Repository navigation
Conversation
| local schema_version | ||
|
|
||
| for schema_version in 5.11 5.11.1 5.11.2 5.11.3; do | ||
| sed "s/>5\.11\.3</>$schema_version</" \ |
There was a problem hiding this comment.
Instead of this ugly sed command you can have a special placeholder in the OVAL file like SCHEMA_VERSION_PLACEHOLDER and a nice sed command that will replace the placeholder.
| mth_str = "SHA-512"; | ||
| pwd++; | ||
| break; | ||
| case 'y': |
There was a problem hiding this comment.
Yescrypt is emitted for all schema versions from 5.8 onward, but its enumeration is added only to 5.11 through 5.11.3. Evaluating a 5.8, 5.9, 5.10, or 5.10.1 definition against a yescrypt shadow entry now produces <encrypt_method>yescrypt</encrypt_method>, which fails validation against that version’s system-characteristics schema. Gate the new result value on schema version >= 5.11.
| while (*pwd == '!') | ||
| pwd++; | ||
|
|
||
| if (pwd == NULL || |
There was a problem hiding this comment.
You need to move the check for pwd == NULL before the while loop.
|
| set -e -o pipefail | ||
|
|
||
| tmpdir="" | ||
| trap 'if [[ $tmpdir ]]; then rm -rf "$tmpdir"; fi' EXIT |
There was a problem hiding this comment.
My AI suggests this:
test_run executes the test function in a subshell. The assignment to tmpdir therefore never reaches the parent shell, and the parent’s EXIT trap is not executed by that subshell. As a result, every run leaves /tmp/test_shadow_yescrypt.* behind, including the shadow fixture and XML output.
I confirmed the directory remained after a successful test run. Move the trap into test_probes_shadow_yescrypt, immediately after creating the temporary directory, so cleanup runs on both success and failure.



Description
definitionsandsystem characteristicsand allowsyescryptto be an acceptable encryption method for shadow entriesparse_enc_mthto recognize$y$prefix for parsed entries!,*,xbefore the entries, fixing the situation, when locked accounts and accounts with placeholder password are mistaken for entries withDESencryption methodTesting
ctest -R shadowto execute all shadow probe tests including the newtest_probes_shadow_yescrypt.sh- Plain yescrypt hashes, locked hashes with
!and!!, and stripped$y$markers.- Rejection of malformed identifiers such as
$yx$and incomplete$yprefixes.- Existing SHA-512 detection.
- Definitions and results validation across OVAL 5.11–5.11.3.