Stop emitting import rego.v1 from the scope transpiler

What does this MR do and why?

Stops Gitlab::PolicyStore::ScopeTranspiler from emitting import rego.v1. The line goes from SCOPE_PRELUDE, from the four committed scope fixtures, and from the README's example output. Nothing else changes: package gitlab.scope stays, per GOVERN-006.

Regorus 0.11, the engine the Policy Engine runs, enables rego.v1 by default, so the import is a verified no-op rather than a compatibility guard. That finding is @mcavoj's, linked under References, and it asks for the line to go from every example, template, and generated program.

This is not quite a cosmetic deletion, which is why it ships on its own rather than folded into another change. The generated programs use contains and if, the two keywords the import used to enable, so removing it rests entirely on the default being on. Both were checked against the engine rather than assumed: every generated program and every fixture compiles with no errors, and the same checker does report errors for a syntax error or a missing package line, so a clean result means something.

RuleTranspiler in !249000 (merged) drops the same line from its own prelude. The two are separate because that MR is still in review, and this change is worth landing without waiting on it. The remaining occurrence after both is ee/app/assets/javascripts/policy_store/catalog/rego_templates.js, which needs its own change, since the template it lives in also exposes matches rather than the violation shape the engine parses.

How to set up and validate locally

No feature flag or licence: the transpiler is a plain object in the gitlab-policy-store gem, so every step runs on the rails console.

  1. Compile a scoped policy and verify the program opens with package gitlab.scope, a blank line, then applicable :=, with no import between them
scoped = Gitlab::PolicyStore::ScopeTranspiler.new(
  { "compliance_frameworks" => [{ "id" => 5 }] }, policy_name: "Framework 5 only"
).transpile

puts scoped.lines.first(3).join
scoped.include?("import")
# => false
  1. Compile an unscoped policy, which takes the other branch of scope_block, and verify it opens the same way, because the prelude is shared and the import was in it rather than in either branch
puts Gitlab::PolicyStore::ScopeTranspiler.new(nil, policy_name: "Everywhere").transpile.lines.first(3).join
  1. Confirm the opposite path is untouched. Store a hand-written program that does carry the import and verify it comes back verbatim, because an authored scope_rego is never compiled, so this change cannot reach it
authored = "package gitlab.scope\n\nimport rego.v1\n\nscope_applies := true\n"

policy = Gitlab::PolicyStore.create(
  organization_id: 1, name: "Hand written", trigger_type: "deployment_requested", scope_rego: authored
)

policy.scope_rego == authored
# => true

References

Edited by Marcos Rocha

Merge request reports

Loading
Loading