A Proxmox node runs its own kernel under every guest, which makes it the host where a kernel CVE's preconditions matter most. ProxmoxDriver mixes in KernelFactsMixin from napalm-device-types and supplies only the transport, the existing exec path. Requires napalm-device-types 2.1.0.
47 lines
1.6 KiB
Python
47 lines
1.6 KiB
Python
"""`get_kernel_facts`: what the node's kernel has built and loaded.
|
|
|
|
A Proxmox node runs its own kernel under every guest, which makes it the host
|
|
where a kernel CVE's preconditions matter most. The command and its parse are
|
|
napalm-device-types'; the driver only carries the command over its exec path.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import base64
|
|
import gzip
|
|
from unittest.mock import patch
|
|
|
|
import pytest
|
|
|
|
from napalm_device_types import KernelFactsMixin
|
|
from napalm_device_types.kernel import KERNEL_FACTS_COMMAND
|
|
from napalm_proxmox.driver import ProxmoxDriver
|
|
|
|
REPORT = (
|
|
"[release]\n6.8.12-4-pve\n[loaded]\nkvm_intel\n[builtin]\nkernel/net/ipv4/tcp_cubic.ko\n"
|
|
"[available]\nkernel/net/tipc/tipc.ko\n[config]\nCONFIG_TIPC=m\n"
|
|
)
|
|
WIRE = "KFACTS_BEGIN\n" + base64.encodebytes(gzip.compress(REPORT.encode())).decode() + "KFACTS_END"
|
|
|
|
|
|
def test_the_driver_declares_the_contract():
|
|
assert issubclass(ProxmoxDriver, KernelFactsMixin)
|
|
|
|
|
|
def test_it_runs_the_shared_command(driver):
|
|
with patch.object(driver, "_exec_ssh_command", return_value=WIRE) as exec_:
|
|
facts = driver.get_kernel_facts()
|
|
|
|
exec_.assert_called_once_with(KERNEL_FACTS_COMMAND)
|
|
assert facts["release"] == "6.8.12-4-pve"
|
|
assert facts["loaded"] == ["kvm_intel"]
|
|
assert facts["builtin"] == ["tcp_cubic"]
|
|
assert facts["available"] == ["tipc"]
|
|
assert facts["config"] == {"CONFIG_TIPC": "m"}
|
|
|
|
|
|
def test_output_without_a_report_raises(driver):
|
|
with patch.object(driver, "_exec_ssh_command", return_value=""):
|
|
with pytest.raises(ValueError):
|
|
driver.get_kernel_facts()
|