archlinux-s390x/patches/pkgbuild/pinentry.sh
Mathieu Benoit 09ef26798a [FIX] the build host answered questions the target should
Five packages, one shape: a default computed from this machine rather than
from Arch, and arch-meson's --auto-features enabled turning what was optional
into a requirement.

dbus taught the method. It stopped three times in a row on a different
documentation tool -- ducktype, then yelp-build, then qhelpgenerator. The
first two were installed. The third needs Qt, so the chain had no end. All
three are `auto` features promoted to mandatory; pinned off, they cost
nothing. A single missing library is a host dependency. A queue of them is a
feature that should be disabled.

pinentry wanted Qt6 for a passphrase prompt; tty and curses remain.
krb5 asked for a system ss library Ubuntu ships no headers for, and said
"cannot run test program" instead of saying so.
sqlite found tcl, then installed into share/tcltk because Ubuntu's
tclConfig.sh says so and Arch's says lib.
gettext linked the host's libselinux, silently -- the sixth package to do it,
and the first the audit caught rather than a build.

--- FR ---

Cinq paquets, une seule forme : une valeur par défaut calculée depuis cette
machine plutôt que depuis Arch, et le --auto-features enabled d'arch-meson qui
transforme l'optionnel en exigence.

dbus a enseigné la méthode. Il s'est arrêté trois fois de suite sur un outil
de documentation différent — ducktype, puis yelp-build, puis qhelpgenerator.
Les deux premiers ont été installés. Le troisième exige Qt : la chaîne ne
terminait nulle part. Les trois sont des features `auto` promues en
obligations ; épinglées à disabled, elles ne coûtent rien. Une bibliothèque
manquante est une dépendance hôte. Une file d'attente en est une
fonctionnalité à désactiver.

pinentry réclamait Qt6 pour une invite de mot de passe ; tty et curses
suffisent.
krb5 demandait une bibliothèque ss système dont Ubuntu ne livre aucun
en-tête, et annonçait « cannot run test program » plutôt que de le dire.
sqlite trouvait tcl, puis installait dans share/tcltk parce que le
tclConfig.sh d'Ubuntu le dit là où celui d'Arch dit lib.
gettext liait le libselinux de l'hôte, en silence — sixième paquet à le
faire, et le premier que l'audit a pris plutôt qu'une compilation.

Assisted-by: Claude Opus 5
2026-08-19 05:28:32 -04:00

84 lines
4.1 KiB
Bash
Executable file

#!/usr/bin/env bash
# pinentry: three graphical front ends, on a machine with no display stack.
#
# configure: error:
# ***
# *** Qt6 (Qt6Core, Qt6Gui, Qt6Widgets) is required.
# ***
#
# Arch builds every front end pinentry has -- tty, curses, emacs, gnome3 and
# qt -- and declares qt6-base, gcr, kguiaddons and kwindowsystem as
# makedepends. None of that exists on this build host, and none of it belongs
# in a bootstrap: pacman needs a passphrase prompt on a terminal, nothing more.
#
# THE HONEST FRAMING. This is not architectural -- Qt runs on s390x perfectly
# well. It is deferred, and TODO.md says so: a desktop on Z would want these
# back, and the way back is to build qt6-base and the KDE pieces first. What
# is not defensible is dragging a GUI toolkit into the closure of a package
# manager's passphrase prompt.
#
# THE SECOND PLACE, and then a THIRD. libsecret and glib2 are in the top-level
# depends= and exist only to serve the front ends being switched off. --nodeps
# means makepkg never checks them, so leaving them would ship a pinentry that
# cannot install -- the same trap as gcc-libs/libhwasan, make/guile and
# gnutls/leancrypto.
#
# The third place is package(), which APPENDS more:
#
# depends+=( libglib-2.0.so libncursesw.so libsecret-1.so )
#
# The first version of this hook fixed the array at the top of the file, ran
# its guard against that array, passed, and shipped the append untouched. The
# guard checked the place I was thinking about rather than every place the
# name occurs -- which is exactly the mistake the note above warns against.
# Only libncursesw.so survives; the other two name libraries this build no
# longer links.
#
# tty, curses and fallback-curses stay, and so does emacs: it is a protocol
# over a pipe, not a toolkit, and it links nothing extra.
set -euo pipefail
python3 - <<'PY'
import io
s = io.open("PKGBUILD", encoding="utf-8").read()
for flag in ("--enable-pinentry-gnome3", "--enable-pinentry-qt", "--enable-libsecret"):
off = flag.replace("--enable-", "--disable-", 1)
assert s.count(flag) == 1, "pinentry: expected exactly one %s" % flag
s = s.replace(flag, off, 1)
old = " 'glibc' 'ncurses' 'libassuan' 'libsecret' 'glib2'\n"
assert s.count(old) == 1, "pinentry: depends block not in the expected form"
s = s.replace(old, " 'glibc' 'ncurses' 'libassuan'\n", 1)
# package() appends three sonames; two of them are gone with the front ends.
old = " depends+=(\n libglib-2.0.so\n libncursesw.so\n libsecret-1.so\n )\n"
assert s.count(old) == 1, "pinentry: package() depends+= not in the expected form"
s = s.replace(old, " depends+=(\n libncursesw.so\n )\n", 1)
# package() renames the GTK binary, which is no longer built.
old = ' # The -gtk backend has been built to be used with GTK3.\n mv "${pkgdir}/usr/bin/pinentry-gtk"{-2,}\n'
assert s.count(old) == 1, "pinentry: gtk rename not in the expected form"
s = s.replace(old, "", 1)
io.open("PKGBUILD", "w", encoding="utf-8").write(s)
PY
for f in gnome3 qt libsecret; do
grep -q -- "--disable-pinentry-$f\|--disable-$f" PKGBUILD || {
echo "pinentry: $f front end still enabled" >&2; exit 1; }
done
grep -qE "^ 'glibc' 'ncurses' 'libassuan'$" PKGBUILD || {
echo "pinentry: depends not reduced" >&2; exit 1; }
# EVERY place the names occur -- but as they are actually WRITTEN, not as bare
# substrings. The first version of this loop grepped for `libsecret` and
# matched the `--disable-libsecret` it had just inserted, so a correct patch
# reported failure. Third guard in this port to check something adjacent to
# what it meant; the lesson is that a guard needs the same care as the edit.
for n in "'libsecret'" "'glib2'" "libglib-2.0.so" "libsecret-1.so" \
"--enable-libsecret" "--enable-pinentry-qt" "--enable-pinentry-gnome3" \
'pinentry-gtk"{-2,}'; do
grep -qF -- "$n" PKGBUILD && {
echo "pinentry: $n still present" >&2; exit 1; }
done
grep -q -- "--enable-pinentry-curses" PKGBUILD || {
echo "pinentry: curses front end lost -- nothing would prompt" >&2; exit 1; }
echo "pinentry: tty/curses/emacs only (no Qt, GNOME or libsecret on this host)"