Commit Graph

239 Commits

Author SHA1 Message Date
Jay Lorch
2b4ab8e12d Simpler spec for Number::eq 2026-03-19 14:48:03 -07:00
Jay Lorch
41c2d502fa Simplify Number::eq spec 2026-03-19 13:58:10 -07:00
Jay Lorch
85e58c6f6c Simplify float comparisons by assuming IEEE 2026-03-19 11:52:35 -07:00
Jay Lorch
9e18ded98e Simplify float spec by avoiding partial_cmp_spec 2026-03-19 11:33:30 -07:00
Jay Lorch
2e454f2708 Simplify float specs by assuming determinism 2026-03-19 10:49:59 -07:00
Jay Lorch
d107c1b647 Use float specs in latest Verus 2026-03-18 18:21:10 -07:00
Jay Lorch
462e39f2ad Switch to attribute syntax 2026-03-12 18:31:02 -07:00
Jay Lorch
7e1afe0e86 More specs for Number 2026-03-11 17:43:20 -07:00
Jay Lorch
100be610db Don't shut off so much of bigint when not verifying 2026-03-03 17:00:30 -08:00
Jay Lorch
586d631f09 Got cargo build working 2026-03-03 16:46:09 -08:00
Jay Lorch
5819992d17 More progress toward cargo build 2026-03-03 16:44:31 -08:00
Jay Lorch
90894aa8e1 Progress to cargo build success 2026-03-03 16:35:05 -08:00
Jay Lorch
1f2a2ecb41 More specs for Number 2026-03-03 16:20:59 -08:00
Jay Lorch
ba987998c4 More Number proofs 2026-03-03 15:58:36 -08:00
Jay Lorch
c3813c8876 Avoid some build errors 2026-03-03 15:16:35 -08:00
Jay Lorch
6ab452989f Proofs about some float operations 2026-03-03 14:43:45 -08:00
Jay Lorch
4865364b48 Verus specs for BigNum, Number 2026-02-27 15:52:00 -08:00
Jay Lorch
156772c523 Add Verus dependencies 2026-02-17 13:25:11 -08:00
Anand Krishnamoorthi
3f7a5496dc feat(bindings)!: add RVM/Program support across FFI and language bindings (#565)
- FFI: add RVM/Program APIs, execution state accessors, HostAwait handling, and buffer/result helpers in rvm.rs, common.rs, engine.rs.
- Compiler: emit HostAwait for __builtin_host_await in function_calls.rs.
- RVM tests: add HostAwait regression cases and extend harness for suspend/resume responses in host_await.yaml and mod.rs.
- C/C++: add RVM tests/examples and wrapper updates in rvm_tests.c, rvm_tests.cpp, regorus.hpp, plus CMake wiring.
- C#: add Program/Rvm bindings, SafeHandle/PInvoke, tests, and example usage in Regorus, RvmProgramTests.cs, Program.cs, and README updates.
- Go: add Program/Rvm bindings, tests, and examples in rvm.go, rvm_test.go, main.go.
- Java: add Program/Rvm bindings, JNI glue, and examples in lib.rs, regorus, Test.java.
- Python: add Program/Rvm bindings and examples in lib.rs, test.py.
- WASM: add Program/Rvm bindings and examples in lib.rs, test.js.
- Tooling: wire binding tests in xtask and ignore generated Java artifacts in .gitignore.

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2026-01-30 23:55:31 +05:30
Anand Krishnamoorthi
10eebfe54c test(rvm): Move vm execution limit tests to a separate test to avoid flakiness (#558)
Having a separate integration test allows the execution tests to freely
change the global fallback limits without affecting other tests.

also ask release-plz to ignore xtask package

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2026-01-29 04:15:33 +05:30
Anand Krishnamoorthi
394625d4bc feat!: add cooperative execution-time limits across engine, VM, and binding (#539)
- Introduce ExecutionTimer/ExecutionTimerConfig to allow limiting evaluating time.
- To amortize time checking costs, checking interval can be configured via the notion of work units
- A global fallback time limit can be set to universally limit all evaluation in addition to engine level limit setting.
- Implement limnits in interpreter and RVM. In RVM, also handle suspend/resume so that time during pause is not counted.
- Add engine-level APIs to set/clear per-engine timer configuration and apply global fallback defaults.
- Surface execution-time limits through FFI and C# bindings
- Add C# tests and example usage to validate engine overrides, global fallback behavior, and compiled policy enforcement.
- Expand docs for execution-time limit
- Add interpreter YAML cases and VM unit tests for time-limit behavior and deterministic time sources.

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2026-01-28 05:58:03 +05:30
Anand Krishnamoorthi
fd59bb5a91 feat(memory): Allocator-backed global memory limits (#544)
Policy evaluation at scale needs to be able to set memory limits
so that a bad policy does not hog memory or to ensure that
policy evaluation itself does not use too much memory which could
cause other components to suffer.

This PR introduces capability to set and enforce global memory limits.
It also lays the groundwork for enabling per evaluation limits in future.

Once a global memory limit is set, Regorus maintains per thread counters
to track memory activity (allocation, deallocation) of a thread.
These counters are periodically flushed to global memory counters.
Per thread counters avoid the contention that updating global counters
on each alloc/free would cause.

Policy evaluation periodically checks these counters and raises errors
if allocated memory has exceeded the configured limit.

Currently memory limit capability is exposed only to FFI and C#.

Also update mimalloc to v2.2.6

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2026-01-24 07:08:54 +05:30
Anand Krishnamoorthi
9426b2ec02 fix: Imports without a name binding (#543)
Handle imports that don't use the `as` clause to create a binding.
These imports are bound to the last identifier in the imported path.

Fix both interpreter and compiler.
Add tests.

fixes #541

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2026-01-15 03:57:52 +05:30
Anand Krishnamoorthi
740db8a0f5 chore: Harden RVM implementation (#537)
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2026-01-14 06:07:31 +05:30
Anand Krishnamoorthi
5afbd96159 chore: Interpreter hardening (#536)
Fix majority of the interpreter lint errors/warnings

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-30 18:21:09 -06:00
Anand Krishnamoorthi
28891ef883 chore: Harden instructions and program (#535)
Also enforce sane limits in program

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-30 18:20:07 -06:00
Anand Krishnamoorthi
49958c2ece chore: Make clippy clean and harden helpers (#532)
- Promote common accessors (Expr/Rule span/eidx, ScopeContext constructors, Engine::set_rego_v0) to const
- Prefer Option combinators (map_or, then_some) and map_or_else
- Tighten engine logic: add missing semicolons, use checked u32::try_from, make boolean query evaluation avoid unchecked indexing,

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-29 14:47:09 -06:00
Anand Krishnamoorthi
08a5e00960 chore: Harden lexer bounds and span handling (#531)
- Document arithmetic safety assumptions and add explicit lexer limits for columns, file size (1 MiB), and line count.
  Realistic policies will be well within these bounds.
- Use checked arithmetic to prevent overflow underflow.
- Avoid var name shadowing.
- Misc clippy lints

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-29 14:46:05 -06:00
Anand Krishnamoorthi
1d71df30b6 chore: Fix lint errors in lookup.rs (#530)
- Made the lookup module crate-visible to address clippy’s redundant visibility lint.
- Replaced unchecked as casts with a fallible usize_from_u32 helper and propagate conversion errors in lookup accessors.
- Switched LookupIndexError to implement core::error::Error for no_std correctness.
- Fixed the pattern type mismatch by matching on the value in the Display impl.
- Promoted trivial helpers to const fn (new, module_len) per clippy suggestions.
- Centralized bounds-checked slot access via slot_ref/slot_mut to keep getters/clearers lint-clean and avoid unchecked indexing.

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-29 13:53:46 -06:00
Anand Krishnamoorthi
249dcd0b43 chore: Add clippy lints (#529)
Lints are added (deny) at crate level.

In each offending file, the failing lints are explicitly allowed.
Each file will be fixed in subsequent PRs.

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-23 15:59:34 -06:00
Anand Krishnamoorthi
dbfb8e38a8 fix: Skip reordering in truncated queries.
In case all the statements of a query don't execute,
skip reordering the result expressions to match the
source order. Doing so requires maintaining additional
data structures not worth the complexity for now.

Additionally we want to discourage queries and encourage
evaluating rules. Queries are inherently less performant
than rules which can be precompiled.

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-19 12:08:09 -06:00
Anand Krishnamoorthi
273a80571e fix: apply expression ordering to schedule in a safe way
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-19 11:33:25 -06:00
Anand Krishnamoorthi
3f29eb2fa6 fix: Create ordered statements in a safe way
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-19 11:33:25 -06:00
Anand Krishnamoorthi
889a02ddd6 fix: Avoid unwrap when accesssing current module
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-19 11:33:24 -06:00
Anand Krishnamoorthi
70f63a0982 fix: Avoid unrap/expect in context management
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-19 11:33:24 -06:00
Anand Krishnamoorthi
6bc1249dc8 feat: Safeguard lookup use
Detect invalid indexes and raise internal errors.

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-19 11:33:24 -06:00
Anand Krishnamoorthi
5d0cf95332 feat: add recursion limit to parser
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-19 11:33:24 -06:00
Anand Krishnamoorthi
fd4bb3081f feat: Safeguard against panics in parser
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-19 11:33:24 -06:00
Anand Krishnamoorthi
93a633750c feat: Guard against runtime panics in lexer
Add guardrails for operations to ensure that they
won't panic at runtime.

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-19 11:33:24 -06:00
Anand Krishnamoorthi
8b84d4ce12 Merge pull request #525 from tjons/tjons/feat-implement-net-cidr-expand
feat: implement `net.cidr_expand` builtin
2025-12-17 13:16:52 -06:00
Anand Krishnamoorthi
9fa8036ce4 feat: Implement Rego else block compilation
- teach the Rego compiler to compile else chains correctly
- test suite

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-16 12:03:03 -06:00
Anand Krishnamoorthi
a232b13e50 feat: Else blocks in definitions
- ensure both run-to-completion and suspendable rule execution stop evaluating
  bodies once one succeeds so later else branches are skipped
- test cases

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-16 12:03:03 -06:00
Anand Krishnamoorthi
d0fa639bb8 feat: Reject with keyword usage
RVM does not plan to support the `with` keyword which is mainly used
for testing.

- introduce CompilerError::WithKeywordUnsupported and fail query compilation
  when any literal carries with_mods
- skip OPA test cases that hit the error

The "withkeyword" folder is retained in the TODO list to indicate its
lack of support.

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-16 12:03:02 -06:00
Anand Krishnamoorthi
a514e8da83 fix: Implement RVM set ops correctly
- treat set subtraction in RVM the same as the interpreter by supporting
  Value::Set operands in sub_values
- emit internal-only builtin names for set union/intersection and register
  handlers so compiled bytecode resolves without exposing new Rego builtins
- add regression coverage for literal set difference/intersection
  (x/y from failure.rego) in tests/rvm/rego/cases/sets.yaml

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-16 12:03:02 -06:00
Anand Krishnamoorthi
252ae0e312 Merge pull request #516 from anakrish/rvm-opa-2
Handle more OPA semantics in RVM and compiler
2025-12-16 11:28:36 -06:00
tjons
c41f289b19 feat: implement net.cidr_expand builtin
Signed-off-by: tjons <tylerschade99@gmail.com>
2025-12-16 06:05:32 -05:00
Hans Krutzer
3962b3c38d fix: Integer underflow in lexer error message formatting 2025-12-15 20:00:45 +01:00
Anand Krishnamoorthi
bedf667adc feat: Handle literal comparisons that use = and comprehensions without loops
- emit AssertCondition for equality-only assignment plans (outside soft-assert mode) so rules like `0 = 1` fail under the VM just like the interpreter
- let comprehension bodies consume assertion failures by advancing or exiting their iteration context, both in run-to-completion and suspendable execution

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-03 13:34:14 -06:00
Anand Krishnamoorthi
8269968c4a feat: Handle computed reference roots in RVM compiler
Allow compile_chained_ref to fall back to “evaluate root expression → chain access”
so literal arrays, comprehensions, and other computed roots no longer raise NotSimpleReferenceChain.

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-03 13:34:14 -06:00
Anand Krishnamoorthi
e3d23766ae feat: Ensure RVM caches deterministic builtins
Mirror interpreter implementation:
- use builtins::must_cache to determine whether builtin must be cached.
- reuse cached value when applicable
- clear the VM’s builtin cache whenever execution state resets to avoid leaking values across runs
- add a YAML regression for rand.intn set comprehensions and re-enable the rand cases in the OPA test suite

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2025-12-03 13:34:14 -06:00