mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-10-08 07:15:27 +02:00
_orch_failures assumed every level of a jobs.lookup_jid result was a dict. A list or string at the top level, in return.data, in a step's changes, or in changes.ret raised AttributeError. Because result checks run before the drain and a record is only removed after it is evaluated, one such record would have failed every 15s pass and stopped all pushes until it was removed by hand. Guard each shape, and evaluate each record under its own exception handler so an unreadable result is logged and dropped instead of blocking the drainer. Per-step parsing moves to _step_failures. Search stdout as well as stderr for the async jid, in case salt-run logging is routed to stdout. Close the RotatingFileHandler in test_make_logger_adds_handler_once to avoid a ResourceWarning on Python 3.12+. Verified on a 3.4.0 standalone: real failed and successful orchestration results parse as before, a record whose evaluation raises is logged and removed while the next record still reports, and a replicated SOC change to telegraf.output (and its revert) is pushed, rendered and logged as succeeded.