mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge pull request #10824 from ioito/automated-cherry-pick-of-#10709-upstream-release-3.7
Automated cherry pick of #10709: Hotfix/qx secrule sync fix
This commit is contained in:
@@ -38,7 +38,13 @@ func TestAliyunRuleSync(t *testing.T) {
|
||||
ruleWithName("", "in:allow tcp 22", 100),
|
||||
ruleWithName("", "in:allow tcp 1212", 100),
|
||||
},
|
||||
Common: []cloudprovider.SecurityRule{},
|
||||
Common: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "in:deny tcp 443", 1),
|
||||
ruleWithName("", "in:allow udp 1231", 1),
|
||||
ruleWithName("", "in:allow tcp 3389", 100),
|
||||
ruleWithName("", "in:allow tcp 22", 100),
|
||||
ruleWithName("", "in:allow tcp 1212", 100),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
@@ -53,7 +59,7 @@ func TestAliyunRuleSync(t *testing.T) {
|
||||
Common: []cloudprovider.SecurityRule{},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "out:deny tcp 443", 49),
|
||||
ruleWithName("", "out:deny tcp 443", 99),
|
||||
},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
OutDels: []cloudprovider.SecurityRule{},
|
||||
|
||||
@@ -29,7 +29,7 @@ func TestAzureRuleSync(t *testing.T) {
|
||||
Common: []cloudprovider.SecurityRule{},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "out:allow any", 2096),
|
||||
ruleWithName("", "out:allow any", 4096),
|
||||
},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
OutDels: []cloudprovider.SecurityRule{},
|
||||
@@ -44,16 +44,18 @@ func TestAzureRuleSync(t *testing.T) {
|
||||
ruleWithName("test-tcp", "out:allow tcp 100-200", 1000),
|
||||
ruleWithName("test-udp", "out:allow udp 200-300", 1002),
|
||||
},
|
||||
Common: []cloudprovider.SecurityRule{
|
||||
Common: []cloudprovider.SecurityRule{},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "out:allow tcp 100-200", 4094),
|
||||
ruleWithName("", "out:allow udp 200-300", 4095),
|
||||
ruleWithName("", "out:allow any", 4096),
|
||||
},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
OutDels: []cloudprovider.SecurityRule{
|
||||
ruleWithName("test-tcp", "out:allow tcp 100-200", 1000),
|
||||
ruleWithName("test-udp", "out:allow udp 200-300", 1002),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "out:allow any", 2096),
|
||||
},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
OutDels: []cloudprovider.SecurityRule{},
|
||||
},
|
||||
{
|
||||
Name: "Test add rules",
|
||||
@@ -67,8 +69,8 @@ func TestAzureRuleSync(t *testing.T) {
|
||||
},
|
||||
Common: []cloudprovider.SecurityRule{},
|
||||
InAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "in:allow tcp", 2098),
|
||||
ruleWithName("", "in:allow udp", 2098),
|
||||
ruleWithName("", "in:allow tcp", 4094),
|
||||
ruleWithName("", "in:allow udp", 4095),
|
||||
},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{
|
||||
@@ -89,14 +91,16 @@ func TestAzureRuleSync(t *testing.T) {
|
||||
ruleWithName("allow-icmp", "in:allow icmp", 400),
|
||||
},
|
||||
Common: []cloudprovider.SecurityRule{
|
||||
ruleWithName("allow-tcp", "in:allow tcp", 300),
|
||||
ruleWithName("allow-icmp", "in:allow icmp", 400),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "in:allow udp", 2098),
|
||||
ruleWithName("", "in:allow tcp", 398),
|
||||
ruleWithName("", "in:allow udp", 399),
|
||||
},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{
|
||||
ruleWithName("allow-tcp", "in:allow tcp", 300),
|
||||
},
|
||||
OutDels: []cloudprovider.SecurityRule{},
|
||||
},
|
||||
{
|
||||
@@ -113,7 +117,7 @@ func TestAzureRuleSync(t *testing.T) {
|
||||
ruleWithName("allow-tcp-22", "in:allow tcp 22", 300),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "in:allow tcp 33", 301),
|
||||
ruleWithName("", "in:allow tcp 33", 299),
|
||||
},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
@@ -139,17 +143,15 @@ func TestAzureRuleSync(t *testing.T) {
|
||||
Common: []cloudprovider.SecurityRule{
|
||||
ruleWithName("in_allow_tcp_22_4013", "in:allow tcp 22", 4013),
|
||||
ruleWithName("in_allow_udp_55_4014", "in:allow udp 55", 4014),
|
||||
ruleWithName("in_allow_tcp_1002_4012", "in:allow tcp 1002", 4012),
|
||||
ruleWithName("in_allow_tcp_1050_4010", "in:allow tcp 1050", 4010),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "in:allow tcp 1050", 4010),
|
||||
ruleWithName("", "in:allow tcp 1011", 4011),
|
||||
ruleWithName("", "in:allow tcp 1002", 4012),
|
||||
},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{
|
||||
ruleWithName("in_allow_tcp_1050_4010", "in:allow tcp 1050", 4010),
|
||||
ruleWithName("in_allow_tcp_1010_4011", "in:allow tcp 1010", 4011),
|
||||
ruleWithName("in_allow_tcp_1002_4012", "in:allow tcp 1002", 4012),
|
||||
},
|
||||
OutDels: []cloudprovider.SecurityRule{},
|
||||
},
|
||||
@@ -176,20 +178,17 @@ func TestAzureRuleSync(t *testing.T) {
|
||||
Common: []cloudprovider.SecurityRule{
|
||||
ruleWithName("in_allow_tcp_22_4013", "in:allow tcp 22", 4013),
|
||||
ruleWithName("in_allow_udp_55_4014", "in:allow udp 55", 4014),
|
||||
ruleWithName("in_allow_tcp_1002_4012", "in:allow tcp 1002", 4012),
|
||||
ruleWithName("in_allow_tcp_1012_4011", "in:allow tcp 1012", 4011),
|
||||
ruleWithName("in_allow_tcp_1050_4010", "in:allow tcp 1050", 4010),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "in:allow icmp", 2096),
|
||||
ruleWithName("", "in:allow tcp 1050", 4010),
|
||||
ruleWithName("", "in:allow tcp 1012", 4011),
|
||||
ruleWithName("", "in:allow tcp 1002", 4012),
|
||||
ruleWithName("", "in:allow udp 1055", 4013),
|
||||
ruleWithName("", "in:allow icmp", 4009),
|
||||
ruleWithName("", "in:allow udp 1055", 4008),
|
||||
},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{
|
||||
ruleWithName("in_allow_tcp_1055_4009", "in:allow tcp 1055", 4009),
|
||||
ruleWithName("in_allow_tcp_1050_4010", "in:allow tcp 1050", 4010),
|
||||
ruleWithName("in_allow_tcp_1012_4011", "in:allow tcp 1012", 4011),
|
||||
ruleWithName("in_allow_tcp_1002_4012", "in:allow tcp 1002", 4012),
|
||||
},
|
||||
OutDels: []cloudprovider.SecurityRule{},
|
||||
},
|
||||
|
||||
@@ -41,6 +41,7 @@ func TestKvmRuleSync(t *testing.T) {
|
||||
}
|
||||
|
||||
aliyun := []TestData{
|
||||
|
||||
{
|
||||
Name: "Test aliyun rules",
|
||||
SrcRules: cloudprovider.SecurityRuleSet{
|
||||
@@ -60,19 +61,24 @@ func TestKvmRuleSync(t *testing.T) {
|
||||
ruleWithName("allow tcp 80", "in:allow tcp 80", 50),
|
||||
ruleWithName("allow tcp", "in:allow tcp", 1),
|
||||
},
|
||||
Common: []cloudprovider.SecurityRule{
|
||||
Common: []cloudprovider.SecurityRule{},
|
||||
InAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "in:allow tcp 1521", 1),
|
||||
ruleWithName("", "in:allow tcp 3389", 1),
|
||||
ruleWithName("", "in:allow tcp 443", 1),
|
||||
ruleWithName("", "in:allow tcp 6379", 1),
|
||||
ruleWithName("", "in:allow tcp 80", 1),
|
||||
},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{
|
||||
ruleWithName("allow tcp", "in:allow tcp", 51),
|
||||
ruleWithName("allow tcp", "in:allow tcp", 1),
|
||||
ruleWithName("allow tcp 1521", "in:allow tcp 1521", 50),
|
||||
ruleWithName("allow tcp 3389", "in:allow tcp 3389", 50),
|
||||
ruleWithName("allow tcp 443", "in:allow tcp 443", 50),
|
||||
ruleWithName("allow tcp 6379", "in:allow tcp 6379", 50),
|
||||
ruleWithName("allow tcp 80", "in:allow tcp 80", 50),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{
|
||||
ruleWithName("allow tcp", "in:allow tcp", 51),
|
||||
ruleWithName("allow tcp", "in:allow tcp", 1),
|
||||
},
|
||||
OutDels: []cloudprovider.SecurityRule{},
|
||||
},
|
||||
{
|
||||
@@ -84,8 +90,8 @@ func TestKvmRuleSync(t *testing.T) {
|
||||
DestRules: []cloudprovider.SecurityRule{},
|
||||
Common: []cloudprovider.SecurityRule{},
|
||||
InAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithPeerSecgroup("allow tcp 443", "in:allow tcp 443", 51, "peer1"),
|
||||
ruleWithName("deny tcp 1521", "in:deny tcp 1521", 51),
|
||||
ruleWithPeerSecgroup("allow tcp 443", "in:allow tcp 443", 3, "peer1"),
|
||||
ruleWithName("deny tcp 1521", "in:deny tcp 1521", 2),
|
||||
},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
|
||||
@@ -43,7 +43,7 @@ func TestOpenStackRuleSync(t *testing.T) {
|
||||
OutDels: []cloudprovider.SecurityRule{},
|
||||
},
|
||||
{
|
||||
Name: "Test deny rules",
|
||||
Name: "Test deny rules 2",
|
||||
SrcRules: cloudprovider.SecurityRuleSet{
|
||||
ruleWithPriority("in:deny any", 100),
|
||||
ruleWithPriority("in:allow any", 99),
|
||||
@@ -53,7 +53,9 @@ func TestOpenStackRuleSync(t *testing.T) {
|
||||
ruleWithName("", "in:allow any", 0),
|
||||
ruleWithName("", "out:allow any", 0),
|
||||
},
|
||||
Common: []cloudprovider.SecurityRule{},
|
||||
Common: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "out:allow any", 0),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{
|
||||
|
||||
@@ -22,6 +22,7 @@ import (
|
||||
|
||||
func TestQcloudRuleSync(t *testing.T) {
|
||||
data := []TestData{
|
||||
|
||||
{
|
||||
Name: "Test out rules",
|
||||
SrcRules: cloudprovider.SecurityRuleSet{
|
||||
@@ -32,11 +33,98 @@ func TestQcloudRuleSync(t *testing.T) {
|
||||
Common: []cloudprovider.SecurityRule{},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithName("", "out:allow any", 48),
|
||||
ruleWithName("", "out:allow any", 100),
|
||||
},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
OutDels: []cloudprovider.SecurityRule{},
|
||||
},
|
||||
{
|
||||
Name: "Test peer out rules",
|
||||
SrcRules: cloudprovider.SecurityRuleSet{
|
||||
ruleWithPeerSecgroup("", "out:allow tcp", 1, "sec2"),
|
||||
ruleWithPriority("out:deny any", 1),
|
||||
},
|
||||
DestRules: []cloudprovider.SecurityRule{
|
||||
ruleWithPeerSecgroup("", "out:allow tcp", 2, "sec2"),
|
||||
ruleWithPriority("out:deny any", 1),
|
||||
},
|
||||
Common: []cloudprovider.SecurityRule{
|
||||
ruleWithPeerSecgroup("", "out:allow tcp", 2, "sec2"),
|
||||
ruleWithPriority("out:deny any", 1),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
OutDels: []cloudprovider.SecurityRule{},
|
||||
},
|
||||
{
|
||||
Name: "Test peer out rules priority",
|
||||
SrcRules: cloudprovider.SecurityRuleSet{
|
||||
ruleWithPeerSecgroup("", "out:allow tcp", 2, "sec2"),
|
||||
ruleWithPriority("out:deny any", 1),
|
||||
},
|
||||
DestRules: []cloudprovider.SecurityRule{
|
||||
ruleWithPeerSecgroup("", "out:allow tcp", 2, "sec2"),
|
||||
ruleWithPriority("out:deny any", 1),
|
||||
},
|
||||
Common: []cloudprovider.SecurityRule{
|
||||
ruleWithPriority("out:deny any", 1),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithPeerSecgroup("", "out:allow tcp", 0, "sec2"),
|
||||
},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
OutDels: []cloudprovider.SecurityRule{
|
||||
ruleWithPeerSecgroup("", "out:allow tcp", 2, "sec2"),
|
||||
},
|
||||
},
|
||||
{
|
||||
Name: "Test peer out rules priority 2",
|
||||
SrcRules: cloudprovider.SecurityRuleSet{
|
||||
ruleWithPeerSecgroup("", "out:deny tcp", 4, "sec2"),
|
||||
ruleWithPriority("out:allow any", 5),
|
||||
},
|
||||
DestRules: []cloudprovider.SecurityRule{
|
||||
ruleWithPeerSecgroup("", "out:deny tcp", 0, "sec2"),
|
||||
ruleWithPriority("out:allow any", 3),
|
||||
},
|
||||
Common: []cloudprovider.SecurityRule{
|
||||
ruleWithPeerSecgroup("", "out:deny tcp", 1, "sec2"),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{
|
||||
ruleWithPriority("out:allow any", 0),
|
||||
},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
OutDels: []cloudprovider.SecurityRule{
|
||||
ruleWithPriority("out:allow any", 3),
|
||||
},
|
||||
},
|
||||
{
|
||||
Name: "Test peer out rules 1",
|
||||
SrcRules: cloudprovider.SecurityRuleSet{
|
||||
ruleWithPeerSecgroup("", "out:deny tcp 22", 60, "Sys-Default"),
|
||||
ruleWithPriority("out:allow 10.0.0.0/8 udp", 10),
|
||||
},
|
||||
DestRules: []cloudprovider.SecurityRule{
|
||||
ruleWithPriority("out:allow any", 1),
|
||||
ruleWithPeerSecgroup("", "out:deny tcp 22", 2, "Sys-Default"),
|
||||
ruleWithPriority("out:allow 10.0.0.0/8 udp", 3),
|
||||
ruleWithPriority("out:allow any", 4),
|
||||
},
|
||||
Common: []cloudprovider.SecurityRule{
|
||||
ruleWithPeerSecgroup("", "out:deny tcp 22", 2, "Sys-Default"),
|
||||
ruleWithPriority("out:allow 10.0.0.0/8 udp", 3),
|
||||
ruleWithPriority("out:allow any", 4),
|
||||
},
|
||||
InAdds: []cloudprovider.SecurityRule{},
|
||||
OutAdds: []cloudprovider.SecurityRule{},
|
||||
InDels: []cloudprovider.SecurityRule{},
|
||||
OutDels: []cloudprovider.SecurityRule{
|
||||
ruleWithPriority("out:allow any", 1),
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
for _, d := range data {
|
||||
|
||||
@@ -21,7 +21,6 @@ import (
|
||||
|
||||
"yunion.io/x/pkg/util/secrules"
|
||||
"yunion.io/x/pkg/util/stringutils"
|
||||
"yunion.io/x/pkg/utils"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudprovider"
|
||||
)
|
||||
@@ -81,15 +80,8 @@ func (d TestData) Test(t *testing.T, srcD, destD cloudprovider.SecDriver) {
|
||||
externalIds = append(externalIds, fmt.Sprintf("%s-%d", outDels[i].String(), outDels[i].Priority))
|
||||
}
|
||||
}
|
||||
destRules := cloudprovider.SecurityRuleSet{}
|
||||
for i := range dest.Rules {
|
||||
if utils.IsInStringArray(dest.Rules[i].ExternalId, externalIds) || utils.IsInStringArray(fmt.Sprintf("%s-%d", dest.Rules[i].String(), dest.Rules[i].Priority), externalIds) {
|
||||
continue
|
||||
}
|
||||
destRules = append(destRules, dest.Rules[i])
|
||||
}
|
||||
dest.Rules = destRules
|
||||
_, inAdds, outAdds, inDels, outDels = cloudprovider.CompareRules(src, dest, true)
|
||||
dest.Rules = append(append(common, inAdds...), outAdds...)
|
||||
_, inAdds, outAdds, inDels, outDels = cloudprovider.CompareRules(dest, src, true)
|
||||
//check(t, "common", common, rd.Common)
|
||||
check(t, "inAdds", inAdds, rd.InAdds, dest.MinPriority, dest.MaxPriority)
|
||||
check(t, "outAdds", outAdds, rd.OutAdds, dest.MinPriority, dest.MaxPriority)
|
||||
@@ -146,11 +138,11 @@ var check = func(t *testing.T, name string, ret, expect []cloudprovider.Security
|
||||
show(fmt.Sprintf("%s expect", name), expect)
|
||||
t.Fatalf("invalid index(%d) %s rule name %s expect %s", i, name, ret[i].Name, expect[i].Name)
|
||||
}
|
||||
// if ret[i].Priority != expect[i].Priority {
|
||||
// show(fmt.Sprintf("%s rule", name), ret)
|
||||
// show(fmt.Sprintf("%s expect", name), expect)
|
||||
// t.Fatalf("invalid index(%d) %s rule priority %d expect %d", i, name, ret[i].Priority, expect[i].Priority)
|
||||
// }
|
||||
if ret[i].Priority != expect[i].Priority {
|
||||
show(fmt.Sprintf("%s rule", name), ret)
|
||||
show(fmt.Sprintf("%s expect", name), expect)
|
||||
t.Fatalf("invalid index(%d) %s rule priority %d expect %d", i, name, ret[i].Priority, expect[i].Priority)
|
||||
}
|
||||
if max != min && (ret[i].Priority < min || ret[i].Priority > max) {
|
||||
t.Fatalf("invalid index(%d) %s rules %s priority should be in [%d, %d] current is %d", i, name, ret[i].String(), min, max, ret[i].Priority)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user