Enforce preconfigured policy defaults as override exceptions

What does this MR do and why?

Enforce preconfigured policy defaults as override exceptions

The scan execution policy variable override denylist was built only from variable keys the policy author declared explicitly. Preconfigured scan-type defaults (SAST_EXCLUDED_PATHS, DS_EXCLUDED_PATHS, etc.) never appeared in that list, so a project-level CI/CD variable of the same name silently won over the documented "policy can't be overridden" guarantee whenever the policy relied on the default instead of setting the variable itself.

This fixes Security::ScanExecutionPolicy::Config#variables_override_for to include each scan type's preconfigured restricted variable keys (ScanPipelineService::SCAN_VARIABLES_WITH_RESTRICTED_VARIABLES) in the denylist alongside any variables the policy explicitly declares. This affects the inline scan execution policy injection path (type: pipeline policy rules running in a normal push/MR pipeline) — the dedicated scheduled-policy pipeline path already builds its denylist from the full merged variable set and was not affected.

References

Resolves #627552

Screenshots or screen recordings

N/A — backend-only fix, no UI change.

How to set up and validate locally

  1. Create a group-level scan execution policy enforcing SAST with a pipeline rule, without declaring SAST_EXCLUDED_PATHS.
  2. In a project under that group, set a project-level CI/CD variable SAST_EXCLUDED_PATHS=*.py.
  3. Run a pipeline and inspect the semgrep-sast-0 job's variables.
  4. Before this change: SAST_EXCLUDED_PATHS resolves to the project variable (*.py), excluding files it shouldn't. After this change: the project variable is ignored and the policy's preconfigured default applies, as documented.
  5. Or run the added spec: bin/rspec ee/spec/services/ci/create_pipeline_service/scan_execution_policy_spec.rb

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading