#! /usr/bin/atf-sh
#	$NetBSD: net_common.sh,v 1.32 2019/07/18 04:22:22 ozaki-r Exp $
#
# Copyright (c) 2016 Internet Initiative Japan Inc.
# All rights reserved.
#
# Redistribution and use in source and binary forms, with or without
# modification, are permitted provided that the following conditions
# are met:
# 1. Redistributions of source code must retain the above copyright
#    notice, this list of conditions and the following disclaimer.
# 2. Redistributions in binary form must reproduce the above copyright
#    notice, this list of conditions and the following disclaimer in the
#    documentation and/or other materials provided with the distribution.
#
# THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
# ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
# TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
# PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
# BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
# POSSIBILITY OF SUCH DAMAGE.
#

#
# Common utility functions for tests/net
#

HIJACKING="env LD_PRELOAD=/usr/lib/librumphijack.so \
    RUMPHIJACK=path=/rump,socket=all:nolocal,sysctl=yes"
ONEDAYISH="(23h5[0-9]m|1d0h0m)[0-9]+s ?"

extract_new_packets()
{
	local bus=$1
	local old=./.__old

	if [ ! -f $old ]; then
		old=/dev/null
	fi

	shmif_dumpbus -p - $bus 2>/dev/null |
	    tcpdump -n -e -r - 2>/dev/null > ./.__new
	diff -u $old ./.__new | grep '^+' | cut -d '+' -f 2   > ./.__diff
	mv -f ./.__new ./.__old
	cat ./.__diff
}

check_route()
{
	local target=$1
	local gw=$2
	local flags=${3:-\.\+}
	local ifname=${4:-\.\+}

	target=$(echo $target | sed 's/\./\\./g')
	if [ "$gw" = "" ]; then
		gw=".+"
	else
		gw=$(echo $gw | sed 's/\./\\./g')
	fi

	atf_check -s exit:0 -e ignore \
	    -o match:"^$target +$gw +$flags +- +- +.+ +$ifname" \
	    rump.netstat -rn
}

check_route_flags()
{

	check_route "$1" "" "$2" ""
}

check_route_gw()
{

	check_route "$1" "$2" "" ""
}

check_route_no_entry()
{
	local target=$(echo "$1" | sed 's/\./\\./g')

	atf_check -s exit:0 -e ignore -o not-match:"^$target" rump.netstat -rn
}

get_linklocal_addr()
{

	RUMP_SERVER=${1} rump.ifconfig ${2} inet6 |
	    awk "/fe80/ {sub(/%$2/, \"\"); sub(/\\/[0-9]*/, \"\"); print \$2;}"

	return 0
}

get_macaddr()
{

	RUMP_SERVER=${1} rump.ifconfig ${2} | awk '/address/ {print $2;}'
}

HTTPD_PID=./.__httpd.pid
start_httpd()
{
	local sock=$1
	local ip=$2
	local backup=$RUMP_SERVER

	export RUMP_SERVER=$sock

	# start httpd in daemon mode
	atf_check -s exit:0 env LD_PRELOAD=/usr/lib/librumphijack.so \
	    /usr/libexec/httpd -P $HTTPD_PID -i $ip -b -s $(pwd)

	export RUMP_SERVER=$backup

	sleep 3
}

stop_httpd()
{

	if [ -f $HTTPD_PID ]; then
		kill -9 $(cat $HTTPD_PID)
		rm -f $HTTPD_PID
		sleep 1
	fi
}

NC_PID=./.__nc.pid
start_nc_server()
{
	local sock=$1
	local port=$2
	local outfile=$3
	local proto=${4:-ipv4}
	local backup=$RUMP_SERVER
	local opts=

	export RUMP_SERVER=$sock

	if [ $proto = ipv4 ]; then
		opts="-l -4"
	else
		opts="-l -6"
	fi

	env LD_PRELOAD=/usr/lib/librumphijack.so nc $opts $port > $outfile &
	echo $! > $NC_PID

	if [ $proto = ipv4 ]; then
		$DEBUG && rump.netstat -a -f inet
	else
		$DEBUG && rump.netstat -a -f inet6
	fi

	export RUMP_SERVER=$backup

	sleep 1
}

stop_nc_server()
{

	if [ -f $NC_PID ]; then
		kill -9 $(cat $NC_PID)
		rm -f $NC_PID
		sleep 1
	fi
}

BASIC_LIBS="-lrumpnet -lrumpnet_net -lrumpnet_netinet -lrumpnet_shmif"
FS_LIBS="$BASIC_LIBS -lrumpdev -lrumpvfs -lrumpfs_ffs"
CRYPTO_LIBS="$BASIC_LIBS -lrumpdev -lrumpdev_opencrypto \
    -lrumpkern_z -lrumpkern_crypto"
NPF_LIBS="$BASIC_LIBS -lrumpdev -lrumpvfs -lrumpdev_bpf -lrumpnet_npf"
CRYPTO_NPF_LIBS="$CRYPTO_LIBS -lrumpvfs -lrumpdev_bpf -lrumpnet_npf"

# We cannot keep variables between test phases, so need to store in files
_rump_server_socks=./.__socks
_rump_server_ifaces=./.__ifaces
_rump_server_buses=./.__buses

DEBUG_SYSCTL_ENTRIES="net.inet.arp.debug net.inet6.icmp6.nd6_debug \
    net.inet.ipsec.debug"

IPSEC_KEY_DEBUG=${IPSEC_KEY_DEBUG:-false}

_rump_server_start_common()
{
	local sock=$1
	local backup=$RUMP_SERVER

	shift 1

	atf_check -s exit:0 rump_server "$@" "$sock"

	if $DEBUG; then
		# Enable debugging features in the kernel
		export RUMP_SERVER=$sock
		for ent in $DEBUG_SYSCTL_ENTRIES; do
			if rump.sysctl -q $ent; then
				atf_check -s exit:0 rump.sysctl -q -w $ent=1
			fi
		done
		export RUMP_SERVER=$backup
	fi
	if $IPSEC_KEY_DEBUG; then
		# Enable debugging features in the kernel
		export RUMP_SERVER=$sock
		if rump.sysctl -q net.key.debug; then
			atf_check -s exit:0 \
			    rump.sysctl -q -w net.key.debug=0xffff
		fi
		export RUMP_SERVER=$backup
	fi

	echo $sock >> $_rump_server_socks
	$DEBUG && cat $_rump_server_socks
}

rump_server_start()
{
	local sock=$1
	local lib=
	local libs="$BASIC_LIBS"

	shift 1

	for lib
	do
		libs="$libs -lrumpnet_$lib"
	done

	_rump_server_start_common $sock $libs

	return 0
}

rump_server_fs_start()
{
	local sock=$1
	local lib=
	local libs="$FS_LIBS"

	shift 1

	for lib
	do
		libs="$libs -lrumpnet_$lib"
	done

	_rump_server_start_common $sock $libs

	return 0
}

rump_server_crypto_start()
{
	local sock=$1
	local lib=
	local libs="$CRYPTO_LIBS"

	shift 1

	for lib
	do
		libs="$libs -lrumpnet_$lib"
	done

	_rump_server_start_common $sock $libs

	return 0
}

rump_server_npf_start()
{
	local sock=$1
	local lib=
	local libs="$NPF_LIBS"

	shift 1

	for lib
	do
		libs="$libs -lrumpnet_$lib"
	done

	_rump_server_start_common $sock $libs

	return 0
}

rump_server_crypto_npf_start()
{
	local sock=$1
	local lib=
	local libs="$CRYPTO_NPF_LIBS"

	shift 1

	for lib
	do
		libs="$libs -lrumpnet_$lib"
	done

	_rump_server_start_common $sock $libs

	return 0
}

rump_server_add_iface()
{
	local sock=$1
	local ifname=$2
	local bus=$3
	local backup=$RUMP_SERVER

	export RUMP_SERVER=$sock
	atf_check -s exit:0 rump.ifconfig $ifname create
	atf_check -s exit:0 rump.ifconfig $ifname linkstr $bus
	export RUMP_SERVER=$backup

	echo $sock $ifname >> $_rump_server_ifaces
	$DEBUG && cat $_rump_server_ifaces

	echo $bus >> $_rump_server_buses
	cat $_rump_server_buses |sort -u >./.__tmp
	mv -f ./.__tmp $_rump_server_buses
	$DEBUG && cat $_rump_server_buses

	return 0
}

rump_server_destroy_ifaces()
{
	local backup=$RUMP_SERVER
	local output=ignore

	$DEBUG && cat $_rump_server_ifaces

	# Try to dump states before destroying interfaces
	for sock in $(cat $_rump_server_socks); do
		export RUMP_SERVER=$sock
		if $DEBUG; then
			output=save:/dev/stdout
		fi
		atf_check -s exit:0 -o $output rump.ifconfig
		atf_check -s exit:0 -o $output rump.netstat -nr
		# XXX still need hijacking
		atf_check -s exit:0 -o $output $HIJACKING rump.netstat -nai
		atf_check -s exit:0 -o $output rump.arp -na
		atf_check -s exit:0 -o $output rump.ndp -na
		atf_check -s exit:0 -o $output $HIJACKING ifmcstat
	done

	# XXX using pipe doesn't work. See PR bin/51667
	#cat $_rump_server_ifaces | while read sock ifname; do
	while read sock ifname; do
		export RUMP_SERVER=$sock
		if rump.ifconfig -l |grep -q $ifname; then
			atf_check -s exit:0 rump.ifconfig $ifname destroy
		fi
		atf_check -s exit:0 -o ignore rump.ifconfig
	done < $_rump_server_ifaces
	export RUMP_SERVER=$backup

	return 0
}

rump_server_halt_servers()
{
	local backup=$RUMP_SERVER

	$DEBUG && cat $_rump_server_socks
	for sock in $(cat $_rump_server_socks); do
		env RUMP_SERVER=$sock rump.halt
	done
	export RUMP_SERVER=$backup

	return 0
}

extract_rump_server_core()
{

	if [ -f rump_server.core ]; then
		gdb -ex bt /usr/bin/rump_server rump_server.core
		# Extract kernel logs including a panic message
		strings rump_server.core |grep -E '^\[.+\] '
	fi
}

dump_kernel_stats()
{
	local sock=$1

	echo "### Dumping $sock"
	export RUMP_SERVER=$sock
	rump.ifconfig -av
	rump.netstat -nr
	# XXX still need hijacking
	$HIJACKING rump.netstat -nai
	rump.arp -na
	rump.ndp -na
	$HIJACKING ifmcstat
	$HIJACKING dmesg
}

rump_server_dump_servers()
{
	local backup=$RUMP_SERVER

	$DEBUG && cat $_rump_server_socks
	for sock in $(cat $_rump_server_socks); do
		dump_kernel_stats $sock
	done
	export RUMP_SERVER=$backup

	extract_rump_server_core
	return 0
}

rump_server_dump_buses()
{

	if [ ! -f $_rump_server_buses ]; then
		return 0
	fi

	$DEBUG && cat $_rump_server_buses
	for bus in $(cat $_rump_server_buses); do
		echo "### Dumping $bus"
		shmif_dumpbus -p - $bus 2>/dev/null| tcpdump -n -e -r -
	done
	return 0
}

cleanup()
{

	rump_server_halt_servers
}

dump()
{

	rump_server_dump_servers
	rump_server_dump_buses
}

skip_if_qemu()
{
	if sysctl machdep.cpu_brand 2>/dev/null | grep QEMU >/dev/null 2>&1
	then
	    atf_skip "unreliable under qemu, skip until PR kern/43997 fixed"
	fi
}

test_create_destroy_common()
{
	local sock=$1
	local ifname=$2
	local test_address=${3:-false}
	local ipv4="10.0.0.1/24"
	local ipv6="fc00::1"

	export RUMP_SERVER=$sock

	atf_check -s exit:0 rump.ifconfig $ifname create
	atf_check -s exit:0 rump.ifconfig $ifname destroy

	atf_check -s exit:0 rump.ifconfig $ifname create
	atf_check -s exit:0 rump.ifconfig $ifname up
	atf_check -s exit:0 rump.ifconfig $ifname down
	atf_check -s exit:0 rump.ifconfig $ifname destroy

	# Destroy while UP
	atf_check -s exit:0 rump.ifconfig $ifname create
	atf_check -s exit:0 rump.ifconfig $ifname up
	atf_check -s exit:0 rump.ifconfig $ifname destroy

	if ! $test_address; then
		return
	fi

	# With an IPv4 address
	atf_check -s exit:0 rump.ifconfig $ifname create
	atf_check -s exit:0 rump.ifconfig $ifname inet $ipv4
	atf_check -s exit:0 rump.ifconfig $ifname up
	atf_check -s exit:0 rump.ifconfig $ifname destroy

	# With an IPv6 address
	atf_check -s exit:0 rump.ifconfig $ifname create
	atf_check -s exit:0 rump.ifconfig $ifname inet6 $ipv6
	atf_check -s exit:0 rump.ifconfig $ifname up
	atf_check -s exit:0 rump.ifconfig $ifname destroy

	unset RUMP_SERVER
}
#	$NetBSD: t_l2tp.sh,v 1.4 2018/02/01 05:22:01 ozaki-r Exp $
#
# Copyright (c) 2017 Internet Initiative Japan Inc.
# All rights reserved.
#
# Redistribution and use in source and binary forms, with or without
# modification, are permitted provided that the following conditions
# are met:
# 1. Redistributions of source code must retain the above copyright
#    notice, this list of conditions and the following disclaimer.
# 2. Redistributions in binary form must reproduce the above copyright
#    notice, this list of conditions and the following disclaimer in the
#    documentation and/or other materials provided with the distribution.
#
# THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
# ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
# TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
# PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
# BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
# POSSIBILITY OF SUCH DAMAGE.
#

LAC1SOCK=unix://commsock1
LAC2SOCK=unix://commsock2
CLIENT1SOCK=unix://commsock3
CLIENT2SOCK=unix://commsock4

WAN_LINK=bus0
LAC1_LAN_LINK=bus1
LAC2_LAN_LINK=bus2

LAC1_WANIP=10.0.0.1
LAC1_SESSION=1234
CLIENT1_LANIP=192.168.1.1
LAC2_WANIP=10.0.0.2
LAC2_SESSION=4321
CLIENT2_LANIP=192.168.1.2

LAC1_WANIP6=fc00::1
CLIENT1_LANIP6=fc00:1::1
LAC2_WANIP6=fc00::2
CLIENT2_LANIP6=fc00:1::2

TIMEOUT=5
DEBUG=${DEBUG:-false}

atf_test_case l2tp_create_destroy cleanup
l2tp_create_destroy_head()
{

	atf_set "descr" "Test creating/destroying l2tp interfaces"
	atf_set "require.progs" "rump_server"
}

l2tp_create_destroy_body()
{

	rump_server_start $LAC1SOCK l2tp

	test_create_destroy_common $LAC1SOCK l2tp0
}

l2tp_create_destroy_cleanup()
{

	$DEBUG && dump
	cleanup
}

setup_lac()
{
	sock=${1}
	lanlink=${2}
	wan=${3}
	wan_mode=${4}


	rump_server_add_iface ${sock} shmif0 ${lanlink}
	rump_server_add_iface ${sock} shmif1 ${WAN_LINK}

	export RUMP_SERVER=${sock}

	if [ ${wan_mode} = "ipv6" ]; then
		atf_check -s exit:0 rump.ifconfig shmif1 inet6 ${wan}
	else
		atf_check -s exit:0 rump.ifconfig shmif1 inet ${wan} netmask 0xff000000
	fi
	atf_check -s exit:0 rump.ifconfig shmif0 up
	atf_check -s exit:0 rump.ifconfig shmif1 up

	unset RUMP_SERVER
}

test_lac()
{
	sock=${1}
	wan=${2}
	wan_mode=${3}

	export RUMP_SERVER=${sock}

	atf_check -s exit:0 -o match:shmif0 rump.ifconfig
	atf_check -s exit:0 -o match:shmif1 rump.ifconfig
	if [ ${wan_mode} = "ipv6" ]; then
		atf_check -s exit:0 -o ignore rump.ping6 -n -c 1 -X $TIMEOUT ${wan}
	else
		atf_check -s exit:0 -o ignore rump.ping -n -c 1 -w $TIMEOUT ${wan}
	fi

	unset RUMP_SERVER
}

setup_client()
{
	sock=${1}
	lanlink=${2}
	lan=${3}
	lan_mode=${4}

	rump_server_add_iface ${sock} shmif0 ${lanlink}

	export RUMP_SERVER=${sock}
	if [ ${lan_mode} = "ipv6" ]; then
		atf_check -s exit:0 rump.ifconfig shmif0 inet6 ${lan}
	else
		atf_check -s exit:0 rump.ifconfig shmif0 inet ${lan} netmask 0xffffff00
	fi
	atf_check -s exit:0 rump.ifconfig shmif0 up

	unset RUMP_SERVER
}

test_client()
{
	sock=${1}
	lan=${2}
	lan_mode=${3}

	export RUMP_SERVER=${sock}

	atf_check -s exit:0 -o match:shmif0 rump.ifconfig
	if [ ${lan_mode} = "ipv6" ]; then
		atf_check -s exit:0 -o ignore rump.ping6 -n -c 1 -X $TIMEOUT ${lan}
	else
		atf_check -s exit:0 -o ignore rump.ping -n -c 1 -w $TIMEOUT ${lan}
	fi

	unset RUMP_SERVER
}

setup()
{
	lan_mode=${1}
	wan_mode=${2}

	rump_server_start $LAC1SOCK netinet6 bridge l2tp
	rump_server_start $LAC2SOCK netinet6 bridge l2tp
	rump_server_start $CLIENT1SOCK netinet6 bridge l2tp
	rump_server_start $CLIENT2SOCK netinet6 bridge l2tp

	client1_lan=""
	client2_lan=""
	if [ ${lan_mode} = "ipv6" ]; then
		client1_lan=${CLIENT1_LANIP6}
		client2_lan=${CLIENT2_LANIP6}
	else
		client1_lan=${CLIENT1_LANIP}
		client2_lan=${CLIENT2_LANIP}
	fi

	if [ ${wan_mode} = "ipv6" ]; then
		setup_lac $LAC1SOCK $LAC1_LAN_LINK $LAC1_WANIP6 ${wan_mode}
		setup_lac $LAC2SOCK $LAC2_LAN_LINK $LAC2_WANIP6 ${wan_mode}
		setup_client $CLIENT1SOCK $LAC1_LAN_LINK \
			     ${client1_lan} ${lan_mode}
		setup_client $CLIENT2SOCK $LAC2_LAN_LINK \
			     ${client2_lan} ${lan_mode}
	else
		setup_lac $LAC1SOCK $LAC1_LAN_LINK $LAC1_WANIP ${wan_mode}
		setup_lac $LAC2SOCK $LAC2_LAN_LINK $LAC2_WANIP ${wan_mode}
		setup_client $CLIENT1SOCK $LAC1_LAN_LINK \
			     ${client1_lan} ${lan_mode}
		setup_client $CLIENT2SOCK $LAC2_LAN_LINK \
			     ${client2_lan} ${lan_mode}
	fi
}

test_setup()
{
	lan_mode=${1}
	wan_mode=${2}

	client1_lan=""
	client2_lan=""
	if [ ${lan_mode} = "ipv6" ]; then
		client1_lan=$CLIENT1_LANIP6
		client2_lan=$CLIENT2_LANIP6
	else
		client1_lan=$CLIENT1_LANIP
		client2_lan=$CLIENT2_LANIP
	fi
	if [ ${wan_mode} = "ipv6" ]; then
		test_lac ${LAC1SOCK} $LAC1_WANIP6 ${wan_mode}
		test_lac ${LAC2SOCK} $LAC2_WANIP6 ${wan_mode}
		test_client ${CLIENT1SOCK} ${client1_lan} ${lan_mode}
		test_client ${CLIENT2SOCK} ${client2_lan} ${lan_mode}
	else
		test_lac ${LAC1SOCK} $LAC1_WANIP ${wan_mode}
		test_lac ${LAC2SOCK} $LAC2_WANIP ${wan_mode}
		test_client ${CLIENT1SOCK} ${client1_lan} ${lan_mode}
		test_client ${CLIENT2SOCK} ${client2_lan} ${lan_mode}
	fi
}

setup_if_l2tp()
{
	sock=${1}
	src=${2}
	dst=${3}
	src_session=${4}
	dst_session=${5}

	export RUMP_SERVER=${sock}

	atf_check -s exit:0 rump.ifconfig l2tp0 create
	atf_check -s exit:0 rump.ifconfig l2tp0 tunnel ${src} ${dst}
	atf_check -s exit:0 rump.ifconfig l2tp0 session ${src_session} ${dst_session}
	atf_check -s exit:0 rump.ifconfig l2tp0 up

	atf_check -s exit:0 rump.ifconfig bridge0 create
	atf_check -s exit:0 rump.ifconfig bridge0 up
	export LD_PRELOAD=/usr/lib/librumphijack.so
	atf_check -s exit:0 brconfig bridge0 add shmif0
	atf_check -s exit:0 brconfig bridge0 add l2tp0
	unset LD_PRELOAD

	$DEBUG && rump.ifconfig -v l2tp0
	$DEBUG && rump.ifconfig -v bridge0

	unset RUMP_SERVER
}

setup_tunnel()
{
	wan_mode=${1}

	src=""
	dst=""
	src_session=""
	dst_session=""

	if [ ${wan_mode} = "ipv6" ]; then
		src=$LAC1_WANIP6
		dst=$LAC2_WANIP6
	else
		src=$LAC1_WANIP
		dst=$LAC2_WANIP
	fi
	src_session=${LAC1_SESSION}
	dst_session=${LAC2_SESSION}
	setup_if_l2tp $LAC1SOCK ${src} ${dst} ${src_session} ${dst_session}

	if [ ${wan_mode} = "ipv6" ]; then
		src=$LAC2_WANIP6
		dst=$LAC1_WANIP6
	else
		src=$LAC2_WANIP
		dst=$LAC1_WANIP
	fi
	src_session=${LAC2_SESSION}
	dst_session=${LAC1_SESSION}
	setup_if_l2tp $LAC2SOCK ${src} ${dst} ${src_session} ${dst_session}
}

test_setup_tunnel()
{
	mode=${1}

	if [ ${mode} = "ipv6" ]; then
		lac1_wan=$LAC1_WANIP6
		lac2_wan=$LAC2_WANIP6
	else
		lac1_wan=$LAC1_WANIP
		lac2_wan=$LAC2_WANIP
	fi
	export RUMP_SERVER=$LAC1SOCK
	atf_check -s exit:0 -o match:l2tp0 rump.ifconfig
	if [ ${mode} = "ipv6" ]; then
	    atf_check -s exit:0 -o ignore rump.ping6 -n -c 1 -X $TIMEOUT ${lac2_wan}
	else
	    atf_check -s exit:0 -o ignore rump.ping -n -c 1 -w $TIMEOUT ${lac2_wan}
	fi

	export RUMP_SERVER=$LAC2SOCK
	atf_check -s exit:0 -o match:l2tp0 rump.ifconfig
	if [ ${mode} = "ipv6" ]; then
	    atf_check -s exit:0 -o ignore rump.ping6 -n -c 1 -X $TIMEOUT ${lac1_wan}
	else
	    atf_check -s exit:0 -o ignore rump.ping -n -c 1 -w $TIMEOUT ${lac1_wan}
	fi

	unset RUMP_SERVER
}

teardown_tunnel()
{
	export RUMP_SERVER=$LAC1SOCK
	atf_check -s exit:0 rump.ifconfig bridge0 destroy
	atf_check -s exit:0 rump.ifconfig l2tp0 deletetunnel
	atf_check -s exit:0 rump.ifconfig l2tp0 destroy

	export RUMP_SERVER=$LAC2SOCK
	atf_check -s exit:0 rump.ifconfig bridge0 destroy
	atf_check -s exit:0 rump.ifconfig l2tp0 deletetunnel
	atf_check -s exit:0 rump.ifconfig l2tp0 destroy

	unset RUMP_SERVER
}

test_ping_failure()
{
	mode=$1

	export RUMP_SERVER=$CLIENT1SOCK
	if [ ${mode} = "ipv6" ]; then
		atf_check -s not-exit:0 -o ignore -e ignore \
			rump.ping6 -n -X $TIMEOUT -c 1 $CLIENT2_LANIP6
	else
		atf_check -s not-exit:0 -o ignore -e ignore \
			rump.ping -n -w $TIMEOUT -c 1 $CLIENT2_LANIP
	fi

	export RUMP_SERVER=$CLIENT2SOCK
	if [ ${mode} = "ipv6" ]; then
		atf_check -s not-exit:0 -o ignore -e ignore \
			rump.ping6 -n -X $TIMEOUT -c 1 $CLIENT1_LANIP6
	else
		atf_check -s not-exit:0 -o ignore -e ignore \
			rump.ping -n -w $TIMEOUT -c 1 $CLIENT1_LANIP
	fi

	unset RUMP_SERVER
}

test_ping_success()
{
	mode=$1

	export RUMP_SERVER=$CLIENT1SOCK
	if [ ${mode} = "ipv6" ]; then
		# XXX
		# rump.ping6 rarely fails with the message that
		# "failed to get receiving hop limit".
		# This is a known issue being analyzed.
		atf_check -s exit:0 -o ignore \
			rump.ping6 -n -X $TIMEOUT -c 1 $CLIENT2_LANIP6
	else
		atf_check -s exit:0 -o ignore \
			rump.ping -n -w $TIMEOUT -c 1 $CLIENT2_LANIP
	fi
	export RUMP_SERVER=$LAC1SOCK
	$DEBUG && rump.ifconfig -v l2tp0
	$DEBUG && rump.ifconfig -v bridge0
	$DEBUG && rump.ifconfig -v shmif0

	export RUMP_SERVER=$CLIENT2SOCK
	if [ ${mode} = "ipv6" ]; then
		atf_check -s exit:0 -o ignore \
			rump.ping6 -n -X $TIMEOUT -c 1 $CLIENT1_LANIP6
	else
		atf_check -s exit:0 -o ignore \
			rump.ping -n -w $TIMEOUT -c 1 $CLIENT1_LANIP
	fi
	export RUMP_SERVER=$LAC2SOCK
	$DEBUG && rump.ifconfig -v l2tp0
	$DEBUG && rump.ifconfig -v bridge0
	$DEBUG && rump.ifconfig -v shmif0

	unset RUMP_SERVER
}

basic_setup()
{
	lan_mode=$1
	wan_mode=$2

	setup ${lan_mode} ${wan_mode}
	test_setup ${lan_mode} ${wan_mode}

	# Enable once PR kern/49219 is fixed
	#test_ping_failure

	setup_tunnel ${wan_mode}
	sleep 1
	test_setup_tunnel ${wan_mode}
}

basic_test()
{
	lan_mode=$1
	wan_mode=$2 # not use

	test_ping_success ${lan_mode}
}

basic_teardown()
{
	lan_mode=$1
	wan_mode=$2 # not use

	teardown_tunnel
	test_ping_failure ${lan_mode}
}

add_test()
{
	category=$1
	desc=$2
	lan_mode=$3
	wan_mode=$4

	name="l2tp_${category}_${lan_mode}over${wan_mode}"
	fulldesc="Does ${lan_mode} over ${wan_mode} if_l2tp ${desc}"

	atf_test_case ${name} cleanup
	eval "${name}_head() {
			atf_set descr \"${fulldesc}\"
			atf_set require.progs rump_server
		}
	    ${name}_body() {
			${category}_setup ${lan_mode} ${wan_mode}
			${category}_test ${lan_mode} ${wan_mode}
			${category}_teardown ${lan_mode} ${wan_mode}
			rump_server_destroy_ifaces
	    }
	    ${name}_cleanup() {
			\$DEBUG && dump
			cleanup
		}"
	atf_add_test_case ${name}
}

add_test_allproto()
{
	category=$1
	desc=$2

	add_test ${category} "${desc}" ipv4 ipv4
	add_test ${category} "${desc}" ipv4 ipv6
	add_test ${category} "${desc}" ipv6 ipv4
	add_test ${category} "${desc}" ipv6 ipv6
}

atf_init_test_cases()
{

	atf_add_test_case l2tp_create_destroy

	add_test_allproto basic "basic tests"
#	add_test_allproto recursive "recursive check tests"
}
