plus3it / plus3it/ash-linux-formula
[BUG] Missing Dependency in `ash-linux/el8/STIGbyID/cat2/RHEL-08-030590.sls`
Nobody has claimed this yet.
- Dominant language
- SaltStack
- Stars
- 19
- Forks
- 17
- PR merge metrics
- No merged PRs in 30d
Description
Describe the bug
If not running the entirety of the ash-linux-formula – specifically triggerable if invoking watchmaker with --exclude-states ash-linux.el8.VendorSTIG.remediate – this state will fail due to file not found for the /etc/audit/rules.d/logins.rules file.
Severity
Breaks the ability to do some partial watchmaker executions
To Reproduce
Steps to reproduce the behavior:
-
Launch an EL8-based EC2 (etc)
-
Invoke watchmaker with
watchmaker --exclude-states ash-linux.el8.VendorSTIG.remediate -
Wait for watchmaker to exit
-
See error like:
Log faillock modifications (RHEL-08-030590): __id__: Log faillock modifications (RHEL-08-030590) __run_num__: 81 __sls__: ash-linux.el8.STIGbyID.cat2.RHEL-08-030590 changes: {} comment: '/etc/audit/rules.d/logins.rules: file not found' duration: 10.043 name: /etc/audit/rules.d/logins.rules result: false start_time: '14:02:03.551634'In the watchmaker logs:
Expected behavior
The state should be successfully executable regardless of exclusions of other states.
Deviance Description
Screenshots
Additional context
Fix Suggestions
Add a step to the formula that ensures that the target file exists before executing attempts to alter it.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with ash-linux/el8/STIGbyID/cat2/RHEL-08-030590.sls and reproduce with watchmaker --exclude-states ash-linux.el8.VendorSTIG.remediate on an EL8 system. Confirm the state no longer fails because /etc/audit/rules.d/logins.rules is missing, and verify it runs successfully when other states are excluded.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- linux
- Domain
- operating-systems, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 58/100