tests: add test-ipv6-p2p for the server-side IPv6 address

Verifies that with a per-user /127 network the client is leased
network + 1 and the server takes the network address, that an explicit
IPv6 address equal to the server's /127 address is rejected, and that on
a wider network network + 1 is now leasable while the server takes the
network address. Replaces the p2p-net test, which could not connect
(ns.sh was not sourced) and had no occtl socket configured.

Relates: #714

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
This commit is contained in:
Nikos Mavrogiannopoulos
2026-09-29 22:12:55 +02:00
parent 3206e11665
commit 67ae4d3ace
6 changed files with 172 additions and 1 deletions
+28
View File
@@ -0,0 +1,28 @@
# Used by test-ipv6-p2p; the per-user files in user-config-ipv6-p2p/
# override ipv6-network to exercise /127 point-to-point networks.
auth = "plain[@SRCDIR@/data/test1.passwd]"
isolate-workers = @ISOLATE_WORKERS@
use-dbus = no
max-clients = 16
max-same-clients = 2
tcp-port = @PORT@
udp-port = @PORT@
keepalive = 32400
dpd = 440
try-mtu-discovery = false
server-cert = @SRCDIR@/certs/server-cert.pem
server-key = @SRCDIR@/certs/server-key.pem
tls-priorities = "PERFORMANCE:%SERVER_PRECEDENCE:%COMPAT"
auth-timeout = 40
pid-file = /var/run/ocserv.pid
socket-file = /var/run/ocserv-socket
run-as-user = nobody
run-as-group = daemon
device = vpns
default-domain = example.com
ipv4-network = @VPNNET@
ipv6-network = @VPNNET6@
ping-leases = false
config-per-user = @CONFIG_PER_USER_DIR@/
occtl-socket-file = @OCCTL_SOCKET@
use-occtl = true
+1
View File
@@ -0,0 +1 @@
ipv6-network = @VPNNET6_BASE@0/127
+2
View File
@@ -0,0 +1,2 @@
ipv6-network = @VPNNET6_BASE@2/127
explicit-ipv6 = @VPNNET6_BASE@2
+2
View File
@@ -0,0 +1,2 @@
ipv6-network = @VPNNET6B@
explicit-ipv6 = @VPNNET6B_BASE@1
+2 -1
View File
@@ -301,7 +301,8 @@ if get_option('root-tests')
'haproxy-connect', 'test-iroute', 'test-multi-cookie',
'test-pass-script', 'idle-timeout', 'idle-timeout-icmpv6', 'test-year-2038',
'test-cookie-timeout', 'test-cookie-timeout-2',
'test-explicit-ip', 'test-ipv4-p2p', 'test-cookie-invalidation',
'test-explicit-ip', 'test-ipv4-p2p', 'test-ipv6-p2p',
'test-cookie-invalidation',
'test-user-config', 'test-append-routes', 'test-ban',
'multiple-routes', 'json', 'test-udp-listen-host',
'test-max-same-1', 'test-vhost-udp-port-inheritance',
+137
View File
@@ -0,0 +1,137 @@
#!/bin/bash
#
# Copyright (C) 2026 Nikos Mavrogiannopoulos
#
# This file is part of ocserv.
#
# ocserv is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published by the
# Free Software Foundation; either version 2 of the License, or (at
# your option) any later version.
#
# ocserv is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
# General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program. If not, see <https://www.gnu.org/licenses/>.
# Tests that the server side of the IPv6 tunnel takes the network address:
# on a /127 point-to-point network (RFC 6164) the client is leased the
# other address, and an explicit IP equal to the network address is
# rejected while network + 1 is usable. See REQ-MAIN-NET-006.
#
# The server runs in its own network namespace (ns.sh) because the host
# namespace of CI containers may have IPv6 disabled, which makes setting
# the tun device's IPv6 address fail and the session fall back to IPv4.
SERV="${SERV:-../src/ocserv}"
srcdir=${srcdir:-.}
TMPFILE=outfile.$$
OCCTL_SOCKET=./occtl-ipv6-p2p-$$.socket
SERVERCERT=pin-sha256:xp3scfzy3rOQsv9NcOve/8YVVv+pHr4qNCXEXrNl5s8=
. `dirname $0`/common.sh
. `dirname $0`/random-net.sh
# a second, wider network for the explicit network + 1 case
alloc_vpnnet6 VPNNET6B
eval "${GETPORT}"
function finish {
set +e
test -n "${CPID}" && kill ${CPID} >/dev/null 2>&1
test -n "${PID}" && kill ${PID} >/dev/null 2>&1
rm -f ${TMPFILE} ${CONFIG}
rm -rf ${CONFIG_PER_USER_DIR}
}
. `dirname $0`/ns.sh
# connect <user>: on success leaves the client running as $CPID with its
# verbose output in $TMPFILE
connect()
{
user=$1
COOKIE=''
eval `echo "$user" | ${CMDNS1} $OPENCONNECT -q $ADDRESS:$PORT -u $user --servercert=$SERVERCERT --authenticate`
if [ -z "$COOKIE" ];then
return 1
fi
rm -f $TMPFILE
echo "$user" | ${CMDNS1} $OPENCONNECT -v $ADDRESS:$PORT -u $user -C "$COOKIE" --servercert=$SERVERCERT --script=/bin/true >$TMPFILE 2>&1 &
CPID=$!
sleep 3
if ! grep "Established DTLS" $TMPFILE >/dev/null 2>&1;then
kill $CPID 2>/dev/null
return 1
fi
return 0
}
# check_header <header> <expected value>
check_header()
{
got=`grep "$1:" $TMPFILE | head -1 | sed 's/.*'"$1"': *//' | tr -d '\r'`
if test "$got" != "$2";then
kill $CPID
fail $PID "FAIL: expected $1: $2, got '$got'"
fi
}
# check_server_ip <user> <expected server address>
check_server_ip()
{
got=`${OCCTL} -s ${OCCTL_SOCKET} show user $1 2>&1 | grep "P-t-P IPv6:" | head -1 | sed 's/.*P-t-P IPv6: *//' | awk '{print $1}'`
if test "$got" != "$2";then
kill $CPID
fail $PID "FAIL: expected P-t-P IPv6: $2, got '$got'"
fi
}
echo "Testing the server side IPv6 address and /127 point-to-point networks... "
update_config_dir user-config-ipv6-p2p
update_config test-ipv6-p2p.config
${CMDNS2} ${SERV} -d 1 -f -c "${CONFIG}" & PID=$!
wait_server $PID
echo -n "Connecting with a /127 network... "
connect test
if test $? != 0;then
cat $TMPFILE
fail $PID "FAIL: expected a lease from ${VPNNET6_BASE}0/127, got no connection"
fi
check_header X-CSTP-Address-IP6 ${VPNNET6_BASE}1/128
check_server_ip test ${VPNNET6_ADDR}
kill $CPID
echo ok
echo -n "Connecting with the server address of a /127 as explicit IP... "
connect test2
if test $? = 0;then
kill $CPID
fail $PID "FAIL: expected rejection of ${VPNNET6_BASE}2 (server address), got a connection"
fi
echo ok
echo -n "Connecting with network + 1 of a /112 as explicit IP... "
connect test3
if test $? != 0;then
cat $TMPFILE
fail $PID "FAIL: expected a connection with ${VPNNET6B_BASE}1, got none"
fi
check_header X-CSTP-Address-IP6 ${VPNNET6B_BASE}1/128
check_server_ip test3 ${VPNNET6B_ADDR}
kill $CPID
echo ok
kill $PID
wait
exit 0