Blame SOURCES/0034-tests-shell-Add-test-for-bitwise-avoidance-fixes.patch

87db66
From 6aef90100bebe2b00d4edffe59fb9c43643816de Mon Sep 17 00:00:00 2001
87db66
From: Phil Sutter <phil@nwl.cc>
87db66
Date: Tue, 10 Nov 2020 14:50:46 +0100
87db66
Subject: [PATCH] tests/shell: Add test for bitwise avoidance fixes
87db66
87db66
Masked address matching was recently improved to avoid bitwise
87db66
expression if the given mask covers full bytes. Make use of nft netlink
87db66
debug output to assert iptables-nft generates the right bytecode for
87db66
each situation.
87db66
87db66
Signed-off-by: Phil Sutter <phil@nwl.cc>
87db66
(cherry picked from commit 81a2e128512837b53e5b9ea501b6c8dc64eeca78)
87db66
Signed-off-by: Phil Sutter <psutter@redhat.com>
87db66
---
87db66
 .../nft-only/0009-needless-bitwise_0          | 339 ++++++++++++++++++
87db66
 1 file changed, 339 insertions(+)
87db66
 create mode 100755 iptables/tests/shell/testcases/nft-only/0009-needless-bitwise_0
87db66
87db66
diff --git a/iptables/tests/shell/testcases/nft-only/0009-needless-bitwise_0 b/iptables/tests/shell/testcases/nft-only/0009-needless-bitwise_0
87db66
new file mode 100755
87db66
index 0000000000000..c5c6e706a1029
87db66
--- /dev/null
87db66
+++ b/iptables/tests/shell/testcases/nft-only/0009-needless-bitwise_0
87db66
@@ -0,0 +1,339 @@
87db66
+#!/bin/bash -x
87db66
+
87db66
+[[ $XT_MULTI == *xtables-nft-multi ]] || { echo "skip $XT_MULTI"; exit 0; }
87db66
+set -e
87db66
+
87db66
+nft flush ruleset
87db66
+
87db66
+(
87db66
+	echo "*filter"
87db66
+	for plen in "" 32 30 24 16 8 0; do
87db66
+		addr="10.1.2.3${plen:+/}$plen"
87db66
+		echo "-A OUTPUT -d $addr"
87db66
+	done
87db66
+	echo "COMMIT"
87db66
+) | $XT_MULTI iptables-restore
87db66
+
87db66
+(
87db66
+	echo "*filter"
87db66
+	for plen in "" 128 124 120 112 88 80 64 48 16 8 0; do
87db66
+		addr="feed:c0ff:ee00:0102:0304:0506:0708:090A${plen:+/}$plen"
87db66
+		echo "-A OUTPUT -d $addr"
87db66
+	done
87db66
+	echo "COMMIT"
87db66
+) | $XT_MULTI ip6tables-restore
87db66
+
87db66
+masks="
87db66
+ff:ff:ff:ff:ff:ff
87db66
+ff:ff:ff:ff:ff:f0
87db66
+ff:ff:ff:ff:ff:00
87db66
+ff:ff:ff:ff:00:00
87db66
+ff:ff:ff:00:00:00
87db66
+ff:ff:00:00:00:00
87db66
+ff:00:00:00:00:00
87db66
+"
87db66
+(
87db66
+	echo "*filter"
87db66
+	for plen in "" 32 30 24 16 8 0; do
87db66
+		addr="10.1.2.3${plen:+/}$plen"
87db66
+		echo "-A OUTPUT -d $addr"
87db66
+	done
87db66
+	for mask in $masks; do
87db66
+		echo "-A OUTPUT --destination-mac fe:ed:00:c0:ff:ee/$mask"
87db66
+	done
87db66
+	echo "COMMIT"
87db66
+) | $XT_MULTI arptables-restore
87db66
+
87db66
+(
87db66
+	echo "*filter"
87db66
+	for mask in $masks; do
87db66
+		echo "-A OUTPUT -d fe:ed:00:c0:ff:ee/$mask"
87db66
+	done
87db66
+	echo "COMMIT"
87db66
+) | $XT_MULTI ebtables-restore
87db66
+
87db66
+EXPECT="ip filter OUTPUT 4
87db66
+  [ payload load 4b @ network header + 16 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0302010a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip filter OUTPUT 5 4
87db66
+  [ payload load 4b @ network header + 16 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0302010a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip filter OUTPUT 6 5
87db66
+  [ payload load 4b @ network header + 16 => reg 1 ]
87db66
+  [ bitwise reg 1 = (reg=1 & 0xfcffffff ) ^ 0x00000000 ]
87db66
+  [ cmp eq reg 1 0x0002010a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip filter OUTPUT 7 6
87db66
+  [ payload load 3b @ network header + 16 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0002010a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip filter OUTPUT 8 7
87db66
+  [ payload load 2b @ network header + 16 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0000010a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip filter OUTPUT 9 8
87db66
+  [ payload load 1b @ network header + 16 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0000000a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip filter OUTPUT 10 9
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 4
87db66
+  [ payload load 16b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xffc0edfe 0x020100ee 0x06050403 0x0a090807 ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 5 4
87db66
+  [ payload load 16b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xffc0edfe 0x020100ee 0x06050403 0x0a090807 ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 6 5
87db66
+  [ payload load 16b @ network header + 24 => reg 1 ]
87db66
+  [ bitwise reg 1 = (reg=1 & 0xffffffff 0xffffffff 0xffffffff 0xf0ffffff ) ^ 0x00000000 0x00000000 0x00000000 0x00000000 ]
87db66
+  [ cmp eq reg 1 0xffc0edfe 0x020100ee 0x06050403 0x00090807 ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 7 6
87db66
+  [ payload load 15b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xffc0edfe 0x020100ee 0x06050403 0x00090807 ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 8 7
87db66
+  [ payload load 14b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xffc0edfe 0x020100ee 0x06050403 0x00000807 ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 9 8
87db66
+  [ payload load 11b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xffc0edfe 0x020100ee 0x00050403 ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 10 9
87db66
+  [ payload load 10b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xffc0edfe 0x020100ee 0x00000403 ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 11 10
87db66
+  [ payload load 8b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xffc0edfe 0x020100ee ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 12 11
87db66
+  [ payload load 6b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xffc0edfe 0x000000ee ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 13 12
87db66
+  [ payload load 2b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0000edfe ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 14 13
87db66
+  [ payload load 1b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x000000fe ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+ip6 filter OUTPUT 15 14
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 3
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 4b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0302010a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 4 3
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 4b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0302010a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 5 4
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 4b @ network header + 24 => reg 1 ]
87db66
+  [ bitwise reg 1 = (reg=1 & 0xfcffffff ) ^ 0x00000000 ]
87db66
+  [ cmp eq reg 1 0x0002010a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 6 5
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 3b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0002010a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 7 6
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 2b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0000010a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 8 7
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 1b @ network header + 24 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0000000a ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 9 8
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 10 9
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 6b @ network header + 18 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xc000edfe 0x0000eeff ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 11 10
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 6b @ network header + 18 => reg 1 ]
87db66
+  [ bitwise reg 1 = (reg=1 & 0xffffffff 0x0000f0ff ) ^ 0x00000000 0x00000000 ]
87db66
+  [ cmp eq reg 1 0xc000edfe 0x0000e0ff ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 12 11
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 5b @ network header + 18 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xc000edfe 0x000000ff ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 13 12
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 4b @ network header + 18 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xc000edfe ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 14 13
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 3b @ network header + 18 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0000edfe ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 15 14
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 2b @ network header + 18 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0000edfe ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+arp filter OUTPUT 16 15
87db66
+  [ payload load 2b @ network header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000100 ]
87db66
+  [ payload load 1b @ network header + 4 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000006 ]
87db66
+  [ payload load 1b @ network header + 5 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x00000004 ]
87db66
+  [ payload load 1b @ network header + 18 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x000000fe ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+bridge filter OUTPUT 4
87db66
+  [ payload load 6b @ link header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xc000edfe 0x0000eeff ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+bridge filter OUTPUT 5 4
87db66
+  [ payload load 6b @ link header + 0 => reg 1 ]
87db66
+  [ bitwise reg 1 = (reg=1 & 0xffffffff 0x0000f0ff ) ^ 0x00000000 0x00000000 ]
87db66
+  [ cmp eq reg 1 0xc000edfe 0x0000e0ff ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+bridge filter OUTPUT 6 5
87db66
+  [ payload load 5b @ link header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xc000edfe 0x000000ff ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+bridge filter OUTPUT 7 6
87db66
+  [ payload load 4b @ link header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0xc000edfe ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+bridge filter OUTPUT 8 7
87db66
+  [ payload load 3b @ link header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0000edfe ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+bridge filter OUTPUT 9 8
87db66
+  [ payload load 2b @ link header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x0000edfe ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+
87db66
+bridge filter OUTPUT 10 9
87db66
+  [ payload load 1b @ link header + 0 => reg 1 ]
87db66
+  [ cmp eq reg 1 0x000000fe ]
87db66
+  [ counter pkts 0 bytes 0 ]
87db66
+"
87db66
+
87db66
+diff -u -Z <(echo "$EXPECT") <(nft --debug=netlink list ruleset | awk '/^table/{exit} {print}')
87db66
-- 
87db66
2.28.0
87db66