SIGN IN SIGN UP

fix(cel): scan Patterns in was_path_opened_with_suffix and was_path_opened_with_prefix (#983)

* test(cel): add test reproducing was_path_opened_with_suffix pattern match failure

Adds unit tests asserting that cp.was_path_opened_with_suffix and
cp.was_path_opened_with_prefix return true when the profile contains
matching paths stored as wildcard patterns (e.g. /*/token or
/*/serviceaccount/.../token). Currently fails because pass-through mode
scans only Values and ignores Patterns.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* fix(cel): scan Patterns in was_path_opened_with_suffix and was_path_opened_with_prefix

When container profiles contain wildcarded or dynamic paths (such as
/*/token or /*/serviceaccount/.../token), they are stored in cp.Opens.Patterns
rather than cp.Opens.Values. In pass-through mode (cp.Opens.All=true),
was_path_opened_with_suffix and was_path_opened_with_prefix were only scanning
cp.Opens.Values and skipping Patterns entirely, causing rules like R0006 to
fire false positives even when the pattern in the profile ended with the queried
suffix.

This fix scans cp.Opens.Patterns with strings.HasSuffix / strings.HasPrefix
alongside cp.Opens.Values.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

---------

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>
M
Matthias Bertschy committed
1c4fb954cdd51edb98a2ad4100be392cd806e44e
Parent: 630336b
Committed by GitHub <noreply@github.com> on 9/25/2026, 7:21:27 AM