outside_test.go 3.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144
  1. package nebula
  2. import (
  3. "net"
  4. "net/netip"
  5. "testing"
  6. "github.com/google/gopacket"
  7. "github.com/google/gopacket/layers"
  8. "github.com/slackhq/nebula/firewall"
  9. "github.com/stretchr/testify/assert"
  10. "golang.org/x/net/ipv4"
  11. )
  12. func Test_newPacket(t *testing.T) {
  13. p := &firewall.Packet{}
  14. // length fails
  15. err := newPacket([]byte{}, true, p)
  16. assert.EqualError(t, err, "packet too short")
  17. err = newPacket([]byte{0x40}, true, p)
  18. assert.EqualError(t, err, "ipv4 packet is less than 20 bytes")
  19. err = newPacket([]byte{0x60}, true, p)
  20. assert.EqualError(t, err, "ipv6 packet is less than 20 bytes")
  21. // length fail with ip options
  22. h := ipv4.Header{
  23. Version: 1,
  24. Len: 100,
  25. Src: net.IPv4(10, 0, 0, 1),
  26. Dst: net.IPv4(10, 0, 0, 2),
  27. Options: []byte{0, 1, 0, 2},
  28. }
  29. b, _ := h.Marshal()
  30. err = newPacket(b, true, p)
  31. assert.EqualError(t, err, "ipv4 packet is less than 28 bytes, ip header len: 24")
  32. // not an ipv4 packet
  33. err = newPacket([]byte{0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0}, true, p)
  34. assert.EqualError(t, err, "packet is an unknown ip version: 0")
  35. // invalid ihl
  36. err = newPacket([]byte{4<<4 | (8 >> 2 & 0x0f), 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0}, true, p)
  37. assert.EqualError(t, err, "ipv4 packet had an invalid header length: 8")
  38. // account for variable ip header length - incoming
  39. h = ipv4.Header{
  40. Version: 1,
  41. Len: 100,
  42. Src: net.IPv4(10, 0, 0, 1),
  43. Dst: net.IPv4(10, 0, 0, 2),
  44. Options: []byte{0, 1, 0, 2},
  45. Protocol: firewall.ProtoTCP,
  46. }
  47. b, _ = h.Marshal()
  48. b = append(b, []byte{0, 3, 0, 4}...)
  49. err = newPacket(b, true, p)
  50. assert.Nil(t, err)
  51. assert.Equal(t, p.Protocol, uint8(firewall.ProtoTCP))
  52. assert.Equal(t, p.LocalAddr, netip.MustParseAddr("10.0.0.2"))
  53. assert.Equal(t, p.RemoteAddr, netip.MustParseAddr("10.0.0.1"))
  54. assert.Equal(t, p.RemotePort, uint16(3))
  55. assert.Equal(t, p.LocalPort, uint16(4))
  56. // account for variable ip header length - outgoing
  57. h = ipv4.Header{
  58. Version: 1,
  59. Protocol: 2,
  60. Len: 100,
  61. Src: net.IPv4(10, 0, 0, 1),
  62. Dst: net.IPv4(10, 0, 0, 2),
  63. Options: []byte{0, 1, 0, 2},
  64. }
  65. b, _ = h.Marshal()
  66. b = append(b, []byte{0, 5, 0, 6}...)
  67. err = newPacket(b, false, p)
  68. assert.Nil(t, err)
  69. assert.Equal(t, p.Protocol, uint8(2))
  70. assert.Equal(t, p.LocalAddr, netip.MustParseAddr("10.0.0.1"))
  71. assert.Equal(t, p.RemoteAddr, netip.MustParseAddr("10.0.0.2"))
  72. assert.Equal(t, p.RemotePort, uint16(6))
  73. assert.Equal(t, p.LocalPort, uint16(5))
  74. }
  75. func Test_newPacket_v6(t *testing.T) {
  76. p := &firewall.Packet{}
  77. ip := layers.IPv6{
  78. Version: 6,
  79. NextHeader: firewall.ProtoUDP,
  80. HopLimit: 128,
  81. SrcIP: net.IPv6linklocalallrouters,
  82. DstIP: net.IPv6linklocalallnodes,
  83. }
  84. udp := layers.UDP{
  85. SrcPort: layers.UDPPort(36123),
  86. DstPort: layers.UDPPort(22),
  87. }
  88. err := udp.SetNetworkLayerForChecksum(&ip)
  89. if err != nil {
  90. panic(err)
  91. }
  92. buffer := gopacket.NewSerializeBuffer()
  93. opt := gopacket.SerializeOptions{
  94. ComputeChecksums: true,
  95. FixLengths: true,
  96. }
  97. err = gopacket.SerializeLayers(buffer, opt, &ip, &udp, gopacket.Payload([]byte{0xde, 0xad, 0xbe, 0xef}))
  98. if err != nil {
  99. panic(err)
  100. }
  101. b := buffer.Bytes()
  102. //test incoming
  103. err = newPacket(b, true, p)
  104. assert.Nil(t, err)
  105. assert.Equal(t, p.Protocol, uint8(firewall.ProtoUDP))
  106. assert.Equal(t, p.RemoteAddr, netip.MustParseAddr("ff02::2"))
  107. assert.Equal(t, p.LocalAddr, netip.MustParseAddr("ff02::1"))
  108. assert.Equal(t, p.RemotePort, uint16(36123))
  109. assert.Equal(t, p.LocalPort, uint16(22))
  110. //test outgoing
  111. err = newPacket(b, false, p)
  112. assert.Nil(t, err)
  113. assert.Equal(t, p.Protocol, uint8(firewall.ProtoUDP))
  114. assert.Equal(t, p.LocalAddr, netip.MustParseAddr("ff02::2"))
  115. assert.Equal(t, p.RemoteAddr, netip.MustParseAddr("ff02::1"))
  116. assert.Equal(t, p.LocalPort, uint16(36123))
  117. assert.Equal(t, p.RemotePort, uint16(22))
  118. }