Commit 21396139 authored by Updatebot's avatar Updatebot Committed by jschanck@mozilla.com
Browse files

Bug 1967307 - Update NSS to 091af6a9930bd41ada8694bb4487cb8dac62e9c1 r=jschanck

parent e9fadcbe
Loading
Loading
Loading
Loading
+1 −0
Changes for security/nss/gtests/ssl_gtest/manifest.mn: 1 added line, 0 removed lines.
Original line number Diff line number Diff line
@@ -40,6 +40,7 @@ CPPSRCS = \
      ssl_loopback_unittest.cc \
      ssl_masking_unittest.cc \
      ssl_misc_unittest.cc \
      ssl_option_unittest.cc \
      ssl_record_unittest.cc \
      ssl_recordsep_unittest.cc \
      ssl_recordsize_unittest.cc \
+1 −0
Changes for security/nss/gtests/ssl_gtest/ssl_fuzz_unittest.cc: 1 added line, 0 removed lines.
Original line number Diff line number Diff line
@@ -65,6 +65,7 @@ static std::unordered_set<PRInt32> gFuzzedSslOptions = {
    SSL_SUPPRESS_END_OF_EARLY_DATA,
    SSL_ENABLE_GREASE,                    // tls_client, tls_server
    SSL_ENABLE_CH_EXTENSION_PERMUTATION,  // tls_client
    SSL_DB_LOAD_CERTIFICATE_CHAIN,
};

const uint8_t kShortEmptyFinished[8] = {0};
+1 −0
Changes for security/nss/gtests/ssl_gtest/ssl_gtest.gyp: 1 added line, 0 removed lines.
Original line number Diff line number Diff line
@@ -40,6 +40,7 @@
        'ssl_loopback_unittest.cc',
        'ssl_masking_unittest.cc',
        'ssl_misc_unittest.cc',
        'ssl_option_unittest.cc',
        'ssl_record_unittest.cc',
        'ssl_recordsep_unittest.cc',
        'ssl_recordsize_unittest.cc',
+64 −0
Changes for security/nss/gtests/ssl_gtest/ssl_option_unittest.cc: 64 added lines, 0 removed lines.
Original line number Diff line number Diff line
/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
/* vim: set ts=2 et sw=2 tw=80: */
/* This Source Code Form is subject to the terms of the Mozilla Public
 * License, v. 2.0. If a copy of the MPL was not distributed with this file,
 * You can obtain one at http://mozilla.org/MPL/2.0/. */

#include "gtest_utils.h"
#include "ssl.h"
#include "tls_connect.h"

namespace nss_test {

class SslOptionTest : public ::testing::Test {};

static PRInt32 nextOption(PRInt32 index) {
  switch (++index) {
    case SSL_SOCKS:                // pinned to false
    case 4:                        // not defined
    case SSL_ENABLE_SSL2:          // pinned to false
    case SSL_V2_COMPATIBLE_HELLO:  // pinned to false
    case SSL_ENABLE_TLS:           // depends on other options
    case SSL_NO_STEP_DOWN:         // pinned to false
    case SSL_BYPASS_PKCS11:        // pinned to false
    case SSL_ENABLE_NPN:           // pinned to false
    case SSL_RECORD_SIZE_LIMIT:    // not a boolean
      return nextOption(index);
  }
  return index;
}

TEST_F(SslOptionTest, OptionSetDefault) {
  PRIntn original, modified;
  PRInt32 index = nextOption(0);
  while (SECSuccess == SSL_OptionGetDefault(index, &original)) {
    EXPECT_EQ(SECSuccess, SSL_OptionSetDefault(index, 1 ^ original));
    EXPECT_EQ(SECSuccess, SSL_OptionGetDefault(index, &modified));
    EXPECT_EQ(modified, 1 ^ original);
    EXPECT_EQ(SECSuccess, SSL_OptionSetDefault(index, original));
    index = nextOption(index);
  }

  // Update the expected value here when new options are added.
  EXPECT_EQ(index, SSL_DB_LOAD_CERTIFICATE_CHAIN + 1);
}

TEST_F(TlsConnectStreamTls13, OptionSet) {
  EnsureTlsSetup();
  PRIntn original, modified;
  PRInt32 index = nextOption(0);
  while (SECSuccess == SSL_OptionGetDefault(index, &original)) {
    EXPECT_EQ(SECSuccess,
              SSL_OptionSet(client_->ssl_fd(), index, 1 ^ original));
    EXPECT_EQ(SECSuccess, SSL_OptionGet(client_->ssl_fd(), index, &modified));
    EXPECT_EQ(modified, 1 ^ original);
    EXPECT_EQ(SECSuccess, SSL_OptionSet(client_->ssl_fd(), index, original));
    index = nextOption(index);
  }

  // Update the expected value here when new options are added.
  EXPECT_EQ(index, SSL_DB_LOAD_CERTIFICATE_CHAIN + 1);
  Connect();
}

}  // namespace nss_test
+6 −0
Changes for security/nss/lib/ssl/ssl.h: 6 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -380,6 +380,12 @@ SSL_IMPORT PRFileDesc *DTLS_ImportFD(PRFileDesc *model, PRFileDesc *fd);
 */
#define SSL_ENABLE_CH_EXTENSION_PERMUTATION 43

/* Import the peer certificate chain into the database before the
 * authCertificate callback is invoked for certificate validation.
 * This behavior is enabled by default.
 */
#define SSL_DB_LOAD_CERTIFICATE_CHAIN 44

#ifdef SSL_DEPRECATED_FUNCTION
/* Old deprecated function names */
SSL_IMPORT SECStatus SSL_Enable(PRFileDesc *fd, int option, PRIntn on);
Loading