test(gate): install iproute2 in the docker lane — without ip every slot is free
test / go + panel tests (push) Successful in 15m18s
release / test gate (push) Successful in 10m57s
release / apk aarch64_cortex-a53 (push) Successful in 5m52s
release / apk x86_64 (push) Failing after 28s
release / release apk (push) Successful in 6s

This change was already in the working tree when this session started; it is
committed here because it is load-bearing and an uncommitted load-bearing file
is a trap.

netplane.L3SlotFor asks the kernel through `ip link show` and reclaims through
`ip link del`. golang:1.26 ships no iproute2, so in the docker re-exec lane
every slot read as FREE, TestIntegrationL3StaleSlotIsReclaimed stood itself
down rather than pass while proving the opposite of what it claims, and [5/7]
then failed the gate — correctly, since this environment HAS root and
/dev/net/tun and the capability guard is therefore not what skipped it.

Installing it is also what made the concurrent-namespace defect visible at all
(see 06c04c157): with no `ip` on PATH, no `ip link del` was ever issued and the
two test binaries that were destroying shater/generate's TUN looked innocent.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BHw89tdWddzhjUc4bAH4tS
This commit is contained in:
2026-07-27 03:25:58 +03:00
co-authored by Claude Opus 5
parent 06c04c157d
commit e38108a7c4
+16 -1
View File
@@ -301,7 +301,22 @@ if [ "$(go env GOOS)" != "linux" ] && [ "${SHATER_TESTS_IN_DOCKER:-0}" != "1" ];
-w /src \
-e SHATER_TESTS_IN_DOCKER=1 \
-e SHATER_REQUIRE_PRIVILEGED="${SHATER_REQUIRE_PRIVILEGED:-0}" \
"$image" bash scripts/run-tests.sh "$@"
"$image" bash -c '
# netplane.L3SlotFor asks the kernel through `ip link show` and reclaims a
# stale slot through `ip link del`. Without iproute2 EVERY slot reads as
# free, so TestIntegrationL3StaleSlotIsReclaimed refuses to run rather than
# pass while proving the opposite of what it claims — and [5/7] then fails
# the whole gate, correctly. golang:1.26 ships no iproute2, so install it
# here rather than let the image quietly narrow what this gate can verify.
# On a Linux host the script never re-execs, and the router has ip-full as
# a hard dependency, so this is the docker path only.
if ! command -v ip >/dev/null 2>&1; then
echo " iproute2: absent from '"$image"' — installing (the slot-reclaim test needs it)"
apt-get update -qq >/dev/null 2>&1 && apt-get install -y -qq iproute2 >/dev/null 2>&1 \
|| echo " iproute2: INSTALL FAILED — [5/7] will report the gap by name"
fi
exec bash scripts/run-tests.sh "$@"
' _ "$@"
docker_rc=$?
if [ "$host_js_rc" -ne 0 ]; then
echo "== TEST GATE FAILED — a non-Go suite failed on the host (see [7/7] above). ==" >&2