SIGN IN SIGN UP

path-wildcards: anchored trailing-* + per-endpoint port + R0040 args (#807)

* feat(projection): add ExecsByPath composite-key surface to ProjectedContainerProfile

Signed-off-by: entlein <einentlein@gmail.com>

* path-wildcards: anchored trailing-* + per-endpoint port + R0040 args

Signed-off-by: entlein <einentlein@gmail.com>

* restoring ap_was_path_opened_with_flags

Signed-off-by: entlein <einentlein@gmail.com>

* apply rabbit feedback: align R0040 args consumer with rc1 final state

Signed-off-by: entlein <einentlein@gmail.com>

* build(go.mod): replace kubescape/storage with sister execs branch

This PR (R0040 args consumer) references dynamicpathdetector.CompareExecArgs,
which ships in k8sstormcenter/storage's upstream-pr/sbob-execs branch (the
storage sibling of kubescape/storage#322), not in any released
kubescape/storage tag. The PR's existing go.mod pin (v0.0.258) does not
contain it.

Adds a replace directive to the sister branch's current tip (5e39d001 —
feat(apis): add ExecCalls.ArgsRequired + MatchExecArgs to express 'no args').
Removed when the sister storage PR kubescape/storage#322 merges and a
release ships CompareExecArgs.

Companion to the stacking-on-NA-#812 cherry-pick (provides cp.ExecsByPath)
in the previous commits on this branch.

Resolves the matthyx 'does not build' blocker on PR #807 (2026-05-27).

Signed-off-by: entlein <einentlein@gmail.com>

* test: add Test_32_UnexpectedProcessArguments +
   fixtures

Signed-off-by: entlein <einentlein@gmail.com>

* test: add Test_32_UnexpectedProcessArguments + fixtures

Signed-off-by: entlein <einentlein@gmail.com>

* build(go.mod): drop sister-branch replace; pin kubescape/storage v0.0.278

Storage PR kubescape/storage#322 (CompareExecArgs + MatchExecArgs +
ExecCalls.ArgsRequired) merged to kubescape/storage main and a release
was cut (v0.0.278, 2026-05-28). The k8sstormcenter sister-branch
replace is no longer needed — pinning the real tag.

Signed-off-by: entlein <einentlein@gmail.com>

* fix(tests): de-duplicate Test_32 / file-header / package decl

Previous Test_32 add appended the full umbrella component_test.go on top
of the legitimate one, producing two //go:build directives, two package
clauses, two import blocks and a triplicated Test_32 body. gofmt -e
rejected the file at lines 1574, 1576, 4978, 5206.

Truncates to the last legitimate line and re-appends only the Test_32
function from the umbrella branch. File parses clean, single instance
of each top-level element.

Resolves matthyx blocker (1) on PR #807 (2026-05-28).

Signed-off-by: entlein <einentlein@gmail.com>

* build(go.mod): tidy + pin runtime-spec v1.2.1 for -mod=readonly clean

Storage v0.0.278 bump pulled in a transitive dep set that drove
runtime-spec up to v1.3.0, which is incompatible with containerd
v1.7.32's spec_opts.go (cannot use int64 as *int64). Upstream NA main
runs on runtime-spec v1.2.1; pin it the same way here via replace so
'go test -mod=readonly' is clean (matthyx blocker 2 on PR #807, 2026-05-28).

Also runs full mod tidy now that v0.0.278 has shipped — populates the
transitive go.sum entries that were missing under the previous
sister-branch replace, so CI's -mod=readonly accepts the module graph.

Signed-off-by: entlein <einentlein@gmail.com>

* fix(projection): ExecsByPath becomes path -> []argv-vectors

Previous shape (map[string][]string) collapsed duplicate Path entries
to the last seen, breaking merged profiles where
mergeApplicationProfile legitimately appends multiple ExecCalls per
path with distinct argv shapes. ap.was_executed_with_args silently
rejected valid executions that matched any but the final entry
(matthyx blocker 3 on PR #807, 2026-05-28).

extractExecsByPath now appends each Args slice to a per-path list.
wasExecutedWithArgs iterates the list and returns true when any
vector matches via CompareExecArgs. The 'absent key means no argv
constraint' back-compat semantic is unchanged. Cloned-slice
invariant preserved.

Updates TestApply_ExecsByPath_PopulatesFromSpec to assert the
appended-list shape and the second-entry mutation invariant.

Signed-off-by: entlein <einentlein@gmail.com>

* test(mock): populate ExecsByPath in RuleObjectCacheMock projection

Mirrors containerprofilecache.Apply's extractExecsByPath shape so
exec-args unit tests exercise the real wildcard matcher instead of
hitting the absent-key 'no argv constraint' back-compat fallback.
Same per-Path append + nil→empty-slice rules.

Fixes the four TestExecWithArgsWildcardInProfile cases that were
silently returning true (back-compat) and getting marked as failing
expected:false (sh -x wrong flag, ls -l no directory, echo goodbye
world wrong literal anchor, curl --pass alice wrong literal).

Signed-off-by: entlein <einentlein@gmail.com>

* test 27 is for PR 807, test 32 is for PR 805, now swapping them , also go mod sync with main

Signed-off-by: entlein <einentlein@gmail.com>

* restoring earlier go dependencies

Signed-off-by: entlein <einentlein@gmail.com>

* go.mod dependencies

Signed-off-by: entlein <einentlein@gmail.com>

* adding strings in import

Signed-off-by: entlein <einentlein@gmail.com>

* rebase attempt 1

Signed-off-by: entlein <einentlein@gmail.com>

* consolidating PRs 807 811 and 812 all into 807

Signed-off-by: entlein <einentlein@gmail.com>

---------

Signed-off-by: entlein <einentlein@gmail.com>
Co-authored-by: Entlein <eineintlein@gmail.com>
D
Duck committed
d4c012f67364b9e6ca7288ad76ef0ded209dd425
Parent: 7db8f99
Committed by GitHub <noreply@github.com> on 6/25/2026, 12:32:09 PM