fix: addon to opens-gadget there was still a missing piece. Also adding the bitnami images to Test27 (they generate evidence) (#893)
* Update README.md * fix gadget AGAIN Signed-off-by: entlein <einentlein@gmail.com> * fix(gadgets): guard the procfs prepend against u32 offset wrap The 5-byte proc/ prepend decremented buf_off unguarded; a dentry chain longer than the half-buffer could wrap the offset and corrupt the emitted path (masked writes keep it memory-safe). Unreachable for PATH_MAX-bounded paths - defense in depth. On insufficient space the prepend is skipped. Signed-off-by: entlein <einentlein@gmail.com> * test(gadgets): pin the procfs-prepend offset-wrap guard and its arithmetic Proves the u32 wrap below buf_off=5 and pins the shipped header (guard present, buffer constants unchanged) so the analysis breaks loudly on drift. Signed-off-by: entlein <einentlein@gmail.com> * test(component): harden Test_27 path assertions with a runc-heavy workload recorded_profile_absolute_paths gains the scrambled-path check (a resolved path never begins with a numeric segment) and a second learned workload, bitnami/redis: its container init opens procfs through detached fsopen/fsmount handles on runc >= 1.2, the natural reproducer for prefix-stripped /proc paths that plain nginx never exercises. A positive control requires at least one /proc/-rooted open in the bitnami profile so a silently event-less gadget cannot pass the negative checks vacuously. Signed-off-by: entlein <einentlein@gmail.com> * test(component): drive the Test_27 runc-heavy leg with the exact distro-demo redis manifest Replace the hand-written fixture with the verbatim helm render of the redis distro deployment (bitnamicharts/redis 27.0.18, digest-pinned image - the tag was removed from the registries, which is what timed the previous leg out). The test applies every rendered document and waits on the statefulset pod and the learned profile completion directly. Signed-off-by: entlein <einentlein@gmail.com> * Delete tests/resources/bitnami-redis-deployment.yaml the patch didnt delete, just add Signed-off-by: entlein <einentlein@gmail.com> * Update component_test.go add null guard that got lost in the conflict resolv Signed-off-by: entlein <einentlein@gmail.com> * fixing Test27 (version3) Signed-off-by: entlein <einentlein@gmail.com> * last Test fix for Test27 Signed-off-by: entlein <einentlein@gmail.com> * Update README.md Readme should not show up with a diff in this PR * conflict was resolved wrong Signed-off-by: entlein <einentlein@gmail.com> --------- Signed-off-by: entlein <einentlein@gmail.com>
D
Duck committed
f0d393ea5443f96e5c0d72ccc8d5f48d338a206f
Parent: 664ecbc
Committed by GitHub <noreply@github.com>
on 8/18/2026, 11:44:00 AM