internal/worker: readSource from outside sandbox

Diagnostic messages refer to paths within the sandbox, which could be
sandboxed paths since the analyzer runs in the sandbox.

Change-Id: Ic7ebffee8234c47e42ff1f1fa0da2b6713ebb8bf
Reviewed-on: https://go-review.googlesource.com/c/pkgsite-metrics/+/713960
Reviewed-by: Ethan Lee <ethanalee@google.com>
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/internal/worker/analysis.go b/internal/worker/analysis.go
index fa6cbf5..ff7e019 100644
--- a/internal/worker/analysis.go
+++ b/internal/worker/analysis.go
@@ -352,6 +352,9 @@
 		if err != nil {
 			return err
 		}
+		if strings.HasPrefix(file, "/root/go/pkg/mod") {
+			file = "/bundle/rootfs" + file
+		}
 		source, err := readSource(file, line, nContext)
 		if err != nil {
 			return fmt.Errorf("reading %s:%d: %w", file, line, err)