Files
bee/audit/internal/collector/dmesg_events_test.go
T
Mikhail ChusavitinandClaude Sonnet 5 56d12b1f3c fix(collector): use word-boundary matching for dmesg severity
dmesgSeverity classified a kernel log line as Critical via plain
strings.Contains, without word boundaries, so common words that merely
contain a keyword as a substring false-positive — "disabled by
default" was flagged Critical because "default" contains "fault"
(de-fault). Found in a support bundle where 140/238 event_logs entries
came back Critical, most of them harmless boot messages (module load
notices, "... is initialized", "disabled by default"), drowning out
genuinely critical entries (Xid, AER, ECC) in the same list.

Switch to the same \b-bounded regexes already used for the capture
patterns above it in this file.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-24 17:41:28 +03:00

57 lines
1.5 KiB
Go

package collector
import "testing"
func TestDmesgSeverity_xidCodes(t *testing.T) {
tests := []struct {
name string
msg string
want string
}{
{
name: "xid 64 remap write failure escalates to critical",
msg: "NVRM: Xid (PCI:0000:65:00): 64, pid=1234, name=python",
want: statusCritical,
},
{
name: "xid 94 contained ecc is downgraded to warning",
msg: "NVRM: Xid (PCI:0000:65:00): 94, pid=1234, name=python",
want: statusWarning,
},
{
name: "xid 63 remap committed is downgraded to warning",
msg: "NVRM: Xid (PCI:0000:65:00): 63, pid=1234, Class 0x90a0",
want: statusWarning,
},
{
name: "unrecognized xid code falls back to generic critical",
msg: "NVRM: Xid (PCI:0000:65:00): 79, pid=1234, GPU has fallen off the bus",
want: statusCritical,
},
{
name: "non-xid generic error keyword",
msg: "blk_update_request: I/O error, dev sda",
want: statusCritical,
},
{
name: "disabled by default is not a fault substring match",
msg: "Yama: disabled by default; enable with sysctl kernel.yama.*",
want: statusWarning,
},
{
name: "benign NVRM driver load message still escalates via NVRM keyword",
msg: "NVRM: loading NVIDIA UNIX Open Kernel Module for x86_64 580.159.03",
want: statusCritical,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
got := dmesgSeverity(tt.msg)
if got != tt.want {
t.Fatalf("dmesgSeverity(%q) = %q, want %q", tt.msg, got, tt.want)
}
})
}
}