DPTP-5102: Fix hostNetwork pod port ownership leak by scoping process cache per pod - #86
Conversation
Code Review by Qodo
Context used✅ Compliance rules (platform):
10 rules 1.
|
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: richardsonnick, smith-xyz The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/hold |
|
@richardsonnick can you check what qodo is complaining about there? Not sure if there is another area this could fail at. |
Previously process ownership was keyed by IP, so hostNetwork pods sharing a node IP could inherit ports resolved from unrelated pods (e.g. ovnkube-node). Add a podOwnedPorts cache keyed by namespace/name and Client.GetOwnedPorts to return only ports whose listening process was resolved in that pod's own PID namespace. Update the scanner's filterByProcessPorts to use the per-pod owned set instead of an IP-based process map. Co-authored-by: Cursor <cursoragent@cursor.com>
e358362 to
96fe851
Compare
|
New changes are detected. LGTM label has been removed. |
|
@richardsonnick: This pull request references DPTP-5102 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the bug to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@richardsonnick: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Previously process ownership was keyed by IP, so hostNetwork pods sharing a node IP could inherit ports resolved from unrelated pods (e.g. ovnkube-node). Add a podOwnedPorts cache keyed by namespace/name and Client.GetOwnedPorts to return only ports whose listening process was resolved in that pod's own PID namespace. Update the scanner's filterByProcessPorts to use the per-pod owned set instead of an IP-based process map.