mirror of
https://github.com/openai/codex.git
synced 2026-09-29 16:57:06 +08:00
Format Python scripts across the repository (#42109)
## Why The root Python formatting pass only covered `scripts/`, leaving Python utilities elsewhere in the repository outside `just fmt` and `just fmt-check`. ## What changed - Run the scripts Ruff formatter from the repository root. - Exclude `sdk/python`, which has its own formatter pass, and `codex-rs/vendor`. - Apply Ruff formatting to the newly covered Python files and update the formatter coverage test. GitOrigin-RevId: 73ac82b8bb9c713d589724f6c4f926399febb513
This commit is contained in:
@@ -49,10 +49,14 @@ class NotarizationConfiguration:
|
||||
"vault_name": "AZURE_KEYVAULT_NAME",
|
||||
"vault_key_name": "APPLE_NOTARIZATION_AKV_KEY_NAME",
|
||||
}
|
||||
values = {field: os.environ.get(name, "").strip() for field, name in required.items()}
|
||||
values = {
|
||||
field: os.environ.get(name, "").strip() for field, name in required.items()
|
||||
}
|
||||
missing = [name for field, name in required.items() if not values[field]]
|
||||
if missing:
|
||||
raise NotarizationError("Missing notarization configuration: " + ", ".join(missing))
|
||||
raise NotarizationError(
|
||||
"Missing notarization configuration: " + ", ".join(missing)
|
||||
)
|
||||
if not re.fullmatch(r"[A-Za-z][A-Za-z0-9-]{2,23}", values["vault_name"]):
|
||||
raise NotarizationError("Invalid signing vault name")
|
||||
if not re.fullmatch(r"[A-Za-z0-9-]+", values["vault_key_name"]):
|
||||
@@ -90,7 +94,9 @@ class NotarizationConfiguration:
|
||||
try:
|
||||
result = subprocess.run(command, check=True, capture_output=True, text=True)
|
||||
except (OSError, subprocess.CalledProcessError) as error:
|
||||
raise NotarizationError("Notarization signing key could not be read") from error
|
||||
raise NotarizationError(
|
||||
"Notarization signing key could not be read"
|
||||
) from error
|
||||
try:
|
||||
metadata = json.loads(result.stdout)
|
||||
returned_key_id = metadata["id"]
|
||||
@@ -99,10 +105,10 @@ class NotarizationConfiguration:
|
||||
except (json.JSONDecodeError, KeyError, TypeError) as error:
|
||||
raise NotarizationError("Notarization key metadata is invalid") from error
|
||||
|
||||
key_id_prefix = (
|
||||
f"https://{values['vault_name']}.vault.azure.net/keys/{values['vault_key_name']}/"
|
||||
)
|
||||
if not isinstance(returned_key_id, str) or not returned_key_id.startswith(key_id_prefix):
|
||||
key_id_prefix = f"https://{values['vault_name']}.vault.azure.net/keys/{values['vault_key_name']}/"
|
||||
if not isinstance(returned_key_id, str) or not returned_key_id.startswith(
|
||||
key_id_prefix
|
||||
):
|
||||
raise NotarizationError("Unexpected notarization signing key")
|
||||
returned_key_version = returned_key_id[len(key_id_prefix) :]
|
||||
if not re.fullmatch(r"[0-9a-fA-F]{32}", returned_key_version):
|
||||
@@ -120,7 +126,9 @@ class NotarizationConfiguration:
|
||||
r"[0-9a-fA-F]{4}-[0-9a-fA-F]{12}",
|
||||
apple_issuer_id.strip(),
|
||||
):
|
||||
raise NotarizationError("Notarization apple-issuer-id tag must contain a valid UUID")
|
||||
raise NotarizationError(
|
||||
"Notarization apple-issuer-id tag must contain a valid UUID"
|
||||
)
|
||||
|
||||
values["issuer_id"] = apple_issuer_id.strip()
|
||||
values["apple_key_id"] = apple_key_id.strip()
|
||||
@@ -147,12 +155,18 @@ def base64url_decode(value: str) -> bytes:
|
||||
"""Decode a base64url value and reject malformed input."""
|
||||
|
||||
try:
|
||||
return base64.b64decode(value + "=" * (-len(value) % 4), altchars=b"-_", validate=True)
|
||||
return base64.b64decode(
|
||||
value + "=" * (-len(value) % 4), altchars=b"-_", validate=True
|
||||
)
|
||||
except (ValueError, UnicodeEncodeError) as error:
|
||||
raise NotarizationError("Signing service returned an invalid signature") from error
|
||||
raise NotarizationError(
|
||||
"Signing service returned an invalid signature"
|
||||
) from error
|
||||
|
||||
|
||||
def create_apple_jwt(configuration: NotarizationConfiguration, *, issued_at: int) -> str:
|
||||
def create_apple_jwt(
|
||||
configuration: NotarizationConfiguration, *, issued_at: int
|
||||
) -> str:
|
||||
"""Create an authentication token for notarization requests."""
|
||||
|
||||
header = {"alg": "ES256", "kid": configuration.apple_key_id, "typ": "JWT"}
|
||||
@@ -164,8 +178,12 @@ def create_apple_jwt(configuration: NotarizationConfiguration, *, issued_at: int
|
||||
"aud": "appstoreconnect-v1",
|
||||
"scope": ["/notary/v2"],
|
||||
}
|
||||
encoded_header = base64url_encode(json.dumps(header, separators=(",", ":")).encode("utf-8"))
|
||||
encoded_claims = base64url_encode(json.dumps(claims, separators=(",", ":")).encode("utf-8"))
|
||||
encoded_header = base64url_encode(
|
||||
json.dumps(header, separators=(",", ":")).encode("utf-8")
|
||||
)
|
||||
encoded_claims = base64url_encode(
|
||||
json.dumps(claims, separators=(",", ":")).encode("utf-8")
|
||||
)
|
||||
signing_input = f"{encoded_header}.{encoded_claims}"
|
||||
digest = hashlib.sha256(signing_input.encode("ascii")).digest()
|
||||
key_url = configuration.versioned_key_id
|
||||
@@ -206,7 +224,9 @@ def create_apple_jwt(configuration: NotarizationConfiguration, *, issued_at: int
|
||||
returned_key_id = response["kid"]
|
||||
encoded_signature = response["value"]
|
||||
except (json.JSONDecodeError, KeyError, TypeError) as error:
|
||||
raise NotarizationError("Signing service returned an invalid response") from error
|
||||
raise NotarizationError(
|
||||
"Signing service returned an invalid response"
|
||||
) from error
|
||||
|
||||
# Reject signatures generated with a different key version.
|
||||
if returned_key_id != key_url:
|
||||
@@ -220,7 +240,9 @@ def create_apple_jwt(configuration: NotarizationConfiguration, *, issued_at: int
|
||||
return f"{signing_input}.{base64url_encode(signature)}"
|
||||
|
||||
|
||||
def json_request(url: str, token: str, *, body: dict[str, Any] | None = None) -> dict[str, Any]:
|
||||
def json_request(
|
||||
url: str, token: str, *, body: dict[str, Any] | None = None
|
||||
) -> dict[str, Any]:
|
||||
"""Send an authenticated JSON request to Apple's notarization service."""
|
||||
|
||||
data = None if body is None else json.dumps(body).encode("utf-8")
|
||||
@@ -239,7 +261,9 @@ def json_request(url: str, token: str, *, body: dict[str, Any] | None = None) ->
|
||||
result = json.load(response)
|
||||
except urllib.error.HTTPError as error:
|
||||
detail = error.read(1024).decode("utf-8", errors="replace")
|
||||
raise NotarizationError(f"Apple Notary API returned HTTP {error.code}: {detail}") from error
|
||||
raise NotarizationError(
|
||||
f"Apple Notary API returned HTTP {error.code}: {detail}"
|
||||
) from error
|
||||
except (OSError, json.JSONDecodeError) as error:
|
||||
raise NotarizationError("Apple Notary API request failed") from error
|
||||
|
||||
@@ -281,9 +305,12 @@ def upload_to_apple_s3(
|
||||
"object",
|
||||
)
|
||||
if any(
|
||||
not isinstance(credentials.get(name), str) or not credentials[name] for name in required
|
||||
not isinstance(credentials.get(name), str) or not credentials[name]
|
||||
for name in required
|
||||
):
|
||||
raise NotarizationError("Apple returned incomplete temporary upload credentials")
|
||||
raise NotarizationError(
|
||||
"Apple returned incomplete temporary upload credentials"
|
||||
)
|
||||
|
||||
size = path.stat().st_size
|
||||
if not 0 < size <= MAX_SINGLE_UPLOAD_BYTES:
|
||||
@@ -293,7 +320,9 @@ def upload_to_apple_s3(
|
||||
amz_date = now.strftime("%Y%m%dT%H%M%SZ")
|
||||
date_stamp = now.strftime("%Y%m%d")
|
||||
host = f"{credentials['bucket']}.s3.{AWS_REGION}.amazonaws.com"
|
||||
object_path = "/" + urllib.parse.quote(credentials["object"].lstrip("/"), safe="/-_.~")
|
||||
object_path = "/" + urllib.parse.quote(
|
||||
credentials["object"].lstrip("/"), safe="/-_.~"
|
||||
)
|
||||
headers = {
|
||||
"content-type": "application/octet-stream",
|
||||
"host": host,
|
||||
@@ -319,7 +348,9 @@ def upload_to_apple_s3(
|
||||
signing_key = ("AWS4" + credentials["awsSecretAccessKey"]).encode("utf-8")
|
||||
for component in (date_stamp, AWS_REGION, "s3", "aws4_request"):
|
||||
signing_key = hmac_sha256(signing_key, component)
|
||||
signature = hmac.new(signing_key, string_to_sign.encode("utf-8"), hashlib.sha256).hexdigest()
|
||||
signature = hmac.new(
|
||||
signing_key, string_to_sign.encode("utf-8"), hashlib.sha256
|
||||
).hexdigest()
|
||||
authorization = (
|
||||
"AWS4-HMAC-SHA256 "
|
||||
f"Credential={credentials['awsAccessKeyId']}/{credential_scope}, "
|
||||
@@ -346,10 +377,14 @@ def upload_to_apple_s3(
|
||||
f"Apple notarization payload upload failed with HTTP {error.code}"
|
||||
) from error
|
||||
except OSError as error:
|
||||
raise NotarizationError("Apple notarization payload upload failed") from error
|
||||
raise NotarizationError(
|
||||
"Apple notarization payload upload failed"
|
||||
) from error
|
||||
|
||||
|
||||
def write_developer_log(submission_id: str, token: str, destination: Path | None) -> None:
|
||||
def write_developer_log(
|
||||
submission_id: str, token: str, destination: Path | None
|
||||
) -> None:
|
||||
"""Write the submission's optional diagnostic report."""
|
||||
|
||||
if destination is None:
|
||||
@@ -358,9 +393,13 @@ def write_developer_log(submission_id: str, token: str, destination: Path | None
|
||||
try:
|
||||
log_url = response["data"]["attributes"]["developerLogUrl"]
|
||||
except (KeyError, TypeError) as error:
|
||||
raise NotarizationError("Apple did not provide a notarization developer log") from error
|
||||
raise NotarizationError(
|
||||
"Apple did not provide a notarization developer log"
|
||||
) from error
|
||||
if not isinstance(log_url, str) or not log_url.startswith("https://"):
|
||||
raise NotarizationError("Apple returned an invalid notarization developer log URL")
|
||||
raise NotarizationError(
|
||||
"Apple returned an invalid notarization developer log URL"
|
||||
)
|
||||
try:
|
||||
# Do not forward unrelated authorization headers to the download URL.
|
||||
with urllib.request.urlopen(log_url, timeout=60) as response:
|
||||
@@ -370,7 +409,9 @@ def write_developer_log(submission_id: str, token: str, destination: Path | None
|
||||
f"Apple notarization developer log download failed with HTTP {error.code}"
|
||||
) from error
|
||||
except OSError as error:
|
||||
raise NotarizationError("Apple notarization developer log download failed") from error
|
||||
raise NotarizationError(
|
||||
"Apple notarization developer log download failed"
|
||||
) from error
|
||||
|
||||
|
||||
def notarize(
|
||||
@@ -395,11 +436,15 @@ def notarize(
|
||||
submission_id = response["data"]["id"]
|
||||
upload_credentials = response["data"]["attributes"]
|
||||
except (KeyError, TypeError) as error:
|
||||
raise NotarizationError("Apple returned an invalid notarization submission") from error
|
||||
raise NotarizationError(
|
||||
"Apple returned an invalid notarization submission"
|
||||
) from error
|
||||
if not isinstance(submission_id, str) or not submission_id:
|
||||
raise NotarizationError("Apple did not return a notarization submission ID")
|
||||
if not isinstance(upload_credentials, dict):
|
||||
raise NotarizationError("Apple returned invalid notarization upload credentials")
|
||||
raise NotarizationError(
|
||||
"Apple returned invalid notarization upload credentials"
|
||||
)
|
||||
|
||||
print(f"Uploading notarization submission {submission_id} for {path.name}")
|
||||
upload_to_apple_s3(path, file_digest, upload_credentials)
|
||||
@@ -416,7 +461,9 @@ def notarize(
|
||||
try:
|
||||
status = result["data"]["attributes"]["status"]
|
||||
except (KeyError, TypeError) as error:
|
||||
raise NotarizationError("Apple returned an invalid notarization status") from error
|
||||
raise NotarizationError(
|
||||
"Apple returned an invalid notarization status"
|
||||
) from error
|
||||
|
||||
if status in {"Accepted", "Invalid", "Rejected"}:
|
||||
# Save diagnostics for both accepted and rejected submissions.
|
||||
@@ -449,7 +496,9 @@ def main() -> int:
|
||||
|
||||
try:
|
||||
if not arguments.file.is_file():
|
||||
raise NotarizationError(f"Notarization payload does not exist: {arguments.file}")
|
||||
raise NotarizationError(
|
||||
f"Notarization payload does not exist: {arguments.file}"
|
||||
)
|
||||
if arguments.max_wait_seconds < 0:
|
||||
raise NotarizationError("--max-wait-seconds must be non-negative")
|
||||
if arguments.report_log is not None:
|
||||
|
||||
@@ -35,7 +35,9 @@ CREDENTIALS = {
|
||||
|
||||
|
||||
def response(payload):
|
||||
return io.BytesIO(json.dumps(payload).encode() if isinstance(payload, dict) else payload)
|
||||
return io.BytesIO(
|
||||
json.dumps(payload).encode() if isinstance(payload, dict) else payload
|
||||
)
|
||||
|
||||
|
||||
def azure_response(payload):
|
||||
@@ -66,10 +68,16 @@ class NotarizationTest(unittest.TestCase):
|
||||
notary.NotarizationConfiguration.from_environment()
|
||||
for issuer_id in (None, "", " "):
|
||||
with self.subTest(issuer_id=issuer_id):
|
||||
show.return_value = azure_response({**metadata, "apple_issuer_id": issuer_id})
|
||||
with self.assertRaisesRegex(notary.NotarizationError, "apple-issuer-id tag"):
|
||||
show.return_value = azure_response(
|
||||
{**metadata, "apple_issuer_id": issuer_id}
|
||||
)
|
||||
with self.assertRaisesRegex(
|
||||
notary.NotarizationError, "apple-issuer-id tag"
|
||||
):
|
||||
notary.NotarizationConfiguration.from_environment()
|
||||
show.return_value = azure_response({**metadata, "apple_issuer_id": "invalid-issuer"})
|
||||
show.return_value = azure_response(
|
||||
{**metadata, "apple_issuer_id": "invalid-issuer"}
|
||||
)
|
||||
with self.assertRaisesRegex(notary.NotarizationError, "valid UUID"):
|
||||
notary.NotarizationConfiguration.from_environment()
|
||||
self.assertIn(
|
||||
@@ -78,7 +86,10 @@ class NotarizationTest(unittest.TestCase):
|
||||
show.call_args.args[0],
|
||||
)
|
||||
|
||||
invalid_environment = {**ENVIRONMENT, "APPLE_NOTARIZATION_AKV_KEY_NAME": "../bad"}
|
||||
invalid_environment = {
|
||||
**ENVIRONMENT,
|
||||
"APPLE_NOTARIZATION_AKV_KEY_NAME": "../bad",
|
||||
}
|
||||
with (
|
||||
patch.dict(os.environ, invalid_environment, clear=True),
|
||||
self.assertRaisesRegex(notary.NotarizationError, "key name"),
|
||||
@@ -91,10 +102,14 @@ class NotarizationTest(unittest.TestCase):
|
||||
"kid": CONFIGURATION.versioned_key_id,
|
||||
"value": notary.base64url_encode(signature),
|
||||
}
|
||||
with patch.object(notary.subprocess, "run", return_value=azure_response(payload)) as sign:
|
||||
with patch.object(
|
||||
notary.subprocess, "run", return_value=azure_response(payload)
|
||||
) as sign:
|
||||
token = notary.create_apple_jwt(CONFIGURATION, issued_at=1_780_000_000)
|
||||
header, claims, encoded_signature = token.split(".")
|
||||
self.assertEqual(json.loads(notary.base64url_decode(header))["kid"], "APPLEKEY01")
|
||||
self.assertEqual(
|
||||
json.loads(notary.base64url_decode(header))["kid"], "APPLEKEY01"
|
||||
)
|
||||
self.assertEqual(
|
||||
json.loads(notary.base64url_decode(claims))["iss"], CONFIGURATION.issuer_id
|
||||
)
|
||||
@@ -113,7 +128,11 @@ class NotarizationTest(unittest.TestCase):
|
||||
|
||||
def test_rejects_wrong_key_versions_and_invalid_signatures(self) -> None:
|
||||
cases = (
|
||||
(CONFIGURATION.versioned_key_id + "wrong", bytes(64), "unexpected key version"),
|
||||
(
|
||||
CONFIGURATION.versioned_key_id + "wrong",
|
||||
bytes(64),
|
||||
"unexpected key version",
|
||||
),
|
||||
(CONFIGURATION.versioned_key_id, b"short", "64 JOSE"),
|
||||
)
|
||||
for key_id, signature, message in cases:
|
||||
@@ -141,7 +160,15 @@ class NotarizationTest(unittest.TestCase):
|
||||
response(b""),
|
||||
response({"data": {"attributes": {"status": "In Progress"}}}),
|
||||
response({"data": {"attributes": {"status": "Accepted"}}}),
|
||||
response({"data": {"attributes": {"developerLogUrl": "https://logs.example.com/log"}}}),
|
||||
response(
|
||||
{
|
||||
"data": {
|
||||
"attributes": {
|
||||
"developerLogUrl": "https://logs.example.com/log"
|
||||
}
|
||||
}
|
||||
}
|
||||
),
|
||||
response(b'{"status":"Accepted"}'),
|
||||
]
|
||||
with tempfile.TemporaryDirectory() as directory:
|
||||
@@ -153,7 +180,9 @@ class NotarizationTest(unittest.TestCase):
|
||||
output = io.StringIO()
|
||||
with (
|
||||
patch.object(notary.subprocess, "run", return_value=signature),
|
||||
patch.object(notary.urllib.request, "urlopen", side_effect=responses) as requests,
|
||||
patch.object(
|
||||
notary.urllib.request, "urlopen", side_effect=responses
|
||||
) as requests,
|
||||
patch.object(notary.time, "sleep") as sleep,
|
||||
contextlib.redirect_stdout(output),
|
||||
):
|
||||
@@ -185,9 +214,15 @@ class NotarizationWrapperTest(unittest.TestCase):
|
||||
"CALL_LOG": str(call_log),
|
||||
}
|
||||
for name in ("az", "python3", "rcodesign"):
|
||||
body = "exit 0" if name == "az" else f'printf "{name} %s\\n" "$*" >> "$CALL_LOG"'
|
||||
body = (
|
||||
"exit 0"
|
||||
if name == "az"
|
||||
else f'printf "{name} %s\\n" "$*" >> "$CALL_LOG"'
|
||||
)
|
||||
executable = tools / name
|
||||
executable.write_text(f"#!/usr/bin/env bash\nset -euo pipefail\n{body}\n")
|
||||
executable.write_text(
|
||||
f"#!/usr/bin/env bash\nset -euo pipefail\n{body}\n"
|
||||
)
|
||||
executable.chmod(0o755)
|
||||
for kind in ("binary", "dmg"):
|
||||
with self.subTest(kind=kind):
|
||||
@@ -195,7 +230,9 @@ class NotarizationWrapperTest(unittest.TestCase):
|
||||
artifact.write_bytes(b"signed release artifact")
|
||||
subprocess.run(
|
||||
[
|
||||
str(SIGNING_DIRECTORY / f"notarize_macos_{kind}_with_akv.sh"),
|
||||
str(
|
||||
SIGNING_DIRECTORY / f"notarize_macos_{kind}_with_akv.sh"
|
||||
),
|
||||
f"--{kind}",
|
||||
str(artifact),
|
||||
"--report-dir",
|
||||
|
||||
@@ -236,12 +236,7 @@ class RustyV8BazelTest(unittest.TestCase):
|
||||
TemporaryDirectory() as target_dir,
|
||||
TemporaryDirectory() as output_dir,
|
||||
):
|
||||
gn_out = (
|
||||
Path(target_dir)
|
||||
/ "x86_64-pc-windows-msvc"
|
||||
/ "release"
|
||||
/ "gn_out"
|
||||
)
|
||||
gn_out = Path(target_dir) / "x86_64-pc-windows-msvc" / "release" / "gn_out"
|
||||
(gn_out / "obj").mkdir(parents=True)
|
||||
(gn_out / "obj" / "rusty_v8.lib").write_bytes(b"archive")
|
||||
(gn_out / "src_binding.rs").write_text("binding")
|
||||
|
||||
@@ -168,9 +168,7 @@ def main() -> None:
|
||||
canary = canary_required(files, base_version, head_version)
|
||||
windows_source = windows_source_required(files, base_version, head_version)
|
||||
if base_version != head_version:
|
||||
canary_reason = (
|
||||
f"v8 version changed from {base_version} to {head_version}"
|
||||
)
|
||||
canary_reason = f"v8 version changed from {base_version} to {head_version}"
|
||||
windows_source_reason = canary_reason
|
||||
else:
|
||||
canary_reason = (
|
||||
|
||||
@@ -167,7 +167,9 @@ def manifest_errors(
|
||||
"create crate features"
|
||||
)
|
||||
|
||||
if not is_internal_dependency(path, dependency_name, dependency, internal_package_names):
|
||||
if not is_internal_dependency(
|
||||
path, dependency_name, dependency, internal_package_names
|
||||
):
|
||||
continue
|
||||
|
||||
dependency_features = dependency.get("features")
|
||||
@@ -354,7 +356,9 @@ def add_unused_exception_errors(
|
||||
)
|
||||
|
||||
|
||||
def add_failure(failures_by_path: dict[str, list[str]], path_key: str, error: str) -> None:
|
||||
def add_failure(
|
||||
failures_by_path: dict[str, list[str]], path_key: str, error: str
|
||||
) -> None:
|
||||
failures_by_path.setdefault(path_key, []).append(error)
|
||||
|
||||
|
||||
|
||||
@@ -66,7 +66,7 @@ def dependency_sections(manifest: dict) -> list[tuple[str, dict]]:
|
||||
for section_name in ("dependencies", "dev-dependencies", "build-dependencies"):
|
||||
dependencies = target.get(section_name)
|
||||
if isinstance(dependencies, dict):
|
||||
sections.append((f'target.{target_name}.{section_name}', dependencies))
|
||||
sections.append((f"target.{target_name}.{section_name}", dependencies))
|
||||
|
||||
return sections
|
||||
|
||||
@@ -77,7 +77,9 @@ def source_failures() -> list[str]:
|
||||
text = path.read_text()
|
||||
for line_number, line in enumerate(text.splitlines(), start=1):
|
||||
if any(pattern.search(line) for pattern in FORBIDDEN_SOURCE_PATTERNS):
|
||||
failures.append(f"{relative_path(path)}:{line_number} imports `codex_core`")
|
||||
failures.append(
|
||||
f"{relative_path(path)}:{line_number} imports `codex_core`"
|
||||
)
|
||||
return failures
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user