|
5 | 5 | package ssh
|
6 | 6 |
|
7 | 7 | import (
|
| 8 | + "io" |
| 9 | + "net" |
| 10 | + "sync/atomic" |
8 | 11 | "testing"
|
| 12 | + "time" |
9 | 13 | )
|
10 | 14 |
|
11 | 15 | func TestClientAuthRestrictedPublicKeyAlgos(t *testing.T) {
|
@@ -59,27 +63,70 @@ func TestClientAuthRestrictedPublicKeyAlgos(t *testing.T) {
|
59 | 63 | }
|
60 | 64 |
|
61 | 65 | func TestNewServerConnValidationErrors(t *testing.T) {
|
62 |
| - c1, c2, err := netPipe() |
63 |
| - if err != nil { |
64 |
| - t.Fatalf("netPipe: %v", err) |
65 |
| - } |
66 |
| - defer c1.Close() |
67 |
| - defer c2.Close() |
68 |
| - |
69 | 66 | serverConf := &ServerConfig{
|
70 | 67 | PublicKeyAuthAlgorithms: []string{CertAlgoRSAv01},
|
71 | 68 | }
|
72 |
| - _, _, _, err = NewServerConn(c1, serverConf) |
| 69 | + c := &markerConn{} |
| 70 | + _, _, _, err := NewServerConn(c, serverConf) |
73 | 71 | if err == nil {
|
74 | 72 | t.Fatal("NewServerConn with invalid public key auth algorithms succeeded")
|
75 | 73 | }
|
| 74 | + if !c.closed.Load() { |
| 75 | + t.Fatal("NewServerConn with invalid public key auth algorithms left connection open") |
| 76 | + } |
| 77 | + if c.used.Load() { |
| 78 | + t.Fatal("NewServerConn with invalid public key auth algorithms used connection") |
| 79 | + } |
| 80 | + |
76 | 81 | serverConf = &ServerConfig{
|
77 | 82 | Config: Config{
|
78 | 83 | KeyExchanges: []string{kexAlgoDHGEXSHA256},
|
79 | 84 | },
|
80 | 85 | }
|
81 |
| - _, _, _, err = NewServerConn(c1, serverConf) |
| 86 | + c = &markerConn{} |
| 87 | + _, _, _, err = NewServerConn(c, serverConf) |
82 | 88 | if err == nil {
|
83 | 89 | t.Fatal("NewServerConn with unsupported key exchange succeeded")
|
84 | 90 | }
|
| 91 | + if !c.closed.Load() { |
| 92 | + t.Fatal("NewServerConn with unsupported key exchange left connection open") |
| 93 | + } |
| 94 | + if c.used.Load() { |
| 95 | + t.Fatal("NewServerConn with unsupported key exchange used connection") |
| 96 | + } |
85 | 97 | }
|
| 98 | + |
| 99 | +type markerConn struct { |
| 100 | + closed atomic.Bool |
| 101 | + used atomic.Bool |
| 102 | +} |
| 103 | + |
| 104 | +func (c *markerConn) Close() error { |
| 105 | + c.closed.Store(true) |
| 106 | + return nil |
| 107 | +} |
| 108 | + |
| 109 | +func (c *markerConn) Read(b []byte) (n int, err error) { |
| 110 | + c.used.Store(true) |
| 111 | + if c.closed.Load() { |
| 112 | + return 0, net.ErrClosed |
| 113 | + } else { |
| 114 | + return 0, io.EOF |
| 115 | + } |
| 116 | +} |
| 117 | + |
| 118 | +func (c *markerConn) Write(b []byte) (n int, err error) { |
| 119 | + c.used.Store(true) |
| 120 | + if c.closed.Load() { |
| 121 | + return 0, net.ErrClosed |
| 122 | + } else { |
| 123 | + return 0, io.ErrClosedPipe |
| 124 | + } |
| 125 | +} |
| 126 | + |
| 127 | +func (*markerConn) LocalAddr() net.Addr { return nil } |
| 128 | +func (*markerConn) RemoteAddr() net.Addr { return nil } |
| 129 | + |
| 130 | +func (*markerConn) SetDeadline(t time.Time) error { return nil } |
| 131 | +func (*markerConn) SetReadDeadline(t time.Time) error { return nil } |
| 132 | +func (*markerConn) SetWriteDeadline(t time.Time) error { return nil } |
0 commit comments