[WARNING]: Collection infra.leapp does not support Ansible version 2.14.18 [WARNING]: running playbook inside collection infra.leapp ansible-playbook [core 2.14.18] config file = /etc/ansible/ansible.cfg configured module search path = ['/root/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules'] ansible python module location = /usr/lib/python3.9/site-packages/ansible ansible collection location = /root/.ansible/collections:/usr/share/ansible/collections executable location = /usr/bin/ansible-playbook python version = 3.9.25 (main, Nov 10 2025, 00:00:00) [GCC 11.5.0 20240719 (Red Hat 11.5.0-11)] (/usr/bin/python3) jinja version = 3.1.2 libyaml = True Using /etc/ansible/ansible.cfg as config file Skipping callback 'default', as we already have a stdout callback. Skipping callback 'minimal', as we already have a stdout callback. Skipping callback 'oneline', as we already have a stdout callback. PLAYBOOK: tests_remediations_8to9.yml ****************************************** 1 plays in /root/.ansible/collections/ansible_collections/infra/leapp/tests/tests_remediations_8to9.yml PLAY [Test RHEL 8 to 9 remediations] ******************************************* TASK [Gathering Facts] ********************************************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tests_remediations_8to9.yml:2 ok: [managed-node02] TASK [Include tests_upgrade_custom playbook] *********************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tests_remediations_8to9.yml:22 included: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/tests_upgrade_custom.yml for managed-node02 TASK [tests_upgrade_custom | Check if leapp upgrade log exists] **************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/tests_upgrade_custom.yml:12 ok: [managed-node02] => {"changed": false, "stat": {"exists": false}} TASK [tests_upgrade_custom | Skip test if already upgraded or not RHEL {{ rhel_base_ver }}] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/tests_upgrade_custom.yml:17 META: end_play conditional evaluated to False, continuing play skipping: [managed-node02] => {"msg": "end_play", "skip_reason": "end_play conditional evaluated to False, continuing play"} TASK [tests_upgrade_custom | Include common upgrade tasks] ********************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/tests_upgrade_custom.yml:27 included: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml for managed-node02 TASK [common_upgrade_tasks | Remove leapp packages] **************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:6 ok: [managed-node02] => {"changed": false, "msg": "Nothing to do", "rc": 0, "results": []} TASK [common_upgrade_tasks | Gather setup tasks] ******************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:11 ok: [managed-node02 -> localhost] => {"changed": false, "examined": 3, "files": [{"atime": 1768225904.3955438, "ctime": 1768225904.093543, "dev": 51716, "gid": 0, "gr_name": "root", "inode": 176160909, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mode": "0644", "mtime": 1768225904.093543, "nlink": 1, "path": "/root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/remediate_cifs.yml", "pw_name": "root", "rgrp": true, "roth": true, "rusr": true, "size": 272, "uid": 0, "wgrp": false, "woth": false, "wusr": true, "xgrp": false, "xoth": false, "xusr": false}, {"atime": 1768225904.3955438, "ctime": 1768225904.093543, "dev": 51716, "gid": 0, "gr_name": "root", "inode": 176160910, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mode": "0644", "mtime": 1768225904.093543, "nlink": 1, "path": "/root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/remediate_removed_kernel_drivers.yml", "pw_name": "root", "rgrp": true, "roth": true, "rusr": true, "size": 913, "uid": 0, "wgrp": false, "woth": false, "wusr": true, "xgrp": false, "xoth": false, "xusr": false}, {"atime": 1768225904.3955438, "ctime": 1768225904.093543, "dev": 51716, "gid": 0, "gr_name": "root", "inode": 176160911, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mode": "0644", "mtime": 1768225904.093543, "nlink": 1, "path": "/root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/version_lock.yml", "pw_name": "root", "rgrp": true, "roth": true, "rusr": true, "size": 539, "uid": 0, "wgrp": false, "woth": false, "wusr": true, "xgrp": false, "xoth": false, "xusr": false}], "matched": 3, "msg": "All paths examined", "skipped_paths": {}} TASK [common_upgrade_tasks | Do remediation setup tasks] *********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:18 included: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/remediate_cifs.yml for managed-node02 => (item=/root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/remediate_cifs.yml) included: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/remediate_removed_kernel_drivers.yml for managed-node02 => (item=/root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/remediate_removed_kernel_drivers.yml) TASK [setup | remediate_cifs | Add a CIFS share to /etc/fstab] ***************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/remediate_cifs.yml:3 changed: [managed-node02] => {"backup": "", "changed": true, "msg": "line added"} TASK [setup | remediate_removed_kernel_drivers | Set list of test kernel modules] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/remediate_removed_kernel_drivers.yml:4 ok: [managed-node02] => {"ansible_facts": {"leapp_test_kernel_modules": ["dnet", "dlci", "liquidio"]}, "changed": false} TASK [setup | remediate_removed_kernel_drivers | Load the test kernel modules] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/remediate_removed_kernel_drivers.yml:21 TASK [infra.leapp.common : manage_kernel_modules | Load or unload kernel modules] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_kernel_modules.yml:5 [WARNING]: Collection community.general does not support Ansible version 2.14.18 included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml for managed-node02 => (item=dnet) included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml for managed-node02 => (item=dlci) included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml for managed-node02 => (item=liquidio) TASK [infra.leapp.common : manage_one_kernel_module | Load or unload kernel module] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:5 changed: [managed-node02] => {"changed": true, "name": "dnet", "params": "", "state": "present"} TASK [infra.leapp.common : manage_one_kernel_module | Disable modules-load.d file entry] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:17 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : manage_one_kernel_module | Ensure modules are not loaded at boot] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:25 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : manage_one_kernel_module | Debug modprobe.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:33 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : manage_one_kernel_module | Debug modules-load.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:37 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : manage_one_kernel_module | Load or unload kernel module] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:5 changed: [managed-node02] => {"changed": true, "name": "dlci", "params": "", "state": "present"} TASK [infra.leapp.common : manage_one_kernel_module | Disable modules-load.d file entry] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:17 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : manage_one_kernel_module | Ensure modules are not loaded at boot] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:25 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : manage_one_kernel_module | Debug modprobe.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:33 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : manage_one_kernel_module | Debug modules-load.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:37 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : manage_one_kernel_module | Load or unload kernel module] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:5 changed: [managed-node02] => {"changed": true, "name": "liquidio", "params": "", "state": "present"} TASK [infra.leapp.common : manage_one_kernel_module | Disable modules-load.d file entry] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:17 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : manage_one_kernel_module | Ensure modules are not loaded at boot] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:25 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : manage_one_kernel_module | Debug modprobe.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:33 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : manage_one_kernel_module | Debug modules-load.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:37 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [common_upgrade_tasks | Do setup tasks] *********************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:29 skipping: [managed-node02] => (item=/root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/version_lock.yml) => {"ansible_loop_var": "setup_task_file", "changed": false, "setup_task_file": "/root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/setup/version_lock.yml", "skip_reason": "Conditional result was False"} skipping: [managed-node02] => {"changed": false, "msg": "All items skipped"} TASK [common_upgrade_tasks | Run first analysis] ******************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:40 TASK [infra.leapp.common : Log directory exists] ******************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:3 changed: [managed-node02] => {"changed": true, "gid": 0, "group": "root", "mode": "0755", "owner": "root", "path": "/var/log/ripu", "secontext": "unconfined_u:object_r:var_log_t:s0", "size": 6, "state": "directory", "uid": 0} TASK [infra.leapp.common : Check for existing log file] ************************ task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:11 ok: [managed-node02] => {"changed": false, "stat": {"exists": false}} TASK [infra.leapp.common : Fail if log file already exists] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:16 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : Create new log file] ******************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:23 NOTIFIED HANDLER infra.leapp.common : Check for log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Add end time to log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Slurp ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Decode ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Rename log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Check for log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Add end time to log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Slurp ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Decode ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Rename log file for managed-node02 changed: [managed-node02] => {"changed": true, "checksum": "194649036d4d3cf1a35d93e541236cb877d8ffa7", "dest": "/var/log/ripu/ripu.log", "gid": 0, "group": "root", "md5sum": "1c3fea0df3be1156e899b4d6b779a03d", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:var_log_t:s0", "size": 61, "src": "/root/.ansible/tmp/ansible-tmp-1768226060.4734006-7822-96807374030081/source", "state": "file", "uid": 0} TASK [infra.leapp.common : /etc/ansible/facts.d directory exists] ************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:35 changed: [managed-node02] => {"changed": true, "gid": 0, "group": "root", "mode": "0755", "owner": "root", "path": "/etc/ansible/facts.d", "secontext": "unconfined_u:object_r:etc_t:s0", "size": 6, "state": "directory", "uid": 0} TASK [infra.leapp.common : Capture current ansible_facts for validation after upgrade] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:43 changed: [managed-node02] => {"changed": true, "checksum": "5f0e3c7532a33a73dc44e3a72d57ba74a88b1ec2", "dest": "/etc/ansible/facts.d/pre_ripu.fact", "gid": 0, "group": "root", "md5sum": "b1e03e567db09cdbf77734f0ce09e3c8", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:etc_t:s0", "size": 13829, "src": "/root/.ansible/tmp/ansible-tmp-1768226061.5982132-7861-158990949952137/source", "state": "file", "uid": 0} TASK [infra.leapp.common : Capture a list of non-rhel versioned packages] ****** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:51 ok: [managed-node02] => {"changed": false, "cmd": "set -o pipefail; export PATH=$PATH; rpm -qa | grep -ve '[\\.|+]el8' | grep -vE '^(gpg-pubkey|libmodulemd|katello-ca-consumer)' | sort", "delta": "0:00:00.848443", "end": "2026-01-12 08:54:23.424253", "failed_when_result": false, "msg": "non-zero return code", "rc": 1, "start": "2026-01-12 08:54:22.575810", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} TASK [infra.leapp.common : Create fact with the non-rhel versioned packages list] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:65 ok: [managed-node02] => {"ansible_facts": {"non_rhel_packages": []}, "changed": false} TASK [infra.leapp.common : Capture the list of non-rhel versioned packages in a separate fact file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:69 changed: [managed-node02] => {"changed": true, "checksum": "97d170e1550eee4afc0af065b78cda302a97674c", "dest": "/etc/ansible/facts.d/non_rhel_packages.fact", "gid": 0, "group": "root", "md5sum": "d751713988987e9331980363e24189ce", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:etc_t:s0", "size": 2, "src": "/root/.ansible/tmp/ansible-tmp-1768226063.5743058-7908-192186950350565/source", "state": "file", "uid": 0} TASK [infra.leapp.analysis : Include tasks for preupg assistant analysis] ****** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/main.yml:9 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.analysis : Include tasks for leapp preupgrade analysis] ****** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/main.yml:13 included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml for managed-node02 TASK [infra.leapp.analysis : analysis-leapp | Register to leapp activation key] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:2 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [analysis-leapp | Include custom_local_repos for local_repos_pre_leapp] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:14 TASK [infra.leapp.common : custom_local_repos | Remove old /etc/leapp/files/leapp_upgrade_repositories.repo] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:2 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : custom_local_repos | Enable custom upgrade yum repositories] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:9 skipping: [managed-node02] => {"changed": false, "skipped_reason": "No items in the list"} TASK [infra.leapp.analysis : analysis-leapp | Install packages for preupgrade analysis on RHEL 7] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:22 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.analysis : analysis-leapp | Install packages for preupgrade analysis on RHEL 8] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:29 changed: [managed-node02] => {"changed": true, "msg": "", "rc": 0, "results": ["Installed: policycoreutils-python-utils-2.9-26.el8_10.noarch", "Installed: leapp-0.20.0-1.el8_10.noarch", "Installed: leapp-deps-0.20.0-1.el8_10.noarch", "Installed: leapp-upgrade-el8toel9-0.23.0-1.el8_10.noarch", "Installed: leapp-upgrade-el8toel9-deps-0.23.0-1.el8_10.noarch", "Installed: systemd-container-239-82.el8_10.13.x86_64", "Installed: python3-leapp-0.20.0-1.el8_10.noarch"]} TASK [infra.leapp.analysis : analysis-leapp | Install packages for preupgrade analysis on RHEL 9] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:36 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.analysis : analysis-leapp | Ensure leapp log directory exists] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:43 ok: [managed-node02] => {"changed": false, "gid": 0, "group": "root", "mode": "0700", "owner": "root", "path": "/var/log/leapp", "secontext": "system_u:object_r:var_log_t:s0", "size": 6, "state": "directory", "uid": 0} TASK [infra.leapp.analysis : analysis-leapp | Populate leapp_answers file] ***** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:51 changed: [managed-node02] => {"changed": true, "checksum": "3d934ad808576e3a7fb4c14a89645a4ad55ccf53", "dest": "/var/log/leapp/answerfile", "gid": 0, "group": "root", "md5sum": "01e375235c8e4cafdec593b260354063", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:var_log_t:s0", "size": 48, "src": "/root/.ansible/tmp/ansible-tmp-1768226071.7562447-8098-130972061143669/source", "state": "file", "uid": 0} TASK [analysis-leapp | Create /etc/leapp/files/leapp_upgrade_repositories.repo] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:60 TASK [infra.leapp.common : custom_local_repos | Remove old /etc/leapp/files/leapp_upgrade_repositories.repo] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:2 ok: [managed-node02] => {"changed": false, "path": "/etc/leapp/files/leapp_upgrade_repositories.repo", "state": "absent"} TASK [infra.leapp.common : custom_local_repos | Enable custom upgrade yum repositories] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:9 changed: [managed-node02] => (item={'name': 'rhel-9-for-x86_64-baseos-rpms', 'description': 'BaseOS for x86_64', 'baseurl': '__RHEL_9_6_BASEOS_REPO_URL__', 'state': 'present'}) => {"ansible_loop_var": "item", "changed": true, "item": {"baseurl": "__RHEL_9_6_BASEOS_REPO_URL__", "description": "BaseOS for x86_64", "name": "rhel-9-for-x86_64-baseos-rpms", "state": "present"}, "repo": "rhel-9-for-x86_64-baseos-rpms", "state": "present"} changed: [managed-node02] => (item={'name': 'rhel-9-for-x86_64-appstream-rpms', 'description': 'AppStream for x86_64', 'baseurl': '__RHEL_9_6_APPSTREAM_REPO_URL__', 'state': 'present'}) => {"ansible_loop_var": "item", "changed": true, "item": {"baseurl": "__RHEL_9_6_APPSTREAM_REPO_URL__", "description": "AppStream for x86_64", "name": "rhel-9-for-x86_64-appstream-rpms", "state": "present"}, "repo": "rhel-9-for-x86_64-appstream-rpms", "state": "present"} TASK [infra.leapp.analysis : analysis-leapp | Leapp preupgrade report] ********* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:71 ASYNC FAILED on managed-node02: jid=j97981528317.7697 changed: [managed-node02] => {"ansible_job_id": "j97981528317.7697", "changed": true, "cmd": "set -o pipefail; export PATH=$PATH; ulimit -n 16384; leapp preupgrade --report-schema=1.2.0 --no-rhsm 2>&1 | tee -a /var/log/ripu/ripu.log\n", "delta": "0:00:38.681443", "end": "2026-01-12 08:55:13.038763", "failed_when_result": false, "finished": 1, "msg": "non-zero return code", "rc": 1, "results_file": "/root/.ansible_async/j97981528317.7697", "start": "2026-01-12 08:54:34.357320", "started": 1, "stderr": "", "stderr_lines": [], "stdout": "\n============================================================\n UNSUPPORTED UPGRADE \n============================================================\n\nVariable LEAPP_UNSUPPORTED has been detected. Proceeding at your own risk.\nDevelopment variables have been detected:\n- LEAPP_DEVEL_RPMS_ALL_SIGNED=1\n\n============================================================\n UNSUPPORTED UPGRADE \n============================================================\n\n==> Processing phase `configuration_phase`\n====> * ipu_workflow_config\n IPU workflow config actor\n==> Processing phase `FactsCollection`\n====> * scan_kernel_cmdline\n Scan the kernel command line of the booted system.\n====> * network_manager_read_config\n Provides data about NetworkManager configuration.\n====> * scan_files_for_target_userspace\n Scan the source system and identify files that will be copied into the target userspace when it is created.\n====> * udevadm_info\n Produces data exported by the \"udevadm info\" command.\n====> * check_custom_network_scripts\n Check the existence of custom network-scripts and warn user about possible\n====> * scan_grub_config\n Scan grub configuration files for errors.\n====> * scan_systemd_source\n Provides info about systemd on the source system\n====> * persistentnetnames\n Get network interface information for physical ethernet interfaces of the original system.\n====> * scan_source_files\n Scan files (explicitly specified) of the source system.\n====> * network_manager_connection_scanner\n Scan NetworkManager connection keyfiles\n====> * biosdevname\n Enable biosdevname on the target RHEL system if all interfaces on the source RHEL\n====> * scan_pkg_manager\n Provides data about package manager (yum/dnf)\n====> * scanblacklistca\n Scan the file system for distrusted CA's in the blacklist directory.\n====> * register_ruby_irb_adjustment\n Register a workaround to allow rubygem-irb's directory -> symlink conversion.\n====> * scandasd\n In case of s390x architecture, check whether DASD is used.\n====> * repository_mapping\n Produces message containing repository mapping based on provided file.\n====> * scan_subscription_manager_info\n Scans the current system for subscription manager information\n====> * load_device_driver_deprecation_data\n Loads deprecation data for drivers and devices (PCI & CPU)\n====> * open_ssl_config_scanner\n Read an OpenSSL configuration file for further analysis.\n====> * scan_grub_device_name\n Find the name of the block devices where GRUB is located\n====> * transaction_workarounds\n Provides additional RPM transaction tasks based on bundled RPM packages.\n====> * sssd_facts_8to9\n Check SSSD configuration for changes in RHEL9 and report them in model.\n====> * read_openssh_config\n Collect information about the OpenSSH configuration.\n====> * scanzfcp\n In case of s390x architecture, check whether ZFCP is used.\n====> * scan_custom_repofile\n Scan the custom /etc/leapp/files/leapp_upgrade_repositories.repo repo file.\n====> * persistentnetnamesdisable\n Disable systemd-udevd persistent network naming on machine with single eth0 NIC\n====> * scan_target_os_image\n Scans the provided target OS ISO image to use as a content source for the IPU, if any.\n====> * roce_scanner\n Detect active RoCE NICs on IBM Z machines.\n====> * ifcfg_scanner\n Scan ifcfg files with legacy network configuration\n====> * root_scanner\n Scan the system root directory and produce a message containing\n====> * storage_scanner\n Provides data about storage settings.\n====> * scanmemory\n Scan Memory of the machine.\n====> * firewalld_collect_used_object_names\n This actor reads firewalld's configuration and produces Model\n====> * scanclienablerepo\n Produce CustomTargetRepository based on the LEAPP_ENABLE_REPOS in config.\n====> * scancryptopolicies\n Scan information about system wide set crypto policies including:\n====> * xorgdrvfacts8to9\n Check the journal logs for deprecated Xorg drivers.\n====> * system_facts\n Provides data about many facts from system.\n====> * scan_source_boot_entry\n Scan the default boot entry of the source system.\n====> * pci_devices_scanner\n Provides data about existing PCI Devices.\n====> * get_enabled_modules\n Provides data about which module streams are enabled on the source system.\n====> * repositories_blacklist\n Exclude target repositories provided by Red Hat without support.\n====> * scan_default_initramfs\n Scan details of the default boot entry's initramfs image.\n====> * copy_dnf_conf_into_target_userspace\n Copy dnf.conf into target userspace\n====> * nis_scanner\n Collect information about the NIS packages configuration.\n====> * scan_sap_hana\n Gathers information related to SAP HANA instances on the system.\n====> * firewalld_collect_global_config\n This actor reads firewalld's configuration and produces Model\n====> * scan_custom_modifications_actor\n Collects information about files in leapp directories that have been modified or newly added.\n====> * rpm_scanner\n Provides data about installed RPM Packages.\n====> * scan_fips\n Determine whether the source system has FIPS enabled.\n====> * luks_scanner\n Provides data about active LUKS devices.\n====> * scancpu\n Scan CPUs of the machine.\n====> * get_installed_desktops\n Actor checks if kde or gnome desktop environments\n====> * remove_obsolete_gpg_keys\n Remove obsoleted RPM GPG keys.\n====> * selinuxcontentscanner\n Scan the system for any SELinux customizations\n====> * xfs_info_scanner\n This actor scans all mounted mountpoints for XFS information.\n====> * detect_kernel_drivers\n Matches all currently loaded kernel drivers against known deprecated and removed drivers.\n====> * distribution_signed_rpm_scanner\n Provide data about distribution signed & third-party RPM packages.\n====> * vdo_conversion_scanner\n Provides conversion info about VDO devices.\n====> * scan_hybrid_image_azure\n Check if the system is using Azure hybrid image.\n====> * trusted_gpg_keys_scanner\n Scan for trusted GPG keys.\n====> * checkrhui\n Check if system is using RHUI infrastructure (on public cloud) and send messages to\n====> * used_repository_scanner\n Scan used enabled repositories\n====> * scan_source_kernel\n Scan the source system kernel.\n====> * scan_dynamic_linker_configuration\n Scan the dynamic linker configuration and find modifications.\n====> * multipath_conf_read_8to9\n Read multipath configuration files and extract the necessary information\n====> * ipa_scanner\n Scan system for ipa-client and ipa-server status\n====> * rpm_transaction_config_tasks_collector\n Provides additional RPM transaction tasks from /etc/leapp/transaction.\n====> * satellite_upgrade_facts\n Report which Satellite packages require updates and how to handle PostgreSQL data\n====> * satellite_upgrade_services\n Reconfigure Satellite services\n====> * pes_events_scanner\n Provides data about package events from Package Evolution Service.\n====> * setuptargetrepos\n Produces list of repositories that should be available to be used during IPU process.\n==> Processing phase `Checks`\n====> * unsupported_upgrade_check\n Checks environment variables and produces a warning report if the upgrade is unsupported.\n====> * checkmemory\n The actor check the size of RAM against RHEL8 minimal hardware requirements\n====> * mysql_check\n Actor checking for presence of MySQL installation.\n====> * bacula_check\n Actor checking for presence of Bacula installation.\n====> * check_os_release\n Check if the current RHEL minor version is supported. If not, inhibit the upgrade process.\n====> * check_nvidia_proprietary_driver\n Check if NVIDIA proprietary driver is in use. If yes, inhibit the upgrade process.\n====> * check_deprecated_rpm_signature\n Check whether any packages signed by RSA/SHA1 are installed\n====> * emit_net_naming_scheme\n Emit necessary modifications of the upgrade environment and target command line to use net.naming-scheme.\n====> * cephvolumescan\n Retrieves the list of encrypted Ceph OSD\n====> * dotnet_unsupported_versions_check\n Check for installed .NET versions that are no longer supported.\n====> * check_installed_kernels\n Inhibit IPU (in-place upgrade) when installed kernels conflict with a safe upgrade.\n====> * checkblacklistca\n No documentation has been provided for the checkblacklistca actor.\n====> * check_insights_auto_register\n Checks if system can be automatically registered into Red Hat Insights\n====> * firewalld_check_allow_zone_drifting\n This actor will check if AllowZoneDrifting=yes in firewalld.conf. This\n====> * check_target_iso\n Check that the provided target ISO is a valid ISO image and is located on a persistent partition.\n====> * mariadb_check\n Actor checking for presence of MariaDB installation.\n====> * roce_check\n Check whether RoCE is used on the system and well configured for the upgrade.\n====> * check_boot_avail_space\n Check if at least 100Mib of available space on /boot. If not, inhibit the upgrade process.\n====> * check_fstab_mount_order\n Checks order of entries in /etc/fstab based on their mount point and inhibits upgrade if overshadowing is detected.\n====> * check_valid_grubcfg_hybrid\n Check potential for boot failures in Azure Gen1 VMs due to invalid grubcfg\n====> * check_consumed_assets\n Check whether Leapp is using correct data assets.\n====> * open_ssh_subsystem_sftp\n The RHEL9 changes the SCP to use SFTP protocol internally. The both RHEL8 and RHEL9\n====> * check_bls_grub_onppc64\n Check whether GRUB config is BLS aware on RHEL 8 ppc64le systems\n====> * check_custom_modifications_actor\n Checks CustomModifications messages and produces a report about files in leapp directories that have been\n====> * check_kpatch\n Carry over kpatch-dnf and it's config into the container\n====> * check_detected_devices_and_drivers\n Checks whether or not detected devices and drivers are usable on the target system.\n====> * check_openssl_conf\n Check whether the openssl configuration and openssl-IBMCA.\n====> * check_dynamic_linker_configuration\n Check for customization of dynamic linker configuration.\n====> * check_etc_releasever\n Check releasever info and provide a guidance based on the facts\n====> * openssh_permit_root_login\n OpenSSH no longer allows root logins with password.\n====> * check_fips\n Inhibit upgrade if FIPS is detected as enabled.\n====> * check_rhsmsku\n Ensure the system is subscribed to the subscription manager\n====> * check_sap_hana\n If SAP HANA has been detected, several checks are performed to ensure a successful upgrade.\n====> * checktargetrepos\n Check whether target yum repositories are specified.\n====> * check_grub_core\n Check whether we are on legacy (BIOS) system and instruct Leapp to upgrade GRUB core\n====> * postgresql_check\n Actor checking for presence of PostgreSQL installation.\n====> * check_vdo\n Check if VDO devices need to be migrated to lvm management.\n====> * check_ifcfg\n Ensures that ifcfg files are compatible with NetworkManager\n====> * check_ipa_server\n Check for ipa-server and inhibit upgrade\n====> * efi_check_boot\n Adjust EFI boot entry for first reboot\n====> * check_arm_bootloader\n Install required RPM packages for ARM system upgrades on paths with\n====> * check_luks\n Check if any encrypted partitions are in use and whether they are supported for the upgrade.\n====> * sssd_check_8to9\n Check SSSD configuration for changes in RHEL9 and report them in model.\n====> * distribution_signed_rpm_check\n Check if there are any packages that are not signed by distribution GPG keys.\n====> * check_microarchitecture\n Inhibit if RHEL9 microarchitecture requirements are not satisfied\n====> * xorgdrvcheck8to9\n Warn if Xorg deprecated drivers are in use.\n====> * check_mount_options\n Check for mount options preventing the upgrade.\n====> * check_nfs\n Check if NFS filesystem is in use. If yes, inhibit the upgrade process.\n====> * open_ssl_config_check\n The OpenSSL configuration changed between RHEL8 and RHEL9 significantly with the rebase to\n====> * check_cifs\n Check if CIFS filesystem is in use. If yes, inhibit the upgrade process.\n====> * check_persistent_mounts\n Check if mounts required to be persistent are mounted in persistent fashion.\n====> * firewalld_check_service_tftp_client\n This actor will inhibit if firewalld's configuration is using service\n====> * multipath_conf_check_8to9\n Checks if changes to the multipath configuration files are necessary\n====> * nis_check\n Checks if any of NIS components is installed and configured\n====> * check_yum_plugins_enabled\n Checks that the required yum plugins are enabled.\n====> * check_skipped_repositories\n Produces a report if any repositories enabled on the system are going to be skipped.\n====> * check_root_symlinks\n Check if the symlinks /bin and /lib are relative, not absolute.\n====> * detect_grub_config_error\n Check grub configuration for various errors.\n====> * open_ssh_drop_in_directory_check\n Trigger a notice that the main sshd_config will be updated to contain\n====> * check_target_version\n Check that the target system version is supported by the upgrade process.\n====> * check_grubenv_to_file\n Check whether grubenv is a symlink on Azure hybrid images using BIOS.\n====> * check_rpm_transaction_events\n Filter RPM transaction events based on installed RPM packages\n====> * crypto_policies_check\n This actor consumes previously gathered information about crypto policies on the source\n====> * check_systemd_broken_symlinks\n Check whether some systemd symlinks are broken\n====> * check_se_linux\n Check SELinux status and produce decision messages for further action.\n====> * check_system_arch\n Check if system is running at a supported architecture. If no, inhibit the upgrade process.\n====> * network_deprecations\n Ensures that network configuration doesn't rely on unsupported settings\n====> * check_skip_phase\n Skip all the subsequent phases until the report phase.\n==> Processing phase `Reports`\n====> * verify_check_results\n Check all dialogs and notify that user needs to make some choices.\n====> * verify_check_results\n Check all generated results messages and notify user about them.\n\nDebug output written to /var/log/leapp/leapp-preupgrade.log\n\n============================================================\n REPORT OVERVIEW \n============================================================\n\nUpgrade has been inhibited due to the following problems:\n 1. Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\n 2. Use of NFS detected. Upgrade can't proceed\n 3. Use of CIFS detected. Upgrade can't proceed\n\nHIGH and MEDIUM severity reports:\n 1. Packages available in excluded repositories will not be installed\n 2. Upgrade is unsupported\n 3. Remote root logins globally allowed using password\n 4. GRUB2 core will be automatically updated during the upgrade\n\nReports summary:\n Errors: 0\n Inhibitors: 3\n HIGH severity reports: 4\n MEDIUM severity reports: 0\n LOW severity reports: 1\n INFO severity reports: 3\n\nBefore continuing, review the full report below for details about discovered problems and possible remediation instructions:\n A report has been generated at /var/log/leapp/leapp-report.txt\n A report has been generated at /var/log/leapp/leapp-report.json\n\n============================================================\n END OF REPORT OVERVIEW \n============================================================\n\nAnswerfile has been generated at /var/log/leapp/answerfile", "stdout_lines": ["", "============================================================", " UNSUPPORTED UPGRADE ", "============================================================", "", "Variable LEAPP_UNSUPPORTED has been detected. Proceeding at your own risk.", "Development variables have been detected:", "- LEAPP_DEVEL_RPMS_ALL_SIGNED=1", "", "============================================================", " UNSUPPORTED UPGRADE ", "============================================================", "", "==> Processing phase `configuration_phase`", "====> * ipu_workflow_config", " IPU workflow config actor", "==> Processing phase `FactsCollection`", "====> * scan_kernel_cmdline", " Scan the kernel command line of the booted system.", "====> * network_manager_read_config", " Provides data about NetworkManager configuration.", "====> * scan_files_for_target_userspace", " Scan the source system and identify files that will be copied into the target userspace when it is created.", "====> * udevadm_info", " Produces data exported by the \"udevadm info\" command.", "====> * check_custom_network_scripts", " Check the existence of custom network-scripts and warn user about possible", "====> * scan_grub_config", " Scan grub configuration files for errors.", "====> * scan_systemd_source", " Provides info about systemd on the source system", "====> * persistentnetnames", " Get network interface information for physical ethernet interfaces of the original system.", "====> * scan_source_files", " Scan files (explicitly specified) of the source system.", "====> * network_manager_connection_scanner", " Scan NetworkManager connection keyfiles", "====> * biosdevname", " Enable biosdevname on the target RHEL system if all interfaces on the source RHEL", "====> * scan_pkg_manager", " Provides data about package manager (yum/dnf)", "====> * scanblacklistca", " Scan the file system for distrusted CA's in the blacklist directory.", "====> * register_ruby_irb_adjustment", " Register a workaround to allow rubygem-irb's directory -> symlink conversion.", "====> * scandasd", " In case of s390x architecture, check whether DASD is used.", "====> * repository_mapping", " Produces message containing repository mapping based on provided file.", "====> * scan_subscription_manager_info", " Scans the current system for subscription manager information", "====> * load_device_driver_deprecation_data", " Loads deprecation data for drivers and devices (PCI & CPU)", "====> * open_ssl_config_scanner", " Read an OpenSSL configuration file for further analysis.", "====> * scan_grub_device_name", " Find the name of the block devices where GRUB is located", "====> * transaction_workarounds", " Provides additional RPM transaction tasks based on bundled RPM packages.", "====> * sssd_facts_8to9", " Check SSSD configuration for changes in RHEL9 and report them in model.", "====> * read_openssh_config", " Collect information about the OpenSSH configuration.", "====> * scanzfcp", " In case of s390x architecture, check whether ZFCP is used.", "====> * scan_custom_repofile", " Scan the custom /etc/leapp/files/leapp_upgrade_repositories.repo repo file.", "====> * persistentnetnamesdisable", " Disable systemd-udevd persistent network naming on machine with single eth0 NIC", "====> * scan_target_os_image", " Scans the provided target OS ISO image to use as a content source for the IPU, if any.", "====> * roce_scanner", " Detect active RoCE NICs on IBM Z machines.", "====> * ifcfg_scanner", " Scan ifcfg files with legacy network configuration", "====> * root_scanner", " Scan the system root directory and produce a message containing", "====> * storage_scanner", " Provides data about storage settings.", "====> * scanmemory", " Scan Memory of the machine.", "====> * firewalld_collect_used_object_names", " This actor reads firewalld's configuration and produces Model", "====> * scanclienablerepo", " Produce CustomTargetRepository based on the LEAPP_ENABLE_REPOS in config.", "====> * scancryptopolicies", " Scan information about system wide set crypto policies including:", "====> * xorgdrvfacts8to9", " Check the journal logs for deprecated Xorg drivers.", "====> * system_facts", " Provides data about many facts from system.", "====> * scan_source_boot_entry", " Scan the default boot entry of the source system.", "====> * pci_devices_scanner", " Provides data about existing PCI Devices.", "====> * get_enabled_modules", " Provides data about which module streams are enabled on the source system.", "====> * repositories_blacklist", " Exclude target repositories provided by Red Hat without support.", "====> * scan_default_initramfs", " Scan details of the default boot entry's initramfs image.", "====> * copy_dnf_conf_into_target_userspace", " Copy dnf.conf into target userspace", "====> * nis_scanner", " Collect information about the NIS packages configuration.", "====> * scan_sap_hana", " Gathers information related to SAP HANA instances on the system.", "====> * firewalld_collect_global_config", " This actor reads firewalld's configuration and produces Model", "====> * scan_custom_modifications_actor", " Collects information about files in leapp directories that have been modified or newly added.", "====> * rpm_scanner", " Provides data about installed RPM Packages.", "====> * scan_fips", " Determine whether the source system has FIPS enabled.", "====> * luks_scanner", " Provides data about active LUKS devices.", "====> * scancpu", " Scan CPUs of the machine.", "====> * get_installed_desktops", " Actor checks if kde or gnome desktop environments", "====> * remove_obsolete_gpg_keys", " Remove obsoleted RPM GPG keys.", "====> * selinuxcontentscanner", " Scan the system for any SELinux customizations", "====> * xfs_info_scanner", " This actor scans all mounted mountpoints for XFS information.", "====> * detect_kernel_drivers", " Matches all currently loaded kernel drivers against known deprecated and removed drivers.", "====> * distribution_signed_rpm_scanner", " Provide data about distribution signed & third-party RPM packages.", "====> * vdo_conversion_scanner", " Provides conversion info about VDO devices.", "====> * scan_hybrid_image_azure", " Check if the system is using Azure hybrid image.", "====> * trusted_gpg_keys_scanner", " Scan for trusted GPG keys.", "====> * checkrhui", " Check if system is using RHUI infrastructure (on public cloud) and send messages to", "====> * used_repository_scanner", " Scan used enabled repositories", "====> * scan_source_kernel", " Scan the source system kernel.", "====> * scan_dynamic_linker_configuration", " Scan the dynamic linker configuration and find modifications.", "====> * multipath_conf_read_8to9", " Read multipath configuration files and extract the necessary information", "====> * ipa_scanner", " Scan system for ipa-client and ipa-server status", "====> * rpm_transaction_config_tasks_collector", " Provides additional RPM transaction tasks from /etc/leapp/transaction.", "====> * satellite_upgrade_facts", " Report which Satellite packages require updates and how to handle PostgreSQL data", "====> * satellite_upgrade_services", " Reconfigure Satellite services", "====> * pes_events_scanner", " Provides data about package events from Package Evolution Service.", "====> * setuptargetrepos", " Produces list of repositories that should be available to be used during IPU process.", "==> Processing phase `Checks`", "====> * unsupported_upgrade_check", " Checks environment variables and produces a warning report if the upgrade is unsupported.", "====> * checkmemory", " The actor check the size of RAM against RHEL8 minimal hardware requirements", "====> * mysql_check", " Actor checking for presence of MySQL installation.", "====> * bacula_check", " Actor checking for presence of Bacula installation.", "====> * check_os_release", " Check if the current RHEL minor version is supported. If not, inhibit the upgrade process.", "====> * check_nvidia_proprietary_driver", " Check if NVIDIA proprietary driver is in use. If yes, inhibit the upgrade process.", "====> * check_deprecated_rpm_signature", " Check whether any packages signed by RSA/SHA1 are installed", "====> * emit_net_naming_scheme", " Emit necessary modifications of the upgrade environment and target command line to use net.naming-scheme.", "====> * cephvolumescan", " Retrieves the list of encrypted Ceph OSD", "====> * dotnet_unsupported_versions_check", " Check for installed .NET versions that are no longer supported.", "====> * check_installed_kernels", " Inhibit IPU (in-place upgrade) when installed kernels conflict with a safe upgrade.", "====> * checkblacklistca", " No documentation has been provided for the checkblacklistca actor.", "====> * check_insights_auto_register", " Checks if system can be automatically registered into Red Hat Insights", "====> * firewalld_check_allow_zone_drifting", " This actor will check if AllowZoneDrifting=yes in firewalld.conf. This", "====> * check_target_iso", " Check that the provided target ISO is a valid ISO image and is located on a persistent partition.", "====> * mariadb_check", " Actor checking for presence of MariaDB installation.", "====> * roce_check", " Check whether RoCE is used on the system and well configured for the upgrade.", "====> * check_boot_avail_space", " Check if at least 100Mib of available space on /boot. If not, inhibit the upgrade process.", "====> * check_fstab_mount_order", " Checks order of entries in /etc/fstab based on their mount point and inhibits upgrade if overshadowing is detected.", "====> * check_valid_grubcfg_hybrid", " Check potential for boot failures in Azure Gen1 VMs due to invalid grubcfg", "====> * check_consumed_assets", " Check whether Leapp is using correct data assets.", "====> * open_ssh_subsystem_sftp", " The RHEL9 changes the SCP to use SFTP protocol internally. The both RHEL8 and RHEL9", "====> * check_bls_grub_onppc64", " Check whether GRUB config is BLS aware on RHEL 8 ppc64le systems", "====> * check_custom_modifications_actor", " Checks CustomModifications messages and produces a report about files in leapp directories that have been", "====> * check_kpatch", " Carry over kpatch-dnf and it's config into the container", "====> * check_detected_devices_and_drivers", " Checks whether or not detected devices and drivers are usable on the target system.", "====> * check_openssl_conf", " Check whether the openssl configuration and openssl-IBMCA.", "====> * check_dynamic_linker_configuration", " Check for customization of dynamic linker configuration.", "====> * check_etc_releasever", " Check releasever info and provide a guidance based on the facts", "====> * openssh_permit_root_login", " OpenSSH no longer allows root logins with password.", "====> * check_fips", " Inhibit upgrade if FIPS is detected as enabled.", "====> * check_rhsmsku", " Ensure the system is subscribed to the subscription manager", "====> * check_sap_hana", " If SAP HANA has been detected, several checks are performed to ensure a successful upgrade.", "====> * checktargetrepos", " Check whether target yum repositories are specified.", "====> * check_grub_core", " Check whether we are on legacy (BIOS) system and instruct Leapp to upgrade GRUB core", "====> * postgresql_check", " Actor checking for presence of PostgreSQL installation.", "====> * check_vdo", " Check if VDO devices need to be migrated to lvm management.", "====> * check_ifcfg", " Ensures that ifcfg files are compatible with NetworkManager", "====> * check_ipa_server", " Check for ipa-server and inhibit upgrade", "====> * efi_check_boot", " Adjust EFI boot entry for first reboot", "====> * check_arm_bootloader", " Install required RPM packages for ARM system upgrades on paths with", "====> * check_luks", " Check if any encrypted partitions are in use and whether they are supported for the upgrade.", "====> * sssd_check_8to9", " Check SSSD configuration for changes in RHEL9 and report them in model.", "====> * distribution_signed_rpm_check", " Check if there are any packages that are not signed by distribution GPG keys.", "====> * check_microarchitecture", " Inhibit if RHEL9 microarchitecture requirements are not satisfied", "====> * xorgdrvcheck8to9", " Warn if Xorg deprecated drivers are in use.", "====> * check_mount_options", " Check for mount options preventing the upgrade.", "====> * check_nfs", " Check if NFS filesystem is in use. If yes, inhibit the upgrade process.", "====> * open_ssl_config_check", " The OpenSSL configuration changed between RHEL8 and RHEL9 significantly with the rebase to", "====> * check_cifs", " Check if CIFS filesystem is in use. If yes, inhibit the upgrade process.", "====> * check_persistent_mounts", " Check if mounts required to be persistent are mounted in persistent fashion.", "====> * firewalld_check_service_tftp_client", " This actor will inhibit if firewalld's configuration is using service", "====> * multipath_conf_check_8to9", " Checks if changes to the multipath configuration files are necessary", "====> * nis_check", " Checks if any of NIS components is installed and configured", "====> * check_yum_plugins_enabled", " Checks that the required yum plugins are enabled.", "====> * check_skipped_repositories", " Produces a report if any repositories enabled on the system are going to be skipped.", "====> * check_root_symlinks", " Check if the symlinks /bin and /lib are relative, not absolute.", "====> * detect_grub_config_error", " Check grub configuration for various errors.", "====> * open_ssh_drop_in_directory_check", " Trigger a notice that the main sshd_config will be updated to contain", "====> * check_target_version", " Check that the target system version is supported by the upgrade process.", "====> * check_grubenv_to_file", " Check whether grubenv is a symlink on Azure hybrid images using BIOS.", "====> * check_rpm_transaction_events", " Filter RPM transaction events based on installed RPM packages", "====> * crypto_policies_check", " This actor consumes previously gathered information about crypto policies on the source", "====> * check_systemd_broken_symlinks", " Check whether some systemd symlinks are broken", "====> * check_se_linux", " Check SELinux status and produce decision messages for further action.", "====> * check_system_arch", " Check if system is running at a supported architecture. If no, inhibit the upgrade process.", "====> * network_deprecations", " Ensures that network configuration doesn't rely on unsupported settings", "====> * check_skip_phase", " Skip all the subsequent phases until the report phase.", "==> Processing phase `Reports`", "====> * verify_check_results", " Check all dialogs and notify that user needs to make some choices.", "====> * verify_check_results", " Check all generated results messages and notify user about them.", "", "Debug output written to /var/log/leapp/leapp-preupgrade.log", "", "============================================================", " REPORT OVERVIEW ", "============================================================", "", "Upgrade has been inhibited due to the following problems:", " 1. Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.", " 2. Use of NFS detected. Upgrade can't proceed", " 3. Use of CIFS detected. Upgrade can't proceed", "", "HIGH and MEDIUM severity reports:", " 1. Packages available in excluded repositories will not be installed", " 2. Upgrade is unsupported", " 3. Remote root logins globally allowed using password", " 4. GRUB2 core will be automatically updated during the upgrade", "", "Reports summary:", " Errors: 0", " Inhibitors: 3", " HIGH severity reports: 4", " MEDIUM severity reports: 0", " LOW severity reports: 1", " INFO severity reports: 3", "", "Before continuing, review the full report below for details about discovered problems and possible remediation instructions:", " A report has been generated at /var/log/leapp/leapp-report.txt", " A report has been generated at /var/log/leapp/leapp-report.json", "", "============================================================", " END OF REPORT OVERVIEW ", "============================================================", "", "Answerfile has been generated at /var/log/leapp/answerfile"]} TASK [analysis-leapp | Include custom_local_repos for local_repos_post_analysis] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:89 TASK [infra.leapp.common : custom_local_repos | Remove old /etc/leapp/files/leapp_upgrade_repositories.repo] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:2 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : custom_local_repos | Enable custom upgrade yum repositories] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:9 skipping: [managed-node02] => {"changed": false, "skipped_reason": "No items in the list"} TASK [infra.leapp.analysis : analysis-leapp | Include check-results-file.yml] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:97 included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/check-results-file.yml for managed-node02 TASK [infra.leapp.analysis : check-results-file | Result file status] ********** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/check-results-file.yml:2 ok: [managed-node02] => {"changed": false, "stat": {"atime": 1768226112.8370078, "attr_flags": "", "attributes": [], "block_size": 4096, "blocks": 16, "charset": "us-ascii", "checksum": "bf192cdf6bfda5fcc7bddaee654aea31d507ff0f", "ctime": 1768226112.8370078, "dev": 51715, "device_type": 0, "executable": false, "exists": true, "gid": 0, "gr_name": "root", "inode": 780140696, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0644", "mtime": 1768226112.8370078, "nlink": 1, "path": "/var/log/leapp/leapp-report.txt", "pw_name": "root", "readable": true, "rgrp": true, "roth": true, "rusr": true, "size": 6775, "uid": 0, "version": "324450059", "wgrp": false, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false}} TASK [infra.leapp.analysis : check-results-file | Check that result file exists] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/check-results-file.yml:7 ok: [managed-node02] => { "changed": false, "msg": "All assertions passed" } TASK [analysis-leapp | Run parse_leapp_report to check for inhibitors] ********* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:100 TASK [infra.leapp.common : parse_leapp_report | Default upgrade_inhibited to false] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:12 ok: [managed-node02] => {"ansible_facts": {"upgrade_inhibited": false}, "changed": false} TASK [infra.leapp.common : parse_leapp_report | Collect human readable report results] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:16 ok: [managed-node02] => {"changed": false, "content": "Risk Factor: high (inhibitor)
Title: Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.
Summary: Support for the following RHEL 8 device drivers has been removed in RHEL 9:
     - dnet
     - liquidio
     - dlci

Related links:
    - Leapp preupgrade getting "Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.": https://access.redhat.com/solutions/6971716
    - Leapp upgrade fail with error "Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.": https://access.redhat.com/solutions/5436131
Key: 7ae2961239eec9905e2580fa6309a589b1dca953
----------------------------------------
Risk Factor: high (inhibitor)
Title: Use of NFS detected. Upgrade can't proceed
Summary: NFS is currently not supported by the inplace upgrade.
We have found NFS usage at the following locations:
- NFS shares found in /etc/fstab:
 - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat
 - nest.test.redhat.com:/mnt/qa /mnt/qa
 - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive
 - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist
 - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew
 - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch

Related links:
    - Why does leapp upgrade fail on detecting NFS during upgrade?: https://access.redhat.com/solutions/6964006
Remediation: [hint] Disable NFS temporarily for the upgrade if possible.
Key: 9881b25faceeeaa7a6478bcdac29afd7f6baaaed
----------------------------------------
Risk Factor: high (inhibitor)
Title: Use of CIFS detected. Upgrade can't proceed
Summary: CIFS is currently not supported by the inplace upgrade.
Related links:
    - Leapp upgrade failed with error "Inhibitor: Use of CIFS detected. Upgrade cannot proceed": https://access.redhat.com/solutions/6964304
Remediation: [hint] Comment out CIFS entries to proceed with the upgrade.
Key: d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a
----------------------------------------
Risk Factor: high 
Title: Packages available in excluded repositories will not be installed
Summary: 1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled "Excluded target system repositories" for details.
The list of these packages:
- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)
Key: 2437e204808f987477c0e9be8e4c95b3a87a9f3e
----------------------------------------
Risk Factor: high 
Title: Upgrade is unsupported
Summary: Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.

Key: 9e5088e3c1f371e020ec777c3d86578f4be143cf
----------------------------------------
Risk Factor: high 
Title: Remote root logins globally allowed using password
Summary: RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.
Remediation: [hint] If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.
Key: e738f78bc8f3a84411a4210e3b609057139d1855
----------------------------------------
Risk Factor: high 
Title: GRUB2 core will be automatically updated during the upgrade
Summary: On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running "grub2-install" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.
Key: ac7030e05d2ee248d34f08a9fa040b352bc410a3
----------------------------------------
Risk Factor: low 
Title: SElinux will be set to permissive mode
Summary: SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.
Remediation: [hint] Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the "/root/tmp_leapp_py3" SElinux warnings.
Key: 39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f
----------------------------------------
Risk Factor: info 
Title: Excluded target system repositories
Summary: The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.
- codeready-builder-for-rhel-9-s390x-rpms
- codeready-builder-beta-for-rhel-9-x86_64-rpms
- codeready-builder-for-rhel-9-rhui-rpms
- codeready-builder-beta-for-rhel-9-aarch64-rpms
- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms
- codeready-builder-for-rhel-9-ppc64le-rpms
- codeready-builder-for-rhel-9-x86_64-rhui-rpms
- codeready-builder-beta-for-rhel-9-s390x-rpms
- codeready-builder-beta-for-rhel-9-ppc64le-rpms
- codeready-builder-for-rhel-9-aarch64-eus-rpms
- codeready-builder-for-rhel-9-x86_64-eus-rpms
- codeready-builder-for-rhel-9-x86_64-rpms
- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms
- codeready-builder-for-rhel-9-s390x-eus-rpms
- codeready-builder-for-rhel-9-ppc64le-eus-rpms
- codeready-builder-for-rhel-9-aarch64-rpms
- crb
Remediation: [hint] If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).
Key: 1b9132cb2362ae7830e48eee7811be9527747de8
----------------------------------------
Risk Factor: info 
Title: The upgrade will prepend the Include directive to OpenSSH sshd_config
Summary: OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`
Key: 96da6937c25c6492e4f1228ee146795989fd3718
----------------------------------------
Risk Factor: info 
Title: SElinux relabeling will be scheduled
Summary: SElinux relabeling will be scheduled as the status is permissive/enforcing.
Key: 8fb81863f8413bd617c2a55b69b8e10ff03d7c72
----------------------------------------
", "encoding": "base64", "source": "/var/log/leapp/leapp-report.txt"} TASK [infra.leapp.common : parse_leapp_report | Collect JSON report results] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:21 ok: [managed-node02] => {"changed": false, "content": "{
  "entries": [
    {
      "audience": "sysadmin",
      "detail": {
        "remediations": [
          {
            "context": "If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "repository",
        "failure"
      ],
      "key": "1b9132cb2362ae7830e48eee7811be9527747de8",
      "severity": "info",
      "summary": "The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.\n- codeready-builder-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-rhui-rpms\n- codeready-builder-beta-for-rhel-9-aarch64-rpms\n- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms\n- codeready-builder-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-beta-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-aarch64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-rpms\n- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-for-rhel-9-s390x-eus-rpms\n- codeready-builder-for-rhel-9-ppc64le-eus-rpms\n- codeready-builder-for-rhel-9-aarch64-rpms\n- crb",
      "title": "Excluded target system repositories",
      "timeStamp": "2026-01-12T13:54:50.273616Z",
      "hostname": "managed-node02",
      "actor": "repositories_blacklist",
      "id": "0f07a5448003e83a04bb526016d4b33e328da97de8e696a359b21d29d6dd0ca2"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "related_resources": [
          {
            "scheme": "package",
            "title": "jitterentropy-devel"
          }
        ]
      },
      "groups": [
        "repository"
      ],
      "key": "2437e204808f987477c0e9be8e4c95b3a87a9f3e",
      "severity": "high",
      "summary": "1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled \"Excluded target system repositories\" for details.\nThe list of these packages:\n- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)",
      "title": "Packages available in excluded repositories will not be installed",
      "timeStamp": "2026-01-12T13:55:07.330503Z",
      "hostname": "managed-node02",
      "actor": "pes_events_scanner",
      "id": "f03da8195ba01808f011f834a4196c501d6b3f18b7e7e3bae7a4ee453934e11d"
    },
    {
      "audience": "sysadmin",
      "groups": [
        "upgrade process",
        "sanity"
      ],
      "key": "9e5088e3c1f371e020ec777c3d86578f4be143cf",
      "severity": "high",
      "summary": "Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.\n",
      "title": "Upgrade is unsupported",
      "timeStamp": "2026-01-12T13:55:07.484475Z",
      "hostname": "managed-node02",
      "actor": "unsupported_upgrade_check",
      "id": "3fc40063b0b979e99eea5cf0238752492a31d3dffc4bc98f50f595419afb7a4d"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "external": [
          {
            "title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"",
            "url": "https://access.redhat.com/solutions/6971716"
          },
          {
            "title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"",
            "url": "https://access.redhat.com/solutions/5436131"
          }
        ]
      },
      "groups": [
        "kernel",
        "drivers",
        "inhibitor"
      ],
      "key": "7ae2961239eec9905e2580fa6309a589b1dca953",
      "severity": "high",
      "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n     - dnet\n     - liquidio\n     - dlci\n",
      "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.",
      "timeStamp": "2026-01-12T13:55:09.387759Z",
      "hostname": "managed-node02",
      "actor": "check_detected_devices_and_drivers",
      "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "related_resources": [
          {
            "scheme": "package",
            "title": "openssh-server"
          },
          {
            "scheme": "file",
            "title": "/etc/ssh/sshd_config"
          }
        ],
        "remediations": [
          {
            "context": "If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "authentication",
        "security",
        "network",
        "services"
      ],
      "key": "e738f78bc8f3a84411a4210e3b609057139d1855",
      "severity": "high",
      "summary": "RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.",
      "title": "Remote root logins globally allowed using password",
      "timeStamp": "2026-01-12T13:55:09.674314Z",
      "hostname": "managed-node02",
      "actor": "openssh_permit_root_login",
      "id": "a2e756b7234ca6ce24ffed93d514fa68491afcef9e093c19a5758b6bd59e4f24"
    },
    {
      "audience": "sysadmin",
      "groups": [
        "boot"
      ],
      "key": "ac7030e05d2ee248d34f08a9fa040b352bc410a3",
      "severity": "high",
      "summary": "On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running \"grub2-install\" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.",
      "title": "GRUB2 core will be automatically updated during the upgrade",
      "timeStamp": "2026-01-12T13:55:10.220125Z",
      "hostname": "managed-node02",
      "actor": "check_grub_core",
      "id": "324a17d8b1d3245e455322b53661791ef6a3c9ecd9a48dcc752b1317a290a010"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "external": [
          {
            "title": "Why does leapp upgrade fail on detecting NFS during upgrade?",
            "url": "https://access.redhat.com/solutions/6964006"
          }
        ],
        "related_resources": [
          {
            "scheme": "file",
            "title": "/etc/fstab"
          }
        ],
        "remediations": [
          {
            "context": "Disable NFS temporarily for the upgrade if possible.",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "filesystem",
        "network",
        "inhibitor"
      ],
      "key": "9881b25faceeeaa7a6478bcdac29afd7f6baaaed",
      "severity": "high",
      "summary": "NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n",
      "title": "Use of NFS detected. Upgrade can't proceed",
      "timeStamp": "2026-01-12T13:55:11.142353Z",
      "hostname": "managed-node02",
      "actor": "check_nfs",
      "id": "2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "external": [
          {
            "title": "Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\"",
            "url": "https://access.redhat.com/solutions/6964304"
          }
        ],
        "related_resources": [
          {
            "scheme": "file",
            "title": "/etc/fstab"
          }
        ],
        "remediations": [
          {
            "context": "Comment out CIFS entries to proceed with the upgrade.",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "filesystem",
        "network",
        "inhibitor"
      ],
      "key": "d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a",
      "severity": "high",
      "summary": "CIFS is currently not supported by the inplace upgrade.",
      "title": "Use of CIFS detected. Upgrade can't proceed",
      "timeStamp": "2026-01-12T13:55:11.287236Z",
      "hostname": "managed-node02",
      "actor": "check_cifs",
      "id": "6a06bcae8d148e7123d9fb89c4338a0adaaa89b1927bdd25a9a2156bc2dee822"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "related_resources": [
          {
            "scheme": "package",
            "title": "openssh-server"
          },
          {
            "scheme": "file",
            "title": "/etc/ssh/sshd_config"
          }
        ]
      },
      "groups": [
        "authentication",
        "security",
        "network",
        "services"
      ],
      "key": "96da6937c25c6492e4f1228ee146795989fd3718",
      "severity": "info",
      "summary": "OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`",
      "title": "The upgrade will prepend the Include directive to OpenSSH sshd_config",
      "timeStamp": "2026-01-12T13:55:12.091208Z",
      "hostname": "managed-node02",
      "actor": "open_ssh_drop_in_directory_check",
      "id": "1aa85a7300eb2cdc66fd34590ca8170d0ff1a7330a2a0fdfded6086cbad84b17"
    },
    {
      "audience": "sysadmin",
      "groups": [
        "selinux",
        "security"
      ],
      "key": "8fb81863f8413bd617c2a55b69b8e10ff03d7c72",
      "severity": "info",
      "summary": "SElinux relabeling will be scheduled as the status is permissive/enforcing.",
      "title": "SElinux relabeling will be scheduled",
      "timeStamp": "2026-01-12T13:55:12.469366Z",
      "hostname": "managed-node02",
      "actor": "check_se_linux",
      "id": "07d9135d924068cc5ca6284e5496442221635888f07b0644b33ee42f99331bf8"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "remediations": [
          {
            "context": "Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the \"/root/tmp_leapp_py3\" SElinux warnings.",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "selinux",
        "security"
      ],
      "key": "39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f",
      "severity": "low",
      "summary": "SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.",
      "title": "SElinux will be set to permissive mode",
      "timeStamp": "2026-01-12T13:55:12.471808Z",
      "hostname": "managed-node02",
      "actor": "check_se_linux",
      "id": "2d50fc721d27a76536f935c597cec547de25b8ec82ad77270dca0bd552929716"
    }
  ],
  "leapp_run_id": "976bbc19-67c1-42f4-8c1e-b3e9cfea1360"
}
", "encoding": "base64", "source": "/var/log/leapp/leapp-report.json"} TASK [infra.leapp.common : parse_leapp_report | Parse report results] ********** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:26 ok: [managed-node02] => {"ansible_facts": {"leapp_report_json": {"entries": [{"actor": "repositories_blacklist", "audience": "sysadmin", "detail": {"remediations": [{"context": "If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).", "type": "hint"}]}, "groups": ["repository", "failure"], "hostname": "managed-node02", "id": "0f07a5448003e83a04bb526016d4b33e328da97de8e696a359b21d29d6dd0ca2", "key": "1b9132cb2362ae7830e48eee7811be9527747de8", "severity": "info", "summary": "The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.\n- codeready-builder-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-rhui-rpms\n- codeready-builder-beta-for-rhel-9-aarch64-rpms\n- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms\n- codeready-builder-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-beta-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-aarch64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-rpms\n- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-for-rhel-9-s390x-eus-rpms\n- codeready-builder-for-rhel-9-ppc64le-eus-rpms\n- codeready-builder-for-rhel-9-aarch64-rpms\n- crb", "timeStamp": "2026-01-12T13:54:50.273616Z", "title": "Excluded target system repositories"}, {"actor": "pes_events_scanner", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "jitterentropy-devel"}]}, "groups": ["repository"], "hostname": "managed-node02", "id": "f03da8195ba01808f011f834a4196c501d6b3f18b7e7e3bae7a4ee453934e11d", "key": "2437e204808f987477c0e9be8e4c95b3a87a9f3e", "severity": "high", "summary": "1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled \"Excluded target system repositories\" for details.\nThe list of these packages:\n- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)", "timeStamp": "2026-01-12T13:55:07.330503Z", "title": "Packages available in excluded repositories will not be installed"}, {"actor": "unsupported_upgrade_check", "audience": "sysadmin", "groups": ["upgrade process", "sanity"], "hostname": "managed-node02", "id": "3fc40063b0b979e99eea5cf0238752492a31d3dffc4bc98f50f595419afb7a4d", "key": "9e5088e3c1f371e020ec777c3d86578f4be143cf", "severity": "high", "summary": "Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.\n", "timeStamp": "2026-01-12T13:55:07.484475Z", "title": "Upgrade is unsupported"}, {"actor": "check_detected_devices_and_drivers", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/6971716"}, {"title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/5436131"}]}, "groups": ["kernel", "drivers", "inhibitor"], "hostname": "managed-node02", "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec", "key": "7ae2961239eec9905e2580fa6309a589b1dca953", "severity": "high", "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n", "timeStamp": "2026-01-12T13:55:09.387759Z", "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."}, {"actor": "openssh_permit_root_login", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "openssh-server"}, {"scheme": "file", "title": "/etc/ssh/sshd_config"}], "remediations": [{"context": "If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.", "type": "hint"}]}, "groups": ["authentication", "security", "network", "services"], "hostname": "managed-node02", "id": "a2e756b7234ca6ce24ffed93d514fa68491afcef9e093c19a5758b6bd59e4f24", "key": "e738f78bc8f3a84411a4210e3b609057139d1855", "severity": "high", "summary": "RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.", "timeStamp": "2026-01-12T13:55:09.674314Z", "title": "Remote root logins globally allowed using password"}, {"actor": "check_grub_core", "audience": "sysadmin", "groups": ["boot"], "hostname": "managed-node02", "id": "324a17d8b1d3245e455322b53661791ef6a3c9ecd9a48dcc752b1317a290a010", "key": "ac7030e05d2ee248d34f08a9fa040b352bc410a3", "severity": "high", "summary": "On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running \"grub2-install\" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.", "timeStamp": "2026-01-12T13:55:10.220125Z", "title": "GRUB2 core will be automatically updated during the upgrade"}, {"actor": "check_nfs", "audience": "sysadmin", "detail": {"external": [{"title": "Why does leapp upgrade fail on detecting NFS during upgrade?", "url": "https://access.redhat.com/solutions/6964006"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Disable NFS temporarily for the upgrade if possible.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037", "key": "9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "severity": "high", "summary": "NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n", "timeStamp": "2026-01-12T13:55:11.142353Z", "title": "Use of NFS detected. Upgrade can't proceed"}, {"actor": "check_cifs", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\"", "url": "https://access.redhat.com/solutions/6964304"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Comment out CIFS entries to proceed with the upgrade.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "6a06bcae8d148e7123d9fb89c4338a0adaaa89b1927bdd25a9a2156bc2dee822", "key": "d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a", "severity": "high", "summary": "CIFS is currently not supported by the inplace upgrade.", "timeStamp": "2026-01-12T13:55:11.287236Z", "title": "Use of CIFS detected. Upgrade can't proceed"}, {"actor": "open_ssh_drop_in_directory_check", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "openssh-server"}, {"scheme": "file", "title": "/etc/ssh/sshd_config"}]}, "groups": ["authentication", "security", "network", "services"], "hostname": "managed-node02", "id": "1aa85a7300eb2cdc66fd34590ca8170d0ff1a7330a2a0fdfded6086cbad84b17", "key": "96da6937c25c6492e4f1228ee146795989fd3718", "severity": "info", "summary": "OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`", "timeStamp": "2026-01-12T13:55:12.091208Z", "title": "The upgrade will prepend the Include directive to OpenSSH sshd_config"}, {"actor": "check_se_linux", "audience": "sysadmin", "groups": ["selinux", "security"], "hostname": "managed-node02", "id": "07d9135d924068cc5ca6284e5496442221635888f07b0644b33ee42f99331bf8", "key": "8fb81863f8413bd617c2a55b69b8e10ff03d7c72", "severity": "info", "summary": "SElinux relabeling will be scheduled as the status is permissive/enforcing.", "timeStamp": "2026-01-12T13:55:12.469366Z", "title": "SElinux relabeling will be scheduled"}, {"actor": "check_se_linux", "audience": "sysadmin", "detail": {"remediations": [{"context": "Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the \"/root/tmp_leapp_py3\" SElinux warnings.", "type": "hint"}]}, "groups": ["selinux", "security"], "hostname": "managed-node02", "id": "2d50fc721d27a76536f935c597cec547de25b8ec82ad77270dca0bd552929716", "key": "39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f", "severity": "low", "summary": "SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.", "timeStamp": "2026-01-12T13:55:12.471808Z", "title": "SElinux will be set to permissive mode"}], "leapp_run_id": "976bbc19-67c1-42f4-8c1e-b3e9cfea1360"}, "leapp_report_txt": ["Risk Factor: high (inhibitor)", "Title: Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.", "Summary: Support for the following RHEL 8 device drivers has been removed in RHEL 9:", " - dnet", " - liquidio", " - dlci", "", "Related links:", " - Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\": https://access.redhat.com/solutions/6971716", " - Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\": https://access.redhat.com/solutions/5436131", "Key: 7ae2961239eec9905e2580fa6309a589b1dca953", "----------------------------------------", "Risk Factor: high (inhibitor)", "Title: Use of NFS detected. Upgrade can't proceed", "Summary: NFS is currently not supported by the inplace upgrade.", "We have found NFS usage at the following locations:", "- NFS shares found in /etc/fstab:", " - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat", " - nest.test.redhat.com:/mnt/qa /mnt/qa", " - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive", " - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist", " - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew", " - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch", "", "Related links:", " - Why does leapp upgrade fail on detecting NFS during upgrade?: https://access.redhat.com/solutions/6964006", "Remediation: [hint] Disable NFS temporarily for the upgrade if possible.", "Key: 9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "----------------------------------------", "Risk Factor: high (inhibitor)", "Title: Use of CIFS detected. Upgrade can't proceed", "Summary: CIFS is currently not supported by the inplace upgrade.", "Related links:", " - Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\": https://access.redhat.com/solutions/6964304", "Remediation: [hint] Comment out CIFS entries to proceed with the upgrade.", "Key: d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a", "----------------------------------------", "Risk Factor: high ", "Title: Packages available in excluded repositories will not be installed", "Summary: 1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled \"Excluded target system repositories\" for details.", "The list of these packages:", "- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)", "Key: 2437e204808f987477c0e9be8e4c95b3a87a9f3e", "----------------------------------------", "Risk Factor: high ", "Title: Upgrade is unsupported", "Summary: Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.", "", "Key: 9e5088e3c1f371e020ec777c3d86578f4be143cf", "----------------------------------------", "Risk Factor: high ", "Title: Remote root logins globally allowed using password", "Summary: RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.", "Remediation: [hint] If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.", "Key: e738f78bc8f3a84411a4210e3b609057139d1855", "----------------------------------------", "Risk Factor: high ", "Title: GRUB2 core will be automatically updated during the upgrade", "Summary: On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running \"grub2-install\" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.", "Key: ac7030e05d2ee248d34f08a9fa040b352bc410a3", "----------------------------------------", "Risk Factor: low ", "Title: SElinux will be set to permissive mode", "Summary: SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.", "Remediation: [hint] Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the \"/root/tmp_leapp_py3\" SElinux warnings.", "Key: 39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f", "----------------------------------------", "Risk Factor: info ", "Title: Excluded target system repositories", "Summary: The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.", "- codeready-builder-for-rhel-9-s390x-rpms", "- codeready-builder-beta-for-rhel-9-x86_64-rpms", "- codeready-builder-for-rhel-9-rhui-rpms", "- codeready-builder-beta-for-rhel-9-aarch64-rpms", "- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms", "- codeready-builder-for-rhel-9-ppc64le-rpms", "- codeready-builder-for-rhel-9-x86_64-rhui-rpms", "- codeready-builder-beta-for-rhel-9-s390x-rpms", "- codeready-builder-beta-for-rhel-9-ppc64le-rpms", "- codeready-builder-for-rhel-9-aarch64-eus-rpms", "- codeready-builder-for-rhel-9-x86_64-eus-rpms", "- codeready-builder-for-rhel-9-x86_64-rpms", "- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms", "- codeready-builder-for-rhel-9-s390x-eus-rpms", "- codeready-builder-for-rhel-9-ppc64le-eus-rpms", "- codeready-builder-for-rhel-9-aarch64-rpms", "- crb", "Remediation: [hint] If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).", "Key: 1b9132cb2362ae7830e48eee7811be9527747de8", "----------------------------------------", "Risk Factor: info ", "Title: The upgrade will prepend the Include directive to OpenSSH sshd_config", "Summary: OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`", "Key: 96da6937c25c6492e4f1228ee146795989fd3718", "----------------------------------------", "Risk Factor: info ", "Title: SElinux relabeling will be scheduled", "Summary: SElinux relabeling will be scheduled as the status is permissive/enforcing.", "Key: 8fb81863f8413bd617c2a55b69b8e10ff03d7c72", "----------------------------------------", ""]}, "changed": false} TASK [infra.leapp.common : parse_leapp_report | Check for inhibitors] ********** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:32 skipping: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'remediations': [{'context': 'If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).', 'type': 'hint'}]}, 'groups': ['repository', 'failure'], 'key': '1b9132cb2362ae7830e48eee7811be9527747de8', 'severity': 'info', 'summary': 'The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.\n- codeready-builder-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-rhui-rpms\n- codeready-builder-beta-for-rhel-9-aarch64-rpms\n- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms\n- codeready-builder-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-beta-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-aarch64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-rpms\n- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-for-rhel-9-s390x-eus-rpms\n- codeready-builder-for-rhel-9-ppc64le-eus-rpms\n- codeready-builder-for-rhel-9-aarch64-rpms\n- crb', 'title': 'Excluded target system repositories', 'timeStamp': '2026-01-12T13:54:50.273616Z', 'hostname': 'managed-node02', 'actor': 'repositories_blacklist', 'id': '0f07a5448003e83a04bb526016d4b33e328da97de8e696a359b21d29d6dd0ca2'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "repositories_blacklist", "audience": "sysadmin", "detail": {"remediations": [{"context": "If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).", "type": "hint"}]}, "groups": ["repository", "failure"], "hostname": "managed-node02", "id": "0f07a5448003e83a04bb526016d4b33e328da97de8e696a359b21d29d6dd0ca2", "key": "1b9132cb2362ae7830e48eee7811be9527747de8", "severity": "info", "summary": "The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.\n- codeready-builder-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-rhui-rpms\n- codeready-builder-beta-for-rhel-9-aarch64-rpms\n- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms\n- codeready-builder-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-beta-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-aarch64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-rpms\n- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-for-rhel-9-s390x-eus-rpms\n- codeready-builder-for-rhel-9-ppc64le-eus-rpms\n- codeready-builder-for-rhel-9-aarch64-rpms\n- crb", "timeStamp": "2026-01-12T13:54:50.273616Z", "title": "Excluded target system repositories"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'related_resources': [{'scheme': 'package', 'title': 'jitterentropy-devel'}]}, 'groups': ['repository'], 'key': '2437e204808f987477c0e9be8e4c95b3a87a9f3e', 'severity': 'high', 'summary': '1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled "Excluded target system repositories" for details.\nThe list of these packages:\n- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)', 'title': 'Packages available in excluded repositories will not be installed', 'timeStamp': '2026-01-12T13:55:07.330503Z', 'hostname': 'managed-node02', 'actor': 'pes_events_scanner', 'id': 'f03da8195ba01808f011f834a4196c501d6b3f18b7e7e3bae7a4ee453934e11d'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "pes_events_scanner", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "jitterentropy-devel"}]}, "groups": ["repository"], "hostname": "managed-node02", "id": "f03da8195ba01808f011f834a4196c501d6b3f18b7e7e3bae7a4ee453934e11d", "key": "2437e204808f987477c0e9be8e4c95b3a87a9f3e", "severity": "high", "summary": "1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled \"Excluded target system repositories\" for details.\nThe list of these packages:\n- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)", "timeStamp": "2026-01-12T13:55:07.330503Z", "title": "Packages available in excluded repositories will not be installed"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'groups': ['upgrade process', 'sanity'], 'key': '9e5088e3c1f371e020ec777c3d86578f4be143cf', 'severity': 'high', 'summary': 'Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.\n', 'title': 'Upgrade is unsupported', 'timeStamp': '2026-01-12T13:55:07.484475Z', 'hostname': 'managed-node02', 'actor': 'unsupported_upgrade_check', 'id': '3fc40063b0b979e99eea5cf0238752492a31d3dffc4bc98f50f595419afb7a4d'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "unsupported_upgrade_check", "audience": "sysadmin", "groups": ["upgrade process", "sanity"], "hostname": "managed-node02", "id": "3fc40063b0b979e99eea5cf0238752492a31d3dffc4bc98f50f595419afb7a4d", "key": "9e5088e3c1f371e020ec777c3d86578f4be143cf", "severity": "high", "summary": "Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.\n", "timeStamp": "2026-01-12T13:55:07.484475Z", "title": "Upgrade is unsupported"}, "skip_reason": "Conditional result was False"} ok: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'external': [{'title': 'Leapp preupgrade getting "Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."', 'url': 'https://access.redhat.com/solutions/6971716'}, {'title': 'Leapp upgrade fail with error "Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."', 'url': 'https://access.redhat.com/solutions/5436131'}]}, 'groups': ['kernel', 'drivers', 'inhibitor'], 'key': '7ae2961239eec9905e2580fa6309a589b1dca953', 'severity': 'high', 'summary': 'Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n', 'title': 'Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.', 'timeStamp': '2026-01-12T13:55:09.387759Z', 'hostname': 'managed-node02', 'actor': 'check_detected_devices_and_drivers', 'id': 'fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec'}) => {"ansible_facts": {"leapp_inhibitors": [{"actor": "check_detected_devices_and_drivers", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/6971716"}, {"title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/5436131"}]}, "groups": ["kernel", "drivers", "inhibitor"], "hostname": "managed-node02", "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec", "key": "7ae2961239eec9905e2580fa6309a589b1dca953", "severity": "high", "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n", "timeStamp": "2026-01-12T13:55:09.387759Z", "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."}], "upgrade_inhibited": true}, "ansible_loop_var": "item", "changed": false, "item": {"actor": "check_detected_devices_and_drivers", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/6971716"}, {"title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/5436131"}]}, "groups": ["kernel", "drivers", "inhibitor"], "hostname": "managed-node02", "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec", "key": "7ae2961239eec9905e2580fa6309a589b1dca953", "severity": "high", "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n", "timeStamp": "2026-01-12T13:55:09.387759Z", "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."}} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'related_resources': [{'scheme': 'package', 'title': 'openssh-server'}, {'scheme': 'file', 'title': '/etc/ssh/sshd_config'}], 'remediations': [{'context': 'If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.', 'type': 'hint'}]}, 'groups': ['authentication', 'security', 'network', 'services'], 'key': 'e738f78bc8f3a84411a4210e3b609057139d1855', 'severity': 'high', 'summary': 'RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.', 'title': 'Remote root logins globally allowed using password', 'timeStamp': '2026-01-12T13:55:09.674314Z', 'hostname': 'managed-node02', 'actor': 'openssh_permit_root_login', 'id': 'a2e756b7234ca6ce24ffed93d514fa68491afcef9e093c19a5758b6bd59e4f24'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "openssh_permit_root_login", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "openssh-server"}, {"scheme": "file", "title": "/etc/ssh/sshd_config"}], "remediations": [{"context": "If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.", "type": "hint"}]}, "groups": ["authentication", "security", "network", "services"], "hostname": "managed-node02", "id": "a2e756b7234ca6ce24ffed93d514fa68491afcef9e093c19a5758b6bd59e4f24", "key": "e738f78bc8f3a84411a4210e3b609057139d1855", "severity": "high", "summary": "RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.", "timeStamp": "2026-01-12T13:55:09.674314Z", "title": "Remote root logins globally allowed using password"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'groups': ['boot'], 'key': 'ac7030e05d2ee248d34f08a9fa040b352bc410a3', 'severity': 'high', 'summary': 'On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running "grub2-install" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.', 'title': 'GRUB2 core will be automatically updated during the upgrade', 'timeStamp': '2026-01-12T13:55:10.220125Z', 'hostname': 'managed-node02', 'actor': 'check_grub_core', 'id': '324a17d8b1d3245e455322b53661791ef6a3c9ecd9a48dcc752b1317a290a010'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "check_grub_core", "audience": "sysadmin", "groups": ["boot"], "hostname": "managed-node02", "id": "324a17d8b1d3245e455322b53661791ef6a3c9ecd9a48dcc752b1317a290a010", "key": "ac7030e05d2ee248d34f08a9fa040b352bc410a3", "severity": "high", "summary": "On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running \"grub2-install\" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.", "timeStamp": "2026-01-12T13:55:10.220125Z", "title": "GRUB2 core will be automatically updated during the upgrade"}, "skip_reason": "Conditional result was False"} ok: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'external': [{'title': 'Why does leapp upgrade fail on detecting NFS during upgrade?', 'url': 'https://access.redhat.com/solutions/6964006'}], 'related_resources': [{'scheme': 'file', 'title': '/etc/fstab'}], 'remediations': [{'context': 'Disable NFS temporarily for the upgrade if possible.', 'type': 'hint'}]}, 'groups': ['filesystem', 'network', 'inhibitor'], 'key': '9881b25faceeeaa7a6478bcdac29afd7f6baaaed', 'severity': 'high', 'summary': 'NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n', 'title': "Use of NFS detected. Upgrade can't proceed", 'timeStamp': '2026-01-12T13:55:11.142353Z', 'hostname': 'managed-node02', 'actor': 'check_nfs', 'id': '2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037'}) => {"ansible_facts": {"leapp_inhibitors": [{"actor": "check_detected_devices_and_drivers", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/6971716"}, {"title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/5436131"}]}, "groups": ["kernel", "drivers", "inhibitor"], "hostname": "managed-node02", "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec", "key": "7ae2961239eec9905e2580fa6309a589b1dca953", "severity": "high", "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n", "timeStamp": "2026-01-12T13:55:09.387759Z", "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."}, {"actor": "check_nfs", "audience": "sysadmin", "detail": {"external": [{"title": "Why does leapp upgrade fail on detecting NFS during upgrade?", "url": "https://access.redhat.com/solutions/6964006"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Disable NFS temporarily for the upgrade if possible.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037", "key": "9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "severity": "high", "summary": "NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n", "timeStamp": "2026-01-12T13:55:11.142353Z", "title": "Use of NFS detected. Upgrade can't proceed"}], "upgrade_inhibited": true}, "ansible_loop_var": "item", "changed": false, "item": {"actor": "check_nfs", "audience": "sysadmin", "detail": {"external": [{"title": "Why does leapp upgrade fail on detecting NFS during upgrade?", "url": "https://access.redhat.com/solutions/6964006"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Disable NFS temporarily for the upgrade if possible.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037", "key": "9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "severity": "high", "summary": "NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n", "timeStamp": "2026-01-12T13:55:11.142353Z", "title": "Use of NFS detected. Upgrade can't proceed"}} ok: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'external': [{'title': 'Leapp upgrade failed with error "Inhibitor: Use of CIFS detected. Upgrade cannot proceed"', 'url': 'https://access.redhat.com/solutions/6964304'}], 'related_resources': [{'scheme': 'file', 'title': '/etc/fstab'}], 'remediations': [{'context': 'Comment out CIFS entries to proceed with the upgrade.', 'type': 'hint'}]}, 'groups': ['filesystem', 'network', 'inhibitor'], 'key': 'd0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a', 'severity': 'high', 'summary': 'CIFS is currently not supported by the inplace upgrade.', 'title': "Use of CIFS detected. Upgrade can't proceed", 'timeStamp': '2026-01-12T13:55:11.287236Z', 'hostname': 'managed-node02', 'actor': 'check_cifs', 'id': '6a06bcae8d148e7123d9fb89c4338a0adaaa89b1927bdd25a9a2156bc2dee822'}) => {"ansible_facts": {"leapp_inhibitors": [{"actor": "check_detected_devices_and_drivers", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/6971716"}, {"title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/5436131"}]}, "groups": ["kernel", "drivers", "inhibitor"], "hostname": "managed-node02", "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec", "key": "7ae2961239eec9905e2580fa6309a589b1dca953", "severity": "high", "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n", "timeStamp": "2026-01-12T13:55:09.387759Z", "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."}, {"actor": "check_nfs", "audience": "sysadmin", "detail": {"external": [{"title": "Why does leapp upgrade fail on detecting NFS during upgrade?", "url": "https://access.redhat.com/solutions/6964006"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Disable NFS temporarily for the upgrade if possible.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037", "key": "9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "severity": "high", "summary": "NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n", "timeStamp": "2026-01-12T13:55:11.142353Z", "title": "Use of NFS detected. Upgrade can't proceed"}, {"actor": "check_cifs", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\"", "url": "https://access.redhat.com/solutions/6964304"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Comment out CIFS entries to proceed with the upgrade.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "6a06bcae8d148e7123d9fb89c4338a0adaaa89b1927bdd25a9a2156bc2dee822", "key": "d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a", "severity": "high", "summary": "CIFS is currently not supported by the inplace upgrade.", "timeStamp": "2026-01-12T13:55:11.287236Z", "title": "Use of CIFS detected. Upgrade can't proceed"}], "upgrade_inhibited": true}, "ansible_loop_var": "item", "changed": false, "item": {"actor": "check_cifs", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\"", "url": "https://access.redhat.com/solutions/6964304"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Comment out CIFS entries to proceed with the upgrade.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "6a06bcae8d148e7123d9fb89c4338a0adaaa89b1927bdd25a9a2156bc2dee822", "key": "d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a", "severity": "high", "summary": "CIFS is currently not supported by the inplace upgrade.", "timeStamp": "2026-01-12T13:55:11.287236Z", "title": "Use of CIFS detected. Upgrade can't proceed"}} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'related_resources': [{'scheme': 'package', 'title': 'openssh-server'}, {'scheme': 'file', 'title': '/etc/ssh/sshd_config'}]}, 'groups': ['authentication', 'security', 'network', 'services'], 'key': '96da6937c25c6492e4f1228ee146795989fd3718', 'severity': 'info', 'summary': 'OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`', 'title': 'The upgrade will prepend the Include directive to OpenSSH sshd_config', 'timeStamp': '2026-01-12T13:55:12.091208Z', 'hostname': 'managed-node02', 'actor': 'open_ssh_drop_in_directory_check', 'id': '1aa85a7300eb2cdc66fd34590ca8170d0ff1a7330a2a0fdfded6086cbad84b17'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "open_ssh_drop_in_directory_check", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "openssh-server"}, {"scheme": "file", "title": "/etc/ssh/sshd_config"}]}, "groups": ["authentication", "security", "network", "services"], "hostname": "managed-node02", "id": "1aa85a7300eb2cdc66fd34590ca8170d0ff1a7330a2a0fdfded6086cbad84b17", "key": "96da6937c25c6492e4f1228ee146795989fd3718", "severity": "info", "summary": "OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`", "timeStamp": "2026-01-12T13:55:12.091208Z", "title": "The upgrade will prepend the Include directive to OpenSSH sshd_config"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'groups': ['selinux', 'security'], 'key': '8fb81863f8413bd617c2a55b69b8e10ff03d7c72', 'severity': 'info', 'summary': 'SElinux relabeling will be scheduled as the status is permissive/enforcing.', 'title': 'SElinux relabeling will be scheduled', 'timeStamp': '2026-01-12T13:55:12.469366Z', 'hostname': 'managed-node02', 'actor': 'check_se_linux', 'id': '07d9135d924068cc5ca6284e5496442221635888f07b0644b33ee42f99331bf8'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "check_se_linux", "audience": "sysadmin", "groups": ["selinux", "security"], "hostname": "managed-node02", "id": "07d9135d924068cc5ca6284e5496442221635888f07b0644b33ee42f99331bf8", "key": "8fb81863f8413bd617c2a55b69b8e10ff03d7c72", "severity": "info", "summary": "SElinux relabeling will be scheduled as the status is permissive/enforcing.", "timeStamp": "2026-01-12T13:55:12.469366Z", "title": "SElinux relabeling will be scheduled"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'remediations': [{'context': 'Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the "/root/tmp_leapp_py3" SElinux warnings.', 'type': 'hint'}]}, 'groups': ['selinux', 'security'], 'key': '39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f', 'severity': 'low', 'summary': 'SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.', 'title': 'SElinux will be set to permissive mode', 'timeStamp': '2026-01-12T13:55:12.471808Z', 'hostname': 'managed-node02', 'actor': 'check_se_linux', 'id': '2d50fc721d27a76536f935c597cec547de25b8ec82ad77270dca0bd552929716'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "check_se_linux", "audience": "sysadmin", "detail": {"remediations": [{"context": "Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the \"/root/tmp_leapp_py3\" SElinux warnings.", "type": "hint"}]}, "groups": ["selinux", "security"], "hostname": "managed-node02", "id": "2d50fc721d27a76536f935c597cec547de25b8ec82ad77270dca0bd552929716", "key": "39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f", "severity": "low", "summary": "SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.", "timeStamp": "2026-01-12T13:55:12.471808Z", "title": "SElinux will be set to permissive mode"}, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : parse_leapp_report | Collect inhibitors] ************ task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:44 ok: [managed-node02] => {"changed": false, "cmd": ["awk", "/\\(inhibitor\\)/,/^-------/", "/var/log/leapp/leapp-report.txt"], "delta": "0:00:00.003618", "end": "2026-01-12 08:55:37.414958", "failed_when_result": false, "msg": "", "rc": 0, "start": "2026-01-12 08:55:37.411340", "stderr": "", "stderr_lines": [], "stdout": "Risk Factor: high (inhibitor)\nTitle: Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\nSummary: Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n\nRelated links:\n - Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\": https://access.redhat.com/solutions/6971716\n - Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\": https://access.redhat.com/solutions/5436131\nKey: 7ae2961239eec9905e2580fa6309a589b1dca953\n----------------------------------------\nRisk Factor: high (inhibitor)\nTitle: Use of NFS detected. Upgrade can't proceed\nSummary: NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n\nRelated links:\n - Why does leapp upgrade fail on detecting NFS during upgrade?: https://access.redhat.com/solutions/6964006\nRemediation: [hint] Disable NFS temporarily for the upgrade if possible.\nKey: 9881b25faceeeaa7a6478bcdac29afd7f6baaaed\n----------------------------------------\nRisk Factor: high (inhibitor)\nTitle: Use of CIFS detected. Upgrade can't proceed\nSummary: CIFS is currently not supported by the inplace upgrade.\nRelated links:\n - Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\": https://access.redhat.com/solutions/6964304\nRemediation: [hint] Comment out CIFS entries to proceed with the upgrade.\nKey: d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a\n----------------------------------------", "stdout_lines": ["Risk Factor: high (inhibitor)", "Title: Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.", "Summary: Support for the following RHEL 8 device drivers has been removed in RHEL 9:", " - dnet", " - liquidio", " - dlci", "", "Related links:", " - Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\": https://access.redhat.com/solutions/6971716", " - Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\": https://access.redhat.com/solutions/5436131", "Key: 7ae2961239eec9905e2580fa6309a589b1dca953", "----------------------------------------", "Risk Factor: high (inhibitor)", "Title: Use of NFS detected. Upgrade can't proceed", "Summary: NFS is currently not supported by the inplace upgrade.", "We have found NFS usage at the following locations:", "- NFS shares found in /etc/fstab:", " - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat", " - nest.test.redhat.com:/mnt/qa /mnt/qa", " - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive", " - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist", " - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew", " - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch", "", "Related links:", " - Why does leapp upgrade fail on detecting NFS during upgrade?: https://access.redhat.com/solutions/6964006", "Remediation: [hint] Disable NFS temporarily for the upgrade if possible.", "Key: 9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "----------------------------------------", "Risk Factor: high (inhibitor)", "Title: Use of CIFS detected. Upgrade can't proceed", "Summary: CIFS is currently not supported by the inplace upgrade.", "Related links:", " - Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\": https://access.redhat.com/solutions/6964304", "Remediation: [hint] Comment out CIFS entries to proceed with the upgrade.", "Key: d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a", "----------------------------------------"]} TASK [infra.leapp.common : parse_leapp_report | Collect high errors] *********** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:53 ok: [managed-node02] => {"changed": false, "cmd": ["awk", "/high \\(error\\)/,/^-------/", "/var/log/leapp/leapp-report.txt"], "delta": "0:00:00.003467", "end": "2026-01-12 08:55:37.767135", "failed_when_result": false, "msg": "", "rc": 0, "start": "2026-01-12 08:55:37.763668", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} TASK [infra.leapp.analysis : Set stats for leapp_inhibitors] ******************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/main.yml:17 ok: [managed-node02] => {"ansible_stats": {"aggregate": true, "data": {"leapp_inhibitors": [{"actor": "check_detected_devices_and_drivers", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/6971716"}, {"title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/5436131"}]}, "groups": ["kernel", "drivers", "inhibitor"], "hostname": "managed-node02", "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec", "key": "7ae2961239eec9905e2580fa6309a589b1dca953", "severity": "high", "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n", "timeStamp": "2026-01-12T13:55:09.387759Z", "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."}, {"actor": "check_nfs", "audience": "sysadmin", "detail": {"external": [{"title": "Why does leapp upgrade fail on detecting NFS during upgrade?", "url": "https://access.redhat.com/solutions/6964006"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Disable NFS temporarily for the upgrade if possible.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037", "key": "9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "severity": "high", "summary": "NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n", "timeStamp": "2026-01-12T13:55:11.142353Z", "title": "Use of NFS detected. Upgrade can't proceed"}, {"actor": "check_cifs", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\"", "url": "https://access.redhat.com/solutions/6964304"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Comment out CIFS entries to proceed with the upgrade.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "6a06bcae8d148e7123d9fb89c4338a0adaaa89b1927bdd25a9a2156bc2dee822", "key": "d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a", "severity": "high", "summary": "CIFS is currently not supported by the inplace upgrade.", "timeStamp": "2026-01-12T13:55:11.287236Z", "title": "Use of CIFS detected. Upgrade can't proceed"}]}, "per_host": false}, "changed": false} TASK [infra.leapp.analysis : Notify analysis report is done handler] *********** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/main.yml:22 NOTIFIED HANDLER infra.leapp.analysis : Preupgrade analysis report is done for managed-node02 NOTIFIED HANDLER infra.leapp.analysis : Display inhibitors for managed-node02 NOTIFIED HANDLER infra.leapp.analysis : Display errors for managed-node02 changed: [managed-node02] => {"changed": true, "msg": "All assertions passed"} TASK [common_upgrade_tasks | Flush handlers] *********************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:44 META: triggered running handlers for managed-node02 RUNNING HANDLER [infra.leapp.common : Check for log file] ********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:3 ok: [managed-node02] => {"changed": false, "stat": {"atime": 1768226061.1201675, "attr_flags": "", "attributes": [], "block_size": 4096, "blocks": 40, "charset": "us-ascii", "checksum": "fe39c403c79a740e57488de9c2163a3ab4621c0e", "ctime": 1768226112.9910073, "dev": 51715, "device_type": 0, "executable": false, "exists": true, "gid": 0, "gr_name": "root", "inode": 109052038, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0644", "mtime": 1768226112.9910073, "nlink": 1, "path": "/var/log/ripu/ripu.log", "pw_name": "root", "readable": true, "rgrp": true, "roth": true, "rusr": true, "size": 16547, "uid": 0, "version": "955661204", "wgrp": false, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false}} RUNNING HANDLER [infra.leapp.common : Add end time to log file] **************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:9 changed: [managed-node02] => {"backup": "", "changed": true, "msg": "line added"} RUNNING HANDLER [infra.leapp.common : Slurp ripu.log file] ********************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:19 ok: [managed-node02] => {"changed": false, "content": "RIPU preupgrade analysis
Job started at 2026-01-12T13:54:20Z

============================================================
                    UNSUPPORTED UPGRADE                     
============================================================

Variable LEAPP_UNSUPPORTED has been detected. Proceeding at your own risk.
Development variables have been detected:
- LEAPP_DEVEL_RPMS_ALL_SIGNED=1

============================================================
                    UNSUPPORTED UPGRADE                     
============================================================

==> Processing phase `configuration_phase`
====> * ipu_workflow_config
        IPU workflow config actor
==> Processing phase `FactsCollection`
====> * scan_kernel_cmdline
        Scan the kernel command line of the booted system.
====> * network_manager_read_config
        Provides data about NetworkManager configuration.
====> * scan_files_for_target_userspace
        Scan the source system and identify files that will be copied into the target userspace when it is created.
====> * udevadm_info
        Produces data exported by the "udevadm info" command.
====> * check_custom_network_scripts
        Check the existence of custom network-scripts and warn user about possible
====> * scan_grub_config
        Scan grub configuration files for errors.
====> * scan_systemd_source
        Provides info about systemd on the source system
====> * persistentnetnames
        Get network interface information for physical ethernet interfaces of the original system.
====> * scan_source_files
        Scan files (explicitly specified) of the source system.
====> * network_manager_connection_scanner
        Scan NetworkManager connection keyfiles
====> * biosdevname
        Enable biosdevname on the target RHEL system if all interfaces on the source RHEL
====> * scan_pkg_manager
        Provides data about package manager (yum/dnf)
====> * scanblacklistca
        Scan the file system for distrusted CA's in the blacklist directory.
====> * register_ruby_irb_adjustment
        Register a workaround to allow rubygem-irb's directory -> symlink conversion.
====> * scandasd
        In case of s390x architecture, check whether DASD is used.
====> * repository_mapping
        Produces message containing repository mapping based on provided file.
====> * scan_subscription_manager_info
        Scans the current system for subscription manager information
====> * load_device_driver_deprecation_data
        Loads deprecation data for drivers and devices (PCI & CPU)
====> * open_ssl_config_scanner
        Read an OpenSSL configuration file for further analysis.
====> * scan_grub_device_name
        Find the name of the block devices where GRUB is located
====> * transaction_workarounds
        Provides additional RPM transaction tasks based on bundled RPM packages.
====> * sssd_facts_8to9
        Check SSSD configuration for changes in RHEL9 and report them in model.
====> * read_openssh_config
        Collect information about the OpenSSH configuration.
====> * scanzfcp
        In case of s390x architecture, check whether ZFCP is used.
====> * scan_custom_repofile
        Scan the custom /etc/leapp/files/leapp_upgrade_repositories.repo repo file.
====> * persistentnetnamesdisable
        Disable systemd-udevd persistent network naming on machine with single eth0 NIC
====> * scan_target_os_image
        Scans the provided target OS ISO image to use as a content source for the IPU, if any.
====> * roce_scanner
        Detect active RoCE NICs on IBM Z machines.
====> * ifcfg_scanner
        Scan ifcfg files with legacy network configuration
====> * root_scanner
        Scan the system root directory and produce a message containing
====> * storage_scanner
        Provides data about storage settings.
====> * scanmemory
        Scan Memory of the machine.
====> * firewalld_collect_used_object_names
        This actor reads firewalld's configuration and produces Model
====> * scanclienablerepo
        Produce CustomTargetRepository based on the LEAPP_ENABLE_REPOS in config.
====> * scancryptopolicies
        Scan information about system wide set crypto policies including:
====> * xorgdrvfacts8to9
        Check the journal logs for deprecated Xorg drivers.
====> * system_facts
        Provides data about many facts from system.
====> * scan_source_boot_entry
        Scan the default boot entry of the source system.
====> * pci_devices_scanner
        Provides data about existing PCI Devices.
====> * get_enabled_modules
        Provides data about which module streams are enabled on the source system.
====> * repositories_blacklist
        Exclude target repositories provided by Red Hat without support.
====> * scan_default_initramfs
        Scan details of the default boot entry's initramfs image.
====> * copy_dnf_conf_into_target_userspace
        Copy dnf.conf into target userspace
====> * nis_scanner
        Collect information about the NIS packages configuration.
====> * scan_sap_hana
        Gathers information related to SAP HANA instances on the system.
====> * firewalld_collect_global_config
        This actor reads firewalld's configuration and produces Model
====> * scan_custom_modifications_actor
        Collects information about files in leapp directories that have been modified or newly added.
====> * rpm_scanner
        Provides data about installed RPM Packages.
====> * scan_fips
        Determine whether the source system has FIPS enabled.
====> * luks_scanner
        Provides data about active LUKS devices.
====> * scancpu
        Scan CPUs of the machine.
====> * get_installed_desktops
        Actor checks if kde or gnome desktop environments
====> * remove_obsolete_gpg_keys
        Remove obsoleted RPM GPG keys.
====> * selinuxcontentscanner
        Scan the system for any SELinux customizations
====> * xfs_info_scanner
        This actor scans all mounted mountpoints for XFS information.
====> * detect_kernel_drivers
        Matches all currently loaded kernel drivers against known deprecated and removed drivers.
====> * distribution_signed_rpm_scanner
        Provide data about distribution signed & third-party RPM packages.
====> * vdo_conversion_scanner
        Provides conversion info about VDO devices.
====> * scan_hybrid_image_azure
        Check if the system is using Azure hybrid image.
====> * trusted_gpg_keys_scanner
        Scan for trusted GPG keys.
====> * checkrhui
        Check if system is using RHUI infrastructure (on public cloud) and send messages to
====> * used_repository_scanner
        Scan used enabled repositories
====> * scan_source_kernel
        Scan the source system kernel.
====> * scan_dynamic_linker_configuration
        Scan the dynamic linker configuration and find modifications.
====> * multipath_conf_read_8to9
        Read multipath configuration files and extract the necessary information
====> * ipa_scanner
        Scan system for ipa-client and ipa-server status
====> * rpm_transaction_config_tasks_collector
        Provides additional RPM transaction tasks from /etc/leapp/transaction.
====> * satellite_upgrade_facts
        Report which Satellite packages require updates and how to handle PostgreSQL data
====> * satellite_upgrade_services
        Reconfigure Satellite services
====> * pes_events_scanner
        Provides data about package events from Package Evolution Service.
====> * setuptargetrepos
        Produces list of repositories that should be available to be used during IPU process.
==> Processing phase `Checks`
====> * unsupported_upgrade_check
        Checks environment variables and produces a warning report if the upgrade is unsupported.
====> * checkmemory
        The actor check the size of RAM against RHEL8 minimal hardware requirements
====> * mysql_check
        Actor checking for presence of MySQL installation.
====> * bacula_check
        Actor checking for presence of Bacula installation.
====> * check_os_release
        Check if the current RHEL minor version is supported. If not, inhibit the upgrade process.
====> * check_nvidia_proprietary_driver
        Check if NVIDIA proprietary driver is in use. If yes, inhibit the upgrade process.
====> * check_deprecated_rpm_signature
        Check whether any packages signed by RSA/SHA1 are installed
====> * emit_net_naming_scheme
        Emit necessary modifications of the upgrade environment and target command line to use net.naming-scheme.
====> * cephvolumescan
        Retrieves the list of encrypted Ceph OSD
====> * dotnet_unsupported_versions_check
        Check for installed .NET versions that are no longer supported.
====> * check_installed_kernels
        Inhibit IPU (in-place upgrade) when installed kernels conflict with a safe upgrade.
====> * checkblacklistca
        No documentation has been provided for the checkblacklistca actor.
====> * check_insights_auto_register
        Checks if system can be automatically registered into Red Hat Insights
====> * firewalld_check_allow_zone_drifting
        This actor will check if AllowZoneDrifting=yes in firewalld.conf. This
====> * check_target_iso
        Check that the provided target ISO is a valid ISO image and is located on a persistent partition.
====> * mariadb_check
        Actor checking for presence of MariaDB installation.
====> * roce_check
        Check whether RoCE is used on the system and well configured for the upgrade.
====> * check_boot_avail_space
        Check if at least 100Mib of available space on /boot. If not, inhibit the upgrade process.
====> * check_fstab_mount_order
        Checks order of entries in /etc/fstab based on their mount point and inhibits upgrade if overshadowing is detected.
====> * check_valid_grubcfg_hybrid
        Check potential for boot failures in Azure Gen1 VMs due to invalid grubcfg
====> * check_consumed_assets
        Check whether Leapp is using correct data assets.
====> * open_ssh_subsystem_sftp
        The RHEL9 changes the SCP to use SFTP protocol internally. The both RHEL8 and RHEL9
====> * check_bls_grub_onppc64
        Check whether GRUB config is BLS aware on RHEL 8 ppc64le systems
====> * check_custom_modifications_actor
        Checks CustomModifications messages and produces a report about files in leapp directories that have been
====> * check_kpatch
        Carry over kpatch-dnf and it's config into the container
====> * check_detected_devices_and_drivers
        Checks whether or not detected devices and drivers are usable on the target system.
====> * check_openssl_conf
        Check whether the openssl configuration and openssl-IBMCA.
====> * check_dynamic_linker_configuration
        Check for customization of dynamic linker configuration.
====> * check_etc_releasever
        Check releasever info and provide a guidance based on the facts
====> * openssh_permit_root_login
        OpenSSH no longer allows root logins with password.
====> * check_fips
        Inhibit upgrade if FIPS is detected as enabled.
====> * check_rhsmsku
        Ensure the system is subscribed to the subscription manager
====> * check_sap_hana
        If SAP HANA has been detected, several checks are performed to ensure a successful upgrade.
====> * checktargetrepos
        Check whether target yum repositories are specified.
====> * check_grub_core
        Check whether we are on legacy (BIOS) system and instruct Leapp to upgrade GRUB core
====> * postgresql_check
        Actor checking for presence of PostgreSQL installation.
====> * check_vdo
        Check if VDO devices need to be migrated to lvm management.
====> * check_ifcfg
        Ensures that ifcfg files are compatible with NetworkManager
====> * check_ipa_server
        Check for ipa-server and inhibit upgrade
====> * efi_check_boot
        Adjust EFI boot entry for first reboot
====> * check_arm_bootloader
        Install required RPM packages for ARM system upgrades on paths with
====> * check_luks
        Check if any encrypted partitions are in use and whether they are supported for the upgrade.
====> * sssd_check_8to9
        Check SSSD configuration for changes in RHEL9 and report them in model.
====> * distribution_signed_rpm_check
        Check if there are any packages that are not signed by distribution GPG keys.
====> * check_microarchitecture
        Inhibit if RHEL9 microarchitecture requirements are not satisfied
====> * xorgdrvcheck8to9
        Warn if Xorg deprecated drivers are in use.
====> * check_mount_options
        Check for mount options preventing the upgrade.
====> * check_nfs
        Check if NFS filesystem is in use. If yes, inhibit the upgrade process.
====> * open_ssl_config_check
        The OpenSSL configuration changed between RHEL8 and RHEL9 significantly with the rebase to
====> * check_cifs
        Check if CIFS filesystem is in use. If yes, inhibit the upgrade process.
====> * check_persistent_mounts
        Check if mounts required to be persistent are mounted in persistent fashion.
====> * firewalld_check_service_tftp_client
        This actor will inhibit if firewalld's configuration is using service
====> * multipath_conf_check_8to9
        Checks if changes to the multipath configuration files are necessary
====> * nis_check
        Checks if any of NIS components is installed and configured
====> * check_yum_plugins_enabled
        Checks that the required yum plugins are enabled.
====> * check_skipped_repositories
        Produces a report if any repositories enabled on the system are going to be skipped.
====> * check_root_symlinks
        Check if the symlinks /bin and /lib are relative, not absolute.
====> * detect_grub_config_error
        Check grub configuration for various errors.
====> * open_ssh_drop_in_directory_check
        Trigger a notice that the main sshd_config will be updated to contain
====> * check_target_version
        Check that the target system version is supported by the upgrade process.
====> * check_grubenv_to_file
        Check whether grubenv is a symlink on Azure hybrid images using BIOS.
====> * check_rpm_transaction_events
        Filter RPM transaction events based on installed RPM packages
====> * crypto_policies_check
        This actor consumes previously gathered information about crypto policies on the source
====> * check_systemd_broken_symlinks
        Check whether some systemd symlinks are broken
====> * check_se_linux
        Check SELinux status and produce decision messages for further action.
====> * check_system_arch
        Check if system is running at a supported architecture. If no, inhibit the upgrade process.
====> * network_deprecations
        Ensures that network configuration doesn't rely on unsupported settings
====> * check_skip_phase
        Skip all the subsequent phases until the report phase.
==> Processing phase `Reports`
====> * verify_check_results
        Check all dialogs and notify that user needs to make some choices.
====> * verify_check_results
        Check all generated results messages and notify user about them.

Debug output written to /var/log/leapp/leapp-preupgrade.log

============================================================
                      REPORT OVERVIEW                       
============================================================

Upgrade has been inhibited due to the following problems:
    1. Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.
    2. Use of NFS detected. Upgrade can't proceed
    3. Use of CIFS detected. Upgrade can't proceed

HIGH and MEDIUM severity reports:
    1. Packages available in excluded repositories will not be installed
    2. Upgrade is unsupported
    3. Remote root logins globally allowed using password
    4. GRUB2 core will be automatically updated during the upgrade

Reports summary:
    Errors:                      0
    Inhibitors:                  3
    HIGH severity reports:       4
    MEDIUM severity reports:     0
    LOW severity reports:        1
    INFO severity reports:       3

Before continuing, review the full report below for details about discovered problems and possible remediation instructions:
    A report has been generated at /var/log/leapp/leapp-report.txt
    A report has been generated at /var/log/leapp/leapp-report.json

============================================================
                   END OF REPORT OVERVIEW                   
============================================================

Answerfile has been generated at /var/log/leapp/answerfile
Job ended at 2026-01-12T13:55:38Z
", "encoding": "base64", "source": "/var/log/ripu/ripu.log"} RUNNING HANDLER [infra.leapp.common : Decode ripu.log file] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:26 ok: [managed-node02] => {"ansible_facts": {"ripu_log_file": ["RIPU preupgrade analysis", "Job started at 2026-01-12T13:54:20Z", "", "============================================================", " UNSUPPORTED UPGRADE ", "============================================================", "", "Variable LEAPP_UNSUPPORTED has been detected. Proceeding at your own risk.", "Development variables have been detected:", "- LEAPP_DEVEL_RPMS_ALL_SIGNED=1", "", "============================================================", " UNSUPPORTED UPGRADE ", "============================================================", "", "==> Processing phase `configuration_phase`", "====> * ipu_workflow_config", " IPU workflow config actor", "==> Processing phase `FactsCollection`", "====> * scan_kernel_cmdline", " Scan the kernel command line of the booted system.", "====> * network_manager_read_config", " Provides data about NetworkManager configuration.", "====> * scan_files_for_target_userspace", " Scan the source system and identify files that will be copied into the target userspace when it is created.", "====> * udevadm_info", " Produces data exported by the \"udevadm info\" command.", "====> * check_custom_network_scripts", " Check the existence of custom network-scripts and warn user about possible", "====> * scan_grub_config", " Scan grub configuration files for errors.", "====> * scan_systemd_source", " Provides info about systemd on the source system", "====> * persistentnetnames", " Get network interface information for physical ethernet interfaces of the original system.", "====> * scan_source_files", " Scan files (explicitly specified) of the source system.", "====> * network_manager_connection_scanner", " Scan NetworkManager connection keyfiles", "====> * biosdevname", " Enable biosdevname on the target RHEL system if all interfaces on the source RHEL", "====> * scan_pkg_manager", " Provides data about package manager (yum/dnf)", "====> * scanblacklistca", " Scan the file system for distrusted CA's in the blacklist directory.", "====> * register_ruby_irb_adjustment", " Register a workaround to allow rubygem-irb's directory -> symlink conversion.", "====> * scandasd", " In case of s390x architecture, check whether DASD is used.", "====> * repository_mapping", " Produces message containing repository mapping based on provided file.", "====> * scan_subscription_manager_info", " Scans the current system for subscription manager information", "====> * load_device_driver_deprecation_data", " Loads deprecation data for drivers and devices (PCI & CPU)", "====> * open_ssl_config_scanner", " Read an OpenSSL configuration file for further analysis.", "====> * scan_grub_device_name", " Find the name of the block devices where GRUB is located", "====> * transaction_workarounds", " Provides additional RPM transaction tasks based on bundled RPM packages.", "====> * sssd_facts_8to9", " Check SSSD configuration for changes in RHEL9 and report them in model.", "====> * read_openssh_config", " Collect information about the OpenSSH configuration.", "====> * scanzfcp", " In case of s390x architecture, check whether ZFCP is used.", "====> * scan_custom_repofile", " Scan the custom /etc/leapp/files/leapp_upgrade_repositories.repo repo file.", "====> * persistentnetnamesdisable", " Disable systemd-udevd persistent network naming on machine with single eth0 NIC", "====> * scan_target_os_image", " Scans the provided target OS ISO image to use as a content source for the IPU, if any.", "====> * roce_scanner", " Detect active RoCE NICs on IBM Z machines.", "====> * ifcfg_scanner", " Scan ifcfg files with legacy network configuration", "====> * root_scanner", " Scan the system root directory and produce a message containing", "====> * storage_scanner", " Provides data about storage settings.", "====> * scanmemory", " Scan Memory of the machine.", "====> * firewalld_collect_used_object_names", " This actor reads firewalld's configuration and produces Model", "====> * scanclienablerepo", " Produce CustomTargetRepository based on the LEAPP_ENABLE_REPOS in config.", "====> * scancryptopolicies", " Scan information about system wide set crypto policies including:", "====> * xorgdrvfacts8to9", " Check the journal logs for deprecated Xorg drivers.", "====> * system_facts", " Provides data about many facts from system.", "====> * scan_source_boot_entry", " Scan the default boot entry of the source system.", "====> * pci_devices_scanner", " Provides data about existing PCI Devices.", "====> * get_enabled_modules", " Provides data about which module streams are enabled on the source system.", "====> * repositories_blacklist", " Exclude target repositories provided by Red Hat without support.", "====> * scan_default_initramfs", " Scan details of the default boot entry's initramfs image.", "====> * copy_dnf_conf_into_target_userspace", " Copy dnf.conf into target userspace", "====> * nis_scanner", " Collect information about the NIS packages configuration.", "====> * scan_sap_hana", " Gathers information related to SAP HANA instances on the system.", "====> * firewalld_collect_global_config", " This actor reads firewalld's configuration and produces Model", "====> * scan_custom_modifications_actor", " Collects information about files in leapp directories that have been modified or newly added.", "====> * rpm_scanner", " Provides data about installed RPM Packages.", "====> * scan_fips", " Determine whether the source system has FIPS enabled.", "====> * luks_scanner", " Provides data about active LUKS devices.", "====> * scancpu", " Scan CPUs of the machine.", "====> * get_installed_desktops", " Actor checks if kde or gnome desktop environments", "====> * remove_obsolete_gpg_keys", " Remove obsoleted RPM GPG keys.", "====> * selinuxcontentscanner", " Scan the system for any SELinux customizations", "====> * xfs_info_scanner", " This actor scans all mounted mountpoints for XFS information.", "====> * detect_kernel_drivers", " Matches all currently loaded kernel drivers against known deprecated and removed drivers.", "====> * distribution_signed_rpm_scanner", " Provide data about distribution signed & third-party RPM packages.", "====> * vdo_conversion_scanner", " Provides conversion info about VDO devices.", "====> * scan_hybrid_image_azure", " Check if the system is using Azure hybrid image.", "====> * trusted_gpg_keys_scanner", " Scan for trusted GPG keys.", "====> * checkrhui", " Check if system is using RHUI infrastructure (on public cloud) and send messages to", "====> * used_repository_scanner", " Scan used enabled repositories", "====> * scan_source_kernel", " Scan the source system kernel.", "====> * scan_dynamic_linker_configuration", " Scan the dynamic linker configuration and find modifications.", "====> * multipath_conf_read_8to9", " Read multipath configuration files and extract the necessary information", "====> * ipa_scanner", " Scan system for ipa-client and ipa-server status", "====> * rpm_transaction_config_tasks_collector", " Provides additional RPM transaction tasks from /etc/leapp/transaction.", "====> * satellite_upgrade_facts", " Report which Satellite packages require updates and how to handle PostgreSQL data", "====> * satellite_upgrade_services", " Reconfigure Satellite services", "====> * pes_events_scanner", " Provides data about package events from Package Evolution Service.", "====> * setuptargetrepos", " Produces list of repositories that should be available to be used during IPU process.", "==> Processing phase `Checks`", "====> * unsupported_upgrade_check", " Checks environment variables and produces a warning report if the upgrade is unsupported.", "====> * checkmemory", " The actor check the size of RAM against RHEL8 minimal hardware requirements", "====> * mysql_check", " Actor checking for presence of MySQL installation.", "====> * bacula_check", " Actor checking for presence of Bacula installation.", "====> * check_os_release", " Check if the current RHEL minor version is supported. If not, inhibit the upgrade process.", "====> * check_nvidia_proprietary_driver", " Check if NVIDIA proprietary driver is in use. If yes, inhibit the upgrade process.", "====> * check_deprecated_rpm_signature", " Check whether any packages signed by RSA/SHA1 are installed", "====> * emit_net_naming_scheme", " Emit necessary modifications of the upgrade environment and target command line to use net.naming-scheme.", "====> * cephvolumescan", " Retrieves the list of encrypted Ceph OSD", "====> * dotnet_unsupported_versions_check", " Check for installed .NET versions that are no longer supported.", "====> * check_installed_kernels", " Inhibit IPU (in-place upgrade) when installed kernels conflict with a safe upgrade.", "====> * checkblacklistca", " No documentation has been provided for the checkblacklistca actor.", "====> * check_insights_auto_register", " Checks if system can be automatically registered into Red Hat Insights", "====> * firewalld_check_allow_zone_drifting", " This actor will check if AllowZoneDrifting=yes in firewalld.conf. This", "====> * check_target_iso", " Check that the provided target ISO is a valid ISO image and is located on a persistent partition.", "====> * mariadb_check", " Actor checking for presence of MariaDB installation.", "====> * roce_check", " Check whether RoCE is used on the system and well configured for the upgrade.", "====> * check_boot_avail_space", " Check if at least 100Mib of available space on /boot. If not, inhibit the upgrade process.", "====> * check_fstab_mount_order", " Checks order of entries in /etc/fstab based on their mount point and inhibits upgrade if overshadowing is detected.", "====> * check_valid_grubcfg_hybrid", " Check potential for boot failures in Azure Gen1 VMs due to invalid grubcfg", "====> * check_consumed_assets", " Check whether Leapp is using correct data assets.", "====> * open_ssh_subsystem_sftp", " The RHEL9 changes the SCP to use SFTP protocol internally. The both RHEL8 and RHEL9", "====> * check_bls_grub_onppc64", " Check whether GRUB config is BLS aware on RHEL 8 ppc64le systems", "====> * check_custom_modifications_actor", " Checks CustomModifications messages and produces a report about files in leapp directories that have been", "====> * check_kpatch", " Carry over kpatch-dnf and it's config into the container", "====> * check_detected_devices_and_drivers", " Checks whether or not detected devices and drivers are usable on the target system.", "====> * check_openssl_conf", " Check whether the openssl configuration and openssl-IBMCA.", "====> * check_dynamic_linker_configuration", " Check for customization of dynamic linker configuration.", "====> * check_etc_releasever", " Check releasever info and provide a guidance based on the facts", "====> * openssh_permit_root_login", " OpenSSH no longer allows root logins with password.", "====> * check_fips", " Inhibit upgrade if FIPS is detected as enabled.", "====> * check_rhsmsku", " Ensure the system is subscribed to the subscription manager", "====> * check_sap_hana", " If SAP HANA has been detected, several checks are performed to ensure a successful upgrade.", "====> * checktargetrepos", " Check whether target yum repositories are specified.", "====> * check_grub_core", " Check whether we are on legacy (BIOS) system and instruct Leapp to upgrade GRUB core", "====> * postgresql_check", " Actor checking for presence of PostgreSQL installation.", "====> * check_vdo", " Check if VDO devices need to be migrated to lvm management.", "====> * check_ifcfg", " Ensures that ifcfg files are compatible with NetworkManager", "====> * check_ipa_server", " Check for ipa-server and inhibit upgrade", "====> * efi_check_boot", " Adjust EFI boot entry for first reboot", "====> * check_arm_bootloader", " Install required RPM packages for ARM system upgrades on paths with", "====> * check_luks", " Check if any encrypted partitions are in use and whether they are supported for the upgrade.", "====> * sssd_check_8to9", " Check SSSD configuration for changes in RHEL9 and report them in model.", "====> * distribution_signed_rpm_check", " Check if there are any packages that are not signed by distribution GPG keys.", "====> * check_microarchitecture", " Inhibit if RHEL9 microarchitecture requirements are not satisfied", "====> * xorgdrvcheck8to9", " Warn if Xorg deprecated drivers are in use.", "====> * check_mount_options", " Check for mount options preventing the upgrade.", "====> * check_nfs", " Check if NFS filesystem is in use. If yes, inhibit the upgrade process.", "====> * open_ssl_config_check", " The OpenSSL configuration changed between RHEL8 and RHEL9 significantly with the rebase to", "====> * check_cifs", " Check if CIFS filesystem is in use. If yes, inhibit the upgrade process.", "====> * check_persistent_mounts", " Check if mounts required to be persistent are mounted in persistent fashion.", "====> * firewalld_check_service_tftp_client", " This actor will inhibit if firewalld's configuration is using service", "====> * multipath_conf_check_8to9", " Checks if changes to the multipath configuration files are necessary", "====> * nis_check", " Checks if any of NIS components is installed and configured", "====> * check_yum_plugins_enabled", " Checks that the required yum plugins are enabled.", "====> * check_skipped_repositories", " Produces a report if any repositories enabled on the system are going to be skipped.", "====> * check_root_symlinks", " Check if the symlinks /bin and /lib are relative, not absolute.", "====> * detect_grub_config_error", " Check grub configuration for various errors.", "====> * open_ssh_drop_in_directory_check", " Trigger a notice that the main sshd_config will be updated to contain", "====> * check_target_version", " Check that the target system version is supported by the upgrade process.", "====> * check_grubenv_to_file", " Check whether grubenv is a symlink on Azure hybrid images using BIOS.", "====> * check_rpm_transaction_events", " Filter RPM transaction events based on installed RPM packages", "====> * crypto_policies_check", " This actor consumes previously gathered information about crypto policies on the source", "====> * check_systemd_broken_symlinks", " Check whether some systemd symlinks are broken", "====> * check_se_linux", " Check SELinux status and produce decision messages for further action.", "====> * check_system_arch", " Check if system is running at a supported architecture. If no, inhibit the upgrade process.", "====> * network_deprecations", " Ensures that network configuration doesn't rely on unsupported settings", "====> * check_skip_phase", " Skip all the subsequent phases until the report phase.", "==> Processing phase `Reports`", "====> * verify_check_results", " Check all dialogs and notify that user needs to make some choices.", "====> * verify_check_results", " Check all generated results messages and notify user about them.", "", "Debug output written to /var/log/leapp/leapp-preupgrade.log", "", "============================================================", " REPORT OVERVIEW ", "============================================================", "", "Upgrade has been inhibited due to the following problems:", " 1. Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.", " 2. Use of NFS detected. Upgrade can't proceed", " 3. Use of CIFS detected. Upgrade can't proceed", "", "HIGH and MEDIUM severity reports:", " 1. Packages available in excluded repositories will not be installed", " 2. Upgrade is unsupported", " 3. Remote root logins globally allowed using password", " 4. GRUB2 core will be automatically updated during the upgrade", "", "Reports summary:", " Errors: 0", " Inhibitors: 3", " HIGH severity reports: 4", " MEDIUM severity reports: 0", " LOW severity reports: 1", " INFO severity reports: 3", "", "Before continuing, review the full report below for details about discovered problems and possible remediation instructions:", " A report has been generated at /var/log/leapp/leapp-report.txt", " A report has been generated at /var/log/leapp/leapp-report.json", "", "============================================================", " END OF REPORT OVERVIEW ", "============================================================", "", "Answerfile has been generated at /var/log/leapp/answerfile", "Job ended at 2026-01-12T13:55:38Z", ""]}, "changed": false} RUNNING HANDLER [infra.leapp.common : Rename log file] ************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:32 changed: [managed-node02] => {"changed": true, "cmd": "export PATH=$PATH\nmv /var/log/ripu/ripu.log /var/log/ripu/ripu.log-20260112T085408\n", "delta": "0:00:00.004556", "end": "2026-01-12 08:55:39.334022", "msg": "", "rc": 0, "start": "2026-01-12 08:55:39.329466", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} RUNNING HANDLER [infra.leapp.common : Check for log file] ********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:3 ok: [managed-node02] => {"changed": false, "stat": {"exists": false}} RUNNING HANDLER [infra.leapp.common : Add end time to log file] **************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:9 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Slurp ripu.log file] ********************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:19 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Decode ripu.log file] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:26 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Rename log file] ************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:32 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.analysis : Display inhibitors] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/handlers/main.yml:32 ok: [managed-node02] => { "results_inhibitors.stdout_lines": [ "Risk Factor: high (inhibitor)", "Title: Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.", "Summary: Support for the following RHEL 8 device drivers has been removed in RHEL 9:", " - dnet", " - liquidio", " - dlci", "", "Related links:", " - Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\": https://access.redhat.com/solutions/6971716", " - Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\": https://access.redhat.com/solutions/5436131", "Key: 7ae2961239eec9905e2580fa6309a589b1dca953", "----------------------------------------", "Risk Factor: high (inhibitor)", "Title: Use of NFS detected. Upgrade can't proceed", "Summary: NFS is currently not supported by the inplace upgrade.", "We have found NFS usage at the following locations:", "- NFS shares found in /etc/fstab:", " - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat", " - nest.test.redhat.com:/mnt/qa /mnt/qa", " - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive", " - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist", " - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew", " - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch", "", "Related links:", " - Why does leapp upgrade fail on detecting NFS during upgrade?: https://access.redhat.com/solutions/6964006", "Remediation: [hint] Disable NFS temporarily for the upgrade if possible.", "Key: 9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "----------------------------------------", "Risk Factor: high (inhibitor)", "Title: Use of CIFS detected. Upgrade can't proceed", "Summary: CIFS is currently not supported by the inplace upgrade.", "Related links:", " - Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\": https://access.redhat.com/solutions/6964304", "Remediation: [hint] Comment out CIFS entries to proceed with the upgrade.", "Key: d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a", "----------------------------------------" ] } RUNNING HANDLER [infra.leapp.analysis : Display errors] ************************ task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/handlers/main.yml:40 skipping: [managed-node02] => {} RUNNING HANDLER [infra.leapp.analysis : Preupgrade analysis report is done] **** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/handlers/main.yml:48 ok: [managed-node02] => { "msg": "The preupgrade analysis report generation is now complete. WARNING: Inhibitors found. Review the tasks above or the result file at /var/log/leapp/leapp-report.txt." } TASK [common_upgrade_tasks | Show all inhibitors collected by analysis] ******** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:47 ok: [managed-node02] => { "leapp_inhibitors | default([])": [ { "actor": "check_detected_devices_and_drivers", "audience": "sysadmin", "detail": { "external": [ { "title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/6971716" }, { "title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/5436131" } ] }, "groups": [ "kernel", "drivers", "inhibitor" ], "hostname": "managed-node02", "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec", "key": "7ae2961239eec9905e2580fa6309a589b1dca953", "severity": "high", "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n", "timeStamp": "2026-01-12T13:55:09.387759Z", "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed." }, { "actor": "check_nfs", "audience": "sysadmin", "detail": { "external": [ { "title": "Why does leapp upgrade fail on detecting NFS during upgrade?", "url": "https://access.redhat.com/solutions/6964006" } ], "related_resources": [ { "scheme": "file", "title": "/etc/fstab" } ], "remediations": [ { "context": "Disable NFS temporarily for the upgrade if possible.", "type": "hint" } ] }, "groups": [ "filesystem", "network", "inhibitor" ], "hostname": "managed-node02", "id": "2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037", "key": "9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "severity": "high", "summary": "NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n", "timeStamp": "2026-01-12T13:55:11.142353Z", "title": "Use of NFS detected. Upgrade can't proceed" }, { "actor": "check_cifs", "audience": "sysadmin", "detail": { "external": [ { "title": "Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\"", "url": "https://access.redhat.com/solutions/6964304" } ], "related_resources": [ { "scheme": "file", "title": "/etc/fstab" } ], "remediations": [ { "context": "Comment out CIFS entries to proceed with the upgrade.", "type": "hint" } ] }, "groups": [ "filesystem", "network", "inhibitor" ], "hostname": "managed-node02", "id": "6a06bcae8d148e7123d9fb89c4338a0adaaa89b1927bdd25a9a2156bc2dee822", "key": "d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a", "severity": "high", "summary": "CIFS is currently not supported by the inplace upgrade.", "timeStamp": "2026-01-12T13:55:11.287236Z", "title": "Use of CIFS detected. Upgrade can't proceed" } ] } TASK [common_upgrade_tasks | Extract inhibitor titles] ************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:51 ok: [managed-node02] => {"ansible_facts": {"inhibitor_titles": ["Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.", "Use of NFS detected. Upgrade can't proceed", "Use of CIFS detected. Upgrade can't proceed"]}, "changed": false} TASK [common_upgrade_tasks | Initialize remediation_todo] ********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:55 ok: [managed-node02] => {"ansible_facts": {"leapp_remediation_todo": []}, "changed": false} TASK [common_upgrade_tasks | Map inhibitors to remediation_todo] *************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:59 ok: [managed-node02] => (item=Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.) => {"ansible_facts": {"leapp_remediation_todo": ["leapp_loaded_removed_kernel_drivers"]}, "ansible_loop_var": "inhibitor_title", "changed": false, "inhibitor_title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."} ok: [managed-node02] => (item=Use of NFS detected. Upgrade can't proceed) => {"ansible_facts": {"leapp_remediation_todo": ["leapp_loaded_removed_kernel_drivers", "leapp_nfs_detected"]}, "ansible_loop_var": "inhibitor_title", "changed": false, "inhibitor_title": "Use of NFS detected. Upgrade can't proceed"} ok: [managed-node02] => (item=Use of CIFS detected. Upgrade can't proceed) => {"ansible_facts": {"leapp_remediation_todo": ["leapp_loaded_removed_kernel_drivers", "leapp_nfs_detected", "leapp_cifs_detected"]}, "ansible_loop_var": "inhibitor_title", "changed": false, "inhibitor_title": "Use of CIFS detected. Upgrade can't proceed"} TASK [common_upgrade_tasks | Debug remediation_todo] *************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:69 ok: [managed-node02] => { "leapp_remediation_todo": [ "leapp_loaded_removed_kernel_drivers", "leapp_nfs_detected", "leapp_cifs_detected" ] } TASK [common_upgrade_tasks | Run remediation] ********************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:73 TASK [infra.leapp.remediate : Check that the leapp-report.json exists] ********* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/main.yml:7 ok: [managed-node02] => {"changed": false, "stat": {"atime": 1768226136.8049357, "attr_flags": "", "attributes": [], "block_size": 4096, "blocks": 24, "charset": "us-ascii", "checksum": "cdf4191065774b7d19f54636697be1702e657507", "ctime": 1768226112.838008, "dev": 51715, "device_type": 0, "executable": false, "exists": true, "gid": 0, "gr_name": "root", "inode": 780140697, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0644", "mtime": 1768226112.838008, "nlink": 1, "path": "/var/log/leapp/leapp-report.json", "pw_name": "root", "readable": true, "rgrp": true, "roth": true, "rusr": true, "size": 12266, "uid": 0, "version": "2829395674", "wgrp": false, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false}} TASK [infra.leapp.remediate : Set leapp_report_missing to true if the leapp-report.json does not exist] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/main.yml:12 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.remediate : Read leapp report] ******************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/main.yml:17 ok: [managed-node02] => {"changed": false, "content": "{
  "entries": [
    {
      "audience": "sysadmin",
      "detail": {
        "remediations": [
          {
            "context": "If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "repository",
        "failure"
      ],
      "key": "1b9132cb2362ae7830e48eee7811be9527747de8",
      "severity": "info",
      "summary": "The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.\n- codeready-builder-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-rhui-rpms\n- codeready-builder-beta-for-rhel-9-aarch64-rpms\n- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms\n- codeready-builder-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-beta-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-aarch64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-rpms\n- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-for-rhel-9-s390x-eus-rpms\n- codeready-builder-for-rhel-9-ppc64le-eus-rpms\n- codeready-builder-for-rhel-9-aarch64-rpms\n- crb",
      "title": "Excluded target system repositories",
      "timeStamp": "2026-01-12T13:54:50.273616Z",
      "hostname": "managed-node02",
      "actor": "repositories_blacklist",
      "id": "0f07a5448003e83a04bb526016d4b33e328da97de8e696a359b21d29d6dd0ca2"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "related_resources": [
          {
            "scheme": "package",
            "title": "jitterentropy-devel"
          }
        ]
      },
      "groups": [
        "repository"
      ],
      "key": "2437e204808f987477c0e9be8e4c95b3a87a9f3e",
      "severity": "high",
      "summary": "1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled \"Excluded target system repositories\" for details.\nThe list of these packages:\n- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)",
      "title": "Packages available in excluded repositories will not be installed",
      "timeStamp": "2026-01-12T13:55:07.330503Z",
      "hostname": "managed-node02",
      "actor": "pes_events_scanner",
      "id": "f03da8195ba01808f011f834a4196c501d6b3f18b7e7e3bae7a4ee453934e11d"
    },
    {
      "audience": "sysadmin",
      "groups": [
        "upgrade process",
        "sanity"
      ],
      "key": "9e5088e3c1f371e020ec777c3d86578f4be143cf",
      "severity": "high",
      "summary": "Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.\n",
      "title": "Upgrade is unsupported",
      "timeStamp": "2026-01-12T13:55:07.484475Z",
      "hostname": "managed-node02",
      "actor": "unsupported_upgrade_check",
      "id": "3fc40063b0b979e99eea5cf0238752492a31d3dffc4bc98f50f595419afb7a4d"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "external": [
          {
            "title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"",
            "url": "https://access.redhat.com/solutions/6971716"
          },
          {
            "title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"",
            "url": "https://access.redhat.com/solutions/5436131"
          }
        ]
      },
      "groups": [
        "kernel",
        "drivers",
        "inhibitor"
      ],
      "key": "7ae2961239eec9905e2580fa6309a589b1dca953",
      "severity": "high",
      "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n     - dnet\n     - liquidio\n     - dlci\n",
      "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.",
      "timeStamp": "2026-01-12T13:55:09.387759Z",
      "hostname": "managed-node02",
      "actor": "check_detected_devices_and_drivers",
      "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "related_resources": [
          {
            "scheme": "package",
            "title": "openssh-server"
          },
          {
            "scheme": "file",
            "title": "/etc/ssh/sshd_config"
          }
        ],
        "remediations": [
          {
            "context": "If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "authentication",
        "security",
        "network",
        "services"
      ],
      "key": "e738f78bc8f3a84411a4210e3b609057139d1855",
      "severity": "high",
      "summary": "RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.",
      "title": "Remote root logins globally allowed using password",
      "timeStamp": "2026-01-12T13:55:09.674314Z",
      "hostname": "managed-node02",
      "actor": "openssh_permit_root_login",
      "id": "a2e756b7234ca6ce24ffed93d514fa68491afcef9e093c19a5758b6bd59e4f24"
    },
    {
      "audience": "sysadmin",
      "groups": [
        "boot"
      ],
      "key": "ac7030e05d2ee248d34f08a9fa040b352bc410a3",
      "severity": "high",
      "summary": "On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running \"grub2-install\" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.",
      "title": "GRUB2 core will be automatically updated during the upgrade",
      "timeStamp": "2026-01-12T13:55:10.220125Z",
      "hostname": "managed-node02",
      "actor": "check_grub_core",
      "id": "324a17d8b1d3245e455322b53661791ef6a3c9ecd9a48dcc752b1317a290a010"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "external": [
          {
            "title": "Why does leapp upgrade fail on detecting NFS during upgrade?",
            "url": "https://access.redhat.com/solutions/6964006"
          }
        ],
        "related_resources": [
          {
            "scheme": "file",
            "title": "/etc/fstab"
          }
        ],
        "remediations": [
          {
            "context": "Disable NFS temporarily for the upgrade if possible.",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "filesystem",
        "network",
        "inhibitor"
      ],
      "key": "9881b25faceeeaa7a6478bcdac29afd7f6baaaed",
      "severity": "high",
      "summary": "NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n",
      "title": "Use of NFS detected. Upgrade can't proceed",
      "timeStamp": "2026-01-12T13:55:11.142353Z",
      "hostname": "managed-node02",
      "actor": "check_nfs",
      "id": "2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "external": [
          {
            "title": "Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\"",
            "url": "https://access.redhat.com/solutions/6964304"
          }
        ],
        "related_resources": [
          {
            "scheme": "file",
            "title": "/etc/fstab"
          }
        ],
        "remediations": [
          {
            "context": "Comment out CIFS entries to proceed with the upgrade.",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "filesystem",
        "network",
        "inhibitor"
      ],
      "key": "d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a",
      "severity": "high",
      "summary": "CIFS is currently not supported by the inplace upgrade.",
      "title": "Use of CIFS detected. Upgrade can't proceed",
      "timeStamp": "2026-01-12T13:55:11.287236Z",
      "hostname": "managed-node02",
      "actor": "check_cifs",
      "id": "6a06bcae8d148e7123d9fb89c4338a0adaaa89b1927bdd25a9a2156bc2dee822"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "related_resources": [
          {
            "scheme": "package",
            "title": "openssh-server"
          },
          {
            "scheme": "file",
            "title": "/etc/ssh/sshd_config"
          }
        ]
      },
      "groups": [
        "authentication",
        "security",
        "network",
        "services"
      ],
      "key": "96da6937c25c6492e4f1228ee146795989fd3718",
      "severity": "info",
      "summary": "OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`",
      "title": "The upgrade will prepend the Include directive to OpenSSH sshd_config",
      "timeStamp": "2026-01-12T13:55:12.091208Z",
      "hostname": "managed-node02",
      "actor": "open_ssh_drop_in_directory_check",
      "id": "1aa85a7300eb2cdc66fd34590ca8170d0ff1a7330a2a0fdfded6086cbad84b17"
    },
    {
      "audience": "sysadmin",
      "groups": [
        "selinux",
        "security"
      ],
      "key": "8fb81863f8413bd617c2a55b69b8e10ff03d7c72",
      "severity": "info",
      "summary": "SElinux relabeling will be scheduled as the status is permissive/enforcing.",
      "title": "SElinux relabeling will be scheduled",
      "timeStamp": "2026-01-12T13:55:12.469366Z",
      "hostname": "managed-node02",
      "actor": "check_se_linux",
      "id": "07d9135d924068cc5ca6284e5496442221635888f07b0644b33ee42f99331bf8"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "remediations": [
          {
            "context": "Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the \"/root/tmp_leapp_py3\" SElinux warnings.",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "selinux",
        "security"
      ],
      "key": "39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f",
      "severity": "low",
      "summary": "SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.",
      "title": "SElinux will be set to permissive mode",
      "timeStamp": "2026-01-12T13:55:12.471808Z",
      "hostname": "managed-node02",
      "actor": "check_se_linux",
      "id": "2d50fc721d27a76536f935c597cec547de25b8ec82ad77270dca0bd552929716"
    }
  ],
  "leapp_run_id": "976bbc19-67c1-42f4-8c1e-b3e9cfea1360"
}
", "encoding": "base64", "source": "/var/log/leapp/leapp-report.json"} TASK [infra.leapp.remediate : Parse leapp report] ****************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/main.yml:23 ok: [managed-node02] => {"ansible_facts": {"leapp_report_data": {"entries": [{"actor": "repositories_blacklist", "audience": "sysadmin", "detail": {"remediations": [{"context": "If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).", "type": "hint"}]}, "groups": ["repository", "failure"], "hostname": "managed-node02", "id": "0f07a5448003e83a04bb526016d4b33e328da97de8e696a359b21d29d6dd0ca2", "key": "1b9132cb2362ae7830e48eee7811be9527747de8", "severity": "info", "summary": "The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.\n- codeready-builder-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-rhui-rpms\n- codeready-builder-beta-for-rhel-9-aarch64-rpms\n- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms\n- codeready-builder-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-beta-for-rhel-9-s390x-rpms\n- codeready-builder-beta-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-aarch64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-eus-rpms\n- codeready-builder-for-rhel-9-x86_64-rpms\n- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-for-rhel-9-s390x-eus-rpms\n- codeready-builder-for-rhel-9-ppc64le-eus-rpms\n- codeready-builder-for-rhel-9-aarch64-rpms\n- crb", "timeStamp": "2026-01-12T13:54:50.273616Z", "title": "Excluded target system repositories"}, {"actor": "pes_events_scanner", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "jitterentropy-devel"}]}, "groups": ["repository"], "hostname": "managed-node02", "id": "f03da8195ba01808f011f834a4196c501d6b3f18b7e7e3bae7a4ee453934e11d", "key": "2437e204808f987477c0e9be8e4c95b3a87a9f3e", "severity": "high", "summary": "1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled \"Excluded target system repositories\" for details.\nThe list of these packages:\n- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)", "timeStamp": "2026-01-12T13:55:07.330503Z", "title": "Packages available in excluded repositories will not be installed"}, {"actor": "unsupported_upgrade_check", "audience": "sysadmin", "groups": ["upgrade process", "sanity"], "hostname": "managed-node02", "id": "3fc40063b0b979e99eea5cf0238752492a31d3dffc4bc98f50f595419afb7a4d", "key": "9e5088e3c1f371e020ec777c3d86578f4be143cf", "severity": "high", "summary": "Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.\n", "timeStamp": "2026-01-12T13:55:07.484475Z", "title": "Upgrade is unsupported"}, {"actor": "check_detected_devices_and_drivers", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/6971716"}, {"title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/5436131"}]}, "groups": ["kernel", "drivers", "inhibitor"], "hostname": "managed-node02", "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec", "key": "7ae2961239eec9905e2580fa6309a589b1dca953", "severity": "high", "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n", "timeStamp": "2026-01-12T13:55:09.387759Z", "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."}, {"actor": "openssh_permit_root_login", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "openssh-server"}, {"scheme": "file", "title": "/etc/ssh/sshd_config"}], "remediations": [{"context": "If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.", "type": "hint"}]}, "groups": ["authentication", "security", "network", "services"], "hostname": "managed-node02", "id": "a2e756b7234ca6ce24ffed93d514fa68491afcef9e093c19a5758b6bd59e4f24", "key": "e738f78bc8f3a84411a4210e3b609057139d1855", "severity": "high", "summary": "RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.", "timeStamp": "2026-01-12T13:55:09.674314Z", "title": "Remote root logins globally allowed using password"}, {"actor": "check_grub_core", "audience": "sysadmin", "groups": ["boot"], "hostname": "managed-node02", "id": "324a17d8b1d3245e455322b53661791ef6a3c9ecd9a48dcc752b1317a290a010", "key": "ac7030e05d2ee248d34f08a9fa040b352bc410a3", "severity": "high", "summary": "On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running \"grub2-install\" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.", "timeStamp": "2026-01-12T13:55:10.220125Z", "title": "GRUB2 core will be automatically updated during the upgrade"}, {"actor": "check_nfs", "audience": "sysadmin", "detail": {"external": [{"title": "Why does leapp upgrade fail on detecting NFS during upgrade?", "url": "https://access.redhat.com/solutions/6964006"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Disable NFS temporarily for the upgrade if possible.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037", "key": "9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "severity": "high", "summary": "NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n", "timeStamp": "2026-01-12T13:55:11.142353Z", "title": "Use of NFS detected. Upgrade can't proceed"}, {"actor": "check_cifs", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\"", "url": "https://access.redhat.com/solutions/6964304"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Comment out CIFS entries to proceed with the upgrade.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "6a06bcae8d148e7123d9fb89c4338a0adaaa89b1927bdd25a9a2156bc2dee822", "key": "d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a", "severity": "high", "summary": "CIFS is currently not supported by the inplace upgrade.", "timeStamp": "2026-01-12T13:55:11.287236Z", "title": "Use of CIFS detected. Upgrade can't proceed"}, {"actor": "open_ssh_drop_in_directory_check", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "openssh-server"}, {"scheme": "file", "title": "/etc/ssh/sshd_config"}]}, "groups": ["authentication", "security", "network", "services"], "hostname": "managed-node02", "id": "1aa85a7300eb2cdc66fd34590ca8170d0ff1a7330a2a0fdfded6086cbad84b17", "key": "96da6937c25c6492e4f1228ee146795989fd3718", "severity": "info", "summary": "OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`", "timeStamp": "2026-01-12T13:55:12.091208Z", "title": "The upgrade will prepend the Include directive to OpenSSH sshd_config"}, {"actor": "check_se_linux", "audience": "sysadmin", "groups": ["selinux", "security"], "hostname": "managed-node02", "id": "07d9135d924068cc5ca6284e5496442221635888f07b0644b33ee42f99331bf8", "key": "8fb81863f8413bd617c2a55b69b8e10ff03d7c72", "severity": "info", "summary": "SElinux relabeling will be scheduled as the status is permissive/enforcing.", "timeStamp": "2026-01-12T13:55:12.469366Z", "title": "SElinux relabeling will be scheduled"}, {"actor": "check_se_linux", "audience": "sysadmin", "detail": {"remediations": [{"context": "Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the \"/root/tmp_leapp_py3\" SElinux warnings.", "type": "hint"}]}, "groups": ["selinux", "security"], "hostname": "managed-node02", "id": "2d50fc721d27a76536f935c597cec547de25b8ec82ad77270dca0bd552929716", "key": "39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f", "severity": "low", "summary": "SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.", "timeStamp": "2026-01-12T13:55:12.471808Z", "title": "SElinux will be set to permissive mode"}], "leapp_run_id": "976bbc19-67c1-42f4-8c1e-b3e9cfea1360"}}, "changed": false} TASK [infra.leapp.remediate : Check that the 6to7 preupgrade report exists] **** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/main.yml:28 ok: [managed-node02] => {"changed": false, "stat": {"exists": false}} TASK [infra.leapp.remediate : Set leapp_report_missing_6to7 to true if the 6to7 preupgrade report does not exist] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/main.yml:33 ok: [managed-node02] => {"ansible_facts": {"leapp_report_missing_6to7": true}, "changed": false} TASK [infra.leapp.remediate : Read 6to7 preupgrade report] ********************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/main.yml:38 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.remediate : Remediate the system] **************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/main.yml:44 included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_cifs_detected.yml for managed-node02 => (item=leapp_cifs_detected) included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_loaded_removed_kernel_drivers.yml for managed-node02 => (item=leapp_loaded_removed_kernel_drivers) included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_nfs_detected.yml for managed-node02 => (item=leapp_nfs_detected) TASK [infra.leapp.remediate : leapp_cifs_detected | Comment CIFS shares in /etc/fstab] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_cifs_detected.yml:4 changed: [managed-node02] => {"changed": true, "msg": "1 replacements made", "rc": 0} TASK [infra.leapp.remediate : leapp_loaded_removed_kernel_drivers | Continue when leapp report is missing] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_loaded_removed_kernel_drivers.yml:2 skipping: [managed-node02] => {} TASK [infra.leapp.remediate : leapp_loaded_removed_kernel_drivers | End execution of playbook if no entry found in leapp report] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_loaded_removed_kernel_drivers.yml:15 skipping: [managed-node02] => {} TASK [infra.leapp.remediate : leapp_loaded_removed_kernel_drivers | Print unsupported modules] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_loaded_removed_kernel_drivers.yml:23 ok: [managed-node02] => { "unsupported_modules": [ "dnet", "liquidio", "dlci" ] } TASK [leapp_loaded_removed_kernel_drivers | Unload unsupported modules] ******** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_loaded_removed_kernel_drivers.yml:27 TASK [infra.leapp.common : manage_kernel_modules | Load or unload kernel modules] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_kernel_modules.yml:5 included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml for managed-node02 => (item=dnet) included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml for managed-node02 => (item=liquidio) included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml for managed-node02 => (item=dlci) TASK [infra.leapp.common : manage_one_kernel_module | Load or unload kernel module] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:5 changed: [managed-node02] => {"changed": true, "name": "dnet", "params": "", "state": "absent"} TASK [infra.leapp.common : manage_one_kernel_module | Disable modules-load.d file entry] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:17 changed: [managed-node02] => {"changed": true, "checksum": "91a7a0bc4840a6a87c0cffccf9e33132e08a5975", "dest": "/etc/modules-load.d/90-dnet.conf", "gid": 0, "group": "root", "md5sum": "6c60d213824e4ba2b79ea0434cc263a7", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:etc_t:s0", "size": 38, "src": "/root/.ansible/tmp/ansible-tmp-1768226142.8196018-8837-273093677350167/source", "state": "file", "uid": 0} TASK [infra.leapp.common : manage_one_kernel_module | Ensure modules are not loaded at boot] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:25 changed: [managed-node02] => {"changed": true, "checksum": "80b564372947ce926eb7aaf9cd866acaacb97054", "dest": "/etc/modprobe.d/dnet.conf", "gid": 0, "group": "root", "md5sum": "231d5e3b5beace6bc6e426d9e8c66e62", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:modules_conf_t:s0", "size": 69, "src": "/root/.ansible/tmp/ansible-tmp-1768226143.5089636-8869-76987309712725/source", "state": "file", "uid": 0} TASK [infra.leapp.common : manage_one_kernel_module | Debug modprobe.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:33 ok: [managed-node02] => {"changed": false, "cmd": ["cat", "/etc/modprobe.d/dnet.conf"], "delta": "0:00:00.002765", "end": "2026-01-12 08:55:44.448959", "msg": "", "rc": 0, "start": "2026-01-12 08:55:44.446194", "stderr": "", "stderr_lines": [], "stdout": "#\n# Ansible managed\n#\n# leapp\n\nblacklist dnet\ninstall dnet /bin/true", "stdout_lines": ["#", "# Ansible managed", "#", "# leapp", "", "blacklist dnet", "install dnet /bin/true"]} TASK [infra.leapp.common : manage_one_kernel_module | Debug modules-load.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:37 ok: [managed-node02] => {"changed": false, "cmd": ["cat", "/etc/modules-load.d/90-dnet.conf"], "delta": "0:00:00.003000", "end": "2026-01-12 08:55:44.816152", "msg": "", "rc": 0, "start": "2026-01-12 08:55:44.813152", "stderr": "", "stderr_lines": [], "stdout": "#\n# Ansible managed\n#\n# leapp\n\n# dnet", "stdout_lines": ["#", "# Ansible managed", "#", "# leapp", "", "# dnet"]} TASK [infra.leapp.common : manage_one_kernel_module | Load or unload kernel module] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:5 changed: [managed-node02] => {"changed": true, "name": "liquidio", "params": "", "state": "absent"} TASK [infra.leapp.common : manage_one_kernel_module | Disable modules-load.d file entry] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:17 changed: [managed-node02] => {"changed": true, "checksum": "366c875292b35d38f38b21c82fbbc59db7e7dee1", "dest": "/etc/modules-load.d/90-liquidio.conf", "gid": 0, "group": "root", "md5sum": "f0f0c505fe0981abf6c5df447207c5cb", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:etc_t:s0", "size": 42, "src": "/root/.ansible/tmp/ansible-tmp-1768226145.330131-8963-200959051293248/source", "state": "file", "uid": 0} TASK [infra.leapp.common : manage_one_kernel_module | Ensure modules are not loaded at boot] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:25 changed: [managed-node02] => {"changed": true, "checksum": "96c9525c5181e2d02f8c7bedcc837f74e8eb7baf", "dest": "/etc/modprobe.d/liquidio.conf", "gid": 0, "group": "root", "md5sum": "a8923a55c189f4d6e836b0c518130677", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:modules_conf_t:s0", "size": 77, "src": "/root/.ansible/tmp/ansible-tmp-1768226146.010452-8993-159780374852322/source", "state": "file", "uid": 0} TASK [infra.leapp.common : manage_one_kernel_module | Debug modprobe.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:33 ok: [managed-node02] => {"changed": false, "cmd": ["cat", "/etc/modprobe.d/liquidio.conf"], "delta": "0:00:00.002819", "end": "2026-01-12 08:55:46.972390", "msg": "", "rc": 0, "start": "2026-01-12 08:55:46.969571", "stderr": "", "stderr_lines": [], "stdout": "#\n# Ansible managed\n#\n# leapp\n\nblacklist liquidio\ninstall liquidio /bin/true", "stdout_lines": ["#", "# Ansible managed", "#", "# leapp", "", "blacklist liquidio", "install liquidio /bin/true"]} TASK [infra.leapp.common : manage_one_kernel_module | Debug modules-load.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:37 ok: [managed-node02] => {"changed": false, "cmd": ["cat", "/etc/modules-load.d/90-liquidio.conf"], "delta": "0:00:00.003004", "end": "2026-01-12 08:55:47.325374", "msg": "", "rc": 0, "start": "2026-01-12 08:55:47.322370", "stderr": "", "stderr_lines": [], "stdout": "#\n# Ansible managed\n#\n# leapp\n\n# liquidio", "stdout_lines": ["#", "# Ansible managed", "#", "# leapp", "", "# liquidio"]} TASK [infra.leapp.common : manage_one_kernel_module | Load or unload kernel module] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:5 changed: [managed-node02] => {"changed": true, "name": "dlci", "params": "", "state": "absent"} TASK [infra.leapp.common : manage_one_kernel_module | Disable modules-load.d file entry] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:17 changed: [managed-node02] => {"changed": true, "checksum": "652a341f553a038d014254a92e8237446eebdc30", "dest": "/etc/modules-load.d/90-dlci.conf", "gid": 0, "group": "root", "md5sum": "fa28d05ac3feb960227c7ca8b3ba957a", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:etc_t:s0", "size": 38, "src": "/root/.ansible/tmp/ansible-tmp-1768226147.787026-9063-247786070355945/source", "state": "file", "uid": 0} TASK [infra.leapp.common : manage_one_kernel_module | Ensure modules are not loaded at boot] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:25 changed: [managed-node02] => {"changed": true, "checksum": "38f7006fbcc380057a08e5913d8fc7b99077454c", "dest": "/etc/modprobe.d/dlci.conf", "gid": 0, "group": "root", "md5sum": "458640820340a947c3ddc3a1ac1eef2b", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:modules_conf_t:s0", "size": 69, "src": "/root/.ansible/tmp/ansible-tmp-1768226148.4552321-9097-275808251085298/source", "state": "file", "uid": 0} TASK [infra.leapp.common : manage_one_kernel_module | Debug modprobe.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:33 ok: [managed-node02] => {"changed": false, "cmd": ["cat", "/etc/modprobe.d/dlci.conf"], "delta": "0:00:00.002900", "end": "2026-01-12 08:55:49.380356", "msg": "", "rc": 0, "start": "2026-01-12 08:55:49.377456", "stderr": "", "stderr_lines": [], "stdout": "#\n# Ansible managed\n#\n# leapp\n\nblacklist dlci\ninstall dlci /bin/true", "stdout_lines": ["#", "# Ansible managed", "#", "# leapp", "", "blacklist dlci", "install dlci /bin/true"]} TASK [infra.leapp.common : manage_one_kernel_module | Debug modules-load.d file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/manage_one_kernel_module.yml:37 ok: [managed-node02] => {"changed": false, "cmd": ["cat", "/etc/modules-load.d/90-dlci.conf"], "delta": "0:00:00.002774", "end": "2026-01-12 08:55:49.723784", "msg": "", "rc": 0, "start": "2026-01-12 08:55:49.721010", "stderr": "", "stderr_lines": [], "stdout": "#\n# Ansible managed\n#\n# leapp\n\n# dlci", "stdout_lines": ["#", "# Ansible managed", "#", "# leapp", "", "# dlci"]} TASK [infra.leapp.remediate : leapp_nfs_detected | Continue when leapp report is missing] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_nfs_detected.yml:2 skipping: [managed-node02] => {} TASK [infra.leapp.remediate : leapp_nfs_detected | End execution of playbook if no entry found in leapp report] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_nfs_detected.yml:15 skipping: [managed-node02] => {} TASK [infra.leapp.remediate : leapp_nfs_detected | Get fstab_entries] ********** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_nfs_detected.yml:25 ok: [managed-node02] => (item=- NFS shares found in /etc/fstab: - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat - nest.test.redhat.com:/mnt/qa /mnt/qa - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch ) => {"ansible_facts": {"fstab_entries": ["ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat", "nest.test.redhat.com:/mnt/qa", "vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive", "nest.test.redhat.com:/mnt/tpsdist", "ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot", "ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch"]}, "ansible_loop_var": "item", "changed": false, "item": "- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n"} TASK [infra.leapp.remediate : leapp_nfs_detected | Get nfs_mounts] ************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_nfs_detected.yml:31 skipping: [managed-node02] => (item=- NFS shares found in /etc/fstab: - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat - nest.test.redhat.com:/mnt/qa /mnt/qa - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch ) => {"ansible_loop_var": "item", "changed": false, "item": "- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n", "skip_reason": "Conditional result was False"} skipping: [managed-node02] => {"changed": false, "msg": "All items skipped"} TASK [infra.leapp.remediate : leapp_nfs_detected | Comment NFS shares in /etc/fstab] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_nfs_detected.yml:37 changed: [managed-node02] => (item=ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat) => {"ansible_loop_var": "item", "changed": true, "cmd": "set -o pipefail\nentry=\"ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat\"\ngrep -qF \"$entry\" /etc/fstab && sed -i \"s|^$entry|# $entry|\" /etc/fstab\n", "delta": "0:00:00.005812", "end": "2026-01-12 08:55:50.293676", "item": "ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat", "msg": "", "rc": 0, "start": "2026-01-12 08:55:50.287864", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} changed: [managed-node02] => (item=nest.test.redhat.com:/mnt/qa) => {"ansible_loop_var": "item", "changed": true, "cmd": "set -o pipefail\nentry=\"nest.test.redhat.com:/mnt/qa\"\ngrep -qF \"$entry\" /etc/fstab && sed -i \"s|^$entry|# $entry|\" /etc/fstab\n", "delta": "0:00:00.005236", "end": "2026-01-12 08:55:50.648856", "item": "nest.test.redhat.com:/mnt/qa", "msg": "", "rc": 0, "start": "2026-01-12 08:55:50.643620", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} changed: [managed-node02] => (item=vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive) => {"ansible_loop_var": "item", "changed": true, "cmd": "set -o pipefail\nentry=\"vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive\"\ngrep -qF \"$entry\" /etc/fstab && sed -i \"s|^$entry|# $entry|\" /etc/fstab\n", "delta": "0:00:00.005933", "end": "2026-01-12 08:55:50.995698", "item": "vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive", "msg": "", "rc": 0, "start": "2026-01-12 08:55:50.989765", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} changed: [managed-node02] => (item=nest.test.redhat.com:/mnt/tpsdist) => {"ansible_loop_var": "item", "changed": true, "cmd": "set -o pipefail\nentry=\"nest.test.redhat.com:/mnt/tpsdist\"\ngrep -qF \"$entry\" /etc/fstab && sed -i \"s|^$entry|# $entry|\" /etc/fstab\n", "delta": "0:00:00.005244", "end": "2026-01-12 08:55:51.356186", "item": "nest.test.redhat.com:/mnt/tpsdist", "msg": "", "rc": 0, "start": "2026-01-12 08:55:51.350942", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} changed: [managed-node02] => (item=ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot) => {"ansible_loop_var": "item", "changed": true, "cmd": "set -o pipefail\nentry=\"ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot\"\ngrep -qF \"$entry\" /etc/fstab && sed -i \"s|^$entry|# $entry|\" /etc/fstab\n", "delta": "0:00:00.005940", "end": "2026-01-12 08:55:51.710474", "item": "ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot", "msg": "", "rc": 0, "start": "2026-01-12 08:55:51.704534", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} changed: [managed-node02] => (item=ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch) => {"ansible_loop_var": "item", "changed": true, "cmd": "set -o pipefail\nentry=\"ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch\"\ngrep -qF \"$entry\" /etc/fstab && sed -i \"s|^$entry|# $entry|\" /etc/fstab\n", "delta": "0:00:00.005564", "end": "2026-01-12 08:55:52.070136", "item": "ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch", "msg": "", "rc": 0, "start": "2026-01-12 08:55:52.064572", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} TASK [infra.leapp.remediate : leapp_nfs_detected | Unmount NFS Mounts] ********* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/remediate/tasks/leapp_nfs_detected.yml:46 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [common_upgrade_tasks | Gather verify remediation tasks] ****************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:77 ok: [managed-node02 -> localhost] => {"changed": false, "examined": 1, "files": [{"atime": 1768225904.3955438, "ctime": 1768225904.093543, "dev": 51716, "gid": 0, "gr_name": "root", "inode": 201326735, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mode": "0644", "mtime": 1768225904.093543, "nlink": 1, "path": "/root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/verify/preupgrade/remediate_cifs.yml", "pw_name": "root", "rgrp": true, "roth": true, "rusr": true, "size": 503, "uid": 0, "wgrp": false, "woth": false, "wusr": true, "xgrp": false, "xoth": false, "xusr": false}], "matched": 1, "msg": "All paths examined", "skipped_paths": {}} TASK [common_upgrade_tasks | Verify remediations] ****************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:85 included: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/verify/preupgrade/remediate_cifs.yml for managed-node02 => (item=/root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/verify/preupgrade/remediate_cifs.yml) TASK [preupgrade | remediate_cifs | Verify the cifs shares remediation] ******** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/verify/preupgrade/remediate_cifs.yml:5 ok: [managed-node02] => {"changed": false, "cmd": ["cat", "/etc/fstab"], "delta": "0:00:00.002820", "end": "2026-01-12 08:55:52.789223", "failed_when_result": false, "msg": "", "rc": 0, "start": "2026-01-12 08:55:52.786403", "stderr": "", "stderr_lines": [], "stdout": "UUID=be7086e1-b01b-487c-8435-4068d6d6b000\t/\txfs\tdefaults\t0\t0\nUUID=CB6E-B696\t/boot/efi\tvfat\tdefaults,uid=0,gid=0,umask=077,shortname=winnt\t0\t2\n# ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat nfs ro,rsize=32768,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0\n# nest.test.redhat.com:/mnt/qa /mnt/qa nfs defaults,rsize=8192,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0\n# vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive nfs ro,rsize=32768,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0\n# nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist nfs defaults,rsize=8192,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0\n# ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew nfs ro,rsize=32768,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0\n# ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch nfs ro,rsize=32768,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0\n# //127.0.0.1/test_remediate_cifs /mnt/cifs cifs username=test,password=test 0 0", "stdout_lines": ["UUID=be7086e1-b01b-487c-8435-4068d6d6b000\t/\txfs\tdefaults\t0\t0", "UUID=CB6E-B696\t/boot/efi\tvfat\tdefaults,uid=0,gid=0,umask=077,shortname=winnt\t0\t2", "# ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat nfs ro,rsize=32768,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0", "# nest.test.redhat.com:/mnt/qa /mnt/qa nfs defaults,rsize=8192,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0", "# vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive nfs ro,rsize=32768,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0", "# nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist nfs defaults,rsize=8192,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0", "# ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew nfs ro,rsize=32768,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0", "# ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch nfs ro,rsize=32768,wsize=8192,bg,noauto,noatime,nosuid,nodev,intr,noauto 0 0", "# //127.0.0.1/test_remediate_cifs /mnt/cifs cifs username=test,password=test 0 0"]} TASK [common_upgrade_tasks | Flush handlers] *********************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:92 META: triggered running handlers for managed-node02 TASK [common_upgrade_tasks | Run analysis after remediation] ******************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:95 TASK [infra.leapp.common : Log directory exists] ******************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:3 ok: [managed-node02] => {"changed": false, "gid": 0, "group": "root", "mode": "0755", "owner": "root", "path": "/var/log/ripu", "secontext": "unconfined_u:object_r:var_log_t:s0", "size": 38, "state": "directory", "uid": 0} TASK [infra.leapp.common : Check for existing log file] ************************ task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:11 ok: [managed-node02] => {"changed": false, "stat": {"exists": false}} TASK [infra.leapp.common : Fail if log file already exists] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:16 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : Create new log file] ******************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:23 NOTIFIED HANDLER infra.leapp.common : Check for log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Add end time to log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Slurp ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Decode ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Rename log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Check for log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Add end time to log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Slurp ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Decode ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Rename log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Check for log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Add end time to log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Slurp ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Decode ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Rename log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Check for log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Add end time to log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Slurp ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Decode ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Rename log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Check for log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Add end time to log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Slurp ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Decode ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Rename log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Check for log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Add end time to log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Slurp ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Decode ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Rename log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Check for log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Add end time to log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Slurp ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Decode ripu.log file for managed-node02 NOTIFIED HANDLER infra.leapp.common : Rename log file for managed-node02 changed: [managed-node02] => {"changed": true, "checksum": "cfcd3b53118ce9e2888f1476ca1dcabc82a839e4", "dest": "/var/log/ripu/ripu.log", "gid": 0, "group": "root", "md5sum": "3eb5e48f8479ae31a5001b3f76b1b5b7", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:var_log_t:s0", "size": 61, "src": "/root/.ansible/tmp/ansible-tmp-1768226153.667629-9337-53680883422695/source", "state": "file", "uid": 0} TASK [infra.leapp.common : /etc/ansible/facts.d directory exists] ************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:35 ok: [managed-node02] => {"changed": false, "gid": 0, "group": "root", "mode": "0755", "owner": "root", "path": "/etc/ansible/facts.d", "secontext": "unconfined_u:object_r:etc_t:s0", "size": 57, "state": "directory", "uid": 0} TASK [infra.leapp.common : Capture current ansible_facts for validation after upgrade] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:43 ok: [managed-node02] => {"changed": false, "checksum": "5f0e3c7532a33a73dc44e3a72d57ba74a88b1ec2", "dest": "/etc/ansible/facts.d/pre_ripu.fact", "gid": 0, "group": "root", "mode": "0644", "owner": "root", "path": "/etc/ansible/facts.d/pre_ripu.fact", "secontext": "system_u:object_r:etc_t:s0", "size": 13829, "state": "file", "uid": 0} TASK [infra.leapp.common : Capture a list of non-rhel versioned packages] ****** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:51 ok: [managed-node02] => {"changed": false, "cmd": "set -o pipefail; export PATH=$PATH; rpm -qa | grep -ve '[\\.|+]el8' | grep -vE '^(gpg-pubkey|libmodulemd|katello-ca-consumer)' | sort", "delta": "0:00:00.855124", "end": "2026-01-12 08:55:56.360353", "failed_when_result": false, "msg": "non-zero return code", "rc": 1, "start": "2026-01-12 08:55:55.505229", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} TASK [infra.leapp.common : Create fact with the non-rhel versioned packages list] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:65 ok: [managed-node02] => {"ansible_facts": {"non_rhel_packages": []}, "changed": false} TASK [infra.leapp.common : Capture the list of non-rhel versioned packages in a separate fact file] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/main.yml:69 ok: [managed-node02] => {"changed": false, "checksum": "97d170e1550eee4afc0af065b78cda302a97674c", "dest": "/etc/ansible/facts.d/non_rhel_packages.fact", "gid": 0, "group": "root", "mode": "0644", "owner": "root", "path": "/etc/ansible/facts.d/non_rhel_packages.fact", "secontext": "system_u:object_r:etc_t:s0", "size": 2, "state": "file", "uid": 0} TASK [infra.leapp.analysis : Include tasks for preupg assistant analysis] ****** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/main.yml:9 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.analysis : Include tasks for leapp preupgrade analysis] ****** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/main.yml:13 included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml for managed-node02 TASK [infra.leapp.analysis : analysis-leapp | Register to leapp activation key] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:2 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [analysis-leapp | Include custom_local_repos for local_repos_pre_leapp] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:14 TASK [infra.leapp.common : custom_local_repos | Remove old /etc/leapp/files/leapp_upgrade_repositories.repo] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:2 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : custom_local_repos | Enable custom upgrade yum repositories] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:9 skipping: [managed-node02] => {"changed": false, "skipped_reason": "No items in the list"} TASK [infra.leapp.analysis : analysis-leapp | Install packages for preupgrade analysis on RHEL 7] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:22 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.analysis : analysis-leapp | Install packages for preupgrade analysis on RHEL 8] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:29 ok: [managed-node02] => {"changed": false, "msg": "Nothing to do", "rc": 0, "results": []} TASK [infra.leapp.analysis : analysis-leapp | Install packages for preupgrade analysis on RHEL 9] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:36 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.analysis : analysis-leapp | Ensure leapp log directory exists] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:43 ok: [managed-node02] => {"changed": false, "gid": 0, "group": "root", "mode": "0700", "owner": "root", "path": "/var/log/leapp", "secontext": "system_u:object_r:var_log_t:s0", "size": 146, "state": "directory", "uid": 0} TASK [infra.leapp.analysis : analysis-leapp | Populate leapp_answers file] ***** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:51 changed: [managed-node02] => {"changed": true, "checksum": "3d934ad808576e3a7fb4c14a89645a4ad55ccf53", "dest": "/var/log/leapp/answerfile", "gid": 0, "group": "root", "md5sum": "01e375235c8e4cafdec593b260354063", "mode": "0644", "owner": "root", "secontext": "system_u:object_r:var_log_t:s0", "size": 48, "src": "/root/.ansible/tmp/ansible-tmp-1768226158.8604283-9448-1900447573188/source", "state": "file", "uid": 0} TASK [analysis-leapp | Create /etc/leapp/files/leapp_upgrade_repositories.repo] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:60 TASK [infra.leapp.common : custom_local_repos | Remove old /etc/leapp/files/leapp_upgrade_repositories.repo] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:2 changed: [managed-node02] => {"changed": true, "path": "/etc/leapp/files/leapp_upgrade_repositories.repo", "state": "absent"} TASK [infra.leapp.common : custom_local_repos | Enable custom upgrade yum repositories] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:9 changed: [managed-node02] => (item={'name': 'rhel-9-for-x86_64-baseos-rpms', 'description': 'BaseOS for x86_64', 'baseurl': '__RHEL_9_6_BASEOS_REPO_URL__', 'state': 'present'}) => {"ansible_loop_var": "item", "changed": true, "item": {"baseurl": "__RHEL_9_6_BASEOS_REPO_URL__", "description": "BaseOS for x86_64", "name": "rhel-9-for-x86_64-baseos-rpms", "state": "present"}, "repo": "rhel-9-for-x86_64-baseos-rpms", "state": "present"} changed: [managed-node02] => (item={'name': 'rhel-9-for-x86_64-appstream-rpms', 'description': 'AppStream for x86_64', 'baseurl': '__RHEL_9_6_APPSTREAM_REPO_URL__', 'state': 'present'}) => {"ansible_loop_var": "item", "changed": true, "item": {"baseurl": "__RHEL_9_6_APPSTREAM_REPO_URL__", "description": "AppStream for x86_64", "name": "rhel-9-for-x86_64-appstream-rpms", "state": "present"}, "repo": "rhel-9-for-x86_64-appstream-rpms", "state": "present"} TASK [infra.leapp.analysis : analysis-leapp | Leapp preupgrade report] ********* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:71 ASYNC FAILED on managed-node02: jid=j474302917601.21604 changed: [managed-node02] => {"ansible_job_id": "j474302917601.21604", "changed": true, "cmd": "set -o pipefail; export PATH=$PATH; ulimit -n 16384; leapp preupgrade --report-schema=1.2.0 --no-rhsm 2>&1 | tee -a /var/log/ripu/ripu.log\n", "delta": "0:00:38.169898", "end": "2026-01-12 08:56:39.188423", "failed_when_result": false, "finished": 1, "msg": "non-zero return code", "rc": 1, "results_file": "/root/.ansible_async/j474302917601.21604", "start": "2026-01-12 08:56:01.018525", "started": 1, "stderr": "", "stderr_lines": [], "stdout": "\n============================================================\n UNSUPPORTED UPGRADE \n============================================================\n\nVariable LEAPP_UNSUPPORTED has been detected. Proceeding at your own risk.\nDevelopment variables have been detected:\n- LEAPP_DEVEL_RPMS_ALL_SIGNED=1\n\n============================================================\n UNSUPPORTED UPGRADE \n============================================================\n\n==> Processing phase `configuration_phase`\n====> * ipu_workflow_config\n IPU workflow config actor\n==> Processing phase `FactsCollection`\n====> * scandasd\n In case of s390x architecture, check whether DASD is used.\n====> * storage_scanner\n Provides data about storage settings.\n====> * firewalld_collect_used_object_names\n This actor reads firewalld's configuration and produces Model\n====> * rpm_scanner\n Provides data about installed RPM Packages.\n====> * scanzfcp\n In case of s390x architecture, check whether ZFCP is used.\n====> * persistentnetnames\n Get network interface information for physical ethernet interfaces of the original system.\n====> * open_ssl_config_scanner\n Read an OpenSSL configuration file for further analysis.\n====> * remove_obsolete_gpg_keys\n Remove obsoleted RPM GPG keys.\n====> * get_enabled_modules\n Provides data about which module streams are enabled on the source system.\n====> * scan_custom_modifications_actor\n Collects information about files in leapp directories that have been modified or newly added.\n====> * network_manager_read_config\n Provides data about NetworkManager configuration.\n====> * distribution_signed_rpm_scanner\n Provide data about distribution signed & third-party RPM packages.\n====> * scan_systemd_source\n Provides info about systemd on the source system\n====> * scanclienablerepo\n Produce CustomTargetRepository based on the LEAPP_ENABLE_REPOS in config.\n====> * nis_scanner\n Collect information about the NIS packages configuration.\n====> * ifcfg_scanner\n Scan ifcfg files with legacy network configuration\n====> * firewalld_collect_global_config\n This actor reads firewalld's configuration and produces Model\n====> * scan_target_os_image\n Scans the provided target OS ISO image to use as a content source for the IPU, if any.\n====> * persistentnetnamesdisable\n Disable systemd-udevd persistent network naming on machine with single eth0 NIC\n====> * vdo_conversion_scanner\n Provides conversion info about VDO devices.\n====> * scan_files_for_target_userspace\n Scan the source system and identify files that will be copied into the target userspace when it is created.\n====> * scan_source_boot_entry\n Scan the default boot entry of the source system.\n====> * scan_source_files\n Scan files (explicitly specified) of the source system.\n====> * luks_scanner\n Provides data about active LUKS devices.\n====> * scan_grub_device_name\n Find the name of the block devices where GRUB is located\n====> * multipath_conf_read_8to9\n Read multipath configuration files and extract the necessary information\n====> * scan_default_initramfs\n Scan details of the default boot entry's initramfs image.\n====> * network_manager_connection_scanner\n Scan NetworkManager connection keyfiles\n====> * copy_dnf_conf_into_target_userspace\n Copy dnf.conf into target userspace\n====> * get_installed_desktops\n Actor checks if kde or gnome desktop environments\n====> * root_scanner\n Scan the system root directory and produce a message containing\n====> * system_facts\n Provides data about many facts from system.\n====> * load_device_driver_deprecation_data\n Loads deprecation data for drivers and devices (PCI & CPU)\n====> * selinuxcontentscanner\n Scan the system for any SELinux customizations\n====> * sssd_facts_8to9\n Check SSSD configuration for changes in RHEL9 and report them in model.\n====> * scancryptopolicies\n Scan information about system wide set crypto policies including:\n====> * scan_source_kernel\n Scan the source system kernel.\n====> * scan_sap_hana\n Gathers information related to SAP HANA instances on the system.\n====> * check_custom_network_scripts\n Check the existence of custom network-scripts and warn user about possible\n====> * read_openssh_config\n Collect information about the OpenSSH configuration.\n====> * xorgdrvfacts8to9\n Check the journal logs for deprecated Xorg drivers.\n====> * biosdevname\n Enable biosdevname on the target RHEL system if all interfaces on the source RHEL\n====> * scan_hybrid_image_azure\n Check if the system is using Azure hybrid image.\n====> * udevadm_info\n Produces data exported by the \"udevadm info\" command.\n====> * scan_pkg_manager\n Provides data about package manager (yum/dnf)\n====> * trusted_gpg_keys_scanner\n Scan for trusted GPG keys.\n====> * scan_grub_config\n Scan grub configuration files for errors.\n====> * register_ruby_irb_adjustment\n Register a workaround to allow rubygem-irb's directory -> symlink conversion.\n====> * roce_scanner\n Detect active RoCE NICs on IBM Z machines.\n====> * checkrhui\n Check if system is using RHUI infrastructure (on public cloud) and send messages to\n====> * transaction_workarounds\n Provides additional RPM transaction tasks based on bundled RPM packages.\n====> * scan_subscription_manager_info\n Scans the current system for subscription manager information\n====> * xfs_info_scanner\n This actor scans all mounted mountpoints for XFS information.\n====> * pci_devices_scanner\n Provides data about existing PCI Devices.\n====> * scan_kernel_cmdline\n Scan the kernel command line of the booted system.\n====> * scan_dynamic_linker_configuration\n Scan the dynamic linker configuration and find modifications.\n====> * scanblacklistca\n Scan the file system for distrusted CA's in the blacklist directory.\n====> * scan_custom_repofile\n Scan the custom /etc/leapp/files/leapp_upgrade_repositories.repo repo file.\n====> * scanmemory\n Scan Memory of the machine.\n====> * repository_mapping\n Produces message containing repository mapping based on provided file.\n====> * used_repository_scanner\n Scan used enabled repositories\n====> * ipa_scanner\n Scan system for ipa-client and ipa-server status\n====> * rpm_transaction_config_tasks_collector\n Provides additional RPM transaction tasks from /etc/leapp/transaction.\n====> * satellite_upgrade_facts\n Report which Satellite packages require updates and how to handle PostgreSQL data\n====> * repositories_blacklist\n Exclude target repositories provided by Red Hat without support.\n====> * detect_kernel_drivers\n Matches all currently loaded kernel drivers against known deprecated and removed drivers.\n====> * scan_fips\n Determine whether the source system has FIPS enabled.\n====> * scancpu\n Scan CPUs of the machine.\n====> * satellite_upgrade_services\n Reconfigure Satellite services\n====> * pes_events_scanner\n Provides data about package events from Package Evolution Service.\n====> * setuptargetrepos\n Produces list of repositories that should be available to be used during IPU process.\n==> Processing phase `Checks`\n====> * check_microarchitecture\n Inhibit if RHEL9 microarchitecture requirements are not satisfied\n====> * check_se_linux\n Check SELinux status and produce decision messages for further action.\n====> * efi_check_boot\n Adjust EFI boot entry for first reboot\n====> * crypto_policies_check\n This actor consumes previously gathered information about crypto policies on the source\n====> * check_root_symlinks\n Check if the symlinks /bin and /lib are relative, not absolute.\n====> * checktargetrepos\n Check whether target yum repositories are specified.\n====> * check_system_arch\n Check if system is running at a supported architecture. If no, inhibit the upgrade process.\n====> * unsupported_upgrade_check\n Checks environment variables and produces a warning report if the upgrade is unsupported.\n====> * check_os_release\n Check if the current RHEL minor version is supported. If not, inhibit the upgrade process.\n====> * open_ssl_config_check\n The OpenSSL configuration changed between RHEL8 and RHEL9 significantly with the rebase to\n====> * multipath_conf_check_8to9\n Checks if changes to the multipath configuration files are necessary\n====> * check_arm_bootloader\n Install required RPM packages for ARM system upgrades on paths with\n====> * nis_check\n Checks if any of NIS components is installed and configured\n====> * check_target_version\n Check that the target system version is supported by the upgrade process.\n====> * open_ssh_drop_in_directory_check\n Trigger a notice that the main sshd_config will be updated to contain\n====> * distribution_signed_rpm_check\n Check if there are any packages that are not signed by distribution GPG keys.\n====> * check_etc_releasever\n Check releasever info and provide a guidance based on the facts\n====> * firewalld_check_allow_zone_drifting\n This actor will check if AllowZoneDrifting=yes in firewalld.conf. This\n====> * xorgdrvcheck8to9\n Warn if Xorg deprecated drivers are in use.\n====> * firewalld_check_service_tftp_client\n This actor will inhibit if firewalld's configuration is using service\n====> * check_skipped_repositories\n Produces a report if any repositories enabled on the system are going to be skipped.\n====> * check_vdo\n Check if VDO devices need to be migrated to lvm management.\n====> * check_target_iso\n Check that the provided target ISO is a valid ISO image and is located on a persistent partition.\n====> * network_deprecations\n Ensures that network configuration doesn't rely on unsupported settings\n====> * emit_net_naming_scheme\n Emit necessary modifications of the upgrade environment and target command line to use net.naming-scheme.\n====> * check_custom_modifications_actor\n Checks CustomModifications messages and produces a report about files in leapp directories that have been\n====> * sssd_check_8to9\n Check SSSD configuration for changes in RHEL9 and report them in model.\n====> * check_insights_auto_register\n Checks if system can be automatically registered into Red Hat Insights\n====> * check_installed_kernels\n Inhibit IPU (in-place upgrade) when installed kernels conflict with a safe upgrade.\n====> * check_sap_hana\n If SAP HANA has been detected, several checks are performed to ensure a successful upgrade.\n====> * mysql_check\n Actor checking for presence of MySQL installation.\n====> * check_nvidia_proprietary_driver\n Check if NVIDIA proprietary driver is in use. If yes, inhibit the upgrade process.\n====> * openssh_permit_root_login\n OpenSSH no longer allows root logins with password.\n====> * check_grub_core\n Check whether we are on legacy (BIOS) system and instruct Leapp to upgrade GRUB core\n====> * detect_grub_config_error\n Check grub configuration for various errors.\n====> * check_mount_options\n Check for mount options preventing the upgrade.\n====> * postgresql_check\n Actor checking for presence of PostgreSQL installation.\n====> * check_fstab_mount_order\n Checks order of entries in /etc/fstab based on their mount point and inhibits upgrade if overshadowing is detected.\n====> * check_systemd_broken_symlinks\n Check whether some systemd symlinks are broken\n====> * bacula_check\n Actor checking for presence of Bacula installation.\n====> * check_valid_grubcfg_hybrid\n Check potential for boot failures in Azure Gen1 VMs due to invalid grubcfg\n====> * cephvolumescan\n Retrieves the list of encrypted Ceph OSD\n====> * check_openssl_conf\n Check whether the openssl configuration and openssl-IBMCA.\n====> * check_yum_plugins_enabled\n Checks that the required yum plugins are enabled.\n====> * check_persistent_mounts\n Check if mounts required to be persistent are mounted in persistent fashion.\n====> * check_deprecated_rpm_signature\n Check whether any packages signed by RSA/SHA1 are installed\n====> * checkblacklistca\n No documentation has been provided for the checkblacklistca actor.\n====> * check_cifs\n Check if CIFS filesystem is in use. If yes, inhibit the upgrade process.\n====> * roce_check\n Check whether RoCE is used on the system and well configured for the upgrade.\n====> * check_boot_avail_space\n Check if at least 100Mib of available space on /boot. If not, inhibit the upgrade process.\n====> * check_ipa_server\n Check for ipa-server and inhibit upgrade\n====> * check_grubenv_to_file\n Check whether grubenv is a symlink on Azure hybrid images using BIOS.\n====> * dotnet_unsupported_versions_check\n Check for installed .NET versions that are no longer supported.\n====> * open_ssh_subsystem_sftp\n The RHEL9 changes the SCP to use SFTP protocol internally. The both RHEL8 and RHEL9\n====> * check_detected_devices_and_drivers\n Checks whether or not detected devices and drivers are usable on the target system.\n====> * check_dynamic_linker_configuration\n Check for customization of dynamic linker configuration.\n====> * check_nfs\n Check if NFS filesystem is in use. If yes, inhibit the upgrade process.\n====> * mariadb_check\n Actor checking for presence of MariaDB installation.\n====> * check_consumed_assets\n Check whether Leapp is using correct data assets.\n====> * checkmemory\n The actor check the size of RAM against RHEL8 minimal hardware requirements\n====> * check_bls_grub_onppc64\n Check whether GRUB config is BLS aware on RHEL 8 ppc64le systems\n====> * check_kpatch\n Carry over kpatch-dnf and it's config into the container\n====> * check_rhsmsku\n Ensure the system is subscribed to the subscription manager\n====> * check_ifcfg\n Ensures that ifcfg files are compatible with NetworkManager\n====> * check_fips\n Inhibit upgrade if FIPS is detected as enabled.\n====> * check_luks\n Check if any encrypted partitions are in use and whether they are supported for the upgrade.\n====> * check_skip_phase\n Skip all the subsequent phases until the report phase.\n====> * check_rpm_transaction_events\n Filter RPM transaction events based on installed RPM packages\n==> Processing phase `TargetTransactionFactsCollection`\n====> * create_iso_repofile\n Create custom repofile containing information about repositories found in target OS installation ISO, if used.\n====> * target_userspace_creator\n Initializes a directory to be populated as a minimal environment to run binaries from the target system.\nBaseOS for x86_64 0.0 B/s | 0 B 00:00 \n\n============================================================\n ERRORS \n============================================================\n\n2026-01-12 08:56:38.945717 [ERROR] Actor: target_userspace_creator\nMessage: Unable to install RHEL 9 userspace packages.\nSummary:\n Details: Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.\n Stderr: Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\n Error: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\n\n============================================================\n END OF ERRORS \n============================================================\n\nDebug output written to /var/log/leapp/leapp-preupgrade.log\n\n============================================================\n REPORT OVERVIEW \n============================================================\n\nFollowing errors occurred and the upgrade cannot continue:\n 1. Actor: target_userspace_creator\n Message: Unable to install RHEL 9 userspace packages.\n\nHIGH and MEDIUM severity reports:\n 1. Packages available in excluded repositories will not be installed\n 2. Upgrade is unsupported\n 3. Remote root logins globally allowed using password\n 4. GRUB2 core will be automatically updated during the upgrade\n\nReports summary:\n Errors: 1\n Inhibitors: 0\n HIGH severity reports: 4\n MEDIUM severity reports: 0\n LOW severity reports: 1\n INFO severity reports: 3\n\nBefore continuing, review the full report below for details about discovered problems and possible remediation instructions:\n A report has been generated at /var/log/leapp/leapp-report.txt\n A report has been generated at /var/log/leapp/leapp-report.json\n\n============================================================\n END OF REPORT OVERVIEW \n============================================================\n\nAnswerfile has been generated at /var/log/leapp/answerfile", "stdout_lines": ["", "============================================================", " UNSUPPORTED UPGRADE ", "============================================================", "", "Variable LEAPP_UNSUPPORTED has been detected. Proceeding at your own risk.", "Development variables have been detected:", "- LEAPP_DEVEL_RPMS_ALL_SIGNED=1", "", "============================================================", " UNSUPPORTED UPGRADE ", "============================================================", "", "==> Processing phase `configuration_phase`", "====> * ipu_workflow_config", " IPU workflow config actor", "==> Processing phase `FactsCollection`", "====> * scandasd", " In case of s390x architecture, check whether DASD is used.", "====> * storage_scanner", " Provides data about storage settings.", "====> * firewalld_collect_used_object_names", " This actor reads firewalld's configuration and produces Model", "====> * rpm_scanner", " Provides data about installed RPM Packages.", "====> * scanzfcp", " In case of s390x architecture, check whether ZFCP is used.", "====> * persistentnetnames", " Get network interface information for physical ethernet interfaces of the original system.", "====> * open_ssl_config_scanner", " Read an OpenSSL configuration file for further analysis.", "====> * remove_obsolete_gpg_keys", " Remove obsoleted RPM GPG keys.", "====> * get_enabled_modules", " Provides data about which module streams are enabled on the source system.", "====> * scan_custom_modifications_actor", " Collects information about files in leapp directories that have been modified or newly added.", "====> * network_manager_read_config", " Provides data about NetworkManager configuration.", "====> * distribution_signed_rpm_scanner", " Provide data about distribution signed & third-party RPM packages.", "====> * scan_systemd_source", " Provides info about systemd on the source system", "====> * scanclienablerepo", " Produce CustomTargetRepository based on the LEAPP_ENABLE_REPOS in config.", "====> * nis_scanner", " Collect information about the NIS packages configuration.", "====> * ifcfg_scanner", " Scan ifcfg files with legacy network configuration", "====> * firewalld_collect_global_config", " This actor reads firewalld's configuration and produces Model", "====> * scan_target_os_image", " Scans the provided target OS ISO image to use as a content source for the IPU, if any.", "====> * persistentnetnamesdisable", " Disable systemd-udevd persistent network naming on machine with single eth0 NIC", "====> * vdo_conversion_scanner", " Provides conversion info about VDO devices.", "====> * scan_files_for_target_userspace", " Scan the source system and identify files that will be copied into the target userspace when it is created.", "====> * scan_source_boot_entry", " Scan the default boot entry of the source system.", "====> * scan_source_files", " Scan files (explicitly specified) of the source system.", "====> * luks_scanner", " Provides data about active LUKS devices.", "====> * scan_grub_device_name", " Find the name of the block devices where GRUB is located", "====> * multipath_conf_read_8to9", " Read multipath configuration files and extract the necessary information", "====> * scan_default_initramfs", " Scan details of the default boot entry's initramfs image.", "====> * network_manager_connection_scanner", " Scan NetworkManager connection keyfiles", "====> * copy_dnf_conf_into_target_userspace", " Copy dnf.conf into target userspace", "====> * get_installed_desktops", " Actor checks if kde or gnome desktop environments", "====> * root_scanner", " Scan the system root directory and produce a message containing", "====> * system_facts", " Provides data about many facts from system.", "====> * load_device_driver_deprecation_data", " Loads deprecation data for drivers and devices (PCI & CPU)", "====> * selinuxcontentscanner", " Scan the system for any SELinux customizations", "====> * sssd_facts_8to9", " Check SSSD configuration for changes in RHEL9 and report them in model.", "====> * scancryptopolicies", " Scan information about system wide set crypto policies including:", "====> * scan_source_kernel", " Scan the source system kernel.", "====> * scan_sap_hana", " Gathers information related to SAP HANA instances on the system.", "====> * check_custom_network_scripts", " Check the existence of custom network-scripts and warn user about possible", "====> * read_openssh_config", " Collect information about the OpenSSH configuration.", "====> * xorgdrvfacts8to9", " Check the journal logs for deprecated Xorg drivers.", "====> * biosdevname", " Enable biosdevname on the target RHEL system if all interfaces on the source RHEL", "====> * scan_hybrid_image_azure", " Check if the system is using Azure hybrid image.", "====> * udevadm_info", " Produces data exported by the \"udevadm info\" command.", "====> * scan_pkg_manager", " Provides data about package manager (yum/dnf)", "====> * trusted_gpg_keys_scanner", " Scan for trusted GPG keys.", "====> * scan_grub_config", " Scan grub configuration files for errors.", "====> * register_ruby_irb_adjustment", " Register a workaround to allow rubygem-irb's directory -> symlink conversion.", "====> * roce_scanner", " Detect active RoCE NICs on IBM Z machines.", "====> * checkrhui", " Check if system is using RHUI infrastructure (on public cloud) and send messages to", "====> * transaction_workarounds", " Provides additional RPM transaction tasks based on bundled RPM packages.", "====> * scan_subscription_manager_info", " Scans the current system for subscription manager information", "====> * xfs_info_scanner", " This actor scans all mounted mountpoints for XFS information.", "====> * pci_devices_scanner", " Provides data about existing PCI Devices.", "====> * scan_kernel_cmdline", " Scan the kernel command line of the booted system.", "====> * scan_dynamic_linker_configuration", " Scan the dynamic linker configuration and find modifications.", "====> * scanblacklistca", " Scan the file system for distrusted CA's in the blacklist directory.", "====> * scan_custom_repofile", " Scan the custom /etc/leapp/files/leapp_upgrade_repositories.repo repo file.", "====> * scanmemory", " Scan Memory of the machine.", "====> * repository_mapping", " Produces message containing repository mapping based on provided file.", "====> * used_repository_scanner", " Scan used enabled repositories", "====> * ipa_scanner", " Scan system for ipa-client and ipa-server status", "====> * rpm_transaction_config_tasks_collector", " Provides additional RPM transaction tasks from /etc/leapp/transaction.", "====> * satellite_upgrade_facts", " Report which Satellite packages require updates and how to handle PostgreSQL data", "====> * repositories_blacklist", " Exclude target repositories provided by Red Hat without support.", "====> * detect_kernel_drivers", " Matches all currently loaded kernel drivers against known deprecated and removed drivers.", "====> * scan_fips", " Determine whether the source system has FIPS enabled.", "====> * scancpu", " Scan CPUs of the machine.", "====> * satellite_upgrade_services", " Reconfigure Satellite services", "====> * pes_events_scanner", " Provides data about package events from Package Evolution Service.", "====> * setuptargetrepos", " Produces list of repositories that should be available to be used during IPU process.", "==> Processing phase `Checks`", "====> * check_microarchitecture", " Inhibit if RHEL9 microarchitecture requirements are not satisfied", "====> * check_se_linux", " Check SELinux status and produce decision messages for further action.", "====> * efi_check_boot", " Adjust EFI boot entry for first reboot", "====> * crypto_policies_check", " This actor consumes previously gathered information about crypto policies on the source", "====> * check_root_symlinks", " Check if the symlinks /bin and /lib are relative, not absolute.", "====> * checktargetrepos", " Check whether target yum repositories are specified.", "====> * check_system_arch", " Check if system is running at a supported architecture. If no, inhibit the upgrade process.", "====> * unsupported_upgrade_check", " Checks environment variables and produces a warning report if the upgrade is unsupported.", "====> * check_os_release", " Check if the current RHEL minor version is supported. If not, inhibit the upgrade process.", "====> * open_ssl_config_check", " The OpenSSL configuration changed between RHEL8 and RHEL9 significantly with the rebase to", "====> * multipath_conf_check_8to9", " Checks if changes to the multipath configuration files are necessary", "====> * check_arm_bootloader", " Install required RPM packages for ARM system upgrades on paths with", "====> * nis_check", " Checks if any of NIS components is installed and configured", "====> * check_target_version", " Check that the target system version is supported by the upgrade process.", "====> * open_ssh_drop_in_directory_check", " Trigger a notice that the main sshd_config will be updated to contain", "====> * distribution_signed_rpm_check", " Check if there are any packages that are not signed by distribution GPG keys.", "====> * check_etc_releasever", " Check releasever info and provide a guidance based on the facts", "====> * firewalld_check_allow_zone_drifting", " This actor will check if AllowZoneDrifting=yes in firewalld.conf. This", "====> * xorgdrvcheck8to9", " Warn if Xorg deprecated drivers are in use.", "====> * firewalld_check_service_tftp_client", " This actor will inhibit if firewalld's configuration is using service", "====> * check_skipped_repositories", " Produces a report if any repositories enabled on the system are going to be skipped.", "====> * check_vdo", " Check if VDO devices need to be migrated to lvm management.", "====> * check_target_iso", " Check that the provided target ISO is a valid ISO image and is located on a persistent partition.", "====> * network_deprecations", " Ensures that network configuration doesn't rely on unsupported settings", "====> * emit_net_naming_scheme", " Emit necessary modifications of the upgrade environment and target command line to use net.naming-scheme.", "====> * check_custom_modifications_actor", " Checks CustomModifications messages and produces a report about files in leapp directories that have been", "====> * sssd_check_8to9", " Check SSSD configuration for changes in RHEL9 and report them in model.", "====> * check_insights_auto_register", " Checks if system can be automatically registered into Red Hat Insights", "====> * check_installed_kernels", " Inhibit IPU (in-place upgrade) when installed kernels conflict with a safe upgrade.", "====> * check_sap_hana", " If SAP HANA has been detected, several checks are performed to ensure a successful upgrade.", "====> * mysql_check", " Actor checking for presence of MySQL installation.", "====> * check_nvidia_proprietary_driver", " Check if NVIDIA proprietary driver is in use. If yes, inhibit the upgrade process.", "====> * openssh_permit_root_login", " OpenSSH no longer allows root logins with password.", "====> * check_grub_core", " Check whether we are on legacy (BIOS) system and instruct Leapp to upgrade GRUB core", "====> * detect_grub_config_error", " Check grub configuration for various errors.", "====> * check_mount_options", " Check for mount options preventing the upgrade.", "====> * postgresql_check", " Actor checking for presence of PostgreSQL installation.", "====> * check_fstab_mount_order", " Checks order of entries in /etc/fstab based on their mount point and inhibits upgrade if overshadowing is detected.", "====> * check_systemd_broken_symlinks", " Check whether some systemd symlinks are broken", "====> * bacula_check", " Actor checking for presence of Bacula installation.", "====> * check_valid_grubcfg_hybrid", " Check potential for boot failures in Azure Gen1 VMs due to invalid grubcfg", "====> * cephvolumescan", " Retrieves the list of encrypted Ceph OSD", "====> * check_openssl_conf", " Check whether the openssl configuration and openssl-IBMCA.", "====> * check_yum_plugins_enabled", " Checks that the required yum plugins are enabled.", "====> * check_persistent_mounts", " Check if mounts required to be persistent are mounted in persistent fashion.", "====> * check_deprecated_rpm_signature", " Check whether any packages signed by RSA/SHA1 are installed", "====> * checkblacklistca", " No documentation has been provided for the checkblacklistca actor.", "====> * check_cifs", " Check if CIFS filesystem is in use. If yes, inhibit the upgrade process.", "====> * roce_check", " Check whether RoCE is used on the system and well configured for the upgrade.", "====> * check_boot_avail_space", " Check if at least 100Mib of available space on /boot. If not, inhibit the upgrade process.", "====> * check_ipa_server", " Check for ipa-server and inhibit upgrade", "====> * check_grubenv_to_file", " Check whether grubenv is a symlink on Azure hybrid images using BIOS.", "====> * dotnet_unsupported_versions_check", " Check for installed .NET versions that are no longer supported.", "====> * open_ssh_subsystem_sftp", " The RHEL9 changes the SCP to use SFTP protocol internally. The both RHEL8 and RHEL9", "====> * check_detected_devices_and_drivers", " Checks whether or not detected devices and drivers are usable on the target system.", "====> * check_dynamic_linker_configuration", " Check for customization of dynamic linker configuration.", "====> * check_nfs", " Check if NFS filesystem is in use. If yes, inhibit the upgrade process.", "====> * mariadb_check", " Actor checking for presence of MariaDB installation.", "====> * check_consumed_assets", " Check whether Leapp is using correct data assets.", "====> * checkmemory", " The actor check the size of RAM against RHEL8 minimal hardware requirements", "====> * check_bls_grub_onppc64", " Check whether GRUB config is BLS aware on RHEL 8 ppc64le systems", "====> * check_kpatch", " Carry over kpatch-dnf and it's config into the container", "====> * check_rhsmsku", " Ensure the system is subscribed to the subscription manager", "====> * check_ifcfg", " Ensures that ifcfg files are compatible with NetworkManager", "====> * check_fips", " Inhibit upgrade if FIPS is detected as enabled.", "====> * check_luks", " Check if any encrypted partitions are in use and whether they are supported for the upgrade.", "====> * check_skip_phase", " Skip all the subsequent phases until the report phase.", "====> * check_rpm_transaction_events", " Filter RPM transaction events based on installed RPM packages", "==> Processing phase `TargetTransactionFactsCollection`", "====> * create_iso_repofile", " Create custom repofile containing information about repositories found in target OS installation ISO, if used.", "====> * target_userspace_creator", " Initializes a directory to be populated as a minimal environment to run binaries from the target system.", "BaseOS for x86_64 0.0 B/s | 0 B 00:00 ", "", "============================================================", " ERRORS ", "============================================================", "", "2026-01-12 08:56:38.945717 [ERROR] Actor: target_userspace_creator", "Message: Unable to install RHEL 9 userspace packages.", "Summary:", " Details: Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.", " Stderr: Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals", " Error: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!", "", "============================================================", " END OF ERRORS ", "============================================================", "", "Debug output written to /var/log/leapp/leapp-preupgrade.log", "", "============================================================", " REPORT OVERVIEW ", "============================================================", "", "Following errors occurred and the upgrade cannot continue:", " 1. Actor: target_userspace_creator", " Message: Unable to install RHEL 9 userspace packages.", "", "HIGH and MEDIUM severity reports:", " 1. Packages available in excluded repositories will not be installed", " 2. Upgrade is unsupported", " 3. Remote root logins globally allowed using password", " 4. GRUB2 core will be automatically updated during the upgrade", "", "Reports summary:", " Errors: 1", " Inhibitors: 0", " HIGH severity reports: 4", " MEDIUM severity reports: 0", " LOW severity reports: 1", " INFO severity reports: 3", "", "Before continuing, review the full report below for details about discovered problems and possible remediation instructions:", " A report has been generated at /var/log/leapp/leapp-report.txt", " A report has been generated at /var/log/leapp/leapp-report.json", "", "============================================================", " END OF REPORT OVERVIEW ", "============================================================", "", "Answerfile has been generated at /var/log/leapp/answerfile"]} TASK [analysis-leapp | Include custom_local_repos for local_repos_post_analysis] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:89 TASK [infra.leapp.common : custom_local_repos | Remove old /etc/leapp/files/leapp_upgrade_repositories.repo] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:2 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [infra.leapp.common : custom_local_repos | Enable custom upgrade yum repositories] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/custom_local_repos.yml:9 skipping: [managed-node02] => {"changed": false, "skipped_reason": "No items in the list"} TASK [infra.leapp.analysis : analysis-leapp | Include check-results-file.yml] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:97 included: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/check-results-file.yml for managed-node02 TASK [infra.leapp.analysis : check-results-file | Result file status] ********** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/check-results-file.yml:2 ok: [managed-node02] => {"changed": false, "stat": {"atime": 1768226198.984739, "attr_flags": "", "attributes": [], "block_size": 4096, "blocks": 16, "charset": "us-ascii", "checksum": "c7baa90b1714b7c4154d9355b8745f869dd50afa", "ctime": 1768226198.984739, "dev": 51715, "device_type": 0, "executable": false, "exists": true, "gid": 0, "gr_name": "root", "inode": 780140696, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0644", "mtime": 1768226198.984739, "nlink": 1, "path": "/var/log/leapp/leapp-report.txt", "pw_name": "root", "readable": true, "rgrp": true, "roth": true, "rusr": true, "size": 6266, "uid": 0, "version": "324450061", "wgrp": false, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false}} TASK [infra.leapp.analysis : check-results-file | Check that result file exists] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/check-results-file.yml:7 ok: [managed-node02] => { "changed": false, "msg": "All assertions passed" } TASK [analysis-leapp | Run parse_leapp_report to check for inhibitors] ********* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/analysis-leapp.yml:100 TASK [infra.leapp.common : parse_leapp_report | Default upgrade_inhibited to false] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:12 ok: [managed-node02] => {"ansible_facts": {"upgrade_inhibited": false}, "changed": false} TASK [infra.leapp.common : parse_leapp_report | Collect human readable report results] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:16 ok: [managed-node02] => {"changed": false, "content": "Risk Factor: high (error)
Title: Unable to install RHEL 9 userspace packages.
Summary: {"details": "Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.", "stderr": "Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\nError: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\n"}
Key: 0e5d8451adfe372b923058fd09028cb5356e733d
----------------------------------------
Risk Factor: high 
Title: Packages available in excluded repositories will not be installed
Summary: 1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled "Excluded target system repositories" for details.
The list of these packages:
- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)
Key: 2437e204808f987477c0e9be8e4c95b3a87a9f3e
----------------------------------------
Risk Factor: high 
Title: Upgrade is unsupported
Summary: Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.

Key: 9e5088e3c1f371e020ec777c3d86578f4be143cf
----------------------------------------
Risk Factor: high 
Title: Remote root logins globally allowed using password
Summary: RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.
Remediation: [hint] If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.
Key: e738f78bc8f3a84411a4210e3b609057139d1855
----------------------------------------
Risk Factor: high 
Title: GRUB2 core will be automatically updated during the upgrade
Summary: On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running "grub2-install" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.
Key: ac7030e05d2ee248d34f08a9fa040b352bc410a3
----------------------------------------
Risk Factor: low 
Title: SElinux will be set to permissive mode
Summary: SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.
Remediation: [hint] Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the "/root/tmp_leapp_py3" SElinux warnings.
Key: 39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f
----------------------------------------
Risk Factor: info 
Title: Excluded target system repositories
Summary: The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.
- codeready-builder-beta-for-rhel-9-ppc64le-rpms
- crb
- codeready-builder-for-rhel-9-rhui-rpms
- codeready-builder-beta-for-rhel-9-x86_64-rpms
- codeready-builder-for-rhel-9-x86_64-eus-rpms
- codeready-builder-beta-for-rhel-9-aarch64-rpms
- codeready-builder-for-rhel-9-aarch64-eus-rpms
- codeready-builder-for-rhel-9-ppc64le-rpms
- codeready-builder-for-rhel-9-x86_64-rpms
- codeready-builder-for-rhel-9-x86_64-rhui-rpms
- codeready-builder-beta-for-rhel-9-s390x-rpms
- codeready-builder-for-rhel-9-ppc64le-eus-rpms
- codeready-builder-for-rhel-9-aarch64-rpms
- codeready-builder-for-rhel-9-s390x-eus-rpms
- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms
- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms
- codeready-builder-for-rhel-9-s390x-rpms
Remediation: [hint] If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).
Key: 1b9132cb2362ae7830e48eee7811be9527747de8
----------------------------------------
Risk Factor: info 
Title: SElinux relabeling will be scheduled
Summary: SElinux relabeling will be scheduled as the status is permissive/enforcing.
Key: 8fb81863f8413bd617c2a55b69b8e10ff03d7c72
----------------------------------------
Risk Factor: info 
Title: The upgrade will prepend the Include directive to OpenSSH sshd_config
Summary: OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`
Key: 96da6937c25c6492e4f1228ee146795989fd3718
----------------------------------------
", "encoding": "base64", "source": "/var/log/leapp/leapp-report.txt"} TASK [infra.leapp.common : parse_leapp_report | Collect JSON report results] *** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:21 ok: [managed-node02] => {"changed": false, "content": "{
  "entries": [
    {
      "audience": "sysadmin",
      "detail": {
        "remediations": [
          {
            "context": "If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "repository",
        "failure"
      ],
      "key": "1b9132cb2362ae7830e48eee7811be9527747de8",
      "severity": "info",
      "summary": "The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.\n- codeready-builder-beta-for-rhel-9-ppc64le-rpms\n- crb\n- codeready-builder-for-rhel-9-rhui-rpms\n- codeready-builder-beta-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-x86_64-eus-rpms\n- codeready-builder-beta-for-rhel-9-aarch64-rpms\n- codeready-builder-for-rhel-9-aarch64-eus-rpms\n- codeready-builder-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-beta-for-rhel-9-s390x-rpms\n- codeready-builder-for-rhel-9-ppc64le-eus-rpms\n- codeready-builder-for-rhel-9-aarch64-rpms\n- codeready-builder-for-rhel-9-s390x-eus-rpms\n- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms\n- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-for-rhel-9-s390x-rpms",
      "title": "Excluded target system repositories",
      "timeStamp": "2026-01-12T13:56:31.236393Z",
      "hostname": "managed-node02",
      "actor": "repositories_blacklist",
      "id": "868685a6bf98a48b652a3a170bd78fee7a387b9651e501a14071ac51f7c43913"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "related_resources": [
          {
            "scheme": "package",
            "title": "jitterentropy-devel"
          }
        ]
      },
      "groups": [
        "repository"
      ],
      "key": "2437e204808f987477c0e9be8e4c95b3a87a9f3e",
      "severity": "high",
      "summary": "1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled \"Excluded target system repositories\" for details.\nThe list of these packages:\n- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)",
      "title": "Packages available in excluded repositories will not be installed",
      "timeStamp": "2026-01-12T13:56:32.368354Z",
      "hostname": "managed-node02",
      "actor": "pes_events_scanner",
      "id": "91016e5f89184d7c9a2f6d265bc2324ec7d6669363f705c739a3069d670a5394"
    },
    {
      "audience": "sysadmin",
      "groups": [
        "selinux",
        "security"
      ],
      "key": "8fb81863f8413bd617c2a55b69b8e10ff03d7c72",
      "severity": "info",
      "summary": "SElinux relabeling will be scheduled as the status is permissive/enforcing.",
      "title": "SElinux relabeling will be scheduled",
      "timeStamp": "2026-01-12T13:56:32.668009Z",
      "hostname": "managed-node02",
      "actor": "check_se_linux",
      "id": "0352a9ca70636bdbed2ffe709fb12371364ee399cf2e1b7df7865e2b81af695c"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "remediations": [
          {
            "context": "Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the \"/root/tmp_leapp_py3\" SElinux warnings.",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "selinux",
        "security"
      ],
      "key": "39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f",
      "severity": "low",
      "summary": "SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.",
      "title": "SElinux will be set to permissive mode",
      "timeStamp": "2026-01-12T13:56:32.670996Z",
      "hostname": "managed-node02",
      "actor": "check_se_linux",
      "id": "b17c1727b566d1516bc22a2da182bc320563ec714af2ab9b0c750c3f188fd83a"
    },
    {
      "audience": "sysadmin",
      "groups": [
        "upgrade process",
        "sanity"
      ],
      "key": "9e5088e3c1f371e020ec777c3d86578f4be143cf",
      "severity": "high",
      "summary": "Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.\n",
      "title": "Upgrade is unsupported",
      "timeStamp": "2026-01-12T13:56:33.040982Z",
      "hostname": "managed-node02",
      "actor": "unsupported_upgrade_check",
      "id": "9adc7472e4fcc76595b3459181bb25a9496645197b19cd93d6c67161c2882bf5"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "related_resources": [
          {
            "scheme": "package",
            "title": "openssh-server"
          },
          {
            "scheme": "file",
            "title": "/etc/ssh/sshd_config"
          }
        ]
      },
      "groups": [
        "authentication",
        "security",
        "network",
        "services"
      ],
      "key": "96da6937c25c6492e4f1228ee146795989fd3718",
      "severity": "info",
      "summary": "OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`",
      "title": "The upgrade will prepend the Include directive to OpenSSH sshd_config",
      "timeStamp": "2026-01-12T13:56:33.449683Z",
      "hostname": "managed-node02",
      "actor": "open_ssh_drop_in_directory_check",
      "id": "0e83b31d447d22ba5e87257f30056b4d3a7925c99b322719af8f32b337f34afb"
    },
    {
      "audience": "sysadmin",
      "detail": {
        "related_resources": [
          {
            "scheme": "package",
            "title": "openssh-server"
          },
          {
            "scheme": "file",
            "title": "/etc/ssh/sshd_config"
          }
        ],
        "remediations": [
          {
            "context": "If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.",
            "type": "hint"
          }
        ]
      },
      "groups": [
        "authentication",
        "security",
        "network",
        "services"
      ],
      "key": "e738f78bc8f3a84411a4210e3b609057139d1855",
      "severity": "high",
      "summary": "RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.",
      "title": "Remote root logins globally allowed using password",
      "timeStamp": "2026-01-12T13:56:34.799142Z",
      "hostname": "managed-node02",
      "actor": "openssh_permit_root_login",
      "id": "29603c1674698844cb17371e3cf29ee3ca5b57ea00b2bddd11aea2342771c406"
    },
    {
      "audience": "sysadmin",
      "groups": [
        "boot"
      ],
      "key": "ac7030e05d2ee248d34f08a9fa040b352bc410a3",
      "severity": "high",
      "summary": "On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running \"grub2-install\" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.",
      "title": "GRUB2 core will be automatically updated during the upgrade",
      "timeStamp": "2026-01-12T13:56:34.871176Z",
      "hostname": "managed-node02",
      "actor": "check_grub_core",
      "id": "4d5fd58cc26863e79860716f1e85b1f62f0c62287eb898631ba2222c619c54fb"
    },
    {
      "audience": "sysadmin",
      "groups": [
        "error"
      ],
      "key": "0e5d8451adfe372b923058fd09028cb5356e733d",
      "severity": "high",
      "summary": "{\"details\": \"Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.\", \"stderr\": \"Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\\nError: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\\n\"}",
      "title": "Unable to install RHEL 9 userspace packages.",
      "timeStamp": "2026-01-12T13:56:38.945938Z",
      "hostname": "managed-node02",
      "actor": "target_userspace_creator",
      "id": "4d34020fc771cfac0f017b37650c78a51c3dc0a39d25184bbb7bb9641c1702b2"
    }
  ],
  "leapp_run_id": "1c608039-3f80-4c54-a658-1b63f885c00d"
}
", "encoding": "base64", "source": "/var/log/leapp/leapp-report.json"} TASK [infra.leapp.common : parse_leapp_report | Parse report results] ********** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:26 ok: [managed-node02] => {"ansible_facts": {"leapp_report_json": {"entries": [{"actor": "repositories_blacklist", "audience": "sysadmin", "detail": {"remediations": [{"context": "If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).", "type": "hint"}]}, "groups": ["repository", "failure"], "hostname": "managed-node02", "id": "868685a6bf98a48b652a3a170bd78fee7a387b9651e501a14071ac51f7c43913", "key": "1b9132cb2362ae7830e48eee7811be9527747de8", "severity": "info", "summary": "The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.\n- codeready-builder-beta-for-rhel-9-ppc64le-rpms\n- crb\n- codeready-builder-for-rhel-9-rhui-rpms\n- codeready-builder-beta-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-x86_64-eus-rpms\n- codeready-builder-beta-for-rhel-9-aarch64-rpms\n- codeready-builder-for-rhel-9-aarch64-eus-rpms\n- codeready-builder-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-beta-for-rhel-9-s390x-rpms\n- codeready-builder-for-rhel-9-ppc64le-eus-rpms\n- codeready-builder-for-rhel-9-aarch64-rpms\n- codeready-builder-for-rhel-9-s390x-eus-rpms\n- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms\n- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-for-rhel-9-s390x-rpms", "timeStamp": "2026-01-12T13:56:31.236393Z", "title": "Excluded target system repositories"}, {"actor": "pes_events_scanner", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "jitterentropy-devel"}]}, "groups": ["repository"], "hostname": "managed-node02", "id": "91016e5f89184d7c9a2f6d265bc2324ec7d6669363f705c739a3069d670a5394", "key": "2437e204808f987477c0e9be8e4c95b3a87a9f3e", "severity": "high", "summary": "1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled \"Excluded target system repositories\" for details.\nThe list of these packages:\n- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)", "timeStamp": "2026-01-12T13:56:32.368354Z", "title": "Packages available in excluded repositories will not be installed"}, {"actor": "check_se_linux", "audience": "sysadmin", "groups": ["selinux", "security"], "hostname": "managed-node02", "id": "0352a9ca70636bdbed2ffe709fb12371364ee399cf2e1b7df7865e2b81af695c", "key": "8fb81863f8413bd617c2a55b69b8e10ff03d7c72", "severity": "info", "summary": "SElinux relabeling will be scheduled as the status is permissive/enforcing.", "timeStamp": "2026-01-12T13:56:32.668009Z", "title": "SElinux relabeling will be scheduled"}, {"actor": "check_se_linux", "audience": "sysadmin", "detail": {"remediations": [{"context": "Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the \"/root/tmp_leapp_py3\" SElinux warnings.", "type": "hint"}]}, "groups": ["selinux", "security"], "hostname": "managed-node02", "id": "b17c1727b566d1516bc22a2da182bc320563ec714af2ab9b0c750c3f188fd83a", "key": "39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f", "severity": "low", "summary": "SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.", "timeStamp": "2026-01-12T13:56:32.670996Z", "title": "SElinux will be set to permissive mode"}, {"actor": "unsupported_upgrade_check", "audience": "sysadmin", "groups": ["upgrade process", "sanity"], "hostname": "managed-node02", "id": "9adc7472e4fcc76595b3459181bb25a9496645197b19cd93d6c67161c2882bf5", "key": "9e5088e3c1f371e020ec777c3d86578f4be143cf", "severity": "high", "summary": "Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.\n", "timeStamp": "2026-01-12T13:56:33.040982Z", "title": "Upgrade is unsupported"}, {"actor": "open_ssh_drop_in_directory_check", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "openssh-server"}, {"scheme": "file", "title": "/etc/ssh/sshd_config"}]}, "groups": ["authentication", "security", "network", "services"], "hostname": "managed-node02", "id": "0e83b31d447d22ba5e87257f30056b4d3a7925c99b322719af8f32b337f34afb", "key": "96da6937c25c6492e4f1228ee146795989fd3718", "severity": "info", "summary": "OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`", "timeStamp": "2026-01-12T13:56:33.449683Z", "title": "The upgrade will prepend the Include directive to OpenSSH sshd_config"}, {"actor": "openssh_permit_root_login", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "openssh-server"}, {"scheme": "file", "title": "/etc/ssh/sshd_config"}], "remediations": [{"context": "If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.", "type": "hint"}]}, "groups": ["authentication", "security", "network", "services"], "hostname": "managed-node02", "id": "29603c1674698844cb17371e3cf29ee3ca5b57ea00b2bddd11aea2342771c406", "key": "e738f78bc8f3a84411a4210e3b609057139d1855", "severity": "high", "summary": "RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.", "timeStamp": "2026-01-12T13:56:34.799142Z", "title": "Remote root logins globally allowed using password"}, {"actor": "check_grub_core", "audience": "sysadmin", "groups": ["boot"], "hostname": "managed-node02", "id": "4d5fd58cc26863e79860716f1e85b1f62f0c62287eb898631ba2222c619c54fb", "key": "ac7030e05d2ee248d34f08a9fa040b352bc410a3", "severity": "high", "summary": "On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running \"grub2-install\" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.", "timeStamp": "2026-01-12T13:56:34.871176Z", "title": "GRUB2 core will be automatically updated during the upgrade"}, {"actor": "target_userspace_creator", "audience": "sysadmin", "groups": ["error"], "hostname": "managed-node02", "id": "4d34020fc771cfac0f017b37650c78a51c3dc0a39d25184bbb7bb9641c1702b2", "key": "0e5d8451adfe372b923058fd09028cb5356e733d", "severity": "high", "summary": "{\"details\": \"Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.\", \"stderr\": \"Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\\nError: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\\n\"}", "timeStamp": "2026-01-12T13:56:38.945938Z", "title": "Unable to install RHEL 9 userspace packages."}], "leapp_run_id": "1c608039-3f80-4c54-a658-1b63f885c00d"}, "leapp_report_txt": ["Risk Factor: high (error)", "Title: Unable to install RHEL 9 userspace packages.", "Summary: {\"details\": \"Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.\", \"stderr\": \"Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\\nError: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\\n\"}", "Key: 0e5d8451adfe372b923058fd09028cb5356e733d", "----------------------------------------", "Risk Factor: high ", "Title: Packages available in excluded repositories will not be installed", "Summary: 1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled \"Excluded target system repositories\" for details.", "The list of these packages:", "- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)", "Key: 2437e204808f987477c0e9be8e4c95b3a87a9f3e", "----------------------------------------", "Risk Factor: high ", "Title: Upgrade is unsupported", "Summary: Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.", "", "Key: 9e5088e3c1f371e020ec777c3d86578f4be143cf", "----------------------------------------", "Risk Factor: high ", "Title: Remote root logins globally allowed using password", "Summary: RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.", "Remediation: [hint] If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.", "Key: e738f78bc8f3a84411a4210e3b609057139d1855", "----------------------------------------", "Risk Factor: high ", "Title: GRUB2 core will be automatically updated during the upgrade", "Summary: On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running \"grub2-install\" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.", "Key: ac7030e05d2ee248d34f08a9fa040b352bc410a3", "----------------------------------------", "Risk Factor: low ", "Title: SElinux will be set to permissive mode", "Summary: SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.", "Remediation: [hint] Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the \"/root/tmp_leapp_py3\" SElinux warnings.", "Key: 39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f", "----------------------------------------", "Risk Factor: info ", "Title: Excluded target system repositories", "Summary: The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.", "- codeready-builder-beta-for-rhel-9-ppc64le-rpms", "- crb", "- codeready-builder-for-rhel-9-rhui-rpms", "- codeready-builder-beta-for-rhel-9-x86_64-rpms", "- codeready-builder-for-rhel-9-x86_64-eus-rpms", "- codeready-builder-beta-for-rhel-9-aarch64-rpms", "- codeready-builder-for-rhel-9-aarch64-eus-rpms", "- codeready-builder-for-rhel-9-ppc64le-rpms", "- codeready-builder-for-rhel-9-x86_64-rpms", "- codeready-builder-for-rhel-9-x86_64-rhui-rpms", "- codeready-builder-beta-for-rhel-9-s390x-rpms", "- codeready-builder-for-rhel-9-ppc64le-eus-rpms", "- codeready-builder-for-rhel-9-aarch64-rpms", "- codeready-builder-for-rhel-9-s390x-eus-rpms", "- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms", "- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms", "- codeready-builder-for-rhel-9-s390x-rpms", "Remediation: [hint] If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).", "Key: 1b9132cb2362ae7830e48eee7811be9527747de8", "----------------------------------------", "Risk Factor: info ", "Title: SElinux relabeling will be scheduled", "Summary: SElinux relabeling will be scheduled as the status is permissive/enforcing.", "Key: 8fb81863f8413bd617c2a55b69b8e10ff03d7c72", "----------------------------------------", "Risk Factor: info ", "Title: The upgrade will prepend the Include directive to OpenSSH sshd_config", "Summary: OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`", "Key: 96da6937c25c6492e4f1228ee146795989fd3718", "----------------------------------------", ""]}, "changed": false} TASK [infra.leapp.common : parse_leapp_report | Check for inhibitors] ********** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:32 skipping: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'remediations': [{'context': 'If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).', 'type': 'hint'}]}, 'groups': ['repository', 'failure'], 'key': '1b9132cb2362ae7830e48eee7811be9527747de8', 'severity': 'info', 'summary': 'The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.\n- codeready-builder-beta-for-rhel-9-ppc64le-rpms\n- crb\n- codeready-builder-for-rhel-9-rhui-rpms\n- codeready-builder-beta-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-x86_64-eus-rpms\n- codeready-builder-beta-for-rhel-9-aarch64-rpms\n- codeready-builder-for-rhel-9-aarch64-eus-rpms\n- codeready-builder-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-beta-for-rhel-9-s390x-rpms\n- codeready-builder-for-rhel-9-ppc64le-eus-rpms\n- codeready-builder-for-rhel-9-aarch64-rpms\n- codeready-builder-for-rhel-9-s390x-eus-rpms\n- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms\n- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-for-rhel-9-s390x-rpms', 'title': 'Excluded target system repositories', 'timeStamp': '2026-01-12T13:56:31.236393Z', 'hostname': 'managed-node02', 'actor': 'repositories_blacklist', 'id': '868685a6bf98a48b652a3a170bd78fee7a387b9651e501a14071ac51f7c43913'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "repositories_blacklist", "audience": "sysadmin", "detail": {"remediations": [{"context": "If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).", "type": "hint"}]}, "groups": ["repository", "failure"], "hostname": "managed-node02", "id": "868685a6bf98a48b652a3a170bd78fee7a387b9651e501a14071ac51f7c43913", "key": "1b9132cb2362ae7830e48eee7811be9527747de8", "severity": "info", "summary": "The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.\n- codeready-builder-beta-for-rhel-9-ppc64le-rpms\n- crb\n- codeready-builder-for-rhel-9-rhui-rpms\n- codeready-builder-beta-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-x86_64-eus-rpms\n- codeready-builder-beta-for-rhel-9-aarch64-rpms\n- codeready-builder-for-rhel-9-aarch64-eus-rpms\n- codeready-builder-for-rhel-9-ppc64le-rpms\n- codeready-builder-for-rhel-9-x86_64-rpms\n- codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-beta-for-rhel-9-s390x-rpms\n- codeready-builder-for-rhel-9-ppc64le-eus-rpms\n- codeready-builder-for-rhel-9-aarch64-rpms\n- codeready-builder-for-rhel-9-s390x-eus-rpms\n- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms\n- rhui-codeready-builder-for-rhel-9-x86_64-rhui-rpms\n- codeready-builder-for-rhel-9-s390x-rpms", "timeStamp": "2026-01-12T13:56:31.236393Z", "title": "Excluded target system repositories"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'related_resources': [{'scheme': 'package', 'title': 'jitterentropy-devel'}]}, 'groups': ['repository'], 'key': '2437e204808f987477c0e9be8e4c95b3a87a9f3e', 'severity': 'high', 'summary': '1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled "Excluded target system repositories" for details.\nThe list of these packages:\n- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)', 'title': 'Packages available in excluded repositories will not be installed', 'timeStamp': '2026-01-12T13:56:32.368354Z', 'hostname': 'managed-node02', 'actor': 'pes_events_scanner', 'id': '91016e5f89184d7c9a2f6d265bc2324ec7d6669363f705c739a3069d670a5394'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "pes_events_scanner", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "jitterentropy-devel"}]}, "groups": ["repository"], "hostname": "managed-node02", "id": "91016e5f89184d7c9a2f6d265bc2324ec7d6669363f705c739a3069d670a5394", "key": "2437e204808f987477c0e9be8e4c95b3a87a9f3e", "severity": "high", "summary": "1 packages will be skipped because they are available only in target system repositories that are intentionally excluded from the list of repositories used during the upgrade. See the report message titled \"Excluded target system repositories\" for details.\nThe list of these packages:\n- jitterentropy-devel (repoid: codeready-builder-for-rhel-9-x86_64-rpms)", "timeStamp": "2026-01-12T13:56:32.368354Z", "title": "Packages available in excluded repositories will not be installed"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'groups': ['selinux', 'security'], 'key': '8fb81863f8413bd617c2a55b69b8e10ff03d7c72', 'severity': 'info', 'summary': 'SElinux relabeling will be scheduled as the status is permissive/enforcing.', 'title': 'SElinux relabeling will be scheduled', 'timeStamp': '2026-01-12T13:56:32.668009Z', 'hostname': 'managed-node02', 'actor': 'check_se_linux', 'id': '0352a9ca70636bdbed2ffe709fb12371364ee399cf2e1b7df7865e2b81af695c'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "check_se_linux", "audience": "sysadmin", "groups": ["selinux", "security"], "hostname": "managed-node02", "id": "0352a9ca70636bdbed2ffe709fb12371364ee399cf2e1b7df7865e2b81af695c", "key": "8fb81863f8413bd617c2a55b69b8e10ff03d7c72", "severity": "info", "summary": "SElinux relabeling will be scheduled as the status is permissive/enforcing.", "timeStamp": "2026-01-12T13:56:32.668009Z", "title": "SElinux relabeling will be scheduled"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'remediations': [{'context': 'Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the "/root/tmp_leapp_py3" SElinux warnings.', 'type': 'hint'}]}, 'groups': ['selinux', 'security'], 'key': '39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f', 'severity': 'low', 'summary': 'SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.', 'title': 'SElinux will be set to permissive mode', 'timeStamp': '2026-01-12T13:56:32.670996Z', 'hostname': 'managed-node02', 'actor': 'check_se_linux', 'id': 'b17c1727b566d1516bc22a2da182bc320563ec714af2ab9b0c750c3f188fd83a'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "check_se_linux", "audience": "sysadmin", "detail": {"remediations": [{"context": "Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the \"/root/tmp_leapp_py3\" SElinux warnings.", "type": "hint"}]}, "groups": ["selinux", "security"], "hostname": "managed-node02", "id": "b17c1727b566d1516bc22a2da182bc320563ec714af2ab9b0c750c3f188fd83a", "key": "39d7183dafba798aa4bbb1e70b0ef2bbe5b1772f", "severity": "low", "summary": "SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.", "timeStamp": "2026-01-12T13:56:32.670996Z", "title": "SElinux will be set to permissive mode"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'groups': ['upgrade process', 'sanity'], 'key': '9e5088e3c1f371e020ec777c3d86578f4be143cf', 'severity': 'high', 'summary': 'Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.\n', 'title': 'Upgrade is unsupported', 'timeStamp': '2026-01-12T13:56:33.040982Z', 'hostname': 'managed-node02', 'actor': 'unsupported_upgrade_check', 'id': '9adc7472e4fcc76595b3459181bb25a9496645197b19cd93d6c67161c2882bf5'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "unsupported_upgrade_check", "audience": "sysadmin", "groups": ["upgrade process", "sanity"], "hostname": "managed-node02", "id": "9adc7472e4fcc76595b3459181bb25a9496645197b19cd93d6c67161c2882bf5", "key": "9e5088e3c1f371e020ec777c3d86578f4be143cf", "severity": "high", "summary": "Environment variable LEAPP_UNSUPPORTED has been detected. A successful and safe upgrade process cannot be guaranteed. From now on you are continuing at your own risk.\n", "timeStamp": "2026-01-12T13:56:33.040982Z", "title": "Upgrade is unsupported"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'related_resources': [{'scheme': 'package', 'title': 'openssh-server'}, {'scheme': 'file', 'title': '/etc/ssh/sshd_config'}]}, 'groups': ['authentication', 'security', 'network', 'services'], 'key': '96da6937c25c6492e4f1228ee146795989fd3718', 'severity': 'info', 'summary': 'OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`', 'title': 'The upgrade will prepend the Include directive to OpenSSH sshd_config', 'timeStamp': '2026-01-12T13:56:33.449683Z', 'hostname': 'managed-node02', 'actor': 'open_ssh_drop_in_directory_check', 'id': '0e83b31d447d22ba5e87257f30056b4d3a7925c99b322719af8f32b337f34afb'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "open_ssh_drop_in_directory_check", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "openssh-server"}, {"scheme": "file", "title": "/etc/ssh/sshd_config"}]}, "groups": ["authentication", "security", "network", "services"], "hostname": "managed-node02", "id": "0e83b31d447d22ba5e87257f30056b4d3a7925c99b322719af8f32b337f34afb", "key": "96da6937c25c6492e4f1228ee146795989fd3718", "severity": "info", "summary": "OpenSSH server configuration needs to be modified to contain Include directive for the RHEL9 to work properly and integrate with the other parts of the OS. The following snippet will be added to the /etc/ssh/sshd_config during the ApplicationsPhase: `Include /etc/ssh/sshd_config.d/*.conf`", "timeStamp": "2026-01-12T13:56:33.449683Z", "title": "The upgrade will prepend the Include directive to OpenSSH sshd_config"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'detail': {'related_resources': [{'scheme': 'package', 'title': 'openssh-server'}, {'scheme': 'file', 'title': '/etc/ssh/sshd_config'}], 'remediations': [{'context': 'If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.', 'type': 'hint'}]}, 'groups': ['authentication', 'security', 'network', 'services'], 'key': 'e738f78bc8f3a84411a4210e3b609057139d1855', 'severity': 'high', 'summary': 'RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.', 'title': 'Remote root logins globally allowed using password', 'timeStamp': '2026-01-12T13:56:34.799142Z', 'hostname': 'managed-node02', 'actor': 'openssh_permit_root_login', 'id': '29603c1674698844cb17371e3cf29ee3ca5b57ea00b2bddd11aea2342771c406'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "openssh_permit_root_login", "audience": "sysadmin", "detail": {"related_resources": [{"scheme": "package", "title": "openssh-server"}, {"scheme": "file", "title": "/etc/ssh/sshd_config"}], "remediations": [{"context": "If you depend on remote root logins using passwords, consider setting up a different user for remote administration. Otherwise you can ignore this message.", "type": "hint"}]}, "groups": ["authentication", "security", "network", "services"], "hostname": "managed-node02", "id": "29603c1674698844cb17371e3cf29ee3ca5b57ea00b2bddd11aea2342771c406", "key": "e738f78bc8f3a84411a4210e3b609057139d1855", "severity": "high", "summary": "RHEL9 no longer allows remote root logins, but the server configuration explicitly overrides this default. The configuration file will not be updated and root is still going to be allowed to login with password. This is not recommended and considered as a security risk.", "timeStamp": "2026-01-12T13:56:34.799142Z", "title": "Remote root logins globally allowed using password"}, "skip_reason": "Conditional result was False"} skipping: [managed-node02] => (item={'audience': 'sysadmin', 'groups': ['boot'], 'key': 'ac7030e05d2ee248d34f08a9fa040b352bc410a3', 'severity': 'high', 'summary': 'On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running "grub2-install" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.', 'title': 'GRUB2 core will be automatically updated during the upgrade', 'timeStamp': '2026-01-12T13:56:34.871176Z', 'hostname': 'managed-node02', 'actor': 'check_grub_core', 'id': '4d5fd58cc26863e79860716f1e85b1f62f0c62287eb898631ba2222c619c54fb'}) => {"ansible_loop_var": "item", "changed": false, "item": {"actor": "check_grub_core", "audience": "sysadmin", "groups": ["boot"], "hostname": "managed-node02", "id": "4d5fd58cc26863e79860716f1e85b1f62f0c62287eb898631ba2222c619c54fb", "key": "ac7030e05d2ee248d34f08a9fa040b352bc410a3", "severity": "high", "summary": "On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running \"grub2-install\" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.", "timeStamp": "2026-01-12T13:56:34.871176Z", "title": "GRUB2 core will be automatically updated during the upgrade"}, "skip_reason": "Conditional result was False"} ok: [managed-node02] => (item={'audience': 'sysadmin', 'groups': ['error'], 'key': '0e5d8451adfe372b923058fd09028cb5356e733d', 'severity': 'high', 'summary': '{"details": "Command [\'systemd-nspawn\', \'--register=no\', \'--quiet\', \'--keep-unit\', \'--capability=all\', \'-D\', \'/var/lib/leapp/scratch/mounts/root_/system_overlay\', \'--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1\', \'--setenv=LEAPP_UNSUPPORTED=1\', \'--setenv=LEAPP_HOSTNAME=managed-node02\', \'--setenv=LEAPP_EXPERIMENTAL=0\', \'--setenv=LEAPP_NO_RHSM=1\', \'--setenv=LEAPP_NO_RHSM_FACTS=1\', \'--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga\', \'--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7\', \'--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default\', \'--setenv=LEAPP_IPU_IN_PROGRESS=8to9\', \'--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d\', \'--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools\', \'--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files\', \'dnf\', \'install\', \'-y\', \'--setopt=module_platform_id=platform:el9\', \'--setopt=keepcache=1\', \'--releasever\', \'9.7\', \'--installroot\', \'/el9target\', \'--disablerepo\', \'*\', \'--enablerepo\', \'rhel-9-for-x86_64-baseos-rpms\', \'--enablerepo\', \'rhel-9-for-x86_64-appstream-rpms\', \'dnf-command(config-manager)\', \'dnf\', \'util-linux\', \'--disableplugin\', \'subscription-manager\'] failed with exit code 1.", "stderr": "Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\\nError: Failed to download metadata for repo \'rhel-9-for-x86_64-baseos-rpms\': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\\n"}', 'title': 'Unable to install RHEL 9 userspace packages.', 'timeStamp': '2026-01-12T13:56:38.945938Z', 'hostname': 'managed-node02', 'actor': 'target_userspace_creator', 'id': '4d34020fc771cfac0f017b37650c78a51c3dc0a39d25184bbb7bb9641c1702b2'}) => {"ansible_facts": {"leapp_inhibitors": [{"actor": "check_detected_devices_and_drivers", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/6971716"}, {"title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/5436131"}]}, "groups": ["kernel", "drivers", "inhibitor"], "hostname": "managed-node02", "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec", "key": "7ae2961239eec9905e2580fa6309a589b1dca953", "severity": "high", "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n", "timeStamp": "2026-01-12T13:55:09.387759Z", "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."}, {"actor": "check_nfs", "audience": "sysadmin", "detail": {"external": [{"title": "Why does leapp upgrade fail on detecting NFS during upgrade?", "url": "https://access.redhat.com/solutions/6964006"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Disable NFS temporarily for the upgrade if possible.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037", "key": "9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "severity": "high", "summary": "NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n", "timeStamp": "2026-01-12T13:55:11.142353Z", "title": "Use of NFS detected. Upgrade can't proceed"}, {"actor": "check_cifs", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\"", "url": "https://access.redhat.com/solutions/6964304"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Comment out CIFS entries to proceed with the upgrade.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "6a06bcae8d148e7123d9fb89c4338a0adaaa89b1927bdd25a9a2156bc2dee822", "key": "d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a", "severity": "high", "summary": "CIFS is currently not supported by the inplace upgrade.", "timeStamp": "2026-01-12T13:55:11.287236Z", "title": "Use of CIFS detected. Upgrade can't proceed"}, {"actor": "target_userspace_creator", "audience": "sysadmin", "groups": ["error"], "hostname": "managed-node02", "id": "4d34020fc771cfac0f017b37650c78a51c3dc0a39d25184bbb7bb9641c1702b2", "key": "0e5d8451adfe372b923058fd09028cb5356e733d", "severity": "high", "summary": "{\"details\": \"Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.\", \"stderr\": \"Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\\nError: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\\n\"}", "timeStamp": "2026-01-12T13:56:38.945938Z", "title": "Unable to install RHEL 9 userspace packages."}], "upgrade_inhibited": true}, "ansible_loop_var": "item", "changed": false, "item": {"actor": "target_userspace_creator", "audience": "sysadmin", "groups": ["error"], "hostname": "managed-node02", "id": "4d34020fc771cfac0f017b37650c78a51c3dc0a39d25184bbb7bb9641c1702b2", "key": "0e5d8451adfe372b923058fd09028cb5356e733d", "severity": "high", "summary": "{\"details\": \"Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.\", \"stderr\": \"Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\\nError: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\\n\"}", "timeStamp": "2026-01-12T13:56:38.945938Z", "title": "Unable to install RHEL 9 userspace packages."}} TASK [infra.leapp.common : parse_leapp_report | Collect inhibitors] ************ task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:44 ok: [managed-node02] => {"changed": false, "cmd": ["awk", "/\\(inhibitor\\)/,/^-------/", "/var/log/leapp/leapp-report.txt"], "delta": "0:00:00.003758", "end": "2026-01-12 08:57:03.514310", "failed_when_result": false, "msg": "", "rc": 0, "start": "2026-01-12 08:57:03.510552", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} TASK [infra.leapp.common : parse_leapp_report | Collect high errors] *********** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/tasks/parse_leapp_report.yml:53 ok: [managed-node02] => {"changed": false, "cmd": ["awk", "/high \\(error\\)/,/^-------/", "/var/log/leapp/leapp-report.txt"], "delta": "0:00:00.004283", "end": "2026-01-12 08:57:03.886102", "failed_when_result": false, "msg": "", "rc": 0, "start": "2026-01-12 08:57:03.881819", "stderr": "", "stderr_lines": [], "stdout": "Risk Factor: high (error)\nTitle: Unable to install RHEL 9 userspace packages.\nSummary: {\"details\": \"Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.\", \"stderr\": \"Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\\nError: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\\n\"}\nKey: 0e5d8451adfe372b923058fd09028cb5356e733d\n----------------------------------------", "stdout_lines": ["Risk Factor: high (error)", "Title: Unable to install RHEL 9 userspace packages.", "Summary: {\"details\": \"Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.\", \"stderr\": \"Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\\nError: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\\n\"}", "Key: 0e5d8451adfe372b923058fd09028cb5356e733d", "----------------------------------------"]} TASK [infra.leapp.analysis : Set stats for leapp_inhibitors] ******************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/main.yml:17 ok: [managed-node02] => {"ansible_stats": {"aggregate": true, "data": {"leapp_inhibitors": [{"actor": "check_detected_devices_and_drivers", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp preupgrade getting \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/6971716"}, {"title": "Leapp upgrade fail with error \"Inhibitor: Detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed.\"", "url": "https://access.redhat.com/solutions/5436131"}]}, "groups": ["kernel", "drivers", "inhibitor"], "hostname": "managed-node02", "id": "fd90920b0fa4beb250dec2bc83b7f345cef5bdf008ba8b913712ac0aa66b4dec", "key": "7ae2961239eec9905e2580fa6309a589b1dca953", "severity": "high", "summary": "Support for the following RHEL 8 device drivers has been removed in RHEL 9:\n - dnet\n - liquidio\n - dlci\n", "timeStamp": "2026-01-12T13:55:09.387759Z", "title": "Leapp detected loaded kernel drivers which have been removed in RHEL 9. Upgrade cannot proceed."}, {"actor": "check_nfs", "audience": "sysadmin", "detail": {"external": [{"title": "Why does leapp upgrade fail on detecting NFS during upgrade?", "url": "https://access.redhat.com/solutions/6964006"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Disable NFS temporarily for the upgrade if possible.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "2280b45166370fc50f00cdb530b5594fe88161fa16228233597156c6e5564037", "key": "9881b25faceeeaa7a6478bcdac29afd7f6baaaed", "severity": "high", "summary": "NFS is currently not supported by the inplace upgrade.\nWe have found NFS usage at the following locations:\n- NFS shares found in /etc/fstab:\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat /mnt/redhat\n - nest.test.redhat.com:/mnt/qa /mnt/qa\n - vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive /mnt/engarchive\n - nest.test.redhat.com:/mnt/tpsdist /mnt/tpsdist\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_engineering_sm/devarchive/redhat/brewroot /mnt/brew\n - ntap-rdu2-c01-eng01-nfs01b.storage.rdu2.redhat.com:/bos_eng01_devops_brew_scratch_nfs_sm/scratch /mnt/brew_scratch\n", "timeStamp": "2026-01-12T13:55:11.142353Z", "title": "Use of NFS detected. Upgrade can't proceed"}, {"actor": "check_cifs", "audience": "sysadmin", "detail": {"external": [{"title": "Leapp upgrade failed with error \"Inhibitor: Use of CIFS detected. Upgrade cannot proceed\"", "url": "https://access.redhat.com/solutions/6964304"}], "related_resources": [{"scheme": "file", "title": "/etc/fstab"}], "remediations": [{"context": "Comment out CIFS entries to proceed with the upgrade.", "type": "hint"}]}, "groups": ["filesystem", "network", "inhibitor"], "hostname": "managed-node02", "id": "6a06bcae8d148e7123d9fb89c4338a0adaaa89b1927bdd25a9a2156bc2dee822", "key": "d0e1aa3f7c4fc4450bdcb9a27f47ff464d6af24a", "severity": "high", "summary": "CIFS is currently not supported by the inplace upgrade.", "timeStamp": "2026-01-12T13:55:11.287236Z", "title": "Use of CIFS detected. Upgrade can't proceed"}, {"actor": "target_userspace_creator", "audience": "sysadmin", "groups": ["error"], "hostname": "managed-node02", "id": "4d34020fc771cfac0f017b37650c78a51c3dc0a39d25184bbb7bb9641c1702b2", "key": "0e5d8451adfe372b923058fd09028cb5356e733d", "severity": "high", "summary": "{\"details\": \"Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.\", \"stderr\": \"Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\\nError: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\\n\"}", "timeStamp": "2026-01-12T13:56:38.945938Z", "title": "Unable to install RHEL 9 userspace packages."}]}, "per_host": false}, "changed": false} TASK [infra.leapp.analysis : Notify analysis report is done handler] *********** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/tasks/main.yml:22 NOTIFIED HANDLER infra.leapp.analysis : Preupgrade analysis report is done for managed-node02 NOTIFIED HANDLER infra.leapp.analysis : Display inhibitors for managed-node02 NOTIFIED HANDLER infra.leapp.analysis : Display errors for managed-node02 changed: [managed-node02] => {"changed": true, "msg": "All assertions passed"} TASK [common_upgrade_tasks | Flush handlers] *********************************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:99 META: triggered running handlers for managed-node02 RUNNING HANDLER [infra.leapp.common : Check for log file] ********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:3 ok: [managed-node02] => {"changed": false, "stat": {"atime": 1768226154.1878815, "attr_flags": "", "attributes": [], "block_size": 4096, "blocks": 40, "charset": "us-ascii", "checksum": "1b3c80ba8225be58362455e08e41e9974afd327f", "ctime": 1768226199.1427386, "dev": 51715, "device_type": 0, "executable": false, "exists": true, "gid": 0, "gr_name": "root", "inode": 838860951, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0644", "mtime": 1768226199.1427386, "nlink": 1, "path": "/var/log/ripu/ripu.log", "pw_name": "root", "readable": true, "rgrp": true, "roth": true, "rusr": true, "size": 18668, "uid": 0, "version": "438170517", "wgrp": false, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false}} RUNNING HANDLER [infra.leapp.common : Add end time to log file] **************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:9 changed: [managed-node02] => {"backup": "", "changed": true, "msg": "line added"} RUNNING HANDLER [infra.leapp.common : Slurp ripu.log file] ********************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:19 ok: [managed-node02] => {"changed": false, "content": "RIPU preupgrade analysis
Job started at 2026-01-12T13:55:53Z

============================================================
                    UNSUPPORTED UPGRADE                     
============================================================

Variable LEAPP_UNSUPPORTED has been detected. Proceeding at your own risk.
Development variables have been detected:
- LEAPP_DEVEL_RPMS_ALL_SIGNED=1

============================================================
                    UNSUPPORTED UPGRADE                     
============================================================

==> Processing phase `configuration_phase`
====> * ipu_workflow_config
        IPU workflow config actor
==> Processing phase `FactsCollection`
====> * scandasd
        In case of s390x architecture, check whether DASD is used.
====> * storage_scanner
        Provides data about storage settings.
====> * firewalld_collect_used_object_names
        This actor reads firewalld's configuration and produces Model
====> * rpm_scanner
        Provides data about installed RPM Packages.
====> * scanzfcp
        In case of s390x architecture, check whether ZFCP is used.
====> * persistentnetnames
        Get network interface information for physical ethernet interfaces of the original system.
====> * open_ssl_config_scanner
        Read an OpenSSL configuration file for further analysis.
====> * remove_obsolete_gpg_keys
        Remove obsoleted RPM GPG keys.
====> * get_enabled_modules
        Provides data about which module streams are enabled on the source system.
====> * scan_custom_modifications_actor
        Collects information about files in leapp directories that have been modified or newly added.
====> * network_manager_read_config
        Provides data about NetworkManager configuration.
====> * distribution_signed_rpm_scanner
        Provide data about distribution signed & third-party RPM packages.
====> * scan_systemd_source
        Provides info about systemd on the source system
====> * scanclienablerepo
        Produce CustomTargetRepository based on the LEAPP_ENABLE_REPOS in config.
====> * nis_scanner
        Collect information about the NIS packages configuration.
====> * ifcfg_scanner
        Scan ifcfg files with legacy network configuration
====> * firewalld_collect_global_config
        This actor reads firewalld's configuration and produces Model
====> * scan_target_os_image
        Scans the provided target OS ISO image to use as a content source for the IPU, if any.
====> * persistentnetnamesdisable
        Disable systemd-udevd persistent network naming on machine with single eth0 NIC
====> * vdo_conversion_scanner
        Provides conversion info about VDO devices.
====> * scan_files_for_target_userspace
        Scan the source system and identify files that will be copied into the target userspace when it is created.
====> * scan_source_boot_entry
        Scan the default boot entry of the source system.
====> * scan_source_files
        Scan files (explicitly specified) of the source system.
====> * luks_scanner
        Provides data about active LUKS devices.
====> * scan_grub_device_name
        Find the name of the block devices where GRUB is located
====> * multipath_conf_read_8to9
        Read multipath configuration files and extract the necessary information
====> * scan_default_initramfs
        Scan details of the default boot entry's initramfs image.
====> * network_manager_connection_scanner
        Scan NetworkManager connection keyfiles
====> * copy_dnf_conf_into_target_userspace
        Copy dnf.conf into target userspace
====> * get_installed_desktops
        Actor checks if kde or gnome desktop environments
====> * root_scanner
        Scan the system root directory and produce a message containing
====> * system_facts
        Provides data about many facts from system.
====> * load_device_driver_deprecation_data
        Loads deprecation data for drivers and devices (PCI & CPU)
====> * selinuxcontentscanner
        Scan the system for any SELinux customizations
====> * sssd_facts_8to9
        Check SSSD configuration for changes in RHEL9 and report them in model.
====> * scancryptopolicies
        Scan information about system wide set crypto policies including:
====> * scan_source_kernel
        Scan the source system kernel.
====> * scan_sap_hana
        Gathers information related to SAP HANA instances on the system.
====> * check_custom_network_scripts
        Check the existence of custom network-scripts and warn user about possible
====> * read_openssh_config
        Collect information about the OpenSSH configuration.
====> * xorgdrvfacts8to9
        Check the journal logs for deprecated Xorg drivers.
====> * biosdevname
        Enable biosdevname on the target RHEL system if all interfaces on the source RHEL
====> * scan_hybrid_image_azure
        Check if the system is using Azure hybrid image.
====> * udevadm_info
        Produces data exported by the "udevadm info" command.
====> * scan_pkg_manager
        Provides data about package manager (yum/dnf)
====> * trusted_gpg_keys_scanner
        Scan for trusted GPG keys.
====> * scan_grub_config
        Scan grub configuration files for errors.
====> * register_ruby_irb_adjustment
        Register a workaround to allow rubygem-irb's directory -> symlink conversion.
====> * roce_scanner
        Detect active RoCE NICs on IBM Z machines.
====> * checkrhui
        Check if system is using RHUI infrastructure (on public cloud) and send messages to
====> * transaction_workarounds
        Provides additional RPM transaction tasks based on bundled RPM packages.
====> * scan_subscription_manager_info
        Scans the current system for subscription manager information
====> * xfs_info_scanner
        This actor scans all mounted mountpoints for XFS information.
====> * pci_devices_scanner
        Provides data about existing PCI Devices.
====> * scan_kernel_cmdline
        Scan the kernel command line of the booted system.
====> * scan_dynamic_linker_configuration
        Scan the dynamic linker configuration and find modifications.
====> * scanblacklistca
        Scan the file system for distrusted CA's in the blacklist directory.
====> * scan_custom_repofile
        Scan the custom /etc/leapp/files/leapp_upgrade_repositories.repo repo file.
====> * scanmemory
        Scan Memory of the machine.
====> * repository_mapping
        Produces message containing repository mapping based on provided file.
====> * used_repository_scanner
        Scan used enabled repositories
====> * ipa_scanner
        Scan system for ipa-client and ipa-server status
====> * rpm_transaction_config_tasks_collector
        Provides additional RPM transaction tasks from /etc/leapp/transaction.
====> * satellite_upgrade_facts
        Report which Satellite packages require updates and how to handle PostgreSQL data
====> * repositories_blacklist
        Exclude target repositories provided by Red Hat without support.
====> * detect_kernel_drivers
        Matches all currently loaded kernel drivers against known deprecated and removed drivers.
====> * scan_fips
        Determine whether the source system has FIPS enabled.
====> * scancpu
        Scan CPUs of the machine.
====> * satellite_upgrade_services
        Reconfigure Satellite services
====> * pes_events_scanner
        Provides data about package events from Package Evolution Service.
====> * setuptargetrepos
        Produces list of repositories that should be available to be used during IPU process.
==> Processing phase `Checks`
====> * check_microarchitecture
        Inhibit if RHEL9 microarchitecture requirements are not satisfied
====> * check_se_linux
        Check SELinux status and produce decision messages for further action.
====> * efi_check_boot
        Adjust EFI boot entry for first reboot
====> * crypto_policies_check
        This actor consumes previously gathered information about crypto policies on the source
====> * check_root_symlinks
        Check if the symlinks /bin and /lib are relative, not absolute.
====> * checktargetrepos
        Check whether target yum repositories are specified.
====> * check_system_arch
        Check if system is running at a supported architecture. If no, inhibit the upgrade process.
====> * unsupported_upgrade_check
        Checks environment variables and produces a warning report if the upgrade is unsupported.
====> * check_os_release
        Check if the current RHEL minor version is supported. If not, inhibit the upgrade process.
====> * open_ssl_config_check
        The OpenSSL configuration changed between RHEL8 and RHEL9 significantly with the rebase to
====> * multipath_conf_check_8to9
        Checks if changes to the multipath configuration files are necessary
====> * check_arm_bootloader
        Install required RPM packages for ARM system upgrades on paths with
====> * nis_check
        Checks if any of NIS components is installed and configured
====> * check_target_version
        Check that the target system version is supported by the upgrade process.
====> * open_ssh_drop_in_directory_check
        Trigger a notice that the main sshd_config will be updated to contain
====> * distribution_signed_rpm_check
        Check if there are any packages that are not signed by distribution GPG keys.
====> * check_etc_releasever
        Check releasever info and provide a guidance based on the facts
====> * firewalld_check_allow_zone_drifting
        This actor will check if AllowZoneDrifting=yes in firewalld.conf. This
====> * xorgdrvcheck8to9
        Warn if Xorg deprecated drivers are in use.
====> * firewalld_check_service_tftp_client
        This actor will inhibit if firewalld's configuration is using service
====> * check_skipped_repositories
        Produces a report if any repositories enabled on the system are going to be skipped.
====> * check_vdo
        Check if VDO devices need to be migrated to lvm management.
====> * check_target_iso
        Check that the provided target ISO is a valid ISO image and is located on a persistent partition.
====> * network_deprecations
        Ensures that network configuration doesn't rely on unsupported settings
====> * emit_net_naming_scheme
        Emit necessary modifications of the upgrade environment and target command line to use net.naming-scheme.
====> * check_custom_modifications_actor
        Checks CustomModifications messages and produces a report about files in leapp directories that have been
====> * sssd_check_8to9
        Check SSSD configuration for changes in RHEL9 and report them in model.
====> * check_insights_auto_register
        Checks if system can be automatically registered into Red Hat Insights
====> * check_installed_kernels
        Inhibit IPU (in-place upgrade) when installed kernels conflict with a safe upgrade.
====> * check_sap_hana
        If SAP HANA has been detected, several checks are performed to ensure a successful upgrade.
====> * mysql_check
        Actor checking for presence of MySQL installation.
====> * check_nvidia_proprietary_driver
        Check if NVIDIA proprietary driver is in use. If yes, inhibit the upgrade process.
====> * openssh_permit_root_login
        OpenSSH no longer allows root logins with password.
====> * check_grub_core
        Check whether we are on legacy (BIOS) system and instruct Leapp to upgrade GRUB core
====> * detect_grub_config_error
        Check grub configuration for various errors.
====> * check_mount_options
        Check for mount options preventing the upgrade.
====> * postgresql_check
        Actor checking for presence of PostgreSQL installation.
====> * check_fstab_mount_order
        Checks order of entries in /etc/fstab based on their mount point and inhibits upgrade if overshadowing is detected.
====> * check_systemd_broken_symlinks
        Check whether some systemd symlinks are broken
====> * bacula_check
        Actor checking for presence of Bacula installation.
====> * check_valid_grubcfg_hybrid
        Check potential for boot failures in Azure Gen1 VMs due to invalid grubcfg
====> * cephvolumescan
        Retrieves the list of encrypted Ceph OSD
====> * check_openssl_conf
        Check whether the openssl configuration and openssl-IBMCA.
====> * check_yum_plugins_enabled
        Checks that the required yum plugins are enabled.
====> * check_persistent_mounts
        Check if mounts required to be persistent are mounted in persistent fashion.
====> * check_deprecated_rpm_signature
        Check whether any packages signed by RSA/SHA1 are installed
====> * checkblacklistca
        No documentation has been provided for the checkblacklistca actor.
====> * check_cifs
        Check if CIFS filesystem is in use. If yes, inhibit the upgrade process.
====> * roce_check
        Check whether RoCE is used on the system and well configured for the upgrade.
====> * check_boot_avail_space
        Check if at least 100Mib of available space on /boot. If not, inhibit the upgrade process.
====> * check_ipa_server
        Check for ipa-server and inhibit upgrade
====> * check_grubenv_to_file
        Check whether grubenv is a symlink on Azure hybrid images using BIOS.
====> * dotnet_unsupported_versions_check
        Check for installed .NET versions that are no longer supported.
====> * open_ssh_subsystem_sftp
        The RHEL9 changes the SCP to use SFTP protocol internally. The both RHEL8 and RHEL9
====> * check_detected_devices_and_drivers
        Checks whether or not detected devices and drivers are usable on the target system.
====> * check_dynamic_linker_configuration
        Check for customization of dynamic linker configuration.
====> * check_nfs
        Check if NFS filesystem is in use. If yes, inhibit the upgrade process.
====> * mariadb_check
        Actor checking for presence of MariaDB installation.
====> * check_consumed_assets
        Check whether Leapp is using correct data assets.
====> * checkmemory
        The actor check the size of RAM against RHEL8 minimal hardware requirements
====> * check_bls_grub_onppc64
        Check whether GRUB config is BLS aware on RHEL 8 ppc64le systems
====> * check_kpatch
        Carry over kpatch-dnf and it's config into the container
====> * check_rhsmsku
        Ensure the system is subscribed to the subscription manager
====> * check_ifcfg
        Ensures that ifcfg files are compatible with NetworkManager
====> * check_fips
        Inhibit upgrade if FIPS is detected as enabled.
====> * check_luks
        Check if any encrypted partitions are in use and whether they are supported for the upgrade.
====> * check_skip_phase
        Skip all the subsequent phases until the report phase.
====> * check_rpm_transaction_events
        Filter RPM transaction events based on installed RPM packages
==> Processing phase `TargetTransactionFactsCollection`
====> * create_iso_repofile
        Create custom repofile containing information about repositories found in target OS installation ISO, if used.
====> * target_userspace_creator
        Initializes a directory to be populated as a minimal environment to run binaries from the target system.
BaseOS for x86_64                               0.0  B/s |   0  B     00:00    

============================================================
                           ERRORS                           
============================================================

2026-01-12 08:56:38.945717 [ERROR] Actor: target_userspace_creator
Message: Unable to install RHEL 9 userspace packages.
Summary:
    Details: Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.
    Stderr: Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals
            Error: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!

============================================================
                       END OF ERRORS                        
============================================================

Debug output written to /var/log/leapp/leapp-preupgrade.log

============================================================
                      REPORT OVERVIEW                       
============================================================

Following errors occurred and the upgrade cannot continue:
    1. Actor: target_userspace_creator
       Message: Unable to install RHEL 9 userspace packages.

HIGH and MEDIUM severity reports:
    1. Packages available in excluded repositories will not be installed
    2. Upgrade is unsupported
    3. Remote root logins globally allowed using password
    4. GRUB2 core will be automatically updated during the upgrade

Reports summary:
    Errors:                      1
    Inhibitors:                  0
    HIGH severity reports:       4
    MEDIUM severity reports:     0
    LOW severity reports:        1
    INFO severity reports:       3

Before continuing, review the full report below for details about discovered problems and possible remediation instructions:
    A report has been generated at /var/log/leapp/leapp-report.txt
    A report has been generated at /var/log/leapp/leapp-report.json

============================================================
                   END OF REPORT OVERVIEW                   
============================================================

Answerfile has been generated at /var/log/leapp/answerfile
Job ended at 2026-01-12T13:57:04Z
", "encoding": "base64", "source": "/var/log/ripu/ripu.log"} RUNNING HANDLER [infra.leapp.common : Decode ripu.log file] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:26 ok: [managed-node02] => {"ansible_facts": {"ripu_log_file": ["RIPU preupgrade analysis", "Job started at 2026-01-12T13:55:53Z", "", "============================================================", " UNSUPPORTED UPGRADE ", "============================================================", "", "Variable LEAPP_UNSUPPORTED has been detected. Proceeding at your own risk.", "Development variables have been detected:", "- LEAPP_DEVEL_RPMS_ALL_SIGNED=1", "", "============================================================", " UNSUPPORTED UPGRADE ", "============================================================", "", "==> Processing phase `configuration_phase`", "====> * ipu_workflow_config", " IPU workflow config actor", "==> Processing phase `FactsCollection`", "====> * scandasd", " In case of s390x architecture, check whether DASD is used.", "====> * storage_scanner", " Provides data about storage settings.", "====> * firewalld_collect_used_object_names", " This actor reads firewalld's configuration and produces Model", "====> * rpm_scanner", " Provides data about installed RPM Packages.", "====> * scanzfcp", " In case of s390x architecture, check whether ZFCP is used.", "====> * persistentnetnames", " Get network interface information for physical ethernet interfaces of the original system.", "====> * open_ssl_config_scanner", " Read an OpenSSL configuration file for further analysis.", "====> * remove_obsolete_gpg_keys", " Remove obsoleted RPM GPG keys.", "====> * get_enabled_modules", " Provides data about which module streams are enabled on the source system.", "====> * scan_custom_modifications_actor", " Collects information about files in leapp directories that have been modified or newly added.", "====> * network_manager_read_config", " Provides data about NetworkManager configuration.", "====> * distribution_signed_rpm_scanner", " Provide data about distribution signed & third-party RPM packages.", "====> * scan_systemd_source", " Provides info about systemd on the source system", "====> * scanclienablerepo", " Produce CustomTargetRepository based on the LEAPP_ENABLE_REPOS in config.", "====> * nis_scanner", " Collect information about the NIS packages configuration.", "====> * ifcfg_scanner", " Scan ifcfg files with legacy network configuration", "====> * firewalld_collect_global_config", " This actor reads firewalld's configuration and produces Model", "====> * scan_target_os_image", " Scans the provided target OS ISO image to use as a content source for the IPU, if any.", "====> * persistentnetnamesdisable", " Disable systemd-udevd persistent network naming on machine with single eth0 NIC", "====> * vdo_conversion_scanner", " Provides conversion info about VDO devices.", "====> * scan_files_for_target_userspace", " Scan the source system and identify files that will be copied into the target userspace when it is created.", "====> * scan_source_boot_entry", " Scan the default boot entry of the source system.", "====> * scan_source_files", " Scan files (explicitly specified) of the source system.", "====> * luks_scanner", " Provides data about active LUKS devices.", "====> * scan_grub_device_name", " Find the name of the block devices where GRUB is located", "====> * multipath_conf_read_8to9", " Read multipath configuration files and extract the necessary information", "====> * scan_default_initramfs", " Scan details of the default boot entry's initramfs image.", "====> * network_manager_connection_scanner", " Scan NetworkManager connection keyfiles", "====> * copy_dnf_conf_into_target_userspace", " Copy dnf.conf into target userspace", "====> * get_installed_desktops", " Actor checks if kde or gnome desktop environments", "====> * root_scanner", " Scan the system root directory and produce a message containing", "====> * system_facts", " Provides data about many facts from system.", "====> * load_device_driver_deprecation_data", " Loads deprecation data for drivers and devices (PCI & CPU)", "====> * selinuxcontentscanner", " Scan the system for any SELinux customizations", "====> * sssd_facts_8to9", " Check SSSD configuration for changes in RHEL9 and report them in model.", "====> * scancryptopolicies", " Scan information about system wide set crypto policies including:", "====> * scan_source_kernel", " Scan the source system kernel.", "====> * scan_sap_hana", " Gathers information related to SAP HANA instances on the system.", "====> * check_custom_network_scripts", " Check the existence of custom network-scripts and warn user about possible", "====> * read_openssh_config", " Collect information about the OpenSSH configuration.", "====> * xorgdrvfacts8to9", " Check the journal logs for deprecated Xorg drivers.", "====> * biosdevname", " Enable biosdevname on the target RHEL system if all interfaces on the source RHEL", "====> * scan_hybrid_image_azure", " Check if the system is using Azure hybrid image.", "====> * udevadm_info", " Produces data exported by the \"udevadm info\" command.", "====> * scan_pkg_manager", " Provides data about package manager (yum/dnf)", "====> * trusted_gpg_keys_scanner", " Scan for trusted GPG keys.", "====> * scan_grub_config", " Scan grub configuration files for errors.", "====> * register_ruby_irb_adjustment", " Register a workaround to allow rubygem-irb's directory -> symlink conversion.", "====> * roce_scanner", " Detect active RoCE NICs on IBM Z machines.", "====> * checkrhui", " Check if system is using RHUI infrastructure (on public cloud) and send messages to", "====> * transaction_workarounds", " Provides additional RPM transaction tasks based on bundled RPM packages.", "====> * scan_subscription_manager_info", " Scans the current system for subscription manager information", "====> * xfs_info_scanner", " This actor scans all mounted mountpoints for XFS information.", "====> * pci_devices_scanner", " Provides data about existing PCI Devices.", "====> * scan_kernel_cmdline", " Scan the kernel command line of the booted system.", "====> * scan_dynamic_linker_configuration", " Scan the dynamic linker configuration and find modifications.", "====> * scanblacklistca", " Scan the file system for distrusted CA's in the blacklist directory.", "====> * scan_custom_repofile", " Scan the custom /etc/leapp/files/leapp_upgrade_repositories.repo repo file.", "====> * scanmemory", " Scan Memory of the machine.", "====> * repository_mapping", " Produces message containing repository mapping based on provided file.", "====> * used_repository_scanner", " Scan used enabled repositories", "====> * ipa_scanner", " Scan system for ipa-client and ipa-server status", "====> * rpm_transaction_config_tasks_collector", " Provides additional RPM transaction tasks from /etc/leapp/transaction.", "====> * satellite_upgrade_facts", " Report which Satellite packages require updates and how to handle PostgreSQL data", "====> * repositories_blacklist", " Exclude target repositories provided by Red Hat without support.", "====> * detect_kernel_drivers", " Matches all currently loaded kernel drivers against known deprecated and removed drivers.", "====> * scan_fips", " Determine whether the source system has FIPS enabled.", "====> * scancpu", " Scan CPUs of the machine.", "====> * satellite_upgrade_services", " Reconfigure Satellite services", "====> * pes_events_scanner", " Provides data about package events from Package Evolution Service.", "====> * setuptargetrepos", " Produces list of repositories that should be available to be used during IPU process.", "==> Processing phase `Checks`", "====> * check_microarchitecture", " Inhibit if RHEL9 microarchitecture requirements are not satisfied", "====> * check_se_linux", " Check SELinux status and produce decision messages for further action.", "====> * efi_check_boot", " Adjust EFI boot entry for first reboot", "====> * crypto_policies_check", " This actor consumes previously gathered information about crypto policies on the source", "====> * check_root_symlinks", " Check if the symlinks /bin and /lib are relative, not absolute.", "====> * checktargetrepos", " Check whether target yum repositories are specified.", "====> * check_system_arch", " Check if system is running at a supported architecture. If no, inhibit the upgrade process.", "====> * unsupported_upgrade_check", " Checks environment variables and produces a warning report if the upgrade is unsupported.", "====> * check_os_release", " Check if the current RHEL minor version is supported. If not, inhibit the upgrade process.", "====> * open_ssl_config_check", " The OpenSSL configuration changed between RHEL8 and RHEL9 significantly with the rebase to", "====> * multipath_conf_check_8to9", " Checks if changes to the multipath configuration files are necessary", "====> * check_arm_bootloader", " Install required RPM packages for ARM system upgrades on paths with", "====> * nis_check", " Checks if any of NIS components is installed and configured", "====> * check_target_version", " Check that the target system version is supported by the upgrade process.", "====> * open_ssh_drop_in_directory_check", " Trigger a notice that the main sshd_config will be updated to contain", "====> * distribution_signed_rpm_check", " Check if there are any packages that are not signed by distribution GPG keys.", "====> * check_etc_releasever", " Check releasever info and provide a guidance based on the facts", "====> * firewalld_check_allow_zone_drifting", " This actor will check if AllowZoneDrifting=yes in firewalld.conf. This", "====> * xorgdrvcheck8to9", " Warn if Xorg deprecated drivers are in use.", "====> * firewalld_check_service_tftp_client", " This actor will inhibit if firewalld's configuration is using service", "====> * check_skipped_repositories", " Produces a report if any repositories enabled on the system are going to be skipped.", "====> * check_vdo", " Check if VDO devices need to be migrated to lvm management.", "====> * check_target_iso", " Check that the provided target ISO is a valid ISO image and is located on a persistent partition.", "====> * network_deprecations", " Ensures that network configuration doesn't rely on unsupported settings", "====> * emit_net_naming_scheme", " Emit necessary modifications of the upgrade environment and target command line to use net.naming-scheme.", "====> * check_custom_modifications_actor", " Checks CustomModifications messages and produces a report about files in leapp directories that have been", "====> * sssd_check_8to9", " Check SSSD configuration for changes in RHEL9 and report them in model.", "====> * check_insights_auto_register", " Checks if system can be automatically registered into Red Hat Insights", "====> * check_installed_kernels", " Inhibit IPU (in-place upgrade) when installed kernels conflict with a safe upgrade.", "====> * check_sap_hana", " If SAP HANA has been detected, several checks are performed to ensure a successful upgrade.", "====> * mysql_check", " Actor checking for presence of MySQL installation.", "====> * check_nvidia_proprietary_driver", " Check if NVIDIA proprietary driver is in use. If yes, inhibit the upgrade process.", "====> * openssh_permit_root_login", " OpenSSH no longer allows root logins with password.", "====> * check_grub_core", " Check whether we are on legacy (BIOS) system and instruct Leapp to upgrade GRUB core", "====> * detect_grub_config_error", " Check grub configuration for various errors.", "====> * check_mount_options", " Check for mount options preventing the upgrade.", "====> * postgresql_check", " Actor checking for presence of PostgreSQL installation.", "====> * check_fstab_mount_order", " Checks order of entries in /etc/fstab based on their mount point and inhibits upgrade if overshadowing is detected.", "====> * check_systemd_broken_symlinks", " Check whether some systemd symlinks are broken", "====> * bacula_check", " Actor checking for presence of Bacula installation.", "====> * check_valid_grubcfg_hybrid", " Check potential for boot failures in Azure Gen1 VMs due to invalid grubcfg", "====> * cephvolumescan", " Retrieves the list of encrypted Ceph OSD", "====> * check_openssl_conf", " Check whether the openssl configuration and openssl-IBMCA.", "====> * check_yum_plugins_enabled", " Checks that the required yum plugins are enabled.", "====> * check_persistent_mounts", " Check if mounts required to be persistent are mounted in persistent fashion.", "====> * check_deprecated_rpm_signature", " Check whether any packages signed by RSA/SHA1 are installed", "====> * checkblacklistca", " No documentation has been provided for the checkblacklistca actor.", "====> * check_cifs", " Check if CIFS filesystem is in use. If yes, inhibit the upgrade process.", "====> * roce_check", " Check whether RoCE is used on the system and well configured for the upgrade.", "====> * check_boot_avail_space", " Check if at least 100Mib of available space on /boot. If not, inhibit the upgrade process.", "====> * check_ipa_server", " Check for ipa-server and inhibit upgrade", "====> * check_grubenv_to_file", " Check whether grubenv is a symlink on Azure hybrid images using BIOS.", "====> * dotnet_unsupported_versions_check", " Check for installed .NET versions that are no longer supported.", "====> * open_ssh_subsystem_sftp", " The RHEL9 changes the SCP to use SFTP protocol internally. The both RHEL8 and RHEL9", "====> * check_detected_devices_and_drivers", " Checks whether or not detected devices and drivers are usable on the target system.", "====> * check_dynamic_linker_configuration", " Check for customization of dynamic linker configuration.", "====> * check_nfs", " Check if NFS filesystem is in use. If yes, inhibit the upgrade process.", "====> * mariadb_check", " Actor checking for presence of MariaDB installation.", "====> * check_consumed_assets", " Check whether Leapp is using correct data assets.", "====> * checkmemory", " The actor check the size of RAM against RHEL8 minimal hardware requirements", "====> * check_bls_grub_onppc64", " Check whether GRUB config is BLS aware on RHEL 8 ppc64le systems", "====> * check_kpatch", " Carry over kpatch-dnf and it's config into the container", "====> * check_rhsmsku", " Ensure the system is subscribed to the subscription manager", "====> * check_ifcfg", " Ensures that ifcfg files are compatible with NetworkManager", "====> * check_fips", " Inhibit upgrade if FIPS is detected as enabled.", "====> * check_luks", " Check if any encrypted partitions are in use and whether they are supported for the upgrade.", "====> * check_skip_phase", " Skip all the subsequent phases until the report phase.", "====> * check_rpm_transaction_events", " Filter RPM transaction events based on installed RPM packages", "==> Processing phase `TargetTransactionFactsCollection`", "====> * create_iso_repofile", " Create custom repofile containing information about repositories found in target OS installation ISO, if used.", "====> * target_userspace_creator", " Initializes a directory to be populated as a minimal environment to run binaries from the target system.", "BaseOS for x86_64 0.0 B/s | 0 B 00:00 ", "", "============================================================", " ERRORS ", "============================================================", "", "2026-01-12 08:56:38.945717 [ERROR] Actor: target_userspace_creator", "Message: Unable to install RHEL 9 userspace packages.", "Summary:", " Details: Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.", " Stderr: Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals", " Error: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!", "", "============================================================", " END OF ERRORS ", "============================================================", "", "Debug output written to /var/log/leapp/leapp-preupgrade.log", "", "============================================================", " REPORT OVERVIEW ", "============================================================", "", "Following errors occurred and the upgrade cannot continue:", " 1. Actor: target_userspace_creator", " Message: Unable to install RHEL 9 userspace packages.", "", "HIGH and MEDIUM severity reports:", " 1. Packages available in excluded repositories will not be installed", " 2. Upgrade is unsupported", " 3. Remote root logins globally allowed using password", " 4. GRUB2 core will be automatically updated during the upgrade", "", "Reports summary:", " Errors: 1", " Inhibitors: 0", " HIGH severity reports: 4", " MEDIUM severity reports: 0", " LOW severity reports: 1", " INFO severity reports: 3", "", "Before continuing, review the full report below for details about discovered problems and possible remediation instructions:", " A report has been generated at /var/log/leapp/leapp-report.txt", " A report has been generated at /var/log/leapp/leapp-report.json", "", "============================================================", " END OF REPORT OVERVIEW ", "============================================================", "", "Answerfile has been generated at /var/log/leapp/answerfile", "Job ended at 2026-01-12T13:57:04Z", ""]}, "changed": false} RUNNING HANDLER [infra.leapp.common : Rename log file] ************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:32 changed: [managed-node02] => {"changed": true, "cmd": "export PATH=$PATH\nmv /var/log/ripu/ripu.log /var/log/ripu/ripu.log-20260112T085408\n", "delta": "0:00:00.004092", "end": "2026-01-12 08:57:05.447870", "msg": "", "rc": 0, "start": "2026-01-12 08:57:05.443778", "stderr": "", "stderr_lines": [], "stdout": "", "stdout_lines": []} RUNNING HANDLER [infra.leapp.common : Check for log file] ********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:3 ok: [managed-node02] => {"changed": false, "stat": {"exists": false}} RUNNING HANDLER [infra.leapp.common : Add end time to log file] **************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:9 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Slurp ripu.log file] ********************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:19 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Decode ripu.log file] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:26 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Rename log file] ************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:32 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.analysis : Display inhibitors] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/handlers/main.yml:32 skipping: [managed-node02] => {} RUNNING HANDLER [infra.leapp.analysis : Display errors] ************************ task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/handlers/main.yml:40 ok: [managed-node02] => { "results_errors.stdout_lines": [ "Risk Factor: high (error)", "Title: Unable to install RHEL 9 userspace packages.", "Summary: {\"details\": \"Command ['systemd-nspawn', '--register=no', '--quiet', '--keep-unit', '--capability=all', '-D', '/var/lib/leapp/scratch/mounts/root_/system_overlay', '--setenv=LEAPP_DEVEL_RPMS_ALL_SIGNED=1', '--setenv=LEAPP_UNSUPPORTED=1', '--setenv=LEAPP_HOSTNAME=managed-node02', '--setenv=LEAPP_EXPERIMENTAL=0', '--setenv=LEAPP_NO_RHSM=1', '--setenv=LEAPP_NO_RHSM_FACTS=1', '--setenv=LEAPP_TARGET_PRODUCT_CHANNEL=ga', '--setenv=LEAPP_UPGRADE_PATH_TARGET_RELEASE=9.7', '--setenv=LEAPP_UPGRADE_PATH_FLAVOUR=default', '--setenv=LEAPP_IPU_IN_PROGRESS=8to9', '--setenv=LEAPP_EXECUTION_ID=1c608039-3f80-4c54-a658-1b63f885c00d', '--setenv=LEAPP_COMMON_TOOLS=:/etc/leapp/repos.d/system_upgrade/common/tools:/etc/leapp/repos.d/system_upgrade/el8toel9/tools', '--setenv=LEAPP_COMMON_FILES=:/etc/leapp/repos.d/system_upgrade/common/files:/etc/leapp/repos.d/system_upgrade/el8toel9/files', 'dnf', 'install', '-y', '--setopt=module_platform_id=platform:el9', '--setopt=keepcache=1', '--releasever', '9.7', '--installroot', '/el9target', '--disablerepo', '*', '--enablerepo', 'rhel-9-for-x86_64-baseos-rpms', '--enablerepo', 'rhel-9-for-x86_64-appstream-rpms', 'dnf-command(config-manager)', 'dnf', 'util-linux', '--disableplugin', 'subscription-manager'] failed with exit code 1.\", \"stderr\": \"Host and machine ids are equal (ec252cf5e84d82267655798af7ca1889): refusing to link journals\\nError: Failed to download metadata for repo 'rhel-9-for-x86_64-baseos-rpms': Cannot download repomd.xml: Empty mirrorlist and no basepath specified!\\n\"}", "Key: 0e5d8451adfe372b923058fd09028cb5356e733d", "----------------------------------------" ] } RUNNING HANDLER [infra.leapp.analysis : Preupgrade analysis report is done] **** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/analysis/handlers/main.yml:48 ok: [managed-node02] => { "msg": "The preupgrade analysis report generation is now complete. WARNING: Inhibitors found. Review the tasks above or the result file at /var/log/leapp/leapp-report.txt." } RUNNING HANDLER [infra.leapp.common : Check for log file] ********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:3 ok: [managed-node02] => {"changed": false, "stat": {"exists": false}} RUNNING HANDLER [infra.leapp.common : Add end time to log file] **************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:9 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Slurp ripu.log file] ********************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:19 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Decode ripu.log file] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:26 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Rename log file] ************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:32 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Check for log file] ********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:3 ok: [managed-node02] => {"changed": false, "stat": {"exists": false}} RUNNING HANDLER [infra.leapp.common : Add end time to log file] **************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:9 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Slurp ripu.log file] ********************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:19 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Decode ripu.log file] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:26 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Rename log file] ************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:32 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Check for log file] ********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:3 ok: [managed-node02] => {"changed": false, "stat": {"exists": false}} RUNNING HANDLER [infra.leapp.common : Add end time to log file] **************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:9 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Slurp ripu.log file] ********************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:19 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Decode ripu.log file] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:26 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Rename log file] ************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:32 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Check for log file] ********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:3 ok: [managed-node02] => {"changed": false, "stat": {"exists": false}} RUNNING HANDLER [infra.leapp.common : Add end time to log file] **************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:9 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Slurp ripu.log file] ********************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:19 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Decode ripu.log file] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:26 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Rename log file] ************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:32 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Check for log file] ********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:3 ok: [managed-node02] => {"changed": false, "stat": {"exists": false}} RUNNING HANDLER [infra.leapp.common : Add end time to log file] **************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:9 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Slurp ripu.log file] ********************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:19 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Decode ripu.log file] ******************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:26 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} RUNNING HANDLER [infra.leapp.common : Rename log file] ************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/roles/common/handlers/main.yml:32 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [common_upgrade_tasks | Run upgrade role] ********************************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:103 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [common_upgrade_tasks | Gather verify postupgrade tasks] ****************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:110 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [common_upgrade_tasks | Run verification tasks after upgrade] ************* task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/common_upgrade_tasks.yml:118 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [tests_upgrade_custom | Assert that the system has been upgraded] ********* task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/tests_upgrade_custom.yml:30 skipping: [managed-node02] => {"changed": false, "skip_reason": "Conditional result was False"} TASK [tests_upgrade_custom | Mark upgrade as completed] ************************ task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/tests_upgrade_custom.yml:45 ok: [managed-node02] => {"ansible_facts": {"leapp_upgrade_completed": true}, "changed": false} TASK [tests_upgrade_custom | Cleanup | Remove log files] *********************** task path: /root/.ansible/collections/ansible_collections/infra/leapp/tests/tasks/tests_upgrade_custom.yml:49 changed: [managed-node02] => {"changed": true, "cmd": "set -euxo pipefail\nrm -f /var/log/leapp/leapp-upgrade.log\nrm -f /var/log/ripu/ripu.log*\n", "delta": "0:00:00.004523", "end": "2026-01-12 08:57:08.516296", "msg": "", "rc": 0, "start": "2026-01-12 08:57:08.511773", "stderr": "+ rm -f /var/log/leapp/leapp-upgrade.log\n+ rm -f /var/log/ripu/ripu.log-20260112T085408", "stderr_lines": ["+ rm -f /var/log/leapp/leapp-upgrade.log", "+ rm -f /var/log/ripu/ripu.log-20260112T085408"], "stdout": "", "stdout_lines": []} PLAY RECAP ********************************************************************* managed-node02 : ok=131 changed=36 unreachable=0 failed=0 skipped=73 rescued=0 ignored=0