mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-08-27 01:48:22 +02:00
The UEK8 rollout installs the new kernel and flips the boot default, but leaves the stock EL9 (RHCK) packages behind: disk in /boot and a stale GRUB entry on every upgraded node. They cannot be removed in the same pass that installs UEK8. dnf's protect_running_kernel refuses to erase the booted kernel-core, so the removal has to wait until the node has rebooted onto 6.x. Waiting is the safer sequencing anyway -- the node proves it comes up on UEK8 before its fallback is deleted -- so this does not remove RHCK from the uek7 branch either, where dnf would allow it. so-kernel-upgrade grows a --cleanup mode that does only the removal and no-ops (exit 0, with a log line) on a node not yet running UEK8. Its uek8 branch, which previously reported "nothing to do", now runs that cleanup along with set_default_kernel_conf -- which also closes a gap where a node that came up on UEK8 straight from a fresh install never had DEFAULTKERNEL=kernel-uek-core written. The common highstate calls --cleanup gated on the running kernel, so the cleanup lands grid-wide as each node reboots: fresh installs reboot at the end of setup, upgraded nodes whenever the admin schedules it. The rpm check inside the script is the idempotency guard, so subsequent highstates cost an rpm query rather than a dnf transaction, and the package list is not duplicated into the state where it could drift.