From nobody Wed Dec 17 00:02:43 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of redhat.com designates 209.132.183.28 as permitted sender) client-ip=209.132.183.28; envelope-from=libvir-list-bounces@redhat.com; helo=mx1.redhat.com; Authentication-Results: mx.zohomail.com; spf=pass (zoho.com: domain of redhat.com designates 209.132.183.28 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com Return-Path: Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28]) by mx.zohomail.com with SMTPS id 1519959027640874.8435568106545; Thu, 1 Mar 2018 18:50:27 -0800 (PST) Received: from smtp.corp.redhat.com (int-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 4865E7FDD5; Fri, 2 Mar 2018 02:50:26 +0000 (UTC) Received: from colo-mx.corp.redhat.com (colo-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.20]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 1D0F7620BA; Fri, 2 Mar 2018 02:50:26 +0000 (UTC) Received: from lists01.pubmisc.prod.ext.phx2.redhat.com (lists01.pubmisc.prod.ext.phx2.redhat.com [10.5.19.33]) by colo-mx.corp.redhat.com (Postfix) with ESMTP id D797618033F4; Fri, 2 Mar 2018 02:50:25 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx05.intmail.prod.int.rdu2.redhat.com [10.11.54.5]) by lists01.pubmisc.prod.ext.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id w222oBSG016146 for ; Thu, 1 Mar 2018 21:50:11 -0500 Received: by smtp.corp.redhat.com (Postfix) id BFD359C072; Fri, 2 Mar 2018 02:50:11 +0000 (UTC) Received: from vhost2.laine.org (ovpn-117-175.phx2.redhat.com [10.3.117.175]) by smtp.corp.redhat.com (Postfix) with ESMTP id 587609C07F for ; Fri, 2 Mar 2018 02:50:11 +0000 (UTC) From: Laine Stump To: libvir-list@redhat.com Date: Thu, 1 Mar 2018 21:50:00 -0500 Message-Id: <20180302025000.26919-5-laine@laine.org> In-Reply-To: <20180302025000.26919-1-laine@laine.org> References: <20180302025000.26919-1-laine@laine.org> X-Scanned-By: MIMEDefang 2.79 on 10.11.54.5 X-loop: libvir-list@redhat.com Subject: [libvirt] [tck PATCH v2 4/4] nwfilter tests: remove all hardcoded references to 192.168.122 network X-BeenThere: libvir-list@redhat.com X-Mailman-Version: 2.1.12 Precedence: junk List-Id: Development discussions about the libvirt library & tools List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Sender: libvir-list-bounces@redhat.com Errors-To: libvir-list-bounces@redhat.com X-Scanned-By: MIMEDefang 2.79 on 10.5.11.11 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.27]); Fri, 02 Mar 2018 02:50:26 +0000 (UTC) X-ZohoMail: RSF_0 Z_629925259 SPT_0 Content-Type: text/plain; charset="utf-8" The nwfilter tests have a few places that hardcode 192.168.122 as the address of libvirt's default network. Remove all of these and replace them with addresses that are dynamically determined based on get_network_ip(). (This will have the immediate effect of helping the tests to succeed when libvirt-tck is run in a virtual machine, since virtual machines often have their default network set to a different subnet (in order to avoid conflict with the L0 host's default network)). Signed-off-by: Laine Stump Reviewed-by: Daniel P. Berrang=C3=A9 --- New in V2. Another patch not necessarily related to $subject of the cover letter, but useful to have. scripts/nwfilter/210-no-mac-spoofing.t | 9 ++++++--- scripts/nwfilter/220-no-ip-spoofing.t | 14 ++++++++++---- scripts/nwfilter/230-no-mac-broadcast.t | 8 ++++++-- scripts/nwfilter/240-no-arp-spoofing.t | 19 ++++++++++++++----- 4 files changed, 36 insertions(+), 14 deletions(-) diff --git a/scripts/nwfilter/210-no-mac-spoofing.t b/scripts/nwfilter/210-= no-mac-spoofing.t index 148fbeb..7b74f94 100644 --- a/scripts/nwfilter/210-no-mac-spoofing.t +++ b/scripts/nwfilter/210-no-mac-spoofing.t @@ -42,6 +42,10 @@ END { $tck->cleanup if $tck; } =20 +my $networkip =3D get_network_ip($conn, "default"); +my $networkipaddr =3D $networkip->addr(); +diag "network ip is $networkip, individual ip is $networkipaddr"; + # create first domain and start it my $xml =3D $tck->generic_domain(name =3D> "tck", fullos =3D> 1, netmode =3D> "network", @@ -71,7 +75,7 @@ my $mac =3D get_first_macaddress($dom); diag "mac is $mac"; =20 my $guestip =3D get_ip_from_leases($conn, "default", $mac); -diag "ip is $guestip"; +diag "guest ip is $guestip"; =20 # check ebtables entry my $ebtables =3D (-e '/sbin/ebtables') ? '/sbin/ebtables' : '/usr/sbin/ebt= ables'; @@ -82,7 +86,6 @@ $_ =3D $mac; s/00/0/g;=20 ok($ebtable =3D~ $_, "check ebtables entry"); =20 -my $gateway =3D "192.168.122.1"; my $macfalse =3D "52:54:00:f9:21:22"; my $ping =3D `ping -c 10 $guestip`; diag $ping; @@ -104,7 +107,7 @@ ip link set \\\$DEV down ip link set \\\$DEV address ${macfalse} ip link set \\\$DEV up ip addr show dev \\\$DEV -ping -c 10 ${gateway} 2>&1 +ping -c 10 ${networkipaddr} 2>&1 ip link set \\\$DEV down ip link set \\\$DEV address ${mac} ip link set \\\$DEV up diff --git a/scripts/nwfilter/220-no-ip-spoofing.t b/scripts/nwfilter/220-n= o-ip-spoofing.t index 2f454c5..85c4807 100644 --- a/scripts/nwfilter/220-no-ip-spoofing.t +++ b/scripts/nwfilter/220-no-ip-spoofing.t @@ -45,7 +45,6 @@ END { my $networkip =3D get_network_ip($conn, "default"); my $networkipaddr =3D $networkip->addr(); diag "network ip is $networkip, individual ip is $networkipaddr"; -=20 =20 # create first domain and start it my $xml =3D $tck->generic_domain(name =3D> "tck", fullos =3D> 1, @@ -71,7 +70,14 @@ my $mac =3D get_first_macaddress($dom); diag "mac is $mac"; =20 my $guestip =3D get_ip_from_leases($conn, "default", $mac); -diag "ip is $guestip"; +diag "guest ip is $guestip"; + +my $spoofip =3D $networkip + 1; +if ($spoofip->addr() eq $guestip) { + $spoofip++; +} +my $spoofipaddr =3D $spoofip->addr(); +diag "spoof ip is $spoofipaddr"; =20 # check ebtables entry my $ebtables =3D (-e '/sbin/ebtables') ? '/sbin/ebtables' : '/usr/sbin/ebt= ables'; @@ -96,11 +102,11 @@ ip addr show \\\$DEV kill \\\$(pidof dhclient) ip link set \\\$DEV down ip addr flush dev \\\$DEV -ip addr add 192.168.122.183/\\\$MASK dev \\\$DEV +ip addr add ${spoofipaddr}/\\\$MASK dev \\\$DEV ip link set \\\$DEV up ip addr show \\\$DEV sleep 1 -ping -c 1 192.168.122.1 +ping -c 1 ${networkipaddr} ip link set \\\$DEV down ip addr flush dev \\\$DEV ip addr add ${guestip}/\\\$MASK dev \\\$DEV diff --git a/scripts/nwfilter/230-no-mac-broadcast.t b/scripts/nwfilter/230= -no-mac-broadcast.t index 6f5318a..08695ae 100644 --- a/scripts/nwfilter/230-no-mac-broadcast.t +++ b/scripts/nwfilter/230-no-mac-broadcast.t @@ -41,6 +41,10 @@ END { $tck->cleanup if $tck; } =20 +my $networkip =3D get_network_ip($conn, "default"); +my $networkipbroadcast =3D $networkip->broadcast()->addr(); +diag "network ip is $networkip, broadcast address is $networkipbroadcast"; + # create first domain and start it my $xml =3D $tck->generic_domain(name =3D> "tck", fullos =3D> 1, netmode =3D> "network", @@ -80,7 +84,7 @@ ok($ebtable =3D~ "-d Broadcast -j DROP", "check ebtables = entry for \"-d Broadcast =20 # prepare tcpdump diag "prepare tcpdump"; -system("/usr/sbin/tcpdump -v -i virbr0 -n host 192.168.122.255 and ether h= ost ff:ff:ff:ff:ff:ff 2> /tmp/tcpdump.log &"); +system("/usr/sbin/tcpdump -v -i virbr0 -n host $networkipbroadcast and eth= er host ff:ff:ff:ff:ff:ff 2> /tmp/tcpdump.log &"); =20 # log into guest diag "ssh'ing into $guestip"; @@ -92,7 +96,7 @@ my $ssh =3D Net::OpenSSH->new($guestip, # now generate a mac broadcast paket=20 diag "generate mac broadcast"; my $cmdfile =3D < /test.sh +echo 'ping -c 1 $networkipbroadcast -b' > /test.sh EOF diag $cmdfile; my ($stdout, $stderr) =3D $ssh->capture2($cmdfile); diff --git a/scripts/nwfilter/240-no-arp-spoofing.t b/scripts/nwfilter/240-= no-arp-spoofing.t index a8ab7a5..350b604 100644 --- a/scripts/nwfilter/240-no-arp-spoofing.t +++ b/scripts/nwfilter/240-no-arp-spoofing.t @@ -34,8 +34,6 @@ use Test::Exception; use Net::OpenSSH; use File::Spec::Functions qw(catfile catdir rootdir); =20 -my $spoofid =3D "192.168.122.183"; - my $tck =3D Sys::Virt::TCK->new(); my $conn =3D eval { $tck->setup(); }; BAIL_OUT "failed to setup test harness: $@" if $@; @@ -43,6 +41,10 @@ END { $tck->cleanup if $tck; } =20 +my $networkip =3D get_network_ip($conn, "default"); +my $networkipaddr =3D $networkip->addr(); +diag "network ip is $networkip, individual ip is $networkipaddr"; + # create first domain and start it my $xml =3D $tck->generic_domain(name =3D> "tck", fullos =3D> 1, netmode =3D> "network", @@ -72,7 +74,14 @@ my $mac =3D get_first_macaddress($dom); diag "mac is $mac"; =20 my $guestip =3D get_ip_from_leases($conn, "default", $mac); -diag "ip is $guestip"; +diag "guest ip is $guestip"; + +my $spoofip =3D $networkip + 1; +if ($spoofip->addr() eq $guestip) { + $spoofip++; +} +my $spoofipaddr =3D $spoofip->addr(); +diag "spoof ip is $spoofipaddr"; =20 # check ebtables entry my $ebtables =3D (-e '/sbin/ebtables') ? '/sbin/ebtables' : '/usr/sbin/ebt= ables'; @@ -95,7 +104,7 @@ my $ssh =3D Net::OpenSSH->new($guestip, # now generate a arp spoofing packets=20 diag "generate arpspoof script"; my $cmdfile =3D < /test.sh EOF @@ -127,7 +136,7 @@ system("kill -15 `/sbin/pidof tcpdump`"); diag "tcpdump.log:"; my $tcpdumplog =3D `cat /tmp/tcpdump.log`; diag($tcpdumplog); -ok($tcpdumplog !~ "${spoofid} is-at", "tcpdump expected to capture no arp = reply packets"); +ok($tcpdumplog !~ "${spoofipaddr} is-at", "tcpdump expected to capture no = arp reply packets"); =20 shutdown_vm_gracefully($dom); =20 --=20 2.14.3 -- libvir-list mailing list libvir-list@redhat.com https://www.redhat.com/mailman/listinfo/libvir-list