only remove visibility matching explicit default_visibility (#1512)

## Buildtools PR checklist

- [x] The code in this PR is covered by unit/integration tests.
- [x] I have tested these changes and provide testing instructions
below.
- [ ] I have either responded to, or resolved all Gemini comments on the
PR.
- [x] I have read Google Eng Practices on [Small
Changes](https://google.github.io/eng-practices/review/developer/small-cls.html),
this PR either follows these guidelines or the description provides
reasoning for why they can not be followed.

## Description

Previously, buildozer's fix.go:105 routine stripped `visibility`
attributes whenever they matched an explicit `default_visibility` or
defaulted to `["//visibility:private"]` when `default_visibility` was
omitted.

However, Starlark macros and custom rules often implement their own
default visibility logic (e.g., defaulting to public or custom targets
when `visibility` is omitted). Stripping `visibility =
["//visibility:private"]` when no package-level default is declared can
silently broaden visibility.

Rather than relying on fragile heuristics to identify macros and loaded
rules, this change refactors fix.go:105 to only strip visibility
attributes when `default_visibility` is **explicitly defined** in a
`package()` declaration:

- **Explicit `default_visibility` required**: If `default_visibility` is
not explicitly set on the package, rule `visibility` attributes are
preserved.
- **Unordered string list matching**: Compares string lists using
`slices.Sorted`, allowing redundant visibility to be removed even if
list elements appear in a different order.
- **Identifier matching**: Supports matching identifier expressions
(e.g. `package(default_visibility = PUBLIC)` and `visibility = PUBLIC`).


### (optional) These changes were tested using the following steps

Ran unit tests covering all cases:
```bash
    go test ./edit -run TestFix
```

Unit test cases in fix_test.go verify:

  • Preserving visibility when default_visibility is not set
  • Removing redundant visibility with differing slice order
  • Removing redundant visibility matching identifiers
  • Preserving non-matching visibility

---------

Co-authored-by: Kyle Dobitz <kyledobitz@gmail.com>
Co-authored-by: Tim Malmström <oreflow@google.com>
2 files changed
tree: 4ee24e1670831a46d2fc02469d8632a55fd8c546
  1. .bazelci/
  2. .github/
  3. api_proto/
  4. build/
  5. build_proto/
  6. buildifier/
  7. buildozer/
  8. bzlenv/
  9. config/
  10. convertast/
  11. deps_proto/
  12. differ/
  13. edit/
  14. extra_actions_base_proto/
  15. file/
  16. generatetables/
  17. labels/
  18. lang/
  19. release/
  20. tables/
  21. testutils/
  22. unused_deps/
  23. warn/
  24. wspace/
  25. .bazelrc
  26. .bazelversion
  27. .gitignore
  28. .mailmap
  29. .pre-commit-config.yaml
  30. AGENTS.md
  31. BUILD.bazel
  32. CODEOWNERS
  33. CONTRIBUTING.md
  34. CONTRIBUTORS
  35. go.mod
  36. go.sum
  37. launcher.js
  38. LICENSE
  39. MODULE.bazel
  40. README.md
  41. status.py
  42. update_generated.sh
  43. WARNINGS.md
  44. WORKSPACE
  45. WORKSPACE.bzlmod
README.md

Buildtools for bazel

This repository contains developer tools for working with Google's bazel buildtool.

Build status

Setup

See instructions in each tool's directory.