PEP8 again
This commit is contained in:
@@ -36,61 +36,62 @@ LOG = logging.getLogger('nova.tests.network')
|
||||
|
||||
|
||||
class IptablesManagerTestCase(test.TestCase):
|
||||
sample_filter = """# Generated by iptables-save on Fri Feb 18 15:17:05 2011
|
||||
*filter
|
||||
:INPUT ACCEPT [2223527:305688874]
|
||||
:FORWARD ACCEPT [0:0]
|
||||
:OUTPUT ACCEPT [2172501:140856656]
|
||||
:nova-compute-FORWARD - [0:0]
|
||||
:nova-compute-INPUT - [0:0]
|
||||
:nova-compute-local - [0:0]
|
||||
:nova-compute-OUTPUT - [0:0]
|
||||
:nova-filter-top - [0:0]
|
||||
-A FORWARD -j nova-filter-top
|
||||
-A OUTPUT -j nova-filter-top
|
||||
-A nova-filter-top -j nova-compute-local
|
||||
-A INPUT -j nova-compute-INPUT
|
||||
-A OUTPUT -j nova-compute-OUTPUT
|
||||
-A FORWARD -j nova-compute-FORWARD
|
||||
-A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
|
||||
-A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
|
||||
-A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
|
||||
-A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
|
||||
-A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
|
||||
-A FORWARD -i virbr0 -o virbr0 -j ACCEPT
|
||||
-A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
|
||||
-A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
|
||||
COMMIT
|
||||
# Completed on Fri Feb 18 15:17:05 2011"""
|
||||
sample_filter = ['#Generated by iptables-save on Fri Feb 18 15:17:05 2011',
|
||||
'*filter',
|
||||
':INPUT ACCEPT [2223527:305688874]',
|
||||
':FORWARD ACCEPT [0:0]',
|
||||
':OUTPUT ACCEPT [2172501:140856656]',
|
||||
':nova-compute-FORWARD - [0:0]',
|
||||
':nova-compute-INPUT - [0:0]',
|
||||
':nova-compute-local - [0:0]',
|
||||
':nova-compute-OUTPUT - [0:0]',
|
||||
':nova-filter-top - [0:0]',
|
||||
'-A FORWARD -j nova-filter-top ',
|
||||
'-A OUTPUT -j nova-filter-top ',
|
||||
'-A nova-filter-top -j nova-compute-local ',
|
||||
'-A INPUT -j nova-compute-INPUT ',
|
||||
'-A OUTPUT -j nova-compute-OUTPUT ',
|
||||
'-A FORWARD -j nova-compute-FORWARD ',
|
||||
'-A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT ',
|
||||
'-A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT ',
|
||||
'-A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT ',
|
||||
'-A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT ',
|
||||
'-A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT ',
|
||||
'-A FORWARD -i virbr0 -o virbr0 -j ACCEPT ',
|
||||
'-A FORWARD -o virbr0 -j REJECT --reject-with '
|
||||
'icmp-port-unreachable ',
|
||||
'-A FORWARD -i virbr0 -j REJECT --reject-with '
|
||||
'icmp-port-unreachable ',
|
||||
'COMMIT',
|
||||
'# Completed on Fri Feb 18 15:17:05 2011']
|
||||
|
||||
sample_nat = """# Generated by iptables-save on Fri Feb 18 15:17:05 2011
|
||||
*nat
|
||||
:PREROUTING ACCEPT [3936:762355]
|
||||
:INPUT ACCEPT [2447:225266]
|
||||
:OUTPUT ACCEPT [63491:4191863]
|
||||
:POSTROUTING ACCEPT [63112:4108641]
|
||||
:nova-compute-OUTPUT - [0:0]
|
||||
:nova-compute-floating-ip-snat - [0:0]
|
||||
:nova-compute-SNATTING - [0:0]
|
||||
:nova-compute-PREROUTING - [0:0]
|
||||
:nova-compute-POSTROUTING - [0:0]
|
||||
:nova-postrouting-bottom - [0:0]
|
||||
-A PREROUTING -j nova-compute-PREROUTING
|
||||
-A OUTPUT -j nova-compute-OUTPUT
|
||||
-A POSTROUTING -j nova-compute-POSTROUTING
|
||||
-A POSTROUTING -j nova-postrouting-bottom
|
||||
-A nova-postrouting-bottom -j nova-compute-SNATTING
|
||||
-A nova-compute-SNATTING -j nova-compute-floating-ip-snat
|
||||
COMMIT
|
||||
# Completed on Fri Feb 18 15:17:05 2011
|
||||
"""
|
||||
sample_nat = ['# Generated by iptables-save on Fri Feb 18 15:17:05 2011',
|
||||
'*nat',
|
||||
':PREROUTING ACCEPT [3936:762355]',
|
||||
':INPUT ACCEPT [2447:225266]',
|
||||
':OUTPUT ACCEPT [63491:4191863]',
|
||||
':POSTROUTING ACCEPT [63112:4108641]',
|
||||
':nova-compute-OUTPUT - [0:0]',
|
||||
':nova-compute-floating-ip-snat - [0:0]',
|
||||
':nova-compute-SNATTING - [0:0]',
|
||||
':nova-compute-PREROUTING - [0:0]',
|
||||
':nova-compute-POSTROUTING - [0:0]',
|
||||
':nova-postrouting-bottom - [0:0]',
|
||||
'-A PREROUTING -j nova-compute-PREROUTING ',
|
||||
'-A OUTPUT -j nova-compute-OUTPUT ',
|
||||
'-A POSTROUTING -j nova-compute-POSTROUTING ',
|
||||
'-A POSTROUTING -j nova-postrouting-bottom ',
|
||||
'-A nova-postrouting-bottom -j nova-compute-SNATTING ',
|
||||
'-A nova-compute-SNATTING -j nova-compute-floating-ip-snat ',
|
||||
'COMMIT',
|
||||
'# Completed on Fri Feb 18 15:17:05 2011']
|
||||
|
||||
def setUp(self):
|
||||
super(IptablesManagerTestCase, self).setUp()
|
||||
self.manager = linux_net.IptablesManager()
|
||||
|
||||
def test_filter_rules_are_wrapped(self):
|
||||
current_lines = self.sample_filter.split('\n')
|
||||
current_lines = self.sample_filter
|
||||
|
||||
table = self.manager.ipv4['filter']
|
||||
table.add_rule('FORWARD', '-s 1.2.3.4/5 -j DROP')
|
||||
@@ -104,7 +105,7 @@ COMMIT
|
||||
'-s 1.2.3.4/5 -j DROP' not in new_lines)
|
||||
|
||||
def test_nat_rules(self):
|
||||
current_lines = self.sample_nat.split('\n')
|
||||
current_lines = self.sample_nat
|
||||
new_lines = self.manager._modify_rules(current_lines,
|
||||
self.manager.ipv4['nat'])
|
||||
|
||||
@@ -139,7 +140,7 @@ COMMIT
|
||||
"Built-in chain %s not wrapped" % (chain,))
|
||||
|
||||
def test_filter_rules(self):
|
||||
current_lines = self.sample_filter.split('\n')
|
||||
current_lines = self.sample_filter
|
||||
new_lines = self.manager._modify_rules(current_lines,
|
||||
self.manager.ipv4['filter'])
|
||||
|
||||
|
||||
Reference in New Issue
Block a user