Fix X509 test failures on Android - #50301

Merged
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes
Apr 6, 2021
Merged

Fix X509 test failures on Android#50301
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes

Conversation

@jkoritzinsky

@jkoritzinskyjkoritzinsky commented Mar 26, 2021

Copy link
Copy Markdown
Member

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Fixes#50565

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @bartonjs, @vcsjones, @krwq, @GrabYourPitchforks
See info in area-owners.md if you want to be subscribed.

Issue Details

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Author:jkoritzinsky
Assignees:-
Labels:

area-System.Security, os-android

Milestone:-

Comment on lines 102 to +108
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">
<Compile Include="X509StoreMutableTests.Android.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' != 'true'">
<Compile Include="RevocationTests\DynamicRevocationTests.Default.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's reuse existing groups when possible.

@jkoritzinsky

This comment has been minimized.

@elinor-fung

Copy link
Copy Markdown
Member

CI wasm failure is happening because of the added[ConditionalClass(typeof(DynamicRevocationTests), nameof(SupportsDynamicRevocation))] attribute. During test discovery, this results in DynamicRevocationTests being loaded and its static fields being initialized. This fails because using Oid from System.Security.Cryptography.Encoding is throwing PNSE on browser.

privatestaticreadonlyOids_tlsServerOid=newOid("1.3.6.1.5.5.7.3.1",null);

This entire test assembly is actually disabled / marked as failing on browser:

[assembly:ActiveIssue("https://github.com/dotnet/runtime/issues/37669",TestPlatforms.Browser)]

But the test discovery still goes through every test method and tries to determine the traits for each method. We could rework this so that it continues avoiding using any types that will hit PNSE on browser during test discovery, but it seems weird/wasteful that we're making our test runs go through bundling, sending off to helix, test discovery, and result reporting when we know the entire suite (and many of its dependencies) are not currently supported.

@steveisok / @lewing is there a reason we want to have this suite disabled on browser through the ActiveIssue attribute instead of adding it to ProjectExclusions?

@steveisok

Copy link
Copy Markdown
Member

@elinor-fung There was probably a point in time where we thought labeling ActiveIssue at the assembly level was the way to skip whole suites. I think it makes sense to add to <ProjectExclusions> instead.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PublicKeyTests.SupportsBrainpool shouldn't be needed.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for humoring me.

@ghost

ghost commented Apr 5, 2021

Copy link
Copy Markdown

Hello @jkoritzinsky!

Because this pull request has the auto-merge label, I will be glad to assist with helping to merge this pull request once all check-in policies pass.

p.s. you can customize the way I help with merging this pull request, such as holding this pull request until a specific person approves. Simply @mention me (@msftbot) and give me an instruction to get started! Learn more here.

@ghost
ghost merged commit c0a710f into dotnet:mainApr 6, 2021
thaystg added a commit to thaystg/runtime that referenced this pull request Apr 6, 2021
…shim_mono
# By Aaron Robinson (10) and others
# Via GitHub
* upstream/main: (108 commits)
[mbr] Add Apple sample (dotnet#50740)
make EstablishProxyTunnelAsync throw on failure status code from proxy (dotnet#50763)
Improve RGB Min Max evaluation performance by using 2 or 3 comparison… (dotnet#50622)
[mono] More domain cleanups (dotnet#50479)
Fix Crossgen2 of PlatformDefaultMemberFunction methods and calls. (dotnet#50754)
Disable EventSource generator in design-time builds (dotnet#50741)
Fix X509 test failures on Android (dotnet#50301)
Do not confuse fgDispBasicBlocks in fgMorphBlocks (dotnet#50703)
Enforce 64KB event payload size limit on EventPipe (dotnet#50600)
Reorganize CoreCLR native build to reduce CMake reconfigures when the build system is untouched (dotnet#49906)
[mbr] Turn on hot reload for iOS, tvOS and MacCatalyst (dotnet#50458)
improve connection scavenge logic by doing zero-byte read (dotnet#50545)
Resolve call mdtokens when making tier 1 inline observations (dotnet#50675)
Annotate APIs in System.Private.Xml (dotnet#49682)
Support compiling against OpenSSL 3 headers
Change Configuration.Json to use a regular Dictionary. (dotnet#50611)
Remove unused BigNumFromBinary P/Invoke (dotnet#50670)
Make Ninja the default CMake generator on Windows for the repo (dotnet#49715)
[AppleAppBuilder] Entitlements to run tests on catalyst using the JIT (dotnet#50637)
[mono] Fix delegate invokes to dynamic methods in mixed mode. (dotnet#50547)
...
# Conflicts:
#	src/mono/dlls/mscordbi/CMakeLists.txt
@ghostghost locked as resolved and limited conversation to collaborators May 6, 2021
@karelzkarelz added this to the 6.0.0 milestone May 20, 2021
@jkoritzinsky
jkoritzinsky deleted the x509certs-test-fixes branch September 28, 2021 00:04
This pull request was closed.
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

System.Security.Cryptography.X509Certificates.Tests fail on Android

5 participants

@jkoritzinsky@elinor-fung@steveisok@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Fix X509 test failures on Android - #50301

Merged
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes
Apr 6, 2021
Merged

Fix X509 test failures on Android#50301
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes

Conversation

@jkoritzinsky

@jkoritzinskyjkoritzinsky commented Mar 26, 2021

Copy link
Copy Markdown
Member

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Fixes#50565

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @bartonjs, @vcsjones, @krwq, @GrabYourPitchforks
See info in area-owners.md if you want to be subscribed.

Issue Details

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Author:jkoritzinsky
Assignees:-
Labels:

area-System.Security, os-android

Milestone:-

Comment on lines 102 to +108
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">
<Compile Include="X509StoreMutableTests.Android.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' != 'true'">
<Compile Include="RevocationTests\DynamicRevocationTests.Default.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's reuse existing groups when possible.

@jkoritzinsky

This comment has been minimized.

@elinor-fung

Copy link
Copy Markdown
Member

CI wasm failure is happening because of the added[ConditionalClass(typeof(DynamicRevocationTests), nameof(SupportsDynamicRevocation))] attribute. During test discovery, this results in DynamicRevocationTests being loaded and its static fields being initialized. This fails because using Oid from System.Security.Cryptography.Encoding is throwing PNSE on browser.

privatestaticreadonlyOids_tlsServerOid=newOid("1.3.6.1.5.5.7.3.1",null);

This entire test assembly is actually disabled / marked as failing on browser:

[assembly:ActiveIssue("https://github.com/dotnet/runtime/issues/37669",TestPlatforms.Browser)]

But the test discovery still goes through every test method and tries to determine the traits for each method. We could rework this so that it continues avoiding using any types that will hit PNSE on browser during test discovery, but it seems weird/wasteful that we're making our test runs go through bundling, sending off to helix, test discovery, and result reporting when we know the entire suite (and many of its dependencies) are not currently supported.

@steveisok / @lewing is there a reason we want to have this suite disabled on browser through the ActiveIssue attribute instead of adding it to ProjectExclusions?

@steveisok

Copy link
Copy Markdown
Member

@elinor-fung There was probably a point in time where we thought labeling ActiveIssue at the assembly level was the way to skip whole suites. I think it makes sense to add to <ProjectExclusions> instead.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PublicKeyTests.SupportsBrainpool shouldn't be needed.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for humoring me.

@ghost

ghost commented Apr 5, 2021

Copy link
Copy Markdown

Hello @jkoritzinsky!

Because this pull request has the auto-merge label, I will be glad to assist with helping to merge this pull request once all check-in policies pass.

p.s. you can customize the way I help with merging this pull request, such as holding this pull request until a specific person approves. Simply @mention me (@msftbot) and give me an instruction to get started! Learn more here.

@ghost
ghost merged commit c0a710f into dotnet:mainApr 6, 2021
thaystg added a commit to thaystg/runtime that referenced this pull request Apr 6, 2021
…shim_mono
# By Aaron Robinson (10) and others
# Via GitHub
* upstream/main: (108 commits)
[mbr] Add Apple sample (dotnet#50740)
make EstablishProxyTunnelAsync throw on failure status code from proxy (dotnet#50763)
Improve RGB Min Max evaluation performance by using 2 or 3 comparison… (dotnet#50622)
[mono] More domain cleanups (dotnet#50479)
Fix Crossgen2 of PlatformDefaultMemberFunction methods and calls. (dotnet#50754)
Disable EventSource generator in design-time builds (dotnet#50741)
Fix X509 test failures on Android (dotnet#50301)
Do not confuse fgDispBasicBlocks in fgMorphBlocks (dotnet#50703)
Enforce 64KB event payload size limit on EventPipe (dotnet#50600)
Reorganize CoreCLR native build to reduce CMake reconfigures when the build system is untouched (dotnet#49906)
[mbr] Turn on hot reload for iOS, tvOS and MacCatalyst (dotnet#50458)
improve connection scavenge logic by doing zero-byte read (dotnet#50545)
Resolve call mdtokens when making tier 1 inline observations (dotnet#50675)
Annotate APIs in System.Private.Xml (dotnet#49682)
Support compiling against OpenSSL 3 headers
Change Configuration.Json to use a regular Dictionary. (dotnet#50611)
Remove unused BigNumFromBinary P/Invoke (dotnet#50670)
Make Ninja the default CMake generator on Windows for the repo (dotnet#49715)
[AppleAppBuilder] Entitlements to run tests on catalyst using the JIT (dotnet#50637)
[mono] Fix delegate invokes to dynamic methods in mixed mode. (dotnet#50547)
...
# Conflicts:
#	src/mono/dlls/mscordbi/CMakeLists.txt
@ghostghost locked as resolved and limited conversation to collaborators May 6, 2021
@karelzkarelz added this to the 6.0.0 milestone May 20, 2021
@jkoritzinsky
jkoritzinsky deleted the x509certs-test-fixes branch September 28, 2021 00:04
This pull request was closed.
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

System.Security.Cryptography.X509Certificates.Tests fail on Android

5 participants

@jkoritzinsky@elinor-fung@steveisok@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix X509 test failures on Android - #50301

Merged
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes
Apr 6, 2021
Merged

Fix X509 test failures on Android#50301
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes

Conversation

@jkoritzinsky

@jkoritzinskyjkoritzinsky commented Mar 26, 2021

Copy link
Copy Markdown
Member

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Fixes#50565

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @bartonjs, @vcsjones, @krwq, @GrabYourPitchforks
See info in area-owners.md if you want to be subscribed.

Issue Details

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Author:jkoritzinsky
Assignees:-
Labels:

area-System.Security, os-android

Milestone:-

Comment on lines 102 to +108
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">
<Compile Include="X509StoreMutableTests.Android.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' != 'true'">
<Compile Include="RevocationTests\DynamicRevocationTests.Default.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's reuse existing groups when possible.

@jkoritzinsky

This comment has been minimized.

@elinor-fung

Copy link
Copy Markdown
Member

CI wasm failure is happening because of the added[ConditionalClass(typeof(DynamicRevocationTests), nameof(SupportsDynamicRevocation))] attribute. During test discovery, this results in DynamicRevocationTests being loaded and its static fields being initialized. This fails because using Oid from System.Security.Cryptography.Encoding is throwing PNSE on browser.

privatestaticreadonlyOids_tlsServerOid=newOid("1.3.6.1.5.5.7.3.1",null);

This entire test assembly is actually disabled / marked as failing on browser:

[assembly:ActiveIssue("https://github.com/dotnet/runtime/issues/37669",TestPlatforms.Browser)]

But the test discovery still goes through every test method and tries to determine the traits for each method. We could rework this so that it continues avoiding using any types that will hit PNSE on browser during test discovery, but it seems weird/wasteful that we're making our test runs go through bundling, sending off to helix, test discovery, and result reporting when we know the entire suite (and many of its dependencies) are not currently supported.

@steveisok / @lewing is there a reason we want to have this suite disabled on browser through the ActiveIssue attribute instead of adding it to ProjectExclusions?

@steveisok

Copy link
Copy Markdown
Member

@elinor-fung There was probably a point in time where we thought labeling ActiveIssue at the assembly level was the way to skip whole suites. I think it makes sense to add to <ProjectExclusions> instead.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PublicKeyTests.SupportsBrainpool shouldn't be needed.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for humoring me.

@ghost

ghost commented Apr 5, 2021

Copy link
Copy Markdown

Hello @jkoritzinsky!

Because this pull request has the auto-merge label, I will be glad to assist with helping to merge this pull request once all check-in policies pass.

p.s. you can customize the way I help with merging this pull request, such as holding this pull request until a specific person approves. Simply @mention me (@msftbot) and give me an instruction to get started! Learn more here.

@ghost
ghost merged commit c0a710f into dotnet:mainApr 6, 2021
thaystg added a commit to thaystg/runtime that referenced this pull request Apr 6, 2021
…shim_mono
# By Aaron Robinson (10) and others
# Via GitHub
* upstream/main: (108 commits)
[mbr] Add Apple sample (dotnet#50740)
make EstablishProxyTunnelAsync throw on failure status code from proxy (dotnet#50763)
Improve RGB Min Max evaluation performance by using 2 or 3 comparison… (dotnet#50622)
[mono] More domain cleanups (dotnet#50479)
Fix Crossgen2 of PlatformDefaultMemberFunction methods and calls. (dotnet#50754)
Disable EventSource generator in design-time builds (dotnet#50741)
Fix X509 test failures on Android (dotnet#50301)
Do not confuse fgDispBasicBlocks in fgMorphBlocks (dotnet#50703)
Enforce 64KB event payload size limit on EventPipe (dotnet#50600)
Reorganize CoreCLR native build to reduce CMake reconfigures when the build system is untouched (dotnet#49906)
[mbr] Turn on hot reload for iOS, tvOS and MacCatalyst (dotnet#50458)
improve connection scavenge logic by doing zero-byte read (dotnet#50545)
Resolve call mdtokens when making tier 1 inline observations (dotnet#50675)
Annotate APIs in System.Private.Xml (dotnet#49682)
Support compiling against OpenSSL 3 headers
Change Configuration.Json to use a regular Dictionary. (dotnet#50611)
Remove unused BigNumFromBinary P/Invoke (dotnet#50670)
Make Ninja the default CMake generator on Windows for the repo (dotnet#49715)
[AppleAppBuilder] Entitlements to run tests on catalyst using the JIT (dotnet#50637)
[mono] Fix delegate invokes to dynamic methods in mixed mode. (dotnet#50547)
...
# Conflicts:
#	src/mono/dlls/mscordbi/CMakeLists.txt
@ghostghost locked as resolved and limited conversation to collaborators May 6, 2021
@karelzkarelz added this to the 6.0.0 milestone May 20, 2021
@jkoritzinsky
jkoritzinsky deleted the x509certs-test-fixes branch September 28, 2021 00:04
This pull request was closed.
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

System.Security.Cryptography.X509Certificates.Tests fail on Android

5 participants

@jkoritzinsky@elinor-fung@steveisok@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix X509 test failures on Android - #50301

Merged
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes
Apr 6, 2021
Merged

Fix X509 test failures on Android#50301
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes

Conversation

@jkoritzinsky

@jkoritzinskyjkoritzinsky commented Mar 26, 2021

Copy link
Copy Markdown
Member

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Fixes#50565

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @bartonjs, @vcsjones, @krwq, @GrabYourPitchforks
See info in area-owners.md if you want to be subscribed.

Issue Details

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Author:jkoritzinsky
Assignees:-
Labels:

area-System.Security, os-android

Milestone:-

Comment on lines 102 to +108
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">
<Compile Include="X509StoreMutableTests.Android.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' != 'true'">
<Compile Include="RevocationTests\DynamicRevocationTests.Default.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's reuse existing groups when possible.

@jkoritzinsky

This comment has been minimized.

@elinor-fung

Copy link
Copy Markdown
Member

CI wasm failure is happening because of the added[ConditionalClass(typeof(DynamicRevocationTests), nameof(SupportsDynamicRevocation))] attribute. During test discovery, this results in DynamicRevocationTests being loaded and its static fields being initialized. This fails because using Oid from System.Security.Cryptography.Encoding is throwing PNSE on browser.

privatestaticreadonlyOids_tlsServerOid=newOid("1.3.6.1.5.5.7.3.1",null);

This entire test assembly is actually disabled / marked as failing on browser:

[assembly:ActiveIssue("https://github.com/dotnet/runtime/issues/37669",TestPlatforms.Browser)]

But the test discovery still goes through every test method and tries to determine the traits for each method. We could rework this so that it continues avoiding using any types that will hit PNSE on browser during test discovery, but it seems weird/wasteful that we're making our test runs go through bundling, sending off to helix, test discovery, and result reporting when we know the entire suite (and many of its dependencies) are not currently supported.

@steveisok / @lewing is there a reason we want to have this suite disabled on browser through the ActiveIssue attribute instead of adding it to ProjectExclusions?

@steveisok

Copy link
Copy Markdown
Member

@elinor-fung There was probably a point in time where we thought labeling ActiveIssue at the assembly level was the way to skip whole suites. I think it makes sense to add to <ProjectExclusions> instead.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PublicKeyTests.SupportsBrainpool shouldn't be needed.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for humoring me.

@ghost

ghost commented Apr 5, 2021

Copy link
Copy Markdown

Hello @jkoritzinsky!

Because this pull request has the auto-merge label, I will be glad to assist with helping to merge this pull request once all check-in policies pass.

p.s. you can customize the way I help with merging this pull request, such as holding this pull request until a specific person approves. Simply @mention me (@msftbot) and give me an instruction to get started! Learn more here.

@ghost
ghost merged commit c0a710f into dotnet:mainApr 6, 2021
thaystg added a commit to thaystg/runtime that referenced this pull request Apr 6, 2021
…shim_mono
# By Aaron Robinson (10) and others
# Via GitHub
* upstream/main: (108 commits)
[mbr] Add Apple sample (dotnet#50740)
make EstablishProxyTunnelAsync throw on failure status code from proxy (dotnet#50763)
Improve RGB Min Max evaluation performance by using 2 or 3 comparison… (dotnet#50622)
[mono] More domain cleanups (dotnet#50479)
Fix Crossgen2 of PlatformDefaultMemberFunction methods and calls. (dotnet#50754)
Disable EventSource generator in design-time builds (dotnet#50741)
Fix X509 test failures on Android (dotnet#50301)
Do not confuse fgDispBasicBlocks in fgMorphBlocks (dotnet#50703)
Enforce 64KB event payload size limit on EventPipe (dotnet#50600)
Reorganize CoreCLR native build to reduce CMake reconfigures when the build system is untouched (dotnet#49906)
[mbr] Turn on hot reload for iOS, tvOS and MacCatalyst (dotnet#50458)
improve connection scavenge logic by doing zero-byte read (dotnet#50545)
Resolve call mdtokens when making tier 1 inline observations (dotnet#50675)
Annotate APIs in System.Private.Xml (dotnet#49682)
Support compiling against OpenSSL 3 headers
Change Configuration.Json to use a regular Dictionary. (dotnet#50611)
Remove unused BigNumFromBinary P/Invoke (dotnet#50670)
Make Ninja the default CMake generator on Windows for the repo (dotnet#49715)
[AppleAppBuilder] Entitlements to run tests on catalyst using the JIT (dotnet#50637)
[mono] Fix delegate invokes to dynamic methods in mixed mode. (dotnet#50547)
...
# Conflicts:
#	src/mono/dlls/mscordbi/CMakeLists.txt
@ghostghost locked as resolved and limited conversation to collaborators May 6, 2021
@karelzkarelz added this to the 6.0.0 milestone May 20, 2021
@jkoritzinsky
jkoritzinsky deleted the x509certs-test-fixes branch September 28, 2021 00:04
This pull request was closed.
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

System.Security.Cryptography.X509Certificates.Tests fail on Android

5 participants

@jkoritzinsky@elinor-fung@steveisok@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Fix X509 test failures on Android - #50301

Merged
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes
Apr 6, 2021
Merged

Fix X509 test failures on Android#50301
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes

Conversation

@jkoritzinsky

@jkoritzinskyjkoritzinsky commented Mar 26, 2021

Copy link
Copy Markdown
Member

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Fixes#50565

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @bartonjs, @vcsjones, @krwq, @GrabYourPitchforks
See info in area-owners.md if you want to be subscribed.

Issue Details

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Author:jkoritzinsky
Assignees:-
Labels:

area-System.Security, os-android

Milestone:-

Comment on lines 102 to +108
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">
<Compile Include="X509StoreMutableTests.Android.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' != 'true'">
<Compile Include="RevocationTests\DynamicRevocationTests.Default.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's reuse existing groups when possible.

@jkoritzinsky

This comment has been minimized.

@elinor-fung

Copy link
Copy Markdown
Member

CI wasm failure is happening because of the added[ConditionalClass(typeof(DynamicRevocationTests), nameof(SupportsDynamicRevocation))] attribute. During test discovery, this results in DynamicRevocationTests being loaded and its static fields being initialized. This fails because using Oid from System.Security.Cryptography.Encoding is throwing PNSE on browser.

privatestaticreadonlyOids_tlsServerOid=newOid("1.3.6.1.5.5.7.3.1",null);

This entire test assembly is actually disabled / marked as failing on browser:

[assembly:ActiveIssue("https://github.com/dotnet/runtime/issues/37669",TestPlatforms.Browser)]

But the test discovery still goes through every test method and tries to determine the traits for each method. We could rework this so that it continues avoiding using any types that will hit PNSE on browser during test discovery, but it seems weird/wasteful that we're making our test runs go through bundling, sending off to helix, test discovery, and result reporting when we know the entire suite (and many of its dependencies) are not currently supported.

@steveisok / @lewing is there a reason we want to have this suite disabled on browser through the ActiveIssue attribute instead of adding it to ProjectExclusions?

@steveisok

Copy link
Copy Markdown
Member

@elinor-fung There was probably a point in time where we thought labeling ActiveIssue at the assembly level was the way to skip whole suites. I think it makes sense to add to <ProjectExclusions> instead.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PublicKeyTests.SupportsBrainpool shouldn't be needed.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for humoring me.

@ghost

ghost commented Apr 5, 2021

Copy link
Copy Markdown

Hello @jkoritzinsky!

Because this pull request has the auto-merge label, I will be glad to assist with helping to merge this pull request once all check-in policies pass.

p.s. you can customize the way I help with merging this pull request, such as holding this pull request until a specific person approves. Simply @mention me (@msftbot) and give me an instruction to get started! Learn more here.

@ghost
ghost merged commit c0a710f into dotnet:mainApr 6, 2021
thaystg added a commit to thaystg/runtime that referenced this pull request Apr 6, 2021
…shim_mono
# By Aaron Robinson (10) and others
# Via GitHub
* upstream/main: (108 commits)
[mbr] Add Apple sample (dotnet#50740)
make EstablishProxyTunnelAsync throw on failure status code from proxy (dotnet#50763)
Improve RGB Min Max evaluation performance by using 2 or 3 comparison… (dotnet#50622)
[mono] More domain cleanups (dotnet#50479)
Fix Crossgen2 of PlatformDefaultMemberFunction methods and calls. (dotnet#50754)
Disable EventSource generator in design-time builds (dotnet#50741)
Fix X509 test failures on Android (dotnet#50301)
Do not confuse fgDispBasicBlocks in fgMorphBlocks (dotnet#50703)
Enforce 64KB event payload size limit on EventPipe (dotnet#50600)
Reorganize CoreCLR native build to reduce CMake reconfigures when the build system is untouched (dotnet#49906)
[mbr] Turn on hot reload for iOS, tvOS and MacCatalyst (dotnet#50458)
improve connection scavenge logic by doing zero-byte read (dotnet#50545)
Resolve call mdtokens when making tier 1 inline observations (dotnet#50675)
Annotate APIs in System.Private.Xml (dotnet#49682)
Support compiling against OpenSSL 3 headers
Change Configuration.Json to use a regular Dictionary. (dotnet#50611)
Remove unused BigNumFromBinary P/Invoke (dotnet#50670)
Make Ninja the default CMake generator on Windows for the repo (dotnet#49715)
[AppleAppBuilder] Entitlements to run tests on catalyst using the JIT (dotnet#50637)
[mono] Fix delegate invokes to dynamic methods in mixed mode. (dotnet#50547)
...
# Conflicts:
#	src/mono/dlls/mscordbi/CMakeLists.txt
@ghostghost locked as resolved and limited conversation to collaborators May 6, 2021
@karelzkarelz added this to the 6.0.0 milestone May 20, 2021
@jkoritzinsky
jkoritzinsky deleted the x509certs-test-fixes branch September 28, 2021 00:04
This pull request was closed.
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

System.Security.Cryptography.X509Certificates.Tests fail on Android

5 participants

@jkoritzinsky@elinor-fung@steveisok@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix X509 test failures on Android - #50301

Merged
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes
Apr 6, 2021
Merged

Fix X509 test failures on Android#50301
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes

Conversation

@jkoritzinsky

@jkoritzinskyjkoritzinsky commented Mar 26, 2021

Copy link
Copy Markdown
Member

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Fixes#50565

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @bartonjs, @vcsjones, @krwq, @GrabYourPitchforks
See info in area-owners.md if you want to be subscribed.

Issue Details

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Author:jkoritzinsky
Assignees:-
Labels:

area-System.Security, os-android

Milestone:-

Comment on lines 102 to +108
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">
<Compile Include="X509StoreMutableTests.Android.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' != 'true'">
<Compile Include="RevocationTests\DynamicRevocationTests.Default.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's reuse existing groups when possible.

@jkoritzinsky

This comment has been minimized.

@elinor-fung

Copy link
Copy Markdown
Member

CI wasm failure is happening because of the added[ConditionalClass(typeof(DynamicRevocationTests), nameof(SupportsDynamicRevocation))] attribute. During test discovery, this results in DynamicRevocationTests being loaded and its static fields being initialized. This fails because using Oid from System.Security.Cryptography.Encoding is throwing PNSE on browser.

privatestaticreadonlyOids_tlsServerOid=newOid("1.3.6.1.5.5.7.3.1",null);

This entire test assembly is actually disabled / marked as failing on browser:

[assembly:ActiveIssue("https://github.com/dotnet/runtime/issues/37669",TestPlatforms.Browser)]

But the test discovery still goes through every test method and tries to determine the traits for each method. We could rework this so that it continues avoiding using any types that will hit PNSE on browser during test discovery, but it seems weird/wasteful that we're making our test runs go through bundling, sending off to helix, test discovery, and result reporting when we know the entire suite (and many of its dependencies) are not currently supported.

@steveisok / @lewing is there a reason we want to have this suite disabled on browser through the ActiveIssue attribute instead of adding it to ProjectExclusions?

@steveisok

Copy link
Copy Markdown
Member

@elinor-fung There was probably a point in time where we thought labeling ActiveIssue at the assembly level was the way to skip whole suites. I think it makes sense to add to <ProjectExclusions> instead.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PublicKeyTests.SupportsBrainpool shouldn't be needed.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for humoring me.

@ghost

ghost commented Apr 5, 2021

Copy link
Copy Markdown

Hello @jkoritzinsky!

Because this pull request has the auto-merge label, I will be glad to assist with helping to merge this pull request once all check-in policies pass.

p.s. you can customize the way I help with merging this pull request, such as holding this pull request until a specific person approves. Simply @mention me (@msftbot) and give me an instruction to get started! Learn more here.

@ghost
ghost merged commit c0a710f into dotnet:mainApr 6, 2021
thaystg added a commit to thaystg/runtime that referenced this pull request Apr 6, 2021
…shim_mono
# By Aaron Robinson (10) and others
# Via GitHub
* upstream/main: (108 commits)
[mbr] Add Apple sample (dotnet#50740)
make EstablishProxyTunnelAsync throw on failure status code from proxy (dotnet#50763)
Improve RGB Min Max evaluation performance by using 2 or 3 comparison… (dotnet#50622)
[mono] More domain cleanups (dotnet#50479)
Fix Crossgen2 of PlatformDefaultMemberFunction methods and calls. (dotnet#50754)
Disable EventSource generator in design-time builds (dotnet#50741)
Fix X509 test failures on Android (dotnet#50301)
Do not confuse fgDispBasicBlocks in fgMorphBlocks (dotnet#50703)
Enforce 64KB event payload size limit on EventPipe (dotnet#50600)
Reorganize CoreCLR native build to reduce CMake reconfigures when the build system is untouched (dotnet#49906)
[mbr] Turn on hot reload for iOS, tvOS and MacCatalyst (dotnet#50458)
improve connection scavenge logic by doing zero-byte read (dotnet#50545)
Resolve call mdtokens when making tier 1 inline observations (dotnet#50675)
Annotate APIs in System.Private.Xml (dotnet#49682)
Support compiling against OpenSSL 3 headers
Change Configuration.Json to use a regular Dictionary. (dotnet#50611)
Remove unused BigNumFromBinary P/Invoke (dotnet#50670)
Make Ninja the default CMake generator on Windows for the repo (dotnet#49715)
[AppleAppBuilder] Entitlements to run tests on catalyst using the JIT (dotnet#50637)
[mono] Fix delegate invokes to dynamic methods in mixed mode. (dotnet#50547)
...
# Conflicts:
#	src/mono/dlls/mscordbi/CMakeLists.txt
@ghostghost locked as resolved and limited conversation to collaborators May 6, 2021
@karelzkarelz added this to the 6.0.0 milestone May 20, 2021
@jkoritzinsky
jkoritzinsky deleted the x509certs-test-fixes branch September 28, 2021 00:04
This pull request was closed.
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

System.Security.Cryptography.X509Certificates.Tests fail on Android

5 participants

@jkoritzinsky@elinor-fung@steveisok@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix X509 test failures on Android - #50301

Merged
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes
Apr 6, 2021
Merged

Fix X509 test failures on Android#50301
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes

Conversation

@jkoritzinsky

@jkoritzinskyjkoritzinsky commented Mar 26, 2021

Copy link
Copy Markdown
Member

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Fixes#50565

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @bartonjs, @vcsjones, @krwq, @GrabYourPitchforks
See info in area-owners.md if you want to be subscribed.

Issue Details

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Author:jkoritzinsky
Assignees:-
Labels:

area-System.Security, os-android

Milestone:-

Comment on lines 102 to +108
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">
<Compile Include="X509StoreMutableTests.Android.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' != 'true'">
<Compile Include="RevocationTests\DynamicRevocationTests.Default.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's reuse existing groups when possible.

@jkoritzinsky

This comment has been minimized.

@elinor-fung

Copy link
Copy Markdown
Member

CI wasm failure is happening because of the added[ConditionalClass(typeof(DynamicRevocationTests), nameof(SupportsDynamicRevocation))] attribute. During test discovery, this results in DynamicRevocationTests being loaded and its static fields being initialized. This fails because using Oid from System.Security.Cryptography.Encoding is throwing PNSE on browser.

privatestaticreadonlyOids_tlsServerOid=newOid("1.3.6.1.5.5.7.3.1",null);

This entire test assembly is actually disabled / marked as failing on browser:

[assembly:ActiveIssue("https://github.com/dotnet/runtime/issues/37669",TestPlatforms.Browser)]

But the test discovery still goes through every test method and tries to determine the traits for each method. We could rework this so that it continues avoiding using any types that will hit PNSE on browser during test discovery, but it seems weird/wasteful that we're making our test runs go through bundling, sending off to helix, test discovery, and result reporting when we know the entire suite (and many of its dependencies) are not currently supported.

@steveisok / @lewing is there a reason we want to have this suite disabled on browser through the ActiveIssue attribute instead of adding it to ProjectExclusions?

@steveisok

Copy link
Copy Markdown
Member

@elinor-fung There was probably a point in time where we thought labeling ActiveIssue at the assembly level was the way to skip whole suites. I think it makes sense to add to <ProjectExclusions> instead.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PublicKeyTests.SupportsBrainpool shouldn't be needed.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for humoring me.

@ghost

ghost commented Apr 5, 2021

Copy link
Copy Markdown

Hello @jkoritzinsky!

Because this pull request has the auto-merge label, I will be glad to assist with helping to merge this pull request once all check-in policies pass.

p.s. you can customize the way I help with merging this pull request, such as holding this pull request until a specific person approves. Simply @mention me (@msftbot) and give me an instruction to get started! Learn more here.

@ghost
ghost merged commit c0a710f into dotnet:mainApr 6, 2021
thaystg added a commit to thaystg/runtime that referenced this pull request Apr 6, 2021
…shim_mono
# By Aaron Robinson (10) and others
# Via GitHub
* upstream/main: (108 commits)
[mbr] Add Apple sample (dotnet#50740)
make EstablishProxyTunnelAsync throw on failure status code from proxy (dotnet#50763)
Improve RGB Min Max evaluation performance by using 2 or 3 comparison… (dotnet#50622)
[mono] More domain cleanups (dotnet#50479)
Fix Crossgen2 of PlatformDefaultMemberFunction methods and calls. (dotnet#50754)
Disable EventSource generator in design-time builds (dotnet#50741)
Fix X509 test failures on Android (dotnet#50301)
Do not confuse fgDispBasicBlocks in fgMorphBlocks (dotnet#50703)
Enforce 64KB event payload size limit on EventPipe (dotnet#50600)
Reorganize CoreCLR native build to reduce CMake reconfigures when the build system is untouched (dotnet#49906)
[mbr] Turn on hot reload for iOS, tvOS and MacCatalyst (dotnet#50458)
improve connection scavenge logic by doing zero-byte read (dotnet#50545)
Resolve call mdtokens when making tier 1 inline observations (dotnet#50675)
Annotate APIs in System.Private.Xml (dotnet#49682)
Support compiling against OpenSSL 3 headers
Change Configuration.Json to use a regular Dictionary. (dotnet#50611)
Remove unused BigNumFromBinary P/Invoke (dotnet#50670)
Make Ninja the default CMake generator on Windows for the repo (dotnet#49715)
[AppleAppBuilder] Entitlements to run tests on catalyst using the JIT (dotnet#50637)
[mono] Fix delegate invokes to dynamic methods in mixed mode. (dotnet#50547)
...
# Conflicts:
#	src/mono/dlls/mscordbi/CMakeLists.txt
@ghostghost locked as resolved and limited conversation to collaborators May 6, 2021
@karelzkarelz added this to the 6.0.0 milestone May 20, 2021
@jkoritzinsky
jkoritzinsky deleted the x509certs-test-fixes branch September 28, 2021 00:04
This pull request was closed.
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

System.Security.Cryptography.X509Certificates.Tests fail on Android

5 participants

@jkoritzinsky@elinor-fung@steveisok@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Fix X509 test failures on Android - #50301

Merged
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes
Apr 6, 2021
Merged

Fix X509 test failures on Android#50301
15 commits merged into
dotnet:mainfrom
jkoritzinsky:x509certs-test-fixes

Conversation

@jkoritzinsky

@jkoritzinskyjkoritzinsky commented Mar 26, 2021

Copy link
Copy Markdown
Member

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Fixes#50565

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @bartonjs, @vcsjones, @krwq, @GrabYourPitchforks
See info in area-owners.md if you want to be subscribed.

Issue Details

Disable tests on Android that use unsupported features (Brainpool curve, PSS padding in cert signatures).

Disable outerloop test that checks against a validation status that is unsupported on Android.

Handle JNI thread shutdown (Android API Level 21 is more strict about this than API Level 29).

Fix some memory leaks.

Disable tests that depend on OCSP when on older Android versions.

Older versions of Android can include the same cert in the cert collection twice if it is also the trusted root. Handle this case and don't return the cert twice.

Author:jkoritzinsky
Assignees:-
Labels:

area-System.Security, os-android

Milestone:-

Comment on lines 102 to +108
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">
<Compile Include="X509StoreMutableTests.Android.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' != 'true'">
<Compile Include="RevocationTests\DynamicRevocationTests.Default.cs" />
</ItemGroup>
<ItemGroup Condition="'$(UseAndroidCrypto)' == 'true'">

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's reuse existing groups when possible.

@jkoritzinsky

This comment has been minimized.

@elinor-fung

Copy link
Copy Markdown
Member

CI wasm failure is happening because of the added[ConditionalClass(typeof(DynamicRevocationTests), nameof(SupportsDynamicRevocation))] attribute. During test discovery, this results in DynamicRevocationTests being loaded and its static fields being initialized. This fails because using Oid from System.Security.Cryptography.Encoding is throwing PNSE on browser.

privatestaticreadonlyOids_tlsServerOid=newOid("1.3.6.1.5.5.7.3.1",null);

This entire test assembly is actually disabled / marked as failing on browser:

[assembly:ActiveIssue("https://github.com/dotnet/runtime/issues/37669",TestPlatforms.Browser)]

But the test discovery still goes through every test method and tries to determine the traits for each method. We could rework this so that it continues avoiding using any types that will hit PNSE on browser during test discovery, but it seems weird/wasteful that we're making our test runs go through bundling, sending off to helix, test discovery, and result reporting when we know the entire suite (and many of its dependencies) are not currently supported.

@steveisok / @lewing is there a reason we want to have this suite disabled on browser through the ActiveIssue attribute instead of adding it to ProjectExclusions?

@steveisok

Copy link
Copy Markdown
Member

@elinor-fung There was probably a point in time where we thought labeling ActiveIssue at the assembly level was the way to skip whole suites. I think it makes sense to add to <ProjectExclusions> instead.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PublicKeyTests.SupportsBrainpool shouldn't be needed.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for humoring me.

@ghost

ghost commented Apr 5, 2021

Copy link
Copy Markdown

Hello @jkoritzinsky!

Because this pull request has the auto-merge label, I will be glad to assist with helping to merge this pull request once all check-in policies pass.

p.s. you can customize the way I help with merging this pull request, such as holding this pull request until a specific person approves. Simply @mention me (@msftbot) and give me an instruction to get started! Learn more here.

@ghost
ghost merged commit c0a710f into dotnet:mainApr 6, 2021
thaystg added a commit to thaystg/runtime that referenced this pull request Apr 6, 2021
…shim_mono
# By Aaron Robinson (10) and others
# Via GitHub
* upstream/main: (108 commits)
[mbr] Add Apple sample (dotnet#50740)
make EstablishProxyTunnelAsync throw on failure status code from proxy (dotnet#50763)
Improve RGB Min Max evaluation performance by using 2 or 3 comparison… (dotnet#50622)
[mono] More domain cleanups (dotnet#50479)
Fix Crossgen2 of PlatformDefaultMemberFunction methods and calls. (dotnet#50754)
Disable EventSource generator in design-time builds (dotnet#50741)
Fix X509 test failures on Android (dotnet#50301)
Do not confuse fgDispBasicBlocks in fgMorphBlocks (dotnet#50703)
Enforce 64KB event payload size limit on EventPipe (dotnet#50600)
Reorganize CoreCLR native build to reduce CMake reconfigures when the build system is untouched (dotnet#49906)
[mbr] Turn on hot reload for iOS, tvOS and MacCatalyst (dotnet#50458)
improve connection scavenge logic by doing zero-byte read (dotnet#50545)
Resolve call mdtokens when making tier 1 inline observations (dotnet#50675)
Annotate APIs in System.Private.Xml (dotnet#49682)
Support compiling against OpenSSL 3 headers
Change Configuration.Json to use a regular Dictionary. (dotnet#50611)
Remove unused BigNumFromBinary P/Invoke (dotnet#50670)
Make Ninja the default CMake generator on Windows for the repo (dotnet#49715)
[AppleAppBuilder] Entitlements to run tests on catalyst using the JIT (dotnet#50637)
[mono] Fix delegate invokes to dynamic methods in mixed mode. (dotnet#50547)
...
# Conflicts:
#	src/mono/dlls/mscordbi/CMakeLists.txt
@ghostghost locked as resolved and limited conversation to collaborators May 6, 2021
@karelzkarelz added this to the 6.0.0 milestone May 20, 2021
@jkoritzinsky
jkoritzinsky deleted the x509certs-test-fixes branch September 28, 2021 00:04
This pull request was closed.
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

System.Security.Cryptography.X509Certificates.Tests fail on Android

5 participants

@jkoritzinsky@elinor-fung@steveisok@bartonjs@karelz