Documentation
¶
Overview ¶
- Package cel @Author: zhizhuo @IDE:GoLand @File: celcompile.go @Date: 2025/2/7 上午8:57*
- Package cel @Author: zhizhuo @IDE:GoLand @File: celprogram.go @Date: 2025/2/7 上午9:22*
Index ¶
- func ReadCompileOptions() []cel.EnvOption
- func WithResponseCache(ctx context.Context) context.Context
- type CustomLib
- func (c *CustomLib) BatchUpdateCompileOptions(declarations map[string]*cel.Type)
- func (c *CustomLib) Evaluate(expression string, variables map[string]any) (ref.Val, error)
- func (c *CustomLib) EvaluateContext(ctx context.Context, expression string, variables map[string]any) (ref.Val, error)
- func (c *CustomLib) Evidence(variables map[string]any) ([]Evidence, bool)
- func (c *CustomLib) PreRegisterRuleFunctions(names []string)
- func (c *CustomLib) Prepare(expression string) error
- func (c *CustomLib) Reset()
- func (c *CustomLib) ReverseConfig() scantypes.ReverseConfig
- func (c *CustomLib) SetContext(ctx context.Context)
- func (c *CustomLib) SetEvidenceEnabled(enabled bool)
- func (c *CustomLib) SetRequestOptions(client *network.HTTPClient, opts network.OptionsRequest)
- func (c *CustomLib) SetReverseConfig(config scantypes.ReverseConfig)
- func (c *CustomLib) UpdateCompileOption(name string, t *cel.Type)
- func (c *CustomLib) WriteRuleFunctionsROptions(name string, value bool)
- type Evidence
- type PreparedLibrary
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ReadCompileOptions ¶
ReadCompileOptions 返回 CEL 环境选项(类型、变量、函数实现)
Types ¶
type CustomLib ¶
type CustomLib struct {
// contains filtered or unexported fields
}
CustomLib 只保存本次求值的数据。环境和程序是有界缓存中的不可变对象。 零参数规则函数在解析时展开为输入变量访问,程序不捕获其他扫描的可变状态。
func NewCustomLib ¶
func NewCustomLib() *CustomLib
func (*CustomLib) BatchUpdateCompileOptions ¶
func (*CustomLib) EvaluateContext ¶
func (*CustomLib) Evidence ¶ added in v1.2.0
Evidence 必须在相应表达式求值之后、下一次求值之前读取。 仅沿实际执行且符合逻辑结果的分支取证,不重新执行 CEL 或其 I/O、随机函数。
func (*CustomLib) PreRegisterRuleFunctions ¶
func (*CustomLib) Reset ¶
func (c *CustomLib) Reset()
Reset 释放扫描、响应和程序引用;仅保留小型空规则表供下一次求值复用。 CustomLib 的可变状态只属于一个执行者,不得在求值期间重置或并发使用。
func (*CustomLib) ReverseConfig ¶
func (c *CustomLib) ReverseConfig() scantypes.ReverseConfig
func (*CustomLib) SetContext ¶
func (*CustomLib) SetEvidenceEnabled ¶ added in v1.2.0
func (*CustomLib) SetRequestOptions ¶
func (c *CustomLib) SetRequestOptions(client *network.HTTPClient, opts network.OptionsRequest)
SetRequestOptions 让反连查询遵循所属扫描实例的代理、超时与限流策略。
func (*CustomLib) SetReverseConfig ¶
func (c *CustomLib) SetReverseConfig(config scantypes.ReverseConfig)
SetReverseConfig 绑定当前执行者的反连配置,Reset 时一并清除。
func (*CustomLib) UpdateCompileOption ¶
func (*CustomLib) WriteRuleFunctionsROptions ¶
type Evidence ¶ added in v1.2.0
type Evidence struct {
Expression string `json:"expression"`
Field string `json:"field,omitempty"`
Matched bool `json:"matched"`
Start int `json:"start"`
End int `json:"end"`
SnippetStart int `json:"snippet_start"`
Snippet string `json:"snippet,omitempty"`
Encoding string `json:"encoding,omitempty"`
Truncated bool `json:"truncated,omitempty"`
}
Evidence 的位置是原始字段的字节区间 [Start, End)。-1 表示没有可定位内容。 二进制片段以 base64 保存;SnippetStart 始终使用解码前的字节位置。
type PreparedLibrary ¶
type PreparedLibrary struct {
// contains filtered or unexported fields
}
PreparedLibrary 属于只读规则快照。加载时固定环境和程序,运行时只创建 本次扫描的规则结果与请求状态,避免为每个目标重复拼接环境签名和查询缓存。
func PrepareLibrary ¶
func PrepareLibrary(rules, expressions []string, evidence ...bool) (*PreparedLibrary, error)
func (*PreparedLibrary) BatchSafe ¶
func (p *PreparedLibrary) BatchSafe() bool
BatchSafe 表明内置执行计划不包含推导循环、等待或反连 I/O。 请求是否已缓存仍由 Runner 判断,动态规则沿用逐条调度路径。
func (*PreparedLibrary) InitEvaluation ¶
func (p *PreparedLibrary) InitEvaluation(lib *CustomLib)
InitEvaluation 为独占的执行状态绑定只读程序,旧的规则结果、动态声明和 请求配置均不跨指纹复用。p 为 nil 时使用动态编译路径。
func (*PreparedLibrary) NewEvaluation ¶
func (p *PreparedLibrary) NewEvaluation() *CustomLib