feat: say where a pending update comes from, whether it is a security fix, and whether the host needs a reboot
netOrk MVP 5 measures "security updates applied within N days" and starts patch runs inside agreed windows. That needs three things every Linux driver reads the same way, so they live here once: - UpdateDict gains optional `origin` and `security` (None = unknown). - package_updates: APT_UPGRADABLE_COMMAND and parse_apt_upgradable(). apt's suites are the origin; a "-security" suite makes it a security update; several architectures of one package are one entry. The command runs through a pipe with its exit status printed inside the group: through a pseudo-terminal apt drew progress and keypad codes, one of which (ESC >) a screen-scraping read took for a prompt and stopped at. The parser raises ValueError when apt failed or its status never arrived. DNF_SECURITY_COMMAND / parse_dnf_security() / nevra_name() for dnf/yum. - host_status: HOST_STATUS_COMMAND, parse_host_status(), HostStatusMixin (template form, hook _run_host_status_command). reboot_required from /var/run/reboot-required, needs-restarting -r, or a newer kernel of the running flavour (a Raspberry Pi carries two flavours side by side); auto_updates from APT::Periodic::Unattended-Upgrade with its timer, or dnf-automatic. HostStatusDict in models.py. - terminal.strip_terminal_codes(): CSI, OSC and two-character escapes, now also used by the systemd parser. - UpdateMixin: contract refresh_available_updates(); get_available_updates' docstring now states the rule that a reader raises when it cannot read and never returns [] for "don't know". Fixtures are real output from Ubuntu 24.04, Debian 13 / OMV, Raspberry Pi OS and Proxmox VE 9. Version 2.3.0.
This commit is contained in:
@@ -0,0 +1,200 @@
|
||||
"""Host status: does the host need a reboot, and does it patch itself?
|
||||
|
||||
A patch run that installed a new kernel has not closed anything until the host
|
||||
boots it, so "reboot required" is part of being patched. Whether the host
|
||||
installs updates on its own (unattended-upgrades, dnf-automatic) is what netOrk
|
||||
shows next to the window it governs. Both are read the same way on every Linux
|
||||
host, so the command and its parse live here once (netOrk MVP 5).
|
||||
|
||||
The fixtures are the real states of six hosts on netOrk's test server.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import pytest
|
||||
|
||||
from napalm_device_types import OSDriver
|
||||
from napalm_device_types.host_status import (
|
||||
HOST_STATUS_COMMAND,
|
||||
HostStatusMixin,
|
||||
kernel_reboot_pending,
|
||||
parse_host_status,
|
||||
)
|
||||
|
||||
|
||||
def _wire(
|
||||
*,
|
||||
reboot_file=False,
|
||||
running="6.8.0-142-generic",
|
||||
modules=("6.8.0-139-generic", "6.8.0-142-generic"),
|
||||
needs_restarting=None,
|
||||
periodic=None,
|
||||
timer="enabled",
|
||||
dnf_timers=("not-found", "not-found"),
|
||||
):
|
||||
lines = ["HSTAT_BEGIN"]
|
||||
if reboot_file:
|
||||
lines.append("[reboot-required]")
|
||||
if needs_restarting is not None:
|
||||
lines += ["[needs-restarting]", str(needs_restarting)]
|
||||
lines += ["[kernel]", running, "[modules]", *modules]
|
||||
if periodic is not None:
|
||||
lines += ["[apt-config]", *periodic]
|
||||
lines += [
|
||||
"[timers]",
|
||||
f"apt-daily-upgrade.timer {timer}",
|
||||
f"dnf-automatic.timer {dnf_timers[0]}",
|
||||
f"dnf-automatic-install.timer {dnf_timers[1]}",
|
||||
"HSTAT_END",
|
||||
]
|
||||
return "\n".join(lines) + "\n"
|
||||
|
||||
|
||||
UNATTENDED = ['APT::Periodic::Update-Package-Lists "1";', 'APT::Periodic::Unattended-Upgrade "1";']
|
||||
|
||||
|
||||
class TestRebootRequired:
|
||||
def test_the_reboot_required_file_says_so(self):
|
||||
status = parse_host_status(_wire(reboot_file=True))
|
||||
|
||||
assert status["reboot_required"] is True
|
||||
assert "reboot-required" in status["reboot_reason"]
|
||||
|
||||
def test_a_newer_installed_kernel_than_the_running_one(self):
|
||||
"""z2m-garden: running 6.8.0-139, 6.8.0-142 installed."""
|
||||
status = parse_host_status(
|
||||
_wire(
|
||||
running="6.8.0-139-generic",
|
||||
modules=("6.8.0-87-generic", "6.8.0-139-generic", "6.8.0-142-generic"),
|
||||
)
|
||||
)
|
||||
|
||||
assert status["reboot_required"] is True
|
||||
assert "6.8.0-142-generic" in status["reboot_reason"]
|
||||
|
||||
def test_the_newest_kernel_running_needs_none(self):
|
||||
"""vault-01: 6.8.0-142 running and newest; 6.8.0-94 sorts below it."""
|
||||
status = parse_host_status(
|
||||
_wire(running="6.8.0-142-generic", modules=("6.8.0-94-generic", "6.8.0-142-generic"))
|
||||
)
|
||||
|
||||
assert status["reboot_required"] is False
|
||||
assert status["reboot_reason"] is None
|
||||
|
||||
def test_needs_restarting_exit_1_means_reboot(self):
|
||||
assert parse_host_status(_wire(needs_restarting=1))["reboot_required"] is True
|
||||
|
||||
def test_needs_restarting_exit_0_does_not(self):
|
||||
assert parse_host_status(_wire(needs_restarting=0))["reboot_required"] is False
|
||||
|
||||
def test_no_kernel_information_is_unknown(self):
|
||||
"""A container has no /lib/modules of its own."""
|
||||
status = parse_host_status(_wire(modules=()))
|
||||
|
||||
assert status["reboot_required"] is None
|
||||
|
||||
|
||||
class TestKernelRebootPending:
|
||||
@pytest.mark.parametrize(
|
||||
("running", "installed", "newer"),
|
||||
[
|
||||
# Raspberry Pi: two flavours side by side; only the running one counts.
|
||||
(
|
||||
"6.18.33+rpt-rpi-v8",
|
||||
[
|
||||
"6.12.75+rpt-rpi-2712",
|
||||
"6.12.75+rpt-rpi-v8",
|
||||
"6.18.33+rpt-rpi-2712",
|
||||
"6.18.33+rpt-rpi-v8",
|
||||
],
|
||||
None,
|
||||
),
|
||||
# Debian (OMV): 7.1.8 installed while 7.1.3 runs.
|
||||
(
|
||||
"7.1.3+deb13-amd64",
|
||||
["6.12.57+deb13-amd64", "7.1.3+deb13-amd64", "7.1.8+deb13-amd64"],
|
||||
"7.1.8+deb13-amd64",
|
||||
),
|
||||
# Proxmox: 7.0.14-19 is newer than 7.0.2-6, numerically.
|
||||
("7.0.14-19-pve", ["7.0.14-19-pve", "7.0.2-6-pve"], None),
|
||||
# Arch: the running kernel's modules were replaced by the upgrade.
|
||||
("6.10.5-arch1-1", ["6.10.9-arch1-1"], "6.10.9-arch1-1"),
|
||||
],
|
||||
)
|
||||
def test_the_newer_kernel_of_the_running_flavour(self, running, installed, newer):
|
||||
assert kernel_reboot_pending(running, installed) == newer
|
||||
|
||||
|
||||
class TestAutoUpdates:
|
||||
def test_unattended_upgrades_switched_on(self):
|
||||
assert parse_host_status(_wire(periodic=UNATTENDED))["auto_updates"] is True
|
||||
|
||||
def test_apt_without_the_setting_does_not_patch_itself(self):
|
||||
"""Proxmox and Raspberry Pi OS: apt-config answers, the setting is absent."""
|
||||
assert parse_host_status(_wire(periodic=[]))["auto_updates"] is False
|
||||
|
||||
def test_switched_off_by_zero(self):
|
||||
off = ['APT::Periodic::Unattended-Upgrade "0";']
|
||||
|
||||
assert parse_host_status(_wire(periodic=off))["auto_updates"] is False
|
||||
|
||||
def test_a_disabled_timer_stops_it_even_when_configured(self):
|
||||
status = parse_host_status(_wire(periodic=UNATTENDED, timer="disabled"))
|
||||
|
||||
assert status["auto_updates"] is False
|
||||
|
||||
def test_dnf_automatic(self):
|
||||
status = parse_host_status(_wire(dnf_timers=("enabled", "not-found")))
|
||||
|
||||
assert status["auto_updates"] is True
|
||||
|
||||
def test_neither_apt_nor_dnf_is_unknown(self):
|
||||
assert parse_host_status(_wire())["auto_updates"] is None
|
||||
|
||||
|
||||
class TestTheReport:
|
||||
def test_a_cut_short_report_raises(self):
|
||||
with pytest.raises(ValueError):
|
||||
parse_host_status(_wire().replace("HSTAT_END\n", ""))
|
||||
|
||||
def test_the_frame_is_not_in_the_command_itself(self):
|
||||
assert "HSTAT_BEGIN" not in HOST_STATUS_COMMAND
|
||||
assert "HSTAT_END" not in HOST_STATUS_COMMAND
|
||||
|
||||
def test_it_runs_without_a_terminal(self):
|
||||
"""No colour codes from ls, nothing a screen scraper could take for a prompt."""
|
||||
assert HOST_STATUS_COMMAND.rstrip().endswith("| cat")
|
||||
|
||||
def test_terminal_codes_are_dropped(self):
|
||||
status = parse_host_status(
|
||||
"\x1b[0m" + _wire(reboot_file=True).replace("HSTAT_END", "\x1b>HSTAT_END")
|
||||
)
|
||||
|
||||
assert status["reboot_required"] is True
|
||||
|
||||
def test_it_changes_nothing(self):
|
||||
for word in ("rm ", "apt-get ", "dnf install", "systemctl start", "reboot"):
|
||||
assert word not in HOST_STATUS_COMMAND.replace("reboot-required", "")
|
||||
|
||||
|
||||
class _Driver(HostStatusMixin):
|
||||
def __init__(self, reply: str) -> None:
|
||||
self.reply = reply
|
||||
self.commands: list = []
|
||||
|
||||
def _run_host_status_command(self, command: str) -> str:
|
||||
self.commands.append(command)
|
||||
return self.reply
|
||||
|
||||
|
||||
class TestHostStatusMixin:
|
||||
def test_a_driver_supplies_only_the_transport(self):
|
||||
driver = _Driver(_wire(reboot_file=True, periodic=UNATTENDED))
|
||||
|
||||
status = driver.get_host_status()
|
||||
|
||||
assert driver.commands == [HOST_STATUS_COMMAND]
|
||||
assert (status["reboot_required"], status["auto_updates"]) == (True, True)
|
||||
|
||||
def test_not_every_os_driver_has_it(self):
|
||||
assert not hasattr(OSDriver, "get_host_status")
|
||||
@@ -0,0 +1,149 @@
|
||||
"""Pending updates: which package, from where, and whether it closes a security hole.
|
||||
|
||||
A patch deadline ("security updates within 14 days") needs to know which pending
|
||||
update is a security update. apt says so in the suite a candidate comes from
|
||||
(``noble-security``, ``stable-security``); dnf says so in its update advisories.
|
||||
Reading that is the same for every driver whose host runs apt or dnf, so the
|
||||
parsers live here once (netOrk MVP 5, #556).
|
||||
|
||||
Fixture lines are from real hosts (Ubuntu 24.04, Debian 13 / OMV, Proxmox VE 9).
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import pytest
|
||||
|
||||
from napalm_device_types.package_updates import (
|
||||
APT_UPGRADABLE_COMMAND,
|
||||
nevra_name,
|
||||
parse_apt_upgradable,
|
||||
parse_dnf_security,
|
||||
)
|
||||
|
||||
UBUNTU = """\
|
||||
docker-compose-plugin/noble 5.6.0-1~ubuntu.24.04~noble amd64 [upgradable from: 5.5.1-1~ubuntu.24.04~noble]
|
||||
openssl/noble-updates,noble-security 3.0.13-0ubuntu3.6 amd64 [upgradable from: 3.0.13-0ubuntu3.5]
|
||||
__APT_RC=0
|
||||
"""
|
||||
|
||||
DEBIAN = """\
|
||||
linux-image-amd64/stable-backports 7.1.13-1~bpo13+1 amd64 [upgradable from: 7.1.8-1~bpo13+1]
|
||||
libssl3t64/stable-security 3.5.1-1+deb13u2 amd64 [upgradable from: 3.5.1-1+deb13u1]
|
||||
__APT_RC=0
|
||||
"""
|
||||
|
||||
|
||||
def _by_name(updates):
|
||||
return {u["name"]: u for u in updates}
|
||||
|
||||
|
||||
class TestAptUpgradable:
|
||||
def test_each_line_is_a_package_with_both_versions(self):
|
||||
update = _by_name(parse_apt_upgradable(UBUNTU))["docker-compose-plugin"]
|
||||
|
||||
assert update["current_version"] == "5.5.1-1~ubuntu.24.04~noble"
|
||||
assert update["new_version"] == "5.6.0-1~ubuntu.24.04~noble"
|
||||
|
||||
def test_the_suites_are_its_origin(self):
|
||||
updates = _by_name(parse_apt_upgradable(UBUNTU))
|
||||
|
||||
assert updates["openssl"]["origin"] == "noble-updates,noble-security"
|
||||
assert updates["docker-compose-plugin"]["origin"] == "noble"
|
||||
|
||||
def test_a_suite_apt_lists_twice_is_named_once(self):
|
||||
line = (
|
||||
"fonts-opensymbol/noble-updates,noble-updates,noble-security,noble-security "
|
||||
"4:102.12+LibO24.2.7-0ubuntu0.24.04.7 all [upgradable from: 4:102.12+LibO24.2.7-0ubuntu0.24.04.6]\n"
|
||||
"__APT_RC=0\n"
|
||||
)
|
||||
|
||||
assert parse_apt_upgradable(line)[0]["origin"] == "noble-updates,noble-security"
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
("output", "name", "security"),
|
||||
[
|
||||
(UBUNTU, "openssl", True),
|
||||
(UBUNTU, "docker-compose-plugin", False),
|
||||
(DEBIAN, "libssl3t64", True),
|
||||
(DEBIAN, "linux-image-amd64", False),
|
||||
],
|
||||
)
|
||||
def test_a_security_suite_makes_it_a_security_update(self, output, name, security):
|
||||
assert _by_name(parse_apt_upgradable(output))[name]["security"] is security
|
||||
|
||||
def test_a_line_the_terminal_wrapped_is_joined(self):
|
||||
wrapped = (
|
||||
"openssl/noble-updates,noble-security 3.0.13-0ubuntu3.6 amd64 [upgradable fro\n"
|
||||
" m: 3.0.13-0ubuntu3.5]\n__APT_RC=0\n"
|
||||
)
|
||||
|
||||
assert _by_name(parse_apt_upgradable(wrapped))["openssl"]["current_version"] == (
|
||||
"3.0.13-0ubuntu3.5"
|
||||
)
|
||||
|
||||
def test_one_package_for_several_architectures_is_one_entry(self):
|
||||
multiarch = (
|
||||
"libc6/noble-updates 2.39-0ubuntu8.5 amd64 [upgradable from: 2.39-0ubuntu8.4]\n"
|
||||
"libc6/noble-updates,noble-security 2.39-0ubuntu8.5 i386 [upgradable from: 2.39-0ubuntu8.4]\n"
|
||||
"__APT_RC=0\n"
|
||||
)
|
||||
|
||||
updates = parse_apt_upgradable(multiarch)
|
||||
|
||||
assert [u["name"] for u in updates] == ["libc6"]
|
||||
assert updates[0]["security"] is True
|
||||
|
||||
def test_noise_is_ignored(self):
|
||||
noisy = "Listing... Done\nWARNING: apt does not have a stable CLI interface.\n" + UBUNTU
|
||||
|
||||
assert len(parse_apt_upgradable(noisy)) == 2
|
||||
|
||||
def test_nothing_pending_is_an_empty_list(self):
|
||||
assert parse_apt_upgradable("__APT_RC=0\n") == []
|
||||
|
||||
def test_a_list_without_its_exit_status_raises(self):
|
||||
"""Cut short: a transport stopped reading early, so nothing can be concluded."""
|
||||
with pytest.raises(ValueError):
|
||||
parse_apt_upgradable(UBUNTU.replace("__APT_RC=0\n", ""))
|
||||
|
||||
def test_a_failed_apt_raises(self):
|
||||
with pytest.raises(ValueError, match="100"):
|
||||
parse_apt_upgradable("E: Could not get lock\n__APT_RC=100\n")
|
||||
|
||||
def test_terminal_codes_around_the_status_are_dropped(self):
|
||||
"""What a pseudo-terminal left on a Raspberry Pi OS host."""
|
||||
raw = "Listing... 0%\n\x1b[?1h\x1b=\n" + UBUNTU.replace("__APT_RC=0", "\x1b>__APT_RC=0")
|
||||
|
||||
assert len(parse_apt_upgradable(raw)) == 2
|
||||
|
||||
def test_the_command_reads_without_root_or_a_terminal(self):
|
||||
"""Through a pipe apt draws no progress and no terminal codes; one of
|
||||
those, ESC >, ended a screen-scraping read at a false prompt."""
|
||||
assert "LC_ALL=C apt list --upgradable" in APT_UPGRADABLE_COMMAND
|
||||
assert APT_UPGRADABLE_COMMAND.rstrip().endswith("| cat")
|
||||
assert "sudo" not in APT_UPGRADABLE_COMMAND
|
||||
|
||||
|
||||
class TestDnfSecurity:
|
||||
ADVISORIES = """\
|
||||
FEDORA-2024-1a2b3c4d5e Important/Sec. openssl-libs-1:3.1.4-2.fc40.x86_64
|
||||
FEDORA-2024-1a2b3c4d5e Important/Sec. openssl-1:3.1.4-2.fc40.x86_64
|
||||
RLSA-2024:1234 Moderate/Sec. kernel-core-5.14.0-427.13.1.el9_4.x86_64
|
||||
"""
|
||||
|
||||
def test_the_names_of_packages_with_a_security_advisory(self):
|
||||
assert parse_dnf_security(self.ADVISORIES) == {"openssl-libs", "openssl", "kernel-core"}
|
||||
|
||||
def test_nothing_is_an_empty_set(self):
|
||||
assert parse_dnf_security("") == set()
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
("nevra", "name"),
|
||||
[
|
||||
("openssl-libs-1:3.1.4-2.fc40.x86_64", "openssl-libs"),
|
||||
("kernel-core-5.14.0-427.13.1.el9_4.x86_64", "kernel-core"),
|
||||
("python3-dnf-4.14.0-9.el9.noarch", "python3-dnf"),
|
||||
],
|
||||
)
|
||||
def test_the_name_of_a_nevra(self, nevra, name):
|
||||
assert nevra_name(nevra) == name
|
||||
Reference in New Issue
Block a user