Fix conflict with file_permissions* rules fails in RHEL9 BSI SYS.1.3 #14342
+2
−0
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description:
package_cron_installedrule that installs thecronpackage before all cron-related checks are executedRationale:
all rules in the
cron_and_atgroup pass even when no cron files are found.after these checks,
aide_periodic_cron_checkingis executed, which installs thecronpackage.A subsequent check finds the cron files in their default state
file_groupowner_cron* andfile_owner_cron* rules are passing, because the default state of the cron files satisfies the rule requirementsfile_permissions_cron* rules fail, because default cron permissions are755(instead of the required700)Fixes file_permissions and rpm_verify_permissions rules conflict with each other (BSI profile) #13844
Review Hints:
/hardening/container/bootc-image-builder/bsiusing autocontest