@@ -14,18 +14,18 @@ Signed-off-by: Markus Rudy <mr@edgeless.systems>
14
14
6 files changed, 85 insertions(+)
15
15
16
16
diff --git a/src/tools/genpolicy/rules.rego b/src/tools/genpolicy/rules.rego
17
- index a5208cf9d3b38edfe6ab777ce0bafb81bf3b84dc..aa0488ae2dffc63780967ca706ea2c8ffcfb1391 100644
17
+ index 4e4c3b3e03ddf173ebfcf07915f3f16a6801627b..b904391af531327d7def819cb9da47cd04d7124e 100644
18
18
--- a/src/tools/genpolicy/rules.rego
19
19
+++ b/src/tools/genpolicy/rules.rego
20
- @@ -62 ,6 +62 ,7 @@ CreateContainerRequest {
20
+ @@ -63 ,6 +63 ,7 @@ CreateContainerRequest {
21
21
22
22
i_oci := input.OCI
23
23
i_storages := input.storages
24
24
+ i_devices := input.devices
25
25
26
26
# Check if any element from the policy_data.containers array allows the input request.
27
27
some p_container in policy_data.containers
28
- @@ -85 ,6 +86 ,9 @@ CreateContainerRequest {
28
+ @@ -86 ,6 +87 ,9 @@ CreateContainerRequest {
29
29
p_storages := p_container.storages
30
30
allow_by_anno(p_oci, i_oci, p_storages, i_storages)
31
31
@@ -35,7 +35,7 @@ index a5208cf9d3b38edfe6ab777ce0bafb81bf3b84dc..aa0488ae2dffc63780967ca706ea2c8f
35
35
allow_linux(p_oci, i_oci)
36
36
37
37
print("CreateContainerRequest: true")
38
- @@ -361 ,6 +365 ,16 @@ allow_log_directory(p_oci, i_oci) {
38
+ @@ -362 ,6 +366 ,16 @@ allow_log_directory(p_oci, i_oci) {
39
39
print("allow_log_directory: true")
40
40
}
41
41
@@ -52,15 +52,15 @@ index a5208cf9d3b38edfe6ab777ce0bafb81bf3b84dc..aa0488ae2dffc63780967ca706ea2c8f
52
52
allow_linux(p_oci, i_oci) {
53
53
p_namespaces := p_oci.Linux.Namespaces
54
54
print("allow_linux: p namespaces =", p_namespaces)
55
- @@ -372 ,6 +386 ,7 @@ allow_linux(p_oci, i_oci) {
55
+ @@ -373 ,6 +387 ,7 @@ allow_linux(p_oci, i_oci) {
56
56
57
57
allow_masked_paths(p_oci, i_oci)
58
58
allow_readonly_paths(p_oci, i_oci)
59
59
+ allow_linux_devices(p_oci.Linux.Devices, i_oci.Linux.Devices)
60
60
61
61
print("allow_linux: true")
62
62
}
63
- @@ -460 ,6 +475 ,13 @@ allow_readonly_path(p_elem, i_array, masked_paths) {
63
+ @@ -461 ,6 +476 ,13 @@ allow_readonly_path(p_elem, i_array, masked_paths) {
64
64
print("allow_readonly_path 2: true")
65
65
}
66
66
0 commit comments