Chromium Code Reviews| Index: net/base/crl_filter_unittest.cc |
| diff --git a/net/base/crl_filter_unittest.cc b/net/base/crl_filter_unittest.cc |
| new file mode 100644 |
| index 0000000000000000000000000000000000000000..8b3fba1e92a02732cbee82455a26f32fa5c63739 |
| --- /dev/null |
| +++ b/net/base/crl_filter_unittest.cc |
| @@ -0,0 +1,212 @@ |
| +// Copyright (c) 2011 The Chromium Authors. All rights reserved. |
| +// Use of this source code is governed by a BSD-style license that can be |
| +// found in the LICENSE file. |
| + |
| +#include "net/base/crl_filter.h" |
| +#include "testing/gtest/include/gtest/gtest.h" |
| + |
| +// These data blocks were generated using a lot of code that is still in |
| +// development. For now, if you need to update them, you have to contact agl. |
| +static const uint8 kTestFilter[] = { |
| + 0xab, 0x00, 0x7b, 0x22, 0x56, 0x65, 0x72, 0x73, 0x69, 0x6f, 0x6e, 0x22, 0x3a, |
| + 0x30, 0x2c, 0x22, 0x43, 0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x73, 0x22, 0x3a, |
| + 0x22, 0x43, 0x52, 0x4c, 0x46, 0x69, 0x6c, 0x74, 0x65, 0x72, 0x22, 0x2c, 0x22, |
| + 0x53, 0x65, 0x71, 0x75, 0x65, 0x6e, 0x63, 0x65, 0x22, 0x3a, 0x30, 0x2c, 0x22, |
| + 0x44, 0x65, 0x6c, 0x74, 0x61, 0x46, 0x72, 0x6f, 0x6d, 0x22, 0x3a, 0x30, 0x2c, |
| + 0x22, 0x48, 0x65, 0x61, 0x64, 0x65, 0x72, 0x5a, 0x4c, 0x65, 0x6e, 0x67, 0x74, |
| + 0x68, 0x22, 0x3a, 0x32, 0x31, 0x38, 0x2c, 0x22, 0x48, 0x65, 0x61, 0x64, 0x65, |
| + 0x72, 0x4c, 0x65, 0x6e, 0x67, 0x74, 0x68, 0x22, 0x3a, 0x32, 0x35, 0x39, 0x2c, |
| + 0x22, 0x53, 0x69, 0x67, 0x6e, 0x69, 0x6e, 0x67, 0x50, 0x75, 0x62, 0x6c, 0x69, |
| + 0x63, 0x4b, 0x65, 0x79, 0x22, 0x3a, 0x22, 0x22, 0x2c, 0x22, 0x53, 0x69, 0x67, |
| + 0x6e, 0x69, 0x6e, 0x67, 0x4b, 0x65, 0x79, 0x53, 0x69, 0x67, 0x6e, 0x61, 0x74, |
| + 0x75, 0x72, 0x65, 0x22, 0x3a, 0x22, 0x22, 0x2c, 0x22, 0x50, 0x61, 0x79, 0x6c, |
| + 0x6f, 0x61, 0x64, 0x53, 0x69, 0x67, 0x6e, 0x61, 0x74, 0x75, 0x72, 0x65, 0x22, |
| + 0x3a, 0x22, 0x22, 0x7d, 0x78, 0x9c, 0x74, 0xcd, 0x4d, 0x4f, 0x83, 0x30, 0x18, |
| + 0x07, 0xf0, 0xef, 0xf2, 0x5c, 0x25, 0xbc, 0xb8, 0x82, 0x4b, 0x13, 0x0f, 0x38, |
| + 0x8d, 0x36, 0x63, 0xca, 0x98, 0x2c, 0x26, 0xc6, 0x03, 0x76, 0x0f, 0xac, 0x91, |
| + 0xb5, 0x5a, 0x9e, 0xca, 0xc8, 0xb2, 0xef, 0x2e, 0x18, 0xaf, 0x5e, 0x7f, 0xf9, |
| + 0xbf, 0x9c, 0x60, 0x8b, 0xb6, 0x53, 0x46, 0x03, 0x0f, 0x3d, 0x78, 0x34, 0x74, |
| + 0x83, 0xb5, 0xb1, 0x08, 0x3c, 0x9a, 0x85, 0xec, 0x2a, 0x8a, 0x58, 0xcc, 0x7e, |
| + 0x39, 0xad, 0x09, 0xed, 0x9f, 0xc6, 0x2c, 0x99, 0x74, 0x55, 0x1d, 0x8b, 0x4a, |
| + 0x37, 0x63, 0x96, 0x25, 0xe1, 0x7c, 0x6a, 0xbb, 0xc3, 0x9d, 0x26, 0xab, 0xb0, |
| + 0x1b, 0x29, 0xf6, 0x60, 0x51, 0x64, 0x9d, 0xd0, 0xb2, 0x75, 0x3b, 0xdc, 0x01, |
| + 0x7f, 0x3d, 0x41, 0x59, 0x64, 0xc0, 0x61, 0x4f, 0xf4, 0xc9, 0x83, 0xa0, 0xef, |
| + 0x7b, 0xbf, 0xe9, 0xa8, 0x22, 0x25, 0x7d, 0x69, 0x0e, 0xc1, 0xbd, 0x31, 0x4d, |
| + 0x8b, 0x42, 0x8f, 0x3f, 0x1a, 0x29, 0x75, 0xb4, 0x37, 0x56, 0xd1, 0xf0, 0x9f, |
| + 0xfb, 0xd2, 0xb6, 0xe0, 0x41, 0x5e, 0x59, 0xd4, 0xb4, 0xc9, 0x97, 0x62, 0xf3, |
| + 0x90, 0x5e, 0xc6, 0xc9, 0xb8, 0x4f, 0xb6, 0x2d, 0x57, 0x5f, 0xce, 0x6d, 0x03, |
| + 0xb6, 0xb8, 0xcd, 0x96, 0xb3, 0xe7, 0xf0, 0xa2, 0xfe, 0x78, 0xc9, 0xc5, 0xb1, |
| + 0x57, 0xdf, 0x03, 0xca, 0xc1, 0x3e, 0x89, 0x01, 0xd7, 0xc5, 0xfc, 0x7d, 0x5d, |
| + 0x5e, 0xc3, 0xf9, 0xed, 0xfc, 0x13, 0x00, 0x00, 0xff, 0xff, 0x8a, 0x9f, 0x55, |
| + 0x48, 0x43, 0x5d, 0x4a, 0xac, 0xae, 0xd7, 0x88, 0xc4, 0xf7, 0x6e, 0xdc, 0x7c, |
| + 0x6b, 0x74, 0xd2, 0x1a, 0x22, 0xbf, 0x5b, 0x2e, 0x9f, 0xbd, 0xee, 0x09, 0xe7, |
| + 0x87, 0x16, 0x17, 0xa2, 0x6b, 0xf1, 0x37, 0x04, 0x61, 0x83, 0xd5, 0xc4, 0x79, |
| + 0xa4, 0x35, 0xc3, 0xb1, 0x2b, 0x58, 0x9f, 0xc7, 0x0c, 0x2a, 0x7e, 0xf8, 0xd2, |
| + 0x28, 0x46, 0xb4, 0x4f, 0x99, 0xea, 0xd8, 0x3d, 0x18, 0xd2, 0x69, 0x5a, 0x64, |
| + 0x3f, 0x00, 0x00, 0x00, |
| +}; |
| + |
| +static const unsigned kTestFilterExpectedNumValues = 45; |
| +static const uint32 kTestFilterExpectedValues[kTestFilterExpectedNumValues] = { |
| + 673, 838, 1182, 1673, 1743, 2707, 3185, 4066, |
| + 6481, 6946, 8662, 8934, 10437, 11178, 13945, 14692, |
| + 15223, 15728, 19590, 19656, 20086, 21102, 22159, 23615, |
| + 27924, 28748, 29405, 29815, 33754, 34276, 34526, 34725, |
| + 35046, 35550, 38925, 39006, 39279, 39916, 41272, 41670, |
| + 41793, 44130, 44341, 44619, 45896, |
| +}; |
| + |
| +// kGIASPKI is the DER encoded SubjectPublicKeyInfo of the GIA certificate. |
| +static const uint8 kGIASPKI[] = { |
| + 0x30, 0x81, 0x9f, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, |
| + 0x01, 0x01, 0x01, 0x05, 0x00, 0x03, 0x81, 0x8d, 0x00, 0x30, 0x81, 0x89, 0x02, |
| + 0x81, 0x81, 0x00, 0xc9, 0xed, 0xb7, 0xa4, 0x8b, 0x9c, 0x57, 0xe7, 0x84, 0x3e, |
| + 0x40, 0x7d, 0x84, 0xf4, 0x8f, 0xd1, 0x71, 0x63, 0x53, 0x99, 0xe7, 0x79, 0x74, |
| + 0x14, 0xaf, 0x44, 0x99, 0x33, 0x20, 0x92, 0x8d, 0x7b, 0xe5, 0x28, 0x0c, 0xba, |
| + 0xad, 0x6c, 0x49, 0x7e, 0x83, 0x5f, 0x34, 0x59, 0x4e, 0x0a, 0x7a, 0x30, 0xcd, |
| + 0xd0, 0xd7, 0xc4, 0x57, 0x45, 0xed, 0xd5, 0xaa, 0xd6, 0x73, 0x26, 0xce, 0xad, |
| + 0x32, 0x13, 0xb8, 0xd7, 0x0f, 0x1d, 0x3b, 0xdf, 0xdd, 0xdc, 0x08, 0x36, 0xa8, |
| + 0x6f, 0x51, 0x44, 0x9b, 0xca, 0xd6, 0x20, 0x52, 0x73, 0xb7, 0x26, 0x87, 0x35, |
| + 0x6a, 0xdb, 0xa9, 0xe5, 0xd4, 0x59, 0xa5, 0x2b, 0xfc, 0x67, 0x19, 0x39, 0xfa, |
| + 0x93, 0x18, 0x18, 0x6c, 0xde, 0xdd, 0x25, 0x8a, 0x0e, 0x33, 0x14, 0x47, 0xc2, |
| + 0xef, 0x01, 0x50, 0x79, 0xe4, 0xfd, 0x69, 0xd1, 0xa7, 0xc0, 0xac, 0xe2, 0x57, |
| + 0x6f, 0x02, 0x03, 0x01, 0x00, 0x01, |
| +}; |
| + |
| +static const uint8 kDeltaTestFilter1[] = { |
| + 0xae, 0x00, 0x7b, 0x22, 0x56, 0x65, 0x72, 0x73, 0x69, 0x6f, 0x6e, 0x22, 0x3a, |
| + 0x30, 0x2c, 0x22, 0x43, 0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x73, 0x22, 0x3a, |
| + 0x22, 0x43, 0x52, 0x4c, 0x46, 0x69, 0x6c, 0x74, 0x65, 0x72, 0x22, 0x2c, 0x22, |
| + 0x44, 0x65, 0x6c, 0x74, 0x61, 0x46, 0x72, 0x6f, 0x6d, 0x22, 0x3a, 0x30, 0x2c, |
| + 0x22, 0x48, 0x65, 0x61, 0x64, 0x65, 0x72, 0x5a, 0x4c, 0x65, 0x6e, 0x67, 0x74, |
| + 0x68, 0x22, 0x3a, 0x32, 0x30, 0x32, 0x2c, 0x22, 0x48, 0x65, 0x61, 0x64, 0x65, |
| + 0x72, 0x4c, 0x65, 0x6e, 0x67, 0x74, 0x68, 0x22, 0x3a, 0x32, 0x31, 0x37, 0x2c, |
| + 0x22, 0x52, 0x61, 0x6e, 0x67, 0x65, 0x4c, 0x65, 0x6e, 0x67, 0x74, 0x68, 0x22, |
| + 0x3a, 0x30, 0x2c, 0x22, 0x53, 0x69, 0x67, 0x6e, 0x69, 0x6e, 0x67, 0x50, 0x75, |
| + 0x62, 0x6c, 0x69, 0x63, 0x4b, 0x65, 0x79, 0x22, 0x3a, 0x22, 0x22, 0x2c, 0x22, |
| + 0x53, 0x69, 0x67, 0x6e, 0x69, 0x6e, 0x67, 0x4b, 0x65, 0x79, 0x53, 0x69, 0x67, |
| + 0x6e, 0x61, 0x74, 0x75, 0x72, 0x65, 0x22, 0x3a, 0x22, 0x22, 0x2c, 0x22, 0x50, |
| + 0x61, 0x79, 0x6c, 0x6f, 0x61, 0x64, 0x53, 0x69, 0x67, 0x6e, 0x61, 0x74, 0x75, |
| + 0x72, 0x65, 0x22, 0x3a, 0x22, 0x22, 0x7d, 0x78, 0x9c, 0x24, 0xcb, 0xdf, 0x4a, |
| + 0xc3, 0x30, 0x14, 0xc7, 0xf1, 0x77, 0x39, 0xd7, 0x95, 0xe4, 0x64, 0xac, 0xd5, |
| + 0x82, 0x17, 0x5b, 0x11, 0x8c, 0xd6, 0x52, 0x1b, 0x36, 0x64, 0xe2, 0x45, 0xe8, |
| + 0xce, 0xea, 0xb0, 0x26, 0x36, 0x7f, 0xec, 0x64, 0xcc, 0x67, 0xb7, 0x9b, 0x77, |
| + 0x87, 0xcf, 0xf9, 0xfe, 0x8e, 0xa0, 0x68, 0x88, 0x64, 0x5a, 0x82, 0x9c, 0x27, |
| + 0xb0, 0x26, 0xe7, 0xf7, 0xd6, 0x5c, 0xee, 0xca, 0x86, 0x25, 0xed, 0xac, 0x9b, |
| + 0x3e, 0x38, 0xe3, 0x29, 0x66, 0xd9, 0x8d, 0xc0, 0x0b, 0x2f, 0x76, 0x81, 0xdc, |
| + 0xbf, 0x0a, 0x81, 0x78, 0xd6, 0x27, 0x7d, 0x68, 0xb4, 0xe9, 0xa6, 0x76, 0x8e, |
| + 0xe2, 0x3c, 0x8e, 0x9f, 0x77, 0x26, 0xb8, 0x3d, 0xf9, 0x49, 0x12, 0x28, 0x9a, |
| + 0xd2, 0x4b, 0xd3, 0xf6, 0x71, 0x4b, 0x5b, 0xc8, 0x5f, 0x8f, 0xb0, 0x6a, 0x4a, |
| + 0xc8, 0xe1, 0x3d, 0x84, 0xaf, 0x9c, 0xb1, 0x71, 0x1c, 0xd9, 0xaf, 0xee, 0x7a, |
| + 0xd6, 0xba, 0xfe, 0x0a, 0x21, 0x81, 0x5a, 0x3b, 0x32, 0x41, 0xd5, 0x8f, 0x52, |
| + 0xdd, 0x2f, 0xc4, 0x3c, 0x9d, 0xd2, 0x4d, 0x31, 0xeb, 0x5a, 0x5b, 0xae, 0xb3, |
| + 0x87, 0x4a, 0xf2, 0x58, 0xf9, 0x1f, 0xfe, 0xb2, 0x19, 0xae, 0xd5, 0xe1, 0x3b, |
| + 0x43, 0xa9, 0x86, 0xc1, 0x15, 0x69, 0x64, 0xcf, 0xcb, 0x7a, 0xa5, 0x3f, 0xec, |
| + 0x2d, 0x9c, 0xde, 0x4e, 0x7f, 0x01, 0x00, 0x00, 0xff, 0xff, 0xc1, 0xf9, 0x42, |
| + 0x93, 0x32, 0x3b, 0x84, 0x52, 0x5d, 0xa6, 0x01, 0x00, |
| +}; |
| + |
| +static const uint8 kDeltaTestFilter2[] = { |
| + 0xb2, 0x00, 0x7b, 0x22, 0x56, 0x65, 0x72, 0x73, 0x69, 0x6f, 0x6e, 0x22, 0x3a, |
| + 0x30, 0x2c, 0x22, 0x43, 0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x73, 0x22, 0x3a, |
| + 0x22, 0x43, 0x52, 0x4c, 0x46, 0x69, 0x6c, 0x74, 0x65, 0x72, 0x44, 0x65, 0x6c, |
| + 0x74, 0x61, 0x22, 0x2c, 0x22, 0x44, 0x65, 0x6c, 0x74, 0x61, 0x46, 0x72, 0x6f, |
| + 0x6d, 0x22, 0x3a, 0x30, 0x2c, 0x22, 0x48, 0x65, 0x61, 0x64, 0x65, 0x72, 0x5a, |
| + 0x4c, 0x65, 0x6e, 0x67, 0x74, 0x68, 0x22, 0x3a, 0x34, 0x30, 0x2c, 0x22, 0x48, |
| + 0x65, 0x61, 0x64, 0x65, 0x72, 0x4c, 0x65, 0x6e, 0x67, 0x74, 0x68, 0x22, 0x3a, |
| + 0x32, 0x31, 0x37, 0x2c, 0x22, 0x52, 0x61, 0x6e, 0x67, 0x65, 0x4c, 0x65, 0x6e, |
| + 0x67, 0x74, 0x68, 0x22, 0x3a, 0x32, 0x2c, 0x22, 0x53, 0x69, 0x67, 0x6e, 0x69, |
| + 0x6e, 0x67, 0x50, 0x75, 0x62, 0x6c, 0x69, 0x63, 0x4b, 0x65, 0x79, 0x22, 0x3a, |
| + 0x22, 0x22, 0x2c, 0x22, 0x53, 0x69, 0x67, 0x6e, 0x69, 0x6e, 0x67, 0x4b, 0x65, |
| + 0x79, 0x53, 0x69, 0x67, 0x6e, 0x61, 0x74, 0x75, 0x72, 0x65, 0x22, 0x3a, 0x22, |
| + 0x22, 0x2c, 0x22, 0x50, 0x61, 0x79, 0x6c, 0x6f, 0x61, 0x64, 0x53, 0x69, 0x67, |
| + 0x6e, 0x61, 0x74, 0x75, 0x72, 0x65, 0x22, 0x3a, 0x22, 0x22, 0x7d, 0x78, 0xf9, |
| + 0xc1, 0xf9, 0x42, 0x93, 0xaa, 0x56, 0x22, 0xda, 0x63, 0x16, 0x06, 0x40, 0x80, |
| + 0xe9, 0x31, 0x63, 0x23, 0x90, 0x28, 0x3e, 0x8f, 0x99, 0x91, 0xe4, 0x31, 0x23, |
| + 0xea, 0x78, 0x0c, 0x10, 0x00, 0x00, 0xff, 0xff, 0xb6, 0xa2, 0x42, 0x83, 0x91, |
| + 0x24, 0x49, 0x92, 0x48, 0x92, 0x24, 0x49, 0x26, 0x49, 0x92, 0x24, 0xd4, 0xb5, |
| + 0xad, 0xcf, 0x00, 0x00, |
| +}; |
| + |
| +// kRevokedCertSerialNumber is the serial number of a certificate that is |
| +// listed in the GIA CRL. |
| +static const uint8 kRevokedCertSerialNumber[] = { |
| + 0x36, 0xa0, 0x42, 0xb4, 0x00, 0x03, 0x00, 0x00, 0x27, 0x86, |
| +}; |
| + |
| +static const uint8 kDeltaResultSHA256[] = { |
| + 0x7d, 0x00, 0xea, 0x3e, 0x58, 0xb6, 0xda, 0x16, 0x6f, 0x3c, 0xae, 0xe1, 0xa3, |
| + 0x26, 0x39, 0x5b, 0x5c, 0xa5, 0x2f, 0x41, 0xde, 0xd7, 0x81, 0xd6, 0xa4, 0x4c, |
| + 0x1d, 0x4b, 0xdc, 0x57, 0x62, 0x6f, |
| +}; |
| + |
| +TEST(CRLFilterTest, Parse) { |
| + base::StringPiece s(reinterpret_cast<const char*>(kTestFilter), |
| + sizeof(kTestFilter)); |
| + scoped_refptr<net::CRLFilter> filter(net::CRLFilter::Parse(s)); |
| + ASSERT_TRUE(filter.get() != NULL); |
| + |
| + EXPECT_EQ(filter->num_entries(), kTestFilterExpectedNumValues); |
| + EXPECT_EQ(filter->max_range(), kTestFilterExpectedNumValues << 10); |
| + |
| + std::vector<uint64> values(filter->DebugValues()); |
| + ASSERT_EQ(values.size(), kTestFilterExpectedNumValues); |
| + |
| + for (unsigned i = 0; i < kTestFilterExpectedNumValues; i++) { |
| + EXPECT_EQ(kTestFilterExpectedValues[i], values[i]); |
| + } |
| +} |
| + |
| +TEST(CRLFilterTest, DeltaUpdates) { |
| + base::StringPiece s(reinterpret_cast<const char *>(kDeltaTestFilter1), |
|
Ryan Sleevi
2011/06/02 22:01:54
nit: const char * -> const char*
|
| + sizeof(kDeltaTestFilter1)); |
| + scoped_refptr<net::CRLFilter> filter(net::CRLFilter::Parse(s)); |
| + ASSERT_TRUE(filter.get() != NULL); |
| + |
| + base::StringPiece delta_bytes( |
| + reinterpret_cast<const char*>(kDeltaTestFilter2), |
| + sizeof(kDeltaTestFilter2)); |
| + scoped_refptr<net::CRLFilter> delta(filter->ApplyDelta(delta_bytes)); |
| + ASSERT_TRUE(delta.get() != NULL); |
| + |
| + ASSERT_TRUE(delta->SHA256() == |
| + std::string(reinterpret_cast<const char *>(kDeltaResultSHA256), |
|
Ryan Sleevi
2011/06/02 22:01:54
nit: const char * -> const char*
|
| + sizeof(kDeltaResultSHA256))); |
| +} |
| + |
| +TEST(CRLFilterTest, Entries) { |
| + base::StringPiece s(reinterpret_cast<const char*>(kTestFilter), |
| + sizeof(kTestFilter)); |
| + scoped_refptr<net::CRLFilter> filter(net::CRLFilter::Parse(s)); |
| + ASSERT_TRUE(filter.get() != NULL); |
| + |
| + base::StringPiece cert_spki; |
| + std::string serial_number = "1"; // not a real serial number. |
| + std::vector<base::StringPiece> crl_urls; |
| + static const char kFakeCRLURL[] = "http://example.com/crl"; |
| + crl_urls.push_back(base::StringPiece(kFakeCRLURL, sizeof(kFakeCRLURL))); |
| + base::StringPiece parent_spki; |
| + |
| + ASSERT_EQ(net::CRLFilter::UNKNOWN, |
| + filter->CheckCertificate(cert_spki, serial_number, crl_urls, |
| + parent_spki)); |
| + |
| + crl_urls.clear(); |
| + static const char kGIACRLURL[] = |
| + "http://www.gstatic.com/GoogleInternetAuthority/" |
| + "GoogleInternetAuthority.crl"; |
| + crl_urls.push_back(kGIACRLURL); |
| + |
| + parent_spki = base::StringPiece(reinterpret_cast<const char*>(kGIASPKI), |
| + sizeof(kGIASPKI)); |
| + ASSERT_EQ(net::CRLFilter::NOT_REVOKED, |
| + filter->CheckCertificate(cert_spki, serial_number, crl_urls, |
| + parent_spki)); |
| + |
| + serial_number = |
| + std::string(reinterpret_cast<const char*>(kRevokedCertSerialNumber), |
| + sizeof(kRevokedCertSerialNumber)); |
| + ASSERT_EQ(net::CRLFilter::PROBABLY_REVOKED, |
| + filter->CheckCertificate(cert_spki, serial_number, crl_urls, |
| + parent_spki)); |
| +} |