Skip to content

stabilization: Mark missing_auid tests as pass for lastlog/faillock audit rules - #15059

Merged
Mab879 merged 2 commits into
ComplianceAsCode:stabilizationfrom
ggbecker:fix-audit-lastlog-auid-test-stabilization
Aug 26, 2026
Merged

stabilization: Mark missing_auid tests as pass for lastlog/faillock audit rules#15059
Mab879 merged 2 commits into
ComplianceAsCode:stabilizationfrom
ggbecker:fix-audit-lastlog-auid-test-stabilization

Conversation

@ggbecker

Copy link
Copy Markdown
Member

Backport of #15058

The OVAL check for audit_rules_login_events_lastlog on rhel9 (modern
audit watch style) matches audit rules with or without the auid filters
(-F auid>=1000 -F auid!=unset), since the generated pattern ends with
'perm=wa.*$'. A rule that omits the auid filters therefore passes the
scan, so the rhel9_missing_auid scenario must be a pass test, not a fail.
Like audit_rules_login_events_lastlog, this rule uses the audit_rules_watch
template and on rhel9 (modern audit watch style) the OVAL check matches
audit rules with or without the auid filters (-F auid>=1000 -F auid!=unset),
since the generated pattern ends with 'perm=wa.*$'. A rule that omits the
auid filters therefore passes the scan, so the rhel9_missing_auid scenario
must be a pass test, not a fail.
@ggbecker ggbecker added this to the 0.1.82 milestone Aug 26, 2026
@ggbecker ggbecker added RHEL Red Hat Enterprise Linux product related. STIG STIG Benchmark related. labels Aug 26, 2026
@ggbecker ggbecker changed the title stabilization: Mark missing_auid tests as pass for lastlog/faillock audit rules - #15058 stabilization: Mark missing_auid tests as pass for lastlog/faillock audit rules Aug 26, 2026
@Mab879 Mab879 self-assigned this Aug 26, 2026
@Mab879
Mab879 merged commit 3e3afcf into ComplianceAsCode:stabilization Aug 26, 2026
58 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

RHEL Red Hat Enterprise Linux product related. STIG STIG Benchmark related.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants