WP-30/31/32: contract and failing tests for backup management; OS scan skips container dirs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
@ -104,6 +104,10 @@ impl TrivyScanner {
|
||||
}
|
||||
}
|
||||
|
||||
/// Skipped by the OS scan: containerd/snap content (scanned per image instead) and pseudo filesystems.
|
||||
pub const ROOTFS_SKIP_DIRS: &str =
|
||||
"/var/snap/microk8s/common,/snap,/var/lib/snapd,/var/lib/containerd,/var/lib/docker,/proc,/sys,/dev,/run,/tmp";
|
||||
|
||||
const COMMON: [&str; 7] = [
|
||||
"--format",
|
||||
"json",
|
||||
@ -133,7 +137,8 @@ impl VulnerabilityScanner for TrivyScanner {
|
||||
async fn scan_os(&self, out: &dyn LineSink) -> Result<Vec<RawFinding>, DomainError> {
|
||||
let mut args = vec!["rootfs"];
|
||||
args.extend(COMMON);
|
||||
args.push("/");
|
||||
// container image layers, snaps and pseudo filesystems are not part of the host OS
|
||||
args.extend(["--skip-dirs", ROOTFS_SKIP_DIRS, "/"]);
|
||||
self.scan(&args, out).await
|
||||
}
|
||||
async fn scan_image(
|
||||
@ -287,6 +292,18 @@ mod tests {
|
||||
},
|
||||
"rootfs" | "image" => {
|
||||
assert!(args.contains(&"--format") && args.contains(&"json"));
|
||||
if args[0] == "rootfs" {
|
||||
let skip = args
|
||||
.iter()
|
||||
.position(|a| *a == "--skip-dirs")
|
||||
.map(|i| args[i + 1])
|
||||
.unwrap_or("");
|
||||
assert!(
|
||||
skip.contains("/var/snap/microk8s/common") && skip.contains("/proc"),
|
||||
"{skip}"
|
||||
);
|
||||
assert_eq!(*args.last().unwrap(), "/");
|
||||
}
|
||||
crate::host::Output {
|
||||
stdout: SAMPLE.into(),
|
||||
success: true,
|
||||
|
||||
Reference in New Issue
Block a user