mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
Building a Destination Unreachable or Packet Too Big and writing it to the TUN is host-side IPv6 work, but the send logic lived in the node's session handler. Move it to ipv6tun::icmp behind IcmpContext, which borrows the TUN channel, our address and the Packet Too Big rate limiter for the length of one use. Borrowing rather than holding a clone of the TUN sender keeps teardown able to close the channel. The logic is unchanged. Packet Too Big still consults the per-source limiter before anything else, and Destination Unreachable is still unlimited. The discovery lookup timeout now hands its queued packets to the context as one no-route report instead of sending one reply per packet itself. Node keeps send_icmpv6_dest_unreachable and send_icmpv6_packet_too_big as wrappers over the context, so the outbound handler and the tests that drive it are unchanged; the Destination Unreachable wrapper now takes &mut self because the context borrows the limiter. The two Packet Too Big debug lines now log under fips::ipv6tun::icmp instead of fips::node::handlers::session. Add that target to the test harness filters that relied on fips::node=debug or the session trace filter to show them, and note the rename in the changelog.
81 lines
3.4 KiB
YAML
81 lines
3.4 KiB
YAML
networks:
|
|
# Management bridge only. The FIPS transport under test is raw Ethernet on a
|
|
# veth pair the harness creates *after* the daemons are already running —
|
|
# that is the whole point of the suite — so no FIPS traffic crosses this
|
|
# network. No subnet is requested, so two concurrent runs cannot collide on
|
|
# one address range.
|
|
#
|
|
# The compose project name is still fixed, so two runs that do not set
|
|
# COMPOSE_PROJECT_NAME share a project and the second `up` recreates the
|
|
# first's containers. The local CI runner scopes it externally
|
|
# (run_iface_binding in ci-local.sh); a bare hand run does not.
|
|
ifb-net:
|
|
driver: bridge
|
|
labels:
|
|
- "com.corganlabs.fips-ci=1"
|
|
|
|
x-fips-common: &fips-common
|
|
build:
|
|
# The harness scopes its build context per run and passes it here; the
|
|
# shared directory is the hand-run default. Compose resolves a relative
|
|
# value against THIS file's directory, so the harness must export an
|
|
# absolute path.
|
|
context: ${FIPS_BUILD_CONTEXT:-../docker}
|
|
image: ${FIPS_TEST_IMAGE:-fips-test:latest}
|
|
entrypoint: ["/usr/local/bin/entrypoint.sh"]
|
|
cap_add:
|
|
- NET_ADMIN
|
|
- NET_RAW
|
|
restart: "no"
|
|
environment:
|
|
# `default`, deliberately — NOT `chaos`. The chaos entrypoint waits up to
|
|
# 30 s for every configured Ethernet interface to appear before it starts
|
|
# the daemon, which is precisely the workaround this mechanism retires. The
|
|
# daemon must do its own waiting here or the suite proves nothing.
|
|
- FIPS_TEST_MODE=default
|
|
- RUST_LOG=info,fips::transport::ethernet=debug,fips::node=debug,fips::ipv6tun::icmp=debug
|
|
networks:
|
|
- ifb-net
|
|
|
|
services:
|
|
node-a:
|
|
<<: *fips-common
|
|
container_name: fips-ifb-node-a${FIPS_CI_NAME_SUFFIX:-}
|
|
hostname: host-a
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-a/fips.yaml:/etc/fips/fips.yaml:ro
|
|
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-a/fips.key:/etc/fips/fips.key:ro
|
|
|
|
node-b:
|
|
<<: *fips-common
|
|
container_name: fips-ifb-node-b${FIPS_CI_NAME_SUFFIX:-}
|
|
hostname: host-b
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-b/fips.yaml:/etc/fips/fips.yaml:ro
|
|
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-b/fips.key:/etc/fips/fips.key:ro
|
|
|
|
# The clean-start case. Its interface exists before its daemon does, which is
|
|
# the ordinary state of a booted router and the one ordering node-a and
|
|
# node-b cannot produce: their interface is created after they are already
|
|
# running, so they can only ever bind through the binder loop.
|
|
#
|
|
# The gate is what buys that ordering. The harness needs a running container
|
|
# to have a netns to move a veth into, but the daemon must not start until
|
|
# after the move — so the container comes up, parks on this file, and the
|
|
# harness releases it once the interface is in place.
|
|
node-c:
|
|
<<: *fips-common
|
|
container_name: fips-ifb-node-c${FIPS_CI_NAME_SUFFIX:-}
|
|
hostname: host-c
|
|
entrypoint: ["/bin/sh", "-c"]
|
|
command:
|
|
- |
|
|
while [ ! -e /tmp/fips-go ]; do sleep 0.2; done
|
|
exec /usr/local/bin/entrypoint.sh
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-c/fips.yaml:/etc/fips/fips.yaml:ro
|
|
- ./generated-configs${FIPS_CI_NAME_SUFFIX:-}/node-c/fips.key:/etc/fips/fips.key:ro
|