fix: resolve advisory_packages join in postgres, skip 1.5TB purl scan (CM-1362) - #4433
fix: resolve advisory_packages join in postgres, skip 1.5TB purl scan (CM-1362)#4433themarolt wants to merge 4 commits into
Conversation
… (CM-1362) Signed-off-by: Uroš Marolt <[email protected]>
PR SummaryMedium Risk Overview Pipeline behavior: Bonus: Reviewed by Cursor Bugbot for commit cc2a3ea. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
Pull request overview
Reduces advisory-package BigQuery scanning by resolving package identities in PostgreSQL while allowing downstream jobs to continue after ceiling breaches.
Changes:
- Removes the costly BigQuery purl lookup and adds shared package-name parsing.
- Resolves package IDs through PostgreSQL’s indexed package identity.
- Adds typed, non-retryable ceiling failures and lowers the scan limit.
Reviewed changes
Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
services/libs/data-access-layer/src/packages/osv.ts |
Fixes scoped npm identity reconstruction. |
services/apps/packages_worker/src/deps-dev/workflows/ingestPackages.ts |
Uses shared identity parsing. |
services/apps/packages_worker/src/deps-dev/workflows/ingestAdvisories.ts |
Resolves package IDs in PostgreSQL and handles ceiling failures. |
services/apps/packages_worker/src/deps-dev/workflows/bootstrapOsspckgs.ts |
Soft-fails advisory ceiling breaches. |
services/apps/packages_worker/src/deps-dev/README.md |
Documents revised scan ceilings. |
services/apps/packages_worker/src/deps-dev/queries/pgIdentity.ts |
Adds shared identity SQL generation. |
services/apps/packages_worker/src/deps-dev/queries/advisoriesSql.ts |
Removes the BigQuery purl scan. |
services/apps/packages_worker/src/deps-dev/activities/bqExportToGcs.ts |
Makes ceiling failures typed and non-retryable. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Signed-off-by: Uroš Marolt <[email protected]>
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 10 out of 10 changed files in this pull request and generated no new comments.
Suppressed comments (2)
services/libs/data-access-layer/src/packages/osv.ts:316
- The scoped-npm catch-up fix has no regression coverage. The existing
resolveMissingPackageIdsintegration case only uses an npm package withnamespace: null, so it would pass with the old double-@expression. Add a scoped fixture (for example namespace@types, namenode, package name@types/node) and assert thatpackage_idresolves.
WHEN p.ecosystem = 'npm' THEN p.namespace || '/' || p.name
services/apps/packages_worker/src/deps-dev/activities/notifyBqCeilingSkip.ts:20
- This alert runs after the advisory-header step has already merged rows, so “Existing data untouched” is inaccurate; only the advisory-package step was skipped. The message can mislead operators investigating a partially completed run.
text: `Ingest skipped for this run so scorecard/ranking still complete. Existing data untouched. ${input.message}`,
Signed-off-by: Uroš Marolt <[email protected]>
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 10 out of 10 changed files in this pull request and generated no new comments.
Suppressed comments (1)
services/apps/packages_worker/src/deps-dev/activities/notifyBqCeilingSkip.ts:20
- The ceiling breach occurs after Step 1 has already merged advisory header rows, so “Existing data untouched” is inaccurate and may mislead operators. State specifically that advisory-package/range data was preserved and that advisory headers may already have been ingested.
text: `Ingest skipped for this run so scorecard/ranking still complete. Existing data untouched. ${input.message}`,
Signed-off-by: Uroš Marolt <[email protected]>
Summary
bootstrapOsspckgshas failed its last 5 weekly runs atingestAdvisories— a BQ dry-run guard aborts becauseadvisory_packagesscans ~1.5 TB. Root cause: apurl_mapCTE joins the entirePackageVersionsLatesttable just to attach apurlused for one join key, which we already have locally in Postgres. This drops the BQ scan for that step to ~1.4 GB and stops the failure from strandingscorecard/ranking downstream.Changes
purl_mapCTE frombuildAdvisoryPackagesSql— no BQ-side purl lookup.advisory_packages.package_idin Postgres instead, joining on the same(ecosystem, namespace, name)identitypackagesalready carries a unique index on (COALESCE(namespace,'')matches the index expression, so this stays an index lookup, not a scan).queries/pgIdentity.ts(packageNameSplitSql) so the namespace/name split logic isn't duplicated betweeningestPackages.tsandingestAdvisories.ts.purlcolumn from theadvisory_packagesstaging DDL/columns; switch that DDL toDROP TABLE IF EXISTS+CREATE(matchesingestDependentCounts.ts) so a stalepurlcolumn doesn't silently surviveCREATE ... IF NOT EXISTS.BQ_DATASET_INGEST_ADVISORY_PACKAGES_MAX_BQ_GB1500 → 50 (measured actual ~1.4 GB; keeps the ceiling a real regression gate).bqExportToGcsnow throws a typedApplicationFailure.nonRetryable(..., 'BQ_CEILING_EXCEEDED')on ceiling breach instead of a plainError(a dry-run byte count is deterministic, so retrying is pure waste).ingestAdvisoriesunwraps that fromActivityFailureand rethrows a workflow-levelApplicationFailureof the same type;bootstrapOsspckgsnow soft-fails only on that type around the advisories step (mirrors the existingdependent_counts/package_dependenciesguards) — a ceiling breach no longer strandsscorecard/ranking for the whole run.resolveMissingPackageIds(osv.ts:316) built'@' || namespace || '/' || namefor npm, butnamespacealready contains the@— every scoped npm advisory package was silently unresolvable in this catch-up. One-line fix, same identity-reconstruction logic as the rest of this PR.Type of change
JIRA ticket
https://linuxfoundation.atlassian.net/browse/CM-1362