Repository navigation
fix: web-admin 端口 NAT 显示公网 + isLocalV4 与 agent 同步 TEST-NETs - #16
Merged
Merged
Conversation
agent 上报的是网卡地址,NAT 机器的网卡上只有内网 IPv4,面板因此只显示 10.x 之类的地址。hub 已记录连接来源地址 ip,此前只在 agent 未上报网卡地址 时使用。 网卡 IPv4 属于内网、CGNAT、回环或链路本地,而来源是公网 IPv4 时,来源地址 排在最前,内网地址随后,两者均可点击复制。hub 与节点同网时来源同样是内网 地址,显示不变。不引入任何外部查询。 移植自 monitor-probe/monitor@fde2981 (#9)。 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
agent/src/collect.rs 的 is_public 已扩展到 192.0.0/24(464XLAT CLAT)、 198.18/15(TUN 代理 fake-IP)、0/8、224+(多播/保留),但 web-admin 的 isLocalV4 只查 192.168/16 等,没同步新排除项。一台 Clash TUN 或 464XLAT 的机器上报的 "公网"地址在面板被当成公网,但 hub 看到的是另一回事,login-throttling 与 地址展示都对不上。 把上述四个新范围加进 isLocalV4,让面板的私网判定与 agent 完全一致。 addresses() 的现存测试用例(覆盖公网/私网/CGNAT/同网等场景)继续通过。 来自 ce-code-review #1(adversarial P1,已通过验证)。 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
上游迁移时漏了 TEST-NET-2 (198.51.100/24)、TEST-NET-3 (203.0.113/24) 与 240.0.0.0/4 范围,这些 IANA special-purpose 段 本应被面板当成非公网。补全 isLocalV4 与 agent is_public 的 范围集合。 更新 2 处用 203.0.113.7 当 "公网 connection source" 的 测试断言 —— 现在 203.0.113.7 正确地被判为本地,公网 connection source 的验证改用 8.8.8.8。新加 2 条断言锁定新范围。 来自 ce-code-review #1 的延伸:面板是这次扫描发现的"三处 保持同步"列表里的另一处。 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
根因
NAT 后的 VPS 公网 IP 在后台"地址"列展示不出来。本修复包含三个相关改动:
addresses()helper 把 hub 看到的公网 connection source IP 排在最前(NAT 机器的连接来源 = NAT 出口公网 IP)isLocalV4与 agent 的is_public范围同步(初版端口漏了 192.0.0/24 和 198.18/15)改动
3 个 commit:
1. fix(web-admin): NAT 节点优先显示连接来源的公网地址(
ccd1ccd)移植自 monitor-probe#9。新增
addresses(node)helper:agent 上报的是网卡地址(对 NAT 机器是 10.x 之类的内网),ip是 hub 看到的连接来源(NAT 后是真实公网 IP)。当node.ipv4是私网、而ip是公网 v4 时,把ip排在最前。Hub 与节点同网时ip同样不前置。2. fix(review): web-admin isLocalV4 补齐与 agent is_public 一致的排除范围(
9e9a47a)修复 ce-code-review #1(adversarial P1, 验证为 authorization-authentication)。agent 的
is_public已扩展到 192.0.0/24 (464XLAT CLAT)、198.18/15 (TUN 代理 fake-IP)、0/8、224+(多播/保留),但 web-admin 的isLocalV4只查 192.168/16,没同步新排除项。补齐 4 个范围。3. fix(web-admin): isLocalV4 与 agent is_public 同步排除 TEST-NETs(
68c8ed6)独立的范围遗漏:TEST-NET-2 (198.51.100/24)、TEST-NET-3 (203.0.113/24) 与 240.0.0.0/4 (reserved) 都没排除。这些 IANA special-purpose 段本应被面板当成非公网。补全与 agent
is_public一致。测试
测试用例已更新:
配套
agent 仓库 PR 的 commit
89295ea是同一处范围遗漏的修复:agentis_public也补 TEST-NETs,与本 PR 保持同步。