[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <20220923201319.493208-36-dima@arista.com>
Date: Fri, 23 Sep 2022 21:13:19 +0100
From: Dmitry Safonov <dima@...sta.com>
To: linux-kernel@...r.kernel.org, David Ahern <dsahern@...nel.org>,
Eric Dumazet <edumazet@...gle.com>
Cc: Dmitry Safonov <dima@...sta.com>,
Andy Lutomirski <luto@...capital.net>,
Ard Biesheuvel <ardb@...nel.org>,
Bob Gilligan <gilligan@...sta.com>,
Dan Carpenter <dan.carpenter@...cle.com>,
"David S. Miller" <davem@...emloft.net>,
Dmitry Safonov <0x7f454c46@...il.com>,
Eric Biggers <ebiggers@...nel.org>,
"Eric W. Biederman" <ebiederm@...ssion.com>,
Francesco Ruggeri <fruggeri@...sta.com>,
Herbert Xu <herbert@...dor.apana.org.au>,
Hideaki YOSHIFUJI <yoshfuji@...ux-ipv6.org>,
Ivan Delalande <colona@...sta.com>,
Jakub Kicinski <kuba@...nel.org>,
Leonard Crestez <cdleonard@...il.com>,
Paolo Abeni <pabeni@...hat.com>,
Salam Noureddine <noureddine@...sta.com>,
Shuah Khan <shuah@...nel.org>, netdev@...r.kernel.org,
linux-crypto@...r.kernel.org
Subject: [PATCH v2 35/35] selftests/fcnal-test.sh: Add TCP-AO tests
These are basic TCP-AO functionality tests, more detailed coverage with
functional testing is done by selftests/net/tcp_ao library and binaries.
Sample output:
> TEST: Global server - ns-A IP [ OK ]
> TEST: Global server - ns-A loopback IP [ OK ]
> TEST: Device server - ns-A IP [ OK ]
> TEST: No server - ns-A IP [ OK ]
> TEST: No server - ns-A loopback IP [ OK ]
> TEST: Client - ns-B IP [ OK ]
> TEST: Client, device bind - ns-B IP [ OK ]
> TEST: No server, unbound client - ns-B IP [ OK ]
> TEST: No server, device client - ns-B IP [ OK ]
> TEST: Client - ns-B loopback IP [ OK ]
> TEST: Client, device bind - ns-B loopback IP [ OK ]
> TEST: No server, unbound client - ns-B loopback IP [ OK ]
> TEST: No server, device client - ns-B loopback IP [ OK ]
> TEST: Global server, local connection - ns-A IP [ OK ]
> TEST: Global server, local connection - ns-A loopback IP [ OK ]
> TEST: Global server, local connection - loopback [ OK ]
> TEST: Device server, unbound client, local connection - ns-A IP [ OK ]
> TEST: Device server, unbound client, local connection - ns-A loopback IP [ OK ]
> TEST: Device server, unbound client, local connection - loopback [ OK ]
> TEST: Global server, device client, local connection - ns-A IP [ OK ]
> TEST: Global server, device client, local connection - ns-A loopback IP [ OK ]
> TEST: Global server, device client, local connection - loopback [ OK ]
> TEST: Device server, device client, local connection - ns-A IP [ OK ]
> TEST: No server, device client, local conn - ns-A IP [ OK ]
> TEST: MD5: Single address config [ OK ]
> TEST: MD5: Server no config, client uses password [ OK ]
> TEST: MD5: Client uses wrong password [ OK ]
> TEST: MD5: Client address does not match address configured with password [ OK ]
> TEST: MD5: Prefix config [ OK ]
> TEST: MD5: Prefix config, client uses wrong password [ OK ]
> TEST: MD5: Prefix config, client address not in configured prefix [ OK ]
> TEST: TCP-AO [hmac(sha1):12]: Single address config [ OK ]
> TEST: TCP-AO [hmac(sha1):12]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [hmac(sha1):12]: Client uses wrong password [ OK ]
> TEST: TCP-AO [cmac(aes128):12]: Single address config [ OK ]
> TEST: TCP-AO [cmac(aes128):12]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [cmac(aes128):12]: Client uses wrong password [ OK ]
> TEST: TCP-AO [hmac(rmd160):12]: Single address config [ OK ]
> TEST: TCP-AO [hmac(rmd160):12]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [hmac(rmd160):12]: Client uses wrong password [ OK ]
> TEST: TCP-AO [hmac(sha512):12]: Single address config [ OK ]
> TEST: TCP-AO [hmac(sha512):12]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [hmac(sha512):12]: Client uses wrong password [ OK ]
> TEST: TCP-AO [hmac(sha384):12]: Single address config [ OK ]
> TEST: TCP-AO [hmac(sha384):12]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [hmac(sha384):12]: Client uses wrong password [ OK ]
> TEST: TCP-AO [hmac(sha256):12]: Single address config [ OK ]
> TEST: TCP-AO [hmac(sha256):12]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [hmac(sha256):12]: Client uses wrong password [ OK ]
> TEST: TCP-AO [hmac(md5):12]: Single address config [ OK ]
> TEST: TCP-AO [hmac(md5):12]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [hmac(md5):12]: Client uses wrong password [ OK ]
> TEST: TCP-AO [hmac(sha224):12]: Single address config [ OK ]
> TEST: TCP-AO [hmac(sha224):12]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [hmac(sha224):12]: Client uses wrong password [ OK ]
> TEST: TCP-AO [hmac(sha3-512):12]: Single address config [ OK ]
> TEST: TCP-AO [hmac(sha3-512):12]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [hmac(sha3-512):12]: Client uses wrong password [ OK ]
> TEST: TCP-AO: Client address does not match address configured with password [ OK ]
> TEST: TCP-AO: Prefix config [ OK ]
> TEST: TCP-AO: Prefix config, client uses wrong password [ OK ]
> TEST: TCP-AO: Prefix config, client address not in configured prefix [ OK ]
> TEST: TCP-AO: Different key ids [ OK ]
> TEST: TCP-AO: Wrong keyid [ OK ]
> TEST: TCP-AO [cmac(aes128):16]: Single address config [ OK ]
> TEST: TCP-AO [cmac(aes128):16]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [cmac(aes128):16]: Client uses wrong password [ OK ]
> TEST: TCP-AO [hmac(sha1):16]: Single address config [ OK ]
> TEST: TCP-AO [hmac(sha1):16]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [hmac(sha1):16]: Client uses wrong password [ OK ]
> TEST: TCP-AO [cmac(aes128):4]: Single address config [ OK ]
> TEST: TCP-AO [cmac(aes128):4]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [cmac(aes128):4]: Client uses wrong password [ OK ]
> TEST: TCP-AO [hmac(sha1):4]: Single address config [ OK ]
> TEST: TCP-AO [hmac(sha1):4]: Server no config, client uses password [ OK ]
> TEST: TCP-AO [hmac(sha1):4]: Client uses wrong password [ OK ]
> TEST: TCP-AO: add MD5 and TCP-AO for the same peer address [ OK ]
> TEST: TCP-AO: MD5 and TCP-AO on connect() [ OK ]
> TEST: TCP-AO: Exclude TCP options [ OK ]
Signed-off-by: Dmitry Safonov <dima@...sta.com>
---
tools/testing/selftests/net/fcnal-test.sh | 239 ++++++++++++++++++++++
1 file changed, 239 insertions(+)
diff --git a/tools/testing/selftests/net/fcnal-test.sh b/tools/testing/selftests/net/fcnal-test.sh
index 321cbb0b55c4..fdd762408dc2 100755
--- a/tools/testing/selftests/net/fcnal-test.sh
+++ b/tools/testing/selftests/net/fcnal-test.sh
@@ -76,6 +76,12 @@ BCAST_IP=255.255.255.255
MD5_PW=abc123
MD5_WRONG_PW=abc1234
+AO_PW=abc123
+AO_WRONG_PW=abc1234
+AO_HASH_ALGOS="hmac(sha1) cmac(aes128)"
+AO_HASH_ALGOS+=" hmac(rmd160) hmac(sha512)"
+AO_HASH_ALGOS+=" hmac(sha384) hmac(sha256) hmac(md5)"
+AO_HASH_ALGOS+=" hmac(sha224) hmac(sha3-512)"
MCAST=ff02::1
# set after namespace create
@@ -900,6 +906,123 @@ ipv4_tcp_md5_novrf()
log_test $? 2 "MD5: Prefix config, client address not in configured prefix"
}
+#
+# TCP-AO tests without VRF
+#
+ipv4_tcp_ao_algos()
+{
+ # basic use case
+ log_start
+ run_cmd nettest -s -T 100:100 --tcpao_algo=$1 --tcpao_maclen=$2 \
+ -X ${AO_PW} -m ${NSB_IP} &
+ sleep 1
+ run_cmd_nsb nettest -r ${NSA_IP} -T 100:100 --tcpao_algo=$1 \
+ --tcpao_maclen=$2 -X ${AO_PW}
+ log_test $? 0 "TCP-AO [$1:$2]: Single address config"
+
+ # client sends TCP-AO, server not configured
+ log_start
+ show_hint "Should timeout due to TCP-AO password mismatch"
+ run_cmd nettest -s &
+ sleep 1
+ run_cmd_nsb nettest -r ${NSA_IP} -T 100:100 --tcpao_algo=$1 \
+ --tcpao_maclen=$2 -X ${AO_PW}
+ log_test $? 2 "TCP-AO [$1:$2]: Server no config, client uses password"
+
+ # wrong password
+ log_start
+ show_hint "Should timeout since client uses wrong password"
+ run_cmd nettest -s -T 100:100 --tcpao_algo=$1 --tcpao_maclen=$2 \
+ -X ${AO_PW} -m ${NSB_IP} &
+ sleep 1
+ run_cmd_nsb nettest -r ${NSA_IP} -T 100:100 --tcpao_algo=$1 \
+ --tcpao_maclen=$2 -X ${AO_WRONG_PW}
+ log_test $? 2 "TCP-AO [$1:$2]: Client uses wrong password"
+}
+
+ipv4_tcp_ao_novrf()
+{
+ #
+ # single address
+ #
+ for i in $AO_HASH_ALGOS ; do
+ ipv4_tcp_ao_algos $i 12
+ done
+
+ # client from different address
+ log_start
+ show_hint "Should timeout due to TCP-AO address mismatch"
+ run_cmd nettest -s -T 100:100 -X ${AO_PW} -m ${NSB_LO_IP} &
+ sleep 1
+ run_cmd_nsb nettest -r ${NSA_IP} -T 100:100 -X ${AO_PW}
+ log_test $? 2 "TCP-AO: Client address does not match address configured with password"
+
+ # client in prefix
+ log_start
+ run_cmd nettest -s -T 100:100 -X ${AO_PW} -m ${NS_NET} &
+ sleep 1
+ run_cmd_nsb nettest -r ${NSA_IP} -T 100:100 -X ${AO_PW}
+ log_test $? 0 "TCP-AO: Prefix config"
+
+ # client in prefix, wrong password
+ log_start
+ show_hint "Should timeout since client uses wrong password"
+ run_cmd nettest -s -T 100:100 -X ${AO_PW} -m ${NS_NET} &
+ sleep 1
+ run_cmd_nsb nettest -r ${NSA_IP} -T 100:100 -X ${AO_WRONG_PW}
+ log_test $? 2 "TCP-AO: Prefix config, client uses wrong password"
+
+ # client outside of prefix
+ log_start
+ show_hint "Should timeout due to address out of TCP-AO prefix mismatch"
+ run_cmd nettest -s -T 100:100 -X ${AO_PW} -m ${NS_NET} &
+ sleep 1
+ run_cmd_nsb nettest -c ${NSB_LO_IP} -r ${NSA_IP} -T 100:100 -X ${AO_PW}
+ log_test $? 2 "TCP-AO: Prefix config, client address not in configured prefix"
+
+ # TCP-AO more specific tests
+ # sendid != rcvid
+ log_start
+ run_cmd nettest -s -T 100:101 -X ${AO_PW} -m ${NSB_IP} &
+ sleep 1
+ run_cmd_nsb nettest -r ${NSA_IP} -T 101:100 -X ${AO_PW}
+ log_test $? 0 "TCP-AO: Different key ids"
+
+ # Wrong keyid
+ log_start
+ show_hint "Should timeout due to a wrong keyid"
+ run_cmd nettest -s -T 100:100 -X ${AO_PW} -m ${NSB_IP} &
+ sleep 1
+ run_cmd_nsb nettest -r ${NSA_IP} -T 101:101 -X ${AO_PW}
+ log_test $? 2 "TCP-AO: Wrong keyid"
+
+ # Variable maclen
+ ipv4_tcp_ao_algos "cmac(aes128)" 16
+ ipv4_tcp_ao_algos "hmac(sha1)" 16
+ ipv4_tcp_ao_algos "cmac(aes128)" 4
+ ipv4_tcp_ao_algos "hmac(sha1)" 4
+
+ # MD5 and TCP-AO for the same peer
+ log_start
+ run_cmd nettest -s -T 100:100 -M -X ${AO_PW} -m ${NSB_IP}
+ log_test $? 1 "TCP-AO: add MD5 and TCP-AO for the same peer address"
+
+ # Connect with both TCP-AO and MD5 on the socket
+ log_start
+ show_hint "Should fail to connect with both MD5 and TCP-AO on the socket"
+ run_cmd nettest -s -T 100:100 -M -X ${AO_PW} -m ${NSB_IP} &
+ sleep 1
+ run_cmd_nsb nettest -r ${NSA_IP} -T 100:100 -M -X ${AO_PW}
+ log_test $? 1 "TCP-AO: MD5 and TCP-AO on connect()"
+
+ # Exclude TCP options
+ log_start
+ run_cmd nettest -s -T 100:101 -X ${AO_PW} -m ${NSB_IP} --tcpao_excopts &
+ sleep 1
+ run_cmd_nsb nettest -r ${NSA_IP} -T 101:100 -X ${AO_PW} --tcpao_excopts
+ log_test $? 0 "TCP-AO: Exclude TCP options"
+}
+
#
# MD5 tests with VRF
#
@@ -1217,6 +1340,7 @@ ipv4_tcp_novrf()
log_test_addr ${a} $? 1 "No server, device client, local conn"
ipv4_tcp_md5_novrf
+ ipv4_tcp_ao_novrf
}
ipv4_tcp_vrf()
@@ -2488,6 +2612,120 @@ ipv6_tcp_md5_novrf()
log_test $? 2 "MD5: Prefix config, client address not in configured prefix"
}
+ipv6_tcp_ao_algos()
+{
+ # basic use case
+ log_start
+ run_cmd nettest -6 -s -T 100:100 --tcpao_algo=$1 --tcpao_maclen=$2 \
+ -X ${AO_PW} -m ${NSB_IP6} &
+ sleep 1
+ run_cmd_nsb nettest -6 -r ${NSA_IP6} -T 100:100 --tcpao_algo=$1 \
+ --tcpao_maclen=$2 -X ${AO_PW}
+ log_test $? 0 "TCP-AO [$1:$2]: Single address config"
+
+ # client sends TCP-AO, server not configured
+ log_start
+ show_hint "Should timeout since server does not have TCP-AO auth"
+ run_cmd nettest -6 -s &
+ sleep 1
+ run_cmd_nsb nettest -6 -r ${NSA_IP6} -T 100:100 --tcpao_algo=$1 \
+ --tcpao_maclen=$2 -X ${AO_PW}
+ log_test $? 2 "TCP-AO [$1:$2]: Server no config, client uses password"
+
+ # wrong password
+ log_start
+ show_hint "Should timeout since client uses wrong password"
+ run_cmd nettest -6 -s -T 100:100 --tcpao_algo=$1 --tcpao_maclen=$2 \
+ -X ${AO_PW} -m ${NSB_IP6} &
+ sleep 1
+ run_cmd_nsb nettest -6 -r ${NSA_IP6} -T 100:100 --tcpao_algo=$1 \
+ --tcpao_maclen=$2 -X ${AO_WRONG_PW}
+ log_test $? 2 "TCP-AO [$1:$2]: Client uses wrong password"
+}
+
+ipv6_tcp_ao_novrf()
+{
+ #
+ # single address
+ #
+ for i in $AO_HASH_ALGOS ; do
+ ipv6_tcp_ao_algos $i 12
+ done
+
+ # client from different address
+ log_start
+ show_hint "Should timeout since server config differs from client"
+ run_cmd nettest -6 -s -T 100:100 -X ${AO_PW} -m ${NSB_LO_IP6} &
+ sleep 1
+ run_cmd_nsb nettest -6 -r ${NSA_IP6} -T 100:100 -X ${AO_PW}
+ log_test $? 2 "TCP-AO: Client address does not match address configured with password"
+
+ # client in prefix
+ log_start
+ run_cmd nettest -6 -s -T 100:100 -X ${AO_PW} -m ${NS_NET6} &
+ sleep 1
+ run_cmd_nsb nettest -6 -r ${NSA_IP6} -T 100:100 -X ${AO_PW}
+ log_test $? 0 "TCP-AO: Prefix config"
+
+ # client in prefix, wrong password
+ log_start
+ show_hint "Should timeout since client uses wrong password"
+ run_cmd nettest -6 -s -T 100:100 -X ${AO_PW} -m ${NS_NET6} &
+ sleep 1
+ run_cmd_nsb nettest -6 -r ${NSA_IP6} -T 100:100 -X ${AO_WRONG_PW}
+ log_test $? 2 "TCP-AO: Prefix config, client uses wrong password"
+
+ # client outside of prefix
+ log_start
+ show_hint "Should timeout since client address is outside of prefix"
+ run_cmd nettest -6 -s -T 100:100 -X ${AO_PW} -m ${NS_NET6} &
+ sleep 1
+ run_cmd_nsb nettest -6 -c ${NSB_LO_IP6} -r ${NSA_IP6} -T 100:100 -X ${AO_PW}
+ log_test $? 2 "TCP-AO: Prefix config, client address not in configured prefix"
+
+ # TCP-AO more specific tests
+ # sendid != rcvid
+ log_start
+ run_cmd nettest -6 -s -T 100:101 -X ${AO_PW} -m ${NSB_IP6} &
+ sleep 1
+ run_cmd_nsb nettest -6 -r ${NSA_IP6} -T 101:100 -X ${AO_PW}
+ log_test $? 0 "TCP-AO: Different key ids"
+
+ # Wrong keyid
+ log_start
+ show_hint "Should timeout due to a wrong keyid"
+ run_cmd nettest -6 -s -T 100:100 -X ${AO_PW} -m ${NSB_IP6} &
+ sleep 1
+ run_cmd_nsb nettest -6 -r ${NSA_IP6} -T 101:101 -X ${AO_PW}
+ log_test $? 2 "TCP-AO: Wrong keyid"
+
+ # Variable maclen
+ ipv6_tcp_ao_algos "cmac(aes128)" 16
+ ipv6_tcp_ao_algos "hmac(sha1)" 16
+ ipv6_tcp_ao_algos "cmac(aes128)" 4
+ ipv6_tcp_ao_algos "hmac(sha1)" 4
+
+ # MD5 and TCP-AO for the same peer
+ log_start
+ run_cmd nettest -6 -s -T 100:100 -M -X ${AO_PW} -m ${NSB_IP6}
+ log_test $? 1 "TCP-AO: add MD5 and TCP-AO for the same peer address"
+
+ # Connect with both TCP-AO and MD5 on the socket
+ log_start
+ show_hint "Should fail to connect with both MD5 and TCP-AO on the socket"
+ run_cmd nettest -6 -s -T 100:100 -M -X ${AO_PW} -m ${NSB_IP6} &
+ sleep 1
+ run_cmd_nsb nettest -6 -r ${NSA_IP6} -T 100:100 -M -X ${AO_PW}
+ log_test $? 1 "TCP-AO: MD5 and TCP-AO on connect()"
+
+ # Exclude TCP options
+ log_start
+ run_cmd nettest -6 -s -T 100:101 -X ${AO_PW} -m ${NSB_IP6} --tcpao_excopts &
+ sleep 1
+ run_cmd_nsb nettest -6 -r ${NSA_IP6} -T 101:100 -X ${AO_PW} --tcpao_excopts
+ log_test $? 0 "TCP-AO: Exclude TCP options"
+}
+
#
# MD5 tests with VRF
#
@@ -2750,6 +2988,7 @@ ipv6_tcp_novrf()
done
ipv6_tcp_md5_novrf
+ ipv6_tcp_ao_novrf
}
ipv6_tcp_vrf()
--
2.37.2
Powered by blists - more mailing lists