Use the kernel_module Chef InSpec audit resource to test kernel modules on Linux platforms. These parameters are located under /lib/modules. Any submodule may be tested using this resource.
The kernel_module resource can also verify if a kernel module is blacklisted or if a module is disabled via a fake install using the bin_true or bin_false method.
This resource is distributed along with Chef InSpec itself. You can use it automatically.
This resource first became available in v1.0.0 of InSpec.
A kernel_module resource block declares a module name, and then tests if that module is a loaded kernel module, if it is enabled, disabled or if it is blacklisted:
describe kernel_module('module_name') do
it { should be_loaded }
it { should_not be_disabled }
it { should_not be_blacklisted }
end
where
'module_name' must specify a kernel module, such as 'bridge'
{ should be_loaded } tests if the module is a loaded kernel module{ should be_blacklisted } tests if the module is blacklisted or if the module is disabled via a fake install using /bin/false or /bin/true{ should be_disabled } tests if the module is disabled via a fake install using /bin/false or /bin/trueThe following examples show how to use this Chef InSpec audit resource.
The version property tests if the kernel module on the system has the correct version:
its('version') { should eq '3.2.2' }
describe kernel_module('bridge') do
it { should be_loaded }
its('version') { should cmp >= '2.2.2' }
end
describe kernel_module('video') do
it { should be_loaded }
it { should_not be_disabled }
it { should_not be_blacklisted }
end
describe kernel_module('floppy') do
it { should be_blacklisted }
end
describe kernel_module('video') do
it { should_not be_blacklisted }
it { should be_loaded }
end
describe kernel_module('sstfb') do
it { should_not be_loaded }
it { should be_disabled }
end
describe kernel_module('nvidiafb') do
it { should_not be_loaded }
it { should be_blacklisted }
end
describe kernel_module('dhcp') do
it { should_not be_loaded }
end
For a full list of available matchers, please visit our matchers page.
The be_blacklisted matcher tests if the kernel module is a blacklisted module:
it { should be_blacklisted }
The be_disabled matcher tests if the kernel module is disabled:
it { should be_disabled }
The be_loaded matcher tests if the kernel module is loaded:
it { should be_loaded }
© Chef Software, Inc.
Licensed under the Creative Commons Attribution 3.0 Unported License.
The Chef™ Mark and Chef Logo are either registered trademarks/service marks or trademarks/servicemarks of Chef, in the United States and other countries and are used with Chef Inc's permission.
We are not affiliated with, endorsed or sponsored by Chef Inc.
https://docs.chef.io/inspec/resources/kernel_module/