import CS rhel-system-roles-2.4.0-0.1.el9

This commit is contained in:
AlmaLinux RelEng Bot 2026-08-24 09:38:16 -04:00
parent 9db4a4136a
commit eac196ff8d
5 changed files with 255 additions and 114 deletions

75
.gitignore vendored
View File

@ -1,37 +1,40 @@
SOURCES/ad_integration-1.6.3.tar.gz
SOURCES/aide-1.2.5.tar.gz
SOURCES/ad_integration-1.9.0.tar.gz
SOURCES/aide-1.4.0.tar.gz
SOURCES/ansible-posix-2.1.0.tar.gz
SOURCES/ansible-sshd-v0.31.0.tar.gz
SOURCES/auto-maintenance-1.120.5.tar.gz
SOURCES/bootloader-1.1.6.tar.gz
SOURCES/certificate-1.4.4.tar.gz
SOURCES/cockpit-1.7.4.tar.gz
SOURCES/community-general-11.4.5.tar.gz
SOURCES/containers-podman-1.19.0.tar.gz
SOURCES/crypto_policies-1.5.2.tar.gz
SOURCES/fapolicyd-1.1.12.tar.gz
SOURCES/firewall-1.11.6.tar.gz
SOURCES/gfs2-1.0.5.tar.gz
SOURCES/ha_cluster-1.29.1.tar.gz
SOURCES/journald-1.5.2.tar.gz
SOURCES/kdump-1.5.1.tar.gz
SOURCES/kernel_settings-1.3.8.tar.gz
SOURCES/keylime_server-1.2.4.tar.gz
SOURCES/logging-1.15.5.tar.gz
SOURCES/metrics-1.14.2.tar.gz
SOURCES/nbde_client-1.3.8.tar.gz
SOURCES/nbde_server-1.5.2.tar.gz
SOURCES/network-1.17.9.tar.gz
SOURCES/podman-1.9.2.tar.gz
SOURCES/postfix-1.6.6.tar.gz
SOURCES/postgresql-1.5.1.tar.gz
SOURCES/rhc-1.6.13.tar.gz
SOURCES/selinux-1.11.1.tar.gz
SOURCES/snapshot-1.6.4.tar.gz
SOURCES/ssh-1.7.1.tar.gz
SOURCES/storage-1.19.5.tar.gz
SOURCES/sudo-1.2.9.tar.gz
SOURCES/systemd-1.3.7.tar.gz
SOURCES/timesync-1.11.4.tar.gz
SOURCES/tlog-1.4.5.tar.gz
SOURCES/vpn-1.6.16.tar.gz
SOURCES/ansible-sshd-v0.34.0.tar.gz
SOURCES/auditd-1.1.0.tar.gz
SOURCES/auto-maintenance-2.4.0.tar.gz
SOURCES/bootloader-2.1.0.tar.gz
SOURCES/certificate-1.9.0.tar.gz
SOURCES/cockpit-1.9.0.tar.gz
SOURCES/community-general-11.4.9.tar.gz
SOURCES/containers-podman-1.20.2.tar.gz
SOURCES/crypto_policies-1.8.0.tar.gz
SOURCES/fapolicyd-1.3.0.tar.gz
SOURCES/firewall-1.13.0.tar.gz
SOURCES/gfs2-1.2.0.tar.gz
SOURCES/ha_cluster-1.32.1.tar.gz
SOURCES/journald-1.7.0.tar.gz
SOURCES/kdump-1.7.0.tar.gz
SOURCES/kernel_settings-1.5.0.tar.gz
SOURCES/keylime_server-1.4.0.tar.gz
SOURCES/logging-1.17.0.tar.gz
SOURCES/metrics-1.17.0.tar.gz
SOURCES/nbde_client-1.7.0.tar.gz
SOURCES/nbde_server-1.7.0.tar.gz
SOURCES/network-1.21.0.tar.gz
SOURCES/podman-1.14.1.tar.gz
SOURCES/postfix-1.9.0.tar.gz
SOURCES/postgresql-1.8.0.tar.gz
SOURCES/rhc-1.8.0.tar.gz
SOURCES/selinux-1.13.0.tar.gz
SOURCES/snapshot-1.9.0.tar.gz
SOURCES/ssh-1.9.0.tar.gz
SOURCES/storage-1.22.0.tar.gz
SOURCES/sudo-1.4.0.tar.gz
SOURCES/systemd-1.5.0.tar.gz
SOURCES/timesync-1.14.1.tar.gz
SOURCES/tlog-1.6.1.tar.gz
SOURCES/trustee_client-1.1.0.tar.gz
SOURCES/trustee_server-1.1.0.tar.gz
SOURCES/vpn-1.9.0.tar.gz

View File

@ -1,37 +1,40 @@
351dff58a5a20dbccb80d69b5b4e5f4c9f1e238c SOURCES/ad_integration-1.6.3.tar.gz
d9ac27779e8bd554a345461a6ae6e0789b543286 SOURCES/aide-1.2.5.tar.gz
d183fb7e3cde922438fa498d02b4e035d764654e SOURCES/ad_integration-1.9.0.tar.gz
bc59eda11340c9fe0f00f1b0d203a40dd7b80de0 SOURCES/aide-1.4.0.tar.gz
9db48a6875bd9371771521ee55f73a97552dbeb1 SOURCES/ansible-posix-2.1.0.tar.gz
d16bfd57e9f9d13a339a51d5c56ed65c101e7345 SOURCES/ansible-sshd-v0.31.0.tar.gz
aae4d4684f98b95b19d8479265c777693cc7b43e SOURCES/auto-maintenance-1.120.5.tar.gz
9ab440814465c1b4d6cfadcf655f92f29e8e16a5 SOURCES/bootloader-1.1.6.tar.gz
875efc924ce3979236bf995f0fbc7eca8580c112 SOURCES/certificate-1.4.4.tar.gz
7f60a92b7e42d864dc6d236496784dc244587635 SOURCES/cockpit-1.7.4.tar.gz
d9e10a1ee0566bc8b454a75d52685afb3e34444d SOURCES/community-general-11.4.5.tar.gz
f83386ba87f9d7c8db1ad62cc07616a7c723e1d8 SOURCES/containers-podman-1.19.0.tar.gz
1e7f0353dd7a8bb955df23f38e9de78365eb493c SOURCES/crypto_policies-1.5.2.tar.gz
648d4432ee1e9515b4035a9ff6e9b4832da5cc34 SOURCES/fapolicyd-1.1.12.tar.gz
7622bb29e15d72064187dbe75bb32c7a8ad3237c SOURCES/firewall-1.11.6.tar.gz
4e80f3da46d0422a300a0c0f0d908a4d5f27a996 SOURCES/gfs2-1.0.5.tar.gz
d69e33bd4eaae995f1b6232af92ed4fe3d005f32 SOURCES/ha_cluster-1.29.1.tar.gz
69e567a8967c8554005e022e1411f39cd2fc8001 SOURCES/journald-1.5.2.tar.gz
51059dc680bac42d60f6aa129b6395a8bce043b0 SOURCES/kdump-1.5.1.tar.gz
01ecd1adf95240c3cabe48bf0c254423904ba660 SOURCES/kernel_settings-1.3.8.tar.gz
e84bac87da92defeba5f3cf3e7019fd93a9311fc SOURCES/keylime_server-1.2.4.tar.gz
cd14ba8613f0f431036e8a247821276778bf6a11 SOURCES/logging-1.15.5.tar.gz
ee8ba2a86f9528763fc73579d3cfdcec5491c106 SOURCES/metrics-1.14.2.tar.gz
2824552c7bf217f8223abed681e24fe1be6997b7 SOURCES/nbde_client-1.3.8.tar.gz
aa4c4f70c5b272a1e362276c2307d3a60282b6fd SOURCES/nbde_server-1.5.2.tar.gz
b2689a06f24019c7af8c39382ef5b24aa1e807fc SOURCES/network-1.17.9.tar.gz
1a36f6686ad8c379762ebb1f1d840b044ed05deb SOURCES/podman-1.9.2.tar.gz
2d3a8610195dd4d340890e78c943de2a6653eb99 SOURCES/postfix-1.6.6.tar.gz
4619113f04b2c02e91b93307e418c9206652c64c SOURCES/postgresql-1.5.1.tar.gz
92f6c736935895b3fbcd4413badc0d4375593743 SOURCES/rhc-1.6.13.tar.gz
01a04011032bafa0fd6f2775129afe689096969b SOURCES/selinux-1.11.1.tar.gz
dab4611b6166b3af0fc107726f4d47aac10e4bab SOURCES/snapshot-1.6.4.tar.gz
65476450f7bd6b59ea1ac868a3b0833a0d5ab204 SOURCES/ssh-1.7.1.tar.gz
c57f9f33a3fad61496e56ca8b59718f545aa4dc9 SOURCES/storage-1.19.5.tar.gz
aebfb0ad941504331fe1bb9465af551c86050fb9 SOURCES/sudo-1.2.9.tar.gz
a1a635ea35b87ec2d0a268cd7f7246c4d832628f SOURCES/systemd-1.3.7.tar.gz
a0fa887aafd7e8b352b39e0eca1010e8e160b8e2 SOURCES/timesync-1.11.4.tar.gz
d391876aa227d68c8a677ad0a592063bc89971a7 SOURCES/tlog-1.4.5.tar.gz
7e29c5eb846a3b308a8b74807b9d8513b3942348 SOURCES/vpn-1.6.16.tar.gz
4bb67f44342dddc9971f0c133ff1c30172082b40 SOURCES/ansible-sshd-v0.34.0.tar.gz
698f3eb531aed3395cbf5cac88d4d91634a9ec60 SOURCES/auditd-1.1.0.tar.gz
b0d5aa1ffff790c6ac5be11d027946b54a45cddd SOURCES/auto-maintenance-2.4.0.tar.gz
feab912e0e5fa9e5438f35c9267a0d68dfa6e250 SOURCES/bootloader-2.1.0.tar.gz
0c7f7ed29a11bf0e81672eb09be958e6889ad9bd SOURCES/certificate-1.9.0.tar.gz
dd4ee282fbcecb3bf95a1a8e0866499b3569d118 SOURCES/cockpit-1.9.0.tar.gz
8038456e1965d99dccef339037dabd74f699410b SOURCES/community-general-11.4.9.tar.gz
07d654cac93c611431db5cb21588995959defa30 SOURCES/containers-podman-1.20.2.tar.gz
0cf0b8107e44323574dd642d5367937ab47ad719 SOURCES/crypto_policies-1.8.0.tar.gz
57b6002b863dda161dcfec5f6c52dcaec50d260e SOURCES/fapolicyd-1.3.0.tar.gz
2a6c34a6c37b31bbd5aaf2c852e6ae4b4e85e384 SOURCES/firewall-1.13.0.tar.gz
d267f0593ef1dad5031e5983b2c93e99ad550dbc SOURCES/gfs2-1.2.0.tar.gz
b12736ea9c77de9287c8681eb9bee8d4224856bb SOURCES/ha_cluster-1.32.1.tar.gz
a68f3bf61ac960bda211a36b65d7465f45daf96a SOURCES/journald-1.7.0.tar.gz
64fc645227019d772911544836bd7510ba42eca5 SOURCES/kdump-1.7.0.tar.gz
4c8bbbf559ef035be47b965a63ea90c5a3dddbbd SOURCES/kernel_settings-1.5.0.tar.gz
b2bff28603bd46fd2e1022c3c54b81cfc5c706b1 SOURCES/keylime_server-1.4.0.tar.gz
0f01930196f27388edfe57e9eefda8e328a8d374 SOURCES/logging-1.17.0.tar.gz
1f51d9ce81f05500d06b20ca641b4e3ddaf4cf13 SOURCES/metrics-1.17.0.tar.gz
a308c3b8d6b3491809e0c033db4e752d3df3c198 SOURCES/nbde_client-1.7.0.tar.gz
fe5e5a5a8c728fea83b49739f722466de76b06d4 SOURCES/nbde_server-1.7.0.tar.gz
ec683bf02afb19fcc2ec41a9487152eb309c1551 SOURCES/network-1.21.0.tar.gz
e477ec759e6fcae874335378d310a12446a7660a SOURCES/podman-1.14.1.tar.gz
cfb27c0b3ec7e5c7f643ccd4edf8911133ce6a9f SOURCES/postfix-1.9.0.tar.gz
8f02462ca9fdd8f683d6035cee8aa6a85470334e SOURCES/postgresql-1.8.0.tar.gz
f3410724a95d7a3567884853276eb6934707580e SOURCES/rhc-1.8.0.tar.gz
eb41d88e1db8b7784e3da7ce1226df20d7c09ade SOURCES/selinux-1.13.0.tar.gz
dc041b8764caecaf1a56827422a0b0fb4c0ee452 SOURCES/snapshot-1.9.0.tar.gz
285eead049ea9d65af8be8738a793bbdb7e811a6 SOURCES/ssh-1.9.0.tar.gz
6bedbfb3c09cbd4d2e4b83907d2e633935f5429c SOURCES/storage-1.22.0.tar.gz
6d2fb0edc44cd9179963692d7912410310bc0d5a SOURCES/sudo-1.4.0.tar.gz
055ff26a040f068b775f385b3634ee9e62bf62dc SOURCES/systemd-1.5.0.tar.gz
b727117bf47658fb66bca4223fbedd579bcf8dfe SOURCES/timesync-1.14.1.tar.gz
279b3da25766e0be730b0571cfe27dad3ee9e477 SOURCES/tlog-1.6.1.tar.gz
d4bde8c238964a4facebf2b82c59d9e9a4c5ec78 SOURCES/trustee_client-1.1.0.tar.gz
c53e7f6c6e6c686184fbe6a8ff514b1a832248fa SOURCES/trustee_server-1.1.0.tar.gz
9bcbdf4a46a0b659ffe056f3a5aea3bacf193511 SOURCES/vpn-1.9.0.tar.gz

View File

@ -1,6 +1,51 @@
Changelog
=========
[2.4.0] - 2026-08-11
----------------------------
### New Features
- Write roles fingerprints to /var/log/sysroles.jsonl
- [allow disable of secure logging in system roles for debugging [rhel-9]](https://redhat.atlassian.net/browse/RHEL-175651)
- [auditd - auditd system role](https://redhat.atlassian.net/browse/RHEL-170879)
- [certificate - feat: manage system certificate trust, CA certificates [rhel-9]](https://redhat.atlassian.net/browse/RHEL-210678)
- [certificate - feat: Implement support for passing an issuer argument to the provider. [rhel-9]](https://redhat.atlassian.net/browse/RHEL-220560)
- [crypto_policies - [RFE] redhat.rhel_system_roles.crypto_policies add option to reapply policy when .pmod file is changed [rhel-9]](https://redhat.atlassian.net/browse/RHEL-181360)
- [fapolicyd - [RFE] - Manage trusted directories with fapolicyd RHEL System Role [rhel-9]](https://redhat.atlassian.net/browse/RHEL-219366)
- [firewall - RFE: firewall system role not idempotent when using "previous: replaced" [rhel-9]](https://redhat.atlassian.net/browse/RHEL-176144)
- [ha_cluster - [RFE] rhel_system_roles.ha_cluster - export fencing levels configuration [rhel-9]](https://redhat.atlassian.net/browse/RHEL-175659)
- [ha_cluster - [RFE] rhel_system_roles.ha_cluster - export node attributes and utilization configuration [rhel-9]](https://redhat.atlassian.net/browse/RHEL-175658)
- [podman,selinux - Restart quadlet when mounted host files changed the state [rhel-9]](https://redhat.atlassian.net/browse/RHEL-145225)
- [snapshot - explain in README how to use the extend feature [rhel-9]](https://redhat.atlassian.net/browse/RHEL-182280)
- [snapshot - feat: add list command to report the status of LVM snapshots for specified VGs/LVs [rhel-9]](https://redhat.atlassian.net/browse/RHEL-175664)
- [snapshot - feat: add support for revertable snapshots with boot-time rollback capability [rhel-9]](https://redhat.atlassian.net/browse/RHEL-212147)
- [sshd - feat: Add new c10s options GSSAPIAllowS4U2Self and GSSAPIProxyS4U2Services [rhel-9]](https://redhat.atlassian.net/browse/RHEL-167858)
- [storage - [RFE] The storage system role should only install stratis when it's needed [rhel-9]](https://redhat.atlassian.net/browse/RHEL-181990)
- [timesync - Support key and keyfile for authentication [rhel-9]](https://redhat.atlassian.net/browse/RHEL-145210)
- [trustee_client - trustee_client - new system role [rhel-9]](https://redhat.atlassian.net/browse/RHEL-175619)
- [trustee_server - trustee_server - new system role [rhel-9]](https://redhat.atlassian.net/browse/RHEL-175618)
### Bug Fixes
- [ad_integration - realm join fails after changing to AD crypto policy [rhel-9]](https://redhat.atlassian.net/browse/RHEL-177565)
- [bootloader - [RFE] Provide an option to disable timeout management in redhat.rhel_system_roles.bootloader [rhel-9]](https://redhat.atlassian.net/browse/RHEL-211555)
- [bootloader - bootloader system role changes /boot/grub2/grub.cfg permissions from 0600 to 0700 on UEFI systems causing CIS 1.4.2 compliance failure [rhel-9]](https://redhat.atlassian.net/browse/RHEL-191870)
- [bootloader - Role ignores check mode / files changed in check mode [rhel-9]](https://redhat.atlassian.net/browse/RHEL-180861)
- [bootloader - fix: support duplicate option names with different values [rhel-9]](https://redhat.atlassian.net/browse/RHEL-180604)
- [certificate - Certificate renewal every time the role runs for IPA [rhel-9]](https://redhat.atlassian.net/browse/RHEL-220565)
- [kernel_settings - The kernel_settings role is not idempotent on el7 [rhel-9]](https://redhat.atlassian.net/browse/RHEL-151853)
- [nbde_client - add support for static networking with IP configuration [rhel-9]](https://redhat.atlassian.net/browse/RHEL-212633)
- [nbde_client - nbde_client role should use hostonly_cmdline=yes on EL10 and later [rhel-9]](https://redhat.atlassian.net/browse/RHEL-208709)
- [nbde_server - fix: Prevent symlink following privilege escalation in nbde_server_tang module [rhel-9]](https://redhat.atlassian.net/browse/RHEL-189402)
- [network - Inverted retry condition in SysUtil.link_infos() makes retry loop ineffective [rhel-9]](https://redhat.atlassian.net/browse/RHEL-157026)
- [podman - Prune images on ansible run [rhel-9]](https://redhat.atlassian.net/browse/RHEL-212677)
- [podman - Support for multiple kubernetes objects in `podman_kube_specs` `kube_file_content` [rhel-9]](https://redhat.atlassian.net/browse/RHEL-191866)
- [podman - `podman_run_as_user` is required to be set when running this role as non-root user [rhel-9]](https://redhat.atlassian.net/browse/RHEL-212672)
- [selinux - fix: ensure policy modules are loaded before they can be referenced [rhel-9]](https://redhat.atlassian.net/browse/RHEL-182481)
- [sudo - Small fix for line continuation characters [rhel-9]](https://redhat.atlassian.net/browse/RHEL-178497)
- [sudo - Space missing in sudoers.j2 template before tags [rhel-9]](https://redhat.atlassian.net/browse/RHEL-178506)
[1.120.5] - 2026-02-23
----------------------------

View File

@ -1,10 +1,12 @@
Source801: https://galaxy.ansible.com/download/ansible-posix-2.1.0.tar.gz
Source901: https://galaxy.ansible.com/download/community-general-11.4.5.tar.gz
Source902: https://galaxy.ansible.com/download/containers-podman-1.19.0.tar.gz
Source901: https://galaxy.ansible.com/download/community-general-11.4.9.tar.gz
Source902: https://galaxy.ansible.com/download/containers-podman-1.20.2.tar.gz
Provides: bundled(ansible-collection(ansible.posix)) = 2.1.0
Provides: bundled(ansible-collection(community.general)) = 11.4.5
Provides: bundled(ansible-collection(containers.podman)) = 1.19.0
# we are stuck at this major version for community-general because newer
# versions do not support older python versions that RHEL 7 uses
Provides: bundled(ansible-collection(community.general)) = 11.4.9
Provides: bundled(ansible-collection(containers.podman)) = 1.20.2
Source996: CHANGELOG.rst
Source998: collection_readme.sh

View File

@ -23,7 +23,7 @@ Name: linux-system-roles
%endif
Url: https://github.com/linux-system-roles
Summary: Set of interfaces for unified system management
Version: 1.120.5
Version: 2.4.0
Release: 0.1%{?dist}
License: GPLv3+ and MIT and BSD and Python
@ -86,110 +86,119 @@ Requires: (ansible-core >= 2.11.0 or ansible >= 2.9.0)
%%global rolestodir %%{?rolestodir} %%{roletodir%{1}}
}
%global mainid 1.120.5
%global mainid 2.4.0
Source: %{url}/auto-maintenance/archive/%{mainid}/auto-maintenance-%{mainid}.tar.gz
# BEGIN AUTOGENERATED SOURCES
%global rolename1 postfix
%deftag 1 1.6.6
%deftag 1 1.9.0
%global rolename2 selinux
%deftag 2 1.11.1
%deftag 2 1.13.0
%global rolename3 timesync
%deftag 3 1.11.4
%deftag 3 1.14.1
%global rolename4 kdump
%deftag 4 1.5.1
%deftag 4 1.7.0
%global rolename5 network
%deftag 5 1.17.9
%deftag 5 1.21.0
%global rolename6 storage
%deftag 6 1.19.5
%deftag 6 1.22.0
%global rolename7 metrics
%deftag 7 1.14.2
%deftag 7 1.17.0
%global rolename8 tlog
%deftag 8 1.4.5
%deftag 8 1.6.1
%global rolename9 kernel_settings
%deftag 9 1.3.8
%deftag 9 1.5.0
%global rolename10 logging
%deftag 10 1.15.5
%deftag 10 1.17.0
%global rolename11 nbde_server
%deftag 11 1.5.2
%deftag 11 1.7.0
%global rolename12 nbde_client
%deftag 12 1.3.8
%deftag 12 1.7.0
%global rolename13 certificate
%deftag 13 1.4.4
%deftag 13 1.9.0
%global rolename14 crypto_policies
%deftag 14 1.5.2
%deftag 14 1.8.0
%global forgeorg15 https://github.com/willshersystems
%global repo15 ansible-sshd
%global rolename15 sshd
%deftag 15 v0.31.0
%deftag 15 v0.34.0
%global rolename16 ssh
%deftag 16 1.7.1
%deftag 16 1.9.0
%global rolename17 ha_cluster
%deftag 17 1.29.1
%deftag 17 1.32.1
%global rolename18 vpn
%deftag 18 1.6.16
%deftag 18 1.9.0
%global rolename19 firewall
%deftag 19 1.11.6
%deftag 19 1.13.0
%global rolename20 cockpit
%deftag 20 1.7.4
%deftag 20 1.9.0
%global rolename21 podman
%deftag 21 1.9.2
%deftag 21 1.14.1
%global rolename22 ad_integration
%deftag 22 1.6.3
%deftag 22 1.9.0
%global rolename23 rhc
%deftag 23 1.6.13
%deftag 23 1.8.0
%global rolename24 journald
%deftag 24 1.5.2
%deftag 24 1.7.0
%global rolename25 postgresql
%deftag 25 1.5.1
%deftag 25 1.8.0
%global rolename26 systemd
%deftag 26 1.3.7
%deftag 26 1.5.0
%global rolename27 keylime_server
%deftag 27 1.2.4
%deftag 27 1.4.0
%global rolename28 fapolicyd
%deftag 28 1.1.12
%deftag 28 1.3.0
%global rolename29 bootloader
%deftag 29 1.1.6
%deftag 29 2.1.0
%global rolename30 snapshot
%deftag 30 1.6.4
%deftag 30 1.9.0
%global rolename31 gfs2
%deftag 31 1.0.5
%deftag 31 1.2.0
%global rolename32 sudo
%deftag 32 1.2.9
%deftag 32 1.4.0
%global rolename33 aide
%deftag 33 1.2.5
%deftag 33 1.4.0
%global rolename34 trustee_client
%deftag 34 1.1.0
%global rolename35 trustee_server
%deftag 35 1.1.0
%global rolename36 auditd
%deftag 36 1.1.0
Source1: %{archiveurl1}
Source2: %{archiveurl2}
@ -224,6 +233,9 @@ Source30: %{archiveurl30}
Source31: %{archiveurl31}
Source32: %{archiveurl32}
Source33: %{archiveurl33}
Source34: %{archiveurl34}
Source35: %{archiveurl35}
Source36: %{archiveurl36}
# END AUTOGENERATED SOURCES
# Includes with definitions/tags that differ between RHEL and Fedora
@ -289,7 +301,7 @@ end
%prep
# BEGIN AUTOGENERATED SETUP
%setup -q -a1 -a2 -a3 -a4 -a5 -a6 -a7 -a8 -a9 -a10 -a11 -a12 -a13 -a14 -a15 -a16 -a17 -a18 -a19 -a20 -a21 -a22 -a23 -a24 -a25 -a26 -a27 -a28 -a29 -a30 -a31 -a32 -a33 -n %{getarchivedir 0}
%setup -q -a1 -a2 -a3 -a4 -a5 -a6 -a7 -a8 -a9 -a10 -a11 -a12 -a13 -a14 -a15 -a16 -a17 -a18 -a19 -a20 -a21 -a22 -a23 -a24 -a25 -a26 -a27 -a28 -a29 -a30 -a31 -a32 -a33 -a34 -a35 -a36 -n %{getarchivedir 0}
# END AUTOGENERATED SETUP
# vendoring prep steps, if any
@ -313,13 +325,15 @@ for rolename in %{rolenames}; do
done
cd %{rolename15}
find -P tests examples -name \*.yml | while read file; do
find -P tasks templates tests examples -name \*.yml | while read file; do
sed -r -i -e "s/willshersystems:ansible-sshd/system_role:sshd/" \
-e "s/ansible-sshd/linux-system-roles.sshd/" \
-e "s/ willshersystems.sshd/ linux-system-roles.sshd/" "$file"
done
sed -r -i -e "s/ willshersystems.sshd/ linux-system-roles.sshd/" README.md README.html
sed -r -i -e 's/min_ansible_version: 2.8/min_ansible_version: "2.9"/' meta/main.yml
# ansible-sshd does not enable fingerprinting by default, so enable it here
sed -r -i -e 's/sshd_enable_fingerprint: false/sshd_enable_fingerprint: true/' defaults/main.yml
cd ..
cd %{rolename7}
@ -356,6 +370,13 @@ rm %{rolename5}/tests/playbooks/roles
rm %{rolename5}/scripts/print_all_options.py
rm %{rolename5}/tests/ensure_provider_tests.py
# remove plans directory containing unnecessary fmf test plans
for rolename in %{rolenames}; do
if [ -d ${rolename}/plans ]; then
rm -r ${rolename}/plans
fi
done
# fix system_roles fingerprint in "external" roles
python3 lsr_fingerprint.py
@ -399,6 +420,20 @@ for role in %{rolenames}; do
# in the first 14 lines of README.md, remove any line that looks like a
# github action badge. README.html doesn't have these lines.
sed -e "1,14 {\\,${matchstr},d; /\!\[/d}" -i $role/README.md
# Enable write_log_file by default for all roles
defaults_file="$role/defaults/main.yml"
vars_file="$role/vars/main.yml"
if grep -q "^__${role}_write_log_file: false$" "$defaults_file"; then
sed -i -e "s/^__${role}_write_log_file: false$/__${role}_write_log_file: true/" \
"$defaults_file"
elif grep -q "^__${role}_write_log_file: false$" "$vars_file"; then
sed -i -e "s/^__${role}_write_log_file: false$/__${role}_write_log_file: true/" \
"$vars_file"
else
echo "ERROR: ^__${role}_write_log_file: false\$ not found in $defaults_file or $vars_file" >&2
exit 1
fi
done
if [ ! -d %{collection_dest_path} ]; then
@ -547,7 +582,7 @@ for role in %{rolenames}; do
done
rm -f %{buildroot}%{ansible_roles_dir}/%{roleinstprefix}*/semaphore
rm -r %{buildroot}%{ansible_roles_dir}/%{roleinstprefix}*/molecule
rm -rf %{buildroot}%{ansible_roles_dir}/%{roleinstprefix}*/molecule
# remove .dot files/directories, but keep the .ostree directory
for item in %{buildroot}%{ansible_roles_dir}/%{roleinstprefix}*/.[A-Za-z]*; do
@ -686,6 +721,59 @@ find %{buildroot}%{ansible_roles_dir} -mindepth 1 -maxdepth 1 | \
%endif
%changelog
* Tue Aug 11 2026 Rich Megginson <rmeggins@redhat.com> - 2.4.0-0.1
- Resolves: RHEL-220560 : certificate - feat: Implement support for passing an issuer argument to the provider.
- Resolves: RHEL-220565 : certificate - Certificate renewal every time the role runs for IPA
- Resolves: RHEL-219366 : fapolicyd - [RFE] - Manage trusted directories with fapolicyd RHEL System Role
- Write roles fingerprints to /var/log/sysroles.jsonl
* Mon Jul 27 2026 Rich Megginson <rmeggins@redhat.com> - 2.0.0-0.1
- Resolves: RHEL-180861 : bootloader - Role ignores check mode / files changed in check mode [rhel-9]
- Resolves: RHEL-211555 : bootloader - [RFE] Provide an option to disable timeout management in redhat.rhel_system_roles.bootloader [rhel-9]
- Resolves: RHEL-210678 : certificate - feat: manage system certificate trust, CA certificates [rhel-9]
- Resolves: RHEL-208709 : nbde_client - nbde_client role should use hostonly_cmdline=yes on EL10 and later [rhel-9]
- Resolves: RHEL-212633 : nbde_client - add support for static networking with IP configuration [rhel-9]
- Resolves: RHEL-212677 : podman - Prune images on ansible run [rhel-9]
- Resolves: RHEL-191866 : podman - Support for multiple kubernetes objects in `podman_kube_specs` `kube_file_content` [rhel-9]
- Resolves: RHEL-212672 : podman - `podman_run_as_user` is required to be set when running this role as non-root user [rhel-9]
- Resolves: RHEL-212147 : snapshot - feat: add support for revertable snapshots with boot-time rollback capability [rhel-9]
- Resolves: RHEL-145210 : timesync - Support key and keyfile for authentication [rhel-9]
* Sat Jun 27 2026 Rich Megginson <rmeggins@redhat.com> - 1.127.2-0.1
- Resolves: RHEL-180604 : bootloader - fix: support duplicate option names with different values [rhel-9]
- Resolves: RHEL-181360 : crypto_policies - [RFE] redhat.rhel_system_roles.crypto_policies add option to reapply policy when .pmod file is changed [rhel-9]
- Resolves: RHEL-184523 : firewall - fix: role should not configure firewall if only getting facts [rhel-9]
- Resolves: RHEL-189407 : firewall - fix: ensure rich rule handling is idempotent [rhel-9]
- Resolves: RHEL-189402 : nbde_server - fix: Prevent symlink following privilege escalation in nbde_server_tang module [rhel-9]
- Resolves: RHEL-157026 : network - Inverted retry condition in SysUtil.link_infos() makes retry loop ineffective [rhel-9]
- Resolves: RHEL-145225 : podman - Restart quadlet when mounted host files changed the state [rhel-9]
- Resolves: RHEL-182481 : selinux - fix: ensure policy modules are loaded before they can be referenced [rhel-9]
- Resolves: RHEL-182280 : snapshot - explain in README how to use the extend feature [rhel-9]
- Resolves: RHEL-167858 : sshd - feat: Add new c10s options GSSAPIAllowS4U2Self and GSSAPIProxyS4U2Services [rhel-9]
- Resolves: RHEL-181990 : storage - [RFE] The storage system role should only install stratis when it's needed [rhel-9]
- Resolves: RHEL-178506 : sudo - Space missing in sudoers.j2 template before tags [rhel-9]
- Resolves: RHEL-178497 : sudo - Small fix for line continuation characters [rhel-9]
- Remove plans directory from roles
It contains unnecessary fmf plans that had been added by
https://github.com/linux-system-roles/.github/pull/85
* Thu May 21 2026 Rich Megginson <rmeggins@redhat.com> - 1.125.2-0.1
- Resolves: RHEL-177565 : ad_integration - realm join fails after changing to AD crypto policy [rhel-9]
* Wed May 13 2026 Rich Megginson <rmeggins@redhat.com> - 1.125.1-0.1
- Added syslog fingerprinting to all roles
- Change verbosity level 3 for no_log to use verbosity-based logging in all roles
- Resolves: RHEL-175651 : allow disable of secure logging in system roles for debugging [rhel-9]
- Resolves: RHEL-170879 : auditd - auditd system role
- Resolves: RHEL-176144 : firewall - RFE: firewall system role not idempotent when using "previous: replaced" [rhel-9]
- Resolves: RHEL-175659 : ha_cluster - [RFE] rhel_system_roles.ha_cluster - export fencing levels configuration [rhel-9]
- Resolves: RHEL-175658 : ha_cluster - [RFE] rhel_system_roles.ha_cluster - export node attributes and utilization configuration [rhel-9]
- Resolves: RHEL-151853 : kernel_settings - The kernel_settings role is not idempotent on el7 [rhel-9]
- Resolves: RHEL-175664 : snapshot - feat: add list command to report the status of LVM snapshots for specified VGs/LVs [rhel-9]
- Resolves: RHEL-167858 : sshd - feat: Add new c10s options GSSAPIAllowS4U2Self and GSSAPIProxyS4U2Services [rhel-9]
- Resolves: RHEL-175619 : trustee_client - trustee_client - new system role [rhel-9]
- Resolves: RHEL-175618 : trustee_server - trustee_server - new system role [rhel-9]
* Mon Feb 23 2026 Rich Megginson <rmeggins@redhat.com> - 1.120.5-0.1
- Resolves: RHEL-151438 : storage - fix: ensure libblockdev-loop package on EL7 for loop mounts