Read a ufw rule's direction: an outgoing rule answers no opening, and incoming is the default ufw merges on (hq ADR 0103)
This commit is contained in:
@@ -597,18 +597,24 @@ func TestUfwTakesTheMeshsRuleAndTheOperatorsForOne(t *testing.T) {
|
||||
func TestEveryCapturedRuleFormIsRead(t *testing.T) {
|
||||
want := map[string]string{
|
||||
"allow 22/tcp": "tcp 22 in= from=any", "allow 9200": " 9200 in= from=any",
|
||||
"allow from 192.0.2.0/24 to any port 9300 proto tcp": "tcp 9300 in= from=192.0.2.0/24",
|
||||
"allow in on eth0 to any port 9301 proto tcp": "tcp 9301 in=eth0 from=any",
|
||||
"allow 9500:9510/tcp": "tcp 9500:9510 in= from=any",
|
||||
"allow 80,443/tcp": "tcp 80,443 in= from=any",
|
||||
"allow in on mesh0 to any port 5432 proto tcp": "tcp 5432 in=mesh0 from=any",
|
||||
"route allow 8080/tcp": "tcp 8080 in= from=any",
|
||||
"allow 9900/tcp": "tcp 9900 in= from=any",
|
||||
"allow from 192.0.2.0/24 to any port 9300 proto tcp": "tcp 9300 in= from=192.0.2.0/24",
|
||||
"allow in on eth0 to any port 9301 proto tcp": "tcp 9301 in=eth0 from=any",
|
||||
"allow 9500:9510/tcp": "tcp 9500:9510 in= from=any",
|
||||
"allow 80,443/tcp": "tcp 80,443 in= from=any",
|
||||
"allow in on mesh0 to any port 5432 proto tcp": "tcp 5432 in=mesh0 from=any",
|
||||
"route allow 8080/tcp": "tcp 8080 in= from=any",
|
||||
"allow 9900/tcp": "tcp 9900 in= from=any",
|
||||
"allow out 5671/tcp": "tcp 5671 in= from=any",
|
||||
"deny out 5672/tcp": "tcp 5672 in= from=any",
|
||||
"allow out on eth0 to any port 5673 proto tcp": "tcp 5673 in= from=any",
|
||||
"allow log 9001/tcp": "tcp 9001 in= from=any",
|
||||
"route allow log 8084/tcp": "tcp 8084 in= from=any",
|
||||
"allow in on mesh0 log-all to any port 9002 proto tcp": "tcp 9002 in=mesh0 from=any",
|
||||
}
|
||||
rules, err := added(context.Background(), func(context.Context, string, ...string) (string, error) {
|
||||
return captured(t, "ufw-forms.txt"), nil
|
||||
})
|
||||
if err != nil || len(rules) != 15 {
|
||||
if err != nil || len(rules) != 21 {
|
||||
t.Fatalf("read %d rules: %v", len(rules), err)
|
||||
}
|
||||
for _, rule := range rules {
|
||||
@@ -716,3 +722,37 @@ func TestALogTypeIsReadInEitherPlace(t *testing.T) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnOutgoingRuleNeverAnswersAnOpening(t *testing.T) {
|
||||
// `ufw allow out 5671/tcp` lets this machine reach others; nothing arrives through it, and
|
||||
// ufw keeps it as a rule of its own — captured in testdata/ufw-direction.txt.
|
||||
raw := captured(t, "ufw-direction.txt")
|
||||
if !strings.Contains(raw, "ufw allow out 9007/tcp\nufw allow 9007/tcp") {
|
||||
t.Fatalf("the capture no longer shows an outgoing rule standing beside an incoming one:\n%s", raw)
|
||||
}
|
||||
for _, operators := range []string{"allow out 5671/tcp", "allow out on eth0 to any port 5671 proto tcp",
|
||||
"deny out 5671/tcp"} {
|
||||
f := &fakeUFW{installed: true, active: true, rules: []string{operators}}
|
||||
done, err := Converge(context.Background(), f.run, opening("adoption.bus", 5671, "everywhere", "incoming", 0))
|
||||
if err != nil {
|
||||
t.Errorf("%q: an outgoing rule was taken for a conflict: %v", operators, err)
|
||||
continue
|
||||
}
|
||||
if done.Action != "created" || done.SatisfiedBy != "" {
|
||||
t.Errorf("%q: an outgoing rule answered an incoming opening: %+v", operators, done)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestIncomingIsUfwsDefaultDirection(t *testing.T) {
|
||||
// Captured: `deny in 9006/tcp` and `allow 9006/tcp` are one rule to ufw, so the mesh must read
|
||||
// them as one too, or it would take an operator's refusal over.
|
||||
raw := captured(t, "ufw-direction.txt")
|
||||
if !strings.Contains(raw, "ufw allow 9005/tcp") || strings.Contains(raw, "ufw deny 9006/tcp") {
|
||||
t.Fatalf("the capture no longer shows `in` as the default direction:\n%s", raw)
|
||||
}
|
||||
f := &fakeUFW{installed: true, active: true, rules: []string{"deny in to any port 5671 proto tcp"}}
|
||||
if _, err := Converge(context.Background(), f.run, opening("adoption.bus", 5671, "everywhere", "incoming", 0)); err == nil {
|
||||
t.Error("an incoming refusal ufw would merge was not refused")
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user