From 8bbf030baa8169312e81c5a43a5ee2adfeb925d5 Mon Sep 17 00:00:00 2001 From: Pablo Neira Ayuso Date: Tue, 12 Jan 2016 16:38:19 +0100 Subject: tests/py: don't test log statement from protocol match I think this unit tests should be self-contained at some level. The shell/ directory should be used to catch regressions at ruleset level, ie. these kind of combinations. Another motivation is that I want that netdev/ingress gets tested (coming in a follow up patch), and we don't support log there yet, so I would need to skip this test for that case. Signed-off-by: Pablo Neira Ayuso --- tests/py/ip/ip.t | 12 ++++++------ tests/py/ip/ip.t.payload | 18 ++++++------------ tests/py/ip/ip.t.payload.inet | 18 ++++++------------ 3 files changed, 18 insertions(+), 30 deletions(-) (limited to 'tests/py/ip') diff --git a/tests/py/ip/ip.t b/tests/py/ip/ip.t index 152323b9..bb4198a1 100644 --- a/tests/py/ip/ip.t +++ b/tests/py/ip/ip.t @@ -57,7 +57,7 @@ ip frag-off { 33-55};ok - ip frag-off != { 33-55};ok ip ttl 0 drop;ok -ip ttl 233 log;ok +ip ttl 233;ok ip ttl 33-55;ok ip ttl != 45-50;ok ip ttl {43, 53, 45 };ok @@ -68,8 +68,8 @@ ip ttl {43, 53, 45 };ok ip ttl { 33-55};ok - ip ttl != { 33-55};ok -ip protocol tcp log;ok;ip protocol 6 log -ip protocol != tcp log;ok;ip protocol != 6 log +ip protocol tcp;ok;ip protocol 6 +ip protocol != tcp;ok;ip protocol != 6 ip protocol { icmp, esp, ah, comp, udp, udplite, tcp, dccp, sctp} accept;ok;ip protocol { 33, 136, 17, 51, 50, 6, 132, 1, 108} accept - ip protocol != { icmp, esp, ah, comp, udp, udplite, tcp, dccp, sctp} accept;ok @@ -86,8 +86,8 @@ ip checksum { 33-55};ok ip saddr 192.168.2.0/24;ok ip saddr != 192.168.2.0/24;ok ip saddr 192.168.3.1 ip daddr 192.168.3.100;ok -ip saddr != 1.1.1.1 log prefix giuseppe;ok;ip saddr != 1.1.1.1 log prefix "giuseppe" -ip saddr 1.1.1.1 log prefix example group 1;ok;ip saddr 1.1.1.1 log prefix "example" group 1 +ip saddr != 1.1.1.1;ok;ip saddr != 1.1.1.1 +ip saddr 1.1.1.1;ok;ip saddr 1.1.1.1 ip daddr 192.168.0.1-192.168.0.250;ok ip daddr 10.0.0.0-10.255.255.255;ok ip daddr 172.16.0.0-172.31.255.255;ok @@ -105,7 +105,7 @@ ip saddr != 192.168.1.3-192.168.33.55;ok ip daddr 192.168.0.1;ok ip daddr 192.168.0.1 drop;ok -ip daddr 192.168.0.2 log;ok +ip daddr 192.168.0.2;ok ip saddr \& 0xff == 1;ok;ip saddr & 0.0.0.255 == 0.0.0.1 ip saddr \& 0.0.0.255 \< 0.0.0.127;ok;ip saddr & 0.0.0.255 < 0.0.0.127 diff --git a/tests/py/ip/ip.t.payload b/tests/py/ip/ip.t.payload index da2dc218..aa3bfe9d 100644 --- a/tests/py/ip/ip.t.payload +++ b/tests/py/ip/ip.t.payload @@ -119,11 +119,10 @@ ip test-ip4 input [ cmp eq reg 1 0x00000000 ] [ immediate reg 0 drop ] -# ip ttl 233 log +# ip ttl 233 ip test-ip4 input [ payload load 1b @ network header + 8 => reg 1 ] [ cmp eq reg 1 0x000000e9 ] - [ log prefix (null) ] # ip ttl 33-55 ip test-ip4 input @@ -153,17 +152,15 @@ ip test-ip4 input [ payload load 1b @ network header + 8 => reg 1 ] [ lookup reg 1 set set%d ] -# ip protocol tcp log +# ip protocol tcp ip test-ip4 input [ payload load 1b @ network header + 9 => reg 1 ] [ cmp eq reg 1 0x00000006 ] - [ log prefix (null) ] -# ip protocol != tcp log +# ip protocol != tcp ip test-ip4 input [ payload load 1b @ network header + 9 => reg 1 ] [ cmp neq reg 1 0x00000006 ] - [ log prefix (null) ] # ip protocol { icmp, esp, ah, comp, udp, udplite, tcp, dccp, sctp} accept set%d test-ip4 3 @@ -235,17 +232,15 @@ ip test-ip4 input [ payload load 8b @ network header + 12 => reg 1 ] [ cmp eq reg 1 0x0103a8c0 0x6403a8c0 ] -# ip saddr != 1.1.1.1 log prefix giuseppe +# ip saddr != 1.1.1.1 ip test-ip4 input [ payload load 4b @ network header + 12 => reg 1 ] [ cmp neq reg 1 0x01010101 ] - [ log prefix giuseppe ] -# ip saddr 1.1.1.1 log prefix example group 1 +# ip saddr 1.1.1.1 ip test-ip4 input [ payload load 4b @ network header + 12 => reg 1 ] [ cmp eq reg 1 0x01010101 ] - [ log prefix example group 1 snaplen 0 qthreshold 0] # ip daddr 192.168.0.1-192.168.0.250 ip test-ip4 input @@ -329,11 +324,10 @@ ip test-ip4 input [ cmp eq reg 1 0x0100a8c0 ] [ immediate reg 0 drop ] -# ip daddr 192.168.0.2 log +# ip daddr 192.168.0.2 ip test-ip4 input [ payload load 4b @ network header + 16 => reg 1 ] [ cmp eq reg 1 0x0200a8c0 ] - [ log prefix (null) ] # ip saddr \& 0xff == 1 ip test-ip4 input diff --git a/tests/py/ip/ip.t.payload.inet b/tests/py/ip/ip.t.payload.inet index 35f73ff7..4d4d4859 100644 --- a/tests/py/ip/ip.t.payload.inet +++ b/tests/py/ip/ip.t.payload.inet @@ -157,13 +157,12 @@ inet test-inet input [ cmp eq reg 1 0x00000000 ] [ immediate reg 0 drop ] -# ip ttl 233 log +# ip ttl 233 inet test-inet input [ meta load nfproto => reg 1 ] [ cmp eq reg 1 0x00000002 ] [ payload load 1b @ network header + 8 => reg 1 ] [ cmp eq reg 1 0x000000e9 ] - [ log prefix (null) ] # ip ttl 33-55 inet test-inet input @@ -201,21 +200,19 @@ inet test-inet input [ payload load 1b @ network header + 8 => reg 1 ] [ lookup reg 1 set set%d ] -# ip protocol tcp log +# ip protocol tcp inet test-inet input [ meta load nfproto => reg 1 ] [ cmp eq reg 1 0x00000002 ] [ payload load 1b @ network header + 9 => reg 1 ] [ cmp eq reg 1 0x00000006 ] - [ log prefix (null) ] -# ip protocol != tcp log +# ip protocol != tcp inet test-inet input [ meta load nfproto => reg 1 ] [ cmp eq reg 1 0x00000002 ] [ payload load 1b @ network header + 9 => reg 1 ] [ cmp neq reg 1 0x00000006 ] - [ log prefix (null) ] # ip protocol { icmp, esp, ah, comp, udp, udplite, tcp, dccp, sctp} accept set%d test-inet 3 @@ -309,21 +306,19 @@ inet test-inet input [ payload load 8b @ network header + 12 => reg 1 ] [ cmp eq reg 1 0x0103a8c0 0x6403a8c0 ] -# ip saddr != 1.1.1.1 log prefix giuseppe +# ip saddr != 1.1.1.1 inet test-inet input [ meta load nfproto => reg 1 ] [ cmp eq reg 1 0x00000002 ] [ payload load 4b @ network header + 12 => reg 1 ] [ cmp neq reg 1 0x01010101 ] - [ log prefix giuseppe ] -# ip saddr 1.1.1.1 log prefix example group 1 +# ip saddr 1.1.1.1 inet test-inet input [ meta load nfproto => reg 1 ] [ cmp eq reg 1 0x00000002 ] [ payload load 4b @ network header + 12 => reg 1 ] [ cmp eq reg 1 0x01010101 ] - [ log prefix example group 1 snaplen 0 qthreshold 0] # ip daddr 192.168.0.1-192.168.0.250 inet test-inet input @@ -433,13 +428,12 @@ inet test-inet input [ cmp eq reg 1 0x0100a8c0 ] [ immediate reg 0 drop ] -# ip daddr 192.168.0.2 log +# ip daddr 192.168.0.2 inet test-inet input [ meta load nfproto => reg 1 ] [ cmp eq reg 1 0x00000002 ] [ payload load 4b @ network header + 16 => reg 1 ] [ cmp eq reg 1 0x0200a8c0 ] - [ log prefix (null) ] # ip saddr \& 0xff == 1 inet test-inet input -- cgit v1.2.3