fix(monitor): clarify Lynis removal outcomes and threshold guidance

This commit is contained in:
martino
2026-09-29 00:42:44 +02:00
parent 72f77069ca
commit d27012806b
15 changed files with 485 additions and 75 deletions
+5 -5
View File
@@ -388,9 +388,9 @@ def lynis_report_delete():
"""Delete Lynis audit report files"""
if not security_manager:
return jsonify({"success": False, "message": "Security manager not available"}), 500
deleted = []
try:
import os
deleted = []
for f in ["/var/log/lynis-report.dat", "/var/log/lynis.log", "/var/log/lynis-output.log"]:
if os.path.isfile(f):
os.remove(f)
@@ -398,9 +398,9 @@ def lynis_report_delete():
if deleted:
return jsonify({"success": True, "message": f"Deleted: {', '.join(deleted)}"})
else:
return jsonify({"success": False, "message": "No report files found to delete"})
return jsonify({"success": False, "outcome": "no_files", "message": "No report files found to delete"})
except Exception as e:
return jsonify({"success": False, "message": str(e)}), 500
return jsonify({"success": False, "partial": bool(deleted), "message": str(e)}), 500
# -------------------------------------------------------------------
@@ -427,8 +427,8 @@ def lynis_uninstall():
if not security_manager:
return jsonify({"success": False, "message": "Security manager not available"}), 500
try:
success, message = security_manager.uninstall_lynis()
return jsonify({"success": success, "message": message})
success, message, partial, outcome = security_manager.uninstall_lynis()
return jsonify({"success": success, "message": message, "partial": partial, "outcome": outcome})
except Exception as e:
return jsonify({"success": False, "message": str(e)}), 500
+10 -3
View File
@@ -2577,18 +2577,21 @@ def uninstall_fail2ban():
def uninstall_lynis():
"""
Uninstall Lynis and clean up all files.
Returns (success, message).
Returns (success, message, partial, outcome). Partial records completed removals only.
"""
removed = []
try:
import shutil
# Remove installation directory
if os.path.exists("/opt/lynis"):
shutil.rmtree("/opt/lynis")
removed.append("/opt/lynis")
# Remove wrapper script
if os.path.exists("/usr/local/bin/lynis"):
os.remove("/usr/local/bin/lynis")
removed.append("/usr/local/bin/lynis")
# Remove report files
for report_file in [
@@ -2598,6 +2601,7 @@ def uninstall_lynis():
]:
if os.path.exists(report_file):
os.remove(report_file)
removed.append(report_file)
# Update component status
base_dir = "/usr/local/share/proxmenux"
@@ -2615,6 +2619,9 @@ def uninstall_lynis():
except Exception:
pass
return True, "Lynis has been uninstalled successfully"
if not removed:
return False, "No Lynis files found to remove", False, "no_files"
return True, "Lynis has been uninstalled successfully", False, "removed"
except Exception as e:
return False, f"Error uninstalling Lynis: {str(e)}"
return False, f"Error uninstalling Lynis: {str(e)}", bool(removed), "failed"