mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-22 07:48:26 +00:00
The isolation loop and the failure-log dump both built container names without the run suffix, so under a suffixed run they addressed containers that do not exist. The consequence was worse than the visible failure. Two of the three checks in that loop assert a ping FAILS, and a ping into a non-existent container fails for the wrong reason - so both passed vacuously, and the security assertion the loop exists for was silently a no-op. Only the third check, which expects a ping to succeed, noticed anything was wrong. Add a guard that fails loudly when the container is absent, so a future naming slip cannot quietly turn these back into no-ops rather than surfacing as one confusing failure among two false passes. These sites were missed because the suite passes when run by hand: with no suffix set the unsuffixed names are correct, and the defect only appears under the automation that sets one. Verified this time with the suffix set, which is the condition that matters: 18 of 18, container names resolving to real containers.