Conversation
|
This datastream diff is auto generated by the check Click here to see the full diffansible remediation for rule 'xccdf_org.ssgproject.content_rule_file_permission_user_init_files' differs.
--- xccdf_org.ssgproject.content_rule_file_permission_user_init_files
+++ xccdf_org.ssgproject.content_rule_file_permission_user_init_files
@@ -46,6 +46,7 @@
ansible.builtin.file:
path: '{{ item.1.path }}'
mode: u-s,g-wxs,o=
+ follow: false
loop: '{{ q(''ansible.builtin.subelements'', found_init_files.results, ''files'',
{''skip_missing'': True}) }}'
tags:
bash remediation for rule 'xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root' differs.
--- xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root
+++ xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root
@@ -12,7 +12,7 @@
if ! grep -qP "$USERS_IGNORED_REGEX" <<< "${interactive_users[$i]}" && \
[ "${interactive_users_shell[$i]}" != "/sbin/nologin" ]; then
- readarray -t init_files < <(find "${interactive_users_home[$i]}" -maxdepth 1 \
+ readarray -t init_files < <(find "${interactive_users_home[$i]}" -type f -maxdepth 1 \
-exec basename {} \; | grep -P "$var_user_initialization_files_regex")
for file in "${init_files[@]}"; do
chmod u-s,g-wxs,o= "${interactive_users_home[$i]}/$file"
ansible remediation for rule 'xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root' differs.
--- xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root
+++ xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root
@@ -46,6 +46,7 @@
ansible.builtin.file:
path: '{{ item.1.path }}'
mode: u-s,g-wxs,o=
+ follow: false
loop: '{{ q(''ansible.builtin.subelements'', found_init_files.results, ''files'',
{''skip_missing'': True}) }}'
tags: |
|
@Mab879 any idea why CaC have both |
Looks like Jan add this rule little over 2 years ago. Seems like CIS and STIG benchmark split. |
|
Ansible fix seems fine. |
f2b39bb to
d245442
Compare
That is RHEL 10+ only. Reverting. |
d245442 to
dbd5e9e
Compare
|
@Mab879: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Description:
Rationale:
Follow up to #14808