MCPcopy Create free account
hub / github.com/google/nftables / TestRuleOperations

Function TestRuleOperations

nftables_test.go:87–232  ·  view source on GitHub ↗
(t *testing.T)

Source from the content-addressed store, hash-verified

85}
86
87func TestRuleOperations(t *testing.T) {
88 // Create a new network namespace to test these operations,
89 // and tear down the namespace at test completion.
90 c, newNS := nftest.OpenSystemConn(t, *enableSysTests)
91 defer nftest.CleanupSystemConn(t, newNS)
92 // Clear all rules at the beginning + end of the test.
93 c.FlushRuleset()
94 defer c.FlushRuleset()
95
96 filter := c.AddTable(&nftables.Table{
97 Family: nftables.TableFamilyIPv4,
98 Name: "filter",
99 })
100
101 prerouting := c.AddChain(&nftables.Chain{
102 Name: "base-chain",
103 Table: filter,
104 Type: nftables.ChainTypeFilter,
105 Hooknum: nftables.ChainHookPrerouting,
106 Priority: nftables.ChainPriorityFilter,
107 })
108
109 c.AddRule(&nftables.Rule{
110 Table: filter,
111 Chain: prerouting,
112 Exprs: []expr.Any{
113 &expr.Verdict{
114 // [ immediate reg 0 drop ]
115 Kind: expr.VerdictDrop,
116 },
117 },
118 })
119
120 c.AddRule(&nftables.Rule{
121 Table: filter,
122 Chain: prerouting,
123 Exprs: []expr.Any{
124 &expr.Verdict{
125 // [ immediate reg 0 drop ]
126 Kind: expr.VerdictDrop,
127 },
128 },
129 })
130
131 c.InsertRule(&nftables.Rule{
132 Table: filter,
133 Chain: prerouting,
134 Exprs: []expr.Any{
135 &expr.Verdict{
136 // [ immediate reg 0 accept ]
137 Kind: expr.VerdictAccept,
138 },
139 },
140 })
141
142 c.InsertRule(&nftables.Rule{
143 Table: filter,
144 Chain: prerouting,

Callers

nothing calls this directly

Calls 10

OpenSystemConnFunction · 0.92
CleanupSystemConnFunction · 0.92
FlushRulesetMethod · 0.80
AddTableMethod · 0.80
AddChainMethod · 0.80
AddRuleMethod · 0.80
InsertRuleMethod · 0.80
FlushMethod · 0.80
GetRulesMethod · 0.80
ReplaceRuleMethod · 0.80

Tested by

no test coverage detected

Used in the wild real call sites across dependent graphs

searching dependent graphs…