Files
petrbalvin a9b8039ef7
Test / test (push) Successful in 2m4s
Release / gates (push) Successful in 2m5s
Release / build (amd64, freebsd) (push) Successful in 1m27s
Release / build (amd64, linux) (push) Successful in 1m22s
Release / build (amd64, netbsd) (push) Successful in 1m19s
Release / build (amd64, openbsd) (push) Successful in 1m20s
Release / build (arm64, darwin) (push) Successful in 1m21s
Release / build (arm64, freebsd) (push) Successful in 1m26s
Release / build (arm64, linux) (push) Successful in 1m25s
Release / build (arm64, netbsd) (push) Successful in 1m31s
Release / build (arm64, openbsd) (push) Successful in 1m27s
Release / build (loong64, linux) (push) Successful in 1m37s
Release / build (riscv64, linux) (push) Successful in 1m21s
Release / release (push) Successful in 40s
feat: full NFSv4.2 server and client in pure Go
Assisted-by: GLM 5.3 Flash
2026-09-21 18:51:17 +02:00

60 lines
1.7 KiB
Go

// Copyright (c) 2026 Petr Balvín <opensource@petrbalvin.org> (https://petrbalvin.org)
// SPDX-License-Identifier: MIT
package krb5
import (
"bytes"
"testing"
)
// The AP-REP the acceptor answers with completes the client half of the
// context: it verifies under the session key, and nothing else does.
func TestClientAcceptRepRoundTrip(t *testing.T) {
key := make([]byte, 32)
for i := range key {
key[i] = byte(i + 1)
}
client, token, err := ClientInit(EtypeAES256, key, "EXAMPLE.ORG", "nfs", "client")
if err != nil {
t.Fatal(err)
}
acceptor, aprep, err := AcceptInit(token, key)
if err != nil {
t.Fatal(err)
}
_ = acceptor
if err := client.ClientAcceptRep(aprep); err != nil {
t.Fatalf("accept rep: %v", err)
}
// The shared key makes both halves sign tokens the other verifies.
mic, err := client.GetMIC([]byte("data"))
if err != nil {
t.Fatal(err)
}
if err := acceptor.VerifyMIC([]byte("data"), mic); err != nil {
t.Fatalf("cross verify: %v", err)
}
// Anything but the genuine AP-REP is refused: a wrong tag, a wrong
// message type, a body from another key.
if err := client.ClientAcceptRep([]byte{0x6e, 0x00}); err == nil {
t.Fatal("a two byte token accepted")
}
tampered := append([]byte{}, aprep...)
tampered[len(tampered)-1] ^= 1
if err := client.ClientAcceptRep(tampered); err == nil {
t.Fatal("a tampered AP-REP accepted")
}
other, otoken, err := ClientInit(EtypeAES256, key, "EXAMPLE.ORG", "nfs", "other")
if err != nil {
t.Fatal(err)
}
if err := other.ClientAcceptRep(aprep); err == nil {
t.Fatal("an AP-REP of another context accepted")
}
if bytes.Equal(otoken, token) {
t.Fatal("two inits minted the same token")
}
}