From e366f9452cdf77dc80a63de8e90b294439dc313c Mon Sep 17 00:00:00 2001 From: JackDoan Date: Tue, 8 Sep 2026 09:40:55 -0500 Subject: [PATCH] smoke: Prove windows honors NlMtu with a 9000 byte ping Follow-up to #1871. The Get-NetIPInterface check proves the value was written, not that windows fragments to it. A 9000 byte payload only crosses the tunnel as fragments cut at NlMtu on the way out of the adapter. Left at the adapter default it reaches nebula whole, overflows the udp.MTU (9001) write buffer and is dropped, so the ping never answers. Anything smaller would ride out as one oversized datagram and survive on IP fragmentation of the underlay, which is why a payload that is merely larger than tun.mtu would not catch a regression. Both families are pinged from the windows side so the v4 NlMtu, which was always right, gets the same guard. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01J34ExJUUPKWUvr2g5GMREi --- .github/workflows/smoke/smoke-windows.ps1 | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/.github/workflows/smoke/smoke-windows.ps1 b/.github/workflows/smoke/smoke-windows.ps1 index e94768a9..c8f55b51 100644 --- a/.github/workflows/smoke/smoke-windows.ps1 +++ b/.github/workflows/smoke/smoke-windows.ps1 @@ -263,6 +263,20 @@ try { } Write-Host "OK: WSL peer -> windows lighthouse over v6" + # The NlMtu check above proves the value was written, not that windows honors it. A payload this size only + # crosses the tunnel as fragments cut at NlMtu on the way out of the adapter. Left at the adapter default it + # reaches nebula whole, overflows the udp.MTU (9001) write buffer and is dropped, so the ping never answers. + # Anything smaller would ride out as one oversized datagram and survive on IP fragmentation of the underlay. + $BigPayload = 9000 + foreach ($target in @(@{ Family = 'v4'; Ip = $Ip2 }, @{ Family = 'v6'; Ip = $Ip6_2 })) { + Wait-Until -TimeoutSec 30 -What "$($target.Family) ping with a $BigPayload byte payload from windows lighthouse to WSL peer ($($target.Ip))" -Predicate { + if ($peerProc.HasExited) { throw "peer exited (code $($peerProc.ExitCode)) before the large $($target.Family) ping succeeded" } + $null = & ping.exe -n 1 -w 1000 -l $BigPayload $target.Ip + $LASTEXITCODE -eq 0 + } + Write-Host "OK: windows lighthouse -> WSL peer, $BigPayload byte $($target.Family) payload" + } + Write-Host '' Write-Host 'All smoke checks passed.' }