diff --git a/.gitignore b/.gitignore index ea1cd1e..0ab7433 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ -SOURCES/sos-4.5.0.tar.gz -SOURCES/sos-audit-0.3.tgz +SOURCES/sos-4.10.0.tar.gz +SOURCES/sos-audit-0.3-1.tgz diff --git a/.sos.metadata b/.sos.metadata index 8c05a90..f5396df 100644 --- a/.sos.metadata +++ b/.sos.metadata @@ -1,2 +1,2 @@ -d5e166c75250aef01c86a3a9d8c9fcc8db335f4e SOURCES/sos-4.5.0.tar.gz -9d478b9f0085da9178af103078bbf2fd77b0175a SOURCES/sos-audit-0.3.tgz +6042daa19f01ecf2f1e331ae70482653fd500d1f SOURCES/sos-4.10.0.tar.gz +00752b68ec5e1141192a9dab7d44377b8d637bf7 SOURCES/sos-audit-0.3-1.tgz diff --git a/SOURCES/0001-cleaner-Make-cleaner-s-obfuscate_file-properly-worki.patch b/SOURCES/0001-cleaner-Make-cleaner-s-obfuscate_file-properly-worki.patch new file mode 100644 index 0000000..e45e19e --- /dev/null +++ b/SOURCES/0001-cleaner-Make-cleaner-s-obfuscate_file-properly-worki.patch @@ -0,0 +1,101 @@ +From 3efc8888852225396ebb4f0f9ae95edf4e5badfa Mon Sep 17 00:00:00 2001 +From: Pavel Moravec +Date: Wed, 20 Aug 2025 20:07:05 +0200 +Subject: [PATCH] [cleaner] Make cleaner's obfuscate_file properly working + +The fix is three-fold: +- obfuscate_file must clean file content and not filename +- cleaner's main_archive must be populated by parsers first +- obfuscate_file dont need short_name as it is always called with + implicit value of short_name that cleaner will strip itself + +Closes: #4109 +Closes: #4110 + +Signed-off-by: Pavel Moravec +--- + sos/cleaner/__init__.py | 7 ++++--- + sos/collector/__init__.py | 9 +++------ + sos/report/__init__.py | 9 +++------ + 3 files changed, 10 insertions(+), 15 deletions(-) + +diff --git a/sos/cleaner/__init__.py b/sos/cleaner/__init__.py +index 4a1470b5..dcd60c66 100644 +--- a/sos/cleaner/__init__.py ++++ b/sos/cleaner/__init__.py +@@ -537,7 +537,7 @@ third party. + logfile.write(line) + + if archive: +- self.obfuscate_file(log_name, short_name="sos_logs/cleaner.log") ++ self.obfuscate_file(log_name) + self.archive.add_file(log_name, dest="sos_logs/cleaner.log") + + def get_new_checksum(self, archive_path): +@@ -678,6 +678,7 @@ third party. + for prepper in self.get_preppers(): + for archive in self.report_paths: + self._prepare_archive_with_prepper(archive, prepper) ++ self.main_archive.set_parsers(self.parsers) + + def obfuscate_report(self, archive): # pylint: disable=too-many-branches + """Individually handle each archive or directory we've discovered by +@@ -784,8 +785,8 @@ third party. + self.ui_log.info("Exception while processing " + f"{archive.archive_name}: {err}") + +- def obfuscate_file(self, filename, short_name): +- self.main_archive.obfuscate_filename(filename, short_name) ++ def obfuscate_file(self, filename): ++ self.main_archive.obfuscate_arc_files([filename]) + + def obfuscate_symlinks(self, archive): + """Iterate over symlinks in the archive and obfuscate their names. +diff --git a/sos/collector/__init__.py b/sos/collector/__init__.py +index 7a414501..e6b55f20 100644 +--- a/sos/collector/__init__.py ++++ b/sos/collector/__init__.py +@@ -1405,16 +1405,13 @@ this utility or remote systems that it connects to. + if do_clean: + _dir = os.path.join(self.tmpdir, self.archive._name) + cleaner.obfuscate_file( +- os.path.join(_dir, 'sos_logs', 'sos.log'), +- short_name='sos.log' ++ os.path.join(_dir, 'sos_logs', 'sos.log') + ) + cleaner.obfuscate_file( +- os.path.join(_dir, 'sos_logs', 'ui.log'), +- short_name='ui.log' ++ os.path.join(_dir, 'sos_logs', 'ui.log') + ) + cleaner.obfuscate_file( +- os.path.join(_dir, 'sos_reports', 'manifest.json'), +- short_name='manifest.json' ++ os.path.join(_dir, 'sos_reports', 'manifest.json') + ) + + arc_name = self.archive.finalize(method=None) +diff --git a/sos/report/__init__.py b/sos/report/__init__.py +index 074afcff..9fb94d6a 100644 +--- a/sos/report/__init__.py ++++ b/sos/report/__init__.py +@@ -1571,13 +1571,10 @@ class SoSReport(SoSComponent): + # Now, separately clean the log files that cleaner also wrote to + if do_clean: + _dir = os.path.join(self.tmpdir, self.archive._name) +- cleaner.obfuscate_file(os.path.join(_dir, 'sos_logs', 'sos.log'), +- short_name='sos.log') +- cleaner.obfuscate_file(os.path.join(_dir, 'sos_logs', 'ui.log'), +- short_name='ui.log') ++ cleaner.obfuscate_file(os.path.join(_dir, 'sos_logs', 'sos.log')) ++ cleaner.obfuscate_file(os.path.join(_dir, 'sos_logs', 'ui.log')) + cleaner.obfuscate_file( +- os.path.join(_dir, 'sos_reports', 'manifest.json'), +- short_name='manifest.json' ++ os.path.join(_dir, 'sos_reports', 'manifest.json') + ) + + # Now, just (optionally) pack the report and print work outcome; let +-- +2.49.0 + diff --git a/SOURCES/0002-openstack_nova-Improve-scrubbing.patch b/SOURCES/0002-openstack_nova-Improve-scrubbing.patch new file mode 100644 index 0000000..91b376c --- /dev/null +++ b/SOURCES/0002-openstack_nova-Improve-scrubbing.patch @@ -0,0 +1,72 @@ +From 6378a4ee9fa3eeaf384bd87fc87e24a0c5608658 Mon Sep 17 00:00:00 2001 +From: Pavel Moravec +Date: Tue, 19 Aug 2025 09:08:15 +0200 +Subject: [PATCH] [openstack_nova] Improve scrubbing + +Improve postproc obfuscation in two ways: +- apply postproc also to /var/lib/openstack/config/nova on RedHatNova +- obfuscate just password from transport_url, not the whole URL + +Closes: #4108 + +Signed-off-by: Pavel Moravec +--- + sos/report/plugins/openstack_nova.py | 20 +++++++++++--------- + 1 file changed, 11 insertions(+), 9 deletions(-) + +diff --git a/sos/report/plugins/openstack_nova.py b/sos/report/plugins/openstack_nova.py +index 728aed1e..2635866e 100644 +--- a/sos/report/plugins/openstack_nova.py ++++ b/sos/report/plugins/openstack_nova.py +@@ -29,6 +29,7 @@ class OpenStackNova(Plugin): + var_puppet_gen = "/var/lib/config-data/puppet-generated/nova" + service_name = "openstack-nova-api.service" + apachepkg = None ++ postproc_dirs = ["/etc/nova/",] + + def setup(self): + +@@ -141,12 +142,13 @@ class OpenStackNova(Plugin): + self.add_copy_spec(specs) + + def apply_regex_sub(self, regexp, subst): +- """ Apply regex substitution """ +- self.do_path_regex_sub("/etc/nova/*", regexp, subst) +- for npath in ['', '_libvirt', '_metadata', '_placement']: +- self.do_path_regex_sub( +- f"{self.var_puppet_gen}{npath}/etc/nova/*", +- regexp, subst) ++ """ Apply regex substitution to all sensitive dirs """ ++ for _dir in self.postproc_dirs: ++ self.do_path_regex_sub(f"{_dir}/*", regexp, subst) ++ for npath in ['', '_libvirt', '_metadata', '_placement']: ++ self.do_path_regex_sub( ++ f"{self.var_puppet_gen}{npath}{_dir}/*", ++ regexp, subst) + + def postproc(self): + protect_keys = [ +@@ -155,10 +157,9 @@ class OpenStackNova(Plugin): + "xenapi_connection_password", "password", "host_password", + "vnc_password", "admin_password", "connection_password", + "memcache_secret_key", "s3_secret_key", +- "metadata_proxy_shared_secret", "fixed_key", "transport_url", +- "rbd_secret_uuid" ++ "metadata_proxy_shared_secret", "fixed_key", "rbd_secret_uuid" + ] +- connection_keys = ["connection", "sql_connection"] ++ connection_keys = ["connection", "sql_connection", "transport_url"] + + join_con_keys = "|".join(connection_keys) + +@@ -214,6 +215,7 @@ class RedHatNova(OpenStackNova, RedHatPlugin): + apachepkg = "httpd" + nova = False + packages = ('openstack-selinux',) ++ postproc_dirs = ["/etc/nova/", "/var/lib/openstack/config/nova"] + + def setup(self): + super().setup() +-- +2.49.0 + diff --git a/SOURCES/sosreport-binary.patch b/SOURCES/sosreport-binary.patch new file mode 100644 index 0000000..245a155 --- /dev/null +++ b/SOURCES/sosreport-binary.patch @@ -0,0 +1,31 @@ +--- /dev/null 2025-04-03 01:35:45.132999852 +0200 ++++ sos-4.10.0/bin/sosreport 2025-04-15 13:54:04.924751581 +0200 +@@ -0,0 +1,6 @@ ++#!/usr/bin/python3 ++msg = ("sosreport binary is deprecated, use 'sos report' instead") ++print(msg) ++exit(1) ++ ++# vim:ts=4 et sw=4 + +--- /dev/null 2025-04-03 01:35:45.132999852 +0200 ++++ sos-4.10.0/bin/sos-collector 2025-04-15 15:10:17.780281627 +0200 +@@ -0,0 +1,6 @@ ++#!/usr/bin/python3 ++msg = ("sos-collector binary is deprecated, use 'sos collector' instead") ++print(msg) ++exit(1) ++ ++# vim:ts=4 et sw=4 + +--- sos-4.10.0/setup.py 2025-04-15 15:17:21.938635468 +0200 ++++ sos-4.10.0/setup.py 2025-04-15 15:17:41.328198501 +0200 +@@ -34,7 +34,7 @@ + maintainer_email='jacob.r.hunsaker@gmail.com', + url='https://github.com/sosreport/sos', + license="GPLv2+", +- scripts=['bin/sos'], ++ scripts=['bin/sos', 'bin/sosreport', 'bin/sos-collector'], + data_files=data_files, + packages=find_packages(include=['sos', 'sos.*']) + ) diff --git a/SPECS/sos.spec b/SPECS/sos.spec index 95eed99..629ffa2 100644 --- a/SPECS/sos.spec +++ b/SPECS/sos.spec @@ -1,30 +1,30 @@ %{!?python_sitelib: %define python_sitelib %(%{__python} -c "from distutils.sysconfig import get_python_lib; print get_python_lib()")} -%global auditversion 0.3 +%global auditversion 0.3-1 Summary: A set of tools to gather troubleshooting information from a system Name: sos -Version: 4.5.0 +Version: 4.10.0 Release: 1%{?dist} Group: Applications/System Source0: https://github.com/sosreport/sos/archive/%{version}/sos-%{version}.tar.gz Source1: sos-audit-%{auditversion}.tgz -License: GPLv2+ +License: GPL-2.0-or-later BuildArch: noarch Url: https://github.com/sosreport/sos BuildRequires: python3-devel BuildRequires: gettext BuildRequires: python3-setuptools -Requires: tar -Requires: bzip2 -Requires: xz Requires: python3-requests +Requires: python3-setuptools Recommends: python3-magic Recommends: python3-pexpect Recommends: python3-pyyaml Conflicts: vdsm < 4.40 Obsoletes: sos-collector <= 1.9 - +Patch1: sosreport-binary.patch +Patch2: 0001-cleaner-Make-cleaner-s-obfuscate_file-properly-worki.patch +Patch3: 0002-openstack_nova-Improve-scrubbing.patch %description Sos is a set of tools that gathers information about system @@ -35,6 +35,9 @@ support technicians and developers. %prep %setup -qn %{name}-%{version} %setup -T -D -a1 -q +%patch -P 1 -p1 +%patch -P 2 -p1 +%patch -P 3 -p1 %build %py3_build @@ -47,7 +50,9 @@ install -d -m 700 %{buildroot}%{_sysconfdir}/%{name}/cleaner install -d -m 755 %{buildroot}%{_sysconfdir}/%{name}/presets.d install -d -m 755 %{buildroot}%{_sysconfdir}/%{name}/groups.d install -d -m 755 %{buildroot}%{_sysconfdir}/%{name}/extras.d +install -d -m 755 %{buildroot}%{_sysconfdir}/tmpfiles.d/ install -m 644 %{name}.conf %{buildroot}%{_sysconfdir}/%{name}/%{name}.conf +install -m 644 tmpfiles/tmpfilesd-sos-rh.conf %{buildroot}%{_sysconfdir}/tmpfiles.d/%{name}.conf rm -rf %{buildroot}/usr/config/ @@ -67,6 +72,7 @@ cd .. %dir /etc/sos/presets.d %dir /etc/sos/extras.d %dir /etc/sos/groups.d +%{_sysconfdir}/tmpfiles.d/%{name}.conf %{python3_sitelib}/* %{_mandir}/man1/* %{_mandir}/man5/sos.conf.5.gz @@ -78,7 +84,7 @@ cd .. %package audit Summary: Audit use of some commands for support purposes -License: GPLv2+ +License: GPL-2.0-or-later Group: Application/System %description audit @@ -101,9 +107,150 @@ of the system. Currently storage and filesystem commands are audited. %{_mandir}/man8/sos-audit.sh.8.gz %ghost /etc/audit/rules.d/40-sos-filesystem.rules %ghost /etc/audit/rules.d/40-sos-storage.rules +%license LICENSE %changelog +* Thu Aug 21 2025 Jan Jansky = 4.10.0-1 +- Update to 4.10.0 + Resolves: RHEL-110500 + Resolves: RHEL-110501 + Resolves: RHEL-110502 + Resolves: RHEL-110503 + +* Fri Jul 04 2025 Jan Jansky = 4.9.2-1 +- Update to 4.9.2 + Resolves: RHEL-101717 + Resolves: RHEL-101718 + Resolves: RHEL-101719 + Resolves: RHEL-101720 + +* Fri May 30 2025 Jan Jansky = 4.9.1-2 +- Update to 4.9.1-2 in RHEL 9 + Resolves: RHEL-86668 + Resolves: RHEL-86644 + Resolves: RHEL-86647 + Resolves: RHEL-86646 + +* Tue Apr 15 2025 Jan Jansky = 4.9.1-1 +- Update to 4.9.1 in RHEL 9 + Resolves: RHEL-86668 + Resolves: RHEL-86644 + Resolves: RHEL-86647 + Resolves: RHEL-86646 + +* Fri Jan 24 2025 Jan Jansky = 4.8.2-2 +- Add new plugin aap_containerized + Resolves: RHEL-76057 + +* Tue Jan 07 2025 Jan Jansky = 4.8.2-1 +- Update to 4.8.2 in RHEL 9 + Resolves: RHEL-72942 + +* Wed Oct 23 2024 Jan Jansky = 4.8.1-1 +- Update to 4.8.1 in RHEL 9 + Resolves: RHEL-64159 + +* Tue Oct 15 2024 Jan Jansky = 4.8.0-5 +- Rebase to 4.8.0 and adding credential obfuscation + Resolves: RHEL-58096 + +* Fri Sep 27 2024 Jan Jansky = 4.8.0-4 +- Added credentials obfuscation from multiple files + Resolves: RHEL-58096 + +* Wed Sep 25 2024 Jan Jansky = 4.8.0-3 +- Update 4.8.0 + Resolves: RHEL-58096 + +* Thu Sep 19 2024 Jan Jansky = 4.8.0-2 +- Update to 4.8.0 + Resolves: RHEL-58096 + +* Mon Sep 09 2024 Pierguido Lambri = 4.8.0-1 +- New upstream release + Resolves: RHEL-58096 + +* Wed Aug 21 2024 Pavel Moravec = 4.7.2-3 +- reverting RHEL-22732 patch due to regressions + Resolves: RHEL-49781 + +* Fri Jun 21 2024 Pierguido Lambri = 4.7.2-1 +- New upstream release + Resolves: RHEL-49781 + +* Thu May 09 2024 Pavel Moravec = 4.7.1-3 +- [archive] Fix get_archive_root after files reordering + Resolves: RHEL-35945 + +* Mon Apr 08 2024 Jan Jansky = 4.7.1-1 +- rebase to upstream 4.7.1 + Resolves: RHEL-32106 + +* Tue Feb 20 2024 Jan Jansky = 4.7.0-1 +- rebase to upstream 4.7.0 + Resolves: RHEL-26115 + +* Thu Jan 11 2024 Pavel Moravec = 4.6.1-1 +- rebase to upstream 4.6.1 + Resolves: RHEL-21174 +- [redhat] Change authentication method for RHEL + Resolves: RHEL-21178 + +* Wed Oct 18 2023 Pavel Moravec = 4.6.0-5 + [pulpcore] Scrub AUTH_LDAP_BIND_PASSWORD value + Resolves: RHEL-13701 + +* Tue Oct 17 2023 Pavel Moravec = 4.6.0-4 +- [pulp] Fix dynaconf obfuscation and add AUTH_LDAP_BIND_PASSWORD + Resolves: RHEL-13701 + +* Thu Oct 12 2023 Pavel Moravec = 4.6.0-3 +- [greenboot] seperate logs to a standalone plugin; enhance [microshift] + Resolves: SUPDEV148 + +* Fri Sep 01 2023 Pavel Moravec = 4.6.0-2 +- [openshift_ovn] Collect additional ovnkube node logs + Resolves: SUPDEV145 + +* Wed Aug 23 2023 Jan Jansky = 4.6.0-1 +- [ultrapath] Add new plugin for Huawei UltraPath + Resolves: bz2187407 +- [cleaner] Use data filter for extraction + Resolves: bz2217906 +- [discovery] Enable the plugin by containers + Resolves: bz2222134 + +* Thu Jul 27 2023 Pavel Moravec = 4.5.6-1 +- Collect db files for ovn interconnect environment + Resolves: bz2226682 + +* Fri Jul 14 2023 Jan Jansky - 4.5.5-2 +- Adding patch for cleaning mac addresses + Resolves: bz2217943 + +* Mon Jul 03 2023 Jan Jansky = 4.5.5-1 +- Rebase on upstream 4.5.5 + Resolves: bz2217943 + +* Wed May 31 2023 Pavel Moravec = 4.5.4-1 +- [specfile] add runtime requirement to python3-setuptools + Resolves: bz2207776 + +* Thu May 04 2023 Jan Jansky = 4.5.3-1 +- [unpackaged] Print unpackaged symlinks instead of targets + Resolves: bz2169684 +- [report] Ignore case when scrubbing via do_file_sub + Resolves: bz2174254 +- [powerpc]: To collect lparnumascore logs + Resolves: bz2177984 + +* Wed Mar 08 2023 Pavel Moravec = 4.5.1-3 +- Rebase on upstream 4.5.1 + Resolves: bz2175808 +- [microshift] Fix microshift get and add commands + Resolves: bz2175650 + * Tue Feb 07 2023 Pavel Moravec = 4.5.0-1 - Rebase on upstream 4.5.0 Resolves: bz2082615 @@ -336,8 +483,7 @@ of the system. Currently storage and filesystem commands are audited. * Thu Apr 01 2021 Pavel Moravec - 4.1-3 - adding sos-audit - [gluster] Add glusterd public keys and status files - Resolves: bz1925419 + Resolves: bz1925419 * Wed Mar 10 2021 Sandro Bonazzola - 4.1-1 - Rebase to 4.1 -