From patchwork Tue Dec 5 14:07:35 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Shyam Saini X-Patchwork-Id: 844761 X-Patchwork-Delegate: pablo@netfilter.org Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=none (mailfrom) smtp.mailfrom=vger.kernel.org (client-ip=209.132.180.67; helo=vger.kernel.org; envelope-from=netfilter-devel-owner@vger.kernel.org; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="Pjw1hyfq"; dkim-atps=neutral Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by ozlabs.org (Postfix) with ESMTP id 3yrk9K392Rz9tB8 for ; Wed, 6 Dec 2017 01:08:05 +1100 (AEDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752690AbdLEOIC (ORCPT ); Tue, 5 Dec 2017 09:08:02 -0500 Received: from mail-pg0-f67.google.com ([74.125.83.67]:39348 "EHLO mail-pg0-f67.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753414AbdLEOH4 (ORCPT ); Tue, 5 Dec 2017 09:07:56 -0500 Received: by mail-pg0-f67.google.com with SMTP id w7so210496pgv.6 for ; Tue, 05 Dec 2017 06:07:56 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=XmX9v2U3UvXFwrHGwKJlRpXaRseczxp/mdijM0ctXls=; b=Pjw1hyfqoZ6hYHCc6c7xrNEtcwdzdkXimzzqm1Y7wW+UkjTzmZfwB68+VgaNZmaZXF vBCXGDAsUkGpUmu0Jk6aqJq4R/ebWWn58JjF8QmOBabJe+7z62eXFx3l8HOuGplJhy5U Le8PWkf0IEe6c3SIOBgKy2yfpq45dnDAyCGOHOx9qWIF/z+n5tKT7WrazW9peVwYH/DQ mrnWHvqbkbEG8No7W0YLdF64Q6qUJLz7C0eHO8/olY8yT+yIH2d+4B0/RDZWIZH8HQAS ZJqOumImjIUdJe+0iuh3cyzS2VwTO1GrfDh6jimY1IjalmQ6dFhFyWVilNMlPIpgqrve Zgzg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=XmX9v2U3UvXFwrHGwKJlRpXaRseczxp/mdijM0ctXls=; b=NIFSkFC85+cxYlP/Gwu8xM7DKSvUfT5DnICOI1wmI0nLpWECLkVTjKXuxZqkjc6wYu nHmasmFDrx2wyQSAt9fNyOLKMakbh0HK6YlPMQFL50BHzMfRu+n/fgQL8thRkKptVkaY D8aYcw5+o/Nt6ao17BR4k73WZ2EuHvws6koqB7gAY8Nxt71KV42QSc4Q3fJ+FLqRVpRa RkAcD1E8/Jm3OAd9uJf/O2fcTjd4F0pmuw+D3VYIxW0qmgxehm2F8NTx1+3ncwEOf/Zl woFzkgFkR0c/dAMlUfoMSudcKCcDk2mRW2ntJ+A874Cnjf1QsP15HTPah8IUmd4MZgAE d6KQ== X-Gm-Message-State: AJaThX6hrb2a/+vu+bxXtazb+ZPzIGLDJcdt0+B8jxFSwFr/w3dsm5cf 6HkmffZXaaUkFkX0g3n0vtms3w== X-Google-Smtp-Source: AGs4zMbxErT2CHkfQtqQZIZTVUyY2/796AhkbxcCSH01JsGhDSe4n5kfJdtudsG+4DWz6NsNlKfa+Q== X-Received: by 10.99.100.67 with SMTP id y64mr17523465pgb.19.1512482875369; Tue, 05 Dec 2017 06:07:55 -0800 (PST) Received: from administrator-ThinkPad-L450.one97.delhi.net ([203.122.38.200]) by smtp.gmail.com with ESMTPSA id b10sm520200pfj.20.2017.12.05.06.07.53 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Tue, 05 Dec 2017 06:07:54 -0800 (PST) From: Shyam Saini To: netfilter-devel@vger.kernel.org Cc: Shyam Saini Subject: [PATCH nft V5 2/2] tests: shell: Add tests for low level json import Date: Tue, 5 Dec 2017 19:37:35 +0530 Message-Id: <1512482855-29426-2-git-send-email-mayhs11saini@gmail.com> X-Mailer: git-send-email 1.9.1 In-Reply-To: <1512482855-29426-1-git-send-email-mayhs11saini@gmail.com> References: <1512482855-29426-1-git-send-email-mayhs11saini@gmail.com> Sender: netfilter-devel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netfilter-devel@vger.kernel.org Test upcoming "import json" statement. Basically it loads same set of rules by "nft -f" and "nft import vm json" and prints differences(if any) in the ruleset listed by "nft list ruleset" in each case. For Example: $ ./run-tests.sh testcases/import/vm_json_import_0 Signed-off-by: Shyam Saini --- V5: Patch series rebased V4: Adopt new "vm" symbol for export/import operations --- tests/shell/testcases/import/vm_json_import_0 | 71 +++++++++++++++++++++++++++ 1 file changed, 71 insertions(+) create mode 100755 tests/shell/testcases/import/vm_json_import_0 diff --git a/tests/shell/testcases/import/vm_json_import_0 b/tests/shell/testcases/import/vm_json_import_0 new file mode 100755 index 000000000000..dc367f646140 --- /dev/null +++ b/tests/shell/testcases/import/vm_json_import_0 @@ -0,0 +1,71 @@ +#!/bin/bash + +tmpfile=$(mktemp) + +if [ ! -w $tmpfile ] ; then + echo "Failed to create tmp file" >&2 + exit 0 +fi + +trap "rm -rf $tmpfile" EXIT # cleanup if aborted + +RULESET="table ip mangle { + set blackhole { + type ipv4_addr + elements = { 192.168.1.4, 192.168.1.5 } + } + + chain prerouting { + type filter hook prerouting priority 0; policy accept; + tcp dport { ssh, http } accept + ip saddr @blackhole drop + icmp type echo-request accept + iifname \"lo\" accept + icmp type echo-request counter packets 0 bytes 0 + ct state established,related accept + tcp flags != syn counter packets 7 bytes 841 + ip saddr 192.168.1.100 ip daddr 192.168.1.1 counter packets 0 bytes 0 + } +} +table arp x { + chain y { + arp htype 22 + arp ptype ip + arp operation != rrequest + arp operation { request, reply, rrequest, rreply, inrequest, inreply, nak } + arp hlen 33-45 + } +} +table bridge x { + chain y { + type filter hook input priority 0; policy accept; + vlan id 4094 + vlan id 4094 vlan cfi 0 + vlan id 1 ip saddr 10.0.0.0/23 udp dport domain + } +} +table ip6 x { + chain y { + type nat hook postrouting priority 0; policy accept; + icmpv6 id 33-45 + ip6 daddr fe00::1-fe00::200 udp dport domain counter packets 0 bytes 0 + meta l4proto tcp masquerade to :1024 + iifname \"wlan0\" ct state established,new tcp dport vmap { ssh : drop, 222 : drop } masquerade + tcp dport ssh ip6 daddr 1::2 ether saddr 00:0f:54:0c:11:04 accept + ip6 daddr fe00::1-fe00::200 udp dport domain counter packets 0 bytes 0 masquerade + } +}" + +echo "$RULESET" > $tmpfile +$NFT -f $tmpfile +$NFT export vm json > $tmpfile +$NFT flush ruleset +cat $tmpfile | $NFT import vm json + +RESULT="$($NFT list ruleset)" + + +if [ "$RULESET" != "$RESULT" ] ; then + DIFF="$(which diff)" + [ -x $DIFF ] && $DIFF -u <(echo "$RULESET") <(echo "$RESULT") +fi