mirror of
https://github.com/openai/codex.git
synced 2026-09-16 12:13:30 +00:00
64 lines
1.8 KiB
Rust
64 lines
1.8 KiB
Rust
use std::fs;
|
|
use std::path::PathBuf;
|
|
|
|
use anyhow::Context;
|
|
use anyhow::Result;
|
|
use clap::Parser;
|
|
use codex_execpolicy::PolicyParser;
|
|
use codex_execpolicy::execpolicycheck::format_matches_json;
|
|
|
|
/// CLI for evaluating exec policies
|
|
#[derive(Parser)]
|
|
#[command(name = "codex-execpolicy")]
|
|
enum Cli {
|
|
/// Evaluate a command against a policy.
|
|
Check {
|
|
#[arg(short, long = "policy", value_name = "PATH", required = true)]
|
|
policies: Vec<PathBuf>,
|
|
|
|
/// Pretty-print the JSON output.
|
|
#[arg(long)]
|
|
pretty: bool,
|
|
|
|
/// Command tokens to check.
|
|
#[arg(
|
|
value_name = "COMMAND",
|
|
required = true,
|
|
trailing_var_arg = true,
|
|
allow_hyphen_values = true
|
|
)]
|
|
command: Vec<String>,
|
|
},
|
|
}
|
|
|
|
fn main() -> Result<()> {
|
|
let cli = Cli::parse();
|
|
match cli {
|
|
Cli::Check {
|
|
policies,
|
|
command,
|
|
pretty,
|
|
} => cmd_check(policies, command, pretty),
|
|
}
|
|
}
|
|
|
|
fn cmd_check(policy_paths: Vec<PathBuf>, args: Vec<String>, pretty: bool) -> Result<()> {
|
|
let policy = load_policies(&policy_paths)?;
|
|
|
|
let matched_rules = policy.matches_for_command(&args, None);
|
|
let json = format_matches_json(&matched_rules, pretty)?;
|
|
println!("{json}");
|
|
Ok(())
|
|
}
|
|
|
|
fn load_policies(policy_paths: &[PathBuf]) -> Result<codex_execpolicy::Policy> {
|
|
let mut parser = PolicyParser::new();
|
|
for policy_path in policy_paths {
|
|
let policy_file_contents = fs::read_to_string(policy_path)
|
|
.with_context(|| format!("failed to read policy at {}", policy_path.display()))?;
|
|
let policy_identifier = policy_path.to_string_lossy().to_string();
|
|
parser.parse(&policy_identifier, &policy_file_contents)?;
|
|
}
|
|
Ok(parser.build())
|
|
}
|