-
Notifications
You must be signed in to change notification settings - Fork 472
chore: Migrate gsutil usage to gcloud storage #4239
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
chore: Migrate gsutil usage to gcloud storage #4239
Conversation
|
Hi @ashmeenkaur, Can we get your review on this PR? Thanks! |
Summary of ChangesHello @gurusai-voleti, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request automates the migration from the legacy Highlights
🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console. Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
This pull request automatically migrates gsutil commands to gcloud storage. The changes are generally correct and follow the migration guide. I've identified a few instances where shell=True is used with subprocess calls, which poses a security risk of command injection, especially since parts of the commands are constructed from configuration files. I've provided suggestions to refactor these calls to be more secure by avoiding shell=True.
| process = Popen( | ||
| 'gsutil -m cp -r {}/* {}'.format(TEMPORARY_DIRECTORY, | ||
| 'gcloud storage cp --recursive {}/* {}'.format(TEMPORARY_DIRECTORY, | ||
| destination_blob_name), | ||
| shell=True) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Using shell=True with Popen and string formatting can lead to shell injection vulnerabilities if destination_blob_name contains malicious characters from the config file. It's safer to pass arguments as a list and avoid shell=True. You can use an f-string with a trailing slash on the source directory to copy its contents recursively, which avoids shell globbing.
| process = Popen( | |
| 'gsutil -m cp -r {}/* {}'.format(TEMPORARY_DIRECTORY, | |
| 'gcloud storage cp --recursive {}/* {}'.format(TEMPORARY_DIRECTORY, | |
| destination_blob_name), | |
| shell=True) | |
| process = Popen([ | |
| 'gcloud', 'storage', 'cp', '--recursive', | |
| f'{TEMPORARY_DIRECTORY}/', destination_blob_name | |
| ], | |
| shell=False) |
| contents = subprocess.check_output( | ||
| 'gsutil -m ls {}'.format(path), shell=True) | ||
| 'gcloud storage ls {}'.format(path), shell=True) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Using shell=True with subprocess.check_output and string formatting can lead to shell injection vulnerabilities if path contains malicious characters from the config file. It's safer to pass arguments as a list and set shell=False.
| contents = subprocess.check_output( | |
| 'gsutil -m ls {}'.format(path), shell=True) | |
| 'gcloud storage ls {}'.format(path), shell=True) | |
| contents = subprocess.check_output( | |
| ['gcloud', 'storage', 'ls', path], shell=False) |
| subprocess.call( | ||
| 'gsutil -m rm -r gs://{}/*'.format(directory_structure.name), | ||
| 'gcloud storage rm --recursive gs://{}/*'.format(directory_structure.name), | ||
| shell=True, stdout=subprocess.DEVNULL, stderr=subprocess.STDOUT) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Using shell=True with subprocess.call and string formatting can lead to shell injection vulnerabilities if directory_structure.name contains malicious characters from the config file. It's safer to pass arguments as a list and set shell=False. The * wildcard will be interpreted by gcloud itself.
| subprocess.call( | |
| 'gsutil -m rm -r gs://{}/*'.format(directory_structure.name), | |
| 'gcloud storage rm --recursive gs://{}/*'.format(directory_structure.name), | |
| shell=True, stdout=subprocess.DEVNULL, stderr=subprocess.STDOUT) | |
| subprocess.call( | |
| ['gcloud', 'storage', 'rm', '--recursive', f'gs://{directory_structure.name}/*'], | |
| shell=False, stdout=subprocess.DEVNULL, stderr=subprocess.STDOUT) |
Automated: Migrate {target_path} from gsutil to gcloud storage
This CL is part of the on going effort to migrate from the legacy
gsutiltool to the new and improvedgcloud storagecommand-line interface.gcloud storageis the recommended and modern tool for interacting with Google Cloud Storage, offering better performance, unified authentication, and a more consistent command structure with othergcloudcomponents. 🚀Automation Details
This change was generated automatically by an agent that targets users of
gsutil.The transformations applied are based on the gsutil to gcloud storage migration guide.
While we have based the automation on the migration guide, every use case is unique.
It is crucial that you thoroughly test these changes in environments appropriate to your use-case before merging.
Be aware of potential differences between
gsutilandgcloud storagethat could impact your workflows.For instance, the structure of command output may have changed, requiring updates to any scripts that parse it. Similarly, command behavior can differ subtly; the
gcloud storage rsynccommand has a different file deletion logic thangsutil rsync, which could lead to unintended file deletions.Our migration guides can help guide you through a list of mappings and some notable differences between the two tools.
Standard presubmit tests are run as part of this CL's workflow. If you need to target an additional test workflow or require assistance with testing, please let us know.
Please verify that all your Cloud Storage operations continue to work as expected to avoid any potential disruptions in production.
Support and Collaboration
The
GCS CLIteam is here to help! If you encounter any issues, have a complex use case that this automated change doesn't cover, or face any other blockers, please don't hesitate to reach out.We are happy to work with you to test and adjust these changes as needed.
Contact:
[email protected]We appreciate your partnership in this important migration effort!
#gsutil-migration