bridge_test.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536
  1. package bridge
  2. import (
  3. "bytes"
  4. "fmt"
  5. "net"
  6. "regexp"
  7. "testing"
  8. "github.com/docker/libnetwork/driverapi"
  9. "github.com/docker/libnetwork/iptables"
  10. "github.com/docker/libnetwork/netlabel"
  11. "github.com/docker/libnetwork/netutils"
  12. "github.com/docker/libnetwork/types"
  13. "github.com/vishvananda/netlink"
  14. )
  15. func TestCreateFullOptions(t *testing.T) {
  16. defer netutils.SetupTestNetNS(t)()
  17. d := newDriver()
  18. config := &configuration{
  19. EnableIPForwarding: true,
  20. }
  21. netConfig := &networkConfiguration{
  22. BridgeName: DefaultBridgeName,
  23. EnableIPv6: true,
  24. FixedCIDR: bridgeNetworks[0],
  25. EnableIPTables: true,
  26. }
  27. _, netConfig.FixedCIDRv6, _ = net.ParseCIDR("2001:db8::/48")
  28. genericOption := make(map[string]interface{})
  29. genericOption[netlabel.GenericData] = config
  30. if err := d.Config(genericOption); err != nil {
  31. t.Fatalf("Failed to setup driver config: %v", err)
  32. }
  33. netOption := make(map[string]interface{})
  34. netOption[netlabel.GenericData] = netConfig
  35. err := d.CreateNetwork("dummy", netOption)
  36. if err != nil {
  37. t.Fatalf("Failed to create bridge: %v", err)
  38. }
  39. }
  40. func TestCreate(t *testing.T) {
  41. defer netutils.SetupTestNetNS(t)()
  42. d := newDriver()
  43. config := &networkConfiguration{BridgeName: DefaultBridgeName}
  44. genericOption := make(map[string]interface{})
  45. genericOption[netlabel.GenericData] = config
  46. if err := d.CreateNetwork("dummy", genericOption); err != nil {
  47. t.Fatalf("Failed to create bridge: %v", err)
  48. }
  49. }
  50. func TestCreateFail(t *testing.T) {
  51. defer netutils.SetupTestNetNS(t)()
  52. d := newDriver()
  53. config := &networkConfiguration{BridgeName: "dummy0"}
  54. genericOption := make(map[string]interface{})
  55. genericOption[netlabel.GenericData] = config
  56. if err := d.CreateNetwork("dummy", genericOption); err == nil {
  57. t.Fatal("Bridge creation was expected to fail")
  58. }
  59. }
  60. type testInterface struct {
  61. id int
  62. mac net.HardwareAddr
  63. addr net.IPNet
  64. addrv6 net.IPNet
  65. srcName string
  66. dstName string
  67. }
  68. type testEndpoint struct {
  69. ifaces []*testInterface
  70. gw net.IP
  71. gw6 net.IP
  72. hostsPath string
  73. resolvConfPath string
  74. }
  75. func (te *testEndpoint) Interfaces() []driverapi.InterfaceInfo {
  76. iList := make([]driverapi.InterfaceInfo, len(te.ifaces))
  77. for i, iface := range te.ifaces {
  78. iList[i] = iface
  79. }
  80. return iList
  81. }
  82. func (te *testEndpoint) AddInterface(id int, mac net.HardwareAddr, ipv4 net.IPNet, ipv6 net.IPNet) error {
  83. iface := &testInterface{id: id, addr: ipv4, addrv6: ipv6}
  84. te.ifaces = append(te.ifaces, iface)
  85. return nil
  86. }
  87. func (i *testInterface) ID() int {
  88. return i.id
  89. }
  90. func (i *testInterface) MacAddress() net.HardwareAddr {
  91. return i.mac
  92. }
  93. func (i *testInterface) Address() net.IPNet {
  94. return i.addr
  95. }
  96. func (i *testInterface) AddressIPv6() net.IPNet {
  97. return i.addrv6
  98. }
  99. func (i *testInterface) SetNames(srcName string, dstName string) error {
  100. i.srcName = srcName
  101. i.dstName = dstName
  102. return nil
  103. }
  104. func (te *testEndpoint) InterfaceNames() []driverapi.InterfaceNameInfo {
  105. iList := make([]driverapi.InterfaceNameInfo, len(te.ifaces))
  106. for i, iface := range te.ifaces {
  107. iList[i] = iface
  108. }
  109. return iList
  110. }
  111. func (te *testEndpoint) SetGateway(gw net.IP) error {
  112. te.gw = gw
  113. return nil
  114. }
  115. func (te *testEndpoint) SetGatewayIPv6(gw6 net.IP) error {
  116. te.gw6 = gw6
  117. return nil
  118. }
  119. func (te *testEndpoint) SetHostsPath(path string) error {
  120. te.hostsPath = path
  121. return nil
  122. }
  123. func (te *testEndpoint) SetResolvConfPath(path string) error {
  124. te.resolvConfPath = path
  125. return nil
  126. }
  127. func TestQueryEndpointInfo(t *testing.T) {
  128. testQueryEndpointInfo(t, true)
  129. }
  130. func TestQueryEndpointInfoHairpin(t *testing.T) {
  131. testQueryEndpointInfo(t, false)
  132. }
  133. func testQueryEndpointInfo(t *testing.T, ulPxyEnabled bool) {
  134. defer netutils.SetupTestNetNS(t)()
  135. d := newDriver()
  136. dd, _ := d.(*driver)
  137. config := &networkConfiguration{
  138. BridgeName: DefaultBridgeName,
  139. EnableIPTables: true,
  140. EnableICC: false,
  141. EnableUserlandProxy: ulPxyEnabled,
  142. }
  143. genericOption := make(map[string]interface{})
  144. genericOption[netlabel.GenericData] = config
  145. err := d.CreateNetwork("net1", genericOption)
  146. if err != nil {
  147. t.Fatalf("Failed to create bridge: %v", err)
  148. }
  149. portMappings := getPortMapping()
  150. epOptions := make(map[string]interface{})
  151. epOptions[netlabel.PortMap] = portMappings
  152. te := &testEndpoint{ifaces: []*testInterface{}}
  153. err = d.CreateEndpoint("net1", "ep1", te, epOptions)
  154. if err != nil {
  155. t.Fatalf("Failed to create an endpoint : %s", err.Error())
  156. }
  157. network, ok := dd.networks["net1"]
  158. if !ok {
  159. t.Fatalf("Cannot find network %s inside driver", "net1")
  160. }
  161. ep, _ := network.endpoints["ep1"]
  162. data, err := d.EndpointOperInfo(network.id, ep.id)
  163. if err != nil {
  164. t.Fatalf("Failed to ask for endpoint operational data: %v", err)
  165. }
  166. pmd, ok := data[netlabel.PortMap]
  167. if !ok {
  168. t.Fatalf("Endpoint operational data does not contain port mapping data")
  169. }
  170. pm, ok := pmd.([]types.PortBinding)
  171. if !ok {
  172. t.Fatalf("Unexpected format for port mapping in endpoint operational data")
  173. }
  174. if len(ep.portMapping) != len(pm) {
  175. t.Fatalf("Incomplete data for port mapping in endpoint operational data")
  176. }
  177. for i, pb := range ep.portMapping {
  178. if !pb.Equal(&pm[i]) {
  179. t.Fatalf("Unexpected data for port mapping in endpoint operational data")
  180. }
  181. }
  182. // Cleanup as host ports are there
  183. err = releasePorts(ep)
  184. if err != nil {
  185. t.Fatalf("Failed to release mapped ports: %v", err)
  186. }
  187. }
  188. func TestCreateLinkWithOptions(t *testing.T) {
  189. defer netutils.SetupTestNetNS(t)()
  190. d := newDriver()
  191. config := &networkConfiguration{BridgeName: DefaultBridgeName}
  192. netOptions := make(map[string]interface{})
  193. netOptions[netlabel.GenericData] = config
  194. err := d.CreateNetwork("net1", netOptions)
  195. if err != nil {
  196. t.Fatalf("Failed to create bridge: %v", err)
  197. }
  198. mac := net.HardwareAddr([]byte{0x1e, 0x67, 0x66, 0x44, 0x55, 0x66})
  199. epOptions := make(map[string]interface{})
  200. epOptions[netlabel.MacAddress] = mac
  201. te := &testEndpoint{ifaces: []*testInterface{}}
  202. err = d.CreateEndpoint("net1", "ep", te, epOptions)
  203. if err != nil {
  204. t.Fatalf("Failed to create an endpoint: %s", err.Error())
  205. }
  206. err = d.Join("net1", "ep", "sbox", te, nil)
  207. if err != nil {
  208. t.Fatalf("Failed to join the endpoint: %v", err)
  209. }
  210. ifaceName := te.ifaces[0].srcName
  211. veth, err := netlink.LinkByName(ifaceName)
  212. if err != nil {
  213. t.Fatal(err)
  214. }
  215. if !bytes.Equal(mac, veth.Attrs().HardwareAddr) {
  216. t.Fatalf("Failed to parse and program endpoint configuration")
  217. }
  218. }
  219. func getExposedPorts() []types.TransportPort {
  220. return []types.TransportPort{
  221. types.TransportPort{Proto: types.TCP, Port: uint16(5000)},
  222. types.TransportPort{Proto: types.UDP, Port: uint16(400)},
  223. types.TransportPort{Proto: types.TCP, Port: uint16(600)},
  224. }
  225. }
  226. func getPortMapping() []types.PortBinding {
  227. return []types.PortBinding{
  228. types.PortBinding{Proto: types.TCP, Port: uint16(230), HostPort: uint16(23000)},
  229. types.PortBinding{Proto: types.UDP, Port: uint16(200), HostPort: uint16(22000)},
  230. types.PortBinding{Proto: types.TCP, Port: uint16(120), HostPort: uint16(12000)},
  231. }
  232. }
  233. func TestLinkContainers(t *testing.T) {
  234. defer netutils.SetupTestNetNS(t)()
  235. d := newDriver()
  236. config := &networkConfiguration{
  237. BridgeName: DefaultBridgeName,
  238. EnableIPTables: true,
  239. EnableICC: false,
  240. }
  241. genericOption := make(map[string]interface{})
  242. genericOption[netlabel.GenericData] = config
  243. err := d.CreateNetwork("net1", genericOption)
  244. if err != nil {
  245. t.Fatalf("Failed to create bridge: %v", err)
  246. }
  247. exposedPorts := getExposedPorts()
  248. epOptions := make(map[string]interface{})
  249. epOptions[netlabel.ExposedPorts] = exposedPorts
  250. te1 := &testEndpoint{ifaces: []*testInterface{}}
  251. err = d.CreateEndpoint("net1", "ep1", te1, epOptions)
  252. if err != nil {
  253. t.Fatalf("Failed to create an endpoint : %s", err.Error())
  254. }
  255. addr1 := te1.ifaces[0].addr
  256. if addr1.IP.To4() == nil {
  257. t.Fatalf("No Ipv4 address assigned to the endpoint: ep1")
  258. }
  259. te2 := &testEndpoint{ifaces: []*testInterface{}}
  260. err = d.CreateEndpoint("net1", "ep2", te2, nil)
  261. if err != nil {
  262. t.Fatalf("Failed to create an endpoint : %s", err.Error())
  263. }
  264. addr2 := te2.ifaces[0].addr
  265. if addr2.IP.To4() == nil {
  266. t.Fatalf("No Ipv4 address assigned to the endpoint: ep2")
  267. }
  268. ce := []string{"ep1"}
  269. cConfig := &containerConfiguration{ChildEndpoints: ce}
  270. genericOption = make(map[string]interface{})
  271. genericOption[netlabel.GenericData] = cConfig
  272. err = d.Join("net1", "ep2", "", te2, genericOption)
  273. if err != nil {
  274. t.Fatalf("Failed to link ep1 and ep2")
  275. }
  276. out, err := iptables.Raw("-L", DockerChain)
  277. for _, pm := range exposedPorts {
  278. regex := fmt.Sprintf("%s dpt:%d", pm.Proto.String(), pm.Port)
  279. re := regexp.MustCompile(regex)
  280. matches := re.FindAllString(string(out[:]), -1)
  281. if len(matches) != 1 {
  282. t.Fatalf("IP Tables programming failed %s", string(out[:]))
  283. }
  284. regex = fmt.Sprintf("%s spt:%d", pm.Proto.String(), pm.Port)
  285. matched, _ := regexp.MatchString(regex, string(out[:]))
  286. if !matched {
  287. t.Fatalf("IP Tables programming failed %s", string(out[:]))
  288. }
  289. }
  290. err = d.Leave("net1", "ep2")
  291. if err != nil {
  292. t.Fatalf("Failed to unlink ep1 and ep2")
  293. }
  294. out, err = iptables.Raw("-L", DockerChain)
  295. for _, pm := range exposedPorts {
  296. regex := fmt.Sprintf("%s dpt:%d", pm.Proto.String(), pm.Port)
  297. re := regexp.MustCompile(regex)
  298. matches := re.FindAllString(string(out[:]), -1)
  299. if len(matches) != 0 {
  300. t.Fatalf("Leave should have deleted relevant IPTables rules %s", string(out[:]))
  301. }
  302. regex = fmt.Sprintf("%s spt:%d", pm.Proto.String(), pm.Port)
  303. matched, _ := regexp.MatchString(regex, string(out[:]))
  304. if matched {
  305. t.Fatalf("Leave should have deleted relevant IPTables rules %s", string(out[:]))
  306. }
  307. }
  308. // Error condition test with an invalid endpoint-id "ep4"
  309. ce = []string{"ep1", "ep4"}
  310. cConfig = &containerConfiguration{ChildEndpoints: ce}
  311. genericOption = make(map[string]interface{})
  312. genericOption[netlabel.GenericData] = cConfig
  313. err = d.Join("net1", "ep2", "", te2, genericOption)
  314. if err != nil {
  315. out, err = iptables.Raw("-L", DockerChain)
  316. for _, pm := range exposedPorts {
  317. regex := fmt.Sprintf("%s dpt:%d", pm.Proto.String(), pm.Port)
  318. re := regexp.MustCompile(regex)
  319. matches := re.FindAllString(string(out[:]), -1)
  320. if len(matches) != 0 {
  321. t.Fatalf("Error handling should rollback relevant IPTables rules %s", string(out[:]))
  322. }
  323. regex = fmt.Sprintf("%s spt:%d", pm.Proto.String(), pm.Port)
  324. matched, _ := regexp.MatchString(regex, string(out[:]))
  325. if matched {
  326. t.Fatalf("Error handling should rollback relevant IPTables rules %s", string(out[:]))
  327. }
  328. }
  329. } else {
  330. t.Fatalf("Expected Join to fail given link conditions are not satisfied")
  331. }
  332. }
  333. func TestValidateConfig(t *testing.T) {
  334. // Test mtu
  335. c := networkConfiguration{Mtu: -2}
  336. err := c.Validate()
  337. if err == nil {
  338. t.Fatalf("Failed to detect invalid MTU number")
  339. }
  340. c.Mtu = 9000
  341. err = c.Validate()
  342. if err != nil {
  343. t.Fatalf("unexpected validation error on MTU number")
  344. }
  345. // Bridge network
  346. _, network, _ := net.ParseCIDR("172.28.0.0/16")
  347. // Test FixedCIDR
  348. _, containerSubnet, _ := net.ParseCIDR("172.27.0.0/16")
  349. c = networkConfiguration{
  350. AddressIPv4: network,
  351. FixedCIDR: containerSubnet,
  352. }
  353. err = c.Validate()
  354. if err == nil {
  355. t.Fatalf("Failed to detect invalid FixedCIDR network")
  356. }
  357. _, containerSubnet, _ = net.ParseCIDR("172.28.0.0/16")
  358. c.FixedCIDR = containerSubnet
  359. err = c.Validate()
  360. if err != nil {
  361. t.Fatalf("Unexpected validation error on FixedCIDR network")
  362. }
  363. _, containerSubnet, _ = net.ParseCIDR("172.28.0.0/15")
  364. c.FixedCIDR = containerSubnet
  365. err = c.Validate()
  366. if err == nil {
  367. t.Fatalf("Failed to detect invalid FixedCIDR network")
  368. }
  369. _, containerSubnet, _ = net.ParseCIDR("172.28.0.0/17")
  370. c.FixedCIDR = containerSubnet
  371. err = c.Validate()
  372. if err != nil {
  373. t.Fatalf("Unexpected validation error on FixedCIDR network")
  374. }
  375. // Test v4 gw
  376. c.DefaultGatewayIPv4 = net.ParseIP("172.27.30.234")
  377. err = c.Validate()
  378. if err == nil {
  379. t.Fatalf("Failed to detect invalid default gateway")
  380. }
  381. c.DefaultGatewayIPv4 = net.ParseIP("172.28.30.234")
  382. err = c.Validate()
  383. if err != nil {
  384. t.Fatalf("Unexpected validation error on default gateway")
  385. }
  386. // Test v6 gw
  387. _, containerSubnet, _ = net.ParseCIDR("2001:1234:ae:b004::/64")
  388. c = networkConfiguration{
  389. EnableIPv6: true,
  390. FixedCIDRv6: containerSubnet,
  391. DefaultGatewayIPv6: net.ParseIP("2001:1234:ac:b004::bad:a55"),
  392. }
  393. err = c.Validate()
  394. if err == nil {
  395. t.Fatalf("Failed to detect invalid v6 default gateway")
  396. }
  397. c.DefaultGatewayIPv6 = net.ParseIP("2001:1234:ae:b004::bad:a55")
  398. err = c.Validate()
  399. if err != nil {
  400. t.Fatalf("Unexpected validation error on v6 default gateway")
  401. }
  402. c.FixedCIDRv6 = nil
  403. err = c.Validate()
  404. if err == nil {
  405. t.Fatalf("Failed to detect invalid v6 default gateway")
  406. }
  407. }
  408. func TestSetDefaultGw(t *testing.T) {
  409. defer netutils.SetupTestNetNS(t)()
  410. d := newDriver()
  411. _, subnetv6, _ := net.ParseCIDR("2001:db8:ea9:9abc:b0c4::/80")
  412. gw4 := bridgeNetworks[0].IP.To4()
  413. gw4[3] = 254
  414. gw6 := net.ParseIP("2001:db8:ea9:9abc:b0c4::254")
  415. config := &networkConfiguration{
  416. BridgeName: DefaultBridgeName,
  417. EnableIPv6: true,
  418. FixedCIDRv6: subnetv6,
  419. DefaultGatewayIPv4: gw4,
  420. DefaultGatewayIPv6: gw6,
  421. }
  422. genericOption := make(map[string]interface{})
  423. genericOption[netlabel.GenericData] = config
  424. err := d.CreateNetwork("dummy", genericOption)
  425. if err != nil {
  426. t.Fatalf("Failed to create bridge: %v", err)
  427. }
  428. te := &testEndpoint{ifaces: []*testInterface{}}
  429. err = d.CreateEndpoint("dummy", "ep", te, nil)
  430. if err != nil {
  431. t.Fatalf("Failed to create endpoint: %v", err)
  432. }
  433. err = d.Join("dummy", "ep", "sbox", te, nil)
  434. if err != nil {
  435. t.Fatalf("Failed to join endpoint: %v", err)
  436. }
  437. if !gw4.Equal(te.gw) {
  438. t.Fatalf("Failed to configure default gateway. Expected %v. Found %v", gw4, te.gw)
  439. }
  440. if !gw6.Equal(te.gw6) {
  441. t.Fatalf("Failed to configure default gateway. Expected %v. Found %v", gw6, te.gw6)
  442. }
  443. }