<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>13095</bug_id>
          
          <creation_ts>2018-12-19 14:01:02 +0000</creation_ts>
          <short_desc>Use Django ORM instead of sqlite directly</short_desc>
          <delta_ts>2023-10-18 20:55:20 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>6</classification_id>
          <classification>Yocto Project Subprojects</classification>
          <product>Security Response Tool</product>
          <component>General</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>NOTABUG</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard> </status_whiteboard>
          <keywords></keywords>
          <priority>Low</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>4.3 M4</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ross Burton">ross.burton</reporter>
          <assigned_to name="David Reyna">david.reyna</assigned_to>
          <cc>randy.macleod</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>82536</commentid>
    <comment_count>0</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2018-12-19 14:01:02 +0000</bug_when>
    <thetext>The NIST/MITRE/etc fetching scripts write to the sqlite data directly, using a generated Python file to expose name/column index mappings.

Instead, these tools should just import the database model and use the standard Django interfaces, so they don&apos;t rely on the underlying data model.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>82539</commentid>
    <comment_count>1</comment_count>
    <who name="David Reyna">david.reyna</who>
    <bug_when>2018-12-19 18:41:48 +0000</bug_when>
    <thetext>These database actions were originally written in Django.

They were explicitly moved to command line scripts away from Django, because:

1) The scripts literally run an order of magnitude faster that the Django wrappers. What takes an hour now took half a day or more before.

2) The command line scripts are much more compatible with background update scripts and CRON jobs, a crucial requirement.

- David</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>84429</commentid>
    <comment_count>2</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2019-07-16 09:13:39 +0000</bug_when>
    <thetext>Coming back to this, to productise srtool sqlite really isn&apos;t up to scratch.  If the update hooks were just management hooks then calling them from cron is trivial.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>85135</commentid>
    <comment_count>3</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2019-10-01 15:08:54 +0000</bug_when>
    <thetext>Another good reason to use the ORM directly is that it lets us switch from sqlite to postresql.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>96721</commentid>
    <comment_count>4</comment_count>
    <who name="David Reyna">david.reyna</who>
    <bug_when>2023-10-18 20:55:20 +0000</bug_when>
    <thetext>Per my previous comment, the pure Django implementation is impossibly slow for the magnitude of CVE and defect records.

To accommodate the underlying database model for these backend scripts, we have added the script &quot;bin/common/srtool_sqa.py&quot; to provide the needed abstraction. The databases SQLite, Postgres, and MySQL are supported.

In addition, we have provided a migration script to move data from the original SQLite to for example Postgres. 

The migration script also works the other way, for example Postgres to SQLite. The reason is that is it imperative to be able to back up the database in case of errors or host crashes. Postgres does not have a model for backing up its data base other that generating SQL statements. This migration script does exactly that but puts it into an SQLite database, which given that it is one file is easy to preserve remotely, plus it is a form that can be directly accessed bu the SRTool.

David</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>