|
|
40251c |
From a698ca94c40b6edf058995f9f2b1fc197a16efe4 Mon Sep 17 00:00:00 2001
|
|
|
40251c |
From: Eric Garver <eric@garver.life>
|
|
|
40251c |
Date: Thu, 16 Jan 2020 09:02:28 -0500
|
|
|
40251c |
Subject: [PATCH 27/37] test: enhance test for rhbz1729097
|
|
|
40251c |
|
|
|
40251c |
(cherry picked from commit c2b8059559c210e586b03b44eaf189370b976770)
|
|
|
40251c |
(cherry picked from commit 47368842f5519b43cb02cb4f2cca59b9049e5268)
|
|
|
40251c |
---
|
|
|
40251c |
src/tests/regression/rhbz1715977.at | 107 +++++++++++++++++++++++++++-
|
|
|
40251c |
1 file changed, 105 insertions(+), 2 deletions(-)
|
|
|
40251c |
|
|
|
40251c |
diff --git a/src/tests/regression/rhbz1715977.at b/src/tests/regression/rhbz1715977.at
|
|
|
40251c |
index ce6dd075c2b5..5de9b5679023 100644
|
|
|
40251c |
--- a/src/tests/regression/rhbz1715977.at
|
|
|
40251c |
+++ b/src/tests/regression/rhbz1715977.at
|
|
|
40251c |
@@ -1,9 +1,112 @@
|
|
|
40251c |
-FWD_START_TEST([rich rule destination with service destination])
|
|
|
40251c |
-AT_KEYWORDS(rich service rhbz1715977)
|
|
|
40251c |
+FWD_START_TEST([rich rule source/destination with service destination])
|
|
|
40251c |
+AT_KEYWORDS(rich service rhbz1715977 rhbz1729097 rhbz1791783)
|
|
|
40251c |
|
|
|
40251c |
FWD_CHECK([-q --permanent --zone=internal --add-interface=foobar0])
|
|
|
40251c |
FWD_CHECK([-q --permanent --zone=internal --add-rich-rule='rule family=ipv4 destination address="192.168.122.235/32" service name="ssh" accept'])
|
|
|
40251c |
FWD_RELOAD
|
|
|
40251c |
+NFT_LIST_RULES([inet], [filter_IN_internal_allow], 0, [dnl
|
|
|
40251c |
+ table inet firewalld {
|
|
|
40251c |
+ chain filter_IN_internal_allow {
|
|
|
40251c |
+ tcp dport 22 ct state new,untracked accept
|
|
|
40251c |
+ ip daddr 224.0.0.251 udp dport 5353 ct state new,untracked accept
|
|
|
40251c |
+ ip6 daddr ff02::fb udp dport 5353 ct state new,untracked accept
|
|
|
40251c |
+ udp dport 137 ct helper set "helper-netbios-ns-udp"
|
|
|
40251c |
+ udp dport 137 ct state new,untracked accept
|
|
|
40251c |
+ udp dport 138 ct state new,untracked accept
|
|
|
40251c |
+ ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
|
|
|
40251c |
+ tcp dport 9090 ct state new,untracked accept
|
|
|
40251c |
+ ip daddr 192.168.122.235 tcp dport 22 ct state new,untracked accept
|
|
|
40251c |
+ }
|
|
|
40251c |
+ }
|
|
|
40251c |
+])
|
|
|
40251c |
+IPTABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
|
|
|
40251c |
+ ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp -- 0.0.0.0/0 224.0.0.251 udp dpt:5353 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:137 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:138 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT tcp -- 0.0.0.0/0 192.168.122.235 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
40251c |
+])
|
|
|
40251c |
+IP6TABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
|
|
|
40251c |
+ ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 ff02::fb udp dpt:5353 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 ::/0 udp dpt:137 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 ::/0 udp dpt:138 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
40251c |
+])
|
|
|
40251c |
+
|
|
|
40251c |
+FWD_CHECK([-q --zone=internal --add-rich-rule='rule family=ipv4 destination address="192.168.111.222/32" source address="10.10.10.0/24" service name="ssh" accept'])
|
|
|
40251c |
+NFT_LIST_RULES([inet], [filter_IN_internal_allow], 0, [dnl
|
|
|
40251c |
+ table inet firewalld {
|
|
|
40251c |
+ chain filter_IN_internal_allow {
|
|
|
40251c |
+ tcp dport 22 ct state new,untracked accept
|
|
|
40251c |
+ ip daddr 224.0.0.251 udp dport 5353 ct state new,untracked accept
|
|
|
40251c |
+ ip6 daddr ff02::fb udp dport 5353 ct state new,untracked accept
|
|
|
40251c |
+ udp dport 137 ct helper set "helper-netbios-ns-udp"
|
|
|
40251c |
+ udp dport 137 ct state new,untracked accept
|
|
|
40251c |
+ udp dport 138 ct state new,untracked accept
|
|
|
40251c |
+ ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
|
|
|
40251c |
+ tcp dport 9090 ct state new,untracked accept
|
|
|
40251c |
+ ip daddr 192.168.122.235 tcp dport 22 ct state new,untracked accept
|
|
|
40251c |
+ ip daddr 192.168.111.222 ip saddr 10.10.10.0/24 tcp dport 22 ct state new,untracked accept
|
|
|
40251c |
+ }
|
|
|
40251c |
+ }
|
|
|
40251c |
+])
|
|
|
40251c |
+IPTABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
|
|
|
40251c |
+ ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp -- 0.0.0.0/0 224.0.0.251 udp dpt:5353 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:137 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:138 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT tcp -- 0.0.0.0/0 192.168.122.235 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT tcp -- 10.10.10.0/24 192.168.111.222 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
40251c |
+])
|
|
|
40251c |
+IP6TABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
|
|
|
40251c |
+ ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 ff02::fb udp dpt:5353 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 ::/0 udp dpt:137 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 ::/0 udp dpt:138 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
40251c |
+])
|
|
|
40251c |
+
|
|
|
40251c |
+FWD_CHECK([-q --zone=internal --add-rich-rule='rule family=ipv4 service name="ssdp" accept'])
|
|
|
40251c |
+NFT_LIST_RULES([inet], [filter_IN_internal_allow], 0, [dnl
|
|
|
40251c |
+ table inet firewalld {
|
|
|
40251c |
+ chain filter_IN_internal_allow {
|
|
|
40251c |
+ tcp dport 22 ct state new,untracked accept
|
|
|
40251c |
+ ip daddr 224.0.0.251 udp dport 5353 ct state new,untracked accept
|
|
|
40251c |
+ ip6 daddr ff02::fb udp dport 5353 ct state new,untracked accept
|
|
|
40251c |
+ udp dport 137 ct helper set "helper-netbios-ns-udp"
|
|
|
40251c |
+ udp dport 137 ct state new,untracked accept
|
|
|
40251c |
+ udp dport 138 ct state new,untracked accept
|
|
|
40251c |
+ ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
|
|
|
40251c |
+ tcp dport 9090 ct state new,untracked accept
|
|
|
40251c |
+ ip daddr 192.168.122.235 tcp dport 22 ct state new,untracked accept
|
|
|
40251c |
+ ip daddr 192.168.111.222 ip saddr 10.10.10.0/24 tcp dport 22 ct state new,untracked accept
|
|
|
40251c |
+ ip daddr 239.255.255.250 udp dport 1900 ct state new,untracked accept
|
|
|
40251c |
+ }
|
|
|
40251c |
+ }
|
|
|
40251c |
+])
|
|
|
40251c |
+IPTABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
|
|
|
40251c |
+ ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp -- 0.0.0.0/0 224.0.0.251 udp dpt:5353 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:137 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:138 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT tcp -- 0.0.0.0/0 192.168.122.235 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT tcp -- 10.10.10.0/24 192.168.111.222 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp -- 0.0.0.0/0 239.255.255.250 udp dpt:1900 ctstate NEW,UNTRACKED
|
|
|
40251c |
+])
|
|
|
40251c |
+IP6TABLES_LIST_RULES([filter], [IN_internal_allow], 0, [dnl
|
|
|
40251c |
+ ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 ff02::fb udp dpt:5353 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 ::/0 udp dpt:137 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 ::/0 udp dpt:138 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
|
|
|
40251c |
+ ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
40251c |
+])
|
|
|
40251c |
|
|
|
40251c |
FWD_CHECK([-q --zone=internal --add-rich-rule='rule family=ipv4 destination address="192.168.122.235/32" service name="mdns" accept'], 122, [ignore], [ignore])
|
|
|
40251c |
FWD_CHECK([-q --permanent --zone=internal --add-rich-rule='rule family=ipv4 destination address="192.168.122.235/32" service name="mdns" accept'])
|
|
|
40251c |
--
|
|
|
40251c |
2.23.0
|
|
|
40251c |
|