cel

package
v0.59.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 17, 2026 License: Apache-2.0 Imports: 21 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// TrigramBinaryMagicBytes defines the 7-byte magic prefix for serialized TrigramIndex binary files.
	TrigramBinaryMagicBytes = "KHITRIX"
	// TrigramBinaryVersion defines the version byte of the TrigramIndex binary format.
	TrigramBinaryVersion = byte(0x03)
)

Variables

View Source
var (
	// ErrInvalidTrigramHeader indicates that the binary stream does not begin with valid magic bytes and version.
	ErrInvalidTrigramHeader = errors.New("invalid trigram index binary header")
)

Functions

func MatchLogField

func MatchLogField(
	l *LogData,
	pathKey string,
	patterns []string,
	pool *khifilev6model.ReadonlyInternPool,
	trigramIndex *TrigramIndex,
) (bool, error)

MatchLogField checks if a log body or field matches the given regular expression pattern(s).

func MatchTimelinePath

func MatchTimelinePath(t *TimelineData, key string, patterns []string, tlMap map[uint32]*TimelineData) bool

MatchTimelinePath checks if any key in timeline's hierarchy path matches the given pattern(s) case-insensitively.

func MatchTimelineRevisionBodyField

func MatchTimelineRevisionBodyField(t *TimelineData, pathKey string, patterns []string, pool *khifilev6model.ReadonlyInternPool) bool

MatchTimelineRevisionBodyField checks if any revision in timeline matches the pathKey and pattern(s).

func ValidateLogQuery

func ValidateLogQuery(query string) error

ValidateLogQuery validates a CEL log expression syntax and types.

func ValidateTimelineQuery

func ValidateTimelineQuery(query string) error

ValidateTimelineQuery validates a CEL timeline expression syntax and types.

func WithLogContext

func WithLogContext(ctx context.Context, l *LogData) context.Context

WithLogContext binds the given LogData to the context for CEL evaluation.

func WithTimelineContext

func WithTimelineContext(ctx context.Context, t *TimelineData) context.Context

WithTimelineContext binds the given TimelineData to the context for CEL evaluation.

Types

type AllQuery

type AllQuery struct{}

AllQuery represents an unconstrained query matching all candidates (Universe).

func (*AllQuery) Simplify

func (q *AllQuery) Simplify() TrigramQuery

Simplify returns the AllQuery unchanged.

func (*AllQuery) String

func (q *AllQuery) String() string

String returns a human-readable representation of AllQuery.

type AndQuery

type AndQuery struct {
	Children []TrigramQuery
}

AndQuery represents a conjunction (AND) of sub-queries.

func (*AndQuery) Simplify

func (q *AndQuery) Simplify() TrigramQuery

Simplify reduces the AndQuery by eliminating neutral elements and flattening nested ANDs.

func (*AndQuery) String

func (q *AndQuery) String() string

String returns a human-readable representation of AndQuery.

type EventInfo

type EventInfo struct {
	LogID    uint32
	Severity uint32
}

EventInfo represents lightweight event metadata associated with a timeline for CEL evaluation.

type LogData

type LogData struct {
	ID              uint32
	LogTypeID       uint32
	SeverityTypeID  uint32
	SummaryStringID uint32
	BodyStructID    uint32
}

LogData encapsulates the indexed log attributes and struct ID required for CEL evaluation. It holds primitive IDs to ensure zero pointers and minimal memory footprint.

func LogFromContext

func LogFromContext(ctx context.Context) *LogData

LogFromContext retrieves the LogData bound to the context.

type LogEvaluator

type LogEvaluator struct {
	// contains filtered or unexported fields
}

LogEvaluator compiles and executes CEL expressions on LogData.

func NewLogEvaluator

func NewLogEvaluator() (*LogEvaluator, error)

NewLogEvaluator creates a new LogEvaluator.

func (*LogEvaluator) Compile

func (e *LogEvaluator) Compile(expr string) error

Compile parses and compiles the CEL expression string. If expr is empty, evaluation always passes.

func (*LogEvaluator) Evaluate

func (e *LogEvaluator) Evaluate(ctx context.Context, l *LogData) (bool, error)

Evaluate evaluates the compiled CEL expression against the provided log.

func (*LogEvaluator) SetInternPool

func (e *LogEvaluator) SetInternPool(pool *khifilev6model.ReadonlyInternPool)

SetInternPool binds the ReadonlyInternPool for on-demand struct/string resolution.

func (*LogEvaluator) SetStyleResolver

func (e *LogEvaluator) SetStyleResolver(resolver StyleResolver)

SetStyleResolver binds the StyleResolver for on-demand log type and severity resolution.

func (*LogEvaluator) SetTrigramIndex

func (e *LogEvaluator) SetTrigramIndex(idx *TrigramIndex)

SetTrigramIndex binds the TrigramIndex for fast substring struct matching.

type LogTrigramItem

type LogTrigramItem struct {
	ID              uint32
	SummaryStringID uint32
	BodyStructID    uint32
}

LogTrigramItem represents a minimal log record for Trigram indexing.

type NoneQuery

type NoneQuery struct{}

NoneQuery represents an impossible query matching no candidates (Empty).

func (*NoneQuery) Simplify

func (q *NoneQuery) Simplify() TrigramQuery

Simplify returns the NoneQuery unchanged.

func (*NoneQuery) String

func (q *NoneQuery) String() string

String returns a human-readable representation of NoneQuery.

type OrQuery

type OrQuery struct {
	Children []TrigramQuery
}

OrQuery represents a disjunction (OR) of sub-queries.

func (*OrQuery) Simplify

func (q *OrQuery) Simplify() TrigramQuery

Simplify reduces the OrQuery by eliminating neutral elements and flattening nested ORs.

func (*OrQuery) String

func (q *OrQuery) String() string

String returns a human-readable representation of OrQuery.

type RevisionInfo

type RevisionInfo struct {
	LogID                uint32
	ChangedTime          int64
	PrincipalStringID    uint32
	Verb                 string
	State                string
	ResourceBodyStructID uint32
	Severity             uint32
}

RevisionInfo represents lightweight revision history metadata associated with a timeline for CEL evaluation.

type SimpleStyleResolver

type SimpleStyleResolver struct {
	LogTypes   map[uint32]string
	Severities map[uint32]uint32
}

SimpleStyleResolver provides a map-based StyleResolver implementation for evaluation and testing.

func (*SimpleStyleResolver) ResolveLogType

func (s *SimpleStyleResolver) ResolveLogType(id uint32) string

ResolveLogType returns the log type label corresponding to the given ID.

func (*SimpleStyleResolver) ResolveSeverity

func (s *SimpleStyleResolver) ResolveSeverity(id uint32) uint32

ResolveSeverity returns the severity order value corresponding to the given ID.

type StyleResolver

type StyleResolver interface {
	ResolveLogType(id uint32) string
	ResolveSeverity(id uint32) uint32
}

StyleResolver resolves style attributes (e.g. log type label, severity order) from their IDs.

type TermQuery

type TermQuery struct {
	Term string
}

TermQuery represents a single 3-gram term constraint.

func (*TermQuery) Simplify

func (q *TermQuery) Simplify() TrigramQuery

Simplify returns the TermQuery unchanged.

func (*TermQuery) String

func (q *TermQuery) String() string

String returns a human-readable representation of TermQuery.

type TimelineData

type TimelineData struct {
	ID           uint32
	ParentID     uint32
	ChildrenIDs  []uint32
	Name         string
	TimelineType string
	Events       []EventInfo
	Revisions    []RevisionInfo
	MaxSeverity  uint32
	SeverityMask uint8
}

TimelineData encapsulates the indexed timeline attributes and nested items required for CEL evaluation.

func TimelineFromContext

func TimelineFromContext(ctx context.Context) *TimelineData

TimelineFromContext retrieves the TimelineData bound to the context.

func (*TimelineData) ComputePath

func (t *TimelineData) ComputePath(tlMap map[uint32]*TimelineData) map[string]string

ComputePath resolves the timeline hierarchy path map on demand by traversing parent timelines.

func (*TimelineData) ForEachLogID

func (t *TimelineData) ForEachLogID(cb func(logID uint32) bool)

ForEachLogID iterates over all log IDs associated with this timeline's events and revisions. If the callback returns false, iteration stops early.

type TimelineEvaluator

type TimelineEvaluator struct {
	// contains filtered or unexported fields
}

TimelineEvaluator compiles and executes CEL expressions on TimelineData.

func NewTimelineEvaluator

func NewTimelineEvaluator() (*TimelineEvaluator, error)

NewTimelineEvaluator creates a new TimelineEvaluator.

func (*TimelineEvaluator) Compile

func (e *TimelineEvaluator) Compile(expr string) error

Compile parses and compiles the CEL expression string. If expr is empty, evaluation always passes.

func (*TimelineEvaluator) Evaluate

func (e *TimelineEvaluator) Evaluate(ctx context.Context, t *TimelineData) (bool, error)

Evaluate evaluates the compiled CEL expression against the provided timeline.

func (*TimelineEvaluator) SetInternPool

func (e *TimelineEvaluator) SetInternPool(pool *khifilev6model.ReadonlyInternPool)

SetInternPool binds the ReadonlyInternPool for on-demand struct resolution.

func (*TimelineEvaluator) SetTimelineMap

func (e *TimelineEvaluator) SetTimelineMap(m map[uint32]*TimelineData)

SetTimelineMap binds the timeline map for hierarchy-based path resolution.

type TrigramIndex

type TrigramIndex struct {
	// contains filtered or unexported fields
}

TrigramIndex provides fast regular expression and substring candidate search over log IDs using Roaring Bitmaps.

func NewTrigramIndex

func NewTrigramIndex() *TrigramIndex

NewTrigramIndex creates an empty TrigramIndex.

func (*TrigramIndex) BuildFromLogPool

func (t *TrigramIndex) BuildFromLogPool(pool *khifilev6model.ReadonlyInternPool, logs []LogTrigramItem, onProgress TrigramProgressCallback) error

BuildFromLogPool indexes trigrams from an InternPool and a slice of LogTrigramItems in streaming parallel chunks.

func (*TrigramIndex) BuildFromStructPool

func (t *TrigramIndex) BuildFromStructPool(pool *khifilev6model.ReadonlyInternPool, structIDs []uint32, onProgress TrigramProgressCallback) error

BuildFromStructPool indexes trigrams from a ReadonlyInternPool and a slice of StructIDs in streaming chunks. It maps each struct ID to itself as a log ID for backward compatibility with struct-level indexing tests.

func (*TrigramIndex) BuildFromStructYAMLs

func (t *TrigramIndex) BuildFromStructYAMLs(ctx context.Context, structYAMLs map[uint32]string, onProgress TrigramProgressCallback) error

BuildFromStructYAMLs indexes trigrams from pre-serialized struct YAML strings concurrently using Roaring Bitmaps.

func (*TrigramIndex) FindCandidateLogs

func (t *TrigramIndex) FindCandidateLogs(pattern string) *roaring.Bitmap

FindCandidateLogs returns a Roaring Bitmap containing candidate LogIDs whose summary or body could match the regex pattern. If the regex is unconstrained by trigrams (e.g. wildcards or <3 char literals), it returns nil, meaning all logs are candidates. If the pattern cannot match any indexed log, it returns an empty Roaring Bitmap.

func (*TrigramIndex) FindCandidateLogsWithField

func (t *TrigramIndex) FindCandidateLogsWithField(pathKey string, pattern string) *roaring.Bitmap

FindCandidateLogsWithField returns a Roaring Bitmap containing candidate LogIDs whose summary or body could match both the field pathKey and the regex pattern. If both the field path and pattern are unconstrained, it returns nil (Universe). If the combination cannot match any indexed log, it returns an empty Roaring Bitmap.

func (*TrigramIndex) ReadFrom

func (t *TrigramIndex) ReadFrom(r io.Reader) (int64, error)

ReadFrom restores the TrigramIndex from an io.Reader containing binary serialized TrigramIndex data.

func (*TrigramIndex) WriteTo

func (t *TrigramIndex) WriteTo(w io.Writer) (int64, error)

WriteTo serializes the TrigramIndex into the given io.Writer in compact binary format.

type TrigramKey

type TrigramKey uint64

TrigramKey represents a 3-rune trigram packed into a single uint64. Each Unicode code point (rune) is at most 21 bits (0x000000 to 0x10FFFF). Bit layout: [ r0 (21 bits) | r1 (21 bits) | r2 (21 bits) ] using 63 of 64 bits.

func MakeTrigramKey

func MakeTrigramKey(r0, r1, r2 rune) TrigramKey

MakeTrigramKey packs three lowercase runes into a TrigramKey.

func TrigramKeyFromString

func TrigramKeyFromString(s string) (TrigramKey, bool)

TrigramKeyFromString converts a 3-rune string into a TrigramKey. If the string does not contain at least 3 runes, it returns 0, false.

func (TrigramKey) String

func (k TrigramKey) String() string

String returns the 3-rune string representation of the TrigramKey.

func (TrigramKey) Unpack

func (k TrigramKey) Unpack() (r0, r1, r2 rune)

Unpack returns the three constituent runes of a TrigramKey.

type TrigramProgressCallback

type TrigramProgressCallback = worker.ProgressCallback

TrigramProgressCallback receives streaming progress updates during Trigram index building.

type TrigramQuery

type TrigramQuery interface {
	String() string
	Simplify() TrigramQuery
}

TrigramQuery represents a node in the Boolean AST of trigram search requirements.

func PathToTrigramQuery

func PathToTrigramQuery(pathKey string) TrigramQuery

PathToTrigramQuery converts a field path key into a TrigramQuery constraining candidates to logs/structs that contain the path's constituent field segments formatted as YAML keys. If pathKey is empty or "*", or if none of the segments have at least 3 runes with colon, it returns &AllQuery{}.

func RegexToTrigramQuery

func RegexToTrigramQuery(s *syntax.Regexp) TrigramQuery

RegexToTrigramQuery translates a parsed syntax.Regexp into a TrigramQuery Boolean AST.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL