Conversation
The OVAL read the syslog uid from /etc/passwd into a local_variable and compared every /var/log file's owner against it. On systems that use syslog-ng instead of rsyslog there is no 'syslog' user, so the variable had no value and any non-root-owned file made the whole check evaluate to 'error' instead of a real pass/fail. Split the criteria: when a dedicated syslog user exists, require owner root or syslog (unchanged); when it does not, require owner root only. The syslog uid variable is now only evaluated in the branch where it has a value. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015YN4ez6hrFpegisiLLo3zx
|
Hi @israel-villar. Thanks for your PR. I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with Tip We noticed you've done this a few times! Consider joining the org to skip this step and gain Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
This datastream diff is auto generated by the check Click here to see the full diffOVAL for rule 'xccdf_org.ssgproject.content_rule_file_ownerships_var_log' differs.
--- oval:ssg-file_ownerships_var_log:def:1
+++ oval:ssg-file_ownerships_var_log:def:1
@@ -1,2 +1,7 @@
+criteria OR
criteria AND
+criterion oval:ssg-file_ownerships_var_log_test_syslog_user_present:tst:1
criterion oval:ssg-test_file_ownership_var_log:tst:1
+criteria AND
+criterion oval:ssg-file_ownerships_var_log_test_syslog_user_absent:tst:1
+criterion oval:ssg-file_ownerships_var_log_test_file_ownership_var_log_root_only:tst:1
New data stream adds bash remediation for rule 'xccdf_org.ssgproject.content_rule_file_ownerships_var_log'. |
jan-cerny
left a comment
There was a problem hiding this comment.
Can you add a tests scenario covering the new no-syslog situation?
…iation, enable on Debian Add Automatus test scenarios covering the no-dedicated-syslog-user case (e.g. syslog-ng instead of rsyslog), addressing jan-cerny's review comment on PR ComplianceAsCode#15118. While testing, the new fail scenario exposed a real bug in the bash remediation: 'find ! -user syslog' fails outright (exit 1, no files processed) when the 'syslog' user does not exist, so remediation silently did nothing on such systems. Only add the '-user syslog' exclusion to the find command when that user actually exists. The bash remediation was also restricted to Ubuntu only, even though the OVAL check already applies to Debian. The remediation logic is generic (no Ubuntu-specific behavior), so extend it to multi_platform_debian too -- fitting, since the no-syslog-user (syslog-ng) case is more typical of Debian than Ubuntu. The two new test scenarios are scoped to both platforms; the pre-existing scenarios are left Ubuntu-only to keep this change focused. Verified via Automatus (Docker): - ubuntu2404: all 8 scenarios pass with bash remediation. - debian13: the 2 new scenarios pass with bash remediation; the other 6 are correctly skipped as not applicable (still Ubuntu-only). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ARJshBwZJW1AiYFotscgT
|
Added the test scenarios for the no-syslog-user case. Testing them also surfaced a bug in the bash remediation (it broke when there's no syslog user) and showed the remediation could apply to Debian too, so I fixed both. |
Description:
file_ownerships_var_loginto two branches:sysloguser exists → require ownerrootorsyslog(unchanged behaviour);sysloguser → require ownerrootonly.sysloguidlocal_variableis now only referenced in the branch where it is guaranteed to have a value. Definitionversionbumped to2.Rationale:
syslog-nginstead ofrsyslogthere is no dedicatedsysloguser, so thelocal_variablethat reads its uid from/etc/passwdhas no value.error. As a result, on such a system any non-root-owned file under/var/logmade the whole rule reporterrorinstead of a meaningfulpass/fail.Review Hints:
file_ownerships_var_log/oval/shared.xml../build_product debian13 rhel9 ubuntu2404 sle15 --datastream,ctestand OVAL schema validation pass.syslog-nghost: the rule changes fromerrorto a realfail/pass.