Squashed commit of the following:
commit 4081e22202693bd7c4ea00e95daad8e628c6fd5a
Author: Oliver Gorwits <oliver@cpan.org>
Date:   Mon May 29 21:02:07 2023 +0100
    large rename of check_acl* to acl_matches*
commit 3cfa284ddd24d68765c255578cc5c184afbdcd83
Author: Oliver Gorwits <oliver@cpan.org>
Date:   Fri May 19 20:39:03 2023 +0100
    update permission doc
commit 8c7bb93cc5e9fafb770f98f446e45cbd94b14894
Author: Oliver Gorwits <oliver@cpan.org>
Date:   Wed May 17 21:50:07 2023 +0100
    migrate most check_acl_only to acl_matches_only
commit c47f699f2a22f08f2f3e093ed0f24c891e6f9a82
Author: Oliver Gorwits <oliver@cpan.org>
Date:   Wed May 17 21:39:19 2023 +0100
    rename check_acl* to be acl_matches*
commit a884a22c3ab1f3262118c3a47ed8e25b0b0a7336
Author: Oliver Gorwits <oliver@cpan.org>
Date:   Sun May 14 16:50:42 2023 +0100
    update macsuck_no_deviceports to use acl_matches
commit 8c256af728721329b64d071fa529dfc844073ac6
Author: Oliver Gorwits <oliver@cpan.org>
Date:   Sun May 7 22:54:33 2023 +0100
    update hide_deviceports to use acl_matches multi @things
commit cd5d9978aba1da459be4fed4500f395df13f7784
Author: Oliver Gorwits <oliver@cpan.org>
Date:   Sun May 7 22:53:38 2023 +0100
    check_acl fix to allow all @things to offer a property before fallback to missing as empty string
commit 1a3ab9a7646e9f994f03126d45fc36e9e5a13ed5
Author: Oliver Gorwits <oliver@cpan.org>
Date:   Tue May 2 15:31:17 2023 +0100
    add ignore_deviceports to portproperties discover; improve comments
commit 51385ce89458dc939587dae902fda431719c22c9
Merge: b97c07d2 3f8ffe78
Author: Oliver Gorwits <oliver@cpan.org>
Date:   Tue May 2 15:21:48 2023 +0100
    Merge branch 'master' into og-acl_multidict
commit b97c07d237d750c1d9eb3095d8ff3908512eac2a
Author: Oliver Gorwits <oliver@cpan.org>
Date:   Sat Mar 25 14:37:53 2023 +0000
    add support for arrayref of items, and unblessed hash, to check_acl
		
	
		
			
				
	
	
		
			75 lines
		
	
	
		
			2.0 KiB
		
	
	
	
		
			Perl
		
	
	
	
	
	
			
		
		
	
	
			75 lines
		
	
	
		
			2.0 KiB
		
	
	
	
		
			Perl
		
	
	
	
	
	
| package App::Netdisco::Worker::Plugin::Arpnip::Subnets;
 | |
| 
 | |
| use Dancer ':syntax';
 | |
| use App::Netdisco::Worker::Plugin;
 | |
| use aliased 'App::Netdisco::Worker::Status';
 | |
| 
 | |
| use App::Netdisco::Transport::SNMP ();
 | |
| use App::Netdisco::Util::Permission 'acl_matches';
 | |
| use Dancer::Plugin::DBIC 'schema';
 | |
| use NetAddr::IP::Lite ':lower';
 | |
| use Time::HiRes 'gettimeofday';
 | |
| 
 | |
| register_worker({ phase => 'main', driver => 'snmp' }, sub {
 | |
|   my ($job, $workerconf) = @_;
 | |
| 
 | |
|   my $device = $job->device;
 | |
|   my $snmp = App::Netdisco::Transport::SNMP->reader_for($device)
 | |
|     or return Status->defer("arpnip failed: could not SNMP connect to $device");
 | |
| 
 | |
|   # get directly connected networks
 | |
|   my @subnets = gather_subnets($device);
 | |
|   # TODO: IPv6 subnets
 | |
| 
 | |
|   my $now = 'to_timestamp('. (join '.', gettimeofday) .')::timestamp';
 | |
|   store_subnet($_, $now) for @subnets;
 | |
| 
 | |
|   return Status->info(sprintf ' [%s] arpnip - processed %s Subnet entries',
 | |
|     $device->ip, scalar @subnets);
 | |
| });
 | |
| 
 | |
| # gathers device subnets
 | |
| sub gather_subnets {
 | |
|   my $device = shift;
 | |
|   my @subnets = ();
 | |
| 
 | |
|   my $snmp = App::Netdisco::Transport::SNMP->reader_for($device)
 | |
|     or return (); # already checked!
 | |
| 
 | |
|   my $ip_netmask = $snmp->ip_netmask;
 | |
|   foreach my $entry (keys %$ip_netmask) {
 | |
|       my $ip = NetAddr::IP::Lite->new($entry) or next;
 | |
|       my $addr = $ip->addr;
 | |
| 
 | |
|       next if $addr eq '0.0.0.0';
 | |
|       next if acl_matches($ip, 'group:__LOOPBACK_ADDRESSES__');
 | |
|       next if setting('ignore_private_nets') and $ip->is_rfc1918;
 | |
| 
 | |
|       my $netmask = $ip_netmask->{$addr} || $ip->bits();
 | |
|       next if $netmask eq '255.255.255.255' or $netmask eq '0.0.0.0';
 | |
| 
 | |
|       my $cidr = NetAddr::IP::Lite->new($addr, $netmask)->network->cidr;
 | |
| 
 | |
|       debug sprintf ' [%s] arpnip - found subnet %s', $device->ip, $cidr;
 | |
|       push @subnets, $cidr;
 | |
|   }
 | |
| 
 | |
|   return @subnets;
 | |
| }
 | |
| 
 | |
| # update subnets with new networks
 | |
| sub store_subnet {
 | |
|   my ($subnet, $now) = @_;
 | |
| 
 | |
|   schema('netdisco')->txn_do(sub {
 | |
|     schema('netdisco')->resultset('Subnet')->update_or_create(
 | |
|     {
 | |
|       net => $subnet,
 | |
|       last_discover => \$now,
 | |
|     },
 | |
|     { for => 'update' });
 | |
|   });
 | |
| }
 | |
| 
 | |
| true;
 |