From da876cc62b46673877a178d7a939d4deed115cc7 Mon Sep 17 00:00:00 2001 From: Alfred Wingate Date: Wed, 10 Dec 2025 05:07:57 +0200 Subject: [PATCH] sys-apps/selinux-python: use distutils-r1 for python module Bug: https://bugs.gentoo.org/965451 See-Also: 6f81dc7ef7f9e427243a4c21d40a0fdc9bb4d681 Signed-off-by: Alfred Wingate Part-of: https://github.com/gentoo/gentoo/pull/44974 Signed-off-by: Sam James --- .../files/selinux-python-3.8.1-no-pip.patch | 14 ++ .../selinux-python-3.8.1-r1.ebuild | 138 ++++++++++++++++++ .../selinux-python/selinux-python-9999.ebuild | 113 ++++++++------ 3 files changed, 219 insertions(+), 46 deletions(-) create mode 100644 sys-apps/selinux-python/files/selinux-python-3.8.1-no-pip.patch create mode 100644 sys-apps/selinux-python/selinux-python-3.8.1-r1.ebuild diff --git a/sys-apps/selinux-python/files/selinux-python-3.8.1-no-pip.patch b/sys-apps/selinux-python/files/selinux-python-3.8.1-no-pip.patch new file mode 100644 index 0000000000000..5ca6a7012155d --- /dev/null +++ b/sys-apps/selinux-python/files/selinux-python-3.8.1-no-pip.patch @@ -0,0 +1,14 @@ +Use eclass functions to install under PEP517 + +Patch to ensure failure if the change fails to apply. + +--- a/sepolicy/Makefile ++++ b/sepolicy/Makefile +@@ -27,7 +27,6 @@ test: + @$(PYTHON) test_sepolicy.py -v + + install: +- $(PYTHON) -m pip install --prefix=$(PREFIX) `test -n "$(DESTDIR)" && echo --root $(DESTDIR) --ignore-installed --no-deps` $(PYTHON_SETUP_ARGS) . + [ -d $(DESTDIR)$(BINDIR) ] || mkdir -p $(DESTDIR)$(BINDIR) + install -m 755 sepolicy.py $(DESTDIR)$(BINDIR)/sepolicy + (cd $(DESTDIR)$(BINDIR); ln -sf sepolicy sepolgen) diff --git a/sys-apps/selinux-python/selinux-python-3.8.1-r1.ebuild b/sys-apps/selinux-python/selinux-python-3.8.1-r1.ebuild new file mode 100644 index 0000000000000..cdce08cc2a756 --- /dev/null +++ b/sys-apps/selinux-python/selinux-python-3.8.1-r1.ebuild @@ -0,0 +1,138 @@ +# Copyright 1999-2025 Gentoo Authors +# Distributed under the terms of the GNU General Public License v2 + +EAPI="8" + +DISTUTILS_USE_PEP517=setuptools +PYTHON_COMPAT=( python3_{11..13} ) +PYTHON_REQ_USE="xml(+)" + +inherit distutils-r1 toolchain-funcs + +MY_PV="${PV//_/-}" +MY_P="${PN}-${MY_PV}" + +DESCRIPTION="SELinux core utilities" +HOMEPAGE="https://github.com/SELinuxProject/selinux/wiki" + +if [[ ${PV} == 9999 ]] ; then + inherit git-r3 + EGIT_REPO_URI="https://github.com/SELinuxProject/selinux.git" + S="${WORKDIR}/${P}/${PN#selinux-}" +else + SRC_URI="https://github.com/SELinuxProject/selinux/releases/download/${MY_PV}/${MY_P}.tar.gz" + KEYWORDS="~amd64 ~arm ~arm64 ~x86" + S="${WORKDIR}/${MY_P}" +fi + +LICENSE="GPL-2" +SLOT="0" +IUSE="test" +RESTRICT="!test? ( test )" + +RDEPEND=">=sys-libs/libselinux-${PV}:=[python] + >=sys-libs/libsemanage-${PV}:=[python(+)] + >=sys-libs/libsepol-${PV}:=[static-libs(+)] + >=app-admin/setools-4.2.0[${PYTHON_USEDEP}] + >=sys-process/audit-1.5.1[python,${PYTHON_USEDEP}]" +DEPEND="${RDEPEND}" +BDEPEND=" + test? ( + ${RDEPEND} + >=sys-apps/secilc-${PV} + )" + +PATCHES=( + "${FILESDIR}"/selinux-python-3.8.1-no-pip.patch +) + +src_prepare() { + default + + sed -e 's/-Werror//g' -i "${S}"/*/Makefile || die "Failed to remove Werror" + + pushd sepolicy >/dev/null || die + # To avoid default + DISTUTILS_OPTIONAL=1 distutils-r1_src_prepare + popd >/dev/null || die +} + +python_compile() { + distutils-r1_python_compile + emake -C "${S}" \ + CC="$(tc-getCC)" \ + LIBDIR="\$(PREFIX)/$(get_libdir)" +} + +src_compile() { + pushd sepolicy >/dev/null || die + distutils-r1_src_compile + popd >/dev/null || die +} + +python_test() { + # The different subprojects have some interproject dependencies: + # - audit2allow depens on sepolgen + # - chcat depends on semanage + # and maybe others. + # Add all the modules of the individual subprojects to the + # PYTHONPATH, so they get actually found and used. In + # particular, already installed versions on the system are not + # used. + for dir in audit2allow chcat semanage sepolgen/src sepolicy ; do + PYTHONPATH="${S}/${dir}:${PYTHONPATH}" + done + PYTHONPATH=${PYTHONPATH} emake -C "${S}" test +} + +src_test() { + pushd sepolicy >/dev/null || die + distutils-r1_src_test + popd >/dev/null || die +} + +python_install() { + distutils-r1_python_install + emake -C "${S}" \ + DESTDIR="${D}" \ + LIBDIR="\$(PREFIX)/$(get_libdir)" \ + install + + # Install over previously installed scripts to ensure proper python support + python_doscript "${S}"/audit2allow/audit2allow + python_doscript "${S}"/audit2allow/sepolgen-ifgen + python_doscript "${S}"/chcat/chcat + python_newscript "${S}"/sepolicy/sepolicy.py sepolicy + + python_scriptinto /usr/sbin + python_doscript "${S}"/semanage/semanage + + python_optimize +} + +python_install_all() { + # Create sepolgen.conf with different devel location definition + mkdir -p "${D}"/etc/selinux || die "Failed to create selinux directory"; + if [[ -f /etc/selinux/config ]]; + then + local selinuxtype=$(awk -F'=' '/^SELINUXTYPE/ {print $2}' /etc/selinux/config); + echo "SELINUX_DEVEL_PATH=/usr/share/selinux/${selinuxtype}/include:/usr/share/selinux/${selinuxtype}" \ + > "${D}"/etc/selinux/sepolgen.conf || die "Failed to generate sepolgen" + else + local selinuxtype="${POLICY_TYPES%% *}"; + if [[ -n "${selinuxtype}" ]]; + then + echo "SELINUX_DEVEL_PATH=/usr/share/selinux/${selinuxtype}/include:/usr/share/selinux/${selinuxtype}" \ + > "${D}"/etc/selinux/sepolgen.conf || die "Failed to generate sepolgen" + else + echo "SELINUX_DEVEL_PATH=/usr/share/selinux/strict/include:/usr/share/selinux/strict" \ + > "${D}"/etc/selinux/sepolgen.conf || die "Failed to generate sepolgen" + fi + fi +} + +src_install() { + pushd sepolicy >/dev/null || die + distutils-r1_src_install + popd >/dev/null || die +} diff --git a/sys-apps/selinux-python/selinux-python-9999.ebuild b/sys-apps/selinux-python/selinux-python-9999.ebuild index e9776921c2c00..cdce08cc2a756 100644 --- a/sys-apps/selinux-python/selinux-python-9999.ebuild +++ b/sys-apps/selinux-python/selinux-python-9999.ebuild @@ -2,10 +2,12 @@ # Distributed under the terms of the GNU General Public License v2 EAPI="8" -PYTHON_COMPAT=( python3_{10..13} ) + +DISTUTILS_USE_PEP517=setuptools +PYTHON_COMPAT=( python3_{11..13} ) PYTHON_REQ_USE="xml(+)" -inherit python-r1 toolchain-funcs +inherit distutils-r1 toolchain-funcs MY_PV="${PV//_/-}" MY_P="${PN}-${MY_PV}" @@ -27,14 +29,12 @@ LICENSE="GPL-2" SLOT="0" IUSE="test" RESTRICT="!test? ( test )" -REQUIRED_USE="${PYTHON_REQUIRED_USE}" RDEPEND=">=sys-libs/libselinux-${PV}:=[python] >=sys-libs/libsemanage-${PV}:=[python(+)] >=sys-libs/libsepol-${PV}:=[static-libs(+)] >=app-admin/setools-4.2.0[${PYTHON_USEDEP}] - >=sys-process/audit-1.5.1[python,${PYTHON_USEDEP}] - ${PYTHON_DEPS}" + >=sys-process/audit-1.5.1[python,${PYTHON_USEDEP}]" DEPEND="${RDEPEND}" BDEPEND=" test? ( @@ -42,60 +42,75 @@ BDEPEND=" >=sys-apps/secilc-${PV} )" +PATCHES=( + "${FILESDIR}"/selinux-python-3.8.1-no-pip.patch +) + src_prepare() { default - sed -i 's/-Werror//g' "${S}"/*/Makefile || die "Failed to remove Werror" - python_copy_sources + sed -e 's/-Werror//g' -i "${S}"/*/Makefile || die "Failed to remove Werror" + + pushd sepolicy >/dev/null || die + # To avoid default + DISTUTILS_OPTIONAL=1 distutils-r1_src_prepare + popd >/dev/null || die +} + +python_compile() { + distutils-r1_python_compile + emake -C "${S}" \ + CC="$(tc-getCC)" \ + LIBDIR="\$(PREFIX)/$(get_libdir)" } src_compile() { - building() { - emake -C "${BUILD_DIR}" \ - CC="$(tc-getCC)" \ - LIBDIR="\$(PREFIX)/$(get_libdir)" - } - python_foreach_impl building + pushd sepolicy >/dev/null || die + distutils-r1_src_compile + popd >/dev/null || die +} + +python_test() { + # The different subprojects have some interproject dependencies: + # - audit2allow depens on sepolgen + # - chcat depends on semanage + # and maybe others. + # Add all the modules of the individual subprojects to the + # PYTHONPATH, so they get actually found and used. In + # particular, already installed versions on the system are not + # used. + for dir in audit2allow chcat semanage sepolgen/src sepolicy ; do + PYTHONPATH="${S}/${dir}:${PYTHONPATH}" + done + PYTHONPATH=${PYTHONPATH} emake -C "${S}" test } src_test() { - testing() { - # The different subprojects have some interproject dependencies: - # - audit2allow depens on sepolgen - # - chcat depends on semanage - # and maybe others. - # Add all the modules of the individual subprojects to the - # PYTHONPATH, so they get actually found and used. In - # particular, already installed versions on the system are not - # used. - for dir in audit2allow chcat semanage sepolgen/src sepolicy ; do - PYTHONPATH="${BUILD_DIR}/${dir}:${PYTHONPATH}" - done - PYTHONPATH=${PYTHONPATH} \ - emake -C "${BUILD_DIR}" \ - test - } - python_foreach_impl testing + pushd sepolicy >/dev/null || die + distutils-r1_src_test + popd >/dev/null || die } -src_install() { - installation() { - emake -C "${BUILD_DIR}" \ - DESTDIR="${D}" \ - LIBDIR="\$(PREFIX)/$(get_libdir)" \ - install - python_optimize - } - python_foreach_impl installation +python_install() { + distutils-r1_python_install + emake -C "${S}" \ + DESTDIR="${D}" \ + LIBDIR="\$(PREFIX)/$(get_libdir)" \ + install - # Set version-specific scripts - for pyscript in audit2allow sepolgen-ifgen sepolicy chcat; do - python_replicate_script "${ED}/usr/bin/${pyscript}" - done - for pyscript in semanage; do - python_replicate_script "${ED}/usr/sbin/${pyscript}" - done + # Install over previously installed scripts to ensure proper python support + python_doscript "${S}"/audit2allow/audit2allow + python_doscript "${S}"/audit2allow/sepolgen-ifgen + python_doscript "${S}"/chcat/chcat + python_newscript "${S}"/sepolicy/sepolicy.py sepolicy + python_scriptinto /usr/sbin + python_doscript "${S}"/semanage/semanage + + python_optimize +} + +python_install_all() { # Create sepolgen.conf with different devel location definition mkdir -p "${D}"/etc/selinux || die "Failed to create selinux directory"; if [[ -f /etc/selinux/config ]]; @@ -115,3 +130,9 @@ src_install() { fi fi } + +src_install() { + pushd sepolicy >/dev/null || die + distutils-r1_src_install + popd >/dev/null || die +}