"""`get_packages` and the source coordinate OSV matching needs. A Proxmox node is a Debian host, so its packages are matched against Debian advisories — and OSV states those ranges in *source* package versions. Reporting the source package without its version leaves a consumer holding two numbers on different axes: `libldb2` is `2:2.11.0+samba4.22.11+dfsg-…` while its source, samba, is `2:4.22.11+dfsg-…`, and comparing the first against a samba range is meaningless. Measured before this was fixed: on three Proxmox nodes, **every one** of their 2 349 packages carried a source package and no source version — 802 of 802, 774 of 774, 773 of 773 — while twenty non-Proxmox hosts had both. The format string simply never asked for the field. """ from __future__ import annotations import pytest # `${Package}\t${Version}\t${db:Status-Status}\t${Installed-Size}\t${source:Package}\t${source:Version}` DPKG = ( "openssh-server\t1:9.2p1-2\tinstalled\t1024\topenssh\t1:9.2p1-2\n" "libldb2\t2:2.11.0+samba4.22.11+dfsg-0+deb13u1\tinstalled\t512\tsamba\t2:4.22.11+dfsg-0+deb13u1\n" "curl\t7.88.1-10\tinstalled\t256\t\t\n" ) @pytest.mark.parametrize("driver_with_exec", [DPKG], indirect=True) def test_the_source_version_is_reported(driver_with_exec): """The field the whole fix is about.""" packages = {p["name"]: p for p in driver_with_exec.get_packages()} assert packages["libldb2"]["source_package"] == "samba" assert packages["libldb2"]["source_version"] == "2:4.22.11+dfsg-0+deb13u1" @pytest.mark.parametrize("driver_with_exec", [DPKG], indirect=True) def test_the_binary_version_is_kept_beside_it(driver_with_exec): """Both are wanted: one says what is installed, the other is the axis the advisory's range is stated on.""" libldb2 = {p["name"]: p for p in driver_with_exec.get_packages()}["libldb2"] assert libldb2["version"] == "2:2.11.0+samba4.22.11+dfsg-0+deb13u1" @pytest.mark.parametrize("driver_with_exec", [DPKG], indirect=True) def test_an_empty_source_falls_back_to_the_package_itself(driver_with_exec): """dpkg leaves both fields empty when the source is the package — and an older dpkg leaves them empty because it does not know the field at all. Neither may produce a package with no coordinate.""" curl = {p["name"]: p for p in driver_with_exec.get_packages()}["curl"] assert curl["source_package"] == "curl" assert curl["source_version"] == "7.88.1-10" def test_the_query_asks_for_the_field(): """The defect was in the format string, not in the parsing: the driver reported a source package it had asked for and a source version it had not, so no amount of parsing could have produced one.""" import inspect from napalm_proxmox import system_mixin source = inspect.getsource(system_mixin.ProxmoxSystemMixin.get_packages) assert "source:Version" in source