[action] [PR:25576] Add Python 3.13 and newer PTF image compatibility - #1387
Merged
Merged
Conversation
<!-- Please make sure you've read and understood our contributing guidelines; https://github.com/sonic-net/SONiC/blob/gh-pages/CONTRIBUTING.md Please provide following information to help code review process a bit easier: --> ### Description of PR <!-- - Please include a summary of the change and which issue is fixed. - Please also include relevant motivation and context. Where should reviewer start? background context? - List any dependencies that are required for this change. --> Summary: Fixes compatibility issues with Python 3.13 docker-ptf container and newer Debian PTF images: TACACS daemon startup failure when docker-ptf uses Python 3.13 (crypt module removed) sysctl configuration failure on newer Debian trixie PTF images ### Type of change <!-- - Fill x for your type of change. - e.g. - [x] Bug fix --> - [ ] Bug fix - [x] Testbed and Framework(new/improvement) - [ ] New Test case - [ ] Skipped for non-supported platforms - [ ] Test case improvement ### Back port request - [ ] 202311 - [ ] 202405 - [ ] 202411 - [ ] 202505 - [ ] 202511 - [ ] 202512 - [x] 202605 ### Approach #### What is the motivation for this PR? Docker-ptf needs to migrate from Bookworm to Trixie. and the python version in Trixie is 3.13, which removed the crypt module that was used to generate DES crypt(3) hashes for TACACS authentication. When ansible delegates the password encryption command to docker-ptf and it's running Python 3.13, the playbook fails. And Debian trixie's procps no longer ships `sysctl.conf`, requires `sysctl --system` instead of `sysctl -p` #### How did you do it? Modified the password encryption shell commands to: 1. Try python3 -c "import crypt; ..." first (some docker-ptf images may still use python3.11) 2. Fall back to openssl passwd -crypt -salt ab if Python's crypt module is unavailable 3. Both methods produce identical DES crypt(3) hashes expected by tac_plus daemon 4. Replaced `sysctl -p` (legacy `sysctl.conf`) with `sysctl --system` (reads drop-in dirs) #### How did you verify/test it? #### Any platform specific information? #### Supported testbed topology if it's a new test case? ### Documentation <!-- (If it's a new feature, new test case) Did you update documentation/Wiki relevant to your implementation? Link to the wiki page? --> Signed-off-by: Sonic Build Admin <sonicbld@microsoft.com>
mssonicbld
requested review from
Sai Kiran (opcoder0) and
Ying Xie (yxieca)
as code owners
August 28, 2026 20:00
Collaborator
Author
|
Original PR: sonic-net/sonic-mgmt#25576 |
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Collaborator
Author
|
/azp run |
|
Azure Pipelines will not run the associated pipelines, because the pull request was updated after the run command was issued. Review the pull request again and issue a new run command. |
12 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of PR
Summary:
Fixes compatibility issues with Python 3.13 docker-ptf container and newer Debian PTF images:
TACACS daemon startup failure when docker-ptf uses Python 3.13 (crypt module removed)
sysctl configuration failure on newer Debian trixie PTF images
Type of change
Back port request
Approach
What is the motivation for this PR?
Docker-ptf needs to migrate from Bookworm to Trixie. and the python version in Trixie is 3.13, which removed the crypt module that was used to generate DES crypt(3) hashes for TACACS authentication. When ansible delegates the password encryption command to docker-ptf and it's running Python 3.13, the playbook fails. And Debian trixie's procps no longer ships
sysctl.conf, requiressysctl --systeminstead ofsysctl -pHow did you do it?
Modified the password encryption shell commands to:
sysctl -p(legacysysctl.conf) withsysctl --system(reads drop-in dirs)How did you verify/test it?
Any platform specific information?
Supported testbed topology if it's a new test case?
Documentation
Signed-off-by: Sonic Build Admin sonicbld@microsoft.com