| 224 | } |
| 225 | |
| 226 | func (p *Policy) CheckPolicy(ctx context.Context, req *policysession.CheckPolicyRequest) (*policysession.DecisionResponse, *gwpb.ResolveSourceMetaRequest, error) { |
| 227 | if req.Source == nil || req.Source.Source == nil { |
| 228 | return nil, nil, errors.Errorf("no source info in request") |
| 229 | } |
| 230 | |
| 231 | var platform *ocispecs.Platform |
| 232 | if req.Platform != nil { |
| 233 | pl, err := platformFromReq(req) |
| 234 | if err != nil { |
| 235 | return nil, nil, err |
| 236 | } |
| 237 | platform = pl |
| 238 | } else { |
| 239 | platform = p.opt.DefaultPlatform |
| 240 | } |
| 241 | |
| 242 | inp, err := SourceToInput(ctx, p.opt.VerifierProvider, req.Source, platform, p.opt.Log) |
| 243 | if err != nil { |
| 244 | return nil, nil, errors.Wrap(err, "failed to build policy input") |
| 245 | } |
| 246 | |
| 247 | baseOpts, closeRoot, err := p.regoBaseOpts() |
| 248 | if err != nil { |
| 249 | return nil, nil, err |
| 250 | } |
| 251 | defer closeRoot() |
| 252 | |
| 253 | p.log(logrus.InfoLevel, "checking policy for source %s", sourceName(req)) |
| 254 | |
| 255 | for range maxResolveIterations { |
| 256 | runInput := inp |
| 257 | applyEnvWithDepth(&runInput, p.opt.Env, 0) |
| 258 | |
| 259 | runOpts := append([]func(*rego.Rego){}, baseOpts...) |
| 260 | runOpts = append(runOpts, rego.Input(runInput)) |
| 261 | |
| 262 | st := &state{Input: runInput} |
| 263 | for _, f := range p.funcs { |
| 264 | runOpts = append(runOpts, f.impl(st)) |
| 265 | } |
| 266 | |
| 267 | dt, err := json.MarshalIndent(runInput, "", " ") |
| 268 | if err != nil { |
| 269 | return nil, nil, errors.Wrapf(err, "failed to marshal policy input") |
| 270 | } |
| 271 | p.log(logrus.DebugLevel, "policy input: %s", dt) |
| 272 | |
| 273 | unknowns := inp.Unknowns() |
| 274 | if len(unknowns) > 0 { |
| 275 | p.log(logrus.DebugLevel, "unknowns for policy evaluation: %+v", summarizeUnknownsForLog(unknowns)) |
| 276 | runOpts = append(runOpts, rego.Unknowns(unknowns)) |
| 277 | } |
| 278 | r := rego.New(runOpts...) |
| 279 | |
| 280 | if len(unknowns) > 0 { |
| 281 | pq, err := r.Partial(ctx) |
| 282 | if err != nil { |
| 283 | return nil, nil, err |