mirror of
https://github.com/espressif/openthread.git
synced 2026-07-28 14:47:46 +00:00
This commit adds a new Nexus test case for 'Key Increment of 1 with
Roll-over' (6.6.2) as specified in the test specification.
The test verifies that the DUT properly decrypts MAC and MLE packets
secured with a Key Index incremented by 1 (causing a rollover) and
switches to the new key.
Summary of changes:
- Implemented Nexus test 6.6.2:
- Added tests/nexus/test_6_6_2.cpp: Implements the test execution
for both Topology A (End Device 'ED_1') and Topology B (Sleepy
End Device 'SED_1'). The test initializes the network with
KeySequenceCounter = 127, then increments it to 128 to force
a key switch and rollover. The test uses direct method calls,
sets log level to note, and uses AllowList for connectivity.
- Added tests/nexus/verify_6_6_2.py: PCAP verification script.
Validates MLE Child ID Request and ICMPv6 Echo packets use the
expected Key Index (128 then 1), Key Source (127), and
Key ID Mode.
- Updated build and execution scripts:
- Modified tests/nexus/CMakeLists.txt to build the new test.
- Updated tests/nexus/run_nexus_tests.sh to include 6_6_2 in the
default test list and added expansion logic for A/B topologies.
This commit is contained in:
@@ -176,6 +176,7 @@ ot_nexus_test(6_4_1 "cert;nexus")
|
||||
ot_nexus_test(6_4_2 "cert;nexus")
|
||||
ot_nexus_test(6_5_1 "cert;nexus")
|
||||
ot_nexus_test(6_6_1 "cert;nexus")
|
||||
ot_nexus_test(6_6_2 "cert;nexus")
|
||||
ot_nexus_test(7_1_1 "cert;nexus")
|
||||
|
||||
# Misc tests
|
||||
|
||||
@@ -112,6 +112,7 @@ DEFAULT_TESTS=(
|
||||
"6_4_2"
|
||||
"6_5_1"
|
||||
"6_6_1"
|
||||
"6_6_2"
|
||||
"7_1_1"
|
||||
)
|
||||
|
||||
@@ -204,7 +205,7 @@ run_test()
|
||||
expanded_tests=()
|
||||
for t in "${TESTS_TO_RUN[@]}"; do
|
||||
case "$t" in
|
||||
6_1_1 | 6_1_2 | 6_1_3 | 6_2_1 | 6_2_2 | 6_3_1 | 6_3_2 | 6_4_1 | 6_4_2 | 6_5_1 | 6_6_1)
|
||||
6_1_1 | 6_1_2 | 6_1_3 | 6_2_1 | 6_2_2 | 6_3_1 | 6_3_2 | 6_4_1 | 6_4_2 | 6_5_1 | 6_6_1 | 6_6_2)
|
||||
expanded_tests+=("${t}_A" "${t}_B")
|
||||
;;
|
||||
*)
|
||||
|
||||
@@ -0,0 +1,265 @@
|
||||
/*
|
||||
* Copyright (c) 2026, The OpenThread Authors.
|
||||
* All rights reserved.
|
||||
*
|
||||
* Redistribution and use in source and binary forms, with or without
|
||||
* modification, are permitted provided that the following conditions are met:
|
||||
* 1. Redistributions of source code must retain the above copyright
|
||||
* notice, this list of conditions and the following disclaimer.
|
||||
* 2. Redistributions in binary form must reproduce the above copyright
|
||||
* notice, this list of conditions and the following disclaimer in the
|
||||
* documentation and/or other materials provided with the distribution.
|
||||
* 3. Neither the name of the copyright holder nor the
|
||||
* names of its contributors may be used to endorse or promote products
|
||||
* derived from this software without specific prior written permission.
|
||||
*
|
||||
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
|
||||
* AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
* ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
|
||||
* LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
||||
* INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
||||
* CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
||||
* POSSIBILITY OF SUCH DAMAGE.
|
||||
*/
|
||||
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
|
||||
#include "mac/data_poll_sender.hpp"
|
||||
#include "platform/nexus_core.hpp"
|
||||
#include "platform/nexus_node.hpp"
|
||||
#include "thread/key_manager.hpp"
|
||||
|
||||
namespace ot {
|
||||
namespace Nexus {
|
||||
|
||||
/**
|
||||
* Time to advance for a node to form a network and become leader, in milliseconds.
|
||||
*/
|
||||
static constexpr uint32_t kFormNetworkTime = 13 * 1000;
|
||||
|
||||
/**
|
||||
* Time to advance for the DUT to attach to the leader, in milliseconds.
|
||||
*/
|
||||
static constexpr uint32_t kAttachTime = 10 * 1000;
|
||||
|
||||
/**
|
||||
* Time to wait for ICMPv6 Echo response, in milliseconds.
|
||||
*/
|
||||
static constexpr uint32_t kEchoTimeout = 5000;
|
||||
|
||||
/**
|
||||
* Data poll period for SED, in milliseconds.
|
||||
*/
|
||||
static constexpr uint32_t kPollPeriod = 500;
|
||||
|
||||
/**
|
||||
* Initial key sequence counter.
|
||||
*/
|
||||
static constexpr uint32_t kInitialKeySequence = 127;
|
||||
|
||||
/**
|
||||
* Next key sequence counter.
|
||||
*/
|
||||
static constexpr uint32_t kNextKeySequence = 128;
|
||||
|
||||
enum Topology
|
||||
{
|
||||
kTopologyA,
|
||||
kTopologyB,
|
||||
};
|
||||
|
||||
void RunTest6_6_2(Topology aTopology, const char *aJsonFile)
|
||||
{
|
||||
/**
|
||||
* 6.6.2 Key Increment of 1 with Roll-over
|
||||
*
|
||||
* 6.6.2.1 Topology
|
||||
* - Topology A: DUT as End Device (ED_1)
|
||||
* - Topology B: DUT as Sleepy End Device (SED_1)
|
||||
* - Leader
|
||||
*
|
||||
* 6.6.2.2 Purpose & Description
|
||||
* The purpose of this test case is to verify that the DUT properly decrypts MAC and MLE packets secured with a Key
|
||||
* Index incremented by 1 (which causes a rollover) and switches to the new key.
|
||||
*
|
||||
* Spec Reference | V1.1 Section | V1.3.0 Section
|
||||
* --------------------------------|--------------|---------------
|
||||
* MLE Message Security Processing | 7.3.1 | 7.3.1
|
||||
*/
|
||||
|
||||
Core nexus;
|
||||
|
||||
Node &leader = nexus.CreateNode();
|
||||
Node &dut = nexus.CreateNode();
|
||||
|
||||
leader.SetName("LEADER");
|
||||
|
||||
if (aTopology == kTopologyA)
|
||||
{
|
||||
dut.SetName("ED_1");
|
||||
}
|
||||
else
|
||||
{
|
||||
dut.SetName("SED_1");
|
||||
}
|
||||
|
||||
nexus.AdvanceTime(0);
|
||||
|
||||
Instance::SetLogLevel(kLogLevelNote);
|
||||
|
||||
if (aTopology == kTopologyA)
|
||||
{
|
||||
Log("---------------------------------------------------------------------------------------");
|
||||
Log("Topology A: ED_1 (DUT)");
|
||||
}
|
||||
else
|
||||
{
|
||||
Log("---------------------------------------------------------------------------------------");
|
||||
Log("Topology B: SED_1 (DUT)");
|
||||
}
|
||||
|
||||
Log("---------------------------------------------------------------------------------------");
|
||||
Log("Step 1: Leader");
|
||||
|
||||
/**
|
||||
* Step 1: Leader
|
||||
* - Description: Harness instructs the device to form the network using thrKeySequenceCounter = 0x7F (127).
|
||||
* - Pass Criteria: N/A
|
||||
*/
|
||||
leader.AllowList(dut);
|
||||
dut.AllowList(leader);
|
||||
|
||||
leader.Form();
|
||||
leader.Get<KeyManager>().SetCurrentKeySequence(kInitialKeySequence,
|
||||
KeyManager::kForceUpdate | KeyManager::kGuardTimerUnchanged);
|
||||
|
||||
nexus.AdvanceTime(kFormNetworkTime);
|
||||
VerifyOrQuit(leader.Get<Mle::Mle>().IsLeader());
|
||||
|
||||
Log("---------------------------------------------------------------------------------------");
|
||||
Log("Step 2: ED_1 / SED_1 (DUT)");
|
||||
|
||||
/**
|
||||
* Step 2: ED_1 / SED_1 (DUT)
|
||||
* - Description: Attach the DUT to the network.
|
||||
* - Pass Criteria:
|
||||
* - The MLE Auxiliary Security Header of the MLE Child ID Request MUST contain:
|
||||
* - Key Source = 0x7F (127)
|
||||
* - Key Index = 0x80 (128)
|
||||
* - Key ID Mode = 2
|
||||
*/
|
||||
if (aTopology == kTopologyA)
|
||||
{
|
||||
dut.Join(leader, Node::kAsMed);
|
||||
}
|
||||
else
|
||||
{
|
||||
dut.Join(leader, Node::kAsSed);
|
||||
SuccessOrQuit(dut.Get<DataPollSender>().SetExternalPollPeriod(kPollPeriod));
|
||||
}
|
||||
|
||||
nexus.AdvanceTime(kAttachTime);
|
||||
VerifyOrQuit(dut.Get<Mle::Mle>().IsChild());
|
||||
|
||||
Log("---------------------------------------------------------------------------------------");
|
||||
Log("Step 3: Leader");
|
||||
|
||||
/**
|
||||
* Step 3: Leader
|
||||
* - Description: Harness instructs the device to send an ICMPv6 Echo Request to the DUT. The MAC Auxiliary
|
||||
* security header contains:
|
||||
* - Key Index = 0x80 (128)
|
||||
* - Key ID Mode = 1
|
||||
* - Pass Criteria: N/A
|
||||
*/
|
||||
leader.SendEchoRequest(dut.Get<Mle::Mle>().GetLinkLocalAddress(), 0, 0, 64);
|
||||
|
||||
Log("---------------------------------------------------------------------------------------");
|
||||
Log("Step 4: ED_1 / SED_1 (DUT)");
|
||||
|
||||
/**
|
||||
* Step 4: ED_1 / SED_1 (DUT)
|
||||
* - Description: Automatically replies with ICMPv6 Echo Reply.
|
||||
* - Pass Criteria:
|
||||
* - The DUT MUST reply with ICMPv6 Echo Reply.
|
||||
* - The MAC Auxiliary Security Header MUST contain:
|
||||
* - Key Index = 0x80 (128)
|
||||
* - Key ID Mode = 1
|
||||
*/
|
||||
nexus.AdvanceTime(kEchoTimeout);
|
||||
|
||||
Log("---------------------------------------------------------------------------------------");
|
||||
Log("Step 5: Leader");
|
||||
|
||||
/**
|
||||
* Step 5: Leader
|
||||
* - Description: Harness instructs the device to increment thrKeySequenceCounter by 1 to force a key switch.
|
||||
* Incoming frame counters shall be set to 0 for all existing devices. All subsequent MLE and MAC frames are sent
|
||||
* with Key Index = 1.
|
||||
* - Pass Criteria: N/A
|
||||
*/
|
||||
leader.Get<KeyManager>().SetCurrentKeySequence(kNextKeySequence,
|
||||
KeyManager::kForceUpdate | KeyManager::kGuardTimerUnchanged);
|
||||
|
||||
Log("---------------------------------------------------------------------------------------");
|
||||
Log("Step 6: Leader");
|
||||
|
||||
/**
|
||||
* Step 6: Leader
|
||||
* - Description: Harness instructs the device to send an ICMPv6 Echo Request to the DUT. The MAC Auxiliary
|
||||
* Security Header contains:
|
||||
* - Key Index = 1
|
||||
* - Key ID Mode = 1
|
||||
* - Pass Criteria: N/A
|
||||
*/
|
||||
leader.SendEchoRequest(dut.Get<Mle::Mle>().GetLinkLocalAddress(), 1, 0, 64);
|
||||
|
||||
Log("---------------------------------------------------------------------------------------");
|
||||
Log("Step 7: ED_1 / SED_1 (DUT)");
|
||||
|
||||
/**
|
||||
* Step 7: ED_1 / SED_1 (DUT)
|
||||
* - Description: Automatically replies with ICMPv6 Echo Reply.
|
||||
* - Pass Criteria:
|
||||
* - The DUT MUST reply with ICMPv6 Echo Reply.
|
||||
* - The MAC Auxiliary Security Header MUST contain:
|
||||
* - Key Index = 1
|
||||
* - Key ID Mode = 1
|
||||
*/
|
||||
nexus.AdvanceTime(kEchoTimeout);
|
||||
|
||||
nexus.SaveTestInfo(aJsonFile);
|
||||
}
|
||||
|
||||
} // namespace Nexus
|
||||
} // namespace ot
|
||||
|
||||
int main(int argc, char *argv[])
|
||||
{
|
||||
if (argc < 2)
|
||||
{
|
||||
ot::Nexus::RunTest6_6_2(ot::Nexus::kTopologyA, "test_6_6_2_A.json");
|
||||
ot::Nexus::RunTest6_6_2(ot::Nexus::kTopologyB, "test_6_6_2_B.json");
|
||||
}
|
||||
else if (strcmp(argv[1], "A") == 0)
|
||||
{
|
||||
ot::Nexus::RunTest6_6_2(ot::Nexus::kTopologyA, (argc > 2) ? argv[2] : "test_6_6_2_A.json");
|
||||
}
|
||||
else if (strcmp(argv[1], "B") == 0)
|
||||
{
|
||||
ot::Nexus::RunTest6_6_2(ot::Nexus::kTopologyB, (argc > 2) ? argv[2] : "test_6_6_2_B.json");
|
||||
}
|
||||
else
|
||||
{
|
||||
fprintf(stderr, "Error: Invalid topology '%s'. Must be 'A' or 'B'.\n", argv[1]);
|
||||
return 1;
|
||||
}
|
||||
|
||||
printf("All tests passed\n");
|
||||
return 0;
|
||||
}
|
||||
@@ -0,0 +1,163 @@
|
||||
#!/usr/bin/env python3
|
||||
#
|
||||
# Copyright (c) 2026, The OpenThread Authors.
|
||||
# All rights reserved.
|
||||
#
|
||||
# Redistribution and use in source and binary forms, with or without
|
||||
# modification, are permitted provided that the following conditions are met:
|
||||
# 1. Redistributions of source code must retain the above copyright
|
||||
# notice, this list of conditions and the following disclaimer.
|
||||
# 2. Redistributions in binary form must reproduce the above copyright
|
||||
# notice, this list of conditions and the following disclaimer in the
|
||||
# documentation and/or other materials provided with the distribution.
|
||||
# 3. Neither the name of the copyright holder nor the
|
||||
# names of its contributors may be used to endorse or promote products
|
||||
# derived from this software without specific prior written permission.
|
||||
#
|
||||
# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
|
||||
# AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
# ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
|
||||
# LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
||||
# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
||||
# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
||||
# POSSIBILITY OF SUCH DAMAGE.
|
||||
#
|
||||
|
||||
import sys
|
||||
import os
|
||||
|
||||
# Add the current directory to sys.path to find verify_utils
|
||||
CUR_DIR = os.path.dirname(os.path.abspath(__file__))
|
||||
sys.path.append(CUR_DIR)
|
||||
|
||||
import verify_utils
|
||||
from pktverify import consts
|
||||
|
||||
|
||||
def verify(pv):
|
||||
# 6.6.2 Key Increment of 1 with Roll-over
|
||||
#
|
||||
# 6.6.2.1 Topology
|
||||
# - Topology A: DUT as End Device (ED_1)
|
||||
# - Topology B: DUT as Sleepy End Device (SED_1)
|
||||
# - Leader
|
||||
#
|
||||
# 6.6.2.2 Purpose & Description
|
||||
# The purpose of this test case is to verify that the DUT properly decrypts MAC and MLE packets secured with a Key
|
||||
# Index incremented by 1 (which causes a rollover) and switches to the new key.
|
||||
#
|
||||
# Spec Reference | V1.1 Section | V1.3.0 Section
|
||||
# --------------------------------|--------------|---------------
|
||||
# MLE Message Security Processing | 7.3.1 | 7.3.1
|
||||
|
||||
pkts = pv.pkts
|
||||
pv.summary.show()
|
||||
|
||||
LEADER = pv.vars['LEADER']
|
||||
|
||||
if 'ED_1' in pv.vars:
|
||||
dut = pv.vars['ED_1']
|
||||
name = 'ED_1'
|
||||
elif 'SED_1' in pv.vars:
|
||||
dut = pv.vars['SED_1']
|
||||
name = 'SED_1'
|
||||
else:
|
||||
raise ValueError("Neither ED_1 nor SED_1 found in topology vars")
|
||||
|
||||
# Step 1: Leader
|
||||
# - Description: Harness instructs the device to form the network using thrKeySequenceCounter = 0x7F (127).
|
||||
# - Pass Criteria: N/A
|
||||
print("Step 1: Leader forms the network using thrKeySequenceCounter = 0x7F (127).")
|
||||
|
||||
# Step 2: ED_1 / SED_1 (DUT)
|
||||
# - Description: Attach the DUT to the network.
|
||||
# - Pass Criteria:
|
||||
# - The MLE Auxiliary Security Header of the MLE Child ID Request MUST contain:
|
||||
# - Key Source = 0x7F (127)
|
||||
# - Key Index = 0x80 (128)
|
||||
# - Key ID Mode = 2
|
||||
print(f"Step 2: {name} (DUT) sends a MLE Child ID Request.")
|
||||
|
||||
pkts.filter_wpan_src64(dut).\
|
||||
filter_wpan_dst64(LEADER).\
|
||||
filter_mle_cmd(consts.MLE_CHILD_ID_REQUEST).\
|
||||
filter(lambda p: p.wpan.aux_sec.key_id_mode == 2).\
|
||||
filter(lambda p: p.wpan.aux_sec.key_index == 128).\
|
||||
filter(lambda p: p.wpan.aux_sec.key_source == 127).\
|
||||
must_next()
|
||||
|
||||
# Step 3: Leader
|
||||
# - Description: Harness instructs the device to send an ICMPv6 Echo Request to the DUT. The MAC Auxiliary security
|
||||
# header contains:
|
||||
# - Key Index = 0x80 (128)
|
||||
# - Key ID Mode = 1
|
||||
# - Pass Criteria: N/A
|
||||
print("Step 3: Leader sends an ICMPv6 Echo Request to the DUT.")
|
||||
|
||||
pkts.filter_ping_request().\
|
||||
filter_wpan_src64(LEADER).\
|
||||
filter_wpan_dst64(dut).\
|
||||
filter(lambda p: p.wpan.aux_sec.key_id_mode == 1).\
|
||||
filter(lambda p: p.wpan.aux_sec.key_index == 128).\
|
||||
must_next()
|
||||
|
||||
# Step 4: ED_1 / SED_1 (DUT)
|
||||
# - Description: Automatically replies with ICMPv6 Echo Reply.
|
||||
# - Pass Criteria:
|
||||
# - The DUT MUST reply with ICMPv6 Echo Reply.
|
||||
# - The MAC Auxiliary Security Header MUST contain:
|
||||
# - Key Index = 0x80 (128)
|
||||
# - Key ID Mode = 1
|
||||
print(f"Step 4: {name} (DUT) MUST reply with ICMPv6 Echo Reply.")
|
||||
|
||||
pkts.filter_ping_reply().\
|
||||
filter_wpan_src64(dut).\
|
||||
filter_wpan_dst64(LEADER).\
|
||||
filter(lambda p: p.wpan.aux_sec.key_id_mode == 1).\
|
||||
filter(lambda p: p.wpan.aux_sec.key_index == 128).\
|
||||
must_next()
|
||||
|
||||
# Step 5: Leader
|
||||
# - Description: Harness instructs the device to increment thrKeySequenceCounter by 1 to force a key switch.
|
||||
# Incoming frame counters shall be set to 0 for all existing devices. All subsequent MLE and MAC frames are sent
|
||||
# with Key Index = 1.
|
||||
print("Step 5: Leader increments thrKeySequenceCounter by 1 to force a key switch.")
|
||||
|
||||
# Step 6: Leader
|
||||
# - Description: Harness instructs the device to send an ICMPv6 Echo Request to the DUT. The MAC Auxiliary Security
|
||||
# Header contains:
|
||||
# - Key Index = 1
|
||||
# - Key ID Mode = 1
|
||||
# - Pass Criteria: N/A
|
||||
print("Step 6: Leader sends an ICMPv6 Echo Request to the DUT.")
|
||||
|
||||
pkts.filter_ping_request().\
|
||||
filter_wpan_src64(LEADER).\
|
||||
filter_wpan_dst64(dut).\
|
||||
filter(lambda p: p.wpan.aux_sec.key_id_mode == 1).\
|
||||
filter(lambda p: p.wpan.aux_sec.key_index == 1).\
|
||||
must_next()
|
||||
|
||||
# Step 7: ED_1 / SED_1 (DUT)
|
||||
# - Description: Automatically replies with ICMPv6 Echo Reply.
|
||||
# - Pass Criteria:
|
||||
# - The DUT MUST reply with ICMPv6 Echo Reply.
|
||||
# - The MAC Auxiliary Security Header MUST contain:
|
||||
# - Key Index = 1
|
||||
# - Key ID Mode = 1
|
||||
print(f"Step 7: {name} (DUT) MUST reply with ICMPv6 Echo Reply.")
|
||||
|
||||
pkts.filter_ping_reply().\
|
||||
filter_wpan_src64(dut).\
|
||||
filter_wpan_dst64(LEADER).\
|
||||
filter(lambda p: p.wpan.aux_sec.key_id_mode == 1).\
|
||||
filter(lambda p: p.wpan.aux_sec.key_index == 1).\
|
||||
must_next()
|
||||
|
||||
|
||||
if __name__ == '__main__':
|
||||
verify_utils.run_main(verify)
|
||||
Reference in New Issue
Block a user