This PR extends entity manifests to describe in particular what Cedar ancestors are required. This can greatly reduce the data required, since entities may have many ancestors. This change is implemented by re-using the existing access trie data structure to describe all the ancestors required.
The change in this PR is (choose one, and delete the other options):
[ ] A breaking change requiring a major version bump to cedar-policy (e.g., changes to the signature of an existing API).
[ ] A backwards-compatible change requiring a minor version bump to cedar-policy (e.g., addition of a new API).
[ ] A bug fix or other functionality change requiring a patch to cedar-policy.
[ ] A change "invisible" to users (e.g., documentation, changes to "internal" crates like cedar-policy-core, cedar-validator, etc.)
[x] A change (breaking or otherwise) that only impacts unreleased or experimental code.
I confirm that this PR (choose one, and delete the other options):
[ ] Updates the "Unreleased" section of the CHANGELOG with a description of my change (required for major/minor version bumps).
[x] Does not update the CHANGELOG because my change does not significantly impact released code.
I confirm that cedar-spec (choose one, and delete the other options):
[ ] Does not require updates because my change does not impact the Cedar formal model or DRT infrastructure.
[ ] Requires updates, and I have made / will make these updates myself. (Please include in your description a timeline or link to the relevant PR in cedar-spec, and how you have tested that your updates are correct.)
[x] Requires updates, but I do not plan to make them in the near future. (Make sure that your changes are hidden behind a feature flag to mark them as experimental.)
[ ] I'm not sure how my change impacts cedar-spec. (Post your PR anyways, and we'll discuss in the comments.)
Description of changes
This PR extends entity manifests to describe in particular what Cedar ancestors are required. This can greatly reduce the data required, since entities may have many ancestors. This change is implemented by re-using the existing access trie data structure to describe all the ancestors required.
PR stack: https://github.com/cedar-policy/cedar/pull/1102 https://github.com/cedar-policy/cedar/pull/1105 https://github.com/cedar-policy/cedar/pull/1154 https://github.com/cedar-policy/cedar/pull/1156 https://github.com/cedar-policy/cedar/pull/1171 (This PR)
1196
https://github.com/cedar-policy/cedar/pull/1208
Issue #, if available
Checklist for requesting a review
The change in this PR is (choose one, and delete the other options):
cedar-policy
(e.g., changes to the signature of an existing API).cedar-policy
(e.g., addition of a new API).cedar-policy
.cedar-policy-core
,cedar-validator
, etc.)I confirm that this PR (choose one, and delete the other options):
I confirm that
cedar-spec
(choose one, and delete the other options):cedar-spec
, and how you have tested that your updates are correct.)cedar-spec
. (Post your PR anyways, and we'll discuss in the comments.)