fix(systempolicy): match process dirs by prefix, not suffix - #779
Open
magic-peach wants to merge 1 commit into
Open
magic-peach wants to merge 1 commit into
magic-peach wants to merge 1 commit into
Conversation
The process dirs filter used containsFormat, a suffix match, while the otherwise identical file dirs filter right above it uses containsDirectory, a prefix match. A directory filter should match paths under it, so process dirs silently behaved differently from file dirs and let logs through it should have filtered. Switched it to containsDirectory and added a test. Signed-off-by: Akanksha Trehun <akankshatrehun@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose of PR?:
FilterSystemLogsByConfig used containsFormat, a suffix-matching helper, for the ProcessDirs filter check instead of containsDirectory, the prefix-matching helper the equivalent FileDirs check right above it already uses. A resource path under a configured process directory never actually matched, so the filter silently never excluded anything it was meant to.
Fixes #
Does this PR introduce a breaking change?
No. This corrects the ProcessDirs filter to behave like the sibling FileDirs filter, which already uses prefix matching.
If the changes in this PR are manually verified, list down the scenarios covered::
Added a unit test asserting that a log with Resource "/usr/bin/curl" is excluded when ProcessDirs is configured with "/usr/bin/". Confirmed it fails on the unmodified code and passes with the fix.
Additional information for reviewer? :
Found by reading the code, not tied to an existing issue.
Checklist:
<type>(<scope>): <subject>