* Platforms like Alpine, Busybox which implements musl,
does not support providing service with getent command.
Fail with an error on such platforms.
Fixes: #85568
Signed-off-by: metformin503 <hou_huangbolin@126.com>
Co-authored-by: Abhijeet Kasurde <Akasurde@redhat.com>
Ensure that the `debugpy` module bundled by VSCode is included in the
debug environment set by `ansible-test shell --dev-debug-on-demand`.
This means that `debugpy` does not need to be manually installed in the
Python environment running Ansible.
* ansible-config: default validate to checking all plugin configs
ansible-config validate defaulted to -t base, so any configuration file
using a section owned by a plugin (e.g. [ssh_connection]) was reported
as an unknown section, and keys inside such sections were never
validated at all - a stock, perfectly valid ansible.cfg failed
validation out of the box.
Default the validate action to -t all so installed plugin configuration
is taken into account. An explicit -t still narrows validation, and the
other ansible-config actions keep their base default (the -t default is
now resolved per action in post_process_args, since the shared parent
parser action object cannot carry per-subcommand defaults).
Fixes#86398
Signed-off-by: Apoorv Darshan <ad13dtu@gmail.com>
* Move -t to per-default shared parsers built by a factory
Per review: instead of a None sentinel resolved in post_process_args,
provide two small shared parent parsers for -t (one with default
'base', one with default 'all', built by a factory) so each
subcommand's --help states its actual default.
Signed-off-by: Apoorv Darshan <ad13dtu@gmail.com>
* Address review: parametrize ansible-config type tests
Deduplicate the three near-identical tests into a single
@pytest.mark.parametrize with descriptive IDs, return the resolved type
directly from the helper, add return-type annotations, and turn the
helper's leading comment into a docstring.
* Default ansible-config type to all for every action
Broaden the new default as requested in review, while keeping -t base as the compatibility override for users who need the previous behavior. Cover every action and both explicit override paths in the parser tests.
Assisted-by: OpenAI Codex
Signed-off-by: Apoorv Darshan <ad13dtu@gmail.com>
* Move ansible-config default coverage to integration tests
Exercise the public CLI across every action and run existing init, validate, and dump scenarios without an explicit type. Remove the parser-only unit test and use translation-friendly changelog wording.
Assisted-by: OpenAI Codex
Signed-off-by: Apoorv Darshan <ad13dtu@gmail.com>
* Document ansible-config default as breaking
Move the entry into the generated porting-guide section and document the -t base compatibility override.
Assisted-by: OpenAI Codex
Signed-off-by: Apoorv Darshan <ad13dtu@gmail.com>
---------
Signed-off-by: Apoorv Darshan <ad13dtu@gmail.com>
is_netmask only validated each octet against VALID_MASKS independently and
never checked that the octets form a contiguous run of network bits. As a
result masks like 255.255.0.255, 254.255.255.0 or 0.255.0.0 were reported as
valid, and downstream helpers such as to_masklen/to_subnet then produced
nonsensical results.
Verify that the assembled 32-bit mask is a contiguous block of 1s followed by
0s.
Signed-off-by: semx <7532921+semx@users.noreply.github.com>
Co-authored-by: Abhijeet Kasurde <akasurde@redhat.com>
* Fix collection loader iterator for ext modules
Fixes the collection loader iter_modules logic to return compiled Python
extension modules. This loader is used when attempting to call
`pkgutil.iter_modules` on a package that is contained inside the
`ansible_collections` path. Before extension modules were skipped which
would break imports of 3rd party modules that used compiled extensions
if it was installed in a Python environment located inside a collection.
* Fix up pkg logic
* Added integration test
* Add newline to alias file
* Update lib/ansible/utils/collection_loader/_collection_finder.py
Co-authored-by: 🇺🇦 Sviatoslav Sydorenko (Святослав Сидоренко) <wk.cvs.github@sydorenko.org.ua>
---------
Co-authored-by: 🇺🇦 Sviatoslav Sydorenko (Святослав Сидоренко) <wk.cvs.github@sydorenko.org.ua>
* fix bcrypt salt string formatting on musl libc by ensuring it is always zero-padded to 2 digits
Fixes: #87180
Signed-off-by: Abhijeet Kasurde <Akasurde@redhat.com>
The language packs are an Ubuntu-specific packaging. On Debian systems
(and derivatives) these packages don't exist and the language files are
installed by default with the package (as confirmed with `apt-file
search tar.mo`)
* Deconstruct AGENTS.md to context dir
* Split guidelines applicable to both humans and agents to top-level `context` dir.
* Instruct agents to read all context files for now- piecemeal/just-in-time context ingestion has been spotty and problematic to date.
Co-authored-by: Matt Clay <matt@mystile.com>
Assisted-by: Claude
* update package-data sanity to ignore context
* markdown line length sanity
* Ignore context dir in change detection
* Remove core plugin deprecation instructions
* Inconsistent with published docs and docsite behavior- resolve those first.
---------
Co-authored-by: Matt Clay <matt@mystile.com>
* ansible-test - Update RHEL remotes
* Include packaging in RHEL bootstrapping
This is needed for the Ansible pip module to function in the absence of setuptools.
Pytest 9.1 fixed parametrize to correctly unpack single-element tuple values when using a string argnames with a trailing comma (e.g. "arg,"), treating it like the tuple form ("arg",) (pytest-dev/pytest#719).
This causes test_missing_lchmod_is_link_in_sticky_dir to fail because the trailing comma in @pytest.mark.parametrize('stdin,', ...) now makes pytest try to unpack {} as a sequence, finding 0 elements for 1 name.
Remove the spurious trailing comma from 'stdin,'.
Assisted-by: Claude Opus 4.6
The async_wrapper now stops the module process before writing the timeout result to the async job file. This ensures a valid JSON file that async_status can parse.
Improve gather_facts parallel=true timeout responsiveness when gather_timeout is less than 10.
Fix integration tests.
When the ansible-test timeout is enabled, a callback plugin is injected
into ansible-playbook that uses faulthandler.dump_traceback_later to
write all thread stacks to a file shortly before the deadline. This
provides diagnostic information for intermittent CI hangs where the
process stops producing output with no traceback or error.
Also fixes collection/setup.sh to handle multiple colon-separated
paths in ANSIBLE_COLLECTIONS_PATH.
Assisted-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Fix IndexError in free strategy when hosts become unreachable
Fixes an IndexError crash in the free strategy plugin when hosts
become unreachable during playbook execution.
The bug occurred when:
- last_host index persists across outer loop iterations
- hosts_left is regenerated each iteration via get_hosts_left()
- Some hosts become unreachable between iterations
- hosts_left shrinks but last_host retains its previous value
- Accessing hosts_left[last_host] raises IndexError
The fix adds a bounds check after regenerating hosts_left to reset
last_host to 0 if it's out of bounds. This preserves the round-robin
fairness algorithm while preventing the IndexError.
Assisted-by: Claude Sonnet 4.5 <noreply@anthropic.com>
* integration test
* review comment fixes
* ci_complete
* Pass malformed role requirements as positional arguments to prevent arbitrary git configuration
* Add test coverage, checking for specific errors and that git clone is always followed by --
Co-authored-by: 🇺🇦 Sviatoslav Sydorenko (Святослав Сидоренко) <wk.cvs.github@sydorenko.org.ua>
* Drop Python 3.12 controller support
* Remove obsolete code
* Remove obsolete centos6 test code
* Skip tests on unsupported platforms
* Work around lack of Alpine controller support in tests
* While modifying the user with lusermod command, warn user
if home directory does not exists and move_home is set to
true.
Fixes: #37398
Signed-off-by: Abhijeet Kasurde <Akasurde@redhat.com>
* Allow root to use sudo on managed Alpine VMs
This fixes the become_su test on Alpine when running non-split.
* Remove test user sudoers file when removing the user
* Recognize password failures for BusyBox su
Only for BusyBox since that was the context where this initally came up. It may
make sense to add this warning more broadly.
chsh on Alpine warns but does not error when changing to an invalid shell.
Other distros error with an invalid shell.
Signed-off-by: Sam Doran <sdoran@redhat.com>
Co-authored-by: Abhijeet Kasurde <Akasurde@redhat.com>
PR #87041
PR #87010 bumped the container used in CI for uploading the coverage
measurements to Codecov and its runtime now uses Python 3.13.
The previously set `.azure-pipelines/scripts/dependencies/codecov.txt`
pip constraints used to lock down the transitive dependencies in that
environment were of older versions and `test-results-parser==0.5.4`
caused pip to trigger building this dependency from an sdist due to
the latest platform-specific wheel available for that version being
tagged for Python 3.12.
The new container does not have enough of the build toolchain and the
build fails being unable to find the `cc` linker [[1]].
This patch mass-upgrades the transitive dependencies in said deptree
to newer versions that also ship platform-specific wheels for Python
3.13 and 3.14.
[1]: https://dev.azure.com/ansible/ansible/_build/results?buildId=181432&view=logs&j=d7668ad9-d7bb-5ae4-c14f-5061b89e467d&s=44856301-4c0b-5572-5f50-eb8e385c84fd&t=7f884d87-6a36-516f-9067-af4cf77c020d&l=93
ci_coverage
ci_complete