From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=ifacCPBr; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by passt.top (Postfix) with ESMTPS id 292FA5A026E for ; Mon, 27 Jul 2026 11:55:32 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785146131; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=0xcgJiUlFNPg3bov1cGXcEal+o6gy5S2wmds85TDlLw=; b=ifacCPBrokeZM3DOy7xQgphqsQRZNh/xzjW1fbsboVZJ4O7gNmxFfsMvROFFPvoMrvB+9q ny+ZxbLdBDo3o/savreApakCyDZUN8fGXFlVw6nfT/6NYuv74eQvn+Be9jIhvFBNNoMzOp AL7TFrZmdKGDh/QfFTXKJND87LheP4A= Received: from mail-ed1-f72.google.com (mail-ed1-f72.google.com [209.85.208.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-190-CE2ryoSZPECRQhC69q9ZSw-1; Mon, 27 Jul 2026 05:55:29 -0400 X-MC-Unique: CE2ryoSZPECRQhC69q9ZSw-1 X-Mimecast-MFC-AGG-ID: CE2ryoSZPECRQhC69q9ZSw_1785146128 Received: by mail-ed1-f72.google.com with SMTP id 4fb4d7f45d1cf-69cd6606b19so2363465a12.1 for ; Mon, 27 Jul 2026 02:55:29 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785146128; x=1785750928; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0xcgJiUlFNPg3bov1cGXcEal+o6gy5S2wmds85TDlLw=; b=rzmHLsD3v3yVnZYy3WJildajjsp8XCiB27VJcaybJImfiNjSoHC3tPLtHF0JSPGT21 gvNuf3yjJg1CKjdCf/QYPeIzG+g+OIQssL/GqEPw5xLjDTijTxuOw0qBcNABNchPfyZI yjTQ8mRzQFO8Lg8yoY8NZ50+/KsNy37z4RbGL1vuIqmjUsbcZya8xrh1Pp4p1Yd0usNn ZB4k6MKlYf+GujT6SuH0FS3HrT5hvVEHx4p5RIYFoXJ2WlTMrqfKl7cQYUh9TQRsG0WM 68uWsswux/45ZHC1KdU0Zanah0q5+8Wnl9P4xBokZ+zfFytOtoaAiCJPfU68jRmFfHnV 8Ylw== X-Gm-Message-State: AOJu0YwZWSP8yi03ge8QS2dLXDPcJFDOMjAWNu944Mfd42iwaJsNh0rs KPSr/71Uh5WUQk7YYG2pIh3cSFU4rIVE1KmYHMhEPnsepetZsX5iUn1EC5PmZn+Af/gOmtZObne unV6hGnRueHdbmW1Zbl5TAK1cHFo03RJuD42ZiBIWH4gvdOMzyKoY2tDbX7ZtIw== X-Gm-Gg: AR+sD11cqWJ9UFmZTZXw2HsLfoYhr0F2kb0SsjvMas2aiwuRn5V2YQbRG5a1CsBtBdm RnBNbhNv2cMwy7OaWNm4FdcwLl3kOLd/znJnhHadzv2AUebJ4fawAABgTmHZ2UCy3JMG6jkig7E EYCIFrg2iYu5M7sObGsaeos856UbQO7zopSLJOcCIYJqYZjcjrOKqBSEdn9TjIHYgIkaQbK6Pkl UU+wmn2AxvXF9hADHLzdW3CnnKHYabQp0stqZpmM2NocnsrjtjhUXvSaDkXrfyRH4WgQHW+F5RY rSEr6YrV72nMw/FUXNVum/Y66tSC7kFijhcK9u97RTEMqUWOGgJkohXiJq8m2iN2+6u5YOvecO8 uiHQgJA== X-Received: by 2002:a17:906:6315:b0:c15:d608:f112 with SMTP id a640c23a62f3a-c1f1f16ba60mr326896066b.58.1785146128096; Mon, 27 Jul 2026 02:55:28 -0700 (PDT) X-Received: by 2002:a17:906:6315:b0:c15:d608:f112 with SMTP id a640c23a62f3a-c1f1f16ba60mr326894366b.58.1785146127623; Mon, 27 Jul 2026 02:55:27 -0700 (PDT) Received: from [192.168.188.22] ([80.243.52.136]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69fb5543370sm2357290a12.15.2026.07.27.02.55.26 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 27 Jul 2026 02:55:27 -0700 (PDT) Message-ID: <8a7a4a65-33f8-4442-80cc-8dcc3d616127@redhat.com> Date: Mon, 27 Jul 2026 11:55:25 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [BUG] --map-guest-addr target resolved once at startup; host network change kills the mapping silently and permanently To: David Gibson , Yuxi Liu References: From: Paul Holzinger In-Reply-To: X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: D7Kvv5eqIdoiPnzg0ubxvjnzP84l2ekZFmUmJRd0yUk_1785146128 X-Mimecast-Originator: redhat.com Content-Language: en-US Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Message-ID-Hash: G7YT7PNUK4VOQQKLRQ53CPAJPXX5JGYG X-Message-ID-Hash: G7YT7PNUK4VOQQKLRQ53CPAJPXX5JGYG X-MailFrom: pholzing@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: passt-dev@passt.top X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On 27/07/2026 03:47, David Gibson wrote: > On Sat, Jul 25, 2026 at 09:28:14AM -0700, Yuxi Liu wrote: >> Hello, >> >> Bug report against pasta, as used by rootless podman for >> host.containers.internal. >> >> What happens >> ------------ >> Rootless container, default pasta networking (podman passes >> --no-map-gw --map-guest-addr 169.254.1.2), on a laptop. The laptop >> moves to a different network (hotel wifi, home, office). From that >> moment, every connection from the container to 169.254.1.2 times out. >> Forever. General outbound from the container keeps working, so the >> failure looks like the host service died. The host service is fine and >> answers on the host the whole time. Only recreating the container >> fixes the route. >> >> Why it happens >> -------------- >> --map-guest-addr forwards mapped traffic to the host's external >> address (commit 57b7bd2). pasta resolves that address once, at >> startup, and never again. After the host moves networks, pasta still >> connect()s to the launch-time address. Nobody owns that address >> anymore, the SYNs vanish, and no error is logged anywhere. >> >> pasta already runs a live netlink monitor in its event loop >> (RTMGRP_NEIGH, neighbour events). Host address changes are the one >> thing it reads once at startup and never watches afterward. Re-reading >> the current address needs no privilege: getifaddrs() works for any >> process. > Right. This is a known limitation. We're working on it, but it's > fairly difficult to fix correctly, because it interacts with a bunch > of other features. This is largely tracked by this bug: > https://bugs.passt.top/show_bug.cgi?id=141 And tracked for podman here already as well: https://github.com/podman-container-tools/podman/issues/24970 > >> Reproduce >> --------- >> 1. Laptop on wifi network A. Run a rootless podman container with the >> default pasta network. Have any service listening on the host, >> say port 8191. >> 2. In the container: curl >> https://www.google.com/url?q=http://host.containers.internal:8191&source=gmail&ust=1785083212577000&sa=E >> -> answers. >> 3. Move the laptop to wifi network B. >> 4. Same curl -> timeout. Stays dead until the container is recreated. >> >> Versions: passt 0.0~git20250503.587980c-2 (Ubuntu 25.10), >> podman 5.4.2. >> >> Expected >> -------- >> One of: >> 1. pasta re-resolves the mapping target when the host's addresses >> change, or >> 2. the mapped route fails loudly (RST) instead of silently, or >> 3. the man page warns that the mapping dies permanently on host >> network change. >> >> Laptops are a mainstream platform for rootless podman. A silent, >> permanent route death on every wifi change is a serious defect for >> them. >> >> Workaround >> ---------- >> --map-guest-addr none --map-host-loopback 169.254.1.2 (via podman: >> --network=pasta:--map-guest-addr,none,--map-host-loopback,169.254.1.2). >> Mapped traffic then arrives on the host as 127.0.0.1, which the host >> owns on every network. This changes source semantics (connections >> appear to come from loopback), which is acceptable when you control >> both sides. > Right, for your use case, --map-host-loopback seems like a good > workaround. Even when we implement a netlink monitor, > --map-guest-addr (or its future equivalent) can't really work when the > laptop is not on any external network, because there is no external > host address to direct traffic to. > -- Paul Holzinger