Repository navigation
Feat/tests - #42
Merged
Merged
Feat/tests#42
Conversation
added 24 commits
October 11, 2026 00:44
Added configurable process responses and disposal assertions; covered mutation/listing failures and flush ordering. Preserve stderr and reject failed partial dumps. HasChain now suppresses only recognizable missing-chain errors. Validation: Fast suite: 395 passed, 15 skipped; compiler required DOTNET_PROCESSOR_COUNT=2 and a 1 GiB GC limit on this host.
Exercise the production restore commit with configurable process responses, exact input and disposal assertions. Preserve stderr for every exit code, attach failed-rule context, reject failed save output, and accept patched help on stdout or stderr. Validation: Fast suite: 407 passed, 15 skipped.
Clear successful restore transactions, prevent immediate replace/add-chain/raw-add commands from being queued, preserve flush-before-delete, and remove the throwing managed finalizer. Add reuse, rollback, failure recovery, nested-start, disposal, and IPv6 fallback tests. Validation: Fast suite: 410 passed, 15 skipped.
Normalize syntactic single quotes without corrupting apostrophes inside double-quoted payloads. Reject unterminated quotes and propagate restore stream failures. Cover Unicode, escaped quotes, backslashes, empty arguments, per-table framing, duplicate chains, and writes failing at each boundary. Validation: Fast suite passed; native restore syntax compatibility remains covered by the separate integration work.
Add direct whole-ruleset orchestration tests for multi-table creation, references, selective deletion, no-op updates, bounded retries, and original error preservation. Rebuild pending chain state on every attempt, reject negative retry budgets, and roll back commit failures without masking errors. Validation: Fast suite passed. Native ordered-commit ownership is validated in plan 15.
Protect rules against replacement as well as deletion, materialize desired sequences once, and replace at the actual current-chain position with model rollback on command failure. Test protected rules at every position through both binary and restore clients, convergence, empty desired rules, duplicate rules, and custom equality. Validation: Fast suite passed.
Execute real ipset restore and transaction methods with process fakes. Correct inverted restore success and missing create/timeout serialization, reject failed save output, add explicit rollback and nested-start protection, and clear transaction buffers even after failure. Cover immediate operation errors and recovery. Validation: Fast suite passed.
Cover all ipset sync modes with existing/missing sets and explicit deletion policies. Preserve entries during SetOnly replacement, carry bucket/init metadata, detect temporary-name collisions, reject incompatible family/type swaps before mutation, and discard queued transactions on failure. Validation: Fast suite passed. Kernel swap compatibility is exercised only on a disposable Linux host.
Make entry-key hashing agree with equality by excluding timeout and including the second address. Use the key comparer for parsed sets, add entries only after parsing completes, and implement full entry hashing. Test hash-set/dictionary lookup, deduplication, timeout updates, tuple distinctions, and constructor/parser parity. Validation: Fast suite passed.
Add set and entry round-trip metadata tests and invalid-input atomicity tests. Validate tuple arity, required option values and counter text; reject extra entry tokens, preserve initval and timeout serialization, and explicitly test rejection of unsupported MAC set types rather than adding unsupported type flags. Validation: Fast suite passed. Packet/byte counters remain intentionally observational and are not serialized as key data.
Validate save framing and counter syntax, distinguish incomplete dumps from valid empty tables, select the requested table from multi-table input, and apply ignoreErrors consistently to counter-prefixed and plain rules. Assert CRLF handling, exact rule order, large counters, and recovery of later valid rules. Validation: Fast suite passed. Chain policy/counters remain outside the existing model.
Add deterministic tokenization and invalid-command theories, preserving empty quoted arguments, whitespace and escaped payloads. Report missing option values, reject malformed offsets and dangling/repeated negation, accept optional insert positions, and retain the deliberate unknown-module polyfill contract. Validation: Fast suite passed.
Add IPv6 core/TCP/UDP and NAT round trips with independent address assertions, IPv6 save parsing, executable selection and inet6 tuple synchronization. Reject mismatched core address families. Fix CIDR lookup losing the second tuple address, which caused identical sets to delete and re-add entries. Validation: Fast suite passed; no native dependency required.
Add separately parameterized IPv4/IPv6 native edit-and-commit tests with independent save/counter readback and an IPv6 ABI-specific incompatible-revision test. Probe family prerequisites and report missing kernel tables explicitly rather than entering unsupported native paths. Validation: Fast suite passed. Isolated full run: IPv4 passed; two IPv6 cases skipped because this host lacks ip6_tables. An initial constructor-failure crash is addressed in plan 15.
Fix native table-init errors long-jumping without an active recovery frame, constructor/refcount cleanup, rejected-family finalization, and duplicate/omitted ordered commits. Bound BPF formatting and release allocations on all failures. Add native construction, disposal, rollback/reuse, commit-order and BPF buffer tests. Validation: Fast suite passed. Isolated native lifecycle/family tests passed where supported; IPv6 kernel-dependent cases skip because ip6_tables is absent.
Correct conntrack native cleanup signatures, Linux family mapping, independent dump buffers, shared-state locking, and failure cleanup. Reject malformed extraction/restore lengths. Add deterministic native-boundary tests and seeded UDP filter assertions. Validation: Fast suite: 526 passed, 26 skipped. Isolated Linux conntrack selection: 18 passed, including seeded flow and native dump/extraction.
Unify accounting XML parsing and correct swapped byte/packet counters. Preserve unsigned counters, escape object names, and report malformed records and command failures consistently. Add Get/List/reset/existence and process-disposal coverage. Validation: Fast suite: 537 passed, 27 skipped, zero failures.
Replace route smoke checks with field/export assertions; cover table selection, empty and malformed listings, flags and command failures. Preserve existing table output, avoid null table injection, validate rule priorities, and reject nonzero command exits. Validation: Fast suite: 551 passed, 27 skipped, zero failures.
Add reconciliation set-difference, duplicate, idempotency and failure-order tests plus object identity and clone ownership coverage. Snapshot and deduplicate current objects before mutation; compare and hash object fields independently of dictionary insertion order. Validation: Fast suite: 562 passed, 27 skipped, zero failures.
Establish CIDR containment/count/rebase boundaries for both families, reject malformed prefixes and ranges, and preserve explicit zero-address prefixes. Keep generic uint ranges distinct from endpoint port limits; support bracketed IPv6 single endpoints while preserving the legacy invalid-input fallback. Validation: Fast suite: 596 passed, 27 skipped, zero failures.
Cover multiport boundaries, TCP/UDP source/destination ports, goto targets, custom mangle base rules, ipset output and empty nested generators. Merge overlapping/duplicate ranges correctly, validate callbacks, support omitted jump setters and remove empty nested chains without dangling jumps; fix empty-group logging. Validation: Fast suite: 603 passed, 27 skipped, zero failures.
Preserve counters when deep-cloning rulesets, including disabled counter values. Verify IPv4/IPv6 clone equality, ordered duplicates, multiple tables, empty chains, comments, system references and independent module/rule/chain mutations. Validation: Fast suite: 605 passed, 27 skipped, zero failures.
Cover iptables and SYNPROXY version thresholds with fixed process responses. Parse IPv4/IPv6 binary banners and plain, distro and custom kernel releases; report process failures and reject malformed or overflowing versions. Document that version eligibility does not establish module availability. Validation: Fast suite: 627 passed, 27 skipped, zero failures.
Add a stubbed runner harness for modes, filters, backend restoration, failures and runtime environment propagation. Reject invalid modes, clear inherited system-test skips in full mode and preserve runtime limits through sudo. Restore executable entry points, align CI with stable/opt-in kernel policy, and require native TRX coverage with explicit skip reporting. Update the plan index with final validation. Validation: Runner harness: 17 cases passed; native-report checker: 4 tests passed; fast: 627 passed/27 skipped; isolated stable full: 645 passed/5 skipped. Two full skips are unavailable IPv6 kernel tests; three are preexisting disabled tests. CI checker correctly rejects the missing IPv6 coverage. Shell syntax, YAML parsing and whitespace checks passed.
Owner
Author
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3bd4433472
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
added 3 commits
October 11, 2026 02:09
Recognize the nfacct get ENOENT diagnostic and return null/false for missing accounting objects. Keep permission, socket, process-start, partial-output and non-lookup failures visible. Add regression coverage for lookup-then-create and reset lookups. Validation: reproduced both missing-object failures before the fix; all 22 NfAcctTests now pass via test.sh --fast with a focused filter.
Preserve the original IPv6 ScopeId when constructing a rebased address. Cover scoped host and subnet prefixes, unscoped IPv6, and IPv4 without changing the input address. Validation: reproduced scope loss in the /128 and /64 tests before the fix. Full fast suite passes: 650 passed, 27 skipped, zero failures.
Address PR #42 review comment 4239937010 by comparing nonzero desired InitVal values during set configuration comparison. Keep zero unspecified to avoid replacing sets with kernel-selected seeds. Add regression tests for mismatched, matching and unspecified seeds, replacement payloads, and repeat-sync idempotency. Validation: reproduced four failures before the fix. Full fast suite: 660 passed, 27 skipped, zero failures.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.