diff --git a/sys-apps/selinux-python/Manifest b/sys-apps/selinux-python/Manifest index 387a56bf43794..bd8719268b935 100644 --- a/sys-apps/selinux-python/Manifest +++ b/sys-apps/selinux-python/Manifest @@ -1,4 +1,5 @@ DIST selinux-python-3.10.tar.gz 3635967 BLAKE2B 1688b53236605e88bb87d40beb199a6b2394f5739047e7dbc08db6fb4710754796a33ad73948b659fc16789b8fb96bf9cbb2fa66b050a8004b0788409d47381e SHA512 07ee5d1b612dd2679deca31049de7e9cc79cd16d86a46458f76af0d781022db515246c112804381ba045a0ceffe620af53c8b280553d555b2e3ab6b7ac177ebe +DIST selinux-python-3.11.tar.gz 3653704 BLAKE2B 900a9e131f2fc07331bd42fb254ee86646b596c3f078442e12f629c57e66b73b0f0fceb7fef9b9c5a72a5be2086e61ed2da58151cca1b0936ce127f2fdb10358 SHA512 43d65baec6544c7f56e37798c723edfa669edacf065e877d43a1b7124bd6730f5b641f709d1a123f6756c13ce166bdf444a53dfc2370a2f302e771ebee0d281a DIST selinux-python-3.7.tar.gz 3652377 BLAKE2B 59fd7cab0034c175f42f6120ba665701945adcbd4e8af97a0dc2a1c79688a596b199528886ceea079a3f7a969258611fb660449d313d9e893de381293e786381 SHA512 036bc1f0e64cbbaade592dc7899a92765a0bac426140d7d3960f73bad6eb5f95d79d91e0f0e1604f88a991ebf59c4c90ccaaa4158f5dc4d3275ca2aed1673b09 DIST selinux-python-3.8.1.tar.gz 3652823 BLAKE2B dde6081f55d646a6993083a000524b4ce834718f7cd555c8be88574f227f3d8ed24f390dc4568f3f66c1f3643a606779b6350ad28dfbfe2a1bd9d5a6798c37e0 SHA512 bad791411cff373cf749302d44205495a9d100ca6140ea895cb87a85f5d0b0cfaaf4b7418fca661fb3233d14951755d1c2d85961c731243c92622fdfb343734a DIST selinux-python-3.9.tar.gz 3652691 BLAKE2B b1e66ef4199cf22e811924c9626248217eea3745154aa8925f1713aa4a0e1edfb5c15c35ce1c3da14797c7c1d3929220f0411b973efd5b27aa893ad62c35dcca SHA512 e63f6628acdd82ea7a4ef3339429de70b3bd958051e82f4efb13ad3ab65560f482f4852052d4b91c5767a60a51305206b8c1dd3b724d815bca1b7a5d3b97214e diff --git a/sys-apps/selinux-python/files/selinux-python-3.11-no-pip.patch b/sys-apps/selinux-python/files/selinux-python-3.11-no-pip.patch index 33fba9a3b8f9b..5ecaea80e29da 100644 --- a/sys-apps/selinux-python/files/selinux-python-3.11-no-pip.patch +++ b/sys-apps/selinux-python/files/selinux-python-3.11-no-pip.patch @@ -1,14 +1,13 @@ Use eclass functions to install under PEP517 Patch to ensure failure if the change fails to apply. - --- a/sepolicy/Makefile +++ b/sepolicy/Makefile -@@ -27,7 +27,6 @@ test: +@@ -26,7 +26,6 @@ test: @$(PYTHON) test_sepolicy.py -v - install: -- $(PYTHON) -m pip install --no-build-isolation --prefix=$(PREFIX) `test -n "$(DESTDIR)" && echo --root $(DESTDIR) --ignore-installed --no-deps` $(PYTHON_SETUP_ARGS) . + install: python-build +- $(PYTHON) -m pip install --no-build-isolation --force-reinstall --prefix=$(PREFIX) `test -n "$(DESTDIR)" && echo --root $(DESTDIR) --ignore-installed --no-deps` dist/*.whl [ -d $(DESTDIR)$(BINDIR) ] || mkdir -p $(DESTDIR)$(BINDIR) install -m 755 sepolicy.py $(DESTDIR)$(BINDIR)/sepolicy (cd $(DESTDIR)$(BINDIR); ln -sf sepolicy sepolgen) diff --git a/sys-apps/selinux-python/selinux-python-3.11.ebuild b/sys-apps/selinux-python/selinux-python-3.11.ebuild new file mode 100644 index 0000000000000..da1748d5626ec --- /dev/null +++ b/sys-apps/selinux-python/selinux-python-3.11.ebuild @@ -0,0 +1,142 @@ +# Copyright 1999-2026 Gentoo Authors +# Distributed under the terms of the GNU General Public License v2 + +EAPI="8" + +DISTUTILS_USE_PEP517=setuptools +PYTHON_COMPAT=( python3_{12..14} ) +PYTHON_REQ_USE="xml(+)" + +inherit distutils-r1 toolchain-funcs + +MY_PV="${PV//_/-}" +MY_P="${PN}-${MY_PV}" + +DESCRIPTION="SELinux core utilities" +HOMEPAGE="https://github.com/SELinuxProject/selinux/wiki" + +if [[ ${PV} == 9999 ]] ; then + inherit git-r3 + EGIT_REPO_URI="https://github.com/SELinuxProject/selinux.git" + S="${WORKDIR}/${P}/${PN#selinux-}" +else + SRC_URI="https://github.com/SELinuxProject/selinux/releases/download/${MY_PV}/${MY_P}.tar.gz" + KEYWORDS="~amd64 ~arm ~arm64 ~x86" + S="${WORKDIR}/${MY_P}" +fi + +LICENSE="GPL-2" +SLOT="0" +IUSE="test" +RESTRICT="!test? ( test )" + +RDEPEND=">=sys-libs/libselinux-${PV}:=[python] + >=sys-libs/libsemanage-${PV}:=[python(+)] + >=sys-libs/libsepol-${PV}:=[static-libs(+)] + >=app-admin/setools-4.2.0[${PYTHON_USEDEP}] + >=sys-process/audit-1.5.1[python,${PYTHON_USEDEP}]" +DEPEND="${RDEPEND}" +BDEPEND=" + test? ( + ${RDEPEND} + sec-policy/selinux-base + >=sys-apps/secilc-${PV} + )" + +PATCHES=( + "${FILESDIR}"/selinux-python-3.11-no-pip.patch +) + +src_prepare() { + default + + sed -e 's/-Werror//g' -i "${S}"/*/Makefile || die "Failed to remove Werror" + + pushd sepolicy >/dev/null || die + # To avoid default + DISTUTILS_OPTIONAL=1 distutils-r1_src_prepare + popd >/dev/null || die +} + +python_compile() { + distutils-r1_python_compile + emake -C "${S}" \ + CC="$(tc-getCC)" \ + LIBDIR="\$(PREFIX)/$(get_libdir)" +} + +src_compile() { + pushd sepolicy >/dev/null || die + distutils-r1_src_compile + popd >/dev/null || die +} + +python_test() { + # The different subprojects have some interproject dependencies: + # - audit2allow depens on sepolgen + # - chcat depends on semanage + # and maybe others. + # Add all the modules of the individual subprojects to the + # PYTHONPATH, so they get actually found and used. In + # particular, already installed versions on the system are not + # used. + for dir in audit2allow chcat semanage sepolgen/src sepolicy ; do + PYTHONPATH="${S}/${dir}:${PYTHONPATH}" + done + PYTHONPATH=${PYTHONPATH} emake -C "${S}" test +} + +src_test() { + pushd sepolicy >/dev/null || die + distutils-r1_src_test + popd >/dev/null || die +} + +python_install() { + distutils-r1_python_install + emake -C "${S}" \ + DESTDIR="${D}" \ + LIBDIR="\$(PREFIX)/$(get_libdir)" \ + install + + # Install over previously installed scripts to ensure proper python support + python_doscript "${S}"/audit2allow/audit2allow + python_doscript "${S}"/audit2allow/sepolgen-ifgen + python_doscript "${S}"/chcat/chcat + python_newscript "${S}"/sepolicy/sepolicy.py sepolicy + + python_scriptinto /usr/sbin + python_doscript "${S}"/semanage/semanage + + # set _PYTHON_SCRIPTROOT to the implicit default for the next python target, bug #967869 + python_scriptinto /usr/bin + + python_optimize +} + +python_install_all() { + # Create sepolgen.conf with different devel location definition + mkdir -p "${D}"/etc/selinux || die "Failed to create selinux directory"; + if [[ -f /etc/selinux/config ]]; + then + local selinuxtype=$(awk -F'=' '/^SELINUXTYPE/ {print $2}' /etc/selinux/config); + echo "SELINUX_DEVEL_PATH=/usr/share/selinux/${selinuxtype}/include:/usr/share/selinux/${selinuxtype}" \ + > "${D}"/etc/selinux/sepolgen.conf || die "Failed to generate sepolgen" + else + local selinuxtype="${POLICY_TYPES%% *}"; + if [[ -n "${selinuxtype}" ]]; + then + echo "SELINUX_DEVEL_PATH=/usr/share/selinux/${selinuxtype}/include:/usr/share/selinux/${selinuxtype}" \ + > "${D}"/etc/selinux/sepolgen.conf || die "Failed to generate sepolgen" + else + echo "SELINUX_DEVEL_PATH=/usr/share/selinux/strict/include:/usr/share/selinux/strict" \ + > "${D}"/etc/selinux/sepolgen.conf || die "Failed to generate sepolgen" + fi + fi +} + +src_install() { + pushd sepolicy >/dev/null || die + distutils-r1_src_install + popd >/dev/null || die +}