internal/worker: readSource from outside sandbox Diagnostic messages refer to paths within the sandbox, which could be sandboxed paths since the analyzer runs in the sandbox. Change-Id: Ic7ebffee8234c47e42ff1f1fa0da2b6713ebb8bf Reviewed-on: https://go-review.googlesource.com/c/pkgsite-metrics/+/713960 Reviewed-by: Ethan Lee <ethanalee@google.com> LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/internal/worker/analysis.go b/internal/worker/analysis.go index fa6cbf5..ff7e019 100644 --- a/internal/worker/analysis.go +++ b/internal/worker/analysis.go
@@ -352,6 +352,9 @@ if err != nil { return err } + if strings.HasPrefix(file, "/root/go/pkg/mod") { + file = "/bundle/rootfs" + file + } source, err := readSource(file, line, nContext) if err != nil { return fmt.Errorf("reading %s:%d: %w", file, line, err)