xref: /aosp_15_r20/hardware/interfaces/gatekeeper/aidl/vts/functional/VtsHalGatekeeperTargetTest.cpp (revision 4d7e907c777eeecc4c5bd7cf640a754fac206ff7)
1*4d7e907cSAndroid Build Coastguard Worker /*
2*4d7e907cSAndroid Build Coastguard Worker  * Copyright (C) 2022 The Android Open Source Project
3*4d7e907cSAndroid Build Coastguard Worker  *
4*4d7e907cSAndroid Build Coastguard Worker  * Licensed under the Apache License, Version 2.0 (the "License");
5*4d7e907cSAndroid Build Coastguard Worker  * you may not use this file except in compliance with the License.
6*4d7e907cSAndroid Build Coastguard Worker  * You may obtain a copy of the License at
7*4d7e907cSAndroid Build Coastguard Worker  *
8*4d7e907cSAndroid Build Coastguard Worker  *      http://www.apache.org/licenses/LICENSE-2.0
9*4d7e907cSAndroid Build Coastguard Worker  *
10*4d7e907cSAndroid Build Coastguard Worker  * Unless required by applicable law or agreed to in writing, software
11*4d7e907cSAndroid Build Coastguard Worker  * distributed under the License is distributed on an "AS IS" BASIS,
12*4d7e907cSAndroid Build Coastguard Worker  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13*4d7e907cSAndroid Build Coastguard Worker  * See the License for the specific language governing permissions and
14*4d7e907cSAndroid Build Coastguard Worker  * limitations under the License.
15*4d7e907cSAndroid Build Coastguard Worker  */
16*4d7e907cSAndroid Build Coastguard Worker 
17*4d7e907cSAndroid Build Coastguard Worker #define LOG_TAG "gatekeeper_aidl_hal_test"
18*4d7e907cSAndroid Build Coastguard Worker 
19*4d7e907cSAndroid Build Coastguard Worker #include <inttypes.h>
20*4d7e907cSAndroid Build Coastguard Worker #include <unistd.h>
21*4d7e907cSAndroid Build Coastguard Worker 
22*4d7e907cSAndroid Build Coastguard Worker #include <algorithm>
23*4d7e907cSAndroid Build Coastguard Worker #include <cmath>
24*4d7e907cSAndroid Build Coastguard Worker #include <string>
25*4d7e907cSAndroid Build Coastguard Worker #include <vector>
26*4d7e907cSAndroid Build Coastguard Worker 
27*4d7e907cSAndroid Build Coastguard Worker #include <aidl/Gtest.h>
28*4d7e907cSAndroid Build Coastguard Worker #include <aidl/Vintf.h>
29*4d7e907cSAndroid Build Coastguard Worker #include <aidl/android/hardware/gatekeeper/GatekeeperEnrollResponse.h>
30*4d7e907cSAndroid Build Coastguard Worker #include <aidl/android/hardware/gatekeeper/GatekeeperVerifyResponse.h>
31*4d7e907cSAndroid Build Coastguard Worker #include <aidl/android/hardware/gatekeeper/IGatekeeper.h>
32*4d7e907cSAndroid Build Coastguard Worker #include <aidl/android/hardware/security/keymint/HardwareAuthToken.h>
33*4d7e907cSAndroid Build Coastguard Worker #include <android-base/endian.h>
34*4d7e907cSAndroid Build Coastguard Worker #include <android/binder_manager.h>
35*4d7e907cSAndroid Build Coastguard Worker #include <android/binder_process.h>
36*4d7e907cSAndroid Build Coastguard Worker #include <hardware/hw_auth_token.h>
37*4d7e907cSAndroid Build Coastguard Worker 
38*4d7e907cSAndroid Build Coastguard Worker #include <log/log.h>
39*4d7e907cSAndroid Build Coastguard Worker 
40*4d7e907cSAndroid Build Coastguard Worker using aidl::android::hardware::gatekeeper::GatekeeperEnrollResponse;
41*4d7e907cSAndroid Build Coastguard Worker using aidl::android::hardware::gatekeeper::GatekeeperVerifyResponse;
42*4d7e907cSAndroid Build Coastguard Worker using aidl::android::hardware::gatekeeper::IGatekeeper;
43*4d7e907cSAndroid Build Coastguard Worker using aidl::android::hardware::security::keymint::HardwareAuthToken;
44*4d7e907cSAndroid Build Coastguard Worker using Status = ::ndk::ScopedAStatus;
45*4d7e907cSAndroid Build Coastguard Worker 
46*4d7e907cSAndroid Build Coastguard Worker struct GatekeeperRequest {
47*4d7e907cSAndroid Build Coastguard Worker     uint32_t uid;
48*4d7e907cSAndroid Build Coastguard Worker     uint64_t challenge;
49*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> curPwdHandle;
50*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> curPwd;
51*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> newPwd;
GatekeeperRequestGatekeeperRequest52*4d7e907cSAndroid Build Coastguard Worker     GatekeeperRequest() : uid(0), challenge(0) {}
53*4d7e907cSAndroid Build Coastguard Worker };
54*4d7e907cSAndroid Build Coastguard Worker 
55*4d7e907cSAndroid Build Coastguard Worker // ASSERT_* macros generate return "void" internally
56*4d7e907cSAndroid Build Coastguard Worker // we have to use EXPECT_* if we return anything but "void"
verifyAuthToken(GatekeeperVerifyResponse & rsp)57*4d7e907cSAndroid Build Coastguard Worker static void verifyAuthToken(GatekeeperVerifyResponse& rsp) {
58*4d7e907cSAndroid Build Coastguard Worker     uint32_t auth_type = static_cast<uint32_t>(rsp.hardwareAuthToken.authenticatorType);
59*4d7e907cSAndroid Build Coastguard Worker     uint64_t auth_tstamp = static_cast<uint64_t>(rsp.hardwareAuthToken.timestamp.milliSeconds);
60*4d7e907cSAndroid Build Coastguard Worker 
61*4d7e907cSAndroid Build Coastguard Worker     EXPECT_EQ(HW_AUTH_PASSWORD, auth_type);
62*4d7e907cSAndroid Build Coastguard Worker     EXPECT_NE(UINT64_C(~0), auth_tstamp);
63*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Authenticator ID: %016" PRIX64, rsp.hardwareAuthToken.authenticatorId);
64*4d7e907cSAndroid Build Coastguard Worker     EXPECT_NE(UINT32_C(0), rsp.hardwareAuthToken.userId);
65*4d7e907cSAndroid Build Coastguard Worker }
66*4d7e907cSAndroid Build Coastguard Worker 
67*4d7e907cSAndroid Build Coastguard Worker // The main test class for Gatekeeper AIDL HAL.
68*4d7e907cSAndroid Build Coastguard Worker class GatekeeperAidlTest : public ::testing::TestWithParam<std::string> {
69*4d7e907cSAndroid Build Coastguard Worker   protected:
setUid(uint32_t uid)70*4d7e907cSAndroid Build Coastguard Worker     void setUid(uint32_t uid) { uid_ = uid; }
71*4d7e907cSAndroid Build Coastguard Worker 
doEnroll(GatekeeperRequest & req,GatekeeperEnrollResponse & rsp)72*4d7e907cSAndroid Build Coastguard Worker     Status doEnroll(GatekeeperRequest& req, GatekeeperEnrollResponse& rsp) {
73*4d7e907cSAndroid Build Coastguard Worker         Status ret;
74*4d7e907cSAndroid Build Coastguard Worker         while (true) {
75*4d7e907cSAndroid Build Coastguard Worker             ret = gatekeeper_->enroll(uid_, req.curPwdHandle, req.curPwd, req.newPwd, &rsp);
76*4d7e907cSAndroid Build Coastguard Worker             if (ret.isOk()) break;
77*4d7e907cSAndroid Build Coastguard Worker             if (getReturnStatusCode(ret) != IGatekeeper::ERROR_RETRY_TIMEOUT) break;
78*4d7e907cSAndroid Build Coastguard Worker             ALOGI("%s: got retry code; retrying in 1 sec", __func__);
79*4d7e907cSAndroid Build Coastguard Worker             sleep(1);
80*4d7e907cSAndroid Build Coastguard Worker         }
81*4d7e907cSAndroid Build Coastguard Worker         return ret;
82*4d7e907cSAndroid Build Coastguard Worker     }
83*4d7e907cSAndroid Build Coastguard Worker 
doVerify(GatekeeperRequest & req,GatekeeperVerifyResponse & rsp)84*4d7e907cSAndroid Build Coastguard Worker     Status doVerify(GatekeeperRequest& req, GatekeeperVerifyResponse& rsp) {
85*4d7e907cSAndroid Build Coastguard Worker         Status ret;
86*4d7e907cSAndroid Build Coastguard Worker         while (true) {
87*4d7e907cSAndroid Build Coastguard Worker             ret = gatekeeper_->verify(uid_, req.challenge, req.curPwdHandle, req.newPwd, &rsp);
88*4d7e907cSAndroid Build Coastguard Worker             if (ret.isOk()) break;
89*4d7e907cSAndroid Build Coastguard Worker             if (getReturnStatusCode(ret) != IGatekeeper::ERROR_RETRY_TIMEOUT) break;
90*4d7e907cSAndroid Build Coastguard Worker             ALOGI("%s: got retry code; retrying in 1 sec", __func__);
91*4d7e907cSAndroid Build Coastguard Worker             sleep(1);
92*4d7e907cSAndroid Build Coastguard Worker         }
93*4d7e907cSAndroid Build Coastguard Worker         return ret;
94*4d7e907cSAndroid Build Coastguard Worker     }
95*4d7e907cSAndroid Build Coastguard Worker 
doDeleteUser()96*4d7e907cSAndroid Build Coastguard Worker     Status doDeleteUser() { return gatekeeper_->deleteUser(uid_); }
97*4d7e907cSAndroid Build Coastguard Worker 
doDeleteAllUsers()98*4d7e907cSAndroid Build Coastguard Worker     Status doDeleteAllUsers() { return gatekeeper_->deleteAllUsers(); }
99*4d7e907cSAndroid Build Coastguard Worker 
generatePassword(std::vector<uint8_t> & password,uint8_t seed)100*4d7e907cSAndroid Build Coastguard Worker     void generatePassword(std::vector<uint8_t>& password, uint8_t seed) {
101*4d7e907cSAndroid Build Coastguard Worker         password.resize(16);
102*4d7e907cSAndroid Build Coastguard Worker         memset(password.data(), seed, password.size());
103*4d7e907cSAndroid Build Coastguard Worker     }
104*4d7e907cSAndroid Build Coastguard Worker 
checkEnroll(GatekeeperEnrollResponse & rsp,Status & ret,bool expectSuccess)105*4d7e907cSAndroid Build Coastguard Worker     void checkEnroll(GatekeeperEnrollResponse& rsp, Status& ret, bool expectSuccess) {
106*4d7e907cSAndroid Build Coastguard Worker         if (expectSuccess) {
107*4d7e907cSAndroid Build Coastguard Worker             EXPECT_TRUE(ret.isOk());
108*4d7e907cSAndroid Build Coastguard Worker             EXPECT_EQ(IGatekeeper::STATUS_OK, rsp.statusCode);
109*4d7e907cSAndroid Build Coastguard Worker             EXPECT_NE(nullptr, rsp.data.data());
110*4d7e907cSAndroid Build Coastguard Worker             EXPECT_GT(rsp.data.size(), UINT32_C(0));
111*4d7e907cSAndroid Build Coastguard Worker             EXPECT_NE(UINT32_C(0), rsp.secureUserId);
112*4d7e907cSAndroid Build Coastguard Worker         } else {
113*4d7e907cSAndroid Build Coastguard Worker             EXPECT_EQ(IGatekeeper::ERROR_GENERAL_FAILURE, getReturnStatusCode(ret));
114*4d7e907cSAndroid Build Coastguard Worker             EXPECT_EQ(UINT32_C(0), rsp.data.size());
115*4d7e907cSAndroid Build Coastguard Worker         }
116*4d7e907cSAndroid Build Coastguard Worker     }
117*4d7e907cSAndroid Build Coastguard Worker 
checkVerify(GatekeeperVerifyResponse & rsp,Status & ret,uint64_t challenge,bool expectSuccess)118*4d7e907cSAndroid Build Coastguard Worker     void checkVerify(GatekeeperVerifyResponse& rsp, Status& ret, uint64_t challenge,
119*4d7e907cSAndroid Build Coastguard Worker                      bool expectSuccess) {
120*4d7e907cSAndroid Build Coastguard Worker         if (expectSuccess) {
121*4d7e907cSAndroid Build Coastguard Worker             EXPECT_TRUE(ret.isOk());
122*4d7e907cSAndroid Build Coastguard Worker             EXPECT_GE(rsp.statusCode, IGatekeeper::STATUS_OK);
123*4d7e907cSAndroid Build Coastguard Worker             EXPECT_LE(rsp.statusCode, IGatekeeper::STATUS_REENROLL);
124*4d7e907cSAndroid Build Coastguard Worker 
125*4d7e907cSAndroid Build Coastguard Worker             verifyAuthToken(rsp);
126*4d7e907cSAndroid Build Coastguard Worker             EXPECT_EQ(challenge, rsp.hardwareAuthToken.challenge);
127*4d7e907cSAndroid Build Coastguard Worker         } else {
128*4d7e907cSAndroid Build Coastguard Worker             EXPECT_EQ(IGatekeeper::ERROR_GENERAL_FAILURE, getReturnStatusCode(ret));
129*4d7e907cSAndroid Build Coastguard Worker         }
130*4d7e907cSAndroid Build Coastguard Worker     }
131*4d7e907cSAndroid Build Coastguard Worker 
enrollNewPassword(std::vector<uint8_t> & password,GatekeeperEnrollResponse & rsp,bool expectSuccess)132*4d7e907cSAndroid Build Coastguard Worker     void enrollNewPassword(std::vector<uint8_t>& password, GatekeeperEnrollResponse& rsp,
133*4d7e907cSAndroid Build Coastguard Worker                            bool expectSuccess) {
134*4d7e907cSAndroid Build Coastguard Worker         GatekeeperRequest req;
135*4d7e907cSAndroid Build Coastguard Worker         req.newPwd = password;
136*4d7e907cSAndroid Build Coastguard Worker         Status ret = doEnroll(req, rsp);
137*4d7e907cSAndroid Build Coastguard Worker         checkEnroll(rsp, ret, expectSuccess);
138*4d7e907cSAndroid Build Coastguard Worker     }
139*4d7e907cSAndroid Build Coastguard Worker 
verifyPassword(std::vector<uint8_t> & password,std::vector<uint8_t> & passwordHandle,uint64_t challenge,GatekeeperVerifyResponse & verifyRsp,bool expectSuccess)140*4d7e907cSAndroid Build Coastguard Worker     void verifyPassword(std::vector<uint8_t>& password, std::vector<uint8_t>& passwordHandle,
141*4d7e907cSAndroid Build Coastguard Worker                         uint64_t challenge, GatekeeperVerifyResponse& verifyRsp,
142*4d7e907cSAndroid Build Coastguard Worker                         bool expectSuccess) {
143*4d7e907cSAndroid Build Coastguard Worker         GatekeeperRequest verifyReq;
144*4d7e907cSAndroid Build Coastguard Worker 
145*4d7e907cSAndroid Build Coastguard Worker         // build verify request for the same password (we want it to succeed)
146*4d7e907cSAndroid Build Coastguard Worker         verifyReq.newPwd = password;
147*4d7e907cSAndroid Build Coastguard Worker         // use enrolled password handle we've got
148*4d7e907cSAndroid Build Coastguard Worker         verifyReq.curPwdHandle = passwordHandle;
149*4d7e907cSAndroid Build Coastguard Worker         verifyReq.challenge = challenge;
150*4d7e907cSAndroid Build Coastguard Worker         Status ret = doVerify(verifyReq, verifyRsp);
151*4d7e907cSAndroid Build Coastguard Worker         checkVerify(verifyRsp, ret, challenge, expectSuccess);
152*4d7e907cSAndroid Build Coastguard Worker     }
153*4d7e907cSAndroid Build Coastguard Worker 
getReturnStatusCode(const Status & result)154*4d7e907cSAndroid Build Coastguard Worker     int32_t getReturnStatusCode(const Status& result) {
155*4d7e907cSAndroid Build Coastguard Worker         if (!result.isOk()) {
156*4d7e907cSAndroid Build Coastguard Worker             if (result.getExceptionCode() == EX_SERVICE_SPECIFIC) {
157*4d7e907cSAndroid Build Coastguard Worker                 return result.getServiceSpecificError();
158*4d7e907cSAndroid Build Coastguard Worker             }
159*4d7e907cSAndroid Build Coastguard Worker             return IGatekeeper::ERROR_GENERAL_FAILURE;
160*4d7e907cSAndroid Build Coastguard Worker         }
161*4d7e907cSAndroid Build Coastguard Worker         return IGatekeeper::STATUS_OK;
162*4d7e907cSAndroid Build Coastguard Worker     }
163*4d7e907cSAndroid Build Coastguard Worker 
164*4d7e907cSAndroid Build Coastguard Worker   protected:
165*4d7e907cSAndroid Build Coastguard Worker     std::shared_ptr<IGatekeeper> gatekeeper_;
166*4d7e907cSAndroid Build Coastguard Worker     uint32_t uid_;
167*4d7e907cSAndroid Build Coastguard Worker 
168*4d7e907cSAndroid Build Coastguard Worker   public:
GatekeeperAidlTest()169*4d7e907cSAndroid Build Coastguard Worker     GatekeeperAidlTest() : uid_(0) {}
SetUp()170*4d7e907cSAndroid Build Coastguard Worker     virtual void SetUp() override {
171*4d7e907cSAndroid Build Coastguard Worker         gatekeeper_ = IGatekeeper::fromBinder(
172*4d7e907cSAndroid Build Coastguard Worker             ndk::SpAIBinder(AServiceManager_waitForService(GetParam().c_str())));
173*4d7e907cSAndroid Build Coastguard Worker         ASSERT_NE(nullptr, gatekeeper_.get());
174*4d7e907cSAndroid Build Coastguard Worker         doDeleteAllUsers();
175*4d7e907cSAndroid Build Coastguard Worker     }
176*4d7e907cSAndroid Build Coastguard Worker 
TearDown()177*4d7e907cSAndroid Build Coastguard Worker     virtual void TearDown() override { doDeleteAllUsers(); }
178*4d7e907cSAndroid Build Coastguard Worker };
179*4d7e907cSAndroid Build Coastguard Worker 
180*4d7e907cSAndroid Build Coastguard Worker /**
181*4d7e907cSAndroid Build Coastguard Worker  * Ensure we can enroll new password
182*4d7e907cSAndroid Build Coastguard Worker  */
TEST_P(GatekeeperAidlTest,EnrollSuccess)183*4d7e907cSAndroid Build Coastguard Worker TEST_P(GatekeeperAidlTest, EnrollSuccess) {
184*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> password;
185*4d7e907cSAndroid Build Coastguard Worker     GatekeeperEnrollResponse rsp;
186*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Enroll (expected success)");
187*4d7e907cSAndroid Build Coastguard Worker     generatePassword(password, 0);
188*4d7e907cSAndroid Build Coastguard Worker     enrollNewPassword(password, rsp, true);
189*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Enroll done");
190*4d7e907cSAndroid Build Coastguard Worker }
191*4d7e907cSAndroid Build Coastguard Worker 
192*4d7e907cSAndroid Build Coastguard Worker /**
193*4d7e907cSAndroid Build Coastguard Worker  * Ensure we can not enroll empty password
194*4d7e907cSAndroid Build Coastguard Worker  */
TEST_P(GatekeeperAidlTest,EnrollNoPassword)195*4d7e907cSAndroid Build Coastguard Worker TEST_P(GatekeeperAidlTest, EnrollNoPassword) {
196*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> password;
197*4d7e907cSAndroid Build Coastguard Worker     GatekeeperEnrollResponse rsp;
198*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Enroll (expected failure)");
199*4d7e907cSAndroid Build Coastguard Worker     enrollNewPassword(password, rsp, false);
200*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Enroll done");
201*4d7e907cSAndroid Build Coastguard Worker }
202*4d7e907cSAndroid Build Coastguard Worker 
203*4d7e907cSAndroid Build Coastguard Worker /**
204*4d7e907cSAndroid Build Coastguard Worker  * Ensure we can successfully verify previously enrolled password
205*4d7e907cSAndroid Build Coastguard Worker  */
TEST_P(GatekeeperAidlTest,VerifySuccess)206*4d7e907cSAndroid Build Coastguard Worker TEST_P(GatekeeperAidlTest, VerifySuccess) {
207*4d7e907cSAndroid Build Coastguard Worker     GatekeeperEnrollResponse enrollRsp;
208*4d7e907cSAndroid Build Coastguard Worker     GatekeeperVerifyResponse verifyRsp;
209*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> password;
210*4d7e907cSAndroid Build Coastguard Worker 
211*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Enroll+Verify (expected success)");
212*4d7e907cSAndroid Build Coastguard Worker     generatePassword(password, 0);
213*4d7e907cSAndroid Build Coastguard Worker     enrollNewPassword(password, enrollRsp, true);
214*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(password, enrollRsp.data, 1, verifyRsp, true);
215*4d7e907cSAndroid Build Coastguard Worker 
216*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing unenrolled password doesn't verify");
217*4d7e907cSAndroid Build Coastguard Worker     verifyRsp = {0, 0, {}};
218*4d7e907cSAndroid Build Coastguard Worker     generatePassword(password, 1);
219*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(password, enrollRsp.data, 1, verifyRsp, false);
220*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Enroll+Verify done");
221*4d7e907cSAndroid Build Coastguard Worker }
222*4d7e907cSAndroid Build Coastguard Worker 
223*4d7e907cSAndroid Build Coastguard Worker /**
224*4d7e907cSAndroid Build Coastguard Worker  * Ensure that passwords containing a NUL byte aren't truncated
225*4d7e907cSAndroid Build Coastguard Worker  */
TEST_P(GatekeeperAidlTest,PasswordIsBinaryData)226*4d7e907cSAndroid Build Coastguard Worker TEST_P(GatekeeperAidlTest, PasswordIsBinaryData) {
227*4d7e907cSAndroid Build Coastguard Worker     GatekeeperEnrollResponse enrollRsp;
228*4d7e907cSAndroid Build Coastguard Worker     GatekeeperVerifyResponse verifyRsp;
229*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> rightPassword = {'A', 'B', 'C', '\0', 'D', 'E', 'F'};
230*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> wrongPassword = {'A', 'B', 'C', '\0', '\0', '\0', '\0'};
231*4d7e907cSAndroid Build Coastguard Worker 
232*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Enroll+Verify of password with embedded NUL (expected success)");
233*4d7e907cSAndroid Build Coastguard Worker     enrollNewPassword(rightPassword, enrollRsp, true);
234*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(rightPassword, enrollRsp.data, 1, verifyRsp, true);
235*4d7e907cSAndroid Build Coastguard Worker 
236*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Verify of wrong password (expected failure)");
237*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(wrongPassword, enrollRsp.data, 1, verifyRsp, false);
238*4d7e907cSAndroid Build Coastguard Worker 
239*4d7e907cSAndroid Build Coastguard Worker     ALOGI("PasswordIsBinaryData test done");
240*4d7e907cSAndroid Build Coastguard Worker }
241*4d7e907cSAndroid Build Coastguard Worker 
242*4d7e907cSAndroid Build Coastguard Worker /**
243*4d7e907cSAndroid Build Coastguard Worker  * Ensure that long passwords aren't truncated
244*4d7e907cSAndroid Build Coastguard Worker  */
TEST_P(GatekeeperAidlTest,LongPassword)245*4d7e907cSAndroid Build Coastguard Worker TEST_P(GatekeeperAidlTest, LongPassword) {
246*4d7e907cSAndroid Build Coastguard Worker     GatekeeperEnrollResponse enrollRsp;
247*4d7e907cSAndroid Build Coastguard Worker     GatekeeperVerifyResponse verifyRsp;
248*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> password;
249*4d7e907cSAndroid Build Coastguard Worker 
250*4d7e907cSAndroid Build Coastguard Worker     password.resize(64);  // maximum length used by Android
251*4d7e907cSAndroid Build Coastguard Worker     memset(password.data(), 'A', password.size());
252*4d7e907cSAndroid Build Coastguard Worker 
253*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Enroll+Verify of long password (expected success)");
254*4d7e907cSAndroid Build Coastguard Worker     enrollNewPassword(password, enrollRsp, true);
255*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(password, enrollRsp.data, 1, verifyRsp, true);
256*4d7e907cSAndroid Build Coastguard Worker 
257*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Verify of wrong password (expected failure)");
258*4d7e907cSAndroid Build Coastguard Worker     password[password.size() - 1] ^= 1;
259*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(password, enrollRsp.data, 1, verifyRsp, false);
260*4d7e907cSAndroid Build Coastguard Worker 
261*4d7e907cSAndroid Build Coastguard Worker     ALOGI("LongPassword test done");
262*4d7e907cSAndroid Build Coastguard Worker }
263*4d7e907cSAndroid Build Coastguard Worker 
264*4d7e907cSAndroid Build Coastguard Worker /**
265*4d7e907cSAndroid Build Coastguard Worker  * Ensure we can securely update password (keep the same
266*4d7e907cSAndroid Build Coastguard Worker  * secure user_id) if we prove we know old password
267*4d7e907cSAndroid Build Coastguard Worker  */
TEST_P(GatekeeperAidlTest,TrustedReenroll)268*4d7e907cSAndroid Build Coastguard Worker TEST_P(GatekeeperAidlTest, TrustedReenroll) {
269*4d7e907cSAndroid Build Coastguard Worker     GatekeeperEnrollResponse enrollRsp;
270*4d7e907cSAndroid Build Coastguard Worker     GatekeeperRequest reenrollReq;
271*4d7e907cSAndroid Build Coastguard Worker     GatekeeperEnrollResponse reenrollRsp;
272*4d7e907cSAndroid Build Coastguard Worker     GatekeeperVerifyResponse verifyRsp;
273*4d7e907cSAndroid Build Coastguard Worker     GatekeeperVerifyResponse reenrollVerifyRsp;
274*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> password;
275*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> newPassword;
276*4d7e907cSAndroid Build Coastguard Worker 
277*4d7e907cSAndroid Build Coastguard Worker     generatePassword(password, 0);
278*4d7e907cSAndroid Build Coastguard Worker 
279*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Trusted Reenroll (expected success)");
280*4d7e907cSAndroid Build Coastguard Worker     enrollNewPassword(password, enrollRsp, true);
281*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(password, enrollRsp.data, 0, verifyRsp, true);
282*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Primary Enroll+Verify done");
283*4d7e907cSAndroid Build Coastguard Worker 
284*4d7e907cSAndroid Build Coastguard Worker     generatePassword(newPassword, 1);
285*4d7e907cSAndroid Build Coastguard Worker     reenrollReq.newPwd = newPassword;
286*4d7e907cSAndroid Build Coastguard Worker     reenrollReq.curPwd = password;
287*4d7e907cSAndroid Build Coastguard Worker     reenrollReq.curPwdHandle = enrollRsp.data;
288*4d7e907cSAndroid Build Coastguard Worker 
289*4d7e907cSAndroid Build Coastguard Worker     Status ret = doEnroll(reenrollReq, reenrollRsp);
290*4d7e907cSAndroid Build Coastguard Worker     checkEnroll(reenrollRsp, ret, true);
291*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(newPassword, reenrollRsp.data, 0, reenrollVerifyRsp, true);
292*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Trusted ReEnroll+Verify done");
293*4d7e907cSAndroid Build Coastguard Worker 
294*4d7e907cSAndroid Build Coastguard Worker     verifyAuthToken(verifyRsp);
295*4d7e907cSAndroid Build Coastguard Worker     verifyAuthToken(reenrollVerifyRsp);
296*4d7e907cSAndroid Build Coastguard Worker     EXPECT_EQ(verifyRsp.hardwareAuthToken.userId, reenrollVerifyRsp.hardwareAuthToken.userId);
297*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Trusted Reenroll done");
298*4d7e907cSAndroid Build Coastguard Worker }
299*4d7e907cSAndroid Build Coastguard Worker 
300*4d7e907cSAndroid Build Coastguard Worker /**
301*4d7e907cSAndroid Build Coastguard Worker  * Ensure we can update password (and get new
302*4d7e907cSAndroid Build Coastguard Worker  * secure user_id) if we don't know old password
303*4d7e907cSAndroid Build Coastguard Worker  */
TEST_P(GatekeeperAidlTest,UntrustedReenroll)304*4d7e907cSAndroid Build Coastguard Worker TEST_P(GatekeeperAidlTest, UntrustedReenroll) {
305*4d7e907cSAndroid Build Coastguard Worker     GatekeeperEnrollResponse enrollRsp;
306*4d7e907cSAndroid Build Coastguard Worker     GatekeeperEnrollResponse reenrollRsp;
307*4d7e907cSAndroid Build Coastguard Worker     GatekeeperVerifyResponse verifyRsp;
308*4d7e907cSAndroid Build Coastguard Worker     GatekeeperVerifyResponse reenrollVerifyRsp;
309*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> password;
310*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> newPassword;
311*4d7e907cSAndroid Build Coastguard Worker 
312*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Untrusted Reenroll (expected success)");
313*4d7e907cSAndroid Build Coastguard Worker     generatePassword(password, 0);
314*4d7e907cSAndroid Build Coastguard Worker     enrollNewPassword(password, enrollRsp, true);
315*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(password, enrollRsp.data, 0, verifyRsp, true);
316*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Primary Enroll+Verify done");
317*4d7e907cSAndroid Build Coastguard Worker 
318*4d7e907cSAndroid Build Coastguard Worker     generatePassword(newPassword, 1);
319*4d7e907cSAndroid Build Coastguard Worker     enrollNewPassword(newPassword, reenrollRsp, true);
320*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(newPassword, reenrollRsp.data, 0, reenrollVerifyRsp, true);
321*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Untrusted ReEnroll+Verify done");
322*4d7e907cSAndroid Build Coastguard Worker 
323*4d7e907cSAndroid Build Coastguard Worker     verifyAuthToken(verifyRsp);
324*4d7e907cSAndroid Build Coastguard Worker     verifyAuthToken(reenrollVerifyRsp);
325*4d7e907cSAndroid Build Coastguard Worker     EXPECT_NE(verifyRsp.hardwareAuthToken.userId, reenrollVerifyRsp.hardwareAuthToken.userId);
326*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Untrusted Reenroll done");
327*4d7e907cSAndroid Build Coastguard Worker }
328*4d7e907cSAndroid Build Coastguard Worker 
329*4d7e907cSAndroid Build Coastguard Worker /**
330*4d7e907cSAndroid Build Coastguard Worker  * Ensure we don't get successful verify with invalid data
331*4d7e907cSAndroid Build Coastguard Worker  */
TEST_P(GatekeeperAidlTest,VerifyNoData)332*4d7e907cSAndroid Build Coastguard Worker TEST_P(GatekeeperAidlTest, VerifyNoData) {
333*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> password;
334*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> passwordHandle;
335*4d7e907cSAndroid Build Coastguard Worker     GatekeeperVerifyResponse verifyRsp;
336*4d7e907cSAndroid Build Coastguard Worker 
337*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Verify (expected failure)");
338*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(password, passwordHandle, 0, verifyRsp, false);
339*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing Verify done");
340*4d7e907cSAndroid Build Coastguard Worker }
341*4d7e907cSAndroid Build Coastguard Worker 
342*4d7e907cSAndroid Build Coastguard Worker /**
343*4d7e907cSAndroid Build Coastguard Worker  * Ensure we can not verify password after we enrolled it and then deleted user
344*4d7e907cSAndroid Build Coastguard Worker  */
TEST_P(GatekeeperAidlTest,DeleteUserTest)345*4d7e907cSAndroid Build Coastguard Worker TEST_P(GatekeeperAidlTest, DeleteUserTest) {
346*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> password;
347*4d7e907cSAndroid Build Coastguard Worker     GatekeeperEnrollResponse enrollRsp;
348*4d7e907cSAndroid Build Coastguard Worker     GatekeeperVerifyResponse verifyRsp;
349*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing deleteUser (expected success)");
350*4d7e907cSAndroid Build Coastguard Worker     setUid(10001);
351*4d7e907cSAndroid Build Coastguard Worker     generatePassword(password, 0);
352*4d7e907cSAndroid Build Coastguard Worker     enrollNewPassword(password, enrollRsp, true);
353*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(password, enrollRsp.data, 0, verifyRsp, true);
354*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Enroll+Verify done");
355*4d7e907cSAndroid Build Coastguard Worker     auto result = doDeleteUser();
356*4d7e907cSAndroid Build Coastguard Worker     EXPECT_TRUE(result.isOk() ||
357*4d7e907cSAndroid Build Coastguard Worker                 (getReturnStatusCode(result) == IGatekeeper::ERROR_NOT_IMPLEMENTED));
358*4d7e907cSAndroid Build Coastguard Worker     ALOGI("DeleteUser done");
359*4d7e907cSAndroid Build Coastguard Worker     if (result.isOk()) {
360*4d7e907cSAndroid Build Coastguard Worker         verifyRsp = {0, 0, {}};
361*4d7e907cSAndroid Build Coastguard Worker         verifyPassword(password, enrollRsp.data, 0, verifyRsp, false);
362*4d7e907cSAndroid Build Coastguard Worker         ALOGI("Verify after Delete done (must fail)");
363*4d7e907cSAndroid Build Coastguard Worker     }
364*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing deleteUser done: rsp=%" PRIi32, getReturnStatusCode(result));
365*4d7e907cSAndroid Build Coastguard Worker }
366*4d7e907cSAndroid Build Coastguard Worker 
367*4d7e907cSAndroid Build Coastguard Worker /**
368*4d7e907cSAndroid Build Coastguard Worker  * Ensure we can not delete a user that does not exist
369*4d7e907cSAndroid Build Coastguard Worker  */
TEST_P(GatekeeperAidlTest,DeleteInvalidUserTest)370*4d7e907cSAndroid Build Coastguard Worker TEST_P(GatekeeperAidlTest, DeleteInvalidUserTest) {
371*4d7e907cSAndroid Build Coastguard Worker     std::vector<uint8_t> password;
372*4d7e907cSAndroid Build Coastguard Worker     GatekeeperEnrollResponse enrollRsp;
373*4d7e907cSAndroid Build Coastguard Worker     GatekeeperVerifyResponse verifyRsp;
374*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing deleteUser (expected failure)");
375*4d7e907cSAndroid Build Coastguard Worker     setUid(10002);
376*4d7e907cSAndroid Build Coastguard Worker     generatePassword(password, 0);
377*4d7e907cSAndroid Build Coastguard Worker     enrollNewPassword(password, enrollRsp, true);
378*4d7e907cSAndroid Build Coastguard Worker     verifyPassword(password, enrollRsp.data, 0, verifyRsp, true);
379*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Enroll+Verify done");
380*4d7e907cSAndroid Build Coastguard Worker 
381*4d7e907cSAndroid Build Coastguard Worker     // Delete the user
382*4d7e907cSAndroid Build Coastguard Worker     Status result1 = doDeleteUser();
383*4d7e907cSAndroid Build Coastguard Worker     EXPECT_TRUE(result1.isOk() ||
384*4d7e907cSAndroid Build Coastguard Worker                 (getReturnStatusCode(result1) == IGatekeeper::ERROR_NOT_IMPLEMENTED));
385*4d7e907cSAndroid Build Coastguard Worker 
386*4d7e907cSAndroid Build Coastguard Worker     // Delete the user again
387*4d7e907cSAndroid Build Coastguard Worker     Status result2 = doDeleteUser();
388*4d7e907cSAndroid Build Coastguard Worker     int32_t retCode2 = getReturnStatusCode(result2);
389*4d7e907cSAndroid Build Coastguard Worker     EXPECT_TRUE((retCode2 == IGatekeeper::ERROR_NOT_IMPLEMENTED) ||
390*4d7e907cSAndroid Build Coastguard Worker                 (retCode2 == IGatekeeper::ERROR_GENERAL_FAILURE));
391*4d7e907cSAndroid Build Coastguard Worker     ALOGI("DeleteUser done");
392*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing deleteUser done: rsp=%" PRIi32, retCode2);
393*4d7e907cSAndroid Build Coastguard Worker }
394*4d7e907cSAndroid Build Coastguard Worker 
395*4d7e907cSAndroid Build Coastguard Worker /**
396*4d7e907cSAndroid Build Coastguard Worker  * Ensure we can not verify passwords after we enrolled them and then deleted
397*4d7e907cSAndroid Build Coastguard Worker  * all users
398*4d7e907cSAndroid Build Coastguard Worker  */
TEST_P(GatekeeperAidlTest,DeleteAllUsersTest)399*4d7e907cSAndroid Build Coastguard Worker TEST_P(GatekeeperAidlTest, DeleteAllUsersTest) {
400*4d7e907cSAndroid Build Coastguard Worker     struct UserData {
401*4d7e907cSAndroid Build Coastguard Worker         uint32_t userId;
402*4d7e907cSAndroid Build Coastguard Worker         std::vector<uint8_t> password;
403*4d7e907cSAndroid Build Coastguard Worker         GatekeeperEnrollResponse enrollRsp;
404*4d7e907cSAndroid Build Coastguard Worker         GatekeeperVerifyResponse verifyRsp;
405*4d7e907cSAndroid Build Coastguard Worker         UserData(int id) { userId = id; }
406*4d7e907cSAndroid Build Coastguard Worker     } users[3]{10001, 10002, 10003};
407*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing deleteAllUsers (expected success)");
408*4d7e907cSAndroid Build Coastguard Worker 
409*4d7e907cSAndroid Build Coastguard Worker     // enroll multiple users
410*4d7e907cSAndroid Build Coastguard Worker     for (size_t i = 0; i < sizeof(users) / sizeof(users[0]); ++i) {
411*4d7e907cSAndroid Build Coastguard Worker         setUid(users[i].userId);
412*4d7e907cSAndroid Build Coastguard Worker         generatePassword(users[i].password, (i % 255) + 1);
413*4d7e907cSAndroid Build Coastguard Worker         enrollNewPassword(users[i].password, users[i].enrollRsp, true);
414*4d7e907cSAndroid Build Coastguard Worker     }
415*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Multiple users enrolled");
416*4d7e907cSAndroid Build Coastguard Worker 
417*4d7e907cSAndroid Build Coastguard Worker     // verify multiple users
418*4d7e907cSAndroid Build Coastguard Worker     for (size_t i = 0; i < sizeof(users) / sizeof(users[0]); ++i) {
419*4d7e907cSAndroid Build Coastguard Worker         setUid(users[i].userId);
420*4d7e907cSAndroid Build Coastguard Worker         verifyPassword(users[i].password, users[i].enrollRsp.data, 0, users[i].verifyRsp, true);
421*4d7e907cSAndroid Build Coastguard Worker     }
422*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Multiple users verified");
423*4d7e907cSAndroid Build Coastguard Worker 
424*4d7e907cSAndroid Build Coastguard Worker     Status result = doDeleteAllUsers();
425*4d7e907cSAndroid Build Coastguard Worker     EXPECT_TRUE(result.isOk() ||
426*4d7e907cSAndroid Build Coastguard Worker                 (getReturnStatusCode(result) == IGatekeeper::ERROR_NOT_IMPLEMENTED));
427*4d7e907cSAndroid Build Coastguard Worker     ALOGI("All users deleted");
428*4d7e907cSAndroid Build Coastguard Worker 
429*4d7e907cSAndroid Build Coastguard Worker     if (result.isOk()) {
430*4d7e907cSAndroid Build Coastguard Worker         // verify multiple users after they are deleted; all must fail
431*4d7e907cSAndroid Build Coastguard Worker         for (size_t i = 0; i < sizeof(users) / sizeof(users[0]); ++i) {
432*4d7e907cSAndroid Build Coastguard Worker             setUid(users[i].userId);
433*4d7e907cSAndroid Build Coastguard Worker             users[i].verifyRsp = {0, 0, {}};
434*4d7e907cSAndroid Build Coastguard Worker             verifyPassword(users[i].password, users[i].enrollRsp.data, 0, users[i].verifyRsp,
435*4d7e907cSAndroid Build Coastguard Worker                            false);
436*4d7e907cSAndroid Build Coastguard Worker         }
437*4d7e907cSAndroid Build Coastguard Worker         ALOGI("Multiple users verified after delete (all must fail)");
438*4d7e907cSAndroid Build Coastguard Worker     }
439*4d7e907cSAndroid Build Coastguard Worker 
440*4d7e907cSAndroid Build Coastguard Worker     ALOGI("Testing deleteAllUsers done: rsp=%" PRIi32, getReturnStatusCode(result));
441*4d7e907cSAndroid Build Coastguard Worker }
442*4d7e907cSAndroid Build Coastguard Worker 
443*4d7e907cSAndroid Build Coastguard Worker GTEST_ALLOW_UNINSTANTIATED_PARAMETERIZED_TEST(GatekeeperAidlTest);
444*4d7e907cSAndroid Build Coastguard Worker INSTANTIATE_TEST_SUITE_P(
445*4d7e907cSAndroid Build Coastguard Worker     PerInstance, GatekeeperAidlTest,
446*4d7e907cSAndroid Build Coastguard Worker     testing::ValuesIn(android::getAidlHalInstanceNames(IGatekeeper::descriptor)),
447*4d7e907cSAndroid Build Coastguard Worker     android::PrintInstanceNameToString);
448*4d7e907cSAndroid Build Coastguard Worker 
main(int argc,char ** argv)449*4d7e907cSAndroid Build Coastguard Worker int main(int argc, char** argv) {
450*4d7e907cSAndroid Build Coastguard Worker     ::testing::InitGoogleTest(&argc, argv);
451*4d7e907cSAndroid Build Coastguard Worker     ABinderProcess_setThreadPoolMaxThreadCount(1);
452*4d7e907cSAndroid Build Coastguard Worker     ABinderProcess_startThreadPool();
453*4d7e907cSAndroid Build Coastguard Worker     return RUN_ALL_TESTS();
454*4d7e907cSAndroid Build Coastguard Worker }
455