| Message ID | 20240903085745.2594893-2-michael@amarulasolutions.com |
|---|---|
| State | New |
| Headers |
Return-Path:
<linux-amarula+bncBCXK73FY3AFRBEE73O3AMGQEA262FII@amarulasolutions.com>
X-Original-To: linux-amarula@patchwork.amarulasolutions.com
Delivered-To: linux-amarula@patchwork.amarulasolutions.com
Received: from mail-lj1-f197.google.com (mail-lj1-f197.google.com
[209.85.208.197])
by ganimede.amarulasolutions.com (Postfix) with ESMTPS id 59B0D3F228
for <linux-amarula@patchwork.amarulasolutions.com>;
Tue, 3 Sep 2024 10:57:53 +0200 (CEST)
Received: by mail-lj1-f197.google.com with SMTP id
38308e7fff4ca-2f515891a64sf48572771fa.2
for <linux-amarula@patchwork.amarulasolutions.com>;
Tue, 03 Sep 2024 01:57:53 -0700 (PDT)
ARC-Seal: i=2; a=rsa-sha256; t=1725353873; cv=pass;
d=google.com; s=arc-20240605;
b=NPIQrkSOPRxaBnvyVivFOmxYvtY21TlFj3fk9WKrkifbOC5jUWLF0CHFR03A0dHCTq
Lx2JKJ+V2+FcMFt4ZH27XVqm4XAuNkRhbkxCsSWidq29vx1jT735Zf8rEQ2T330VieLJ
iBJiJ3kQ3fOPYMIUURfGe0ZWjeMO6f1C/xGBsgqI96cR7ItdDaGW2URiLNvh6MCM2BTr
c9X+iaeBSvuvIEVVaB6tRAI2rc9pTEyG4HQeFEW8KWBBr5hm3KdO1oGG4iCsbKZj12YO
fD9xRjjxuWup/8Uw4g0QCZXYrkK9Uh5bnq3Mp2DgbEq9zezODSarqDPlpK9toTONO6TH
zPmg==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20240605;
h=list-unsubscribe:list-archive:list-help:list-post:list-id
:mailing-list:precedence:mime-version:references:in-reply-to
:message-id:date:subject:cc:to:from:dkim-signature;
bh=jQdc8/npVdo5yvyh6ZGZEkge/fW/SS8rNfI9hBU44eI=;
fh=EbhNGqucF1ame+MhKUJ7jviRk4FQaXyqo+D3sc4fH3Y=;
b=kumf+8Y9pkgqcPstY6ppfZE+G7FPdx2yBvxSJ2j0ZORvpbT7KBCLNE5F+IPErGPpNq
JOZvoW/yWR71/Kx8TlY2xUYQGxtqFU8K/92OijRy1A2NfI2EKO317/gsdN2CX2YvdLIw
hkX9AADBTnOoBdH2K7EwxanbxdcmRBqefKhRwbIlfkHPbNlfMJGb5HORNiZK3LQ7g50w
bRk+yTvN1kbZ2flPHHcYk14Wj57eVE0M6OEtzm1yiyXdizdsMIUYz6/UymuAWXoQ/hvv
gWGnr7ezTtdkg299ki75g4W+nEHuylPk3qchez6ikwaPQq00AVJXx+fAVNz+CzluFg9F
MXbg==;
darn=patchwork.amarulasolutions.com
ARC-Authentication-Results: i=2; mx.google.com;
dkim=pass header.i=@amarulasolutions.com header.s=google
header.b=L9eawMVI;
spf=pass (google.com: domain of michael@amarulasolutions.com designates
209.85.220.41 as permitted sender)
smtp.mailfrom=michael@amarulasolutions.com;
dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=amarulasolutions.com;
dara=pass header.i=@amarulasolutions.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=amarulasolutions.com; s=google; t=1725353872; x=1725958672;
darn=patchwork.amarulasolutions.com;
h=list-unsubscribe:list-archive:list-help:list-post:list-id
:mailing-list:precedence:x-original-authentication-results
:x-original-sender:mime-version:references:in-reply-to:message-id
:date:subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to;
bh=jQdc8/npVdo5yvyh6ZGZEkge/fW/SS8rNfI9hBU44eI=;
b=l/EEwLSafpr1c3OoP5LPsdGFSHa9dmz08bf1rO95dhdwN8N9LyMaFz+9J1F8nGie0p
ThFWntYwE7MQ54xFqc32r0GqNa7R0M837oHrSW7e6N5P1CbIF1PvdGNBPO3PspafLiDv
k2WbnlMWGFrDcls1gQJxA9uuO/I4X+R48Xmlk=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1725353872; x=1725958672;
h=list-unsubscribe:list-archive:list-help:list-post
:x-spam-checked-in-group:list-id:mailing-list:precedence
:x-original-authentication-results:x-original-sender:mime-version
:references:in-reply-to:message-id:date:subject:cc:to:from
:x-beenthere:x-gm-message-state:from:to:cc:subject:date:message-id
:reply-to;
bh=jQdc8/npVdo5yvyh6ZGZEkge/fW/SS8rNfI9hBU44eI=;
b=F+REDWUIXgkLN9JZhyofWTASWMr+1QfbNrmhma0q26oOXbmfrkUfya8fiAdX9i9DUS
GyrNdPE5mvFTX9nbMSM//P8bv6+gcSptdjADGQhWG1Y+LLRc1Xo+0tE/t/ATjJeVTLot
U6tl2V7+12ZLoJ+aj3+VYtF7SWbfgUNHUFWD8xzuhAvRWsS4YNJlv0l9fiJQHkZGlipS
lB3XkDRQBaTcV6866+62VPCu2UR0NCQ/uYHgHjRYbqXWFUbu66VN4JcT4YOzeQXseYYC
TwpnqovFQ9YB8IHTrfKPvx+8KbLp6cQZ1/Png1B4oOG1Y184km8jQ01rcFpikQTJkZ3T
LrFA==
X-Forwarded-Encrypted: i=2;
AJvYcCW3/3oSru+qNnNdVVW4/EyCqw1MeBzsOl1CHylhPaDr+9LVwb4R/IMrq/3FZpJw9uKlXhtOGPNRlZm7qEMl@patchwork.amarulasolutions.com
X-Gm-Message-State: AOJu0Yxbu/x7T1LGiL0x6gWmKUdiNhE55iGgXTDbHQf1WUsiCczsrMDk
fakPlZ1wOJbNNmqDIK7ukiN92KqzcgRcoVgWDp2e4HxPI7yUWHgeoSoUCsby7e6rbA==
X-Google-Smtp-Source:
AGHT+IGRaYzPkZ/l0k9K+EA1+V+bMn17Q8TXoRiA+tGGOJS88BazmBl5SghljZXli1AkuY+vtyVwAw==
X-Received: by 2002:a2e:a781:0:b0:2f1:a19b:d5a4 with SMTP id
38308e7fff4ca-2f636a2b8f9mr33344161fa.22.1725353872499;
Tue, 03 Sep 2024 01:57:52 -0700 (PDT)
X-BeenThere: linux-amarula@amarulasolutions.com
Received: by 2002:a05:6402:40c1:b0:5c2:61a7:62df with SMTP id
4fb4d7f45d1cf-5c261a76a38ls379450a12.0.-pod-prod-01-eu; Tue, 03 Sep 2024
01:57:51 -0700 (PDT)
X-Received: by 2002:a05:6402:d06:b0:5c2:6bf7:8531 with SMTP id
4fb4d7f45d1cf-5c26bf78562mr1282281a12.33.1725353870590;
Tue, 03 Sep 2024 01:57:50 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1725353870; cv=none;
d=google.com; s=arc-20160816;
b=n7T2xzMsFQalNrl+T8X0ynJRBRnf0jbcov9Y2q+AwjFGw9AoxrQXWYjwVdk1nBvSwz
SjahvQgzzblPW6/E9Now3bjs2QIeAyA5CrTtVBdkOMBMG/8ZDRSCsGyiNOfpq4KFyTTN
T5n2lOnD64IEH3rWN1JBqP2gJABCO+U8ZurhbH8eadx3UXH4cMUK1F99WLvTHtlT1RI2
v9WK8K1JK/mAzSQ2OhfcpA4Q14NzyxRDDn45QjdB0kL8IXfle9lFkHda3px/922D9t6C
AOPSb1cP7vzt8kdp2jICAXWFp0tgFhhdab6oNM+l/zJIUMaNHn2LkkjZC1ckx5aKBWUp
bIPw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20160816;
h=content-transfer-encoding:mime-version:references:in-reply-to
:message-id:date:subject:cc:to:from:dkim-signature;
bh=Z/tdhvFiWdgaMAbB6/frfY7NgEMt1w255SEMEObrNH8=;
fh=tFw5bWiU1jBH/a1ncq8wme8lpRu4N+XMJNVYG1SrYIo=;
b=WjjRwrzuTLjNhNUA3AaeHs2rwxcTVZPiOr8ePNLW5i4aTIpoC0YCYfzKZ7aibhiwKH
nS8mWL4In98rJYL6mDyiqRvG+kdvSy6wTKJ/TF0SXumdFnxXoxwu4E1R9nEQD02RNI7c
nvwmKyAMkuqSAIerrQkYfKVW8/c7jn3reNAHq80I7ubfbH0i7KwOZb2QGyQmibgmzDLK
jrUNCGoNfuGLWv8I6qRCm74ju85fSGWvgrCaXuqmjkywkcenjV5JE4gqBCAdc7NzUNz6
8Rjy6E2SNmUb72nf0tiSN7SVv+zuC8PM9ji3ORa3J6Mv9ey/iU7bmbd4qtAs/z1IqHs+
Vbag==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@amarulasolutions.com header.s=google
header.b=L9eawMVI;
spf=pass (google.com: domain of michael@amarulasolutions.com designates
209.85.220.41 as permitted sender)
smtp.mailfrom=michael@amarulasolutions.com;
dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=amarulasolutions.com;
dara=pass header.i=@amarulasolutions.com
Received: from mail-sor-f41.google.com (mail-sor-f41.google.com.
[209.85.220.41])
by mx.google.com with SMTPS id
4fb4d7f45d1cf-5c25254cfd3sor820024a12.2.2024.09.03.01.57.50
for <linux-amarula@amarulasolutions.com>
(Google Transport Security);
Tue, 03 Sep 2024 01:57:50 -0700 (PDT)
Received-SPF: pass (google.com: domain of michael@amarulasolutions.com
designates 209.85.220.41 as permitted sender) client-ip=209.85.220.41;
X-Received: by 2002:a05:6402:26c5:b0:5c2:4740:939d with SMTP id
4fb4d7f45d1cf-5c25c4034bamr4762882a12.26.1725353869700;
Tue, 03 Sep 2024 01:57:49 -0700 (PDT)
Received: from panicking.amarulasolutions.com
(93-35-133-65.ip55.fastwebnet.it. [93.35.133.65])
by smtp.gmail.com with ESMTPSA id
4fb4d7f45d1cf-5c226ccfeacsm6204487a12.78.2024.09.03.01.57.48
(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
Tue, 03 Sep 2024 01:57:49 -0700 (PDT)
From: Michael Trimarchi <michael@amarulasolutions.com>
To: buildroot@buildroot.org
Cc: linux-amarula@amarulasolutions.com,
Michael Trimarchi <michael@amarulasolutions.com>
Subject: [PATCH V2 2/2] scripts/cve: Restart the clone if the pull generate an
exception
Date: Tue, 3 Sep 2024 10:57:45 +0200
Message-ID: <20240903085745.2594893-2-michael@amarulasolutions.com>
X-Mailer: git-send-email 2.43.0
In-Reply-To: <20240903085745.2594893-1-michael@amarulasolutions.com>
References: <20240903085745.2594893-1-michael@amarulasolutions.com>
MIME-Version: 1.0
X-Original-Sender: michael@amarulasolutions.com
X-Original-Authentication-Results: mx.google.com; dkim=pass
header.i=@amarulasolutions.com header.s=google header.b=L9eawMVI;
spf=pass (google.com: domain of michael@amarulasolutions.com designates
209.85.220.41 as permitted sender)
smtp.mailfrom=michael@amarulasolutions.com;
dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=amarulasolutions.com;
dara=pass header.i=@amarulasolutions.com
Content-Type: text/plain; charset="UTF-8"
Precedence: list
Mailing-list: list linux-amarula@amarulasolutions.com;
contact linux-amarula+owners@amarulasolutions.com
List-ID: <linux-amarula.amarulasolutions.com>
X-Spam-Checked-In-Group: linux-amarula@amarulasolutions.com
X-Google-Group-Id: 476853432473
List-Post:
<https://groups.google.com/a/amarulasolutions.com/group/linux-amarula/post>,
<mailto:linux-amarula@amarulasolutions.com>
List-Help:
<https://support.google.com/a/amarulasolutions.com/bin/topic.py?topic=25838>,
<mailto:linux-amarula+help@amarulasolutions.com>
List-Archive:
<https://groups.google.com/a/amarulasolutions.com/group/linux-amarula/>
List-Unsubscribe:
<mailto:googlegroups-manage+476853432473+unsubscribe@googlegroups.com>,
<https://groups.google.com/a/amarulasolutions.com/group/linux-amarula/subscribe>
|
| Series |
[V2,1/2] scripts/cve: Avoid to do a complete clone of cve git repository
|
|
Commit Message
Michael Trimarchi
Sept. 3, 2024, 8:57 a.m. UTC
If we are not able to pull from the directory, restart from a clean
clone. This can happen for corrupt repository or unfinished download
Signed-off-by: Michael Trimarchi <michael@amarulasolutions.com>
---
V1->V2: Adjust the commit message
---
support/scripts/cve.py | 21 ++++++++++++++-------
1 file changed, 14 insertions(+), 7 deletions(-)
Comments
On Tue, 3 Sep 2024 10:57:45 +0200 Michael Trimarchi <michael@amarulasolutions.com> wrote: > diff --git a/support/scripts/cve.py b/support/scripts/cve.py > index dcb3a63925..6cd9aab963 100755 > --- a/support/scripts/cve.py > +++ b/support/scripts/cve.py > @@ -21,6 +21,7 @@ import datetime > import os > import distutils.version > import json > +import shutil > import subprocess > import sys > import operator > @@ -69,15 +70,21 @@ class CVE: > > @staticmethod > def download_nvd(nvd_git_dir): > + done = False > print(f"Updating from {NVD_BASE_URL}") > if os.path.exists(nvd_git_dir): > - subprocess.check_call( > - ["git", "pull", "--depth", "1"], > - cwd=nvd_git_dir, > - stdout=subprocess.DEVNULL, > - stderr=subprocess.DEVNULL, > - ) > - else: > + try: > + subprocess.check_call( > + ["git", "pull", "--depth", "1"], > + cwd=nvd_git_dir, > + stdout=subprocess.DEVNULL, > + stderr=subprocess.DEVNULL, > + ) > + done = True > + except: > + shutil.rmtree(nvd_git_dir) The thing I'm worried about is that you can also get a failure of "git pull" for example due to a network timeout or something like that, which doesn't need a full git clone, but just a "try again" later... and now we're going to wipe out the entire local clone, and try to clone everything again. Is that a good idea? Also, perhaps we need to show an error message if the "git pull" failed, and saying we're falling back to a full clone, or something? > + if (not done): if not done: is sufficient, we are not writing C code here :-) Thanks! Thomas
Hi Thomas On Tue, Sep 3, 2024 at 8:52 PM Thomas Petazzoni <thomas.petazzoni@bootlin.com> wrote: > > On Tue, 3 Sep 2024 10:57:45 +0200 > Michael Trimarchi <michael@amarulasolutions.com> wrote: > > > diff --git a/support/scripts/cve.py b/support/scripts/cve.py > > index dcb3a63925..6cd9aab963 100755 > > --- a/support/scripts/cve.py > > +++ b/support/scripts/cve.py > > @@ -21,6 +21,7 @@ import datetime > > import os > > import distutils.version > > import json > > +import shutil > > import subprocess > > import sys > > import operator > > @@ -69,15 +70,21 @@ class CVE: > > > > @staticmethod > > def download_nvd(nvd_git_dir): > > + done = False > > print(f"Updating from {NVD_BASE_URL}") > > if os.path.exists(nvd_git_dir): > > - subprocess.check_call( > > - ["git", "pull", "--depth", "1"], > > - cwd=nvd_git_dir, > > - stdout=subprocess.DEVNULL, > > - stderr=subprocess.DEVNULL, > > - ) > > - else: > > + try: > > + subprocess.check_call( > > + ["git", "pull", "--depth", "1"], > > + cwd=nvd_git_dir, > > + stdout=subprocess.DEVNULL, > > + stderr=subprocess.DEVNULL, > > + ) > > + done = True > > + except: > > + shutil.rmtree(nvd_git_dir) > > The thing I'm worried about is that you can also get a failure of "git > pull" for example due to a network timeout or something like that, > which doesn't need a full git clone, but just a "try again" later... > and now we're going to wipe out the entire local clone, and try to > clone everything again. Is that a good idea? > > Also, perhaps we need to show an error message if the "git pull" > failed, and saying we're falling back to a full clone, or something? > > > + if (not done): > > if not done: > > > is sufficient, we are not writing C code here :-) Sorry, I will ask my colleague to write python and send a better strategy. I totally agree with you. Anyway I have a plan to add more information on cve reporting, hope that you like the idea. Mostly I'm playing with parser for jenkins and love to add buildroot too but I don't have enough information to show https://github.com/jenkinsci/analysis-model/pull/1085 Michael > > Thanks! > > Thomas > -- > Thomas Petazzoni, co-owner and CEO, Bootlin > Embedded Linux and Kernel engineering and training > https://bootlin.com
diff --git a/support/scripts/cve.py b/support/scripts/cve.py index dcb3a63925..6cd9aab963 100755 --- a/support/scripts/cve.py +++ b/support/scripts/cve.py @@ -21,6 +21,7 @@ import datetime import os import distutils.version import json +import shutil import subprocess import sys import operator @@ -69,15 +70,21 @@ class CVE: @staticmethod def download_nvd(nvd_git_dir): + done = False print(f"Updating from {NVD_BASE_URL}") if os.path.exists(nvd_git_dir): - subprocess.check_call( - ["git", "pull", "--depth", "1"], - cwd=nvd_git_dir, - stdout=subprocess.DEVNULL, - stderr=subprocess.DEVNULL, - ) - else: + try: + subprocess.check_call( + ["git", "pull", "--depth", "1"], + cwd=nvd_git_dir, + stdout=subprocess.DEVNULL, + stderr=subprocess.DEVNULL, + ) + done = True + except: + shutil.rmtree(nvd_git_dir) + + if (not done): # Create the directory and its parents; git # happily clones into an empty directory. os.makedirs(nvd_git_dir)