2 Commits
Author SHA1 Message Date
stefan-gorules a7157f3448 fix: scope policy evaluation to the import closure (#525)
* fix: scope policy evaluation to the import closure

A policy is now analysed and evaluated together with the policies it
imports (transitively), instead of every policy connected to it by imports
in either direction. Importers and siblings no longer leak into each other:
compiled evaluate() of an imported policy used to run its importers' and
siblings' blocks.

- Evaluation gate analyses the entry's import closure as one unit, so a
  child may read fields and reference entities its importer declares when
  evaluated through that importer
- compile() reports a policy that is only valid through an importer with
  kind "policyImportOnly" instead of failing it as a plain "policy"; errors
  are computed once per key
- Scope diagnostics (duplicate writers, input overrides, data model and
  dictionary collisions, cycles) are reported for the whole closure, and
  conflicts introduced by combining imports are reported on the importer
- Single-entity scope checks run per import closure instead of workspace-wide

* fix: unknown import relationship targets and renames across imports

- An unresolved relationship/reference target inside an imported policy now
  blocks the importer's evaluation and compile(), as on master; the check was
  still limited to the policy being analysed, so the importer compiled and
  the broken child was reported as "policyImportOnly"
- Rename and find-references analyse each policy's expressions in every
  importer's context too, so reads of a field declared by an importer are
  found in the imported policy again
2026-09-28 12:17:12 +02:00
stefan-gorules 6c0ca51354 feat: policy engine (#450)
* feat: policy engine

* fix: cargo fmt

* fix: resolve issues with miri
2026-06-23 18:51:47 +02:00