aim-web2.1.0rc9

This commit is contained in:
admin_rb
2026-09-22 19:23:17 +02:00
parent d095887d2e
commit 3dfc80b782
438 changed files with 31613 additions and 1510 deletions
+105
View File
@@ -0,0 +1,105 @@
# AIM 3.3.0rc8 controller acceptance
Run on disposable/approved targets under the actual execution UID, groups, HOME and
service sandbox, using native ansible-core 2.19.11 and declared collections. Do not use
an ordinary root shell as evidence for another worker. Do not send raw Vaults/config
secrets in test feedback. Keep the staging exceptions from the accepted deployment.
## Installation and unchanged controls
Verify checksum, preview the deployer, confirm only named obsolete Core docs are removed,
quiesce jobs/writers and apply. Verify `aim --version`, `aimctl --version`, capabilities,
independent terminal startup, Vault wrong-then-correct retry and cancellation. Confirm
operator aim.yml/inventory/keys/add-on state are unchanged. `aimctl staging-check` must
pass inside the executor, including differing process and passwd homes when relevant.
## Discover the new contract without credentials
```bash
aimctl capabilities
printf '%s\n' '{"api_version":"1.0","operation":"list_playbooks","customer":"CUSTOMER"}' | aimctl request
printf '%s\n' '{"api_version":"1.0","operation":"prepare","request":{"customer":"CUSTOMER","playbook":"debug_detect_host_roles","hosts":["HOST"]}}' | aimctl request
```
Replace identifiers. Request JSON is one line. Expect operation_results capability and
prepared result_contract with host_capabilities_v1; unchanged explicit targets/revision.
Nonreporting `debug_test_connection` must advertise result:null. Unknown options/hosts
must still fail before launch. Schema changes must stale an earlier preparation.
## Fresh approved execution matrix
Supply credentials through the established one-run provider/private FD. Use summary
and detail on separate newly approved runs; compare reports rather than event ordering.
Do not cache the password or reuse a provider/revision after source changes.
| Operation | Evidence required |
|---|---|
| Detect roles | Eight booleans agree with authorized native report; no inventory mutation |
| Disk usage | Compare Windows/Linux observed byte counts; handle unavailable/empty mounts |
| Export event logs | Paths exist after apply; existing logs not cleared; check creates no export |
| Start services | Disposable services: one recoverable, one failing dependency/disabled/race case, one excluded; compare before/after states and fixed reasons |
| Patch OS | Disposable snapshots: verify Linux net package/version changes; Windows uses one native win_updates wave per approved patch stage; IDs/KBs/HRESULTs; user-visible reboot message/delay; default stops after reboot with continuation_required; explicit post-reboot continuation starts another wave |
| Checkmk cleanup | Preview removes nothing; approved deletion lists only managed files actually changed |
| Read Checkmk user config | Plugins/local/unknown sections preserved in report; dummy passphrase and MRPE command data redacted; reject other basenames; no timestamp/content write |
| Checkmk install | Installed version agrees with registry/package DB; services observed; idempotent rerun shows no package/config changes |
| Checkmk config update | One approved rule/file change reported; second run no change; unrelated local/MRPE/unknown files untouched |
New reporting tasks change task counts. Compare effects, failure states and payloads,
not historical exact ok/skipped totals. For patching, protect against concurrent package
management and record starting snapshot/selected categories. A partial update still
requires explicit recovery decisions; never repeat automatically.
### Windows patch-wave acceptance
Use a disposable Windows target with several applicable updates. Confirm the normal apply
path contains one `win_updates state=installed` task for the selected categories rather than
one task per update. Windows/collection-native sequencing inside that wave is expected; AIM
should not emit `accept_list` selectors for individual discovered updates.
Record the structured result and compare it to Windows Update history. Installed and failed
updates should retain bounded IDs/titles/KBs/HRESULT classifications. A mixed native result
must not lose successful updates merely because another update failed. Raw failure messages
or exception text must not enter the operation result.
With `os_patching_rescan_after_reboot: false` (catalog default), allow the current wave to
finish and require reboot. The user should receive the reviewed message/delay. After
reconnect the run must end without another install/search wave. Expect
`continuation_required: true` and `remaining_updates_known: false`; a new approved run owns
the next patch state.
Also test a host that begins with an already-pending reboot. With automatic reboot enabled
and post-reboot continuation false, AIM should reboot and stop before patch installation.
With continuation true, it may begin the first native update wave after reboot. With
automatic reboot disabled, it must fail preflight before new installs.
Repeat with `os_patching_rescan_after_reboot: true`. After a patch-triggered reboot AIM may
start another native update wave. Do not infer this opt-in from the reboot flag. Explicit
continuation remains bounded to 12 waves. A failed wave must stop and must never be replayed
automatically.
For a failed update, confirm `failed_updates` contains only bounded title/ID, unsigned/hex
HRESULT, reason and fixed message. If `0x80240016` can be reproduced, expect
`install_not_allowed`; do not expect `preexisting_reboot_required` unless the separate
preflight actually observed a pending reboot.
## Fail-closed fixtures (disposable catalog/playbook only)
After each fixture edit, prepare/review anew. Test missing required publisher; wrong
schema/type/extra fields; publisher under no_log; duplicate publication; >limit data;
and a supplied secret canary in an output string. Expect no rejected payload in public
JSON/logs. Native exit 0 with invalid/missing required data must fail at result_validation,
retain exit_code 0/native target facts and never replay. No declaration must export
nothing even if unrelated debug/custom stats contain a secret.
Test two targets with one unreachable and one completed report. Overall native failure
remains; one available report does not imply all-target success. Test Ctrl+C mid-run:
report must not claim earlier observations are completed output. Ensure no residual
credential/helper process and a subsequent fresh operation works. Test chunked output
beyond a single private frame; a torn stream must fail, never silently truncate.
## Sign-off
Record version, execution UID/group context, runtime/collection versions, platform and
which cases were tested, separately for native terminal and service. Do not mark global
transport, another OS, Server 2012 R2 or another service identity accepted from one Windows
11 test. Report final status/exit/target facts/report availability with credentials removed.