2016-08-29 13:18:25 +00:00
|
|
|
|
|
|
|
import ./make-test.nix ({ pkgs, ...} : {
|
|
|
|
name = "ferm";
|
|
|
|
meta = with pkgs.stdenv.lib.maintainers; {
|
|
|
|
maintainers = [ mic92 ];
|
|
|
|
};
|
|
|
|
|
|
|
|
nodes =
|
|
|
|
{ client =
|
2018-07-20 20:56:59 +00:00
|
|
|
{ pkgs, ... }:
|
2016-08-29 13:18:25 +00:00
|
|
|
with pkgs.lib;
|
|
|
|
{
|
|
|
|
networking = {
|
2017-12-03 04:14:54 +00:00
|
|
|
interfaces.eth1.ipv6.addresses = mkOverride 0 [ { address = "fd00::2"; prefixLength = 64; } ];
|
|
|
|
interfaces.eth1.ipv4.addresses = mkOverride 0 [ { address = "192.168.1.2"; prefixLength = 24; } ];
|
2016-08-29 13:18:25 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
server =
|
2018-07-20 20:56:59 +00:00
|
|
|
{ pkgs, ... }:
|
2016-08-29 13:18:25 +00:00
|
|
|
with pkgs.lib;
|
|
|
|
{
|
|
|
|
networking = {
|
2017-12-03 04:14:54 +00:00
|
|
|
interfaces.eth1.ipv6.addresses = mkOverride 0 [ { address = "fd00::1"; prefixLength = 64; } ];
|
|
|
|
interfaces.eth1.ipv4.addresses = mkOverride 0 [ { address = "192.168.1.1"; prefixLength = 24; } ];
|
2016-08-29 13:18:25 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
services = {
|
|
|
|
ferm.enable = true;
|
|
|
|
ferm.config = ''
|
|
|
|
domain (ip ip6) table filter chain INPUT {
|
|
|
|
interface lo ACCEPT;
|
|
|
|
proto tcp dport 8080 REJECT reject-with tcp-reset;
|
|
|
|
}
|
|
|
|
'';
|
|
|
|
nginx.enable = true;
|
|
|
|
nginx.httpConfig = ''
|
|
|
|
server {
|
|
|
|
listen 80;
|
|
|
|
listen [::]:80;
|
|
|
|
listen 8080;
|
|
|
|
listen [::]:8080;
|
|
|
|
|
|
|
|
location /status { stub_status on; }
|
|
|
|
}
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
testScript =
|
|
|
|
''
|
|
|
|
startAll;
|
|
|
|
|
|
|
|
$client->waitForUnit("network.target");
|
|
|
|
$server->waitForUnit("ferm.service");
|
|
|
|
$server->waitForUnit("nginx.service");
|
2016-09-04 12:34:06 +00:00
|
|
|
$server->waitUntilSucceeds("ss -ntl | grep -q 80");
|
2016-08-29 13:18:25 +00:00
|
|
|
|
|
|
|
subtest "port 80 is allowed", sub {
|
|
|
|
$client->succeed("curl --fail -g http://192.168.1.1:80/status");
|
|
|
|
$client->succeed("curl --fail -g http://[fd00::1]:80/status");
|
|
|
|
};
|
|
|
|
|
|
|
|
subtest "port 8080 is not allowed", sub {
|
|
|
|
$server->succeed("curl --fail -g http://192.168.1.1:8080/status");
|
|
|
|
$server->succeed("curl --fail -g http://[fd00::1]:8080/status");
|
|
|
|
|
|
|
|
$client->fail("curl --fail -g http://192.168.1.1:8080/status");
|
|
|
|
$client->fail("curl --fail -g http://[fd00::1]:8080/status");
|
|
|
|
};
|
|
|
|
'';
|
|
|
|
})
|