xref: /aosp_15_r20/external/boringssl/src/ssl/test/test_state.cc (revision 8fb009dc861624b67b6cdb62ea21f0f22d0c584b)
1 /* Copyright (c) 2018, Google Inc.
2  *
3  * Permission to use, copy, modify, and/or distribute this software for any
4  * purpose with or without fee is hereby granted, provided that the above
5  * copyright notice and this permission notice appear in all copies.
6  *
7  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
8  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
9  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
10  * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
11  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
12  * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
13  * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
14 
15 #include "test_state.h"
16 
17 #include <openssl/ssl.h>
18 
19 #include "../../crypto/internal.h"
20 #include "../internal.h"
21 
22 using namespace bssl;
23 
24 static CRYPTO_once_t g_once = CRYPTO_ONCE_INIT;
25 static int g_state_index = 0;
26 // Some code treats the zero time special, so initialize the clock to a
27 // non-zero time.
28 static timeval g_clock = { 1234, 1234 };
29 
TestStateExFree(void * parent,void * ptr,CRYPTO_EX_DATA * ad,int index,long argl,void * argp)30 static void TestStateExFree(void *parent, void *ptr, CRYPTO_EX_DATA *ad,
31                             int index, long argl, void *argp) {
32   delete ((TestState *)ptr);
33 }
34 
InitGlobals()35 static bool InitGlobals() {
36   CRYPTO_once(&g_once, [] {
37     g_state_index =
38         SSL_get_ex_new_index(0, nullptr, nullptr, nullptr, TestStateExFree);
39   });
40   return g_state_index >= 0;
41 }
42 
GetClock()43 struct timeval *GetClock() {
44   return &g_clock;
45 }
46 
AdvanceClock(unsigned seconds)47 void AdvanceClock(unsigned seconds) {
48   g_clock.tv_sec += seconds;
49 }
50 
SetTestState(SSL * ssl,std::unique_ptr<TestState> state)51 bool SetTestState(SSL *ssl, std::unique_ptr<TestState> state) {
52   if (!InitGlobals()) {
53     return false;
54   }
55   // |SSL_set_ex_data| takes ownership of |state| only on success.
56   if (SSL_set_ex_data(ssl, g_state_index, state.get()) == 1) {
57     state.release();
58     return true;
59   }
60   return false;
61 }
62 
GetTestState(const SSL * ssl)63 TestState *GetTestState(const SSL *ssl) {
64   if (!InitGlobals()) {
65     return nullptr;
66   }
67   return static_cast<TestState *>(SSL_get_ex_data(ssl, g_state_index));
68 }
69 
ssl_ctx_add_session(SSL_SESSION * session,void * void_param)70 static void ssl_ctx_add_session(SSL_SESSION *session, void *void_param) {
71   SSL_CTX *ctx = reinterpret_cast<SSL_CTX *>(void_param);
72   UniquePtr<SSL_SESSION> new_session = SSL_SESSION_dup(
73       session, SSL_SESSION_INCLUDE_NONAUTH | SSL_SESSION_INCLUDE_TICKET);
74   if (new_session != nullptr) {
75     SSL_CTX_add_session(ctx, new_session.get());
76   }
77 }
78 
CopySessions(SSL_CTX * dst,const SSL_CTX * src)79 void CopySessions(SSL_CTX *dst, const SSL_CTX *src) {
80   lh_SSL_SESSION_doall_arg(src->sessions, ssl_ctx_add_session, dst);
81 }
82 
push_session(SSL_SESSION * session,void * arg)83 static void push_session(SSL_SESSION *session, void *arg) {
84   auto s = reinterpret_cast<std::vector<SSL_SESSION *> *>(arg);
85   s->push_back(session);
86 }
87 
SerializeContextState(SSL_CTX * ctx,CBB * cbb)88 bool SerializeContextState(SSL_CTX *ctx, CBB *cbb) {
89   CBB out, ctx_sessions, ticket_keys;
90   uint8_t keys[48];
91   if (!CBB_add_u24_length_prefixed(cbb, &out) ||
92       !CBB_add_u16(&out, 0 /* version */) ||
93       !SSL_CTX_get_tlsext_ticket_keys(ctx, &keys, sizeof(keys)) ||
94       !CBB_add_u8_length_prefixed(&out, &ticket_keys) ||
95       !CBB_add_bytes(&ticket_keys, keys, sizeof(keys)) ||
96       !CBB_add_asn1(&out, &ctx_sessions, CBS_ASN1_SEQUENCE)) {
97     return false;
98   }
99   std::vector<SSL_SESSION *> sessions;
100   lh_SSL_SESSION_doall_arg(ctx->sessions, push_session, &sessions);
101   for (const auto &sess : sessions) {
102     if (!ssl_session_serialize(sess, &ctx_sessions)) {
103       return false;
104     }
105   }
106   return CBB_flush(cbb);
107 }
108 
DeserializeContextState(CBS * cbs,SSL_CTX * ctx)109 bool DeserializeContextState(CBS *cbs, SSL_CTX *ctx) {
110   CBS in, sessions, ticket_keys;
111   uint16_t version;
112   constexpr uint16_t kVersion = 0;
113   if (!CBS_get_u24_length_prefixed(cbs, &in) ||
114       !CBS_get_u16(&in, &version) ||
115       version > kVersion ||
116       !CBS_get_u8_length_prefixed(&in, &ticket_keys) ||
117       !SSL_CTX_set_tlsext_ticket_keys(ctx, CBS_data(&ticket_keys),
118                                       CBS_len(&ticket_keys)) ||
119       !CBS_get_asn1(&in, &sessions, CBS_ASN1_SEQUENCE)) {
120     return false;
121   }
122   while (CBS_len(&sessions)) {
123     UniquePtr<SSL_SESSION> session =
124         SSL_SESSION_parse(&sessions, ctx->x509_method, ctx->pool);
125     if (!session) {
126       return false;
127     }
128     SSL_CTX_add_session(ctx, session.get());
129   }
130   return true;
131 }
132 
Serialize(CBB * cbb) const133 bool TestState::Serialize(CBB *cbb) const {
134   CBB out, pending, text;
135   if (!CBB_add_u24_length_prefixed(cbb, &out) ||
136       !CBB_add_u16(&out, 0 /* version */) ||
137       !CBB_add_u24_length_prefixed(&out, &pending) ||
138       (pending_session &&
139        !ssl_session_serialize(pending_session.get(), &pending)) ||
140       !CBB_add_u16_length_prefixed(&out, &text) ||
141       !CBB_add_bytes(
142           &text, reinterpret_cast<const uint8_t *>(msg_callback_text.data()),
143           msg_callback_text.length()) ||
144       !CBB_add_asn1_uint64(&out, g_clock.tv_sec) ||
145       !CBB_add_asn1_uint64(&out, g_clock.tv_usec) ||
146       !CBB_flush(cbb)) {
147     return false;
148   }
149   return true;
150 }
151 
Deserialize(CBS * cbs,SSL_CTX * ctx)152 std::unique_ptr<TestState> TestState::Deserialize(CBS *cbs, SSL_CTX *ctx) {
153   CBS in, pending_session, text;
154   auto state = std::make_unique<TestState>();
155   uint16_t version;
156   constexpr uint16_t kVersion = 0;
157   uint64_t sec, usec;
158   if (!CBS_get_u24_length_prefixed(cbs, &in) ||  //
159       !CBS_get_u16(&in, &version) ||             //
160       version > kVersion ||
161       !CBS_get_u24_length_prefixed(&in, &pending_session) ||
162       !CBS_get_u16_length_prefixed(&in, &text) ||
163       !CBS_get_asn1_uint64(&in, &sec) ||   //
164       !CBS_get_asn1_uint64(&in, &usec) ||  //
165       usec >= 1000000) {
166     return nullptr;
167   }
168   if (CBS_len(&pending_session)) {
169     state->pending_session = SSL_SESSION_parse(
170         &pending_session, ctx->x509_method, ctx->pool);
171     if (!state->pending_session) {
172       return nullptr;
173     }
174   }
175   state->msg_callback_text = std::string(
176       reinterpret_cast<const char *>(CBS_data(&text)), CBS_len(&text));
177   g_clock.tv_sec = sec;
178   g_clock.tv_usec = usec;
179   return state;
180 }
181