From 6c637004843796ccb7a6713330ebd6032c16703d Mon Sep 17 00:00:00 2001 From: Jonathan Hui Date: Thu, 19 Feb 2026 17:31:54 -0600 Subject: [PATCH] [nexus] add test 6.6.2 Key Increment of 1 with Roll-over (#12490) (#12497) This commit adds a new Nexus test case for 'Key Increment of 1 with Roll-over' (6.6.2) as specified in the test specification. The test verifies that the DUT properly decrypts MAC and MLE packets secured with a Key Index incremented by 1 (causing a rollover) and switches to the new key. Summary of changes: - Implemented Nexus test 6.6.2: - Added tests/nexus/test_6_6_2.cpp: Implements the test execution for both Topology A (End Device 'ED_1') and Topology B (Sleepy End Device 'SED_1'). The test initializes the network with KeySequenceCounter = 127, then increments it to 128 to force a key switch and rollover. The test uses direct method calls, sets log level to note, and uses AllowList for connectivity. - Added tests/nexus/verify_6_6_2.py: PCAP verification script. Validates MLE Child ID Request and ICMPv6 Echo packets use the expected Key Index (128 then 1), Key Source (127), and Key ID Mode. - Updated build and execution scripts: - Modified tests/nexus/CMakeLists.txt to build the new test. - Updated tests/nexus/run_nexus_tests.sh to include 6_6_2 in the default test list and added expansion logic for A/B topologies. --- tests/nexus/CMakeLists.txt | 1 + tests/nexus/run_nexus_tests.sh | 3 +- tests/nexus/test_6_6_2.cpp | 265 +++++++++++++++++++++++++++++++++ tests/nexus/verify_6_6_2.py | 163 ++++++++++++++++++++ 4 files changed, 431 insertions(+), 1 deletion(-) create mode 100644 tests/nexus/test_6_6_2.cpp create mode 100644 tests/nexus/verify_6_6_2.py diff --git a/tests/nexus/CMakeLists.txt b/tests/nexus/CMakeLists.txt index 3be1a95e7..80b5a34b2 100644 --- a/tests/nexus/CMakeLists.txt +++ b/tests/nexus/CMakeLists.txt @@ -176,6 +176,7 @@ ot_nexus_test(6_4_1 "cert;nexus") ot_nexus_test(6_4_2 "cert;nexus") ot_nexus_test(6_5_1 "cert;nexus") ot_nexus_test(6_6_1 "cert;nexus") +ot_nexus_test(6_6_2 "cert;nexus") ot_nexus_test(7_1_1 "cert;nexus") # Misc tests diff --git a/tests/nexus/run_nexus_tests.sh b/tests/nexus/run_nexus_tests.sh index a96e84fc0..8dcfe6373 100755 --- a/tests/nexus/run_nexus_tests.sh +++ b/tests/nexus/run_nexus_tests.sh @@ -112,6 +112,7 @@ DEFAULT_TESTS=( "6_4_2" "6_5_1" "6_6_1" + "6_6_2" "7_1_1" ) @@ -204,7 +205,7 @@ run_test() expanded_tests=() for t in "${TESTS_TO_RUN[@]}"; do case "$t" in - 6_1_1 | 6_1_2 | 6_1_3 | 6_2_1 | 6_2_2 | 6_3_1 | 6_3_2 | 6_4_1 | 6_4_2 | 6_5_1 | 6_6_1) + 6_1_1 | 6_1_2 | 6_1_3 | 6_2_1 | 6_2_2 | 6_3_1 | 6_3_2 | 6_4_1 | 6_4_2 | 6_5_1 | 6_6_1 | 6_6_2) expanded_tests+=("${t}_A" "${t}_B") ;; *) diff --git a/tests/nexus/test_6_6_2.cpp b/tests/nexus/test_6_6_2.cpp new file mode 100644 index 000000000..15a686dd7 --- /dev/null +++ b/tests/nexus/test_6_6_2.cpp @@ -0,0 +1,265 @@ +/* + * Copyright (c) 2026, The OpenThread Authors. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. Neither the name of the copyright holder nor the + * names of its contributors may be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" + * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE + * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + * POSSIBILITY OF SUCH DAMAGE. + */ + +#include +#include + +#include "mac/data_poll_sender.hpp" +#include "platform/nexus_core.hpp" +#include "platform/nexus_node.hpp" +#include "thread/key_manager.hpp" + +namespace ot { +namespace Nexus { + +/** + * Time to advance for a node to form a network and become leader, in milliseconds. + */ +static constexpr uint32_t kFormNetworkTime = 13 * 1000; + +/** + * Time to advance for the DUT to attach to the leader, in milliseconds. + */ +static constexpr uint32_t kAttachTime = 10 * 1000; + +/** + * Time to wait for ICMPv6 Echo response, in milliseconds. + */ +static constexpr uint32_t kEchoTimeout = 5000; + +/** + * Data poll period for SED, in milliseconds. + */ +static constexpr uint32_t kPollPeriod = 500; + +/** + * Initial key sequence counter. + */ +static constexpr uint32_t kInitialKeySequence = 127; + +/** + * Next key sequence counter. + */ +static constexpr uint32_t kNextKeySequence = 128; + +enum Topology +{ + kTopologyA, + kTopologyB, +}; + +void RunTest6_6_2(Topology aTopology, const char *aJsonFile) +{ + /** + * 6.6.2 Key Increment of 1 with Roll-over + * + * 6.6.2.1 Topology + * - Topology A: DUT as End Device (ED_1) + * - Topology B: DUT as Sleepy End Device (SED_1) + * - Leader + * + * 6.6.2.2 Purpose & Description + * The purpose of this test case is to verify that the DUT properly decrypts MAC and MLE packets secured with a Key + * Index incremented by 1 (which causes a rollover) and switches to the new key. + * + * Spec Reference | V1.1 Section | V1.3.0 Section + * --------------------------------|--------------|--------------- + * MLE Message Security Processing | 7.3.1 | 7.3.1 + */ + + Core nexus; + + Node &leader = nexus.CreateNode(); + Node &dut = nexus.CreateNode(); + + leader.SetName("LEADER"); + + if (aTopology == kTopologyA) + { + dut.SetName("ED_1"); + } + else + { + dut.SetName("SED_1"); + } + + nexus.AdvanceTime(0); + + Instance::SetLogLevel(kLogLevelNote); + + if (aTopology == kTopologyA) + { + Log("---------------------------------------------------------------------------------------"); + Log("Topology A: ED_1 (DUT)"); + } + else + { + Log("---------------------------------------------------------------------------------------"); + Log("Topology B: SED_1 (DUT)"); + } + + Log("---------------------------------------------------------------------------------------"); + Log("Step 1: Leader"); + + /** + * Step 1: Leader + * - Description: Harness instructs the device to form the network using thrKeySequenceCounter = 0x7F (127). + * - Pass Criteria: N/A + */ + leader.AllowList(dut); + dut.AllowList(leader); + + leader.Form(); + leader.Get().SetCurrentKeySequence(kInitialKeySequence, + KeyManager::kForceUpdate | KeyManager::kGuardTimerUnchanged); + + nexus.AdvanceTime(kFormNetworkTime); + VerifyOrQuit(leader.Get().IsLeader()); + + Log("---------------------------------------------------------------------------------------"); + Log("Step 2: ED_1 / SED_1 (DUT)"); + + /** + * Step 2: ED_1 / SED_1 (DUT) + * - Description: Attach the DUT to the network. + * - Pass Criteria: + * - The MLE Auxiliary Security Header of the MLE Child ID Request MUST contain: + * - Key Source = 0x7F (127) + * - Key Index = 0x80 (128) + * - Key ID Mode = 2 + */ + if (aTopology == kTopologyA) + { + dut.Join(leader, Node::kAsMed); + } + else + { + dut.Join(leader, Node::kAsSed); + SuccessOrQuit(dut.Get().SetExternalPollPeriod(kPollPeriod)); + } + + nexus.AdvanceTime(kAttachTime); + VerifyOrQuit(dut.Get().IsChild()); + + Log("---------------------------------------------------------------------------------------"); + Log("Step 3: Leader"); + + /** + * Step 3: Leader + * - Description: Harness instructs the device to send an ICMPv6 Echo Request to the DUT. The MAC Auxiliary + * security header contains: + * - Key Index = 0x80 (128) + * - Key ID Mode = 1 + * - Pass Criteria: N/A + */ + leader.SendEchoRequest(dut.Get().GetLinkLocalAddress(), 0, 0, 64); + + Log("---------------------------------------------------------------------------------------"); + Log("Step 4: ED_1 / SED_1 (DUT)"); + + /** + * Step 4: ED_1 / SED_1 (DUT) + * - Description: Automatically replies with ICMPv6 Echo Reply. + * - Pass Criteria: + * - The DUT MUST reply with ICMPv6 Echo Reply. + * - The MAC Auxiliary Security Header MUST contain: + * - Key Index = 0x80 (128) + * - Key ID Mode = 1 + */ + nexus.AdvanceTime(kEchoTimeout); + + Log("---------------------------------------------------------------------------------------"); + Log("Step 5: Leader"); + + /** + * Step 5: Leader + * - Description: Harness instructs the device to increment thrKeySequenceCounter by 1 to force a key switch. + * Incoming frame counters shall be set to 0 for all existing devices. All subsequent MLE and MAC frames are sent + * with Key Index = 1. + * - Pass Criteria: N/A + */ + leader.Get().SetCurrentKeySequence(kNextKeySequence, + KeyManager::kForceUpdate | KeyManager::kGuardTimerUnchanged); + + Log("---------------------------------------------------------------------------------------"); + Log("Step 6: Leader"); + + /** + * Step 6: Leader + * - Description: Harness instructs the device to send an ICMPv6 Echo Request to the DUT. The MAC Auxiliary + * Security Header contains: + * - Key Index = 1 + * - Key ID Mode = 1 + * - Pass Criteria: N/A + */ + leader.SendEchoRequest(dut.Get().GetLinkLocalAddress(), 1, 0, 64); + + Log("---------------------------------------------------------------------------------------"); + Log("Step 7: ED_1 / SED_1 (DUT)"); + + /** + * Step 7: ED_1 / SED_1 (DUT) + * - Description: Automatically replies with ICMPv6 Echo Reply. + * - Pass Criteria: + * - The DUT MUST reply with ICMPv6 Echo Reply. + * - The MAC Auxiliary Security Header MUST contain: + * - Key Index = 1 + * - Key ID Mode = 1 + */ + nexus.AdvanceTime(kEchoTimeout); + + nexus.SaveTestInfo(aJsonFile); +} + +} // namespace Nexus +} // namespace ot + +int main(int argc, char *argv[]) +{ + if (argc < 2) + { + ot::Nexus::RunTest6_6_2(ot::Nexus::kTopologyA, "test_6_6_2_A.json"); + ot::Nexus::RunTest6_6_2(ot::Nexus::kTopologyB, "test_6_6_2_B.json"); + } + else if (strcmp(argv[1], "A") == 0) + { + ot::Nexus::RunTest6_6_2(ot::Nexus::kTopologyA, (argc > 2) ? argv[2] : "test_6_6_2_A.json"); + } + else if (strcmp(argv[1], "B") == 0) + { + ot::Nexus::RunTest6_6_2(ot::Nexus::kTopologyB, (argc > 2) ? argv[2] : "test_6_6_2_B.json"); + } + else + { + fprintf(stderr, "Error: Invalid topology '%s'. Must be 'A' or 'B'.\n", argv[1]); + return 1; + } + + printf("All tests passed\n"); + return 0; +} diff --git a/tests/nexus/verify_6_6_2.py b/tests/nexus/verify_6_6_2.py new file mode 100644 index 000000000..d1b960e67 --- /dev/null +++ b/tests/nexus/verify_6_6_2.py @@ -0,0 +1,163 @@ +#!/usr/bin/env python3 +# +# Copyright (c) 2026, The OpenThread Authors. +# All rights reserved. +# +# Redistribution and use in source and binary forms, with or without +# modification, are permitted provided that the following conditions are met: +# 1. Redistributions of source code must retain the above copyright +# notice, this list of conditions and the following disclaimer. +# 2. Redistributions in binary form must reproduce the above copyright +# notice, this list of conditions and the following disclaimer in the +# documentation and/or other materials provided with the distribution. +# 3. Neither the name of the copyright holder nor the +# names of its contributors may be used to endorse or promote products +# derived from this software without specific prior written permission. +# +# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +# AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +# ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +# LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +# POSSIBILITY OF SUCH DAMAGE. +# + +import sys +import os + +# Add the current directory to sys.path to find verify_utils +CUR_DIR = os.path.dirname(os.path.abspath(__file__)) +sys.path.append(CUR_DIR) + +import verify_utils +from pktverify import consts + + +def verify(pv): + # 6.6.2 Key Increment of 1 with Roll-over + # + # 6.6.2.1 Topology + # - Topology A: DUT as End Device (ED_1) + # - Topology B: DUT as Sleepy End Device (SED_1) + # - Leader + # + # 6.6.2.2 Purpose & Description + # The purpose of this test case is to verify that the DUT properly decrypts MAC and MLE packets secured with a Key + # Index incremented by 1 (which causes a rollover) and switches to the new key. + # + # Spec Reference | V1.1 Section | V1.3.0 Section + # --------------------------------|--------------|--------------- + # MLE Message Security Processing | 7.3.1 | 7.3.1 + + pkts = pv.pkts + pv.summary.show() + + LEADER = pv.vars['LEADER'] + + if 'ED_1' in pv.vars: + dut = pv.vars['ED_1'] + name = 'ED_1' + elif 'SED_1' in pv.vars: + dut = pv.vars['SED_1'] + name = 'SED_1' + else: + raise ValueError("Neither ED_1 nor SED_1 found in topology vars") + + # Step 1: Leader + # - Description: Harness instructs the device to form the network using thrKeySequenceCounter = 0x7F (127). + # - Pass Criteria: N/A + print("Step 1: Leader forms the network using thrKeySequenceCounter = 0x7F (127).") + + # Step 2: ED_1 / SED_1 (DUT) + # - Description: Attach the DUT to the network. + # - Pass Criteria: + # - The MLE Auxiliary Security Header of the MLE Child ID Request MUST contain: + # - Key Source = 0x7F (127) + # - Key Index = 0x80 (128) + # - Key ID Mode = 2 + print(f"Step 2: {name} (DUT) sends a MLE Child ID Request.") + + pkts.filter_wpan_src64(dut).\ + filter_wpan_dst64(LEADER).\ + filter_mle_cmd(consts.MLE_CHILD_ID_REQUEST).\ + filter(lambda p: p.wpan.aux_sec.key_id_mode == 2).\ + filter(lambda p: p.wpan.aux_sec.key_index == 128).\ + filter(lambda p: p.wpan.aux_sec.key_source == 127).\ + must_next() + + # Step 3: Leader + # - Description: Harness instructs the device to send an ICMPv6 Echo Request to the DUT. The MAC Auxiliary security + # header contains: + # - Key Index = 0x80 (128) + # - Key ID Mode = 1 + # - Pass Criteria: N/A + print("Step 3: Leader sends an ICMPv6 Echo Request to the DUT.") + + pkts.filter_ping_request().\ + filter_wpan_src64(LEADER).\ + filter_wpan_dst64(dut).\ + filter(lambda p: p.wpan.aux_sec.key_id_mode == 1).\ + filter(lambda p: p.wpan.aux_sec.key_index == 128).\ + must_next() + + # Step 4: ED_1 / SED_1 (DUT) + # - Description: Automatically replies with ICMPv6 Echo Reply. + # - Pass Criteria: + # - The DUT MUST reply with ICMPv6 Echo Reply. + # - The MAC Auxiliary Security Header MUST contain: + # - Key Index = 0x80 (128) + # - Key ID Mode = 1 + print(f"Step 4: {name} (DUT) MUST reply with ICMPv6 Echo Reply.") + + pkts.filter_ping_reply().\ + filter_wpan_src64(dut).\ + filter_wpan_dst64(LEADER).\ + filter(lambda p: p.wpan.aux_sec.key_id_mode == 1).\ + filter(lambda p: p.wpan.aux_sec.key_index == 128).\ + must_next() + + # Step 5: Leader + # - Description: Harness instructs the device to increment thrKeySequenceCounter by 1 to force a key switch. + # Incoming frame counters shall be set to 0 for all existing devices. All subsequent MLE and MAC frames are sent + # with Key Index = 1. + print("Step 5: Leader increments thrKeySequenceCounter by 1 to force a key switch.") + + # Step 6: Leader + # - Description: Harness instructs the device to send an ICMPv6 Echo Request to the DUT. The MAC Auxiliary Security + # Header contains: + # - Key Index = 1 + # - Key ID Mode = 1 + # - Pass Criteria: N/A + print("Step 6: Leader sends an ICMPv6 Echo Request to the DUT.") + + pkts.filter_ping_request().\ + filter_wpan_src64(LEADER).\ + filter_wpan_dst64(dut).\ + filter(lambda p: p.wpan.aux_sec.key_id_mode == 1).\ + filter(lambda p: p.wpan.aux_sec.key_index == 1).\ + must_next() + + # Step 7: ED_1 / SED_1 (DUT) + # - Description: Automatically replies with ICMPv6 Echo Reply. + # - Pass Criteria: + # - The DUT MUST reply with ICMPv6 Echo Reply. + # - The MAC Auxiliary Security Header MUST contain: + # - Key Index = 1 + # - Key ID Mode = 1 + print(f"Step 7: {name} (DUT) MUST reply with ICMPv6 Echo Reply.") + + pkts.filter_ping_reply().\ + filter_wpan_src64(dut).\ + filter_wpan_dst64(LEADER).\ + filter(lambda p: p.wpan.aux_sec.key_id_mode == 1).\ + filter(lambda p: p.wpan.aux_sec.key_index == 1).\ + must_next() + + +if __name__ == '__main__': + verify_utils.run_main(verify)