-
Notifications
You must be signed in to change notification settings - Fork 320
/
Copy pathEvaluatorCommand.kt
359 lines (306 loc) · 16.1 KB
/
EvaluatorCommand.kt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
/*
* Copyright (C) 2017 The ORT Project Authors (see <https://github.com/oss-review-toolkit/ort/blob/main/NOTICE>)
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*
* SPDX-License-Identifier: Apache-2.0
* License-Filename: LICENSE
*/
package org.ossreviewtoolkit.plugins.commands.evaluator
import com.github.ajalt.clikt.core.ProgramResult
import com.github.ajalt.clikt.core.terminal
import com.github.ajalt.clikt.parameters.options.associate
import com.github.ajalt.clikt.parameters.options.convert
import com.github.ajalt.clikt.parameters.options.default
import com.github.ajalt.clikt.parameters.options.flag
import com.github.ajalt.clikt.parameters.options.multiple
import com.github.ajalt.clikt.parameters.options.option
import com.github.ajalt.clikt.parameters.options.split
import com.github.ajalt.clikt.parameters.types.enum
import com.github.ajalt.clikt.parameters.types.file
import java.io.File
import java.net.URI
import java.time.Duration
import kotlin.time.toKotlinDuration
import org.apache.logging.log4j.kotlin.logger
import org.ossreviewtoolkit.evaluator.Evaluator
import org.ossreviewtoolkit.model.FileFormat
import org.ossreviewtoolkit.model.ResolvedPackageCurations.Companion.REPOSITORY_CONFIGURATION_PROVIDER_ID
import org.ossreviewtoolkit.model.RuleViolation
import org.ossreviewtoolkit.model.config.CopyrightGarbage
import org.ossreviewtoolkit.model.config.LicenseFilePatterns
import org.ossreviewtoolkit.model.config.RepositoryConfiguration
import org.ossreviewtoolkit.model.config.createFileArchiver
import org.ossreviewtoolkit.model.config.orEmpty
import org.ossreviewtoolkit.model.licenses.DefaultLicenseInfoProvider
import org.ossreviewtoolkit.model.licenses.LicenseClassifications
import org.ossreviewtoolkit.model.licenses.LicenseInfoResolver
import org.ossreviewtoolkit.model.licenses.orEmpty
import org.ossreviewtoolkit.model.readValue
import org.ossreviewtoolkit.model.readValueOrDefault
import org.ossreviewtoolkit.model.utils.CompositePackageConfigurationProvider
import org.ossreviewtoolkit.model.utils.DefaultResolutionProvider
import org.ossreviewtoolkit.model.utils.addPackageConfigurations
import org.ossreviewtoolkit.model.utils.addPackageCurations
import org.ossreviewtoolkit.model.utils.addResolutions
import org.ossreviewtoolkit.model.utils.mergeLabels
import org.ossreviewtoolkit.plugins.commands.api.OrtCommand
import org.ossreviewtoolkit.plugins.commands.api.utils.SeverityStatsPrinter
import org.ossreviewtoolkit.plugins.commands.api.utils.configurationGroup
import org.ossreviewtoolkit.plugins.commands.api.utils.inputGroup
import org.ossreviewtoolkit.plugins.commands.api.utils.outputGroup
import org.ossreviewtoolkit.plugins.commands.api.utils.readOrtResult
import org.ossreviewtoolkit.plugins.commands.api.utils.writeOrtResult
import org.ossreviewtoolkit.plugins.packageconfigurationproviders.api.PackageConfigurationProviderFactory
import org.ossreviewtoolkit.plugins.packageconfigurationproviders.api.SimplePackageConfigurationProvider
import org.ossreviewtoolkit.plugins.packageconfigurationproviders.dir.DirPackageConfigurationProvider
import org.ossreviewtoolkit.plugins.packagecurationproviders.api.SimplePackageCurationProvider
import org.ossreviewtoolkit.plugins.packagecurationproviders.file.FilePackageCurationProvider
import org.ossreviewtoolkit.utils.common.expandTilde
import org.ossreviewtoolkit.utils.common.safeMkdirs
import org.ossreviewtoolkit.utils.ort.ORT_COPYRIGHT_GARBAGE_FILENAME
import org.ossreviewtoolkit.utils.ort.ORT_EVALUATOR_RULES_FILENAME
import org.ossreviewtoolkit.utils.ort.ORT_LICENSE_CLASSIFICATIONS_FILENAME
import org.ossreviewtoolkit.utils.ort.ORT_RESOLUTIONS_FILENAME
import org.ossreviewtoolkit.utils.ort.ortConfigDirectory
class EvaluatorCommand : OrtCommand(
name = "evaluate",
help = "Evaluate ORT result files against policy rules."
) {
private val ortFile by option(
"--ort-file", "-i",
help = "The ORT result file to read as input."
).convert { it.expandTilde() }
.file(mustExist = true, canBeFile = true, canBeDir = false, mustBeWritable = false, mustBeReadable = true)
.convert { it.absoluteFile.normalize() }
.inputGroup()
private val outputDir by option(
"--output-dir", "-o",
help = "The directory to write the ORT result file with evaluation results to. If no output directory is " +
"specified, no ORT result file is written and only the exit code signals a success or failure."
).convert { it.expandTilde() }
.file(mustExist = false, canBeFile = false, canBeDir = true, mustBeWritable = false, mustBeReadable = false)
.convert { it.absoluteFile.normalize() }
.outputGroup()
private val outputFormats by option(
"--output-formats", "-f",
help = "The list of output formats to be used for the ORT result file(s)."
).enum<FileFormat>().split(",").default(listOf(FileFormat.YAML)).outputGroup()
private val rulesFile by option(
"--rules-file", "-r",
help = "The name of a script file containing rules."
).convert { it.expandTilde() }
.file(mustExist = true, canBeFile = true, canBeDir = false, mustBeWritable = false, mustBeReadable = true)
.convert { it.absoluteFile.normalize() }
.multiple()
private val rulesResource by option(
"--rules-resource",
help = "The name of a script resource on the classpath that contains rules."
).multiple()
private val copyrightGarbageFile by option(
"--copyright-garbage-file",
help = "A file containing copyright statements which are marked as garbage."
).convert { it.expandTilde() }
.file(mustExist = true, canBeFile = true, canBeDir = false, mustBeWritable = false, mustBeReadable = true)
.convert { it.absoluteFile.normalize() }
.default(ortConfigDirectory.resolve(ORT_COPYRIGHT_GARBAGE_FILENAME))
.configurationGroup()
private val licenseClassificationsFile by option(
"--license-classifications-file",
help = "A file containing the license classifications which are passed as parameter to the rules script."
).convert { it.expandTilde() }
.file(mustExist = true, canBeFile = true, canBeDir = false, mustBeWritable = false, mustBeReadable = true)
.convert { it.absoluteFile.normalize() }
.default(ortConfigDirectory.resolve(ORT_LICENSE_CLASSIFICATIONS_FILENAME))
.configurationGroup()
private val packageConfigurationsDir by option(
"--package-configurations-dir",
help = "A directory that is searched recursively for package configuration files. Each file must only " +
"contain a single package configuration."
).convert { it.expandTilde() }
.file(mustExist = true, canBeFile = false, canBeDir = true, mustBeWritable = false, mustBeReadable = true)
.convert { it.absoluteFile.normalize() }
.configurationGroup()
private val packageCurationsFile by option(
"--package-curations-file",
help = "A file containing package curations. This replaces all package curations contained in the given ORT " +
"result file with the ones present in the given file and, if enabled, those from the repository " +
"configuration."
).convert { it.expandTilde() }
.file(mustExist = true, canBeFile = true, canBeDir = false, mustBeWritable = false, mustBeReadable = true)
.convert { it.absoluteFile.normalize() }
.configurationGroup()
private val packageCurationsDir by option(
"--package-curations-dir",
help = "A directory containing package curation files. This replaces all package curations contained in the " +
"given ORT result file with the ones present in the given directory and, if enabled, those from the " +
"repository configuration."
).convert { it.expandTilde() }
.file(mustExist = true, canBeFile = false, canBeDir = true, mustBeWritable = false, mustBeReadable = true)
.convert { it.absoluteFile.normalize() }
.configurationGroup()
private val repositoryConfigurationFile by option(
"--repository-configuration-file",
help = "A file containing the repository configuration. If set, overrides the repository configuration " +
"contained in the ORT result input file."
).convert { it.expandTilde() }
.file(mustExist = true, canBeFile = true, canBeDir = false, mustBeWritable = false, mustBeReadable = true)
.convert { it.absoluteFile.normalize() }
.configurationGroup()
private val resolutionsFile by option(
"--resolutions-file",
help = "A file containing issue and rule violation resolutions."
).convert { it.expandTilde() }
.file(mustExist = true, canBeFile = true, canBeDir = false, mustBeWritable = false, mustBeReadable = true)
.convert { it.absoluteFile.normalize() }
.default(ortConfigDirectory.resolve(ORT_RESOLUTIONS_FILENAME))
.configurationGroup()
private val labels by option(
"--label", "-l",
help = "Set a label in the ORT result, overwriting any existing label of the same name. Can be used multiple " +
"times. For example: --label distribution=external"
).associate()
private val checkSyntax by option(
"--check-syntax",
help = "Do not evaluate the script but only check its syntax. No output is written in this case."
).flag()
override fun run() {
val scriptUrls = mutableSetOf<URI>()
rulesFile.mapTo(scriptUrls) { it.toURI() }
rulesResource.mapTo(scriptUrls) { javaClass.getResource(it).toURI() }
if (scriptUrls.isEmpty()) {
scriptUrls += ortConfigDirectory.resolve(ORT_EVALUATOR_RULES_FILENAME).toURI()
}
val configurationFiles = listOfNotNull(
copyrightGarbageFile,
licenseClassificationsFile,
packageCurationsFile,
repositoryConfigurationFile
)
val configurationInfo = configurationFiles.joinToString("\n\t") { file ->
file.absolutePath + " (does not exist)".takeIf { !file.exists() }.orEmpty()
}
echo("Looking for evaluator-specific configuration in the following files and directories:")
echo("\t" + configurationInfo)
// Fail early if output files exist and must not be overwritten.
val outputFiles = mutableSetOf<File>()
outputDir?.let { absoluteOutputDir ->
outputFormats.mapTo(outputFiles) { format ->
absoluteOutputDir.resolve("evaluation-result.${format.fileExtension}")
}
validateOutputFiles(outputFiles)
}
if (checkSyntax) {
val evaluator = Evaluator()
var allChecksSucceeded = true
scriptUrls.forEach {
if (evaluator.checkSyntax(it.toURL().readText())) {
echo("Syntax check for $it succeeded.")
} else {
echo("Syntax check for $it failed.")
allChecksSucceeded = false
}
}
if (allChecksSucceeded) return else throw ProgramResult(2)
}
val existingOrtFile = requireNotNull(ortFile) {
"The '--ort-file' option is required unless the '--check-syntax' option is used."
}
var ortResultInput = readOrtResult(existingOrtFile)
repositoryConfigurationFile?.let {
val config = it.readValueOrDefault(RepositoryConfiguration())
ortResultInput = ortResultInput.replaceConfig(config)
}
if (packageCurationsDir != null || packageCurationsFile != null) {
val packageCurationProviders = buildList {
if (ortConfig.enableRepositoryPackageCurations) {
val packageCurations = ortResultInput.repository.config.curations.packages
add(REPOSITORY_CONFIGURATION_PROVIDER_ID to SimplePackageCurationProvider(packageCurations))
}
val providerFromOption = FilePackageCurationProvider(packageCurationsFile, packageCurationsDir)
add("EvaluatorCommandOption" to providerFromOption)
}
ortResultInput = ortResultInput.addPackageCurations(packageCurationProviders)
}
val enabledPackageConfigurationProviders = buildList {
val repositoryPackageConfigurations = ortResultInput.repository.config.packageConfigurations
if (ortConfig.enableRepositoryPackageConfigurations) {
add(SimplePackageConfigurationProvider(repositoryPackageConfigurations))
} else {
if (repositoryPackageConfigurations.isNotEmpty()) {
logger.info { "Local package configurations were not applied because the feature is not enabled." }
}
}
if (packageConfigurationsDir != null) {
add(DirPackageConfigurationProvider(packageConfigurationsDir))
} else {
val packageConfigurationProviders =
PackageConfigurationProviderFactory.create(ortConfig.packageConfigurationProviders)
addAll(packageConfigurationProviders.map { it.second })
}
}
val packageConfigurationProvider =
CompositePackageConfigurationProvider(*enabledPackageConfigurationProviders.toTypedArray())
val copyrightGarbage = copyrightGarbageFile.takeIf { it.isFile }?.readValue<CopyrightGarbage>().orEmpty()
val licenseInfoResolver = LicenseInfoResolver(
provider = DefaultLicenseInfoProvider(ortResultInput, packageConfigurationProvider),
copyrightGarbage = copyrightGarbage,
addAuthorsToCopyrights = ortConfig.addAuthorsToCopyrights,
archiver = ortConfig.scanner.archive.createFileArchiver(),
licenseFilePatterns = LicenseFilePatterns.getInstance()
)
val resolutionProvider = DefaultResolutionProvider.create(ortResultInput, resolutionsFile)
val licenseClassifications =
licenseClassificationsFile.takeIf { it.isFile }?.readValue<LicenseClassifications>().orEmpty()
val evaluator = Evaluator(ortResultInput, licenseInfoResolver, resolutionProvider, licenseClassifications)
val scripts = scriptUrls.map { it.toURL().readText() }
val evaluatorRun = evaluator.run(*scripts.toTypedArray())
val duration = with(evaluatorRun) { Duration.between(startTime, endTime).toKotlinDuration() }
echo("The evaluation of ${scriptUrls.size} script(s) took $duration.")
evaluatorRun.violations.forEach { violation ->
echo(violation.format())
}
// Note: This overwrites any existing EvaluatorRun from the input file.
val ortResultOutput = ortResultInput.copy(evaluator = evaluatorRun)
.mergeLabels(labels)
.addPackageConfigurations(packageConfigurationProvider)
.addResolutions(resolutionProvider)
outputDir?.let { absoluteOutputDir ->
absoluteOutputDir.safeMkdirs()
writeOrtResult(ortResultOutput, outputFiles, terminal)
}
SeverityStatsPrinter(terminal, resolutionProvider).stats(evaluatorRun.violations)
.print().conclude(ortConfig.severeRuleViolationThreshold, 2)
}
}
private fun RuleViolation.format() =
buildString {
append(severity)
append(": ")
append(rule)
append(" - ")
pkg?.let { id ->
append(id.toCoordinates())
append(" - ")
}
license?.let { license ->
append(license)
licenseSource?.let { source ->
append(" (")
append(source)
append(")")
}
append(" - ")
}
append(message)
}