2022-04-12 08:24:36 -04:00
|
|
|
package keyservice
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"errors"
|
|
|
|
"net"
|
|
|
|
"testing"
|
|
|
|
"time"
|
|
|
|
|
2022-06-29 09:26:29 -04:00
|
|
|
"github.com/edgelesssys/constellation/bootstrapper/role"
|
2022-06-15 09:58:23 -04:00
|
|
|
"github.com/edgelesssys/constellation/internal/atls"
|
2022-06-29 10:17:23 -04:00
|
|
|
"github.com/edgelesssys/constellation/internal/cloud/metadata"
|
2022-06-13 05:40:27 -04:00
|
|
|
"github.com/edgelesssys/constellation/internal/grpc/atlscredentials"
|
2022-06-28 10:51:30 -04:00
|
|
|
"github.com/edgelesssys/constellation/internal/logger"
|
2022-06-15 09:58:23 -04:00
|
|
|
"github.com/edgelesssys/constellation/internal/oid"
|
2022-06-01 04:14:36 -04:00
|
|
|
"github.com/edgelesssys/constellation/joinservice/joinproto"
|
2022-08-02 06:35:23 -04:00
|
|
|
"github.com/edgelesssys/constellation/state/keyproto"
|
2022-04-12 08:24:36 -04:00
|
|
|
"github.com/stretchr/testify/assert"
|
2022-06-30 09:24:36 -04:00
|
|
|
"go.uber.org/goleak"
|
2022-04-12 08:24:36 -04:00
|
|
|
"google.golang.org/grpc"
|
|
|
|
"google.golang.org/grpc/test/bufconn"
|
2022-06-01 04:14:36 -04:00
|
|
|
testclock "k8s.io/utils/clock/testing"
|
2022-04-12 08:24:36 -04:00
|
|
|
)
|
|
|
|
|
2022-06-30 09:24:36 -04:00
|
|
|
func TestMain(m *testing.M) {
|
2022-06-01 04:14:36 -04:00
|
|
|
goleak.VerifyTestMain(m)
|
2022-06-30 09:24:36 -04:00
|
|
|
}
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
func TestRequestKeyLoop(t *testing.T) {
|
2022-06-01 04:14:36 -04:00
|
|
|
clockstep := struct{}{}
|
|
|
|
someErr := errors.New("failed")
|
2022-06-29 10:17:23 -04:00
|
|
|
defaultInstance := metadata.InstanceMetadata{
|
2022-04-12 08:24:36 -04:00
|
|
|
Name: "test-instance",
|
|
|
|
ProviderID: "/test/provider",
|
2022-06-29 09:26:29 -04:00
|
|
|
Role: role.ControlPlane,
|
2022-05-24 04:04:42 -04:00
|
|
|
PrivateIPs: []string{"192.0.2.1"},
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
testCases := map[string]struct {
|
2022-06-01 04:14:36 -04:00
|
|
|
answers []any
|
2022-04-12 08:24:36 -04:00
|
|
|
}{
|
|
|
|
"success": {
|
2022-06-01 04:14:36 -04:00
|
|
|
answers: []any{
|
|
|
|
listAnswer{listResponse: []metadata.InstanceMetadata{defaultInstance}},
|
|
|
|
issueRejoinTicketAnswer{stateDiskKey: []byte{0x1}, measurementSecret: []byte{0x2}},
|
|
|
|
pushStateDiskKeyAnswer{},
|
2022-04-12 08:24:36 -04:00
|
|
|
},
|
|
|
|
},
|
2022-06-01 04:14:36 -04:00
|
|
|
"recover metadata list error": {
|
|
|
|
answers: []any{
|
|
|
|
listAnswer{err: someErr},
|
|
|
|
clockstep,
|
|
|
|
listAnswer{listResponse: []metadata.InstanceMetadata{defaultInstance}},
|
|
|
|
issueRejoinTicketAnswer{stateDiskKey: []byte{0x1}, measurementSecret: []byte{0x2}},
|
|
|
|
pushStateDiskKeyAnswer{},
|
|
|
|
},
|
2022-04-12 08:24:36 -04:00
|
|
|
},
|
2022-06-01 04:14:36 -04:00
|
|
|
"recover issue rejoin ticket error": {
|
|
|
|
answers: []any{
|
|
|
|
listAnswer{listResponse: []metadata.InstanceMetadata{defaultInstance}},
|
|
|
|
issueRejoinTicketAnswer{err: someErr},
|
|
|
|
clockstep,
|
|
|
|
listAnswer{listResponse: []metadata.InstanceMetadata{defaultInstance}},
|
|
|
|
issueRejoinTicketAnswer{stateDiskKey: []byte{0x1}, measurementSecret: []byte{0x2}},
|
|
|
|
pushStateDiskKeyAnswer{},
|
|
|
|
},
|
2022-04-12 08:24:36 -04:00
|
|
|
},
|
2022-06-01 04:14:36 -04:00
|
|
|
"recover push key error": {
|
|
|
|
answers: []any{
|
|
|
|
listAnswer{listResponse: []metadata.InstanceMetadata{defaultInstance}},
|
|
|
|
issueRejoinTicketAnswer{stateDiskKey: []byte{0x1}, measurementSecret: []byte{0x2}},
|
|
|
|
pushStateDiskKeyAnswer{err: someErr},
|
|
|
|
clockstep,
|
|
|
|
listAnswer{listResponse: []metadata.InstanceMetadata{defaultInstance}},
|
|
|
|
issueRejoinTicketAnswer{stateDiskKey: []byte{0x1}, measurementSecret: []byte{0x2}},
|
|
|
|
pushStateDiskKeyAnswer{},
|
2022-04-12 08:24:36 -04:00
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for name, tc := range testCases {
|
|
|
|
t.Run(name, func(t *testing.T) {
|
2022-06-01 04:14:36 -04:00
|
|
|
metadataServer := newStubMetadataServer()
|
|
|
|
joinServer := newStubJoinAPIServer()
|
|
|
|
keyServer := newStubKeyAPIServer()
|
2022-04-12 08:24:36 -04:00
|
|
|
|
2022-06-01 04:14:36 -04:00
|
|
|
listener := bufconn.Listen(1024)
|
2022-04-12 08:24:36 -04:00
|
|
|
defer listener.Close()
|
2022-06-15 09:58:23 -04:00
|
|
|
creds := atlscredentials.New(atls.NewFakeIssuer(oid.Dummy{}), nil)
|
2022-06-01 04:14:36 -04:00
|
|
|
grpcServer := grpc.NewServer(grpc.Creds(creds))
|
|
|
|
joinproto.RegisterAPIServer(grpcServer, joinServer)
|
|
|
|
keyproto.RegisterAPIServer(grpcServer, keyServer)
|
|
|
|
go grpcServer.Serve(listener)
|
|
|
|
defer grpcServer.GracefulStop()
|
2022-04-12 08:24:36 -04:00
|
|
|
|
2022-06-01 04:14:36 -04:00
|
|
|
clock := testclock.NewFakeClock(time.Now())
|
|
|
|
keyReceived := make(chan struct{}, 1)
|
2022-04-11 08:25:19 -04:00
|
|
|
keyWaiter := &KeyAPI{
|
2022-06-01 04:14:36 -04:00
|
|
|
listenAddr: "192.0.2.1:30090",
|
2022-06-28 10:51:30 -04:00
|
|
|
log: logger.NewTest(t),
|
2022-06-01 04:14:36 -04:00
|
|
|
metadata: metadataServer,
|
2022-04-12 08:24:36 -04:00
|
|
|
keyReceived: keyReceived,
|
2022-06-01 04:14:36 -04:00
|
|
|
clock: clock,
|
|
|
|
timeout: 1 * time.Second,
|
|
|
|
interval: 1 * time.Second,
|
|
|
|
}
|
|
|
|
grpcOpts := []grpc.DialOption{
|
|
|
|
grpc.WithContextDialer(func(ctx context.Context, s string) (net.Conn, error) {
|
|
|
|
return listener.DialContext(ctx)
|
|
|
|
}),
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|
|
|
|
|
2022-06-01 04:14:36 -04:00
|
|
|
// Start the request loop under tests.
|
|
|
|
done := make(chan struct{})
|
2022-04-12 08:24:36 -04:00
|
|
|
go func() {
|
2022-06-01 04:14:36 -04:00
|
|
|
defer close(done)
|
|
|
|
keyWaiter.requestKeyLoop("1234", grpcOpts...)
|
2022-04-12 08:24:36 -04:00
|
|
|
}()
|
|
|
|
|
2022-06-01 04:14:36 -04:00
|
|
|
// Play test case answers.
|
|
|
|
for _, answ := range tc.answers {
|
|
|
|
switch answ := answ.(type) {
|
|
|
|
case listAnswer:
|
|
|
|
metadataServer.listAnswerC <- answ
|
|
|
|
case issueRejoinTicketAnswer:
|
|
|
|
joinServer.issueRejoinTicketAnswerC <- answ
|
|
|
|
case pushStateDiskKeyAnswer:
|
|
|
|
keyServer.pushStateDiskKeyAnswerC <- answ
|
|
|
|
default:
|
|
|
|
clock.Step(time.Second)
|
|
|
|
}
|
|
|
|
}
|
2022-04-12 08:24:36 -04:00
|
|
|
|
2022-06-01 04:14:36 -04:00
|
|
|
// Stop the request loop.
|
|
|
|
keyReceived <- struct{}{}
|
2022-04-12 08:24:36 -04:00
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
func TestPushStateDiskKey(t *testing.T) {
|
|
|
|
testCases := map[string]struct {
|
2022-04-26 10:54:05 -04:00
|
|
|
testAPI *KeyAPI
|
|
|
|
request *keyproto.PushStateDiskKeyRequest
|
|
|
|
wantErr bool
|
2022-04-11 08:25:19 -04:00
|
|
|
}{
|
|
|
|
"success": {
|
|
|
|
testAPI: &KeyAPI{keyReceived: make(chan struct{}, 1)},
|
2022-07-26 04:58:39 -04:00
|
|
|
request: &keyproto.PushStateDiskKeyRequest{StateDiskKey: []byte("AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"), MeasurementSecret: []byte("BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB")},
|
2022-04-11 08:25:19 -04:00
|
|
|
},
|
|
|
|
"key already set": {
|
|
|
|
testAPI: &KeyAPI{
|
|
|
|
keyReceived: make(chan struct{}, 1),
|
|
|
|
key: []byte("AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"),
|
|
|
|
},
|
2022-07-26 04:58:39 -04:00
|
|
|
request: &keyproto.PushStateDiskKeyRequest{StateDiskKey: []byte("BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB"), MeasurementSecret: []byte("CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC")},
|
2022-04-26 10:54:05 -04:00
|
|
|
wantErr: true,
|
2022-04-11 08:25:19 -04:00
|
|
|
},
|
|
|
|
"incorrect size of pushed key": {
|
2022-04-26 10:54:05 -04:00
|
|
|
testAPI: &KeyAPI{keyReceived: make(chan struct{}, 1)},
|
2022-07-26 04:58:39 -04:00
|
|
|
request: &keyproto.PushStateDiskKeyRequest{StateDiskKey: []byte("AAAAAAAAAAAAAAAA"), MeasurementSecret: []byte("BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB")},
|
|
|
|
wantErr: true,
|
|
|
|
},
|
|
|
|
"incorrect size of measurement secret": {
|
|
|
|
testAPI: &KeyAPI{keyReceived: make(chan struct{}, 1)},
|
|
|
|
request: &keyproto.PushStateDiskKeyRequest{StateDiskKey: []byte("AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"), MeasurementSecret: []byte("BBBBBBBBBBBBBBBB")},
|
2022-04-26 10:54:05 -04:00
|
|
|
wantErr: true,
|
2022-04-11 08:25:19 -04:00
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for name, tc := range testCases {
|
|
|
|
t.Run(name, func(t *testing.T) {
|
|
|
|
assert := assert.New(t)
|
|
|
|
|
2022-06-28 10:51:30 -04:00
|
|
|
tc.testAPI.log = logger.NewTest(t)
|
2022-04-11 08:25:19 -04:00
|
|
|
_, err := tc.testAPI.PushStateDiskKey(context.Background(), tc.request)
|
2022-04-26 10:54:05 -04:00
|
|
|
if tc.wantErr {
|
2022-04-11 08:25:19 -04:00
|
|
|
assert.Error(err)
|
|
|
|
} else {
|
|
|
|
assert.NoError(err)
|
|
|
|
assert.Equal(tc.request.StateDiskKey, tc.testAPI.key)
|
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestResetKey(t *testing.T) {
|
2022-06-01 04:14:36 -04:00
|
|
|
api := New(logger.NewTest(t), nil, nil, time.Second, time.Millisecond)
|
2022-04-11 08:25:19 -04:00
|
|
|
|
|
|
|
api.key = []byte{0x1, 0x2, 0x3}
|
|
|
|
api.ResetKey()
|
|
|
|
assert.Nil(t, api.key)
|
|
|
|
}
|
|
|
|
|
2022-06-01 04:14:36 -04:00
|
|
|
type stubMetadataServer struct {
|
|
|
|
listAnswerC chan listAnswer
|
|
|
|
}
|
|
|
|
|
|
|
|
func newStubMetadataServer() *stubMetadataServer {
|
|
|
|
return &stubMetadataServer{
|
|
|
|
listAnswerC: make(chan listAnswer),
|
|
|
|
}
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|
|
|
|
|
2022-06-01 04:14:36 -04:00
|
|
|
func (s *stubMetadataServer) List(context.Context) ([]metadata.InstanceMetadata, error) {
|
|
|
|
answer := <-s.listAnswerC
|
|
|
|
return answer.listResponse, answer.err
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|
|
|
|
|
2022-06-01 04:14:36 -04:00
|
|
|
type listAnswer struct {
|
2022-06-29 10:17:23 -04:00
|
|
|
listResponse []metadata.InstanceMetadata
|
2022-06-01 04:14:36 -04:00
|
|
|
err error
|
|
|
|
}
|
|
|
|
|
|
|
|
type stubJoinAPIServer struct {
|
|
|
|
issueRejoinTicketAnswerC chan issueRejoinTicketAnswer
|
|
|
|
joinproto.UnimplementedAPIServer
|
|
|
|
}
|
|
|
|
|
|
|
|
func newStubJoinAPIServer() *stubJoinAPIServer {
|
|
|
|
return &stubJoinAPIServer{
|
|
|
|
issueRejoinTicketAnswerC: make(chan issueRejoinTicketAnswer),
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *stubJoinAPIServer) IssueRejoinTicket(context.Context, *joinproto.IssueRejoinTicketRequest) (*joinproto.IssueRejoinTicketResponse, error) {
|
|
|
|
answer := <-s.issueRejoinTicketAnswerC
|
|
|
|
resp := &joinproto.IssueRejoinTicketResponse{
|
|
|
|
StateDiskKey: answer.stateDiskKey,
|
|
|
|
MeasurementSecret: answer.measurementSecret,
|
|
|
|
}
|
|
|
|
return resp, answer.err
|
|
|
|
}
|
|
|
|
|
|
|
|
type issueRejoinTicketAnswer struct {
|
|
|
|
stateDiskKey []byte
|
|
|
|
measurementSecret []byte
|
|
|
|
err error
|
|
|
|
}
|
|
|
|
|
|
|
|
type stubKeyAPIServer struct {
|
|
|
|
pushStateDiskKeyAnswerC chan pushStateDiskKeyAnswer
|
|
|
|
keyproto.UnimplementedAPIServer
|
|
|
|
}
|
|
|
|
|
|
|
|
func newStubKeyAPIServer() *stubKeyAPIServer {
|
|
|
|
return &stubKeyAPIServer{
|
|
|
|
pushStateDiskKeyAnswerC: make(chan pushStateDiskKeyAnswer),
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *stubKeyAPIServer) PushStateDiskKey(context.Context, *keyproto.PushStateDiskKeyRequest) (*keyproto.PushStateDiskKeyResponse, error) {
|
|
|
|
answer := <-s.pushStateDiskKeyAnswerC
|
|
|
|
return &keyproto.PushStateDiskKeyResponse{}, answer.err
|
2022-04-11 08:25:19 -04:00
|
|
|
}
|
|
|
|
|
2022-06-01 04:14:36 -04:00
|
|
|
type pushStateDiskKeyAnswer struct {
|
|
|
|
err error
|
2022-04-11 08:25:19 -04:00
|
|
|
}
|