CI / test (3.10) (push) Successful in 27s
CI / test (3.11) (push) Successful in 27s
CI / test (3.12) (push) Successful in 37s
CI / test (3.10) (pull_request) Successful in 42s
CI / test (3.11) (pull_request) Successful in 42s
CI / test (3.12) (pull_request) Successful in 38s
get_listening_sockets() in the shape of napalm-device-types' ListeningSocketsMixin, whose ss/cgroup reading is Linux's, and with its rule: read as root first, and without root when that brings nothing back, which the reading reports as `attributed: False`. - FreeBSD: `sockstat -46lq -P tcp,udp`, which sees every socket either way. - OpenBSD: `fstat -n` as root (the sockets nothing is connected to; port 0 is unbound), `netstat -an` without root, as fstat shows a user only their own processes; those sockets come without a process. - Addresses as ss prints them: `*` becomes 0.0.0.0 or :: by family, IPv6 without brackets, a zone (`fe80::1%lo0`) becomes the interface. One entry per socket, the first process holding it. No get_kernel_facts on purpose: KernelFactsMixin reports a Linux kernel's modules and CONFIG_ options, which a BSD kernel does not have. Fixtures recorded on the FreeBSD 15.1 and OpenBSD 7.9 VMs with test listeners on 127.0.0.1 and ::1 (NetOrk/netork#798).
62 lines
2.8 KiB
Markdown
62 lines
2.8 KiB
Markdown
# napalm-bsd
|
|
|
|
NAPALM drivers for **FreeBSD** (`freebsd`) and **OpenBSD** (`openbsd`) hosts,
|
|
over SSH, built on [napalm-device-types](https://git.netork.io/NAPALM/napalm-device-types)'
|
|
`OSDriver`. Written for netOrk, which provisions and manages BSD VMs
|
|
(NetOrk/netork#792).
|
|
|
|
## Design
|
|
|
|
- One shared `BsdDriver` (`napalm_bsd/base.py`) holds the SSH layer and every
|
|
reader whose tools agree between the BSDs. `FreeBSDDriver` and
|
|
`OpenBSDDriver` name only the commands that differ (hostname, release,
|
|
kernel, hardware, `netstat -rnW` vs `-rn`).
|
|
- Every command runs on its own SSH **exec channel** (`run_on_transport` from
|
|
napalm-device-types): no PTY to parse a prompt from, stdout and stderr apart,
|
|
a real exit status. `run_command()` / `open_stream()` are public
|
|
(`CommandChannelMixin`).
|
|
- Root comes from `sudo -S` with the sudo password on stdin (never on a command
|
|
line), or `sudo -n` without one, as in napalm-linux. netOrk provisions `sudo`
|
|
on BSD VMs for that reason; `doas` cannot read a password from stdin.
|
|
- Parsing is in `napalm_bsd/parse.py`, pure functions tested on output recorded
|
|
from real systems (`tests/fixtures/`, each directory's `COMMANDS.txt` lists
|
|
what produced it).
|
|
|
|
## Supported getters
|
|
|
|
| Getter | FreeBSD | OpenBSD | Source |
|
|
|---|---|---|---|
|
|
| `get_facts` | ✓ | ✓ | `kern.hostname`/`hostname`, `freebsd-version`/`uname`, `kenv smbios.*`/`hw.*`, `kern.boottime` |
|
|
| `get_interfaces`, `get_interfaces_ip` | ✓ | ✓ | `ifconfig -a` |
|
|
| `get_route_to` | ✓ | ✓ | `netstat -rnW` / `netstat -rn` |
|
|
| `get_arp_table` | ✓ | ✓ | `arp -an` |
|
|
| `get_lldp_neighbors` | `{}` | `{}` | no LLDP daemon in either base system |
|
|
| `get_users`, `get_processes`, `get_cron_jobs` | ✓ | ✓ | `/etc/passwd`+`/etc/group`, `ps … lstart`, system crontab + `crontab -l` |
|
|
| `get_listening_sockets` | ✓ | ✓ | `sockstat -46lq` / `fstat -n` as root, `netstat -an` without |
|
|
|
|
`get_listening_sockets` has the shape of napalm-device-types'
|
|
`ListeningSocketsMixin` (whose `ss`/cgroup reading is Linux's) and its rule:
|
|
read as root first, without root when that brings nothing back
|
|
(`attributed: False`). FreeBSD's `sockstat` sees every socket either way;
|
|
OpenBSD's `fstat` shows a user only their own processes, so without root the
|
|
sockets come from `netstat -an`, unnamed.
|
|
|
|
There is deliberately no `get_kernel_facts`: `KernelFactsMixin` reports a
|
|
Linux kernel's modules and `CONFIG_*` options, which a BSD kernel does not
|
|
have, and `hasattr(driver, "get_kernel_facts")` has to stay truthful.
|
|
|
|
Packages, services, updates (#799) and SNMP (#800) follow.
|
|
|
|
## Connection arguments
|
|
|
|
`optional_args`: `port` (22), `key_file`, `sudo_password`, `allow_agent`,
|
|
`look_for_keys` (both off by default).
|
|
|
|
## Development
|
|
|
|
```bash
|
|
pip install "napalm-device-types @ git+https://git.netork.io/NAPALM/napalm-device-types.git"
|
|
pip install -e ".[dev]"
|
|
pytest
|
|
```
|