2 // KCJoiningSessionTest.m
7 #import <XCTest/XCTest.h>
9 #import <Foundation/Foundation.h>
11 #import <KeychainCircle/KCJoiningSession.h>
12 #import <KeychainCircle/KCError.h>
13 #import <KeychainCircle/NSError+KCCreationHelpers.h>
14 #import <KeychainCircle/KCAESGCMDuplexSession.h>
16 #include <Security/SecBase.h>
17 #include <Security/SecureObjectSync/SOSFullPeerInfo.h>
18 #include <Security/SecureObjectSync/SOSPeerInfoInternal.h>
20 #include <CommonCrypto/CommonRandomSPI.h>
23 __unused static SOSFullPeerInfoRef SOSNSFullPeerInfoCreate(NSDictionary* gestalt,
24 NSData* backupKey, SecKeyRef signingKey,
25 SecKeyRef octagonSigningKey,
26 SecKeyRef octagonEncryptionKey,
29 CFErrorRef errorRef = NULL;
31 SOSFullPeerInfoRef result = SOSFullPeerInfoCreate(NULL, (__bridge CFDictionaryRef) gestalt, (__bridge CFDataRef) backupKey, signingKey, octagonSigningKey, octagonEncryptionKey, &errorRef);
33 if (errorRef && error) {
34 *error = (__bridge_transfer NSError*) errorRef;
41 static SecKeyRef GenerateFullECKey_internal(int keySize, NSError** error)
43 SecKeyRef full_key = NULL;
45 NSDictionary* keygen_parameters = @{ (__bridge NSString*)kSecAttrKeyType:(__bridge NSString*) kSecAttrKeyTypeEC,
46 (__bridge NSString*)kSecAttrKeySizeInBits: [NSNumber numberWithInt: keySize] };
49 (void) OSStatusError(SecKeyGeneratePair((__bridge CFDictionaryRef)keygen_parameters, NULL, &full_key), error, @"Generate Key failed");
54 static SecKeyRef GenerateFullECKey(int keySize, NSError** error) {
55 return GenerateFullECKey_internal(keySize, error);
59 @interface KCJoiningRequestTestDelegate : NSObject <KCJoiningRequestSecretDelegate, KCJoiningRequestCircleDelegate>
60 @property (readwrite) NSString* sharedSecret;
62 @property (readonly) NSString* accountCode;
63 @property (readonly) NSData* circleJoinData;
64 @property (readwrite) SOSPeerInfoRef peerInfo;
66 @property (readwrite) NSString* incorrectSecret;
67 @property (readwrite) int incorrectTries;
70 + (id) requestDelegateWithSecret:(NSString*) secret;
71 - (id) init NS_UNAVAILABLE;
72 - (id) initWithSecret: (NSString*) secret
73 incorrectSecret: (NSString*) wrongSecret
74 incorrectTries: (int) retries NS_DESIGNATED_INITIALIZER;
76 - (NSString*) verificationFailed: (bool) codeChanged;
77 - (SOSPeerInfoRef) copyPeerInfoError: (NSError**) error;
78 - (bool) processCircleJoinData: (NSData*) circleJoinData version:(PiggyBackProtocolVersion)version error: (NSError**)error ;
79 - (bool) processAccountCode: (NSString*) accountCode error: (NSError**)error;
83 @implementation KCJoiningRequestTestDelegate
91 + (id) requestDelegateWithSecret:(NSString*) secret {
92 return [[KCJoiningRequestTestDelegate alloc] initWithSecret:secret
97 + (id) requestDelegateWithSecret:(NSString*) secret
98 incorrectSecret:(NSString*) wrongSecret
99 incorrectTries:(int) retries {
100 return [[KCJoiningRequestTestDelegate alloc] initWithSecret:secret
101 incorrectSecret:wrongSecret
102 incorrectTries:retries];
106 - (id) initWithSecret: (NSString*) secret
107 incorrectSecret: (NSString*) incorrectSecret
108 incorrectTries: (int) retries {
111 SecKeyRef signingKey = GenerateFullECKey(256, NULL);
112 SecKeyRef octagonSigningKey = GenerateFullECKey(384, NULL);
113 SecKeyRef octagonEncryptionKey = GenerateFullECKey(384, NULL);
115 SOSPeerInfoRef newPeerInfo = SOSPeerInfoCreate(NULL, (__bridge CFDictionaryRef) @{(__bridge NSString*)kPIUserDefinedDeviceNameKey:@"Fakey"}, NULL, signingKey, octagonSigningKey, octagonEncryptionKey, NULL);
117 if (newPeerInfo == NULL) {
120 self.peerInfo = newPeerInfo;
121 CFRelease(newPeerInfo);
124 self.sharedSecret = secret;
125 self.incorrectSecret = incorrectSecret;
126 self.incorrectTries = retries;
131 - (NSString*) nextSecret {
132 if (self.incorrectTries > 0) {
133 self.incorrectTries -= 1;
134 return self.incorrectSecret;
136 return self.sharedSecret;
139 - (NSString*) secret {
140 return [self nextSecret];
143 - (NSString*) verificationFailed: (bool) codeChanged {
144 return [self nextSecret];
147 - (SOSPeerInfoRef) copyPeerInfoError: (NSError**) error {
152 return (SOSPeerInfoRef) CFRetain(self.peerInfo);
155 - (bool) processCircleJoinData: (NSData*) circleJoinData version:(PiggyBackProtocolVersion)version error: (NSError**)error {
156 self->_circleJoinData = circleJoinData;
160 - (bool) processAccountCode: (NSString*) accountCode error: (NSError**)error {
161 self->_accountCode = accountCode;
167 @interface KCJoiningAcceptTestDelegate : NSObject <KCJoiningAcceptSecretDelegate, KCJoiningAcceptCircleDelegate>
168 @property (readonly) NSArray<NSString*>* secrets;
169 @property (readwrite) NSUInteger currentSecret;
170 @property (readwrite) int retriesLeft;
171 @property (readwrite) int retriesPerSecret;
173 @property (readonly) NSString* codeToUse;
174 @property (readonly) NSData* circleJoinData;
175 @property (readonly) SOSPeerInfoRef peerInfo;
177 + (id) acceptDelegateWithSecret: (NSString*) secret code: (NSString*) code;
178 + (id) acceptDelegateWithSecrets: (NSArray<NSString*>*) secrets retries: (int) retries code: (NSString*) code;
179 - (id) initWithSecrets: (NSArray<NSString*>*) secrets retries: (int) retries code: (NSString*) code NS_DESIGNATED_INITIALIZER;
182 - (NSString*) secret;
183 - (NSString*) accountCode;
185 - (KCRetryOrNot) verificationFailed: (NSError**) error;
186 - (NSData*) circleJoinDataFor: (SOSPeerInfoRef) peer
187 error: (NSError**) error;
189 - (id) init NS_UNAVAILABLE;
193 @implementation KCJoiningAcceptTestDelegate
195 + (id) acceptDelegateWithSecrets: (NSArray<NSString*>*) secrets retries: (int) retries code: (NSString*) code {
196 return [[KCJoiningAcceptTestDelegate alloc] initWithSecrets:secrets retries:retries code:code];
200 + (id) acceptDelegateWithSecret: (NSString*) secret code: (NSString*) code {
201 return [[KCJoiningAcceptTestDelegate alloc] initWithSecret:secret code:code];
204 - (id) initWithSecret: (NSString*) secret code: (NSString*) code {
205 return [self initWithSecrets:@[secret] retries:3 code:code];
208 - (id) initWithSecrets: (NSArray<NSString*>*) secrets retries: (int) retries code: (NSString*) code {
211 self->_secrets = secrets;
212 self.currentSecret = 0;
213 self->_retriesPerSecret = retries;
214 self->_retriesLeft = self.retriesPerSecret;
216 self->_codeToUse = code;
218 uint8_t joinDataBuffer[] = { 10, 9, 8, 7, 6, 5, 4, 3, 2, 1 };
219 self->_circleJoinData = [NSData dataWithBytes: joinDataBuffer length: sizeof(joinDataBuffer) ];
224 - (KCRetryOrNot) advanceSecret {
225 if (self.retriesLeft == 0) {
226 self.currentSecret += 1;
227 if (self.currentSecret >= [self.secrets count]) {
228 self.currentSecret = [self.secrets count] - 1;
230 self.retriesLeft = self.retriesPerSecret;
231 return kKCRetryWithNewChallenge;
233 self.retriesLeft -= 1;
234 return kKCRetryWithSameChallenge;
238 - (NSString*) secret {
239 return self.secrets[self.currentSecret];
241 - (NSString*) accountCode {
242 return self.codeToUse;
245 - (KCRetryOrNot) verificationFailed: (NSError**) error {
246 return [self advanceSecret];
249 - (NSData*) circleJoinDataFor: (SOSPeerInfoRef) peer
250 error: (NSError**) error {
251 uint8_t joinDataBuffer[] = { 10, 9, 8, 7, 6, 5, 4, 3, 2, 1 };
253 self->_peerInfo = peer;
254 return [NSData dataWithBytes: joinDataBuffer length: sizeof(joinDataBuffer) ];
257 -(NSData*) circleGetInitialSyncViews: (NSError**) error{
258 return [NSData data];
264 @interface KCJoiningSessionTest : XCTestCase
268 @implementation KCJoiningSessionTest
272 // Put setup code here. This method is called before the invocation of each test method in the class.
276 // Put teardown code here. This method is called after the invocation of each test method in the class.
280 - (void)testJoiningSession {
281 NSError* error = nil;
283 NSString* secret = @"123456";
284 NSString* code = @"987654";
286 uint64_t dsid = 0x1234567887654321;
288 KCJoiningRequestTestDelegate* requestDelegate = [KCJoiningRequestTestDelegate requestDelegateWithSecret: secret];
289 KCJoiningRequestSecretSession *requestSession = [[KCJoiningRequestSecretSession alloc] initWithSecretDelegate:requestDelegate
291 rng:ccDRBGGetRngState()
294 NSData* initialMessage = [requestSession initialMessage: &error];
296 XCTAssertNotNil(initialMessage, @"No initial message");
297 XCTAssertNil(error, @"Got error %@", error);
299 KCJoiningAcceptTestDelegate* acceptDelegate = [KCJoiningAcceptTestDelegate acceptDelegateWithSecret:secret code:code];
300 KCJoiningAcceptSession* acceptSession = [[KCJoiningAcceptSession alloc] initWithSecretDelegate:acceptDelegate
301 circleDelegate:acceptDelegate
303 rng:ccDRBGGetRngState()
307 NSData* challenge = [acceptSession processMessage: initialMessage error: &error];
309 XCTAssertNotNil(challenge, @"No initial message");
310 XCTAssertNil(error, @"Got error %@", error);
313 NSData* response = [requestSession processMessage: challenge error: &error];
315 XCTAssertNotNil(response, @"No response message");
316 XCTAssertNil(error, @"Got error %@", error);
319 NSData* verification = [acceptSession processMessage: response error: &error];
321 XCTAssertNotNil(verification, @"No verification message");
322 XCTAssertNil(error, @"Got error %@", error);
325 NSData* doneMessage = [requestSession processMessage: verification error: &error];
327 XCTAssertNotNil(doneMessage, @"No response message");
328 XCTAssertNil(error, @"Got error %@", error);
330 XCTAssertTrue([requestSession isDone], @"SecretSession done");
331 XCTAssertFalse([acceptSession isDone], @"Unexpected accept session done");
333 KCAESGCMDuplexSession* aesSession = [requestSession session];
334 requestSession = nil;
336 KCJoiningRequestCircleSession* requestSecretSession = [KCJoiningRequestCircleSession sessionWithCircleDelegate:requestDelegate session:aesSession error:&error];
338 XCTAssertNotNil(requestSecretSession, @"No request secret session");
339 XCTAssertNil(error, @"Got error %@", error);
342 NSData* peerInfoMessage = [requestSecretSession initialMessage: &error];
344 XCTAssertNotNil(peerInfoMessage, @"No peerInfo message");
345 XCTAssertNil(error, @"Got error %@", error);
347 XCTAssertEqualObjects(requestDelegate.accountCode, acceptDelegate.codeToUse, @"Code made it");
350 NSData* blobMessage = [acceptSession processMessage:peerInfoMessage error: &error];
352 XCTAssertNotNil(blobMessage, @"No blob message");
353 XCTAssertNil(error, @"Got error %@", error);
355 // We have different peer_info types due to wierd linking of our tests.
356 // Compare the der representations:
357 NSData* rp_der = requestDelegate.peerInfo != nil ? (__bridge_transfer NSData*) SOSPeerInfoCopyEncodedData(requestDelegate.peerInfo, NULL, NULL) : nil;
358 NSData* ap_der = acceptDelegate.peerInfo != nil ? (__bridge_transfer NSData*) SOSPeerInfoCopyEncodedData(acceptDelegate.peerInfo, NULL, NULL) : nil;
360 XCTAssertEqualObjects(rp_der, ap_der, @"Peer infos match");
363 NSData* nothing = [requestSecretSession processMessage:blobMessage error: &error];
365 XCTAssertEqualObjects(requestDelegate.circleJoinData, acceptDelegate.circleJoinData);
367 XCTAssertNotNil(nothing, @"No initial message");
368 XCTAssertNil(error, @"Got error %@", error);
370 XCTAssertTrue([requestSecretSession isDone], @"requesor done");
371 XCTAssertTrue([acceptSession isDone], @"acceptor done");
375 - (void)testJoiningSessionRetry {
376 NSError* error = nil;
378 NSString* secret = @"123456";
379 NSString* code = @"987654";
381 uint64_t dsid = 0x1234567887654321;
383 KCJoiningRequestTestDelegate* requestDelegate = [KCJoiningRequestTestDelegate requestDelegateWithSecret: secret incorrectSecret:@"777888" incorrectTries:3];
384 KCJoiningRequestSecretSession *requestSession = [[KCJoiningRequestSecretSession alloc] initWithSecretDelegate:requestDelegate
386 rng:ccDRBGGetRngState()
389 NSData* initialMessage = [requestSession initialMessage: &error];
391 XCTAssertNotNil(initialMessage, @"No initial message");
392 XCTAssertNil(error, @"Got error %@", error);
394 KCJoiningAcceptTestDelegate* acceptDelegate = [KCJoiningAcceptTestDelegate acceptDelegateWithSecret:secret code:code];
395 KCJoiningAcceptSession* acceptSession = [[KCJoiningAcceptSession alloc] initWithSecretDelegate:acceptDelegate
396 circleDelegate:acceptDelegate
398 rng:ccDRBGGetRngState()
402 NSData* challenge = [acceptSession processMessage: initialMessage error: &error];
404 XCTAssertNotNil(challenge, @"No initial message");
405 XCTAssertNil(error, @"Got error %@", error);
407 NSData* response = nil;
408 NSData* verification = nil;
410 NSData* nextChallenge = challenge;
411 for (int tries = 0; tries < 4; ++tries) {
413 response = [requestSession processMessage: nextChallenge error: &error];
415 XCTAssertNotNil(response, @"No response message");
416 XCTAssertNil(error, @"Got error %@", error);
418 XCTAssertNotEqualObjects(requestDelegate.accountCode, acceptDelegate.codeToUse, @"Code should not make it");
421 verification = [acceptSession processMessage: response error: &error];
423 XCTAssertNotNil(verification, @"No verification message");
424 XCTAssertNil(error, @"Got error %@", error);
426 nextChallenge = verification;
430 NSData* doneMessage = [requestSession processMessage: verification error: &error];
432 XCTAssertNotNil(doneMessage, @"No response message");
433 XCTAssertNil(error, @"Got error %@", error);
435 XCTAssertTrue([requestSession isDone], @"SecretSession done");
436 XCTAssertFalse([acceptSession isDone], @"Unexpected accept session done");
438 KCAESGCMDuplexSession* aesSession = [requestSession session];
439 requestSession = nil;
442 KCJoiningRequestCircleSession* requestSecretSession = [KCJoiningRequestCircleSession sessionWithCircleDelegate:requestDelegate session:aesSession error:&error];
444 XCTAssertNotNil(requestSecretSession, @"No request secret session");
445 XCTAssertNil(error, @"Got error %@", error);
448 NSData* peerInfoMessage = [requestSecretSession initialMessage: &error];
450 XCTAssertNotNil(peerInfoMessage, @"No peerInfo message");
451 XCTAssertNil(error, @"Got error %@", error);
453 XCTAssertEqualObjects(requestDelegate.accountCode, acceptDelegate.codeToUse, @"Code made it");
456 NSData* blobMessage = [acceptSession processMessage:peerInfoMessage error: &error];
458 XCTAssertNotNil(blobMessage, @"No blob message");
459 XCTAssertNil(error, @"Got error %@", error);
461 // We have different peer_info types due to wierd linking of our tests.
462 // Compare the der representations:
463 NSData* rp_der = requestDelegate.peerInfo != nil ? (__bridge_transfer NSData*) SOSPeerInfoCopyEncodedData(requestDelegate.peerInfo, NULL, NULL) : nil;
464 NSData* ap_der = acceptDelegate.peerInfo != nil ? (__bridge_transfer NSData*) SOSPeerInfoCopyEncodedData(acceptDelegate.peerInfo, NULL, NULL) : nil;
466 XCTAssertEqualObjects(rp_der, ap_der, @"Peer infos match");
469 NSData* nothing = [requestSecretSession processMessage:blobMessage error: &error];
471 XCTAssertEqualObjects(requestDelegate.circleJoinData, acceptDelegate.circleJoinData);
473 XCTAssertNotNil(nothing, @"No initial message");
474 XCTAssertNil(error, @"Got error %@", error);
476 XCTAssertTrue([requestSecretSession isDone], @"requesor done");
477 XCTAssertTrue([acceptSession isDone], @"acceptor done");
481 - (void)testJoiningSessionCodeChange {
482 NSError* error = nil;
484 NSString* secret = @"123456";
485 NSString* code = @"987654";
487 uint64_t dsid = 0x1234567887654321;
489 KCJoiningRequestTestDelegate* requestDelegate = [KCJoiningRequestTestDelegate requestDelegateWithSecret: secret];
490 KCJoiningRequestSecretSession *requestSession = [[KCJoiningRequestSecretSession alloc] initWithSecretDelegate:requestDelegate
492 rng:ccDRBGGetRngState()
495 NSData* initialMessage = [requestSession initialMessage: &error];
497 XCTAssertNotNil(initialMessage, @"No initial message");
498 XCTAssertNil(error, @"Got error %@", error);
500 KCJoiningAcceptTestDelegate* acceptDelegate = [KCJoiningAcceptTestDelegate acceptDelegateWithSecrets:@[@"222222", @"3333333", secret] retries:1 code:code];
501 KCJoiningAcceptSession* acceptSession = [[KCJoiningAcceptSession alloc] initWithSecretDelegate:acceptDelegate
502 circleDelegate:acceptDelegate
504 rng:ccDRBGGetRngState()
508 NSData* challenge = [acceptSession processMessage: initialMessage error: &error];
510 XCTAssertNotNil(challenge, @"No initial message");
511 XCTAssertNil(error, @"Got error %@", error);
513 NSData* response = nil;
514 NSData* verification = nil;
516 NSData* nextChallenge = challenge;
517 for (int tries = 0; tries < 5; ++tries) {
519 response = [requestSession processMessage: nextChallenge error: &error];
521 XCTAssertNotNil(response, @"No response message");
522 XCTAssertNil(error, @"Got error %@", error);
524 XCTAssertNotEqualObjects(requestDelegate.accountCode, acceptDelegate.codeToUse, @"Code should not make it");
527 verification = [acceptSession processMessage: response error: &error];
529 XCTAssertNotNil(verification, @"No verification message");
530 XCTAssertNil(error, @"Got error %@", error);
532 nextChallenge = verification;
536 NSData* doneMessage = [requestSession processMessage: verification error: &error];
538 XCTAssertNotNil(doneMessage, @"No response message");
539 XCTAssertNil(error, @"Got error %@", error);
541 XCTAssertTrue([requestSession isDone], @"SecretSession done");
542 XCTAssertFalse([acceptSession isDone], @"Unexpected accept session done");
544 KCAESGCMDuplexSession* aesSession = [requestSession session];
545 requestSession = nil;
548 KCJoiningRequestCircleSession* requestSecretSession = [KCJoiningRequestCircleSession sessionWithCircleDelegate:requestDelegate session:aesSession error:&error];
550 XCTAssertNotNil(requestSecretSession, @"No request secret session");
551 XCTAssertNil(error, @"Got error %@", error);
554 NSData* peerInfoMessage = [requestSecretSession initialMessage: &error];
556 XCTAssertNotNil(peerInfoMessage, @"No peerInfo message");
557 XCTAssertNil(error, @"Got error %@", error);
559 XCTAssertEqualObjects(requestDelegate.accountCode, acceptDelegate.codeToUse, @"Code made it");
562 NSData* blobMessage = [acceptSession processMessage:peerInfoMessage error: &error];
564 XCTAssertNotNil(blobMessage, @"No blob message");
565 XCTAssertNil(error, @"Got error %@", error);
567 // We have different peer_info types due to wierd linking of our tests.
568 // Compare the der representations:
569 NSData* rp_der = requestDelegate.peerInfo != nil ? (__bridge_transfer NSData*) SOSPeerInfoCopyEncodedData(requestDelegate.peerInfo, NULL, NULL) : nil;
570 NSData* ap_der = acceptDelegate.peerInfo != nil ? (__bridge_transfer NSData*) SOSPeerInfoCopyEncodedData(acceptDelegate.peerInfo, NULL, NULL) : nil;
572 XCTAssertEqualObjects(rp_der, ap_der, @"Peer infos match");
575 NSData* nothing = [requestSecretSession processMessage:blobMessage error: &error];
577 XCTAssertEqualObjects(requestDelegate.circleJoinData, acceptDelegate.circleJoinData);
579 XCTAssertNotNil(nothing, @"No initial message");
580 XCTAssertNil(error, @"Got error %@", error);
582 XCTAssertTrue([requestSecretSession isDone], @"requesor done");
583 XCTAssertTrue([acceptSession isDone], @"acceptor done");