blob: 98db9d42f84753b850494f06b9026dbe5f38f73d [file] [log] [blame]
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -08001#!/usr/bin/env python3
2# -*- coding: utf-8 -*-
George Burgess IV9e0cfde2022-09-27 15:08:15 -07003# Copyright 2021 The ChromiumOS Authors
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -08004# Use of this source code is governed by a BSD-style license that can be
5# found in the LICENSE file.
6""" This script cleans up the vendor directory.
7"""
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -07008import argparse
George Burgess IV635f7262022-08-09 21:32:20 -07009import collections
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +000010import hashlib
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -080011import json
12import os
13import pathlib
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -070014import re
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -070015import shutil
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +000016import subprocess
George Burgess IV04833702022-08-09 22:00:38 -070017import textwrap
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -070018import toml
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +000019
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -070020# We only care about crates we're actually going to use and that's usually
21# limited to ones with cfg(linux). For running `cargo metadata`, limit results
22# to only this platform
23DEFAULT_PLATFORM_FILTER = "x86_64-unknown-linux-gnu"
24
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +000025
26def _rerun_checksums(package_path):
27 """Re-run checksums for given package.
28
29 Writes resulting checksums to $package_path/.cargo-checksum.json.
30 """
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -070031 hashes = dict()
George Burgess IV7dffc252022-08-31 14:37:01 -070032 checksum_path = os.path.join(package_path, ".cargo-checksum.json")
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +000033 if not pathlib.Path(checksum_path).is_file():
34 return False
35
George Burgess IV7dffc252022-08-31 14:37:01 -070036 with open(checksum_path, "r") as fread:
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +000037 contents = json.load(fread)
38
39 for root, _, files in os.walk(package_path, topdown=True):
40 for f in files:
41 # Don't checksum an existing checksum file
42 if f == ".cargo-checksum.json":
43 continue
44
45 file_path = os.path.join(root, f)
George Burgess IV7dffc252022-08-31 14:37:01 -070046 with open(file_path, "rb") as frb:
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +000047 m = hashlib.sha256()
48 m.update(frb.read())
49 d = m.hexdigest()
50
51 # Key is relative to the package path so strip from beginning
52 key = os.path.relpath(file_path, package_path)
53 hashes[key] = d
54
55 if hashes:
George Burgess IV7dffc252022-08-31 14:37:01 -070056 print(
57 "{} regenerated {} hashes".format(package_path, len(hashes.keys()))
58 )
59 contents["files"] = hashes
60 with open(checksum_path, "w") as fwrite:
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -070061 json.dump(contents, fwrite, sort_keys=True)
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +000062
63 return True
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -080064
65
66def _remove_OWNERS_checksum(root):
George Burgess IV7dffc252022-08-31 14:37:01 -070067 """Delete all OWNERS files from the checksum file.
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -080068
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +000069 Args:
70 root: Root directory for the vendored crate.
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -080071
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +000072 Returns:
73 True if OWNERS was found and cleaned up. Otherwise False.
74 """
George Burgess IV7dffc252022-08-31 14:37:01 -070075 checksum_path = os.path.join(root, ".cargo-checksum.json")
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -080076 if not pathlib.Path(checksum_path).is_file():
77 return False
78
George Burgess IV7dffc252022-08-31 14:37:01 -070079 with open(checksum_path, "r") as fread:
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -080080 contents = json.load(fread)
81
82 del_keys = []
George Burgess IV7dffc252022-08-31 14:37:01 -070083 for cfile in contents["files"]:
84 if "OWNERS" in cfile:
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -080085 del_keys.append(cfile)
86
87 for key in del_keys:
George Burgess IV7dffc252022-08-31 14:37:01 -070088 del contents["files"][key]
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -080089
90 if del_keys:
George Burgess IV7dffc252022-08-31 14:37:01 -070091 print("{} deleted: {}".format(root, del_keys))
92 with open(checksum_path, "w") as fwrite:
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -070093 json.dump(contents, fwrite, sort_keys=True)
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -080094
95 return bool(del_keys)
96
97
98def cleanup_owners(vendor_path):
George Burgess IV7dffc252022-08-31 14:37:01 -070099 """Remove owners checksums from the vendor directory.
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -0800100
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000101 We currently do not check in the OWNERS files from vendored crates because
102 they interfere with the find-owners functionality in gerrit. This cleanup
103 simply finds all instances of "OWNERS" in the checksum files within and
104 removes them.
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -0800105
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000106 Args:
107 vendor_path: Absolute path to vendor directory.
108 """
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -0800109 deps_cleaned = []
110 for root, dirs, _ in os.walk(vendor_path):
111 for d in dirs:
112 removed = _remove_OWNERS_checksum(os.path.join(root, d))
113 if removed:
114 deps_cleaned.append(d)
115
116 if deps_cleaned:
George Burgess IV7dffc252022-08-31 14:37:01 -0700117 print("Cleanup owners:\n {}".format("\n".join(deps_cleaned)))
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -0800118
119
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000120def apply_single_patch(patch, workdir):
121 """Apply a single patch and return whether it was successful.
122
123 Returns:
124 True if successful. False otherwise.
125 """
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000126 proc = subprocess.run(["patch", "-p1", "-i", patch], cwd=workdir)
127 return proc.returncode == 0
128
129
George Burgess IV30c5c362022-08-19 17:05:02 -0700130def apply_patch_script(script, workdir):
131 """Run the given patch script, returning whether it exited cleanly.
132
133 Returns:
134 True if successful. False otherwise.
135 """
136 return subprocess.run([script], cwd=workdir).returncode == 0
137
138
George Burgess IV635f7262022-08-09 21:32:20 -0700139def determine_vendor_crates(vendor_path):
140 """Returns a map of {crate_name: [directory]} at the given vendor_path."""
141 result = collections.defaultdict(list)
142 for crate_name_plus_ver in os.listdir(vendor_path):
George Burgess IV7dffc252022-08-31 14:37:01 -0700143 name, _ = crate_name_plus_ver.rsplit("-", 1)
George Burgess IV40cc91c2022-08-15 13:07:40 -0700144 result[name].append(crate_name_plus_ver)
George Burgess IV635f7262022-08-09 21:32:20 -0700145
146 for crate_list in result.values():
George Burgess IV40cc91c2022-08-15 13:07:40 -0700147 crate_list.sort()
George Burgess IV635f7262022-08-09 21:32:20 -0700148 return result
149
150
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000151def apply_patches(patches_path, vendor_path):
152 """Finds patches and applies them to sub-folders in the vendored crates.
153
154 Args:
155 patches_path: Path to folder with patches. Expect all patches to be one
156 level down (matching the crate name).
157 vendor_path: Root path to vendored crates directory.
158 """
159 checksums_for = {}
160
161 # Don't bother running if patches directory is empty
162 if not pathlib.Path(patches_path).is_dir():
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700163 return
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000164
George Burgess IV30c5c362022-08-19 17:05:02 -0700165 patches_failed = False
George Burgess IV635f7262022-08-09 21:32:20 -0700166 vendor_crate_map = determine_vendor_crates(vendor_path)
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000167 # Look for all patches and apply them
168 for d in os.listdir(patches_path):
169 dir_path = os.path.join(patches_path, d)
170
171 # We don't process patches in root dir
172 if not os.path.isdir(dir_path):
173 continue
174
George Burgess IV30c5c362022-08-19 17:05:02 -0700175 # We accept one of two forms here:
176 # - direct targets (these name # `${crate_name}-${version}`)
177 # - simply the crate name (which applies to all versions of the
178 # crate)
179 direct_target = os.path.join(vendor_path, d)
180 if os.path.isdir(direct_target):
181 patch_targets = [d]
182 elif d in vendor_crate_map:
183 patch_targets = vendor_crate_map[d]
184 else:
George Burgess IV7dffc252022-08-31 14:37:01 -0700185 raise RuntimeError(f"Unknown crate in {vendor_path}: {d}")
George Burgess IV30c5c362022-08-19 17:05:02 -0700186
George Burgess IV635f7262022-08-09 21:32:20 -0700187 for patch in os.listdir(dir_path):
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000188 file_path = os.path.join(dir_path, patch)
189
190 # Skip if not a patch file
George Burgess IV30c5c362022-08-19 17:05:02 -0700191 if not os.path.isfile(file_path):
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000192 continue
193
George Burgess IV30c5c362022-08-19 17:05:02 -0700194 if patch.endswith(".patch"):
195 apply = apply_single_patch
196 elif os.access(file_path, os.X_OK):
197 apply = apply_patch_script
George Burgess IV635f7262022-08-09 21:32:20 -0700198 else:
George Burgess IV30c5c362022-08-19 17:05:02 -0700199 # Unrecognized. Skip it.
200 continue
201
202 for target_name in patch_targets:
203 checksums_for[target_name] = True
204 target = os.path.join(vendor_path, target_name)
205 print(f"-- Applying {file_path} to {target}")
206 if not apply(file_path, target):
207 print(f"Failed to apply {file_path} to {target}")
208 patches_failed = True
209
210 # Do this late, so we can report all of the failing patches in one
211 # invocation.
212 if patches_failed:
George Burgess IV7dffc252022-08-31 14:37:01 -0700213 raise ValueError("Patches failed; please see above logs")
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000214
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000215 # Re-run checksums for all modified packages since we applied patches.
216 for key in checksums_for.keys():
217 _rerun_checksums(os.path.join(vendor_path, key))
218
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700219
George Burgess IV18af5632022-08-30 14:10:53 -0700220def get_workspace_cargo_toml(working_dir):
George Burgess IV40cc91c2022-08-15 13:07:40 -0700221 """Returns all Cargo.toml files under working_dir."""
George Burgess IV7dffc252022-08-31 14:37:01 -0700222 return [working_dir / "projects" / "Cargo.toml"]
George Burgess IV40cc91c2022-08-15 13:07:40 -0700223
224
Abhishek Pandit-Subedifa902382021-08-20 11:04:33 -0700225def run_cargo_vendor(working_dir):
226 """Runs cargo vendor.
227
228 Args:
229 working_dir: Directory to run inside. This should be the directory where
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700230 Cargo.toml is kept.
Abhishek Pandit-Subedifa902382021-08-20 11:04:33 -0700231 """
George Burgess IV635f7262022-08-09 21:32:20 -0700232 # Cargo will refuse to revendor into versioned directories, which leads to
233 # repeated `./vendor.py` invocations trying to apply patches to
234 # already-patched sources. Remove the existing vendor directory to avoid
235 # this.
George Burgess IV7dffc252022-08-31 14:37:01 -0700236 vendor_dir = working_dir / "vendor"
George Burgess IV635f7262022-08-09 21:32:20 -0700237 if vendor_dir.exists():
George Burgess IV40cc91c2022-08-15 13:07:40 -0700238 shutil.rmtree(vendor_dir)
239
George Burgess IV18af5632022-08-30 14:10:53 -0700240 cargo_cmdline = [
George Burgess IV7dffc252022-08-31 14:37:01 -0700241 "cargo",
242 "vendor",
243 "--versioned-dirs",
244 "-v",
245 "--manifest-path=projects/Cargo.toml",
246 "--",
247 "vendor",
George Burgess IV18af5632022-08-30 14:10:53 -0700248 ]
George Burgess IV40cc91c2022-08-15 13:07:40 -0700249 subprocess.check_call(cargo_cmdline, cwd=working_dir)
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000250
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700251
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700252def load_metadata(working_dir, filter_platform=DEFAULT_PLATFORM_FILTER):
George Burgess IV40cc91c2022-08-15 13:07:40 -0700253 """Load metadata for all projects under a given directory.
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700254
255 Args:
George Burgess IV40cc91c2022-08-15 13:07:40 -0700256 working_dir: Base directory to run from.
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700257 filter_platform: Filter packages to ones configured for this platform.
258 """
George Burgess IV40cc91c2022-08-15 13:07:40 -0700259 metadata_objects = []
George Burgess IV18af5632022-08-30 14:10:53 -0700260 cmd = [
George Burgess IV7dffc252022-08-31 14:37:01 -0700261 "cargo",
262 "metadata",
263 "--format-version=1",
264 "--manifest-path=projects/Cargo.toml",
George Burgess IV18af5632022-08-30 14:10:53 -0700265 ]
266 # Conditionally add platform filter
267 if filter_platform:
268 cmd += ("--filter-platform", filter_platform)
269 output = subprocess.check_output(cmd, cwd=working_dir)
270 return json.loads(output)
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700271
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700272
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700273class LicenseManager:
George Burgess IV7dffc252022-08-31 14:37:01 -0700274 """Manage consolidating licenses for all packages."""
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700275
George Burgess IV124e6a12022-09-09 10:44:29 -0700276 # These are all the licenses we support. Keys are what is seen in metadata
277 # and values are what is expected by ebuilds.
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700278 SUPPORTED_LICENSES = {
George Burgess IV7dffc252022-08-31 14:37:01 -0700279 "0BSD": "0BSD",
280 "Apache-2.0": "Apache-2.0",
281 "BSD-3-Clause": "BSD-3",
282 "ISC": "ISC",
283 "MIT": "MIT",
284 "MPL-2.0": "MPL-2.0",
285 "unicode": "unicode",
Dan Callaghan91f80542022-09-09 10:57:23 +1000286 "Zlib": "ZLIB",
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700287 }
288
289 # Prefer to take attribution licenses in this order. All these require that
290 # we actually use the license file found in the package so they MUST have
291 # a license file set.
George Burgess IV7dffc252022-08-31 14:37:01 -0700292 PREFERRED_ATTRIB_LICENSE_ORDER = ["MIT", "BSD-3", "ISC"]
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700293
294 # If Apache license is found, always prefer it (simplifies attribution)
George Burgess IV7dffc252022-08-31 14:37:01 -0700295 APACHE_LICENSE = "Apache-2.0"
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700296
297 # Regex for license files found in the vendored directories. Search for
298 # these files with re.IGNORECASE.
299 #
300 # These will be searched in order with the earlier entries being preferred.
301 LICENSE_NAMES_REGEX = [
George Burgess IV7dffc252022-08-31 14:37:01 -0700302 r"^license-mit$",
303 r"^copyright$",
304 r"^licen[cs]e.*$",
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700305 ]
306
307 # Some crates have their license file in other crates. This usually occurs
308 # because multiple crates are published from the same git repository and the
309 # license isn't updated in each sub-crate. In these cases, we can just
310 # ignore these packages.
311 MAP_LICENSE_TO_OTHER = {
George Burgess IV7dffc252022-08-31 14:37:01 -0700312 "failure_derive": "failure",
313 "grpcio-compiler": "grpcio",
314 "grpcio-sys": "grpcio",
315 "rustyline-derive": "rustyline",
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700316 }
317
318 # Map a package to a specific license and license file. Only use this if
319 # a package doesn't have an easily discoverable license or exports its
320 # license in a weird way. Prefer to patch the project with a license and
321 # upstream the patch instead.
322 STATIC_LICENSE_MAP = {
323 # "package name": ( "license name", "license file relative location")
George Burgess IVf4a5e362022-08-30 14:30:36 -0700324 # Patch for adding this is upstream, but the patch application doesn't
325 # apply to `cargo metadata`. This is presumably because it can't detect
326 # our vendor directory.
327 # https://gitlab.freedesktop.org/slirp/libslirp-sys/-/merge_requests/6
George Burgess IV7dffc252022-08-31 14:37:01 -0700328 "libslirp-sys": ("MIT", "LICENSE"),
Dan Callaghan91f80542022-09-09 10:57:23 +1000329 # Upstream prefers to embed license text inside README.md:
330 "riscv": ("ISC", "README.md"),
331 "riscv-rt": ("ISC", "README.md"),
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700332 }
333
334 def __init__(self, working_dir, vendor_dir):
335 self.working_dir = working_dir
336 self.vendor_dir = vendor_dir
337
338 def _find_license_in_dir(self, search_dir):
339 for p in os.listdir(search_dir):
340 # Ignore anything that's not a file
341 if not os.path.isfile(os.path.join(search_dir, p)):
342 continue
343
344 # Now check if the name matches any of the regexes
345 # We'll return the first matching file.
346 for regex in self.LICENSE_NAMES_REGEX:
347 if re.search(regex, p, re.IGNORECASE):
348 yield os.path.join(search_dir, p)
349 break
350
351 def _guess_license_type(self, license_file):
George Burgess IV7dffc252022-08-31 14:37:01 -0700352 if "-MIT" in license_file:
353 return "MIT"
354 elif "-APACHE" in license_file:
355 return "APACHE"
356 elif "-BSD" in license_file:
357 return "BSD-3"
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700358
George Burgess IV7dffc252022-08-31 14:37:01 -0700359 with open(license_file, "r") as f:
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700360 lines = f.read()
George Burgess IV7dffc252022-08-31 14:37:01 -0700361 if "MIT" in lines:
362 return "MIT"
363 elif "Apache" in lines:
364 return "APACHE"
365 elif "BSD 3-Clause" in lines:
366 return "BSD-3"
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700367
George Burgess IV7dffc252022-08-31 14:37:01 -0700368 return ""
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700369
George Burgess IV7dffc252022-08-31 14:37:01 -0700370 def generate_license(
371 self, skip_license_check, print_map_to_file, license_shorthand_file
372 ):
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700373 """Generate single massive license file from metadata."""
George Burgess IV18af5632022-08-30 14:10:53 -0700374 metadata = load_metadata(self.working_dir)
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700375
376 has_license_types = set()
377 bad_licenses = {}
378
379 # Keep license map ordered so it generates a consistent license map
380 license_map = {}
381
382 skip_license_check = skip_license_check or []
George Burgess IV4ae42062022-08-15 18:54:51 -0700383 has_unicode_license = False
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700384
George Burgess IV18af5632022-08-30 14:10:53 -0700385 for package in metadata["packages"]:
George Burgess IV40cc91c2022-08-15 13:07:40 -0700386 # Skip the synthesized Cargo.toml packages that exist solely to
387 # list dependencies.
George Burgess IV7dffc252022-08-31 14:37:01 -0700388 if "path+file:///" in package["id"]:
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700389 continue
390
George Burgess IV7dffc252022-08-31 14:37:01 -0700391 pkg_name = package["name"]
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700392 if pkg_name in skip_license_check:
393 print(
George Burgess IV7dffc252022-08-31 14:37:01 -0700394 "Skipped license check on {}. Reason: Skipped from command line".format(
395 pkg_name
396 )
397 )
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700398 continue
399
400 if pkg_name in self.MAP_LICENSE_TO_OTHER:
401 print(
George Burgess IV7dffc252022-08-31 14:37:01 -0700402 "Skipped license check on {}. Reason: License already in {}".format(
403 pkg_name, self.MAP_LICENSE_TO_OTHER[pkg_name]
404 )
405 )
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700406 continue
407
408 # Check if we have a static license map for this package. Use the
409 # static values if we have it already set.
410 if pkg_name in self.STATIC_LICENSE_MAP:
411 (license, license_file) = self.STATIC_LICENSE_MAP[pkg_name]
412 license_map[pkg_name] = {
413 "license": license,
414 "license_file": license_file,
415 }
416 continue
417
418 license_files = []
George Burgess IV93ba4732022-08-13 14:10:10 -0700419 # use `or ''` instead of get's default, since `package` may have a
420 # None value for 'license'.
George Burgess IV7dffc252022-08-31 14:37:01 -0700421 license = package.get("license") or ""
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700422
423 # We ignore the metadata for license file because most crates don't
424 # have it set. Just scan the source for licenses.
George Burgess IV7dffc252022-08-31 14:37:01 -0700425 pkg_version = package["version"]
426 license_files = list(
427 self._find_license_in_dir(
428 os.path.join(self.vendor_dir, f"{pkg_name}-{pkg_version}")
429 )
430 )
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700431
George Burgess IV4ae42062022-08-15 18:54:51 -0700432 # FIXME(b/240953811): The code later in this loop is only
433 # structured to handle ORs, not ANDs. Fortunately, this license in
434 # particular is `AND`ed between a super common license (Apache) and
435 # a more obscure one (unicode). This hack is specifically intended
436 # for the `unicode-ident` crate, though no crate name check is
437 # made, since it's OK other crates happen to have this license.
George Burgess IV7dffc252022-08-31 14:37:01 -0700438 if license == "(MIT OR Apache-2.0) AND Unicode-DFS-2016":
George Burgess IV4ae42062022-08-15 18:54:51 -0700439 has_unicode_license = True
440 # We'll check later to be sure MIT or Apache-2.0 is represented
441 # properly.
442 for x in license_files:
George Burgess IV7dffc252022-08-31 14:37:01 -0700443 if os.path.basename(x) == "LICENSE-UNICODE":
George Burgess IV4ae42062022-08-15 18:54:51 -0700444 license_file = x
445 break
446 else:
George Burgess IV7dffc252022-08-31 14:37:01 -0700447 raise ValueError(
448 "No LICENSE-UNICODE found in " f"{license_files}"
449 )
George Burgess IV4ae42062022-08-15 18:54:51 -0700450 license_map[pkg_name] = {
451 "license": license,
452 "license_file": license_file,
453 }
George Burgess IV7dffc252022-08-31 14:37:01 -0700454 has_license_types.add("unicode")
George Burgess IV4ae42062022-08-15 18:54:51 -0700455 continue
456
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700457 # If there are multiple licenses, they are delimited with "OR" or "/"
George Burgess IV7dffc252022-08-31 14:37:01 -0700458 delim = " OR " if " OR " in license else "/"
George Burgess IV40cc91c2022-08-15 13:07:40 -0700459 found = [x.strip() for x in license.split(delim)]
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700460
461 # Filter licenses to ones we support
462 licenses_or = [
George Burgess IV7dffc252022-08-31 14:37:01 -0700463 self.SUPPORTED_LICENSES[f]
464 for f in found
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700465 if f in self.SUPPORTED_LICENSES
466 ]
467
468 # If apache license is found, always prefer it because it simplifies
469 # license attribution (we can use existing Apache notice)
470 if self.APACHE_LICENSE in licenses_or:
471 has_license_types.add(self.APACHE_LICENSE)
George Burgess IV7dffc252022-08-31 14:37:01 -0700472 license_map[pkg_name] = {"license": self.APACHE_LICENSE}
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700473
474 # Handle single license that has at least one license file
475 # We pick the first license file and the license
476 elif len(licenses_or) == 1:
477 if license_files:
478 l = licenses_or[0]
479 lf = license_files[0]
480
481 has_license_types.add(l)
482 license_map[pkg_name] = {
George Burgess IV7dffc252022-08-31 14:37:01 -0700483 "license": l,
484 "license_file": os.path.relpath(lf, self.working_dir),
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700485 }
486 else:
487 bad_licenses[pkg_name] = "{} missing license file".format(
George Burgess IV7dffc252022-08-31 14:37:01 -0700488 licenses_or[0]
489 )
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700490 # Handle multiple licenses
491 elif len(licenses_or) > 1:
492 # Check preferred licenses in order
493 license_found = False
494 for l in self.PREFERRED_ATTRIB_LICENSE_ORDER:
495 if not l in licenses_or:
496 continue
497
498 for f in license_files:
499 if self._guess_license_type(f) == l:
500 license_found = True
501 has_license_types.add(l)
502 license_map[pkg_name] = {
George Burgess IV7dffc252022-08-31 14:37:01 -0700503 "license": l,
504 "license_file": os.path.relpath(
505 f, self.working_dir
506 ),
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700507 }
508 break
509
510 # Break out of loop if license is found
511 if license_found:
512 break
513 else:
514 bad_licenses[pkg_name] = license
515
516 # If we had any bad licenses, we need to abort
517 if bad_licenses:
518 for k in bad_licenses.keys():
George Burgess IV7dffc252022-08-31 14:37:01 -0700519 print(
520 "{} had no acceptable licenses: {}".format(
521 k, bad_licenses[k]
522 )
523 )
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700524 raise Exception("Bad licenses in vendored packages.")
525
526 # Write license map to file
527 if print_map_to_file:
George Burgess IV7dffc252022-08-31 14:37:01 -0700528 with open(
529 os.path.join(self.working_dir, print_map_to_file), "w"
530 ) as lfile:
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700531 json.dump(license_map, lfile, sort_keys=True)
532
533 # Raise missing licenses unless we have a valid reason to ignore them
534 raise_missing_license = False
535 for name, v in license_map.items():
George Burgess IV7dffc252022-08-31 14:37:01 -0700536 if (
537 "license_file" not in v
538 and v.get("license", "") != self.APACHE_LICENSE
539 ):
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700540 raise_missing_license = True
George Burgess IV7dffc252022-08-31 14:37:01 -0700541 print(
542 " {}: Missing license file. Fix or add to ignorelist.".format(
543 name
544 )
545 )
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700546
547 if raise_missing_license:
548 raise Exception(
549 "Unhandled missing license file. "
George Burgess IV7dffc252022-08-31 14:37:01 -0700550 "Make sure all are accounted for before continuing."
551 )
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700552
George Burgess IV4ae42062022-08-15 18:54:51 -0700553 if has_unicode_license:
554 if self.APACHE_LICENSE not in has_license_types:
George Burgess IV7dffc252022-08-31 14:37:01 -0700555 raise ValueError(
556 "Need the apache license; currently have: "
557 f"{sorted(has_license_types)}"
558 )
George Burgess IV4ae42062022-08-15 18:54:51 -0700559
George Burgess IV04833702022-08-09 22:00:38 -0700560 sorted_licenses = sorted(has_license_types)
George Burgess IV124e6a12022-09-09 10:44:29 -0700561 print("The following licenses are in use:", sorted_licenses)
George Burgess IV7dffc252022-08-31 14:37:01 -0700562 header = textwrap.dedent(
563 """\
George Burgess IV04833702022-08-09 22:00:38 -0700564 # File to describe the licenses used by this registry.
Daniel Verkampd9d085b2022-09-07 10:52:27 -0700565 # Used so it's easy to automatically verify ebuilds are updated.
George Burgess IV04833702022-08-09 22:00:38 -0700566 # Each line is a license. Lines starting with # are comments.
George Burgess IV7dffc252022-08-31 14:37:01 -0700567 """
568 )
569 with open(license_shorthand_file, "w", encoding="utf-8") as f:
George Burgess IV04833702022-08-09 22:00:38 -0700570 f.write(header)
George Burgess IV7dffc252022-08-31 14:37:01 -0700571 f.write("\n".join(sorted_licenses))
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700572
573
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700574# TODO(abps) - This needs to be replaced with datalog later. We should compile
575# all crab files into datalog and query it with our requirements
576# instead.
577class CrabManager:
578 """Manage audit files."""
George Burgess IV7dffc252022-08-31 14:37:01 -0700579
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700580 def __init__(self, working_dir, crab_dir):
581 self.working_dir = working_dir
582 self.crab_dir = crab_dir
583
584 def _check_bad_traits(self, crabdata):
585 """Checks that a package's crab audit meets our requirements.
586
587 Args:
588 crabdata: Dict with crab keys in standard templated format.
589 """
George Burgess IV7dffc252022-08-31 14:37:01 -0700590 common = crabdata["common"]
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700591 # TODO(b/200578411) - Figure out what conditions we should enforce as
592 # part of the audit.
593 conditions = [
George Burgess IV7dffc252022-08-31 14:37:01 -0700594 common.get("deny", None),
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700595 ]
596
597 # If any conditions are true, this crate is not acceptable.
598 return any(conditions)
599
600 def verify_traits(self):
George Burgess IV7dffc252022-08-31 14:37:01 -0700601 """Verify that all required CRAB traits for this repository are met."""
George Burgess IV18af5632022-08-30 14:10:53 -0700602 metadata = load_metadata(self.working_dir)
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700603
604 failing_crates = {}
605
606 # Verify all packages have a CRAB file associated with it and they meet
607 # all our required traits
George Burgess IV18af5632022-08-30 14:10:53 -0700608 for package in metadata["packages"]:
George Burgess IV40cc91c2022-08-15 13:07:40 -0700609 # Skip the synthesized Cargo.toml packages that exist solely to
610 # list dependencies.
George Burgess IV7dffc252022-08-31 14:37:01 -0700611 if "path+file:///" in package["id"]:
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700612 continue
613
George Burgess IV7dffc252022-08-31 14:37:01 -0700614 crabname = "{}-{}".format(package["name"], package["version"])
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700615 filename = os.path.join(self.crab_dir, "{}.toml".format(crabname))
616
617 # If crab file doesn't exist, the crate fails
618 if not os.path.isfile(filename):
619 failing_crates[crabname] = "No crab file".format(filename)
620 continue
621
George Burgess IV7dffc252022-08-31 14:37:01 -0700622 with open(filename, "r") as f:
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700623 crabdata = toml.loads(f.read())
624
625 # If crab file's crate_name and version keys don't match this
626 # package, it also fails. This is just housekeeping...
George Burgess IV7dffc252022-08-31 14:37:01 -0700627 if (
628 package["name"] != crabdata["crate_name"]
629 or package["version"] != crabdata["version"]
630 ):
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700631 failing_crates[crabname] = "Crate name or version don't match"
632 continue
633
634 if self._check_bad_traits(crabdata):
635 failing_crates[crabname] = "Failed bad traits check"
636
George Burgess IV9e0cfde2022-09-27 15:08:15 -0700637 # If we had any failing crates, list them now, and exit with an error.
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700638 if failing_crates:
George Burgess IV7dffc252022-08-31 14:37:01 -0700639 print("Failed CRAB audit:")
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700640 for k, v in failing_crates.items():
George Burgess IV9e0cfde2022-09-27 15:08:15 -0700641 print(f" {k}: {v}")
642 raise ValueError("CRAB audit did not complete successfully.")
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700643
644
George Burgess IVd4ff0502022-08-14 23:27:57 -0700645def clean_features_in_place(cargo_toml):
646 """Removes all side-effects of features in `cargo_toml`."""
George Burgess IV7dffc252022-08-31 14:37:01 -0700647 features = cargo_toml.get("features")
George Burgess IVd4ff0502022-08-14 23:27:57 -0700648 if not features:
649 return
650
651 for name, value in features.items():
George Burgess IV7dffc252022-08-31 14:37:01 -0700652 if name != "default":
George Burgess IVd4ff0502022-08-14 23:27:57 -0700653 features[name] = []
654
655
George Burgess IV0313d782022-08-15 23:45:44 -0700656def remove_all_target_dependencies_in_place(cargo_toml):
George Burgess IVd4ff0502022-08-14 23:27:57 -0700657 """Removes all `target.*.dependencies` from `cargo_toml`."""
George Burgess IV7dffc252022-08-31 14:37:01 -0700658 target = cargo_toml.get("target")
George Burgess IVd4ff0502022-08-14 23:27:57 -0700659 if not target:
660 return
George Burgess IV0313d782022-08-15 23:45:44 -0700661
George Burgess IVd4ff0502022-08-14 23:27:57 -0700662 empty_keys = []
663 for key, values in target.items():
George Burgess IV7dffc252022-08-31 14:37:01 -0700664 values.pop("dependencies", None)
665 values.pop("dev-dependencies", None)
George Burgess IVd4ff0502022-08-14 23:27:57 -0700666 if not values:
667 empty_keys.append(key)
George Burgess IV0313d782022-08-15 23:45:44 -0700668
George Burgess IVd4ff0502022-08-14 23:27:57 -0700669 if len(empty_keys) == len(target):
George Burgess IV7dffc252022-08-31 14:37:01 -0700670 del cargo_toml["target"]
George Burgess IVd4ff0502022-08-14 23:27:57 -0700671 else:
672 for key in empty_keys:
673 del target[key]
George Burgess IV0313d782022-08-15 23:45:44 -0700674
675
George Burgess IV7dffc252022-08-31 14:37:01 -0700676class CrateDestroyer:
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700677 LIB_RS_BODY = """compile_error!("This crate cannot be built for this configuration.");\n"""
678
679 def __init__(self, working_dir, vendor_dir):
680 self.working_dir = working_dir
681 self.vendor_dir = vendor_dir
682
683 def _modify_cargo_toml(self, pkg_path):
George Burgess IV7dffc252022-08-31 14:37:01 -0700684 with open(os.path.join(pkg_path, "Cargo.toml"), "r") as cargo:
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700685 contents = toml.load(cargo)
686
George Burgess IV7dffc252022-08-31 14:37:01 -0700687 package = contents["package"]
George Burgess IVd4ff0502022-08-14 23:27:57 -0700688
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700689 # Change description, license and delete license key
George Burgess IV7dffc252022-08-31 14:37:01 -0700690 package["description"] = "Empty crate that should not build."
691 package["license"] = "Apache-2.0"
George Burgess IVd4ff0502022-08-14 23:27:57 -0700692
George Burgess IV7dffc252022-08-31 14:37:01 -0700693 package.pop("license_file", None)
George Burgess IVd4ff0502022-08-14 23:27:57 -0700694 # If there's no build.rs but we specify `links = "foo"`, Cargo gets
695 # upset.
George Burgess IV7dffc252022-08-31 14:37:01 -0700696 package.pop("links", None)
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700697
George Burgess IV0313d782022-08-15 23:45:44 -0700698 # Some packages have cfg-specific dependencies. Remove them here; we
699 # don't care about the dependencies of an empty package.
700 #
701 # This is a load-bearing optimization: `dev-python/toml` doesn't
702 # always round-trip dumps(loads(x)) correctly when `x` has keys with
703 # strings (b/242589711#comment3). The place this has bitten us so far
704 # is target dependencies, which can be harmlessly removed for now.
George Burgess IVd4ff0502022-08-14 23:27:57 -0700705 #
706 # Cleaning features in-place is also necessary, since we're removing
707 # dependencies, and a feature can enable features in dependencies.
708 # Cargo errors out on `[features] foo = "bar/baz"` if `bar` isn't a
709 # dependency.
710 clean_features_in_place(contents)
George Burgess IV0313d782022-08-15 23:45:44 -0700711 remove_all_target_dependencies_in_place(contents)
712
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700713 with open(os.path.join(pkg_path, "Cargo.toml"), "w") as cargo:
714 toml.dump(contents, cargo)
715
716 def _replace_source_contents(self, package_path):
717 # First load the checksum file before starting
718 checksum_file = os.path.join(package_path, ".cargo-checksum.json")
George Burgess IV7dffc252022-08-31 14:37:01 -0700719 with open(checksum_file, "r") as csum:
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700720 checksum_contents = json.load(csum)
721
722 # Also load the cargo.toml file which we need to write back
723 cargo_file = os.path.join(package_path, "Cargo.toml")
George Burgess IV7dffc252022-08-31 14:37:01 -0700724 with open(cargo_file, "rb") as cfile:
George Burgess IV3e344e42022-08-09 21:07:04 -0700725 cargo_contents = cfile.read()
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700726
727 shutil.rmtree(package_path)
728
729 # Make package and src dirs and replace lib.rs
730 os.makedirs(os.path.join(package_path, "src"), exist_ok=True)
731 with open(os.path.join(package_path, "src", "lib.rs"), "w") as librs:
732 librs.write(self.LIB_RS_BODY)
733
734 # Restore cargo.toml
George Burgess IV7dffc252022-08-31 14:37:01 -0700735 with open(cargo_file, "wb") as cfile:
George Burgess IV3e344e42022-08-09 21:07:04 -0700736 cfile.write(cargo_contents)
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700737
738 # Restore checksum
George Burgess IV7dffc252022-08-31 14:37:01 -0700739 with open(checksum_file, "w") as csum:
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700740 json.dump(checksum_contents, csum)
741
742 def destroy_unused_crates(self):
George Burgess IV18af5632022-08-30 14:10:53 -0700743 metadata = load_metadata(self.working_dir, filter_platform=None)
George Burgess IV7dffc252022-08-31 14:37:01 -0700744 used_packages = {
745 p["name"] for p in load_metadata(self.working_dir)["packages"]
746 }
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700747
748 cleaned_packages = []
George Burgess IV40cc91c2022-08-15 13:07:40 -0700749 # Since we're asking for _all_ metadata packages, we may see
750 # duplication.
George Burgess IV18af5632022-08-30 14:10:53 -0700751 for package in metadata["packages"]:
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700752 # Skip used packages
753 if package["name"] in used_packages:
754 continue
755
756 # Detect the correct package path to destroy
George Burgess IV7dffc252022-08-31 14:37:01 -0700757 pkg_path = os.path.join(
758 self.vendor_dir,
759 "{}-{}".format(package["name"], package["version"]),
760 )
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700761 if not os.path.isdir(pkg_path):
George Burgess IV635f7262022-08-09 21:32:20 -0700762 print(f'Crate {package["name"]} not found at {pkg_path}')
763 continue
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700764
765 self._replace_source_contents(pkg_path)
766 self._modify_cargo_toml(pkg_path)
767 _rerun_checksums(pkg_path)
768 cleaned_packages.append(package["name"])
769
770 for pkg in cleaned_packages:
George Burgess IV635f7262022-08-09 21:32:20 -0700771 print("Removed unused crate", pkg)
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700772
George Burgess IV7dffc252022-08-31 14:37:01 -0700773
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700774def main(args):
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -0800775 current_path = pathlib.Path(__file__).parent.absolute()
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000776 patches = os.path.join(current_path, "patches")
777 vendor = os.path.join(current_path, "vendor")
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700778 crab_dir = os.path.join(current_path, "crab", "crates")
George Burgess IV04833702022-08-09 22:00:38 -0700779 license_shorthand_file = os.path.join(current_path, "licenses_used.txt")
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -0800780
Abhishek Pandit-Subedifa902382021-08-20 11:04:33 -0700781 # First, actually run cargo vendor
782 run_cargo_vendor(current_path)
783
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000784 # Order matters here:
785 # - Apply patches (also re-calculates checksums)
786 # - Cleanup any owners files (otherwise, git check-in or checksums are
787 # unhappy)
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700788 # - Destroy unused crates
Abhishek Pandit-Subedi5065a0f2021-06-13 20:38:55 +0000789 apply_patches(patches, vendor)
790 cleanup_owners(vendor)
Abhishek Pandit-Subedif0eb6e02021-09-24 16:36:12 -0700791 destroyer = CrateDestroyer(current_path, vendor)
792 destroyer.destroy_unused_crates()
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -0800793
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700794 # Combine license file and check for any bad licenses
795 lm = LicenseManager(current_path, vendor)
George Burgess IV7dffc252022-08-31 14:37:01 -0700796 lm.generate_license(
797 args.skip_license_check, args.license_map, license_shorthand_file
798 )
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700799
Abhishek Pandit-Subedice0f5b22021-09-10 15:50:08 -0700800 # Run crab audit on all packages
801 crab = CrabManager(current_path, crab_dir)
802 crab.verify_traits()
803
Abhishek Pandit-Subedib75bd562021-02-25 15:32:22 -0800804
George Burgess IV7dffc252022-08-31 14:37:01 -0700805if __name__ == "__main__":
806 parser = argparse.ArgumentParser(description="Vendor packages properly")
807 parser.add_argument(
808 "--skip-license-check",
809 "-s",
810 help="Skip the license check on a specific package",
811 action="append",
812 )
813 parser.add_argument("--license-map", help="Write license map to this file")
Abhishek Pandit-Subedie393cb72021-08-22 10:41:13 -0700814 args = parser.parse_args()
815
816 main(args)