Two bugs prevented the firewall step from working:
1. `netstat` was used to detect the SSH peer IP — not installed on
OpenWrt by default, so raw_conn was empty and the entire firewall
step was silently skipped.
2. Even if detection had worked, `src='*'` is wrong when zones have
`input='REJECT'`. The rule only takes effect before the zone policy
if `src` is the exact zone name.
Fix: switch to `ss` (always present), strip any IPv6-mapped prefix,
then walk `uci show firewall` to find the zone whose network interface
shares the same /24 as the peer IP. Use that zone name as `src`.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Added _lldpd_fix_interface() helper that detects the management interface
via the default route and strips any .VID suffix (e.g. br-ap.10 → br-ap).
LLDP is L2 and must run on the bridge itself — sending on a VLAN subinterface
produces tagged frames the switch won't recognize as LLDP.
The helper runs every poll so existing wrong configs (e.g. eth0 from the
original install action) are corrected automatically on the next poll.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
opkg list-upgradable and apk version output contains version strings and
comparison operators; meta.packages now stores only the bare package name
so the schedule-updates API validation passes.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Install snmpd-nossl + luci-app-snmpd via opkg, configure via UCI with correct
field names (group/viewname/context='none'), bare port 161, stop+pkill before
start to break crash loops. get_snmp_config() reads current UCI snmpd state.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>