3 # lint.py - part of the FDroid server tool
4 # Copyright (C) 2013-2014 Daniel Martí <mvdan@mvdan.cc>
6 # This program is free software: you can redistribute it and/or modify
7 # it under the terms of the GNU Affero General Public License as published by
8 # the Free Software Foundation, either version 3 of the License, or
9 # (at your option) any later version.
11 # This program is distributed in the hope that it will be useful,
12 # but WITHOUT ANY WARRANTY; without even the implied warranty of
13 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See th
14 # GNU Affero General Public License for more details.
16 # You should have received a copy of the GNU Affero General Public Licen
17 # along with this program. If not, see <http://www.gnu.org/licenses/>.
19 from argparse import ArgumentParser
27 from . import metadata
28 from . import rewritemeta
34 def enforce_https(domain):
35 return (re.compile(r'^[^h][^t][^t][^p][^s]://[^/]*' + re.escape(domain) + r'(/.*)?', re.IGNORECASE),
36 domain + " URLs should always use https://")
40 enforce_https('github.com'),
41 enforce_https('gitlab.com'),
42 enforce_https('bitbucket.org'),
43 enforce_https('apache.org'),
44 enforce_https('google.com'),
45 enforce_https('git.code.sf.net'),
46 enforce_https('svn.code.sf.net'),
47 enforce_https('anongit.kde.org'),
48 enforce_https('savannah.nongnu.org'),
49 enforce_https('git.savannah.nongnu.org'),
50 enforce_https('download.savannah.nongnu.org'),
51 enforce_https('savannah.gnu.org'),
52 enforce_https('git.savannah.gnu.org'),
53 enforce_https('download.savannah.gnu.org'),
54 enforce_https('github.io'),
55 enforce_https('gitlab.io'),
56 enforce_https('githubusercontent.com'),
60 def forbid_shortener(domain):
61 return (re.compile(r'https?://[^/]*' + re.escape(domain) + r'/.*'),
62 _("URL shorteners should not be used"))
65 http_url_shorteners = [
66 forbid_shortener('1url.com'),
67 forbid_shortener('adf.ly'),
68 forbid_shortener('bc.vc'),
69 forbid_shortener('bit.do'),
70 forbid_shortener('bit.ly'),
71 forbid_shortener('bitly.com'),
72 forbid_shortener('budurl.com'),
73 forbid_shortener('buzurl.com'),
74 forbid_shortener('cli.gs'),
75 forbid_shortener('cur.lv'),
76 forbid_shortener('cutt.us'),
77 forbid_shortener('db.tt'),
78 forbid_shortener('filoops.info'),
79 forbid_shortener('goo.gl'),
80 forbid_shortener('is.gd'),
81 forbid_shortener('ity.im'),
82 forbid_shortener('j.mp'),
83 forbid_shortener('l.gg'),
84 forbid_shortener('lnkd.in'),
85 forbid_shortener('moourl.com'),
86 forbid_shortener('ow.ly'),
87 forbid_shortener('para.pt'),
88 forbid_shortener('po.st'),
89 forbid_shortener('q.gs'),
90 forbid_shortener('qr.ae'),
91 forbid_shortener('qr.net'),
92 forbid_shortener('rdlnk.com'),
93 forbid_shortener('scrnch.me'),
94 forbid_shortener('short.nr'),
95 forbid_shortener('sn.im'),
96 forbid_shortener('snipurl.com'),
97 forbid_shortener('su.pr'),
98 forbid_shortener('t.co'),
99 forbid_shortener('tiny.cc'),
100 forbid_shortener('tinyarrows.com'),
101 forbid_shortener('tinyurl.com'),
102 forbid_shortener('tr.im'),
103 forbid_shortener('tweez.me'),
104 forbid_shortener('twitthis.com'),
105 forbid_shortener('twurl.nl'),
106 forbid_shortener('tyn.ee'),
107 forbid_shortener('u.bb'),
108 forbid_shortener('u.to'),
109 forbid_shortener('ur1.ca'),
110 forbid_shortener('urlof.site'),
111 forbid_shortener('v.gd'),
112 forbid_shortener('vzturl.com'),
113 forbid_shortener('x.co'),
114 forbid_shortener('xrl.us'),
115 forbid_shortener('yourls.org'),
116 forbid_shortener('zip.net'),
117 forbid_shortener('✩.ws'),
118 forbid_shortener('➡.ws'),
121 http_checks = https_enforcings + http_url_shorteners + [
122 (re.compile(r'.*github\.com/[^/]+/[^/]+\.git'),
123 _("Appending .git is not necessary")),
124 (re.compile(r'.*://[^/]*(github|gitlab|bitbucket|rawgit)[^/]*/([^/]+/){1,3}master'),
125 _("Use /HEAD instead of /master to point at a file in the default branch")),
129 'WebSite': http_checks,
130 'SourceCode': http_checks,
131 'Repo': https_enforcings,
132 'UpdateCheckMode': https_enforcings,
133 'IssueTracker': http_checks + [
134 (re.compile(r'.*github\.com/[^/]+/[^/]+/*$'),
135 _("/issues is missing")),
136 (re.compile(r'.*gitlab\.com/[^/]+/[^/]+/*$'),
137 _("/issues is missing")),
139 'Donate': http_checks + [
140 (re.compile(r'.*flattr\.com'),
141 _("Flattr donation methods belong in the FlattrID flag")),
142 (re.compile(r'.*liberapay\.com'),
143 _("Liberapay donation methods belong in the LiberapayID flag")),
145 'Changelog': http_checks,
148 _("Unnecessary leading space")),
149 (re.compile(r'.*\s$'),
150 _("Unnecessary trailing space")),
153 (re.compile(r'.*\b(free software|open source)\b.*', re.IGNORECASE),
154 _("No need to specify that the app is Free Software")),
155 (re.compile(r'.*((your|for).*android|android.*(app|device|client|port|version))', re.IGNORECASE),
156 _("No need to specify that the app is for Android")),
157 (re.compile(r'.*[a-z0-9][.!?]( |$)'),
158 _("Punctuation should be avoided")),
160 _("Unnecessary leading space")),
161 (re.compile(r'.*\s$'),
162 _("Unnecessary trailing space")),
164 'Description': https_enforcings + http_url_shorteners + [
165 (re.compile(r'\s*[*#][^ .]'),
166 _("Invalid bulleted list")),
168 _("Unnecessary leading space")),
169 (re.compile(r'.*\s$'),
170 _("Unnecessary trailing space")),
171 (re.compile(r'.*<(applet|base|body|button|embed|form|head|html|iframe|img|input|link|object|picture|script|source|style|svg|video).*', re.IGNORECASE),
172 _("Forbidden HTML tags")),
173 (re.compile(r'''.*\s+src=["']javascript:.*'''),
174 _("Javascript in HTML src attributes")),
178 locale_pattern = re.compile(r'^[a-z]{2,3}(-[A-Z][A-Z])?$')
181 def check_regexes(app):
182 for f, checks in regex_checks.items():
185 t = metadata.fieldtype(f)
186 if t == metadata.TYPE_MULTILINE:
187 for l in v.splitlines():
189 yield "%s at line '%s': %s" % (f, l, r)
194 yield "%s '%s': %s" % (f, v, r)
197 def get_lastbuild(builds):
201 if not build.disable:
202 vercode = int(build.versionCode)
203 if lowest_vercode == -1 or vercode < lowest_vercode:
204 lowest_vercode = vercode
205 if not lastbuild or int(build.versionCode) > int(lastbuild.versionCode):
210 def check_ucm_tags(app):
211 lastbuild = get_lastbuild(app.builds)
212 if (lastbuild is not None
214 and app.UpdateCheckMode == 'RepoManifest'
215 and not lastbuild.commit.startswith('unknown')
216 and lastbuild.versionCode == app.CurrentVersionCode
217 and not lastbuild.forcevercode
218 and any(s in lastbuild.commit for s in '.,_-/')):
219 yield _("Last used commit '{commit}' looks like a tag, but Update Check Mode is '{ucm}'")\
220 .format(commit=lastbuild.commit, ucm=app.UpdateCheckMode)
223 def check_char_limits(app):
224 limits = config['char_limits']
226 if len(app.Summary) > limits['summary']:
227 yield _("Summary of length {length} is over the {limit} char limit")\
228 .format(length=len(app.Summary), limit=limits['summary'])
230 if len(app.Description) > limits['description']:
231 yield _("Description of length {length} is over the {limit} char limit")\
232 .format(length=len(app.Description), limit=limits['description'])
235 def check_old_links(app):
245 if any(s in app.Repo for s in usual_sites):
246 for f in ['WebSite', 'SourceCode', 'IssueTracker', 'Changelog']:
248 if any(s in v for s in old_sites):
249 yield _("App is in '{repo}' but has a link to {url}")\
250 .format(repo=app.Repo, url=v)
253 def check_useless_fields(app):
254 if app.UpdateCheckName == app.id:
255 yield _("Update Check Name is set to the known app id - it can be removed")
258 filling_ucms = re.compile(r'^(Tags.*|RepoManifest.*)')
261 def check_checkupdates_ran(app):
262 if filling_ucms.match(app.UpdateCheckMode):
263 if not app.AutoName and not app.CurrentVersion and app.CurrentVersionCode == '0':
264 yield _("UCM is set but it looks like checkupdates hasn't been run yet")
267 def check_empty_fields(app):
268 if not app.Categories:
269 yield _("Categories are not set")
272 all_categories = set([
283 "Science & Education",
293 def check_categories(app):
294 for categ in app.Categories:
295 if categ not in all_categories:
296 yield _("Category '%s' is not valid" % categ)
299 def check_duplicates(app):
300 if app.Name and app.Name == app.AutoName:
301 yield _("Name '%s' is just the auto name - remove it") % app.Name
304 for f in ['Source Code', 'Web Site', 'Issue Tracker', 'Changelog']:
310 yield _("Duplicate link in '{field}': {url}").format(field=f, url=v)
314 name = app.Name or app.AutoName
315 if app.Summary and name:
316 if app.Summary.lower() == name.lower():
317 yield _("Summary '%s' is just the app's name") % app.Summary
319 if app.Summary and app.Description and len(app.Description) == 1:
320 if app.Summary.lower() == app.Description[0].lower():
321 yield _("Description '%s' is just the app's summary") % app.Summary
324 for l in app.Description.splitlines():
328 yield _("Description has a duplicate line")
332 desc_url = re.compile(r'(^|[^[])\[([^ ]+)( |\]|$)')
335 def check_mediawiki_links(app):
336 wholedesc = ' '.join(app.Description)
337 for um in desc_url.finditer(wholedesc):
339 for m, r in http_checks:
341 yield _("URL {url} in Description: {error}").format(url=url, error=r)
344 def check_bulleted_lists(app):
345 validchars = ['*', '#']
348 for l in app.Description.splitlines():
353 if l[0] == lchar and l[1] == ' ':
355 if lcount > 2 and lchar not in validchars:
356 yield _("Description has a list (%s) but it isn't bulleted (*) nor numbered (#)") % lchar
363 def check_builds(app):
364 supported_flags = set(metadata.build_flags)
365 # needed for YAML and JSON
366 for build in app.builds:
368 if build.disable.startswith('Generated by import.py'):
369 yield _("Build generated by `fdroid import` - remove disable line once ready")
371 for s in ['master', 'origin', 'HEAD', 'default', 'trunk']:
372 if build.commit and build.commit.startswith(s):
373 yield _("Branch '{branch}' used as commit in build '{versionName}'")\
374 .format(branch=s, versionName=build.versionName)
375 for srclib in build.srclibs:
377 ref = srclib.split('@')[1].split('/')[0]
378 if ref.startswith(s):
379 yield _("Branch '{branch}' used as commit in srclib '{srclib}'")\
380 .format(branch=s, srclib=srclib)
382 yield _('srclibs missing name and/or @') + ' (srclibs: ' + srclib + ')'
383 for key in build.keys():
384 if key not in supported_flags:
385 yield _('%s is not an accepted build field') % key
388 def check_files_dir(app):
389 dir_path = os.path.join('metadata', app.id)
390 if not os.path.isdir(dir_path):
393 for name in os.listdir(dir_path):
394 path = os.path.join(dir_path, name)
395 if not (os.path.isfile(path) or name == 'signatures' or locale_pattern.match(name)):
396 yield _("Found non-file at %s") % path
400 used = {'signatures', }
401 for build in app.builds:
402 for fname in build.patch:
403 if fname not in files:
404 yield _("Unknown file '{filename}' in build '{versionName}'")\
405 .format(filename=fname, versionName=build.versionName)
409 for name in files.difference(used):
410 if locale_pattern.match(name):
412 yield _("Unused file at %s") % os.path.join(dir_path, name)
415 def check_format(app):
416 if options.format and not rewritemeta.proper_format(app):
417 yield _("Run rewritemeta to fix formatting")
420 def check_license_tag(app):
421 '''Ensure all license tags are in https://spdx.org/license-list'''
422 if app.License.rstrip('+') not in SPDX:
423 yield _('Invalid license tag "%s"! Use only tags from https://spdx.org/license-list') \
427 def check_extlib_dir(apps):
428 dir_path = os.path.join('build', 'extlib')
429 unused_extlib_files = set()
430 for root, dirs, files in os.walk(dir_path):
432 unused_extlib_files.add(os.path.join(root, name)[len(dir_path) + 1:])
436 for build in app.builds:
437 for path in build.extlibs:
438 if path not in unused_extlib_files:
439 yield _("{appid}: Unknown extlib {path} in build '{versionName}'")\
440 .format(appid=app.id, path=path, versionName=build.versionName)
444 for path in unused_extlib_files.difference(used):
445 if any(path.endswith(s) for s in [
447 'source.txt', 'origin.txt', 'md5.txt',
448 'LICENSE', 'LICENSE.txt',
449 'COPYING', 'COPYING.txt',
450 'NOTICE', 'NOTICE.txt',
453 yield _("Unused extlib at %s") % os.path.join(dir_path, path)
456 def check_for_unsupported_metadata_files(basedir=""):
457 """Checks whether any non-metadata files are in metadata/"""
462 formats = config['accepted_formats']
463 for f in glob.glob(basedir + 'metadata/*') + glob.glob(basedir + 'metadata/.*'):
467 exists = exists or os.path.exists(f + '.' + t)
469 print(_('"%s/" has no matching metadata file!') % f)
471 elif not os.path.splitext(f)[1][1:] in formats:
472 print('"' + f.replace(basedir, '')
473 + '" is not a supported file format: (' + ','.join(formats) + ')')
481 global config, options
483 # Parse command line...
484 parser = ArgumentParser(usage="%(prog)s [options] [APPID [APPID ...]]")
485 common.setup_global_opts(parser)
486 parser.add_argument("-f", "--format", action="store_true", default=False,
487 help=_("Also warn about formatting issues, like rewritemeta -l"))
488 parser.add_argument("appid", nargs='*', help=_("applicationId in the form APPID"))
489 metadata.add_metadata_arguments(parser)
490 options = parser.parse_args()
491 metadata.warnings_action = options.W
493 config = common.read_config(options)
496 allapps = metadata.read_metadata(xref=True)
497 apps = common.read_app_args(options.appid, allapps, False)
499 anywarns = check_for_unsupported_metadata_files()
501 apps_check_funcs = []
502 if len(options.appid) == 0:
503 # otherwise it finds tons of unused extlibs
504 apps_check_funcs.append(check_extlib_dir)
505 for check_func in apps_check_funcs:
506 for warn in check_func(apps.values()):
510 for appid, app in apps.items():
519 check_checkupdates_ran,
520 check_useless_fields,
524 check_mediawiki_links,
525 check_bulleted_lists,
532 for check_func in app_check_funcs:
533 for warn in check_func(app):
535 print("%s: %s" % (appid, warn))
541 # A compiled, public domain list of official SPDX license tags from:
542 # https://github.com/sindresorhus/spdx-license-list/blob/v3.0.1/spdx-simple.json
543 # The deprecated license tags have been removed from the list, they are at the
544 # bottom, starting after the last license tags that start with Z.
545 # This is at the bottom, since its a long list of data
547 "PublicDomain", # an F-Droid addition, until we can enforce a better option
587 "BSD-2-Clause-FreeBSD",
588 "BSD-2-Clause-NetBSD",
590 "BSD-3-Clause-Clear",
591 "BSD-3-Clause-No-Nuclear-License",
592 "BSD-3-Clause-No-Nuclear-License-2014",
593 "BSD-3-Clause-No-Nuclear-Warranty",
597 "BSD-3-Clause-Attribution",
613 "CNRI-Python-GPL-Compatible",
747 "MPL-2.0-no-copyleft-exception",
871 "zlib-acknowledgement",
877 if __name__ == "__main__":