|
| 1 | +%% This Source Code Form is subject to the terms of the Mozilla Public |
| 2 | +%% License, v. 2.0. If a copy of the MPL was not distributed with this |
| 3 | +%% file, You can obtain one at https://mozilla.org/MPL/2.0/. |
| 4 | +%% |
| 5 | +%% Copyright (c) 2007-2026 Broadcom. All Rights Reserved. The term "Broadcom" refers to Broadcom Inc. and/or its subsidiaries. All rights reserved. |
| 6 | +%% |
| 7 | + |
| 8 | +-module(tls_options_SUITE). |
| 9 | + |
| 10 | +-compile([export_all, nowarn_export_all]). |
| 11 | + |
| 12 | +-include_lib("proper/include/proper.hrl"). |
| 13 | +-include_lib("common_test/include/ct.hrl"). |
| 14 | +-include_lib("eunit/include/eunit.hrl"). |
| 15 | + |
| 16 | +all() -> |
| 17 | + [{group, unit}, |
| 18 | + {group, prop}]. |
| 19 | + |
| 20 | +groups() -> |
| 21 | + [{unit, [parallel], |
| 22 | + [fail_if_no_peer_cert_defaults_to_true, |
| 23 | + fail_if_no_peer_cert_false_is_respected, |
| 24 | + fail_if_no_peer_cert_true_is_respected, |
| 25 | + verify_always_set_to_verify_peer, |
| 26 | + verify_fun_always_set, |
| 27 | + verify_fun_overrides_user_value, |
| 28 | + partial_chain_always_set, |
| 29 | + cacerts_added_when_missing, |
| 30 | + cacerts_not_added_when_present, |
| 31 | + cacertfile_prevents_cacerts_default, |
| 32 | + both_cacerts_and_cacertfile_preserved, |
| 33 | + user_options_are_preserved]}, |
| 34 | + {prop, [parallel], |
| 35 | + [prop_verify_always_verify_peer, |
| 36 | + prop_fail_if_no_peer_cert_default, |
| 37 | + prop_fail_if_no_peer_cert_respected, |
| 38 | + prop_cacerts_default_when_no_ca_opts, |
| 39 | + prop_user_options_preserved]}]. |
| 40 | + |
| 41 | +suite() -> |
| 42 | + [{timetrap, {seconds, 60}}]. |
| 43 | + |
| 44 | +init_per_suite(Config) -> |
| 45 | + Config. |
| 46 | + |
| 47 | +end_per_suite(_Config) -> |
| 48 | + ok. |
| 49 | + |
| 50 | +init_per_group(_GroupName, Config) -> |
| 51 | + Config. |
| 52 | + |
| 53 | +end_per_group(_GroupName, Config) -> |
| 54 | + Config. |
| 55 | + |
| 56 | +init_per_testcase(_Case, Config) -> |
| 57 | + Config. |
| 58 | + |
| 59 | +end_per_testcase(_Case, _Config) -> |
| 60 | + ok. |
| 61 | + |
| 62 | +%% ------------------------------------------------------------------- |
| 63 | +%% Unit tests |
| 64 | +%% ------------------------------------------------------------------- |
| 65 | + |
| 66 | +fail_if_no_peer_cert_defaults_to_true(_Config) -> |
| 67 | + Opts = merge([]), |
| 68 | + true = opt(fail_if_no_peer_cert, Opts). |
| 69 | + |
| 70 | +fail_if_no_peer_cert_false_is_respected(_Config) -> |
| 71 | + Opts = merge([{fail_if_no_peer_cert, false}]), |
| 72 | + false = opt(fail_if_no_peer_cert, Opts). |
| 73 | + |
| 74 | +fail_if_no_peer_cert_true_is_respected(_Config) -> |
| 75 | + Opts = merge([{fail_if_no_peer_cert, true}]), |
| 76 | + true = opt(fail_if_no_peer_cert, Opts). |
| 77 | + |
| 78 | +verify_always_set_to_verify_peer(_Config) -> |
| 79 | + verify_peer = opt(verify, merge([])), |
| 80 | + verify_peer = opt(verify, merge([{verify, verify_none}])), |
| 81 | + verify_peer = opt(verify, merge([{verify, verify_peer}])). |
| 82 | + |
| 83 | +verify_fun_always_set(_Config) -> |
| 84 | + Opts = merge([]), |
| 85 | + {Fun, continue} = opt(verify_fun, Opts), |
| 86 | + true = is_function(Fun, 3). |
| 87 | + |
| 88 | +verify_fun_overrides_user_value(_Config) -> |
| 89 | + UserFun = fun(_Cert, _Event, State) -> {valid, State} end, |
| 90 | + Opts = merge([{verify_fun, {UserFun, some_state}}]), |
| 91 | + {Fun, continue} = opt(verify_fun, Opts), |
| 92 | + true = (Fun =/= UserFun). |
| 93 | + |
| 94 | +partial_chain_always_set(_Config) -> |
| 95 | + Opts = merge([]), |
| 96 | + Fun = opt(partial_chain, Opts), |
| 97 | + true = is_function(Fun, 1). |
| 98 | + |
| 99 | +cacerts_added_when_missing(_Config) -> |
| 100 | + Opts = merge([]), |
| 101 | + [] = opt(cacerts, Opts). |
| 102 | + |
| 103 | +cacerts_not_added_when_present(_Config) -> |
| 104 | + MyCaCerts = [<<1, 2, 3>>], |
| 105 | + Opts = merge([{cacerts, MyCaCerts}]), |
| 106 | + MyCaCerts = opt(cacerts, Opts). |
| 107 | + |
| 108 | +cacertfile_prevents_cacerts_default(_Config) -> |
| 109 | + Opts = merge([{cacertfile, "/path/to/ca.pem"}]), |
| 110 | + "/path/to/ca.pem" = opt(cacertfile, Opts), |
| 111 | + undefined = opt(cacerts, Opts). |
| 112 | + |
| 113 | +both_cacerts_and_cacertfile_preserved(_Config) -> |
| 114 | + MyCaCerts = [<<1, 2, 3>>], |
| 115 | + Opts = merge([{cacerts, MyCaCerts}, {cacertfile, "/path/to/ca.pem"}]), |
| 116 | + MyCaCerts = opt(cacerts, Opts), |
| 117 | + "/path/to/ca.pem" = opt(cacertfile, Opts). |
| 118 | + |
| 119 | +user_options_are_preserved(_Config) -> |
| 120 | + Input = [{certfile, "/path/to/cert.pem"}, |
| 121 | + {keyfile, "/path/to/key.pem"}, |
| 122 | + {versions, ['tlsv1.2', 'tlsv1.3']}], |
| 123 | + Opts = merge(Input), |
| 124 | + "/path/to/cert.pem" = opt(certfile, Opts), |
| 125 | + "/path/to/key.pem" = opt(keyfile, Opts), |
| 126 | + ['tlsv1.2', 'tlsv1.3'] = opt(versions, Opts). |
| 127 | + |
| 128 | +%% ------------------------------------------------------------------- |
| 129 | +%% Property-based tests |
| 130 | +%% ------------------------------------------------------------------- |
| 131 | + |
| 132 | +prop_verify_always_verify_peer(_Config) -> |
| 133 | + run_proper( |
| 134 | + fun() -> |
| 135 | + ?FORALL( |
| 136 | + UserOpts, tls_options(), |
| 137 | + verify_peer =:= opt(verify, merge(UserOpts))) |
| 138 | + end). |
| 139 | + |
| 140 | +prop_fail_if_no_peer_cert_default(_Config) -> |
| 141 | + run_proper( |
| 142 | + fun() -> |
| 143 | + ?FORALL( |
| 144 | + UserOpts, tls_options_without(fail_if_no_peer_cert), |
| 145 | + true =:= opt(fail_if_no_peer_cert, merge(UserOpts))) |
| 146 | + end). |
| 147 | + |
| 148 | +prop_fail_if_no_peer_cert_respected(_Config) -> |
| 149 | + run_proper( |
| 150 | + fun() -> |
| 151 | + ?FORALL( |
| 152 | + {Val, BaseOpts}, {boolean(), tls_options_without(fail_if_no_peer_cert)}, |
| 153 | + Val =:= opt(fail_if_no_peer_cert, |
| 154 | + merge([{fail_if_no_peer_cert, Val} | BaseOpts]))) |
| 155 | + end). |
| 156 | + |
| 157 | +prop_cacerts_default_when_no_ca_opts(_Config) -> |
| 158 | + run_proper( |
| 159 | + fun() -> |
| 160 | + ?FORALL( |
| 161 | + UserOpts, tls_options_without_ca(), |
| 162 | + [] =:= opt(cacerts, merge(UserOpts))) |
| 163 | + end). |
| 164 | + |
| 165 | +prop_user_options_preserved(_Config) -> |
| 166 | + run_proper( |
| 167 | + fun() -> |
| 168 | + ?FORALL( |
| 169 | + UserOpts, tls_options(), |
| 170 | + begin |
| 171 | + Merged = merge(UserOpts), |
| 172 | + %% Every user option that is not overridden by the |
| 173 | + %% plugin must appear in the result. |
| 174 | + Overridden = [verify, verify_fun, partial_chain], |
| 175 | + lists:all( |
| 176 | + fun({K, V}) -> |
| 177 | + lists:member(K, Overridden) orelse |
| 178 | + opt(K, Merged) =:= V |
| 179 | + end, UserOpts) |
| 180 | + end) |
| 181 | + end). |
| 182 | + |
| 183 | +%% ------------------------------------------------------------------- |
| 184 | +%% Generators |
| 185 | +%% ------------------------------------------------------------------- |
| 186 | + |
| 187 | +tls_options() -> |
| 188 | + ?LET(Opts, list(tls_option()), |
| 189 | + unique_keys(Opts)). |
| 190 | + |
| 191 | +tls_options_without(Key) -> |
| 192 | + ?LET(Opts, tls_options(), |
| 193 | + lists:keydelete(Key, 1, Opts)). |
| 194 | + |
| 195 | +tls_options_without_ca() -> |
| 196 | + ?LET(Opts, tls_options(), |
| 197 | + lists:filter(fun({K, _}) -> |
| 198 | + K =/= cacerts andalso K =/= cacertfile |
| 199 | + end, Opts)). |
| 200 | + |
| 201 | +tls_option() -> |
| 202 | + oneof([ |
| 203 | + {verify, oneof([verify_peer, verify_none])}, |
| 204 | + {fail_if_no_peer_cert, boolean()}, |
| 205 | + {depth, range(0, 10)}, |
| 206 | + {certfile, binary()}, |
| 207 | + {keyfile, binary()}, |
| 208 | + {cacerts, list(binary())}, |
| 209 | + {cacertfile, binary()}, |
| 210 | + {versions, list(oneof(['tlsv1.2', 'tlsv1.3']))}, |
| 211 | + {ciphers, list(binary())} |
| 212 | + ]). |
| 213 | + |
| 214 | +unique_keys(Opts) -> |
| 215 | + lists:foldl(fun({K, _} = Opt, Acc) -> |
| 216 | + case lists:keymember(K, 1, Acc) of |
| 217 | + true -> Acc; |
| 218 | + false -> [Opt | Acc] |
| 219 | + end |
| 220 | + end, [], Opts). |
| 221 | + |
| 222 | +%% ------------------------------------------------------------------- |
| 223 | +%% Helpers |
| 224 | +%% ------------------------------------------------------------------- |
| 225 | + |
| 226 | +merge(Options) -> |
| 227 | + rabbit_trust_store_app:merge_tls_options(Options). |
| 228 | + |
| 229 | +opt(Key, Options) -> |
| 230 | + proplists:get_value(Key, Options). |
| 231 | + |
| 232 | +run_proper(Fun) -> |
| 233 | + ?assert(proper:counterexample( |
| 234 | + Fun(), |
| 235 | + [{numtests, 100}, |
| 236 | + {on_output, fun(".", _) -> ok; |
| 237 | + (F, A) -> ct:pal(?LOW_IMPORTANCE, F, A) |
| 238 | + end}])). |
0 commit comments