openssl/test
Benjamin Kaduk c39e4048b5 Do not set a nonzero default max_early_data
When early data support was first added, this seemed like a good
idea, as it would allow applications to just add SSL_read_early_data()
calls as needed and have things "Just Work".  However, for applications
that do not use TLS 1.3 early data, there is a negative side effect.
Having a nonzero max_early_data in a SSL_CTX (and thus, SSL objects
derived from it) means that when generating a session ticket,
tls_construct_stoc_early_data() will indicate to the client that
the server supports early data.  This is true, in that the implementation
of TLS 1.3 (i.e., OpenSSL) does support early data, but does not
necessarily indicate that the server application supports early data,
when the default value is nonzero.  In this case a well-intentioned
client would send early data along with its resumption attempt, which
would then be ignored by the server application, a waste of network
bandwidth.

Since, in order to successfully use TLS 1.3 early data, the application
must introduce calls to SSL_read_early_data(), it is not much additional
burden to require that the application also calls
SSL_{CTX_,}set_max_early_data() in order to enable the feature; doing
so closes this scenario where early data packets would be sent on
the wire but ignored.

Update SSL_read_early_data.pod accordingly, and make s_server and
our test programs into applications that are compliant with the new
requirements on applications that use early data.

Fixes #4725

Reviewed-by: Matt Caswell <matt@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/5483)
2018-02-28 21:47:09 -06:00
..
certs Modify expected output of a CRL to match the changed printout 2017-11-16 01:19:55 +01:00
ct
d2i-tests add test for CVE-2016-7053 2016-11-10 13:04:11 +00:00
ocsp-tests Fix OCSP_basic_verify() cert chain construction in case bs->certs is NULL 2017-08-16 14:32:38 -04:00
ossl_shim Update copyright year 2018-02-13 13:59:25 +00:00
recipes Adapt 15-test_out_option.t for more than just Unix 2018-02-28 18:48:05 +01:00
smime-certs Add alternative CMS P-256 cert 2017-08-10 16:48:18 +01:00
ssl-tests Enable TLSv1.3 by default 2018-02-07 21:34:18 +00:00
testutil Update copyright year 2018-02-27 13:59:42 +00:00
aborttest.c
afalgtest.c Revert "Modify test/afalgtest to fail if the afalg engine couldn't be loaded" 2018-02-07 22:18:44 +01:00
asn1_encode_test.c Update copyright year 2018-02-27 13:59:42 +00:00
asn1_internal_test.c Fix AppVeyor/VC build failure 2017-11-16 14:02:27 +01:00
asn1_string_table_test.c [Win] Fix some test method signatures ... 2017-08-16 10:36:34 -04:00
asn1_time_test.c Update copyright year 2018-02-13 13:59:25 +00:00
asynciotest.c Update ServerHello to new draft-22 format 2017-12-14 15:06:37 +00:00
asynctest.c asynctest: don't depend on apps 2017-03-28 14:40:25 +02:00
bad_dtls_test.c Remove unicode characters from source 2017-12-08 11:56:37 +01:00
bftest.c Consistent formatting for sizeof(foo) 2017-12-07 19:11:49 -05:00
bio_enc_test.c Fix no-chacha and no-poly1305 2017-08-25 11:34:08 +01:00
bioprinttest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
bntest.c Update copyright year 2018-02-13 13:59:25 +00:00
bntests.pl Make bntest be (mostly) file-based. 2016-11-28 12:26:05 -05:00
build.info Fix no-ec build 2018-02-21 11:13:15 +00:00
CAss.cnf
CAssdh.cnf
CAssdsa.cnf
CAssrsa.cnf
casttest.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
CAtsa.cnf Added support for ESSCertIDv2 2017-05-03 09:04:23 +02:00
chacha_internal_test.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
cipher_overhead_test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
cipherbytes_test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
cipherlist_test.c Update copyright year 2018-02-13 13:59:25 +00:00
ciphername_test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
clienthellotest.c Update copyright year 2018-02-13 13:59:25 +00:00
cms-examples.pl
constant_time_test.c Update copyright year 2018-02-27 13:59:42 +00:00
crltest.c Factorise duplicated code. 2017-11-13 07:52:35 -05:00
ct_test.c test/ct_test.c: remove dependency on -lm. 2018-02-26 17:48:06 +01:00
ctype_internal_test.c e_os.h removal from other headers and source files. 2017-08-30 07:20:43 +10:00
curve448_internal_test.c Update copyright year 2018-02-27 13:59:42 +00:00
d2i_test.c Consistent formatting for sizeof(foo) 2017-12-07 19:11:49 -05:00
danetest.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
danetest.in
danetest.pem
destest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
dhtest.c Allow DH_set0_key with only private key. 2017-09-26 14:48:51 +02:00
drbgtest.c DRBG: make the derivation function the default for ctr_drbg 2018-02-13 17:32:54 +01:00
drbgtest.h Add DRBG random method 2017-07-19 03:25:16 -04:00
dsatest.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
dtls_mtu_test.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
dtlstest.c add callback handler for setting DTLS timer interval 2017-09-06 08:30:00 +02:00
dtlsv1listentest.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
ecdsatest.c [Win] Fix some test method signatures ... 2017-08-16 10:36:34 -04:00
ecstresstest.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
ectest.c Consistent formatting for sizeof(foo) 2017-12-07 19:11:49 -05:00
enginetest.c Add EVP_PKEY_METHOD redirection test 2017-10-12 00:03:32 +01:00
evp_extra_test.c Fix no-ec 2017-12-08 08:29:17 -06:00
evp_test.c Don't assume shared key length matches expected length 2017-10-12 02:40:30 +01:00
evp_test.h Add support for multiple update calls in evp_test 2017-05-19 21:02:24 +01:00
exdatatest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
exptest.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
fatalerrtest.c Fix the buffer sizing in the fatalerrtest 2017-12-07 14:35:30 +00:00
generate_buildtest.pl
generate_ssl_tests.pl Consolidate the locations where we have our internal perl modules 2017-08-15 11:30:47 +02:00
gmdifftest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
handshake_helper.c Fix a gcc warning about possible fall through 2018-02-15 11:56:47 +01:00
handshake_helper.h Use ChaCha only if prioritized by clnt 2017-11-30 07:13:08 +10:00
hmactest.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
ideatest.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
igetest.c Consistent formatting for sizeof(foo) 2017-12-07 19:11:49 -05:00
lhash_test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
md2test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
mdc2_internal_test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
mdc2test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
memleaktest.c Update secmemtest and memeleaktest to use the test infrastructure. 2017-04-12 10:59:53 +01:00
modes_internal_test.c Update copyright year 2018-02-13 13:59:25 +00:00
ocspapitest.c Wrap more of ocspapitest.c in OPENSSL_NO_OCSP 2017-12-08 09:16:36 -06:00
P1ss.cnf
P2ss.cnf
packettest.c Resolve warnings in VC-WIN32 build, which allows to add /WX. 2017-11-13 10:58:57 +01:00
pbelutest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
pemtest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
pkcs7-1.pem
pkcs7.pem
pkey_meth_kdf_test.c Add PKEY_CTX setter tests for TLS1-PRF 2017-08-21 10:05:14 +01:00
pkey_meth_test.c [Win] Fix some test method signatures ... 2017-08-16 10:36:34 -04:00
pkits-test.pl Many spelling fixes/typo's corrected. 2017-11-11 19:03:10 -05:00
poly1305_internal_test.c Update copyright year 2018-02-13 13:59:25 +00:00
rc2test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
rc4test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
rc5test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
README Fix test documentation. 2017-09-08 13:58:59 -05:00
README.external Many spelling fixes/typo's corrected. 2017-11-11 19:03:10 -05:00
README.ssltest.md Session resume broken switching contexts 2017-10-04 10:21:08 +10:00
recordlentest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
rsa_mp_test.c rsa/rsa_gen.c: harmonize keygen's ability with RSA_security_bits. 2017-11-28 20:05:48 +01:00
rsa_test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
run_tests.pl test/run_tests.pl: don't use Module::Load::Conditional. 2017-09-02 20:20:51 +02:00
sanitytest.c Consistent formatting for sizeof(foo) 2017-12-07 19:11:49 -05:00
secmemtest.c Fix some Typos and indents 2017-08-11 10:16:33 -04:00
serverinfo2.pem Add a SERVERINFOV2 format test file 2017-05-03 14:37:42 +01:00
serverinfo.pem
servername_test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
session.pem Update the test/session.pem to have a tick_nonce value 2017-07-07 15:02:09 +01:00
shibboleth.pfx
shlibloadtest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
siphash_internal_test.c Update copyright year 2018-02-13 13:59:25 +00:00
sm4_internal_test.c SM4: Add SM4 block cipher to EVP 2017-10-31 15:19:14 +10:00
smcont.txt
srptest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
ssl_cert_table_internal_test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
ssl_test_ctx_test.c Use ChaCha only if prioritized by clnt 2017-11-30 07:13:08 +10:00
ssl_test_ctx_test.conf Implement Maximum Fragment Length TLS extension. 2017-11-05 17:46:48 +01:00
ssl_test_ctx.c Update copyright year 2018-02-13 13:59:25 +00:00
ssl_test_ctx.h Update copyright year 2018-02-13 13:59:25 +00:00
ssl_test.c Use ChaCha only if prioritized by clnt 2017-11-30 07:13:08 +10:00
ssl_test.tmpl
sslapitest.c Do not set a nonzero default max_early_data 2018-02-28 21:47:09 -06:00
sslbuffertest.c Fix some typo and comments 2017-08-12 20:07:17 +02:00
sslcorrupttest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
ssltest_old.c Consistent formatting for sizeof(foo) 2017-12-07 19:11:49 -05:00
ssltestlib.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
ssltestlib.h Add some tests for the new TLSv1.3 PSK code 2017-06-21 14:45:36 +01:00
Sssdsa.cnf
Sssrsa.cnf
stack_test.c Add a reserve call to the stack data structure. 2017-09-28 06:53:40 +10:00
test_test.c Test support for time_t comparisons. 2017-11-28 08:56:45 +10:00
test.cnf
testcrl.pem
testdsa.pem
testdsapub.pem
testec-p256.pem
testecpub-p256.pem
testp7.pem
testreq2.pem
testrsa.pem
testrsapub.pem
testsid.pem
testutil.h Test support for time_t comparisons. 2017-11-28 08:56:45 +10:00
testx509.pem
threadstest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
time_offset_test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
tls13ccstest.c Do not set a nonzero default max_early_data 2018-02-28 21:47:09 -06:00
tls13encryptiontest.c e_os.h removal from other headers and source files. 2017-08-30 07:20:43 +10:00
tls13secretstest.c Export keying material using early exporter master secret 2018-02-26 13:35:54 +00:00
uitest.c [Win] Fix some test method signatures ... 2017-08-16 10:36:34 -04:00
Uss.cnf
v3-cert1.pem
v3-cert2.pem
v3ext.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
v3nametest.c Update copyright year 2018-02-13 13:59:25 +00:00
verify_extra_test.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
wpackettest.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
x509_check_cert_pkey_test.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
x509_dup_cert_test.c Update the test framework so that the need for test_main is removed. Everything 2017-07-27 07:53:08 +10:00
x509_internal_test.c Iron out /WX errors in VC-WIN32. 2017-11-17 21:22:26 +01:00
x509_time_test.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00
x509aux.c Use "" not <> for internal/ includes 2017-08-22 09:54:20 -04:00

How to add recipes
==================

For any test that you want to perform, you write a script located in
test/recipes/, named {nn}-test_{name}.t, where {nn} is a two digit number and
{name} is a unique name of your choice.

Please note that if a test involves a new testing executable, you will need to
do some additions in test/Makefile.  More on this later.


Naming conventions
=================

A test executable is named test/{name}test.c

A test recipe is named test/recipes/{nn}-test_{name}.t, where {nn} is a two
digit number and {name} is a unique name of your choice.

The number {nn} is (somewhat loosely) grouped as follows:

00-04  sanity, internal and essential API tests
05-09  individual symmetric cipher algorithms
10-14  math (bignum)
15-19  individual asymmetric cipher algorithms
20-24  openssl commands (some otherwise not tested)
25-29  certificate forms, generation and verification
30-35  engine and evp
60-79  APIs
   70  PACKET layer
80-89  "larger" protocols (CA, CMS, OCSP, SSL, TSA)
90-98  misc
99     most time consuming tests [such as test_fuzz]


A recipe that just runs a test executable
=========================================

A script that just runs a program looks like this:

    #! /usr/bin/perl

    use OpenSSL::Test::Simple;

    simple_test("test_{name}", "{name}test", "{name}");

{name} is the unique name you have chosen for your test.

The second argument to `simple_test' is the test executable, and `simple_test'
expects it to be located in test/

For documentation on OpenSSL::Test::Simple, do
`perldoc util/perl/OpenSSL/Test/Simple.pm'.


A recipe that runs a more complex test
======================================

For more complex tests, you will need to read up on Test::More and
OpenSSL::Test.  Test::More is normally preinstalled, do `man Test::More' for
documentation.  For OpenSSL::Test, do `perldoc util/perl/OpenSSL/Test.pm'.

A script to start from could be this:

    #! /usr/bin/perl

    use strict;
    use warnings;
    use OpenSSL::Test;

    setup("test_{name}");

    plan tests => 2;                # The number of tests being performed

    ok(test1, "test1");
    ok(test2, "test1");

    sub test1
    {
        # test feature 1
    }

    sub test2
    {
        # test feature 2
    }


Changes to test/build.info
==========================

Whenever a new test involves a new test executable you need to do the
following (at all times, replace {NAME} and {name} with the name of your
test):

* add {name} to the list of programs under PROGRAMS_NO_INST

* create a three line description of how to build the test, you will have
to modify the include paths and source files if you don't want to use the
basic test framework:

    SOURCE[{name}]={name}.c
    INCLUDE[{name}]=.. ../include
    DEPEND[{name}]=../libcrypto libtestutil.a

Generic form of C test executables
==================================

    #include "testutil.h"

    static int my_test(void)
    {
        int testresult = 0;                 /* Assume the test will fail    */
        int observed;

        observed = function();              /* Call the code under test     */
        if (!TEST_int_equal(observed, 2))   /* Check the result is correct  */
            goto end;                       /* Exit on failure - optional   */

        testresult = 1;                     /* Mark the test case a success */
    end:
        cleanup();                          /* Any cleanup you require      */
        return testresult;
    }

    int setup_tests(void)
    {
        ADD_TEST(my_test);                  /* Add each test separately     */
        return 1;                           /* Indicate success             */
    }

You should use the TEST_xxx macros provided by testutil.h to test all failure
conditions.  These macros produce an error message in a standard format if the
condition is not met (and nothing if the condition is met).  Additional
information can be presented with the TEST_info macro that takes a printf
format string and arguments.  TEST_error is useful for complicated conditions,
it also takes a printf format string and argument.  In all cases the TEST_xxx
macros are guaranteed to evaluate their arguments exactly once.  This means
that expressions with side effects are allowed as parameters.  Thus,

    if (!TEST_ptr(ptr = OPENSSL_malloc(..)))

works fine and can be used in place of:

    ptr = OPENSSL_malloc(..);
    if (!TEST_ptr(ptr))

The former produces a more meaningful message on failure than the latter.