MCPcopy Create free account
hub / github.com/google/nftables / TestMatchPacketHeader

Function TestMatchPacketHeader

nftables_test.go:3283–3411  ·  view source on GitHub ↗
(t *testing.T)

Source from the content-addressed store, hash-verified

3281}
3282
3283func TestMatchPacketHeader(t *testing.T) {
3284 // The want byte sequences come from stracing nft(8), e.g.:
3285 // strace -f -v -x -s 2048 -eraw=sendto nft add table ip nat
3286 //
3287 // The nft(8) command sequence was adopted from:
3288 // https://wiki.nftables.org/wiki-nftables/index.php/Matching_packet_headers
3289 want := [][]byte{
3290 // batch begin
3291 []byte("\x00\x00\x00\x0a"),
3292 // nft flush ruleset
3293 []byte("\x00\x00\x00\x00"),
3294 // nft add table ip filter
3295 []byte("\x02\x00\x00\x00\x0b\x00\x01\x00\x66\x69\x6c\x74\x65\x72\x00\x00\x08\x00\x02\x00\x00\x00\x00\x00"),
3296 // nft add chain filter input '{' type filter hook forward priority filter \; '}'
3297 []byte("\x02\x00\x00\x00\x0b\x00\x01\x00\x66\x69\x6c\x74\x65\x72\x00\x00\x0a\x00\x03\x00\x69\x6e\x70\x75\x74\x00\x00\x00\x14\x00\x04\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x00\x0b\x00\x07\x00\x66\x69\x6c\x74\x65\x72\x00\x00"),
3298 // nft add rule ip filter input tcp flags syn tcp option maxseg size 1-500 drop
3299 []byte("\x02\x00\x00\x00\x0b\x00\x01\x00\x66\x69\x6c\x74\x65\x72\x00\x00\x0a\x00\x02\x00\x69\x6e\x70\x75\x74\x00\x00\x00\xc4\x01\x04\x80\x24\x00\x01\x80\x09\x00\x01\x00\x6d\x65\x74\x61\x00\x00\x00\x00\x14\x00\x02\x80\x08\x00\x02\x00\x00\x00\x00\x10\x08\x00\x01\x00\x00\x00\x00\x01\x2c\x00\x01\x80\x08\x00\x01\x00\x63\x6d\x70\x00\x20\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x00\x0c\x00\x03\x80\x05\x00\x01\x00\x06\x00\x00\x00\x34\x00\x01\x80\x0c\x00\x01\x00\x70\x61\x79\x6c\x6f\x61\x64\x00\x24\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x02\x08\x00\x03\x00\x00\x00\x00\x0d\x08\x00\x04\x00\x00\x00\x00\x01\x44\x00\x01\x80\x0c\x00\x01\x00\x62\x69\x74\x77\x69\x73\x65\x00\x34\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x01\x08\x00\x03\x00\x00\x00\x00\x01\x0c\x00\x04\x80\x05\x00\x01\x00\x02\x00\x00\x00\x0c\x00\x05\x80\x05\x00\x01\x00\x00\x00\x00\x00\x2c\x00\x01\x80\x08\x00\x01\x00\x63\x6d\x70\x00\x20\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x01\x0c\x00\x03\x80\x05\x00\x01\x00\x00\x00\x00\x00\x44\x00\x01\x80\x0b\x00\x01\x00\x65\x78\x74\x68\x64\x72\x00\x00\x34\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x05\x00\x02\x00\x02\x00\x00\x00\x08\x00\x03\x00\x00\x00\x00\x02\x08\x00\x04\x00\x00\x00\x00\x02\x08\x00\x06\x00\x00\x00\x00\x01\x08\x00\x05\x00\x00\x00\x00\x00\x2c\x00\x01\x80\x08\x00\x01\x00\x63\x6d\x70\x00\x20\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x05\x0c\x00\x03\x80\x06\x00\x01\x00\x00\x01\x00\x00\x2c\x00\x01\x80\x08\x00\x01\x00\x63\x6d\x70\x00\x20\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x03\x0c\x00\x03\x80\x06\x00\x01\x00\x01\xf4\x00\x00\x30\x00\x01\x80\x0e\x00\x01\x00\x69\x6d\x6d\x65\x64\x69\x61\x74\x65\x00\x00\x00\x1c\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x00\x10\x00\x02\x80\x0c\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x00"),
3300 // batch end
3301 []byte("\x00\x00\x00\x0a"),
3302 }
3303
3304 c, err := nftables.New(nftables.WithTestDial(
3305 func(req []netlink.Message) ([]netlink.Message, error) {
3306 for idx, msg := range req {
3307 b, err := msg.MarshalBinary()
3308 if err != nil {
3309 t.Fatal(err)
3310 }
3311 if len(b) < 16 {
3312 continue
3313 }
3314 b = b[16:]
3315 if len(want) == 0 {
3316 t.Errorf("no want entry for message %d: %x", idx, b)
3317 continue
3318 }
3319 if got, want := b, want[0]; !bytes.Equal(got, want) {
3320 t.Errorf("message %d: %s", idx, linediff(nfdump(got), nfdump(want)))
3321 }
3322 want = want[1:]
3323 }
3324 return req, nil
3325 }))
3326 if err != nil {
3327 t.Fatal(err)
3328 }
3329
3330 c.FlushRuleset()
3331
3332 filter := c.AddTable(&nftables.Table{
3333 Family: nftables.TableFamilyIPv4,
3334 Name: "filter",
3335 })
3336
3337 input := c.AddChain(&nftables.Chain{
3338 Name: "input",
3339 Table: filter,
3340 Type: nftables.ChainTypeFilter,

Callers

nothing calls this directly

Calls 10

NewFunction · 0.92
WithTestDialFunction · 0.92
FlushRulesetMethod · 0.80
AddTableMethod · 0.80
AddChainMethod · 0.80
AddRuleMethod · 0.80
FlushMethod · 0.80
linediffFunction · 0.70
nfdumpFunction · 0.70
PutUint16Method · 0.65

Tested by

no test coverage detected

Used in the wild real call sites across dependent graphs

searching dependent graphs…