rhel8-playbook-stig.yml and rhel9-playbook-stig.yml using stale ansible_facts
msakhwand opened this issue · comments
Share the context
The ansible_facts.mounts used on in the task "Ensure non-root local partitions are mounted with nodev option" is using a stale copy of ansible_facts and As this overwrites the changes made in the previous taks to add noexec and nosuid to the mount options.
Description of problem:
This is only impacts if both nodev and nosuid/noexec are missing. this i not an issue if any one of them is present
Proposed change:
A new call to builtin.setup should be made before the task "Ensure non-root local partitions are mounted with nodev option"
References:
- rhel8-playbook-stig.yml
- rhel9-playbook-stig.yml