diff --git a/patches/pkgbuild/gpgme.sh b/patches/pkgbuild/gpgme.sh new file mode 100755 index 0000000..b3510f2 --- /dev/null +++ b/patches/pkgbuild/gpgme.sh @@ -0,0 +1,35 @@ +#!/usr/bin/env bash +# gpgme: do not build the gpg test harness. +# +# make[3]: Entering directory '.../gpgme/tests/gpg' +# gpgconf: error running '/usr/bin/gpg-connect-agent': exit status 1 +# gpgconf: error running '/usr/bin/gpg-connect-agent KILLDIRMNGR': General error +# +# This is not check() -- EL_NOCHECK skips that. gpgme's `make all` descends into +# tests/gpg and SETS UP a throwaway GNUPGHOME, which means starting an agent. +# Inside the chroot there is no dbus, no session and no tty, so the agent cannot +# come up and the setup fails while merely building. +# +# --disable-gpg-test is gpgme's own switch, and the PKGBUILD already passes its +# sibling --disable-gpgsm-test for the same kind of reason. This is the third +# time this port has found that "no tests" and "no test harness" are different +# requests: skipping check() does not stop `make all` from building what check() +# would have run. +set -euo pipefail +python3 - <<'ZZPY' +import io, re +lines = io.open("PKGBUILD", encoding="utf-8").read().split("\n") +hit = [i for i, l in enumerate(lines) if re.match(r"^[ \t]*--disable-gpgsm-test", l)] +assert len(hit) == 1, "gpgme: expected one --disable-gpgsm-test, got %d" % len(hit) +i = hit[0] +ind = re.match(r"^[ \t]*", lines[i]).group(0) +cont = lines[i].rstrip().endswith("\\") +# Insert BEFORE, so the continuation state of the last option is untouched -- +# adding a line after a final option that has no backslash would end the command. +lines.insert(i, ind + "--disable-gpg-test \\") +io.open("PKGBUILD", "w", encoding="utf-8").write("\n".join(lines)) +ZZPY +grep -q -- "--disable-gpg-test" PKGBUILD || { echo "gpgme: the flag was not added" >&2; exit 1; } +grep -B1 -- "--disable-gpgsm-test" PKGBUILD | grep -q -- "--disable-gpg-test" || { + echo "gpgme: the flag is not adjacent to its sibling" >&2; exit 1; } +echo "gpgme: gpg test harness not built" diff --git a/patches/pkgbuild/groff.sh b/patches/pkgbuild/groff.sh new file mode 100755 index 0000000..48dd0cb --- /dev/null +++ b/patches/pkgbuild/groff.sh @@ -0,0 +1,47 @@ +#!/usr/bin/env bash +# groff: one decorative figure, and no netpbm to draw it. +# +# program 'xpmtoppm' is missing; can't generate doc/gnu.eps +# make[2]: *** [Makefile:19801: doc/gnu.eps] Error 1 +# +# xpmtoppm belongs to netpbm. What it produces is the GNU logo, as EPS, for +# groff's own manual -- and getting it would mean packaging netpbm and the image +# libraries under it (libjpeg-turbo, libpng, libtiff, jbigkit), none of which +# anything else in this bootstrap wants. +# +# NO CONFIGURE SWITCH EXISTS: groff's configure has neither --without-doc nor +# --disable-doc, so there was nothing to turn off. Adding an invented flag would +# have been worse than useless -- autoconf merely warns about options it does not +# know, the build would have failed identically, and the hook's own check would +# have passed. +# +# The Makefile is generated, so it is edited after configure and before make. The +# variable is emptied rather than the rule patched, because the INSTALL side is +# already tolerant: +# +# if test -f "$$d/gnu.eps"; then ... fi +# +# so with nothing built, nothing is installed and nothing complains. One line, +# and the only one whose absence the rest of the Makefile already handles. +set -euo pipefail +python3 - <<'ZZPY' +import io, re +lines = io.open("PKGBUILD", encoding="utf-8").read().split("\n") +mk = [i for i, l in enumerate(lines) if re.match(r"^[ \t]*make[ \t]*$", l)] +assert len(mk) >= 1, "groff: no bare `make` line found in build()" +i = mk[0] +ind = re.match(r"^[ \t]*", lines[i]).group(0) +lines[i:i] = [ + ind + "# doc/gnu.eps needs xpmtoppm from netpbm, which this port does not", + ind + "# package. The install side already skips the file when it is absent.", + ind + 'sed -i "s|^DOC_GNU_EPS = doc/gnu.eps$|DOC_GNU_EPS =|" Makefile', + ind + 'grep -q "^DOC_GNU_EPS =$" Makefile', +] +io.open("PKGBUILD", "w", encoding="utf-8").write("\n".join(lines)) +ZZPY +grep -q "DOC_GNU_EPS" PKGBUILD || { echo "groff: the figure was not dropped" >&2; exit 1; } +# The grep inside build() is the real check: it runs against the generated +# Makefile and fails the build if the variable was not what this hook expects. +grep -q 'grep -q "\^DOC_GNU_EPS =\$" Makefile' PKGBUILD || { + echo "groff: the in-build verification is missing" >&2; exit 1; } +echo "groff: GNU logo figure dropped (no netpbm)" diff --git a/patches/pkgbuild/systemd.sh b/patches/pkgbuild/systemd.sh index 3556c0e..eb097f6 100755 --- a/patches/pkgbuild/systemd.sh +++ b/patches/pkgbuild/systemd.sh @@ -263,3 +263,26 @@ ZZPY grep -q -- "-Dbpf-framework=disabled" PKGBUILD || { echo "systemd: bpf-framework was not disabled" >&2; exit 1; } echo "systemd: BPF framework disabled (no libbpf, no clang)" + +# --- no AppArmor --------------------------------------------------------------- +# +# meson.build:1098:14: ERROR: Dependency "libapparmor" not found (tried pkgconfig) +# +# The second dependency systemd asked for that this port does not package, after +# libbpf. AppArmor is a Debian/Ubuntu security module; Arch ships it but nothing +# in this bootstrap uses it, and systemd's support for it is a set of unit +# directives (AppArmorProfile=) rather than anything the system needs to boot. +# +# -Dapparmor=disabled is systemd's own switch. Revisit if the target ever runs +# an AppArmor policy. +set -euo pipefail +python3 - <<'ZZPY' +import io +s = io.open("PKGBUILD", encoding="utf-8").read() +old = "-Dapparmor=enabled" +assert s.count(old) == 1, "systemd: expected one apparmor option, got %d" % s.count(old) +s = s.replace(old, "-Dapparmor=disabled", 1) +io.open("PKGBUILD", "w", encoding="utf-8").write(s) +ZZPY +grep -q -- "-Dapparmor=disabled" PKGBUILD || { echo "systemd: apparmor not disabled" >&2; exit 1; } +echo "systemd: AppArmor disabled"