test(procfs): verify host processes get container ID "host" (#860)
Adds a unit test that runs the real ProcfsTracer against the live /proc with an empty container collection (the bare-host scenario) and asserts every observed process event is assigned the reserved container ID "host" (armotypes.HostContainerID) and never an empty string. A second case proves the assignment is a deliberate else-branch: when a container is present in the collection for a mount namespace, the lookup used by handleProcfsEvent returns that container's real ID, and only an untracked mount namespace falls back to "host". Pure Go, no eBPF and no privileges required (the procfs feeder only reads /proc), so it runs in CI. Guards CEL rules that key on event.containerId == 'host' to scope behavior to host contexts. Signed-off-by: Ben <ben@armosec.io>
B
Ben Hirschberg committed
6a86345e3b2c91635df705ab99ea14cd27bc02e3
Parent: fa92c73
Committed by GitHub <noreply@github.com>
on 7/22/2026, 2:33:20 PM