integration: block reused HA ping callback connections

Updates #3517
This commit is contained in:
Kristoffer Dalby
2026-10-07 09:43:59 +00:00
parent b8146aa7cd
commit 8c66b76353
+8 -5
View File
@@ -3649,8 +3649,11 @@ func TestHASubnetRouterPingFailover(t *testing.T) {
[]tsic.Option{
tsic.WithAcceptRoutes(),
tsic.WithPackages("iptables"),
tsic.WithDERPOverHTTP(),
},
hsic.WithTestName("rt-hapingfail"),
// The firewall matches the callback path while Noise remains encrypted.
hsic.WithoutTLS(),
hsic.WithHAProbing(10*time.Second, 5*time.Second),
)
requireNoErrHeadscaleEnv(t, err)
@@ -3759,21 +3762,21 @@ func TestHASubnetRouterPingFailover(t *testing.T) {
t.Log("=== HA setup verified. Blocking ping callbacks on router 1 via iptables ===")
// Block NEW outbound TCP from router 1 to headscale.
// Preserves the existing Noise HTTP/2 long-poll (ESTABLISHED).
// Block plaintext ping callbacks, including requests on reused HTTP
// connections. The encrypted Noise long-poll remains available.
hsIP := headscale.GetIPInNetwork(usernet1)
iptablesAdd := []string{
"iptables", "-A", "OUTPUT",
"-d", hsIP,
"-p", "tcp", "--dport", "8080",
"-m", "state", "--state", "NEW",
"-m", "string", "--algo", "kmp", "--string", "/machine/ping-response",
"-j", "DROP",
}
_, _, err = subRouter1.Execute(iptablesAdd)
require.NoError(t, err, "failed to add iptables rule")
t.Logf("Blocked new TCP connections from %s to headscale at %s:8080",
t.Logf("Blocked ping callbacks from %s to headscale at %s:8080",
subRouter1.Hostname(), hsIP)
// Wait for the prober to detect the failure and trigger failover.
@@ -3818,7 +3821,7 @@ func TestHASubnetRouterPingFailover(t *testing.T) {
"iptables", "-D", "OUTPUT",
"-d", hsIP,
"-p", "tcp", "--dport", "8080",
"-m", "state", "--state", "NEW",
"-m", "string", "--algo", "kmp", "--string", "/machine/ping-response",
"-j", "DROP",
}