Skip to content

Conversation

@teacup-on-rockingchair
Copy link
Contributor

Description:

  • Fix for some basic rules for SLE16 platform

Rationale:

  • Add support to for SLE16 in rules:

    • sebool_selinuxuser_execmod
    • rsyslog_remote_loghost
    • service_auditd_enabled
  • Make sle remediation for rsyslog_remote_loghost relevant for sle16 also

  • enable sle16 bool template for policycoreutils

Review Hints:

Rules are added in sle6 base profile until #13965 is merged

@openshift-ci
Copy link

openshift-ci bot commented Oct 22, 2025

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@openshift-ci openshift-ci bot added the do-not-merge/work-in-progress Used by openshift-ci bot. label Oct 22, 2025
@teacup-on-rockingchair teacup-on-rockingchair marked this pull request as ready for review October 22, 2025 11:26
@teacup-on-rockingchair teacup-on-rockingchair requested a review from a team as a code owner October 22, 2025 11:26
@openshift-ci openshift-ci bot removed the do-not-merge/work-in-progress Used by openshift-ci bot. label Oct 22, 2025
@teacup-on-rockingchair teacup-on-rockingchair added Ansible Ansible remediation update. Bash Bash remediation update. SLES SUSE Linux Enterprise Server product related. labels Oct 22, 2025
@teacup-on-rockingchair teacup-on-rockingchair added this to the 0.1.79 milestone Oct 22, 2025
@teacup-on-rockingchair
Copy link
Contributor Author

@vojtapolasek can you please review this since I cannot review my own stuff, and also cannot override the static-checks error that seems to be failing everywhere.

@teacup-on-rockingchair teacup-on-rockingchair marked this pull request as draft November 10, 2025 09:47
@openshift-ci openshift-ci bot added the do-not-merge/work-in-progress Used by openshift-ci bot. label Nov 10, 2025
@teacup-on-rockingchair teacup-on-rockingchair force-pushed the sle16_fix_rsyslog_remote_loghost branch from 639f63a to d4eb68e Compare November 10, 2025 10:37
@teacup-on-rockingchair teacup-on-rockingchair marked this pull request as ready for review November 10, 2025 10:39
@openshift-ci openshift-ci bot removed the do-not-merge/work-in-progress Used by openshift-ci bot. label Nov 10, 2025
@openshift-ci
Copy link

openshift-ci bot commented Nov 10, 2025

@teacup-on-rockingchair: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-aws-openshift-node-compliance 8266983 link true /test e2e-aws-openshift-node-compliance
ci/prow/e2e-aws-openshift-platform-compliance 8266983 link true /test e2e-aws-openshift-platform-compliance

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Copy link
Contributor

@svet-se svet-se left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

@teacup-on-rockingchair teacup-on-rockingchair merged commit 8a4b85f into ComplianceAsCode:master Nov 10, 2025
137 of 141 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ansible Ansible remediation update. Bash Bash remediation update. SLES SUSE Linux Enterprise Server product related.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants