[meta-security-compliance][PATCH] scap-security-guide: Fix openembedded platform tests and build


Jate Sujjavanich
 

Add patches to fix openembedded nodistro tests and openembedded build wit=
hin
ssg metadata.

Signed-Off-By: Jate Sujjavanich <jatedev@gmail.com>
---
...c-file-check-tests-in-installed-OS-d.patch | 46 +++++++++++++++++++
...g-openembedded-from-ssg-constants.py.patch | 34 ++++++++++++++
.../scap-security-guide_git.bb | 2 +
3 files changed, 82 insertions(+)
create mode 100644 meta-security-compliance/recipes-openscap/scap-securi=
ty-guide/files/0001-Fix-platform-spec-file-check-tests-in-installed-OS-d.=
patch
create mode 100644 meta-security-compliance/recipes-openscap/scap-securi=
ty-guide/files/0002-Fix-missing-openembedded-from-ssg-constants.py.patch

diff --git a/meta-security-compliance/recipes-openscap/scap-security-guid=
e/files/0001-Fix-platform-spec-file-check-tests-in-installed-OS-d.patch b=
/meta-security-compliance/recipes-openscap/scap-security-guide/files/0001=
-Fix-platform-spec-file-check-tests-in-installed-OS-d.patch
new file mode 100644
index 0000000..60664a3
--- /dev/null
+++ b/meta-security-compliance/recipes-openscap/scap-security-guide/files=
/0001-Fix-platform-spec-file-check-tests-in-installed-OS-d.patch
@@ -0,0 +1,46 @@
+From 2beb4bc83a157b21edb1a3fef295cd4cced467df Mon Sep 17 00:00:00 2001
+From: Jate Sujjavanich <jatedev@gmail.com>
+Date: Thu, 7 Jan 2021 18:10:01 -0500
+Subject: [PATCH 1/3] Fix platform spec, file check, tests in installed O=
S
+ detect for openembedded
+
+Change platform to multi in openembedded installed check matching others
+and allowing compile of xml into oval
+---
+ shared/checks/oval/installed_OS_is_openembedded.xml | 11 ++++++-----
+ 1 file changed, 6 insertions(+), 5 deletions(-)
+
+diff --git a/shared/checks/oval/installed_OS_is_openembedded.xml b/share=
d/checks/oval/installed_OS_is_openembedded.xml
+index 763d17bcb..01df16b43 100644
+--- a/shared/checks/oval/installed_OS_is_openembedded.xml
++++ b/shared/checks/oval/installed_OS_is_openembedded.xml
+@@ -1,11 +1,9 @@
+-</def-group>
+-
+ <def-group>
+ <definition class=3D"inventory" id=3D"installed_OS_is_openembedded" v=
ersion=3D"2">
+ <metadata>
+ <title>OpenEmbedded</title>
+ <affected family=3D"unix">
+- <platform>OPENEMBEDDED</platform>
++ <platform>multi_platform_all</platform>
+ </affected>
+ <reference ref_id=3D"cpe:/o:openembedded:openembedded:0"
+ source=3D"CPE" />
+@@ -20,8 +18,11 @@
+ </criteria>
+ </definition>
+=20
+- <ind:textfilecontent54_object id=3D"test_openembedded" version=3D"1" =
comment=3D"Check OPenEmbedded version">
+- <ind:filepath>/etc/os-release/ind:filepath>
++ <ind:textfilecontent54_test check=3D"all" check_existence=3D"at_least=
_one_exists" comment=3D"Check OpenEmbedded version" id=3D"test_openembedd=
ed" version=3D"1">
++ <ind:object object_ref=3D"obj_openembedded" />
++ </ind:textfilecontent54_test>
++ <ind:textfilecontent54_object id=3D"obj_openembedded" version=3D"1" c=
omment=3D"Check OpenEmbedded version">
++ <ind:filepath>/etc/os-release</ind:filepath>
+ <ind:pattern operation=3D"pattern match">^VERSION_ID=3D\"nodistro\.=
[0-9].$</ind:pattern>
+ <ind:instance datatype=3D"int">1</ind:instance>
+ </ind:textfilecontent54_object>
+--=20
+2.24.3 (Apple Git-128)
+
diff --git a/meta-security-compliance/recipes-openscap/scap-security-guid=
e/files/0002-Fix-missing-openembedded-from-ssg-constants.py.patch b/meta-=
security-compliance/recipes-openscap/scap-security-guide/files/0002-Fix-m=
issing-openembedded-from-ssg-constants.py.patch
new file mode 100644
index 0000000..1e712f6
--- /dev/null
+++ b/meta-security-compliance/recipes-openscap/scap-security-guide/files=
/0002-Fix-missing-openembedded-from-ssg-constants.py.patch
@@ -0,0 +1,34 @@
+From 037a12301968a56f0c7e492ea4a05d2eecbd4cc6 Mon Sep 17 00:00:00 2001
+From: Jate Sujjavanich <jatedev@gmail.com>
+Date: Fri, 8 Jan 2021 20:18:00 -0500
+Subject: [PATCH 2/3] Fix missing openembedded from ssg/constants.py
+
+---
+ ssg/constants.py | 4 +++-
+ 1 file changed, 3 insertions(+), 1 deletion(-)
+
+diff --git a/ssg/constants.py b/ssg/constants.py
+index fab7cda5d..2ca289f84 100644
+--- a/ssg/constants.py
++++ b/ssg/constants.py
+@@ -234,7 +234,8 @@ PRODUCT_TO_CPE_MAPPING =3D {
+ }
+=20
+ MULTI_PLATFORM_LIST =3D ["rhel", "fedora", "rhosp", "rhv", "debian", "u=
buntu",
+- "wrlinux", "opensuse", "sle", "ol", "ocp", "exam=
ple"]
++ "wrlinux", "opensuse", "sle", "ol", "ocp", "exam=
ple",
++ "openembedded"]
+=20
+ MULTI_PLATFORM_MAPPING =3D {
+ "multi_platform_debian": ["debian8"],
+@@ -249,6 +250,7 @@ MULTI_PLATFORM_MAPPING =3D {
+ "multi_platform_sle": ["sle11", "sle12"],
+ "multi_platform_ubuntu": ["ubuntu1404", "ubuntu1604", "ubuntu1804"]=
,
+ "multi_platform_wrlinux": ["wrlinux"],
++ "multi_platform_openembedded": ["openembedded"],
+ }
+=20
+ RHEL_CENTOS_CPE_MAPPING =3D {
+--=20
+2.24.3 (Apple Git-128)
+
diff --git a/meta-security-compliance/recipes-openscap/scap-security-guid=
e/scap-security-guide_git.bb b/meta-security-compliance/recipes-openscap/=
scap-security-guide/scap-security-guide_git.bb
index 6e7180f..0617c56 100644
--- a/meta-security-compliance/recipes-openscap/scap-security-guide/scap-=
security-guide_git.bb
+++ b/meta-security-compliance/recipes-openscap/scap-security-guide/scap-=
security-guide_git.bb
@@ -7,6 +7,8 @@ SRC_URI =3D "git://github.com/akuster/scap-security-guide=
.git;branch=3Doe-0.1.44; \
file://0001-fix-deprecated-instance-of-element.getchildren.pa=
tch \
file://0002-fix-deprecated-getiterator-function.patch \
file://0003-fix-remaining-getchildren-and-getiterator-functio=
ns.patch \
+ file://0001-Fix-platform-spec-file-check-tests-in-installed-O=
S-d.patch \
+ file://0002-Fix-missing-openembedded-from-ssg-constants.py.pa=
tch \
"
PV =3D "0.1.44+git${SRCPV}"
=20
--=20
2.25.1

Join yocto@lists.yoctoproject.org to automatically receive all group messages.