feat: report where an update comes from and whether it is a security fix, refresh the index, read the host status
For netOrk MVP 5, on napalm-device-types 2.3.0: - get_available_updates (apt) runs the shared APT_UPGRADABLE_COMMAND and parse_apt_upgradable: origin and security from apt's suites, and a ValueError instead of [] when apt failed or its output was cut short. - dnf/yum: check-update's exit status decides (0 none, 100 updates, anything else raises); security comes from `updateinfo list --security`, and is None when dnf cannot say. The repository column becomes the origin. - refresh_available_updates(): apt-get update, dnf/yum makecache, apk update; pacman is left out (-Sy without -u invites a partial upgrade). - HostStatusMixin: reboot required and self-patching, read over SSH. - _run_privileged(): root runs directly, a sudo password goes through _sudo, otherwise sudo -n. Shared by service control and the refresh. - _split_status() drops terminal codes before it looks for the exit status; a pseudo-terminal left keypad codes in front of the marker. OpenMediaVault inherits all of it.
This commit is contained in:
+80
-38
@@ -32,11 +32,17 @@ from netmiko.exceptions import (
|
||||
from napalm.base.exceptions import ConnectionException, ConnectionClosedException
|
||||
from napalm.base.netmiko_helpers import netmiko_args
|
||||
from napalm_device_types import (
|
||||
APT_UPGRADABLE_COMMAND,
|
||||
DNF_SECURITY_COMMAND,
|
||||
FingerprintRule,
|
||||
HostStatusMixin,
|
||||
KernelFactsMixin,
|
||||
OSDriver,
|
||||
SystemdServicesMixin,
|
||||
SystemdUnavailable,
|
||||
parse_apt_upgradable,
|
||||
parse_dnf_security,
|
||||
strip_terminal_codes,
|
||||
)
|
||||
from napalm_device_types.models import (
|
||||
ApplyUpdatesResultDict,
|
||||
@@ -62,6 +68,33 @@ _PKG_MANAGERS = ["apt", "dnf", "yum", "apk", "pacman"]
|
||||
_RC_MARKER = "__NETORK_RC="
|
||||
_RC_MARKER_RE = re.compile(rf"^{_RC_MARKER}(\d+)\s*$", re.MULTILINE)
|
||||
|
||||
|
||||
def _split_status(raw: str) -> tuple[str, int | None]:
|
||||
"""``(output, exit_status)`` of a command followed by ``echo {_RC_MARKER}$?``.
|
||||
|
||||
The status is ``None`` when the marker never arrived (output cut short), so
|
||||
a caller can tell "unknown" from "succeeded".
|
||||
"""
|
||||
raw = strip_terminal_codes(raw)
|
||||
matches = list(_RC_MARKER_RE.finditer(raw))
|
||||
if not matches:
|
||||
return raw, None
|
||||
last = matches[-1]
|
||||
return (raw[: last.start()] + raw[last.end():]).strip(), int(last.group(1))
|
||||
|
||||
|
||||
#: How each package manager refreshes its index. pacman is left out on purpose:
|
||||
#: ``pacman -Sy`` without ``-u`` invites a partial upgrade on the next install.
|
||||
_REFRESH = {
|
||||
# No LC_ALL=C here: under sudo it is an environment variable sudoers may refuse
|
||||
# to set. Only the exit status decides, so the language is merely what is shown.
|
||||
"apt": "apt-get update -q 2>&1",
|
||||
"dnf": "dnf makecache -q 2>&1",
|
||||
"yum": "yum makecache -q 2>&1",
|
||||
"apk": "apk update -q 2>&1",
|
||||
}
|
||||
_YUM_SECURITY_COMMAND = "LC_ALL=C yum updateinfo list security -q 2>/dev/null"
|
||||
|
||||
#: What to do when sudo wants a password netOrk does not have.
|
||||
_SUDO_PASSWORD_HINT = (
|
||||
"sudo requires a password on this device but none is configured in netOrk. "
|
||||
@@ -151,7 +184,7 @@ def _short_image_id(raw: str) -> str:
|
||||
return raw.strip().removeprefix("sha256:")[:12]
|
||||
|
||||
|
||||
class LinuxDriver(KernelFactsMixin, SystemdServicesMixin, OSDriver):
|
||||
class LinuxDriver(KernelFactsMixin, SystemdServicesMixin, HostStatusMixin, OSDriver):
|
||||
"""NAPALM driver for generic Linux systems.
|
||||
|
||||
Connects via SSH (netmiko ``linux`` device type) and auto-detects the
|
||||
@@ -297,13 +330,9 @@ class LinuxDriver(KernelFactsMixin, SystemdServicesMixin, OSDriver):
|
||||
The status is ``None`` when the marker never arrived (output cut short),
|
||||
so a caller can tell "unknown" from "succeeded".
|
||||
"""
|
||||
raw = self._sudo(f"{command}; echo {_RC_MARKER}$?", read_timeout=read_timeout)
|
||||
matches = list(_RC_MARKER_RE.finditer(raw))
|
||||
if not matches:
|
||||
return raw, None
|
||||
last = matches[-1]
|
||||
output = (raw[: last.start()] + raw[last.end():]).strip()
|
||||
return output, int(last.group(1))
|
||||
return _split_status(
|
||||
self._sudo(f"{command}; echo {_RC_MARKER}$?", read_timeout=read_timeout)
|
||||
)
|
||||
|
||||
def _is_root(self) -> bool:
|
||||
"""Whether the SSH user is root, asked once per session.
|
||||
@@ -321,12 +350,24 @@ class LinuxDriver(KernelFactsMixin, SystemdServicesMixin, OSDriver):
|
||||
Without a sudo password, ``sudo -n`` fails at once where a prompt would
|
||||
otherwise hang the session until the read timeout.
|
||||
"""
|
||||
if not privileged or self._is_root():
|
||||
if not privileged:
|
||||
return self._send(command, read_timeout=timeout)
|
||||
return self._run_privileged(command, timeout)
|
||||
|
||||
def _run_privileged(self, command: str, timeout: float = 100) -> str:
|
||||
"""Run *command* as root: directly for a root login, through ``_sudo``
|
||||
with a sudo password, and through ``sudo -n`` without one -- which fails at
|
||||
once where a password prompt would hang the session until the timeout."""
|
||||
if self._is_root():
|
||||
return self._send(command, read_timeout=timeout)
|
||||
if self._sudo_password:
|
||||
return self._sudo(command, read_timeout=timeout)
|
||||
return self._send(f"sudo -n {command}", read_timeout=timeout)
|
||||
|
||||
def _run_host_status_command(self, command: str) -> str:
|
||||
"""The transport for ``HostStatusMixin.get_host_status``: read-only, no sudo."""
|
||||
return self._send(command, read_timeout=60)
|
||||
|
||||
def _detect_pkg_manager(self) -> str | None:
|
||||
"""Return the first package manager binary found on PATH."""
|
||||
for pm in _PKG_MANAGERS:
|
||||
@@ -1243,48 +1284,49 @@ class LinuxDriver(KernelFactsMixin, SystemdServicesMixin, OSDriver):
|
||||
def _get_updates_apt(self) -> list[UpdateDict]:
|
||||
# apt list --upgradable does not need root; avoid sudo so it works even
|
||||
# without a configured sudo password.
|
||||
out = self._send(
|
||||
"LC_ALL=C apt list --upgradable 2>/dev/null | grep -v '^Listing'",
|
||||
read_timeout=60,
|
||||
)
|
||||
# Join wrapped lines: netmiko's 80-col pseudo-TTY causes long apt lines to
|
||||
# break; continuation lines start with a space.
|
||||
raw_lines: List[str] = []
|
||||
for line in out.splitlines():
|
||||
if line.startswith(" ") and raw_lines:
|
||||
raw_lines[-1] += line.strip()
|
||||
else:
|
||||
raw_lines.append(line)
|
||||
updates: list[UpdateDict] = []
|
||||
for line in raw_lines:
|
||||
# openssh-server/stable 1:9.2p1-2+deb12u2 amd64 [upgradable from: 1:9.2p1-2+deb12u1]
|
||||
m = re.match(
|
||||
r"^(\S+)/\S+\s+(\S+)\s+\S+\s+\[upgradable from:\s+(\S+)\]", line
|
||||
)
|
||||
if m:
|
||||
updates.append({
|
||||
"name": m.group(1),
|
||||
"current_version": m.group(3),
|
||||
"new_version": m.group(2),
|
||||
})
|
||||
return updates
|
||||
# Raises ValueError when apt failed or the output was cut short.
|
||||
return parse_apt_upgradable(self._send(APT_UPGRADABLE_COMMAND, read_timeout=60))
|
||||
|
||||
def _get_updates_rpm(self) -> list[UpdateDict]:
|
||||
"""dnf/yum check-update: exit 100 means updates, 0 none, anything else failed."""
|
||||
cmd = "dnf check-update --quiet 2>/dev/null" if self._pkg_manager == "dnf" else "yum check-update -q 2>/dev/null"
|
||||
out = self._sudo(cmd)
|
||||
output, status = _split_status(self._run_privileged(f"{cmd}; echo {_RC_MARKER}$?", 120))
|
||||
if status not in (0, 100):
|
||||
raise RuntimeError(f"{self._pkg_manager} check-update failed (exit {status}): {output[-200:]}")
|
||||
security = self._rpm_security_names()
|
||||
updates: list[UpdateDict] = []
|
||||
for line in out.splitlines():
|
||||
for line in output.splitlines():
|
||||
parts = line.split()
|
||||
if len(parts) >= 2 and not line.startswith(" ") and "." in parts[0]:
|
||||
name_arch = parts[0]
|
||||
name = name_arch.rsplit(".", 1)[0] if "." in name_arch else name_arch
|
||||
name = parts[0].rsplit(".", 1)[0]
|
||||
updates.append({
|
||||
"name": name,
|
||||
"current_version": "",
|
||||
"new_version": parts[1],
|
||||
"origin": parts[2] if len(parts) >= 3 else None,
|
||||
"security": None if security is None else name in security,
|
||||
})
|
||||
return updates
|
||||
|
||||
def _rpm_security_names(self) -> set[str] | None:
|
||||
"""Packages a pending security advisory covers; None when dnf/yum cannot say."""
|
||||
cmd = DNF_SECURITY_COMMAND if self._pkg_manager == "dnf" else _YUM_SECURITY_COMMAND
|
||||
output, status = _split_status(self._run_privileged(f"{cmd}; echo {_RC_MARKER}$?", 120))
|
||||
return parse_dnf_security(output) if status == 0 else None
|
||||
|
||||
def refresh_available_updates(self) -> dict[str, Any]:
|
||||
"""Refresh the package index (apt-get update, dnf makecache, apk update)."""
|
||||
cmd = _REFRESH.get(self._pkg_manager or "")
|
||||
if cmd is None:
|
||||
return {
|
||||
"success": False,
|
||||
"output": f"Refreshing the index is not supported for {self._pkg_manager!r}",
|
||||
}
|
||||
output, status = _split_status(self._run_privileged(f"{cmd}; echo {_RC_MARKER}$?", 180))
|
||||
if status != 0 and "password is required" in output:
|
||||
output = f"{output}\n{_SUDO_PASSWORD_HINT}"
|
||||
return {"success": status == 0, "output": output}
|
||||
|
||||
def _get_updates_apk(self) -> list[UpdateDict]:
|
||||
out = self._send("apk version -l '<' 2>/dev/null")
|
||||
updates: list[UpdateDict] = []
|
||||
|
||||
Reference in New Issue
Block a user