aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rwxr-xr-xgcov.sh44
-rw-r--r--src/firejail/netfilter.c2
-rwxr-xr-xtest/network/net_netfilter.exp22
-rwxr-xr-xtest/network/network.sh4
4 files changed, 46 insertions, 26 deletions
diff --git a/gcov.sh b/gcov.sh
index 0f2808ace..ef95b44b0 100755
--- a/gcov.sh
+++ b/gcov.sh
@@ -21,29 +21,29 @@ rm -fr gcov-dir gcov-file
21firejail --version 21firejail --version
22gcov_generate 22gcov_generate
23 23
24make test-firecfg | grep TESTING 24#make test-firecfg | grep TESTING
25gcov_generate 25#gcov_generate
26make test-apparmor | grep TESTING 26#make test-apparmor | grep TESTING
27gcov_generate 27#gcov_generate
28make test-network | grep TESTING 28make test-network | grep TESTING
29gcov_generate 29gcov_generate
30make test-appimage | grep TESTING 30#make test-appimage | grep TESTING
31gcov_generate 31#gcov_generate
32make test-chroot | grep TESTING 32#make test-chroot | grep TESTING
33gcov_generate 33#gcov_generate
34make test-sysutils | grep TESTING 34#make test-sysutils | grep TESTING
35gcov_generate 35#gcov_generate
36make test-private-etc | grep TESTING 36#make test-private-etc | grep TESTING
37gcov_generate 37#gcov_generate
38make test-profiles | grep TESTING 38#make test-profiles | grep TESTING
39gcov_generate 39#gcov_generate
40make test-fcopy | grep TESTING 40#make test-fcopy | grep TESTING
41gcov_generate 41#gcov_generate
42make test-fnetfilter | grep TESTING 42make test-fnetfilter | grep TESTING
43gcov_generate 43gcov_generate
44make test-fs | grep TESTING 44#make test-fs | grep TESTING
45gcov_generate 45#gcov_generate
46make test-utils | grep TESTING 46#make test-utils | grep TESTING
47gcov_generate 47#gcov_generate
48make test-environment | grep TESTING 48#make test-environment | grep TESTING
49gcov_generate 49#gcov_generate
diff --git a/src/firejail/netfilter.c b/src/firejail/netfilter.c
index b4deda562..32fdd6218 100644
--- a/src/firejail/netfilter.c
+++ b/src/firejail/netfilter.c
@@ -248,5 +248,5 @@ void netfilter_print(pid_t pid, int ipv6) {
248 exit(1); 248 exit(1);
249 } 249 }
250 250
251 sbox_run(SBOX_ROOT | SBOX_CAPS_NETWORK | SBOX_SECCOMP, 2, iptables, "-vL"); 251 sbox_run(SBOX_ROOT | SBOX_CAPS_NETWORK | SBOX_SECCOMP, 2, iptables, "-nvL");
252} 252}
diff --git a/test/network/net_netfilter.exp b/test/network/net_netfilter.exp
index 56480251e..ac144e19d 100755
--- a/test/network/net_netfilter.exp
+++ b/test/network/net_netfilter.exp
@@ -20,7 +20,27 @@ spawn $env(SHELL)
20send -- "firejail --netfilter.print=test\r" 20send -- "firejail --netfilter.print=test\r"
21expect { 21expect {
22 timeout {puts "TESTING ERROR 1\n";exit} 22 timeout {puts "TESTING ERROR 1\n";exit}
23 "ACCEPT all -- any any anywhere anywhere state RELATED,ESTABLISHED" 23 "ACCEPT"
24}
25expect {
26 timeout {puts "TESTING ERROR 1\n";exit}
27 "lo"
28}
29expect {
30 timeout {puts "TESTING ERROR 1\n";exit}
31 "ACCEPT"
32}
33expect {
34 timeout {puts "TESTING ERROR 1\n";exit}
35 "state RELATED,ESTABLISHED"
36}
37expect {
38 timeout {puts "TESTING ERROR 1\n";exit}
39 "ACCEPT"
40}
41expect {
42 timeout {puts "TESTING ERROR 1\n";exit}
43 "icmptype 8"
24} 44}
25 45
26after 500 46after 500
diff --git a/test/network/network.sh b/test/network/network.sh
index e062358d4..2a7de2680 100755
--- a/test/network/network.sh
+++ b/test/network/network.sh
@@ -39,8 +39,8 @@ echo "TESTING: bandwidth (net_bandwidth.exp)"
39echo "TESTING: ipv6 (ip6.exp)" 39echo "TESTING: ipv6 (ip6.exp)"
40./ip6.exp 40./ip6.exp
41 41
42#echo "TESTING: ipv6 netfilter(ip6_netfilter.exp)" 42echo "TESTING: ipv6 netfilter(ip6_netfilter.exp)"
43#./ip6_netfilter.exp 43./ip6_netfilter.exp
44 44
45sudo ip link set br0 down 45sudo ip link set br0 down
46sudo brctl delbr br0 46sudo brctl delbr br0