Public bug reported:

[ Impact ]

 * When attempting to build https://github.com/ComplianceAsCode/content via 
`./build_product ubuntu2404`), OpenSCAP fails to locate its default CPE 
dictionary file. The build process outputs repeated errors:
   `OpenSCAP Error: Unable to open file: 
'/usr/share/openscap/cpe/openscap-cpe-dict.xml' 
[./src/source/oscap_source.c:298]`
   `Failed to add default CPE to newly created CPE Session. 
[./src/CPE/cpe_session.c:58]`

 * A packaging change stopped installing `/usr/share/openscap/cpe/`.
Reverting that change restores the default CPE files required for
`openscap-scanner` to generate HTML guides and perform evaluations
successfully.

[ Test Plan ]

 * Detailed instructions to reproduce the bug:
   1. On an affected system (resolute and newer), install the required build 
dependencies:
      `sudo apt update && sudo apt install -y cmake make openscap-scanner 
libxml2-utils ninja-build xsltproc git`
   2. Clone the ComplianceAsCode repository:
      `git clone https://github.com/ComplianceAsCode/content.git && cd content`
   3. Run the product build script:
      `./build_product ubuntu2404` or `./build_product -j32 ubuntu2404` 32 is 
the number of cpu cores for parallel build.
   4. Observe the console output near the end. Note the repeated `OpenSCAP 
Error: Unable to open file: '/usr/share/openscap/cpe/openscap-cpe-dict.xml'` 
failures.

 * Verification using the updated package:
   1. Update `openscap-scanner` to the version containing the fix.
   2. Verify that the dictionary file now exists:
      `ls -l /usr/share/openscap/cpe/openscap-cpe-dict.xml`
   3. Re-run the build process:
      `./build_product ubuntu2404`
   4. Confirm the build completes cleanly without CPE file open errors.

[ Where problems could occur ]

 * Re-introducing these files increases package file footprint slightly
and populates `/usr/share/openscap/cpe/`. If a user manually placed
custom files with identical names into `/usr/share/openscap/cpe/`,
`dpkg` may issue a overwrite prompt or conflict during upgrade. But to
my understanding, no one should do such thing and no one actually did
customization in real world.

 * Because this change strictly restores static XML dictionary files
expected by upstream OpenSCAP, the risk of breaking existing workloads
or binary compatibility is extremely low.

[ Other Info ]

 * Upstream/Debian Fix reference:
https://salsa.debian.org/debian/openscap/-/merge_requests/1?pow_referer=

** Affects: openscap (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168407

Title:
  Openscap Stop installing /usr/share/openscap/cpe

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/2168407/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to