feat: run commands and streams on an exec channel, reach the container engine #18

Merged
christianmanivong merged 1 commits from feat/container-engine-channel into master 2026-10-07 16:04:33 +00:00
Owner

Implements the public channel and container engine access from NAPALM/napalm-device-types#18 (NetOrk/netork#765, phase 1 = netork#769).

  • run_command() / open_stream() open an exec channel on netmiko's existing SSH transport (remote_conn_pre.get_transport()): no second login, no PTY, separate stderr, real exit code.
  • privileged=True: root runs directly; with a sudo password sudo -S -p '' sh -c '<cmd>' with the password on stdin (never on the command line), stdin data follows it; without one sudo -n, which fails instead of prompting.
  • ContainerEngineMixin mixed in, so open_container_engine("docker").open_api() streams the Engine API over docker system dial-stdio. OpenMediaVault and QNAP inherit it.
  • Existing Docker methods (get_docker_info, get_docker_outdated, ...) unchanged; they go in phase 9.

Tests: tests/test_command_channel.py (all three privilege paths, stdin ordering, stream prefix, dial-stdio, closed connection); suite 134 passed against the device-types branch.

Depends on NAPALM/napalm-device-types#18: CI installs napalm-device-types from main, so it goes green only after that merge.

Priority: P3

Refs NAPALM/napalm-device-types#17

Implements the public channel and container engine access from NAPALM/napalm-device-types#18 (NetOrk/netork#765, phase 1 = netork#769). - `run_command()` / `open_stream()` open an exec channel on netmiko's existing SSH transport (`remote_conn_pre.get_transport()`): no second login, no PTY, separate stderr, real exit code. - `privileged=True`: root runs directly; with a sudo password `sudo -S -p '' sh -c '<cmd>'` with the password on stdin (never on the command line), stdin data follows it; without one `sudo -n`, which fails instead of prompting. - `ContainerEngineMixin` mixed in, so `open_container_engine("docker").open_api()` streams the Engine API over `docker system dial-stdio`. OpenMediaVault and QNAP inherit it. - Existing Docker methods (`get_docker_info`, `get_docker_outdated`, ...) unchanged; they go in phase 9. Tests: `tests/test_command_channel.py` (all three privilege paths, stdin ordering, stream prefix, dial-stdio, closed connection); suite 134 passed against the device-types branch. **Depends on NAPALM/napalm-device-types#18**: CI installs napalm-device-types from main, so it goes green only after that merge. Priority: P3 Refs NAPALM/napalm-device-types#17
christianmanivong added 1 commit 2026-10-07 15:59:45 +00:00
feat: run commands and streams on an exec channel, reach the container engine
CI / test (3.10) (push) Failing after 16s
CI / test (3.11) (push) Failing after 16s
CI / test (3.12) (push) Successful in 39s
CI / test (3.10) (pull_request) Successful in 38s
CI / test (3.11) (pull_request) Successful in 36s
CI / test (3.12) (pull_request) Successful in 38s
51ee33eebe
netOrk drove this driver's shell through the private `_send` (an
interactive PTY, stdout and stderr merged, no exit code) and opened its
own paramiko connections for Docker. napalm-device-types 2.6.0 makes the
channel public; this implements it (NetOrk/netork#765):

- `run_command()` and `open_stream()` open an exec channel on the SSH
  transport netmiko already holds: no second login, no PTY, a real exit
  status.
- `privileged=True` follows the driver's existing rules: as root the
  command runs directly; with a sudo password it goes through
  `sudo -S -p ''` and the password is written to stdin, never onto the
  command line; without one `sudo -n` fails at once instead of hanging.
- `ContainerEngineMixin` is mixed in, so `open_container_engine("docker")`
  streams the Engine API over `docker system dial-stdio`.

The existing Docker methods are unchanged. Version 0.2.0, requires
napalm-device-types >= 2.6.0.

Refs NAPALM/napalm-device-types#17
christianmanivong merged commit fe29b507b0 into master 2026-10-07 16:04:33 +00:00
christianmanivong deleted branch feat/container-engine-channel 2026-10-07 16:04:33 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: NAPALM/napalm-linux#18