Skip to content

Limit MySQL discovery to the configured database - #137

Closed
just-some-random-pal wants to merge 1 commit into
planetscale:mainfrom
just-some-random-pal:fix/mysql-database-scope
Closed

just-some-random-pal wants to merge 1 commit into
planetscale:mainfrom
just-some-random-pal:fix/mysql-database-scope

Conversation

@just-some-random-pal

@just-some-random-pal just-some-random-pal commented Oct 8, 2026 •

Copy link
Copy Markdown

mysql.database now scopes MySQL discovery the way MySQL Setup already says it does. Before, the setting only chose the connection's default database, and schema discovery scanned every non-system database on the server. Closes #124.

What changes:

  • run_analysis passes {"database": ...} to every MySQL analyzer, so the setting is available where the queries are built.
  • MySQLSchemaAnalyzer returns the configured database from _get_database_list without running SHOW DATABASES, and every information_schema query compares table_schema to that database instead of excluding the system databases.
  • MySQLFeatureAnalyzer applies the same filter to its schema-based checks (full-text indexes, spatial columns, foreign keys, partitions, InnoDB compression), so a feature in another database is no longer reported for the configured one.
  • An empty database keeps the current server-wide behavior, which the README and config template already describe as "discover all databases".
  • Configuration, performance, replication, and security checks stay server-wide, and the doc now says so, because those describe the instance rather than a schema.

The filter embeds the configured name as a hex literal (table_schema = 0x6170...) rather than a quoted string. The fragment is spliced into many queries that execute_query runs without parameters, and a hex literal keeps the name out of SQL syntax regardless of the connection's escaping mode. Left as a plain literal it has the same coercibility as the quoted system database names the file already compares against information_schema, so it takes the column's character set on every supported server rather than depending on a utf8mb3/utf8mb4 tie-break. A unit test checks that app' OR 1=1 reaches the server only as hex.

Verification:

  • Unit tests: five new cases in test_mysql_discovery.py, test_mysql_schema_analyzer.py, and test_mysql_feature_analyzer.py. The full suite, black, flake8, mypy, and bandit pass with the CI settings.
  • End to end against a MySQL 8.0 container with an app database and an other_app database that has a full-text index: with database: app the report lists only app in database_catalog and every schema list, and full_text_indexing is false. With database: "" both databases appear and full_text_indexing is true.
  • The hex literal matches a database name containing a quote and one containing non-ASCII characters, both against information_schema.schemata and against a utf8mb3_general_ci column, with the connection in utf8mb4 and in utf8mb3.

`mysql.database` now scopes schema discovery and schema-based feature
detection to one database, as docs/mysql.md already describes. An empty
value still discovers every user database. Configuration, performance,
replication, and security checks remain server-wide.

The configured name is embedded as a hex literal so it stays out of SQL
syntax and compares in the column's character set on every supported
server.

Closes planetscale#124
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MySQL: mysql.database does not limit discovery to one database

1 participant