)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"4278a2dee9efd280d58a023a05dc0aca96134059","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"7f83b64d_336805e2","updated":"2026-07-22 14:47:57.000000000","message":"Nice! A couple of minor comments, otherwise good to go IMO.","commit_id":"b80f39ab8ab8be48b40beed8161bc6c804c4243f"}],"specs/approved/ngs-libssh-migration.rst":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"401c25a122e83d062e039d037d997f01fb09f3dd","unresolved":false,"context_lines":[{"line_number":15,"context_line":"The ``paramiko`` library has been pinned to versions below 5.0 due to"},{"line_number":16,"context_line":"breakage in ``netmiko``, and the ``netmiko`` maintainer has indicated"},{"line_number":17,"context_line":"that work on the next major version addressing this will not begin until"},{"line_number":18,"context_line":"fall/winter 2026. This timeline makes it impossible for a compatible"},{"line_number":19,"context_line":"``netmiko`` release to land in OpenStack\u0027s 2026.2 cycle."},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"This specification proposes creating new NGS SSH CLI drivers backed by"}],"source_content_type":"text/x-rst","patch_set":2,"id":"7e16f739_5984cb94","line":18,"updated":"2026-07-20 14:59:32.000000000","message":"I\u0027m not convinced that our work will take less time.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"adb52c4825d6b9bb6eeebb108d4e04c29011bc81","unresolved":false,"context_lines":[{"line_number":15,"context_line":"The ``paramiko`` library has been pinned to versions below 5.0 due to"},{"line_number":16,"context_line":"breakage in ``netmiko``, and the ``netmiko`` maintainer has indicated"},{"line_number":17,"context_line":"that work on the next major version addressing this will not begin until"},{"line_number":18,"context_line":"fall/winter 2026. This timeline makes it impossible for a compatible"},{"line_number":19,"context_line":"``netmiko`` release to land in OpenStack\u0027s 2026.2 cycle."},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"This specification proposes creating new NGS SSH CLI drivers backed by"}],"source_content_type":"text/x-rst","patch_set":2,"id":"697f6a7c_1391f578","line":18,"in_reply_to":"7e16f739_5984cb94","updated":"2026-07-20 18:30:05.000000000","message":"The netmiko maintainer is on the record basically treating newer paramiko as breaking since it breaks connectivity to older devices. The goal here is to move forward and ultimately have a plan to do so. Doesn\u0027t mean we won\u0027t be done, but I guess my goal is a plan at the moment.\n\nAnd truthfully, odds are we won\u0027t actually start that until afterwards either, but from a overall security standpoint the goal needs to be to advance the capabilities and expectations which sometimes means setting a new bar as well.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"401c25a122e83d062e039d037d997f01fb09f3dd","unresolved":false,"context_lines":[{"line_number":62,"context_line":"  delegates cryptography to OpenSSL and is FIPS compatible when"},{"line_number":63,"context_line":"  OpenSSL runs in FIPS mode, eliminating this workaround."},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"* **Dependency simplification** -- Reducing the transitive dependency"},{"line_number":66,"context_line":"  chain through ``netmiko`` and ``paramiko`` lowers the surface area"},{"line_number":67,"context_line":"  for version conflicts with other OpenStack projects."},{"line_number":68,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"cb9e0fc3_66406521","line":65,"updated":"2026-07-20 14:59:32.000000000","message":"Moving the difficult parts under our umbrella is not a simplification though","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"adb52c4825d6b9bb6eeebb108d4e04c29011bc81","unresolved":false,"context_lines":[{"line_number":62,"context_line":"  delegates cryptography to OpenSSL and is FIPS compatible when"},{"line_number":63,"context_line":"  OpenSSL runs in FIPS mode, eliminating this workaround."},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"* **Dependency simplification** -- Reducing the transitive dependency"},{"line_number":66,"context_line":"  chain through ``netmiko`` and ``paramiko`` lowers the surface area"},{"line_number":67,"context_line":"  for version conflicts with other OpenStack projects."},{"line_number":68,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"3117bdb1_9145d9f1","line":65,"in_reply_to":"cb9e0fc3_66406521","updated":"2026-07-20 18:30:05.000000000","message":"No disagreement there.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"401c25a122e83d062e039d037d997f01fb09f3dd","unresolved":false,"context_lines":[{"line_number":76,"context_line":"  the ``netmiko`` version pin would block its consumption regardless."},{"line_number":77,"context_line":"  Building on ``libssh`` positions NGS to negotiate post-quantum"},{"line_number":78,"context_line":"  algorithms as switch vendors begin shipping firmware that supports"},{"line_number":79,"context_line":"  them."},{"line_number":80,"context_line":""},{"line_number":81,"context_line":"And while some of these motivations will reach different points with"},{"line_number":82,"context_line":"time, there is increased value in operational choice for our users."}],"source_content_type":"text/x-rst","patch_set":2,"id":"3ea53f0c_3dbf7bda","line":79,"updated":"2026-07-20 14:59:32.000000000","message":"Which is WAY after fall/winter 2026.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"401c25a122e83d062e039d037d997f01fb09f3dd","unresolved":false,"context_lines":[{"line_number":89,"context_line":"``netmiko``/``paramiko`` driver set as replacements become available."},{"line_number":90,"context_line":""},{"line_number":91,"context_line":"New libssh-based Driver Framework"},{"line_number":92,"context_line":"---------------------------------"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"A new base class (tentatively ``LibsshSwitch``) will be created alongside"},{"line_number":95,"context_line":"the existing ``NetmikoSwitch`` base class. It will:"}],"source_content_type":"text/x-rst","patch_set":2,"id":"d115b142_198f4733","line":92,"updated":"2026-07-20 14:59:32.000000000","message":"This part needs to be brutally honest about the amount of work we\u0027re talking about and how hard it will be to maintain it.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"e3fe896844a14975dd1ac50334f6c90e70356e75","unresolved":true,"context_lines":[{"line_number":89,"context_line":"``netmiko``/``paramiko`` driver set as replacements become available."},{"line_number":90,"context_line":""},{"line_number":91,"context_line":"New libssh-based Driver Framework"},{"line_number":92,"context_line":"---------------------------------"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"A new base class (tentatively ``LibsshSwitch``) will be created alongside"},{"line_number":95,"context_line":"the existing ``NetmikoSwitch`` base class. It will:"}],"source_content_type":"text/x-rst","patch_set":2,"id":"6cdaa786_fb6b5091","line":92,"in_reply_to":"5cc1ff00_b9ee6311","updated":"2026-07-21 05:34:00.000000000","message":"Yeah, it\u0027s a fine line. I think it\u0027s important here because most readers (myself included) are not familiar with Netmiko internals so don\u0027t really imagine what it takes to replace it.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"adb52c4825d6b9bb6eeebb108d4e04c29011bc81","unresolved":true,"context_lines":[{"line_number":89,"context_line":"``netmiko``/``paramiko`` driver set as replacements become available."},{"line_number":90,"context_line":""},{"line_number":91,"context_line":"New libssh-based Driver Framework"},{"line_number":92,"context_line":"---------------------------------"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"A new base class (tentatively ``LibsshSwitch``) will be created alongside"},{"line_number":95,"context_line":"the existing ``NetmikoSwitch`` base class. It will:"}],"source_content_type":"text/x-rst","patch_set":2,"id":"5cc1ff00_b9ee6311","line":92,"in_reply_to":"d115b142_198f4733","updated":"2026-07-20 18:30:05.000000000","message":"Okay, I concur, unfortunately I\u0027ve also gotten feedback recently that being too verbose is a turn-off on reviews and this was my attempt to keep it zoomed out.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"401c25a122e83d062e039d037d997f01fb09f3dd","unresolved":false,"context_lines":[{"line_number":137,"context_line":""},{"line_number":138,"context_line":"* Cisco IOS (IOSv)"},{"line_number":139,"context_line":"* Juniper Junos (vQFX)"},{"line_number":140,"context_line":"* Dell OS10 (OS10 VM)"},{"line_number":141,"context_line":"* Nokia SR Linux (containerlab)"},{"line_number":142,"context_line":"* HPE Aruba ArubaOS-CX (AOS-CX Simulator)"},{"line_number":143,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"6d6437b3_8a434108","line":140,"updated":"2026-07-20 14:59:32.000000000","message":"And here we\u0027ll have a lot of argument: Junos, OS10 and Nokia are high priority for us..","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"adb52c4825d6b9bb6eeebb108d4e04c29011bc81","unresolved":false,"context_lines":[{"line_number":137,"context_line":""},{"line_number":138,"context_line":"* Cisco IOS (IOSv)"},{"line_number":139,"context_line":"* Juniper Junos (vQFX)"},{"line_number":140,"context_line":"* Dell OS10 (OS10 VM)"},{"line_number":141,"context_line":"* Nokia SR Linux (containerlab)"},{"line_number":142,"context_line":"* HPE Aruba ArubaOS-CX (AOS-CX Simulator)"},{"line_number":143,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"f8ec0a98_6aeb95f3","line":140,"in_reply_to":"6d6437b3_8a434108","updated":"2026-07-20 18:30:05.000000000","message":"I think we can move them up, I just know the big asks I get are Cisco/SONiC/Cumulus NVUE. We can punt Arista and bring up Junos/Nokia SR. It was just a first pass at what seemed reasonable to focus on.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"4f5646c8db15ebb5803b8d4ec8ed9c71214e5d4c","unresolved":true,"context_lines":[{"line_number":137,"context_line":""},{"line_number":138,"context_line":"* Cisco IOS (IOSv)"},{"line_number":139,"context_line":"* Juniper Junos (vQFX)"},{"line_number":140,"context_line":"* Dell OS10 (OS10 VM)"},{"line_number":141,"context_line":"* Nokia SR Linux (containerlab)"},{"line_number":142,"context_line":"* HPE Aruba ArubaOS-CX (AOS-CX Simulator)"},{"line_number":143,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"ff72101a_84d8bff3","line":140,"in_reply_to":"f8ec0a98_6aeb95f3","updated":"2026-07-21 13:25:11.000000000","message":"Marking as not resolved yet since we\u0027ll need to shuffle the order of switches drivers based upon discussion","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"4f5646c8db15ebb5803b8d4ec8ed9c71214e5d4c","unresolved":true,"context_lines":[{"line_number":143,"context_line":""},{"line_number":144,"context_line":"**Tier 3** -- Tactical value:"},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"* Open vSwitch (native, used for CI)"},{"line_number":147,"context_line":"* Dell Enterprise SONiC (inherits from SONiC)"},{"line_number":148,"context_line":""},{"line_number":149,"context_line":"Deprecation"}],"source_content_type":"text/x-rst","patch_set":2,"id":"b37a7f96_9b29d8f3","line":146,"updated":"2026-07-21 13:25:11.000000000","message":"We should likely consider OVS as \"tier-3, but do first to at least wire up and verify port binding to behavior is working out of the box\"","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"422017a1d8ab8f5ed98da40ccdd916061834b210","unresolved":true,"context_lines":[{"line_number":143,"context_line":""},{"line_number":144,"context_line":"**Tier 3** -- Tactical value:"},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"* Open vSwitch (native, used for CI)"},{"line_number":147,"context_line":"* Dell Enterprise SONiC (inherits from SONiC)"},{"line_number":148,"context_line":""},{"line_number":149,"context_line":"Deprecation"}],"source_content_type":"text/x-rst","patch_set":2,"id":"33e0a058_a7df1322","line":146,"in_reply_to":"b37a7f96_9b29d8f3","updated":"2026-07-21 13:55:26.000000000","message":"So tier-1 really :)","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"401c25a122e83d062e039d037d997f01fb09f3dd","unresolved":false,"context_lines":[{"line_number":209,"context_line":"**Use scrapli instead of libssh.** The ``scrapli`` library provides"},{"line_number":210,"context_line":"network device automation without ``paramiko``, supporting system SSH,"},{"line_number":211,"context_line":"``asyncssh``, and ``ssh2-python`` transports. This trades one upstream"},{"line_number":212,"context_line":"dependency for another and does not use ``libssh`` specifically, but"},{"line_number":213,"context_line":"could reduce the base class effort. This remains an option if"},{"line_number":214,"context_line":"``libssh`` integration proves problematic."},{"line_number":215,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"18026925_cb09bf42","line":212,"updated":"2026-07-20 14:59:32.000000000","message":"A dependency in itself is not a problem. Are there any other issues that prevent us from starting with scrapli (and rewriting the backend only if it does not work)?","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"adb52c4825d6b9bb6eeebb108d4e04c29011bc81","unresolved":true,"context_lines":[{"line_number":209,"context_line":"**Use scrapli instead of libssh.** The ``scrapli`` library provides"},{"line_number":210,"context_line":"network device automation without ``paramiko``, supporting system SSH,"},{"line_number":211,"context_line":"``asyncssh``, and ``ssh2-python`` transports. This trades one upstream"},{"line_number":212,"context_line":"dependency for another and does not use ``libssh`` specifically, but"},{"line_number":213,"context_line":"could reduce the base class effort. This remains an option if"},{"line_number":214,"context_line":"``libssh`` integration proves problematic."},{"line_number":215,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"cd941bb6_88a1a631","line":212,"in_reply_to":"18026925_cb09bf42","updated":"2026-07-20 18:30:05.000000000","message":"It might be possible. Although I\u0027m curious if folks would be okay with Zig build chain dependencies.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"4f5646c8db15ebb5803b8d4ec8ed9c71214e5d4c","unresolved":true,"context_lines":[{"line_number":209,"context_line":"**Use scrapli instead of libssh.** The ``scrapli`` library provides"},{"line_number":210,"context_line":"network device automation without ``paramiko``, supporting system SSH,"},{"line_number":211,"context_line":"``asyncssh``, and ``ssh2-python`` transports. This trades one upstream"},{"line_number":212,"context_line":"dependency for another and does not use ``libssh`` specifically, but"},{"line_number":213,"context_line":"could reduce the base class effort. This remains an option if"},{"line_number":214,"context_line":"``libssh`` integration proves problematic."},{"line_number":215,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"c6441eac_5237e3ea","line":212,"in_reply_to":"53b8aa95_9105337c","updated":"2026-07-21 13:25:11.000000000","message":"Yeah, I nerd sniped our downstream release delivery team regarding Zig, and basically they said \"not impossible, not as much a risk as Go, but it requires basically a bleeding edge llvm build which we don\u0027t have out of the box\"","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"e3fe896844a14975dd1ac50334f6c90e70356e75","unresolved":false,"context_lines":[{"line_number":209,"context_line":"**Use scrapli instead of libssh.** The ``scrapli`` library provides"},{"line_number":210,"context_line":"network device automation without ``paramiko``, supporting system SSH,"},{"line_number":211,"context_line":"``asyncssh``, and ``ssh2-python`` transports. This trades one upstream"},{"line_number":212,"context_line":"dependency for another and does not use ``libssh`` specifically, but"},{"line_number":213,"context_line":"could reduce the base class effort. This remains an option if"},{"line_number":214,"context_line":"``libssh`` integration proves problematic."},{"line_number":215,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"53b8aa95_9105337c","line":212,"in_reply_to":"a9bfb621_6797c035","updated":"2026-07-21 05:34:00.000000000","message":"Oh yeah, this is a bit of an issue.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"a378e31197da15bcd3ca58857caa94e13288b52e","unresolved":true,"context_lines":[{"line_number":209,"context_line":"**Use scrapli instead of libssh.** The ``scrapli`` library provides"},{"line_number":210,"context_line":"network device automation without ``paramiko``, supporting system SSH,"},{"line_number":211,"context_line":"``asyncssh``, and ``ssh2-python`` transports. This trades one upstream"},{"line_number":212,"context_line":"dependency for another and does not use ``libssh`` specifically, but"},{"line_number":213,"context_line":"could reduce the base class effort. This remains an option if"},{"line_number":214,"context_line":"``libssh`` integration proves problematic."},{"line_number":215,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"a9bfb621_6797c035","line":212,"in_reply_to":"cd941bb6_88a1a631","updated":"2026-07-20 20:39:02.000000000","message":"So, looks like the way it works is we would need to have Zig in our toolchain to compile libscrpli which would supply the bridge for transports which include the ssh command *and* libssh2 directly.\n\nWe could then potentially add/track and maybe submit back changes if we were not viewed as tainted by AI.  I was discussing it with someone else earlier today and they remarked that scrapli was super anti-ai in the \"your not even allowed to ask an ai about it and then submit a change you wrote\", which could also increase the barrier.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"401c25a122e83d062e039d037d997f01fb09f3dd","unresolved":false,"context_lines":[{"line_number":214,"context_line":"``libssh`` integration proves problematic."},{"line_number":215,"context_line":""},{"line_number":216,"context_line":"**Do nothing and wait for netmiko.** This leaves NGS pinned to"},{"line_number":217,"context_line":"``paramiko`` \u003c 5.0 for the foreseeable future, deferring the ability"},{"line_number":218,"context_line":"to adopt modern cryptographic capabilities."},{"line_number":219,"context_line":""},{"line_number":220,"context_line":"Data model impact"}],"source_content_type":"text/x-rst","patch_set":2,"id":"4e8cab94_fca930b2","line":217,"updated":"2026-07-20 14:59:32.000000000","message":"I think the problem is not waiting, it\u0027s that paramiko has removed an old but popular algorithm. Does libssh have the same issue?","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"422017a1d8ab8f5ed98da40ccdd916061834b210","unresolved":true,"context_lines":[{"line_number":214,"context_line":"``libssh`` integration proves problematic."},{"line_number":215,"context_line":""},{"line_number":216,"context_line":"**Do nothing and wait for netmiko.** This leaves NGS pinned to"},{"line_number":217,"context_line":"``paramiko`` \u003c 5.0 for the foreseeable future, deferring the ability"},{"line_number":218,"context_line":"to adopt modern cryptographic capabilities."},{"line_number":219,"context_line":""},{"line_number":220,"context_line":"Data model impact"}],"source_content_type":"text/x-rst","patch_set":2,"id":"885485d0_629fa659","line":217,"in_reply_to":"321b26b7_f79dd40a","updated":"2026-07-21 13:55:26.000000000","message":"That\u0027s what I wanted to confirm. I\u0027m trying to avoid a situation where SHA1 works *somehow* still, and we break it by migration.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"e3fe896844a14975dd1ac50334f6c90e70356e75","unresolved":true,"context_lines":[{"line_number":214,"context_line":"``libssh`` integration proves problematic."},{"line_number":215,"context_line":""},{"line_number":216,"context_line":"**Do nothing and wait for netmiko.** This leaves NGS pinned to"},{"line_number":217,"context_line":"``paramiko`` \u003c 5.0 for the foreseeable future, deferring the ability"},{"line_number":218,"context_line":"to adopt modern cryptographic capabilities."},{"line_number":219,"context_line":""},{"line_number":220,"context_line":"Data model impact"}],"source_content_type":"text/x-rst","patch_set":2,"id":"c65791cd_359aeb2a","line":217,"in_reply_to":"3b2f081a_4bc7bdfe","updated":"2026-07-21 05:34:00.000000000","message":"To rephrase: for people who don\u0027t care about FIPS, will a switch to libssh fix the breakage that Paramiko 5 introduced?","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"adb52c4825d6b9bb6eeebb108d4e04c29011bc81","unresolved":true,"context_lines":[{"line_number":214,"context_line":"``libssh`` integration proves problematic."},{"line_number":215,"context_line":""},{"line_number":216,"context_line":"**Do nothing and wait for netmiko.** This leaves NGS pinned to"},{"line_number":217,"context_line":"``paramiko`` \u003c 5.0 for the foreseeable future, deferring the ability"},{"line_number":218,"context_line":"to adopt modern cryptographic capabilities."},{"line_number":219,"context_line":""},{"line_number":220,"context_line":"Data model impact"}],"source_content_type":"text/x-rst","patch_set":2,"id":"3b2f081a_4bc7bdfe","line":217,"in_reply_to":"4e8cab94_fca930b2","updated":"2026-07-20 18:30:05.000000000","message":"Libssh is just the core ssh library of the OS, so it is inherently going to map whatever the base OS has and provides and also allows for the base cryptographic polices of the host to be in force.  In a sense, paramiko is a bypass mechanism.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"4f5646c8db15ebb5803b8d4ec8ed9c71214e5d4c","unresolved":true,"context_lines":[{"line_number":214,"context_line":"``libssh`` integration proves problematic."},{"line_number":215,"context_line":""},{"line_number":216,"context_line":"**Do nothing and wait for netmiko.** This leaves NGS pinned to"},{"line_number":217,"context_line":"``paramiko`` \u003c 5.0 for the foreseeable future, deferring the ability"},{"line_number":218,"context_line":"to adopt modern cryptographic capabilities."},{"line_number":219,"context_line":""},{"line_number":220,"context_line":"Data model impact"}],"source_content_type":"text/x-rst","patch_set":2,"id":"321b26b7_f79dd40a","line":217,"in_reply_to":"c65791cd_359aeb2a","updated":"2026-07-21 13:25:11.000000000","message":"My apologies, but I don\u0027t see how that is a relevant question because what paramiko did was remove SHA1.\n\nSHA1 had already long been removed from the ssh/openssl ecosystem so that class of issue would have never occured. Odds are the operator with a switch which still wants/needs SHA1 would have found it just not working years earlier and would have needed to replace the switch or upgrade to the latest and greatest firmware.\n\nPerhaps a cleaner way to carry it is paramiko has sort of been hiding a bunch of technical debt in the name of compatibility, but that technical debt is now weight. Mix in resistance to change, such as still wanting to use SHA1 with network devices, and you end up in the situation we\u0027re generally in now.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"401c25a122e83d062e039d037d997f01fb09f3dd","unresolved":false,"context_lines":[{"line_number":216,"context_line":"**Do nothing and wait for netmiko.** This leaves NGS pinned to"},{"line_number":217,"context_line":"``paramiko`` \u003c 5.0 for the foreseeable future, deferring the ability"},{"line_number":218,"context_line":"to adopt modern cryptographic capabilities."},{"line_number":219,"context_line":""},{"line_number":220,"context_line":"Data model impact"},{"line_number":221,"context_line":"-----------------"},{"line_number":222,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"65abf1b9_4364ebd2","line":219,"updated":"2026-07-20 14:59:32.000000000","message":"Is netconf/openconfig a viable alternative for target hardware?","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"4f5646c8db15ebb5803b8d4ec8ed9c71214e5d4c","unresolved":true,"context_lines":[{"line_number":216,"context_line":"**Do nothing and wait for netmiko.** This leaves NGS pinned to"},{"line_number":217,"context_line":"``paramiko`` \u003c 5.0 for the foreseeable future, deferring the ability"},{"line_number":218,"context_line":"to adopt modern cryptographic capabilities."},{"line_number":219,"context_line":""},{"line_number":220,"context_line":"Data model impact"},{"line_number":221,"context_line":"-----------------"},{"line_number":222,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"27ee3ed7_877ffea0","line":219,"in_reply_to":"3e9320b7_2d8e6c2f","updated":"2026-07-21 13:25:11.000000000","message":".... Well, because we would be replacing all of the under the hood internals that we would have to treat any \"replacement\" as a net-new driver.\n\nFor what it is worth, I\u0027ll update this spec, likely in a few hours once I\u0027m awake and through my sequence of initial meetings this morning.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"adb52c4825d6b9bb6eeebb108d4e04c29011bc81","unresolved":true,"context_lines":[{"line_number":216,"context_line":"**Do nothing and wait for netmiko.** This leaves NGS pinned to"},{"line_number":217,"context_line":"``paramiko`` \u003c 5.0 for the foreseeable future, deferring the ability"},{"line_number":218,"context_line":"to adopt modern cryptographic capabilities."},{"line_number":219,"context_line":""},{"line_number":220,"context_line":"Data model impact"},{"line_number":221,"context_line":"-----------------"},{"line_number":222,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"c33ce261_bfdfe920","line":219,"in_reply_to":"65abf1b9_4364ebd2","updated":"2026-07-20 18:30:05.000000000","message":"I don\u0027t think so, but that also will force us to draw a drastically different approach than the current command approach. Not saying that is wrong, but depending on the exact path details, we are likely to incur even more work and risk in a larger refactor to leverage netconf/openconfig models. Definitely worth some more research.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"e3fe896844a14975dd1ac50334f6c90e70356e75","unresolved":true,"context_lines":[{"line_number":216,"context_line":"**Do nothing and wait for netmiko.** This leaves NGS pinned to"},{"line_number":217,"context_line":"``paramiko`` \u003c 5.0 for the foreseeable future, deferring the ability"},{"line_number":218,"context_line":"to adopt modern cryptographic capabilities."},{"line_number":219,"context_line":""},{"line_number":220,"context_line":"Data model impact"},{"line_number":221,"context_line":"-----------------"},{"line_number":222,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"3e9320b7_2d8e6c2f","line":219,"in_reply_to":"c33ce261_bfdfe920","updated":"2026-07-21 05:34:00.000000000","message":"Let\u0027s at least write it down please. As a person who have little clue about netconf, it\u0027s absolutely not clear to me why we cannot gradually switch to the new backend we\u0027re introducing.","commit_id":"d48637a875653b27e0305a2676e89f9b124ac6b7"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"4278a2dee9efd280d58a023a05dc0aca96134059","unresolved":true,"context_lines":[{"line_number":68,"context_line":""},{"line_number":69,"context_line":"* **Dependency simplification** -- Reducing the transitive dependency"},{"line_number":70,"context_line":"  chain through ``netmiko`` and ``paramiko`` lowers the surface area"},{"line_number":71,"context_line":"  for version conflicts with other OpenStack projects."},{"line_number":72,"context_line":""},{"line_number":73,"context_line":"* **Modern algorithm support** -- As switch vendors update firmware"},{"line_number":74,"context_line":"  to prefer newer key exchange and cipher algorithms, the SSH client"}],"source_content_type":"text/x-rst","patch_set":3,"id":"6292969f_6cde60f4","line":71,"updated":"2026-07-22 14:47:57.000000000","message":"I assume we won\u0027t achieve this goal any more?","commit_id":"b80f39ab8ab8be48b40beed8161bc6c804c4243f"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"e9d898e036019ada7a0b55e20b573c01a36668f5","unresolved":true,"context_lines":[{"line_number":68,"context_line":""},{"line_number":69,"context_line":"* **Dependency simplification** -- Reducing the transitive dependency"},{"line_number":70,"context_line":"  chain through ``netmiko`` and ``paramiko`` lowers the surface area"},{"line_number":71,"context_line":"  for version conflicts with other OpenStack projects."},{"line_number":72,"context_line":""},{"line_number":73,"context_line":"* **Modern algorithm support** -- As switch vendors update firmware"},{"line_number":74,"context_line":"  to prefer newer key exchange and cipher algorithms, the SSH client"}],"source_content_type":"text/x-rst","patch_set":3,"id":"38ccee70_070bdbb5","line":71,"in_reply_to":"6292969f_6cde60f4","updated":"2026-07-22 15:11:52.000000000","message":"I still think it is broadly possible, but that will invovle moving the \"hot path\" through to the libssh model for users. Users who stay on netmiko based drivers will sort of just be stuck unless they have an alternative. At some point, its a discussion between the operator and their hardware vendor more than us if we support generally applicable models. I also think a logical step beyond this is gnm... whatever it was. The g-rpc based model.  That will need to be a whole other class of driver.","commit_id":"b80f39ab8ab8be48b40beed8161bc6c804c4243f"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"4278a2dee9efd280d58a023a05dc0aca96134059","unresolved":true,"context_lines":[{"line_number":143,"context_line":"* Be registered as a separate stevedore entry point following the"},{"line_number":144,"context_line":"  naming convention"},{"line_number":145,"context_line":"  ``\u003cdriver_method\u003e_\u003cconnection_method\u003e_\u003cvendor\u003e_\u003cmodel\u003e``, e.g.,"},{"line_number":146,"context_line":"  ``netconf_libssh_arista_eos``. This makes the configuration"},{"line_number":147,"context_line":"  interface and transport explicit so operators know what they are"},{"line_number":148,"context_line":"  enabling. Existing ``netmiko_`` prefixed drivers remain available"},{"line_number":149,"context_line":"  for operators who prefer or require the SSH CLI model."}],"source_content_type":"text/x-rst","patch_set":3,"id":"5a391db3_43e9a088","line":146,"updated":"2026-07-22 14:47:57.000000000","message":"Maybe we drop `libssh` from the name and make the transport configurable? It does not seem to be an inherent part of the driver.","commit_id":"b80f39ab8ab8be48b40beed8161bc6c804c4243f"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"e9d898e036019ada7a0b55e20b573c01a36668f5","unresolved":true,"context_lines":[{"line_number":143,"context_line":"* Be registered as a separate stevedore entry point following the"},{"line_number":144,"context_line":"  naming convention"},{"line_number":145,"context_line":"  ``\u003cdriver_method\u003e_\u003cconnection_method\u003e_\u003cvendor\u003e_\u003cmodel\u003e``, e.g.,"},{"line_number":146,"context_line":"  ``netconf_libssh_arista_eos``. This makes the configuration"},{"line_number":147,"context_line":"  interface and transport explicit so operators know what they are"},{"line_number":148,"context_line":"  enabling. Existing ``netmiko_`` prefixed drivers remain available"},{"line_number":149,"context_line":"  for operators who prefer or require the SSH CLI model."}],"source_content_type":"text/x-rst","patch_set":3,"id":"25ad9141_ac61bf23","line":146,"in_reply_to":"5a391db3_43e9a088","updated":"2026-07-22 15:11:52.000000000","message":"So, I inherently wanted to take the path of explicitly setting it so we limit the path taken in the driver model to achieve a reduction in the dependency surface and testing surface. Configurable also inherently drives us towards having to keep the path and variation around for as long as ncclient does. Maybe that is okay, dunno. I guess I could see us being okay with that and doing that, but then we also open the door to needing to have the Netconf over TLS transport, which means additional complexity and very different configuration options given its no longer SSH, but it is certificate based authentication to the remote endpoint.","commit_id":"b80f39ab8ab8be48b40beed8161bc6c804c4243f"},{"author":{"_account_id":25437,"name":"Allain Legacy","email":"alegacy@redhat.com","username":"alegacy"},"change_message_id":"43098a94abbddcfa7fe07baa27438ea6347f6f6b","unresolved":true,"context_lines":[{"line_number":170,"context_line":""},{"line_number":171,"context_line":"**Tier 2** -- medium priority:"},{"line_number":172,"context_line":""},{"line_number":173,"context_line":"* Dell OS10 -- NETCONF supported"},{"line_number":174,"context_line":"* Nokia SR Linux -- NETCONF supported"},{"line_number":175,"context_line":"* Arista EOS -- a vendor-agnostic NETCONF/OpenConfig driver"},{"line_number":176,"context_line":"  already exists in-tree; per-vendor work may focus on features"}],"source_content_type":"text/x-rst","patch_set":3,"id":"f95e5f38_71d72ac5","line":173,"range":{"start_line":173,"start_character":0,"end_line":173,"end_character":32},"updated":"2026-07-22 18:20:35.000000000","message":"I\u0027d like to see Dell OS10 bumped up to tier 1.  I have access to some and could at least offer to test the existing standalone networking use case against it.","commit_id":"b80f39ab8ab8be48b40beed8161bc6c804c4243f"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"41bbc8a9842316a6e6e2c6a62c72a817c6d6c338","unresolved":true,"context_lines":[{"line_number":170,"context_line":""},{"line_number":171,"context_line":"**Tier 2** -- medium priority:"},{"line_number":172,"context_line":""},{"line_number":173,"context_line":"* Dell OS10 -- NETCONF supported"},{"line_number":174,"context_line":"* Nokia SR Linux -- NETCONF supported"},{"line_number":175,"context_line":"* Arista EOS -- a vendor-agnostic NETCONF/OpenConfig driver"},{"line_number":176,"context_line":"  already exists in-tree; per-vendor work may focus on features"}],"source_content_type":"text/x-rst","patch_set":3,"id":"f9879d08_55ab9459","line":173,"range":{"start_line":173,"start_character":0,"end_line":173,"end_character":32},"in_reply_to":"f95e5f38_71d72ac5","updated":"2026-07-22 20:48:00.000000000","message":"Honestly, I don\u0027t think Dell will be focusing on OS10 moving forward, so I don\u0027t think we should try to keep things delineated so we break the effort into relative chunks. Granted, odds are the patches will be sorted together, but my attempt at tiering is a overlap of current use and future likely usage.","commit_id":"b80f39ab8ab8be48b40beed8161bc6c804c4243f"},{"author":{"_account_id":4571,"name":"Steve Baker","email":"sbaker@redhat.com","username":"steve-stevebaker"},"change_message_id":"f31ba9cafdbc89e547b154ca6207cb9726cc39fe","unresolved":true,"context_lines":[{"line_number":453,"context_line":""},{"line_number":454,"context_line":"Work Items"},{"line_number":455,"context_line":"----------"},{"line_number":456,"context_line":""},{"line_number":457,"context_line":"1. Update ``NetconfSwitch`` base class to support ``ncclient``\u0027s"},{"line_number":458,"context_line":"   ``connect_libssh()`` transport as the default, with ``paramiko``"},{"line_number":459,"context_line":"   transport as a fallback."}],"source_content_type":"text/x-rst","patch_set":3,"id":"a2766edc_42743097","line":456,"updated":"2026-07-21 21:39:21.000000000","message":"I think there should be a work item for moving the netmiko and ncclient dependences to pyproject.toml [project.optional-dependencies] and ensuring imports fail gracefully etc when no netmiko driver is configured","commit_id":"b80f39ab8ab8be48b40beed8161bc6c804c4243f"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"c94907356b74ed0e8a777678e72d872a3ebac515","unresolved":true,"context_lines":[{"line_number":453,"context_line":""},{"line_number":454,"context_line":"Work Items"},{"line_number":455,"context_line":"----------"},{"line_number":456,"context_line":""},{"line_number":457,"context_line":"1. Update ``NetconfSwitch`` base class to support ``ncclient``\u0027s"},{"line_number":458,"context_line":"   ``connect_libssh()`` transport as the default, with ``paramiko``"},{"line_number":459,"context_line":"   transport as a fallback."}],"source_content_type":"text/x-rst","patch_set":3,"id":"3eb5cc76_22e1fd71","line":456,"in_reply_to":"a2766edc_42743097","updated":"2026-07-22 14:18:13.000000000","message":"I guess that is a good callout, I am not seeking to avoid installation in general, because ncclient has paramiko as a dependency, but there is a libssh transport so there is an out.\n\nI guess where I\u0027m at is... paramiko might get to a better place, but we should not focus on it as the singular/only path. In the mean time, we may see more issues fixed, but this gives us a more direct path.","commit_id":"b80f39ab8ab8be48b40beed8161bc6c804c4243f"}]}
