By default we copy host routes to the container with pasta and --config-net. However, this can fail if those routes contain RTA_SRC attributes and we use -a to give the container an address different from that on the host. Setting a route with RTA_SRC musc give an address which is set on an interface in the namespace, so if we copy an RTA_SRC from the host with a host address to a namespace with a different address, we get an -EINVAL on the NEWROUTE, causing --config-net to fail entirely. This is the root cause of at least one of the failures noted in https://github.com/containers/podman/pull/19699#issuecomment-1688769287
Oops, it's actually RTA_PREFSRC, not RTA_SRC that's the issue.