diff --git a/.gitignore b/.gitignore index 8574401..329f996 100644 --- a/.gitignore +++ b/.gitignore @@ -53,3 +53,8 @@ /scap-security-guide-0.1.67.tar.bz2 /scap-security-guide-0.1.68.tar.bz2 /scap-security-guide-0.1.69.tar.bz2 +/scap-security-guide-0.1.70.tar.bz2 +/scap-security-guide-0.1.71.tar.bz2 +/scap-security-guide-0.1.72.tar.bz2 +/scap-security-guide-0.1.73.tar.bz2 +/scap-security-guide-0.1.74.tar.bz2 diff --git a/gating.yaml b/gating.yaml index 1d65cc1..46eab8d 100644 --- a/gating.yaml +++ b/gating.yaml @@ -17,6 +17,4 @@ product_versions: - rhel-* decision_context: osci_compose_gate rules: - - !PassingTestCaseRule {test_case_name: baseos-ci.brew-build.tier1.functional} - - !PassingTestCaseRule {test_case_name: baseos-ci.brew-build.ci-beaker.functional} - - !PassingTestCaseRule {test_case_name: baseos-ci.brew-build.tedude.validation} + - !PassingTestCaseRule {test_case_name: osci.brew-build./plans/ci/tier1.functional} diff --git a/plans/fedora_tests.fmf b/plans/fedora_tests.fmf index 63d6437..3f21692 100644 --- a/plans/fedora_tests.fmf +++ b/plans/fedora_tests.fmf @@ -1,6 +1,5 @@ -summary: Run tests from scap-security-guide tests repository +summary: Run all tests in this repository discover: how: fmf - url: https://src.fedoraproject.org/tests/scap-security-guide execute: how: tmt diff --git a/scap-security-guide.spec b/scap-security-guide.spec index d45547b..8a35575 100644 --- a/scap-security-guide.spec +++ b/scap-security-guide.spec @@ -4,7 +4,7 @@ %global _vpath_builddir build Name: scap-security-guide -Version: 0.1.69 +Version: 0.1.74 Release: 1%{?dist} Summary: Security guidance and baselines in SCAP formats License: BSD-3-Clause @@ -99,6 +99,26 @@ rm %{buildroot}/%{_docdir}/%{name}/Contributors.md %endif %changelog +* Mon Aug 12 2024 Matthew Burket - 0.1.74-1 +- Update to latest upstream release + https://github.com/ComplianceAsCode/content/releases/tag/v0.1.74 + +* Wed May 22 2024 Jan Černý - 0.1.73-1 +- Update to latest upstream release + https://github.com/ComplianceAsCode/content/releases/tag/v0.1.73 + +* Fri Feb 09 2024 Vojtech Polasek - 0.1.72-1 +- Update to latest upstream SCAP-Security-Guide-0.1.72 release: + https://github.com/ComplianceAsCode/content/releases/tag/v0.1.72 + +* Tue Dec 19 2023 Vojtech Polasek - 0.1.71-1 +- Update to latest upstream SCAP-Security-Guide-0.1.71 release: + https://github.com/ComplianceAsCode/content/releases/tag/v0.1.71 + +* Thu Oct 12 2023 Matthew Burket - 0.1.70-1 +- Update to latest upstream SCAP-Security-Guide-0.1.70 release: + https://github.com/ComplianceAsCode/content/releases/tag/v0.1.70 + * Thu Aug 03 2023 Jan Černý - 0.1.69-1 - Update to latest upstream SCAP-Security-Guide-0.1.69 release: https://github.com/ComplianceAsCode/content/releases/tag/v0.1.69 diff --git a/sources b/sources index b00e054..0ced6da 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (scap-security-guide-0.1.69.tar.bz2) = 224d308608c1254a74290f2967f39ba0cef2df199399d70cb1b90386836bb1da313bf699e488d15a308c0a6ea70c30a8f5cc4a6c0b58a863f2f8154f022dd7bb +SHA512 (scap-security-guide-0.1.74.tar.bz2) = 773cc7fb72e8d24fe9b12bf58815e051db21ee474cd0c3aebd07c2026712a89e6174c00840b1fd56195c900a541ff9e656240ee6b5a1cf3f3fe9b119cbedc30f diff --git a/tests/smoke-test/main.fmf b/tests/smoke-test/main.fmf new file mode 100644 index 0000000..6e01198 --- /dev/null +++ b/tests/smoke-test/main.fmf @@ -0,0 +1,27 @@ +summary: Test calls upstream test suite. +description: | + Runs upstream test suite against content built from the source RPM - testing + the content from the installed scap-security-guide is not feasible as the + upstream test suite is hardcoded to test the content from the CMAKE_BINARY_DIR + directory with hardcoded paths which are not the same as paths where content is + installed from the scap-security-guide RPM. Test suite is also built from the + scap-security-guide source RPM by running %prep and %build stages from the spec + file. +contact: Matus Marhefka +test: ./runtest.sh +framework: beakerlib +require: + - library(ControlFlow/Cleanup) + - library(rpm/snapshot) + - scap-security-guide +recommend: + - yum-utils + - rpm-build + - dnf-plugins-core + - gcc + - python3-pytest + - python3-pip + - python3-devel + - ansible +duration: 90m +enabled: true diff --git a/tests/smoke-test/runtest.sh b/tests/smoke-test/runtest.sh new file mode 100755 index 0000000..b356a60 --- /dev/null +++ b/tests/smoke-test/runtest.sh @@ -0,0 +1,80 @@ +#!/bin/bash +# vim: dict=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# runtest.sh of /CoreOS/scap-security-guide/Sanity/smoke-test +# Description: Test calls upstream test suite. +# Author: Marek Haicman +# +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# Copyright (c) 2018 Red Hat, Inc. All rights reserved. +# +# This copyrighted material is made available to anyone wishing +# to use, modify, copy, or redistribute it subject to the terms +# and conditions of the GNU General Public License version 2. +# +# This program is distributed in the hope that it will be +# useful, but WITHOUT ANY WARRANTY; without even the implied +# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR +# PURPOSE. See the GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public +# License along with this program; if not, write to the Free +# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, +# Boston, MA 02110-1301, USA. +# +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +. /usr/share/beakerlib/beakerlib.sh || exit 1 + +PACKAGE="scap-security-guide" + +rlJournalStart + + rlPhaseStartSetup + rlImport ControlFlow/Cleanup rpm/snapshot || rlDie "Failed to import libraries" + rlAssertRpm "$PACKAGE" + + RpmSnapshotCreate + CleanupRegister "RpmSnapshotRevert" + rlRun "TmpDir=\$(mktemp -d)" 0 + CleanupRegister "rlRun 'rm -r $TmpDir' 0 'Removing tmp directory'" + rlRun "pushd $TmpDir" + CleanupRegister "rlRun 'popd'" + + rlFetchSrcForInstalled $PACKAGE + rlRun "dnf builddep -y $PACKAGE*" + SITE_PACKAGES=$(python3 -c 'import sysconfig; print(sysconfig.get_paths()["purelib"])') + rlRun "pip3 install --target=$SITE_PACKAGES ruamel.yaml yamlpath prometheus-client" + CleanupRegister "rlRun 'pip3 uninstall -y ruamel.yaml yamlpath prometheus-client'" + TOPDIR=`rpm --eval %_topdir` + rlRun "rm -rf ${TOPDIR}/BUILD/${PACKAGE}*" 0-255 + rlRun "rpm -ihv `ls *.rpm`" 0 "Install $PACKAGE source RPM" + rlPhaseEnd + + rlPhaseStartSetup "Prepare upstream test suite (%prep and %build stages from the spec file)" + rlRun "rpmbuild -v -bc ${TOPDIR}/SPECS/${PACKAGE}.spec" + CleanupRegister "rlRun 'rm -rf ${TOPDIR}/BUILD/${PACKAGE}*'" + CleanupRegister "rlRun 'rm -rf ${TOPDIR}/SPECS/${PACKAGE}*'" + CleanupRegister "rlRun 'rm -rf ${TOPDIR}/SOURCES/*'" + rlPhaseEnd + + rlPhaseStartTest "Run upstream test suite" + BUILD_DIR_PATH="$(find $TOPDIR -name build | grep scap-security-guide)" + rlRun -s "cmake --build $BUILD_DIR_PATH --target test -- ARGS='--output-on-failure'" + rv=$? + + # if we got error, submit file with result of particular test for easier debugging + if [ $rv -ne 0 ]; then + FILE="${BUILD_DIR_PATH}/Testing/Temporary/LastTest.log" + rlBundleLogs test_outputs $(readlink -f $FILE) + fi + rlPhaseEnd + + rlPhaseStartCleanup + CleanupDo + rlPhaseEnd + +rlJournalPrintText +rlJournalEnd