fix(cel): scan Patterns in was_path_opened_with_suffix and was_path_opened_with_prefix (#983)
* test(cel): add test reproducing was_path_opened_with_suffix pattern match failure Adds unit tests asserting that cp.was_path_opened_with_suffix and cp.was_path_opened_with_prefix return true when the profile contains matching paths stored as wildcard patterns (e.g. /*/token or /*/serviceaccount/.../token). Currently fails because pass-through mode scans only Values and ignores Patterns. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * fix(cel): scan Patterns in was_path_opened_with_suffix and was_path_opened_with_prefix When container profiles contain wildcarded or dynamic paths (such as /*/token or /*/serviceaccount/.../token), they are stored in cp.Opens.Patterns rather than cp.Opens.Values. In pass-through mode (cp.Opens.All=true), was_path_opened_with_suffix and was_path_opened_with_prefix were only scanning cp.Opens.Values and skipping Patterns entirely, causing rules like R0006 to fire false positives even when the pattern in the profile ended with the queried suffix. This fix scans cp.Opens.Patterns with strings.HasSuffix / strings.HasPrefix alongside cp.Opens.Values. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> --------- Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>
M
Matthias Bertschy committed
1c4fb954cdd51edb98a2ad4100be392cd806e44e
Parent: 630336b
Committed by GitHub <noreply@github.com>
on 9/25/2026, 7:21:27 AM