blob: a843ca6d516e52a86276765bb134f05a74126626 [file] [log] [blame]
Alexander Afanasyevba2cf392017-01-13 19:05:23 -08001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
Zhiyi Zhanga1302f62017-10-31 10:22:35 -07002/*
Davide Pesavento47ce2ee2023-05-09 01:33:33 -04003 * Copyright (c) 2013-2023 Regents of the University of California.
Alexander Afanasyevba2cf392017-01-13 19:05:23 -08004 *
5 * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions).
6 *
7 * ndn-cxx library is free software: you can redistribute it and/or modify it under the
8 * terms of the GNU Lesser General Public License as published by the Free Software
9 * Foundation, either version 3 of the License, or (at your option) any later version.
10 *
11 * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License and GNU Lesser
16 * General Public License along with ndn-cxx, e.g., in COPYING.md file. If not, see
17 * <http://www.gnu.org/licenses/>.
18 *
19 * See AUTHORS.md for complete list of ndn-cxx authors and contributors.
20 */
21
Alexander Afanasyev09236c22020-06-03 13:42:38 -040022#include "ndn-cxx/security/certificate-fetcher-direct-fetch.hpp"
Davide Pesavento4c1ad4c2020-11-16 21:12:02 -050023
Davide Pesavento7e780642018-11-24 15:51:34 -050024#include "ndn-cxx/lp/tags.hpp"
Davide Pesavento4c1ad4c2020-11-16 21:12:02 -050025#include "ndn-cxx/security/validation-policy-simple-hierarchy.hpp"
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080026
Davide Pesavento2acce252022-09-08 22:03:03 -040027#include "tests/test-common.hpp"
Alexander Afanasyev09236c22020-06-03 13:42:38 -040028#include "tests/unit/security/validator-fixture.hpp"
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080029
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080030#include <boost/range/adaptor/sliced.hpp>
Davide Pesavento7e780642018-11-24 15:51:34 -050031#include <boost/range/adaptor/strided.hpp>
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080032
Davide Pesavento47ce2ee2023-05-09 01:33:33 -040033namespace ndn::tests {
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080034
Davide Pesavento47ce2ee2023-05-09 01:33:33 -040035using namespace ndn::security;
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080036
37BOOST_AUTO_TEST_SUITE(Security)
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080038BOOST_AUTO_TEST_SUITE(TestCertificateFetcherDirectFetch)
39
Davide Pesavento47ce2ee2023-05-09 01:33:33 -040040struct Cert {};
41struct Timeout {};
42struct Nack {};
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080043
44template<class Response>
45class CertificateFetcherDirectFetchFixture : public HierarchicalValidatorFixture<ValidationPolicySimpleHierarchy,
46 CertificateFetcherDirectFetch>
47{
48public:
Alexander Afanasyev1660d002019-03-18 10:45:39 -040049 enum class ResponseType {
50 INFRASTRUCTURE,
51 DIRECT,
52 BOTH
53 };
54
55public:
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080056 CertificateFetcherDirectFetchFixture()
Alexander Afanasyev09236c22020-06-03 13:42:38 -040057 : data("/Security/ValidatorFixture/Sub1/Sub3/Data")
58 , interest("/Security/ValidatorFixture/Sub1/Sub3/Interest")
59 , interestNoTag("/Security/ValidatorFixture/Sub1/Sub3/Interest2")
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080060 {
Alexander Afanasyev09236c22020-06-03 13:42:38 -040061 Identity subSubIdentity = addSubCertificate("/Security/ValidatorFixture/Sub1/Sub3", subIdentity);
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080062 cache.insert(subSubIdentity.getDefaultKey().getDefaultCertificate());
63
64 m_keyChain.sign(data, signingByIdentity(subSubIdentity));
65 m_keyChain.sign(interest, signingByIdentity(subSubIdentity));
66 m_keyChain.sign(interestNoTag, signingByIdentity(subSubIdentity));
67
68 data.setTag(make_shared<lp::IncomingFaceIdTag>(123));
69 interest.setTag(make_shared<lp::IncomingFaceIdTag>(123));
70
71 processInterest = [this] (const Interest& interest) {
72 auto nextHopFaceIdTag = interest.template getTag<lp::NextHopFaceIdTag>();
73 if (nextHopFaceIdTag == nullptr) {
Alexander Afanasyev1660d002019-03-18 10:45:39 -040074 if (responseType == ResponseType::INFRASTRUCTURE || responseType == ResponseType::BOTH) {
75 makeResponse(interest);
76 }
77 }
78 else {
79 if (responseType == ResponseType::DIRECT || responseType == ResponseType::BOTH) {
80 makeResponse(interest);
81 }
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080082 }
83 };
84 }
85
86 void
87 makeResponse(const Interest& interest);
88
Alexander Afanasyev1660d002019-03-18 10:45:39 -040089 void
90 setResponseType(ResponseType type)
91 {
92 responseType = type;
93 }
94
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080095public:
96 Data data;
97 Interest interest;
98 Interest interestNoTag;
Alexander Afanasyev1660d002019-03-18 10:45:39 -040099 ResponseType responseType = ResponseType::INFRASTRUCTURE;
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800100};
101
102template<>
103void
104CertificateFetcherDirectFetchFixture<Cert>::makeResponse(const Interest& interest)
105{
106 auto cert = cache.find(interest);
107 if (cert == nullptr) {
108 return;
109 }
110 face.receive(*cert);
111}
112
113template<>
114void
115CertificateFetcherDirectFetchFixture<Timeout>::makeResponse(const Interest& interest)
116{
117 // do nothing
118}
119
120template<>
121void
122CertificateFetcherDirectFetchFixture<Nack>::makeResponse(const Interest& interest)
123{
Davide Pesavento2acce252022-09-08 22:03:03 -0400124 face.receive(makeNack(interest, lp::NackReason::NO_ROUTE));
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800125}
126
127using Failures = boost::mpl::vector<Timeout, Nack>;
128
129BOOST_FIXTURE_TEST_CASE(ValidateSuccessData, CertificateFetcherDirectFetchFixture<Cert>)
130{
Zhiyi Zhanga1302f62017-10-31 10:22:35 -0700131 VALIDATE_SUCCESS(this->data, "Should get accepted, normal and/or direct interests bring certs");
132 BOOST_CHECK_EQUAL(this->face.sentInterests.size(), 4);
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800133
Zhiyi Zhanga1302f62017-10-31 10:22:35 -0700134 // odd interests
135 for (const auto& sentInterest : this->face.sentInterests | boost::adaptors::strided(2)) {
136 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
137 }
138
139 // even interests
140 for (const auto& sentInterest : this->face.sentInterests |
141 boost::adaptors::sliced(1, this->face.sentInterests.size()) |
142 boost::adaptors::strided(2)) {
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800143 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() == nullptr);
144 }
145}
146
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400147BOOST_FIXTURE_TEST_CASE(ValidateSuccessDataDirectOnly, CertificateFetcherDirectFetchFixture<Cert>)
148{
149 setResponseType(ResponseType::DIRECT);
150 static_cast<CertificateFetcherDirectFetch&>(validator.getFetcher()).setSendDirectInterestOnly(true);
151
152 VALIDATE_SUCCESS(this->data, "Should get accepted, direct interests bring certs");
153 BOOST_CHECK_EQUAL(this->face.sentInterests.size(), 2);
154
155 for (const auto& sentInterest : this->face.sentInterests) {
156 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
157 }
158}
159
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800160BOOST_FIXTURE_TEST_CASE_TEMPLATE(ValidateFailureData, T, Failures, CertificateFetcherDirectFetchFixture<T>)
161{
Zhiyi Zhanga1302f62017-10-31 10:22:35 -0700162 VALIDATE_FAILURE(this->data, "Should fail, as all interests either NACKed or timeout");
Davide Pesavento2acce252022-09-08 22:03:03 -0400163 BOOST_TEST(this->lastError.getCode() == ValidationError::CANNOT_RETRIEVE_CERT);
Ashlesh Gawande3e39a4d2018-08-30 16:49:13 -0500164 // Direct fetcher sends two interests each time - to network and face
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400165 // 3 retries on nack or timeout (2 * (1 + 3) = 8)
Davide Pesavento2acce252022-09-08 22:03:03 -0400166 BOOST_TEST(this->face.sentInterests.size() == 8);
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800167
Zhiyi Zhanga1302f62017-10-31 10:22:35 -0700168 // odd interests
169 for (const auto& sentInterest : this->face.sentInterests | boost::adaptors::strided(2)) {
170 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
171 }
172
173 // even interests
174 for (const auto& sentInterest : this->face.sentInterests |
175 boost::adaptors::sliced(1, this->face.sentInterests.size()) |
176 boost::adaptors::strided(2)) {
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800177 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() == nullptr);
178 }
179}
180
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400181BOOST_FIXTURE_TEST_CASE_TEMPLATE(ValidateFailureDataDirectOnly, T, Failures, CertificateFetcherDirectFetchFixture<T>)
182{
183 this->setResponseType(CertificateFetcherDirectFetchFixture<T>::ResponseType::DIRECT);
184 static_cast<CertificateFetcherDirectFetch&>(this->validator.getFetcher()).setSendDirectInterestOnly(true);
185
186 VALIDATE_FAILURE(this->data, "Should fail, as all interests either NACKed or timeout");
Davide Pesavento2acce252022-09-08 22:03:03 -0400187 BOOST_TEST(this->lastError.getCode() == ValidationError::CANNOT_RETRIEVE_CERT);
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400188 // Direct fetcher sends two interests each time - to network and face
189 // 3 retries on nack or timeout (1 + 3 = 4)
Davide Pesavento2acce252022-09-08 22:03:03 -0400190 BOOST_TEST(this->face.sentInterests.size() == 4);
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400191
192 for (const auto& sentInterest : this->face.sentInterests) {
193 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
194 }
195}
196
197BOOST_FIXTURE_TEST_CASE_TEMPLATE(ValidateFailureDataNoTagDirectOnly, T, Failures, CertificateFetcherDirectFetchFixture<T>)
198{
199 this->setResponseType(CertificateFetcherDirectFetchFixture<T>::ResponseType::DIRECT);
200 static_cast<CertificateFetcherDirectFetch&>(this->validator.getFetcher()).setSendDirectInterestOnly(true);
201
202 this->data.template removeTag<lp::IncomingFaceIdTag>();
203 this->interest.template removeTag<lp::IncomingFaceIdTag>();
204
205 VALIDATE_FAILURE(this->data, "Should fail, as no interests are expected");
Davide Pesavento2acce252022-09-08 22:03:03 -0400206 BOOST_TEST(this->lastError.getCode() == ValidationError::CANNOT_RETRIEVE_CERT);
207 BOOST_TEST(this->face.sentInterests.size() == 0);
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400208}
209
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800210BOOST_FIXTURE_TEST_CASE(ValidateSuccessInterest, CertificateFetcherDirectFetchFixture<Cert>)
211{
212 VALIDATE_SUCCESS(this->interest, "Should get accepted, normal and/or direct interests bring certs");
213 BOOST_CHECK_EQUAL(this->face.sentInterests.size(), 4);
214
215 // odd interests
216 for (const auto& sentInterest : this->face.sentInterests | boost::adaptors::strided(2)) {
217 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
218 }
219
220 // even interests
221 for (const auto& sentInterest : this->face.sentInterests |
222 boost::adaptors::sliced(1, this->face.sentInterests.size()) |
223 boost::adaptors::strided(2)) {
224 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() == nullptr);
225 }
226}
227
228BOOST_FIXTURE_TEST_CASE_TEMPLATE(ValidateFailureInterest, T, Failures, CertificateFetcherDirectFetchFixture<T>)
229{
230 VALIDATE_FAILURE(this->interest, "Should fail, as all interests either NACKed or timeout");
Davide Pesavento2acce252022-09-08 22:03:03 -0400231 BOOST_TEST(this->lastError.getCode() == ValidationError::CANNOT_RETRIEVE_CERT);
Ashlesh Gawande3e39a4d2018-08-30 16:49:13 -0500232 // Direct fetcher sends two interests each time - to network and face
233 // 3 retries on nack or timeout (2 * (1 + 3) = 4)
Davide Pesavento2acce252022-09-08 22:03:03 -0400234 BOOST_TEST(this->face.sentInterests.size() == 8);
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800235
236 // odd interests
237 for (const auto& sentInterest : this->face.sentInterests | boost::adaptors::strided(2)) {
238 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
239 }
240
241 // even interests
242 for (const auto& sentInterest : this->face.sentInterests |
243 boost::adaptors::sliced(1, this->face.sentInterests.size()) |
244 boost::adaptors::strided(2)) {
245 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() == nullptr);
246 }
247}
248
249BOOST_AUTO_TEST_SUITE_END() // TestCertificateFetcherDirectFetch
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800250BOOST_AUTO_TEST_SUITE_END() // Security
251
Davide Pesavento47ce2ee2023-05-09 01:33:33 -0400252} // namespace ndn::tests