public inbox for passt-dev@passt.top
 help / color / mirror / code / Atom feed
From: Paul Holzinger <pholzing@redhat.com>
To: David Gibson <david@gibson.dropbear.id.au>,
	Yuxi Liu <yuxi_liu@berkeley.edu>
Cc: passt-dev@passt.top
Subject: Re: [BUG] --map-guest-addr target resolved once at startup; host network change kills the mapping silently and permanently
Date: Mon, 27 Jul 2026 11:55:25 +0200	[thread overview]
Message-ID: <8a7a4a65-33f8-4442-80cc-8dcc3d616127@redhat.com> (raw)
In-Reply-To: <ama4jkMCI5z4tUNV@zatzit>


On 27/07/2026 03:47, David Gibson wrote:
> On Sat, Jul 25, 2026 at 09:28:14AM -0700, Yuxi Liu wrote:
>> Hello,
>>
>> Bug report against pasta, as used by rootless podman for
>> host.containers.internal.
>>
>> What happens
>> ------------
>> Rootless container, default pasta networking (podman passes
>> --no-map-gw --map-guest-addr 169.254.1.2), on a laptop. The laptop
>> moves to a different network (hotel wifi, home, office). From that
>> moment, every connection from the container to 169.254.1.2 times out.
>> Forever. General outbound from the container keeps working, so the
>> failure looks like the host service died. The host service is fine and
>> answers on the host the whole time. Only recreating the container
>> fixes the route.
>>
>> Why it happens
>> --------------
>> --map-guest-addr forwards mapped traffic to the host's external
>> address (commit 57b7bd2). pasta resolves that address once, at
>> startup, and never again. After the host moves networks, pasta still
>> connect()s to the launch-time address. Nobody owns that address
>> anymore, the SYNs vanish, and no error is logged anywhere.
>>
>> pasta already runs a live netlink monitor in its event loop
>> (RTMGRP_NEIGH, neighbour events). Host address changes are the one
>> thing it reads once at startup and never watches afterward. Re-reading
>> the current address needs no privilege: getifaddrs() works for any
>> process.
> Right.  This is a known limitation.  We're working on it, but it's
> fairly difficult to fix correctly, because it interacts with a bunch
> of other features.  This is largely tracked by this bug:
>      https://bugs.passt.top/show_bug.cgi?id=141
And tracked for podman here already as well:
https://github.com/podman-container-tools/podman/issues/24970
>
>> Reproduce
>> ---------
>> 1. Laptop on wifi network A. Run a rootless podman container with the
>> default pasta network. Have any service listening on the host,
>> say port 8191.
>> 2. In the container: curl
>> https://www.google.com/url?q=http://host.containers.internal:8191&source=gmail&ust=1785083212577000&sa=E
>> -> answers.
>> 3. Move the laptop to wifi network B.
>> 4. Same curl -> timeout. Stays dead until the container is recreated.
>>
>> Versions: passt 0.0~git20250503.587980c-2 (Ubuntu 25.10),
>> podman 5.4.2.
>>
>> Expected
>> --------
>> One of:
>> 1. pasta re-resolves the mapping target when the host's addresses
>> change, or
>> 2. the mapped route fails loudly (RST) instead of silently, or
>> 3. the man page warns that the mapping dies permanently on host
>> network change.
>>
>> Laptops are a mainstream platform for rootless podman. A silent,
>> permanent route death on every wifi change is a serious defect for
>> them.
>>
>> Workaround
>> ----------
>> --map-guest-addr none --map-host-loopback 169.254.1.2 (via podman:
>> --network=pasta:--map-guest-addr,none,--map-host-loopback,169.254.1.2).
>> Mapped traffic then arrives on the host as 127.0.0.1, which the host
>> owns on every network. This changes source semantics (connections
>> appear to come from loopback), which is acceptable when you control
>> both sides.
> Right, for your use case, --map-host-loopback seems like a good
> workaround.  Even when we implement a netlink monitor,
> --map-guest-addr (or its future equivalent) can't really work when the
> laptop is not on any external network, because there is no external
> host address to direct traffic to.
>
-- 
Paul Holzinger


  reply	other threads:[~2026-07-27  9:55 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-25 16:28 Yuxi Liu
2026-07-27  1:47 ` David Gibson
2026-07-27  9:55   ` Paul Holzinger [this message]
2026-07-27 16:48 ` Stefano Brivio

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8a7a4a65-33f8-4442-80cc-8dcc3d616127@redhat.com \
    --to=pholzing@redhat.com \
    --cc=david@gibson.dropbear.id.au \
    --cc=passt-dev@passt.top \
    --cc=yuxi_liu@berkeley.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this public inbox

	https://passt.top/passt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).