Files
fips/testing/iface-binding/docker-compose.yml
T
Johnathan Corgan f444457270 Move ICMPv6 error sending toward the host into ipv6tun
Building a Destination Unreachable or Packet Too Big and writing it to
the TUN is host-side IPv6 work, but the send logic lived in the node's
session handler. Move it to ipv6tun::icmp behind IcmpContext, which
borrows the TUN channel, our address and the Packet Too Big rate
limiter for the length of one use. Borrowing rather than holding a
clone of the TUN sender keeps teardown able to close the channel.

The logic is unchanged. Packet Too Big still consults the per-source
limiter before anything else, and Destination Unreachable is still
unlimited. The discovery lookup timeout now hands its queued packets to
the context as one no-route report instead of sending one reply per
packet itself. Node keeps send_icmpv6_dest_unreachable and
send_icmpv6_packet_too_big as wrappers over the context, so the outbound
handler and the tests that drive it are unchanged; the Destination
Unreachable wrapper now takes &mut self because the context borrows the
limiter.

The two Packet Too Big debug lines now log under fips::ipv6tun::icmp
instead of fips::node::handlers::session. Add that target to the test
harness filters that relied on fips::node=debug or the session trace
filter to show them, and note the rename in the changelog.
2026-09-24 14:12:26 +00:00

81 lines
3.4 KiB
YAML

networks:
# Management bridge only. The FIPS transport under test is raw Ethernet on a
# veth pair the harness creates *after* the daemons are already running —
# that is the whole point of the suite — so no FIPS traffic crosses this
# network. No subnet is requested, so two concurrent runs cannot collide on
# one address range.
#
# The compose project name is still fixed, so two runs that do not set
# COMPOSE_PROJECT_NAME share a project and the second `up` recreates the
# first's containers. The local CI runner scopes it externally
# (run_iface_binding in ci-local.sh); a bare hand run does not.
ifb-net:
driver: bridge
labels:
- "com.corganlabs.fips-ci=1"
x-fips-common: &fips-common
build:
# The harness scopes its build context per run and passes it here; the
# shared directory is the hand-run default. Compose resolves a relative
# value against THIS file's directory, so the harness must export an
# absolute path.
context: ${FIPS_BUILD_CONTEXT:-../docker}
image: ${FIPS_TEST_IMAGE:-fips-test:latest}
entrypoint: ["/usr/local/bin/entrypoint.sh"]
cap_add:
- NET_ADMIN
- NET_RAW
restart: "no"
environment:
# `default`, deliberately — NOT `chaos`. The chaos entrypoint waits up to
# 30 s for every configured Ethernet interface to appear before it starts
# the daemon, which is precisely the workaround this mechanism retires. The
# daemon must do its own waiting here or the suite proves nothing.
- FIPS_TEST_MODE=default
- RUST_LOG=info,fips::transport::ethernet=debug,fips::node=debug,fips::ipv6tun::icmp=debug
networks:
- ifb-net
services:
node-a:
<<: *fips-common
container_name: fips-ifb-node-a${FIPS_CI_NAME_SUFFIX:-}
hostname: host-a
volumes:
- ../docker/resolv.conf:/etc/resolv.conf:ro
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-a/fips.yaml:/etc/fips/fips.yaml:ro
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-a/fips.key:/etc/fips/fips.key:ro
node-b:
<<: *fips-common
container_name: fips-ifb-node-b${FIPS_CI_NAME_SUFFIX:-}
hostname: host-b
volumes:
- ../docker/resolv.conf:/etc/resolv.conf:ro
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-b/fips.yaml:/etc/fips/fips.yaml:ro
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-b/fips.key:/etc/fips/fips.key:ro
# The clean-start case. Its interface exists before its daemon does, which is
# the ordinary state of a booted router and the one ordering node-a and
# node-b cannot produce: their interface is created after they are already
# running, so they can only ever bind through the binder loop.
#
# The gate is what buys that ordering. The harness needs a running container
# to have a netns to move a veth into, but the daemon must not start until
# after the move — so the container comes up, parks on this file, and the
# harness releases it once the interface is in place.
node-c:
<<: *fips-common
container_name: fips-ifb-node-c${FIPS_CI_NAME_SUFFIX:-}
hostname: host-c
entrypoint: ["/bin/sh", "-c"]
command:
- |
while [ ! -e /tmp/fips-go ]; do sleep 0.2; done
exec /usr/local/bin/entrypoint.sh
volumes:
- ../docker/resolv.conf:/etc/resolv.conf:ro
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-c/fips.yaml:/etc/fips/fips.yaml:ro
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-c/fips.key:/etc/fips/fips.key:ro