2015-11-17 06:51:22 +01:00
|
|
|
import pytest
|
|
|
|
from mock import Mock, patch, call
|
|
|
|
import socket
|
2017-09-24 14:11:26 +02:00
|
|
|
from socket import AF_INET, AF_INET6
|
2015-11-17 06:51:22 +01:00
|
|
|
import struct
|
|
|
|
|
2015-12-15 01:40:55 +01:00
|
|
|
from sshuttle.helpers import Fatal
|
2015-11-17 06:51:22 +01:00
|
|
|
from sshuttle.methods import get_method
|
|
|
|
|
|
|
|
|
|
|
|
def test_get_supported_features():
|
|
|
|
method = get_method('nat')
|
|
|
|
features = method.get_supported_features()
|
|
|
|
assert not features.ipv6
|
|
|
|
assert not features.udp
|
2015-12-15 01:40:55 +01:00
|
|
|
assert features.dns
|
2015-11-17 06:51:22 +01:00
|
|
|
|
|
|
|
|
|
|
|
def test_get_tcp_dstip():
|
|
|
|
sock = Mock()
|
|
|
|
sock.getsockopt.return_value = struct.pack(
|
2017-09-24 14:11:26 +02:00
|
|
|
'!HHBBBB', socket.ntohs(AF_INET), 1024, 127, 0, 0, 1)
|
2015-11-17 06:51:22 +01:00
|
|
|
method = get_method('nat')
|
|
|
|
assert method.get_tcp_dstip(sock) == ('127.0.0.1', 1024)
|
|
|
|
assert sock.mock_calls == [call.getsockopt(0, 80, 16)]
|
|
|
|
|
|
|
|
|
|
|
|
def test_recv_udp():
|
|
|
|
sock = Mock()
|
|
|
|
sock.recvfrom.return_value = "11111", "127.0.0.1"
|
|
|
|
method = get_method('nat')
|
|
|
|
result = method.recv_udp(sock, 1024)
|
|
|
|
assert sock.mock_calls == [call.recvfrom(1024)]
|
|
|
|
assert result == ("127.0.0.1", None, "11111")
|
|
|
|
|
|
|
|
|
|
|
|
def test_send_udp():
|
|
|
|
sock = Mock()
|
|
|
|
method = get_method('nat')
|
|
|
|
method.send_udp(sock, None, "127.0.0.1", "22222")
|
|
|
|
assert sock.mock_calls == [call.sendto("22222", "127.0.0.1")]
|
|
|
|
|
|
|
|
|
|
|
|
def test_setup_tcp_listener():
|
|
|
|
listener = Mock()
|
|
|
|
method = get_method('nat')
|
|
|
|
method.setup_tcp_listener(listener)
|
|
|
|
assert listener.mock_calls == []
|
|
|
|
|
|
|
|
|
|
|
|
def test_setup_udp_listener():
|
|
|
|
listener = Mock()
|
|
|
|
method = get_method('nat')
|
|
|
|
method.setup_udp_listener(listener)
|
|
|
|
assert listener.mock_calls == []
|
|
|
|
|
|
|
|
|
2015-12-15 01:40:55 +01:00
|
|
|
def test_assert_features():
|
2015-11-17 06:51:22 +01:00
|
|
|
method = get_method('nat')
|
2015-12-15 01:40:55 +01:00
|
|
|
features = method.get_supported_features()
|
|
|
|
method.assert_features(features)
|
|
|
|
|
|
|
|
features.udp = True
|
|
|
|
with pytest.raises(Fatal):
|
|
|
|
method.assert_features(features)
|
|
|
|
|
|
|
|
features.ipv6 = True
|
|
|
|
with pytest.raises(Fatal):
|
|
|
|
method.assert_features(features)
|
2015-11-17 06:51:22 +01:00
|
|
|
|
|
|
|
|
|
|
|
def test_firewall_command():
|
|
|
|
method = get_method('nat')
|
|
|
|
assert not method.firewall_command("somthing")
|
|
|
|
|
|
|
|
|
|
|
|
@patch('sshuttle.methods.nat.ipt')
|
|
|
|
@patch('sshuttle.methods.nat.ipt_ttl')
|
|
|
|
@patch('sshuttle.methods.nat.ipt_chain_exists')
|
|
|
|
def test_setup_firewall(mock_ipt_chain_exists, mock_ipt_ttl, mock_ipt):
|
|
|
|
mock_ipt_chain_exists.return_value = True
|
|
|
|
method = get_method('nat')
|
|
|
|
assert method.name == 'nat'
|
|
|
|
|
|
|
|
with pytest.raises(Exception) as excinfo:
|
|
|
|
method.setup_firewall(
|
|
|
|
1024, 1026,
|
2017-09-24 14:11:26 +02:00
|
|
|
[(AF_INET6, u'2404:6800:4004:80c::33')],
|
|
|
|
AF_INET6,
|
|
|
|
[(AF_INET6, 64, False, u'2404:6800:4004:80c::', 0, 0),
|
|
|
|
(AF_INET6, 128, True, u'2404:6800:4004:80c::101f', 80, 80)],
|
2017-09-08 03:17:37 +02:00
|
|
|
True,
|
|
|
|
None)
|
2015-11-17 06:51:22 +01:00
|
|
|
assert str(excinfo.value) \
|
|
|
|
== 'Address family "AF_INET6" unsupported by nat method_name'
|
|
|
|
assert mock_ipt_chain_exists.mock_calls == []
|
|
|
|
assert mock_ipt_ttl.mock_calls == []
|
|
|
|
assert mock_ipt.mock_calls == []
|
|
|
|
|
|
|
|
with pytest.raises(Exception) as excinfo:
|
|
|
|
method.setup_firewall(
|
|
|
|
1025, 1027,
|
2017-09-24 14:11:26 +02:00
|
|
|
[(AF_INET, u'1.2.3.33')],
|
|
|
|
AF_INET,
|
|
|
|
[(AF_INET, 24, False, u'1.2.3.0', 8000, 9000),
|
|
|
|
(AF_INET, 32, True, u'1.2.3.66', 8080, 8080)],
|
2017-09-08 03:17:37 +02:00
|
|
|
True,
|
|
|
|
None)
|
2015-11-17 06:51:22 +01:00
|
|
|
assert str(excinfo.value) == 'UDP not supported by nat method_name'
|
|
|
|
assert mock_ipt_chain_exists.mock_calls == []
|
|
|
|
assert mock_ipt_ttl.mock_calls == []
|
|
|
|
assert mock_ipt.mock_calls == []
|
|
|
|
|
|
|
|
method.setup_firewall(
|
|
|
|
1025, 1027,
|
2017-09-24 14:11:26 +02:00
|
|
|
[(AF_INET, u'1.2.3.33')],
|
|
|
|
AF_INET,
|
|
|
|
[(AF_INET, 24, False, u'1.2.3.0', 8000, 9000),
|
|
|
|
(AF_INET, 32, True, u'1.2.3.66', 8080, 8080)],
|
2017-09-08 03:17:37 +02:00
|
|
|
False,
|
|
|
|
None)
|
2015-11-17 06:51:22 +01:00
|
|
|
assert mock_ipt_chain_exists.mock_calls == [
|
2017-09-24 14:11:26 +02:00
|
|
|
call(AF_INET, 'nat', 'sshuttle-1025')
|
2015-11-17 06:51:22 +01:00
|
|
|
]
|
|
|
|
assert mock_ipt_ttl.mock_calls == [
|
2017-09-24 14:11:26 +02:00
|
|
|
call(AF_INET, 'nat', '-A', 'sshuttle-1025', '-j', 'REDIRECT',
|
Adds support for tunneling specific port ranges (#144)
* Adds support for tunneling specific port ranges
This set of changes implements the ability of specifying a port or port
range for an IP or subnet to only tunnel those ports for that subnet.
Also supports excluding a port or port range for a given IP or subnet.
When, for a given subnet, there are intercepting ranges being added and
excluded, the most specific, i.e., smaller range, takes precedence. In
case of a tie the exclusion wins.
For different subnets, the most specific, i.e., largest swidth, takes
precedence independent of any eventual port ranges.
Examples:
Tunnels all traffic to the 188.0.0.0/8 subnet except those to port 443.
```
sshuttle -r <server> 188.0.0.0/8 -x 188.0.0.0/8:443
```
Only tunnels traffic to port 80 of the 188.0.0.0/8 subnet.
```
sshuttle -r <server> 188.0.0.0/8:80
```
Tunnels traffic to the 188.0.0.0/8 subnet and the port range that goes
from 80 to 89.
```
sshuttle -r <server> 188.0.0.0/8:80-89 -x 188.0.0.0/8:80-90
```
* Allow subnets to be specified with domain names
Simplifies the implementation of address parsing by using
socket.getaddrinfo(), which can handle domain resolution, IPv4 and IPv6
addresses. This was proposed and mostly implemented by @DavidBuchanan314
in #146.
Signed-off-by: David Buchanan <DavidBuchanan314@users.noreply.github.com>
Signed-off-by: João Vieira <vieira@yubo.be>
* Also use getaddrinfo for parsing listen addr:port
* Fixes tests for tunneling a port range
* Updates documentation to include port/port range
Adds some examples with subnet:port and subnet:port-port.
Also clarifies the versions of Python supported on the server while
maintaining the recommendation for Python 2.7, 3.5 or later.
Mentions support for pfSense.
* In Py2 only named arguments may follow *expression
Fixes issue in Python 2.7 where *expression may only be followed by
named arguments.
* Use right regex to extract ip4/6, mask and ports
* Tests for parse_subnetport
2017-05-07 05:18:13 +02:00
|
|
|
'--dest', u'1.2.3.0/24', '-p', 'tcp', '--dport', '8000:9000',
|
|
|
|
'--to-ports', '1025'),
|
2017-09-24 14:11:26 +02:00
|
|
|
call(AF_INET, 'nat', '-A', 'sshuttle-1025', '-j', 'REDIRECT',
|
2015-11-17 06:51:22 +01:00
|
|
|
'--dest', u'1.2.3.33/32', '-p', 'udp',
|
|
|
|
'--dport', '53', '--to-ports', '1027')
|
|
|
|
]
|
|
|
|
assert mock_ipt.mock_calls == [
|
2017-09-24 14:11:26 +02:00
|
|
|
call(AF_INET, 'nat', '-D', 'OUTPUT', '-j', 'sshuttle-1025'),
|
|
|
|
call(AF_INET, 'nat', '-D', 'PREROUTING', '-j', 'sshuttle-1025'),
|
|
|
|
call(AF_INET, 'nat', '-F', 'sshuttle-1025'),
|
|
|
|
call(AF_INET, 'nat', '-X', 'sshuttle-1025'),
|
|
|
|
call(AF_INET, 'nat', '-N', 'sshuttle-1025'),
|
|
|
|
call(AF_INET, 'nat', '-F', 'sshuttle-1025'),
|
|
|
|
call(AF_INET, 'nat', '-I', 'OUTPUT', '1', '-j', 'sshuttle-1025'),
|
|
|
|
call(AF_INET, 'nat', '-I', 'PREROUTING', '1', '-j', 'sshuttle-1025'),
|
|
|
|
call(AF_INET, 'nat', '-A', 'sshuttle-1025', '-j', 'RETURN',
|
Adds support for tunneling specific port ranges (#144)
* Adds support for tunneling specific port ranges
This set of changes implements the ability of specifying a port or port
range for an IP or subnet to only tunnel those ports for that subnet.
Also supports excluding a port or port range for a given IP or subnet.
When, for a given subnet, there are intercepting ranges being added and
excluded, the most specific, i.e., smaller range, takes precedence. In
case of a tie the exclusion wins.
For different subnets, the most specific, i.e., largest swidth, takes
precedence independent of any eventual port ranges.
Examples:
Tunnels all traffic to the 188.0.0.0/8 subnet except those to port 443.
```
sshuttle -r <server> 188.0.0.0/8 -x 188.0.0.0/8:443
```
Only tunnels traffic to port 80 of the 188.0.0.0/8 subnet.
```
sshuttle -r <server> 188.0.0.0/8:80
```
Tunnels traffic to the 188.0.0.0/8 subnet and the port range that goes
from 80 to 89.
```
sshuttle -r <server> 188.0.0.0/8:80-89 -x 188.0.0.0/8:80-90
```
* Allow subnets to be specified with domain names
Simplifies the implementation of address parsing by using
socket.getaddrinfo(), which can handle domain resolution, IPv4 and IPv6
addresses. This was proposed and mostly implemented by @DavidBuchanan314
in #146.
Signed-off-by: David Buchanan <DavidBuchanan314@users.noreply.github.com>
Signed-off-by: João Vieira <vieira@yubo.be>
* Also use getaddrinfo for parsing listen addr:port
* Fixes tests for tunneling a port range
* Updates documentation to include port/port range
Adds some examples with subnet:port and subnet:port-port.
Also clarifies the versions of Python supported on the server while
maintaining the recommendation for Python 2.7, 3.5 or later.
Mentions support for pfSense.
* In Py2 only named arguments may follow *expression
Fixes issue in Python 2.7 where *expression may only be followed by
named arguments.
* Use right regex to extract ip4/6, mask and ports
* Tests for parse_subnetport
2017-05-07 05:18:13 +02:00
|
|
|
'--dest', u'1.2.3.66/32', '-p', 'tcp', '--dport', '8080:8080')
|
2015-11-17 06:51:22 +01:00
|
|
|
]
|
|
|
|
mock_ipt_chain_exists.reset_mock()
|
|
|
|
mock_ipt_ttl.reset_mock()
|
|
|
|
mock_ipt.reset_mock()
|
|
|
|
|
2017-09-24 14:11:26 +02:00
|
|
|
method.restore_firewall(1025, AF_INET, False, None)
|
2015-11-17 06:51:22 +01:00
|
|
|
assert mock_ipt_chain_exists.mock_calls == [
|
2017-09-24 14:11:26 +02:00
|
|
|
call(AF_INET, 'nat', 'sshuttle-1025')
|
2015-11-17 06:51:22 +01:00
|
|
|
]
|
|
|
|
assert mock_ipt_ttl.mock_calls == []
|
|
|
|
assert mock_ipt.mock_calls == [
|
2017-09-24 14:11:26 +02:00
|
|
|
call(AF_INET, 'nat', '-D', 'OUTPUT', '-j', 'sshuttle-1025'),
|
|
|
|
call(AF_INET, 'nat', '-D', 'PREROUTING', '-j', 'sshuttle-1025'),
|
|
|
|
call(AF_INET, 'nat', '-F', 'sshuttle-1025'),
|
|
|
|
call(AF_INET, 'nat', '-X', 'sshuttle-1025')
|
2015-11-17 06:51:22 +01:00
|
|
|
]
|
|
|
|
mock_ipt_chain_exists.reset_mock()
|
|
|
|
mock_ipt_ttl.reset_mock()
|
|
|
|
mock_ipt.reset_mock()
|