blob: ca185c60da173f8abadb67bbdecf45f800246a33 [file] [log] [blame]
Alexander Afanasyevba2cf392017-01-13 19:05:23 -08001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
Zhiyi Zhanga1302f62017-10-31 10:22:35 -07002/*
Davide Pesavento47ce2ee2023-05-09 01:33:33 -04003 * Copyright (c) 2013-2023 Regents of the University of California.
Alexander Afanasyevba2cf392017-01-13 19:05:23 -08004 *
5 * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions).
6 *
7 * ndn-cxx library is free software: you can redistribute it and/or modify it under the
8 * terms of the GNU Lesser General Public License as published by the Free Software
9 * Foundation, either version 3 of the License, or (at your option) any later version.
10 *
11 * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License and GNU Lesser
16 * General Public License along with ndn-cxx, e.g., in COPYING.md file. If not, see
17 * <http://www.gnu.org/licenses/>.
18 *
19 * See AUTHORS.md for complete list of ndn-cxx authors and contributors.
20 */
21
Alexander Afanasyev09236c22020-06-03 13:42:38 -040022#include "ndn-cxx/security/certificate-fetcher-direct-fetch.hpp"
Davide Pesavento4c1ad4c2020-11-16 21:12:02 -050023
Davide Pesavento7e780642018-11-24 15:51:34 -050024#include "ndn-cxx/lp/tags.hpp"
Davide Pesavento4c1ad4c2020-11-16 21:12:02 -050025#include "ndn-cxx/security/validation-policy-simple-hierarchy.hpp"
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080026
Davide Pesavento2acce252022-09-08 22:03:03 -040027#include "tests/test-common.hpp"
Alexander Afanasyev09236c22020-06-03 13:42:38 -040028#include "tests/unit/security/validator-fixture.hpp"
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080029
Davide Pesavento49e1e872023-11-11 00:45:23 -050030#include <boost/mp11/list.hpp>
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080031#include <boost/range/adaptor/sliced.hpp>
Davide Pesavento7e780642018-11-24 15:51:34 -050032#include <boost/range/adaptor/strided.hpp>
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080033
Davide Pesavento47ce2ee2023-05-09 01:33:33 -040034namespace ndn::tests {
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080035
Davide Pesavento47ce2ee2023-05-09 01:33:33 -040036using namespace ndn::security;
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080037
38BOOST_AUTO_TEST_SUITE(Security)
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080039BOOST_AUTO_TEST_SUITE(TestCertificateFetcherDirectFetch)
40
Davide Pesavento47ce2ee2023-05-09 01:33:33 -040041struct Cert {};
42struct Timeout {};
43struct Nack {};
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080044
45template<class Response>
46class CertificateFetcherDirectFetchFixture : public HierarchicalValidatorFixture<ValidationPolicySimpleHierarchy,
47 CertificateFetcherDirectFetch>
48{
49public:
Alexander Afanasyev1660d002019-03-18 10:45:39 -040050 enum class ResponseType {
51 INFRASTRUCTURE,
52 DIRECT,
53 BOTH
54 };
55
56public:
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080057 CertificateFetcherDirectFetchFixture()
Alexander Afanasyev09236c22020-06-03 13:42:38 -040058 : data("/Security/ValidatorFixture/Sub1/Sub3/Data")
59 , interest("/Security/ValidatorFixture/Sub1/Sub3/Interest")
60 , interestNoTag("/Security/ValidatorFixture/Sub1/Sub3/Interest2")
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080061 {
Alexander Afanasyev09236c22020-06-03 13:42:38 -040062 Identity subSubIdentity = addSubCertificate("/Security/ValidatorFixture/Sub1/Sub3", subIdentity);
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080063 cache.insert(subSubIdentity.getDefaultKey().getDefaultCertificate());
64
65 m_keyChain.sign(data, signingByIdentity(subSubIdentity));
66 m_keyChain.sign(interest, signingByIdentity(subSubIdentity));
67 m_keyChain.sign(interestNoTag, signingByIdentity(subSubIdentity));
68
69 data.setTag(make_shared<lp::IncomingFaceIdTag>(123));
70 interest.setTag(make_shared<lp::IncomingFaceIdTag>(123));
71
72 processInterest = [this] (const Interest& interest) {
73 auto nextHopFaceIdTag = interest.template getTag<lp::NextHopFaceIdTag>();
74 if (nextHopFaceIdTag == nullptr) {
Alexander Afanasyev1660d002019-03-18 10:45:39 -040075 if (responseType == ResponseType::INFRASTRUCTURE || responseType == ResponseType::BOTH) {
76 makeResponse(interest);
77 }
78 }
79 else {
80 if (responseType == ResponseType::DIRECT || responseType == ResponseType::BOTH) {
81 makeResponse(interest);
82 }
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080083 }
84 };
85 }
86
87 void
88 makeResponse(const Interest& interest);
89
Alexander Afanasyev1660d002019-03-18 10:45:39 -040090 void
91 setResponseType(ResponseType type)
92 {
93 responseType = type;
94 }
95
Alexander Afanasyevba2cf392017-01-13 19:05:23 -080096public:
97 Data data;
98 Interest interest;
99 Interest interestNoTag;
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400100 ResponseType responseType = ResponseType::INFRASTRUCTURE;
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800101};
102
103template<>
104void
105CertificateFetcherDirectFetchFixture<Cert>::makeResponse(const Interest& interest)
106{
107 auto cert = cache.find(interest);
108 if (cert == nullptr) {
109 return;
110 }
111 face.receive(*cert);
112}
113
114template<>
115void
116CertificateFetcherDirectFetchFixture<Timeout>::makeResponse(const Interest& interest)
117{
118 // do nothing
119}
120
121template<>
122void
123CertificateFetcherDirectFetchFixture<Nack>::makeResponse(const Interest& interest)
124{
Davide Pesavento2acce252022-09-08 22:03:03 -0400125 face.receive(makeNack(interest, lp::NackReason::NO_ROUTE));
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800126}
127
Davide Pesavento49e1e872023-11-11 00:45:23 -0500128using Failures = boost::mp11::mp_list<Timeout, Nack>;
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800129
130BOOST_FIXTURE_TEST_CASE(ValidateSuccessData, CertificateFetcherDirectFetchFixture<Cert>)
131{
Zhiyi Zhanga1302f62017-10-31 10:22:35 -0700132 VALIDATE_SUCCESS(this->data, "Should get accepted, normal and/or direct interests bring certs");
133 BOOST_CHECK_EQUAL(this->face.sentInterests.size(), 4);
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800134
Zhiyi Zhanga1302f62017-10-31 10:22:35 -0700135 // odd interests
136 for (const auto& sentInterest : this->face.sentInterests | boost::adaptors::strided(2)) {
137 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
138 }
139
140 // even interests
141 for (const auto& sentInterest : this->face.sentInterests |
142 boost::adaptors::sliced(1, this->face.sentInterests.size()) |
143 boost::adaptors::strided(2)) {
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800144 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() == nullptr);
145 }
146}
147
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400148BOOST_FIXTURE_TEST_CASE(ValidateSuccessDataDirectOnly, CertificateFetcherDirectFetchFixture<Cert>)
149{
150 setResponseType(ResponseType::DIRECT);
151 static_cast<CertificateFetcherDirectFetch&>(validator.getFetcher()).setSendDirectInterestOnly(true);
152
153 VALIDATE_SUCCESS(this->data, "Should get accepted, direct interests bring certs");
154 BOOST_CHECK_EQUAL(this->face.sentInterests.size(), 2);
155
156 for (const auto& sentInterest : this->face.sentInterests) {
157 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
158 }
159}
160
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800161BOOST_FIXTURE_TEST_CASE_TEMPLATE(ValidateFailureData, T, Failures, CertificateFetcherDirectFetchFixture<T>)
162{
Zhiyi Zhanga1302f62017-10-31 10:22:35 -0700163 VALIDATE_FAILURE(this->data, "Should fail, as all interests either NACKed or timeout");
Davide Pesavento2acce252022-09-08 22:03:03 -0400164 BOOST_TEST(this->lastError.getCode() == ValidationError::CANNOT_RETRIEVE_CERT);
Ashlesh Gawande3e39a4d2018-08-30 16:49:13 -0500165 // Direct fetcher sends two interests each time - to network and face
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400166 // 3 retries on nack or timeout (2 * (1 + 3) = 8)
Davide Pesavento2acce252022-09-08 22:03:03 -0400167 BOOST_TEST(this->face.sentInterests.size() == 8);
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800168
Zhiyi Zhanga1302f62017-10-31 10:22:35 -0700169 // odd interests
170 for (const auto& sentInterest : this->face.sentInterests | boost::adaptors::strided(2)) {
171 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
172 }
173
174 // even interests
175 for (const auto& sentInterest : this->face.sentInterests |
176 boost::adaptors::sliced(1, this->face.sentInterests.size()) |
177 boost::adaptors::strided(2)) {
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800178 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() == nullptr);
179 }
180}
181
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400182BOOST_FIXTURE_TEST_CASE_TEMPLATE(ValidateFailureDataDirectOnly, T, Failures, CertificateFetcherDirectFetchFixture<T>)
183{
184 this->setResponseType(CertificateFetcherDirectFetchFixture<T>::ResponseType::DIRECT);
185 static_cast<CertificateFetcherDirectFetch&>(this->validator.getFetcher()).setSendDirectInterestOnly(true);
186
187 VALIDATE_FAILURE(this->data, "Should fail, as all interests either NACKed or timeout");
Davide Pesavento2acce252022-09-08 22:03:03 -0400188 BOOST_TEST(this->lastError.getCode() == ValidationError::CANNOT_RETRIEVE_CERT);
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400189 // Direct fetcher sends two interests each time - to network and face
190 // 3 retries on nack or timeout (1 + 3 = 4)
Davide Pesavento2acce252022-09-08 22:03:03 -0400191 BOOST_TEST(this->face.sentInterests.size() == 4);
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400192
193 for (const auto& sentInterest : this->face.sentInterests) {
194 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
195 }
196}
197
198BOOST_FIXTURE_TEST_CASE_TEMPLATE(ValidateFailureDataNoTagDirectOnly, T, Failures, CertificateFetcherDirectFetchFixture<T>)
199{
200 this->setResponseType(CertificateFetcherDirectFetchFixture<T>::ResponseType::DIRECT);
201 static_cast<CertificateFetcherDirectFetch&>(this->validator.getFetcher()).setSendDirectInterestOnly(true);
202
203 this->data.template removeTag<lp::IncomingFaceIdTag>();
204 this->interest.template removeTag<lp::IncomingFaceIdTag>();
205
206 VALIDATE_FAILURE(this->data, "Should fail, as no interests are expected");
Davide Pesavento2acce252022-09-08 22:03:03 -0400207 BOOST_TEST(this->lastError.getCode() == ValidationError::CANNOT_RETRIEVE_CERT);
208 BOOST_TEST(this->face.sentInterests.size() == 0);
Alexander Afanasyev1660d002019-03-18 10:45:39 -0400209}
210
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800211BOOST_FIXTURE_TEST_CASE(ValidateSuccessInterest, CertificateFetcherDirectFetchFixture<Cert>)
212{
213 VALIDATE_SUCCESS(this->interest, "Should get accepted, normal and/or direct interests bring certs");
214 BOOST_CHECK_EQUAL(this->face.sentInterests.size(), 4);
215
216 // odd interests
217 for (const auto& sentInterest : this->face.sentInterests | boost::adaptors::strided(2)) {
218 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
219 }
220
221 // even interests
222 for (const auto& sentInterest : this->face.sentInterests |
223 boost::adaptors::sliced(1, this->face.sentInterests.size()) |
224 boost::adaptors::strided(2)) {
225 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() == nullptr);
226 }
227}
228
229BOOST_FIXTURE_TEST_CASE_TEMPLATE(ValidateFailureInterest, T, Failures, CertificateFetcherDirectFetchFixture<T>)
230{
231 VALIDATE_FAILURE(this->interest, "Should fail, as all interests either NACKed or timeout");
Davide Pesavento2acce252022-09-08 22:03:03 -0400232 BOOST_TEST(this->lastError.getCode() == ValidationError::CANNOT_RETRIEVE_CERT);
Ashlesh Gawande3e39a4d2018-08-30 16:49:13 -0500233 // Direct fetcher sends two interests each time - to network and face
234 // 3 retries on nack or timeout (2 * (1 + 3) = 4)
Davide Pesavento2acce252022-09-08 22:03:03 -0400235 BOOST_TEST(this->face.sentInterests.size() == 8);
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800236
237 // odd interests
238 for (const auto& sentInterest : this->face.sentInterests | boost::adaptors::strided(2)) {
239 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() != nullptr);
240 }
241
242 // even interests
243 for (const auto& sentInterest : this->face.sentInterests |
244 boost::adaptors::sliced(1, this->face.sentInterests.size()) |
245 boost::adaptors::strided(2)) {
246 BOOST_CHECK(sentInterest.template getTag<lp::NextHopFaceIdTag>() == nullptr);
247 }
248}
249
250BOOST_AUTO_TEST_SUITE_END() // TestCertificateFetcherDirectFetch
Alexander Afanasyevba2cf392017-01-13 19:05:23 -0800251BOOST_AUTO_TEST_SUITE_END() // Security
252
Davide Pesavento47ce2ee2023-05-09 01:33:33 -0400253} // namespace ndn::tests