These 69 commits are when the Protocol Buffers files have changed:
| Commit: | d9ba36a | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Claude | |
fix: close log subscribers in place, and carry the handler chain next to the line A removal whose wait ran out parked the occupied gate aside and the refused module was re-subscribed with a fresh one, so the retry the upgrade note recommends found only the empty new gate, reported nothing delivering, and let unload_plugin run under the handler the first attempt had refused for - and a purge after it did the same. The re-subscription also came after the refusal was logged, at the end of the list under a new id, so the module still loaded missed that line. The logger now takes the walk lists' shape: close_subscriber() closes a subscriber's gate in its place and waits for the lines inside it; reopen_subscriber() puts it back where it was; drop_subscriber() takes it out once nothing is inside. A gate a line is still inside simply stays closed in the list, so every later close, purge or clear waits for that line again, and a second add_subscriber() reopens the existing gate rather than handing out another. The separate draining list is gone. remove_subscriber() is close plus drop. The handler chain rode in hand-encoded protobuf bytes, spotted by the first byte - silently defeated by any path that re-serialised the line or a future field sorting first, and parsed twice. It now travels out of band: do_log hands it to the driver's new do_log_from_handler(), the console driver passes it straight back through the subscriber manager's new on_handler_log_message(), and the threaded driver queues it next to the line. Both are defaulted, so a driver or a subscriber that does not care is unchanged, and the line itself is never touched; log.proto is back to what main has. Assisted-by: Claude Code:claude-opus-5-5 Claude-Session: https://claude.ai/code/session_01NSoZ46k4khHVCwXpurkUdP Signed-off-by: Michael Medin <michael@medin.name>
The documentation is generated from this commit.
| Commit: | 45dc476 | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Claude | |
fix: gate each log subscriber on its own, and withhold a handler's line only from its chain 0e76d6a entered every subscriber's tracker before the first call, so a line stuck in ElasticClient had already entered WEBServer's and refused its unload for the whole outage - and its test pinned that. Each subscriber now sits behind its own gate (threads::gated), entered only around the call into it. A removal closes the gate, waits for the lines inside that subscriber only, and takes the subscriber out of the gate, so the remover is its last holder: the explicit leave() after each call no longer wakes a remover while the delivery still holds a reference, and a module's destructor never runs on the logging thread. A removal that cannot wait a line out keeps the subscriber draining, and clear_subscribers() waits for it again at shutdown and names it. The handler tag was a depth check that hid every line logged on the delivering thread from every handler: a failure ElasticClient logged from its handler no longer reached the web UI's live log or check_nscp's error tally. A line a handler writes now carries the chain of handlers it came through, in a new top-level LogEntry.handled_by field, and is withheld from those only; every other handler gets it, as on main. Two handlers that log per line stop after one round each. The field is written ahead of the entries, so on_log_message spots it from the first byte and parses only such a line, where every line used to be parsed once here and again by each subscriber. The tag replaces the Entry.from_log_handler flag added on this branch. set_backend() builds its backend and hands it to use_backend(), so the path the tests take and the one the service takes are the same. Assisted-by: Claude Code:claude-opus-5-5 Claude-Session: https://claude.ai/code/session_01NSoZ46k4khHVCwXpurkUdP Signed-off-by: Michael Medin <michael@medin.name>
| Commit: | 0e76d6a | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Claude | |
fix: tag a handler's log line in the line itself, and track deliveries per subscriber f679044 remembered a handler's lines by content and withheld the next identical line from the handlers. That keyed suppression on the wrong thing: on the threaded backend a byte-identical line from another source could be popped first, never reach any handler, and leave the handler's own copy untagged and fanned out back to it - and a line the backend dropped left its tag behind for good, while every line on every thread scanned the pending ones under the mutex. LogEntry has no timestamp, so repeated errors collide easily. The tag now travels in the line: do_log, on the thread where the depth is known, sets a new from_log_handler field on each entry, and on_log_message reads it back however the line travelled. Nothing is remembered, so nothing can be stolen or leak. A line that is not a LogEntry is delivered as before. Deliveries are counted per subscriber, each with its own tracker, entered under the list mutex before the first call. remove() waits only for the lines inside the subscriber being removed, so a slow ElasticClient handler no longer refuses the unload of CheckNSCP; it scans the list before copying it, so an unload of a module that never subscribed costs no copy. clear_subscribers() now returns the subscribers a line was still inside when its single shared bound ran out, for shutdown to leave alone. Assisted-by: Claude Code:claude-fable-5-1 Claude-Session: https://claude.ai/code/session_01NSoZ46k4khHVCwXpurkUdP Signed-off-by: Michael Medin <michael@medin.name>
| Commit: | 84174dd | |
|---|---|---|
| Author: | Michael Medin | |
feature: report facts from a cached snapshot, and say when they were read Facts are cheap to gather today and will not stay that way: a `storage` or `software` set means walking volumes or the uninstall hives, and the policy has to be right before the expensive producer arrives rather than after. CheckSystem now reads the machine once and reports that reading thereafter. Host facts describe what a machine *is* - the OS it boots, the silicon it sits on, how much memory is in it - and none of that changes while the process runs, so the hourly round has nothing to re-read. `startup` and `manual` collect; `scheduled` and `reload` report what is held. An unknown reason reads as scheduled, so a core that grows a new one cannot silently turn a cached producer into a collecting one. That makes the round's timestamp a lie, which is the other half of this. `collected` says when the core last *asked*; showing it against cached values claims an inventory is as fresh as the last poll. So a producer can now say when it actually read, `FactSet.gathered`, and the core keeps it per set and returns it in the envelope. It is kept beside the set rather than inside it, and that is load-bearing: the repository decides "did anything change" by comparing the encoded document, so a timestamp in there would make every round a change and bump the revision hourly forever - re-uploading an inventory that never moved. For the same reason `mark_gathered` is separate from `set()` and is called whatever `set()` returned: the unchanged case is exactly the one where a cached producer has something true to say about age. Consumers show the age of the values, not of the round: nscp> facts Revision: 2 Checked: 2026-09-24T05:19:23Z Gathered: hardware: 2026-09-24T05:19:10Z os: 2026-09-24T05:19:10Z and the web UI moves the timestamp onto each card as "gathered", leaving a quieter "checked" chip in the toolbar. A set whose producer does not say falls back to the round, which is right: it read them just now. Verified on Windows across a 5s interval - `Checked` advances while `Gathered` and `revision` stay put, and `facts refresh` moves `Gathered`. Assisted-by: Claude Code:claude-opus-5 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Michael Medin <michael@medin.name>
The documentation is generated from this commit.
| Commit: | 5298aa7 | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
refactor: carry host facts as protobuf, like every other ABI payload Facts were the odd one out. The registry, settings, storage, commands and metrics all cross the plugin ABI as serialised protobuf; facts crossed it as JSON, and the core stored the document as boost::json on top of that. This moves them onto the house format, while nothing produces a fact set yet and the change therefore costs nobody a migration. `libs/protobuf/facts.proto` is the document: * `Value` (a oneof over string, int64, uint64, double, bool, `Object` and `List`), `Field`, `Object` and `List`. Hand-rolled rather than google.protobuf.Struct because Struct is full-runtime and a LITE_RUNTIME message cannot import it - the same reason metrics.proto spells out its own recursive bundle. * `Object` holds `repeated Field`, not a protobuf `map`, so the order of an object's keys is ours to decide. The core sorts every object as it accepts a set, which is what makes two collections of the same inventory compare equal byte for byte, and through that what keeps the revision from moving when nothing changed. * `FactSet { id, facts, removed, error }` replaces the three states the JSON spread across `sets`, an explicit null and a separate `errors` map. Not mentioning a set at all is still the third one: it leaves what the core has, so a transient failure never blanks the inventory. * `FactsQueryMessage`/`FactsMessage` for NSFetchFacts and `FactsRequestMessage`/`FactsResponseMessage` (GET/REFRESH) for NSAPIFactsQuery. Neither ABI signature changes - both entry points always passed opaque buffers - so only what is inside them is different. JSON survives in exactly one place, and deliberately. `fact_repository` stores protobuf, but `to_json()` renders the document the way the fleet upload sends it and `get_hash()` is the SHA-256 of precisely those bytes. That is the one boundary where an implementation that is not this one has to agree on an encoding, and JSON has a canonical form to agree on where protobuf defines none. The hash is now computed on demand rather than kept up to date, because only the upload reads it: the agent's own reads and writes never look at it. The size budget counts encoded bytes instead of the canonical JSON's length. The JSON rendering is in `nscapi/protobuf/facts.hpp` beside the tree helpers, so the REST layer that follows shares it. Its doubles go through streams imbued with the classic locale rather than printf or a default stringstream: both follow the locale, and a host that writes 1,5 would otherwise put something that is not a number into the document the server hashes. `nscapi::facts` keeps the builder a producer sees - `set()`, `record(id)`, `value()`, `strings()`, `time()` - and only changes what it builds and how it is handed over (`serialize()`, plus `to_message()` for a test that would rather assert on the tree than on bytes). Boost.JSON is no longer linked into plugin_api at all, so a module that produces facts stops pulling a JSON library in through the plugin API. Tests: the repository's rules, sorting and hash stability all move over, with the document written as JSON in the fixtures and converted, so what a test asserts stays readable. The contract between a producer and the core is now driven through the real builder rather than hand-written JSON, and two cases join it - a set that failed to collect keeps the value it had, and every scalar type survives the round trip, including a uint64 past int64 and a double whose decimal point is a dot. Assisted-by: Claude Code:claude-opus-5 Signed-off-by: Michael Medin <michael@medin.name>
| Commit: | b03dd4f | |
|---|---|---|
| Author: | Michael Medin | |
refactor: carry host facts as protobuf, like every other ABI payload Facts were the odd one out. The registry, settings, storage, commands and metrics all cross the plugin ABI as serialised protobuf; facts crossed it as JSON, and the core stored the document as boost::json on top of that. This moves them onto the house format, while nothing produces a fact set yet and the change therefore costs nobody a migration. `libs/protobuf/facts.proto` is the document: * `Value` (a oneof over string, int64, uint64, double, bool, `Object` and `List`), `Field`, `Object` and `List`. Hand-rolled rather than google.protobuf.Struct because Struct is full-runtime and a LITE_RUNTIME message cannot import it - the same reason metrics.proto spells out its own recursive bundle. * `Object` holds `repeated Field`, not a protobuf `map`, so the order of an object's keys is ours to decide. The core sorts every object as it accepts a set, which is what makes two collections of the same inventory compare equal byte for byte, and through that what keeps the revision from moving when nothing changed. * `FactSet { id, facts, removed, error }` replaces the three states the JSON spread across `sets`, an explicit null and a separate `errors` map. Not mentioning a set at all is still the third one: it leaves what the core has, so a transient failure never blanks the inventory. * `FactsQueryMessage`/`FactsMessage` for NSFetchFacts and `FactsRequestMessage`/`FactsResponseMessage` (GET/REFRESH) for NSAPIFactsQuery. Neither ABI signature changes - both entry points always passed opaque buffers - so only what is inside them is different. JSON survives in exactly one place, and deliberately. `fact_repository` stores protobuf, but `to_json()` renders the document the way the fleet upload sends it and `get_hash()` is the SHA-256 of precisely those bytes. That is the one boundary where an implementation that is not this one has to agree on an encoding, and JSON has a canonical form to agree on where protobuf defines none. The hash is now computed on demand rather than kept up to date, because only the upload reads it: the agent's own reads and writes never look at it. The size budget counts encoded bytes instead of the canonical JSON's length. The JSON rendering is in `nscapi/protobuf/facts.hpp` beside the tree helpers, so the REST layer that follows shares it. Its doubles go through streams imbued with the classic locale rather than printf or a default stringstream: both follow the locale, and a host that writes 1,5 would otherwise put something that is not a number into the document the server hashes. `nscapi::facts` keeps the builder a producer sees - `set()`, `record(id)`, `value()`, `strings()`, `time()` - and only changes what it builds and how it is handed over (`serialize()`, plus `to_message()` for a test that would rather assert on the tree than on bytes). Boost.JSON is no longer linked into plugin_api at all, so a module that produces facts stops pulling a JSON library in through the plugin API. Tests: the repository's rules, sorting and hash stability all move over, with the document written as JSON in the fixtures and converted, so what a test asserts stays readable. The contract between a producer and the core is now driven through the real builder rather than hand-written JSON, and two cases join it - a set that failed to collect keeps the value it had, and every scalar type survives the round trip, including a uint64 past int64 and a double whose decimal point is a dot. Assisted-by: Claude Code:claude-opus-5 Signed-off-by: Michael Medin <michael@medin.name>
| Commit: | 1d8bbac | |
|---|---|---|
| Author: | Michael Medin | |
fix: make a web session logout outlive an unclean stop Nine review findings on the session-persistence change. The first one is the only behaviour change an operator can see; the rest are correctness, documentation and test coverage. Revoking a session only removed it from memory. The table reached the disk at a clean shutdown and nowhere else, so a logout followed by a crash, a SIGKILL or a power loss resurrected the session at the next start - the one thing the security notice promised would not happen. A put may now ask the core to write the store before returning (`flush` on the storage put request), and every revocation writes the remaining table out that way. Two savers would then have been writing nsclient.tmp at once, so storage_manager::save() takes a mutex of its own; WEBServer serialises its own exports for the same reason, since a logout now writes from the thread serving the request. A record dated in the future was treated as expired, which is right for a live session and wrong for a stored one: a host whose clock is behind at boot - no battery-backed clock, NTP not reached yet - dropped every session it had stored and then blanked the table at the next shutdown. Such a record is now restored with its age reset, and the host is told once that its clock is behind. The comment on token_entry said a session without a credential fingerprint was never persisted, while snapshot() exported one anyway for import to refuse. snapshot() now leaves it out, so every record on disk has all four fields. grant_store::get_role was added as a non-inserting twin of fetch_role because fetch_role used `users[uid]`, which inserted an empty role for every unknown uid a permission check asked about. fetch_role uses find() instead, which fixes the growth, makes the lookup const, and leaves get_role as a plain accessor. import_sessions hashed a credential fingerprint per row rather than per user, and repeated a has_user() check that fingerprint_for_user already makes. persist_sessions tested a `session` that is constructed with the module and never reset. Documentation: both the notice and the upgrade note said a password change ends that user's sessions "whether or not the agent was restarted in between". It does not. A settings reload re-enters loadModuleEx with reloadStart and the user table is only read in the normalStart branch, so the running service keeps the users it started with: until it is restarted the new password does not work and the old sessions do not end. Both pages now say that, and both are rewritten in the voice of the notice next to them - what the reader sees and does, not how the agent is put together. Tests: the integration suite was skipped whole on Windows because the fixture's stop() there is a SIGKILL. It is now split, and the half that does not need a clean stop runs everywhere - including a new case that logs a key out, kills the agent and asserts the key is gone while one issued after the last clean shutdown is still there, which is only possible if the logout wrote the file. Unit tests cover the clock-skew import, the revocation handler, snapshot skipping a fingerprint-less session, and a permission check not mutating the grant store. `let rotatedKey` moved up beside the other keys it is threaded through. Assisted-by: Claude Code:claude-opus-5 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LUCZFc86TSphwmh6hzbuXy Signed-off-by: Michael Medin <michael@medin.name>
| Commit: | 21b40ff | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
feature: mark experimental modules and check commands A check that landed last month and one that has been there for a decade look identical in every list NSClient++ offers, so nothing tells an operator which options are safe to build a monitoring template on. A module or a command can now declare that it is still moving, and every surface that lists it says so. module.json gained an "experimental" flag: inside "module" for a whole module (a zip bundle declares the same key at the top level of its manifest) and on any entry in "commands". The build turns the command flag into part of the registration the module sends to the registry, and the module flag into a new optional NSGetModuleFlags export which the core reads when it inventories a module - whether it is loaded or only sitting in the module directory. A module built before the export exists simply does not have it and declares nothing, and an alias inherits the flag of the command it stands for. From the registry it reaches every consumer: * `nscp test` appends "(experimental)" to the name in queries, aliases, list and plugins, and adds a "Status:" line to desc. * REST reports an `experimental` field on /modules, /queries and /aliases. * the web UI shows an Experimental chip in both lists and on the module and query pages, and its filter field matches on the word. * the reference documentation marks the command and module tables and puts a note on the command or module itself. Everything added in the last six months is marked: the recent check_* commands of CheckDisk, CheckDocker, CheckNet, CheckNSCP, CheckSystem, CheckSystemUnix and Scheduler, plus the whole of CheckMSSQL, CheckMySQL, CheckSecurity, CheckWindowsApps, IcingaClient and NSCANgClient. The mark says nothing about whether a check works - only that its options, keywords and output may still change - and it comes off as each one settles. Assisted-by: Claude Code:claude-opus-5 Signed-off-by: Michael Medin <michael@medin.name>
| Commit: | bb55e70 | |
|---|---|---|
| Author: | Michael Medin | |
feature: give every metric a description, a unit and a real type The OpenMetrics endpoint emitted a name, a value and `# TYPE ... gauge`, and nothing else. Nobody was told what `system_mem_commited_avail` measured or what it was measured in; monotonic counts were typed as gauges, so `rate()` was unsafe on the very metrics it is for; and a string-valued metric - uptime, boot time, a MAC address, the power source - had no numeric sample, so it was dropped from the exposition entirely. The schema already modelled most of this and no producer ever filled it in. `Metric.desc` becomes the `# HELP` text, falling back to the bundle's `desc` so a section of near-identical metrics (one per core, one per NIC) is described once; `Metric.dims` becomes labels; which member of the `value` oneof is set is the type. One additive field was missing, `Metric.unit = 12`, which becomes `# UNIT` and makes the family name end in the unit, as the spec requires of a family that declares one - so `system_mem_physical_total` is `system_mem_physical_total_bytes` now. Producers declare all of it through a builder in `nscapi::metrics`: metric(mem, "physical.used").help("Physical memory in use").unit("bytes").gauge(used); The four `add_metric` overloads stay as the no-metadata shorthand, so an out-of-tree module keeps working and keeps producing exactly what it did. The sweep covers the core's own `workers` bundle, `Scheduler`, both `CheckSystem`s (memory, cpu, uptime, pdh, network, temperature, cpu frequency, battery, OS updates, process history, real-time filter counts) and `CheckDisk`, and moves the two hand-rolled protobuf sites onto the builder as well. Typing is a judgement per metric rather than a rename of everything that looks like a count. Only what is monotonic for the life of the agent is a counter: worker and scheduler jobs/submitted/errors, `times_seen`, the real-time filter counts. The WMI `Packets*Errors` fields read like totals and are turned into per-second rates before they reach the bundle, so they stay gauges. Retyping a metric would have made it vanish from every consumer that asked `has_gauge_value()` - the JSON views and with them the web UI dashboard, Graphite, Elastic, the Python dict and the shared metrics store. They read it through `nscapi::metrics::numeric_value()` now, so a counter is forwarded like any other number and the flat key set does not move. Strings come back as their section's `_info` family, the `node_uname_info` shape: `system_uptime_info{uptime="1d 12:30",boot="2026-09-13 01:15"} 1`. The endpoint now serves two bodies rather than one. The two specifications disagree about what a counter's metadata lines name - the family in OpenMetrics 1.0 (`# TYPE workers_jobs counter`, sample `workers_jobs_total`), the sample in the older text format (`# TYPE workers_jobs_total counter`) - and `info` does not exist in the older one at all. A single body loses the type of every counter for one of the two readers, and the strict OpenMetrics parser rejects the older spelling outright, so both are rendered from one snapshot and the controller serves whichever matches the `Content-Type` it answers with. Sample lines are identical in both. Two producers can now describe their own metrics: a predefined PDH counter takes optional `help` and `unit` keys (help defaulting to the counter path), and a Python script may return `{"value": 42, "help": …, "unit": …, "type": "counter"}` in place of a bare number - which still means a gauge with no description, as it always did. Verified against `prometheus_client`'s two parsers on a real scrape: 328 families, and the strict OpenMetrics parser rejects the older body, which is what the second rendering exists to prevent. Assisted-by: Claude Code:claude-opus-5 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AzrBiR3cDoWmrQ69SLWMDj Signed-off-by: Michael Medin <michael@medin.name>
| Commit: | 9188bac | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
fix(settings): redact sensitive values on settings read paths The REST settings read endpoints (GET /api/v2/settings/... and /descriptions) and the `nscp settings --list`/`--show` CLI returned values for keys registered sensitive (add_password / is_sensitive_key) in clear text, while the /diff endpoint already masked them. A principal scoped to only settings.get could therefore read stored secrets it should not see in plaintext (e.g. the shared /settings/default password). Add an opt-in redact_sensitive flag to the settings Query/Inventory protobuf requests. The REST read endpoints set it, so values for sensitive keys are returned as "***", mirroring parse_diff. Internal self-reads (a module loading its own secret, e.g. WEBServer reading /settings/default/password at boot) leave the flag unset and still get the real value, so authentication keeps working. The CLI list/show paths mask via is_sensitive_key directly. This is a defence-in-depth / consistency fix, not a new authorization boundary: the plaintext still lives in nsclient.ini and any principal holding write or execute privilege can read it regardless. Reported-by: yagust (https://github.com/yagust) Assisted-by: Claude Code:claude-fable-5 Signed-off-by: Michael Medin <michael@medin.name>
| Commit: | 86da6b5 | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
Fixed #748 support for nagios range based syntax in performance data
| Commit: | 3b1835c | |
|---|---|---|
| Author: | Michael Medin | |
Added support for showing settings diff in the web UI
| Commit: | 88a338b | |
|---|---|---|
| Author: | Michael Medin | |
Started to re-add dotnet support
| Commit: | 019ed90 | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
Added the concept of "types" to the settings system so we can difrentiate between int and strings
| Commit: | 1bdd9db | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
feature: Added support for storing passwords in credential manager * Improves error handling in installer * Fixes some settings issues * deprecated settings --generate in favor of settings --update (does the same but is a better name) * Adds embry of a guide to secure NSClient++
| Commit: | 7b3061f | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | GitHub | |
Updated all dependencies and added pipelines * Massive update with changes updates to all libraries and third party dependencies * Updated to python 3 * Automated build pipelines (Github Actions) * Currently Disabled: * DotNet modules * Lua scripting * Web interface (server still works, just no UI) * Fixed more build issues * Fixed performance data parsing when > 1Tb * Added option to disable TLS1.1, TLS1.2 and TLS1.3
| Commit: | b23153d | |
|---|---|---|
| Author: | Michael Medin | |
Fixed syntax issues protobuf files Added metrics dimension support
| Commit: | b7859e8 | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
BREAKING CHANGE: Protobuf 3 upgrade including reworking internal messages
| Commit: | 34a56dc | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
New API and rewritten web page to use angular 2
| Commit: | c4d2c3d | |
|---|---|---|
| Author: | Michael Medin | |
Added storeage API
| Commit: | c3c3e7d | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
Removed query from settings protobuf api as it was never used
| Commit: | 919d742 | |
|---|---|---|
| Author: | Michael Medin | |
Improved the markdown docs for the plugin API
| Commit: | 835635e | |
|---|---|---|
| Author: | Michael Medin | |
Major overhaul of the documentation making the generated bits easier to read...
| Commit: | 71050f8 | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
return values should be optional
| Commit: | 55cbccd | |
|---|---|---|
| Author: | Michael Medin | |
Fixed typo
| Commit: | 1d943a6 | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
Added som comments to the protobuf file
| Commit: | ec0aded | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
Core: Added events
| Commit: | 880edaf | |
|---|---|---|
| Author: | Michael Medin | |
Removed attachments (as they are never used)
| Commit: | 4317ff2 | |
|---|---|---|
| Author: | Michael Medin | |
Changed cr/lf on all files locally
| Commit: | 7a87a8d | |
|---|---|---|
| Author: | Michael Medin | |
removed unused ipc
| Commit: | dded848 | |
|---|---|---|
| Author: | Michael Medin | |
Added support for config templates
| Commit: | 056e922 | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
Started to implement trace logging
| Commit: | 7ded24e | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
Fixed issues with module names and plugins (to make grouping queries possible)
| Commit: | 4131eda | |
|---|---|---|
| Author: | Michael Medin | |
more regressions fixes for targets and other objects Added new "bundle command" to headers to allow executing entire sets
| Commit: | 2b504cb | |
|---|---|---|
| Author: | Michael Medin | |
* Added metrics message implementation * New dashboard with based on metrics message implementation * bumped version of web ui components
| Commit: | 176e69a | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
rather big and messy change where i have reworked all the clients
| Commit: | a579c48 | |
|---|---|---|
| Author: | Michael Medin | |
TODO
| Commit: | 8662578 | |
|---|---|---|
| Author: | Michael Medin | |
Adde documentation to protobuf file
| Commit: | de2abae | |
|---|---|---|
| Author: | Pall Sigurdsson | |
| Committer: | Pall Sigurdsson | |
Fix typo CRITCAL > CRITICAL I noticed a probelm in CheckNSCP.cpp and CheckHelpers that sometimes CRITCAL was being returned as a status. Not sure if it was intentional or not, but I replaced all occurances. It looks like some of the source files have old DOS file endings (^M) instead of unix-friendly linebreaks. My search replace stripped some of them and I hope that does not cause any damage. Please check it out and let me know if this was the right thing to do.
| Commit: | 12d16e0 | |
|---|---|---|
| Author: | Michael Medin | |
* Major refactoring of json handling * now uses exact same messages as protobuf (compiled from protobuf) * Added json-protobuf (library to compile protobuf to json spirit) * Added help-pb to get help as protobuf from commands * Removed help-csv since help-pb is better (and built-in to inventory) * Clenaedup protobuf file and removed some unesseceary fields. * migrated "test" client into a separate moduile (CommandClient) * greatly extended the client interfaces (both web and console) to have new and improved commands
| Commit: | b9e22fd | |
|---|---|---|
| Author: | Michael Medin | |
* Extensive additions to the WEB UI * Console can be used much like nscp tesat * Log view is enhaned * Modules view added
| Commit: | ba996b1 | |
|---|---|---|
| Author: | Michael Medin | |
removed some unnessecary shared dependencies
| Commit: | 5e0420f | |
|---|---|---|
| Author: | Michael Medin | |
Added settings and log view to web ui as well as login and other tweaks. Tweaked some in the settings subsystem to better provide for the WEB ui. Made console log asynch to improve speed a bit.
| Commit: | 8cedc33 | |
|---|---|---|
| Author: | Michael Medin | |
Essentially a brand new check subsystem as well as internal refactoring
| Commit: | b217851 | |
|---|---|---|
| Author: | Michael Medin | |
documentation updates as well as backend support for generating documentation
| Commit: | f542694 | |
|---|---|---|
| Author: | Michael Medin | |
Yet another massive update with mainly internal stuff The most interesting thing is I guess the new documentation toolkit which is now "working" (not much content yet, but it will come)
| Commit: | 94bb8cc | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
Fixed issue with commands escaping Changed a lot of the utf16 into utf8 as well as major API refactoring
| Commit: | c77838e | |
|---|---|---|
| Author: | Michael Medin | |
Massive refactoring effort. All(most) commands now support help for interactive help as well as built-in documentation for all(most) commands and configuration.
| Commit: | b029214 | |
|---|---|---|
| Author: | Michael Medin | |
| Committer: | Michael Medin | |
* Created json module information blocks
| Commit: | a90ef7c | |
|---|---|---|
| Author: | Michael Medin | |
* Initial merge of 0.4.1 into 0.4.2
| Commit: | 77c0100 | |
|---|---|---|
| Author: | Michael Medin | |
Merge branch '0.4.1' into 0.4.2 Conflicts: CMakeLists.txt changelog helpers/settings_manager/settings_handler_impl.hpp include/nscapi/nscapi_plugin_impl.cpp include/nscapi/nscapi_plugin_impl.hpp include/settings/impl/settings_http.hpp include/settings/impl/settings_old.hpp libs/protobuf/plugin.proto modules/CheckExternalScripts/CheckExternalScripts.cpp modules/CheckSystem/CMakeLists.txt modules/CheckSystem/CheckSystem.cpp modules/CheckSystem/CheckSystem.h modules/CheckSystem/PDHCollector.cpp modules/LUAScript/LUAScript.cpp modules/LUAScript/script_wrapper.hpp service/cli_parser.hpp version.txt
| Commit: | 53be5c8 | |
|---|---|---|
| Author: | Michael Medin | |
* LUAScript: Improved lua scripting module a lot * LUAScript: Added protocol buffer support to lua scripts * tests: Rewrote (halfway there) test_nrpe python script as a lua script. * CheckEventLog: Fixed command name when submitting real-time "no action checks"
| Commit: | 393a00f | |
|---|---|---|
| Author: | Michael Medin | |
* Improved settings API with new protocolbuffers command (available from python) * Improved registration API with new protocolbuffers command (available from python) * Created new python documentation module docs.py * Improved command line syntax so executable commands now take an optional module prefix
| Commit: | 8d89d7a | |
|---|---|---|
| Author: | Michael Medin | |
* Fixed issue with default port for NSCA/NRPE/* clients * Removed FileLogger * Rewritten log implementation from ground up without using crappy boost library which requires DNS :( * Removed some annoying "error" messages * Tweaked FileLogger a bit to be more "modern" * Changed so file-name expansion is more efficient * Changed so modules are defaulted to 0 in config. * Log levels are case sensitive * Fixed so log level is not read from ini file * improved plugin processing from ini files
| Commit: | c74d7b6 | |
|---|---|---|
| Author: | Michael Medin | |
* Added new module CauseCrash which has a single command CrashClient to allow the service to be crashed remotly *WARNING* Dont use this command, it is for debugging and testing purpouses only * Fixed issue with BreakPad which was disabled * Fixed some unix issues (sorry but hudson's stopped emailing me again:( ) * Fixed service --install (now sets correct options) * Fixed service --install (now sets description correctly) * Fixed log level defined in protobuf (now same as rest of the system) * Fixed some issues with the check_nscp command
| Commit: | 9b9be81 | |
|---|---|---|
| Author: | Michael Medin | |
* Fixed many many issues all over the place as I tried to make things working for my pressention at nwc.
| Commit: | a629015 | |
|---|---|---|
| Author: | Michael Medin | |
* Started on NSCA unit-tests in python * Refactored channel API a bit to better suite NSCA (and how it actually works) * Changed how headers are created (nothice this might have broken NSCP stuff, havent checked) * Created helper lib for Python Unittests * Renamed NSCAAgent to NSCAClient (to be consistant) * Created a NSCAServer module (again for consistancy) This will be the defenition of the new "channels" so keep a lookout in the next few weeks
| Commit: | 2b2e9b8 | |
|---|---|---|
| Author: | Michael Medin | |
Another massive commit with a single comment, but essentially this is the first version with a proper distributed message queue this will be the foundation of some pretty cool stuff in the next few weeks/months... * Implemented first version of DistributedClient and DistributedSServer which work so now we have a proper message based transport. Still a lot of rough edges such as cookie and authentication support is hard coded. We also need a proper two way distributed server as well as implement "all" payload types.
| Commit: | 7515d00 | |
|---|---|---|
| Author: | Michael Medin | |
* Massive overhaul here and there * Added new helper for handling "targets" (so they are the same) * Extracted "command line handling" so all clients will work the same * Extracted command processor to a common class to make all clients work the same * Added initial zeromq stuff (nothing usable) * Added an implementation layer for NSCP protocol parsing (so zeromq stuff can reuse it)
| Commit: | 81e420c | |
|---|---|---|
| Author: | Michael Medin | |
* Added support for loading same plugin twice (in different sessions) * Added preliminary support for routing passive checks
| Commit: | b38e845 | |
|---|---|---|
| Author: | Michael Medin | |
* Sever refactoring of the new API (there is now two pb files ipc for NSCP protocol and plugin for plugin communication) * Cleaned up API helper functions
| Commit: | 438998b | |
|---|---|---|
| Author: | Michael Medin | |
Initial version of the NSCP protocol (very crude) also might not build on *nix as I haven't verified that yet... Will improve this this week and hopefully have something better in a bit... But this works so thought Id commit it anyways if I break something :)
| Commit: | 2c95d22 | |
|---|---|---|
| Author: | Michael Medin | |
2011-08-14 MickeM * Rename Function to Registry in PythonScript API as well as some other function renames * Started to clean up the helpers around the API * Added support for execute to PythonScripts to execute commands * BUG: just realised that static plugin instances prevent multiple instances :) Will fix but not now as it is not important (for me)... * Added initial support for channels to PythonScript Core still lacks support for subscribing to arbitrary channel
| Commit: | 39c73cd | |
|---|---|---|
| Author: | Michael Medin | |
2011-08-13 MickeM * Added support for command line execution to PythonScript module * Readded support for specifying module on command line with --client mode * Fixed some issues with the NRPEClient module 2011-08-12 MickeM * Finnished (rough) adding back command line exec (with modern API) * Fixed so installer uses correct name for dll:s (now Server not Listsener)
| Commit: | c391984 | |
|---|---|---|
| Author: | Michael Medin | |
0.4.x: * tweaks to the build environment to make the installer work * fixed Unicode issue * fixed performance data * improved so alias doesn't re-process the data so much
| Commit: | 58ee653 | |
|---|---|---|
| Author: | Michael Medin | |
| Commit: | 8988f9e | |
|---|---|---|
| Author: | Michael Medin | |
Added in performance e data for NRPE and NSCA as well as added in debug build for the protocol buffer library lookup thingy
| Commit: | 40970de | |
|---|---|---|
| Author: | Michael Medin | |
Preliminary NSCA support (much is hard coded right now so only a PoC not a finished concept)
| Commit: | 2018659 | |
|---|---|---|
| Author: | Michael Medin | |
Added protocol buffers for internal channels (only command as of now) this means this builds lacks "performance data" (as it has yet to be re-added) as well as requires changes to plugins as the API is NEW!