Files
ihasvpn/internal/netcfg/nft_test.go
T
jcoffey-dev 02e7993c87 Rename the project to ihasvpn
WGX shares its name with several other WireGuard tools, so the project
becomes ihasvpn, alongside ihasmail.

- Module github.com/Coffey-Labs/ihasvpn, command cmd/ihasvpn, image
  ghcr.io/coffey-labs/ihasvpn.
- Environment variables move from WGX_* to IHASVPN_*. The default database
  is ihasvpn.db, the nftables table is `ihasvpn`, metrics are ihasvpn_*, and
  the session cookie and theme key are renamed, so existing sessions end.
- The mark is the ihasmail cat peeking over the edge of a shield, drawn as
  a vector. docs/brand/generate.py builds the mark, mono mark, wordmarks,
  social card, favicons and app icons from that one drawing.
- The console takes ihasmail's palette: the ihasmail.org teal-navy for dark,
  its contrast-checked light tiers with the site's light accent, received
  traffic in the cat's orange and sent in teal. The wordmark weight and
  font stack follow ihasmail.org.
- Detail values wrap at spaces before breaking inside an address, so an
  IPv6 tunnel address no longer splits mid-number.
- The README history note about the earlier WGX installer is gone with the
  name it explained. Screenshots retaken.
2026-09-12 23:48:36 -07:00

54 lines
1.3 KiB
Go

package netcfg
import (
"net/netip"
"strings"
"testing"
)
func TestRuleset(t *testing.T) {
r := Rules{
Iface: "wg0",
Egress: "eth0",
ListenPort: 51820,
Subnets: []netip.Prefix{netip.MustParsePrefix("10.8.0.0/24"), netip.MustParsePrefix("fd42::/64")},
PeerIsolation: true,
ClampMSS: true,
}
out := Ruleset(r)
for _, want := range []string{
"table inet ihasvpn {",
"udp dport 51820 accept",
`iifname "wg0" oifname "wg0" drop`,
`tcp option maxseg size set rt mtu`,
`ip saddr 10.8.0.0/24 oifname "eth0" masquerade`,
`ip6 saddr fd42::/64 oifname "eth0" masquerade`,
`oifname "wg0" ct state related,established accept`,
} {
if !strings.Contains(out, want) {
t.Errorf("ruleset missing %q:\n%s", want, out)
}
}
// Without an egress, masquerade on anything that is not the tunnel.
r.Egress = ""
r.PeerIsolation = false
out = Ruleset(r)
if !strings.Contains(out, `oifname != "wg0" masquerade`) {
t.Errorf("expected wildcard masquerade:\n%s", out)
}
if strings.Contains(out, "peer isolation") {
t.Error("isolation rule present when off")
}
}
func TestWanted(t *testing.T) {
v4 := Wanted(false)
v6 := Wanted(true)
if len(v6) != len(v4)+1 {
t.Fatal("ipv6 forwarding not added")
}
if v4[0].Key != "net.ipv4.ip_forward" || !v4[0].Required {
t.Fatal("ip_forward must be first and required")
}
}