These changes add support for set values in preparation for rules support. With these changes in place we will be able to compile all rules to wasm. These changes mostly duplicate existing code paths for object values but specialize them for sets. Sets are implemented as sorted lists for now. Set operations are O(n) for now. These changes are not accompanied with end-to-end tests due to partial evaluation. I.e., if set literals are constructed, any test operations like iteration will be unrolled by partial evaluation and since input can only contain JSON values, we don't have a way to fully exercise the set values. Once rules are supported we can improve this. Signed-off-by: Torin Sandall <torinsandall@gmail.com>
OPA-WASM
This directory contains a library that implements various low-level operations for policies compiled into WebAssembly (WASM). Specifically, the library implements:
- JSON parsing
- JSON AST (e.g., comparison, iteration, lookup, etc.)
- String operations
- Memory allocation
This library does not make any backwards compatibility guarantees.
Development
You should have Docker installed to build and test changes to the library. We
commit the output of the build (opa.wasm) into the repository so it's
important for the build output to be reproducible.
You can build the library by running make build. This will produce WASM
executables under the _obj directory.
You can test the library by running make test. By default the test runner
does not print messages when tests pass. If you run make test VERBOSE=1 it
will log all of the tests that were run.
You can run make hack to start a shell inside the builder image. This is
useful if you need to interact with low-level WASM tooling like
wasm-objdump, wasm2wat, etc. or LLVM itself.
You must manually push the builder image if you make changes to it (run make builder to produce a new Docker image).
Vendoring
If you make changes to the library, run the make generate in the parent
directory and commit the results back to the repository. The generate
target will:
- Build the OPA-WASM library
- Copy the library into the internal/compiler/wasm/opa directory.
- Run the tool to generate the internal/compiler/wasm/opa/opa.go file.