openssl/test
Rich Salz 12fb8c3d2d Add DRBG random method
Ported from the last FIPS release, with DUAL_EC and SHA1 and the
self-tests removed.  Since only AES-CTR is supported, other code
simplifications were done.  Removed the "entropy blocklen" concept.

Moved internal functions to new include/internal/rand.h.

Reviewed-by: Paul Dale <paul.dale@oracle.com>
(Merged from https://github.com/openssl/openssl/pull/3789)
2017-07-19 03:25:16 -04:00
..
certs Cleanup some copyright stuff 2017-06-30 21:56:44 -04:00
ct
d2i-tests
ocsp-tests
ossl_shim Cleanup some copyright stuff 2017-06-30 21:56:44 -04:00
recipes Add DRBG random method 2017-07-19 03:25:16 -04:00
smime-certs
ssl-tests Add additional ECDSA/Ed25519 selection tests. 2017-07-13 12:38:42 +01:00
testlib
testutil testutil: stanza files are text files, open them as such 2017-07-15 19:11:31 +02:00
aborttest.c
afalgtest.c
asn1_encode_test.c TAP line filter BIO. 2017-06-22 09:35:08 +10:00
asn1_internal_test.c
asynciotest.c
asynctest.c
bad_dtls_test.c
bftest.c Test cleaning and modernisation 2017-07-14 07:35:17 +10:00
bio_enc_test.c
bioprinttest.c
bntest.c Fix some issues raise by coverity in the tests. 2017-07-14 07:31:29 +10:00
bntests.pl
build.info Add DRBG random method 2017-07-19 03:25:16 -04:00
CAss.cnf
CAssdh.cnf
CAssdsa.cnf
CAssrsa.cnf
casttest.c
CAtsa.cnf
chacha_internal_test.c
cipher_overhead_test.c
cipherbytes_test.c
cipherlist_test.c Remove uses of the TEST_check macro. 2017-06-23 07:41:01 +10:00
clienthellotest.c
cms-examples.pl
constant_time_test.c Fix the constant time 64 test 2017-06-23 17:22:38 +01:00
crltest.c
ct_test.c Fix compiler warnings 2017-07-05 13:40:23 +10:00
d2i_test.c
danetest.c Fix some issues raise by coverity in the tests. 2017-07-14 07:31:29 +10:00
danetest.in
danetest.pem
destest.c
dhtest.c Test cleaning and modernisation 2017-07-14 07:35:17 +10:00
drbgtest.c Add DRBG random method 2017-07-19 03:25:16 -04:00
drbgtest.h Add DRBG random method 2017-07-19 03:25:16 -04:00
dsatest.c Use randomness not entropy 2017-06-27 12:14:49 -04:00
dtls_mtu_test.c
dtlstest.c
dtlsv1listentest.c
ecdsatest.c Fix build with no-threads no-ec 2017-06-30 19:55:47 +01:00
ecstresstest.c
ectest.c BN_pseudo_rand is really BN_rand 2017-07-03 19:26:56 -04:00
enginetest.c Test cleaning and modernisation 2017-07-14 07:35:17 +10:00
evp_extra_test.c
evp_test.c Fix some issues raise by coverity in the tests. 2017-07-14 07:31:29 +10:00
evp_test.h
exdatatest.c
exptest.c Fix some issues raise by coverity in the tests. 2017-07-14 07:31:29 +10:00
generate_buildtest.pl
generate_ssl_tests.pl
gmdifftest.c
handshake_helper.c Address Coverity issues. 2017-07-17 06:59:45 +10:00
handshake_helper.h
hmactest.c Test cleaning and modernisation 2017-07-14 07:35:17 +10:00
ideatest.c
igetest.c
lhash_test.c
md2test.c
mdc2_internal_test.c
mdc2test.c
memleaktest.c
modes_internal_test.c
P1ss.cnf
P2ss.cnf
packettest.c
pbelutest.c Fix some issues raise by coverity in the tests. 2017-07-14 07:31:29 +10:00
pemtest.c
pkcs7-1.pem
pkcs7.pem
pkey_meth_test.c
pkits-test.pl
poly1305_internal_test.c
randtest.c
rc2test.c
rc4test.c
rc5test.c
README Test cleaning and modernisation 2017-07-14 07:35:17 +10:00
README.external
README.ssltest.md
recordlentest.c
rsa_test.c Test cleaning and modernisation 2017-07-14 07:35:17 +10:00
run_tests.pl test/run_tests.pl: Make sure to exit with a code that's understood universally 2017-07-07 11:31:03 +02:00
sanitytest.c
secmemtest.c
serverinfo2.pem
serverinfo.pem
session.pem Update the test/session.pem to have a tick_nonce value 2017-07-07 15:02:09 +01:00
shibboleth.pfx
shlibloadtest.c
siphash_internal_test.c
smcont.txt
srptest.c
ssl_cert_table_internal_test.c Add sanity test for certificate table 2017-07-13 12:38:42 +01:00
ssl_test_ctx_test.c Remove uses of the TEST_check macro. 2017-06-23 07:41:01 +10:00
ssl_test_ctx_test.conf
ssl_test_ctx.c Remove uses of the TEST_check macro. 2017-06-23 07:41:01 +10:00
ssl_test_ctx.h
ssl_test.c Remove the TEST_check macro. 2017-07-05 07:56:22 +10:00
ssl_test.tmpl
sslapitest.c Add a test for SSL_clear() 2017-07-18 17:35:47 +01:00
sslcorrupttest.c Remove uses of the TEST_check macro. 2017-06-23 07:41:01 +10:00
ssltest_old.c Test cleaning and modernisation 2017-07-14 07:35:17 +10:00
ssltestlib.c
ssltestlib.h
Sssdsa.cnf
Sssrsa.cnf
stack_test.c
test_test.c
test.cnf
testcrl.pem
testdsa.pem
testdsapub.pem
testec-p256.pem
testecpub-p256.pem
testp7.pem
testreq2.pem
testrsa.pem
testrsapub.pem
testsid.pem
testutil.h Remove the TEST_check macro. 2017-07-05 07:56:22 +10:00
testx509.pem
threadstest.c
time_offset_test.c
tls13encryptiontest.c
tls13secretstest.c Update tls13_hkdf_expand() to take the length of the data 2017-07-07 15:02:09 +01:00
uitest.c Remove the possibility to disable the UI module entirely 2017-07-03 07:51:04 +02:00
Uss.cnf
v3-cert1.pem
v3-cert2.pem
v3ext.c
v3nametest.c
verify_extra_test.c
wpackettest.c
x509_check_cert_pkey_test.c
x509_dup_cert_test.c
x509_internal_test.c
x509_time_test.c
x509aux.c

How to add recipes
==================

For any test that you want to perform, you write a script located in
test/recipes/, named {nn}-test_{name}.t, where {nn} is a two digit number and
{name} is a unique name of your choice.

Please note that if a test involves a new testing executable, you will need to
do some additions in test/Makefile.  More on this later.


Naming conventions
=================

A test executable is named test/{name}test.c

A test recipe is named test/recipes/{nn}-test_{name}.t, where {nn} is a two
digit number and {name} is a unique name of your choice.

The number {nn} is (somewhat loosely) grouped as follows:

00-04  sanity, internal and essential API tests
05-09  individual symmetric cipher algorithms
10-14  math (bignum)
15-19  individual asymmetric cipher algorithms
20-24  openssl commands (some otherwise not tested)
25-29  certificate forms, generation and verification
30-35  engine and evp
60-79  APIs
   70  PACKET layer
80-89  "larger" protocols (CA, CMS, OCSP, SSL, TSA)
90-98  misc
99     most time consuming tests [such as test_fuzz]


A recipe that just runs a test executable
=========================================

A script that just runs a program looks like this:

    #! /usr/bin/perl

    use OpenSSL::Test::Simple;

    simple_test("test_{name}", "{name}test", "{name}");

{name} is the unique name you have chosen for your test.

The second argument to `simple_test' is the test executable, and `simple_test'
expects it to be located in test/

For documentation on OpenSSL::Test::Simple, do
`perldoc test/testlib/OpenSSL/Test/Simple.pm'.


A recipe that runs a more complex test
======================================

For more complex tests, you will need to read up on Test::More and
OpenSSL::Test.  Test::More is normally preinstalled, do `man Test::More' for
documentation.  For OpenSSL::Test, do `perldoc test/testlib/OpenSSL/Test.pm'.

A script to start from could be this:

    #! /usr/bin/perl

    use strict;
    use warnings;
    use OpenSSL::Test;

    setup("test_{name}");

    plan tests => 2;                # The number of tests being performed

    ok(test1, "test1");
    ok(test2, "test1");

    sub test1
    {
        # test feature 1
    }

    sub test2
    {
        # test feature 2
    }


Changes to test/build.info
==========================

Whenever a new test involves a new test executable you need to do the
following (at all times, replace {NAME} and {name} with the name of your
test):

* add {name} to the list of programs under PROGRAMS_NO_INST

* create a three line description of how to build the test, you will have
to modify the include paths and source files if you don't want to use the
basic test framework:

    SOURCE[{name}]={name}.c
    INCLUDE[{name}]=.. ../include
    DEPEND[{name}]=../libcrypto libtestutil.a

Generic form of C test executables
==================================

    #include "testutil.h"

    static int my_test(void)
    {
        int testresult = 0;                 /* Assume the test will fail    */
        int observed;

        observed = function();              /* Call the code under test     */
        if (!TEST_int_equal(observed, 2))   /* Check the result is correct  */
            goto end;                       /* Exit on failure - optional   */

        testresult = 1;                     /* Mark the test case a success */
    end:
        cleanup();                          /* Any cleanup you require      */
        return testresult;
    }

    void register_tests(void)
    {
        ADD_TEST(my_test);                  /* Add each test separately     */
    }

You should use the TEST_xxx macros provided by testutil.h to test all failure
conditions.  These macros produce an error message in a standard format if the
condition is not met (and nothing if the condition is met).  Additional
information can be presented with the TEST_info macro that takes a printf
format string and arguments.  TEST_error is useful for complicated conditions,
it also takes a printf format string and argument.  In all cases the TEST_xxx
macros are guaranteed to evaluate their arguments exactly once.  This means
that expressions with side effects are allowed as parameters.  Thus,

    if (!TEST_ptr(ptr = OPENSSL_malloc(..)))

works fine and can be used in place of:

    ptr = OPENSSL_malloc(..);
    if (!TEST_ptr(ptr))

The former produces a more meaningful message on failure than the latter.