content icon indicating copy to clipboard operation
content copied to clipboard

Add new rule file_permissions_sudo

Open Mab879 opened this issue 1 year ago • 11 comments

Description:

Add new rule file_permissions_sudo

Rationale:

To cover ANSSI R38

Mab879 avatar Feb 13 '24 16:02 Mab879

Start a new ephemeral environment with changes proposed in this pull request:

rhel8 (from CTF) Environment (using Fedora as testing environment) Open in Gitpod

Fedora Testing Environment Open in Gitpod

Oracle Linux 8 Environment Open in Gitpod

github-actions[bot] avatar Feb 13 '24 16:02 github-actions[bot]

/packit retest-failed

Mab879 avatar Feb 13 '24 18:02 Mab879

/packit retest-failed

jan-cerny avatar Feb 14 '24 09:02 jan-cerny

@Mab879 Testing farm fail is legit, it fail in the rule file_permissions_sudo in the ANSSI profile. The actual permissions are of /usr/bin/sudo are 4111.

jan-cerny avatar Feb 15 '24 08:02 jan-cerny

/packit retest-failed

Mab879 avatar Feb 15 '24 22:02 Mab879

@Mab879 Testing farm fail is legit, it fail in the rule file_permissions_sudo in the ANSSI profile. The actual permissions are of /usr/bin/sudo are 4111.

So I misread the permissions in ANSSI, they are looking for 4110, but that might not be possible.

Mab879 avatar Feb 15 '24 22:02 Mab879

Moving to 4111 as 4110 doesn't seem possible.

Mab879 avatar Feb 16 '24 13:02 Mab879

Code Climate has analyzed commit 257bf01f and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 58.3% (0.0% change).

View more on Code Climate.

qlty-cloud-legacy[bot] avatar Feb 16 '24 13:02 qlty-cloud-legacy[bot]

/packit retest-failed

jan-cerny avatar Feb 19 '24 08:02 jan-cerny

/packit retest-failed

jan-cerny avatar Feb 19 '24 08:02 jan-cerny

/packit retest-failed

jan-cerny avatar Feb 19 '24 13:02 jan-cerny

/packit retest- failed

jan-cerny avatar Feb 20 '24 07:02 jan-cerny

/packit retest-failed

jan-cerny avatar Feb 20 '24 14:02 jan-cerny

/packit retest-failed

jan-cerny avatar Feb 21 '24 10:02 jan-cerny

/packit retest-failed

jan-cerny avatar Feb 22 '24 07:02 jan-cerny

/packit retest-failed

jan-cerny avatar Feb 22 '24 08:02 jan-cerny

/packit retest-failed

jan-cerny avatar Feb 22 '24 10:02 jan-cerny

/packit retest-failed

jan-cerny avatar Feb 22 '24 10:02 jan-cerny