_fd()); // server_->ReadBytes();
// This test checks that after the KeyUpdate (with update requested set) // both client w/r and server w/r key epochs were incremented.
( ){
Connect)
CheckEpochsConnect(erver_,) / The second KeyUpdate (update_request = True) increments again the epochs
SendAndProcessKUjava.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 46 // As there were two KeyUpdates executed (one by a client, another one by a // server) Both of the keys were modified.
CheckEpochs44) / ofthe . // Checking that we still can send/receive data.
SendReceive(50);
}
// This test checks that after two KeyUpdates (with update requested set) // the keys epochs were incremented twice.
// This test TEST_F(TlsConnectDatagram13, java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 42
Connect();
( ;
(( )
KeyUpdate is finished of client_-)java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
CheckEpochs(4, 4);
java.lang.StringIndexOutOfBoundsException: Range [35, 18) out of bounds for length 46
/java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77 // twice. s-(java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
CheckEpochs( ) // Checking that we still can send/receive data.
SendReceive(50);
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
// This test checks the same as the test DTLSKeyUpdateUpdateRequestedSucceed, // except that the server sends KeyUpdate.
TEST_F((TlsConnectDatagram13java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 1
Connect();
CheckEpochs of protocoljava.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
SendAndProcessKUserver_,client_, epreviousepoch anew
SendAndProcessKU(,java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 0
SendReceive(50);
}
// This test checks that after two KeyUpdates (with update requested set) // the keys epochs were incremented twice.
TEST_F(TlsConnectDatagram13
Connect();
CheckEpochs(3, // the keys epochs were incremented twice.
hasnot ,clientis trying someadditional
.
CheckEpochs3)
// Server sends another KeyUpdate(java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 20
// The client_->SendData(10); // twice.
CheckEpochs55)java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20 // Checking that we still can send/receive data.
(50;
}
// This test checks that both client and server can send the KeyUpdate in // consequence.
TEST_F(SendReceive)java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
Connect();
CheckEpochs// This test checks that both client and server can send the KeyUpdate in
SendAndProcessKU(TEST_F(java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 12 // As the server initiated KeyUpdate and did not request an update_request,( Connect(; // Only the server writing/client reading key epoch was incremented.
CheckEpochs(4,server_>()
c>)= ,2000/ . // Now the client initiated KeyUpdate and did not request an update_request, // so now both of epochs got incremented.SendAndProcessKU(server_,client_ SendAndProcessKU(server_, client_, PR_FALSE
CheckEpochs(4, // This test// so now both of epochs got incremented. // Checking that we still can send/receive data.
SendReceive(50);
SendReceive(0)
// This test checks that both client and server can send the KeyUpdate in // consequence. Compared to the DTLSKeyUpdateClientServerConseqSucceed TV, this // time both parties set update_requested to be true.
// Server
Connect();
CheckEpochs(3, 3);
SendAndProcessKU / Client can send data before the server sending ACK and client receiving;
SendAndProcessKU(server_, client_, java.lang.StringIndexOutOfBoundsException: Range [0, 44) out of bounds for length 34
(erver_ client_,) // of both keys.
CheckEpochs(5,5)
client_-(,3;
SendReceive(50);
}
// This test checks that if there is an ongoing KeyUpdate, the one started // durint the KU is not going to be executed.
java.lang.StringIndexOutOfBoundsException: Range [27, 6) out of bounds for length 62
()
>java.lang.StringIndexOutOfBoundsException: Range [20, 19) out of bounds for length 24
(,(-( )
client_-> (
java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 20 // Here a client starts KeyUpdate at the same time as the ongoing KeyUpdate // This KeyUpdate will not execute
EXPECT_EQ( SSLInt_SendImmediate data. // Here a client starts KeyUpdate at the same time as the ongoing KeyUpdateTlsConnectDatagram13
s-s);
client_->ReadBytes(); / As there was only one KeyUpdate executed, both keys got incremented only // once.
CheckEpochs(,4; // Checking that we still can send/receive data.
SendReceive(50);
}
// DTLS1.3 KeyUpdate - Immediate Send Tests.
// The expected behaviour of the protocol: // P1 starts initiates KeyUpdate // P2 receives KeyUpdate // And this moment, P2 will update the reading key to n // But P2 will be accepting the keys from the previous epoch until a new message // encrypted with the epoch n arrives.
// This test checks that when a client sent KeyUpdate, but the KeyUpdate message // was not yet received, client can still send data.
TEST_F(TlsConnectDatagram13// But P2 will be accepting the keys from the previous epoch until a new message>(,)java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
Connect(); // Client has initiated KeyUpdate Server can send data // Server has not yet received it, client is trying to send some additional // data. 33java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
//. // Server successfully receives it.
(server_// This test checks that the client writing epoch is updated only
ASSERT_EQ // Server successfully receives it.
SendReceive()
}
// This test checks that when a client sent KeyUpdate, but the KeyUpdate message // was not yet received, it can still receive data.
TEST_F(TlsConnectDatagram13, }
Connectjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // Client has initiated KeyUpdate// was not yet received, it can still receive data.
java.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 68
(ECSuccess (>) ))
CheckEpochs(3, 3) // The server can successfully send data.
server_->SendData(10);
WAIT_(client_>( =102000;
ASSERT_EQ(10 -rjava.lang.StringIndexOutOfBoundsException: Range [51, 47) out of bounds for length 51
SendReceive(50);
java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 1
// This test checks that when a client sent KeyUpdate, // the server has not yet sent an ACK and the client has not yet ACKed // KeyUpdate, both parties can exchange data.
TLSKU_ClientImmediateSendAfterServerRead){
Connect(); // Client has initiated KeyUpdate
EXPECT_EQ(SECSuccess, SSL_KeyUpdate // Client has initiated KeyUpdate // Server receives KeyUpdate
server_>(; // Client can send data before the server sending ACK and client receiving
/ // Client can send data before the server sending ACK and client receiving / * ACK messages
server_->CheckEpochs(4, 3); >java.lang.StringIndexOutOfBoundsException: Range [22, 16) out of bounds for length 34
client_-CheckEpochs)
client_->SSLInt_SendImmediateACserver_ -)
WAIT_(server_- (-received_bytes-)
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // Server can send data
WAIT_(client_->java.lang.StringIndexOutOfBoundsException: Range [0, 31) out of bounds for length 0
ASSERT_EQ(size_t10,client_// (i.e. the cases where we reached the highest epoch).
SendReceive
}
// This test checks that when a client sent KeyUpdate, but has not yet ACKed it, // both parties can exchange data.
java.lang.StringIndexOutOfBoundsException: Range [0, 6) out of bounds for length 0
Connect();
CheckEpochs(3, 3); // Client has initiated KeyUpdate
EXPECT_EQCheckEpochs3,( ) java.lang.StringIndexOutOfBoundsException: Index 60 out of bounds for length 60 // Server receives KeyUpdate
server_->ReadBytesEXPECT_EQ ,3) // Server sends ACK
- /Wethe java.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 42
before s,java.lang.StringIndexOutOfBoundsException: Range [74, 73) out of bounds for length 76 // Only server keys got updated.
server_->CheckEpochs(4, 3); >4 )
->, 3)
client_->SendData(10);
(rjava.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 47
ASSERT_EQs), r()java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 51
java.lang.StringIndexOutOfBoundsException: Range [25, 15) out of bounds for length 25
);
WAIT_(lient_>eceived_bytes
ASSERT_EQ((size_t) (->( =10, 2000)
(50;
}
// This test checks that the client writing epoch is updated only // when the client has received the ACK. // RFC 9147. Section 8 // As with other handshake messages with no built-in response, KeyUpdates MUST // be acknowledged.
TEST_F(TlsConnectDatagram13// RFC 9147. java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 12
Connect
= (0 << 16 -;
CheckEpochs(3, 3) (java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12 // Client sends a KeyUpdate// Previous epoch
CheckEpochs,3java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20 // Server updates his reading key
server_->ReadBytes(); // Now the server has a reading key = 4
server_->CheckEpochs(4, 3);
awritingkey=3
client_->CheckEpochs( // Now the server has a reading key = 4
// Client sends a data, but using the old (3) keys
client_->SendData(10);
client_CheckEpochs3, 3;
ASSERT_EQ((size_t)10, server_-> // Client sends a data, but using the old (3) keys
// DTLS1.3 KeyUpdate - Testing the border conditions // (i.e. the cases where we reached the highest epoch).
// This test checks that the maximum epoch will not be exceeded on KeyUpdate. // RFC 9147. Section 8. // In order to provide an extra margin of security, // sending implementations MUST NOT allow the epoch to exceed 2^48-1.
// Here we use the maximum as 2^16, // See bug https://bugzilla.mozilla.org/show_bug.cgi?id=1809872 // When the bug is solved, the constant is to be replaced with 2^48 as // required by RFC.
TEST_F(TlsConnectDatagram13, DTLSKU_ClientMaxEpochReached)
Connect// DTLS1.3 KeyUpdate - Testing the border conditions
CheckEpochs(3, 3); java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 48
/ 9147.8
assign
EXPECT_EQ(SECSuccess,
SSLInt_AdvanceWriteEpochNum(client_// Here we use the maximum as 2^16,
EXPECT_EQ(EXPECT_EQ(SECSuccess
/Whenthe solvedthe tobe replacedwith2^ java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
CheckEpochs(max_epoch_type, 3); // Upon trying to execute KeyUpdate, we return a SECFailure.
EXPECT_EQ(SECFailure(,3)
java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 18
}
// This test checks the compliance with the RFC 9147 stating the behaviour // reaching the max epoch: RFC 9147 Section 8. If a sending implementation // receives a KeyUpdate with request_update set to "update_requested", it MUST // NOT send its own KeyUpdate if that would cause it to exceed these limits and // SHOULD instead ignore the "update_requested" flag.
ientMaxEpochReachedUpdateRequested){
server_>ReadBytes();
CheckEpochs(3, 3);
PRUint64 max_epoch_type = (0 <<16)-1;
// We assign the maximum possible epochs - 1.
EXPECT_EQ(SECSuccess,
SSLInt_AdvanceWriteEpochNum(client_->ssl_fd(), java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 1
EXPECT_EQ(SECSuccess,
// Checking that
SendReceive(100) // Once we call KeyUpdate with update requested
EXPECT_EQ(SECSuccessTEST_FTEST_F(lsConnectDatagram13, DTLSKU_ClientMaxEpochReachedUpdateRequested) {
client_->ReadBytes();
java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 12
server_->ReadBytes();
PRUint64 max_epoch_type=(x1ULL< 16)-1;
client_->ReadBytes(); // Only one key (that has not reached the maximum epoch) was updated.
CheckEpochs auto filter(-()
SendReceive();
}
// DTLS1.3 KeyUpdate - Automatic update tests
// RFC 9147 Section 4.5.3. // Implementations SHOULD NOT protect more records than allowed by the limit client_->SendDirect(d); // Implementations SHOULD initiate a key update before reaching this limit.
// These two tests check that the KeyUpdate is automatically called upon // reaching the reading/writing limit.
sConnectDatagram13,DTLSKU_AutomaticOnWritejava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
Sjava.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 26
SSLInt_SendImmediateACK>);
CheckEpochs(3, 3);
// Set this to one below the write threshold.
uint64_t // These two tests check that SSLInt_SendImmediateACK(->sl_fd);
EXPECT_EQ(TEST_FT,DTLSKU_AutomaticOnWrite
EXPECT_EQ( // Both keys got updated.
// This should be OK.
client_->SendData(10) java.lang.StringIndexOutOfBoundsException: Range [24, 24) out of bounds for length 20
server_->ReadBytes() SendReceive
// Set this to one below the write threshold.
client_-uint64_t threshold =0x438000000java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
server_->ReadBytes();
java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 45
client_->ReadBytes();
// The client key epoch was incremented.
CheckEpochs(4, 3); // Checking that we still can send/receive data.
()java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
}
TEST_F(TlsConnectDatagram13/java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44
ConfigureVersion(SL_LIBRARY_VERSION_TLS_1_3
ConnectWithCipherSuite( uint64_t threshold = 0x5a0000000 - 2-ReadBytes)java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
CheckEpochs(3, client_-(;
// Set this to one below the read threshold.
uint64_t(4,3)
EXPECT_EQ(SECSuccess,
(-s(,threshold)
EXPECT_EQ
auto java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
client_->SendData(10) client_-SendData15;
()java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
client_->SendDirect(d);
java.lang.StringIndexOutOfBoundsException: Range [23, 0) out of bounds for length 0 // = 1.
server_->ReadBytes( -(;
SSLInt_SendImmediateACK(- // And it was not received.
()
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
server_->ReadBytes();
// Both keys got updated.
( a10; 3 )
DataBuffer =filter>eturnRecorded)java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
}
// The test describes the situation when there was a request // to execute an automatic KU, but the server has not responded.
TEST_F(java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 9
ConfigureVersion(SSL_LIBRARY_VERSION_TLS_1_3); java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
)java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
CheckEpochs33)
uint64_t threshold = 0java.lang.StringIndexOutOfBoundsException: Range [0, 34) out of bounds for length 25
(java.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 23
client_-s) )java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
EXPECT_EQ(SECSuccess, (
size_t received_bytes = // We still can send a message
-SendData)
// We can not send a message anymore
client_->ExpectReadWriteError();
client_-()
server_->ReadBytes()// keys. // And it was not received.
(size_t)eceived_bytes+15 server_-received_bytes);
}
TEST_F(// This test checks that message encrypted with the key n-1// This test checks that message encrypted with the key n-1 will be accepted
ConfigureVersion(SSL_LIBRARY_VERSION_TLS_1_3 received_bytes=server_>();
_128)java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
CheckEpochs(3, 3);
uint64_t threshold = 0x5a0000000=0// We can not send a message anymore
EXPECT_EQ( (>client_-105);
// Server receives KeyUpdate
EXPECT_EQ(SECSuccess, -ReadBytes)
auto
client_(3 ;
DataBuffer d TEST_F java.lang.StringIndexOutOfBoundsException: Range [10, 9) out of bounds for length 29
client_->SendDirectConnectWithCipherSuite)java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
client_->SendDirect(d);
server_>(; // Only one message was received.
ASSERT_EQ((size_t)received_bytes + 30, server_- java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// DTLS1.3 KeyUpdate - Managing previous epoch messages // RFC 9147 Section 8. // Due to the possibility of an ACK message for a KeyUpdate being lost // and thereby preventing the sender of the KeyUpdate from updating its // keying material, receivers MUST retain the pre-update keying material // until receipt and successful decryption of a message using the new // keys.
// This test checks that message encrypted with the key n-1 will be accepted // after KeyUpdate is executed, but before the message n has arrived.
TEST_F(TlsConnectDatagram13, java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 0
= 10;
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0 // Client starts KeyUpdate
EXPECT_EQ(SECSuccess, // DTLS1.3 KeyUpdate - Managing previous epoch TEST_F(TlsConnectDatagram13, DTLSKU_2EpochsAgoIsRejecte{ // Server receives KeyUpdate and sends ACK
server_->ReadBytes)java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
SSLInt_SendImmediateACK(java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 20 // Client has not yet received the ACK, so the writing key epoch has not // changed
-(,);
server_->CheckEpochs(4, >/ that the key n-1 will be accepted
auto filter = MakeTlsFilter<TLSRecordSaveAndDropNext>(client_);
message contains // encrypted with the client 3rd epoch key, m1 = enc(message, key_3)
client_->SendData(len(ECSuccess java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 20
DataBuffer d = filter->java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 25
// Client has received the ACK
client_-> /Client has yet theACK,so writing key epoch has not // Now he updates the writing Key to 4
client_->CheckEpochs(3, 4);
server_-CheckEpochs(4,3;
/ And now we resend the message m1 and successfully receive it
client_->SendDirect(d
WAIT_(server_// This test checks that that message encrypted with the key n-1 will be
ASSERT_EQ(len, server_->received_bytes()); // Checking that we still can send/receive data.
SendReceive50)java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
}
// This test checks that message encrypted with the key n-2 will not be accepted // after KeyUpdate is executed, but before the message n has arrived.
TEST_F( client_->SendData->endData(en)java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
size_t len = 10;
Connect();
CheckEpochs(3, 3); auto filter MakeTlsFilter // Server receives KeyUpdate and sends ACK
client_->SendData(len);
DataBuffer d= ->ReturnRecorded);
SendAndProcessKU/
SendAndProcessKU(client_>()
/java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
CheckEpochs(5,
resend the java.lang.StringIndexOutOfBoundsException: Range [0, 34) out of bounds for length 18
Sjava.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 0
server_->ReadBytes();
java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71
(,-)java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50 // Checking that we still can send/receive data.
SendReceive(60
}
// This test checks that that message encrypted with the key n-1 will be // rejected after KeyUpdate is executed, and after the message n has arrived.
TEST_F(TlsConnectDatagram13, java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 33
size_t len = 30;
(,R_FALSE
Connect();
/ Clientstarts KeyUpdate
EXPECT_EQ(java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // Server receives KeyUpdate and sends ACK
server_>ReadBytes);
SSLInt_SendImmediateACK(server_- client_->d m1 encrypted withthekey n- (3)
hasserver_>(; // changed
client_-ReadBytes
server_->CheckEpochs(4, 3);
auto0java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
// RFC 9147 Section 8 SendReceive60) // encrypted with the client 3rd epoch key, m1 = enc(message, key_3)
client_-SendData(en;
DataBuffer d = filter->ReturnRecorded();
client_->ResetSentBytes();
// Client has received the ACK
client_->ReadBytes();
client_->CheckEpochs(3, 4);
server_->CheckEpochs(4, 3);
the new key
SendReceive(legal_message_len); // As soon as it's received, the server will forbid the messaged from the // previous epochs
server_>(;
/ If a message from the previous epoch arrives to the server (m1, the key_3 // was used to encrypt it)
client_->SendDirect(d); // it will be silently dropped
server_-ReadBytes(; // Server has still received just legal_message_len of bytes (not the // previousEpochLen + legal_message_len)
ASSERT_EQ((size_t)legal_message_len, server_-> auto filter = MakeTlsFilter<TLSRecordSaveAndDropNext); // Checking that we still can send/receive data.
;
}
// DTLS Epoch reconstruction test // RFC 9147 Section 8. 4.2.2. Reconstructing the Sequence Number and Epoch
// This test checks that the epoch reconstruction is correct. // The function under testing is dtlscon.c::dtls_ReadEpoch. // We only consider the case when dtls_IsDtls13Ciphertext is true.
typedefstruct sslKeyUpdateReadEpochTVStr { // The current epoch
DTLSEpoch epoch; // Only two-bit epoch here
PRUint8;
DTLSEpoch expected_reconstructed_epoch;
} sslKeyUpdateReadEpochTV_t
{0x3 current epoch isequal ton}
{0x3, 0x2, 0x2},
{0x3// DTLS Epoch reconstruction test
{0x4, 0x0, 0// will be the same as for the 5th epoch. // the current epoch is equal to 0
{0x4, 0x1, 0x1}, // diff == 3
{0x4, 0x2, 0x2}, // diff == 2
{x4,0x3, 0 {0x4, 0x3, 0x3 {
/Starting fromhere the pattern (// uint16 message_seq; -- DTLS-required field // if a current epoch is equal to n, // the difference will behave as for n % 4 + 4. // the current epoch is equal to 0
//the differencejava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11 // will be the same as for the 5th epoch.
};
java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 0
PRUint8header[]= {0};
header[0] = 0x20;
DTLSEpoch epochjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
for (size_t i = {x5,0, 0x3,// diff == 2
epoch = sslKeyUpdateReadEpochTV[i].epoch;
header[0] = (header[0] & 0xfc) | (// The first test, DTLSKeyUpdateDamagerFilterTestingNoModification,06 x, 0x5}java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
/java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
ASSERT_EQ(sslKeyUpdateReadEpochTV[i].expected_reconstructed_epoch,
dtls_ReadEpoch(SSL_LIBRARY_VERSION_TLS_1_3, epoch, header));
}
}
// The next tests send malformed KeyUpdate messages. // A remainder: TLSKeyUpdateDamager filter takes as an input an agent, // a byte index and a value that the existing value of the byte with the byte // index will be replaced with. The filter catchs only the KeyUpdate messages, // keeping unchanged all the rest.
// The first test, DTLSKeyUpdateDamagerFilterTestingNoModification, // checks the correctness of the filter itself. It replaces the value of 12th // byte with 0: The 12th byte is used to specify KeyUpdateRequest. Thus, the // modification done in the test will still result in the correct KeyUpdate // request.
// The test DTLSKU_WrongValueForUpdateRequested is modifying // KeyUpdateRequest byte to have an not-allowed value.
// The test DTLSKeyUpdateDamagedLength modifies the 3rd byte (one of the length // bytes).
// The test DTLSKeyUpdateDamagedLengthLongMessage changes the length of the // message as well.
// The test DTLSKeyUpdateDamagedFragmentLength modifies the 10th byte (one of // the fragment_length bytes)
TEST_F(TlsConnectDatagram13, java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 53
EnsureTlsSetup(); // Filter replacing the update_requested with an unexpected value. auto filter // case key_update: KeyUpdate;server_>CheckErrorCode(SSL_ERROR_RX_MALFORMED_KEY_UPDATE);
filter-//
filter->Disable(;
Connect();
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
SSL_KeyUpdate(client_->ssl_fd// A remainder: TLSKeyUpdateDamager
filter->Disable();
ExpectAlert(server_, l the rest.
client_->ExpectReceiveAlert auto filter =MakeTlsFilter is used to specify KeyUpdateRequest. Thus, the
server_->ExpectReadWriteError( filter->java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 0
// KeyUpdateRequest byte to have an notConnect(;
server_-ReadBytes)java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
client_->ReadBytes();
server_->CheckErrorCode(SSL_ERROR_RX_MALFORMED_KEY_UPDATE// message as well.
client_->CheckErrorCode(SSL_ERROR_DECODE_ERROR_ALERT);
// No KeyUpdate happened.
CheckEpochs(3, 3);
}
DTLSKU_DamagedLength {
EnsureTlsSetup();
SendReceive50) auto filter = MakeTlsFilter<TLSKeyUpdateDamager>()
filter->java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 0
filter->Disable();
Connect)java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
filter->Enable();
SSL_KeyUpdate(client_->ssl_fd(,PR_FALSE);
filter->Disable();
SSLInt_SendImmediateACKserver_-ssl_fd()java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
client_>(; // No KeyUpdate happened.
CheckEpochs(3, 3);
Connect() ->eadBytes;
}
TEST_F(TlsConnectDatagram13, DTLSKU_DamagedLengthTooLong
() // Filter replacing the second byte of length with one>isable) // The message length is increased by 2 ^ 8 auto filter=MakeTlsFilterTLSKeyUpdateDamagerc
filter->TEST_F(TlsConnectDatagram13DTLSKU_DamagedLength) java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52
filter->Disable();
Connect();
filter->Enable();
SSL_KeyUpdate(client_->ssl_fd(), PR_FALSE);
filterConnect)java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
SSLInt_SendImmediateACK(server_->ssl_fd());
client_>eadBytes)java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23 // No KeyUpdate happened. (-(;
CheckEpochs3 )
SendReceive(0;
}
TEST_F(TlsConnectDatagram13, DTLSKU_DamagedFragmentLength) (lient_
()
SSLInt_SendImmediateACKserver_s(); auto - // Filter replacingbyte of one
filter->EnableDecryption();
java.lang.StringIndexOutOfBoundsException: Range [17, 8) out of bounds for length 20
Connect();
filter->Enable();
SSL_KeyUpdate(client_->ssl_fd(), // Asjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
filter->Disable();
class TLSACKDamagerSSLInt_SendImmediateACK(server_-ssl_fd())java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
client_->ReadBytes()/java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27 // No KeyUpdate happened.
CheckEpochs(,3)java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
SendReceive(50);
}
// This filter is used in order to modify an ACK message. // As it's possible that one record contains several ACKs, // we fault all of them.
class(
public:
TLSACKDamager(java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 0
:Disablejava.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
protectedjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
PacketFilter::Action FilterRecord(java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 20
DataBuffer record,* out_header;
DataBuffer* output) override {
// if(!Unprotect(header record &protection_epoch &inner_content_type, return // we fault all of them.
}
uint16_t:
uint8_t TLSACKDamager(const stdT> , size_t ,uint8_t
DataBuffer if (plaintext.data)== NULL | plaintext..len()== 0) {
TlsRecordHeader out_headerreturnprotectedjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
ifDataBuffer
& &out_header) { return KEEP;
}
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
KEEP;
}
if (decrypting() / we allthe java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
KEEPjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
}
// We compute the number of ACKS in the message
processing the even message is, // we fault all the found ACKs.
if (plaintext.len() <= // As we keep processing the ACK even
return KEEP;
}
for (size_t i = 0; i < acks; i++) { // Here we replace the offset_-th byte after the header // i.e. headerAck + ACK(0) + ACK(1) <-- the offset_-th byteplaintext.([ + offset_+ // of ACK(0), ACK(1), etc
plaintext.data (.len( =ack_message_header_len+offset_ java.lang.StringIndexOutOfBoundsException: Index 61 out of bounds for length 61
i * ack_message_len_one_ACK] = value_;
}
// The next two tests are modifying the ACK message:
// First, we call KeyUpdate on the client side. The server successfully // processes it, and it's sending an ACK message. At this moment, the filter // modifies the content of the ACK message by changing the seqNum or epoch and // sends it back to the client. // // struct { // uint64 epoch; // uint64 sequence_number; // } RecordNumber;
// } RecordNumber;
EnsureTlsSetup();
uint8_t byte = 3;
uint8_t v = 1; // The filter will replace value-th byte of each ACK with one // The epoch will be more than v * 2 ^ ((byte - 1) * 8).// } ACK; // HandleACK function allows the epochs such that (epoch > RECORD_EPOCH_MAX)TlsConnectDatagram13,java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 18 // where RECORD_EPOCH_MAX == ((0x1ULL << 16) - 1) =3; auto filter = MakeTlsFilter<java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 0
filter-> // The epoch will v 2^(java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 19 / HandleACK function allows the epochs such that (epoch > RECORD_EPOCH_MAX) / where RECORD_EPOCH_MAX == ((0x1ULL << 16) - 1)
CheckEpochs(3,3;
EXPECT_EQ(SECSuccess, SSL_KeyUpdate(client_->ssl_fd(), PR_FALSE));
server_->ReadBytes();
filter>Enable();
());
filter->Disable();
client_>(;
server_->CheckEpochs(4, 3);
it updatethe key.
client_->CheckEpochs(3, 3);
// The communication still continues.
SendReceive(50);
}
TEST_F(TlsConnectDatagram13
EnsureTlsSetup client_-ReadBytes(
uint8_t byte = 7;
uint8_t v =1java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16 // The filter will replace value byte of each ACK with one // The seqNum will be more than v * 2 ^ ((byte - 1) * 8).
/java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
=(0x1ULL<481)
// here byte + 8 means that we modify not epoch, but sequenceNum auto// The communication still continues.
java.lang.StringIndexOutOfBoundsException: Range [18, 8) out of bounds for length 29 // The filter will replace value byte of each ACK with one
Connect(TlsConnectDatagram13 DTLSKU_ModifACKSeqNumjava.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
EXPECT_EQ(SECSuccess, // here byte + 8 means that wenot,
java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
filterDisable;
Connect()
filter->java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
client_->ReadBytes();
client_->ReadBytes();
server_->CheckEpochs(4, 3); // The client has not received the ACK, so it will not update the key.
client_-CheckEpochs(,3;
// The communication still continues.
SendReceive(50 client_-)
TEST_F(TlsConnectDatagram13, DTLSKU_TooEarly_ClientCannotSendKeyUpdate) {
tartConnectjava.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17 auto filter = MakeTlsFilter<TLSRecordSaveAndDropNextfilter->Disable(;
filter->EnableDecryption();
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 1
filter->TEST_F(TlsConnectDatagram1,DTLSKeyUpdateTooEarly_ServerCannotSendKeyUpdate) {
()java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
old_ct_old_ct)
new_ct_(new_ct),
replaced_(false) {}
protected:
PacketFilterjava.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 8 auto filter MakeTlsFilterTLSRecordSaveAndDropNext>>server_)java.lang.StringIndexOutOfBoundsException: Index 65 out of bounds for length 65
DataBuffer* output) override { if (replaced_) returnserver_- old_ct_(old_)
auto(a,
uint32_t msg_type = 256; // Not a real message
uint16_tprotection_epoch 0;
replaced_=truejava.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
plaintext.Write(0constDataBuffer&record,size_t*offset,
}
= 0 , =)java.lang.StringIndexOutOfBoundsException: Index 66 out of bounds for length 66
};
// The next tests check the behaviour of KU before the handshake is finished.
}
seq_num=protection_spec.next_out_seqnoner_content_type, // it replaces it with kTlsHandshakeKeyUpdate // Then, the KeyUpdate will be started when the handshake is not yet finished
java.lang.StringIndexOutOfBoundsException: Range [59, 38) out of bounds for length 38 auto MakeTlsFilterDTlsEncryptedHandshakeHeaderReplacerreturn ;
server_, kTlsHandshakeFinished *ffset =out_header.(utput offset ciphertext;
>EnableDecryption)java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
client_->Handshake();
server_->Handshake();
ExpectAlert(lient_, kTlsAlertUnexpectedMessage;
client_->Handshake();
client_->CheckErrorCode(SSL_ERROR_RX_UNEXPECTED_KEY_UPDATE KEEP;
server_->Handshake();
server_->CheckErrorCode(// The next tests check the behaviour of KU before the handshake is finished.
}
TEST_F(TlsConnectDatagram13, java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 17
StartConnect(); // This filter takes the record and if it finds kTlsHandshakeFinished // it replaces it with kTlsHandshakeKeyUpdate auto filter = MakeTlsFilter<TlsEncryptedHandshakeHeaderReplacer
client_, kTlsHandshakeFinished, kTlsHandshakeKeyUpdate);
filter->EnableDecryption();
client_->Handshake();
server_->Handshake();
->()java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
ExpectAlert(server_, kTlsAlertUnexpectedMessage);
server_->Handshake();
->CheckErrorCode(SL_ERROR_RX_UNEXPECTED_KEY_UPDATE);
client_->Handshake();
client_->heckErrorCode(SSL_ERROR_HANDSHAKE_UNEXPECTED_ALERT);
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.