Expand description
The condition language a [filter.rule.<name>] is written in.
A rule’s when is a boolean expression over the names of
[filter.check.<name>] entries:
when = "mgmt-net or (inventory and corp-names)"expr := term ( "or" term )*
term := factor ( "and" factor )*
factor := "not" factor | "(" expr ")" | name
name := [a-z0-9-]+not binds tightest, then and, then or; and and or are
left-associative. The three keywords are matched case-insensitively, and a
check may therefore not be named one of them — is_reserved_word is
what the policy builder asks, since the tokenizer resolves the ambiguity in
the keyword’s favour and a check named and would simply be unreachable.
§Why a string and not nested TOML
An all/any/none table would need no parser, but
Config::merged_sections merges a profile’s
configuration onto the global one per key for tables and wholesale for
everything else. A global all = [...] and a profile’s any = [...] would
therefore merge into one table carrying both keys, and the profile would have
meant to replace the condition rather than add to it. A string is a scalar,
so it replaces — the only sane inheritance for a policy expression.
§Errors carry a column
Every failure names the character position it gave up at, because the whole expression is one line in a configuration file and “invalid condition” would send an operator hunting through it. Columns are 1-based.
Structs§
- Expr
Error - Why an expression would not parse, and where.
Enums§
- Condition
- A parsed
whenexpression.
Functions§
- is_
reserved_ word - Whether
nameis one of the three words the condition language reserves.