-
Notifications
You must be signed in to change notification settings - Fork 1
Migrate user-defined AP/NN to containerprofile #58
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
20d5470
3f9299b
1be5ede
d9108c1
a251069
903443d
8c82261
f2f730f
d1bab20
856dc36
aacf398
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,29 @@ | ||
| package containerprofilecache | ||
|
|
||
| import ( | ||
| "testing" | ||
|
|
||
| "github.com/kubescape/storage/pkg/apis/softwarecomposition/v1beta1" | ||
| "github.com/stretchr/testify/assert" | ||
| "github.com/stretchr/testify/require" | ||
| ) | ||
|
|
||
| // TestProjectField_StarPathRoutesToPatterns pins that a path-surface opens | ||
| // entry containing the "*" WildcardIdentifier is classified as a Pattern, | ||
| // not a literal Value. Regression guard: containsDynamicSegment previously | ||
| // recognised only "⋯", silently routing "/etc/ssl/*" into Values. | ||
| func TestProjectField_StarPathRoutesToPatterns(t *testing.T) { | ||
| cp := &v1beta1.ContainerProfile{ | ||
| Spec: v1beta1.ContainerProfileSpec{ | ||
| Opens: []v1beta1.OpenCalls{{Path: "/etc/ssl/*"}, {Path: "/etc/ld.so.cache"}}, | ||
| }, | ||
| } | ||
| pcp := Apply(nil, cp, nil) // nil spec => pass-through (All=true) | ||
|
|
||
| require.Contains(t, pcp.Opens.Patterns, "/etc/ssl/*", | ||
| "a '*'-bearing path entry must be a Pattern") | ||
| _, inValues := pcp.Opens.Values["/etc/ssl/*"] | ||
| assert.False(t, inValues, "'*'-bearing path entry must NOT be a literal Value") | ||
| _, cacheInValues := pcp.Opens.Values["/etc/ld.so.cache"] | ||
| assert.True(t, cacheInValues, "a literal path entry stays a Value") | ||
|
Comment on lines
+21
to
+28
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win Cover explicit filtering mode too. This test only exercises nil-spec pass-through ( 🤖 Prompt for AI Agents |
||
| } | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win
Consider asserting
entry.RVhere, and/or adding a refresh-cycle test.This test would have caught the
entry.RVbug flagged incontainerprofilecache.go(Line 451-508:entry.RVends up equal to the user-defined CP's ResourceVersion instead of""). Addingassert.Equal(t, "", entry.RV, ...)here, plus a follow-up test that calls the reconciler's refresh path a second tick and confirms the user-defined CP overlay is re-fetched, would close that gap.🤖 Prompt for AI Agents