mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-06 03:28:24 +00:00
Bringing the TUN device and the .fips DNS responder up and taking them down is host-side work, but the bodies sat inline in the node's supervisor arms, and their handles were eight loose fields on the supervisor. Move the bodies to ipv6tun::lifecycle and gather the handles into one Handles struct there, held by the supervisor. The supervisor arms, their order and the child-exit reporting are unchanged; each arm now calls into ipv6tun. The TUN start is two calls so the node can refresh its MSS ceiling between them, exactly where it did before: open_tun creates and logs the device, then spawn_tun creates the macOS/FreeBSD shutdown pipe and starts the writer and reader threads. A failure to create the device still continues without a TUN, and a pipe or writer failure still fails the node's start. stop_tun and stop_dns carry the teardown unchanged, including the shutdown-pipe write that wakes the reader on macOS and FreeBSD. The TUN device name moves into Handles as well, so the teardown up-set can ask ipv6tun whether each child is up. A TUN counts as up when it has a device name, not when it has a sender, so an app-owned TUN still produces no TUN teardown; DNS counts as up while its task handle exists. Node::tun_name, tun_tx, dns_local_addr and enable_app_owned_tun keep their behaviour and now read or write the handles. Node::mesh_ifindex had no caller left outside a test and is replaced by the same method on Handles. Tests install a TUN sender through a test-only Node::install_tun. The moved log lines now log under fips::ipv6tun::lifecycle instead of fips::node::lifecycle. Add that target to the NAT harness and its trace overlay, and to the harnesses that relied on fips::node=debug, and note the rename in the changelog.
46 lines
2.3 KiB
YAML
46 lines
2.3 KiB
YAML
# Compose override that bumps RUST_LOG to trace level on the modules
|
|
# relevant to NAT-traversal handshake-completion flake evidence
|
|
# collection:
|
|
#
|
|
# - fips::nostr — overlay advert publish/consume
|
|
# (where the cross-init race begins)
|
|
# - fips::transport::udp — UDP socket bind/send/recv
|
|
# (where the punch packets flow)
|
|
# - fips::node::lifecycle — daemon bootstrap, peer state
|
|
# machine, adoption transitions
|
|
# - fips::ipv6tun::lifecycle — TUN and DNS child start/stop
|
|
# (formerly logged under
|
|
# node::lifecycle)
|
|
# - fips::node::handlers::handshake — Noise handshake msg1/2/3,
|
|
# cross-init tie-breaker
|
|
# ("Ignoring established NAT
|
|
# traversal..." emits here)
|
|
# - fips::node::dataplane::forwarding — transit/local datagram routing
|
|
# (catches drops post-adoption)
|
|
#
|
|
# Other modules stay at info to keep log volume manageable. The base
|
|
# docker-compose.yml's `*fips-common` env block sets RUST_LOG as a
|
|
# list-form env var (`- RUST_LOG=...`); the override below replaces
|
|
# it entirely via the YAML map form, which is the docker-compose
|
|
# override semantics for the environment field.
|
|
#
|
|
# Service-name layout: only the two `lan-*` services are FIPS daemons;
|
|
# the relay and stun services are not (and don't honor RUST_LOG).
|
|
#
|
|
# Include this override via the FIPS_NAT_EXTRA_COMPOSE env var that
|
|
# testing/nat/scripts/nat-test.sh consults:
|
|
# FIPS_NAT_EXTRA_COMPOSE=testing/mesh-lab/compose-trace-nat.yml \
|
|
# bash testing/nat/scripts/nat-test.sh lan
|
|
#
|
|
# The mesh-lab harness sets it automatically when FIPS_MESH_LAB_TRACE
|
|
# is set and the suite is nat-lan.
|
|
|
|
x-trace-rust-log: &trace-rust-log
|
|
RUST_LOG: "info,fips::nostr=trace,fips::transport::udp=trace,fips::node::lifecycle=trace,fips::ipv6tun::lifecycle=trace,fips::node::handlers::handshake=trace,fips::node::dataplane::forwarding=trace"
|
|
|
|
services:
|
|
lan-a:
|
|
environment: *trace-rust-log
|
|
lan-b:
|
|
environment: *trace-rust-log
|