audit_log_forwarding_enabled: potential false negative when audit inputRef is not on the first pipeline
Los mantenedores suelen responder en 3 días
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 65/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Tranquilo
- Área
- security
Línea de trabajo
Comienza en applications/openshift/api-server/audit_log_forwarding_enabled e inspecciona cómo evalúa la regla ClusterLogForwarder spec.pipelines. Reproduce el manifiesto proporcionado con audit solo en el segundo pipeline y verifica después que la regla pase; añade o actualiza la cobertura si existen tests para esta regla.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Description
Rule: ocp4-audit-log-forwarding-enabled (applications/openshift/api-server/audit_log_forwarding_enabled)
it appears the check is expected to evaluate every pipeline in every
ClusterLogForwarder object and PASS if audit appears in the inputRefs
of any pipeline.
Suspected issue
In my test cluster, I have a single ClusterLogForwarder object with two
pipelines:
apiVersion: observability.openshift.io/v1
kind: ClusterLogForwarder
metadata:
name: instance
namespace: openshift-logging
spec:
pipelines:
- name: app-logs
inputRefs:
- application
outputRefs:
- app-sink
- name: audit-logs
inputRefs:
- audit
outputRefs:
- siem-sink
Only the second pipeline (audit-logs) references audit in inputRefs.
The first pipeline does not.
Expected behavior
The rule should evaluate to PASS, since at least one pipeline
(audit-logs) forwards audit logs.
Actual behavior
If it evaluates as FAIL, this suggests the underlying OVAL/CEL check may only
be inspecting the first pipeline entry (e.g. .spec.pipelines[0].inputRefs)
rather than iterating over the full pipelines[] array, which would be a
false negative for any CLF object where the audit pipeline is not first in
the list.
After I removed my first pipleline entry, the check passed.
- Lenguaje dominante
- Shell
- Estrellas
- 2.8k
- Forks
- 835
- Merge medio
- 4 d 6 h
- PR fusionados (30 d)
- 44
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ComplianceAsCode/content
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
ComplianceAsCode/content#15152 ·
Los mantenedores suelen responder en 3 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
ComplianceAsCode/content#15151 ·
Los mantenedores suelen responder en 3 días
-
Rules of audit_rules_dac_modification template are misaligned with DISAPosiblemente ocupada @macko1 la tomó hace 7 días. Abiertoproductization-issue RHEL10 STIG triaged
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
ComplianceAsCode/content#15135 · 1 asignado ·
Los mantenedores suelen responder en 3 días
-
triaged
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
ComplianceAsCode/content#14994 · 3 comentarios ·
Los mantenedores suelen responder en 3 días
-
triaged
Dificultad 2/5 Medio día Aptitud para principiantes 62/100
ComplianceAsCode/content#12264 ·
Los mantenedores suelen responder en 3 días
Todos los issues de ComplianceAsCode/content
Issues similares
-
Feature Needs Triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
project-chip/certification-tool#1154 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
beehive-lab/TornadoVM#1151 ·
Los mantenedores suelen responder en 1 día
-
component/tests
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
NVIDIA/nodewright#735 ·
Los mantenedores suelen responder en 1 día
-
writing-plans: user-facing text that describes app behaviour should cite the code it describesAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
obra/superpowers#2433 ·
Los mantenedores suelen responder en 5 días