Files
fips/testing/nat/scripts
Johnathan Corgan 73e33158c4 Give the NAT-lab path assertions a diagnostic and a state dump
Four path assertions failed with a bare exit, printing neither what they
expected nor what they saw, and triggering none of the scenario
diagnostics their siblings already call. A red nat-symmetric run said
only that a path check failed, which is why the 2026-08-13 master failure
could not be diagnosed and why the load-dependent flake behind it has
never been root-caused.

Both helpers now report the container, the expectation, what was actually
observed and a projection of the peer or link table, and separate a
failed fipsctl exec from unparseable output from a genuine mismatch. All
twelve call sites dump the scenario diagnostics on failure, in the same
shape the surrounding wait_for_peers calls already use.

The projected field names are read from the control-socket query
implementation rather than guessed. A passing assertion prints nothing.

No retry was added. A bounded retry is listed as a possibility in the
issue, but it would suppress exactly the transient that needs to be
caught; the right order is to let the next red print its state first.
2026-08-22 09:19:04 +01:00
..