Skip to content

Add yescrypt support to encrypt_method in shadow probe - #2441

Open
Arden97 wants to merge 1 commit into
OpenSCAP:mainfrom
Arden97:yescrypt
Open

Arden97 wants to merge 1 commit into
OpenSCAP:mainfrom
Arden97:yescrypt

Conversation

@Arden97

@Arden97 Arden97 commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Description

  • This PR updates the OVAL 5.11 schema enumerations for definitions and system characteristics and allows yescrypt to be an acceptable encryption method for shadow entries
  • updates parse_enc_mth to recognize $y$ prefix for parsed entries
  • also adds mechanism to skip !, *, x before the entries, fixing the situation, when locked accounts and accounts with placeholder password are mistaken for entries with DES  encryption method
  • fixes Add yescrypt support to encrypt_method in shadow probe #2398

Testing

  • use ctest -R shadow to execute all shadow probe tests including the new test_probes_shadow_yescrypt.sh
  • the test covers
      - Plain yescrypt hashes, locked hashes with ! and !!, and stripped $y$ markers.
      - Rejection of malformed identifiers such as $yx$ and incomplete $y prefixes.
      - Existing SHA-512 detection.
      - Definitions and results validation across OVAL 5.11–5.11.3.

Comment thread src/OVAL/probes/unix/shadow_probe.c Fixed
jan-cerny
jan-cerny previously approved these changes Oct 7, 2026
local schema_version

for schema_version in 5.11 5.11.1 5.11.2 5.11.3; do
sed "s/>5\.11\.3</>$schema_version</" \

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of this ugly sed command you can have a special placeholder in the OVAL file like SCHEMA_VERSION_PLACEHOLDER and a nice sed command that will replace the placeholder.

mth_str = "SHA-512";
pwd++;
break;
case 'y':

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yescrypt is emitted for all schema versions from 5.8 onward, but its enumeration is added only to 5.11 through 5.11.3. Evaluating a 5.8, 5.9, 5.10, or 5.10.1 definition against a yescrypt shadow entry now produces <encrypt_method>yescrypt</encrypt_method>, which fails validation against that version’s system-characteristics schema. Gate the new result value on schema version >= 5.11.

Comment thread src/OVAL/probes/unix/shadow_probe.c Outdated
while (*pwd == '!')
pwd++;

if (pwd == NULL ||

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You need to move the check for pwd == NULL before the while loop.

@jan-cerny jan-cerny self-assigned this Oct 7, 2026
@jan-cerny jan-cerny added this to the 1.4.5 milestone Oct 7, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

set -e -o pipefail

tmpdir=""
trap 'if [[ $tmpdir ]]; then rm -rf "$tmpdir"; fi' EXIT

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My AI suggests this:

test_run executes the test function in a subshell. The assignment to tmpdir therefore never reaches the parent shell, and the parent’s EXIT trap is not executed by that subshell. As a result, every run leaves /tmp/test_shadow_yescrypt.* behind, including the shadow fixture and XML output.
I confirmed the directory remained after a successful test run. Move the trap into test_probes_shadow_yescrypt, immediately after creating the temporary directory, so cleanup runs on both success and failure.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add yescrypt support to encrypt_method in shadow probe

3 participants