|
|
@@ -73,7 +73,7 @@ func (suite *ParseClientHello_TLSHeaderTestSuite) TestEmpty() {
|
|
73
|
73
|
Once().
|
|
74
|
74
|
Return(errors.New("fail"))
|
|
75
|
75
|
|
|
76
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
76
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
77
|
77
|
suite.ErrorContains(err, "fail")
|
|
78
|
78
|
}
|
|
79
|
79
|
|
|
|
@@ -84,7 +84,7 @@ func (suite *ParseClientHello_TLSHeaderTestSuite) TestNothing() {
|
|
84
|
84
|
Twice().
|
|
85
|
85
|
Return(nil)
|
|
86
|
86
|
|
|
87
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
87
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
88
|
88
|
suite.ErrorIs(err, io.EOF)
|
|
89
|
89
|
}
|
|
90
|
90
|
|
|
|
@@ -96,7 +96,7 @@ func (suite *ParseClientHello_TLSHeaderTestSuite) TestUnknownRecord() {
|
|
96
|
96
|
})
|
|
97
|
97
|
suite.readBuf.WriteByte(10)
|
|
98
|
98
|
|
|
99
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
99
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
100
|
100
|
suite.ErrorContains(err, "unexpected record type 0xa")
|
|
101
|
101
|
}
|
|
102
|
102
|
|
|
|
@@ -107,7 +107,7 @@ func (suite *ParseClientHello_TLSHeaderTestSuite) TestUnknownProtocolVersion() {
|
|
107
|
107
|
0, 0,
|
|
108
|
108
|
})
|
|
109
|
109
|
|
|
110
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
110
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
111
|
111
|
suite.ErrorContains(err, "unexpected protocol version")
|
|
112
|
112
|
}
|
|
113
|
113
|
|
|
|
@@ -118,7 +118,7 @@ func (suite *ParseClientHello_TLSHeaderTestSuite) TestCannotReadRestOfRecord() {
|
|
118
|
118
|
0, 10,
|
|
119
|
119
|
})
|
|
120
|
120
|
|
|
121
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
121
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
122
|
122
|
suite.ErrorIs(err, io.EOF)
|
|
123
|
123
|
}
|
|
124
|
124
|
|
|
|
@@ -142,7 +142,7 @@ func (suite *ParseClientHelloHandshakeTestSuite) TestCannotReadHeader() {
|
|
142
|
142
|
10,
|
|
143
|
143
|
})
|
|
144
|
144
|
|
|
145
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
145
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
146
|
146
|
suite.ErrorContains(err, "cannot read handshake header")
|
|
147
|
147
|
}
|
|
148
|
148
|
|
|
|
@@ -152,7 +152,7 @@ func (suite *ParseClientHelloHandshakeTestSuite) TestIncorrectHandshakeType() {
|
|
152
|
152
|
10, 0, 0, 0,
|
|
153
|
153
|
})
|
|
154
|
154
|
|
|
155
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
155
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
156
|
156
|
suite.ErrorContains(err, "incorrect handshake type")
|
|
157
|
157
|
}
|
|
158
|
158
|
|
|
|
@@ -162,7 +162,7 @@ func (suite *ParseClientHelloHandshakeTestSuite) TestCannotReadHandshake() {
|
|
162
|
162
|
10, 0, 0, 0,
|
|
163
|
163
|
})
|
|
164
|
164
|
|
|
165
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
165
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
166
|
166
|
suite.ErrorIs(err, io.EOF)
|
|
167
|
167
|
}
|
|
168
|
168
|
|
|
|
@@ -192,14 +192,14 @@ func (suite *ParseClientHelloHandshakeBodyTestSuite) writeBody(body []byte) {
|
|
192
|
192
|
func (suite *ParseClientHelloHandshakeBodyTestSuite) TestCannotReadVersion() {
|
|
193
|
193
|
suite.writeBody(nil)
|
|
194
|
194
|
|
|
195
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
195
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
196
|
196
|
suite.ErrorContains(err, "cannot read client version")
|
|
197
|
197
|
}
|
|
198
|
198
|
|
|
199
|
199
|
func (suite *ParseClientHelloHandshakeBodyTestSuite) TestCannotReadRandom() {
|
|
200
|
200
|
suite.writeBody([]byte{3, 3})
|
|
201
|
201
|
|
|
202
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
202
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
203
|
203
|
suite.ErrorContains(err, "cannot read client random")
|
|
204
|
204
|
}
|
|
205
|
205
|
|
|
|
@@ -208,7 +208,7 @@ func (suite *ParseClientHelloHandshakeBodyTestSuite) TestCannotReadSessionIDLeng
|
|
208
|
208
|
|
|
209
|
209
|
suite.writeBody(body)
|
|
210
|
210
|
|
|
211
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
211
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
212
|
212
|
suite.ErrorContains(err, "cannot read session ID length")
|
|
213
|
213
|
}
|
|
214
|
214
|
|
|
|
@@ -218,7 +218,7 @@ func (suite *ParseClientHelloHandshakeBodyTestSuite) TestCannotReadSessionID() {
|
|
218
|
218
|
|
|
219
|
219
|
suite.writeBody(body)
|
|
220
|
220
|
|
|
221
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
221
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
222
|
222
|
suite.ErrorContains(err, "cannot read session id")
|
|
223
|
223
|
}
|
|
224
|
224
|
|
|
|
@@ -227,7 +227,7 @@ func (suite *ParseClientHelloHandshakeBodyTestSuite) TestCannotReadCipherSuiteLe
|
|
227
|
227
|
|
|
228
|
228
|
suite.writeBody(body)
|
|
229
|
229
|
|
|
230
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
230
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
231
|
231
|
suite.ErrorContains(err, "cannot read cipher suite length")
|
|
232
|
232
|
}
|
|
233
|
233
|
|
|
|
@@ -236,7 +236,7 @@ func (suite *ParseClientHelloHandshakeBodyTestSuite) TestCannotReadFirstCipherSu
|
|
236
|
236
|
|
|
237
|
237
|
suite.writeBody(body)
|
|
238
|
238
|
|
|
239
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
239
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
240
|
240
|
suite.ErrorContains(err, "cannot read first cipher suite")
|
|
241
|
241
|
}
|
|
242
|
242
|
|
|
|
@@ -246,7 +246,7 @@ func (suite *ParseClientHelloHandshakeBodyTestSuite) TestCannotSkipRemainingCiph
|
|
246
|
246
|
|
|
247
|
247
|
suite.writeBody(body)
|
|
248
|
248
|
|
|
249
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
249
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
250
|
250
|
suite.ErrorContains(err, "cannot skip remaining cipher suites")
|
|
251
|
251
|
}
|
|
252
|
252
|
|
|
|
@@ -256,7 +256,7 @@ func (suite *ParseClientHelloHandshakeBodyTestSuite) TestCannotReadCompressionMe
|
|
256
|
256
|
|
|
257
|
257
|
suite.writeBody(body)
|
|
258
|
258
|
|
|
259
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
259
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
260
|
260
|
suite.ErrorContains(err, "cannot read compression methods length")
|
|
261
|
261
|
}
|
|
262
|
262
|
|
|
|
@@ -267,7 +267,7 @@ func (suite *ParseClientHelloHandshakeBodyTestSuite) TestCannotSkipCompressionMe
|
|
267
|
267
|
|
|
268
|
268
|
suite.writeBody(body)
|
|
269
|
269
|
|
|
270
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
270
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
271
|
271
|
suite.ErrorContains(err, "cannot skip compression methods")
|
|
272
|
272
|
}
|
|
273
|
273
|
|
|
|
@@ -307,70 +307,70 @@ func (suite *ParseClientHelloSNITestSuite) writeExtensions(extensions []byte) {
|
|
307
|
307
|
func (suite *ParseClientHelloSNITestSuite) TestCannotReadExtensionsLength() {
|
|
308
|
308
|
suite.writeExtensions(nil)
|
|
309
|
309
|
|
|
310
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
310
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
311
|
311
|
suite.ErrorContains(err, "cannot read length of TLS extensions")
|
|
312
|
312
|
}
|
|
313
|
313
|
|
|
314
|
314
|
func (suite *ParseClientHelloSNITestSuite) TestCannotReadExtensions() {
|
|
315
|
315
|
suite.writeExtensions([]byte{0, 10})
|
|
316
|
316
|
|
|
317
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
317
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
318
|
318
|
suite.ErrorContains(err, "cannot read extensions")
|
|
319
|
319
|
}
|
|
320
|
320
|
|
|
321
|
321
|
func (suite *ParseClientHelloSNITestSuite) TestCannotReadExtensionType() {
|
|
322
|
322
|
suite.writeExtensions([]byte{0, 1, 0xAB})
|
|
323
|
323
|
|
|
324
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
324
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
325
|
325
|
suite.ErrorContains(err, "cannot read extension type")
|
|
326
|
326
|
}
|
|
327
|
327
|
|
|
328
|
328
|
func (suite *ParseClientHelloSNITestSuite) TestCannotReadExtensionLength() {
|
|
329
|
329
|
suite.writeExtensions([]byte{0, 2, 0xFF, 0xFF})
|
|
330
|
330
|
|
|
331
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
331
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
332
|
332
|
suite.ErrorContains(err, "length:")
|
|
333
|
333
|
}
|
|
334
|
334
|
|
|
335
|
335
|
func (suite *ParseClientHelloSNITestSuite) TestCannotReadExtensionData() {
|
|
336
|
336
|
suite.writeExtensions([]byte{0, 4, 0xFF, 0xFF, 0, 5})
|
|
337
|
337
|
|
|
338
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
338
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
339
|
339
|
suite.ErrorContains(err, "data: len")
|
|
340
|
340
|
}
|
|
341
|
341
|
|
|
342
|
342
|
func (suite *ParseClientHelloSNITestSuite) TestCannotReadSNIRecordLength() {
|
|
343
|
343
|
suite.writeExtensions([]byte{0, 5, 0, 0, 0, 1, 0xAB})
|
|
344
|
344
|
|
|
345
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
345
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
346
|
346
|
suite.ErrorContains(err, "cannot read the length of the SNI record")
|
|
347
|
347
|
}
|
|
348
|
348
|
|
|
349
|
349
|
func (suite *ParseClientHelloSNITestSuite) TestCannotReadSNIListType() {
|
|
350
|
350
|
suite.writeExtensions([]byte{0, 6, 0, 0, 0, 2, 0, 1})
|
|
351
|
351
|
|
|
352
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
352
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
353
|
353
|
suite.ErrorContains(err, "cannot read SNI list type")
|
|
354
|
354
|
}
|
|
355
|
355
|
|
|
356
|
356
|
func (suite *ParseClientHelloSNITestSuite) TestIncorrectSNIListType() {
|
|
357
|
357
|
suite.writeExtensions([]byte{0, 7, 0, 0, 0, 3, 0, 1, 5})
|
|
358
|
358
|
|
|
359
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
359
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
360
|
360
|
suite.ErrorContains(err, "incorrect SNI list type")
|
|
361
|
361
|
}
|
|
362
|
362
|
|
|
363
|
363
|
func (suite *ParseClientHelloSNITestSuite) TestCannotReadHostnameLength() {
|
|
364
|
364
|
suite.writeExtensions([]byte{0, 8, 0, 0, 0, 4, 0, 2, 0, 0xAB})
|
|
365
|
365
|
|
|
366
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
366
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
367
|
367
|
suite.ErrorContains(err, "incorrect length of the hostname")
|
|
368
|
368
|
}
|
|
369
|
369
|
|
|
370
|
370
|
func (suite *ParseClientHelloSNITestSuite) TestCannotReadHostname() {
|
|
371
|
371
|
suite.writeExtensions([]byte{0, 9, 0, 0, 0, 5, 0, 3, 0, 0, 5})
|
|
372
|
372
|
|
|
373
|
|
- _, err := fake.ReadClientHello(suite.connMock, suite.secret, TolerateTime)
|
|
|
373
|
+ _, err := fake.ReadClientHello(suite.connMock, suite.secret.Key[:], suite.secret.Host, TolerateTime)
|
|
374
|
374
|
suite.ErrorContains(err, "incorrect length of SNI hostname")
|
|
375
|
375
|
}
|
|
376
|
376
|
|