Skip to content

fix(systempolicy): match process dirs by prefix, not suffix - #779

Open
magic-peach wants to merge 1 commit into
accuknox:devfrom
magic-peach:fix-process-dirs-prefix-match
Open

magic-peach wants to merge 1 commit into
accuknox:devfrom
magic-peach:fix-process-dirs-prefix-match

Conversation

@magic-peach

Copy link
Copy Markdown

Purpose of PR?:

FilterSystemLogsByConfig used containsFormat, a suffix-matching helper, for the ProcessDirs filter check instead of containsDirectory, the prefix-matching helper the equivalent FileDirs check right above it already uses. A resource path under a configured process directory never actually matched, so the filter silently never excluded anything it was meant to.

Fixes #

Does this PR introduce a breaking change?

No. This corrects the ProcessDirs filter to behave like the sibling FileDirs filter, which already uses prefix matching.

If the changes in this PR are manually verified, list down the scenarios covered::

Added a unit test asserting that a log with Resource "/usr/bin/curl" is excluded when ProcessDirs is configured with "/usr/bin/". Confirmed it fails on the unmodified code and passes with the fix.

Additional information for reviewer? :

Found by reading the code, not tied to an existing issue.

Checklist:

  • Bug fix. Fixes #
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • This change requires a documentation update
  • PR Title follows the convention of <type>(<scope>): <subject>
  • Commit has unit tests
  • Commit has integration tests

The process dirs filter used containsFormat, a suffix match, while
the otherwise identical file dirs filter right above it uses
containsDirectory, a prefix match. A directory filter should match
paths under it, so process dirs silently behaved differently from
file dirs and let logs through it should have filtered.

Switched it to containsDirectory and added a test.

Signed-off-by: Akanksha Trehun <akankshatrehun@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant