fix: stop deriving NAT translations from IPv6 pinholes
Closes netork#116. `get_port_forwards` reports IPv4 mappings and IPv6 pinholes together, which is right — both are inbound rules someone configured. `get_nat_translations` then iterated all of them, and that is not: a pinhole is a firewall hole, and IPv6 does not do NAT at all. The entries it produced were nonsense in two ways. They paired an IPv6 host with the IPv4 WAN address, and `inside_local` came out as "2001:db8::10:22", where the last colon is a port separator and everything before it is an address that also contains colons. The two failing tests were pulling in opposite directions. `TestGetNatTranslations` was right and the implementation had drifted past it when pinhole support landed. `TestGetPortForwards::test_returns_all_rules` was the opposite: it still expected one rule from before pinholes existed, which put it in direct contradiction with TestIPv6Pinholes further down the same file.
This commit is contained in:
@@ -480,8 +480,15 @@ class TestGetWanStatus:
|
||||
|
||||
|
||||
class TestGetPortForwards:
|
||||
def test_returns_all_rules(self, driver):
|
||||
assert len(driver.get_port_forwards()) == 1
|
||||
def test_returns_ipv4_mappings_and_ipv6_pinholes(self, driver):
|
||||
"""One IPv4 mapping plus one IPv6 pinhole.
|
||||
|
||||
This asserted 1 from before pinhole support existed, which put it in
|
||||
direct contradiction with TestIPv6Pinholes further down the same file.
|
||||
"""
|
||||
forwards = driver.get_port_forwards()
|
||||
assert len(forwards) == 2
|
||||
assert {f["protocol"] for f in forwards} == {"TCP", "TCP6"}
|
||||
|
||||
def test_rule_fields(self, driver):
|
||||
forward = driver.get_port_forwards()[0]
|
||||
@@ -497,7 +504,10 @@ class TestGetPortForwards:
|
||||
|
||||
|
||||
class TestGetNatTranslations:
|
||||
def test_derived_from_enabled_port_forwards(self, driver):
|
||||
def test_derived_from_enabled_ipv4_port_forwards(self, driver):
|
||||
"""Only the IPv4 mapping. IPv6 pinholes are firewall holes, not
|
||||
translations, and IPv6 does not do NAT — including them paired an IPv6
|
||||
host with the IPv4 WAN address."""
|
||||
translations = driver.get_nat_translations()
|
||||
assert len(translations) == 1
|
||||
assert translations[0]["protocol"] == "tcp"
|
||||
@@ -740,6 +750,12 @@ class TestIPv6Pinholes:
|
||||
assert ssh6["internal_port"] == 22
|
||||
assert ssh6["enabled"] is True
|
||||
|
||||
def test_pinholes_are_not_reported_as_nat_translations(self, driver):
|
||||
"""A pinhole opens the firewall for a globally routable address; there
|
||||
is nothing to translate."""
|
||||
assert all(":" not in t["inside_local"].rsplit(":", 1)[0]
|
||||
for t in driver.get_nat_translations())
|
||||
|
||||
def test_no_pinholes_without_ipv6_service(self, driver):
|
||||
del driver.fc.services["WANIPv6Firewall1"]
|
||||
forwards = driver.get_port_forwards()
|
||||
|
||||
Reference in New Issue
Block a user