5513 Commits

Author SHA1 Message Date
Jeremy Grossmann
884526c3be
Merge pull request #2900 from markparonyan/mypy-compute-iou-vm
fix(typing): resolve mypy errors in compute.iou.iou_vm
2026-09-28 23:33:41 +02:00
Jeremy Grossmann
f19274891c
Merge pull request #2898 from markparonyan/mypy-schemas-dynamips-templates
fix(typing): resolve mypy errors in schemas.controller.templates.dynamips_templates
2026-09-28 23:33:22 +02:00
Jeremy Grossmann
7864a4e567
Merge pull request #2897 from markparonyan/mypy-api-controller-links
fix(typing): resolve mypy errors in api.routes.controller.links
2026-09-28 23:26:48 +02:00
Jeremy Grossmann
f6ee1ee01a
Merge pull request #2896 from markparonyan/mypy-api-compute-qemu-nodes
fix(typing): resolve mypy errors in api.routes.compute.qemu_nodes
2026-09-28 23:25:55 +02:00
Jeremy Grossmann
35e1abcaf2
Merge pull request #2895 from markparonyan/mypy-agent-agent-service
fix(typing): resolve mypy errors in agent.gns3_copilot.agent_service
2026-09-28 20:56:12 +02:00
Jeremy Grossmann
02d02cceca
Merge pull request #2899 from markparonyan/mypy-db-models-base
fix(typing): resolve mypy errors in db models
2026-09-28 20:52:55 +02:00
Jeremy Grossmann
71965e0e81
Merge pull request #2894 from markparonyan/mypy-utils-zipfile-zstd
fix(typing): resolve mypy errors in utils.zipfile_zstd
2026-09-28 20:50:20 +02:00
Jeremy Grossmann
4ea31f98b7
Merge pull request #2893 from markparonyan/mypy-agent-mcp
fix(typing): resolve mypy errors in agent.mcp
2026-09-28 20:49:10 +02:00
Mark Paronyan
4802c865fc
fix(typing): resolve mypy errors in compute.iou.iou_vm 2026-09-28 21:48:18 +03:00
Mark Paronyan
db265f9524
fix(typing): resolve mypy errors in db models 2026-09-28 21:48:06 +03:00
Mark Paronyan
6f3e5cfc2b
fix(typing): resolve mypy errors in schemas.controller.templates.dynamips_templates 2026-09-28 21:47:56 +03:00
Mark Paronyan
ecff4beb65
fix(typing): resolve mypy errors in api.routes.controller.links 2026-09-28 21:47:46 +03:00
Mark Paronyan
b8a51fdefc
fix(typing): resolve mypy errors in api.routes.compute.qemu_nodes 2026-09-28 21:47:36 +03:00
Mark Paronyan
644ed63334
fix(typing): resolve mypy errors in agent.gns3_copilot.agent_service 2026-09-28 21:47:26 +03:00
Mark Paronyan
3fc1d27937
fix(typing): resolve mypy errors in utils.zipfile_zstd 2026-09-28 21:47:05 +03:00
Mark Paronyan
6ffa39642f
fix(typing): resolve mypy errors in agent.mcp 2026-09-28 21:41:58 +03:00
Mark Paronyan
8c0a5404ac
Merge branch '3.1' into mypy-compute-qemu-vm 2026-09-28 12:39:38 +03:00
Mark Paronyan
525ef8ca57
fix(typing): resolve mypy errors in compute.qemu.qemu_vm 2026-09-28 12:37:28 +03:00
Jeremy Grossmann
79ecb15164
Merge pull request #2888 from markparonyan/mypy-compute-vmware-vm
fix(typing): resolve mypy errors in compute.vmware.vmware_vm
2026-09-28 11:06:12 +02:00
Jeremy Grossmann
310bb193a5
Merge pull request #2887 from markparonyan/mypy-compute-docker-vm
fix(typing): resolve mypy errors in compute.docker vm modules
2026-09-28 11:03:44 +02:00
Jeremy Grossmann
ccee503b74
Merge pull request #2891 from markparonyan/mypy-controller-compute
fix(typing): resolve mypy errors in controller.compute
2026-09-28 11:01:30 +02:00
Jeremy Grossmann
10b5c1bb6b
Merge branch '3.1' into mypy-compute-project 2026-09-28 10:55:25 +02:00
Jeremy Grossmann
0bd1204d15
Merge pull request #2884 from markparonyan/mypy-config
fix(typing): resolve mypy errors in config
2026-09-28 10:54:17 +02:00
Jeremy Grossmann
0718e038f7
Merge pull request #2883 from markparonyan/mypy-utils-embed-shell
fix(typing): resolve mypy errors in utils.asyncio.embed_shell
2026-09-28 10:47:23 +02:00
Mark Paronyan
21643fe89d
fix(typing): resolve mypy errors in controller.compute 2026-09-28 04:56:59 +00:00
Mark Paronyan
d1df96e0a6
fix(typing): resolve mypy errors in utils.asyncio.embed_shell 2026-09-28 04:56:18 +00:00
Mark Paronyan
fdfb2d5591
fix(typing): resolve mypy errors in compute.vmware.vmware_vm 2026-09-28 04:55:44 +00:00
Mark Paronyan
667b0531f6
fix(typing): resolve mypy errors in compute.project 2026-09-28 04:55:38 +00:00
Mark Paronyan
b8ae84031e
fix(typing): resolve mypy errors in compute.docker vm modules 2026-09-28 04:55:32 +00:00
Mark Paronyan
f858ae23a6
fix(typing): resolve mypy errors in api.routes.index 2026-09-28 04:55:30 +00:00
Mark Paronyan
2512556770
fix(typing): resolve mypy errors in config 2026-09-28 04:55:20 +00:00
grossmj
8df25dec32
Development on 3.1.0.dev7 2026-09-27 20:21:12 +02:00
grossmj
4fa4ef7c2f
Release v3.1.0a6 2026-09-27 19:18:25 +02:00
grossmj
3f2afb0e4a
Bundle web-ui v3.1.0a6 2026-09-27 19:10:11 +02:00
grossmj
1f3d00dd1a
Merge remote-tracking branch 'origin/update-dependencies' into update-dependencies 2026-09-27 19:01:56 +02:00
grossmj
b96774d1f7
Sync appliances 2026-09-27 18:59:42 +02:00
Mark Paronyan
a0450b6bce
refactor: ruff autofixes 2026-09-27 15:55:10 +03:00
Mark Paronyan
8dfe05df3d
chore: justfile with mypy, ruff, pytest checks 2026-09-27 15:43:18 +03:00
Jeremy Grossmann
efd6bb77fe
Merge pull request #2878 from cristian-ciobanu/project-missing-images
Allow projects containing unavailable images to open in a degraded state instead of failing to load
2026-09-22 15:34:36 +02:00
grossmj
34923e46e0
chore(docs): update gns3_server.conf sample about the default NAT interface 2026-09-22 14:56:58 +02:00
Cristi
da16dc9874 fix(qemu): Fixed missing image replacement for linked-clone nodes 2026-09-18 23:58:49 +03:00
Cristi
59a367b88d Allow projects containing missing images to open in a degraded state instead of failing to load 2026-09-18 15:06:17 +03:00
YueGuobin
84e7ead465
fix: make node working directory deletion robust
The rmtree error handler in BaseNode.delete() was chmod'ing the failed
path to S_IWRITE (0o200). On POSIX this strips the search permission
from directories, turning a transient deletion failure into a directory
that can no longer be traversed or deleted. The node deletion itself
silently "succeeds" (rmtree gives up once its error handler returns)
and a later project deletion then fails with EACCES. The handler also
never retried the failed operation, so it did not help on Windows
either (the platform it was written for).

The transient failure exists in practice: a concurrent MD5 checksum
computation caching its result in the node directory (e.g. a properties
request racing the deletion) can recreate a file after rmtree has
listed the directory, making the final rmdir fail with ENOTEMPTY.

- add the missing user permissions instead of replacing the whole mode,
  and retry the failed unlink/rmdir
- retry the whole deletion a few times to absorb files recreated while
  the directory is being deleted
- raise a ComputeError when the directory cannot be fully deleted
  instead of failing silently
2026-09-15 01:23:31 +08:00
YueGuobin
be62e8c022
feat: keep Docker images on computes consistent with the controller host
Only relying on the image name lets a moved tag (e.g. a newer :latest)
silently serve stale content from a compute that already has an image
under the same name. When creating a Docker node, the controller now
pins the image id (Id from the Docker daemon on the controller host)
into the create payload. A compute holding a different image under the
same tag reports the image as missing, which routes it through the
image sync added by the previous commit and re-aligns the tag.

No new template fields or database changes: the controller host daemon
remains the source of truth and the pin is resolved per creation. When
the image is not available on the controller host the pin is omitted
and behavior is unchanged (the compute pulls from the repository).
2026-09-14 00:55:18 +08:00
YueGuobin
c477812332
feat: sync Docker images from the controller to remote computes
When a Docker node is created on a remote compute whose Docker daemon
does not have the image, the compute now raises ImageMissingError
instead of blindly pulling from the Docker repository. The controller
exports the image from the Docker daemon on its host (docker save
stream) and streams it to the compute which loads it, so locally built
or docker-loaded images work across computes. When the image is not
available on the controller host either, the compute is asked to pull
it from the Docker repository as a fallback.

- add a POST /docker/images/load compute endpoint that streams a
  docker save tar into the Docker daemon
- let Docker.http_query pass raw (non-dict) request bodies through so
  the tar can be streamed to the daemon
- drop the inline pull from DockerVM.create() and the now unused
  DockerVM.pull_image wrapper
2026-09-14 00:36:54 +08:00
YueGuobin
4b239cc11a
fix: run the reclaim helper as root regardless of the image's default USER
The one-shot reclaim container inherited the image's baked-in USER:
ghcr.io/nokia/srlinux runs as "user:user", so the "privileged" helper
was exactly as unprivileged as the server itself — chmod/chown on files
written by other uids (srlinux writes as a large internal uid) failed
with EPERM and node/project deletion still broke, just with a different
error. Pass --user 0:0 explicitly so the helper is root no matter what
the image declares, and fix the manual reclaim hint the same way.

Validated live on two stuck srlinux node directories (257/258
foreign-owned entries reclaimed to 0 in ~0.5 s each).
2026-09-12 23:15:52 +08:00
YueGuobin
54d9d7c08f
fix: reclaim root-owned container files so docker nodes and projects can be deleted
The stop-time permission pass necessarily runs before the container's
processes exit, so files written during the shutdown window (syslog
archives, trace flushes) and after any SIGKILL path stay owned by root
on the host. An unprivileged server can neither chown nor delete them,
which broke node deletion and project deletion.

Reclaim them through the only privilege door a non-root server has:
a one-shot throwaway container of the node's own image, entrypoint
overridden to the GNS3 busybox (nothing of the guest boots), chowning
the node directory back to the server user. It runs at the end of
close() — project deletion rmtrees the directory right after the nodes
close, so close must leave a clean tree — and as a retry fallback in
delete(). The helper resolves the image by its create-time ID with
--pull=never, so a stale or retagged image name cannot turn into a
registry pull attempt.
2026-09-12 23:04:28 +08:00
YueGuobin
5d91ca0efc
fix: harden sharkd replay sessions and serve the uncapped frame list
Review-driven session/transport fixes (each reproduced live against
sharkd 4.6.7 before fixing):

- raise the RPC stream limit to 16 MB: a full 1000-row frames page
  measures ~190 KB against the 64 KB StreamReader default, which failed
  the request with a 500 and desynchronized the resident session; a
  line-over-limit ValueError is now treated as a transport failure
- verify JSON-RPC reply ids: a timed-out request's late reply was
  served as the next request's answer; timeouts, dead pipes, malformed
  and stale replies now kill the session for good instead
- make check-spawn atomic under one manager lock: concurrent requests
  for the same pcap double-spawned sharkd and leaked the loser (process
  plus /tmp scratch copy) forever
- refcount sessions and evict idle only (LRU, cap raised 8 -> 16): a
  tag with more sources than the cap respawned every source on every
  request, and concurrent requests could get their session killed
  mid-RPC (spurious 502)
- map FilterError to sharkd's filter rejection (-13002) only; other
  engine failures with a filter set are 502, not a client 400
- detail: accept an optional frame_number to disambiguate
  same-microsecond frames (ts is not unique within a pcap); drop the
  -8003 -> 404 mapping (the range is validated locally, engine errors
  are real faults); a failed hex read is a 404 instead of "hex": null
- a pcap deleted mid-request is a 404, not a 500; the pcap-sized
  scratch copy runs off the event loop; server shutdown kills every
  resident session and drops its scratch directory
- pin the packet-list layout through scratch-HOME Wireshark
  preferences: the column indexes are a contract the server owns
  (protocol-level column negotiation is rejected by sharkd 4.6.x)

Range contract change (WebUI moved to an always-flat list): the merged
frame list is returned in full, deliberately uncapped - truncated and
per-second buckets are removed, frame_count always equals
len(frames), and rendering cost is the client's concern (the window
endpoint remains the incremental path).
2026-09-11 00:55:18 +08:00
YueGuobin
ef5d81498a
feat: accept link=<link_id> on the replay range and frames endpoints
Narrows the merged frame stream to one capture source BEFORE counting,
slicing and bucketing (frame_count / frames | buckets all recomputed on
the narrowed set), AND-composing with the display filter. A pure
identity filter applied before any engine work — only the selected
link's pcap gets a sharkd pass, so link+filter is cheaper than filter
alone.

Two boundaries by contract with the Web UI:
- sources[] stays the tag's stable inventory: every capture source
  listed with engine-free TOTAL counts, unaffected by link/filter — a
  source dropdown must not shrink when the view narrows (this also
  settles sources[].count on total counts rather than post-filter
  matches, which no spec ever required)
- an unknown link_id matches nothing: frame_count 0, start null, empty
  frames/buckets — the same shape as a zero-match display filter,
  deliberately not a 404; an empty link param is treated as absent
2026-09-09 00:53:06 +08:00
YueGuobin
790c423c26
feat: drive marker replay with resident sharkd sessions
sharkd (the Wireshark daemon) is now the single decode engine — the
tshark/PDML path is gone, and without sharkd every replay endpoint
returns 501 (no degraded mode: one engine, one rendering shape for the
Web UI).

- Frame entries gain packet-list columns from sharkd's frames RPC:
  src/dst/proto/info plus the Wireshark coloring hints bg/fg
- range and frames accept ?filter=<display filter>, applied before
  counting and slicing; invalid expressions are 400 carrying sharkd's
  original text; filters travel as single argv-style elements, capped
  at 2000 chars; filtered frames keep their original pcap frame numbers
- frame detail returns sharkd's protocol tree with keys renamed into
  the REST contract (element/label/name/filter_expr/pos+size/expert/
  generated/children): a census-verified closed key set, values
  untouched, unknown keys passed through verbatim, Wireshark-internal
  hf ids dropped. filter_expr gives the UI click-to-filter; pos/size
  drives hex highlighting (hex still read straight from the pcap)
- one resident 'sharkd -' session per source pcap: lazy spawn, /tmp
  scratch copy + scratch HOME (hardened profiles), per-request
  (mtime,size) validation with respawn, LRU bound, per-session lock,
  per-RPC timeout, bounded close

Timeline backbone (gate, record-header scan, merge ordering, canonical
ts strings, hex reads) stays plain Python — identity and ordering never
depend on the engine.
2026-09-08 00:04:04 +08:00