Fix OPNsense config.xml root element mismatch

Real config.xml root is the lowercase <opnsense> element (the whole
firewall config); plugin/core model data like WireGuard lives nested
inside a separate, capitalized <OPNsense> child element. The parser
was matching the capitalized name as the document root, so every real
export failed with "expected element type but have ...".

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019VjwLYRA87o8m9a9zztgs3
This commit is contained in:
sysops
2026-07-24 00:14:14 +02:00
co-authored by Claude Sonnet 5
parent 388a8377cd
commit 3a89a3cb5c
+45 -33
View File
@@ -7,20 +7,27 @@
// for the two-step preview/commit flow that does the actual store writes.
//
// Schema reference (verified against OPNsense core master,
// src/opnsense/mvc/app/models/OPNsense/Wireguard/{Server,Client}.xml):
// src/opnsense/mvc/app/models/OPNsense/Wireguard/{Server,Client}.xml, and
// against real config.xml exports/fixtures, which nest plugin model data
// under a capitalized <OPNsense> element inside the lowercase <opnsense>
// root - the two are NOT the same element):
//
// <OPNsense><wireguard>
// <server><servers>
// <server uuid="..."><enabled/><name/><instance/><pubkey/><privkey/>
// <port/><mtu/><dns/><tunneladdress/><disableroutes/><gateway/>
// <peers/><debug/></server>
// </servers></server>
// <client><clients>
// <client uuid="..."><enabled/><name/><pubkey/><psk/><tunneladdress/>
// <serveraddress/><serverport/><keepalive/></client>
// </clients></client>
// <general><enabled/></general>
// </wireguard></OPNsense>
// <opnsense>
// ...
// <OPNsense><wireguard>
// <server><servers>
// <server uuid="..."><enabled/><name/><instance/><pubkey/><privkey/>
// <port/><mtu/><dns/><tunneladdress/><disableroutes/><gateway/>
// <peers/><debug/></server>
// </servers></server>
// <client><clients>
// <client uuid="..."><enabled/><name/><pubkey/><psk/><tunneladdress/>
// <serveraddress/><serverport/><keepalive/></client>
// </clients></client>
// <general><enabled/></general>
// </wireguard></OPNsense>
// ...
// </opnsense>
package opnsense
import (
@@ -30,24 +37,29 @@ import (
"strings"
)
// rawConfig mirrors the on-disk config.xml structure.
// rawConfig mirrors the on-disk config.xml structure. The root element is
// the lowercase <opnsense> (the whole firewall config); plugin/core model
// data lives inside a capitalized <OPNsense> child element - the two are
// distinct tags, not a casing quirk of one.
type rawConfig struct {
XMLName xml.Name `xml:"OPNsense"`
Wireguard struct {
Server struct {
Servers struct {
Server []rawServer `xml:"server"`
} `xml:"servers"`
} `xml:"server"`
Client struct {
Clients struct {
Client []rawClient `xml:"client"`
} `xml:"clients"`
} `xml:"client"`
General struct {
Enabled string `xml:"enabled"`
} `xml:"general"`
} `xml:"wireguard"`
XMLName xml.Name `xml:"opnsense"`
Ns struct {
Wireguard struct {
Server struct {
Servers struct {
Server []rawServer `xml:"server"`
} `xml:"servers"`
} `xml:"server"`
Client struct {
Clients struct {
Client []rawClient `xml:"client"`
} `xml:"clients"`
} `xml:"client"`
General struct {
Enabled string `xml:"enabled"`
} `xml:"general"`
} `xml:"wireguard"`
} `xml:"OPNsense"`
}
type rawServer struct {
@@ -97,13 +109,13 @@ func Parse(r io.Reader) (*ParsedConfig, error) {
if err := dec.Decode(&cfg); err != nil {
return nil, fmt.Errorf("could not parse config.xml: %w", err)
}
if cfg.XMLName.Local != "OPNsense" {
if cfg.XMLName.Local != "opnsense" {
return nil, fmt.Errorf("not an OPNsense config.xml (unexpected root element %q)", cfg.XMLName.Local)
}
return &ParsedConfig{
Servers: cfg.Wireguard.Server.Servers.Server,
Clients: cfg.Wireguard.Client.Clients.Client,
Servers: cfg.Ns.Wireguard.Server.Servers.Server,
Clients: cfg.Ns.Wireguard.Client.Clients.Client,
}, nil
}