Refuse an opening ufw would merge into a found rule that does other than a plain allow, and read log types in either place (hq ADR 0103)
This commit is contained in:
@@ -658,7 +658,6 @@ func TestARuleThatDoesNotAnswerTheOpeningLeavesItToBeAdded(t *testing.T) {
|
||||
"allow from 192.0.2.0/24 to any port 5671 proto tcp", // narrower: from one range
|
||||
"allow in on eth0 to any port 5671 proto tcp", // narrower: one interface
|
||||
"allow 5671/udp", // another protocol
|
||||
"deny 5671/tcp", // refuses
|
||||
"route allow 5671/tcp", // another path
|
||||
"allow to 192.0.2.1 port 5671 proto tcp", // one address
|
||||
} {
|
||||
@@ -681,3 +680,39 @@ func TestAnOpeningWhoseFoundRuleIsGoneIsAddedAgain(t *testing.T) {
|
||||
t.Fatalf("the opening was not added once nothing answered it: %+v %v", done, err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestARuleUfwWouldMergeThatDoesOtherThanAllowRefusesTheOpening(t *testing.T) {
|
||||
// ufw takes two rules differing only in action or log type for one, and adding the mesh's
|
||||
// would turn the operator's refusal into an allow (novox/hq ADR 0103).
|
||||
for _, operators := range []string{
|
||||
"deny 5671/tcp",
|
||||
"reject 5671/tcp",
|
||||
"limit 5671/tcp",
|
||||
"allow log 5671/tcp",
|
||||
"allow log-all proto tcp to any port 5671",
|
||||
"deny in log to any port 5671 proto tcp comment 'operator note'",
|
||||
} {
|
||||
f := &fakeUFW{installed: true, active: true, rules: []string{operators}}
|
||||
_, err := Converge(context.Background(), f.run, opening("adoption.bus", 5671, "everywhere", "incoming", 0))
|
||||
if err == nil || !strings.Contains(err.Error(), operators) {
|
||||
t.Errorf("%q: the conflict was not refused naming the rule: %v", operators, err)
|
||||
}
|
||||
if f.added() != 0 || len(f.rules) != 1 || f.rules[0] != operators {
|
||||
t.Errorf("%q: something was added or changed: %v %v", operators, f.asked, f.rules)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestALogTypeIsReadInEitherPlace(t *testing.T) {
|
||||
for rule, want := range map[string]string{
|
||||
"allow log 22/tcp": "allow log 22 tcp in=",
|
||||
"allow in log-all on mesh0 to any port 5432 proto tcp": "allow log-all 5432 tcp in=mesh0",
|
||||
"route deny log in on mesh0 to any port 80 proto tcp": "deny log 80 tcp in=mesh0",
|
||||
"allow 22/tcp comment 'log'": "allow 22 tcp in=",
|
||||
} {
|
||||
r, ok := parseRule(rule)
|
||||
if got := r.action + " " + r.log + " " + r.port + " " + r.proto + " in=" + r.in; !ok || got != want {
|
||||
t.Errorf("%q read as %q (%v), want %q", rule, got, ok, want)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user