net-libs/nodejs: Fix build on PAX enable kernel (bug 694100)
authorMagnus Granberg <zorry@gentoo.org>
Wed, 27 Nov 2019 21:28:02 +0000 (22:28 +0100)
committerMagnus Granberg <zorry@gentoo.org>
Wed, 27 Nov 2019 21:29:14 +0000 (22:29 +0100)
We need to disable mprotect on two bins when we compile
bug 694100.

Closes: https://bugs.gentoo.org/694100
Reported-by: Attila Tóth <atoth@atoth.sote.hu>
Co-developed-by: Attila Tóth <atoth@atoth.sote.hu>
Signed-off-by: Magnus Granberg <zorry@gentoo.org>
Package-Manager: Portage-2.3.76, Repoman-2.3.16

net-libs/nodejs/files/nodejs-13.2.0-paxmarking.patch [new file with mode: 0644]
net-libs/nodejs/metadata.xml
net-libs/nodejs/nodejs-13.2.0.ebuild
net-libs/nodejs/nodejs-99999999.ebuild

diff --git a/net-libs/nodejs/files/nodejs-13.2.0-paxmarking.patch b/net-libs/nodejs/files/nodejs-13.2.0-paxmarking.patch
new file mode 100644 (file)
index 0000000..143e416
--- /dev/null
@@ -0,0 +1,71 @@
+    Bug: 694100
+    Add actions for pax marking mkcodecache and node_mksnapshot
+    to disable mprotect for pax enable kernel.
+    Reported-by: Attila Tóth <atoth@atoth.sote.hu>
+    Co-developed-by: Attila Tóth <atoth@atoth.sote.hu>
+    Signed-off-by: Magnus Granberg <zorry@gentoo.org>
+    
+--- a/node.gyp 2019-10-23 11:52:41.000000000 +0200
++++ a/node.gyp 2019-11-12 20:58:43.957881862 +0100
+@@ -233,7 +233,9 @@
+       'deps/acorn-plugins/acorn-static-class-features/index.js',
+     ],
+     'node_mksnapshot_exec': '<(PRODUCT_DIR)/<(EXECUTABLE_PREFIX)node_mksnapshot<(EXECUTABLE_SUFFIX)',
++    'node_mksnapshot_u_exec': '<(PRODUCT_DIR)/<(EXECUTABLE_PREFIX)node_mksnapshot_u<(EXECUTABLE_SUFFIX)',
+     'mkcodecache_exec': '<(PRODUCT_DIR)/<(EXECUTABLE_PREFIX)mkcodecache<(EXECUTABLE_SUFFIX)',
++    'mkcodecache_u_exec': '<(PRODUCT_DIR)/<(EXECUTABLE_PREFIX)mkcodecache_u<(EXECUTABLE_SUFFIX)',
+     'conditions': [
+       [ 'node_shared=="true"', {
+         'node_target_type%': 'shared_library',
+@@ -436,10 +438,24 @@
+           ],
+           'actions': [
+             {
++              'action_name': 'run_pax_mkcodecache',
++              'inputs': [
++                '<(mkcodecache_exec)',
++              ],
++              'outputs': [
++                '<(mkcodecache_u_exec)',
++              ],
++              'action': [
++                'bash',
++                '-c',
++                'mv <(mkcodecache_exec) <(mkcodecache_u_exec) && paxmark.sh m <(mkcodecache_u_exec)',
++              ],
++            },
++            {
+               'action_name': 'run_mkcodecache',
+               'process_outputs_as_sources': 1,
+               'inputs': [
+-                '<(mkcodecache_exec)',
++                '<(mkcodecache_u_exec)',
+               ],
+               'outputs': [
+                 '<(SHARED_INTERMEDIATE_DIR)/node_code_cache.cc',
+@@ -461,10 +477,24 @@
+           ],
+           'actions': [
+             {
++              'action_name': 'run_pax_mksnapshot',
++              'inputs': [
++                '<(node_mksnapshot_exec)',
++              ],
++              'outputs': [
++                '<(node_mksnapshot_u_exec)',
++              ],
++              'action': [
++                'bash',
++                '-c',
++                'mv <(node_mksnapshot_exec) <(node_mksnapshot_u_exec) && paxmark.sh m <(node_mksnapshot_u_exec)',
++              ],
++            },
++            {
+               'action_name': 'node_mksnapshot',
+               'process_outputs_as_sources': 1,
+               'inputs': [
+-                '<(node_mksnapshot_exec)',
++                '<(node_mksnapshot_u_exec)',
+               ],
+               'outputs': [
+                 '<(SHARED_INTERMEDIATE_DIR)/node_snapshot.cc',
index aaaba184187b286d48b18cd356a78fe4ec6322b9..3f344f0d8eda51ae9f8597911c9b1dce2094ef2a 100644 (file)
@@ -7,6 +7,7 @@
        <use>
                <flag name="inspector">Enable V8 inspector</flag>
                <flag name="npm">Enable NPM package manager</flag>
+               <flag name="pax_kernel">Enable building under a PaX enabled kernel</flag>
                <flag name="snapshot">Enable snapshot creation for faster startup</flag>
                <flag name="systemtap">Enable SystemTAP/DTrace tracing</flag>
        </use>
index 56bbeb5526f4e3db83adf5cece7219114cc0d612..8013ab7c39ae61c9d45fa6be472dfa5ee690d955 100644 (file)
@@ -15,7 +15,7 @@ SRC_URI="
 LICENSE="Apache-1.1 Apache-2.0 BSD BSD-2 MIT"
 SLOT="0"
 KEYWORDS="~amd64 ~arm ~arm64 ~ppc ~ppc64 ~x86 ~amd64-linux ~x64-macos"
-IUSE="cpu_flags_x86_sse2 debug doc icu inspector +npm +snapshot +ssl systemtap test"
+IUSE="cpu_flags_x86_sse2 debug doc icu inspector +npm pax_kernel +snapshot +ssl systemtap test"
 REQUIRED_USE="
        inspector? ( icu ssl )
        npm? ( ssl )
@@ -33,6 +33,7 @@ BDEPEND="
        ${PYTHON_DEPS}
        systemtap? ( dev-util/systemtap )
        test? ( net-misc/curl )
+       pax_kernel? ( sys-apps/elfix )
 "
 DEPEND="
        ${RDEPEND}
@@ -86,6 +87,9 @@ src_prepare() {
                BUILDTYPE=Debug
        fi
 
+       # We need to disable mprotect on two files when it builds Bug 694100.
+       use pax_kernel && PATCHES+=( "${FILESDIR}"/${PN}-13.2.0-paxmarking.patch )
+
        default
 }
 
@@ -124,8 +128,6 @@ src_configure() {
 }
 
 src_compile() {
-       emake -C out mksnapshot
-       pax-mark m "out/${BUILDTYPE}/mksnapshot"
        emake -C out
 }
 
index e36828c990ad5011a9030b821d35f8399b4491ca..96dcccf3770e763b4c16a7103ab3e9fa1a364af0 100644 (file)
@@ -13,7 +13,7 @@ EGIT_REPO_URI="https://github.com/nodejs/node"
 LICENSE="Apache-1.1 Apache-2.0 BSD BSD-2 MIT"
 SLOT="0"
 KEYWORDS=""
-IUSE="cpu_flags_x86_sse2 debug doc icu inspector +npm +snapshot +ssl systemtap test"
+IUSE="cpu_flags_x86_sse2 debug doc icu inspector +npm pax_kernel +snapshot +ssl systemtap test"
 REQUIRED_USE="
        inspector? ( icu ssl )
        npm? ( ssl )
@@ -31,6 +31,7 @@ BDEPEND="
        ${PYTHON_DEPS}
        systemtap? ( dev-util/systemtap )
        test? ( net-misc/curl )
+       pax_kernel? ( sys-apps/elfix )
 "
 DEPEND="
        ${RDEPEND}
@@ -82,6 +83,9 @@ src_prepare() {
                BUILDTYPE=Debug
        fi
 
+       # We need to disable mprotect on two files when it builds Bug 694100.
+       use pax_kernel && PATCHES+=( "${FILESDIR}"/${PN}-13.2.0-paxmarking.patch )
+
        default
 }
 
@@ -120,8 +124,6 @@ src_configure() {
 }
 
 src_compile() {
-       emake -C out mksnapshot
-       pax-mark m "out/${BUILDTYPE}/mksnapshot"
        emake -C out
 }