Deleted Vulnerabilities::Export::Part records leave behind orphaned Upload records

Summary

When Vulnerabilities::Export::Part records are deleted, their associated Upload records are not cleaned up. This leaves orphaned uploads in the database that fail Geo verification with:

Skipping transfer due to validation error: The model which owns this upload is missing. upload ID#?, Vulnerabilities::Export::Part ID#?

Impact

  • No user-facing impact — the vulnerability export parts have been intentionally deleted.
  • Causes noise in Geo replication failure metrics on GitLab Dedicated (currently 250+ orphaned records across tenants).
  • Similar issues have been filed and fixed for other model types: Vulnerabilities::Remediation (#497516 (closed)), DesignManagement::Action (#497517), ImportExportUpload (#554288 (closed)).

Expected behaviour

Deleting a Vulnerabilities::Export::Part should also destroy its associated Upload record(s).

Workaround

On the primary Rails console, run the documented delete_orphaned_uploads method: https://docs.gitlab.com/administration/geo/replication/troubleshooting/synchronization_verification/#failed-verification-of-uploads-on-the-primary-geo-site

References

Edited by 🤖 GitLab Bot 🤖