#!/usr/bin/env bash # netvm-topology.sh — live topology + per-node diagnostics. # Run as root (operator: sudo -n via the allowlist). set -u SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)" . "$SCRIPT_DIR/netvm-names.sh" for ns in $(ip netns list 2>/dev/null | awk '{print $1}' | grep '^warp-'); do netvm_names "${ns#warp-}" hs=$(ip netns exec "$ns" wg show "$WG" latest-handshakes 2>/dev/null | awk '{print $2}') [ -z "$hs" ] && hs="none" egress=$(ip netns exec "$ns" curl -sk --max-time 10 'https://1.1.1.1/cdn-cgi/trace' 2>/dev/null | grep -oP '^ip=\K.*' || true) printf 'node=%s netns=%s ifaces=%s/%s handshake=%s egress=%s\n' "$NODE" "$ns" "$WG" "$VETH" "$hs" "${egress:-?}" done iptables -t nat -L POSTROUTING -n 2>/dev/null | grep '10.201\.' || echo "(no netvm NAT rules on host)" echo "--- CDP relays (connectivity check; pidfile is secondary) ---" for ns in $(ip netns list 2>/dev/null | awk '{print $1}' | grep '^warp-'); do netvm_names "${ns#warp-}" # Registry-pinned CDP ports (same mapping as netvm-names.sh). # NOTE: keep this case in sync with the pinned mapping — the "*" fallback # trusts $CDP_PORT from netvm_names(), which is pinned for registry nodes # and hash-derived otherwise. case "$NODE" in muse) port=9410 ;; pip) port=9420 ;; 646) port=9430 ;; opm) port=9440 ;; def) port=9450 ;; dev) port=9455 ;; *) port="$CDP_PORT" ;; esac target="$PEER_IP:$port" pidfile="/run/netvm-${NODE}-cdp-relay.pid" # PRIMARY verdict: actual connectivity to the relay on the veth IP. # pidfiles go stale (dead/recycled PIDs) and lied about status — 2026-10-04. if curl -s -m 5 "http://$target/json/version" 2>/dev/null | grep -q '"Browser"'; then echo "$NODE: relay UP ($target -> 127.0.0.1:$port)" elif [ -f "$pidfile" ] && kill -0 "$(cat "$pidfile" 2>/dev/null)" 2>/dev/null; then echo "$NODE: relay DOWN on $target (process alive per pidfile but not responding — stale/misrouted?)" else echo "$NODE: relay DOWN on $target (no relay process; pidfile missing or stale)" fi done