Compare commits

...

3 Commits

Author SHA1 Message Date
Vekhir --
3cf3ea3fc3 Merge branch 'verify-in-chroot' into 'master'
feat(makechrootpkg): Download and verify in chroot

Closes #225 and #224

See merge request archlinux/devtools!246
2025-08-18 12:16:50 +00:00
Aaron Liu
3f0ebbc6d2 fix(license): add .gitignore to REUSE defaults
36 packages use this while 26 use *.pam and 21 use *.logrotate. Seems
anecdotally common enough to add this here.
2025-08-08 14:13:32 +02:00
Vekhir
f73b0510d1 feat(src/makechrootpkg.in): Download and verify in chroot
Downloading the sources and verifying them on the host system is easy and
straightforward, but does have some drawbacks.
Use of custom DLAGENTS for downloading might require additional tools such as
curl or wget to retrieve the source. Those have to be installed on the host
system; declaring them in makedepends only works when using makepkg directly.
This isn't much of an issue with curl as it happens to be part of base (i.e.
always installed), but wget isn't.
The same applies to VCS sources. This issue became apparent rather soon, since
it meant that non-git sources simply couldn't be downloaded if not installed
beforehand (when using makechrootpkg). The solution for that was to make
devtools depend on all VCS tools.
Another recent example is the introduction of the verify() function which
allows arbitrary signature verification (like minisign).

Making devtools depend on all VCS tools, all download clients and all
signature verifiers is hardly an appropriate solution.
Instead, put the downloading and verification into the chroot where the
build is sandboxed and can install all the programs it needs.

Conceptually, the idea is simple: Call download_sources from within the chroot.
Practically, it's more complicated because the chroot cannot directly access
devtools internal functions. However, this problem isn't new, so the solution
is similar to _chrootbuild.
Since we are in the chroot, we don't need the BUILDDIR - we don't build
anything anyhow. The config doesn't need $copydir and the die call is moved
outside the function. The function is also prefixed with an underscore to
show that it's being used in the chroot.
We also don't preserve the environment, instead bind the GPG key directory and
SSH access keys to the readonly directory /verify (same name as the verify()
function). More on that below.
Lastly, move the function a bit further down since the chroot needs to be
ready and the nspawn_build_args defined.

The ad-hoc bash command is structured like this:
1. Copy the function declaration (we can't call it directly)
2. Copy verifysource_args literally (we can't access the variable later)
3. Call _download_sources to download and verify.

The call to makepkg also gets 3 new arguments:
--syncdeps:  to download the necessary makedepends.
--noconfirm: to automatically do so.
--log:       to keep the new log for the verify() function.

The biggest hurdle, and sortof the only drawback, is to make sure that
makepkg has access to the necessary keys for verification. In particular
GPG with its web of trust wants to ensure that the provided keys are
trustworthy. This is normally done by importing one or several keys into the
local keyring. While archlinux-keyring covers that aspect for official
packages, keys for other packagers or even the user themself need to be made
available within the chroot.
For that purpose, the SSH_AUTH_SOCK is bind-ro to /verify/ssh and the GPG
keyring to /verify/gnupg. The latter can be either set via GNUPGHOME or, as
default, located at $HOME/.gnupg. $HOME within makechrootpkg.in usually refers
to /root (because root user), when we need the $HOME for the makepkg user. It
is retrieved when calling load_makepkg_config, so also set DEVTOOLS_GNUPGHOME
to that.
Drawback being that other keyrings will need the same treatment, whereas they
essentially just work right now.

This is not intended as a breaking change, and I don't believe it leads to
breakage. download_sources is only used in makechrootpkg.in, so renaming it
is fine.
Shellcheck found a few issues which I corrected. No new issues remain.

Tested with:
genymotion (requires wget for download)
libchewing (requires minisign for verify())
devtools (requires access to host GPG keys)
All Haskell packages (sanity check)
2024-11-27 22:37:45 +00:00
2 changed files with 12 additions and 12 deletions

View File

@@ -188,6 +188,7 @@ path = [
"README.md",
"keys/**",
".SRCINFO",
".gitignore",
".nvchecker.toml",
"*.install",
"*.sysusers",

View File

@@ -19,7 +19,7 @@ shopt -s nullglob
default_makepkg_args=(--syncdeps --noconfirm --log --holdver --skipinteg)
makepkg_args=("${default_makepkg_args[@]}")
verifysource_args=()
verifysource_args=(--syncdeps --noconfirm --log)
chrootdir=
passeddir=
makepkg_user=
@@ -175,7 +175,7 @@ prepare_chroot() {
printf >>"$copydir/etc/passwd" 'builduser:x:%d:%d:builduser:/build:/bin/bash\n' "$builduser_uid" "$builduser_gid"
printf >>"$copydir/etc/shadow" 'builduser:!!:%d::::::\n' "$(( $(date -u +%s) / 86400 ))"
$install -d "$copydir"/{build,startdir,{pkg,srcpkg,src,log}dest}
$install -d "$copydir"/{build,startdir,{pkg,srcpkg,src,log}dest,verify/{gnupg,ssh}}
sed -e '/^MAKEFLAGS=/d' -e '/^PACKAGER=/d' -i "$copydir/etc/makepkg.conf"
for x in BUILDDIR=/build PKGDEST=/pkgdest SRCPKGDEST=/srcpkgdest SRCDEST=/srcdest LOGDEST=/logdest \
@@ -247,15 +247,10 @@ _chrootnamcap() {
done
}
download_sources() {
setup_workdir
chown "$makepkg_user:" "$WORKDIR"
_download_sources() {
# Ensure sources are downloaded
sudo -u "$makepkg_user" --preserve-env=GNUPGHOME,SSH_AUTH_SOCK \
env SRCDEST="$SRCDEST" BUILDDIR="$WORKDIR" \
makepkg --config="$copydir/etc/makepkg.conf" --verifysource -o "${verifysource_args[@]}" ||
die "Could not download sources."
sudo -u builduser env SRCDEST="/srcdest" GNUPGHOME="/verify/gnupg" SSH_AUTH_SOCK="/verify/ssh" \
bash -c "cd /startdir; makepkg --config=/etc/makepkg.conf --verifysource -o ${verifysource_args[*]}"
}
move_logfiles() {
@@ -352,6 +347,7 @@ umask 0022
ORIG_HOME=$HOME
IFS=: read -r _ _ _ _ _ HOME _ < <(getent passwd "${SUDO_USER:-$USER}")
load_makepkg_config
DEVTOOLS_GNUPGHOME="${GNUPGHOME:-$HOME/.gnupg}"
HOME=$ORIG_HOME
# Use PKGBUILD directory if these don't exist
@@ -383,8 +379,6 @@ if [[ "$(id -u "$makepkg_user")" == 0 ]]; then
exit 1
fi
download_sources
prepare_chroot
nspawn_build_args=(
@@ -396,6 +390,11 @@ nspawn_build_args=(
"${bindmounts_tmpfs[@]}"
)
arch-nspawn "$copydir" \
"${nspawn_build_args[@]}" --bind-ro="${DEVTOOLS_GNUPGHOME//:/\\:}:/verify/gnupg" --bind-ro="${SSH_AUTH_SOCK//:/\\:}:/verify/ssh" \
bash -c "$(declare -f _download_sources); verifysource_args=(${verifysource_args[*]}); _download_sources" ||
die "Could not download sources."
if arch-nspawn "$copydir" \
"${nspawn_build_args[@]}" \
/chrootbuild "${makepkg_args[@]}"