From 449525c4b3122925bc46752619a53c0d3230e640 Mon Sep 17 00:00:00 2001 From: Armando Acosta Date: Fri, 1 Nov 2024 14:13:03 -0600 Subject: [PATCH] Fix RH references for OL Update fapolicy_default_deny and libreport-plugin rules to omit RH references in OL build Signed-off-by: Armando Acosta --- .../fapolicyd/fapolicy_default_deny/ansible/shared.yml | 2 ++ .../services/fapolicyd/fapolicy_default_deny/bash/shared.sh | 2 ++ .../package_libreport-plugin-logger_removed/rule.yml | 4 ++++ 3 files changed, 8 insertions(+) diff --git a/linux_os/guide/services/fapolicyd/fapolicy_default_deny/ansible/shared.yml b/linux_os/guide/services/fapolicyd/fapolicy_default_deny/ansible/shared.yml index 16aa203f3ea..627e5fdb7aa 100644 --- a/linux_os/guide/services/fapolicyd/fapolicy_default_deny/ansible/shared.yml +++ b/linux_os/guide/services/fapolicyd/fapolicy_default_deny/ansible/shared.yml @@ -7,7 +7,9 @@ - name: {{{ rule_title }}} - Ensure a Final Rule Denying Everything ansible.builtin.copy: content: | + {{%- if 'ol' not in families %}} # Red Hat KCS 7003854 (https://access.redhat.com/solutions/7003854) + {{%- endif %}} deny perm=any all : all dest: /etc/fapolicyd/rules.d/99-deny-everything.rules owner: root diff --git a/linux_os/guide/services/fapolicyd/fapolicy_default_deny/bash/shared.sh b/linux_os/guide/services/fapolicyd/fapolicy_default_deny/bash/shared.sh index af00aa0ee72..e0dc973b3cd 100644 --- a/linux_os/guide/services/fapolicyd/fapolicy_default_deny/bash/shared.sh +++ b/linux_os/guide/services/fapolicyd/fapolicy_default_deny/bash/shared.sh @@ -5,7 +5,9 @@ # disruption = low cat > /etc/fapolicyd/rules.d/99-deny-everything.rules << EOF +{{%- if 'ol' not in families %}} # Red Hat KCS 7003854 (https://access.redhat.com/solutions/7003854) +{{%- endif %}} deny perm=any all : all EOF diff --git a/linux_os/guide/system/software/system-tools/package_libreport-plugin-logger_removed/rule.yml b/linux_os/guide/system/software/system-tools/package_libreport-plugin-logger_removed/rule.yml index f368ebbbe05..810e4f9c6bc 100644 --- a/linux_os/guide/system/software/system-tools/package_libreport-plugin-logger_removed/rule.yml +++ b/linux_os/guide/system/software/system-tools/package_libreport-plugin-logger_removed/rule.yml @@ -8,7 +8,11 @@ description: |- rationale: |- libreport-plugin-logger is a ABRT plugin to report bugs into the + {{%- if 'ol' in families %}} + Oracle Linux Support system. + {{%- else %}} Red Hat Support system. + {{%- endif %}} severity: low