Files
fips/testing/firewall
Johnathan Corgan 1eb0e8a34e Move the TUN and DNS child start and stop bodies into ipv6tun
Bringing the TUN device and the .fips DNS responder up and taking them
down is host-side work, but the bodies sat inline in the node's
supervisor arms, and their handles were eight loose fields on the
supervisor. Move the bodies to ipv6tun::lifecycle and gather the
handles into one Handles struct there, held by the supervisor. The
supervisor arms, their order and the child-exit reporting are
unchanged; each arm now calls into ipv6tun.

The TUN start is two calls so the node can refresh its MSS ceiling
between them, exactly where it did before: open_tun creates and logs
the device, then spawn_tun creates the macOS/FreeBSD shutdown pipe and
starts the writer and reader threads. A failure to create the device
still continues without a TUN, and a pipe or writer failure still fails
the node's start. stop_tun and stop_dns carry the teardown unchanged,
including the shutdown-pipe write that wakes the reader on macOS and
FreeBSD.

The TUN device name moves into Handles as well, so the teardown up-set
can ask ipv6tun whether each child is up. A TUN counts as up when it
has a device name, not when it has a sender, so an app-owned TUN still
produces no TUN teardown; DNS counts as up while its task handle
exists. Node::tun_name, tun_tx, dns_local_addr and
enable_app_owned_tun keep their behaviour and now read or write the
handles. Node::mesh_ifindex had no caller left outside a test and is
replaced by the same method on Handles. Tests install a TUN sender
through a test-only Node::install_tun.

The moved log lines now log under fips::ipv6tun::lifecycle instead of
fips::node::lifecycle. Add that target to the NAT harness and its trace
overlay, and to the harnesses that relied on fips::node=debug, and note
the rename in the changelog.
2026-09-24 14:45:51 +00:00
..

Firewall Baseline Test

End-to-end exercise of the production fips0 nftables baseline at packaging/common/fips.nft. Closes the v0.3.0 audit gap that the default-deny + conntrack + drop-in semantics had no integration coverage.

What this exercises

The fips.nft baseline polices ONLY the fips0 mesh interface and implements default-deny inbound. This suite asserts the four behaviors documented in the file's header are actually true on a live mesh:

  • (a) Unallowed inbound on fips0 is dropped
  • (b) Outbound-initiated flows get their reply via the ct state established,related accept rule
  • (c) ICMPv6 echo-request is accepted (ping6 reachability)
  • (d) A drop-in .nft file under /etc/fips/fips.d/ adds an allowlisted port and that port is accepted

A drop-counter check after case (a) confirms the connection was actively DROP'd by the fips chain (not silently unrouted).

Topology

Two FIPS nodes peered over UDP on a Docker bridge network:

Container Hostname Firewall
fips-fw-container-a host-a none (probe)
fips-fw-container-b host-b fips.nft + drop-in

The bridge network requests no subnet, so docker assigns one from its own address pool and two concurrent runs never contend for a fixed range. No node's IPv4 address is therefore known before startup, and the generated peer stanzas address each other by docker hostname, resolved through the container's dnsmasq to docker's embedded DNS. The firewall assertions themselves are unaffected: they run over the fips0 overlay, whose addresses are derived from the node npubs.

node-b mounts the production packaging/common/fips.nft read-only at /etc/fips/fips.nft, plus a drop-in at /etc/fips/fips.d/services.nft containing tcp dport 22 accept. node-a is unfirewalled and serves as the probe origin.

Both containers run the unified test image's default mode, which starts dnsmasq + sshd (port 22) + iperf3 + python http.server on port 8000 + the FIPS daemon.

fips-firewall.service activation

The production unit's ExecStart is:

ExecStart=/usr/sbin/nft -f /etc/fips/fips.nft

The unified test image does not run systemd, so test.sh invokes the same nft -f command directly inside node-b after fips0 is up and peering has converged. The deb-install harness covers the systemd unit-enablement path under real systemd separately.

Run

Build the Linux binaries and test image:

./testing/scripts/build.sh --no-docker

Run the suite:

./testing/firewall/test.sh

test.sh regenerates fixtures automatically before starting Docker. Use --skip-build to reuse the existing release binaries and the existing test image: the suite then neither builds nor pulls the image named by FIPS_TEST_IMAGE (default fips-test:latest), so that image must already exist. Use --keep-up to leave the containers running for inspection.

Expected output shape

=== Generating firewall fixtures
=== Starting firewall harness
=== Waiting for fips0 on both nodes
=== Waiting for peer convergence
=== Resolving fips0 addresses
  node-a: fd97:...
  node-b: fd97:...
=== Activating fips-firewall on fips-fw-container-b
PASS: fips-fw-container-b: fips.nft baseline + drop-in loaded
=== Case (c): ICMPv6 echo-request to firewalled node
PASS: (c) ICMPv6 ping node-a → node-b accepted
=== Case (a): unallowed inbound TCP/8000 from node-a → node-b
PASS: (a) inbound TCP/8000 dropped (curl rc=28, timed out as expected)
=== Case (b): node-b initiates outbound TCP, expects reply via conntrack
PASS: (b) outbound from node-b got HTTP 200 via conntrack reply path
=== Case (d): drop-in allowlisted TCP/22 from node-a → node-b
PASS: (d) drop-in allowlisted TCP/22 reachable
=== Drop counter incremented (case a should have ticked it)
PASS: drop counter = N (case a was actually dropped, not just unrouted)
=== Firewall integration test passed

Inspect the loaded ruleset

docker exec fips-fw-container-b nft list table inet fips

Stop and clean up

docker compose -f testing/firewall/docker-compose.yml down

Generated fixture location

testing/firewall/generated-configs/ (gitignored), or generated-configs<suffix>/ when FIPS_CI_NAME_SUFFIX is set, which is how concurrent runs keep their fixtures apart.