Skip to content

The Docker suite does not cover the MASQUERADE rule it is named for #51

Description

@FAZuH

Found by mutation testing while verifying the audit refactor (commit 0a1e63c). The suite is green, but a piece of the behaviour the Docker tests exist to verify is not actually verified there.

The experiment

Mutating build_masquerade_args in crates/natmap/src/iptables.rs:184 from MASQUERADE to ACCEPT — a real behaviour change, the POSTROUTING rule no longer masquerades:

cargo test -p lab-ops_natmap                    -> 1 FAILED (masquerade_args_matches_ctn_ip)
cargo test -p lab-ops --test natmap_docker      -> 34 passed, 0 failed

The unit suite caught it. The Docker suite, whose whole reason for existing is to run privileged containers with real iptables, did not notice at all. The mutant was reverted and the tree is clean.

Why it matters

The audit already found 19 tests that pass vacuously (#44 covers those). This is the other half of the problem: a test that is green because it never checked. Here the gap is that the Docker harness greps for DNAT and never for the MASQUERADE rule it installs, so the one rule that makes source-IP preservation work end to end has no integration-level check.

What to build

The Docker suite asserting the rules it actually installs, not just the ones it greps for today.

Suggested: a mapping scenario that installs a Docker port mapping and then asserts the full rule set in iptables-save output — the DNAT, the FORWARD ACCEPT, the POSTROUTING MASQUERADE, and the comment. The two loopback-MASQUERADE tests that exist today (docker_mapping_loopback_host_installs_loopback_masquerade and its negative counterpart) are the closest model, so the assertion shape is already in the suite.

Acceptance criteria

  • Re-applying the MASQUERADE → ACCEPT mutation makes a Docker test fail. Demonstrate this; it is the acceptance criterion.
  • The rule set asserted is the full set the daemon installs for a mapping, not a substring of it
  • The test is falsifiable: no early return, no soft skip, no assertion that passes on a host without the rule
  • Consistent with the argv-assertion work in Table-drive the parse_port_mappings and iptables argv tests #45 (exact comparison, not contains)
  • cargo test -p lab-ops --test natmap_docker --all-features still passes 34/34 on a clean run

Blocked by

None (can start immediately).

NixOS hosts need the OPENSSL_LIB_DIR and LD_LIBRARY_PATH exports from AGENTS.md to run this at all.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ready-for-agentFully specified, ready for an AFK agent

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions