Skip to content

[action] [PR:25576] Add Python 3.13 and newer PTF image compatibility - #1387

Merged
bingwang-ms merged 1 commit into
Azure:202512from
mssonicbld:cherry/msft-202512/25576
Aug 28, 2026
Merged

[action] [PR:25576] Add Python 3.13 and newer PTF image compatibility#1387
bingwang-ms merged 1 commit into
Azure:202512from
mssonicbld:cherry/msft-202512/25576

Conversation

@mssonicbld

Copy link
Copy Markdown
Collaborator

Description of PR

Summary:
Fixes compatibility issues with Python 3.13 docker-ptf container and newer Debian PTF images:

TACACS daemon startup failure when docker-ptf uses Python 3.13 (crypt module removed)
sysctl configuration failure on newer Debian trixie PTF images

Type of change

  • Bug fix
  • Testbed and Framework(new/improvement)
  • New Test case
    • Skipped for non-supported platforms
  • Test case improvement

Back port request

  • 202311
  • 202405
  • 202411
  • 202505
  • 202511
  • 202512
  • 202605

Approach

What is the motivation for this PR?

Docker-ptf needs to migrate from Bookworm to Trixie. and the python version in Trixie is 3.13, which removed the crypt module that was used to generate DES crypt(3) hashes for TACACS authentication. When ansible delegates the password encryption command to docker-ptf and it's running Python 3.13, the playbook fails. And Debian trixie's procps no longer ships sysctl.conf, requires sysctl --system instead of sysctl -p

How did you do it?

Modified the password encryption shell commands to:

  1. Try python3 -c "import crypt; ..." first (some docker-ptf images may still use python3.11)
  2. Fall back to openssl passwd -crypt -salt ab if Python's crypt module is unavailable
  3. Both methods produce identical DES crypt(3) hashes expected by tac_plus daemon
  4. Replaced sysctl -p (legacy sysctl.conf) with sysctl --system (reads drop-in dirs)

How did you verify/test it?

Any platform specific information?

Supported testbed topology if it's a new test case?

Documentation

Signed-off-by: Sonic Build Admin sonicbld@microsoft.com

<!--
Please make sure you've read and understood our contributing guidelines;
https://github.com/sonic-net/SONiC/blob/gh-pages/CONTRIBUTING.md

Please provide following information to help code review process a bit easier:
-->
### Description of PR
<!--
- Please include a summary of the change and which issue is fixed.
- Please also include relevant motivation and context. Where should reviewer start? background context?
- List any dependencies that are required for this change.
-->

Summary:
Fixes compatibility issues with Python 3.13 docker-ptf container and newer Debian PTF images:

TACACS daemon startup failure when docker-ptf uses Python 3.13 (crypt module removed)
sysctl configuration failure on newer Debian trixie PTF images

### Type of change

<!--
- Fill x for your type of change.
- e.g.
- [x] Bug fix
-->

- [ ] Bug fix
- [x] Testbed and Framework(new/improvement)
- [ ] New Test case
    - [ ] Skipped for non-supported platforms
- [ ] Test case improvement

### Back port request
- [ ] 202311
- [ ] 202405
- [ ] 202411
- [ ] 202505
- [ ] 202511
- [ ] 202512
- [x] 202605

### Approach
#### What is the motivation for this PR?
Docker-ptf needs to migrate from Bookworm to Trixie. and the python version in Trixie is 3.13, which removed the crypt module that was used to generate DES crypt(3) hashes for TACACS authentication. When ansible delegates the password encryption command to docker-ptf and it's running Python 3.13, the playbook fails. And Debian trixie's procps no longer ships `sysctl.conf`, requires `sysctl --system` instead of `sysctl -p`
#### How did you do it?
Modified the password encryption shell commands to:
1. Try python3 -c "import crypt; ..." first (some docker-ptf images may still use python3.11)
2. Fall back to openssl passwd -crypt -salt ab if Python's crypt module is unavailable
3. Both methods produce identical DES crypt(3) hashes expected by tac_plus daemon
4. Replaced `sysctl -p` (legacy `sysctl.conf`) with `sysctl --system` (reads drop-in dirs)
#### How did you verify/test it?

#### Any platform specific information?

#### Supported testbed topology if it's a new test case?

### Documentation
<!--
(If it's a new feature, new test case)
Did you update documentation/Wiki relevant to your implementation?
Link to the wiki page?
-->

Signed-off-by: Sonic Build Admin <sonicbld@microsoft.com>
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

Original PR: sonic-net/sonic-mgmt#25576

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@bingwang-ms
bingwang-ms merged commit 6f8f748 into Azure:202512 Aug 28, 2026
3 checks passed
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines will not run the associated pipelines, because the pull request was updated after the run command was issued. Review the pull request again and issue a new run command.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants