fix: say what uninstall_package cannot reach, instead of posting anyway
CI / test (3.10) (push) Failing after 1m10s
CI / test (3.11) (push) Failing after 1m7s
CI / test (3.12) (push) Failing after 13s
CI / test (3.9) (push) Failing after 24s

`firmware/remove` acts on the OPNsense plugin set, and `get_packages`
reads the same list — so software installed as a plain FreeBSD package is
invisible to the one and unreachable by the other. The Wazuh agent is
exactly that, on a driver the agent plugin lists as supported.

Observed during a fleet-wide rollback on 2026-09-19: the `gw` device
could not be handled through netOrk at all, and the request posted for it
could never have succeeded.

A name that is not a plugin now raises NotImplementedError rather than
being POSTed. A request that cannot work reports failure for the wrong
reason and sends whoever reads it looking in the wrong place; netOrk
turns NotImplementedError into a 501, which is the accurate answer.

Reaching plain packages would need shell access, and the credentials
stored for these devices are frequently API-key only — that is a decision
of its own, not a detail of this one.

The injection guard still runs first: a malformed name is a ValueError
before anything asks whether it is a plugin.

netork#241
This commit is contained in:
Christian Manivong
2026-09-20 22:44:04 +02:00
parent 5d193ba7e8
commit 4dd0fc2aee
2 changed files with 70 additions and 0 deletions
+20
View File
@@ -2126,10 +2126,30 @@ class OPNsenseDriver(OPNsensePingMixin, FirewallDriver):
"""Remove an OPNsense plugin by name.
Calls ``POST /api/core/firmware/remove/{name}``.
**Plugins only, and it says so.** ``firmware/remove`` acts on the
plugin set, and ``get_packages`` reads the same list — so software
installed as a plain FreeBSD package is invisible to the one and
unreachable by the other. The Wazuh agent is exactly that, on a driver
the agent plugin lists as supported, and during a fleet-wide rollback
the request posted for it could never have succeeded.
Raising beats posting. A request that cannot work reports failure for
the wrong reason and sends whoever reads it looking in the wrong place;
netOrk turns ``NotImplementedError`` into a 501, which is the accurate
answer. Reaching plain packages would need shell access, and the
credentials stored for these devices are frequently API-key only —
a decision of its own rather than a detail of this one.
"""
import re as _re
if not _re.match(r'^[a-zA-Z0-9_\-\.]+$', name):
raise ValueError(f"Invalid package name: {name!r}")
if not name.startswith("os-"):
raise NotImplementedError(
f"{name!r} is not an OPNsense plugin. This driver can remove plugins "
"(os-*) through the firmware API; a FreeBSD package needs shell access, "
"which is not configured for OPNsense devices."
)
try:
result = self._post(f"/api/core/firmware/remove/{name}")
return {"success": True, "output": str(result)}