zjncs opened a new issue, #5601:
URL: https://github.com/apache/rocketmq-dashboard/issues/5601

   ## Description
   
   `rmqctl/scripts/license-binary.go` splits the repository LICENSE/NOTICE at 
an LF-only marker to separate the binary package's attribution from the web 
source-package's:
   
   ```go
   base := func(name string) string {
       text := string(read(filepath.Join(*root, name)))
       return strings.Split(text, "\nThird-party source materials\n")[0]
   }
   ```
   
   On a Git checkout with CRLF line endings — the **default for Git for 
Windows** (`core.autocrlf=true`) — the file contains `\r\nThird-party source 
materials\r\n`, the LF-only marker never matches, and `base()` returns the 
**entire file**, mixing the web source-package attribution (LobeHub etc.) into 
the binary package's LICENSE/NOTICE.
   
   The repo's own test pins exactly this contract and fails on such a checkout:
   
   ```
   $ go test ./scripts/ -run TestBinaryLicensePackagingTest
       --- FAIL: TestBinaryLicensePackagingTest/linux (…)
           license-binary_test.go:116: the binary must carry the ASF NOTICE and 
must not mix in the web
                source-package attribution
   ```
   
   CI never sees this because the ubuntu runner checks out with LF endings — 
while the repo explicitly supports Windows development (`build-windows.ps1`, 
windows targets in `build-all`, and the test itself exercises the windows 
packaging path).
   
   ## Impact
   
   - Every Windows contributor with the default Git config gets a failing `go 
test ./...` in the scripts package.
   - Worse than the test failure: actually generating release materials on such 
a checkout produces a **non-compliant binary package** — the web source-package 
attribution is baked into the binary LICENSE/NOTICE, which is precisely what 
the check exists to prevent.
   
   ## Expected behavior
   
   The split must not depend on the checkout's line endings — normalize CRLF 
before matching the marker (the canonical repo content is LF; normalization 
restores it).
   
   ## Environment
   
   - branch: master (0228dad5)
   - file: `rmqctl/scripts/license-binary.go` (the `base()` closure)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to