summaryrefslogtreecommitdiffhomepage
path: root/ios/MullvadVPNUITests/Networking/LeakCheck.swift
blob: 1e80c571770e24cadd13fdb42fc420e67ca88f94 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
//
//  LeakCheck.swift
//  MullvadVPN
//
//  Created by Niklas Berglund on 2024-12-16.
//  Copyright © 2025 Mullvad VPN AB. All rights reserved.
//

import XCTest

class LeakCheck {
    static func assertNoLeaks(streams: [Stream], rules: [NoTrafficToHostLeakRule]) {
        XCTAssertFalse(streams.isEmpty, "No streams to leak check")
        XCTAssertFalse(rules.isEmpty, "No leak rules to check")

        for rule in rules where rule.isViolated(streams: streams) {
            XCTFail("Leaked traffic destined to \(rule.host) outside of the tunnel connection")
        }
    }

    static func assertLeaks(streams: [Stream], rules: [NoTrafficToHostLeakRule]) {
        XCTAssertFalse(streams.isEmpty, "No streams to leak check")
        XCTAssertFalse(rules.isEmpty, "No leak rules to check")

        for rule in rules where rule.isViolated(streams: streams) == false {
            XCTFail("Expected to leak traffic to \(rule.host) outside of tunnel")
        }
    }
}

class NoTrafficToHostLeakRule {
    let host: String

    init(host: String) {
        self.host = host
    }

    func isViolated(streams: [Stream]) -> Bool {
        streams.filter { $0.destinationAddress == host }.isEmpty == false
    }
}