Module: Homebrew::Vulns::PlatformIndependence Private

Defined in:
vulns/platform_independence.rb

Overview

This module is part of a private API. This module may only be used in the Homebrew/brew repository. Third parties should avoid using this module if possible, as it may be removed or changed without warning.

Proves independence of the metadata read by Match, not of installation. Unknown Ruby or DSL is deliberately evaluated separately on each platform.

Constant Summary collapse

SOURCE_CALLS =

This constant is part of a private API. This constant may only be used in the Homebrew/brew repository. Third parties should avoid using this constant if possible, as it may be removed or changed without warning.

[:url, :mirror, :version, :sha256, :sha1, :md5].freeze
FORMULA_CALLS =

This constant is part of a private API. This constant may only be used in the Homebrew/brew repository. Third parties should avoid using this constant if possible, as it may be removed or changed without warning.

T.let((SOURCE_CALLS + [
  :desc, :homepage, :head, :revision, :version_scheme, :license, :depends_on,
  :uses_from_macos, :keg_only, :conflicts_with, :option, :deprecated_option,
  :deprecate!, :disable!, :pypi_packages
]).freeze, T::Array[Symbol])

Class Method Summary collapse

Class Method Details

.formula?(formula) ⇒ Boolean

This method is part of a private API. This method may only be used in the Homebrew/brew repository. Third parties should avoid using this method if possible, as it may be removed or changed without warning.

Parameters:

Returns:

  • (Boolean)


19
20
21
22
23
# File 'vulns/platform_independence.rb', line 19

def self.formula?(formula)
  source?(formula.path.read)
rescue SystemCallError
  false
end

.source?(source) ⇒ Boolean

This method is part of a private API. This method may only be used in the Homebrew/brew repository. Third parties should avoid using this method if possible, as it may be removed or changed without warning.

Parameters:

Returns:

  • (Boolean)


26
27
28
29
30
31
32
33
34
35
36
37
38
39
# File 'vulns/platform_independence.rb', line 26

def self.source?(source)
  parsed = Prism.parse(source)
  return false unless parsed.success?

  statements = parsed.value.statements.body
  definition = statements.first
  return false if !statements.one? || !definition.is_a?(Prism::ClassNode)
  return false unless definition.constant_path.is_a?(Prism::ConstantReadNode)

  parent = definition.superclass
  return false if !parent.is_a?(Prism::ConstantReadNode) || parent.name != :Formula

  body?(definition.body, :formula)
end