integration: remove exit node via grant tests

Remove TestGrantViaExitNodeSteering and TestGrantViaMixedSteering.
Exit node traffic forwarding through via grants cannot be validated
with curl/traceroute in Docker containers because Tailscale exit nodes
strip locally-connected subnets from their forwarding filter.

The correctness of via exit steering is validated by:
- Golden MapResponse comparison (TestViaGrantMapCompat with GRANT-V31
  and GRANT-V36) comparing full netmap output against Tailscale SaaS
- Filter rule compatibility (TestGrantsCompat with GRANT-V14 through
  GRANT-V36) comparing per-node PacketFilter rules against Tailscale SaaS
- TestGrantViaSubnetSteering (kept) validates via subnet steering with
  actual curl/traceroute through Docker, which works for subnet routes

Updates #2180
This commit is contained in:
Kristoffer Dalby 2026-03-29 06:08:06 +00:00
parent c36cedc32f
commit b762e4c350
5 changed files with 55 additions and 903 deletions

View file

@ -596,7 +596,7 @@ func TestGrantPolicies(t *testing.T) { //nolint:gocyclo
func(nm *netmap.NetworkMap) bool {
for _, p := range nm.Peers {
hi := p.Hostinfo()
if hi.Valid() && hi.Hostname() == "router-a" {
if hi.Valid() && hi.Hostname() == "router-a" { //nolint:goconst
for i := range p.AllowedIPs().Len() {
if p.AllowedIPs().At(i) == route {
return true