My object looks like this-
<process58_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.owasp.oval:obj:1" version="0" comment="Object holds apache2 process info">
<command_line operation="pattern match">.*apache2 .*|.*httpd .*</command_line>
<pid datatype="int" operation="greater than">0</pid>
While collection of this object is just fine on ovaldi v 5.10, it doesn't work since ovaldi v 5.10.1. I am getting error -
2012-08-05T18:37:00 : DEBUG : Collecting object id: oval:org.owasp.oval:obj:1
2012-08-05T18:37:00 : DEBUG : Error while collecting data for object: oval:org.owasp.oval:obj:1 context_new(unconfined
2012-08-05T18:37:00 : DEBUG : Collecting object id: oval:org.owasp.oval:obj:2
I am collecting data on Ubuntu 10.04.4 LTS.
Attached is the complete OVAL def. file.
I' can re-produce this on Ubuntu 11 and 12 server also.
Looking at SVN changes, I can see several process related features were added and I think it could be a bug in one of them.
Looking at the error context_new(unconfined) it seems culprit could be somewhere in selinux_domain_label (just a guess)
I will be happy to provide more information. Please contact me on firstname.lastname@example.org