openssl/test
Matt Caswell f01344cb5c Do not reset SNI data in SSL_do_handshake()
PR #3783 introduce coded to reset the server side SNI state in
SSL_do_handshake() to ensure any erroneous config time SNI changes are
cleared. Unfortunately SSL_do_handshake() can be called mid-handshake
multiple times so this is the wrong place to do this and can mean that
any SNI data is cleared later on in the handshake too.

Therefore move the code to a more appropriate place.

Fixes #7014

Reviewed-by: Tim Hudson <tjh@openssl.org>
Reviewed-by: Viktor Dukhovni <viktor@openssl.org>
Reviewed-by: Ben Kaduk <kaduk@mit.edu>
(Merged from https://github.com/openssl/openssl/pull/7149)
2018-09-07 18:24:59 +01:00
..
certs Limit scope of CN name constraints 2018-05-23 11:12:13 -04:00
ct
d2i-tests
ocsp-tests
ossl_shim Fix BoringSSL external test failures 2018-08-22 15:15:19 +01:00
recipes Do not reset SNI data in SSL_do_handshake() 2018-09-07 18:24:59 +01:00
smime-certs
ssl-tests Add a test for RSA key exchange with both RSA and RSA-PSS certs 2018-09-04 11:28:01 +01:00
testutil testutil/driver.c: Fix function prototype warning [-Wstrict-prototypes] 2018-06-22 01:04:34 +02:00
aborttest.c
afalgtest.c
asn1_encode_test.c
asn1_internal_test.c test/asn1_internal_test.c: silence the new check for the ASN1 method table 2018-08-07 23:35:06 +02:00
asn1_string_table_test.c
asn1_time_test.c
asynciotest.c Update code for the final RFC version of TLSv1.3 (RFC8446) 2018-08-15 12:33:30 +01:00
asynctest.c Update copyright year 2018-05-29 13:16:04 +01:00
bad_dtls_test.c
bftest.c
bio_callback_test.c
bio_enc_test.c
bioprinttest.c
bntest.c Fixed range of random produced in BN_is_prime_fasttest_ex() to be 1 < rand < w-1. It was using 1<= rand < w (which is wrong by 1 on both ends) 2018-06-22 07:07:20 +10:00
bntests.pl
build.info Do not reset SNI data in SSL_do_handshake() 2018-09-07 18:24:59 +01:00
CAss.cnf
CAssdh.cnf
CAssdsa.cnf
CAssrsa.cnf
casttest.c
CAtsa.cnf
chacha_internal_test.c
cipher_overhead_test.c
cipherbytes_test.c
cipherlist_test.c Use void in all function definitions that do not take any arguments 2018-05-11 14:37:48 +02:00
ciphername_test.c
clienthellotest.c
cms-examples.pl
cmsapitest.c Add a CMS API test 2018-05-08 08:43:39 +01:00
conf_include_test.c NCONF_get_number refix. 2018-07-11 09:03:22 +10:00
constant_time_test.c
crltest.c
ct_test.c
ctype_internal_test.c
curve448_internal_test.c
d2i_test.c
danetest.c
danetest.in
danetest.pem
destest.c
dhtest.c Update copyright year 2018-05-29 13:16:04 +01:00
drbg_cavs_data.c
drbg_cavs_data.h
drbg_cavs_test.c
drbgtest.c Use void in all function definitions that do not take any arguments 2018-05-11 14:37:48 +02:00
drbgtest.h
dsa_no_digest_size_test.c Add test for DSA signatures of raw digests of various sizes 2018-07-29 21:27:36 +02:00
dsatest.c
dtls_mtu_test.c Update copyright year 2018-05-29 13:16:04 +01:00
dtlstest.c Fix no-ec in combination with no-dh 2018-05-22 13:21:24 +01:00
dtlsv1listentest.c Update copyright year 2018-05-29 13:16:04 +01:00
ecdsatest.c
ecstresstest.c Use the new non-curve type specific EC functions internally 2018-07-31 09:08:38 +01:00
ectest.c Use the new non-curve type specific EC functions internally 2018-07-31 09:08:38 +01:00
enginetest.c
errtest.c Save and restore the Windows error around TlsGetValue. 2018-05-23 17:34:54 -04:00
evp_extra_test.c Add test case for SM2 evp verification 2018-09-07 18:12:26 +08:00
evp_test.c Add a helper routine so that evp_test can compare memory without producing 2018-08-20 06:52:11 +10:00
evp_test.h
exdatatest.c Update copyright year 2018-05-29 13:16:04 +01:00
exptest.c
fatalerrtest.c
generate_buildtest.pl Update copyright year 2018-05-29 13:16:04 +01:00
generate_ssl_tests.pl
gmdifftest.c
gosttest.c Add a GOST test 2018-07-13 18:14:43 +01:00
handshake_helper.c Change Post Handshake auth so that it is opt-in 2018-08-20 15:14:01 +01:00
handshake_helper.h
hmactest.c
ideatest.c
igetest.c
lhash_test.c
md2test.c
mdc2_internal_test.c Update copyright year 2018-05-29 13:16:04 +01:00
mdc2test.c
memleaktest.c
modes_internal_test.c Use void in all function definitions that do not take any arguments 2018-05-11 14:37:48 +02:00
ocspapitest.c
P1ss.cnf
P2ss.cnf
packettest.c
pbelutest.c
pemtest.c Fix the comment of PEM_read_bio_ex 2018-09-03 20:35:11 +08:00
pkcs7-1.pem
pkcs7.pem
pkey_meth_kdf_test.c Update copyright year 2018-05-29 13:16:04 +01:00
pkey_meth_test.c Update copyright year 2018-05-29 13:16:04 +01:00
pkits-test.pl
poly1305_internal_test.c
rc2test.c
rc4test.c
rc5test.c
rdrand_sanitytest.c Use void in all function definitions that do not take any arguments 2018-05-11 14:37:48 +02:00
README
README.external
README.ssltest.md
recordlentest.c
rsa_mp_test.c
rsa_test.c
run_tests.pl Update copyright year 2018-05-01 13:34:30 +01:00
sanitytest.c Relocate memcmp test. 2018-08-07 10:51:01 +10:00
secmemtest.c Zero memory in CRYPTO_secure_malloc. 2018-08-22 09:20:18 +10:00
serverinfo2.pem
serverinfo.pem
servername_test.c Do not reset SNI data in SSL_do_handshake() 2018-09-07 18:24:59 +01:00
session.pem Don't store the ticket nonce in the session 2018-06-07 10:58:35 +01:00
shibboleth.pfx
shlibloadtest.c Extend dladdr() for AIX, consequence from changes for openssl#6368. 2018-08-22 21:50:33 +02:00
siphash_internal_test.c
sm2_internal_test.c Make SM2 ID stick to specification 2018-09-07 18:12:26 +08:00
sm4_internal_test.c
smcont.txt
srptest.c
ssl_cert_table_internal_test.c Use void in all function definitions that do not take any arguments 2018-05-11 14:37:48 +02:00
ssl_test_ctx_test.c
ssl_test_ctx_test.conf
ssl_test_ctx.c Change Post Handshake auth so that it is opt-in 2018-08-20 15:14:01 +01:00
ssl_test_ctx.h Change Post Handshake auth so that it is opt-in 2018-08-20 15:14:01 +01:00
ssl_test.c
ssl_test.tmpl
sslapitest.c Test that we can handle a PHA CertificateRequest after we sent close_notify 2018-09-07 11:15:20 +01:00
sslbuffertest.c
sslcorrupttest.c Use void in all function definitions that do not take any arguments 2018-05-11 14:37:48 +02:00
ssltest_old.c Use void in all function definitions that do not take any arguments 2018-05-11 14:37:48 +02:00
ssltestlib.c Add a bi-directional shutdown test 2018-06-27 10:03:20 +01:00
ssltestlib.h Add a bi-directional shutdown test 2018-06-27 10:03:20 +01:00
Sssdsa.cnf
Sssrsa.cnf
stack_test.c
sysdefault.cnf
sysdefaulttest.c
test_test.c Relocate memcmp test. 2018-08-07 10:51:01 +10:00
test.cnf
testcrl.pem
testdsa.pem
testdsapub.pem
testec-p256.pem
testecpub-p256.pem
testp7.pem
testreq2.pem
testrsa.pem
testrsapub.pem
testsid.pem
testutil.h
testx509.pem
threadstest.c
time_offset_test.c Update copyright year 2018-05-29 13:16:04 +01:00
tls13ccstest.c Use void in all function definitions that do not take any arguments 2018-05-11 14:37:48 +02:00
tls13encryptiontest.c Update the TLSv1.3 test vectors 2018-07-20 10:45:41 +01:00
tls13secretstest.c Update the TLSv1.3 test vectors 2018-07-20 10:45:41 +01:00
uitest.c
Uss.cnf
v3-cert1.pem
v3-cert2.pem
v3ext.c
v3nametest.c Use void in all function definitions that do not take any arguments 2018-05-11 14:37:48 +02:00
verify_extra_test.c Update copyright year 2018-05-01 13:34:30 +01:00
versions.c
wpackettest.c
x509_check_cert_pkey_test.c
x509_dup_cert_test.c
x509_internal_test.c Update copyright year 2018-05-29 13:16:04 +01:00
x509_time_test.c Update copyright year 2018-05-29 13:16:04 +01:00
x509aux.c Update copyright year 2018-06-20 15:29:23 +01:00

How to add recipes
==================

For any test that you want to perform, you write a script located in
test/recipes/, named {nn}-test_{name}.t, where {nn} is a two digit number and
{name} is a unique name of your choice.

Please note that if a test involves a new testing executable, you will need to
do some additions in test/Makefile.  More on this later.


Naming conventions
=================

A test executable is named test/{name}test.c

A test recipe is named test/recipes/{nn}-test_{name}.t, where {nn} is a two
digit number and {name} is a unique name of your choice.

The number {nn} is (somewhat loosely) grouped as follows:

00-04  sanity, internal and essential API tests
05-09  individual symmetric cipher algorithms
10-14  math (bignum)
15-19  individual asymmetric cipher algorithms
20-24  openssl commands (some otherwise not tested)
25-29  certificate forms, generation and verification
30-35  engine and evp
60-79  APIs
   70  PACKET layer
80-89  "larger" protocols (CA, CMS, OCSP, SSL, TSA)
90-98  misc
99     most time consuming tests [such as test_fuzz]


A recipe that just runs a test executable
=========================================

A script that just runs a program looks like this:

    #! /usr/bin/perl

    use OpenSSL::Test::Simple;

    simple_test("test_{name}", "{name}test", "{name}");

{name} is the unique name you have chosen for your test.

The second argument to `simple_test' is the test executable, and `simple_test'
expects it to be located in test/

For documentation on OpenSSL::Test::Simple, do
`perldoc util/perl/OpenSSL/Test/Simple.pm'.


A recipe that runs a more complex test
======================================

For more complex tests, you will need to read up on Test::More and
OpenSSL::Test.  Test::More is normally preinstalled, do `man Test::More' for
documentation.  For OpenSSL::Test, do `perldoc util/perl/OpenSSL/Test.pm'.

A script to start from could be this:

    #! /usr/bin/perl

    use strict;
    use warnings;
    use OpenSSL::Test;

    setup("test_{name}");

    plan tests => 2;                # The number of tests being performed

    ok(test1, "test1");
    ok(test2, "test1");

    sub test1
    {
        # test feature 1
    }

    sub test2
    {
        # test feature 2
    }


Changes to test/build.info
==========================

Whenever a new test involves a new test executable you need to do the
following (at all times, replace {NAME} and {name} with the name of your
test):

* add {name} to the list of programs under PROGRAMS_NO_INST

* create a three line description of how to build the test, you will have
to modify the include paths and source files if you don't want to use the
basic test framework:

    SOURCE[{name}]={name}.c
    INCLUDE[{name}]=.. ../include
    DEPEND[{name}]=../libcrypto libtestutil.a

Generic form of C test executables
==================================

    #include "testutil.h"

    static int my_test(void)
    {
        int testresult = 0;                 /* Assume the test will fail    */
        int observed;

        observed = function();              /* Call the code under test     */
        if (!TEST_int_equal(observed, 2))   /* Check the result is correct  */
            goto end;                       /* Exit on failure - optional   */

        testresult = 1;                     /* Mark the test case a success */
    end:
        cleanup();                          /* Any cleanup you require      */
        return testresult;
    }

    int setup_tests(void)
    {
        ADD_TEST(my_test);                  /* Add each test separately     */
        return 1;                           /* Indicate success             */
    }

You should use the TEST_xxx macros provided by testutil.h to test all failure
conditions.  These macros produce an error message in a standard format if the
condition is not met (and nothing if the condition is met).  Additional
information can be presented with the TEST_info macro that takes a printf
format string and arguments.  TEST_error is useful for complicated conditions,
it also takes a printf format string and argument.  In all cases the TEST_xxx
macros are guaranteed to evaluate their arguments exactly once.  This means
that expressions with side effects are allowed as parameters.  Thus,

    if (!TEST_ptr(ptr = OPENSSL_malloc(..)))

works fine and can be used in place of:

    ptr = OPENSSL_malloc(..);
    if (!TEST_ptr(ptr))

The former produces a more meaningful message on failure than the latter.