probe

package
v1.1.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: Apache-2.0 Imports: 25 Imported by: 0

Documentation

Overview

Package probe runs network measurements and knows nothing about the central.

Index

Constants

View Source
const DenyNone = "none"

DenyNone is the --deny value that denies nothing.

Variables

View Source
var DefaultDeny = []string{
	"127.0.0.0/8", "::1/128",
	"169.254.0.0/16", "fe80::/10",
	"0.0.0.0/8", "::/128",
	"224.0.0.0/4", "ff00::/8",

	"100.100.100.200/32", "192.0.0.192/32", "168.63.129.16/32", "fd00:ec2::254/128",
}

DefaultDeny are the ranges an edge never connects to unless told otherwise: loopback, link-local, unspecified, multicast and the metadata services of the clouds. Private ranges are allowed: probing an intranet is the point.

Functions

func Validate added in v1.1.0

func Validate(c api.Check) error

Validate reports why a check cannot be run: a target or an expectation that its kind cannot read, or an interval that is too short for it.

Types

type Outcome added in v1.1.0

type Outcome struct {
	OK  bool
	RTT time.Duration
	Err string
}

Outcome is the result of one measurement.

type Policy added in v1.1.0

type Policy struct {
	// contains filtered or unexported fields
}

Policy lists the address ranges a probe must not connect to. The zero value denies nothing.

func DefaultPolicy added in v1.1.0

func DefaultPolicy() Policy

DefaultPolicy is the policy of DefaultDeny.

func ParseDeny added in v1.1.0

func ParseDeny(value string) (Policy, error)

ParseDeny reads CIDR ranges separated by commas, or "none".

func ParsePolicy added in v1.1.0

func ParsePolicy(cidrs []string) (Policy, error)

ParsePolicy builds a policy from CIDR prefixes.

func (Policy) Control added in v1.1.0

func (p Policy) Control(_, address string, _ syscall.RawConn) error

Control is a net.Dialer hook. It sees the address that is about to be dialed, after name resolution, so it also covers redirects and DNS answers that point at a denied range.

func (Policy) Denies added in v1.1.0

func (p Policy) Denies(ip netip.Addr) bool

Denies reports whether the policy forbids connecting to ip.

type Prober

type Prober struct {
	// contains filtered or unexported fields
}

Prober runs measurements. Every connection it opens goes through the policy.

func New

func New(policy Policy, timeout time.Duration) *Prober

New builds a prober whose measurements stop after timeout.

func (*Prober) Banner added in v1.1.0

func (p *Prober) Banner(ctx context.Context, target, expect string) Outcome

Banner opens a connection and reads what the service says first: the line of an SSH, SMTP, FTP, IMAP or POP3 server, or the greeting of a database. It fails when nothing comes, or when expect is not in the line. The time is the connection and the first line.

func (*Prober) Closed added in v1.1.0

func (p *Prober) Closed(ctx context.Context, target string) Outcome

Closed checks that a port is not reachable: it is a good result when the connection is refused or goes unanswered, a failure when it opens. Use it for what must stay behind a firewall: a database, a management port.

func (*Prober) DNS added in v1.1.0

func (p *Prober) DNS(ctx context.Context, target, expect string) Outcome

DNS measures the time to resolve a name. A good answer has at least one record, and when expect is given, one of them holds that text.

func (*Prober) Domain added in v1.1.0

func (p *Prober) Domain(ctx context.Context, target, expect string) Outcome

Domain asks the RDAP service of the registry when a domain expires, and fails when it is within expect days (30 by default). The time is the whole query.

func (*Prober) Download added in v1.1.0

func (p *Prober) Download(ctx context.Context, target, expect string) Outcome

Download takes up to 8 MiB of a file. The time is the whole download. With expect, it fails when the speed is lower, in megabits per second.

func (*Prober) HTTP added in v1.1.0

func (p *Prober) HTTP(ctx context.Context, target string) Outcome

HTTP measures the time until the response headers of a GET arrive. A status of 400 or more is a failure.

func (*Prober) NTP added in v1.1.0

func (p *Prober) NTP(ctx context.Context, target, expect string) Outcome

NTP asks a time server for the time. The time is the round trip. It fails when the clock of this machine is further than expect from the server's, so it also tells when the edge itself has drifted.

func (*Prober) Ping added in v1.1.0

func (p *Prober) Ping(ctx context.Context, target, expect string) Outcome

Ping sends four ICMP echoes. It fails when more than expect percent of them are lost (50 by default); the time is the mean of the answers.

It needs no privilege on Linux when the group of the process may open ping sockets (net.ipv4.ping_group_range), and otherwise a raw socket.

func (*Prober) Run added in v1.1.0

func (p *Prober) Run(ctx context.Context, c api.Check) Outcome

Run measures c.

func (*Prober) TCP added in v1.1.0

func (p *Prober) TCP(ctx context.Context, target string) Outcome

TCP measures the time to open a connection to host:port.

func (*Prober) TLS added in v1.1.0

func (p *Prober) TLS(ctx context.Context, target, expect string) Outcome

TLS measures the time to open a connection and finish the handshake. It fails when the certificate is not trusted, does not match the name, or expires in fewer days than expect (14 by default).

func (*Prober) Traceroute added in v1.1.0

func (p *Prober) Traceroute(ctx context.Context, target, expect string) Outcome

Traceroute follows the path to a host, one router at a time. It is good when the host is reached in at most expect hops (30 by default); otherwise it says where the path ended: the last router that answered, and how far it was. The time is the round trip to the host.

It needs Linux, and no privilege: it sends UDP packets with a short time to live and reads the ICMP errors that come back.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL