From d14a2126152231bfe77fad807eb11fbc044f6d93 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Thu, 26 Dec 2024 22:04:37 +0100 Subject: [PATCH] nixos/tests/opensnitch: test all possible values for ProcMonitorMethod --- nixos/tests/opensnitch.nix | 107 +++++++++++++++++++++---------------- 1 file changed, 62 insertions(+), 45 deletions(-) diff --git a/nixos/tests/opensnitch.nix b/nixos/tests/opensnitch.nix index 4781cc485dbe..dbb536e9a769 100644 --- a/nixos/tests/opensnitch.nix +++ b/nixos/tests/opensnitch.nix @@ -1,5 +1,13 @@ import ./make-test-python.nix ( - { pkgs, ... }: + { pkgs, lib, ... }: + let + monitorMethods = [ + "ebpf" + "proc" + "ftrace" + "audit" + ]; + in { name = "opensnitch"; @@ -7,10 +15,9 @@ import ./make-test-python.nix ( maintainers = [ onny ]; }; - nodes = { - server = - { ... }: - { + nodes = + { + server = { networking.firewall.allowedTCPPorts = [ 80 ]; services.caddy = { enable = true; @@ -19,50 +26,60 @@ import ./make-test-python.nix ( ''; }; }; - - clientBlocked = - { ... }: - { - services.opensnitch = { - enable = true; - settings.DefaultAction = "deny"; - }; - }; - - clientAllowed = - { ... }: - { - services.opensnitch = { - enable = true; - settings.DefaultAction = "deny"; - rules = { - curl = { - name = "curl"; - enabled = true; - action = "allow"; - duration = "always"; - operator = { - type = "simple"; - sensitive = false; - operand = "process.path"; - data = "${pkgs.curl}/bin/curl"; + } + // (lib.listToAttrs ( + map ( + m: + lib.nameValuePair "client_blocked_${m}" { + services.opensnitch = { + enable = true; + settings.DefaultAction = "deny"; + settings.ProcMonitorMethod = m; + }; + } + ) monitorMethods + )) + // (lib.listToAttrs ( + map ( + m: + lib.nameValuePair "client_allowed_${m}" { + services.opensnitch = { + enable = true; + settings.DefaultAction = "deny"; + settings.ProcMonitorMethod = m; + rules = { + curl = { + name = "curl"; + enabled = true; + action = "allow"; + duration = "always"; + operator = { + type = "simple"; + sensitive = false; + operand = "process.path"; + data = "${pkgs.curl}/bin/curl"; + }; }; }; }; - }; - }; - }; + } + ) monitorMethods + )); - testScript = '' - start_all() - server.wait_for_unit("caddy.service") - server.wait_for_open_port(80) + testScript = + '' + start_all() + server.wait_for_unit("caddy.service") + server.wait_for_open_port(80) + '' + + lib.concatLines ( + map (m: '' + client_blocked_${m}.wait_for_unit("opensnitchd.service") + client_blocked_${m}.fail("curl http://server") - clientBlocked.wait_for_unit("opensnitchd.service") - clientBlocked.fail("curl http://server") - - clientAllowed.wait_for_unit("opensnitchd.service") - clientAllowed.succeed("curl http://server") - ''; + client_allowed_${m}.wait_for_unit("opensnitchd.service") + client_allowed_${m}.succeed("curl http://server") + '') monitorMethods + ); } )