Blame SOURCES/0024-test-direct-verify-rule-order-with-multiple-address-.patch

19026f
From ed0b0a7f967f33729e4ec7472b4229f0317fd92d Mon Sep 17 00:00:00 2001
19026f
From: Eric Garver <eric@garver.life>
19026f
Date: Fri, 9 Apr 2021 13:34:31 -0400
19026f
Subject: [PATCH 24/30] test(direct): verify rule order with multiple address
19026f
 with -s/-d
19026f
19026f
Coverage: rhbz 1940928
19026f
Coverage: rhbz 1949552
19026f
(cherry picked from commit 80c30dacc066af4d6d71d298b5e47625ecee5bdf)
19026f
(cherry picked from commit c1262441db90108eb8044053ae1b93f66f0c2839)
19026f
---
19026f
 src/tests/regression/regression.at  |  1 +
19026f
 src/tests/regression/rhbz1940928.at | 52 +++++++++++++++++++++++++++++
19026f
 2 files changed, 53 insertions(+)
19026f
 create mode 100644 src/tests/regression/rhbz1940928.at
19026f
19026f
diff --git a/src/tests/regression/regression.at b/src/tests/regression/regression.at
19026f
index a49bb3b756e7..8156ee608189 100644
19026f
--- a/src/tests/regression/regression.at
19026f
+++ b/src/tests/regression/regression.at
19026f
@@ -39,3 +39,4 @@ m4_include([regression/rhbz1871298.at])
19026f
 m4_include([regression/rhbz1596304.at])
19026f
 m4_include([regression/gh703.at])
19026f
 m4_include([regression/ipset_netmask_allowed.at])
19026f
+m4_include([regression/rhbz1940928.at])
19026f
diff --git a/src/tests/regression/rhbz1940928.at b/src/tests/regression/rhbz1940928.at
19026f
new file mode 100644
19026f
index 000000000000..0a4367080b5e
19026f
--- /dev/null
19026f
+++ b/src/tests/regression/rhbz1940928.at
19026f
@@ -0,0 +1,52 @@
19026f
+FWD_START_TEST([direct -s/-d multiple addresses])
19026f
+AT_KEYWORDS(direct rhbz1940928 rhbz1949552)
19026f
+CHECK_IPTABLES
19026f
+
19026f
+dnl test triggers a limitation in iptables-restore
19026f
+dnl
19026f
+AT_CHECK([sed -i 's/^IndividualCalls.*/IndividualCalls=no/' ./firewalld.conf])
19026f
+FWD_RELOAD
19026f
+
19026f
+FWD_CHECK([--direct --add-rule ipv4 filter OUTPUT 0 -m state --state ESTABLISHED,RELATED -j ACCEPT], 0, [ignore], [ignore])
19026f
+FWD_CHECK([--direct --add-rule ipv4 filter OUTPUT 2 -p tcp -d 10.0.0.0/8,172.16.0.0/16,192.168.0.0/24 -j ACCEPT], 0, [ignore], [ignore])
19026f
+FWD_CHECK([--direct --add-rule ipv4 filter OUTPUT 2 -p udp -d 10.0.0.0/8,172.16.0.0/16,192.168.0.0/24 -j ACCEPT], 0, [ignore], [ignore])
19026f
+FWD_CHECK([--direct --add-rule ipv4 filter OUTPUT 9 -j DROP], 0, [ignore], [ignore])
19026f
+
19026f
+IPTABLES_LIST_RULES_ALWAYS([filter], [m4_if(iptables, FIREWALL_BACKEND, [OUTPUT_direct], [OUTPUT])], 0, [dnl
19026f
+		ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
19026f
+		ACCEPT     tcp  --  0.0.0.0/0            10.0.0.0/8
19026f
+		ACCEPT     tcp  --  0.0.0.0/0            172.16.0.0/16
19026f
+		ACCEPT     tcp  --  0.0.0.0/0            192.168.0.0/24
19026f
+		ACCEPT     udp  --  0.0.0.0/0            10.0.0.0/8
19026f
+		ACCEPT     udp  --  0.0.0.0/0            172.16.0.0/16
19026f
+		ACCEPT     udp  --  0.0.0.0/0            192.168.0.0/24
19026f
+		DROP       all  --  0.0.0.0/0            0.0.0.0/0
19026f
+])
19026f
+
19026f
+FWD_CHECK([--direct --add-rule ipv4 filter OUTPUT 1 -p sctp -d 10.0.0.0/8,172.16.0.0/16,192.168.0.0/24 -j ACCEPT], 0, [ignore], [ignore])
19026f
+
19026f
+IPTABLES_LIST_RULES_ALWAYS([filter], [m4_if(iptables, FIREWALL_BACKEND, [OUTPUT_direct], [OUTPUT])], 0, [dnl
19026f
+		ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
19026f
+		ACCEPT     sctp --  0.0.0.0/0            10.0.0.0/8
19026f
+		ACCEPT     sctp --  0.0.0.0/0            172.16.0.0/16
19026f
+		ACCEPT     sctp --  0.0.0.0/0            192.168.0.0/24
19026f
+		ACCEPT     tcp  --  0.0.0.0/0            10.0.0.0/8
19026f
+		ACCEPT     tcp  --  0.0.0.0/0            172.16.0.0/16
19026f
+		ACCEPT     tcp  --  0.0.0.0/0            192.168.0.0/24
19026f
+		ACCEPT     udp  --  0.0.0.0/0            10.0.0.0/8
19026f
+		ACCEPT     udp  --  0.0.0.0/0            172.16.0.0/16
19026f
+		ACCEPT     udp  --  0.0.0.0/0            192.168.0.0/24
19026f
+		DROP       all  --  0.0.0.0/0            0.0.0.0/0
19026f
+])
19026f
+
19026f
+FWD_CHECK([--direct --remove-rule ipv4 filter OUTPUT 0 -m state --state ESTABLISHED,RELATED -j ACCEPT], 0, [ignore], [ignore])
19026f
+FWD_CHECK([--direct --remove-rule ipv4 filter OUTPUT 1 -p sctp -d 10.0.0.0/8,172.16.0.0/16,192.168.0.0/24 -j ACCEPT], 0, [ignore], [ignore])
19026f
+FWD_CHECK([--direct --remove-rule ipv4 filter OUTPUT 2 -p tcp -d 10.0.0.0/8,172.16.0.0/16,192.168.0.0/24 -j ACCEPT], 0, [ignore], [ignore])
19026f
+FWD_CHECK([--direct --remove-rule ipv4 filter OUTPUT 2 -p udp -d 10.0.0.0/8,172.16.0.0/16,192.168.0.0/24 -j ACCEPT], 0, [ignore], [ignore])
19026f
+FWD_CHECK([--direct --remove-rule ipv4 filter OUTPUT 9 -j DROP], 0, [ignore], [ignore])
19026f
+
19026f
+
19026f
+IPTABLES_LIST_RULES_ALWAYS([filter], [m4_if(iptables, FIREWALL_BACKEND, [OUTPUT_direct], [OUTPUT])], 0, [dnl
19026f
+])
19026f
+
19026f
+FWD_END_TEST
19026f
-- 
19026f
2.27.0
19026f