2 GoCheese -- Python private package repository and caching proxy
3 Copyright (C) 2019-2022 Sergey Matveev <stargrave@stargrave.org>
5 This program is free software: you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation, version 3 of the License.
9 This program is distributed in the hope that it will be useful,
10 but WITHOUT ANY WARRANTY; without even the implied warranty of
11 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 GNU General Public License for more details.
14 You should have received a copy of the GNU General Public License
15 along with this program. If not, see <http://www.gnu.org/licenses/>.
38 // https://warehouse.pypa.io/api-reference/legacy.html
41 HTMLRootTmplRaw string
42 HTMLRootTmpl = template.Must(template.New("root").Parse(HTMLRootTmplRaw))
45 HTMLReleasesTmplRaw string
46 HTMLReleasesTmpl = template.Must(template.New("list").Parse(HTMLReleasesTmplRaw))
47 KnownExts = []string{".tar.bz2", ".tar.gz", ".whl", ".zip", ".egg",
48 ".exe", ".dmg", ".msi", ".rpm", ".deb", ".tgz"}
51 func listRoot(w http.ResponseWriter, r *http.Request) {
52 files, err := os.ReadDir(Root)
54 log.Println("error", r.RemoteAddr, "root", err)
55 http.Error(w, err.Error(), http.StatusInternalServerError)
58 packages := make([]string, 0, len(files))
59 for _, f := range files {
60 packages = append(packages, f.Name())
62 sort.Strings(packages)
64 err = HTMLRootTmpl.Execute(&buf, struct {
68 RefreshURLPath: *RefreshURLPath,
72 log.Println("error", r.RemoteAddr, "root", err)
73 http.Error(w, err.Error(), http.StatusInternalServerError)
79 type PkgReleaseInfoByName []*PkgReleaseInfo
81 func (a PkgReleaseInfoByName) Len() int {
85 func (a PkgReleaseInfoByName) Swap(i, j int) {
86 a[i], a[j] = a[j], a[i]
89 func (a PkgReleaseInfoByName) Less(i, j int) bool {
90 if a[i].Version == a[j].Version {
91 return a[i].Filename < a[j].Filename
93 return a[i].Version < a[j].Version
96 // Version format is too complicated: https://www.python.org/dev/peps/pep-0386/
97 // So here is very simple parser working good enough for most packages
98 func filenameToVersion(fn string) string {
99 fn = strings.TrimSuffix(fn, GPGSigExt)
101 for _, ext := range KnownExts {
102 trimmed = strings.TrimSuffix(fn, ext)
108 cols := strings.Split(fn, "-")
109 for i := 0; i < len(cols); i++ {
110 if len(cols[i]) == 0 {
113 if ('0' <= cols[i][0]) && (cols[i][0] <= '9') {
123 func listDir(pkgName string, doSize bool) (int64, []*PkgReleaseInfo, error) {
124 dirPath := filepath.Join(Root, pkgName)
125 entries, err := os.ReadDir(dirPath)
129 files := make(map[string]fs.DirEntry, len(entries))
130 for _, entry := range entries {
134 if entry.Name()[0] == '.' {
137 files[entry.Name()] = entry
139 releaseFiles := make(map[string]*PkgReleaseInfo)
140 for _, algo := range KnownHashAlgos {
141 for fn, entry := range files {
143 return 0, nil, errors.New("killed")
145 if !strings.HasSuffix(fn, "."+algo) {
149 digest, err := os.ReadFile(filepath.Join(dirPath, fn))
153 fnClean := strings.TrimSuffix(fn, "."+algo)
154 release := releaseFiles[fnClean]
156 fi, err := entry.Info()
160 release = &PkgReleaseInfo{
162 Version: filenameToVersion(fnClean),
163 UploadTimeISO8601: fi.ModTime().UTC().Truncate(
165 ).Format(time.RFC3339),
166 Digests: make(map[string]string),
168 releaseFiles[fnClean] = release
169 if entry, exists := files[fnClean]; exists {
171 fi, err := entry.Info()
175 release.Size = fi.Size()
177 delete(files, fnClean)
179 if _, exists := files[fnClean+GPGSigExt]; exists {
180 release.HasSig = true
181 delete(files, fnClean+GPGSigExt)
184 release.Digests[algo] = hex.EncodeToString(digest)
187 releases := make([]*PkgReleaseInfo, 0, len(releaseFiles))
188 for _, release := range releaseFiles {
189 releases = append(releases, release)
191 sort.Sort(PkgReleaseInfoByName(releases))
192 fi, err := os.Stat(dirPath)
196 serial := fi.ModTime().Unix()
197 if fi, err = os.Stat(filepath.Join(dirPath, MDFile)); err == nil {
198 serial += fi.ModTime().Unix()
200 return serial, releases, nil
204 w http.ResponseWriter,
207 autorefresh, gpgUpdate bool,
209 dirPath := filepath.Join(Root, pkgName)
211 if !refreshDir(w, r, pkgName, "", gpgUpdate) {
214 } else if _, err := os.Stat(dirPath); os.IsNotExist(err) &&
215 !refreshDir(w, r, pkgName, "", false) {
218 serial, releases, err := listDir(pkgName, false)
220 log.Println("error", r.RemoteAddr, "list", pkgName, err)
221 http.Error(w, err.Error(), http.StatusInternalServerError)
224 for _, release := range releases {
225 singleDigest := make(map[string]string)
226 if digest, exists := release.Digests[HashAlgoSHA256]; exists {
227 singleDigest[HashAlgoSHA256] = digest
228 } else if digest, exists := release.Digests[HashAlgoSHA512]; exists {
229 singleDigest[HashAlgoSHA512] = digest
230 } else if digest, exists := release.Digests[HashAlgoBLAKE2b256]; exists {
231 singleDigest[HashAlgoBLAKE2b256] = digest
233 singleDigest = release.Digests
235 release.Digests = singleDigest
238 err = HTMLReleasesTmpl.Execute(&buf, struct {
239 RefreshURLPath string
241 Releases []*PkgReleaseInfo
243 RefreshURLPath: *RefreshURLPath,
248 log.Println("error", r.RemoteAddr, "list", pkgName, err)
249 http.Error(w, err.Error(), http.StatusInternalServerError)
252 w.Header().Set("X-PyPI-Last-Serial", strconv.FormatInt(serial, 10))
254 w.Write([]byte(fmt.Sprintf("<!--SERIAL %d-->\n", serial)))