1 /*
2 * Copyright 2016 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 *
16 * IptablesBaseTest.cpp - utility class for tests that use iptables
17 */
18
19 #include <string>
20 #include <vector>
21
22 #include <gtest/gtest.h>
23
24 #include "IptablesBaseTest.h"
25 #include "NetdConstants.h"
26
IptablesBaseTest()27 IptablesBaseTest::IptablesBaseTest() {
28 sCmds.clear();
29 sRestoreCmds.clear();
30 }
31
fake_android_fork_exec(int argc,char * argv[],int * status,bool,bool)32 int IptablesBaseTest::fake_android_fork_exec(int argc, char* argv[], int *status, bool, bool) {
33 std::string cmd = argv[0];
34 for (int i = 1; i < argc; i++) {
35 cmd += " ";
36 cmd += argv[i];
37 }
38 sCmds.push_back(cmd);
39 *status = 0;
40 return 0;
41 }
42
fakeExecIptables(IptablesTarget target,...)43 int IptablesBaseTest::fakeExecIptables(IptablesTarget target, ...) {
44 std::string cmd = " -w";
45 va_list args;
46 va_start(args, target);
47 const char *arg;
48 do {
49 arg = va_arg(args, const char *);
50 if (arg != nullptr) {
51 cmd += " ";
52 cmd += arg;
53 }
54 } while (arg);
55
56 if (target == V4 || target == V4V6) {
57 sCmds.push_back(IPTABLES_PATH + cmd);
58 }
59 if (target == V6 || target == V4V6) {
60 sCmds.push_back(IP6TABLES_PATH + cmd);
61 }
62
63 return 0;
64 }
65
fakeExecIptablesRestore(IptablesTarget target,const std::string & commands)66 int IptablesBaseTest::fakeExecIptablesRestore(IptablesTarget target, const std::string& commands) {
67 sRestoreCmds.push_back({ target, commands });
68 return 0;
69 }
70
expectIptablesCommand(IptablesTarget target,int pos,const std::string & cmd)71 int IptablesBaseTest::expectIptablesCommand(IptablesTarget target, int pos,
72 const std::string& cmd) {
73
74 if ((unsigned) pos >= sCmds.size()) {
75 ADD_FAILURE() << "Expected too many iptables commands, want command "
76 << pos + 1 << "/" << sCmds.size();
77 return -1;
78 }
79
80 if (target == V4 || target == V4V6) {
81 EXPECT_EQ("/system/bin/iptables -w " + cmd, sCmds[pos++]);
82 }
83 if (target == V6 || target == V4V6) {
84 EXPECT_EQ("/system/bin/ip6tables -w " + cmd, sCmds[pos++]);
85 }
86
87 return target == V4V6 ? 2 : 1;
88 }
89
expectIptablesCommands(const std::vector<std::string> & expectedCmds)90 void IptablesBaseTest::expectIptablesCommands(const std::vector<std::string>& expectedCmds) {
91 ExpectedIptablesCommands expected;
92 for (auto cmd : expectedCmds) {
93 expected.push_back({ V4V6, cmd });
94 }
95 expectIptablesCommands(expected);
96 }
97
expectIptablesCommands(const ExpectedIptablesCommands & expectedCmds)98 void IptablesBaseTest::expectIptablesCommands(const ExpectedIptablesCommands& expectedCmds) {
99 size_t pos = 0;
100 for (size_t i = 0; i < expectedCmds.size(); i ++) {
101 auto target = expectedCmds[i].first;
102 auto cmd = expectedCmds[i].second;
103 int numConsumed = expectIptablesCommand(target, pos, cmd);
104 if (numConsumed < 0) {
105 // Read past the end of the array.
106 break;
107 }
108 pos += numConsumed;
109 }
110
111 EXPECT_EQ(pos, sCmds.size());
112 sCmds.clear();
113 }
114
expectIptablesRestoreCommands(const std::vector<std::string> & expectedCmds)115 void IptablesBaseTest::expectIptablesRestoreCommands(const std::vector<std::string>& expectedCmds) {
116 ExpectedIptablesCommands expected;
117 for (auto cmd : expectedCmds) {
118 expected.push_back({ V4V6, cmd });
119 }
120 expectIptablesRestoreCommands(expected);
121 }
122
expectIptablesRestoreCommands(const ExpectedIptablesCommands & expectedCmds)123 void IptablesBaseTest::expectIptablesRestoreCommands(const ExpectedIptablesCommands& expectedCmds) {
124 EXPECT_EQ(expectedCmds.size(), sRestoreCmds.size());
125 for (size_t i = 0; i < expectedCmds.size(); i++) {
126 EXPECT_EQ(expectedCmds[i], sRestoreCmds[i]) <<
127 "iptables-restore command " << i << " differs";
128 }
129 sRestoreCmds.clear();
130 }
131
132 std::vector<std::string> IptablesBaseTest::sCmds = {};
133 IptablesBaseTest::ExpectedIptablesCommands IptablesBaseTest::sRestoreCmds = {};
134