Skip to content

[SDS-2914] Report all debug scan failure reasons - #390

Merged
GeoffreyRdn merged 9 commits into
mainfrom
geoffrey.redon/SDS-2914-multi-reason-partial-matches
Sep 25, 2026
Merged

GeoffreyRdn merged 9 commits into
mainfrom
geoffrey.redon/SDS-2914-multi-reason-partial-matches

Conversation

@GeoffreyRdn

@GeoffreyRdn GeoffreyRdn commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • replace the singular flattened debug-scan status with an ordered statuses array
  • collect regex candidates with every condition removed, then add each configured condition in isolation to identify every rejection reason
  • preserve deterministic status ordering and existing multipass excluded-scope behavior
  • cover multi-condition failures, serialization, per-candidate independence, and no-condition scan counts

Landing order

Important

Do not merge this PR until both prerequisite compatibility PRs have landed

Testing

  • cargo fmt --all -- --check
  • cargo test -p dd-sensitive-data-scanner debug_scan (23 passed)
  • make check-rust
  • make test-rust (457 passed)

Pull the inline included- and excluded-keyword span lookups out of
debug_scan and debug_scan_excluded_keywords into included_keyword_info
and excluded_keyword_info. Both take the compiled rule as an Option so
they can be reused by callers that have not proven the rule is a regex
rule.

No behavior change.
Replace DebugRuleMatch.status with statuses: Vec<DebugRuleMatchStatus>
and drop #[serde(flatten)] so each status serializes as a tagged object
inside a "statuses" array instead of being flattened onto the match.

Detection still yields at most one status per match, so behavior is
unchanged. This only moves the type and wire format to a list so the
next commit can report every failing condition.

BREAKING CHANGE: the debug scan JSON payload replaces the flattened
"status" field with a "statuses" array.
Partial matches previously relied on relaxing exactly one condition at a
time and keeping matches that newly appeared. When two conditions failed
together, every probe was still blocked by the other, so the candidate
was reported by none of them and disappeared from the output entirely.

Scan once with a fully relaxed rule to collect every regex candidate,
then probe each configured condition in isolation. A candidate missing
from a probe's matches was rejected by that condition, so all failing
conditions are collected instead of only the first. Statuses follow a
deterministic order: included keyword, excluded keyword, checksum,
included scope, excluded scope, suppression. Output is sorted by path
then start index.

Probes are only built for configured conditions, and the relaxed scan is
skipped when a rule has none, so a rule without conditions still scans
the event exactly once.

Multipass rejection keeps reporting InExcludedScope when an allowed-path
match is dropped because the same value occurs under an excluded path.
Add coverage for candidates rejected by several conditions at once,
including the two reported reproductions (missing included keyword with
a failing checksum, and missing included keyword with a suppression),
three simultaneous failures, and a match both outside the included scope
and inside the excluded scope.

Also cover the serialized "statuses" shape, per-candidate status
independence across paths, full and partial matches in the same event,
retained deserialization of the dormant IncludedKeywordTooFar status,
and CountingEvent assertions pinning that a rule with no conditions,
or with empty suppressions, still visits the event exactly once.
@GeoffreyRdn GeoffreyRdn changed the title SDS-2914 Report all debug scan failure reasons [SDS-2914] Report all debug scan failure reasons Sep 18, 2026
@GeoffreyRdn
GeoffreyRdn marked this pull request as ready for review September 18, 2026 15:32
@GeoffreyRdn
GeoffreyRdn requested a review from a team as a code owner September 18, 2026 15:32
@GeoffreyRdn

Copy link
Copy Markdown
Contributor Author

Other PRs were merged, waiting to be deployed.

@GeoffreyRdn
GeoffreyRdn merged commit 2e55a73 into main Sep 25, 2026
5 checks passed
@GeoffreyRdn
GeoffreyRdn deleted the geoffrey.redon/SDS-2914-multi-reason-partial-matches branch September 25, 2026 12:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants