Files
fips/testing/static/scripts
Johnathan Corgan 364fed7c07 Probe the gateway's inbound forwards with no mapping and assert the rewrite
The inbound port-forward probes ran while the DNS mapping to gw-server
from Phase 4 was still live. Each mapping installs an SNAT rule matching
only the mesh address, ahead of the LAN masquerade, so that rule took
gw-server's inbound flows and the probes passed whether or not the LAN
masquerade worked. The probes also passed on any response, so a flow
rewritten by the LAN masquerade could not be told from one rewritten by
a mapping's SNAT rule.

Phase 7 now checks only the port-forward rules, and the probes move to a
new Phase 8b, after Phase 8 has reclaimed the mapping. Phase 8b first
checks that the control socket reports no mapping to gw-server and that
the kernel's table holds no SNAT rule. If that gate fails, the probes are
recorded as failed rather than skipped silently, so a reclamation failure
cannot leave the forwards passing through the SNAT rule.

After the probes, Phase 8b reads the gateway's conntrack table and
checks, for each of the three forwards, that the reply goes to the
gateway's LAN address. A mapping's SNAT sends it to a pool address
instead, and no rewrite at all to gw-server's own mesh address, so each
case reds with the address it found.

The self-test's conntrack and proxy neighbour inputs are now taken
verbatim from real gateway suite runs: a healthy run's table after the
inbound probes, a mapping's SNAT entry, and a wrong-interface run's
unreplied entries and neighbour entries. Inputs that need two situations
at once join lines from different runs.
2026-09-26 18:59:43 +00:00
..