tag v0.155.0 Tagger: imagebuilder-bot <imagebuilder-bots+imagebuilder-bot@redhat.com> Changes with 0.155.0 ---------------- * Fedora 43: add shadow-utils when LockRoot is enabled, update cloud-init service name (osbuild/images#1618) * Author: Achilleas Koutsou, Reviewers: Gianluca Zuccarelli, Michael Vogt * Update osbuild dependency commit ID to latest (osbuild/images#1609) * Author: SchutzBot, Reviewers: Achilleas Koutsou, Simon de Vlieger, Tomáš Hozza * Update snapshots to 20250626 (osbuild/images#1623) * Author: SchutzBot, Reviewers: Achilleas Koutsou, Simon de Vlieger * distro/rhel9: xz compress azure-cvm image type [HMS-8587] (osbuild/images#1620) * Author: Achilleas Koutsou, Reviewers: Simon de Vlieger, Tomáš Hozza * distro/rhel: introduce new image type: Azure SAP Apps [HMS-8738] (osbuild/images#1612) * Author: Achilleas Koutsou, Reviewers: Simon de Vlieger, Tomáš Hozza * distro/rhel: move ansible-core to sap_extras_pkgset (osbuild/images#1624) * Author: Achilleas Koutsou, Reviewers: Brian C. Lane, Tomáš Hozza * github/create-tag: allow passing the version when run manually (osbuild/images#1621) * Author: Achilleas Koutsou, Reviewers: Lukáš Zapletal, Tomáš Hozza * rhel9: move image-config into pure YAML (HMS-8593) (osbuild/images#1616) * Author: Michael Vogt, Reviewers: Achilleas Koutsou, Simon de Vlieger * test: split manifest checksums into separate files (osbuild/images#1625) * Author: Achilleas Koutsou, Reviewers: Simon de Vlieger, Tomáš Hozza — Somewhere on the Internet, 2025-06-30 --- tag v0.156.0 Tagger: imagebuilder-bot <imagebuilder-bots+imagebuilder-bot@redhat.com> Changes with 0.156.0 ---------------- * Many: delete repositories for EOL distributions (HMS-7044) (osbuild/images#1607) * Author: Tomáš Hozza, Reviewers: Michael Vogt, Simon de Vlieger * RHSM/facts: add 'image-builder CLI' API type (osbuild/images#1640) * Author: Tomáš Hozza, Reviewers: Brian C. Lane, Simon de Vlieger * Update dependencies 2025-06-29 (osbuild/images#1628) * Author: SchutzBot, Reviewers: Simon de Vlieger, Tomáš Hozza * Update osbuild dependency commit ID to latest (osbuild/images#1627) * Author: SchutzBot, Reviewers: Simon de Vlieger, Tomáš Hozza * [RFC] image: drop `InstallWeakDeps` from image.DiskImage (osbuild/images#1642) * Author: Michael Vogt, Reviewers: Brian C. Lane, Simon de Vlieger, Tomáš Hozza * build(deps): bump the go-deps group across 1 directory with 3 updates (osbuild/images#1632) * Author: dependabot[bot], Reviewers: SchutzBot, Tomáš Hozza * distro/rhel10: xz compress azure-cvm image type (osbuild/images#1638) * Author: Achilleas Koutsou, Reviewers: Brian C. Lane, Simon de Vlieger * distro: cleanup/refactor distro/{defs,generic} (HMS-8744) (osbuild/images#1570) * Author: Michael Vogt, Reviewers: Simon de Vlieger, Tomáš Hozza * distro: remove some hardcoded values from generic/images.go (osbuild/images#1636) * Author: Michael Vogt, Reviewers: Simon de Vlieger, Tomáš Hozza * distro: small tweaks for the YAML based imagetypes (osbuild/images#1622) * Author: Michael Vogt, Reviewers: Brian C. Lane, Simon de Vlieger * fedora/wsl: packages and locale (osbuild/images#1635) * Author: Simon de Vlieger, Reviewers: Michael Vogt, Tomáš Hozza * image/many: make compression more generic (osbuild/images#1634) * Author: Simon de Vlieger, Reviewers: Brian C. Lane, Michael Vogt * manifest: handle content template name with spaces (osbuild/images#1641) * Author: Bryttanie, Reviewers: Brian C. Lane, Michael Vogt, Tomáš Hozza * many: implement gzip (osbuild/images#1633) * Author: Simon de Vlieger, Reviewers: Michael Vogt, Tomáš Hozza * rhel/azure: set GRUB_TERMINAL based on architecture [RHEL-91383] (osbuild/images#1626) * Author: Achilleas Koutsou, Reviewers: Simon de Vlieger, Tomáš Hozza — Somewhere on the Internet, 2025-07-07 ---
71 lines
2.9 KiB
Markdown
71 lines
2.9 KiB
Markdown
# Common Expression Language
|
|
|
|
The Common Expression Language (CEL) implements common semantics for expression
|
|
evaluation, enabling different applications to more easily interoperate.
|
|
|
|
Key Applications
|
|
|
|
* Security policy: organizations have complex infrastructure and need common
|
|
tooling to reason about the system as a whole
|
|
* Protocols: expressions are a useful data type and require interoperability
|
|
across programming languages and platforms.
|
|
|
|
|
|
Guiding philosophy:
|
|
|
|
1. Keep it small & fast.
|
|
* CEL evaluates in linear time, is mutation free, and not Turing-complete.
|
|
This limitation is a feature of the language design, which allows the
|
|
implementation to evaluate orders of magnitude faster than equivalently
|
|
sandboxed JavaScript.
|
|
2. Make it extensible.
|
|
* CEL is designed to be embedded in applications, and allows for
|
|
extensibility via its context which allows for functions and data to be
|
|
provided by the software that embeds it.
|
|
3. Developer-friendly.
|
|
* The language is approachable to developers. The initial spec was based
|
|
on the experience of developing Firebase Rules and usability testing
|
|
many prior iterations.
|
|
* The library itself and accompanying toolings should be easy to adopt by
|
|
teams that seek to integrate CEL into their platforms.
|
|
|
|
The required components of a system that supports CEL are:
|
|
|
|
* The textual representation of an expression as written by a developer. It is
|
|
of similar syntax to expressions in C/C++/Java/JavaScript
|
|
* A representation of the program's abstract syntax tree (AST).
|
|
* A compiler library that converts the textual representation to the binary
|
|
representation. This can be done ahead of time (in the control plane) or
|
|
just before evaluation (in the data plane).
|
|
* A context containing one or more typed variables, often protobuf messages.
|
|
Most use-cases will use `attribute_context.proto`
|
|
* An evaluator library that takes the binary format in the context and
|
|
produces a result, usually a Boolean.
|
|
|
|
For use cases which require persistence or cross-process communcation, it is
|
|
highly recommended to serialize the type-checked expression as a protocol
|
|
buffer. The CEL team will maintains canonical protocol buffers for ASTs and
|
|
will keep these versions identical and wire-compatible in perpetuity:
|
|
|
|
* [CEL canonical](https://github.com/google/cel-spec/tree/master/proto/cel/expr)
|
|
* [CEL v1alpha1](https://github.com/googleapis/googleapis/tree/master/google/api/expr/v1alpha1)
|
|
|
|
|
|
Example of boolean conditions and object construction:
|
|
|
|
``` c
|
|
// Condition
|
|
account.balance >= transaction.withdrawal
|
|
|| (account.overdraftProtection
|
|
&& account.overdraftLimit >= transaction.withdrawal - account.balance)
|
|
|
|
// Object construction
|
|
common.GeoPoint{ latitude: 10.0, longitude: -5.5 }
|
|
```
|
|
|
|
For more detail, see:
|
|
|
|
* [Introduction](doc/intro.md)
|
|
* [Language Definition](doc/langdef.md)
|
|
|
|
Released under the [Apache License](LICENSE).
|