-
Notifications
You must be signed in to change notification settings - Fork 763
Open
Labels
CISCIS Benchmark related.CIS Benchmark related.Image ModeBootable containers and Image Mode RHELBootable containers and Image Mode RHELRHEL10Red Hat Enterprise Linux 10 product related.Red Hat Enterprise Linux 10 product related.productization-issueIssue found in upstream stabilization process.Issue found in upstream stabilization process.
Description
Description of problem:
The upstream daily productization run has discovered that rule file_permissions_boot_grub2 fails in these tests on RHEL 10.2:
- /hardening/container/bootc-image-builder/cis
- /hardening/container/bootc-image-builder/cis_workstation_l2
- /hardening/container/anaconda-ostree/cis
- /hardening/container/anaconda-ostree/cis_workstation_l2
- /hardening/container/old-new/cis
- /hardening/container/old-new/cis_workstation_l2
SCAP Security Guide Version:
Current upstream master branch as of 2025-12-17 as of HEAD ef80c11
Operating System Version:
RHEL 10.2 RHEL-10.2-20251216.0
Steps to Reproduce:
- Deploy a RHEL 10.2 Image Mode system hardened with CIS Server or Workstation Level 2 profile.
- Run an oscap scan of the deployed system.
Actual Results:
Rule fails in the post-deployment verification scan.
Expected Results:
Rule passes in the post-deployment verification scan.
Additional Information/Debugging Steps:
it could be related to coreos/bootupd#952
Metadata
Metadata
Assignees
Labels
CISCIS Benchmark related.CIS Benchmark related.Image ModeBootable containers and Image Mode RHELBootable containers and Image Mode RHELRHEL10Red Hat Enterprise Linux 10 product related.Red Hat Enterprise Linux 10 product related.productization-issueIssue found in upstream stabilization process.Issue found in upstream stabilization process.