# Restrict instance-identifier in must statement

**URL:** <https://dmap-community.ductus.global/t/restrict-instance-identifier-in-must-statement/579>\
**Category:** YANG\
**Created:** [July 14, 2016, 6:58am UTC](https://dmap-community.ductus.global/t/restrict-instance-identifier-in-must-statement/579 "2016-07-14T06:58:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![JamesZhang](https://avatars.discourse-cdn.com/v4/letter/j/c89c15/32.png) [@JamesZhang](https://dmap-community.ductus.global/u/JamesZhang)\
**Post date:** [July 14, 2016, 6:58am UTC](https://dmap-community.ductus.global/t/restrict-instance-identifier-in-must-statement/579/1 "2016-07-14T06:58:05Z")

</div>

I am trying to write must statement to restrict the instance-identifier, if ref is for instance of “/container/foo”, range should be from 1 to 100, if ref is for instance of “/ifs/if”, range should be from 101 to 200.  
I am not sure how to write the must statement in container test below.

yang example:  
container ifs {  
list if {  
key “name”;  
leaf name {  
type string;  
}  
}  
}  
container foo {  
list bar {  
key “name”;  
leaf name {  
type string;  
}  
}  
}

container test {  
/_if ref is for instance of “/container/foo”, range should be from 1 to 100._/  
/_if ref is for instance of “/ifs/if”, range should be from 101 to 200._/  
must “??” {}  
error-message;  
}  
leaf ref {  
type instance-identifier;  
}  
leaf range {  
type uint32;  
}  
}

---

<div class="post-metadata">

**Author:** ![waitai](https://yyz2.discourse-cdn.com/flex010/user_avatar/dmap-community.ductus.global/waitai/32/436_2.png) [@waitai](https://dmap-community.ductus.global/u/waitai)\
**Post date:** [July 14, 2016, 7:38pm UTC](https://dmap-community.ductus.global/t/restrict-instance-identifier-in-must-statement/579/2 "2016-07-14T19:38:45Z")

</div>

You can write your must statement as follows for the leaf node named range:

```
leaf range {
  type uint32;
  must "(starts-with (.., '/ifs:ifs') and . > 100 and . < 201)
         or (starts-with(.., '/ifs:foo') and . > 0 and . < 101)";
}

```

in which the first ifs after the / is the prefix for your YANG module.

---

<div class="post-metadata">

**Author:** ![JamesZhang](https://avatars.discourse-cdn.com/v4/letter/j/c89c15/32.png) [@JamesZhang](https://dmap-community.ductus.global/u/JamesZhang)\
**Post date:** [July 19, 2016, 6:26am UTC](https://dmap-community.ductus.global/t/restrict-instance-identifier-in-must-statement/579/3 "2016-07-19T06:26:50Z")

</div>

thanks, it works. thanks for helping on this, with tailf:annotate statement, there is a clear approach to have such validation logic yang model without polluting the original data model.  
btw:do we have some typical use cases of using xpath for must statement? I don’t have much more knowledge on it.

---

<div class="post-metadata">

**Author:** ![waitai](https://yyz2.discourse-cdn.com/flex010/user_avatar/dmap-community.ductus.global/waitai/32/436_2.png) [@waitai](https://dmap-community.ductus.global/u/waitai)\
**Post date:** [July 19, 2016, 4:36pm UTC](https://dmap-community.ductus.global/t/restrict-instance-identifier-in-must-statement/579/4 "2016-07-19T16:36:32Z")

</div>

The use of must statements in YANG models are very common. For example, it is being used in an IETF standardized YANG model called ietf-system.yang which is part of the linuxcfg example in the ConfD distribution.

---

<div class="post-metadata">

**Author:** ![JamesZhang](https://avatars.discourse-cdn.com/v4/letter/j/c89c15/32.png) [@JamesZhang](https://dmap-community.ductus.global/u/JamesZhang)\
**Post date:** [July 20, 2016, 6:44am UTC](https://dmap-community.ductus.global/t/restrict-instance-identifier-in-must-statement/579/5 "2016-07-20T06:44:56Z")

</div>

Thanks for helping this 🙂

---

<div class="post-metadata">

**Author:** ![JamesZhang](https://avatars.discourse-cdn.com/v4/letter/j/c89c15/32.png) [@JamesZhang](https://dmap-community.ductus.global/u/JamesZhang)\
**Post date:** [September 22, 2016, 2:03am UTC](https://dmap-community.ductus.global/t/restrict-instance-identifier-in-must-statement/579/6 "2016-09-22T02:03:24Z")

</div>

if the case is instance-identifier to point to a deep path, which more list data node in that path (e.g. /foo/bar[name=n1]/bar2[name=n2]/bar3[name=n3]), I guess there is no way to use regex function from xpath 1.0 to match that path.  
I know we have valdation callpoint can help on this, if it is can be done in yang model it could be better.

---

<div class="post-metadata">

**Author:** ![JamesZhang](https://avatars.discourse-cdn.com/v4/letter/j/c89c15/32.png) [@JamesZhang](https://dmap-community.ductus.global/u/JamesZhang)\
**Post date:** [September 22, 2016, 2:51am UTC](https://dmap-community.ductus.global/t/restrict-instance-identifier-in-must-statement/579/7 "2016-09-22T02:51:37Z")

</div>

I found `re-match` function in manual, it could help this case.

---

<div class="post-metadata">

**Author:** ![per](https://avatars.discourse-cdn.com/v4/letter/p/9f8e36/32.png) [@per](https://dmap-community.ductus.global/u/per)\
**Post date:** [September 22, 2016, 7:44pm UTC](https://dmap-community.ductus.global/t/restrict-instance-identifier-in-must-statement/579/8 "2016-09-22T19:44:29Z")

</div>

Check out the extension tailf:path-filters in the tailf\_yang\_extensions(5) manual page.
