configtest.c revision 1.3
1/* $OpenBSD: configtest.c,v 1.3 2023/07/02 06:37:27 beck Exp $ */ 2/* 3 * Copyright (c) 2017 Joel Sing <jsing@openbsd.org> 4 * 5 * Permission to use, copy, modify, and distribute this software for any 6 * purpose with or without fee is hereby granted, provided that the above 7 * copyright notice and this permission notice appear in all copies. 8 * 9 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES 10 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 11 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR 12 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 13 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 14 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 15 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 16 */ 17 18#include <err.h> 19#include <stdio.h> 20#include <stdlib.h> 21 22#include <tls.h> 23 24struct parse_protocols_test { 25 const char *protostr; 26 int want_return; 27 uint32_t want_protocols; 28}; 29 30struct parse_protocols_test parse_protocols_tests[] = { 31 { 32 .protostr = NULL, 33 .want_return = 0, 34 .want_protocols = TLS_PROTOCOLS_DEFAULT, 35 }, 36 { 37 .protostr = "default", 38 .want_return = 0, 39 .want_protocols = TLS_PROTOCOLS_DEFAULT, 40 }, 41 { 42 .protostr = "secure", 43 .want_return = 0, 44 .want_protocols = TLS_PROTOCOLS_DEFAULT, 45 }, 46 { 47 .protostr = "all", 48 .want_return = 0, 49 .want_protocols = TLS_PROTOCOLS_ALL, 50 }, 51 { 52 .protostr = "tlsv1", 53 .want_return = 0, 54 .want_protocols = TLS_PROTOCOL_TLSv1, 55 }, 56 { 57 .protostr = "tlsv1.2", 58 .want_return = 0, 59 .want_protocols = TLS_PROTOCOL_TLSv1_2, 60 }, 61 { 62 .protostr = "tlsv1.3", 63 .want_return = 0, 64 .want_protocols = TLS_PROTOCOL_TLSv1_3, 65 }, 66 { 67 .protostr = "", 68 .want_return = -1, 69 .want_protocols = 0, 70 }, 71 { 72 .protostr = "tlsv1.0:tlsv1.1:tlsv1.2:tlsv1.3", 73 .want_return = 0, 74 .want_protocols = TLS_PROTOCOL_TLSv1_2 | TLS_PROTOCOL_TLSv1_3, 75 }, 76 { 77 .protostr = "tlsv1.0,tlsv1.1,tlsv1.2,tlsv1.3", 78 .want_return = 0, 79 .want_protocols = TLS_PROTOCOL_TLSv1_2 | TLS_PROTOCOL_TLSv1_3, 80 }, 81 { 82 .protostr = "tlsv1.1,tlsv1.2,tlsv1.0", 83 .want_return = 0, 84 .want_protocols = TLS_PROTOCOL_TLSv1_2, 85 }, 86 { 87 .protostr = "tlsv1.1,tlsv1.2,tlsv1.1", 88 .want_return = 0, 89 .want_protocols = TLS_PROTOCOL_TLSv1_2, 90 }, 91 { 92 .protostr = "tlsv1.1,tlsv1.2,!tlsv1.1", 93 .want_return = 0, 94 .want_protocols = 0, 95 }, 96 { 97 .protostr = "unknown", 98 .want_return = -1, 99 .want_protocols = 0, 100 }, 101 { 102 .protostr = "all,!unknown", 103 .want_return = -1, 104 .want_protocols = 0, 105 }, 106 { 107 .protostr = "sslv3,tlsv1.0,tlsv1.1,tlsv1.2", 108 .want_return = -1, 109 .want_protocols = 0, 110 }, 111 { 112 .protostr = "all,!tlsv1.0", 113 .want_return = 0, 114 .want_protocols = TLS_PROTOCOL_TLSv1_3, 115 }, 116 { 117 .protostr = "!tlsv1.0", 118 .want_return = 0, 119 .want_protocols = TLS_PROTOCOL_TLSv1_3, 120 }, 121 { 122 .protostr = "!tlsv1.0,!tlsv1.1,!tlsv1.3", 123 .want_return = 0, 124 .want_protocols = 0, 125 }, 126 { 127 .protostr = "!tlsv1.0,!tlsv1.1,tlsv1.2,!tlsv1.3", 128 .want_return = 0, 129 .want_protocols = TLS_PROTOCOL_TLSv1_2, 130 }, 131}; 132 133#define N_PARSE_PROTOCOLS_TESTS \ 134 (sizeof(parse_protocols_tests) / sizeof(*parse_protocols_tests)) 135 136static int 137do_parse_protocols_test(int test_no, struct parse_protocols_test *ppt) 138{ 139 uint32_t protocols = 0; 140 int failed = 1; 141 int rv; 142 143 rv = tls_config_parse_protocols(&protocols, ppt->protostr); 144 if (rv != ppt->want_return) { 145 fprintf(stderr, "FAIL: test %i - tls_config_parse_protocols() " 146 "returned %i, want %i\n", test_no, rv, ppt->want_return); 147 goto done; 148 } 149 if (protocols != ppt->want_protocols) { 150 fprintf(stderr, "FAIL: test %i - got protocols 0x%x, " 151 "want 0x%x\n", test_no, protocols, ppt->want_protocols); 152 goto done; 153 } 154 155 failed = 0; 156 157 done: 158 return (failed); 159} 160 161int 162main(int argc, char **argv) 163{ 164 int failed = 0; 165 size_t i; 166 167 tls_init(); 168 169 for (i = 0; i < N_PARSE_PROTOCOLS_TESTS; i++) 170 failed += do_parse_protocols_test(i, &parse_protocols_tests[i]); 171 172 return (failed); 173} 174