blob: 2c7b0f052648896f2a7f9488f1f7764cf4a4e390 [file] [log] [blame]
Garrick Evansf0ab7132019-06-18 14:50:42 +09001// Copyright 2019 The Chromium OS Authors. All rights reserved.
2// Use of this source code is governed by a BSD-style license that can be
3// found in the LICENSE file.
4
Garrick Evans3388a032020-03-24 11:25:55 +09005#include "patchpanel/datapath.h"
Garrick Evansf0ab7132019-06-18 14:50:42 +09006
Garrick Evansc7ae82c2019-09-04 16:25:10 +09007#include <linux/if_tun.h>
Taoyu Li90c13912019-11-26 17:56:54 +09008#include <net/if.h>
Garrick Evansc7ae82c2019-09-04 16:25:10 +09009#include <sys/ioctl.h>
10
Garrick Evansf0ab7132019-06-18 14:50:42 +090011#include <utility>
12#include <vector>
13
Garrick Evansc7ae82c2019-09-04 16:25:10 +090014#include <base/bind.h>
Qijiang Fane90b8792020-03-09 16:15:41 +090015#include <base/bind_helpers.h>
Garrick Evansf0ab7132019-06-18 14:50:42 +090016#include <base/strings/string_util.h>
Garrick Evans8e8e3472020-01-23 14:03:50 +090017#include <gmock/gmock.h>
Garrick Evansf0ab7132019-06-18 14:50:42 +090018#include <gtest/gtest.h>
19
Jason Jeremy Imana7273a32020-08-04 11:25:31 +090020#include "patchpanel/mock_firewall.h"
Garrick Evans3388a032020-03-24 11:25:55 +090021#include "patchpanel/net_util.h"
Garrick Evansf0ab7132019-06-18 14:50:42 +090022
Garrick Evans8e8e3472020-01-23 14:03:50 +090023using testing::_;
24using testing::ElementsAre;
25using testing::Return;
26using testing::StrEq;
27
Garrick Evans3388a032020-03-24 11:25:55 +090028namespace patchpanel {
Garrick Evansc7ae82c2019-09-04 16:25:10 +090029namespace {
30
Hugo Benichi76675592020-04-08 14:29:57 +090031// TODO(hugobenichi) Centralize this constant definition
32constexpr pid_t kTestPID = -2;
33
Hugo Benichie8758b52020-04-03 14:49:01 +090034std::vector<ioctl_req_t> ioctl_reqs;
35std::vector<std::pair<std::string, struct rtentry>> ioctl_rtentry_args;
Garrick Evansc7ae82c2019-09-04 16:25:10 +090036
37// Capture all ioctls and succeed.
Taoyu Li90c13912019-11-26 17:56:54 +090038int ioctl_req_cap(int fd, ioctl_req_t req, ...) {
Hugo Benichie8758b52020-04-03 14:49:01 +090039 ioctl_reqs.push_back(req);
40 return 0;
41}
42
43// Capture ioctls for SIOCADDRT and SIOCDELRT and succeed.
44int ioctl_rtentry_cap(int fd, ioctl_req_t req, struct rtentry* arg) {
45 ioctl_reqs.push_back(req);
46 ioctl_rtentry_args.push_back({"", *arg});
47 // Copy the string poited by rtentry.rt_dev because Add/DeleteIPv4Route pass
48 // this value to ioctl() on the stack.
49 if (arg->rt_dev) {
50 auto& cap = ioctl_rtentry_args.back();
51 cap.first = std::string(arg->rt_dev);
52 cap.second.rt_dev = (char*)cap.first.c_str();
53 }
Garrick Evansc7ae82c2019-09-04 16:25:10 +090054 return 0;
55}
56
57} // namespace
58
Garrick Evans8e8e3472020-01-23 14:03:50 +090059class MockProcessRunner : public MinijailedProcessRunner {
60 public:
61 MockProcessRunner() = default;
62 ~MockProcessRunner() = default;
63
Garrick Evans2470caa2020-03-04 14:15:41 +090064 MOCK_METHOD1(WriteSentinelToContainer, int(pid_t pid));
Garrick Evans8e8e3472020-01-23 14:03:50 +090065 MOCK_METHOD3(brctl,
66 int(const std::string& cmd,
67 const std::vector<std::string>& argv,
68 bool log_failures));
69 MOCK_METHOD4(chown,
70 int(const std::string& uid,
71 const std::string& gid,
72 const std::string& file,
73 bool log_failures));
Garrick Evans8e8e3472020-01-23 14:03:50 +090074 MOCK_METHOD4(ip,
75 int(const std::string& obj,
76 const std::string& cmd,
77 const std::vector<std::string>& args,
78 bool log_failures));
79 MOCK_METHOD4(ip6,
80 int(const std::string& obj,
81 const std::string& cmd,
82 const std::vector<std::string>& args,
83 bool log_failures));
Jie Jiangcf5ce9c2020-07-14 17:22:03 +090084 MOCK_METHOD4(iptables,
Garrick Evans8e8e3472020-01-23 14:03:50 +090085 int(const std::string& table,
86 const std::vector<std::string>& argv,
Jie Jiangcf5ce9c2020-07-14 17:22:03 +090087 bool log_failures,
88 std::string* output));
89 MOCK_METHOD4(ip6tables,
Garrick Evans8e8e3472020-01-23 14:03:50 +090090 int(const std::string& table,
91 const std::vector<std::string>& argv,
Jie Jiangcf5ce9c2020-07-14 17:22:03 +090092 bool log_failures,
93 std::string* output));
Garrick Evans8e8e3472020-01-23 14:03:50 +090094 MOCK_METHOD2(modprobe_all,
95 int(const std::vector<std::string>& modules, bool log_failures));
96 MOCK_METHOD3(sysctl_w,
97 int(const std::string& key,
98 const std::string& value,
99 bool log_failures));
Hugo Benichi33860d72020-07-09 16:34:01 +0900100 MOCK_METHOD3(ip_netns_attach,
101 int(const std::string& netns_name,
102 pid_t netns_pid,
103 bool log_failures));
104 MOCK_METHOD2(ip_netns_delete,
105 int(const std::string& netns_name, bool log_failures));
Garrick Evans8e8e3472020-01-23 14:03:50 +0900106};
107
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900108TEST(DatapathTest, AddTAP) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900109 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900110 MockFirewall firewall;
111 Datapath datapath(&runner, &firewall, ioctl_req_cap);
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900112 MacAddress mac = {1, 2, 3, 4, 5, 6};
Qijiang Fane90b8792020-03-09 16:15:41 +0900113 Subnet subnet(Ipv4Addr(100, 115, 92, 4), 30, base::DoNothing());
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900114 auto addr = subnet.AllocateAtOffset(0);
Garrick Evans4f9f5572019-11-26 10:25:16 +0900115 auto ifname = datapath.AddTAP("foo0", &mac, addr.get(), "");
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900116 EXPECT_EQ(ifname, "foo0");
Hugo Benichie8758b52020-04-03 14:49:01 +0900117 std::vector<ioctl_req_t> expected = {
118 TUNSETIFF, TUNSETPERSIST, SIOCSIFADDR, SIOCSIFNETMASK,
119 SIOCSIFHWADDR, SIOCGIFFLAGS, SIOCSIFFLAGS};
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900120 EXPECT_EQ(ioctl_reqs, expected);
121 ioctl_reqs.clear();
122}
123
124TEST(DatapathTest, AddTAPWithOwner) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900125 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900126 MockFirewall firewall;
127 Datapath datapath(&runner, &firewall, ioctl_req_cap);
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900128 MacAddress mac = {1, 2, 3, 4, 5, 6};
Qijiang Fane90b8792020-03-09 16:15:41 +0900129 Subnet subnet(Ipv4Addr(100, 115, 92, 4), 30, base::DoNothing());
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900130 auto addr = subnet.AllocateAtOffset(0);
Garrick Evans4f9f5572019-11-26 10:25:16 +0900131 auto ifname = datapath.AddTAP("foo0", &mac, addr.get(), "root");
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900132 EXPECT_EQ(ifname, "foo0");
Hugo Benichie8758b52020-04-03 14:49:01 +0900133 std::vector<ioctl_req_t> expected = {
134 TUNSETIFF, TUNSETPERSIST, TUNSETOWNER, SIOCSIFADDR,
135 SIOCSIFNETMASK, SIOCSIFHWADDR, SIOCGIFFLAGS, SIOCSIFFLAGS};
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900136 EXPECT_EQ(ioctl_reqs, expected);
137 ioctl_reqs.clear();
138}
139
Garrick Evans621ed262019-11-13 12:28:43 +0900140TEST(DatapathTest, AddTAPNoAddrs) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900141 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900142 MockFirewall firewall;
143 Datapath datapath(&runner, &firewall, ioctl_req_cap);
Garrick Evans4f9f5572019-11-26 10:25:16 +0900144 auto ifname = datapath.AddTAP("foo0", nullptr, nullptr, "");
Garrick Evans621ed262019-11-13 12:28:43 +0900145 EXPECT_EQ(ifname, "foo0");
Hugo Benichie8758b52020-04-03 14:49:01 +0900146 std::vector<ioctl_req_t> expected = {TUNSETIFF, TUNSETPERSIST, SIOCGIFFLAGS,
147 SIOCSIFFLAGS};
Garrick Evans621ed262019-11-13 12:28:43 +0900148 EXPECT_EQ(ioctl_reqs, expected);
149 ioctl_reqs.clear();
150}
151
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900152TEST(DatapathTest, RemoveTAP) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900153 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900154 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900155 EXPECT_CALL(runner, ip(StrEq("tuntap"), StrEq("del"),
156 ElementsAre("foo0", "mode", "tap"), true));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900157 Datapath datapath(&runner, &firewall);
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900158 datapath.RemoveTAP("foo0");
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900159}
Garrick Evansf0ab7132019-06-18 14:50:42 +0900160
Hugo Benichi33860d72020-07-09 16:34:01 +0900161TEST(DatapathTest, NetnsAttachName) {
162 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900163 MockFirewall firewall;
Hugo Benichi33860d72020-07-09 16:34:01 +0900164 EXPECT_CALL(runner, ip_netns_delete(StrEq("netns_foo"), false));
165 EXPECT_CALL(runner, ip_netns_attach(StrEq("netns_foo"), 1234, true));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900166 Datapath datapath(&runner, &firewall);
Hugo Benichi33860d72020-07-09 16:34:01 +0900167 EXPECT_TRUE(datapath.NetnsAttachName("netns_foo", 1234));
168}
169
170TEST(DatapathTest, NetnsDeleteName) {
171 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900172 MockFirewall firewall;
Hugo Benichi33860d72020-07-09 16:34:01 +0900173 EXPECT_CALL(runner, ip_netns_delete(StrEq("netns_foo"), true));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900174 Datapath datapath(&runner, &firewall);
Hugo Benichi33860d72020-07-09 16:34:01 +0900175 EXPECT_TRUE(datapath.NetnsDeleteName("netns_foo"));
176}
177
Garrick Evans8a949dc2019-07-18 16:17:53 +0900178TEST(DatapathTest, AddBridge) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900179 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900180 MockFirewall firewall;
181 Datapath datapath(&runner, &firewall);
Garrick Evans8e8e3472020-01-23 14:03:50 +0900182 EXPECT_CALL(runner, brctl(StrEq("addbr"), ElementsAre("br"), true));
Garrick Evans6f4fa3a2020-02-10 16:15:09 +0900183 EXPECT_CALL(
184 runner,
185 ip(StrEq("addr"), StrEq("add"),
186 ElementsAre("1.1.1.1/30", "brd", "1.1.1.3", "dev", "br"), true));
Garrick Evans7a1a9ee2020-01-28 11:03:57 +0900187 EXPECT_CALL(runner,
188 ip(StrEq("link"), StrEq("set"), ElementsAre("br", "up"), true));
Garrick Evans8e8e3472020-01-23 14:03:50 +0900189 EXPECT_CALL(runner, iptables(StrEq("mangle"),
190 ElementsAre("-A", "PREROUTING", "-i", "br", "-j",
Hugo Benichi6c445322020-08-12 16:46:19 +0900191 "MARK", "--set-mark", "1/1", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900192 true, nullptr));
Garrick Evans7a1a9ee2020-01-28 11:03:57 +0900193 datapath.AddBridge("br", Ipv4Addr(1, 1, 1, 1), 30);
Garrick Evans8a949dc2019-07-18 16:17:53 +0900194}
195
Hugo Benichi76675592020-04-08 14:29:57 +0900196TEST(DatapathTest, ConnectVethPair) {
197 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900198 MockFirewall firewall;
Hugo Benichi76675592020-04-08 14:29:57 +0900199 EXPECT_CALL(runner, ip(StrEq("link"), StrEq("add"),
200 ElementsAre("veth_foo", "type", "veth", "peer", "name",
Hugo Benichi33860d72020-07-09 16:34:01 +0900201 "peer_foo", "netns", "netns_foo"),
Hugo Benichi76675592020-04-08 14:29:57 +0900202 true));
203 EXPECT_CALL(runner, ip(StrEq("addr"), StrEq("add"),
204 ElementsAre("100.115.92.169/30", "brd",
205 "100.115.92.171", "dev", "peer_foo"),
206 true))
207 .WillOnce(Return(0));
208 EXPECT_CALL(runner, ip(StrEq("link"), StrEq("set"),
209 ElementsAre("dev", "peer_foo", "up", "addr",
210 "01:02:03:04:05:06", "multicast", "on"),
211 true))
212 .WillOnce(Return(0));
Hugo Benichi76675592020-04-08 14:29:57 +0900213 EXPECT_CALL(runner, ip(StrEq("link"), StrEq("set"),
214 ElementsAre("veth_foo", "up"), true));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900215 Datapath datapath(&runner, &firewall);
Hugo Benichi33860d72020-07-09 16:34:01 +0900216 EXPECT_TRUE(datapath.ConnectVethPair(kTestPID, "netns_foo", "veth_foo",
217 "peer_foo", {1, 2, 3, 4, 5, 6},
Hugo Benichi76675592020-04-08 14:29:57 +0900218 Ipv4Addr(100, 115, 92, 169), 30, true));
219}
220
Garrick Evans2470caa2020-03-04 14:15:41 +0900221TEST(DatapathTest, AddVirtualInterfacePair) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900222 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900223 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900224 EXPECT_CALL(runner, ip(StrEq("link"), StrEq("add"),
225 ElementsAre("veth_foo", "type", "veth", "peer", "name",
Hugo Benichi33860d72020-07-09 16:34:01 +0900226 "peer_foo", "netns", "netns_foo"),
Garrick Evans8e8e3472020-01-23 14:03:50 +0900227 true));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900228 Datapath datapath(&runner, &firewall);
Hugo Benichi33860d72020-07-09 16:34:01 +0900229 EXPECT_TRUE(
230 datapath.AddVirtualInterfacePair("netns_foo", "veth_foo", "peer_foo"));
Garrick Evans2470caa2020-03-04 14:15:41 +0900231}
232
233TEST(DatapathTest, ToggleInterface) {
234 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900235 MockFirewall firewall;
Garrick Evans2470caa2020-03-04 14:15:41 +0900236 EXPECT_CALL(runner,
237 ip(StrEq("link"), StrEq("set"), ElementsAre("foo", "up"), true));
Garrick Evans7a1a9ee2020-01-28 11:03:57 +0900238 EXPECT_CALL(runner, ip(StrEq("link"), StrEq("set"),
Garrick Evans2470caa2020-03-04 14:15:41 +0900239 ElementsAre("bar", "down"), true));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900240 Datapath datapath(&runner, &firewall);
Garrick Evans2470caa2020-03-04 14:15:41 +0900241 EXPECT_TRUE(datapath.ToggleInterface("foo", true));
242 EXPECT_TRUE(datapath.ToggleInterface("bar", false));
243}
244
245TEST(DatapathTest, ConfigureInterface) {
246 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900247 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900248 EXPECT_CALL(
249 runner,
Garrick Evans2470caa2020-03-04 14:15:41 +0900250 ip(StrEq("addr"), StrEq("add"),
251 ElementsAre("1.1.1.1/30", "brd", "1.1.1.3", "dev", "foo"), true))
252 .WillOnce(Return(0));
253 EXPECT_CALL(runner, ip(StrEq("link"), StrEq("set"),
254 ElementsAre("dev", "foo", "up", "addr",
255 "02:02:02:02:02:02", "multicast", "on"),
256 true))
257 .WillOnce(Return(0));
258
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900259 Datapath datapath(&runner, &firewall);
Garrick Evans2470caa2020-03-04 14:15:41 +0900260 MacAddress mac_addr = {2, 2, 2, 2, 2, 2};
261 EXPECT_TRUE(datapath.ConfigureInterface("foo", mac_addr, Ipv4Addr(1, 1, 1, 1),
262 30, true, true));
Garrick Evans54861622019-07-19 09:05:09 +0900263}
264
265TEST(DatapathTest, RemoveInterface) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900266 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900267 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900268 EXPECT_CALL(runner,
269 ip(StrEq("link"), StrEq("delete"), ElementsAre("foo"), false));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900270 Datapath datapath(&runner, &firewall);
Garrick Evans54861622019-07-19 09:05:09 +0900271 datapath.RemoveInterface("foo");
Garrick Evans54861622019-07-19 09:05:09 +0900272}
273
Garrick Evans8a949dc2019-07-18 16:17:53 +0900274TEST(DatapathTest, RemoveBridge) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900275 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900276 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900277 EXPECT_CALL(runner, iptables(StrEq("mangle"),
278 ElementsAre("-D", "PREROUTING", "-i", "br", "-j",
Hugo Benichi6c445322020-08-12 16:46:19 +0900279 "MARK", "--set-mark", "1/1", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900280 true, nullptr));
Garrick Evans7a1a9ee2020-01-28 11:03:57 +0900281 EXPECT_CALL(runner,
282 ip(StrEq("link"), StrEq("set"), ElementsAre("br", "down"), true));
Garrick Evans8e8e3472020-01-23 14:03:50 +0900283 EXPECT_CALL(runner, brctl(StrEq("delbr"), ElementsAre("br"), true));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900284 Datapath datapath(&runner, &firewall);
Garrick Evans8a949dc2019-07-18 16:17:53 +0900285 datapath.RemoveBridge("br");
Garrick Evans8a949dc2019-07-18 16:17:53 +0900286}
287
Garrick Evansf0ab7132019-06-18 14:50:42 +0900288TEST(DatapathTest, AddInboundIPv4DNAT) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900289 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900290 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900291 EXPECT_CALL(runner, iptables(StrEq("nat"),
292 ElementsAre("-A", "PREROUTING", "-i", "eth0",
293 "-m", "socket", "--nowildcard", "-j",
294 "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900295 true, nullptr));
Garrick Evans8e8e3472020-01-23 14:03:50 +0900296 EXPECT_CALL(runner, iptables(StrEq("nat"),
297 ElementsAre("-A", "PREROUTING", "-i", "eth0",
298 "-p", "tcp", "-j", "DNAT",
299 "--to-destination", "1.2.3.4", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900300 true, nullptr));
Garrick Evans8e8e3472020-01-23 14:03:50 +0900301 EXPECT_CALL(runner, iptables(StrEq("nat"),
302 ElementsAre("-A", "PREROUTING", "-i", "eth0",
303 "-p", "udp", "-j", "DNAT",
304 "--to-destination", "1.2.3.4", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900305 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900306 Datapath datapath(&runner, &firewall);
Garrick Evansf0ab7132019-06-18 14:50:42 +0900307 datapath.AddInboundIPv4DNAT("eth0", "1.2.3.4");
Garrick Evansf0ab7132019-06-18 14:50:42 +0900308}
309
310TEST(DatapathTest, RemoveInboundIPv4DNAT) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900311 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900312 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900313 EXPECT_CALL(runner, iptables(StrEq("nat"),
314 ElementsAre("-D", "PREROUTING", "-i", "eth0",
315 "-m", "socket", "--nowildcard", "-j",
316 "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900317 true, nullptr));
Garrick Evans8e8e3472020-01-23 14:03:50 +0900318 EXPECT_CALL(runner, iptables(StrEq("nat"),
319 ElementsAre("-D", "PREROUTING", "-i", "eth0",
320 "-p", "tcp", "-j", "DNAT",
321 "--to-destination", "1.2.3.4", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900322 true, nullptr));
Garrick Evans8e8e3472020-01-23 14:03:50 +0900323 EXPECT_CALL(runner, iptables(StrEq("nat"),
324 ElementsAre("-D", "PREROUTING", "-i", "eth0",
325 "-p", "udp", "-j", "DNAT",
326 "--to-destination", "1.2.3.4", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900327 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900328 Datapath datapath(&runner, &firewall);
Garrick Evansf0ab7132019-06-18 14:50:42 +0900329 datapath.RemoveInboundIPv4DNAT("eth0", "1.2.3.4");
Garrick Evansf0ab7132019-06-18 14:50:42 +0900330}
331
332TEST(DatapathTest, AddOutboundIPv4) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900333 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900334 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900335 EXPECT_CALL(runner, iptables(StrEq("filter"),
336 ElementsAre("-A", "FORWARD", "-o", "eth0", "-j",
337 "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900338 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900339 Datapath datapath(&runner, &firewall);
Garrick Evansf0ab7132019-06-18 14:50:42 +0900340 datapath.AddOutboundIPv4("eth0");
Garrick Evansf0ab7132019-06-18 14:50:42 +0900341}
342
343TEST(DatapathTest, RemoveInboundIPv4) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900344 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900345 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900346 EXPECT_CALL(runner, iptables(StrEq("filter"),
347 ElementsAre("-D", "FORWARD", "-o", "eth0", "-j",
348 "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900349 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900350 Datapath datapath(&runner, &firewall);
Garrick Evansf0ab7132019-06-18 14:50:42 +0900351 datapath.RemoveOutboundIPv4("eth0");
Garrick Evansf0ab7132019-06-18 14:50:42 +0900352}
353
Garrick Evans664a82f2019-12-17 12:18:05 +0900354TEST(DatapathTest, MaskInterfaceFlags) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900355 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900356 MockFirewall firewall;
357 Datapath datapath(&runner, &firewall, ioctl_req_cap);
Garrick Evans664a82f2019-12-17 12:18:05 +0900358 bool result = datapath.MaskInterfaceFlags("foo0", IFF_DEBUG);
Taoyu Li90c13912019-11-26 17:56:54 +0900359 EXPECT_TRUE(result);
Hugo Benichie8758b52020-04-03 14:49:01 +0900360 std::vector<ioctl_req_t> expected = {SIOCGIFFLAGS, SIOCSIFFLAGS};
Taoyu Li90c13912019-11-26 17:56:54 +0900361 EXPECT_EQ(ioctl_reqs, expected);
362 ioctl_reqs.clear();
363}
364
365TEST(DatapathTest, AddIPv6Forwarding) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900366 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900367 MockFirewall firewall;
Taoyu Lica49c832019-12-06 17:56:43 +0900368 // Return 1 on iptables -C to simulate rule not existing case
Garrick Evans8e8e3472020-01-23 14:03:50 +0900369 EXPECT_CALL(runner, ip6tables(StrEq("filter"),
370 ElementsAre("-C", "FORWARD", "-i", "eth0", "-o",
371 "arc_eth0", "-j", "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900372 false, nullptr))
Garrick Evans8e8e3472020-01-23 14:03:50 +0900373 .WillOnce(Return(1));
374 EXPECT_CALL(runner, ip6tables(StrEq("filter"),
375 ElementsAre("-A", "FORWARD", "-i", "eth0", "-o",
376 "arc_eth0", "-j", "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900377 true, nullptr));
Garrick Evans8e8e3472020-01-23 14:03:50 +0900378 EXPECT_CALL(runner, ip6tables(StrEq("filter"),
379 ElementsAre("-C", "FORWARD", "-i", "arc_eth0",
380 "-o", "eth0", "-j", "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900381 false, nullptr))
Garrick Evans8e8e3472020-01-23 14:03:50 +0900382 .WillOnce(Return(1));
383 EXPECT_CALL(runner, ip6tables(StrEq("filter"),
384 ElementsAre("-A", "FORWARD", "-i", "arc_eth0",
385 "-o", "eth0", "-j", "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900386 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900387 Datapath datapath(&runner, &firewall);
Taoyu Li90c13912019-11-26 17:56:54 +0900388 datapath.AddIPv6Forwarding("eth0", "arc_eth0");
Taoyu Li90c13912019-11-26 17:56:54 +0900389}
390
Taoyu Lica49c832019-12-06 17:56:43 +0900391TEST(DatapathTest, AddIPv6ForwardingRuleExists) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900392 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900393 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900394 EXPECT_CALL(runner, ip6tables(StrEq("filter"),
395 ElementsAre("-C", "FORWARD", "-i", "eth0", "-o",
396 "arc_eth0", "-j", "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900397 false, nullptr));
Garrick Evans8e8e3472020-01-23 14:03:50 +0900398 EXPECT_CALL(runner, ip6tables(StrEq("filter"),
399 ElementsAre("-C", "FORWARD", "-i", "arc_eth0",
400 "-o", "eth0", "-j", "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900401 false, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900402 Datapath datapath(&runner, &firewall);
Taoyu Lica49c832019-12-06 17:56:43 +0900403 datapath.AddIPv6Forwarding("eth0", "arc_eth0");
Taoyu Lica49c832019-12-06 17:56:43 +0900404}
405
Taoyu Li90c13912019-11-26 17:56:54 +0900406TEST(DatapathTest, RemoveIPv6Forwarding) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900407 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900408 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900409 EXPECT_CALL(runner, ip6tables(StrEq("filter"),
410 ElementsAre("-D", "FORWARD", "-i", "eth0", "-o",
411 "arc_eth0", "-j", "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900412 true, nullptr));
Garrick Evans8e8e3472020-01-23 14:03:50 +0900413 EXPECT_CALL(runner, ip6tables(StrEq("filter"),
414 ElementsAre("-D", "FORWARD", "-i", "arc_eth0",
415 "-o", "eth0", "-j", "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900416 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900417 Datapath datapath(&runner, &firewall);
Taoyu Li90c13912019-11-26 17:56:54 +0900418 datapath.RemoveIPv6Forwarding("eth0", "arc_eth0");
Taoyu Li90c13912019-11-26 17:56:54 +0900419}
420
Taoyu Lieb6cc8f2019-12-09 15:53:04 +0900421TEST(DatapathTest, AddIPv6HostRoute) {
Garrick Evans8e8e3472020-01-23 14:03:50 +0900422 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900423 MockFirewall firewall;
Garrick Evans8e8e3472020-01-23 14:03:50 +0900424 EXPECT_CALL(runner,
425 ip6(StrEq("route"), StrEq("replace"),
426 ElementsAre("2001:da8:e00::1234/128", "dev", "eth0"), true));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900427 Datapath datapath(&runner, &firewall);
Taoyu Lieb6cc8f2019-12-09 15:53:04 +0900428 datapath.AddIPv6HostRoute("eth0", "2001:da8:e00::1234", 128);
Taoyu Lieb6cc8f2019-12-09 15:53:04 +0900429}
430
Hugo Benichie8758b52020-04-03 14:49:01 +0900431TEST(DatapathTest, AddIPv4Route) {
432 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900433 MockFirewall firewall;
434 Datapath datapath(&runner, &firewall, (ioctl_t)ioctl_rtentry_cap);
Hugo Benichie8758b52020-04-03 14:49:01 +0900435
436 datapath.AddIPv4Route(Ipv4Addr(192, 168, 1, 1), Ipv4Addr(100, 115, 93, 0),
437 Ipv4Addr(255, 255, 255, 0));
438 datapath.DeleteIPv4Route(Ipv4Addr(192, 168, 1, 1), Ipv4Addr(100, 115, 93, 0),
439 Ipv4Addr(255, 255, 255, 0));
440 datapath.AddIPv4Route("eth0", Ipv4Addr(100, 115, 92, 8),
441 Ipv4Addr(255, 255, 255, 252));
442 datapath.DeleteIPv4Route("eth0", Ipv4Addr(100, 115, 92, 8),
443 Ipv4Addr(255, 255, 255, 252));
444
445 std::vector<ioctl_req_t> expected_reqs = {SIOCADDRT, SIOCDELRT, SIOCADDRT,
446 SIOCDELRT};
447 EXPECT_EQ(expected_reqs, ioctl_reqs);
448 ioctl_reqs.clear();
449
450 std::string route1 =
451 "{rt_dst: {family: AF_INET, port: 0, addr: 100.115.93.0}, rt_genmask: "
452 "{family: AF_INET, port: 0, addr: 255.255.255.0}, rt_gateway: {family: "
453 "AF_INET, port: 0, addr: 192.168.1.1}, rt_dev: null, rt_flags: RTF_UP | "
454 "RTF_GATEWAY}";
455 std::string route2 =
456 "{rt_dst: {family: AF_INET, port: 0, addr: 100.115.92.8}, rt_genmask: "
457 "{family: AF_INET, port: 0, addr: 255.255.255.252}, rt_gateway: {unset}, "
458 "rt_dev: eth0, rt_flags: RTF_UP | RTF_GATEWAY}";
459 std::vector<std::string> captured_routes;
460 for (const auto& route : ioctl_rtentry_args) {
461 std::ostringstream stream;
462 stream << route.second;
463 captured_routes.emplace_back(stream.str());
464 }
465 ioctl_rtentry_args.clear();
466 EXPECT_EQ(route1, captured_routes[0]);
467 EXPECT_EQ(route1, captured_routes[1]);
468 EXPECT_EQ(route2, captured_routes[2]);
469 EXPECT_EQ(route2, captured_routes[3]);
470}
471
Garrick Evansd291af62020-05-25 10:39:06 +0900472TEST(DatapathTest, AddSNATMarkRules) {
473 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900474 MockFirewall firewall;
Taoyu Li79871c92020-07-02 16:09:39 +0900475 EXPECT_CALL(
476 runner,
477 iptables(StrEq("filter"),
Hugo Benichi6c445322020-08-12 16:46:19 +0900478 ElementsAre("-A", "FORWARD", "-m", "mark", "--mark", "1/1", "-m",
Taoyu Li79871c92020-07-02 16:09:39 +0900479 "state", "--state", "INVALID", "-j", "DROP", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900480 true, nullptr));
Hugo Benichi6c445322020-08-12 16:46:19 +0900481 EXPECT_CALL(runner,
482 iptables(StrEq("filter"),
483 ElementsAre("-A", "FORWARD", "-m", "mark", "--mark",
484 "1/1", "-j", "ACCEPT", "-w"),
485 true, nullptr));
Garrick Evansd291af62020-05-25 10:39:06 +0900486 EXPECT_CALL(runner,
487 iptables(StrEq("nat"),
488 ElementsAre("-A", "POSTROUTING", "-m", "mark", "--mark",
Hugo Benichi6c445322020-08-12 16:46:19 +0900489 "1/1", "-j", "MASQUERADE", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900490 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900491 Datapath datapath(&runner, &firewall);
Garrick Evansd291af62020-05-25 10:39:06 +0900492 datapath.AddSNATMarkRules();
493}
494
495TEST(DatapathTest, RemoveSNATMarkRules) {
496 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900497 MockFirewall firewall;
Taoyu Li79871c92020-07-02 16:09:39 +0900498 EXPECT_CALL(
499 runner,
500 iptables(StrEq("filter"),
Hugo Benichi6c445322020-08-12 16:46:19 +0900501 ElementsAre("-D", "FORWARD", "-m", "mark", "--mark", "1/1", "-m",
Taoyu Li79871c92020-07-02 16:09:39 +0900502 "state", "--state", "INVALID", "-j", "DROP", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900503 true, nullptr));
Hugo Benichi6c445322020-08-12 16:46:19 +0900504 EXPECT_CALL(runner,
505 iptables(StrEq("filter"),
506 ElementsAre("-D", "FORWARD", "-m", "mark", "--mark",
507 "1/1", "-j", "ACCEPT", "-w"),
508 true, nullptr));
Garrick Evansd291af62020-05-25 10:39:06 +0900509 EXPECT_CALL(runner,
510 iptables(StrEq("nat"),
511 ElementsAre("-D", "POSTROUTING", "-m", "mark", "--mark",
Hugo Benichi6c445322020-08-12 16:46:19 +0900512 "1/1", "-j", "MASQUERADE", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900513 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900514 Datapath datapath(&runner, &firewall);
Garrick Evansd291af62020-05-25 10:39:06 +0900515 datapath.RemoveSNATMarkRules();
516}
517
518TEST(DatapathTest, AddForwardEstablishedRule) {
519 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900520 MockFirewall firewall;
Garrick Evansd291af62020-05-25 10:39:06 +0900521 EXPECT_CALL(runner,
522 iptables(StrEq("filter"),
523 ElementsAre("-A", "FORWARD", "-m", "state", "--state",
524 "ESTABLISHED,RELATED", "-j", "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900525 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900526 Datapath datapath(&runner, &firewall);
Garrick Evansd291af62020-05-25 10:39:06 +0900527 datapath.AddForwardEstablishedRule();
528}
529
530TEST(DatapathTest, RemoveForwardEstablishedRule) {
531 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900532 MockFirewall firewall;
Garrick Evansd291af62020-05-25 10:39:06 +0900533 EXPECT_CALL(runner,
534 iptables(StrEq("filter"),
535 ElementsAre("-D", "FORWARD", "-m", "state", "--state",
536 "ESTABLISHED,RELATED", "-j", "ACCEPT", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900537 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900538 Datapath datapath(&runner, &firewall);
Garrick Evansd291af62020-05-25 10:39:06 +0900539 datapath.RemoveForwardEstablishedRule();
540}
541
Garrick Evansff6e37f2020-05-25 10:54:47 +0900542TEST(DatapathTest, AddInterfaceSNAT) {
543 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900544 MockFirewall firewall;
Garrick Evansff6e37f2020-05-25 10:54:47 +0900545 EXPECT_CALL(runner, iptables(StrEq("nat"),
546 ElementsAre("-A", "POSTROUTING", "-o", "wwan+",
547 "-j", "MASQUERADE", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900548 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900549 Datapath datapath(&runner, &firewall);
Garrick Evansff6e37f2020-05-25 10:54:47 +0900550 datapath.AddInterfaceSNAT("wwan+");
551}
552
553TEST(DatapathTest, RemoveInterfaceSNAT) {
554 MockProcessRunner runner;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900555 MockFirewall firewall;
Garrick Evansff6e37f2020-05-25 10:54:47 +0900556 EXPECT_CALL(runner, iptables(StrEq("nat"),
557 ElementsAre("-D", "POSTROUTING", "-o", "wwan+",
558 "-j", "MASQUERADE", "-w"),
Jie Jiangcf5ce9c2020-07-14 17:22:03 +0900559 true, nullptr));
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900560 Datapath datapath(&runner, &firewall);
Garrick Evansff6e37f2020-05-25 10:54:47 +0900561 datapath.RemoveInterfaceSNAT("wwan+");
562}
563
Garrick Evans2f581a02020-05-11 10:43:35 +0900564TEST(DatapathTest, ArcVethHostName) {
565 EXPECT_EQ("vetheth0", ArcVethHostName("eth0"));
566 EXPECT_EQ("vethrmnet0", ArcVethHostName("rmnet0"));
567 EXPECT_EQ("vethrmnet_data0", ArcVethHostName("rmnet_data0"));
568 EXPECT_EQ("vethifnamsiz_i0", ArcVethHostName("ifnamsiz_ifnam0"));
569 auto ifname = ArcVethHostName("exceeds_ifnamesiz_checkanyway");
570 EXPECT_EQ("vethexceeds_ify", ifname);
571 EXPECT_LT(ifname.length(), IFNAMSIZ);
572}
573
Garrick Evans8a067562020-05-11 12:47:30 +0900574TEST(DatapathTest, ArcBridgeName) {
575 EXPECT_EQ("arc_eth0", ArcBridgeName("eth0"));
576 EXPECT_EQ("arc_rmnet0", ArcBridgeName("rmnet0"));
577 EXPECT_EQ("arc_rmnet_data0", ArcBridgeName("rmnet_data0"));
578 EXPECT_EQ("arc_ifnamsiz_i0", ArcBridgeName("ifnamsiz_ifnam0"));
579 auto ifname = ArcBridgeName("exceeds_ifnamesiz_checkanyway");
580 EXPECT_EQ("arc_exceeds_ify", ifname);
581 EXPECT_LT(ifname.length(), IFNAMSIZ);
582}
583
Garrick Evans3388a032020-03-24 11:25:55 +0900584} // namespace patchpanel