forked from kay/RouterOS
NIOSSHError.localizedDescription bridged auf NSError und liefert nur "The operation couldn't be completed. (NIOSSH.NIOSSHError error 1.)" — der eigentliche Fehlertyp/die Diagnostik steckt in der internen CustomStringConvertible-Beschreibung. String(describing:) statt .localizedDescription verwenden, um den echten Grund (z.B. Algorithmus- Aushandlung, Host-Key, Auth) sichtbar zu machen. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HReLXMbmPvtQ23p1iWiJNW
67 lines
2.5 KiB
Swift
67 lines
2.5 KiB
Swift
import Foundation
|
|
import Citadel
|
|
|
|
/// SSH+CLI transport fallback for RouterOS devices/firmware without the REST API (pre-7.1).
|
|
///
|
|
/// Known limitation (tracked for M7 hardening): host key validation currently accepts any key.
|
|
/// This is acceptable for now because REST already provides certificate TOFU on the primary
|
|
/// path and this fallback is used for local-network devices only, but it should get the same
|
|
/// trust-on-first-use treatment before wider distribution.
|
|
final class SSHTransport: RouterOSTransport {
|
|
let kind: RouterOSTransportKind = .ssh
|
|
|
|
private let credentials: RouterOSCredentials
|
|
private var client: SSHClient?
|
|
|
|
init(credentials: RouterOSCredentials) {
|
|
self.credentials = credentials
|
|
}
|
|
|
|
func connect() async throws {
|
|
do {
|
|
client = try await SSHClient.connect(
|
|
host: credentials.host,
|
|
port: credentials.sshPort,
|
|
authenticationMethod: .passwordBased(username: credentials.username, password: credentials.password),
|
|
hostKeyValidator: .acceptAnything(),
|
|
reconnect: .never
|
|
)
|
|
} catch {
|
|
// NIOSSHError's `.localizedDescription` is a useless generic NSError-bridged string
|
|
// ("The operation couldn't be completed."); its real diagnostics only surface via
|
|
// CustomStringConvertible, which `String(describing:)` picks up.
|
|
throw RouterOSError.transportUnavailable("SSH-Verbindung fehlgeschlagen: \(String(describing: error))")
|
|
}
|
|
}
|
|
|
|
func fetchDeviceInfo() async throws -> RouterDeviceInfo {
|
|
let output = try await run("/system resource print without-paging")
|
|
return RouterOSCliParser.parseDeviceInfo(output)
|
|
}
|
|
|
|
func fetchInterfaces() async throws -> [NetworkInterface] {
|
|
let output = try await run("/interface print without-paging terse")
|
|
return RouterOSCliParser.parseInterfaces(output)
|
|
}
|
|
|
|
func disconnect() async {
|
|
try? await client?.close()
|
|
client = nil
|
|
}
|
|
|
|
/// Full human-readable config export (`/export terse`), used for local backups.
|
|
func exportConfiguration() async throws -> String {
|
|
try await run("/export terse")
|
|
}
|
|
|
|
func apply(_ command: RouterOSCommand) async throws {
|
|
_ = try await run(command.cliLine)
|
|
}
|
|
|
|
private func run(_ command: String) async throws -> String {
|
|
guard let client else { throw RouterOSError.notConnected }
|
|
let buffer = try await client.executeCommand(command)
|
|
return String(buffer: buffer)
|
|
}
|
|
}
|