Skip to content

Fix lineinfile Ansible template emitting empty regexp - #15142

Open
HSP18SCM23P wants to merge 16 commits into
ComplianceAsCode:masterfrom
HSP18SCM23P:fix-lineinfile-empty-regexp
Open

HSP18SCM23P wants to merge 16 commits into
ComplianceAsCode:masterfrom
HSP18SCM23P:fix-lineinfile-empty-regexp

Conversation

@HSP18SCM23P

Copy link
Copy Markdown

Description:

The shared lineinfile template was the only ansible_lineinfile call site omitting the regex argument, so every generated task shipped regexp: '' which matches every line and causes Ansible to replace the last line of the target file (destroying it on first run, appending duplicates after). The fix passes an explicit anchored regex per rule.

Fixes #15034

@openshift-ci openshift-ci Bot added the needs-ok-to-test Used by openshift-ci bot. label Sep 25, 2026
@openshift-ci

openshift-ci Bot commented Sep 25, 2026

Copy link
Copy Markdown

Hi @HSP18SCM23P. Thanks for your PR.

I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@HSP18SCM23P

Copy link
Copy Markdown
Author

Note: set_firewalld_default_zone and sssd_enable_certmap are intentionally untouched — both rules disable the ansible and bash backends, so the lineinfile template is never rendered for them.

@ggbecker

Copy link
Copy Markdown
Member

Please make sure all those extra empty newlines are not part of the proposed changes.

Signed-off-by: HSP18SCM23P <38229980+HSP18SCM23P@users.noreply.github.com>
Signed-off-by: HSP18SCM23P <38229980+HSP18SCM23P@users.noreply.github.com>
Signed-off-by: HSP18SCM23P <38229980+HSP18SCM23P@users.noreply.github.com>
Signed-off-by: HSP18SCM23P <38229980+HSP18SCM23P@users.noreply.github.com>
Signed-off-by: HSP18SCM23P <38229980+HSP18SCM23P@users.noreply.github.com>
Signed-off-by: HSP18SCM23P <38229980+HSP18SCM23P@users.noreply.github.com>
Signed-off-by: HSP18SCM23P <38229980+HSP18SCM23P@users.noreply.github.com>
Signed-off-by: HSP18SCM23P <38229980+HSP18SCM23P@users.noreply.github.com>
Signed-off-by: HSP18SCM23P <38229980+HSP18SCM23P@users.noreply.github.com>
Signed-off-by: HSP18SCM23P <38229980+HSP18SCM23P@users.noreply.github.com>
@HSP18SCM23P

Copy link
Copy Markdown
Author

Confirmed — the extra blank lines have been removed. The diff is now exactly the five one-line regex: additions plus the template fix (+6/−3 across 6 files), pushed in cleanup commits 952478f–ae615bc.

@macko1

macko1 commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Hello @HSP18SCM23P and thanks for the contribution.

Please improve the PR description - use the provided template.
I'd like to also ask you to provide detailed testing scenarios (commands+results), all in the PR description. You can refer to the style guide on how to proceed. https://complianceascode.readthedocs.io/en/latest/manual/developer/04_style_guide.html

This will make the review much faster.

Thanks! 🙏

@macko1 macko1 left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See #15142 (comment), please

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-ok-to-test Used by openshift-ci bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

lineinfile template generates regexp: '', so remediation overwrites the last line of the target file

3 participants