Skip to content

Testing & CI

The repository carries a self-contained suite — 50 tests at the time of writing — that runs under plain dyalogscript and in GitHub Actions on every push. It found (and now guards the fixes for) seven real defects, from a TCP-coalescing handshake flake to the absence of host-key verification.

Running locally

cd Tests
dyalogscript RunTests.apls unit      # unit tests only, no network

# full suite against throwaway local OpenSSH servers:
eval "$(bash setup_sshd.sh | grep '^export')"
dyalogscript RunTests.apls

setup_sshd.sh starts two disposable sshd instances on 127.0.0.1: the real test server, and an "impostor" with a different host key used by the man-in-the-middle test. Run as a normal user it uses key auth only (the two password tests skip); in CI it runs as root and everything runs. The tests keep their own known_hosts files and never touch ~/.ssh.

What the suite proves

  • Crypto primitives against official vectors: NIST SHA-256 and AES-128-CTR, RFC 4231 HMAC, DH commutativity over the real group14 prime
  • RSA sign/verify cross-validated against OpenSSL both ways, plus tamper rejection (bit-flips, truncation, garbage, wrong message)
  • Wire codecs including UTF-8 strings, mpint edge cases, packet framing, and packet-stream reassembly over a mock transport (coalesced and fragmented delivery)
  • Live protocol against real OpenSSH: both auth methods and their failure modes, exec (multi-packet, UTF-8, binary output), byte-exact SFTP round-trips confirmed by remote sha256sum, UTF-8 paths
  • Trust: TOFU pinning, strict mode, revocation, and a live impostor server refused before authentication
  • Lifecycle: reconnects, use-after-close, clean retry after failure, and a 15-handshake stress per run

See Tests/README.md for the full layout and conventions.

Continuous integration

.github/workflows/test.yml runs the suite in the official dyalog/dyalog:20.0 container: it installs openssh-server and openssl, starts the test servers via setup_sshd.sh, and executes dyalogscript RunTests.apls. The job fails if any test fails.

Documentation

These pages are a Zensical project (zensical.toml + docs/), using the Dyalog house theme from docs/documentation-assetsz:

pip install zensical
zensical serve

.github/workflows/docs.yml strict-builds the site on every push and pull request, and publishes it to GitHub Pages on pushes to the default branch (enable Settings → Pages → Source: GitHub Actions once).