mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The inbound port-forward probes ran while the DNS mapping to gw-server from Phase 4 was still live. Each mapping installs an SNAT rule matching only the mesh address, ahead of the LAN masquerade, so that rule took gw-server's inbound flows and the probes passed whether or not the LAN masquerade worked. The probes also passed on any response, so a flow rewritten by the LAN masquerade could not be told from one rewritten by a mapping's SNAT rule. Phase 7 now checks only the port-forward rules, and the probes move to a new Phase 8b, after Phase 8 has reclaimed the mapping. Phase 8b first checks that the control socket reports no mapping to gw-server and that the kernel's table holds no SNAT rule. If that gate fails, the probes are recorded as failed rather than skipped silently, so a reclamation failure cannot leave the forwards passing through the SNAT rule. After the probes, Phase 8b reads the gateway's conntrack table and checks, for each of the three forwards, that the reply goes to the gateway's LAN address. A mapping's SNAT sends it to a pool address instead, and no rewrite at all to gw-server's own mesh address, so each case reds with the address it found. The self-test's conntrack and proxy neighbour inputs are now taken verbatim from real gateway suite runs: a healthy run's table after the inbound probes, a mapping's SNAT entry, and a wrong-interface run's unreplied entries and neighbour entries. Inputs that need two situations at once join lines from different runs.