Compare commits
68 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8df1e2a9ea | ||
|
|
1637063e41 |
||
|
|
bb5959df53 | ||
|
|
bd79f797ab |
||
|
|
cbff176307 |
||
|
|
af3b67787c | ||
|
|
02bb14b4e0 | ||
|
|
e311191a52 |
||
|
|
b80e2207d8 |
||
|
|
499e36d274 |
||
|
|
fbf76d834e | ||
|
|
afd5aedc48 | ||
|
|
d4ba75887d | ||
|
|
0e2a008939 | ||
|
|
ad8e38c1ce | ||
|
|
fa439a6850 | ||
|
|
571bdd076e |
||
|
|
3c3b3b80e5 | ||
|
|
a5cb95db65 | ||
|
|
073e61aac5 | ||
|
|
a8f8ac69c4 | ||
|
|
1ec1d5000d | ||
|
|
36de3a55f5 | ||
|
|
8a305566a3 | ||
|
|
e9550519bf | ||
|
|
ddb4a40b6d | ||
|
|
317dec4c14 | ||
|
|
5d3f57ca92 | ||
|
|
e588252f32 | ||
|
|
13c5eb8001 | ||
|
|
192107cf59 | ||
|
|
c64d08d2c6 | ||
|
|
9e43a57baa | ||
|
|
ae3860f028 | ||
|
|
2500d553b0 | ||
|
|
7448413b48 | ||
|
|
adbc78f7e5 | ||
|
|
538e9e4af3 | ||
|
|
cd4c51aa14 | ||
|
|
9321395849 | ||
|
|
500fdac831 | ||
|
|
2bc9c2e6db | ||
|
|
64a2d8e60f | ||
|
|
1a4066dba6 | ||
|
|
a4377deb59 | ||
|
|
2930a649dd | ||
|
|
facca30efe | ||
|
|
3293d4fc62 | ||
|
|
1176496c1b | ||
|
|
d1eedd270f | ||
|
|
e0b27dc7c8 | ||
|
|
f82a4f4237 | ||
|
|
1e1397c2f4 | ||
|
|
893d396f9f | ||
|
|
b873de19c0 | ||
|
|
87cd170875 | ||
|
|
439bd0b931 | ||
|
|
2f106e4f74 | ||
|
|
d8daa046b4 | ||
|
|
3210c5bbdd | ||
|
|
e4c3512666 | ||
|
|
20f142c3a5 | ||
|
|
4f696fcce8 | ||
|
|
53abd55a48 | ||
|
|
d119e01e6c | ||
|
|
b0f00522a6 |
||
|
|
41cc61516d | ||
|
|
ec69b1e129 |
10 changed files with 377 additions and 85 deletions
1
.fmf/version
Normal file
1
.fmf/version
Normal file
|
|
@ -0,0 +1 @@
|
|||
1
|
||||
38
.gitignore
vendored
38
.gitignore
vendored
|
|
@ -1,36 +1,2 @@
|
|||
/scap-security-guide-0.1-3.tar.gz
|
||||
/scap-security-guide-0.1.4.tar.gz
|
||||
/scap-security-guide-0.1-16.tar.gz
|
||||
/scap-security-guide-0.1.5.tar.gz
|
||||
/scap-security-guide-0.1.18.tar.gz
|
||||
/scap-security-guide-0.1.19.tar.gz
|
||||
/scap-security-guide-0.1.21.tar.gz
|
||||
/v0.1.22.tar.gz
|
||||
/v0.1.23.tar.gz
|
||||
/v0.1.24.tar.gz
|
||||
/v0.1.25.tar.gz
|
||||
/v0.1.26.tar.gz
|
||||
/v0.1.27.tar.gz
|
||||
/v0.1.28.tar.gz
|
||||
/scap-security-guide-0.1.29.tar.gz
|
||||
/0.1.29.tar.gz
|
||||
/v0.1.29.tar.gz
|
||||
/v0.1.30.tar.gz
|
||||
/scap-security-guide-0.1.31.tar.gz
|
||||
/scap-security-guide-0.1.32.tar.gz
|
||||
/scap-security-guide-0.1.33.tar.bz2
|
||||
/scap-security-guide-0.1.34.tar.bz2
|
||||
/scap-security-guide-0.1.35.tar.bz2
|
||||
/scap-security-guide-0.1.36.tar.bz2
|
||||
/scap-security-guide-0.1.37.tar.bz2
|
||||
/scap-security-guide-0.1.38.tar.bz2
|
||||
/scap-security-guide-0.1.39.tar.bz2
|
||||
/scap-security-guide-0.1.40.tar.bz2
|
||||
/scap-security-guide-0.1.41.tar.bz2
|
||||
/scap-security-guide-0.1.42.tar.bz2
|
||||
/scap-security-guide-0.1.43.tar.bz2
|
||||
/scap-security-guide-0.1.44.tar.bz2
|
||||
/scap-security-guide-0.1.45.tar.bz2
|
||||
/scap-security-guide-0.1.47.tar.bz2
|
||||
/scap-security-guide-0.1.48.tar.bz2
|
||||
/scap-security-guide-0.1.49.tar.bz2
|
||||
/scap-security-guide-0.1.78.tar.bz2
|
||||
/scap-security-guide-0.1.79.tar.bz2
|
||||
|
|
|
|||
1
ci.fmf
Normal file
1
ci.fmf
Normal file
|
|
@ -0,0 +1 @@
|
|||
resultsdb-testcase: separate
|
||||
20
gating.yaml
Normal file
20
gating.yaml
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
--- !Policy
|
||||
product_versions:
|
||||
- fedora-*
|
||||
decision_context: bodhi_update_push_testing
|
||||
subject_type: koji_build
|
||||
rules:
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/fedora_tests.functional}
|
||||
--- !Policy
|
||||
product_versions:
|
||||
- fedora-*
|
||||
decision_context: bodhi_update_push_stable
|
||||
subject_type: koji_build
|
||||
rules:
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/fedora_tests.functional}
|
||||
--- !Policy
|
||||
product_versions:
|
||||
- rhel-*
|
||||
decision_context: osci_compose_gate
|
||||
rules:
|
||||
- !PassingTestCaseRule {test_case_name: osci.brew-build./plans/ci/tier1.functional}
|
||||
5
plans/fedora_tests.fmf
Normal file
5
plans/fedora_tests.fmf
Normal file
|
|
@ -0,0 +1,5 @@
|
|||
summary: Run all tests in this repository
|
||||
discover:
|
||||
how: fmf
|
||||
execute:
|
||||
how: tmt
|
||||
|
|
@ -1,31 +0,0 @@
|
|||
From 174293162e5840684d967e36840fc1f9f57c90be Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Mat=C4=9Bj=20T=C3=BD=C4=8D?= <matyc@redhat.com>
|
||||
Date: Thu, 5 Dec 2019 15:02:05 +0100
|
||||
Subject: [PATCH] Fix XML "parsing" of the remediation functions file.
|
||||
|
||||
A proper fix is not worth the effort, as we aim to kill shared Bash remediation
|
||||
with Jinja2 macros.
|
||||
---
|
||||
ssg/build_remediations.py | 8 ++++----
|
||||
1 file changed, 4 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/ssg/build_remediations.py b/ssg/build_remediations.py
|
||||
index 7da807bd68..13e90f7327 100644
|
||||
--- a/ssg/build_remediations.py
|
||||
+++ b/ssg/build_remediations.py
|
||||
@@ -56,11 +56,11 @@ def get_available_functions(build_dir):
|
||||
remediation_functions = []
|
||||
with codecs.open(xmlfilepath, "r", encoding="utf-8") as xmlfile:
|
||||
filestring = xmlfile.read()
|
||||
- # This regex looks implementation dependent but we can rely on
|
||||
- # ElementTree sorting XML attrs alphabetically. Hidden is guaranteed
|
||||
- # to be the first attr and ID is guaranteed to be second.
|
||||
+ # This regex looks implementation dependent but we can rely on the element attributes
|
||||
+ # being present on one line.
|
||||
+ # We can't rely on ElementTree sorting XML attrs in any way since Python 3.7.
|
||||
remediation_functions = re.findall(
|
||||
- r'<Value hidden=\"true\" id=\"function_(\S+)\"',
|
||||
+ r'<Value[^>]*id=\"function_(\S+)\"',
|
||||
filestring, re.DOTALL
|
||||
)
|
||||
|
||||
|
|
@ -1,5 +1,10 @@
|
|||
# SSG build system and tests count with build directory name `build`.
|
||||
# For more details see:
|
||||
# https://fedoraproject.org/wiki/Changes/CMake_to_do_out-of-source_builds
|
||||
%global _vpath_builddir build
|
||||
|
||||
Name: scap-security-guide
|
||||
Version: 0.1.49
|
||||
Version: 0.1.79
|
||||
Release: 1%{?dist}
|
||||
Summary: Security guidance and baselines in SCAP formats
|
||||
License: BSD-3-Clause
|
||||
|
|
@ -7,10 +12,14 @@ URL: https://github.com/ComplianceAsCode/content/
|
|||
Source0: https://github.com/ComplianceAsCode/content/releases/download/v%{version}/scap-security-guide-%{version}.tar.bz2
|
||||
BuildArch: noarch
|
||||
|
||||
BuildRequires: libxslt, expat, python3, openscap-scanner >= 1.2.5, cmake >= 3.8, python3-jinja2, python3-PyYAML
|
||||
BuildRequires: libxslt
|
||||
BuildRequires: openscap-scanner >= 1.2.5
|
||||
BuildRequires: cmake >= 2.8
|
||||
BuildRequires: python%{python3_pkgversion}
|
||||
BuildRequires: python%{python3_pkgversion}-jinja2
|
||||
BuildRequires: python%{python3_pkgversion}-PyYAML
|
||||
BuildRequires: python%{python3_pkgversion}-setuptools
|
||||
Requires: xml-common, openscap-scanner >= 1.2.5
|
||||
Obsoletes: openscap-content < 0:0.9.13
|
||||
Provides: openscap-content
|
||||
|
||||
%description
|
||||
The scap-security-guide project provides a guide for configuration of the
|
||||
|
|
@ -18,7 +27,7 @@ system from the final system's security point of view. The guidance is specified
|
|||
in the Security Content Automation Protocol (SCAP) format and constitutes
|
||||
a catalog of practical hardening advice, linked to government requirements
|
||||
where applicable. The project bridges the gap between generalized policy
|
||||
requirements and specific implementation guidelines. The Fedora system
|
||||
requirements and specific implementation guidelines. The system
|
||||
administrator can use the oscap CLI tool from openscap-scanner package, or the
|
||||
scap-workbench GUI tool from scap-workbench package to verify that the system
|
||||
conforms to provided guideline. Refer to scap-security-guide(8) manual page for
|
||||
|
|
@ -33,34 +42,248 @@ The %{name}-doc package contains HTML formatted documents containing
|
|||
hardening guidances that have been generated from XCCDF benchmarks
|
||||
present in %{name} package.
|
||||
|
||||
%prep
|
||||
%setup -q
|
||||
mkdir build
|
||||
%if ( %{defined rhel} && (! %{defined centos}) && (! %{defined eln}) )
|
||||
%package rule-playbooks
|
||||
Summary: Ansible playbooks per each rule.
|
||||
Group: System Environment/Base
|
||||
Requires: %{name} = %{version}-%{release}
|
||||
|
||||
%description rule-playbooks
|
||||
The %{name}-rule-playbooks package contains individual ansible playbooks per rule.
|
||||
%endif
|
||||
|
||||
%prep
|
||||
%autosetup -p1
|
||||
|
||||
%define cmake_defines_common -DSSG_SEPARATE_SCAP_FILES_ENABLED=OFF -DSSG_BASH_SCRIPTS_ENABLED=OFF -DSSG_BUILD_SCAP_12_DS=OFF
|
||||
%define cmake_defines_specific %{nil}
|
||||
%if 0%{?rhel} && ! %{defined eln}
|
||||
%define cmake_defines_specific -DSSG_PRODUCT_DEFAULT:BOOLEAN=FALSE -DSSG_PRODUCT_RHEL%{rhel}:BOOLEAN=TRUE -DSSG_SCIENTIFIC_LINUX_DERIVATIVES_ENABLED:BOOL=OFF -DSSG_CENTOS_DERIVATIVES_ENABLED:BOOL=OFF -DSSG_ANSIBLE_PLAYBOOKS_PER_RULE_ENABLED:BOOL=ON
|
||||
%endif
|
||||
%if 0%{?centos}
|
||||
%define cmake_defines_specific -DSSG_PRODUCT_DEFAULT:BOOLEAN=FALSE -DSSG_PRODUCT_RHEL%{centos}:BOOLEAN=TRUE -DSSG_SCIENTIFIC_LINUX_DERIVATIVES_ENABLED:BOOL=OFF -DSSG_CENTOS_DERIVATIVES_ENABLED:BOOL=ON
|
||||
%endif
|
||||
|
||||
mkdir -p build
|
||||
%build
|
||||
cd build
|
||||
%cmake ../
|
||||
%make_build
|
||||
%cmake %{cmake_defines_common} %{cmake_defines_specific}
|
||||
%cmake_build
|
||||
|
||||
%install
|
||||
cd build
|
||||
%make_install
|
||||
%cmake_install
|
||||
rm %{buildroot}/%{_docdir}/%{name}/README.md
|
||||
rm %{buildroot}/%{_docdir}/%{name}/Contributors.md
|
||||
|
||||
%files
|
||||
%{_datadir}/xml/scap/ssg/content
|
||||
%{_datadir}/%{name}/kickstart
|
||||
%{_datadir}/%{name}/ansible
|
||||
%{_datadir}/%{name}/bash
|
||||
%{_datadir}/%{name}/ansible/*.yml
|
||||
%{_datadir}/%{name}/tailoring
|
||||
%lang(en) %{_mandir}/man8/scap-security-guide.8.*
|
||||
%doc %{_docdir}/%{name}/LICENSE
|
||||
%doc %{_docdir}/%{name}/README.md
|
||||
%doc %{_docdir}/%{name}/Contributors.md
|
||||
%if ( %{defined rhel} && (! %{defined centos}) && (! %{defined eln}) )
|
||||
%exclude %{_datadir}/%{name}/ansible/rule_playbooks
|
||||
%endif
|
||||
|
||||
%files doc
|
||||
%doc %{_docdir}/%{name}/guides/*.html
|
||||
%doc %{_docdir}/%{name}/tables/*.html
|
||||
|
||||
%if ( %{defined rhel} && (! %{defined centos}) && (! %{defined eln}) )
|
||||
%files rule-playbooks
|
||||
%defattr(-,root,root,-)
|
||||
%{_datadir}/%{name}/ansible/rule_playbooks
|
||||
%endif
|
||||
|
||||
%changelog
|
||||
* Fri Nov 28 2025 Jan Černý <jcerny@redhat.com> - 0.1.79-1
|
||||
- Upgrade to the latest upstream release
|
||||
|
||||
* Mon Sep 08 2025 Matthew Burket <mburket@redhat.com> - 0.1.78-1
|
||||
- Update to latest upstream release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.78
|
||||
|
||||
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.77-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
|
||||
|
||||
* Mon Jun 02 2025 Matthew Burket <mburket@redhat.com> - 0.1.77-1
|
||||
- Update to latest upstream release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.77
|
||||
|
||||
* Fri Mar 07 2025 Matthew Burket <mburket@redhat.com> - 0.1.76-2
|
||||
- Remove expat as a BuildRequires as it is no longer needed
|
||||
|
||||
* Tue Feb 25 2025 Evgenii Kolesnikov <ekolesni@redhat.com> - 0.1.76-1
|
||||
- Update to latest upstream release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.76
|
||||
|
||||
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.75-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
|
||||
|
||||
* Thu Nov 14 2024 Matthew Burket <mburket@redhat.com> - 0.1.75-1
|
||||
- Update to latest upstream release
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.75
|
||||
|
||||
* Mon Aug 12 2024 Matthew Burket <mburket@redhat.com> - 0.1.74-1
|
||||
- Update to latest upstream release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.74
|
||||
- Remove /usr/bin/python3 from BuildRequires
|
||||
|
||||
* Sat Jul 20 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.73-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
|
||||
|
||||
* Wed May 22 2024 Jan Černý <jcerny@redhat.com> - 0.1.73-1
|
||||
- Update to latest upstream release
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.73
|
||||
|
||||
* Fri Feb 09 2024 Vojtech Polasek <vpolasek@redhat.com> - 0.1.72-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.72 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.72
|
||||
|
||||
* Sat Jan 27 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.71-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
|
||||
|
||||
* Tue Dec 19 2023 Vojtech Polasek <vpolasek@redhat.com> - 0.1.71-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.71 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.71
|
||||
|
||||
* Thu Oct 12 2023 Matthew Burket <mburket@redhat.com> - 0.1.70-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.70 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.70
|
||||
|
||||
* Thu Aug 03 2023 Jan Černý <jcerny@redhat.com> - 0.1.69-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.69 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.69
|
||||
|
||||
* Sat Jul 22 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.68-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
|
||||
|
||||
* Thu Jun 15 2023 Jan Černý <jcerny@redhat.com> - 0.1.68-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.68 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.68
|
||||
|
||||
* Wed Apr 12 2023 Matthew Burket <mburket@redhat.com> - 0.1.67-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.67 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.67
|
||||
|
||||
|
||||
* Fri Feb 03 2023 Vojtech Polasek <vpolasek@redhat.com> - 0.1.66-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.66 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.66
|
||||
|
||||
* Sat Jan 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.65-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
|
||||
|
||||
* Tue Dec 06 2022 Marcus Burghardt <maburgha@redhat.com> - 0.1.65-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.65 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.65
|
||||
|
||||
* Tue Oct 04 2022 Watson Sato <wsato@redhat.com> - 0.1.64-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.64 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.64
|
||||
|
||||
* Mon Aug 01 2022 Watson Sato <wsato@redhat.com> - 0.1.63-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.63 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.63
|
||||
|
||||
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.62-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
|
||||
|
||||
* Thu Jun 09 2022 Vojtech Polasek <vpolasek@redhat.com> - 0.1.62-2
|
||||
- rebuild, the release did not get propagated into rawhide
|
||||
|
||||
* Mon May 30 2022 Vojtech Polasek <vpolasek@redhat.com> - 0.1.62-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.62 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.62
|
||||
|
||||
* Wed May 04 2022 Watson Sato <wsato@redhat.com> - 0.1.61-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.61 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.61
|
||||
|
||||
* Fri Jan 28 2022 Watson Sato <wsato@redhat.com> - 0.1.60-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.60 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.60
|
||||
|
||||
* Sat Jan 22 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.59-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
|
||||
|
||||
* Wed Dec 01 2021 Watson Sato <wsato@redhat.com> - 0.1.59-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.59 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.59
|
||||
- Fix loading of jinja files
|
||||
|
||||
* Thu Sep 30 2021 Watson Sato <wsato@redhat.com> - 0.1.58-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.58 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.58
|
||||
- Fix license warning.
|
||||
|
||||
* Thu Jul 29 2021 Matej Tyc <matyc@redhat.com> - 0.1.57-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.57 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.57
|
||||
|
||||
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.56-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
|
||||
|
||||
* Tue Jun 08 2021 Matej Tyc <matyc@redhat.com> - 0.1.56-2
|
||||
- Updated the packaging according to the RHEL development trends.
|
||||
- Don't ship 1.2 datastreams and Bash remediations.
|
||||
- Clean up dependencies and other package metadata.
|
||||
- Change the RHEL target.
|
||||
|
||||
* Wed May 26 2021 Vojtech Polasek <vpolasek@redhat.com> - 0.1.56-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.56 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.56
|
||||
|
||||
* Fri Mar 19 2021 Vojtech Polasek <vpolasek@redhat.com> - 0.1.55-2
|
||||
- rebuilt
|
||||
|
||||
* Fri Mar 19 2021 Vojtech Polasek <vpolasek@redhat.com> - 0.1.55-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.55 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.55
|
||||
|
||||
* Fri Feb 12 2021 Matej Tyc <matyc@redhat.com> - 0.1.54-3
|
||||
- Moved the spec file closer to the RHEL one.
|
||||
|
||||
* Fri Feb 12 2021 Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-2
|
||||
- fix definition of build directory
|
||||
|
||||
* Fri Feb 05 2021 Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.54 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.54
|
||||
|
||||
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.53-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
|
||||
|
||||
* Mon Nov 16 2020 Vojtech Polasek <vpolasek@redhat.com> - 0.1.53-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.53 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.53
|
||||
|
||||
* Wed Sep 23 2020 Vojtech Polasek <vpolasek@redhat.com> - 0.1.52-3
|
||||
- revert previous rework, it did not solve the problem
|
||||
|
||||
* Wed Sep 23 2020 Vojtech Polasek <vpolasek@redhat.com> - 0.1.52-2
|
||||
- rewrite solution for CMake out of source builds
|
||||
|
||||
* Mon Sep 21 2020 Vojtech Polasek <vpolasek@redhat.com> - 0.1.52-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.52 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.52
|
||||
|
||||
* Tue Aug 04 2020 Jan Černý <jcerny@redhat.com> - 0.1.51-4
|
||||
- Update for new CMake out of source builds
|
||||
https://fedoraproject.org/wiki/Changes/CMake_to_do_out-of-source_builds
|
||||
- Fix FTBS in Rawhide/F33 (RHBZ#1863741)
|
||||
|
||||
* Sat Aug 01 2020 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.51-3
|
||||
- Second attempt - Rebuilt for
|
||||
https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
|
||||
|
||||
* Wed Jul 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 0.1.51-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
|
||||
|
||||
* Fri Jul 17 2020 Vojtech Polasek <vpolasek@redhat.com> - 0.1.51-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.51 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.51
|
||||
|
||||
* Mon Mar 23 2020 Watson Sato <wsato@redhat.com> - 0.1.49-1
|
||||
- Update to latest upstream SCAP-Security-Guide-0.1.49 release:
|
||||
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.49
|
||||
|
|
|
|||
2
sources
2
sources
|
|
@ -1 +1 @@
|
|||
SHA512 (scap-security-guide-0.1.49.tar.bz2) = 888f3a3a190e69448058fe3beda5c28ecb99704cc7b5bbea3b48d16ed4414960495059854bef685472996763ff81c10fbf8258ff82d2f235b3aeac2ebb051b4b
|
||||
SHA512 (scap-security-guide-0.1.79.tar.bz2) = 57963e896aef6089523bb7165ece32dafeedc2caf0baac594c4d0d083ff00bd37c4fdc1c98357db1c70523bb67543c07b6a41b7d989ba1a8e97907218d954311
|
||||
|
|
|
|||
27
tests/smoke-test/main.fmf
Normal file
27
tests/smoke-test/main.fmf
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
summary: Test calls upstream test suite.
|
||||
description: |
|
||||
Runs upstream test suite against content built from the source RPM - testing
|
||||
the content from the installed scap-security-guide is not feasible as the
|
||||
upstream test suite is hardcoded to test the content from the CMAKE_BINARY_DIR
|
||||
directory with hardcoded paths which are not the same as paths where content is
|
||||
installed from the scap-security-guide RPM. Test suite is also built from the
|
||||
scap-security-guide source RPM by running %prep and %build stages from the spec
|
||||
file.
|
||||
contact: Matus Marhefka <mmarhefk@redhat.com>
|
||||
test: ./runtest.sh
|
||||
framework: beakerlib
|
||||
require:
|
||||
- library(ControlFlow/Cleanup)
|
||||
- library(rpm/snapshot)
|
||||
- scap-security-guide
|
||||
recommend:
|
||||
- yum-utils
|
||||
- rpm-build
|
||||
- dnf-plugins-core
|
||||
- gcc
|
||||
- python3-pytest
|
||||
- python3-pip
|
||||
- python3-devel
|
||||
- ansible
|
||||
duration: 90m
|
||||
enabled: true
|
||||
80
tests/smoke-test/runtest.sh
Executable file
80
tests/smoke-test/runtest.sh
Executable file
|
|
@ -0,0 +1,80 @@
|
|||
#!/bin/bash
|
||||
# vim: dict=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# runtest.sh of /CoreOS/scap-security-guide/Sanity/smoke-test
|
||||
# Description: Test calls upstream test suite.
|
||||
# Author: Marek Haicman <mhaicman@redhat.com>
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# Copyright (c) 2018 Red Hat, Inc. All rights reserved.
|
||||
#
|
||||
# This copyrighted material is made available to anyone wishing
|
||||
# to use, modify, copy, or redistribute it subject to the terms
|
||||
# and conditions of the GNU General Public License version 2.
|
||||
#
|
||||
# This program is distributed in the hope that it will be
|
||||
# useful, but WITHOUT ANY WARRANTY; without even the implied
|
||||
# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
|
||||
# PURPOSE. See the GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public
|
||||
# License along with this program; if not, write to the Free
|
||||
# Software Foundation, Inc., 51 Franklin Street, Fifth Floor,
|
||||
# Boston, MA 02110-1301, USA.
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
. /usr/share/beakerlib/beakerlib.sh || exit 1
|
||||
|
||||
PACKAGE="scap-security-guide"
|
||||
|
||||
rlJournalStart
|
||||
|
||||
rlPhaseStartSetup
|
||||
rlImport ControlFlow/Cleanup rpm/snapshot || rlDie "Failed to import libraries"
|
||||
rlAssertRpm "$PACKAGE"
|
||||
|
||||
RpmSnapshotCreate
|
||||
CleanupRegister "RpmSnapshotRevert"
|
||||
rlRun "TmpDir=\$(mktemp -d)" 0
|
||||
CleanupRegister "rlRun 'rm -r $TmpDir' 0 'Removing tmp directory'"
|
||||
rlRun "pushd $TmpDir"
|
||||
CleanupRegister "rlRun 'popd'"
|
||||
|
||||
rlFetchSrcForInstalled $PACKAGE
|
||||
rlRun "dnf builddep -y $PACKAGE*"
|
||||
SITE_PACKAGES=$(python3 -c 'import sysconfig; print(sysconfig.get_paths()["purelib"])')
|
||||
rlRun "pip3 install --target=$SITE_PACKAGES ruamel.yaml yamlpath prometheus-client"
|
||||
CleanupRegister "rlRun 'pip3 uninstall -y ruamel.yaml yamlpath prometheus-client'"
|
||||
TOPDIR=`rpm --eval %_topdir`
|
||||
rlRun "rm -rf ${TOPDIR}/BUILD/${PACKAGE}*" 0-255
|
||||
rlRun "rpm -ihv `ls *.rpm`" 0 "Install $PACKAGE source RPM"
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartSetup "Prepare upstream test suite (%prep and %build stages from the spec file)"
|
||||
rlRun "rpmbuild -v -bc ${TOPDIR}/SPECS/${PACKAGE}.spec"
|
||||
CleanupRegister "rlRun 'rm -rf ${TOPDIR}/BUILD/${PACKAGE}*'"
|
||||
CleanupRegister "rlRun 'rm -rf ${TOPDIR}/SPECS/${PACKAGE}*'"
|
||||
CleanupRegister "rlRun 'rm -rf ${TOPDIR}/SOURCES/*'"
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartTest "Run upstream test suite"
|
||||
BUILD_DIR_PATH="$(find $TOPDIR -name build | grep scap-security-guide)"
|
||||
rlRun -s "cmake --build $BUILD_DIR_PATH --target test -- ARGS='--output-on-failure'"
|
||||
rv=$?
|
||||
|
||||
# if we got error, submit file with result of particular test for easier debugging
|
||||
if [ $rv -ne 0 ]; then
|
||||
FILE="${BUILD_DIR_PATH}/Testing/Temporary/LastTest.log"
|
||||
rlBundleLogs test_outputs $(readlink -f $FILE)
|
||||
fi
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartCleanup
|
||||
CleanupDo
|
||||
rlPhaseEnd
|
||||
|
||||
rlJournalPrintText
|
||||
rlJournalEnd
|
||||
Loading…
Add table
Add a link
Reference in a new issue