Part of the whole-repo test-suite audit (2026-09-30). These tests report green while asserting nothing, which makes every other result in the suite untrustworthy. Not production-code bugs.
What to build
Unit tests that run against fakes the repo already owns, and that cannot interfere with each other or with the host.
Findings
- The host firewall is wired into unit tests.
test_app_state() at crates/natmap/src/api.rs:949 builds a real IptablesManager (api.rs:952). Two tests then early-return on error, so they pass without asserting anything: add_dnat_duplicate_is_idempotent (api.rs:1067, if result.is_err() { return; }) and add_mapping_with_target_ip_success (api.rs:1163). crates/natmap/src/client.rs:219 (14 tests) and crates/natmap/src/daemon.rs:1047 do the same. FakeIptables already exists 120 lines away at daemon.rs:828, and test_app_state_with at daemon.rs:1027 already accepts an injected one. make_daemon with three fakes exists at daemon.rs:958 and is used by 24 tests in the same file.
- Real Docker socket plus a discarded error.
crates/auto-discover/src/daemon.rs:765,780 and crates/natmap/src/daemon.rs:1054,1067 build real clients (DockerClient, ConsulClient::from_env, NatmapClient::default_socket), run them with let _ = ....await discarding the error, then assert logs_contain("container.id=123456789012") — the literal the test itself passed in. They pass whether or not Docker exists. natmap/daemon.rs:1072 additionally .unwrap()s Docker::connect_with_local_defaults(), so it panics on any box without Docker.
- A test that asserts nothing at all.
tests/auto_discover/recovery.rs:476 large_config_many_services builds a shell script into let _script and returns. No run(), no assertion. It also duplicates registration.rs:391 concurrent_starts_all_registered, which does run.
- A silently skipped Docker test.
tests/natmap_docker.rs:189 does which ip6tables || (echo "SKIP: ..." && exit 0), so the test passes on any host without ip6tables and says nothing.
- An assertion helper that cannot fail.
tests/auto_discover/mod.rs:101 assert_pass checks output.contains("PASS"), but run() at mod.rs:44 already panics on non-zero exit and every script reaches its echo "PASS" only after its exit 1 checks. It is a tautology in 46 of 47 uses. Keep the helper only for the handful of tests that can genuinely soft-skip, and make those report SKIP visibly in cargo test output.
- Non-deterministic port allocation.
crates/lab-lib/src/port.rs:255,267,285 use "127.0.0.1:0", which asks the OS for any port, so each call allocates a different random one. Bind port 0, read the real port back, assert on that.
- Overlapping hardcoded port bands.
port.rs:219 uses 21000 + t*40 + i and crates/natmap/src/daemon.rs:952 uses 21000 + (pid % 400) * 24. They collide.
- Shared mutable state across tests.
crates/natmap/src/api.rs:955,959 and daemon.rs:1017,1036 hardcode /tmp/natmap-test-state.json and /tmp/natmap.sock for about 20 tests. client.rs:226 correctly overrides both with a tempfile::TempDir; api.rs:949 does not.
Acceptance criteria
Blocked by
Per the test-writing guidelines: a flaky test is worse than no test, because it erodes trust in the whole suite until failures are ignored. Do not add #[ignore] as a way out; use the existing fakes.
Part of the whole-repo test-suite audit (2026-09-30). These tests report green while asserting nothing, which makes every other result in the suite untrustworthy. Not production-code bugs.
What to build
Unit tests that run against fakes the repo already owns, and that cannot interfere with each other or with the host.
Findings
test_app_state()atcrates/natmap/src/api.rs:949builds a realIptablesManager(api.rs:952). Two tests then early-return on error, so they pass without asserting anything:add_dnat_duplicate_is_idempotent(api.rs:1067,if result.is_err() { return; }) andadd_mapping_with_target_ip_success(api.rs:1163).crates/natmap/src/client.rs:219(14 tests) andcrates/natmap/src/daemon.rs:1047do the same.FakeIptablesalready exists 120 lines away atdaemon.rs:828, andtest_app_state_withatdaemon.rs:1027already accepts an injected one.make_daemonwith three fakes exists atdaemon.rs:958and is used by 24 tests in the same file.crates/auto-discover/src/daemon.rs:765,780andcrates/natmap/src/daemon.rs:1054,1067build real clients (DockerClient,ConsulClient::from_env,NatmapClient::default_socket), run them withlet _ = ....awaitdiscarding the error, then assertlogs_contain("container.id=123456789012")— the literal the test itself passed in. They pass whether or not Docker exists.natmap/daemon.rs:1072additionally.unwrap()sDocker::connect_with_local_defaults(), so it panics on any box without Docker.tests/auto_discover/recovery.rs:476 large_config_many_servicesbuilds a shell script intolet _scriptand returns. Norun(), no assertion. It also duplicatesregistration.rs:391 concurrent_starts_all_registered, which does run.tests/natmap_docker.rs:189doeswhich ip6tables || (echo "SKIP: ..." && exit 0), so the test passes on any host without ip6tables and says nothing.tests/auto_discover/mod.rs:101 assert_passchecksoutput.contains("PASS"), butrun()atmod.rs:44already panics on non-zero exit and every script reaches itsecho "PASS"only after itsexit 1checks. It is a tautology in 46 of 47 uses. Keep the helper only for the handful of tests that can genuinely soft-skip, and make those report SKIP visibly incargo testoutput.crates/lab-lib/src/port.rs:255,267,285use"127.0.0.1:0", which asks the OS for any port, so each call allocates a different random one. Bind port 0, read the real port back, assert on that.port.rs:219uses21000 + t*40 + iandcrates/natmap/src/daemon.rs:952uses21000 + (pid % 400) * 24. They collide.crates/natmap/src/api.rs:955,959anddaemon.rs:1017,1036hardcode/tmp/natmap-test-state.jsonand/tmp/natmap.sockfor about 20 tests.client.rs:226correctly overrides both with atempfile::TempDir;api.rs:949does not.Acceptance criteria
#[cfg(test)] mod testsconstructsIptablesManager, connects to Docker, or reaches Consul over the networkcargo test -p lab-ops_natmap --libandcargo test -p lab-ops_auto-discover --libpass on a host with no Docker daemon and no iptables write permission/tmpcargo testoutput rather than passing silentlyBlocked by
Per the test-writing guidelines: a flaky test is worse than no test, because it erodes trust in the whole suite until failures are ignored. Do not add
#[ignore]as a way out; use the existing fakes.