Files
alknet/tasks/tls/tests.md
T
deepseek-v4-pro ae0a0d3985 chore: mark Phase 0 and Phase 1 tasks as completed
All six tasks are done:
- core/connection-credentials: ConnectionCredentials + RemoteIdentity in alknet-core
- tls/crate-init: alknet-tls crate skeleton with deps and feature flags
- tls/server-extract: server-side TLS code extracted into alknet-tls
- tls/client-extract: client-side TLS code extracted into alknet-tls
- tls/tests: 34 TLS tests moved and adapted into alknet-tls
- tls/review-tls: spec conformance review passed, all feature combos green
2026-07-17 10:10:59 +00:00

127 lines
7.7 KiB
Markdown

---
id: tls/tests
name: Move and adapt TLS tests from endpoint.rs and call_client.rs into alknet-tls
status: completed
depends_on: [tls/client-extract]
scope: moderate
risk: low
impact: component
level: implementation
---
## Description
Phase 1, Task 4 of the crate extraction. Move the TLS-related tests from
`crates/alknet-core/src/endpoint.rs` and `crates/alknet-call/src/client/call_client.rs`
into `crates/alknet-tls/`. Adapt them to test the new public API types
(`TlsServerConfig`, `TlsClientConfig`) instead of the old free functions.
The old tests **stay** in their original files (duplicated) — no breakage. The new
crate's tests are self-contained and pass standalone.
### Server-side tests to move (from `endpoint.rs`)
22 tests total. Move to `crates/alknet-tls/src/server.rs` `#[cfg(test)] mod tests`:
| Test | Line | What it tests |
|------|------|---------------|
| `raw_key_cert_resolver_only_raw_public_keys` | 1099 | `RawKeyCertResolver` trait impl |
| `self_signed_cert_generation_produces_cert_and_key` | 1204 | `generate_self_signed_cert` |
| `acme_directory_production_url` | 1255 | `AcmeDirectory::Production` URL |
| `acme_directory_staging_url` | 1262 | `AcmeDirectory::Staging` URL |
| `acme_directory_custom_url` | 1272 | `AcmeDirectory::Custom` URL |
| `tls_setup_x509_returns_no_acme_state` | 1280 | `TlsSetup::new` with X509 |
| `build_rustls_server_config_raw_key_succeeds` | 1368 | `build_rustls_server_config` RawKey |
| `build_rustls_server_config_self_signed_succeeds` | 1379 | `build_rustls_server_config` SelfSigned |
| `build_rustls_server_config_acme_is_unreachable` | 1391 | ACME guard in `build_rustls_server_config` |
| `build_quinn_server_config_from_rustls_succeeds` | 1403 | `build_quinn_server_config_from_rustls` |
| `load_private_key_returns_error_when_no_key_present` | 1415 | `load_private_key` error path |
| `load_private_key_returns_error_when_file_missing` | 1428 | `load_private_key` missing file |
| `load_cert_chain_returns_error_when_file_missing` | 1440 | `load_cert_chain` missing file |
| `accept_any_cert_verifier_offers_and_does_not_require_client_auth` | 1454 | `AcceptAnyCertVerifier` trait |
| `accept_any_cert_verifier_verifies_any_client_cert` | 1464 | `AcceptAnyCertVerifier` verify |
| `accept_any_cert_verifier_supported_schemes_are_non_empty` | 1478 | `AcceptAnyCertVerifier` schemes |
| `accept_any_cert_verifier_debug_is_implemented` | 1489 | `AcceptAnyCertVerifier` Debug |
| `ed25519_signing_key_choose_scheme_returns_some_for_ed25519` | 1499 | `Ed25519SigningKey` choose_scheme |
| `ed25519_signing_key_choose_scheme_returns_none_without_ed25519` | 1512 | `Ed25519SigningKey` no ED25519 |
| `ed25519_signing_key_algorithm_is_ed25519` | 1525 | `Ed25519SigningKey` algorithm |
| `ed25519_signing_key_public_key_returns_spki` | 1534 | `Ed25519SigningKey` public_key |
| `ed25519_signing_key_signer_signs_message` | 1545 | `Ed25519SigningKey` sign |
| `ed25519_signing_key_debug_does_not_leak_material` | 1560 | `Ed25519SigningKey` Debug |
| `raw_key_cert_resolver_debug_is_implemented` | 1569 | `RawKeyCertResolver` Debug |
### Client-side tests to move (from `call_client.rs`)
10 tests total. Move to `crates/alknet-tls/src/client.rs` `#[cfg(test)] mod tests`:
| Test | Line | What it tests | Adaptation |
|------|------|---------------|------------|
| `fingerprint_pin_verifier_matches_correct_ed25519_fingerprint` | 750 | verifier accept | Test via `FingerprintPinVerifier` directly (no change needed) |
| `fingerprint_pin_verifier_rejects_wrong_ed25519_fingerprint` | 769 | verifier reject | Same |
| `fingerprint_pin_verifier_matches_correct_sha256_fingerprint` | 789 | verifier X.509 accept | Same |
| `fingerprint_pin_verifier_rejects_wrong_sha256_fingerprint` | 806 | verifier X.509 reject | Same |
| `select_server_verifier_returns_ca_verifier_for_none` | 822 | CA path | Test via `TlsClientConfig::new` or keep as unit test of internal fn |
| `select_server_verifier_returns_fingerprint_pin_for_some` | 839 | pin path | Same |
| `build_client_auth_presents_ed25519_raw_key_without_error` | 857 | client cert resolver | Test via `TlsClientConfig::new` or keep as unit test |
| `build_client_auth_none_resolves_to_no_client_cert` | 879 | no-cert resolver | Same |
| `build_quinn_client_config_with_raw_key_identity_builds_without_error` | 893 | full config build | Adapt to test `TlsClientConfig::new` + `for_quinn()` |
| `build_quinn_client_config_with_no_remote_identity_builds_without_error` | 909 | CA-verify config | Adapt to test `TlsClientConfig::new` + `for_quinn()` |
### Test adaptations
1. **Imports**: Update to use `alknet_tls::*` types, `alknet_core::config::*`, etc.
2. **Server tests**: Most server-side tests test free functions directly — they can stay
as unit tests of the internal functions, or be adapted to test through `TlsServerConfig::new()`.
The `tls_setup_x509_returns_no_acme_state` test should go through `TlsServerConfig::new()`.
3. **Client tests**: The `build_quinn_client_config_*` tests should be adapted to test
`TlsClientConfig::new(credentials, alpn)?.for_quinn()` instead of the free function.
The verifier and client-auth tests can stay as unit tests of the internal functions.
4. **`Ed25519SigningKey` tests**: Move to `crates/alknet-tls/src/signing.rs` `#[cfg(test)] mod tests`.
5. **`load_cert_chain` / `load_private_key` tests**: Move to `crates/alknet-tls/src/pem.rs` `#[cfg(test)] mod tests`.
6. **Test helpers**: The `build_ed25519_spki_der`, `build_x509_cert_der`, `aws_lc_rs_provider`,
`verify_pin` helpers from `call_client.rs` tests should move with the tests that use them.
7. **Feature gates**: All quinn-dependent tests need `#[cfg(feature = "quinn")]`. The
`acme_directory_*` tests don't need quinn. The `ed25519_signing_key_*` tests need quinn
(they use `rustls::sign::SigningKey`).
### What stays in the original files
The old tests in `endpoint.rs` and `call_client.rs` are **not deleted** — they stay as
duplicates. The prune happens in Phase 4 (core) and Phase 5 (call). This task only adds
tests to `alknet-tls`.
## Acceptance Criteria
- [ ] All 22 server-side TLS tests moved to `alknet-tls/src/server.rs` and pass
- [ ] All 10 client-side TLS tests moved to `alknet-tls/src/client.rs` and pass
- [ ] `Ed25519SigningKey` tests (6) moved to `alknet-tls/src/signing.rs` and pass
- [ ] `load_cert_chain` / `load_private_key` tests (3) moved to `alknet-tls/src/pem.rs` and pass
- [ ] `build_quinn_client_config_*` tests adapted to use `TlsClientConfig::new().for_quinn()`
- [ ] `tls_setup_x509_returns_no_acme_state` adapted to use `TlsServerConfig::new()`
- [ ] All test helpers (`build_ed25519_spki_der`, `build_x509_cert_der`, `aws_lc_rs_provider`, `verify_pin`) moved with their tests
- [ ] Feature gates correct on all moved tests
- [ ] `cargo test -p alknet-tls` passes (all feature combos)
- [ ] `cargo test -p alknet-core` still passes (old tests untouched)
- [ ] `cargo test -p alknet-call` still passes (old tests untouched)
- [ ] `cargo clippy -p alknet-tls --all-targets` succeeds with no warnings
## References
- docs/research/alknet-crate-extraction/findings.md — Phase 1, test lists
- crates/alknet-core/src/endpoint.rs — lines 935-1606 (server-side tests)
- crates/alknet-call/src/client/call_client.rs — lines 569-930 (client-side tests)
## Notes
> This is the test migration task — 32 tests total (22 server + 10 client).
> The tests are well-understood and mostly need import updates. The
> `build_quinn_client_config_*` tests need the most adaptation (testing through
> `TlsClientConfig` instead of the free function). The old tests stay in their
> original files — the prune happens in Phases 4-5. Test helpers that are shared
> between multiple test functions should move to a `#[cfg(test)]` module in the
> same file.
## Summary
> To be filled on completion