1*6777b538SAndroid Build Coastguard Worker // Copyright 2022 The Chromium Authors
2*6777b538SAndroid Build Coastguard Worker // Use of this source code is governed by a BSD-style license that can be
3*6777b538SAndroid Build Coastguard Worker // found in the LICENSE file.
4*6777b538SAndroid Build Coastguard Worker
5*6777b538SAndroid Build Coastguard Worker #include "net/test/ssl_test_util.h"
6*6777b538SAndroid Build Coastguard Worker
7*6777b538SAndroid Build Coastguard Worker #include <string>
8*6777b538SAndroid Build Coastguard Worker #include <string_view>
9*6777b538SAndroid Build Coastguard Worker
10*6777b538SAndroid Build Coastguard Worker #include "third_party/boringssl/src/include/openssl/hpke.h"
11*6777b538SAndroid Build Coastguard Worker
12*6777b538SAndroid Build Coastguard Worker namespace net {
13*6777b538SAndroid Build Coastguard Worker
MakeTestEchKeys(std::string_view public_name,size_t max_name_len,std::vector<uint8_t> * ech_config_list)14*6777b538SAndroid Build Coastguard Worker bssl::UniquePtr<SSL_ECH_KEYS> MakeTestEchKeys(
15*6777b538SAndroid Build Coastguard Worker std::string_view public_name,
16*6777b538SAndroid Build Coastguard Worker size_t max_name_len,
17*6777b538SAndroid Build Coastguard Worker std::vector<uint8_t>* ech_config_list) {
18*6777b538SAndroid Build Coastguard Worker bssl::ScopedEVP_HPKE_KEY key;
19*6777b538SAndroid Build Coastguard Worker if (!EVP_HPKE_KEY_generate(key.get(), EVP_hpke_x25519_hkdf_sha256())) {
20*6777b538SAndroid Build Coastguard Worker return nullptr;
21*6777b538SAndroid Build Coastguard Worker }
22*6777b538SAndroid Build Coastguard Worker
23*6777b538SAndroid Build Coastguard Worker uint8_t* ech_config;
24*6777b538SAndroid Build Coastguard Worker size_t ech_config_len;
25*6777b538SAndroid Build Coastguard Worker if (!SSL_marshal_ech_config(&ech_config, &ech_config_len,
26*6777b538SAndroid Build Coastguard Worker /*config_id=*/1, key.get(),
27*6777b538SAndroid Build Coastguard Worker std::string(public_name).c_str(), max_name_len)) {
28*6777b538SAndroid Build Coastguard Worker return nullptr;
29*6777b538SAndroid Build Coastguard Worker }
30*6777b538SAndroid Build Coastguard Worker bssl::UniquePtr<uint8_t> scoped_ech_config(ech_config);
31*6777b538SAndroid Build Coastguard Worker
32*6777b538SAndroid Build Coastguard Worker uint8_t* ech_config_list_raw;
33*6777b538SAndroid Build Coastguard Worker size_t ech_config_list_len;
34*6777b538SAndroid Build Coastguard Worker bssl::UniquePtr<SSL_ECH_KEYS> keys(SSL_ECH_KEYS_new());
35*6777b538SAndroid Build Coastguard Worker if (!keys ||
36*6777b538SAndroid Build Coastguard Worker !SSL_ECH_KEYS_add(keys.get(), /*is_retry_config=*/1, ech_config,
37*6777b538SAndroid Build Coastguard Worker ech_config_len, key.get()) ||
38*6777b538SAndroid Build Coastguard Worker !SSL_ECH_KEYS_marshal_retry_configs(keys.get(), &ech_config_list_raw,
39*6777b538SAndroid Build Coastguard Worker &ech_config_list_len)) {
40*6777b538SAndroid Build Coastguard Worker return nullptr;
41*6777b538SAndroid Build Coastguard Worker }
42*6777b538SAndroid Build Coastguard Worker bssl::UniquePtr<uint8_t> scoped_ech_config_list(ech_config_list_raw);
43*6777b538SAndroid Build Coastguard Worker
44*6777b538SAndroid Build Coastguard Worker ech_config_list->assign(ech_config_list_raw,
45*6777b538SAndroid Build Coastguard Worker ech_config_list_raw + ech_config_list_len);
46*6777b538SAndroid Build Coastguard Worker return keys;
47*6777b538SAndroid Build Coastguard Worker }
48*6777b538SAndroid Build Coastguard Worker
49*6777b538SAndroid Build Coastguard Worker } // namespace net
50