Commit Graph
10 Commits
Author SHA1 Message Date
Christian ManivongandClaude Sonnet 4.6 ee69ec8da9 fix: mixin classes must precede AccessPointDriver in OpenWrtDriver MRO
NetworkDriver (parent of AccessPointDriver) raises NotImplementedError for all
standard NAPALM methods. With AccessPointDriver listed first, get_interfaces()
and get_vlans() from the mixins were shadowed and always raised NotImplementedError
(empty message) — causing all AP polls to report 0 interfaces and 0 VLANs.

Fix: reorder inheritance so mixins come before AccessPointDriver. The standard
NAPALM method stubs in NetworkDriver are now shadowed by the mixin implementations.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-25 13:48:25 +02:00
Christian ManivongandClaude Sonnet 4.6 e3a0a9e4b3 feat: Fingerprint-Attribute für Discovery-Scoring
Ergänzt DRIVER_NAME, HTTP_FINGERPRINT, SNMP_FINGERPRINT, SSH_FINGERPRINT,
PORT_SPECS und SNMP_OBJECT_ID_PREFIX gemäß docs/DISCOVERY_FINGERPRINTING.md.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-24 14:47:08 +02:00
Christian ManivongandClaude Sonnet 4.6 042a2b6d2e fix: get_facts() reads hardware vendor from /tmp/sysinfo/board_name
board_name format is "vendor,model" (e.g. "sophos,ap100"). The prefix
before the comma is title-cased to give the manufacturer name (e.g.
"Sophos"). Falls back to "OpenWrt" when board_name is unavailable.

The model is already read from /tmp/sysinfo/model which gives the full
human-readable name (e.g. "Sophos AP100") — no change needed there.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-22 22:37:25 +02:00
Christian ManivongandClaude Sonnet 4.6 b7e4831b26 fix: _action_fix_snmp uses src=<mgmt_zone> in firewall rule
The previous attempt added a rule without src= which lands in the global
nftables input chain. Traffic from the management interface (br-ap.10)
jumps immediately to input_mgmt, so the global rule was never reached.

Now detects the management zone name by finding the zone whose allow-SSH
rule already exists (the named rule pattern allow_ssh_from_<zone>).
Removes any mis-scoped previous SNMP rule, then adds a named UCI rule
allow_snmp_from_<zone> with src=<zone> so fw4 places it in the correct
chain (input_mgmt). Persists across reboots via uci commit + fw4 reload.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-19 22:03:33 +02:00
Christian ManivongandClaude Sonnet 4.6 e05d878f94 fix: implement _action_fix_snmp for OpenWRT
The method was called but missing — always raised AttributeError, so
Fix SNMP did nothing on OpenWRT devices.

OpenWRT's default firewall (fw4) policy-drops everything except the
ports explicitly listed in the management zone (SSH/HTTP/HTTPS/ICMP).
SNMP (UDP/161) is not in that list, which is why snmpd runs but is
unreachable from outside the device.

Fix adds a persistent UCI firewall rule for UDP/161, reloads fw4
immediately, verifies snmpd is running, and probes locally if SNMP
client tools are available. Returns success so callers can clear the
snmp_no_data warning.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-19 21:35:30 +02:00
Christian ManivongandClaude Sonnet 4.6 85041c13bb fix: configure lldpd on bridge interface, not VLAN subinterface
Added _lldpd_fix_interface() helper that detects the management interface
via the default route and strips any .VID suffix (e.g. br-ap.10 → br-ap).
LLDP is L2 and must run on the bridge itself — sending on a VLAN subinterface
produces tagged frames the switch won't recognize as LLDP.

The helper runs every poll so existing wrong configs (e.g. eth0 from the
original install action) are corrected automatically on the next poll.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-10 00:23:33 +02:00
Christian ManivongandClaude Sonnet 4.6 77c9d386db fix: return key (PSK) from get_ssids() for drift detection
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-04 13:28:40 +02:00
Christian ManivongandClaude Sonnet 4.6 0493520e5f fix: extract clean package names in updates_available warning meta
opkg list-upgradable and apk version output contains version strings and
comparison operators; meta.packages now stores only the bare package name
so the schedule-updates API validation passes.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-02 13:28:07 +02:00
Christian ManivongandClaude Sonnet 4.6 64964c1b33 feat: SNMP support — get_snmp_config(), fix_snmp action
Install snmpd-nossl + luci-app-snmpd via opkg, configure via UCI with correct
field names (group/viewname/context='none'), bare port 161, stop+pkill before
start to break crash loops. get_snmp_config() reads current UCI snmpd state.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-01 13:09:32 +02:00
Christian Manivong 1f0349aee9 initial commit 2026-05-29 09:10:40 +02:00