SIGN IN SIGN UP

fix: addon to opens-gadget there was still a missing piece. Also adding the bitnami images to Test27 (they generate evidence) (#893)

* Update README.md

* fix gadget AGAIN

Signed-off-by: entlein <einentlein@gmail.com>

* fix(gadgets): guard the procfs prepend against u32 offset wrap

The 5-byte proc/ prepend decremented buf_off unguarded; a dentry chain longer
than the half-buffer could wrap the offset and corrupt the emitted path
(masked writes keep it memory-safe). Unreachable for PATH_MAX-bounded paths -
defense in depth. On insufficient space the prepend is skipped.

Signed-off-by: entlein <einentlein@gmail.com>

* test(gadgets): pin the procfs-prepend offset-wrap guard and its arithmetic

Proves the u32 wrap below buf_off=5 and pins the shipped header (guard
present, buffer constants unchanged) so the analysis breaks loudly on drift.

Signed-off-by: entlein <einentlein@gmail.com>

* test(component): harden Test_27 path assertions with a runc-heavy workload

recorded_profile_absolute_paths gains the scrambled-path check (a resolved
path never begins with a numeric segment) and a second learned workload,
bitnami/redis: its container init opens procfs through detached
fsopen/fsmount handles on runc >= 1.2, the natural reproducer for
prefix-stripped /proc paths that plain nginx never exercises. A positive
control requires at least one /proc/-rooted open in the bitnami profile so a
silently event-less gadget cannot pass the negative checks vacuously.

Signed-off-by: entlein <einentlein@gmail.com>

* test(component): drive the Test_27 runc-heavy leg with the exact distro-demo redis manifest

Replace the hand-written fixture with the verbatim helm render of the redis
distro deployment (bitnamicharts/redis 27.0.18, digest-pinned image - the
tag was removed from the registries, which is what timed the previous leg
out). The test applies every rendered document and waits on the statefulset
pod and the learned profile completion directly.

Signed-off-by: entlein <einentlein@gmail.com>

* Delete tests/resources/bitnami-redis-deployment.yaml

the patch didnt delete, just add

Signed-off-by: entlein <einentlein@gmail.com>

* Update component_test.go

add null guard that got lost in the conflict resolv

Signed-off-by: entlein <einentlein@gmail.com>

* fixing Test27 (version3)

Signed-off-by: entlein <einentlein@gmail.com>

* last Test fix for Test27

Signed-off-by: entlein <einentlein@gmail.com>

* Update README.md

Readme should not show up with a diff in this PR

* conflict was resolved wrong

Signed-off-by: entlein <einentlein@gmail.com>

---------

Signed-off-by: entlein <einentlein@gmail.com>
D
Duck committed
f0d393ea5443f96e5c0d72ccc8d5f48d338a206f
Parent: 664ecbc
Committed by GitHub <noreply@github.com> on 8/18/2026, 11:44:00 AM