Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
G
gitlab-ce
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
1
Merge Requests
1
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
nexedi
gitlab-ce
Commits
80bd717a
Commit
80bd717a
authored
Mar 06, 2020
by
Can Eldem
Committed by
Mayra Cabrera
Mar 06, 2020
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Move file under ee folder make it no-op for general operation
Remove index for undoing migration
parent
c864834c
Changes
7
Hide whitespace changes
Inline
Side-by-side
Showing
7 changed files
with
251 additions
and
0 deletions
+251
-0
changelogs/unreleased/replace-undefined-with-unknown.yml
changelogs/unreleased/replace-undefined-with-unknown.yml
+5
-0
db/post_migrate/20200227140242_update_occurrence_severity_column.rb
...grate/20200227140242_update_occurrence_severity_column.rb
+34
-0
db/schema.rb
db/schema.rb
+1
-0
ee/lib/ee/gitlab/background_migration/remove_undefined_occurrence_severity_level.rb
...d_migration/remove_undefined_occurrence_severity_level.rb
+35
-0
ee/spec/lib/ee/gitlab/background_migration/remove_undefined_occurrence_severity_level_spec.rb
...ration/remove_undefined_occurrence_severity_level_spec.rb
+54
-0
ee/spec/migrations/update_occurrence_severity_column_spec.rb
ee/spec/migrations/update_occurrence_severity_column_spec.rb
+109
-0
lib/gitlab/background_migration/remove_undefined_occurrence_severity_level.rb
...d_migration/remove_undefined_occurrence_severity_level.rb
+13
-0
No files found.
changelogs/unreleased/replace-undefined-with-unknown.yml
0 → 100644
View file @
80bd717a
---
title
:
Replace undefined severity with unknown severity for occurrences
merge_request
:
26085
author
:
type
:
other
db/post_migrate/20200227140242_update_occurrence_severity_column.rb
0 → 100644
View file @
80bd717a
# frozen_string_literal: true
class
UpdateOccurrenceSeverityColumn
<
ActiveRecord
::
Migration
[
6.0
]
include
Gitlab
::
Database
::
MigrationHelpers
DOWNTIME
=
false
disable_ddl_transaction!
BATCH_SIZE
=
1_000
INTERVAL
=
5
.
minutes
# 23_044 records to be updated on GitLab.com,
def
up
# create temporary index for undefined vulnerabilities
add_concurrent_index
(
:vulnerability_occurrences
,
:id
,
where:
'severity = 0'
,
name:
'undefined_vulnerabilities'
)
return
unless
Gitlab
.
ee?
migration
=
Gitlab
::
BackgroundMigration
::
RemoveUndefinedOccurrenceSeverityLevel
migration_name
=
migration
.
to_s
.
demodulize
relation
=
migration
::
Occurrence
.
undefined_severity
queue_background_migration_jobs_by_range_at_intervals
(
relation
,
migration_name
,
INTERVAL
,
batch_size:
BATCH_SIZE
)
end
def
down
# no-op
# temporary index is to be dropped in a different migration in an upcoming release
remove_concurrent_index
(
:vulnerability_occurrences
,
:id
,
where:
'severity = 0'
,
name:
'undefined_vulnerabilities'
)
# This migration can not be reversed because we can not know which records had undefined severity
end
end
db/schema.rb
View file @
80bd717a
...
...
@@ -4502,6 +4502,7 @@ ActiveRecord::Schema.define(version: 2020_03_04_160823) do
t
.
string
"metadata_version"
,
null:
false
t
.
text
"raw_metadata"
,
null:
false
t
.
bigint
"vulnerability_id"
t
.
index
[
"id"
],
name:
"undefined_vulnerabilities"
,
where:
"(severity = 0)"
t
.
index
[
"primary_identifier_id"
],
name:
"index_vulnerability_occurrences_on_primary_identifier_id"
t
.
index
[
"project_id"
,
"primary_identifier_id"
,
"location_fingerprint"
,
"scanner_id"
],
name:
"index_vulnerability_occurrences_on_unique_keys"
,
unique:
true
t
.
index
[
"scanner_id"
],
name:
"index_vulnerability_occurrences_on_scanner_id"
...
...
ee/lib/ee/gitlab/background_migration/remove_undefined_occurrence_severity_level.rb
0 → 100644
View file @
80bd717a
# frozen_string_literal: true
module
EE
module
Gitlab
module
BackgroundMigration
module
RemoveUndefinedOccurrenceSeverityLevel
extend
::
Gitlab
::
Utils
::
Override
class
Occurrence
<
ActiveRecord
::
Base
include
::
EachBatch
self
.
table_name
=
'vulnerability_occurrences'
SEVERITY_LEVELS
=
{
undefined:
0
,
unknown:
2
}.
with_indifferent_access
.
freeze
enum
severity:
SEVERITY_LEVELS
def
self
.
undefined_severity
where
(
severity:
Occurrence
.
severities
[
:undefined
])
end
end
override
:perform
def
perform
(
start_id
,
stop_id
)
Occurrence
.
undefined_severity
.
where
(
id:
start_id
..
stop_id
)
.
update_all
(
severity:
Occurrence
.
severities
[
:unknown
])
end
end
end
end
end
ee/spec/lib/ee/gitlab/background_migration/remove_undefined_occurrence_severity_level_spec.rb
0 → 100644
View file @
80bd717a
# frozen_string_literal: true
require
'spec_helper'
describe
Gitlab
::
BackgroundMigration
::
RemoveUndefinedOccurrenceSeverityLevel
,
:migration
,
schema:
20200227140242
do
let
(
:vulnerabilities
)
{
table
(
:vulnerability_occurrences
)
}
let
(
:identifiers
)
{
table
(
:vulnerability_identifiers
)
}
let
(
:scanners
)
{
table
(
:vulnerability_scanners
)
}
let
(
:projects
)
{
table
(
:projects
)
}
it
'updates undefined severity level to unknown'
do
projects
.
create!
(
id:
123
,
namespace_id:
12
,
name:
'gitlab'
,
path:
'gitlab'
)
(
1
..
3
).
to_a
.
each
do
|
identifier_id
|
identifiers
.
create!
(
id:
identifier_id
,
project_id:
123
,
fingerprint:
'd432c2ad2953e8bd587a3a43b3ce309b5b0154c'
+
identifier_id
.
to_s
,
external_type:
'SECURITY_ID'
,
external_id:
'SECURITY_0'
,
name:
'SECURITY_IDENTIFIER 0'
)
end
scanners
.
create!
(
id:
6
,
project_id:
123
,
external_id:
'clair'
,
name:
'Security Scanner'
)
vul1
=
vulnerabilities
.
create!
(
vuln_params
(
1
))
vulnerabilities
.
create!
(
vuln_params
(
2
))
vul3
=
vulnerabilities
.
create!
(
vuln_params
(
3
).
merge
(
severity:
2
))
expect
(
vulnerabilities
.
where
(
severity:
2
).
count
).
to
eq
(
1
)
described_class
.
new
.
perform
(
vul1
.
id
,
vul3
.
id
)
expect
(
vulnerabilities
.
where
(
severity:
2
).
count
).
to
eq
(
3
)
end
def
vuln_params
(
primary_identifier_id
)
attrs
=
attributes_for
(
:vulnerabilities_occurrence
)
{
severity:
0
,
confidence:
5
,
report_type:
2
,
project_id:
123
,
scanner_id:
6
,
primary_identifier_id:
primary_identifier_id
,
project_fingerprint:
attrs
[
:project_fingerprint
],
location_fingerprint:
attrs
[
:location_fingerprint
],
uuid:
attrs
[
:uuid
],
name:
attrs
[
:name
],
metadata_version:
'1.3'
,
raw_metadata:
attrs
[
:raw_metadata
]
}
end
end
ee/spec/migrations/update_occurrence_severity_column_spec.rb
0 → 100644
View file @
80bd717a
# frozen_string_literal: true
require
'spec_helper'
require
Rails
.
root
.
join
(
'db'
,
'post_migrate'
,
'20200227140242_update_occurrence_severity_column.rb'
)
describe
UpdateOccurrenceSeverityColumn
,
:migration
do
let
(
:vulnerabilities
)
{
table
(
:vulnerability_occurrences
)
}
let
(
:identifiers
)
{
table
(
:vulnerability_identifiers
)
}
let
(
:scanners
)
{
table
(
:vulnerability_scanners
)
}
let
(
:projects
)
{
table
(
:projects
)
}
let
(
:vul1
)
{
attributes_for
(
:vulnerabilities_occurrence
,
id:
1
,
report_type:
2
,
confidence:
5
)
}
let
(
:vul2
)
{
attributes_for
(
:vulnerabilities_occurrence
,
id:
2
,
report_type:
2
,
confidence:
5
)
}
before
do
stub_const
(
"
#{
described_class
}
::BATCH_SIZE"
,
2
)
end
it
'updates confidence levels for container scanning reports'
,
:sidekiq_might_not_need_inline
do
allow_any_instance_of
(
Gitlab
).
to
receive
(
:ee?
).
and_return
(
true
)
projects
.
create!
(
id:
123
,
namespace_id:
12
,
name:
'gitlab'
,
path:
'gitlab'
)
identifiers
.
create!
(
id:
1
,
project_id:
123
,
fingerprint:
'd432c2ad2953e8bd587a3a43b3ce309b5b0154c2'
,
external_type:
'SECURITY_ID'
,
external_id:
'SECURITY_0'
,
name:
'SECURITY_IDENTIFIER 0'
)
identifiers
.
create!
(
id:
2
,
project_id:
123
,
fingerprint:
'd432c2ad2953e8bd587a3a43b3ce309b5b0154c3'
,
external_type:
'SECURITY_ID'
,
external_id:
'SECURITY_0'
,
name:
'SECURITY_IDENTIFIER 0'
)
scanners
.
create!
(
id:
6
,
project_id:
123
,
external_id:
'clair'
,
name:
'Security Scanner'
)
vulnerabilities
.
create!
(
id:
vul1
[
:id
],
severity:
0
,
confidence:
5
,
report_type:
2
,
project_id:
123
,
scanner_id:
6
,
primary_identifier_id:
1
,
project_fingerprint:
vul1
[
:project_fingerprint
],
location_fingerprint:
vul1
[
:location_fingerprint
],
uuid:
vul1
[
:uuid
],
name:
vul1
[
:name
],
metadata_version:
'1.3'
,
raw_metadata:
vul1
[
:raw_metadata
])
vulnerabilities
.
create!
(
id:
vul2
[
:id
],
severity:
2
,
confidence:
5
,
report_type:
2
,
project_id:
123
,
scanner_id:
6
,
primary_identifier_id:
2
,
project_fingerprint:
vul2
[
:project_fingerprint
],
location_fingerprint:
vul2
[
:location_fingerprint
],
uuid:
vul2
[
:uuid
],
name:
vul2
[
:name
],
metadata_version:
'1.3'
,
raw_metadata:
vul2
[
:raw_metadata
])
expect
(
vulnerabilities
.
where
(
severity:
0
).
count
).
to
eq
(
1
)
migrate!
expect
(
vulnerabilities
.
exists?
(
severity:
0
)).
to
be_falsy
end
it
'skips migration for ce'
do
allow_any_instance_of
(
Gitlab
).
to
receive
(
:ee?
).
and_return
(
false
)
projects
.
create!
(
id:
123
,
namespace_id:
12
,
name:
'gitlab'
,
path:
'gitlab'
)
identifiers
.
create!
(
id:
1
,
project_id:
123
,
fingerprint:
'd432c2ad2953e8bd587a3a43b3ce309b5b0154c2'
,
external_type:
'SECURITY_ID'
,
external_id:
'SECURITY_0'
,
name:
'SECURITY_IDENTIFIER 0'
)
scanners
.
create!
(
id:
6
,
project_id:
123
,
external_id:
'clair'
,
name:
'Security Scanner'
)
vulnerabilities
.
create!
(
id:
vul1
[
:id
],
severity:
0
,
confidence:
5
,
report_type:
2
,
project_id:
123
,
scanner_id:
6
,
primary_identifier_id:
1
,
project_fingerprint:
vul1
[
:project_fingerprint
],
location_fingerprint:
vul1
[
:location_fingerprint
],
uuid:
vul1
[
:uuid
],
name:
vul1
[
:name
],
metadata_version:
'1.3'
,
raw_metadata:
vul1
[
:raw_metadata
])
expect
(
vulnerabilities
.
where
(
severity:
0
).
count
).
to
eq
(
1
)
migrate!
expect
(
vulnerabilities
.
exists?
(
severity:
0
)).
to
be_truthy
end
end
lib/gitlab/background_migration/remove_undefined_occurrence_severity_level.rb
0 → 100644
View file @
80bd717a
# frozen_string_literal: true
# rubocop:disable Style/Documentation
module
Gitlab
module
BackgroundMigration
class
RemoveUndefinedOccurrenceSeverityLevel
def
perform
(
start_id
,
stop_id
)
end
end
end
end
Gitlab
::
BackgroundMigration
::
RemoveUndefinedOccurrenceSeverityLevel
.
prepend_if_ee
(
'EE::Gitlab::BackgroundMigration::RemoveUndefinedOccurrenceSeverityLevel'
)
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment