openssl/test
Matt Caswell ac9fc67a48 Add DTLS replay protection test
Injects a record from epoch 1 during epoch 0 handshake, with a record
sequence number in the future, to test that the record replay protection
feature works as expected. This is described more fully in the next commit.

Reviewed-by: Richard Levitte <levitte@openssl.org>
2016-08-19 13:52:40 +01:00
..
certs Extend mkcert.sh to support nameConstraints generation and more complex 2016-07-11 23:30:04 +01:00
ct
d2i-tests
ocsp-tests
recipes Add a DTLS unprocesed records test 2016-08-19 13:52:40 +01:00
smime-certs spelling fixes, just comments and readme. 2016-08-05 19:07:30 -04:00
ssl-tests Port multi-buffer tests 2016-08-18 12:46:00 +02:00
testlib/OpenSSL Run the fuzzing corpora as tests. 2016-07-01 13:45:45 +01:00
aborttest.c
afalgtest.c Handle inability to create AFALG socket 2016-06-13 17:28:40 +01:00
asynciotest.c Split create_ssl_connection() 2016-08-19 13:52:40 +01:00
asynctest.c Fix a few if(, for(, while( inside code. 2016-07-20 07:21:53 -04:00
bad_dtls_test.c Kill PACKET_starts() from bad_dtls_test 2016-08-10 12:50:51 +01:00
bftest.c
bioprinttest.c Whitespace cleanup in apps 2016-06-29 09:56:39 -04:00
bntest.c Change callers to use the new constants. 2016-08-10 10:07:37 -04:00
build.info Add a DTLS unprocesed records test 2016-08-19 13:52:40 +01:00
CAss.cnf RT3809: basicConstraints is critical 2016-06-13 09:18:22 -04:00
CAssdh.cnf
CAssdsa.cnf
CAssrsa.cnf
casttest.c
CAtsa.cnf
cipherlist_test.c
clienthellotest.c Fix clienthellotest to use PACKET functions 2016-08-10 12:50:51 +01:00
cms-examples.pl
constant_time_test.c
ct_test.c Improves CTLOG_STORE setters 2016-08-15 12:56:47 -04:00
d2i_test.c
danetest.c Perform DANE-EE(3) name checks by default 2016-07-12 10:16:34 -04:00
danetest.in Perform DANE-EE(3) name checks by default 2016-07-12 10:16:34 -04:00
danetest.pem
destest.c spelling fixes, just comments and readme. 2016-08-05 19:07:30 -04:00
dhtest.c Fix the build and tests following constification of DH, DSA, RSA 2016-06-16 13:34:44 +01:00
dsatest.c Fix the build and tests following constification of DH, DSA, RSA 2016-06-16 13:34:44 +01:00
dtlstest.c Add DTLS replay protection test 2016-08-19 13:52:40 +01:00
dtlsv1listentest.c Simplify and rename SSL_set_rbio() and SSL_set_wbio() 2016-07-29 14:09:57 +01:00
ecdhtest_cavs.h Whitespace cleanup in apps 2016-06-29 09:56:39 -04:00
ecdhtest.c
ecdsatest.c spelling fixes, just comments and readme. 2016-08-05 19:07:30 -04:00
ectest.c RT 4242: reject invalid EC point coordinates 2016-06-09 23:58:20 +02:00
enginetest.c
evp_extra_test.c
evp_test.c Check for bad filename in evp_test 2016-08-12 14:04:53 -04:00
evptests.txt Update X25519 key format in evptests.txt 2016-08-13 14:11:05 +01:00
exdatatest.c
exptest.c Change callers to use the new constants. 2016-08-10 10:07:37 -04:00
generate_buildtest.pl Move the building of test/buildtest_*. to be done unconditionally 2016-08-05 21:17:05 +02:00
generate_ssl_tests.pl Reorganize SSL test structures 2016-08-08 12:06:26 +02:00
gmdifftest.c
handshake_helper.c Test that the peers send at most one fatal alert 2016-08-18 12:49:32 +02:00
handshake_helper.h Test that the peers send at most one fatal alert 2016-08-18 12:49:32 +02:00
heartbeat_test.c
hmactest.c Fix hmac test case 6 2016-06-30 08:52:37 -04:00
ideatest.c
igetest.c
md2test.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
md4test.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
md5test.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
mdc2test.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
memleaktest.c
methtest.c
p5_crpt2_test.c Useless includes 2016-06-18 16:30:24 -04:00
P1ss.cnf
P2ss.cnf
packettest.c
pbelutest.c
pkcs7-1.pem
pkcs7.pem
pkits-test.pl
r160test.c
randtest.c
rc2test.c
rc4test.c
rc5test.c
README two typo fixes 2016-08-16 15:51:58 -04:00
README.ssltest.md Add more details on how to add a new SSL test 2016-08-19 14:50:25 +02:00
rmdtest.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
rsa_test.c Deprecate the flags that switch off constant time 2016-06-06 11:09:06 +01:00
run_tests.pl
sanitytest.c Platform sanity test 2016-07-08 15:56:55 -04:00
secmemtest.c
serverinfo.pem
sha1test.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
sha256t.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
sha512t.c check return values for EVP_Digest*() APIs 2016-07-15 14:09:05 +01:00
smcont.txt test/smcont.txt: trigger assertion in bio_enc.c. 2016-07-31 17:03:17 +02:00
srptest.c
ssl_test_ctx_test.c Port multi-buffer tests 2016-08-18 12:46:00 +02:00
ssl_test_ctx_test.conf Port multi-buffer tests 2016-08-18 12:46:00 +02:00
ssl_test_ctx.c Port multi-buffer tests 2016-08-18 12:46:00 +02:00
ssl_test_ctx.h Port multi-buffer tests 2016-08-18 12:46:00 +02:00
ssl_test.c Test that the peers send at most one fatal alert 2016-08-18 12:49:32 +02:00
ssl_test.tmpl test/ssl_test.tmpl: make it work with elderly perl. 2016-08-16 12:43:44 +02:00
sslapitest.c Split create_ssl_connection() 2016-08-19 13:52:40 +01:00
ssltest_old.c Constify char* input parameters in apps code 2016-08-17 17:09:19 +01:00
ssltestlib.c Split create_ssl_connection() 2016-08-19 13:52:40 +01:00
ssltestlib.h Split create_ssl_connection() 2016-08-19 13:52:40 +01:00
Sssdsa.cnf
Sssrsa.cnf
test.cnf
testcrl.pem
testdsa.pem
testdsapub.pem
testec-p256.pem
testecpub-p256.pem
testp7.pem
testreq2.pem
testrsa.pem
testrsapub.pem
testsid.pem
testutil.c SSL test framework: port NPN and ALPN tests 2016-07-19 14:17:48 +02:00
testutil.h Add TEST_check 2016-08-10 14:41:21 +02:00
testx509.pem
threadstest.c include/openssl: don't include <windows.h> in public headers. 2016-07-08 11:49:44 +02:00
Uss.cnf
v3-cert1.pem
v3-cert2.pem
v3ext.c Add some accessor API's 2016-06-08 11:37:06 -04:00
v3nametest.c
verify_extra_test.c Fix a few if(, for(, while( inside code. 2016-07-20 07:21:53 -04:00
wp_test.c crypto/cryptlib.c: omit OPENSSL_ia32cap_loc(). 2016-06-22 20:20:37 +02:00
x509aux.c

How to add recipes
==================

For any test that you want to perform, you write a script located in
test/recipes/, named {nn}-test_{name}.t, where {nn} is a two digit number and
{name} is a unique name of your choice.

Please note that if a test involves a new testing executable, you will need to
do some additions in test/Makefile.  More on this later.


Naming conventions
=================

A test executable is named test/{name}test.c

A test recipe is named test/recipes/{nn}-test_{name}.t, where {nn} is a two
digit number and {name} is a unique name of your choice.

The number {nn} is (somewhat loosely) grouped as follows:

05  individual symmetric cipher algorithms
10  math (bignum)
15  individual asymmetric cipher algorithms
20  openssl enc
25  certificate forms, generation and verification
30  engine and evp
70  PACKET layer
80  "larger" protocols (CA, CMS, OCSP, SSL, TSA)
90  misc


A recipe that just runs a test executable
=========================================

A script that just runs a program looks like this:

    #! /usr/bin/perl
    
    use OpenSSL::Test::Simple;
    
    simple_test("test_{name}", "{name}test", "{name}");

{name} is the unique name you have chosen for your test.

The second argument to `simple_test' is the test executable, and `simple_test'
expects it to be located in test/

For documentation on OpenSSL::Test::Simple, do
`perldoc test/testlib/OpenSSL/Test/Simple.pm'.


A recipe that runs a more complex test
======================================

For more complex tests, you will need to read up on Test::More and
OpenSSL::Test.  Test::More is normally preinstalled, do `man Test::More' for
documentation.  For OpenSSL::Test, do `perldoc test/testlib/OpenSSL/Test.pm'.

A script to start from could be this:

    #! /usr/bin/perl
    
    use strict;
    use warnings;
    use OpenSSL::Test;
    
    setup("test_{name}");
    
    plan tests => 2;                # The number of tests being performed
    
    ok(test1, "test1");
    ok(test2, "test1");
    
    sub test1
    {
        # test feature 1
    }
    
    sub test2
    {
        # test feature 2
    }
    

Changes to test/Makefile
========================

Whenever a new test involves a new test executable you need to do the
following (at all times, replace {NAME} and {name} with the name of your
test):

* among the variables for test executables at the beginning, add a line like
  this:

    {NAME}TEST= {name}test

* add `$({NAME}TEST)$(EXE_EXT)' to the assignment of EXE:

* add `$({NAME}TEST).o' to the assignment of OBJ:

* add `$({NAME}TEST).c' to the assignment of SRC:

* add the following lines for building the executable:

    $({NAME}TEST)$(EXE_EXT): $({NAME}TEST).o $(DLIBCRYPTO)
           @target=$({NAME}TEST); $(BUILD_CMD)