From 4edc838408a34a8958671103e7446ddc2dae918b Mon Sep 17 00:00:00 2001 From: Pablo Neira Ayuso Date: Tue, 27 Oct 2020 13:28:23 +0100 Subject: conntrack: default to unspec family for dualstack setups 2bcbae4c14b2 ("conntrack: -f family filter does not work") restored the fallback to IPv4 if -f is not specified, which was the original behaviour. This patch modifies the default to use the unspec family if -f is not specified for the following ct commands: - list - update - delete - get (these two commands below do not support for -f though, but in case this is extended in the future to support it): - flush - event The existing code that parses IPv4 and IPv6 addresses already infers the family, which simplifies the introduction of this update. The expect commands are not updated, they still require many mandatory options for filtering. This patch includes a few test updates too. Based on patch from Mikhail Sennikovsky. Signed-off-by: Pablo Neira Ayuso --- tests/conntrack/testsuite/01delete | 5 +++++ tests/conntrack/testsuite/02filter | 8 ++++++++ 2 files changed, 13 insertions(+) (limited to 'tests/conntrack/testsuite') diff --git a/tests/conntrack/testsuite/01delete b/tests/conntrack/testsuite/01delete index 2755491..64dbb10 100644 --- a/tests/conntrack/testsuite/01delete +++ b/tests/conntrack/testsuite/01delete @@ -30,3 +30,8 @@ -D -s 1.1.1.0/24 -d 2.2.2.0/24 ; OK # try same command again but with CIDR (no matching found) -D -s 1.1.1.0/24 -d 2.2.2.0/24 ; BAD +# try to delete mismatching address family +-D -s ::1 -d 2.2.2.2 ; BAD +# try to delete IPv6 address without specifying IPv6 family +-I -s ::1 -d ::2 -p tcp --sport 20 --dport 10 --state LISTEN -u SEEN_REPLY -t 40 ; OK +-D -s ::1 ; OK diff --git a/tests/conntrack/testsuite/02filter b/tests/conntrack/testsuite/02filter index 91a75eb..d58637f 100644 --- a/tests/conntrack/testsuite/02filter +++ b/tests/conntrack/testsuite/02filter @@ -23,5 +23,13 @@ conntrack -L --mark 0/0xffffffff; OK conntrack -L -s 1.1.1.0 --mask-src 255.255.255.0 -d 2.0.0.0 --mask-dst 255.0.0.0 ; OK conntrack -L -s 1.1.1.4/24 -d 2.3.4.5/8 ; OK conntrack -L -s 1.1.2.0/24 -d 2.3.4.5/8 ; OK +# filter filter mismatching address family +conntrack -L -s 2.2.2.2 -d ::1 ; BAD +# filter by IPv6 address, it implicitly sets IPv6 family +conntrack -L -s ::1 ; OK +# filter by IPv6 address mask, it implicitly sets IPv6 family +conntrack -L -s abcd:abcd:abcd:: --mask-src ffff:ffff:ffff:: ; OK +# filter filter mismatching address family +conntrack -L --mask-src ffff:ffff:ffff:: --mask-dst 255.0.0.0 ; BAD # delete dummy conntrack -D -d 2.2.2.2 ; OK -- cgit v1.2.3