From fbf5c1cf2bbc1fa5cdbdf54ee4b1ed7815bf1e35 Mon Sep 17 00:00:00 2001 From: Gabriel Becker Date: Tue, 25 Aug 2026 18:20:51 +0200 Subject: [PATCH 1/5] Enable CUI profile testing on RHEL-10 ComplianceAsCode/content now derives the cui (NIST 800-171) profile from the nist_800_171 control file for RHEL 8, 9, and 10 alike, so RHEL-10 has a cui profile too. Remove the "there is no CUI profile on RHEL-10+" adjust blocks that disabled cui testing there, so it runs uniformly across RHEL 8, 9, and 10. --- hardening/anaconda/main.fmf | 4 ---- hardening/anaconda/with-gui.fmf | 3 --- hardening/ansible/main.fmf | 4 ---- hardening/ansible/uefi.fmf | 4 ---- hardening/ansible/with-gui.fmf | 3 --- hardening/container/anaconda-ostree/main.fmf | 4 ---- hardening/container/bootc-image-builder/main.fmf | 4 ---- hardening/container/old-new/main.fmf | 4 ---- hardening/host-os/ansible/main.fmf | 3 --- hardening/host-os/oscap/main.fmf | 3 --- hardening/image-builder/main.fmf | 4 ---- hardening/image-builder/uefi.fmf | 4 ---- hardening/kickstart/main.fmf | 4 ---- hardening/kickstart/uefi.fmf | 4 ---- hardening/kickstart/with-gui.fmf | 3 --- hardening/oscap/main.fmf | 4 ---- hardening/oscap/old-new/main.fmf | 4 ---- hardening/oscap/uefi.fmf | 4 ---- hardening/oscap/with-gui.fmf | 3 --- scanning/boot-errors/main.fmf | 4 ---- scanning/host-os/ansible-check/check-mode/main.fmf | 3 --- 21 files changed, 77 deletions(-) diff --git a/hardening/anaconda/main.fmf b/hardening/anaconda/main.fmf index 5cf5858a..8c366165 100644 --- a/hardening/anaconda/main.fmf +++ b/hardening/anaconda/main.fmf @@ -62,10 +62,6 @@ adjust+: /cui: tag+: - fips - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/anaconda/with-gui.fmf b/hardening/anaconda/with-gui.fmf index e269035e..d1207a92 100644 --- a/hardening/anaconda/with-gui.fmf +++ b/hardening/anaconda/with-gui.fmf @@ -53,9 +53,6 @@ tag+: because: > not supported on RHEL-8 according to RHEL documentation, the "Profiles not compatible with Server with GUI" table - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/ansible/main.fmf b/hardening/ansible/main.fmf index 98d4f2bb..35aa7c76 100644 --- a/hardening/ansible/main.fmf +++ b/hardening/ansible/main.fmf @@ -66,10 +66,6 @@ adjust+: /cui: tag+: - fips - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/ansible/uefi.fmf b/hardening/ansible/uefi.fmf index 5465a6a0..b3169268 100644 --- a/hardening/ansible/uefi.fmf +++ b/hardening/ansible/uefi.fmf @@ -42,10 +42,6 @@ adjust+: /cui: tag+: - fips - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/ansible/with-gui.fmf b/hardening/ansible/with-gui.fmf index c0c0bd70..49babb12 100644 --- a/hardening/ansible/with-gui.fmf +++ b/hardening/ansible/with-gui.fmf @@ -53,9 +53,6 @@ tag+: because: > not supported on RHEL-8 according to RHEL documentation, the "Profiles not compatible with Server with GUI" table - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/container/anaconda-ostree/main.fmf b/hardening/container/anaconda-ostree/main.fmf index a0f9f115..609c5416 100644 --- a/hardening/container/anaconda-ostree/main.fmf +++ b/hardening/container/anaconda-ostree/main.fmf @@ -65,10 +65,6 @@ adjust+: /cui: tag+: - fips - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/container/bootc-image-builder/main.fmf b/hardening/container/bootc-image-builder/main.fmf index 57545d20..19f0ad1e 100644 --- a/hardening/container/bootc-image-builder/main.fmf +++ b/hardening/container/bootc-image-builder/main.fmf @@ -63,10 +63,6 @@ adjust+: - subset-profile /cui: - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/container/old-new/main.fmf b/hardening/container/old-new/main.fmf index 656a8dfc..d81f6d8b 100644 --- a/hardening/container/old-new/main.fmf +++ b/hardening/container/old-new/main.fmf @@ -70,10 +70,6 @@ adjust+: - subset-profile /cui: - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/host-os/ansible/main.fmf b/hardening/host-os/ansible/main.fmf index d3ed1951..55cf2912 100644 --- a/hardening/host-os/ansible/main.fmf +++ b/hardening/host-os/ansible/main.fmf @@ -51,9 +51,6 @@ adjust+: /cui: adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ - when: distro == rhel-8 or distro == centos-stream-8 require+: [rng-tools] because: > diff --git a/hardening/host-os/oscap/main.fmf b/hardening/host-os/oscap/main.fmf index 7acbf5d8..251ad3c3 100644 --- a/hardening/host-os/oscap/main.fmf +++ b/hardening/host-os/oscap/main.fmf @@ -42,9 +42,6 @@ tag: /cui: adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ - when: distro == rhel-8 or distro == centos-stream-8 require+: [rng-tools] because: > diff --git a/hardening/image-builder/main.fmf b/hardening/image-builder/main.fmf index 5aeb80d9..9656e9cd 100644 --- a/hardening/image-builder/main.fmf +++ b/hardening/image-builder/main.fmf @@ -68,10 +68,6 @@ extra-priority: 1 - subset-profile /cui: - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/image-builder/uefi.fmf b/hardening/image-builder/uefi.fmf index c0e33145..263539f2 100644 --- a/hardening/image-builder/uefi.fmf +++ b/hardening/image-builder/uefi.fmf @@ -40,10 +40,6 @@ adjust+: - subset-profile /cui: - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/kickstart/main.fmf b/hardening/kickstart/main.fmf index 7c276926..10b1c14b 100644 --- a/hardening/kickstart/main.fmf +++ b/hardening/kickstart/main.fmf @@ -64,10 +64,6 @@ adjust+: /cui: tag+: - fips - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/kickstart/uefi.fmf b/hardening/kickstart/uefi.fmf index ec5dc28a..d77f3293 100644 --- a/hardening/kickstart/uefi.fmf +++ b/hardening/kickstart/uefi.fmf @@ -42,10 +42,6 @@ adjust+: /cui: tag+: - fips - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/kickstart/with-gui.fmf b/hardening/kickstart/with-gui.fmf index e269035e..d1207a92 100644 --- a/hardening/kickstart/with-gui.fmf +++ b/hardening/kickstart/with-gui.fmf @@ -53,9 +53,6 @@ tag+: because: > not supported on RHEL-8 according to RHEL documentation, the "Profiles not compatible with Server with GUI" table - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/oscap/main.fmf b/hardening/oscap/main.fmf index 777cf581..f7f4e616 100644 --- a/hardening/oscap/main.fmf +++ b/hardening/oscap/main.fmf @@ -61,10 +61,6 @@ adjust+: /cui: tag+: - fips - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/oscap/old-new/main.fmf b/hardening/oscap/old-new/main.fmf index c88a20bf..a7761ed7 100644 --- a/hardening/oscap/old-new/main.fmf +++ b/hardening/oscap/old-new/main.fmf @@ -45,10 +45,6 @@ environment+: /cui: tag+: - fips - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/oscap/uefi.fmf b/hardening/oscap/uefi.fmf index 5465a6a0..b3169268 100644 --- a/hardening/oscap/uefi.fmf +++ b/hardening/oscap/uefi.fmf @@ -42,10 +42,6 @@ adjust+: /cui: tag+: - fips - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/hardening/oscap/with-gui.fmf b/hardening/oscap/with-gui.fmf index 7d4bbae0..479c92d2 100644 --- a/hardening/oscap/with-gui.fmf +++ b/hardening/oscap/with-gui.fmf @@ -53,9 +53,6 @@ tag+: because: > not supported on RHEL-8 according to RHEL documentation, the "Profiles not compatible with Server with GUI" table - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/scanning/boot-errors/main.fmf b/scanning/boot-errors/main.fmf index 671677e7..4e596029 100644 --- a/scanning/boot-errors/main.fmf +++ b/scanning/boot-errors/main.fmf @@ -66,10 +66,6 @@ adjust+: /cui: tag+: - fips - adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ /e8: diff --git a/scanning/host-os/ansible-check/check-mode/main.fmf b/scanning/host-os/ansible-check/check-mode/main.fmf index b82eb6bb..cc01faed 100644 --- a/scanning/host-os/ansible-check/check-mode/main.fmf +++ b/scanning/host-os/ansible-check/check-mode/main.fmf @@ -52,9 +52,6 @@ adjust+: /cui: adjust+: - - when: distro >= rhel-10 or distro >= centos-stream-10 - enabled: false - because: there is no CUI profile on RHEL-10+ - when: distro == rhel-8 or distro == centos-stream-8 require+: [rng-tools] because: > From df3b5d436f6422cc5ca3fa42c2b864255c5919be Mon Sep 17 00:00:00 2001 From: Gabriel Becker Date: Wed, 26 Aug 2026 18:01:59 +0200 Subject: [PATCH 2/5] Handle CUI profile testing failures found during stabilization - Disable CUI with GUI for anaconda/kickstart install-time hardening, as the CUI profile removes GUI-incompatible packages (like OSPP), which aborts the non-interactive installation. - Waive image-builder CUI errors: osbuild-composer does not yet have the CUI profile in its allow list (unsupported profile xccdf_org.ssgproject.content_profile_cui). - Waive anaconda/cui socket_systemd-journal-remote_disabled, the same known anaconda limitation already waived for the cis profile. --- conf/waivers/productization | 8 ++++++++ hardening/anaconda/with-gui.fmf | 7 ++----- hardening/kickstart/with-gui.fmf | 7 ++----- 3 files changed, 12 insertions(+), 10 deletions(-) diff --git a/conf/waivers/productization b/conf/waivers/productization index 898f73c9..9fb5de18 100644 --- a/conf/waivers/productization +++ b/conf/waivers/productization @@ -48,6 +48,7 @@ /hardening/anaconda/with-gui/[^/]+/service_avahi-daemon_disabled /hardening/anaconda/with-gui/[^/]+/service_dnsmasq_disabled /hardening/anaconda(/with-gui)?/cis[^/]*/socket_systemd-journal-remote_disabled +/hardening/anaconda/cui/socket_systemd-journal-remote_disabled # https://github.com/ComplianceAsCode/content/issues/11498 /hardening/anaconda/with-gui/[^/]+/service_bluetooth_disabled # related to, but probably not caused by: @@ -101,6 +102,13 @@ /hardening/image-builder/uefi/ism_o_top_secret rhel == 10 and status == 'error' +# Image builder needs to add the CUI profile to its allow list; osbuild-composer +# rejects it with "unsupported profile xccdf_org.ssgproject.content_profile_cui" +# https://redhat.atlassian.net/browse/HMS-11244 +/hardening/image-builder/cui +/hardening/image-builder/uefi/cui + status == 'error' + # https://github.com/ComplianceAsCode/content/issues/15002 /hardening/host-os/ansible/.+/mount_option_tmp_noexec True diff --git a/hardening/anaconda/with-gui.fmf b/hardening/anaconda/with-gui.fmf index d1207a92..92ecdc32 100644 --- a/hardening/anaconda/with-gui.fmf +++ b/hardening/anaconda/with-gui.fmf @@ -48,11 +48,8 @@ tag+: tag+: - fips adjust+: - - when: distro == rhel-8 or distro == centos-stream-8 - enabled: false - because: > - not supported on RHEL-8 according to RHEL documentation, - the "Profiles not compatible with Server with GUI" table + - enabled: false + because: CUI profile is not supported with GUI /e8: diff --git a/hardening/kickstart/with-gui.fmf b/hardening/kickstart/with-gui.fmf index d1207a92..92ecdc32 100644 --- a/hardening/kickstart/with-gui.fmf +++ b/hardening/kickstart/with-gui.fmf @@ -48,11 +48,8 @@ tag+: tag+: - fips adjust+: - - when: distro == rhel-8 or distro == centos-stream-8 - enabled: false - because: > - not supported on RHEL-8 according to RHEL documentation, - the "Profiles not compatible with Server with GUI" table + - enabled: false + because: CUI profile is not supported with GUI /e8: From 955440a440fb318cc923aeb22d21672deccd0589 Mon Sep 17 00:00:00 2001 From: Gabriel Becker Date: Mon, 31 Aug 2026 19:26:57 +0200 Subject: [PATCH 3/5] Disable CUI with GUI for oscap and ansible hardening Mirror the CIS handling: the plain cis profile is disabled with GUI in all with-gui plans, and CUI (which is essentially CIS Level 2 Server and now also removes X Windows packages) is likewise incompatible with a GUI install. Disable /cui unconditionally in oscap/with-gui and ansible/with-gui, matching the anaconda and kickstart with-gui plans. --- hardening/ansible/with-gui.fmf | 7 ++----- hardening/oscap/with-gui.fmf | 7 ++----- 2 files changed, 4 insertions(+), 10 deletions(-) diff --git a/hardening/ansible/with-gui.fmf b/hardening/ansible/with-gui.fmf index 49babb12..49452219 100644 --- a/hardening/ansible/with-gui.fmf +++ b/hardening/ansible/with-gui.fmf @@ -48,11 +48,8 @@ tag+: tag+: - fips adjust+: - - when: distro == rhel-8 or distro == centos-stream-8 - enabled: false - because: > - not supported on RHEL-8 according to RHEL documentation, - the "Profiles not compatible with Server with GUI" table + - enabled: false + because: CUI profile is not supported with GUI /e8: diff --git a/hardening/oscap/with-gui.fmf b/hardening/oscap/with-gui.fmf index 479c92d2..4b575f0d 100644 --- a/hardening/oscap/with-gui.fmf +++ b/hardening/oscap/with-gui.fmf @@ -48,11 +48,8 @@ tag+: tag+: - fips adjust+: - - when: distro == rhel-8 or distro == centos-stream-8 - enabled: false - because: > - not supported on RHEL-8 according to RHEL documentation, - the "Profiles not compatible with Server with GUI" table + - enabled: false + because: CUI profile is not supported with GUI /e8: From ecdfb68cf9a1f9f597d96ca827caaaffd6f1adfd Mon Sep 17 00:00:00 2001 From: Gabriel Becker Date: Wed, 2 Sep 2026 11:06:23 +0200 Subject: [PATCH 4/5] Remove the fips tag from the CUI profile The fips tag makes the guest get installed with the fips=1 kernel argument (see hardening/*/test.py). CUI's content was never made FIPS-aware: unlike ospp/stig (which explicitly select a fips_*-prefixed crypto-policy variable), cui reuses cis's configure_custom_crypto_policy_cis rule, which sets a non-FIPS 'DEFAULT:NO-SHA1:...' base policy regardless. Installing a cui guest with fips=1 while its own remediation then applies a non-FIPS crypto policy leaves the system in an inconsistent state (kernel/OpenSSL enforcing FIPS-validated crypto, userspace crypto-policy saying otherwise), which is the leading suspect for the intermittent 'scp: Connection closed' failures seen after remediation on RHEL 9 x86_64 hardening tests. cis, which is not fips-tagged, never hits this. Since cui was never designed to run under FIPS mode (its crypto-policy handling is identical to cis), stop installing it with fips=1, matching how cis itself is tested. --- hardening/anaconda/main.fmf | 2 -- hardening/anaconda/with-gui.fmf | 2 -- hardening/ansible/main.fmf | 2 -- hardening/ansible/uefi.fmf | 2 -- hardening/ansible/with-gui.fmf | 2 -- hardening/container/anaconda-ostree/main.fmf | 2 -- hardening/kickstart/main.fmf | 2 -- hardening/kickstart/uefi.fmf | 2 -- hardening/kickstart/with-gui.fmf | 2 -- hardening/oscap/main.fmf | 2 -- hardening/oscap/old-new/main.fmf | 2 -- hardening/oscap/uefi.fmf | 2 -- hardening/oscap/with-gui.fmf | 2 -- scanning/boot-errors/main.fmf | 2 -- 14 files changed, 28 deletions(-) diff --git a/hardening/anaconda/main.fmf b/hardening/anaconda/main.fmf index 8c366165..12e09dde 100644 --- a/hardening/anaconda/main.fmf +++ b/hardening/anaconda/main.fmf @@ -60,8 +60,6 @@ adjust+: - subset-profile /cui: - tag+: - - fips /e8: diff --git a/hardening/anaconda/with-gui.fmf b/hardening/anaconda/with-gui.fmf index 92ecdc32..7572e9aa 100644 --- a/hardening/anaconda/with-gui.fmf +++ b/hardening/anaconda/with-gui.fmf @@ -45,8 +45,6 @@ tag+: - subset-profile /cui: - tag+: - - fips adjust+: - enabled: false because: CUI profile is not supported with GUI diff --git a/hardening/ansible/main.fmf b/hardening/ansible/main.fmf index 35aa7c76..ecdbff4d 100644 --- a/hardening/ansible/main.fmf +++ b/hardening/ansible/main.fmf @@ -64,8 +64,6 @@ adjust+: - subset-profile /cui: - tag+: - - fips /e8: diff --git a/hardening/ansible/uefi.fmf b/hardening/ansible/uefi.fmf index b3169268..24cba9e0 100644 --- a/hardening/ansible/uefi.fmf +++ b/hardening/ansible/uefi.fmf @@ -40,8 +40,6 @@ adjust+: - subset-profile /cui: - tag+: - - fips /e8: diff --git a/hardening/ansible/with-gui.fmf b/hardening/ansible/with-gui.fmf index 49452219..92933435 100644 --- a/hardening/ansible/with-gui.fmf +++ b/hardening/ansible/with-gui.fmf @@ -45,8 +45,6 @@ tag+: - subset-profile /cui: - tag+: - - fips adjust+: - enabled: false because: CUI profile is not supported with GUI diff --git a/hardening/container/anaconda-ostree/main.fmf b/hardening/container/anaconda-ostree/main.fmf index 609c5416..380ac3e9 100644 --- a/hardening/container/anaconda-ostree/main.fmf +++ b/hardening/container/anaconda-ostree/main.fmf @@ -63,8 +63,6 @@ adjust+: - subset-profile /cui: - tag+: - - fips /e8: diff --git a/hardening/kickstart/main.fmf b/hardening/kickstart/main.fmf index 10b1c14b..1f1ce653 100644 --- a/hardening/kickstart/main.fmf +++ b/hardening/kickstart/main.fmf @@ -62,8 +62,6 @@ adjust+: - subset-profile /cui: - tag+: - - fips /e8: diff --git a/hardening/kickstart/uefi.fmf b/hardening/kickstart/uefi.fmf index d77f3293..06bed68a 100644 --- a/hardening/kickstart/uefi.fmf +++ b/hardening/kickstart/uefi.fmf @@ -40,8 +40,6 @@ adjust+: - subset-profile /cui: - tag+: - - fips /e8: diff --git a/hardening/kickstart/with-gui.fmf b/hardening/kickstart/with-gui.fmf index 92ecdc32..7572e9aa 100644 --- a/hardening/kickstart/with-gui.fmf +++ b/hardening/kickstart/with-gui.fmf @@ -45,8 +45,6 @@ tag+: - subset-profile /cui: - tag+: - - fips adjust+: - enabled: false because: CUI profile is not supported with GUI diff --git a/hardening/oscap/main.fmf b/hardening/oscap/main.fmf index f7f4e616..021c8c3e 100644 --- a/hardening/oscap/main.fmf +++ b/hardening/oscap/main.fmf @@ -59,8 +59,6 @@ adjust+: - subset-profile /cui: - tag+: - - fips /e8: diff --git a/hardening/oscap/old-new/main.fmf b/hardening/oscap/old-new/main.fmf index a7761ed7..e739b6bd 100644 --- a/hardening/oscap/old-new/main.fmf +++ b/hardening/oscap/old-new/main.fmf @@ -43,8 +43,6 @@ environment+: - subset-profile /cui: - tag+: - - fips /e8: diff --git a/hardening/oscap/uefi.fmf b/hardening/oscap/uefi.fmf index b3169268..24cba9e0 100644 --- a/hardening/oscap/uefi.fmf +++ b/hardening/oscap/uefi.fmf @@ -40,8 +40,6 @@ adjust+: - subset-profile /cui: - tag+: - - fips /e8: diff --git a/hardening/oscap/with-gui.fmf b/hardening/oscap/with-gui.fmf index 4b575f0d..4b4b8b5a 100644 --- a/hardening/oscap/with-gui.fmf +++ b/hardening/oscap/with-gui.fmf @@ -45,8 +45,6 @@ tag+: - subset-profile /cui: - tag+: - - fips adjust+: - enabled: false because: CUI profile is not supported with GUI diff --git a/scanning/boot-errors/main.fmf b/scanning/boot-errors/main.fmf index 4e596029..d9fee7be 100644 --- a/scanning/boot-errors/main.fmf +++ b/scanning/boot-errors/main.fmf @@ -64,8 +64,6 @@ adjust+: - subset-profile /cui: - tag+: - - fips /e8: From 116531e1454372efdfcecf70d929a08976fad046 Mon Sep 17 00:00:00 2001 From: Gabriel Becker Date: Mon, 7 Sep 2026 15:53:00 +0200 Subject: [PATCH 5/5] Waive aide_build_database and ensure_pam_wheel_group_empty on old-new CUI Both rules fail on /hardening/container/old-new/cui, the Image Mode Day-2 upgrade scenario, for reasons rooted in how bootc handles state across a "bootc switch": - aide_build_database: old CUI doesn't select this rule, so the AIDE db is never seeded into /var on the old image. /var is never re-provisioned by "bootc switch", so the db built into the new image never reaches the guest. Deterministic. - ensure_pam_wheel_group_empty: old CUI doesn't select this rule, so the empty-wheel fix baked into the new image's /etc/group can be dropped by ostree's /etc 3-way merge on switch if the live copy looks locally modified. Confirmed flaky. Moved into a new conf/waivers/test_specific file, dedicated to waivers rooted in test methodology rather than in content/product defects, with a header explaining the general old-new/bootc-switch mechanism. --- conf/waivers/test_specific | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) create mode 100644 conf/waivers/test_specific diff --git a/conf/waivers/test_specific b/conf/waivers/test_specific new file mode 100644 index 00000000..c999091d --- /dev/null +++ b/conf/waivers/test_specific @@ -0,0 +1,28 @@ +# Waivers rooted in how a specific Contest test is built, rather than in the +# scanned content or product itself. Grouped separately from conf/waivers/permanent +# so the "content/product defect" and "test methodology" waivers aren't mixed. + +# /hardening/container/old-new/* simulates an Image Mode Day-2 upgrade: an old +# image (hardened with the currently shipped content) is booted, then switched +# ("bootc switch") to a new image (hardened with the tested CaC content), and +# scanned post-switch. "bootc switch" does not re-run remediation and does not +# re-provision /var, and only 3-way-merges /etc against the live system - it +# does not simply replace guest state with the new image's state. So rules that +# the *old* content didn't select can fail post-switch even though the new +# image itself was hardened correctly, because whatever the new image's build +# produced under /var (or a locally-diverged /etc) never reaches the running +# guest. +# +# TODO: Remove these waivers when the "old" content contains the rules. +# --- +# aide_build_database: old CUI doesn't select this rule, so the AIDE db is never +# seeded into /var on the old image. /var is never re-provisioned by "bootc +# switch", so the db built into the new image never reaches the guest. Deterministic. +/hardening/container/old-new/cui/aide_build_database +# ensure_pam_wheel_group_empty: old CUI doesn't select this rule, so the empty-wheel +# fix baked into the new image's /etc/group can be dropped by ostree's /etc 3-way +# merge on "bootc switch" if the live copy looks locally modified. Confirmed flaky. +/hardening/container/old-new/cui/ensure_pam_wheel_group_empty + True + +# vim: syntax=python