Skip to content

LXC: live E2E for schema 0.8 directional egress covers only IPv4 #1001

Description

Raised on #983 independently by Branden Bonaby (@bbonaby) (marked for follow-up) and Soham Das (@SohamDas2021) (marked non-blocking).

What is covered today

tests/scripts/run_lxc_network_ga_egress_test.sh exercises the directional egress path against a real LXC container, and every case in it is IPv4.

What is not

  • IPv6 directional peers. The existing live IPv6 test uses the legacy host-list shape, so the parser-to-ip6tables path for a directional peer is covered only by unit assertions.
  • ICMP and ICMPv6 selectors.
  • Port ranges (port with endPort).
  • protocol: any.

These are rule-level assertions only. Nothing proves the argument vectors the unit tests check actually produce the intended behavior on a live host.

Suggested shape

Add live cases to the GA egress script covering at least one IPv6 allow and one IPv6 deny with directional peers, plus one ICMP case and one port-range case. Wire them into tests/scripts/run_lxc_all_tests.sh alongside the existing entry.

Activity

  1. added
    Area-TestShared test infrastructure, fixtures, harnesses, probes, or end-to-end validation.
    Backend-ProcessContainerWindows ProcessContainer behavior, including BaseContainer and AppContainer isolation tiers.
    OS-LinuxApplies specifically to Linux hosts or Linux behavior.
    on Aug 22, 2026
  2. github-actions commented on Aug 22, 2026

    @github-actions

    Triage complete.

    Labels applied: OS-Linux, Container-Process, Area-Test-Executor

    Assigned: @SohamDas2021 (Linux/LXC owner) and @theelliotm (executor test infrastructure owner)

    This issue tracks missing live E2E coverage for schema 0.8 directional egress on LXC: IPv6 peers, ICMP/ICMPv6, port ranges, and protocol: any are currently covered only by unit assertions and need live cases in run_lxc_network_ga_egress_test.sh.

    Maintainers: Comment /investigate to check whether this issue or bug is valid against the most current code. Copilot will also produce a report with the changes that will be needed. For a small, unambiguous documentation or test fix, it may also create one draft PR.

    Generated by 🏷️ Issue Triage for #1001 · sonnet46 · 20.2 AIC · ⌖ 5.4 AIC · ⊞ 7.6K · ◷

  3. added
    Issue-TaskEngineering, maintenance, or operational work that is not a bug or feature request.
    Priority2High-impact issue affecting key functionality; prioritize for the next appropriate release.
    on Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Area-TestShared test infrastructure, fixtures, harnesses, probes, or end-to-end validation.Backend-ProcessContainerWindows ProcessContainer behavior, including BaseContainer and AppContainer isolation tiers.Issue-TaskEngineering, maintenance, or operational work that is not a bug or feature request.OS-LinuxApplies specifically to Linux hosts or Linux behavior.Priority2High-impact issue affecting key functionality; prioritize for the next appropriate release.

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions