Blame SOURCES/0027-test-enhance-test-for-rhbz1729097.patch

40251c
From a698ca94c40b6edf058995f9f2b1fc197a16efe4 Mon Sep 17 00:00:00 2001
40251c
From: Eric Garver <eric@garver.life>
40251c
Date: Thu, 16 Jan 2020 09:02:28 -0500
40251c
Subject: [PATCH 27/37] test: enhance test for rhbz1729097
40251c
40251c
(cherry picked from commit c2b8059559c210e586b03b44eaf189370b976770)
40251c
(cherry picked from commit 47368842f5519b43cb02cb4f2cca59b9049e5268)
40251c
---
40251c
 src/tests/regression/rhbz1715977.at | 107 +++++++++++++++++++++++++++-
40251c
 1 file changed, 105 insertions(+), 2 deletions(-)
40251c
40251c
diff --git a/src/tests/regression/rhbz1715977.at b/src/tests/regression/rhbz1715977.at
40251c
index ce6dd075c2b5..5de9b5679023 100644
40251c
--- a/src/tests/regression/rhbz1715977.at
40251c
+++ b/src/tests/regression/rhbz1715977.at
40251c
@@ -1,9 +1,112 @@
40251c
-FWD_START_TEST([rich rule destination with service destination])
40251c
-AT_KEYWORDS(rich service rhbz1715977)
40251c
+FWD_START_TEST([rich rule source/destination with service destination])
40251c
+AT_KEYWORDS(rich service rhbz1715977 rhbz1729097 rhbz1791783)
40251c
 
40251c
 FWD_CHECK([-q --permanent --zone=internal --add-interface=foobar0])
40251c
 FWD_CHECK([-q --permanent --zone=internal --add-rich-rule='rule family=ipv4 destination address="192.168.122.235/32" service name="ssh" accept'])
40251c
 FWD_RELOAD
40251c
+NFT_LIST_RULES([inet], [filter_IN_internal_allow], 0, [dnl
40251c
+    table inet firewalld {
40251c
+        chain filter_IN_internal_allow {
40251c
+            tcp dport 22 ct state new,untracked accept
40251c
+            ip daddr 224.0.0.251 udp dport 5353 ct state new,untracked accept
40251c
+            ip6 daddr ff02::fb udp dport 5353 ct state new,untracked accept
40251c
+            udp dport 137 ct helper set "helper-netbios-ns-udp"
40251c
+            udp dport 137 ct state new,untracked accept
40251c
+            udp dport 138 ct state new,untracked accept
40251c
+            ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
40251c
+            tcp dport 9090 ct state new,untracked accept
40251c
+            ip daddr 192.168.122.235 tcp dport 22 ct state new,untracked accept
40251c
+        }
40251c
+    }
40251c
+])
40251c
+IPTABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
40251c
+    ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp -- 0.0.0.0/0 224.0.0.251 udp dpt:5353 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:137 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:138 ctstate NEW,UNTRACKED
40251c
+    ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
40251c
+    ACCEPT tcp -- 0.0.0.0/0 192.168.122.235 tcp dpt:22 ctstate NEW,UNTRACKED
40251c
+])
40251c
+IP6TABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
40251c
+    ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 ff02::fb udp dpt:5353 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 ::/0 udp dpt:137 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 ::/0 udp dpt:138 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
40251c
+    ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
40251c
+])
40251c
+
40251c
+FWD_CHECK([-q --zone=internal --add-rich-rule='rule family=ipv4 destination address="192.168.111.222/32" source address="10.10.10.0/24" service name="ssh" accept'])
40251c
+NFT_LIST_RULES([inet], [filter_IN_internal_allow], 0, [dnl
40251c
+    table inet firewalld {
40251c
+        chain filter_IN_internal_allow {
40251c
+            tcp dport 22 ct state new,untracked accept
40251c
+            ip daddr 224.0.0.251 udp dport 5353 ct state new,untracked accept
40251c
+            ip6 daddr ff02::fb udp dport 5353 ct state new,untracked accept
40251c
+            udp dport 137 ct helper set "helper-netbios-ns-udp"
40251c
+            udp dport 137 ct state new,untracked accept
40251c
+            udp dport 138 ct state new,untracked accept
40251c
+            ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
40251c
+            tcp dport 9090 ct state new,untracked accept
40251c
+            ip daddr 192.168.122.235 tcp dport 22 ct state new,untracked accept
40251c
+            ip daddr 192.168.111.222 ip saddr 10.10.10.0/24 tcp dport 22 ct state new,untracked accept
40251c
+        }
40251c
+    }
40251c
+])
40251c
+IPTABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
40251c
+    ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp -- 0.0.0.0/0 224.0.0.251 udp dpt:5353 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:137 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:138 ctstate NEW,UNTRACKED
40251c
+    ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
40251c
+    ACCEPT tcp -- 0.0.0.0/0 192.168.122.235 tcp dpt:22 ctstate NEW,UNTRACKED
40251c
+    ACCEPT tcp -- 10.10.10.0/24 192.168.111.222 tcp dpt:22 ctstate NEW,UNTRACKED
40251c
+])
40251c
+IP6TABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
40251c
+    ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 ff02::fb udp dpt:5353 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 ::/0 udp dpt:137 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 ::/0 udp dpt:138 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
40251c
+    ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
40251c
+])
40251c
+
40251c
+FWD_CHECK([-q --zone=internal --add-rich-rule='rule family=ipv4 service name="ssdp" accept'])
40251c
+NFT_LIST_RULES([inet], [filter_IN_internal_allow], 0, [dnl
40251c
+    table inet firewalld {
40251c
+        chain filter_IN_internal_allow {
40251c
+            tcp dport 22 ct state new,untracked accept
40251c
+            ip daddr 224.0.0.251 udp dport 5353 ct state new,untracked accept
40251c
+            ip6 daddr ff02::fb udp dport 5353 ct state new,untracked accept
40251c
+            udp dport 137 ct helper set "helper-netbios-ns-udp"
40251c
+            udp dport 137 ct state new,untracked accept
40251c
+            udp dport 138 ct state new,untracked accept
40251c
+            ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
40251c
+            tcp dport 9090 ct state new,untracked accept
40251c
+            ip daddr 192.168.122.235 tcp dport 22 ct state new,untracked accept
40251c
+            ip daddr 192.168.111.222 ip saddr 10.10.10.0/24 tcp dport 22 ct state new,untracked accept
40251c
+            ip daddr 239.255.255.250 udp dport 1900 ct state new,untracked accept
40251c
+        }
40251c
+    }
40251c
+])
40251c
+IPTABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
40251c
+    ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp -- 0.0.0.0/0 224.0.0.251 udp dpt:5353 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:137 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:138 ctstate NEW,UNTRACKED
40251c
+    ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
40251c
+    ACCEPT tcp -- 0.0.0.0/0 192.168.122.235 tcp dpt:22 ctstate NEW,UNTRACKED
40251c
+    ACCEPT tcp -- 10.10.10.0/24 192.168.111.222 tcp dpt:22 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp -- 0.0.0.0/0 239.255.255.250 udp dpt:1900 ctstate NEW,UNTRACKED
40251c
+])
40251c
+IP6TABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
40251c
+    ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 ff02::fb udp dpt:5353 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 ::/0 udp dpt:137 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 ::/0 udp dpt:138 ctstate NEW,UNTRACKED
40251c
+    ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
40251c
+    ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
40251c
+])
40251c
 
40251c
 FWD_CHECK([-q --zone=internal --add-rich-rule='rule family=ipv4 destination address="192.168.122.235/32" service name="mdns" accept'], 122, [ignore], [ignore])
40251c
 FWD_CHECK([-q --permanent --zone=internal --add-rich-rule='rule family=ipv4 destination address="192.168.122.235/32" service name="mdns" accept'])
40251c
-- 
40251c
2.23.0
40251c