[SDS-2914] Report all debug scan failure reasons - #390
Merged
GeoffreyRdn merged 9 commits intoSep 25, 2026
Merged
Conversation
Pull the inline included- and excluded-keyword span lookups out of debug_scan and debug_scan_excluded_keywords into included_keyword_info and excluded_keyword_info. Both take the compiled rule as an Option so they can be reused by callers that have not proven the rule is a regex rule. No behavior change.
Replace DebugRuleMatch.status with statuses: Vec<DebugRuleMatchStatus> and drop #[serde(flatten)] so each status serializes as a tagged object inside a "statuses" array instead of being flattened onto the match. Detection still yields at most one status per match, so behavior is unchanged. This only moves the type and wire format to a list so the next commit can report every failing condition. BREAKING CHANGE: the debug scan JSON payload replaces the flattened "status" field with a "statuses" array.
Partial matches previously relied on relaxing exactly one condition at a time and keeping matches that newly appeared. When two conditions failed together, every probe was still blocked by the other, so the candidate was reported by none of them and disappeared from the output entirely. Scan once with a fully relaxed rule to collect every regex candidate, then probe each configured condition in isolation. A candidate missing from a probe's matches was rejected by that condition, so all failing conditions are collected instead of only the first. Statuses follow a deterministic order: included keyword, excluded keyword, checksum, included scope, excluded scope, suppression. Output is sorted by path then start index. Probes are only built for configured conditions, and the relaxed scan is skipped when a rule has none, so a rule without conditions still scans the event exactly once. Multipass rejection keeps reporting InExcludedScope when an allowed-path match is dropped because the same value occurs under an excluded path.
Add coverage for candidates rejected by several conditions at once, including the two reported reproductions (missing included keyword with a failing checksum, and missing included keyword with a suppression), three simultaneous failures, and a match both outside the included scope and inside the excluded scope. Also cover the serialized "statuses" shape, per-candidate status independence across paths, full and partial matches in the same event, retained deserialization of the dormant IncludedKeywordTooFar status, and CountingEvent assertions pinning that a rule with no conditions, or with empty suppressions, still visits the event exactly once.
…14-multi-reason-partial-matches # Conflicts: # sds/Cargo.lock
GeoffreyRdn
marked this pull request as ready for review
September 18, 2026 15:32
fuchsnj
approved these changes
Sep 22, 2026
Contributor
Author
|
Other PRs were merged, waiting to be deployed. |
GeoffreyRdn
enabled auto-merge
September 25, 2026 11:56
GeoffreyRdn
deleted the
geoffrey.redon/SDS-2914-multi-reason-partial-matches
branch
September 25, 2026 12:01
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Landing order
Important
Do not merge this PR until both prerequisite compatibility PRs have landed
Testing
cargo fmt --all -- --checkcargo test -p dd-sensitive-data-scanner debug_scan(23 passed)make check-rustmake test-rust(457 passed)