feat: report what listens, and which OPNsense service it is #10

Merged
christianmanivong merged 1 commits from feat/listening-sockets into master 2026-10-07 05:24:06 +00:00
Owner

get_listening_sockets from /api/diagnostics/interface/get_socket_statistics: netstat's sockets with sockstat's user, command and PID, collected by configd as root. No SSH needed.

  • A listening socket has no peer (*:*). * is the any-address of the socket's family.
  • unit is a name of the firewall's own service list (/api/core/service/search), so netOrk matches a socket to its service. The command, cut to ten characters by FreeBSD, matches a service name, the start of one, or an alias (sshd → openssh, FRR's daemons → frr, kea-ctrl-agent → kea-dhcp). lighttpd is webgui, or captiveportal when it runs as www.
  • WireGuard's sockets belong to the kernel. They are matched by the listen ports from /api/wireguard/service/show.

Checked live against an OPNsense 26.7.5 firewall: 119 sockets, all with a service except the IPv6 loopback ones (sockstat names no process for those). The fixture is that answer, cut down, with documentation addresses. For NetOrk/netork#673.

`get_listening_sockets` from `/api/diagnostics/interface/get_socket_statistics`: netstat's sockets with sockstat's user, command and PID, collected by configd as root. No SSH needed. - A listening socket has no peer (`*:*`). `*` is the any-address of the socket's family. - `unit` is a name of the firewall's own service list (`/api/core/service/search`), so netOrk matches a socket to its service. The command, cut to ten characters by FreeBSD, matches a service name, the start of one, or an alias (`sshd` → `openssh`, FRR's daemons → `frr`, `kea-ctrl-agent` → `kea-dhcp`). lighttpd is `webgui`, or `captiveportal` when it runs as `www`. - WireGuard's sockets belong to the kernel. They are matched by the listen ports from `/api/wireguard/service/show`. **Checked live** against an OPNsense 26.7.5 firewall: 119 sockets, all with a service except the IPv6 loopback ones (sockstat names no process for those). The fixture is that answer, cut down, with documentation addresses. For NetOrk/netork#673.
christianmanivong added 1 commit 2026-10-07 05:20:50 +00:00
feat: report what listens, and which OPNsense service it is
CI / test (3.10) (push) Successful in 40s
CI / test (3.11) (push) Successful in 30s
CI / test (3.12) (push) Successful in 31s
CI / test (3.10) (pull_request) Successful in 29s
CI / test (3.11) (pull_request) Successful in 28s
CI / test (3.12) (pull_request) Successful in 30s
2fb1226734
get_listening_sockets reads /api/diagnostics/interface/get_socket_statistics:
netstat's sockets with sockstat's user, command and PID, collected by
configd as root, so no SSH is needed. A listening socket is one without a
peer (*:*); "*" is the any-address of the socket's family.

Which service: the socket's unit is a name of the firewall's own service
list, so netOrk can match it to the service. The command (cut to ten
characters by FreeBSD) matches a service name, the start of one, or one
of the daemons whose service is called otherwise (sshd is openssh, the
FRR daemons are frr, kea-ctrl-agent is kea-dhcp). lighttpd is the web UI,
or the captive portal when it runs as www. WireGuard's sockets belong to
the kernel and are told by the listen ports of /api/wireguard/service/show.

The fixture is a real OPNsense 26.7.5 firewall's answer, cut down, with
documentation addresses. For netOrk#673.
christianmanivong merged commit fa88850535 into master 2026-10-07 05:24:06 +00:00
christianmanivong deleted branch feat/listening-sockets 2026-10-07 05:24:06 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: NAPALM/napalm-opnsense#10