{
 "number": 31349,
 "repo": "bitcoin/bitcoin",
 "url": "https://github.com/bitcoin/bitcoin/pull/31349",
 "title": "ci: detect outbound internet traffic generated while running tests",
 "author": "vasild",
 "author_association": "MEMBER",
 "created_at": "2024-11-22T13:58:43Z",
 "updated_at": "2026-09-15T23:48:56Z",
 "age_days": 664,
 "draft": false,
 "labels": [
  "Tests"
 ],
 "milestone": null,
 "base": "master",
 "head_sha": "84bb496c6165154a64fcccd31e6ca5354531fd60",
 "head_ref": "test_log_internet_traffic",
 "head_repo": "vasild/bitcoin",
 "head_history": [
  {
   "t": "2024-11-22T14:12:21Z",
   "sha": "3ec89f41d8997df475dabb5ae0b56b0646b01569"
  },
  {
   "t": "2024-11-25T09:08:40Z",
   "sha": "3c4b2035e1fc3b52741a6483b3ce5ee7ccb62110"
  },
  {
   "t": "2024-11-25T09:39:28Z",
   "sha": "67c6bce2405a616a83bdf662303800ad57b80ef1"
  },
  {
   "t": "2024-11-25T12:00:35Z",
   "sha": "1592a7dad4a92b28a7ea38988f4338733041c17f"
  },
  {
   "t": "2024-11-25T16:05:12Z",
   "sha": "071e43ffae892a0c2da68afcb784504bc7fef570"
  },
  {
   "t": "2024-11-27T15:40:38Z",
   "sha": "8799018bd58e51fa6fa4e7e9f8d7715713567165"
  },
  {
   "t": "2024-11-27T17:27:48Z",
   "sha": "803ed4638b7260139ce156fa39d21c4d626c9873"
  },
  {
   "t": "2024-11-28T17:30:41Z",
   "sha": "54a6884db40e56c7db547a98aa990a9d14b42bfa"
  },
  {
   "t": "2024-11-29T11:46:43Z",
   "sha": "f2b3b8d7d5403eb91cd167a874664d43653cd4da"
  },
  {
   "t": "2024-11-29T12:30:10Z",
   "sha": "6d1c27de47bf7898486399662519defef8b20903"
  },
  {
   "t": "2024-11-29T13:56:11Z",
   "sha": "eb50e89e31f693983dcfcaf80b152c6ebf2d93a2"
  },
  {
   "t": "2024-12-02T10:43:18Z",
   "sha": "9c01e101dd2cd660b21d1a009e9085afb19d999f"
  },
  {
   "t": "2024-12-02T12:43:35Z",
   "sha": "57924f4a75862b2bcfa01051a0140bdaf8b35446"
  },
  {
   "t": "2024-12-02T16:04:49Z",
   "sha": "b241a913e85e80deca78e442551a9aaafda70001"
  },
  {
   "t": "2024-12-03T08:33:02Z",
   "sha": "c88464d7549415cb51a0f93a86c567f86e521b2e"
  },
  {
   "t": "2024-12-04T10:26:10Z",
   "sha": "feabffd80878e215bf7709e180895f26279051cc"
  },
  {
   "t": "2024-12-04T13:44:43Z",
   "sha": "925ee8707e5a1b9c527be29438602b238bd40abd"
  },
  {
   "t": "2024-12-05T08:16:31Z",
   "sha": "56dbe78934d7e20d51c4559d94e1a29fecb9bc6f"
  },
  {
   "t": "2024-12-05T08:57:47Z",
   "sha": "5f3b24711e041690071442463b35db8ad7545ed6"
  },
  {
   "t": "2024-12-05T09:54:09Z",
   "sha": "a6c3c9defbcc30692aa001b334a06632a9e4347d"
  },
  {
   "t": "2024-12-11T05:22:43Z",
   "sha": "46e38e2e33b79da1de50e6b3c1013b9ebf64c3f9"
  },
  {
   "t": "2024-12-17T13:03:58Z",
   "sha": "95fc90610a1162fc06e61b607488d05229c9909f"
  },
  {
   "t": "2024-12-23T18:41:42Z",
   "sha": "0ac9caf7beb6bc6e7680b0fe386d0ed71794decc"
  },
  {
   "t": "2024-12-23T18:47:51Z",
   "sha": "d8cd80e8148195e916042113d426e2a5fcad45dd"
  },
  {
   "t": "2024-12-24T08:39:45Z",
   "sha": "48843ec694110c9fadb92cdf263cf73bbd462ad9"
  },
  {
   "t": "2025-01-06T13:36:44Z",
   "sha": "bbfc58a0af80265a9a53f5956f88c1915a686a7e"
  },
  {
   "t": "2025-01-15T08:21:27Z",
   "sha": "69e076664d4fbc9c10a34dad4631ebd1139fa25d"
  },
  {
   "t": "2025-02-21T07:53:27Z",
   "sha": "76feae207dc1095d71f7efe7766ec8959eda81c8"
  },
  {
   "t": "2025-04-16T14:33:23Z",
   "sha": "4652f75bbfbe879f95dfa78d9fb4352137af3c76"
  },
  {
   "t": "2025-09-04T08:23:52Z",
   "sha": "f400e0bb82920adf50fec1b9d701e8e85e62030a"
  },
  {
   "t": "2025-09-04T12:53:11Z",
   "sha": "9dcbf6ccded636d78dca43b5cb920c206a89c7d8"
  },
  {
   "t": "2025-09-04T13:06:00Z",
   "sha": "a9ac49c8accffeffaae72f54021fd939c951844c"
  },
  {
   "t": "2025-09-04T15:29:24Z",
   "sha": "778675ac717586407f2eee6ffd9ec41f2a3b1fdb"
  },
  {
   "t": "2025-09-08T10:15:46Z",
   "sha": "151edfaf78115402c29088dabc271c2b268102a5"
  },
  {
   "t": "2025-09-26T12:44:17Z",
   "sha": "f4fdf81d3a1811561ed35d6ce2424978be284d51"
  },
  {
   "t": "2025-09-30T12:36:36Z",
   "sha": "39f90a4a78020087d19491be7b315ad91f252e46"
  },
  {
   "t": "2025-09-30T14:14:54Z",
   "sha": "c652deb3c16b7edccb741b9b473502092c0c2638"
  },
  {
   "t": "2025-10-16T08:59:44Z",
   "sha": "6e0f3a4a58916301bbf3e38242e97d8d3408d47f"
  },
  {
   "t": "2025-11-20T07:19:45Z",
   "sha": "47f4f65d0c8ba4680bab45b085939ace9624f3a2"
  },
  {
   "t": "2026-02-04T14:36:08Z",
   "sha": "31e20d76eefdb8800acbed7cd71a5c86556396c7"
  },
  {
   "t": "2026-02-04T17:18:00Z",
   "sha": "23605aa86ce05da8c9eb9d3598a749898dba70d6"
  },
  {
   "t": "2026-05-01T10:08:36Z",
   "sha": "17492c744cf37e7619a5b9dd7946013fa2e14d15"
  },
  {
   "t": "2026-05-15T09:42:21Z",
   "sha": "c7e331d5fc82378c84f056eb6703c9712d451ed1"
  },
  {
   "t": "2026-05-15T10:15:21Z",
   "sha": "f439badbefd4f96a83e161f991a326924cdbb3a6"
  },
  {
   "t": "2026-06-18T11:12:03Z",
   "sha": "ac04209081e915ec96f5ef3a6140f2233594aea8"
  },
  {
   "t": "2026-06-18T12:31:58Z",
   "sha": "84bb496c6165154a64fcccd31e6ca5354531fd60"
  }
 ],
 "additions": 77,
 "deletions": 2,
 "changed_files": 6,
 "commit_count": 1,
 "size_bucket": "S",
 "mergeable_state": "clean",
 "bot": {
  "drahtbot": {
   "present": true,
   "reviews": {
    "concept_ack": [
     {
      "login": "laanwj",
      "url": "https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-2497252843"
     },
     {
      "login": "jonatack",
      "url": "https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-2500872083"
     },
     {
      "login": "BrandonOdiwuor",
      "url": "https://github.com/bitcoin/bitcoin/pull/31349#pullrequestreview-2465656461"
     },
     {
      "login": "sipa",
      "url": "https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-2559801865"
     },
     {
      "login": "Sjors",
      "url": "https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-2586797138"
     },
     {
      "login": "1440000bytes",
      "url": "https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-2500761664"
     },
     {
      "login": "maflcko",
      "url": "https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-4380459750"
     }
    ],
    "stale_ack": [
     {
      "login": "0xB10C",
      "url": "https://github.com/bitcoin/bitcoin/pull/31349#pullrequestreview-2518644005"
     },
     {
      "login": "fjahr",
      "url": "https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-3353839249"
     },
     {
      "login": "ryanofsky",
      "url": "https://github.com/bitcoin/bitcoin/pull/31349#pullrequestreview-3589303104"
     }
    ]
   },
   "conflicts": [
    {
     "number": 36252,
     "title": "ci, iwyu: skip subtrees in compilation database",
     "author": "ryanofsky"
    },
    {
     "number": 35762,
     "title": "test: optionally run functional tests via CTest",
     "author": "willcl-ark"
    }
   ]
  }
 },
 "acks_parsed": {
  "laanwj": {
   "kind": "concept_ack",
   "hash": null,
   "t": "2024-11-25T08:33:30Z",
   "stale": false
  },
  "1440000bytes": {
   "kind": "concept_ack",
   "hash": null,
   "t": "2024-11-26T13:09:08Z",
   "stale": false
  },
  "jonatack": {
   "kind": "concept_ack",
   "hash": null,
   "t": "2024-11-26T13:57:02Z",
   "stale": false
  },
  "BrandonOdiwuor": {
   "kind": "concept_ack",
   "hash": null,
   "t": "2024-11-27T17:44:26Z",
   "stale": false
  },
  "0xB10C": {
   "kind": "ack",
   "hash": "95fc90610a1162fc06e61b607488d05229c9909f",
   "t": "2024-12-21T12:27:10Z",
   "stale": true
  },
  "sipa": {
   "kind": "concept_ack",
   "hash": null,
   "t": "2024-12-23T14:24:50Z",
   "stale": false
  },
  "fjahr": {
   "kind": "ack",
   "hash": "c652deb3c16b7edccb741b9b473502092c0c2638",
   "t": "2025-09-30T21:18:28Z",
   "stale": true
  },
  "Sjors": {
   "kind": "concept_ack",
   "hash": null,
   "t": "2025-01-13T11:01:41Z",
   "stale": false
  },
  "ryanofsky": {
   "kind": "ack",
   "hash": "47f4f65d0c8ba4680bab45b085939ace9624f3a2",
   "t": "2025-12-17T19:21:32Z",
   "stale": true
  }
 },
 "acks_tally": {
  "ack": 0,
  "stale_ack": 3,
  "concept_ack": 6,
  "approach_ack": 0,
  "nack": 0,
  "concept_nack": 0,
  "approach_nack": 0
 },
 "reviews": {
  "approved": 6,
  "changes_requested": 0,
  "distinct_reviewers": [
   "0xB10C",
   "1440000bytes",
   "BrandonOdiwuor",
   "Sjors",
   "fanquake",
   "fjahr",
   "jonatack",
   "laanwj",
   "luke-jr",
   "maflcko",
   "ryanofsky",
   "sedited",
   "sipa"
  ]
 },
 "signals": {
  "needs_rebase": false,
  "ci_failed": false,
  "mergeable_state": "clean",
  "last_author_activity": "2026-06-18T12:34:27Z",
  "last_reviewer_activity": "2026-08-28T18:38:15Z",
  "last_reviewer": "fjahr",
  "author_silent_days": 91,
  "waiting_on_author_days": 19,
  "days_since_update": 1
 },
 "refs": {
  "mentioned": [
   31343
  ],
  "depends_on": [],
  "fixes": [],
  "linked_issues": [],
  "references": [
   {
    "number": 31343,
    "type": "pull",
    "state": "closed",
    "merged": true,
    "merged_at": "2024-12-11",
    "title": "test: avoid internet traffic in rpc_net.py"
   }
  ],
  "conflicts": [
   36252,
   35762
  ]
 },
 "stack": {
  "shares_commits_with": [],
  "based_on": [],
  "base_for": []
 },
 "review_paths": [
  "ci/test/03_test_script.sh",
  "src/test/node_init_tests.cpp",
  "src/test/util/setup_common.cpp"
 ],
 "body": "Prevent generating outbound traffic on a non-loopback interface during tests.\n\n* Fix `node_init_tests/init_test`\n* Change CI to catch new regressions, including DNS traffic. DNS traffic is detected because some VMs have configured a non-loopback DNS server, `[1111:1111::1]:53`. This is achieved by running `tcpdump` during tests and inspecting its output after the tests. Add `--cap-add NET_RAW` to docker to be able to run `tcpdump`.\n\nResolves https://github.com/bitcoin/bitcoin/issues/31339",
 "commits": [
  {
   "sha": "84bb496c6165154a64fcccd31e6ca5354531fd60",
   "date": "2026-06-18T12:31:19Z",
   "message": "ci: detect outbound internet traffic generated while running tests\n\nResolves https://github.com/bitcoin/bitcoin/issues/31339"
  }
 ],
 "timeline": [
  {
   "t": "2024-11-22T14:12:21Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "3ec89f41d8997df475dabb5ae0b56b0646b01569"
  },
  {
   "t": "2024-11-22T14:17:35Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "Nice. Conecpt ACK!"
  },
  {
   "t": "2024-11-25T08:33:30Z",
   "kind": "comment",
   "who": "laanwj",
   "assoc": "MEMBER",
   "text": "Concept ACK\n\ni'm slightly worried this may generate false positive. As is, this detects traffic on the entire (virtual) machine while running the tests. Are there no other daemons running on the CI instance that could interfere with this?"
  },
  {
   "t": "2024-11-25T09:08:40Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "3c4b2035e1fc3b52741a6483b3ce5ee7ccb62110"
  },
  {
   "t": "2024-11-25T09:08:56Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "@laanwj, Right! And `ps ax` in the VM looks suspiciously scarce: https://github.com/bitcoin/bitcoin/issues/31339#issuecomment-2491003878 showing just `bash` and `03_test_script.sh`.\n\nAnother source of false positive could be if somebody from the outside initiates communication to the VM to which it responds. E.g. an outsider tries to connect to the VM to which it responds with an outbound packet e.g. TCP RST. At least that should be obvious from the error log, showing the incoming packet first (I just pushed a slight change for that). Maybe also the traffic-from-another-daemon could be obvious - e.g. if there is traffic to `apt.update.ubuntu.com:443`..."
  },
  {
   "t": "2024-11-25T09:39:28Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "67c6bce2405a616a83bdf662303800ad57b80ef1"
  },
  {
   "t": "2024-11-25T12:00:35Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "1592a7dad4a92b28a7ea38988f4338733041c17f"
  },
  {
   "t": "2024-11-25T15:07:46Z",
   "kind": "comment",
   "who": "laanwj",
   "assoc": "MEMBER",
   "text": "[quoted text omitted]\n\nExactly. For all we know, the CI VM is firewalled off sufficiently that this can't happen, but we don't know.\n\n[quoted text omitted]\nAh yes, as long as it's only some extra logging, having a manual factor in this is fine. It only becomes critical if network traffic would cause a CI failure.\n\ni'm not aware of a straightforward way to \"log network traffic of this process and subproceses only\". Yes, it could be done with a linux network namespace, but that's a lot of hassle.\n\n[quoted text omitted]\nSeeing this, it might already be namespaced. Though a process namespace doesn't necessarily mean the network namespace is isolated."
  },
  {
   "t": "2024-11-25T16:05:12Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "071e43ffae892a0c2da68afcb784504bc7fef570"
  },
  {
   "t": "2024-11-25T16:12:04Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`1592a7dad4...071e43ffae`: fix `feature_config_args.py` and `p2p_seednode.py` to not generate non-loopback traffic.\n\n[quoted text omitted]\nMy intention here is to fail the CI because otherwise the log will be buried in the CI output and nobody will notice it. It follows that if this fails randomly with false positives when one would have to investigate it manually for arbitrary PRs which is highly highly highly undesirable."
  },
  {
   "t": "2024-11-25T16:25:46Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": null,
   "text": "The return code is ignored, which is why CI passed, despite the tests calling out"
  },
  {
   "t": "2024-11-26T00:55:16Z",
   "kind": "comment",
   "who": "0xB10C",
   "assoc": "MEMBER",
   "text": "Ran this on my CI runner which has 8.8.8.8 configured as DNS server for docker.\n\nhttps://cirrus-ci.com/task/5500763260059648?logs=ci#L1137\n\n```\n[00:46:26.215] + tcpdump -n -r /tmp/tcpdump_eth0 tcp or udp\n[00:46:26.219] 00:42:50.052764 IP 172.18.0.2.46566 > 8.8.8.8.53: 39301+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:50.053181 IP 172.18.0.2.58686 > 8.8.8.8.53: 36487+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:50.059038 IP 8.8.8.8.53 > 172.18.0.2.46566: 39301 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:50.060121 IP 8.8.8.8.53 > 172.18.0.2.58686: 36487 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:50.060574 IP 172.18.0.2.34312 > 8.8.8.8.53: 25243+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:50.060939 IP 172.18.0.2.47040 > 8.8.8.8.53: 63641+ AAAA? x9.dummySeed.invalid. (38)\n...\n```\n\nEdit: My understanding is as follows: The DNS requests normally go to a local DNS resolver which then asks an upstream resolver. The upstream resolver (possibly your ISP) indirectly learns that you are running Bitcoin Core tests, even if there was no direct communication over a non-loopback interface.\n\nEdit 2: full tcpdump output here:\n\n```\n[00:46:26.209] ++ tcpdump -n -r /tmp/tcpdump_eth0 --direction=out tcp or udp\n[00:46:26.213] reading from file /tmp/tcpdump_eth0, link-type EN10MB (Ethernet), snapshot length 262144\n[00:46:26.215] + '[' -n '00:42:50.052764 IP 172.18.0.2.46566 > 8.8.8.8.53: 39301+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:50.053181 IP 172.18.0.2.58686 > 8.8.8.8.53: 36487+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:50.059038 IP 8.8.8.8.53 > 172.18.0.2.46566: 39301 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:42:50.060121 IP 8.8.8.8.53 > 172.18.0.2.58686: 36487 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:42:50.060574 IP 172.18.0.2.34312 > 8.8.8.8.53: 25243+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:50.060939 IP 172.18.0.2.47040 > 8.8.8.8.53: 63641+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:50.066767 IP 8.8.8.8.53 > 172.18.0.2.34312: 25243 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:42:50.068273 IP 8.8.8.8.53 > 172.18.0.2.47040: 63641 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:42:50.420185 IP 172.18.0.2.55135 > 8.8.8.8.53: 9419+ A? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.215] 00:42:50.420589 IP 172.18.0.2.42709 > 8.8.8.8.53: 57544+ AAAA? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.215] 00:42:50.426139 IP 8.8.8.8.53 > 172.18.0.2.55135: 9419 NXDomain 0/1/0 (124)\n[00:46:26.215] 00:42:50.426488 IP 8.8.8.8.53 > 172.18.0.2.42709: 57544 NXDomain 0/1/0 (124)\n[00:46:26.215] 00:42:50.426928 IP 172.18.0.2.42643 > 8.8.8.8.53: 12212+ A? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.215] 00:42:50.427362 IP 172.18.0.2.33528 > 8.8.8.8.53: 41906+ AAAA? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.215] 00:42:50.432905 IP 8.8.8.8.53 > 172.18.0.2.42643: 12212 NXDomain 0/1/0 (124)\n[00:46:26.215] 00:42:50.433389 IP 8.8.8.8.53 > 172.18.0.2.33528: 41906 NXDomain 0/1/0 (124)\n[00:46:26.215] 00:42:50.785947 IP 172.18.0.2.40413 > 8.8.8.8.53: 23723+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:50.786307 IP 172.18.0.2.33152 > 8.8.8.8.53: 51880+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:50.786916 IP 172.18.0.2.60591 > 8.8.8.8.53: 57214+ A? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.215] 00:42:50.787237 IP 172.18.0.2.51085 > 8.8.8.8.53: 45180+ AAAA? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.215] 00:42:50.792174 IP 8.8.8.8.53 > 172.18.0.2.33152: 51880 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:42:50.792196 IP 8.8.8.8.53 > 172.18.0.2.40413: 23723 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:42:50.794262 IP 8.8.8.8.53 > 172.18.0.2.51085: 45180 NXDomain 0/1/0 (124)\n[00:46:26.215] 00:42:50.794281 IP 8.8.8.8.53 > 172.18.0.2.60591: 57214 NXDomain 0/1/0 (124)\n[00:46:26.215] 00:42:50.794701 IP 172.18.0.2.53594 > 8.8.8.8.53: 7814+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:50.794819 IP 172.18.0.2.33826 > 8.8.8.8.53: 50053+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:50.795297 IP 172.18.0.2.54482 > 8.8.8.8.53: 30981+ A? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.215] 00:42:50.795592 IP 172.18.0.2.48225 > 8.8.8.8.53: 65050+ AAAA? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.215] 00:42:50.800988 IP 8.8.8.8.53 > 172.18.0.2.33826: 50053 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:42:50.801160 IP 8.8.8.8.53 > 172.18.0.2.53594: 7814 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:42:50.801189 IP 8.8.8.8.53 > 172.18.0.2.54482: 30981 NXDomain 0/1/0 (124)\n[00:46:26.215] 00:42:50.801282 IP 8.8.8.8.53 > 172.18.0.2.48225: 65050 NXDomain 0/1/0 (124)\n[00:46:26.215] 00:42:51.151925 IP 172.18.0.2.45895 > 8.8.8.8.53: 32540+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:51.154708 IP 172.18.0.2.39532 > 8.8.8.8.53: 3102+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:51.160435 IP 8.8.8.8.53 > 172.18.0.2.45895: 32540 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:42:51.160623 IP 8.8.8.8.53 > 172.18.0.2.39532: 3102 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:42:51.161037 IP 172.18.0.2.54958 > 8.8.8.8.53: 64262+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:51.161501 IP 172.18.0.2.55394 > 8.8.8.8.53: 38663+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:42:51.167068 IP 8.8.8.8.53 > 172.18.0.2.54958: 64262 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:42:51.167562 IP 8.8.8.8.53 > 172.18.0.2.55394: 38663 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:43:13.896684 IP 172.18.0.2.38577 > 8.8.8.8.53: 37859+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:43:13.898035 IP 172.18.0.2.57872 > 8.8.8.8.53: 26852+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:43:13.904071 IP 8.8.8.8.53 > 172.18.0.2.38577: 37859 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:43:13.904515 IP 8.8.8.8.53 > 172.18.0.2.57872: 26852 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:43:13.905051 IP 172.18.0.2.41442 > 8.8.8.8.53: 3978+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:43:13.905744 IP 172.18.0.2.51126 > 8.8.8.8.53: 44169+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:43:13.910763 IP 8.8.8.8.53 > 172.18.0.2.41442: 3978 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:43:13.912478 IP 8.8.8.8.53 > 172.18.0.2.51126: 44169 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:43:14.345922 IP 172.18.0.2.46373 > 8.8.8.8.53: 23556+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:43:14.346104 IP 172.18.0.2.55199 > 8.8.8.8.53: 59658+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:43:14.352039 IP 8.8.8.8.53 > 172.18.0.2.55199: 59658 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:43:14.352108 IP 8.8.8.8.53 > 172.18.0.2.46373: 23556 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:43:14.355678 IP 172.18.0.2.40940 > 8.8.8.8.53: 56364+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:43:14.356531 IP 172.18.0.2.51128 > 8.8.8.8.53: 29229+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:43:14.361956 IP 8.8.8.8.53 > 172.18.0.2.40940: 56364 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:43:14.362506 IP 8.8.8.8.53 > 172.18.0.2.51128: 29229 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:44:27.054154 IP 172.18.0.2.51812 > 11.22.33.44.18444: Flags [S], seq 3432062659, win 64240, options [mss 1460,sackOK,TS val 1043001621 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:44:27.945389 IP 172.18.0.2.51828 > 11.22.33.44.18444: Flags [S], seq 3743466587, win 64240, options [mss 1460,sackOK,TS val 1043002513 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:44:28.096227 IP 172.18.0.2.51812 > 11.22.33.44.18444: Flags [S], seq 3432062659, win 64240, options [mss 1460,sackOK,TS val 1043002664 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:44:28.992218 IP 172.18.0.2.51828 > 11.22.33.44.18444: Flags [S], seq 3743466587, win 64240, options [mss 1460,sackOK,TS val 1043003560 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:44:29.120219 IP 172.18.0.2.51812 > 11.22.33.44.18444: Flags [S], seq 3432062659, win 64240, options [mss 1460,sackOK,TS val 1043003688 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:44:30.016217 IP 172.18.0.2.51828 > 11.22.33.44.18444: Flags [S], seq 3743466587, win 64240, options [mss 1460,sackOK,TS val 1043004584 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:44:30.144232 IP 172.18.0.2.51812 > 11.22.33.44.18444: Flags [S], seq 3432062659, win 64240, options [mss 1460,sackOK,TS val 1043004712 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:44:31.040220 IP 172.18.0.2.51828 > 11.22.33.44.18444: Flags [S], seq 3743466587, win 64240, options [mss 1460,sackOK,TS val 1043005608 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:44:31.168218 IP 172.18.0.2.51812 > 11.22.33.44.18444: Flags [S], seq 3432062659, win 64240, options [mss 1460,sackOK,TS val 1043005736 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:44:32.064218 IP 172.18.0.2.51828 > 11.22.33.44.18444: Flags [S], seq 3743466587, win 64240, options [mss 1460,sackOK,TS val 1043006632 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:45:32.199353 IP 172.18.0.2.34256 > 0.0.0.1.18444: Flags [S], seq 2197884795, win 64240, options [mss 1460,sackOK,TS val 2531031147 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:45:33.248224 IP 172.18.0.2.34256 > 0.0.0.1.18444: Flags [S], seq 2197884795, win 64240, options [mss 1460,sackOK,TS val 2531032196 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:45:34.272224 IP 172.18.0.2.34256 > 0.0.0.1.18444: Flags [S], seq 2197884795, win 64240, options [mss 1460,sackOK,TS val 2531033220 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:45:35.296253 IP 172.18.0.2.34256 > 0.0.0.1.18444: Flags [S], seq 2197884795, win 64240, options [mss 1460,sackOK,TS val 2531034244 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:45:36.320281 IP 172.18.0.2.34256 > 0.0.0.1.18444: Flags [S], seq 2197884795, win 64240, options [mss 1460,sackOK,TS val 2531035268 ecr 0,nop,wscale 7], length 0\n[00:46:26.215] 00:45:37.442439 IP 172.18.0.2.52570 > 8.8.8.8.53: 3832+ AAAA? some.node. (27)\n[00:46:26.215] 00:45:37.442487 IP 172.18.0.2.60704 > 8.8.8.8.53: 1023+ A? some.node. (27)\n[00:46:26.215] 00:45:37.448551 IP 8.8.8.8.53 > 172.18.0.2.60704: 1023 NXDomain 0/1/0 (102)\n[00:46:26.215] 00:45:37.448911 IP 8.8.8.8.53 > 172.18.0.2.52570: 3832 NXDomain 0/1/0 (102)\n[00:46:26.215] 00:45:37.449395 IP 172.18.0.2.53889 > 8.8.8.8.53: 63359+ AAAA? some.node. (27)\n[00:46:26.215] 00:45:37.449419 IP 172.18.0.2.51133 > 8.8.8.8.53: 6268+ A? some.node. (27)\n[00:46:26.215] 00:45:37.455701 IP 8.8.8.8.53 > 172.18.0.2.51133: 6268 NXDomain 0/1/0 (102)\n[00:46:26.215] 00:45:37.455743 IP 8.8.8.8.53 > 172.18.0.2.53889: 63359 NXDomain 0/1/0 (102)\n[00:46:26.215] 00:45:37.734057 IP 172.18.0.2.50765 > 8.8.8.8.53: 34600+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:45:37.734277 IP 172.18.0.2.47474 > 8.8.8.8.53: 53797+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:45:37.740114 IP 8.8.8.8.53 > 172.18.0.2.50765: 34600 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:45:37.740144 IP 8.8.8.8.53 > 172.18.0.2.47474: 53797 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:45:37.740754 IP 172.18.0.2.33593 > 8.8.8.8.53: 4491+ A? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:45:37.740756 IP 172.18.0.2.34759 > 8.8.8.8.53: 34698+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.215] 00:45:37.746602 IP 8.8.8.8.53 > 172.18.0.2.34759: 34698 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:45:37.746641 IP 8.8.8.8.53 > 172.18.0.2.33593: 4491 NXDomain 0/1/0 (113)\n[00:46:26.215] 00:45:38.234283 IP 172.18.0.2.33343 > 8.8.8.8.53: 22856+ A? dummySeed.invalid. (35)\n[00:46:26.215] 00:45:38.234286 IP 172.18.0.2.43752 > 8.8.8.8.53: 55883+ AAAA? dummySeed.invalid. (35)\n[00:46:26.215] 00:45:38.240530 IP 8.8.8.8.53 > 172.18.0.2.43752: 55883 NXDomain 0/1/0 (110)\n[00:46:26.215] 00:45:38.240809 IP 8.8.8.8.53 > 172.18.0.2.33343: 22856 NXDomain 0/1/0 (110)\n[00:46:26.215] 00:45:38.241237 IP 172.18.0.2.35861 > 8.8.8.8.53: 14859+ A? dummySeed.invalid. (35)\n[00:46:26.215] 00:45:38.241238 IP 172.18.0.2.51487 > 8.8.8.8.53: 46093+ AAAA? dummySeed.invalid. (35)\n[00:46:26.215] 00:45:38.247292 IP 8.8.8.8.53 > 172.18.0.2.35861: 14859 NXDomain 0/1/0 (110)\n[00:46:26.215] 00:45:38.247320 IP 8.8.8.8.53 > 172.18.0.2.51487: 46093 NXDomain 0/1/0 (110)\n[00:46:26.215] 00:45:39.779784 IP 172.18.0.2.34493 > 8.8.8.8.53: 26799+ A? fakenodeaddr. (30)\n[00:46:26.215] 00:45:39.779791 IP 172.18.0.2.56878 > 8.8.8.8.53: 61600+ AAAA? fakenodeaddr. (30)\n[00:46:26.215] 00:45:39.785890 IP 8.8.8.8.53 > 172.18.0.2.56878: 61600 NXDomain 0/1/0 (105)\n[00:46:26.215] 00:45:39.785928 IP 8.8.8.8.53 > 172.18.0.2.34493: 26799 NXDomain 0/1/0 (105)\n[00:46:26.215] 00:45:39.786515 IP 172.18.0.2.54375 > 8.8.8.8.53: 52196+ A? fakenodeaddr. (30)\n[00:46:26.215] 00:45:39.786693 IP 172.18.0.2.53292 > 8.8.8.8.53: 56037+ AAAA? fakenodeaddr. (30)\n[00:46:26.215] 00:45:39.792298 IP 8.8.8.8.53 > 172.18.0.2.54375: 52196 NXDomain 0/1/0 (105)\n[00:46:26.215] 00:45:39.792592 IP 8.8.8.8.53 > 172.18.0.2.53292: 56037 NXDomain 0/1/0 (105)\n[00:46:26.215] 00:45:42.174906 IP 11.22.33.44.18444 > 172.18.0.2.51812: Flags [R.], seq 0, ack 3432062660, win 65535, length 0\n[00:46:26.215] 00:45:42.722951 IP 172.18.0.2.33938 > 8.8.8.8.53: 23646+ AAAA? fakeaddress1. (30)\n[00:46:26.215] 00:45:42.723043 IP 172.18.0.2.38954 > 8.8.8.8.53: 24914+ A? fakeaddress1. (30)\n[00:46:26.215] 00:45:42.728907 IP 8.8.8.8.53 > 172.18.0.2.38954: 24914 NXDomain 0/1/0 (105)\n[00:46:26.215] 00:45:42.729111 IP 8.8.8.8.53 > 172.18.0.2.33938: 23646 NXDomain 0/1/0 (105)\n[00:46:26.215] 00:45:42.729684 IP 172.18.0.2.52893 > 8.8.8.8.53: 3801+ AAAA? fakeaddress1. (30)\n[00:46:26.215] 00:45:42.729715 IP 172.18.0.2.57497 > 8.8.8.8.53: 62431+ A? fakeaddress1. (30)\n[00:46:26.215] 00:45:42.735746 IP 8.8.8.8.53 > 172.18.0.2.57497: 62431 NXDomain 0/1/0 (105)\n[00:46:26.215] 00:45:42.735771 IP 8.8.8.8.53 > 172.18.0.2.52893: 3801 NXDomain 0/1/0 (105)\n[00:46:26.215] 00:45:43.175350 IP 11.22.33.44.18444 > 172.18.0.2.51828: Flags [R.], seq 0, ack 3743466588, win 65535, length 0' ']'\n[00:46:26.215] + echo 'Outbound TCP or UDP packets on the non loopback interface generated during tests:'\n[00:46:26.215] Outbound TCP or UDP packets on the non loopback interface generated during tests:\n[00:46:26.215] + tcpdump -n -r /tmp/tcpdump_eth0 tcp or udp\n[00:46:26.218] reading from file /tmp/tcpdump_eth0, link-type EN10MB (Ethernet), snapshot length 262144\n[00:46:26.219] 00:42:50.052764 IP 172.18.0.2.46566 > 8.8.8.8.53: 39301+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:50.053181 IP 172.18.0.2.58686 > 8.8.8.8.53: 36487+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:50.059038 IP 8.8.8.8.53 > 172.18.0.2.46566: 39301 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:50.060121 IP 8.8.8.8.53 > 172.18.0.2.58686: 36487 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:50.060574 IP 172.18.0.2.34312 > 8.8.8.8.53: 25243+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:50.060939 IP 172.18.0.2.47040 > 8.8.8.8.53: 63641+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:50.066767 IP 8.8.8.8.53 > 172.18.0.2.34312: 25243 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:50.068273 IP 8.8.8.8.53 > 172.18.0.2.47040: 63641 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:50.420185 IP 172.18.0.2.55135 > 8.8.8.8.53: 9419+ A? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.219] 00:42:50.420589 IP 172.18.0.2.42709 > 8.8.8.8.53: 57544+ AAAA? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.219] 00:42:50.426139 IP 8.8.8.8.53 > 172.18.0.2.55135: 9419 NXDomain 0/1/0 (124)\n[00:46:26.219] 00:42:50.426488 IP 8.8.8.8.53 > 172.18.0.2.42709: 57544 NXDomain 0/1/0 (124)\n[00:46:26.219] 00:42:50.426928 IP 172.18.0.2.42643 > 8.8.8.8.53: 12212+ A? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.219] 00:42:50.427362 IP 172.18.0.2.33528 > 8.8.8.8.53: 41906+ AAAA? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.219] 00:42:50.432905 IP 8.8.8.8.53 > 172.18.0.2.42643: 12212 NXDomain 0/1/0 (124)\n[00:46:26.219] 00:42:50.433389 IP 8.8.8.8.53 > 172.18.0.2.33528: 41906 NXDomain 0/1/0 (124)\n[00:46:26.219] 00:42:50.785947 IP 172.18.0.2.40413 > 8.8.8.8.53: 23723+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:50.786307 IP 172.18.0.2.33152 > 8.8.8.8.53: 51880+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:50.786916 IP 172.18.0.2.60591 > 8.8.8.8.53: 57214+ A? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.219] 00:42:50.787237 IP 172.18.0.2.51085 > 8.8.8.8.53: 45180+ AAAA? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.219] 00:42:50.792174 IP 8.8.8.8.53 > 172.18.0.2.33152: 51880 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:50.792196 IP 8.8.8.8.53 > 172.18.0.2.40413: 23723 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:50.794262 IP 8.8.8.8.53 > 172.18.0.2.51085: 45180 NXDomain 0/1/0 (124)\n[00:46:26.219] 00:42:50.794281 IP 8.8.8.8.53 > 172.18.0.2.60591: 57214 NXDomain 0/1/0 (124)\n[00:46:26.219] 00:42:50.794701 IP 172.18.0.2.53594 > 8.8.8.8.53: 7814+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:50.794819 IP 172.18.0.2.33826 > 8.8.8.8.53: 50053+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:50.795297 IP 172.18.0.2.54482 > 8.8.8.8.53: 30981+ A? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.219] 00:42:50.795592 IP 172.18.0.2.48225 > 8.8.8.8.53: 65050+ AAAA? fakenodeaddr.fakedomain.invalid. (49)\n[00:46:26.219] 00:42:50.800988 IP 8.8.8.8.53 > 172.18.0.2.33826: 50053 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:50.801160 IP 8.8.8.8.53 > 172.18.0.2.53594: 7814 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:50.801189 IP 8.8.8.8.53 > 172.18.0.2.54482: 30981 NXDomain 0/1/0 (124)\n[00:46:26.219] 00:42:50.801282 IP 8.8.8.8.53 > 172.18.0.2.48225: 65050 NXDomain 0/1/0 (124)\n[00:46:26.219] 00:42:51.151925 IP 172.18.0.2.45895 > 8.8.8.8.53: 32540+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:51.154708 IP 172.18.0.2.39532 > 8.8.8.8.53: 3102+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:51.160435 IP 8.8.8.8.53 > 172.18.0.2.45895: 32540 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:51.160623 IP 8.8.8.8.53 > 172.18.0.2.39532: 3102 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:51.161037 IP 172.18.0.2.54958 > 8.8.8.8.53: 64262+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:51.161501 IP 172.18.0.2.55394 > 8.8.8.8.53: 38663+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:42:51.167068 IP 8.8.8.8.53 > 172.18.0.2.54958: 64262 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:42:51.167562 IP 8.8.8.8.53 > 172.18.0.2.55394: 38663 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:43:13.896684 IP 172.18.0.2.38577 > 8.8.8.8.53: 37859+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:43:13.898035 IP 172.18.0.2.57872 > 8.8.8.8.53: 26852+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:43:13.904071 IP 8.8.8.8.53 > 172.18.0.2.38577: 37859 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:43:13.904515 IP 8.8.8.8.53 > 172.18.0.2.57872: 26852 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:43:13.905051 IP 172.18.0.2.41442 > 8.8.8.8.53: 3978+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:43:13.905744 IP 172.18.0.2.51126 > 8.8.8.8.53: 44169+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:43:13.910763 IP 8.8.8.8.53 > 172.18.0.2.41442: 3978 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:43:13.912478 IP 8.8.8.8.53 > 172.18.0.2.51126: 44169 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:43:14.345922 IP 172.18.0.2.46373 > 8.8.8.8.53: 23556+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:43:14.346104 IP 172.18.0.2.55199 > 8.8.8.8.53: 59658+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:43:14.352039 IP 8.8.8.8.53 > 172.18.0.2.55199: 59658 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:43:14.352108 IP 8.8.8.8.53 > 172.18.0.2.46373: 23556 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:43:14.355678 IP 172.18.0.2.40940 > 8.8.8.8.53: 56364+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:43:14.356531 IP 172.18.0.2.51128 > 8.8.8.8.53: 29229+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:43:14.361956 IP 8.8.8.8.53 > 172.18.0.2.40940: 56364 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:43:14.362506 IP 8.8.8.8.53 > 172.18.0.2.51128: 29229 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:44:27.054154 IP 172.18.0.2.51812 > 11.22.33.44.18444: Flags [S], seq 3432062659, win 64240, options [mss 1460,sackOK,TS val 1043001621 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:44:27.945389 IP 172.18.0.2.51828 > 11.22.33.44.18444: Flags [S], seq 3743466587, win 64240, options [mss 1460,sackOK,TS val 1043002513 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:44:28.096227 IP 172.18.0.2.51812 > 11.22.33.44.18444: Flags [S], seq 3432062659, win 64240, options [mss 1460,sackOK,TS val 1043002664 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:44:28.992218 IP 172.18.0.2.51828 > 11.22.33.44.18444: Flags [S], seq 3743466587, win 64240, options [mss 1460,sackOK,TS val 1043003560 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:44:29.120219 IP 172.18.0.2.51812 > 11.22.33.44.18444: Flags [S], seq 3432062659, win 64240, options [mss 1460,sackOK,TS val 1043003688 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:44:30.016217 IP 172.18.0.2.51828 > 11.22.33.44.18444: Flags [S], seq 3743466587, win 64240, options [mss 1460,sackOK,TS val 1043004584 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:44:30.144232 IP 172.18.0.2.51812 > 11.22.33.44.18444: Flags [S], seq 3432062659, win 64240, options [mss 1460,sackOK,TS val 1043004712 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:44:31.040220 IP 172.18.0.2.51828 > 11.22.33.44.18444: Flags [S], seq 3743466587, win 64240, options [mss 1460,sackOK,TS val 1043005608 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:44:31.168218 IP 172.18.0.2.51812 > 11.22.33.44.18444: Flags [S], seq 3432062659, win 64240, options [mss 1460,sackOK,TS val 1043005736 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:44:32.064218 IP 172.18.0.2.51828 > 11.22.33.44.18444: Flags [S], seq 3743466587, win 64240, options [mss 1460,sackOK,TS val 1043006632 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:45:32.199353 IP 172.18.0.2.34256 > 0.0.0.1.18444: Flags [S], seq 2197884795, win 64240, options [mss 1460,sackOK,TS val 2531031147 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:45:33.248224 IP 172.18.0.2.34256 > 0.0.0.1.18444: Flags [S], seq 2197884795, win 64240, options [mss 1460,sackOK,TS val 2531032196 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:45:34.272224 IP 172.18.0.2.34256 > 0.0.0.1.18444: Flags [S], seq 2197884795, win 64240, options [mss 1460,sackOK,TS val 2531033220 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:45:35.296253 IP 172.18.0.2.34256 > 0.0.0.1.18444: Flags [S], seq 2197884795, win 64240, options [mss 1460,sackOK,TS val 2531034244 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:45:36.320281 IP 172.18.0.2.34256 > 0.0.0.1.18444: Flags [S], seq 2197884795, win 64240, options [mss 1460,sackOK,TS val 2531035268 ecr 0,nop,wscale 7], length 0\n[00:46:26.219] 00:45:37.442439 IP 172.18.0.2.52570 > 8.8.8.8.53: 3832+ AAAA? some.node. (27)\n[00:46:26.219] 00:45:37.442487 IP 172.18.0.2.60704 > 8.8.8.8.53: 1023+ A? some.node. (27)\n[00:46:26.219] 00:45:37.448551 IP 8.8.8.8.53 > 172.18.0.2.60704: 1023 NXDomain 0/1/0 (102)\n[00:46:26.219] 00:45:37.448911 IP 8.8.8.8.53 > 172.18.0.2.52570: 3832 NXDomain 0/1/0 (102)\n[00:46:26.219] 00:45:37.449395 IP 172.18.0.2.53889 > 8.8.8.8.53: 63359+ AAAA? some.node. (27)\n[00:46:26.219] 00:45:37.449419 IP 172.18.0.2.51133 > 8.8.8.8.53: 6268+ A? some.node. (27)\n[00:46:26.219] 00:45:37.455701 IP 8.8.8.8.53 > 172.18.0.2.51133: 6268 NXDomain 0/1/0 (102)\n[00:46:26.219] 00:45:37.455743 IP 8.8.8.8.53 > 172.18.0.2.53889: 63359 NXDomain 0/1/0 (102)\n[00:46:26.219] 00:45:37.734057 IP 172.18.0.2.50765 > 8.8.8.8.53: 34600+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:45:37.734277 IP 172.18.0.2.47474 > 8.8.8.8.53: 53797+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:45:37.740114 IP 8.8.8.8.53 > 172.18.0.2.50765: 34600 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:45:37.740144 IP 8.8.8.8.53 > 172.18.0.2.47474: 53797 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:45:37.740754 IP 172.18.0.2.33593 > 8.8.8.8.53: 4491+ A? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:45:37.740756 IP 172.18.0.2.34759 > 8.8.8.8.53: 34698+ AAAA? x9.dummySeed.invalid. (38)\n[00:46:26.219] 00:45:37.746602 IP 8.8.8.8.53 > 172.18.0.2.34759: 34698 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:45:37.746641 IP 8.8.8.8.53 > 172.18.0.2.33593: 4491 NXDomain 0/1/0 (113)\n[00:46:26.219] 00:45:38.234283 IP 172.18.0.2.33343 > 8.8.8.8.53: 22856+ A? dummySeed.invalid. (35)\n[00:46:26.219] 00:45:38.234286 IP 172.18.0.2.43752 > 8.8.8.8.53: 55883+ AAAA? dummySeed.invalid. (35)\n[00:46:26.219] 00:45:38.240530 IP 8.8.8.8.53 > 172.18.0.2.43752: 55883 NXDomain 0/1/0 (110)\n[00:46:26.219] 00:45:38.240809 IP 8.8.8.8.53 > 172.18.0.2.33343: 22856 NXDomain 0/1/0 (110)\n[00:46:26.219] 00:45:38.241237 IP 172.18.0.2.35861 > 8.8.8.8.53: 14859+ A? dummySeed.invalid. (35)\n[00:46:26.219] 00:45:38.241238 IP 172.18.0.2.51487 > 8.8.8.8.53: 46093+ AAAA? dummySeed.invalid. (35)\n[00:46:26.219] 00:45:38.247292 IP 8.8.8.8.53 > 172.18.0.2.35861: 14859 NXDomain 0/1/0 (110)\n[00:46:26.219] 00:45:38.247320 IP 8.8.8.8.53 > 172.18.0.2.51487: 46093 NXDomain 0/1/0 (110)\n[00:46:26.219] 00:45:39.779784 IP 172.18.0.2.34493 > 8.8.8.8.53: 26799+ A? fakenodeaddr. (30)\n[00:46:26.219] 00:45:39.779791 IP 172.18.0.2.56878 > 8.8.8.8.53: 61600+ AAAA? fakenodeaddr. (30)\n[00:46:26.219] 00:45:39.785890 IP 8.8.8.8.53 > 172.18.0.2.56878: 61600 NXDomain 0/1/0 (105)\n[00:46:26.219] 00:45:39.785928 IP 8.8.8.8.53 > 172.18.0.2.34493: 26799 NXDomain 0/1/0 (105)\n[00:46:26.219] 00:45:39.786515 IP 172.18.0.2.54375 > 8.8.8.8.53: 52196+ A? fakenodeaddr. (30)\n[00:46:26.219] 00:45:39.786693 IP 172.18.0.2.53292 > 8.8.8.8.53: 56037+ AAAA? fakenodeaddr. (30)\n[00:46:26.219] 00:45:39.792298 IP 8.8.8.8.53 > 172.18.0.2.54375: 52196 NXDomain 0/1/0 (105)\n[00:46:26.219] 00:45:39.792592 IP 8.8.8.8.53 > 172.18.0.2.53292: 56037 NXDomain 0/1/0 (105)\n[00:46:26.219] 00:45:42.174906 IP 11.22.33.44.18444 > 172.18.0.2.51812: Flags [R.], seq 0, ack 3432062660, win 65535, length 0\n[00:46:26.219] 00:45:42.722951 IP 172.18.0.2.33938 > 8.8.8.8.53: 23646+ AAAA? fakeaddress1. (30)\n[00:46:26.219] 00:45:42.723043 IP 172.18.0.2.38954 > 8.8.8.8.53: 24914+ A? fakeaddress1. (30)\n[00:46:26.219] 00:45:42.728907 IP 8.8.8.8.53 > 172.18.0.2.38954: 24914 NXDomain 0/1/0 (105)\n[00:46:26.219] 00:45:42.729111 IP 8.8.8.8.53 > 172.18.0.2.33938: 23646 NXDomain 0/1/0 (105)\n[00:46:26.219] 00:45:42.729684 IP 172.18.0.2.52893 > 8.8.8.8.53: 3801+ AAAA? fakeaddress1. (30)\n[00:46:26.219] 00:45:42.729715 IP 172.18.0.2.57497 > 8.8.8.8.53: 62431+ A? fakeaddress1. (30)\n[00:46:26.219] 00:45:42.735746 IP 8.8.8.8.53 > 172.18.0.2.57497: 62431 NXDomain 0/1/0 (105)\n[00:46:26.219] 00:45:42.735771 IP 8.8.8.8.53 > 172.18.0.2.52893: 3801 NXDomain 0/1/0 (105)\n[00:46:26.219] 00:45:43.175350 IP 11.22.33.44.18444 > 172.18.0.2.51828: Flags [R.], seq 0, ack 3743466588, win 65535, length 0\n```"
  },
  {
   "t": "2024-11-26T08:54:57Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1856911491,
   "text": "On some of the VMs this produces:\n\n```\n[09:47:01.270] + tcpdump -n -i eth0 -w /tmp/tcpdump_eth0\n[09:47:01.334] tcpdump: eth0: You don't have permission to perform this capture on that device\n[09:47:01.335] (socket: Operation not permitted)\n```\n\nand then the CI passes because the return code is ignored. I think better not fail the CI when `tcpdump` does not work in that environment. It is ok as long as `tcpdump` works on at least one VM to catch problems."
  },
  {
   "t": "2024-11-26T09:04:24Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1856911491,
   "text": "The problem is that no one will notice if this isn't run on any machine, because it will silently pass even if there is an error."
  },
  {
   "t": "2024-11-26T09:11:05Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1856911491,
   "text": "True, if it stops working on all VMs, then nobody will notice. Any ideas how to approach this?"
  },
  {
   "t": "2024-11-26T09:24:01Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1856911491,
   "text": "I'd say it is fine to ignore it by default (if you want). However, there should be one machine in the CI matrix to run the check (and fail on any error).\n\nThe cirrus workers are running in a user account, so they may not have the permissions (unless they are switched to @0xB10C's workers, which are running as root?). Alternatively, you could try with `--cap-add=...`/`--privileged`, but I haven't tried this. I guess the only task that has the required permissions right now is the ASan GHA task?"
  },
  {
   "t": "2024-11-26T13:09:08Z",
   "kind": "comment",
   "who": "1440000bytes",
   "assoc": "CONTRIBUTOR",
   "text": "Concept ACK\n\nA simple solution to avoid leaking IP address when running tests locally would be to disconnect internet while running tests."
  },
  {
   "t": "2024-11-26T13:57:02Z",
   "kind": "comment",
   "who": "jonatack",
   "assoc": "MEMBER",
   "text": "Concept ACK. Per https://bitcoin-irc.chaincode.com/bitcoin-core-dev/2024-11-26#1069602: \"it turns out the owners of 1.2.3.4, 11.22.33.44 and 8.8.8.8, if they would bother, would know the IP address of every dev who runs the functional tests at home.\""
  },
  {
   "t": "2024-11-27T11:22:14Z",
   "kind": "review_comment",
   "who": "0xB10C",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1856911491,
   "text": "[quoted text omitted]\n\nthe runner setup I'm working on explicitly **doesn't** run as root and is far from finished :)"
  },
  {
   "t": "2024-11-27T11:52:07Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1856911491,
   "text": "[quoted text omitted]\n\nAre you sure, because the current CI (in this run) is run in a user account (not root), and gives a permission error. The same CI in your run does not give a permission error, so there seems to be a difference.\n\nThe only thing I see is that you are using docker, which IIRC is running rootful by default."
  },
  {
   "t": "2024-11-27T13:30:37Z",
   "kind": "review_comment",
   "who": "0xB10C",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1856911491,
   "text": "I'm using [rootless-docker](https://docs.docker.com/engine/security/rootless/) which runs dockerd as a user account. Inside the container, you're root and can tcpdump on the containers `eth0` interface, but you can't* e.g. mount and edit the hosts `/etc/passwd` like you can't with the user account.\n\n*until someone finds a vuln in rootless-docker"
  },
  {
   "t": "2024-11-27T13:59:46Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1856911491,
   "text": "It may be that docker rootless has a different capabilities set, compared to podman. (Can be checked with `capsh --print`).\n\nIn any case, my preference would be to explicitly list the required caps, instead of relying on a vendor default."
  },
  {
   "t": "2024-11-27T15:40:38Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "8799018bd58e51fa6fa4e7e9f8d7715713567165"
  },
  {
   "t": "2024-11-27T15:43:26Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1856911491,
   "text": "[quoted text omitted]\n\nI changed it to insist that the tcpdump file was created on the ASAN env. So the ASAN job will be red if this stops working on it."
  },
  {
   "t": "2024-11-27T17:27:48Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "803ed4638b7260139ce156fa39d21c4d626c9873"
  },
  {
   "t": "2024-11-27T17:36:08Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`8799018bd5...803ed4638b`: include https://github.com/bitcoin/bitcoin/pull/31343 into this PR to demonstrate that #31343 works as intended and also to turn the CI here green.\n\nAbout the false positives - I think it is worth trying this in its current mode where any detected traffic is assumed to have originated from the tests and fails the CI. If this ever fails the CI for another reason (false positive), then it would be easy to turn this into a \"report in the logs only but don't fail\" by removing the `exit 1` line.\n\nAbout the DNS traffic - I did `cat /etc/resolv.conf` in the CI and the name server is indeed configured as a local one: `nameserver 127.0.0.11`."
  },
  {
   "t": "2024-11-27T17:44:26Z",
   "kind": "review",
   "who": "BrandonOdiwuor",
   "assoc": "CONTRIBUTOR",
   "state": "COMMENTED",
   "commit": "803ed4638b7260139ce156fa39d21c4d626c9873",
   "text": "Concept ACK"
  },
  {
   "t": "2024-11-28T07:59:48Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1856911491,
   "text": "I don't think this is sufficient. The CI failure (https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-2499335672) will remain, depending on a vendor default.\n\nAgain, my preference would be to explicitly list the required (or removed) caps, instead of relying on a vendor default. Otherwise, it will become harder to run the CI locally, or lead to vendor-lock-in."
  },
  {
   "t": "2024-11-28T17:30:41Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "54a6884db40e56c7db547a98aa990a9d14b42bfa"
  },
  {
   "t": "2024-11-28T17:31:56Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "Converted to draft for a while, testing docker with full privileges (need cirrus which does not run in my personal fork)."
  },
  {
   "t": "2024-11-29T11:46:43Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "f2b3b8d7d5403eb91cd167a874664d43653cd4da"
  },
  {
   "t": "2024-11-29T12:30:10Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "6d1c27de47bf7898486399662519defef8b20903"
  },
  {
   "t": "2024-11-29T13:56:11Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "eb50e89e31f693983dcfcaf80b152c6ebf2d93a2"
  },
  {
   "t": "2024-12-02T10:43:18Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "9c01e101dd2cd660b21d1a009e9085afb19d999f"
  },
  {
   "t": "2024-12-02T12:43:35Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "57924f4a75862b2bcfa01051a0140bdaf8b35446"
  },
  {
   "t": "2024-12-02T16:04:49Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "b241a913e85e80deca78e442551a9aaafda70001"
  },
  {
   "t": "2024-12-03T08:33:02Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "c88464d7549415cb51a0f93a86c567f86e521b2e"
  },
  {
   "t": "2024-12-03T08:41:36Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1856911491,
   "text": "[quoted text omitted]\n\nDone, `NET_RAW` is required to run `tcpdump`: https://www.tcpdump.org/manpages/pcap.3pcap.html\n\nPlus, the ASAN job requires that `tcpdump -w` runs and creates the file, otherwise it will be red.\n\nI think that resolves the concerns from this thread, so I am closing it. Feel free to comment / reopen if there is more to this."
  },
  {
   "t": "2024-12-03T10:48:44Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "Ready for review. I updated the OP with some details."
  },
  {
   "t": "2024-12-03T10:59:57Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": null,
   "text": "I don't think this works reliably? See:\n\n```\n              This output will be buffered if written to a file or pipe, so a program reading from the file or pipe may not see packets for an arbitrary amount of time after they are received.  Use the -U flag to cause packets to be\n              written as soon as they are received."
  },
  {
   "t": "2024-12-03T11:01:56Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": null,
   "text": "Why is this needed? The file isn't cleared anyway (and exited if it isn't clear), so might as well just run the processes and never kill them?\n\nAlso, it doesn't seem to be working anyway on some of the tasks?"
  },
  {
   "t": "2024-12-04T10:26:10Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "feabffd80878e215bf7709e180895f26279051cc"
  },
  {
   "t": "2024-12-04T10:28:29Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1867506582,
   "text": "Even better! Added `-U`.\n\nWith `-U` is does not matter anymore, but I think it was ok before as well, see my comment [below](https://github.com/bitcoin/bitcoin/pull/31349#discussion_r1867509291)."
  },
  {
   "t": "2024-12-04T10:39:37Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1867509291,
   "text": "To 1. flush the file and 2. so that the next set of tests can start fresh without leftover `tcpdump` processes. Now 1. is not needed because of `-U`, but I will leave this `kill` for 2.\n\nIn my experiments `SIGTERM` would cause `tcpdump` to exit gracefully - flush the file and then exit. `SIGKILL` would result in unflushed file.\n\nYes, in some tasks `kill` gives \"permission denied\" even if docker is running with `--privileged` or `--cap-add ALL`."
  },
  {
   "t": "2024-12-04T10:48:12Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1867509291,
   "text": "[quoted text omitted]\n\nThat is interesting, because all tasks should be running on workers that are set up identically.\n\n[quoted text omitted]\nMy thinking was to just have a single process, which is started once and never killed. This should remove the need to kill it, and also the need (and code) to start it every time."
  },
  {
   "t": "2024-12-04T10:49:54Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": null,
   "text": "This is also ignoring the return code? So it could also lead to CI silently passing on all tasks, when it should not."
  },
  {
   "t": "2024-12-04T10:53:20Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1869211837,
   "text": "Generally, I am not sure if bash is the right language to implement something like this. Silently ignoring possible errors doesn't seem like a great approach. Other languages, such as Rust or Python are a bit more explicit in documenting when a return code is ignored."
  },
  {
   "t": "2024-12-04T10:57:20Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1867509291,
   "text": "Then it would be unclear whether the traffic was generated by unit tests, functional tests or fuzz tests. So I start/stop a separate monitoring for each of those set of tests. I perceived this information useful when investigating. It is already tough that it is not known which test generated the traffic.\n\nSomehow I do not like reading from the \"live\" file while it is being written. `-U` would help not to miss data, but it might happen that by the time we read it the last packet is still being written and is half-written and the reading `tcpdump` is upset by that."
  },
  {
   "t": "2024-12-04T10:59:49Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1867509291,
   "text": "[quoted text omitted]\n\nI noticed those tasks print:\n\n[quoted text omitted]\nBtw, now with `tcpdump -U` those tasks do not print \"tcpdump: truncated dump file; tried to read 4 file header bytes, only got 0\" anymore"
  },
  {
   "t": "2024-12-04T11:06:23Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1867509291,
   "text": "[quoted text omitted]\n\nThat should be identical for all tasks as well. See:\n\n* https://cirrus-ci.com/task/5454797781860352?logs=ci#L186\n* https://cirrus-ci.com/task/5314060293505024?logs=ci#L184\n\nThe only difference should be that one is bare metal and the other is KVM, but I don't see how this could cause a difference here."
  },
  {
   "t": "2024-12-04T11:11:49Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1867509291,
   "text": "Hmm, right. Then I have no idea why `kill` does not work on some. It is ok as long as it works on at least one."
  },
  {
   "t": "2024-12-04T12:07:21Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1869211837,
   "text": "Ignoring the return status of `tcpdump` here is deliberate because some VMs, the ones that couldn't stop `tcpdump` failed to read the unflushed file with an error like \"tcpdump: truncated dump file; tried to read 4 file header bytes, only got 0\". Now they don't due to the added `-U`, hmm..."
  },
  {
   "t": "2024-12-04T12:32:03Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1869211837,
   "text": "I'd say this is unrelated to flushing. Ignoring the return code in all tasks can mean that even the tasks where the detection is working are going to silently break tomorrow. As mentioned previously in the thread you closed, I think this is brittle.\n\nTo clarify, my feedback not just applies to the line I commented on, but it applies to all code where the return code is silently ignored and where it could lead to silent breakage."
  },
  {
   "t": "2024-12-04T13:44:43Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "925ee8707e5a1b9c527be29438602b238bd40abd"
  },
  {
   "t": "2024-12-04T13:46:15Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1869211837,
   "text": "Ok, I changed this to fail if `tcpdump` gives error when it reads the file."
  },
  {
   "t": "2024-12-04T13:46:55Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`feabffd808...925ee8707e`: (hopefully) address https://github.com/bitcoin/bitcoin/pull/31349#discussion_r1869211837"
  },
  {
   "t": "2024-12-04T15:07:10Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "I think the `tcpdump` approach works well enough. I am posting here just for the records - an alternative approach is to use `iptables` to detect traffic. I managed to get it to log the traffic, but couldn't read that log - I could only see a summary of how many packets matched, not individual ones and their destination address.\n\nBelow is a WIP patch which can be used as a starting point if I or somebody else wants to pursue that further.\n\n[patch] WIP iptables\n\n```diff\ndiff --git a/ci/test/00_setup_env.sh b/ci/test/00_setup_env.sh\nindex 94149106ee..7889910684 100755\n--- a/ci/test/00_setup_env.sh\n+++ b/ci/test/00_setup_env.sh\n@@ -61,10 +61,10 @@ export CCACHE_COMPRESS=${CCACHE_COMPRESS:-1}\n export CCACHE_DIR=\"${CCACHE_DIR:-$BASE_SCRATCH_DIR/ccache}\"\n # Folder where the build result is put (bin and lib).\n export BASE_OUTDIR=${BASE_OUTDIR:-$BASE_SCRATCH_DIR/out}\n # The folder for previous release binaries.\n # This folder exists only on the ci guest, and on the ci host as a volume.\n export PREVIOUS_RELEASES_DIR=${PREVIOUS_RELEASES_DIR:-$BASE_ROOT_DIR/prev_releases}\n-export CI_BASE_PACKAGES=${CI_BASE_PACKAGES:-build-essential pkg-config curl ca-certificates ccache python3 rsync git procps bison e2fsprogs cmake net-tools tcpdump}\n+export CI_BASE_PACKAGES=${CI_BASE_PACKAGES:-build-essential pkg-config curl ca-certificates ccache python3 rsync git procps bison e2fsprogs cmake net-tools tcpdump bind9-host iptables inetutils-telnet}\n export GOAL=${GOAL:-install}\n export DIR_QA_ASSETS=${DIR_QA_ASSETS:-${BASE_SCRATCH_DIR}/qa-assets}\n export CI_RETRY_EXE=${CI_RETRY_EXE:-\"retry --\"}\ndiff --git a/ci/test/02_run_container.sh b/ci/test/02_run_container.sh\nindex e1539e8bef..0fb5feaec5 100755\n--- a/ci/test/02_run_container.sh\n+++ b/ci/test/02_run_container.sh\n@@ -88,13 +88,24 @@ if [ -z \"$DANGER_RUN_CI_ON_HOST\" ]; then\n   # When detecting podman-docker, `--external` should be added.\n   docker image prune --force --filter \"label=$CI_IMAGE_LABEL\"\n\n   # Append $USER to /tmp/env to support multi-user systems and $CONTAINER_NAME\n   # to allow support starting multiple runs simultaneously by the same user.\n   # shellcheck disable=SC2086\n-  CI_CONTAINER_ID=$(docker run --cap-add LINUX_IMMUTABLE --cap-add NET_RAW $CI_CONTAINER_CAP --rm --interactive --detach --tty \\\n+  CI_CONTAINER_ID=$(docker run \\\n+                  --cap-add LINUX_IMMUTABLE \\\n+                  --cap-add NET_ADMIN \\\n+                  --cap-add SYSLOG \\\n+                  $CI_CONTAINER_CAP \\\n+                  --cap-add NET_ADMIN \\\n+                  --cap-add NET_RAW \\\n+                  --privileged \\\n+                  --rm \\\n+                  --interactive \\\n+                  --detach \\\n+                  --tty \\\n                   --mount \"type=bind,src=$BASE_READ_ONLY_DIR,dst=$BASE_READ_ONLY_DIR,readonly\" \\\n                   --mount \"${CI_CCACHE_MOUNT}\" \\\n                   --mount \"${CI_DEPENDS_MOUNT}\" \\\n                   --mount \"${CI_DEPENDS_SOURCES_MOUNT}\" \\\n                   --mount \"${CI_PREVIOUS_RELEASES_MOUNT}\" \\\n                   --env-file /tmp/env-$USER-$CONTAINER_NAME \\\ndiff --git a/ci/test/03_test_script.sh b/ci/test/03_test_script.sh\nindex 71048330e6..c4b22417a5 100755\n--- a/ci/test/03_test_script.sh\n+++ b/ci/test/03_test_script.sh\n@@ -188,12 +188,31 @@ function traffic_monitor_end()\n       tcpdump -n -r \"$f\" tcp or udp\n       exit 1\n     fi\n   done\n }\n\n+ifconfig || :\n+echo \"Non-loopback interfaces: $(get_interfaces)\"\n+\n+traffic_monitor_begin\n+iptables  -A OUTPUT -j LOG --log-prefix \"ttttt1\" --log-level emerg || :\n+ip6tables -A OUTPUT -j LOG --log-prefix \"ttttt2\" --log-level emerg || :\n+iptables  -A OUTPUT -m addrtype \\! --dst-type LOCAL -j LOG --log-prefix \"ttttt3\" --log-level emerg || :\n+ip6tables -A OUTPUT -m addrtype \\! --dst-type LOCAL -j LOG --log-prefix \"ttttt4\" --log-level emerg || :\n+id || :\n+cat /etc/resolv.conf || :\n+host bitcoin.org || :\n+host nonexistentinvalidfoobarbaz.org || :\n+telnet 50.60.1.2 3456 || :\n+dmesg |grep ttttt || :\n+grep -r ttttt /var/log/ || :\n+iptables -v -x -n -L || :\n+traffic_monitor_end\n+exit 34\n+\n if [ \"$RUN_UNIT_TESTS\" = \"true\" ]; then\n   traffic_monitor_begin\n   DIR_UNIT_TEST_DATA=\"${DIR_UNIT_TEST_DATA}\" LD_LIBRARY_PATH=\"${DEPENDS_DIR}/${HOST}/lib\" CTEST_OUTPUT_ON_FAILURE=ON ctest --stop-on-failure \"${MAKEJOBS}\" --timeout $(( TEST_RUNNER_TIMEOUT_FACTOR * 60 ))\n   traffic_monitor_end\n fi\n```"
  },
  {
   "t": "2024-12-04T15:43:44Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1869211837,
   "text": "Again, my feedback not just applies to the line I commented on, but it applies to all code where the return code is silently ignored and where it could lead to silent breakage.\n\nFor example, pipefail isn't set, so `get_interfaces` can also silently fail ..."
  },
  {
   "t": "2024-12-04T16:43:58Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1869211837,
   "text": "I assume `ifconfig` without any arguments will never fail.\n\nDo you think it would be better to change it to:\n\n```diff\n function get_interfaces()\n {\n+  set -o pipefail\n   ifconfig | awk -F ':| ' '/^[^[:space:]]/ { if (!match($1, /^lo/)) { print $1 } }'\n+  set +o pipefail\n }\n```\n\nor that is just clutter?"
  },
  {
   "t": "2024-12-04T18:53:28Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1869211837,
   "text": "There is also `top -l 1 -s 0 | awk ' /PhysMem/ {print}'` near the start of `03_test_script.sh`. Maybe `set -o pipefail` at the start of the file? (would be somewhat out of scope of this PR, but I am fine with it if nobody objects)"
  },
  {
   "t": "2024-12-05T07:57:35Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1869211837,
   "text": "[quoted text omitted]\n\nI don't think this is right. Even if the program was a magic unicorn that never could fail for any reason at all, it will fail when it is missing.\n\nThis can happen easily when someone removes \"unused\" CI packages with the proof that CI passes.\n\nYou can also check it locally:\n\n```\n# ifconfig | cat\nsh: 13: ifconfig: not found\n# echo $?\n0\n```\n\n[quoted text omitted]\nCorrect, but this is a macos-only debug-only log, unrelated to checking the behavior of Bitcoin Core or the Bitcoin Core tests. Even if it were to fail, I don't see how it could lead to a test failure or test misbehaviour being silently ignored."
  },
  {
   "t": "2024-12-05T08:16:31Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "56dbe78934d7e20d51c4559d94e1a29fecb9bc6f"
  },
  {
   "t": "2024-12-05T08:16:41Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`925ee8707e...56dbe78934`: rebase due to conflicts"
  },
  {
   "t": "2024-12-05T08:57:47Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "5f3b24711e041690071442463b35db8ad7545ed6"
  },
  {
   "t": "2024-12-05T09:37:39Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`56dbe78934...5f3b24711e`: use distinct tcpdump file per test (unitparallel, unitsequential, functional, fuzz, tidy) and log that in case of detected traffic."
  },
  {
   "t": "2024-12-05T09:54:09Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "a6c3c9defbcc30692aa001b334a06632a9e4347d"
  },
  {
   "t": "2024-12-05T09:54:58Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`5f3b24711e...a6c3c9defb`: https://github.com/bitcoin/bitcoin/pull/31349#discussion_r1870850323"
  },
  {
   "t": "2024-12-05T09:55:35Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1869211837,
   "text": "Enabled `pipefail` as in the above diff. Thanks!"
  },
  {
   "t": "2024-12-11T05:22:43Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "46e38e2e33b79da1de50e6b3c1013b9ebf64c3f9"
  },
  {
   "t": "2024-12-11T05:24:31Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`a6c3c9defb...46e38e2e33`: rebase and remove merged #31343 which this PR included."
  },
  {
   "t": "2024-12-17T13:03:58Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "95fc90610a1162fc06e61b607488d05229c9909f"
  },
  {
   "t": "2024-12-17T13:16:57Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`46e38e2e33...95fc90610a`: rebase due to conflicts and don't stop the `tcpdump` processes because it is now not necessary because distinct files are used for each run, https://github.com/bitcoin/bitcoin/pull/31349#discussion_r1867509291."
  },
  {
   "t": "2024-12-17T13:19:02Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1867509291,
   "text": "In one of the previous pushes I changed it to use distinct tcpdump files for each test run, so 2. from https://github.com/bitcoin/bitcoin/pull/31349#discussion_r1869187689 is not necessary any more. Removed this snippet."
  },
  {
   "t": "2024-12-21T12:24:08Z",
   "kind": "review_comment",
   "who": "0xB10C",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": null,
   "text": "nit: someone renaming this file down the line might not be aware of a dependency on this exact file name"
  },
  {
   "t": "2024-12-21T12:27:10Z",
   "kind": "review",
   "who": "0xB10C",
   "assoc": "MEMBER",
   "state": "APPROVED",
   "commit": "95fc90610a1162fc06e61b607488d05229c9909f",
   "text": "ACK 95fc90610a1162fc06e61b607488d05229c9909f\n\nNice solution to use `127.0.0.1:1` as unreachable proxy for DNS requests too. I [ran](https://cirrus-ci.com/build/4807331864641536) this on my CI runners with a `8.8.8.8` and `1.1.1.1` as DNS servers as [before](https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-2499335672) and the tests don't connect out now. I [ran](https://cirrus-ci.com/build/6328887816224768) with `test: avoid generating non-loopback traffic from feature_config_args.py` reverted to check that a few tasks fail and report the outgoing connections. I did a light code review, looked at e.g. the tcpdump options being used, but didn't look at the iptables alternative."
  },
  {
   "t": "2024-12-23T10:51:33Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1894615448,
   "text": "Yeah, I was thinking the same... Should I change it to the following?\n\n```diff\n-     if [ ! -e \"$f\" ] && [ \"$FILE_ENV\" != \"./ci/test/00_setup_env_native_asan.sh\" ] ; then\n+     if [ ! -e \"$f\" ] && [ \"$CONTAINER_NAME\" != \"ci_native_asan\" ] ; then\n```"
  },
  {
   "t": "2024-12-23T13:42:09Z",
   "kind": "review_comment",
   "who": "0xB10C",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1894615448,
   "text": "Yet another alternative would be to set a flag like `CI_FAIL_IF_NO_TCPDUMP_FILE` (or similar) in  00_setup_env_native_asan.sh and add a comment mentioning the dependency:\n- if the script name or the container name are renamed, this will still work\n- if script is removed, someone might see the comment about the dependency during review\n- it's easy to add more tasks to the list of required tasks by just adding `CI_FAIL_IF_NO_TCPDUMP=\"true\"`"
  },
  {
   "t": "2024-12-23T14:24:50Z",
   "kind": "comment",
   "who": "sipa",
   "assoc": "MEMBER",
   "text": "Concept ACK"
  },
  {
   "t": "2024-12-23T18:41:42Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "0ac9caf7beb6bc6e7680b0fe386d0ed71794decc"
  },
  {
   "t": "2024-12-23T18:42:41Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`95fc90610a...0ac9caf7be`: do https://github.com/bitcoin/bitcoin/pull/31349#discussion_r1895767330"
  },
  {
   "t": "2024-12-23T18:47:51Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "d8cd80e8148195e916042113d426e2a5fcad45dd"
  },
  {
   "t": "2024-12-23T18:48:29Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`0ac9caf7be...d8cd80e814`: forgot to add a comment in the previous push"
  },
  {
   "t": "2024-12-24T08:39:45Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "48843ec694110c9fadb92cdf263cf73bbd462ad9"
  },
  {
   "t": "2024-12-24T11:29:11Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`d8cd80e...48843ec`: `s/=/!=/` :facepalm:"
  },
  {
   "t": "2024-12-24T11:42:48Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": null,
   "text": "Given that you no longer kill tcpdump, the code should work on all CI tasks, except for the GHA macos tasks?\n\nIf there are only a few tasks that do not work, it may be better to just carve them out, instead of enumerating all the ones that work or dealing with code to ensure that at least one works for each config (fuzz/tidy/tests)?"
  },
  {
   "t": "2024-12-24T12:08:50Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1894615448,
   "text": "Done! Much better."
  },
  {
   "t": "2024-12-24T12:29:13Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1896679919,
   "text": "The table in the OP describes each task and its status wrt to this. There are 18 tasks. It is supposed to work on the top 5+4=9 tasks. The other 9 tasks are not expected to run this - e.g. Windows or tidy that does not run any tests or macOS that runs without docker and has no enough permissions.\n\nThe intention here is to have at least one task that runs this. But it will not hurt to enforce it on more. Do you want to add `CI_FAIL_IF_NO_TCPDUMP_FILE=1` to more tasks? Or reverse the logic to `CI_OK_IF_NO_TCPDUMP_FILE=1` in the tasks that are expected to not run this (maybe it is the same if it is 9 vs 9 tasks)?"
  },
  {
   "t": "2024-12-24T12:39:21Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1896679919,
   "text": "[quoted text omitted]\n\nIf no tests are run, then no exclusion is needed as well. Though, if this is not expected to run on tidy, I wonder why `traffic_monitor_begin \"tidy\"` exists? This leaves macOS, which can be excluded. The other tasks, which do not use the CI infra anyway, so don't need to be excluded as well."
  },
  {
   "t": "2024-12-30T17:05:55Z",
   "kind": "comment",
   "who": "fjahr",
   "assoc": "MEMBER",
   "text": "Concept ACK\n\nThe changes in the tests look good but I need a little more time with the CI stuff. Maybe the PR could have been split there to get the critical fixes in faster but I guess it's a bit late now."
  },
  {
   "t": "2025-01-06T13:36:44Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "bbfc58a0af80265a9a53f5956f88c1915a686a7e"
  },
  {
   "t": "2025-01-06T13:38:35Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`48843ec694...bbfc58a0af`: rebase and \"If there are only a few tasks that do not work, it may be better to just carve them out, instead of enumerating all the ones that work\", see [above](https://github.com/bitcoin/bitcoin/pull/31349#discussion_r1896679919)."
  },
  {
   "t": "2025-01-06T13:41:44Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 1896679919,
   "text": "You are right! Flipped the logic to exclude only macOS.\n\nNo strong opinion on \"tidy\" - I added it because those tests should not generate internet traffic. Would drop it if requested."
  },
  {
   "t": "2025-01-06T15:02:36Z",
   "kind": "comment",
   "who": "fanquake",
   "assoc": "MEMBER",
   "text": "I tried testing the asan job, via `time MAKEJOBS=\"-j17\" FILE_ENV=\"./ci/test/00_setup_env_native_asan.sh\" ./ci/test_run_all.sh`, on a Fedora dev box, and it fails with the following output:\n```bash\n+ chown root:root /tmp/tcpdump_unitparallel_eth0\n++ tcpdump -n -r /tmp/tcpdump_unitparallel_eth0 --direction=out tcp or udp\nreading from file /tmp/tcpdump_unitparallel_eth0, link-type EN10MB (Ethernet), snapshot length 262144\n+ out='14:47:32.023429 IP6 1111:1111::4.33262 > 1111:1111::1.53: 9493+ A? debuginfod.fedoraproject.org. (46)\n14:47:32.023487 IP6 1111:1111::4.33262 > 1111:1111::1.53: 1815+ AAAA? debuginfod.fedoraproject.org. (46)\n14:47:32.050396 IP6 1111:1111::4.51620 > 1111:1111::1.53: 22098+ A? debuginfod.fedoraproject.org. (46)\n14:47:32.050457 IP6 1111:1111::4.51620 > 1111:1111::1.53: 19536+ AAAA? debuginfod.fedoraproject.org. (46)\n14:47:32.059718 IP6 1111:1111::4.48563 > 1111:1111::1.53: 672+ A? debuginfod.fedoraproject.org. (46)\n14:47:32.060018 IP6 1111:1111::4.48563 > 1111:1111::1.53: 1965+ AAAA? debuginfod.fedoraproject.org. (46)\n14:47:32.069417 IP6 1111:1111::1.53 > 1111:1111::4.51620: 22098 2/0/0 A 38.145.60.21, A 38.145.60.20 (78)\n14:47:32.069442 IP6 1111:1111::1.53 > 1111:1111::4.33262: 9493 2/0/0 A 38.145.60.21, A 38.145.60.20 (78)\n14:47:32.069467 IP6 1111:1111::1.53 > 1111:1111::4.48563: 672 2/0/0 A 38.145.60.21, A 38.145.60.20 (78)\n14:47:32.163955 IP6 1111:1111::4.41445 > 1111:1111::1.53: 34154+ A? debuginfod.fedoraproject.org. (46)\n14:47:32.164474 IP6 1111:1111::4.41445 > 1111:1111::1.53: 49518+ AAAA? debuginfod.fedoraproject.org. (46)\n14:47:32.164826 IP6 1111:1111::1.53 > 1111:1111::4.41445: 34154 2/0/0 A 38.145.60.21, A 38.145.60.20 (78)\n14:47:32.184123 IP6 1111:1111::4.51525 > 1111:1111::1.53: 40013+ A? debuginfod.fedoraproject.org. (46)\n14:47:32.184205 IP6 1111:1111::4.51525 > 1111:1111::1.53: 32841+ AAAA? debuginfod.fedoraproject.org. (46)\n14:47:32.186645 IP6 1111:1111::1.53 > 1111:1111::4.51525: 40013 2/0/0 A 38.145.60.21, A 38.145.60.20 (78)\n```"
  },
  {
   "t": "2025-01-07T11:12:00Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "The current CI failure is unrelated to this PR and is fixed separately in https://github.com/bitcoin/bitcoin/pull/31614. It will probably pass if the CI task is restarted because it is a race.\n\n[quoted text omitted]\n@fanquake so some piece of the command:\n\n```\nDIR_UNIT_TEST_DATA=\"${DIR_UNIT_TEST_DATA}\" LD_LIBRARY_PATH=\"${DEPENDS_DIR}/${HOST}/lib\" CTEST_OUTPUT_ON_FAILURE=ON ctest --stop-on-failure \"${MAKEJOBS}\" --timeout $(( TEST_RUNNER_TIMEOUT_FACTOR * 60 ))\n```\n\nGenerated DNS requests for `debuginfod.fedoraproject.org` :eyes: :open_mouth:. It is probably not `test_bitcoin` because grepping for `debuginfo` or `fedoraproject` in the entire code base of Bitcoin Core yields no results. Is this running directly on the host or inside docker? Looks like some spyware that calls home when `ctest` or `test_bitcoin` is run.\n\nEdit: if it is running on the host without docker then it could be that processes other than `ctest` and `test_bitcoin` are run during the tests and they generate the traffic. Related: https://fedoraproject.org/wiki/Debuginfod."
  },
  {
   "t": "2025-01-08T20:38:38Z",
   "kind": "comment",
   "who": "luke-jr",
   "assoc": "CONTRIBUTOR",
   "text": "[quoted text omitted]\n\nNot quite that, but iptables has the ability to match and log uid"
  },
  {
   "t": "2025-01-08T23:46:33Z",
   "kind": "comment",
   "who": "0xB10C",
   "assoc": "MEMBER",
   "text": "[quoted text omitted]\n\nI guess checking that we're in a docker container (that hopefully doesn't have other services that does anything network related) is the only option here. Only fail in docker, otherwise just print, if possible.\n\nPossibly by checking that `/proc/1/cgroup` exists and this is not empty with `cat /proc/1/cgroup | grep docker` - though I haven't tested this."
  },
  {
   "t": "2025-01-09T12:22:51Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "[quoted text omitted]\n\nNone of the CI tasks use fedora, so the only way to run the native_asan task on Fedora is to run it in a container, which still failed here. So I don't think your suggestion  will help, but I haven't tried it."
  },
  {
   "t": "2025-01-09T12:39:31Z",
   "kind": "comment",
   "who": "fanquake",
   "assoc": "MEMBER",
   "text": "Note that this isn't Fedora specific. The exact same issue happens on Ubuntu."
  },
  {
   "t": "2025-01-09T12:42:09Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "Maybe the test changes can be split up from the ci changes, given that this is still WIP?"
  },
  {
   "t": "2025-01-13T09:26:09Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "Extracted the changes to the tests in https://github.com/bitcoin/bitcoin/pull/31646 (suggested by @fjahr and @maflcko)."
  },
  {
   "t": "2025-01-13T09:35:58Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "@fanquake, is the problem you reported above https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-2573295321 when the tests run on the host, without a docker?"
  },
  {
   "t": "2025-01-13T11:01:41Z",
   "kind": "comment",
   "who": "Sjors",
   "assoc": "MEMBER",
   "text": "Concept ACK\n\nI tested this with https://github.com/Sjors/bitcoin/pull/76 on my own CI setup, which uses Cirrus workers configured using (roughly) the instructions here: https://github.com/bitcoin/bitcoin/blob/master/.cirrus.yml#L8 (using podman-docker)\n\n(I did run into an issue, left a comment there since it might be specific to my setup)"
  },
  {
   "t": "2025-01-13T11:16:21Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "I guess an env var is leaking into the docker. To reproduce you could try setting the URL via the env var `DEBUGINFOD_URLS=https://debuginfod.fedoraproject.org/ `, but I haven't tried it."
  },
  {
   "t": "2025-01-13T11:58:00Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "Checked locally that the following fails for me as well: `time env -i HOME=\"$HOME\" PATH=\"$PATH\" USER=\"$USER\" MAKEJOBS=\"-j$( nproc )\" FILE_ENV=\"./ci/test/00_setup_env_native_asan.sh\" DEBUGINFOD_URLS='https://debuginfod.fedoraproject.org/' ./ci/test_run_all.sh`\n\nIn theory it is not recommended to run the tests without a clean `env`, according to the `ci/README.md`. So I am not sure if this can be left as-is, or a workaround for DEBUGINFOD_URLS is convenient ."
  },
  {
   "t": "2025-01-15T08:21:27Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "69e076664d4fbc9c10a34dad4631ebd1139fa25d"
  },
  {
   "t": "2025-01-15T08:30:16Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`bbfc58a0af...69e076664d`: drop the tests changes from this PR because they were already merged via https://github.com/bitcoin/bitcoin/pull/31646. So here remains a CI change to detect future regressions.\n\nIf people want to run this manually, outside of the CI in a way that causes false positive (discussion above), what about something like this:\n\n```diff\n--- i/ci/test/03_test_script.sh\n+++ w/ci/test/03_test_script.sh\n@@ -184,13 +184,15 @@ function traffic_monitor_end()\n     # \"permission denied\" if they are not owned by root:root.\n     chown root:root \"$f\"\n     out=\"$(tcpdump -n -r \"$f\" --direction=out tcp or udp)\"\n     if [ -n \"$out\" ] ; then\n       echo \"Error: outbound TCP or UDP packets on the non loopback interface generated during $test_name tests:\" >&2\n       tcpdump -n -r \"$f\" tcp or udp\n-      exit 1\n+      if [ -z \"$INTERNET_TRAFFIC_EXPECTED\" ] ; then\n+        exit 1\n+      fi\n     fi\n   done\n }\n\n if [ \"$RUN_UNIT_TESTS\" = \"true\" ]; then\n   traffic_monitor_begin \"unitparallel\"\n```\n\nand then, obviously, set `INTERNET_TRAFFIC_EXPECTED=1` when running this manually (in unclean environment)? Or leave it as it is?"
  },
  {
   "t": "2025-02-21T07:53:27Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "76feae207dc1095d71f7efe7766ec8959eda81c8"
  },
  {
   "t": "2025-02-21T07:55:33Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`69e076664d...76feae207d`: rebase due to conflicts and allow to log but not treat as an error detected internet traffic (`$INTERNET_TRAFFIC_EXPECTED` mentioned above). Can be used when running manually outside of CI where other programs on the host can generate internet traffic."
  },
  {
   "t": "2025-04-16T14:33:23Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "4652f75bbfbe879f95dfa78d9fb4352137af3c76"
  },
  {
   "t": "2025-04-16T14:33:46Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`76feae207d...4652f75bbf`: rebase due to conflicts"
  },
  {
   "t": "2025-09-04T08:23:52Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "f400e0bb82920adf50fec1b9d701e8e85e62030a"
  },
  {
   "t": "2025-09-04T08:24:06Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`4652f75bbf...f400e0bb82`: rebase due to conflicts"
  },
  {
   "t": "2025-09-04T12:53:11Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "9dcbf6ccded636d78dca43b5cb920c206a89c7d8"
  },
  {
   "t": "2025-09-04T13:06:00Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "a9ac49c8accffeffaae72f54021fd939c951844c"
  },
  {
   "t": "2025-09-04T13:12:05Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`f400e0bb82...9dcbf6ccde`: fix a new case of non-loopback traffic from `node_init_tests/init_test`.\n\nThis PR originally contained a few fixes of tests that generated network traffic + a CI change to catch such future cases in CI. Then the tests fixes were moved to https://github.com/bitcoin/bitcoin/pull/31646 and merged. Then the activity here waned.\n\nNow there is a new case of network traffic generated by a test which went in `master` unnoticed. I have fixed that and included it here.\n\n`9dcbf6ccde...a9ac49c8ac`: rebase due to conflicts"
  },
  {
   "t": "2025-09-04T13:39:20Z",
   "kind": "review_comment",
   "who": "ryanofsky",
   "assoc": "MEMBER",
   "path": "src/test/node_init_tests.cpp",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": null,
   "text": "In commit \"ci: detect outbound internet traffic generated while running tests\" (f400e0bb82920adf50fec1b9d701e8e85e62030a)\n\nThanks for the fix! I think instead of manipulating CreateSock for this specific test it would be probably better to add `gArgs.ForceSetArg(\"-natpmp\", \"0\");` to `BasicTestingSetup::BasicTestingSetup`. Reasons:\n\n- It would work generally for all tests, not just this one test\n- This would make unit tests more consistent with [functional tests](https://github.com/bitcoin/bitcoin/blob/2d8f5b91881e53a9d29e85aa796fbc7e53a1a380/test/functional/test_framework/util.py#L460)\n- CreateSock seems like a band-aid more than a cure. I think the problem here is the test *trying* to use the network, not just being able to use it after it tries.\n\nIf you prefer current approach, though, it seems ok."
  },
  {
   "t": "2025-09-04T13:53:45Z",
   "kind": "review",
   "who": "ryanofsky",
   "assoc": "MEMBER",
   "state": "APPROVED",
   "commit": "a9ac49c8accffeffaae72f54021fd939c951844c",
   "text": "Code review ACK a9ac49c8accffeffaae72f54021fd939c951844c\n\nThanks for the fix! Note that this fix may (I'm not sure) mask an integer overflow issue https://github.com/bitcoin/bitcoin/pull/32345#discussion_r2294091366 that seems like it is a real bug.\n\nThe new tcpdump mechanism to detect unexpected traffic is pretty simple and seems very nice. Another idea could be to have unit test setup use `CreateSock` to throw errors if code attempts a remote connection to make errors a little easier to catch locally. But tcpdump solution is more general so seems like a good approach regardless."
  },
  {
   "t": "2025-09-04T15:29:24Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "778675ac717586407f2eee6ffd9ec41f2a3b1fdb"
  },
  {
   "t": "2025-09-04T15:29:27Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "src/test/node_init_tests.cpp",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 2322207556,
   "text": "Yeah, I thought about setting `-natpmp` to off, but decided would be better to test with the default arguments as that more closely matches the real world. That argument seems weak.\n\n[quoted text omitted]\nI agree. Changed to what you suggest above."
  },
  {
   "t": "2025-09-04T15:30:05Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`a9ac49c8ac...778675ac71`: pick https://github.com/bitcoin/bitcoin/pull/31349#discussion_r2322207556"
  },
  {
   "t": "2025-09-08T10:15:46Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5"
  },
  {
   "t": "2025-09-08T10:16:12Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`778675ac71...151edfaf78`: rebase due to conflicts"
  },
  {
   "t": "2025-09-09T13:40:58Z",
   "kind": "review",
   "who": "ryanofsky",
   "assoc": "MEMBER",
   "state": "APPROVED",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "text": "Code review ACK 151edfaf78115402c29088dabc271c2b268102a5. Just rebased since last review and replaced node_init_tests fix CreateSock fix with natpmp=0 fix"
  },
  {
   "t": "2025-09-09T14:12:02Z",
   "kind": "review_comment",
   "who": "sipa",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": null,
   "text": "This `INTERNET_TRAFFIC_EXPECTED` seems to be unused?"
  },
  {
   "t": "2025-09-11T09:04:43Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 2333792206,
   "text": "`INTERNET_TRAFFIC_EXPECTED` is a means to turn this into a non-fatal error. For folks that want to run the CI shell scripts outside of CI, in environments where other programs on the same machine create internet traffic. It came from here: https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-2591928909"
  },
  {
   "t": "2025-09-11T09:35:08Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "[quoted text omitted]\n\nI think that is worth exploring. Opened https://github.com/bitcoin/bitcoin/issues/33363 to track it, so that it does not get forgotten."
  },
  {
   "t": "2025-09-26T11:32:53Z",
   "kind": "review_comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 2333792206,
   "text": "Due to a silent merge conflict, this won't actually work. To pass the setting into the container, the hidden setting has to be \"documented\" now. For context, see https://github.com/bitcoin/bitcoin/blob/65e909dfdd934f033727e5404b5616a29dc18209/ci/test/02_run_container.py#L29-L34\n\nHowever, the silent conflict should have also fixed the bug that made this setting necessary in the first place.\n\nIt was added for https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-2586911979. However, I expect the command to now pass. (Haven't tried)"
  },
  {
   "t": "2025-09-26T12:44:17Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "f4fdf81d3a1811561ed35d6ce2424978be284d51"
  },
  {
   "t": "2025-09-26T12:45:00Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`151edfaf78...f4fdf81d3a`: rebase and [remove `INTERNET_TRAFFIC_EXPECTED`](https://github.com/bitcoin/bitcoin/pull/31349#discussion_r2333792206)."
  },
  {
   "t": "2025-09-26T12:45:31Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "151edfaf78115402c29088dabc271c2b268102a5",
   "in_reply_to": 2333792206,
   "text": "Removed `INTERNET_TRAFFIC_EXPECTED`. Maybe it was an overkill in the first place."
  },
  {
   "t": "2025-09-29T10:11:08Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "Updated the PR description. It referred to a older version of the PR."
  },
  {
   "t": "2025-09-29T19:16:35Z",
   "kind": "review",
   "who": "ryanofsky",
   "assoc": "MEMBER",
   "state": "APPROVED",
   "commit": "f4fdf81d3a1811561ed35d6ce2424978be284d51",
   "text": "Code review ACK f4fdf81d3a1811561ed35d6ce2424978be284d51, just dropping INTERNET_TRAFFIC_EXPECTED variable since last review"
  },
  {
   "t": "2025-09-29T19:25:03Z",
   "kind": "review_comment",
   "who": "fjahr",
   "assoc": "MEMBER",
   "path": "src/test/util/setup_common.cpp",
   "commit": "f4fdf81d3a1811561ed35d6ce2424978be284d51",
   "in_reply_to": null,
   "text": "nit: Would be nice to add a comment here so people don't have to hunt down the commit description."
  },
  {
   "t": "2025-09-29T21:58:40Z",
   "kind": "review_comment",
   "who": "fjahr",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "84bb496c6165154a64fcccd31e6ca5354531fd60",
   "in_reply_to": null,
   "text": "nit: here I would also like a bit of documention, maybe adding a small section in `ci/readme.md` would be the right place for this?"
  },
  {
   "t": "2025-09-29T21:58:48Z",
   "kind": "review",
   "who": "fjahr",
   "assoc": "MEMBER",
   "state": "COMMENTED",
   "commit": "f4fdf81d3a1811561ed35d6ce2424978be284d51",
   "text": "Hm, I was hoping I could easily test this by commenting out the change in the first commit and then running this in the CI, which I did by pushing to this branch: https://github.com/fjahr/bitcoin/commits/pr31349/ While not everything has finished, some job including unit tests succeeded and the only failing job [ran out of space](https://github.com/fjahr/bitcoin/actions/runs/18109731912/job/51532955001) which seems unrelated. Am I missing something here?"
  },
  {
   "t": "2025-09-30T12:36:36Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "39f90a4a78020087d19491be7b315ad91f252e46"
  },
  {
   "t": "2025-09-30T12:37:17Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "src/test/util/setup_common.cpp",
   "commit": "f4fdf81d3a1811561ed35d6ce2424978be284d51",
   "in_reply_to": 2389021877,
   "text": "Added `// Avoid non-loopback network traffic during tests.`"
  },
  {
   "t": "2025-09-30T12:39:03Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "84bb496c6165154a64fcccd31e6ca5354531fd60",
   "in_reply_to": 2389363270,
   "text": "I added brief comments to the newly added functions. `ci/README.md` seems to me too high level for this. No strong opinion though."
  },
  {
   "t": "2025-09-30T12:45:07Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`f4fdf81d3a...39f90a4a78`: add some comments, suggested by @fjahr above. Also, restore the `exit 1` which I accidentally removed in a previous push.\n\n[quoted text omitted]\nThe traffic is detected and reported in your CI jobs (search for `Error: outbound`), but there was no `exit 1` \ud83e\udd26. Sorry for that :face_in_clouds: :face_with_head_bandage:"
  },
  {
   "t": "2025-09-30T13:07:44Z",
   "kind": "review_comment",
   "who": "ryanofsky",
   "assoc": "MEMBER",
   "path": "src/test/util/setup_common.cpp",
   "commit": "17492c744cf37e7619a5b9dd7946013fa2e14d15",
   "in_reply_to": null,
   "text": "In commit \"test: avoid non-loopback network traffic from node_init_tests/init_test\" (d8372a220fb9691347d88547e381b8579ad35edb)\n\nCould be nice to add the same comment to functional test setup as well\n\nhttps://github.com/bitcoin/bitcoin/blob/25212dfdb4cd7291392b6a94130f658c5bfa0a48/test/functional/test_framework/util.py#L460"
  },
  {
   "t": "2025-09-30T13:10:20Z",
   "kind": "review_comment",
   "who": "ryanofsky",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "39f90a4a78020087d19491be7b315ad91f252e46",
   "in_reply_to": null,
   "text": "In commit \"ci: detect outbound internet traffic generated while running tests\" (39f90a4a78020087d19491be7b315ad91f252e46)\n\nNot important but these are global variables. Might be a little better to set as `local test_name=\"$1\"` etc"
  },
  {
   "t": "2025-09-30T13:12:04Z",
   "kind": "review",
   "who": "ryanofsky",
   "assoc": "MEMBER",
   "state": "APPROVED",
   "commit": "39f90a4a78020087d19491be7b315ad91f252e46",
   "text": "Code review ACK 39f90a4a78020087d19491be7b315ad91f252e46 just documenting things better since last review and adding missing `exit 1` to trigger CI failure (nice find!)"
  },
  {
   "t": "2025-09-30T14:13:41Z",
   "kind": "comment",
   "who": "fjahr",
   "assoc": "MEMBER",
   "text": "tACK 39f90a4a78020087d19491be7b315ad91f252e46\n\nThanks for addressing my comments! Tested again by pushing the latest version of the code with the change of the first commit commented out. I could observe the expected failure in the CI this time: https://github.com/fjahr/bitcoin/actions/runs/18131366221/job/51598667988\n\nI would be happy to re-review if you decide to address @ryanofsky 's latest comments."
  },
  {
   "t": "2025-09-30T14:14:54Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "c652deb3c16b7edccb741b9b473502092c0c2638"
  },
  {
   "t": "2025-09-30T14:15:16Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`39f90a4a78...c652deb3c1`: address suggestions"
  },
  {
   "t": "2025-09-30T14:15:33Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "39f90a4a78020087d19491be7b315ad91f252e46",
   "in_reply_to": 2391395521,
   "text": "Added `local`, thanks!"
  },
  {
   "t": "2025-09-30T14:15:45Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "src/test/util/setup_common.cpp",
   "commit": "17492c744cf37e7619a5b9dd7946013fa2e14d15",
   "in_reply_to": 2391385737,
   "text": "Done."
  },
  {
   "t": "2025-09-30T21:18:28Z",
   "kind": "comment",
   "who": "fjahr",
   "assoc": "MEMBER",
   "text": "re-ACK c652deb3c16b7edccb741b9b473502092c0c2638\n\nJust addressed @ryanofsky 's comments."
  },
  {
   "t": "2025-10-15T18:07:48Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "Not sure why I get this failure, but when installing a fresh Fedora VM, then podman-docker inside that, and then running this pull rebased, I got:\n\n```\nMAKEJOBS=\"-j$(nproc)\" FILE_ENV=\"./ci/test/00_setup_env_native_nowallet_libbitcoinkernel.sh\" ./ci/test_run_all.sh\n\n...\n\n100% tests passed, 0 tests failed out of 135\n\nTotal Test time (real) =  42.30 sec\n+ traffic_monitor_end unit\n+ test_name=unit\n++ get_interfaces\n++ set -o pipefail\n++ ifconfig\n++ awk -F ':| ' '/^[^[:space:]]/ { if (!match($1, /^lo/)) { print $1 } }'\n++ set +o pipefail\n+ for ifname in $(get_interfaces)\n++ tcpdump_file unit eth0\n++ local test_name=unit\n++ local interface_name=eth0\n++ echo /tmp/tcpdump_unit_eth0\n+ f=/tmp/tcpdump_unit_eth0\n+ '[' '!' -e /tmp/tcpdump_unit_eth0 ']'\n+ chown root:root /tmp/tcpdump_unit_eth0\n++ tcpdump -n -r /tmp/tcpdump_unit_eth0 --direction=out tcp or udp\nreading from file /tmp/tcpdump_unit_eth0, link-type EN10MB (Ethernet), snapshot length 262144\n+ out='17:59:15.979577 IP6 1111:1111::3.59201 > 1111:1111::1.53: 20844+ A? x9.dummySeed.invalid. (38)\n17:59:15.979644 IP6 1111:1111::3.59201 > 1111:1111::1.53: 49770+ AAAA? x9.dummySeed.invalid. (38)\n17:59:15.980117 IP6 1111:1111::1.53 > 1111:1111::3.59201: 20844 NXDomain* 0/0/0 (38)\n17:59:15.980200 IP6 1111:1111::1.53 > 1111:1111::3.59201: 49770 NXDomain* 0/0/0 (38)\n17:59:15.982301 IP6 1111:1111::3.51971 > 1111:1111::1.53: 35137+ A? x9.dummySeed.invalid. (38)\n17:59:15.982320 IP6 1111:1111::3.51971 > 1111:1111::1.53: 18242+ AAAA? x9.dummySeed.invalid. (38)\n17:59:15.983461 IP6 1111:1111::1.53 > 1111:1111::3.51971: 35137 NXDomain* 0/0/0 (38)\n17:59:15.983567 IP6 1111:1111::1.53 > 1111:1111::3.51971: 18242 NXDomain* 0/0/0 (38)'\n+ '[' -n '17:59:15.979577 IP6 1111:1111::3.59201 > 1111:1111::1.53: 20844+ A? x9.dummySeed.invalid. (38)\n17:59:15.979644 IP6 1111:1111::3.59201 > 1111:1111::1.53: 49770+ AAAA? x9.dummySeed.invalid. (38)\n17:59:15.980117 IP6 1111:1111::1.53 > 1111:1111::3.59201: 20844 NXDomain* 0/0/0 (38)\n17:59:15.980200 IP6 1111:1111::1.53 > 1111:1111::3.59201: 49770 NXDomain* 0/0/0 (38)\n17:59:15.982301 IP6 1111:1111::3.51971 > 1111:1111::1.53: 35137+ A? x9.dummySeed.invalid. (38)\n17:59:15.982320 IP6 1111:1111::3.51971 > 1111:1111::1.53: 18242+ AAAA? x9.dummySeed.invalid. (38)\n17:59:15.983461 IP6 1111:1111::1.53 > 1111:1111::3.51971: 35137 NXDomain* 0/0/0 (38)\n17:59:15.983567 IP6 1111:1111::1.53 > 1111:1111::3.51971: 18242 NXDomain* 0/0/0 (38)' ']'\n+ echo 'Error: outbound TCP or UDP packets on the non loopback interface generated during unit tests:'\nError: outbound TCP or UDP packets on the non loopback interface generated during unit tests:\n+ tcpdump -n -r /tmp/tcpdump_unit_eth0 tcp or udp\nreading from file /tmp/tcpdump_unit_eth0, link-type EN10MB (Ethernet), snapshot length 262144\n17:59:15.979577 IP6 1111:1111::3.59201 > 1111:1111::1.53: 20844+ A? x9.dummySeed.invalid. (38)\n17:59:15.979644 IP6 1111:1111::3.59201 > 1111:1111::1.53: 49770+ AAAA? x9.dummySeed.invalid. (38)\n17:59:15.980117 IP6 1111:1111::1.53 > 1111:1111::3.59201: 20844 NXDomain* 0/0/0 (38)\n17:59:15.980200 IP6 1111:1111::1.53 > 1111:1111::3.59201: 49770 NXDomain* 0/0/0 (38)\n17:59:15.982301 IP6 1111:1111::3.51971 > 1111:1111::1.53: 35137+ A? x9.dummySeed.invalid. (38)\n17:59:15.982320 IP6 1111:1111::3.51971 > 1111:1111::1.53: 18242+ AAAA? x9.dummySeed.invalid. (38)\n17:59:15.983461 IP6 1111:1111::1.53 > 1111:1111::3.51971: 35137 NXDomain* 0/0/0 (38)\n17:59:15.983567 IP6 1111:1111::1.53 > 1111:1111::3.51971: 18242 NXDomain* 0/0/0 (38)\n+ exit 1\n```\n\nFor reference, that IP is from `ci/test/02_run_container.sh:  docker network create --ipv6 --subnet 1111:1111::/112 ci-ip6net || true`\n\nThough, `FILE_ENV=\"./ci/test/00_setup_env_native_previous_releases.sh\"` passes fine :shrug:"
  },
  {
   "t": "2025-10-16T08:36:20Z",
   "kind": "comment",
   "who": "fanquake",
   "assoc": "MEMBER",
   "text": "Yea, I have seen the same, on one of my Fedora boxes, which would be a blocker, given it breaks running the CI locally."
  },
  {
   "t": "2025-10-16T08:59:44Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "6e0f3a4a58916301bbf3e38242e97d8d3408d47f"
  },
  {
   "t": "2025-10-16T09:01:10Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`c652deb3c1...6e0f3a4a58`: rebase due to conflicts\n\n[quoted text omitted]\nIt is making requests to the DNS server at `1111:1111::1.53`, trying to resolve `x9.dummySeed.invalid.`\n\nhttps://github.com/bitcoin/bitcoin/blob/e14451ac87339ed61b8c872f027184a978dd96eb/src/kernel/chainparams.cpp#L596-L598"
  },
  {
   "t": "2025-10-16T11:07:40Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "[quoted text omitted]\n\nYes, I understand this, but I don't understand why the CI is green on this pull request here, but it fails locally when using podman. I guess it could be due to running as root inside the VM. Though, the failure seemingly not being reproducible on every run makes it even more odd.\n\nMy cmd history today (once it passed, once it failed):\n\n```\n   1  git clone https://github.com/vasild/bitcoin/ --depth=1 --branch=test_log_internet_traffic ./test_oct_16\n   2  cd test_oct_16/\n   3  env -i RUN_FUNCTIONAL_TESTS=false HOME=\"$HOME\" PATH=\"$PATH\" USER=\"$USER\" MAKEJOBS=\"-j$(nproc)\" FILE_ENV=\"./ci/test/00_setup_env_native_nowallet_libbitcoinkernel.sh\" ./ci/test_run_all.sh"
  },
  {
   "t": "2025-10-16T14:01:57Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "I can't reproduce locally. An attempt to resolve `x9.dummySeed.invalid.` during unit tests looks like one of those issues that this PR aims to uncover."
  },
  {
   "t": "2025-10-21T09:28:38Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "[quoted text omitted]\n\nAre you sure? Above I tried on Fedora podman-docker, and today it also failed on Ubuntu podman-docker:\n\n```\n(root)# docker --version\nEmulate Docker CLI using podman. Create /etc/containers/nodocker to quiet msg.\npodman version 4.9.3"
  },
  {
   "t": "2025-10-21T12:11:48Z",
   "kind": "comment",
   "who": "fanquake",
   "assoc": "MEMBER",
   "text": "Yea. Still failing for me with Podman (5.6.2) on my Fedora box."
  },
  {
   "t": "2025-10-21T13:15:12Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "From the output, I think there may be several unit tests affected, and they should probably be fixed, even if the GHA CI does not catch this issue.\n\nAlso, I tried on a fresh Ubuntu VM with a fresh user account (not root) and the issue persists. So I think the issue generally uncovers via podman."
  },
  {
   "t": "2025-11-20T07:19:45Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "47f4f65d0c8ba4680bab45b085939ace9624f3a2"
  },
  {
   "t": "2025-11-20T08:55:28Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`6e0f3a4a58...47f4f65d0c`: rebase due to conflicts\n\nIs the local failure you observe reproducible or sporadic? If it is reproducible maybe you can nail down which test is making the traffic? Previously to find the offending test I bisected the list of tests (used to nail down the traffic from `node_init_tests/init_test` which is fixed in this PR). Here is a write-only script to list all tests (681 currently) and run only e.g. from 1 to 340:\n\n```sh\nBUILD/bin/test_bitcoin $(BUILD/bin/test_bitcoin --list_content 2>&1 |(IFS=\"*\" ; while read line ; do line_trim=\"$(sed 's/^[[:space:]]*//' <<<$line)\" ; if [ \"$line\" = \"$line_trim\" ] ; then s=\"$line\" ; continue ; fi ; echo \"--run_test=$s/$line_trim\" ; done |sed -n '1,340p'))\n```\n\nThis can be substituted for:\n\nhttps://github.com/bitcoin/bitcoin/blob/1af46cff947802828ee15dccc0ea1d603074cde7/ci/test/03_test_script.sh#L178-L181"
  },
  {
   "t": "2025-12-17T19:21:32Z",
   "kind": "review",
   "who": "ryanofsky",
   "assoc": "MEMBER",
   "state": "APPROVED",
   "commit": "47f4f65d0c8ba4680bab45b085939ace9624f3a2",
   "text": "Code review ACK 47f4f65d0c8ba4680bab45b085939ace9624f3a2. Since last review just rebased to avoid conflicts, added comments to commit message and test, added `local` to some bash variables"
  },
  {
   "t": "2025-12-17T19:28:18Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "[quoted text omitted]\n\nMaybe 50%, see my previous comment: https://github.com/bitcoin/bitcoin/pull/31349#issuecomment-3410342332.\n\nI guess this makes bisect a bit harder, but it should be possible by running 10 times, or so."
  },
  {
   "t": "2025-12-18T13:16:44Z",
   "kind": "comment",
   "who": "fanquake",
   "assoc": "MEMBER",
   "text": "Still fails for me running the CI (via Podman 5.7.1) on my Fedora box (this PR rebased on master):\n```bash\nALL                                                    | \u2713 Passed  | 6980 s (accumulated)\nRuntime: 1243 s\n\n+ traffic_monitor_end functional\n+ test_name=functional\n++ get_interfaces\n++ set -o pipefail\n++ ifconfig\n++ awk -F ':| ' '/^[^[:space:]]/ { if (!match($1, /^lo/)) { print $1 } }'\n++ set +o pipefail\n+ for ifname in $(get_interfaces)\n++ tcpdump_file functional eth0\n++ local test_name=functional\n++ local interface_name=eth0\n++ echo /tmp/tcpdump_functional_eth0\n+ f=/tmp/tcpdump_functional_eth0\n+ '[' '!' -e /tmp/tcpdump_functional_eth0 ']'\n+ chown root:root /tmp/tcpdump_functional_eth0\n++ tcpdump -n -r /tmp/tcpdump_functional_eth0 --direction=out tcp or udp\nreading from file /tmp/tcpdump_functional_eth0, link-type EN10MB (Ethernet), snapshot length 262144\n<snip>\n+ echo 'Error: outbound TCP or UDP packets on the non loopback interface generated during functional tests:'\nError: outbound TCP or UDP packets on the non loopback interface generated during functional tests:\n+ tcpdump -n -r /tmp/tcpdump_functional_eth0 tcp or udp\nreading from file /tmp/tcpdump_functional_eth0, link-type EN10MB (Ethernet), snapshot length 262144\n<snip>\n+ exit 1\nCommand '['./ci/test/02_run_container.sh']' returned non-zero exit status 1.\n\nreal\t43m11.110s\nuser\t0m55.959s\nsys\t0m45.018s\n```"
  },
  {
   "t": "2025-12-18T14:29:29Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "This is intended to work on CI and it does so well. Should I reintroduce [INTERNET_TRAFFIC_EXPECTED](https://github.com/bitcoin/bitcoin/pull/31349#discussion_r2333792206) to deal with local runs by making it possible to turn these reports into non-fatal errors?"
  },
  {
   "t": "2025-12-18T14:32:08Z",
   "kind": "comment",
   "who": "fanquake",
   "assoc": "MEMBER",
   "text": "[quoted text omitted]\n\nBeing able to run the CI locally is fully supported and a required use case (there are CI jobs which are not run in the main repo)."
  },
  {
   "t": "2025-12-18T14:48:57Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "I tend to agree with @fanquake. Running the CI locally should be easy and supported. We don't want to end up in a place where the CI is basically just a prayer toward Microsoft/GHA to please run the scripts and to please run them correctly.\n\nI think the open questions are:\n\n* Why does the GHA CI *not* catch the issue seen in local runs?\n* Which test is responsible for the issues in local runs, and what is the fix?"
  },
  {
   "t": "2026-01-23T16:02:43Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "[quoted text omitted]\n\nI think we don't use static linking in the CI, so `LD_PRELOAD` could be used here. Either an off-the-shelf tool like https://chris-lamb.co.uk/posts/disabling-internet-specific-processes-libfiu, or something self-brewed, that aborts and then prints the full stacktrace."
  },
  {
   "t": "2026-02-04T14:36:08Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "31e20d76eefdb8800acbed7cd71a5c86556396c7"
  },
  {
   "t": "2026-02-04T14:38:07Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`47f4f65d0c8ba4680bab45b085939ace9624f3a2...31e20d76eefdb8800acbed7cd71a5c86556396c7`: rebase due to conflicts\n\n[quoted text omitted]\n@fanquake, @maflcko what do you think about this?"
  },
  {
   "t": "2026-02-04T15:15:25Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "I've already replied (see the several comments above). To summarize:\n\n* This seems like a Github-only feature right now: Instead of further entangling with a centralized third party that has in the past shown bad judgement when it comes to hosting open source software (yt-dl, OSS issues spam, ...), it would be better to write vendor-agnostic and platform-agnostic code.\n* Even if GitHub was more trustworthy, putting everything in their hands without having an easy way to run the check locally seems odd.\n* The current GitHub config doesn't even catch the issues that were found when running this locally, underlining the last point.\n* The current failures are non-deterministic, which is a blocker to merging this. We have enough intermittent issues already, and I don't think it is a good use of time to add more, when there isn't even enough time to  track and deal with the existing ones.\n* Even if the failures were deterministic, there isn't an easy way to find out where they originate.\n\nGenerally, when it comes to CI failures, they should ideally be easily reproducible, and understandable, and actionable."
  },
  {
   "t": "2026-02-04T15:22:47Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "Also, the CI fails here:\n\n```\n\n2026-02-04T14:47:42.5515093Z ++ get_interfaces\n2026-02-04T14:47:42.5515140Z ++ set -o pipefail\n2026-02-04T14:47:42.5515193Z ++ ifconfig\n2026-02-04T14:47:42.5515285Z ++ awk -F ':| ' '/^[^[:space:]]/ { if (!match($1, /^lo/)) { print $1 } }'\n2026-02-04T14:47:42.5515330Z ++ set +o pipefail\n2026-02-04T14:47:42.5515389Z + for ifname in $(get_interfaces)\n2026-02-04T14:47:42.5515440Z ++ tcpdump_file tidy eth0\n2026-02-04T14:47:42.5515488Z ++ local test_name=tidy\n2026-02-04T14:47:42.5515539Z ++ local interface_name=eth0\n2026-02-04T14:47:42.5515597Z ++ echo /tmp/tcpdump_tidy_eth0\n2026-02-04T14:47:42.5515650Z + f=/tmp/tcpdump_tidy_eth0\n2026-02-04T14:47:42.5515705Z + '[' '!' -e /tmp/tcpdump_tidy_eth0 ']'\n2026-02-04T14:47:42.5515755Z + '[' '' = 1 ']'\n2026-02-04T14:47:42.5515814Z + chown root:root /tmp/tcpdump_tidy_eth0\n2026-02-04T14:47:42.5515924Z chown: cannot access '/tmp/tcpdump_tidy_eth0': No such file or directory\n2026-02-04T14:47:42.5516267Z Command '['docker', 'exec', '6bbd21ffa835315ad85b36569530424f74269bf340657c40b4bf0a96fdd16747', '/home/admin/actions-runner/_work/_temp/ci/test/03_test_script.sh']' returned non-zero exit status 1."
  },
  {
   "t": "2026-02-04T17:18:00Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "23605aa86ce05da8c9eb9d3598a749898dba70d6"
  },
  {
   "t": "2026-02-04T17:39:58Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "[quoted text omitted]\n\n[quoted text omitted]\nLink? The idea is to make these checks suppress-able. Or even it can be made to run only in CI and not on local runs by default, if e.g. `INTERNET_TRAFFIC_EXPECTED` is enabled by default and CI explicitly disables it.\n\nThat would be better than the current situation. Right now it is not running on CI and is not running locally.\n\n[quoted text omitted]\n`31e20d76eefdb8800acbed7cd71a5c86556396c7...23605aa86ce05da8c9eb9d3598a749898dba70d6`: fix a flawed git-auto-resolved-conflict.\n\n[quoted text omitted]\nIt is changing some docker parameters and is using `tcpdump` inside the VM. Why do you think that is \"Github-only\"?\n\n[quoted text omitted]\nThose are failures when you ran it locally which I could not reproduce. CI is green and I have no idea what to do from here. I do not think that the current tests we have non-deterministically, sometimes, generate internet traffic and sometimes don't.\n\n[quoted text omitted]\nTrue. My thinking is that if it bricks the CI on some PR, then the author of the PR will have an idea which part of their changes are causing it."
  },
  {
   "t": "2026-02-04T20:14:48Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "[quoted text omitted]\n\nMaybe, if the changes are just adding an obvious remote call. Though, if there is a pre-existing issue in one of the background threads, and the failure is racy, and the pull request triggers this as a side-effect, it will be less clear.\n\n[quoted text omitted]\nI think suppressions make sense where they are understood to suppress a known false-positive, or a known don't-care scenario.\n\nUsing a suppression to wholesale disable a feature locally in the presence of true-positives seems odd.\n\n[quoted text omitted]\nYour suggestion is to run \"not on local runs\", which I understand as \"GitHub-only\".\n\n[quoted text omitted]\nThere is more than just myself who ran into the issue. Traffic to `\"dummySeed.invalid.\"` doesn't look like a false-positive to me. And it was non-deterministically for me.\n\nAs I already mentioned, a solution to this problem would be to print a stacktrace when the call happens, and then abort the program/CI immediately. This would make any failure traceable, and thus hopefully fixable."
  },
  {
   "t": "2026-05-01T10:08:36Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "17492c744cf37e7619a5b9dd7946013fa2e14d15"
  },
  {
   "t": "2026-05-01T10:19:11Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`23605aa86ce05da8c9eb9d3598a749898dba70d6...17492c744cf37e7619a5b9dd7946013fa2e14d15`: rebase due to conflicts\n\nHow can I move this forward? It is stuck in some local unexplained \"internet traffic detected\" failures in local runs by @maflcko and @fanquake that I could not reproduce. My suggestion to add (restore) the option to make \"internet traffic detected\" errors non-fatal so that local runs can always succeed do not seem to gain traction with @maflcko and @fanquake.\n\nFurther, @maflcko suggests it would be better if a backtrace is printed when a test tries to access internet. I agree this would be better, but there is no patch for that and nobody is working on it as far as I know.\n\nFor the time being I will be rebasing this more frequently which would do the job of detecting regressions on `master` here in this PR. Should also extract the first commit `test: avoid non-loopback network traffic from node_init_tests/init_test` into its own PR (_edit: done in https://github.com/bitcoin/bitcoin/pull/35193_)."
  },
  {
   "t": "2026-05-05T14:55:41Z",
   "kind": "comment",
   "who": "maflcko",
   "assoc": "MEMBER",
   "text": "I think to move it forward in the current state without the detailed backtrace, it would have to be opt-in. Otherwise, basically all places uses podman would have to opt-out. However, then the value would be limited, because no one would enable it? So it would be a GitHub-CI-only feature, basically? I think there is value here, re-Concept ACK, to clarify."
  },
  {
   "t": "2026-05-15T09:42:21Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "c7e331d5fc82378c84f056eb6703c9712d451ed1"
  },
  {
   "t": "2026-05-15T10:11:43Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`17492c744cf37e7619a5b9dd7946013fa2e14d15...c7e331d5fc82378c84f056eb6703c9712d451ed1`: rebase and run unit tests with `-dnsseed=0` as per the [comment](https://github.com/bitcoin/bitcoin/pull/35193#issuecomment-4408027938) from @ferminquant, thank you :heart:!\n\nI think what was going on was this - without `-dnsseed=0` some tests were still using the DNS seeds. If the local resolver was configured to be at `127.0.0.1` (`nameserver` in `/etc/resolv.conf`) and that resolver did not forward requests further, then this was not detected because the code in `ci/test/03_test_script.sh` was considering loopback traffic as safe. Otherwise the DNS traffic was detected and reported as non-loopback traffic.\n\nI played with this locally with a non-127.0.0.1 resolver and DNS queries were made to the resolver only sometimes. My guess is that the OS does some basic caching, so if e.g. `x9.dummySeed.invalid.` is once resolved, a subsequent query for that will not be send to the resolver.\n\nThat said, with the addition of `-dnsseed=0` this should be robust and work as intended on docker or podman, locally or in CI cloud. Anyway I do not mind re-adding the option to make the errors non-fatal if people think it would be useful. That is - make it opt-in (@maflcko) with default enabled.\n\n`strace -f -e trace=network test_bitcoin --run_test=node_init_tests/init_test` can be used to inspect individual tests (thanks, @ferminquant) which might be more convenient than bisecting the pile of all tests under `tcpdump` which I have used before to nail down an offending test."
  },
  {
   "t": "2026-05-15T10:15:21Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "f439badbefd4f96a83e161f991a326924cdbb3a6"
  },
  {
   "t": "2026-05-18T17:56:54Z",
   "kind": "review_comment",
   "who": "ryanofsky",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "84bb496c6165154a64fcccd31e6ca5354531fd60",
   "in_reply_to": null,
   "text": "In commit \"test: avoid non-loopback network traffic from node_init_tests/init_test\" (1c500b17098e2c65129a1dda7345b9961f4a951f)\n\nLooks like there is a bug here because `filter` variable is not reset if `ifname` does not begin with \"lo\". Also filter is not declared as a local variable so it will persist between calls. (Would also suggest declaring other variables like `test_name`, `f`, and `out` local here and below)"
  },
  {
   "t": "2026-05-18T18:02:11Z",
   "kind": "review",
   "who": "ryanofsky",
   "assoc": "MEMBER",
   "state": "COMMENTED",
   "commit": "f439badbefd4f96a83e161f991a326924cdbb3a6",
   "text": "Code review f439badbefd4f96a83e161f991a326924cdbb3a6. Looks good and it would be nice if the dnsseed fix resolves things so the PR isn't blocked.\n\nI think there is a bug that could cause non-port 53 traffic on non-loopback interfaces to be ignored, see comment below."
  },
  {
   "t": "2026-06-18T11:12:03Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "ac04209081e915ec96f5ef3a6140f2233594aea8"
  },
  {
   "t": "2026-06-18T11:12:50Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`f439badbefd4f96a83e161f991a326924cdbb3a6...ac04209081e915ec96f5ef3a6140f2233594aea8`: rebase due to conflict and take suggestion https://github.com/bitcoin/bitcoin/pull/31349#discussion_r3260950846"
  },
  {
   "t": "2026-06-18T11:13:07Z",
   "kind": "review_comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "84bb496c6165154a64fcccd31e6ca5354531fd60",
   "in_reply_to": 3260950846,
   "text": "Done, thanks!"
  },
  {
   "t": "2026-06-18T12:19:43Z",
   "kind": "comment",
   "who": "fanquake",
   "assoc": "MEMBER",
   "text": "```bash\nIn ci/test/03_test_script.sh line 224:\n    local f=$(tcpdump_file \"$test_name\" \"$ifname\")\n          ^-- SC2155 (warning): Declare and assign separately to avoid masking return values.\n\nIn ci/test/03_test_script.sh line 235:\n    local out=\"$(tcpdump -n -r \"$f\" --direction=out tcp or udp)\"\n          ^-^ SC2155 (warning): Declare and assign separately to avoid masking return values.\n\nFor more information:\n  https://www.shellcheck.net/wiki/SC2155 -- Declare and assign separately to ...\n^---- \u26a0\ufe0f Failure generated from lint-shell.py\n```"
  },
  {
   "t": "2026-06-18T12:31:58Z",
   "kind": "force_push",
   "who": "vasild",
   "commit": "84bb496c6165154a64fcccd31e6ca5354531fd60"
  },
  {
   "t": "2026-06-18T12:34:27Z",
   "kind": "comment",
   "who": "vasild",
   "assoc": "MEMBER",
   "text": "`ac04209081e915ec96f5ef3a6140f2233594aea8...84bb496c6165154a64fcccd31e6ca5354531fd60`: pet shell linter"
  },
  {
   "t": "2026-08-27T11:32:43Z",
   "kind": "comment",
   "who": "sedited",
   "assoc": "MEMBER",
   "text": "@ryanofsky @fjahr @maflcko can you give this another look?"
  },
  {
   "t": "2026-08-28T13:09:11Z",
   "kind": "review_comment",
   "who": "fjahr",
   "assoc": "MEMBER",
   "path": "ci/test/03_test_script.sh",
   "commit": "84bb496c6165154a64fcccd31e6ca5354531fd60",
   "in_reply_to": null,
   "text": "It seems that `--direction` is only enforced at capture time, so it should be moved to the tcpdump call in `traffic_monitor_begin()`. Or maybe just delete here if we don't want to filter there because here it seems to be no op."
  },
  {
   "t": "2026-08-28T18:38:15Z",
   "kind": "review",
   "who": "fjahr",
   "assoc": "MEMBER",
   "state": "COMMENTED",
   "commit": "84bb496c6165154a64fcccd31e6ca5354531fd60",
   "text": "Looks good to me aside from the seeming misuse of `--direction`."
  }
 ],
 "labels_log": [
  {
   "t": "2024-11-22T13:58:50Z",
   "action": "labeled",
   "label": "Tests",
   "who": "DrahtBot"
  },
  {
   "t": "2024-11-22T14:12:26Z",
   "action": "labeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2024-11-25T10:30:16Z",
   "action": "unlabeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2024-11-25T12:51:56Z",
   "action": "labeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2024-11-25T13:17:49Z",
   "action": "unlabeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2024-11-27T16:42:39Z",
   "action": "labeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2024-11-29T13:10:12Z",
   "action": "unlabeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2024-12-05T00:35:01Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2024-12-05T08:57:52Z",
   "action": "labeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2024-12-05T09:02:45Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2024-12-05T11:22:35Z",
   "action": "unlabeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2024-12-13T12:00:28Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2024-12-17T14:30:13Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2024-12-17T16:31:00Z",
   "action": "labeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2024-12-17T18:01:37Z",
   "action": "unlabeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2025-01-14T21:08:54Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-01-15T11:11:50Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-01-17T13:12:52Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-02-21T08:39:20Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-04-02T14:16:57Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-04-16T14:40:06Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-07-14T12:49:24Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-09-04T10:42:24Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-09-04T12:58:50Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-09-04T15:26:09Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-09-05T17:45:44Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-09-08T12:07:56Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-10-15T12:12:14Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-10-16T09:40:39Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-10-29T10:52:40Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-11-20T07:59:59Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2025-11-20T08:09:33Z",
   "action": "labeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2025-12-08T15:45:00Z",
   "action": "unlabeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2026-02-03T13:27:36Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2026-02-04T15:57:02Z",
   "action": "labeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2026-02-04T16:00:36Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2026-02-04T18:16:17Z",
   "action": "unlabeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2026-03-13T10:41:43Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2026-05-01T10:59:11Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2026-05-15T10:15:52Z",
   "action": "labeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2026-05-15T11:14:06Z",
   "action": "unlabeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2026-06-11T15:33:36Z",
   "action": "labeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2026-06-18T12:06:35Z",
   "action": "unlabeled",
   "label": "Needs rebase",
   "who": "DrahtBot"
  },
  {
   "t": "2026-06-18T12:16:55Z",
   "action": "labeled",
   "label": "CI failed",
   "who": "DrahtBot"
  },
  {
   "t": "2026-06-18T13:35:27Z",
   "action": "unlabeled",
   "label": "CI failed",
   "who": "DrahtBot"
  }
 ],
 "state_log": [
  {
   "t": "2024-11-28T17:30:00Z",
   "kind": "convert_to_draft",
   "who": "vasild"
  },
  {
   "t": "2024-12-03T10:48:48Z",
   "kind": "ready_for_review",
   "who": "vasild"
  }
 ],
 "text_chars": 80001,
 "text_tokens_estimate": 20000,
 "changed_paths": [
  "ci/test/00_setup_env.sh",
  "ci/test/00_setup_env_mac_native.sh",
  "ci/test/00_setup_env_mac_native_fuzz.sh",
  "ci/test/00_setup_env_native_alpine_musl.sh",
  "ci/test/02_run_container.py",
  "ci/test/03_test_script.sh"
 ],
 "files": [
  {
   "path": "ci/test/00_setup_env.sh",
   "add": 1,
   "del": 1
  },
  {
   "path": "ci/test/00_setup_env_mac_native.sh",
   "add": 2,
   "del": 0
  },
  {
   "path": "ci/test/00_setup_env_mac_native_fuzz.sh",
   "add": 2,
   "del": 0
  },
  {
   "path": "ci/test/00_setup_env_native_alpine_musl.sh",
   "add": 1,
   "del": 1
  },
  {
   "path": "ci/test/02_run_container.py",
   "add": 1,
   "del": 0
  },
  {
   "path": "ci/test/03_test_script.sh",
   "add": 70,
   "del": 0
  }
 ],
 "test_lines": 79,
 "git": {
  "head": "84bb496c6165154a64fcccd31e6ca5354531fd60",
  "head_matches_backup": true,
  "base": "341360964a6fef725825639edc507c275f8ad0b2",
  "commits": [
   {
    "sha": "84bb496c61",
    "subject": "ci: detect outbound internet traffic generated while running tests",
    "files": 6,
    "add": 77,
    "del": 2
   }
  ],
  "patch_truncated": false
 },
 "input_hash": "fdb4836e18e1e1da",
 "extracted_at": "2026-09-17T16:15:31+00:00"
}