2 GoCheese -- Python private package repository and caching proxy
3 Copyright (C) 2019-2022 Sergey Matveev <stargrave@stargrave.org>
5 This program is free software: you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation, version 3 of the License.
9 This program is distributed in the hope that it will be useful,
10 but WITHOUT ANY WARRANTY; without even the implied warranty of
11 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 GNU General Public License for more details.
14 You should have received a copy of the GNU General Public License
15 along with this program. If not, see <http://www.gnu.org/licenses/>.
39 // https://warehouse.pypa.io/api-reference/legacy.html
42 HTMLRootTmplRaw string
43 HTMLRootTmpl = template.Must(template.New("root").Parse(HTMLRootTmplRaw))
46 HTMLReleasesTmplRaw string
47 HTMLReleasesTmpl = template.Must(template.New("list").Parse(HTMLReleasesTmplRaw))
48 KnownExts = []string{".tar.bz2", ".tar.gz", ".whl", ".zip", ".egg",
49 ".exe", ".dmg", ".msi", ".rpm", ".deb", ".tgz"}
52 func listRoot(w http.ResponseWriter, r *http.Request) {
53 files, err := ioutil.ReadDir(Root)
55 log.Println("error", r.RemoteAddr, "root", err)
56 http.Error(w, err.Error(), http.StatusInternalServerError)
59 packages := make([]string, 0, len(files))
60 for _, f := range files {
61 packages = append(packages, f.Name())
63 sort.Strings(packages)
65 err = HTMLRootTmpl.Execute(&buf, struct {
69 RefreshURLPath: *RefreshURLPath,
73 log.Println("error", r.RemoteAddr, "root", err)
74 http.Error(w, err.Error(), http.StatusInternalServerError)
80 type PkgReleaseInfoByName []*PkgReleaseInfo
82 func (a PkgReleaseInfoByName) Len() int {
86 func (a PkgReleaseInfoByName) Swap(i, j int) {
87 a[i], a[j] = a[j], a[i]
90 func (a PkgReleaseInfoByName) Less(i, j int) bool {
91 if a[i].Version == a[j].Version {
92 return a[i].Filename < a[j].Filename
94 return a[i].Version < a[j].Version
97 // Version format is too complicated: https://www.python.org/dev/peps/pep-0386/
98 // So here is very simple parser working good enough for most packages
99 func filenameToVersion(fn string) string {
100 fn = strings.TrimSuffix(fn, GPGSigExt)
102 for _, ext := range KnownExts {
103 trimmed = strings.TrimSuffix(fn, ext)
109 cols := strings.Split(fn, "-")
110 for i := 0; i < len(cols); i++ {
111 if len(cols[i]) == 0 {
114 if ('0' <= cols[i][0]) && (cols[i][0] <= '9') {
124 func listDir(pkgName string, doSize bool) (int64, []*PkgReleaseInfo, error) {
125 dirPath := filepath.Join(Root, pkgName)
126 entries, err := os.ReadDir(dirPath)
130 files := make(map[string]fs.DirEntry, len(entries))
131 for _, entry := range entries {
135 if entry.Name()[0] == '.' {
138 files[entry.Name()] = entry
140 releaseFiles := make(map[string]*PkgReleaseInfo)
141 for _, algo := range KnownHashAlgos {
142 for fn, entry := range files {
144 return 0, nil, errors.New("killed")
146 if !strings.HasSuffix(fn, "."+algo) {
150 digest, err := ioutil.ReadFile(filepath.Join(dirPath, fn))
154 fnClean := strings.TrimSuffix(fn, "."+algo)
155 release := releaseFiles[fnClean]
157 fi, err := entry.Info()
161 release = &PkgReleaseInfo{
163 Version: filenameToVersion(fnClean),
164 UploadTimeISO8601: fi.ModTime().UTC().Truncate(
166 ).Format(time.RFC3339),
167 Digests: make(map[string]string),
169 releaseFiles[fnClean] = release
170 if entry, exists := files[fnClean]; exists {
172 fi, err := entry.Info()
176 release.Size = fi.Size()
178 delete(files, fnClean)
180 if _, exists := files[fnClean+GPGSigExt]; exists {
181 release.HasSig = true
182 delete(files, fnClean+GPGSigExt)
185 release.Digests[algo] = hex.EncodeToString(digest)
188 releases := make([]*PkgReleaseInfo, 0, len(releaseFiles))
189 for _, release := range releaseFiles {
190 releases = append(releases, release)
192 sort.Sort(PkgReleaseInfoByName(releases))
193 fi, err := os.Stat(dirPath)
197 serial := fi.ModTime().Unix()
198 if fi, err = os.Stat(filepath.Join(dirPath, MDFile)); err == nil {
199 serial += fi.ModTime().Unix()
201 return serial, releases, nil
205 w http.ResponseWriter,
208 autorefresh, gpgUpdate bool,
210 dirPath := filepath.Join(Root, pkgName)
212 if !refreshDir(w, r, pkgName, "", gpgUpdate) {
215 } else if _, err := os.Stat(dirPath); os.IsNotExist(err) &&
216 !refreshDir(w, r, pkgName, "", false) {
219 serial, releases, err := listDir(pkgName, false)
221 log.Println("error", r.RemoteAddr, "list", pkgName, err)
222 http.Error(w, err.Error(), http.StatusInternalServerError)
225 for _, release := range releases {
226 singleDigest := make(map[string]string)
227 if digest, exists := release.Digests[HashAlgoSHA256]; exists {
228 singleDigest[HashAlgoSHA256] = digest
229 } else if digest, exists := release.Digests[HashAlgoSHA512]; exists {
230 singleDigest[HashAlgoSHA512] = digest
231 } else if digest, exists := release.Digests[HashAlgoBLAKE2b256]; exists {
232 singleDigest[HashAlgoBLAKE2b256] = digest
234 singleDigest = release.Digests
236 release.Digests = singleDigest
239 err = HTMLReleasesTmpl.Execute(&buf, struct {
240 RefreshURLPath string
242 Releases []*PkgReleaseInfo
244 RefreshURLPath: *RefreshURLPath,
249 log.Println("error", r.RemoteAddr, "list", pkgName, err)
250 http.Error(w, err.Error(), http.StatusInternalServerError)
253 w.Header().Set("X-PyPI-Last-Serial", strconv.FormatInt(serial, 10))
255 w.Write([]byte(fmt.Sprintf("<!--SERIAL %d-->\n", serial)))