Tobias Brunner
da04914933
test-vectors: Use plugin features
2013-06-11 11:18:18 +02:00
Tobias Brunner
17f00db6d6
revocation: Use plugin features with soft dependencies on fetcher and en-/decoding
2013-06-11 11:18:18 +02:00
Tobias Brunner
25da1943b3
padlock: Use plugin features to properly register algorithms
2013-06-11 11:18:18 +02:00
Tobias Brunner
7756c0383e
pkcs11: Use plugin_features_add() in get_features()
2013-06-11 11:18:18 +02:00
Tobias Brunner
886a40d75e
plugin-feature: Added helper function to extend arrays of plugin features
2013-06-11 11:18:18 +02:00
Tobias Brunner
c172a92bfb
constraints: Use plugin features with soft dependency on X.509 decoding
2013-06-11 11:18:18 +02:00
Tobias Brunner
e3bdf03af4
blowfish: Use plugin features to properly register crypter
2013-06-11 11:18:18 +02:00
Tobias Brunner
8f49a8d0a6
resolve: Use plugin features to register attribute handler
2013-06-11 11:18:18 +02:00
Tobias Brunner
44d5e10d9e
attr: Use plugin features to register attribute provider
2013-06-11 11:18:18 +02:00
Tobias Brunner
21d094f402
ipseckey: Allow en-/disabling at runtime using plugin reload feature
2013-06-11 11:18:18 +02:00
Tobias Brunner
82d3f5122b
ipseckey: Use plugin features and depend on RESOLVER
...
Also fixed a double-free of the resolver instance.
2013-06-11 11:18:18 +02:00
Tobias Brunner
d895721489
unbound: Use plugin features and provide RESOLVER
2013-06-11 11:18:18 +02:00
Tobias Brunner
f5bd1a5e09
plugin-feature: Add feature for DNSSEC-enabled resolvers
2013-06-11 11:18:18 +02:00
Tobias Brunner
924196d6d4
ha: Use plugin features to register listeners and attribute provider
2013-06-11 11:18:18 +02:00
Tobias Brunner
e5f4b3ca5b
farp: Use plugin features to register listener
2013-06-11 11:18:17 +02:00
Tobias Brunner
aa71f5f515
error-notify: Use plugin features to register listener
2013-06-11 11:18:17 +02:00
Tobias Brunner
57c29f6895
duplicheck: Use plugin features to register listener
2013-06-11 11:18:17 +02:00
Tobias Brunner
6c51ff745c
coupling: Use plugin features and soft depend on SHA1
2013-06-11 11:18:17 +02:00
Tobias Brunner
0c52198bc1
certexpire: Use plugin features to register listener
2013-06-11 11:18:17 +02:00
Tobias Brunner
94ca7252c1
addrblock: Use plugin features with soft dependency on X.509 decoding
2013-06-11 11:18:17 +02:00
Tobias Brunner
12459a4dc8
dhcp: Use plugin features with dependency to RNG implementation
2013-06-11 11:18:17 +02:00
Tobias Brunner
11a27ea28f
sql: Use plugin features with dependency to database backend
2013-06-11 11:18:17 +02:00
Tobias Brunner
989ec772b5
attr-sql: Use plugin features with dependency to database backend
2013-06-11 11:18:17 +02:00
Tobias Brunner
8a6cc1e35f
plugin-feature: Function added to exactly compare plugin features
2013-06-11 11:18:17 +02:00
Tobias Brunner
270e425b24
Socket plugins soft depend on the kernel-ipsec plugin feature
...
On most platforms calls to methods to bypass the IKE sockets and enabling
UDP decapsulation are required.
2013-06-11 11:18:17 +02:00
Tobias Brunner
c50da645b8
Merge branch 'unit-tests'
...
Adds a test runner and several test suites for libstrongswan.
Also adds an option to produce a test coverage report.
Several bugs were fixed in the process and chunk_hash() was replaced
with an improved implementation based on SipHash-2-4 (with a randomly
allocated key to prevent hash flooding attacks).
2013-06-11 11:16:30 +02:00
Tobias Brunner
bde35a6fb2
Suppress log messages during tests
2013-06-11 11:03:13 +02:00
Tobias Brunner
f2eeb54e8b
Remove explicit leak detective checks as these are now done for all tests
2013-06-11 11:03:13 +02:00
Tobias Brunner
95e9915074
Enable leak detective for all test cases
2013-06-11 11:03:13 +02:00
Tobias Brunner
2b4902973b
Added tests for bio_writer_t
2013-06-11 11:03:13 +02:00
Tobias Brunner
eeb73dec79
Ensure buffer in bio_writer_t is properly increased
...
The previous code was problematic if bufsize/increase was smaller than 8
and an u_int64_t was written when the buffer was too small. Also, for
large chunks and small bufsizes realloc() was called several times
instead of just once.
2013-06-11 11:03:13 +02:00
Tobias Brunner
b4029a4aae
Added tests for bio_reader_t
2013-06-11 11:03:13 +02:00
Tobias Brunner
01e15ab5c7
Add getter for the number of leaks to leak_detective_t
2013-06-11 11:03:13 +02:00
Tobias Brunner
80d9a9b722
Added tests for utils/enum.c
2013-06-11 11:03:13 +02:00
Tobias Brunner
9947a1f2f4
Gracefully handle NULL as argument for enum_from_name()
2013-06-11 11:03:13 +02:00
Tobias Brunner
06f6d80245
Additional tests for identification_t added
2013-06-11 11:03:13 +02:00
Tobias Brunner
b1abf22bd0
Fail DN parsing if OID is unterminated
...
This is the case if the last OID is not followed by a = or if the string
starts with a =.
2013-06-11 11:03:12 +02:00
Tobias Brunner
f00c350688
Fix DN printing if last RDN has an empty value
2013-06-11 11:03:12 +02:00
Tobias Brunner
10584df24f
Fix DN parsing if last RDN has an empty value
2013-06-11 11:03:12 +02:00
Tobias Brunner
c04498b608
Fix output of ASN.1 GN
2013-06-11 11:03:12 +02:00
Tobias Brunner
78c37de15a
Use chunk_from_str in identification_from_string
...
We always have a non-empty string in those cases as "" is now handled
as ID_ANY.
2013-06-11 11:03:12 +02:00
Tobias Brunner
c1be5d66cd
Use local variable in chunk_from_str()
...
This allows using strdup() or other string functions as argument
without calling them twice.
2013-06-11 11:03:12 +02:00
Tobias Brunner
456a31e895
Parse empty string as ID_ANY
2013-06-11 11:03:12 +02:00
Tobias Brunner
af67613ed6
Added tests for utils/utils.[ch]
2013-06-11 11:03:12 +02:00
Tobias Brunner
7b91011d6e
Allow memstr() to be called with NULL arguments
2013-06-11 11:03:12 +02:00
Tobias Brunner
438a6693ca
Removed unused clalloc() function
2013-06-11 11:03:12 +02:00
Tobias Brunner
819c02dbc6
timeval_add_ms() fixed
...
1000000us are exactly 1s so.
2013-06-11 11:03:12 +02:00
Tobias Brunner
c2dba63bd4
Additional tests for chunk_t
2013-06-11 11:03:12 +02:00
Tobias Brunner
ab73ae67d3
Also capture coverage data for tests but filter them from the result
...
Otherwise calls from test cases to static inline functions are not captured.
2013-06-11 11:03:12 +02:00
Tobias Brunner
9a8c873e90
Add tests for lib->get|set
2013-06-11 11:03:12 +02:00
Tobias Brunner
0e55270aea
Remove dead code in token enumerator
...
Since we always search for the nearest separator (and strip them from
the front of the next token) there can't be any separators left at the
end of a token.
2013-06-11 11:03:12 +02:00
Tobias Brunner
7e9f6b276b
Additional and improved enumerator_t tests
2013-06-11 11:03:11 +02:00
Tobias Brunner
0713c90927
Test remove and remove_at of hashtable_t if all items are in the same bucket
2013-06-11 11:03:11 +02:00
Tobias Brunner
c721d6b6a3
Add test cases for invoke_* and clone_* of linked_list_t
2013-06-11 11:03:11 +02:00
Tobias Brunner
afb6d9c301
Improve tests for linked_list_t.replace()
2013-06-11 11:03:11 +02:00
Tobias Brunner
cca70ed331
Add additional tests for linked_list_t
2013-06-11 11:03:11 +02:00
Tobias Brunner
bc90b3dd0a
Improved test for linked_list_t.insert_before()
2013-06-11 11:03:11 +02:00
Tobias Brunner
01a3ba9e0f
Enable coverage report for libstrongswan
2013-06-11 11:03:11 +02:00
Tobias Brunner
1f14b4a1f9
Add --enable-coverage configure option
...
This configure flag enables lcov [1] coverage generation and is intended
to be used with unit tests (--enable-unit-tests is implied).
A html coverage report can be generated by issuing the following command
in the toplevel build directory:
make coverage
[1] - http://ltp.sourceforge.net/coverage/lcov.php
Based on a patch by Adrian-Ken Rueegsegger.
2013-06-11 11:03:11 +02:00
Tobias Brunner
952073b8a7
Use proper type for enumerator_t/linked_list_t tests
...
Worked with -O2 but not with -O0.
2013-06-11 11:03:11 +02:00
Tobias Brunner
de42bf35f9
Converted test for recursive mutex_t
2013-06-11 11:03:11 +02:00
Tobias Brunner
bed4bc1327
Randomly allocate chunk_hash() key during first use
...
This avoids hash flooding attacks.
2013-06-11 11:03:11 +02:00
Tobias Brunner
d1953fe403
Replace chunk_hash() with output from chunk_mac()
...
The quality is way better, the calculation is a bit slower though.
The key is statically initialized to zero, which will be changed later
to prevent hash flooding.
2013-06-11 11:03:11 +02:00
Tobias Brunner
1255de5a20
Adding chunk_mac() which calculates a 64-bit MAC using SipHash-2-4
2013-06-11 11:03:11 +02:00
Tobias Brunner
4e67f19528
Converted tests for chunk_t
2013-06-11 11:03:11 +02:00
Tobias Brunner
e09461bf77
Converted and added tests for hashtable_t
2013-06-11 11:03:10 +02:00
Tobias Brunner
0298be5705
Converted tests for identification_t
2013-06-11 11:03:10 +02:00
Tobias Brunner
3cbacad40b
Remove obsolete enumerator/linked_list tests in unit_tester plugin
2013-06-11 11:03:10 +02:00
Tobias Brunner
26e8375b14
Add tests combining linked_list_t and enumerators
2013-06-11 11:03:10 +02:00
Tobias Brunner
d3b06618f8
Some minor Doxygen fixes for linked_list_t
2013-06-11 11:03:10 +02:00
Tobias Brunner
ff8f12298f
Add basic tests for linked_list_t
2013-06-11 11:03:10 +02:00
Tobias Brunner
0d67c8329b
Redirect test runner output to stderr
...
This allows redirecting stdout of 'make check' to /dev/null.
2013-06-11 11:03:10 +02:00
Tobias Brunner
f15fcdc9d8
Add tests for enumerator_t
2013-06-11 11:03:10 +02:00
Tobias Brunner
156dcbc12e
Add test runner for unit tests in libstrongswan
2013-06-11 11:03:10 +02:00
Tobias Brunner
62516a7465
testing: Increase base image size so there is space for test results on winnetou
2013-06-11 11:01:26 +02:00
Tobias Brunner
053ad34959
testing: Ignore errors when searching for imcv log entries in daemon.log
2013-06-10 18:52:32 +02:00
Tobias Brunner
5d52087b54
Added missing string for full-length HMAC-SHA512 signer
2013-06-10 11:48:18 +02:00
Tobias Brunner
cfae3a227d
attr: Fix handling of invalid IPs listed after valid ones
...
Invalid IPs listed after a valid one resulted in an attribute
of the same type but with invalid data.
2013-06-05 17:26:24 +02:00
Tobias Brunner
c480b5f458
Allow memwipe() to be called with NULL argument
2013-05-27 18:41:16 +02:00
Tobias Brunner
c6e1eda6d0
testing: Set terminal title when logging in via SSH
...
Since we always log in as root use a simpler command prompt. And don't
store duplicate commands in the bash command history.
2013-05-15 10:35:48 +02:00
Tobias Brunner
bd538e8c4a
openssl: Only warn about unavailable FIPS mode if the user requested it
2013-05-08 15:23:14 +02:00
Tobias Brunner
c1f1df4b40
Merge branch 'charon-cmd-pkcs12'
...
Adds support for PKCS#12 files in charon-cmd and ipsec.secrets.
Also fixes the cleanup of the OpenSSL library in the openssl plugin.
2013-05-08 15:19:38 +02:00
Tobias Brunner
6040eff900
stroke: Add second password if provided
2013-05-08 15:02:41 +02:00
Tobias Brunner
b7aa6b789e
Load pkcs7 plugin in charon (and while we are at it in nm)
2013-05-08 15:02:41 +02:00
Tobias Brunner
1c080407b2
stroke: Fail silently if another builder calls PW callback after giving up
...
Also reduced the number of tries to 3.
2013-05-08 15:02:41 +02:00
Tobias Brunner
4a64c3e9a0
stroke: Cache passwords so the user is not prompted multiple times for the same password
...
To verify/decrypt a PKCS#12 container a password might be needed
multiple times. If it was entered correctly we don't want to bother the
user again with another password prompt.
The passwords for MAC creation and encryption could be different so the
user might be prompted multiple times after all.
2013-05-08 15:02:41 +02:00
Tobias Brunner
e240b03e68
stroke: Fix prompt and error messages in passphrase callback
2013-05-08 15:02:41 +02:00
Tobias Brunner
7971278c92
stroke: Load credentials from PKCS#12 files (P12 token)
2013-05-08 15:02:41 +02:00
Tobias Brunner
904390e887
openssl: Cleanup thread specific error buffer
2013-05-08 15:02:40 +02:00
Tobias Brunner
3ee2af97bf
openssl: Don't use deprecated CRYPTO_set_id_callback() with OpenSSL >= 1.0.0
2013-05-08 15:02:40 +02:00
Tobias Brunner
780900ab0e
openssl: Add PKCS#12 parsing via OpenSSL
2013-05-08 15:02:40 +02:00
Tobias Brunner
651d5ab8e7
openssl: Properly cleanup OpenSSL library
2013-05-08 15:02:40 +02:00
Tobias Brunner
02116fdc2d
charon-cmd: Add support for PKCS#12 files
2013-05-08 15:02:40 +02:00
Tobias Brunner
3bd498284e
PEM plugin loads PKCS#12 containers from (DER-encoded) files
...
It is not actually able to handle PEM encoded PKCS#12 files produced
by OpenSSL.
2013-05-08 15:02:40 +02:00
Tobias Brunner
abc04e6b3f
Remove pluto specific certificate types
2013-05-08 15:02:40 +02:00
Tobias Brunner
f77d6e16d2
charon-cmd: match_me/match_other are optional in callback credentials
2013-05-08 15:02:40 +02:00
Tobias Brunner
89d350f46a
charon-cmd: Request password for private keys
2013-05-08 15:02:40 +02:00
Tobias Brunner
1f2a34d6d8
Add support for untruncated HMAC-SHA-512
2013-05-08 15:02:39 +02:00
Tobias Brunner
d8be7d38bf
Also support 128-bit RC2
2013-05-08 15:02:39 +02:00
Tobias Brunner
feef637368
Add pkcs12 plugin which adds support for decoding PKCS#12 containers
2013-05-08 15:02:39 +02:00