Context
The v0.0.1 SBOB spec at §4.7 declares the following NetworkNeighbor fields as optional:
identifier (string)
type (enum external / internal, default external)
podSelector (label selector)
namespaceSelector (label selector)
The current Go struct in pkg/apis/softwarecomposition/v1beta1/network_types.go tags all of them as protobuf req:
type NetworkNeighbor struct {
Identifier string `protobuf:"bytes,1,req,name=identifier"`
Type CommunicationType `protobuf:"bytes,2,req,name=type"`
DNS string `protobuf:"bytes,3,req,name=dns"` // deprecated
DNSNames []string `protobuf:"bytes,4,rep,name=dnsNames"`
Ports []NetworkPort `protobuf:"bytes,5,rep,name=ports"`
PodSelector *metav1.LabelSelector `protobuf:"bytes,6,req,name=podSelector"`
NamespaceSelector *metav1.LabelSelector `protobuf:"bytes,7,req,name=namespaceSelector"`
IPAddress string `protobuf:"bytes,8,req,name=ipAddress"` // deprecated
IPAddresses []string `protobuf:"bytes,9,rep,name=ipAddresses"`
}
The kubescape runtime tolerates the omissions in practice — profiles routinely arrive with empty Identifier or absent selectors and nothing breaks. But the schema tags don't reflect that, and there are no explicit tests pinning the runtime tolerance.
Why this matters
Without pinning tests, a future binding refresh (e.g. make generate against a regenerated .proto file, or an upstream merge that re-asserts req) could re-introduce hard-fail behaviour on omitted fields. The runtime would then fall over for any v0.0.2 SBOB that takes the spec at its word and omits the optional fields.
What this issue tracks
Add explicit unit tests in pkg/apis/softwarecomposition/v1beta1/ (next to the existing network_types_protobuf_test.go) that round-trip a NetworkNeighbor with each of the optional fields omitted, asserting:
Identifier == "" round-trips — empty identifier serialises/deserialises without error.
Type == "" defaults to external on read (or, if the matcher doesn't default, the round-trip preserves the empty string and the matcher MUST treat empty as external per §4.7).
PodSelector == nil and NamespaceSelector == nil round-trip — nil pointer survives serialise/deserialise; matchers handle nil selectors gracefully.
Ports == nil vs Ports == []NetworkPort{} — confirm both forms round-trip cleanly, and that the matchers distinguish NULL (any-port wildcard implicit) from NONE (declared zero-port traffic) per §5.4.
The protobuf req tags can probably stay (changing them risks an on-the-wire incompatibility that we'd want to think about separately) — the value of the tests is asserting that omission at the Go-struct layer is tolerated end-to-end. If a binding regression flips the tag enforcement on, the tests fail loudly.
Acceptance
Related
Surfaces from the v0.0.1 spec ↔ code alignment pass (2026-05-16). The corresponding spec change for the policyBinding shape mismatch is being addressed separately in the spec document.
Context
The v0.0.1 SBOB spec at §4.7 declares the following
NetworkNeighborfields as optional:identifier(string)type(enumexternal/internal, defaultexternal)podSelector(label selector)namespaceSelector(label selector)The current Go struct in
pkg/apis/softwarecomposition/v1beta1/network_types.gotags all of them as protobufreq:The kubescape runtime tolerates the omissions in practice — profiles routinely arrive with empty
Identifieror absent selectors and nothing breaks. But the schema tags don't reflect that, and there are no explicit tests pinning the runtime tolerance.Why this matters
Without pinning tests, a future binding refresh (e.g.
make generateagainst a regenerated.protofile, or an upstream merge that re-assertsreq) could re-introduce hard-fail behaviour on omitted fields. The runtime would then fall over for any v0.0.2 SBOB that takes the spec at its word and omits the optional fields.What this issue tracks
Add explicit unit tests in
pkg/apis/softwarecomposition/v1beta1/(next to the existingnetwork_types_protobuf_test.go) that round-trip aNetworkNeighborwith each of the optional fields omitted, asserting:Identifier == ""round-trips — empty identifier serialises/deserialises without error.Type == ""defaults toexternalon read (or, if the matcher doesn't default, the round-trip preserves the empty string and the matcher MUST treat empty as external per §4.7).PodSelector == nilandNamespaceSelector == nilround-trip — nil pointer survives serialise/deserialise; matchers handle nil selectors gracefully.Ports == nilvsPorts == []NetworkPort{}— confirm both forms round-trip cleanly, and that the matchers distinguish NULL (any-port wildcard implicit) from NONE (declared zero-port traffic) per §5.4.The protobuf
reqtags can probably stay (changing them risks an on-the-wire incompatibility that we'd want to think about separately) — the value of the tests is asserting that omission at the Go-struct layer is tolerated end-to-end. If a binding regression flips the tag enforcement on, the tests fail loudly.Acceptance
network_types_optionality_test.goRelated
Surfaces from the v0.0.1 spec ↔ code alignment pass (2026-05-16). The corresponding spec change for the policyBinding shape mismatch is being addressed separately in the spec document.