feat: say where a pending update comes from, whether it is a security fix, and whether the host needs a reboot

netOrk MVP 5 measures "security updates applied within N days" and starts
patch runs inside agreed windows. That needs three things every Linux driver
reads the same way, so they live here once:

- UpdateDict gains optional `origin` and `security` (None = unknown).
- package_updates: APT_UPGRADABLE_COMMAND and parse_apt_upgradable(). apt's
  suites are the origin; a "-security" suite makes it a security update;
  several architectures of one package are one entry. The command runs
  through a pipe with its exit status printed inside the group: through a
  pseudo-terminal apt drew progress and keypad codes, one of which (ESC >)
  a screen-scraping read took for a prompt and stopped at. The parser raises
  ValueError when apt failed or its status never arrived.
  DNF_SECURITY_COMMAND / parse_dnf_security() / nevra_name() for dnf/yum.
- host_status: HOST_STATUS_COMMAND, parse_host_status(), HostStatusMixin
  (template form, hook _run_host_status_command). reboot_required from
  /var/run/reboot-required, needs-restarting -r, or a newer kernel of the
  running flavour (a Raspberry Pi carries two flavours side by side);
  auto_updates from APT::Periodic::Unattended-Upgrade with its timer, or
  dnf-automatic. HostStatusDict in models.py.
- terminal.strip_terminal_codes(): CSI, OSC and two-character escapes, now
  also used by the systemd parser.
- UpdateMixin: contract refresh_available_updates(); get_available_updates'
  docstring now states the rule that a reader raises when it cannot read and
  never returns [] for "don't know".

Fixtures are real output from Ubuntu 24.04, Debian 13 / OMV, Raspberry Pi OS
and Proxmox VE 9. Version 2.3.0.
This commit is contained in:
2026-10-06 00:19:24 +02:00
parent 4071f35050
commit 18676a573f
11 changed files with 731 additions and 8 deletions
+200
View File
@@ -0,0 +1,200 @@
"""Host status: does the host need a reboot, and does it patch itself?
A patch run that installed a new kernel has not closed anything until the host
boots it, so "reboot required" is part of being patched. Whether the host
installs updates on its own (unattended-upgrades, dnf-automatic) is what netOrk
shows next to the window it governs. Both are read the same way on every Linux
host, so the command and its parse live here once (netOrk MVP 5).
The fixtures are the real states of six hosts on netOrk's test server.
"""
from __future__ import annotations
import pytest
from napalm_device_types import OSDriver
from napalm_device_types.host_status import (
HOST_STATUS_COMMAND,
HostStatusMixin,
kernel_reboot_pending,
parse_host_status,
)
def _wire(
*,
reboot_file=False,
running="6.8.0-142-generic",
modules=("6.8.0-139-generic", "6.8.0-142-generic"),
needs_restarting=None,
periodic=None,
timer="enabled",
dnf_timers=("not-found", "not-found"),
):
lines = ["HSTAT_BEGIN"]
if reboot_file:
lines.append("[reboot-required]")
if needs_restarting is not None:
lines += ["[needs-restarting]", str(needs_restarting)]
lines += ["[kernel]", running, "[modules]", *modules]
if periodic is not None:
lines += ["[apt-config]", *periodic]
lines += [
"[timers]",
f"apt-daily-upgrade.timer {timer}",
f"dnf-automatic.timer {dnf_timers[0]}",
f"dnf-automatic-install.timer {dnf_timers[1]}",
"HSTAT_END",
]
return "\n".join(lines) + "\n"
UNATTENDED = ['APT::Periodic::Update-Package-Lists "1";', 'APT::Periodic::Unattended-Upgrade "1";']
class TestRebootRequired:
def test_the_reboot_required_file_says_so(self):
status = parse_host_status(_wire(reboot_file=True))
assert status["reboot_required"] is True
assert "reboot-required" in status["reboot_reason"]
def test_a_newer_installed_kernel_than_the_running_one(self):
"""z2m-garden: running 6.8.0-139, 6.8.0-142 installed."""
status = parse_host_status(
_wire(
running="6.8.0-139-generic",
modules=("6.8.0-87-generic", "6.8.0-139-generic", "6.8.0-142-generic"),
)
)
assert status["reboot_required"] is True
assert "6.8.0-142-generic" in status["reboot_reason"]
def test_the_newest_kernel_running_needs_none(self):
"""vault-01: 6.8.0-142 running and newest; 6.8.0-94 sorts below it."""
status = parse_host_status(
_wire(running="6.8.0-142-generic", modules=("6.8.0-94-generic", "6.8.0-142-generic"))
)
assert status["reboot_required"] is False
assert status["reboot_reason"] is None
def test_needs_restarting_exit_1_means_reboot(self):
assert parse_host_status(_wire(needs_restarting=1))["reboot_required"] is True
def test_needs_restarting_exit_0_does_not(self):
assert parse_host_status(_wire(needs_restarting=0))["reboot_required"] is False
def test_no_kernel_information_is_unknown(self):
"""A container has no /lib/modules of its own."""
status = parse_host_status(_wire(modules=()))
assert status["reboot_required"] is None
class TestKernelRebootPending:
@pytest.mark.parametrize(
("running", "installed", "newer"),
[
# Raspberry Pi: two flavours side by side; only the running one counts.
(
"6.18.33+rpt-rpi-v8",
[
"6.12.75+rpt-rpi-2712",
"6.12.75+rpt-rpi-v8",
"6.18.33+rpt-rpi-2712",
"6.18.33+rpt-rpi-v8",
],
None,
),
# Debian (OMV): 7.1.8 installed while 7.1.3 runs.
(
"7.1.3+deb13-amd64",
["6.12.57+deb13-amd64", "7.1.3+deb13-amd64", "7.1.8+deb13-amd64"],
"7.1.8+deb13-amd64",
),
# Proxmox: 7.0.14-19 is newer than 7.0.2-6, numerically.
("7.0.14-19-pve", ["7.0.14-19-pve", "7.0.2-6-pve"], None),
# Arch: the running kernel's modules were replaced by the upgrade.
("6.10.5-arch1-1", ["6.10.9-arch1-1"], "6.10.9-arch1-1"),
],
)
def test_the_newer_kernel_of_the_running_flavour(self, running, installed, newer):
assert kernel_reboot_pending(running, installed) == newer
class TestAutoUpdates:
def test_unattended_upgrades_switched_on(self):
assert parse_host_status(_wire(periodic=UNATTENDED))["auto_updates"] is True
def test_apt_without_the_setting_does_not_patch_itself(self):
"""Proxmox and Raspberry Pi OS: apt-config answers, the setting is absent."""
assert parse_host_status(_wire(periodic=[]))["auto_updates"] is False
def test_switched_off_by_zero(self):
off = ['APT::Periodic::Unattended-Upgrade "0";']
assert parse_host_status(_wire(periodic=off))["auto_updates"] is False
def test_a_disabled_timer_stops_it_even_when_configured(self):
status = parse_host_status(_wire(periodic=UNATTENDED, timer="disabled"))
assert status["auto_updates"] is False
def test_dnf_automatic(self):
status = parse_host_status(_wire(dnf_timers=("enabled", "not-found")))
assert status["auto_updates"] is True
def test_neither_apt_nor_dnf_is_unknown(self):
assert parse_host_status(_wire())["auto_updates"] is None
class TestTheReport:
def test_a_cut_short_report_raises(self):
with pytest.raises(ValueError):
parse_host_status(_wire().replace("HSTAT_END\n", ""))
def test_the_frame_is_not_in_the_command_itself(self):
assert "HSTAT_BEGIN" not in HOST_STATUS_COMMAND
assert "HSTAT_END" not in HOST_STATUS_COMMAND
def test_it_runs_without_a_terminal(self):
"""No colour codes from ls, nothing a screen scraper could take for a prompt."""
assert HOST_STATUS_COMMAND.rstrip().endswith("| cat")
def test_terminal_codes_are_dropped(self):
status = parse_host_status(
"\x1b[0m" + _wire(reboot_file=True).replace("HSTAT_END", "\x1b>HSTAT_END")
)
assert status["reboot_required"] is True
def test_it_changes_nothing(self):
for word in ("rm ", "apt-get ", "dnf install", "systemctl start", "reboot"):
assert word not in HOST_STATUS_COMMAND.replace("reboot-required", "")
class _Driver(HostStatusMixin):
def __init__(self, reply: str) -> None:
self.reply = reply
self.commands: list = []
def _run_host_status_command(self, command: str) -> str:
self.commands.append(command)
return self.reply
class TestHostStatusMixin:
def test_a_driver_supplies_only_the_transport(self):
driver = _Driver(_wire(reboot_file=True, periodic=UNATTENDED))
status = driver.get_host_status()
assert driver.commands == [HOST_STATUS_COMMAND]
assert (status["reboot_required"], status["auto_updates"]) == (True, True)
def test_not_every_os_driver_has_it(self):
assert not hasattr(OSDriver, "get_host_status")
+149
View File
@@ -0,0 +1,149 @@
"""Pending updates: which package, from where, and whether it closes a security hole.
A patch deadline ("security updates within 14 days") needs to know which pending
update is a security update. apt says so in the suite a candidate comes from
(``noble-security``, ``stable-security``); dnf says so in its update advisories.
Reading that is the same for every driver whose host runs apt or dnf, so the
parsers live here once (netOrk MVP 5, #556).
Fixture lines are from real hosts (Ubuntu 24.04, Debian 13 / OMV, Proxmox VE 9).
"""
from __future__ import annotations
import pytest
from napalm_device_types.package_updates import (
APT_UPGRADABLE_COMMAND,
nevra_name,
parse_apt_upgradable,
parse_dnf_security,
)
UBUNTU = """\
docker-compose-plugin/noble 5.6.0-1~ubuntu.24.04~noble amd64 [upgradable from: 5.5.1-1~ubuntu.24.04~noble]
openssl/noble-updates,noble-security 3.0.13-0ubuntu3.6 amd64 [upgradable from: 3.0.13-0ubuntu3.5]
__APT_RC=0
"""
DEBIAN = """\
linux-image-amd64/stable-backports 7.1.13-1~bpo13+1 amd64 [upgradable from: 7.1.8-1~bpo13+1]
libssl3t64/stable-security 3.5.1-1+deb13u2 amd64 [upgradable from: 3.5.1-1+deb13u1]
__APT_RC=0
"""
def _by_name(updates):
return {u["name"]: u for u in updates}
class TestAptUpgradable:
def test_each_line_is_a_package_with_both_versions(self):
update = _by_name(parse_apt_upgradable(UBUNTU))["docker-compose-plugin"]
assert update["current_version"] == "5.5.1-1~ubuntu.24.04~noble"
assert update["new_version"] == "5.6.0-1~ubuntu.24.04~noble"
def test_the_suites_are_its_origin(self):
updates = _by_name(parse_apt_upgradable(UBUNTU))
assert updates["openssl"]["origin"] == "noble-updates,noble-security"
assert updates["docker-compose-plugin"]["origin"] == "noble"
def test_a_suite_apt_lists_twice_is_named_once(self):
line = (
"fonts-opensymbol/noble-updates,noble-updates,noble-security,noble-security "
"4:102.12+LibO24.2.7-0ubuntu0.24.04.7 all [upgradable from: 4:102.12+LibO24.2.7-0ubuntu0.24.04.6]\n"
"__APT_RC=0\n"
)
assert parse_apt_upgradable(line)[0]["origin"] == "noble-updates,noble-security"
@pytest.mark.parametrize(
("output", "name", "security"),
[
(UBUNTU, "openssl", True),
(UBUNTU, "docker-compose-plugin", False),
(DEBIAN, "libssl3t64", True),
(DEBIAN, "linux-image-amd64", False),
],
)
def test_a_security_suite_makes_it_a_security_update(self, output, name, security):
assert _by_name(parse_apt_upgradable(output))[name]["security"] is security
def test_a_line_the_terminal_wrapped_is_joined(self):
wrapped = (
"openssl/noble-updates,noble-security 3.0.13-0ubuntu3.6 amd64 [upgradable fro\n"
" m: 3.0.13-0ubuntu3.5]\n__APT_RC=0\n"
)
assert _by_name(parse_apt_upgradable(wrapped))["openssl"]["current_version"] == (
"3.0.13-0ubuntu3.5"
)
def test_one_package_for_several_architectures_is_one_entry(self):
multiarch = (
"libc6/noble-updates 2.39-0ubuntu8.5 amd64 [upgradable from: 2.39-0ubuntu8.4]\n"
"libc6/noble-updates,noble-security 2.39-0ubuntu8.5 i386 [upgradable from: 2.39-0ubuntu8.4]\n"
"__APT_RC=0\n"
)
updates = parse_apt_upgradable(multiarch)
assert [u["name"] for u in updates] == ["libc6"]
assert updates[0]["security"] is True
def test_noise_is_ignored(self):
noisy = "Listing... Done\nWARNING: apt does not have a stable CLI interface.\n" + UBUNTU
assert len(parse_apt_upgradable(noisy)) == 2
def test_nothing_pending_is_an_empty_list(self):
assert parse_apt_upgradable("__APT_RC=0\n") == []
def test_a_list_without_its_exit_status_raises(self):
"""Cut short: a transport stopped reading early, so nothing can be concluded."""
with pytest.raises(ValueError):
parse_apt_upgradable(UBUNTU.replace("__APT_RC=0\n", ""))
def test_a_failed_apt_raises(self):
with pytest.raises(ValueError, match="100"):
parse_apt_upgradable("E: Could not get lock\n__APT_RC=100\n")
def test_terminal_codes_around_the_status_are_dropped(self):
"""What a pseudo-terminal left on a Raspberry Pi OS host."""
raw = "Listing... 0%\n\x1b[?1h\x1b=\n" + UBUNTU.replace("__APT_RC=0", "\x1b>__APT_RC=0")
assert len(parse_apt_upgradable(raw)) == 2
def test_the_command_reads_without_root_or_a_terminal(self):
"""Through a pipe apt draws no progress and no terminal codes; one of
those, ESC >, ended a screen-scraping read at a false prompt."""
assert "LC_ALL=C apt list --upgradable" in APT_UPGRADABLE_COMMAND
assert APT_UPGRADABLE_COMMAND.rstrip().endswith("| cat")
assert "sudo" not in APT_UPGRADABLE_COMMAND
class TestDnfSecurity:
ADVISORIES = """\
FEDORA-2024-1a2b3c4d5e Important/Sec. openssl-libs-1:3.1.4-2.fc40.x86_64
FEDORA-2024-1a2b3c4d5e Important/Sec. openssl-1:3.1.4-2.fc40.x86_64
RLSA-2024:1234 Moderate/Sec. kernel-core-5.14.0-427.13.1.el9_4.x86_64
"""
def test_the_names_of_packages_with_a_security_advisory(self):
assert parse_dnf_security(self.ADVISORIES) == {"openssl-libs", "openssl", "kernel-core"}
def test_nothing_is_an_empty_set(self):
assert parse_dnf_security("") == set()
@pytest.mark.parametrize(
("nevra", "name"),
[
("openssl-libs-1:3.1.4-2.fc40.x86_64", "openssl-libs"),
("kernel-core-5.14.0-427.13.1.el9_4.x86_64", "kernel-core"),
("python3-dnf-4.14.0-9.el9.noarch", "python3-dnf"),
],
)
def test_the_name_of_a_nevra(self, nevra, name):
assert nevra_name(nevra) == name