aboutcode-org / aboutcode-org/scancode-toolkit

Duplicate LGPL key in rubygems LICENSES_MAPPING makes one mapping unreachable

Đang mở
#5,314 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Python
Star
2.6k
Fork
791
Merge trung bình
1 ngày 12 giờ
Pull request đã merge (30 ngày)
5

Mô tả

### Description

`LICENSES_MAPPING` in `src/packagedcode/rubygems.py` defines `'LGPL'` twice, on two consecutive lines (679-680):

```python
'LGPL': 'lgpl',
'LGPL': 'lgpl-2.0-plus',
```

Both are entries of the same dict literal, so the first is discarded and every gem declaring a bare `LGPL` resolves to `lgpl-2.0-plus`.

That is worth a second look on its own: an unversioned `LGPL` declaration does not state a version, and `lgpl-2.0-plus` asserts one. The generic `'LGPL': 'lgpl'` line immediately above looks like the mapping intended for the unversioned case, and the table already has separate explicit entries for the versioned spellings. Either way, which one applies is currently decided by line order rather than intent, and the unreachable line is misleading to read.

### How To Reproduce

```python
import ast, collections

src = open('src/packagedcode/rubygems.py').read()
for node in ast.walk(ast.parse(src)):
if isinstance(node, ast.Dict):
counts = collections.Counter(
k.value for k in node.keys
if isinstance(k, ast.Constant) and isinstance(k.value, str)
)
for key, n in counts.items():
if n > 1:
print(f'line {node.lineno}: duplicate key {key!r} x{n}')
```

```
line 658: duplicate key 'LGPL' x2
```

And the effective value:

```python
>>> from packagedcode.rubygems import LICENSES_MAPPING
>>> LICENSES_MAPPING['LGPL']
'lgpl-2.0-plus'
```

The `'lgpl'` entry is unreachable.

### Suggested fix

Remove one of the two lines. I have opened a PR that drops the unreachable one and keeps the current result, so nothing changes at runtime. If a bare `LGPL` should instead stay unversioned as `lgpl`, that is a one-word change on top and I am happy to make it.

### System configuration

* What OS are you running on? Linux (x86_64)
* What version of scancode-toolkit was used? 33.0.0rc1, `develop` at 5ebebf2
* What installation method was used to install/run scancode? source checkout
* Python version: 3.x

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.