The fact that it only fails for conntrack scenario and even before Local IP creation makes me think it might be related to iptables_hybrid firewall driver used for this scenario.
Looking at comments [1] and [2] I remembered that iptables_hybrid lacks isolation between hosts in fullstack tests. Since local_ip test uses 2 hosts we better use noop firewall for conntrack scenario.
The fact that it only fails for conntrack scenario and even before Local IP creation makes me think it might be related to iptables_hybrid firewall driver used for this scenario.
Looking at comments [1] and [2] I remembered that iptables_hybrid lacks isolation between hosts in fullstack tests. Since local_ip test uses 2 hosts we better use noop firewall for conntrack scenario.
[1] https:/ /github. com/openstack/ neutron/ blob/3dfe607242 1e3d5dc708a3bf0 65fb1a64ea3129a /neutron/ tests/fullstack /test_securityg roup.py# L96
[2] https:/ /github. com/openstack/ neutron/ blob/3dfe607242 1e3d5dc708a3bf0 65fb1a64ea3129a /neutron/ tests/fullstack /test_securityg roup.py# L536