Clarify extended permission evaluation - #48
Conversation
dburgener
left a comment
There was a problem hiding this comment.
Thanks for the PR!
I think the overall idea that this needs more clarification is good, but I do have some comments hoping to clarify and sharpen the explanation a bit before we merge.
| considered. | ||
|
|
||
| * If an extended permission rule is defined, the policy is first evaluated | ||
| according to the high-level resource policy. For example: |
There was a problem hiding this comment.
See above regarding "high-level resource policy". Additionally, I think this could spell out the situation more explicitly. After the AVC and constraint checks are performed, then the xperm checks will be applied.
There was a problem hiding this comment.
That makes sense, thank you. I have updated this to clarify "standard AVC checks".
Great, thank you for the review! I have attempted to clarify the explanation as per your comments, but please let me know if anything could use further clarification. |
|
Thanks for the updates! This seems good to me now. My typical practice is to leave approved PRs up for a week or two in case any other maintainers have comments and then merge via direct push. In this case, since this has been open for a while and other maintainers have had some time, I'll probably plan to merge later this week. |
|
Great, thank you! That sounds good to me. |
Adding documentation to clarify the automatic-deny evaluation when extended permissions are defined, as well as the overall evaluation logic. Signed-off-by: Liz Prucka <lizprucka@google.com>
|
Merged via direct push, thanks! |
Adding documentation to clarify the automatic-deny evaluation when extended permissions are defined,
as well as the overall evaluation logic.