Refactor AccessProvider and ScopedAccessProvider
[platform/core/test/security-tests.git] / src / ckm / privileged / async-api.cpp
1 /*
2  *  Copyright (c) 2000 - 2020 Samsung Electronics Co., Ltd All Rights Reserved
3  *
4  *  Contact: Bumjin Im <bj.im@samsung.com>
5  *
6  *  Licensed under the Apache License, Version 2.0 (the "License");
7  *  you may not use this file except in compliance with the License.
8  *  You may obtain a copy of the License at
9  *
10  *      http://www.apache.org/licenses/LICENSE-2.0
11  *
12  *  Unless required by applicable law or agreed to in writing, software
13  *  distributed under the License is distributed on an "AS IS" BASIS,
14  *  WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15  *  See the License for the specific language governing permissions and
16  *  limitations under the License
17  */
18 /*
19  * @file       async-api.cpp
20  * @author     Krzysztof Jackiewicz (k.jackiewicz@samsung.com)
21  * @version    1.0
22  */
23
24 #include <mutex>
25 #include <utility>
26 #include <condition_variable>
27 #include <cassert>
28
29 #include <ckmc/ckmc-type.h>
30 #include <ckm/ckm-manager-async.h>
31 #include <ckm/ckm-manager.h>
32 #include <ckm/ckm-control.h>
33 #include <ckm/ckm-raw-buffer.h>
34
35 #include <fstream>
36
37 #include <dpl/test/test_runner.h>
38 #include <dpl/test/test_runner_child.h>
39
40 #include <tests_common.h>
41 #include <test-certs.h>
42 #include <ckm-common.h>
43 #include <scoped-app-context.h>
44 #include <random>
45
46 using namespace CKM;
47 using namespace std;
48 using namespace TestData;
49
50 namespace {
51
52 const char* TEST_DATA = "dsflsdkghkslhglrtghierhgilrehgidsafasdffsgfdgdgfdgfdgfdgfdggf";
53
54 const char* TEST_PASS = "test-pass";
55
56 const CertificateShPtrVector EMPTY_CERT_VECTOR;
57 const CertificateShPtrVector NULL_PTR_VECTOR = {
58         CertificateShPtr(),
59         CertificateShPtr(),
60         CertificateShPtr()
61 };
62 const AliasVector EMPTY_ALIAS_VECTOR;
63 const Alias alias_PKCS_exportable = "async-test-PKCS-export";
64 const Alias alias_PKCS_not_exportable = "async-test-PKCS-no-export";
65
66 class MyObserver: public ManagerAsync::Observer
67 {
68 public:
69     MyObserver() :
70             m_finished(false), m_error(0)
71     {
72     }
73
74     void ReceivedError(int error)
75     {
76         m_finished = true;
77         m_error = error;
78         m_cv.notify_one();
79     }
80
81     void ReceivedSaveKey() { Succeeded(); }
82     void ReceivedSaveCertificate() { Succeeded(); }
83     void ReceivedSaveData() { Succeeded(); }
84     void ReceivedSavePKCS12() { Succeeded(); }
85
86     void ReceivedRemovedAlias() { Succeeded(); }
87
88     void ReceivedKey(Key &&) { Succeeded(); }
89     void ReceivedCertificate(Certificate &&) { Succeeded(); }
90     void ReceivedData(RawBuffer &&) { Succeeded(); }
91     void ReceivedPKCS12(PKCS12ShPtr && pkcs) { m_pkcs = pkcs; Succeeded(); }
92
93     void ReceivedKeyAliasVector(AliasVector && av) { m_aliases = move(av); Succeeded(); }
94     void ReceivedCertificateAliasVector(AliasVector && av) { m_aliases = move(av); Succeeded(); }
95     void ReceivedDataAliasVector(AliasVector && av) { m_aliases = move(av); Succeeded(); }
96
97     void ReceivedCreateKeyAES() { Succeeded(); }
98     void ReceivedCreateKeyPair() { Succeeded(); }
99
100     void ReceivedGetCertificateChain(CertificateShPtrVector && chain)
101             { m_certChain = move(chain); Succeeded(); }
102
103     void ReceivedCreateSignature(RawBuffer && buffer) { m_signed = move(buffer); Succeeded(); }
104     void ReceivedVerifySignature() { Succeeded(); }
105
106     void ReceivedOCSPCheck(int status) { m_ocspStatus = status; Succeeded(); }
107
108     void ReceivedSetPermission() { Succeeded(); }
109
110     void WaitForResponse()
111     {
112         unique_lock < mutex > lock(m_mutex);
113
114         m_cv.wait(lock, [this] {return m_finished;});
115     }
116
117     bool m_finished;
118     int m_error;
119     AliasVector m_aliases;
120     CertificateShPtrVector m_certChain;
121     PKCS12ShPtr m_pkcs;
122     RawBuffer m_signed;
123     int m_ocspStatus;
124
125 protected:
126     void Succeeded()
127     {
128         m_finished = true;
129         m_cv.notify_one();
130     }
131
132     mutex m_mutex;
133     condition_variable m_cv;
134 };
135
136 typedef shared_ptr<MyObserver> MyObserverPtr;
137
138 enum Type {
139     RSA,
140     DSA,
141     ECDSA,
142     AES
143 };
144
145 struct KeyContainer
146 {
147     // assymetric
148     KeyContainer(const std::string& prv_pem, const std::string& pub_pem) {
149         RawBuffer buffer_prv(prv_pem.begin(), prv_pem.end());
150         prv = Key::create(buffer_prv);
151         assert(prv);
152
153         RawBuffer buffer_pub(pub_pem.begin(), pub_pem.end());
154         pub = Key::create(buffer_pub);
155         assert(pub);
156     }
157
158     // symmetric
159     KeyContainer(const RawBuffer& key_raw) {
160         prv = pub = Key::createAES(key_raw);
161         assert(prv);
162         assert(pub);
163     }
164
165     KeyShPtr prv;
166     KeyShPtr pub;
167 };
168
169 typedef map<Type, vector<KeyContainer> > KeyMap;
170
171
172 KeyMap initializeKeys()
173 {
174     KeyMap km;
175
176     km[RSA].emplace_back(
177             "-----BEGIN RSA PRIVATE KEY-----\n"
178             "MIICXAIBAAKBgQDMP6sKttnQ58BAi27b8X+8KVQtJgpJhhCF0RtWaTVqAhVDG3y4\n"
179             "x6IuAvXDtPSjLe/2E01fYGVxNComPJOmUOfUD06BCWPYH2+7jOfQIOy/TMlt+W7x\n"
180             "fou9rqnPRoKRaodoLqH5WK0ahkntWCAjstoKZoG+3Op0tEjy0jpmzeyNiQIDAQAB\n"
181             "AoGBAJRDX1CuvNx1bkwsKvQDkTqwMYd4hp0qcVICIbsPMhPaoT6OdHHZkHOf+HDx\n"
182             "KWhOj1LsXgzu95Q+Tp5k+LURI8ayu2RTsz/gYECgPNUsZ7gXl4co1bK+g5kiC+qr\n"
183             "sgSfkbYpp0OXefnl5x4KaJlZeSpn0UdDqx0kwI1x2E098i1VAkEA5thNY9YZNQdN\n"
184             "p6aopxOF5OmAjbLkq6wu255rDM5YgeepXXro/lmPociobtv8vPzbWKfoYZJL0Zj4\n"
185             "Qzj7Qz7s0wJBAOKBbpeG9PuNP1nR1h8kvyuILW8F89JOcIOUeqwokq4eJVqXdFIj\n"
186             "ct8eSEFmyXNqXD7b9+Tcw6vRIZuddVhNcrMCQAlpaD5ZzE1NLu1W7ilhsmPS4Vrl\n"
187             "oE0fiAmMO/EZuKITP+R/zmAQZrrB45whe/x4krjan67auByjj/utpxDmz+ECQEg/\n"
188             "UK80dN/n5dUYgVvdtLyF6zgGhgcGzgyqR5ayOlcfdnq25Htuoy1X02RJDOirfFDw\n"
189             "iNmPMTqUskuYpd1MltECQBwcy1cpnJWIXwCTQwg3enjkOVw80Tbr3iU9ASjHJTH2\n"
190             "N6FGHC4BQCm1fL6Bo0/0oSra+Ika3/1Vw1WwijUSiO8=\n"
191             "-----END RSA PRIVATE KEY-----",
192
193             "-----BEGIN PUBLIC KEY-----\n"
194             "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMP6sKttnQ58BAi27b8X+8KVQt\n"
195             "JgpJhhCF0RtWaTVqAhVDG3y4x6IuAvXDtPSjLe/2E01fYGVxNComPJOmUOfUD06B\n"
196             "CWPYH2+7jOfQIOy/TMlt+W7xfou9rqnPRoKRaodoLqH5WK0ahkntWCAjstoKZoG+\n"
197             "3Op0tEjy0jpmzeyNiQIDAQAB\n"
198             "-----END PUBLIC KEY-----"
199     );
200
201     km[RSA].emplace_back(
202             "-----BEGIN RSA PRIVATE KEY-----\n"
203             "MIIJKgIBAAKCAgEAzIft00bxMjLwkweLexg3+dmcibxEJRf6veU+9uYMLxnZfWS6\n"
204             "YX0EGab6Ab17jj5TOO4tIVzTUT6b/RxZ1wuitagFvGhm3Uy6pMvj64AI1e3IjZ6T\n"
205             "AQKw7Fb+YO6r7X9gzY8MnAKA4IfzzTQqJEaBx8yLSKIcza6SOxcUywNb1Ij+ro7m\n"
206             "Tus3fLP3ZbhEuA/sd3+wsgaw0uL04kgC72H2QNv3kBPuYdQQrXhoxCcIVtSIl8pU\n"
207             "fI367KQQ3MsXCucjkAvm6xAr/Wig91yue6t89paSCZakBt8SGjA6mSpmrp7lPlKE\n"
208             "9FYZ8Sxgj3H4fXIcyyD0aOa0RxZBE6t06OE4m41dD/Lzv0ZQE1mSDwxjrZWpxOzb\n"
209             "lliTiGDLhdWMF3zxeDhcWY9cTALOedJI3GNA+wRMf3yd41q6yvTC1rVd/+R6P37J\n"
210             "IudLZqwQTEr8wX12cT1fLmGBwAgbgTdzz1Kpf6AeVzqY2OYgdOHMCQzcTg9PqdS4\n"
211             "V3mUq6gnguhf/2iTgCPfVRgEuc3mLESGDNp4+klR5zlh8+kN5ZjfzEgpZ+eWlDes\n"
212             "NBBCZni0ELe1+JHD9V5oaloLEOk5e5JiwRTZ4rsmBqOwuglHFW52dIZEG9u/20ta\n"
213             "QMImzIym1nxl1e6GoL+yeNVs6oK90+lX3s7+8lLQwmLiBLx0Yr/RXKf6gJUCAwEA\n"
214             "AQKCAgEAmHp1yN7Ijd4AD/y99WTWxkN/OgfK3cSEv/EaAcL7LlodFCh18pva5Kzh\n"
215             "EU8Lv72jGXwm1Qp418bPT+FE8NbR1I+QxycmGLFNK/J81mK7M5FzxHCFs2koMOmh\n"
216             "9u236vTdXCHbCqurHLj9/ut2x1hxBFzvMZT52DTe+4J3k+nLGiWPiN8rv4YH9cXN\n"
217             "GF5JjNcCOQxO1Em8pVthqRh6Z7Amf6/9XcIeI3yPemOb5zAaPXFw64iBd+H5QVYG\n"
218             "5DPb19r9XjQhUPjbcq3/4qmLwtLT9JnIAbH2UtEWk8OEzA8aQfBfgxjN2cIe0Pd+\n"
219             "fTJASHU8FgtZaqMjnyNuHJXkMIFHSwrn4IyVJgSK6wX2IQ+7vJoWQyg2w6DbpSRq\n"
220             "cyqNvHiJ7z/4IcKC7zCT/Wv/DgmIl8W395UThEMvdqxQtiDLkxeeRpNqFU9OCw0B\n"
221             "d3tJr4bR2VCigikOhP2noSbhHNxgYRdwXrLhuMmygnEgcCTGzUZzNk3ZabdXgo1O\n"
222             "bCdHrK3Fe1iHm82JtDAWLZo6KjXrlTrDKM7RIbvKFDvp8Omet8GGCFcFU5cz+QBW\n"
223             "gUyLSdxR5RoEjBbe0a1KUptdQvXmYiks0krd3UdO1mVeHel4CcMxn8+iHn8SaSbP\n"
224             "ggFZ8JnuwgtNo0soVKsWGATH65Xe7nskmrnDFUheoKmtUWPpLUECggEBAOUt+OX8\n"
225             "0jqYuPsgNWHH1MxMwXR+fw5N68LWJXIdWw5H1TYDjwA1iBFku/O/xx7Jag7Y0A2l\n"
226             "1Z+3pMZmx64KaSu5VWwGvM08kPXxUXTAgI8qGfS395mqv+MOGFTs5r9QyM//sm5D\n"
227             "2osdK1Urs2D7+3r6QDXbNhhSeWG4fYhwzfgOwZtZkEcqa5IHqYoxDrJ1PrDOUCx6\n"
228             "xUAkWBEsSclzT3/5CpdcqKkbwxF8uPF8zs56olJyU81HDoLIlQcw7HgcP6w060I0\n"
229             "/zX4MFMD/Iq9Umb38mXPT1HjkQytHN0n0DklpgooGXzdeTfO1HgW+jY9gP398BWd\n"
230             "kKpm9xcFddATlT0CggEBAOR3gVRswKrXGOOsUdV3ErJF1lKYssYxq2neKA6A0WvE\n"
231             "qgKHOgZO9ztD6/UgX41uc+3rKfvmY5AsldGZgd0ov/DyeF0N834LeBVayG1fdcEt\n"
232             "amqjfVnQSHY437JyQ/qn63j/Se+HqbeEifJi+11OwPD9TwoUWS2xmldc+nehCdHs\n"
233             "WQUQiNuDSVoBgLlj3FbI9WXlkE/zQxb3qG48SCiiyQBfuyrD/5L/siq+ETjKemdK\n"
234             "HQaxJ4TcBnHSU92tpG7AFrtSa8T+kE335Z6f+/jawxFbJln3+uUnrljfo0EuD//5\n"
235             "ZB7ev8B0XWU+RK9y4KWnK0wmwwKyheNmGhN3Q9H3vjkCggEBALNGTQeLx+Ayi7FW\n"
236             "Nqvwp9PQzxwTv8wuxBg7cDteH1aCdpS0H+7n8TK5/BTmlhrNL/vBOq8SZJN2Ep1o\n"
237             "1Rad6jtb1SiV9KcPk83wIeoUk/xp0LgQGM3KNiSlZ/82+iH6Tbv3p1p+Fbzw6m7L\n"
238             "qpxZQRWoIQaAHkbUbUM2EGzk4RoEYQrm+ufQlSk8eTEywu5yrMGeAjVpLFfKlmGI\n"
239             "pYfCfhP7en+A6iavIt7RE9ND8Hqwj72y1T8lMIK56WogqTojzuMk2kuGLYXISfUG\n"
240             "j0zwYD9QAfwGOWQzgcnKuWN+u3GYs9QKHjYBAcvYLXhrcPtxDTCirmYaRYom1W7a\n"
241             "xJgqWXkCggEBALwWbpDUn6GGR+VX/l8hEnFV8WY6dCOazKXx0URvZPm2BMjkDy8W\n"
242             "X4+ZEW7S4heLsUFT81KAj8MoEYdnO3SZkbuJwvHJBIbmZkweWxdAGa+Z9hwo0I/a\n"
243             "W22I0REV5UU8bS1F7taV93EwWmkEeDCPH2THBgUkT27A4nG+CC3olC8QxxDWVfVy\n"
244             "FjdVOWZnAgUomG71GWPYv4jvBukKE9Xwfk4igfJpPcUFYOazZ3Y7q53RdCgIPKKy\n"
245             "iVO3dnfv9ol+9rfs2PBrKt4lkhKPX1+2qhVl1yMGdrWlf3GHW93TUDTKWlTXyUFm\n"
246             "C2XIZ7+RccSu5YRh/PYBhxx4+ErCS0FXFnECggEAAr/slAO0x10V7kmshltYG08t\n"
247             "fEBcynlHoZxJGCLAxd5uFfIl8GxsywKYsaKcdbewFbH3+0b3BuQYzyuzTo1wtNL6\n"
248             "06qeBC8xoVqcuLaOP1ZVl6nPSK83DGE3YTq1Afk0QclydBm1hpBLQyoI5CjIHKTQ\n"
249             "pyVWfB+F2ppBOYtKvNubyKd6blBK2j1IawGJEG/6wDfFSvWJziT7zTk+mIecxb+I\n"
250             "Qj8I06c1T31kzfJ71Vx1DUWZW/65xmFD4D6vkEFsGfjkcmSMK83PHhrSE1CmZ/rq\n"
251             "uPjo7MY8fylkeVfefQoKhTUkr6Nz/DVaGTbTostgRog+Vx676FQrM4EzjSSqgA==\n"
252             "-----END RSA PRIVATE KEY-----\n",
253             "-----BEGIN PUBLIC KEY-----\n"
254             "MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAzIft00bxMjLwkweLexg3\n"
255             "+dmcibxEJRf6veU+9uYMLxnZfWS6YX0EGab6Ab17jj5TOO4tIVzTUT6b/RxZ1wui\n"
256             "tagFvGhm3Uy6pMvj64AI1e3IjZ6TAQKw7Fb+YO6r7X9gzY8MnAKA4IfzzTQqJEaB\n"
257             "x8yLSKIcza6SOxcUywNb1Ij+ro7mTus3fLP3ZbhEuA/sd3+wsgaw0uL04kgC72H2\n"
258             "QNv3kBPuYdQQrXhoxCcIVtSIl8pUfI367KQQ3MsXCucjkAvm6xAr/Wig91yue6t8\n"
259             "9paSCZakBt8SGjA6mSpmrp7lPlKE9FYZ8Sxgj3H4fXIcyyD0aOa0RxZBE6t06OE4\n"
260             "m41dD/Lzv0ZQE1mSDwxjrZWpxOzblliTiGDLhdWMF3zxeDhcWY9cTALOedJI3GNA\n"
261             "+wRMf3yd41q6yvTC1rVd/+R6P37JIudLZqwQTEr8wX12cT1fLmGBwAgbgTdzz1Kp\n"
262             "f6AeVzqY2OYgdOHMCQzcTg9PqdS4V3mUq6gnguhf/2iTgCPfVRgEuc3mLESGDNp4\n"
263             "+klR5zlh8+kN5ZjfzEgpZ+eWlDesNBBCZni0ELe1+JHD9V5oaloLEOk5e5JiwRTZ\n"
264             "4rsmBqOwuglHFW52dIZEG9u/20taQMImzIym1nxl1e6GoL+yeNVs6oK90+lX3s7+\n"
265             "8lLQwmLiBLx0Yr/RXKf6gJUCAwEAAQ==\n"
266             "-----END PUBLIC KEY-----");
267     km[DSA].emplace_back(
268             "-----BEGIN DSA PRIVATE KEY-----\n"
269             "MIIBuwIBAAKBgQDIsQRYgnU4mm5VrMyykpNNzeHTQAO8E2hJAcOwNPBrdos8amak\n"
270             "rcJnyBaNh56ZslcuXNEKJuxiDsy4VM9KUR8fHTqTiF5s+4NArzdrdwNQpKWjAqJN\n"
271             "fgpCdaLZHw9o857flcQ4dyYNnAz1/SNGnv03Dm8EYRNRFNaFNw7zBPjyVwIVANyj\n"
272             "7ijLfrCbDZDi6ond5Np1Ns0hAoGBAIcS1ceWtw6DAGmYww27r/1lLtqjrq8j0w0a\n"
273             "F6Ly+pZ/y+WTw9KT18eRKPmVgruVSn3VVVJeN00XaoKvfPSHkTRIE5rro2ZEInhp\n"
274             "3g0Vak7EXJWe7KKBRXqSMNFkndjKv1nyNKeWSEq9Xql6SPn8J8TfmbyUpPSIglZR\n"
275             "vJ2DHwHJAoGAPZLRdIhIIJi4UWoyQrCqk1iF3pkBeukXzeZGqNWEjgzLAjMZEVYM\n"
276             "DLLKippahjxLZSWB7LOoS+XE4fonpBBute/tgF23ToR8fQuiBu+KvtAP/QuCOJ/L\n"
277             "S0aYYr1/eXmMByYPZ58Vf93KuUgoUAkWmc+mLBn6J2+fygnWcOOSo6sCFC/slPOv\n"
278             "yAKPlW7WQzgV5jLLNUW7\n"
279             "-----END DSA PRIVATE KEY-----\n",
280             "-----BEGIN PUBLIC KEY-----\n"
281             "MIIBtzCCASwGByqGSM44BAEwggEfAoGBAMixBFiCdTiablWszLKSk03N4dNAA7wT\n"
282             "aEkBw7A08Gt2izxqZqStwmfIFo2HnpmyVy5c0Qom7GIOzLhUz0pRHx8dOpOIXmz7\n"
283             "g0CvN2t3A1CkpaMCok1+CkJ1otkfD2jznt+VxDh3Jg2cDPX9I0ae/TcObwRhE1EU\n"
284             "1oU3DvME+PJXAhUA3KPuKMt+sJsNkOLqid3k2nU2zSECgYEAhxLVx5a3DoMAaZjD\n"
285             "Dbuv/WUu2qOuryPTDRoXovL6ln/L5ZPD0pPXx5Eo+ZWCu5VKfdVVUl43TRdqgq98\n"
286             "9IeRNEgTmuujZkQieGneDRVqTsRclZ7sooFFepIw0WSd2Mq/WfI0p5ZISr1eqXpI\n"
287             "+fwnxN+ZvJSk9IiCVlG8nYMfAckDgYQAAoGAPZLRdIhIIJi4UWoyQrCqk1iF3pkB\n"
288             "eukXzeZGqNWEjgzLAjMZEVYMDLLKippahjxLZSWB7LOoS+XE4fonpBBute/tgF23\n"
289             "ToR8fQuiBu+KvtAP/QuCOJ/LS0aYYr1/eXmMByYPZ58Vf93KuUgoUAkWmc+mLBn6\n"
290             "J2+fygnWcOOSo6s=\n"
291             "-----END PUBLIC KEY-----\n"
292     );
293     km[ECDSA].emplace_back(
294             "-----BEGIN EC PRIVATE KEY-----\n"
295             "MF8CAQEEGF3rz8OuFpcESrlqCm0G96oovr0XbX+DRKAKBggqhkjOPQMBAaE0AzIA\n"
296             "BHiZYByQiRNQ91GWNnTfoBbp9G8DP9oJYc/cDZlk4lKUpmbvm//RWf1U7ag3tOVy\n"
297             "sQ==\n"
298             "-----END EC PRIVATE KEY-----",
299
300             "-----BEGIN PUBLIC KEY-----\n"
301             "MEkwEwYHKoZIzj0CAQYIKoZIzj0DAQEDMgAEeJlgHJCJE1D3UZY2dN+gFun0bwM/\n"
302             "2glhz9wNmWTiUpSmZu+b/9FZ/VTtqDe05XKx\n"
303             "-----END PUBLIC KEY-----"
304     );
305
306     CKM::RawBuffer AES_key = createRandomBuffer(256/8);
307     km[AES].emplace_back(AES_key);
308
309     return km;
310 }
311
312 KeyMap keys = initializeKeys();
313 typedef vector<CertificateShPtr> CertVector;
314
315 const RawBuffer raw_buffer(const char* buffer)
316 {
317     return RawBuffer(buffer, buffer + strlen(buffer));
318 }
319
320 const RawBuffer test_buffer = raw_buffer("test_string");
321
322 template <typename F, typename... Args>
323 void test_negative(F&& func, int expected, Args... args)
324 {
325     MyObserverPtr obs = make_shared<MyObserver>();
326     ManagerAsync mgr;
327
328     (mgr.*func)(static_pointer_cast < ManagerAsync::Observer > (obs), args...);
329     obs->WaitForResponse();
330
331     RUNNER_ASSERT_MSG(obs->m_finished, "Request is not finished!");
332     RUNNER_ASSERT_MSG(
333             obs->m_error == expected,
334             "Expected " << expected << "/" << APICodeToString(expected) <<
335             " got: " << obs->m_error << "/" << APICodeToString(obs->m_error));
336 }
337
338 template <typename F, typename... Args>
339 void test_invalid_param(F&& func, Args... args)
340 {
341     test_negative(move(func), CKM_API_ERROR_INPUT_PARAM, args...);
342 }
343
344 template <typename F, typename... Args>
345 MyObserverPtr test_positive(F&& func, Args... args)
346 {
347     MyObserverPtr obs = make_shared<MyObserver>();
348     ManagerAsync mgr;
349
350     (mgr.*func)(static_pointer_cast < ManagerAsync::Observer > (obs), args...);
351     obs->WaitForResponse();
352
353     RUNNER_ASSERT_MSG(obs->m_finished, "Request is not finished!");
354     RUNNER_ASSERT_MSG(obs->m_error == 0,
355                          "Request failed " << obs->m_error << "/" << APICodeToString(obs->m_error));
356     return obs;
357 }
358
359 template <typename F, typename... Args>
360 void test_check_aliases(F&& func, const AliasVector& expected, Args... args)
361 {
362     auto obs = test_positive(move(func), args...);
363     RUNNER_ASSERT_MSG(obs->m_aliases == expected, "Retrieved aliases differ from expected");
364 }
365
366 template <typename F, typename... Args>
367 void test_check_cert_chain(F&& func, size_t expected, Args... args)
368 {
369     auto obs = test_positive(move(func), args...);
370     RUNNER_ASSERT_MSG(
371             obs->m_certChain.size() == expected,
372             "Expected chain length: " << expected << " got: " << obs->m_certChain.size());
373 }
374
375 typedef void (ManagerAsync::*certChainFn1)(const ManagerAsync::ObserverPtr&,
376                                            const CertificateShPtr&,
377                                            const CertificateShPtrVector&,
378                                            const CertificateShPtrVector&,
379                                            bool);
380
381 typedef void (ManagerAsync::*certChainFn2)(const ManagerAsync::ObserverPtr&,
382                                            const CertificateShPtr&,
383                                            const AliasVector&,
384                                            const AliasVector&,
385                                            bool);
386
387 class UserEnv : public RemoveDataEnv<APP_UID>
388 {
389 public:
390     void init(const std::string & str) {
391         RemoveDataEnv<APP_UID>::init(str);
392         unlock_user_data(APP_UID, TEST_PASS);
393         m_ctx.reset(new ScopedAppContext(TEST_LABEL, APP_UID, APP_GID));
394     }
395     void finish() {
396         m_ctx.reset();
397         // lock is performed by remove_user_data() in RemoveDataEnv
398         RemoveDataEnv<APP_UID>::finish();
399     }
400     std::unique_ptr<ScopedAppContext> m_ctx;
401 };
402
403 } // namespace anonymous
404
405 RUNNER_TEST_GROUP_INIT(CKM_ASYNC_API);
406
407 // setPermission
408 RUNNER_TEST(TA1810_allow_access_invalid_param, UserEnv)
409 {
410     test_no_observer(&ManagerAsync::setPermission, "alias", "accessor", CKM::Permission::READ | CKM::Permission::REMOVE);
411     test_invalid_param(&ManagerAsync::setPermission, "", "accessor", CKM::Permission::READ | CKM::Permission::REMOVE);
412     test_invalid_param(&ManagerAsync::setPermission, "alias", "", CKM::Permission::READ | CKM::Permission::REMOVE);
413 }
414
415 RUNNER_TEST(TA1820_allow_access, RemoveDataEnv<APP_UID>)
416 {
417     ScopedDBUnlock dbu(APP_UID, TEST_PASS);
418
419     // prepare: add data
420     std::string alias1 = aliasWithLabel(TEST_LABEL, "alias-1");
421     std::string alias2 = aliasWithLabel(TEST_LABEL, "alias-2");
422     std::string alias3 = aliasWithLabel(TEST_LABEL, "alias-3");
423     {
424         ScopedAppContext ctx(TEST_LABEL, APP_UID, APP_GID);
425         save_data(alias1.c_str(), TEST_DATA);
426         save_data(alias2.c_str(), TEST_DATA);
427         save_data(alias3.c_str(), TEST_DATA);
428
429         test_positive(&ManagerAsync::setPermission,
430                       alias2,
431                       TEST_LABEL_2,
432                       CKM::Permission::READ);
433         test_positive(&ManagerAsync::setPermission,
434                       alias3,
435                       TEST_LABEL_2,
436                       CKM::Permission::READ | CKM::Permission::REMOVE);
437     }
438
439     {
440         ScopedAppContext ctx(TEST_LABEL_2, APP_UID, APP_GID);
441
442         test_negative(&ManagerAsync::getData, CKM_API_ERROR_DB_ALIAS_UNKNOWN, alias1, "");
443         test_negative(&ManagerAsync::removeAlias, CKM_API_ERROR_DB_ALIAS_UNKNOWN, alias1);
444
445         // test from allowed label, but without properly addressing alias (coming from default label)
446         test_negative(&ManagerAsync::getData, CKM_API_ERROR_DB_ALIAS_UNKNOWN, "alias-2", "");
447
448         // now test with appropriate addressing
449         test_positive(&ManagerAsync::getData, alias2, "");
450         test_negative(&ManagerAsync::removeAlias, CKM_API_ERROR_ACCESS_DENIED, alias2);
451
452         test_positive(&ManagerAsync::getData, alias3, "");
453         test_positive(&ManagerAsync::removeAlias, alias3);
454     }
455 }
456
457 // denyAccess
458 RUNNER_TEST(TA1910_deny_access_invalid_param, UserEnv)
459 {
460     test_no_observer(&ManagerAsync::setPermission, "alias", "accessor", CKM::Permission::NONE);
461     test_invalid_param(&ManagerAsync::setPermission, "", "accessor", CKM::Permission::NONE);
462     test_invalid_param(&ManagerAsync::setPermission, "alias", "", CKM::Permission::NONE);
463 }
464
465 RUNNER_TEST(TA1920_deny_access, RemoveDataEnv<APP_UID>)
466 {
467     ScopedDBUnlock dbu(APP_UID, TEST_PASS);
468
469     // prepare: add data
470     std::string alias1 = aliasWithLabel(TEST_LABEL, "alias-1");
471     {
472         ScopedAppContext ctx(TEST_LABEL, APP_UID, APP_GID);
473         save_data(alias1.c_str(), TEST_DATA);
474
475         test_positive(&ManagerAsync::setPermission,
476                       alias1,
477                       TEST_LABEL_2,
478                       CKM::Permission::READ | CKM::Permission::REMOVE);
479         test_positive(&ManagerAsync::setPermission,
480                       alias1,
481                       TEST_LABEL_2,
482                       CKM::Permission::NONE);
483     }
484
485     {
486         ScopedAppContext ctx(TEST_LABEL_2, APP_UID, APP_GID);
487
488         test_negative(&ManagerAsync::getData, CKM_API_ERROR_DB_ALIAS_UNKNOWN, alias1, "");
489         test_negative(&ManagerAsync::removeAlias, CKM_API_ERROR_DB_ALIAS_UNKNOWN, alias1);
490     }
491 }