Skip to content

Commit

Permalink
More tweaks for unsafe interpolation
Browse files Browse the repository at this point in the history
  • Loading branch information
jcpunk committed Sep 5, 2023
1 parent ed0bde5 commit c7817cb
Show file tree
Hide file tree
Showing 2 changed files with 10 additions and 10 deletions.
8 changes: 4 additions & 4 deletions manifests/init.pp
Original file line number Diff line number Diff line change
Expand Up @@ -181,15 +181,15 @@
}

exec { 'firewalld::set_default_zone_active':
command => ['firewall-cmd --set-default-zone ', $default_zone],
command => ['firewall-cmd', '--set-default-zone', $default_zone],
unless => "[ $(firewall-cmd --get-default-zone) = ${default_zone} ]",
onlyif => 'firewall-cmd --state',
require => Service['firewalld'],
provider => 'shell',
}

exec { 'firewalld::set_default_zone_offline':
command => ['firewall-offline-cmd --set-default-zone ', $default_zone],
command => ['firewall-offline-cmd', '--set-default-zone', $default_zone],
unless => ["[ $(firewall-offline-cmd --get-default-zone) = ${default_zone} ]", 'firewall-cmd --state',],
require => Service['firewalld'],
provider => 'shell',
Expand All @@ -206,14 +206,14 @@
}

exec { 'firewalld::set_log_denied_active':
command => ['firewall-cmd --set-log-denied ', $log_denied],
command => ['firewall-cmd', '--set-log-denied', $log_denied],
unless => "[ $(firewall-cmd --get-log-denied) = ${log_denied} ]",
onlyif => 'firewall-cmd --state',
require => Service['firewalld'],
provider => 'shell',
}
exec { 'firewalld::set_log_denied_offline':
command => ['firewall-offline-cmd --set-log-denied ', $log_denied],
command => ['firewall-offline-cmd', '--set-log-denied', $log_denied],
unless => ["[ $(firewall-offline-cmd --get-log-denied) = ${log_denied} ]", 'firewall-cmd --state'],
require => Service['firewalld'],
provider => 'shell',
Expand Down
12 changes: 6 additions & 6 deletions spec/classes/init_spec.rb
Original file line number Diff line number Diff line change
Expand Up @@ -52,12 +52,12 @@
it do
is_expected.to contain_exec('firewalld::set_default_zone').that_requires('Service[firewalld]')
is_expected.to contain_exec('firewalld::set_default_zone_active').with(
command: ['firewall-cmd --set-default-zone ', 'restricted'],
command: ['firewall-cmd', '--set-default-zone', 'restricted'],
unless: '[ $(firewall-cmd --get-default-zone) = restricted ]',
onlyif: 'firewall-cmd --state'
).that_requires('Service[firewalld]')
is_expected.to contain_exec('firewalld::set_default_zone_offline').with(
command: ['firewall-offline-cmd --set-default-zone ', 'restricted'],
command: ['firewall-offline-cmd', '--set-default-zone', 'restricted'],
unless: ['[ $(firewall-offline-cmd --get-default-zone) = restricted ]', 'firewall-cmd --state']
).that_requires('Service[firewalld]')
end
Expand Down Expand Up @@ -258,12 +258,12 @@
it do
is_expected.to contain_exec('firewalld::set_default_zone').that_requires('Service[firewalld]')
is_expected.to contain_exec('firewalld::set_default_zone_active').with(
command: ['firewall-cmd --set-default-zone ', 'public'],
command: ['firewall-cmd', '--set-default-zone', 'public'],
unless: '[ $(firewall-cmd --get-default-zone) = public ]',
onlyif: 'firewall-cmd --state'
).that_requires('Service[firewalld]')
is_expected.to contain_exec('firewalld::set_default_zone_offline').with(
command: ['firewall-offline-cmd --set-default-zone ', 'public'],
command: ['firewall-offline-cmd', '--set-default-zone', 'public'],
unless: ['[ $(firewall-offline-cmd --get-default-zone) = public ]', 'firewall-cmd --state']
).that_requires('Service[firewalld]')
end
Expand All @@ -280,12 +280,12 @@
it do
is_expected.to contain_exec('firewalld::set_log_denied').that_requires('Service[firewalld]')
is_expected.to contain_exec('firewalld::set_log_denied_active').with(
command: ['firewall-cmd --set-log-denied ', cond],
command: ['firewall-cmd', '--set-log-denied', cond],
unless: "[ $(firewall-cmd --get-log-denied) = #{cond} ]",
onlyif: 'firewall-cmd --state'
).that_requires('Service[firewalld]')
is_expected.to contain_exec('firewalld::set_log_denied_offline').with(
command: ['firewall-offline-cmd --set-log-denied ', cond],
command: ['firewall-offline-cmd', '--set-log-denied', cond],
unless: ["[ $(firewall-offline-cmd --get-log-denied) = #{cond} ]", 'firewall-cmd --state']
).that_requires('Service[firewalld]')
end
Expand Down

0 comments on commit c7817cb

Please sign in to comment.