Files
regorus/bindings/java
Anand Krishnamoorthi fd59bb5a91 feat(memory): Allocator-backed global memory limits (#544)
Policy evaluation at scale needs to be able to set memory limits
so that a bad policy does not hog memory or to ensure that
policy evaluation itself does not use too much memory which could
cause other components to suffer.

This PR introduces capability to set and enforce global memory limits.
It also lays the groundwork for enabling per evaluation limits in future.

Once a global memory limit is set, Regorus maintains per thread counters
to track memory activity (allocation, deallocation) of a thread.
These counters are periodically flushed to global memory counters.
Per thread counters avoid the contention that updating global counters
on each alloc/free would cause.

Policy evaluation periodically checks these counters and raises errors
if allocated memory has exceeded the configured limit.

Currently memory limit capability is exposed only to FFI and C#.

Also update mimalloc to v2.2.6

Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
2026-01-24 07:08:54 +05:30
..
2025-03-10 11:56:01 -07:00
2024-02-22 15:00:07 -08:00
2024-02-18 08:21:58 -08:00
2025-03-10 11:56:01 -07:00

Regorus Java

Regorus is

  • Rego-Rus(t) - A fast, light-weight Rego interpreter written in Rust.
  • Rigorous - A rigorous enforcer of well-defined Rego semantics.

See main Regorus page for more details about the project.

Building

Due to operational overhead we don't publish Java bindings to Maven Central currently (see https://github.com/microsoft/regorus/issues/237) and you need to build from source to use it.

In order to build Regorus Java for a target platform, you need to install Rust target for that platform first:

$ rustup target add aarch64-apple-darwin

Afterwards, you can build native library for that target using:

$ cargo build --release --target aarch64-apple-darwin

You will then have a native library at target/aarch64-apple-darwin/release/libregorus_java.dylib depending on your target.

You then need to build Java bindings using:

$ mvn package

And you will have a JAR at ./target/regorus-java-0.1.5.jar.

Usage

You can use Regorus Java bindings as:

import com.microsoft.regorus.Engine;

public class Test {
    public static void main(String[] args) {
        try (Engine engine = new Engine()) {
            engine.addPolicy(
                "hello.rego",
                "package test\nmessage = concat(\", \", [input.message, data.message])"
            );
            engine.addDataJson("{\"message\":\"World!\"}");
            engine.setInputJson("{\"message\":\"Hello\"}");
            String resJson = engine.evalQuery("data.test.message");

            System.out.println(resJson);
        }
    }
}

You need to ensure artifacts built in previous section are in Java's classpath.

For example with java CLI:

$ java -Djava.library.path=../../target/aarch64-apple-darwin/release/ -cp target/regorus-java-0.1.5.jar Test.java

should gave you the output:

{"result":[{"expressions":[{"value":"Hello, World!","text":"data.test.message","location":{"row":1,"col":1}}]}]}