mirror of
				https://gitlab.archlinux.org/archlinux/devtools.git
				synced 2025-10-25 22:12:05 +02:00 
			
		
		
		
	Compare commits
	
		
			20 Commits
		
	
	
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
|   | db135e9013 | ||
|   | 443aedca9a | ||
|   | b58fb33482 | ||
|   | f743f58682 | ||
|   | 98166e3454 | ||
|   | 273d5a7a43 | ||
|   | e5fe74102d | ||
|   | 28140068ce | ||
|   | bf7dc83bab | ||
|   | cae954ddb5 | ||
|   | 285a4e94cd | ||
|   | a78bdb841d | ||
|   | 12a1300694 | ||
|   | 625e6bd412 | ||
|   | 6dce935b99 | ||
|   | 98841eb694 | ||
|   | be00fcd47b | ||
|   | 651f8f834f | ||
|   | d83805bc54 | ||
|   | af6c0a0f6a | 
| @@ -26,6 +26,8 @@ usage() { | ||||
| 	exit 1 | ||||
| } | ||||
|  | ||||
| orig_argv=("$@") | ||||
|  | ||||
| while getopts 'hC:M:c:' arg; do | ||||
| 	case "$arg" in | ||||
| 		C) pac_conf="$OPTARG" ;; | ||||
| @@ -38,7 +40,7 @@ done | ||||
| shift $(($OPTIND - 1)) | ||||
|  | ||||
| (( $# < 1 )) && die 'You must specify a directory.' | ||||
| check_root "$0" "$@" | ||||
| check_root "$0" "${orig_argv[@]}" | ||||
|  | ||||
| working_dir=$(readlink -f "$1") | ||||
| shift 1 | ||||
| @@ -84,7 +86,7 @@ umask 0022 | ||||
|  | ||||
| # Sanity check | ||||
| if [[ ! -f "$working_dir/.arch-chroot" ]]; then | ||||
| 	die "'%s' does not appear to be a Arch chroot." "$working_dir" | ||||
| 	die "'%s' does not appear to be an Arch chroot." "$working_dir" | ||||
| elif [[ $(cat "$working_dir/.arch-chroot") != $CHROOT_VERSION ]]; then | ||||
| 	die "chroot '%s' is not at version %s. Please rebuild." "$working_dir" "$CHROOT_VERSION" | ||||
| fi | ||||
| @@ -94,11 +96,8 @@ copy_hostconf | ||||
|  | ||||
| eval $(grep '^CARCH=' "$working_dir/etc/makepkg.conf") | ||||
|  | ||||
| machine_name="${working_dir//[![:alnum:]_-]/-}" | ||||
| machine_name="${machine_name#-}" | ||||
|  | ||||
| exec ${CARCH:+setarch "$CARCH"} systemd-nspawn 2>/dev/null \ | ||||
| 	-D "$working_dir" \ | ||||
| 	--machine "$machine_name" \ | ||||
| 	--register=no \ | ||||
| 	"${mount_args[@]}" \ | ||||
| 	"$@" | ||||
|   | ||||
| @@ -29,6 +29,8 @@ usage() { | ||||
| 	exit 1 | ||||
| } | ||||
|  | ||||
| orig_argv=("$@") | ||||
|  | ||||
| while getopts 'hcr:' arg; do | ||||
| 	case "${arg}" in | ||||
| 		c) clean_first=true ;; | ||||
| @@ -37,11 +39,11 @@ while getopts 'hcr:' arg; do | ||||
| 	esac | ||||
| done | ||||
|  | ||||
| check_root "$0" "${orig_argv[@]}" | ||||
|  | ||||
| # Pass all arguments after -- right to makepkg | ||||
| makechrootpkg_args+=("${@:$OPTIND}") | ||||
|  | ||||
| check_root "$0" "$@" | ||||
|  | ||||
| if ${clean_first} || [[ ! -d "${chroots}/${repo}-${arch}" ]]; then | ||||
| 	msg "Creating chroot for [${repo}] (${arch})..." | ||||
|  | ||||
| @@ -49,7 +51,7 @@ if ${clean_first} || [[ ! -d "${chroots}/${repo}-${arch}" ]]; then | ||||
| 		[[ -d $copy ]] || continue | ||||
| 		msg2 "Deleting chroot copy '$(basename "${copy}")'..." | ||||
|  | ||||
| 		lock 9 "$copydir.lock" "Locking chroot copy '$copy'" | ||||
| 		lock 9 "$copy.lock" "Locking chroot copy '$copy'" | ||||
|  | ||||
| 		if [[ "$(stat -f -c %T "${copy}")" == btrfs ]]; then | ||||
| 			{ type -P btrfs && btrfs subvolume delete "${copy}"; } &>/dev/null | ||||
|   | ||||
							
								
								
									
										11
									
								
								checkpkg.in
									
									
									
									
									
								
							
							
						
						
									
										11
									
								
								checkpkg.in
									
									
									
									
									
								
							| @@ -63,12 +63,11 @@ for _pkgname in "${pkgname[@]}"; do | ||||
|  | ||||
| 	sdiff -s "$TEMPDIR/filelist-$_pkgname-old" "$TEMPDIR/filelist-$_pkgname" | ||||
|  | ||||
| 	if diff "$TEMPDIR/filelist-$_pkgname"{-old,} | grep '\.so' &>/dev/null; then | ||||
| 		mkdir -p "$TEMPDIR/pkg" | ||||
| 		bsdtar -x -C "$TEMPDIR" -f "$pkgfile" #> /dev/null | ||||
| 		comm -13 <(sort "$TEMPDIR/filelist-$_pkgname-old") <(sort "$TEMPDIR/filelist-$_pkgname") | grep .so$ | while read i; do | ||||
| 			echo "${i}: " "$(objdump -p "$TEMPDIR/$i" | grep SONAME)" | ||||
| 		done | ||||
| 	find-libprovides "$TEMPDIR/$oldpkg" 2>/dev/null | sort > "$TEMPDIR/libraries-$_pkgname-old" | ||||
| 	find-libprovides "$pkgfile" 2>/dev/null | sort > "$TEMPDIR/libraries-$_pkgname" | ||||
| 	if ! diff_output="$(sdiff -s "$TEMPDIR/libraries-$_pkgname-old" "$TEMPDIR/libraries-$_pkgname")"; then | ||||
| 		msg "Sonames differ in $_pkgname!" | ||||
| 		echo "$diff_output" | ||||
| 	else | ||||
| 		msg "No soname differences for $_pkgname." | ||||
| 	fi | ||||
|   | ||||
| @@ -32,11 +32,11 @@ else | ||||
| 	setup_workdir | ||||
|  | ||||
| 	case ${script_mode} in | ||||
| 		deps) bsdtar -C $WORKDIR -xf "$1";; | ||||
| 		provides) bsdtar -C $WORKDIR -xf "$1" --include="*.so*";; | ||||
| 		deps) bsdtar -C "$WORKDIR" -xf "$1";; | ||||
| 		provides) bsdtar -C "$WORKDIR" -xf "$1" --include="*.so*";; | ||||
| 	esac | ||||
|  | ||||
| 	pushd $WORKDIR >/dev/null | ||||
| 	pushd "$WORKDIR" >/dev/null | ||||
| fi | ||||
|  | ||||
| process_sofile() { | ||||
| @@ -50,16 +50,16 @@ process_sofile() { | ||||
| 	if ! in_array "${soname}=${soversion}-${soarch}" ${soobjects[@]}; then | ||||
| 		# libfoo.so=1-64 | ||||
| 		echo "${soname}=${soversion}-${soarch}" | ||||
| 		soobjects=(${soobjects[@]} "${soname}=${soversion}-${soarch}") | ||||
| 		soobjects+=("${soname}=${soversion}-${soarch}") | ||||
| 	fi | ||||
| } | ||||
|  | ||||
| case $script_mode in | ||||
| 	deps) find_args="-perm -u+x";; | ||||
| 	provides) find_args="-name *.so*";; | ||||
| 	deps) find_args=(-perm -u+x);; | ||||
|   provides) find_args=(-name '*.so*');; | ||||
| esac | ||||
|  | ||||
| find . -type f $find_args | while read filename; do | ||||
| find . -type f "${find_args[@]}" | while read filename; do | ||||
| 	if [[ $script_mode = "provides" ]]; then | ||||
| 		# ignore if we don't have a shared object | ||||
| 		if ! LC_ALL=C readelf -h "$filename" 2>/dev/null | grep -q '.*Type:.*DYN (Shared object file).*'; then | ||||
|   | ||||
| @@ -79,8 +79,9 @@ trap_abort() { | ||||
| } | ||||
|  | ||||
| trap_exit() { | ||||
| 	local r=$? | ||||
| 	trap - EXIT INT QUIT TERM HUP | ||||
| 	cleanup | ||||
| 	cleanup $r | ||||
| } | ||||
|  | ||||
| die() { | ||||
| @@ -237,7 +238,6 @@ check_root() { | ||||
| 	if type -P sudo >/dev/null; then | ||||
| 		exec sudo -- "$@" | ||||
| 	else | ||||
| 		exec su root -c "$(printf '%q' "$@")" | ||||
| 		exec su root -c "$(printf ' %q' "$@")" | ||||
| 	fi | ||||
| 	die 'This script must be run as root.' | ||||
| } | ||||
|   | ||||
| @@ -12,7 +12,7 @@ m4_include(lib/common.sh) | ||||
|  | ||||
| shopt -s nullglob | ||||
|  | ||||
| makepkg_args='-s --noconfirm -L --holdver' | ||||
| makepkg_args=(-s --noconfirm -L --holdver) | ||||
| repack=false | ||||
| update_first=false | ||||
| clean_first=false | ||||
| @@ -46,7 +46,7 @@ usage() { | ||||
| 	echo 'command:' | ||||
| 	echo '    mkarchroot <chrootdir>/root base-devel' | ||||
| 	echo '' | ||||
| 	echo "Default makepkg args: $makepkg_args" | ||||
| 	echo "Default makepkg args: ${makepkg_args[*]}" | ||||
| 	echo '' | ||||
| 	echo 'Flags:' | ||||
| 	echo '-h         This help' | ||||
| @@ -66,9 +66,10 @@ usage() { | ||||
| 	exit 1 | ||||
| } | ||||
|  | ||||
| orig_argv=("$@") | ||||
|  | ||||
| while getopts 'hcur:I:l:nTD:d:' arg; do | ||||
| 	case "$arg" in | ||||
| 		h) usage ;; | ||||
| 		c) clean_first=true ;; | ||||
| 		D) bindmounts_ro+=(--bind-ro="$OPTARG") ;; | ||||
| 		d) bindmounts_rw+=(--bind="$OPTARG") ;; | ||||
| @@ -76,15 +77,16 @@ while getopts 'hcur:I:l:nTD:d:' arg; do | ||||
| 		r) passeddir="$OPTARG" ;; | ||||
| 		I) install_pkgs+=("$OPTARG") ;; | ||||
| 		l) copy="$OPTARG" ;; | ||||
| 		n) run_namcap=true; makepkg_args="$makepkg_args -i" ;; | ||||
| 		n) run_namcap=true; makepkg_args+=(-i) ;; | ||||
| 		T) temp_chroot=true; copy+="-$$" ;; | ||||
| 		h|*) usage ;; | ||||
| 	esac | ||||
| done | ||||
|  | ||||
| check_root "$0" "$@" | ||||
|  | ||||
| [[ ! -f PKGBUILD && -z "${install_pkgs[*]}" ]] && die 'This must be run in a directory containing a PKGBUILD.' | ||||
|  | ||||
| check_root "$0" "${orig_argv[@]}" | ||||
|  | ||||
| # Canonicalize chrootdir, getting rid of trailing / | ||||
| chrootdir=$(readlink -e "$passeddir") | ||||
| [[ ! -d $chrootdir ]] && die "No chroot dir defined, or invalid path '%s'" "$passeddir" | ||||
| @@ -100,7 +102,7 @@ else | ||||
| fi | ||||
|  | ||||
| # Pass all arguments after -- right to makepkg | ||||
| makepkg_args="$makepkg_args ${*:$OPTIND}" | ||||
| makepkg_args+=("${@:$OPTIND}") | ||||
|  | ||||
| # See if -R was passed to makepkg | ||||
| for arg in "${@:OPTIND}"; do | ||||
| @@ -113,7 +115,7 @@ for arg in "${@:OPTIND}"; do | ||||
| done | ||||
|  | ||||
| if [[ -n $SUDO_USER ]]; then | ||||
| 	USER_HOME=$(eval echo ~$SUDO_USER) | ||||
| 	eval "USER_HOME=~$SUDO_USER" | ||||
| else | ||||
| 	USER_HOME=$HOME | ||||
| fi | ||||
| @@ -164,7 +166,7 @@ create_chroot() { | ||||
|  | ||||
| clean_temporary() { | ||||
| 	stat_busy "Removing temporary copy [$copy]" | ||||
| 	if [[ "$chroottype" == btrfs ]]; then | ||||
| 	if [[ "$chroottype" == btrfs ]] && ! mountpoint -q "$copydir"; then | ||||
| 		btrfs subvolume delete "$copydir" >/dev/null || | ||||
| 			die "Unable to delete subvolume %s" "$copydir" | ||||
| 	else | ||||
| @@ -234,7 +236,13 @@ prepare_chroot() { | ||||
| 		echo 'SRCDEST="/srcdest"' >> "$copydir/etc/makepkg.conf" | ||||
| 	fi | ||||
|  | ||||
| 	chown -R nobody "$copydir"/{build,pkgdest,srcpkgdest,logdest,srcdest,startdir} | ||||
| 	builduser_uid=${SUDO_UID:-$UID} | ||||
|  | ||||
| 	# We can't use useradd without chrooting, otherwise it invokes PAM modules | ||||
| 	# which we might not be able to load (i.e. when building i686 packages on | ||||
| 	# an x86_64 host). | ||||
| 	printf 'builduser:x:%d:100:builduser:/:/usr/bin/nologin\n' "$builduser_uid" >>"$copydir/etc/passwd" | ||||
| 	chown -R "$builduser_uid" "$copydir"/{build,pkgdest,srcpkgdest,logdest,srcdest,startdir} | ||||
|  | ||||
| 	if [[ -n $MAKEFLAGS ]]; then | ||||
| 		sed -i '/^MAKEFLAGS=/d' "$copydir/etc/makepkg.conf" | ||||
| @@ -246,18 +254,33 @@ prepare_chroot() { | ||||
| 		echo "PACKAGER='${PACKAGER}'" >> "$copydir/etc/makepkg.conf" | ||||
| 	fi | ||||
|  | ||||
| 	if [[ ! -f $copydir/etc/sudoers.d/nobody-pacman ]]; then | ||||
| 		cat > "$copydir/etc/sudoers.d/nobody-pacman" <<EOF | ||||
| 	if [[ ! -f $copydir/etc/sudoers.d/builduser-pacman ]]; then | ||||
| 		cat > "$copydir/etc/sudoers.d/builduser-pacman" <<EOF | ||||
| Defaults env_keep += "HOME" | ||||
| nobody ALL = NOPASSWD: /usr/bin/pacman | ||||
| builduser ALL = NOPASSWD: /usr/bin/pacman | ||||
| EOF | ||||
| 		chmod 440 "$copydir/etc/sudoers.d/nobody-pacman" | ||||
| 		chmod 440 "$copydir/etc/sudoers.d/builduser-pacman" | ||||
| 	fi | ||||
|  | ||||
| 	# This is a little gross, but this way the script is recreated every time in the | ||||
| 	# working copy | ||||
| 	printf $'#!/bin/bash\n%s\n_chrootbuild %q %q' "$(declare -f _chrootbuild)" \ | ||||
| 		"$makepkg_args" "$run_namcap" >"$copydir/chrootbuild" | ||||
| 	{ | ||||
| 		printf '#!/bin/bash\n' | ||||
| 		declare -f _chrootbuild | ||||
| 		printf '_chrootbuild' | ||||
| 		printf ' %q' "${makepkg_args[@]}" | ||||
| 		printf ' || exit\n' | ||||
|  | ||||
| 		if $run_namcap; then | ||||
| 			cat <<'EOF' | ||||
| pacman -S --needed --noconfirm namcap | ||||
| for pkgfile in /startdir/PKGBUILD /pkgdest/*; do | ||||
| 	echo "Checking ${pkgfile##*/}" | ||||
| 	sudo -u builduser namcap "$pkgfile" 2>&1 | tee "/logdest/${pkgfile##*/}-namcap.log" | ||||
| done | ||||
| EOF | ||||
| 		fi | ||||
| 	} >"$copydir/chrootbuild" | ||||
| 	chmod +x "$copydir/chrootbuild" | ||||
| } | ||||
|  | ||||
| @@ -283,8 +306,6 @@ download_sources() { | ||||
| _chrootbuild() { | ||||
| 	# This function isn't run in makechrootpkg, | ||||
| 	# so no global variables | ||||
| 	local makepkg_args="$1" | ||||
| 	local run_namcap="$2" | ||||
|  | ||||
| 	. /etc/profile | ||||
| 	export HOME=/build | ||||
| @@ -302,7 +323,7 @@ _chrootbuild() { | ||||
| 			for vcsdir in */.$vcs; do | ||||
| 				rm "${vcsdir%/.$vcs}" | ||||
| 				cp -a "${dir}_host/${vcsdir%/.$vcs}" . | ||||
| 				chown -R nobody "${vcsdir%/.$vcs}" | ||||
| 				chown -R builduser "${vcsdir%/.$vcs}" | ||||
| 			done | ||||
| 		done | ||||
| 	done | ||||
| @@ -312,7 +333,7 @@ _chrootbuild() { | ||||
| 	# XXX: Keep PKGBUILD writable for pkgver() | ||||
| 	rm PKGBUILD* | ||||
| 	cp /startdir_host/PKGBUILD* . | ||||
| 	chown nobody PKGBUILD* | ||||
| 	chown builduser PKGBUILD* | ||||
|  | ||||
| 	# Safety check | ||||
| 	if [[ ! -w PKGBUILD ]]; then | ||||
| @@ -320,17 +341,7 @@ _chrootbuild() { | ||||
| 		exit 1 | ||||
| 	fi | ||||
|  | ||||
| 	sudo -u nobody makepkg $makepkg_args || exit 1 | ||||
|  | ||||
| 	if $run_namcap; then | ||||
| 		pacman -S --needed --noconfirm namcap | ||||
| 		for pkgfile in /startdir/PKGBUILD /pkgdest/*; do | ||||
| 			echo "Checking ${pkgfile##*/}" | ||||
| 			sudo -u nobody namcap "$pkgfile" 2>&1 | tee "/logdest/${pkgfile##*/}-namcap.log" | ||||
| 		done | ||||
| 	fi | ||||
|  | ||||
| 	exit 0 | ||||
| 	sudo -u builduser makepkg "$@" | ||||
| } | ||||
|  | ||||
| move_products() { | ||||
|   | ||||
| @@ -19,6 +19,13 @@ DLAGENTS=('ftp::/usr/bin/curl -fC - --ftp-pasv --retry 3 --retry-delay 3 -o %o % | ||||
| # /usr/bin/lftpget -c | ||||
| # /usr/bin/wget | ||||
|  | ||||
| #-- The the package required by makepkg to download VCS sources | ||||
| #  Format: 'protocol::package' | ||||
| VCSCLIENTS=('bzr::bzr' | ||||
|             'git::git' | ||||
|             'hg::mercurial' | ||||
|             'svn::subversion') | ||||
|  | ||||
| ######################################################################### | ||||
| # ARCHITECTURE, COMPILE FLAGS | ||||
| ######################################################################### | ||||
|   | ||||
| @@ -19,6 +19,13 @@ DLAGENTS=('ftp::/usr/bin/curl -fC - --ftp-pasv --retry 3 --retry-delay 3 -o %o % | ||||
| # /usr/bin/lftpget -c | ||||
| # /usr/bin/wget | ||||
|  | ||||
| #-- The the package required by makepkg to download VCS sources | ||||
| #  Format: 'protocol::package' | ||||
| VCSCLIENTS=('bzr::bzr' | ||||
|             'git::git' | ||||
|             'hg::mercurial' | ||||
|             'svn::subversion') | ||||
|  | ||||
| ######################################################################### | ||||
| # ARCHITECTURE, COMPILE FLAGS | ||||
| ######################################################################### | ||||
|   | ||||
| @@ -15,7 +15,7 @@ CHROOT_VERSION='v3' | ||||
| working_dir='' | ||||
|  | ||||
| usage() { | ||||
| 	echo "Usage: ${0##*/} [options] working-dir [package-list | app]" | ||||
| 	echo "Usage: ${0##*/} [options] working-dir package-list..." | ||||
| 	echo ' options:' | ||||
| 	echo '    -C <file>     Location of a pacman config file' | ||||
| 	echo '    -M <file>     Location of a makepkg config file' | ||||
| @@ -24,6 +24,8 @@ usage() { | ||||
| 	exit 1 | ||||
| } | ||||
|  | ||||
| orig_argv=("$@") | ||||
|  | ||||
| while getopts 'hC:M:c:' arg; do | ||||
| 	case "$arg" in | ||||
| 		C) pac_conf="$OPTARG" ;; | ||||
| @@ -37,7 +39,7 @@ shift $(($OPTIND - 1)) | ||||
|  | ||||
| (( $# < 2 )) && die 'You must specify a directory and one or more packages.' | ||||
|  | ||||
| check_root "$0" "$@" | ||||
| check_root "$0" "${orig_argv[@]}" | ||||
|  | ||||
| working_dir="$(readlink -f $1)" | ||||
| shift 1 | ||||
|   | ||||
		Reference in New Issue
	
	Block a user