Author SHA1 Message Date
Christian Manivong c644519af6 feat: read the node's listening sockets through napalm-device-types
ProxmoxDriver mixes in ListeningSocketsMixin (napalm-device-types 2.4.0)
and carries its command over the exec path, which runs as root either
way: whether pveproxy, a Ceph manager or anything else on the node listens
on an address reachable from outside it.

For netOrk#658.
2026-10-06 18:19:57 +02:00
christianmanivong 6c9a6e7017 Merge pull request 'feat: declare that upgrading everything must be a full upgrade on Proxmox VE' (#10) from feat/full-upgrade into master 2026-10-06 10:27:21 +00:00
Christian Manivong 66c9be7d25 feat: declare that upgrading everything must be a full upgrade on Proxmox VE
A plain apt-get upgrade holds back what needs new or removed packages and
can leave a node half updated; Proxmox documents apt full-upgrade. netOrk
reads FULL_UPGRADE when it upgrades the host (MVP 5).
2026-10-06 12:27:02 +02:00
christianmanivong 222cd45c66 Merge pull request 'feat: report where an update comes from and whether it is a security fix, refresh the index, read the host status' (#9) from feat/update-origin-host-status into master 2026-10-05 22:20:09 +00:00
Christian Manivong 02a441ff09 feat: report where an update comes from and whether it is a security fix, refresh the index, read the host status
For netOrk MVP 5, on napalm-device-types 2.3.0:

- get_available_updates reads `apt list --upgradable` over the exec path
  (APT_UPGRADABLE_COMMAND), so each update carries its suite and security
  status; the APT API, which names only "Debian"/"Proxmox", is the fallback
  with security unknown. It raises when neither answers instead of returning
  [] -- it used to swallow every error.
- refresh_available_updates(): POST nodes/{n}/apt/update.
- HostStatusMixin over the exec path (reboot required, self-patching).
2026-10-06 00:20:08 +02:00
christianmanivong 1881ee7330 Merge pull request 'fix: report which services are enabled, and whether an action worked' (#8) from feat/systemd-services-mixin into master 2026-10-05 11:12:15 +00:00
6 changed files with 226 additions and 14 deletions
+8
View File
@@ -36,8 +36,10 @@ logger = logging.getLogger(__name__)
from napalm_device_types import (
FingerprintRule,
HostStatusMixin,
HypervisorDriver,
KernelFactsMixin,
ListeningSocketsMixin,
PortSpec,
SystemdServicesMixin,
)
@@ -83,7 +85,9 @@ class ProxmoxDriver(
ProxmoxRoutingMixin,
ProxmoxSystemMixin,
KernelFactsMixin,
ListeningSocketsMixin,
SystemdServicesMixin,
HostStatusMixin,
HypervisorDriver,
):
"""NAPALM driver for Proxmox VE nodes."""
@@ -94,6 +98,10 @@ class ProxmoxDriver(
USES_SSH = False
# A PVE node reboots through a full init sequence plus storage checks.
REBOOT_SETTLE_SECONDS = 90
#: "Upgrade everything" must be a full upgrade on Proxmox VE: a plain
#: ``apt-get upgrade`` holds back what needs new or removed packages and can
#: leave the node half updated. netOrk reads this when it upgrades the host.
FULL_UPGRADE = True
PORT_SPECS = [
PortSpec("https", 8006, weight=8.0),
]
+49 -13
View File
@@ -20,6 +20,8 @@ import logging
import re
from typing import Any
from napalm_device_types import APT_UPGRADABLE_COMMAND, parse_apt_upgradable
from napalm_proxmox import utils
logger = logging.getLogger(__name__)
@@ -229,6 +231,15 @@ class ProxmoxSystemMixin:
"""The transport for ``KernelFactsMixin.get_kernel_facts``: the exec path."""
return self._exec_ssh_command(command)
# ------------------------------------------------------------------ #
# Listening sockets (ListeningSocketsMixin supplies get_listening_sockets)
# ------------------------------------------------------------------ #
def _run_listening_sockets_command(self, command: str, *, privileged: bool) -> str:
"""The transport for ``ListeningSocketsMixin.get_listening_sockets``:
the exec path, which runs as root either way."""
return str(self._exec_ssh_command(command))
# ------------------------------------------------------------------ #
# Packages (Debian APT)
# ------------------------------------------------------------------ #
@@ -362,22 +373,47 @@ class ProxmoxSystemMixin:
# ------------------------------------------------------------------ #
def get_available_updates(self) -> list[_JsonDict]:
"""Return list of upgradable packages from the Proxmox APT API."""
updates: list[_JsonDict] = []
"""Return the node's upgradable packages, with origin and security status.
``apt list --upgradable`` over the exec path names each candidate's suite
(``trixie-security``); the APT API names only an Origin ("Debian",
"Proxmox") and is the fallback, with the security status unknown.
:raises Exception: when neither answers -- never an empty list for
"could not read".
"""
try:
for upd in self._api.nodes(self._node_name).apt.update.get():
pkg = upd.get("Package", "")
if not pkg:
continue
updates.append({
"name": pkg,
"current_version": upd.get("OldVersion", ""),
"new_version": upd.get("Version", ""),
})
except Exception as exc:
logger.debug("Failed to fetch available updates: %s", exc)
updates = parse_apt_upgradable(self._exec_ssh_command(APT_UPGRADABLE_COMMAND) or "")
except ValueError as exc:
logger.debug("apt list over the exec path failed, using the API: %s", exc)
updates = self._updates_from_api()
return sorted(updates, key=lambda u: u["name"])
def _updates_from_api(self) -> list[_JsonDict]:
return [
{
"name": upd["Package"],
"current_version": upd.get("OldVersion", ""),
"new_version": upd.get("Version", ""),
"origin": upd.get("Origin"),
"security": None,
}
for upd in self._api.nodes(self._node_name).apt.update.get() # type: ignore[union-attr]
if upd.get("Package")
]
def refresh_available_updates(self) -> _JsonDict:
"""Resynchronise the node's package index (``POST nodes/{n}/apt/update``)."""
try:
task = self._api.nodes(self._node_name).apt.update.post() # type: ignore[union-attr]
except Exception as exc:
return {"success": False, "output": str(exc)}
return {"success": True, "output": f"Package index refresh started ({task})"}
def _run_host_status_command(self, command: str) -> str:
"""The transport for ``HostStatusMixin.get_host_status``: the exec path."""
return str(self._exec_ssh_command(command))
def apply_updates(self, packages: list[str]) -> _JsonDict:
"""Upgrade the given packages via ``apt-get install`` over SSH."""
for pkg in packages:
+1 -1
View File
@@ -25,7 +25,7 @@ classifiers = [
requires-python = ">=3.9"
dependencies = [
"napalm>=5.0.0",
"napalm_device_types>=2.2.0",
"napalm_device_types>=2.4.0",
"paramiko>=5.0.0", # CVE-2026-44405; imported directly for SSH fallback (driver.py)
"proxmoxer>=2.0.0",
"netaddr>=0.9.0",
+11
View File
@@ -0,0 +1,11 @@
"""Proxmox VE says that "upgrade everything" must be a full upgrade on it.
A plain ``apt-get upgrade`` can leave a node half updated; Proxmox documents
``apt full-upgrade``. netOrk reads ``FULL_UPGRADE`` to choose.
"""
from napalm_proxmox.driver import ProxmoxDriver
def test_a_full_upgrade_is_declared():
assert ProxmoxDriver.FULL_UPGRADE is True
+37
View File
@@ -0,0 +1,37 @@
"""`get_listening_sockets`: what listens on the node, and which service it is.
Whether pveproxy, a Ceph manager or a guest-facing service is reachable from
outside the node is decided by the address it listens on. The command and its
parse are napalm-device-types'; the driver only carries the command over its
exec path, which already runs as root.
"""
from __future__ import annotations
from unittest.mock import patch
from napalm_device_types import ListeningSocketsMixin
from napalm_proxmox.driver import ProxmoxDriver
WIRE = (
"SOCK_BEGIN\n[ss]\n"
'tcp LISTEN 0 4096 *:8006 *:* users:(("pveproxy worker",pid=2101,fd=6))\n'
"__SS_RC=0\n[cgroups]\n"
"2101 0::/system.slice/pveproxy.service\n"
"SOCK_END\n"
)
def test_the_driver_declares_the_contract():
assert issubclass(ProxmoxDriver, ListeningSocketsMixin)
def test_it_reads_as_root_over_the_exec_path(driver):
with patch.object(driver, "_exec_ssh_command", return_value=WIRE) as exec_:
reading = driver.get_listening_sockets()
[command] = [c.args[0] for c in exec_.call_args_list]
assert command.startswith("sh -c '")
assert reading["attributed"] is True
[socket] = reading["sockets"]
assert (socket["address"], socket["port"], socket["unit"]) == ("*", 8006, "pveproxy")
+120
View File
@@ -0,0 +1,120 @@
"""Pending updates on a Proxmox node: from where, whether they are security fixes,
and whether the node needs a reboot.
The node's APT API names only an Origin ("Debian", "Proxmox"), the same for the
main and the security archive. ``apt list --upgradable`` over the exec path
names the suite (``trixie-security``), so that is read first; the API remains
the fallback, with the security status left unknown. A reader that cannot read
raises: an empty list would tell netOrk that nothing is pending.
"""
from __future__ import annotations
from unittest.mock import MagicMock, patch
import pytest
from napalm_device_types import HostStatusMixin
from napalm_device_types.host_status import HOST_STATUS_COMMAND
from napalm_device_types.package_updates import APT_UPGRADABLE_COMMAND
from napalm_proxmox.driver import ProxmoxDriver
APT = (
"libssl3t64/stable-security 3.5.1-1+deb13u2 amd64 [upgradable from: 3.5.1-1+deb13u1]\n"
"ceph-common/stable 20.2.4-pve5 amd64 [upgradable from: 20.2.4-pve4]\n"
)
API_ENTRY = {
"Package": "librados2",
"OldVersion": "20.2.4-pve4",
"Version": "20.2.4-pve5",
"Origin": "Proxmox",
}
def _api_updates(driver, entries=None, error=None):
api = MagicMock()
getter = api.nodes.return_value.apt.update.get
if error:
getter.side_effect = error
else:
getter.return_value = entries or []
driver._api = api
return api
class TestAvailableUpdates:
def test_apt_over_the_exec_path_names_the_suite(self, driver):
with patch.object(driver, "_exec_ssh_command", return_value=APT + "__APT_RC=0\n") as exec_:
updates = {u["name"]: u for u in driver.get_available_updates()}
exec_.assert_called_once_with(APT_UPGRADABLE_COMMAND)
assert updates["libssl3t64"]["security"] is True
assert updates["ceph-common"]["security"] is False
assert updates["ceph-common"]["origin"] == "stable"
def test_the_api_is_the_fallback_with_security_unknown(self, driver):
_api_updates(driver, [API_ENTRY])
with patch.object(driver, "_exec_ssh_command", return_value=""):
updates = driver.get_available_updates()
assert updates == [
{
"name": "librados2",
"current_version": "20.2.4-pve4",
"new_version": "20.2.4-pve5",
"origin": "Proxmox",
"security": None,
}
]
def test_a_failed_apt_falls_back_too(self, driver):
_api_updates(driver, [API_ENTRY])
with patch.object(driver, "_exec_ssh_command", return_value="E: lock\n__APT_RC=100\n"):
assert [u["name"] for u in driver.get_available_updates()] == ["librados2"]
def test_nothing_readable_raises_instead_of_reporting_nothing(self, driver):
_api_updates(driver, error=RuntimeError("API timeout"))
with patch.object(driver, "_exec_ssh_command", return_value=""):
with pytest.raises(RuntimeError):
driver.get_available_updates()
def test_nothing_pending_is_an_empty_list(self, driver):
with patch.object(driver, "_exec_ssh_command", return_value="__APT_RC=0\n"):
assert driver.get_available_updates() == []
class TestRefresh:
def test_the_node_refreshes_its_index_through_the_api(self, driver):
api = _api_updates(driver)
api.nodes.return_value.apt.update.post.return_value = "UPID:pve1:0001"
result = driver.refresh_available_updates()
assert result["success"] is True
api.nodes.return_value.apt.update.post.assert_called_once()
def test_a_refused_refresh_says_why(self, driver):
api = _api_updates(driver)
api.nodes.return_value.apt.update.post.side_effect = RuntimeError(
"403 Permission check failed"
)
result = driver.refresh_available_updates()
assert result == {"success": False, "output": "403 Permission check failed"}
class TestHostStatus:
def test_the_node_is_read_over_the_exec_path(self, driver):
report = (
"HSTAT_BEGIN\n[kernel]\n7.0.14-19-pve\n[modules]\n7.0.14-19-pve\n7.0.2-6-pve\n"
"[timers]\napt-daily-upgrade.timer enabled\nHSTAT_END\n"
)
with patch.object(driver, "_exec_ssh_command", return_value=report) as exec_:
status = driver.get_host_status()
exec_.assert_called_once_with(HOST_STATUS_COMMAND)
assert status["reboot_required"] is False
def test_the_driver_declares_the_contract(self):
assert issubclass(ProxmoxDriver, HostStatusMixin)