Merged from trunk 9058:9062
authorFabian Groffen <grobian@gentoo.org>
Fri, 28 Dec 2007 13:39:30 +0000 (13:39 -0000)
committerFabian Groffen <grobian@gentoo.org>
Fri, 28 Dec 2007 13:39:30 +0000 (13:39 -0000)
   | 9059    | Bug #201498 - Use desktop-file-validate to validate          |
   | zmedico | *.desktop files inside ${FILESDIR} and generate a            |
   |         | "desktop.invalid" qa warning if an error is detected. Thanks |
   |         | to Betelgeuse for the initial patch.                         |

   | 9060    | Minor code readablity enhancements: * Use relative_path and  |
   | zmedico | full_path variables for files being checked instead of       |
   |         | spreading code like x+"/files/"+y all over the place. * Use  |
   |         | stat.S_IMODE with octal 0111 instead of hex 0x0248 in the    |
   |         | file.executable checks.                                      |

   | 9061    | Bug #203323 - Fix the FEATURES=sfperms code so that it       |
   | zmedico | doesn't chmod g-r on binaries that are both setuid and       |
   |         | setgid. In that case, just chmod o-r.                        |

   | 9062    | Always make sure that the depend phase triggers a source     |
   | zmedico | ${EBUILD} call, even if "${T}"/environment happens to exist  |
   |         | for some reason.                                             |

svn path=/main/branches/prefix/; revision=9063

bin/ebuild.sh
bin/misc-functions.sh
bin/repoman

index c955a8a55b60d69ce709bcc7d450242018235fc2..b38db01dd535104ea0f9ad99ab381235de7762b1 100755 (executable)
@@ -1658,7 +1658,11 @@ if ! hasq ${EBUILD_PHASE} clean depend && \
 fi
 
 if ! hasq ${EBUILD_PHASE} clean && \
-       ( [ ! -f "${T}"/environment ] || hasq noauto ${FEATURES} ) ; then
+       (
+               hasq ${EBUILD_PHASE} depend || \
+               [ ! -f "${T}"/environment ] || \
+               hasq noauto ${FEATURES}
+       ) ; then
        # The bashrcs get an opportunity here to set aliases that will be expanded
        # during sourcing of ebuilds and eclasses.
        source_all_bashrcs
index b4220ce07752e1890ac4cb174ef37317d9593894..74387bc930105f1e4596b3faea2fd2841fc77a3d 100644 (file)
@@ -511,17 +511,30 @@ preinst_sfperms() {
        fi
        # Smart FileSystem Permissions
        if hasq sfperms $FEATURES; then
+               local i
 #note not space-safe
                for i in $(find "${ED}" -type f -perm -4000); do
-                       ebegin ">>> SetUID: [chmod go-r] $i "
-                       chmod go-r "$i"
-                       eend $?
+                       if [ -n "$(find "$i" -perm -2000)" ] ; then
+                               ebegin ">>> SetUID and SetGID: [chmod o-r] /${i#${D}}"
+                               chmod o-r "$i"
+                               eend $?
+                       else
+                               ebegin ">>> SetUID: [chmod go-r] /${i#${D}}"
+                               chmod go-r "$i"
+                               eend $?
+                       fi
                done
 #note not space-safe
                for i in $(find "${ED}" -type f -perm -2000); do
-                       ebegin ">>> SetGID: [chmod o-r] $i "
-                       chmod o-r "$i"
-                       eend $?
+                       if [ -n "$(find "$i" -perm -4000)" ] ; then
+                               # This case is already handled
+                               # by the SetUID check above.
+                               true
+                       else
+                               ebegin ">>> SetGID: [chmod o-r] /${i#${D}}"
+                               chmod o-r "$i"
+                               eend $?
+                       fi
                done
        fi
 }
index 7396b3b6a9e3adb0a8f2da0fbc3f064d02c4300d..6dd8ec2f27cb395e29c8774494f20ddfd1bc62e1 100755 (executable)
@@ -8,6 +8,7 @@
 # that last one is tricky because multiple profiles need to be checked.
 
 import codecs
+import commands
 import errno
 import formatter
 import logging
@@ -233,6 +234,7 @@ def ParseArgs(args, qahelp):
 
 qahelp={
        "CVS/Entries.IO_error":"Attempting to commit, and an IO error was encountered access the Entries file",
+       "desktop.invalid":"desktop-file-validate reports errors in a *.desktop file",
        "digest.partial":"Digest files do not contain all corresponding URI elements",
        "digest.assumed":"Existing digest must be assumed correct (Package level only)",
        "digestentry.unused":"Digest/Manifest entry has no matching SRC_URI entry",
@@ -310,6 +312,7 @@ qawarnings=[
 "ebuild.nostable",
 "ebuild.allmasked",
 "ebuild.nesteddie",
+"desktop.invalid",
 "digest.assumed",
 "digest.missing",
 "digestentry.unused",
@@ -796,6 +799,10 @@ else:
 stats={}
 fails={}
 
+# provided by the desktop-file-utils package
+desktop_file_validate = find_binary("desktop-file-validate")
+desktop_pattern = re.compile(r'.*\.desktop$')
+
 for x in qacats:
        stats[x]=0
        fails[x]=[]
@@ -1152,9 +1159,11 @@ for x in scanlist:
                        for y in filesdirlist:
                                if not y.startswith("digest-"):
                                        continue
-                               if os.stat(checkdir+"/files/"+y)[0] & 0x0248:
+                               relative_path = os.path.join(x, "files", y)
+                               full_path = os.path.join(repodir, relative_path)
+                               if stat.S_IMODE(os.stat(full_path).st_mode) & 0111:
                                        stats["file.executable"] += 1
-                                       fails["file.executable"].append(x+"/files/"+y)
+                                       fails["file.executable"].append(relative_path)
                                
                                mykey = catdir + "/" + y[7:]
                                if y[7:] not in ebuildlist:
@@ -1216,8 +1225,10 @@ for x in scanlist:
                # use filesdirlist as a stack, appending directories as needed so people can't hide > 20k files in a subdirectory.
                while filesdirlist:
                        y = filesdirlist.pop(0)
+                       relative_path = os.path.join(x, "files", y)
+                       full_path = os.path.join(repodir, relative_path)
                        try:
-                               mystat = os.stat(checkdir+"/files/"+y)
+                               mystat = os.stat(full_path)
                        except OSError, oe:
                                if oe.errno == 2:
                                        # don't worry about it.  it likely was removed via fix above.
@@ -1242,6 +1253,23 @@ for x in scanlist:
                                        fails["file.name"].append("%s/files/%s: char '%s'" % (checkdir, y, c))
                                        break
 
+                       if desktop_file_validate and desktop_pattern.match(y):
+                               status, cmd_output = commands.getstatusoutput(
+                                       "'%s' '%s'" % (desktop_file_validate, full_path))
+                               if os.WIFEXITED(status) and os.WEXITSTATUS(status) != os.EX_OK:
+                                       # Note: in the future we may want to grab the
+                                       # warnings in addition to the errors. We're
+                                       # just doing errors now since we don't want
+                                       # to generate too much noise at first.
+                                       error_re = re.compile(r'.*\s*error:\s*(.*)')
+                                       for line in cmd_output.splitlines():
+                                               error_match = error_re.match(line)
+                                               if error_match is None:
+                                                       continue
+                                               stats["desktop.invalid"] += 1
+                                               fails["desktop.invalid"].append(
+                                                       relative_path + ': %s' % error_match.group(1))
+
        del mydigests
 
        if "ChangeLog" not in checkdirlist:
@@ -1271,9 +1299,11 @@ for x in scanlist:
        allmasked = True
 
        for y in ebuildlist:
-               if os.stat(checkdir+"/"+y+".ebuild")[0] & 0x0248:
+               relative_path = os.path.join(x, y + ".ebuild")
+               full_path = os.path.join(repodir, relative_path)
+               if stat.S_IMODE(os.stat(full_path).st_mode) & 0111:
                        stats["file.executable"] += 1
-                       fails["file.executable"].append(x+"/"+y+".ebuild")
+                       fails["file.executable"].append(relative_path)
                if (isCvs or isSvn) and y not in eadded:
                        #ebuild not added to cvs
                        stats["ebuild.notadded"]=stats["ebuild.notadded"]+1
@@ -1553,8 +1583,6 @@ for x in scanlist:
                                for mybad in mybadrestrict:
                                        fails["RESTRICT.invalid"].append(x+"/"+y+".ebuild: %s" % mybad)
                # Syntax Checks
-               relative_path = os.path.join(x, y + ".ebuild")
-               full_path = os.path.join(repodir, relative_path)
                f = open(full_path, 'rb')
                try:
                        for check_name, e in run_checks(f, os.stat(full_path).st_mtime):