Satisfies ignores a LicenseRef alternative of an OR
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 65/100
Línea de trabajo
The bug is in the Satisfies function's handling of LicenseRef within OR and AND expressions. Start by examining the spdxexp package, particularly the Satisfies function and its helpers for evaluating expressions. The provided test cases in the issue body show the exact failure; run them to confirm. Look at how license identifiers are matched, focusing on the logic for OR and AND nodes when a LicenseRef is involved. The fix likely involves adjusting the comparison or normalization step for LicenseRef values.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
A LicenseRef that is an alternative of an OR does not count towards Satisfies: MIT OR LicenseRef-x is not satisfied by an allowed list of just LicenseRef-x, and MIT AND (LicenseRef-a OR LicenseRef-b) is satisfied by MIT alone, although neither reference is allowed. The same two shapes with list identifiers in place of the references give the expected answers:
package main
import (
"fmt"
"github.com/github/go-spdx/v2/spdxexp"
)
func main() {
cases := []struct {
expr string
allowed []string
}{
{"MIT OR LicenseRef-x", []string{"LicenseRef-x"}},
{"MIT OR ISC", []string{"ISC"}},
{"MIT AND (LicenseRef-a OR LicenseRef-b)", []string{"MIT"}},
{"MIT AND (ISC OR BSD-3-Clause)", []string{"MIT"}},
}
for _, c := range cases {
ok, err := spdxexp.Satisfies(c.expr, c.allowed)
fmt.Printf("Satisfies(%q, %q) = %v, %v\n", c.expr, c.allowed, ok, err)
}
}
Output:
Satisfies("MIT OR LicenseRef-x", ["LicenseRef-x"]) = false, <nil>
Satisfies("MIT OR ISC", ["ISC"]) = true, <nil>
Satisfies("MIT AND (LicenseRef-a OR LicenseRef-b)", ["MIT"]) = true, <nil>
Satisfies("MIT AND (ISC OR BSD-3-Clause)", ["MIT"]) = false, <nil>
I expected the first call to return true, like the second, and the third to return false, like the fourth. Putting the reference first (LicenseRef-x OR MIT) gives the same false, and the third result means an expression that requires a license absent from the allowed list passes the check.
Tested on v2.7.0 and on current main (48a80b3).
BTW, this was found by an automated program that writes property-based tests for various open source projects using hegel (but it has been reviewed by hand before reporting). We've also potentially found (but not yet hand validated) 15 other bugs in go-spdx. You can see the tests at https://github.com/hegeldev/hegel-zoo/tree/main/targets/go/go-spdx. Let us know if you would like us to file the other bugs found and/or contribute the tests. NB the tests are currently LLM generated and probably not yet suitable for inclusion as is, but we're happy to help get them into a better state if you want them.
- Lenguaje dominante
- Go
- Estrellas
- 53
- Forks
- 16
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/go-spdx
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
Dificultad 3/5 1-2 días Aptitud para principiantes 65/100
-
fix noisy update license PRAbierto
Dificultad 3/5 1-2 días Aptitud para principiantes 38/100
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
-
maintenance
Dificultad 1/5 1-3 horas Aptitud para principiantes 45/100
Todos los issues de github/go-spdx
Issues similares
-
agentic-workflows
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
Los mantenedores suelen responder en 1 día
-
priority/4/normal status/needs-triage type/bug/unconfirmed
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
authelia/authelia#13292 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
blinklabs-io/actions#138 ·
Los mantenedores suelen responder en 1 día
-
[UI] AlbumDetails collapses multi-genre list to single primary genre on viewports < lg breakpointAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día