From patchwork Sun Oct 15 14:15:19 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Shyam Saini X-Patchwork-Id: 826009 X-Patchwork-Delegate: pablo@netfilter.org Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=none (mailfrom) smtp.mailfrom=vger.kernel.org (client-ip=209.132.180.67; helo=vger.kernel.org; envelope-from=netfilter-devel-owner@vger.kernel.org; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="kFxWor+h"; dkim-atps=neutral Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by ozlabs.org (Postfix) with ESMTP id 3yFNm65Wzpz9t2c for ; Mon, 16 Oct 2017 01:16:06 +1100 (AEDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751767AbdJOOQG (ORCPT ); Sun, 15 Oct 2017 10:16:06 -0400 Received: from mail-pf0-f195.google.com ([209.85.192.195]:52265 "EHLO mail-pf0-f195.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751386AbdJOOQF (ORCPT ); Sun, 15 Oct 2017 10:16:05 -0400 Received: by mail-pf0-f195.google.com with SMTP id e64so13874483pfk.9 for ; Sun, 15 Oct 2017 07:16:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=aEoH6fYMl5/mpJimnm3QLwY3SSt1sByXc0SFhGZz7LY=; b=kFxWor+hfY3efXSl7qQ6gCD7mIVVxnqWCyZ7KTFG1s7el4kpyMKp6P8PdZXEgKM4hA IoLy89Ux6tL5Ftr0nOZTKyaZhAF5rYmTuO1Fk+UgB4usSXEv342LdgQI5pRkTQMD74pF kXDEB+EZprXV7FqHw+qBps3eBFyG/CkbhqVXo0YHVZw6bjdiT6W+T/Rd9DdOpBZ/4tlQ +WhkjiqSMhUCvp2qYuG98WIJWlEtBGmgN5gNutfUMDzfxuVYQmLhRfWF6bm/epyhZXTN mce3Adth4Gehl6YotmmOpNvc1OLjrJw3ia5dCm6Zg+pCOrm4y8OeG9T0Ane1+bi42Dwj GNjw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=aEoH6fYMl5/mpJimnm3QLwY3SSt1sByXc0SFhGZz7LY=; b=L49Zc3jVpieGNNNxcPA3VJLz3RW7bXX9WwWRaP4APOoIq5mnkRg42mjRb72LPzyniV 0R64N9oUZqHBVh8e65qYX/VVMkkcNxqL/6iIurIJjYCArKw+KBNBk4DJWTSWfRZNc57y Lhyvz/96ZFRSjT/v8dq2uD5Z6I+6d6LjOlFBPCiujZOJ9pUuZQ0tYL3EOK+7F22cnW6g xF0NbnV5FRI3NoRw4L6zC2fS+KsalzTXWch3xCbp8j/xErtDqinZcv7etKgQHkGXfbzX VvFowwX6Egaq7nxZsaUxjPKVcLDfFn8lFSrZBqi+9BsUNQsUo6TmVjNN7adsDHpibPJE Egrw== X-Gm-Message-State: AMCzsaU+brxJra8ezTQ7z8/8ZGKbQz+5dRlNXJjty1g6Mny6caZGH55M iykLLvz07ubKxEmGwjmFeb+l1/tj X-Google-Smtp-Source: AOwi7QCqt+OApgQ/JbFVBN5+Cu4ytzhdZrGAVTcQ1Km/xTDferOAWyHA7O2OTo7e5tA+PikF1WNTEQ== X-Received: by 10.159.207.139 with SMTP id z11mr6258906plo.335.1508076964280; Sun, 15 Oct 2017 07:16:04 -0700 (PDT) Received: from localhost.localdomain ([42.111.4.189]) by smtp.gmail.com with ESMTPSA id b2sm9084456pgt.14.2017.10.15.07.16.02 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Sun, 15 Oct 2017 07:16:03 -0700 (PDT) From: Shyam Saini To: netfilter-devel@vger.kernel.org Cc: Shyam Saini Subject: [PATCH nft V4 2/2] tests: shell: Add tests for low level json import Date: Sun, 15 Oct 2017 19:45:19 +0530 Message-Id: <1508076919-25873-2-git-send-email-mayhs11saini@gmail.com> X-Mailer: git-send-email 1.9.1 In-Reply-To: <1508076919-25873-1-git-send-email-mayhs11saini@gmail.com> References: <1508076919-25873-1-git-send-email-mayhs11saini@gmail.com> Sender: netfilter-devel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netfilter-devel@vger.kernel.org Test upcoming "import json" statement. Basically it loads same set of rules by "nft -f" and "nft import vm json" and prints differences(if any) in the ruleset listed by "nft list ruleset" in each case. For Example: $ ./run-tests.sh testcases/import/vm_json_import_0 Signed-off-by: Shyam Saini --- V4: Adopt new "vm" symbol for export/import operations --- tests/shell/testcases/import/vm_json_import_0 | 72 +++++++++++++++++++++++++++ 1 file changed, 72 insertions(+) create mode 100755 tests/shell/testcases/import/vm_json_import_0 diff --git a/tests/shell/testcases/import/vm_json_import_0 b/tests/shell/testcases/import/vm_json_import_0 new file mode 100755 index 000000000000..87ab8c8b6679 --- /dev/null +++ b/tests/shell/testcases/import/vm_json_import_0 @@ -0,0 +1,72 @@ +#!/bin/bash + +tmpfile=$(mktemp) + +if [ ! -w $tmpfile ] ; then + echo "Failed to create tmp file" >&2 + exit 0 +fi + +trap "rm -rf $tmpfile" EXIT # cleanup if aborted + +RULESET="table ip mangle { + set blackhole { + type ipv4_addr + elements = { 192.168.1.4, 192.168.1.5 } + } + + chain prerouting { + type filter hook prerouting priority 0; policy accept; + tcp dport { ssh, http } accept + ip saddr @blackhole drop + icmp type echo-request accept + iifname \"lo\" accept + icmp type echo-request counter packets 0 bytes 0 + ct state established,related accept + tcp flags != syn counter packets 7 bytes 841 + ip saddr 192.168.1.100 ip daddr 192.168.1.1 counter packets 0 bytes 0 + } +} +table arp x { + chain y { + arp htype 22 + arp ptype ip + arp operation != rrequest + arp operation { request, reply, rrequest, rreply, inrequest, inreply, nak } + arp hlen 33-45 + } +} +table bridge x { + chain y { + type filter hook input priority 0; policy accept; + vlan id 4094 + vlan id 4094 vlan cfi 0 + vlan id 1 ip saddr 10.0.0.0/23 udp dport domain + } +} +table ip6 x { + chain y { + type nat hook postrouting priority 0; policy accept; + icmpv6 id 33-45 + ip6 daddr fe00::1-fe00::200 udp dport domain counter packets 0 bytes 0 + meta l4proto tcp masquerade to :1024 + iifname \"wlan0\" ct state established,new tcp dport vmap { ssh : drop, 222 : drop } masquerade + tcp dport ssh ip6 daddr 1::2 ether saddr 00:0f:54:0c:11:04 accept + ip6 daddr fe00::1-fe00::200 udp dport domain counter packets 0 bytes 0 masquerade + } +}" + +echo "$RULESET" > $tmpfile +$NFT -f $tmpfile +$NFT export vm json > $tmpfile +$NFT flush ruleset +cat $tmpfile | $NFT import vm json + +RESULT="$($NFT list ruleset)" + + +if [ "$RULESET" != "$RESULT" ] ; then + DIFF="$(which diff)" + [ -x $DIFF ] && $DIFF -u <(echo "$RULESET") <(echo "$RESULT") +fi +