genpolicy: Enable AdditionalGids checks in rules.rego

With added support for parsing these fields in genpolicy, we can now
enable policy verification of AdditionalGids.

Signed-off-by: Cameron Baird <cameronbaird@microsoft.com>
This commit is contained in:
Cameron Baird
2025-04-24 22:25:55 +00:00
parent 29ee46c186
commit d3cd1af593

View File

@@ -699,8 +699,8 @@ allow_user(p_process, i_process) {
print("allow_user: input gid =", i_user.GID, "policy gid =", p_user.GID)
p_user.GID == i_user.GID
# TODO: compare the additionalGids field too after computing its value
# based on /etc/passwd and /etc/group from the container image.
print("allow_user: input additionalGids =", i_user.AdditionalGids, "policy additionalGids =", p_user.AdditionalGids)
p_user.AdditionalGids == i_user.AdditionalGids
}
allow_args(p_process, i_process, s_name) {