Skip to content

Conversation

vojtapolasek
Copy link
Collaborator

Description:

  • check also for presence of /run/ostree-booted file
  • I made modifications to both OVAL files - one in shared/applicability/oval, another in shared/checks/oval, I am not sure when the shared/checks/oval/bootc.xml is used, but I think it is a good idea to keep them in sync

Rationale:

Review Hints:

Build content not including this PR:

  1. Run a RHEL VM, install rpm-ostree, bootc
  2. oscap xccdf eval --profile stig --rule xccdf_org.ssgproject.content_rule_enable_dracut_fips_module ssg-rhel9-ds.xml

This should result in "not applicable", although it should be applicable.

Build the content with this PR and repeat steps above.

The result will be probably "fail", but definitely not "not applicable".

@vojtapolasek vojtapolasek added this to the 0.1.79 milestone Oct 17, 2025
@vojtapolasek vojtapolasek added the CPE-AL CPE Applicability Language label Oct 17, 2025
@vojtapolasek vojtapolasek changed the title enhance OVAL check for applicability in bootc env WIP: enhance OVAL check for applicability in bootc env Oct 17, 2025
@openshift-ci openshift-ci bot added the do-not-merge/work-in-progress Used by openshift-ci bot. label Oct 17, 2025
@vojtapolasek vojtapolasek marked this pull request as draft October 17, 2025 13:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CPE-AL CPE Applicability Language do-not-merge/work-in-progress Used by openshift-ci bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bootc detection easily matches non-bootc systems

1 participant