diff options
author | Andrew Geissler <geissonator@yahoo.com> | 2021-03-06 00:22:30 +0300 |
---|---|---|
committer | Brad Bishop <bradleyb@fuzziesquirrel.com> | 2021-03-15 14:02:06 +0300 |
commit | 8b1392834def7d17263b45bd1aab35759235fb3e (patch) | |
tree | 8c15f7cbef2b020a8f41839f56be0c02f57ac39c /meta-security/meta-security-compliance | |
parent | 3e34fba3f6b8389074f64203299fa60ec0fc18e1 (diff) | |
download | openbmc-8b1392834def7d17263b45bd1aab35759235fb3e.tar.xz |
meta-security: subtree update:6053e8b8e2..9504d02694
Armin Kuster (19):
softhsm: drop pkg as meta-oe has it
apparmor: Inherit python3targetconfig
python3-suricata-update: Inherit python3targetconfig
openscap: Inherit python3targetconfig
scap-security-guide: Inherit python3targetconfig
nikito: Update common-licenses references to match new names
kas-security-base.yml: build setting updates
kas-security-base.yml: drop DL_DIR
arpwatch: upgrade 3.0 -> 3.1
checksec: upgrade 2.1.0 -> 2.4.0
ding-libs: upgrade 0.5.0 -> 0.6.1
fscryptctl: upgrade 0.1.0 -> 1.0.0
libseccomp: upgrade 2.5.0 -> 2.5.1
python3-privacyidea: upgrade 3.3 -> 3.5.1
python3-scapy: upgrade 2.4.3 -> 2.4.4
samhain: update to 4.4.3
opendnssec: update to 2.1.8
suricata: update to 4.10.0
python3-fail2ban: update to 0.11.2
Jate Sujjavanich (1):
scap-security-guide: Fix openembedded platform tests and build
Ming Liu (9):
ima-evm-utils: set native REQUIRED_DISTRO_FEATURES to empty
initramfs-framework-ima: fix a wrong path
ima-evm-keys: add recipe
initramfs-framework-ima: RDEPENDS on ima-evm-keys
meta: refactor IMA/EVM sign rootfs
README.md: update according to the refactoring in ima-evm-rootfs.bbclass
initramfs-framework-ima: let ima_enabled return 0
ima-evm-rootfs.bbclass: avoid generating /etc/fstab for wic
ima-policy-hashed: add CGROUP2_SUPER_MAGIC fsmagic
Yi Zhao (1):
ibmswtpm2: disable camellia algorithm
Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
Change-Id: Ic7dc6f5425a1493ac0534e10ed682662d109e60c
Diffstat (limited to 'meta-security/meta-security-compliance')
5 files changed, 84 insertions, 2 deletions
diff --git a/meta-security/meta-security-compliance/recipes-openscap/openscap/openscap.inc b/meta-security/meta-security-compliance/recipes-openscap/openscap/openscap.inc index afa576a9b..812ea9f3a 100644 --- a/meta-security/meta-security-compliance/recipes-openscap/openscap/openscap.inc +++ b/meta-security/meta-security-compliance/recipes-openscap/openscap/openscap.inc @@ -11,7 +11,7 @@ DEPENDS_class-native = "pkgconfig-native swig-native curl-native libxml2-native S = "${WORKDIR}/git" -inherit cmake pkgconfig python3native perlnative +inherit cmake pkgconfig python3native python3targetconfig perlnative PACKAGECONFIG ?= "python3 rpm perl gcrypt ${@bb.utils.contains('DISTRO_FEATURES', 'selinux', 'selinux', '', d)}" PACKAGECONFIG[python3] = "-DENABLE_PYTHON3=ON, ,python3, python3" diff --git a/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/files/0001-Fix-platform-spec-file-check-tests-in-installed-OS-d.patch b/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/files/0001-Fix-platform-spec-file-check-tests-in-installed-OS-d.patch new file mode 100644 index 000000000..60664a371 --- /dev/null +++ b/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/files/0001-Fix-platform-spec-file-check-tests-in-installed-OS-d.patch @@ -0,0 +1,46 @@ +From 2beb4bc83a157b21edb1a3fef295cd4cced467df Mon Sep 17 00:00:00 2001 +From: Jate Sujjavanich <jatedev@gmail.com> +Date: Thu, 7 Jan 2021 18:10:01 -0500 +Subject: [PATCH 1/3] Fix platform spec, file check, tests in installed OS + detect for openembedded + +Change platform to multi in openembedded installed check matching others +and allowing compile of xml into oval +--- + shared/checks/oval/installed_OS_is_openembedded.xml | 11 ++++++----- + 1 file changed, 6 insertions(+), 5 deletions(-) + +diff --git a/shared/checks/oval/installed_OS_is_openembedded.xml b/shared/checks/oval/installed_OS_is_openembedded.xml +index 763d17bcb..01df16b43 100644 +--- a/shared/checks/oval/installed_OS_is_openembedded.xml ++++ b/shared/checks/oval/installed_OS_is_openembedded.xml +@@ -1,11 +1,9 @@ +-</def-group> +- + <def-group> + <definition class="inventory" id="installed_OS_is_openembedded" version="2"> + <metadata> + <title>OpenEmbedded</title> + <affected family="unix"> +- <platform>OPENEMBEDDED</platform> ++ <platform>multi_platform_all</platform> + </affected> + <reference ref_id="cpe:/o:openembedded:openembedded:0" + source="CPE" /> +@@ -20,8 +18,11 @@ + </criteria> + </definition> + +- <ind:textfilecontent54_object id="test_openembedded" version="1" comment="Check OPenEmbedded version"> +- <ind:filepath>/etc/os-release/ind:filepath> ++ <ind:textfilecontent54_test check="all" check_existence="at_least_one_exists" comment="Check OpenEmbedded version" id="test_openembedded" version="1"> ++ <ind:object object_ref="obj_openembedded" /> ++ </ind:textfilecontent54_test> ++ <ind:textfilecontent54_object id="obj_openembedded" version="1" comment="Check OpenEmbedded version"> ++ <ind:filepath>/etc/os-release</ind:filepath> + <ind:pattern operation="pattern match">^VERSION_ID=\"nodistro\.[0-9].$</ind:pattern> + <ind:instance datatype="int">1</ind:instance> + </ind:textfilecontent54_object> +-- +2.24.3 (Apple Git-128) + diff --git a/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/files/0002-Fix-missing-openembedded-from-ssg-constants.py.patch b/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/files/0002-Fix-missing-openembedded-from-ssg-constants.py.patch new file mode 100644 index 000000000..1e712f672 --- /dev/null +++ b/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/files/0002-Fix-missing-openembedded-from-ssg-constants.py.patch @@ -0,0 +1,34 @@ +From 037a12301968a56f0c7e492ea4a05d2eecbd4cc6 Mon Sep 17 00:00:00 2001 +From: Jate Sujjavanich <jatedev@gmail.com> +Date: Fri, 8 Jan 2021 20:18:00 -0500 +Subject: [PATCH 2/3] Fix missing openembedded from ssg/constants.py + +--- + ssg/constants.py | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +diff --git a/ssg/constants.py b/ssg/constants.py +index fab7cda5d..2ca289f84 100644 +--- a/ssg/constants.py ++++ b/ssg/constants.py +@@ -234,7 +234,8 @@ PRODUCT_TO_CPE_MAPPING = { + } + + MULTI_PLATFORM_LIST = ["rhel", "fedora", "rhosp", "rhv", "debian", "ubuntu", +- "wrlinux", "opensuse", "sle", "ol", "ocp", "example"] ++ "wrlinux", "opensuse", "sle", "ol", "ocp", "example", ++ "openembedded"] + + MULTI_PLATFORM_MAPPING = { + "multi_platform_debian": ["debian8"], +@@ -249,6 +250,7 @@ MULTI_PLATFORM_MAPPING = { + "multi_platform_sle": ["sle11", "sle12"], + "multi_platform_ubuntu": ["ubuntu1404", "ubuntu1604", "ubuntu1804"], + "multi_platform_wrlinux": ["wrlinux"], ++ "multi_platform_openembedded": ["openembedded"], + } + + RHEL_CENTOS_CPE_MAPPING = { +-- +2.24.3 (Apple Git-128) + diff --git a/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/scap-security-guide.inc b/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/scap-security-guide.inc index 32fce0fbb..d1a9511f3 100644 --- a/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/scap-security-guide.inc +++ b/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/scap-security-guide.inc @@ -10,7 +10,7 @@ DEPENDS = "openscap-native python3 python3-pyyaml-native python3-jinja2-native l S = "${WORKDIR}/git" -inherit cmake pkgconfig python3native +inherit cmake pkgconfig python3native python3targetconfig STAGING_OSCAP_BUILDDIR = "${TMPDIR}/work-shared/openscap/oscap-build-artifacts" export OSCAP_CPE_PATH="${STAGING_OSCAP_BUILDDIR}${datadir_native}/openscap/cpe" diff --git a/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/scap-security-guide_git.bb b/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/scap-security-guide_git.bb index 6e7180f55..0617c56e7 100644 --- a/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/scap-security-guide_git.bb +++ b/meta-security/meta-security-compliance/recipes-openscap/scap-security-guide/scap-security-guide_git.bb @@ -7,6 +7,8 @@ SRC_URI = "git://github.com/akuster/scap-security-guide.git;branch=oe-0.1.44; \ file://0001-fix-deprecated-instance-of-element.getchildren.patch \ file://0002-fix-deprecated-getiterator-function.patch \ file://0003-fix-remaining-getchildren-and-getiterator-functions.patch \ + file://0001-Fix-platform-spec-file-check-tests-in-installed-OS-d.patch \ + file://0002-Fix-missing-openembedded-from-ssg-constants.py.patch \ " PV = "0.1.44+git${SRCPV}" |