#!/bin/bash

. ./test.common

test_start "NTP authentication with NTS"

check_config_h 'FEAT_NTS 1' || test_skip
certtool --help &> /dev/null || test_skip

export CLKNETSIM_START_DATE=$(date -d 'Jan  1 00:00:00 UTC 2010' +'%s')

cat > tmp/cert.cfg <<EOF
cn = "node1.net1.clk"
serial = 001
activation_date = "2010-01-01 00:00:00 UTC"
expiration_date = "2010-01-02 00:00:00 UTC"
#dns_name = "node1.net1.clk"
signing_key
encryption_key
EOF

certtool --generate-privkey --key-type=ed25519 --outfile tmp/server.key &> tmp/log.certtool
certtool --generate-self-signed --load-privkey tmp/server.key \
	--template tmp/cert.cfg --outfile tmp/server.crt &>> tmp/log.certtool

max_sync_time=400
dns=1
server_conf="
ntsserverkey tmp/server.key
ntsservercert tmp/server.crt
ntsprocesses 0
ntsrotate 66
ntsdumpdir tmp
"
client_server_options="minpoll 6 maxpoll 6 nts"
client_conf="
nosystemcert
ntstrustedcerts tmp/server.crt
logdir tmp
log rawmeasurements"

run_test || test_fail
check_chronyd_exit || test_fail
check_source_selection || test_fail
check_sync || test_fail

check_file_messages "20.*123\.1.* 111 111 1111" 75 80 measurements.log || test_fail
check_file_messages "20.*123\.1.* 111 001 0000" 37 39 measurements.log || test_fail
check_file_messages "	2	1	.*	4460	" 260 300 log.packets || test_fail
check_file_messages "." 6 6 ntskeys || test_fail
rm -f tmp/measurements.log

client_conf+="
ntsrefresh 120
ntsdumpdir tmp"

run_test || test_fail
check_chronyd_exit || test_fail
check_source_selection || test_fail
check_sync || test_fail

check_file_messages "20.*123\.1.* 111 111 1111" 99 103 measurements.log || test_fail
check_file_messages "20.*123\.1.* 111 001 0000" 0 0 measurements.log || test_fail
check_file_messages "	2	1	.*	4460	" 350 390 log.packets || test_fail
check_file_messages "." 6 6 ntskeys || test_fail
check_file_messages "." 12 13 192.168.123.1.nts || test_fail
rm -f tmp/measurements.log

export CLKNETSIM_START_DATE=$(date -d 'Jan  1 00:00:00 UTC 2010 + 40000 sec' +'%s')

server_conf+="
ntsrotate 100000"
client_conf+="
ntsrefresh 39500"

run_test || test_fail
check_chronyd_exit || test_fail
check_source_selection || test_fail
check_sync || test_fail

check_file_messages "20.*123\.1.* 111 111 1111" 150 160 measurements.log || test_fail
check_file_messages "20.*123\.1.* 111 001 0000" 0 0 measurements.log || test_fail
check_file_messages "	2	1	.*	4460	" 6 10 log.packets || test_fail
check_file_messages "^9\.......e+03	2	1	.*	4460	" 6 10 log.packets || test_fail
check_file_messages "." 6 6 ntskeys || test_fail
check_file_messages "." 12 13 192.168.123.1.nts || test_fail
rm -f tmp/measurements.log

client_conf="
nosystemcert"

run_test || test_fail
check_chronyd_exit || test_fail
check_source_selection && test_fail
check_sync && test_fail

check_file_messages "	2	1	.*	123	" 0 0 log.packets || test_fail
check_file_messages "	2	1	.*	4460	" 10 20 log.packets || test_fail

export CLKNETSIM_START_DATE=$(date -d 'Jan  2 00:00:01 UTC 2010' +'%s')

client_conf="
nosystemcert
ntstrustedcerts tmp/server.crt"

run_test || test_fail
check_chronyd_exit || test_fail
check_source_selection && test_fail
check_sync && test_fail

check_file_messages "	2	1	.*	123	" 0 0 log.packets || test_fail
check_file_messages "	2	1	.*	4460	" 10 20 log.packets || test_fail
check_log_messages "expired certificate" 4 4 || test_fail

client_conf+="
nocerttimecheck 1"

run_test || test_fail
check_chronyd_exit || test_fail
check_source_selection || test_fail
check_sync || test_fail

export CLKNETSIM_START_DATE=$(date -d 'Jan  1 00:00:00 UTC 2010' +'%s')

server_conf="
ntsserverkey tmp/server.key
ntsservercert tmp/server.crt
ntsprocesses 0
ntsrotate 0
ntsdumpdir tmp
ntsntpserver 192.168.123.2"
client_conf="
nosystemcert
ntstrustedcerts tmp/server.crt
ntsrefresh 500"
client_server_conf="server node1.net1.clk $client_server_options"

run_test || test_fail
check_chronyd_exit || test_fail
check_source_selection && test_fail
check_sync && test_fail

check_file_messages "	2	1	.*	4460	" 50 100 log.packets || test_fail
check_file_messages "	2	2	.*	4460	" 0 0 log.packets || test_fail
check_log_messages "Source 192.168.123.1 changed to 192.168.123.2" 6 8 || test_fail
check_log_messages "Source 192.168.123.2 replaced with 192.168.123.1" 6 8 || test_fail

servers=2

run_test || test_fail
check_chronyd_exit || test_fail
check_source_selection || test_fail
check_sync || test_fail

check_file_messages "	3	1	.*	4460	" 100 150 log.packets || test_fail
check_file_messages "	3	2	.*	4460	" 0 0 log.packets || test_fail
check_log_messages "Source 192.168.123.1 changed to 192.168.123.2" 1 1 || test_fail
check_log_messages "Source 192.168.123.2 replaced with 192.168.123.1" 0 0 || test_fail

server_conf+="
ntsratelimit interval 12 burst 1 leak 4"

client_chronyd_options="-d -d"
run_test || test_fail
check_chronyd_exit || test_fail
check_source_selection && test_fail

check_file_messages "	3	1	.*	4460	1	0	2" 25 50 log.packets || test_fail
check_file_messages "	3	2	.*	4460	" 0 0 log.packets || test_fail
check_log_messages "Source 192.168.123.1 changed to 192.168.123.2" 2 6 || test_fail
check_log_messages "Source 192.168.123.2 replaced with 192.168.123.1" 1 6 || test_fail

test_pass
