def test_returns_when_no_action_found(self, log_mock): self.scanner_rule.delete() ScannerResult.run_action(self.version) log_mock.assert_called_with('No action to execute for version %s.', self.version.id)
def test_runs_delay_auto_approval(self, _delay_auto_approval_mock): self.scanner_rule.update(action=DELAY_AUTO_APPROVAL) ScannerResult.run_action(self.version) assert _delay_auto_approval_mock.called _delay_auto_approval_mock.assert_called_with(self.version)
def test_runs_flag_for_human_review(self, flag_for_human_review_mock): self.scanner_rule.update(action=FLAG_FOR_HUMAN_REVIEW) ScannerResult.run_action(self.version) assert flag_for_human_review_mock.called flag_for_human_review_mock.assert_called_with(self.version)
def test_runs_no_action(self, no_action_mock): self.scanner_rule.update(action=NO_ACTION) ScannerResult.run_action(self.version) assert no_action_mock.called no_action_mock.assert_called_with(self.version)
def test_flags_for_human_review_by_mad_when_score_is_too_high(self): version = version_factory(addon=addon_factory()) results = {'scanners': {'customs': {'score': 0.99}}} ScannerResult.objects.create(version=version, scanner=MAD, results=results) ScannerResult.run_action(version) assert version.reviewerflags.needs_human_review_by_mad
def test_does_not_flag_for_human_review_by_mad_when_score_is_okay(self): version = version_factory(addon=addon_factory()) results = {'scanners': {'customs': {'score': 0.2}}} ScannerResult.objects.create(version=version, scanner=MAD, results=results) ScannerResult.run_action(version) with self.assertRaises(VersionReviewerFlags.DoesNotExist): version.reviewerflags
def test_selects_the_action_with_the_highest_severity( self, flag_for_human_review_mock, no_action_mock): # Create another rule and add it to the current scanner result. This # rule is more severe than `rule-1` created in `setUp()`. rule = ScannerRule.objects.create(name='rule-2', scanner=self.scanner, action=FLAG_FOR_HUMAN_REVIEW) self.scanner_result.matched_rules.add(rule) ScannerResult.run_action(self.version) assert not no_action_mock.called assert flag_for_human_review_mock.called
def test_flags_for_human_review_by_mad_when_models_disagree(self): version = version_factory(addon=addon_factory()) results = { 'scanners': { 'customs': {'result_details': {'models_agree': False}} } } ScannerResult.objects.create( version=version, scanner=MAD, results=results ) ScannerResult.run_action(version) assert version.versionreviewerflags.needs_human_review_by_mad
def test_selects_active_actions_only(self, flag_for_human_review_mock, no_action_mock): # Create another rule and add it to the current scanner result. This # rule is more severe than `rule-1` created in `setUp()`. In this test # case, we disable this rule, though. rule = ScannerRule.objects.create( name='rule-2', scanner=self.scanner, action=FLAG_FOR_HUMAN_REVIEW, is_active=False, ) self.scanner_result.matched_rules.add(rule) ScannerResult.run_action(self.version) assert no_action_mock.called assert not flag_for_human_review_mock.called
def process(self, version): """Process a single version, figuring out if it should be auto-approved and calling the approval code if necessary.""" already_locked = AutoApprovalSummary.check_is_locked(version) if not already_locked: # Lock the addon for ourselves if possible. Even though # AutoApprovalSummary.create_summary_for_version() will do # call check_is_locked() again later when calculating the verdict, # we have to do it now to prevent overwriting an existing lock with # our own. set_reviewing_cache(version.addon.pk, settings.TASK_USER_ID) try: with transaction.atomic(): log.info('Processing %s version %s...', str(version.addon.name), str(version.version)) if waffle.switch_is_active('run-action-in-auto-approve'): # We want to execute `run_action()` only once. summary_exists = AutoApprovalSummary.objects.filter( version=version).exists() if summary_exists: log.info('Not running run_action() because it has ' 'already been executed') else: ScannerResult.run_action(version) summary, info = AutoApprovalSummary.create_summary_for_version( version, dry_run=self.dry_run) self.stats.update({k: int(v) for k, v in info.items()}) if summary.verdict == self.successful_verdict: if summary.verdict == amo.AUTO_APPROVED: self.approve(version) self.stats['auto_approved'] += 1 verdict_string = summary.get_verdict_display() else: verdict_string = '%s (%s)' % ( summary.get_verdict_display(), ', '.join( summary.verdict_info_prettifier(info))) log.info('Auto Approval for %s version %s: %s', str(version.addon.name), str(version.version), verdict_string) # At this point, any exception should have rolled back the transaction, # so even if we did create/update an AutoApprovalSummary instance that # should have been rolled back. This ensures that, for instance, a # signing error doesn't leave the version and its autoapprovalsummary # in conflicting states. except (AutoApprovalNotEnoughFilesError, AutoApprovalNoValidationResultError): log.info( 'Version %s was skipped either because it had no ' 'files or because it had no validation attached.', version) self.stats['error'] += 1 except SigningError: statsd.incr('reviewers.auto_approve.approve.failure') log.info('Version %s was skipped because of a signing error', version) self.stats['error'] += 1 finally: # Always clear our own lock no matter what happens (but only ours). if not already_locked: clear_reviewing_cache(version.addon.pk)
def test_raise_when_action_is_invalid(self): # `12345` is an invalid action ID self.scanner_rule.update(action=12345) with pytest.raises(Exception, match='invalid action 12345'): ScannerResult.run_action(self.version)
def process(self, version): """Process a single version, figuring out if it should be auto-approved and calling the approval code if necessary.""" already_locked = AutoApprovalSummary.check_is_locked(version) if not already_locked: # Lock the addon for ourselves if possible. Even though # AutoApprovalSummary.create_summary_for_version() will do # call check_is_locked() again later when calculating the verdict, # we have to do it now to prevent overwriting an existing lock with # our own. set_reviewing_cache(version.addon.pk, settings.TASK_USER_ID) # Discard any existing celery tasks that may have been queued before: # If there are any left at this point, it means the transaction from # the previous loop iteration was not committed and we shouldn't # trigger the corresponding tasks. _discard_tasks() # Queue celery tasks for this version, avoiding triggering them too # soon... _start_queuing_tasks() try: with transaction.atomic(): # ...and release the queued tasks to celery once transaction # is committed. transaction.on_commit(_send_tasks_and_stop_queuing) log.info( 'Processing %s version %s...', str(version.addon.name), str(version.version), ) if waffle.switch_is_active('run-action-in-auto-approve'): # We want to execute `run_action()` only once. summary_exists = AutoApprovalSummary.objects.filter( version=version).exists() if summary_exists: log.info('Not running run_action() because it has ' 'already been executed') else: ScannerResult.run_action(version) summary, info = AutoApprovalSummary.create_summary_for_version( version, dry_run=self.dry_run) self.stats.update({k: int(v) for k, v in info.items()}) if summary.verdict == self.successful_verdict: if summary.verdict == amo.AUTO_APPROVED: self.approve(version) self.stats['auto_approved'] += 1 verdict_string = summary.get_verdict_display() else: verdict_string = '%s (%s)' % ( summary.get_verdict_display(), ', '.join(summary.verdict_info_prettifier(info)), ) log.info( 'Auto Approval for %s version %s: %s', str(version.addon.name), str(version.version), verdict_string, ) # At this point, any exception should have rolled back the transaction, # so even if we did create/update an AutoApprovalSummary instance that # should have been rolled back. This ensures that, for instance, a # signing error doesn't leave the version and its autoapprovalsummary # in conflicting states. except (AutoApprovalNotEnoughFilesError, AutoApprovalNoValidationResultError): log.info( 'Version %s was skipped either because it had no ' 'files or because it had no validation attached.', version, ) self.stats['error'] += 1 except SigningError: statsd.incr('reviewers.auto_approve.approve.failure') log.info('Version %s was skipped because of a signing error', version) self.stats['error'] += 1 finally: # Always clear our own lock no matter what happens (but only ours). if not already_locked: clear_reviewing_cache(version.addon.pk) # Stop post request task queue before moving on (useful in tests to # leave a fresh state for the next test. Note that we don't want to # send or clear queued tasks (they may belong to a transaction that # has been rolled back, or they may not have been processed by the # on commit handler yet). _stop_queuing_tasks()