feat: complete nx9-wg v0.8.0 platform

This commit is contained in:
thakares committed 2026-08-17 14:25:45 +05:30
1 parent c75e5c4e71
commit c8a9b7cde6
52 files changed
+7751 -725

No files matched your search

+84 -1
View File
@@ -28,6 +28,11 @@ pub trait NetworkEngine: Send + Sync {
/// Get current active generated nftables ruleset.
async fn get_active_nftables_ruleset(&self) -> Result<String>;
/// Check if desired routes have drift against live/active state.
async fn has_route_drift(&self, _routes: &[Route]) -> Result<bool> {
Ok(false)
}
}
/// In-memory simulated network engine for tests and non-root execution.
@@ -88,14 +93,91 @@ impl NetworkEngine for SimulatedNetworkEngine {
let active = self.active_ruleset.read().await;
Ok(active.clone())
}
async fn has_route_drift(&self, routes: &[Route]) -> Result<bool> {
let enabled_routes: Vec<Route> = routes.iter().filter(|r| r.enabled).cloned().collect();
let active = self.active_routes.read().await;
Ok(enabled_routes != *active)
}
}
/// Linux Native Network Engine with kernel sysfs / netlink checks and fallback.
/// Linux Native Network Engine with RTNETLINK and direct procfs forwarding.
#[cfg(target_os = "linux")]
pub use crate::native_linux::{
FirewallDiagnostics, NativeLinuxNetworkEngine, NativeLinuxNftablesEngine,
};
/// Fallback Simulated Network Engine for non-Linux platforms and unit testing.
#[cfg(not(target_os = "linux"))]
#[derive(Debug, Clone, Default)]
pub struct NativeLinuxNetworkEngine {
fallback: SimulatedNetworkEngine,
}
#[cfg(not(target_os = "linux"))]
#[derive(Debug, Clone, serde::Serialize, serde::Deserialize)]
pub struct FirewallDiagnostics {
pub table_exists: bool,
pub table_name: String,
pub family: String,
pub chain_count: usize,
pub chains: Vec<String>,
pub rule_count: usize,
pub nat_enabled: bool,
pub live_ruleset: Option<String>,
pub kernel_status: String,
}
#[cfg(not(target_os = "linux"))]
#[derive(Debug, Clone, Default)]
pub struct NativeLinuxNftablesEngine {
fallback: SimulatedNetworkEngine,
}
#[cfg(not(target_os = "linux"))]
impl NativeLinuxNftablesEngine {
pub fn new() -> Self {
Self {
fallback: SimulatedNetworkEngine::new(),
}
}
pub async fn table_exists(&self) -> Result<bool> {
Ok(false)
}
pub async fn get_live_ruleset(&self) -> Result<String> {
self.fallback.get_active_nftables_ruleset().await
}
pub async fn apply_ruleset(&self, ruleset: &str) -> Result<()> {
Ok(())
}
pub async fn delete_table(&self) -> Result<()> {
Ok(())
}
pub async fn diagnose(
&self,
_desired_rules: &[FirewallRule],
desired_nat: bool,
) -> Result<FirewallDiagnostics> {
Ok(FirewallDiagnostics {
table_exists: false,
table_name: "nx9_wg".to_string(),
family: "inet".to_string(),
chain_count: 0,
chains: Vec::new(),
rule_count: 0,
nat_enabled: desired_nat,
live_ruleset: None,
kernel_status: "simulated".to_string(),
})
}
}
#[cfg(not(target_os = "linux"))]
impl NativeLinuxNetworkEngine {
pub fn new() -> Self {
Self {
@@ -104,6 +186,7 @@ impl NativeLinuxNetworkEngine {
}
}
#[cfg(not(target_os = "linux"))]
#[async_trait::async_trait]
impl NetworkEngine for NativeLinuxNetworkEngine {
async fn sync_routes(&self, routes: &[Route]) -> Result<()> {