Skip to content

validate_action process checks match their own wrapper and falsely pass #371

Description

@Calmingstorm

Confirmed false-positive health check

Reviewed master at 886c36d8ebe861aa987059a1744d45b78797baae (v4.7.0). Suggested priority: P1, because this can falsely certify a stopped service after an operational change.

The process check builds pgrep -f <pattern> >/dev/null && echo PRESENT || echo ABSENT. The parent shell's command line contains the same pattern, so pgrep can find its own wrapper instead of the requested process. Excluding pgrep itself does not exclude ancestors.

Source: command construction, evaluation, production execution.

Reproduction

Generate a fresh random token in Python, use it as Check(type="process", target=token), run _build_command(check) through a shell, then pass its actual output to _evaluate.

target: odin-review-no-such-process-<random-token>
output: PRESENT
exit_code: 0
evaluated_status: pass

No target process was started. Independently reproduced twice with different runtime-generated tokens, so the enclosing review invocation did not already contain the token. No live service was changed.

Expected behavior / acceptance criteria

  • An absent process returns fail, never pass because the checker or its ancestors matched.
  • An actual matching fixture process still returns pass.
  • Exercise the generated shell command, not only mocked PRESENT/ABSENT strings.
  • Handle regex patterns and exclude the complete checking process tree on supported local/remote platforms. Merely inspecting pgrep's exit status is insufficient.
  • Keep the existing host-access checks intact.

Behavior change: previously false-positive checks become failures. Current focused suite passes 79 tests despite this defect. No source changes were made.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions