...

Text file src/github.com/Microsoft/hcsshim/pkg/securitypolicy/api.rego

Documentation: github.com/Microsoft/hcsshim/pkg/securitypolicy

     1package api
     2
     3version := "@@API_VERSION@@"
     4
     5enforcement_points := {
     6    "mount_device": {"introducedVersion": "0.1.0", "default_results": {"allowed": false}},
     7    "mount_overlay": {"introducedVersion": "0.1.0", "default_results": {"allowed": false}},
     8    "create_container": {"introducedVersion": "0.1.0", "default_results": {"allowed": false, "env_list": null, "allow_stdio_access": false}},
     9    "unmount_device": {"introducedVersion": "0.2.0", "default_results": {"allowed": true}},
    10    "unmount_overlay": {"introducedVersion": "0.6.0", "default_results": {"allowed": true}},
    11    "exec_in_container": {"introducedVersion": "0.2.0", "default_results": {"allowed": true, "env_list": null}},
    12    "exec_external": {"introducedVersion": "0.3.0", "default_results": {"allowed": true, "env_list": null, "allow_stdio_access": false}},
    13    "shutdown_container": {"introducedVersion": "0.4.0", "default_results": {"allowed": true}},
    14    "signal_container_process": {"introducedVersion": "0.5.0", "default_results": {"allowed": true}},
    15    "plan9_mount": {"introducedVersion": "0.6.0", "default_results": {"allowed": true}},
    16    "plan9_unmount": {"introducedVersion": "0.6.0", "default_results": {"allowed": true}},
    17    "get_properties": {"introducedVersion": "0.7.0", "default_results": {"allowed": true}},
    18    "dump_stacks": {"introducedVersion": "0.7.0", "default_results": {"allowed": true}},
    19    "runtime_logging": {"introducedVersion": "0.8.0", "default_results": {"allowed": true}},
    20    "load_fragment": {"introducedVersion": "0.9.0", "default_results": {"allowed": false, "add_module": false}},
    21    "scratch_mount": {"introducedVersion": "0.10.0", "default_results": {"allowed": true}},
    22    "scratch_unmount": {"introducedVersion": "0.10.0", "default_results": {"allowed": true}},
    23}

View as plain text