Enforce preconfigured policy defaults as override exceptions
What does this MR do and why?
Enforce preconfigured policy defaults as override exceptions
The scan execution policy variable override denylist was built only from
variable keys the policy author declared explicitly. Preconfigured
scan-type defaults (SAST_EXCLUDED_PATHS, DS_EXCLUDED_PATHS, etc.) never
appeared in that list, so a project-level CI/CD variable of the same name
silently won over the documented "policy can't be overridden" guarantee
whenever the policy relied on the default instead of setting the variable
itself.
This fixes Security::ScanExecutionPolicy::Config#variables_override_for
to include each scan type's preconfigured restricted variable keys
(ScanPipelineService::SCAN_VARIABLES_WITH_RESTRICTED_VARIABLES) in the
denylist alongside any variables the policy explicitly declares. This
affects the inline scan execution policy injection path (type: pipeline
policy rules running in a normal push/MR pipeline) — the dedicated
scheduled-policy pipeline path already builds its denylist from the full
merged variable set and was not affected.
References
Resolves #627552
Screenshots or screen recordings
N/A — backend-only fix, no UI change.
How to set up and validate locally
- Create a group-level scan execution policy enforcing SAST with a
pipelinerule, without declaringSAST_EXCLUDED_PATHS. - In a project under that group, set a project-level CI/CD variable
SAST_EXCLUDED_PATHS=*.py. - Run a pipeline and inspect the
semgrep-sast-0job's variables. - Before this change:
SAST_EXCLUDED_PATHSresolves to the project variable (*.py), excluding files it shouldn't. After this change: the project variable is ignored and the policy's preconfigured default applies, as documented. - Or run the added spec:
bin/rspec ee/spec/services/ci/create_pipeline_service/scan_execution_policy_spec.rb
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.