Skip to content

fix: web-admin 端口 NAT 显示公网 + isLocalV4 与 agent 同步 TEST-NETs - #16

Merged
CarlJia merged 3 commits into
mainfrom
fix/web-admin-nat-display
Sep 18, 2026
Merged

CarlJia merged 3 commits into
mainfrom
fix/web-admin-nat-display

Conversation

@CarlJia

@CarlJia CarlJia commented Sep 18, 2026

Copy link
Copy Markdown
Owner

根因

NAT 后的 VPS 公网 IP 在后台"地址"列展示不出来。本修复包含三个相关改动:

  1. 移植上游 fix(web-admin): NAT 节点优先显示连接来源的公网地址 monitor-probe/monitor#9 — addresses() helper 把 hub 看到的公网 connection source IP 排在最前(NAT 机器的连接来源 = NAT 出口公网 IP)
  2. 修复 ce-code-review feat: WASM 插件通知系统——离线/到期事件、沙箱插件运行时与管理面板 #1 — isLocalV4 与 agent 的 is_public 范围同步(初版端口漏了 192.0.0/24 和 198.18/15)
  3. 修复独立范围遗漏 — 与 agent 同步,补 TEST-NET-2/3 与 240.0.0.0/4 排除

改动

3 个 commit:

1. fix(web-admin): NAT 节点优先显示连接来源的公网地址(ccd1ccd)

移植自 monitor-probe#9。新增 addresses(node) helper:agent 上报的是网卡地址(对 NAT 机器是 10.x 之类的内网),ip 是 hub 看到的连接来源(NAT 后是真实公网 IP)。当 node.ipv4 是私网、而 ip 是公网 v4 时,把 ip 排在最前。Hub 与节点同网时 ip 同样不前置。

2. fix(review): web-admin isLocalV4 补齐与 agent is_public 一致的排除范围(9e9a47a)

修复 ce-code-review #1(adversarial P1, 验证为 authorization-authentication)。agent 的 is_public 已扩展到 192.0.0/24 (464XLAT CLAT)、198.18/15 (TUN 代理 fake-IP)、0/8、224+(多播/保留),但 web-admin 的 isLocalV4 只查 192.168/16,没同步新排除项。补齐 4 个范围。

3. fix(web-admin): isLocalV4 与 agent is_public 同步排除 TEST-NETs(68c8ed6)

独立的范围遗漏:TEST-NET-2 (198.51.100/24)、TEST-NET-3 (203.0.113/24) 与 240.0.0.0/4 (reserved) 都没排除。这些 IANA special-purpose 段本应被面板当成非公网。补全与 agent is_public 一致。

测试

cargo test --bins   # 186 passed, 0 failed
npm test            # 全部通过(包含 addresses() 的 11 个用例)
npm run build       # 类型检查通过

测试用例已更新:

  • 2 处用 203.0.113.7 当"公网 connection source"的断言改为 8.8.8.8(203.0.113.7 现在正确地不算公网)
  • 新加 2 条断言锁定新范围的 panel 行为

配套

agent 仓库 PR 的 commit 89295ea 是同一处范围遗漏的修复:agent is_public 也补 TEST-NETs,与本 PR 保持同步。

CarlJia and others added 3 commits September 19, 2026 00:15
agent 上报的是网卡地址,NAT 机器的网卡上只有内网 IPv4,面板因此只显示
10.x 之类的地址。hub 已记录连接来源地址 ip,此前只在 agent 未上报网卡地址
时使用。

网卡 IPv4 属于内网、CGNAT、回环或链路本地,而来源是公网 IPv4 时,来源地址
排在最前,内网地址随后,两者均可点击复制。hub 与节点同网时来源同样是内网
地址,显示不变。不引入任何外部查询。

移植自 monitor-probe/monitor@fde2981 (#9)。

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
agent/src/collect.rs 的 is_public 已扩展到 192.0.0/24(464XLAT CLAT)、
198.18/15(TUN 代理 fake-IP)、0/8、224+(多播/保留),但 web-admin 的 isLocalV4
只查 192.168/16 等,没同步新排除项。一台 Clash TUN 或 464XLAT 的机器上报的
"公网"地址在面板被当成公网,但 hub 看到的是另一回事,login-throttling 与
地址展示都对不上。

把上述四个新范围加进 isLocalV4,让面板的私网判定与 agent 完全一致。
addresses() 的现存测试用例(覆盖公网/私网/CGNAT/同网等场景)继续通过。

来自 ce-code-review #1(adversarial P1,已通过验证)。

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
上游迁移时漏了 TEST-NET-2 (198.51.100/24)、TEST-NET-3
(203.0.113/24) 与 240.0.0.0/4 范围,这些 IANA special-purpose 段
本应被面板当成非公网。补全 isLocalV4 与 agent is_public 的
范围集合。

更新 2 处用 203.0.113.7 当 "公网 connection source" 的
测试断言 —— 现在 203.0.113.7 正确地被判为本地,公网 connection
source 的验证改用 8.8.8.8。新加 2 条断言锁定新范围。

来自 ce-code-review #1 的延伸:面板是这次扫描发现的"三处
保持同步"列表里的另一处。

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@CarlJia
CarlJia merged commit c19891e into main Sep 18, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant