Fills in the three device-specific methods so the generic diff/apply from napalm-device-types works against OPNsense: searchReservation for the read, addReservation/setReservation for the write, service/reconfigure for the commit. Until now the driver could only create and delete reservations as a side-effect of VM provisioning, and never read them back — so there was no way to see what a firewall already had. Kea's `subnet` field on a reservation is a model relation that comes back as the related subnet's CIDR in some versions and as its UUID in others. Both are accepted and normalised to a CIDR; an unresolvable relation degrades to an empty string rather than raising, so one orphaned entry cannot make the whole inventory unreadable. apply_dhcp_reservation deliberately does not reconfigure: that is the commit's job, so a batch costs one daemon reload instead of one per entry. Verified against mocked Kea responses only — no live OPNsense was available at the time of writing. The CIDR-vs-UUID branch in particular is defensive rather than empirically confirmed.