mirror of
https://github.com/hansjone/netx.git
synced 2026-10-09 02:00:46 +08:00
feat(ne-exec): allow ping and ping6 on managed NE CLI path
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
06a5615095
commit
9a39ddfcc7
3 changed files with 9 additions and 6 deletions
|
|
@ -30,8 +30,8 @@ _BLOCKED_RE = re.compile(
|
|||
r")"
|
||||
)
|
||||
|
||||
# Only vendor read-only query verbs (Cisco show / Huawei-ZTE display).
|
||||
_ALLOWED_PREFIX_RE = re.compile(r"(?i)^(show\s|display\s)")
|
||||
# Read-only CLI: show/display plus ping reachability checks.
|
||||
_ALLOWED_PREFIX_RE = re.compile(r"(?i)^(show\s|display\s|ping\s|ping6\s)")
|
||||
|
||||
# Unicode / C1 line separators that can smuggle a second CLI after a show prefix.
|
||||
_FORBIDDEN_LINE_SEPARATORS = ("\u2028", "\u2029", "\x85", "\x0b", "\x0c")
|
||||
|
|
|
|||
|
|
@ -391,7 +391,7 @@ HTTP_MCP_TOOLS: list[dict[str, Any]] = [
|
|||
},
|
||||
{
|
||||
"name": "execManagedNe",
|
||||
"description": "Run read-only CLI on a managed NE via netx (show/display only; max 5 commands).",
|
||||
"description": "Run read-only CLI on a managed NE via netx (show/display/ping; max 5 commands).",
|
||||
"inputSchema": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
|
|
|
|||
|
|
@ -15,10 +15,13 @@ class NeExecValidationTests(unittest.TestCase):
|
|||
def test_allows_display(self) -> None:
|
||||
_validate_command("display interface brief")
|
||||
|
||||
def test_blocks_ping_and_other_non_show_display(self) -> None:
|
||||
def test_allows_ping(self) -> None:
|
||||
_validate_command("ping 192.168.0.1")
|
||||
_validate_command("ping6 2001::1")
|
||||
_validate_command("PING 10.0.0.1 vrf MGMT")
|
||||
|
||||
def test_blocks_non_allowed_prefix(self) -> None:
|
||||
for cmd in (
|
||||
"ping 192.168.0.1",
|
||||
"ping6 2001::1",
|
||||
"get system info",
|
||||
"traceroute 192.168.0.1",
|
||||
"tracert 192.168.0.1",
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue