get_system_config() already parsed the whole system section but returned
only a slice of it, so netOrk had no IST side for three AP-profile fields
and could not compare them at all — the fields were editable, stored and
silently ineffective.
Adds:
* syslog_remote / syslog_ip / syslog_port / syslog_proto — read from the
system section that was already being parsed. log_remote gates the
others: OpenWrt ships nothing without it, so a leftover log_ip must
not read as an active target.
* luci_enabled — from the uhttpd init script rather than its listener
config, so the answer stays "is the web UI served" and re-enabling
restores whatever was configured before.
* bridge_stp — None when there is no br-ap at all, which is a different
statement from "bridge without STP" and has to stay distinguishable.
netOrk #164
get_device_warnings() now returns only {code, meta} — severity, title,
message, and action are resolved centrally by netork's
WARNING_CATALOG (netork/core/device_warnings.py), not by the driver.
Keeps this driver independent of netork and avoids per-vendor drift in
how the same warning code is presented.
Two bugs prevented the firewall step from working:
1. `netstat` was used to detect the SSH peer IP — not installed on
OpenWrt by default, so raw_conn was empty and the entire firewall
step was silently skipped.
2. Even if detection had worked, `src='*'` is wrong when zones have
`input='REJECT'`. The rule only takes effect before the zone policy
if `src` is the exact zone name.
Fix: switch to `ss` (always present), strip any IPv6-mapped prefix,
then walk `uci show firewall` to find the zone whose network interface
shares the same /24 as the peer IP. Use that zone name as `src`.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>