WP-30/31/32: contract and failing tests for backup management; OS scan skips container dirs
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-02 23:05:22 +02:00
parent 5026ce22de
commit 39af18b336
16 changed files with 1456 additions and 1 deletions

View File

@ -104,6 +104,10 @@ impl TrivyScanner {
}
}
/// Skipped by the OS scan: containerd/snap content (scanned per image instead) and pseudo filesystems.
pub const ROOTFS_SKIP_DIRS: &str =
"/var/snap/microk8s/common,/snap,/var/lib/snapd,/var/lib/containerd,/var/lib/docker,/proc,/sys,/dev,/run,/tmp";
const COMMON: [&str; 7] = [
"--format",
"json",
@ -133,7 +137,8 @@ impl VulnerabilityScanner for TrivyScanner {
async fn scan_os(&self, out: &dyn LineSink) -> Result<Vec<RawFinding>, DomainError> {
let mut args = vec!["rootfs"];
args.extend(COMMON);
args.push("/");
// container image layers, snaps and pseudo filesystems are not part of the host OS
args.extend(["--skip-dirs", ROOTFS_SKIP_DIRS, "/"]);
self.scan(&args, out).await
}
async fn scan_image(
@ -287,6 +292,18 @@ mod tests {
},
"rootfs" | "image" => {
assert!(args.contains(&"--format") && args.contains(&"json"));
if args[0] == "rootfs" {
let skip = args
.iter()
.position(|a| *a == "--skip-dirs")
.map(|i| args[i + 1])
.unwrap_or("");
assert!(
skip.contains("/var/snap/microk8s/common") && skip.contains("/proc"),
"{skip}"
);
assert_eq!(*args.last().unwrap(), "/");
}
crate::host::Output {
stdout: SAMPLE.into(),
success: true,