Blame tests/client/torture_knownhosts.c

Packit Service 31306d
/*
Packit Service 31306d
 * This file is part of the SSH Library
Packit Service 31306d
 *
Packit Service 31306d
 * Copyright (c) 2010 by Aris Adamantiadis
Packit Service 31306d
 *
Packit Service 31306d
 * The SSH Library is free software; you can redistribute it and/or modify
Packit Service 31306d
 * it under the terms of the GNU Lesser General Public License as published by
Packit Service 31306d
 * the Free Software Foundation; either version 2.1 of the License, or (at your
Packit Service 31306d
 * option) any later version.
Packit Service 31306d
 *
Packit Service 31306d
 * The SSH Library is distributed in the hope that it will be useful, but
Packit Service 31306d
 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
Packit Service 31306d
 * or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU Lesser General Public
Packit Service 31306d
 * License for more details.
Packit Service 31306d
 *
Packit Service 31306d
 * You should have received a copy of the GNU Lesser General Public License
Packit Service 31306d
 * along with the SSH Library; see the file COPYING.  If not, write to
Packit Service 31306d
 * the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
Packit Service 31306d
 * MA 02111-1307, USA.
Packit Service 31306d
 */
Packit Service 31306d
Packit Service 31306d
#include "config.h"
Packit Service 31306d
Packit Service 31306d
#define LIBSSH_STATIC
Packit Service 31306d
Packit Service 31306d
#include "torture.h"
Packit Service 31306d
#include "torture_key.h"
Packit Service 31306d
Packit Service 31306d
#include <sys/types.h>
Packit Service 31306d
#include <pwd.h>
Packit Service 31306d
#include <errno.h>
Packit Service 31306d
Packit Service 31306d
#include "session.c"
Packit Service 31306d
#include "known_hosts.c"
Packit Service 31306d
Packit Service 31306d
#define TMP_FILE_TEMPLATE "known_hosts_XXXXXX"
Packit Service 31306d
Packit Service 31306d
#define BADRSA "AAAAB3NzaC1yc2EAAAADAQABAAABAQChm5" \
Packit Service 31306d
               "a6Av65O8cKtx5YXOnui3wJnYE6A6J/I4kZSAibbn14Jcl+34VJQwv96f25AxNmo" \
Packit Service 31306d
               "NwoiZV93IzdypQmiuieh6s6wB9WhYjU9K/6CkIpNhpCxswA90b3ePjS7LnR9B9J" \
Packit Service 31306d
               "slPSbG1H0KC1c5lb7G3utXteXtM+4YvCvpN5VdC4CpghT+p0cwN2Na8Md5vRItz" \
Packit Service 31306d
               "YgIytryNn7LLiwYfoSxvWigFrTTZsrVtCOYyNgklmffpGdzuC43wdANvTewfI9G" \
Packit Service 31306d
               "o71r8EXmEc228CrYPmb8Scv3mpXFK/BosohSGkPlEHu9lf3YjnknBicDaVtJOYp" \
Packit Service 31306d
               "wnXJPjZo2EhG79HxDRpjJHH"
Packit Service 31306d
#define BADED25519 "AAAAC3NzaC1lZDI1NTE5AAAAIE74wHmKKkrxpW/dZ69pKPlMoWG9VvWfrNnUkWRQqaDa"
Packit Service 31306d
Packit Service 31306d
static int sshd_setup(void **state)
Packit Service 31306d
{
Packit Service 31306d
    torture_setup_sshd_server(state, false);
Packit Service 31306d
Packit Service 31306d
    return 0;
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
static int sshd_teardown(void **state) {
Packit Service 31306d
    torture_teardown_sshd_server(state);
Packit Service 31306d
Packit Service 31306d
    return 0;
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
static int session_setup(void **state)
Packit Service 31306d
{
Packit Service 31306d
    struct torture_state *s = *state;
Packit Service 31306d
    int verbosity = torture_libssh_verbosity();
Packit Service 31306d
    struct passwd *pwd;
Packit Service 31306d
    bool process_config = false;
Packit Service 31306d
    int rc;
Packit Service 31306d
Packit Service 31306d
    pwd = getpwnam("bob");
Packit Service 31306d
    assert_non_null(pwd);
Packit Service 31306d
Packit Service 31306d
    rc = setuid(pwd->pw_uid);
Packit Service 31306d
    assert_return_code(rc, errno);
Packit Service 31306d
Packit Service 31306d
    s->ssh.session = ssh_new();
Packit Service 31306d
    assert_non_null(s->ssh.session);
Packit Service 31306d
Packit Service 31306d
    ssh_options_set(s->ssh.session, SSH_OPTIONS_LOG_VERBOSITY, &verbosity);
Packit Service 31306d
    ssh_options_set(s->ssh.session, SSH_OPTIONS_PROCESS_CONFIG,
Packit Service 31306d
                    &process_config);
Packit Service 31306d
    ssh_options_set(s->ssh.session, SSH_OPTIONS_HOST, TORTURE_SSH_SERVER);
Packit Service 31306d
    ssh_options_set(s->ssh.session, SSH_OPTIONS_USER, TORTURE_SSH_USER_ALICE);
Packit Service 31306d
Packit Service 31306d
    return 0;
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
static int session_teardown(void **state)
Packit Service 31306d
{
Packit Service 31306d
    struct torture_state *s = *state;
Packit Service 31306d
Packit Service 31306d
    ssh_disconnect(s->ssh.session);
Packit Service 31306d
    ssh_free(s->ssh.session);
Packit Service 31306d
Packit Service 31306d
    return 0;
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
Packit Service 31306d
static void torture_knownhosts_port(void **state) {
Packit Service 31306d
    struct torture_state *s = *state;
Packit Service 31306d
    ssh_session session = s->ssh.session;
Packit Service 31306d
    char tmp_file[1024] = {0};
Packit Service 31306d
    char *known_hosts_file = NULL;
Packit Service 31306d
    char buffer[200];
Packit Service 31306d
    char *p;
Packit Service 31306d
    FILE *file;
Packit Service 31306d
    int rc;
Packit Service 31306d
    bool process_config = false;
Packit Service 31306d
Packit Service 31306d
    snprintf(tmp_file,
Packit Service 31306d
             sizeof(tmp_file),
Packit Service 31306d
             "%s/%s",
Packit Service 31306d
             s->socket_dir,
Packit Service 31306d
             TMP_FILE_TEMPLATE);
Packit Service 31306d
Packit Service 31306d
    known_hosts_file = torture_create_temp_file(tmp_file);
Packit Service 31306d
    assert_non_null(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_KNOWNHOSTS, known_hosts_file);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_connect(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    session->opts.port = 1234;
Packit Service 31306d
    rc = ssh_write_knownhost(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    file = fopen(known_hosts_file, "r");
Packit Service 31306d
    assert_non_null(file);
Packit Service 31306d
    p = fgets(buffer, sizeof(buffer), file);
Packit Service 31306d
    assert_non_null(p);
Packit Service 31306d
    fclose(file);
Packit Service 31306d
    buffer[sizeof(buffer) - 1] = '\0';
Packit Service 31306d
    assert_non_null(strstr(buffer,"[127.0.0.10]:1234 "));
Packit Service 31306d
Packit Service 31306d
    ssh_disconnect(session);
Packit Service 31306d
    ssh_free(session);
Packit Service 31306d
Packit Service 31306d
    /* Now, connect back to the ssh server and verify the known host line */
Packit Service 31306d
    s->ssh.session = session = ssh_new();
Packit Service 31306d
Packit Service 31306d
    ssh_options_set(session, SSH_OPTIONS_PROCESS_CONFIG, &process_config);
Packit Service 31306d
    ssh_options_set(session, SSH_OPTIONS_HOST, TORTURE_SSH_SERVER);
Packit Service 31306d
    ssh_options_set(session, SSH_OPTIONS_KNOWNHOSTS, known_hosts_file);
Packit Service 31306d
    free(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_connect(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    session->opts.port = 1234;
Packit Service 31306d
    rc = ssh_is_server_known(session);
Packit Service 31306d
    assert_int_equal(rc, SSH_SERVER_KNOWN_OK);
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
static void torture_knownhosts_wildcard(void **state)
Packit Service 31306d
{
Packit Service 31306d
    struct torture_state *s = *state;
Packit Service 31306d
    ssh_session session = s->ssh.session;
Packit Service 31306d
    char tmp_file[1024] = {0};
Packit Service 31306d
    char *known_hosts_file = NULL;
Packit Service 31306d
    const char *key = NULL;
Packit Service 31306d
    FILE *file;
Packit Service 31306d
    int rc;
Packit Service 31306d
Packit Service 31306d
    snprintf(tmp_file,
Packit Service 31306d
             sizeof(tmp_file),
Packit Service 31306d
             "%s/%s",
Packit Service 31306d
             s->socket_dir,
Packit Service 31306d
             TMP_FILE_TEMPLATE);
Packit Service 31306d
Packit Service 31306d
    known_hosts_file = torture_create_temp_file(tmp_file);
Packit Service 31306d
    assert_non_null(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    file = fopen(known_hosts_file, "w");
Packit Service 31306d
    assert_non_null(file);
Packit Service 31306d
    key = torture_get_testkey_pub(SSH_KEYTYPE_RSA);
Packit Service 31306d
    fprintf(file, "[127.0.0.10]:* %s\n", key);
Packit Service 31306d
    fclose(file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_HOST, TORTURE_SSH_SERVER);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_KNOWNHOSTS, known_hosts_file);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
    free(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_connect(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_is_server_known(session);
Packit Service 31306d
    assert_int_equal(rc, SSH_SERVER_KNOWN_OK);
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
static void torture_knownhosts_standard_port(void **state)
Packit Service 31306d
{
Packit Service 31306d
    struct torture_state *s = *state;
Packit Service 31306d
    ssh_session session = s->ssh.session;
Packit Service 31306d
    char tmp_file[1024] = {0};
Packit Service 31306d
    char *known_hosts_file = NULL;
Packit Service 31306d
    const char *key = NULL;
Packit Service 31306d
    FILE *file;
Packit Service 31306d
    int rc;
Packit Service 31306d
Packit Service 31306d
    snprintf(tmp_file,
Packit Service 31306d
             sizeof(tmp_file),
Packit Service 31306d
             "%s/%s",
Packit Service 31306d
             s->socket_dir,
Packit Service 31306d
             TMP_FILE_TEMPLATE);
Packit Service 31306d
Packit Service 31306d
    known_hosts_file = torture_create_temp_file(tmp_file);
Packit Service 31306d
    assert_non_null(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    file = fopen(known_hosts_file, "w");
Packit Service 31306d
    assert_non_null(file);
Packit Service 31306d
    key = torture_get_testkey_pub(SSH_KEYTYPE_RSA);
Packit Service 31306d
    fprintf(file, "[127.0.0.10]:22 %s\n", key);
Packit Service 31306d
    fclose(file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_HOST, TORTURE_SSH_SERVER);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_KNOWNHOSTS, known_hosts_file);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
    free(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_connect(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_is_server_known(session);
Packit Service 31306d
    assert_int_equal(rc, SSH_SERVER_KNOWN_OK);
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
static void torture_knownhosts_fail(void **state) {
Packit Service 31306d
    struct torture_state *s = *state;
Packit Service 31306d
    ssh_session session = s->ssh.session;
Packit Service 31306d
    char tmp_file[1024] = {0};
Packit Service 31306d
    char *known_hosts_file = NULL;
Packit Service 31306d
    FILE *file;
Packit Service 31306d
    int rc;
Packit Service 31306d
Packit Service 31306d
    snprintf(tmp_file,
Packit Service 31306d
             sizeof(tmp_file),
Packit Service 31306d
             "%s/%s",
Packit Service 31306d
             s->socket_dir,
Packit Service 31306d
             TMP_FILE_TEMPLATE);
Packit Service 31306d
Packit Service 31306d
    known_hosts_file = torture_create_temp_file(tmp_file);
Packit Service 31306d
    assert_non_null(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_KNOWNHOSTS, known_hosts_file);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_HOSTKEYS, "rsa-sha2-256");
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    file = fopen(known_hosts_file, "w");
Packit Service 31306d
    assert_non_null(file);
Packit Service 31306d
    free(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    fprintf(file, "127.0.0.10 ssh-rsa %s\n", BADRSA);
Packit Service 31306d
    fclose(file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_connect(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_is_server_known(session);
Packit Service 31306d
    assert_int_equal(rc, SSH_SERVER_KNOWN_CHANGED);
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
static void torture_knownhosts_other(void **state) {
Packit Service 31306d
    struct torture_state *s = *state;
Packit Service 31306d
    ssh_session session = s->ssh.session;
Packit Service 31306d
    char tmp_file[1024] = {0};
Packit Service 31306d
    char *known_hosts_file = NULL;
Packit Service 31306d
    FILE *file;
Packit Service 31306d
    int rc;
Packit Service 31306d
Packit Service 31306d
    snprintf(tmp_file,
Packit Service 31306d
             sizeof(tmp_file),
Packit Service 31306d
             "%s/%s",
Packit Service 31306d
             s->socket_dir,
Packit Service 31306d
             TMP_FILE_TEMPLATE);
Packit Service 31306d
Packit Service 31306d
    known_hosts_file = torture_create_temp_file(tmp_file);
Packit Service 31306d
    assert_non_null(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_KNOWNHOSTS, known_hosts_file);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_HOSTKEYS, "ecdsa-sha2-nistp521");
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    file = fopen(known_hosts_file, "w");
Packit Service 31306d
    assert_non_null(file);
Packit Service 31306d
    free(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    fprintf(file, "127.0.0.10 ssh-rsa %s\n", BADRSA);
Packit Service 31306d
    fclose(file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_connect(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_is_server_known(session);
Packit Service 31306d
    assert_int_equal(rc, SSH_SERVER_FOUND_OTHER);
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
static void torture_knownhosts_other_auto(void **state) {
Packit Service 31306d
    struct torture_state *s = *state;
Packit Service 31306d
    ssh_session session = s->ssh.session;
Packit Service 31306d
    char tmp_file[1024] = {0};
Packit Service 31306d
    char *known_hosts_file = NULL;
Packit Service 31306d
    int rc;
Packit Service b92011
    bool process_config = false;
Packit Service 31306d
Packit Service 31306d
    snprintf(tmp_file,
Packit Service 31306d
             sizeof(tmp_file),
Packit Service 31306d
             "%s/%s",
Packit Service 31306d
             s->socket_dir,
Packit Service 31306d
             TMP_FILE_TEMPLATE);
Packit Service 31306d
Packit Service 31306d
    known_hosts_file = torture_create_temp_file(tmp_file);
Packit Service 31306d
    assert_non_null(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_HOST, TORTURE_SSH_SERVER);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_KNOWNHOSTS, known_hosts_file);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_HOSTKEYS, "ecdsa-sha2-nistp521");
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_connect(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_is_server_known(session);
Packit Service 31306d
    assert_int_equal(rc, SSH_SERVER_NOT_KNOWN);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_write_knownhost(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    ssh_disconnect(session);
Packit Service 31306d
    ssh_free(session);
Packit Service 31306d
Packit Service 31306d
    /* connect again and check host key */
Packit Service 31306d
    session = ssh_new();
Packit Service 31306d
    assert_non_null(session);
Packit Service 31306d
Packit Service 31306d
    s->ssh.session = session;
Packit Service 31306d
Packit Service b92011
    rc = ssh_options_set(session, SSH_OPTIONS_PROCESS_CONFIG, &process_config);
Packit Service b92011
    assert_ssh_return_code(session, rc);
Packit Service b92011
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_HOST, TORTURE_SSH_SERVER);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_KNOWNHOSTS, known_hosts_file);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_connect(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    /* ssh-rsa is the default but libssh should try ssh-ed25519 instead */
Packit Service 31306d
    rc = ssh_is_server_known(session);
Packit Service 31306d
    assert_int_equal(rc, SSH_SERVER_KNOWN_OK);
Packit Service 31306d
Packit Service 31306d
    /* session will be freed by session_teardown() */
Packit Service 31306d
    free(known_hosts_file);
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
static void torture_knownhosts_conflict(void **state) {
Packit Service 31306d
    struct torture_state *s = *state;
Packit Service 31306d
    ssh_session session = s->ssh.session;
Packit Service 31306d
    char tmp_file[1024] = {0};
Packit Service 31306d
    char *known_hosts_file = NULL;
Packit Service 31306d
    FILE *file;
Packit Service 31306d
    int rc;
Packit Service b92011
    bool process_config = false;
Packit Service 31306d
Packit Service 31306d
    snprintf(tmp_file,
Packit Service 31306d
             sizeof(tmp_file),
Packit Service 31306d
             "%s/%s",
Packit Service 31306d
             s->socket_dir,
Packit Service 31306d
             TMP_FILE_TEMPLATE);
Packit Service 31306d
Packit Service 31306d
    known_hosts_file = torture_create_temp_file(tmp_file);
Packit Service 31306d
    assert_non_null(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_HOST, TORTURE_SSH_SERVER);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_KNOWNHOSTS, known_hosts_file);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_HOSTKEYS, "rsa-sha2-256");
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    file = fopen(known_hosts_file, "w");
Packit Service 31306d
    assert_non_null(file);
Packit Service 31306d
    fprintf(file, "127.0.0.10 ssh-rsa %s\n", BADRSA);
Packit Service 31306d
    fprintf(file, "127.0.0.10 ssh-ed25519 %s\n", BADED25519);
Packit Service 31306d
    fclose(file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_connect(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_is_server_known(session);
Packit Service 31306d
    assert_int_equal(rc, SSH_SERVER_KNOWN_CHANGED);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_write_knownhost(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    ssh_disconnect(session);
Packit Service 31306d
    ssh_free(session);
Packit Service 31306d
Packit Service 31306d
    /* connect again and check host key */
Packit Service 31306d
    session = ssh_new();
Packit Service 31306d
    assert_non_null(session);
Packit Service 31306d
Packit Service 31306d
    s->ssh.session = session;
Packit Service 31306d
Packit Service b92011
    rc = ssh_options_set(session, SSH_OPTIONS_PROCESS_CONFIG, &process_config);
Packit Service b92011
    assert_ssh_return_code(session, rc);
Packit Service b92011
Packit Service 31306d
    ssh_options_set(session, SSH_OPTIONS_HOST, TORTURE_SSH_SERVER);
Packit Service 31306d
    ssh_options_set(session, SSH_OPTIONS_KNOWNHOSTS, known_hosts_file);
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_HOSTKEYS, "rsa-sha2-256");
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_connect(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_is_server_known(session);
Packit Service 31306d
    assert_int_equal(rc, SSH_SERVER_KNOWN_OK);
Packit Service 31306d
Packit Service 31306d
    /* session will be freed by session_teardown() */
Packit Service 31306d
    free(known_hosts_file);
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
static void torture_knownhosts_no_hostkeychecking(void **state)
Packit Service 31306d
{
Packit Service 31306d
Packit Service 31306d
    struct torture_state *s = *state;
Packit Service 31306d
    ssh_session session = s->ssh.session;
Packit Service 31306d
    char tmp_file[1024] = {0};
Packit Service 31306d
    char *known_hosts_file = NULL;
Packit Service 31306d
    enum ssh_known_hosts_e found;
Packit Service 31306d
    int strict_host_key_checking = 0;
Packit Service 31306d
    int rc;
Packit Service 31306d
Packit Service 31306d
    snprintf(tmp_file,
Packit Service 31306d
             sizeof(tmp_file),
Packit Service 31306d
             "%s/%s",
Packit Service 31306d
             s->socket_dir,
Packit Service 31306d
             TMP_FILE_TEMPLATE);
Packit Service 31306d
Packit Service 31306d
    known_hosts_file = torture_create_temp_file(tmp_file);
Packit Service 31306d
    assert_non_null(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_KNOWNHOSTS, known_hosts_file);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
    free(known_hosts_file);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_HOSTKEYS, "ecdsa-sha2-nistp521");
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_connect(session);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    found = ssh_session_is_known_server(session);
Packit Service 31306d
    assert_int_equal(found, SSH_KNOWN_HOSTS_UNKNOWN);
Packit Service 31306d
Packit Service 31306d
    rc = ssh_options_set(session, SSH_OPTIONS_STRICTHOSTKEYCHECK, &strict_host_key_checking);
Packit Service 31306d
    assert_ssh_return_code(session, rc);
Packit Service 31306d
Packit Service 31306d
    found = ssh_session_is_known_server(session);
Packit Service 31306d
    assert_int_equal(found, SSH_KNOWN_HOSTS_OK);
Packit Service 31306d
}
Packit Service 31306d
Packit Service 31306d
int torture_run_tests(void) {
Packit Service 31306d
    int rc;
Packit Service 31306d
    struct CMUnitTest tests[] = {
Packit Service 31306d
        cmocka_unit_test_setup_teardown(torture_knownhosts_wildcard,
Packit Service 31306d
                                        session_setup,
Packit Service 31306d
                                        session_teardown),
Packit Service 31306d
        cmocka_unit_test_setup_teardown(torture_knownhosts_standard_port,
Packit Service 31306d
                                        session_setup,
Packit Service 31306d
                                        session_teardown),
Packit Service 31306d
        cmocka_unit_test_setup_teardown(torture_knownhosts_port,
Packit Service 31306d
                                        session_setup,
Packit Service 31306d
                                        session_teardown),
Packit Service 31306d
        cmocka_unit_test_setup_teardown(torture_knownhosts_fail,
Packit Service 31306d
                                        session_setup,
Packit Service 31306d
                                        session_teardown),
Packit Service 31306d
        cmocka_unit_test_setup_teardown(torture_knownhosts_other,
Packit Service 31306d
                                        session_setup,
Packit Service 31306d
                                        session_teardown),
Packit Service 31306d
        cmocka_unit_test_setup_teardown(torture_knownhosts_other_auto,
Packit Service 31306d
                                        session_setup,
Packit Service 31306d
                                        session_teardown),
Packit Service 31306d
        cmocka_unit_test_setup_teardown(torture_knownhosts_conflict,
Packit Service 31306d
                                        session_setup,
Packit Service 31306d
                                        session_teardown),
Packit Service 31306d
        cmocka_unit_test_setup_teardown(torture_knownhosts_no_hostkeychecking,
Packit Service 31306d
                                        session_setup,
Packit Service 31306d
                                        session_teardown),
Packit Service 31306d
    };
Packit Service 31306d
Packit Service 31306d
    ssh_init();
Packit Service 31306d
Packit Service 31306d
    torture_filter_tests(tests);
Packit Service 31306d
    rc = cmocka_run_group_tests(tests, sshd_setup, sshd_teardown);
Packit Service 31306d
Packit Service 31306d
    ssh_finalize();
Packit Service 31306d
    return rc;
Packit Service 31306d
}