Skip to content

Fix chronyd_server_directive - #15105

Merged
jan-cerny merged 4 commits into
ComplianceAsCode:masterfrom
alanmcanonical:chronyd_server_directive_oval
Sep 18, 2026
Merged

jan-cerny merged 4 commits into
ComplianceAsCode:masterfrom
alanmcanonical:chronyd_server_directive_oval

Conversation

@alanmcanonical

Copy link
Copy Markdown
Contributor

Description:

  • Fix sed in chronyd_server_directive tests/
  • Add mixed pool and server entries test case for chronyd_server_directive
  • Fix oval regex

Rationale:

  • sed contains a syntax error
  • Only entries starting with \s*server is allowed

Signed-off-by: Alan Moore <alan.moore@canonical.com>
Signed-off-by: Alan Moore <alan.moore@canonical.com>
Signed-off-by: Alan Moore <alan.moore@canonical.com>
@openshift-ci openshift-ci Bot added the needs-ok-to-test Used by openshift-ci bot. label Sep 9, 2026
@openshift-ci

openshift-ci Bot commented Sep 9, 2026

Copy link
Copy Markdown

Hi @alanmcanonical. Thanks for your PR.

I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Tip

We noticed you've done this a few times! Consider joining the org to skip this step and gain /lgtm and other bot rights. We recommend asking approvers on your previous PRs to sponsor you.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@alanmcanonical

alanmcanonical commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor Author

test result before fix (added mixed.fail.sh):

libvirt: QEMU Driver error : argument unsupported: QEMU guest agent is not configured
INFO - xccdf_org.ssgproject.content_rule_chronyd_server_directive
INFO - Script file_empty.fail.sh using profile (all) OK
INFO - Script multiple_servers.pass.sh using profile (all) OK
INFO - Script line_missing.fail.sh using profile (all) OK
INFO - Script file_missing.fail.sh using profile (all) OK
INFO - Script only_pool.fail.sh using profile (all) OK
ERROR - Script mixed.fail.sh using profile (all) found issue:
ERROR - Rule evaluation resulted in pass, instead of expected fail during initial stage
ERROR - The initial scan failed for rule 'xccdf_org.ssgproject.content_rule_chronyd_server_directive'.
INFO - Script only_server.pass.sh using profile (all) OK

test result after fix:

python3 tests/automatus.py rule --libvirt qemu:///system sec-noble-amd64 --datastream build/ssg-ubuntu2404-ds.xml --remediate-using bash --profile chronyd_server_directive chronyd_server_directive --profile (all)
Setting console output to log level INFO

INFO - xccdf_org.ssgproject.content_rule_chronyd_server_directive
INFO - Script file_empty.fail.sh using profile (all) OK
INFO - Script multiple_servers.pass.sh using profile (all) OK
INFO - Script line_missing.fail.sh using profile (all) OK
INFO - Script file_missing.fail.sh using profile (all) OK
INFO - Script only_pool.fail.sh using profile (all) OK
INFO - Script mixed.fail.sh using profile (all) OK
WARNING - No remediation is available for rule 'xccdf_org.ssgproject.content_rule_chronyd_server_directive'.
INFO - Script only_server.pass.sh using profile (all) OK

Signed-off-by: Alan Moore <alan.moore@canonical.com>
@Mab879 Mab879 added this to the 0.1.83 milestone Sep 11, 2026

@jan-cerny jan-cerny left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

jcerny@fedora:~/work/git/scap-security-guide (pr/15105)$ python3 tests/automatus.py rule --remediate-using ansible --libvirt qemu:///system  ssgts_rhel10 chronyd_server_directive
Setting console output to log level INFO
INFO - The base image option has not been specified, choosing libvirt-based test environment.
INFO - Logging into /home/jcerny/work/git/scap-security-guide/logs/rule-custom-2026-09-18-1340/test_suite.log
INFO - xccdf_org.ssgproject.content_rule_chronyd_server_directive
INFO - Script file_empty.fail.sh using profile (all) OK
INFO - Script file_missing.fail.sh using profile (all) OK
INFO - Script line_missing.fail.sh using profile (all) OK
INFO - Script mixed.fail.sh using profile (all) OK
INFO - Script multiple_servers.pass.sh using profile (all) OK
INFO - Script only_pool.fail.sh using profile (all) OK
INFO - Script only_server.pass.sh using profile (all) OK
jcerny@fedora:~/work/git/scap-security-guide (pr/15105)$ python3 tests/automatus.py rule --remediate-using ansible --libvirt qemu:///system  ssgts_rhel10 --remediate-using ansible chronyd_server_directive
Setting console output to log level INFO
INFO - The base image option has not been specified, choosing libvirt-based test environment.
INFO - Logging into /home/jcerny/work/git/scap-security-guide/logs/rule-custom-2026-09-18-1345/test_suite.log
INFO - xccdf_org.ssgproject.content_rule_chronyd_server_directive
INFO - Script file_empty.fail.sh using profile (all) OK
INFO - Script file_missing.fail.sh using profile (all) OK
INFO - Script line_missing.fail.sh using profile (all) OK
INFO - Script mixed.fail.sh using profile (all) OK
INFO - Script multiple_servers.pass.sh using profile (all) OK
INFO - Script only_pool.fail.sh using profile (all) OK
INFO - Script only_server.pass.sh using profile (all) OK

@jan-cerny
jan-cerny merged commit c2989a1 into ComplianceAsCode:master Sep 18, 2026
60 of 62 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-ok-to-test Used by openshift-ci bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants