From: Fabian Groffen Date: Fri, 28 Dec 2007 13:39:30 +0000 (-0000) Subject: Merged from trunk 9058:9062 X-Git-Url: http://git.tremily.us/gitweb.cgi?a=commitdiff_plain;h=20e38def7734ed78f037611d756eeadfa86d3e4d;p=portage.git Merged from trunk 9058:9062 | 9059 | Bug #201498 - Use desktop-file-validate to validate | | zmedico | *.desktop files inside ${FILESDIR} and generate a | | | "desktop.invalid" qa warning if an error is detected. Thanks | | | to Betelgeuse for the initial patch. | | 9060 | Minor code readablity enhancements: * Use relative_path and | | zmedico | full_path variables for files being checked instead of | | | spreading code like x+"/files/"+y all over the place. * Use | | | stat.S_IMODE with octal 0111 instead of hex 0x0248 in the | | | file.executable checks. | | 9061 | Bug #203323 - Fix the FEATURES=sfperms code so that it | | zmedico | doesn't chmod g-r on binaries that are both setuid and | | | setgid. In that case, just chmod o-r. | | 9062 | Always make sure that the depend phase triggers a source | | zmedico | ${EBUILD} call, even if "${T}"/environment happens to exist | | | for some reason. | svn path=/main/branches/prefix/; revision=9063 --- diff --git a/bin/ebuild.sh b/bin/ebuild.sh index c955a8a55..b38db01dd 100755 --- a/bin/ebuild.sh +++ b/bin/ebuild.sh @@ -1658,7 +1658,11 @@ if ! hasq ${EBUILD_PHASE} clean depend && \ fi if ! hasq ${EBUILD_PHASE} clean && \ - ( [ ! -f "${T}"/environment ] || hasq noauto ${FEATURES} ) ; then + ( + hasq ${EBUILD_PHASE} depend || \ + [ ! -f "${T}"/environment ] || \ + hasq noauto ${FEATURES} + ) ; then # The bashrcs get an opportunity here to set aliases that will be expanded # during sourcing of ebuilds and eclasses. source_all_bashrcs diff --git a/bin/misc-functions.sh b/bin/misc-functions.sh index b4220ce07..74387bc93 100644 --- a/bin/misc-functions.sh +++ b/bin/misc-functions.sh @@ -511,17 +511,30 @@ preinst_sfperms() { fi # Smart FileSystem Permissions if hasq sfperms $FEATURES; then + local i #note not space-safe for i in $(find "${ED}" -type f -perm -4000); do - ebegin ">>> SetUID: [chmod go-r] $i " - chmod go-r "$i" - eend $? + if [ -n "$(find "$i" -perm -2000)" ] ; then + ebegin ">>> SetUID and SetGID: [chmod o-r] /${i#${D}}" + chmod o-r "$i" + eend $? + else + ebegin ">>> SetUID: [chmod go-r] /${i#${D}}" + chmod go-r "$i" + eend $? + fi done #note not space-safe for i in $(find "${ED}" -type f -perm -2000); do - ebegin ">>> SetGID: [chmod o-r] $i " - chmod o-r "$i" - eend $? + if [ -n "$(find "$i" -perm -4000)" ] ; then + # This case is already handled + # by the SetUID check above. + true + else + ebegin ">>> SetGID: [chmod o-r] /${i#${D}}" + chmod o-r "$i" + eend $? + fi done fi } diff --git a/bin/repoman b/bin/repoman index 7396b3b6a..6dd8ec2f2 100755 --- a/bin/repoman +++ b/bin/repoman @@ -8,6 +8,7 @@ # that last one is tricky because multiple profiles need to be checked. import codecs +import commands import errno import formatter import logging @@ -233,6 +234,7 @@ def ParseArgs(args, qahelp): qahelp={ "CVS/Entries.IO_error":"Attempting to commit, and an IO error was encountered access the Entries file", + "desktop.invalid":"desktop-file-validate reports errors in a *.desktop file", "digest.partial":"Digest files do not contain all corresponding URI elements", "digest.assumed":"Existing digest must be assumed correct (Package level only)", "digestentry.unused":"Digest/Manifest entry has no matching SRC_URI entry", @@ -310,6 +312,7 @@ qawarnings=[ "ebuild.nostable", "ebuild.allmasked", "ebuild.nesteddie", +"desktop.invalid", "digest.assumed", "digest.missing", "digestentry.unused", @@ -796,6 +799,10 @@ else: stats={} fails={} +# provided by the desktop-file-utils package +desktop_file_validate = find_binary("desktop-file-validate") +desktop_pattern = re.compile(r'.*\.desktop$') + for x in qacats: stats[x]=0 fails[x]=[] @@ -1152,9 +1159,11 @@ for x in scanlist: for y in filesdirlist: if not y.startswith("digest-"): continue - if os.stat(checkdir+"/files/"+y)[0] & 0x0248: + relative_path = os.path.join(x, "files", y) + full_path = os.path.join(repodir, relative_path) + if stat.S_IMODE(os.stat(full_path).st_mode) & 0111: stats["file.executable"] += 1 - fails["file.executable"].append(x+"/files/"+y) + fails["file.executable"].append(relative_path) mykey = catdir + "/" + y[7:] if y[7:] not in ebuildlist: @@ -1216,8 +1225,10 @@ for x in scanlist: # use filesdirlist as a stack, appending directories as needed so people can't hide > 20k files in a subdirectory. while filesdirlist: y = filesdirlist.pop(0) + relative_path = os.path.join(x, "files", y) + full_path = os.path.join(repodir, relative_path) try: - mystat = os.stat(checkdir+"/files/"+y) + mystat = os.stat(full_path) except OSError, oe: if oe.errno == 2: # don't worry about it. it likely was removed via fix above. @@ -1242,6 +1253,23 @@ for x in scanlist: fails["file.name"].append("%s/files/%s: char '%s'" % (checkdir, y, c)) break + if desktop_file_validate and desktop_pattern.match(y): + status, cmd_output = commands.getstatusoutput( + "'%s' '%s'" % (desktop_file_validate, full_path)) + if os.WIFEXITED(status) and os.WEXITSTATUS(status) != os.EX_OK: + # Note: in the future we may want to grab the + # warnings in addition to the errors. We're + # just doing errors now since we don't want + # to generate too much noise at first. + error_re = re.compile(r'.*\s*error:\s*(.*)') + for line in cmd_output.splitlines(): + error_match = error_re.match(line) + if error_match is None: + continue + stats["desktop.invalid"] += 1 + fails["desktop.invalid"].append( + relative_path + ': %s' % error_match.group(1)) + del mydigests if "ChangeLog" not in checkdirlist: @@ -1271,9 +1299,11 @@ for x in scanlist: allmasked = True for y in ebuildlist: - if os.stat(checkdir+"/"+y+".ebuild")[0] & 0x0248: + relative_path = os.path.join(x, y + ".ebuild") + full_path = os.path.join(repodir, relative_path) + if stat.S_IMODE(os.stat(full_path).st_mode) & 0111: stats["file.executable"] += 1 - fails["file.executable"].append(x+"/"+y+".ebuild") + fails["file.executable"].append(relative_path) if (isCvs or isSvn) and y not in eadded: #ebuild not added to cvs stats["ebuild.notadded"]=stats["ebuild.notadded"]+1 @@ -1553,8 +1583,6 @@ for x in scanlist: for mybad in mybadrestrict: fails["RESTRICT.invalid"].append(x+"/"+y+".ebuild: %s" % mybad) # Syntax Checks - relative_path = os.path.join(x, y + ".ebuild") - full_path = os.path.join(repodir, relative_path) f = open(full_path, 'rb') try: for check_name, e in run_checks(f, os.stat(full_path).st_mtime):