diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index 606dbbe3..8f6ec0e9 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -67,14 +67,14 @@ jobs: env: CC: ${{ matrix.cc }} SSL: ${{ matrix.ssl }} - TFLAGS: -DMQTT_LOCALHOST -DNO_ABORT + TFLAGS: -DMQTT_HOST -DNO_ABORT # -DMQTT_HOST_NAME=\"server\" steps: - uses: actions/checkout@v4 with: { fetch-depth: 2 } - uses: webfactory/ssh-agent@v0.9.1 with: ssh-private-key: ${{ secrets.HEALTH_TESTS_SSH_KEY }} - - run: if [ "${{ matrix.target }}" == "mip_tap_test" ]; then ./test/setup_ga_network.sh ; export IPV6=0; else export IPV6=1 ; fi && sudo apt -y update ; sudo apt -y install libmbedtls-dev libwolfssl-dev && make -C test ${{ matrix.target }} > log + - run: if [ "${{ matrix.target }}" == "mip_tap_test" ]; then source ./test/setup_ga_network.sh ; export IPV6=0; sed -i -e "s/127.0.0.1/$HOST_IP/" test/mosquitto.conf; ./test/setup_mqtt_server.sh; else export IPV6=1 ; fi && sudo apt -y update ; sudo apt -y install libmbedtls-dev libwolfssl-dev && make -C test ${{ matrix.target }} > log - if: success() || failure() run: | cat log diff --git a/.github/workflows/on_demand.yml b/.github/workflows/on_demand.yml index 851855b9..cf882f58 100644 --- a/.github/workflows/on_demand.yml +++ b/.github/workflows/on_demand.yml @@ -4,29 +4,60 @@ on: env: IPV6: 0 jobs: - macos: - runs-on: macos-latest + mip: + runs-on: ubuntu-latest strategy: fail-fast: false matrix: - ssl: [MBEDTLS, WOLFSSL] - select: [-DMG_ENABLE_POLL=1] - name: macos SSL=${{ matrix.ssl }} TFLAGS=${{ matrix.select }} + cc: [gcc] + target: [mip_tap_test] + ssl: ["", BUILTIN, MBEDTLS, OPENSSL, WOLFSSL] + # #3226: built-in TCP is currently not working with WolfSSL (builds fine) + exclude: + - ssl: WOLFSSL + target: mip_tap_test + name: ${{ matrix.target }} CC=${{ matrix.cc }} SSL=${{ matrix.ssl }} env: + CC: ${{ matrix.cc }} SSL: ${{ matrix.ssl }} - TFLAGS: ${{ matrix.select }} -DMQTT_LOCALHOST -DNO_ABORT -Wno-sign-conversion -Wno-undef # Workarounds for MbedTLS - HOMEBREW_NO_AUTO_UPDATE: 1 + TFLAGS: -DMQTT_HOST -DNO_ABORT # -DMQTT_HOST_NAME=\"server\" steps: - uses: actions/checkout@v4 with: { fetch-depth: 2 } - uses: webfactory/ssh-agent@v0.9.1 with: ssh-private-key: ${{ secrets.HEALTH_TESTS_SSH_KEY }} - - run: brew install mbedtls wolfssl mosquitto gawk # jq openssl already pre-installed - - run: /opt/homebrew/opt/mosquitto/sbin/mosquitto -c /Users/runner/work/mongoose/mongoose/test/mosquitto.conf.macos & - - run: make -C test test ASAN_OPTIONS= MBEDTLS=$(echo $(brew --cellar)/mbedtls*/*) OPENSSL=$(echo $(brew --cellar)/openssl*/*) WOLFSSL=$(echo $(brew --cellar)/wolfssl*/*) > log + - run: if [ "${{ matrix.target }}" == "mip_tap_test" ]; then source ./test/setup_ga_network.sh ; export IPV6=0; sed -i -e "s/127.0.0.1/$HOST_IP/" test/mosquitto.conf; ./test/setup_mqtt_server.sh; else export IPV6=1 ; fi && sudo apt -y update ; sudo apt -y install libmbedtls-dev libwolfssl-dev && make -C test ${{ matrix.target }} > log - if: success() || failure() run: | cat log test/health.awk < log > json - scp -o "StrictHostKeyChecking=no" json "root@176.9.217.245:/data/downloads/health/macos_test_cc_${{ matrix.ssl }}_${{ matrix.select }}_$(date +"%Y%m%d").json" + scp -o "StrictHostKeyChecking=no" json "root@176.9.217.245:/data/downloads/health/${{ matrix.target }}_${{ matrix.cc }}_${{ matrix.ssl }}_$(date +"%Y%m%d").json" + + +# macos: +# runs-on: macos-latest +# strategy: +# fail-fast: false +# matrix: +# ssl: [MBEDTLS, WOLFSSL] +# select: [-DMG_ENABLE_POLL=1] +# name: macos SSL=${{ matrix.ssl }} TFLAGS=${{ matrix.select }} +# env: +# SSL: ${{ matrix.ssl }} +# TFLAGS: ${{ matrix.select }} -DMQTT_LOCALHOST -DNO_ABORT -Wno-sign-conversion -Wno-undef # Workarounds for MbedTLS +# HOMEBREW_NO_AUTO_UPDATE: 1 +# steps: +# - uses: actions/checkout@v4 +# with: { fetch-depth: 2 } +# - uses: webfactory/ssh-agent@v0.9.1 +# with: +# ssh-private-key: ${{ secrets.HEALTH_TESTS_SSH_KEY }} +# - run: brew install mbedtls wolfssl mosquitto gawk # jq openssl already pre-installed +# - run: /opt/homebrew/opt/mosquitto/sbin/mosquitto -c /Users/runner/work/mongoose/mongoose/test/mosquitto.conf.macos & +# - run: make -C test test ASAN_OPTIONS= MBEDTLS=$(echo $(brew --cellar)/mbedtls*/*) OPENSSL=$(echo $(brew --cellar)/openssl*/*) WOLFSSL=$(echo $(brew --cellar)/wolfssl*/*) > log +# - if: success() || failure() +# run: | +# cat log +# test/health.awk < log > json +# scp -o "StrictHostKeyChecking=no" json "root@176.9.217.245:/data/downloads/health/macos_test_cc_${{ matrix.ssl }}_${{ matrix.select }}_$(date +"%Y%m%d").json" diff --git a/test/Makefile b/test/Makefile index 36faa3cd..eecaeb73 100644 --- a/test/Makefile +++ b/test/Makefile @@ -87,7 +87,7 @@ mip_test: mip_test.c mongoose.c mongoose.h packed_fs.c Makefile $(CC) mip_test.c packed_fs.c $(CFLAGS) $(LDFLAGS) -o $@ ASAN_OPTIONS=$(ASAN_OPTIONS) $(RUN) ./$@ -mip_tap_test: mip_tap_test.c mongoose.c mongoose.h packed_fs.c Makefile tls_multirec/server +mip_tap_test: mip_x_test.c mip_tap_test.c mongoose.c mongoose.h packed_fs.c Makefile tls_multirec/server $(CC) mip_tap_test.c packed_fs.c $(CFLAGS) $(LDFLAGS) -o $@ ASAN_OPTIONS=$(ASAN_OPTIONS) $(RUN) ./$@ @@ -96,7 +96,7 @@ port_tap_bridge: port_tap_bridge.c cc port_tap_bridge.c -o $@ # requires port_tap_bridge to be running -mip_port_test: mip_port_test.c mongoose.c mongoose.h packed_fs.c Makefile tls_multirec/server +mip_port_test: mip_x_test.c mip_port_test.c mongoose.c mongoose.h packed_fs.c Makefile tls_multirec/server $(CC) mip_port_test.c packed_fs.c $(CFLAGS) $(LDFLAGS) -o $@ ASAN_OPTIONS=$(ASAN_OPTIONS) $(RUN) ./$@ diff --git a/test/data/e8.crt b/test/data/e8.crt deleted file mode 100644 index 3b0aaff2..00000000 --- a/test/data/e8.crt +++ /dev/null @@ -1,32 +0,0 @@ - - 1 s:C=US, O=Let's Encrypt, CN=E8 - i:C=US, O=Internet Security Research Group, CN=ISRG Root X1 - a:PKEY: id-ecPublicKey, 384 (bit); sigalg: RSA-SHA256 - v:NotBefore: Mar 13 00:00:00 2024 GMT; NotAfter: Mar 12 23:59:59 2027 GMT ------BEGIN CERTIFICATE----- -MIIEVjCCAj6gAwIBAgIQY5WTY8JOcIJxWRi/w9ftVjANBgkqhkiG9w0BAQsFADBP -MQswCQYDVQQGEwJVUzEpMCcGA1UEChMgSW50ZXJuZXQgU2VjdXJpdHkgUmVzZWFy -Y2ggR3JvdXAxFTATBgNVBAMTDElTUkcgUm9vdCBYMTAeFw0yNDAzMTMwMDAwMDBa -Fw0yNzAzMTIyMzU5NTlaMDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBF -bmNyeXB0MQswCQYDVQQDEwJFODB2MBAGByqGSM49AgEGBSuBBAAiA2IABNFl8l7c -S7QMApzSsvru6WyrOq44ofTUOTIzxULUzDMMNMchIJBwXOhiLxxxs0LXeb5GDcHb -R6EToMffgSZjO9SNHfY9gjMy9vQr5/WWOrQTZxh7az6NSNnq3u2ubT6HTKOB+DCB -9TAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMB -MBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFI8NE6L2Ln7RUGwzGDhdWY4j -cpHKMB8GA1UdIwQYMBaAFHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEB -BCYwJDAiBggrBgEFBQcwAoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzATBgNVHSAE -DDAKMAgGBmeBDAECATAnBgNVHR8EIDAeMBygGqAYhhZodHRwOi8veDEuYy5sZW5j -ci5vcmcvMA0GCSqGSIb3DQEBCwUAA4ICAQBnE0hGINKsCYWi0Xx1ygxD5qihEjZ0 -RI3tTZz1wuATH3ZwYPIp97kWEayanD1j0cDhIYzy4CkDo2jB8D5t0a6zZWzlr98d -AQFNh8uKJkIHdLShy+nUyeZxc5bNeMp1Lu0gSzE4McqfmNMvIpeiwWSYO9w82Ob8 -otvXcO2JUYi3svHIWRm3+707DUbL51XMcY2iZdlCq4Wa9nbuk3WTU4gr6LY8MzVA -aDQG2+4U3eJ6qUF10bBnR1uuVyDYs9RhrwucRVnfuDj29CMLTsplM5f5wSV5hUpm -Uwp/vV7M4w4aGunt74koX71n4EdagCsL/Yk5+mAQU0+tue0JOfAV/R6t1k+Xk9s2 -HMQFeoxppfzAVC04FdG9M+AC2JWxmFSt6BCuh3CEey3fE52Qrj9YM75rtvIjsm/1 -Hl+u//Wqxnu1ZQ4jpa+VpuZiGOlWrqSP9eogdOhCGisnyewWJwRQOqK16wiGyZeR -xs/Bekw65vwSIaVkBruPiTfMOo0Zh4gVa8/qJgMbJbyrwwG97z/PRgmLKCDl8z3d -tA0Z7qq7fta0Gl24uyuB05dqI5J1LvAzKuWdIjT1tP8qCoxSE/xpix8hX2dt3h+/ -jujUgFPFZ0EVZ0xSyBNRF3MboGZnYXFUxpNjTWPKpagDHJQmqrAcDmWJnMsFY3jS -u1igv3OefnWjSQ== ------END CERTIFICATE----- - diff --git a/test/mip_x_test.c b/test/mip_x_test.c index 6d3fd4b9..e7fd2fa7 100644 --- a/test/mip_x_test.c +++ b/test/mip_x_test.c @@ -8,8 +8,11 @@ bool mip_x_test(struct mg_mgr *); -#ifdef MQTT_LOCALHOST -#define MQTT_URL "mqtt://127.0.0.1:1883" +#ifdef MQTT_HOST +// we'll generate MQTT_URL +#ifndef MQTT_HOST_NAME +#define MQTT_HOST_NAME "localhost" +#endif #else #define MQTT_URL "mqtt://broker.hivemq.com:1883" #endif @@ -49,7 +52,7 @@ static const char *s_ca_cert = "emyPxgcYxn/eR44/KJ4EBs+lVDR3veyJm+kXQ99b21/+jh5Xos1AnX5iItreGCc=\n" "-----END CERTIFICATE-----\n"; #elif MG_TLS -#ifdef MQTT_LOCALHOST +#ifdef MQTT_HOST // we'll generate MQTTS_URL #define MQTTS_CA mg_str(s_ca_cert) static const char *s_ca_cert = @@ -64,7 +67,7 @@ static const char *s_ca_cert = #else #define MQTTS_URL "mqtts://broker.hivemq.com:8883" #define MQTTS_CA mg_unpacked("/data/ca.pem") -#endif // MQTT_LOCALHOST +#endif // MQTT_HOST #endif static char *host_ip; @@ -163,15 +166,8 @@ static void fcb(struct mg_connection *c, int ev, void *ev_data) { } else { opts.name = mg_url_host(fd->url); opts.ca = mg_unpacked("/data/ca.pem"); -#if MG_TLS == MG_TLS_BUILTIN - // our TLS does not search for the proper CA in a bundle - opts.ca = mg_file_read(&mg_fs_posix, "data/e5.crt"); -#endif } mg_tls_init(c, &opts); -#if MG_TLS == MG_TLS_BUILTIN - mg_free((void *) opts.ca.buf); -#endif } } else if (ev == MG_EV_HTTP_MSG) { struct mg_http_message *hm = (struct mg_http_message *) ev_data; @@ -263,7 +259,12 @@ static void mqtt_fn(struct mg_connection *c, int ev, void *ev_data) { struct mg_tls_opts opts; memset(&opts, 0, sizeof(opts)); opts.ca = MQTTS_CA; +#if defined(MQTT_HOST) && MG_TLS != MG_TLS_BUILTIN + opts.name = mg_str_s(MQTT_HOST_NAME); + printf("HOST_NAME: %.*s\n", (int) opts.name.len, opts.name.buf); +#else opts.name = mg_url_host(data->url); +#endif mg_tls_init(c, &opts); #endif } else if (ev == MG_EV_MQTT_OPEN) { @@ -322,26 +323,33 @@ static void test_mqtt_connsubpub(struct mg_mgr *mgr) { memset(&opts, 0, sizeof(opts)); opts.clean = true, opts.version = 4; data.passed = false; -#if defined(MQTT_LOCALHOST) && MG_TLS != MG_TLS_BUILTIN +#if defined(MQTT_HOST) && MG_TLS != MG_TLS_BUILTIN if (host_ip == NULL) { - printf("\nMQTT_LOCALHOST defined but no HOST_IP provided, skipping MQTTS tests\n"); + printf("\nMQTT_HOST defined but no HOST_IP provided, skipping MQTT tests\n"); return; } printf("HOST_IP: %s\n", host_ip); #endif #if MG_TLS -#if defined(MQTT_LOCALHOST) && MG_TLS != MG_TLS_BUILTIN +#if MG_TLS != MG_TLS_BUILTIN +#if defined(MQTT_HOST) data.url = mg_mprintf("mqtts://%s:8883", host_ip); #else data.url = strdup(MQTTS_URL); #endif -#else -#ifdef MQTT_LOCALHOST +#else // MG_TLS != MG_TLS_BUILTIN +#if defined(MQTT_HOST) + printf("\nAssuming MQTT_HOST is NOT 1.3, ignoring it for MQTTS tests\n"); +#endif + data.url = strdup(MQTTS_URL); +#endif +#else // MG_TLS +#ifdef MQTT_HOST data.url = mg_mprintf("mqtt://%s:1883", host_ip); #else data.url = strdup(MQTT_URL); #endif -#endif +#endif // MG_TLS s_conn = mg_mqtt_connect(mgr, data.url, &opts, mqtt_fn, &data); ASSERT(s_conn != NULL); for (int i = 0; i < 1000 && s_conn != NULL && !s_conn->is_closing; i++) { @@ -414,16 +422,32 @@ static void test_tls(struct mg_mgr *mgr) { return; } printf("HOST_IP: %s\n", host_ip); - // - POST a large file, make sure we drain TLS buffers and read all: done at - // server test, using curl as POSTing client + printf("NO SIMPLE TLS TEST, no known way to connect to ourselves and no server in HOST_IP\n"); +#if MG_TLS == MG_TLS_BUILTIN && defined(__linux__) && \ + MG_ENABLE_CHACHA20 // skip for non-CHACHA tests // - Fire patched server, test multiple TLS records per TCP segment handling - url = mg_mprintf("https://%s:8443", host_ip); // for historic reasons - ASSERT(system("tls_multirec/server -d tls_multirec &") == 0); - sleep(1); - ASSERT(fetch(mgr, buf, url, "GET /thefile HTTP/1.0\n\n") == 200); - ASSERT(cmpbody(buf, data.buf) == 0); // "thefile" links to Makefile - ASSERT(system("killall tls_multirec/server") == 0); - free(url); + // skip other TLS stacks to avoid "bad client hello", we are 1.3 only + if (access("tls_multirec/server", X_OK) == 0) { + url = mg_mprintf("https://%s:8443", host_ip); + ASSERT(system("tls_multirec/server -d tls_multirec &") == 0); + sleep(1); + // fetch() needs to loop enough times in order to process all TLS records; + // otherwise it will end with 200 and shorter file contents + ASSERT(fetch(mgr, buf, url, "GET /thefile HTTP/1.0\n\n") == 200); + ASSERT(cmpbody(buf, data.buf) == 0); // "thefile" links to Makefile + ASSERT(system("killall tls_multirec/server") == 0); + free(url); + } else { + printf("SKIPPED TLS MULTIPLE RECORDS TEST, tls_multirec/server NOT PRESENT\n"); + } +#else + printf("SKIPPED TLS MULTIPLE RECORDS TEST, not a known TLS 1.3 stack\n"); + (void) cmpbody("", ""); + (void) mgr; + (void) url; // these three: NO SIMPLE TLS TEST + (void) buf; + (void) data; +#endif #else (void) cmpbody("", ""); (void) mgr; diff --git a/test/setup_ga_network.sh b/test/setup_ga_network.sh index af1911e9..7e7bd3d7 100755 --- a/test/setup_ga_network.sh +++ b/test/setup_ga_network.sh @@ -4,7 +4,7 @@ BRIDGE_BROADCAST=192.168.32.255 BRIDGE_IP=192.168.32.1 BRIDGE_NETWORK=192.168.32.0/24 BRIDGE_MASK=255.255.255.0 -// Host network is 'eth0' +# Host network is 'eth0' TAP=tap0 # see our network configuration