From patchwork Sat Jun 9 17:34:27 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Arushi Singhal X-Patchwork-Id: 927188 X-Patchwork-Delegate: pablo@netfilter.org Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=none (mailfrom) smtp.mailfrom=vger.kernel.org (client-ip=209.132.180.67; helo=vger.kernel.org; envelope-from=netfilter-devel-owner@vger.kernel.org; receiver=) Authentication-Results: ozlabs.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="nGKy+Bpn"; dkim-atps=neutral Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by ozlabs.org (Postfix) with ESMTP id 4135xp4c9pz9s2g for ; Sun, 10 Jun 2018 03:34:38 +1000 (AEST) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753268AbeFIReh (ORCPT ); Sat, 9 Jun 2018 13:34:37 -0400 Received: from mail-pf0-f196.google.com ([209.85.192.196]:42435 "EHLO mail-pf0-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753207AbeFIReg (ORCPT ); Sat, 9 Jun 2018 13:34:36 -0400 Received: by mail-pf0-f196.google.com with SMTP id w7-v6so8129357pfn.9 for ; Sat, 09 Jun 2018 10:34:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=date:from:to:cc:subject:message-id:mime-version:content-disposition :user-agent; bh=vrV6mIcJTrIbrfyVivoHkB4YBkGBFUXrv6nzAhcoZl4=; b=nGKy+BpnDbWsPcVQvcw7WtucThX5nQ4+lvN9/gdiO1SgTObXGE7C1R1k6akndZKqUS 1SvH2LiHcNjFQ0xTAu5dHyi3Bb1Bg8ROhzCKTMeuVNZxRyoOc2zmXJrryolec9q5yAwd tc3Uaw/tqUUnf6YiTn/TTT2gS2T5yqMnLM4ADTrqkRO5Dt8KhlKP2PR2Pf6Xlcrz+k8Z ud8OeBWXWAWwPw5KiL82P9HyYO25K4KvooFyHGiIwOIgdbQFPswUc46de9OyjwNZbGSU wZIl28rGF4rK1NjJWSx6amETtaCvLAJlEQ75d6RvKpJgI3i6Wht0qlFbFBJYWp6IbuxS uu2Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:mime-version :content-disposition:user-agent; bh=vrV6mIcJTrIbrfyVivoHkB4YBkGBFUXrv6nzAhcoZl4=; b=T/bafqmtYQ1uijpdH7tXBUtWxsJipmPxCWQsUbpmsLYMpnxlTEWU5c/TzM6+kHeBb4 cq3SWxCzjloPhp6JAcl0qrjmAwzY7zHN0L8lj7/L5pHCsUNuLgoNNwgBs15QYF3ovgyF 2EBs+r/T+N5XbVvyldDQ49KDohox0C23OEr0pE1EP5qpo6wceT4C95M+ah32mVetu5+0 zBAXHbTUi2kWmLxEY25HaSG23ChSDCfw1FTS4L6I9xwLsNCmh8OJDJS/G/X+LXgrk8dP Ys26+QoF4fc5Lcbvypb2Sty5oBEIBUksD4K83OfzGmQlJqlqrNndqpdywO8eJpKVF1IQ P+PA== X-Gm-Message-State: APt69E31polO5xBCajPkDC9pOMWEWnxe6DCszH/W2eFD8eRdcwRi/FXK F2CoKSIc9wuqdmoprwA3w87ydq3b X-Google-Smtp-Source: ADUXVKLorEAG47dPSgZQ6I3JZw6GZ3o0hnYnxMV4N/zEzDKSSyQHUNDqlmnjnX5Dory2JHeG42qwng== X-Received: by 2002:a62:e117:: with SMTP id q23-v6mr10982764pfh.75.1528565675901; Sat, 09 Jun 2018 10:34:35 -0700 (PDT) Received: from arushi-HP-Laptop-15-bs1xx ([2405:204:5423:1593:b4fd:e676:fa38:accb]) by smtp.gmail.com with ESMTPSA id x124-v6sm29370311pgb.53.2018.06.09.10.34.34 (version=TLS1 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Sat, 09 Jun 2018 10:34:35 -0700 (PDT) Date: Sat, 9 Jun 2018 23:04:27 +0530 From: Arushi Singhal To: pablo@netfilter.org Cc: netfilter-devel@vger.kernel.org Subject: [PATCH v2] iptables: tests: shell: add shell test-suite Message-ID: <20180609173427.GA6139@arushi-HP-Laptop-15-bs1xx> MIME-Version: 1.0 Content-Disposition: inline User-Agent: Mutt/1.5.24 (2015-08-30) Sender: netfilter-devel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netfilter-devel@vger.kernel.org To run the test suite (as root): % cd iptables/tests/shell % ./run-tests.sh Test files are executables files with the pattern <> , where N is the expected return code of the executable. Since they are located with `find', test-files can be spreaded in any sub-directories. You can turn on a verbose execution by calling: % ./run-tests.sh -v Before each call to the test-files, `kernel_cleanup' will be called. Also, test-files will receive the environment variable $IPTABLES which contains the path to the iptables binary being tested. You can pass an arbitrary $IPTABLES value as well: % IPTABLES=/../../xtables-multi iptables ./run-tests.sh Signed-off-by: Arushi Singhal --- changes in v2 - Called the same script setting $IPTABLES to iptables or ip6tables instead of having the same script twice for iptables and ip6tables. iptables/tests/shell/run-tests.sh | 129 +++++++++++++++++++++ .../tests/shell/testcases/chain/0001duplicate_1 | 11 ++ .../tests/shell/testcases/chain/0002duplicate_0 | 11 ++ .../tests/shell/testcases/chain/0003duplicate_1 | 11 ++ iptables/tests/shell/testcases/chain/0004rename_0 | 6 + iptables/tests/shell/testcases/chain/0005rename_1 | 12 ++ 6 files changed, 180 insertions(+) create mode 100755 iptables/tests/shell/run-tests.sh create mode 100755 iptables/tests/shell/testcases/chain/0001duplicate_1 create mode 100755 iptables/tests/shell/testcases/chain/0002duplicate_0 create mode 100755 iptables/tests/shell/testcases/chain/0003duplicate_1 create mode 100755 iptables/tests/shell/testcases/chain/0004rename_0 create mode 100755 iptables/tests/shell/testcases/chain/0005rename_1 diff --git a/iptables/tests/shell/run-tests.sh b/iptables/tests/shell/run-tests.sh new file mode 100755 index 0000000..cf5cbdc --- /dev/null +++ b/iptables/tests/shell/run-tests.sh @@ -0,0 +1,129 @@ +#!/bin/bash + +#configuration +TESTDIR="./$(dirname $0)/" +RETURNCODE_SEPARATOR="_" +XTABLES_MULTI="$(dirname $0)/../../xtables-multi" +DIFF=$(which diff) + +msg_error() { + echo "E: $1 ..." >&2 + exit 1 +} + +msg_warn() { + echo "W: $1" >&2 +} + +msg_info() { + echo "I: $1" +} + +if [ "$(id -u)" != "0" ] ; then + msg_error "this requires root!" +fi + +[ -z "$IPTABLES" ] && IPTABLES=$XTABLES_MULTI +if [ ! -x "$IPTABLES" ] ; then + msg_error "no xtables-multi binary!" +else + msg_info "using xtables-multi binary $IPTABLES" +fi + +if [ ! -d "$TESTDIR" ] ; then + msg_error "missing testdir $TESTDIR" +fi + +FIND="$(which find)" +if [ ! -x "$FIND" ] ; then + msg_error "no find binary found" +fi + +MODPROBE="$(which modprobe)" +if [ ! -x "$MODPROBE" ] ; then + msg_error "no modprobe binary found" +fi + +DEPMOD="$(which depmod)" +if [ ! -x "$DEPMOD" ] ; then + msg_error "no depmod binary found" +fi + +if [ "$1" == "-v" ] ; then + VERBOSE=y + shift +fi + +for arg in "$@"; do + if grep ^.*${RETURNCODE_SEPARATOR}[0-9]\\+$ <<< $arg >/dev/null ; then + SINGLE+=" $arg" + VERBOSE=y + else + msg_error "unknown parameter '$arg'" + fi +done + +kernel_cleanup() { + for it in iptables ip6tables; do + for table in filter mangle nat raw; do + $it -t $table -nL >/dev/null 2>&1 || continue # non-existing table + $it -t $table -F # delete rules + $it -t $table -X # delete custom chains + $it -t $table -Z # zero counters + done + done + $DEPMOD -a + $MODPROBE -raq \ + ip_tables iptable_nat iptable_mangle ipt_REJECT +} + +find_tests() { + if [ ! -z "$SINGLE" ] ; then + echo $SINGLE + return + fi + ${FIND} ${TESTDIR} -executable -regex \ + .*${RETURNCODE_SEPARATOR}[0-9]+ | sort +} + + +echo "" +ok=0 +failed=0 + +for testfile in $(find_tests) +do + + for it in iptables ip6tables; do + kernel_cleanup + rc_spec=`echo $(basename ${testfile}) | cut -d _ -f2-` + IPTABLES="$XTABLES_MULTI $it" + + msg_info "[EXECUTING] $testfile" + test_output=$(IPTABLES=$IPTABLES ${testfile} 2>&1) + rc_got=$? + echo -en "\033[1A\033[K" # clean the [EXECUTING] foobar line + + if [ "$rc_got" == "$rc_spec" ] ; then + msg_info "[OK] $testfile" + [ "$VERBOSE" == "y" ] && [ ! -z "$test_output" ] && echo "$test_output" + ((ok++)) + + else + ((failed++)) + if [ "$VERBOSE" == "y" ] ; then + msg_warn "[FAILED] $testfile: expected $rc_spec but got $rc_got" + [ ! -z "$test_output" ] && echo "$test_output" + else + msg_warn "[FAILED] $testfile" + fi + fi + + done +done + +echo "" +msg_info "results: [OK] $ok [FAILED] $failed [TOTAL] $((ok+failed))" + +kernel_cleanup +exit 0 diff --git a/iptables/tests/shell/testcases/chain/0001duplicate_1 b/iptables/tests/shell/testcases/chain/0001duplicate_1 new file mode 100755 index 0000000..6d42cec --- /dev/null +++ b/iptables/tests/shell/testcases/chain/0001duplicate_1 @@ -0,0 +1,11 @@ +#!/bin/bash + +set -e + +$IPTABLES -t filter -N c1 +$IPTABLES -t filter -N c1 + +if [ $? -eq 0 ]; then + echo "E: Duplicate chains" >&2 + exit 0 +fi diff --git a/iptables/tests/shell/testcases/chain/0002duplicate_0 b/iptables/tests/shell/testcases/chain/0002duplicate_0 new file mode 100755 index 0000000..6d42cec --- /dev/null +++ b/iptables/tests/shell/testcases/chain/0002duplicate_0 @@ -0,0 +1,11 @@ +#!/bin/bash + +set -e + +$IPTABLES -t filter -N c1 +$IPTABLES -t filter -N c1 + +if [ $? -eq 0 ]; then + echo "E: Duplicate chains" >&2 + exit 0 +fi diff --git a/iptables/tests/shell/testcases/chain/0003duplicate_1 b/iptables/tests/shell/testcases/chain/0003duplicate_1 new file mode 100755 index 0000000..6d42cec --- /dev/null +++ b/iptables/tests/shell/testcases/chain/0003duplicate_1 @@ -0,0 +1,11 @@ +#!/bin/bash + +set -e + +$IPTABLES -t filter -N c1 +$IPTABLES -t filter -N c1 + +if [ $? -eq 0 ]; then + echo "E: Duplicate chains" >&2 + exit 0 +fi diff --git a/iptables/tests/shell/testcases/chain/0004rename_0 b/iptables/tests/shell/testcases/chain/0004rename_0 new file mode 100755 index 0000000..a85369a --- /dev/null +++ b/iptables/tests/shell/testcases/chain/0004rename_0 @@ -0,0 +1,6 @@ +#!/bin/bash + +set -e + +$IPTABLES -N c1 +$IPTABLES -E c1 c2 diff --git a/iptables/tests/shell/testcases/chain/0005rename_1 b/iptables/tests/shell/testcases/chain/0005rename_1 new file mode 100755 index 0000000..7261b6d --- /dev/null +++ b/iptables/tests/shell/testcases/chain/0005rename_1 @@ -0,0 +1,12 @@ +#!/bin/bash + +set -e + +$IPTABLES -N c1 +$IPTABLES -N c2 +$IPTABLES -E c1 c2 + +if [ $? -eq 0 ] ; then + echo "E: Renamed with existing chain" >&2 + exit 0 +fi