From 306f908257e11d26f5bb11672305c077e7e25c71 Mon Sep 17 00:00:00 2001 From: Jan Jansky Date: Tue, 28 Jul 2026 13:04:33 +0200 Subject: [PATCH] Update to 4.11.2-4 Resolves: RHEL-189445 Signed-off-by: Jan Jansky --- ...aller-Scrub-secrets-in-CLI-arg-dumps.patch | 37 ++++++++ ...most-specific-policy-when-multiple-m.patch | 74 +++++++++++++++ ...sys-devices-system-cpu-cpu-subdirs-c.patch | 90 +++++++++++++++++++ sos.spec | 11 ++- 4 files changed, 211 insertions(+), 1 deletion(-) create mode 100644 0004-foreman-installer-Scrub-secrets-in-CLI-arg-dumps.patch create mode 100644 0005-policies-Prefer-most-specific-policy-when-multiple-m.patch create mode 100644 0006-processor-Limit-sys-devices-system-cpu-cpu-subdirs-c.patch diff --git a/0004-foreman-installer-Scrub-secrets-in-CLI-arg-dumps.patch b/0004-foreman-installer-Scrub-secrets-in-CLI-arg-dumps.patch new file mode 100644 index 0000000..898d720 --- /dev/null +++ b/0004-foreman-installer-Scrub-secrets-in-CLI-arg-dumps.patch @@ -0,0 +1,37 @@ +From 2fab657e3909f76e31bc6c56a5ad26f86a9925e5 Mon Sep 17 00:00:00 2001 +From: Pavel Moravec +Date: Tue, 23 Jun 2026 17:17:01 +0200 +Subject: [PATCH] [foreman-installer] Scrub secrets in CLI arg dumps + +Installer logs dump CLI args we need to scrub. + +Closes: #4367 + +Signed-off-by: Pavel Moravec +--- + sos/report/plugins/foreman_installer.py | 7 ++++--- + 1 file changed, 4 insertions(+), 3 deletions(-) + +diff --git a/sos/report/plugins/foreman_installer.py b/sos/report/plugins/foreman_installer.py +index f55cde23..89eef2e4 100644 +--- a/sos/report/plugins/foreman_installer.py ++++ b/sos/report/plugins/foreman_installer.py +@@ -54,11 +54,12 @@ class ForemanInstaller(Plugin, DebianPlugin, UbuntuPlugin): + r"::(.*(token|secret|key|passw).*)\") value:) " + r"(.*)") + self.do_path_regex_sub(install_logs, logs_debug_reg, r"\1 \2 ********") +- # also hide passwords in yet different formats ++ # also hide passwords in yet different formats, including CLI arg dumps + self.do_path_regex_sub( + install_logs, +- r"password(\", \"|=|\" value: \"|\": \")(.*?)(\", \".*|\"]]|\"|$)", +- r"password\1********\3") ++ r"((?:password|consumer-key|consumer-secret|key-secret|secret-key|" ++ r"oauth-key|oauth-secret)(?:\", \"|\": \"|=))([^\"\n]*)(\"|$)", ++ r"\1********\3") + self.do_path_regex_sub( + "/var/log/foreman-installer/foreman-proxy*", + r"(\s*proxy_password\s=) (.*)", +-- +2.54.0 + diff --git a/0005-policies-Prefer-most-specific-policy-when-multiple-m.patch b/0005-policies-Prefer-most-specific-policy-when-multiple-m.patch new file mode 100644 index 0000000..5a1f5d1 --- /dev/null +++ b/0005-policies-Prefer-most-specific-policy-when-multiple-m.patch @@ -0,0 +1,74 @@ +From 6085b2580173a7a43de8b541584c82481c617aa2 Mon Sep 17 00:00:00 2001 +From: asadawar +Date: Mon, 27 Jul 2026 17:50:42 +0530 +Subject: [PATCH] [policies] Prefer most specific policy when multiple match + +When multiple policies within the same module return True from +check(), the policy loader now selects the most specific one +(deepest in the class hierarchy) instead of whichever happens +to sort first alphabetically. + +Previously, import_policy() returned classes sorted by name via +inspect.getmembers(), and load() picked the first match. This +caused RHELPolicy to always win over RedHatCoreOSPolicy inside +a toolbox container on RHCOS, because uppercase 'H' sorts before +lowercase 'e' in ASCII. Both policies return True in that context +(RHEL for the container's /etc/redhat-release, RHCOS for the +host's /host/etc/os-release), but the more specific RHCOS policy +was never reached. + +This has existed since RedHatCoreOSPolicy was introduced in 2019 +(commit fa06bc09c95c) but was never visible because RHCOS had no +behavioral differences from RHEL until the archive naming change +in commit 0e919b6. + +The fix collects all matching policies from a module and sorts by +MRO depth (descending), so a subclass is always preferred over +its parent. This is safe because a subclass that returns True from +check() is by definition a more precise match than its parent. + +Assisted-by: Claude Code +Signed-off-by: asadawar +--- + sos/policies/__init__.py | 18 +++++++++++------- + 1 file changed, 11 insertions(+), 7 deletions(-) + +diff --git a/sos/policies/__init__.py b/sos/policies/__init__.py +index 35b3a532..b4920e82 100644 +--- a/sos/policies/__init__.py ++++ b/sos/policies/__init__.py +@@ -29,20 +29,24 @@ def import_policy(name): + return None + + +-def load(cache={}, sysroot=None, init=None, probe_runtime=True, ++def load(cache=None, sysroot=None, init=None, probe_runtime=True, + remote_exec=None, remote_check=''): ++ if cache is None: ++ cache = {} + if 'policy' in cache: + return cache.get('policy') + + import sos.policies.distros + helper = ImporterHelper(sos.policies.distros) ++ matches = [] + for module in helper.get_modules(): +- for policy in import_policy(module): +- if policy.check(remote=remote_check): +- cache['policy'] = policy(sysroot=sysroot, init=init, +- probe_runtime=probe_runtime, +- remote_exec=remote_exec) +- break ++ matches.extend([policy for policy in (import_policy(module) or []) ++ if policy.check(remote=remote_check)]) ++ if matches: ++ matches.sort(key=lambda p: len(p.__mro__), reverse=True) ++ cache['policy'] = matches[0](sysroot=sysroot, init=init, ++ probe_runtime=probe_runtime, ++ remote_exec=remote_exec) + + if sys.platform != 'linux': + raise Exception("SoS is not supported on this platform") +-- +2.55.0 + diff --git a/0006-processor-Limit-sys-devices-system-cpu-cpu-subdirs-c.patch b/0006-processor-Limit-sys-devices-system-cpu-cpu-subdirs-c.patch new file mode 100644 index 0000000..8d30d21 --- /dev/null +++ b/0006-processor-Limit-sys-devices-system-cpu-cpu-subdirs-c.patch @@ -0,0 +1,90 @@ +From d94095e55d69d5e4135df0193c9726c2789526ab Mon Sep 17 00:00:00 2001 +From: Pavel Moravec +Date: Wed, 29 Jul 2026 10:46:25 +0200 +Subject: [PATCH] [processor] Limit /sys/devices/system/cpu/cpu* subdirs + collected + +For systems with >500 CPUs, collecting all such directories means +millions of files to be collected, what excessivelly slows down the +plugin until its timeout. + +Limit the default number of such directories to 64, configurable via a +plugin option. + +Resolves: #4399 + +Signed-off-by: Pavel Moravec +--- + sos/report/plugins/processor.py | 41 ++++++++++++++++++++++++++++++++- + 1 file changed, 40 insertions(+), 1 deletion(-) + +diff --git a/sos/report/plugins/processor.py b/sos/report/plugins/processor.py +index 9375b5a1..593bd36b 100644 +--- a/sos/report/plugins/processor.py ++++ b/sos/report/plugins/processor.py +@@ -6,7 +6,9 @@ + # + # See the LICENSE file in the source distribution for further information. + +-from sos.report.plugins import Plugin, IndependentPlugin, SoSPredicate ++import re ++from sos.report.plugins import (Plugin, IndependentPlugin, SoSPredicate, ++ PluginOpt) + from sos.policies.distros.ubuntu import UbuntuPolicy + + +@@ -18,6 +20,11 @@ class Processor(Plugin, IndependentPlugin): + profiles = ('system', 'hardware', 'memory') + files = ('/proc/cpuinfo',) + packages = ('cpufreq-utils', 'cpuid') ++ option_list = [ ++ PluginOpt('max_cpu_dirs', default=64, val_type=int, ++ desc='Maximum number of cpu[0-9]+ directories ' ++ 'to collect from /sys/devices/system/cpu'), ++ ] + + cpu_kmods = [] + +@@ -43,7 +50,39 @@ class Processor(Plugin, IndependentPlugin): + # copy /sys/devices/system/cpu/cpuX with separately applied sizelimit + # this is required for systems with tens/hundreds of CPUs where the + # cumulative directory size exceeds 25MB or even 100MB. ++ # Limit cpu[0-9]* directories to avoid excessive collection. ++ # All non-cpu* directories are always collected. ++ max_cpu_dirs = self.get_option('max_cpu_dirs') ++ if max_cpu_dirs < 0: ++ self._log_info(f"Invalid {max_cpu_dirs=} value provided, " ++ f"replacing by 0." ++ ) ++ max_cpu_dirs = 0 + cdirs = self.listdir('/sys/devices/system/cpu') ++ ++ if len(cdirs) > max_cpu_dirs: ++ # separate cpu from non-cpu, then limit cpu dirs ++ cpu_pattern = re.compile(r'cpu(\d+)') ++ cpu_dirs = [] ++ other_dirs = [] ++ ++ for cdir in cdirs: ++ if cpu_pattern.fullmatch(cdir): ++ cpu_dirs.append(cdir) ++ else: ++ other_dirs.append(cdir) ++ ++ # Only limit if cpu_dirs specifically exceeds max ++ if len(cpu_dirs) > max_cpu_dirs: ++ self._log_info( ++ f"Limiting cpu directories from {len(cpu_dirs)} to " ++ f"{max_cpu_dirs} (use '-k processor.max_cpu_dirs=N' " ++ f"to change)." ++ ) ++ cpu_dirs = sorted(cpu_dirs)[:max_cpu_dirs] ++ ++ cdirs = other_dirs + cpu_dirs ++ + self.add_copy_spec([ + self.path_join('/sys/devices/system/cpu', cdir) for cdir in cdirs + ]) +-- +2.55.0 + diff --git a/sos.spec b/sos.spec index f88f639..b143b73 100644 --- a/sos.spec +++ b/sos.spec @@ -5,7 +5,7 @@ Summary: A set of tools to gather troubleshooting information from a system Name: sos Version: 4.11.2 -Release: 3%{?dist} +Release: 4%{?dist} Group: Applications/System Source0: https://github.com/sosreport/sos/archive/%{version}/sos-%{version}.tar.gz Source1: sos-audit-%{auditversion}.tgz @@ -25,6 +25,9 @@ Obsoletes: sos-collector <= 1.9 Patch1: 0001-sosreport-binary.patch Patch2: 0002-revert-PR4092-and-PR4275.patch Patch3: 0003-foremanctl-valkey-PR4376.patch +Patch4: 0004-foreman-installer-Scrub-secrets-in-CLI-arg-dumps.patch +Patch5: 0005-policies-Prefer-most-specific-policy-when-multiple-m.patch +Patch6: 0006-processor-Limit-sys-devices-system-cpu-cpu-subdirs-c.patch %description Sos is a set of tools that gathers information about system @@ -38,6 +41,9 @@ support technicians and developers. %patch -P 1 -p1 %patch -P 2 -p1 %patch -P 3 -p1 +%patch -P 4 -p1 +%patch -P 5 -p1 +%patch -P 6 -p1 %build %py3_build @@ -110,6 +116,9 @@ of the system. Currently storage and filesystem commands are audited. %license LICENSE %changelog +* Wed Aug 05 2026 Jan Jansky = 4.11.2-4 +- Update to 4.11.2-4 + * Fri Jul 17 2026 Jan Jansky = 4.11.2-3 - Update to 4.11.2-3