Skip to content

aartool 3.4.0

Choose a tag to compare

@Bantou96 Bantou96 released this 28 Aug 21:10
· 42 commits to main since this release
e7eedb9

aartool 3.4.0

The tool used to call itself four different things. A tester said the output was confusing; they were right, and it was broader than the one string they had spotted. This release makes every surface say aartool, and fixes a score that treated "could not be verified" as "wrong".

One name

The terminal said CyberAar Security Score, --help said CyberAar Security Baseline Checker, the HTML footer said CyberAar Baseline Checker while the body of the same page said plain Security Score, and only the dashboard said aartool. Meanwhile aartool --version reported 3.3.7 and the report it had just written reported 4.6.7.

CyberAar is the company. aartool is the product. Output names the product.

Renamed, with the old names still readable

  • cyberaar-baseline.sh is now aartool-baseline.sh
  • reports are written as aartool-<host>-<date>.{html,json}
  • the JSON root key is aartool, was cyberaar_baseline

All three are backward compatible on the read side. Report discovery matches both filename patterns, and diff, advise, report and the dashboard accept either root key, so audits already on disk keep working.

cyberaar-baseline.sh is still attached to this release, byte-identical to aartool-baseline.sh, so existing install notes and bookmarks keep working. It will be dropped in a later release; move to the new name.

The score no longer counts "unverified" as "wrong"

It was PASS / TOTAL, so a warning cost exactly as much as a failure. A machine with 8 real failures and 57 warnings scored 40% in red. Many warnings mean "could not be checked here" rather than "this is wrong": no /boot, no mokutil, no systemd inside a container.

score = (PASS + WARN/2) / TOTAL

The same machine now scores 67%. Failures lead the summary line and the weighting is printed under the score. Scores are not comparable across this change, so aartool diff now says so when the two reports it is given came from different engine versions.

Fixed

  • Kernel checks printed above the first section header with no header of their own. checks/kernel.sh was the only check family with no wrapping function, so its twelve KRN-* results ran at load time, before anything else. Twelve unlabelled rows were the first thing every user saw. They now appear as "1b. KERNEL ATTACK SURFACE".
  • Reports were unreadable by the person who ran them. The standalone script must run as root, so it wrote root:root mode 600 and left you unable to open the file it had just printed a path to. It now hands reports back to SUDO_UID, as aartool inspect already did.
  • --help printed a version from the build machine. The banner interpolated a command inside an unquoted heredoc and advertised whatever aartool was installed where the release was built. Guarded now, in both directions.
  • The HTML report subtitle repeated its own heading verbatim.
  • INT-07 restated INT-01 verbatim when AIDE is absent, so one missing package read as two problems.

Verifying the download

Release assets do not carry the executable bit.

curl -fsSLO https://github.com/cyberaar/aartool/releases/latest/download/aartool-baseline.sh
curl -fsSLO https://github.com/cyberaar/aartool/releases/latest/download/SHA256SUMS
sha256sum -c SHA256SUMS --ignore-missing
chmod +x aartool-baseline.sh && sudo ./aartool-baseline.sh

914 assertions and 31 Molecule scenarios on Rocky 9 and Ubuntu 22.04, all green.