The Crappy Cisco IOS CLI Error Reporting
TL&DR: It’s really hard to figure out when a Cisco IOS box configured via its CLI reports a configuration error.
One of the drawbacks of using Netmiko to configure network devices is its inherent lack of error detection – while it can switch into configuration mode and exit it (including a commit operation if needed), it doesn’t detect configuration errors.
No big deal (I thought); the configuration error messages generated by Cisco IOS always start with a percent sign (%), so I’d just use that as the error_pattern parameter of the send_config_from_file command. A few integration test failures later, that turned out to be a bad idea; Cisco IOS starts errors and warnings with the percentage sign, and there’s absolutely no reliable way to differentiate between the two.
An idealist might think being careful when creating device configuration templates helps. After all, everything works as expected if your configuration commands don’t trigger a warning, right? Nope; some features (for example, DHCP pools without directly connected subnets) cannot be configured without creating a warning.
But wait, I had another idea: what if I could match lines that start with a percent sign but do not include ‘warning’? I probably missed something (negative lookahead has supposedly been available “forever”), but the regular expression I created worked well in Python 3.14, but not in Python 3.10 (which we still support due to Ubuntu 22.02 support). Anyway, after that, I understood the crazy list of “these are true errors” in the Ansible Cisco IOS terminal driver.
Fortunately, some newer operating systems aren’t so sloppy; using ^% as the error-detecting regular expression worked just fine on Arista EOS.
But They Didn’t Know Better (Oh, Really?)
Before someone tells me Cisco IOS is over 40 years old, and we didn’t know we’d need easy-to-recognize error messages in those days:
- I’ve been working on a VAX/VMS system in the early 1980s1, and its error messages were very easy to recognize (hint: they started with a percentage sign ;) and were easy to parse, for example:
%TYPE-W-SEARCHFAIL, error searching for DKA0:[000000]NOTHHERE.LIS;
-RMS-E-FNF, file not found
- VAX/VMS predates Cisco IOS by a few years. VAX/VMS was released in 1977; early Cisco IOS code was supposedly written in the early 1980s.
- The first version of Cisco IOS I worked with in early 1990s (8.x) already generated nice messages we’re all familiar with, for example:
%SYS-5-CONFIG_I: Configured from console by admin on vty0 (192.168.121.1)
- I was so delighted when I first saw those messages; they immediately reminded me of VAX/VMS error messages (including the starting percentage sign). Little did I know the only reason they were structured so nicely was the Syslog message format.
Alas, nobody thought about other consumers of the device CLI beyond human eyes in those days, so we’ve been stuck with a careless (in retrospect) hard-to-deal-with implementation for almost half a century.
-
Sharing 2MB of RAM with 30 other interactive users ↩︎