Skip to content

Commit c92fc31

Browse files
authored
Merge pull request #422 from Limmen/snort_manager
add Snort manager
2 parents f9d1af8 + 25a394b commit c92fc31

File tree

2 files changed

+164
-3
lines changed

2 files changed

+164
-3
lines changed

emulation-system/tests/test_start_host_manager.py

+2-3
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,6 @@
1-
from typing import List, Any, Generator
21
import pytest
3-
import logging
42
import docker
3+
import logging
54
import grpc
65
from unittest.mock import MagicMock
76
from docker.types import IPAMConfig, IPAMPool
@@ -43,7 +42,7 @@ def network(docker_client) -> Generator:
4342
network.remove()
4443

4544

46-
def get_derived_containers(docker_client, excluded_tag="blank") -> List[Any]:
45+
def get_derived_containers(docker_client, excluded_tag="blank") -> None:
4746
"""
4847
Get all the containers except the blank ones
4948
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,162 @@
1+
from typing import List, Any, Generator
2+
import pytest
3+
import docker
4+
import logging
5+
import grpc
6+
from unittest.mock import MagicMock
7+
from docker.types import IPAMConfig, IPAMPool
8+
import time
9+
from csle_common.dao.emulation_config.emulation_env_config import EmulationEnvConfig
10+
from csle_common.util.emulation_util import EmulationUtil
11+
import csle_common.constants.constants as constants
12+
from csle_common.controllers.snort_ids_controller import SnortIDSController
13+
import csle_collector.snort_ids_manager.snort_ids_manager_pb2_grpc
14+
import csle_collector.snort_ids_manager.snort_ids_manager_pb2
15+
from csle_common.metastore.metastore_facade import MetastoreFacade
16+
from IPython.lib.editorhooks import emacs
17+
18+
19+
@pytest.fixture(scope="module")
20+
def docker_client() -> None:
21+
"""
22+
Initialize and Provide a Docker client instance for the test
23+
24+
:return: None
25+
"""
26+
return docker.from_env()
27+
28+
29+
@pytest.fixture(scope="module")
30+
def network(docker_client) -> None:
31+
"""
32+
Create a custom network with a specific subnet
33+
34+
:param docker_client: docker_client
35+
:yield: network
36+
37+
:return: None
38+
"""
39+
subnet = "15.15.15.0/24"
40+
ipam_pool = IPAMPool(subnet=subnet)
41+
ipam_config = IPAMConfig(pool_configs=[ipam_pool])
42+
logging.info(f"Creating virtual network with subnet: {subnet}")
43+
network = docker_client.networks.create("test_network", driver="bridge", ipam=ipam_config)
44+
yield network
45+
network.remove()
46+
47+
48+
def get_derived_containers(docker_client, excluded_tag=constants.CONTAINER_IMAGES.BLANK) -> List[Any]:
49+
"""
50+
Get all the containers except the blank ones
51+
52+
:param docker_client: docker_client
53+
54+
:return: None
55+
"""
56+
# Get all images except those with the excluded tag
57+
config = MetastoreFacade.get_config(id=1)
58+
match_tag = config.version
59+
all_images = docker_client.images.list()
60+
derived_images = [
61+
image
62+
for image in all_images
63+
if any(match_tag in tag for tag in image.tags)
64+
and all(constants.CONTAINER_IMAGES.BASE not in tag for tag in image.tags)
65+
and all(excluded_tag not in tag for tag in image.tags)
66+
]
67+
return derived_images
68+
69+
70+
@pytest.fixture(scope="module", params=get_derived_containers(docker.from_env()))
71+
def container_setup(request, docker_client, network) -> Generator:
72+
"""
73+
Starts a Docker container before running tests and ensures its stopped and removed after tests complete.
74+
75+
:param request: request
76+
:param docker_client: docker_client
77+
:yield: container
78+
79+
:return: None
80+
"""
81+
# Create and start each derived container
82+
image = request.param
83+
container = docker_client.containers.create(
84+
image.tags[0],
85+
command="sh -c 'while true; do sleep 3600; done'",
86+
detach=True,
87+
)
88+
network.connect(container)
89+
container.start()
90+
yield container
91+
logging.info(f"Stopping and removing container: {container.id} with image: {container.image.tags}")
92+
container.stop()
93+
container.remove()
94+
95+
96+
def test_start_snort_manager(container_setup) -> None:
97+
"""
98+
Start snort_manager in a container
99+
100+
:param container_setup: container_setup
101+
102+
:return: None
103+
"""
104+
failed_containers = []
105+
containers_info = []
106+
container_setup.reload()
107+
assert container_setup.status == "running"
108+
# Mock emulation_env_config
109+
emulation_env_config = MagicMock(spec=EmulationEnvConfig)
110+
emulation_env_config.get_connection.return_value = MagicMock()
111+
emulation_env_config.snort_ids_manager_config = MagicMock()
112+
emulation_env_config.snort_ids_manager_config.snort_ids_manager_port = 50051
113+
emulation_env_config.snort_ids_manager_config.snort_ids_manager_log_dir = "/var/log/snort"
114+
emulation_env_config.snort_ids_manager_config.snort_ids_manager_log_file = "snort.log"
115+
emulation_env_config.snort_ids_manager_config.snort_ids_manager_max_workers = 4
116+
117+
ip = container_setup.attrs[constants.DOCKER.NETWORK_SETTINGS][constants.DOCKER.IP_ADDRESS_INFO]
118+
port = emulation_env_config.snort_ids_manager_config.snort_ids_manager_port
119+
try:
120+
# Start host_manager command
121+
cmd = (
122+
f"/root/miniconda3/bin/python3 /snort_ids_manager.py "
123+
f"--port {emulation_env_config.snort_ids_manager_config.snort_ids_manager_port} "
124+
f"--logdir {emulation_env_config.snort_ids_manager_config.snort_ids_manager_log_dir} "
125+
f"--logfile {emulation_env_config.snort_ids_manager_config.snort_ids_manager_log_file} "
126+
f"--maxworkers {emulation_env_config.snort_ids_manager_config.snort_ids_manager_max_workers}"
127+
)
128+
# Run cmd in the container
129+
logging.info(f"Starting snort manager in container: {container_setup.id} "
130+
f"with image: {container_setup.image.tags}")
131+
container_setup.exec_run(cmd, detach=True)
132+
# Check if snort_manager starts
133+
cmd = (
134+
f"sh -c '{constants.COMMANDS.PS_AUX} | {constants.COMMANDS.GREP} "
135+
f"{constants.COMMANDS.SPACE_DELIM}{constants.TRAFFIC_COMMANDS.SNORT_IDS_MANAGER_FILE_NAME}'"
136+
)
137+
logging.info(f"Verifying that snort manager is running in container: {container_setup.id} "
138+
f"with image: {container_setup.image.tags}")
139+
result = container_setup.exec_run(cmd)
140+
output = result.output.decode("utf-8")
141+
assert constants.COMMANDS.SEARCH_SNORT_IDS_MANAGER in output, "Snort manager is not running in the container"
142+
time.sleep(5)
143+
# Call grpc
144+
with grpc.insecure_channel(f"{ip}:{port}", options=constants.GRPC_SERVERS.GRPC_OPTIONS) as channel:
145+
stub = csle_collector.snort_ids_manager.snort_ids_manager_pb2_grpc.SnortIdsManagerStub(channel)
146+
status = csle_collector.snort_ids_manager.query_snort_ids_manager.get_snort_ids_monitor_status(stub=stub)
147+
assert status
148+
except Exception as e:
149+
print(f"Error occurred in container {container_setup.name}: {e}")
150+
failed_containers.append(container_setup.name)
151+
containers_info.append(
152+
{
153+
"container_status": container_setup.status,
154+
"container_image": container_setup.image.tags,
155+
"name": container_setup.name,
156+
"error": str(e),
157+
}
158+
)
159+
if failed_containers:
160+
logging.info("Containers that failed to start the snort manager:")
161+
logging.info(containers_info)
162+
assert not failed_containers, f"T{failed_containers} failed"

0 commit comments

Comments
 (0)