Repository navigation
feat(envd): iptables DNAT backend for IPv4 port forwarding - #2697
ValentaTomas wants to merge 7 commits into
Conversation
…hysteresis
gopsutil's net.Connections walks /proc/<pid>/fd for every process every
second to attach PIDs to TCP sockets. The port forwarder never used the
PID for anything; it was a key component of the (pid, port) lookup map
but only because that's what the gopsutil call happened to provide. On a
sandbox running ~100 processes × ~20 FDs that's thousands of readlink
syscalls per scan.
- Replace the gopsutil call with a tiny /proc/net/tcp{,6} parser that
extracts (family, ip, port, status) for LISTEN sockets only. No /proc
walk; one read per protocol per scan.
- Drop the PID component of the forwarder's map key (family-ip-port is
enough — if a different process binds the same address the forwarded
path is still correct).
- Add a 3-scan hysteresis: a listener that disappears for a single scan
no longer drops its socat. Absorbs short flickers from things like
next.js HMR rebuilds and docker compose restarts.
macOS handler tests build via a `proc_listeners_other.go` no-op stub.
PR SummaryMedium Risk Overview Reviewed by Cursor Bugbot for commit 6b4f194. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
Code Review
Ignoring errors from listListeningSockets can cause the scanner to broadcast an empty list, which may lead to the unintended termination of all active port forwardings during transient filesystem errors. The forwarder fails to clean up persistent iptables rules when the subscriber channel closes, resulting in kernel resource leaks. Furthermore, the iptables backend appends rules without verifying if they already exist, causing redundant rules to accumulate across service restarts.
❌ 9 Tests Failed:
View the full list of 9 ❄️ flaky test(s)
To view more test analytics, go to the Test Analytics Dashboard |
Opt-in alternative to per-port socat for IPv4 listeners. IPv6 keeps socat. Toggled by ENVD_PORT_FORWARDER_IPV4_IPTABLES=1. - iptablesBackend adds/removes PREROUTING DNAT rules from sourceIP:port to 127.0.0.1:port. - route_localnet=1 enabled at forwarder start. - Falls back to socat if iptables fails.
fec454e to
cbb07f7
Compare
|
Superseded by a provision-time blanket DNAT rule (see follow-up PR). One rule covers all ports without envd-side iptables management. |
Opt-in alternative to per-port socat for IPv4 listeners (IPv6 keeps socat). Toggled by
ENVD_PORT_FORWARDER_IPV4_IPTABLES=1.Stacks on #2693.