Home | History | Annotate | Line # | Download | only in libnpftest
npf_rule_test.c revision 1.16
      1   1.1     rmind /*
      2  1.16     rmind  * NPF ruleset tests.
      3   1.1     rmind  *
      4   1.1     rmind  * Public Domain.
      5   1.1     rmind  */
      6   1.1     rmind 
      7  1.13  christos #ifdef _KERNEL
      8   1.1     rmind #include <sys/types.h>
      9  1.13  christos #endif
     10   1.1     rmind 
     11   1.1     rmind #include "npf_impl.h"
     12   1.1     rmind #include "npf_test.h"
     13   1.1     rmind 
     14  1.16     rmind #define	CHECK_TRUE(x)	\
     15  1.16     rmind     if (!(x)) { printf("FAIL: %s line %d\n", __func__, __LINE__); return 0; }
     16  1.16     rmind 
     17   1.1     rmind #define	RESULT_PASS	0
     18   1.1     rmind #define	RESULT_BLOCK	ENETUNREACH
     19   1.1     rmind 
     20   1.1     rmind static const struct test_case {
     21   1.1     rmind 	const char *	src;
     22   1.1     rmind 	const char *	dst;
     23   1.1     rmind 	const char *	ifname;
     24   1.1     rmind 	int		di;
     25   1.1     rmind 	int		stateful_ret;
     26   1.1     rmind 	int		ret;
     27   1.1     rmind } test_cases[] = {
     28   1.1     rmind 
     29   1.1     rmind 	/* Stateful pass. */
     30   1.1     rmind 	{
     31   1.1     rmind 		.src = "10.1.1.1",		.dst = "10.1.1.2",
     32   1.1     rmind 		.ifname = IFNAME_INT,		.di = PFIL_OUT,
     33   1.1     rmind 		.stateful_ret = RESULT_PASS,	.ret = RESULT_PASS
     34   1.1     rmind 	},
     35   1.1     rmind 	{
     36   1.1     rmind 		.src = "10.1.1.2",		.dst = "10.1.1.1",
     37   1.1     rmind 		.ifname = IFNAME_INT,		.di = PFIL_IN,
     38   1.1     rmind 		.stateful_ret = RESULT_PASS,	.ret = RESULT_BLOCK
     39   1.1     rmind 	},
     40   1.1     rmind 
     41   1.1     rmind 	/* Pass forwards stream only. */
     42   1.1     rmind 	{
     43   1.1     rmind 		.src = "10.1.1.1",		.dst = "10.1.1.3",
     44   1.1     rmind 		.ifname = IFNAME_INT,		.di = PFIL_OUT,
     45   1.1     rmind 		.stateful_ret = RESULT_PASS,	.ret = RESULT_PASS
     46   1.1     rmind 	},
     47   1.1     rmind 	{
     48   1.1     rmind 		.src = "10.1.1.3",		.dst = "10.1.1.1",
     49   1.1     rmind 		.ifname = IFNAME_INT,		.di = PFIL_IN,
     50   1.1     rmind 		.stateful_ret = RESULT_BLOCK,	.ret = RESULT_BLOCK
     51   1.1     rmind 	},
     52   1.1     rmind 
     53   1.1     rmind 	/* Block. */
     54   1.1     rmind 	{	.src = "10.1.1.1",		.dst = "10.1.1.4",
     55   1.1     rmind 		.ifname = IFNAME_INT,		.di = PFIL_OUT,
     56   1.1     rmind 		.stateful_ret = RESULT_BLOCK,	.ret = RESULT_BLOCK
     57   1.1     rmind 	},
     58   1.1     rmind 
     59   1.1     rmind };
     60   1.1     rmind 
     61   1.1     rmind static struct mbuf *
     62   1.1     rmind fill_packet(const struct test_case *t)
     63   1.1     rmind {
     64   1.1     rmind 	struct mbuf *m;
     65   1.1     rmind 	struct ip *ip;
     66   1.1     rmind 	struct udphdr *uh;
     67   1.1     rmind 
     68   1.1     rmind 	m = mbuf_construct(IPPROTO_UDP);
     69   1.1     rmind 	uh = mbuf_return_hdrs(m, false, &ip);
     70   1.1     rmind 	ip->ip_src.s_addr = inet_addr(t->src);
     71   1.1     rmind 	ip->ip_dst.s_addr = inet_addr(t->dst);
     72   1.1     rmind 	uh->uh_sport = htons(9000);
     73   1.1     rmind 	uh->uh_dport = htons(9000);
     74   1.1     rmind 	return m;
     75   1.1     rmind }
     76   1.1     rmind 
     77   1.1     rmind static int
     78  1.15     rmind npf_rule_raw_test(struct mbuf *m, ifnet_t *ifp, int di)
     79   1.1     rmind {
     80  1.13  christos 	npf_t *npf = npf_getkernctx();
     81  1.13  christos 	npf_cache_t npc = { .npc_info = 0, .npc_ctx = npf };
     82   1.3     rmind 	nbuf_t nbuf;
     83   1.1     rmind 	npf_rule_t *rl;
     84  1.14  christos 	npf_match_info_t mi;
     85  1.14  christos 	int error;
     86   1.1     rmind 
     87  1.13  christos 	nbuf_init(npf, &nbuf, m, ifp);
     88  1.11     rmind 	npc.npc_nbuf = &nbuf;
     89  1.11     rmind 	npf_cache_all(&npc);
     90   1.3     rmind 
     91   1.4     rmind 	int slock = npf_config_read_enter();
     92  1.13  christos 	rl = npf_ruleset_inspect(&npc, npf_config_ruleset(npf),
     93   1.3     rmind 	    di, NPF_LAYER_3);
     94   1.1     rmind 	if (rl) {
     95  1.14  christos 		error = npf_rule_conclude(rl, &mi);
     96   1.1     rmind 	} else {
     97   1.1     rmind 		error = ENOENT;
     98   1.1     rmind 	}
     99   1.4     rmind 	npf_config_read_exit(slock);
    100   1.1     rmind 	return error;
    101   1.1     rmind }
    102   1.1     rmind 
    103   1.4     rmind static int
    104  1.15     rmind npf_test_case(unsigned i)
    105   1.4     rmind {
    106   1.8     rmind 	const struct test_case *t = &test_cases[i];
    107  1.13  christos 	ifnet_t *ifp = npf_test_getif(t->ifname);
    108   1.4     rmind 	int error;
    109   1.4     rmind 
    110   1.4     rmind 	struct mbuf *m = fill_packet(t);
    111  1.15     rmind 	error = npf_rule_raw_test(m, ifp, t->di);
    112   1.4     rmind 	m_freem(m);
    113   1.4     rmind 	return error;
    114   1.4     rmind }
    115   1.4     rmind 
    116   1.4     rmind static npf_rule_t *
    117   1.4     rmind npf_blockall_rule(void)
    118   1.4     rmind {
    119  1.13  christos 	npf_t *npf = npf_getkernctx();
    120  1.15     rmind 	nvlist_t *rule = nvlist_create(0);
    121   1.4     rmind 
    122  1.15     rmind 	nvlist_add_number(rule, "attr",
    123   1.7     rmind 	    NPF_RULE_IN | NPF_RULE_OUT | NPF_RULE_DYNAMIC);
    124  1.15     rmind 	return npf_rule_alloc(npf, rule);
    125   1.4     rmind }
    126   1.4     rmind 
    127   1.1     rmind bool
    128   1.1     rmind npf_rule_test(bool verbose)
    129   1.1     rmind {
    130  1.13  christos 	npf_t *npf = npf_getkernctx();
    131   1.4     rmind 	npf_ruleset_t *rlset;
    132   1.4     rmind 	npf_rule_t *rl;
    133   1.6     rmind 	uint64_t id;
    134   1.4     rmind 	int error;
    135   1.2     rmind 
    136   1.1     rmind 	for (unsigned i = 0; i < __arraycount(test_cases); i++) {
    137   1.1     rmind 		const struct test_case *t = &test_cases[i];
    138  1.13  christos 		ifnet_t *ifp = npf_test_getif(t->ifname);
    139   1.4     rmind 		int serror;
    140   1.1     rmind 
    141   1.1     rmind 		if (ifp == NULL) {
    142   1.1     rmind 			printf("Interface %s is not configured.\n", t->ifname);
    143   1.1     rmind 			return false;
    144   1.1     rmind 		}
    145   1.1     rmind 
    146   1.2     rmind 		struct mbuf *m = fill_packet(t);
    147  1.15     rmind 		error = npf_rule_raw_test(m, ifp, t->di);
    148  1.13  christos 		serror = npf_packet_handler(npf, &m, ifp, t->di);
    149   1.1     rmind 
    150   1.1     rmind 		if (m) {
    151   1.1     rmind 			m_freem(m);
    152   1.1     rmind 		}
    153   1.1     rmind 
    154   1.1     rmind 		if (verbose) {
    155  1.16     rmind 			printf("rule test %d:\texpected %d (stateful) and %d\n"
    156  1.16     rmind 			    "\t\t-> returned %d and %d\n",
    157   1.1     rmind 			    i + 1, t->stateful_ret, t->ret, serror, error);
    158   1.1     rmind 		}
    159  1.16     rmind 		CHECK_TRUE(serror == t->stateful_ret && error == t->ret);
    160   1.1     rmind 	}
    161   1.4     rmind 
    162   1.8     rmind 	/*
    163   1.8     rmind 	 * Test dynamic NPF rules.
    164   1.8     rmind 	 */
    165   1.8     rmind 
    166  1.15     rmind 	error = npf_test_case(0);
    167  1.16     rmind 	CHECK_TRUE(error == RESULT_PASS);
    168   1.4     rmind 
    169  1.13  christos 	npf_config_enter(npf);
    170  1.13  christos 	rlset = npf_config_ruleset(npf);
    171   1.4     rmind 
    172   1.4     rmind 	rl = npf_blockall_rule();
    173   1.4     rmind 	error = npf_ruleset_add(rlset, "test-rules", rl);
    174  1.16     rmind 	CHECK_TRUE(error == 0);
    175   1.4     rmind 
    176  1.15     rmind 	error = npf_test_case(0);
    177  1.16     rmind 	CHECK_TRUE(error == RESULT_BLOCK);
    178   1.4     rmind 
    179   1.6     rmind 	id = npf_rule_getid(rl);
    180   1.6     rmind 	error = npf_ruleset_remove(rlset, "test-rules", id);
    181  1.16     rmind 	CHECK_TRUE(error == 0);
    182   1.4     rmind 
    183  1.13  christos 	npf_config_exit(npf);
    184   1.4     rmind 
    185  1.15     rmind 	error = npf_test_case(0);
    186  1.16     rmind 	CHECK_TRUE(error == RESULT_PASS);
    187   1.4     rmind 
    188  1.16     rmind 	return true;
    189   1.1     rmind }
    190