Compare commits
6 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| b886fb2045 | |||
| cfb02e1763 | |||
| 5b53ca3d52 | |||
| 92a30913b4 | |||
| a288a8ef9a | |||
| c65d596099 |
6
Cargo.lock
generated
6
Cargo.lock
generated
@@ -279,7 +279,7 @@ checksum = "a1d728cc89cf3aee9ff92b05e62b19ee65a02b5702cff7d5a377e32c6ae29d8d"
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "cm-dashboard"
|
name = "cm-dashboard"
|
||||||
version = "0.1.247"
|
version = "0.1.252"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"chrono",
|
"chrono",
|
||||||
@@ -301,7 +301,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "cm-dashboard-agent"
|
name = "cm-dashboard-agent"
|
||||||
version = "0.1.247"
|
version = "0.1.252"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"async-trait",
|
"async-trait",
|
||||||
@@ -325,7 +325,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "cm-dashboard-shared"
|
name = "cm-dashboard-shared"
|
||||||
version = "0.1.247"
|
version = "0.1.252"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"chrono",
|
"chrono",
|
||||||
"serde",
|
"serde",
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "cm-dashboard-agent"
|
name = "cm-dashboard-agent"
|
||||||
version = "0.1.247"
|
version = "0.1.253"
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ use cm_dashboard_shared::{AgentData, ServiceData, SubServiceData, SubServiceMetr
|
|||||||
use std::process::Command;
|
use std::process::Command;
|
||||||
use std::sync::RwLock;
|
use std::sync::RwLock;
|
||||||
use std::time::Instant;
|
use std::time::Instant;
|
||||||
use tracing::debug;
|
use tracing::{debug, info};
|
||||||
|
|
||||||
use super::{Collector, CollectorError};
|
use super::{Collector, CollectorError};
|
||||||
use crate::config::SystemdConfig;
|
use crate::config::SystemdConfig;
|
||||||
@@ -154,7 +154,8 @@ impl SystemdCollector {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if service_name == "openvpn-vpn-connection" && status_info.active_state == "active" {
|
if service_name == "openvpn-vpn-download" && status_info.active_state == "active" {
|
||||||
|
// Add VPN route
|
||||||
if let Some(external_ip) = self.get_vpn_external_ip() {
|
if let Some(external_ip) = self.get_vpn_external_ip() {
|
||||||
let metrics = Vec::new();
|
let metrics = Vec::new();
|
||||||
|
|
||||||
@@ -165,9 +166,8 @@ impl SystemdCollector {
|
|||||||
service_type: "vpn_route".to_string(),
|
service_type: "vpn_route".to_string(),
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
if service_name == "openvpn-vpn-download" && status_info.active_state == "active" {
|
// Add torrent stats
|
||||||
if let Some((active_count, download_mbps, upload_mbps)) = self.get_qbittorrent_stats() {
|
if let Some((active_count, download_mbps, upload_mbps)) = self.get_qbittorrent_stats() {
|
||||||
let metrics = Vec::new();
|
let metrics = Vec::new();
|
||||||
|
|
||||||
@@ -915,17 +915,28 @@ impl SystemdCollector {
|
|||||||
/// Returns: (tcp_ports_string, udp_ports_string)
|
/// Returns: (tcp_ports_string, udp_ports_string)
|
||||||
fn get_nftables_open_ports(&self) -> (String, String) {
|
fn get_nftables_open_ports(&self) -> (String, String) {
|
||||||
let output = Command::new("timeout")
|
let output = Command::new("timeout")
|
||||||
.args(&["3", "nft", "list", "ruleset"])
|
.args(&["3", "sudo", "nft", "list", "ruleset"])
|
||||||
.output();
|
.output();
|
||||||
|
|
||||||
let output = match output {
|
let output = match output {
|
||||||
Ok(out) if out.status.success() => out,
|
Ok(out) if out.status.success() => out,
|
||||||
_ => return (String::new(), String::new()),
|
Ok(out) => {
|
||||||
|
info!("nft command failed with status: {:?}, stderr: {}",
|
||||||
|
out.status, String::from_utf8_lossy(&out.stderr));
|
||||||
|
return (String::new(), String::new());
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
info!("Failed to execute nft command: {}", e);
|
||||||
|
return (String::new(), String::new());
|
||||||
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
let output_str = match String::from_utf8(output.stdout) {
|
let output_str = match String::from_utf8(output.stdout) {
|
||||||
Ok(s) => s,
|
Ok(s) => s,
|
||||||
Err(_) => return (String::new(), String::new()),
|
Err(_) => {
|
||||||
|
info!("Failed to parse nft output as UTF-8");
|
||||||
|
return (String::new(), String::new());
|
||||||
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
let mut tcp_ports = std::collections::HashSet::new();
|
let mut tcp_ports = std::collections::HashSet::new();
|
||||||
@@ -933,26 +944,26 @@ impl SystemdCollector {
|
|||||||
|
|
||||||
// Parse nftables output for WAN incoming accept rules with dport
|
// Parse nftables output for WAN incoming accept rules with dport
|
||||||
// Looking for patterns like: tcp dport 22 accept or tcp dport { 22, 80, 443 } accept
|
// Looking for patterns like: tcp dport 22 accept or tcp dport { 22, 80, 443 } accept
|
||||||
// Only include rules in input chain without private network source restrictions
|
// Only include rules in input_wan chain
|
||||||
let mut in_input_chain = false;
|
let mut in_wan_chain = false;
|
||||||
|
|
||||||
for line in output_str.lines() {
|
for line in output_str.lines() {
|
||||||
let line = line.trim();
|
let line = line.trim();
|
||||||
|
|
||||||
// Track if we're in the input chain
|
// Track if we're in the input_wan chain
|
||||||
if line.contains("chain input") || line.contains("chain INPUT") {
|
if line.contains("chain input_wan") {
|
||||||
in_input_chain = true;
|
in_wan_chain = true;
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Reset when entering other chains
|
// Reset when exiting chain (closing brace) or entering other chains
|
||||||
if line.starts_with("chain ") && !line.contains("input") && !line.contains("INPUT") {
|
if line == "}" || (line.starts_with("chain ") && !line.contains("input_wan")) {
|
||||||
in_input_chain = false;
|
in_wan_chain = false;
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Only process rules in input chain
|
// Only process rules in input_wan chain
|
||||||
if !in_input_chain {
|
if !in_wan_chain {
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -961,14 +972,6 @@ impl SystemdCollector {
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Skip internal network traffic (LAN/private networks)
|
|
||||||
if line.contains("ip saddr 192.168.") ||
|
|
||||||
line.contains("ip saddr 10.") ||
|
|
||||||
line.contains("ip saddr 172.16.") ||
|
|
||||||
line.contains("iifname \"lo\"") {
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
|
|
||||||
// Parse TCP ports
|
// Parse TCP ports
|
||||||
if line.contains("tcp dport") {
|
if line.contains("tcp dport") {
|
||||||
for port in self.extract_ports_from_nft_rule(line) {
|
for port in self.extract_ports_from_nft_rule(line) {
|
||||||
@@ -993,6 +996,8 @@ impl SystemdCollector {
|
|||||||
let tcp_str = tcp_vec.iter().map(|p| p.to_string()).collect::<Vec<_>>().join(", ");
|
let tcp_str = tcp_vec.iter().map(|p| p.to_string()).collect::<Vec<_>>().join(", ");
|
||||||
let udp_str = udp_vec.iter().map(|p| p.to_string()).collect::<Vec<_>>().join(", ");
|
let udp_str = udp_vec.iter().map(|p| p.to_string()).collect::<Vec<_>>().join(", ");
|
||||||
|
|
||||||
|
info!("nftables WAN ports - TCP: '{}', UDP: '{}'", tcp_str, udp_str);
|
||||||
|
|
||||||
(tcp_str, udp_str)
|
(tcp_str, udp_str)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "cm-dashboard"
|
name = "cm-dashboard"
|
||||||
version = "0.1.247"
|
version = "0.1.253"
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "cm-dashboard-shared"
|
name = "cm-dashboard-shared"
|
||||||
version = "0.1.247"
|
version = "0.1.253"
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
|
|||||||
Reference in New Issue
Block a user