Commit 20a12c9
authored
feat: add PolicyCheck callback to CopyOptions (#1189)
## What
Adds an optional `PolicyCheck` callback to `CopyOptions`:
```go
PolicyCheck func(ctx context.Context, srcRef string) error
```
`Copy` invokes it once with the source reference before any I/O. A
non-nil return aborts the copy and the error is wrapped via `%w`
(`policy check failed for %s: %w`).
When `PolicyCheck` is nil the behavior is unchanged.
## Why
Lets callers plug in policy enforcement (e.g., containers-policy.json
signature/identity checks) without the root `oras` package taking a
build-time dependency on the `policy` package. Keeps the `oras` <->
`registry/remote/policy` boundary clean.
Part of the v3 PR-by-PR breakdown (**PR 17: `feat/copy-policy-check`**).
Self-contained; no new package deps.
(Note: prs.md lists `content_test.go`, `example_test.go`, and
`example_copy_test.go` under this PR, but those diffs in
`feat/everything` are actually `repo.Registry.PlainHTTP` /
`NewCredentialFunc` renames that belong to PR 13. They are intentionally
excluded here so this PR stays scoped to PolicyCheck.)
## Test plan
- [x] `go build -mod=mod ./...`
- [x] `go test -mod=mod -run TestCopy_PolicyCheck -v .` — PASS for
`rejected`, `allowed`, `no policy` subtests
- [x] `go test -mod=mod -run Copy .` — full Copy test family passes
Signed-off-by: Terry Howe <terrylhowe@gmail.com>1 parent 702345e commit 20a12c9
2 files changed
Lines changed: 109 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
54 | 54 | | |
55 | 55 | | |
56 | 56 | | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
57 | 63 | | |
58 | 64 | | |
59 | 65 | | |
| |||
136 | 142 | | |
137 | 143 | | |
138 | 144 | | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
139 | 153 | | |
140 | 154 | | |
141 | 155 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2635 | 2635 | | |
2636 | 2636 | | |
2637 | 2637 | | |
| 2638 | + | |
| 2639 | + | |
| 2640 | + | |
| 2641 | + | |
| 2642 | + | |
| 2643 | + | |
| 2644 | + | |
| 2645 | + | |
| 2646 | + | |
| 2647 | + | |
| 2648 | + | |
| 2649 | + | |
| 2650 | + | |
| 2651 | + | |
| 2652 | + | |
| 2653 | + | |
| 2654 | + | |
| 2655 | + | |
| 2656 | + | |
| 2657 | + | |
| 2658 | + | |
| 2659 | + | |
| 2660 | + | |
| 2661 | + | |
| 2662 | + | |
| 2663 | + | |
| 2664 | + | |
| 2665 | + | |
| 2666 | + | |
| 2667 | + | |
| 2668 | + | |
| 2669 | + | |
| 2670 | + | |
| 2671 | + | |
| 2672 | + | |
| 2673 | + | |
| 2674 | + | |
| 2675 | + | |
| 2676 | + | |
| 2677 | + | |
| 2678 | + | |
| 2679 | + | |
| 2680 | + | |
| 2681 | + | |
| 2682 | + | |
| 2683 | + | |
| 2684 | + | |
| 2685 | + | |
| 2686 | + | |
| 2687 | + | |
| 2688 | + | |
| 2689 | + | |
| 2690 | + | |
| 2691 | + | |
| 2692 | + | |
| 2693 | + | |
| 2694 | + | |
| 2695 | + | |
| 2696 | + | |
| 2697 | + | |
| 2698 | + | |
| 2699 | + | |
| 2700 | + | |
| 2701 | + | |
| 2702 | + | |
| 2703 | + | |
| 2704 | + | |
| 2705 | + | |
| 2706 | + | |
| 2707 | + | |
| 2708 | + | |
| 2709 | + | |
| 2710 | + | |
| 2711 | + | |
| 2712 | + | |
| 2713 | + | |
| 2714 | + | |
| 2715 | + | |
| 2716 | + | |
| 2717 | + | |
| 2718 | + | |
| 2719 | + | |
| 2720 | + | |
| 2721 | + | |
| 2722 | + | |
| 2723 | + | |
| 2724 | + | |
| 2725 | + | |
| 2726 | + | |
| 2727 | + | |
| 2728 | + | |
| 2729 | + | |
| 2730 | + | |
| 2731 | + | |
| 2732 | + | |
0 commit comments