Compare commits
32
Commits
3ca2ed72ed
..
master
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0f5e2a1d37 | ||
|
|
b7a13d5153 | ||
|
|
007590b9bf | ||
|
|
79e52f060e | ||
|
|
3571149639 | ||
|
|
60b56c37e0 | ||
|
|
e82f99df7b | ||
|
|
2fed2f73e2 | ||
|
|
b49acb8ed7 | ||
|
|
a6f9a17858 | ||
|
|
e31bc2a3bf | ||
|
|
84717ff53b | ||
|
|
31b8a37895 | ||
|
|
a6e5568e0b | ||
|
|
b6b1827f96 | ||
|
|
ac288823a7 | ||
|
|
b4e6bbf79f | ||
|
|
b45444c831 | ||
|
|
e8eadb46c6 | ||
|
|
55635ab551 | ||
|
|
549e8c01e0 | ||
|
|
d33739832b | ||
|
|
7faaafb7a3 | ||
|
|
799d1ce749 | ||
|
|
ce40299033 | ||
|
|
27027eec56 | ||
|
|
c8fc46c373 | ||
|
|
661d56074c | ||
|
|
2f049338b5 | ||
|
|
07dcdbfe50 | ||
|
|
1cee26823e | ||
|
|
8436013dcd |
@@ -0,0 +1,48 @@
|
||||
name: CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: ["**"]
|
||||
pull_request:
|
||||
branches: ["**"]
|
||||
|
||||
jobs:
|
||||
test:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
python-version: ["3.10", "3.11", "3.12"]
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup Python
|
||||
uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: ${{ matrix.python-version }}
|
||||
cache: pip
|
||||
|
||||
- name: Install package with dev extras
|
||||
run: |
|
||||
python -m pip install --upgrade pip
|
||||
# napalm-device-types lives in git.netork.io/NAPALM, not on PyPI: without this
|
||||
# pip looks there, finds an unrelated 0.1.0 and the job dies before any test.
|
||||
python -m pip install "napalm-device-types @ git+https://git.netork.io/NAPALM/napalm-device-types.git"
|
||||
python -m pip install -e ".[dev]"
|
||||
|
||||
- name: Run unit tests
|
||||
run: |
|
||||
python -m pytest -q --tb=short
|
||||
|
||||
- name: Build wheel and sdist
|
||||
run: |
|
||||
python -m pip install build
|
||||
python -m build
|
||||
|
||||
- name: Upload dist artifacts
|
||||
# v4 refuses to run on Gitea ("not currently supported on GHES").
|
||||
uses: actions/upload-artifact@v3
|
||||
with:
|
||||
name: dist-${{ matrix.python-version }}
|
||||
path: dist/*
|
||||
@@ -48,7 +48,8 @@ with Driver(
|
||||
optional_args={
|
||||
# "port": 22,
|
||||
# "pkg_manager": "apt", # force package manager; auto-detected by default
|
||||
# "secret": "sudo-pass", # password for sudo / enable (defaults to login password)
|
||||
# "sudo_password": "sudo-pass", # for commands that need root; without it,
|
||||
# # `sudo -n` (passwordless sudo) is tried
|
||||
# "debugging": True, # enable verbose logging
|
||||
},
|
||||
) as dev:
|
||||
@@ -69,6 +70,10 @@ with Driver(
|
||||
|
||||
# Upgrade everything with pending updates
|
||||
result = dev.apply_updates([])
|
||||
|
||||
# Restart a service (start, stop, restart, enable, disable)
|
||||
result = dev.manage_service("cron", "restart")
|
||||
print(result) # {"success": True, "output": ""}
|
||||
```
|
||||
|
||||
## Supported NAPALM methods
|
||||
@@ -99,7 +104,8 @@ with Driver(
|
||||
| `get_packages()` | ✅ | apt, dnf, yum, apk, pacman |
|
||||
| `get_pending_updates()` | ✅ | apt, dnf, yum, apk, pacman |
|
||||
| `apply_updates(packages)` | ✅ | apt, dnf, yum, apk, pacman |
|
||||
| `get_services()` | ✅ | systemd (fallback: SysV `service`) |
|
||||
| `get_services()` | ✅ | systemd, one round trip (fallback: SysV `service`) |
|
||||
| `manage_service(name, action)` | ✅ | systemd: start, stop, restart, enable, disable |
|
||||
| `get_users()` | ✅ | `/etc/passwd` + `/etc/group` |
|
||||
| `get_processes()` | ✅ | `ps axo` |
|
||||
| `get_cron_jobs()` | ✅ | user crontabs + `/etc/cron.d/` |
|
||||
@@ -127,13 +133,25 @@ The SSH user needs read access to:
|
||||
| `/etc/passwd`, `/etc/group` | world-readable (default) |
|
||||
| `/proc/uptime`, `/sys/class/dmi/…` | world-readable (default) |
|
||||
| User crontabs (`/var/spool/cron/…`) | `root` or `sudo` required |
|
||||
| `systemctl is-enabled <unit>` | unprivileged on most distros |
|
||||
| `systemctl list-unit-files`, `systemctl show` | unprivileged |
|
||||
| `systemctl start/stop/restart/enable/disable` | `root`, or `sudo` (with `sudo_password`, or passwordless) |
|
||||
| `apt list --upgradable` | may require `apt-get update` (root) |
|
||||
| `dnf check-update` / `yum check-update` | unprivileged, but slower without cache |
|
||||
|
||||
For full functionality it is recommended to run as `root` or grant passwordless `sudo` for
|
||||
the above commands.
|
||||
|
||||
`get_services()` and `manage_service()` come from napalm-device-types'
|
||||
`SystemdServicesMixin`; this driver supplies only the transport. An action runs as
|
||||
`timeout 45 systemctl --no-ask-password <action> -- <unit>.service`, so a unit that hangs
|
||||
on its way up or down cannot hold the session, and only the exit status decides whether it
|
||||
succeeded. Without a sudo password it uses `sudo -n`, which fails at once instead of
|
||||
waiting for a password prompt.
|
||||
|
||||
On OpenMediaVault (napalm-openmediavault inherits this driver), enabling or disabling a
|
||||
unit that OMV manages itself — Samba, NFS, SSH — may be reverted the next time OMV applies
|
||||
its configuration.
|
||||
|
||||
## Tested distributions
|
||||
|
||||
| Distribution | Version | Package manager | Tested |
|
||||
|
||||
+475
-112
@@ -31,7 +31,20 @@ from netmiko.exceptions import (
|
||||
)
|
||||
from napalm.base.exceptions import ConnectionException, ConnectionClosedException
|
||||
from napalm.base.netmiko_helpers import netmiko_args
|
||||
from napalm_device_types import FingerprintRule, OSDriver
|
||||
from napalm_device_types import (
|
||||
APT_UPGRADABLE_COMMAND,
|
||||
DNF_SECURITY_COMMAND,
|
||||
FingerprintRule,
|
||||
HostStatusMixin,
|
||||
KernelFactsMixin,
|
||||
ListeningSocketsMixin,
|
||||
OSDriver,
|
||||
SystemdServicesMixin,
|
||||
SystemdUnavailable,
|
||||
parse_apt_upgradable,
|
||||
parse_dnf_security,
|
||||
strip_terminal_codes,
|
||||
)
|
||||
from napalm_device_types.models import (
|
||||
ApplyUpdatesResultDict,
|
||||
CronJobDict,
|
||||
@@ -50,6 +63,76 @@ logger = logging.getLogger("napalm_linux")
|
||||
# Package managers in detection order
|
||||
_PKG_MANAGERS = ["apt", "dnf", "yum", "apk", "pacman"]
|
||||
|
||||
#: Printed after a command by ``_sudo_status`` so its exit status survives the
|
||||
#: trip through an interactive shell. Matched only on a line of its own with a
|
||||
#: number after it — an echoed command line carries the literal ``$?`` instead.
|
||||
_RC_MARKER = "__NETORK_RC="
|
||||
_RC_MARKER_RE = re.compile(rf"^{_RC_MARKER}(\d+)\s*$", re.MULTILINE)
|
||||
|
||||
|
||||
#: The end of a command's output when nothing better is known: a line that looks
|
||||
#: like a shell prompt.
|
||||
_PROMPT_RE = r"[#$\>]\s*$"
|
||||
#: A command ending in ``echo __NAME=$?`` reports its exit status on a line of its
|
||||
#: own: ``_RC_MARKER`` here, ``__APT_RC=`` and ``__SVC_RC=`` in napalm-device-types.
|
||||
_STATUS_ECHO_RE = re.compile(r"echo\s+(__[A-Z_]+=)\$\?")
|
||||
|
||||
|
||||
def _expect_for(command: str) -> str:
|
||||
"""The pattern that ends *command*'s output.
|
||||
|
||||
netmiko stops reading as soon as the pattern matches what it has read so far.
|
||||
A line the command prints can end in ``#``, ``$`` or ``>`` -- apt's
|
||||
``<ftpmaster@ubuntu.com>`` after a bad signature -- and was taken for the
|
||||
prompt: half the output came back, and the rest started the next command's
|
||||
(#615). A command that echoes its exit status is read until that marker, with
|
||||
a number, and the prompt line after it. The echoed command line carries a
|
||||
literal ``$?`` and cannot match.
|
||||
"""
|
||||
markers = _STATUS_ECHO_RE.findall(command)
|
||||
if not markers:
|
||||
return _PROMPT_RE
|
||||
return re.escape(markers[-1]) + r"\d+\s*\n.*" + _PROMPT_RE
|
||||
|
||||
|
||||
def _split_status(raw: str) -> tuple[str, int | None]:
|
||||
"""``(output, exit_status)`` of a command followed by ``echo {_RC_MARKER}$?``.
|
||||
|
||||
The status is ``None`` when the marker never arrived (output cut short), so
|
||||
a caller can tell "unknown" from "succeeded".
|
||||
"""
|
||||
raw = strip_terminal_codes(raw)
|
||||
matches = list(_RC_MARKER_RE.finditer(raw))
|
||||
if not matches:
|
||||
return raw, None
|
||||
last = matches[-1]
|
||||
return (raw[: last.start()] + raw[last.end():]).strip(), int(last.group(1))
|
||||
|
||||
|
||||
#: How each package manager refreshes its index. pacman is left out on purpose:
|
||||
#: ``pacman -Sy`` without ``-u`` invites a partial upgrade on the next install.
|
||||
_REFRESH = {
|
||||
# No LC_ALL=C here: under sudo it is an environment variable sudoers may refuse
|
||||
# to set. Only the exit status decides, so the language is merely what is shown.
|
||||
"apt": "apt-get update -q 2>&1",
|
||||
"dnf": "dnf makecache -q 2>&1",
|
||||
"yum": "yum makecache -q 2>&1",
|
||||
"apk": "apk update -q 2>&1",
|
||||
}
|
||||
_YUM_SECURITY_COMMAND = "LC_ALL=C yum updateinfo list security -q 2>/dev/null"
|
||||
|
||||
#: Restart the host two seconds later, detached from this session: the launcher's
|
||||
#: exit status comes back before the host goes down, and closing the session
|
||||
#: cannot take the restart with it.
|
||||
_REBOOT_DETACHED = "sh -c '(trap \"\" HUP; sleep 2; /sbin/reboot) </dev/null >/dev/null 2>&1 &'"
|
||||
|
||||
#: What to do when sudo wants a password netOrk does not have.
|
||||
_SUDO_PASSWORD_HINT = (
|
||||
"sudo requires a password on this device but none is configured in netOrk. "
|
||||
"Please add the sudo password to a Credential Profile assigned to this device, "
|
||||
"or configure passwordless sudo (NOPASSWD) for this user."
|
||||
)
|
||||
|
||||
# DMI field values that carry no useful information (OEM defaults, blanks)
|
||||
_BAD_DMI: frozenset[str] = frozenset({
|
||||
"", "none", "n/a", "not specified", "not applicable",
|
||||
@@ -116,7 +199,25 @@ def _arm_vendor_from_model(model: str) -> str:
|
||||
return " ".join(brand)
|
||||
|
||||
|
||||
class LinuxDriver(OSDriver):
|
||||
#: A bare image ID (``d626d04934cd``), not a registry reference. ``docker ps``
|
||||
#: falls back to this whenever the tag a container was created from has since
|
||||
#: been moved to a newer image — i.e. exactly after a pull without a recreate.
|
||||
_IMAGE_ID_RE = re.compile(r"^(sha256:)?[0-9a-f]{12,64}$")
|
||||
|
||||
|
||||
def _looks_like_image_id(ref: str) -> bool:
|
||||
"""True if *ref* is an image ID rather than something a registry can resolve."""
|
||||
return bool(_IMAGE_ID_RE.match(ref.strip()))
|
||||
|
||||
|
||||
def _short_image_id(raw: str) -> str:
|
||||
"""Normalise ``sha256:<64hex>`` and ``<12hex>`` to a comparable 12-char form."""
|
||||
return raw.strip().removeprefix("sha256:")[:12]
|
||||
|
||||
|
||||
class LinuxDriver(
|
||||
KernelFactsMixin, ListeningSocketsMixin, SystemdServicesMixin, HostStatusMixin, OSDriver
|
||||
):
|
||||
"""NAPALM driver for generic Linux systems.
|
||||
|
||||
Connects via SSH (netmiko ``linux`` device type) and auto-detects the
|
||||
@@ -126,6 +227,9 @@ class LinuxDriver(OSDriver):
|
||||
TYPE_LABEL = "Linux"
|
||||
VENDOR = "Linux"
|
||||
DRIVER_NAME = "linux"
|
||||
# A general-purpose host runs through a full init sequence; NAS derivatives
|
||||
# (OpenMediaVault, QNAP) inherit this and are, if anything, slower.
|
||||
REBOOT_SETTLE_SECONDS = 90
|
||||
SNMP_FINGERPRINT = [
|
||||
FingerprintRule("linux", weight=5.0),
|
||||
]
|
||||
@@ -235,7 +339,7 @@ class LinuxDriver(OSDriver):
|
||||
command,
|
||||
read_timeout=read_timeout,
|
||||
cmd_verify=False,
|
||||
expect_string=r'[#$\>]\s*$',
|
||||
expect_string=_expect_for(command),
|
||||
).strip()
|
||||
|
||||
def _sudo(self, command: str, read_timeout: float = 100) -> str:
|
||||
@@ -248,6 +352,70 @@ class LinuxDriver(OSDriver):
|
||||
return self._send(wrapped, read_timeout=read_timeout)
|
||||
return self._send(f'sudo {command}', read_timeout=read_timeout)
|
||||
|
||||
def _sudo_status(self, command: str, read_timeout: float = 100) -> tuple[str, int | None]:
|
||||
"""Run *command* via sudo and return ``(output, exit_status)``.
|
||||
|
||||
``_sudo`` callers append ``|| true`` so a failing command yields output
|
||||
instead of an error, which throws the exit status away. This variant
|
||||
echoes ``$?`` straight after the sudo pipeline instead — sudo passes
|
||||
the command's status through, and a failed password is non-zero too.
|
||||
|
||||
The status is ``None`` when the marker never arrived (output cut short),
|
||||
so a caller can tell "unknown" from "succeeded".
|
||||
"""
|
||||
return _split_status(
|
||||
self._sudo(f"{command}; echo {_RC_MARKER}$?", read_timeout=read_timeout)
|
||||
)
|
||||
|
||||
def _is_root(self) -> bool:
|
||||
"""Whether the SSH user is root, asked once per session.
|
||||
|
||||
A root login on a box without sudo (an LXC container, a minimal Debian)
|
||||
must not have its commands prefixed with a sudo that is not there.
|
||||
"""
|
||||
if getattr(self, "_root", None) is None:
|
||||
self._root = self._send("id -u") == "0"
|
||||
return bool(self._root)
|
||||
|
||||
def _run_service_command(self, command: str, *, privileged: bool, timeout: int) -> str:
|
||||
"""The transport for :class:`SystemdServicesMixin`.
|
||||
|
||||
Without a sudo password, ``sudo -n`` fails at once where a prompt would
|
||||
otherwise hang the session until the read timeout.
|
||||
"""
|
||||
if not privileged:
|
||||
return self._send(command, read_timeout=timeout)
|
||||
return self._run_privileged(command, timeout)
|
||||
|
||||
def _run_privileged(self, command: str, timeout: float = 100) -> str:
|
||||
"""Run *command* as root: directly for a root login, through ``_sudo``
|
||||
with a sudo password, and through ``sudo -n`` without one -- which fails at
|
||||
once where a password prompt would hang the session until the timeout."""
|
||||
if self._is_root():
|
||||
return self._send(command, read_timeout=timeout)
|
||||
if self._sudo_password:
|
||||
return self._sudo(command, read_timeout=timeout)
|
||||
return self._send(f"sudo -n {command}", read_timeout=timeout)
|
||||
|
||||
def reboot_host(self) -> None:
|
||||
"""Restart the host (``HostRebootMixin``); returns once the restart is under way.
|
||||
|
||||
:raises RuntimeError: when the host refuses -- sudo without a password,
|
||||
no ``reboot`` -- or its answer carried no exit status.
|
||||
"""
|
||||
output, status = _split_status(
|
||||
self._run_privileged(f"{_REBOOT_DETACHED}; echo {_RC_MARKER}$?", 30)
|
||||
)
|
||||
if status != 0:
|
||||
reason = output or f"the reboot command exited with status {status}"
|
||||
if "password is required" in output:
|
||||
reason = f"{reason}\n{_SUDO_PASSWORD_HINT}"
|
||||
raise RuntimeError(reason)
|
||||
|
||||
def _run_host_status_command(self, command: str) -> str:
|
||||
"""The transport for ``HostStatusMixin.get_host_status``: read-only, no sudo."""
|
||||
return self._send(command, read_timeout=60)
|
||||
|
||||
def _detect_pkg_manager(self) -> str | None:
|
||||
"""Return the first package manager binary found on PATH."""
|
||||
for pm in _PKG_MANAGERS:
|
||||
@@ -381,6 +549,10 @@ class LinuxDriver(OSDriver):
|
||||
iface_out = self._send("ip -o link show | awk -F': ' '{print $2}' | cut -d@ -f1")
|
||||
interface_list = [i.strip() for i in iface_out.splitlines() if i.strip() and i.strip() != "lo"]
|
||||
|
||||
# Currently-booted kernel release, distinct from an installed-but-not-yet-
|
||||
# booted newer kernel (used for kernel CVE relevance).
|
||||
running_kernel = self._send("uname -r").strip()
|
||||
|
||||
return {
|
||||
"hostname": hostname,
|
||||
"fqdn": fqdn,
|
||||
@@ -390,6 +562,7 @@ class LinuxDriver(OSDriver):
|
||||
"os_version": os_version,
|
||||
"uptime": uptime_secs,
|
||||
"interface_list": interface_list,
|
||||
"running_kernel": running_kernel,
|
||||
}
|
||||
|
||||
def _parse_uptime(self) -> int:
|
||||
@@ -791,6 +964,27 @@ class LinuxDriver(OSDriver):
|
||||
}
|
||||
}
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# KernelFactsMixin – the transport for get_kernel_facts
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
def _run_kernel_facts_command(self, command: str) -> str:
|
||||
"""The transport for ``KernelFactsMixin.get_kernel_facts``: read-only, no sudo."""
|
||||
return self._send(command, read_timeout=60)
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# ListeningSocketsMixin – the transport for get_listening_sockets
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
def _run_listening_sockets_command(self, command: str, *, privileged: bool) -> str:
|
||||
"""The transport for ``ListeningSocketsMixin.get_listening_sockets``.
|
||||
|
||||
Read-only either way; root only so that ``ss`` names every process.
|
||||
"""
|
||||
if privileged:
|
||||
return self._run_privileged(command, 60)
|
||||
return self._send(command, read_timeout=60)
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# OSDriver – package management
|
||||
# ------------------------------------------------------------------
|
||||
@@ -810,17 +1004,36 @@ class LinuxDriver(OSDriver):
|
||||
|
||||
def _get_packages_apt(self) -> list[PackageDict]:
|
||||
out = self._send(
|
||||
"dpkg-query -W -f='${Package}\\t${Version}\\t${Installed-Size}\\t${binary:Summary}\\n' 2>/dev/null"
|
||||
"dpkg-query -W -f='${Package}\\t${Version}\\t${Installed-Size}"
|
||||
"\\t${source:Package}\\t${source:Version}\\t${binary:Summary}\\n' 2>/dev/null"
|
||||
)
|
||||
packages: list[PackageDict] = []
|
||||
for line in out.splitlines():
|
||||
parts = line.split("\t", 3)
|
||||
# Summary stays last and keeps whatever it contains: maxsplit must
|
||||
# equal the number of tabs the format writes, not the field count.
|
||||
parts = line.split("\t", 5)
|
||||
if len(parts) < 2:
|
||||
continue
|
||||
name = parts[0].strip()
|
||||
version = parts[1].strip()
|
||||
size = int(parts[2].strip()) * 1024 if len(parts) > 2 and parts[2].strip().isdigit() else 0
|
||||
description = parts[3].strip() if len(parts) > 3 else ""
|
||||
# Debian source package (e.g. openssh-server → openssh) for OSV matching.
|
||||
source_package = parts[3].strip() if len(parts) > 3 and parts[3].strip() else name
|
||||
# And its version, which is a different number from this package's.
|
||||
#
|
||||
# OSV states Debian ranges in *source* versions. A source package
|
||||
# that ships several binaries gives each its own upstream version:
|
||||
# libldb2 is 2:2.11.0+samba4.22.11+dfsg-… while its source, samba,
|
||||
# is 2:4.22.11+dfsg-…. A consumer matching on source_package and
|
||||
# comparing `version` compares two unrelated numbers — dpkg reads
|
||||
# ldb's 2.11.0 as older than the 2:4.17.4+dfsg-1 that fixed
|
||||
# CVE-2022-44640, and a host five releases past the fix was reported
|
||||
# vulnerable on four packages at once.
|
||||
#
|
||||
# dpkg leaves this empty when it equals `Version`; so does an older
|
||||
# dpkg that does not know the field at all.
|
||||
source_version = parts[4].strip() if len(parts) > 4 and parts[4].strip() else version
|
||||
description = parts[5].strip() if len(parts) > 5 else ""
|
||||
packages.append({
|
||||
"name": name,
|
||||
"version": version,
|
||||
@@ -828,6 +1041,8 @@ class LinuxDriver(OSDriver):
|
||||
"description": description,
|
||||
"size": size,
|
||||
"source": "apt",
|
||||
"source_package": source_package,
|
||||
"source_version": source_version,
|
||||
})
|
||||
return packages
|
||||
|
||||
@@ -1000,26 +1215,88 @@ class LinuxDriver(OSDriver):
|
||||
success = not any(kw in low for kw in ("error:", "failed", "no packages", "not found", "unable to locate", "no match"))
|
||||
return {"success": success, "output": raw.strip()}
|
||||
|
||||
def uninstall_package(self, name: str) -> dict[str, Any]:
|
||||
"""Remove a package by name. Returns ``{"success": bool, "output": str}``."""
|
||||
#: Words in a package manager's output that mean it did not do the job.
|
||||
#: Only consulted when the exit status is unknown; see ``_uninstall_failed``.
|
||||
_UNINSTALL_FAILED = ("error:", "failed", "not found", "is not installed", "no packages")
|
||||
|
||||
def uninstall_package(self, name: str, purge: bool = False) -> dict[str, Any]:
|
||||
"""Remove a package by name. Returns ``{"success": bool, "output": str}``.
|
||||
|
||||
``purge`` also removes the package's configuration where the package
|
||||
manager distinguishes the two. Off by default: configuration somebody
|
||||
may want back is not this function's to delete unless it was asked for.
|
||||
|
||||
It matters for more than tidiness. A package's apt source survives a
|
||||
plain ``remove``, so the repository keeps being fetched on every
|
||||
``apt-get update`` long after the package itself is gone — which is what
|
||||
the Wazuh agent left behind on thirteen hosts.
|
||||
|
||||
**The dpkg fallback.** A package whose ``postinst`` failed sits at
|
||||
``install ok unpacked``, and apt cannot remove it: it configures a
|
||||
package before removing it, and configuring is precisely what is broken.
|
||||
Seven of those thirteen hosts were in that state after an upgrade whose
|
||||
postinst could not reach a manager that had been decommissioned, and on
|
||||
one of them only ``dpkg --purge --force-all`` got it out.
|
||||
|
||||
So the fallback runs **only after apt has failed**, never as a routine
|
||||
second step: forcing dpkg past its own consistency checks is a bigger
|
||||
hammer than apt, and a caller who reaches for it every time will
|
||||
eventually break something apt would have refused to.
|
||||
"""
|
||||
from shlex import quote as _q
|
||||
safe = _q(name)
|
||||
pm = self._pkg_manager
|
||||
if pm == "apt":
|
||||
raw = self._sudo(f"DEBIAN_FRONTEND=noninteractive apt-get remove -y {safe} 2>&1 || true")
|
||||
action = "purge" if purge else "remove"
|
||||
cmd = f"DEBIAN_FRONTEND=noninteractive apt-get {action} -y {safe} 2>&1"
|
||||
elif pm in ("dnf", "yum"):
|
||||
raw = self._sudo(f"{pm} remove -y {safe} 2>&1 || true")
|
||||
cmd = f"{pm} remove -y {safe} 2>&1"
|
||||
elif pm == "apk":
|
||||
raw = self._sudo(f"apk del {safe} 2>&1 || true")
|
||||
# apk and pacman have no separate purge; asking for one is not an
|
||||
# error, it simply has nothing extra to do.
|
||||
cmd = f"apk del {safe} 2>&1"
|
||||
elif pm == "pacman":
|
||||
raw = self._sudo(f"pacman -R --noconfirm {safe} 2>&1 || true")
|
||||
cmd = f"pacman -R --noconfirm {safe} 2>&1"
|
||||
else:
|
||||
return {"success": False, "output": f"Unsupported package manager: {pm}"}
|
||||
low = raw.lower()
|
||||
success = not any(kw in low for kw in ("error:", "failed", "not found", "is not installed", "no packages"))
|
||||
return {"success": success, "output": raw.strip()}
|
||||
|
||||
def get_pending_updates(self) -> list[UpdateDict]:
|
||||
raw, rc = self._sudo_status(cmd)
|
||||
failed = self._uninstall_failed(raw, rc)
|
||||
|
||||
if failed and pm == "apt":
|
||||
forced, forced_rc = self._sudo_status(f"dpkg --purge --force-all {safe} 2>&1")
|
||||
raw = f"{raw.strip()}\n--- dpkg --purge --force-all ---\n{forced.strip()}"
|
||||
failed = self._uninstall_failed(forced, forced_rc)
|
||||
|
||||
return {"success": not failed, "output": raw.strip()}
|
||||
|
||||
def _uninstall_failed(self, output: str, rc: int | None = None) -> bool:
|
||||
"""Whether the package manager did not do the job.
|
||||
|
||||
The exit status decides whenever there is one (netork#267): it is the
|
||||
answer the package manager actually gives, where the output is prose
|
||||
that every tool phrases differently. A prerm printing "Failed to stop
|
||||
…" while the removal completes is a success; a non-zero exit with
|
||||
nothing alarming in the output is not.
|
||||
|
||||
Only when the status is unknown (``rc is None``) is the output read,
|
||||
as the best answer left. apt prefixes its own errors with ``E: `` at
|
||||
the start of a line, and the commonest of them — ``E: Sub-process
|
||||
/usr/bin/dpkg returned an error code (1)`` — contains neither "error:"
|
||||
nor "failed". The keyword list alone therefore read a failed removal
|
||||
as a success, which is the worst direction for this particular answer
|
||||
to be wrong in.
|
||||
|
||||
Matched at line start rather than anywhere: "note: " ends in "e: ".
|
||||
"""
|
||||
if rc is not None:
|
||||
return rc != 0
|
||||
low = output.lower()
|
||||
if any(line.lstrip().startswith("e: ") for line in low.splitlines()):
|
||||
return True
|
||||
return any(kw in low for kw in self._UNINSTALL_FAILED)
|
||||
|
||||
def get_available_updates(self) -> list[UpdateDict]:
|
||||
if self._pkg_manager == "apt":
|
||||
return self._get_updates_apt()
|
||||
if self._pkg_manager in ("dnf", "yum"):
|
||||
@@ -1032,10 +1309,6 @@ class LinuxDriver(OSDriver):
|
||||
f"Package manager '{self._pkg_manager}' is not supported"
|
||||
)
|
||||
|
||||
def get_available_updates(self) -> list[UpdateDict]:
|
||||
"""Alias for get_pending_updates(); called by the netork API backend."""
|
||||
return self.get_pending_updates()
|
||||
|
||||
def get_device_warnings(self) -> List[dict[str, Any]]:
|
||||
"""Return warning dicts for issues detected on this device.
|
||||
|
||||
@@ -1052,8 +1325,6 @@ class LinuxDriver(OSDriver):
|
||||
if updates:
|
||||
warnings.append({
|
||||
"code": "updates_available",
|
||||
"severity": "warning",
|
||||
"action": None,
|
||||
"meta": {
|
||||
"count": len(updates),
|
||||
"packages": [u.get("name", "") for u in updates],
|
||||
@@ -1065,8 +1336,6 @@ class LinuxDriver(OSDriver):
|
||||
if self._apt_proxy_url not in current:
|
||||
warnings.append({
|
||||
"code": "apt_proxy_missing",
|
||||
"severity": "warning",
|
||||
"action": "fix_apt_proxy",
|
||||
"meta": {"expected_url": self._apt_proxy_url},
|
||||
})
|
||||
except Exception as exc:
|
||||
@@ -1076,48 +1345,49 @@ class LinuxDriver(OSDriver):
|
||||
def _get_updates_apt(self) -> list[UpdateDict]:
|
||||
# apt list --upgradable does not need root; avoid sudo so it works even
|
||||
# without a configured sudo password.
|
||||
out = self._send(
|
||||
"LC_ALL=C apt list --upgradable 2>/dev/null | grep -v '^Listing'",
|
||||
read_timeout=60,
|
||||
)
|
||||
# Join wrapped lines: netmiko's 80-col pseudo-TTY causes long apt lines to
|
||||
# break; continuation lines start with a space.
|
||||
raw_lines: List[str] = []
|
||||
for line in out.splitlines():
|
||||
if line.startswith(" ") and raw_lines:
|
||||
raw_lines[-1] += line.strip()
|
||||
else:
|
||||
raw_lines.append(line)
|
||||
updates: list[UpdateDict] = []
|
||||
for line in raw_lines:
|
||||
# openssh-server/stable 1:9.2p1-2+deb12u2 amd64 [upgradable from: 1:9.2p1-2+deb12u1]
|
||||
m = re.match(
|
||||
r"^(\S+)/\S+\s+(\S+)\s+\S+\s+\[upgradable from:\s+(\S+)\]", line
|
||||
)
|
||||
if m:
|
||||
updates.append({
|
||||
"name": m.group(1),
|
||||
"current_version": m.group(3),
|
||||
"new_version": m.group(2),
|
||||
})
|
||||
return updates
|
||||
# Raises ValueError when apt failed or the output was cut short.
|
||||
return parse_apt_upgradable(self._send(APT_UPGRADABLE_COMMAND, read_timeout=60))
|
||||
|
||||
def _get_updates_rpm(self) -> list[UpdateDict]:
|
||||
"""dnf/yum check-update: exit 100 means updates, 0 none, anything else failed."""
|
||||
cmd = "dnf check-update --quiet 2>/dev/null" if self._pkg_manager == "dnf" else "yum check-update -q 2>/dev/null"
|
||||
out = self._sudo(cmd)
|
||||
output, status = _split_status(self._run_privileged(f"{cmd}; echo {_RC_MARKER}$?", 120))
|
||||
if status not in (0, 100):
|
||||
raise RuntimeError(f"{self._pkg_manager} check-update failed (exit {status}): {output[-200:]}")
|
||||
security = self._rpm_security_names()
|
||||
updates: list[UpdateDict] = []
|
||||
for line in out.splitlines():
|
||||
for line in output.splitlines():
|
||||
parts = line.split()
|
||||
if len(parts) >= 2 and not line.startswith(" ") and "." in parts[0]:
|
||||
name_arch = parts[0]
|
||||
name = name_arch.rsplit(".", 1)[0] if "." in name_arch else name_arch
|
||||
name = parts[0].rsplit(".", 1)[0]
|
||||
updates.append({
|
||||
"name": name,
|
||||
"current_version": "",
|
||||
"new_version": parts[1],
|
||||
"origin": parts[2] if len(parts) >= 3 else None,
|
||||
"security": None if security is None else name in security,
|
||||
})
|
||||
return updates
|
||||
|
||||
def _rpm_security_names(self) -> set[str] | None:
|
||||
"""Packages a pending security advisory covers; None when dnf/yum cannot say."""
|
||||
cmd = DNF_SECURITY_COMMAND if self._pkg_manager == "dnf" else _YUM_SECURITY_COMMAND
|
||||
output, status = _split_status(self._run_privileged(f"{cmd}; echo {_RC_MARKER}$?", 120))
|
||||
return parse_dnf_security(output) if status == 0 else None
|
||||
|
||||
def refresh_available_updates(self) -> dict[str, Any]:
|
||||
"""Refresh the package index (apt-get update, dnf makecache, apk update)."""
|
||||
cmd = _REFRESH.get(self._pkg_manager or "")
|
||||
if cmd is None:
|
||||
return {
|
||||
"success": False,
|
||||
"output": f"Refreshing the index is not supported for {self._pkg_manager!r}",
|
||||
}
|
||||
output, status = _split_status(self._run_privileged(f"{cmd}; echo {_RC_MARKER}$?", 180))
|
||||
if status != 0 and "password is required" in output:
|
||||
output = f"{output}\n{_SUDO_PASSWORD_HINT}"
|
||||
return {"success": status == 0, "output": output}
|
||||
|
||||
def _get_updates_apk(self) -> list[UpdateDict]:
|
||||
out = self._send("apk version -l '<' 2>/dev/null")
|
||||
updates: list[UpdateDict] = []
|
||||
@@ -1247,50 +1517,25 @@ class LinuxDriver(OSDriver):
|
||||
return {"success": False, "output": "", "error": str(exc)}
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# OSDriver – services (systemd)
|
||||
# OSDriver – services (systemd, through SystemdServicesMixin)
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
def get_services(self) -> list[ServiceDict]:
|
||||
"""Return systemd service units (falls back to service --status-all on SysV)."""
|
||||
out = self._send(
|
||||
"systemctl list-units --type=service --all --no-legend --no-pager "
|
||||
"--plain 2>/dev/null"
|
||||
)
|
||||
if not out:
|
||||
"""systemd's services in one round trip; ``service --status-all`` without systemd."""
|
||||
try:
|
||||
return super().get_services()
|
||||
except SystemdUnavailable:
|
||||
return self._get_services_sysv()
|
||||
|
||||
services: list[ServiceDict] = []
|
||||
for line in out.splitlines():
|
||||
# ssh.service loaded active running OpenBSD Secure Shell server
|
||||
parts = line.split(None, 4)
|
||||
if len(parts) < 4:
|
||||
continue
|
||||
unit, load, active, sub = parts[0], parts[1], parts[2], parts[3]
|
||||
name = unit.removesuffix(".service")
|
||||
running = active == "active" and sub == "running"
|
||||
enabled_out = self._send(
|
||||
f"systemctl is-enabled {unit} 2>/dev/null"
|
||||
)
|
||||
enabled = enabled_out.strip() == "enabled"
|
||||
def manage_service(self, name: str, action: str) -> dict[str, Any]:
|
||||
"""Start, stop, restart, enable or disable a systemd service.
|
||||
|
||||
# Retrieve main PID for running services
|
||||
pid = 0
|
||||
if running:
|
||||
pid_out = self._send(
|
||||
f"systemctl show -p MainPID --value {unit} 2>/dev/null"
|
||||
)
|
||||
try:
|
||||
pid = int(pid_out.strip())
|
||||
except ValueError:
|
||||
pid = 0
|
||||
|
||||
services.append({
|
||||
"name": name,
|
||||
"running": running,
|
||||
"enabled": enabled,
|
||||
"pid": pid,
|
||||
})
|
||||
return services
|
||||
:raises ValueError: for an unknown action or an invalid name.
|
||||
"""
|
||||
result = super().manage_service(name, action)
|
||||
if not result["success"] and "password is required" in result["output"]:
|
||||
result["output"] = f"{result['output']}\n{_SUDO_PASSWORD_HINT}"
|
||||
return result
|
||||
|
||||
def _get_services_sysv(self) -> list[ServiceDict]:
|
||||
out = self._send("service --status-all 2>/dev/null")
|
||||
@@ -1484,6 +1729,16 @@ class LinuxDriver(OSDriver):
|
||||
# Docker
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
def _docker_bin(self) -> str:
|
||||
"""Path to the docker binary.
|
||||
|
||||
A hook rather than a literal because the Docker *logic* is the same
|
||||
everywhere while the *location* is not: QTS ships Container Station's
|
||||
docker under /share/<pool>/.qpkg/ and never puts it on PATH. Subclasses
|
||||
override this one method instead of reimplementing the surface.
|
||||
"""
|
||||
return "docker"
|
||||
|
||||
def get_docker_info(self) -> DockerInfoDict:
|
||||
"""Return information about the local Docker environment.
|
||||
|
||||
@@ -1502,26 +1757,31 @@ class LinuxDriver(OSDriver):
|
||||
"""
|
||||
import json as _json
|
||||
|
||||
docker = self._docker_bin()
|
||||
|
||||
# Check docker binary first (docker --version doesn't need socket access)
|
||||
if not self._send("command -v docker 2>/dev/null").strip():
|
||||
if not self._send(f"command -v {docker} 2>/dev/null").strip():
|
||||
return {"available": False}
|
||||
|
||||
# Verify socket access — docker ps is cheaper and fails immediately on permission errors
|
||||
ps_check = self._send("docker ps 2>&1")
|
||||
ps_check = self._send(f"{docker} ps 2>&1")
|
||||
if "permission denied" in ps_check.lower() or "cannot connect" in ps_check.lower():
|
||||
return {"available": False, "permission_denied": True}
|
||||
|
||||
version = self._send("docker --version 2>/dev/null").strip()
|
||||
version = self._send(f"{docker} --version 2>/dev/null").strip()
|
||||
|
||||
combined = self._send(
|
||||
"echo '---CONTAINERS---'; "
|
||||
"docker ps -a --format '{{json .}}' 2>/dev/null; "
|
||||
f"{docker} ps -a --format '{{{{json .}}}}' 2>/dev/null; "
|
||||
"echo '---IMAGES---'; "
|
||||
"docker images --format '{{json .}}' 2>/dev/null; "
|
||||
f"{docker} images --format '{{{{json .}}}}' 2>/dev/null; "
|
||||
"echo '---VOLUMES---'; "
|
||||
"docker volume ls --format '{{json .}}' 2>/dev/null; "
|
||||
f"{docker} volume ls --format '{{{{json .}}}}' 2>/dev/null; "
|
||||
"echo '---NETWORKS---'; "
|
||||
"docker network ls --format '{{json .}}' 2>/dev/null",
|
||||
f"{docker} network ls --format '{{{{json .}}}}' 2>/dev/null; "
|
||||
"echo '---CONFIGIMAGES---'; "
|
||||
f"{docker} ps -aq 2>/dev/null | xargs -r {docker} inspect "
|
||||
f"--format '{{{{.Id}}}}|{{{{.Config.Image}}}}|{{{{.Image}}}}' 2>/dev/null",
|
||||
read_timeout=60,
|
||||
)
|
||||
|
||||
@@ -1540,7 +1800,8 @@ class LinuxDriver(OSDriver):
|
||||
raw_containers = _section(combined, "---CONTAINERS---", "---IMAGES---")
|
||||
raw_images = _section(combined, "---IMAGES---", "---VOLUMES---")
|
||||
raw_volumes = _section(combined, "---VOLUMES---", "---NETWORKS---")
|
||||
raw_networks = _section(combined, "---NETWORKS---", "\x00") # sentinel
|
||||
raw_networks = _section(combined, "---NETWORKS---", "---CONFIGIMAGES---")
|
||||
raw_cfgimages = _section(combined, "---CONFIGIMAGES---", "\x00") # sentinel
|
||||
|
||||
def _parse_labels(raw: Any) -> Dict[str, str]:
|
||||
"""Parse Docker labels — may be a dict (JSON map) or comma-sep string."""
|
||||
@@ -1601,6 +1862,44 @@ class LinuxDriver(OSDriver):
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
# Stable image reference + restart-pending detection.
|
||||
#
|
||||
# ``docker ps`` only reports a usable tag while that tag still resolves to
|
||||
# the running image. Pull a newer image without recreating the container and
|
||||
# it degrades to a bare image ID — useless as a registry reference, and the
|
||||
# very state in which an update is waiting. ``.Config.Image`` is the
|
||||
# reference the container was created from and never degrades.
|
||||
cfg_by_cid: dict[str, tuple] = {}
|
||||
for line in raw_cfgimages.splitlines():
|
||||
parts = line.strip().split("|")
|
||||
if len(parts) != 3 or not parts[0]:
|
||||
continue
|
||||
cid, cfg_ref, run_id = parts
|
||||
cfg_by_cid[cid[:12]] = (cfg_ref.strip(), run_id.strip())
|
||||
|
||||
tag_index: dict[str, tuple] = {}
|
||||
for im in images:
|
||||
repo, tag = im.get("repository", ""), im.get("tag", "")
|
||||
if not repo or not tag or "<none>" in (repo, tag):
|
||||
continue
|
||||
tag_index[f"{repo}:{tag}"] = (_short_image_id(im.get("id", "")), im.get("version", ""))
|
||||
|
||||
for c in containers:
|
||||
cfg_ref, run_id = cfg_by_cid.get(c.get("id", "")[:12], ("", ""))
|
||||
if not cfg_ref:
|
||||
continue
|
||||
c["image_ref"] = cfg_ref
|
||||
c["running_image_id"] = _short_image_id(run_id)
|
||||
c["restart_pending"] = False
|
||||
c["pending_version"] = ""
|
||||
# A stopped container is not "pending a restart" in any useful sense.
|
||||
if c.get("state") != "running":
|
||||
continue
|
||||
tag_id, tag_version = tag_index.get(cfg_ref, ("", ""))
|
||||
if tag_id and c["running_image_id"] and tag_id != c["running_image_id"]:
|
||||
c["restart_pending"] = True
|
||||
c["pending_version"] = tag_version
|
||||
|
||||
# Volumes
|
||||
volumes: List[dict[str, Any]] = []
|
||||
for line in raw_volumes.splitlines():
|
||||
@@ -1658,15 +1957,28 @@ class LinuxDriver(OSDriver):
|
||||
Returns a list of image references that have a newer digest available.
|
||||
"""
|
||||
outdated_images: List[str] = []
|
||||
candidate_images: List[str] = list({
|
||||
c["image"] for c in containers
|
||||
if c.get("image")
|
||||
and "@sha256:" not in c.get("image", "") # skip digest-pinned
|
||||
})
|
||||
# Prefer the reference the container was created from. `image` is whatever
|
||||
# `docker ps` displayed, which collapses to a bare image ID once the tag has
|
||||
# moved on — and an image ID is not something a registry can resolve.
|
||||
candidate_images: List[str] = []
|
||||
for c in containers:
|
||||
ref = (c.get("image_ref") or c.get("image") or "").strip()
|
||||
if not ref or "@sha256:" in ref: # skip digest-pinned
|
||||
continue
|
||||
if _looks_like_image_id(ref):
|
||||
logger.warning(
|
||||
"container %s reports image ID %r instead of a tag — cannot ask the "
|
||||
"registry about it; skipping update check",
|
||||
c.get("name", "?"), ref,
|
||||
)
|
||||
continue
|
||||
if ref not in candidate_images:
|
||||
candidate_images.append(ref)
|
||||
for img_name in candidate_images:
|
||||
try:
|
||||
local_raw = self._send(
|
||||
f"docker inspect {img_name!r} --format '{{{{index .RepoDigests 0}}}}' 2>/dev/null",
|
||||
f"{self._docker_bin()} inspect {img_name!r} "
|
||||
f"--format '{{{{index .RepoDigests 0}}}}' 2>/dev/null",
|
||||
read_timeout=5,
|
||||
).strip()
|
||||
if not local_raw or "@" not in local_raw:
|
||||
@@ -1674,7 +1986,7 @@ class LinuxDriver(OSDriver):
|
||||
local_digest = local_raw.split("@", 1)[1]
|
||||
|
||||
remote_full = self._send(
|
||||
f"docker buildx imagetools inspect {img_name!r} 2>&1",
|
||||
f"{self._docker_bin()} buildx imagetools inspect {img_name!r} 2>&1",
|
||||
read_timeout=30,
|
||||
).strip()
|
||||
if ("429" in remote_full
|
||||
@@ -1693,6 +2005,11 @@ class LinuxDriver(OSDriver):
|
||||
remote_digest = _ls[7:].strip()
|
||||
break
|
||||
if not remote_digest or not remote_digest.startswith("sha256:"):
|
||||
# Silence here is indistinguishable from "up to date" — say so.
|
||||
logger.warning(
|
||||
"no digest returned for %s; skipping update check. Registry said: %s",
|
||||
img_name, remote_full[:200].replace("\n", " ") or "(nothing)",
|
||||
)
|
||||
continue
|
||||
if local_digest != remote_digest:
|
||||
outdated_images.append(img_name)
|
||||
@@ -1716,7 +2033,7 @@ class LinuxDriver(OSDriver):
|
||||
import shlex as _shlex
|
||||
|
||||
raw = self._send(
|
||||
f"docker inspect {_shlex.quote(container_id)} 2>/dev/null",
|
||||
f"{self._docker_bin()} inspect {_shlex.quote(container_id)} 2>/dev/null",
|
||||
read_timeout=10,
|
||||
).strip()
|
||||
if not raw:
|
||||
@@ -1884,8 +2201,44 @@ class LinuxDriver(OSDriver):
|
||||
return self._action_fix_snmp()
|
||||
if action == "fix_apt_proxy":
|
||||
return self._action_fix_apt_proxy()
|
||||
if action == "apt_update_upgrade":
|
||||
return self._action_apt_update_upgrade()
|
||||
raise NotImplementedError(f"Unknown action: {action!r}")
|
||||
|
||||
def _action_apt_update_upgrade(self) -> DeviceActionResultDict:
|
||||
"""Refresh the apt cache and fully upgrade all packages (apt-based systems only).
|
||||
|
||||
Uses full-upgrade (not plain upgrade) — plain "apt-get upgrade" refuses
|
||||
to install/remove packages even when required to satisfy a newer
|
||||
version's dependencies, silently leaving those updates pending.
|
||||
"""
|
||||
if self._pkg_manager != "apt":
|
||||
return {
|
||||
"success": True,
|
||||
"output": f"Skipped — package manager is {self._pkg_manager!r}, not apt.",
|
||||
}
|
||||
|
||||
sudo_check = self._send("sudo -n true 2>&1 || echo __SUDO_NEEDS_PW__")
|
||||
if "__SUDO_NEEDS_PW__" in sudo_check or "password is required" in sudo_check.lower():
|
||||
if not self._sudo_password:
|
||||
return {
|
||||
"success": False,
|
||||
"output": _SUDO_PASSWORD_HINT,
|
||||
}
|
||||
|
||||
lines: list[str] = []
|
||||
try:
|
||||
out = self._sudo("apt-get update -y 2>&1", read_timeout=90)
|
||||
lines.append(f"[update] {out.strip()[-300:]}")
|
||||
out = self._sudo(
|
||||
"DEBIAN_FRONTEND=noninteractive apt-get full-upgrade -y 2>&1", read_timeout=240
|
||||
)
|
||||
lines.append(f"[upgrade] {out.strip()[-300:]}")
|
||||
return {"success": True, "output": "\n".join(lines)}
|
||||
except Exception as exc:
|
||||
lines.append(f"[error] {exc}")
|
||||
return {"success": False, "output": "\n".join(lines)}
|
||||
|
||||
def _action_fix_snmp(self) -> DeviceActionResultDict:
|
||||
"""Install, configure and start snmpd with community 'public'."""
|
||||
lines: list[str] = []
|
||||
@@ -1896,11 +2249,7 @@ class LinuxDriver(OSDriver):
|
||||
if not self._sudo_password:
|
||||
return {
|
||||
"success": False,
|
||||
"output": (
|
||||
"sudo requires a password on this device but none is configured in netOrk. "
|
||||
"Please add the sudo password to a Credential Profile assigned to this device, "
|
||||
"or configure passwordless sudo (NOPASSWD) for this user."
|
||||
),
|
||||
"output": _SUDO_PASSWORD_HINT,
|
||||
}
|
||||
|
||||
# 1. Install snmpd if missing
|
||||
@@ -1908,6 +2257,16 @@ class LinuxDriver(OSDriver):
|
||||
if not pkg_mgr:
|
||||
return {"success": False, "output": "Package manager not detected — cannot install snmpd."}
|
||||
|
||||
# Refresh the package index first — a freshly provisioned (or simply
|
||||
# long-untouched) system's cache can be stale/empty, which makes the
|
||||
# install below fail outright rather than just being slow.
|
||||
if pkg_mgr == "apt":
|
||||
try:
|
||||
update_out = self._sudo("apt-get update -y 2>&1", read_timeout=90)
|
||||
lines.append(f"[update] {update_out.strip()[-200:]}")
|
||||
except Exception as exc:
|
||||
lines.append(f"[warn] apt-get update failed: {exc}")
|
||||
|
||||
# Install both snmpd (daemon) and snmp (client tools incl. snmpget for probing)
|
||||
install_cmd: dict[str, str] = {
|
||||
"apt": "DEBIAN_FRONTEND=noninteractive apt-get install -y snmpd snmp 2>&1",
|
||||
@@ -1918,8 +2277,12 @@ class LinuxDriver(OSDriver):
|
||||
}
|
||||
cmd = install_cmd.get(pkg_mgr)
|
||||
if cmd:
|
||||
try:
|
||||
out = self._sudo(cmd, read_timeout=120)
|
||||
lines.append(f"[install] {out.strip()[-200:]}")
|
||||
except Exception as exc:
|
||||
lines.append(f"[error] install failed: {exc}")
|
||||
return {"success": False, "output": "\n".join(lines)}
|
||||
|
||||
# 2. Determine the IP netOrk is connecting from by checking the established SSH connection
|
||||
netork_ip = ""
|
||||
|
||||
+1
-1
@@ -37,7 +37,7 @@ classifiers = [
|
||||
]
|
||||
dependencies = [
|
||||
"napalm>=4.0",
|
||||
"napalm-device-types>=0.3.0",
|
||||
"napalm-device-types>=2.4.0",
|
||||
"netmiko>=4.0.0",
|
||||
"paramiko>=5.0.0", # CVE-2026-44405
|
||||
]
|
||||
|
||||
+967
-11
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user