galeb

Једноставна статичка дистрибуција заснована на musl-у
Дневник | Датотеке | Референце | ПРОЧИТАЈМЕ | ЛИЦЕНЦА

чување a685cd003ee2891cdbcf805d7a4b490b1e962ede
родитељ 857529d9874c3d821ea23dd18ae98e16f9ea3a56
Аутор: Страхиња Радић <contact@strahinja.org>
Датум:   Sat, 15 Apr 2023 10:28:42 +0200

* Add musl fixed headers into pkg
* Check what needs to be removed in pat/
* Fix metalog and reflex timestamps
* Replace /${TLD}/bin/sed with \${SED} (and with /sucks/bin/sed)
* Remove `mkdir -p /local/include`/`rm -fr /local/include` in some substeps
* Add /local/bin to path, and in some substeps (opendoas...)

Signed-off-by: Страхиња Радић <contact@strahinja.org>

Diffstat:
M01-cross.sh | 1-
M03-packages.sh | 155+++++++++++++++++++++++++++++++++++++++++--------------------------------------
MTODO | 16++--------------
MTODO.done | 21++++++++++++++++++++-
Mlib/fun.sh | 23++++++++++++-----------
Dpat/libffi-alpine/pax-dlmmap.patch | 120-------------------------------------------------------------------------------
Dpat/libuv-mlfs/autogen-hardcode.patch | 11-----------
Dpat/xz-alpine/xzgrep-ZDI-CAN-16587.patch | 94-------------------------------------------------------------------------------
измењених датотека: 8, додавања: 114(+), брисања: 327(-)

diff --git a/01-cross.sh b/01-cross.sh @@ -933,7 +933,6 @@ else ln -s pigz /${TLD}/bin/unpigz ln -s pigz /${TLD}/bin/gzip ln -s pigz /${TLD}/bin/gunzip - sh ) || exit 1 remove_dir ${G_SRC}/${pkg} fi diff --git a/03-packages.sh b/03-packages.sh @@ -10,7 +10,7 @@ HOST_SED=0 HOST_TAR=0 export HOST_COREUTILS HOST_FIND HOST_MD5SUM HOST_SED HOST_TAR -PATH=/${TLD}/bin:/bin:/sbin:/sucks/bin:/sucks/sbin:/plan9/bin +PATH=/${TLD}/bin:/local/bin:/bin:/sbin:/sucks/bin:/sucks/sbin:/plan9/bin export PATH trap exit_cleanup HUP PIPE INT QUIT TERM EXIT @@ -557,7 +557,9 @@ else if [ ! -e config.mk.orig ]; then cp config.mk config.mk.orig - /${TLD}/bin/sed -i -e 's,/usr/local\(/plan9\),\1,g' \ + + SED=/${TLD}/bin/sed + ${SED} -i -e 's,/usr/local\(/plan9\),\1,g' \ -e 's,^CFLAGS\s\++= ,&-static --static -fcommon ,g' \ -e 's,^LDFLAGS\s\++= ,&-static --static -fcommon ,g' \ -e 's,^OBJTYPE\s\+= 386,#&,g' \ @@ -566,7 +568,7 @@ else fi if [ ! -e std.mk.orig ]; then cp std.mk std.mk.orig - /${TLD}/bin/sed -i -e 's,^#\(\s\+@strip.*\),\1,' std.mk + ${SED} -i -e 's,^#\(\s\+@strip.*\),\1,' std.mk fi cat <<! >MKPK mkpk_name() @@ -869,7 +871,8 @@ else extract_pkg ${G_SRC} ${pkg} ${pkg}.tar.xz ( cd_or_fail ${G_SRC}/${pkg} - /${TLD}/bin/sed -i \ + SED=/${TLD}/bin/sed + ${SED} -i \ -e 's@#ENCRYPT_METHOD DES@ENCRYPT_METHOD SHA512@' \ etc/login.defs @@ -877,7 +880,7 @@ else # in shadow 4.9 # - *Not* fixed in 4.11.1, so this is still needed. # - *Still* not fixed in 4.13, so it is likely intentional. - /${TLD}/bin/sed -i \ + ${SED} -i \ -e 's/^\(#define SHA_ROUNDS_MAX 9999999\)99/\1/' \ libmisc/salt.c @@ -1105,7 +1108,7 @@ gcc -dumpspecs | sed -e 's,/'${TLD}',,g' \ mv_or_fail specs ${SPECFILE} unset SPECFILE -PATH=/bin:/sucks/bin:/${TLD}/bin +PATH=/local/bin:/bin:/sucks/bin:/${TLD}/bin export PATH #for lib in gcc_s.so gcc_s.so.1 stdc++.a stdc++.so stdc++.so.6 @@ -1411,8 +1414,9 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS CXXFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed - /${TLD}/bin/sed -i s/mawk// configure + \${SED} -i s/mawk// configure ./configure --prefix="\${PREFIX}" \\ --without-shared \\ @@ -1975,12 +1979,13 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed - /${TLD}/bin/sed -i 's|_GL_WARN_ON_USE (gets|//_GL_WARN_ON_USE (gets|' \\ + \${SED} -i 's|_GL_WARN_ON_USE (gets|//_GL_WARN_ON_USE (gets|' \\ lib/stdio.in.h echo '#define PATH_PROCNET_DEV "/proc/net/dev"' \\ >> ifconfig/system/linux.h - /${TLD}/bin/sed -i 's|port : "whois"|port : "nicname"|' whois/whois.c + \${SED} -i 's|port : "whois"|port : "nicname"|' whois/whois.c ./configure --prefix="\${PREFIX}" \\ --localstatedir=/var \\ @@ -2138,8 +2143,9 @@ mkpk_install() DESTDIR=/build PERL=/sucks/bin/perl export CFLAGS LDFLAGS PREFIX DESTDIR PERL + SED=/sucks/bin/sed - /${TLD}/bin/sed -i 's:\\\${:\\\$\\{:' intltool-update.in + \${SED} -i 's:\\\${:\\\$\\{:' intltool-update.in ./configure --prefix="\${PREFIX}" @@ -2341,8 +2347,9 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed - /${TLD}/bin/sed -i '/pkgconfig_DATA/i pkgconfigdir=/lib/pkgconfig' \\ + \${SED} -i '/pkgconfig_DATA/i pkgconfigdir=/lib/pkgconfig' \\ Makefile.am ./bootstrap.sh @@ -2386,8 +2393,9 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed - /${TLD}/bin/sed -i '/pkgconfig_DATA/i pkgconfigdir=/lib/pkgconfig' \\ + \${SED} -i '/pkgconfig_DATA/i pkgconfigdir=/lib/pkgconfig' \\ Makefile.am ./bootstrap.sh @@ -2418,9 +2426,6 @@ else ( cd_or_fail ${G_SRC}/${pkg} -# apply_patch packages -Np1 -i \ -# ${G_PAT}/xz-alpine/xzgrep-ZDI-CAN-16587.patch - cat <<! >MKPK mkpk_name() { @@ -2478,7 +2483,7 @@ mkpk_install() CFLAGS=-Os -pipe -static --static -fcommon -fPIC LDFLAGS=-static --static -fcommon -s @ - /${TLD}/bin/sed -i 's,/usr/local,,g' Makefile + /sucks/bin/sed -i 's,/usr/local,,g' Makefile make LIBINTL=MUSL ${JN} || exit 1 make LIBINTL=MUSL DESTDIR="\${DESTDIR}" prefix="\${PREFIX}" install @@ -2649,9 +2654,6 @@ else ( cd_or_fail ${G_SRC}/${pkg} -# apply_patch packages -Np1 -i \ -# ${G_PAT}/libffi-alpine/pax-dlmmap.patch - cat <<! >MKPK mkpk_name() { @@ -2808,12 +2810,13 @@ mkpk_install() LDFLAGS='-static --static -fcommon -s' DESTDIR=/build export CFLAGS LDFLAGS DESTDIR + SED=/sucks/bin/sed cc \${CFLAGS} -o mozilla/certdata2pem certdata2pem.c - /${TLD}/bin/sed -i -e 's,python3 certdata2pem.py,./certdata2pem,g' \\ + \${SED} -i -e 's,python3 certdata2pem.py,./certdata2pem,g' \\ mozilla/Makefile - /${TLD}/bin/sed -i -e 's,\(.*\)\(certdata2pem.*\),\1\2\n\1./'\ + \${SED} -i -e 's,\(.*\)\(certdata2pem.*\),\1\2\n\1./'\ 'remove-expired-certs.sh,' mozilla/Makefile mkdir -p ../build @@ -2835,7 +2838,7 @@ mkpk_install() cd /build/share/ca-certificates /${TLD}/bin/find . -name '*.crt' | sort | cut -b3- > \\ /build/etc/ca-certificates.conf - /${TLD}/bin/sed -i -e 's,--tmpdir,-p /tmp,g' \\ + \${SED} -i -e 's,--tmpdir,-p /tmp,g' \\ /build/bin/update-ca-certificates /${TLD}/bin/ln -sv /etc/ssl/certs/ca-certificates.crt \\ @@ -3027,6 +3030,7 @@ mkpk_install() DESTDIR=/build LIBS=-lstdc++ export CFLAGS LDFLAGS CXXFLAGS PREFIX DESTDIR LIBS + SED=/sucks/bin/sed (cd build/meson meson setup \\ @@ -3038,9 +3042,9 @@ mkpk_install() b cd b - /${TLD}/bin/sed -i 's,/lib/libz.so,/lib/libz.a,g' \\ + \${SED} -i 's,/lib/libz.so,/lib/libz.a,g' \\ meson-info/intro-dependencies.json - /${TLD}/bin/sed -i 's,/lib/libz.so,/lib/libz.a,g' \\ + \${SED} -i 's,/lib/libz.so,/lib/libz.a,g' \\ build.ninja ninja ${JN} ninja install) @@ -3187,8 +3191,9 @@ mkpk_install() PREFIX=/ DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed - /${TLD}/bin/sed -i s/3000/5000/ libxslt/transform.c doc/xsltproc.1 \\ + \${SED} -i s/3000/5000/ libxslt/transform.c doc/xsltproc.1 \\ doc/xsltproc.xml ./configure --prefix="\${PREFIX}" --disable-shared || exit 1 @@ -3236,8 +3241,9 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS DESTDIR + SED=/sucks/bin/sed - /${TLD}/bin/sed -i '1i#include <langinfo.h>' proc/escape.c + \${SED} -i '1i#include <langinfo.h>' proc/escape.c ac_cv_func_malloc_0_nonnull=yes \ ac_cv_func_realloc_0_nonnull=yes \ @@ -3290,9 +3296,9 @@ mkpk_install() LDFLAGS='-static --static -fcommon -s' DESTDIR=/build export CFLAGS LDFLAGS DESTDIR + SED=/sucks/bin/sed - - /${TLD}/bin/sed -i -e 's/^HOSTCC =.*/HOSTCC = gcc -Wall/' \\ + \${SED} -i -e 's/^HOSTCC =.*/HOSTCC = gcc -Wall/' \\ -e 's/^CFLAGS =/#&/' \\ -e "s/^#CFLAGS =\\$/CFLAGS = \${CFLAGS}&/" \\ -e 's/^#\( YACC = yacc.*\)/\1/' \\ @@ -3339,13 +3345,14 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed ./configure --prefix="\${PREFIX}" --disable-shared make ${JN} || exit 1 make install-strip - /${TLD}/bin/sed -i '1s,/tools,,' /build/bin/checkmk + \${SED} -i '1s,/tools,,' /build/bin/checkmk mkdir -p /build/sucks/share/aclocal mv /build/share/aclocal/* /build/sucks/share/aclocal/ @@ -3411,10 +3418,6 @@ else ( cd_or_fail ${G_SRC}/${pkg} - -# apply_patch packages -Np1 -i \ -# ${G_PAT}/libuv-mlfs/autogen-hardcode.patch - cat <<! >MKPK mkpk_name() { @@ -3485,7 +3488,6 @@ mkpk_install() LIBS='-lcurl -lssl -lcrypto' LDLIBS=\${LIBS} export PREFIX DESTDIR LIBS LDLIBS - SED=/${TLD}/bin/sed \${SED} -i.bak '/"lib64"/s,lib64,lib,' \\ @@ -3593,11 +3595,12 @@ mkpk_install() DESTDIR=/build MANDIR='\$(INSTDIR)/share/man' export CFLAGS LDFLAGS DESTDIR + SED=/sucks/bin/sed - /${TLD}/bin/sed -i 's,^\\(CFLAGS_SYS= \\).*,\\1'"\${CFLAGS}"',;'\ + \${SED} -i 's,^\\(CFLAGS_SYS= \\).*,\\1'"\${CFLAGS}"',;'\ 's,^\\(INSTDIR = \\).*,\\1'"\${DESTDIR}"',;'\ 's,^\\(MANDIR = \\).*,\\1'"\${MANDIR}"',;'\ -'s,^\\(\\s\\)\\+sed ,\\1'"/${TLD}/bin/sed"' ,g' Makefile +'s,^\\(\\s\\)\\+sed ,\\1'"\${SED}"' ,g' Makefile patch -Np1 -i fix-makefile-malformed-utf-8.patch make all || exit 1 make install @@ -3959,10 +3962,11 @@ mkpk_install() FALLBACKDATE="12 Apr 2023" PREFIX=/build export SLED_CC FALLBACKVER FALLBACKDATE PREFIX + SED=/sucks/bin/sed if [ ! -e do.orig ]; then cp do do.orig - /${TLD}/bin/sed -i -e "s,\\<xargs\\>,/${TLD}/bin/xargs,g" do + \${SED} -i -e "s,\\<xargs\\>,/${TLD}/bin/xargs,g" do fi ./do clean install } @@ -4300,8 +4304,7 @@ mkpk_install() LIBDIR=/lib YACC=yacc export CFLAGS LDFLAGS PREFIX DESTDIR DOCDIR LIBDIR YACC - - SED=/${TLD}/bin/sed + SED=/sucks/bin/sed \${SED} -i -e '/ARPD/d' -e 's,^\\(PREFIX.*=\\).*,\\1'\${PREFIX}',g' \\ Makefile || exit 1 @@ -4421,11 +4424,12 @@ mkpk_install() DESTDIR=/build YACC=yacc export CFLAGS LDFLAGS DESTDIR YACC + SED=/sucks/bin/sed autoreconf -fvi || exit 1 - /${TLD}/bin/sed -e '/^PKG_CHECK_MODULES.*/d' -i configure.ac - /${TLD}/bin/sed -e 's,tests ,,g' -i Makefile.am + \${SED} -e '/^PKG_CHECK_MODULES.*/d' -i configure.ac + \${SED} -e 's,tests ,,g' -i Makefile.am ./configure --prefix=/ --disable-vlock || exit 1 @@ -4635,10 +4639,11 @@ mkpk_install() FALLBACKDATE="10 Apr 2023" PREFIX=/build export TABLE_CC FALLBACKVER FALLBACKDATE PREFIX + SED=/sucks/bin/sed if [ ! -e do.orig ]; then cp do do.orig - /${TLD}/bin/sed -i -e "s,\\<xargs\\>,/${TLD}/bin/xargs,g" do + \${SED} -i -e "s,\\<xargs\\>,/${TLD}/bin/xargs,g" do fi patch -Np1 -i tcc-unicode-string-literals.patch ./do clean install @@ -4947,8 +4952,9 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed - /${TLD}/bin/sed -i -e '/^PREFIX/s,/usr/local,,' Makefile + \${SED} -i -e '/^PREFIX/s,/usr/local,,' Makefile make ${JN} make DESTDIR="\${DESTDIR}" install @@ -5132,6 +5138,7 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed ./configure --prefix="\${PREFIX}" \\ --sysconfdir=/etc \\ @@ -5140,7 +5147,7 @@ mkpk_install() --disable-netbeans \\ --without-x || exit 1 - /${TLD}/bin/sed -i -e '/#define SYS_VIMRC/s,/\*.*\(#define.*"\) '\ + \${SED} -i -e '/#define SYS_VIMRC/s,/\*.*\(#define.*"\) '\ '\*/,\1,' src/feature.h make ${JN} || exit 1 @@ -5325,16 +5332,17 @@ mkpk_install() CFLAGS+=' -I../lib ' export CFLAGS + SED=/sucks/bin/sed make || true # Hack sucky auto*hell - /${TLD}/bin/sed -i 's/^\\(# *if \\)\$/\\10/g' lib/stdint.h - /${TLD}/bin/sed -i \\ + \${SED} -i 's/^\\(# *if \\)\$/\\10/g' lib/stdint.h + \${SED} -i \\ -e 's/^\\(# *if \\)\$/\\10/g' \\ -e 's/^\\(# *if defined __MINGW32__ && !\\)\$/\\11/g' \\ lib/wctype.h - /${TLD}/bin/sed -i 's/^\\(# *if \\)\$/\\10/g' lib/wchar.h + \${SED} -i 's/^\\(# *if \\)\$/\\10/g' lib/wchar.h # This should be enough, but it doesn't work, so have to 'make all' #make src/stty || exit 1 @@ -5436,10 +5444,11 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed autoreconf -vif - /${TLD}/bin/sed -i '/The name/,+2 d' src/global.c + \${SED} -i '/The name/,+2 d' src/global.c ./configure --prefix="\${PREFIX}" \\ --bindir=/bin \\ @@ -5483,10 +5492,11 @@ mkpk_install() LDFLAGS='-static --static -fcommon -s' LDLIBS=-lc export CFLAGS LDFLAGS LDLIBS + SED=/sucks/bin/sed if [ ! -e config.mk.orig ]; then cp config.mk config.mk.orig - /${TLD}/bin/sed -i -e "s,^\\(PREFIX\\s*=\\s*\\).*,PREFIX = ," \\ + \${SED} -i -e "s,^\\(PREFIX\\s*=\\s*\\).*,PREFIX = ," \\ -e "s,^\\(CC\\s*=\\s*\\).*,CC = \${CC}," \\ config.mk fi @@ -5528,10 +5538,11 @@ mkpk_install() LDFLAGS='-static -fcommon' LDLIBS=-lc export AR CC CFLAGS LDFLAGS LDLIBS + SED=/sucks/bin/sed if [ ! -e config.mk.orig ]; then cp config.mk config.mk.orig - /${TLD}/bin/sed -i -e "s,^\\(PREFIX\\s*=\\s*\\).*,PREFIX = ," \\ + \${SED} -i -e "s,^\\(PREFIX\\s*=\\s*\\).*,PREFIX = ," \\ -e "s,^\\(CC\\s*=\\s*\\).*,CC = \${CC}," \\ config.mk fi @@ -5725,6 +5736,7 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed make ${JN} PREFIX="\${PREFIX}" DESTDIR="\${DESTDIR}" \\ -C src \\ @@ -5736,8 +5748,8 @@ mkpk_install() make ${JN} PREFIX="\${PREFIX}" DESTDIR="\${DESTDIR}" \\ efivar-static - /${TLD}/bin/sed -i 's,/lib64,/lib,g' src/efiboot.pc - /${TLD}/bin/sed -i 's,/lib64,/lib,g' src/efivar.pc + \${SED} -i 's,/lib64,/lib,g' src/efiboot.pc + \${SED} -i 's,/lib64,/lib,g' src/efivar.pc mkdir -p \${DESTDIR}\${PREFIX}/bin install -Dm0755 src/efivar-static \${DESTDIR}\${PREFIX}/bin/efivar @@ -5807,8 +5819,9 @@ mkpk_install() DESTDIR=/build EFI_LOADER='grubx64.efi' export CFLAGS LDFLAGS PREFIX DESTDIR EFILOADER + SED=/sucks/bin/sed - /${TLD}/bin/sed -e '/extern int efi_set_verbose/d' -i src/efibootmgr.c + \${SED} -e '/extern int efi_set_verbose/d' -i src/efibootmgr.c make ${JN} PREFIX="\${PREFIX}" EXTRA_FLAGS="\${CFLAGS}" EFIDIR=GALEB \\ EFI_LOADER="\${EFI_LOADER}" || { sh; exit 1; } @@ -6188,10 +6201,11 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed if [ ! -e config.mk.orig ]; then cp config.mk config.mk.orig - /${TLD}/bin/sed -i -e "s,/usr/local,,g" \\ + \${SED} -i -e "s,/usr/local,,g" \\ -e "s,^CFLAGS\\s\\+= ,&\${CFLAGS} ,g" \\ -e "s,^LDFLAGS\\s\\+= ,&\${LDFLAGS} ,g" \\ -e 's,^PNG.*=.*,& -lz ,g' \\ @@ -6363,9 +6377,6 @@ mkpk_install() DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR - # Supress warning about missing include dir - mkdir -p /local/include - NOCONFIGURE=1 autoreconf -vif || exit 1 ./configure --prefix="\${PREFIX}" \\ @@ -6374,8 +6385,6 @@ mkpk_install() make ${JN} || exit 1 make DESTDIR="\${DESTDIR}" install - - rm -fr /local/include } ! mkpk ${pkg} @@ -6416,9 +6425,6 @@ mkpk_install() export CFLAGS CXXFLAGS LDFLAGS PREFIX DESTDIR export GMP_LIBS HOGWEED_LIBS - # Supress warning about missing include dir - mkdir -p /local/include - ./configure --prefix="\${PREFIX}" \\ --enable-static \\ --disable-shared \\ @@ -6468,9 +6474,6 @@ mkpk_install() DESTDIR=/build export CFLAGS CXXFLAGS LDFLAGS DESTDIR - # Supress warning about missing include dir - mkdir -p /local/include - ./configure --prefix="\${PREFIX}" \\ --enable-static \\ --disable-shared \\ @@ -6720,8 +6723,6 @@ else apply_patch final -Np1 -i \ ${G_PAT}/gnupg-alpine/0001-Include-sys-select.h-for-\ FD_SETSIZE.patch - #apply_patch final -Np1 -i \ - # ${G_PAT}/gnupg-alpine/fix-i18n.patch cat <<! >MKPK mkpk_name() @@ -6736,8 +6737,9 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed - /${TLD}/bin/sed -e '/noinst_SCRIPTS = gpg-zip/c '\\ + \${SED} -e '/noinst_SCRIPTS = gpg-zip/c '\\ 'sbin_SCRIPTS += gpg-zip' -i tools/Makefile.in # ,--- This is why pkg-config sucks: static linking requires to manually @@ -6846,7 +6848,7 @@ mkpk_install() # Adjust as necessary cat <<@ >\${DESTDIR}/etc/doas.conf deny root -permit nopass setenv { PATH=/bin:/sucks/bin:/plan9/bin EDITOR } :wheel +permit nopass setenv { PATH=/local/bin:/bin:/sucks/bin:/plan9/bin EDITOR } :wheel @ chmod 4755 \${DESTDIR}\${PREFIX}/bin/doas @@ -6883,8 +6885,9 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed - /${TLD}/bin/sed -i -e 's,\\<encrypt\\>,pass_encrypt,g' pass.c + \${SED} -i -e 's,\\<encrypt\\>,pass_encrypt,g' pass.c cat <<@ >config.mk PREFIX=\${PREFIX} @@ -6951,10 +6954,10 @@ mkpk_install() LDFLAGS='-s' PREFIX=/sucks DESTDIR=/build - SED=/${TLD}/bin/sed + SED=/sucks/bin/sed export CFLAGS LDFLAGS PREFIX DESTDIR SED - make ${JN} PREFIX=\${PREFIX} DESTDIR=\${DESTDIR} SED=\${SED} \\ + make ${JN} PREFIX="\${PREFIX}" DESTDIR="\${DESTDIR}" SED="\${SED}" \\ -C . install || exit 1 } ! @@ -7098,13 +7101,14 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed ./configure --prefix="\${PREFIX}" \\ --enable-static \\ --disable-shared || exit 1 # Needs to be hacked in? - /${TLD}/bin/sed -i 's/\(-lssl -lcrypto\)/\1 -lz/g' Makefile + \${SED} -i 's/\(-lssl -lcrypto\)/\1 -lz/g' Makefile make V=1 ${JN} || exit 1 make install @@ -7183,8 +7187,9 @@ mkpk_install() PREFIX='' DESTDIR=/build export CFLAGS LDFLAGS PREFIX DESTDIR + SED=/sucks/bin/sed - /${TLD}/bin/sed -i -e 's,/usr/local,'\${DESTDIR}',' \\ + \${SED} -i -e 's,/usr/local,'\${DESTDIR}',' \\ -e '/^MANDIR/s,/man,/share&,' \\ -e "/^CFLAGS/s,\\(CFLAGS=\\).*,\\1\${CFLAGS}," \\ -e "/^LDFLAGS/s,\\(LDFLAGS=\\).*,\\1\${LDFLAGS}," \\ @@ -7367,7 +7372,7 @@ begin_substep linux-5.17.13 msg warn "Next, configure Linux by using: " msg warn " mv /bin/ln /bin/_ln " -msg warn " export PATH=/bin:/sucks/bin:/tools/bin " +msg warn " export PATH=/local/bin:/bin:/sucks/bin:/tools/bin " msg warn " make LEX=/${TLD}/bin/flex menuconfig && \\\\ " msg warn " make CFLAGS=-fPIE LDFLAGS=-fPIE LEX=/${TLD}/bin/flex \\\\" msg warn " BC=/${TLD}/bin/bc bzImage modules modules_install && \\\\" diff --git a/TODO b/TODO @@ -9,17 +9,8 @@ High priority [ ] Continue work on X.Org [ ] Add and test wpa_supplicant -[ ] Add musl fixed headers into pkg - -[ ] Check what needs to be removed in pat/ - -[ ] Fix metalog and reflex timestamps - -[ ] Replace /${TLD}/bin/sed with \${SED} (and possibly with /sucks/bin/sed? - -[ ] Remove `mkdir -p /local/include`/`rm -fr /local/include` in some substeps - -[ ] Add /local/bin to path, and in some substeps (opendoas...) +[ ] Use https://raw.githubusercontent.com/9fans/plan9port/master/lib/fortunes + as a fortune file Low priority @@ -27,9 +18,6 @@ Low priority [ ] Add ghostscript (for groff) -[ ] Use https://raw.githubusercontent.com/9fans/plan9port/master/lib/fortunes - as a fortune file - < > See if any packages can be trimmed from the bootstrap < > Create a dedicated shutdown suid executable diff --git a/TODO.done b/TODO.done @@ -1,5 +1,24 @@ Done todos ----------- +========== + +2.2 +--- + +[x] Add musl fixed headers into pkg + +[x] Check what needs to be removed in pat/ + +[/] Fix metalog and reflex timestamps + +[x] Replace /${TLD}/bin/sed with \${SED} (and possibly with /sucks/bin/sed? + +[x] Remove `mkdir -p /local/include`/`rm -fr /local/include` in some substeps + +[x] Add /local/bin to path, and in some substeps (opendoas...) + + +2.1 +--- [x] Check libtool; it has references to /tools/bin/sed and grep - Not a problem in bootstrap scripts, but it could be when using libtool in diff --git a/lib/fun.sh b/lib/fun.sh @@ -347,7 +347,8 @@ mkpk() fi cd .. - mkdir -p bin build dev etc include libexec plan9 share sucks tmp tools + mkdir -p bin build dev etc include libexec local plan9 share sucks + mkdir -p tmp tools bm() { @@ -369,6 +370,7 @@ mkpk() rbm include rbm lib rbm libexec + rbm local rbm plan9 rbm share rbm sucks @@ -418,6 +420,7 @@ mkpk() umount ../sucks umount ../share umount ../plan9 + umount ../local umount ../libexec umount ../lib umount ../include @@ -428,15 +431,13 @@ mkpk() if [ ${fail} -eq 0 ]; then msg info "mkpk packing..." cd ../build - g_find . \( -type b -o -type c -o \ - -type f -o -type l \) \ - -cnewer ../timestamp \ - -printf "%p\n" \ - | sort | uniq | tar -c -T - | \ - xz -9 > ${G_SPKG}/$(mkpk_name).tar.xz && \ - cd ${G_SPKG} && \ - g_shasum $(mkpk_name).tar.xz >$(mkpk_name).sha512 && \ - { cd - >/dev/null 2>&1; } + g_find . \( -type b -o -type c -o -type f -o -type l \) \ + -cnewer ../timestamp -printf "%p\n" \ + | sort | uniq | tar -c -T - \ + | xz -9 > ${G_SPKG}/$(mkpk_name).tar.xz \ + && cd ${G_SPKG} \ + && g_shasum $(mkpk_name).tar.xz >$(mkpk_name).sha512 \ + && { cd - >/dev/null 2>&1; } rm ../timestamp fi @@ -447,7 +448,7 @@ mkpk() rm -fr sucks rm -fr share rm usr - rmdir bin dev etc include libexec plan9 tmp tools + rmdir bin dev etc include libexec local plan9 tmp tools exit ${fail} ) || { msg err "mkpk failed" diff --git a/pat/libffi-alpine/pax-dlmmap.patch b/pat/libffi-alpine/pax-dlmmap.patch @@ -1,120 +0,0 @@ -From 48d2e46528fb6e621d95a7fa194069fd136b712d Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Stefan=20B=C3=BChler?= <buehler@cert.uni-stuttgart.de> -Date: Wed, 7 Sep 2016 15:49:48 +0200 -Subject: [PATCH 1/2] dlmmap_locked always needs locking as it always modifies - execsize - ---- - src/closures.c | 13 ++++--------- - 1 file changed, 4 insertions(+), 9 deletions(-) - -diff --git a/src/closures.c b/src/closures.c -index 2e0ffb45..04d6e27f 100644 ---- a/src/closures.c -+++ b/src/closures.c -@@ -769,16 +769,11 @@ dlmmap (void *start, size_t length, int prot, - MREMAP_DUP and prot at this point. */ - } - -- if (execsize == 0 || execfd == -1) -- { -- pthread_mutex_lock (&open_temp_exec_file_mutex); -- ptr = dlmmap_locked (start, length, prot, flags, offset); -- pthread_mutex_unlock (&open_temp_exec_file_mutex); -+ pthread_mutex_lock (&open_temp_exec_file_mutex); -+ ptr = dlmmap_locked (start, length, prot, flags, offset); -+ pthread_mutex_unlock (&open_temp_exec_file_mutex); - -- return ptr; -- } -- -- return dlmmap_locked (start, length, prot, flags, offset); -+ return ptr; - } - - /* Release memory at the given address, as well as the corresponding - -From 7aad5f895e2dfdb79d2ef67e1b231d21063e6511 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Stefan=20B=C3=BChler?= <buehler@cert.uni-stuttgart.de> -Date: Wed, 7 Sep 2016 15:50:54 +0200 -Subject: [PATCH 2/2] ignore PaX EMUTRAMP flag; instead check for MPROTECT - -- code using ffi_closure_alloc doesn't necessarily generate gcc compatible trampolines; only those are allowed by PaX -- if MPROTECT is enabled use the same workaround as is used for SELinux (double mmap()) ---- - src/closures.c | 29 +++++++++++++---------------- - 1 file changed, 13 insertions(+), 16 deletions(-) - -diff --git a/src/closures.c b/src/closures.c -index 04d6e27f..babecc1a 100644 ---- a/src/closures.c -+++ b/src/closures.c -@@ -401,14 +401,15 @@ selinux_enabled_check (void) - - #endif /* !FFI_MMAP_EXEC_SELINUX */ - --/* On PaX enable kernels that have MPROTECT enable we can't use PROT_EXEC. */ -+/* On PaX enable kernels that have MPROTECT enabled we can't use PROT_EXEC. */ - #ifdef FFI_MMAP_EXEC_EMUTRAMP_PAX - #include <stdlib.h> - --static int emutramp_enabled = -1; -+/* -1: not read yet; 0: no PaX or MPROTECT disabled; 1: MPROTECT enabled. */ -+static int mprotect_enabled = -1; - - static int --emutramp_enabled_check (void) -+mprotect_enabled_check (void) - { - char *buf = NULL; - size_t len = 0; -@@ -422,9 +423,7 @@ emutramp_enabled_check (void) - while (getline (&buf, &len, f) != -1) - if (!strncmp (buf, "PaX:", 4)) - { -- char emutramp; -- if (sscanf (buf, "%*s %*c%c", &emutramp) == 1) -- ret = (emutramp == 'E'); -+ ret = (NULL != strchr (buf + 4, 'M')); - break; - } - free (buf); -@@ -432,8 +431,9 @@ emutramp_enabled_check (void) - return ret; - } - --#define is_emutramp_enabled() (emutramp_enabled >= 0 ? emutramp_enabled \ -- : (emutramp_enabled = emutramp_enabled_check ())) -+#define is_mprotect_enabled() (mprotect_enabled >= 0 ? mprotect_enabled \ -+ : (mprotect_enabled = mprotect_enabled_check ())) -+ - #endif /* FFI_MMAP_EXEC_EMUTRAMP_PAX */ - - #elif defined (__CYGWIN__) || defined(__INTERIX) -@@ -446,7 +446,7 @@ emutramp_enabled_check (void) - #endif /* !defined(X86_WIN32) && !defined(X86_WIN64) */ - - #ifndef FFI_MMAP_EXEC_EMUTRAMP_PAX --#define is_emutramp_enabled() 0 -+#define is_mprotect_enabled() 0 - #endif /* FFI_MMAP_EXEC_EMUTRAMP_PAX */ - - /* Declare all functions defined in dlmalloc.c as static. */ -@@ -750,13 +750,10 @@ dlmmap (void *start, size_t length, int prot, - && flags == (MAP_PRIVATE | MAP_ANONYMOUS) - && fd == -1 && offset == 0); - -- if (execfd == -1 && is_emutramp_enabled ()) -- { -- ptr = mmap (start, length, prot & ~PROT_EXEC, flags, fd, offset); -- return ptr; -- } -- -- if (execfd == -1 && !is_selinux_enabled ()) -+ /* -1 != execfd hints that we already decided to use dlmmap_locked -+ last time. If PaX MPROTECT or SELinux is active fallback to -+ dlmmap_locked. */ -+ if (execfd == -1 && !is_mprotect_enabled () && !is_selinux_enabled ()) - { - ptr = mmap (start, length, prot | PROT_EXEC, flags, fd, offset); - diff --git a/pat/libuv-mlfs/autogen-hardcode.patch b/pat/libuv-mlfs/autogen-hardcode.patch @@ -1,11 +0,0 @@ -diff -uNr libuv-v1.41.0.orig/autogen.sh libuv-v1.41.0/autogen.sh ---- libuv-v1.41.0.orig/autogen.sh 2021-02-13 11:57:24.000000000 -0600 -+++ libuv-v1.41.0/autogen.sh 2021-06-21 10:48:58.247976405 -0500 -@@ -41,6 +41,6 @@ - - set -ex - "$LIBTOOLIZE" --copy --"$ACLOCAL" -I m4 -+aclocal -I /share/aclocal -I m4 - "$AUTOCONF" - "$AUTOMAKE" --add-missing --copy diff --git a/pat/xz-alpine/xzgrep-ZDI-CAN-16587.patch b/pat/xz-alpine/xzgrep-ZDI-CAN-16587.patch @@ -1,94 +0,0 @@ -From 69d1b3fc29677af8ade8dc15dba83f0589cb63d6 Mon Sep 17 00:00:00 2001 -From: Lasse Collin <lasse.collin@tukaani.org> -Date: Tue, 29 Mar 2022 19:19:12 +0300 -Subject: [PATCH] xzgrep: Fix escaping of malicious filenames (ZDI-CAN-16587). - -Malicious filenames can make xzgrep to write to arbitrary files -or (with a GNU sed extension) lead to arbitrary code execution. - -xzgrep from XZ Utils versions up to and including 5.2.5 are -affected. 5.3.1alpha and 5.3.2alpha are affected as well. -This patch works for all of them. - -This bug was inherited from gzip's zgrep. gzip 1.12 includes -a fix for zgrep. - -The issue with the old sed script is that with multiple newlines, -the N-command will read the second line of input, then the -s-commands will be skipped because it's not the end of the -file yet, then a new sed cycle starts and the pattern space -is printed and emptied. So only the last line or two get escaped. - -One way to fix this would be to read all lines into the pattern -space first. However, the included fix is even simpler: All lines -except the last line get a backslash appended at the end. To ensure -that shell command substitution doesn't eat a possible trailing -newline, a colon is appended to the filename before escaping. -The colon is later used to separate the filename from the grep -output so it is fine to add it here instead of a few lines later. - -The old code also wasn't POSIX compliant as it used \n in the -replacement section of the s-command. Using \<newline> is the -POSIX compatible method. - -LC_ALL=C was added to the two critical sed commands. POSIX sed -manual recommends it when using sed to manipulate pathnames -because in other locales invalid multibyte sequences might -cause issues with some sed implementations. In case of GNU sed, -these particular sed scripts wouldn't have such problems but some -other scripts could have, see: - - info '(sed)Locale Considerations' - -This vulnerability was discovered by: -cleemy desu wayo working with Trend Micro Zero Day Initiative - -Thanks to Jim Meyering and Paul Eggert discussing the different -ways to fix this and for coordinating the patch release schedule -with gzip. ---- - src/scripts/xzgrep.in | 20 ++++++++++++-------- - 1 file changed, 12 insertions(+), 8 deletions(-) - -diff --git a/src/scripts/xzgrep.in b/src/scripts/xzgrep.in -index b180936..e5186ba 100644 ---- a/src/scripts/xzgrep.in -+++ b/src/scripts/xzgrep.in -@@ -180,22 +180,26 @@ for i; do - { test $# -eq 1 || test $no_filename -eq 1; }; then - eval "$grep" - else -+ # Append a colon so that the last character will never be a newline -+ # which would otherwise get lost in shell command substitution. -+ i="$i:" -+ -+ # Escape & \ | and newlines only if such characters are present -+ # (speed optimization). - case $i in - (*' - '* | *'&'* | *'\'* | *'|'*) -- i=$(printf '%s\n' "$i" | -- sed ' -- $!N -- $s/[&\|]/\\&/g -- $s/\n/\\n/g -- ');; -+ i=$(printf '%s\n' "$i" | LC_ALL=C sed 's/[&\|]/\\&/g; $!s/$/\\/');; - esac -- sed_script="s|^|$i:|" -+ -+ # $i already ends with a colon so don't add it here. -+ sed_script="s|^|$i|" - - # Fail if grep or sed fails. - r=$( - exec 4>&1 -- (eval "$grep" 4>&-; echo $? >&4) 3>&- | sed "$sed_script" >&3 4>&- -+ (eval "$grep" 4>&-; echo $? >&4) 3>&- | -+ LC_ALL=C sed "$sed_script" >&3 4>&- - ) || r=2 - exit $r - fi >&3 5>&- --- -2.35.1 -