Azure Update Manager disregards FIPS repositories for Ubuntu 22.04
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 55/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- python, ubuntu
- Lĩnh vực
- devops, operating-systems
Hướng nghiên cứu
Bắt đầu với AptitudePackageManager.py:186 và quá trình xây dựng danh sách nguồn bảo mật, sau đó lần theo install_security_updates_azgps_coordinated() ở các dòng 486-490 cùng với đường dẫn phát hiện Ubuntu Pro. Tái hiện hoặc kiểm tra trường hợp Ubuntu 22.04 FIPS được mô tả trong issue; được xem là hoàn tất khi các bản cập nhật openssh FIPS vẫn khả dụng trong quá trình cài đặt và các gói không phải FIPS không được chọn.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Describe the bug
Due to the filter in AptitudePackageManager, updates provided by the FIPS repo https://esm.ubuntu.com/fips-updates/ubuntu jammy-updates does not pass the filter and is dropped. If the Ubuntu Pro client is enabled, this problem is worse and will ultimately lead to non-FIPS packages being installed causing conflicts.
Azure Update Manager installs non-FIPS openssh-server on FIPS-enabled Ubuntu 22.04
Root Cause
The LinuxPatchExtension (v1.6.64) has two independent mechanisms for discovering
available updates:
- apt-get -s dist-upgrade (using a custom filtered source list)
- Ubuntu Pro Client API (via uaclient.api.u.pro.packages.updates.v1)
When building the security-classification source list, the extension filters each
deb line with a simple substring check:
AptitudePackageManager.py:186
if base_classification == Constants.PackageClassification.SECURITY and "security" not in line:
continue
The FIPS updates repo uses suite name "jammy-updates", not "jammy-security":
deb https://esm.ubuntu.com/fips-updates/ubuntu jammy-updates main
So it gets excluded from the security source list. Other ESM repos survive because
they have "-security" suites (jammy-apps-security, jammy-infra-security).
During DISCOVERY, the Pro Client independently finds the FIPS openssh packages
(classified as "standard-security") and they get merged into the combined package
list. The log shows them as "Pro Client only updates."
During INSTALLATION, the Pro Client is not involved. The extension calls:
AptitudePackageManager.py:486-490
install_security_updates_azgps_coordinated() ->
apt-get -y --only-upgrade true dist-upgrade
This rebuilds the same filtered security source list (without the FIPS repo).
apt resolves openssh-server from jammy-security instead, installing the non-FIPS
version.
Summary: discovery uses Pro Client (FIPS-aware), installation uses apt with a
filtered source list (not FIPS-aware). The two paths are not coordinated.
- Ngôn ngữ chính
- Python
- Star
- 12
- Fork
- 20
- Merge trung bình
- 19 giờ 43 phút
- Pull request đã merge (30 ngày)
- 3
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của Azure/LinuxPatchExtension
-
Độ khó 2/5 Nửa ngày Mức phù hợp với người mới 68/100
Azure/LinuxPatchExtension#350 · 1 bình luận ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
Azure/LinuxPatchExtension#381 · 1 reaction ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
Azure/LinuxPatchExtension#369 · 1 bình luận ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 52/100
Azure/LinuxPatchExtension#339 · 3 bình luận ·
-
Allow to specify package versionĐang mở
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 38/100
Azure/LinuxPatchExtension#335 ·
Tất cả issue của Azure/LinuxPatchExtension
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
NousResearch/hermes-plugin-claude-subscription-directsdk#94 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Claiming namespace `reactogenic`Đang mởnamespace operations
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
EclipseFdn/open-vsx.org#13702 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
modelscope/ms-swift#10287 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
modelscope/FunASR#3757 ·
Maintainer thường phản hồi trong vòng 1 ngày