policy: normalize local policy paths

Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
This commit is contained in:
CrazyMax
2026-07-17 11:29:51 +02:00
parent 59af558217
commit bd4ea1bb06
2 changed files with 52 additions and 4 deletions
+3 -4
View File
@@ -200,7 +200,7 @@ func (p *policyPathFSRef) resolve(name string) (fs.StatFS, string, error) {
if err != nil {
return nil, "", err
}
return cwd, filepath.Clean(v), nil
return cwd, path.Clean(filepath.ToSlash(v)), nil
}
contextFS, err := p.getContextFS()
@@ -276,13 +276,12 @@ func (p *policyPathFSRef) Close() error {
func normalizeLocalPolicyPath(name, contextDir string) string {
if filepath.IsAbs(name) && contextDir != "" {
if rel, err := filepath.Rel(contextDir, name); err == nil {
rel = filepath.Clean(rel)
if rel != ".." && !strings.HasPrefix(rel, ".."+string(filepath.Separator)) {
return rel
return path.Clean(filepath.ToSlash(rel))
}
}
}
return filepath.Clean(name)
return path.Clean(filepath.ToSlash(name))
}
type memoizedPolicyFS struct {
+49
View File
@@ -11,6 +11,55 @@ import (
"github.com/stretchr/testify/require"
)
func TestLoadPolicyDataLocalPaths(t *testing.T) {
dir := t.TempDir()
policyData := []byte("package docker\n")
policyRelPath := filepath.Join("policy", "allow.rego")
require.NoError(t, os.MkdirAll(filepath.Join(dir, "policy"), 0700))
require.NoError(t, os.WriteFile(filepath.Join(dir, policyRelPath), policyData, 0600))
t.Run("context-relative", func(t *testing.T) {
provider := newPolicyPathFS(context.Background(), nil, policyOpt{
ContextDir: dir,
})
dt, ok, err := loadPolicyData(provider, policyRelPath)
require.NoError(t, err)
require.True(t, ok)
require.Equal(t, policyData, dt)
})
t.Run("context-absolute", func(t *testing.T) {
provider := newPolicyPathFS(context.Background(), nil, policyOpt{
ContextDir: dir,
})
dt, ok, err := loadPolicyData(provider, filepath.Join(dir, policyRelPath))
require.NoError(t, err)
require.True(t, ok)
require.Equal(t, policyData, dt)
})
t.Run("cwd", func(t *testing.T) {
cwd, err := os.Getwd()
require.NoError(t, err)
require.NoError(t, os.Chdir(dir))
t.Cleanup(func() {
require.NoError(t, os.Chdir(cwd))
})
provider := newPolicyPathFS(context.Background(), nil, policyOpt{})
dt, ok, err := loadPolicyData(provider, "cwd://"+policyRelPath)
require.NoError(t, err)
require.True(t, ok)
require.Equal(t, policyData, dt)
})
}
func TestNormalizeLocalPolicyPath(t *testing.T) {
require.Equal(t, "policy/allow.rego", normalizeLocalPolicyPath(filepath.Join("policy", "allow.rego"), ""))
}
func TestMemoizedPolicyFSRefCountedClose(t *testing.T) {
var initCalls int
var closeCalls int