Commit Graph

69292 Commits

Author SHA1 Message Date
Brad Thurber
325befa557 new runner for vistara (#33263)
* new runner for vistara

* clean lint
2016-05-16 09:23:16 -07:00
Kevin Alberts
2f76a2dc34 linux_acl: Allow '-' as a separation character in ACL permissions. Fixes #31270 (#33172)
This allows using acl states with things like '- perms: r-x' or '- perms: r--', which also works when manually setting ACL's using setfacl.
2016-05-16 08:01:09 -07:00
Eric Radman
d7bd667f79 Unbreak passwd change/expire reading on OpenBSD (#33227)
Tested on OpenBSD 5.9, the format for master.passwd for NetBSD should be
the same.
2016-05-16 07:56:51 -07:00
Rob Nagler
1e636f141f allow top cfg to be YAML for consistency and flexibility (current syntax does not allow blank lines or comments) (#33189) 2016-05-16 07:49:31 -07:00
Hu Min
6654d15daa allow user to revert vm to the specific snapshot for vmware (#33234)
* allow user to revert vm to the selected snapshot for vmware

* fixed Pylint check failed

* add two blank lines to fix Pylink check failed

* refactor code according to nmadhok's comments
2016-05-16 07:44:52 -07:00
Mostafa Hussein
d1b114bdae Support for Advanced Policy Firewall (APF) (#33134)
* Add Support for CSF

* Add Support for APF

* add new apf module to docs

* add blank line to match salt lint rules

* adding deny/remove host functions

* using python instead of bash while finding out if APF is running

* add error handling if iptc is missing

* remove trailing space
2016-05-16 07:42:26 -07:00
Moe
3b50a7b98d Fix list_values, add test (#33264) 2016-05-16 07:31:19 -07:00
rattlesnack
05e763c53c Gentoo/OpenRC service management enhancements (#33260)
* gentoo service enhancements

* fixing command examples
making sure enabled handles multiple runlevel

* unused import removed

* replacing collection.OrderedDict with salt.utils.odict.OrderedDict

* set replaced with list
2016-05-16 07:26:24 -07:00
Dane
30ca6443a9 Don't send passwords after shim delimiter is found (#33170)
The SSH_PASSWORD_PROMPT_RE regexp used to detect if SSH is requesting a
password can be triggered if the shim is returning data to the server
with text that matches the regex, including inside JSON results. This
then results in the server unable to parse the JSON results. This
patch fixes this issue by looking for the shim delimiter in the output and
disabling the sending of passwords after the delimiter is found.

Fixes #29422.
2016-05-13 15:36:38 -06:00
Erik Johnson
5c2870c24f Properly report on invalid gitfs/git_pillar/winrepo repos (#33244) 2016-05-13 15:32:51 -06:00
Nicole Thomas
bfd4bb6c47 Merge pull request #33241 from rallytime/merge-develop
[develop] Merge forward from 2016.3 to develop
2016-05-13 11:35:26 -06:00
rallytime
b1e505f80e Merge branch '2016.3' into 'develop'
Conflicts:
  - doc/topics/releases/2015.5.11.rst
  - doc/topics/releases/2015.8.9.rst
  - salt/cloud/clouds/nova.py
  - salt/minion.py
2016-05-13 09:47:46 -06:00
skizunov
332058d5e3 Windows: salt fails to start when running in system account (#33220)
`salt/utils/__init__.py`:
- In `get_user`, if it is the built-in system account, return the
more recogizable 'SYSTEM' (which is the return value of
`GetUserName`) instead of the SAM format which looks like:
'<DOMAIN>\<HOSTNAME>$'.

`salt/utils/win_functions.py`:
- In `get_current_user` do the same change as above.
- In `is_admin`, accept the system account sid ('S-1-5-18') as
administrator access. It technically isn't in the 'administrators'
group but has the same access rights as administrators.
- In `get_user_groups`, if the user is 'SYSTEM', don't invoke
`win32net.NetUserGetLocalGroups`. It will not recognize the
'SYSTEM' username because it is a special built-in account and thus
throw an exception. Instead, just add 'SYSTEM' to the list of groups.
`get_sid_from_name` will still convert it correctly to 'S-1-5-18'.

Signed-off-by: Sergey Kizunov <sergey.kizunov@ni.com>
2016-05-13 08:20:59 -07:00
Andrew Hammond
bc8f010489 add nodegroups ext_pillar (#33179)
* add nodegroups ext_pillar

* nodegroups ext_pillar documentation tweaks

* put name in AUTHORS rather than directly in module
2016-05-13 08:26:13 -06:00
Justin Anderson
012dc882aa Fix boto_vpc_test to work with #32677 (#33214) 2016-05-13 08:22:10 -06:00
Seth House
6a69136080 Expose CherryPy option to write access and error logs (#33226) 2016-05-13 08:15:38 -06:00
Nicole Thomas
a7713806e9 Merge pull request #33221 from rallytime/merge-2016.3
[2016.3] Merge forward from 2015.8 to 2016.3
2016-05-12 20:59:57 -06:00
rallytime
679200aeb2 Merge branch '2015.8' into '2016.3'
Conflicts:
  - salt/scripts.py
2016-05-12 16:52:27 -06:00
Nicole Thomas
6dc5d605b1 Merge pull request #33217 from rallytime/merge-forward-2015.8
[2015.8] Merge forward from 2015.5 to 2015.8
2016-05-12 16:45:39 -06:00
Joseph Hall
1aee8e8dcf Fix 2 more errors with listing networks (#33216) 2016-05-12 14:56:07 -07:00
Joseph Hall
6794a7d2c6 Allow VMs to use a virtual network from a different resource group (#33218) 2016-05-12 14:54:50 -07:00
rallytime
4655607b58 Merge branch '2015.5' into '2015.8'
No conflicts.
2016-05-12 15:44:56 -06:00
Jεan Sacren
8685ffa2e9 Add timezone integration test for Solaris (#33167) 2016-05-12 14:40:37 -07:00
Thomas S Hatch
698f1eb657 Merge pull request #33211 from cachedout/user_kill
Don't try to kill a parent proc if we can't
2016-05-12 15:29:50 -06:00
Alejandro del Castillo
2d1068d2a5 Windows minion fix (broken on PR #33011) (#33206)
* minion.py: fix Windows minion

On Windows, by default, new processes are created to handle new jobs. The
minion instance member, is reconstructed on the new process. However, the
connected state is not being preserved, which prevents the minion from
sending updates on the PUB channel. Add parameter to _target to pass
existing connected state.

PR #33011 added a minion_instance.connected check to _thread_return, which
prevented the minion from returning it's result to the master.

Signed-off-by: Alejandro del Castillo <alejandro.delcastillo@ni.com>

* _thread_multi_return: add multifunc support to standalone minion

Currently salt-call doesn't have support for multifunc jobs in either
the CLI or the python API. This change add the same logic present in
_thread_return to get the standalone minion to behave correctly, in case
multifunc jobs are support by the Caller class in the future.

Signed-off-by: Alejandro del Castillo <alejandro.delcastillo@ni.com>
2016-05-12 13:56:50 -07:00
Joseph Hall
558e401b3a Fix list_networks() when a resource_group has no networks (#33208) 2016-05-12 13:56:07 -07:00
Rodrigo Candido Gryzinski
aaf6383f4f add auth database parameter to MongoDB module and state functions (#33209) 2016-05-12 13:55:26 -07:00
Nicole Thomas
730bec1eef [2015.8] Merge forward from 2015.5 to 2015.8 (#33207)
* Fix file.managed for Windows (#33181)

* Revert back to import string_types

For some reason, there is a problem with the following
code when run from the file.py module:
```
from salt.ext import six
comment = 'This is a string'
isinstance(comment, six.string_types)
```
When run from within the python shell it works fine.

* Add six import

* Fix some lint

* Use correct six import

* Changed it back to explicit import

* Additional comments specific to 2015.5

* Fix file.managed for real

* Move comment to clarify purpose

* update 2015.5.11 release notes (#33197)

* Add pip installed and removed test (#33178)

* Resolve issue with pkg module on Mint Linux (#33205)

Closes #32198
2016-05-12 13:54:47 -07:00
Jay Port
ab9cc08a71 catch None cases for comments in jboss7 state module (#33190) 2016-05-12 13:39:32 -07:00
Mike Place
d4f2e5baa7 Don't try to kill a parent proc if we can't 2016-05-12 14:02:00 -06:00
Erik Johnson
379b151d75 Add a fetch when compiling git_pillar for masterless minions (#33204)
Fixes #32917.
2016-05-12 13:53:51 -06:00
Mike Place
f86832911e Resolve issue with pkg module on Mint Linux (#33205)
Closes #32198
2016-05-12 12:23:34 -06:00
Laurent
0ab52ab690 propagate opts to salt.util.http call (#33154) 2016-05-12 10:26:23 -07:00
Moe
8967d8ded1 Add initial win_snmp modules (#33112)
* Add initial win_snmp modules

* Modify for loader.
2016-05-12 10:24:35 -07:00
skizunov
987d2f12e2 Windows: salt fails to start when running as domain user (#33153)
The following error occurs when running salt-master or salt-minion
under a domain user account:

  File "...\lib\site-packages\
  salt\utils\win_functions.py", line 79, in get_user_groups
      groups = win32net.NetUserGetLocalGroups(None, name)
      pywintypes.error: (2221, 'NetUserGetLocalGroups',
      'The user name could not be found.')

`salt/utils/__init__.py`:
- Change `get_user` to use:
`win32api.GetUserNameEx(win32api.NameSamCompatible)`. This will return
the username in the format 'DOMAIN\username'.

`salt/utils/win_functions.py`:
- Change `get_current_user` to also use
`win32api.GetUserNameEx(win32api.NameSamCompatible)`. This will fix the
problem when it passes the username to `win32net.NetUserGetLocalGroups`.

`salt/client/__init__.py`:
- In `LocalClient.__read_master_key`, on Windows replace the username
portion of the keyfile path so that '\' is converted to '_'. This will
allow a valid filename.

`salt/daemons/masterapi.py`:
- In `access_keys`, on Windows replace the username
portion of the keyfile path so that '\' is converted to '_'. This will
allow a valid filename.

Signed-off-by: Sergey Kizunov <sergey.kizunov@ni.com>
2016-05-12 10:19:17 -07:00
Justin Findlay
b3805d825a cloud.clouds.ec2: cache each named node (#33164) 2016-05-12 10:16:27 -07:00
Rob Nagler
c083572c09 better log message when Jinja can't find include file (#33176) 2016-05-12 10:13:59 -07:00
Erik Johnson
86db5df7c1 Properly handle failed git commands when redirect_stderr=True (#33203)
* Properly handle redirected stderr

When running subprocess.Popen.communicate() on a command run with stderr
redirected to subprocess.STDOUT, the 2nd element of the return tuple
(representing the stderr) will be None, since all of the standard error
was sent to stdout.

Functions interpreting the return data from cmd.run_all will be
expecting the ``stderr`` key in the return dict to contain a string, not
a NoneType, so this commit forces the stderr to be set to an empty
string when redirect_stderr is True.

* Look at stdout instead of stderr for error text when redirect_stderr is True
2016-05-12 10:10:46 -07:00
Jεan Sacren
0138de8107 Set default to UTC for Gentoo (#33166) 2016-05-12 08:34:38 -07:00
Justin Anderson
a09e1b6335 Add pip installed and removed test (#33178) 2016-05-12 08:31:41 -07:00
Erik Johnson
8a0950de27 Don't force use of global ssh_config when git identity file is specified (#33152)
I can no longer reproduce the edge case I was trying to fix with this
logic, and it's a bad solution anyway in that it caused #32685.
2016-05-12 08:28:19 -07:00
Nicole Thomas
457d9dd4f5 [develop] Merge forward from 2016.3 to develop (#33193)
* Add run_on_start docs to schedule.rst (#32958)

Fixes #22580

* Backport #33021 manually to 2015.5 (#33044)

* Saltfile with pillar tests (#33045)

* add file.managed with pillar data tests

* do not require git for other tests

* Fix minor document error of test.assertion (#33067)

* test pillar.items output (#33060)

* File and User test fixes for 2015.5 on Fedora23 (#33055)

* Fix file_test.test_symlink on 2015.5

* Fix failing user present test

* add test for installing package while using salt-call --local (#33025)

* add test for installing package while using salt-call --local

* fix pylint

* ssh docs: install py-2.6 for RHEL 5

* Bugfix: Restore boolean values from the repo configuration

* Add test data for repos

* Add repo config test

* Bugfix (follow-up): setting priority requires non-positive integer

* modules.npm: do not log npm --version at info level (#33084)

* salt-cloud: fix ipv6-only virtual machines (#32865)

* salt-cloud: fix ipv6-only virtual machines

* fix hostname for rsync fallback in scp_file function

* use 4 spaces instead of 2

* remove global variable, use direct socket call instead

* Use saltstack repo in buildpackage.py on CentOS 5 (#33080)

* Lower display of msgpack failure msg to debug (#33078)

Closes #33074

* cloud.query needs to define mapper.opts (#33098)

* clarify docs that map is designed to be run once. is not stateful (#33102)

* Moved _finger_fail method to parent class.

Method _finger_fail method from SAuth to AsyncAuth class to make method available
in both class and fix an issue where _finger_Fail is called inside AsyncAuth.

* Fix 33058 (#33099)

* Fix servermanager module

- Added check for 2008 version of windows
- Added Import-Module ServerManager to _pshell_json.
  Apparently this needs to run each time we issue a
  servermanager command.

* Fix list_available

* salt.utils.gitfs: fix formatting for warning messages (#33064)

* salt.utils.gitfs: fix formatting for warning messages

When git_pillar support was added to salt.utils.gitfs, the
recommendation globals had string formatting placeholders added to them,
but the locations where these values are referenced do not call
``.format()`` to properly replace them. This commit fixes that
oversight.

* Remove more gitfs and master-specific wording from log messages

* Add a check that the cmdline of the found proc matches (#33129)

* Doc mock decorators (#33132)

* Add mock function for mocking decorators

* Mock the stdlib user module because importing it will open the repl

* Fix broken parsing of usermgmt.conf on OpenBSD (#33135)

When creating a new user, if a group of the same name already exists,
the usermgmt.conf file is consulted to determine the primary group.
It's in these cases that the parsing bug is triggered.

This code change addresses several of the existing issues:

- The previous split statement explicitly specified a single space.
  Since a config line may have any number of spaces and/or tabs
  surrounding the entries, the resulting array's elements may be
  incorrect.

- According to the man pages for usermgmt.conf, the "group" config
  entry accpets a single parameter -- so we shouldn't iterate.

- The "val[1]" was returning the 2nd letter of each word and not the
  second word on the config line as intended.

* Move salt-ssh thin dir location to /var/tmp (#33130)

* Move salt-ssh thin dir location to /var/tmp

Closes #32771

* Remove performance penelty language

* If cache_jobs: True is set, populate the local job cache when running salt-call (#33100)

* If cache_jobs: True is set, populate the local job cache

Fixes #32834

Allows a masterless minion to query the job cache.

* Refactor cache_jobs functionality to be DRY

* Skipping salt-call --local test

* Back-port #31769 to 2015.8 (#33139)

* Handle empty acl_name in linux_acl state

Calls to setfacl interpret an empty group or user name to mean to be the
owner of the file they're operating on. For example, for a directory
owned by group 'admin', the ACL 'default:group::rwx' is equivalent to
'default:group:admin:rwx'.

The output of the getfacl execution module returns ACLs in the format of
'group:admin:rwx' instead of 'group::rwx'. This commit changes the
acl.present state to look for the owner of the file if the acl_name
paremeter is empty.

* Fix acl.present/acl.absent changing default ACLs

The behaviour of the acl.present and acl.absent is to check the data
structure returned by getfacl contains a key by the name of acl_type.

However, this data structure does not contain any default ACLs if none
exist, so this check will fail. We omit the check if a default ACL was
passed into the state functions.

Unfortunately, the call to modfacl may fail if the user passes in an
acl_type such as 'default:random'. In this case the state will appear to
succeed, but do nothing.

This fixes the state module to allow setting default ACLs on files which
have none.

* Fix regression in 2016.3 HEAD when version is specified (#33146)

Resolves #33013.

* Hash fileclients by opts (#33142)

* Hash fileclients by opts

There was an issue whereby the cache of the fileclient was being overwritten
by dueling minion instances in multimaster mode. This protects them by hashing
by the id of opts.

Closes #25040

* Silly typo!

* Remove tests which do not test any actual functionality or are too tightly coupled to the implementation

* Strip ldap fqdn (#33127)

* Add option to strip off domain names on computer names that come from LDAP/AD

* Add strip_domains option for ldap.

* Add documentation for auth.ldap.minion_stripdomains.

* [2015.5] Update to latest bootstrap script v2016.05.10 (#33155)

* [2015.8] Update to latest bootstrap script v2016.05.10 (#33156)

* [2016.3] Update to latest bootstrap script v2016.05.10 (#33157)

* add 2015.5.11 release notes (#33160)

* add 2015.8.9 release notes (#33161)

* Pip fix (#33180)

* fix pip!!

* make it work with old pip as well

* Added resiliency

* Don't need to check, just get the right name

* [2015.5] Update to latest bootstrap script v2016.05.11 (#33185)
2016-05-12 07:53:39 -07:00
Justin Findlay
ce071330de update 2015.8.9 release notes (#33198) 2016-05-12 05:03:07 -06:00
Justin Findlay
96e3586f12 update 2015.5.11 release notes (#33197) 2016-05-12 04:54:40 -06:00
Shane Lee
09b072a412 Fix file.managed for Windows (#33181)
* Revert back to import string_types

For some reason, there is a problem with the following
code when run from the file.py module:
```
from salt.ext import six
comment = 'This is a string'
isinstance(comment, six.string_types)
```
When run from within the python shell it works fine.

* Add six import

* Fix some lint

* Use correct six import

* Changed it back to explicit import

* Additional comments specific to 2015.5

* Fix file.managed for real

* Move comment to clarify purpose
2016-05-11 17:59:05 -06:00
Nicole Thomas
85c8ba1e47 Merge pull request #33192 from rallytime/merge-2016.3
[2016.3] Merge forward from 2015.8 to 2016.3
2016-05-11 17:29:07 -06:00
rallytime
a93c35d537 Merge branch '2015.8' into '2016.3'
Conflicts:
  - salt/cloud/deploy/bootstrap-salt.sh
2016-05-11 16:36:42 -06:00
Nicole Thomas
6177a6a36f Merge pull request #33188 from rallytime/merge-2015.8
[2015.8] Merge forward from 2015.5 to 2015.8
2016-05-11 16:32:29 -06:00
Chandler
b28b507c4a Add username, channel, and emoji support to slack module (#33184)
* Add username, channel, and emoji support to slack module

* Fix for API compatibility
2016-05-11 16:03:06 -06:00
rallytime
f12bba6ebc Merge branch '2015.5' into '2015.8'
Conflicts:
  - salt/cloud/deploy/bootstrap-salt.sh
2016-05-11 15:14:23 -06:00