view stream_limit_conn.t @ 1871:1ba5108b6c24

Tests: handled unsupported PSS in sigalgs. It might happen that TLSv1.3 is disabled and PSS isn't supported as seen on Amazon Linux (LTS). Now setting sigalgs is retried without PSS on failure. Patch by Maxim Dounin.
author Sergey Kandaurov <pluknet@nginx.com>
date Tue, 23 May 2023 16:30:02 +0400
parents f3ba4c74de31
children
line wrap: on
line source

#!/usr/bin/perl

# (C) Andrey Zelenkov
# (C) Nginx, Inc.

# Tests for stream limit_conn module.

###############################################################################

use warnings;
use strict;

use Test::More;

BEGIN { use FindBin; chdir($FindBin::Bin); }

use lib 'lib';
use Test::Nginx;

###############################################################################

select STDERR; $| = 1;
select STDOUT; $| = 1;

my $t = Test::Nginx->new()->has(qw/http stream stream_limit_conn/)
	->plan(8)->write_file_expand('nginx.conf', <<'EOF');

%%TEST_GLOBALS%%

daemon off;

events {
}

stream {
    %%TEST_GLOBALS_STREAM%%

    limit_conn_zone  $binary_remote_addr  zone=zone:1m;
    limit_conn_zone  $binary_remote_addr  zone=zone2:1m;

    server {
        listen           127.0.0.1:8080;
        proxy_pass       127.0.0.1:8084;
        limit_conn       zone 1;
    }

    server {
        listen           127.0.0.1:8085;
        proxy_pass       127.0.0.1:8084;
        limit_conn       zone 5;
    }

    server {
        listen           127.0.0.1:8081;
        proxy_pass       127.0.0.1:8084;
        limit_conn       zone2 1;
    }

    server {
        listen           127.0.0.1:8082;
        proxy_pass       127.0.0.1:8080;
        limit_conn       zone2 1;
    }

    server {
        listen           127.0.0.1:8083;
        proxy_pass       127.0.0.1:8080;
        limit_conn       zone 1;
    }
}

http {
    %%TEST_GLOBALS_HTTP%%

    server {
        listen       127.0.0.1:8084;
        server_name  localhost;

        location / { }
    }
}

EOF

$t->write_file('index.html', '');
$t->run();

###############################################################################

like(get(), qr/200 OK/, 'passed');

# same and other zones

my $s = http(<<EOF, start => 1, sleep => 0.2);
GET / HTTP/1.0
EOF

ok($s, 'long connection');

is(get(), undef, 'rejected same zone');
like(get('127.0.0.1:' . port(8081)), qr/200 OK/, 'passed different zone');
like(get('127.0.0.1:' . port(8085)), qr/200 OK/, 'passed same zone unlimited');

ok(http(<<EOF, socket => $s), 'long connection closed');
Host: localhost

EOF

# zones proxy chain

like(get('127.0.0.1:' . port(8082)), qr/200 OK/, 'passed proxy');
is(get('127.0.0.1:' . port(8083)), undef, 'rejected proxy');

###############################################################################

sub get {
	my $peer = shift;

	my $r = http_get('/', socket => getconn($peer));
	if (!$r) {
		$r = undef;
	}

	return $r;
}

sub getconn {
	my $peer = shift;
	my $s = IO::Socket::INET->new(
		Proto => 'tcp',
		PeerAddr => $peer || '127.0.0.1:' . port(8080)
	)
		or die "Can't connect to nginx: $!\n";

	return $s;
}

###############################################################################