初始提交:terminalX 可运行态(M0/M1/M1.5 已真机验证)
- M0: libghostty SSH 终端(渲染/输入/连接)+ 白屏修复(OutputGate) + 会话状态机/自动重连 - M1: tsnet 用户态组网 + SSH-over-tsnet(fd 桥),shell 级真机验证;R5(Go+gvisor+C+++Swift 同进程) retire - M1.5: tmux -CC 原生 tab(MVP) - 结构: packages/(TXCore·TXTransport), apps/TerminalX, vendor/(libghostty-spm/libssh2/mbedtls/tsnet-bridge), artifacts/ - 文档: CLAUDE.md + docs/HANDOFF.md(新会话入口) - 环境: 认证代理→依赖 vendor 本地化;Go 在 ~/.local/go;仅模拟器/未签名 - 待续: M2 mosh, tmux 多 pane, M4 安全(host key/SE) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
730
vendor/mbedtls/tests/opt-testcases/handshake-generated.sh
vendored
Normal file
730
vendor/mbedtls/tests/opt-testcases/handshake-generated.sh
vendored
Normal file
@@ -0,0 +1,730 @@
|
||||
# Miscellaneous tests related to the TLS handshake layer.
|
||||
#
|
||||
# Automatically generated by generate_tls_handshake_tests.py. Do not edit!
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
run_test "Handshake defragmentation on client: no fragmentation, for reference" \
|
||||
"$O_NEXT_SRV -allow_no_dhe_kex" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-C "waiting for more fragments"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on client: len=512, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -split_send_frag 512" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 512, 0\\.\\.512 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 512\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 512/" \
|
||||
-c "Consume: waiting for more handshake fragments 512/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=512, TLS 1.2" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 512" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 512, 0\\.\\.512 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 512\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 512/" \
|
||||
-c "Consume: waiting for more handshake fragments 512/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on client: len=513, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -split_send_frag 513" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 513, 0\\.\\.513 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 513\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 513/" \
|
||||
-c "Consume: waiting for more handshake fragments 513/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=513, TLS 1.2" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 513" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 513, 0\\.\\.513 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 513\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 513/" \
|
||||
-c "Consume: waiting for more handshake fragments 513/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on client: len=256, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -split_send_frag 256" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 256, 0\\.\\.256 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 256\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 256/" \
|
||||
-c "Consume: waiting for more handshake fragments 256/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=256, TLS 1.2" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 256" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 256, 0\\.\\.256 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 256\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 256/" \
|
||||
-c "Consume: waiting for more handshake fragments 256/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on client: len=128, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -split_send_frag 128" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 128, 0\\.\\.128 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 128\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 128/" \
|
||||
-c "Consume: waiting for more handshake fragments 128/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=128, TLS 1.2" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 128" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 128, 0\\.\\.128 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 128\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 128/" \
|
||||
-c "Consume: waiting for more handshake fragments 128/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on client: len=64, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -split_send_frag 64" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 64, 0\\.\\.64 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 64\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 64/" \
|
||||
-c "Consume: waiting for more handshake fragments 64/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=64, TLS 1.2" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 64" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 64, 0\\.\\.64 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 64\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 64/" \
|
||||
-c "Consume: waiting for more handshake fragments 64/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on client: len=36, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -split_send_frag 36" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 36, 0\\.\\.36 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 36\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 36/" \
|
||||
-c "Consume: waiting for more handshake fragments 36/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=36, TLS 1.2" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 36" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 36, 0\\.\\.36 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 36\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 36/" \
|
||||
-c "Consume: waiting for more handshake fragments 36/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on client: len=32, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -split_send_frag 32" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 32, 0\\.\\.32 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 32\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 32/" \
|
||||
-c "Consume: waiting for more handshake fragments 32/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=32, TLS 1.2" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 32" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 32, 0\\.\\.32 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 32\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 32/" \
|
||||
-c "Consume: waiting for more handshake fragments 32/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on client: len=16, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -split_send_frag 16" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 16, 0\\.\\.16 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 16\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 16/" \
|
||||
-c "Consume: waiting for more handshake fragments 16/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=16, TLS 1.2" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 16" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 16, 0\\.\\.16 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 16\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 16/" \
|
||||
-c "Consume: waiting for more handshake fragments 16/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on client: len=13, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -split_send_frag 13" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 13, 0\\.\\.13 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 13\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 13/" \
|
||||
-c "Consume: waiting for more handshake fragments 13/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=13, TLS 1.2" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 13" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 13, 0\\.\\.13 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 13\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 13/" \
|
||||
-c "Consume: waiting for more handshake fragments 13/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on client: len=5, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -split_send_frag 5" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 5, 0\\.\\.5 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 5\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 5/" \
|
||||
-c "Consume: waiting for more handshake fragments 5/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=5, TLS 1.2" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 5" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 5, 0\\.\\.5 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 5\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 5/" \
|
||||
-c "Consume: waiting for more handshake fragments 5/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on client: len=4, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -split_send_frag 4" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 4/" \
|
||||
-c "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=4, TLS 1.2, default" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 4" \
|
||||
"$P_CLI debug_level=4" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 4/" \
|
||||
-c "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=4, TLS 1.2, null" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 4 -cipher ALL@SECLEVEL=0:COMPLEMENTOFALL@SECLEVEL=0" \
|
||||
"$P_CLI debug_level=4 force_ciphersuite=TLS-ECDHE-ECDSA-WITH-NULL-SHA" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 4/" \
|
||||
-c "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=4, TLS 1.2, ChachaPoly" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 4" \
|
||||
"$P_CLI debug_level=4 force_ciphersuite=TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 4/" \
|
||||
-c "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=4, TLS 1.2, GCM" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 4" \
|
||||
"$P_CLI debug_level=4 force_ciphersuite=TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 4/" \
|
||||
-c "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
run_test "Handshake defragmentation on client: len=4, TLS 1.2, CBC, etm=n" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 4" \
|
||||
"$P_CLI debug_level=4 force_ciphersuite=TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256 etm=0" \
|
||||
0 \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 4/" \
|
||||
-c "Consume: waiting for more handshake fragments 4/" \
|
||||
-C "using encrypt then mac"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
requires_config_enabled MBEDTLS_SSL_ENCRYPT_THEN_MAC
|
||||
run_test "Handshake defragmentation on client: len=4, TLS 1.2, CBC, etm=y" \
|
||||
"$O_NEXT_SRV -tls1_2 -split_send_frag 4" \
|
||||
"$P_CLI debug_level=4 force_ciphersuite=TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256 etm=1" \
|
||||
0 \
|
||||
-c "using encrypt then mac" \
|
||||
-c "reassembled record" \
|
||||
-c "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-c "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-c "Prepare: waiting for more handshake fragments 4/" \
|
||||
-c "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
run_test "Handshake defragmentation on client: len=3, TLS 1.3" \
|
||||
"$O_NEXT_SRV -tls1_3 -allow_no_dhe_kex -split_send_frag 3" \
|
||||
"$P_CLI debug_level=4" \
|
||||
1 \
|
||||
-c "=> ssl_tls13_process_server_hello" \
|
||||
-c "handshake message too short: 3" \
|
||||
-c "SSL - An invalid SSL record was received"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
run_test "Handshake defragmentation on client: len=3, TLS 1.2" \
|
||||
"$O_NEXT_SRV -tls1_2 -allow_no_dhe_kex -split_send_frag 3" \
|
||||
"$P_CLI debug_level=4" \
|
||||
1 \
|
||||
-c "handshake message too short: 3" \
|
||||
-c "SSL - An invalid SSL record was received"
|
||||
|
||||
run_test "Handshake defragmentation on server: no fragmentation, for reference" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -allow_no_dhe_kex -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-S "waiting for more fragments"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=512, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -split_send_frag 512 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 512, 0\\.\\.512 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 512\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 512/" \
|
||||
-s "Consume: waiting for more handshake fragments 512/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=512, TLS 1.2" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 512 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 512, 0\\.\\.512 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 512\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 512/" \
|
||||
-s "Consume: waiting for more handshake fragments 512/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=513, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -split_send_frag 513 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 513, 0\\.\\.513 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 513\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 513/" \
|
||||
-s "Consume: waiting for more handshake fragments 513/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=513, TLS 1.2" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 513 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 513, 0\\.\\.513 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 513\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 513/" \
|
||||
-s "Consume: waiting for more handshake fragments 513/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=256, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -split_send_frag 256 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 256, 0\\.\\.256 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 256\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 256/" \
|
||||
-s "Consume: waiting for more handshake fragments 256/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=256, TLS 1.2" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 256 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 256, 0\\.\\.256 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 256\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 256/" \
|
||||
-s "Consume: waiting for more handshake fragments 256/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=128, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -split_send_frag 128 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 128, 0\\.\\.128 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 128\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 128/" \
|
||||
-s "Consume: waiting for more handshake fragments 128/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=128, TLS 1.2" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 128 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 128, 0\\.\\.128 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 128\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 128/" \
|
||||
-s "Consume: waiting for more handshake fragments 128/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=64, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -split_send_frag 64 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 64, 0\\.\\.64 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 64\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 64/" \
|
||||
-s "Consume: waiting for more handshake fragments 64/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=64, TLS 1.2" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 64 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 64, 0\\.\\.64 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 64\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 64/" \
|
||||
-s "Consume: waiting for more handshake fragments 64/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=36, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -split_send_frag 36 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 36, 0\\.\\.36 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 36\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 36/" \
|
||||
-s "Consume: waiting for more handshake fragments 36/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=36, TLS 1.2" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 36 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 36, 0\\.\\.36 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 36\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 36/" \
|
||||
-s "Consume: waiting for more handshake fragments 36/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=32, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -split_send_frag 32 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 32, 0\\.\\.32 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 32\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 32/" \
|
||||
-s "Consume: waiting for more handshake fragments 32/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=32, TLS 1.2" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 32 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 32, 0\\.\\.32 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 32\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 32/" \
|
||||
-s "Consume: waiting for more handshake fragments 32/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=16, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -split_send_frag 16 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 16, 0\\.\\.16 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 16\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 16/" \
|
||||
-s "Consume: waiting for more handshake fragments 16/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=16, TLS 1.2" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 16 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 16, 0\\.\\.16 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 16\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 16/" \
|
||||
-s "Consume: waiting for more handshake fragments 16/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=13, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -split_send_frag 13 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 13, 0\\.\\.13 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 13\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 13/" \
|
||||
-s "Consume: waiting for more handshake fragments 13/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=13, TLS 1.2" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 13 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 13, 0\\.\\.13 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 13\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 13/" \
|
||||
-s "Consume: waiting for more handshake fragments 13/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=5, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -split_send_frag 5 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 5, 0\\.\\.5 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 5\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 5/" \
|
||||
-s "Consume: waiting for more handshake fragments 5/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=5, TLS 1.2" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 5 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 5, 0\\.\\.5 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 5\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 5/" \
|
||||
-s "Consume: waiting for more handshake fragments 5/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=4, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -split_send_frag 4 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 4/" \
|
||||
-s "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
run_test "Handshake defragmentation on server: len=4, TLS 1.2, default" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 4 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 4/" \
|
||||
-s "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_ciphersuite_enabled TLS-ECDHE-ECDSA-WITH-NULL-SHA
|
||||
run_test "Handshake defragmentation on server: len=4, TLS 1.2, null" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 4 -cipher ECDHE-ECDSA-NULL-SHA@SECLEVEL=0 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 4/" \
|
||||
-s "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_ciphersuite_enabled TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256
|
||||
run_test "Handshake defragmentation on server: len=4, TLS 1.2, ChachaPoly" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 4 -cipher ECDHE-ECDSA-CHACHA20-POLY1305 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 4/" \
|
||||
-s "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_ciphersuite_enabled TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256
|
||||
run_test "Handshake defragmentation on server: len=4, TLS 1.2, GCM" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 4 -cipher ECDHE-ECDSA-AES128-GCM-SHA256 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 4/" \
|
||||
-s "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_ciphersuite_enabled TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256
|
||||
run_test "Handshake defragmentation on server: len=4, TLS 1.2, CBC, etm=n" \
|
||||
"$P_SRV debug_level=4 etm=0 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 4 -cipher ECDHE-ECDSA-AES128-SHA256 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 4/" \
|
||||
-s "Consume: waiting for more handshake fragments 4/" \
|
||||
-S "using encrypt then mac"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
requires_certificate_authentication
|
||||
requires_ciphersuite_enabled TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256
|
||||
requires_config_enabled MBEDTLS_SSL_ENCRYPT_THEN_MAC
|
||||
run_test "Handshake defragmentation on server: len=4, TLS 1.2, CBC, etm=y" \
|
||||
"$P_SRV debug_level=4 etm=1 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -split_send_frag 4 -cipher ECDHE-ECDSA-AES128-SHA256 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
0 \
|
||||
-s "using encrypt then mac" \
|
||||
-s "reassembled record" \
|
||||
-s "initial handshake fragment: 4, 0\\.\\.4 of [0-9]\\+" \
|
||||
-s "subsequent handshake fragment: [0-9]\\+, 4\\.\\." \
|
||||
-s "Prepare: waiting for more handshake fragments 4/" \
|
||||
-s "Consume: waiting for more handshake fragments 4/"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||
run_test "Handshake defragmentation on server: len=3, TLS 1.3" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_3 -allow_no_dhe_kex -split_send_frag 3 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
1 \
|
||||
-s "=> parse client hello" \
|
||||
-s "handshake message too short: 3" \
|
||||
-s "SSL - An invalid SSL record was received"
|
||||
|
||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||
run_test "Handshake defragmentation on server: len=3, TLS 1.2" \
|
||||
"$P_SRV debug_level=4 auth_mode=required" \
|
||||
"$O_NEXT_CLI -tls1_2 -allow_no_dhe_kex -split_send_frag 3 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
|
||||
1 \
|
||||
-s "=> parse client hello" \
|
||||
-s "handshake message too short: 3" \
|
||||
-s "SSL - An invalid SSL record was received"
|
||||
|
||||
# End of automatically generated file.
|
||||
374
vendor/mbedtls/tests/opt-testcases/sample.sh
vendored
Normal file
374
vendor/mbedtls/tests/opt-testcases/sample.sh
vendored
Normal file
@@ -0,0 +1,374 @@
|
||||
# Test that SSL sample programs can interoperate with each other
|
||||
# and with OpenSSL and GnuTLS.
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
: ${PROGRAMS_DIR:=../programs/ssl}
|
||||
|
||||
run_test "Sample: ssl_client1, ssl_server2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_server2" \
|
||||
"$PROGRAMS_DIR/ssl_client1" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-S "error" \
|
||||
-C "error"
|
||||
|
||||
requires_protocol_version tls12
|
||||
run_test "Sample: ssl_client1, openssl server, TLS 1.2" \
|
||||
-P 4433 \
|
||||
"$O_SRV -tls1_2" \
|
||||
"$PROGRAMS_DIR/ssl_client1" \
|
||||
0 \
|
||||
-c "Protocol.*TLSv1.2" \
|
||||
-S "ERROR" \
|
||||
-C "error"
|
||||
|
||||
requires_protocol_version tls12
|
||||
run_test "Sample: ssl_client1, gnutls server, TLS 1.2" \
|
||||
-P 4433 \
|
||||
"$G_SRV --priority=NORMAL:-VERS-TLS-ALL:+VERS-TLS1.2" \
|
||||
"$PROGRAMS_DIR/ssl_client1" \
|
||||
0 \
|
||||
-s "Version: TLS1.2" \
|
||||
-c "<TD>Protocol version:</TD><TD>TLS1.2</TD>" \
|
||||
-S "Error" \
|
||||
-C "error"
|
||||
|
||||
requires_protocol_version tls13
|
||||
requires_openssl_tls1_3
|
||||
run_test "Sample: ssl_client1, openssl server, TLS 1.3" \
|
||||
-P 4433 \
|
||||
"$O_NEXT_SRV -tls1_3" \
|
||||
"$PROGRAMS_DIR/ssl_client1" \
|
||||
0 \
|
||||
-c "New, TLSv1.3, Cipher is" \
|
||||
-S "ERROR" \
|
||||
-C "error"
|
||||
|
||||
requires_protocol_version tls13
|
||||
requires_gnutls_tls1_3
|
||||
run_test "Sample: ssl_client1, gnutls server, TLS 1.3" \
|
||||
-P 4433 \
|
||||
"$G_NEXT_SRV --priority=NORMAL:-VERS-TLS-ALL:+VERS-TLS1.3" \
|
||||
"$PROGRAMS_DIR/ssl_client1" \
|
||||
0 \
|
||||
-s "Version: TLS1.3" \
|
||||
-c "<TD>Protocol version:</TD><TD>TLS1.3</TD>" \
|
||||
-S "Error" \
|
||||
-C "error"
|
||||
|
||||
# The server complains of extra data after it closes the connection
|
||||
# because the client keeps sending data, so the server receives
|
||||
# more application data when it expects a new handshake. We consider
|
||||
# the test a success if both sides have sent and received application
|
||||
# data, no matter what happens afterwards.
|
||||
run_test "Sample: dtls_client, ssl_server2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_server2 dtls=1 server_addr=localhost" \
|
||||
"$PROGRAMS_DIR/dtls_client" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-C "error"
|
||||
|
||||
# The dtls_client program connects to localhost. This test case fails on
|
||||
# systems where the name "localhost" resolves to an IPv6 address, but
|
||||
# the IPv6 connection is not possible. Possible reasons include:
|
||||
# * OpenSSL is too old (IPv6 support was added in 1.1.0).
|
||||
# * OpenSSL was built without IPv6 support.
|
||||
# * A firewall blocks IPv6.
|
||||
#
|
||||
# To facilitate working with this test case, have it run with $OPENSSL_NEXT
|
||||
# which is at least 1.1.1a. At the time it was introduced, this test case
|
||||
# passed with OpenSSL 1.0.2g on an environment where IPv6 is disabled.
|
||||
requires_protocol_version dtls12
|
||||
run_test "Sample: dtls_client, openssl server, DTLS 1.2" \
|
||||
-P 4433 \
|
||||
"$O_NEXT_SRV -dtls1_2" \
|
||||
"$PROGRAMS_DIR/dtls_client" \
|
||||
0 \
|
||||
-s "Echo this" \
|
||||
-c "Echo this" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-S "ERROR" \
|
||||
-C "error"
|
||||
|
||||
requires_protocol_version dtls12
|
||||
run_test "Sample: dtls_client, gnutls server, DTLS 1.2" \
|
||||
-P 4433 \
|
||||
"$G_SRV -u --echo --priority=NORMAL:-VERS-TLS-ALL:+VERS-TLS1.2" \
|
||||
"$PROGRAMS_DIR/dtls_client" \
|
||||
0 \
|
||||
-s "Server listening" \
|
||||
-s "[1-9][0-9]* bytes command:" \
|
||||
-c "Echo this" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-S "Error" \
|
||||
-C "error"
|
||||
|
||||
run_test "Sample: ssl_server, ssl_client2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_server" \
|
||||
"$PROGRAMS_DIR/ssl_client2" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-S "error" \
|
||||
-C "error"
|
||||
|
||||
run_test "Sample: ssl_client1 with ssl_server" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_server" \
|
||||
"$PROGRAMS_DIR/ssl_client1" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-S "error" \
|
||||
-C "error"
|
||||
|
||||
requires_protocol_version tls12
|
||||
run_test "Sample: ssl_server, openssl client, TLS 1.2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_server" \
|
||||
"$O_CLI -tls1_2" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS-" \
|
||||
-c "Protocol.*TLSv1.2" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
requires_protocol_version tls12
|
||||
run_test "Sample: ssl_server, gnutls client, TLS 1.2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_server" \
|
||||
"$G_CLI --priority=NORMAL:-VERS-TLS-ALL:+VERS-TLS1.2 localhost" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS-" \
|
||||
-c "Description:.*TLS1.2" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
requires_protocol_version tls13
|
||||
requires_openssl_tls1_3
|
||||
run_test "Sample: ssl_server, openssl client, TLS 1.3" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_server" \
|
||||
"$O_NEXT_CLI -tls1_3" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS1-3-" \
|
||||
-c "New, TLSv1.3, Cipher is" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
requires_protocol_version tls13
|
||||
requires_gnutls_tls1_3
|
||||
run_test "Sample: ssl_server, gnutls client, TLS 1.3" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_server" \
|
||||
"$G_NEXT_CLI --priority=NORMAL:-VERS-TLS-ALL:+VERS-TLS1.3 localhost" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS1-3-" \
|
||||
-c "Description:.*TLS1.3" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
run_test "Sample: ssl_fork_server, ssl_client2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_fork_server" \
|
||||
"$PROGRAMS_DIR/ssl_client2" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-S "error" \
|
||||
-C "error"
|
||||
|
||||
run_test "Sample: ssl_client1 with ssl_fork_server" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_fork_server" \
|
||||
"$PROGRAMS_DIR/ssl_client1" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-S "error" \
|
||||
-C "error"
|
||||
|
||||
requires_protocol_version tls12
|
||||
run_test "Sample: ssl_fork_server, openssl client, TLS 1.2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_fork_server" \
|
||||
"$O_CLI -tls1_2" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS-" \
|
||||
-c "Protocol.*TLSv1.2" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
requires_protocol_version tls12
|
||||
run_test "Sample: ssl_fork_server, gnutls client, TLS 1.2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_fork_server" \
|
||||
"$G_CLI --priority=NORMAL:-VERS-TLS-ALL:+VERS-TLS1.2 localhost" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS-" \
|
||||
-c "Description:.*TLS1.2" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
requires_protocol_version tls13
|
||||
requires_openssl_tls1_3
|
||||
run_test "Sample: ssl_fork_server, openssl client, TLS 1.3" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_fork_server" \
|
||||
"$O_NEXT_CLI -tls1_3" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS1-3-" \
|
||||
-c "New, TLSv1.3, Cipher is" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
requires_protocol_version tls13
|
||||
requires_gnutls_tls1_3
|
||||
run_test "Sample: ssl_fork_server, gnutls client, TLS 1.3" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_fork_server" \
|
||||
"$G_NEXT_CLI --priority=NORMAL:-VERS-TLS-ALL:+VERS-TLS1.3 localhost" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS1-3-" \
|
||||
-c "Description:.*TLS1.3" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
run_test "Sample: ssl_pthread_server, ssl_client2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_pthread_server" \
|
||||
"$PROGRAMS_DIR/ssl_client2" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-S "error" \
|
||||
-C "error"
|
||||
|
||||
run_test "Sample: ssl_client1 with ssl_pthread_server" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_pthread_server" \
|
||||
"$PROGRAMS_DIR/ssl_client1" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-S "error" \
|
||||
-C "error"
|
||||
|
||||
requires_protocol_version tls12
|
||||
run_test "Sample: ssl_pthread_server, openssl client, TLS 1.2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_pthread_server" \
|
||||
"$O_CLI -tls1_2" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS-" \
|
||||
-c "Protocol.*TLSv1.2" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
requires_protocol_version tls12
|
||||
run_test "Sample: ssl_pthread_server, gnutls client, TLS 1.2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_pthread_server" \
|
||||
"$G_CLI --priority=NORMAL:-VERS-TLS-ALL:+VERS-TLS1.2 localhost" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS-" \
|
||||
-c "Description:.*TLS1.2" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
requires_protocol_version tls13
|
||||
requires_openssl_tls1_3
|
||||
run_test "Sample: ssl_pthread_server, openssl client, TLS 1.3" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_pthread_server" \
|
||||
"$O_NEXT_CLI -tls1_3" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS1-3-" \
|
||||
-c "New, TLSv1.3, Cipher is" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
requires_protocol_version tls13
|
||||
requires_gnutls_tls1_3
|
||||
run_test "Sample: ssl_pthread_server, gnutls client, TLS 1.3" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/ssl_pthread_server" \
|
||||
"$G_NEXT_CLI --priority=NORMAL:-VERS-TLS-ALL:+VERS-TLS1.3 localhost" \
|
||||
0 \
|
||||
-s "Successful connection using: TLS1-3-" \
|
||||
-c "Description:.*TLS1.3" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
run_test "Sample: dtls_client with dtls_server" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/dtls_server" \
|
||||
"$PROGRAMS_DIR/dtls_client" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-S "error" \
|
||||
-C "error"
|
||||
|
||||
run_test "Sample: ssl_client2, dtls_server" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/dtls_server" \
|
||||
"$PROGRAMS_DIR/ssl_client2 dtls=1" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "[1-9][0-9]* bytes read" \
|
||||
-c "[1-9][0-9]* bytes written" \
|
||||
-S "error" \
|
||||
-C "error"
|
||||
|
||||
requires_protocol_version dtls12
|
||||
run_test "Sample: dtls_server, openssl client, DTLS 1.2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/dtls_server" \
|
||||
"$O_CLI -dtls1_2" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "Protocol.*TLSv1.2" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
|
||||
requires_protocol_version dtls12
|
||||
run_test "Sample: dtls_server, gnutls client, DTLS 1.2" \
|
||||
-P 4433 \
|
||||
"$PROGRAMS_DIR/dtls_server" \
|
||||
"$G_CLI -u --priority=NORMAL:-VERS-TLS-ALL:+VERS-TLS1.2 localhost" \
|
||||
0 \
|
||||
-s "[1-9][0-9]* bytes read" \
|
||||
-s "[1-9][0-9]* bytes written" \
|
||||
-c "Description:.*DTLS1.2" \
|
||||
-S "error" \
|
||||
-C "ERROR"
|
||||
14032
vendor/mbedtls/tests/opt-testcases/tls13-compat.sh
vendored
Normal file
14032
vendor/mbedtls/tests/opt-testcases/tls13-compat.sh
vendored
Normal file
File diff suppressed because it is too large
Load Diff
3325
vendor/mbedtls/tests/opt-testcases/tls13-kex-modes.sh
vendored
Normal file
3325
vendor/mbedtls/tests/opt-testcases/tls13-kex-modes.sh
vendored
Normal file
File diff suppressed because it is too large
Load Diff
1362
vendor/mbedtls/tests/opt-testcases/tls13-misc.sh
vendored
Normal file
1362
vendor/mbedtls/tests/opt-testcases/tls13-misc.sh
vendored
Normal file
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user