Something went wrong. Try again.
Maps Linux distribution source packages to their upstream repositories, and through them to each other
Something went wrong. Try again.
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117// Package bulk holds the association table: every source package of a distribution suite,// resolved to an upstream repository, with the evidence behind each mapping. It is built from// whole-archive sources (UDD for Debian) rather than one package at a time, and published as// JSONL (canonical, diffable) and SQLite (for queries; Python reads it with the standard// library).package bulk
import ( "regexp" "strings" "time"
"tangled.org/odd.computer/isomorph/internal/model")
// Status values of Package.Status.const ( // StatusResolved: the best candidate is a repository. StatusResolved = "resolved" // StatusUnresolved: no field named or hinted at a repository. StatusUnresolved = "unresolved")
// Basis values: the kind of evidence behind a mapping, strongest first.const ( // BasisMetadata: a field whose purpose is to name the upstream repository (DEP-12 // Repository, Repository-Browse). BasisMetadata = "metadata" // BasisVCSSource: the package builds from the repository (an Arch git source). BasisVCSSource = "vcs-source" // BasisReleaseURL: a release tarball or debian/watch URL on a forge, or a tarball on a // host whose repository is known (ftp.gnu.org -> Savannah). BasisReleaseURL = "release-url" // BasisDerived: a third-party dataset derived from the packaging (rb.zq1.de giturls, itself // computed from spec Url:/Source: fields). BasisDerived = "derived" // BasisBugTracker: a bug tracker URL on a forge (DEP-12 Bug-Database). BasisBugTracker = "bug-tracker" // BasisHomepage: a homepage on a forge or a well-known project site. BasisHomepage = "homepage" // BasisSecondary is a secondary spec source (Source1 and up: configuration files, shell // completions, test dependencies). It corroborates a candidate but never decides one: of // the openSUSE packages it alone resolved, about a third named another project's // repository (docs/EVALUATION.md). BasisSecondary = "secondary-source")
// basisRank orders the bases, strongest first.var basisRank = map[string]int{BasisMetadata: 0, BasisVCSSource: 1, BasisReleaseURL: 2, BasisDerived: 3, BasisBugTracker: 4, BasisHomepage: 5, BasisSecondary: 6}
var secondarySpecSourceRe = regexp.MustCompile(`^spec:Source[1-9][0-9]*$`)
// BasisOf maps an evidence source name onto its basis.func BasisOf(source string) string { switch { case source == "debian/upstream/metadata:Repository", source == "debian/upstream/metadata:Repository-Browse": return BasisMetadata case strings.HasPrefix(source, "SRCINFO:source:"), strings.HasPrefix(source, "APKBUILD:source:"), source == "APKBUILD:_repo_url", source == "spec:Git-Clone": return BasisVCSSource case strings.HasPrefix(source, "_service:"): // obs_scm, tar_scm and the like fetch a repository; download_url and download_files // fetch release files. if strings.HasPrefix(source, "_service:download") { return BasisReleaseURL } return BasisVCSSource case secondarySpecSourceRe.MatchString(source): return BasisSecondary case source == "SRCINFO:source", source == "APKBUILD:source", source == "debian/watch:upstream_url", strings.HasPrefix(source, "spec:Source"): return BasisReleaseURL case source == "debian/upstream/metadata:Bug-Database": return BasisBugTracker case source == "zq1:giturls": return BasisDerived } return BasisHomepage}
// Package is one source package (Debian source, openSUSE spec, Arch pkgbase, Alpine origin)// in one suite, with its resolved upstream.type Package struct { Distro model.Distro `json:"distro"` Suite string `json:"suite"` Name string `json:"package"` // Version is the distro version, as the distro writes it. Version string `json:"version"` // OSVEcosystem is the OSV ecosystem string ("Debian:sid"); empty where OSV defines none. OSVEcosystem string `json:"osv_ecosystem,omitempty"` // PURL identifies the source package (advisory: purl's distro qualifiers are not // standardised, so consumers should key on (OSVEcosystem, Name)). PURL string `json:"purl,omitempty"` Binaries []string `json:"binaries,omitempty"` Homepage string `json:"homepage,omitempty"` // UpstreamKey is the repourl key of the best candidate; Repo is its clone URL, ready for an // OSV GIT range. UpstreamKey string `json:"upstream_key,omitempty"` Repo string `json:"repo,omitempty"` Status string `json:"status"` // Basis is the kind of evidence that decided the mapping (Basis* constants). The evaluation // reports measured agreement per basis; there is deliberately no numeric confidence. Basis string `json:"basis,omitempty"` // Evidence lists every observation considered, highest weight first. Evidence []model.Evidence `json:"evidence,omitempty"` // SourceSHA256 are the sha256 of the upstream source archives the package builds from // (Debian .orig tarballs); equal hashes across distros mean the same upstream release. SourceSHA256 []string `json:"source_sha256,omitempty"`}
// Source describes where one (distro, suite) slice of the table came from.type Source struct { Distro model.Distro `json:"distro"` Suite string `json:"suite"` Origin string `json:"origin"` FetchedAt time.Time `json:"fetched_at"` Packages int `json:"packages"`}