mirror of
https://github.com/microsoft/regorus.git
synced 2026-08-05 02:16:11 +00:00
* feat: add Azure Policy builtins with YAML test suite Implement ARM template functions for Azure Policy evaluation: Builtins: - String: indexOf, lastIndexOf, trim, format, split, startsWith, endsWith, padLeft, concat, replace, toLower, toUpper, substring, guid, uniqueString - DateTime: dateTimeAdd, dateTimeFromEpoch, dateTimeToEpoch, addDays - Collection: intersection, union, take, skip, first, last, min, max, range, items, tryGet, tryIndexFromEnd, empty, array, createObject - Encoding: base64, base64ToString, base64ToJson, uri, uriComponent, uriComponentToString, dataUri, dataUriToString - Numeric: int, float, intDiv, intMod - Misc: json, join, bool, string, coalesce, if, getParameter, resolveField - Logic: logicAll, logicAny Key implementation details: - Unicode case-insensitive search via ICU4X case folding with single-pass fold_with_char_map() for indexOf/lastIndexOf - .NET composite formatting (System.String.Format) with alignment, standard and custom datetime format specifiers, numeric format specifiers - DateTime round-trip preserves input shape (Z vs +00:00, T vs space, fractional seconds) when no explicit output format is supplied - Zero-cost as_str() helper borrows directly from Value::String(Rc<str>) - BTreeSet<&Value> in array union avoids redundant cloning Test suite: - 53 YAML test files exercising all builtins via direct BUILTINS registry - Coverage for edge cases: empty inputs, Unicode, fractional seconds, invalid alignment, unknown format specifiers, RFC3339 offset shapes Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com> * fix: address PR review comments - Fix percent_encode to only uppercase hex digits, not entire string - Remove guid/uniqueString (unsupported); delete custom SHA-1 impl - Replace unwrap_or(0) with proper error in format placeholder parsing - Hoist CaseMapper into static CaseMapperBorrowed for zero per-call overhead - Pre-allocate Vec in range() with_capacity - Update bindings/ffi and bindings/ruby Cargo.lock - Fix uri_component test expectations for correct case preservation Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com> * fix: address second round of PR review comments - float(): return Undefined when as_f64() fails instead of leaking the original non-f64 representation - createObject(): reject odd number of arguments with an error (ARM-template parity) - format(): error on unknown numeric format specifiers instead of silently passing through (matches .NET FormatException behavior) - format(): cap alignment width at 10,000 to prevent DoS from user-controlled format strings like {0,1000000000} - Add YAML test cases for all new error behaviors Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com> * fix: address third round of PR review comments - percent_decode: reject incomplete % escapes (e.g. "%", "%2") instead of treating them as literal characters - parse_iso8601_duration: reject leftover digits without a unit designator at T boundary and end-of-input (e.g. "P1", "P1T2H") - yaml_to_value: panic on unsupported YAML numeric representations instead of silently mapping to Null - Revert unused src/languages/mod.rs changes (module is defined inline in lib.rs) Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com> * fix: add missing edge-case tests and fix empty-delimiter panic - fn_split: return input as single-element array for empty string delimiter instead of panicking (Rust's str::split("") panics) - format: add test for F3 higher precision ({0:F3} + 1.23456 → 1.235) - format: add test for N2 float with thousands separator - format: add test for negative index error ({-1}) - split: add test for empty-string delimiter - uri: add tests for query string and fragment in relative URI - createObject: add test for non-string (numeric) keys Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com> * fix: address fourth round of PR review comments - Add MAX_VARIADIC_ARGS (64) constant for variadic builtin arity instead of registering with 0 (logic_all, logic_any, min, max, format, intersection, union, coalesce, createObject); set dateTimeAdd to exact arity 3 - Switch indexOf/lastIndexOf to UTF-16 code-unit indices to match .NET String.IndexOf semantics (track ch.len_utf16() in fold_with_char_map, use encode_utf16().count() for empty-needle lastIndexOf) - Use DateTime::<Utc>::from_timestamp for explicit timezone type - Remove stale docs/azure-policy/casing.md link from module doc - Fix misleading comment in want_error test branch (code bails on Undefined, not accepts it) Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com> --------- Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
211 lines
5.7 KiB
TOML
211 lines
5.7 KiB
TOML
[workspace]
|
|
|
|
members = [
|
|
"tests/ensure_no_std",
|
|
"xtask",
|
|
]
|
|
|
|
[package]
|
|
name = "regorus"
|
|
description = "A fast, lightweight Rego (OPA policy language) interpreter"
|
|
version = "0.9.1"
|
|
edition = "2021"
|
|
license = "MIT AND Apache-2.0 AND BSD-3-Clause"
|
|
repository = "https://github.com/microsoft/regorus"
|
|
keywords = ["interpreter", "no_std", "opa", "policy-as-code", "rego"]
|
|
|
|
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
|
|
|
|
[lib]
|
|
doctest = false
|
|
|
|
[features]
|
|
default = ["full-opa", "arc", "rvm"]
|
|
|
|
arc = []
|
|
ast = []
|
|
azure_policy = ["dep:jsonschema", "dep:chrono", "dep:ipnet", "dep:icu_casemap", "arc", "dashmap"]
|
|
azure-rbac = ["regex", "time", "net"]
|
|
base64 = ["dep:data-encoding"]
|
|
base64url = ["dep:data-encoding"]
|
|
coverage = []
|
|
hex = ["dep:data-encoding"]
|
|
http = []
|
|
glob = ["dep:globset"]
|
|
graph = []
|
|
jsonschema = ["dep:jsonschema"]
|
|
mimalloc = ["dep:mimalloc"]
|
|
net = ["dep:ipnet"]
|
|
no_std = ["lazy_static/spin_no_std"]
|
|
opa-runtime = []
|
|
regex = ["dep:regex"]
|
|
cache = ["dep:lru"]
|
|
rvm = ["dep:postcard", "dep:indexmap"]
|
|
semver = ["dep:semver"]
|
|
allocator-memory-limits = ["std", "mimalloc", "mimalloc/allocator-memory-limits"]
|
|
std = ["rand/std", "rand/std_rng", "serde_json/std", "indexmap?/std", "msvc_spectre_libs", "dep:parking_lot" ]
|
|
time = ["dep:chrono", "dep:chrono-tz"]
|
|
uuid = ["dep:uuid"]
|
|
urlquery = ["dep:url"]
|
|
yaml = ["serde_yaml"]
|
|
full-opa = [
|
|
"base64",
|
|
"base64url",
|
|
"coverage",
|
|
"glob",
|
|
"graph",
|
|
"hex",
|
|
"http",
|
|
"jsonschema",
|
|
"net",
|
|
"opa-runtime",
|
|
"regex",
|
|
"cache",
|
|
"semver",
|
|
"std",
|
|
"time",
|
|
"uuid",
|
|
"urlquery",
|
|
"yaml",
|
|
|
|
#"rego-extensions"
|
|
]
|
|
|
|
# Features that can be used in no_std environments.
|
|
# Note that: the spin_no_std feature in lazy_static must be specified.
|
|
opa-no-std = [
|
|
"arc",
|
|
"base64",
|
|
"base64url",
|
|
"coverage",
|
|
"graph",
|
|
"hex",
|
|
"no_std",
|
|
"opa-runtime",
|
|
"regex",
|
|
"semver",
|
|
# Configure lazy_static to use spinlocks.
|
|
"lazy_static/spin_no_std"
|
|
]
|
|
|
|
# Rego language extensions
|
|
rego-extensions = []
|
|
|
|
# This feature enables some testing utils for OPA tests.
|
|
opa-testutil = []
|
|
rand = ["dep:rand"]
|
|
|
|
[dependencies]
|
|
anyhow = { version = "1.0.45", default-features = false }
|
|
serde = {version = "1.0.150", default-features = false, features = ["derive", "rc", "alloc"] }
|
|
serde_json = { version = "1.0.89", default-features = false, features = ["alloc"] }
|
|
lazy_static = { version = "1.4.0", default-features = false }
|
|
thiserror = { version = "2.0", default-features = false }
|
|
|
|
data-encoding = { version = "2.8.0", optional = true, default-features=false, features = ["alloc"] }
|
|
num-bigint = { version = "0.4", default-features = false }
|
|
num-traits = { version = "0.2", default-features = false }
|
|
parking_lot = { version = "0.12", optional = true }
|
|
spin = { version = "0.9.8", default-features = false, features = ["mutex", "spin_mutex"] }
|
|
|
|
globset = { version = "0.4.16", features = ["simd-accel"], default-features = false, optional = true }
|
|
regex = {version = "1.11.1", optional = true, default-features = false }
|
|
semver = {version = "1.0.25", optional = true, default-features = false }
|
|
url = { version = "2.5.4", optional = true }
|
|
uuid = { version = "1.15.1", default-features = false, features = ["v4", "fast-rng"], optional = true }
|
|
jsonschema = { version = "0.30.0", default-features = false, optional = true }
|
|
chrono = { version = "0.4.40", optional = true }
|
|
chrono-tz = { version = "0.10.1", optional = true }
|
|
ipnet = { version = "2.11.0", optional = true, default-features = false }
|
|
icu_casemap = { version = "2.1", optional = true, default-features = false, features = ["compiled_data"] }
|
|
|
|
serde_yaml = {version = "0.9.16", default-features = false, optional = true }
|
|
# Specify thread_rng for in order to use random_range
|
|
rand = { version = "0.9.0", default-features = false, features = ["thread_rng"], optional = true }
|
|
|
|
# Causes the project to link with the Spectre-mitigated CRT and libs.
|
|
msvc_spectre_libs = { version = "0.1", features = ["error"], optional = true }
|
|
dashmap = { version = "6.1", default-features = false, optional = true }
|
|
lru = { version = "0.16", default-features = false, optional = true }
|
|
mimalloc = { package = "regorus-mimalloc", path = "mimalloc", version = "2.2.6", optional = true }
|
|
|
|
# rvm related deps
|
|
indexmap = { version = "2.12.1", default-features = false, features = ["serde"], optional = true }
|
|
postcard = { version = "1.1.3", default-features = false, features = ["alloc"], optional = true }
|
|
|
|
[dev-dependencies]
|
|
anyhow = "1.0.45"
|
|
cfg-if = "1.0.0"
|
|
clap = { version = "4.5.53", features = ["derive"] }
|
|
prettydiff = { version = "0.9.0", default-features = false }
|
|
serde_yaml = "0.9.16"
|
|
test-generator = "0.3.1"
|
|
walkdir = "2.3.2"
|
|
criterion = { version = "0.8" }
|
|
|
|
num_cpus = "1.16"
|
|
|
|
[build-dependencies]
|
|
anyhow = "1.0"
|
|
|
|
[profile.release]
|
|
debug = true
|
|
lto = true
|
|
codegen-units = 1
|
|
|
|
[[test]]
|
|
name="opa"
|
|
harness=false
|
|
test=false
|
|
required-features = ["full-opa"]
|
|
|
|
[[test]]
|
|
name="aci"
|
|
harness=false
|
|
test=false
|
|
|
|
[[test]]
|
|
name="kata"
|
|
harness=false
|
|
test=false
|
|
|
|
[[bench]]
|
|
name = "regorus_benchmark"
|
|
harness = false
|
|
|
|
[[bench]]
|
|
name = "schema_validation_benchmark"
|
|
harness = false
|
|
required-features = ["azure_policy"]
|
|
|
|
[[bench]]
|
|
name = "engine_evaluation_benchmark"
|
|
path = "benches/evaluation/engine_evaluation_benchmark.rs"
|
|
harness = false
|
|
|
|
[[bench]]
|
|
name = "compiled_policy_evaluation_benchmark"
|
|
path = "benches/evaluation/compiled_policy_evaluation_benchmark.rs"
|
|
harness = false
|
|
|
|
[[bench]]
|
|
name = "aci_benchmark"
|
|
harness = false
|
|
|
|
[[bench]]
|
|
name = "rvm_benchmark"
|
|
harness = false
|
|
required-features = ["rvm"]
|
|
|
|
[[example]]
|
|
name="regorus"
|
|
harness=false
|
|
test=false
|
|
doctest=false
|
|
|
|
[package.metadata.docs.rs]
|
|
# To build locally:
|
|
# RUSTDOCFLAGS="--cfg docsrs" cargo +nightly doc --all-features --no-deps
|
|
all-features = true
|
|
rustdoc-args = ["--cfg", "docsrs"]
|