fix(scanner): Do not end checkout paths of nested projects with a '/' - #12507
antoni67cf wants to merge 1 commit into
Conversation
3f62c66 to
c10de35
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #12507 +/- ##
=========================================
Coverage 59.21% 59.21%
Complexity 1892 1892
=========================================
Files 366 366
Lines 13839 13839
Branches 1462 1462
=========================================
Hits 8195 8195
+ Misses 5115 5114 -1
- Partials 529 530 +1
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
| import org.ossreviewtoolkit.model.config.ScannerConfiguration | ||
| import org.ossreviewtoolkit.scanner.provenance.NestedProvenance | ||
|
|
||
| class CheckoutPathsForProvenanceTest : WordSpec({ |
There was a problem hiding this comment.
Please make the change in a way so that the test easier to maintain. This is a lot of code
for this little logic.
There was a problem hiding this comment.
Done, thanks. Dropped the standalone spec and made getCheckoutPathsForProvenance() private again. The fix is now covered by a single end-to-end case in ScannerTest ("pass checkout paths without a trailing '/' for a project below the analysis root"), which asserts the checkout paths passed to the provenance scanner for both the nested project (nested) and its submodule (nested/sub). Without the fix it fails with the ScanContext require message.
Since ed3ab25, `getCheckoutPathsForProvenance()` appends a '/' to every non-empty checkout path, while the `require` check added to `ScanContext` in the same commit rejects exactly such paths. As a result, scanning a project whose repository is located below the analysis root, e.g. in a Git submodule, fails with "The following checkout paths start or end with a '/' which is not allowed". Strip the trailing '/' again and only add the separator when building the checkout paths of nested repositories, so that neither a leading nor a trailing '/' is created. Fixes: oss-review-toolkit#12506. Signed-off-by: Antoni <168914426+cow-lang@users.noreply.github.com>
c10de35 to
c1aa14c
Compare
|
@fviernau, can you please re-review for tomorrow's release? |
Since ed3ab25,
getCheckoutPathsForProvenance()appends a '/' to every non-empty checkout path, while therequirecheck added toScanContextin the same commit rejects exactly such paths.As a result, scanning a project whose repository is located below the analysis root, e.g. in a Git submodule, fails with "The following checkout paths start or end with a '/' which is not allowed".
Strip the trailing '/' again and only add the separator when building the checkout paths of nested repositories, so that neither a leading nor a trailing '/' is created.
A minimal reproduction is available at https://github.com/antoni67cf/ort-submodule-scan-repro.
Fixes: #12506.