Skip to content

Clarification in describe_module_disable macro - #13909

Merged
jan-cerny merged 2 commits into
ComplianceAsCode:masterfrom
Arden97:RHEL-106814-update
Sep 22, 2025
Merged

Clarification in describe_module_disable macro#13909
jan-cerny merged 2 commits into
ComplianceAsCode:masterfrom
Arden97:RHEL-106814-update

Conversation

@Arden97

@Arden97 Arden97 commented Sep 19, 2025

Copy link
Copy Markdown
Member

Description:

Adding some clarifications about using install {module} /bin/false and install {module} /bin/true in remediation scripts for disabling kernel modules.

Rationale:

Changes were made in response to a RHEL-106814 ticket on Jira.

Review Hints:

  • Shared macro describe_module_disable in /shared/macros/01-general.jinja file was modified. These changes will affect all of the rules that are using kernel_module_disabled template

@openshift-ci

openshift-ci Bot commented Sep 19, 2025

Copy link
Copy Markdown

Hi @Arden97. Thanks for your PR.

I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci openshift-ci Bot added the needs-ok-to-test Used by openshift-ci bot. label Sep 19, 2025
@jan-cerny jan-cerny self-assigned this Sep 19, 2025
@jan-cerny jan-cerny added this to the 0.1.79 milestone Sep 19, 2025

@jan-cerny jan-cerny left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The fail of Automatus jobs is caused by running the kernel modules test scenarios as identified by CTF on a container back end which doesn't contain any kernel. The fail isn't caused by the contents of this PR. I have verified that this change updated the description in kernel_module_usb-storage_disabled.

@jan-cerny
jan-cerny merged commit a8c9174 into ComplianceAsCode:master Sep 22, 2025
121 of 126 checks passed
@Arden97
Arden97 deleted the RHEL-106814-update branch September 22, 2025 08:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-ok-to-test Used by openshift-ci bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants