mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The gateway test wrote lan_interface: eth1 into the gateway config before any container existed, on the assumption that Docker attaches the LAN network as eth1. Docker does not promise that order, at the first start or at later ones, and a wrong name that exists passes the gateway's startup check. The LAN masquerade for inbound port forwards and the proxy NDP entries for virtual IPs then went on the wrong interface, and nothing in the suite noticed. The gateway container's entrypoint now finds the interface holding the gateway's LAN address and writes the gateway's config from it before fips-gateway starts, so every docker start and restart re-derives it. The config the suite writes carries only a placeholder. The suite checks the running gateway's interface against its own derivation after the first start and after each later start, checks that the LAN masquerade and the proxy NDP entry are on it, and checks that a restarted gateway's config carries the ttl and grace settings the later phases rely on. inject-config passes its values to Python as arguments rather than splicing them into the program, and a failed config write now fails the writer instead of reporting success. The output parsers are checked against canned tool output by a new selftest subcommand, which the suite also runs first as Phase 0.