zero_length_keys.sh 3.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121
  1. #!/bin/sh
  2. # Check that tor regenerates keys when key files are zero-length
  3. # Test for bug #13111 - Tor fails to start if onion keys are zero length
  4. #
  5. # Usage:
  6. # ./zero_length_keys.sh
  7. # Run all the tests below
  8. # ./zero_length_keys.sh -z
  9. # Check tor will launch and regenerate zero-length keys
  10. # ./zero_length_keys.sh -d
  11. # Check tor regenerates deleted keys (existing behaviour)
  12. # ./zero_length_keys.sh -e
  13. # Check tor does not overwrite existing keys (existing behaviour)
  14. #
  15. # Exit Statuses:
  16. # 0: test succeeded - tor regenerated/kept the files
  17. # 1: test failed - tor did not regenerate/keep the files
  18. # 254: test failed - tor did not generate the key files on first run
  19. # 255: a command failed - the test could not be completed
  20. #
  21. if [ $# -lt 1 ]; then
  22. echo "Testing that tor correctly handles zero-length keys"
  23. "$0" -z && "$0" -d && "$0" -e
  24. exit $?
  25. fi
  26. DATA_DIR=`mktemp -d -t tor_zero_length_keys.XXXXXX`
  27. if [ -z "$DATA_DIR" ]; then
  28. echo "Failure: mktemp invocation returned empty string"
  29. exit 255
  30. fi
  31. trap "rm -rf '$DATA_DIR'" 0
  32. # DisableNetwork means that the ORPort won't actually be opened.
  33. # 'ExitRelay 0' suppresses a warning.
  34. TOR="./src/or/tor --hush --DisableNetwork 1 --ShutdownWaitLength 0 --ORPort 12345 --ExitRelay 0"
  35. if [ -s "$DATA_DIR"/keys/secret_id_key -a -s "$DATA_DIR"/keys/secret_onion_key -a -s "$DATA_DIR"/keys/secret_onion_key_ntor ]; then
  36. echo "Failure: Previous tor keys present in tor data directory"
  37. exit 255
  38. else
  39. echo "Generating initial tor keys"
  40. $TOR --DataDirectory "$DATA_DIR" --PidFile "$DATA_DIR"/pid &
  41. TOR_PID=$!
  42. # generate SIGTERM, hopefully after the keys have been regenerated
  43. sleep 5
  44. kill $TOR_PID
  45. wait $TOR_PID
  46. # tor must successfully generate non-zero-length key files
  47. if [ -s "$DATA_DIR"/keys/secret_id_key -a -s "$DATA_DIR"/keys/secret_onion_key -a -s "$DATA_DIR"/keys/secret_onion_key_ntor ]; then
  48. true #echo "tor generated the initial key files"
  49. else
  50. echo "Failure: tor failed to generate the initial key files"
  51. exit 254
  52. fi
  53. fi
  54. #ls -lh "$DATA_DIR"/keys/ || exit 255
  55. # backup and keep/delete/create zero-length files for the keys
  56. FILE_DESC="keeps existing"
  57. # make a backup
  58. cp -r "$DATA_DIR"/keys "$DATA_DIR"/keys.old
  59. # delete keys for -d or -z
  60. if [ "$1" != "-e" ]; then
  61. FILE_DESC="regenerates deleted"
  62. rm "$DATA_DIR"/keys/secret_id_key || exit 255
  63. rm "$DATA_DIR"/keys/secret_onion_key || exit 255
  64. rm "$DATA_DIR"/keys/secret_onion_key_ntor || exit 255
  65. fi
  66. # create empty files for -z
  67. if [ "$1" = "-z" ]; then
  68. FILE_DESC="regenerates zero-length"
  69. touch "$DATA_DIR"/keys/secret_id_key || exit 255
  70. touch "$DATA_DIR"/keys/secret_onion_key || exit 255
  71. touch "$DATA_DIR"/keys/secret_onion_key_ntor || exit 255
  72. fi
  73. echo "Running tor again to check if it $FILE_DESC keys"
  74. $TOR --DataDirectory "$DATA_DIR" --PidFile "$DATA_DIR"/pid &
  75. TOR_PID=$!
  76. # generate SIGTERM, hopefully after the keys have been regenerated
  77. sleep 5
  78. kill $TOR_PID
  79. wait $TOR_PID
  80. #ls -lh "$DATA_DIR"/keys/ || exit 255
  81. # tor must always have non-zero-length key files
  82. if [ -s "$DATA_DIR"/keys/secret_id_key -a -s "$DATA_DIR"/keys/secret_onion_key -a -s "$DATA_DIR"/keys/secret_onion_key_ntor ]; then
  83. # check if the keys are different to the old ones
  84. diff -q -r "$DATA_DIR"/keys "$DATA_DIR"/keys.old > /dev/null
  85. SAME_KEYS=$?
  86. # if we're not testing existing keys,
  87. # the current keys should be different to the old ones
  88. if [ "$1" != "-e" ]; then
  89. if [ $SAME_KEYS -ne 0 ]; then
  90. echo "Success: test that tor $FILE_DESC key files: different keys"
  91. exit 0
  92. else
  93. echo "Failure: test that tor $FILE_DESC key files: same keys"
  94. exit 1
  95. fi
  96. else #[ "$1" == "-e" ]; then
  97. if [ $SAME_KEYS -eq 0 ]; then
  98. echo "Success: test that tor $FILE_DESC key files: same keys"
  99. exit 0
  100. else
  101. echo "Failure: test that tor $FILE_DESC key files: different keys"
  102. exit 1
  103. fi
  104. fi
  105. else
  106. echo "Failure: test that tor $FILE_DESC key files: no key files"
  107. exit 1
  108. fi