From e6f30e4ce133ff9e33c8d670a12ffb0ef051ddfc Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Tue, 14 Nov 2017 11:10:49 +0800 Subject: [PATCH] Add tests for post-handshake CCS in draft "22". The current PR says the sender only skips it during the handshake. Add a test that we got this right. Change-Id: Ib27eb942f11d955b8a24e32321efe474037f5254 Reviewed-on: https://boringssl-review.googlesource.com/23024 Reviewed-by: David Benjamin Reviewed-by: Steven Valdez Commit-Queue: David Benjamin CQ-Verified: CQ bot account: commit-bot@chromium.org --- ssl/test/runner/common.go | 4 ++++ ssl/test/runner/conn.go | 6 ++++++ ssl/test/runner/runner.go | 14 ++++++++++++++ 3 files changed, 24 insertions(+) diff --git a/ssl/test/runner/common.go b/ssl/test/runner/common.go index 4564b0f5f..02164017b 100644 --- a/ssl/test/runner/common.go +++ b/ssl/test/runner/common.go @@ -632,6 +632,10 @@ type ProtocolBugs struct { // ChangeCipherSpec messages. SendExtraChangeCipherSpec int + // SendPostHandshakeChangeCipherSpec causes the implementation to send + // a ChangeCipherSpec record before every application data record. + SendPostHandshakeChangeCipherSpec bool + // SendUnencryptedFinished, if true, causes the Finished message to be // send unencrypted before ChangeCipherSpec rather than after it. SendUnencryptedFinished bool diff --git a/ssl/test/runner/conn.go b/ssl/test/runner/conn.go index 535946267..c633b50bc 100644 --- a/ssl/test/runner/conn.go +++ b/ssl/test/runner/conn.go @@ -1089,6 +1089,12 @@ func (c *Conn) writeRecord(typ recordType, data []byte) (n int, err error) { return 0, err } + if typ == recordTypeApplicationData && c.config.Bugs.SendPostHandshakeChangeCipherSpec { + if _, err := c.doWriteRecord(recordTypeChangeCipherSpec, []byte{1}); err != nil { + return 0, err + } + } + return c.doWriteRecord(typ, data) } diff --git a/ssl/test/runner/runner.go b/ssl/test/runner/runner.go index 0cd1e8111..f098e8795 100644 --- a/ssl/test/runner/runner.go +++ b/ssl/test/runner/runner.go @@ -11880,6 +11880,20 @@ func addTLS13HandshakeTests() { expectedError: ":TOO_MANY_EMPTY_FRAGMENTS:", }) + testCases = append(testCases, testCase{ + name: "TLS13Draft22-SendPostHandshakeChangeCipherSpec", + config: Config{ + MaxVersion: VersionTLS13, + Bugs: ProtocolBugs{ + SendPostHandshakeChangeCipherSpec: true, + }, + }, + tls13Variant: TLS13Draft22, + shouldFail: true, + expectedError: ":UNEXPECTED_RECORD:", + expectedLocalError: "remote error: unexpected message", + }) + fooString := "foo" barString := "bar"