Warning: Permanently added '3.82.8.27' (ED25519) to the list of known hosts. You can reproduce this build on your computer by running: sudo dnf install copr-rpmbuild /usr/bin/copr-rpmbuild --verbose --drop-resultdir --task-url https://copr.fedorainfracloud.org/backend/get-build-task/9793685-centos-stream-9-x86_64 --chroot centos-stream-9-x86_64 Version: 1.6 PID: 8666 Logging PID: 8668 Task: {'allow_user_ssh': False, 'appstream': False, 'background': False, 'build_id': 9793685, 'buildroot_pkgs': [], 'chroot': 'centos-stream-9-x86_64', 'enable_net': False, 'fedora_review': False, 'git_hash': '2d96fea02aed2e39cd6f731af91d862d714872f2', 'git_repo': 'https://copr-dist-git.fedorainfracloud.org/git/packit/ComplianceAsCode-content-14119/scap-security-guide', 'isolation': 'default', 'memory_reqs': 2048, 'package_name': 'scap-security-guide', 'package_version': '0.1.79-0.20251113092050720330.pr14119.18545.ga45aadb5a1', 'project_dirname': 'ComplianceAsCode-content-14119', 'project_name': 'ComplianceAsCode-content-14119', 'project_owner': 'packit', 'repo_priority': None, 'repos': [{'baseurl': 'https://download.copr.fedorainfracloud.org/results/packit/ComplianceAsCode-content-14119/centos-stream-9-x86_64/', 'id': 'copr_base', 'name': 'Copr repository', 'priority': None}], 'sandbox': 'packit/ComplianceAsCode-content-14119--packit', 'source_json': {}, 'source_type': None, 'ssh_public_keys': None, 'storage': 0, 'submitter': 'packit', 'tags': [], 'task_id': '9793685-centos-stream-9-x86_64', 'timeout': 18000, 'uses_devel_repo': False, 'with_opts': [], 'without_opts': []} Running: git clone https://copr-dist-git.fedorainfracloud.org/git/packit/ComplianceAsCode-content-14119/scap-security-guide /var/lib/copr-rpmbuild/workspace/workdir-zza_3pxq/scap-security-guide --depth 500 --no-single-branch --recursive cmd: ['git', 'clone', 'https://copr-dist-git.fedorainfracloud.org/git/packit/ComplianceAsCode-content-14119/scap-security-guide', '/var/lib/copr-rpmbuild/workspace/workdir-zza_3pxq/scap-security-guide', '--depth', '500', '--no-single-branch', '--recursive'] cwd: . rc: 0 stdout: stderr: Cloning into '/var/lib/copr-rpmbuild/workspace/workdir-zza_3pxq/scap-security-guide'... Running: git checkout 2d96fea02aed2e39cd6f731af91d862d714872f2 -- cmd: ['git', 'checkout', '2d96fea02aed2e39cd6f731af91d862d714872f2', '--'] cwd: /var/lib/copr-rpmbuild/workspace/workdir-zza_3pxq/scap-security-guide rc: 0 stdout: stderr: Note: switching to '2d96fea02aed2e39cd6f731af91d862d714872f2'. You are in 'detached HEAD' state. You can look around, make experimental changes and commit them, and you can discard any commits you make in this state without impacting any branches by switching back to a branch. If you want to create a new branch to retain commits you create, you may do so (now or later) by using -c with the switch command. Example: git switch -c Or undo this operation with: git switch - Turn off this advice by setting config variable advice.detachedHead to false HEAD is now at 2d96fea automatic import of scap-security-guide Running: dist-git-client sources cmd: ['dist-git-client', 'sources'] cwd: /var/lib/copr-rpmbuild/workspace/workdir-zza_3pxq/scap-security-guide rc: 0 stdout: stderr: INFO: Reading stdout from command: git rev-parse --abbrev-ref HEAD INFO: Reading stdout from command: git rev-parse HEAD INFO: Reading sources specification file: sources INFO: Downloading scap-security-guide-0.1.79.tar.gz INFO: Reading stdout from command: curl --help all INFO: Calling: curl -H Pragma: -o scap-security-guide-0.1.79.tar.gz --location --connect-timeout 60 --retry 3 --retry-delay 10 --remote-time --show-error --fail --retry-all-errors https://copr-dist-git.fedorainfracloud.org/repo/pkgs/packit/ComplianceAsCode-content-14119/scap-security-guide/scap-security-guide-0.1.79.tar.gz/md5/b40cba075b6b5f43d9a5b2af3fe95e14/scap-security-guide-0.1.79.tar.gz % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 10.8M 100 10.8M 0 0 381M 0 --:--:-- --:--:-- --:--:-- 386M INFO: Reading stdout from command: md5sum scap-security-guide-0.1.79.tar.gz tail: /var/lib/copr-rpmbuild/main.log: file truncated Running (timeout=18000): unbuffer mock --spec /var/lib/copr-rpmbuild/workspace/workdir-zza_3pxq/scap-security-guide/scap-security-guide.spec --sources /var/lib/copr-rpmbuild/workspace/workdir-zza_3pxq/scap-security-guide --resultdir /var/lib/copr-rpmbuild/results --uniqueext 1763025687.143490 -r /var/lib/copr-rpmbuild/results/configs/child.cfg INFO: mock.py version 6.5 starting (python version = 3.13.7, NVR = mock-6.5-1.fc42), args: /usr/libexec/mock/mock --spec /var/lib/copr-rpmbuild/workspace/workdir-zza_3pxq/scap-security-guide/scap-security-guide.spec --sources /var/lib/copr-rpmbuild/workspace/workdir-zza_3pxq/scap-security-guide --resultdir /var/lib/copr-rpmbuild/results --uniqueext 1763025687.143490 -r /var/lib/copr-rpmbuild/results/configs/child.cfg Start(bootstrap): init plugins INFO: tmpfs initialized INFO: selinux enabled INFO: chroot_scan: initialized INFO: compress_logs: initialized Finish(bootstrap): init plugins Start: init plugins INFO: tmpfs initialized INFO: selinux enabled INFO: chroot_scan: initialized INFO: compress_logs: initialized Finish: init plugins INFO: Signal handler active Start: run INFO: Start(/var/lib/copr-rpmbuild/workspace/workdir-zza_3pxq/scap-security-guide/scap-security-guide.spec) Config(centos-stream-9-x86_64) Start: clean chroot Finish: clean chroot Mock Version: 6.5 INFO: Mock Version: 6.5 Start(bootstrap): chroot init INFO: mounting tmpfs at /var/lib/mock/centos-stream-9-x86_64-bootstrap-1763025687.143490/root. INFO: calling preinit hooks INFO: enabled root cache INFO: enabled package manager cache Start(bootstrap): cleaning package manager metadata Finish(bootstrap): cleaning package manager metadata INFO: Guessed host environment type: unknown INFO: Using container image: quay.io/centos/centos:stream9 INFO: Pulling image: quay.io/centos/centos:stream9 INFO: Tagging container image as mock-bootstrap-47b9eeba-b4ef-4ea0-a489-1f87c635d02e INFO: Checking that 5b0c7c57ab7e66c4e511867aa29b4e32ad79e5013dee3aeb56e71e12a4110b9b image matches host's architecture INFO: Copy content of container 5b0c7c57ab7e66c4e511867aa29b4e32ad79e5013dee3aeb56e71e12a4110b9b to /var/lib/mock/centos-stream-9-x86_64-bootstrap-1763025687.143490/root INFO: mounting 5b0c7c57ab7e66c4e511867aa29b4e32ad79e5013dee3aeb56e71e12a4110b9b with podman image mount INFO: image 5b0c7c57ab7e66c4e511867aa29b4e32ad79e5013dee3aeb56e71e12a4110b9b as /var/lib/containers/storage/overlay/8bee6204d39f03c8f9b031a751e022b9c3cd1febe1a5741d6d5ccc284cd682e0/merged INFO: umounting image 5b0c7c57ab7e66c4e511867aa29b4e32ad79e5013dee3aeb56e71e12a4110b9b (/var/lib/containers/storage/overlay/8bee6204d39f03c8f9b031a751e022b9c3cd1febe1a5741d6d5ccc284cd682e0/merged) with podman image umount INFO: Removing image mock-bootstrap-47b9eeba-b4ef-4ea0-a489-1f87c635d02e INFO: Package manager dnf4 detected and used (fallback) INFO: Not updating bootstrap chroot, bootstrap_image_ready=True Start(bootstrap): creating root cache Finish(bootstrap): creating root cache Finish(bootstrap): chroot init Start: chroot init INFO: mounting tmpfs at /var/lib/mock/centos-stream-9-x86_64-1763025687.143490/root. INFO: calling preinit hooks INFO: enabled root cache INFO: enabled package manager cache Start: cleaning package manager metadata Finish: cleaning package manager metadata INFO: enabled HW Info plugin INFO: Package manager dnf4 detected and used (direct choice) INFO: Buildroot is handled by package management downloaded with a bootstrap image: rpm-4.16.1.3-39.el9.x86_64 python3-dnf-4.14.0-31.el9.noarch python3-dnf-plugins-core-4.3.0-23.el9.noarch yum-4.14.0-31.el9.noarch Start: installing minimal buildroot with dnf No matches found for the following disable plugin patterns: local, spacewalk, versionlock Copr repository 17 kB/s | 3.2 kB 00:00 CentOS Stream 9 - BaseOS 51 MB/s | 8.8 MB 00:00 CentOS Stream 9 - AppStream 117 MB/s | 25 MB 00:00 CentOS Stream 9 - CRB 47 MB/s | 7.3 MB 00:00 CentOS Stream 9 - Extras packages 226 kB/s | 20 kB 00:00 Dependencies resolved. ================================================================================ Package Arch Version Repo Size ================================================================================ Installing: bash x86_64 5.1.8-9.el9 baseos 1.7 M bzip2 x86_64 1.0.8-10.el9 baseos 56 k centos-stream-release noarch 9.0-30.el9 baseos 24 k coreutils x86_64 8.32-39.el9 baseos 1.2 M cpio x86_64 2.13-16.el9 baseos 275 k diffutils x86_64 3.7-12.el9 baseos 397 k findutils x86_64 1:4.8.0-7.el9 baseos 547 k gawk x86_64 5.1.0-6.el9 baseos 1.0 M glibc-minimal-langpack x86_64 2.34-238.el9 baseos 22 k grep x86_64 3.6-5.el9 baseos 269 k gzip x86_64 1.12-1.el9 baseos 163 k info x86_64 6.7-15.el9 baseos 225 k make x86_64 1:4.3-8.el9 baseos 536 k patch x86_64 2.7.6-16.el9 appstream 128 k redhat-rpm-config noarch 210-1.el9 appstream 70 k rpm-build x86_64 4.16.1.3-39.el9 appstream 66 k sed x86_64 4.8-9.el9 baseos 305 k tar x86_64 2:1.34-7.el9 baseos 885 k unzip x86_64 6.0-59.el9 baseos 182 k util-linux x86_64 2.37.4-21.el9 baseos 2.3 M which x86_64 2.21-30.el9 baseos 41 k xz x86_64 5.2.5-8.el9 baseos 226 k Installing dependencies: alternatives x86_64 1.24-2.el9 baseos 39 k audit-libs x86_64 3.1.5-7.el9 baseos 119 k basesystem noarch 11-13.el9 baseos 3.9 k binutils x86_64 2.35.2-67.el9 baseos 4.6 M binutils-gold x86_64 2.35.2-67.el9 baseos 734 k bzip2-libs x86_64 1.0.8-10.el9 baseos 40 k ca-certificates noarch 2025.2.80_v9.0.305-91.el9 baseos 1.0 M centos-gpg-keys noarch 9.0-30.el9 baseos 13 k centos-stream-repos noarch 9.0-30.el9 baseos 9.6 k coreutils-common x86_64 8.32-39.el9 baseos 2.0 M cracklib x86_64 2.9.6-27.el9 baseos 94 k cracklib-dicts x86_64 2.9.6-27.el9 baseos 3.6 M crypto-policies noarch 20250905-1.git377cc42.el9 baseos 90 k curl x86_64 7.76.1-34.el9 baseos 292 k cyrus-sasl-lib x86_64 2.1.27-21.el9 baseos 769 k debugedit x86_64 5.0-11.el9 appstream 77 k dwz x86_64 0.16-1.el9 appstream 134 k ed x86_64 1.14.2-12.el9 baseos 75 k efi-srpm-macros noarch 6-4.el9 appstream 21 k elfutils x86_64 0.193-1.el9 baseos 598 k elfutils-debuginfod-client x86_64 0.193-1.el9 baseos 44 k elfutils-default-yama-scope noarch 0.193-1.el9 baseos 9.7 k elfutils-libelf x86_64 0.193-1.el9 baseos 205 k elfutils-libs x86_64 0.193-1.el9 baseos 268 k file x86_64 5.39-16.el9 baseos 50 k file-libs x86_64 5.39-16.el9 baseos 589 k filesystem x86_64 3.16-5.el9 baseos 4.8 M fonts-srpm-macros noarch 1:2.0.5-7.el9.1 appstream 28 k gdb-minimal x86_64 16.3-2.el9 appstream 4.4 M gdbm-libs x86_64 1:1.23-1.el9 baseos 56 k ghc-srpm-macros noarch 1.5.0-6.el9 appstream 8.8 k glibc x86_64 2.34-238.el9 baseos 2.0 M glibc-common x86_64 2.34-238.el9 baseos 307 k glibc-gconv-extra x86_64 2.34-238.el9 baseos 1.7 M gmp x86_64 1:6.2.0-13.el9 baseos 315 k go-srpm-macros noarch 3.8.1-1.el9 appstream 27 k groff-base x86_64 1.22.4-10.el9 baseos 1.1 M json-c x86_64 0.14-11.el9 baseos 43 k kernel-srpm-macros noarch 1.0-14.el9 appstream 14 k keyutils-libs x86_64 1.6.3-1.el9 baseos 32 k krb5-libs x86_64 1.21.1-8.el9 baseos 766 k libacl x86_64 2.3.1-4.el9 baseos 23 k libarchive x86_64 3.5.3-6.el9 baseos 387 k libattr x86_64 2.5.1-3.el9 baseos 19 k libblkid x86_64 2.37.4-21.el9 baseos 107 k libbrotli x86_64 1.0.9-7.el9 baseos 313 k libcap x86_64 2.48-10.el9 baseos 70 k libcap-ng x86_64 0.8.2-7.el9 baseos 33 k libcom_err x86_64 1.46.5-8.el9 baseos 26 k libcurl x86_64 7.76.1-34.el9 baseos 283 k libdb x86_64 5.3.28-57.el9 baseos 735 k libeconf x86_64 0.4.1-4.el9 baseos 27 k libevent x86_64 2.1.12-8.el9 baseos 262 k libfdisk x86_64 2.37.4-21.el9 baseos 154 k libffi x86_64 3.4.2-8.el9 baseos 38 k libgcc x86_64 11.5.0-11.el9 baseos 85 k libgcrypt x86_64 1.10.0-11.el9 baseos 508 k libgomp x86_64 11.5.0-11.el9 baseos 258 k libgpg-error x86_64 1.42-5.el9 baseos 216 k libidn2 x86_64 2.3.0-7.el9 baseos 101 k libmount x86_64 2.37.4-21.el9 baseos 135 k libnghttp2 x86_64 1.43.0-6.el9 baseos 73 k libpkgconf x86_64 1.7.3-10.el9 baseos 36 k libpsl x86_64 0.21.1-5.el9 baseos 64 k libpwquality x86_64 1.4.4-8.el9 baseos 119 k libselinux x86_64 3.6-3.el9 baseos 86 k libsemanage x86_64 3.6-5.el9 baseos 118 k libsepol x86_64 3.6-3.el9 baseos 329 k libsigsegv x86_64 2.13-4.el9 baseos 27 k libsmartcols x86_64 2.37.4-21.el9 baseos 63 k libssh x86_64 0.10.4-15.el9 baseos 212 k libssh-config noarch 0.10.4-15.el9 baseos 7.7 k libstdc++ x86_64 11.5.0-11.el9 baseos 745 k libtasn1 x86_64 4.16.0-9.el9 baseos 74 k libtool-ltdl x86_64 2.4.6-46.el9 baseos 36 k libunistring x86_64 0.9.10-15.el9 baseos 496 k libutempter x86_64 1.2.1-6.el9 baseos 27 k libuuid x86_64 2.37.4-21.el9 baseos 28 k libverto x86_64 0.3.2-3.el9 baseos 22 k libxcrypt x86_64 4.4.18-3.el9 baseos 116 k libxml2 x86_64 2.9.13-12.el9 baseos 747 k libzstd x86_64 1.5.5-1.el9 baseos 295 k lua-libs x86_64 5.4.4-4.el9 baseos 130 k lua-srpm-macros noarch 1-6.el9 appstream 9.5 k lz4-libs x86_64 1.9.3-5.el9 baseos 68 k mpfr x86_64 4.1.0-7.el9 baseos 326 k ncurses x86_64 6.2-12.20210508.el9 baseos 406 k ncurses-base noarch 6.2-12.20210508.el9 baseos 95 k ncurses-libs x86_64 6.2-12.20210508.el9 baseos 328 k ocaml-srpm-macros noarch 6-6.el9 appstream 8.8 k openblas-srpm-macros noarch 2-11.el9 appstream 8.4 k openldap x86_64 2.6.8-4.el9 baseos 285 k openssl x86_64 1:3.5.1-6.el9 baseos 1.5 M openssl-fips-provider x86_64 1:3.5.1-6.el9 baseos 812 k openssl-libs x86_64 1:3.5.1-6.el9 baseos 2.3 M p11-kit x86_64 0.25.10-1.el9 baseos 561 k p11-kit-trust x86_64 0.25.10-1.el9 baseos 151 k pam x86_64 1.5.1-26.el9 baseos 622 k pcre x86_64 8.44-4.el9 baseos 197 k pcre2 x86_64 10.40-6.el9 baseos 234 k pcre2-syntax noarch 10.40-6.el9 baseos 141 k perl-AutoLoader noarch 5.74-483.el9 appstream 21 k perl-B x86_64 1.80-483.el9 appstream 180 k perl-Carp noarch 1.50-460.el9 appstream 30 k perl-Class-Struct noarch 0.66-483.el9 appstream 22 k perl-Data-Dumper x86_64 2.174-462.el9 appstream 56 k perl-Digest noarch 1.19-4.el9 appstream 26 k perl-Digest-MD5 x86_64 2.58-4.el9 appstream 37 k perl-Encode x86_64 4:3.08-462.el9 appstream 1.7 M perl-Errno x86_64 1.30-483.el9 appstream 15 k perl-Exporter noarch 5.74-461.el9 appstream 32 k perl-Fcntl x86_64 1.13-483.el9 appstream 20 k perl-File-Basename noarch 2.85-483.el9 appstream 17 k perl-File-Path noarch 2.18-4.el9 appstream 36 k perl-File-Temp noarch 1:0.231.100-4.el9 appstream 60 k perl-File-stat noarch 1.09-483.el9 appstream 17 k perl-FileHandle noarch 2.03-483.el9 appstream 15 k perl-Getopt-Long noarch 1:2.52-4.el9 appstream 61 k perl-Getopt-Std noarch 1.12-483.el9 appstream 15 k perl-HTTP-Tiny noarch 0.076-462.el9 appstream 54 k perl-IO x86_64 1.43-483.el9 appstream 88 k perl-IO-Socket-IP noarch 0.41-5.el9 appstream 43 k perl-IO-Socket-SSL noarch 2.073-2.el9 appstream 217 k perl-IPC-Open3 noarch 1.21-483.el9 appstream 22 k perl-MIME-Base64 x86_64 3.16-4.el9 appstream 31 k perl-Mozilla-CA noarch 20200520-6.el9 appstream 13 k perl-Net-SSLeay x86_64 1.94-3.el9 appstream 414 k perl-POSIX x86_64 1.94-483.el9 appstream 96 k perl-PathTools x86_64 3.78-461.el9 appstream 88 k perl-Pod-Escapes noarch 1:1.07-460.el9 appstream 21 k perl-Pod-Perldoc noarch 3.28.01-461.el9 appstream 87 k perl-Pod-Simple noarch 1:3.42-4.el9 appstream 225 k perl-Pod-Usage noarch 4:2.01-4.el9 appstream 41 k perl-Scalar-List-Utils x86_64 4:1.56-462.el9 appstream 71 k perl-SelectSaver noarch 1.02-483.el9 appstream 11 k perl-Socket x86_64 4:2.031-4.el9 appstream 56 k perl-Storable x86_64 1:3.21-460.el9 appstream 96 k perl-Symbol noarch 1.08-483.el9 appstream 14 k perl-Term-ANSIColor noarch 5.01-461.el9 appstream 49 k perl-Term-Cap noarch 1.17-460.el9 appstream 23 k perl-Text-ParseWords noarch 3.30-460.el9 appstream 17 k perl-Text-Tabs+Wrap noarch 2013.0523-460.el9 appstream 24 k perl-Time-Local noarch 2:1.300-7.el9 appstream 34 k perl-URI noarch 5.09-3.el9 appstream 121 k perl-base noarch 2.27-483.el9 appstream 16 k perl-constant noarch 1.33-461.el9 appstream 24 k perl-if noarch 0.60.800-483.el9 appstream 14 k perl-interpreter x86_64 4:5.32.1-483.el9 appstream 70 k perl-libnet noarch 3.13-4.el9 appstream 130 k perl-libs x86_64 4:5.32.1-483.el9 appstream 2.2 M perl-mro x86_64 1.23-483.el9 appstream 28 k perl-overload noarch 1.31-483.el9 appstream 45 k perl-overloading noarch 0.02-483.el9 appstream 12 k perl-parent noarch 1:0.238-460.el9 appstream 15 k perl-podlators noarch 1:4.14-460.el9 appstream 114 k perl-srpm-macros noarch 1-41.el9 appstream 9.1 k perl-subs noarch 1.03-483.el9 appstream 11 k perl-vars noarch 1.05-483.el9 appstream 13 k pkgconf x86_64 1.7.3-10.el9 baseos 41 k pkgconf-m4 noarch 1.7.3-10.el9 baseos 15 k pkgconf-pkg-config x86_64 1.7.3-10.el9 baseos 11 k popt x86_64 1.18-8.el9 baseos 65 k publicsuffix-list-dafsa noarch 20210518-3.el9 baseos 58 k pyproject-srpm-macros noarch 1.16.2-1.el9 appstream 14 k python-srpm-macros noarch 3.9-54.el9 appstream 18 k qt5-srpm-macros noarch 5.15.9-1.el9 appstream 8.8 k readline x86_64 8.1-4.el9 baseos 212 k rpm x86_64 4.16.1.3-39.el9 baseos 535 k rpm-build-libs x86_64 4.16.1.3-39.el9 baseos 88 k rpm-libs x86_64 4.16.1.3-39.el9 baseos 307 k rust-srpm-macros noarch 17-4.el9 appstream 10 k setup noarch 2.13.7-10.el9 baseos 146 k shadow-utils x86_64 2:4.9-15.el9 baseos 1.2 M sqlite-libs x86_64 3.34.1-8.el9 baseos 643 k systemd-libs x86_64 252-59.el9 baseos 678 k tzdata noarch 2025b-2.el9 baseos 901 k util-linux-core x86_64 2.37.4-21.el9 baseos 465 k xz-libs x86_64 5.2.5-8.el9 baseos 93 k zip x86_64 3.0-35.el9 baseos 266 k zlib x86_64 1.2.11-41.el9 baseos 91 k zstd x86_64 1.5.5-1.el9 baseos 464 k Transaction Summary ================================================================================ Install 203 Packages Total download size: 70 M Installed size: 225 M Downloading Packages: (1/203): basesystem-11-13.el9.noarch.rpm 202 kB/s | 3.9 kB 00:00 (2/203): audit-libs-3.1.5-7.el9.x86_64.rpm 5.6 MB/s | 119 kB 00:00 (3/203): alternatives-1.24-2.el9.x86_64.rpm 1.7 MB/s | 39 kB 00:00 (4/203): binutils-gold-2.35.2-67.el9.x86_64.rpm 55 MB/s | 734 kB 00:00 (5/203): bash-5.1.8-9.el9.x86_64.rpm 79 MB/s | 1.7 MB 00:00 (6/203): binutils-2.35.2-67.el9.x86_64.rpm 186 MB/s | 4.6 MB 00:00 (7/203): bzip2-1.0.8-10.el9.x86_64.rpm 5.6 MB/s | 56 kB 00:00 (8/203): bzip2-libs-1.0.8-10.el9.x86_64.rpm 8.3 MB/s | 40 kB 00:00 (9/203): centos-stream-release-9.0-30.el9.noarc 8.4 MB/s | 24 kB 00:00 (10/203): centos-gpg-keys-9.0-30.el9.noarch.rpm 3.4 MB/s | 13 kB 00:00 (11/203): ca-certificates-2025.2.80_v9.0.305-91 167 MB/s | 1.0 MB 00:00 (12/203): centos-stream-repos-9.0-30.el9.noarch 3.2 MB/s | 9.6 kB 00:00 (13/203): cpio-2.13-16.el9.x86_64.rpm 52 MB/s | 275 kB 00:00 (14/203): coreutils-8.32-39.el9.x86_64.rpm 120 MB/s | 1.2 MB 00:00 (15/203): cracklib-2.9.6-27.el9.x86_64.rpm 27 MB/s | 94 kB 00:00 (16/203): coreutils-common-8.32-39.el9.x86_64.r 164 MB/s | 2.0 MB 00:00 (17/203): crypto-policies-20250905-1.git377cc42 23 MB/s | 90 kB 00:00 (18/203): curl-7.76.1-34.el9.x86_64.rpm 55 MB/s | 292 kB 00:00 (19/203): cyrus-sasl-lib-2.1.27-21.el9.x86_64.r 127 MB/s | 769 kB 00:00 (20/203): cracklib-dicts-2.9.6-27.el9.x86_64.rp 191 MB/s | 3.6 MB 00:00 (21/203): ed-1.14.2-12.el9.x86_64.rpm 11 MB/s | 75 kB 00:00 (22/203): diffutils-3.7-12.el9.x86_64.rpm 43 MB/s | 397 kB 00:00 (23/203): elfutils-debuginfod-client-0.193-1.el 15 MB/s | 44 kB 00:00 (24/203): elfutils-default-yama-scope-0.193-1.e 3.5 MB/s | 9.7 kB 00:00 (25/203): elfutils-0.193-1.el9.x86_64.rpm 114 MB/s | 598 kB 00:00 (26/203): elfutils-libelf-0.193-1.el9.x86_64.rp 64 MB/s | 205 kB 00:00 (27/203): elfutils-libs-0.193-1.el9.x86_64.rpm 75 MB/s | 268 kB 00:00 (28/203): file-5.39-16.el9.x86_64.rpm 15 MB/s | 50 kB 00:00 (29/203): file-libs-5.39-16.el9.x86_64.rpm 133 MB/s | 589 kB 00:00 (30/203): findutils-4.8.0-7.el9.x86_64.rpm 114 MB/s | 547 kB 00:00 (31/203): gdbm-libs-1.23-1.el9.x86_64.rpm 12 MB/s | 56 kB 00:00 (32/203): gawk-5.1.0-6.el9.x86_64.rpm 91 MB/s | 1.0 MB 00:00 (33/203): filesystem-3.16-5.el9.x86_64.rpm 217 MB/s | 4.8 MB 00:00 (34/203): glibc-common-2.34-238.el9.x86_64.rpm 38 MB/s | 307 kB 00:00 (35/203): glibc-2.34-238.el9.x86_64.rpm 138 MB/s | 2.0 MB 00:00 (36/203): glibc-minimal-langpack-2.34-238.el9.x 7.0 MB/s | 22 kB 00:00 (37/203): glibc-gconv-extra-2.34-238.el9.x86_64 172 MB/s | 1.7 MB 00:00 (38/203): gmp-6.2.0-13.el9.x86_64.rpm 55 MB/s | 315 kB 00:00 (39/203): grep-3.6-5.el9.x86_64.rpm 47 MB/s | 269 kB 00:00 (40/203): gzip-1.12-1.el9.x86_64.rpm 47 MB/s | 163 kB 00:00 (41/203): info-6.7-15.el9.x86_64.rpm 42 MB/s | 225 kB 00:00 (42/203): groff-base-1.22.4-10.el9.x86_64.rpm 128 MB/s | 1.1 MB 00:00 (43/203): keyutils-libs-1.6.3-1.el9.x86_64.rpm 8.0 MB/s | 32 kB 00:00 (44/203): json-c-0.14-11.el9.x86_64.rpm 5.7 MB/s | 43 kB 00:00 (45/203): libacl-2.3.1-4.el9.x86_64.rpm 5.8 MB/s | 23 kB 00:00 (46/203): krb5-libs-1.21.1-8.el9.x86_64.rpm 95 MB/s | 766 kB 00:00 (47/203): libarchive-3.5.3-6.el9.x86_64.rpm 69 MB/s | 387 kB 00:00 (48/203): libattr-2.5.1-3.el9.x86_64.rpm 7.4 MB/s | 19 kB 00:00 (49/203): libblkid-2.37.4-21.el9.x86_64.rpm 40 MB/s | 107 kB 00:00 (50/203): libbrotli-1.0.9-7.el9.x86_64.rpm 102 MB/s | 313 kB 00:00 (51/203): libcap-2.48-10.el9.x86_64.rpm 18 MB/s | 70 kB 00:00 (52/203): libcap-ng-0.8.2-7.el9.x86_64.rpm 13 MB/s | 33 kB 00:00 (53/203): libcom_err-1.46.5-8.el9.x86_64.rpm 9.2 MB/s | 26 kB 00:00 (54/203): libcurl-7.76.1-34.el9.x86_64.rpm 55 MB/s | 283 kB 00:00 (55/203): libdb-5.3.28-57.el9.x86_64.rpm 78 MB/s | 735 kB 00:00 (56/203): libeconf-0.4.1-4.el9.x86_64.rpm 2.7 MB/s | 27 kB 00:00 (57/203): libevent-2.1.12-8.el9.x86_64.rpm 33 MB/s | 262 kB 00:00 (58/203): libfdisk-2.37.4-21.el9.x86_64.rpm 24 MB/s | 154 kB 00:00 (59/203): libffi-3.4.2-8.el9.x86_64.rpm 7.1 MB/s | 38 kB 00:00 (60/203): libgcc-11.5.0-11.el9.x86_64.rpm 25 MB/s | 85 kB 00:00 (61/203): libgomp-11.5.0-11.el9.x86_64.rpm 79 MB/s | 258 kB 00:00 (62/203): libgcrypt-1.10.0-11.el9.x86_64.rpm 101 MB/s | 508 kB 00:00 (63/203): libgpg-error-1.42-5.el9.x86_64.rpm 44 MB/s | 216 kB 00:00 (64/203): libidn2-2.3.0-7.el9.x86_64.rpm 16 MB/s | 101 kB 00:00 (65/203): libnghttp2-1.43.0-6.el9.x86_64.rpm 15 MB/s | 73 kB 00:00 (66/203): libmount-2.37.4-21.el9.x86_64.rpm 20 MB/s | 135 kB 00:00 (67/203): libpsl-0.21.1-5.el9.x86_64.rpm 22 MB/s | 64 kB 00:00 (68/203): libpkgconf-1.7.3-10.el9.x86_64.rpm 9.1 MB/s | 36 kB 00:00 (69/203): libpwquality-1.4.4-8.el9.x86_64.rpm 30 MB/s | 119 kB 00:00 (70/203): libselinux-3.6-3.el9.x86_64.rpm 22 MB/s | 86 kB 00:00 (71/203): libsemanage-3.6-5.el9.x86_64.rpm 22 MB/s | 118 kB 00:00 (72/203): libsepol-3.6-3.el9.x86_64.rpm 70 MB/s | 329 kB 00:00 (73/203): libsigsegv-2.13-4.el9.x86_64.rpm 6.4 MB/s | 27 kB 00:00 (74/203): libsmartcols-2.37.4-21.el9.x86_64.rpm 20 MB/s | 63 kB 00:00 (75/203): libssh-0.10.4-15.el9.x86_64.rpm 62 MB/s | 212 kB 00:00 (76/203): libssh-config-0.10.4-15.el9.noarch.rp 2.5 MB/s | 7.7 kB 00:00 (77/203): libtool-ltdl-2.4.6-46.el9.x86_64.rpm 9.2 MB/s | 36 kB 00:00 (78/203): libtasn1-4.16.0-9.el9.x86_64.rpm 15 MB/s | 74 kB 00:00 (79/203): libstdc++-11.5.0-11.el9.x86_64.rpm 91 MB/s | 745 kB 00:00 (80/203): libutempter-1.2.1-6.el9.x86_64.rpm 6.1 MB/s | 27 kB 00:00 (81/203): libunistring-0.9.10-15.el9.x86_64.rpm 81 MB/s | 496 kB 00:00 (82/203): libuuid-2.37.4-21.el9.x86_64.rpm 6.5 MB/s | 28 kB 00:00 (83/203): libverto-0.3.2-3.el9.x86_64.rpm 7.4 MB/s | 22 kB 00:00 (84/203): libxcrypt-4.4.18-3.el9.x86_64.rpm 31 MB/s | 116 kB 00:00 (85/203): libzstd-1.5.5-1.el9.x86_64.rpm 64 MB/s | 295 kB 00:00 (86/203): libxml2-2.9.13-12.el9.x86_64.rpm 95 MB/s | 747 kB 00:00 (87/203): lua-libs-5.4.4-4.el9.x86_64.rpm 26 MB/s | 130 kB 00:00 (88/203): lz4-libs-1.9.3-5.el9.x86_64.rpm 25 MB/s | 68 kB 00:00 (89/203): mpfr-4.1.0-7.el9.x86_64.rpm 59 MB/s | 326 kB 00:00 (90/203): ncurses-6.2-12.20210508.el9.x86_64.rp 72 MB/s | 406 kB 00:00 (91/203): make-4.3-8.el9.x86_64.rpm 65 MB/s | 536 kB 00:00 (92/203): ncurses-base-6.2-12.20210508.el9.noar 28 MB/s | 95 kB 00:00 (93/203): openldap-2.6.8-4.el9.x86_64.rpm 72 MB/s | 285 kB 00:00 (94/203): ncurses-libs-6.2-12.20210508.el9.x86_ 58 MB/s | 328 kB 00:00 (95/203): openssl-fips-provider-3.5.1-6.el9.x86 100 MB/s | 812 kB 00:00 (96/203): openssl-3.5.1-6.el9.x86_64.rpm 117 MB/s | 1.5 MB 00:00 (97/203): openssl-libs-3.5.1-6.el9.x86_64.rpm 169 MB/s | 2.3 MB 00:00 (98/203): p11-kit-trust-0.25.10-1.el9.x86_64.rp 36 MB/s | 151 kB 00:00 (99/203): p11-kit-0.25.10-1.el9.x86_64.rpm 74 MB/s | 561 kB 00:00 (100/203): pam-1.5.1-26.el9.x86_64.rpm 124 MB/s | 622 kB 00:00 (101/203): pcre2-10.40-6.el9.x86_64.rpm 55 MB/s | 234 kB 00:00 (102/203): pcre-8.44-4.el9.x86_64.rpm 34 MB/s | 197 kB 00:00 (103/203): pcre2-syntax-10.40-6.el9.noarch.rpm 49 MB/s | 141 kB 00:00 (104/203): pkgconf-1.7.3-10.el9.x86_64.rpm 16 MB/s | 41 kB 00:00 (105/203): pkgconf-m4-1.7.3-10.el9.noarch.rpm 4.2 MB/s | 15 kB 00:00 (106/203): pkgconf-pkg-config-1.7.3-10.el9.x86_ 5.2 MB/s | 11 kB 00:00 (107/203): popt-1.18-8.el9.x86_64.rpm 24 MB/s | 65 kB 00:00 (108/203): publicsuffix-list-dafsa-20210518-3.e 21 MB/s | 58 kB 00:00 (109/203): readline-8.1-4.el9.x86_64.rpm 57 MB/s | 212 kB 00:00 (110/203): rpm-build-libs-4.16.1.3-39.el9.x86_6 37 MB/s | 88 kB 00:00 (111/203): rpm-4.16.1.3-39.el9.x86_64.rpm 103 MB/s | 535 kB 00:00 (112/203): rpm-libs-4.16.1.3-39.el9.x86_64.rpm 92 MB/s | 307 kB 00:00 (113/203): sed-4.8-9.el9.x86_64.rpm 78 MB/s | 305 kB 00:00 (114/203): setup-2.13.7-10.el9.noarch.rpm 40 MB/s | 146 kB 00:00 (115/203): sqlite-libs-3.34.1-8.el9.x86_64.rpm 72 MB/s | 643 kB 00:00 (116/203): systemd-libs-252-59.el9.x86_64.rpm 75 MB/s | 678 kB 00:00 (117/203): shadow-utils-4.9-15.el9.x86_64.rpm 91 MB/s | 1.2 MB 00:00 (118/203): unzip-6.0-59.el9.x86_64.rpm 73 MB/s | 182 kB 00:00 (119/203): tar-1.34-7.el9.x86_64.rpm 138 MB/s | 885 kB 00:00 (120/203): tzdata-2025b-2.el9.noarch.rpm 113 MB/s | 901 kB 00:00 (121/203): util-linux-core-2.37.4-21.el9.x86_64 98 MB/s | 465 kB 00:00 (122/203): which-2.21-30.el9.x86_64.rpm 13 MB/s | 41 kB 00:00 (123/203): xz-5.2.5-8.el9.x86_64.rpm 70 MB/s | 226 kB 00:00 (124/203): util-linux-2.37.4-21.el9.x86_64.rpm 181 MB/s | 2.3 MB 00:00 (125/203): xz-libs-5.2.5-8.el9.x86_64.rpm 15 MB/s | 93 kB 00:00 (126/203): zip-3.0-35.el9.x86_64.rpm 76 MB/s | 266 kB 00:00 (127/203): zlib-1.2.11-41.el9.x86_64.rpm 20 MB/s | 91 kB 00:00 (128/203): debugedit-5.0-11.el9.x86_64.rpm 20 MB/s | 77 kB 00:00 (129/203): zstd-1.5.5-1.el9.x86_64.rpm 88 MB/s | 464 kB 00:00 (130/203): dwz-0.16-1.el9.x86_64.rpm 51 MB/s | 134 kB 00:00 (131/203): efi-srpm-macros-6-4.el9.noarch.rpm 8.1 MB/s | 21 kB 00:00 (132/203): fonts-srpm-macros-2.0.5-7.el9.1.noar 9.4 MB/s | 28 kB 00:00 (133/203): ghc-srpm-macros-1.5.0-6.el9.noarch.r 3.2 MB/s | 8.8 kB 00:00 (134/203): go-srpm-macros-3.8.1-1.el9.noarch.rp 8.3 MB/s | 27 kB 00:00 (135/203): kernel-srpm-macros-1.0-14.el9.noarch 4.7 MB/s | 14 kB 00:00 (136/203): lua-srpm-macros-1-6.el9.noarch.rpm 2.7 MB/s | 9.5 kB 00:00 (137/203): ocaml-srpm-macros-6-6.el9.noarch.rpm 1.5 MB/s | 8.8 kB 00:00 (138/203): openblas-srpm-macros-2-11.el9.noarch 2.0 MB/s | 8.4 kB 00:00 (139/203): patch-2.7.6-16.el9.x86_64.rpm 21 MB/s | 128 kB 00:00 (140/203): gdb-minimal-16.3-2.el9.x86_64.rpm 190 MB/s | 4.4 MB 00:00 (141/203): perl-AutoLoader-5.74-483.el9.noarch. 2.0 MB/s | 21 kB 00:00 (142/203): perl-B-1.80-483.el9.x86_64.rpm 32 MB/s | 180 kB 00:00 (143/203): perl-Carp-1.50-460.el9.noarch.rpm 12 MB/s | 30 kB 00:00 (144/203): perl-Class-Struct-0.66-483.el9.noarc 9.4 MB/s | 22 kB 00:00 (145/203): perl-Data-Dumper-2.174-462.el9.x86_6 20 MB/s | 56 kB 00:00 (146/203): perl-Digest-1.19-4.el9.noarch.rpm 12 MB/s | 26 kB 00:00 (147/203): perl-Digest-MD5-2.58-4.el9.x86_64.rp 16 MB/s | 37 kB 00:00 (148/203): perl-Errno-1.30-483.el9.x86_64.rpm 5.2 MB/s | 15 kB 00:00 (149/203): perl-Exporter-5.74-461.el9.noarch.rp 12 MB/s | 32 kB 00:00 (150/203): perl-Encode-3.08-462.el9.x86_64.rpm 180 MB/s | 1.7 MB 00:00 (151/203): perl-Fcntl-1.13-483.el9.x86_64.rpm 4.0 MB/s | 20 kB 00:00 (152/203): perl-File-Basename-2.85-483.el9.noar 3.3 MB/s | 17 kB 00:00 (153/203): perl-File-Path-2.18-4.el9.noarch.rpm 14 MB/s | 36 kB 00:00 (154/203): perl-File-stat-1.09-483.el9.noarch.r 5.7 MB/s | 17 kB 00:00 (155/203): perl-File-Temp-0.231.100-4.el9.noarc 17 MB/s | 60 kB 00:00 (156/203): perl-FileHandle-2.03-483.el9.noarch. 7.4 MB/s | 15 kB 00:00 (157/203): perl-Getopt-Long-2.52-4.el9.noarch.r 22 MB/s | 61 kB 00:00 (158/203): perl-Getopt-Std-1.12-483.el9.noarch. 5.5 MB/s | 15 kB 00:00 (159/203): perl-HTTP-Tiny-0.076-462.el9.noarch. 20 MB/s | 54 kB 00:00 (160/203): perl-IO-Socket-IP-0.41-5.el9.noarch. 22 MB/s | 43 kB 00:00 (161/203): perl-IO-1.43-483.el9.x86_64.rpm 32 MB/s | 88 kB 00:00 (162/203): perl-IO-Socket-SSL-2.073-2.el9.noarc 73 MB/s | 217 kB 00:00 (163/203): perl-MIME-Base64-3.16-4.el9.x86_64.r 14 MB/s | 31 kB 00:00 (164/203): perl-IPC-Open3-1.21-483.el9.noarch.r 7.1 MB/s | 22 kB 00:00 (165/203): perl-Mozilla-CA-20200520-6.el9.noarc 6.7 MB/s | 13 kB 00:00 (166/203): perl-POSIX-1.94-483.el9.x86_64.rpm 39 MB/s | 96 kB 00:00 (167/203): perl-Net-SSLeay-1.94-3.el9.x86_64.rp 104 MB/s | 414 kB 00:00 (168/203): perl-PathTools-3.78-461.el9.x86_64.r 25 MB/s | 88 kB 00:00 (169/203): perl-Pod-Escapes-1.07-460.el9.noarch 6.3 MB/s | 21 kB 00:00 (170/203): perl-Pod-Perldoc-3.28.01-461.el9.noa 28 MB/s | 87 kB 00:00 (171/203): perl-Pod-Simple-3.42-4.el9.noarch.rp 65 MB/s | 225 kB 00:00 (172/203): perl-Pod-Usage-2.01-4.el9.noarch.rpm 15 MB/s | 41 kB 00:00 (173/203): perl-Scalar-List-Utils-1.56-462.el9. 25 MB/s | 71 kB 00:00 (174/203): perl-SelectSaver-1.02-483.el9.noarch 5.3 MB/s | 11 kB 00:00 (175/203): perl-Socket-2.031-4.el9.x86_64.rpm 22 MB/s | 56 kB 00:00 (176/203): perl-Symbol-1.08-483.el9.noarch.rpm 6.2 MB/s | 14 kB 00:00 (177/203): perl-Storable-3.21-460.el9.x86_64.rp 31 MB/s | 96 kB 00:00 (178/203): perl-Term-ANSIColor-5.01-461.el9.noa 18 MB/s | 49 kB 00:00 (179/203): perl-Text-ParseWords-3.30-460.el9.no 7.0 MB/s | 17 kB 00:00 (180/203): perl-Term-Cap-1.17-460.el9.noarch.rp 7.3 MB/s | 23 kB 00:00 (181/203): perl-Text-Tabs+Wrap-2013.0523-460.el 12 MB/s | 24 kB 00:00 (182/203): perl-Time-Local-1.300-7.el9.noarch.r 12 MB/s | 34 kB 00:00 (183/203): perl-URI-5.09-3.el9.noarch.rpm 36 MB/s | 121 kB 00:00 (184/203): perl-base-2.27-483.el9.noarch.rpm 5.6 MB/s | 16 kB 00:00 (185/203): perl-constant-1.33-461.el9.noarch.rp 12 MB/s | 24 kB 00:00 (186/203): perl-if-0.60.800-483.el9.noarch.rpm 7.0 MB/s | 14 kB 00:00 (187/203): perl-interpreter-5.32.1-483.el9.x86_ 26 MB/s | 70 kB 00:00 (188/203): perl-libnet-3.13-4.el9.noarch.rpm 48 MB/s | 130 kB 00:00 (189/203): perl-mro-1.23-483.el9.x86_64.rpm 13 MB/s | 28 kB 00:00 (190/203): perl-overload-1.31-483.el9.noarch.rp 19 MB/s | 45 kB 00:00 (191/203): perl-overloading-0.02-483.el9.noarch 5.8 MB/s | 12 kB 00:00 (192/203): perl-parent-0.238-460.el9.noarch.rpm 7.0 MB/s | 15 kB 00:00 (193/203): perl-libs-5.32.1-483.el9.x86_64.rpm 212 MB/s | 2.2 MB 00:00 (194/203): perl-podlators-4.14-460.el9.noarch.r 21 MB/s | 114 kB 00:00 (195/203): perl-srpm-macros-1-41.el9.noarch.rpm 2.4 MB/s | 9.1 kB 00:00 (196/203): perl-subs-1.03-483.el9.noarch.rpm 5.9 MB/s | 11 kB 00:00 (197/203): perl-vars-1.05-483.el9.noarch.rpm 5.3 MB/s | 13 kB 00:00 (198/203): pyproject-srpm-macros-1.16.2-1.el9.n 4.3 MB/s | 14 kB 00:00 (199/203): qt5-srpm-macros-5.15.9-1.el9.noarch. 1.4 MB/s | 8.8 kB 00:00 (200/203): python-srpm-macros-3.9-54.el9.noarch 2.3 MB/s | 18 kB 00:00 (201/203): redhat-rpm-config-210-1.el9.noarch.r 11 MB/s | 70 kB 00:00 (202/203): rpm-build-4.16.1.3-39.el9.x86_64.rpm 27 MB/s | 66 kB 00:00 (203/203): rust-srpm-macros-17-4.el9.noarch.rpm 3.9 MB/s | 10 kB 00:00 -------------------------------------------------------------------------------- Total 112 MB/s | 70 MB 00:00 CentOS Stream 9 - BaseOS 1.6 MB/s | 1.6 kB 00:00 Importing GPG key 0x8483C65D: Userid : "CentOS (CentOS Official Signing Key) " Fingerprint: 99DB 70FA E1D7 CE22 7FB6 4882 05B5 55B3 8483 C65D From : /usr/share/distribution-gpg-keys/centos/RPM-GPG-KEY-CentOS-Official Key imported successfully Running transaction check Transaction check succeeded. Running transaction test Transaction test succeeded. Running transaction Running scriptlet: filesystem-3.16-5.el9.x86_64 1/1 Preparing : 1/1 Installing : rust-srpm-macros-17-4.el9.noarch 1/203 Installing : qt5-srpm-macros-5.15.9-1.el9.noarch 2/203 Installing : perl-srpm-macros-1-41.el9.noarch 3/203 Installing : openblas-srpm-macros-2-11.el9.noarch 4/203 Installing : ocaml-srpm-macros-6-6.el9.noarch 5/203 Installing : ghc-srpm-macros-1.5.0-6.el9.noarch 6/203 Installing : tzdata-2025b-2.el9.noarch 7/203 Installing : publicsuffix-list-dafsa-20210518-3.el9.noarch 8/203 Installing : pkgconf-m4-1.7.3-10.el9.noarch 9/203 Installing : pcre2-syntax-10.40-6.el9.noarch 10/203 Installing : ncurses-base-6.2-12.20210508.el9.noarch 11/203 Installing : libssh-config-0.10.4-15.el9.noarch 12/203 Installing : coreutils-common-8.32-39.el9.x86_64 13/203 Installing : centos-gpg-keys-9.0-30.el9.noarch 14/203 Installing : centos-stream-repos-9.0-30.el9.noarch 15/203 Installing : centos-stream-release-9.0-30.el9.noarch 16/203 Installing : setup-2.13.7-10.el9.noarch 17/203 warning: /etc/hosts created as /etc/hosts.rpmnew Running scriptlet: setup-2.13.7-10.el9.noarch 17/203 Installing : filesystem-3.16-5.el9.x86_64 18/203 Installing : basesystem-11-13.el9.noarch 19/203 Installing : ncurses-libs-6.2-12.20210508.el9.x86_64 20/203 Installing : bash-5.1.8-9.el9.x86_64 21/203 Running scriptlet: bash-5.1.8-9.el9.x86_64 21/203 Installing : libgcc-11.5.0-11.el9.x86_64 22/203 Running scriptlet: libgcc-11.5.0-11.el9.x86_64 22/203 Installing : glibc-gconv-extra-2.34-238.el9.x86_64 23/203 Running scriptlet: glibc-gconv-extra-2.34-238.el9.x86_64 23/203 Installing : glibc-minimal-langpack-2.34-238.el9.x86_64 24/203 Installing : glibc-common-2.34-238.el9.x86_64 25/203 Running scriptlet: glibc-2.34-238.el9.x86_64 26/203 Installing : glibc-2.34-238.el9.x86_64 26/203 Running scriptlet: glibc-2.34-238.el9.x86_64 26/203 Installing : zlib-1.2.11-41.el9.x86_64 27/203 Installing : xz-libs-5.2.5-8.el9.x86_64 28/203 Installing : bzip2-libs-1.0.8-10.el9.x86_64 29/203 Installing : libzstd-1.5.5-1.el9.x86_64 30/203 Installing : elfutils-libelf-0.193-1.el9.x86_64 31/203 Installing : libstdc++-11.5.0-11.el9.x86_64 32/203 Installing : libxcrypt-4.4.18-3.el9.x86_64 33/203 Installing : libuuid-2.37.4-21.el9.x86_64 34/203 Installing : gmp-1:6.2.0-13.el9.x86_64 35/203 Installing : libattr-2.5.1-3.el9.x86_64 36/203 Installing : libacl-2.3.1-4.el9.x86_64 37/203 Installing : libcap-2.48-10.el9.x86_64 38/203 Installing : popt-1.18-8.el9.x86_64 39/203 Installing : libcom_err-1.46.5-8.el9.x86_64 40/203 Installing : lz4-libs-1.9.3-5.el9.x86_64 41/203 Installing : readline-8.1-4.el9.x86_64 42/203 Installing : crypto-policies-20250905-1.git377cc42.el9.noarch 43/203 Running scriptlet: crypto-policies-20250905-1.git377cc42.el9.noarch 43/203 Installing : mpfr-4.1.0-7.el9.x86_64 44/203 Installing : dwz-0.16-1.el9.x86_64 45/203 Installing : unzip-6.0-59.el9.x86_64 46/203 Installing : file-libs-5.39-16.el9.x86_64 47/203 Installing : file-5.39-16.el9.x86_64 48/203 Installing : sqlite-libs-3.34.1-8.el9.x86_64 49/203 Installing : alternatives-1.24-2.el9.x86_64 50/203 Installing : libcap-ng-0.8.2-7.el9.x86_64 51/203 Installing : audit-libs-3.1.5-7.el9.x86_64 52/203 Installing : libffi-3.4.2-8.el9.x86_64 53/203 Installing : libsepol-3.6-3.el9.x86_64 54/203 Installing : libsigsegv-2.13-4.el9.x86_64 55/203 Installing : gawk-5.1.0-6.el9.x86_64 56/203 Installing : libsmartcols-2.37.4-21.el9.x86_64 57/203 Installing : libtasn1-4.16.0-9.el9.x86_64 58/203 Installing : p11-kit-0.25.10-1.el9.x86_64 59/203 Installing : libunistring-0.9.10-15.el9.x86_64 60/203 Installing : libidn2-2.3.0-7.el9.x86_64 61/203 Installing : lua-libs-5.4.4-4.el9.x86_64 62/203 Installing : libpsl-0.21.1-5.el9.x86_64 63/203 Installing : p11-kit-trust-0.25.10-1.el9.x86_64 64/203 Running scriptlet: p11-kit-trust-0.25.10-1.el9.x86_64 64/203 Installing : zip-3.0-35.el9.x86_64 65/203 Installing : zstd-1.5.5-1.el9.x86_64 66/203 Running scriptlet: groff-base-1.22.4-10.el9.x86_64 67/203 Installing : groff-base-1.22.4-10.el9.x86_64 67/203 Running scriptlet: groff-base-1.22.4-10.el9.x86_64 67/203 Installing : bzip2-1.0.8-10.el9.x86_64 68/203 Installing : libxml2-2.9.13-12.el9.x86_64 69/203 Installing : info-6.7-15.el9.x86_64 70/203 Installing : ed-1.14.2-12.el9.x86_64 71/203 Installing : cpio-2.13-16.el9.x86_64 72/203 Installing : diffutils-3.7-12.el9.x86_64 73/203 Installing : gdbm-libs-1:1.23-1.el9.x86_64 74/203 Installing : json-c-0.14-11.el9.x86_64 75/203 Installing : keyutils-libs-1.6.3-1.el9.x86_64 76/203 Installing : libbrotli-1.0.9-7.el9.x86_64 77/203 Installing : libdb-5.3.28-57.el9.x86_64 78/203 Installing : libeconf-0.4.1-4.el9.x86_64 79/203 Installing : libgomp-11.5.0-11.el9.x86_64 80/203 Installing : libgpg-error-1.42-5.el9.x86_64 81/203 Installing : libgcrypt-1.10.0-11.el9.x86_64 82/203 Installing : libnghttp2-1.43.0-6.el9.x86_64 83/203 Installing : libpkgconf-1.7.3-10.el9.x86_64 84/203 Installing : pkgconf-1.7.3-10.el9.x86_64 85/203 Installing : pkgconf-pkg-config-1.7.3-10.el9.x86_64 86/203 Installing : libtool-ltdl-2.4.6-46.el9.x86_64 87/203 Installing : libverto-0.3.2-3.el9.x86_64 88/203 Installing : ncurses-6.2-12.20210508.el9.x86_64 89/203 Installing : pcre-8.44-4.el9.x86_64 90/203 Installing : grep-3.6-5.el9.x86_64 91/203 Installing : xz-5.2.5-8.el9.x86_64 92/203 Installing : pcre2-10.40-6.el9.x86_64 93/203 Installing : libselinux-3.6-3.el9.x86_64 94/203 Installing : sed-4.8-9.el9.x86_64 95/203 Installing : findutils-1:4.8.0-7.el9.x86_64 96/203 Installing : openssl-fips-provider-1:3.5.1-6.el9.x86_64 97/203 Installing : openssl-libs-1:3.5.1-6.el9.x86_64 98/203 Installing : coreutils-8.32-39.el9.x86_64 99/203 Running scriptlet: ca-certificates-2025.2.80_v9.0.305-91.el9.noarch 100/203 Installing : ca-certificates-2025.2.80_v9.0.305-91.el9.noarch 100/203 Running scriptlet: ca-certificates-2025.2.80_v9.0.305-91.el9.noarch 100/203 Installing : libblkid-2.37.4-21.el9.x86_64 101/203 Running scriptlet: libblkid-2.37.4-21.el9.x86_64 101/203 Installing : krb5-libs-1.21.1-8.el9.x86_64 102/203 Installing : libmount-2.37.4-21.el9.x86_64 103/203 Installing : gzip-1.12-1.el9.x86_64 104/203 Installing : cracklib-2.9.6-27.el9.x86_64 105/203 Installing : systemd-libs-252-59.el9.x86_64 106/203 Running scriptlet: systemd-libs-252-59.el9.x86_64 106/203 Installing : libarchive-3.5.3-6.el9.x86_64 107/203 Installing : util-linux-core-2.37.4-21.el9.x86_64 108/203 Running scriptlet: util-linux-core-2.37.4-21.el9.x86_64 108/203 Installing : cracklib-dicts-2.9.6-27.el9.x86_64 109/203 Installing : cyrus-sasl-lib-2.1.27-21.el9.x86_64 110/203 Installing : libssh-0.10.4-15.el9.x86_64 111/203 Installing : libfdisk-2.37.4-21.el9.x86_64 112/203 Installing : perl-Digest-1.19-4.el9.noarch 113/203 Installing : perl-Digest-MD5-2.58-4.el9.x86_64 114/203 Installing : perl-B-1.80-483.el9.x86_64 115/203 Installing : perl-FileHandle-2.03-483.el9.noarch 116/203 Installing : perl-Data-Dumper-2.174-462.el9.x86_64 117/203 Installing : perl-libnet-3.13-4.el9.noarch 118/203 Installing : perl-AutoLoader-5.74-483.el9.noarch 119/203 Installing : perl-base-2.27-483.el9.noarch 120/203 Installing : perl-URI-5.09-3.el9.noarch 121/203 Installing : perl-if-0.60.800-483.el9.noarch 122/203 Installing : perl-IO-Socket-IP-0.41-5.el9.noarch 123/203 Installing : perl-Time-Local-2:1.300-7.el9.noarch 124/203 Installing : perl-File-Path-2.18-4.el9.noarch 125/203 Installing : perl-IO-Socket-SSL-2.073-2.el9.noarch 126/203 Installing : perl-Net-SSLeay-1.94-3.el9.x86_64 127/203 Installing : perl-Pod-Escapes-1:1.07-460.el9.noarch 128/203 Installing : perl-Text-Tabs+Wrap-2013.0523-460.el9.noarch 129/203 Installing : perl-Mozilla-CA-20200520-6.el9.noarch 130/203 Installing : perl-Class-Struct-0.66-483.el9.noarch 131/203 Installing : perl-POSIX-1.94-483.el9.x86_64 132/203 Installing : perl-Term-ANSIColor-5.01-461.el9.noarch 133/203 Installing : perl-IPC-Open3-1.21-483.el9.noarch 134/203 Installing : perl-subs-1.03-483.el9.noarch 135/203 Installing : perl-File-Temp-1:0.231.100-4.el9.noarch 136/203 Installing : perl-Term-Cap-1.17-460.el9.noarch 137/203 Installing : perl-Pod-Simple-1:3.42-4.el9.noarch 138/203 Installing : perl-HTTP-Tiny-0.076-462.el9.noarch 139/203 Installing : perl-Socket-4:2.031-4.el9.x86_64 140/203 Installing : perl-SelectSaver-1.02-483.el9.noarch 141/203 Installing : perl-Symbol-1.08-483.el9.noarch 142/203 Installing : perl-File-stat-1.09-483.el9.noarch 143/203 Installing : perl-podlators-1:4.14-460.el9.noarch 144/203 Installing : perl-Pod-Perldoc-3.28.01-461.el9.noarch 145/203 Installing : perl-Fcntl-1.13-483.el9.x86_64 146/203 Installing : perl-Text-ParseWords-3.30-460.el9.noarch 147/203 Installing : perl-mro-1.23-483.el9.x86_64 148/203 Installing : perl-IO-1.43-483.el9.x86_64 149/203 Installing : perl-overloading-0.02-483.el9.noarch 150/203 Installing : perl-Pod-Usage-4:2.01-4.el9.noarch 151/203 Installing : perl-Errno-1.30-483.el9.x86_64 152/203 Installing : perl-File-Basename-2.85-483.el9.noarch 153/203 Installing : perl-Getopt-Std-1.12-483.el9.noarch 154/203 Installing : perl-MIME-Base64-3.16-4.el9.x86_64 155/203 Installing : perl-Scalar-List-Utils-4:1.56-462.el9.x86_64 156/203 Installing : perl-constant-1.33-461.el9.noarch 157/203 Installing : perl-Storable-1:3.21-460.el9.x86_64 158/203 Installing : perl-overload-1.31-483.el9.noarch 159/203 Installing : perl-parent-1:0.238-460.el9.noarch 160/203 Installing : perl-vars-1.05-483.el9.noarch 161/203 Installing : perl-Getopt-Long-1:2.52-4.el9.noarch 162/203 Installing : perl-Carp-1.50-460.el9.noarch 163/203 Installing : perl-Exporter-5.74-461.el9.noarch 164/203 Installing : perl-PathTools-3.78-461.el9.x86_64 165/203 Installing : perl-Encode-4:3.08-462.el9.x86_64 166/203 Installing : perl-libs-4:5.32.1-483.el9.x86_64 167/203 Installing : perl-interpreter-4:5.32.1-483.el9.x86_64 168/203 Installing : kernel-srpm-macros-1.0-14.el9.noarch 169/203 Installing : openssl-1:3.5.1-6.el9.x86_64 170/203 Installing : libpwquality-1.4.4-8.el9.x86_64 171/203 Installing : pam-1.5.1-26.el9.x86_64 172/203 Installing : libevent-2.1.12-8.el9.x86_64 173/203 Installing : libsemanage-3.6-5.el9.x86_64 174/203 Installing : shadow-utils-2:4.9-15.el9.x86_64 175/203 Running scriptlet: libutempter-1.2.1-6.el9.x86_64 176/203 Installing : libutempter-1.2.1-6.el9.x86_64 176/203 Installing : openldap-2.6.8-4.el9.x86_64 177/203 Installing : libcurl-7.76.1-34.el9.x86_64 178/203 Installing : curl-7.76.1-34.el9.x86_64 179/203 Installing : rpm-4.16.1.3-39.el9.x86_64 180/203 Installing : rpm-libs-4.16.1.3-39.el9.x86_64 181/203 Installing : efi-srpm-macros-6-4.el9.noarch 182/203 Installing : lua-srpm-macros-1-6.el9.noarch 183/203 Installing : tar-2:1.34-7.el9.x86_64 184/203 Installing : patch-2.7.6-16.el9.x86_64 185/203 Installing : elfutils-default-yama-scope-0.193-1.el9.noarch 186/203 Running scriptlet: elfutils-default-yama-scope-0.193-1.el9.noarch 186/203 Installing : elfutils-libs-0.193-1.el9.x86_64 187/203 Installing : elfutils-debuginfod-client-0.193-1.el9.x86_64 188/203 Installing : binutils-gold-2.35.2-67.el9.x86_64 189/203 Installing : binutils-2.35.2-67.el9.x86_64 190/203 Running scriptlet: binutils-2.35.2-67.el9.x86_64 190/203 Installing : elfutils-0.193-1.el9.x86_64 191/203 Installing : gdb-minimal-16.3-2.el9.x86_64 192/203 Installing : debugedit-5.0-11.el9.x86_64 193/203 Installing : rpm-build-libs-4.16.1.3-39.el9.x86_64 194/203 Installing : fonts-srpm-macros-1:2.0.5-7.el9.1.noarch 195/203 Installing : go-srpm-macros-3.8.1-1.el9.noarch 196/203 Installing : python-srpm-macros-3.9-54.el9.noarch 197/203 Installing : pyproject-srpm-macros-1.16.2-1.el9.noarch 198/203 Installing : redhat-rpm-config-210-1.el9.noarch 199/203 Installing : rpm-build-4.16.1.3-39.el9.x86_64 200/203 Installing : util-linux-2.37.4-21.el9.x86_64 201/203 Installing : make-1:4.3-8.el9.x86_64 202/203 Installing : which-2.21-30.el9.x86_64 203/203 Running scriptlet: filesystem-3.16-5.el9.x86_64 203/203 Running scriptlet: ca-certificates-2025.2.80_v9.0.305-91.el9.noarch 203/203 Running scriptlet: rpm-4.16.1.3-39.el9.x86_64 203/203 Running scriptlet: which-2.21-30.el9.x86_64 203/203 Verifying : alternatives-1.24-2.el9.x86_64 1/203 Verifying : audit-libs-3.1.5-7.el9.x86_64 2/203 Verifying : basesystem-11-13.el9.noarch 3/203 Verifying : bash-5.1.8-9.el9.x86_64 4/203 Verifying : binutils-2.35.2-67.el9.x86_64 5/203 Verifying : binutils-gold-2.35.2-67.el9.x86_64 6/203 Verifying : bzip2-1.0.8-10.el9.x86_64 7/203 Verifying : bzip2-libs-1.0.8-10.el9.x86_64 8/203 Verifying : ca-certificates-2025.2.80_v9.0.305-91.el9.noarch 9/203 Verifying : centos-gpg-keys-9.0-30.el9.noarch 10/203 Verifying : centos-stream-release-9.0-30.el9.noarch 11/203 Verifying : centos-stream-repos-9.0-30.el9.noarch 12/203 Verifying : coreutils-8.32-39.el9.x86_64 13/203 Verifying : coreutils-common-8.32-39.el9.x86_64 14/203 Verifying : cpio-2.13-16.el9.x86_64 15/203 Verifying : cracklib-2.9.6-27.el9.x86_64 16/203 Verifying : cracklib-dicts-2.9.6-27.el9.x86_64 17/203 Verifying : crypto-policies-20250905-1.git377cc42.el9.noarch 18/203 Verifying : curl-7.76.1-34.el9.x86_64 19/203 Verifying : cyrus-sasl-lib-2.1.27-21.el9.x86_64 20/203 Verifying : diffutils-3.7-12.el9.x86_64 21/203 Verifying : ed-1.14.2-12.el9.x86_64 22/203 Verifying : elfutils-0.193-1.el9.x86_64 23/203 Verifying : elfutils-debuginfod-client-0.193-1.el9.x86_64 24/203 Verifying : elfutils-default-yama-scope-0.193-1.el9.noarch 25/203 Verifying : elfutils-libelf-0.193-1.el9.x86_64 26/203 Verifying : elfutils-libs-0.193-1.el9.x86_64 27/203 Verifying : file-5.39-16.el9.x86_64 28/203 Verifying : file-libs-5.39-16.el9.x86_64 29/203 Verifying : filesystem-3.16-5.el9.x86_64 30/203 Verifying : findutils-1:4.8.0-7.el9.x86_64 31/203 Verifying : gawk-5.1.0-6.el9.x86_64 32/203 Verifying : gdbm-libs-1:1.23-1.el9.x86_64 33/203 Verifying : glibc-2.34-238.el9.x86_64 34/203 Verifying : glibc-common-2.34-238.el9.x86_64 35/203 Verifying : glibc-gconv-extra-2.34-238.el9.x86_64 36/203 Verifying : glibc-minimal-langpack-2.34-238.el9.x86_64 37/203 Verifying : gmp-1:6.2.0-13.el9.x86_64 38/203 Verifying : grep-3.6-5.el9.x86_64 39/203 Verifying : groff-base-1.22.4-10.el9.x86_64 40/203 Verifying : gzip-1.12-1.el9.x86_64 41/203 Verifying : info-6.7-15.el9.x86_64 42/203 Verifying : json-c-0.14-11.el9.x86_64 43/203 Verifying : keyutils-libs-1.6.3-1.el9.x86_64 44/203 Verifying : krb5-libs-1.21.1-8.el9.x86_64 45/203 Verifying : libacl-2.3.1-4.el9.x86_64 46/203 Verifying : libarchive-3.5.3-6.el9.x86_64 47/203 Verifying : libattr-2.5.1-3.el9.x86_64 48/203 Verifying : libblkid-2.37.4-21.el9.x86_64 49/203 Verifying : libbrotli-1.0.9-7.el9.x86_64 50/203 Verifying : libcap-2.48-10.el9.x86_64 51/203 Verifying : libcap-ng-0.8.2-7.el9.x86_64 52/203 Verifying : libcom_err-1.46.5-8.el9.x86_64 53/203 Verifying : libcurl-7.76.1-34.el9.x86_64 54/203 Verifying : libdb-5.3.28-57.el9.x86_64 55/203 Verifying : libeconf-0.4.1-4.el9.x86_64 56/203 Verifying : libevent-2.1.12-8.el9.x86_64 57/203 Verifying : libfdisk-2.37.4-21.el9.x86_64 58/203 Verifying : libffi-3.4.2-8.el9.x86_64 59/203 Verifying : libgcc-11.5.0-11.el9.x86_64 60/203 Verifying : libgcrypt-1.10.0-11.el9.x86_64 61/203 Verifying : libgomp-11.5.0-11.el9.x86_64 62/203 Verifying : libgpg-error-1.42-5.el9.x86_64 63/203 Verifying : libidn2-2.3.0-7.el9.x86_64 64/203 Verifying : libmount-2.37.4-21.el9.x86_64 65/203 Verifying : libnghttp2-1.43.0-6.el9.x86_64 66/203 Verifying : libpkgconf-1.7.3-10.el9.x86_64 67/203 Verifying : libpsl-0.21.1-5.el9.x86_64 68/203 Verifying : libpwquality-1.4.4-8.el9.x86_64 69/203 Verifying : libselinux-3.6-3.el9.x86_64 70/203 Verifying : libsemanage-3.6-5.el9.x86_64 71/203 Verifying : libsepol-3.6-3.el9.x86_64 72/203 Verifying : libsigsegv-2.13-4.el9.x86_64 73/203 Verifying : libsmartcols-2.37.4-21.el9.x86_64 74/203 Verifying : libssh-0.10.4-15.el9.x86_64 75/203 Verifying : libssh-config-0.10.4-15.el9.noarch 76/203 Verifying : libstdc++-11.5.0-11.el9.x86_64 77/203 Verifying : libtasn1-4.16.0-9.el9.x86_64 78/203 Verifying : libtool-ltdl-2.4.6-46.el9.x86_64 79/203 Verifying : libunistring-0.9.10-15.el9.x86_64 80/203 Verifying : libutempter-1.2.1-6.el9.x86_64 81/203 Verifying : libuuid-2.37.4-21.el9.x86_64 82/203 Verifying : libverto-0.3.2-3.el9.x86_64 83/203 Verifying : libxcrypt-4.4.18-3.el9.x86_64 84/203 Verifying : libxml2-2.9.13-12.el9.x86_64 85/203 Verifying : libzstd-1.5.5-1.el9.x86_64 86/203 Verifying : lua-libs-5.4.4-4.el9.x86_64 87/203 Verifying : lz4-libs-1.9.3-5.el9.x86_64 88/203 Verifying : make-1:4.3-8.el9.x86_64 89/203 Verifying : mpfr-4.1.0-7.el9.x86_64 90/203 Verifying : ncurses-6.2-12.20210508.el9.x86_64 91/203 Verifying : ncurses-base-6.2-12.20210508.el9.noarch 92/203 Verifying : ncurses-libs-6.2-12.20210508.el9.x86_64 93/203 Verifying : openldap-2.6.8-4.el9.x86_64 94/203 Verifying : openssl-1:3.5.1-6.el9.x86_64 95/203 Verifying : openssl-fips-provider-1:3.5.1-6.el9.x86_64 96/203 Verifying : openssl-libs-1:3.5.1-6.el9.x86_64 97/203 Verifying : p11-kit-0.25.10-1.el9.x86_64 98/203 Verifying : p11-kit-trust-0.25.10-1.el9.x86_64 99/203 Verifying : pam-1.5.1-26.el9.x86_64 100/203 Verifying : pcre-8.44-4.el9.x86_64 101/203 Verifying : pcre2-10.40-6.el9.x86_64 102/203 Verifying : pcre2-syntax-10.40-6.el9.noarch 103/203 Verifying : pkgconf-1.7.3-10.el9.x86_64 104/203 Verifying : pkgconf-m4-1.7.3-10.el9.noarch 105/203 Verifying : pkgconf-pkg-config-1.7.3-10.el9.x86_64 106/203 Verifying : popt-1.18-8.el9.x86_64 107/203 Verifying : publicsuffix-list-dafsa-20210518-3.el9.noarch 108/203 Verifying : readline-8.1-4.el9.x86_64 109/203 Verifying : rpm-4.16.1.3-39.el9.x86_64 110/203 Verifying : rpm-build-libs-4.16.1.3-39.el9.x86_64 111/203 Verifying : rpm-libs-4.16.1.3-39.el9.x86_64 112/203 Verifying : sed-4.8-9.el9.x86_64 113/203 Verifying : setup-2.13.7-10.el9.noarch 114/203 Verifying : shadow-utils-2:4.9-15.el9.x86_64 115/203 Verifying : sqlite-libs-3.34.1-8.el9.x86_64 116/203 Verifying : systemd-libs-252-59.el9.x86_64 117/203 Verifying : tar-2:1.34-7.el9.x86_64 118/203 Verifying : tzdata-2025b-2.el9.noarch 119/203 Verifying : unzip-6.0-59.el9.x86_64 120/203 Verifying : util-linux-2.37.4-21.el9.x86_64 121/203 Verifying : util-linux-core-2.37.4-21.el9.x86_64 122/203 Verifying : which-2.21-30.el9.x86_64 123/203 Verifying : xz-5.2.5-8.el9.x86_64 124/203 Verifying : xz-libs-5.2.5-8.el9.x86_64 125/203 Verifying : zip-3.0-35.el9.x86_64 126/203 Verifying : zlib-1.2.11-41.el9.x86_64 127/203 Verifying : zstd-1.5.5-1.el9.x86_64 128/203 Verifying : debugedit-5.0-11.el9.x86_64 129/203 Verifying : dwz-0.16-1.el9.x86_64 130/203 Verifying : efi-srpm-macros-6-4.el9.noarch 131/203 Verifying : fonts-srpm-macros-1:2.0.5-7.el9.1.noarch 132/203 Verifying : gdb-minimal-16.3-2.el9.x86_64 133/203 Verifying : ghc-srpm-macros-1.5.0-6.el9.noarch 134/203 Verifying : go-srpm-macros-3.8.1-1.el9.noarch 135/203 Verifying : kernel-srpm-macros-1.0-14.el9.noarch 136/203 Verifying : lua-srpm-macros-1-6.el9.noarch 137/203 Verifying : ocaml-srpm-macros-6-6.el9.noarch 138/203 Verifying : openblas-srpm-macros-2-11.el9.noarch 139/203 Verifying : patch-2.7.6-16.el9.x86_64 140/203 Verifying : perl-AutoLoader-5.74-483.el9.noarch 141/203 Verifying : perl-B-1.80-483.el9.x86_64 142/203 Verifying : perl-Carp-1.50-460.el9.noarch 143/203 Verifying : perl-Class-Struct-0.66-483.el9.noarch 144/203 Verifying : perl-Data-Dumper-2.174-462.el9.x86_64 145/203 Verifying : perl-Digest-1.19-4.el9.noarch 146/203 Verifying : perl-Digest-MD5-2.58-4.el9.x86_64 147/203 Verifying : perl-Encode-4:3.08-462.el9.x86_64 148/203 Verifying : perl-Errno-1.30-483.el9.x86_64 149/203 Verifying : perl-Exporter-5.74-461.el9.noarch 150/203 Verifying : perl-Fcntl-1.13-483.el9.x86_64 151/203 Verifying : perl-File-Basename-2.85-483.el9.noarch 152/203 Verifying : perl-File-Path-2.18-4.el9.noarch 153/203 Verifying : perl-File-Temp-1:0.231.100-4.el9.noarch 154/203 Verifying : perl-File-stat-1.09-483.el9.noarch 155/203 Verifying : perl-FileHandle-2.03-483.el9.noarch 156/203 Verifying : perl-Getopt-Long-1:2.52-4.el9.noarch 157/203 Verifying : perl-Getopt-Std-1.12-483.el9.noarch 158/203 Verifying : perl-HTTP-Tiny-0.076-462.el9.noarch 159/203 Verifying : perl-IO-1.43-483.el9.x86_64 160/203 Verifying : perl-IO-Socket-IP-0.41-5.el9.noarch 161/203 Verifying : perl-IO-Socket-SSL-2.073-2.el9.noarch 162/203 Verifying : perl-IPC-Open3-1.21-483.el9.noarch 163/203 Verifying : perl-MIME-Base64-3.16-4.el9.x86_64 164/203 Verifying : perl-Mozilla-CA-20200520-6.el9.noarch 165/203 Verifying : perl-Net-SSLeay-1.94-3.el9.x86_64 166/203 Verifying : perl-POSIX-1.94-483.el9.x86_64 167/203 Verifying : perl-PathTools-3.78-461.el9.x86_64 168/203 Verifying : perl-Pod-Escapes-1:1.07-460.el9.noarch 169/203 Verifying : perl-Pod-Perldoc-3.28.01-461.el9.noarch 170/203 Verifying : perl-Pod-Simple-1:3.42-4.el9.noarch 171/203 Verifying : perl-Pod-Usage-4:2.01-4.el9.noarch 172/203 Verifying : perl-Scalar-List-Utils-4:1.56-462.el9.x86_64 173/203 Verifying : perl-SelectSaver-1.02-483.el9.noarch 174/203 Verifying : perl-Socket-4:2.031-4.el9.x86_64 175/203 Verifying : perl-Storable-1:3.21-460.el9.x86_64 176/203 Verifying : perl-Symbol-1.08-483.el9.noarch 177/203 Verifying : perl-Term-ANSIColor-5.01-461.el9.noarch 178/203 Verifying : perl-Term-Cap-1.17-460.el9.noarch 179/203 Verifying : perl-Text-ParseWords-3.30-460.el9.noarch 180/203 Verifying : perl-Text-Tabs+Wrap-2013.0523-460.el9.noarch 181/203 Verifying : perl-Time-Local-2:1.300-7.el9.noarch 182/203 Verifying : perl-URI-5.09-3.el9.noarch 183/203 Verifying : perl-base-2.27-483.el9.noarch 184/203 Verifying : perl-constant-1.33-461.el9.noarch 185/203 Verifying : perl-if-0.60.800-483.el9.noarch 186/203 Verifying : perl-interpreter-4:5.32.1-483.el9.x86_64 187/203 Verifying : perl-libnet-3.13-4.el9.noarch 188/203 Verifying : perl-libs-4:5.32.1-483.el9.x86_64 189/203 Verifying : perl-mro-1.23-483.el9.x86_64 190/203 Verifying : perl-overload-1.31-483.el9.noarch 191/203 Verifying : perl-overloading-0.02-483.el9.noarch 192/203 Verifying : perl-parent-1:0.238-460.el9.noarch 193/203 Verifying : perl-podlators-1:4.14-460.el9.noarch 194/203 Verifying : perl-srpm-macros-1-41.el9.noarch 195/203 Verifying : perl-subs-1.03-483.el9.noarch 196/203 Verifying : perl-vars-1.05-483.el9.noarch 197/203 Verifying : pyproject-srpm-macros-1.16.2-1.el9.noarch 198/203 Verifying : python-srpm-macros-3.9-54.el9.noarch 199/203 Verifying : qt5-srpm-macros-5.15.9-1.el9.noarch 200/203 Verifying : redhat-rpm-config-210-1.el9.noarch 201/203 Verifying : rpm-build-4.16.1.3-39.el9.x86_64 202/203 Verifying : rust-srpm-macros-17-4.el9.noarch 203/203 Installed: alternatives-1.24-2.el9.x86_64 audit-libs-3.1.5-7.el9.x86_64 basesystem-11-13.el9.noarch bash-5.1.8-9.el9.x86_64 binutils-2.35.2-67.el9.x86_64 binutils-gold-2.35.2-67.el9.x86_64 bzip2-1.0.8-10.el9.x86_64 bzip2-libs-1.0.8-10.el9.x86_64 ca-certificates-2025.2.80_v9.0.305-91.el9.noarch centos-gpg-keys-9.0-30.el9.noarch centos-stream-release-9.0-30.el9.noarch centos-stream-repos-9.0-30.el9.noarch coreutils-8.32-39.el9.x86_64 coreutils-common-8.32-39.el9.x86_64 cpio-2.13-16.el9.x86_64 cracklib-2.9.6-27.el9.x86_64 cracklib-dicts-2.9.6-27.el9.x86_64 crypto-policies-20250905-1.git377cc42.el9.noarch curl-7.76.1-34.el9.x86_64 cyrus-sasl-lib-2.1.27-21.el9.x86_64 debugedit-5.0-11.el9.x86_64 diffutils-3.7-12.el9.x86_64 dwz-0.16-1.el9.x86_64 ed-1.14.2-12.el9.x86_64 efi-srpm-macros-6-4.el9.noarch elfutils-0.193-1.el9.x86_64 elfutils-debuginfod-client-0.193-1.el9.x86_64 elfutils-default-yama-scope-0.193-1.el9.noarch elfutils-libelf-0.193-1.el9.x86_64 elfutils-libs-0.193-1.el9.x86_64 file-5.39-16.el9.x86_64 file-libs-5.39-16.el9.x86_64 filesystem-3.16-5.el9.x86_64 findutils-1:4.8.0-7.el9.x86_64 fonts-srpm-macros-1:2.0.5-7.el9.1.noarch gawk-5.1.0-6.el9.x86_64 gdb-minimal-16.3-2.el9.x86_64 gdbm-libs-1:1.23-1.el9.x86_64 ghc-srpm-macros-1.5.0-6.el9.noarch glibc-2.34-238.el9.x86_64 glibc-common-2.34-238.el9.x86_64 glibc-gconv-extra-2.34-238.el9.x86_64 glibc-minimal-langpack-2.34-238.el9.x86_64 gmp-1:6.2.0-13.el9.x86_64 go-srpm-macros-3.8.1-1.el9.noarch grep-3.6-5.el9.x86_64 groff-base-1.22.4-10.el9.x86_64 gzip-1.12-1.el9.x86_64 info-6.7-15.el9.x86_64 json-c-0.14-11.el9.x86_64 kernel-srpm-macros-1.0-14.el9.noarch keyutils-libs-1.6.3-1.el9.x86_64 krb5-libs-1.21.1-8.el9.x86_64 libacl-2.3.1-4.el9.x86_64 libarchive-3.5.3-6.el9.x86_64 libattr-2.5.1-3.el9.x86_64 libblkid-2.37.4-21.el9.x86_64 libbrotli-1.0.9-7.el9.x86_64 libcap-2.48-10.el9.x86_64 libcap-ng-0.8.2-7.el9.x86_64 libcom_err-1.46.5-8.el9.x86_64 libcurl-7.76.1-34.el9.x86_64 libdb-5.3.28-57.el9.x86_64 libeconf-0.4.1-4.el9.x86_64 libevent-2.1.12-8.el9.x86_64 libfdisk-2.37.4-21.el9.x86_64 libffi-3.4.2-8.el9.x86_64 libgcc-11.5.0-11.el9.x86_64 libgcrypt-1.10.0-11.el9.x86_64 libgomp-11.5.0-11.el9.x86_64 libgpg-error-1.42-5.el9.x86_64 libidn2-2.3.0-7.el9.x86_64 libmount-2.37.4-21.el9.x86_64 libnghttp2-1.43.0-6.el9.x86_64 libpkgconf-1.7.3-10.el9.x86_64 libpsl-0.21.1-5.el9.x86_64 libpwquality-1.4.4-8.el9.x86_64 libselinux-3.6-3.el9.x86_64 libsemanage-3.6-5.el9.x86_64 libsepol-3.6-3.el9.x86_64 libsigsegv-2.13-4.el9.x86_64 libsmartcols-2.37.4-21.el9.x86_64 libssh-0.10.4-15.el9.x86_64 libssh-config-0.10.4-15.el9.noarch libstdc++-11.5.0-11.el9.x86_64 libtasn1-4.16.0-9.el9.x86_64 libtool-ltdl-2.4.6-46.el9.x86_64 libunistring-0.9.10-15.el9.x86_64 libutempter-1.2.1-6.el9.x86_64 libuuid-2.37.4-21.el9.x86_64 libverto-0.3.2-3.el9.x86_64 libxcrypt-4.4.18-3.el9.x86_64 libxml2-2.9.13-12.el9.x86_64 libzstd-1.5.5-1.el9.x86_64 lua-libs-5.4.4-4.el9.x86_64 lua-srpm-macros-1-6.el9.noarch lz4-libs-1.9.3-5.el9.x86_64 make-1:4.3-8.el9.x86_64 mpfr-4.1.0-7.el9.x86_64 ncurses-6.2-12.20210508.el9.x86_64 ncurses-base-6.2-12.20210508.el9.noarch ncurses-libs-6.2-12.20210508.el9.x86_64 ocaml-srpm-macros-6-6.el9.noarch openblas-srpm-macros-2-11.el9.noarch openldap-2.6.8-4.el9.x86_64 openssl-1:3.5.1-6.el9.x86_64 openssl-fips-provider-1:3.5.1-6.el9.x86_64 openssl-libs-1:3.5.1-6.el9.x86_64 p11-kit-0.25.10-1.el9.x86_64 p11-kit-trust-0.25.10-1.el9.x86_64 pam-1.5.1-26.el9.x86_64 patch-2.7.6-16.el9.x86_64 pcre-8.44-4.el9.x86_64 pcre2-10.40-6.el9.x86_64 pcre2-syntax-10.40-6.el9.noarch perl-AutoLoader-5.74-483.el9.noarch perl-B-1.80-483.el9.x86_64 perl-Carp-1.50-460.el9.noarch perl-Class-Struct-0.66-483.el9.noarch perl-Data-Dumper-2.174-462.el9.x86_64 perl-Digest-1.19-4.el9.noarch perl-Digest-MD5-2.58-4.el9.x86_64 perl-Encode-4:3.08-462.el9.x86_64 perl-Errno-1.30-483.el9.x86_64 perl-Exporter-5.74-461.el9.noarch perl-Fcntl-1.13-483.el9.x86_64 perl-File-Basename-2.85-483.el9.noarch perl-File-Path-2.18-4.el9.noarch perl-File-Temp-1:0.231.100-4.el9.noarch perl-File-stat-1.09-483.el9.noarch perl-FileHandle-2.03-483.el9.noarch perl-Getopt-Long-1:2.52-4.el9.noarch perl-Getopt-Std-1.12-483.el9.noarch perl-HTTP-Tiny-0.076-462.el9.noarch perl-IO-1.43-483.el9.x86_64 perl-IO-Socket-IP-0.41-5.el9.noarch perl-IO-Socket-SSL-2.073-2.el9.noarch perl-IPC-Open3-1.21-483.el9.noarch perl-MIME-Base64-3.16-4.el9.x86_64 perl-Mozilla-CA-20200520-6.el9.noarch perl-Net-SSLeay-1.94-3.el9.x86_64 perl-POSIX-1.94-483.el9.x86_64 perl-PathTools-3.78-461.el9.x86_64 perl-Pod-Escapes-1:1.07-460.el9.noarch perl-Pod-Perldoc-3.28.01-461.el9.noarch perl-Pod-Simple-1:3.42-4.el9.noarch perl-Pod-Usage-4:2.01-4.el9.noarch perl-Scalar-List-Utils-4:1.56-462.el9.x86_64 perl-SelectSaver-1.02-483.el9.noarch perl-Socket-4:2.031-4.el9.x86_64 perl-Storable-1:3.21-460.el9.x86_64 perl-Symbol-1.08-483.el9.noarch perl-Term-ANSIColor-5.01-461.el9.noarch perl-Term-Cap-1.17-460.el9.noarch perl-Text-ParseWords-3.30-460.el9.noarch perl-Text-Tabs+Wrap-2013.0523-460.el9.noarch perl-Time-Local-2:1.300-7.el9.noarch perl-URI-5.09-3.el9.noarch perl-base-2.27-483.el9.noarch perl-constant-1.33-461.el9.noarch perl-if-0.60.800-483.el9.noarch perl-interpreter-4:5.32.1-483.el9.x86_64 perl-libnet-3.13-4.el9.noarch perl-libs-4:5.32.1-483.el9.x86_64 perl-mro-1.23-483.el9.x86_64 perl-overload-1.31-483.el9.noarch perl-overloading-0.02-483.el9.noarch perl-parent-1:0.238-460.el9.noarch perl-podlators-1:4.14-460.el9.noarch perl-srpm-macros-1-41.el9.noarch perl-subs-1.03-483.el9.noarch perl-vars-1.05-483.el9.noarch pkgconf-1.7.3-10.el9.x86_64 pkgconf-m4-1.7.3-10.el9.noarch pkgconf-pkg-config-1.7.3-10.el9.x86_64 popt-1.18-8.el9.x86_64 publicsuffix-list-dafsa-20210518-3.el9.noarch pyproject-srpm-macros-1.16.2-1.el9.noarch python-srpm-macros-3.9-54.el9.noarch qt5-srpm-macros-5.15.9-1.el9.noarch readline-8.1-4.el9.x86_64 redhat-rpm-config-210-1.el9.noarch rpm-4.16.1.3-39.el9.x86_64 rpm-build-4.16.1.3-39.el9.x86_64 rpm-build-libs-4.16.1.3-39.el9.x86_64 rpm-libs-4.16.1.3-39.el9.x86_64 rust-srpm-macros-17-4.el9.noarch sed-4.8-9.el9.x86_64 setup-2.13.7-10.el9.noarch shadow-utils-2:4.9-15.el9.x86_64 sqlite-libs-3.34.1-8.el9.x86_64 systemd-libs-252-59.el9.x86_64 tar-2:1.34-7.el9.x86_64 tzdata-2025b-2.el9.noarch unzip-6.0-59.el9.x86_64 util-linux-2.37.4-21.el9.x86_64 util-linux-core-2.37.4-21.el9.x86_64 which-2.21-30.el9.x86_64 xz-5.2.5-8.el9.x86_64 xz-libs-5.2.5-8.el9.x86_64 zip-3.0-35.el9.x86_64 zlib-1.2.11-41.el9.x86_64 zstd-1.5.5-1.el9.x86_64 Complete! Finish: installing minimal buildroot with dnf Start: creating root cache Finish: creating root cache Finish: chroot init INFO: Installed packages: INFO: alternatives-1.24-2.el9.x86_64 audit-libs-3.1.5-7.el9.x86_64 basesystem-11-13.el9.noarch bash-5.1.8-9.el9.x86_64 binutils-2.35.2-67.el9.x86_64 binutils-gold-2.35.2-67.el9.x86_64 bzip2-1.0.8-10.el9.x86_64 bzip2-libs-1.0.8-10.el9.x86_64 ca-certificates-2025.2.80_v9.0.305-91.el9.noarch centos-gpg-keys-9.0-30.el9.noarch centos-stream-release-9.0-30.el9.noarch centos-stream-repos-9.0-30.el9.noarch coreutils-8.32-39.el9.x86_64 coreutils-common-8.32-39.el9.x86_64 cpio-2.13-16.el9.x86_64 cracklib-2.9.6-27.el9.x86_64 cracklib-dicts-2.9.6-27.el9.x86_64 crypto-policies-20250905-1.git377cc42.el9.noarch curl-7.76.1-34.el9.x86_64 cyrus-sasl-lib-2.1.27-21.el9.x86_64 debugedit-5.0-11.el9.x86_64 diffutils-3.7-12.el9.x86_64 dwz-0.16-1.el9.x86_64 ed-1.14.2-12.el9.x86_64 efi-srpm-macros-6-4.el9.noarch elfutils-0.193-1.el9.x86_64 elfutils-debuginfod-client-0.193-1.el9.x86_64 elfutils-default-yama-scope-0.193-1.el9.noarch elfutils-libelf-0.193-1.el9.x86_64 elfutils-libs-0.193-1.el9.x86_64 file-5.39-16.el9.x86_64 file-libs-5.39-16.el9.x86_64 filesystem-3.16-5.el9.x86_64 findutils-4.8.0-7.el9.x86_64 fonts-srpm-macros-2.0.5-7.el9.1.noarch gawk-5.1.0-6.el9.x86_64 gdb-minimal-16.3-2.el9.x86_64 gdbm-libs-1.23-1.el9.x86_64 ghc-srpm-macros-1.5.0-6.el9.noarch glibc-2.34-238.el9.x86_64 glibc-common-2.34-238.el9.x86_64 glibc-gconv-extra-2.34-238.el9.x86_64 glibc-minimal-langpack-2.34-238.el9.x86_64 gmp-6.2.0-13.el9.x86_64 go-srpm-macros-3.8.1-1.el9.noarch gpg-pubkey-8483c65d-5ccc5b19 grep-3.6-5.el9.x86_64 groff-base-1.22.4-10.el9.x86_64 gzip-1.12-1.el9.x86_64 info-6.7-15.el9.x86_64 json-c-0.14-11.el9.x86_64 kernel-srpm-macros-1.0-14.el9.noarch keyutils-libs-1.6.3-1.el9.x86_64 krb5-libs-1.21.1-8.el9.x86_64 libacl-2.3.1-4.el9.x86_64 libarchive-3.5.3-6.el9.x86_64 libattr-2.5.1-3.el9.x86_64 libblkid-2.37.4-21.el9.x86_64 libbrotli-1.0.9-7.el9.x86_64 libcap-2.48-10.el9.x86_64 libcap-ng-0.8.2-7.el9.x86_64 libcom_err-1.46.5-8.el9.x86_64 libcurl-7.76.1-34.el9.x86_64 libdb-5.3.28-57.el9.x86_64 libeconf-0.4.1-4.el9.x86_64 libevent-2.1.12-8.el9.x86_64 libfdisk-2.37.4-21.el9.x86_64 libffi-3.4.2-8.el9.x86_64 libgcc-11.5.0-11.el9.x86_64 libgcrypt-1.10.0-11.el9.x86_64 libgomp-11.5.0-11.el9.x86_64 libgpg-error-1.42-5.el9.x86_64 libidn2-2.3.0-7.el9.x86_64 libmount-2.37.4-21.el9.x86_64 libnghttp2-1.43.0-6.el9.x86_64 libpkgconf-1.7.3-10.el9.x86_64 libpsl-0.21.1-5.el9.x86_64 libpwquality-1.4.4-8.el9.x86_64 libselinux-3.6-3.el9.x86_64 libsemanage-3.6-5.el9.x86_64 libsepol-3.6-3.el9.x86_64 libsigsegv-2.13-4.el9.x86_64 libsmartcols-2.37.4-21.el9.x86_64 libssh-0.10.4-15.el9.x86_64 libssh-config-0.10.4-15.el9.noarch libstdc++-11.5.0-11.el9.x86_64 libtasn1-4.16.0-9.el9.x86_64 libtool-ltdl-2.4.6-46.el9.x86_64 libunistring-0.9.10-15.el9.x86_64 libutempter-1.2.1-6.el9.x86_64 libuuid-2.37.4-21.el9.x86_64 libverto-0.3.2-3.el9.x86_64 libxcrypt-4.4.18-3.el9.x86_64 libxml2-2.9.13-12.el9.x86_64 libzstd-1.5.5-1.el9.x86_64 lua-libs-5.4.4-4.el9.x86_64 lua-srpm-macros-1-6.el9.noarch lz4-libs-1.9.3-5.el9.x86_64 make-4.3-8.el9.x86_64 mpfr-4.1.0-7.el9.x86_64 ncurses-6.2-12.20210508.el9.x86_64 ncurses-base-6.2-12.20210508.el9.noarch ncurses-libs-6.2-12.20210508.el9.x86_64 ocaml-srpm-macros-6-6.el9.noarch openblas-srpm-macros-2-11.el9.noarch openldap-2.6.8-4.el9.x86_64 openssl-3.5.1-6.el9.x86_64 openssl-fips-provider-3.5.1-6.el9.x86_64 openssl-libs-3.5.1-6.el9.x86_64 p11-kit-0.25.10-1.el9.x86_64 p11-kit-trust-0.25.10-1.el9.x86_64 pam-1.5.1-26.el9.x86_64 patch-2.7.6-16.el9.x86_64 pcre-8.44-4.el9.x86_64 pcre2-10.40-6.el9.x86_64 pcre2-syntax-10.40-6.el9.noarch perl-AutoLoader-5.74-483.el9.noarch perl-B-1.80-483.el9.x86_64 perl-Carp-1.50-460.el9.noarch perl-Class-Struct-0.66-483.el9.noarch perl-Data-Dumper-2.174-462.el9.x86_64 perl-Digest-1.19-4.el9.noarch perl-Digest-MD5-2.58-4.el9.x86_64 perl-Encode-3.08-462.el9.x86_64 perl-Errno-1.30-483.el9.x86_64 perl-Exporter-5.74-461.el9.noarch perl-Fcntl-1.13-483.el9.x86_64 perl-File-Basename-2.85-483.el9.noarch perl-File-Path-2.18-4.el9.noarch perl-File-Temp-0.231.100-4.el9.noarch perl-File-stat-1.09-483.el9.noarch perl-FileHandle-2.03-483.el9.noarch perl-Getopt-Long-2.52-4.el9.noarch perl-Getopt-Std-1.12-483.el9.noarch perl-HTTP-Tiny-0.076-462.el9.noarch perl-IO-1.43-483.el9.x86_64 perl-IO-Socket-IP-0.41-5.el9.noarch perl-IO-Socket-SSL-2.073-2.el9.noarch perl-IPC-Open3-1.21-483.el9.noarch perl-MIME-Base64-3.16-4.el9.x86_64 perl-Mozilla-CA-20200520-6.el9.noarch perl-Net-SSLeay-1.94-3.el9.x86_64 perl-POSIX-1.94-483.el9.x86_64 perl-PathTools-3.78-461.el9.x86_64 perl-Pod-Escapes-1.07-460.el9.noarch perl-Pod-Perldoc-3.28.01-461.el9.noarch perl-Pod-Simple-3.42-4.el9.noarch perl-Pod-Usage-2.01-4.el9.noarch perl-Scalar-List-Utils-1.56-462.el9.x86_64 perl-SelectSaver-1.02-483.el9.noarch perl-Socket-2.031-4.el9.x86_64 perl-Storable-3.21-460.el9.x86_64 perl-Symbol-1.08-483.el9.noarch perl-Term-ANSIColor-5.01-461.el9.noarch perl-Term-Cap-1.17-460.el9.noarch perl-Text-ParseWords-3.30-460.el9.noarch perl-Text-Tabs+Wrap-2013.0523-460.el9.noarch perl-Time-Local-1.300-7.el9.noarch perl-URI-5.09-3.el9.noarch perl-base-2.27-483.el9.noarch perl-constant-1.33-461.el9.noarch perl-if-0.60.800-483.el9.noarch perl-interpreter-5.32.1-483.el9.x86_64 perl-libnet-3.13-4.el9.noarch perl-libs-5.32.1-483.el9.x86_64 perl-mro-1.23-483.el9.x86_64 perl-overload-1.31-483.el9.noarch perl-overloading-0.02-483.el9.noarch perl-parent-0.238-460.el9.noarch perl-podlators-4.14-460.el9.noarch perl-srpm-macros-1-41.el9.noarch perl-subs-1.03-483.el9.noarch perl-vars-1.05-483.el9.noarch pkgconf-1.7.3-10.el9.x86_64 pkgconf-m4-1.7.3-10.el9.noarch pkgconf-pkg-config-1.7.3-10.el9.x86_64 popt-1.18-8.el9.x86_64 publicsuffix-list-dafsa-20210518-3.el9.noarch pyproject-srpm-macros-1.16.2-1.el9.noarch python-srpm-macros-3.9-54.el9.noarch qt5-srpm-macros-5.15.9-1.el9.noarch readline-8.1-4.el9.x86_64 redhat-rpm-config-210-1.el9.noarch rpm-4.16.1.3-39.el9.x86_64 rpm-build-4.16.1.3-39.el9.x86_64 rpm-build-libs-4.16.1.3-39.el9.x86_64 rpm-libs-4.16.1.3-39.el9.x86_64 rust-srpm-macros-17-4.el9.noarch sed-4.8-9.el9.x86_64 setup-2.13.7-10.el9.noarch shadow-utils-4.9-15.el9.x86_64 sqlite-libs-3.34.1-8.el9.x86_64 systemd-libs-252-59.el9.x86_64 tar-1.34-7.el9.x86_64 tzdata-2025b-2.el9.noarch unzip-6.0-59.el9.x86_64 util-linux-2.37.4-21.el9.x86_64 util-linux-core-2.37.4-21.el9.x86_64 which-2.21-30.el9.x86_64 xz-5.2.5-8.el9.x86_64 xz-libs-5.2.5-8.el9.x86_64 zip-3.0-35.el9.x86_64 zlib-1.2.11-41.el9.x86_64 zstd-1.5.5-1.el9.x86_64 Start: buildsrpm Start: rpmbuild -bs Building target platforms: x86_64 Building for target x86_64 Wrote: /builddir/build/SRPMS/scap-security-guide-0.1.79-0.20251113092050720330.pr14119.18545.ga45aadb5a1.el9.src.rpm Finish: rpmbuild -bs INFO: chroot_scan: 3 files copied to /var/lib/copr-rpmbuild/results/chroot_scan INFO: /var/lib/mock/centos-stream-9-x86_64-1763025687.143490/root/var/log/dnf.rpm.log /var/lib/mock/centos-stream-9-x86_64-1763025687.143490/root/var/log/dnf.librepo.log /var/lib/mock/centos-stream-9-x86_64-1763025687.143490/root/var/log/dnf.log INFO: chroot_scan: creating tarball /var/lib/copr-rpmbuild/results/chroot_scan.tar.gz /bin/tar: Removing leading `/' from member names Finish: buildsrpm INFO: Done(/var/lib/copr-rpmbuild/workspace/workdir-zza_3pxq/scap-security-guide/scap-security-guide.spec) Config(child) 0 minutes 26 seconds INFO: Results and/or logs in: /var/lib/copr-rpmbuild/results INFO: Cleaning up build root ('cleanup_on_success=True') Start: clean chroot INFO: unmounting tmpfs. Finish: clean chroot INFO: Start(/var/lib/copr-rpmbuild/results/scap-security-guide-0.1.79-0.20251113092050720330.pr14119.18545.ga45aadb5a1.el9.src.rpm) Config(centos-stream-9-x86_64) Start(bootstrap): chroot init INFO: mounting tmpfs at /var/lib/mock/centos-stream-9-x86_64-bootstrap-1763025687.143490/root. INFO: reusing tmpfs at /var/lib/mock/centos-stream-9-x86_64-bootstrap-1763025687.143490/root. INFO: calling preinit hooks INFO: enabled root cache INFO: enabled package manager cache Start(bootstrap): cleaning package manager metadata Finish(bootstrap): cleaning package manager metadata Finish(bootstrap): chroot init Start: chroot init INFO: mounting tmpfs at /var/lib/mock/centos-stream-9-x86_64-1763025687.143490/root. INFO: calling preinit hooks INFO: enabled root cache Start: unpacking root cache Finish: unpacking root cache INFO: enabled package manager cache Start: cleaning package manager metadata Finish: cleaning package manager metadata INFO: enabled HW Info plugin INFO: Buildroot is handled by package management downloaded with a bootstrap image: rpm-4.16.1.3-39.el9.x86_64 python3-dnf-4.14.0-31.el9.noarch python3-dnf-plugins-core-4.3.0-23.el9.noarch yum-4.14.0-31.el9.noarch Finish: chroot init Start: build phase for scap-security-guide-0.1.79-0.20251113092050720330.pr14119.18545.ga45aadb5a1.el9.src.rpm Start: build setup for scap-security-guide-0.1.79-0.20251113092050720330.pr14119.18545.ga45aadb5a1.el9.src.rpm Building target platforms: x86_64 Building for target x86_64 Wrote: /builddir/build/SRPMS/scap-security-guide-0.1.79-0.20251113092050720330.pr14119.18545.ga45aadb5a1.el9.src.rpm No matches found for the following disable plugin patterns: local, spacewalk, versionlock Copr repository 36 kB/s | 1.5 kB 00:00 CentOS Stream 9 - BaseOS 90 kB/s | 11 kB 00:00 CentOS Stream 9 - AppStream 120 kB/s | 11 kB 00:00 CentOS Stream 9 - CRB 116 kB/s | 10 kB 00:00 CentOS Stream 9 - Extras packages 135 kB/s | 12 kB 00:00 Dependencies resolved. ================================================================================ Package Arch Version Repository Size ================================================================================ Installing: cmake x86_64 3.26.5-2.el9 appstream 8.7 M libxslt x86_64 1.1.34-12.el9 appstream 233 k openscap-scanner x86_64 1:1.3.12-1.el9 appstream 58 k python3 x86_64 3.9.23-2.el9 baseos 26 k python3-jinja2 noarch 2.11.3-8.el9 appstream 249 k python3-pyyaml x86_64 5.4.1-6.el9 baseos 205 k python3-setuptools noarch 53.0.0-15.el9 baseos 936 k Installing dependencies: acl x86_64 2.3.1-4.el9 baseos 71 k cmake-data noarch 3.26.5-2.el9 appstream 2.4 M cmake-filesystem x86_64 3.26.5-2.el9 appstream 19 k cmake-rpm-macros noarch 3.26.5-2.el9 appstream 11 k dbus x86_64 1:1.12.20-8.el9 baseos 3.8 k dbus-broker x86_64 28-7.el9 baseos 172 k dbus-common noarch 1:1.12.20-8.el9 baseos 15 k dbus-libs x86_64 1:1.12.20-8.el9 baseos 152 k emacs-filesystem noarch 1:27.2-18.el9 appstream 9.2 k expat x86_64 2.5.0-5.el9 baseos 116 k glib2 x86_64 2.68.4-16.el9 baseos 2.6 M gnutls x86_64 3.8.3-9.el9 baseos 1.1 M kmod-libs x86_64 28-11.el9 baseos 62 k libseccomp x86_64 2.5.2-2.el9 baseos 72 k libuv x86_64 1:1.42.0-2.el9 appstream 148 k libyaml x86_64 0.2.5-7.el9 baseos 61 k nettle x86_64 3.10.1-1.el9 baseos 563 k openscap x86_64 1:1.3.12-1.el9 appstream 2.0 M procps-ng x86_64 3.3.17-14.el9 baseos 349 k python3-babel noarch 2.9.1-2.el9 appstream 6.0 M python3-libs x86_64 3.9.23-2.el9 baseos 8.1 M python3-markupsafe x86_64 1.1.1-12.el9 appstream 35 k python3-pip-wheel noarch 21.3.1-1.el9 baseos 1.1 M python3-pytz noarch 2021.1-5.el9 appstream 51 k python3-setuptools-wheel noarch 53.0.0-15.el9 baseos 468 k systemd x86_64 252-59.el9 baseos 4.2 M systemd-pam x86_64 252-59.el9 baseos 283 k systemd-rpm-macros noarch 252-59.el9 baseos 71 k vim-filesystem noarch 2:8.2.2637-22.el9 baseos 13 k xmlsec1 x86_64 1.2.29-13.el9 appstream 189 k xmlsec1-openssl x86_64 1.2.29-13.el9 appstream 90 k Transaction Summary ================================================================================ Install 38 Packages Total download size: 41 M Installed size: 205 M Downloading Packages: (1/38): dbus-1.12.20-8.el9.x86_64.rpm 196 kB/s | 3.8 kB 00:00 (2/38): dbus-broker-28-7.el9.x86_64.rpm 7.5 MB/s | 172 kB 00:00 (3/38): acl-2.3.1-4.el9.x86_64.rpm 3.0 MB/s | 71 kB 00:00 (4/38): dbus-common-1.12.20-8.el9.noarch.rpm 4.3 MB/s | 15 kB 00:00 (5/38): dbus-libs-1.12.20-8.el9.x86_64.rpm 35 MB/s | 152 kB 00:00 (6/38): expat-2.5.0-5.el9.x86_64.rpm 17 MB/s | 116 kB 00:00 (7/38): glib2-2.68.4-16.el9.x86_64.rpm 163 MB/s | 2.6 MB 00:00 (8/38): gnutls-3.8.3-9.el9.x86_64.rpm 80 MB/s | 1.1 MB 00:00 (9/38): kmod-libs-28-11.el9.x86_64.rpm 5.9 MB/s | 62 kB 00:00 (10/38): libyaml-0.2.5-7.el9.x86_64.rpm 25 MB/s | 61 kB 00:00 (11/38): libseccomp-2.5.2-2.el9.x86_64.rpm 22 MB/s | 72 kB 00:00 (12/38): nettle-3.10.1-1.el9.x86_64.rpm 96 MB/s | 563 kB 00:00 (13/38): procps-ng-3.3.17-14.el9.x86_64.rpm 76 MB/s | 349 kB 00:00 (14/38): python3-3.9.23-2.el9.x86_64.rpm 6.0 MB/s | 26 kB 00:00 (15/38): python3-pyyaml-5.4.1-6.el9.x86_64.rpm 51 MB/s | 205 kB 00:00 (16/38): python3-pip-wheel-21.3.1-1.el9.noarch. 99 MB/s | 1.1 MB 00:00 (17/38): python3-setuptools-53.0.0-15.el9.noarc 80 MB/s | 936 kB 00:00 (18/38): python3-setuptools-wheel-53.0.0-15.el9 67 MB/s | 468 kB 00:00 (19/38): python3-libs-3.9.23-2.el9.x86_64.rpm 229 MB/s | 8.1 MB 00:00 (20/38): systemd-pam-252-59.el9.x86_64.rpm 20 MB/s | 283 kB 00:00 (21/38): systemd-252-59.el9.x86_64.rpm 172 MB/s | 4.2 MB 00:00 (22/38): systemd-rpm-macros-252-59.el9.noarch.r 8.2 MB/s | 71 kB 00:00 (23/38): vim-filesystem-8.2.2637-22.el9.noarch. 2.0 MB/s | 13 kB 00:00 (24/38): cmake-filesystem-3.26.5-2.el9.x86_64.r 3.4 MB/s | 19 kB 00:00 (25/38): cmake-rpm-macros-3.26.5-2.el9.noarch.r 2.4 MB/s | 11 kB 00:00 (26/38): cmake-data-3.26.5-2.el9.noarch.rpm 177 MB/s | 2.4 MB 00:00 (27/38): emacs-filesystem-27.2-18.el9.noarch.rp 2.4 MB/s | 9.2 kB 00:00 (28/38): libuv-1.42.0-2.el9.x86_64.rpm 50 MB/s | 148 kB 00:00 (29/38): libxslt-1.1.34-12.el9.x86_64.rpm 50 MB/s | 233 kB 00:00 (30/38): openscap-scanner-1.3.12-1.el9.x86_64.r 16 MB/s | 58 kB 00:00 (31/38): openscap-1.3.12-1.el9.x86_64.rpm 129 MB/s | 2.0 MB 00:00 (32/38): python3-jinja2-2.11.3-8.el9.noarch.rpm 18 MB/s | 249 kB 00:00 (33/38): python3-babel-2.9.1-2.el9.noarch.rpm 164 MB/s | 6.0 MB 00:00 (34/38): python3-markupsafe-1.1.1-12.el9.x86_64 2.7 MB/s | 35 kB 00:00 (35/38): cmake-3.26.5-2.el9.x86_64.rpm 118 MB/s | 8.7 MB 00:00 (36/38): python3-pytz-2021.1-5.el9.noarch.rpm 3.8 MB/s | 51 kB 00:00 (37/38): xmlsec1-1.2.29-13.el9.x86_64.rpm 14 MB/s | 189 kB 00:00 (38/38): xmlsec1-openssl-1.2.29-13.el9.x86_64.r 30 MB/s | 90 kB 00:00 -------------------------------------------------------------------------------- Total 55 MB/s | 41 MB 00:00 Running transaction check Transaction check succeeded. Running transaction test Transaction test succeeded. Running transaction Preparing : 1/1 Installing : libxslt-1.1.34-12.el9.x86_64 1/38 Installing : expat-2.5.0-5.el9.x86_64 2/38 Installing : xmlsec1-1.2.29-13.el9.x86_64 3/38 Installing : cmake-filesystem-3.26.5-2.el9.x86_64 4/38 Installing : libyaml-0.2.5-7.el9.x86_64 5/38 Installing : xmlsec1-openssl-1.2.29-13.el9.x86_64 6/38 Installing : libuv-1:1.42.0-2.el9.x86_64 7/38 Installing : emacs-filesystem-1:27.2-18.el9.noarch 8/38 Installing : vim-filesystem-2:8.2.2637-22.el9.noarch 9/38 Installing : systemd-rpm-macros-252-59.el9.noarch 10/38 Installing : python3-setuptools-wheel-53.0.0-15.el9.noarch 11/38 Installing : python3-pip-wheel-21.3.1-1.el9.noarch 12/38 Installing : python3-3.9.23-2.el9.x86_64 13/38 Installing : python3-libs-3.9.23-2.el9.x86_64 14/38 Installing : python3-setuptools-53.0.0-15.el9.noarch 15/38 Installing : cmake-rpm-macros-3.26.5-2.el9.noarch 16/38 Installing : cmake-data-3.26.5-2.el9.noarch 17/38 Installing : cmake-3.26.5-2.el9.x86_64 18/38 Installing : python3-markupsafe-1.1.1-12.el9.x86_64 19/38 Installing : python3-pytz-2021.1-5.el9.noarch 20/38 Installing : python3-babel-2.9.1-2.el9.noarch 21/38 Installing : procps-ng-3.3.17-14.el9.x86_64 22/38 Installing : nettle-3.10.1-1.el9.x86_64 23/38 Installing : gnutls-3.8.3-9.el9.x86_64 24/38 Installing : glib2-2.68.4-16.el9.x86_64 25/38 Installing : libseccomp-2.5.2-2.el9.x86_64 26/38 Installing : kmod-libs-28-11.el9.x86_64 27/38 Installing : dbus-libs-1:1.12.20-8.el9.x86_64 28/38 Installing : acl-2.3.1-4.el9.x86_64 29/38 Installing : dbus-1:1.12.20-8.el9.x86_64 30/38 Installing : systemd-pam-252-59.el9.x86_64 31/38 Running scriptlet: systemd-252-59.el9.x86_64 32/38 Installing : systemd-252-59.el9.x86_64 32/38 Running scriptlet: systemd-252-59.el9.x86_64 32/38 Installing : dbus-common-1:1.12.20-8.el9.noarch 33/38 Running scriptlet: dbus-common-1:1.12.20-8.el9.noarch 33/38 Created symlink /etc/systemd/system/sockets.target.wants/dbus.socket → /usr/lib/systemd/system/dbus.socket. Created symlink /etc/systemd/user/sockets.target.wants/dbus.socket → /usr/lib/systemd/user/dbus.socket. Running scriptlet: dbus-broker-28-7.el9.x86_64 34/38 Installing : dbus-broker-28-7.el9.x86_64 34/38 Running scriptlet: dbus-broker-28-7.el9.x86_64 34/38 Created symlink /etc/systemd/system/dbus.service → /usr/lib/systemd/system/dbus-broker.service. Created symlink /etc/systemd/user/dbus.service → /usr/lib/systemd/user/dbus-broker.service. Installing : openscap-1:1.3.12-1.el9.x86_64 35/38 Installing : openscap-scanner-1:1.3.12-1.el9.x86_64 36/38 Installing : python3-jinja2-2.11.3-8.el9.noarch 37/38 Installing : python3-pyyaml-5.4.1-6.el9.x86_64 38/38 Running scriptlet: python3-pyyaml-5.4.1-6.el9.x86_64 38/38 Verifying : acl-2.3.1-4.el9.x86_64 1/38 Verifying : dbus-1:1.12.20-8.el9.x86_64 2/38 Verifying : dbus-broker-28-7.el9.x86_64 3/38 Verifying : dbus-common-1:1.12.20-8.el9.noarch 4/38 Verifying : dbus-libs-1:1.12.20-8.el9.x86_64 5/38 Verifying : expat-2.5.0-5.el9.x86_64 6/38 Verifying : glib2-2.68.4-16.el9.x86_64 7/38 Verifying : gnutls-3.8.3-9.el9.x86_64 8/38 Verifying : kmod-libs-28-11.el9.x86_64 9/38 Verifying : libseccomp-2.5.2-2.el9.x86_64 10/38 Verifying : libyaml-0.2.5-7.el9.x86_64 11/38 Verifying : nettle-3.10.1-1.el9.x86_64 12/38 Verifying : procps-ng-3.3.17-14.el9.x86_64 13/38 Verifying : python3-3.9.23-2.el9.x86_64 14/38 Verifying : python3-libs-3.9.23-2.el9.x86_64 15/38 Verifying : python3-pip-wheel-21.3.1-1.el9.noarch 16/38 Verifying : python3-pyyaml-5.4.1-6.el9.x86_64 17/38 Verifying : python3-setuptools-53.0.0-15.el9.noarch 18/38 Verifying : python3-setuptools-wheel-53.0.0-15.el9.noarch 19/38 Verifying : systemd-252-59.el9.x86_64 20/38 Verifying : systemd-pam-252-59.el9.x86_64 21/38 Verifying : systemd-rpm-macros-252-59.el9.noarch 22/38 Verifying : vim-filesystem-2:8.2.2637-22.el9.noarch 23/38 Verifying : cmake-3.26.5-2.el9.x86_64 24/38 Verifying : cmake-data-3.26.5-2.el9.noarch 25/38 Verifying : cmake-filesystem-3.26.5-2.el9.x86_64 26/38 Verifying : cmake-rpm-macros-3.26.5-2.el9.noarch 27/38 Verifying : emacs-filesystem-1:27.2-18.el9.noarch 28/38 Verifying : libuv-1:1.42.0-2.el9.x86_64 29/38 Verifying : libxslt-1.1.34-12.el9.x86_64 30/38 Verifying : openscap-1:1.3.12-1.el9.x86_64 31/38 Verifying : openscap-scanner-1:1.3.12-1.el9.x86_64 32/38 Verifying : python3-babel-2.9.1-2.el9.noarch 33/38 Verifying : python3-jinja2-2.11.3-8.el9.noarch 34/38 Verifying : python3-markupsafe-1.1.1-12.el9.x86_64 35/38 Verifying : python3-pytz-2021.1-5.el9.noarch 36/38 Verifying : xmlsec1-1.2.29-13.el9.x86_64 37/38 Verifying : xmlsec1-openssl-1.2.29-13.el9.x86_64 38/38 Installed: acl-2.3.1-4.el9.x86_64 cmake-3.26.5-2.el9.x86_64 cmake-data-3.26.5-2.el9.noarch cmake-filesystem-3.26.5-2.el9.x86_64 cmake-rpm-macros-3.26.5-2.el9.noarch dbus-1:1.12.20-8.el9.x86_64 dbus-broker-28-7.el9.x86_64 dbus-common-1:1.12.20-8.el9.noarch dbus-libs-1:1.12.20-8.el9.x86_64 emacs-filesystem-1:27.2-18.el9.noarch expat-2.5.0-5.el9.x86_64 glib2-2.68.4-16.el9.x86_64 gnutls-3.8.3-9.el9.x86_64 kmod-libs-28-11.el9.x86_64 libseccomp-2.5.2-2.el9.x86_64 libuv-1:1.42.0-2.el9.x86_64 libxslt-1.1.34-12.el9.x86_64 libyaml-0.2.5-7.el9.x86_64 nettle-3.10.1-1.el9.x86_64 openscap-1:1.3.12-1.el9.x86_64 openscap-scanner-1:1.3.12-1.el9.x86_64 procps-ng-3.3.17-14.el9.x86_64 python3-3.9.23-2.el9.x86_64 python3-babel-2.9.1-2.el9.noarch python3-jinja2-2.11.3-8.el9.noarch python3-libs-3.9.23-2.el9.x86_64 python3-markupsafe-1.1.1-12.el9.x86_64 python3-pip-wheel-21.3.1-1.el9.noarch python3-pytz-2021.1-5.el9.noarch python3-pyyaml-5.4.1-6.el9.x86_64 python3-setuptools-53.0.0-15.el9.noarch python3-setuptools-wheel-53.0.0-15.el9.noarch systemd-252-59.el9.x86_64 systemd-pam-252-59.el9.x86_64 systemd-rpm-macros-252-59.el9.noarch vim-filesystem-2:8.2.2637-22.el9.noarch xmlsec1-1.2.29-13.el9.x86_64 xmlsec1-openssl-1.2.29-13.el9.x86_64 Complete! Finish: build setup for scap-security-guide-0.1.79-0.20251113092050720330.pr14119.18545.ga45aadb5a1.el9.src.rpm Start: rpmbuild scap-security-guide-0.1.79-0.20251113092050720330.pr14119.18545.ga45aadb5a1.el9.src.rpm Building target platforms: x86_64 Building for target x86_64 Executing(%prep): /bin/sh -e /var/tmp/rpm-tmp.pWTpP0 + umask 022 + cd /builddir/build/BUILD + cd /builddir/build/BUILD + rm -rf scap-security-guide-0.1.79 + /usr/bin/gzip -dc /builddir/build/SOURCES/scap-security-guide-0.1.79.tar.gz + /usr/bin/tar -xof - + STATUS=0 + '[' 0 -ne 0 ']' + cd scap-security-guide-0.1.79 + /usr/bin/chmod -Rf a+rX,u+w,g-w,o-w . + mkdir -p build + RPM_EC=0 ++ jobs -p + exit 0 Executing(%build): /bin/sh -e /var/tmp/rpm-tmp.Tpt2cd + umask 022 + cd /builddir/build/BUILD + cd scap-security-guide-0.1.79 + CFLAGS='-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64-v2 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection' + export CFLAGS + CXXFLAGS='-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64-v2 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection' + export CXXFLAGS + FFLAGS='-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64-v2 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection -I/usr/lib64/gfortran/modules' + export FFLAGS + FCFLAGS='-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64-v2 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection -I/usr/lib64/gfortran/modules' + export FCFLAGS + LDFLAGS='-Wl,-z,relro -Wl,--as-needed -Wl,-z,now -specs=/usr/lib/rpm/redhat/redhat-hardened-ld -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 ' + export LDFLAGS + LT_SYS_LIBRARY_PATH=/usr/lib64: + export LT_SYS_LIBRARY_PATH + CC=gcc + export CC + CXX=g++ + export CXX + /usr/bin/cmake -S . -B build -DCMAKE_C_FLAGS_RELEASE:STRING=-DNDEBUG -DCMAKE_CXX_FLAGS_RELEASE:STRING=-DNDEBUG -DCMAKE_Fortran_FLAGS_RELEASE:STRING=-DNDEBUG -DCMAKE_VERBOSE_MAKEFILE:BOOL=ON -DCMAKE_INSTALL_DO_STRIP:BOOL=OFF -DCMAKE_INSTALL_PREFIX:PATH=/usr -DINCLUDE_INSTALL_DIR:PATH=/usr/include -DLIB_INSTALL_DIR:PATH=/usr/lib64 -DSYSCONF_INSTALL_DIR:PATH=/etc -DSHARE_INSTALL_PREFIX:PATH=/usr/share -DLIB_SUFFIX=64 -DBUILD_SHARED_LIBS:BOOL=ON -DSSG_SEPARATE_SCAP_FILES_ENABLED=OFF -DSSG_BASH_SCRIPTS_ENABLED=OFF -DSSG_BUILD_DISA_DELTA_FILES=OFF -DSSG_PRODUCT_DEFAULT:BOOLEAN=FALSE -DSSG_PRODUCT_RHEL9:BOOLEAN=TRUE -DSSG_CENTOS_DERIVATIVES_ENABLED:BOOL=ON -DSSG_SCE_ENABLED:BOOL=ON -- Setting build type to 'Release' as none was specified. -- PYTHONPATH: /builddir/build/BUILD/scap-security-guide-0.1.79 -- Found Python: /usr/bin/python3 (found version "3.9.23") found components: Interpreter -- -- SCAP Security Guide 0.1.79 -- (see /builddir/build/BUILD/scap-security-guide-0.1.79/docs/manual/developer_guide.adoc for build instructions) -- -- Finding Python Modules: -- Found PY_jinja2: /usr/lib/python3.9/site-packages/jinja2 -- Found PY_yaml: /usr/lib64/python3.9/site-packages/yaml -- Could NOT find PY_cmakelint (missing: PY_CMAKELINT) -- Could NOT find PY_github (missing: PY_GITHUB) -- Could NOT find PY_json2html (missing: PY_JSON2HTML) -- Could NOT find PY_lxml (missing: PY_LXML) -- Could NOT find PY_mypy (missing: PY_MYPY) -- Could NOT find PY_openpyxl (missing: PY_OPENPYXL) -- Could NOT find PY_pandas (missing: PY_PANDAS) -- Could NOT find PY_pcre2 (missing: PY_PCRE2) -- Could NOT find PY_pytest (missing: PY_PYTEST) -- Could NOT find PY_pytest_cov (missing: PY_PYTEST_COV) -- Could NOT find PY_myst_parser (missing: PY_MYST_PARSER) -- Could NOT find PY_sphinx (missing: PY_SPHINX) -- Could NOT find PY_sphinxcontrib.autojinja (missing: PY_SPHINXCONTRIB.AUTOJINJA) -- Could NOT find PY_sphinx_rtd_theme (missing: PY_SPHINX_RTD_THEME) -- Could NOT find PY_prometheus_client (missing: PY_PROMETHEUS_CLIENT) -- Could NOT find PY_requests (missing: PY_REQUESTS) -- Could NOT find PY_trestle (missing: PY_TRESTLE) -- -- Summary of Python Tools and Modules: -- python: /usr/bin/python3 (version: 3.9.23) -- python yaml module: /usr/lib64/python3.9/site-packages/yaml -- python jinja2 module: /usr/lib/python3.9/site-packages/jinja2 -- python compliance-trestle module (optional): -- python cmakelint module (optional): -- python github (PyGitHub) module (optional): -- python json2html module (optional): -- python lxml module (optional): -- python mypy module (optional): -- python myst-parser module (optional): -- python openpyxl module (optional): -- python pandas module (optional): -- python pcre2 module (optional): -- python prometheus-client module (optional): -- python pytest_cov module (optional): -- python pytest module (optional): -- python requests module (optional): -- python sphinx module (optional): -- python sphinxcontrib.autojinja module (optional): -- python sphinx_rtd_theme module (optional): -- -- Summary of System Tools: -- oscap: /usr/bin/oscap (version: 1.3.12) -- sed: /usr/bin/sed -- xsltproc: /usr/bin/xsltproc -- xmllint: /usr/bin/xmllint -- ansible-lint module (optional): ANSIBLE_LINT_EXECUTABLE-NOTFOUND -- ansible-playbook module (optional): ANSIBLE_PLAYBOOK_EXECUTABLE-NOTFOUND -- BATS framework (optional): BATS_EXECUTABLE-NOTFOUND -- grep (optional): /usr/bin/grep -- linkchecker (optional): LINKCHECKER_EXECUTABLE-NOTFOUND -- shellcheck (optional): SHELLCHECK_EXECUTABLE-NOTFOUND -- yamllint module (optional): YAMLLINT_EXECUTABLE-NOTFOUND -- -- CMake Settings: -- build type: Release -- build directory: /builddir/build/BUILD/scap-security-guide-0.1.79/build -- generator: Unix Makefiles -- source directory: /builddir/build/BUILD/scap-security-guide-0.1.79 -- -- Build options: -- SSG vendor string: ssgproject -- Logging: -- Ansible Playbooks: ON -- Ansible Playbooks Per Rule: OFF -- Bash scripts: OFF -- Build SCE Content: ON -- Build SRG XLSX Export: OFF -- jinja2 cache: enabled -- jinja2 cache dir: /builddir/build/BUILD/scap-security-guide-0.1.79/build/jinja2_cache -- Separate SCAP files: OFF -- STIG Delta Tailoring files: OFF -- Thin data streams: -- Pre-build Automatus tests: OFF -- -- Validation options: -- BATS tests: ON -- Link Checker validation: ON -- OVAL schematron validation: ON -- shellcheck bash fixes validation: ON -- SCAPVal 1.3 Enabled: OFF -- Validate SCAP content: ON -- Force validate everything: OFF -- Check if rules have been removed from the data stream OFF -- -- Products: -- Amazon Linux 2023: OFF -- Alibaba Cloud Linux 2: OFF -- Alibaba Cloud Linux 3: OFF -- AlmaLinux OS 9: OFF -- Anolis OS 8: OFF -- Anolis OS 23: OFF -- Debian 11: OFF -- Debian 12: OFF -- Debian 13: OFF -- Example: OFF -- EKS: OFF -- Fedora: OFF -- Firefox: OFF -- Kylin Server V10: OFF -- OCP4: OFF -- RHCOS4: OFF -- Oracle Linux 7: OFF -- Oracle Linux 8: OFF -- Oracle Linux 9: OFF -- Oracle Linux 10: OFF -- OpenEmbedded: OFF -- openEuler 22.03 LTS: OFF -- openSUSE: OFF -- RHEL 8: OFF -- RHEL 9: TRUE -- RHEL 10: OFF -- RHV 4: OFF -- SUSE 12: OFF -- SUSE 15: OFF -- SUSE 16: OFF -- SLE Micro 5: OFF -- SLE Micro 6: OFF -- TencentOS Server 4: OFF -- Ubuntu 22.04: OFF -- Ubuntu 24.04: OFF -- -- Scanning for dependencies of rhel9 fixes (bash, ansible, puppet, anaconda, ignition, kubernetes and blueprint)... -- Configuring done (0.4s) -- Generating done (0.0s) CMake Warning: Manually-specified variables were not used by the project: BUILD_SHARED_LIBS CMAKE_CXX_FLAGS_RELEASE CMAKE_C_FLAGS_RELEASE CMAKE_Fortran_FLAGS_RELEASE CMAKE_INSTALL_DO_STRIP INCLUDE_INSTALL_DIR LIB_INSTALL_DIR LIB_SUFFIX SHARE_INSTALL_PREFIX SYSCONF_INSTALL_DIR -- Build files have been written to: /builddir/build/BUILD/scap-security-guide-0.1.79/build + /usr/bin/cmake --build build -j4 --verbose /usr/bin/cmake -S/builddir/build/BUILD/scap-security-guide-0.1.79 -B/builddir/build/BUILD/scap-security-guide-0.1.79/build --check-build-system CMakeFiles/Makefile.cmake 0 /usr/bin/cmake -E cmake_progress_start /builddir/build/BUILD/scap-security-guide-0.1.79/build/CMakeFiles /builddir/build/BUILD/scap-security-guide-0.1.79/build//CMakeFiles/progress.marks /usr/bin/gmake -f CMakeFiles/Makefile2 all gmake[1]: Entering directory '/builddir/build/BUILD/scap-security-guide-0.1.79/build' /usr/bin/gmake -f rhel9/CMakeFiles/generate-internal-rhel9-sce-metadata.json.dir/build.make rhel9/CMakeFiles/generate-internal-rhel9-sce-metadata.json.dir/depend gmake[2]: Entering directory '/builddir/build/BUILD/scap-security-guide-0.1.79/build' cd /builddir/build/BUILD/scap-security-guide-0.1.79/build && /usr/bin/cmake -E cmake_depends "Unix Makefiles" /builddir/build/BUILD/scap-security-guide-0.1.79 /builddir/build/BUILD/scap-security-guide-0.1.79/products/rhel9 /builddir/build/BUILD/scap-security-guide-0.1.79/build /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9 /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9/CMakeFiles/generate-internal-rhel9-sce-metadata.json.dir/DependInfo.cmake --color= gmake[2]: Leaving directory '/builddir/build/BUILD/scap-security-guide-0.1.79/build' /usr/bin/gmake -f rhel9/CMakeFiles/generate-internal-rhel9-sce-metadata.json.dir/build.make rhel9/CMakeFiles/generate-internal-rhel9-sce-metadata.json.dir/build gmake[2]: Entering directory '/builddir/build/BUILD/scap-security-guide-0.1.79/build' [ 1%] [rhel9-content] compiling product yaml cd /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9 && env PYTHONPATH=/builddir/build/BUILD/scap-security-guide-0.1.79 /usr/bin/python3 /builddir/build/BUILD/scap-security-guide-0.1.79/build-scripts/compile_product.py --product-yaml /builddir/build/BUILD/scap-security-guide-0.1.79/products/rhel9/product.yml --product-properties /builddir/build/BUILD/scap-security-guide-0.1.79/product_properties --compiled-product-yaml /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9/product.yml [ 1%] [rhel9-content] generating sce/metadata.json cd /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9 && env PYTHONPATH=/builddir/build/BUILD/scap-security-guide-0.1.79 /usr/bin/python3 /builddir/build/BUILD/scap-security-guide-0.1.79/build-scripts/build_sce.py --build-config-yaml /builddir/build/BUILD/scap-security-guide-0.1.79/build/build_config.yml --product-yaml /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9/product.yml --templates-dir /builddir/build/BUILD/scap-security-guide-0.1.79/shared/templates --output /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9/checks/sce gmake[2]: Leaving directory '/builddir/build/BUILD/scap-security-guide-0.1.79/build' [ 1%] Built target generate-internal-rhel9-sce-metadata.json /usr/bin/gmake -f rhel9/CMakeFiles/rhel9-compile-all.dir/build.make rhel9/CMakeFiles/rhel9-compile-all.dir/depend gmake[2]: Entering directory '/builddir/build/BUILD/scap-security-guide-0.1.79/build' cd /builddir/build/BUILD/scap-security-guide-0.1.79/build && /usr/bin/cmake -E cmake_depends "Unix Makefiles" /builddir/build/BUILD/scap-security-guide-0.1.79 /builddir/build/BUILD/scap-security-guide-0.1.79/products/rhel9 /builddir/build/BUILD/scap-security-guide-0.1.79/build /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9 /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9/CMakeFiles/rhel9-compile-all.dir/DependInfo.cmake --color= gmake[2]: Leaving directory '/builddir/build/BUILD/scap-security-guide-0.1.79/build' /usr/bin/gmake -f rhel9/CMakeFiles/rhel9-compile-all.dir/build.make rhel9/CMakeFiles/rhel9-compile-all.dir/build gmake[2]: Entering directory '/builddir/build/BUILD/scap-security-guide-0.1.79/build' [ 1%] [rhel9-content] compiling everything cd /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9 && /usr/bin/cmake -E make_directory /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9/profiles cd /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9 && env PYTHONPATH=/builddir/build/BUILD/scap-security-guide-0.1.79 /usr/bin/python3 /builddir/build/BUILD/scap-security-guide-0.1.79/build-scripts/compile_all.py --resolved-base /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9 --project-root /builddir/build/BUILD/scap-security-guide-0.1.79 --build-config-yaml /builddir/build/BUILD/scap-security-guide-0.1.79/build/build_config.yml --product-yaml /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9/product.yml --sce-metadata /builddir/build/BUILD/scap-security-guide-0.1.79/build/rhel9/checks/sce/metadata.json --stig-references /builddir/build/BUILD/scap-security-guide-0.1.79/shared/references/disa-stig-rhel9-v2r5-xccdf-manual.xml --rule-id off A Jinja template expansion can mess up the indentation. Please, check if the contents below are correctly expanded: Source yaml: /builddir/build/BUILD/scap-security-guide-0.1.79/products/rhel9/controls/stig_rhel9.yml Expanded yaml: --- policy: 'Red Hat Enterprise Linux 9 Security Technical Implementation Guide' title: 'Red Hat Enterprise Linux 9 Security Technical Implementation Guide' id: stig_rhel9 source: https://www.cyber.mil/stigs/downloads/ version: V2R4 reference_type: stigid product: rhel9 levels: - id: high - id: medium - id: low controls: - id: needed_rules levels: - medium rules: - enable_authselect - var_authselect_profile=sssd - id: RHEL-09-171011 levels: - medium rules: - dconf_gnome_login_banner_text - id: RHEL-09-211010 levels: - high title: RHEL 9 must be a vendor-supported release. rules: - installed_OS_is_vendor_supported status: automated - id: RHEL-09-211015 levels: - medium title: RHEL 9 vendor packaged system security patches and updates must be installed and up to date. rules: - security_patches_up_to_date status: automated - id: RHEL-09-211020 levels: - medium title: RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a command line user logon. rules: - banner_etc_issue - login_banner_text=dod_banners status: automated - id: RHEL-09-211030 levels: - medium title: The graphical display manager must not be the default target on RHEL 9 unless approved. rules: - xwindows_runlevel_target status: automated - id: RHEL-09-211035 levels: - low title: RHEL 9 must enable the hardware random number generator entropy gatherer service. related_rules: - service_rngd_enabled # This rule is causing test failures, See https://github.com/ComplianceAsCode/content/pull/10153 status: pending - id: RHEL-09-211040 levels: - medium title: RHEL 9 systemd-journald service must be enabled. rules: - service_systemd-journald_enabled status: automated - id: RHEL-09-211045 levels: - high title: The systemd Ctrl-Alt-Delete burst key sequence in RHEL 9 must be disabled. rules: - disable_ctrlaltdel_burstaction status: automated - id: RHEL-09-211050 levels: - high title: The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 9. rules: - disable_ctrlaltdel_reboot status: automated - id: RHEL-09-211055 levels: - medium title: RHEL 9 debug-shell systemd service must be disabled. status: automated rules: - service_debug-shell_disabled - id: RHEL-09-212010 levels: - medium title: RHEL 9 must require a boot loader superuser password. rules: - grub2_password status: automated - id: RHEL-09-212015 levels: - medium title: RHEL 9 must disable the ability of systemd to spawn an interactive boot process. rules: - grub2_disable_interactive_boot status: automated - id: RHEL-09-212020 levels: - high title: RHEL 9 must require a unique superusers name upon booting into single-user and maintenance modes. rules: - grub2_admin_username status: automated - id: RHEL-09-212025 levels: - medium title: RHEL 9 /boot/grub2/grub.cfg file must be group-owned by root. rules: - file_groupowner_grub2_cfg status: automated - id: RHEL-09-212030 levels: - medium title: RHEL 9 /boot/grub2/grub.cfg file must be owned by root. rules: - file_owner_grub2_cfg status: automated - id: RHEL-09-212035 levels: - medium title: RHEL 9 must disable virtual system calls. rules: - grub2_vsyscall_argument status: automated - id: RHEL-09-212040 levels: - medium title: RHEL 9 must clear the page allocator to prevent use-after-free attacks. rules: - grub2_page_poison_argument status: automated - id: RHEL-09-212045 levels: - medium title: RHEL 9 must clear SLUB/SLAB objects to prevent use-after-free attacks. rules: - grub2_init_on_free status: automated - id: RHEL-09-212050 levels: - low title: RHEL 9 must enable mitigations against processor-based vulnerabilities. rules: - grub2_pti_argument status: automated - id: RHEL-09-212055 levels: - low title: RHEL 9 must enable auditing of processes that start prior to the audit daemon. rules: - grub2_audit_argument status: automated - id: RHEL-09-213010 levels: - medium title: RHEL 9 must restrict access to the kernel message buffer. rules: - sysctl_kernel_dmesg_restrict status: automated - id: RHEL-09-213015 levels: - medium title: RHEL 9 must prevent kernel profiling by nonprivileged users. rules: - sysctl_kernel_perf_event_paranoid status: automated - id: RHEL-09-213020 levels: - medium title: RHEL 9 must prevent the loading of a new kernel for later execution. rules: - sysctl_kernel_kexec_load_disabled status: automated - id: RHEL-09-213025 levels: - medium title: RHEL 9 must restrict exposed kernel pointer addresses access. rules: - sysctl_kernel_kptr_restrict status: automated - id: RHEL-09-213030 levels: - medium title: RHEL 9 must enable kernel parameters to enforce discretionary access control on hardlinks. rules: - sysctl_fs_protected_hardlinks status: automated - id: RHEL-09-213035 levels: - medium title: RHEL 9 must enable kernel parameters to enforce discretionary access control on symlinks. rules: - sysctl_fs_protected_symlinks status: automated - id: RHEL-09-213040 levels: - medium title: RHEL 9 must disable the kernel.core_pattern. rules: - sysctl_kernel_core_pattern status: automated - id: RHEL-09-213045 levels: - medium title: RHEL 9 must be configured to disable the Asynchronous Transfer Mode kernel module. rules: - kernel_module_atm_disabled status: automated - id: RHEL-09-213050 levels: - medium title: RHEL 9 must be configured to disable the Controller Area Network kernel module. rules: - kernel_module_can_disabled status: automated - id: RHEL-09-213055 levels: - medium title: RHEL 9 must be configured to disable the FireWire kernel module. rules: - kernel_module_firewire-core_disabled status: automated - id: RHEL-09-213060 levels: - medium title: RHEL 9 must disable the Stream Control Transmission Protocol (SCTP) kernel module. rules: - kernel_module_sctp_disabled status: automated - id: RHEL-09-213065 levels: - medium title: RHEL 9 must disable the Transparent Inter Process Communication (TIPC) kernel module. rules: - kernel_module_tipc_disabled status: automated - id: RHEL-09-213070 levels: - medium title: RHEL 9 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. rules: - sysctl_kernel_randomize_va_space status: automated - id: RHEL-09-213075 levels: - medium title: RHEL 9 must disable access to network bpf system call from nonprivileged processes. rules: - sysctl_kernel_unprivileged_bpf_disabled status: automated - id: RHEL-09-213080 levels: - medium title: RHEL 9 must restrict usage of ptrace to descendant processes. rules: - sysctl_kernel_yama_ptrace_scope status: automated - id: RHEL-09-213085 levels: - medium title: RHEL 9 must disable core dump backtraces. rules: - coredump_disable_backtraces status: automated - id: RHEL-09-213090 levels: - medium title: RHEL 9 must disable storing core dumps. rules: - coredump_disable_storage status: automated - id: RHEL-09-213095 levels: - medium title: RHEL 9 must disable core dumps for all users. rules: - disable_users_coredumps status: automated - id: RHEL-09-213100 levels: - medium title: RHEL 9 must disable acquiring, saving, and processing core dumps. rules: - service_systemd-coredump_disabled status: automated - id: RHEL-09-213105 levels: - medium title: RHEL 9 must disable the use of user namespaces. rules: - sysctl_user_max_user_namespaces_no_remediation status: automated - id: RHEL-09-213110 levels: - medium title: RHEL 9 must implement nonexecutable data to protect its memory from unauthorized code execution. rules: - sysctl_kernel_exec_shield status: automated - id: RHEL-09-213115 levels: - medium title: The kdump service on RHEL 9 must be disabled. rules: - service_kdump_disabled status: automated - id: RHEL-09-214010 levels: - medium title: RHEL 9 must ensure cryptographic verification of vendor software packages. rules: - ensure_redhat_gpgkey_installed status: automated - id: RHEL-09-214015 levels: - high title: RHEL 9 must check the GPG signature of software packages originating from external software repositories before installation. rules: - ensure_gpgcheck_globally_activated status: automated - id: RHEL-09-214020 levels: - high title: RHEL 9 must check the GPG signature of locally installed software packages before installation. rules: - ensure_gpgcheck_local_packages status: automated - id: RHEL-09-214025 levels: - high title: RHEL 9 must have GPG signature verification enabled for all software repositories. rules: - ensure_gpgcheck_never_disabled status: automated - id: RHEL-09-214030 levels: - medium title: RHEL 9 must be configured so that the cryptographic hashes of system files match vendor values. related_rules: - rpm_verify_hashes # Due to crypto policies this cannot be selected at this time status: pending - id: RHEL-09-214035 levels: - low title: RHEL 9 must remove all software components after updated versions have been installed. rules: - clean_components_post_updating status: automated - id: RHEL-09-215010 levels: - medium title: RHEL 9 subscription-manager package must be installed. rules: - package_subscription-manager_installed status: automated - id: RHEL-09-215015 levels: - high title: RHEL 9 must not have a File Transfer Protocol (FTP) server package installed. rules: - package_vsftpd_removed status: automated - id: RHEL-09-215020 levels: - medium title: RHEL 9 must not have the sendmail package installed. rules: - package_sendmail_removed status: automated - id: RHEL-09-215025 levels: - medium title: RHEL 9 must not have the nfs-utils package installed. rules: - package_nfs-utils_removed status: automated - id: RHEL-09-215030 levels: - medium title: RHEL 9 must not have the ypserv package installed. related_rules: - package_ypserv_removed status: not applicable # The ypserv package is not available in RHEL 9 - id: RHEL-09-215035 levels: - medium title: RHEL 9 must not have the rsh-server package installed. related_rules: - package_rsh-server_removed status: not applicable # The rsh-server package is not available in RHEL 9 - id: RHEL-09-215040 levels: - medium title: RHEL 9 must not have the telnet-server package installed. rules: - package_telnet-server_removed status: automated - id: RHEL-09-215045 levels: - medium title: RHEL 9 must not have the gssproxy package installed. rules: - package_gssproxy_removed status: automated - id: RHEL-09-215050 levels: - medium title: RHEL 9 must not have the iprutils package installed. rules: - package_iprutils_removed status: automated - id: RHEL-09-215055 levels: - medium title: RHEL 9 must not have the tuned package installed. rules: - package_tuned_removed status: automated - id: RHEL-09-215060 levels: - high title: RHEL 9 must not have a Trivial File Transfer Protocol (TFTP) server package installed. rules: - package_tftp-server_removed status: automated - id: RHEL-09-215065 levels: - medium title: RHEL 9 must not have the quagga package installed. related_rules: - package_quagga_removed status: not applicable # The quagga package is not available in RHEL 9 - id: RHEL-09-215070 levels: - medium title: A graphical display manager must not be installed on RHEL 9 unless approved. rules: - xwindows_remove_packages status: automated - id: RHEL-09-215075 levels: - medium title: RHEL 9 must have the openssl-pkcs11 package installed. rules: - install_smartcard_packages status: automated - id: RHEL-09-215080 levels: - medium title: RHEL 9 must have the gnutls-utils package installed. rules: - package_gnutls-utils_installed status: automated - id: RHEL-09-215085 levels: - medium title: RHEL 9 must have the nss-tools package installed. rules: - package_nss-tools_installed status: automated - id: RHEL-09-215090 levels: - medium title: RHEL 9 must have the rng-tools package installed. rules: - package_rng-tools_installed status: automated - id: RHEL-09-215095 levels: - medium title: RHEL 9 must have the s-nail package installed. rules: - package_s-nail_installed status: automated - id: RHEL-09-215100 levels: - medium title: RHEL 9 must have the crypto-policies package installed. rules: - package_crypto-policies_installed status: automated - id: RHEL-09-215101 levels: - medium title: RHEL 9 must have the Postfix package installed. status: automated rules: - package_postfix_installed - id: RHEL-09-215105 levels: - medium title: RHEL 9 must implement a FIPS 140-3 compliant systemwide cryptographic policy. rules: - configure_crypto_policy - fips_crypto_subpolicy - fips_custom_stig_sub_policy status: automated - id: RHEL-09-231010 levels: - medium title: A separate RHEL 9 file system must be used for user home directories (such as /home or an equivalent). rules: - partition_for_home status: automated - id: RHEL-09-231015 levels: - medium title: RHEL 9 must use a separate file system for /tmp. rules: - partition_for_tmp status: automated - id: RHEL-09-231020 levels: - low title: RHEL 9 must use a separate file system for /var. rules: - partition_for_var status: automated - id: RHEL-09-231025 levels: - low title: RHEL 9 must use a separate file system for /var/log. rules: - partition_for_var_log status: automated - id: RHEL-09-231030 levels: - low title: RHEL 9 must use a separate file system for the system audit data path. rules: - partition_for_var_log_audit status: automated - id: RHEL-09-231035 levels: - medium title: RHEL 9 must use a separate file system for /var/tmp. rules: - partition_for_var_tmp status: automated - id: RHEL-09-231040 levels: - medium title: RHEL 9 file system automount function must be disabled unless required. rules: - service_autofs_disabled status: automated - id: RHEL-09-231045 levels: - medium title: RHEL 9 must prevent device files from being interpreted on file systems that contain user home directories. rules: - mount_option_home_nodev status: automated - id: RHEL-09-231050 levels: - medium title: RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories. rules: - mount_option_home_nosuid status: automated - id: RHEL-09-231055 levels: - medium title: RHEL 9 must prevent code from being executed on file systems that contain user home directories. rules: - mount_option_home_noexec status: automated - id: RHEL-09-231065 levels: - medium title: RHEL 9 must prevent special devices on file systems that are imported via Network File System (NFS). rules: - mount_option_nodev_remote_filesystems status: automated - id: RHEL-09-231070 levels: - medium title: RHEL 9 must prevent code from being executed on file systems that are imported via Network File System (NFS). rules: - mount_option_noexec_remote_filesystems status: automated - id: RHEL-09-231075 levels: - medium title: RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS). rules: - mount_option_nosuid_remote_filesystems status: automated - id: RHEL-09-231080 levels: - medium title: RHEL 9 must prevent code from being executed on file systems that are used with removable media. rules: - mount_option_noexec_removable_partitions status: automated - id: RHEL-09-231085 levels: - medium title: RHEL 9 must prevent special devices on file systems that are used with removable media. rules: - mount_option_nodev_removable_partitions status: automated - id: RHEL-09-231090 levels: - medium title: RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media. rules: - mount_option_nosuid_removable_partitions status: automated - id: RHEL-09-231095 levels: - medium title: RHEL 9 must mount /boot with the nodev option. rules: - mount_option_boot_nodev status: automated - id: RHEL-09-231100 levels: - medium title: RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory. rules: - mount_option_boot_nosuid status: automated - id: RHEL-09-231105 levels: - medium title: RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory. rules: - mount_option_boot_efi_nosuid status: automated - id: RHEL-09-231110 levels: - medium title: RHEL 9 must mount /dev/shm with the nodev option. rules: - mount_option_dev_shm_nodev status: automated - id: RHEL-09-231115 levels: - medium title: RHEL 9 must mount /dev/shm with the noexec option. rules: - mount_option_dev_shm_noexec status: automated - id: RHEL-09-231120 levels: - medium title: RHEL 9 must mount /dev/shm with the nosuid option. rules: - mount_option_dev_shm_nosuid status: automated - id: RHEL-09-231125 levels: - medium title: RHEL 9 must mount /tmp with the nodev option. rules: - mount_option_tmp_nodev status: automated - id: RHEL-09-231130 levels: - medium title: RHEL 9 must mount /tmp with the noexec option. rules: - mount_option_tmp_noexec status: automated - id: RHEL-09-231135 levels: - medium title: RHEL 9 must mount /tmp with the nosuid option. rules: - mount_option_tmp_nosuid status: automated - id: RHEL-09-231140 levels: - medium title: RHEL 9 must mount /var with the nodev option. rules: - mount_option_var_nodev status: automated - id: RHEL-09-231145 levels: - medium title: RHEL 9 must mount /var/log with the nodev option. rules: - mount_option_var_log_nodev status: automated - id: RHEL-09-231150 levels: - medium title: RHEL 9 must mount /var/log with the noexec option. rules: - mount_option_var_log_noexec status: automated - id: RHEL-09-231155 levels: - medium title: RHEL 9 must mount /var/log with the nosuid option. rules: - mount_option_var_log_nosuid status: automated - id: RHEL-09-231160 levels: - medium title: RHEL 9 must mount /var/log/audit with the nodev option. rules: - mount_option_var_log_audit_nodev status: automated - id: RHEL-09-231165 levels: - medium title: RHEL 9 must mount /var/log/audit with the noexec option. rules: - mount_option_var_log_audit_noexec status: automated - id: RHEL-09-231170 levels: - medium title: RHEL 9 must mount /var/log/audit with the nosuid option. rules: - mount_option_var_log_audit_nosuid status: automated - id: RHEL-09-231175 levels: - medium title: RHEL 9 must mount /var/tmp with the nodev option. rules: - mount_option_var_tmp_nodev status: automated - id: RHEL-09-231180 levels: - medium title: RHEL 9 must mount /var/tmp with the noexec option. rules: - mount_option_var_tmp_noexec status: automated - id: RHEL-09-231185 levels: - medium title: RHEL 9 must mount /var/tmp with the nosuid option. rules: - mount_option_var_tmp_nosuid status: automated - id: RHEL-09-231190 levels: - high title: RHEL 9 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection. rules: - encrypt_partitions status: automated - id: RHEL-09-231195 levels: - low title: RHEL 9 must disable mounting of cramfs. rules: - kernel_module_cramfs_disabled status: automated - id: RHEL-09-231200 levels: - medium title: RHEL 9 must prevent special devices on non-root local partitions. rules: - mount_option_nodev_nonroot_local_partitions status: automated - id: RHEL-09-232010 levels: - medium title: RHEL 9 system commands must have mode 755 or less permissive. rules: - file_permissions_binary_dirs status: automated - id: RHEL-09-232015 levels: - medium title: RHEL 9 library directories must have mode 755 or less permissive. rules: - dir_permissions_library_dirs status: automated - id: RHEL-09-232020 levels: - medium title: RHEL 9 library files must have mode 755 or less permissive. rules: - file_permissions_library_dirs status: automated - id: RHEL-09-232025 levels: - medium title: RHEL 9 /var/log directory must have mode 0755 or less permissive. rules: - file_permissions_var_log status: automated - id: RHEL-09-232030 levels: - medium title: RHEL 9 /var/log/messages file must have mode 0640 or less permissive. rules: - file_permissions_var_log_messages status: automated - id: RHEL-09-232035 levels: - medium title: RHEL 9 audit tools must have a mode of 0755 or less permissive. rules: - file_audit_tools_permissions status: automated - id: RHEL-09-232040 levels: - medium title: RHEL 9 cron configuration directories must have a mode of 0700 or less permissive. rules: - package_cron_installed - file_permissions_cron_d - file_permissions_cron_daily - file_permissions_cron_hourly - file_permissions_cron_monthly - file_permissions_cron_weekly status: automated - id: RHEL-09-232045 levels: - medium title: All RHEL 9 local initialization files must have mode 0740 or less permissive. rules: - file_permission_user_init_files_root - var_user_initialization_files_regex=all_dotfiles - rootfiles_configured status: automated - id: RHEL-09-232050 levels: - medium title: All RHEL 9 local interactive user home directories must have mode 0750 or less permissive. rules: - file_permissions_home_directories status: automated - id: RHEL-09-232055 levels: - medium title: RHEL 9 /etc/group file must have mode 0644 or less permissive to prevent unauthorized access. rules: - file_permissions_etc_group status: automated - id: RHEL-09-232060 levels: - medium title: RHEL 9 /etc/group- file must have mode 0644 or less permissive to prevent unauthorized access. rules: - file_permissions_backup_etc_group status: automated - id: RHEL-09-232065 levels: - medium title: RHEL 9 /etc/gshadow file must have mode 0000 or less permissive to prevent unauthorized access. rules: - file_permissions_etc_gshadow status: automated - id: RHEL-09-232070 levels: - medium title: RHEL 9 /etc/gshadow- file must have mode 0000 or less permissive to prevent unauthorized access. rules: - file_permissions_backup_etc_gshadow status: automated - id: RHEL-09-232075 levels: - medium title: RHEL 9 /etc/passwd file must have mode 0644 or less permissive to prevent unauthorized access. rules: - file_permissions_etc_passwd status: automated - id: RHEL-09-232080 levels: - medium title: RHEL 9 /etc/passwd- file must have mode 0644 or less permissive to prevent unauthorized access. rules: - file_permissions_backup_etc_passwd status: automated - id: RHEL-09-232085 levels: - medium title: RHEL 9 /etc/shadow- file must have mode 0000 or less permissive to prevent unauthorized access. rules: - file_permissions_backup_etc_shadow status: automated - id: RHEL-09-232090 levels: - medium title: RHEL 9 /etc/group file must be owned by root. rules: - file_owner_etc_group status: automated - id: RHEL-09-232095 levels: - medium title: RHEL 9 /etc/group file must be group-owned by root. rules: - file_groupowner_etc_group status: automated - id: RHEL-09-232100 levels: - medium title: RHEL 9 /etc/group- file must be owned by root. rules: - file_owner_backup_etc_group - id: RHEL-09-232103 title: RHEL 9 "/etc/audit/" must be owned by root. levels: - medium rules: - file_ownership_audit_configuration status: automated - id: RHEL-09-232104 title: RHEL 9 "/etc/audit/" must be group-owned by root. levels: - medium rules: - file_groupownership_audit_configuration - id: RHEL-09-232105 levels: - medium title: RHEL 9 /etc/group- file must be group-owned by root. rules: - file_groupowner_backup_etc_group status: automated - id: RHEL-09-232110 levels: - medium title: RHEL 9 /etc/gshadow file must be owned by root. rules: - file_owner_etc_gshadow status: automated - id: RHEL-09-232115 levels: - medium title: RHEL 9 /etc/gshadow file must be group-owned by root. rules: - file_groupowner_etc_gshadow status: automated - id: RHEL-09-232120 levels: - medium title: RHEL 9 /etc/gshadow- file must be owned by root. rules: - file_owner_backup_etc_gshadow status: automated - id: RHEL-09-232125 levels: - medium title: RHEL 9 /etc/gshadow- file must be group-owned by root. rules: - file_groupowner_backup_etc_gshadow status: automated - id: RHEL-09-232130 levels: - medium title: RHEL 9 /etc/passwd file must be owned by root. rules: - file_owner_etc_passwd status: automated - id: RHEL-09-232135 levels: - medium title: RHEL 9 /etc/passwd file must be group-owned by root. rules: - file_groupowner_etc_passwd status: automated - id: RHEL-09-232140 levels: - medium title: RHEL 9 /etc/passwd- file must be owned by root. rules: - file_owner_backup_etc_passwd status: automated - id: RHEL-09-232145 levels: - medium title: RHEL 9 /etc/passwd- file must be group-owned by root. rules: - file_groupowner_backup_etc_passwd status: automated - id: RHEL-09-232150 levels: - medium title: RHEL 9 /etc/shadow file must be owned by root. rules: - file_owner_etc_shadow status: automated - id: RHEL-09-232155 levels: - medium title: RHEL 9 /etc/shadow file must be group-owned by root. rules: - file_groupowner_etc_shadow status: automated - id: RHEL-09-232160 levels: - medium title: RHEL 9 /etc/shadow- file must be owned by root. rules: - file_owner_backup_etc_shadow status: automated - id: RHEL-09-232165 levels: - medium title: RHEL 9 /etc/shadow- file must be group-owned by root. rules: - file_groupowner_backup_etc_shadow status: automated - id: RHEL-09-232170 levels: - medium title: RHEL 9 /var/log directory must be owned by root. rules: - file_owner_var_log status: automated - id: RHEL-09-232175 levels: - medium title: RHEL 9 /var/log directory must be group-owned by root. rules: - file_groupowner_var_log status: automated - id: RHEL-09-232180 levels: - medium title: RHEL 9 /var/log/messages file must be owned by root. rules: - file_owner_var_log_messages status: automated - id: RHEL-09-232185 levels: - medium title: RHEL 9 /var/log/messages file must be group-owned by root. rules: - file_groupowner_var_log_messages status: automated - id: RHEL-09-232190 levels: - medium title: RHEL 9 system commands must be owned by root. rules: - file_ownership_binary_dirs status: automated - id: RHEL-09-232195 levels: - medium title: RHEL 9 system commands must be group-owned by root or a system account. rules: - file_groupownership_system_commands_dirs status: automated - id: RHEL-09-232200 levels: - medium title: RHEL 9 library files must be owned by root. rules: - file_ownership_library_dirs status: automated - id: RHEL-09-232205 levels: - medium title: RHEL 9 library files must be group-owned by root or a system account. rules: - root_permissions_syslibrary_files status: automated - id: RHEL-09-232210 levels: - medium title: RHEL 9 library directories must be owned by root. rules: - dir_ownership_library_dirs status: automated - id: RHEL-09-232215 levels: - medium title: RHEL 9 library directories must be group-owned by root or a system account. rules: - dir_group_ownership_library_dirs status: automated - id: RHEL-09-232220 levels: - medium title: RHEL 9 audit tools must be owned by root. rules: - file_audit_tools_ownership status: automated - id: RHEL-09-232225 levels: - medium title: RHEL 9 audit tools must be group-owned by root. rules: - file_audit_tools_group_ownership status: automated - id: RHEL-09-232230 levels: - medium title: RHEL 9 cron configuration files directory must be owned by root. rules: - file_owner_cron_d - file_owner_cron_daily - file_owner_cron_hourly - file_owner_cron_monthly - file_owner_cron_weekly - file_owner_crontab - file_owner_cron_deny status: automated - id: RHEL-09-232235 levels: - medium title: RHEL 9 cron configuration files directory must be group-owned by root. rules: - file_groupowner_cron_d - file_groupowner_cron_daily - file_groupowner_cron_hourly - file_groupowner_cron_monthly - file_groupowner_cron_weekly - file_groupowner_crontab - file_groupowner_cron_deny status: automated - id: RHEL-09-232240 levels: - medium title: All RHEL 9 world-writable directories must be owned by root, sys, bin, or an application user. rules: - dir_perms_world_writable_root_owned status: automated - id: RHEL-09-232245 levels: - medium title: A sticky bit must be set on all RHEL 9 public directories. rules: - dir_perms_world_writable_sticky_bits status: automated - id: RHEL-09-232250 levels: - medium title: All RHEL 9 local files and directories must have a valid group owner. rules: - file_permissions_ungroupowned status: automated - id: RHEL-09-232255 levels: - medium title: All RHEL 9 local files and directories must have a valid owner. rules: - no_files_unowned_by_user status: automated - id: RHEL-09-232260 levels: - medium title: RHEL 9 must be configured so that all system device files are correctly labeled to prevent unauthorized modification. rules: - selinux_all_devicefiles_labeled status: automated - id: RHEL-09-232270 levels: - medium title: RHEL 9 /etc/shadow file must have mode 0000 to prevent unauthorized access. rules: - file_permissions_etc_shadow status: automated - id: RHEL-09-251010 levels: - medium title: RHEL 9 must have the firewalld package installed. rules: - package_firewalld_installed status: automated - id: RHEL-09-251015 levels: - medium title: The firewalld service on RHEL 9 must be active. rules: - service_firewalld_enabled status: automated - id: RHEL-09-251020 levels: - medium title: A RHEL 9 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems. rules: - configured_firewalld_default_deny status: automated - id: RHEL-09-251030 levels: - medium title: RHEL 9 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures on impacted network interfaces are implemented. rules: - firewalld-backend status: automated - id: RHEL-09-251035 levels: - medium title: RHEL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments. rules: - firewalld_sshd_port_enabled status: automated - id: RHEL-09-251040 levels: - medium title: RHEL 9 network interfaces must not be in promiscuous mode. rules: - network_sniffer_disabled status: automated - id: RHEL-09-251045 levels: - medium title: RHEL 9 must enable hardening for the Berkeley Packet Filter just-in-time compiler. rules: - sysctl_net_core_bpf_jit_harden status: automated - id: RHEL-09-252010 levels: - medium title: RHEL 9 must have the chrony package installed. rules: - package_chrony_installed status: automated - id: RHEL-09-252015 levels: - medium title: RHEL 9 chronyd service must be enabled. rules: - service_chronyd_enabled status: automated - id: RHEL-09-252020 levels: - medium title: RHEL 9 must securely compare internal information system clocks at least every 24 hours. rules: - chronyd_or_ntpd_set_maxpoll - chronyd_server_directive - chronyd_specify_remote_server - var_multiple_time_servers=stig - var_time_service_set_maxpoll=18_hours status: automated - id: RHEL-09-252025 levels: - low title: RHEL 9 must disable the chrony daemon from acting as a server. rules: - chronyd_client_only status: automated - id: RHEL-09-252030 levels: - low title: RHEL 9 must disable network management of the chrony daemon. rules: - chronyd_no_chronyc_network status: automated - id: RHEL-09-252035 levels: - medium title: RHEL 9 systems using Domain Name Servers (DNS) resolution must have at least two name servers configured. rules: - network_configure_name_resolution status: automated - id: RHEL-09-252040 levels: - medium title: RHEL 9 must configure a DNS processing mode set be Network Manager. rules: - networkmanager_dns_mode - var_networkmanager_dns_mode=explicit_default status: automated - id: RHEL-09-252045 levels: - medium title: RHEL 9 must not have unauthorized IP tunnels configured. rules: - libreswan_approved_tunnels status: automated - id: RHEL-09-252050 levels: - medium title: RHEL 9 must be configured to prevent unrestricted mail relaying. rules: - postfix_prevent_unrestricted_relay status: automated - id: RHEL-09-252060 levels: - medium title: RHEL 9 must forward mail from postmaster to the root account using a postfix alias. rules: - postfix_client_configure_mail_alias_postmaster status: automated - id: RHEL-09-252065 levels: - medium title: RHEL 9 libreswan package must be installed. rules: - package_libreswan_installed status: automated - id: RHEL-09-252070 levels: - high title: There must be no shosts.equiv files on RHEL 9. rules: - no_host_based_files status: automated - id: RHEL-09-252075 levels: - high title: There must be no .shosts files on RHEL 9. rules: - no_user_host_based_files status: automated - id: RHEL-09-253010 levels: - medium title: RHEL 9 must be configured to use TCP syncookies. rules: - sysctl_net_ipv4_tcp_syncookies status: automated - id: RHEL-09-253015 levels: - medium title: RHEL 9 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages. rules: - sysctl_net_ipv4_conf_all_accept_redirects status: automated - id: RHEL-09-253020 levels: - medium title: RHEL 9 must not forward Internet Protocol version 4 (IPv4) source-routed packets. rules: - sysctl_net_ipv4_conf_all_accept_source_route status: automated - id: RHEL-09-253025 levels: - medium title: RHEL 9 must log IPv4 packets with impossible addresses. rules: - sysctl_net_ipv4_conf_all_log_martians status: automated - id: RHEL-09-253030 levels: - medium title: RHEL 9 must log IPv4 packets with impossible addresses by default. rules: - sysctl_net_ipv4_conf_default_log_martians status: automated - id: RHEL-09-253035 levels: - medium title: RHEL 9 must use reverse path filtering on all IPv4 interfaces. rules: - sysctl_net_ipv4_conf_all_rp_filter status: automated - id: RHEL-09-253040 levels: - medium title: RHEL 9 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted. rules: - sysctl_net_ipv4_conf_default_accept_redirects status: automated - id: RHEL-09-253045 levels: - medium title: RHEL 9 must not forward IPv4 source-routed packets by default. rules: - sysctl_net_ipv4_conf_default_accept_source_route status: automated - id: RHEL-09-253050 levels: - medium title: RHEL 9 must use a reverse-path filter for IPv4 network traffic when possible by default. rules: - sysctl_net_ipv4_conf_default_rp_filter status: automated - id: RHEL-09-253055 levels: - medium title: RHEL 9 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address. rules: - sysctl_net_ipv4_icmp_echo_ignore_broadcasts status: automated - id: RHEL-09-253060 levels: - medium title: RHEL 9 must limit the number of bogus Internet Control Message Protocol (ICMP) response errors logs. rules: - sysctl_net_ipv4_icmp_ignore_bogus_error_responses status: automated - id: RHEL-09-253065 levels: - medium title: RHEL 9 must not send Internet Control Message Protocol (ICMP) redirects. rules: - sysctl_net_ipv4_conf_all_send_redirects status: automated - id: RHEL-09-253070 levels: - medium title: RHEL 9 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default. rules: - sysctl_net_ipv4_conf_default_send_redirects status: automated - id: RHEL-09-253075 levels: - medium title: RHEL 9 must not enable IPv4 packet forwarding unless the system is a router. rules: - sysctl_net_ipv4_conf_all_forwarding status: automated - id: RHEL-09-254010 levels: - medium title: RHEL 9 must not accept router advertisements on all IPv6 interfaces. rules: - sysctl_net_ipv6_conf_all_accept_ra status: automated - id: RHEL-09-254015 levels: - medium title: RHEL 9 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages. rules: - sysctl_net_ipv6_conf_all_accept_redirects status: automated - id: RHEL-09-254020 levels: - medium title: RHEL 9 must not forward IPv6 source-routed packets. rules: - sysctl_net_ipv6_conf_all_accept_source_route status: automated - id: RHEL-09-254025 levels: - medium title: RHEL 9 must not enable IPv6 packet forwarding unless the system is a router. rules: - sysctl_net_ipv6_conf_all_forwarding status: automated - id: RHEL-09-254030 levels: - medium title: RHEL 9 must not accept router advertisements on all IPv6 interfaces by default. rules: - sysctl_net_ipv6_conf_default_accept_ra status: automated - id: RHEL-09-254035 levels: - medium title: RHEL 9 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted. rules: - sysctl_net_ipv6_conf_default_accept_redirects status: automated - id: RHEL-09-254040 levels: - medium title: RHEL 9 must not forward IPv6 source-routed packets by default. rules: - sysctl_net_ipv6_conf_default_accept_source_route status: automated - id: RHEL-09-255010 levels: - medium title: All RHEL 9 networked systems must have SSH installed. rules: - package_openssh-server_installed status: automated - id: RHEL-09-255015 levels: - medium title: All RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission. rules: - service_sshd_enabled status: automated - id: RHEL-09-255020 levels: - medium title: RHEL 9 must have the openssh-clients package installed. rules: - package_openssh-clients_installed status: automated - id: RHEL-09-255025 levels: - medium title: RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a SSH logon. rules: - sshd_enable_warning_banner status: automated - id: RHEL-09-255030 levels: - medium title: RHEL 9 must log SSH connection attempts and failures to the server. rules: - sshd_set_loglevel_verbose status: automated - id: RHEL-09-255035 levels: - medium title: RHEL 9 SSHD must accept public key authentication. rules: - sshd_enable_pubkey_auth status: automated - id: RHEL-09-255040 levels: - high title: RHEL 9 SSHD must not allow blank passwords. rules: - sshd_disable_empty_passwords status: automated - id: RHEL-09-255045 levels: - medium title: RHEL 9 must not permit direct logons to the root account using remote access via SSH. rules: - sshd_disable_root_login status: automated - id: RHEL-09-255050 levels: - high title: RHEL 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD. rules: - sshd_enable_pam status: automated - id: RHEL-09-255055 levels: - medium title: RHEL 9 SSH daemon must be configured to use system-wide crypto policies. rules: - file_sshd_50_redhat_exists - sshd_include_crypto_policy status: automated - id: RHEL-09-255060 levels: - medium title: RHEL 9 must implement DOD-approved encryption ciphers to protect the confidentiality of SSH client connections. rules: - sshd_include_crypto_policy status: automated - id: RHEL-09-255064 title: The RHEL 9 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. levels: - medium rules: - harden_sshd_ciphers_openssh_conf_crypto_policy - sshd_approved_ciphers=stig_rhel9 - id: RHEL-09-255065 levels: - medium title: RHEL 9 must implement DOD-approved encryption ciphers to protect the confidentiality of SSH server connections. rules: - harden_sshd_ciphers_opensshserver_conf_crypto_policy - sshd_approved_ciphers=stig_rhel9 status: automated - id: RHEL-09-255070 levels: - medium title: The RHEL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. rules: - harden_sshd_macs_openssh_conf_crypto_policy - sshd_approved_macs=stig_rhel9 - id: RHEL-09-255075 levels: - medium title: RHEL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms. status: automated rules: - harden_sshd_macs_opensshserver_conf_crypto_policy - sshd_approved_macs=stig_rhel9 - id: RHEL-09-255080 levels: - medium title: RHEL 9 must not allow a noncertificate trusted host SSH logon to the system. rules: - disable_host_auth status: automated - id: RHEL-09-255085 levels: - medium title: RHEL 9 must not allow users to override SSH environment variables. rules: - sshd_do_not_permit_user_env status: automated - id: RHEL-09-255090 levels: - medium title: RHEL 9 must force a frequent session key renegotiation for SSH connections to the server. rules: - sshd_rekey_limit - var_rekey_limit_size=1G - var_rekey_limit_time=1hour status: automated - id: RHEL-09-255095 levels: - medium title: RHEL 9 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive. rules: - sshd_set_keepalive - var_sshd_set_keepalive=1 status: automated - id: RHEL-09-255100 levels: - medium title: RHEL 9 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive. rules: - sshd_set_idle_timeout - sshd_idle_timeout_value=10_minutes status: automated - id: RHEL-09-255105 levels: - medium title: RHEL 9 SSH server configuration file must be group-owned by root. rules: - file_groupowner_sshd_config - directory_groupowner_sshd_config_d - file_groupowner_sshd_drop_in_config status: automated - id: RHEL-09-255110 levels: - medium title: RHEL 9 SSH server configuration file must be owned by root. rules: - file_owner_sshd_config - directory_owner_sshd_config_d - file_owner_sshd_drop_in_config status: automated - id: RHEL-09-255115 levels: - medium title: RHEL 9 SSH server configuration file must have mode 0600 or less permissive. rules: - file_permissions_sshd_config - directory_permissions_sshd_config_d - file_permissions_sshd_drop_in_config status: automated - id: RHEL-09-255120 levels: - medium title: RHEL 9 SSH private host key files must have mode 0640 or less permissive. rules: - file_permissions_sshd_private_key status: automated - id: RHEL-09-255125 levels: - medium title: RHEL 9 SSH public host key files must have mode 0644 or less permissive. rules: - file_permissions_sshd_pub_key status: automated - id: RHEL-09-255130 levels: - medium title: RHEL 9 SSH daemon must not allow compression or must only allow compression after successful authentication. rules: - sshd_disable_compression - var_sshd_disable_compression=no status: automated - id: RHEL-09-255135 levels: - medium title: RHEL 9 SSH daemon must not allow GSSAPI authentication. rules: - sshd_disable_gssapi_auth status: automated - id: RHEL-09-255140 levels: - medium title: RHEL 9 SSH daemon must not allow Kerberos authentication. rules: - sshd_disable_kerb_auth status: automated - id: RHEL-09-255145 levels: - medium title: RHEL 9 SSH daemon must not allow rhosts authentication. rules: - sshd_disable_rhosts status: automated - id: RHEL-09-255150 levels: - medium title: RHEL 9 SSH daemon must not allow known hosts authentication. rules: - sshd_disable_user_known_hosts status: automated - id: RHEL-09-255155 levels: - medium title: RHEL 9 SSH daemon must disable remote X connections for interactive users. rules: - sshd_disable_x11_forwarding status: automated - id: RHEL-09-255160 levels: - medium title: RHEL 9 SSH daemon must perform strict mode checking of home directory configuration files. rules: - sshd_enable_strictmodes status: automated - id: RHEL-09-255165 levels: - medium title: RHEL 9 SSH daemon must display the date and time of the last successful account logon upon an SSH logon. rules: - sshd_print_last_log status: automated - id: RHEL-09-255175 levels: - medium title: RHEL 9 SSH daemon must prevent remote hosts from connecting to the proxy display. rules: - sshd_x11_use_localhost status: automated - id: RHEL-09-271010 levels: - medium title: RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon. rules: - dconf_gnome_banner_enabled status: automated - id: RHEL-09-271015 levels: - medium title: RHEL 9 must prevent a user from overriding the banner-message-enable setting for the graphical user interface. rules: - dconf_gnome_banner_enabled status: automated - id: RHEL-09-271020 levels: - medium title: RHEL 9 must disable the graphical user interface automount function unless required. rules: - dconf_gnome_disable_automount_open status: automated - id: RHEL-09-271025 levels: - medium title: RHEL 9 must prevent a user from overriding the disabling of the graphical user interface automount function. rules: - dconf_gnome_disable_automount_open status: automated - id: RHEL-09-271030 levels: - medium title: RHEL 9 must disable the graphical user interface autorun function unless required. rules: - dconf_gnome_disable_autorun status: automated - id: RHEL-09-271035 levels: - medium title: RHEL 9 must prevent a user from overriding the disabling of the graphical user interface autorun function. rules: - dconf_gnome_disable_autorun status: automated - id: RHEL-09-271040 levels: - high title: RHEL 9 must not allow unattended or automatic logon via the graphical user interface. rules: - gnome_gdm_disable_automatic_login status: automated - id: RHEL-09-271045 levels: - medium title: RHEL 9 must be able to initiate directly a session lock for all connection types using smart card when the smart card is removed. rules: - dconf_gnome_lock_screen_on_smartcard_removal status: automated - id: RHEL-09-271050 levels: - medium title: RHEL 9 must prevent a user from overriding the disabling of the graphical user smart card removal action. rules: - dconf_gnome_lock_screen_on_smartcard_removal status: automated - id: RHEL-09-271055 levels: - medium title: RHEL 9 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions. rules: - dconf_gnome_screensaver_lock_enabled status: automated - id: RHEL-09-271060 levels: - medium title: RHEL 9 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface. rules: - dconf_gnome_screensaver_lock_enabled status: automated - id: RHEL-09-271065 levels: - medium title: RHEL 9 must automatically lock graphical user sessions after 15 minutes of inactivity. rules: - dconf_gnome_screensaver_idle_delay status: automated - id: RHEL-09-271070 levels: - medium title: RHEL 9 must prevent a user from overriding the session idle-delay setting for the graphical user interface. rules: - dconf_gnome_session_idle_user_locks status: automated - id: RHEL-09-271075 levels: - medium title: RHEL 9 must initiate a session lock for graphical user interfaces when the screensaver is activated. rules: - dconf_gnome_screensaver_lock_delay status: automated - id: RHEL-09-271080 levels: - medium title: RHEL 9 must prevent a user from overriding the session lock-delay setting for the graphical user interface. rules: - dconf_gnome_screensaver_user_locks status: automated - id: RHEL-09-271085 levels: - medium title: RHEL 9 must conceal, via the session lock, information previously visible on the display with a publicly viewable image. rules: - dconf_gnome_screensaver_mode_blank status: automated - id: RHEL-09-271090 levels: - medium title: RHEL 9 effective dconf policy must match the policy keyfiles. rules: - dconf_db_up_to_date status: automated - id: RHEL-09-271095 levels: - medium title: RHEL 9 must disable the ability of a user to restart the system from the login screen. rules: - dconf_gnome_disable_restart_shutdown status: automated - id: RHEL-09-271100 levels: - medium title: RHEL 9 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface. rules: - dconf_gnome_disable_restart_shutdown status: automated - id: RHEL-09-271105 levels: - medium title: RHEL 9 must disable the ability of a user to accidentally press Ctrl-Alt-Del and cause a system to shut down or reboot. rules: - dconf_gnome_disable_ctrlaltdel_reboot status: automated - id: RHEL-09-271110 levels: - medium title: RHEL 9 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface. rules: - dconf_gnome_disable_ctrlaltdel_reboot status: automated - id: RHEL-09-271115 levels: - medium title: RHEL 9 must disable the user list at logon for graphical user interfaces. rules: - dconf_gnome_disable_user_list status: automated - id: RHEL-09-291010 levels: - medium title: RHEL 9 must be configured to disable USB mass storage. rules: - kernel_module_usb-storage_disabled status: automated - id: RHEL-09-291015 levels: - medium title: RHEL 9 must have the USBGuard package installed. rules: - package_usbguard_installed status: automated - id: RHEL-09-291020 levels: - medium title: RHEL 9 must have the USBGuard package enabled. rules: - service_usbguard_enabled status: automated - id: RHEL-09-291025 levels: - low title: RHEL 9 must enable Linux audit logging for the USBGuard daemon. rules: - configure_usbguard_auditbackend status: automated - id: RHEL-09-291030 levels: - medium title: RHEL 9 must block unauthorized peripherals before establishing a connection. rules: - usbguard_generate_policy status: automated - id: RHEL-09-291035 levels: - medium title: RHEL 9 Bluetooth must be disabled. rules: - kernel_module_bluetooth_disabled status: automated - id: RHEL-09-291040 levels: - medium title: RHEL 9 wireless network adapters must be disabled. rules: - wireless_disable_interfaces status: automated - id: RHEL-09-411010 levels: - medium title: RHEL 9 user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs. rules: - accounts_maximum_age_login_defs status: automated - id: RHEL-09-411015 levels: - medium title: RHEL 9 user account passwords must have a 60-day maximum password lifetime restriction. rules: - accounts_password_set_max_life_existing - var_accounts_maximum_age_login_defs=60 status: automated - id: RHEL-09-411020 levels: - medium title: All RHEL 9 local interactive user accounts must be assigned a home directory upon creation. rules: - accounts_have_homedir_login_defs status: automated - id: RHEL-09-411025 levels: - medium title: RHEL 9 must set the umask value to 077 for all local interactive user accounts. rules: - accounts_umask_interactive_users - var_accounts_user_umask=077 status: automated - id: RHEL-09-411030 levels: - medium title: RHEL 9 duplicate User IDs (UIDs) must not exist for interactive users. rules: - account_unique_id status: automated - id: RHEL-09-411035 levelException while handling file: /builddir/build/BUILD/scap-security-guide-0.1.79/products/rhel9/controls/stig_rhel9.yml s: - medium title: RHEL 9 system accounts must not have an interactive login shell. rules: - no_shelllogin_for_systemaccounts status: automated - id: RHEL-09-411040 levels: - medium title: RHEL 9 must automatically expire temporary accounts within 72 hours. rules: - account_temp_expire_date status: automated - id: RHEL-09-411045 levels: - medium title: All RHEL 9 interactive users must have a primary group that exists. rules: - gid_passwd_group_same status: automated - id: RHEL-09-411050 levels: - medium title: RHEL 9 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. rules: - account_disable_post_pw_expiration - var_account_disable_post_pw_expiration=35 status: automated - id: RHEL-09-411055 levels: - medium title: Executable search paths within the initialization files of all local interactive RHEL 9 users must only contain paths that resolve to the system default or the users home directory. rules: - accounts_user_home_paths_only status: automated - id: RHEL-09-411060 levels: - medium title: All RHEL 9 local interactive users must have a home directory assigned in the /etc/passwd file. rules: - accounts_user_interactive_home_directory_defined status: automated - id: RHEL-09-411065 levels: - medium title: All RHEL 9 local interactive user home directories defined in the /etc/passwd file must exist. rules: - accounts_user_interactive_home_directory_exists status: automated - id: RHEL-09-411070 levels: - medium title: All RHEL 9 local interactive user home directories must be group-owned by the home directory owner's primary group. rules: - file_groupownership_home_directories status: automated - id: RHEL-09-411075 levels: - medium title: RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur. rules: - accounts_passwords_pam_faillock_deny - var_accounts_passwords_pam_faillock_deny=3 status: automated - id: RHEL-09-411080 levels: - medium title: RHEL 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. rules: - accounts_passwords_pam_faillock_deny_root status: automated - id: RHEL-09-411085 levels: - medium title: RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. rules: - accounts_passwords_pam_faillock_interval - var_accounts_passwords_pam_faillock_fail_interval=900 status: automated - id: RHEL-09-411090 levels: - medium title: RHEL 9 must maintain an account lock until the locked account is released by an administrator. rules: - accounts_passwords_pam_faillock_unlock_time - var_accounts_passwords_pam_faillock_unlock_time=never status: automated - id: RHEL-09-411095 levels: - medium title: RHEL 9 must not have unauthorized accounts. rules: - accounts_authorized_local_users - var_accounts_authorized_local_users_regex=rhel9 status: automated - id: RHEL-09-411100 levels: - high title: The root account must be the only account having unrestricted access to RHEL 9 system. rules: - accounts_no_uid_except_zero status: automated - id: RHEL-09-411105 levels: - medium title: RHEL 9 must ensure account lockouts persist. rules: - accounts_passwords_pam_faillock_dir status: automated - id: RHEL-09-411110 levels: - medium title: RHEL 9 groups must have unique Group ID (GID). rules: - group_unique_id status: automated - id: RHEL-09-411115 levels: - medium title: Local RHEL 9 initialization files must not execute world-writable programs. rules: - accounts_user_dot_no_world_writable_programs status: automated - id: RHEL-09-412035 levels: - medium title: RHEL 9 must automatically exit interactive command shell user sessions after 15 minutes of inactivity. rules: - accounts_tmout - var_accounts_tmout=10_min status: automated - id: RHEL-09-412040 levels: - low title: RHEL 9 must limit the number of concurrent sessions to ten for all accounts and/or account types. rules: - accounts_max_concurrent_login_sessions - var_accounts_max_concurrent_login_sessions=10 status: automated - id: RHEL-09-412045 levels: - medium title: RHEL 9 must log username information when unsuccessful logon attempts occur. rules: - accounts_passwords_pam_faillock_audit status: automated - id: RHEL-09-412050 levels: - medium title: RHEL 9 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt. rules: - accounts_logon_fail_delay - var_accounts_fail_delay=4 status: automated - id: RHEL-09-412055 levels: - medium title: RHEL 9 must define default permissions for the bash shell. rules: - accounts_umask_etc_bashrc status: automated - id: RHEL-09-412060 levels: - medium title: RHEL 9 must define default permissions for the c shell. rules: - accounts_umask_etc_csh_cshrc status: automated - id: RHEL-09-412065 levels: - medium title: RHEL 9 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files. rules: - accounts_umask_etc_login_defs status: automated - id: RHEL-09-412070 levels: - medium title: RHEL 9 must define default permissions for the system default profile. rules: - accounts_umask_etc_profile status: automated - id: RHEL-09-412075 levels: - low title: RHEL 9 must display the date and time of the last successful account logon upon logon. rules: - display_login_attempts status: automated - id: RHEL-09-412080 levels: - medium title: RHEL 9 must terminate idle user sessions. rules: - logind_session_timeout - var_logind_session_timeout=15_minutes status: automated - id: RHEL-09-431010 levels: - high title: RHEL 9 must use a Linux Security Module configured to enforce limits on system services. rules: - selinux_state - var_selinux_state=enforcing status: automated - id: RHEL-09-431015 levels: - medium title: RHEL 9 must enable the SELinux targeted policy. rules: - selinux_policytype - var_selinux_policy_name=targeted status: automated - id: RHEL-09-431016 title: 'RHEL 9 must elevate the SELinux context when an administrator calls the sudo command.' rules: - selinux_context_elevation_for_sudo status: automated - id: RHEL-09-431020 levels: - medium title: RHEL 9 must configure SELinux context type to allow the use of a nondefault faillock tally directory. rules: - account_password_selinux_faillock_dir status: automated - id: RHEL-09-431025 levels: - medium title: RHEL 9 must have policycoreutils package installed. rules: - package_policycoreutils_installed status: automated - id: RHEL-09-431030 levels: - medium title: RHEL 9 policycoreutils-python-utils package must be installed. rules: - package_policycoreutils-python-utils_installed status: automated - id: RHEL-09-432010 levels: - medium title: RHEL 9 must have the sudo package installed. rules: - package_sudo_installed status: automated - id: RHEL-09-432015 levels: - medium title: RHEL 9 must require reauthentication when using the "sudo" command. rules: - sudo_require_reauthentication - var_sudo_timestamp_timeout=always_prompt status: automated - id: RHEL-09-432020 levels: - medium title: RHEL 9 must use the invoking user's password for privilege escalation when using "sudo". rules: - sudoers_validate_passwd status: automated - id: RHEL-09-432025 levels: - medium title: RHEL 9 must require users to reauthenticate for privilege escalation. rules: - sudo_remove_no_authenticate status: automated - id: RHEL-09-432030 levels: - medium title: RHEL 9 must restrict privilege elevation to authorized personnel. rules: - sudo_restrict_privilege_elevation_to_authorized status: automated - id: RHEL-09-432035 levels: - medium title: RHEL 9 must restrict the use of the "su" command. rules: - use_pam_wheel_for_su status: automated - id: RHEL-09-433010 levels: - medium title: RHEL 9 fapolicy module must be installed. rules: - package_fapolicyd_installed status: automated - id: RHEL-09-433015 levels: - medium title: RHEL 9 fapolicy module must be enabled. rules: - service_fapolicyd_enabled status: automated - id: RHEL-09-433016 levels: - medium title: The RHEL 9 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. rules: - fapolicy_default_deny status: automated - id: RHEL-09-611010 levels: - medium title: RHEL 9 must ensure the password complexity module in the system-auth file is configured for three retries or less. rules: - accounts_password_pam_pwquality_retry - var_password_pam_retry=3 status: automated - id: RHEL-09-611025 levels: - high title: RHEL 9 must not allow blank or null passwords. rules: - no_empty_passwords status: automated - id: RHEL-09-611030 levels: - medium title: RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. rules: - account_password_pam_faillock_system_auth status: automated - id: RHEL-09-611035 levels: - medium title: RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file. rules: - account_password_pam_faillock_password_auth status: automated - id: RHEL-09-611040 levels: - medium title: RHEL 9 must ensure the password complexity module is enabled in the password-auth file. rules: - accounts_password_pam_pwquality_password_auth status: automated - id: RHEL-09-611045 levels: - medium title: RHEL 9 must ensure the password complexity module is enabled in the system-auth file. rules: - accounts_password_pam_pwquality_system_auth status: automated - id: RHEL-09-611050 levels: - medium title: RHEL 9 password-auth must be configured to use a sufficient number of hashing rounds. rules: - accounts_password_pam_unix_rounds_password_auth - var_password_pam_unix_rounds=100000 status: automated - id: RHEL-09-611055 levels: - medium title: RHEL 9 system-auth must be configured to use a sufficient number of hashing rounds. rules: - accounts_password_pam_unix_rounds_system_auth status: automated - id: RHEL-09-611060 levels: - medium title: RHEL 9 must enforce password complexity rules for the root account. rules: - accounts_password_pam_enforce_root status: automated - id: RHEL-09-611065 levels: - medium title: RHEL 9 must enforce password complexity by requiring that at least one lowercase character be used. rules: - accounts_password_pam_lcredit - var_password_pam_lcredit=1 status: automated - id: RHEL-09-611070 levels: - medium title: RHEL 9 must enforce password complexity by requiring that at least one numeric character be used. rules: - accounts_password_pam_dcredit - var_password_pam_dcredit=1 status: automated - id: RHEL-09-611075 levels: - medium title: RHEL 9 passwords for new users or password changes must have a 24 hours minimum password lifetime restriction in /etc/login.defs. rules: - accounts_minimum_age_login_defs status: automated - id: RHEL-09-611080 levels: - medium title: RHEL 9 passwords must have a 24 hours minimum password lifetime restriction in /etc/shadow. rules: - accounts_password_set_min_life_existing - var_accounts_minimum_age_login_defs=1 status: automated - id: RHEL-09-611085 levels: - medium title: RHEL 9 must require users to provide a password for privilege escalation. rules: - sudo_remove_nopasswd status: automated - id: RHEL-09-611090 levels: - medium title: RHEL 9 passwords must be created with a minimum of 15 characters. rules: - accounts_password_pam_minlen - var_password_pam_minlen=15 status: automated - id: RHEL-09-611100 levels: - medium title: RHEL 9 must enforce password complexity by requiring that at least one special character be used. rules: - accounts_password_pam_ocredit - var_password_pam_ocredit=1 status: automated - id: RHEL-09-611105 levels: - medium title: RHEL 9 must prevent the use of dictionary words for passwords. rules: - accounts_password_pam_dictcheck - var_password_pam_dictcheck=1 status: automated - id: RHEL-09-611110 levels: - medium title: RHEL 9 must enforce password complexity by requiring that at least one uppercase character be used. rules: - accounts_password_pam_ucredit - var_password_pam_ucredit=1 status: automated - id: RHEL-09-611115 levels: - medium title: RHEL 9 must require the change of at least eight characters when passwords are changed. rules: - accounts_password_pam_difok - var_password_pam_difok=8 status: automated - id: RHEL-09-611120 levels: - medium title: RHEL 9 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed. rules: - accounts_password_pam_maxclassrepeat - var_password_pam_maxclassrepeat=4 status: automated - id: RHEL-09-611125 levels: - medium title: RHEL 9 must require the maximum number of repeating characters be limited to three when passwords are changed. rules: - accounts_password_pam_maxrepeat - var_password_pam_maxrepeat=3 status: automated - id: RHEL-09-611130 levels: - medium title: RHEL 9 must require the change of at least four character classes when passwords are changed. rules: - accounts_password_pam_minclass - var_password_pam_minclass=4 status: automated - id: RHEL-09-611135 levels: - medium title: RHEL 9 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords. rules: - set_password_hashing_algorithm_libuserconf - var_password_hashing_algorithm_pam=sha512 status: automated - id: RHEL-09-611140 levels: - medium title: RHEL 9 must be configured to use the shadow file to store only encrypted representations of passwords. rules: - set_password_hashing_algorithm_logindefs - var_password_hashing_algorithm=SHA512 status: automated - id: RHEL-09-611145 levels: - medium title: RHEL 9 must not be configured to bypass password requirements for privilege escalation. rules: - disallow_bypass_password_sudo status: automated - id: RHEL-09-611155 levels: - medium title: RHEL 9 must not have accounts configured with blank or null passwords. rules: - no_empty_passwords_etc_shadow status: automated - id: RHEL-09-611160 levels: - medium title: RHEL 9 must use the CAC smart card driver. rules: - configure_opensc_card_drivers - var_smartcard_drivers=cac status: automated - id: RHEL-09-611165 levels: - medium title: RHEL 9 must enable certificate based smart card authentication. rules: - sssd_enable_smartcards status: automated - id: RHEL-09-611170 levels: - medium title: RHEL 9 must implement certificate status checking for multifactor authentication. rules: - sssd_certificate_verification - var_sssd_certificate_verification_digest_function=sha512 status: automated - id: RHEL-09-611175 levels: - medium title: RHEL 9 must have the pcsc-lite package installed. rules: - package_pcsc-lite_installed status: automated - id: RHEL-09-611180 levels: - medium title: The pcscd service on RHEL 9 must be active. rules: - service_pcscd_enabled status: automated - id: RHEL-09-611185 levels: - medium title: RHEL 9 must have the opensc package installed. rules: - package_opensc_installed status: automated - id: RHEL-09-611190 levels: - medium title: RHEL 9, for PKI-based authentication, must enforce authorized access to the corresponding private key. rules: - ssh_keys_passphrase_protected status: automated - id: RHEL-09-611195 levels: - medium title: RHEL 9 must require authentication to access emergency mode. rules: - require_emergency_target_auth status: automated - id: RHEL-09-611200 levels: - medium title: RHEL 9 must require authentication to access single-user mode. rules: - require_singleuser_auth status: automated - id: RHEL-09-631010 levels: - medium title: RHEL 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. rules: - sssd_has_trust_anchor status: automated - id: RHEL-09-631015 levels: - medium title: RHEL 9 must map the authenticated identity to the user or group account for PKI-based authentication. rules: - sssd_enable_certmap status: automated - id: RHEL-09-631020 levels: - medium title: RHEL 9 must prohibit the use of cached authenticators after one day. rules: - sssd_offline_cred_expiration status: automated - id: RHEL-09-651010 levels: - medium title: RHEL 9 must have the AIDE package installed. rules: - package_aide_installed - aide_build_database status: automated - id: RHEL-09-651015 levels: - medium title: RHEL 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered. rules: - aide_scan_notification status: automated - id: RHEL-09-651020 levels: - medium title: RHEL 9 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories. rules: - aide_use_fips_hashes status: automated - id: RHEL-09-651025 levels: - medium title: RHEL 9 must use cryptographic mechanisms to protect the integrity of audit tools. rules: - aide_check_audit_tools status: automated - id: RHEL-09-651030 levels: - low title: RHEL 9 must be configured so that the file integrity tool verifies Access Control Lists (ACLs). rules: - aide_verify_acls status: automated - id: RHEL-09-651035 levels: - low title: RHEL 9 must be configured so that the file integrity tool verifies extended attributes. rules: - aide_verify_ext_attributes status: automated - id: RHEL-09-652010 levels: - medium title: RHEL 9 must have the rsyslog package installed. rules: - package_rsyslog_installed status: automated - id: RHEL-09-652015 levels: - medium title: RHEL 9 must have the packages required for encrypting offloaded audit logs installed. rules: - package_rsyslog-gnutls_installed status: automated - id: RHEL-09-652020 levels: - medium title: The rsyslog service on RHEL 9 must be active. rules: - service_rsyslog_enabled status: automated - id: RHEL-09-652025 levels: - medium title: RHEL 9 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation. rules: - rsyslog_nolisten status: automated - id: RHEL-09-652030 levels: - medium title: All RHEL 9 remote access methods must be monitored. rules: - rsyslog_remote_access_monitoring status: automated - id: RHEL-09-652040 levels: - medium title: RHEL 9 must authenticate the remote logging server for offloading audit logs via rsyslog. rules: - rsyslog_encrypt_offload_actionsendstreamdriverauthmode status: automated - id: RHEL-09-652045 levels: - medium title: RHEL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog. rules: - rsyslog_encrypt_offload_actionsendstreamdrivermode status: automated - id: RHEL-09-652050 levels: - medium title: RHEL 9 must encrypt via the gtls driver the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog. rules: - rsyslog_encrypt_offload_defaultnetstreamdriver status: automated - id: RHEL-09-652055 levels: - medium title: RHEL 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog. rules: - rsyslog_remote_loghost status: automated - id: RHEL-09-652060 levels: - medium title: RHEL 9 must use cron logging. rules: - rsyslog_cron_logging status: automated - id: RHEL-09-653010 levels: - medium title: RHEL 9 audit package must be installed. rules: - package_audit_installed status: automated - id: RHEL-09-653015 levels: - medium title: RHEL 9 audit service must be enabled. rules: - service_auditd_enabled status: automated - id: RHEL-09-653020 levels: - medium title: RHEL 9 audit system must take appropriate action when an error writing to the audit storage volume occurs. rules: - auditd_data_disk_error_action_stig - var_auditd_disk_error_action=halt status: automated - id: RHEL-09-653025 levels: - medium title: RHEL 9 audit system must take appropriate action when the audit storage volume is full. rules: - auditd_data_disk_full_action_stig - var_auditd_disk_full_action=halt status: automated - id: RHEL-09-653030 levels: - medium title: RHEL 9 must allocate audit record storage capacity to store at least one week's worth of audit records. rules: - auditd_audispd_configure_sufficiently_large_partition status: automated - id: RHEL-09-653035 levels: - medium title: RHEL 9 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity. rules: - auditd_data_retention_space_left_percentage - var_auditd_space_left_percentage=25pc status: automated - id: RHEL-09-653040 levels: - medium title: RHEL 9 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization. rules: - auditd_data_retention_space_left_action - var_auditd_space_left_action=email status: automated - id: RHEL-09-653045 levels: - medium title: RHEL 9 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity. rules: - auditd_data_retention_admin_space_left_percentage - var_auditd_admin_space_left_percentage=5pc status: automated - id: RHEL-09-653050 levels: - medium title: RHEL 9 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity. rules: - auditd_data_retention_admin_space_left_action - var_auditd_admin_space_left_action=single status: automated - id: RHEL-09-653055 levels: - medium title: RHEL 9 audit system must take appropriate action when the audit files have reached maximum size. rules: - auditd_data_retention_max_log_file_action_stig - var_auditd_max_log_file_action=rotate status: automated - id: RHEL-09-653060 levels: - medium title: RHEL 9 must label all offloaded audit logs before sending them to the central log server. rules: - auditd_name_format - var_auditd_name_format=stig status: automated - id: RHEL-09-653065 levels: - medium title: RHEL 9 must take appropriate action when the internal event queue is full. rules: - auditd_overflow_action status: automated - id: RHEL-09-653070 levels: - medium title: RHEL 9 System Administrator (SA) and/or information system security officer (ISSO) (at a minimum) must be alerted of an audit processing failure event. rules: - auditd_data_retention_action_mail_acct - var_auditd_action_mail_acct=root status: automated - id: RHEL-09-653075 levels: - medium title: RHEL 9 audit system must audit local events. rules: - auditd_local_events status: automated - id: RHEL-09-653080 levels: - medium title: RHEL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access. rules: - directory_group_ownership_var_log_audit status: automated - id: RHEL-09-653085 levels: - medium title: RHEL 9 audit log directory must be owned by root to prevent unauthorized read access. rules: - directory_ownership_var_log_audit status: automated - id: RHEL-09-653090 levels: - medium title: RHEL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log. rules: - file_permissions_var_log_audit status: automated - id: RHEL-09-653095 levels: - medium title: RHEL 9 must periodically flush audit records to disk to prevent the loss of audit records. rules: - auditd_freq - var_auditd_freq=100 status: automated - id: RHEL-09-653100 levels: - medium title: RHEL 9 must produce audit records containing information to establish the identity of any individual or process associated with the event. rules: - auditd_log_format status: automated - id: RHEL-09-653105 levels: - medium title: RHEL 9 must write audit records to disk. rules: - auditd_write_logs status: automated - id: RHEL-09-653110 levels: - medium title: RHEL 9 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. rules: - file_permissions_audit_configuration status: automated - id: RHEL-09-653115 levels: - medium title: RHEL 9 /etc/audit/auditd.conf file must have 0640 or less permissive to prevent unauthorized access. rules: - file_permissions_etc_audit_auditd status: automated - id: RHEL-09-653120 levels: - low title: RHEL 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon. rules: - grub2_audit_backlog_limit_argument - var_audit_backlog_limit=8192 status: automated - id: RHEL-09-653125 levels: - medium title: RHEL 9 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure. rules: - postfix_client_configure_mail_alias status: automated - id: RHEL-09-653130 levels: - medium title: RHEL 9 audispd-plugins package must be installed. rules: - package_audispd-plugins_installed status: automated - id: RHEL-09-654010 levels: - medium title: RHEL 9 must audit uses of the "execve" system call. rules: - audit_rules_suid_privilege_function status: automated - id: RHEL-09-654015 levels: - medium title: RHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls. rules: - audit_rules_dac_modification_chmod - audit_rules_dac_modification_fchmod - audit_rules_dac_modification_fchmodat status: automated - id: RHEL-09-654020 levels: - medium title: RHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls. rules: - audit_rules_dac_modification_chown - audit_rules_dac_modification_fchown - audit_rules_dac_modification_fchownat - audit_rules_dac_modification_lchown status: automated - id: RHEL-09-654025 levels: - medium title: RHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls. rules: - audit_rules_dac_modification_setxattr - audit_rules_dac_modification_fsetxattr - audit_rules_dac_modification_lsetxattr - audit_rules_dac_modification_removexattr - audit_rules_dac_modification_fremovexattr - audit_rules_dac_modification_lremovexattr status: automated - id: RHEL-09-654030 levels: - medium title: RHEL 9 must audit all uses of umount system calls. rules: - audit_rules_privileged_commands_umount status: automated - id: RHEL-09-654035 levels: - medium title: RHEL 9 must audit all uses of the chacl command. rules: - audit_rules_execution_chacl status: automated - id: RHEL-09-654040 levels: - medium title: RHEL 9 must audit all uses of the setfacl command. rules: - audit_rules_execution_setfacl status: automated - id: RHEL-09-654045 levels: - medium title: RHEL 9 must audit all uses of the chcon command. rules: - audit_rules_execution_chcon status: automated - id: RHEL-09-654050 levels: - medium title: RHEL 9 must audit all uses of the semanage command. rules: - audit_rules_execution_semanage status: automated - id: RHEL-09-654055 levels: - medium title: RHEL 9 must audit all uses of the setfiles command. rules: - audit_rules_execution_setfiles status: automated - id: RHEL-09-654060 levels: - medium title: RHEL 9 must audit all uses of the setsebool command. rules: - audit_rules_execution_setsebool status: automated - id: RHEL-09-654065 levels: - medium title: RHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls. rules: - audit_rules_file_deletion_events_rename - audit_rules_file_deletion_events_unlink - audit_rules_file_deletion_events_rmdir - audit_rules_file_deletion_events_renameat - audit_rules_file_deletion_events_unlinkat status: automated - id: RHEL-09-654070 levels: - medium title: RHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls. rules: - audit_rules_unsuccessful_file_modification_creat - audit_rules_unsuccessful_file_modification_truncate - audit_rules_unsuccessful_file_modification_ftruncate - audit_rules_unsuccessful_file_modification_open - audit_rules_unsuccessful_file_modification_openat - audit_rules_unsuccessful_file_modification_open_by_handle_at status: automated - id: RHEL-09-654075 levels: - medium title: RHEL 9 must audit all uses of the delete_module system call. rules: - audit_rules_kernel_module_loading_delete status: automated - id: RHEL-09-654080 levels: - medium title: RHEL 9 must audit all uses of the init_module and finit_module system calls. rules: - audit_rules_kernel_module_loading_finit - audit_rules_kernel_module_loading_init status: automated - id: RHEL-09-654085 levels: - medium title: RHEL 9 must audit all uses of the chage command. rules: - audit_rules_privileged_commands_chage status: automated - id: RHEL-09-654090 levels: - medium title: RHEL 9 must audit all uses of the chsh command. rules: - audit_rules_privileged_commands_chsh status: automated - id: RHEL-09-654095 levels: - medium title: RHEL 9 must audit all uses of the crontab command. rules: - audit_rules_privileged_commands_crontab status: automated - id: RHEL-09-654096 title: RHEL 9 must audit any script or executable called by cron as root or by any privileged user. rules: - audit_rules_etc_cron_d - audit_rules_var_spool_cron status: automated - id: RHEL-09-654100 levels: - medium title: RHEL 9 must audit all uses of the gpasswd command. rules: - audit_rules_privileged_commands_gpasswd status: automated - id: RHEL-09-654105 levels: - medium title: RHEL 9 must audit all uses of the kmod command. rules: - audit_rules_privileged_commands_kmod status: automated - id: RHEL-09-654110 levels: - medium title: RHEL 9 must audit all uses of the newgrp command. rules: - audit_rules_privileged_commands_newgrp status: automated - id: RHEL-09-654115 levels: - medium title: RHEL 9 must audit all uses of the pam_timestamp_check command. rules: - audit_rules_privileged_commands_pam_timestamp_check status: automated - id: RHEL-09-654120 levels: - medium title: RHEL 9 must audit all uses of the passwd command. rules: - audit_rules_privileged_commands_passwd status: automated - id: RHEL-09-654125 levels: - medium title: RHEL 9 must audit all uses of the postdrop command. rules: - audit_rules_privileged_commands_postdrop status: automated - id: RHEL-09-654130 levels: - medium title: RHEL 9 must audit all uses of the postqueue command. rules: - audit_rules_privileged_commands_postqueue status: automated - id: RHEL-09-654135 levels: - medium title: RHEL 9 must audit all uses of the ssh-agent command. rules: - audit_rules_privileged_commands_ssh_agent status: automated - id: RHEL-09-654140 levels: - medium title: RHEL 9 must audit all uses of the ssh-keysign command. rules: - audit_rules_privileged_commands_ssh_keysign status: automated - id: RHEL-09-654145 levels: - medium title: RHEL 9 must audit all uses of the su command. rules: - audit_rules_privileged_commands_su status: automated - id: RHEL-09-654150 levels: - medium title: RHEL 9 must audit all uses of the sudo command. rules: - audit_rules_privileged_commands_sudo status: automated - id: RHEL-09-654155 levels: - medium title: RHEL 9 must audit all uses of the sudoedit command. rules: - audit_rules_privileged_commands_sudoedit status: automated - id: RHEL-09-654160 levels: - medium title: RHEL 9 must audit all uses of the unix_chkpwd command. rules: - audit_rules_privileged_commands_unix_chkpwd status: automated - id: RHEL-09-654165 levels: - medium title: RHEL 9 must audit all uses of the unix_update command. rules: - audit_rules_privileged_commands_unix_update status: automated - id: RHEL-09-654170 levels: - medium title: RHEL 9 must audit all uses of the userhelper command. rules: - audit_rules_privileged_commands_userhelper status: automated - id: RHEL-09-654175 levels: - medium title: RHEL 9 must audit all uses of the usermod command. rules: - audit_rules_privileged_commands_usermod status: automated - id: RHEL-09-654180 levels: - medium title: RHEL 9 must audit all uses of the mount command. rules: - audit_rules_privileged_commands_mount status: automated - id: RHEL-09-654185 levels: - medium title: Successful/unsuccessful uses of the init command in RHEL 9 must generate an audit record. rules: - audit_privileged_commands_init status: automated - id: RHEL-09-654190 levels: - medium title: Successful/unsuccessful uses of the poweroff command in RHEL 9 must generate an audit record. rules: - audit_privileged_commands_poweroff status: automated - id: RHEL-09-654195 levels: - medium title: Successful/unsuccessful uses of the reboot command in RHEL 9 must generate an audit record. rules: - audit_privileged_commands_reboot status: automated - id: RHEL-09-654200 levels: - medium title: Successful/unsuccessful uses of the shutdown command in RHEL 9 must generate an audit record. rules: - audit_privileged_commands_shutdown status: automated - id: RHEL-09-654205 levels: - medium title: Successful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record. rules: - audit_rules_dac_modification_umount status: automated - id: RHEL-09-654210 levels: - medium title: Successful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record. rules: - audit_rules_dac_modification_umount2 status: automated - id: RHEL-09-654215 levels: - medium title: RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. rules: - audit_rules_sudoers status: automated - id: RHEL-09-654220 levels: - medium title: RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory. rules: - audit_rules_sudoers_d status: automated - id: RHEL-09-654225 levels: - medium title: RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group. rules: - audit_rules_usergroup_modification_group status: automated - id: RHEL-09-654230 levels: - medium title: RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow. rules: - audit_rules_usergroup_modification_gshadow status: automated - id: RHEL-09-654235 levels: - medium title: RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd. rules: - audit_rules_usergroup_modification_opasswd status: automated - id: RHEL-09-654240 levels: - medium title: RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd. rules: - audit_rules_usergroup_modification_passwd status: automated - id: RHEL-09-654245 levels: - medium title: RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. rules: - audit_rules_usergroup_modification_shadow status: automated - id: RHEL-09-654250 levels: - medium title: RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock. rules: - audit_rules_login_events_faillock status: automated - id: RHEL-09-654255 levels: - medium title: RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog. rules: - audit_rules_login_events_lastlog status: automated - id: RHEL-09-654260 levels: - medium title: RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog. rules: - audit_rules_login_events_tallylog status: automated - id: RHEL-09-654265 levels: - medium title: RHEL 9 must take appropriate action when a critical audit processing failure occurs. rules: - audit_rules_system_shutdown status: automated - id: RHEL-09-654270 levels: - medium title: RHEL 9 audit system must protect logon UIDs from unauthorized change. rules: - audit_rules_immutable_login_uids status: automated - id: RHEL-09-654275 levels: - medium title: RHEL 9 audit system must protect auditing rules from unauthorized change. rules: - audit_rules_immutable status: automated - id: RHEL-09-671010 levels: - high title: RHEL 9 must enable FIPS mode. rules: - enable_fips_mode - sysctl_crypto_fips_enabled - var_system_crypto_policy=fips_stig - enable_dracut_fips_module status: automated - id: RHEL-09-671015 levels: - medium title: RHEL 9 must employ FIPS 140-3 approved cryptographic hashing algorithms for all stored passwords. rules: - accounts_password_all_shadowed_sha512 status: automated - id: RHEL-09-671020 levels: - medium title: RHEL 9 IP tunnels must use FIPS 140-2/140-3 approved cryptographic algorithms. rules: - configure_libreswan_crypto_policy status: automated - id: RHEL-09-671025 levels: - medium title: RHEL 9 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3 approved cryptographic hashing algorithm for system authentication. rules: - set_password_hashing_algorithm_passwordauth status: automated - id: RHEL-09-672015 levels: - high title: RHEL 9 crypto policy files must match files shipped with the operating system. status: pending - id: RHEL-09-672020 levels: - medium title: RHEL 9 crypto policy must not be overridden. notes: Rules for this control are intentionally not implemented. Checking whether files under /etc/crypto-policies/back-ends/ are symlinks is not an appropriate way to verify the consistency of the system's cryptographic settings. The suggested fix mentioned in the STIG does not fully satisfy its own requirements, as it also symlinks the nss.config file. Furthermore, running sudo 'update-crypto-policies --set FIPS' is not a reliable way to ensure FIPS compliance. Customers should refer to the official Red Hat Documentation and use the 'fips=1' kernel option during system installation to ensure the system is in FIPS mode. More information can be found at: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/security_hardening/switching-rhel-to-fips-mode_security-hardening status: pending - id: RHEL-09-672025 levels: - medium title: RHEL 9 must use mechanisms meeting the requirements of applicable federal laws, executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module. rules: - configure_kerberos_crypto_policy status: automated - id: RHEL-09-672030 levels: - high title: RHEL 9 must implement DOD-approved TLS encryption in the GnuTLS package. rules: - configure_crypto_policy status: automated - id: RHEL-09-672050 levels: - medium title: RHEL 9 must implement DOD-approved encryption in the bind package. rules: - configure_bind_crypto_policy status: automated gmake[2]: *** [rhel9/CMakeFiles/rhel9-compile-all.dir/build.make:78: rhel9/ssg_build_compile_all-rhel9] Error 1 gmake[2]: Leaving directory '/builddir/build/BUILD/scap-security-guide-0.1.79/build' gmake[1]: Leaving directory '/builddir/build/BUILD/scap-security-guide-0.1.79/build' gmake[1]: *** [CMakeFiles/Makefile2:386: rhel9/CMakeFiles/rhel9-compile-all.dir/all] Error 2 gmake: *** [Makefile:157: all] Error 2 RPM build errors: error: Bad exit status from /var/tmp/rpm-tmp.Tpt2cd (%build) Bad exit status from /var/tmp/rpm-tmp.Tpt2cd (%build) Finish: rpmbuild scap-security-guide-0.1.79-0.20251113092050720330.pr14119.18545.ga45aadb5a1.el9.src.rpm Finish: build phase for scap-security-guide-0.1.79-0.20251113092050720330.pr14119.18545.ga45aadb5a1.el9.src.rpm INFO: chroot_scan: 3 files copied to /var/lib/copr-rpmbuild/results/chroot_scan INFO: /var/lib/mock/centos-stream-9-x86_64-1763025687.143490/root/var/log/dnf.rpm.log /var/lib/mock/centos-stream-9-x86_64-1763025687.143490/root/var/log/dnf.librepo.log /var/lib/mock/centos-stream-9-x86_64-1763025687.143490/root/var/log/dnf.log INFO: chroot_scan: creating tarball /var/lib/copr-rpmbuild/results/chroot_scan.tar.gz /bin/tar: Removing leading `/' from member names ERROR: Exception(/var/lib/copr-rpmbuild/results/scap-security-guide-0.1.79-0.20251113092050720330.pr14119.18545.ga45aadb5a1.el9.src.rpm) Config(centos-stream-9-x86_64) 0 minutes 17 seconds INFO: Results and/or logs in: /var/lib/copr-rpmbuild/results INFO: Cleaning up build root ('cleanup_on_failure=True') Start: clean chroot INFO: unmounting tmpfs. Finish: clean chroot ERROR: Command failed: # /usr/bin/systemd-nspawn -q -M bda2909ea78948cb80a00a9e4c5c533b -D /var/lib/mock/centos-stream-9-x86_64-1763025687.143490/root -a -u mockbuild --capability=cap_ipc_lock --capability=cap_ipc_lock --bind=/tmp/mock-resolv.0nw3kph9:/etc/resolv.conf --bind=/dev/btrfs-control --bind=/dev/mapper/control --bind=/dev/fuse --bind=/dev/loop-control --bind=/dev/loop0 --bind=/dev/loop1 --bind=/dev/loop2 --bind=/dev/loop3 --bind=/dev/loop4 --bind=/dev/loop5 --bind=/dev/loop6 --bind=/dev/loop7 --bind=/dev/loop8 --bind=/dev/loop9 --bind=/dev/loop10 --bind=/dev/loop11 --console=pipe --setenv=TERM=vt100 --setenv=SHELL=/bin/bash --setenv=HOME=/builddir --setenv=HOSTNAME=mock --setenv=PATH=/usr/bin:/bin:/usr/sbin:/sbin '--setenv=PROMPT_COMMAND=printf "\033]0;\007"' '--setenv=PS1= \s-\v\$ ' --setenv=LANG=C.UTF-8 --resolv-conf=off bash --login -c '/usr/bin/rpmbuild -bb --target x86_64 --nodeps /builddir/build/originals/scap-security-guide.spec' Copr build error: Build failed