openstack-ansible-security fails on the audit package verification when run a second time

Bug #1649991 reported by Nikhil Gupta
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack-Ansible
Fix Released
Low
Unassigned

Bug Description

On the newton/stable branch the openstack-ansible-security role fails on the task `Check audit package contents for alterations with rpm (for V-38637)` when the role is run a second time for centos or rhel operating systems.

The shell command "rpmverify audit audit-libs | grep -v -E '\\.conf$'| wc -l" fails to take into account that the /var/log/audit directory would change as it would have new audit logs under it during the run after the first run.

This is not an issue on the master.

Revision history for this message
Nikhil Gupta (lihkin) wrote :
Revision history for this message
Enzo (enzowang-nz) wrote :

I met the same issue. /var/log/audit triggers the failure.

Changed in openstack-ansible:
importance: Undecided → Low
assignee: nobody → Logan V (loganv)
assignee: Logan V (loganv) → nobody
Revision history for this message
Logan V (loganv) wrote :
Revision history for this message
Logan V (loganv) wrote :

Also, the above patch has merged into Newton, so this should be fixed in the stable/newton branch currently.

Revision history for this message
Jean-Philippe Evrard (jean-philippe-evrard) wrote :

I'll mark this as Fix Released, and we'll wait for the OP feedback/re-opening.

Changed in openstack-ansible:
status: New → Fix Released
Revision history for this message
Nikhil Gupta (lihkin) wrote :

Thanks for the fix. Looks good.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.