fix(deps): update module github.com/open-policy-agent/opa to v1.21.1 (9.4) - #8220
elastic-renovate-prod[bot] wants to merge 1 commit into
Conversation
a6e3a28 to
14b5aba
Compare
14b5aba to
cac0aa5
Compare
cac0aa5 to
2bcf1d3
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
2bcf1d3 to
4f3c508
Compare
4f3c508 to
e5c396f
Compare
e5c396f to
cd6943a
Compare
cd6943a to
82f3d7b
Compare
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
71770b7 to
c0ae90a
Compare
c0ae90a to
65bdde8
Compare
65bdde8 to
00df191
Compare
00df191 to
5e4b527
Compare
5e4b527 to
44f19ba
Compare
44f19ba to
37a04b2
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
37a04b2 to
c479b6a
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
c479b6a to
cb2c8db
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
cb2c8db to
8dd3ede
Compare
8dd3ede to
94325ee
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
94325ee to
efc9bd3
Compare
This PR contains the following updates:
v1.19.1→v1.21.1Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
open-policy-agent/opa (github.com/open-policy-agent/opa)
v1.21.1Compare Source
This release fixes a compiler regression introduced in OPA v1.21.0.
Fix
some … in/everyin comprehensions nested in object and set literals (#9280)A comprehension using
some … inoreveryin its body, nested inside an object or set literal, was wrongly treated as ground, so the compiler skipped rewriting it.some … inthen failed withrego_unsafe_var_error;everycaused a compiler panic:Array literals weren't affected, and neither were literals that contain some other non-ground term.
authored by @srenatus, reported by @tun0
v1.21.0Compare Source
This release contains a mix of new features and bug fixes. Notably:
Rules with general refs no longer collide in the recursion check (#6813)
Before, this was a recursion error:
Rules with a variable in their head are all stored at the ground prefix of their ref, so
p[x].foo.barandp[x].foo.bazlooked like dependencies of each other. The compiler isnow less conservative and compares the ref parts past the prefix. Genuine cycles are still
reported.
The IR and Wasm targets however still return an error: they plan one function per ground
path prefix, and cannot evaluate part of a function that is still being planned.
Authored by @sspaink, reported by @tsandall
Data and Query APIs can return rule labels in the response (#9211)
# METADATAlabelsfor evaluated rules were only available in decision logevents. The Data API (
GET/POST /v1/data) and Query API (GET/POST /v1/query) now accept arule_labelsquery parameter to include the samemerged labels in the response payload, under a
rule_labelskey.Authored by @srenatus
Behavior change: response gzip compression now bounds its buffer to
min_length(#9205)The server's gzip response compression (
server.encoding.gzip) buffered an entireincoming
Writecall before deciding whether to compress, so a single large write couldgrow the buffer well past
min_lengthbefore that decision was made. The handler is nowbuilt on
klauspost/compress/gzhttpinstead of a hand-rolled buffer and
gzip.Writerpool, which caps what it buffers tomin_length(floored at 512 bytes) before streaming the remainder through the chosenpath.
min_lengthandcompression_levelbehave the same as before; only gzip isnegotiated, not zstd.
Authored by @srenatus
YAML is now parsed against the 1.2 core schema (#5754, #6598)
OPA parsed YAML with a library pinned to go-yaml v2, which implements YAML 1.1. Under
1.1, the bare words
y,n,yes,no,onandoffresolve to booleans, so aGitHub Actions workflow loaded with
--datacame back withtruewhere it should havehad
on:{ "true": "push" }These words are now plain strings, as the YAML 1.2 core schema specifies.
trueandfalseare unaffected. This applies everywhere OPA reads YAML:--data, bundles,config files, and the
yaml.unmarshalbuiltin.If you were relying on
yes/no/on/offbeing read as booleans, quote the value anduse
true/falseinstead.Authored by @sspaink, reported by @scnewma and @johnc-c
Empty composite literals are now typed as empty (#7275)
The type checker used to give the empty object literal
{}the typeobject[any: any], the empty array literal[]the typearray[any], and theempty set literal
set()the typeset[any], i.e. the types of a collectionthat may hold anything. Every other literal is typed by its contents, so
referencing a key that isn't there is caught at compile time — but only for
non-empty literals:
Empty literals are now typed as what they are: an object with no properties, an
array with no items, and a set with no members. Both examples above now fail to
compile, and so does every other way of selecting from an empty literal,
including iterating one (
some x in []).Comparing an empty object or array literal against a value whose type says it
can't be empty (
{"foo": "bar"} == {}) is now a match error too, the same way{"foo": "bar"} == {"bar": "foo"}already was. Usecount(x) == 0to test acollection for emptiness without asserting its type. Sets are unaffected here:
set[string]describes any set of strings, the empty one included, so{"foo"} == set()still compiles.Authored by @sspaink, reported by @disaverio
Rule indexing improvements
The rule indexer now excludes rules from more kinds of expression, and builds a smaller
trie to do it with. See Use indexed statements
for what is indexed.
startswith,endswith,strings.any_prefix_matchandstrings.any_suffix_matchare indexed when the base strings are known at compile time.
(
data.groups.admins.members[input.subject]) is indexed by asking that object for thekey, where such a ruleset used to leave every rule a candidate.
x := input; x.foo == "a") are indexed thesame as
input.foo == "a", and a chain of assignments no longer drops the constraintat the end of it.
reached by several values no longer leaves the rest of the rule unindexed.
do. A
complete rules must not produce multiple outputserror now points at the firstof the conflicting definitions rather than the second, and partial evaluation names
and orders the generated locals of its support rules differently. What a policy
evaluates to is unaffected.
Changes
Runtime, SDK, Tooling
querystack-trace framing mode (#9128) authored by @johanfyllingrunner.CapturePrintOutputsetting never read (#9104) authored by @anderseknertifbody (#9109) authored by @sspaink, reported by @anderseknertDisableUndefinedOutputsetting (#9185) authored by @anderseknertCompiler, Topdown and Rego
GenericTransformer(#9148) authored by @anderseknertoutputVarsForExprEq(#8302) authored by @zanarellidev, reported by @johanfyllinginoperator against the collection's types (#5658) authored by @sspaink, reported by @anderseknertsemverbuilt-ins (#9004) authored by @sueun-devstrings.replace_n(#9216) authored by @andreaTPDocs, Website, Ecosystem
Miscellaneous
util.MapKeyshelper (#9158) authored by @anderseknerterrors.Ascall sites to useerrors.AsType(#9106) authored by @anderseknertand/orkeywords (#9115) authored by @johanfyllingv1.20.2Compare Source
This release includes a bug fix for a parser regression introduced in v1.20.0, and dependency updates.
Fix stale parse errors on statements starting with
{(#9140)When the
and/orkeywords added in v1.20.0 are imported, a statement that starts with{isfirst read as an explicit operand body, and re-read as a term (a comprehension, for example) if no
andororfollows. Errors recorded during the abandoned first attempt stayed in the parser'sterm cache and were reported against the successful re-read, rejecting policies that parse fine:
The term cache is now restored along with the rest of the parser state when the operand-body guess
is abandoned. Only policies importing
andoror— directly or viaimport future.keywords—were affected; policies that don't import them parse unchanged.
Authored by @sspaink
Miscellaneous
3652eeb) authored by @srenatusv1.20.1Compare Source
This release includes a bug fix for a regression introduced in v1.20.0 in
comparing a number to some float values.
Thanks @kmadan for reporting the issue and submitting a fix!
v1.20.0Compare Source
This release contains a mix of new features and bug fixes. Notably:
andandor, for combining conditions inside a single rule bodyallow_netnow restricts remote JSON Schema$reffetching fromjson.match_schemaandjson.verify_schemaNew Rego keywords:
andandor(#7602)Rego gains two keywords for combining conditions inside a single rule body — a long-standing
request, and one of the larger additions to the language in some time.
andandorlet controlflow that previously had to be split across helper rules stay where it is read.
Before, a rule body that needed to succeed on one of several conditions meant extracting a rule:
Now:
Both keywords are opt-in future keywords:
import future.keywords.and,import future.keywords.or, orimport future.keywordsfor both.An
and/orexpression either succeeds or fails; it never produces a value. So you can't assignone to a variable, pass one to a function, or use one as the head of a comprehension.
Operands can read variables from the rule body around them, but can't create new ones for the rest
of the rule to use — wrap an operand in braces to give it a body of its own, and any variables it
creates stay inside those braces. Only as much is evaluated as needed: if the left side settles the
outcome, the right side is skipped. And when both sides of an
orsucceed, you still get a singleresult; evaluation doesn't split in two.
Further reading:
notTry the new keywords in the Rego Playground, or in your
editor with the VS Code extension
or the IntelliJ IDEA plugin — see
Editor and IDE Support for others.
Authored by @johanfylling
Behavior change:
allow_netapplies to remote JSON Schema$refs (#8979)The
allow_netcapability restricts which hosts remote JSON Schema
$refs may be fetched from, but it was onlywired up on the compile-time type-checking path. Policies using neither
-sschemas nor# METADATA schemas:annotations never reached it, and an unset allowlist permitted every host — so
json.match_schemaand
json.verify_schema,which compile schemas at evaluation time, fetched
$refs from anywhere. Their schema argument cancome from
input, so the host was not necessarily under the policy author's control.The allowlist now travels with the schema loader and is checked per caller at any nesting depth.
Every redirect hop is checked too, matching
http.send, and the inter-query cache key includes theallowlist so a permissive caller cannot populate the cache for a restrictive one.
Authored by @sspaink, reported by @charlesdaniels
Coverage reports explain why a range is not covered (#8937)
Coverage reports showed that a
range was uncovered, but not why: ranges skipped by rule indexing
or early exit looked identical to dead code.
Not-covered ranges are now tagged with a
Kind—index_excludedorearly_exit— determinedby re-evaluating with each optimization disabled and diffing the extra coverage data. Both
supplementary passes run by default when
--coverageis set; the new--coverage-runsflag onopa evalandopa testselects which of them to run, and an empty list disables them.Authored by @charlieegan3
Runtime, SDK, Tooling
server.encodingandserver.decodingvalidation to Rego (#8903) authored by @sspainkand/orlogical expressions (#8683) reported and authored by @johanfyllingand/oroperand bodies (#9053) authored by @sspaink, reported by @anderseknertnotoperand (#9079) authored by @sspaink|infix in parens when output would be re-interpreted as comprehension (#8977) authored by @johanfyllingand/orlogical keywords (#8819) reported and authored by @johanfylling(*Rego).compileModules(#9059) authored by @anderseknertand/orimports (#9066) reported and authored by @johanfyllingCompiler, Topdown and Rego
and()/or()set built-in calls (#9012) authored by @johanfyllingprintcall (#9038) authored by @sspainkwith(#2903) authored by @sspaink, reported by @gshively11future.keywordswildcard import not including thenotkeyword (#9093) authored by @johanfyllingand/orexpressions (#8997) authored by @sspaink, reported by @johanfyllingprintcalls asand/oroperands (#9047) authored by @sspainknot,andandorbodies (#9069) authored by @johanfylling{ ... | ... }notoperands (#8978) authored by @johanfyllingConfiguration
📅 Schedule: Branch creation - Between 01:00 AM and 01:59 AM, Monday through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.