Files
fips/testing/mesh-lab/compose-trace.yml
T
Johnathan Corgan f444457270 Move ICMPv6 error sending toward the host into ipv6tun
Building a Destination Unreachable or Packet Too Big and writing it to
the TUN is host-side IPv6 work, but the send logic lived in the node's
session handler. Move it to ipv6tun::icmp behind IcmpContext, which
borrows the TUN channel, our address and the Packet Too Big rate
limiter for the length of one use. Borrowing rather than holding a
clone of the TUN sender keeps teardown able to close the channel.

The logic is unchanged. Packet Too Big still consults the per-source
limiter before anything else, and Destination Unreachable is still
unlimited. The discovery lookup timeout now hands its queued packets to
the context as one no-route report instead of sending one reply per
packet itself. Node keeps send_icmpv6_dest_unreachable and
send_icmpv6_packet_too_big as wrappers over the context, so the outbound
handler and the tests that drive it are unchanged; the Destination
Unreachable wrapper now takes &mut self because the context borrows the
limiter.

The two Packet Too Big debug lines now log under fips::ipv6tun::icmp
instead of fips::node::handlers::session. Add that target to the test
harness filters that relied on fips::node=debug or the session trace
filter to show them, and note the rename in the changelog.
2026-09-24 14:12:26 +00:00

77 lines
3.1 KiB
YAML

# Compose override that bumps RUST_LOG to trace level on the modules
# relevant to rekey-class flake evidence collection:
#
# - fips::node::handlers::rekey — FMP/FSP rekey state machine
# - fips::node::handlers::handshake — Noise handshake (cross-init,
# dual-init, msg1/2/3 dispatch)
# - fips::node::dataplane::forwarding — transit datagram forwarding,
# route lookup, drops
# - fips::node::handlers::session — FSP K-bit cutover, drain
# - fips::node::dataplane::encrypted — FMP K-bit flip detection
# - fips::node::handlers::mmp — link liveness, SRTT, ETX
# - fips::ipv6tun::icmp — ICMPv6 Packet Too Big toward
# the host (formerly logged
# under handlers::session)
#
# Other modules stay at info to keep log volume manageable. The base
# docker-compose.yml's per-service RUST_LOG values (currently
# `info,fips::node::handlers::rekey=debug` for the rekey profile, plus
# handshake=debug on the variant profiles) are fully replaced by the
# values below via the YAML map form: docker compose's override
# semantics replace the map entry rather than merging individual
# environment keys.
#
# Service-name layout follows the base compose: per-profile services
# named `<profile>-<node-letter>` (rekey-a..e for the rekey profile,
# rekey-accept-off-a..e for the accept-off variant,
# rekey-outbound-only-a..e for the outbound-only variant). All 15
# rekey-family services get the same trace-RUST_LOG value.
#
# Include this override alongside the base compose via:
# docker compose -f testing/static/docker-compose.yml \
# -f testing/mesh-lab/compose-resource-limits.yml \
# -f testing/mesh-lab/compose-trace.yml up -d
#
# The run-loop.sh harness includes it automatically when the mesh-lab
# environment variable FIPS_MESH_LAB_TRACE=1 is set.
x-trace-rust-log: &trace-rust-log
RUST_LOG: "info,fips::node::handlers::rekey=trace,fips::node::handlers::handshake=trace,fips::node::dataplane::forwarding=trace,fips::node::handlers::session=trace,fips::node::dataplane::encrypted=trace,fips::node::handlers::mmp=trace,fips::ipv6tun::icmp=trace"
services:
# rekey profile
rekey-a:
environment: *trace-rust-log
rekey-b:
environment: *trace-rust-log
rekey-c:
environment: *trace-rust-log
rekey-d:
environment: *trace-rust-log
rekey-e:
environment: *trace-rust-log
# rekey-accept-off profile
rekey-accept-off-a:
environment: *trace-rust-log
rekey-accept-off-b:
environment: *trace-rust-log
rekey-accept-off-c:
environment: *trace-rust-log
rekey-accept-off-d:
environment: *trace-rust-log
rekey-accept-off-e:
environment: *trace-rust-log
# rekey-outbound-only profile
rekey-outbound-only-a:
environment: *trace-rust-log
rekey-outbound-only-b:
environment: *trace-rust-log
rekey-outbound-only-c:
environment: *trace-rust-log
rekey-outbound-only-d:
environment: *trace-rust-log
rekey-outbound-only-e:
environment: *trace-rust-log