package checkrunner import ( "context" "net" "net/http/httptest" "strconv" "testing" "time" ) func splitHostPortInt(t *testing.T, addr string) (string, int) { t.Helper() host, portStr, err := net.SplitHostPort(addr) if err != nil { t.Fatalf("split host port %q: %v", addr, err) } port, err := strconv.Atoi(portStr) if err != nil { t.Fatalf("parse port %q: %v", portStr, err) } return host, port } // TestTLSHandshakeSucceedsAgainstTLSServer confirms a real TLS listener // (self-signed cert, InsecureSkipVerify accepts it) passes the handshake. func TestTLSHandshakeSucceedsAgainstTLSServer(t *testing.T) { ts := httptest.NewTLSServer(nil) defer ts.Close() host, port := splitHostPortInt(t, ts.Listener.Addr().String()) res := TLSHandshake(host, port, time.Second)(context.Background()) if !res.Success { t.Fatalf("expected success, got failure: %s", res.Detail) } wantType := "tls-" + strconv.Itoa(port) if res.CheckType != wantType { t.Fatalf("expected check type %q, got %q", wantType, res.CheckType) } } // TestTLSHandshakeFailsAgainstPlainTCP confirms a bare TCP listener (no TLS // on top) fails the handshake rather than being mistaken for success — // this is exactly the gap a plain TCPConnect check can't catch. func TestTLSHandshakeFailsAgainstPlainTCP(t *testing.T) { ts := httptest.NewServer(nil) defer ts.Close() host, port := splitHostPortInt(t, ts.Listener.Addr().String()) res := TLSHandshake(host, port, time.Second)(context.Background()) if res.Success { t.Fatalf("expected failure against a plain TCP listener, got success") } } // TestTLSHandshakeFailsOnConnectionRefused confirms a closed port reports // failure rather than hanging or panicking. func TestTLSHandshakeFailsOnConnectionRefused(t *testing.T) { l, err := net.Listen("tcp", "127.0.0.1:0") if err != nil { t.Fatalf("listen: %v", err) } _, port := splitHostPortInt(t, l.Addr().String()) l.Close() // close immediately so the port refuses connections res := TLSHandshake("127.0.0.1", port, time.Second)(context.Background()) if res.Success { t.Fatalf("expected failure against a closed port, got success") } }