Commit Graph
14 Commits
Author SHA1 Message Date
Christian Manivong e3a9f4d8b2 feat: report running_kernel (uname -r) in get_facts
Distinguishes the currently-booted kernel from a newer installed-but-not-yet-
booted one, for kernel CVE relevance.
2026-08-23 19:06:10 +07:00
Christian Manivong 20fcf2ebc3 fix: four real defects the fourteen failing tests were pointing at
Closes netork#115.

The suite had been red long enough that it stopped being read. Four of the
fourteen failures were the tests being right.

`interfaces_mixin.py` used `re.match` without importing `re`, so
`get_mac_address_table` raised NameError against any node with a Linux bridge.
The tests never reached that line: they mocked the API call underneath
`_exec_ssh_command`, which takes two positional arguments where the doubles
accepted one, and which base64-wraps the command — so a fixture keyed on
"bridge fdb" appearing in the text matched nothing and the helper returned "".
They mock `_exec_ssh_command` itself now, which is the driver's own seam.

`is_alive` called `_resolve_node()`, which returns early without touching the
API whenever a node was configured through optional_args. A dead connection
reported itself alive. It probes `GET /version` now.

The documented `realm` optional_arg was read into `self._realm` in `__init__`
and then never used. Proxmox authenticates against "<user>@<realm>" and rejects
a bare username, so the option had no effect and callers had to know to type the
realm themselves.

`get_vlans` filtered out entries with no member ports on one return path while
the OVS path returned them, so a configured SDN VNet was visible or invisible
depending on which branch ran. A VNet exists on the node whether or not anything
is attached to it, and netOrk's VLAN discovery reads this.

`get_ipv6_neighbors_table` was simply missing and fell through to NAPALM's stub;
it is implemented against `ip -6 neigh show`, dropping FAILED entries.

The rest were stale tests. The DNS fixture put an FQDN where a search domain
belongs, which made `get_facts` build "pve1.pve1.example.com" and look like a
driver bug. The LLDP fixture was a simplified shape that real `lldpcli show
neighbors summary` does not produce — the parser matches on the ", via: LLDP"
that follows the interface name. And `test_bridge_vlan_show_parsing` covered a
fallback that was replaced by VM-config scanning, asserting an "interfaces" key
this method has never returned; it is now a test of the fallback that exists.
2026-08-21 13:22:03 +07:00
Christian Manivong 51f67704e1 feat: declare USES_SSH = False and REBOOT_SETTLE_SECONDS = 90
Both were facts about this driver that netOrk kept in hardcoded driver-name
sets, each duplicated across a file pair (netork#113). The driver is the right
place for them: everything runs over the PVE REST API, and a node reboots
through a full init sequence plus storage checks before it is worth polling.
2026-08-21 13:07:14 +07:00
Christian ManivongandClaude Haiku 4.5 7bdac4c496 feat(provisioning): implement VM provisioning mixin for Proxmox
Add ProxmoxVMProvisionMixin with three methods:
- create_vm_from_cloud_init(): clone template → dual-NIC config → Cloud-Init → start
- destroy_vm(): stop → delete VM → cleanup snippets
- get_vm_status(): poll guest-agent for IP with optional wait-for-IP polling

Tests (9 cases):
- _wait_for_task success/error/timeout handling
- create_vm happy path + missing snippet storage error
- get_vm_status with/without wait-for-IP, timeout handling
- destroy_vm on running or already-stopped VM

All tests pass (100% coverage on mixin code paths).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-07-06 22:03:41 +02:00
Christian ManivongandClaude Sonnet 4.6 243e66a893 feat: Fingerprint-Attribute für Discovery-Scoring
Ergänzt DRIVER_NAME, HTTP_FINGERPRINT, SNMP_FINGERPRINT, SSH_FINGERPRINT,
PORT_SPECS und SNMP_OBJECT_ID_PREFIX gemäß docs/DISCOVERY_FINGERPRINTING.md.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-24 14:47:08 +02:00
Christian ManivongandClaude Sonnet 4.6 50ccf654ba fix: prefer product_version only when it contains a space (marketing name)
product_version is used as model only when it contains a space, indicating
a human-readable marketing name (e.g. "ThinkCentre M910x"). Part numbers
like "J26843-409" have no space and are skipped — product_name is used
instead (e.g. "NUC6CAYH" for Intel NUC).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-22 22:09:06 +02:00
Christian ManivongandClaude Sonnet 4.6 d9b3ac12ea fix: read DMI fields separately to avoid shell quoting issues
The combined printf approach silently produced empty values when
product_name/version contained special chars or the shell split tokens
incorrectly. Read each /sys/class/dmi/id/ file via a separate cat,
collect lines, then apply vendor-specific model name selection:

- Intel NUC: product_name='NUC6CAYH' (marketing) preferred over
  product_version='J26843-409' (part number)
- Lenovo: product_name='10MYS03U00' (type code, all-caps+digits) →
  prefer product_version='ThinkCentre M910x' (marketing name)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-22 22:02:24 +02:00
Christian ManivongandClaude Sonnet 4.6 a3b0414d99 fix: prefer product_version over product_name for DMI model name
On Lenovo (and some other vendors) product_name contains the machine-type
code (e.g. "10MYS03U00") while product_version holds the marketing name
(e.g. "ThinkCentre M910x"). Read both and prefer product_version when it
is set and different from product_name.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-22 20:08:54 +02:00
Christian ManivongandClaude Sonnet 4.6 9631275d6b fix: get_facts() reads physical hardware info from DMI sysfs via SSH
vendor, model and serial_number now come from /sys/class/dmi/id/
(sys_vendor, product_name, product_serial) via SSH, reflecting the
actual physical server rather than the Proxmox software layer.

Falls back to "Proxmox Server Solutions GmbH" / status.model if SSH
or DMI files are unavailable (e.g. bare-metal without SSH creds).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-22 20:03:14 +02:00
Christian ManivongandClaude Sonnet 4.6 b1ba991e6d feat: set_hostname — update /etc/hostname, /etc/hosts, cert, Postfix
Implements set_hostname on ProxmoxSystemMixin:
1. Writes /etc/hostname (short name, base64-safe transfer)
2. Replaces old hostname in /etc/hosts via Python regex + base64
3. Updates /etc/mailname if present
4. Updates Postfix myhostname via postconf -e if installed
5. Applies hostname immediately at runtime via hostname(1)
6. Regenerates Proxmox node TLS certificate via pvecm updatecerts -f
   (falls back to pvenode cert create → pveproxy restart)

Accepts bare hostname or FQDN. A reboot is required for the Proxmox
node name to update in the web UI / cluster — the driver logs this.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-19 16:30:45 +02:00
Christian Manivong d1e6931ec5 fix: derive VLANs from VM net tags and fix update warning consistency
get_vlans() previously parsed 'bridge vlan show' which trunks all 4094
VIDs by default on VLAN-aware bridges, producing phantom VLAN entries.
Now derives real VLAN assignments from VM/container netN bridge=,tag=
config. get_device_warnings() now reports updates_available with
severity "warning" and a full package list/title, matching the format
used when the warning is refreshed via the updates API (previously
alternated between "info" and "warning" for the same content).
2026-06-12 21:08:08 +02:00
Christian ManivongandClaude Sonnet 4.6 5732a4494e feat: detect missing lldpd and add install_lldpd action
get_device_warnings() now reports lldpd_not_installed (action
install_lldpd) when lldpd is absent, matching the existing
OpenWrt pattern. run_device_action("install_lldpd") installs and
enables lldpd via apt/systemd so LLDP topology links to directly
connected switches can be discovered.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-10 08:34:18 +02:00
Christian ManivongandClaude Sonnet 4.6 90d6592159 fix: accept ssl_verify and verify aliases alongside verify_ssl
Mirrors the robust fallback pattern from napalm-opnsense so the driver
works regardless of which key name the caller passes in optional_args.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-04 22:40:35 +02:00
Christian Manivong f3ecf14c8d initial commit 2026-05-29 09:24:39 +02:00