Skip to content

Newest OPA v1.21.0 breaks ScubaGear (Don't update our pinned version before we make some changes)聽#2440

Description

@buidav

Prerequisites

  • This issue has an informative and human-readable title.

ScubaGear Version

Almost v2.0.0

Operating System

Windows 11

PowerShell Version

5.1

M365 Environment and License(s)

N/A

馃悰 Summary

The latest automated OPA version bump PR to OPA v1.21.0 had it's smoke test fail. This version introduced some changes that broke ScubaGear.

Notably this one in their release notes.


Image

In the smoke test. This file is pointed to as the culprit with a similar exception described in those release notes ScubaGear\PowerShell\ScubaGear\Rego\Utils\TestAssertions.rego:206 : rego_type_error: undefined ref: [***[0***

Image

Tracing the error back to file indicated there. The culprit seems to be this Fail function in the Rego utils.

Image

This is NOT one of the functions we created. The original file appears to be a lift and shift from this repo originally (one of the OPA maintainers). We do use some of the functions in this file but I don't think we use this Fail function specifically.


# METADATA
# description: Fail with provided message
Fail(msg) := [][0] if {
    # regal ignore: print-or-trace-call
    print(msg)
}

This is essentially a hack function to throw an exception in OPA at any time.
It trying to take the 0th index of an empty array which will fail. But before it happens it prints the message in the body.

The new changes in OPA v1.21.0 catch this error at "compile time" now instead of "run time" causing an exception when ScubaGear first invokes the OPA executable.

Fix should be just to remove this function as we don't seem to be using it. But, since they made other breaking changes in this release.
There are 2 issues that have surfaced now from updating.
Test thoroughly before bumping the version and fix anything that pops up.

Update


Image The unit tests action (and local) is breaking as well.
Rules := {
    "SSN": [Rule.Name | some Rule in SensitiveRules; SensitiveContent[0] in Rule.ContentNames], # This line is causing the unsafe error.
    "ITIN": [Rule.Name | some Rule in SensitiveRules; SensitiveContent[1] in Rule.ContentNames],
    "Credit_Card": [Rule.Name | some Rule in SensitiveRules; SensitiveContent[2] in Rule.ContentNames]
}

Similar case. If Rule.ContentNames is an empty array SensitiveContent[0] would throw an exception.
OPA doesn't like that.

Steps to reproduce

  1. Update ScubaGear's pinned OPA version to v1.21.0. This requires manually downloading it or updating the Pinned OPA in the ScubaGearConfigDefaults.
  2. Attempt to run ScubaGear

Expected behavior

For ScubaGear not to crash.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugThis issue or pull request addresses broken functionality

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions