Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

policy improvements #139

Merged
merged 3 commits into from
Jan 5, 2024
Merged

policy improvements #139

merged 3 commits into from
Jan 5, 2024

Conversation

danmihai1
Copy link

  • genpolicy: reject kernel_modules
  • genpolicy: validate create sandbox storages
  • policy: update samples

Reject any CreateSandboxRequest kernel_modules, because these modules
may be used by an attacker.

Signed-off-by: Dan Mihai <[email protected]>
Reject any unexpected values from the CreateSandboxRequest storages
field.

Signed-off-by: Dan Mihai <[email protected]>
Update sample files after genpolicy changes.

Signed-off-by: Dan Mihai <[email protected]>
@danmihai1 danmihai1 merged commit cb8b47c into msft-main Jan 5, 2024
@danmihai1 danmihai1 deleted the danmihai1/policy-improvements2 branch January 21, 2024 16:06
@sprt sprt added the upstream/missing PRs that are yet to be upstreamed label Jan 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
upstream/missing PRs that are yet to be upstreamed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants