Skip to content

schema+wire: SSH get_config.running from show running-config script (#324) - #388

Draft
AdamRickards wants to merge 1 commit into
mainfrom
review/324-config-running
Draft

AdamRickards wants to merge 1 commit into
mainfrom
review/324-config-running

Conversation

@AdamRickards

Copy link
Copy Markdown
Owner

Draft for sidecar live proof; do not merge.

Wires get_config.running to SSH show running-config script via new wire/config.yaml (synthetic hm2configrunning) + wire/ssh/config.yaml with explicit parser: none (SSH default parser is dot_keys). startup stays unwired: no read-only CLI exists on the tested firmware. MOPS/SNMP unchanged (empty).

Offline (tested): SSH sends the command and returns the text; MOPS offline running stays empty; schema shape unchanged.

Live (untested, pending): sidecar get_config.read on this head vs main.

Open before any merge:

  • Receipt redaction: the raw running config would appear in sidecar raw/cli and in parity_diffs prefixes; it may contain credential material.

  • Parity/gold: SSH-only non-empty running vs empty MOPS/SNMP and gold floor.

  • pytest tests/: pass

  • scripts/ci_offline.sh: pass

  • generate_floors_board.py --check: pass

Related #324

…324)

running: new base wire/config.yaml (synthetic hm2configrunning; no MIB
object backs a config-text dump) + wire/ssh/config.yaml overlay sourced
from "show running-config script".

parser: none is explicit and required: SSH.yaml's protocol-level default
parser is dot_keys, which returns {} against the raw text.

startup: deliberately unwired. "show startup-config" is rejected on the
tested firmware, and the saved config can only be read by a mutating
copy into running, which a read-only getter must not do.

MOPS/SNMP unchanged (running stays empty). Offline (tested): SSH sends
the command and returns the text; MOPS offline unchanged. Live sidecar
proof: untested (pending). Open items: receipt redaction, parity/gold
handling for an SSH-only field.

Schema + wire YAML only. Draft for sidecar live proof; do not merge.

Related #324
@AdamRickards

Copy link
Copy Markdown
Owner Author

Sidecar live proof — get_config.read trace:true, head a18962c vs main 9ee450d (2 runs on this head, same result).

protocol main this PR
mops ok, running/startup empty ok, running/startup empty
snmp ok, running/startup empty ok, running/startup empty
ssh ok, running/startup empty, no command sent timeout, phase=call (call budget 6s); last_command = show running-config script
parity_diffs 0 0 (ssh had no result to compare)

Result: fail (ssh untested for content: call did not finish inside the call budget on the tested device; output was still streaming, no prompt returned).

Receipt safety: on timeout, the receipt's session_log_tail carried ~8 KB of running-config text. On success, the full text would also land in raw, in cli (trace), and as a prefix in parity_diffs. Redaction is needed before this can be proven or merged.

Draft; do not merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant