22 Commits
Author SHA1 Message Date
Christian Manivong d45c082355 feat(system): report remote syslog, LuCI state and bridge STP
get_system_config() already parsed the whole system section but returned
only a slice of it, so netOrk had no IST side for three AP-profile fields
and could not compare them at all — the fields were editable, stored and
silently ineffective.

Adds:
  * syslog_remote / syslog_ip / syslog_port / syslog_proto — read from the
    system section that was already being parsed. log_remote gates the
    others: OpenWrt ships nothing without it, so a leftover log_ip must
    not read as an active target.
  * luci_enabled — from the uhttpd init script rather than its listener
    config, so the answer stays "is the web UI served" and re-enabling
    restores whatever was configured before.
  * bridge_stp — None when there is no br-ap at all, which is a different
    statement from "bridge without STP" and has to stay distinguishable.

netOrk #164
2026-08-29 22:41:36 +07:00
Christian Manivong fd972a427e refactor: drop the seven forwarding methods AccessPointDriver forced
AccessPointDriver used to declare get_services, manage_service,
get_available_updates, apply_updates, get_packages, install_package and
remove_package as NotImplementedError stubs. Those stubs preceded
OpenWrtSystemMixin and OpenWrtPackageMixin in the MRO and shadowed their working
implementations, so this driver carried a forwarder for each one purely to
delegate past the base.

napalm-device-types v1.0 makes role bases declaration-only, so nothing shadows
anything and all seven forwarders are dead weight. Every method now resolves
straight to the mixin that implements it.

remove_package went with them: the base now calls the method by the name the
package mixin already used, uninstall_package, so the name adapter is gone too.
2026-08-21 12:50:10 +07:00
Christian Manivong 597a59fa39 fix(snmp): resolve the real firewall zone instead of guessing "lan"
fix_snmp reported success on APs where the rule never reached nftables.
Five defects stacked up:

1. Zone detection required ".src=" and "ssh" in the same `uci show` line.
   UCI prints one option per line, so anonymous rules never matched and
   every device fell through to the hardcoded "lan" fallback.
2. That fallback was never checked against the zones that actually exist.
   On an AP whose zone section has no `option name`, fw4 skips the section,
   so `src='lan'` referenced a zone that was not there and the rule was
   dropped with it.
3. The "already present" guard was a substring test, so a rule written by
   an earlier broken run was skipped forever instead of repaired.
4. Stale-rule deletion never committed — the only `uci commit firewall`
   sat in the add branch that the guard had just skipped.
5. `fw4 reload` errors were swallowed by `|| true`, and with no local
   snmpget the action hardcoded success = True.

Now: the management address comes from $SSH_CONNECTION and is mapped to
its network section (via ipaddr, or via `ip -o -4 addr` -> device when the
interface is DHCP-addressed) and from there to the owning zone. A zone
section without a name aborts the action with the repair command rather
than writing a dead rule — naming it is left to the operator, since an
inert zone becoming active changes what the AP filters. Rules are written
in full every run, stale ones are deleted highest anonymous index first
(uci renumbers @rule[n] on delete) and committed, reload output is no
longer truncated or ignored, and success is verified on the device via
`ss -lun` and a udp/161 lookup in the live ruleset.
2026-08-18 17:54:22 +07:00
Christian Manivong c686fac55e fix(vlans): read bridge-vlan membership from UCI, repair stale tests
get_vlans() relied on `bridge vlan show` for port membership. On devices
whose BusyBox ships without the bridge/ip-full packages the command does
not exist, _send_command returns the shell error, and the parser silently
finds nothing in it. All that survived was the sub-interface fallback,
which restates the bridge topology (br-ap tagged, br-ap.10 untagged) and
never names the uplink port — the only port whose tagging matters.

Measured on two Sophos AP100 (BusyBox 1.37.0): eth0 was absent from the
output entirely, while UCI held ports='eth0:u*' for the management VLAN
and 'eth0:t' for the rest.

UCI bridge-vlan sections are now parsed as a second source. They are
readable without the bridge binary and describe the configured state.
Section collection goes through the type declaration, so named sections
(network.apbr_vlan10) are recognised alongside anonymous ones — the old
regex matched only @bridge-vlan[N], so a hand-built bridge was invisible
even for name lookup. Runtime data keeps precedence where it exists,
since that is what the kernel actually enforces.

Option values are kept raw through collection; stripping quotes there
would collapse ports='lan1:t' 'lan2:t' into a single mangled item.

Also repairs TestGetVlans, red on master since get_vlans() moved to
separate tagged/untagged lists while the tests still asserted the old
'interfaces' key, and TestGetFacts, which never learned about the
number_of_interfaces key get_facts() sets deliberately. Both had left
the interesting behaviour uncovered.
2026-08-17 22:50:08 +07:00
Christian Manivong a8637461bb refactor(warnings): report raw signal only, no severity/presentation
get_device_warnings() now returns only {code, meta} — severity, title,
message, and action are resolved centrally by netork's
WARNING_CATALOG (netork/core/device_warnings.py), not by the driver.
Keeps this driver independent of netork and avoids per-vendor drift in
how the same warning code is presented.
2026-07-20 09:48:20 +02:00
Christian Manivong 6b78ebcacb fix: push_mac_acl() must never set macfilter='disable'
OpenWrt's wifi-scripts validator rejects any macfilter value other than
"allow"/"deny" outright — confirmed on real hardware, setting
macfilter='disable' puts netifd in a permanent restart crash loop with the
radio stuck down. The only way to disable filtering is to delete the option
entirely. Also guards against pushing an empty whitelist (macfilter='allow'
with zero MACs blocks every client outright) by treating it as equivalent
to "off".
2026-07-16 12:05:07 +02:00
Christian Manivong af032a3c4d feat: get_ssids() macfilter/maclist parsing + push_mac_acl()
Adds MAC ACL (whitelist/blacklist) read+write support for wireless SSIDs,
mirroring push_radio_channel's UCI write style. Backs the new Global MAC
ACL feature in netOrk.
2026-07-15 23:19:15 +02:00
Christian Manivong bfc19c2241 fix(deps): pin paramiko>=5.0.0 (CVE-2026-44405) 2026-07-02 12:22:55 +02:00
Christian ManivongandClaude Sonnet 4.6 ee69ec8da9 fix: mixin classes must precede AccessPointDriver in OpenWrtDriver MRO
NetworkDriver (parent of AccessPointDriver) raises NotImplementedError for all
standard NAPALM methods. With AccessPointDriver listed first, get_interfaces()
and get_vlans() from the mixins were shadowed and always raised NotImplementedError
(empty message) — causing all AP polls to report 0 interfaces and 0 VLANs.

Fix: reorder inheritance so mixins come before AccessPointDriver. The standard
NAPALM method stubs in NetworkDriver are now shadowed by the mixin implementations.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-25 13:48:25 +02:00
Christian ManivongandClaude Sonnet 4.6 4c41345489 fix: push_radio_channel uses 'wifi' (full restart) instead of 'wifi reload'
'wifi reload' only reapplies the running config without physically
changing the channel on many ath9k/ath10k/mt76 hardware+driver
combinations. A full 'wifi' (down + up) cycle is required for channel
changes to take effect.

Also updated the test assertion accordingly.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-25 00:01:03 +02:00
Christian ManivongandClaude Sonnet 4.6 512871b1bb feat: get_channel_scan() + push_radio_channel() in OpenWrtWirelessMixin
get_channel_scan(mode='active'|'passive'):
- Discovers AP-mode interfaces via 'iw dev'
- Runs 'iw dev <iface> scan [passive]' on each AP interface
- Parses BSS blocks: BSSID, SSID, frequency, channel, signal, channel
  width (HT/VHT/HE), band (2.4/5/6 GHz)
- Returns dict[iface → list[ChannelScanEntryDict]]

push_radio_channel(radio, channel):
- Sets channel via 'uci set wireless.<radio>.channel=<ch|auto>'
- Commits and reloads: 'uci commit wireless && wifi reload'
- channel=0 writes 'auto'

Tests: 19 new unit tests covering parse logic, active/passive flag,
AP-only interface filtering, 6 GHz band detection, push command order.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-24 23:26:25 +02:00
Christian ManivongandClaude Sonnet 4.6 e3a0a9e4b3 feat: Fingerprint-Attribute für Discovery-Scoring
Ergänzt DRIVER_NAME, HTTP_FINGERPRINT, SNMP_FINGERPRINT, SSH_FINGERPRINT,
PORT_SPECS und SNMP_OBJECT_ID_PREFIX gemäß docs/DISCOVERY_FINGERPRINTING.md.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-24 14:47:08 +02:00
Christian ManivongandClaude Sonnet 4.6 042a2b6d2e fix: get_facts() reads hardware vendor from /tmp/sysinfo/board_name
board_name format is "vendor,model" (e.g. "sophos,ap100"). The prefix
before the comma is title-cased to give the manufacturer name (e.g.
"Sophos"). Falls back to "OpenWrt" when board_name is unavailable.

The model is already read from /tmp/sysinfo/model which gives the full
human-readable name (e.g. "Sophos AP100") — no change needed there.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-22 22:37:25 +02:00
Christian ManivongandClaude Sonnet 4.6 2c0a5e94bf chore: track extracted mixin modules
Split from monolithic openwrt.py into separate mixin files for
interfaces, VLANs, packages, routing, wireless, LLDP, and config.
Already in use by the main driver; just missing from git tracking.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-19 22:13:04 +02:00
Christian ManivongandClaude Sonnet 4.6 b7e4831b26 fix: _action_fix_snmp uses src=<mgmt_zone> in firewall rule
The previous attempt added a rule without src= which lands in the global
nftables input chain. Traffic from the management interface (br-ap.10)
jumps immediately to input_mgmt, so the global rule was never reached.

Now detects the management zone name by finding the zone whose allow-SSH
rule already exists (the named rule pattern allow_ssh_from_<zone>).
Removes any mis-scoped previous SNMP rule, then adds a named UCI rule
allow_snmp_from_<zone> with src=<zone> so fw4 places it in the correct
chain (input_mgmt). Persists across reboots via uci commit + fw4 reload.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-19 22:03:33 +02:00
Christian ManivongandClaude Sonnet 4.6 e05d878f94 fix: implement _action_fix_snmp for OpenWRT
The method was called but missing — always raised AttributeError, so
Fix SNMP did nothing on OpenWRT devices.

OpenWRT's default firewall (fw4) policy-drops everything except the
ports explicitly listed in the management zone (SSH/HTTP/HTTPS/ICMP).
SNMP (UDP/161) is not in that list, which is why snmpd runs but is
unreachable from outside the device.

Fix adds a persistent UCI firewall rule for UDP/161, reloads fw4
immediately, verifies snmpd is running, and probes locally if SNMP
client tools are available. Returns success so callers can clear the
snmp_no_data warning.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-19 21:35:30 +02:00
Christian ManivongandClaude Sonnet 4.6 bea41b32a1 fix: fix_snmp firewall rule uses ss + correct zone name on OpenWrt
Two bugs prevented the firewall step from working:

1. `netstat` was used to detect the SSH peer IP — not installed on
   OpenWrt by default, so raw_conn was empty and the entire firewall
   step was silently skipped.

2. Even if detection had worked, `src='*'` is wrong when zones have
   `input='REJECT'`. The rule only takes effect before the zone policy
   if `src` is the exact zone name.

Fix: switch to `ss` (always present), strip any IPv6-mapped prefix,
then walk `uci show firewall` to find the zone whose network interface
shares the same /24 as the peer IP. Use that zone name as `src`.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-16 16:44:55 +02:00
Christian ManivongandClaude Sonnet 4.6 85041c13bb fix: configure lldpd on bridge interface, not VLAN subinterface
Added _lldpd_fix_interface() helper that detects the management interface
via the default route and strips any .VID suffix (e.g. br-ap.10 → br-ap).
LLDP is L2 and must run on the bridge itself — sending on a VLAN subinterface
produces tagged frames the switch won't recognize as LLDP.

The helper runs every poll so existing wrong configs (e.g. eth0 from the
original install action) are corrected automatically on the next poll.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-10 00:23:33 +02:00
Christian ManivongandClaude Sonnet 4.6 77c9d386db fix: return key (PSK) from get_ssids() for drift detection
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-04 13:28:40 +02:00
Christian ManivongandClaude Sonnet 4.6 0493520e5f fix: extract clean package names in updates_available warning meta
opkg list-upgradable and apk version output contains version strings and
comparison operators; meta.packages now stores only the bare package name
so the schedule-updates API validation passes.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-02 13:28:07 +02:00
Christian ManivongandClaude Sonnet 4.6 64964c1b33 feat: SNMP support — get_snmp_config(), fix_snmp action
Install snmpd-nossl + luci-app-snmpd via opkg, configure via UCI with correct
field names (group/viewname/context='none'), bare port 161, stop+pkill before
start to break crash loops. get_snmp_config() reads current UCI snmpd state.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-01 13:09:32 +02:00
Christian Manivong 1f0349aee9 initial commit 2026-05-29 09:10:40 +02:00