DNM: ONLY FOR TEST | tiflow-test=release-6.5.12-hotfix-20260201#12508
DNM: ONLY FOR TEST | tiflow-test=release-6.5.12-hotfix-20260201#12508haiboumich wants to merge 9 commits intopingcap:release-6.5from
Conversation
|
This cherry pick PR is for a release branch and has not yet been approved by triage owners. To merge this cherry pick:
DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Summary of ChangesHello @haiboumich, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request significantly improves the accuracy and reliability of DDL replication in TiFlow. It introduces mechanisms to correctly track truncated partitioned tables, ensures the precise ordering of DDL events, and addresses a critical issue with Highlights
🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console. Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
There was a problem hiding this comment.
Code Review
This pull request introduces several significant improvements, including correct handling of multi-table DDL ordering using a sequence number, enhanced MySQL sink replication for DEFAULT CURRENT_TIMESTAMP by managing session timestamps, and fixes for TRUNCATE TABLE behavior for partitioned tables. However, a critical SQL injection vulnerability was identified in the DDL query reconstruction logic within cdc/model/sink.go. Specifically, DDL statements such as DROP TABLE, DROP VIEW, RENAME TABLE, and EXCHANGE PARTITION are rebuilt using raw schema and table names without proper escaping of backticks, which could allow an attacker to execute arbitrary SQL. It is recommended to use the existing quotes.QuoteName utility to ensure all identifiers are properly quoted and escaped. Additionally, there is a minor suggestion for improving logging.
| } | ||
|
|
||
| if _, err = tx.ExecContext(ctx, ddl.Query); err != nil { | ||
| log.Error("Failed to ExecContext", zap.Any("err", err), zap.Any("query", ddl.Query)) |
There was a problem hiding this comment.
For better error logging and to ensure type safety with the zap logger, it's recommended to use zap.Error(err) for error types and zap.String("query", ddl.Query) for string types instead of zap.Any. zap.Error can provide more structured logging for errors, including stack traces if available.
| log.Error("Failed to ExecContext", zap.Any("err", err), zap.Any("query", ddl.Query)) | |
| log.Error("Failed to ExecContext", zap.Error(err), zap.String("query", ddl.Query)) |
|
/test pr-verify |
|
@haiboumich: The specified target(s) for Use DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/test pull-verify |
|
/test pull-cdc-integration-mysql-test |
This reverts commit 6ae60b0.
|
@haiboumich: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
What problem does this PR solve?
Issue Number: close #xxx
What is changed and how it works?
Check List
Tests
Questions
Will it cause performance regression or break compatibility?
Do you need to update user documentation, design documentation or monitoring documentation?
Release note