Skip to content

Add test ensuring $TMPDIR is honored by OpenSCAP - #2428

Merged
Mab879 merged 1 commit into
OpenSCAP:mainfrom
jan-cerny:test_tmpdir
Oct 7, 2026
Merged

Mab879 merged 1 commit into
OpenSCAP:mainfrom
jan-cerny:test_tmpdir

Conversation

@jan-cerny

Copy link
Copy Markdown
Member

This commit introduces a test that verifies that the TMPDIR environment variable is honored by OpenSCAP and that the TMPDIR environment variable is correctly used in OpenSCAP when it creates any temporary files during its execution. OpenSCAP shall use TMPDIR as base directory for temporary files, instead of forcing to use /tmp, which may be too small, depending on system's configuration.

This is a regression test for:
https://redhat.atlassian.net/browse/RHEL-222370

This test covers changes introduced by:
#2393

@jan-cerny jan-cerny added this to the 1.4.5 milestone Oct 5, 2026
Comment thread tests/common/test_tmpdir.c Fixed

@Mab879 Mab879 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I know its test code, but let's fix some these automated finding from CodeQL for sure, but I think some the sonar findings are worth fixing as well.

@Mab879

Mab879 commented Oct 5, 2026

Copy link
Copy Markdown
Member

Those CI fails look valid, but I'm not sure what is causing them to fail.

@jan-cerny

Copy link
Copy Markdown
Member Author

The "Gating / Build, Test on Fedora Rawhide (NSS) (Container) (pull_request)" and testing-farm:fedora-rawhide-x86_64 fails can be reproduced separately and therefore aren't caused by this PR. I managed to reproduce them on testing farm machine with Rawhide on the current main branch. I reported it here: #2440

@jan-cerny

Copy link
Copy Markdown
Member Author

@Mab879 Do you have any idea what can we do with the D Security Rating on New Code ?

@Mab879

Mab879 commented Oct 6, 2026

Copy link
Copy Markdown
Member

@Mab879 Do you have any idea what can we do with the D Security Rating on New Code ?

From the site

Temporary files should not be created in publicly writable directories c:S5443

So if you adjust the perms on the folder you create we might be able avoid this warning.

@Mab879 Mab879 self-assigned this Oct 7, 2026
This commit introduces a test that verifies that the TMPDIR
environment variable is honored by OpenSCAP and that the TMPDIR
environment variable is correctly used in OpenSCAP when it creates
any temporary files during its execution. OpenSCAP shall use TMPDIR
as base directory for temporary files, instead of forcing to use /tmp,
which may be too small, depending on system's configuration.

This is a regression test for:
https://redhat.atlassian.net/browse/RHEL-222370

This test covers changes introduced by:
OpenSCAP#2393
@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
D Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@jan-cerny

Copy link
Copy Markdown
Member Author

@Mab879 I have added a chmod call now but it haven't dismissed the Sonar's finding.

@Mab879

Mab879 commented Oct 7, 2026

Copy link
Copy Markdown
Member

@Mab879 I have added a chmod call now but it haven't dismissed the Sonar's finding.

Based on the wording seems this one needs manual review. With the chmod we should be fine. Starting my review, hopefully will be done today.

@Mab879
Mab879 merged commit 0e3eea3 into OpenSCAP:main Oct 7, 2026
17 of 21 checks passed
@jan-cerny jan-cerny mentioned this pull request Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants