commit:     77fd680a378aa2160c14b5e5733666a97c4cef1b
Author:     Kenton Groombridge <concord <AT> gentoo <DOT> org>
AuthorDate: Wed Mar 29 22:20:25 2023 +0000
Commit:     Kenton Groombridge <concord <AT> gentoo <DOT> org>
CommitDate: Thu Mar 30 00:08:04 2023 +0000
URL:        https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=77fd680a

sys-apps/policycoreutils: bump to 3.5

Signed-off-by: Kenton Groombridge <concord <AT> gentoo.org>

 sys-apps/policycoreutils/Manifest                  |   1 +
 .../policycoreutils/policycoreutils-3.5.ebuild     | 168 +++++++++++++++++++++
 2 files changed, 169 insertions(+)

diff --git a/sys-apps/policycoreutils/Manifest 
b/sys-apps/policycoreutils/Manifest
index 8902061e7b5e..da33a6b1b947 100644
--- a/sys-apps/policycoreutils/Manifest
+++ b/sys-apps/policycoreutils/Manifest
@@ -1,3 +1,4 @@
 DIST policycoreutils-3.3.tar.gz 2818092 BLAKE2B 
0ed9f128a774176ebadb71f448af8dee8c616a706314783b646869e7ea91892e358d5bb03e3aece3d0e6dc3203852e4e2925482727df1e5c71e075236ee43e5c
 SHA512 
db658990355f99a8e43f53d20cc67bf9e557b0a7837d1927c80f325b7f93ad47876382278a980b818484d6e31712a9b03e279f947ebc88c4be60a9f395607f98
 DIST policycoreutils-3.4.tar.gz 771435 BLAKE2B 
53654ad8f17c8e539c7821ddcc4f40dde1aa214943b5f2876efbfd8e10c90747d21c1530df3d53e51677159026a70691db6282f3bedc79739673380e053f74a2
 SHA512 
ded0d6fb5e3f165a893ee42411ac82616ddf37a02acaca6a8437b8f10ea12e5594bbd7bc7e3ead12df00c018078950f3fbe55604c41b0554257c4ca18f55ebb6
+DIST policycoreutils-3.5.tar.gz 775639 BLAKE2B 
777b8564484e89385db7a184c4cad9a99aabf1fd1ac41abd5826c7e6ad29118ae9d6f0d0fd968b6ced87f2f04bc6d7cd207b67428151522915367f656fb8d3f8
 SHA512 
7978ef6b7a278c6384c9b397734d03c4932c8aefecceaa1e6a1345be27b253dbe276fdcd219ce83ad732c6ed55d53bbc3254e39bccadd67d2cd1152a14749444
 DIST policycoreutils-extra-1.37.tar.bz2 8809 BLAKE2B 
a7f6122c2e27f54b018174e962bd7f4c14af04e09bbb5300bde6967ea7f2dc5cd03b5787919a4e7f5288bcbc6747922962b5bd3b588ab1e3a035fbff4910d8f5
 SHA512 
0a85cd7cf279256b5e1927f9dfdd89626a1c8b77b0aeb62b496e7e8d1dccbaa315e39f9308fb2df7270f0bc1c10787b19990e7365cad74b47b61e30394c8b23f

diff --git a/sys-apps/policycoreutils/policycoreutils-3.5.ebuild 
b/sys-apps/policycoreutils/policycoreutils-3.5.ebuild
new file mode 100644
index 000000000000..6df44f548cc8
--- /dev/null
+++ b/sys-apps/policycoreutils/policycoreutils-3.5.ebuild
@@ -0,0 +1,168 @@
+# Copyright 1999-2023 Gentoo Authors
+# Distributed under the terms of the GNU General Public License v2
+
+EAPI="7"
+PYTHON_COMPAT=( python3_{9..11} )
+PYTHON_REQ_USE="xml(+)"
+
+inherit multilib python-r1 toolchain-funcs bash-completion-r1
+
+MY_PV="${PV//_/-}"
+MY_P="${PN}-${MY_PV}"
+EXTRAS_VER="1.37"
+
+DESCRIPTION="SELinux core utilities"
+HOMEPAGE="https://github.com/SELinuxProject/selinux/wiki";
+
+if [[ ${PV} == 9999 ]]; then
+       inherit git-r3
+       EGIT_REPO_URI="https://github.com/SELinuxProject/selinux.git";
+       
SRC_URI="https://dev.gentoo.org/~perfinion/distfiles/policycoreutils-extra-${EXTRAS_VER}.tar.bz2";
+       S1="${WORKDIR}/${P}/${PN}"
+       S2="${WORKDIR}/policycoreutils-extra"
+       S="${S1}"
+else
+       
SRC_URI="https://github.com/SELinuxProject/selinux/releases/download/${MY_PV}/${MY_P}.tar.gz
+               
https://dev.gentoo.org/~perfinion/distfiles/policycoreutils-extra-${EXTRAS_VER}.tar.bz2";
+       KEYWORDS="~amd64 ~arm ~arm64 ~mips ~x86"
+       S1="${WORKDIR}/${MY_P}"
+       S2="${WORKDIR}/policycoreutils-extra"
+       S="${S1}"
+fi
+
+LICENSE="GPL-2"
+SLOT="0"
+IUSE="audit pam split-usr"
+REQUIRED_USE="${PYTHON_REQUIRED_USE}"
+
+DEPEND=">=sys-libs/libselinux-${PV}:=[python,${PYTHON_USEDEP}]
+       >=sys-libs/libsemanage-${PV}:=[python(+),${PYTHON_USEDEP}]
+       >=sys-libs/libsepol-${PV}:=
+       sys-libs/libcap-ng:=
+       >=app-admin/setools-4.2.0[${PYTHON_USEDEP}]
+       audit? ( >=sys-process/audit-1.5.1[python,${PYTHON_USEDEP}] )
+       pam? ( sys-libs/pam:= )
+       ${PYTHON_DEPS}"
+
+# Avoid dependency loop in the cross-compile case, bug #755173
+# (Still exists in native)
+BDEPEND="sys-devel/gettext"
+
+# pax-utils for scanelf used by rlpkg
+RDEPEND="${DEPEND}
+       app-misc/pax-utils"
+
+PDEPEND="sys-apps/semodule-utils
+       sys-apps/selinux-python"
+
+src_unpack() {
+       # Override default one because we need the SRC_URI ones even in case of 
9999 ebuilds
+       default
+       if [[ ${PV} == 9999 ]] ; then
+               git-r3_src_unpack
+       fi
+}
+
+src_prepare() {
+       S="${S1}"
+       cd "${S}" || die "Failed to switch to ${S}"
+       if [[ ${PV} != 9999 ]] ; then
+               # If needed for live ebuilds please use /etc/portage/patches
+               eapply 
"${FILESDIR}/policycoreutils-3.1-0001-newrole-not-suid.patch"
+       fi
+
+       # rlpkg is more useful than fixfiles
+       sed -i -e '/^all/s/fixfiles//' "${S}/scripts/Makefile" \
+               || die "fixfiles sed 1 failed"
+       sed -i -e '/fixfiles/d' "${S}/scripts/Makefile" \
+               || die "fixfiles sed 2 failed"
+
+       eapply_user
+
+       sed -i 's/-Werror//g' "${S1}"/*/Makefile || die "Failed to remove 
Werror"
+
+       python_copy_sources
+       # Our extra code is outside the regular directory, so set it to the 
extra
+       # directory. We really should optimize this as it is ugly, but the extra
+       # code is needed for Gentoo at the same time that policycoreutils is 
present
+       # (so we cannot use an additional package for now).
+       S="${S2}"
+       python_copy_sources
+}
+
+src_compile() {
+       building() {
+               emake -C "${BUILD_DIR}" \
+                       AUDIT_LOG_PRIVS="y" \
+                       AUDITH="$(usex audit y n)" \
+                       PAMH="$(usex pam y n)" \
+                       SESANDBOX="n" \
+                       CC="$(tc-getCC)" \
+                       LIBDIR="\$(PREFIX)/$(get_libdir)"
+       }
+       S="${S1}" # Regular policycoreutils
+       python_foreach_impl building
+       S="${S2}" # Extra set
+       python_foreach_impl building
+}
+
+src_install() {
+       # Python scripts are present in many places. There are no extension 
modules.
+       installation-policycoreutils() {
+               einfo "Installing policycoreutils"
+               emake -C "${BUILD_DIR}" DESTDIR="${D}" \
+                       AUDIT_LOG_PRIVS="y" \
+                       AUDITH="$(usex audit y n)" \
+                       PAMH="$(usex pam y n)" \
+                       SESANDBOX="n" \
+                       CC="$(tc-getCC)" \
+                       LIBDIR="\$(PREFIX)/$(get_libdir)" \
+                       install
+               python_optimize
+       }
+
+       installation-extras() {
+               einfo "Installing policycoreutils-extra"
+               emake -C "${BUILD_DIR}" \
+                       DESTDIR="${D}" \
+                       install
+               python_optimize
+       }
+
+       S="${S1}" # policycoreutils
+       python_foreach_impl installation-policycoreutils
+       S="${S2}" # extras
+       python_foreach_impl installation-extras
+       S="${S1}" # back for later
+
+       # remove redhat-style init script
+       rm -fR "${D}/etc/rc.d" || die
+
+       # compatibility symlinks
+       if use split-usr; then
+               dosym ../../sbin/setfiles /usr/sbin/setfiles
+       else
+               # remove sestatus symlink
+               rm -f "${D}"/usr/sbin/sestatus || die
+       fi
+
+       bashcomp_alias setsebool getsebool
+
+       # location for policy definitions
+       dodir /var/lib/selinux
+       keepdir /var/lib/selinux
+
+       # Set version-specific scripts
+       for pyscript in rlpkg; do
+         python_replicate_script "${ED}/usr/sbin/${pyscript}"
+       done
+}
+
+pkg_postinst() {
+       for POLICY_TYPE in ${POLICY_TYPES} ; do
+               # There have been some changes to the policy store, rebuilding 
now.
+               # https://marc.info/?l=selinux&m=143757277819717&w=2
+               einfo "Rebuilding store ${POLICY_TYPE} in '${ROOT:-/}' (without 
re-loading)."
+               semodule -p "${ROOT:-/}" -s "${POLICY_TYPE}" -n -B || die 
"Failed to rebuild policy store ${POLICY_TYPE}"
+       done
+}

Reply via email to