Skip to content

validate_action reports clean logs when journal retrieval fails #372

Description

@Calmingstorm

Confirmed false-clean health check

Reviewed master at 886c36d8ebe861aa987059a1744d45b78797baae (v4.7.0). Suggested priority: P2.

log_absent reports pass when journal retrieval fails without stdout. The generated command discards journalctl stderr and uses a journalctl | grep | head || true pipeline, losing the distinction between successful retrieval with no match and no evidence retrieved at all.

Source: generated journal commands, empty-output pass.

Isolated reproduction

Prepend a temporary fixture executable named journalctl to the subprocess PATH. It emits fixture journalctl failure only to stderr and exits 73. Run the production-generated log_absent command and evaluate its result:

fixture journalctl exit: 73
generated command exit: 0
output: <empty>
evaluated_status: pass

This was independently reproduced twice. No real journals were accessed. The same masking applies to unit-specific and global forms; log_present reports a miss rather than a retrieval error.

Acceptance criteria

  • Preserve retrieval status separately from grep's legitimate no-match status.
  • Successful retrieval/no match is pass for log_absent; failed retrieval is error/indeterminate, never pass.
  • Retain bounded useful diagnostics, rather than suppressing the failure.
  • Cover both target forms, unavailable journalctl, denied/failed retrieval, valid no-match and valid match.

Behavior change: silent evidence failures become visible failures/errors. Focused existing suite: 79 passed. No source changes were made.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions