xref: /aosp_15_r20/external/cronet/net/test/cert_test_util.cc (revision 6777b5387eb2ff775bb5750e3f5d96f37fb7352b)
1*6777b538SAndroid Build Coastguard Worker // Copyright 2012 The Chromium Authors
2*6777b538SAndroid Build Coastguard Worker // Use of this source code is governed by a BSD-style license that can be
3*6777b538SAndroid Build Coastguard Worker // found in the LICENSE file.
4*6777b538SAndroid Build Coastguard Worker 
5*6777b538SAndroid Build Coastguard Worker #include "net/test/cert_test_util.h"
6*6777b538SAndroid Build Coastguard Worker 
7*6777b538SAndroid Build Coastguard Worker #include <string_view>
8*6777b538SAndroid Build Coastguard Worker 
9*6777b538SAndroid Build Coastguard Worker #include "base/files/file_path.h"
10*6777b538SAndroid Build Coastguard Worker #include "base/files/file_util.h"
11*6777b538SAndroid Build Coastguard Worker #include "base/threading/thread_restrictions.h"
12*6777b538SAndroid Build Coastguard Worker #include "net/cert/ev_root_ca_metadata.h"
13*6777b538SAndroid Build Coastguard Worker #include "net/cert/x509_certificate.h"
14*6777b538SAndroid Build Coastguard Worker #include "net/cert/x509_util.h"
15*6777b538SAndroid Build Coastguard Worker #include "net/test/test_data_directory.h"
16*6777b538SAndroid Build Coastguard Worker #include "third_party/boringssl/src/include/openssl/bytestring.h"
17*6777b538SAndroid Build Coastguard Worker #include "third_party/boringssl/src/include/openssl/evp.h"
18*6777b538SAndroid Build Coastguard Worker 
19*6777b538SAndroid Build Coastguard Worker namespace net {
20*6777b538SAndroid Build Coastguard Worker 
CreateCertificateListFromFile(const base::FilePath & certs_dir,std::string_view cert_file,int format)21*6777b538SAndroid Build Coastguard Worker CertificateList CreateCertificateListFromFile(const base::FilePath& certs_dir,
22*6777b538SAndroid Build Coastguard Worker                                               std::string_view cert_file,
23*6777b538SAndroid Build Coastguard Worker                                               int format) {
24*6777b538SAndroid Build Coastguard Worker   base::FilePath cert_path = certs_dir.AppendASCII(cert_file);
25*6777b538SAndroid Build Coastguard Worker   std::string cert_data;
26*6777b538SAndroid Build Coastguard Worker   if (!base::ReadFileToString(cert_path, &cert_data))
27*6777b538SAndroid Build Coastguard Worker     return CertificateList();
28*6777b538SAndroid Build Coastguard Worker   return X509Certificate::CreateCertificateListFromBytes(
29*6777b538SAndroid Build Coastguard Worker       base::as_byte_span(cert_data), format);
30*6777b538SAndroid Build Coastguard Worker }
31*6777b538SAndroid Build Coastguard Worker 
LoadCertificateFiles(const std::vector<std::string> & cert_filenames,CertificateList * certs)32*6777b538SAndroid Build Coastguard Worker ::testing::AssertionResult LoadCertificateFiles(
33*6777b538SAndroid Build Coastguard Worker     const std::vector<std::string>& cert_filenames,
34*6777b538SAndroid Build Coastguard Worker     CertificateList* certs) {
35*6777b538SAndroid Build Coastguard Worker   certs->clear();
36*6777b538SAndroid Build Coastguard Worker   for (const std::string& filename : cert_filenames) {
37*6777b538SAndroid Build Coastguard Worker     scoped_refptr<X509Certificate> cert = CreateCertificateChainFromFile(
38*6777b538SAndroid Build Coastguard Worker         GetTestCertsDirectory(), filename, X509Certificate::FORMAT_AUTO);
39*6777b538SAndroid Build Coastguard Worker     if (!cert)
40*6777b538SAndroid Build Coastguard Worker       return ::testing::AssertionFailure()
41*6777b538SAndroid Build Coastguard Worker              << "Failed loading certificate from file: " << filename
42*6777b538SAndroid Build Coastguard Worker              << " (in directory: " << GetTestCertsDirectory().value() << ")";
43*6777b538SAndroid Build Coastguard Worker     certs->push_back(cert);
44*6777b538SAndroid Build Coastguard Worker   }
45*6777b538SAndroid Build Coastguard Worker 
46*6777b538SAndroid Build Coastguard Worker   return ::testing::AssertionSuccess();
47*6777b538SAndroid Build Coastguard Worker }
48*6777b538SAndroid Build Coastguard Worker 
CreateCertificateChainFromFile(const base::FilePath & certs_dir,std::string_view cert_file,int format)49*6777b538SAndroid Build Coastguard Worker scoped_refptr<X509Certificate> CreateCertificateChainFromFile(
50*6777b538SAndroid Build Coastguard Worker     const base::FilePath& certs_dir,
51*6777b538SAndroid Build Coastguard Worker     std::string_view cert_file,
52*6777b538SAndroid Build Coastguard Worker     int format) {
53*6777b538SAndroid Build Coastguard Worker   CertificateList certs = CreateCertificateListFromFile(
54*6777b538SAndroid Build Coastguard Worker       certs_dir, cert_file, format);
55*6777b538SAndroid Build Coastguard Worker   if (certs.empty())
56*6777b538SAndroid Build Coastguard Worker     return nullptr;
57*6777b538SAndroid Build Coastguard Worker 
58*6777b538SAndroid Build Coastguard Worker   std::vector<bssl::UniquePtr<CRYPTO_BUFFER>> intermediates;
59*6777b538SAndroid Build Coastguard Worker   for (size_t i = 1; i < certs.size(); ++i)
60*6777b538SAndroid Build Coastguard Worker     intermediates.push_back(bssl::UpRef(certs[i]->cert_buffer()));
61*6777b538SAndroid Build Coastguard Worker 
62*6777b538SAndroid Build Coastguard Worker   scoped_refptr<X509Certificate> result(X509Certificate::CreateFromBuffer(
63*6777b538SAndroid Build Coastguard Worker       bssl::UpRef(certs[0]->cert_buffer()), std::move(intermediates)));
64*6777b538SAndroid Build Coastguard Worker   return result;
65*6777b538SAndroid Build Coastguard Worker }
66*6777b538SAndroid Build Coastguard Worker 
ImportCertFromFile(const base::FilePath & cert_path)67*6777b538SAndroid Build Coastguard Worker scoped_refptr<X509Certificate> ImportCertFromFile(
68*6777b538SAndroid Build Coastguard Worker     const base::FilePath& cert_path) {
69*6777b538SAndroid Build Coastguard Worker   base::ScopedAllowBlockingForTesting allow_blocking;
70*6777b538SAndroid Build Coastguard Worker   std::string cert_data;
71*6777b538SAndroid Build Coastguard Worker   if (!base::ReadFileToString(cert_path, &cert_data))
72*6777b538SAndroid Build Coastguard Worker     return nullptr;
73*6777b538SAndroid Build Coastguard Worker 
74*6777b538SAndroid Build Coastguard Worker   CertificateList certs_in_file =
75*6777b538SAndroid Build Coastguard Worker       X509Certificate::CreateCertificateListFromBytes(
76*6777b538SAndroid Build Coastguard Worker           base::as_byte_span(cert_data), X509Certificate::FORMAT_AUTO);
77*6777b538SAndroid Build Coastguard Worker   if (certs_in_file.empty())
78*6777b538SAndroid Build Coastguard Worker     return nullptr;
79*6777b538SAndroid Build Coastguard Worker   return certs_in_file[0];
80*6777b538SAndroid Build Coastguard Worker }
81*6777b538SAndroid Build Coastguard Worker 
ImportCertFromFile(const base::FilePath & certs_dir,std::string_view cert_file)82*6777b538SAndroid Build Coastguard Worker scoped_refptr<X509Certificate> ImportCertFromFile(
83*6777b538SAndroid Build Coastguard Worker     const base::FilePath& certs_dir,
84*6777b538SAndroid Build Coastguard Worker     std::string_view cert_file) {
85*6777b538SAndroid Build Coastguard Worker   return ImportCertFromFile(certs_dir.AppendASCII(cert_file));
86*6777b538SAndroid Build Coastguard Worker }
87*6777b538SAndroid Build Coastguard Worker 
ScopedTestEVPolicy(EVRootCAMetadata * ev_root_ca_metadata,const SHA256HashValue & fingerprint,const char * policy)88*6777b538SAndroid Build Coastguard Worker ScopedTestEVPolicy::ScopedTestEVPolicy(EVRootCAMetadata* ev_root_ca_metadata,
89*6777b538SAndroid Build Coastguard Worker                                        const SHA256HashValue& fingerprint,
90*6777b538SAndroid Build Coastguard Worker                                        const char* policy)
91*6777b538SAndroid Build Coastguard Worker     : fingerprint_(fingerprint), ev_root_ca_metadata_(ev_root_ca_metadata) {
92*6777b538SAndroid Build Coastguard Worker   EXPECT_TRUE(ev_root_ca_metadata->AddEVCA(fingerprint, policy));
93*6777b538SAndroid Build Coastguard Worker }
94*6777b538SAndroid Build Coastguard Worker 
~ScopedTestEVPolicy()95*6777b538SAndroid Build Coastguard Worker ScopedTestEVPolicy::~ScopedTestEVPolicy() {
96*6777b538SAndroid Build Coastguard Worker   EXPECT_TRUE(ev_root_ca_metadata_->RemoveEVCA(fingerprint_));
97*6777b538SAndroid Build Coastguard Worker }
98*6777b538SAndroid Build Coastguard Worker 
99*6777b538SAndroid Build Coastguard Worker }  // namespace net
100