Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 11 additions & 13 deletions systemvm/patches/debian/config/opt/cloud/bin/cs/CsAddress.py
Original file line number Diff line number Diff line change
Expand Up @@ -394,12 +394,13 @@ def fw_router(self):
self.fw.append(["filter", "", "-A INPUT -i lo -j ACCEPT"])

if self.get_type() in ["guest"]:
guestNetworkCidr = self.address['network']
self.fw.append(
["filter", "", "-A INPUT -i %s -p udp -m udp --dport 67 -j ACCEPT" % self.dev])
self.fw.append(
["filter", "", "-A INPUT -i %s -p udp -m udp --dport 53 -j ACCEPT" % self.dev])
["filter", "", "-A INPUT -i %s -p udp -m udp --dport 53 -s %s -j ACCEPT" % (self.dev, guestNetworkCidr)])
self.fw.append(
["filter", "", "-A INPUT -i %s -p tcp -m tcp --dport 53 -j ACCEPT" % self.dev])
["filter", "", "-A INPUT -i %s -p tcp -m tcp --dport 53 -s %s -j ACCEPT" % (self.dev, guestNetworkCidr)])
self.fw.append(
["filter", "", "-A INPUT -i %s -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT" % self.dev])
self.fw.append(
Expand Down Expand Up @@ -436,8 +437,9 @@ def fw_vpcrouter(self):
self.fw.append(["filter", "", "-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT"])

if self.get_type() in ["guest"]:
guestNetworkCidr = self.address['network']
self.fw.append(["filter", "", "-A FORWARD -d %s -o %s -j ACL_INBOUND_%s" %
(self.address['network'], self.dev, self.dev)])
(guestNetworkCidr, self.dev, self.dev)])
self.fw.append(
["filter", "front", "-A ACL_INBOUND_%s -d 224.0.0.18/32 -j ACCEPT" % self.dev])
self.fw.append(
Expand All @@ -452,30 +454,26 @@ def fw_vpcrouter(self):
self.fw.append(
["filter", "", "-A INPUT -i %s -p udp -m udp --dport 67 -j ACCEPT" % self.dev])
self.fw.append(
["filter", "", "-A INPUT -i %s -p udp -m udp --dport 53 -j ACCEPT" % self.dev])
["filter", "", "-A INPUT -i %s -p udp -m udp --dport 53 -s %s -j ACCEPT" % (self.dev, guestNetworkCidr)])
self.fw.append(
["filter", "", "-A INPUT -i %s -p tcp -m tcp --dport 53 -j ACCEPT" % self.dev])
["filter", "", "-A INPUT -i %s -p tcp -m tcp --dport 53 -s %s -j ACCEPT" % (self.dev, guestNetworkCidr)])

self.fw.append(
["filter", "", "-A INPUT -i %s -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT" % self.dev])
self.fw.append(
["filter", "", "-A INPUT -i %s -p tcp -m tcp --dport 8080 -m state --state NEW -j ACCEPT" % self.dev])
self.fw.append(["mangle", "",
"-A PREROUTING -m state --state NEW -i %s -s %s ! -d %s/32 -j ACL_OUTBOUND_%s" %
(self.dev, self.address[
'network'], self.address['gateway'], self.dev)
])
(self.dev, guestNetworkCidr, self.address['gateway'], self.dev)])

self.fw.append(["", "front", "-A NETWORK_STATS_%s -i %s -d %s" %
("eth1", "eth1", self.address['network'])])
("eth1", "eth1", guestNetworkCidr)])
self.fw.append(["", "front", "-A NETWORK_STATS_%s -o %s -s %s" %
("eth1", "eth1", self.address['network'])])
("eth1", "eth1", guestNetworkCidr)])

self.fw.append(["nat", "front",
"-A POSTROUTING -s %s -o %s -j SNAT --to-source %s" %
(self.address['network'], self.dev,
self.address['public_ip'])
])
(guestNetworkCidr, self.dev, self.address['public_ip'])])

if self.get_type() in ["public"]:
self.fw.append(["", "front",
Expand Down
268 changes: 268 additions & 0 deletions test/integration/smoke/test_router_dns.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,268 @@
# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements. See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership. The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing,
# software distributed under the License is distributed on an
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
# KIND, either express or implied. See the License for the
# specific language governing permissions and limitations
# under the License.

import logging
import dns.resolver

from nose.plugins.attrib import attr
from marvin.cloudstackTestCase import cloudstackTestCase
from marvin.lib.utils import cleanup_resources
from marvin.lib.base import (ServiceOffering,
VirtualMachine,
Account,
NATRule,
FireWallRule,
NetworkOffering,
Network)
from marvin.lib.common import (get_zone,
get_template,
get_domain,
list_routers,
list_nat_rules,
list_publicIP)


class TestRouterDns(cloudstackTestCase):

@classmethod
def setUpClass(cls):
cls.logger = logging.getLogger('TestRouterDns')
cls.stream_handler = logging.StreamHandler()
cls.logger.setLevel(logging.DEBUG)
cls.logger.addHandler(cls.stream_handler)

cls.testClient = super(TestRouterDns, cls).getClsTestClient()
cls.api_client = cls.testClient.getApiClient()
cls.services = cls.testClient.getParsedTestDataConfig()

cls.domain = get_domain(cls.api_client)
cls.zone = get_zone(cls.api_client, cls.testClient.getZoneForTests())
cls.services['mode'] = cls.zone.networktype
cls.template = get_template(
cls.api_client,
cls.zone.id,
cls.services["ostype"]
)
cls.services["virtual_machine"]["zoneid"] = cls.zone.id

cls.logger.debug("Creating Admin Account for domain %s on zone %s" % (cls.domain.id, cls.zone.id))
cls.account = Account.create(
cls.api_client,
cls.services["account"],
admin=True,
domainid=cls.domain.id
)

cls.logger.debug("Creating Service Offering on zone %s" % (cls.zone.id))
cls.service_offering = ServiceOffering.create(
cls.api_client,
cls.services["service_offering"]
)

cls.logger.debug("Creating Network Offering on zone %s" % (cls.zone.id))
cls.services["isolated_network_offering"]["egress_policy"] = "true"
cls.network_offering = NetworkOffering.create(cls.api_client,
cls.services["isolated_network_offering"],
conservemode=True)
cls.network_offering.update(cls.api_client, state='Enabled')

cls.logger.debug("Creating Network for Account %s using offering %s" % (cls.account.name, cls.network_offering.id))
cls.network = Network.create(cls.api_client,
cls.services["network"],
accountid=cls.account.name,
domainid=cls.account.domainid,
networkofferingid=cls.network_offering.id,
zoneid=cls.zone.id)

cls.logger.debug("Creating guest VM for Account %s using offering %s" % (cls.account.name, cls.service_offering.id))
cls.vm = VirtualMachine.create(cls.api_client,
cls.services["virtual_machine"],
templateid=cls.template.id,
accountid=cls.account.name,
domainid=cls.domain.id,
serviceofferingid=cls.service_offering.id,
networkids=[str(cls.network.id)])
cls.vm.password = "password"

cls.services["natrule1"] = {
"privateport": 22,
"publicport": 22,
"protocol": "TCP"
}

cls.services["configurableData"] = {
"host": {
"password": "password",
"username": "root",
"port": 22
},
"input": "INPUT",
"forward": "FORWARD"
}

cls._cleanup = [
cls.vm,
cls.network,
cls.network_offering,
cls.service_offering,
cls.account
]


@classmethod
def tearDownClass(cls):
try:
cleanup_resources(cls.api_client, cls._cleanup)
except Exception as e:
raise Exception("Warning: Exception during cleanup : %s" % e)


def setUp(self):
self.apiclient = self.testClient.getApiClient()
self.cleanup = []


def tearDown(self):
try:
cleanup_resources(self.apiclient, self.cleanup)
except Exception as e:
raise Exception("Warning: Exception during cleanup : %s" % e)


def test_router_common(self):
"""Performs common router tests and returns router public_ips"""

routers = list_routers(
self.apiclient,
account=self.account.name,
domainid=self.account.domainid
)

self.assertEqual(
isinstance(routers, list),
True,
"Check for list routers response return valid data"
)

self.assertTrue(
len(routers) >= 1,
"Check list router response"
)

router = routers[0]

self.assertEqual(
router.state,
'Running',
"Check list router response for router state"
)

public_ips = list_publicIP(
self.apiclient,
account=self.account.name,
domainid=self.account.domainid,
zoneid=self.zone.id
)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should there be an assert that public_ips has a length of 1?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed.


self.assertEqual(
isinstance(public_ips, list),
True,
"Check for list public IPs response return valid data"
)

self.assertTrue(
len(public_ips) >= 1,
"Check public IP list has at least one IP"
)

return public_ips


@attr(tags=["advanced", "advancedns", "ssh"], required_hardware="true")
def test_router_dns_externalipquery(self):
"""Checks that non-guest network IPs cannot access VR DNS"""

self.logger.debug("Starting test_router_dns_externalips...")

public_ip = self.test_router_common()[0]

self.logger.debug("Querying VR DNS IP: " + public_ip.ipaddress)
resolver = dns.resolver.Resolver()
resolver.namerservers = [public_ip.ipaddress]
try:
resolver.query('google.com', 'A')
self.fail("Non-guest network IPs are able to access VR DNS, failing.")
except:
self.logger.debug("VR DNS query failed from non-guest network IP as expected")


@attr(tags=["advanced", "advancedns", "ssh"], required_hardware="true")
def test_router_dns_guestipquery(self):

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The setup of this test method and test_router_dns_externalipquery seem very similar. Would it make sense to factor it out to the setup method or some other internal utility method?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Refactored common tests code.

"""Checks that guest VM can query VR DNS"""

self.logger.debug("Starting test_router_dns_guestipquery...")
public_ip = self.test_router_common()[0]

self.logger.debug("Creating Firewall rule for VM ID: %s" % self.vm.id)
FireWallRule.create(
self.apiclient,
ipaddressid=public_ip.id,
protocol=self.services["natrule1"]["protocol"],
cidrlist=['0.0.0.0/0'],
startport=self.services["natrule1"]["publicport"],
endport=self.services["natrule1"]["publicport"]
)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we check that the results of the FireWallRule.create call to ensure that it created as expected?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We'll need to do a list call to verify, but that's not necessary because if there is an issue with fw-rules, SSH into VM will fail.


self.logger.debug("Creating NAT rule for VM ID: %s" % self.vm.id)
nat_rule1 = NATRule.create(
self.apiclient,
self.vm,
self.services["natrule1"],
public_ip.id
)
nat_rules = list_nat_rules(
self.apiclient,
id=nat_rule1.id
)
self.assertEqual(
isinstance(nat_rules, list),
True,
"Check for list NAT rules response return valid data"
)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should there be an assertiong that nat_rules has a length of 1?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed.

self.assertTrue(
len(nat_rules) >= 1,
"Check for list NAT rules to have at least one rule"
)
self.assertEqual(
nat_rules[0].state,
'Active',
"Check list port forwarding rules"
)

result = None
try:
self.logger.debug("SSH into guest VM with IP: %s" % nat_rule1.ipaddress)
ssh = self.vm.get_ssh_client(ipaddress=nat_rule1.ipaddress, port=self.services['natrule1']["publicport"], retries=8)
result = str(ssh.execute("nslookup google.com"))
except Exception as e:
self.fail("Failed to SSH into VM - %s due to exception: %s" % (nat_rule1.ipaddress, e))

if not result:
self.fail("Did not to receive any response from the guest VM, failing.")

self.assertTrue("google.com" in result and "#53" in result,
"VR DNS should serve requests from guest network, unable to get valid nslookup result from guest VM.")
3 changes: 2 additions & 1 deletion tools/marvin/marvin/sshClient.py
Original file line number Diff line number Diff line change
Expand Up @@ -118,7 +118,8 @@ def createConnection(self):
port=self.port,
username=self.user,
password=self.passwd,
timeout=self.timeout)
timeout=self.timeout,
allow_agent=False)
else:
self.ssh.connect(hostname=self.host,
port=self.port,
Expand Down
1 change: 1 addition & 0 deletions tools/marvin/setup.py
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,7 @@
"ddt >= 0.4.0",
"pyvmomi >= 5.5.0",
"netaddr >= 0.7.14",
"dnspython",
"ipmisim >= 0.7"
],
py_modules=['marvin.marvinPlugin'],
Expand Down