2022-07-27 20:16:56 +01:00
|
|
|
// Copyright (c) 2022 Tailscale Inc & AUTHORS All rights reserved.
|
|
|
|
// Use of this source code is governed by a BSD-style
|
|
|
|
// license that can be found in the LICENSE file.
|
|
|
|
|
|
|
|
package tka
|
|
|
|
|
|
|
|
import (
|
2022-07-29 19:03:23 +01:00
|
|
|
"crypto/ed25519"
|
2022-07-27 20:16:56 +01:00
|
|
|
"testing"
|
|
|
|
|
|
|
|
"github.com/google/go-cmp/cmp"
|
2022-08-04 19:45:19 +01:00
|
|
|
"tailscale.com/types/tkatype"
|
2022-07-27 20:16:56 +01:00
|
|
|
)
|
|
|
|
|
2022-07-29 19:03:23 +01:00
|
|
|
type signer25519 ed25519.PrivateKey
|
|
|
|
|
2022-08-04 19:45:19 +01:00
|
|
|
func (s signer25519) SignAUM(sigHash tkatype.AUMSigHash) ([]tkatype.Signature, error) {
|
|
|
|
priv := ed25519.PrivateKey(s)
|
|
|
|
key := Key{Kind: Key25519, Public: priv.Public().(ed25519.PublicKey)}
|
|
|
|
|
|
|
|
return []tkatype.Signature{{
|
|
|
|
KeyID: key.ID(),
|
|
|
|
Signature: ed25519.Sign(priv, sigHash[:]),
|
|
|
|
}}, nil
|
2022-07-29 19:03:23 +01:00
|
|
|
}
|
|
|
|
|
2022-07-27 20:16:56 +01:00
|
|
|
func TestAuthorityBuilderAddKey(t *testing.T) {
|
|
|
|
pub, priv := testingKey25519(t, 1)
|
|
|
|
key := Key{Kind: Key25519, Public: pub, Votes: 2}
|
|
|
|
|
2022-08-26 17:45:16 +01:00
|
|
|
storage := &Mem{}
|
|
|
|
a, _, err := Create(storage, State{
|
2022-07-27 20:16:56 +01:00
|
|
|
Keys: []Key{key},
|
2022-09-07 00:34:16 +01:00
|
|
|
DisablementSecrets: [][]byte{DisablementKDF([]byte{1, 2, 3})},
|
2022-07-29 19:03:23 +01:00
|
|
|
}, signer25519(priv))
|
2022-07-27 20:16:56 +01:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Create() failed: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
pub2, _ := testingKey25519(t, 2)
|
|
|
|
key2 := Key{Kind: Key25519, Public: pub2, Votes: 1}
|
|
|
|
|
2022-07-29 19:03:23 +01:00
|
|
|
b := a.NewUpdater(signer25519(priv))
|
2022-07-27 20:16:56 +01:00
|
|
|
if err := b.AddKey(key2); err != nil {
|
|
|
|
t.Fatalf("AddKey(%v) failed: %v", key2, err)
|
|
|
|
}
|
2022-09-22 19:23:21 +01:00
|
|
|
updates, err := b.Finalize(storage)
|
2022-07-27 20:16:56 +01:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Finalize() failed: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// See if the update is valid by applying it to the authority
|
|
|
|
// + checking if the new key is there.
|
2022-08-26 17:45:16 +01:00
|
|
|
if err := a.Inform(storage, updates); err != nil {
|
2022-07-27 20:16:56 +01:00
|
|
|
t.Fatalf("could not apply generated updates: %v", err)
|
|
|
|
}
|
|
|
|
if _, err := a.state.GetKey(key2.ID()); err != nil {
|
|
|
|
t.Errorf("could not read new key: %v", err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestAuthorityBuilderRemoveKey(t *testing.T) {
|
|
|
|
pub, priv := testingKey25519(t, 1)
|
|
|
|
key := Key{Kind: Key25519, Public: pub, Votes: 2}
|
|
|
|
pub2, _ := testingKey25519(t, 2)
|
|
|
|
key2 := Key{Kind: Key25519, Public: pub2, Votes: 1}
|
|
|
|
|
2022-08-26 17:45:16 +01:00
|
|
|
storage := &Mem{}
|
|
|
|
a, _, err := Create(storage, State{
|
2022-07-27 20:16:56 +01:00
|
|
|
Keys: []Key{key, key2},
|
2022-09-07 00:34:16 +01:00
|
|
|
DisablementSecrets: [][]byte{DisablementKDF([]byte{1, 2, 3})},
|
2022-07-29 19:03:23 +01:00
|
|
|
}, signer25519(priv))
|
2022-07-27 20:16:56 +01:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Create() failed: %v", err)
|
|
|
|
}
|
|
|
|
|
2022-07-29 19:03:23 +01:00
|
|
|
b := a.NewUpdater(signer25519(priv))
|
2022-07-27 20:16:56 +01:00
|
|
|
if err := b.RemoveKey(key2.ID()); err != nil {
|
|
|
|
t.Fatalf("RemoveKey(%v) failed: %v", key2, err)
|
|
|
|
}
|
2022-09-22 19:23:21 +01:00
|
|
|
updates, err := b.Finalize(storage)
|
2022-07-27 20:16:56 +01:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Finalize() failed: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// See if the update is valid by applying it to the authority
|
|
|
|
// + checking if the key has been removed.
|
2022-08-26 17:45:16 +01:00
|
|
|
if err := a.Inform(storage, updates); err != nil {
|
2022-07-27 20:16:56 +01:00
|
|
|
t.Fatalf("could not apply generated updates: %v", err)
|
|
|
|
}
|
|
|
|
if _, err := a.state.GetKey(key2.ID()); err != ErrNoSuchKey {
|
|
|
|
t.Errorf("GetKey(key2).err = %v, want %v", err, ErrNoSuchKey)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestAuthorityBuilderSetKeyVote(t *testing.T) {
|
|
|
|
pub, priv := testingKey25519(t, 1)
|
|
|
|
key := Key{Kind: Key25519, Public: pub, Votes: 2}
|
|
|
|
|
2022-08-26 17:45:16 +01:00
|
|
|
storage := &Mem{}
|
|
|
|
a, _, err := Create(storage, State{
|
2022-07-27 20:16:56 +01:00
|
|
|
Keys: []Key{key},
|
2022-09-07 00:34:16 +01:00
|
|
|
DisablementSecrets: [][]byte{DisablementKDF([]byte{1, 2, 3})},
|
2022-07-29 19:03:23 +01:00
|
|
|
}, signer25519(priv))
|
2022-07-27 20:16:56 +01:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Create() failed: %v", err)
|
|
|
|
}
|
|
|
|
|
2022-07-29 19:03:23 +01:00
|
|
|
b := a.NewUpdater(signer25519(priv))
|
2022-07-27 20:16:56 +01:00
|
|
|
if err := b.SetKeyVote(key.ID(), 5); err != nil {
|
|
|
|
t.Fatalf("SetKeyVote(%v) failed: %v", key.ID(), err)
|
|
|
|
}
|
2022-09-22 19:23:21 +01:00
|
|
|
updates, err := b.Finalize(storage)
|
2022-07-27 20:16:56 +01:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Finalize() failed: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// See if the update is valid by applying it to the authority
|
|
|
|
// + checking if the update is there.
|
2022-08-26 17:45:16 +01:00
|
|
|
if err := a.Inform(storage, updates); err != nil {
|
2022-07-27 20:16:56 +01:00
|
|
|
t.Fatalf("could not apply generated updates: %v", err)
|
|
|
|
}
|
|
|
|
k, err := a.state.GetKey(key.ID())
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
if got, want := k.Votes, uint(5); got != want {
|
|
|
|
t.Errorf("key.Votes = %d, want %d", got, want)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestAuthorityBuilderSetKeyMeta(t *testing.T) {
|
|
|
|
pub, priv := testingKey25519(t, 1)
|
|
|
|
key := Key{Kind: Key25519, Public: pub, Votes: 2, Meta: map[string]string{"a": "b"}}
|
|
|
|
|
2022-08-26 17:45:16 +01:00
|
|
|
storage := &Mem{}
|
|
|
|
a, _, err := Create(storage, State{
|
2022-07-27 20:16:56 +01:00
|
|
|
Keys: []Key{key},
|
2022-09-07 00:34:16 +01:00
|
|
|
DisablementSecrets: [][]byte{DisablementKDF([]byte{1, 2, 3})},
|
2022-07-29 19:03:23 +01:00
|
|
|
}, signer25519(priv))
|
2022-07-27 20:16:56 +01:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Create() failed: %v", err)
|
|
|
|
}
|
|
|
|
|
2022-07-29 19:03:23 +01:00
|
|
|
b := a.NewUpdater(signer25519(priv))
|
2022-07-27 20:16:56 +01:00
|
|
|
if err := b.SetKeyMeta(key.ID(), map[string]string{"b": "c"}); err != nil {
|
|
|
|
t.Fatalf("SetKeyMeta(%v) failed: %v", key, err)
|
|
|
|
}
|
2022-09-22 19:23:21 +01:00
|
|
|
updates, err := b.Finalize(storage)
|
2022-07-27 20:16:56 +01:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Finalize() failed: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// See if the update is valid by applying it to the authority
|
|
|
|
// + checking if the update is there.
|
2022-08-26 17:45:16 +01:00
|
|
|
if err := a.Inform(storage, updates); err != nil {
|
2022-07-27 20:16:56 +01:00
|
|
|
t.Fatalf("could not apply generated updates: %v", err)
|
|
|
|
}
|
|
|
|
k, err := a.state.GetKey(key.ID())
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
if diff := cmp.Diff(map[string]string{"b": "c"}, k.Meta); diff != "" {
|
|
|
|
t.Errorf("updated meta differs (-want, +got):\n%s", diff)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestAuthorityBuilderMultiple(t *testing.T) {
|
|
|
|
pub, priv := testingKey25519(t, 1)
|
|
|
|
key := Key{Kind: Key25519, Public: pub, Votes: 2}
|
|
|
|
|
2022-08-26 17:45:16 +01:00
|
|
|
storage := &Mem{}
|
|
|
|
a, _, err := Create(storage, State{
|
2022-07-27 20:16:56 +01:00
|
|
|
Keys: []Key{key},
|
2022-09-07 00:34:16 +01:00
|
|
|
DisablementSecrets: [][]byte{DisablementKDF([]byte{1, 2, 3})},
|
2022-07-29 19:03:23 +01:00
|
|
|
}, signer25519(priv))
|
2022-07-27 20:16:56 +01:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Create() failed: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
pub2, _ := testingKey25519(t, 2)
|
|
|
|
key2 := Key{Kind: Key25519, Public: pub2, Votes: 1}
|
|
|
|
|
2022-07-29 19:03:23 +01:00
|
|
|
b := a.NewUpdater(signer25519(priv))
|
2022-07-27 20:16:56 +01:00
|
|
|
if err := b.AddKey(key2); err != nil {
|
|
|
|
t.Fatalf("AddKey(%v) failed: %v", key2, err)
|
|
|
|
}
|
|
|
|
if err := b.SetKeyVote(key2.ID(), 42); err != nil {
|
|
|
|
t.Fatalf("SetKeyVote(%v) failed: %v", key2, err)
|
|
|
|
}
|
|
|
|
if err := b.RemoveKey(key.ID()); err != nil {
|
|
|
|
t.Fatalf("RemoveKey(%v) failed: %v", key, err)
|
|
|
|
}
|
2022-09-22 19:23:21 +01:00
|
|
|
updates, err := b.Finalize(storage)
|
2022-07-27 20:16:56 +01:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Finalize() failed: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// See if the update is valid by applying it to the authority
|
|
|
|
// + checking if the update is there.
|
2022-08-26 17:45:16 +01:00
|
|
|
if err := a.Inform(storage, updates); err != nil {
|
2022-07-27 20:16:56 +01:00
|
|
|
t.Fatalf("could not apply generated updates: %v", err)
|
|
|
|
}
|
|
|
|
k, err := a.state.GetKey(key2.ID())
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
if got, want := k.Votes, uint(42); got != want {
|
|
|
|
t.Errorf("key.Votes = %d, want %d", got, want)
|
|
|
|
}
|
|
|
|
if _, err := a.state.GetKey(key.ID()); err != ErrNoSuchKey {
|
|
|
|
t.Errorf("GetKey(key).err = %v, want %v", err, ErrNoSuchKey)
|
|
|
|
}
|
|
|
|
}
|
2022-09-22 19:23:21 +01:00
|
|
|
|
|
|
|
func TestAuthorityBuilderCheckpointsAfterXUpdates(t *testing.T) {
|
|
|
|
pub, priv := testingKey25519(t, 1)
|
|
|
|
key := Key{Kind: Key25519, Public: pub, Votes: 2}
|
|
|
|
|
|
|
|
storage := &Mem{}
|
|
|
|
a, _, err := Create(storage, State{
|
|
|
|
Keys: []Key{key},
|
|
|
|
DisablementSecrets: [][]byte{DisablementKDF([]byte{1, 2, 3})},
|
|
|
|
}, signer25519(priv))
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Create() failed: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
for i := 0; i <= checkpointEvery; i++ {
|
|
|
|
pub2, _ := testingKey25519(t, int64(i+2))
|
|
|
|
key2 := Key{Kind: Key25519, Public: pub2, Votes: 1}
|
|
|
|
|
|
|
|
b := a.NewUpdater(signer25519(priv))
|
|
|
|
if err := b.AddKey(key2); err != nil {
|
|
|
|
t.Fatalf("AddKey(%v) failed: %v", key2, err)
|
|
|
|
}
|
|
|
|
updates, err := b.Finalize(storage)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Finalize() failed: %v", err)
|
|
|
|
}
|
|
|
|
// See if the update is valid by applying it to the authority
|
|
|
|
// + checking if the new key is there.
|
|
|
|
if err := a.Inform(storage, updates); err != nil {
|
|
|
|
t.Fatalf("could not apply generated updates: %v", err)
|
|
|
|
}
|
|
|
|
if _, err := a.state.GetKey(key2.ID()); err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
wantKind := AUMAddKey
|
|
|
|
if i == checkpointEvery-1 { // Genesis + 49 updates == 50 (the value of checkpointEvery)
|
|
|
|
wantKind = AUMCheckpoint
|
|
|
|
}
|
|
|
|
lastAUM, err := storage.AUM(a.Head())
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
if lastAUM.MessageKind != wantKind {
|
|
|
|
t.Errorf("[%d] HeadAUM.MessageKind = %v, want %v", i, lastAUM.MessageKind, wantKind)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Try starting an authority just based on storage.
|
|
|
|
a2, err := Open(storage)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Failed to open from stored AUMs: %v", err)
|
|
|
|
}
|
|
|
|
if a.Head() != a2.Head() {
|
|
|
|
t.Errorf("stored and computed HEAD differ: got %v, want %v", a2.Head(), a.Head())
|
|
|
|
}
|
|
|
|
}
|