blob: ef3926827a40e2289f9c1ff7600135f49a5f437f (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
|
#!/bin/sh
# checks/pf.sh
# pf health summary (enabled, state table usage, rule count), plus the
# actual active filter and nat/rdr rules listed as rows below. The rule
# rows use status "info" (a neutral gray square) rather than "ok" -
# they're informational, not a health signal, and a green square there
# would wrongly imply each individual rule was itself being health-
# checked.
set -eu
DIR=$(dirname "$0")
. "$DIR/../lib/common.sh"
# abbreviate_rule RULE
# Best-effort compression of pfctl's verbose rule syntax so rows fit a
# narrow column without wrapping mid-word. Not a semantic parser - just
# strips/replaces the tokens that are near-universal boilerplate on this
# ruleset (quick, flags S/SA, proto/from-to-port verbosity) and swaps
# in/out for arrows. Uses only the Arrows block (confirmed present in
# the scientifica font); avoids Dingbats (✓/✗) since that block isn't
# shipped. A rule shape this doesn't recognize just passes through
# unshortened - still correct, just longer.
abbreviate_rule() {
printf '%s' "$1" | sed -E \
-e 's/ in / → /' \
-e 's/ out / ← /' \
-e 's/ quick//' \
-e 's/ on / /' \
-e 's/ flags [A-Za-z\/]+//' \
-e 's/ modulate state/ [state]/' \
-e 's/ keep state/ [state]/' \
-e 's/ proto (tcp|udp|icmp)/ \1/' \
-e 's/ from any to any port = ([a-zA-Z0-9]+)/ :\1/' \
-e 's/ inet / /' \
-e 's/ round-robin//' \
-e 's/ all$//' \
-e 's/ all / /' \
-e 's/ +/ /g' \
-e 's/^ +//' -e 's/ +$//'
}
INFO=$(pfctl -si 2>/dev/null) || INFO=""
ENABLED=$(printf '%s\n' "$INFO" | awk -F'[ :]+' '/^Status:/{print $2; exit}')
if [ "$ENABLED" = "Enabled" ]; then
json_line "pf" "pf" "" "ok"
else
json_line "pf" "pf" "${ENABLED:-unknown}" "down"
fi
CURRENT=$(printf '%s\n' "$INFO" | awk '/current entries/{print $NF; exit}')
LIMIT=$(pfctl -sm 2>/dev/null | awk '/^states/{print $NF; exit}')
if [ -n "$CURRENT" ] && [ -n "$LIMIT" ] && [ "$LIMIT" -gt 0 ] 2>/dev/null; then
PCT=$((CURRENT * 100 / LIMIT))
if [ "$PCT" -ge 90 ]; then
SSTATUS=down
elif [ "$PCT" -ge 75 ]; then
SSTATUS=warn
else
SSTATUS=ok
fi
json_line "pf" "state table" "${CURRENT}/${LIMIT} (${PCT}%)" "$SSTATUS"
fi
RULE_COUNT=$(pfctl -sr 2>/dev/null | grep -c .) || RULE_COUNT=0
json_line "pf" "filter rules loaded" "$RULE_COUNT" "ok"
pfctl -sr 2>/dev/null | while IFS= read -r rule; do
[ -n "$rule" ] || continue
json_line "pf" " $(abbreviate_rule "$rule")" "" "info"
done
pfctl -sn 2>/dev/null | while IFS= read -r rule; do
[ -n "$rule" ] || continue
json_line "pf" " nat: $(abbreviate_rule "$rule")" "" "info"
done
|