import assert from 'node:assert/strict'; import fs from 'node:fs'; import path from 'node:path'; import test from 'node:test'; const entrypoint = fs.readFileSync( path.resolve(import.meta.dirname, '../../entrypoint.sh'), 'utf8', ); test('gateway keeps direct forwarding active while TProxy interception is switchable', () => { assert.match(entrypoint, /-p tcp -j TPROXY --on-port "\$TPROXY_PORT"/); assert.match(entrypoint, /-p udp -j TPROXY --on-port "\$TPROXY_PORT"/); assert.match(entrypoint, /-I FORWARD 1 -j "\$GATEWAY_FORWARD_CHAIN"/); assert.match(entrypoint, /-I POSTROUTING 1 -j "\$GATEWAY_NAT_CHAIN"/); assert.match(entrypoint, /-A "\$TPROXY_CHAIN" -i 'br-\+' -j RETURN/); assert.doesNotMatch(entrypoint, /-A PREROUTING -j "\$TPROXY_CHAIN"/); assert.doesNotMatch(entrypoint, /TPROXY_BYPASS_SOURCE_CIDRS|DIRECT_BYPASS_CACHE|ipset/); }); test('control bypasses host routing while dataplane owns it', () => { assert.match(entrypoint, /APP_COMPONENT.*control/); assert.match(entrypoint, /exec node \/app\/src\/server\/index\.js/); assert.match(entrypoint, /APP_COMPONENT.*dataplane/); assert.match(entrypoint, /node \/app\/src\/server\/dataplane\.js/); });