From 65e351b0808770d6c7487f128d53777a866469b2 Mon Sep 17 00:00:00 2001 From: Eduardo Barretto Date: Mon, 11 Mar 2024 13:35:59 +0100 Subject: [PATCH] all_apparmor_profiles_in_enforce_complain_mode: Fix OVAL logic Current OVAL fails with unknown result because the variables are looking for a subexpression of the subject when there's none. Also remove check for unconfined as it is not needed --- .../oval/shared.xml | 15 ++------------- 1 file changed, 2 insertions(+), 13 deletions(-) diff --git a/linux_os/guide/system/apparmor/all_apparmor_profiles_in_enforce_complain_mode/oval/shared.xml b/linux_os/guide/system/apparmor/all_apparmor_profiles_in_enforce_complain_mode/oval/shared.xml index 9347535cf47e..c18fca49b1fc 100644 --- a/linux_os/guide/system/apparmor/all_apparmor_profiles_in_enforce_complain_mode/oval/shared.xml +++ b/linux_os/guide/system/apparmor/all_apparmor_profiles_in_enforce_complain_mode/oval/shared.xml @@ -13,18 +13,12 @@ /sys/kernel/security/apparmor/profiles - ^.*\(enforce\)$ + ^.*(\(enforce)\))$ 1 /sys/kernel/security/apparmor/profiles - ^.*\(complain\)$ - 1 - - - /sys/kernel/security/apparmor/profiles - ^\.*processes are unconfined.*$ + ^.*(\(complain\))$ 1 - - - {{{ rule_id }}}_var_num_apparmor_profiles