Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Default deny GPIO access #41

Open
marnovandermaas opened this issue Sep 5, 2024 · 1 comment
Open

Default deny GPIO access #41

marnovandermaas opened this issue Sep 5, 2024 · 1 comment
Labels
enhancement New feature or request

Comments

@marnovandermaas
Copy link
Contributor

Is there a way to default deny the GPIO access through the rego unless you explicitly define that the compartment has access to it?

@marnovandermaas marnovandermaas added the enhancement New feature or request label Sep 5, 2024
@HU90m
Copy link
Member

HU90m commented Sep 16, 2024

Yes this is possible with cheriot-audit's built-in compartment package, specifically the mmio_allow_list rule with an empty allow set.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants