Found by mutation testing while verifying the audit refactor (commit 0a1e63c). The suite is green, but a piece of the behaviour the Docker tests exist to verify is not actually verified there.
The experiment
Mutating build_masquerade_args in crates/natmap/src/iptables.rs:184 from MASQUERADE to ACCEPT — a real behaviour change, the POSTROUTING rule no longer masquerades:
cargo test -p lab-ops_natmap -> 1 FAILED (masquerade_args_matches_ctn_ip)
cargo test -p lab-ops --test natmap_docker -> 34 passed, 0 failed
The unit suite caught it. The Docker suite, whose whole reason for existing is to run privileged containers with real iptables, did not notice at all. The mutant was reverted and the tree is clean.
Why it matters
The audit already found 19 tests that pass vacuously (#44 covers those). This is the other half of the problem: a test that is green because it never checked. Here the gap is that the Docker harness greps for DNAT and never for the MASQUERADE rule it installs, so the one rule that makes source-IP preservation work end to end has no integration-level check.
What to build
The Docker suite asserting the rules it actually installs, not just the ones it greps for today.
Suggested: a mapping scenario that installs a Docker port mapping and then asserts the full rule set in iptables-save output — the DNAT, the FORWARD ACCEPT, the POSTROUTING MASQUERADE, and the comment. The two loopback-MASQUERADE tests that exist today (docker_mapping_loopback_host_installs_loopback_masquerade and its negative counterpart) are the closest model, so the assertion shape is already in the suite.
Acceptance criteria
Blocked by
None (can start immediately).
NixOS hosts need the OPENSSL_LIB_DIR and LD_LIBRARY_PATH exports from AGENTS.md to run this at all.
Found by mutation testing while verifying the audit refactor (commit
0a1e63c). The suite is green, but a piece of the behaviour the Docker tests exist to verify is not actually verified there.The experiment
Mutating
build_masquerade_argsincrates/natmap/src/iptables.rs:184fromMASQUERADEtoACCEPT— a real behaviour change, the POSTROUTING rule no longer masquerades:The unit suite caught it. The Docker suite, whose whole reason for existing is to run privileged containers with real iptables, did not notice at all. The mutant was reverted and the tree is clean.
Why it matters
The audit already found 19 tests that pass vacuously (#44 covers those). This is the other half of the problem: a test that is green because it never checked. Here the gap is that the Docker harness greps for
DNATand never for the MASQUERADE rule it installs, so the one rule that makes source-IP preservation work end to end has no integration-level check.What to build
The Docker suite asserting the rules it actually installs, not just the ones it greps for today.
Suggested: a mapping scenario that installs a Docker port mapping and then asserts the full rule set in
iptables-saveoutput — the DNAT, the FORWARD ACCEPT, the POSTROUTING MASQUERADE, and the comment. The two loopback-MASQUERADE tests that exist today (docker_mapping_loopback_host_installs_loopback_masqueradeand its negative counterpart) are the closest model, so the assertion shape is already in the suite.Acceptance criteria
MASQUERADE→ACCEPTmutation makes a Docker test fail. Demonstrate this; it is the acceptance criterion.contains)cargo test -p lab-ops --test natmap_docker --all-featuresstill passes 34/34 on a clean runBlocked by
None (can start immediately).
NixOS hosts need the
OPENSSL_LIB_DIRandLD_LIBRARY_PATHexports fromAGENTS.mdto run this at all.