Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions src/macaron/__main__.py
Original file line number Diff line number Diff line change
Expand Up @@ -197,14 +197,31 @@ def verify_policy(verify_policy_args: argparse.Namespace) -> int:
show_prelude(verify_policy_args.database)
return os.EX_OK

policy_content = None
if verify_policy_args.file:
if not os.path.isfile(verify_policy_args.file):
logger.critical('The policy file "%s" does not exist.', verify_policy_args.file)
return os.EX_OSFILE

with open(verify_policy_args.file, encoding="utf-8") as file:
policy_content = file.read()
elif verify_policy_args.policy:
policy_dir = os.path.join(macaron.MACARON_PATH, "resources/policies/datalog")
available_policies = [policy[:-12] for policy in os.listdir(policy_dir) if policy.endswith(".dl.template")]
if verify_policy_args.policy not in available_policies:
logger.error(
"The policy %s is not available. Available policies are: %s",
verify_policy_args.policy,
available_policies,
)
return os.EX_USAGE
policy_path = os.path.join(policy_dir, f"{verify_policy_args.policy}.dl.template")
with open(policy_path, encoding="utf-8") as file:
policy_content = file.read()
if verify_policy_args.package_url:
policy_content = policy_content.replace("<PACKAGE_PURL>", verify_policy_args.package_url)

if policy_content:
result = run_policy_engine(verify_policy_args.database, policy_content)
vsa = generate_vsa(policy_content=policy_content, policy_result=result)
if vsa is not None:
Expand Down Expand Up @@ -538,7 +555,9 @@ def main(argv: list[str] | None = None) -> None:
vp_group = vp_parser.add_mutually_exclusive_group(required=True)

vp_parser.add_argument("-d", "--database", required=True, type=str, help="Path to the database.")
vp_parser.add_argument("-purl", "--package-url", help="PackageURL for policy template.")
vp_group.add_argument("-f", "--file", type=str, help="Path to the Datalog policy.")
vp_group.add_argument("-p", "--policy", help="Example policy to run.")
vp_group.add_argument("-s", "--show-prelude", action="store_true", help="Show policy prelude.")

# Find the repo and commit of a passed PURL, or the commit of a passed PURL and repo.
Expand Down
Loading