diff --git a/.gitignore b/.gitignore index c74915f..2c5004b 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,51 @@ -/scap-security-guide-0.1.78.tar.bz2 -/scap-security-guide-0.1.79.tar.bz2 +/scap-security-guide-0.1-3.tar.gz +/scap-security-guide-0.1.4.tar.gz +/scap-security-guide-0.1-16.tar.gz +/scap-security-guide-0.1.5.tar.gz +/scap-security-guide-0.1.18.tar.gz +/scap-security-guide-0.1.19.tar.gz +/scap-security-guide-0.1.21.tar.gz +/v0.1.22.tar.gz +/v0.1.23.tar.gz +/v0.1.24.tar.gz +/v0.1.25.tar.gz +/v0.1.26.tar.gz +/v0.1.27.tar.gz +/v0.1.28.tar.gz +/scap-security-guide-0.1.29.tar.gz +/0.1.29.tar.gz +/v0.1.29.tar.gz +/v0.1.30.tar.gz +/scap-security-guide-0.1.31.tar.gz +/scap-security-guide-0.1.32.tar.gz +/scap-security-guide-0.1.33.tar.bz2 +/scap-security-guide-0.1.34.tar.bz2 +/scap-security-guide-0.1.35.tar.bz2 +/scap-security-guide-0.1.36.tar.bz2 +/scap-security-guide-0.1.37.tar.bz2 +/scap-security-guide-0.1.38.tar.bz2 +/scap-security-guide-0.1.39.tar.bz2 +/scap-security-guide-0.1.40.tar.bz2 +/scap-security-guide-0.1.41.tar.bz2 +/scap-security-guide-0.1.42.tar.bz2 +/scap-security-guide-0.1.43.tar.bz2 +/scap-security-guide-0.1.44.tar.bz2 +/scap-security-guide-0.1.45.tar.bz2 +/scap-security-guide-0.1.47.tar.bz2 +/scap-security-guide-0.1.48.tar.bz2 +/scap-security-guide-0.1.49.tar.bz2 +/scap-security-guide-0.1.51.tar.bz2 +/scap-security-guide-0.1.52.tar.bz2 +/scap-security-guide-0.1.53.tar.bz2 +/scap-security-guide-0.1.54.tar.bz2 +/scap-security-guide-0.1.55.tar.bz2 +/scap-security-guide-0.1.56.tar.bz2 +/scap-security-guide-0.1.57.tar.bz2 +/scap-security-guide-0.1.58.tar.bz2 +/scap-security-guide-0.1.59.tar.bz2 +/scap-security-guide-0.1.60.tar.bz2 +/scap-security-guide-0.1.61.tar.bz2 +/scap-security-guide-0.1.62.tar.bz2 +/scap-security-guide-0.1.63.tar.bz2 +/scap-security-guide-0.1.64.tar.bz2 +/scap-security-guide-0.1.65.tar.bz2 diff --git a/gating.yaml b/gating.yaml index 46eab8d..1d65cc1 100644 --- a/gating.yaml +++ b/gating.yaml @@ -17,4 +17,6 @@ product_versions: - rhel-* decision_context: osci_compose_gate rules: - - !PassingTestCaseRule {test_case_name: osci.brew-build./plans/ci/tier1.functional} + - !PassingTestCaseRule {test_case_name: baseos-ci.brew-build.tier1.functional} + - !PassingTestCaseRule {test_case_name: baseos-ci.brew-build.ci-beaker.functional} + - !PassingTestCaseRule {test_case_name: baseos-ci.brew-build.tedude.validation} diff --git a/plans/fedora_tests.fmf b/plans/fedora_tests.fmf index 3f21692..63d6437 100644 --- a/plans/fedora_tests.fmf +++ b/plans/fedora_tests.fmf @@ -1,5 +1,6 @@ -summary: Run all tests in this repository +summary: Run tests from scap-security-guide tests repository discover: how: fmf + url: https://src.fedoraproject.org/tests/scap-security-guide execute: how: tmt diff --git a/scap-security-guide-0.1.60-fix-jinja-loading-PR_7944.patch b/scap-security-guide-0.1.60-fix-jinja-loading-PR_7944.patch new file mode 100644 index 0000000..72a07c4 --- /dev/null +++ b/scap-security-guide-0.1.60-fix-jinja-loading-PR_7944.patch @@ -0,0 +1,85 @@ +From 396fb9029e74b38ea09236c6cd1a7cb38f545afe Mon Sep 17 00:00:00 2001 +From: Gabriel Becker +Date: Wed, 1 Dec 2021 13:20:47 +0100 +Subject: [PATCH] Fix jinja issue on fedora rawhide. + +--- + tests/unit/ssg-module/test_playbook_builder.py | 4 ++-- + utils/duplicated_prodtypes.py | 4 ++-- + utils/fix_file_ocilclause.py | 4 ++-- + utils/move_rules.py | 2 +- + 4 files changed, 7 insertions(+), 7 deletions(-) + +diff --git a/tests/unit/ssg-module/test_playbook_builder.py b/tests/unit/ssg-module/test_playbook_builder.py +index 6692c54dfab..38b6f1f52e2 100644 +--- a/tests/unit/ssg-module/test_playbook_builder.py ++++ b/tests/unit/ssg-module/test_playbook_builder.py +@@ -34,9 +34,9 @@ def test_build_rule_playbook(): + assert os.path.exists(real_output_filepath) + + with open(real_output_filepath, "r") as real_output: +- real_output_yaml = yaml.load(real_output) ++ real_output_yaml = yaml.load(real_output, Loader=yaml.Loader) + with open(expected_output_filepath, "r") as expected_output: +- expected_output_yaml = yaml.load(expected_output) ++ expected_output_yaml = yaml.load(expected_output, Loader=yaml.Loader) + + real_play = real_output_yaml.pop() + expected_play = expected_output_yaml.pop() +diff --git a/utils/duplicated_prodtypes.py b/utils/duplicated_prodtypes.py +index 4cb2c16fef8..25c36c58d81 100755 +--- a/utils/duplicated_prodtypes.py ++++ b/utils/duplicated_prodtypes.py +@@ -23,7 +23,7 @@ def _create_profile_cache(ssg_root): + files.sort() + for filename in files: + profile_path = os.path.join(prod_profiles_dir, filename) +- parsed_profile = yaml.load(open(profile_path, 'r')) ++ parsed_profile = yaml.load(open(profile_path, 'r'), Loader=yaml.Loader) + for _obj in parsed_profile['selections']: + obj = _obj + if '=' in obj: +@@ -210,7 +210,7 @@ def find_profiles(ssg_root, path, obj_name): + def parse_from_yaml(file_contents, lines): + new_file_arr = file_contents[lines[0]:lines[1] + 1] + new_file = "\n".join(new_file_arr) +- return yaml.load(new_file) ++ return yaml.load(new_file, Loader=yaml.Loader) + + + def print_file(file_contents): +diff --git a/utils/fix_file_ocilclause.py b/utils/fix_file_ocilclause.py +index 462d2b37c15..d79bb8c51e0 100755 +--- a/utils/fix_file_ocilclause.py ++++ b/utils/fix_file_ocilclause.py +@@ -23,7 +23,7 @@ def _create_profile_cache(ssg_root): + files.sort() + for filename in files: + profile_path = os.path.join(prod_profiles_dir, filename) +- parsed_profile = yaml.load(open(profile_path, 'r')) ++ parsed_profile = yaml.load(open(profile_path, 'r'), Loader=yaml.Loader) + for _obj in parsed_profile['selections']: + obj = _obj + if '=' in obj: +@@ -205,7 +205,7 @@ def fix_ocil_clause(ssg_root, path, obj_name): + def parse_from_yaml(file_contents, lines): + new_file_arr = file_contents[lines[0]:lines[1] + 1] + new_file = "\n".join(new_file_arr) +- return yaml.load(new_file) ++ return yaml.load(new_file, Loader=yaml.Loader) + + + def print_file(file_contents): +diff --git a/utils/move_rules.py b/utils/move_rules.py +index 2deb62b488a..e91a661be85 100755 +--- a/utils/move_rules.py ++++ b/utils/move_rules.py +@@ -340,7 +340,7 @@ def fix_ocil_clause(ssg_root, path, obj_name): + def parse_from_yaml(file_contents, lines): + new_file_arr = file_contents[lines[0]:lines[1] + 1] + new_file = "\n".join(new_file_arr) +- return yaml.load(new_file) ++ return yaml.load(new_file, Loader=yaml.Loader) + + + def print_file(file_contents): diff --git a/scap-security-guide.spec b/scap-security-guide.spec index b9b927b..382f415 100644 --- a/scap-security-guide.spec +++ b/scap-security-guide.spec @@ -4,17 +4,20 @@ %global _vpath_builddir build Name: scap-security-guide -Version: 0.1.79 +Version: 0.1.65 Release: 1%{?dist} Summary: Security guidance and baselines in SCAP formats -License: BSD-3-Clause +License: BSD URL: https://github.com/ComplianceAsCode/content/ Source0: https://github.com/ComplianceAsCode/content/releases/download/v%{version}/scap-security-guide-%{version}.tar.bz2 BuildArch: noarch BuildRequires: libxslt +BuildRequires: expat BuildRequires: openscap-scanner >= 1.2.5 BuildRequires: cmake >= 2.8 +# To get python3 inside the buildroot require its path explicitly in BuildRequires +BuildRequires: /usr/bin/python3 BuildRequires: python%{python3_pkgversion} BuildRequires: python%{python3_pkgversion}-jinja2 BuildRequires: python%{python3_pkgversion}-PyYAML @@ -42,7 +45,7 @@ The %{name}-doc package contains HTML formatted documents containing hardening guidances that have been generated from XCCDF benchmarks present in %{name} package. -%if ( %{defined rhel} && (! %{defined centos}) && (! %{defined eln}) ) +%if ( %{defined rhel} && (! %{defined centos}) ) %package rule-playbooks Summary: Ansible playbooks per each rule. Group: System Environment/Base @@ -57,7 +60,7 @@ The %{name}-rule-playbooks package contains individual ansible playbooks per rul %define cmake_defines_common -DSSG_SEPARATE_SCAP_FILES_ENABLED=OFF -DSSG_BASH_SCRIPTS_ENABLED=OFF -DSSG_BUILD_SCAP_12_DS=OFF %define cmake_defines_specific %{nil} -%if 0%{?rhel} && ! %{defined eln} +%if 0%{?rhel} %define cmake_defines_specific -DSSG_PRODUCT_DEFAULT:BOOLEAN=FALSE -DSSG_PRODUCT_RHEL%{rhel}:BOOLEAN=TRUE -DSSG_SCIENTIFIC_LINUX_DERIVATIVES_ENABLED:BOOL=OFF -DSSG_CENTOS_DERIVATIVES_ENABLED:BOOL=OFF -DSSG_ANSIBLE_PLAYBOOKS_PER_RULE_ENABLED:BOOL=ON %endif %if 0%{?centos} @@ -81,7 +84,7 @@ rm %{buildroot}/%{_docdir}/%{name}/Contributors.md %{_datadir}/%{name}/tailoring %lang(en) %{_mandir}/man8/scap-security-guide.8.* %doc %{_docdir}/%{name}/LICENSE -%if ( %{defined rhel} && (! %{defined centos}) && (! %{defined eln}) ) +%if ( %{defined rhel} && (! %{defined centos}) ) %exclude %{_datadir}/%{name}/ansible/rule_playbooks %endif @@ -89,91 +92,13 @@ rm %{buildroot}/%{_docdir}/%{name}/Contributors.md %doc %{_docdir}/%{name}/guides/*.html %doc %{_docdir}/%{name}/tables/*.html -%if ( %{defined rhel} && (! %{defined centos}) && (! %{defined eln}) ) +%if ( %{defined rhel} && (! %{defined centos}) ) %files rule-playbooks %defattr(-,root,root,-) %{_datadir}/%{name}/ansible/rule_playbooks %endif %changelog -* Fri Nov 28 2025 Jan Černý - 0.1.79-1 -- Upgrade to the latest upstream release - -* Mon Sep 08 2025 Matthew Burket - 0.1.78-1 -- Update to latest upstream release: - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.78 - -* Fri Jul 25 2025 Fedora Release Engineering - 0.1.77-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Mon Jun 02 2025 Matthew Burket - 0.1.77-1 -- Update to latest upstream release: - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.77 - -* Fri Mar 07 2025 Matthew Burket - 0.1.76-2 -- Remove expat as a BuildRequires as it is no longer needed - -* Tue Feb 25 2025 Evgenii Kolesnikov - 0.1.76-1 -- Update to latest upstream release: - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.76 - -* Sun Jan 19 2025 Fedora Release Engineering - 0.1.75-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Thu Nov 14 2024 Matthew Burket - 0.1.75-1 -- Update to latest upstream release - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.75 - -* Mon Aug 12 2024 Matthew Burket - 0.1.74-1 -- Update to latest upstream release: - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.74 -- Remove /usr/bin/python3 from BuildRequires - -* Sat Jul 20 2024 Fedora Release Engineering - 0.1.73-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild - -* Wed May 22 2024 Jan Černý - 0.1.73-1 -- Update to latest upstream release - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.73 - -* Fri Feb 09 2024 Vojtech Polasek - 0.1.72-1 -- Update to latest upstream SCAP-Security-Guide-0.1.72 release: - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.72 - -* Sat Jan 27 2024 Fedora Release Engineering - 0.1.71-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Tue Dec 19 2023 Vojtech Polasek - 0.1.71-1 -- Update to latest upstream SCAP-Security-Guide-0.1.71 release: - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.71 - -* Thu Oct 12 2023 Matthew Burket - 0.1.70-1 -- Update to latest upstream SCAP-Security-Guide-0.1.70 release: - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.70 - -* Thu Aug 03 2023 Jan Černý - 0.1.69-1 -- Update to latest upstream SCAP-Security-Guide-0.1.69 release: - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.69 - -* Sat Jul 22 2023 Fedora Release Engineering - 0.1.68-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild - -* Thu Jun 15 2023 Jan Černý - 0.1.68-1 -- Update to latest upstream SCAP-Security-Guide-0.1.68 release: - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.68 - -* Wed Apr 12 2023 Matthew Burket - 0.1.67-1 -- Update to latest upstream SCAP-Security-Guide-0.1.67 release: - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.67 - - -* Fri Feb 03 2023 Vojtech Polasek - 0.1.66-1 -- Update to latest upstream SCAP-Security-Guide-0.1.66 release: - https://github.com/ComplianceAsCode/content/releases/tag/v0.1.66 - -* Sat Jan 21 2023 Fedora Release Engineering - 0.1.65-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild - * Tue Dec 06 2022 Marcus Burghardt - 0.1.65-1 - Update to latest upstream SCAP-Security-Guide-0.1.65 release: https://github.com/ComplianceAsCode/content/releases/tag/v0.1.65 @@ -186,12 +111,6 @@ rm %{buildroot}/%{_docdir}/%{name}/Contributors.md - Update to latest upstream SCAP-Security-Guide-0.1.63 release: https://github.com/ComplianceAsCode/content/releases/tag/v0.1.63 -* Sat Jul 23 2022 Fedora Release Engineering - 0.1.62-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild - -* Thu Jun 09 2022 Vojtech Polasek - 0.1.62-2 -- rebuild, the release did not get propagated into rawhide - * Mon May 30 2022 Vojtech Polasek - 0.1.62-1 - Update to latest upstream SCAP-Security-Guide-0.1.62 release: https://github.com/ComplianceAsCode/content/releases/tag/v0.1.62 @@ -204,9 +123,6 @@ rm %{buildroot}/%{_docdir}/%{name}/Contributors.md - Update to latest upstream SCAP-Security-Guide-0.1.60 release: https://github.com/ComplianceAsCode/content/releases/tag/v0.1.60 -* Sat Jan 22 2022 Fedora Release Engineering - 0.1.59-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild - * Wed Dec 01 2021 Watson Sato - 0.1.59-1 - Update to latest upstream SCAP-Security-Guide-0.1.59 release: https://github.com/ComplianceAsCode/content/releases/tag/v0.1.59 diff --git a/sources b/sources index f88b2e8..ece9ecf 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (scap-security-guide-0.1.79.tar.bz2) = 57963e896aef6089523bb7165ece32dafeedc2caf0baac594c4d0d083ff00bd37c4fdc1c98357db1c70523bb67543c07b6a41b7d989ba1a8e97907218d954311 +SHA512 (scap-security-guide-0.1.65.tar.bz2) = 8c0f7431da33d80878d37cecff6afd55cfc3cc4085e987a5b0d5cecc8969373afa24c409d25bbe6de5ce1b6a718ed0d8c685a029ec7fec0c0de7d66f5040ad16 diff --git a/tests/smoke-test/main.fmf b/tests/smoke-test/main.fmf deleted file mode 100644 index 6e01198..0000000 --- a/tests/smoke-test/main.fmf +++ /dev/null @@ -1,27 +0,0 @@ -summary: Test calls upstream test suite. -description: | - Runs upstream test suite against content built from the source RPM - testing - the content from the installed scap-security-guide is not feasible as the - upstream test suite is hardcoded to test the content from the CMAKE_BINARY_DIR - directory with hardcoded paths which are not the same as paths where content is - installed from the scap-security-guide RPM. Test suite is also built from the - scap-security-guide source RPM by running %prep and %build stages from the spec - file. -contact: Matus Marhefka -test: ./runtest.sh -framework: beakerlib -require: - - library(ControlFlow/Cleanup) - - library(rpm/snapshot) - - scap-security-guide -recommend: - - yum-utils - - rpm-build - - dnf-plugins-core - - gcc - - python3-pytest - - python3-pip - - python3-devel - - ansible -duration: 90m -enabled: true diff --git a/tests/smoke-test/runtest.sh b/tests/smoke-test/runtest.sh deleted file mode 100755 index b356a60..0000000 --- a/tests/smoke-test/runtest.sh +++ /dev/null @@ -1,80 +0,0 @@ -#!/bin/bash -# vim: dict=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# runtest.sh of /CoreOS/scap-security-guide/Sanity/smoke-test -# Description: Test calls upstream test suite. -# Author: Marek Haicman -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Copyright (c) 2018 Red Hat, Inc. All rights reserved. -# -# This copyrighted material is made available to anyone wishing -# to use, modify, copy, or redistribute it subject to the terms -# and conditions of the GNU General Public License version 2. -# -# This program is distributed in the hope that it will be -# useful, but WITHOUT ANY WARRANTY; without even the implied -# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR -# PURPOSE. See the GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public -# License along with this program; if not, write to the Free -# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, -# Boston, MA 02110-1301, USA. -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -. /usr/share/beakerlib/beakerlib.sh || exit 1 - -PACKAGE="scap-security-guide" - -rlJournalStart - - rlPhaseStartSetup - rlImport ControlFlow/Cleanup rpm/snapshot || rlDie "Failed to import libraries" - rlAssertRpm "$PACKAGE" - - RpmSnapshotCreate - CleanupRegister "RpmSnapshotRevert" - rlRun "TmpDir=\$(mktemp -d)" 0 - CleanupRegister "rlRun 'rm -r $TmpDir' 0 'Removing tmp directory'" - rlRun "pushd $TmpDir" - CleanupRegister "rlRun 'popd'" - - rlFetchSrcForInstalled $PACKAGE - rlRun "dnf builddep -y $PACKAGE*" - SITE_PACKAGES=$(python3 -c 'import sysconfig; print(sysconfig.get_paths()["purelib"])') - rlRun "pip3 install --target=$SITE_PACKAGES ruamel.yaml yamlpath prometheus-client" - CleanupRegister "rlRun 'pip3 uninstall -y ruamel.yaml yamlpath prometheus-client'" - TOPDIR=`rpm --eval %_topdir` - rlRun "rm -rf ${TOPDIR}/BUILD/${PACKAGE}*" 0-255 - rlRun "rpm -ihv `ls *.rpm`" 0 "Install $PACKAGE source RPM" - rlPhaseEnd - - rlPhaseStartSetup "Prepare upstream test suite (%prep and %build stages from the spec file)" - rlRun "rpmbuild -v -bc ${TOPDIR}/SPECS/${PACKAGE}.spec" - CleanupRegister "rlRun 'rm -rf ${TOPDIR}/BUILD/${PACKAGE}*'" - CleanupRegister "rlRun 'rm -rf ${TOPDIR}/SPECS/${PACKAGE}*'" - CleanupRegister "rlRun 'rm -rf ${TOPDIR}/SOURCES/*'" - rlPhaseEnd - - rlPhaseStartTest "Run upstream test suite" - BUILD_DIR_PATH="$(find $TOPDIR -name build | grep scap-security-guide)" - rlRun -s "cmake --build $BUILD_DIR_PATH --target test -- ARGS='--output-on-failure'" - rv=$? - - # if we got error, submit file with result of particular test for easier debugging - if [ $rv -ne 0 ]; then - FILE="${BUILD_DIR_PATH}/Testing/Temporary/LastTest.log" - rlBundleLogs test_outputs $(readlink -f $FILE) - fi - rlPhaseEnd - - rlPhaseStartCleanup - CleanupDo - rlPhaseEnd - -rlJournalPrintText -rlJournalEnd