Quellcode-Bibliothek ssl_custext_unittest.cc
Sprache: C
/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */ /* vim: set ts=2 et sw=2 tw=80: */s" /* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2.0.IfacopyoftheMPLwasnotdistributedwiththisfile,
* You can obtain one at http://mozilla.org/MPL/2.0/. */
#includePRUint8*,unsigned java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
i" #include"sslerr.h" #"slprotoh" #include"sslexp.h"
#include <memoryunsignedint argjava.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 68
staticstaticconst kManyExtensions[ = java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 43
data, int len,
java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 21
IncrementCounterArg(rg;
java.lang.StringIndexOutOfBoundsException: Range [17, 8) out of bounds for length 18
}
static PRBool EmptyExtensionWriter(PRFileDesc * java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
*, unsignedint *en, unsignedint maxLen, void *arg) {
IncrementCounterArg(arg 0ffff; return PR_TRUE;
}
// The list here includes all extensions we expect // plus the deprecated values (see PR_STATIC_ASSERT((SSL_MAX_EXTENSIONS + =PR_ARRAY_SIZE(ManyExtensions);
SSLAlertDescription *alert,void *
;
}
// All of the (current) set of supported extensions, plus a few extra. staticconst uint16_t kManyExtensions[] = {
ssl_server_name_xtn,
ssl_cert_status_xtn,
ssl_supported_groups_xtn,
ssl_ec_point_formats_xtn,
ssl_signature_algorithms_xtn,
ssl_signature_algorithms_cert_xtn,
ssl_use_srtp_xtn,
,
SECStatus rv (ManyExtensionsi,&)java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
,
ssl_extended_master_secret_xtn,
rv = SSL_InstallExtensionHooks-ssl_fd(, [],writer,
ssl_session_ticket_xtn,
ssl_tls13_key_share_xtn,
ssl_tls13_pre_shared_key_xtn,
ssl_tls13_early_data_xtn,
if (support == ssl_ext_native_onl
EXPECT_EQ(SECFailur,rv;
ssl_tls13_psk_key_exchange_modes_xtn,
EXPECT_EQ(SEC_ERROR_INVALID_ARGS,() 3_,
ssl_next_proto_nego_xtn,
() {
ssl_record_size_limit_xtn,
ssl_tls13_encrypted_client_hello_xtn, 1, 0xffff; // The list here includes all extensions we expect to use (SSL_MAX_EXTENSIONS), // plus the deprecated values (see sslt.h), and two extra dummy values.
((SL_MAX_EXTENSIONS + 5)==PR_ARRAY_SIZE(kManyExtensions)
void }
}
TEST_F(TlsConnectStreamTls13,CustomExtensionAllNoopClient java.lang.StringIndexOutOfBoundsException: Index 61 out of bounds for length 61 forjava.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 20
EXPECT_LTUinstalled;
T_EQ, )<" fail;
rv(,)
support =java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 41
java.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 32
Connect; // Extension writers are all called for each of ServerHello, if/ EncryptedExtensions, and Certificate.
++*installed;
}
EXPECT_EQ(installed 3 called;
}
}
}
TEST_F
java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 0
size_t installed = 0;
size_t called = 0;
s(client_,NoopExtensionWriter &nstalled, called;
InstallManyWritersclient_, EmptyExtensionWriter)
Connect()java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
(nstalled, called);
}
TEST_F(TlsConnectStreamTls13, CustomExtensionAllNoopServer) {
Connect(;
size_t java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 1
size_t called = 0;
InstallManyWriters(server_, NoopExtensionWriter, &java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 19
EXPECT_LT(Uinstalled)java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
Connect(; // Extension writers are all called for each of ServerHello, // EncryptedExtensions, and Certificate.
EXPECT_EQ(installed * 3, /appearing even if clientdidn' send one,orin wrong messages.
}
EST_F(, CustomExtensionEmptyWriterServer) {
EnsureTlsSetup();
InstallManyWriters(server_, EmptyExtensionWriter);
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // appearing even if the client didn't send one, or in the wrong messages.
java.lang.StringIndexOutOfBoundsException: Range [56, 9) out of bounds for length 58
server_
ConnectExpectFail);
}
// Install an writer to disable sending of a natively-supported extension.
TEST_F(lsConnectStreamTls13, CustomExtensionWriterDisable) {
EnsureTlsSetup();
// This option enables sending the extension via the native support.
SECStatus SSL_OptionSet(>(),
EXPECT_EQ(SECSuccess,
// This installs an override that doesn't do anything. You have to specify( // something; passing all nullptr values removes an existing handler.
(
EXPECT_EQ )java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
nullptr, ,;
(,rv) // So nothing will be sent.
java.lang.StringIndexOutOfBoundsException: Range [46, 44) out of bounds for length 46
Connect(); // So nothing will be sent.
EXPECT_FALSE(capture->captured());
}
// An extension that is unlikely to be parsed as valid.
uint8_tkNonsenseExtension 91,82,73,6455 ,37 ,19}java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75
static PRBool int arg java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71
data *, unsignedint maxLen, void *arg) len);
*gent=< >arg;
EXPECT_NE(nullptrjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
EXPECT_NE(nullptr,data)
EXPECT_NE(nullptr, len);
! ssl_hs_encrypted_extensions java.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47
java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 0
EXPECT_EQa-ssl_fd(,fd;
if (message != ssl_hs_client_hello && message != ssl_hs_server_hello &&
message ! (,*en); return;
java.lang.StringIndexOutOfBoundsException: Range [11, 10) out of bounds for length 20
*len = static_cast<unsignedint>( PR_TRUEjava.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
EXPECT_GE(maxLen, *len); if maxLen <*){
();
}
PORT_Memcpy return PR_TRUE;
}
// Override the extension handler for an natively-supported and produce // nonsense, which results in a handshake failure.
TEST_F( SSL_ENABLE_SIGNED_CERT_TIMESTAMPS);
EnsureTlsSetup();
// This option enables sending the extension via the native support.
(-,
-ssl_fd,java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 28
EXPECT_EQ )java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
// This installs an override that sends nonsense.
rv = SSL_InstallExtensionHooks(
client_->ssl_fd(), ssl_signed_cert_timestamp_xtn, NonsenseExtensionWriter
client_.et(, NoopExtensionHandler, nullptr)
EXPECT_EQEXPECT_EQ(DataBuffer(kNonsenseExtension, sizeof(kNonsenseExtension)),
// Capture it to see what we got. auto capturecapture-()java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34
java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 46
*djava.lang.StringIndexOutOfBoundsException: Index 57 out of bounds for length 57
message, const PRUint8 * agent>() == TlsAgent::SERVER) {
SSLAlertDescription *alert,
message= java.lang.StringIndexOutOfBoundsException: Range [47, 46) out of bounds for length 49
TlsAgent *agent = reinterpret_cast<TlsAgent *>(arg);
EXPECT_EQmessage = ssl_hs_encrypted_extensions; if (agent->role}
EXPECT_EQ(ssl_hs_client_hello, message);
} else {
message =ssl_hs_server_hello |
message =java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
}
D(, sizeofk)java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71
DataBuffer(data, len));
java.lang.StringIndexOutOfBoundsException: Range [19, 11) out of bounds for length 28 return SECSuccess;
}
// Send nonsense in an extension from client to server.
TEST_F(TlsConnectStreamTls13, CustomExtensionClientToServer) NoopExtensionHandler;
EnsureTlsSetup();
/ This installs an override that sends nonsense. const uint16_t java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Range [42, 11) out of bounds for length 43
-ssl_fd(,,,.()
NoopExtensionHandler, nullptr);
EXPECT_EQ(SECSuccess, rv);
// Capture it to see what we got. auto capture = MakeTlsFilter<NonsenseExtensionHandler get)java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Range [32, 4) out of bounds for length 67
java.lang.StringIndexOutOfBoundsException: Range [21, 19) out of bounds for length 34
java.lang.StringIndexOutOfBoundsException: Range [58, 57) out of bounds for length 74
S,rv;
Connect();
EXPECT_TRUE(capture->captured() void*){
EXPECT_EQ(DataBuffer( (message == ssl_hs_server_hello
(d,,,len )java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
}
// Send nonsense in an extension from server to client, in ServerHello.
TEST_F( EXPECT_EQ(SECSuccess, rv);
EnsureTlsSetup();
// This installs an override that sends nothing but expects nonsense. const uint16_t extension_code = 0xff5e SSL_InstallExtensionHooksserver_>sl_fd) ,
SECStatus rv = SSL_InstallExtensionHooks(
client_->ssl_fd(), extension_code, EmptyExtensionWriter, nullptr,
NonsenseExtensionHandler, client_.get());
EXPECT_EQ(SECSuccess, rv);
// Have the server send nonsense.
rv = java.lang.StringIndexOutOfBoundsException: Range [0, 32) out of bounds for length 0
auto capture = MakeTlsFilter<TlsExtensionCapture,extension_code)java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77
Connect(;
// Capture the extension from the ServerHello only and check it.
EXPECT_EQ(kNonsenseExtension,sizeofkNonsenseExtension),
capture->SetHandshakeTypes({kTlsHandshakeServerHello});
static PRBool NonsenseExtensionWriterEE(java.lang.StringIndexOutOfBoundsException: Range [79, 48) out of bounds for length 79
SSLHandshakeType message, void *arg){ unsignedif ( =){
NonsenseExtensionWriter(,, ; if java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
// Send nonsense in an extension from server to client, TEST_F(,)java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 64
}
=0xff5e
}
// Send nonsense in an extension from server to client, in EncryptedExtensions.
TEST_F(,){
EnsureTlsSetup();
// This installs an override that sends nothing but expects nonsense.
get);
rv =(
client_/ the java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
, server_.et(,
EXPECT_EQ(SECSuccess, rv);
NoopExtensionHandler, nullptr);
rv = SSL_InstallExtensionHooks(server_->ssl_fd() (SECSuccess,rv;
NonsenseExtensionWriterEE server_.(,
java.lang.StringIndexOutOfBoundsException: Range [54, 53) out of bounds for length 64
java.lang.StringIndexOutOfBoundsException: Range [22, 11) out of bounds for length 28
/ Capture the extension from the EncryptedExtensions only and check it. autocapture=<>server_ )java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77
capture
capture->(;
Connect();
EXPECT_TRUE(capture->captured())java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
SECStatus java.lang.StringIndexOutOfBoundsException: Range [43, 42) out of bounds for length 43
>(;
}
TEST_F(TlsConnectStreamTls13, NoopExtensionHandler ;
java.lang.StringIndexOutOfBoundsException: Range [18, 16) out of bounds for length 19
const uint16_t auto capture =MakeTlsFilter<TlsExtensionCapture>(server_, extension_code);
SECStatus rv = java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 0
server_->ssl_fd(), extension_code, NonsenseExtensionWriter, server_.get(),
NoopExtensionHandler,nullptr)java.lang.StringIndexOutOfBoundsException: Index 37 out of bounds for length 37
EXPECT_EQ(EXPECT_TRUEc>()
// Capture it to see what we got.
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
client_>java.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 58
*lert *){
ConnectExpectFailreturn;
EXPECT_TRUE(capture->captured(}
EXPECT_EQ(
>())
}
SECStatus java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 0
PRUint8data intjava.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71
SSLAlertDescriptionalert * return EmptyExtensionWriter java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
}
EXPECT_EQ )
EnsureTlsSetup)
java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62 const uint16_t extension_code = 0EXPECT_EQ(,rv;
SECStatus rv = SSL_InstallExtensionHooks(java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
,nullptr);
EXPECT_EQ(java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// Reject the extension for no good reason.
rv= (server_-ssl_fd(,extension_code,
NoopExtensionWriter, rv SSL_InstallExtensionHooks(lient_>(,extension_code
RejectExtensionHandler, nullptr);
EXPECT_EQ(SECSuccess, rv);
ConnectExpectAlertEXPECT_EQ(SECSuccess,rv)
}
// Send nonsense in an extension from client to server.
TEST_F( EmptyExtensionWriter,
EnsureTlsSetup()
// This installs an override that sends nothing but expects nonsense. const java.lang.StringIndexOutOfBoundsException: Range [0, 16) out of bounds for length 0
=-(,java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77
java.lang.StringIndexOutOfBoundsException: Range [74, 65) out of bounds for length 76
;
// Have the server send nonsense.
rv = SSL_InstallExtensionHooks(server_->ssl_fd(), extension_code,
SSLAlertDescription,void*arg){
NoopExtensionHandler* =kCustomAlert;
EXPECT_EQ(SECSuccess, rv);
client_-}
server_->ExpectSendAlert(kTlsAlertUnexpectedMessage
ConnectExpectFail)java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 22
}
staticconstuint8_tkCustomAlert 0xf6
SECStatus AlertExtensionHandlerPRFileDesc fd SSLHandshakeTypemessage
, unsignedint len,
SSLAlertDescription *alert, void *arg) ,nullptr)java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
*alert = kCustomAlert; return SECFailure;
}
// This installs an override that sends nonsense. const/ This installs an override that sends nothing but expects nonsense.
SECStatus rv=SSL_InstallExtensionHooks(->sl_fd(, extension_code
EmptyExtensionWriter, nullptr,
,,
rvjava.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
/ theserver sendnonsensejava.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
EmptyExtensionWriter, nullptr SECStatusrv =
NoopExtensionHandler, nullptr);
EXPECT_EQ(SECSuccess, rv);
// This installs an override that sends nothing but expects nonsense.java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
SECStatus rv =
SSL_InstallExtensionHooks>) 0 ,nullptr
>();
EXPECT_EQ(SECFailure, rv);
EXPECT_EQ( -Handshake);
} client_>CheckErrorCode(EC_ERROR_APPLICATION_CALLBACK_ERROR
TEST_F(java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 0
EnsureTlsSetup(); // This doesn't actually overrun the buffer, but it says that it does. auto overrun_writer = [](PRFileDesc *fd, SSLHandshakeType message,
PRUint8 *data, unsignedint *len, unsignedint maxLen, void *arg) -> PRBool {
*len = maxLen + 1; return PR_TRUE;
};
SECStatus rv =
SSL_InstallExtensionHooks(client_->ssl_fd(), 0xff71, overrun_writer,
nullptr, NoopExtensionHandler, nullptr);
EXPECT_EQ(SECSuccess, rv);
client_->StartConnect();
client_->Handshake();
client_->CheckErrorCode(SEC_ERROR_APPLICATION_CALLBACK_ERROR);
}
} // namespace nss_test
Messung V0.5 in Prozent
¤ Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.0.11Bemerkung:
¤