Project Number Date
test_Tails_ISO_devel 4537 10 Aug 2026, 11:17

Feature Report

Steps Scenarios Features
Feature Passed Failed Skipped Pending Undefined Total Passed Failed Total Duration Status
The Tor enforcement is effective 37 1 1 0 0 39 7 1 8 2:3.427 Failed
Tags: @product
Feature The Tor enforcement is effective
As a Tails user I want all direct Internet connections I do by mistake or applications do by misconfiguration or buggy leaks to be blocked And as a Tails developer I want to ensure that the automated test suite detects firewall leaks reliably
Tags: @product
10.565
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Given I have started Tails from DVD and logged in and the network is connected 10.298
Then the firewall's policy is to drop all IPv4 traffic 0.063
And the firewall is configured to only allow the clearnet and debian-tor users to connect directly to the Internet over IPv4 0.123
And the firewall's NAT rules only redirect traffic for the Unsafe Browser, Tor's TransPort, and DNSPort 0.045
And the firewall is configured to block all external IPv6 traffic 0.034
After features/support/hooks.rb:339 0.661
After features/support/hooks.rb:108 0.000
Tags: @product @doc
37.061
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.002
Given I have started Tails from DVD and logged in and the network is connected 21.523
And I capture all network traffic 0.002
When I successfully start the Unsafe Browser 7.740
And I open the Tails homepage in the Unsafe Browser 7.388
And the Tails homepage loads in the Unsafe Browser 0.269
Then the firewall leak detector has detected leaks 0.137
After features/support/hooks.rb:339 0.641
After features/support/hooks.rb:108 0.059
Tags: @product
10.305
Scenario Anti test: Detecting TCP leaks of DNS lookups with the firewall leak detector
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Steps
Given I have started Tails from DVD and logged in and the network is connected 9.996
And I capture all network traffic 0.004
And I disable Tails' firewall 0.139
When I do a TCP DNS lookup of "torproject.org" 0.164
Failed to resolve torproject.org:
;; communications error to 9.9.9.9#53: connection reset
;; communications error to 9.9.9.9#53: connection reset
;; no servers could be reached
.
<false> is not true. (Test::Unit::AssertionFailedError)
./features/step_definitions/firewall_leaks.rb:22:in `/^I do a TCP DNS lookup of "(.*?)"$/'
features/tor_enforcement.feature:28:in `When I do a TCP DNS lookup of "torproject.org"'
Then the firewall leak detector has detected leaks 0.000
After features/support/hooks.rb:339 4.984

SCENARIO FAILED: 'Anti test: Detecting TCP leaks of DNS lookups with the firewall leak detector' (at time 03:21:45)

Boot log: https://jenkins.tails.boum.org/job/test_Tails_ISO_devel/4537/artifact/build-artifacts/03:21:45_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.file_content_var_log_boot.log

Screenshot: https://jenkins.tails.boum.org/job/test_Tails_ISO_devel/4537/artifact/build-artifacts/03:21:45_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.png

Video: https://jenkins.tails.boum.org/job/test_Tails_ISO_devel/4537/artifact/build-artifacts/03:21:45_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.mkv

Systemd journal: https://jenkins.tails.boum.org/job/test_Tails_ISO_devel/4537/artifact/build-artifacts/03:21:45_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.journal

After features/support/hooks.rb:108 0.038
Tags: @product
10.711
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.004
Given I have started Tails from DVD and logged in and the network is connected 10.042
And I capture all network traffic 0.006
And I disable Tails' firewall 0.144
When I do a UDP DNS lookup of "torproject.org" 0.339
Then the firewall leak detector has detected leaks 0.177
After features/support/hooks.rb:339 1.001
After features/support/hooks.rb:108 0.039
Tags: @product
14.248
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.002
Given I have started Tails from DVD and logged in and the network is connected 9.877
And I capture all network traffic 0.004
And I disable Tails' firewall 0.179
When I send some ICMP pings 4.058
Then the firewall leak detector has detected leaks 0.127
After features/support/hooks.rb:339 0.916
After features/support/hooks.rb:108 0.047
10.312
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.004
Before features/support/hooks.rb:527 0.004
Given I have started Tails from DVD and logged in and the network is connected 9.850
When I open an untorified UDP connection to 1.2.3.4 on port 42 0.375
Then the untorified connection fails 0.000
And the untorified connection is logged as dropped by the firewall 0.087
After features/support/hooks.rb:535 0.332
After features/support/hooks.rb:339 0.460
After features/support/hooks.rb:108 0.000
15.132
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.004
Before features/support/hooks.rb:527 0.002
Given I have started Tails from DVD and logged in and the network is connected 9.658
When I open an untorified ICMP connection to 1.2.3.4 5.397
Then the untorified connection fails 0.000
And the untorified connection is logged as dropped by the firewall 0.076
After features/support/hooks.rb:535 0.278
After features/support/hooks.rb:339 0.871
After features/support/hooks.rb:108 0.000
Tags: @product
15.090
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Given I have started Tails from DVD without network and logged in 6.570
And the system DNS is using the local DNS resolver 0.008
And the network is plugged 0.030
And I successfully configure Tor 8.474
Then the system DNS is still using the local DNS resolver 0.006
After features/support/hooks.rb:339 1.045
After features/support/hooks.rb:108 0.000