feat: complete nx9-wg v0.8.0 platform
This commit is contained in:
1 parent
c75e5c4e71
commit
c8a9b7cde6
52 files changed
+7751
-725
No files matched your search
@@ -28,6 +28,11 @@ pub trait NetworkEngine: Send + Sync {
|
||||
|
||||
/// Get current active generated nftables ruleset.
|
||||
async fn get_active_nftables_ruleset(&self) -> Result<String>;
|
||||
|
||||
/// Check if desired routes have drift against live/active state.
|
||||
async fn has_route_drift(&self, _routes: &[Route]) -> Result<bool> {
|
||||
Ok(false)
|
||||
}
|
||||
}
|
||||
|
||||
/// In-memory simulated network engine for tests and non-root execution.
|
||||
@@ -88,14 +93,91 @@ impl NetworkEngine for SimulatedNetworkEngine {
|
||||
let active = self.active_ruleset.read().await;
|
||||
Ok(active.clone())
|
||||
}
|
||||
|
||||
async fn has_route_drift(&self, routes: &[Route]) -> Result<bool> {
|
||||
let enabled_routes: Vec<Route> = routes.iter().filter(|r| r.enabled).cloned().collect();
|
||||
let active = self.active_routes.read().await;
|
||||
Ok(enabled_routes != *active)
|
||||
}
|
||||
}
|
||||
|
||||
/// Linux Native Network Engine with kernel sysfs / netlink checks and fallback.
|
||||
/// Linux Native Network Engine with RTNETLINK and direct procfs forwarding.
|
||||
#[cfg(target_os = "linux")]
|
||||
pub use crate::native_linux::{
|
||||
FirewallDiagnostics, NativeLinuxNetworkEngine, NativeLinuxNftablesEngine,
|
||||
};
|
||||
|
||||
/// Fallback Simulated Network Engine for non-Linux platforms and unit testing.
|
||||
#[cfg(not(target_os = "linux"))]
|
||||
#[derive(Debug, Clone, Default)]
|
||||
pub struct NativeLinuxNetworkEngine {
|
||||
fallback: SimulatedNetworkEngine,
|
||||
}
|
||||
|
||||
#[cfg(not(target_os = "linux"))]
|
||||
#[derive(Debug, Clone, serde::Serialize, serde::Deserialize)]
|
||||
pub struct FirewallDiagnostics {
|
||||
pub table_exists: bool,
|
||||
pub table_name: String,
|
||||
pub family: String,
|
||||
pub chain_count: usize,
|
||||
pub chains: Vec<String>,
|
||||
pub rule_count: usize,
|
||||
pub nat_enabled: bool,
|
||||
pub live_ruleset: Option<String>,
|
||||
pub kernel_status: String,
|
||||
}
|
||||
|
||||
#[cfg(not(target_os = "linux"))]
|
||||
#[derive(Debug, Clone, Default)]
|
||||
pub struct NativeLinuxNftablesEngine {
|
||||
fallback: SimulatedNetworkEngine,
|
||||
}
|
||||
|
||||
#[cfg(not(target_os = "linux"))]
|
||||
impl NativeLinuxNftablesEngine {
|
||||
pub fn new() -> Self {
|
||||
Self {
|
||||
fallback: SimulatedNetworkEngine::new(),
|
||||
}
|
||||
}
|
||||
|
||||
pub async fn table_exists(&self) -> Result<bool> {
|
||||
Ok(false)
|
||||
}
|
||||
|
||||
pub async fn get_live_ruleset(&self) -> Result<String> {
|
||||
self.fallback.get_active_nftables_ruleset().await
|
||||
}
|
||||
|
||||
pub async fn apply_ruleset(&self, ruleset: &str) -> Result<()> {
|
||||
Ok(())
|
||||
}
|
||||
|
||||
pub async fn delete_table(&self) -> Result<()> {
|
||||
Ok(())
|
||||
}
|
||||
|
||||
pub async fn diagnose(
|
||||
&self,
|
||||
_desired_rules: &[FirewallRule],
|
||||
desired_nat: bool,
|
||||
) -> Result<FirewallDiagnostics> {
|
||||
Ok(FirewallDiagnostics {
|
||||
table_exists: false,
|
||||
table_name: "nx9_wg".to_string(),
|
||||
family: "inet".to_string(),
|
||||
chain_count: 0,
|
||||
chains: Vec::new(),
|
||||
rule_count: 0,
|
||||
nat_enabled: desired_nat,
|
||||
live_ruleset: None,
|
||||
kernel_status: "simulated".to_string(),
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(not(target_os = "linux"))]
|
||||
impl NativeLinuxNetworkEngine {
|
||||
pub fn new() -> Self {
|
||||
Self {
|
||||
@@ -104,6 +186,7 @@ impl NativeLinuxNetworkEngine {
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(not(target_os = "linux"))]
|
||||
#[async_trait::async_trait]
|
||||
impl NetworkEngine for NativeLinuxNetworkEngine {
|
||||
async fn sync_routes(&self, routes: &[Route]) -> Result<()> {
|
||||
|
||||
Reference in new issue
Block a user