Add UOS Server 25 product - #15149
slark-yuxj wants to merge 1 commit into
Conversation
Add a new product for UnionTech UOS Server 25 (uoss25, codename qianlai). - products/uosserver25: product.yml with CPE cpe:/o:uniontech:uos_server:25:ga:server, CMakeLists.txt, and a Standard System Security profile - shared/checks/oval: OS inventory check detecting the uos-release RPM (version 25) - controls/std_uosserver25.yml: standard security benchmark control file with 29 automated controls (files/permissions, SSH hardening, auditd, PAM, password policies, AIDE, account hygiene) - Register the product in CMakeLists.txt, build_product, and ssg/constants.py (product_directories, FULL_NAME_TO_PRODUCT_MAPPING, MULTI_PLATFORM_LIST, MULTI_PLATFORM_MAPPING, MAKEFILE_ID_TO_PRODUCT_MAP) - shared/applicability/package.yml: UOS uses the shadow package name like openEuler/Kylin (verified on the target system) - .github/workflows/gate_fedora.yml: build uosserver25 in CI Verified on a real UOS Server 25 system (uos-release-25-2510, x86_64, dnf): - ./build_product uosserver25 -d builds the data stream without errors - oscap xccdf eval --profile standard against the live system identifies the OS via the uos-release CPE check and evaluates 30 rules (19 pass, 10 real findings such as auditd disabled, sshd hardening defaults)
|
Hi @slark-yuxj. Thanks for your PR. I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
Hi maintainers, this PR adds UOS Server 25 as a new product, following the pattern of the openeuler2203 and kylinserver10 products. Could someone from the team please take a look and |
|
@marcusburghardt @ggbecker Could someone please |
Add a new product for UnionTech UOS Server 25 (uoss25, codename qianlai).
Description:
This PR adds UOS Server 25 as a new supported product so its data stream
(
ssg-uosserver25-ds.xml) is generated by upstream builds and UOS Server 25systems can be scanned with standard OSCAP tooling.
products/uosserver25: product.yml with CPEcpe:/o:uniontech:uos_server:25:ga:server,CMakeLists.txt, and a Standard System Security profile
shared/checks/oval: OS inventory check detecting the uos-release RPM (version 25)controls/std_uosserver25.yml: standard security benchmark control file with29 automated controls (files/permissions, SSH hardening, auditd, PAM,
password policies, AIDE, account hygiene)
CMakeLists.txt,build_product, andssg/constants.py(product_directories, FULL_NAME_TO_PRODUCT_MAPPING, MULTI_PLATFORM_LIST,
MULTI_PLATFORM_MAPPING, MAKEFILE_ID_TO_PRODUCT_MAP)
shared/applicability/package.yml: UOS uses theshadowpackage name likeopenEuler/Kylin (verified on the target system)
.github/workflows/gate_fedora.yml: build uosserver25 in CIRationale:
UnionTech UOS Server 25 (codename qianlai) is a domestically-developed
enterprise Linux distribution in active production use. Adding it to
ComplianceAsCode lets UOS customers scan and harden their systems with the
same upstream SCAP content used for other enterprise distributions,
following the precedent of openEuler 2203 and Kylin products.
Review Hints:
Verified on real UOS Server 25 systems (standard and Military variants,
uos-release-25-2510, x86_64, dnf, openscap 1.3.9):
./build_product uosserver25 -dbuilds the data stream without errorsoscap xccdf eval --profile standardidentifies the OS via theuos-release CPE check and evaluates 29-30 rules (19 pass, 10 real
findings such as auditd disabled, sshd hardening defaults)
Single self-contained commit; similar in scope to the kylinserver10 /
openeuler2203 product PRs. The
shadowpackage name inshared/applicability/package.ymlis the only change affecting sharedfiles.