Remove tcp source port 179 rule due to caclmgrd's change #5186
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description of PR
Summary:
Fixes # (issue)
caclmgrd has been changed in PR:
sonic-net/sonic-buildimage#9827
It removed the rules for tcp source port 179 for security.
We have to remove these expected rules for tcp source port 179 in function
generate_expected_rules()
as well.Signed-off-by: Zhaohui Sun [email protected]
Type of change
Back port request
Approach
What is the motivation for this PR?
caclmgrd has changed recently, it blocked sonic-mgmt PR testing.
How did you do it?
Remove the expected rules below in function
generate_expected_rules()
a.iptables_rules.append("-A INPUT -p tcp -m tcp --sport 179 -j ACCEPT")
ip6tables_rules.append("-A INPUT -p tcp -m tcp --sport 179 -j ACCEPT")
How did you verify/test it?
run
tests/cacl/test_cacl_application.py::test_cacl_application
Any platform specific information?
Supported testbed topology if it's a new test case?
Documentation