Stop narrowing the shared runtime dir, close the injector on stop, allowlist VNC metrics

This commit is contained in:
Viktor Liu
2026-08-29 10:29:17 +02:00
parent 5ba3de375b
commit b56da75718
5 changed files with 138 additions and 15 deletions
+9 -11
View File
@@ -10,11 +10,13 @@ import (
vncserver "github.com/netbirdio/netbird/client/vnc/server"
)
// newConsoleVNC builds the FreeBSD console fallback: vt(4) framebuffer
// for capture, /dev/uinput for input. The uinput device requires the
// `uinput` kernel module (`kldload uinput`); without it, input init
// fails and we drop to a stub injector so the user still gets a
// view-only screen mirror.
// newConsoleVNC builds the FreeBSD console fallback: the vt(4) framebuffer for
// capture, and no input.
//
// Input injection is not implemented on FreeBSD: the uinput injector is a
// Linux-only implementation built on UI_DEV_CREATE and friends, so this backend
// mirrors the console read-only. It is offered anyway because a view-only
// console is still worth more than nothing on a box with no X server.
func newConsoleVNC() (vncserver.ScreenCapturer, vncserver.InputInjector, error) {
poller := vncserver.NewFBPoller("")
w, h := poller.Width(), poller.Height()
@@ -22,10 +24,6 @@ func newConsoleVNC() (vncserver.ScreenCapturer, vncserver.InputInjector, error)
poller.Close()
return nil, nil, fmt.Errorf("vt framebuffer init failed (vt may not allow mmap on this driver)")
}
if inj, err := vncserver.NewUInputInjector(w, h); err == nil {
return poller, inj, nil
} else {
log.Infof("VNC console: uinput unavailable (%v); view-only mode. Run `kldload uinput` to enable input.", err)
return poller, &vncserver.StubInputInjector{}, nil
}
log.Info("VNC console: FreeBSD has no input backend, serving the console view-only")
return poller, &vncserver.StubInputInjector{}, nil
}
@@ -85,6 +85,26 @@ var allowedMeasurements = map[string]measurementSpec{
"peer_id": true,
},
},
// Emitted per VNC session tick by influxDBMetrics.RecordVNCSessionTick.
"netbird_vnc_traffic": {
allowedFields: map[string]bool{
"period_seconds": true,
"bytes_out": true,
"writes": true,
"fbus": true,
"max_fbu_bytes": true,
"max_fbu_rects": true,
"max_write_bytes": true,
"write_time_seconds": true,
},
allowedTags: map[string]bool{
"deployment_type": true,
"version": true,
"os": true,
"arch": true,
"peer_id": true,
},
},
}
func main() {