Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-45713

annocheck reports stack-prot test fail for openssl-fips-provider

    • Icon: Bug Bug
    • Resolution: Cannot Reproduce
    • Icon: Minor Minor
    • None
    • rhel-9.4
    • openssl-fips-provider
    • None
    • None
    • None
    • sst_security_crypto
    • ssg_security
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None

      What were you trying to do that didn't work?

      Running annocheck stack-prot test against openssl-fips-provider reports a failure for /usr/lib64/ossl-modules/fips.so.

      Please provide the package NVR for which bug is seen:

      openssl-fips-provider-3.0.7-2.el9

      How reproducible:

      Deterministic.

      Steps to reproduce

      1. dnf install -y annobin-annocheck
      2. dnf debuginfo-install -y openssl-fips-provider
      3. rpm -ql openssl-fips-provider | xargs annocheck --verbose --ignore-unknown --ignore-links --skip-all --test-stack-prot

      Actual results

      Hardened: /usr/lib64/ossl-modules/fips.so: MAYB: test: stack-prot, reason: could not determine how the code was created
      Hardened: /usr/lib64/ossl-modules/fips.so: info: For more information visit: https://sourceware.org/annobin/annobin.html/Test-stack-prot.html
      Hardened: /usr/lib64/ossl-modules/fips.so: WARN: This can happen if the program is compiled from a language unknown to annocheck
      Hardened: /usr/lib64/ossl-modules/fips.so: WARN:  or because there are no annobin build notes (could they be in a separate file ?)
      Hardened: /usr/lib64/ossl-modules/fips.so: WARN: For more details see https://sourceware.org/annobin/annobin.html/Absence-of-compiled-code.html
      Hardened: /usr/lib64/ossl-modules/fips.so: Overall: FAIL (due to MAYB results).
      

      Expected results

      No failures for the stack-prot test - failures are either fixed or in case the failures are expected they are documented in the rpminspect.yaml file to have the test skipped including a comment explaining why.

            dbelyavs@redhat.com Dmitry Belyavskiy
            mmarhefk@redhat.com Matus Marhefka
            Matus Marhefka
            Dmitry Belyavskiy Dmitry Belyavskiy
            Alicja Kario Alicja Kario
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved: