aboutcode-org / aboutcode-org/scancode-toolkit

Hash is unexpectedly None for empty files

Abierto
#4,428 11 comentarios 0 reacciones 0 asignados Ver en GitHub
documentation
Lenguaje dominante
Python
Estrellas
2.6k
Forks
791
Merge medio
1 d 12 h
PR fusionados (30 d)
5

Descripción

Generating hashes for empty files will always return `None`, which is not documented and different from the usual hashing algorithms as well as contradicting the SPDX standard.

Example:

```python3
from commoncode.hash import sha1
from hashlib import sha1 as sha1_hashlib
from tempfile import NamedTemporaryFile

with NamedTemporaryFile() as temporary_file:
temporary_file.write(b'')
temporary_file.seek(0)
print(sha1(location=temporary_file.name))
print(sha1_hashlib(string=temporary_file.read(), used_for_security=False).hexdigest())
```

The reason seems to be that https://github.com/aboutcode-org/commoncode/blob/878be6140deac30e2b95fb0fad9eb8feca015fc8/src/commoncode/hash.py#L38 does not use `msg is not None`, but basically `bool(msg)`, which is `False` for empty inputs as well.

Replacing the line with

```python3
self.h = msg is not None and hmodule(msg).digest()[:self.digest_size] or None
```

(as well as replacing the same pattern in `sha1_git_hasher`) seems to fix this issue.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.