Skip to content

Pin NetworkNeighbor optionality (spec §4.7) with explicit tests #34

Description

@entlein

Context

The v0.0.1 SBOB spec at §4.7 declares the following NetworkNeighbor fields as optional:

  • identifier (string)
  • type (enum external / internal, default external)
  • podSelector (label selector)
  • namespaceSelector (label selector)

The current Go struct in pkg/apis/softwarecomposition/v1beta1/network_types.go tags all of them as protobuf req:

type NetworkNeighbor struct {
    Identifier string            `protobuf:"bytes,1,req,name=identifier"`
    Type       CommunicationType `protobuf:"bytes,2,req,name=type"`
    DNS        string            `protobuf:"bytes,3,req,name=dns"`         // deprecated
    DNSNames   []string          `protobuf:"bytes,4,rep,name=dnsNames"`
    Ports      []NetworkPort     `protobuf:"bytes,5,rep,name=ports"`
    PodSelector       *metav1.LabelSelector `protobuf:"bytes,6,req,name=podSelector"`
    NamespaceSelector *metav1.LabelSelector `protobuf:"bytes,7,req,name=namespaceSelector"`
    IPAddress         string                `protobuf:"bytes,8,req,name=ipAddress"`  // deprecated
    IPAddresses       []string              `protobuf:"bytes,9,rep,name=ipAddresses"`
}

The kubescape runtime tolerates the omissions in practice — profiles routinely arrive with empty Identifier or absent selectors and nothing breaks. But the schema tags don't reflect that, and there are no explicit tests pinning the runtime tolerance.

Why this matters

Without pinning tests, a future binding refresh (e.g. make generate against a regenerated .proto file, or an upstream merge that re-asserts req) could re-introduce hard-fail behaviour on omitted fields. The runtime would then fall over for any v0.0.2 SBOB that takes the spec at its word and omits the optional fields.

What this issue tracks

Add explicit unit tests in pkg/apis/softwarecomposition/v1beta1/ (next to the existing network_types_protobuf_test.go) that round-trip a NetworkNeighbor with each of the optional fields omitted, asserting:

  1. Identifier == "" round-trips — empty identifier serialises/deserialises without error.
  2. Type == "" defaults to external on read (or, if the matcher doesn't default, the round-trip preserves the empty string and the matcher MUST treat empty as external per §4.7).
  3. PodSelector == nil and NamespaceSelector == nil round-trip — nil pointer survives serialise/deserialise; matchers handle nil selectors gracefully.
  4. Ports == nil vs Ports == []NetworkPort{} — confirm both forms round-trip cleanly, and that the matchers distinguish NULL (any-port wildcard implicit) from NONE (declared zero-port traffic) per §5.4.

The protobuf req tags can probably stay (changing them risks an on-the-wire incompatibility that we'd want to think about separately) — the value of the tests is asserting that omission at the Go-struct layer is tolerated end-to-end. If a binding regression flips the tag enforcement on, the tests fail loudly.

Acceptance

  • Four pinning tests added in network_types_optionality_test.go
  • Each test exercises round-trip + matcher behaviour against a representative observed event
  • No spec change needed (spec §4.7 is correct as written; this issue is purely about pinning the in-code tolerance)

Related

Surfaces from the v0.0.1 spec ↔ code alignment pass (2026-05-16). The corresponding spec change for the policyBinding shape mismatch is being addressed separately in the spec document.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions