Skip to content

[GSOC23] - C - Implement a StAX parser for OVAL files#7510

Open
HoussemNasri wants to merge 26 commits intouyuni-project:masterfrom
HoussemNasri:oval-stax-parser
Open

[GSOC23] - C - Implement a StAX parser for OVAL files#7510
HoussemNasri wants to merge 26 commits intouyuni-project:masterfrom
HoussemNasri:oval-stax-parser

Conversation

@HoussemNasri
Copy link
Contributor

@HoussemNasri HoussemNasri commented Sep 7, 2023

What does this PR change?

Introduce a StAX parser (instead of the current JAXB parser) for OVAL files to increase memory efficiency when parsing large OVAL files.

Useful Links

GUI diff

No difference.

Before:

After:

  • DONE

Documentation

Test coverage

  • No tests: add explanation

  • No tests: already covered

  • Unit tests were added

  • Cucumber tests were added

  • DONE

Links

Fixes #
Tracks # add downstream PR, if any

  • DONE

Changelogs

Make sure the changelogs entries you are adding are compliant with https://github.com/uyuni-project/uyuni/wiki/Contributing#changelogs and https://github.com/uyuni-project/uyuni/wiki/Contributing#uyuni-projectuyuni-repository

If you don't need a changelog check, please mark this checkbox:

  • No changelog needed

If you uncheck the checkbox after the PR is created, you will need to re-run changelog_test (see below)

Re-run a test

If you need to re-run a test, please mark the related checkbox, it will be unchecked automatically once it has re-run:

  • Re-run test "changelog_test"
  • Re-run test "backend_unittests_pgsql"
  • Re-run test "java_pgsql_tests"
  • Re-run test "schema_migration_test_pgsql"
  • Re-run test "susemanager_unittests"
  • Re-run test "javascript_lint"
  • Re-run test "spacecmd_unittests"

@github-actions
Copy link
Contributor

github-actions bot commented Sep 7, 2023

Suggested tests to cover this Pull Request
  • srv_docker_cve_audit
  • min_cve_audit

@github-actions
Copy link
Contributor

github-actions bot commented Oct 26, 2023

👋 Hello! Thanks for contributing to our project.
Acceptance tests will take some time (aprox. 1h), please be patient ☕

You can see the progress at the end of this page and at https://github.com/uyuni-project/uyuni/pull/7510/checks
Once tests finish, if they fail, you can check 👀 the cucumber report. See the link at the output of the action.
You can also check the artifacts section, which contains the logs at https://github.com/uyuni-project/uyuni/pull/7510/checks.

If you are unsure the failing tests are related to your code, you can check the "reference jobs". These are jobs that run on a scheduled time with code from master. If they fail for the same reason as your build, it means the tests or the infrastructure are broken. If they do not fail, but yours do, it means it is related to your code.

Reference tests:

KNOWN ISSUES

Sometimes the build can fail when pulling new jar files from download.opensuse.org . This is a known limitation. Given this happens rarely, when it does, all you need to do is rerun the test. Sorry for the inconvenience.

For more tips on troubleshooting, see the troubleshooting guide.

Happy hacking!
⚠️ You should not merge if acceptance tests fail to pass. ⚠️

@github-actions
Copy link
Contributor

This PR is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 10 days.

@github-actions github-actions bot added the Stale label Dec 26, 2023
@github-actions
Copy link
Contributor

github-actions bot commented Jan 5, 2024

This PR was closed because it has been stalled for 10 days with no activity.

@github-actions github-actions bot closed this Jan 5, 2024
@mcalmer
Copy link
Contributor

mcalmer commented Jan 5, 2024

@HoussemNasri @parlt91 i think this is still needed, right?

@HoussemNasri
Copy link
Contributor Author

@HoussemNasri @parlt91 i think this is still needed, right?

Yes, the A and B pull requests need to be reviewed first before we can move to this one in case there was some changes that would affect this one (all PRs are kind of stacked on each other). Right now, pr A is under review.

@mcalmer
Copy link
Contributor

mcalmer commented Jan 5, 2024

Than we better reopen this request

@mcalmer mcalmer reopened this Jan 5, 2024
parlt91 added 2 commits April 22, 2025 11:51
Signed-off-by: Pascal Arlt <parlt@suse.com>
Signed-off-by: Pascal Arlt <parlt@suse.com>
@admd admd requested review from mackdk and rjmateus and removed request for rjpmestre May 20, 2025 09:52
@github-actions
Copy link
Contributor

This PR is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 10 days.

@github-actions github-actions bot added the Stale label Jul 20, 2025
@rjmateus rjmateus removed the Stale label Jul 21, 2025
@admd
Copy link
Contributor

admd commented Jul 29, 2025

@rjmateus can you please take another look and see if you spot anything.

@parlt91 once reviewed by Ricardo, we should test it a bit more and if all goes well, we should proceed with merging this PR.

Thank you.

@@ -0,0 +1,114 @@
/*
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Schema folder needs to be updated

* The Oval Parser is responsible for parsing OVAL(Open Vulnerability and Assessment Language) documents
*/
public class OvalParser {
public static final int DEFINITIONS_BULK_SIZE = 500;
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should ready this from a configuration, where the default can be 500.

* @param ovalFileURL the OVAL file to parse
* @return the parsed OVAL encapsulated in an {@link OvalRootType} object.
* */
public OvalRootType parse(URL ovalFileURL) throws OvalParserException {
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This parser is only used for testing. Should we move it to a test-only class? The method could be a utility that would receive a OvalParser instance and the File location. Since it keeps all in memory, I think it is risky to have in the main class when is used only for testing.

* @param ovalFile an XML file containing OVAL definitions to be parsed.
* @return all OVAL definitions in {@code ovalFile}
* */
public List<DefinitionType> parseAllDefinitions(File ovalFile) {
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a dependency for the parser function that is used only for testing. We want people to use the bulk parser, and not the one that loads everything to memory.

OvalParser ovalParser = new OvalParser();
OVALResources ovalResources = ovalParser.parseResources(ovalFile);
ovalParser.parseDefinitionsInBulk(ovalFile, definitionsBulk -> {
OvalRootType ovalRoot = new OvalRootType();
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks to me that the product.getOsFamily() and product.getOsVersion() should also be use to set the OvalRootType.
In the method called savePlatformsVulnerablePackages the OS family and version are being loaded from the OvalRootType but looks to me that it's never set.

@github-actions
Copy link
Contributor

This PR is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 10 days.

@github-actions github-actions bot added the Stale label Oct 11, 2025
@parlt91 parlt91 removed the Stale label Oct 11, 2025
@github-actions
Copy link
Contributor

This PR is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 10 days.

@github-actions github-actions bot added the Stale label Dec 11, 2025
@rjmateus rjmateus removed the Stale label Dec 11, 2025
@github-actions
Copy link
Contributor

This PR is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 10 days.

@github-actions github-actions bot added the Stale label Feb 10, 2026
@admd admd removed the Stale label Feb 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants