Skip to content

fix(scanner): Do not end checkout paths of nested projects with a '/' - #12507

Open
antoni67cf wants to merge 1 commit into
oss-review-toolkit:mainfrom
antoni67cf:fix/scanner-checkout-path-trailing-slash-pr
Open

antoni67cf wants to merge 1 commit into
oss-review-toolkit:mainfrom
antoni67cf:fix/scanner-checkout-path-trailing-slash-pr

Conversation

@antoni67cf

Copy link
Copy Markdown
Contributor

Since ed3ab25, getCheckoutPathsForProvenance() appends a '/' to every non-empty checkout path, while the require check added to ScanContext in the same commit rejects exactly such paths.
As a result, scanning a project whose repository is located below the analysis root, e.g. in a Git submodule, fails with "The following checkout paths start or end with a '/' which is not allowed".

Strip the trailing '/' again and only add the separator when building the checkout paths of nested repositories, so that neither a leading nor a trailing '/' is created.

A minimal reproduction is available at https://github.com/antoni67cf/ort-submodule-scan-repro.

Fixes: #12506.

@antoni67cf
antoni67cf requested a review from a team as a code owner September 23, 2026 12:00
Comment thread scanner/src/test/kotlin/CheckoutPathsForProvenanceTest.kt Fixed
@antoni67cf
antoni67cf force-pushed the fix/scanner-checkout-path-trailing-slash-pr branch from 3f62c66 to c10de35 Compare September 23, 2026 12:28
@codecov

codecov Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 59.21%. Comparing base (3bced1a) to head (c1aa14c).

Additional details and impacted files
@@            Coverage Diff            @@
##               main   #12507   +/-   ##
=========================================
  Coverage     59.21%   59.21%           
  Complexity     1892     1892           
=========================================
  Files           366      366           
  Lines         13839    13839           
  Branches       1462     1462           
=========================================
  Hits           8195     8195           
+ Misses         5115     5114    -1     
- Partials        529      530    +1     
Flag Coverage Δ
funTest-external-tools 16.13% <ø> (ø)
funTest-no-external-tools 29.39% <ø> (+0.22%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.
import org.ossreviewtoolkit.model.config.ScannerConfiguration
import org.ossreviewtoolkit.scanner.provenance.NestedProvenance

class CheckoutPathsForProvenanceTest : WordSpec({

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please make the change in a way so that the test easier to maintain. This is a lot of code
for this little logic.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, thanks. Dropped the standalone spec and made getCheckoutPathsForProvenance() private again. The fix is now covered by a single end-to-end case in ScannerTest ("pass checkout paths without a trailing '/' for a project below the analysis root"), which asserts the checkout paths passed to the provenance scanner for both the nested project (nested) and its submodule (nested/sub). Without the fix it fails with the ScanContext require message.

Since ed3ab25, `getCheckoutPathsForProvenance()` appends a '/' to every
non-empty checkout path, while the `require` check added to
`ScanContext` in the same commit rejects exactly such paths. As a
result, scanning a project whose repository is located below the
analysis root, e.g. in a Git submodule, fails with "The following
checkout paths start or end with a '/' which is not allowed".

Strip the trailing '/' again and only add the separator when building
the checkout paths of nested repositories, so that neither a leading
nor a trailing '/' is created.

Fixes: oss-review-toolkit#12506.
Signed-off-by: Antoni <168914426+cow-lang@users.noreply.github.com>
@antoni67cf
antoni67cf force-pushed the fix/scanner-checkout-path-trailing-slash-pr branch from c10de35 to c1aa14c Compare September 23, 2026 14:06
@antoni67cf
antoni67cf requested a review from fviernau September 23, 2026 14:06
@sschuberth

sschuberth commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

@fviernau, can you please re-review for tomorrow's release?

@sschuberth
sschuberth enabled auto-merge (rebase) September 30, 2026 06:54
@sschuberth
sschuberth requested a review from a team September 30, 2026 06:55

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

4 participants