CI / test (3.10) (push) Successful in 40s
CI / test (3.11) (push) Successful in 30s
CI / test (3.12) (push) Successful in 31s
CI / test (3.10) (pull_request) Successful in 29s
CI / test (3.11) (pull_request) Successful in 28s
CI / test (3.12) (pull_request) Successful in 30s
get_listening_sockets reads /api/diagnostics/interface/get_socket_statistics: netstat's sockets with sockstat's user, command and PID, collected by configd as root, so no SSH is needed. A listening socket is one without a peer (*:*); "*" is the any-address of the socket's family. Which service: the socket's unit is a name of the firewall's own service list, so netOrk can match it to the service. The command (cut to ten characters by FreeBSD) matches a service name, the start of one, or one of the daemons whose service is called otherwise (sshd is openssh, the FRR daemons are frr, kea-ctrl-agent is kea-dhcp). lighttpd is the web UI, or the captive portal when it runs as www. WireGuard's sockets belong to the kernel and are told by the listen ports of /api/wireguard/service/show. The fixture is a real OPNsense 26.7.5 firewall's answer, cut down, with documentation addresses. For netOrk#673.