Stop emitting import rego.v1 from the scope transpiler
What does this MR do and why?
Stops Gitlab::PolicyStore::ScopeTranspiler from emitting import rego.v1. The line goes from
SCOPE_PRELUDE, from the four committed scope fixtures, and from the README's example output.
Nothing else changes: package gitlab.scope stays, per GOVERN-006.
Regorus 0.11, the engine the Policy Engine runs, enables rego.v1 by default, so the import is a
verified no-op rather than a compatibility guard. That finding is @mcavoj's, linked under References,
and it asks for the line to go from every example, template, and generated program.
This is not quite a cosmetic deletion, which is why it ships on its own rather than folded into
another change. The generated programs use contains and if, the two keywords the import used to
enable, so removing it rests entirely on the default being on. Both were checked against the engine
rather than assumed: every generated program and every fixture compiles with no errors, and the same
checker does report errors for a syntax error or a missing package line, so a clean result means
something.
RuleTranspiler in !249000 (merged) drops the same line
from its own prelude. The two are separate because that MR is still in review, and this change is
worth landing without waiting on it. The remaining occurrence after both is
ee/app/assets/javascripts/policy_store/catalog/rego_templates.js, which needs its own change,
since the template it lives in also exposes matches rather than the violation shape the engine
parses.
How to set up and validate locally
No feature flag or licence: the transpiler is a plain object in the gitlab-policy-store gem, so
every step runs on the rails console.
- Compile a scoped policy and verify the program opens with
package gitlab.scope, a blank line, thenapplicable :=, with no import between them
scoped = Gitlab::PolicyStore::ScopeTranspiler.new(
{ "compliance_frameworks" => [{ "id" => 5 }] }, policy_name: "Framework 5 only"
).transpile
puts scoped.lines.first(3).join
scoped.include?("import")
# => false- Compile an unscoped policy, which takes the other branch of
scope_block, and verify it opens the same way, because the prelude is shared and the import was in it rather than in either branch
puts Gitlab::PolicyStore::ScopeTranspiler.new(nil, policy_name: "Everywhere").transpile.lines.first(3).join- Confirm the opposite path is untouched. Store a hand-written program that does carry the import
and verify it comes back verbatim, because an authored
scope_regois never compiled, so this change cannot reach it
authored = "package gitlab.scope\n\nimport rego.v1\n\nscope_applies := true\n"
policy = Gitlab::PolicyStore.create(
organization_id: 1, name: "Hand written", trigger_type: "deployment_requested", scope_rego: authored
)
policy.scope_rego == authored
# => trueReferences
- The finding this implements, that
import rego.v1is a no-op under the engine we run: https://gitlab.com/gitlab-org/gitlab/-/work_items/607649#note_3677019542 - Raised on !249000 (comment 3677030733), which drops the same line from the rule transpiler (open)
package gitlab.scopeis unchanged, per https://gitlab.com/gitlab-org/architecture/govern/design-doc/-/blob/main/decisions/006-policy-scope-rego-quick-check.md- Epic: https://gitlab.com/groups/gitlab-org/-/epics/22937