Skip to content

Commit

Permalink
llbsolver: fix policy rule ordering
Browse files Browse the repository at this point in the history
The older of rules in policy matters. Eg. in [DENY *, ALLOW ref]
mixing the order would deny all sources so map can't be used
to deduplicate the rules.

Signed-off-by: Tonis Tiigi <[email protected]>
(cherry picked from commit 22d8446)
Signed-off-by: Brian Goff <[email protected]>
  • Loading branch information
tonistiigi authored and cpuguy83 committed Sep 7, 2023
1 parent 832fdb5 commit 28012fb
Showing 1 changed file with 5 additions and 11 deletions.
16 changes: 5 additions & 11 deletions solver/llbsolver/solver.go
Original file line number Diff line number Diff line change
Expand Up @@ -977,27 +977,21 @@ func loadEntitlements(b solver.Builder) (entitlements.Set, error) {
}

func loadSourcePolicy(b solver.Builder) (*spb.Policy, error) {
set := make(map[spb.Rule]struct{}, 0)
var srcPol spb.Policy
err := b.EachValue(context.TODO(), keySourcePolicy, func(v interface{}) error {
x, ok := v.(spb.Policy)
if !ok {
return errors.Errorf("invalid source policy %T", v)
}
for _, f := range x.Rules {
set[*f] = struct{}{}
r := *f
srcPol.Rules = append(srcPol.Rules, &r)
}
srcPol.Version = x.Version
return nil
})
if err != nil {
return nil, err
}
var srcPol *spb.Policy
if len(set) > 0 {
srcPol = &spb.Policy{}
for k := range set {
k := k
srcPol.Rules = append(srcPol.Rules, &k)
}
}
return srcPol, nil
return &srcPol, nil
}

0 comments on commit 28012fb

Please sign in to comment.