mirror of
https://github.com/microsoft/regorus.git
synced 2026-08-05 02:16:11 +00:00
feat: make policy length limits configurable per engine (#624)
- Add PolicyLengthConfig struct with max_col, max_file_bytes, and max_lines fields, replacing hardcoded constants in the lexer. - Add Engine::set_policy_length_config and clear_policy_length_config to allow callers to override the default limits. - Add Source::from_contents_with_limits and from_file_with_limits for direct Source construction with custom limits; existing from_contents and from_file signatures are preserved using defaults. - Add tests for default rejection, custom limits, and engine plumbing. - Add bindings for C, C++, Python, WASM/JS, Java, Ruby, C#, Go
This commit is contained in:
@@ -270,3 +270,90 @@ fn file_more_than_64_kb_size() -> Result<()> {
|
||||
assert_eq!(count, 8789);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn default_limits_reject_oversized_file() {
|
||||
let big = "x".repeat(1_048_577);
|
||||
let err = Source::from_contents("big.rego".into(), big).unwrap_err();
|
||||
assert!(err
|
||||
.to_string()
|
||||
.contains("exceeds maximum allowed policy file size"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn custom_limits_accept_larger_file() {
|
||||
use core::num::NonZeroUsize;
|
||||
|
||||
let big = "x".repeat(1_048_577);
|
||||
assert!(Source::from_contents_with_limits(
|
||||
"big.rego".into(),
|
||||
big,
|
||||
NonZeroUsize::new(2_097_152).unwrap(),
|
||||
NonZeroUsize::new(1).unwrap()
|
||||
)
|
||||
.is_ok());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn custom_limits_reject_line_count() {
|
||||
use core::num::NonZeroUsize;
|
||||
|
||||
let err = Source::from_contents_with_limits(
|
||||
"lines.rego".into(),
|
||||
"x\n".repeat(6),
|
||||
NonZeroUsize::new(100).unwrap(),
|
||||
NonZeroUsize::new(5).unwrap(),
|
||||
)
|
||||
.unwrap_err();
|
||||
assert!(err
|
||||
.to_string()
|
||||
.contains("exceeds maximum allowed line count"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn engine_policy_length_config_flows_through() -> Result<()> {
|
||||
use core::num::NonZeroUsize;
|
||||
use regorus::{Engine, PolicyLengthConfig};
|
||||
|
||||
let mut engine = Engine::new();
|
||||
engine.set_policy_length_config(PolicyLengthConfig {
|
||||
max_file_bytes: NonZeroUsize::new(10).unwrap(),
|
||||
..Default::default()
|
||||
});
|
||||
|
||||
let err = engine
|
||||
.add_policy("test.rego".into(), "package test".into())
|
||||
.unwrap_err();
|
||||
assert!(err
|
||||
.to_string()
|
||||
.contains("exceeds maximum allowed policy file size"));
|
||||
|
||||
engine.clear_policy_length_config();
|
||||
engine.add_policy("test.rego".into(), "package test".into())?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn custom_max_col_allows_wide_line() -> Result<()> {
|
||||
use core::num::NonZeroU32;
|
||||
use regorus::{Engine, PolicyLengthConfig};
|
||||
|
||||
// A line wider than the default 1024 columns.
|
||||
let wide = format!("package test\na := \"{}\"", "x".repeat(2000));
|
||||
|
||||
let mut engine = Engine::new();
|
||||
|
||||
// Should fail with default limits.
|
||||
let err = engine
|
||||
.add_policy("wide.rego".into(), wide.clone())
|
||||
.unwrap_err();
|
||||
assert!(err.to_string().contains("maximum column width"));
|
||||
|
||||
// Should succeed with a raised max_col.
|
||||
engine.set_policy_length_config(PolicyLengthConfig {
|
||||
max_col: NonZeroU32::new(4096).unwrap(),
|
||||
..Default::default()
|
||||
});
|
||||
engine.add_policy("wide.rego".into(), wide)?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user