Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Possible issue with SRC-330-3 #16

Closed
dragosprisaca opened this issue Mar 6, 2018 · 4 comments
Closed

Possible issue with SRC-330-3 #16

dragosprisaca opened this issue Mar 6, 2018 · 4 comments
Assignees

Comments

@dragosprisaca
Copy link
Collaborator

Hello Scott,

The attached content fails validation, but there is just one warning (SRC-330-3):
"Warning | 'Warning: The 'cpe:/' prefix (CPE URI binding) is allowed within an @idref attribute, but the CPE Formatted String binding is preferred. See the XCCDF 1.2.1 specification, Section 6.2.5. - TEST: false()'"
Is this the requirement that triggers the error?

Thanks,
_Dragos.
content-and-val-results.zip

@gscottwilson
Copy link
Collaborator

Thank you for reporting this. There are a couple of issue here.

First, the SRC-330-3 has a total of 128 hits of varying severity from information to error. However after 10 results they are truncated in the html report. The overall result of SRC-330-3 will ultimately be assigned the most severe error status found, in this case error, it is just within the 118 truncated results so the specific error result is not visible in the HTML report. This is a known issue and is being tracked with usnistgov/decima#7 In the meantime you can view the xml results file for complete results

Second, the error text "the value of lockout_duration must be greater than or equal to zero - TEST: string-length(.) = 0 or number(.) < 0" comes from a schematron TEST for OVAL 5.11.2 content.
It appears to be a bug as the message says ' must be greater than or equal to zero' while the actual check is '&lt; 0' where &lt (less than) 0.

@gscottwilson
Copy link
Collaborator

Dragos, you can track the first issue at usnistgov/decima#7
The second issue will need to be worked out with the OVAL community. I've assigned you to this ticket as well for updates. Thanks

@dragosprisaca
Copy link
Collaborator Author

Cross reference to OVAL Language issue: OVALProject/Language#304

@dragosprisaca
Copy link
Collaborator Author

Hello Scott,

Can you please update the schematron rules in SCAPVAL as done in OVALProject/Language#302 ?
This should take care of the issues described above.

Thanks,
_Dragos.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants