Skip to content

Add UOS Server 25 product - #15149

Open
slark-yuxj wants to merge 1 commit into
ComplianceAsCode:masterfrom
slark-yuxj:add-uos-server-v25
Open

slark-yuxj wants to merge 1 commit into
ComplianceAsCode:masterfrom
slark-yuxj:add-uos-server-v25

Conversation

@slark-yuxj

Copy link
Copy Markdown

Add a new product for UnionTech UOS Server 25 (uoss25, codename qianlai).

Description:

This PR adds UOS Server 25 as a new supported product so its data stream
(ssg-uosserver25-ds.xml) is generated by upstream builds and UOS Server 25
systems can be scanned with standard OSCAP tooling.

  • products/uosserver25: product.yml with CPE cpe:/o:uniontech:uos_server:25:ga:server,
    CMakeLists.txt, and a Standard System Security profile
  • shared/checks/oval: OS inventory check detecting the uos-release RPM (version 25)
  • controls/std_uosserver25.yml: standard security benchmark control file with
    29 automated controls (files/permissions, SSH hardening, auditd, PAM,
    password policies, AIDE, account hygiene)
  • Register the product in CMakeLists.txt, build_product, and ssg/constants.py
    (product_directories, FULL_NAME_TO_PRODUCT_MAPPING, MULTI_PLATFORM_LIST,
    MULTI_PLATFORM_MAPPING, MAKEFILE_ID_TO_PRODUCT_MAP)
  • shared/applicability/package.yml: UOS uses the shadow package name like
    openEuler/Kylin (verified on the target system)
  • .github/workflows/gate_fedora.yml: build uosserver25 in CI

Rationale:

UnionTech UOS Server 25 (codename qianlai) is a domestically-developed
enterprise Linux distribution in active production use. Adding it to
ComplianceAsCode lets UOS customers scan and harden their systems with the
same upstream SCAP content used for other enterprise distributions,
following the precedent of openEuler 2203 and Kylin products.

Review Hints:

Verified on real UOS Server 25 systems (standard and Military variants,
uos-release-25-2510, x86_64, dnf, openscap 1.3.9):

  • ./build_product uosserver25 -d builds the data stream without errors
  • oscap xccdf eval --profile standard identifies the OS via the
    uos-release CPE check and evaluates 29-30 rules (19 pass, 10 real
    findings such as auditd disabled, sshd hardening defaults)

Single self-contained commit; similar in scope to the kylinserver10 /
openeuler2203 product PRs. The shadow package name in
shared/applicability/package.yml is the only change affecting shared
files.

Add a new product for UnionTech UOS Server 25 (uoss25, codename qianlai).

- products/uosserver25: product.yml with CPE cpe:/o:uniontech:uos_server:25:ga:server,
  CMakeLists.txt, and a Standard System Security profile
- shared/checks/oval: OS inventory check detecting the uos-release RPM (version 25)
- controls/std_uosserver25.yml: standard security benchmark control file with
  29 automated controls (files/permissions, SSH hardening, auditd, PAM,
  password policies, AIDE, account hygiene)
- Register the product in CMakeLists.txt, build_product, and ssg/constants.py
  (product_directories, FULL_NAME_TO_PRODUCT_MAPPING, MULTI_PLATFORM_LIST,
  MULTI_PLATFORM_MAPPING, MAKEFILE_ID_TO_PRODUCT_MAP)
- shared/applicability/package.yml: UOS uses the shadow package name like
  openEuler/Kylin (verified on the target system)
- .github/workflows/gate_fedora.yml: build uosserver25 in CI

Verified on a real UOS Server 25 system (uos-release-25-2510, x86_64, dnf):
- ./build_product uosserver25 -d builds the data stream without errors
- oscap xccdf eval --profile standard against the live system identifies the
  OS via the uos-release CPE check and evaluates 30 rules (19 pass, 10 real
  findings such as auditd disabled, sshd hardening defaults)
@openshift-ci

openshift-ci Bot commented Sep 28, 2026

Copy link
Copy Markdown

Hi @slark-yuxj. Thanks for your PR.

I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci openshift-ci Bot added the needs-ok-to-test Used by openshift-ci bot. label Sep 28, 2026
@slark-yuxj

Copy link
Copy Markdown
Author

Hi maintainers, this PR adds UOS Server 25 as a new product, following the pattern of the openeuler2203 and kylinserver10 products. Could someone from the team please take a look and /ok-to-test? Happy to
address any feedback.

@slark-yuxj

Copy link
Copy Markdown
Author

@marcusburghardt @ggbecker Could someone please /ok-to-test and set a milestone for this PR? The Milestone Check is currently pending because I can't set it myself as an external contributor.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-ok-to-test Used by openshift-ci bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant