Skip to content

Commit 11b740c

Browse files
authored
Bug fixes pr 2.x (#2322)
* The mysql_client role assumes the deploy user exists, so it should depend on user_deploy. * Fixing pre-push git hooks. * Trying to fix ACL linting issue. * Adding default portpathwhitelist variable to rkhunter. * Accidentally doubled up on when clauses. * Adding another when to rkhunter tasks for when no port paths or scripts are defined.
1 parent 5a04ee3 commit 11b740c

File tree

2 files changed

+9
-2
lines changed

2 files changed

+9
-2
lines changed

roles/debian/rkhunter/defaults/main.yml

+1
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@ rkhunter:
1313
allow_ssh_root_user: "{{ sshd.PermitRootLogin | default('prohibit-password') }}"
1414
disable_tests: "suspscan hidden_procs deleted_files packet_cap_apps apps os_specific"
1515
os_package_manager: "NONE" # PKGMGR=NONE is default for Debian, set it to what you need.
16+
portpathwhitelist: []
1617
scriptwhitelist:
1718
- /bin/egrep
1819
- /bin/fgrep

roles/debian/rkhunter/tasks/main.yml

+8-2
Original file line numberDiff line numberDiff line change
@@ -12,23 +12,29 @@
1212
path: "{{ item }}"
1313
register: _rkhunter_existing_scripts_to_whitelist
1414
loop: "{{ rkhunter.scriptwhitelist }}"
15+
when: rkhunter.scriptwhitelist | length > 0
1516

1617
- name: Filter existing scripts
1718
set_fact:
1819
existing_scripts: "{{ existing_scripts | default([]) + [item.item] }}"
19-
when: item.stat.exists
20+
when:
21+
- item.stat.exists
22+
- _rkhunter_existing_scripts_to_whitelist is defined
2023
loop: "{{ _rkhunter_existing_scripts_to_whitelist.results }}"
2124

2225
- name: Check paths for portpath existence
2326
ansible.builtin.stat:
2427
path: "{{ item.split(':')[0] }}"
2528
register: _rkhunter_existing_portpaths_to_whitelist
2629
loop: "{{ rkhunter.portpathwhitelist }}"
30+
when: rkhunter.portpathwhitelist | length > 0
2731

2832
- name: Filter existing portpath
2933
set_fact:
3034
existing_portpaths: "{{ existing_portpaths | default([]) + [item.item] }}"
31-
when: item.stat.exists
35+
when:
36+
- item.stat.exists
37+
- _rkhunter_existing_portpaths_to_whitelist is defined
3238
loop: "{{ _rkhunter_existing_portpaths_to_whitelist.results }}"
3339

3440
- name: Copy rkhunter configuration.

0 commit comments

Comments
 (0)