fix: say what uninstall_package cannot reach, instead of posting anyway
CI / test (3.10) (push) Failing after 1m10s
CI / test (3.11) (push) Failing after 1m7s
CI / test (3.12) (push) Failing after 13s
CI / test (3.9) (push) Failing after 24s

`firmware/remove` acts on the OPNsense plugin set, and `get_packages`
reads the same list — so software installed as a plain FreeBSD package is
invisible to the one and unreachable by the other. The Wazuh agent is
exactly that, on a driver the agent plugin lists as supported.

Observed during a fleet-wide rollback on 2026-09-19: the `gw` device
could not be handled through netOrk at all, and the request posted for it
could never have succeeded.

A name that is not a plugin now raises NotImplementedError rather than
being POSTed. A request that cannot work reports failure for the wrong
reason and sends whoever reads it looking in the wrong place; netOrk
turns NotImplementedError into a 501, which is the accurate answer.

Reaching plain packages would need shell access, and the credentials
stored for these devices are frequently API-key only — that is a decision
of its own, not a detail of this one.

The injection guard still runs first: a malformed name is a ValueError
before anything asks whether it is a plugin.

netork#241
This commit is contained in:
Christian Manivong
2026-09-20 22:44:04 +02:00
parent 5d193ba7e8
commit 4dd0fc2aee
2 changed files with 70 additions and 0 deletions
+50
View File
@@ -2544,3 +2544,53 @@ class TestSyncDnsZone:
added = [d for p, d in calls if p.endswith("addhostoverride")]
assert len(added) == 1
# ---------------------------------------------------------------------------
# uninstall_package – says what it cannot do
# ---------------------------------------------------------------------------
class TestUninstallPackage:
"""`firmware/remove` reaches OPNsense plugins and nothing else.
`get_packages` reads `/api/core/firmware/info` filtered to the plugin list,
and `firmware/remove` acts on the same set. Software installed as a plain
FreeBSD package is invisible to the first and unreachable by the second —
the Wazuh agent being exactly that, on a driver the agent plugin lists as
supported.
Observed during a fleet-wide rollback on 2026-09-19: the `gw` device could
not be handled through netOrk at all, and the request that was posted for
it could never have succeeded.
So it refuses instead of posting. A request that cannot work is worse than
an honest no: the caller stops looking for the real problem. The API turns
NotImplementedError into 501, which is the accurate answer.
"""
def test_a_plugin_is_removed(self, driver):
driver._post = MagicMock(return_value={"status": "ok"})
result = driver.uninstall_package("os-wazuh-agent")
assert result["success"] is True
driver._post.assert_called_once()
def test_a_freebsd_package_is_refused(self, driver):
driver._post = MagicMock()
with pytest.raises(NotImplementedError, match="plugin"):
driver.uninstall_package("wazuh-agent")
driver._post.assert_not_called()
def test_the_refusal_names_the_package(self, driver):
"""Whoever reads the 501 needs to know which name was rejected."""
with pytest.raises(NotImplementedError, match="wazuh-agent"):
driver.uninstall_package("wazuh-agent")
def test_a_malformed_name_is_still_a_ValueError(self, driver):
"""Refusing non-plugins must not swallow the injection guard."""
with pytest.raises(ValueError):
driver.uninstall_package("os-thing; rm -rf /")