Whether a service is reachable from outside its host is decided by the
address it listens on: 0.0.0.0:5432 is, 127.0.0.1:5432 is not. Reading
that is the same on every Linux host, so the command and its parse live
here once and a driver only carries the command across
(ListeningSocketsMixin, _run_listening_sockets_command).
One framed round trip: ss -lntup for every listening TCP and bound UDP
socket, then /proc/<pid>/cgroup for each process holding one, which names
the systemd service (v2, nested slices, v1's name=systemd hierarchy) or
the container (docker-<id>.scope, /docker/<id>) it runs in.
- Root: only root sees every process. The script goes as one sh -c
argument, so a sudo -n prefix covers all of it; when that brings no
report back the reading runs again unprivileged and says it is not
attributed.
- No -H: iproute2 before 4.10 fails on it, which would read as nothing
listening. The header is skipped instead.
- A host without ss raises ListeningSocketsUnavailable; a report cut short
or a failing ss raises ValueError.
- The reading is raw: docker-proxy shows up as docker.service, loopback as
loopback. What counts as reachable is the consumer's call.
2.4.0. For netOrk#658.