Commit Graph
150 Commits
Author SHA1 Message Date
Nicolas Hennion 348af34386 Merge pull request #3646 from Dipet/fix/connections-terminated-states
fix: count terminated connection states instead of counting initiated twice
2026-08-06 09:28:31 +02:00
dipetm 4181b2574f fix: keep zero-valued fields when aggregating processes into programs 2026-08-05 16:44:15 +03:00
dipetm 60e365150e fix: count terminated connection states instead of counting initiated twice 2026-08-05 15:59:15 +03:00
dipetm 82258e3ab6 perf: make remove_non_running_procs O(n) instead of O(n^2) 2026-08-05 13:37:30 +03:00
art22s 44f2ea7219 Fix: guard cursor navigation in client/server mode (see #3221) 2026-08-04 21:13:20 -04:00
Nicolas Hennion d8efdac9bf Merge pull request #3639 from yogendrarau/fix/processcount-pid-max-3637
processcount pid_max always 0, and status comparison uses `is` instead of `==` #3637
2026-08-04 09:28:15 +02:00
yogendrarau ec157a9c30 processcount pid_max always 0, and status comparison uses is instead of == #3637
The status counting loop iterated over every key of the processcount dict, so
'pid_max' was assigned the number of processes whose status is 'pid_max', ie 0.
It was set to the system value on the line above, and 'total' and 'thread' are
recomputed after the loop, so pid_max was the only casualty: /api/4/processcount
reported 0 while /proc/sys/kernel/pid_max was 4194304.

The status was also matched with 'is', which compares identity. It only worked
by accident, because CPython interns identifier-like literals such as 'running'
and 'sleeping'. Any status that is not interned, or not an identifier such as
'disk-sleep', would never match its key.

Count the two status keys only, and compare with '=='. pid_max now keeps the
value read from the system, and stays None when it can not be read (non Linux),
as documented by the property and as initialised by reset_processcount().
2026-08-03 19:50:08 -04:00
nicolargo 613f09ca7f Correct issue on TU and upgrade lib dep 2026-08-01 10:53:33 +02:00
nicolargo 8d0f8276c2 as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config - Correct CVE-2026-68520 2026-08-01 10:19:50 +02:00
Nicolas Hennion 3392c538ad Merge pull request #3626 from Sanjays2402/fix/timescaledb-list-plugin-key-column-mismatch
fix(exports): correct column/value mismatch for list plugins in TimescaleDB
2026-08-01 09:09:24 +02:00
Sanjay Santhanam 2bc099d820 fix(ports): resolve alert level by severity instead of dict ordering
get_default_ret_value() collapsed every matching condition into a single
'ret' key, so the level that won was whichever condition was evaluated
last rather than the most severe one. A URL that was both failing and
slow was reported as WARNING instead of CRITICAL, and a URL whose first
scan had not completed matched both CAREFUL and CRITICAL and was shown
as CRITICAL (which could also fire ports_critical_action).

Resolve by severity (CRITICAL > WARNING > CAREFUL > OK) and stop a None
status from matching the CRITICAL condition for web checks.

Adds tests/test_plugin_ports.py covering the severity ordering and the
four web scan outcomes.

Closes #3632
2026-07-30 11:16:23 -07:00
yogendrarauandClaude Opus 4.8 85635c1d51 Sensors thresholds set in the configuration file are ignored when no critical level is defined #3627
The dispatch selecting the thresholds only probed the critical level, so a
configuration defining careful and/or warning without critical was silently
discarded and the system thresholds were used instead. This affected both the
per sensor (#2058) and the per type (#3049) forms.

AMD k10temp reports no high/critical for Tctl on many boards, so the fallback
returned DEFAULT and the temperature was never highlighted, whatever the user
configured.

Check every criticality level instead, so the documented precedence (specific
sensor, then sensor type, then system) applies as soon as one threshold is set.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-27 18:53:39 -04:00
Sanjay Santhanam 4173c62033 fix(exports): correct column/value mismatch for list plugins in TimescaleDB
The list-plugin branch of the TimescaleDB exporter counted the 'key' field
once as a column but twice in the values: it was appended manually as key_id
and again through the plugin item values(). The item_list[:-1] slice tried to
compensate but dropped the last stat field instead of 'key', and still left
the count off by one, so an N-field plugin produced 3 + N columns for 2 + N
values.

Exporting the network plugin therefore failed with "the query has 25
placeholders but 24 parameters were passed" and no data was inserted.

The 'key' field is now excluded from both the column generation and the value
extend (it is already stored as key_id) and the slice is removed, so column
and value counts match and no stat field is lost.

Adds tests/test_export_timescaledb_list.py covering the column/value count,
the single key_id column, and the previously dropped trailing field.

Closes #3592
2026-07-25 02:51:58 -07:00
Martin ĎuranaandClaude Sonnet 5 3f3210d0fb Fix get_ip_address() returning the last interface instead of the first
The outer loop over network interfaces had no break, so ip_address was
overwritten by every subsequent up/non-loopback interface with a
matching address family. On hosts with Docker, this meant the bridge
IP (e.g. 172.18.0.1) was returned instead of the actual LAN address,
because virtual interfaces can sort after the real one in dict order.

Add a break once a match is found so the function returns the first
qualifying interface, plus regression tests covering the Docker case,
loopback/down-interface skipping, and the no-match case.

Fixes #3617

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015NJfi2d6yvmmDzvPmm4eof
2026-07-24 17:33:06 +02:00
nicolargo 11d66bc6e8 Lint the code 2026-07-18 09:29:06 +02:00
Nicolas Hennion a0bf70bddc Merge pull request #3609 from yogendrarau/fix/csv-network-desync-3606
Fix CSV export column desync when list-plugin items change at runtime…
2026-07-18 09:24:46 +02:00
nicolargo 3c016eb215 VideoCore (v3d) memory shows ~93% on Raspberry Pi 5 with gpu_mem=4M — misleading denominator from drm-total-memory #3611 2026-07-14 09:59:20 +02:00
yogendrarau af6a48695f Wrap long test lines (#3606)
Signed-off-by: yogendrarau <yogendra.rautela7@gmail.com>
2026-07-09 17:10:03 -04:00
yogendrarau 3500044454 Align CSV blocks by header field names to handle variable interface field counts (#3606)
Signed-off-by: yogendrarau <yogendra.rautela7@gmail.com>
2026-07-09 17:04:36 -04:00
yogendrarau 0dd4b1b94b Fix CSV export column desync when list-plugin items change at runtime (#3606)
Signed-off-by: yogendrarau <yogendra.rautela7@gmail.com>
2026-07-09 12:48:56 -04:00
nicolargo 9c280eae54 Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction 2026-07-05 09:46:55 +02:00
nicolargo 5c260ace31 Merge branch 'develop' of github.com:nicolargo/glances into develop 2026-07-04 17:26:50 +02:00
nicolargo 890858944a REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard 2026-07-04 17:26:38 +02:00
Nicolas Hennion d02c730c9c Merge pull request #3579 from lphuc2250gma/maint/20260606064548
chore: improve glances maintenance path
2026-07-04 17:01:24 +02:00
nicolargo 5c07c0d964 Advisory draft — does not cover on-alert action commands (incomplete fix of GHSA-3vwc-qwhc-3mj7 / CVE-2026-53925) 2026-07-04 15:49:52 +02:00
nicolargo ea4cf2f54f Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection 2026-06-28 22:29:01 +02:00
Gabriel St. AngelandClaude Opus 4.8 3107c6ac51 feat(gpu): support NVIDIA Jetson (Tegra) integrated GPU via sysfs fallback
On Jetson (Tegra) the integrated GPU is enumerated by NVML
(nvidia-l4t-nvml) and reports its name (e.g. "Orin (nvgpu)"), but the
per-metric NVML queries return NVML_ERROR_NOT_SUPPORTED, so the GPU
plugin only ever showed N/A for proc/mem/temperature.

Add a Tegra sysfs backend (glances/plugins/gpu/cards/tegra.py) and wire
it into the NVIDIA card as a per-metric fallback: when NVML returns None
for a device detected as Tegra (name contains "nvgpu", or the Tegra GPU
sysfs node exists), read:

- proc:        /sys/devices/platform/gpu.0/load  (per-mille -> percent)
- temperature: the gpu-thermal /sys/class/thermal zone (milli-C -> C)

Memory stays N/A by design: the Tegra GPU shares system RAM, already
reported by the MEM plugin. Scales verified against tegrastats
(GR3D_FREQ and gpu@).

Adds unit tests with committed sysfs fixtures, a NEWS.rst entry and a
docs note.

Verified on JetPack 6.2.1 (L4T R36.4.7) and JetPack 7.2 (L4T R39.2):
identical sysfs node layout and gpu-thermal zone selection on both, with
temperature cross-checked against tegrastats on each.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-07 06:59:59 +00:00
Noa Levi 528aea6cd6 chore: improve glances maintenance path 2026-06-06 06:46:24 +00:00
nicolargo 813a4ec99b Arbitrary file write and command execution via redirection and chaining operators in AMP command configuration - GHSA-3vwc-qwhc-3mj7 - CVE-id-tbd 2026-06-06 08:24:14 +02:00
nicolargo e68e9f4452 Add unit test to containers/docker plugin 2026-05-31 17:34:25 +02:00
nicolargo 2afc533d67 Merge branch 'Issue-3555_load_additional_plugins' of github.com:20086080/glances into 20086080-Issue-3555_load_additional_plugins 2026-05-23 15:48:42 +02:00
nicolargo ff3eec3295 Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py - CVE-2026-46606 2026-05-23 12:27:19 +02:00
nicolargo cf14166fbe test(outdated): json round-trip and graceful migration from legacy pickle cache
Cover the non-RCE behaviour of the new JSON cache:
- round-trip: written file is valid JSON, re-read produces equivalent dict
- legacy pickle: a pre-fix pickle cache is treated as a cache miss, not
  a crash (upgrade path)
- expiry: caches older than 7 days are invalidated
- version skew: caches written by a different installed version are
  invalidated
- first run: a missing file is not an error
2026-05-23 11:52:53 +02:00
nicolargo 7098478c39 test(outdated): failing test — malicious pickle cache must not execute (CVE-2026-46607)
Regression test for GHSA-9837-48hr-q32j: glances/outdated.py reads its
version-check cache file via pickle.load(), a deserialization format
that executes arbitrary callables embedded via __reduce__.

The test plants a poisoned pickle at the cache path and asserts that
_load_cache() does NOT trigger the embedded callable. Against the
current (vulnerable) code this fails because the payload fires before
the TypeError is raised on the unrelated dict subscript.

The fix in the next commit replaces pickle with json, which is a passive
data format.
2026-05-23 11:50:55 +02:00
nicolargo 0de3b8f875 XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard - CVE-2026-46608 2026-05-23 11:40:20 +02:00
nicolargoandClaude Opus 4.7 cad6f985a5 test(xmlrpc): port stripping and missing-Host edge cases
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-23 09:53:06 +02:00
nicolargoandClaude Opus 4.7 8e6c9c955c test(xmlrpc): wildcard Host patterns via fnmatch
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-23 09:52:30 +02:00
nicolargoandClaude Opus 4.7 575dc7e81b test(xmlrpc): allowlisted Host returns 200
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-23 09:51:58 +02:00
nicolargoandClaude Opus 4.7 b88dd7bcfd test(xmlrpc): failing test — spoofed Host should be rejected (CVE-2026-46611)
Adds a second test server bound to a config that enables xmlrpc_allowed_hosts,
plus the failing assertion that a spoofed Host header returns 400. The fix in
glances/server.py follows in the next commit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-23 09:50:40 +02:00
nicolargoandClaude Opus 4.7 b2965cca96 test(xmlrpc): lock in current permissive default (regression baseline)
This test passes on the unpatched server and proves the CVE-2026-46611
vulnerability exists today: a spoofed Host header is accepted.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-23 09:49:43 +02:00
nicolargoandClaude Opus 4.7 01437d61e2 test(xmlrpc): scaffold for Host header validation tests
Re-creates tests/test_xmlrpc.py (deleted symlink) with a pytest module
modelled on test_restful.py: subprocess-launched server and a helper
to POST XML-RPC calls with a controllable Host header. Restores the
existing 'make test-xmlrpc' Makefile target.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-23 09:48:47 +02:00
20086080 bcc18b4ab3 Fix : Codacy 2026-05-21 03:06:41 +00:00
20086080 389b6d45bb Fix : Codacy 2026-05-21 02:57:23 +00:00
20086080 c3a8fb2f05 Test : Unit tests 2026-05-21 02:22:17 +00:00
Nicolas Hennion 7e118d5946 Merge pull request #3557 from DeepSpace2/feat-containers-cpu-limits
feat: add cpu limit to docker, podman and lxd containers
2026-05-17 11:24:50 +02:00
Yan b42defb1d8 Keep auto_unit within limits, so columns stay aligned
Occasionally, columns got misaligned, because auto_unit returned too
many decimals when the number was slightly below 10 or 100.
Actually, when (9.995 <= n < 10) and (99.95 < n < 100).

For example,
10*2**20-1 returned 10.00M instead of 10.0M and
100*2**20-1 returned 100.0M instead of 100M.

Tests added to verify correctness.
2026-05-16 21:45:09 +00:00
Adi b4b2118933 feat: add cpu limit to docker, podman and lxd containers 2026-05-15 17:32:25 +03:00
20086080 7407f35661 Fix : Codacy Issues 2026-05-07 12:59:37 +00:00
20086080 31f07cd6c9 Fix : Codacy Issues 2026-05-07 12:54:47 +00:00
20086080 d529cf2d59 Fix : Codacy Issues 2026-05-07 12:49:09 +00:00