<def-group>
  <definition class="compliance" id="file_groupowner_ovs_pid" version="1">
    {{{ oval_metadata("This test makes sure that /run/openvswitch/ovs-vswitchd.pid is group owned by 800 or 801.", rule_title=rule_title) }}}
    <criteria operator="OR">
      <criterion comment="Check file group ownership of /run/openvswitch/ovs-vswitchd.pid belongs to group 800" test_ref="test_file_groupowner_run_ovs_vswitchd_pid_800" />
      <criterion comment="Check file group ownership of /run/openvswitch/ovs-vswitchd.pid belongs to group 801" test_ref="test_file_groupowner_run_ovs_vswitchd_pid_801" />
    </criteria>
  </definition>

  <unix:file_test check="all" check_existence="all_exist" comment="Testing group ownership of /run/openvswitch/ovs-vswitchd.pid" id="test_file_groupowner_run_ovs_vswitchd_pid_800" version="1">
    <unix:object object_ref="object_file_groupowner_run_ovs_vswitchd_pid" />
    <unix:state state_ref="state_file_groupowner_run_ovs_vswitchd_pid_gid_800" />
  </unix:file_test>

  <unix:file_state id="state_file_groupowner_run_ovs_vswitchd_pid_gid_800" version="1">
    <unix:group_id datatype="int">800</unix:group_id>
  </unix:file_state>

  <unix:file_test check="all" check_existence="all_exist" comment="Testing group ownership of /run/openvswitch/ovs-vswitchd.pid" id="test_file_groupowner_run_ovs_vswitchd_pid_801" version="1">
    <unix:object object_ref="object_file_groupowner_run_ovs_vswitchd_pid" />
    <unix:state state_ref="state_file_groupowner_run_ovs_vswitchd_pid_gid_801" />
  </unix:file_test>

  <unix:file_state id="state_file_groupowner_run_ovs_vswitchd_pid_gid_801" version="1">
    <unix:group_id datatype="int">801</unix:group_id>
  </unix:file_state>

  <unix:file_object comment="/run/openvswitch/ovs-vswitchd.pid" id="object_file_groupowner_run_ovs_vswitchd_pid" version="1">
      <unix:filepath>/run/openvswitch/ovs-vswitchd.pid</unix:filepath>
  </unix:file_object>
</def-group>
