Project Number Date
test_Tails_ISO_stable 6570 10 Aug 2026, 12:47

Feature Report

Steps Scenarios Features
Feature Passed Failed Skipped Pending Undefined Total Passed Failed Total Duration Status
The Tor enforcement is effective 37 1 1 0 0 39 7 1 8 2:0.621 Failed
Tags: @product
Feature The Tor enforcement is effective
As a Tails user I want all direct Internet connections I do by mistake or applications do by misconfiguration or buggy leaks to be blocked And as a Tails developer I want to ensure that the automated test suite detects firewall leaks reliably
Tags: @product
10.411
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Given I have started Tails from DVD and logged in and the network is connected 10.055
Then the firewall's policy is to drop all IPv4 traffic 0.117
And the firewall is configured to only allow the clearnet and debian-tor users to connect directly to the Internet over IPv4 0.134
And the firewall's NAT rules only redirect traffic for the Unsafe Browser, Tor's TransPort, and DNSPort 0.047
And the firewall is configured to block all external IPv6 traffic 0.056
After features/support/hooks.rb:339 0.755
After features/support/hooks.rb:108 0.000
Tags: @product @doc
23.893
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.002
Given I have started Tails from DVD and logged in and the network is connected 9.583
And I capture all network traffic 0.005
When I successfully start the Unsafe Browser 6.867
And I open the Tails homepage in the Unsafe Browser 7.041
And the Tails homepage loads in the Unsafe Browser 0.267
Then the firewall leak detector has detected leaks 0.128
After features/support/hooks.rb:339 0.807
After features/support/hooks.rb:108 0.044
Tags: @product
9.838
Scenario Anti test: Detecting TCP leaks of DNS lookups with the firewall leak detector
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.004
Steps
Given I have started Tails from DVD and logged in and the network is connected 9.590
And I capture all network traffic 0.003
And I disable Tails' firewall 0.107
When I do a TCP DNS lookup of "torproject.org" 0.136
Failed to resolve torproject.org:
;; communications error to 9.9.9.9#53: connection reset
;; communications error to 9.9.9.9#53: connection reset
;; no servers could be reached
.
<false> is not true. (Test::Unit::AssertionFailedError)
./features/step_definitions/firewall_leaks.rb:22:in `/^I do a TCP DNS lookup of "(.*?)"$/'
features/tor_enforcement.feature:28:in `When I do a TCP DNS lookup of "torproject.org"'
Then the firewall leak detector has detected leaks 0.000
After features/support/hooks.rb:339 4.957

SCENARIO FAILED: 'Anti test: Detecting TCP leaks of DNS lookups with the firewall leak detector' (at time 03:22:56)

Boot log: https://jenkins.tails.boum.org/job/test_Tails_ISO_stable/6570/artifact/build-artifacts/03:22:56_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.file_content_var_log_boot.log

Screenshot: https://jenkins.tails.boum.org/job/test_Tails_ISO_stable/6570/artifact/build-artifacts/03:22:56_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.png

Video: https://jenkins.tails.boum.org/job/test_Tails_ISO_stable/6570/artifact/build-artifacts/03:22:56_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.mkv

Systemd journal: https://jenkins.tails.boum.org/job/test_Tails_ISO_stable/6570/artifact/build-artifacts/03:22:56_Anti_test:_Detecting_TCP_leaks_of_DNS_lookups_with_the_firewall_leak_detector.journal

After features/support/hooks.rb:108 0.062
Tags: @product
10.022
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Given I have started Tails from DVD and logged in and the network is connected 9.590
And I capture all network traffic 0.004
And I disable Tails' firewall 0.123
When I do a UDP DNS lookup of "torproject.org" 0.192
Then the firewall leak detector has detected leaks 0.111
After features/support/hooks.rb:339 0.634
After features/support/hooks.rb:108 0.030
Tags: @product
13.712
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Given I have started Tails from DVD and logged in and the network is connected 9.345
And I capture all network traffic 0.003
And I disable Tails' firewall 0.120
When I send some ICMP pings 4.052
Then the firewall leak detector has detected leaks 0.191
After features/support/hooks.rb:339 0.938
After features/support/hooks.rb:108 0.066
9.519
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.002
Before features/support/hooks.rb:527 0.002
Given I have started Tails from DVD and logged in and the network is connected 9.236
When I open an untorified UDP connection to 1.2.3.4 on port 42 0.205
Then the untorified connection fails 0.000
And the untorified connection is logged as dropped by the firewall 0.077
After features/support/hooks.rb:535 0.290
After features/support/hooks.rb:339 0.892
After features/support/hooks.rb:108 0.000
26.840
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Before features/support/hooks.rb:527 0.003
Given I have started Tails from DVD and logged in and the network is connected 21.457
When I open an untorified ICMP connection to 1.2.3.4 5.296
Then the untorified connection fails 0.000
And the untorified connection is logged as dropped by the firewall 0.086
After features/support/hooks.rb:535 0.281
After features/support/hooks.rb:339 0.611
After features/support/hooks.rb:108 0.000
Tags: @product
16.382
Before features/support/hooks.rb:274 0.000
Before features/support/hooks.rb:281 0.003
Given I have started Tails from DVD without network and logged in 6.550
And the system DNS is using the local DNS resolver 0.007
And the network is plugged 0.037
And I successfully configure Tor 9.778
Then the system DNS is still using the local DNS resolver 0.007
After features/support/hooks.rb:339 0.810
After features/support/hooks.rb:108 0.000