Format Python scripts across the repository (#42109)

## Why

The root Python formatting pass only covered `scripts/`, leaving Python utilities elsewhere in the repository outside `just fmt` and `just fmt-check`.

## What changed

- Run the scripts Ruff formatter from the repository root.
- Exclude `sdk/python`, which has its own formatter pass, and `codex-rs/vendor`.
- Apply Ruff formatting to the newly covered Python files and update the formatter coverage test.

GitOrigin-RevId: 73ac82b8bb9c713d589724f6c4f926399febb513
This commit is contained in:
Charlie Marsh
2026-09-01 17:47:29 +00:00
committed by copyberry
parent 6a479e1813
commit 84aa75204a
31 changed files with 1020 additions and 342 deletions
@@ -49,10 +49,14 @@ class NotarizationConfiguration:
"vault_name": "AZURE_KEYVAULT_NAME",
"vault_key_name": "APPLE_NOTARIZATION_AKV_KEY_NAME",
}
values = {field: os.environ.get(name, "").strip() for field, name in required.items()}
values = {
field: os.environ.get(name, "").strip() for field, name in required.items()
}
missing = [name for field, name in required.items() if not values[field]]
if missing:
raise NotarizationError("Missing notarization configuration: " + ", ".join(missing))
raise NotarizationError(
"Missing notarization configuration: " + ", ".join(missing)
)
if not re.fullmatch(r"[A-Za-z][A-Za-z0-9-]{2,23}", values["vault_name"]):
raise NotarizationError("Invalid signing vault name")
if not re.fullmatch(r"[A-Za-z0-9-]+", values["vault_key_name"]):
@@ -90,7 +94,9 @@ class NotarizationConfiguration:
try:
result = subprocess.run(command, check=True, capture_output=True, text=True)
except (OSError, subprocess.CalledProcessError) as error:
raise NotarizationError("Notarization signing key could not be read") from error
raise NotarizationError(
"Notarization signing key could not be read"
) from error
try:
metadata = json.loads(result.stdout)
returned_key_id = metadata["id"]
@@ -99,10 +105,10 @@ class NotarizationConfiguration:
except (json.JSONDecodeError, KeyError, TypeError) as error:
raise NotarizationError("Notarization key metadata is invalid") from error
key_id_prefix = (
f"https://{values['vault_name']}.vault.azure.net/keys/{values['vault_key_name']}/"
)
if not isinstance(returned_key_id, str) or not returned_key_id.startswith(key_id_prefix):
key_id_prefix = f"https://{values['vault_name']}.vault.azure.net/keys/{values['vault_key_name']}/"
if not isinstance(returned_key_id, str) or not returned_key_id.startswith(
key_id_prefix
):
raise NotarizationError("Unexpected notarization signing key")
returned_key_version = returned_key_id[len(key_id_prefix) :]
if not re.fullmatch(r"[0-9a-fA-F]{32}", returned_key_version):
@@ -120,7 +126,9 @@ class NotarizationConfiguration:
r"[0-9a-fA-F]{4}-[0-9a-fA-F]{12}",
apple_issuer_id.strip(),
):
raise NotarizationError("Notarization apple-issuer-id tag must contain a valid UUID")
raise NotarizationError(
"Notarization apple-issuer-id tag must contain a valid UUID"
)
values["issuer_id"] = apple_issuer_id.strip()
values["apple_key_id"] = apple_key_id.strip()
@@ -147,12 +155,18 @@ def base64url_decode(value: str) -> bytes:
"""Decode a base64url value and reject malformed input."""
try:
return base64.b64decode(value + "=" * (-len(value) % 4), altchars=b"-_", validate=True)
return base64.b64decode(
value + "=" * (-len(value) % 4), altchars=b"-_", validate=True
)
except (ValueError, UnicodeEncodeError) as error:
raise NotarizationError("Signing service returned an invalid signature") from error
raise NotarizationError(
"Signing service returned an invalid signature"
) from error
def create_apple_jwt(configuration: NotarizationConfiguration, *, issued_at: int) -> str:
def create_apple_jwt(
configuration: NotarizationConfiguration, *, issued_at: int
) -> str:
"""Create an authentication token for notarization requests."""
header = {"alg": "ES256", "kid": configuration.apple_key_id, "typ": "JWT"}
@@ -164,8 +178,12 @@ def create_apple_jwt(configuration: NotarizationConfiguration, *, issued_at: int
"aud": "appstoreconnect-v1",
"scope": ["/notary/v2"],
}
encoded_header = base64url_encode(json.dumps(header, separators=(",", ":")).encode("utf-8"))
encoded_claims = base64url_encode(json.dumps(claims, separators=(",", ":")).encode("utf-8"))
encoded_header = base64url_encode(
json.dumps(header, separators=(",", ":")).encode("utf-8")
)
encoded_claims = base64url_encode(
json.dumps(claims, separators=(",", ":")).encode("utf-8")
)
signing_input = f"{encoded_header}.{encoded_claims}"
digest = hashlib.sha256(signing_input.encode("ascii")).digest()
key_url = configuration.versioned_key_id
@@ -206,7 +224,9 @@ def create_apple_jwt(configuration: NotarizationConfiguration, *, issued_at: int
returned_key_id = response["kid"]
encoded_signature = response["value"]
except (json.JSONDecodeError, KeyError, TypeError) as error:
raise NotarizationError("Signing service returned an invalid response") from error
raise NotarizationError(
"Signing service returned an invalid response"
) from error
# Reject signatures generated with a different key version.
if returned_key_id != key_url:
@@ -220,7 +240,9 @@ def create_apple_jwt(configuration: NotarizationConfiguration, *, issued_at: int
return f"{signing_input}.{base64url_encode(signature)}"
def json_request(url: str, token: str, *, body: dict[str, Any] | None = None) -> dict[str, Any]:
def json_request(
url: str, token: str, *, body: dict[str, Any] | None = None
) -> dict[str, Any]:
"""Send an authenticated JSON request to Apple's notarization service."""
data = None if body is None else json.dumps(body).encode("utf-8")
@@ -239,7 +261,9 @@ def json_request(url: str, token: str, *, body: dict[str, Any] | None = None) ->
result = json.load(response)
except urllib.error.HTTPError as error:
detail = error.read(1024).decode("utf-8", errors="replace")
raise NotarizationError(f"Apple Notary API returned HTTP {error.code}: {detail}") from error
raise NotarizationError(
f"Apple Notary API returned HTTP {error.code}: {detail}"
) from error
except (OSError, json.JSONDecodeError) as error:
raise NotarizationError("Apple Notary API request failed") from error
@@ -281,9 +305,12 @@ def upload_to_apple_s3(
"object",
)
if any(
not isinstance(credentials.get(name), str) or not credentials[name] for name in required
not isinstance(credentials.get(name), str) or not credentials[name]
for name in required
):
raise NotarizationError("Apple returned incomplete temporary upload credentials")
raise NotarizationError(
"Apple returned incomplete temporary upload credentials"
)
size = path.stat().st_size
if not 0 < size <= MAX_SINGLE_UPLOAD_BYTES:
@@ -293,7 +320,9 @@ def upload_to_apple_s3(
amz_date = now.strftime("%Y%m%dT%H%M%SZ")
date_stamp = now.strftime("%Y%m%d")
host = f"{credentials['bucket']}.s3.{AWS_REGION}.amazonaws.com"
object_path = "/" + urllib.parse.quote(credentials["object"].lstrip("/"), safe="/-_.~")
object_path = "/" + urllib.parse.quote(
credentials["object"].lstrip("/"), safe="/-_.~"
)
headers = {
"content-type": "application/octet-stream",
"host": host,
@@ -319,7 +348,9 @@ def upload_to_apple_s3(
signing_key = ("AWS4" + credentials["awsSecretAccessKey"]).encode("utf-8")
for component in (date_stamp, AWS_REGION, "s3", "aws4_request"):
signing_key = hmac_sha256(signing_key, component)
signature = hmac.new(signing_key, string_to_sign.encode("utf-8"), hashlib.sha256).hexdigest()
signature = hmac.new(
signing_key, string_to_sign.encode("utf-8"), hashlib.sha256
).hexdigest()
authorization = (
"AWS4-HMAC-SHA256 "
f"Credential={credentials['awsAccessKeyId']}/{credential_scope}, "
@@ -346,10 +377,14 @@ def upload_to_apple_s3(
f"Apple notarization payload upload failed with HTTP {error.code}"
) from error
except OSError as error:
raise NotarizationError("Apple notarization payload upload failed") from error
raise NotarizationError(
"Apple notarization payload upload failed"
) from error
def write_developer_log(submission_id: str, token: str, destination: Path | None) -> None:
def write_developer_log(
submission_id: str, token: str, destination: Path | None
) -> None:
"""Write the submission's optional diagnostic report."""
if destination is None:
@@ -358,9 +393,13 @@ def write_developer_log(submission_id: str, token: str, destination: Path | None
try:
log_url = response["data"]["attributes"]["developerLogUrl"]
except (KeyError, TypeError) as error:
raise NotarizationError("Apple did not provide a notarization developer log") from error
raise NotarizationError(
"Apple did not provide a notarization developer log"
) from error
if not isinstance(log_url, str) or not log_url.startswith("https://"):
raise NotarizationError("Apple returned an invalid notarization developer log URL")
raise NotarizationError(
"Apple returned an invalid notarization developer log URL"
)
try:
# Do not forward unrelated authorization headers to the download URL.
with urllib.request.urlopen(log_url, timeout=60) as response:
@@ -370,7 +409,9 @@ def write_developer_log(submission_id: str, token: str, destination: Path | None
f"Apple notarization developer log download failed with HTTP {error.code}"
) from error
except OSError as error:
raise NotarizationError("Apple notarization developer log download failed") from error
raise NotarizationError(
"Apple notarization developer log download failed"
) from error
def notarize(
@@ -395,11 +436,15 @@ def notarize(
submission_id = response["data"]["id"]
upload_credentials = response["data"]["attributes"]
except (KeyError, TypeError) as error:
raise NotarizationError("Apple returned an invalid notarization submission") from error
raise NotarizationError(
"Apple returned an invalid notarization submission"
) from error
if not isinstance(submission_id, str) or not submission_id:
raise NotarizationError("Apple did not return a notarization submission ID")
if not isinstance(upload_credentials, dict):
raise NotarizationError("Apple returned invalid notarization upload credentials")
raise NotarizationError(
"Apple returned invalid notarization upload credentials"
)
print(f"Uploading notarization submission {submission_id} for {path.name}")
upload_to_apple_s3(path, file_digest, upload_credentials)
@@ -416,7 +461,9 @@ def notarize(
try:
status = result["data"]["attributes"]["status"]
except (KeyError, TypeError) as error:
raise NotarizationError("Apple returned an invalid notarization status") from error
raise NotarizationError(
"Apple returned an invalid notarization status"
) from error
if status in {"Accepted", "Invalid", "Rejected"}:
# Save diagnostics for both accepted and rejected submissions.
@@ -449,7 +496,9 @@ def main() -> int:
try:
if not arguments.file.is_file():
raise NotarizationError(f"Notarization payload does not exist: {arguments.file}")
raise NotarizationError(
f"Notarization payload does not exist: {arguments.file}"
)
if arguments.max_wait_seconds < 0:
raise NotarizationError("--max-wait-seconds must be non-negative")
if arguments.report_log is not None:
@@ -35,7 +35,9 @@ CREDENTIALS = {
def response(payload):
return io.BytesIO(json.dumps(payload).encode() if isinstance(payload, dict) else payload)
return io.BytesIO(
json.dumps(payload).encode() if isinstance(payload, dict) else payload
)
def azure_response(payload):
@@ -66,10 +68,16 @@ class NotarizationTest(unittest.TestCase):
notary.NotarizationConfiguration.from_environment()
for issuer_id in (None, "", " "):
with self.subTest(issuer_id=issuer_id):
show.return_value = azure_response({**metadata, "apple_issuer_id": issuer_id})
with self.assertRaisesRegex(notary.NotarizationError, "apple-issuer-id tag"):
show.return_value = azure_response(
{**metadata, "apple_issuer_id": issuer_id}
)
with self.assertRaisesRegex(
notary.NotarizationError, "apple-issuer-id tag"
):
notary.NotarizationConfiguration.from_environment()
show.return_value = azure_response({**metadata, "apple_issuer_id": "invalid-issuer"})
show.return_value = azure_response(
{**metadata, "apple_issuer_id": "invalid-issuer"}
)
with self.assertRaisesRegex(notary.NotarizationError, "valid UUID"):
notary.NotarizationConfiguration.from_environment()
self.assertIn(
@@ -78,7 +86,10 @@ class NotarizationTest(unittest.TestCase):
show.call_args.args[0],
)
invalid_environment = {**ENVIRONMENT, "APPLE_NOTARIZATION_AKV_KEY_NAME": "../bad"}
invalid_environment = {
**ENVIRONMENT,
"APPLE_NOTARIZATION_AKV_KEY_NAME": "../bad",
}
with (
patch.dict(os.environ, invalid_environment, clear=True),
self.assertRaisesRegex(notary.NotarizationError, "key name"),
@@ -91,10 +102,14 @@ class NotarizationTest(unittest.TestCase):
"kid": CONFIGURATION.versioned_key_id,
"value": notary.base64url_encode(signature),
}
with patch.object(notary.subprocess, "run", return_value=azure_response(payload)) as sign:
with patch.object(
notary.subprocess, "run", return_value=azure_response(payload)
) as sign:
token = notary.create_apple_jwt(CONFIGURATION, issued_at=1_780_000_000)
header, claims, encoded_signature = token.split(".")
self.assertEqual(json.loads(notary.base64url_decode(header))["kid"], "APPLEKEY01")
self.assertEqual(
json.loads(notary.base64url_decode(header))["kid"], "APPLEKEY01"
)
self.assertEqual(
json.loads(notary.base64url_decode(claims))["iss"], CONFIGURATION.issuer_id
)
@@ -113,7 +128,11 @@ class NotarizationTest(unittest.TestCase):
def test_rejects_wrong_key_versions_and_invalid_signatures(self) -> None:
cases = (
(CONFIGURATION.versioned_key_id + "wrong", bytes(64), "unexpected key version"),
(
CONFIGURATION.versioned_key_id + "wrong",
bytes(64),
"unexpected key version",
),
(CONFIGURATION.versioned_key_id, b"short", "64 JOSE"),
)
for key_id, signature, message in cases:
@@ -141,7 +160,15 @@ class NotarizationTest(unittest.TestCase):
response(b""),
response({"data": {"attributes": {"status": "In Progress"}}}),
response({"data": {"attributes": {"status": "Accepted"}}}),
response({"data": {"attributes": {"developerLogUrl": "https://logs.example.com/log"}}}),
response(
{
"data": {
"attributes": {
"developerLogUrl": "https://logs.example.com/log"
}
}
}
),
response(b'{"status":"Accepted"}'),
]
with tempfile.TemporaryDirectory() as directory:
@@ -153,7 +180,9 @@ class NotarizationTest(unittest.TestCase):
output = io.StringIO()
with (
patch.object(notary.subprocess, "run", return_value=signature),
patch.object(notary.urllib.request, "urlopen", side_effect=responses) as requests,
patch.object(
notary.urllib.request, "urlopen", side_effect=responses
) as requests,
patch.object(notary.time, "sleep") as sleep,
contextlib.redirect_stdout(output),
):
@@ -185,9 +214,15 @@ class NotarizationWrapperTest(unittest.TestCase):
"CALL_LOG": str(call_log),
}
for name in ("az", "python3", "rcodesign"):
body = "exit 0" if name == "az" else f'printf "{name} %s\\n" "$*" >> "$CALL_LOG"'
body = (
"exit 0"
if name == "az"
else f'printf "{name} %s\\n" "$*" >> "$CALL_LOG"'
)
executable = tools / name
executable.write_text(f"#!/usr/bin/env bash\nset -euo pipefail\n{body}\n")
executable.write_text(
f"#!/usr/bin/env bash\nset -euo pipefail\n{body}\n"
)
executable.chmod(0o755)
for kind in ("binary", "dmg"):
with self.subTest(kind=kind):
@@ -195,7 +230,9 @@ class NotarizationWrapperTest(unittest.TestCase):
artifact.write_bytes(b"signed release artifact")
subprocess.run(
[
str(SIGNING_DIRECTORY / f"notarize_macos_{kind}_with_akv.sh"),
str(
SIGNING_DIRECTORY / f"notarize_macos_{kind}_with_akv.sh"
),
f"--{kind}",
str(artifact),
"--report-dir",
+1 -6
View File
@@ -236,12 +236,7 @@ class RustyV8BazelTest(unittest.TestCase):
TemporaryDirectory() as target_dir,
TemporaryDirectory() as output_dir,
):
gn_out = (
Path(target_dir)
/ "x86_64-pc-windows-msvc"
/ "release"
/ "gn_out"
)
gn_out = Path(target_dir) / "x86_64-pc-windows-msvc" / "release" / "gn_out"
(gn_out / "obj").mkdir(parents=True)
(gn_out / "obj" / "rusty_v8.lib").write_bytes(b"archive")
(gn_out / "src_binding.rs").write_text("binding")
+1 -3
View File
@@ -168,9 +168,7 @@ def main() -> None:
canary = canary_required(files, base_version, head_version)
windows_source = windows_source_required(files, base_version, head_version)
if base_version != head_version:
canary_reason = (
f"v8 version changed from {base_version} to {head_version}"
)
canary_reason = f"v8 version changed from {base_version} to {head_version}"
windows_source_reason = canary_reason
else:
canary_reason = (
@@ -167,7 +167,9 @@ def manifest_errors(
"create crate features"
)
if not is_internal_dependency(path, dependency_name, dependency, internal_package_names):
if not is_internal_dependency(
path, dependency_name, dependency, internal_package_names
):
continue
dependency_features = dependency.get("features")
@@ -354,7 +356,9 @@ def add_unused_exception_errors(
)
def add_failure(failures_by_path: dict[str, list[str]], path_key: str, error: str) -> None:
def add_failure(
failures_by_path: dict[str, list[str]], path_key: str, error: str
) -> None:
failures_by_path.setdefault(path_key, []).append(error)
+4 -2
View File
@@ -66,7 +66,7 @@ def dependency_sections(manifest: dict) -> list[tuple[str, dict]]:
for section_name in ("dependencies", "dev-dependencies", "build-dependencies"):
dependencies = target.get(section_name)
if isinstance(dependencies, dict):
sections.append((f'target.{target_name}.{section_name}', dependencies))
sections.append((f"target.{target_name}.{section_name}", dependencies))
return sections
@@ -77,7 +77,9 @@ def source_failures() -> list[str]:
text = path.read_text()
for line_number, line in enumerate(text.splitlines(), start=1):
if any(pattern.search(line) for pattern in FORBIDDEN_SOURCE_PATTERNS):
failures.append(f"{relative_path(path)}:{line_number} imports `codex_core`")
failures.append(
f"{relative_path(path)}:{line_number} imports `codex_core`"
)
return failures