Files
regorus/CHANGELOG.md
Mark Birger 9a486c79bf fix: Deep-merge nested data documents in Engine::add_data (#760)
* Deep-merge nested data documents in Engine::add_data

add_data previously performed a shallow merge: adding a nested object under a key that already existed either replaced the whole subtree or errored on a spurious conflict, instead of merging the trees. This makes Engine::add_data (and the shared Value::merge) recurse into nested objects so keys from both sides are preserved, matching OPA's data-document merge semantics. Nested sets are unioned as a regorus extension (OPA data is JSON and has no sets). Genuine leaf conflicts (same path, two different scalar values) still error; equal values remain a no-op, which the shared rule-evaluation path relies on. Adds tests for object deep-merge, set union, leaf/type conflicts, and interaction with the 'with data.x' modifier.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs(value): clarify Value::merge conflict wording

Copilot review on #760 noted the doc comment called non-mergeable variants 'non-container values', which is misleading since arrays are containers yet still conflict unless equal. Reword to describe a conflict as any differing pair that is not both objects or both sets (e.g. unequal scalars or arrays).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* perf(value): avoid deep-cloning RHS set during merge union

When unioning sets in Value::merge, the RHS set is often shared: the object arm recurses via existing.merge(v.clone()), which bumps the incoming set's Rc refcount. The old Rc::make_mut(new) then structurally deep-cloned the entire RHS BTreeSet just to drain it via append and immediately discard the copy.

Move the elements out when the RHS set is uniquely owned, and otherwise clone only the per-element Rc handles into the destination. The union result is identical (BTreeSet dedups), but no throwaway set is allocated on the nested-merge path exercised by add_data deep-merge.

Addresses a Copilot review comment on #760.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* fix(engine): make add_data atomic on merge conflict

Now that Value::merge recurses, a conflict in a later nested key was reported only after earlier keys of the same document had already been written into the live init_data, leaving the engine partially mutated on a rejected add_data.

Add a read-only Value::check_mergeable that mirrors merge's conflict rule (objects deep-merge, sets union, equal values no-op, anything else conflicts) and run it in add_data before merging. On conflict nothing is mutated, so add_data is all-or-nothing. The check allocates nothing and never copies the data spine, preserving merge's in-place uniquely-owned fast path (no candidate copy of the data document).

Adds regression tests for a partial object-leaf conflict and a partial set-union conflict. Reported by a maintainer on #760.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* test(engine): add array atomicity regression for add_data

Arrays are atomic leaves, so a differing array at a shared path is a
conflict. The new key sorts before the conflicting array key, so a naive
in-place merge would leak the new key before hitting the conflict. This
test locks in that add_data rejects the whole call and leaves data
untouched.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* fix: make add_data atomic under allocator memory limits

On llocator-memory-limits builds, Value::merge runs the limit check
*after* inserting each key, so an add_data whose merge trips the limit
mid-way left the data document partially mutated. check_mergeable only
models semantic conflicts, not limit failures, so the validate-then-merge
precheck couldn't cover this failure mode.

Use a build-split strategy in dd_data:
- default builds: keep the zero-copy validate-then-merge fast path
  (a conflict is the only way the merge can fail).
- allocator-memory-limits builds: merge into a candidate copy and commit
  only on success, making both conflict and limit failures transactional.
  Value is Rc/copy-on-write, so only touched subtrees are cloned.

check_mergeable is now cfg-gated to the default build to avoid dead code.

Tests (allocator-memory-limits build): add a partial-merge atomicity test
(limit trips mid-merge, data must be untouched) and a candidate-copy
conflict-atomicity test.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* fix: separate strict rule-output merge from data-document deep-merge

#760 made Value::merge recursive so Engine::add_data deep-merges nested
data documents. But that same method also backs rule materialization,
where recursion is wrong: two rule definitions producing different
outputs for one path must conflict (OPA complete-rule semantics), not
silently combine.

Split the two behaviors:
- Value::merge is strict and shallow again (as pre-#760): a key on both
  sides must be equal or it conflicts; used for rule outputs.
- Value::deep_merge is the recursive data-document merge behind add_data;
  check_mergeable validates it up front without allocating, so the
  default build merges in place instead of cloning a candidate.

Also fix zero-arg functions (f() := ...): route their materialization
through strict equality via a new RuleValueMerge selector, so disjoint
outputs ({a:1} vs {b:2}) conflict as OPA does while prefix scaffolding
(a.foo + a.bar) still combines.

Add a 14-case interpreter conformance matrix (multiple_outputs.yaml)
covering functions, static/dynamic partial objects, and ref-heads,
matched against OPA v1.2.0.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* perf(value): make deep_merge acquire mutable access lazily

deep_merge's object arm called Rc::make_mut on the target map up front,
cloning a shared map's spine even when the merge changed nothing (a
no-op subset re-add) or conflicted before any mutation. Decide each
incoming key from a read-only probe (skip / insert / recurse / conflict)
and take Rc::make_mut only when a key actually mutates, so no-op and
conflict merges leave shared maps untouched.

Behavior is unchanged: the equality short-circuit that previously ran
inside the recursive call now runs in the probe, and conflicts bail with
the same message. Add value tests asserting Rc::ptr_eq is preserved
across no-op subset, equal-nested-object, and first-key-conflict merges.

OPA conformance unchanged (3021 pass / 651 fail, byte-identical).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* feat(value): bound deep_merge recursion depth to prevent stack-overflow DoS

deep_merge and check_mergeable recursed unbounded on object/set nesting.
A Value built without serde_json's parse-time recursion limit (the Python
and Ruby native bindings, or programmatic construction) could therefore
drive add_data into a stack overflow -- an uncatchable abort that poisons
every engine in an FFI process.

Thread a depth counter through both functions and bail past MAX_MERGE_DEPTH
(128, matching serde_json's default) so over-deep data fails with a clean
Err. In the default build check_mergeable trips first, keeping add_data
atomic; the guard in deep_merge covers the allocator-memory-limits build
and any disjoint-then-overlapping merge.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs(changelog): note strict zero-arg function conflict and add_data depth limit

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Mark Birger <markbirger@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-07-21 15:18:00 -05:00

38 KiB

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

Fixed

  • Engine::add_data now deep-merges nested data documents instead of only merging top-level keys. Adding { "a": { "x": 1 } } followed by { "a": { "y": 2 } } now yields { "a": { "x": 1, "y": 2 } } (matching OPA's data-document merge). Nested sets under a shared key are unioned. Only genuine leaf conflicts (the same path holding two different values) are reported as errors.
  • A zero-arg function producing two different complete values (e.g. f() := { "a": 1 } and f() := { "b": 2 }) is now reported as a conflict, matching OPA's complete-rule semantics, instead of silently combining the outputs.

Security

  • Engine::add_data now rejects data nested beyond 128 levels instead of risking a stack overflow on adversarially deep input.

0.10.1 - 2026-05-22

Fixed

  • (ffi) eliminate aliasing UB + add Azure Policy JSON compilation FFI (#727)
  • (interpreter,rvm) correct partial object rule iteration and classification (#718)
  • (copilot) robust diff computation for cloud agent environments (#709)

Other

  • (azure_policy) reduce AliasRegistry allocations via Rc sharing (#725)
  • (normalizer) use Rc interning to reduce alias resolution allocations (#726)
  • (deps) bump the rust-dependencies group across 5 directories with 2 updates (#724)
  • (deps) bump the rust-dependencies group across 5 directories with 4 updates (#717)

[0.10.0] - 2026-05-05

Added

  • (copilot) add multi-agent code review skills (#707)
  • (azure_policy) test runner, compiler fixes, and example program (#700)
  • (azure-policy) implement effect compilation and metadata population (#691)
  • (azure-policy) implement count/count.where compilation (#688)
  • (azure-policy) implement condition, expression, field, and template dispatch compilation (#686)
  • (azure-policy) add compiler skeleton with core types and stubs (#674)
  • (rvm) implement Azure Policy condition evaluation (#661)
  • (rvm) new instructions and loop semantics for Azure Policy support (#659)
  • (azure-policy) add policy rule and policy definition parsers (#660)
  • add Azure Policy constraint parser (#658)
  • (rvm) extend program metadata and bump serialization to v6 (#654)
  • add Azure Policy core JSON parser and expression parser (#655)
  • add Azure Policy AST types (#653)
  • (azure-policy) add alias normalization and denormalization (#635)
  • add Azure Policy builtins with YAML test suite (#630)
  • make policy length limits configurable per engine (#624)
  • implement add_extension in Python binding (#596)
  • (rbac) [breaking] add Azure RBAC engine, FFI API, and cross-language tests (#577)
  • Azure RBAC condition interpreter with builtin evaluation coverage and YAML test suite, including quantifier (ForAnyOfAnyValues/ForAllOfAllValues), datetime (DateTimeEquals), IP (IpInRange), GUID (GuidEquals), list (ListContains), and string (StringEquals) semantics.
  • FFI surface for Azure RBAC condition evaluation (see bindings changelog for language-specific wrappers).

Fixed

  • harden regex builtins with compiled-size limit (#705)
  • (ci) skip mimalloc FFI and disable isolation for Miri (#621)

Other

  • bump version to 0.10.0 across all bindings
  • (deps) update all Rust dependencies and fix lockfile refresh workflow (#704)
  • (deps) bump com.google.code.gson:gson (#702)
  • (deps) bump the github-actions group across 1 directory with 5 updates (#690)
  • (deps) bump the per-dependency group across 1 directory with 5 updates (#703)
  • Make git rev-parse in build.rs optional with graceful fallback (#701)
  • (azure_policy) add foundation test cases (#698)
  • (azure_policy) add end-to-end policy test cases (#699)
  • fix rand advisory and harden python CI caching (#675)
  • azure-policy parser: allow overriding the column-width limit (#673)
  • (deps) bump the rust-dependencies group across 5 directories with 6 updates (#671)
  • (deps) bump ruby/setup-ruby in the github-actions group (#670)
  • (csharp) prepare NuGet package for nuget.org publishing (#668)
  • Fix RVM evaluation of default-only rules (#664)
  • (deps) bump minitest in /bindings/ruby in the per-dependency group (#656)
  • (deps) bump the rust-dependencies group across 2 directories with 3 updates (#657)
  • consolidate RVM instruction variants and clean up VM internals (#651)
  • (deps) bump wasm-bindgen-test (#650)
  • (deps) bump rb_sys in /bindings/ruby in the per-dependency group (#649)
  • (deps) bump the rust-dependencies group across 3 directories with 4 updates (#647)
  • (deps) bump the github-actions group across 1 directory with 3 updates (#646)
  • (dependabot) restore cargo dependency grouping (#645)
  • Fix build break (#634)
  • (deps) bump the rust-dependencies group across 5 directories with 16 updates (#633)
  • (dependabot) fix cargo config quoting (#632)
  • (dependabot) fix cargo workspace updates and refresh lockfiles (#629)
  • (deps) bump rubocop in /bindings/ruby in the per-dependency group (#622)
  • (deps) bump the github-actions group with 11 updates (#628)
  • Consolidate Dependabot, fix #595 (mimalloc + indexmap), add feature-matrix CI (#627)
  • RVM compiler & runtime optimizations: caching, instruction fusion, constant hoisting, and correctness fixes (#626)
  • Rvm optimizations (#620)
  • (deps) bump rubocop in /bindings/ruby in the per-dependency group (#618)
  • (ci) add miri workflow (#581)
  • (ci) add cargo audit and deny (#580)
  • switch binary serialization to postcard (#582)
  • (deps-dev) bump org.apache.maven.plugins:maven-surefire-plugin (#605)
  • (deps) bump bytes (#569)
  • (deps) bump the per-dependency group with 2 updates (#603)
  • (deps) bump the per-dependency group across 1 directory with 3 updates (#607)
  • boolean mapping (#612)
  • Bump the per-dependency group with 1 update (#587)
  • (deps) bump the per-dependency group (#585)
  • (deps) bump the per-dependency group (#586)
  • (deps-dev) bump the per-dependency group (#583)
  • (deps) bump the per-dependency group with 12 updates (#593)
  • (dependabot) expand coverage and pin workflows (#579)

Changed

  • [breaking] Switch RVM binary serialization to postcard, bump the format to v4, and mark v1-3 loads as partial (recompile required).

0.9.1 - 2026-02-06

Fixed

  • Release native C# handles reliably to avoid memory growth (#571).
  • Centralize C# handle gating with a short dispose wait and deferred release to avoid leaks while blocking new calls (#571).

Added

  • Manual C# memory growth tests for both using and finalizer paths (#571).
  • C# test runner options for filtered tests, console logging, and skipping sample apps (#571).

0.5.0 - 2025-07-08

Added

  • [breaking] Indexes for nodes in the AST (#414)
  • Updates for Policy Framework (#405)
  • Regorus nuget package (#383)

Fixed

  • emit import warning to stderr (#430)
  • Clippy warnings (#424)
  • Disallow else blocks for set rules (#403)
  • [breaking] Remove cryptographic builtins (#396)
  • [breaking] Fix glob.match behavior in presence of : (#390)
  • C# EvalRule (#387)

Other

  • Update release-plz action to v0.5.108 (#431)
  • Early return for 'some in' statement (#427)
  • Support manually generating C# bindings via Github action and add a README (#423)
  • Make the bindings/cpp CMake project installable (#416)
  • (deps) bump clap from 4.5.38 to 4.5.39 (#415)
  • (deps) Update criterion and other deps (#412)
  • Basic benchmarking setup with Criterion (#408)
  • Default to Rego v1 in regorus parse (#407)
  • (deps) bump clap from 4.5.37 to 4.5.38 (#406)
  • Update dependencies (#401)
  • Add C# test examples (#397)
  • (deps) bump clap from 4.5.35 to 4.5.36 (#395)
  • Python binding portability (#388)
  • (deps) bump clap from 4.5.34 to 4.5.35 (#389)
  • Use VersionPrefix and VersionSuffix (#385)
  • Check-in Cargo.lock files and lockdown .net (#384)

0.4.0 - 2025-03-14

Fixed

  • [breaking] Update ruby json dependency (#381)
  • [breaking] Remove ring dependency (#380)
  • [breaking] Remove sha1 dependency (#379)

Other

  • Specify optimization flags (#378)

0.3.0 - 2025-03-10

Added

  • [breaking] Update to OPA v1.2.0 (#373)

Other

  • (deps) update pyo3 requirement from 0.23.5 to 0.24.0 (#375)
  • Update ruby binding deps, ruby gem version 0.2.3 (#374)
  • (deps) update pyo3 requirement from 0.22.0 to 0.23.5 (#372)
  • (deps) update rand requirement from 0.8.5 to 0.9.0 (#370)
  • (deps) update cbindgen requirement from 0.27.0 to 0.28.0 (#361)
  • Fix typo in README.md (#366)
  • Update dependencies (#369)
  • Fix clippy warning for result? (#362)
  • (deps) update itertools requirement from 0.13.0 to 0.14.0 (#357)
  • (deps) update jsonschema requirement from 0.26.1 to 0.28.1 (#356)
  • resolve anyhow compile errors (#355)
  • (deps) update prettydiff requirement from 0.7.0 to 0.8.0 (#348)

0.2.8 - 2024-11-06

Other

  • (deps) update jsonschema requirement from 0.24.0 to 0.26.1 (#343)
  • Update to OPA v0.70.0 (#341)

0.2.7 - 2024-10-22

Fixed

  • docs failing to build (#334)

Other

  • (deps) update jsonschema requirement from 0.23.0 to 0.24.0 (#332)
  • (deps) update jsonschema requirement from 0.22.3 to 0.23.0 (#331)

0.2.6 - 2024-10-09

Added

  • integer conversion functions for Value (#328)

Other

  • update to OPA v0.69.0 (#327)
  • (deps) update jsonschema requirement from 0.21.0 to 0.22.3 (#326)
  • (deps) update jsonschema requirement from 0.20.0 to 0.21.0 (#325)
  • update to jsonschema 0.20.0 (#323)

0.2.5 - 2024-09-18

Added

Fixed

  • Null terminate C# strings in Rust boundary (#318)
  • Update readme with correct path to example policy (#312)

Other

  • Update jsonschema requirement from 0.18.0 to 0.19.1 (#317)
  • Update chrono-tz requirement from 0.8.5 to 0.10.0 (#316)
  • Add tests for builtin strings::lower method (#313)
  • Add tests for builtin strings::indexof method (#311)

0.2.4 - 2024-09-04

Added

  • OPA v0.68.0. Engine::set_rego_v1 (#305)

Fixed

  • Handle parsing corner cases (#309)
  • Propagate errors encountered in argument evaluation (#308)
  • Issues #302, #303 (#304)

0.2.3 - 2024-08-16

Fixed

  • Match OPA behavior for split (#295)
  • Merge data to init document (#293)

Other

  • Update cbindgen requirement from 0.26.0 to 0.27.0 (#296)
  • Bump rexml in /bindings/ruby in the bundler group across 1 directory (#294)
  • Update csbindgen requirement from =1.9.0 to =1.9.3 (#292)

0.2.2 - 2024-07-28

Added

  • Update to opa v0.67.0 (#286)

Fixed

  • Handle aliases in scheduler (#285)

Other

  • Update readme (#288)
  • Update binding versions (#287)
  • build.rs create hooks dir if not exists (#283)
  • add extension_list example (#281)
  • Fix build break (#278)
  • Update pyo3 requirement from 0.21.0 to 0.22.0 (#275)
  • Update to OPA v0.66.0 (#274)

0.2.1 - 2024-06-19

Added

  • get_policies: Way to obtain policy files and content (#267)

Other

  • Fix c,cpp,no-std binding examples (#272)
  • Update binding versions for next release (#270)
  • rename method from 'Clone' to 'clone' in 'Engine' class to match the java naming convention and definiont in the of java.lang.Object. (#268)
  • Suppress clippy unused warning (#269)
  • Provide ability to get JSON representation of policy AST (#266)
  • Update OPA tests to v0.65.0 (#264)
  • Allow lexer to be used for other policy languages (#262)

0.2.0 - 2024-05-30

Other

  • Add release-plz config to publish only regorus package (#259)
  • Revert "chore: release v0.2.0 (#257)" (#258)
  • release v0.2.0 (#257)
  • Fix release-plz hash (#256)
  • non collections should evaluate to false (#253)
  • Fix merge issue (#252)
  • Update bindings to include newer APIs (#250)
  • update ruby bindings version to 0.1.5, bump deps (#251)
  • Use correct docsrs feature annotation (#248)
  • Lockdown kata test prints as well as prints of various values (#249)
  • Fix bindings and add CI tests (#247)
  • Add test-ruby CI for github actions (#244)
  • Update README.md for Java bindings to mention we don't publish to (#246)
  • Update itertools requirement from 0.12.1 to 0.13.0 (#245)
  • Update ruby bindings for add_policy and add_policy_from_file to return package name (#240)
  • Provide a way to obtain package names of loaded policies (#239)
  • c_no_std binding to show use in C freestanding environments. (#238)
  • Bump rexml in /bindings/ruby in the bundler group across 1 directory (#236)
  • Update prettydiff requirement from 0.6.4 to 0.7.0 (#234)
  • Update jsonschema requirement from 0.17.1 to 0.18.0 (#235)
  • no_std support (#232)
  • add std feature (#231)
  • Tests from MSFT fork of kata-containers (#230)
  • Use alloc, core instead of std (#225)

0.1.5 - 2024-05-07

Added

  • Support policy files greater than 64KB in size (#217)
  • Add tests for kata containers policies (#221)
  • Support for OPA v0.64.0 (#219)
    • New builtin json.marshal_with_options

Changed

  • Improve example in readme (#224)

Fixed

  • OPA Conformance: Do not interpret # within regular string (#216)

0.1.4 - 2024-04-22

Other

  • early return (#189)
  • Fix anyhow dependency issues (#208)
  • remove unused compact-rc dependency (#207)

0.1.3 - 2024-04-11

Other

  • Add a note in example to prefer eval_rule over eval_query (#204)
  • Do not enable serde_json/arbitrary_precision by default (#203)
  • Rewrite so that code compiles with chrono_tz 0.8.5 and 0.9.0 (#201)
  • update ruby bindings (#200)
  • Store Value instances in AST for strings, numbers and idents (#197)
  • :Value> and From<serde_yaml::Value> (#196)
  • Build dependency on git only if opa.runtime feature is enabled. (#194)
  • Update to opa v0.63.0 (#192)
  • Update pyo3 requirement from 0.20.2 to 0.21.0 (#190)
  • Ruby bindings for existing FFI methods, plus eval_rule() (#188)
  • Evaluate rules directly instead of queries (#186)
  • Remove cruft. (#184)

0.1.2 - 2024-03-22

Other

  • Handle non simple refs in chained expressions (#182)
  • Ability to gather print statements (#179)
  • Top-down evaluation (#177)
  • Make unary - operator OPA compatible. (#175)
  • Don't use deprecated chrono Duration methods (#173)
  • Propagate Undefined in object expressions (#171)
  • Bump to OPA v0.62.0 (#169)
  • Fix regression (#164)
  • Separately keep track of whether rules have been evaluated or not (#163)
  • Link Linux libraries against glibc 2.17 using cargo-zigbuild (#158)

0.1.1 - 2024-02-23

Other

  • Handle else block without body (#155)
  • Ignore errors from builtin functions in non strict mode (#154)
  • Java publishing (#151)
  • Document coverage feature; Convenience query functions (#152)
  • Policy Coverage (#149)
  • Initial implementation of policy coverage (#146)
  • Java bindings (#147)
  • Preserve false in single-expression queries (#145)
  • Create rust-clippy.yml (#143)
  • arc feature to enable using Engine and other data structures from multiple threads (#142)
  • genpolicy tweaks (#141)
  • io.jwt.decode (#140)
  • Use compact_rc (#139)
  • Scripting tweaks (#138)

0.1.0-alpha.3 - 2024-02-01

Fixed

  • fix bitwise.and and add tests (#19)

Other

  • Document bindings (#119)
  • Conform to OPA 0.61.0. (#118)
  • Update publish-python.yml
  • Publish python packages (#117)
  • Publish wasm (#116)
  • Set working-directory for wasm-pack
  • Python bindings (#115)
  • WASM binding (#114)
  • release (#112)
  • Improve crate documentation (#111)
  • Try out manual trigger for release-plz (#110)
    • Document Location, Expression, QueryResult (#109)
  • Update Cargo.toml (#108)
  • Change version to 0.1.0-alpha.1 (#107)
  • Add crate documentation (#106)
  • Release preparation (#105)
  • Update READEME.md with current status, grammar etc. (#102)
  • Implement builtin time.parse_duration_ns method (#100)
  • Implement import keyword (#101)
  • OPA conformance: Pass refheads test suite (#90)
  • OPA conformance: Ensure that withkeyword OPA tests pass (#88)
  • Handle walk builtin as a loop expression (#86)
  • Implement most of the builtin time module (#82)
  • OPA Conformance
  • OPA conformance (#81)
  • More OPA conformance (#77)
  • OPA conformance (#71)
  • Builtin UUID module (#68)
  • Add tests for builtin string::format_int method (#65)
  • More builtins and semantic improvements (#66)
  • More OPA conformance; in-progress: ability to trace interpreter (#63)
  • More OPA conformant semantics (#62)
  • Updated readme. Added bundle support. (#61)
  • crypto builtins (#57)
  • Regex and Glob builtins (#56)
  • Formalize concept of a Number (#55)
  • Lock down ACI tests and more OPA test folders (#54)
  • Fix scheduling regression (#53)
  • add full api to engine (#50)
  • Use Rc instead of string. (#52)
  • More library functions (#51)
  • Added semver.is_valid and semver.compare (#49)
  • OPA conformance tests (#45)
  • Avoid dependency on `source lifetime. (#43)
  • Allow with modifier for builtin and user functions (#42)
  • Special cases of refs to data (#41)
  • Fix scheduling statements that don't create bindings (#40)
  • Ability to run the OPA testsuite (#39)
  • Engine (#38)
  • Use Ref for storing ast nodes in collections. (#37)
  • all, any deprecated functions (#35)
  • all, any deprecated functions (#34)
  • Improvements (#33)
  • Order query expression results (#32)
  • Scheduling of statements in user queries (#31)
  • eval, lex, parse commands (#30)
  • eval_user_query for OPA style results (#29)
  • Arity for builtins (#28)
  • Handle chained _ (#27)
  • Minimize PR 22 (#26)
  • improve errors location (#23)
  • Fix clippy warning (#25)
  • negation of an undefined value should return true (#21)
  • Ensure that scopes are cleaned up correctly upon error. (#20)
  • support of or-functions (#18)
  • Statement Scheduler Implementation
  • Remove unnecessary lifetime
  • json.filter, object.filter, object.get, object.keys, object.remove
  • :to_number builtin
  • :trace builtin
  • bitwise builtins
  • :print builtin
  • Partial sprintf implementation.
  • All string functions except sprintf. TODO: Add tests
  • More string functions without tests
  • More string functions
  • concat and contains
  • string concat (WIP)
  • Support build on non Linux platforms
  • Prepare for upstreaming
  • Test for multi-assign
  • Support dependencies between vars defined in same statement
  • Statement scheduler (WIP)
  • Print small-form table of files without 100% coverage.
  • Code tweaks to improve coverage
  • Tests for aggregates builtins
  • Tests for numbers builtins
  • Tests for arrays builtins
  • Tests for types functions
  • Destructuring of arrays and objects in some-in expressions
  • some .. in implementation
  • Fix key, value in membership and some-in
  • refactor
  • Arrays and Aggregates
  • Implement every statement (#4)
  • Set loop index variable if not "_" (#3)
  • Allow comprehensions in default value. (#2)
  • Lock down numbers
  • mod function
  • Builtin functions for numbers (WIP)
  • Implement comparison operators. Formalize semantics.
  • Rework assign operations (#6)
  • Locked down supported values in default rule.
  • Improvements to github workflow (#4)
  • Update name to regorus
  • Update rust.yml
  • Add simple git action
  • Add missing config.toml
  • Update license to MIT
  • Code from github.com/anakrish/rego-rs
  • SUPPORT.md committed
  • SECURITY.md committed
  • README.md committed
  • LICENSE committed
  • CODE_OF_CONDUCT.md committed
  • Initial commit

0.1.0-alpha.2 - 2024-01-19

Other

  • Improve crate documentation (#111)
  • Try out manual trigger for release-plz (#110)
    • Document Location, Expression, QueryResult (#109)

0.1.0-alpha.1 - 2024-01-15

Fixed

  • fix bitwise.and and add tests (#19)

Other

  • Change version to 0.1.0-alpha.1
  • Add crate documentation (#106)
  • Release preparation (#105)
  • Update READEME.md with current status, grammar etc. (#102)
  • Implement builtin time.parse_duration_ns method (#100)
  • Implement import keyword (#101)
  • OPA conformance: Pass refheads test suite (#90)
  • OPA conformance: Ensure that withkeyword OPA tests pass (#88)
  • Handle walk builtin as a loop expression (#86)
  • Implement most of the builtin time module (#82)
  • OPA Conformance
  • OPA conformance (#81)
  • More OPA conformance (#77)
  • OPA conformance (#71)
  • Builtin UUID module (#68)
  • Add tests for builtin string::format_int method (#65)
  • More builtins and semantic improvements (#66)
  • More OPA conformance; in-progress: ability to trace interpreter (#63)
  • More OPA conformant semantics (#62)
  • Updated readme. Added bundle support. (#61)
  • crypto builtins (#57)
  • Regex and Glob builtins (#56)
  • Formalize concept of a Number (#55)
  • Lock down ACI tests and more OPA test folders (#54)
  • Fix scheduling regression (#53)
  • add full api to engine (#50)
  • Use Rc instead of string. (#52)
  • More library functions (#51)
  • Added semver.is_valid and semver.compare (#49)
  • OPA conformance tests (#45)
  • Avoid dependency on `source lifetime. (#43)
  • Allow with modifier for builtin and user functions (#42)
  • Special cases of refs to data (#41)
  • Fix scheduling statements that don't create bindings (#40)
  • Ability to run the OPA testsuite (#39)
  • Engine (#38)
  • Use Ref for storing ast nodes in collections. (#37)
  • all, any deprecated functions (#35)
  • all, any deprecated functions (#34)
  • Improvements (#33)
  • Order query expression results (#32)
  • Scheduling of statements in user queries (#31)
  • eval, lex, parse commands (#30)
  • eval_user_query for OPA style results (#29)
  • Arity for builtins (#28)
  • Handle chained _ (#27)
  • Minimize PR 22 (#26)
  • improve errors location (#23)
  • Fix clippy warning (#25)
  • negation of an undefined value should return true (#21)
  • Ensure that scopes are cleaned up correctly upon error. (#20)
  • support of or-functions (#18)
  • Statement Scheduler Implementation
  • Remove unnecessary lifetime
  • json.filter, object.filter, object.get, object.keys, object.remove
  • :to_number builtin
  • :trace builtin
  • bitwise builtins
  • :print builtin
  • Partial sprintf implementation.
  • All string functions except sprintf. TODO: Add tests
  • More string functions without tests
  • More string functions
  • concat and contains
  • string concat (WIP)
  • Support build on non Linux platforms
  • Prepare for upstreaming
  • Test for multi-assign
  • Support dependencies between vars defined in same statement
  • Statement scheduler (WIP)
  • Print small-form table of files without 100% coverage.
  • Code tweaks to improve coverage
  • Tests for aggregates builtins
  • Tests for numbers builtins
  • Tests for arrays builtins
  • Tests for types functions
  • Destructuring of arrays and objects in some-in expressions
  • some .. in implementation
  • Fix key, value in membership and some-in
  • refactor
  • Arrays and Aggregates
  • Implement every statement (#4)
  • Set loop index variable if not "_" (#3)
  • Allow comprehensions in default value. (#2)
  • Lock down numbers
  • mod function
  • Builtin functions for numbers (WIP)
  • Implement comparison operators. Formalize semantics.
  • Rework assign operations (#6)
  • Locked down supported values in default rule.
  • Improvements to github workflow (#4)
  • Update name to regorus
  • Update rust.yml
  • Add simple git action
  • Add missing config.toml
  • Update license to MIT
  • Code from github.com/anakrish/rego-rs
  • SUPPORT.md committed
  • SECURITY.md committed
  • README.md committed
  • LICENSE committed
  • CODE_OF_CONDUCT.md committed
  • Initial commit