Project Number Date
test_Tails_ISO_devel 4572 27 Aug 2026, 11:10

Feature Report

Steps Scenarios Features
Feature Passed Failed Skipped Pending Undefined Total Passed Failed Total Duration Status
The Tor enforcement is effective 37 1 1 0 0 39 7 1 8 2:11.538 Failed
Tags: @product
Feature The Tor enforcement is effective
As a Tails user I want all direct Internet connections I do by mistake or applications do by misconfiguration or buggy leaks to be blocked And as a Tails developer I want to ensure that the automated test suite detects firewall leaks reliably
Tags: @product
22.334
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Given I have started Tails from DVD and logged in and the network is connected 22.097
Then the firewall's policy is to drop all IPv4 traffic 0.044
And the firewall is configured to only allow the clearnet and debian-tor users to connect directly to the Internet over IPv4 0.108
And the firewall's NAT rules only redirect traffic for the Unsafe Browser, Tor's TransPort, and DNSPort 0.041
And the firewall is configured to block all external IPv6 traffic 0.042
After features/support/hooks.rb:339 0.776
After features/support/hooks.rb:108 0.000
Tags: @product @doc
23.745
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.002
Given I have started Tails from DVD and logged in and the network is connected 9.414
And I capture all network traffic 0.004
When I successfully start the Unsafe Browser 6.842
And I open the Tails homepage in the Unsafe Browser 7.026
And the Tails homepage loads in the Unsafe Browser 0.303
Then the firewall leak detector has detected leaks 0.154
After features/support/hooks.rb:339 0.943
After features/support/hooks.rb:108 0.060
Tags: @product
9.749
Scenario Anti test: Detecting TCP leaks of DNS lookups with the firewall leak detector
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Steps
Given I have started Tails from DVD and logged in and the network is connected 9.433
And I capture all network traffic 0.005
And I disable Tails' firewall 0.163
When I do a TCP DNS lookup of "torproject.org" 0.147
Failed to resolve torproject.org:
;; communications error to 9.9.9.9#53: connection reset
;; communications error to 9.9.9.9#53: connection reset
;; no servers could be reached
.
<false> is not true. (Test::Unit::AssertionFailedError)
./features/step_definitions/firewall_leaks.rb:22:in `/^I do a TCP DNS lookup of "(.*?)"$/'
features/tor_enforcement.feature:28:in `When I do a TCP DNS lookup of "torproject.org"'
Then the firewall leak detector has detected leaks 0.000
After features/support/hooks.rb:339 4.982

SCENARIO FAILED: 'Anti test: Detecting TCP leaks of DNS lookups with the firewall leak detector' (at time 03:14:12)

Boot log: https://jenkins.tails.boum.org/job/test_Tails_ISO_devel/4572/artifact/build-artifacts/03:14:12_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.file_content_var_log_boot.log

Screenshot: https://jenkins.tails.boum.org/job/test_Tails_ISO_devel/4572/artifact/build-artifacts/03:14:12_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.png

Video: https://jenkins.tails.boum.org/job/test_Tails_ISO_devel/4572/artifact/build-artifacts/03:14:12_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.mkv

Systemd journal: https://jenkins.tails.boum.org/job/test_Tails_ISO_devel/4572/artifact/build-artifacts/03:14:12_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.journal

After features/support/hooks.rb:108 0.043
Tags: @product
9.651
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.002
Given I have started Tails from DVD and logged in and the network is connected 9.241
And I capture all network traffic 0.003
And I disable Tails' firewall 0.127
When I do a UDP DNS lookup of "torproject.org" 0.177
Then the firewall leak detector has detected leaks 0.102
After features/support/hooks.rb:339 0.482
After features/support/hooks.rb:108 0.036
Tags: @product
25.360
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.002
Given I have started Tails from DVD and logged in and the network is connected 21.045
And I capture all network traffic 0.003
And I disable Tails' firewall 0.100
When I send some ICMP pings 4.082
Then the firewall leak detector has detected leaks 0.127
After features/support/hooks.rb:339 0.770
After features/support/hooks.rb:108 0.063
10.139
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Before features/support/hooks.rb:527 0.001
Given I have started Tails from DVD and logged in and the network is connected 9.730
When I open an untorified UDP connection to 1.2.3.4 on port 42 0.325
Then the untorified connection fails 0.000
And the untorified connection is logged as dropped by the firewall 0.083
After features/support/hooks.rb:535 0.255
After features/support/hooks.rb:339 0.877
After features/support/hooks.rb:108 0.000
14.774
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Before features/support/hooks.rb:527 0.007
Given I have started Tails from DVD and logged in and the network is connected 9.331
When I open an untorified ICMP connection to 1.2.3.4 5.315
Then the untorified connection fails 0.000
And the untorified connection is logged as dropped by the firewall 0.128
After features/support/hooks.rb:535 0.272
After features/support/hooks.rb:339 0.596
After features/support/hooks.rb:108 0.000
Tags: @product
15.782
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Given I have started Tails from DVD without network and logged in 6.454
And the system DNS is using the local DNS resolver 0.006
And the network is plugged 0.043
And I successfully configure Tor 9.273
Then the system DNS is still using the local DNS resolver 0.004
After features/support/hooks.rb:339 0.884
After features/support/hooks.rb:108 0.000