tidy/
deps.rs

1//! Checks the licenses of third-party dependencies.
2
3use std::collections::{HashMap, HashSet};
4use std::fmt::{Display, Formatter};
5use std::fs::{File, read_dir};
6use std::io::Write;
7use std::path::Path;
8
9use build_helper::ci::CiEnv;
10use cargo_metadata::semver::Version;
11use cargo_metadata::{Metadata, Package, PackageId};
12
13use crate::diagnostics::{RunningCheck, TidyCtx};
14
15#[path = "../../../bootstrap/src/utils/proc_macro_deps.rs"]
16mod proc_macro_deps;
17
18#[derive(Clone, Copy)]
19struct ListLocation {
20    path: &'static str,
21    line: u32,
22}
23
24impl Display for ListLocation {
25    fn fmt(&self, f: &mut Formatter<'_>) -> std::fmt::Result {
26        write!(f, "{}:{}", self.path, self.line)
27    }
28}
29
30/// Creates a [`ListLocation`] for the current location (with an additional offset to the actual list start);
31macro_rules! location {
32    (+ $offset:literal) => {
33        ListLocation { path: file!(), line: line!() + $offset }
34    };
35}
36
37/// These are licenses that are allowed for all crates, including the runtime,
38/// rustc, tools, etc.
39#[rustfmt::skip]
40const LICENSES: &[&str] = &[
41    // tidy-alphabetical-start
42    "0BSD OR MIT OR Apache-2.0",                           // adler2 license
43    "Apache-2.0 / MIT",
44    "Apache-2.0 OR ISC OR MIT",
45    "Apache-2.0 OR MIT",
46    "Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT", // wasi license
47    "Apache-2.0/MIT",
48    "BSD-2-Clause OR Apache-2.0 OR MIT",                   // zerocopy
49    "BSD-2-Clause OR MIT OR Apache-2.0",
50    "BSD-3-Clause/MIT",
51    "CC0-1.0 OR MIT-0 OR Apache-2.0",
52    "ISC",
53    "MIT / Apache-2.0",
54    "MIT AND (MIT OR Apache-2.0)",
55    "MIT AND Apache-2.0 WITH LLVM-exception AND (MIT OR Apache-2.0)", // compiler-builtins
56    "MIT OR Apache-2.0 OR BSD-1-Clause",
57    "MIT OR Apache-2.0 OR LGPL-2.1-or-later",              // r-efi, r-efi-alloc; LGPL is not acceptable, but we use it under MIT OR Apache-2.0
58    "MIT OR Apache-2.0 OR Zlib",                           // tinyvec_macros
59    "MIT OR Apache-2.0",
60    "MIT OR Zlib OR Apache-2.0",                           // miniz_oxide
61    "MIT",
62    "MIT/Apache-2.0",
63    "Unlicense OR MIT",
64    "Unlicense/MIT",
65    "Zlib",                                                // foldhash (FIXME: see PERMITTED_STDLIB_DEPENDENCIES)
66    // tidy-alphabetical-end
67];
68
69/// These are licenses that are allowed for rustc, tools, etc. But not for the runtime!
70#[rustfmt::skip]
71const LICENSES_TOOLS: &[&str] = &[
72    // tidy-alphabetical-start
73    "(Apache-2.0 OR MIT) AND BSD-3-Clause",
74    "(MIT OR Apache-2.0) AND Unicode-3.0",                 // unicode_ident (1.0.14)
75    "(MIT OR Apache-2.0) AND Unicode-DFS-2016",            // unicode_ident (1.0.12)
76    "0BSD",
77    "Apache-2.0 AND ISC",
78    "Apache-2.0 OR BSL-1.0",  // BSL is not acceptable, but we use it under Apache-2.0
79    "Apache-2.0 OR GPL-2.0-only",
80    "Apache-2.0 WITH LLVM-exception",
81    "Apache-2.0",
82    "BSD-2-Clause",
83    "BSD-3-Clause",
84    "CC0-1.0 OR Apache-2.0 OR Apache-2.0 WITH LLVM-exception",
85    "CC0-1.0",
86    "Unicode-3.0",                                         // icu4x
87    "Unicode-DFS-2016",                                    // tinystr
88    "Zlib OR Apache-2.0 OR MIT",                           // tinyvec
89    "Zlib",
90    // tidy-alphabetical-end
91];
92
93type ExceptionList = &'static [(&'static str, &'static str)];
94
95#[derive(Clone, Copy)]
96pub(crate) struct WorkspaceInfo<'a> {
97    /// Path to the directory containing the workspace root Cargo.toml file.
98    pub(crate) path: &'a str,
99    /// The list of license exceptions.
100    pub(crate) exceptions: ExceptionList,
101    /// Optionally:
102    /// * A list of crates for which dependencies need to be explicitly allowed.
103    /// * The list of allowed dependencies.
104    /// * The source code location of the allowed dependencies list
105    crates_and_deps: Option<(&'a [&'a str], &'a [&'a str], ListLocation)>,
106    /// Submodules required for the workspace
107    pub(crate) submodules: &'a [&'a str],
108}
109
110const WORKSPACE_LOCATION: ListLocation = location!(+4);
111
112/// The workspaces to check for licensing and optionally permitted dependencies.
113// FIXME auto detect all cargo workspaces
114pub(crate) const WORKSPACES: &[WorkspaceInfo<'static>] = &[
115    // The root workspace has to be first for check_rustfix to work.
116    WorkspaceInfo {
117        path: ".",
118        exceptions: EXCEPTIONS,
119        crates_and_deps: Some((
120            &["rustc-main"],
121            PERMITTED_RUSTC_DEPENDENCIES,
122            PERMITTED_RUSTC_DEPS_LOCATION,
123        )),
124        submodules: &[],
125    },
126    WorkspaceInfo {
127        path: "library",
128        exceptions: EXCEPTIONS_STDLIB,
129        crates_and_deps: Some((
130            &["sysroot"],
131            PERMITTED_STDLIB_DEPENDENCIES,
132            PERMITTED_STDLIB_DEPS_LOCATION,
133        )),
134        submodules: &[],
135    },
136    WorkspaceInfo {
137        path: "compiler/rustc_codegen_cranelift",
138        exceptions: EXCEPTIONS_CRANELIFT,
139        crates_and_deps: Some((
140            &["rustc_codegen_cranelift"],
141            PERMITTED_CRANELIFT_DEPENDENCIES,
142            PERMITTED_CRANELIFT_DEPS_LOCATION,
143        )),
144        submodules: &[],
145    },
146    WorkspaceInfo {
147        path: "compiler/rustc_codegen_gcc",
148        exceptions: EXCEPTIONS_GCC,
149        crates_and_deps: None,
150        submodules: &[],
151    },
152    WorkspaceInfo {
153        path: "src/bootstrap",
154        exceptions: EXCEPTIONS_BOOTSTRAP,
155        crates_and_deps: None,
156        submodules: &[],
157    },
158    WorkspaceInfo {
159        path: "src/tools/cargo",
160        exceptions: EXCEPTIONS_CARGO,
161        crates_and_deps: None,
162        submodules: &["src/tools/cargo"],
163    },
164    // FIXME uncomment once all deps are vendored
165    //  WorkspaceInfo {
166    //      path: "src/tools/miri/test-cargo-miri",
167    //      crates_and_deps: None
168    //      submodules: &[],
169    //  },
170    // WorkspaceInfo {
171    //      path: "src/tools/miri/test_dependencies",
172    //      crates_and_deps: None,
173    //      submodules: &[],
174    //  }
175    WorkspaceInfo {
176        path: "src/tools/rust-analyzer",
177        exceptions: EXCEPTIONS_RUST_ANALYZER,
178        crates_and_deps: None,
179        submodules: &[],
180    },
181    WorkspaceInfo {
182        path: "src/tools/rustbook",
183        exceptions: EXCEPTIONS_RUSTBOOK,
184        crates_and_deps: None,
185        submodules: &["src/doc/book", "src/doc/reference"],
186    },
187    WorkspaceInfo {
188        path: "src/tools/rustc-perf",
189        exceptions: EXCEPTIONS_RUSTC_PERF,
190        crates_and_deps: None,
191        submodules: &["src/tools/rustc-perf"],
192    },
193    WorkspaceInfo {
194        path: "tests/run-make-cargo/uefi-qemu/uefi_qemu_test",
195        exceptions: EXCEPTIONS_UEFI_QEMU_TEST,
196        crates_and_deps: None,
197        submodules: &[],
198    },
199];
200
201/// These are exceptions to Rust's permissive licensing policy, and
202/// should be considered bugs. Exceptions are only allowed in Rust
203/// tooling. It is _crucial_ that no exception crates be dependencies
204/// of the Rust runtime (std/test).
205#[rustfmt::skip]
206const EXCEPTIONS: ExceptionList = &[
207    // tidy-alphabetical-start
208    ("colored", "MPL-2.0"),                                  // rustfmt
209    ("option-ext", "MPL-2.0"),                               // cargo-miri (via `directories`)
210    // tidy-alphabetical-end
211];
212
213/// These are exceptions to Rust's permissive licensing policy, and
214/// should be considered bugs. Exceptions are only allowed in Rust
215/// tooling. It is _crucial_ that no exception crates be dependencies
216/// of the Rust runtime (std/test).
217#[rustfmt::skip]
218const EXCEPTIONS_STDLIB: ExceptionList = &[
219    // tidy-alphabetical-start
220    ("fortanix-sgx-abi", "MPL-2.0"), // libstd but only for `sgx` target. FIXME: this dependency violates the documentation comment above.
221    // tidy-alphabetical-end
222];
223
224const EXCEPTIONS_CARGO: ExceptionList = &[
225    // tidy-alphabetical-start
226    ("bitmaps", "MPL-2.0+"),
227    ("im-rc", "MPL-2.0+"),
228    ("sized-chunks", "MPL-2.0+"),
229    // tidy-alphabetical-end
230];
231
232const EXCEPTIONS_RUST_ANALYZER: ExceptionList = &[
233    // tidy-alphabetical-start
234    ("option-ext", "MPL-2.0"),
235    // tidy-alphabetical-end
236];
237
238const EXCEPTIONS_RUSTC_PERF: ExceptionList = &[
239    // tidy-alphabetical-start
240    ("inferno", "CDDL-1.0"),
241    ("option-ext", "MPL-2.0"),
242    // tidy-alphabetical-end
243];
244
245const EXCEPTIONS_RUSTBOOK: ExceptionList = &[
246    // tidy-alphabetical-start
247    ("font-awesome-as-a-crate", "CC-BY-4.0 AND MIT"),
248    ("mdbook-core", "MPL-2.0"),
249    ("mdbook-driver", "MPL-2.0"),
250    ("mdbook-html", "MPL-2.0"),
251    ("mdbook-markdown", "MPL-2.0"),
252    ("mdbook-preprocessor", "MPL-2.0"),
253    ("mdbook-renderer", "MPL-2.0"),
254    ("mdbook-summary", "MPL-2.0"),
255    // tidy-alphabetical-end
256];
257
258const EXCEPTIONS_CRANELIFT: ExceptionList = &[];
259
260const EXCEPTIONS_GCC: ExceptionList = &[
261    // tidy-alphabetical-start
262    ("gccjit", "GPL-3.0"),
263    ("gccjit_sys", "GPL-3.0"),
264    // tidy-alphabetical-end
265];
266
267const EXCEPTIONS_BOOTSTRAP: ExceptionList = &[];
268
269const EXCEPTIONS_UEFI_QEMU_TEST: ExceptionList = &[];
270
271const PERMITTED_RUSTC_DEPS_LOCATION: ListLocation = location!(+6);
272
273/// Crates rustc is allowed to depend on. Avoid adding to the list if possible.
274///
275/// This list is here to provide a speed-bump to adding a new dependency to
276/// rustc. Please check with the compiler team before adding an entry.
277const PERMITTED_RUSTC_DEPENDENCIES: &[&str] = &[
278    // tidy-alphabetical-start
279    "adler2",
280    "aho-corasick",
281    "allocator-api2", // FIXME: only appears in Cargo.lock due to https://github.com/rust-lang/cargo/issues/10801
282    "annotate-snippets",
283    "anstream",
284    "anstyle",
285    "anstyle-parse",
286    "anstyle-query",
287    "anstyle-wincon",
288    "ar_archive_writer",
289    "arrayref",
290    "arrayvec",
291    "bitflags",
292    "blake3",
293    "block-buffer",
294    "block2",
295    "bstr",
296    "cc",
297    "cfg-if",
298    "cfg_aliases",
299    "colorchoice",
300    "constant_time_eq",
301    "cpufeatures",
302    "crc32fast",
303    "crossbeam-deque",
304    "crossbeam-epoch",
305    "crossbeam-utils",
306    "crypto-common",
307    "ctrlc",
308    "darling",
309    "darling_core",
310    "darling_macro",
311    "datafrog",
312    "derive-where",
313    "derive_setters",
314    "digest",
315    "dispatch2",
316    "displaydoc",
317    "dissimilar",
318    "dyn-clone",
319    "either",
320    "elsa",
321    "ena",
322    "equivalent",
323    "errno",
324    "expect-test",
325    "fallible-iterator", // dependency of `thorin`
326    "fastrand",
327    "find-msvc-tools",
328    "flate2",
329    "fluent-bundle",
330    "fluent-langneg",
331    "fluent-syntax",
332    "fnv",
333    "foldhash",
334    "generic-array",
335    "getopts",
336    "getrandom",
337    "gimli",
338    "gsgdt",
339    "hashbrown",
340    "icu_collections",
341    "icu_list",
342    "icu_locale",
343    "icu_locale_core",
344    "icu_locale_data",
345    "icu_provider",
346    "ident_case",
347    "indexmap",
348    "intl-memoizer",
349    "intl_pluralrules",
350    "is_terminal_polyfill",
351    "itertools",
352    "itoa",
353    "jiff",
354    "jiff-static",
355    "jobserver",
356    "lazy_static",
357    "leb128",
358    "libc",
359    "libloading",
360    "linux-raw-sys",
361    "litemap",
362    "lock_api",
363    "log",
364    "matchers",
365    "md-5",
366    "measureme",
367    "memchr",
368    "memmap2",
369    "miniz_oxide",
370    "nix",
371    "nu-ansi-term",
372    "objc2",
373    "objc2-encode",
374    "object",
375    "odht",
376    "once_cell",
377    "once_cell_polyfill",
378    "parking_lot",
379    "parking_lot_core",
380    "pathdiff",
381    "perf-event-open-sys",
382    "pin-project-lite",
383    "polonius-engine",
384    "portable-atomic", // dependency for platforms doesn't support `AtomicU64` in std
385    "portable-atomic-util",
386    "potential_utf",
387    "ppv-lite86",
388    "proc-macro-hack",
389    "proc-macro2",
390    "psm",
391    "pulldown-cmark",
392    "pulldown-cmark-escape",
393    "punycode",
394    "quote",
395    "r-efi",
396    "rand",
397    "rand_chacha",
398    "rand_core",
399    "rand_xorshift", // dependency for doc-tests in rustc_thread_pool
400    "rand_xoshiro",
401    "redox_syscall",
402    "ref-cast",
403    "ref-cast-impl",
404    "regex",
405    "regex-automata",
406    "regex-syntax",
407    "rustc-demangle",
408    "rustc-hash",
409    "rustc-literal-escaper",
410    "rustc-stable-hash",
411    "rustc_apfloat",
412    "rustix",
413    "ruzstd", // via object in thorin-dwp
414    "ryu",
415    "schemars",
416    "schemars_derive",
417    "scoped-tls",
418    "scopeguard",
419    "self_cell",
420    "serde",
421    "serde_core",
422    "serde_derive",
423    "serde_derive_internals",
424    "serde_json",
425    "serde_path_to_error",
426    "sha1",
427    "sha2",
428    "sharded-slab",
429    "shlex",
430    "simd-adler32",
431    "smallvec",
432    "stable_deref_trait",
433    "stacker",
434    "static_assertions",
435    "strsim",
436    "syn",
437    "synstructure",
438    "tempfile",
439    "termize",
440    "thin-vec",
441    "thiserror",
442    "thiserror-impl",
443    "thorin-dwp",
444    "thread_local",
445    "tikv-jemalloc-sys",
446    "tinystr",
447    "tinyvec",
448    "tinyvec_macros",
449    "tracing",
450    "tracing-attributes",
451    "tracing-core",
452    "tracing-log",
453    "tracing-subscriber",
454    "tracing-tree",
455    "twox-hash",
456    "type-map",
457    "typenum",
458    "unic-langid",
459    "unic-langid-impl",
460    "unic-langid-macros",
461    "unic-langid-macros-impl",
462    "unicase",
463    "unicode-ident",
464    "unicode-normalization",
465    "unicode-properties",
466    "unicode-script",
467    "unicode-security",
468    "unicode-width",
469    "utf8parse",
470    "valuable",
471    "version_check",
472    "wasi",
473    "wasm-encoder",
474    "wasmparser",
475    "windows",
476    "windows-collections",
477    "windows-core",
478    "windows-future",
479    "windows-implement",
480    "windows-interface",
481    "windows-link",
482    "windows-numerics",
483    "windows-result",
484    "windows-strings",
485    "windows-sys",
486    "windows-targets",
487    "windows-threading",
488    "windows_aarch64_gnullvm",
489    "windows_aarch64_msvc",
490    "windows_i686_gnu",
491    "windows_i686_gnullvm",
492    "windows_i686_msvc",
493    "windows_x86_64_gnu",
494    "windows_x86_64_gnullvm",
495    "windows_x86_64_msvc",
496    "wit-bindgen-rt@0.39.0", // pinned to a specific version due to using a binary blob: <https://github.com/rust-lang/rust/pull/136395#issuecomment-2692769062>
497    "writeable",
498    "yoke",
499    "yoke-derive",
500    "zerocopy",
501    "zerocopy-derive",
502    "zerofrom",
503    "zerofrom-derive",
504    "zerotrie",
505    "zerovec",
506    "zerovec-derive",
507    // tidy-alphabetical-end
508];
509
510const PERMITTED_STDLIB_DEPS_LOCATION: ListLocation = location!(+2);
511
512const PERMITTED_STDLIB_DEPENDENCIES: &[&str] = &[
513    // tidy-alphabetical-start
514    "addr2line",
515    "adler2",
516    "cc",
517    "cfg-if",
518    "compiler_builtins",
519    "dlmalloc",
520    "foldhash", // FIXME: only appears in Cargo.lock due to https://github.com/rust-lang/cargo/issues/10801
521    "fortanix-sgx-abi",
522    "getopts",
523    "gimli",
524    "hashbrown",
525    "hermit-abi",
526    "libc",
527    "memchr",
528    "miniz_oxide",
529    "moto-rt",
530    "object",
531    "r-efi",
532    "r-efi-alloc",
533    "rand",
534    "rand_core",
535    "rand_xorshift",
536    "rustc-demangle",
537    "rustc-literal-escaper",
538    "shlex",
539    "unwinding",
540    "vex-sdk",
541    "wasi",
542    "windows-link",
543    "windows-sys",
544    "windows-targets",
545    "windows_aarch64_gnullvm",
546    "windows_aarch64_msvc",
547    "windows_i686_gnu",
548    "windows_i686_gnullvm",
549    "windows_i686_msvc",
550    "windows_x86_64_gnu",
551    "windows_x86_64_gnullvm",
552    "windows_x86_64_msvc",
553    "wit-bindgen",
554    // tidy-alphabetical-end
555];
556
557const PERMITTED_CRANELIFT_DEPS_LOCATION: ListLocation = location!(+2);
558
559const PERMITTED_CRANELIFT_DEPENDENCIES: &[&str] = &[
560    // tidy-alphabetical-start
561    "allocator-api2",
562    "anyhow",
563    "arbitrary",
564    "bitflags",
565    "bumpalo",
566    "cfg-if",
567    "cranelift-assembler-x64",
568    "cranelift-assembler-x64-meta",
569    "cranelift-bforest",
570    "cranelift-bitset",
571    "cranelift-codegen",
572    "cranelift-codegen-meta",
573    "cranelift-codegen-shared",
574    "cranelift-control",
575    "cranelift-entity",
576    "cranelift-frontend",
577    "cranelift-isle",
578    "cranelift-jit",
579    "cranelift-module",
580    "cranelift-native",
581    "cranelift-object",
582    "cranelift-srcgen",
583    "crc32fast",
584    "equivalent",
585    "fallible-iterator",
586    "foldhash",
587    "gimli",
588    "hashbrown",
589    "heck",
590    "indexmap",
591    "libc",
592    "libloading",
593    "libm",
594    "log",
595    "mach2",
596    "memchr",
597    "object",
598    "proc-macro2",
599    "quote",
600    "regalloc2",
601    "region",
602    "rustc-hash",
603    "serde",
604    "serde_core",
605    "serde_derive",
606    "smallvec",
607    "stable_deref_trait",
608    "syn",
609    "target-lexicon",
610    "unicode-ident",
611    "wasmtime-internal-jit-icache-coherence",
612    "wasmtime-internal-math",
613    "windows-link",
614    "windows-sys",
615    "windows-targets",
616    "windows_aarch64_gnullvm",
617    "windows_aarch64_msvc",
618    "windows_i686_gnu",
619    "windows_i686_gnullvm",
620    "windows_i686_msvc",
621    "windows_x86_64_gnu",
622    "windows_x86_64_gnullvm",
623    "windows_x86_64_msvc",
624    // tidy-alphabetical-end
625];
626
627/// Dependency checks.
628///
629/// `root` is path to the directory with the root `Cargo.toml` (for the workspace). `cargo` is path
630/// to the cargo executable.
631pub fn check(root: &Path, cargo: &Path, tidy_ctx: TidyCtx) {
632    let mut check = tidy_ctx.start_check("deps");
633    let bless = tidy_ctx.is_bless_enabled();
634
635    let mut checked_runtime_licenses = false;
636
637    check_proc_macro_dep_list(root, cargo, bless, &mut check);
638
639    for &WorkspaceInfo { path, exceptions, crates_and_deps, submodules } in WORKSPACES {
640        if has_missing_submodule(root, submodules) {
641            continue;
642        }
643
644        if !root.join(path).join("Cargo.lock").exists() {
645            check.error(format!("the `{path}` workspace doesn't have a Cargo.lock"));
646            continue;
647        }
648
649        let mut cmd = cargo_metadata::MetadataCommand::new();
650        cmd.cargo_path(cargo)
651            .manifest_path(root.join(path).join("Cargo.toml"))
652            .features(cargo_metadata::CargoOpt::AllFeatures)
653            .other_options(vec!["--locked".to_owned()]);
654        let metadata = t!(cmd.exec());
655
656        // Check for packages which have been moved into a different workspace and not updated
657        let absolute_root =
658            if path == "." { root.to_path_buf() } else { t!(std::path::absolute(root.join(path))) };
659        let absolute_root_real = t!(std::path::absolute(&metadata.workspace_root));
660        if absolute_root_real != absolute_root {
661            check.error(format!("{path} is part of another workspace ({} != {}), remove from `WORKSPACES` ({WORKSPACE_LOCATION})", absolute_root.display(), absolute_root_real.display()));
662        }
663        check_license_exceptions(&metadata, path, exceptions, &mut check);
664        if let Some((crates, permitted_deps, location)) = crates_and_deps {
665            let descr = crates.get(0).unwrap_or(&path);
666            check_permitted_dependencies(
667                &metadata,
668                descr,
669                permitted_deps,
670                crates,
671                location,
672                &mut check,
673            );
674        }
675
676        if path == "library" {
677            check_runtime_license_exceptions(&metadata, &mut check);
678            check_runtime_no_duplicate_dependencies(&metadata, &mut check);
679            check_runtime_no_proc_macros(&metadata, &mut check);
680            checked_runtime_licenses = true;
681        }
682    }
683
684    // Sanity check to ensure we don't accidentally remove the workspace containing the runtime
685    // crates.
686    assert!(checked_runtime_licenses);
687}
688
689/// Ensure the list of proc-macro crate transitive dependencies is up to date
690fn check_proc_macro_dep_list(root: &Path, cargo: &Path, bless: bool, check: &mut RunningCheck) {
691    let mut cmd = cargo_metadata::MetadataCommand::new();
692    cmd.cargo_path(cargo)
693        .manifest_path(root.join("Cargo.toml"))
694        .features(cargo_metadata::CargoOpt::AllFeatures)
695        .other_options(vec!["--locked".to_owned()]);
696    let metadata = t!(cmd.exec());
697    let is_proc_macro_pkg = |pkg: &Package| pkg.targets.iter().any(|target| target.is_proc_macro());
698
699    let mut proc_macro_deps = HashSet::new();
700    for pkg in metadata.packages.iter().filter(|pkg| is_proc_macro_pkg(pkg)) {
701        deps_of(&metadata, &pkg.id, &mut proc_macro_deps);
702    }
703    // Remove the proc-macro crates themselves
704    proc_macro_deps.retain(|pkg| !is_proc_macro_pkg(&metadata[pkg]));
705
706    let proc_macro_deps: HashSet<_> =
707        proc_macro_deps.into_iter().map(|dep| metadata[dep].name.as_ref()).collect();
708    let expected = proc_macro_deps::CRATES.iter().copied().collect::<HashSet<_>>();
709
710    let needs_blessing = proc_macro_deps.difference(&expected).next().is_some()
711        || expected.difference(&proc_macro_deps).next().is_some();
712
713    if needs_blessing && bless {
714        let mut proc_macro_deps: Vec<_> = proc_macro_deps.into_iter().collect();
715        proc_macro_deps.sort();
716        let mut file = File::create(root.join("src/bootstrap/src/utils/proc_macro_deps.rs"))
717            .expect("`proc_macro_deps` should exist");
718        writeln!(
719            &mut file,
720            "/// Do not update manually - use `./x.py test tidy --bless`
721/// Holds all direct and indirect dependencies of proc-macro crates in tree.
722/// See <https://github.com/rust-lang/rust/issues/134863>
723pub static CRATES: &[&str] = &[
724    // tidy-alphabetical-start"
725        )
726        .unwrap();
727        for dep in proc_macro_deps {
728            writeln!(&mut file, "    {dep:?},").unwrap();
729        }
730        writeln!(
731            &mut file,
732            "    // tidy-alphabetical-end
733];"
734        )
735        .unwrap();
736    } else {
737        let mut error_found = false;
738
739        for missing in proc_macro_deps.difference(&expected) {
740            error_found = true;
741            check.error(format!(
742                "proc-macro crate dependency `{missing}` is not registered in `src/bootstrap/src/utils/proc_macro_deps.rs`",
743            ));
744        }
745        for extra in expected.difference(&proc_macro_deps) {
746            error_found = true;
747            check.error(format!(
748                "`{extra}` is registered in `src/bootstrap/src/utils/proc_macro_deps.rs`, but is not a proc-macro crate dependency",
749            ));
750        }
751        if error_found {
752            check.message("Run `./x.py test tidy --bless` to regenerate the list");
753        }
754    }
755}
756
757/// Used to skip a check if a submodule is not checked out, and not in a CI environment.
758///
759/// This helps prevent enforcing developers to fetch submodules for tidy.
760pub fn has_missing_submodule(root: &Path, submodules: &[&str]) -> bool {
761    !CiEnv::is_ci()
762        && submodules.iter().any(|submodule| {
763            let path = root.join(submodule);
764            !path.exists()
765            // If the directory is empty, we can consider it as an uninitialized submodule.
766            || read_dir(path).unwrap().next().is_none()
767        })
768}
769
770/// Check that all licenses of runtime dependencies are in the valid list in `LICENSES`.
771///
772/// Unlike for tools we don't allow exceptions to the `LICENSES` list for the runtime with the sole
773/// exception of `fortanix-sgx-abi` which is only used on x86_64-fortanix-unknown-sgx.
774fn check_runtime_license_exceptions(metadata: &Metadata, check: &mut RunningCheck) {
775    for pkg in &metadata.packages {
776        if pkg.source.is_none() {
777            // No need to check local packages.
778            continue;
779        }
780        let license = match &pkg.license {
781            Some(license) => license,
782            None => {
783                check
784                    .error(format!("dependency `{}` does not define a license expression", pkg.id));
785                continue;
786            }
787        };
788        if !LICENSES.contains(&license.as_str()) {
789            // This is a specific exception because SGX is considered "third party".
790            // See https://github.com/rust-lang/rust/issues/62620 for more.
791            // In general, these should never be added and this exception
792            // should not be taken as precedent for any new target.
793            if *pkg.name == "fortanix-sgx-abi" && pkg.license.as_deref() == Some("MPL-2.0") {
794                continue;
795            }
796
797            check.error(format!("invalid license `{}` in `{}`", license, pkg.id));
798        }
799    }
800}
801
802/// Check that all licenses of tool dependencies are in the valid list in `LICENSES`.
803///
804/// Packages listed in `exceptions` are allowed for tools.
805fn check_license_exceptions(
806    metadata: &Metadata,
807    workspace: &str,
808    exceptions: &[(&str, &str)],
809    check: &mut RunningCheck,
810) {
811    // Validate the EXCEPTIONS list hasn't changed.
812    for (name, license) in exceptions {
813        // Check that the package actually exists.
814        if !metadata.packages.iter().any(|p| *p.name == *name) {
815            check.error(format!(
816                "could not find exception package `{name}` in workspace `{workspace}`\n\
817                Remove from EXCEPTIONS list if it is no longer used.",
818            ));
819        }
820        // Check that the license hasn't changed.
821        for pkg in metadata.packages.iter().filter(|p| *p.name == *name) {
822            match &pkg.license {
823                None => {
824                    check.error(format!(
825                        "dependency exception `{}` in workspace `{workspace}` does not declare a license expression",
826                        pkg.id
827                    ));
828                }
829                Some(pkg_license) => {
830                    if pkg_license.as_str() != *license {
831                        check.error(format!(r#"dependency exception `{name}` license in workspace `{workspace}` has changed
832    previously `{license}` now `{pkg_license}`
833    update EXCEPTIONS for the new license
834"#));
835                    }
836                }
837            }
838        }
839        if LICENSES.contains(license) || LICENSES_TOOLS.contains(license) {
840            check.error(format!(
841                "dependency exception `{name}` is not necessary. `{license}` is an allowed license"
842            ));
843        }
844    }
845
846    let exception_names: Vec<_> = exceptions.iter().map(|(name, _license)| *name).collect();
847
848    // Check if any package does not have a valid license.
849    for pkg in &metadata.packages {
850        if pkg.source.is_none() {
851            // No need to check local packages.
852            continue;
853        }
854        if exception_names.contains(&pkg.name.as_str()) {
855            continue;
856        }
857        let license = match &pkg.license {
858            Some(license) => license,
859            None => {
860                check.error(format!(
861                    "dependency `{}` in workspace `{workspace}` does not define a license expression",
862                    pkg.id
863                ));
864                continue;
865            }
866        };
867        if !LICENSES.contains(&license.as_str()) && !LICENSES_TOOLS.contains(&license.as_str()) {
868            check.error(format!(
869                "invalid license `{}` for package `{}` in workspace `{workspace}`",
870                license, pkg.id
871            ));
872        }
873    }
874}
875
876fn check_runtime_no_duplicate_dependencies(metadata: &Metadata, check: &mut RunningCheck) {
877    let mut seen_pkgs = HashSet::new();
878    for pkg in &metadata.packages {
879        if pkg.source.is_none() {
880            continue;
881        }
882
883        // Skip the `wasi` crate here which the standard library explicitly
884        // depends on two version of (one for the `wasm32-wasip1` target and
885        // another for the `wasm32-wasip2` target).
886        if pkg.name.to_string() != "wasi" && !seen_pkgs.insert(&*pkg.name) {
887            check.error(format!(
888                "duplicate package `{}` is not allowed for the standard library",
889                pkg.name
890            ));
891        }
892    }
893}
894
895fn check_runtime_no_proc_macros(metadata: &Metadata, check: &mut RunningCheck) {
896    for pkg in &metadata.packages {
897        if pkg.targets.iter().any(|target| target.is_proc_macro()) {
898            check.error(format!(
899                "proc macro `{}` is not allowed as standard library dependency.\n\
900                Using proc macros in the standard library would break cross-compilation \
901                as proc-macros don't get shipped for the host tuple.",
902                pkg.name
903            ));
904        }
905    }
906}
907
908/// Checks the dependency of `restricted_dependency_crates` at the given path. Changes `bad` to
909/// `true` if a check failed.
910///
911/// Specifically, this checks that the dependencies are on the `permitted_dependencies`.
912fn check_permitted_dependencies(
913    metadata: &Metadata,
914    descr: &str,
915    permitted_dependencies: &[&'static str],
916    restricted_dependency_crates: &[&'static str],
917    permitted_location: ListLocation,
918    check: &mut RunningCheck,
919) {
920    let mut has_permitted_dep_error = false;
921    let mut deps = HashSet::new();
922    for to_check in restricted_dependency_crates {
923        let to_check = pkg_from_name(metadata, to_check);
924        deps_of(metadata, &to_check.id, &mut deps);
925    }
926
927    // Check that the PERMITTED_DEPENDENCIES does not have unused entries.
928    for permitted in permitted_dependencies {
929        fn compare(pkg: &Package, permitted: &str) -> bool {
930            if let Some((name, version)) = permitted.split_once("@") {
931                let Ok(version) = Version::parse(version) else {
932                    return false;
933                };
934                *pkg.name == name && pkg.version == version
935            } else {
936                *pkg.name == permitted
937            }
938        }
939        if !deps.iter().any(|dep_id| compare(pkg_from_id(metadata, dep_id), permitted)) {
940            check.error(format!(
941                "could not find allowed package `{permitted}`\n\
942                Remove from PERMITTED_DEPENDENCIES list if it is no longer used.",
943            ));
944            has_permitted_dep_error = true;
945        }
946    }
947
948    // Get in a convenient form.
949    let permitted_dependencies: HashMap<_, _> = permitted_dependencies
950        .iter()
951        .map(|s| {
952            if let Some((name, version)) = s.split_once('@') {
953                (name, Version::parse(version).ok())
954            } else {
955                (*s, None)
956            }
957        })
958        .collect();
959
960    for dep in deps {
961        let dep = pkg_from_id(metadata, dep);
962        // If this path is in-tree, we don't require it to be explicitly permitted.
963        if dep.source.is_some() {
964            let is_eq = if let Some(version) = permitted_dependencies.get(dep.name.as_str()) {
965                if let Some(version) = version { version == &dep.version } else { true }
966            } else {
967                false
968            };
969            if !is_eq {
970                check.error(format!("Dependency for {descr} not explicitly permitted: {}", dep.id));
971                has_permitted_dep_error = true;
972            }
973        }
974    }
975
976    if has_permitted_dep_error {
977        eprintln!("Go to `{}:{}` for the list.", permitted_location.path, permitted_location.line);
978    }
979}
980
981/// Finds a package with the given name.
982fn pkg_from_name<'a>(metadata: &'a Metadata, name: &'static str) -> &'a Package {
983    let mut i = metadata.packages.iter().filter(|p| *p.name == name);
984    let result =
985        i.next().unwrap_or_else(|| panic!("could not find package `{name}` in package list"));
986    assert!(i.next().is_none(), "more than one package found for `{name}`");
987    result
988}
989
990fn pkg_from_id<'a>(metadata: &'a Metadata, id: &PackageId) -> &'a Package {
991    metadata.packages.iter().find(|p| &p.id == id).unwrap()
992}
993
994/// Recursively find all dependencies.
995fn deps_of<'a>(metadata: &'a Metadata, pkg_id: &'a PackageId, result: &mut HashSet<&'a PackageId>) {
996    if !result.insert(pkg_id) {
997        return;
998    }
999    let node = metadata
1000        .resolve
1001        .as_ref()
1002        .unwrap()
1003        .nodes
1004        .iter()
1005        .find(|n| &n.id == pkg_id)
1006        .unwrap_or_else(|| panic!("could not find `{pkg_id}` in resolve"));
1007    for dep in &node.deps {
1008        deps_of(metadata, &dep.pkg, result);
1009    }
1010}