summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorAkshay Bhat <nodeax@gmail.com>2022-01-21 11:32:39 -0500
committerArmin Kuster <akuster808@gmail.com>2022-02-20 19:38:30 -0800
commit9cd85e054fc8b3844e9bb74f34f4402029182844 (patch)
tree068ddbafaff05a5a6cdcfab25ae552875059fa79
parent7898fc8117c81a08af6e266a9f21e57bc3978b3a (diff)
downloadmeta-security-9cd85e054fc8b3844e9bb74f34f4402029182844.tar.gz
meta-hardening: Fix override syntax
Commit 352e6498a missed updating the override syntax for the "harden" distro override. Fixes: 352e6498a ("meta-hardening: Convert to new override syntax") Signed-off-by: Akshay Bhat <akshay.bhat@timesys.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
-rw-r--r--meta-hardening/recipes-connectivity/openssh/openssh_%.bbappend2
-rw-r--r--meta-hardening/recipes-core/base-files/base-files_%.bbappend2
-rw-r--r--meta-hardening/recipes-core/initscripts/initscripts_1.0.bbappend6
-rw-r--r--meta-hardening/recipes-extended/shadow/shadow_%.bbappend2
-rw-r--r--meta-hardening/recipes-extended/sudo/sudo_%.bbappend4
5 files changed, 8 insertions, 8 deletions
diff --git a/meta-hardening/recipes-connectivity/openssh/openssh_%.bbappend b/meta-hardening/recipes-connectivity/openssh/openssh_%.bbappend
index 17c06ed..e192d3d 100644
--- a/meta-hardening/recipes-connectivity/openssh/openssh_%.bbappend
+++ b/meta-hardening/recipes-connectivity/openssh/openssh_%.bbappend
@@ -1,4 +1,4 @@
1do_install:append_harden () { 1do_install:append:harden () {
2 # to hardend 2 # to hardend
3 sed -i -e 's:#AllowTcpForwarding yes:AllowTcpForwarding no:' ${D}${sysconfdir}/ssh/sshd_config 3 sed -i -e 's:#AllowTcpForwarding yes:AllowTcpForwarding no:' ${D}${sysconfdir}/ssh/sshd_config
4 sed -i -e 's:ClientAliveCountMax 4:ClientAliveCountMax 2:' ${D}${sysconfdir}/ssh/sshd_config 4 sed -i -e 's:ClientAliveCountMax 4:ClientAliveCountMax 2:' ${D}${sysconfdir}/ssh/sshd_config
diff --git a/meta-hardening/recipes-core/base-files/base-files_%.bbappend b/meta-hardening/recipes-core/base-files/base-files_%.bbappend
index 0f0384f..4710b49 100644
--- a/meta-hardening/recipes-core/base-files/base-files_%.bbappend
+++ b/meta-hardening/recipes-core/base-files/base-files_%.bbappend
@@ -1,4 +1,4 @@
1 1
2do_install:append_harden () { 2do_install:append:harden () {
3 sed -i 's/umask.*/umask 027/g' ${D}/${sysconfdir}/profile 3 sed -i 's/umask.*/umask 027/g' ${D}/${sysconfdir}/profile
4} 4}
diff --git a/meta-hardening/recipes-core/initscripts/initscripts_1.0.bbappend b/meta-hardening/recipes-core/initscripts/initscripts_1.0.bbappend
index b27dee9..92e364c 100644
--- a/meta-hardening/recipes-core/initscripts/initscripts_1.0.bbappend
+++ b/meta-hardening/recipes-core/initscripts/initscripts_1.0.bbappend
@@ -1,8 +1,8 @@
1FILESEXTRAPATHS:prepend_harden := "${THISDIR}/files:" 1FILESEXTRAPATHS:prepend:harden := "${THISDIR}/files:"
2 2
3SRC_URI:append_harden = " file://mountall.sh" 3SRC_URI:append:harden = " file://mountall.sh"
4 4
5do_install:append_harden() { 5do_install:append:harden() {
6 install -d ${D}${sysconfdir}/init.d 6 install -d ${D}${sysconfdir}/init.d
7 install -m 0755 ${WORKDIR}/mountall.sh ${D}${sysconfdir}/init.d 7 install -m 0755 ${WORKDIR}/mountall.sh ${D}${sysconfdir}/init.d
8} 8}
diff --git a/meta-hardening/recipes-extended/shadow/shadow_%.bbappend b/meta-hardening/recipes-extended/shadow/shadow_%.bbappend
index 3058b55..793a075 100644
--- a/meta-hardening/recipes-extended/shadow/shadow_%.bbappend
+++ b/meta-hardening/recipes-extended/shadow/shadow_%.bbappend
@@ -1,4 +1,4 @@
1do_install:append_harden () { 1do_install:append:harden () {
2 # to hardend 2 # to hardend
3 sed -i -e 's:UMASK.*:UMASK 027:' ${D}${sysconfdir}/login.defs 3 sed -i -e 's:UMASK.*:UMASK 027:' ${D}${sysconfdir}/login.defs
4 sed -i -e 's:PASS_MAX_DAYS.*:PASS_MAX_DAYS 365:' ${D}${sysconfdir}/login.defs 4 sed -i -e 's:PASS_MAX_DAYS.*:PASS_MAX_DAYS 365:' ${D}${sysconfdir}/login.defs
diff --git a/meta-hardening/recipes-extended/sudo/sudo_%.bbappend b/meta-hardening/recipes-extended/sudo/sudo_%.bbappend
index 97c5f49..2860e8a 100644
--- a/meta-hardening/recipes-extended/sudo/sudo_%.bbappend
+++ b/meta-hardening/recipes-extended/sudo/sudo_%.bbappend
@@ -1,6 +1,6 @@
1 1
2PACKAGECONFIG:append_harden = " pam-wheel" 2PACKAGECONFIG:append:harden = " pam-wheel"
3do_install:append_harden () { 3do_install:append:harden () {
4 if [ "${@bb.utils.contains('DISABLE_ROOT', 'True', 'yes', 'no', d)}" = "yes" ]; then 4 if [ "${@bb.utils.contains('DISABLE_ROOT', 'True', 'yes', 'no', d)}" = "yes" ]; then
5 sed -i -e 's:root ALL=(ALL) ALL:#root ALL=(ALL) ALL:' ${D}${sysconfdir}/sudoers 5 sed -i -e 's:root ALL=(ALL) ALL:#root ALL=(ALL) ALL:' ${D}${sysconfdir}/sudoers
6 fi 6 fi