mirror of
https://gitlab.com/libvirt/libvirt.git
synced 2024-11-03 20:01:16 +00:00
3ba789ccd5
Create a nwfilterxml2firewalltest to exercise the ebiptables_driver.applyNewRules method with a variety of different XML input files. The XML input files are taken from the libvirt-tck nwfilter tests. While the nwfilter tests verify the final state of the iptables chains, this test verifies the set of commands invoked to create the chains. Signed-off-by: Daniel P. Berrange <berrange@redhat.com>
26 lines
1017 B
XML
26 lines
1017 B
XML
<!-- #ipset help && iptables -t match-set -h && ipset list tck_test || ipset create tck_test hash:ip# -->
|
|
<filter name='tck-testcase' chain='root'>
|
|
<uuid>5c6d49af-b071-6127-b4ec-6f8ed4b55335</uuid>
|
|
<rule action='accept' direction='out'>
|
|
<all ipset='tck_test' ipsetflags='src,dst' />
|
|
</rule>
|
|
<rule action='accept' direction='in'>
|
|
<all state='NONE' ipset='tck_test' ipsetflags='src,dst' comment='in+NONE'/>
|
|
</rule>
|
|
<rule action='accept' direction='out'>
|
|
<all state='NONE' ipset='tck_test' ipsetflags='src,dst' comment='out+NONE'/>
|
|
</rule>
|
|
<rule action='accept' direction='in'>
|
|
<all ipset='tck_test' ipsetflags='SRC,DST,SRC' />
|
|
</rule>
|
|
<rule action='accept' direction='in'>
|
|
<all ipset='tck_test' ipsetflags='SRC,dSt,SRC' />
|
|
</rule>
|
|
<rule action='accept' direction='in'>
|
|
<all ipset='$IPSETNAME' ipsetflags='src,dst' />
|
|
</rule>
|
|
<rule action='accept' direction='inout'>
|
|
<all ipset='$IPSETNAME' ipsetflags='src,dst' comment='inout'/>
|
|
</rule>
|
|
</filter>
|