redict/tests
Drew DeVault e035e7b763 ACL: Fix parsing issue leading to denail of service
Fix for CVE-2024-31227

This patch was provided to us by Valkey, who received it from Redis Ltd.

> An authenticated user with sufficient privileges may create a
> malformed ACL selector which, when accessed, triggers a server panic
> and subsequent denial of service.

Fixes: https://codeberg.org/redict/redict/issues/54

Signed-off-by: Drew DeVault <sir@cmpwn.com>
2024-09-16 09:07:54 +02:00
..
assets tests/*: replace redis with redict in Lua usage 2024-03-26 12:12:03 +01:00
cluster tests/*: replace redis with redict in Lua usage 2024-03-26 12:12:03 +01:00
helpers all: let's go LGPL over GPL 2024-03-21 20:11:44 +01:00
integration tests/*: replace redis with redict in Lua usage 2024-03-26 12:12:03 +01:00
modules tests/modules: fix remaining redis => redict cases 2024-03-25 12:45:47 +01:00
sentinel tests/sentinel: update .gitignore 2024-03-25 17:31:07 +01:00
support tests/*: replace redis with redict in Lua usage 2024-03-26 12:12:03 +01:00
tmp minor fixes to the new test suite, html doc updated 2010-05-14 18:48:33 +02:00
unit ACL: Fix parsing issue leading to denail of service 2024-09-16 09:07:54 +02:00
instances.tcl tests/instances.tcl: fix Redis ref in pause_on_error 2024-03-25 17:31:07 +01:00
README.md tests/README.md: s/redis/redict/ 2024-03-21 15:18:01 +01:00
test_helper.tcl all: let's go LGPL over GPL 2024-03-21 20:11:44 +01:00

Redict Test Suite

The normal execution mode of the test suite involves starting and manipulating local redict-server instances, inspecting process state, log files, etc.

The test suite also supports execution against an external server, which is enabled using the --host and --port parameters. When executing against an external server, tests tagged external:skip are skipped.

There are additional runtime options that can further adjust the test suite to match different external server configurations:

Option Impact
--singledb Only use database 0, don't assume others are supported.
--ignore-encoding Skip all checks for specific encoding.
--ignore-digest Skip key value digest validations.
--cluster-mode Run in strict Redict Cluster compatibility mode.
--large-memory Enables tests that consume more than 100mb

Tags

Tags are applied to tests to classify them according to the subsystem they test, but also to indicate compatibility with different run modes and required capabilities.

Tags can be applied in different context levels:

  • start_server context
  • tags context that bundles several tests together
  • A single test context.

The following compatibility and capability tags are currently used:

Tag Indicates
external:skip Not compatible with external servers.
cluster:skip Not compatible with --cluster-mode.
large-memory Test that requires more than 100mb
tls:skip Not compatible with --tls.
needs:repl Uses replication and needs to be able to SYNC from server.
needs:debug Uses the DEBUG command or other debugging focused commands (like OBJECT REFCOUNT).
needs:pfdebug Uses the PFDEBUG command.
needs:config-maxmemory Uses CONFIG SET to manipulate memory limit, eviction policies, etc.
needs:config-resetstat Uses CONFIG RESETSTAT to reset statistics.
needs:reset Uses RESET to reset client connections.
needs:save Uses SAVE or BGSAVE to create an RDB file.

When using an external server (--host and --port), filtering using the external:skip tags is done automatically.

When using --cluster-mode, filtering using the cluster:skip tag is done automatically.

When not using --large-memory, filtering using the largemem:skip tag is done automatically.

In addition, it is possible to specify additional configuration. For example, to run tests on a server that does not permit SYNC use:

./runtest --host <host> --port <port> --tags -needs:repl