Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package opa for openSUSE:Factory checked in at 2026-09-28 10:40:15 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/opa (Old) and /work/SRC/openSUSE:Factory/.opa.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "opa" Mon Sep 28 10:40:15 2026 rev:29 rq:1380306 version:1.21.0 Changes: -------- --- /work/SRC/openSUSE:Factory/opa/opa.changes 2026-09-19 22:23:47.757244529 +0200 +++ /work/SRC/openSUSE:Factory/.opa.new.383539/opa.changes 2026-09-28 10:40:49.300798279 +0200 @@ -1,0 +2,362 @@ +Fri Sep 25 04:58:28 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 1.21.0: + * This release contains a mix of new features and bug fixes. + Notably: + - Improved rule indexing + - Improved rule recursion check + - YAML is parsed against the 1.2 core schema (breaking change) + * Rules with general refs no longer collide in the recursion + check (#6813) + Before, this was a recursion error: + + package play + + p[x].foo.bar if { + x := "a" + not p[x].foo.baz + } + + p[x].foo.baz if { + x := "a" + false + } + + Rules with a variable in their head are all stored at the + ground prefix of their ref, so p[x].foo.bar and p[x].foo.baz + looked like dependencies of each other. The compiler is now + less conservative and compares the ref parts past the prefix. + Genuine cycles are still reported. + The IR and Wasm targets however still return an error: they + plan one function per ground path prefix, and cannot evaluate + part of a function that is still being planned. + * Data and Query APIs can return rule labels in the response + (#9211) + # METADATA labels for evaluated rules were only available in + decision log events. The Data API (GET/POST /v1/data) and Query + API (GET/POST /v1/query) now accept a rule_labels query + parameter to include the same merged labels in the response + payload, under a rule_labels key. + * Behavior change: response gzip compression now bounds its + buffer to min_length (#9205) + The server's gzip response compression (server.encoding.gzip) + buffered an entire incoming Write call before deciding whether + to compress, so a single large write could grow the buffer well + past min_length before that decision was made. The handler is + now built on klauspost/compress/gzhttp instead of a hand-rolled + buffer and gzip.Writer pool, which caps what it buffers to + min_length (floored at 512 bytes) before streaming the + remainder through the chosen path. min_length and + compression_level behave the same as before; only gzip is + negotiated, not zstd. + * YAML is now parsed against the 1.2 core schema (#5754, #6598) + OPA parsed YAML with a library pinned to go-yaml v2, which + implements YAML 1.1. Under 1.1, the bare words y, n, yes, no, + on and off resolve to booleans, so a GitHub Actions workflow + loaded with --data came back with true where it should have had + on: + + on: push + + { "true": "push" } + + These words are now plain strings, as the YAML 1.2 core schema + specifies. true and false are unaffected. This applies + everywhere OPA reads YAML: --data, bundles, config files, and + the yaml.unmarshal builtin. + If you were relying on yes/no/on/off being read as booleans, + quote the value and use true/false instead. + * Empty composite literals are now typed as empty (#7275) + The type checker used to give the empty object literal {} the + type object[any: any], the empty array literal [] the type + array[any], and the empty set literal set() the type set[any], + i.e. the types of a collection that may hold anything. Every + other literal is typed by its contents, so referencing a key + that isn't there is caught at compile time — but only for + non-empty literals: + + obj := {"foo": "bar"} + obj.bar # rego_type_error: undefined ref: obj.bar + + obj := {} + obj.bar # compiles + + Empty literals are now typed as what they are: an object with + no properties, an array with no items, and a set with no + members. Both examples above now fail to compile, and so does + every other way of selecting from an empty literal, including + iterating one (some x in []). + Comparing an empty object or array literal against a value + whose type says it can't be empty ({"foo": "bar"} == {}) is now + a match error too, the same way {"foo": "bar"} == {"bar": + "foo"} already was. Use count(x) == 0 to test a collection for + emptiness without asserting its type. Sets are unaffected here: + set[string] describes any set of strings, the empty one + included, so {"foo"} == set() still compiles. + * Rule indexing improvements + The rule indexer now excludes rules from more kinds of + expression, and builds a smaller trie to do it with. See Use + indexed statements for what is indexed. + - startswith, endswith, strings.any_prefix_match and + strings.any_suffix_match are indexed when the base strings + are known at compile time. + - A reference that reads a key out of the object at its ground + prefix in base data + (data.groups.admins.members[input.subject]) is indexed by + asking that object for the key, where such a ruleset used to + leave every rule a candidate. References rooted at a local + variable (x := input; x.foo == "a") are indexed the same as + input.foo == "a", and a chain of assignments no longer drops + the constraint at the end of it. + - A rule's path through the trie stops at the last level it + constrains, and a reference reached by several values no + longer leaves the rest of the rule unindexed. + - Candidates come back in declaration order, which the indexer + documented but did not do. A complete rules must not produce + multiple outputs error now points at the first of the + conflicting definitions rather than the second, and partial + evaluation names and orders the generated locals of its + support rules differently. What a policy evaluates to is + unaffected. + * Changes + - ast: Count a ref once when an index entry replaces its var + entry (#9257) + - ast: Index a lookup into a collection in base data (#9235) + - ast: Index refs rooted at a local variable (#9081) + - ast: Let concrete index values supersede leftover "any" + entries (#9081) + - ast: Number the references an index is built on (#9190) + - ast: Number the refs a rule requires (#9244) + - ast: Number the rules an index holds (#9190) + - ast: Keep refs no rule constrains to a value out of the trie + (#9190) + - ast: Stop a rule index path at its last constrained level + (#9108) + - ast: Walk a rule tree's children in a stable order (#9190) + - docs: Document indexing of refs rooted at a local variable + (#9081) + - index: Also index suffix matching (endswith, + strings.any_suffix_match) + some tweaks (#9164) + - perf: Add startswith and strings.any_prefix_match indexing + (#9161) + - rego: Benchmark index lookups at every match position (#9190) + * Runtime, SDK, Tooling + - compile: don't panic on non-string table/column mappings + (#9241) + - debug: Adding query stack-trace framing mode (#9128) + - dependencies: Include else bodies and unused ref bindings + (#4814) + - download: Fix Trigger() racing a cancelled context into a + false success (#9233) + - download: Fix ignored OCI downloader settings (#9113) + - download: Note that ociTarget.Exists is dead code (#9233) + - download: Resolve OCI bundles behind an image index (#7461) + - download: Stop BundleRequest timer on OCI early returns + (#9233) + - fix: runner.CapturePrintOutput setting never read (#9104) + - format: don't drop comments after an inline if body (#9109) + - metricsexport: Support custom headers on the OTLP exporter + (#9234) + - plugins/logs: Add trace_id, span_id and request_context to + the event AST (#9193) + - plugins/logs: Fix data race on the cached mask and drop + queries (#9189) + - plugins/logs: Make BenchmarkMaskingRuleCountsNop vary the + rule count (#9222) + - plugins/logs: Report upload failures when retrying requeued + chunks (#9186) + - plugins/rest: Remove unused azureSigningAuthPlugin.host field + (#9215) + - repl: Honor DisableUndefinedOutput setting (#9185) + - repl: Recall multi-line statements as one history entry + (#4939) + - rest: Fix SSO cache path written to wrong field (#9233) + - rest: Remove stray debug print in Azure KeyVault signing + (#9233) + - runtime: Only log diagnostic API access at DEBUG (#8419) + - runtime: Reload the config file on change when --watch is set + (#9184) + - runtime: Return the listener error instead of exiting the + process (#9240) + - runtime: Revert config file reload on --watch (#9219) + - server: Build the middleware stack in one place (#9233) + - storage/disk: Split large bundle writes across transactions + (#9202) + - tracing: Add distributed_tracing.exclude_paths (#7494) + - yaml: Reject documents with unreachable content (#6854) + * Compiler, Topdown and Rego + - ast: Avoid pointer escape in GenericTransformer (#9148) + - ast: Build package exports in a single pass (#9162) + - ast: Clear shared output buffer in outputVarsForExprEq + (#8302) + - ast: Clear the term cache when a brace operand guess is + abandoned (#9140) + - ast: Collect a lookup's candidates in a bitset (#9190) + - ast: Emphasize top-most differing types in type errors (#499) + - ast: Fix panic comparing a decimal zero with a non-integral + number (#9098) reported and + - ast: Fix type errors from allowed undefined function calls + (#6946) + - ast: Hint at missing future keyword imports (#4619) + - ast: Mark JSON schema builtins nondeterministic (#8998) + - ast: Only compute template string scopes for rules that have + one (#9248) + - ast: Point object parse errors at the offending token (#6714) + - ast: Report keywords used as rule names (#6652) + - ast: Report violations from multiple compiler stages (#5815) + - ast: Resolve local ref heads in the ground-prefix path too + (#9081) + - ast: Skip the reordered body's output vars where no closure + reads them (#9248) + - ast: Type check the in operator against the collection's + types (#5658) + - ast: Type empty object and array literals by their contents + (#7275) + - ast: don't box a slice header on the way out of Transform + (#9248) + - ast: don't rebuild modules that have nothing to rewrite + (#9248) + - builtins: Reject leading zeroes and empty pre-release/build + in semver built-ins (#9004) + - compiler: HasherMap returned by getExports never used (#9149) + - rego: Fix EvalDisableInlining always being overridden (#9233) + - rego: Pass Time and Seed through Partial() like Eval() does + (#9233) + - rego: don't run leaktest checks in a parallel test (#9176) + - topdown: Add stack traces to evaluation errors (#555) + - topdown: Fix regex cache leak (#9087) reported and + - topdown: Fix sprintf formatting of floats with zero fraction + (#9187) + - topdown: Hoist enumerate callbacks out of the loop (#9147) + - topdown: Iterate known keys and save unknown ones during PE + (#9139) reported and + - topdown: Record evaluated rules during partial evaluation + (#9163) + - wasm: Match topdown semantics in strings.replace_n (#9216) + * Docs, Website, Ecosystem + - docs: Add Evolith to the OPA ecosystem (#9196) + - docs: Address a number of broken links in blog (#9117) + - docs: Address incorrect package name in example (#9250) + - docs: Ecosystem entry for Agent Evidence Admission (#9213) + - docs: Remove word from missed review to #9172 (#9183) + - docs: Report builtin availability in other interpreters + (#8228) + - docs: Update Agent Evidence Admission repo links (#9255) + - docs: Update builtin availability in other interpreters + (#9157) + - docs: Updates to AI guidelines (#9172) + - website: Implement local search based on Pagefind (#9249) + - website: Use new kapa attr to hide AI chat button (#9239) + * Miscellaneous + - ast: Add util.MapKeys helper (#9158) + - ast: Enable more gocritic linters (#9154) + - ast: Enable unparam linter (#9223) + - ast: More niceties, less allocs, less code (#9228) + - ast: Pin BenchmarkObjectConstruction shuffle seed (#9222) + - ast: Update remaining errors.As call sites to use + errors.AsType (#9106) + - ast: Use modern Go in place of custom compare code (#9151) + - ast: Where have all the allocs gone? (#9137) + - build: Add bench-nightly, a three-arm benchlab experiment + runner (#9118) + - build: Pin pigeon in build/tools instead of go run + pkg@version (#9160) + - bundle: Avoid allocation in getdepth (#9199) + - bundle: Remove unused writeModules helper (#9199) + - bundle: Reuse encoder buffer while hashing (#9199) + - bundle: deep-copy bundle data natively instead of via JSON + round-trip (#9199) + - check: Avoid allocating in checkExprEq (#9150) + - ci: Publish benchmark trend on a schedule instead of per-push + (#9119) + - ci: Run the nightly benchlab experiment (#9118) + - cmd: Stop binding a fixed port in the run tests (#9240) + - github: Drop python from the CodeQL language matrix (#9097) + - nightly: Fix go get smoke test (#9245) + - perf: Cheaper custom function calls (#9167) + - perf: Fix linear runtime for Array.set due to rehashing + (#9161) + - perf: General performance improvements in compiler (#9170) + - style: Some more functional niceties (#9152) + - test/e2e: Wait for diagnostic listeners before running tests + (#9134) + - tests: Expanded testing for and/or keywords (#9115) + - topdown: Fix BulkStartsWith benchmark input generation + (#9222) + - topdown: Enable more revive linters (#9181) + - topdown: Fix flaky TestRegexBuiltinCache (#9254) + - topdown: Fix linter issues (#9231) + - util: Add RoundTripFast (#9199) + - plugins/logs: Use util.RoundTripFast for decision-log event + conversion (#9199) + - rego: Use util.RoundTripFast for input parsing (#9199) + - storage: Use util.RoundTripFast for write round-tripping + (#9199) + - util: Decode RoundTrip's fallback into a fresh value (#9206) + - workflows: Check the nightly go-get job for retractions via + the proxy (#9240) ++++ 65 more lines (skipped) ++++ between /work/SRC/openSUSE:Factory/opa/opa.changes ++++ and /work/SRC/openSUSE:Factory/.opa.new.383539/opa.changes Old: ---- opa-1.20.2.obscpio New: ---- opa-1.21.0.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ opa.spec ++++++ --- /var/tmp/diff_new_pack.gLGVtb/_old 2026-09-28 10:40:53.498974321 +0200 +++ /var/tmp/diff_new_pack.gLGVtb/_new 2026-09-28 10:40:53.500974405 +0200 @@ -17,7 +17,7 @@ Name: opa -Version: 1.20.2 +Version: 1.21.0 Release: 0 Summary: Open source, general-purpose policy engine License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.gLGVtb/_old 2026-09-28 10:40:53.531975705 +0200 +++ /var/tmp/diff_new_pack.gLGVtb/_new 2026-09-28 10:40:53.534975830 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/open-policy-agent/opa.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">refs/tags/v1.20.2</param> + <param name="revision">refs/tags/v1.21.0</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> <param name="changesgenerate">enable</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.gLGVtb/_old 2026-09-28 10:40:53.552976585 +0200 +++ /var/tmp/diff_new_pack.gLGVtb/_new 2026-09-28 10:40:53.554976669 +0200 @@ -3,6 +3,6 @@ <param name="url">https://github.com/open-policy-agent/opa</param> <param name="changesrevision">cc2c5c60a4c486f15a5e8de457e96ed0fefaf5fe</param></service><service name="tar_scm"> <param name="url">https://github.com/open-policy-agent/opa.git</param> - <param name="changesrevision">b2c26708e9d55645d7f837db495031f7e4152594</param></service></servicedata> + <param name="changesrevision">dc6269f2c648bbbece4b76fa1fc3dbb7b61cc7b6</param></service></servicedata> (No newline at EOF) ++++++ opa-1.20.2.obscpio -> opa-1.21.0.obscpio ++++++ ++++ 67952 lines of diff (skipped) ++++++ opa.obsinfo ++++++ --- /var/tmp/diff_new_pack.gLGVtb/_old 2026-09-28 10:40:59.577229199 +0200 +++ /var/tmp/diff_new_pack.gLGVtb/_new 2026-09-28 10:40:59.581229367 +0200 @@ -1,5 +1,5 @@ name: opa -version: 1.20.2 -mtime: 1788467714 -commit: b2c26708e9d55645d7f837db495031f7e4152594 +version: 1.21.0 +mtime: 1790255471 +commit: dc6269f2c648bbbece4b76fa1fc3dbb7b61cc7b6 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/opa/vendor.tar.gz /work/SRC/openSUSE:Factory/.opa.new.383539/vendor.tar.gz differ: char 142, line 1
