From 2bf85cca518ed61dfa38a96c1d510ba1f49f10e8 Mon Sep 17 00:00:00 2001 From: Florian <4150400+gyptazy@users.noreply.github.com> Date: Wed, 12 Jul 2023 22:23:44 +0200 Subject: [PATCH] feature(yum_versionlock): add support to pin specific package versions (#6861) feature(yum_versionlock): add support to pin specific package versions instead of only the package itself --- ...r_change_add-pinning-specific-versions.yml | 2 ++ plugins/modules/yum_versionlock.py | 26 +++++++++++++++---- 2 files changed, 23 insertions(+), 5 deletions(-) create mode 100644 changelogs/fragments/6861-yum_versionlock_minor_change_add-pinning-specific-versions.yml diff --git a/changelogs/fragments/6861-yum_versionlock_minor_change_add-pinning-specific-versions.yml b/changelogs/fragments/6861-yum_versionlock_minor_change_add-pinning-specific-versions.yml new file mode 100644 index 0000000000..0cdd31da5f --- /dev/null +++ b/changelogs/fragments/6861-yum_versionlock_minor_change_add-pinning-specific-versions.yml @@ -0,0 +1,2 @@ +minor_changes: + - yum_versionlock - add support to pin specific package versions instead of only the package itself (https://github.com/ansible-collections/community.general/pull/6861, https://github.com/ansible-collections/community.general/issues/4470). diff --git a/plugins/modules/yum_versionlock.py b/plugins/modules/yum_versionlock.py index fa942a0080..0cbf9be393 100644 --- a/plugins/modules/yum_versionlock.py +++ b/plugins/modules/yum_versionlock.py @@ -1,6 +1,6 @@ #!/usr/bin/python # -*- coding: utf-8 -*- -# Copyright (c) 2018, Florian Paul Azim Hoberg +# Copyright (c) 2018, Florian Paul Azim Hoberg (@gyptazy) # # GNU General Public License v3.0+ (see LICENSES/GPL-3.0-or-later.txt or https://www.gnu.org/licenses/gpl-3.0.txt) # SPDX-License-Identifier: GPL-3.0-or-later @@ -25,7 +25,8 @@ attributes: options: name: description: - - Package name or a list of package names with optional wildcards. + - Package name or a list of package names with optional version or wildcards. + - Specifying versions is supported since community.general 7.2.0. type: list required: true elements: str @@ -50,7 +51,14 @@ EXAMPLES = r''' - name: Prevent Apache / httpd from being updated community.general.yum_versionlock: state: present - name: httpd + name: + - httpd + +- name: Prevent Apache / httpd version 2.4.57-2 from being updated + community.general.yum_versionlock: + state: present + name: + - httpd-0:2.4.57-2.el9 - name: Prevent multiple packages from being updated community.general.yum_versionlock: @@ -111,22 +119,30 @@ class YumVersionLock: def ensure_state(self, packages, command): """ Ensure packages state """ rc, out, err = self.module.run_command([self.yum_bin, "-q", "versionlock", command] + packages) + # If no package can be found this will be written on stdout with rc 0 + if 'No package found for' in out: + self.module.fail_json(msg=out) if rc == 0: return True self.module.fail_json(msg="Error: " + to_native(err) + to_native(out)) def match(entry, name): + match = False m = NEVRA_RE_YUM.match(entry) if not m: m = NEVRA_RE_DNF.match(entry) if not m: return False - return fnmatch(m.group("name"), name) + if fnmatch(m.group("name"), name): + match = True + if entry.rstrip('.*') == name: + match = True + return match def main(): - """ start main program to add/remove a package to yum versionlock""" + """ start main program to add/delete a package to yum versionlock """ module = AnsibleModule( argument_spec=dict( state=dict(default='present', choices=['present', 'absent']),