(t *testing.T)
| 972 | } |
| 973 | |
| 974 | func TestAddCounter(t *testing.T) { |
| 975 | // The want byte sequences come from stracing nft(8), e.g.: |
| 976 | // strace -f -v -x -s 2048 -eraw=sendto nft add table ip nat |
| 977 | // |
| 978 | // The nft(8) command sequence was taken from: |
| 979 | // https://wiki.nftables.org/wiki-nftables/index.php/Performing_Network_Address_Translation_(NAT) |
| 980 | want := [][]byte{ |
| 981 | // batch begin |
| 982 | []byte("\x00\x00\x00\x0a"), |
| 983 | // nft add counter ip filter fwded |
| 984 | []byte("\x02\x00\x00\x00\x0b\x00\x01\x00\x66\x69\x6c\x74\x65\x72\x00\x00\x0a\x00\x02\x00\x66\x77\x64\x65\x64\x00\x00\x00\x08\x00\x03\x00\x00\x00\x00\x01\x1c\x00\x04\x80\x0c\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0c\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00"), |
| 985 | // nft add rule ip filter forward counter name fwded |
| 986 | []byte("\x02\x00\x00\x00\x0b\x00\x01\x00\x66\x69\x6c\x74\x65\x72\x00\x00\x0c\x00\x02\x00\x66\x6f\x72\x77\x61\x72\x64\x00\x2c\x00\x04\x80\x28\x00\x01\x80\x0b\x00\x01\x00\x6f\x62\x6a\x72\x65\x66\x00\x00\x18\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x09\x00\x02\x00\x66\x77\x64\x65\x64\x00\x00\x00"), |
| 987 | // batch end |
| 988 | []byte("\x00\x00\x00\x0a"), |
| 989 | } |
| 990 | |
| 991 | c, err := nftables.New(nftables.WithTestDial( |
| 992 | func(req []netlink.Message) ([]netlink.Message, error) { |
| 993 | for idx, msg := range req { |
| 994 | b, err := msg.MarshalBinary() |
| 995 | if err != nil { |
| 996 | t.Fatal(err) |
| 997 | } |
| 998 | if len(b) < 16 { |
| 999 | continue |
| 1000 | } |
| 1001 | b = b[16:] |
| 1002 | if len(want) == 0 { |
| 1003 | t.Errorf("no want entry for message %d: %x", idx, b) |
| 1004 | continue |
| 1005 | } |
| 1006 | if got, want := b, want[0]; !bytes.Equal(got, want) { |
| 1007 | t.Errorf("message %d: %s", idx, linediff(nfdump(got), nfdump(want))) |
| 1008 | } |
| 1009 | want = want[1:] |
| 1010 | } |
| 1011 | return req, nil |
| 1012 | })) |
| 1013 | if err != nil { |
| 1014 | t.Fatal(err) |
| 1015 | } |
| 1016 | |
| 1017 | c.AddObj(&nftables.CounterObj{ |
| 1018 | Table: &nftables.Table{Name: "filter", Family: nftables.TableFamilyIPv4}, |
| 1019 | Name: "fwded", |
| 1020 | Bytes: 0, |
| 1021 | Packets: 0, |
| 1022 | }) |
| 1023 | |
| 1024 | c.AddRule(&nftables.Rule{ |
| 1025 | Table: &nftables.Table{Name: "filter", Family: nftables.TableFamilyIPv4}, |
| 1026 | Chain: &nftables.Chain{Name: "forward", Type: nftables.ChainTypeFilter}, |
| 1027 | Exprs: []expr.Any{ |
| 1028 | &expr.Objref{ |
| 1029 | Type: 1, |
| 1030 | Name: "fwded", |
| 1031 | }, |
nothing calls this directly
no test coverage detected
searching dependent graphs…