#![warn(missing_docs)]
#![doc = include_str!("../README.md")]
pub mod err;
mod symcc;
mod symccopt;
use cedar_policy::{Effect, Policy, PolicySet, RequestEnv, Schema};
use nonempty::{nonempty, NonEmpty};
use std::fmt;
use err::{Error, Result};
use solver::Solver;
use symcc::{well_typed_policies, well_typed_policy, Environment, SymCompiler};
use symccopt::{
verify_always_allows_opt, verify_always_denies_opt, verify_always_matches_opt,
verify_disjoint_opt, verify_equivalent_opt, verify_implies_opt, verify_matches_disjoint_opt,
verify_matches_equivalent_opt, verify_matches_implies_opt, verify_never_errors_opt,
verify_never_matches_opt, CompiledPolicies,
};
pub use symcc::bitvec;
pub use symcc::ext;
pub use symcc::extension_types;
pub use symcc::factory as term_factory;
pub use symcc::op;
pub use symcc::solver;
pub use symcc::solver_pool;
pub use symcc::term;
pub use symcc::term_type;
pub use symcc::type_abbrevs;
pub use symcc::verifier::Asserts;
pub use symcc::Interpretation;
pub use symcc::{CompiledSchema, Env, ResetMode, SmtLibScript, SymEnv};
impl SymEnv {
pub fn new(schema: &Schema, req_env: &RequestEnv) -> Result<Self> {
let env = Environment::from_request_env(req_env, schema.as_ref())
.ok_or_else(|| Error::ActionNotInSchema(req_env.action().to_string()))?;
Ok(Self::of_env(&env)?)
}
}
#[derive(Clone, Debug)]
#[deprecated(since = "0.3.0", note = "use `CompiledPolicy` instead")]
pub struct WellTypedPolicy {
policy: cedar_policy_core::ast::Policy,
}
#[expect(deprecated, reason = "impl on a deprecated struct")]
impl WellTypedPolicy {
pub fn policy(&self) -> &cedar_policy_core::ast::Policy {
&self.policy
}
pub fn from_policy(
policy: &Policy,
env: &RequestEnv,
schema: &Schema,
) -> Result<WellTypedPolicy> {
well_typed_policy(policy.as_ref(), env, schema).map(|p| WellTypedPolicy { policy: p })
}
pub fn from_policy_unchecked(policy: &Policy) -> Self {
WellTypedPolicy {
policy: policy.as_ref().clone(),
}
}
}
#[expect(deprecated, reason = "impl for a deprecated struct")]
impl fmt::Display for WellTypedPolicy {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
write!(f, "{}", self.policy)
}
}
#[derive(Clone, Debug)]
#[deprecated(since = "0.3.0", note = "use `CompiledPolicySet` instead")]
pub struct WellTypedPolicies {
policies: cedar_policy_core::ast::PolicySet,
}
#[expect(deprecated, reason = "impl on a deprecated struct")]
impl WellTypedPolicies {
pub fn policy_set(&self) -> &cedar_policy_core::ast::PolicySet {
&self.policies
}
pub fn from_policies(
ps: &PolicySet,
env: &RequestEnv,
schema: &Schema,
) -> Result<WellTypedPolicies> {
well_typed_policies(ps.as_ref(), env, schema).map(|ps| WellTypedPolicies { policies: ps })
}
pub fn from_policies_unchecked(ps: &PolicySet) -> Self {
WellTypedPolicies {
policies: ps.as_ref().clone(),
}
}
}
#[expect(deprecated, reason = "impl for a deprecated struct")]
impl fmt::Display for WellTypedPolicies {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
write!(f, "{}", self.policies)
}
}
#[derive(Debug, Clone)]
pub struct CompiledPolicy {
policy: symccopt::CompiledPolicy,
}
impl CompiledPolicy {
pub fn compile(policy: &Policy, env: &RequestEnv, schema: &Schema) -> Result<Self> {
Ok(Self {
policy: symccopt::CompiledPolicy::compile(policy.as_ref(), env, schema)?,
})
}
pub fn compile_with_custom_symenv(
policy: &Policy,
env: &RequestEnv,
schema: &Schema,
symenv: SymEnv,
) -> Result<Self> {
Ok(Self {
policy: symccopt::CompiledPolicy::compile_with_custom_symenv(
policy.as_ref(),
env,
schema,
symenv,
)?,
})
}
pub fn effect(&self) -> Effect {
self.policy.effect()
}
pub fn into_compiled_policyset(self) -> CompiledPolicySet {
CompiledPolicySet {
policies: self.policy.into_compiled_policyset(),
}
}
}
#[derive(Debug, Clone)]
pub struct CompiledPolicySet {
policies: symccopt::CompiledPolicySet,
}
impl CompiledPolicySet {
pub fn compile(pset: &PolicySet, env: &RequestEnv, schema: &Schema) -> Result<Self> {
Ok(Self {
policies: symccopt::CompiledPolicySet::compile(pset.as_ref(), env, schema)?,
})
}
pub fn compile_with_custom_symenv(
pset: &PolicySet,
env: &RequestEnv,
schema: &Schema,
symenv: SymEnv,
) -> Result<Self> {
Ok(Self {
policies: symccopt::CompiledPolicySet::compile_with_custom_symenv(
pset.as_ref(),
env,
schema,
symenv,
)?,
})
}
}
#[derive(Clone, Debug)]
pub struct CedarSymCompiler<S: Solver> {
symcc: SymCompiler<S>,
}
impl<S: Solver> CedarSymCompiler<S> {
pub fn new(solver: S) -> Result<Self> {
Ok(Self {
symcc: SymCompiler::new(solver),
})
}
pub fn with_reset_mode(mut self, reset_mode: ResetMode) -> Self {
self.symcc.set_reset_mode(reset_mode);
self
}
pub fn reset_mode(&self) -> ResetMode {
self.symcc.reset_mode()
}
pub fn solver(&self) -> &S {
self.symcc.solver()
}
pub fn solver_mut(&mut self) -> &mut S {
self.symcc.solver_mut()
}
pub async fn check_unsat(&mut self, asserts: &WellFormedAsserts<'_>) -> Result<bool> {
self.symcc
.check_unsat(|_| Ok(asserts.asserts().clone()), asserts.symenv())
.await
}
pub async fn check_unsat_raw(&mut self, asserts: Asserts, symenv: &SymEnv) -> Result<bool> {
self.symcc.check_unsat(|_| Ok(asserts), symenv).await
}
pub async fn check_sat(&mut self, asserts: &WellFormedAsserts<'_>) -> Result<Option<Env>> {
let policies: Vec<&CompiledPolicies<'_>> = asserts.policies().collect();
let policies_iter = policies.iter().copied();
self.symcc
.sat_asserts_opt(asserts.asserts(), policies_iter)
.await
}
#[deprecated(since = "0.3.0", note = "use `check_never_errors_opt()` instead")]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_never_errors(
&mut self,
policy: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<bool> {
self.symcc.check_never_errors(&policy.policy, symenv).await
}
pub async fn check_never_errors_opt(&mut self, policy: &CompiledPolicy) -> Result<bool> {
self.symcc.check_never_errors_opt(&policy.policy).await
}
#[deprecated(
since = "0.3.0",
note = "use `check_never_errors_with_counterexample_opt()` instead"
)]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_never_errors_with_counterexample(
&mut self,
policy: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<Option<Env>> {
self.symcc
.check_never_errors_with_counterexample(&policy.policy, symenv)
.await
}
pub async fn check_never_errors_with_counterexample_opt(
&mut self,
policy: &CompiledPolicy,
) -> Result<Option<Env>> {
self.symcc
.check_never_errors_with_counterexample_opt(&policy.policy)
.await
}
#[deprecated(since = "0.3.0", note = "use `check_always_matches_opt()` instead")]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_always_matches(
&mut self,
policy: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<bool> {
self.symcc
.check_always_matches(&policy.policy, symenv)
.await
}
pub async fn check_always_matches_opt(&mut self, policy: &CompiledPolicy) -> Result<bool> {
self.symcc.check_always_matches_opt(&policy.policy).await
}
#[deprecated(
since = "0.3.0",
note = "use `check_always_matches_with_counterexample_opt()` instead"
)]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_always_matches_with_counterexample(
&mut self,
policy: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<Option<Env>> {
self.symcc
.check_always_matches_with_counterexample(&policy.policy, symenv)
.await
}
pub async fn check_always_matches_with_counterexample_opt(
&mut self,
policy: &CompiledPolicy,
) -> Result<Option<Env>> {
self.symcc
.check_always_matches_with_counterexample_opt(&policy.policy)
.await
}
#[deprecated(since = "0.3.0", note = "use `check_never_matches_opt()` instead")]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_never_matches(
&mut self,
policy: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<bool> {
self.symcc.check_never_matches(&policy.policy, symenv).await
}
pub async fn check_never_matches_opt(&mut self, policy: &CompiledPolicy) -> Result<bool> {
self.symcc.check_never_matches_opt(&policy.policy).await
}
#[deprecated(
since = "0.3.0",
note = "use `check_never_matches_with_counterexample_opt()` instead"
)]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_never_matches_with_counterexample(
&mut self,
policy: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<Option<Env>> {
self.symcc
.check_never_matches_with_counterexample(&policy.policy, symenv)
.await
}
pub async fn check_never_matches_with_counterexample_opt(
&mut self,
policy: &CompiledPolicy,
) -> Result<Option<Env>> {
self.symcc
.check_never_matches_with_counterexample_opt(&policy.policy)
.await
}
#[deprecated(since = "0.3.0", note = "use `check_matches_equivalent_opt()` instead")]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_matches_equivalent(
&mut self,
policy1: &WellTypedPolicy,
policy2: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<bool> {
self.symcc
.check_matches_equivalent(&policy1.policy, &policy2.policy, symenv)
.await
}
pub async fn check_matches_equivalent_opt(
&mut self,
policy1: &CompiledPolicy,
policy2: &CompiledPolicy,
) -> Result<bool> {
self.symcc
.check_matches_equivalent_opt(&policy1.policy, &policy2.policy)
.await
}
#[deprecated(
since = "0.3.0",
note = "use `check_matches_equivalent_with_counterexample_opt()` instead"
)]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_matches_equivalent_with_counterexample(
&mut self,
policy1: &WellTypedPolicy,
policy2: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<Option<Env>> {
self.symcc
.check_matches_equivalent_with_counterexample(&policy1.policy, &policy2.policy, symenv)
.await
}
pub async fn check_matches_equivalent_with_counterexample_opt(
&mut self,
policy1: &CompiledPolicy,
policy2: &CompiledPolicy,
) -> Result<Option<Env>> {
self.symcc
.check_matches_equivalent_with_counterexample_opt(&policy1.policy, &policy2.policy)
.await
}
#[deprecated(since = "0.3.0", note = "use `check_matches_implies_opt()` instead")]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_matches_implies(
&mut self,
policy1: &WellTypedPolicy,
policy2: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<bool> {
self.symcc
.check_matches_implies(&policy1.policy, &policy2.policy, symenv)
.await
}
pub async fn check_matches_implies_opt(
&mut self,
policy1: &CompiledPolicy,
policy2: &CompiledPolicy,
) -> Result<bool> {
self.symcc
.check_matches_implies_opt(&policy1.policy, &policy2.policy)
.await
}
#[deprecated(
since = "0.3.0",
note = "use `check_matches_implies_with_counterexample_opt()` instead"
)]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_matches_implies_with_counterexample(
&mut self,
policy1: &WellTypedPolicy,
policy2: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<Option<Env>> {
self.symcc
.check_matches_implies_with_counterexample(&policy1.policy, &policy2.policy, symenv)
.await
}
pub async fn check_matches_implies_with_counterexample_opt(
&mut self,
policy1: &CompiledPolicy,
policy2: &CompiledPolicy,
) -> Result<Option<Env>> {
self.symcc
.check_matches_implies_with_counterexample_opt(&policy1.policy, &policy2.policy)
.await
}
#[deprecated(since = "0.3.0", note = "use `check_matches_disjoint_opt()` instead")]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_matches_disjoint(
&mut self,
policy1: &WellTypedPolicy,
policy2: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<bool> {
self.symcc
.check_matches_disjoint(&policy1.policy, &policy2.policy, symenv)
.await
}
pub async fn check_matches_disjoint_opt(
&mut self,
policy1: &CompiledPolicy,
policy2: &CompiledPolicy,
) -> Result<bool> {
self.symcc
.check_matches_disjoint_opt(&policy1.policy, &policy2.policy)
.await
}
#[deprecated(
since = "0.3.0",
note = "use `check_matches_disjoint_with_counterexample_opt()` instead"
)]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_matches_disjoint_with_counterexample(
&mut self,
policy1: &WellTypedPolicy,
policy2: &WellTypedPolicy,
symenv: &SymEnv,
) -> Result<Option<Env>> {
self.symcc
.check_matches_disjoint_with_counterexample(&policy1.policy, &policy2.policy, symenv)
.await
}
pub async fn check_matches_disjoint_with_counterexample_opt(
&mut self,
policy1: &CompiledPolicy,
policy2: &CompiledPolicy,
) -> Result<Option<Env>> {
self.symcc
.check_matches_disjoint_with_counterexample_opt(&policy1.policy, &policy2.policy)
.await
}
#[deprecated(since = "0.3.0", note = "use `check_implies_opt()` instead")]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_implies(
&mut self,
pset1: &WellTypedPolicies,
pset2: &WellTypedPolicies,
symenv: &SymEnv,
) -> Result<bool> {
self.symcc
.check_implies(&pset1.policies, &pset2.policies, symenv)
.await
}
pub async fn check_implies_opt(
&mut self,
pset1: &CompiledPolicySet,
pset2: &CompiledPolicySet,
) -> Result<bool> {
self.symcc
.check_implies_opt(&pset1.policies, &pset2.policies)
.await
}
#[deprecated(
since = "0.3.0",
note = "use `check_implies_with_counterexample_opt()` instead"
)]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_implies_with_counterexample(
&mut self,
pset1: &WellTypedPolicies,
pset2: &WellTypedPolicies,
symenv: &SymEnv,
) -> Result<Option<Env>> {
self.symcc
.check_implies_with_counterexample(&pset1.policies, &pset2.policies, symenv)
.await
}
pub async fn check_implies_with_counterexample_opt(
&mut self,
pset1: &CompiledPolicySet,
pset2: &CompiledPolicySet,
) -> Result<Option<Env>> {
self.symcc
.check_implies_with_counterexample_opt(&pset1.policies, &pset2.policies)
.await
}
#[deprecated(since = "0.3.0", note = "use `check_always_allows_opt()` instead")]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_always_allows(
&mut self,
pset: &WellTypedPolicies,
symenv: &SymEnv,
) -> Result<bool> {
self.symcc.check_always_allows(&pset.policies, symenv).await
}
pub async fn check_always_allows_opt(&mut self, pset: &CompiledPolicySet) -> Result<bool> {
self.symcc.check_always_allows_opt(&pset.policies).await
}
#[deprecated(
since = "0.3.0",
note = "use `check_always_allows_with_counterexample_opt()` instead"
)]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_always_allows_with_counterexample(
&mut self,
pset: &WellTypedPolicies,
symenv: &SymEnv,
) -> Result<Option<Env>> {
self.symcc
.check_always_allows_with_counterexample(&pset.policies, symenv)
.await
}
pub async fn check_always_allows_with_counterexample_opt(
&mut self,
pset: &CompiledPolicySet,
) -> Result<Option<Env>> {
self.symcc
.check_always_allows_with_counterexample_opt(&pset.policies)
.await
}
#[deprecated(since = "0.3.0", note = "use `check_always_denies_opt()` instead")]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_always_denies(
&mut self,
pset: &WellTypedPolicies,
symenv: &SymEnv,
) -> Result<bool> {
self.symcc.check_always_denies(&pset.policies, symenv).await
}
pub async fn check_always_denies_opt(&mut self, pset: &CompiledPolicySet) -> Result<bool> {
self.symcc.check_always_denies_opt(&pset.policies).await
}
#[deprecated(
since = "0.3.0",
note = "use `check_always_denies_with_counterexample_opt()` instead"
)]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_always_denies_with_counterexample(
&mut self,
pset: &WellTypedPolicies,
symenv: &SymEnv,
) -> Result<Option<Env>> {
self.symcc
.check_always_denies_with_counterexample(&pset.policies, symenv)
.await
}
pub async fn check_always_denies_with_counterexample_opt(
&mut self,
pset: &CompiledPolicySet,
) -> Result<Option<Env>> {
self.symcc
.check_always_denies_with_counterexample_opt(&pset.policies)
.await
}
#[deprecated(since = "0.3.0", note = "use `check_equivalent_opt()` instead")]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_equivalent(
&mut self,
pset1: &WellTypedPolicies,
pset2: &WellTypedPolicies,
symenv: &SymEnv,
) -> Result<bool> {
self.symcc
.check_equivalent(&pset1.policies, &pset2.policies, symenv)
.await
}
pub async fn check_equivalent_opt(
&mut self,
pset1: &CompiledPolicySet,
pset2: &CompiledPolicySet,
) -> Result<bool> {
self.symcc
.check_equivalent_opt(&pset1.policies, &pset2.policies)
.await
}
#[deprecated(
since = "0.3.0",
note = "use `check_equivalent_with_counterexample_opt()` instead"
)]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_equivalent_with_counterexample(
&mut self,
pset1: &WellTypedPolicies,
pset2: &WellTypedPolicies,
symenv: &SymEnv,
) -> Result<Option<Env>> {
self.symcc
.check_equivalent_with_counterexample(&pset1.policies, &pset2.policies, symenv)
.await
}
pub async fn check_equivalent_with_counterexample_opt(
&mut self,
pset1: &CompiledPolicySet,
pset2: &CompiledPolicySet,
) -> Result<Option<Env>> {
self.symcc
.check_equivalent_with_counterexample_opt(&pset1.policies, &pset2.policies)
.await
}
#[deprecated(since = "0.3.0", note = "use `check_disjoint_opt()` instead")]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_disjoint(
&mut self,
pset1: &WellTypedPolicies,
pset2: &WellTypedPolicies,
symenv: &SymEnv,
) -> Result<bool> {
self.symcc
.check_disjoint(&pset1.policies, &pset2.policies, symenv)
.await
}
pub async fn check_disjoint_opt(
&mut self,
pset1: &CompiledPolicySet,
pset2: &CompiledPolicySet,
) -> Result<bool> {
self.symcc
.check_disjoint_opt(&pset1.policies, &pset2.policies)
.await
}
#[deprecated(
since = "0.3.0",
note = "use `check_disjoint_with_counterexample_opt()` instead"
)]
#[expect(deprecated, reason = "deprecated function uses deprecated types")]
pub async fn check_disjoint_with_counterexample(
&mut self,
pset1: &WellTypedPolicies,
pset2: &WellTypedPolicies,
symenv: &SymEnv,
) -> Result<Option<Env>> {
self.symcc
.check_disjoint_with_counterexample(&pset1.policies, &pset2.policies, symenv)
.await
}
pub async fn check_disjoint_with_counterexample_opt(
&mut self,
pset1: &CompiledPolicySet,
pset2: &CompiledPolicySet,
) -> Result<Option<Env>> {
self.symcc
.check_disjoint_with_counterexample_opt(&pset1.policies, &pset2.policies)
.await
}
}
#[derive(Clone, Debug)]
pub struct WellFormedAsserts<'a> {
asserts: Asserts,
policies: NonEmpty<CompiledPolicies<'a>>,
}
impl<'a> WellFormedAsserts<'a> {
pub fn symenv(&self) -> &SymEnv {
self.policies.first().symenv()
}
pub fn asserts(&self) -> &Asserts {
&self.asserts
}
fn policies<'s>(&'s self) -> impl Iterator<Item = &'s CompiledPolicies<'a>> + 's {
self.policies.iter()
}
}
pub fn never_errors_asserts<'a>(policy: &'a CompiledPolicy) -> WellFormedAsserts<'a> {
WellFormedAsserts {
asserts: verify_never_errors_opt(&policy.policy),
policies: nonempty![CompiledPolicies::Policy(&policy.policy)],
}
}
pub fn always_matches_asserts<'a>(policy: &'a CompiledPolicy) -> WellFormedAsserts<'a> {
WellFormedAsserts {
asserts: verify_always_matches_opt(&policy.policy),
policies: nonempty![CompiledPolicies::Policy(&policy.policy)],
}
}
pub fn never_matches_asserts<'a>(policy: &'a CompiledPolicy) -> WellFormedAsserts<'a> {
WellFormedAsserts {
asserts: verify_never_matches_opt(&policy.policy),
policies: nonempty![CompiledPolicies::Policy(&policy.policy)],
}
}
pub fn matches_equivalent_asserts<'a>(
policy1: &'a CompiledPolicy,
policy2: &'a CompiledPolicy,
) -> WellFormedAsserts<'a> {
WellFormedAsserts {
asserts: verify_matches_equivalent_opt(&policy1.policy, &policy2.policy),
policies: nonempty![
CompiledPolicies::Policy(&policy1.policy),
CompiledPolicies::Policy(&policy2.policy)
],
}
}
pub fn matches_implies_asserts<'a>(
policy1: &'a CompiledPolicy,
policy2: &'a CompiledPolicy,
) -> WellFormedAsserts<'a> {
WellFormedAsserts {
asserts: verify_matches_implies_opt(&policy1.policy, &policy2.policy),
policies: nonempty![
CompiledPolicies::Policy(&policy1.policy),
CompiledPolicies::Policy(&policy2.policy)
],
}
}
pub fn matches_disjoint_asserts<'a>(
policy1: &'a CompiledPolicy,
policy2: &'a CompiledPolicy,
) -> WellFormedAsserts<'a> {
WellFormedAsserts {
asserts: verify_matches_disjoint_opt(&policy1.policy, &policy2.policy),
policies: nonempty![
CompiledPolicies::Policy(&policy1.policy),
CompiledPolicies::Policy(&policy2.policy)
],
}
}
pub fn always_allows_asserts<'a>(policies: &'a CompiledPolicySet) -> WellFormedAsserts<'a> {
WellFormedAsserts {
asserts: verify_always_allows_opt(&policies.policies),
policies: nonempty![CompiledPolicies::PolicySet(&policies.policies)],
}
}
pub fn always_denies_asserts<'a>(policies: &'a CompiledPolicySet) -> WellFormedAsserts<'a> {
WellFormedAsserts {
asserts: verify_always_denies_opt(&policies.policies),
policies: nonempty![CompiledPolicies::PolicySet(&policies.policies)],
}
}
pub fn implies_asserts<'a>(
policies1: &'a CompiledPolicySet,
policies2: &'a CompiledPolicySet,
) -> WellFormedAsserts<'a> {
WellFormedAsserts {
asserts: verify_implies_opt(&policies1.policies, &policies2.policies),
policies: nonempty![
CompiledPolicies::PolicySet(&policies1.policies),
CompiledPolicies::PolicySet(&policies2.policies)
],
}
}
pub fn equivalent_asserts<'a>(
policies1: &'a CompiledPolicySet,
policies2: &'a CompiledPolicySet,
) -> WellFormedAsserts<'a> {
WellFormedAsserts {
asserts: verify_equivalent_opt(&policies1.policies, &policies2.policies),
policies: nonempty![
CompiledPolicies::PolicySet(&policies1.policies),
CompiledPolicies::PolicySet(&policies2.policies)
],
}
}
pub fn disjoint_asserts<'a>(
policies1: &'a CompiledPolicySet,
policies2: &'a CompiledPolicySet,
) -> WellFormedAsserts<'a> {
WellFormedAsserts {
asserts: verify_disjoint_opt(&policies1.policies, &policies2.policies),
policies: nonempty![
CompiledPolicies::PolicySet(&policies1.policies),
CompiledPolicies::PolicySet(&policies2.policies)
],
}
}