Testing & CI¶
The repository carries a self-contained suite — 50 tests at the time of
writing — that runs under plain dyalogscript and in GitHub Actions on
every push. It found (and now guards the fixes for) seven real defects,
from a TCP-coalescing handshake flake to the absence of host-key
verification.
Running locally¶
cd Tests
dyalogscript RunTests.apls unit # unit tests only, no network
# full suite against throwaway local OpenSSH servers:
eval "$(bash setup_sshd.sh | grep '^export')"
dyalogscript RunTests.apls
setup_sshd.sh starts two disposable sshd instances on 127.0.0.1: the
real test server, and an "impostor" with a different host key used by the
man-in-the-middle test. Run as a normal user it uses key auth only (the
two password tests skip); in CI it runs as root and everything runs. The
tests keep their own known_hosts files and never touch ~/.ssh.
What the suite proves¶
- Crypto primitives against official vectors: NIST SHA-256 and AES-128-CTR, RFC 4231 HMAC, DH commutativity over the real group14 prime
- RSA sign/verify cross-validated against OpenSSL both ways, plus tamper rejection (bit-flips, truncation, garbage, wrong message)
- Wire codecs including UTF-8 strings, mpint edge cases, packet framing, and packet-stream reassembly over a mock transport (coalesced and fragmented delivery)
- Live protocol against real OpenSSH: both auth methods and their
failure modes, exec (multi-packet, UTF-8, binary output), byte-exact
SFTP round-trips confirmed by remote
sha256sum, UTF-8 paths - Trust: TOFU pinning, strict mode, revocation, and a live impostor server refused before authentication
- Lifecycle: reconnects, use-after-close, clean retry after failure, and a 15-handshake stress per run
See Tests/README.md for the full layout and conventions.
Continuous integration¶
.github/workflows/test.yml runs the suite in the official
dyalog/dyalog:20.0 container: it installs openssh-server and
openssl, starts the test servers via setup_sshd.sh, and executes
dyalogscript RunTests.apls. The job fails if any test fails.
Documentation¶
These pages are a Zensical project
(zensical.toml + docs/), using the Dyalog house theme from
docs/documentation-assetsz:
.github/workflows/docs.yml strict-builds the site on every push and
pull request, and publishes it to GitHub Pages on pushes to the default
branch (enable Settings → Pages → Source: GitHub Actions once).