feat: read what listens on which address, and which service it is, once for every driver
Whether a service is reachable from outside its host is decided by the address it listens on: 0.0.0.0:5432 is, 127.0.0.1:5432 is not. Reading that is the same on every Linux host, so the command and its parse live here once and a driver only carries the command across (ListeningSocketsMixin, _run_listening_sockets_command). One framed round trip: ss -lntup for every listening TCP and bound UDP socket, then /proc/<pid>/cgroup for each process holding one, which names the systemd service (v2, nested slices, v1's name=systemd hierarchy) or the container (docker-<id>.scope, /docker/<id>) it runs in. - Root: only root sees every process. The script goes as one sh -c argument, so a sudo -n prefix covers all of it; when that brings no report back the reading runs again unprivileged and says it is not attributed. - No -H: iproute2 before 4.10 fails on it, which would read as nothing listening. The header is skipped instead. - A host without ss raises ListeningSocketsUnavailable; a report cut short or a failing ss raises ValueError. - The reading is raw: docker-proxy shows up as docker.service, loopback as loopback. What counts as reachable is the consumer's call. 2.4.0. For netOrk#658.
This commit is contained in:
@@ -86,6 +86,14 @@ dnf-automatic). `package_updates` holds the shared apt and dnf parsers: apt's su
|
||||
an update's `origin`, a `-security` suite makes it a security update, and dnf's security
|
||||
advisories do the same.
|
||||
|
||||
`ListeningSocketsMixin` (`get_listening_sockets`) is mixed in the same way: every listening
|
||||
TCP and bound UDP socket from `ss -lntup`, with the systemd service or container behind it
|
||||
from `/proc/<pid>/cgroup`, in one round trip. A driver supplies
|
||||
`_run_listening_sockets_command(command, privileged=)`; the command arrives as one `sh -c`
|
||||
argument, so a `sudo -n` prefix covers all of it. Without root `ss` names only the login
|
||||
user's processes, and the reading says so (`attributed: false`) instead of failing. A host
|
||||
without `ss` raises `ListeningSocketsUnavailable`.
|
||||
|
||||
**Update readers raise when they cannot read.** `get_available_updates` returns an empty
|
||||
list only when nothing is pending; netOrk keeps "pending since" per package, and an empty
|
||||
list for "don't know" would reset it.
|
||||
|
||||
Reference in New Issue
Block a user