[PATCH v3 28/36] selftest/net: Add TCP-AO ICMPs accept test
From: Dmitry Safonov <hidden>
Date: 2022-10-27 20:50:08
Also in:
linux-crypto, lkml
Subsystem:
kernel selftest framework, networking [general], the rest · Maintainers:
Shuah Khan, "David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Linus Torvalds
Reverse to icmps-discard test: the server accepts ICMPs, using TCP_AO_CMDF_ACCEPT_ICMP and it is expected to fail under ICMP flood from client. Test that the default pre-TCP-AO behaviour functions when TCP_AO_CMDF_ACCEPT_ICMP is set. Expected output for ipv4 version (in case it receives ICMP_PROT_UNREACH):
# ./icmps-accept_ipv4 1..3 # 3209[lib/setup.c:166] rand seed 1642623870 TAP version 13 # 3209[lib/proc.c:207] Snmp6 Ip6InReceives: 0 => 1 # 3209[lib/proc.c:207] Snmp6 Ip6InNoRoutes: 0 => 1 # 3209[lib/proc.c:207] Snmp6 Ip6InOctets: 0 => 76 # 3209[lib/proc.c:207] Snmp6 Ip6InNoECTPkts: 0 => 1 # 3209[lib/proc.c:207] Tcp InSegs: 3 => 23 # 3209[lib/proc.c:207] Tcp OutSegs: 2 => 22 # 3209[lib/proc.c:207] IcmpMsg InType3: 0 => 4 # 3209[lib/proc.c:207] Icmp InMsgs: 0 => 4 # 3209[lib/proc.c:207] Icmp InDestUnreachs: 0 => 4 # 3209[lib/proc.c:207] Ip InReceives: 3 => 27 # 3209[lib/proc.c:207] Ip InDelivers: 3 => 27 # 3209[lib/proc.c:207] Ip OutRequests: 2 => 22 # 3209[lib/proc.c:207] IpExt InOctets: 288 => 3420 # 3209[lib/proc.c:207] IpExt OutOctets: 124 => 3244 # 3209[lib/proc.c:207] IpExt InNoECTPkts: 3 => 25 # 3209[lib/proc.c:207] TcpExt TCPPureAcks: 1 => 2 # 3209[lib/proc.c:207] TcpExt TCPOrigDataSent: 0 => 20 # 3209[lib/proc.c:207] TcpExt TCPDelivered: 0 => 19 # 3209[lib/proc.c:207] TcpExt TCPAOGood: 3 => 23 ok 1 InDestUnreachs delivered 4 ok 2 server failed with -92: Protocol not available ok 3 TCPAODroppedIcmps counter didn't change: 0 >= 0 # Totals: pass:3 fail:0 xfail:0 xpass:0 skip:0 error:0
Expected output for ipv6 version (in case it receives ADM_PROHIBITED):
# ./icmps-accept_ipv6 1..3 # 3277[lib/setup.c:166] rand seed 1642624035 TAP version 13 # 3277[lib/proc.c:207] Snmp6 Ip6InReceives: 6 => 31 # 3277[lib/proc.c:207] Snmp6 Ip6InDelivers: 4 => 29 # 3277[lib/proc.c:207] Snmp6 Ip6OutRequests: 4 => 24 # 3277[lib/proc.c:207] Snmp6 Ip6InOctets: 592 => 4492 # 3277[lib/proc.c:207] Snmp6 Ip6OutOctets: 332 => 3852 # 3277[lib/proc.c:207] Snmp6 Ip6InNoECTPkts: 6 => 31 # 3277[lib/proc.c:207] Snmp6 Icmp6InMsgs: 1 => 6 # 3277[lib/proc.c:207] Snmp6 Icmp6InDestUnreachs: 0 => 5 # 3277[lib/proc.c:207] Snmp6 Icmp6InType1: 0 => 5 # 3277[lib/proc.c:207] Tcp InSegs: 3 => 23 # 3277[lib/proc.c:207] Tcp OutSegs: 2 => 22 # 3277[lib/proc.c:207] TcpExt TCPPureAcks: 1 => 2 # 3277[lib/proc.c:207] TcpExt TCPOrigDataSent: 0 => 20 # 3277[lib/proc.c:207] TcpExt TCPDelivered: 0 => 19 # 3277[lib/proc.c:207] TcpExt TCPAOGood: 3 => 23 ok 1 Icmp6InDestUnreachs delivered 5 ok 2 server failed with -13: Permission denied ok 3 TCPAODroppedIcmps counter didn't change: 0 >= 0 # Totals: pass:3 fail:0 xfail:0 xpass:0 skip:0 error:0
With some luck the server may fail with ECONNREFUSED (depending on what icmp packet was delivered firstly). For the kernel error handlers see: tab_unreach[] and icmp_err_convert[]. Signed-off-by: Dmitry Safonov <redacted> --- tools/testing/selftests/net/tcp_ao/Makefile | 4 +++- .../testing/selftests/net/tcp_ao/icmps-accept.c | 1 + .../selftests/net/tcp_ao/icmps-discard.c | 17 +++++++++++++++-- 3 files changed, 19 insertions(+), 3 deletions(-) create mode 120000 tools/testing/selftests/net/tcp_ao/icmps-accept.c
diff --git a/tools/testing/selftests/net/tcp_ao/Makefile b/tools/testing/selftests/net/tcp_ao/Makefile
index 9acfd782c20f..a178bde0af08 100644
--- a/tools/testing/selftests/net/tcp_ao/Makefile
+++ b/tools/testing/selftests/net/tcp_ao/Makefile@@ -1,5 +1,5 @@ # SPDX-License-Identifier: GPL-2.0 -TEST_BOTH_AF := connect icmps-discard +TEST_BOTH_AF := connect icmps-discard icmps-accept TEST_IPV4_PROGS := $(TEST_BOTH_AF:%=%_ipv4) TEST_IPV6_PROGS := $(TEST_BOTH_AF:%=%_ipv6)
@@ -43,3 +43,5 @@ $(OUTPUT)/%_ipv4: %.c $(OUTPUT)/%_ipv6: %.c $(LINK.c) -DIPV6_TEST $^ $(LDLIBS) -o $@ +$(OUTPUT)/icmps-accept_ipv4: CFLAGS+= -DTEST_ICMPS_ACCEPT +$(OUTPUT)/icmps-accept_ipv6: CFLAGS+= -DTEST_ICMPS_ACCEPT
diff --git a/tools/testing/selftests/net/tcp_ao/icmps-accept.c b/tools/testing/selftests/net/tcp_ao/icmps-accept.c
new file mode 120000
index 000000000000..0a5bb85eb260
--- /dev/null
+++ b/tools/testing/selftests/net/tcp_ao/icmps-accept.c@@ -0,0 +1 @@ +icmps-discard.c
\ No newline at end of file
diff --git a/tools/testing/selftests/net/tcp_ao/icmps-discard.c b/tools/testing/selftests/net/tcp_ao/icmps-discard.c
index 07eba1308b4e..d90017dfc20d 100644
--- a/tools/testing/selftests/net/tcp_ao/icmps-discard.c
+++ b/tools/testing/selftests/net/tcp_ao/icmps-discard.c@@ -43,8 +43,17 @@ const int sk_ip_level = SOL_IP; const int sk_recverr = IP_RECVERR; #endif -#define test_icmps_fail test_fail -#define test_icmps_ok test_ok +/* + * Server is expected to fail with hard error if + * TCP_AO_CMDF_ACCEPT_ICMP is set + */ +#ifdef TEST_ICMPS_ACCEPT +# define test_icmps_fail test_ok +# define test_icmps_ok test_fail +#else +# define test_icmps_fail test_fail +# define test_icmps_ok test_ok +#endif static void serve_interfered(int sk) {
@@ -98,6 +107,10 @@ static void *server_fn(void *arg) lsk = test_listen_socket(this_ip_addr, test_server_port, 1); +#ifdef TEST_ICMPS_ACCEPT + flags = TCP_AO_CMDF_ACCEPT_ICMP; +#endif + if (test_set_ao(lsk, "password", flags, this_ip_dest, -1, 100, 100)) test_error("setsockopt(TCP_AO)"); synchronize_threads();
--
2.38.1