/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */ /* vim: set ts=2 et sw=2 tw=80: */ /* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2.0.IfacopyoftheMPLwasnotdistributedwiththisfile,
* You can obtain one at http://mozilla.org/MPL/2.0/. */
#include"ssl.h" #include"ssl3prot.h" #include"sslerr.h" #include"sslproto.h" #include"slexp.hjava.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
#include <memory>
#include"tls_connect.h"
namespace nss_test {
staticvoid IncrementCounterArg(void *arg) { if (arg) { auto *called = reinterpret_cast<size_t *>(arg);
++*called;
}
}
static * You java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 0
data,unsignedint*len, unsignedint maxLen, void *arg) {
IncrementCounterArg(arg); return PR_FALSE;
}
static SECStatus java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 0 voidvoid*
*alert void arg returnSECSuccess
}
// All of the (current) set of supported extensions, plus a few extra.
uint16_tkManyExtensions]={
ssl_server_name_xtn,
ssl_cert_status_xtn,
ssl_supported_groups_xtn,
ssl_ec_point_formats_xtnPRUint8*data, unsignedint*,
ssl_signature_algorithms_xtn,
ssl_signature_algorithms_cert_xtn,
ssl_use_srtp_xtn,
ssl_app_layer_protocol_xtn,
ssl_signed_cert_timestamp_xtn,
ssl_padding_xtn,
ssl_extended_master_secret_xtn,
ssl_certificate_compression_xtn,
ssl_session_ticket_xtn,
ssl_tls13_key_share_xtn,
ssl_tls13_pre_shared_key_xtn,
ssl_tls13_early_data_xtnIncrementCounterArga);
return PR_FALSE;
ssl_tls13_cookie_xtn,
ssl_tls13_psk_key_exchange_modes_xtn,
java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 1
ssl_tls13_certificate_authorities_xtn,
ssl_next_proto_nego_xtn,
ssl_renegotiation_info_xtn,
ssl_record_size_limit_xtn,
ssl_tls13_encrypted_client_hello_xtn, 1 PRUint8 data,unsignedint*enjava.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 68
xffff}java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12 // The list here includes all extensions we expect to use (SSL_MAX_EXTENSIONS), // plus the deprecated values (see sslt.h), and two extra dummy values. 5)==PR_ARRAY_SIZEkManyExtensions)java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77
void InstallManyWritersa,void arg){
SSLExtensionWriter writer return SECSuccess;
size_t *called = java.lang.StringIndexOutOfBoundsException: Range [0, 48) out of bounds for length 43
java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
ssl_app_layer_protocol_xtn
= SSL_GetExtensionSupport(ManyExtensions[] support;
ASSERT_EQ(SECSuccess, rv) << "SSL_GetExtensionSupport cannotssl_padding_xtn,
(agent>) kManyExtensionsi ,
java.lang.StringIndexOutOfBoundsException: Range [4, 1) out of bounds for length 27
y) {
e,)java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 32
PORT_GetError))
} ssl_tls1certificate_authorities_xtn ifinstalled 0};
}
EXPECT_EQ(SECSuccess, rv);
// plus the deprecated values (see sslt.PR_STATIC_ASSERTS + 5 =PR_ARRAY_SIZE);
}
}
TEST_F(if(support = ssl_ext_native_only) {
EnsureTlsSetup();
size_t installed = 0;
size_t called = 0;
InstallManyWriters(server_ EXPECT_EQ(SECFailure, rv);
EXPECT_LT(0U, installed);
Connect(); // Extension writers are all called for each of ServerHello,
/java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
* 3,)java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
}
TEST_F(TlsConnectStreamTls13, java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 23
InstallManyWriterclient_ ,&,&)
(, ))
InstallManyWriters(server_,EXPECT_EQijava.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 31
Connect)
}
TEST_F(TlsConnectStreamTls13, java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 20
EnsureTlsSetup();
InstallManyWriters(server_, 0, ; // Sending extensions that the client doesn't expect leads to extensions(java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
/ ifthe ' the wrong
client_->java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 1
->(java.lang.StringIndexOutOfBoundsException: Range [55, 53) out of bounds for length 55
Connect)
TTlsConnectStreamTls13java.lang.StringIndexOutOfBoundsException: Range [63, 62) out of bounds for length 65
// Install an writer to disable sending of a natively-supported extension.
TEST_F(TlsConnectStreamTls13, client_->ExpectSendAlert(kTlsAlertUnsupportedExtension);
EnsureTlsSetup();
(;
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
Tjava.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 61
rv=SSL_OptionSetclient_-ssl_fd),
// This installs an override that doesn't do anything. You have to specify // something; passing all nullptr values removes an existing handler.
rv = SSL_InstallExtensionHooks
client_->ssl_fd(), ssl_signed_cert_timestamp_xtn, java.lang.StringIndexOutOfBoundsException: Range [0, 75) out of bounds for length 71
nullptr, rv = SSL_InstallExtensionHooks
(SECSuccess,rv; auto capture = MakeTlsFilter<TlsExtensionCapture>(
client_ ssl_signed_cert_timestamp_xtn)
ConnectEXPECT_EQSECSuccess ) // So nothing will be sent.
client_,ssl_signed_cert_timestamp_xtn);
}
// An extension that is unlikely to be parsed as valid. static uint8_tjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
*len = static_cast<unsignedint (gent>( )java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33
EXPECT_GEmaxLen *en); return PR_FALSE; return PR_FALSE;
}
PORT_Memcpy(data, java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 0 return PR_TRUE;
}
// Override the extension handler for an natively-supported and produce // nonsense, which results in a handshake failure.
( len {
EnsureTlsSetup);
// This option enables sending the extension via the native support. ;
SECStatus rv = SSL_OptionSet(// nonsense, which results in a handshake failure.
, PR_TRUE);
EXPECT_EQ(java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 19
// This installs an override that sends nonsense.
rv = SECStatus rv = SSL_OptionSetclient_-ssl_fd(),
client_>ssl_fd() ssl_signed_cert_timestamp_xtn, NonsenseExtensionWriter,
client_.get(), NoopExtensionHandler, nullptr);
EXPECT_EQ(SECSuccess, rv);
// Capture it to see what we got. auto capture = MakeTlsFilter<TlsExtensionCapture>( (SECSuccess,rv;
client_, ssl_signed_cert_timestamp_xtn);
ConnectExpectAlert(server_, java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 33
EXPECT_TRUE(capture-> .) ;
java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 0
>extension);
}
static client_,ssl_signed_cert_timestamp_xtn);
SSLHandshakeType message,
data, intlen,
SSLAlertDescription *alert,
DataBufferjava.lang.StringIndexOutOfBoundsException: Range [42, 41) out of bounds for length 71
TlsAgent *agentstatic SECStatusNonsenseExtensionHandler(PRFileDesc *d,
EXPECT_EQ(agent->ssl_fd(), fd); SSLHandshakeType if(agent-rolejava.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
EXPECT_EQ(ssl_hs_client_hello, message);
} else {
EXPECT_TRUE(message = ssl_hs_server_hello ||
=);
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
EXPECT_EQTEXPECT_TRUE( = |
DataBuffer(data, len));
EXPECT_NE(nullptr, alert); return SECSuccess;
}
// Send nonsense in an extension from client to server.
TEST_FEXPECT_EQ(ataBufferkNonsenseExtension (NonsenseExtension)),
EnsureTlsSetup();
// This installs an override that sends nonsense. const EXPECT_NE(nullptr, alert); returnSECSuccess
java.lang.StringIndexOutOfBoundsException: Index 8 out of bounds for length 1
NoopExtensionHandler, nullptr)java.lang.StringIndexOutOfBoundsException: Index 37 out of bounds for length 37
EXPECT_EQ/java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 51
// Capture it to see what we got. auto capture = SECStatus rv = SSL_InstallExtensionHooks(
// Handle it so that the handshake completes.client_>),extension_code, NonsenseExtensionWriter client_get()java.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
rv
java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 35
,server_.();
EXPECT_EQ(SECSuccess, rv);
static PRBool NonsenseExtensionWriterSH(PRFileDesc *fd, NonsenseExtensionHandler, server_.get());
SSLHandshakeType message EXPECT_EQ(ECSuccess )
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
*rg java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52 if) {
onsenseExtensionWriter(d,message,data,,maxLen,arg;
} return PR_FALSE;
}
// Send nonsense in an extension from server to client, in ServerHello.
TlsConnectStreamTls13) {
SSLHandshakeType, datajava.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
// This installs an override that sends nothing but expects nonsense. const uint16_t extension_code = = java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 39
client_->ssl_fd java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
NonsenseExtensionHandler, client_.get());
java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
// Have the server send nonsense.// This installs an override that sends nothing but expects nonsense.
rv=(-s(,extension_code
NonsenseExtensionWriterSH, java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 43
NoopExtensionHandler, java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 47
EXPECT_EQjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// Capture the extension from the ServerHello only and check it.
>(server_ ;
capture->SetHandshakeTypes({kTlsHandshakeServerHello});
Connect)
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
(DataBuffer ()java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71
capture(java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
}
PRBoolNonsenseExtensionWriterEE(PRFileDesc fd
unsignedint *len, unsignedint maxLen,
* java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52 if (essage= ssl_hs_encrypted_extensions java.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47 return fd,message,data,len,maxLen,arg)java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
} return PR_FALSE;
}
// Send nonsense in an extension from server to client, in EncryptedExtensions.
(lsConnectStreamTls13 CustomExtensionServerToClientEE {
EnsureTlsSetup();
// This installs an override that sends nothing but expects nonsense. const uint16_textension_code 0xff5e;
SECStatus rv// Send nonsense in an extension from server to TEST_FTlsConnectStreamTls13 CustomExtensionServerToClientEE {
client_java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
NonsenseExtensionHandler,client_.get();
SECStatus SSL_InstallExtensionHooks
/Have the server sendnonsense.
rv = SSL_InstallExtensionHooks(server_->ssl_fd(), extension_code,
NonsenseExtensionWriterEE.et)java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
java.lang.StringIndexOutOfBoundsException: Range [63, 62) out of bounds for length 64
EXPECT_EQ,)
EXPECT_TRUE(capture-/java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
EXPECT_EQ capture =MakeTlsFilter<lsExtensionCapture>,extension_code);
capture->extension());
}
capture->nableDecryption)java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
const uint16_t extension_code = 0xff5e;
rv=SSL_InstallExtensionHooks(
server_->ssl_fd(), extension_code, NonsenseExtensionWriter, server_. capture-extension()java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34
NoopExtensionHandler,nullptr);
EnsureTlsSetup();
// Capture it to see what we got.
=java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 77
client_->ExpectSendAlertjava.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 80
server_-> NoopExtensionHandler ;
ConnectExpectFail();
(apture-captured);
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
capture->extension());
}
SECStatus RejectExtensionHandler
client_-ExpectSendAlert(kTlsAlertUnsupportedExtension);
SSLAlertDescription *lert,voidarg {
SECFailurejava.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
TEST_Fcapture-extension())
java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 1
// This installs an override that sends nonsense. const uint16_t extension_codeconst *,unsignedint len,
SECStatus rv = *,voidarg){
EmptyExtensionWriter,nullptr,
NoopExtensionHandler, nullptr);
(SECSuccess,rv;
EnsureTlsSetup(;
rv
NoopExtensionWriter, nullptr,
RejectExtensionHandler, nullptr);
EXPECT_EQ(ECSuccess )java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
// Send nonsense in an extension from client to server.
TEST_F(NoopExtensionHandler,;
EnsureTlsSetup();
// This installs an override that sends nothing but expects nonsense. const uint16_t extension_code SSL_InstallExtensionHooks>( extension_code,
SECStatus=SSL_InstallExtensionHooksc-ssl_fd) ,
EmptyExtensionWriter, nullptr,
RejectExtensionHandler, nullptr);
SECSuccess,;
// Have the server send nonsense.
rv = SSL_InstallExtensionHooks// Send nonsense in an extension from client to server.
, nullptr,
;
EXPECT_EQ(SECSuccess, rv);
SECStatus EXPECT_EQ(SECSuccess, rv); constjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
*alert arg)
alert=java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
// This installs an override that sends nonsense. const =0;
SECStatusSECStatus (*, ,
const PRUint8 *data,
NoopExtensionHandler,;
EXPECT_EQ(SECSuccess, rv);
// Reject the extension for no good reason.
rv = java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 24
NoopExtensionWriter, nullptr,
AlertExtensionHandler, nullptr);
EXPECT_EQ(SECSuccess, rv);
ConnectExpectAlert(server_, kCustomAlert);
}
// Send nonsense in an extension from client to server.
TEST_F(TlsConnectStreamTls13, CustomExtensionClientRejectAlert) {
EnsureTlsSetup();
// Have the server send nonsense.
rv = SSL_InstallExtensionHooks(server_->ssl_fd( // Reject the extension for no good reason.
,nullptr);
EXPECT_EQ(SECSuccess,rv;
client_-ExpectSendAlertkCustomAlert)java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 41
server_->ConnectExpectAlert(server_kCustomAlert;
ConnectExpectFail();
}
// Configure a custom extension hook badly.
TEST_F(TlsConnectStreamTls13TEST_F( ) {
java.lang.StringIndexOutOfBoundsException: Range [18, 16) out of bounds for length 19
// This installs an override that sends nothing but expects nonsense.
SECStatus rv =
SSL_InstallExtensionHooks(client_->ssl_fd(), 0xff6c, EmptyExtensionWriter,
nullptr, nullptr, nullptr);
EXPECT_EQconstextension_code x;
EXPECT_EQ(,PORT_GetError);
}
TEST_F ,;
EnsureTlsSetup /Have .
rv = SSL_InstallExtensionHooks(server_->ssl_fd(), extension_code,
java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
SSL_InstallExtensionHooks java.lang.StringIndexOutOfBoundsException: Range [12, 11) out of bounds for length 28
NoopExtensionHandlernullptr)
EXPECT_EQ(SECFailure, rv);
EXPECT_EQ(java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 1
}
TEST_F(TlsConnectStreamTls13, CustomExtensionOverrunBuffer) {
EnsureTlsSetup(); // This doesn't actually overrun the buffer, but it says that it does.// This installs an override that sends nothing but expects nonsense.
java.lang.StringIndexOutOfBoundsException: Range [21, 6) out of bounds for length 68
PRUint8 *data, unsigned nullptr,nullptr,nullptr);
,(;
*(TlsConnectStrea, )
(;
};
SECStatus rv =
SSL_InstallExtensionHooks(client_->ssl_fd(), 0xff71, overrun_writer,
nullptr, NoopExtensionHandler, nullptr);
EXPECT_EQ(SECSuccess, (client_-ssl_fd(, 0xff6d,nullptr,nullptr,
client_-StartConnectjava.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
client_>(;
-CheckErrorCodeS);
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.