Merge pull request #3679 from tomlabaude/pf_ipv6
Added support for IPv6 in pf.py for macOS
This commit is contained in:
commit
8e64ac0575
|
@ -13,9 +13,15 @@ def lookup(address, port, s):
|
|||
# Those still appear as "127.0.0.1" in the table, so we need to strip the prefix.
|
||||
address = re.sub(r"^::ffff:(?=\d+.\d+.\d+.\d+$)", "", address)
|
||||
s = s.decode()
|
||||
spec = "%s:%s" % (address, port)
|
||||
|
||||
# ALL tcp 192.168.1.13:57474 -> 23.205.82.58:443 ESTABLISHED:ESTABLISHED
|
||||
specv4 = "%s:%s" % (address, port)
|
||||
|
||||
# ALL tcp 2a01:e35:8bae:50f0:9d9b:ef0d:2de3:b733[58505] -> 2606:4700:30::681f:4ad0[443] ESTABLISHED:ESTABLISHED
|
||||
specv6 = "%s[%s]" % (address, port)
|
||||
|
||||
for i in s.split("\n"):
|
||||
if "ESTABLISHED:ESTABLISHED" in i and spec in i:
|
||||
if "ESTABLISHED:ESTABLISHED" in i and specv4 in i:
|
||||
s = i.split()
|
||||
if len(s) > 4:
|
||||
if sys.platform.startswith("freebsd"):
|
||||
|
@ -26,4 +32,11 @@ def lookup(address, port, s):
|
|||
|
||||
if len(s) == 2:
|
||||
return s[0], int(s[1])
|
||||
elif "ESTABLISHED:ESTABLISHED" in i and specv6 in i:
|
||||
s = i.split()
|
||||
if len(s) > 4:
|
||||
s = s[4].split("[")
|
||||
port = s[1].split("]")
|
||||
port = port[0]
|
||||
return s[0], int(port)
|
||||
raise RuntimeError("Could not resolve original destination.")
|
||||
|
|
|
@ -1,4 +1,10 @@
|
|||
No ALTQ support in kernel
|
||||
ALTQ related functions disabled
|
||||
ALL tcp 192.168.1.111:40001 -> 5.5.5.6:80 FIN_WAIT_2:FIN_WAIT_2
|
||||
ALL tcp 127.0.0.1:8080 <- 5.5.5.6:80 <- 192.168.1.111:40001 FIN_WAIT_2:FIN_WAIT_2
|
||||
ALL tcp 192.168.1.111:40000 -> 5.5.5.5:80 ESTABLISHED:ESTABLISHED
|
||||
ALL tcp 127.0.0.1:8080 <- 5.5.5.5:80 <- 192.168.1.111:40000 ESTABLISHED:ESTABLISHED
|
||||
ALL tcp 2a01:e35:8bae:50f0:396f:e6c7:f4f1:f3db[40002] -> 2a03:2880:f21f:c5:face:b00c::167[443] ESTABLISHED:ESTABLISHED
|
||||
ALL tcp ::1[8080] <- 2a03:2880:f21f:c5:face:b00c::167[443] <- 2a01:e35:8bae:50f0:396f:e6c7:f4f1:f3db[40002] ESTABLISHED:ESTABLISHED
|
||||
ALL tcp 2a01:e35:8bae:50f0:396f:e6c7:f4f1:f3db[40003] -> 2a03:2880:f21f:c5:face:b00c::167[443] FIN_WAIT_2:FIN_WAIT_2
|
||||
ALL tcp ::1[6970] <- 2a03:2880:f21f:c5:face:b00c::167[443] <- 2a01:e35:8bae:50f0:396f:e6c7:f4f1:f3db[40003] FIN_WAIT_2:FIN_WAIT_2
|
|
@ -19,3 +19,8 @@ class TestLookup:
|
|||
pf.lookup("192.168.1.112", 40000, d)
|
||||
with pytest.raises(Exception, match="Could not resolve original destination"):
|
||||
pf.lookup("192.168.1.111", 40001, d)
|
||||
assert pf.lookup("2a01:e35:8bae:50f0:396f:e6c7:f4f1:f3db", 40002, d) == ("2a03:2880:f21f:c5:face:b00c::167", 443)
|
||||
with pytest.raises(Exception, match="Could not resolve original destination"):
|
||||
pf.lookup("2a01:e35:8bae:50f0:396f:e6c7:f4f1:f3db", 40003, d)
|
||||
with pytest.raises(Exception, match="Could not resolve original destination"):
|
||||
pf.lookup("2a01:e35:face:face:face:face:face:face", 40003, d)
|
||||
|
|
Loading…
Reference in New Issue