mirror of
https://github.com/netbirdio/netbird.git
synced 2026-07-20 23:41:28 +02:00
* [client] categorize root/system-mutating tests behind a privileged build tag Tests that need root or mutate host state (nftables/iptables/DNS, TUN/WireGuard interfaces, routes, eBPF, SSH/service install) are now gated behind a //go:build privileged tag. The default `go test ./client/...` runs as a non-root user with no sudo and leaves host networking untouched; mixed files were split so pure-logic tests stay in the default suite. A self-hosting ory/dockertest/v4 harness (client/testutil/privileged) runs the privileged suite inside a --privileged --cap-add=NET_ADMIN container via `make test-privileged`; a DOCKER_CI=true guard skips the spawn when already inside the container. Added `make test-unit` for the host-safe run. * [client] add PRIV_RUN/PRIV_PKGS filters to the privileged test harness The dockertest harness now reads two optional env vars when building the in-container `go test` command: PRIV_RUN adds a -run test-name filter and PRIV_PKGS overrides the package list. Both empty reproduce the full privileged suite, so CI and `make test-privileged` behave as before. Lets a developer run a single privileged test in the container, e.g.: PRIV_RUN=TestNftablesManager PRIV_PKGS=./client/firewall/nftables/... make test-privileged * [client] fix unused-helper lint after the privileged test split Splitting privileged tests into *_privileged_test.go left their shared helpers in the untagged files, so in the default (no-tag) build they had no callers and golangci-lint flagged them as unused. Moved the privileged-only helpers into the privileged files next to their callers (generateDummyHandler; createEngine/startSignal/startManagement/getConnectedPeers/ getPeers + kaep/kasp; (*mockDaemon).setJWTToken). Annotated the shared routing-test fixtures that must stay untagged for cross-platform compilation with //nolint:unused (systemops_bsd expected* vars, ensureIPv6DefaultRoute on bsd/windows, loopbackIfaceWindows), matching the existing linux variant. * [client] fix privileged test CI failures and run the harness on macOS The host-safe unit run dropped sudo but two privileged test groups were never tagged, and the Docker privileged job silently never ran the suite: - Gate the ssh/server PrivilegeDropper command-construction tests behind the privileged tag (they require root to target a different UID); split them into executor_unix_privileged_test.go. - Tag sharedsock raw-socket tests privileged (need CAP_NET_RAW). - Fix the Docker job command: nested single quotes around the build tags closed the sh -c wrapper early, dropping the go list package set and the privileged tag, so go test ran on the empty repo root. Use double quotes. Make the self-hosting harness usable from a dev Mac: - Build it on darwin as well as linux; it only drives Docker. - Resolve the active docker context endpoint into DOCKER_HOST when the default /var/run/docker.sock is absent (Docker Desktop, Colima, OrbStack). - Rename the misspelled containerGoModache constant to containerGoModCache. * Update client/internal/engine_privileged_test.go Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Update client/internal/routemanager/systemops/systemops_linux_test.go Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Update client/internal/routemanager/systemops/systemops_windows_test.go Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Update client/server/server_privileged_test.go Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * [ci] Run privileged-tagged tests on darwin, windows and freebsd The privileged build tag split moved root/system-mutating tests behind //go:build privileged, but only the linux docker job was given the tag. The native darwin (sudo), windows (PsExec64 -s) and freebsd VM runners already have the required privileges, so add the privileged tag there too to keep CI running the same set of tests as before the split. * [ci] Exclude dockertest harness from the darwin privileged run The privileged tag now compiles client/testutil/privileged on darwin, whose TestRunPrivilegedSuiteInDocker spawns a container the macOS runner has no Docker for. Exclude the harness package from the darwin list, matching the linux job, so the privileged tests run in place without a container spawn. --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
133 lines
4.0 KiB
Go
133 lines
4.0 KiB
Go
//go:build !android && !ios
|
|
|
|
package systemops
|
|
|
|
import (
|
|
"net/netip"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
)
|
|
|
|
func TestIsVpnRoute(t *testing.T) {
|
|
tests := []struct {
|
|
name string
|
|
addr string
|
|
vpnRoutes []string
|
|
localRoutes []string
|
|
expectedVpn bool
|
|
expectedPrefix netip.Prefix
|
|
}{
|
|
{
|
|
name: "Match in VPN routes",
|
|
addr: "192.168.1.1",
|
|
vpnRoutes: []string{"192.168.1.0/24"},
|
|
localRoutes: []string{"10.0.0.0/8"},
|
|
expectedVpn: true,
|
|
expectedPrefix: netip.MustParsePrefix("192.168.1.0/24"),
|
|
},
|
|
{
|
|
name: "Match in local routes",
|
|
addr: "10.1.1.1",
|
|
vpnRoutes: []string{"192.168.1.0/24"},
|
|
localRoutes: []string{"10.0.0.0/8"},
|
|
expectedVpn: false,
|
|
expectedPrefix: netip.MustParsePrefix("10.0.0.0/8"),
|
|
},
|
|
{
|
|
name: "No match",
|
|
addr: "172.16.0.1",
|
|
vpnRoutes: []string{"192.168.1.0/24"},
|
|
localRoutes: []string{"10.0.0.0/8"},
|
|
expectedVpn: false,
|
|
expectedPrefix: netip.Prefix{},
|
|
},
|
|
{
|
|
name: "Default route ignored",
|
|
addr: "192.168.1.1",
|
|
vpnRoutes: []string{"0.0.0.0/0", "192.168.1.0/24"},
|
|
localRoutes: []string{"10.0.0.0/8"},
|
|
expectedVpn: true,
|
|
expectedPrefix: netip.MustParsePrefix("192.168.1.0/24"),
|
|
},
|
|
{
|
|
name: "Default route matches but ignored",
|
|
addr: "172.16.1.1",
|
|
vpnRoutes: []string{"0.0.0.0/0", "192.168.1.0/24"},
|
|
localRoutes: []string{"10.0.0.0/8"},
|
|
expectedVpn: false,
|
|
expectedPrefix: netip.Prefix{},
|
|
},
|
|
{
|
|
name: "Longest prefix match local",
|
|
addr: "192.168.1.1",
|
|
vpnRoutes: []string{"192.168.0.0/16"},
|
|
localRoutes: []string{"192.168.1.0/24"},
|
|
expectedVpn: false,
|
|
expectedPrefix: netip.MustParsePrefix("192.168.1.0/24"),
|
|
},
|
|
{
|
|
name: "Longest prefix match local multiple",
|
|
addr: "192.168.0.1",
|
|
vpnRoutes: []string{"192.168.0.0/16", "192.168.0.0/25", "192.168.0.0/27"},
|
|
localRoutes: []string{"192.168.0.0/24", "192.168.0.0/26", "192.168.0.0/28"},
|
|
expectedVpn: false,
|
|
expectedPrefix: netip.MustParsePrefix("192.168.0.0/28"),
|
|
},
|
|
{
|
|
name: "Longest prefix match vpn",
|
|
addr: "192.168.1.1",
|
|
vpnRoutes: []string{"192.168.1.0/24"},
|
|
localRoutes: []string{"192.168.0.0/16"},
|
|
expectedVpn: true,
|
|
expectedPrefix: netip.MustParsePrefix("192.168.1.0/24"),
|
|
},
|
|
{
|
|
name: "Longest prefix match vpn multiple",
|
|
addr: "192.168.0.1",
|
|
vpnRoutes: []string{"192.168.0.0/16", "192.168.0.0/25", "192.168.0.0/27"},
|
|
localRoutes: []string{"192.168.0.0/24", "192.168.0.0/26"},
|
|
expectedVpn: true,
|
|
expectedPrefix: netip.MustParsePrefix("192.168.0.0/27"),
|
|
},
|
|
{
|
|
name: "Duplicate prefix in both",
|
|
addr: "192.168.1.1",
|
|
vpnRoutes: []string{"192.168.1.0/24"},
|
|
localRoutes: []string{"192.168.1.0/24"},
|
|
expectedVpn: false,
|
|
expectedPrefix: netip.MustParsePrefix("192.168.1.0/24"),
|
|
},
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
addr, err := netip.ParseAddr(tt.addr)
|
|
if err != nil {
|
|
t.Fatalf("Failed to parse address %s: %v", tt.addr, err)
|
|
}
|
|
|
|
var vpnRoutes, localRoutes []netip.Prefix
|
|
for _, route := range tt.vpnRoutes {
|
|
prefix, err := netip.ParsePrefix(route)
|
|
if err != nil {
|
|
t.Fatalf("Failed to parse VPN route %s: %v", route, err)
|
|
}
|
|
vpnRoutes = append(vpnRoutes, prefix)
|
|
}
|
|
|
|
for _, route := range tt.localRoutes {
|
|
prefix, err := netip.ParsePrefix(route)
|
|
if err != nil {
|
|
t.Fatalf("Failed to parse local route %s: %v", route, err)
|
|
}
|
|
localRoutes = append(localRoutes, prefix)
|
|
}
|
|
|
|
isVpn, matchedPrefix := isVpnRoute(addr, vpnRoutes, localRoutes)
|
|
assert.Equal(t, tt.expectedVpn, isVpn, "isVpnRoute should return expectedVpn value")
|
|
assert.Equal(t, tt.expectedPrefix, matchedPrefix, "isVpnRoute should return expectedVpn prefix")
|
|
})
|
|
}
|
|
}
|