2021-06-08 11:24:13 +02:00
|
|
|
package tlsdialer_test
|
2021-02-02 12:05:47 +01:00
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"crypto/tls"
|
|
|
|
"errors"
|
|
|
|
"io"
|
|
|
|
"net"
|
|
|
|
"testing"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/ooni/probe-cli/v3/internal/engine/legacy/netx/handlers"
|
|
|
|
"github.com/ooni/probe-cli/v3/internal/engine/legacy/netx/modelx"
|
|
|
|
"github.com/ooni/probe-cli/v3/internal/engine/netx/errorx"
|
2021-06-08 11:24:13 +02:00
|
|
|
"github.com/ooni/probe-cli/v3/internal/engine/netx/tlsdialer"
|
2021-06-25 11:07:26 +02:00
|
|
|
"github.com/ooni/probe-cli/v3/internal/netxlite"
|
2021-02-02 12:05:47 +01:00
|
|
|
)
|
|
|
|
|
|
|
|
func TestSystemTLSHandshakerEOFError(t *testing.T) {
|
2021-06-25 11:07:26 +02:00
|
|
|
h := &netxlite.TLSHandshakerStdlib{}
|
2021-06-08 11:24:13 +02:00
|
|
|
conn, _, err := h.Handshake(context.Background(), tlsdialer.EOFConn{}, &tls.Config{
|
2021-02-02 12:05:47 +01:00
|
|
|
ServerName: "x.org",
|
|
|
|
})
|
|
|
|
if err != io.EOF {
|
|
|
|
t.Fatal("not the error that we expected")
|
|
|
|
}
|
|
|
|
if conn != nil {
|
|
|
|
t.Fatal("expected nil con here")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
type SetDeadlineConn struct {
|
2021-06-08 11:24:13 +02:00
|
|
|
tlsdialer.EOFConn
|
2021-02-02 12:05:47 +01:00
|
|
|
deadlines []time.Time
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *SetDeadlineConn) SetDeadline(t time.Time) error {
|
|
|
|
c.deadlines = append(c.deadlines, t)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestErrorWrapperTLSHandshakerFailure(t *testing.T) {
|
2021-06-08 11:24:13 +02:00
|
|
|
h := tlsdialer.ErrorWrapperTLSHandshaker{TLSHandshaker: tlsdialer.EOFTLSHandshaker{}}
|
2021-02-02 12:05:47 +01:00
|
|
|
conn, _, err := h.Handshake(
|
2021-06-08 11:24:13 +02:00
|
|
|
context.Background(), tlsdialer.EOFConn{}, new(tls.Config))
|
2021-02-02 12:05:47 +01:00
|
|
|
if !errors.Is(err, io.EOF) {
|
|
|
|
t.Fatal("not the error that we expected")
|
|
|
|
}
|
|
|
|
if conn != nil {
|
|
|
|
t.Fatal("expected nil con here")
|
|
|
|
}
|
|
|
|
var errWrapper *errorx.ErrWrapper
|
|
|
|
if !errors.As(err, &errWrapper) {
|
|
|
|
t.Fatal("cannot cast to ErrWrapper")
|
|
|
|
}
|
|
|
|
if errWrapper.Failure != errorx.FailureEOFError {
|
|
|
|
t.Fatal("unexpected Failure")
|
|
|
|
}
|
|
|
|
if errWrapper.Operation != errorx.TLSHandshakeOperation {
|
|
|
|
t.Fatal("unexpected Operation")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestEmitterTLSHandshakerFailure(t *testing.T) {
|
|
|
|
saver := &handlers.SavingHandler{}
|
|
|
|
ctx := modelx.WithMeasurementRoot(context.Background(), &modelx.MeasurementRoot{
|
|
|
|
Beginning: time.Now(),
|
|
|
|
Handler: saver,
|
|
|
|
})
|
2021-06-08 11:24:13 +02:00
|
|
|
h := tlsdialer.EmitterTLSHandshaker{TLSHandshaker: tlsdialer.EOFTLSHandshaker{}}
|
|
|
|
conn, _, err := h.Handshake(ctx, tlsdialer.EOFConn{}, &tls.Config{
|
2021-02-02 12:05:47 +01:00
|
|
|
ServerName: "www.kernel.org",
|
|
|
|
})
|
|
|
|
if !errors.Is(err, io.EOF) {
|
|
|
|
t.Fatal("not the error that we expected")
|
|
|
|
}
|
|
|
|
if conn != nil {
|
|
|
|
t.Fatal("expected nil con here")
|
|
|
|
}
|
|
|
|
events := saver.Read()
|
|
|
|
if len(events) != 2 {
|
|
|
|
t.Fatal("Wrong number of events")
|
|
|
|
}
|
|
|
|
if events[0].TLSHandshakeStart == nil {
|
|
|
|
t.Fatal("missing TLSHandshakeStart event")
|
|
|
|
}
|
|
|
|
if events[0].TLSHandshakeStart.DurationSinceBeginning == 0 {
|
|
|
|
t.Fatal("expected nonzero DurationSinceBeginning")
|
|
|
|
}
|
|
|
|
if events[0].TLSHandshakeStart.SNI != "www.kernel.org" {
|
|
|
|
t.Fatal("expected nonzero SNI")
|
|
|
|
}
|
|
|
|
if events[1].TLSHandshakeDone == nil {
|
|
|
|
t.Fatal("missing TLSHandshakeDone event")
|
|
|
|
}
|
|
|
|
if events[1].TLSHandshakeDone.DurationSinceBeginning == 0 {
|
|
|
|
t.Fatal("expected nonzero DurationSinceBeginning")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestTLSDialerFailureSplitHostPort(t *testing.T) {
|
2021-06-08 11:24:13 +02:00
|
|
|
dialer := tlsdialer.TLSDialer{}
|
2021-02-02 12:05:47 +01:00
|
|
|
conn, err := dialer.DialTLSContext(
|
|
|
|
context.Background(), "tcp", "www.google.com") // missing port
|
|
|
|
if err == nil {
|
|
|
|
t.Fatal("expected an error here")
|
|
|
|
}
|
|
|
|
if conn != nil {
|
|
|
|
t.Fatal("connection is not nil")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestTLSDialerFailureDialing(t *testing.T) {
|
2021-06-08 11:24:13 +02:00
|
|
|
dialer := tlsdialer.TLSDialer{Dialer: tlsdialer.EOFDialer{}}
|
2021-02-02 12:05:47 +01:00
|
|
|
conn, err := dialer.DialTLSContext(
|
|
|
|
context.Background(), "tcp", "www.google.com:443")
|
|
|
|
if !errors.Is(err, io.EOF) {
|
|
|
|
t.Fatal("expected an error here")
|
|
|
|
}
|
|
|
|
if conn != nil {
|
|
|
|
t.Fatal("connection is not nil")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestTLSDialerFailureHandshaking(t *testing.T) {
|
2021-06-25 11:07:26 +02:00
|
|
|
rec := &RecorderTLSHandshaker{TLSHandshaker: &netxlite.TLSHandshakerStdlib{}}
|
2021-06-08 11:24:13 +02:00
|
|
|
dialer := tlsdialer.TLSDialer{
|
|
|
|
Dialer: tlsdialer.EOFConnDialer{},
|
2021-02-02 12:05:47 +01:00
|
|
|
TLSHandshaker: rec,
|
|
|
|
}
|
|
|
|
conn, err := dialer.DialTLSContext(
|
|
|
|
context.Background(), "tcp", "www.google.com:443")
|
|
|
|
if !errors.Is(err, io.EOF) {
|
|
|
|
t.Fatal("expected an error here")
|
|
|
|
}
|
|
|
|
if conn != nil {
|
|
|
|
t.Fatal("connection is not nil")
|
|
|
|
}
|
|
|
|
if rec.SNI != "www.google.com" {
|
|
|
|
t.Fatal("unexpected SNI value")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestTLSDialerFailureHandshakingOverrideSNI(t *testing.T) {
|
2021-06-25 11:07:26 +02:00
|
|
|
rec := &RecorderTLSHandshaker{TLSHandshaker: &netxlite.TLSHandshakerStdlib{}}
|
2021-06-08 11:24:13 +02:00
|
|
|
dialer := tlsdialer.TLSDialer{
|
2021-02-02 12:05:47 +01:00
|
|
|
Config: &tls.Config{
|
|
|
|
ServerName: "x.org",
|
|
|
|
},
|
2021-06-08 11:24:13 +02:00
|
|
|
Dialer: tlsdialer.EOFConnDialer{},
|
2021-02-02 12:05:47 +01:00
|
|
|
TLSHandshaker: rec,
|
|
|
|
}
|
|
|
|
conn, err := dialer.DialTLSContext(
|
|
|
|
context.Background(), "tcp", "www.google.com:443")
|
|
|
|
if !errors.Is(err, io.EOF) {
|
|
|
|
t.Fatal("expected an error here")
|
|
|
|
}
|
|
|
|
if conn != nil {
|
|
|
|
t.Fatal("connection is not nil")
|
|
|
|
}
|
|
|
|
if rec.SNI != "x.org" {
|
|
|
|
t.Fatal("unexpected SNI value")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
type RecorderTLSHandshaker struct {
|
2021-06-08 11:24:13 +02:00
|
|
|
tlsdialer.TLSHandshaker
|
2021-02-02 12:05:47 +01:00
|
|
|
SNI string
|
|
|
|
}
|
|
|
|
|
|
|
|
func (h *RecorderTLSHandshaker) Handshake(
|
|
|
|
ctx context.Context, conn net.Conn, config *tls.Config,
|
|
|
|
) (net.Conn, tls.ConnectionState, error) {
|
|
|
|
h.SNI = config.ServerName
|
|
|
|
return h.TLSHandshaker.Handshake(ctx, conn, config)
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestDialTLSContextGood(t *testing.T) {
|
2021-06-08 11:24:13 +02:00
|
|
|
dialer := tlsdialer.TLSDialer{
|
2021-02-02 12:05:47 +01:00
|
|
|
Config: &tls.Config{ServerName: "google.com"},
|
|
|
|
Dialer: new(net.Dialer),
|
2021-06-25 11:07:26 +02:00
|
|
|
TLSHandshaker: &netxlite.TLSHandshakerStdlib{},
|
2021-02-02 12:05:47 +01:00
|
|
|
}
|
|
|
|
conn, err := dialer.DialTLSContext(context.Background(), "tcp", "google.com:443")
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
if conn == nil {
|
|
|
|
t.Fatal("connection is nil")
|
|
|
|
}
|
|
|
|
conn.Close()
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestDialTLSContextTimeout(t *testing.T) {
|
2021-06-08 11:24:13 +02:00
|
|
|
dialer := tlsdialer.TLSDialer{
|
2021-02-02 12:05:47 +01:00
|
|
|
Config: &tls.Config{ServerName: "google.com"},
|
|
|
|
Dialer: new(net.Dialer),
|
2021-06-08 11:24:13 +02:00
|
|
|
TLSHandshaker: tlsdialer.ErrorWrapperTLSHandshaker{
|
2021-06-25 11:07:26 +02:00
|
|
|
TLSHandshaker: &netxlite.TLSHandshakerStdlib{
|
|
|
|
Timeout: 10 * time.Microsecond,
|
2021-02-02 12:05:47 +01:00
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
conn, err := dialer.DialTLSContext(context.Background(), "tcp", "google.com:443")
|
|
|
|
if err.Error() != errorx.FailureGenericTimeoutError {
|
|
|
|
t.Fatal("not the error that we expected")
|
|
|
|
}
|
|
|
|
if conn != nil {
|
|
|
|
t.Fatal("connection is not nil")
|
|
|
|
}
|
|
|
|
}
|