v3.3.6
aartool plan now runs to completion on a fresh host.
localhost : ok=128 changed=74 unreachable=0 failed=0 skipped=339
TASK [CyberAar | Hardening complete notification]
Everything since 3.3.3 has been working toward this. Before it, the preview stopped at whichever blocker came first.
What was stopping it
AIDE initialisation used async, which Ansible refuses under --check: "check mode and async cannot be used on same task". It is a validation error, raised before the task would have been skipped for being a command, so the run died rather than previewing. It is the only async task in the codebase.
The GRUB bootloader role failed the whole run when LINUX_BOOTLOADER_PASSWORD was unset, three lines after run-hardening.sh printed "bootloader_password role will be skipped". The wrapper's promise and the role's behaviour contradicted each other and the role won, so a first preview on an ordinary server died on a variable the user had just been told was optional. Only WSL escaped it, because the role skips itself there for unrelated reasons.
Behaviour change: asking for a GRUB password without providing one no longer aborts the run. Both bootloader roles now skip with an explanation.
The arc
| release | what a preview hit |
|---|---|
| 3.3.4 | ufw not installed |
| 3.3.5 | 40 service tasks whose unit did not exist |
| 3.3.6 | async, then a role failing on an optional variable |
Every one reported by someone running the tool, none found by reading it. Thank you to everyone who ran plan on a machine that was not ready for it: that is exactly the machine the first run happens on.
Upgrade
sudo apt update && sudo apt upgrade aartool
sudo dnf upgrade aartool