Skip to content

v3.3.5

Choose a tag to compare

@Bantou96 Bantou96 released this 27 Aug 15:51
· 57 commits to main since this release
c899456

40 of the 48 service tasks in the roles could not survive a preview.

aartool plan runs the hardening playbook with --check, which installs nothing. A role that installs a package and then starts its service therefore met a unit that was not there:

TASK [linux_ssh_hardening_ubuntu : Enable and start ssh service]
fatal: [localhost]: FAILED! => "Could not find the requested service ssh"

That task was already guarded, on _skip_service_mgmt, which covers WSL without systemd. Modern WSL has systemd, so the guard passed and the unit was still absent. A when: on a service task does not mean it is guarded against the unit not existing, which is why fixing the same shape on ufw in 3.3.4 did not prevent this one.

The playbook now inventories the systemd units once, in a pre_task with check_mode: false, and every service task with a literal name is guarded on it in check mode only. Behaviour outside a preview is unchanged.

Of the 48 service tasks, the 8 left alone were already safe: six name no service (daemon-reload cannot fail this way), two use templated names guarded on ansible_facts.services, and one tolerates failure.

test_service_guards.sh enforces this for every future service task and runs in CI, so the class cannot come back one role at a time.

Thanks

Reported by a user running aartool plan on WSL, as was the 3.3.4 firewall bug. WSL is not the target platform, and that is exactly why those reports were valuable: a real server already has ufw, ssh and systemd present, so the whole class was invisible there.

Upgrade

sudo apt update && sudo apt upgrade aartool
sudo dnf upgrade aartool