Chapter 10. Managing Errata
As a part of Red Hat’s quality control and release process, we provide customers with updates for each release of official Red Hat RPMs. Red Hat compiles groups of related package into an erratum along with an advisory that provides a description of the update. There are three types of advisories (in order of importance):
- Security Advisory
- Describes fixed security issues found in the package. The security impact of the issue can be Low, Moderate, Important, or Critical.
- Bug Fix Advisory
- Describes bug fixes for the package.
- Product Enhancement Advisory
- Describes enhancements and new features added to the package.
Red Hat Satellite 6 imports this errata information when synchronizing repositories with Red Hat’s Content Delivery Network (CDN). Red Hat Satellite 6 also provides tools to inspect and filter errata, allowing for precise update management. This way, you can select relevant updates and propagate them through Content Views to selected content hosts.
Errata are labeled according to the most important advisory type they contain. Therefore, errata labeled as Product Enhancement Advisory can contain only enhancement updates, while Bug Fix Advisory errata can contain both bug fixes and enhancements, and Security Advisory can contain all three types.
In Red Hat Satellite, there are two keywords that describe an erratum’s relationship to the available content hosts:
- Applicable
- Erratum applies to one or more content hosts, which means it updates packages present on the content host. Applicable errata are not yet accessible by the content host.
- Installable
- Erratum applies to one or more content hosts and it has been made available to the content host. Installable errata are present in the content host’s life cycle environment and Content View, but are not yet installed. This way, errata can be installed by users who have permissions to manage content hosts, but are not entitled for errata management at higher levels.
This chapter shows how to manage errata and apply them to either a single system or multiple systems.
10.1. Inspecting Available Errata
The following procedure describes how to view and filter the available errata and how to display metadata of the selected advisory.
- Navigate to Content > Errata to view the list of available errata.
Use the filtering tools at the top of the page to limit the number of displayed errata:
- Select the repository to be inspected from the list. All Repositories is selected by default.
- The Applicable check box is selected by default to view only errata applicable to the selected repository. Select the Installable check box to view only errata marked as installable.
To search the table of errata, type the query in the Search field in the form of:
parameter operator value
See Table 10.1, “Parameters Available for Errata Search” for the list of parameters available for search. Find the list of applicable operators in Supported Operators for Granular Search in Administering Red Hat Satellite. Automatic suggestion works as you type. You can also combine queries with the use of and and or operators. For example, to display only security advisories related to the kernel package, type:
type = security and package_name = kernel
Press Enter to start the search.
Click the Errata ID of the erratum you want to inspect:
- The Details tab contains the description of the updated package as well as documentation of important fixes and enhancements provided by the update.
- On the Content Hosts tab, you can apply the erratum to selected content hosts as described in Section 10.5, “Applying Errata to Multiple Systems”.
- The Repositories tab lists repositories that already contain the erratum. You can filter repositories by the environment and Content View, and search for them by the repository name.
Parameter | Description | Example |
---|---|---|
bug | Search by the Bugzilla number. | bug = 1172165 |
cve | Search by the CVE number. | cve = CVE-2015-0235 |
id | Search by the errata ID. The auto-suggest system displays a list of available IDs as you type. | id = RHBA-2014:2004 |
issued | Search by the issue date. You can specify the exact date, like "Feb16,2015", or use keywords, for example "Yesterday", or "1 hour ago". The time range can be specified with the use of the "<" and ">" operators. | issued < "Jan 12,2015" |
package | Search by the full package build name. The auto-suggest system displays a list of available packages as you type. | package = glib2-2.22.5-6.el6.i686 |
package_name | Search by the package name. The auto-suggest system displays a list of available packages as you type. | package_name = glib2 |
severity | Search by the severity of the issue fixed by the security update. Specify Critical, Important, or Moderate. | severity = Critical |
title | Search by the advisory title. | title ~ openssl |
type | Search by the advisory type. Specify security, bugfix, or enhancement. | type = bugfix |
updated |
Search by the date of the last update. You can use the same formats as with the | updated = "6 days ago" |
10.2. Subscribing to Errata Notifications
You can configure email notifications for Satellite users. Users receive a summary of applicable and installable errata, notifications on Content View promotion or after synchronizing a repository. For more information, see the Configuring Email Notifications section in the Administering Red Hat Satellite guide.
10.3. Managing Errata with Content Views
Red Hat Satellite 6 provides various methods to manage and apply errata. You can use Content Views and content filters to limit errata. Such filters include:
- ID - Select specific erratum to allow into your resulting repositories.
- Date Range - Define a date range and include a set of errata released during that date range.
- Type - Select the type of errata to include such as bug fixes, enhancements, and security updates.
10.3.1. Creating a Content View Filter for Errata
Create a content filter to exclude errata after a certain date. This ensures your production systems in the application life cycle are kept up to date to a certain point. Then you can modify the filter’s start date to introduce new errata into your testing environment to test the compatibility of new packages into your application life cycle.
Prerequisites
- A Content View with the repositories that contain required errata is created. For more information, see Section 8.1, “Creating a Content View”.
Procedure
- In the Satellite web UI, navigate to Content > Content Views and select a Content View that you want to use for applying errata.
- Navigate to Yum Content > Filters and click New Filter.
-
In the Name field, enter
Errata Filter
. - From the Content Type list, select Erratum - Date and Type.
- From the Inclusion Type list, select Exclude.
-
In the Description field, enter
Exclude errata items from YYYY-MM-DD
. - Click Save.
- For Errata Type, select the check boxes of errata types you want to exclude. For example, select the Enhancement and Bugfix check boxes and clear the Security check box to exclude enhancement and bugfix errata after certain date, but include all the security errata.
For Date Type, select one of two check boxes:
- Issued On for the issued date of the erratum.
- Updated On for the date of the erratum’s last update.
- Select the Start Date to exclude all errata on or after the selected date.
- Leave the End Date field blank.
- Click Save.
- Click Publish New Version to publish the resulting repository.
-
Enter
Adding errata filter
in the Description field. Click Save.
When the Content View completes publication, notice the Content column reports a reduced number of packages and errata from the initial repository. This means the filter successfully excluded the all non-security errata from the last year.
- Click the Versions tab.
- Click Promote to the right of the published version.
- Select the environments you want to promote the Content View version to.
- In the Description field, enter the description for promoting.
- Click Promote Version to promote this Content View version across the required environments.
For CLI Users
Create a filter for the errata:
# hammer content-view filter create --name "Filter Name" \ --description "Exclude errata items from the YYYY-MM-DD" \ --content-view "CV Name" --organization "Default Organization" \ --type "erratum"
Create a filter rule to exclude all errata on or after the Start Date that you want to set:
# hammer content-view filter rule create --start-date "YYYY-MM-DD" \ --content-view "CV Name" --content-view-filter="Filter Name" \ --organization "Default Organization" --types=security,enhancement,bugfix
Publish the Content View:
# hammer content-view publish --name "CV Name" \ --organization "Default Organization"
Promote the Content View to the lifecycle environment so that the included errata are available to that lifecycle environment:
# hammer content-view version promote \ --content-view "CV Name" \ --organization "Default Organization" \ --to-lifecycle-environment "Lifecycle Environment Name"
10.4. Applying Errata to Individual Systems
Use these procedures to review and apply errata to individual systems.
Prerequisites
- Synchronize Red Hat Satellite repositories with the latest errata available from Red Hat. For more information, see Section 5.6, “Synchronizing Red Hat Repositories”.
- Register the host to an environment and Content View on Satellite Server. For more information, see Registering a Host in the Managing Hosts guide.
-
Install the
katello-agent
package on the host. For more information, see the Installing the Katello Agent section in the Managing Hosts guide.
Procedure
- In the Satellite web UI, navigate to Hosts > Content Hosts and select the host you want to apply errata to.
- Navigate to the Errata tab to see the list of errata.
- Select the errata to apply and click Apply Selected. In the confirmation window, click Apply.
- After the task to update all packages associated with the selected errata completes, click the Details tab to view the updated packages.
For CLI Users
List all errata for the host:
# hammer host errata list \ --host client.example.com
Apply the most recent erratum to the host. Identify the erratum to apply using the erratum ID:
# hammer host errata apply --host "Host Name" \ --errata-ids ERRATUM_ID1,ERRATUM_ID2...
10.5. Applying Errata to Multiple Systems
Use these procedures to review and apply errata to multiple systems.
Prerequisites
- Synchronize Red Hat Satellite repositories with the latest errata available from Red Hat. For more information, see Section 5.6, “Synchronizing Red Hat Repositories”.
- Register the hosts to an environment and Content View on Satellite Server. For more information, see Registering a Host in the Managing Hosts guide.
-
Install the
katello-agent
package on hosts. For more information, see the Installing the Katello Agent section in the Managing Hosts guide.
Procedure
- Navigate to Content > Errata.
- Click the name of an erratum you want to apply.
- Click to Content Hosts tab.
- Select the systems you want to apply errata to and click Apply to Hosts.
- Click Confirm.
For CLI Users
Although the CLI does not have the same tools as the Web UI, you can replicate a similar procedure with CLI commands.
List all installable errata:
# hammer erratum list \ --errata-restrict-installable true \ --organization "Default Organization"
Select the erratum you want to use and list the systems that this erratum is applicable to:
# hammer host list \ --search "applicable_errata = ERRATUM_ID" \ --organization "Default Organization"
Apply the errata to a single system:
# hammer host errata apply \ --host client.example.com \ --organization "Default Organization" \ --errata-ids ERRATUM_ID1,ERRATUM_ID2...
Enter the following command for each host and replace
$HOST
with the name of the system for each execution.# for HOST in `hammer \ --csv --csv-separator "|" host list \ --search "applicable_errata = ERRATUM_ID" \ --organization "Default Organization" | tail -n+2 | awk \ -F "|" '{ print $2 }'` ; do echo \ "== Applying to $HOST ==" ; hammer host errata apply \ --host $HOST --errata-ids ERRATUM_ID1,ERRATUM_ID2 ; done
This command identifies all hosts with erratum_IDs as an applicable erratum and then applies the erratum to each host.