future-architect /
vuls
| 1 | /* Vuls - Vulnerability Scanner |
||
| 2 | Copyright (C) 2016 Future Corporation , Japan. |
||
| 3 | |||
| 4 | This program is free software: you can redistribute it and/or modify |
||
| 5 | it under the terms of the GNU General Public License as published by |
||
| 6 | the Free Software Foundation, either version 3 of the License, or |
||
| 7 | (at your option) any later version. |
||
| 8 | |||
| 9 | This program is distributed in the hope that it will be useful, |
||
| 10 | but WITHOUT ANY WARRANTY; without even the implied warranty of |
||
| 11 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
||
| 12 | GNU General Public License for more details. |
||
| 13 | |||
| 14 | You should have received a copy of the GNU General Public License |
||
| 15 | along with this program. If not, see <http://www.gnu.org/licenses/>. |
||
| 16 | */ |
||
| 17 | |||
| 18 | package oval |
||
| 19 | |||
| 20 | import ( |
||
| 21 | "encoding/json" |
||
| 22 | "fmt" |
||
| 23 | "net/http" |
||
| 24 | "time" |
||
| 25 | |||
| 26 | cnf "github.com/future-architect/vuls/config" |
||
| 27 | "github.com/future-architect/vuls/models" |
||
| 28 | "github.com/future-architect/vuls/util" |
||
| 29 | "github.com/kotakanbe/goval-dictionary/db" |
||
| 30 | "github.com/parnurzeal/gorequest" |
||
| 31 | "golang.org/x/xerrors" |
||
| 32 | ) |
||
| 33 | |||
| 34 | // Client is the interface of OVAL client. |
||
| 35 | type Client interface { |
||
| 36 | CheckHTTPHealth() error |
||
| 37 | FillWithOval(db.DB, *models.ScanResult) (int, error) |
||
| 38 | |||
| 39 | // CheckIfOvalFetched checks if oval entries are in DB by family, release. |
||
| 40 | CheckIfOvalFetched(db.DB, string, string) (bool, error) |
||
| 41 | CheckIfOvalFresh(db.DB, string, string) (bool, error) |
||
| 42 | } |
||
| 43 | |||
| 44 | // Base is a base struct |
||
| 45 | type Base struct { |
||
| 46 | family string |
||
| 47 | } |
||
| 48 | |||
| 49 | // CheckHTTPHealth do health check |
||
| 50 | func (b Base) CheckHTTPHealth() error { |
||
| 51 | if !cnf.Conf.OvalDict.IsFetchViaHTTP() { |
||
| 52 | return nil |
||
| 53 | } |
||
| 54 | |||
| 55 | url := fmt.Sprintf("%s/health", cnf.Conf.OvalDict.URL) |
||
| 56 | var errs []error |
||
| 57 | var resp *http.Response |
||
| 58 | resp, _, errs = gorequest.New().Get(url).End() |
||
| 59 | // resp, _, errs = gorequest.New().SetDebug(config.Conf.Debug).Get(url).End() |
||
| 60 | // resp, _, errs = gorequest.New().Proxy(api.httpProxy).Get(url).End() |
||
| 61 | if 0 < len(errs) || resp == nil || resp.StatusCode != 200 { |
||
| 62 | return xerrors.Errorf("Failed to request to OVAL server. url: %s, errs: %w", |
||
|
0 ignored issues
–
show
introduced
by
Loading history...
|
|||
| 63 | url, errs) |
||
| 64 | } |
||
| 65 | return nil |
||
| 66 | } |
||
| 67 | |||
| 68 | // CheckIfOvalFetched checks if oval entries are in DB by family, release. |
||
| 69 | func (b Base) CheckIfOvalFetched(driver db.DB, osFamily, release string) (fetched bool, err error) { |
||
| 70 | if !cnf.Conf.OvalDict.IsFetchViaHTTP() { |
||
| 71 | count, err := driver.CountDefs(osFamily, release) |
||
| 72 | if err != nil { |
||
| 73 | return false, xerrors.Errorf("Failed to count OVAL defs: %s, %s, %w", osFamily, release, err) |
||
|
0 ignored issues
–
show
|
|||
| 74 | } |
||
| 75 | return 0 < count, nil |
||
| 76 | } |
||
| 77 | |||
| 78 | url, _ := util.URLPathJoin(cnf.Conf.OvalDict.URL, "count", osFamily, release) |
||
| 79 | resp, body, errs := gorequest.New().Get(url).End() |
||
| 80 | if 0 < len(errs) || resp == nil || resp.StatusCode != 200 { |
||
| 81 | return false, xerrors.Errorf("HTTP GET error, url: %s, resp: %v, err: %w", url, resp, errs) |
||
|
0 ignored issues
–
show
|
|||
| 82 | } |
||
| 83 | count := 0 |
||
| 84 | if err := json.Unmarshal([]byte(body), &count); err != nil { |
||
| 85 | return false, xerrors.Errorf("Failed to Unmarshall. body: %s, err: %w", body, err) |
||
|
0 ignored issues
–
show
|
|||
| 86 | } |
||
| 87 | return 0 < count, nil |
||
| 88 | } |
||
| 89 | |||
| 90 | // CheckIfOvalFresh checks if oval entries are fresh enough |
||
| 91 | func (b Base) CheckIfOvalFresh(driver db.DB, osFamily, release string) (ok bool, err error) { |
||
| 92 | var lastModified time.Time |
||
| 93 | if !cnf.Conf.OvalDict.IsFetchViaHTTP() { |
||
| 94 | lastModified = driver.GetLastModified(osFamily, release) |
||
| 95 | } else { |
||
| 96 | url, _ := util.URLPathJoin(cnf.Conf.OvalDict.URL, "lastmodified", osFamily, release) |
||
| 97 | resp, body, errs := gorequest.New().Get(url).End() |
||
| 98 | if 0 < len(errs) || resp == nil || resp.StatusCode != 200 { |
||
| 99 | return false, xerrors.Errorf("HTTP GET error, url: %s, resp: %v, err: %w", url, resp, errs) |
||
|
0 ignored issues
–
show
|
|||
| 100 | } |
||
| 101 | |||
| 102 | if err := json.Unmarshal([]byte(body), &lastModified); err != nil { |
||
| 103 | return false, xerrors.Errorf("Failed to Unmarshall. body: %s, err: %w", body, err) |
||
|
0 ignored issues
–
show
|
|||
| 104 | } |
||
| 105 | } |
||
| 106 | |||
| 107 | since := time.Now() |
||
| 108 | since = since.AddDate(0, 0, -3) |
||
| 109 | if lastModified.Before(since) { |
||
| 110 | util.Log.Warnf("OVAL for %s %s is old, last modified is %s. It's recommended to update OVAL to improve scanning accuracy. How to update OVAL database, see https://github.com/kotakanbe/goval-dictionary#usage", |
||
| 111 | osFamily, release, lastModified) |
||
| 112 | return false, nil |
||
| 113 | } |
||
| 114 | util.Log.Infof("OVAL is fresh: %s %s ", osFamily, release) |
||
| 115 | return true, nil |
||
| 116 | } |
||
| 117 |