advisory-scan: derive windows from a compose diff (--compose-to)
Typing --from/--to/--image by hand means someone has to remember the recipe also
bumped its redis. That is how sidecar CVEs went uncounted for months. Point this
at a PR's compose.yml and it reads the windows off the diff instead.
advisory-scan.py plausible --compose-to <.../branch/<pr>/compose.yml>
-> community-edition: v2.0.0 -> v3.2.1
-> clickhouse-server: 23.4.2.11-alpine -> 24.12-alpine
-> 6 CVEs, identical to the hand-specified args
Details that mattered:
- keyed by SERVICE, not image repo. plausible moved plausible/analytics ->
ghcr.io/plausible/community-edition; keyed by repo that reads as one image
vanishing and an unrelated one appearing, and the app window - the one carrying
the critical - is lost entirely.
- the baseline is the repo's DEFAULT BRANCH resolved from the API, never assumed
to be main, because several recipes keep a stale main beside a live master.
- image names are matched against advisory sources BOTH ways: an image name is
often longer than its source repo (clickhouse/clickhouse-server vs
ClickHouse/ClickHouse) and sometimes shorter (redis vs redis/redis). One
direction silently dropped the clickhouse window.
- credentials go in an Authorization header, never the URL: in-URL creds leak
into shell history and process lists, and urllib mis-parses a password
containing a colon.
--from/--to/--image remain for finer-grained checks (scanning a window that is
not a literal compose diff). 71 tests; discourse 140 / gitea 2 / mailu 2
unchanged.
This commit is contained in:
+136
-1
@@ -660,7 +660,14 @@ def scan(recipe: str, v_from: str | None, v_to: str | None, registry_dir: str,
|
||||
windows[primary] = (v_from, v_to)
|
||||
for key, wf, wt in (images or []):
|
||||
for src in gh_sources:
|
||||
if key.lower() in src.lower() and src not in windows:
|
||||
if src in windows:
|
||||
continue
|
||||
# Match BOTH ways: an image name is often longer than its source repo
|
||||
# (`clickhouse/clickhouse-server` vs source `ClickHouse/ClickHouse`) and sometimes
|
||||
# shorter (`redis` vs `redis/redis`). One-directional matching silently dropped the
|
||||
# clickhouse window when the key was derived from a compose file.
|
||||
k, name = key.lower(), src.split("/")[-1].lower()
|
||||
if k in src.lower() or name in k:
|
||||
windows[src] = (wf, wt)
|
||||
report["windows"] = {k: {"from": f, "to": t} for k, (f, t) in windows.items()}
|
||||
|
||||
@@ -893,6 +900,113 @@ def markdown(rep: dict) -> str:
|
||||
return "\n".join(L)
|
||||
|
||||
|
||||
def _gitea_auth(url: str) -> dict:
|
||||
"""Basic auth for the private mirror, from /srv/cc-ci/.testenv.
|
||||
|
||||
Sent as a HEADER, never embedded in the URL: in-URL credentials leak into shell history, process
|
||||
lists and error messages, and urllib mis-parses a password containing a colon."""
|
||||
host = re.sub(r"^https?://", "", url).split("/")[0]
|
||||
env = {}
|
||||
try:
|
||||
for ln in open(os.environ.get("CCCI_TESTENV", "/srv/cc-ci/.testenv")):
|
||||
if "=" in ln and not ln.strip().startswith("#"):
|
||||
k, v = ln.strip().split("=", 1)
|
||||
env[k] = v.strip().strip("\"'")
|
||||
except OSError:
|
||||
return {}
|
||||
if host != env.get("GITEA_URL", "git.autonomic.zone"):
|
||||
return {}
|
||||
u, pw = env.get("GITEA_USERNAME"), env.get("GITEA_PASSWORD")
|
||||
if not (u and pw):
|
||||
return {}
|
||||
import base64 as _b64
|
||||
return {"Authorization": "Basic " + _b64.b64encode(f"{u}:{pw}".encode()).decode()}
|
||||
|
||||
|
||||
def _compose_images(url: str) -> dict[str, tuple[str, str]]:
|
||||
"""{service: (image-repo, tag)} for a compose file.
|
||||
|
||||
Keyed by SERVICE, not by image repo, because an upgrade may change the repo itself: plausible
|
||||
moved `plausible/analytics` -> `ghcr.io/plausible/community-edition`. Keyed by repo that reads
|
||||
as one image vanishing and an unrelated one appearing, and the app's version window is lost —
|
||||
which is exactly the upgrade most worth scanning."""
|
||||
txt = _fetch(url, _gitea_auth(url))
|
||||
out, svc = {}, None
|
||||
in_services = False
|
||||
for line in txt.splitlines():
|
||||
if re.match(r"^services:\s*$", line):
|
||||
in_services = True
|
||||
continue
|
||||
if in_services and re.match(r"^\S", line):
|
||||
in_services = False
|
||||
if not in_services:
|
||||
continue
|
||||
m = re.match(r"^ (\S+):\s*$", line)
|
||||
if m:
|
||||
svc = m.group(1)
|
||||
continue
|
||||
m = re.match(r"^\s+image:\s*[\"']?([^\"'\s]+)", line)
|
||||
if m and svc:
|
||||
ref = m.group(1).split("@", 1)[0]
|
||||
if "${" in ref or "$(" in ref:
|
||||
continue
|
||||
repo, _, tag = ref.rpartition(":")
|
||||
if repo and tag:
|
||||
out[svc] = (repo, tag)
|
||||
return out
|
||||
|
||||
|
||||
def _default_branch_compose(url: str) -> str | None:
|
||||
"""Same repo as `url`, but its DEFAULT branch — resolved from the API, never assumed.
|
||||
|
||||
Several coopcloud recipes keep a stale `main` beside the real default `master` (gitea's `main`
|
||||
is 1.24.2-rootless while `master` has 1.27.1-rootless), so guessing the branch produces a
|
||||
confidently wrong baseline."""
|
||||
m = re.match(r"(https?://[^/]+)/([^/]+)/([^/]+)/(?:raw|src)/branch/[^/]+/(.*)$", url)
|
||||
if not m:
|
||||
return None
|
||||
host, owner, repo, path = m.groups()
|
||||
try:
|
||||
meta = json.loads(_fetch(f"{host}/api/v1/repos/{owner}/{repo}", _gitea_auth(host)))
|
||||
br = meta.get("default_branch")
|
||||
except Exception: # noqa: BLE001
|
||||
return None
|
||||
return f"{host}/{owner}/{repo}/raw/branch/{br}/{path}" if br else None
|
||||
|
||||
|
||||
def windows_from_compose(to_url: str, from_url: str | None = None) -> tuple[list, str | None]:
|
||||
"""Derive the scan's version windows by DIFFING two compose files.
|
||||
|
||||
This is the deterministic alternative to a human (or a model) deciding which `--image` args a
|
||||
given upgrade needs. Point it at a PR's compose and it reads the windows straight off the diff:
|
||||
every image whose tag changed becomes a window, every image that did not change is correctly
|
||||
left out, and nothing depends on anyone remembering that the recipe also bumped its redis.
|
||||
|
||||
Returns (windows, note) where windows is [(image-name, from, to)].
|
||||
"""
|
||||
if from_url is None:
|
||||
from_url = _default_branch_compose(to_url)
|
||||
if not from_url:
|
||||
raise SystemExit("could not resolve a baseline compose; pass --compose-from explicitly")
|
||||
new, old = _compose_images(to_url), _compose_images(from_url)
|
||||
app, others = None, []
|
||||
for svc, (repo, tag) in sorted(new.items()):
|
||||
if svc not in old:
|
||||
continue
|
||||
prev_repo, prev_tag = old[svc]
|
||||
if prev_tag == tag and prev_repo == repo:
|
||||
continue
|
||||
# The `app` service is the recipe's primary image by coop-cloud convention; its window drives
|
||||
# --from/--to so the scan's primary advisory source is judged against it. Everything else is
|
||||
# a sidecar window keyed by its image name.
|
||||
if svc == "app":
|
||||
app = (repo.split("/")[-1], prev_tag, tag)
|
||||
else:
|
||||
others.append((repo.split("/")[-1], prev_tag, tag))
|
||||
wins = ([app] if app else []) + others
|
||||
return wins, f"baseline {from_url}"
|
||||
|
||||
|
||||
def main() -> int:
|
||||
ap = argparse.ArgumentParser(description=__doc__, formatter_class=argparse.RawDescriptionHelpFormatter)
|
||||
ap.add_argument("recipe")
|
||||
@@ -904,6 +1018,13 @@ def main() -> int:
|
||||
"fix version published), fetch their full text + references and append a "
|
||||
"block for the agent to judge. Additive: it never changes the count above.")
|
||||
ap.add_argument("--registry", default=REGISTRY_DIR)
|
||||
ap.add_argument("--compose-to", default=None, metavar="URL",
|
||||
help="derive the windows by DIFFING this compose against its baseline, instead "
|
||||
"of passing --from/--to/--image by hand. Point it at a PR's compose.yml "
|
||||
"(e.g. .../raw/branch/<pr-branch>/compose.yml).")
|
||||
ap.add_argument("--compose-from", default=None, metavar="URL",
|
||||
help="baseline compose for --compose-to. Default: the same repo's DEFAULT "
|
||||
"branch, resolved from the API (never assumed to be `main`).")
|
||||
ap.add_argument("--image", action="append", default=[], metavar="NAME=FROM:TO",
|
||||
help="a sidecar image and the versions it moved between, e.g. "
|
||||
"--image redis=7.4:8.10 (repeatable). NAME matches a source repo name; "
|
||||
@@ -911,6 +1032,20 @@ def main() -> int:
|
||||
"being left unclassified.")
|
||||
a = ap.parse_args()
|
||||
images = []
|
||||
if a.compose_to:
|
||||
wins, note = windows_from_compose(a.compose_to, a.compose_from)
|
||||
if not wins:
|
||||
print(f"### Advisory scan — {a.recipe}\n\n**No image versions changed between the two "
|
||||
f"compose files, so this upgrade fixes no CVEs by definition.**\n\n_{note}_")
|
||||
return 0
|
||||
print(f"_derived from compose diff ({note}):_", file=sys.stderr)
|
||||
for n_, f_, t_ in wins:
|
||||
print(f"_ {n_}: {f_} → {t_}_", file=sys.stderr)
|
||||
# The `app` service (first entry when present) drives --from/--to; the rest are --image
|
||||
# windows. Passing every window as --image too is harmless: each is matched by name against
|
||||
# the advisory sources, and an unmatched name is simply ignored.
|
||||
a.v_from, a.v_to = a.v_from or wins[0][1], a.v_to or wins[0][2]
|
||||
images = list(wins[1:])
|
||||
for spec in a.image:
|
||||
name, _, rng = spec.partition('=')
|
||||
vf, _, vt = rng.partition(':')
|
||||
|
||||
Reference in New Issue
Block a user