2022-04-12 08:24:36 -04:00
|
|
|
package keyservice
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"errors"
|
|
|
|
"net"
|
|
|
|
"testing"
|
|
|
|
"time"
|
|
|
|
|
2022-05-24 04:04:42 -04:00
|
|
|
"github.com/edgelesssys/constellation/coordinator/cloudprovider/cloudtypes"
|
2022-04-12 08:24:36 -04:00
|
|
|
"github.com/edgelesssys/constellation/coordinator/core"
|
|
|
|
"github.com/edgelesssys/constellation/coordinator/pubapi/pubproto"
|
|
|
|
"github.com/edgelesssys/constellation/coordinator/role"
|
2022-06-01 09:08:42 -04:00
|
|
|
"github.com/edgelesssys/constellation/internal/atls"
|
2022-04-11 08:25:19 -04:00
|
|
|
"github.com/edgelesssys/constellation/state/keyservice/keyproto"
|
2022-04-12 08:24:36 -04:00
|
|
|
"github.com/stretchr/testify/assert"
|
|
|
|
"github.com/stretchr/testify/require"
|
|
|
|
"google.golang.org/grpc"
|
|
|
|
"google.golang.org/grpc/credentials"
|
|
|
|
"google.golang.org/grpc/test/bufconn"
|
|
|
|
)
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
func TestRequestKeyLoop(t *testing.T) {
|
2022-05-24 04:04:42 -04:00
|
|
|
defaultInstance := cloudtypes.Instance{
|
2022-04-12 08:24:36 -04:00
|
|
|
Name: "test-instance",
|
|
|
|
ProviderID: "/test/provider",
|
|
|
|
Role: role.Coordinator,
|
2022-05-24 04:04:42 -04:00
|
|
|
PrivateIPs: []string{"192.0.2.1"},
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
testCases := map[string]struct {
|
|
|
|
server *stubAPIServer
|
2022-04-26 10:54:05 -04:00
|
|
|
wantCalls int
|
2022-05-24 04:04:42 -04:00
|
|
|
listResponse []cloudtypes.Instance
|
2022-04-12 08:24:36 -04:00
|
|
|
dontStartServer bool
|
|
|
|
}{
|
|
|
|
"success": {
|
|
|
|
server: &stubAPIServer{requestStateDiskKeyResp: &pubproto.RequestStateDiskKeyResponse{}},
|
2022-05-24 04:04:42 -04:00
|
|
|
listResponse: []cloudtypes.Instance{defaultInstance},
|
2022-04-12 08:24:36 -04:00
|
|
|
},
|
|
|
|
"no error if server throws an error": {
|
|
|
|
server: &stubAPIServer{
|
|
|
|
requestStateDiskKeyResp: &pubproto.RequestStateDiskKeyResponse{},
|
|
|
|
requestStateDiskKeyErr: errors.New("error"),
|
|
|
|
},
|
2022-05-24 04:04:42 -04:00
|
|
|
listResponse: []cloudtypes.Instance{defaultInstance},
|
2022-04-12 08:24:36 -04:00
|
|
|
},
|
|
|
|
"no error if the server can not be reached": {
|
|
|
|
server: &stubAPIServer{requestStateDiskKeyResp: &pubproto.RequestStateDiskKeyResponse{}},
|
2022-05-24 04:04:42 -04:00
|
|
|
listResponse: []cloudtypes.Instance{defaultInstance},
|
2022-04-12 08:24:36 -04:00
|
|
|
dontStartServer: true,
|
|
|
|
},
|
|
|
|
"no error if no endpoint is available": {
|
|
|
|
server: &stubAPIServer{requestStateDiskKeyResp: &pubproto.RequestStateDiskKeyResponse{}},
|
|
|
|
},
|
|
|
|
"works for multiple endpoints": {
|
|
|
|
server: &stubAPIServer{requestStateDiskKeyResp: &pubproto.RequestStateDiskKeyResponse{}},
|
2022-05-24 04:04:42 -04:00
|
|
|
listResponse: []cloudtypes.Instance{
|
2022-04-12 08:24:36 -04:00
|
|
|
defaultInstance,
|
|
|
|
{
|
|
|
|
Name: "test-instance-2",
|
|
|
|
ProviderID: "/test/provider",
|
|
|
|
Role: role.Coordinator,
|
2022-05-24 04:04:42 -04:00
|
|
|
PrivateIPs: []string{"192.0.2.2"},
|
2022-04-12 08:24:36 -04:00
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for name, tc := range testCases {
|
|
|
|
t.Run(name, func(t *testing.T) {
|
|
|
|
assert := assert.New(t)
|
|
|
|
require := require.New(t)
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
keyReceived := make(chan struct{}, 1)
|
2022-04-12 08:24:36 -04:00
|
|
|
listener := bufconn.Listen(1)
|
|
|
|
defer listener.Close()
|
|
|
|
|
2022-05-24 10:33:44 -04:00
|
|
|
tlsConfig, err := atls.CreateAttestationServerTLSConfig(core.NewMockIssuer(), nil)
|
2022-04-12 08:24:36 -04:00
|
|
|
require.NoError(err)
|
|
|
|
s := grpc.NewServer(grpc.Creds(credentials.NewTLS(tlsConfig)))
|
|
|
|
pubproto.RegisterAPIServer(s, tc.server)
|
|
|
|
|
|
|
|
if !tc.dontStartServer {
|
|
|
|
go func() { require.NoError(s.Serve(listener)) }()
|
|
|
|
}
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
keyWaiter := &KeyAPI{
|
2022-04-12 08:24:36 -04:00
|
|
|
metadata: stubMetadata{listResponse: tc.listResponse},
|
|
|
|
keyReceived: keyReceived,
|
|
|
|
timeout: 500 * time.Millisecond,
|
|
|
|
}
|
|
|
|
|
|
|
|
// notify the API a key was received after 1 second
|
|
|
|
go func() {
|
|
|
|
time.Sleep(1 * time.Second)
|
2022-04-11 08:25:19 -04:00
|
|
|
keyReceived <- struct{}{}
|
2022-04-12 08:24:36 -04:00
|
|
|
}()
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
err = keyWaiter.requestKeyLoop(
|
2022-04-12 08:24:36 -04:00
|
|
|
"1234",
|
|
|
|
grpc.WithContextDialer(func(ctx context.Context, s string) (net.Conn, error) {
|
|
|
|
return listener.DialContext(ctx)
|
|
|
|
}),
|
|
|
|
)
|
|
|
|
assert.NoError(err)
|
|
|
|
|
|
|
|
s.Stop()
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
func TestPushStateDiskKey(t *testing.T) {
|
|
|
|
testCases := map[string]struct {
|
2022-04-26 10:54:05 -04:00
|
|
|
testAPI *KeyAPI
|
|
|
|
request *keyproto.PushStateDiskKeyRequest
|
|
|
|
wantErr bool
|
2022-04-11 08:25:19 -04:00
|
|
|
}{
|
|
|
|
"success": {
|
|
|
|
testAPI: &KeyAPI{keyReceived: make(chan struct{}, 1)},
|
|
|
|
request: &keyproto.PushStateDiskKeyRequest{StateDiskKey: []byte("AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA")},
|
|
|
|
},
|
|
|
|
"key already set": {
|
|
|
|
testAPI: &KeyAPI{
|
|
|
|
keyReceived: make(chan struct{}, 1),
|
|
|
|
key: []byte("AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"),
|
|
|
|
},
|
2022-04-26 10:54:05 -04:00
|
|
|
request: &keyproto.PushStateDiskKeyRequest{StateDiskKey: []byte("BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB")},
|
|
|
|
wantErr: true,
|
2022-04-11 08:25:19 -04:00
|
|
|
},
|
|
|
|
"incorrect size of pushed key": {
|
2022-04-26 10:54:05 -04:00
|
|
|
testAPI: &KeyAPI{keyReceived: make(chan struct{}, 1)},
|
|
|
|
request: &keyproto.PushStateDiskKeyRequest{StateDiskKey: []byte("AAAAAAAAAAAAAAAA")},
|
|
|
|
wantErr: true,
|
2022-04-11 08:25:19 -04:00
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for name, tc := range testCases {
|
|
|
|
t.Run(name, func(t *testing.T) {
|
|
|
|
assert := assert.New(t)
|
|
|
|
|
|
|
|
_, err := tc.testAPI.PushStateDiskKey(context.Background(), tc.request)
|
2022-04-26 10:54:05 -04:00
|
|
|
if tc.wantErr {
|
2022-04-11 08:25:19 -04:00
|
|
|
assert.Error(err)
|
|
|
|
} else {
|
|
|
|
assert.NoError(err)
|
|
|
|
assert.Equal(tc.request.StateDiskKey, tc.testAPI.key)
|
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestResetKey(t *testing.T) {
|
|
|
|
api := New(nil, nil, time.Second)
|
|
|
|
|
|
|
|
api.key = []byte{0x1, 0x2, 0x3}
|
|
|
|
api.ResetKey()
|
|
|
|
assert.Nil(t, api.key)
|
|
|
|
}
|
|
|
|
|
2022-04-12 08:24:36 -04:00
|
|
|
type stubAPIServer struct {
|
|
|
|
requestStateDiskKeyResp *pubproto.RequestStateDiskKeyResponse
|
|
|
|
requestStateDiskKeyErr error
|
|
|
|
pubproto.UnimplementedAPIServer
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *stubAPIServer) GetState(ctx context.Context, in *pubproto.GetStateRequest) (*pubproto.GetStateResponse, error) {
|
|
|
|
return nil, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *stubAPIServer) ActivateAsCoordinator(in *pubproto.ActivateAsCoordinatorRequest, srv pubproto.API_ActivateAsCoordinatorServer) error {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2022-04-20 11:06:47 -04:00
|
|
|
func (s *stubAPIServer) ActivateAsNode(pubproto.API_ActivateAsNodeServer) error {
|
|
|
|
return nil
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
func (s *stubAPIServer) ActivateAdditionalNodes(in *pubproto.ActivateAdditionalNodesRequest, srv pubproto.API_ActivateAdditionalNodesServer) error {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *stubAPIServer) JoinCluster(ctx context.Context, in *pubproto.JoinClusterRequest) (*pubproto.JoinClusterResponse, error) {
|
|
|
|
return nil, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *stubAPIServer) TriggerNodeUpdate(ctx context.Context, in *pubproto.TriggerNodeUpdateRequest) (*pubproto.TriggerNodeUpdateResponse, error) {
|
|
|
|
return nil, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *stubAPIServer) RequestStateDiskKey(ctx context.Context, in *pubproto.RequestStateDiskKeyRequest) (*pubproto.RequestStateDiskKeyResponse, error) {
|
|
|
|
return s.requestStateDiskKeyResp, s.requestStateDiskKeyErr
|
|
|
|
}
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
type stubMetadata struct {
|
2022-05-24 04:04:42 -04:00
|
|
|
listResponse []cloudtypes.Instance
|
2022-04-11 08:25:19 -04:00
|
|
|
}
|
|
|
|
|
2022-05-24 04:04:42 -04:00
|
|
|
func (s stubMetadata) List(ctx context.Context) ([]cloudtypes.Instance, error) {
|
2022-04-11 08:25:19 -04:00
|
|
|
return s.listResponse, nil
|
|
|
|
}
|
|
|
|
|
2022-05-24 04:04:42 -04:00
|
|
|
func (s stubMetadata) Self(ctx context.Context) (cloudtypes.Instance, error) {
|
|
|
|
return cloudtypes.Instance{}, nil
|
2022-04-11 08:25:19 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
func (s stubMetadata) SignalRole(ctx context.Context, role role.Role) error {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s stubMetadata) SetVPNIP(ctx context.Context, vpnIP string) error {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s stubMetadata) Supported() bool {
|
|
|
|
return true
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|