feat(azure_policy): test runner, compiler fixes, and example program (#700)

Adds the YAML test runner that exercises the companion test data PRs, plus
several compiler fixes surfaced during testing:

- Removed parameter register caching that produced wrong results inside
  short-circuiting allOf/anyOf blocks; added literal-index caching for
  parameter defaults to avoid repeated O(n) literal-table scans
- Simplified cross-resource effect details to only emit roleDefinitionIds
  and type (deployment templates are not evaluated for compliance)
- Replaced guid/uniqueString builtins with clear "unsupported" errors
- Normalized datetime output to ISO 8601 with Z suffix
- Added azure_policy parser MAX_COL constant (8192) for long template
  expressions, keeping the global DEFAULT_MAX_COL at 1024
- Added rvm to azure_policy feature dependencies since the compiler
  targets RVM bytecode

Also restructures the example binary into examples/regorus/ with new
azure-policy-eval and azure-policy-aliases subcommands, adds C# alias
normalization tests, and documents Azure Policy support in the README.

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
Anand Krishnamoorthi
2026-04-30 13:02:37 -05:00
committed by GitHub
parent 7f42115b63
commit 4c92fb4d92
24 changed files with 1555 additions and 191 deletions

View File

@@ -1,9 +1,10 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.
# Parse Error Test Suite
# Tests that malformed policy JSON and invalid constructs are properly rejected.
# These test cases are expected to fail parsing.
# Parse Error and Edge Case Test Suite
# Tests mostly malformed policy JSON and invalid constructs to ensure they are
# properly rejected, but also includes valid edge cases that verify parser
# behavior at boundary conditions.
cases:
# =========================================================================
@@ -267,3 +268,33 @@ cases:
resource:
type: "any"
want_effect: "deny"
# =========================================================================
# Compile errors: unsupported deployment-template functions
# =========================================================================
- note: guid_compile_error
policy_rule: |
{
"if": {
"value": "[guid('baseString')]",
"equals": "anything"
},
"then": { "effect": "deny" }
}
resource:
type: "any"
want_compile_error: true
- note: uniquestring_compile_error
policy_rule: |
{
"if": {
"value": "[uniqueString('baseString')]",
"equals": "anything"
},
"then": { "effect": "deny" }
}
resource:
type: "any"
want_compile_error: true