File: rule.yml

package info (click to toggle)
scap-security-guide 0.1.78-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 114,600 kB
  • sloc: xml: 245,305; sh: 84,381; python: 33,093; makefile: 27
file content (35 lines) | stat: -rw-r--r-- 936 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
documentation_complete: true

title: 'Enable support for BUG()'

description: |-
    Disabling this option eliminates support for BUG and WARN, reducing the size of your kernel
    image and potentially quietly ignoring numerous fatal conditions. You should only consider
    disabling this option for embedded systems with no facilities for reporting errors.

    {{{ describe_kernel_build_config("CONFIG_BUG", "y") | indent(4) }}}

rationale: |-
    Not setting this variable may hide a number of critical errors.

warnings:
    {{{ warning_kernel_build_config() | indent(4) }}}

severity: medium

identifiers:
    cce@rhel8: CCE-86095-7
    cce@rhel9: CCE-86096-5
    cce@rhel10: CCE-89980-7

ocil_clause: 'the kernel was not built with the required value'

ocil: |-
    {{{ ocil_kernel_build_config("CONFIG_BUG", "y") | indent(4) }}}

template:
    name: kernel_build_config
    vars:
        config: CONFIG_BUG
        value: 'y'