mirror of
https://github.com/microsoft/regorus.git
synced 2026-08-05 02:16:11 +00:00
* fix(ffi): eliminate aliasing UB via to_shared_ref migration Add to_shared_ref() helper that creates &T (shared reference) from raw pointers instead of &mut T. This eliminates undefined behavior caused by violating Rust's aliasing invariant when C# SafeHandle permits concurrent FFI calls on the same handle. With &mut T, the compiler may assume exclusive (noalias) access and reorder or elide reads/writes — a miscompilation risk when another thread holds a reference to the same object. Switching to &T removes that assumption; actual mutation is mediated by the interior RwLock inside Handle<T>, which is the sole synchronization mechanism. Migrated sites: - rvm.rs: 20 non-drop call sites - engine.rs: 30 non-drop call sites + with_unwind_guard for timer fns - compiled_policy.rs: 2 call sites - Fix null-data UB in regorus_program_deserialize_binary Drop paths retain to_ref() where exclusive access is guaranteed by the caller contract (preventing use-after-free). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * feat(ffi): add Azure Policy JSON compilation FFI and C# bindings - AliasRegistry builder pattern: RegorusAliasRegistryBuilder (mutable, single-threaded) + RegorusAliasRegistry (immutable, Arc-wrapped) - Azure Policy JSON compilation: regorus_compile_azure_policy_rule and regorus_compile_azure_policy_definition with alias registry support - regorus_rvm_set_context for host-supplied ambient data - C# AliasRegistryBuilder and AliasRegistry classes with convenience factories (FromJson, FromManifest, Empty) - C# AzurePolicyCompiler static class for policy rule/definition compilation - Compile functions take *const RegorusAliasRegistry (read-only via to_shared_ref for concurrent compilation safety) - Fix pre-existing clippy warnings across multiple crates Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
54 lines
1.1 KiB
TOML
54 lines
1.1 KiB
TOML
[workspace]
|
|
|
|
[package]
|
|
name = "regorus-ffi"
|
|
version = "0.10.1"
|
|
edition = "2021"
|
|
license = "MIT AND Apache-2.0 AND BSD-3-Clause"
|
|
|
|
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
|
|
[lib]
|
|
crate-type = ["cdylib", "staticlib"]
|
|
|
|
[dependencies]
|
|
anyhow = "1.0"
|
|
regorus = { path = "../..", default-features = false }
|
|
serde_json = "1.0.140"
|
|
parking_lot = { version = "0.12", optional = true }
|
|
|
|
[profile.release]
|
|
# Enable full debug info for optimized builds.
|
|
debug = "full"
|
|
# Split debuginfo into its own file to reduce binary size.
|
|
split-debuginfo = "packed"
|
|
lto = true
|
|
codegen-units = 1
|
|
|
|
[features]
|
|
default = [
|
|
"ast",
|
|
"azure_policy",
|
|
"std",
|
|
"coverage",
|
|
"allocator-memory-limits",
|
|
"rvm",
|
|
"rbac",
|
|
"regorus/arc",
|
|
"regorus/full-opa",
|
|
"cache",
|
|
"contention_checks",
|
|
]
|
|
ast = ["regorus/ast"]
|
|
azure_policy = ["regorus/azure_policy"]
|
|
std = ["regorus/std"]
|
|
coverage = ["regorus/coverage"]
|
|
allocator-memory-limits = ["regorus/allocator-memory-limits"]
|
|
contention_checks = ["parking_lot"]
|
|
rvm = ["regorus/rvm"]
|
|
rbac = ["regorus/azure-rbac"]
|
|
cache = ["regorus/cache"]
|
|
custom_allocator = []
|
|
|
|
[build-dependencies]
|
|
cbindgen = "0.29.2"
|