(t *testing.T)
| 3281 | } |
| 3282 | |
| 3283 | func TestMatchPacketHeader(t *testing.T) { |
| 3284 | // The want byte sequences come from stracing nft(8), e.g.: |
| 3285 | // strace -f -v -x -s 2048 -eraw=sendto nft add table ip nat |
| 3286 | // |
| 3287 | // The nft(8) command sequence was adopted from: |
| 3288 | // https://wiki.nftables.org/wiki-nftables/index.php/Matching_packet_headers |
| 3289 | want := [][]byte{ |
| 3290 | // batch begin |
| 3291 | []byte("\x00\x00\x00\x0a"), |
| 3292 | // nft flush ruleset |
| 3293 | []byte("\x00\x00\x00\x00"), |
| 3294 | // nft add table ip filter |
| 3295 | []byte("\x02\x00\x00\x00\x0b\x00\x01\x00\x66\x69\x6c\x74\x65\x72\x00\x00\x08\x00\x02\x00\x00\x00\x00\x00"), |
| 3296 | // nft add chain filter input '{' type filter hook forward priority filter \; '}' |
| 3297 | []byte("\x02\x00\x00\x00\x0b\x00\x01\x00\x66\x69\x6c\x74\x65\x72\x00\x00\x0a\x00\x03\x00\x69\x6e\x70\x75\x74\x00\x00\x00\x14\x00\x04\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x00\x0b\x00\x07\x00\x66\x69\x6c\x74\x65\x72\x00\x00"), |
| 3298 | // nft add rule ip filter input tcp flags syn tcp option maxseg size 1-500 drop |
| 3299 | []byte("\x02\x00\x00\x00\x0b\x00\x01\x00\x66\x69\x6c\x74\x65\x72\x00\x00\x0a\x00\x02\x00\x69\x6e\x70\x75\x74\x00\x00\x00\xc4\x01\x04\x80\x24\x00\x01\x80\x09\x00\x01\x00\x6d\x65\x74\x61\x00\x00\x00\x00\x14\x00\x02\x80\x08\x00\x02\x00\x00\x00\x00\x10\x08\x00\x01\x00\x00\x00\x00\x01\x2c\x00\x01\x80\x08\x00\x01\x00\x63\x6d\x70\x00\x20\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x00\x0c\x00\x03\x80\x05\x00\x01\x00\x06\x00\x00\x00\x34\x00\x01\x80\x0c\x00\x01\x00\x70\x61\x79\x6c\x6f\x61\x64\x00\x24\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x02\x08\x00\x03\x00\x00\x00\x00\x0d\x08\x00\x04\x00\x00\x00\x00\x01\x44\x00\x01\x80\x0c\x00\x01\x00\x62\x69\x74\x77\x69\x73\x65\x00\x34\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x01\x08\x00\x03\x00\x00\x00\x00\x01\x0c\x00\x04\x80\x05\x00\x01\x00\x02\x00\x00\x00\x0c\x00\x05\x80\x05\x00\x01\x00\x00\x00\x00\x00\x2c\x00\x01\x80\x08\x00\x01\x00\x63\x6d\x70\x00\x20\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x01\x0c\x00\x03\x80\x05\x00\x01\x00\x00\x00\x00\x00\x44\x00\x01\x80\x0b\x00\x01\x00\x65\x78\x74\x68\x64\x72\x00\x00\x34\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x05\x00\x02\x00\x02\x00\x00\x00\x08\x00\x03\x00\x00\x00\x00\x02\x08\x00\x04\x00\x00\x00\x00\x02\x08\x00\x06\x00\x00\x00\x00\x01\x08\x00\x05\x00\x00\x00\x00\x00\x2c\x00\x01\x80\x08\x00\x01\x00\x63\x6d\x70\x00\x20\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x05\x0c\x00\x03\x80\x06\x00\x01\x00\x00\x01\x00\x00\x2c\x00\x01\x80\x08\x00\x01\x00\x63\x6d\x70\x00\x20\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x01\x08\x00\x02\x00\x00\x00\x00\x03\x0c\x00\x03\x80\x06\x00\x01\x00\x01\xf4\x00\x00\x30\x00\x01\x80\x0e\x00\x01\x00\x69\x6d\x6d\x65\x64\x69\x61\x74\x65\x00\x00\x00\x1c\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x00\x10\x00\x02\x80\x0c\x00\x02\x80\x08\x00\x01\x00\x00\x00\x00\x00"), |
| 3300 | // batch end |
| 3301 | []byte("\x00\x00\x00\x0a"), |
| 3302 | } |
| 3303 | |
| 3304 | c, err := nftables.New(nftables.WithTestDial( |
| 3305 | func(req []netlink.Message) ([]netlink.Message, error) { |
| 3306 | for idx, msg := range req { |
| 3307 | b, err := msg.MarshalBinary() |
| 3308 | if err != nil { |
| 3309 | t.Fatal(err) |
| 3310 | } |
| 3311 | if len(b) < 16 { |
| 3312 | continue |
| 3313 | } |
| 3314 | b = b[16:] |
| 3315 | if len(want) == 0 { |
| 3316 | t.Errorf("no want entry for message %d: %x", idx, b) |
| 3317 | continue |
| 3318 | } |
| 3319 | if got, want := b, want[0]; !bytes.Equal(got, want) { |
| 3320 | t.Errorf("message %d: %s", idx, linediff(nfdump(got), nfdump(want))) |
| 3321 | } |
| 3322 | want = want[1:] |
| 3323 | } |
| 3324 | return req, nil |
| 3325 | })) |
| 3326 | if err != nil { |
| 3327 | t.Fatal(err) |
| 3328 | } |
| 3329 | |
| 3330 | c.FlushRuleset() |
| 3331 | |
| 3332 | filter := c.AddTable(&nftables.Table{ |
| 3333 | Family: nftables.TableFamilyIPv4, |
| 3334 | Name: "filter", |
| 3335 | }) |
| 3336 | |
| 3337 | input := c.AddChain(&nftables.Chain{ |
| 3338 | Name: "input", |
| 3339 | Table: filter, |
| 3340 | Type: nftables.ChainTypeFilter, |
nothing calls this directly
no test coverage detected
searching dependent graphs…