Documentation
¶
Index ¶
- Constants
- Variables
- func MatchLogField(l *LogData, pathKey string, patterns []string, ...) (bool, error)
- func MatchTimelinePath(t *TimelineData, key string, patterns []string, tlMap map[uint32]*TimelineData) bool
- func MatchTimelineRevisionBodyField(t *TimelineData, pathKey string, patterns []string, ...) bool
- func ValidateLogQuery(query string) error
- func ValidateTimelineQuery(query string) error
- func WithLogContext(ctx context.Context, l *LogData) context.Context
- func WithTimelineContext(ctx context.Context, t *TimelineData) context.Context
- type AllQuery
- type AndQuery
- type EventInfo
- type LogData
- type LogEvaluator
- func (e *LogEvaluator) Compile(expr string) error
- func (e *LogEvaluator) Evaluate(ctx context.Context, l *LogData) (bool, error)
- func (e *LogEvaluator) SetInternPool(pool *khifilev6model.ReadonlyInternPool)
- func (e *LogEvaluator) SetStyleResolver(resolver StyleResolver)
- func (e *LogEvaluator) SetTrigramIndex(idx *TrigramIndex)
- type LogTrigramItem
- type NoneQuery
- type OrQuery
- type RevisionInfo
- type SimpleStyleResolver
- type StyleResolver
- type TermQuery
- type TimelineData
- type TimelineEvaluator
- type TrigramIndex
- func (t *TrigramIndex) BuildFromLogPool(pool *khifilev6model.ReadonlyInternPool, logs []LogTrigramItem, ...) error
- func (t *TrigramIndex) BuildFromStructPool(pool *khifilev6model.ReadonlyInternPool, structIDs []uint32, ...) error
- func (t *TrigramIndex) BuildFromStructYAMLs(ctx context.Context, structYAMLs map[uint32]string, ...) error
- func (t *TrigramIndex) FindCandidateLogs(pattern string) *roaring.Bitmap
- func (t *TrigramIndex) FindCandidateLogsWithField(pathKey string, pattern string) *roaring.Bitmap
- func (t *TrigramIndex) ReadFrom(r io.Reader) (int64, error)
- func (t *TrigramIndex) WriteTo(w io.Writer) (int64, error)
- type TrigramKey
- type TrigramProgressCallback
- type TrigramQuery
Constants ¶
const ( // TrigramBinaryMagicBytes defines the 7-byte magic prefix for serialized TrigramIndex binary files. TrigramBinaryMagicBytes = "KHITRIX" // TrigramBinaryVersion defines the version byte of the TrigramIndex binary format. TrigramBinaryVersion = byte(0x03) )
Variables ¶
var ( // ErrInvalidTrigramHeader indicates that the binary stream does not begin with valid magic bytes and version. ErrInvalidTrigramHeader = errors.New("invalid trigram index binary header") )
Functions ¶
func MatchLogField ¶
func MatchLogField( l *LogData, pathKey string, patterns []string, pool *khifilev6model.ReadonlyInternPool, trigramIndex *TrigramIndex, ) (bool, error)
MatchLogField checks if a log body or field matches the given regular expression pattern(s).
func MatchTimelinePath ¶
func MatchTimelinePath(t *TimelineData, key string, patterns []string, tlMap map[uint32]*TimelineData) bool
MatchTimelinePath checks if any key in timeline's hierarchy path matches the given pattern(s) case-insensitively.
func MatchTimelineRevisionBodyField ¶
func MatchTimelineRevisionBodyField(t *TimelineData, pathKey string, patterns []string, pool *khifilev6model.ReadonlyInternPool) bool
MatchTimelineRevisionBodyField checks if any revision in timeline matches the pathKey and pattern(s).
func ValidateLogQuery ¶
ValidateLogQuery validates a CEL log expression syntax and types.
func ValidateTimelineQuery ¶
ValidateTimelineQuery validates a CEL timeline expression syntax and types.
func WithLogContext ¶
WithLogContext binds the given LogData to the context for CEL evaluation.
func WithTimelineContext ¶
func WithTimelineContext(ctx context.Context, t *TimelineData) context.Context
WithTimelineContext binds the given TimelineData to the context for CEL evaluation.
Types ¶
type AllQuery ¶
type AllQuery struct{}
AllQuery represents an unconstrained query matching all candidates (Universe).
func (*AllQuery) Simplify ¶
func (q *AllQuery) Simplify() TrigramQuery
Simplify returns the AllQuery unchanged.
type AndQuery ¶
type AndQuery struct {
Children []TrigramQuery
}
AndQuery represents a conjunction (AND) of sub-queries.
func (*AndQuery) Simplify ¶
func (q *AndQuery) Simplify() TrigramQuery
Simplify reduces the AndQuery by eliminating neutral elements and flattening nested ANDs.
type EventInfo ¶
EventInfo represents lightweight event metadata associated with a timeline for CEL evaluation.
type LogData ¶
type LogData struct {
ID uint32
LogTypeID uint32
SeverityTypeID uint32
SummaryStringID uint32
BodyStructID uint32
}
LogData encapsulates the indexed log attributes and struct ID required for CEL evaluation. It holds primitive IDs to ensure zero pointers and minimal memory footprint.
func LogFromContext ¶
LogFromContext retrieves the LogData bound to the context.
type LogEvaluator ¶
type LogEvaluator struct {
// contains filtered or unexported fields
}
LogEvaluator compiles and executes CEL expressions on LogData.
func NewLogEvaluator ¶
func NewLogEvaluator() (*LogEvaluator, error)
NewLogEvaluator creates a new LogEvaluator.
func (*LogEvaluator) Compile ¶
func (e *LogEvaluator) Compile(expr string) error
Compile parses and compiles the CEL expression string. If expr is empty, evaluation always passes.
func (*LogEvaluator) Evaluate ¶
Evaluate evaluates the compiled CEL expression against the provided log.
func (*LogEvaluator) SetInternPool ¶
func (e *LogEvaluator) SetInternPool(pool *khifilev6model.ReadonlyInternPool)
SetInternPool binds the ReadonlyInternPool for on-demand struct/string resolution.
func (*LogEvaluator) SetStyleResolver ¶
func (e *LogEvaluator) SetStyleResolver(resolver StyleResolver)
SetStyleResolver binds the StyleResolver for on-demand log type and severity resolution.
func (*LogEvaluator) SetTrigramIndex ¶
func (e *LogEvaluator) SetTrigramIndex(idx *TrigramIndex)
SetTrigramIndex binds the TrigramIndex for fast substring struct matching.
type LogTrigramItem ¶
LogTrigramItem represents a minimal log record for Trigram indexing.
type NoneQuery ¶
type NoneQuery struct{}
NoneQuery represents an impossible query matching no candidates (Empty).
func (*NoneQuery) Simplify ¶
func (q *NoneQuery) Simplify() TrigramQuery
Simplify returns the NoneQuery unchanged.
type OrQuery ¶
type OrQuery struct {
Children []TrigramQuery
}
OrQuery represents a disjunction (OR) of sub-queries.
func (*OrQuery) Simplify ¶
func (q *OrQuery) Simplify() TrigramQuery
Simplify reduces the OrQuery by eliminating neutral elements and flattening nested ORs.
type RevisionInfo ¶
type RevisionInfo struct {
LogID uint32
ChangedTime int64
PrincipalStringID uint32
Verb string
State string
ResourceBodyStructID uint32
Severity uint32
}
RevisionInfo represents lightweight revision history metadata associated with a timeline for CEL evaluation.
type SimpleStyleResolver ¶
SimpleStyleResolver provides a map-based StyleResolver implementation for evaluation and testing.
func (*SimpleStyleResolver) ResolveLogType ¶
func (s *SimpleStyleResolver) ResolveLogType(id uint32) string
ResolveLogType returns the log type label corresponding to the given ID.
func (*SimpleStyleResolver) ResolveSeverity ¶
func (s *SimpleStyleResolver) ResolveSeverity(id uint32) uint32
ResolveSeverity returns the severity order value corresponding to the given ID.
type StyleResolver ¶
StyleResolver resolves style attributes (e.g. log type label, severity order) from their IDs.
type TermQuery ¶
type TermQuery struct {
Term string
}
TermQuery represents a single 3-gram term constraint.
func (*TermQuery) Simplify ¶
func (q *TermQuery) Simplify() TrigramQuery
Simplify returns the TermQuery unchanged.
type TimelineData ¶
type TimelineData struct {
ID uint32
ParentID uint32
ChildrenIDs []uint32
Name string
TimelineType string
Events []EventInfo
Revisions []RevisionInfo
MaxSeverity uint32
SeverityMask uint8
}
TimelineData encapsulates the indexed timeline attributes and nested items required for CEL evaluation.
func TimelineFromContext ¶
func TimelineFromContext(ctx context.Context) *TimelineData
TimelineFromContext retrieves the TimelineData bound to the context.
func (*TimelineData) ComputePath ¶
func (t *TimelineData) ComputePath(tlMap map[uint32]*TimelineData) map[string]string
ComputePath resolves the timeline hierarchy path map on demand by traversing parent timelines.
func (*TimelineData) ForEachLogID ¶
func (t *TimelineData) ForEachLogID(cb func(logID uint32) bool)
ForEachLogID iterates over all log IDs associated with this timeline's events and revisions. If the callback returns false, iteration stops early.
type TimelineEvaluator ¶
type TimelineEvaluator struct {
// contains filtered or unexported fields
}
TimelineEvaluator compiles and executes CEL expressions on TimelineData.
func NewTimelineEvaluator ¶
func NewTimelineEvaluator() (*TimelineEvaluator, error)
NewTimelineEvaluator creates a new TimelineEvaluator.
func (*TimelineEvaluator) Compile ¶
func (e *TimelineEvaluator) Compile(expr string) error
Compile parses and compiles the CEL expression string. If expr is empty, evaluation always passes.
func (*TimelineEvaluator) Evaluate ¶
func (e *TimelineEvaluator) Evaluate(ctx context.Context, t *TimelineData) (bool, error)
Evaluate evaluates the compiled CEL expression against the provided timeline.
func (*TimelineEvaluator) SetInternPool ¶
func (e *TimelineEvaluator) SetInternPool(pool *khifilev6model.ReadonlyInternPool)
SetInternPool binds the ReadonlyInternPool for on-demand struct resolution.
func (*TimelineEvaluator) SetTimelineMap ¶
func (e *TimelineEvaluator) SetTimelineMap(m map[uint32]*TimelineData)
SetTimelineMap binds the timeline map for hierarchy-based path resolution.
type TrigramIndex ¶
type TrigramIndex struct {
// contains filtered or unexported fields
}
TrigramIndex provides fast regular expression and substring candidate search over log IDs using Roaring Bitmaps.
func NewTrigramIndex ¶
func NewTrigramIndex() *TrigramIndex
NewTrigramIndex creates an empty TrigramIndex.
func (*TrigramIndex) BuildFromLogPool ¶
func (t *TrigramIndex) BuildFromLogPool(pool *khifilev6model.ReadonlyInternPool, logs []LogTrigramItem, onProgress TrigramProgressCallback) error
BuildFromLogPool indexes trigrams from an InternPool and a slice of LogTrigramItems in streaming parallel chunks.
func (*TrigramIndex) BuildFromStructPool ¶
func (t *TrigramIndex) BuildFromStructPool(pool *khifilev6model.ReadonlyInternPool, structIDs []uint32, onProgress TrigramProgressCallback) error
BuildFromStructPool indexes trigrams from a ReadonlyInternPool and a slice of StructIDs in streaming chunks. It maps each struct ID to itself as a log ID for backward compatibility with struct-level indexing tests.
func (*TrigramIndex) BuildFromStructYAMLs ¶
func (t *TrigramIndex) BuildFromStructYAMLs(ctx context.Context, structYAMLs map[uint32]string, onProgress TrigramProgressCallback) error
BuildFromStructYAMLs indexes trigrams from pre-serialized struct YAML strings concurrently using Roaring Bitmaps.
func (*TrigramIndex) FindCandidateLogs ¶
func (t *TrigramIndex) FindCandidateLogs(pattern string) *roaring.Bitmap
FindCandidateLogs returns a Roaring Bitmap containing candidate LogIDs whose summary or body could match the regex pattern. If the regex is unconstrained by trigrams (e.g. wildcards or <3 char literals), it returns nil, meaning all logs are candidates. If the pattern cannot match any indexed log, it returns an empty Roaring Bitmap.
func (*TrigramIndex) FindCandidateLogsWithField ¶
func (t *TrigramIndex) FindCandidateLogsWithField(pathKey string, pattern string) *roaring.Bitmap
FindCandidateLogsWithField returns a Roaring Bitmap containing candidate LogIDs whose summary or body could match both the field pathKey and the regex pattern. If both the field path and pattern are unconstrained, it returns nil (Universe). If the combination cannot match any indexed log, it returns an empty Roaring Bitmap.
type TrigramKey ¶
type TrigramKey uint64
TrigramKey represents a 3-rune trigram packed into a single uint64. Each Unicode code point (rune) is at most 21 bits (0x000000 to 0x10FFFF). Bit layout: [ r0 (21 bits) | r1 (21 bits) | r2 (21 bits) ] using 63 of 64 bits.
func MakeTrigramKey ¶
func MakeTrigramKey(r0, r1, r2 rune) TrigramKey
MakeTrigramKey packs three lowercase runes into a TrigramKey.
func TrigramKeyFromString ¶
func TrigramKeyFromString(s string) (TrigramKey, bool)
TrigramKeyFromString converts a 3-rune string into a TrigramKey. If the string does not contain at least 3 runes, it returns 0, false.
func (TrigramKey) String ¶
func (k TrigramKey) String() string
String returns the 3-rune string representation of the TrigramKey.
func (TrigramKey) Unpack ¶
func (k TrigramKey) Unpack() (r0, r1, r2 rune)
Unpack returns the three constituent runes of a TrigramKey.
type TrigramProgressCallback ¶
type TrigramProgressCallback = worker.ProgressCallback
TrigramProgressCallback receives streaming progress updates during Trigram index building.
type TrigramQuery ¶
type TrigramQuery interface {
String() string
Simplify() TrigramQuery
}
TrigramQuery represents a node in the Boolean AST of trigram search requirements.
func PathToTrigramQuery ¶
func PathToTrigramQuery(pathKey string) TrigramQuery
PathToTrigramQuery converts a field path key into a TrigramQuery constraining candidates to logs/structs that contain the path's constituent field segments formatted as YAML keys. If pathKey is empty or "*", or if none of the segments have at least 3 runes with colon, it returns &AllQuery{}.
func RegexToTrigramQuery ¶
func RegexToTrigramQuery(s *syntax.Regexp) TrigramQuery
RegexToTrigramQuery translates a parsed syntax.Regexp into a TrigramQuery Boolean AST.