sadpandajoe commented on code in PR #39724: URL: https://github.com/apache/superset/pull/39724#discussion_r4044358689
########## scripts/compile_po.py: ########## @@ -0,0 +1,213 @@ +#!/usr/bin/env python3 +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. + +# This script is a cross-platform Python equivalent of po2json.sh. +# It generates .json files from .po translation files used by the frontend. + +from __future__ import annotations + +import glob +import os +import shutil +import subprocess +import sys +from concurrent.futures import as_completed, ThreadPoolExecutor + +# `os.name == "nt"` detects whether the script is running on Windows +# (Windows NT family). On Windows, shell=True is required for subprocess.run +# to resolve and execute batch/cmd wrappers (such as npm.cmd, npx.cmd, or binaries +# under node_modules/.bin) without needing to manually append file extensions or +# encountering FileNotFoundError. +# On POSIX systems (Linux, macOS), shell=False is used for direct process execution. +_SHELL = os.name == "nt" + + +def run_command(command: list[str], cwd: str | None = None, timeout: int = 120) -> int: + try: + result = subprocess.run( # noqa: S603 + command, text=True, shell=_SHELL, check=False, cwd=cwd, timeout=timeout Review Comment: Literal `%...%` in a catalog or checkout path is still expanded before `po2json` sees it: with `USERNAME=alice`, `messages%USERNAME%.po` becomes `messagesalice.po`, even inside the quotes produced here. Windows can run `.cmd` files through `cmd.exe` despite `shell=False` ([Python documentation](https://docs.python.org/3/library/subprocess.html#security-considerations)), so that flag does not remove the shell-parsing boundary, and the mocked subprocess tests do not exercise it. Could this invoke the underlying executable without a batch wrapper, or handle batch expansion and add a Windows test asserting the exact child arguments for literal `%USERNAME%` and `&` paths? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
