[Bug 1938043] Re: ubuntu-security-status

Brian Murray 1938043 at bugs.launchpad.net
Wed Sep 8 16:15:47 UTC 2021


** Description changed:

- In 20.04 ubuntu-security-status incorrect reports the status of
- subscription:
+ Impact
+ ------
+ ubuntu-security-status incorrectly reports the status of Ubuntu Advantage subscriptions.
+ 
+ Test Case
+ ---------
+ 1) ua attach <REDACTED_TOKEN>
+ 2) ubuntu-security-status
+ 
+ With the version of the package in the release pocket you'll see output
+ ending with "This machine is not attached to an Ubuntu Advantage
+ subscription"
+ 
+ With the version of the package from -proposed the output will not say
+ you are not attached.
+ 
+ Another test case
+ 1) Run the version of ubuntu-security-status from -proposed on an unattached system
+ 
+ You'll see output with "This machine is not attached to an Ubuntu
+ Advantage subscription"
+ 
+ Where things could go wrong
+ ---------------------------
+ Its possible that ubuntu-security-status could think that a UA subscription is attached when in fact one is not attached so ubuntu-security-status should also be run on an unattached system.
+ 
+ Original Description
+ --------------------
+ In 20.04 ubuntu-security-status incorrect reports the status of subscription:
  
  ```
- $ sudo ubuntu-security-status 
+ $ sudo ubuntu-security-status
  1594 packages installed, of which:
  1588 receive package updates with LTS until 4/2025
-    6 are receiving security updates with ESM Apps until 4/2030
+    6 are receiving security updates with ESM Apps until 4/2030
  
  This machine is not attached to an Ubuntu Advantage subscription.
  See https://ubuntu.com/advantage
  ```
  
  It shows no subscription in the system even though there is. ua status correctly shows the subscription:
  ```
  $ ua status
  SERVICE       ENTITLED  STATUS    DESCRIPTION
  cis           yes       disabled  Center for Internet Security Audit Tools
  esm-apps      yes       enabled   UA Apps: Extended Security Maintenance (ESM)
  esm-infra     yes       enabled   UA Infra: Extended Security Maintenance (ESM)
  fips          yes       disabled  NIST-certified core packages
  fips-updates  yes       disabled  NIST-certified core packages with priority security updates
  livepatch     yes       disabled  Canonical Livepatch service
  
  Enable services with: ua enable <service>
  
-                 Account: Canonical - staff
-            Subscription: UA Applications - Essential (Virtual)
-             Valid until: 3999-12-31 00:00:00
+                 Account: Canonical - staff
+            Subscription: UA Applications - Essential (Virtual)
+             Valid until: 3999-12-31 00:00:00
  Technical support level: essential
  ```

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to update-manager in Ubuntu.
https://bugs.launchpad.net/bugs/1938043

Title:
  ubuntu-security-status

Status in update-manager package in Ubuntu:
  Fix Released
Status in update-manager source package in Focal:
  Triaged

Bug description:
  Impact
  ------
  ubuntu-security-status incorrectly reports the status of Ubuntu Advantage subscriptions.

  Test Case
  ---------
  1) ua attach <REDACTED_TOKEN>
  2) ubuntu-security-status

  With the version of the package in the release pocket you'll see
  output ending with "This machine is not attached to an Ubuntu
  Advantage subscription"

  With the version of the package from -proposed the output will not say
  you are not attached.

  Another test case
  1) Run the version of ubuntu-security-status from -proposed on an unattached system

  You'll see output with "This machine is not attached to an Ubuntu
  Advantage subscription"

  Where things could go wrong
  ---------------------------
  Its possible that ubuntu-security-status could think that a UA subscription is attached when in fact one is not attached so ubuntu-security-status should also be run on an unattached system.

  Original Description
  --------------------
  In 20.04 ubuntu-security-status incorrect reports the status of subscription:

  ```
  $ sudo ubuntu-security-status
  1594 packages installed, of which:
  1588 receive package updates with LTS until 4/2025
     6 are receiving security updates with ESM Apps until 4/2030

  This machine is not attached to an Ubuntu Advantage subscription.
  See https://ubuntu.com/advantage
  ```

  It shows no subscription in the system even though there is. ua status correctly shows the subscription:
  ```
  $ ua status
  SERVICE       ENTITLED  STATUS    DESCRIPTION
  cis           yes       disabled  Center for Internet Security Audit Tools
  esm-apps      yes       enabled   UA Apps: Extended Security Maintenance (ESM)
  esm-infra     yes       enabled   UA Infra: Extended Security Maintenance (ESM)
  fips          yes       disabled  NIST-certified core packages
  fips-updates  yes       disabled  NIST-certified core packages with priority security updates
  livepatch     yes       disabled  Canonical Livepatch service

  Enable services with: ua enable <service>

                  Account: Canonical - staff
             Subscription: UA Applications - Essential (Virtual)
              Valid until: 3999-12-31 00:00:00
  Technical support level: essential
  ```

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/update-manager/+bug/1938043/+subscriptions




More information about the foundations-bugs mailing list