test_vrf_conntrack_route_leak asserted that no conntrack entry carrying the VRF zone is [UNREPLIED]. The zone is assigned by oifname as well, so it also covers traffic the box originates itself - an IGMPv3 membership report to 224.0.0.22, say, which is [UNREPLIED] by nature and lives for the 600s generic protocol timeout:
unknown 2 584 src=192.0.2.1 dst=224.0.0.22 zone-orig=6099 [UNREPLIED] ...
Whether such an entry exists when the assertion runs depends on when some process joins a multicast group on the VRF interface, so the test fails at random.