You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@cloudstack.apache.org by GitBox <gi...@apache.org> on 2022/07/21 11:39:03 UTC

[GitHub] [cloudstack] rohityadavcloud opened a new pull request, #6562: utils: use safer parsing utility across codebase

rohityadavcloud opened a new pull request, #6562:
URL: https://github.com/apache/cloudstack/pull/6562

   This addresses SonarQube/SonarCloud quality checks to use safer xml parser.
   
   https://sonarcloud.io/organizations/apache/rules?open=java%3AS2755&rule_key=java%3AS2755
   
   ### Types of changes
   
   - [ ] Breaking change (fix or feature that would cause existing functionality to change)
   - [ ] New feature (non-breaking change which adds functionality)
   - [x] Bug fix (non-breaking change which fixes an issue)
   - [x] Enhancement (improves an existing feature and functionality)
   - [ ] Cleanup (Code refactoring and cleanup, that may add test cases)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] rohityadavcloud commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
rohityadavcloud commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1192233507

   @blueorangutan test


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] sonarcloud[bot] commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
sonarcloud[bot] commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1191446246

   Please retry analysis of this Pull-Request directly on [SonarCloud](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562).


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1193081386

   <b>Trillian Build Failed (tid-4534)<b/>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] rohityadavcloud commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
rohityadavcloud commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1193079844

   @blueorangutan test centos8 vmware-70u3


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1192091410

   <b>Trillian test result (tid-4528)</b>
   Environment: xenserver-71 (x2), Advanced Networking with Mgmt server 7
   Total time taken: 36964 seconds
   Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr6562-t4528-xenserver-71.zip
   Smoke tests completed. 100 look OK, 0 have errors
   Only failed tests results shown below:
   
   
   Test | Result | Time (s) | Test File
   --- | --- | --- | ---
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1191591535

   @rohityadavcloud a Trillian-Jenkins matrix job (centos7 mgmt + xs71, centos7 mgmt + vmware65, centos7 mgmt + kvmcentos7) has been kicked to run smoke tests


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1193195421

   <b>Trillian test result (tid-4535)</b>
   Environment: xcpng82 (x2), Advanced Networking with Mgmt server u20
   Total time taken: 50774 seconds
   Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr6562-t4535-xcpng82.zip
   Smoke tests completed. 97 look OK, 3 have errors
   Only failed tests results shown below:
   
   
   Test | Result | Time (s) | Test File
   --- | --- | --- | ---
   test_attach_and_distribute_multiple_volumes | `Error` | 16.97 | test_attach_multiple_volumes.py
   test_attach_multiple_volumes | `Failure` | 13.88 | test_attach_multiple_volumes.py
   test_08_upgrade_kubernetes_ha_cluster | `Failure` | 727.28 | test_kubernetes_clusters.py
   test_12_resize_volume_with_only_size_parameter | `Error` | 1.08 | test_volumes.py
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1192128456

   <b>Trillian test result (tid-4530)</b>
   Environment: vmware-65u2 (x2), Advanced Networking with Mgmt server 7
   Total time taken: 42012 seconds
   Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr6562-t4530-vmware-65u2.zip
   Smoke tests completed. 99 look OK, 1 have errors
   Only failed tests results shown below:
   
   
   Test | Result | Time (s) | Test File
   --- | --- | --- | ---
   test_08_upgrade_kubernetes_ha_cluster | `Failure` | 702.28 | test_kubernetes_clusters.py
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] sonarcloud[bot] commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
sonarcloud[bot] commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1191428231

   SonarCloud Quality Gate failed.&nbsp; &nbsp; [![Quality Gate failed](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/QualityGateBadge/failed-16px.png 'Quality Gate failed')](https://sonarcloud.io/dashboard?id=apache_cloudstack&pullRequest=6562)
   
   [![Bug](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/bug-16px.png 'Bug')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=BUG) [![A](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/A-16px.png 'A')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=BUG) [0 Bugs](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=BUG)  
   [![Vulnerability](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/vulnerability-16px.png 'Vulnerability')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=VULNERABILITY) [![E](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/E-16px.png 'E')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=VULNERABILITY) [1 Vulnerability](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=VULNERABILITY)  
   [![Security Hotspot](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/security_hotspot-16px.png 'Security Hotspot')](https://sonarcloud.io/project/security_hotspots?id=apache_cloudstack&pullRequest=6562&resolved=false&types=SECURITY_HOTSPOT) [![A](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/A-16px.png 'A')](https://sonarcloud.io/project/security_hotspots?id=apache_cloudstack&pullRequest=6562&resolved=false&types=SECURITY_HOTSPOT) [0 Security Hotspots](https://sonarcloud.io/project/security_hotspots?id=apache_cloudstack&pullRequest=6562&resolved=false&types=SECURITY_HOTSPOT)  
   [![Code Smell](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/code_smell-16px.png 'Code Smell')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=CODE_SMELL) [![A](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/A-16px.png 'A')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=CODE_SMELL) [0 Code Smells](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=CODE_SMELL)
   
   [![12.7%](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/CoverageChart/0-16px.png '12.7%')](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_coverage&view=list) [12.7% Coverage](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_coverage&view=list)  
   [![2.9%](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/Duplications/3-16px.png '2.9%')](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_duplicated_lines_density&view=list) [2.9% Duplication](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_duplicated_lines_density&view=list)
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1192234210

   @rohityadavcloud a Trillian-Jenkins test job (centos7 mgmt + kvm-centos7) has been kicked to run smoke tests


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] rohityadavcloud commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
rohityadavcloud commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1193080080

   @blueorangutan test rocky8 vmware-70u3


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] rohityadavcloud commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
rohityadavcloud commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1193080120

   @blueorangutan test ubuntu20 xcpng82


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] rohityadavcloud commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
rohityadavcloud commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1191394064

   @blueorangutan package


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1192106253

   <b>Trillian test result (tid-4529)</b>
   Environment: kvm-centos7 (x2), Advanced Networking with Mgmt server 7
   Total time taken: 38933 seconds
   Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr6562-t4529-kvm-centos7.zip
   Smoke tests completed. 99 look OK, 1 have errors
   Only failed tests results shown below:
   
   
   Test | Result | Time (s) | Test File
   --- | --- | --- | ---
   test_08_upgrade_kubernetes_ha_cluster | `Failure` | 859.77 | test_kubernetes_clusters.py
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] shwstppr commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
shwstppr commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1193984230

   > Trillian test result (tid-4535) Environment: xcpng82 (x2), Advanced Networking with Mgmt server u20 Total time taken: 50774 seconds Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr6562-t4535-xcpng82.zip Smoke tests completed. 97 look OK, 3 have errors Only failed tests results shown below:
   > Test 	Result 	Time (s) 	Test File
   > test_attach_and_distribute_multiple_volumes 	`Error` 	16.97 	test_attach_multiple_volumes.py
   > test_attach_multiple_volumes 	`Failure` 	13.88 	test_attach_multiple_volumes.py
   > test_08_upgrade_kubernetes_ha_cluster 	`Failure` 	727.28 	test_kubernetes_clusters.py
   > test_12_resize_volume_with_only_size_parameter 	`Error` 	1.08 	test_volumes.py
   
   volumes error not related, https://github.com/apache/cloudstack/pull/6549 should fix it


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] sonarcloud[bot] commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
sonarcloud[bot] commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1191445932

   SonarCloud Quality Gate failed.&nbsp; &nbsp; [![Quality Gate failed](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/QualityGateBadge/failed-16px.png 'Quality Gate failed')](https://sonarcloud.io/dashboard?id=apache_cloudstack&pullRequest=6562)
   
   [![Bug](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/bug-16px.png 'Bug')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=BUG) [![A](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/A-16px.png 'A')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=BUG) [0 Bugs](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=BUG)  
   [![Vulnerability](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/vulnerability-16px.png 'Vulnerability')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=VULNERABILITY) [![E](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/E-16px.png 'E')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=VULNERABILITY) [1 Vulnerability](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=VULNERABILITY)  
   [![Security Hotspot](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/security_hotspot-16px.png 'Security Hotspot')](https://sonarcloud.io/project/security_hotspots?id=apache_cloudstack&pullRequest=6562&resolved=false&types=SECURITY_HOTSPOT) [![A](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/A-16px.png 'A')](https://sonarcloud.io/project/security_hotspots?id=apache_cloudstack&pullRequest=6562&resolved=false&types=SECURITY_HOTSPOT) [0 Security Hotspots](https://sonarcloud.io/project/security_hotspots?id=apache_cloudstack&pullRequest=6562&resolved=false&types=SECURITY_HOTSPOT)  
   [![Code Smell](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/code_smell-16px.png 'Code Smell')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=CODE_SMELL) [![A](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/A-16px.png 'A')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=CODE_SMELL) [0 Code Smells](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=CODE_SMELL)
   
   [![50.0%](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/CoverageChart/50-16px.png '50.0%')](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_coverage&view=list) [50.0% Coverage](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_coverage&view=list)  
   [![2.3%](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/Duplications/3-16px.png '2.3%')](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_duplicated_lines_density&view=list) [2.3% Duplication](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_duplicated_lines_density&view=list)
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1191394644

   @rohityadavcloud a Jenkins job has been kicked to build packages. It will be bundled with  KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1191428110

   Packaging result: :heavy_check_mark: el7 :heavy_check_mark: el8 :heavy_check_mark: debian :heavy_check_mark: suse15. SL-JID 3808


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] rohityadavcloud commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
rohityadavcloud commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1193080225

   
   @blueorangutan test ubuntu20 xcpng82
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] sonarcloud[bot] commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
sonarcloud[bot] commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1191430913

   SonarCloud Quality Gate failed.&nbsp; &nbsp; [![Quality Gate failed](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/QualityGateBadge/failed-16px.png 'Quality Gate failed')](https://sonarcloud.io/dashboard?id=apache_cloudstack&pullRequest=6562)
   
   [![Bug](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/bug-16px.png 'Bug')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=BUG) [![A](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/A-16px.png 'A')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=BUG) [0 Bugs](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=BUG)  
   [![Vulnerability](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/vulnerability-16px.png 'Vulnerability')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=VULNERABILITY) [![E](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/E-16px.png 'E')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=VULNERABILITY) [1 Vulnerability](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=VULNERABILITY)  
   [![Security Hotspot](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/security_hotspot-16px.png 'Security Hotspot')](https://sonarcloud.io/project/security_hotspots?id=apache_cloudstack&pullRequest=6562&resolved=false&types=SECURITY_HOTSPOT) [![A](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/A-16px.png 'A')](https://sonarcloud.io/project/security_hotspots?id=apache_cloudstack&pullRequest=6562&resolved=false&types=SECURITY_HOTSPOT) [0 Security Hotspots](https://sonarcloud.io/project/security_hotspots?id=apache_cloudstack&pullRequest=6562&resolved=false&types=SECURITY_HOTSPOT)  
   [![Code Smell](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/code_smell-16px.png 'Code Smell')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=CODE_SMELL) [![A](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/RatingBadge/A-16px.png 'A')](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=CODE_SMELL) [0 Code Smells](https://sonarcloud.io/project/issues?id=apache_cloudstack&pullRequest=6562&resolved=false&types=CODE_SMELL)
   
   [![13.6%](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/CoverageChart/0-16px.png '13.6%')](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_coverage&view=list) [13.6% Coverage](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_coverage&view=list)  
   [![2.9%](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/Duplications/3-16px.png '2.9%')](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_duplicated_lines_density&view=list) [2.9% Duplication](https://sonarcloud.io/component_measures?id=apache_cloudstack&pullRequest=6562&metric=new_duplicated_lines_density&view=list)
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] rohityadavcloud commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
rohityadavcloud commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1191590875

   @blueorangutan test matrix


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] sureshanaparti commented on a diff in pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
sureshanaparti commented on code in PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#discussion_r927323206


##########
utils/src/test/java/org/apache/cloudstack/utils/security/ParserUtilsTest.java:
##########
@@ -0,0 +1,55 @@
+// Licensed to the Apache Software Foundation (ASF) under one
+// or more contributor license agreements.  See the NOTICE file
+// distributed with this work for additional information
+// regarding copyright ownership.  The ASF licenses this file
+// to you under the Apache License, Version 2.0 (the
+// "License"); you may not use this file except in compliance
+// with the License.  You may obtain a copy of the License at
+//
+//   http://www.apache.org/licenses/LICENSE-2.0
+//
+// Unless required by applicable law or agreed to in writing,
+// software distributed under the License is distributed on an
+// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+// KIND, either express or implied.  See the License for the
+// specific language governing permissions and limitations
+// under the License.
+
+package org.apache.cloudstack.utils.security;
+
+import javax.xml.XMLConstants;
+import javax.xml.parsers.DocumentBuilderFactory;
+import javax.xml.parsers.ParserConfigurationException;
+import javax.xml.parsers.SAXParserFactory;
+import javax.xml.transform.TransformerFactory;
+
+import org.xml.sax.SAXNotRecognizedException;
+import org.xml.sax.SAXNotSupportedException;
+
+import junit.framework.TestCase;
+
+public class ParserUtilsTest extends TestCase {
+
+    public void testGetSaferDocumentBuilderFactory() throws ParserConfigurationException {
+        final DocumentBuilderFactory factory = ParserUtils.getSaferDocumentBuilderFactory();
+        assertTrue(factory.getFeature(XMLConstants.FEATURE_SECURE_PROCESSING));
+        assertTrue(factory.getFeature("http://apache.org/xml/features/disallow-doctype-decl"));
+        assertFalse(factory.getFeature("http://xml.org/sax/features/external-general-entities"));

Review Comment:
   can define / use constants for these urls?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1193080359

   @rohityadavcloud a Trillian-Jenkins test job (ubuntu20 mgmt + xcpng82) has been kicked to run smoke tests


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1192855214

   <b>Trillian test result (tid-4532)</b>
   Environment: kvm-centos7 (x2), Advanced Networking with Mgmt server 7
   Total time taken: 43437 seconds
   Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr6562-t4532-kvm-centos7.zip
   Smoke tests completed. 98 look OK, 2 have errors
   Only failed tests results shown below:
   
   
   Test | Result | Time (s) | Test File
   --- | --- | --- | ---
   test_08_upgrade_kubernetes_ha_cluster | `Failure` | 576.91 | test_kubernetes_clusters.py
   test_03_create_redundant_VPC_1tier_2VMs_2IPs_2PF_ACL_reboot_routers | `Failure` | 462.22 | test_vpc_redundant.py
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] rohityadavcloud commented on a diff in pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
rohityadavcloud commented on code in PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#discussion_r927332800


##########
utils/src/test/java/org/apache/cloudstack/utils/security/ParserUtilsTest.java:
##########
@@ -0,0 +1,55 @@
+// Licensed to the Apache Software Foundation (ASF) under one
+// or more contributor license agreements.  See the NOTICE file
+// distributed with this work for additional information
+// regarding copyright ownership.  The ASF licenses this file
+// to you under the Apache License, Version 2.0 (the
+// "License"); you may not use this file except in compliance
+// with the License.  You may obtain a copy of the License at
+//
+//   http://www.apache.org/licenses/LICENSE-2.0
+//
+// Unless required by applicable law or agreed to in writing,
+// software distributed under the License is distributed on an
+// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+// KIND, either express or implied.  See the License for the
+// specific language governing permissions and limitations
+// under the License.
+
+package org.apache.cloudstack.utils.security;
+
+import javax.xml.XMLConstants;
+import javax.xml.parsers.DocumentBuilderFactory;
+import javax.xml.parsers.ParserConfigurationException;
+import javax.xml.parsers.SAXParserFactory;
+import javax.xml.transform.TransformerFactory;
+
+import org.xml.sax.SAXNotRecognizedException;
+import org.xml.sax.SAXNotSupportedException;
+
+import junit.framework.TestCase;
+
+public class ParserUtilsTest extends TestCase {
+
+    public void testGetSaferDocumentBuilderFactory() throws ParserConfigurationException {
+        final DocumentBuilderFactory factory = ParserUtils.getSaferDocumentBuilderFactory();
+        assertTrue(factory.getFeature(XMLConstants.FEATURE_SECURE_PROCESSING));
+        assertTrue(factory.getFeature("http://apache.org/xml/features/disallow-doctype-decl"));
+        assertFalse(factory.getFeature("http://xml.org/sax/features/external-general-entities"));

Review Comment:
   I'll check for ParserUtils but not necessarily the test itself



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1193079933

   @rohityadavcloud unsupported parameters provided. Supported mgmt server os are: `centos7, centos6, suse15, alma8, ubuntu18, ubuntu22, ubuntu20, rocky8`. Supported hypervisors are: `kvm-centos6, kvm-centos7, kvm-rocky8, kvm-alma8, kvm-ubuntu18, kvm-ubuntu20, kvm-ubuntu22, kvm-suse15, vmware-55u3, vmware-60u2, vmware-65u2, vmware-67u3, vmware-70u1, vmware-70u2, vmware-70u3, xenserver-65sp1, xenserver-71, xenserver-74, xcpng74, xcpng76, xcpng80, xcpng81, xcpng82`


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] blueorangutan commented on pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
blueorangutan commented on PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562#issuecomment-1193080203

   @rohityadavcloud a Trillian-Jenkins test job (rocky8 mgmt + vmware-70u3) has been kicked to run smoke tests


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [cloudstack] rohityadavcloud merged pull request #6562: utils: use safer parsing utility across codebase

Posted by GitBox <gi...@apache.org>.
rohityadavcloud merged PR #6562:
URL: https://github.com/apache/cloudstack/pull/6562


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org