test(06-14): fetchguard IANA boundary and zoned dial tests, surf edge coverage
This commit is contained in:
@@ -306,10 +306,43 @@ func withTestLoopback(srv *httptest.Server, p Policy) Policy {
|
||||
}
|
||||
|
||||
func TestDialControlRejectsZonedAndSpecialUse(t *testing.T) {
|
||||
ctl := dialControl(Policy{})
|
||||
for _, a := range []string{"[fe80::1%eth0]:443", "198.18.0.1:443"} {
|
||||
if err := ctl("tcp", a, nil); !errors.Is(err, errPrivateIP) {
|
||||
t.Errorf("%s: got %v", a, err)
|
||||
}
|
||||
probes := []string{"[fe80::1%eth0]:443", "198.18.0.1:443", "192.0.0.1:443", "240.0.0.1:443"}
|
||||
ctl := dialControl(Policy{Mode: PublicOnlyMode})
|
||||
for _, a := range probes {
|
||||
t.Run(a, func(t *testing.T) {
|
||||
err := ctl("tcp", a, nil)
|
||||
if !errors.Is(err, errPrivateIP) {
|
||||
t.Fatalf("dialControl(%s) = %v, want errPrivateIP", a, err)
|
||||
}
|
||||
if got := mapTransportError(err).Reason; got != ReasonPrivateIP {
|
||||
t.Fatalf("reason = %q, want %q", got, ReasonPrivateIP)
|
||||
}
|
||||
})
|
||||
}
|
||||
if err := ctl("tcp", "8.8.8.8:443", nil); err != nil {
|
||||
t.Fatalf("public address rejected: %v", err)
|
||||
}
|
||||
if err := ctl("tcp", "[2606:4700:4700::1111]:443", nil); err != nil {
|
||||
t.Fatalf("public v6 rejected: %v", err)
|
||||
}
|
||||
if err := ctl("tcp", "no-port", nil); err == nil {
|
||||
t.Fatal("address without port accepted")
|
||||
}
|
||||
if err := ctl("tcp", "example.com:443", nil); err == nil || errors.Is(err, errPrivateIP) {
|
||||
t.Fatalf("hostname dial target: err = %v, want unparseable error", err)
|
||||
}
|
||||
if err := dialControl(Policy{skipReservedCheck: true})("tcp", "127.0.0.1:1", nil); err != nil {
|
||||
t.Fatalf("skipReservedCheck: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestFetchPublicOnlyMapsSpecialUseToPrivateIP(t *testing.T) {
|
||||
for _, u := range []string{"https://[fe80::1%25eth0]/", "https://198.18.0.1/", "https://192.0.0.1/", "https://240.0.0.1/"} {
|
||||
t.Run(u, func(t *testing.T) {
|
||||
_, err := Fetch(t.Context(), u, Policy{Mode: PublicOnlyMode, Timeout: 2 * time.Second, MaxBytes: 1024}, nil)
|
||||
if got := reasonFrom(t, err); got != ReasonPrivateIP {
|
||||
t.Fatalf("reason = %q, want %s (err %v)", got, ReasonPrivateIP, err)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user