rev bump with migration patch
authorJason Zaman <perfinion@gentoo.org>
Thu, 23 Apr 2015 13:14:31 +0000 (13:14 +0000)
committerJason Zaman <perfinion@gentoo.org>
Thu, 23 Apr 2015 13:14:31 +0000 (13:14 +0000)
Package-Manager: portage-2.2.18/cvs/Linux x86_64
Manifest-Sign-Key: 0x7EF137EC935B0EAF

sys-libs/libsemanage/ChangeLog
sys-libs/libsemanage/Manifest
sys-libs/libsemanage/files/0001-libsemanage-do-not-copy-contexts-in-semanage_migrate.patch [new file with mode: 0644]
sys-libs/libsemanage/files/0002-semanage_migrate_store-Python3-support.patch [deleted file]
sys-libs/libsemanage/libsemanage-2.4-r1.ebuild [new file with mode: 0644]

index 26b0ff4de3e16faeda6ec39f8b758ed7e53a6c45..5734c4b6edb239aa4ad6fc92fa5a45bb4068d93b 100644 (file)
@@ -1,6 +1,14 @@
 # ChangeLog for sys-libs/libsemanage
 # Copyright 1999-2015 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/sys-libs/libsemanage/ChangeLog,v 1.90 2015/04/18 21:58:59 perfinion Exp $
+# $Header: /var/cvsroot/gentoo-x86/sys-libs/libsemanage/ChangeLog,v 1.91 2015/04/23 13:14:18 perfinion Exp $
+
+*libsemanage-2.4-r1 (23 Apr 2015)
+
+  23 Apr 2015; Jason Zaman <perfinion@gentoo.org>
+  +files/0001-libsemanage-do-not-copy-contexts-in-semanage_migrate.patch,
+  +libsemanage-2.4-r1.ebuild,
+  -files/0002-semanage_migrate_store-Python3-support.patch:
+  rev bump with migration patch
 
   18 Apr 2015; Jason Zaman <perfinion@gentoo.org> -libsemanage-2.3-r3.ebuild,
   -libsemanage-2.4_rc6-r2.ebuild, -libsemanage-2.4_rc7.ebuild:
index 0eb484bc1870ed59e7b48bd406baf856a2ad364b..f613db2c57b9161c0dbd9dfeb162c6b46215050d 100644 (file)
@@ -1,31 +1,32 @@
 -----BEGIN PGP SIGNED MESSAGE-----
 Hash: SHA256
 
-AUX 0002-semanage_migrate_store-Python3-support.patch 10287 SHA256 685bab1de2fdc80952592fe7347f599b3a0dc8c5410606cd96d31275d48fae4d SHA512 4d0dd2b0b9ca81ab7a6b3bfdb89307fd33c8e7f4808ad28eda93246d01f6c91b3a73cb116a84736aa79cd7eaf7563d6aa9bffb38f974d1d445a49fc8c8d77db0 WHIRLPOOL e40042934df6c0747b36a8da53125fe91c07f1b7087f29e93f55ca8103021ff1fbb07d080b6bc5b1ca5b91ef6fdae08d6b0dddfb3e15567ff8a901397041565b
+AUX 0001-libsemanage-do-not-copy-contexts-in-semanage_migrate.patch 7190 SHA256 5746fe5b4f85bb2ca4fdd50b29de98a8561c6a88e66dfb067c3e393eb1399b4d SHA512 ad9923ccad7a0d975b850eaeb5a801b3f933c0a26112226fa19112dd8aa07de9766845dfec44680799a577175c3a564e9c222f7b0968871fd1f69c3140ab569b WHIRLPOOL dda70c907d5ec766886f08e43da0a417ac67652f1682e629c06ce175f37d3db63e9ab257874435a26f4bc1ae7436421a5414b89b997f181a4ff9fe6434c77a2d
 DIST libsemanage-2.2.tar.gz 138208 SHA256 11f60bfa0f1c6063cd9bd99ce0cb4acc9d6d9e9b8d7743d39e847bcd7803bd75 SHA512 09032b1b322fec7346164939ade118034812cb538ebc72121640d4ac5c89d2a66b59caa465027cfbebb590dee039a26d4345eafedf365d7f6ad0b5e90377d50f WHIRLPOOL 49170c5ee9ff57dcc4a15aa72386f37993f76436f0da25808c60dab2d03ba52932d0d4fa753c326900d83d2fae30f8bcf659251f17327783f2e2be3deb4842f4
 DIST libsemanage-2.3.tar.gz 138231 SHA256 03e09e35e611c286e446bef92b6023ef2623815996f5a53394bb02e49a312e4b SHA512 defe3bbdbe51abdaa13a39f693c33446d8a1a8509ac1eb25c7770da2df6487bcb0ca31259d02b4531d4c81db5e221e94e95bec97f6a1a155e1de2f65e6f0da34 WHIRLPOOL 943d4d300aa8ad49c411b10b41c0c3e751c46dbcbbe129bdd1d2e975e231c58391d6ecdee6b27699fff9f6e6facf5b48fc8d57c2ff68692694c7de430750fac9
 DIST libsemanage-2.4.tar.gz 151173 SHA256 1a4cace4ef16786531ec075c0e7b2f961e2fee5dc86c5f983a689058899a6484 SHA512 54f993253b22207b053daf4d34e72c65c72279866416089b6c0f047ef77bca3e307eac0ce6dfe40bd14e2e47e79841b358d5607501779f38d9b5f7c35f3b7729 WHIRLPOOL 7303c06515ed59b5756a87d08aff07671e51d26ce9fa452ca75643dd0ce4658571dc69d86434c943d691a4ab0d90cbdccdaa27e5aaec5fdf8057cf2d5d30631e
 EBUILD libsemanage-2.2-r2.ebuild 3201 SHA256 39aa38de07e4b04b7f200a5abcfbc3a4dc033063c4adcb51813486d26f82c1cf SHA512 f1186f33e4685c0b6403e001db853ce845940f2332fc9b389e3fa96c5ff0762bcdc1ec22caacf12e5045d946fdb6c611b29b7ec1807bff72df93935fa7063a75 WHIRLPOOL 4715e92f0be45cbfb58e3a44bc8c1a1e69f6f66a803d816a4975d5be596f5f2dbfe8f3d95499475b7c0090cbe22e0359dcd1c895b8be619440463e638da16871
 EBUILD libsemanage-2.3-r4.ebuild 3560 SHA256 e8ccb383ae811fdef8e12f8459a11618269b658b591dd4d57d7537021e361d26 SHA512 dda74556b122d354979db9c5c4883479e56f49e5a2c48a4cd70f112fa22f41daaa75bad63d2a0a94672d17fecf63cc0b6a8dc48d58e0908e851bb98b346036a5 WHIRLPOOL 7b0716d3604b6db85818734c6a148485a8bc3aa0b76f1172e1520dbc5294e75ed8d83cc97c065c9e6cc54b6b22e01ea3cbb094f1e39514208f5fc69ca831f781
+EBUILD libsemanage-2.4-r1.ebuild 4680 SHA256 18910f48e17191ebad83a26a1fcb7f1c1278743f25b3e160d9da8d5c322754f0 SHA512 01b5c14ce363d4708068472cdfa5a8d4d0792448217f4b64aca26365a21e1491365e58e0320a0fe9da14adf9cdc23006b6d05454fecd5614cf3d0b2d99c4dfb0 WHIRLPOOL 7fbaa8394b632ecf994ea2370400d24f2137563eb33c512390ce7237429f545ebb63446c9c308f9a087bfc2f9c328d2ef8a3bb64e71c4eac1c814412bebb9a1f
 EBUILD libsemanage-2.4.ebuild 3945 SHA256 20efaf0d321f2806cbf309b06678ba60e2e29694ee51eefb0b36490ae6ff9f07 SHA512 aebcd158ea524bbf9534ea43788fa8764f06f6ae511f1ac1b04196d0330229979fb7ae290e711334359b9c5cf3a3ce0e809817a8da79ed90f540b1cae57780dd WHIRLPOOL d51b6821ca88a636a0ca1d02bfe833bfbe4068694dacdacd45b5e12e63127120c8219d095ef2a11e137d1c41f1da6c6d6fbb8c10d61af3667c75239c147e6b8e
-MISC ChangeLog 13284 SHA256 4d2030f5f9113bcc6b5140df5269f028f68c4103c05fbb42139812e8a4bec0fa SHA512 5bb6a64474986cec0e841ed806623ab15685ee863c02b38efb43f4abe4d92a705069aaa6a6404dd839391da777ed2570aff7d2c76031f8c1b0e217b22ffa79d8 WHIRLPOOL 5be951802cbe51d5b0f7db17b19be228192b20cf4c0ef94c95e5fd81edefe62bf8e445407514f5255c331e322bfe98d8fe25cb1793737b05316f1ba1c5c99438
+MISC ChangeLog 13566 SHA256 e9eeb746b5aa9ab7ce0d84a20808fad355ecb458d87e1fa17aa3bf5f9c666be8 SHA512 efffe3ba647771338af12b95e2c749d17a9dbb624a2b692178774d690904102445da98d7c6d0e299baf9a8d98774768e13fa3582493e1a37c8662442b220c9f0 WHIRLPOOL 086ab33d868885c94198b374b53b5e6ddcfd427d8b3a3b519785118eca8d3b5f31c9e98043282dc92610068897f368e8887fee93db1f920aa9549e2ae764cfee
 MISC metadata.xml 233 SHA256 c5a240155da9b7588e31ff668d3656486a16868654c076f7e1aea823a6b85ae9 SHA512 96a2805dfeebf2e9458e4b602da2cff381f9a3a2e05feb0b36d22b25cac15417e54c8f0572f14f3f944ca7d20377f20ef217ad51105e273a40525b1174df714a WHIRLPOOL 1e68c6d8f1f0446a8be9a001f4c89d641a2055fc9d440be286f753fbf8a216f9d0ed530694f1ff5859a1604eff125316fdcf9593cb91113e4735cc3fa8e8b9a3
 -----BEGIN PGP SIGNATURE-----
 Version: GnuPG v2.0
 
-iQJ8BAEBCABmBQJVMtOkXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
+iQJ8BAEBCABmBQJVOPA2XxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
 ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRFMTYyREVBRDFDQ0REMTEzRjA0QjNENDky
-QkJFRDlDQjFBNjhFRjU1AAoJECu+2csaaO9Vfy4P/376uNPavUDA2KsXL5uCo7T0
-+IWsouJHoieNSv65ZKrlMXOhB3t0khLPF8LKGL8whhNOmQgeYr0iA4fLdMQ48849
-KSzgya4hw4Qv5/T9M+RAXyKptB9Lxus0JzhoXJ7+b5+R3ruNinAsAosp9o0t/Gsg
-6vFDV09qjlvrSwEn06qKOglVpQInsb4ahuwP9YoerKN7h96bsw8OSyGPAlUDRVQP
-GVUT+/ZVOstYb4ONz+fUO4bxQG47SQcwNhNtGaseYoWhD6DIoh5+iKxA3FN/2qnB
-j5WldKVR9PONvDvmHUZwtj13+yIHqLuxeD2hOZ9u18fTivsITQLM4QlKpoLC/9OO
-yiClb3+IsNYLyYlS9ErBhrrYQ9gIQe4yQur5sKCa84P45ti37Po+I3gZee4AKybT
-VgfLKO2wnD+pfWcw+DOguDEu3gPt91xNcVGGon7+wQ9d0lRHcINNO19SypmVIMDV
-62zOFv9TMTxFidzT+inPfXsNCvCXvj89QFKgu5NJz9qyhbVh3pr1JixHiXyUoF2B
-yw6g/YVV5xZYi5nhwQ5gBlP/ntQgWUA6lj66R3OSpPChEX5tXgd6+0wjhqXa0opP
-SppMJZelKfqxFGS3tFpYonHq1k9Imjk2vmOGQr9BITm4qWvH4ouF9ySybFp2+so3
-5O+4IgW9DlS+q3chHhg+
-=Bnia
+QkJFRDlDQjFBNjhFRjU1AAoJECu+2csaaO9Vd2EP/0Nhl1OiqnVaZwoYPufAg+No
+WylQbTPfaHzf81IHv1i7MuyVGrCTUYiORZEq1LEsfiSBSY3O5DysnubWuP0SCrCc
+Wo+DKWFN5nMwvLSOiaZzhriqGBzltiamkageWtBgjwaQk37RTVdkN45+yBW6MmLn
+uxqORtKrfx7WQgsp27+pLI0YoqyvoWdgw+rrWpTVtIXc87rqA9TbPzJtJyi2eu1W
+yLpE4lhNcKOaFflMtAoWXVhpOQMbCy/qJIavv7e3BoJB3oxkwIlhtCJuIFSrNb6L
+zImdDOVJ76ZwyKsfmUiJVGgnjPrcu2SCxObLEKI1YKkQqgKXSxEPSvm8JxfPzPxi
+h0ppKnprLtOlasjJTcy5n1XEws5A19APyYsDHWsDQifZywDT1t7xvQbg5gnMTInR
+rKy/xJU1K9nfv+YDS1ksNowNFWW6rFxnvh8cbvxA7d/6gtmD/okGwYZ4Pm2/KqZ8
+IpwVKbrlQd8sprRyv6AlS2KDC4tKW78N32fywDzOoCdyt/ysnwOp3PPDWY97EDhx
+uNR6OEUMNNhip48ajxXYmT9X8MoAoYXF3bKcrM07FoTBgQaxD/TjO+o7JeZaK2rs
+SYdAaZudVSfpNfk/lczDf53VMxL/suxdvi8jLcY9BzZ4QzrfhWB0dsSiJJvRriAE
+v7Vluh0fX3IbGBNo4FJh
+=f18c
 -----END PGP SIGNATURE-----
diff --git a/sys-libs/libsemanage/files/0001-libsemanage-do-not-copy-contexts-in-semanage_migrate.patch b/sys-libs/libsemanage/files/0001-libsemanage-do-not-copy-contexts-in-semanage_migrate.patch
new file mode 100644 (file)
index 0000000..8e523dc
--- /dev/null
@@ -0,0 +1,208 @@
+From 9caebebd598de737f27cdc8d5253a2cebd67d5a9 Mon Sep 17 00:00:00 2001
+From: Jason Zaman <jason@perfinion.com>
+Date: Wed, 22 Apr 2015 18:27:09 +0400
+Subject: [PATCH] libsemanage: do not copy contexts in semanage_migrate_store
+
+The modules from the old store were previously copied to the new one
+using setfscreatecon and shutil.copy2(). Now that refpolicy has rules
+about the new policy location[1], copying the contexts is redundant.
+
+More importantly, the setcreatefscon caused a constraint violation[2]
+which made the migration fail. In python3, shutil.copy2() copies xattrs
+as well which again causes problems. shutil.copy() is enough for our
+needs here as it will copy the file and permissions in both py2 and 3.
+We do not need the extra things that copy2() does (mtime, xattr, etc).
+
+[1] http://oss.tresys.com/pipermail/refpolicy/2014-December/007511.html
+
+[2]
+type=AVC msg=audit(1429438272.872:1869): avc:  denied  { create } for  pid=28739 comm="semanage_migrat" name="strict" scontext=staff_u:sysadm_r:semanage_t tcontext=system_u:object_r:semanage_store_t tclass=dir permissive=0
+       constrain dir { create relabelfrom relabelto } ((u1 == u2 -Fail-)  or (t1 == can_change_object_identity -Fail-) ); Constraint DENIED
+allow semanage_t semanage_store_t:dir create;
+
+Signed-off-by: Jason Zaman <jason@perfinion.com>
+---
+ libsemanage/utils/semanage_migrate_store | 77 ++++++++------------------------
+ 1 file changed, 18 insertions(+), 59 deletions(-)
+
+diff --git a/libsemanage/utils/semanage_migrate_store b/libsemanage/utils/semanage_migrate_store
+index 03b492e..2f85e9c 100755
+--- a/libsemanage/utils/semanage_migrate_store
++++ b/libsemanage/utils/semanage_migrate_store
+@@ -8,7 +8,6 @@ import shutil
+ import sys
+ from optparse import OptionParser
+ 
+-import bz2
+ import ctypes
+ 
+ sepol = ctypes.cdll.LoadLibrary('libsepol.so')
+@@ -21,41 +20,20 @@ except:
+       exit(1)
+ 
+ 
+-
+-
+-# For some reason this function doesn't exist in libselinux :\
+-def copy_with_context(src, dst):
++def copy_file(src, dst):
+       if DEBUG:
+               print("copying %s to %s" % (src, dst))
+       try:
+-              con = selinux.lgetfilecon_raw(src)[1]
+-      except:
+-              print("Could not get file context of %s" % src, file=sys.stderr)
+-              exit(1)
+-
+-      try:
+-              selinux.setfscreatecon_raw(con)
+-      except:
+-              print("Could not set fs create context: %s" %con, file=sys.stderr)
+-              exit(1)
+-
+-      try:
+-              shutil.copy2(src, dst)
++              shutil.copy(src, dst)
+       except OSError as the_err:
+               (err, strerr) = the_err.args
+               print("Could not copy %s to %s, %s" %(src, dst, strerr), file=sys.stderr)
+               exit(1)
+ 
+-      try:
+-              selinux.setfscreatecon_raw(None)
+-      except:
+-              print("Could not reset fs create context. May need to relabel system.", file=sys.stderr)
+ 
+-def create_dir_from(src, dst, mode):
++def create_dir(dst, mode):
+       if DEBUG: print("Making directory %s" % dst)
+       try:
+-              con = selinux.lgetfilecon_raw(src)[1]
+-              selinux.setfscreatecon_raw(con)
+               os.makedirs(dst, mode)
+       except OSError as the_err:
+               (err, stderr) = the_err.args
+@@ -65,28 +43,18 @@ def create_dir_from(src, dst, mode):
+                       print("Error creating %s" % dst, file=sys.stderr)
+                       exit(1)
+ 
+-      try:
+-              selinux.setfscreatecon_raw(None)
+-      except:
+-              print("Could not reset fs create context. May need to relabel system.", file=sys.stderr)
+ 
+-def create_file_from(src, dst):
++def create_file(dst):
+       if DEBUG: print("Making file %s" % dst)
+       try:
+-              con = selinux.lgetfilecon_raw(src)[1]
+-              selinux.setfscreatecon_raw(con)
+               open(dst, 'a').close()
+       except OSError as the_err:
+               (err, stderr) = the_err.args
+               print("Error creating %s" % dst, file=sys.stderr)
+               exit(1)
+ 
+-      try:
+-              selinux.setfscreatecon_raw(None)
+-      except:
+-              print("Could not reset fs create context. May need to relabel system.", file=sys.stderr)
+ 
+-def copy_module(store, name, con, base):
++def copy_module(store, name, base):
+       if DEBUG: print("Install module %s" % name)
+       (file, ext) = os.path.splitext(name)
+       if ext != ".pp":
+@@ -94,8 +62,6 @@ def copy_module(store, name, con, base):
+               print("warning: %s has invalid extension, skipping" % name, file=sys.stderr)
+               return
+       try:
+-              selinux.setfscreatecon_raw(con)
+-
+               if base:
+                       root = oldstore_path(store)
+               else:
+@@ -105,7 +71,7 @@ def copy_module(store, name, con, base):
+ 
+               os.mkdir("%s/%s" % (bottomdir, file))
+ 
+-              copy_with_context(os.path.join(root, name), "%s/%s/hll" % (bottomdir, file))
++              copy_file(os.path.join(root, name), "%s/%s/hll" % (bottomdir, file))
+ 
+               # This is the ext file that will eventually be used to choose a compiler
+               efile = open("%s/%s/lang_ext" % (bottomdir, file), "w+", 0o600)
+@@ -116,15 +82,11 @@ def copy_module(store, name, con, base):
+               print("Error installing module %s" % name, file=sys.stderr)
+               exit(1)
+ 
+-      try:
+-              selinux.setfscreatecon_raw(None)
+-      except:
+-              print("Could not reset fs create context. May need to relabel system.", file=sys.stderr)
+ 
+-def disable_module(file, root, name, disabledmodules):
++def disable_module(file, name, disabledmodules):
+       if DEBUG: print("Disabling %s" % name)
+       (disabledname, disabledext) = os.path.splitext(file)
+-      create_file_from(os.path.join(root, name), "%s/%s" % (disabledmodules, disabledname))
++      create_file("%s/%s" % (disabledmodules, disabledname))
+ 
+ def migrate_store(store):
+ 
+@@ -138,17 +100,14 @@ def migrate_store(store):
+       print("Migrating from %s to %s" % (oldstore, newstore))
+ 
+       # Build up new directory structure
+-      create_dir_from(oldstore, "%s/%s" % (newroot_path(), store), 0o755)
+-      create_dir_from(oldstore, newstore, 0o700)
+-      create_dir_from(oldstore, newmodules, 0o700)
+-      create_dir_from(oldstore, bottomdir, 0o700)
+-      create_dir_from(oldstore, disabledmodules, 0o700)
+-
+-      # use whatever the file context of bottomdir is for the module directories
+-      con = selinux.lgetfilecon_raw(bottomdir)[1]
++      create_dir("%s/%s" % (newroot_path(), store), 0o755)
++      create_dir(newstore, 0o700)
++      create_dir(newmodules, 0o700)
++      create_dir(bottomdir, 0o700)
++      create_dir(disabledmodules, 0o700)
+ 
+       # Special case for base since it was in a different location
+-      copy_module(store, "base.pp", con, 1)
++      copy_module(store, "base.pp", 1)
+ 
+       # Dir structure built, start copying files
+       for root, dirs, files in os.walk(oldstore):
+@@ -161,7 +120,7 @@ def migrate_store(store):
+                                               newname = "seusers.local"
+                                       else:
+                                               newname = name
+-                                      copy_with_context(os.path.join(root, name), os.path.join(newstore, newname))
++                                      copy_file(os.path.join(root, name), os.path.join(newstore, newname))
+ 
+               elif root == oldmodules:
+                       # This should be the modules directory
+@@ -171,9 +130,9 @@ def migrate_store(store):
+                                       print("Error installing module %s, name conflicts with base" % name, file=sys.stderr)
+                                       exit(1)
+                               elif ext == ".disabled":
+-                                      disable_module(file, root, name, disabledmodules)
++                                      disable_module(file, name, disabledmodules)
+                               else:
+-                                      copy_module(store, name, con, 0)
++                                      copy_module(store, name, 0)
+ 
+ def rebuild_policy():
+       # Ok, the modules are loaded, lets try to rebuild the policy
+@@ -287,7 +246,7 @@ if __name__ == "__main__":
+               "preserve_tunables" ]
+ 
+ 
+-      create_dir_from(oldroot_path(), newroot_path(), 0o755)
++      create_dir(newroot_path(), 0o755)
+ 
+       stores = None
+       if TYPE is not None:
+-- 
+2.0.5
+
diff --git a/sys-libs/libsemanage/files/0002-semanage_migrate_store-Python3-support.patch b/sys-libs/libsemanage/files/0002-semanage_migrate_store-Python3-support.patch
deleted file mode 100644 (file)
index 40f821a..0000000
+++ /dev/null
@@ -1,284 +0,0 @@
-From 877acdb31ff4261f0fcd03a8fb9ada76703802f3 Mon Sep 17 00:00:00 2001
-From: Jason Zaman <jason@perfinion.com>
-Date: Thu, 20 Nov 2014 00:18:59 +0400
-Subject: [PATCH 2/2] semanage_migrate_store: Python3 support
-
-Mainly used the 2to3 conversion tool. Also added in a __future__
-import so that the script continues to work on Python 2.
-
-Tested on 2.7, 3.3, 3.4. Should work on 2.6 too but untested.
-
-Signed-off-by: Jason Zaman <jason@perfinion.com>
-Acked-by: Steve Lawrence <slawrence@tresys.com>
----
- libsemanage/utils/semanage_migrate_store | 86 +++++++++++++++++---------------
- 1 file changed, 45 insertions(+), 41 deletions(-)
-
-diff --git a/libsemanage/utils/semanage_migrate_store b/libsemanage/utils/semanage_migrate_store
-index cbc4f31..0371e49 100755
---- a/libsemanage/utils/semanage_migrate_store
-+++ b/libsemanage/utils/semanage_migrate_store
-@@ -1,6 +1,7 @@
- #!/usr/bin/python -E
- 
- 
-+from __future__ import print_function
- import os
- import errno
- import shutil
-@@ -16,7 +17,7 @@ try:
-       import selinux
-       import semanage
- except:
--      print >> sys.stderr, "You must install libselinux-python and libsemanage-python before running this tool"
-+      print("You must install libselinux-python and libsemanage-python before running this tool", file=sys.stderr)
-       exit(1)
- 
- 
-@@ -25,100 +26,103 @@ except:
- # For some reason this function doesn't exist in libselinux :\
- def copy_with_context(src, dst):
-       if DEBUG:
--              print "copying %s to %s" % (src, dst)
-+              print("copying %s to %s" % (src, dst))
-       try:
-               con = selinux.lgetfilecon_raw(src)[1]
-       except:
--              print >> sys.stderr, "Could not get file context of %s" % src
-+              print("Could not get file context of %s" % src, file=sys.stderr)
-               exit(1)
- 
-       try:
-               selinux.setfscreatecon_raw(con)
-       except:
--              print >> sys.stderr, "Could not set fs create context: %s" %con
-+              print("Could not set fs create context: %s" %con, file=sys.stderr)
-               exit(1)
- 
-       try:
-               shutil.copy2(src, dst)
--      except OSError as (err, strerr):
--              print >> sys.stderr, "Could not copy %s to %s, %s" %(src, dst, strerr)
-+      except OSError as the_err:
-+              (err, strerr) = the_err.args
-+              print("Could not copy %s to %s, %s" %(src, dst, strerr), file=sys.stderr)
-               exit(1)
- 
-       try:
-               selinux.setfscreatecon_raw(None)
-       except:
--              print >> sys.stderr, "Could not reset fs create context. May need to relabel system."
-+              print("Could not reset fs create context. May need to relabel system.", file=sys.stderr)
- 
- def create_dir_from(src, dst, mode):
--      if DEBUG: print "Making directory %s" % dst
-+      if DEBUG: print("Making directory %s" % dst)
-       try:
-               con = selinux.lgetfilecon_raw(src)[1]
-               selinux.setfscreatecon_raw(con)
-               os.makedirs(dst, mode)
--      except OSError as (err, stderr):
-+      except OSError as the_err:
-+              (err, stderr) = the_err.args
-               if err == errno.EEXIST:
-                       pass
-               else:
--                      print >> sys.stderr, "Error creating %s" % dst
-+                      print("Error creating %s" % dst, file=sys.stderr)
-                       exit(1)
- 
-       try:
-               selinux.setfscreatecon_raw(None)
-       except:
--              print >> sys.stderr, "Could not reset fs create context. May need to relabel system."
-+              print("Could not reset fs create context. May need to relabel system.", file=sys.stderr)
- 
- def create_file_from(src, dst):
--      if DEBUG: print "Making file %s" % dst
-+      if DEBUG: print("Making file %s" % dst)
-       try:
-               con = selinux.lgetfilecon_raw(src)[1]
-               selinux.setfscreatecon_raw(con)
-               open(dst, 'a').close()
--      except OSError as (err, stderr):
--              print >> sys.stderr, "Error creating %s" % dst
-+      except OSError as the_err:
-+              (err, stderr) = the_err.args
-+              print("Error creating %s" % dst, file=sys.stderr)
-               exit(1)
- 
-       try:
-               selinux.setfscreatecon_raw(None)
-       except:
--              print >> sys.stderr, "Could not reset fs create context. May need to relabel system."
-+              print("Could not reset fs create context. May need to relabel system.", file=sys.stderr)
- 
- def copy_module(store, name, con, base):
--      if DEBUG: print "Install module %s" % name      
-+      if DEBUG: print("Install module %s" % name)
-       (file, ext) = os.path.splitext(name)
-       if ext != ".pp":
-               # Stray non-pp file in modules directory, skip
--              print >> sys.stderr, "warning: %s has invalid extension, skipping" % name
-+              print("warning: %s has invalid extension, skipping" % name, file=sys.stderr)
-               return
-       try:
-               selinux.setfscreatecon_raw(con)
--      
-+
-               if base:
-                       root = oldstore_path(store)
-               else:
-                       root = oldmodules_path(store)
- 
-               bottomdir = bottomdir_path(store)
--                      
-+
-               os.mkdir("%s/%s" % (bottomdir, file))
- 
-               copy_with_context(os.path.join(root, name), "%s/%s/hll" % (bottomdir, file))
- 
-               # This is the ext file that will eventually be used to choose a compiler
--              efile = open("%s/%s/lang_ext" % (bottomdir, file), "w+", 0600)
-+              efile = open("%s/%s/lang_ext" % (bottomdir, file), "w+", 0o600)
-               efile.write("pp")
-               efile.close()
- 
-       except:
--              print >> sys.stderr, "Error installing module %s" % name
-+              print("Error installing module %s" % name, file=sys.stderr)
-               exit(1)
- 
-       try:
-               selinux.setfscreatecon_raw(None)
-       except:
--              print >> sys.stderr, "Could not reset fs create context. May need to relabel system."
-+              print("Could not reset fs create context. May need to relabel system.", file=sys.stderr)
- 
- def disable_module(file, root, name, disabledmodules):
--      if DEBUG: print "Disabling %s" % name
-+      if DEBUG: print("Disabling %s" % name)
-       (disabledname, disabledext) = os.path.splitext(file)
-       create_file_from(os.path.join(root, name), "%s/%s" % (disabledmodules, disabledname))
- 
-@@ -131,14 +135,14 @@ def migrate_store(store):
-       newmodules = newmodules_path(store);
-       bottomdir = bottomdir_path(store);
- 
--      print "Migrating from %s to %s" % (oldstore, newstore)
-+      print("Migrating from %s to %s" % (oldstore, newstore))
- 
-       # Build up new directory structure
--      create_dir_from(selinux.selinux_policy_root(), "%s/%s" % (newroot_path(), store), 0755)
--      create_dir_from(oldmodules, newstore, 0700)
--      create_dir_from(oldstore, newmodules, 0700)
--      create_dir_from(oldstore, bottomdir, 0700)
--      create_dir_from(oldstore, disabledmodules, 0700)
-+      create_dir_from(selinux.selinux_policy_root(), "%s/%s" % (newroot_path(), store), 0o755)
-+      create_dir_from(oldmodules, newstore, 0o700)
-+      create_dir_from(oldstore, newmodules, 0o700)
-+      create_dir_from(oldstore, bottomdir, 0o700)
-+      create_dir_from(oldstore, disabledmodules, 0o700)
- 
-       # use whatever the file context of bottomdir is for the module directories
-       con = selinux.lgetfilecon_raw(bottomdir)[1]
-@@ -149,7 +153,7 @@ def migrate_store(store):
-       # Dir structure built, start copying files
-       for root, dirs, files in os.walk(oldstore):
-               if root == oldstore:
--                      # This is the top level directory, need to move 
-+                      # This is the top level directory, need to move
-                       for name in files:
-                               # Check to see if it is in TOPPATHS and copy if so
-                               if name in TOPPATHS:
-@@ -164,7 +168,7 @@ def migrate_store(store):
-                       for name in files:
-                               (file, ext) = os.path.splitext(name)
-                               if name == "base.pp":
--                                      print >> sys.stderr, "Error installing module %s, name conflicts with base" % name
-+                                      print("Error installing module %s, name conflicts with base" % name, file=sys.stderr)
-                                       exit(1)
-                               elif ext == ".disabled":
-                                       disable_module(file, root, name, disabledmodules)
-@@ -173,32 +177,32 @@ def migrate_store(store):
- 
- def rebuild_policy():
-       # Ok, the modules are loaded, lets try to rebuild the policy
--      print "Attempting to rebuild policy from %s" % newroot_path()
-+      print("Attempting to rebuild policy from %s" % newroot_path())
- 
-       curstore = selinux.selinux_getpolicytype()[1]
- 
-       handle = semanage.semanage_handle_create()
-       if not handle:
--              print >> sys.stderr, "Could not create semanage handle"
-+              print("Could not create semanage handle", file=sys.stderr)
-               exit(1)
- 
-       semanage.semanage_select_store(handle, curstore, semanage.SEMANAGE_CON_DIRECT)
- 
-       if not semanage.semanage_is_managed(handle):
-               semanage.semanage_handle_destroy(handle)
--              print >> sys.stderr, "SELinux policy is not managed or store cannot be accessed."
-+              print("SELinux policy is not managed or store cannot be accessed.", file=sys.stderr)
-               exit(1)
- 
-       rc = semanage.semanage_access_check(handle)
-       if rc < semanage.SEMANAGE_CAN_WRITE:
-               semanage.semanage_handle_destroy(handle)
--              print >> sys.stderr, "Cannot write to policy store."
-+              print("Cannot write to policy store.", file=sys.stderr)
-               exit(1)
- 
-       rc = semanage.semanage_connect(handle)
-       if rc < 0:
-               semanage.semanage_handle_destroy(handle)
--              print >> sys.stderr, "Could not establish semanage connection"
-+              print("Could not establish semanage connection", file=sys.stderr)
-               exit(1)
- 
-       semanage.semanage_set_rebuild(handle, 1)
-@@ -206,12 +210,12 @@ def rebuild_policy():
-       rc = semanage.semanage_begin_transaction(handle)
-       if rc < 0:
-               semanage.semanage_handle_destroy(handle)
--              print >> sys.stderr, "Could not begin transaction"
-+              print("Could not begin transaction", file=sys.stderr)
-               exit(1)
- 
-       rc = semanage.semanage_commit(handle)
-       if rc < 0:
--              print >> sys.stderr, "Could not commit transaction"
-+              print("Could not commit transaction", file=sys.stderr)
- 
-       semanage.semanage_handle_destroy(handle)
- 
-@@ -283,7 +287,7 @@ if __name__ == "__main__":
-               "preserve_tunables" ]
- 
- 
--      create_dir_from(oldroot_path(), newroot_path(), 0755)
-+      create_dir_from(oldroot_path(), newroot_path(), 0o755)
- 
-       stores = None
-       if TYPE is not None:
-@@ -299,14 +303,14 @@ if __name__ == "__main__":
- 
-               if os.path.isdir(newstore_path(store)):
-                       # store has already been migrated, but old modules dir still exits
--                      print >> sys.stderr, "warning: Policy type %s has already been migrated, but modules still exist in the old store. Skipping store." % store
-+                      print("warning: Policy type %s has already been migrated, but modules still exist in the old store. Skipping store." % store, file=sys.stderr)
-                       continue
- 
-               migrate_store(store)
- 
-               if CLEAN is True:
-                       def remove_error(function, path, execinfo):
--                              print >> sys.stderr, "warning: Unable to remove old store modules directory %s. Cleaning failed." % oldmodules_path(store)
-+                              print("warning: Unable to remove old store modules directory %s. Cleaning failed." % oldmodules_path(store), file=sys.stderr)
-                       shutil.rmtree(oldmodules_path(store), onerror=remove_error)
- 
-       if NOREBUILD is False:
--- 
-2.0.4
-
diff --git a/sys-libs/libsemanage/libsemanage-2.4-r1.ebuild b/sys-libs/libsemanage/libsemanage-2.4-r1.ebuild
new file mode 100644 (file)
index 0000000..d3b3bf3
--- /dev/null
@@ -0,0 +1,127 @@
+# Copyright 1999-2015 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sys-libs/libsemanage/libsemanage-2.4-r1.ebuild,v 1.1 2015/04/23 13:14:18 perfinion Exp $
+
+EAPI="5"
+PYTHON_COMPAT=( python2_7 python3_3 python3_4 )
+
+inherit multilib python-r1 toolchain-funcs eutils multilib-minimal
+
+MY_P="${P//_/-}"
+
+SEPOL_VER="${PV}"
+SELNX_VER="${PV}"
+
+DESCRIPTION="SELinux kernel and policy management library"
+HOMEPAGE="https://github.com/SELinuxProject/selinux/wiki"
+SRC_URI="https://raw.githubusercontent.com/wiki/SELinuxProject/selinux/files/releases/20150202/${MY_P}.tar.gz"
+
+LICENSE="GPL-2"
+SLOT="0"
+KEYWORDS="~amd64 ~x86"
+IUSE="python"
+
+RDEPEND=">=sys-libs/libsepol-${SEPOL_VER}[${MULTILIB_USEDEP}]
+       >=sys-libs/libselinux-${SELNX_VER}[${MULTILIB_USEDEP}]
+       >=sys-process/audit-2.2.2[${MULTILIB_USEDEP}]
+       >=dev-libs/ustr-1.0.4-r2[${MULTILIB_USEDEP}]
+       "
+DEPEND="${RDEPEND}
+       sys-devel/bison
+       sys-devel/flex
+       python? (
+               >=dev-lang/swig-2.0.4-r1
+               virtual/pkgconfig
+               ${PYTHON_DEPS}
+       )"
+
+# tests are not meant to be run outside of the
+# full SELinux userland repo
+RESTRICT="test"
+
+S="${WORKDIR}/${MY_P}"
+
+src_prepare() {
+       echo "# Set this to true to save the linked policy." >> "${S}/src/semanage.conf"
+       echo "# This is normally only useful for analysis" >> "${S}/src/semanage.conf"
+       echo "# or debugging of policy." >> "${S}/src/semanage.conf"
+       echo "save-linked=false" >> "${S}/src/semanage.conf"
+       echo >> "${S}/src/semanage.conf"
+       echo "# Set this to 0 to disable assertion checking." >> "${S}/src/semanage.conf"
+       echo "# This should speed up building the kernel policy" >> "${S}/src/semanage.conf"
+       echo "# from policy modules, but may leave you open to" >> "${S}/src/semanage.conf"
+       echo "# dangerous rules which assertion checking" >> "${S}/src/semanage.conf"
+       echo "# would catch." >> "${S}/src/semanage.conf"
+       echo "expand-check=1" >> "${S}/src/semanage.conf"
+       echo >> "${S}/src/semanage.conf"
+       echo "# Modules in the module store can be compressed" >> "${S}/src/semanage.conf"
+       echo "# with bzip2.  Set this to the bzip2 blocksize" >> "${S}/src/semanage.conf"
+       echo "# 1-9 when compressing.  The higher the number," >> "${S}/src/semanage.conf"
+       echo "# the more memory is traded off for disk space." >> "${S}/src/semanage.conf"
+       echo "# Set to 0 to disable bzip2 compression." >> "${S}/src/semanage.conf"
+       echo "bzip-blocksize=0" >> "${S}/src/semanage.conf"
+       echo >> "${S}/src/semanage.conf"
+       echo "# Reduce memory usage for bzip2 compression and" >> "${S}/src/semanage.conf"
+       echo "# decompression of modules in the module store." >> "${S}/src/semanage.conf"
+       echo "bzip-small=true" >> "${S}/src/semanage.conf"
+
+       epatch "${FILESDIR}/0001-libsemanage-do-not-copy-contexts-in-semanage_migrate.patch"
+
+       epatch_user
+
+       multilib_copy_sources
+}
+
+multilib_src_compile() {
+       emake \
+               AR="$(tc-getAR)" \
+               CC="$(tc-getCC)" \
+               LIBDIR="${EPREFIX}/usr/$(get_libdir)" \
+               all
+
+       if multilib_is_native_abi && use python; then
+               building_py() {
+                       python_export PYTHON_INCLUDEDIR PYTHON_LIBPATH
+                       emake CC="$(tc-getCC)" PYINC="-I${PYTHON_INCLUDEDIR}" PYTHONLBIDIR="${PYTHON_LIBPATH}" PYPREFIX="${EPYTHON##*/}" "$@"
+               }
+               python_foreach_impl building_py swigify
+               python_foreach_impl building_py pywrap
+       fi
+}
+
+multilib_src_install() {
+       emake \
+               LIBDIR="${ED}/usr/$(get_libdir)" \
+               SHLIBDIR="${ED}/usr/$(get_libdir)" \
+               DESTDIR="${ED}" install
+
+       if multilib_is_native_abi && use python; then
+               installation_py() {
+                       emake DESTDIR="${ED}" LIBDIR="${ED}/usr/$(get_libdir)" \
+                               SHLIBDIR="${ED}/usr/$(get_libdir)" install-pywrap
+                       python_optimize # bug 531638
+               }
+               python_foreach_impl installation_py
+       fi
+}
+
+pkg_postinst() {
+       # Migrate the SELinux semanage configuration store if not done already
+       local selinuxtype=$(awk -F'=' '/SELINUXTYPE=/ {print $2}' /etc/selinux/config);
+       if [ -n "${selinuxtype}" ] && [ ! -d /var/lib/selinux/${mcs}/active ] ; then
+               ewarn "Since the 2.4 SELinux userspace, the policy module store is moved"
+               ewarn "from /etc/selinux to /var/lib/selinux. The migration will be run now."
+               ewarn "If there are any issues, it can be done manually by running:"
+               ewarn "/usr/libexec/selinux/semanage_migrate_store"
+               ewarn "For more information, please see"
+               ewarn "- https://github.com/SELinuxProject/selinux/wiki/Policy-Store-Migration"
+       fi
+
+       # Run the store migration without rebuilds
+       for POLICY_TYPE in ${POLICY_TYPES} ; do
+               if [ ! -d "${ROOT}/var/lib/selinux/${POLICY_TYPE}/active" ] ; then
+                       einfo "Migrating store ${POLICY_TYPE} (without policy rebuild)."
+                       /usr/libexec/selinux/semanage_migrate_store -n -s "${POLICY_TYPE}" || die "Failed to migrate store ${POLICY_TYPE}"
+               fi
+       done
+}