Bug 1771438
| Summary: | Patches up-to-date rule has unusable output | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Marek Haicman <mhaicman> | ||||
| Component: | openscap | Assignee: | Jan Černý <jcerny> | ||||
| Status: | CLOSED ERRATA | QA Contact: | Vojtech Polasek <vpolasek> | ||||
| Severity: | medium | Docs Contact: | |||||
| Priority: | medium | ||||||
| Version: | 8.2 | CC: | amitkuma, ekolesni, mhaicman, mmarhefk, vpolasek | ||||
| Target Milestone: | rc | Flags: | pm-rhel:
mirror+
|
||||
| Target Release: | 8.2 | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | openscap-1.3.2-1.el8 | Doc Type: | If docs needed, set a value | ||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2020-04-28 15:40:54 UTC | Type: | Bug | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
Also reported in https://github.com/OpenSCAP/openscap/issues/1320 Hello, Test 1: profile ospp with fetch-remote-resources, nothing seen in o/p --------------------------------------------------------------------- # oscap --verbose DEVEL --verbose-log-file verbose_test1.log xccdf eval --fetch-remote-resources --profile xccdf_org.ssgproject.content_profile_ospp --rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date --results results_test1.xml --report ./report_test1.html /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml Downloading: https://www.redhat.com/security/data/oval/com.redhat.rhsa-RHEL8.xml ... ok # Test2: profile pci-dss with fetch-remote-resources. pass n number of times. ------------------------------------------------------------------------- # oscap --verbose DEVEL --verbose-log-file verbose_test2.log xccdf eval --fetch-remote-resources --profile xccdf_org.ssgproject.content_profile_pci-dss --rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date --results results_test2.xml --report ./report_test2.html /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml Downloading: https://www.redhat.com/security/data/oval/com.redhat.rhsa-RHEL8.xml ... ok Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass # Fixed upstream in https://github.com/OpenSCAP/openscap/pull/1426 Upstream test is located in tests/API/XCCDF/unittests/test_xccdf_check_multi_check2.sh Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:1629 |
Created attachment 1635296 [details] html report with too much granularity Description of problem: When running rule `security_patches_up_to_date` on 8.1 system, the output is quite useless. In the terminal, ``` Title Ensure Software Patches Installed Rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date Ident CCE-80865-9 Result pass ``` is repeated for every check in the CVE OVAL. In html report, the only details are through OVAL details which are in a form that is both unreadable and unsustainable (it will grow too big sooner or later) Version-Release number of selected component (if applicable): [root@ci-vm-10-0-138-146 ~]# rpm -qa openscap scap-security-guide scap-security-guide-0.1.46-3.el8.noarch openscap-1.3.1-2.el8.x86_64 How reproducible: reliably Steps to Reproduce: 1. oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_pci-dss --rule xccdf_org.ssgproject.content_rule_security_patches_up_to_date --results test.xml --fetch-remote-resources --report ./report.html /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml 2. 3. Actual results: As in description * repeated entries `Ensure Software Patches Installed` * html report attached Expected results: I want to know, out of the output, what package or what vulnerability is on the system. Additional info: