MCPcopy Create free account
hub / github.com/docker/buildx / CheckPolicy

Method CheckPolicy

policy/validate.go:226–365  ·  view source on GitHub ↗
(ctx context.Context, req *policysession.CheckPolicyRequest)

Source from the content-addressed store, hash-verified

224}
225
226func (p *Policy) CheckPolicy(ctx context.Context, req *policysession.CheckPolicyRequest) (*policysession.DecisionResponse, *gwpb.ResolveSourceMetaRequest, error) {
227 if req.Source == nil || req.Source.Source == nil {
228 return nil, nil, errors.Errorf("no source info in request")
229 }
230
231 var platform *ocispecs.Platform
232 if req.Platform != nil {
233 pl, err := platformFromReq(req)
234 if err != nil {
235 return nil, nil, err
236 }
237 platform = pl
238 } else {
239 platform = p.opt.DefaultPlatform
240 }
241
242 inp, err := SourceToInput(ctx, p.opt.VerifierProvider, req.Source, platform, p.opt.Log)
243 if err != nil {
244 return nil, nil, errors.Wrap(err, "failed to build policy input")
245 }
246
247 baseOpts, closeRoot, err := p.regoBaseOpts()
248 if err != nil {
249 return nil, nil, err
250 }
251 defer closeRoot()
252
253 p.log(logrus.InfoLevel, "checking policy for source %s", sourceName(req))
254
255 for range maxResolveIterations {
256 runInput := inp
257 applyEnvWithDepth(&runInput, p.opt.Env, 0)
258
259 runOpts := append([]func(*rego.Rego){}, baseOpts...)
260 runOpts = append(runOpts, rego.Input(runInput))
261
262 st := &state{Input: runInput}
263 for _, f := range p.funcs {
264 runOpts = append(runOpts, f.impl(st))
265 }
266
267 dt, err := json.MarshalIndent(runInput, "", " ")
268 if err != nil {
269 return nil, nil, errors.Wrapf(err, "failed to marshal policy input")
270 }
271 p.log(logrus.DebugLevel, "policy input: %s", dt)
272
273 unknowns := inp.Unknowns()
274 if len(unknowns) > 0 {
275 p.log(logrus.DebugLevel, "unknowns for policy evaluation: %+v", summarizeUnknownsForLog(unknowns))
276 runOpts = append(runOpts, rego.Unknowns(unknowns))
277 }
278 r := rego.New(runOpts...)
279
280 if len(unknowns) > 0 {
281 pq, err := r.Partial(ctx)
282 if err != nil {
283 return nil, nil, err

Callers 4

resolveTestInputFunction · 0.95
runEvalFunction · 0.95
runDefaultPolicyImageFunction · 0.80

Calls 15

regoBaseOptsMethod · 0.95
logMethod · 0.95
resolveUnknownsMethod · 0.95
recordDenyIdentifierMethod · 0.95
platformFromReqFunction · 0.85
SourceToInputFunction · 0.85
sourceNameFunction · 0.85
applyEnvWithDepthFunction · 0.85
summarizeUnknownsForLogFunction · 0.85
collectUnknownsFunction · 0.85
runtimeUnknownInputRefsFunction · 0.85
policyDecisionFromResultFunction · 0.85

Tested by 2

runDefaultPolicyImageFunction · 0.64