Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fixes in file_groupownership template #10666

Merged
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -34,5 +34,5 @@ template:
name: file_groupowner
vars:
filepath: ^/etc/cni/net.d/.*$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -42,5 +42,5 @@ template:
name: file_groupowner
vars:
filepath: ^/etc/kubernetes/static-pod-resources/kube-controller-manager-pod-.*/configmaps/controller-manager-kubeconfig/kubeconfig$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -41,4 +41,4 @@ template:
name: file_groupowner
vars:
filepath: /var/lib/etcd/member/
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -41,5 +41,5 @@ template:
name: file_groupowner
vars:
filepath: ^/var/lib/etcd/member/wal/.*$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -43,5 +43,5 @@ template:
name: file_groupowner
vars:
filepath: ^/etc/kubernetes/static-pod-resources/etcd-pod-.*/etcd-pod.yaml$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -56,5 +56,5 @@ template:
name: file_groupowner
vars:
filepath: ^/etc/kubernetes/static-pod-resources/.*/.*/.*/.*\.crt$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -35,5 +35,5 @@ template:
name: file_groupowner
vars:
filepath: ^/var/lib/cni/networks/openshift-sdn/.*$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -41,4 +41,4 @@ template:
vars:
filepath: "^/etc/kubernetes/static-pod-resources/kube-apiserver-pod-.*/kube-apiserver-pod.yaml$"
filepath_is_regex: "true"
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -41,4 +41,4 @@ template:
vars:
filepath: '^/etc/kubernetes/static-pod-resources/kube-controller-manager-pod-.*/kube-controller-manager-pod.yaml$'
filepath_is_regex: 'true'
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -40,5 +40,5 @@ template:
name: file_groupowner
vars:
filepath: ^/etc/kubernetes/static-pod-resources/kube-scheduler-pod-.*/kube-scheduler-pod.yaml$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -28,4 +28,4 @@ ocil: |-
# name: file_groupowner
# vars:
# filepath: /etc/kubernetes/kubeconfig
# filegid: '0'
# gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -46,5 +46,5 @@ template:
name: file_groupowner
vars:
filepath: ^/etc/kubernetes/static-pod-resources/kube-apiserver-certs/secrets/node-kubeconfigs/.*\.kubeconfig$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -34,5 +34,5 @@ template:
name: file_groupowner
vars:
filepath: ^/var/run/multus/cni/net.d/.*$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -56,5 +56,5 @@ template:
name: file_groupowner
vars:
filepath: ^/etc/kubernetes/static-pod-resources/.*/.*/.*/tls\.crt$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -56,5 +56,5 @@ template:
name: file_groupowner
vars:
filepath: ^/etc/kubernetes/static-pod-resources/.*/.*/.*/.*\.key$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -35,4 +35,4 @@ template:
name: file_groupowner
vars:
filepath: /var/run/openshift-sdn/cniserver/config.json
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -30,4 +30,4 @@ template:
vars:
filepath: /etc/openvswitch/
file_regex: ^.*$
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -35,4 +35,4 @@ template:
name: file_groupowner
vars:
filepath: /run/ovn-kubernetes/cni/ovn-cni-server.sock
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -35,5 +35,5 @@ template:
name: file_groupowner
vars:
filepath: ^/var/lib/ovn/etc/*.db$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -35,4 +35,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/openvswitch/.conf.db.~lock~
filegid: 'hugetlbfs'
gid_or_name: 'hugetlbfs'
Original file line number Diff line number Diff line change
Expand Up @@ -35,4 +35,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/openvswitch/.conf.db.~lock~
filegid: 'hugetlbfs'
gid_or_name: 'hugetlbfs'
Original file line number Diff line number Diff line change
Expand Up @@ -35,4 +35,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/openvswitch/conf.db
filegid: 'hugetlbfs'
gid_or_name: 'hugetlbfs'
Original file line number Diff line number Diff line change
Expand Up @@ -35,4 +35,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/openvswitch/conf.db
filegid: openvswitch
gid_or_name: openvswitch
Original file line number Diff line number Diff line change
Expand Up @@ -35,4 +35,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/openvswitch/system-id.conf
filegid: 'hugetlbfs'
gid_or_name: 'hugetlbfs'
Original file line number Diff line number Diff line change
Expand Up @@ -35,4 +35,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/openvswitch/system-id.conf
filegid: 'hugetlbfs'
gid_or_name: 'hugetlbfs'
Original file line number Diff line number Diff line change
Expand Up @@ -42,5 +42,5 @@ template:
name: file_groupowner
vars:
filepath: ^/etc/kubernetes/static-pod-resources/kube-scheduler-pod-.*/configmaps/scheduler-kubeconfig/kubeconfig$
filegid: '0'
gid_or_name: '0'
filepath_is_regex: "true"
Original file line number Diff line number Diff line change
Expand Up @@ -39,4 +39,4 @@ template:
name: file_groupowner
vars:
filepath: {{{ kubeletconf_path }}}
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/kubernetes/kubelet-ca.crt
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@ template:
name: file_groupowner
vars:
filepath: /var/lib/kubelet/kubeconfig
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -36,4 +36,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/systemd/system/kubelet.service
filegid: '0'
gid_or_name: '0'
5 changes: 4 additions & 1 deletion docs/templates/template_reference.md
Original file line number Diff line number Diff line change
Expand Up @@ -279,7 +279,10 @@
subdirectories under the directory specified by **filepath**. Default
value is `"false"`.

- **filegid** - group ID (GID)
- **gid_or_name** - group ID (GID) or a group name.
If the parameter is an integer, it is treated as group ID. If the
parameter is not an integer, it is treated as a group name and it is
converted to GID by reading /etc/group.

- Languages: Ansible, Bash, OVAL

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -53,4 +53,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/cron.d/
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -53,4 +53,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/cron.daily/
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -53,4 +53,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/cron.hourly/
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -53,4 +53,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/cron.monthly/
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -53,4 +53,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/cron.weekly/
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -53,4 +53,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/crontab
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -43,4 +43,4 @@ template:
vars:
filepath: /etc/at.allow
missing_file_pass: 'true'
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -54,4 +54,4 @@ template:
vars:
filepath: /etc/cron.allow
missing_file_pass: 'true'
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -29,5 +29,5 @@ template:
name: file_groupowner
vars:
filepath: /etc/hosts.allow
filegid: '0'
gid_or_name: '0'
missing_file_pass: 'true'
Original file line number Diff line number Diff line change
Expand Up @@ -29,5 +29,5 @@ template:
name: file_groupowner
vars:
filepath: /etc/hosts.deny
filegid: '0'
gid_or_name: '0'
missing_file_pass: 'true'
Original file line number Diff line number Diff line change
Expand Up @@ -55,4 +55,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/ssh/sshd_config
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -35,4 +35,4 @@ template:
- /etc/ssh/
file_regex:
- ^.*_key$
filegid: '{{{ dedicated_ssh_groupname if dedicated_ssh_groupname else '0' }}}'
gid_or_name: '{{{ dedicated_ssh_groupname if dedicated_ssh_groupname else '0' }}}'
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
#!/bin/bash
# platform = multi_platform_ol,multi_platform_rhel

if ! grep -q ssh_keys /etc/group; then
groupadd ssh_keys
fi

FAKE_KEY=$(mktemp -p /etc/ssh/ XXXX_key)
chgrp ssh_keys "$FAKE_KEY"
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
deny_templated_scenarios:
- missing_file_test.pass.sh
Original file line number Diff line number Diff line change
Expand Up @@ -34,5 +34,5 @@ template:
- /etc/ssh/
file_regex:
- ^.*\.pub$
filegid: '0'
gid_or_name: '0'
missing_file_pass: 'true'
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
#!/bin/bash
# platform = multi_platform_ol,multi_platform_rhel

rm -f /etc/ssh/*.pub
Original file line number Diff line number Diff line change
Expand Up @@ -43,4 +43,4 @@ template:
name: file_groupowner
vars:
filepath: /etc/issue
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -41,5 +41,5 @@ template:
name: file_groupowner
vars:
filepath: /etc/issue.net
filegid: '0'
gid_or_name: '0'
missing_file_pass: 'true'
Original file line number Diff line number Diff line change
Expand Up @@ -43,5 +43,5 @@ template:
name: file_groupowner
vars:
filepath: /etc/motd
filegid: '0'
gid_or_name: '0'
missing_file_pass: 'true'
Original file line number Diff line number Diff line change
Expand Up @@ -32,4 +32,4 @@ template:
name: file_groupowner
vars:
filepath: /usr/bin/lastlog
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -40,4 +40,4 @@ template:
file_regex:
- ^audit(\.rules|d\.conf)$
- ^.*\.rules$
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -61,4 +61,4 @@ template:
name: file_groupowner
vars:
filepath: {{{ grub2_boot_path }}}/grub.cfg
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -54,4 +54,4 @@ template:
name: file_groupowner
vars:
filepath: {{{ grub2_boot_path }}}/user.cfg
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -50,4 +50,4 @@ template:
name: file_groupowner
vars:
filepath: {{{ grub2_uefi_boot_path }}}/grub.cfg
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -48,4 +48,4 @@ template:
name: file_groupowner
vars:
filepath: {{{ grub2_uefi_boot_path }}}/user.cfg
filegid: '0'
gid_or_name: '0'
Original file line number Diff line number Diff line change
Expand Up @@ -47,5 +47,5 @@ template:
name: file_groupowner
vars:
filepath: /etc/group-
filegid: '0'
gid_or_name: '0'
missing_file_pass: 'true'
Original file line number Diff line number Diff line change
Expand Up @@ -52,11 +52,11 @@ template:
name: file_groupowner
vars:
filepath: /etc/gshadow-
filegid: '0'
filegid@debian10: '42'
filegid@debian11: '42'
filegid@ubuntu1604: '42'
filegid@ubuntu1804: '42'
filegid@ubuntu2004: '42'
filegid@ubuntu2204: '42'
gid_or_name: '0'
gid_or_name@debian10: '42'
gid_or_name@debian11: '42'
gid_or_name@ubuntu1604: '42'
gid_or_name@ubuntu1804: '42'
gid_or_name@ubuntu2004: '42'
gid_or_name@ubuntu2204: '42'
missing_file_pass: 'true'
Original file line number Diff line number Diff line change
Expand Up @@ -47,5 +47,5 @@ template:
name: file_groupowner
vars:
filepath: /etc/passwd-
filegid: '0'
gid_or_name: '0'
missing_file_pass: 'true'
Loading
Loading