From 0b9f18953a2d3bf1cb800323b523f26c9f0ab15a Mon Sep 17 00:00:00 2001 From: Vit Mojzis Date: Mon, 29 Mar 2021 17:33:31 +0200 Subject: [PATCH 01/24] setroubleshoot-plugins-3.3.14-1 - Update translations --- .gitignore | 1 + setroubleshoot-plugins.spec | 7 +++++-- sources | 1 + 3 files changed, 7 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 11c7f78..a58a8e6 100644 --- a/.gitignore +++ b/.gitignore @@ -122,3 +122,4 @@ setroubleshoot-plugins-2.1.55.tar.gz /setroubleshoot-plugins-3.3.10.tar.gz /setroubleshoot-plugins-3.3.11.tar.gz /setroubleshoot-plugins-3.3.12.tar.gz +/setroubleshoot-plugins-3.3.14.tar.gz diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 909a19a..277aef5 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -5,8 +5,8 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins -Version: 3.3.12 -Release: 4%{?dist} +Version: 3.3.14 +Release: 1%{?dist} License: GPLv2+ URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz @@ -49,6 +49,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Mon Mar 29 2021 Vit Mojzis - 3.3.14-1 +- Update translations + * Wed Jan 27 2021 Fedora Release Engineering - 3.3.12-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild diff --git a/sources b/sources index fbe69de..6b2fe43 100644 --- a/sources +++ b/sources @@ -1 +1,2 @@ SHA512 (setroubleshoot-plugins-3.3.12.tar.gz) = aec345a93aa7cfaea8468c72639dacb89dfc4fa9f1d2ed2e121f5ca20dfd37399877364d95cd8dd548cefcaee4ea818ae4465035a60b6ba18493eb548ef4c87e +SHA512 (setroubleshoot-plugins-3.3.14.tar.gz) = da6882a998aeade67891a722a5b94e2ba1072d9db5d73031854a2c0b51083a0eaf9519dd7987938a86c1f8d263d08882642ac447d7b4bbcd8a859db4b44d61c1 From fd9764ca644b533071fe4192095b0fc72ec01e35 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 23 Jul 2021 17:25:10 +0000 Subject: [PATCH 02/24] - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 277aef5..e093575 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.14 -Release: 1%{?dist} +Release: 2%{?dist} License: GPLv2+ URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz @@ -49,6 +49,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Fri Jul 23 2021 Fedora Release Engineering - 3.3.14-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + * Mon Mar 29 2021 Vit Mojzis - 3.3.14-1 - Update translations From 9aca788f04ac91d9e271783ae38afe5e1bb674fc Mon Sep 17 00:00:00 2001 From: Petr Lautrbach Date: Fri, 3 Sep 2021 16:17:32 +0200 Subject: [PATCH 03/24] restorecon.py: exclude more paths It doesn't make sense to run restorecon on /sys/ /proc/ and /memfd: Resolves: rhbz#1960136 --- 0001-restorecon.py-exclude-more-paths.patch | 26 +++++++++++++++++++++ setroubleshoot-plugins.spec | 3 ++- 2 files changed, 28 insertions(+), 1 deletion(-) create mode 100644 0001-restorecon.py-exclude-more-paths.patch diff --git a/0001-restorecon.py-exclude-more-paths.patch b/0001-restorecon.py-exclude-more-paths.patch new file mode 100644 index 0000000..2189d21 --- /dev/null +++ b/0001-restorecon.py-exclude-more-paths.patch @@ -0,0 +1,26 @@ +From 0f508191647a41f92264c0c8fc877b0110bbd468 Mon Sep 17 00:00:00 2001 +From: Petr Lautrbach +Date: Tue, 10 Aug 2021 20:11:20 +0200 +Subject: [PATCH] restorecon.py: exclude more paths + +It doesn't make sense to run restorecon on /sys/ /proc/ and /memfd: +--- + src/restorecon.py | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/restorecon.py b/src/restorecon.py +index e3044c742367..9594c0d59d96 100644 +--- a/src/restorecon.py ++++ b/src/restorecon.py +@@ -39,7 +39,7 @@ def customizable(target): + + + # List of path prefixes for which this plugin is not executed +-excluded_paths = ["/sys/fs"] ++excluded_paths = ["/sys/", "/proc/", "/memfd:"] + # Test if the specified path starts with some excluded prefix + def excluded_path(target_path): + for path in excluded_paths: +-- +2.32.0 + diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index e093575..309489e 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -12,6 +12,7 @@ URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz # git format-patch -N setroubleshoot-plugins- -- plugins # i=1; for j in 00*patch; do printf "Patch%04d: %s\n" $i $j; i=$((i+1));done +Patch0001: 0001-restorecon.py-exclude-more-paths.patch BuildArch: noarch # gcc is needed only for ./configure @@ -30,7 +31,7 @@ data and system data to provide user friendly reports describing how to interpret SELinux AVC denials. %prep -%autosetup -p 2 +%autosetup -p 1 %build %configure PYTHON=%{__python3} From 96233b03925dbac798f2710f33ae991bb5d3be67 Mon Sep 17 00:00:00 2001 From: Petr Lautrbach Date: Fri, 3 Sep 2021 16:20:12 +0200 Subject: [PATCH 04/24] Drop old tarball from sources --- sources | 1 - 1 file changed, 1 deletion(-) diff --git a/sources b/sources index 6b2fe43..28a0bb9 100644 --- a/sources +++ b/sources @@ -1,2 +1 @@ -SHA512 (setroubleshoot-plugins-3.3.12.tar.gz) = aec345a93aa7cfaea8468c72639dacb89dfc4fa9f1d2ed2e121f5ca20dfd37399877364d95cd8dd548cefcaee4ea818ae4465035a60b6ba18493eb548ef4c87e SHA512 (setroubleshoot-plugins-3.3.14.tar.gz) = da6882a998aeade67891a722a5b94e2ba1072d9db5d73031854a2c0b51083a0eaf9519dd7987938a86c1f8d263d08882642ac447d7b4bbcd8a859db4b44d61c1 From 142c889cd20590a82000850f28ce6c6f4eb5f940 Mon Sep 17 00:00:00 2001 From: Petr Lautrbach Date: Fri, 3 Sep 2021 16:22:46 +0200 Subject: [PATCH 05/24] setroubleshoot-plugins-3.3.14-3 - restorecon.py: exclude more paths (#1960136) --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 309489e..93ac068 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.14 -Release: 2%{?dist} +Release: 3%{?dist} License: GPLv2+ URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz @@ -50,6 +50,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Fri Sep 3 2021 Petr Lautrbach - 3.3.14-3 +- restorecon.py: exclude more paths (#1960136) + * Fri Jul 23 2021 Fedora Release Engineering - 3.3.14-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild From c6ec1df399d429995a3ce35a0d24eb142419d935 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 22 Jan 2022 00:44:02 +0000 Subject: [PATCH 06/24] - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 93ac068..8a754fb 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.14 -Release: 3%{?dist} +Release: 4%{?dist} License: GPLv2+ URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz @@ -50,6 +50,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Sat Jan 22 2022 Fedora Release Engineering - 3.3.14-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + * Fri Sep 3 2021 Petr Lautrbach - 3.3.14-3 - restorecon.py: exclude more paths (#1960136) From e832770250ca886d899f4c6699961af29b723403 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 23 Jul 2022 08:26:03 +0000 Subject: [PATCH 07/24] Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 8a754fb..59a4118 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.14 -Release: 4%{?dist} +Release: 5%{?dist} License: GPLv2+ URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz @@ -50,6 +50,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Sat Jul 23 2022 Fedora Release Engineering - 3.3.14-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + * Sat Jan 22 2022 Fedora Release Engineering - 3.3.14-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild From 60ad8a1851bac73b981271005673727b36ae8bc4 Mon Sep 17 00:00:00 2001 From: Petr Lautrbach Date: Thu, 10 Nov 2022 09:32:43 +0100 Subject: [PATCH 08/24] Migrate License tag to SPDX https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_1 --- setroubleshoot-plugins.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 59a4118..545b7a1 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -7,7 +7,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.14 Release: 5%{?dist} -License: GPLv2+ +License: GPL-2.0-or-later URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz # git format-patch -N setroubleshoot-plugins- -- plugins From 3fdc35208b72edd47d3a321e910297fa10cec41e Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 21 Jan 2023 03:03:42 +0000 Subject: [PATCH 09/24] Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 545b7a1..48c36a8 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.14 -Release: 5%{?dist} +Release: 6%{?dist} License: GPL-2.0-or-later URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz @@ -50,6 +50,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Sat Jan 21 2023 Fedora Release Engineering - 3.3.14-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + * Sat Jul 23 2022 Fedora Release Engineering - 3.3.14-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild From b066bbbd7a4cda050adef9af48eaab9b77ca0c30 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 22 Jul 2023 01:28:31 +0000 Subject: [PATCH 10/24] Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 48c36a8..4e793ed 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.14 -Release: 6%{?dist} +Release: 7%{?dist} License: GPL-2.0-or-later URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz @@ -50,6 +50,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Sat Jul 22 2023 Fedora Release Engineering - 3.3.14-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + * Sat Jan 21 2023 Fedora Release Engineering - 3.3.14-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild From 3e4d0a1bafb702a34ec632fdbf18c104261255db Mon Sep 17 00:00:00 2001 From: Petr Lautrbach Date: Wed, 26 Jul 2023 10:51:31 +0200 Subject: [PATCH 11/24] setroubleshoot-plugins-3.3.14-6 - Update generated configuration files (rhbz#2226425) - Improve disable_ipv6 plugin then_text --- ...mprove-disable_ipv6-plugin-then_text.patch | 29 + ...Update-generated-configuration-files.patch | 1036 +++++++++++++++++ setroubleshoot-plugins.spec | 8 +- 3 files changed, 1072 insertions(+), 1 deletion(-) create mode 100644 0002-Improve-disable_ipv6-plugin-then_text.patch create mode 100644 0003-Update-generated-configuration-files.patch diff --git a/0002-Improve-disable_ipv6-plugin-then_text.patch b/0002-Improve-disable_ipv6-plugin-then_text.patch new file mode 100644 index 0000000..697aabd --- /dev/null +++ b/0002-Improve-disable_ipv6-plugin-then_text.patch @@ -0,0 +1,29 @@ +From f8a5ef9b783f4be5fcb2fa711dd3b550b312a629 Mon Sep 17 00:00:00 2001 +From: Vit Mojzis +Date: Wed, 23 Nov 2022 18:25:20 +0100 +Subject: [PATCH] Improve disable_ipv6 plugin then_text +Content-type: text/plain + +Use more conscious language and be more explicit. + +Signed-off-by: Vit Mojzis +--- + src/disable_ipv6.py | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/disable_ipv6.py b/src/disable_ipv6.py +index 1c858213ddea..ca0b9cc7f49f 100644 +--- a/src/disable_ipv6.py ++++ b/src/disable_ipv6.py +@@ -38,7 +38,7 @@ Disable IPV6 properly. + fix_cmd = "" + + if_text = _("If you want to disable IPV6 on this machine") +- then_text = _("you need to set /proc/sys/net/ipv6/conf/all/disable_ipv6 to 1 and do not blacklist the module'") ++ then_text = _("you need to set /proc/sys/net/ipv6/conf/all/disable_ipv6 to 1 and do not disable the ipv6 kernel module'") + do_text = _("""Add + net.ipv6.conf.all.disable_ipv6 = 1 + to /etc/sysctl.conf +-- +2.41.0 + diff --git a/0003-Update-generated-configuration-files.patch b/0003-Update-generated-configuration-files.patch new file mode 100644 index 0000000..75b7aed --- /dev/null +++ b/0003-Update-generated-configuration-files.patch @@ -0,0 +1,1036 @@ +From 9e54f6a661330070ad25a0e86f197b3530bfc5c7 Mon Sep 17 00:00:00 2001 +From: Petr Lautrbach +Date: Wed, 26 Jul 2023 10:30:07 +0200 +Subject: [PATCH] Update generated configuration files +Content-type: text/plain + +Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=2226425 + + Traceback (most recent call last): + File "", line 2, in + ModuleNotFoundError: No module named 'imp' + make[2]: *** [Makefile:372: install-pluginPYTHON] Error 1 +--- + INSTALL | 320 ++++++++++++++++++++++++++--------------------------- + install-sh | 174 ++++++++++++++++++----------- + missing | 16 +-- + py-compile | 59 ++++++---- + 4 files changed, 313 insertions(+), 256 deletions(-) + +diff --git a/INSTALL b/INSTALL +index 2099840756e6..e82fd21de2ea 100644 +--- a/INSTALL ++++ b/INSTALL +@@ -1,8 +1,8 @@ + Installation Instructions + ************************* + +-Copyright (C) 1994-1996, 1999-2002, 2004-2013 Free Software Foundation, +-Inc. ++ Copyright (C) 1994-1996, 1999-2002, 2004-2017, 2020-2021 Free ++Software Foundation, Inc. + + Copying and distribution of this file, with or without modification, + are permitted in any medium without royalty provided the copyright +@@ -12,97 +12,96 @@ without warranty of any kind. + Basic Installation + ================== + +- Briefly, the shell command `./configure && make && make install' ++ Briefly, the shell command './configure && make && make install' + should configure, build, and install this package. The following +-more-detailed instructions are generic; see the `README' file for ++more-detailed instructions are generic; see the 'README' file for + instructions specific to this package. Some packages provide this +-`INSTALL' file but do not implement all of the features documented ++'INSTALL' file but do not implement all of the features documented + below. The lack of an optional feature in a given package is not + necessarily a bug. More recommendations for GNU packages can be found + in *note Makefile Conventions: (standards)Makefile Conventions. + +- The `configure' shell script attempts to guess correct values for ++ The 'configure' shell script attempts to guess correct values for + various system-dependent variables used during compilation. It uses +-those values to create a `Makefile' in each directory of the package. +-It may also create one or more `.h' files containing system-dependent +-definitions. Finally, it creates a shell script `config.status' that ++those values to create a 'Makefile' in each directory of the package. ++It may also create one or more '.h' files containing system-dependent ++definitions. Finally, it creates a shell script 'config.status' that + you can run in the future to recreate the current configuration, and a +-file `config.log' containing compiler output (useful mainly for +-debugging `configure'). ++file 'config.log' containing compiler output (useful mainly for ++debugging 'configure'). + +- It can also use an optional file (typically called `config.cache' +-and enabled with `--cache-file=config.cache' or simply `-C') that saves +-the results of its tests to speed up reconfiguring. Caching is +-disabled by default to prevent problems with accidental use of stale +-cache files. ++ It can also use an optional file (typically called 'config.cache' and ++enabled with '--cache-file=config.cache' or simply '-C') that saves the ++results of its tests to speed up reconfiguring. Caching is disabled by ++default to prevent problems with accidental use of stale cache files. + + If you need to do unusual things to compile the package, please try +-to figure out how `configure' could check whether to do them, and mail +-diffs or instructions to the address given in the `README' so they can ++to figure out how 'configure' could check whether to do them, and mail ++diffs or instructions to the address given in the 'README' so they can + be considered for the next release. If you are using the cache, and at +-some point `config.cache' contains results you don't want to keep, you ++some point 'config.cache' contains results you don't want to keep, you + may remove or edit it. + +- The file `configure.ac' (or `configure.in') is used to create +-`configure' by a program called `autoconf'. You need `configure.ac' if +-you want to change it or regenerate `configure' using a newer version +-of `autoconf'. ++ The file 'configure.ac' (or 'configure.in') is used to create ++'configure' by a program called 'autoconf'. You need 'configure.ac' if ++you want to change it or regenerate 'configure' using a newer version of ++'autoconf'. + + The simplest way to compile this package is: + +- 1. `cd' to the directory containing the package's source code and type +- `./configure' to configure the package for your system. ++ 1. 'cd' to the directory containing the package's source code and type ++ './configure' to configure the package for your system. + +- Running `configure' might take a while. While running, it prints ++ Running 'configure' might take a while. While running, it prints + some messages telling which features it is checking for. + +- 2. Type `make' to compile the package. ++ 2. Type 'make' to compile the package. + +- 3. Optionally, type `make check' to run any self-tests that come with ++ 3. Optionally, type 'make check' to run any self-tests that come with + the package, generally using the just-built uninstalled binaries. + +- 4. Type `make install' to install the programs and any data files and ++ 4. Type 'make install' to install the programs and any data files and + documentation. When installing into a prefix owned by root, it is + recommended that the package be configured and built as a regular +- user, and only the `make install' phase executed with root ++ user, and only the 'make install' phase executed with root + privileges. + +- 5. Optionally, type `make installcheck' to repeat any self-tests, but ++ 5. Optionally, type 'make installcheck' to repeat any self-tests, but + this time using the binaries in their final installed location. + This target does not install anything. Running this target as a +- regular user, particularly if the prior `make install' required ++ regular user, particularly if the prior 'make install' required + root privileges, verifies that the installation completed + correctly. + + 6. You can remove the program binaries and object files from the +- source code directory by typing `make clean'. To also remove the +- files that `configure' created (so you can compile the package for +- a different kind of computer), type `make distclean'. There is +- also a `make maintainer-clean' target, but that is intended mainly ++ source code directory by typing 'make clean'. To also remove the ++ files that 'configure' created (so you can compile the package for ++ a different kind of computer), type 'make distclean'. There is ++ also a 'make maintainer-clean' target, but that is intended mainly + for the package's developers. If you use it, you may have to get + all sorts of other programs in order to regenerate files that came + with the distribution. + +- 7. Often, you can also type `make uninstall' to remove the installed ++ 7. Often, you can also type 'make uninstall' to remove the installed + files again. In practice, not all packages have tested that + uninstallation works correctly, even though it is required by the + GNU Coding Standards. + +- 8. Some packages, particularly those that use Automake, provide `make ++ 8. Some packages, particularly those that use Automake, provide 'make + distcheck', which can by used by developers to test that all other +- targets like `make install' and `make uninstall' work correctly. ++ targets like 'make install' and 'make uninstall' work correctly. + This target is generally not run by end users. + + Compilers and Options + ===================== + + Some systems require unusual options for compilation or linking that +-the `configure' script does not know about. Run `./configure --help' ++the 'configure' script does not know about. Run './configure --help' + for details on some of the pertinent environment variables. + +- You can give `configure' initial values for configuration parameters +-by setting variables in the command line or in the environment. Here +-is an example: ++ You can give 'configure' initial values for configuration parameters ++by setting variables in the command line or in the environment. Here is ++an example: + + ./configure CC=c99 CFLAGS=-g LIBS=-lposix + +@@ -113,21 +112,21 @@ Compiling For Multiple Architectures + + You can compile the package for more than one kind of computer at the + same time, by placing the object files for each architecture in their +-own directory. To do this, you can use GNU `make'. `cd' to the ++own directory. To do this, you can use GNU 'make'. 'cd' to the + directory where you want the object files and executables to go and run +-the `configure' script. `configure' automatically checks for the +-source code in the directory that `configure' is in and in `..'. This +-is known as a "VPATH" build. ++the 'configure' script. 'configure' automatically checks for the source ++code in the directory that 'configure' is in and in '..'. This is known ++as a "VPATH" build. + +- With a non-GNU `make', it is safer to compile the package for one ++ With a non-GNU 'make', it is safer to compile the package for one + architecture at a time in the source code directory. After you have +-installed the package for one architecture, use `make distclean' before ++installed the package for one architecture, use 'make distclean' before + reconfiguring for another architecture. + + On MacOS X 10.5 and later systems, you can create libraries and + executables that work on multiple system types--known as "fat" or +-"universal" binaries--by specifying multiple `-arch' options to the +-compiler but only a single `-arch' option to the preprocessor. Like ++"universal" binaries--by specifying multiple '-arch' options to the ++compiler but only a single '-arch' option to the preprocessor. Like + this: + + ./configure CC="gcc -arch i386 -arch x86_64 -arch ppc -arch ppc64" \ +@@ -136,105 +135,104 @@ this: + + This is not guaranteed to produce working output in all cases, you + may have to build one architecture at a time and combine the results +-using the `lipo' tool if you have problems. ++using the 'lipo' tool if you have problems. + + Installation Names + ================== + +- By default, `make install' installs the package's commands under +-`/usr/local/bin', include files under `/usr/local/include', etc. You +-can specify an installation prefix other than `/usr/local' by giving +-`configure' the option `--prefix=PREFIX', where PREFIX must be an ++ By default, 'make install' installs the package's commands under ++'/usr/local/bin', include files under '/usr/local/include', etc. You ++can specify an installation prefix other than '/usr/local' by giving ++'configure' the option '--prefix=PREFIX', where PREFIX must be an + absolute file name. + + You can specify separate installation prefixes for + architecture-specific files and architecture-independent files. If you +-pass the option `--exec-prefix=PREFIX' to `configure', the package uses ++pass the option '--exec-prefix=PREFIX' to 'configure', the package uses + PREFIX as the prefix for installing programs and libraries. + Documentation and other data files still use the regular prefix. + + In addition, if you use an unusual directory layout you can give +-options like `--bindir=DIR' to specify different values for particular +-kinds of files. Run `configure --help' for a list of the directories +-you can set and what kinds of files go in them. In general, the +-default for these options is expressed in terms of `${prefix}', so that +-specifying just `--prefix' will affect all of the other directory ++options like '--bindir=DIR' to specify different values for particular ++kinds of files. Run 'configure --help' for a list of the directories ++you can set and what kinds of files go in them. In general, the default ++for these options is expressed in terms of '${prefix}', so that ++specifying just '--prefix' will affect all of the other directory + specifications that were not explicitly provided. + + The most portable way to affect installation locations is to pass the +-correct locations to `configure'; however, many packages provide one or ++correct locations to 'configure'; however, many packages provide one or + both of the following shortcuts of passing variable assignments to the +-`make install' command line to change installation locations without ++'make install' command line to change installation locations without + having to reconfigure or recompile. + + The first method involves providing an override variable for each +-affected directory. For example, `make install ++affected directory. For example, 'make install + prefix=/alternate/directory' will choose an alternate location for all + directory configuration variables that were expressed in terms of +-`${prefix}'. Any directories that were specified during `configure', +-but not in terms of `${prefix}', must each be overridden at install +-time for the entire installation to be relocated. The approach of +-makefile variable overrides for each directory variable is required by +-the GNU Coding Standards, and ideally causes no recompilation. +-However, some platforms have known limitations with the semantics of +-shared libraries that end up requiring recompilation when using this +-method, particularly noticeable in packages that use GNU Libtool. +- +- The second method involves providing the `DESTDIR' variable. For +-example, `make install DESTDIR=/alternate/directory' will prepend +-`/alternate/directory' before all installation names. The approach of +-`DESTDIR' overrides is not required by the GNU Coding Standards, and ++'${prefix}'. Any directories that were specified during 'configure', ++but not in terms of '${prefix}', must each be overridden at install time ++for the entire installation to be relocated. The approach of makefile ++variable overrides for each directory variable is required by the GNU ++Coding Standards, and ideally causes no recompilation. However, some ++platforms have known limitations with the semantics of shared libraries ++that end up requiring recompilation when using this method, particularly ++noticeable in packages that use GNU Libtool. ++ ++ The second method involves providing the 'DESTDIR' variable. For ++example, 'make install DESTDIR=/alternate/directory' will prepend ++'/alternate/directory' before all installation names. The approach of ++'DESTDIR' overrides is not required by the GNU Coding Standards, and + does not work on platforms that have drive letters. On the other hand, + it does better at avoiding recompilation issues, and works well even +-when some directory options were not specified in terms of `${prefix}' +-at `configure' time. ++when some directory options were not specified in terms of '${prefix}' ++at 'configure' time. + + Optional Features + ================= + + If the package supports it, you can cause programs to be installed +-with an extra prefix or suffix on their names by giving `configure' the +-option `--program-prefix=PREFIX' or `--program-suffix=SUFFIX'. +- +- Some packages pay attention to `--enable-FEATURE' options to +-`configure', where FEATURE indicates an optional part of the package. +-They may also pay attention to `--with-PACKAGE' options, where PACKAGE +-is something like `gnu-as' or `x' (for the X Window System). The +-`README' should mention any `--enable-' and `--with-' options that the ++with an extra prefix or suffix on their names by giving 'configure' the ++option '--program-prefix=PREFIX' or '--program-suffix=SUFFIX'. ++ ++ Some packages pay attention to '--enable-FEATURE' options to ++'configure', where FEATURE indicates an optional part of the package. ++They may also pay attention to '--with-PACKAGE' options, where PACKAGE ++is something like 'gnu-as' or 'x' (for the X Window System). The ++'README' should mention any '--enable-' and '--with-' options that the + package recognizes. + +- For packages that use the X Window System, `configure' can usually ++ For packages that use the X Window System, 'configure' can usually + find the X include and library files automatically, but if it doesn't, +-you can use the `configure' options `--x-includes=DIR' and +-`--x-libraries=DIR' to specify their locations. ++you can use the 'configure' options '--x-includes=DIR' and ++'--x-libraries=DIR' to specify their locations. + + Some packages offer the ability to configure how verbose the +-execution of `make' will be. For these packages, running `./configure ++execution of 'make' will be. For these packages, running './configure + --enable-silent-rules' sets the default to minimal output, which can be +-overridden with `make V=1'; while running `./configure ++overridden with 'make V=1'; while running './configure + --disable-silent-rules' sets the default to verbose, which can be +-overridden with `make V=0'. ++overridden with 'make V=0'. + + Particular systems + ================== + +- On HP-UX, the default C compiler is not ANSI C compatible. If GNU +-CC is not installed, it is recommended to use the following options in ++ On HP-UX, the default C compiler is not ANSI C compatible. If GNU CC ++is not installed, it is recommended to use the following options in + order to use an ANSI C compiler: + + ./configure CC="cc -Ae -D_XOPEN_SOURCE=500" + + and if that doesn't work, install pre-built binaries of GCC for HP-UX. + +- HP-UX `make' updates targets which have the same time stamps as +-their prerequisites, which makes it generally unusable when shipped +-generated files such as `configure' are involved. Use GNU `make' +-instead. ++ HP-UX 'make' updates targets which have the same timestamps as their ++prerequisites, which makes it generally unusable when shipped generated ++files such as 'configure' are involved. Use GNU 'make' instead. + + On OSF/1 a.k.a. Tru64, some versions of the default C compiler cannot +-parse its `' header file. The option `-nodtk' can be used as +-a workaround. If GNU CC is not installed, it is therefore recommended +-to try ++parse its '' header file. The option '-nodtk' can be used as a ++workaround. If GNU CC is not installed, it is therefore recommended to ++try + + ./configure CC="cc" + +@@ -242,26 +240,26 @@ and if that doesn't work, try + + ./configure CC="cc -nodtk" + +- On Solaris, don't put `/usr/ucb' early in your `PATH'. This ++ On Solaris, don't put '/usr/ucb' early in your 'PATH'. This + directory contains several dysfunctional programs; working variants of +-these programs are available in `/usr/bin'. So, if you need `/usr/ucb' +-in your `PATH', put it _after_ `/usr/bin'. ++these programs are available in '/usr/bin'. So, if you need '/usr/ucb' ++in your 'PATH', put it _after_ '/usr/bin'. + +- On Haiku, software installed for all users goes in `/boot/common', +-not `/usr/local'. It is recommended to use the following options: ++ On Haiku, software installed for all users goes in '/boot/common', ++not '/usr/local'. It is recommended to use the following options: + + ./configure --prefix=/boot/common + + Specifying the System Type + ========================== + +- There may be some features `configure' cannot figure out ++ There may be some features 'configure' cannot figure out + automatically, but needs to determine by the type of machine the package + will run on. Usually, assuming the package is built to be run on the +-_same_ architectures, `configure' can figure that out, but if it prints ++_same_ architectures, 'configure' can figure that out, but if it prints + a message saying it cannot guess the machine type, give it the +-`--build=TYPE' option. TYPE can either be a short name for the system +-type, such as `sun4', or a canonical name which has the form: ++'--build=TYPE' option. TYPE can either be a short name for the system ++type, such as 'sun4', or a canonical name which has the form: + + CPU-COMPANY-SYSTEM + +@@ -270,101 +268,101 @@ where SYSTEM can have one of these forms: + OS + KERNEL-OS + +- See the file `config.sub' for the possible values of each field. If +-`config.sub' isn't included in this package, then this package doesn't ++ See the file 'config.sub' for the possible values of each field. If ++'config.sub' isn't included in this package, then this package doesn't + need to know the machine type. + + If you are _building_ compiler tools for cross-compiling, you should +-use the option `--target=TYPE' to select the type of system they will ++use the option '--target=TYPE' to select the type of system they will + produce code for. + + If you want to _use_ a cross compiler, that generates code for a + platform different from the build platform, you should specify the + "host" platform (i.e., that on which the generated programs will +-eventually be run) with `--host=TYPE'. ++eventually be run) with '--host=TYPE'. + + Sharing Defaults + ================ + +- If you want to set default values for `configure' scripts to share, +-you can create a site shell script called `config.site' that gives +-default values for variables like `CC', `cache_file', and `prefix'. +-`configure' looks for `PREFIX/share/config.site' if it exists, then +-`PREFIX/etc/config.site' if it exists. Or, you can set the +-`CONFIG_SITE' environment variable to the location of the site script. +-A warning: not all `configure' scripts look for a site script. ++ If you want to set default values for 'configure' scripts to share, ++you can create a site shell script called 'config.site' that gives ++default values for variables like 'CC', 'cache_file', and 'prefix'. ++'configure' looks for 'PREFIX/share/config.site' if it exists, then ++'PREFIX/etc/config.site' if it exists. Or, you can set the ++'CONFIG_SITE' environment variable to the location of the site script. ++A warning: not all 'configure' scripts look for a site script. + + Defining Variables + ================== + + Variables not defined in a site shell script can be set in the +-environment passed to `configure'. However, some packages may run ++environment passed to 'configure'. However, some packages may run + configure again during the build, and the customized values of these + variables may be lost. In order to avoid this problem, you should set +-them in the `configure' command line, using `VAR=value'. For example: ++them in the 'configure' command line, using 'VAR=value'. For example: + + ./configure CC=/usr/local2/bin/gcc + +-causes the specified `gcc' to be used as the C compiler (unless it is ++causes the specified 'gcc' to be used as the C compiler (unless it is + overridden in the site shell script). + +-Unfortunately, this technique does not work for `CONFIG_SHELL' due to +-an Autoconf limitation. Until the limitation is lifted, you can use +-this workaround: ++Unfortunately, this technique does not work for 'CONFIG_SHELL' due to an ++Autoconf limitation. Until the limitation is lifted, you can use this ++workaround: + + CONFIG_SHELL=/bin/bash ./configure CONFIG_SHELL=/bin/bash + +-`configure' Invocation ++'configure' Invocation + ====================== + +- `configure' recognizes the following options to control how it ++ 'configure' recognizes the following options to control how it + operates. + +-`--help' +-`-h' +- Print a summary of all of the options to `configure', and exit. ++'--help' ++'-h' ++ Print a summary of all of the options to 'configure', and exit. + +-`--help=short' +-`--help=recursive' ++'--help=short' ++'--help=recursive' + Print a summary of the options unique to this package's +- `configure', and exit. The `short' variant lists options used +- only in the top level, while the `recursive' variant lists options +- also present in any nested packages. ++ 'configure', and exit. The 'short' variant lists options used only ++ in the top level, while the 'recursive' variant lists options also ++ present in any nested packages. + +-`--version' +-`-V' +- Print the version of Autoconf used to generate the `configure' ++'--version' ++'-V' ++ Print the version of Autoconf used to generate the 'configure' + script, and exit. + +-`--cache-file=FILE' ++'--cache-file=FILE' + Enable the cache: use and save the results of the tests in FILE, +- traditionally `config.cache'. FILE defaults to `/dev/null' to ++ traditionally 'config.cache'. FILE defaults to '/dev/null' to + disable caching. + +-`--config-cache' +-`-C' +- Alias for `--cache-file=config.cache'. ++'--config-cache' ++'-C' ++ Alias for '--cache-file=config.cache'. + +-`--quiet' +-`--silent' +-`-q' ++'--quiet' ++'--silent' ++'-q' + Do not print messages saying which checks are being made. To +- suppress all normal output, redirect it to `/dev/null' (any error ++ suppress all normal output, redirect it to '/dev/null' (any error + messages will still be shown). + +-`--srcdir=DIR' ++'--srcdir=DIR' + Look for the package's source code in directory DIR. Usually +- `configure' can determine that directory automatically. ++ 'configure' can determine that directory automatically. + +-`--prefix=DIR' +- Use DIR as the installation prefix. *note Installation Names:: +- for more details, including other options available for fine-tuning +- the installation locations. ++'--prefix=DIR' ++ Use DIR as the installation prefix. *note Installation Names:: for ++ more details, including other options available for fine-tuning the ++ installation locations. + +-`--no-create' +-`-n' ++'--no-create' ++'-n' + Run the configure checks, but stop before creating any output + files. + +-`configure' also accepts some other, not widely useful, options. Run +-`configure --help' for more details. ++'configure' also accepts some other, not widely useful, options. Run ++'configure --help' for more details. +diff --git a/install-sh b/install-sh +index 0b0fdcbba69a..ec298b537402 100755 +--- a/install-sh ++++ b/install-sh +@@ -1,7 +1,7 @@ + #!/bin/sh + # install - install a program, script, or datafile + +-scriptversion=2013-12-25.23; # UTC ++scriptversion=2020-11-14.01; # UTC + + # This originates from X11R5 (mit/util/scripts/install.sh), which was + # later released in X11R6 (xc/config/util/install.sh) with the +@@ -69,6 +69,11 @@ posix_mkdir= + # Desired mode of installed file. + mode=0755 + ++# Create dirs (including intermediate dirs) using mode 755. ++# This is like GNU 'install' as of coreutils 8.32 (2020). ++mkdir_umask=22 ++ ++backupsuffix= + chgrpcmd= + chmodcmd=$chmodprog + chowncmd= +@@ -99,18 +104,28 @@ Options: + --version display version info and exit. + + -c (ignored) +- -C install only if different (preserve the last data modification time) ++ -C install only if different (preserve data modification time) + -d create directories instead of installing files. + -g GROUP $chgrpprog installed files to GROUP. + -m MODE $chmodprog installed files to MODE. + -o USER $chownprog installed files to USER. ++ -p pass -p to $cpprog. + -s $stripprog installed files. ++ -S SUFFIX attempt to back up existing files, with suffix SUFFIX. + -t DIRECTORY install into DIRECTORY. + -T report an error if DSTFILE is a directory. + + Environment variables override the default commands: + CHGRPPROG CHMODPROG CHOWNPROG CMPPROG CPPROG MKDIRPROG MVPROG + RMPROG STRIPPROG ++ ++By default, rm is invoked with -f; when overridden with RMPROG, ++it's up to you to specify -f if you want it. ++ ++If -S is not specified, no backups are attempted. ++ ++Email bug reports to bug-automake@gnu.org. ++Automake home page: https://www.gnu.org/software/automake/ + " + + while test $# -ne 0; do +@@ -137,8 +152,13 @@ while test $# -ne 0; do + -o) chowncmd="$chownprog $2" + shift;; + ++ -p) cpprog="$cpprog -p";; ++ + -s) stripcmd=$stripprog;; + ++ -S) backupsuffix="$2" ++ shift;; ++ + -t) + is_target_a_directory=always + dst_arg=$2 +@@ -255,6 +275,10 @@ do + dstdir=$dst + test -d "$dstdir" + dstdir_status=$? ++ # Don't chown directories that already exist. ++ if test $dstdir_status = 0; then ++ chowncmd="" ++ fi + else + + # Waiting for this to be detected by the "$cpprog $src $dsttmp" command +@@ -271,15 +295,18 @@ do + fi + dst=$dst_arg + +- # If destination is a directory, append the input filename; won't work +- # if double slashes aren't ignored. ++ # If destination is a directory, append the input filename. + if test -d "$dst"; then + if test "$is_target_a_directory" = never; then + echo "$0: $dst_arg: Is a directory" >&2 + exit 1 + fi + dstdir=$dst +- dst=$dstdir/`basename "$src"` ++ dstbase=`basename "$src"` ++ case $dst in ++ */) dst=$dst$dstbase;; ++ *) dst=$dst/$dstbase;; ++ esac + dstdir_status=0 + else + dstdir=`dirname "$dst"` +@@ -288,27 +315,16 @@ do + fi + fi + ++ case $dstdir in ++ */) dstdirslash=$dstdir;; ++ *) dstdirslash=$dstdir/;; ++ esac ++ + obsolete_mkdir_used=false + + if test $dstdir_status != 0; then + case $posix_mkdir in + '') +- # Create intermediate dirs using mode 755 as modified by the umask. +- # This is like FreeBSD 'install' as of 1997-10-28. +- umask=`umask` +- case $stripcmd.$umask in +- # Optimize common cases. +- *[2367][2367]) mkdir_umask=$umask;; +- .*0[02][02] | .[02][02] | .[02]) mkdir_umask=22;; +- +- *[0-7]) +- mkdir_umask=`expr $umask + 22 \ +- - $umask % 100 % 40 + $umask % 20 \ +- - $umask % 10 % 4 + $umask % 2 +- `;; +- *) mkdir_umask=$umask,go-w;; +- esac +- + # With -d, create the new directory with the user-specified mode. + # Otherwise, rely on $mkdir_umask. + if test -n "$dir_arg"; then +@@ -318,43 +334,49 @@ do + fi + + posix_mkdir=false +- case $umask in +- *[123567][0-7][0-7]) +- # POSIX mkdir -p sets u+wx bits regardless of umask, which +- # is incompatible with FreeBSD 'install' when (umask & 300) != 0. +- ;; +- *) +- tmpdir=${TMPDIR-/tmp}/ins$RANDOM-$$ +- trap 'ret=$?; rmdir "$tmpdir/d" "$tmpdir" 2>/dev/null; exit $ret' 0 +- +- if (umask $mkdir_umask && +- exec $mkdirprog $mkdir_mode -p -- "$tmpdir/d") >/dev/null 2>&1 +- then +- if test -z "$dir_arg" || { +- # Check for POSIX incompatibilities with -m. +- # HP-UX 11.23 and IRIX 6.5 mkdir -m -p sets group- or +- # other-writable bit of parent directory when it shouldn't. +- # FreeBSD 6.1 mkdir -m -p sets mode of existing directory. +- ls_ld_tmpdir=`ls -ld "$tmpdir"` +- case $ls_ld_tmpdir in +- d????-?r-*) different_mode=700;; +- d????-?--*) different_mode=755;; +- *) false;; +- esac && +- $mkdirprog -m$different_mode -p -- "$tmpdir" && { +- ls_ld_tmpdir_1=`ls -ld "$tmpdir"` +- test "$ls_ld_tmpdir" = "$ls_ld_tmpdir_1" +- } +- } +- then posix_mkdir=: +- fi +- rmdir "$tmpdir/d" "$tmpdir" +- else +- # Remove any dirs left behind by ancient mkdir implementations. +- rmdir ./$mkdir_mode ./-p ./-- 2>/dev/null +- fi +- trap '' 0;; +- esac;; ++ # The $RANDOM variable is not portable (e.g., dash). Use it ++ # here however when possible just to lower collision chance. ++ tmpdir=${TMPDIR-/tmp}/ins$RANDOM-$$ ++ ++ trap ' ++ ret=$? ++ rmdir "$tmpdir/a/b" "$tmpdir/a" "$tmpdir" 2>/dev/null ++ exit $ret ++ ' 0 ++ ++ # Because "mkdir -p" follows existing symlinks and we likely work ++ # directly in world-writeable /tmp, make sure that the '$tmpdir' ++ # directory is successfully created first before we actually test ++ # 'mkdir -p'. ++ if (umask $mkdir_umask && ++ $mkdirprog $mkdir_mode "$tmpdir" && ++ exec $mkdirprog $mkdir_mode -p -- "$tmpdir/a/b") >/dev/null 2>&1 ++ then ++ if test -z "$dir_arg" || { ++ # Check for POSIX incompatibilities with -m. ++ # HP-UX 11.23 and IRIX 6.5 mkdir -m -p sets group- or ++ # other-writable bit of parent directory when it shouldn't. ++ # FreeBSD 6.1 mkdir -m -p sets mode of existing directory. ++ test_tmpdir="$tmpdir/a" ++ ls_ld_tmpdir=`ls -ld "$test_tmpdir"` ++ case $ls_ld_tmpdir in ++ d????-?r-*) different_mode=700;; ++ d????-?--*) different_mode=755;; ++ *) false;; ++ esac && ++ $mkdirprog -m$different_mode -p -- "$test_tmpdir" && { ++ ls_ld_tmpdir_1=`ls -ld "$test_tmpdir"` ++ test "$ls_ld_tmpdir" = "$ls_ld_tmpdir_1" ++ } ++ } ++ then posix_mkdir=: ++ fi ++ rmdir "$tmpdir/a/b" "$tmpdir/a" "$tmpdir" ++ else ++ # Remove any dirs left behind by ancient mkdir implementations. ++ rmdir ./$mkdir_mode ./-p ./-- "$tmpdir" 2>/dev/null ++ fi ++ trap '' 0;; + esac + + if +@@ -365,7 +387,7 @@ do + then : + else + +- # The umask is ridiculous, or mkdir does not conform to POSIX, ++ # mkdir does not conform to POSIX, + # or it failed possibly due to a race condition. Create the + # directory the slow way, step by step, checking for races as we go. + +@@ -394,7 +416,7 @@ do + prefixes= + else + if $posix_mkdir; then +- (umask=$mkdir_umask && ++ (umask $mkdir_umask && + $doit_exec $mkdirprog $mkdir_mode -p -- "$dstdir") && break + # Don't fail if two instances are running concurrently. + test -d "$prefix" || exit 1 +@@ -427,14 +449,25 @@ do + else + + # Make a couple of temp file names in the proper directory. +- dsttmp=$dstdir/_inst.$$_ +- rmtmp=$dstdir/_rm.$$_ ++ dsttmp=${dstdirslash}_inst.$$_ ++ rmtmp=${dstdirslash}_rm.$$_ + + # Trap to clean up those temp files at exit. + trap 'ret=$?; rm -f "$dsttmp" "$rmtmp" && exit $ret' 0 + + # Copy the file name to the temp name. +- (umask $cp_umask && $doit_exec $cpprog "$src" "$dsttmp") && ++ (umask $cp_umask && ++ { test -z "$stripcmd" || { ++ # Create $dsttmp read-write so that cp doesn't create it read-only, ++ # which would cause strip to fail. ++ if test -z "$doit"; then ++ : >"$dsttmp" # No need to fork-exec 'touch'. ++ else ++ $doit touch "$dsttmp" ++ fi ++ } ++ } && ++ $doit_exec $cpprog "$src" "$dsttmp") && + + # and set any options; do chmod last to preserve setuid bits. + # +@@ -460,6 +493,13 @@ do + then + rm -f "$dsttmp" + else ++ # If $backupsuffix is set, and the file being installed ++ # already exists, attempt a backup. Don't worry if it fails, ++ # e.g., if mv doesn't support -f. ++ if test -n "$backupsuffix" && test -f "$dst"; then ++ $doit $mvcmd -f "$dst" "$dst$backupsuffix" 2>/dev/null ++ fi ++ + # Rename the file to the real destination. + $doit $mvcmd -f "$dsttmp" "$dst" 2>/dev/null || + +@@ -474,9 +514,9 @@ do + # file should still install successfully. + { + test ! -f "$dst" || +- $doit $rmcmd -f "$dst" 2>/dev/null || ++ $doit $rmcmd "$dst" 2>/dev/null || + { $doit $mvcmd -f "$dst" "$rmtmp" 2>/dev/null && +- { $doit $rmcmd -f "$rmtmp" 2>/dev/null; :; } ++ { $doit $rmcmd "$rmtmp" 2>/dev/null; :; } + } || + { echo "$0: cannot unlink or rename $dst" >&2 + (exit 1); exit 1 +@@ -493,9 +533,9 @@ do + done + + # Local variables: +-# eval: (add-hook 'write-file-hooks 'time-stamp) ++# eval: (add-hook 'before-save-hook 'time-stamp) + # time-stamp-start: "scriptversion=" + # time-stamp-format: "%:y-%02m-%02d.%02H" +-# time-stamp-time-zone: "UTC" ++# time-stamp-time-zone: "UTC0" + # time-stamp-end: "; # UTC" + # End: +diff --git a/missing b/missing +index b7e571efa44e..1fe1611f1851 100755 +--- a/missing ++++ b/missing +@@ -1,9 +1,9 @@ +-#!/bin/sh ++#! /bin/sh + # Common wrapper for a few potentially missing GNU programs. + +-scriptversion=2016-01-11.22; # UTC ++scriptversion=2018-03-07.03; # UTC + +-# Copyright (C) 1996-2017 Free Software Foundation, Inc. ++# Copyright (C) 1996-2021 Free Software Foundation, Inc. + # Originally written by Fran,cois Pinard , 1996. + + # This program is free software; you can redistribute it and/or modify +@@ -17,7 +17,7 @@ scriptversion=2016-01-11.22; # UTC + # GNU General Public License for more details. + + # You should have received a copy of the GNU General Public License +-# along with this program. If not, see . ++# along with this program. If not, see . + + # As a special exception to the GNU General Public License, if you + # distribute this file as part of a program that contains a +@@ -101,9 +101,9 @@ else + exit $st + fi + +-perl_URL=http://www.perl.org/ +-flex_URL=http://flex.sourceforge.net/ +-gnu_software_URL=http://www.gnu.org/software ++perl_URL=https://www.perl.org/ ++flex_URL=https://github.com/westes/flex ++gnu_software_URL=https://www.gnu.org/software + + program_details () + { +@@ -207,7 +207,7 @@ give_advice "$1" | sed -e '1s/^/WARNING: /' \ + exit $st + + # Local variables: +-# eval: (add-hook 'write-file-hooks 'time-stamp) ++# eval: (add-hook 'before-save-hook 'time-stamp) + # time-stamp-start: "scriptversion=" + # time-stamp-format: "%:y-%02m-%02d.%02H" + # time-stamp-time-zone: "UTC0" +diff --git a/py-compile b/py-compile +index bc2039140b6c..81b122b0a546 100755 +--- a/py-compile ++++ b/py-compile +@@ -1,9 +1,9 @@ + #!/bin/sh + # py-compile - Compile a Python program + +-scriptversion=2011-06-08.12; # UTC ++scriptversion=2021-02-27.01; # UTC + +-# Copyright (C) 2000-2014 Free Software Foundation, Inc. ++# Copyright (C) 2000-2021 Free Software Foundation, Inc. + + # This program is free software; you can redistribute it and/or modify + # it under the terms of the GNU General Public License as published by +@@ -16,7 +16,7 @@ scriptversion=2011-06-08.12; # UTC + # GNU General Public License for more details. + + # You should have received a copy of the GNU General Public License +-# along with this program. If not, see . ++# along with this program. If not, see . + + # As a special exception to the GNU General Public License, if you + # distribute this file as part of a program that contains a +@@ -27,7 +27,7 @@ scriptversion=2011-06-08.12; # UTC + # bugs to or send patches to + # . + +-if [ -z "$PYTHON" ]; then ++if test -z "$PYTHON"; then + PYTHON=python + fi + +@@ -96,27 +96,46 @@ done + + files=$* + if test -z "$files"; then +- usage_error "no files given" ++ usage_error "no files given" + fi + + # if basedir was given, then it should be prepended to filenames before + # byte compilation. +-if [ -z "$basedir" ]; then +- pathtrans="path = file" ++if test -z "$basedir"; then ++ pathtrans="path = file" + else +- pathtrans="path = os.path.join('$basedir', file)" ++ pathtrans="path = os.path.join('$basedir', file)" + fi + + # if destdir was given, then it needs to be prepended to the filename to + # byte compile but not go into the compiled file. +-if [ -z "$destdir" ]; then +- filetrans="filepath = path" ++if test -z "$destdir"; then ++ filetrans="filepath = path" + else +- filetrans="filepath = os.path.normpath('$destdir' + os.sep + path)" ++ filetrans="filepath = os.path.normpath('$destdir' + os.sep + path)" ++fi ++ ++python_major=`$PYTHON -V 2>&1 | sed -e 's/.* //;s/\..*$//;1q'` ++if test -z "$python_major"; then ++ echo "$me: could not determine $PYTHON major version, guessing 3" >&2 ++ python_major=3 ++fi ++ ++# The old way to import libraries was deprecated. ++if test "$python_major" -le 2; then ++ import_lib=imp ++ import_test="hasattr(imp, 'get_tag')" ++ import_call=imp.cache_from_source ++ import_arg2=', False' # needed in one call and not the other ++else ++ import_lib=importlib ++ import_test="hasattr(sys.implementation, 'cache_tag')" ++ import_call=importlib.util.cache_from_source ++ import_arg2= + fi + + $PYTHON -c " +-import sys, os, py_compile, imp ++import sys, os, py_compile, $import_lib + + files = '''$files''' + +@@ -129,15 +148,15 @@ for file in files.split(): + continue + sys.stdout.write(file) + sys.stdout.flush() +- if hasattr(imp, 'get_tag'): +- py_compile.compile(filepath, imp.cache_from_source(filepath), path) ++ if $import_test: ++ py_compile.compile(filepath, $import_call(filepath), path) + else: + py_compile.compile(filepath, filepath + 'c', path) + sys.stdout.write('\n')" || exit $? + + # this will fail for python < 1.5, but that doesn't matter ... + $PYTHON -O -c " +-import sys, os, py_compile, imp ++import sys, os, py_compile, $import_lib + + # pypy does not use .pyo optimization + if hasattr(sys, 'pypy_translation_info'): +@@ -153,18 +172,18 @@ for file in files.split(): + continue + sys.stdout.write(file) + sys.stdout.flush() +- if hasattr(imp, 'get_tag'): +- py_compile.compile(filepath, imp.cache_from_source(filepath, False), path) ++ if $import_test: ++ py_compile.compile(filepath, $import_call(filepath$import_arg2), path) + else: + py_compile.compile(filepath, filepath + 'o', path) +-sys.stdout.write('\n')" 2>/dev/null || : ++sys.stdout.write('\n')" 2>/dev/null || exit $? + + # Local Variables: + # mode: shell-script + # sh-indentation: 2 +-# eval: (add-hook 'write-file-hooks 'time-stamp) ++# eval: (add-hook 'before-save-hook 'time-stamp) + # time-stamp-start: "scriptversion=" + # time-stamp-format: "%:y-%02m-%02d.%02H" +-# time-stamp-time-zone: "UTC" ++# time-stamp-time-zone: "UTC0" + # time-stamp-end: "; # UTC" + # End: +-- +2.41.0 + diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 4e793ed..44deaf3 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,13 +6,15 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.14 -Release: 7%{?dist} +Release: 8%{?dist} License: GPL-2.0-or-later URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz # git format-patch -N setroubleshoot-plugins- -- plugins # i=1; for j in 00*patch; do printf "Patch%04d: %s\n" $i $j; i=$((i+1));done Patch0001: 0001-restorecon.py-exclude-more-paths.patch +Patch0002: 0002-Improve-disable_ipv6-plugin-then_text.patch +Patch0003: 0003-Update-generated-configuration-files.patch BuildArch: noarch # gcc is needed only for ./configure @@ -50,6 +52,10 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Wed Jul 26 2023 Petr Lautrbach - 3.3.14-8 +- Update generated configuration files (rhbz#2226425) +- Improve disable_ipv6 plugin then_text + * Sat Jul 22 2023 Fedora Release Engineering - 3.3.14-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild From 007557e46ea508e3a904919e31ee535bd677d979 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 27 Jan 2024 02:41:44 +0000 Subject: [PATCH 12/24] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 44deaf3..80110d6 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.14 -Release: 8%{?dist} +Release: 9%{?dist} License: GPL-2.0-or-later URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz @@ -52,6 +52,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Sat Jan 27 2024 Fedora Release Engineering - 3.3.14-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Wed Jul 26 2023 Petr Lautrbach - 3.3.14-8 - Update generated configuration files (rhbz#2226425) - Improve disable_ipv6 plugin then_text From 2ad1062d72c53aad0ffbc0d9a5d07b1b0b96b314 Mon Sep 17 00:00:00 2001 From: Milos Malik Date: Tue, 2 Apr 2024 13:24:41 +0200 Subject: [PATCH 13/24] run the existing tests via TMT/FMF Use the TMT/FMF instead of STI for running tests. STI does not respect the adjust section in main.fmf files of stored tests. Add missing main.fmf files to tests which are not TMT/FMF enabled. --- .fmf/version | 1 + plans/tests.fmf | 6 +++++ .../use-of-aliases-in-plugins/main.fmf | 25 +++++++++++++++++++ .../use-of-aliases-in-plugins/runtest.sh | 1 - 4 files changed, 32 insertions(+), 1 deletion(-) create mode 100644 .fmf/version create mode 100644 plans/tests.fmf create mode 100644 tests/Regression/use-of-aliases-in-plugins/main.fmf diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/plans/tests.fmf b/plans/tests.fmf new file mode 100644 index 0000000..7d8f9cd --- /dev/null +++ b/plans/tests.fmf @@ -0,0 +1,6 @@ +summary: basic setroubleshoot-plugins test plan +discover: + how: fmf +execute: + how: tmt + diff --git a/tests/Regression/use-of-aliases-in-plugins/main.fmf b/tests/Regression/use-of-aliases-in-plugins/main.fmf new file mode 100644 index 0000000..8bd3e77 --- /dev/null +++ b/tests/Regression/use-of-aliases-in-plugins/main.fmf @@ -0,0 +1,25 @@ +summary: test types and aliases used in plugins +description: |+ + Make sure all types used in setroubleshoot plugins are defined in the policy and are not aliases + +contact: Vit Mojzis +component: + - setroubleshoot-plugins +test: ./runtest.sh +framework: beakerlib +recommend: + - libselinux-utils + - python3-policycoreutils + - setroubleshoot-plugins +duration: 15m +enabled: true +tag: + - NoRHEL4 + - NoRHEL5 + - NoRHEL6 + - NoRHEL7 + - targeted +adjust: + - enabled: false + when: distro == rhel-4, rhel-5, rhel-6, rhel-7 + continue: false diff --git a/tests/Regression/use-of-aliases-in-plugins/runtest.sh b/tests/Regression/use-of-aliases-in-plugins/runtest.sh index 5720f99..b540e6b 100755 --- a/tests/Regression/use-of-aliases-in-plugins/runtest.sh +++ b/tests/Regression/use-of-aliases-in-plugins/runtest.sh @@ -27,7 +27,6 @@ # ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ # Include Beaker environment -. /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 PACKAGE="setroubleshoot-plugins" From 0138d422b686546e80a783586b6b3015091e342b Mon Sep 17 00:00:00 2001 From: Milos Malik Date: Wed, 17 Apr 2024 09:55:06 +0200 Subject: [PATCH 14/24] remove the unnecessary tests.yaml file The repository already contains a TMT test plan (/plans/tests.fmf) which replaces the tests.yaml file. Let's leave the old STI way of running tests finally. --- tests/tests.yml | 11 ----------- 1 file changed, 11 deletions(-) delete mode 100644 tests/tests.yml diff --git a/tests/tests.yml b/tests/tests.yml deleted file mode 100644 index cc1af99..0000000 --- a/tests/tests.yml +++ /dev/null @@ -1,11 +0,0 @@ -- hosts: localhost - roles: - - role: standard-test-beakerlib - tags: - - classic - tests: - - Regression/use-of-aliases-in-plugins - required_packages: - - setroubleshoot-plugins - - selinux-policy-targeted - - python3-policycoreutils From 6ea678f88f5d5837b54aefee0b5fe455f0ac4878 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 20 Jul 2024 05:18:40 +0000 Subject: [PATCH 15/24] Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 80110d6..e775cbf 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.14 -Release: 9%{?dist} +Release: 10%{?dist} License: GPL-2.0-or-later URL: https://github.com/fedora-selinux/setroubleshoot Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz @@ -52,6 +52,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Sat Jul 20 2024 Fedora Release Engineering - 3.3.14-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + * Sat Jan 27 2024 Fedora Release Engineering - 3.3.14-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From ae45697aee8d3fa6a95647a0347d650f1a2ae373 Mon Sep 17 00:00:00 2001 From: Petr Lautrbach Date: Mon, 6 Jan 2025 14:53:46 +0100 Subject: [PATCH 16/24] setroubleshoot-plugin-3.3.15 - restorecon.py: exclude more paths - Improve disable_ipv6 plugin then_text - Update generated configuration files - Update translations --- .gitignore | 1 + 0001-restorecon.py-exclude-more-paths.patch | 26 - ...mprove-disable_ipv6-plugin-then_text.patch | 29 - ...Update-generated-configuration-files.patch | 1036 ----------------- setroubleshoot-plugins.spec | 17 +- sources | 2 +- 6 files changed, 12 insertions(+), 1099 deletions(-) delete mode 100644 0001-restorecon.py-exclude-more-paths.patch delete mode 100644 0002-Improve-disable_ipv6-plugin-then_text.patch delete mode 100644 0003-Update-generated-configuration-files.patch diff --git a/.gitignore b/.gitignore index a58a8e6..e0500d1 100644 --- a/.gitignore +++ b/.gitignore @@ -123,3 +123,4 @@ setroubleshoot-plugins-2.1.55.tar.gz /setroubleshoot-plugins-3.3.11.tar.gz /setroubleshoot-plugins-3.3.12.tar.gz /setroubleshoot-plugins-3.3.14.tar.gz +/setroubleshoot-plugins-3.3.15.tar.gz diff --git a/0001-restorecon.py-exclude-more-paths.patch b/0001-restorecon.py-exclude-more-paths.patch deleted file mode 100644 index 2189d21..0000000 --- a/0001-restorecon.py-exclude-more-paths.patch +++ /dev/null @@ -1,26 +0,0 @@ -From 0f508191647a41f92264c0c8fc877b0110bbd468 Mon Sep 17 00:00:00 2001 -From: Petr Lautrbach -Date: Tue, 10 Aug 2021 20:11:20 +0200 -Subject: [PATCH] restorecon.py: exclude more paths - -It doesn't make sense to run restorecon on /sys/ /proc/ and /memfd: ---- - src/restorecon.py | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/restorecon.py b/src/restorecon.py -index e3044c742367..9594c0d59d96 100644 ---- a/src/restorecon.py -+++ b/src/restorecon.py -@@ -39,7 +39,7 @@ def customizable(target): - - - # List of path prefixes for which this plugin is not executed --excluded_paths = ["/sys/fs"] -+excluded_paths = ["/sys/", "/proc/", "/memfd:"] - # Test if the specified path starts with some excluded prefix - def excluded_path(target_path): - for path in excluded_paths: --- -2.32.0 - diff --git a/0002-Improve-disable_ipv6-plugin-then_text.patch b/0002-Improve-disable_ipv6-plugin-then_text.patch deleted file mode 100644 index 697aabd..0000000 --- a/0002-Improve-disable_ipv6-plugin-then_text.patch +++ /dev/null @@ -1,29 +0,0 @@ -From f8a5ef9b783f4be5fcb2fa711dd3b550b312a629 Mon Sep 17 00:00:00 2001 -From: Vit Mojzis -Date: Wed, 23 Nov 2022 18:25:20 +0100 -Subject: [PATCH] Improve disable_ipv6 plugin then_text -Content-type: text/plain - -Use more conscious language and be more explicit. - -Signed-off-by: Vit Mojzis ---- - src/disable_ipv6.py | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/disable_ipv6.py b/src/disable_ipv6.py -index 1c858213ddea..ca0b9cc7f49f 100644 ---- a/src/disable_ipv6.py -+++ b/src/disable_ipv6.py -@@ -38,7 +38,7 @@ Disable IPV6 properly. - fix_cmd = "" - - if_text = _("If you want to disable IPV6 on this machine") -- then_text = _("you need to set /proc/sys/net/ipv6/conf/all/disable_ipv6 to 1 and do not blacklist the module'") -+ then_text = _("you need to set /proc/sys/net/ipv6/conf/all/disable_ipv6 to 1 and do not disable the ipv6 kernel module'") - do_text = _("""Add - net.ipv6.conf.all.disable_ipv6 = 1 - to /etc/sysctl.conf --- -2.41.0 - diff --git a/0003-Update-generated-configuration-files.patch b/0003-Update-generated-configuration-files.patch deleted file mode 100644 index 75b7aed..0000000 --- a/0003-Update-generated-configuration-files.patch +++ /dev/null @@ -1,1036 +0,0 @@ -From 9e54f6a661330070ad25a0e86f197b3530bfc5c7 Mon Sep 17 00:00:00 2001 -From: Petr Lautrbach -Date: Wed, 26 Jul 2023 10:30:07 +0200 -Subject: [PATCH] Update generated configuration files -Content-type: text/plain - -Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=2226425 - - Traceback (most recent call last): - File "", line 2, in - ModuleNotFoundError: No module named 'imp' - make[2]: *** [Makefile:372: install-pluginPYTHON] Error 1 ---- - INSTALL | 320 ++++++++++++++++++++++++++--------------------------- - install-sh | 174 ++++++++++++++++++----------- - missing | 16 +-- - py-compile | 59 ++++++---- - 4 files changed, 313 insertions(+), 256 deletions(-) - -diff --git a/INSTALL b/INSTALL -index 2099840756e6..e82fd21de2ea 100644 ---- a/INSTALL -+++ b/INSTALL -@@ -1,8 +1,8 @@ - Installation Instructions - ************************* - --Copyright (C) 1994-1996, 1999-2002, 2004-2013 Free Software Foundation, --Inc. -+ Copyright (C) 1994-1996, 1999-2002, 2004-2017, 2020-2021 Free -+Software Foundation, Inc. - - Copying and distribution of this file, with or without modification, - are permitted in any medium without royalty provided the copyright -@@ -12,97 +12,96 @@ without warranty of any kind. - Basic Installation - ================== - -- Briefly, the shell command `./configure && make && make install' -+ Briefly, the shell command './configure && make && make install' - should configure, build, and install this package. The following --more-detailed instructions are generic; see the `README' file for -+more-detailed instructions are generic; see the 'README' file for - instructions specific to this package. Some packages provide this --`INSTALL' file but do not implement all of the features documented -+'INSTALL' file but do not implement all of the features documented - below. The lack of an optional feature in a given package is not - necessarily a bug. More recommendations for GNU packages can be found - in *note Makefile Conventions: (standards)Makefile Conventions. - -- The `configure' shell script attempts to guess correct values for -+ The 'configure' shell script attempts to guess correct values for - various system-dependent variables used during compilation. It uses --those values to create a `Makefile' in each directory of the package. --It may also create one or more `.h' files containing system-dependent --definitions. Finally, it creates a shell script `config.status' that -+those values to create a 'Makefile' in each directory of the package. -+It may also create one or more '.h' files containing system-dependent -+definitions. Finally, it creates a shell script 'config.status' that - you can run in the future to recreate the current configuration, and a --file `config.log' containing compiler output (useful mainly for --debugging `configure'). -+file 'config.log' containing compiler output (useful mainly for -+debugging 'configure'). - -- It can also use an optional file (typically called `config.cache' --and enabled with `--cache-file=config.cache' or simply `-C') that saves --the results of its tests to speed up reconfiguring. Caching is --disabled by default to prevent problems with accidental use of stale --cache files. -+ It can also use an optional file (typically called 'config.cache' and -+enabled with '--cache-file=config.cache' or simply '-C') that saves the -+results of its tests to speed up reconfiguring. Caching is disabled by -+default to prevent problems with accidental use of stale cache files. - - If you need to do unusual things to compile the package, please try --to figure out how `configure' could check whether to do them, and mail --diffs or instructions to the address given in the `README' so they can -+to figure out how 'configure' could check whether to do them, and mail -+diffs or instructions to the address given in the 'README' so they can - be considered for the next release. If you are using the cache, and at --some point `config.cache' contains results you don't want to keep, you -+some point 'config.cache' contains results you don't want to keep, you - may remove or edit it. - -- The file `configure.ac' (or `configure.in') is used to create --`configure' by a program called `autoconf'. You need `configure.ac' if --you want to change it or regenerate `configure' using a newer version --of `autoconf'. -+ The file 'configure.ac' (or 'configure.in') is used to create -+'configure' by a program called 'autoconf'. You need 'configure.ac' if -+you want to change it or regenerate 'configure' using a newer version of -+'autoconf'. - - The simplest way to compile this package is: - -- 1. `cd' to the directory containing the package's source code and type -- `./configure' to configure the package for your system. -+ 1. 'cd' to the directory containing the package's source code and type -+ './configure' to configure the package for your system. - -- Running `configure' might take a while. While running, it prints -+ Running 'configure' might take a while. While running, it prints - some messages telling which features it is checking for. - -- 2. Type `make' to compile the package. -+ 2. Type 'make' to compile the package. - -- 3. Optionally, type `make check' to run any self-tests that come with -+ 3. Optionally, type 'make check' to run any self-tests that come with - the package, generally using the just-built uninstalled binaries. - -- 4. Type `make install' to install the programs and any data files and -+ 4. Type 'make install' to install the programs and any data files and - documentation. When installing into a prefix owned by root, it is - recommended that the package be configured and built as a regular -- user, and only the `make install' phase executed with root -+ user, and only the 'make install' phase executed with root - privileges. - -- 5. Optionally, type `make installcheck' to repeat any self-tests, but -+ 5. Optionally, type 'make installcheck' to repeat any self-tests, but - this time using the binaries in their final installed location. - This target does not install anything. Running this target as a -- regular user, particularly if the prior `make install' required -+ regular user, particularly if the prior 'make install' required - root privileges, verifies that the installation completed - correctly. - - 6. You can remove the program binaries and object files from the -- source code directory by typing `make clean'. To also remove the -- files that `configure' created (so you can compile the package for -- a different kind of computer), type `make distclean'. There is -- also a `make maintainer-clean' target, but that is intended mainly -+ source code directory by typing 'make clean'. To also remove the -+ files that 'configure' created (so you can compile the package for -+ a different kind of computer), type 'make distclean'. There is -+ also a 'make maintainer-clean' target, but that is intended mainly - for the package's developers. If you use it, you may have to get - all sorts of other programs in order to regenerate files that came - with the distribution. - -- 7. Often, you can also type `make uninstall' to remove the installed -+ 7. Often, you can also type 'make uninstall' to remove the installed - files again. In practice, not all packages have tested that - uninstallation works correctly, even though it is required by the - GNU Coding Standards. - -- 8. Some packages, particularly those that use Automake, provide `make -+ 8. Some packages, particularly those that use Automake, provide 'make - distcheck', which can by used by developers to test that all other -- targets like `make install' and `make uninstall' work correctly. -+ targets like 'make install' and 'make uninstall' work correctly. - This target is generally not run by end users. - - Compilers and Options - ===================== - - Some systems require unusual options for compilation or linking that --the `configure' script does not know about. Run `./configure --help' -+the 'configure' script does not know about. Run './configure --help' - for details on some of the pertinent environment variables. - -- You can give `configure' initial values for configuration parameters --by setting variables in the command line or in the environment. Here --is an example: -+ You can give 'configure' initial values for configuration parameters -+by setting variables in the command line or in the environment. Here is -+an example: - - ./configure CC=c99 CFLAGS=-g LIBS=-lposix - -@@ -113,21 +112,21 @@ Compiling For Multiple Architectures - - You can compile the package for more than one kind of computer at the - same time, by placing the object files for each architecture in their --own directory. To do this, you can use GNU `make'. `cd' to the -+own directory. To do this, you can use GNU 'make'. 'cd' to the - directory where you want the object files and executables to go and run --the `configure' script. `configure' automatically checks for the --source code in the directory that `configure' is in and in `..'. This --is known as a "VPATH" build. -+the 'configure' script. 'configure' automatically checks for the source -+code in the directory that 'configure' is in and in '..'. This is known -+as a "VPATH" build. - -- With a non-GNU `make', it is safer to compile the package for one -+ With a non-GNU 'make', it is safer to compile the package for one - architecture at a time in the source code directory. After you have --installed the package for one architecture, use `make distclean' before -+installed the package for one architecture, use 'make distclean' before - reconfiguring for another architecture. - - On MacOS X 10.5 and later systems, you can create libraries and - executables that work on multiple system types--known as "fat" or --"universal" binaries--by specifying multiple `-arch' options to the --compiler but only a single `-arch' option to the preprocessor. Like -+"universal" binaries--by specifying multiple '-arch' options to the -+compiler but only a single '-arch' option to the preprocessor. Like - this: - - ./configure CC="gcc -arch i386 -arch x86_64 -arch ppc -arch ppc64" \ -@@ -136,105 +135,104 @@ this: - - This is not guaranteed to produce working output in all cases, you - may have to build one architecture at a time and combine the results --using the `lipo' tool if you have problems. -+using the 'lipo' tool if you have problems. - - Installation Names - ================== - -- By default, `make install' installs the package's commands under --`/usr/local/bin', include files under `/usr/local/include', etc. You --can specify an installation prefix other than `/usr/local' by giving --`configure' the option `--prefix=PREFIX', where PREFIX must be an -+ By default, 'make install' installs the package's commands under -+'/usr/local/bin', include files under '/usr/local/include', etc. You -+can specify an installation prefix other than '/usr/local' by giving -+'configure' the option '--prefix=PREFIX', where PREFIX must be an - absolute file name. - - You can specify separate installation prefixes for - architecture-specific files and architecture-independent files. If you --pass the option `--exec-prefix=PREFIX' to `configure', the package uses -+pass the option '--exec-prefix=PREFIX' to 'configure', the package uses - PREFIX as the prefix for installing programs and libraries. - Documentation and other data files still use the regular prefix. - - In addition, if you use an unusual directory layout you can give --options like `--bindir=DIR' to specify different values for particular --kinds of files. Run `configure --help' for a list of the directories --you can set and what kinds of files go in them. In general, the --default for these options is expressed in terms of `${prefix}', so that --specifying just `--prefix' will affect all of the other directory -+options like '--bindir=DIR' to specify different values for particular -+kinds of files. Run 'configure --help' for a list of the directories -+you can set and what kinds of files go in them. In general, the default -+for these options is expressed in terms of '${prefix}', so that -+specifying just '--prefix' will affect all of the other directory - specifications that were not explicitly provided. - - The most portable way to affect installation locations is to pass the --correct locations to `configure'; however, many packages provide one or -+correct locations to 'configure'; however, many packages provide one or - both of the following shortcuts of passing variable assignments to the --`make install' command line to change installation locations without -+'make install' command line to change installation locations without - having to reconfigure or recompile. - - The first method involves providing an override variable for each --affected directory. For example, `make install -+affected directory. For example, 'make install - prefix=/alternate/directory' will choose an alternate location for all - directory configuration variables that were expressed in terms of --`${prefix}'. Any directories that were specified during `configure', --but not in terms of `${prefix}', must each be overridden at install --time for the entire installation to be relocated. The approach of --makefile variable overrides for each directory variable is required by --the GNU Coding Standards, and ideally causes no recompilation. --However, some platforms have known limitations with the semantics of --shared libraries that end up requiring recompilation when using this --method, particularly noticeable in packages that use GNU Libtool. -- -- The second method involves providing the `DESTDIR' variable. For --example, `make install DESTDIR=/alternate/directory' will prepend --`/alternate/directory' before all installation names. The approach of --`DESTDIR' overrides is not required by the GNU Coding Standards, and -+'${prefix}'. Any directories that were specified during 'configure', -+but not in terms of '${prefix}', must each be overridden at install time -+for the entire installation to be relocated. The approach of makefile -+variable overrides for each directory variable is required by the GNU -+Coding Standards, and ideally causes no recompilation. However, some -+platforms have known limitations with the semantics of shared libraries -+that end up requiring recompilation when using this method, particularly -+noticeable in packages that use GNU Libtool. -+ -+ The second method involves providing the 'DESTDIR' variable. For -+example, 'make install DESTDIR=/alternate/directory' will prepend -+'/alternate/directory' before all installation names. The approach of -+'DESTDIR' overrides is not required by the GNU Coding Standards, and - does not work on platforms that have drive letters. On the other hand, - it does better at avoiding recompilation issues, and works well even --when some directory options were not specified in terms of `${prefix}' --at `configure' time. -+when some directory options were not specified in terms of '${prefix}' -+at 'configure' time. - - Optional Features - ================= - - If the package supports it, you can cause programs to be installed --with an extra prefix or suffix on their names by giving `configure' the --option `--program-prefix=PREFIX' or `--program-suffix=SUFFIX'. -- -- Some packages pay attention to `--enable-FEATURE' options to --`configure', where FEATURE indicates an optional part of the package. --They may also pay attention to `--with-PACKAGE' options, where PACKAGE --is something like `gnu-as' or `x' (for the X Window System). The --`README' should mention any `--enable-' and `--with-' options that the -+with an extra prefix or suffix on their names by giving 'configure' the -+option '--program-prefix=PREFIX' or '--program-suffix=SUFFIX'. -+ -+ Some packages pay attention to '--enable-FEATURE' options to -+'configure', where FEATURE indicates an optional part of the package. -+They may also pay attention to '--with-PACKAGE' options, where PACKAGE -+is something like 'gnu-as' or 'x' (for the X Window System). The -+'README' should mention any '--enable-' and '--with-' options that the - package recognizes. - -- For packages that use the X Window System, `configure' can usually -+ For packages that use the X Window System, 'configure' can usually - find the X include and library files automatically, but if it doesn't, --you can use the `configure' options `--x-includes=DIR' and --`--x-libraries=DIR' to specify their locations. -+you can use the 'configure' options '--x-includes=DIR' and -+'--x-libraries=DIR' to specify their locations. - - Some packages offer the ability to configure how verbose the --execution of `make' will be. For these packages, running `./configure -+execution of 'make' will be. For these packages, running './configure - --enable-silent-rules' sets the default to minimal output, which can be --overridden with `make V=1'; while running `./configure -+overridden with 'make V=1'; while running './configure - --disable-silent-rules' sets the default to verbose, which can be --overridden with `make V=0'. -+overridden with 'make V=0'. - - Particular systems - ================== - -- On HP-UX, the default C compiler is not ANSI C compatible. If GNU --CC is not installed, it is recommended to use the following options in -+ On HP-UX, the default C compiler is not ANSI C compatible. If GNU CC -+is not installed, it is recommended to use the following options in - order to use an ANSI C compiler: - - ./configure CC="cc -Ae -D_XOPEN_SOURCE=500" - - and if that doesn't work, install pre-built binaries of GCC for HP-UX. - -- HP-UX `make' updates targets which have the same time stamps as --their prerequisites, which makes it generally unusable when shipped --generated files such as `configure' are involved. Use GNU `make' --instead. -+ HP-UX 'make' updates targets which have the same timestamps as their -+prerequisites, which makes it generally unusable when shipped generated -+files such as 'configure' are involved. Use GNU 'make' instead. - - On OSF/1 a.k.a. Tru64, some versions of the default C compiler cannot --parse its `' header file. The option `-nodtk' can be used as --a workaround. If GNU CC is not installed, it is therefore recommended --to try -+parse its '' header file. The option '-nodtk' can be used as a -+workaround. If GNU CC is not installed, it is therefore recommended to -+try - - ./configure CC="cc" - -@@ -242,26 +240,26 @@ and if that doesn't work, try - - ./configure CC="cc -nodtk" - -- On Solaris, don't put `/usr/ucb' early in your `PATH'. This -+ On Solaris, don't put '/usr/ucb' early in your 'PATH'. This - directory contains several dysfunctional programs; working variants of --these programs are available in `/usr/bin'. So, if you need `/usr/ucb' --in your `PATH', put it _after_ `/usr/bin'. -+these programs are available in '/usr/bin'. So, if you need '/usr/ucb' -+in your 'PATH', put it _after_ '/usr/bin'. - -- On Haiku, software installed for all users goes in `/boot/common', --not `/usr/local'. It is recommended to use the following options: -+ On Haiku, software installed for all users goes in '/boot/common', -+not '/usr/local'. It is recommended to use the following options: - - ./configure --prefix=/boot/common - - Specifying the System Type - ========================== - -- There may be some features `configure' cannot figure out -+ There may be some features 'configure' cannot figure out - automatically, but needs to determine by the type of machine the package - will run on. Usually, assuming the package is built to be run on the --_same_ architectures, `configure' can figure that out, but if it prints -+_same_ architectures, 'configure' can figure that out, but if it prints - a message saying it cannot guess the machine type, give it the --`--build=TYPE' option. TYPE can either be a short name for the system --type, such as `sun4', or a canonical name which has the form: -+'--build=TYPE' option. TYPE can either be a short name for the system -+type, such as 'sun4', or a canonical name which has the form: - - CPU-COMPANY-SYSTEM - -@@ -270,101 +268,101 @@ where SYSTEM can have one of these forms: - OS - KERNEL-OS - -- See the file `config.sub' for the possible values of each field. If --`config.sub' isn't included in this package, then this package doesn't -+ See the file 'config.sub' for the possible values of each field. If -+'config.sub' isn't included in this package, then this package doesn't - need to know the machine type. - - If you are _building_ compiler tools for cross-compiling, you should --use the option `--target=TYPE' to select the type of system they will -+use the option '--target=TYPE' to select the type of system they will - produce code for. - - If you want to _use_ a cross compiler, that generates code for a - platform different from the build platform, you should specify the - "host" platform (i.e., that on which the generated programs will --eventually be run) with `--host=TYPE'. -+eventually be run) with '--host=TYPE'. - - Sharing Defaults - ================ - -- If you want to set default values for `configure' scripts to share, --you can create a site shell script called `config.site' that gives --default values for variables like `CC', `cache_file', and `prefix'. --`configure' looks for `PREFIX/share/config.site' if it exists, then --`PREFIX/etc/config.site' if it exists. Or, you can set the --`CONFIG_SITE' environment variable to the location of the site script. --A warning: not all `configure' scripts look for a site script. -+ If you want to set default values for 'configure' scripts to share, -+you can create a site shell script called 'config.site' that gives -+default values for variables like 'CC', 'cache_file', and 'prefix'. -+'configure' looks for 'PREFIX/share/config.site' if it exists, then -+'PREFIX/etc/config.site' if it exists. Or, you can set the -+'CONFIG_SITE' environment variable to the location of the site script. -+A warning: not all 'configure' scripts look for a site script. - - Defining Variables - ================== - - Variables not defined in a site shell script can be set in the --environment passed to `configure'. However, some packages may run -+environment passed to 'configure'. However, some packages may run - configure again during the build, and the customized values of these - variables may be lost. In order to avoid this problem, you should set --them in the `configure' command line, using `VAR=value'. For example: -+them in the 'configure' command line, using 'VAR=value'. For example: - - ./configure CC=/usr/local2/bin/gcc - --causes the specified `gcc' to be used as the C compiler (unless it is -+causes the specified 'gcc' to be used as the C compiler (unless it is - overridden in the site shell script). - --Unfortunately, this technique does not work for `CONFIG_SHELL' due to --an Autoconf limitation. Until the limitation is lifted, you can use --this workaround: -+Unfortunately, this technique does not work for 'CONFIG_SHELL' due to an -+Autoconf limitation. Until the limitation is lifted, you can use this -+workaround: - - CONFIG_SHELL=/bin/bash ./configure CONFIG_SHELL=/bin/bash - --`configure' Invocation -+'configure' Invocation - ====================== - -- `configure' recognizes the following options to control how it -+ 'configure' recognizes the following options to control how it - operates. - --`--help' --`-h' -- Print a summary of all of the options to `configure', and exit. -+'--help' -+'-h' -+ Print a summary of all of the options to 'configure', and exit. - --`--help=short' --`--help=recursive' -+'--help=short' -+'--help=recursive' - Print a summary of the options unique to this package's -- `configure', and exit. The `short' variant lists options used -- only in the top level, while the `recursive' variant lists options -- also present in any nested packages. -+ 'configure', and exit. The 'short' variant lists options used only -+ in the top level, while the 'recursive' variant lists options also -+ present in any nested packages. - --`--version' --`-V' -- Print the version of Autoconf used to generate the `configure' -+'--version' -+'-V' -+ Print the version of Autoconf used to generate the 'configure' - script, and exit. - --`--cache-file=FILE' -+'--cache-file=FILE' - Enable the cache: use and save the results of the tests in FILE, -- traditionally `config.cache'. FILE defaults to `/dev/null' to -+ traditionally 'config.cache'. FILE defaults to '/dev/null' to - disable caching. - --`--config-cache' --`-C' -- Alias for `--cache-file=config.cache'. -+'--config-cache' -+'-C' -+ Alias for '--cache-file=config.cache'. - --`--quiet' --`--silent' --`-q' -+'--quiet' -+'--silent' -+'-q' - Do not print messages saying which checks are being made. To -- suppress all normal output, redirect it to `/dev/null' (any error -+ suppress all normal output, redirect it to '/dev/null' (any error - messages will still be shown). - --`--srcdir=DIR' -+'--srcdir=DIR' - Look for the package's source code in directory DIR. Usually -- `configure' can determine that directory automatically. -+ 'configure' can determine that directory automatically. - --`--prefix=DIR' -- Use DIR as the installation prefix. *note Installation Names:: -- for more details, including other options available for fine-tuning -- the installation locations. -+'--prefix=DIR' -+ Use DIR as the installation prefix. *note Installation Names:: for -+ more details, including other options available for fine-tuning the -+ installation locations. - --`--no-create' --`-n' -+'--no-create' -+'-n' - Run the configure checks, but stop before creating any output - files. - --`configure' also accepts some other, not widely useful, options. Run --`configure --help' for more details. -+'configure' also accepts some other, not widely useful, options. Run -+'configure --help' for more details. -diff --git a/install-sh b/install-sh -index 0b0fdcbba69a..ec298b537402 100755 ---- a/install-sh -+++ b/install-sh -@@ -1,7 +1,7 @@ - #!/bin/sh - # install - install a program, script, or datafile - --scriptversion=2013-12-25.23; # UTC -+scriptversion=2020-11-14.01; # UTC - - # This originates from X11R5 (mit/util/scripts/install.sh), which was - # later released in X11R6 (xc/config/util/install.sh) with the -@@ -69,6 +69,11 @@ posix_mkdir= - # Desired mode of installed file. - mode=0755 - -+# Create dirs (including intermediate dirs) using mode 755. -+# This is like GNU 'install' as of coreutils 8.32 (2020). -+mkdir_umask=22 -+ -+backupsuffix= - chgrpcmd= - chmodcmd=$chmodprog - chowncmd= -@@ -99,18 +104,28 @@ Options: - --version display version info and exit. - - -c (ignored) -- -C install only if different (preserve the last data modification time) -+ -C install only if different (preserve data modification time) - -d create directories instead of installing files. - -g GROUP $chgrpprog installed files to GROUP. - -m MODE $chmodprog installed files to MODE. - -o USER $chownprog installed files to USER. -+ -p pass -p to $cpprog. - -s $stripprog installed files. -+ -S SUFFIX attempt to back up existing files, with suffix SUFFIX. - -t DIRECTORY install into DIRECTORY. - -T report an error if DSTFILE is a directory. - - Environment variables override the default commands: - CHGRPPROG CHMODPROG CHOWNPROG CMPPROG CPPROG MKDIRPROG MVPROG - RMPROG STRIPPROG -+ -+By default, rm is invoked with -f; when overridden with RMPROG, -+it's up to you to specify -f if you want it. -+ -+If -S is not specified, no backups are attempted. -+ -+Email bug reports to bug-automake@gnu.org. -+Automake home page: https://www.gnu.org/software/automake/ - " - - while test $# -ne 0; do -@@ -137,8 +152,13 @@ while test $# -ne 0; do - -o) chowncmd="$chownprog $2" - shift;; - -+ -p) cpprog="$cpprog -p";; -+ - -s) stripcmd=$stripprog;; - -+ -S) backupsuffix="$2" -+ shift;; -+ - -t) - is_target_a_directory=always - dst_arg=$2 -@@ -255,6 +275,10 @@ do - dstdir=$dst - test -d "$dstdir" - dstdir_status=$? -+ # Don't chown directories that already exist. -+ if test $dstdir_status = 0; then -+ chowncmd="" -+ fi - else - - # Waiting for this to be detected by the "$cpprog $src $dsttmp" command -@@ -271,15 +295,18 @@ do - fi - dst=$dst_arg - -- # If destination is a directory, append the input filename; won't work -- # if double slashes aren't ignored. -+ # If destination is a directory, append the input filename. - if test -d "$dst"; then - if test "$is_target_a_directory" = never; then - echo "$0: $dst_arg: Is a directory" >&2 - exit 1 - fi - dstdir=$dst -- dst=$dstdir/`basename "$src"` -+ dstbase=`basename "$src"` -+ case $dst in -+ */) dst=$dst$dstbase;; -+ *) dst=$dst/$dstbase;; -+ esac - dstdir_status=0 - else - dstdir=`dirname "$dst"` -@@ -288,27 +315,16 @@ do - fi - fi - -+ case $dstdir in -+ */) dstdirslash=$dstdir;; -+ *) dstdirslash=$dstdir/;; -+ esac -+ - obsolete_mkdir_used=false - - if test $dstdir_status != 0; then - case $posix_mkdir in - '') -- # Create intermediate dirs using mode 755 as modified by the umask. -- # This is like FreeBSD 'install' as of 1997-10-28. -- umask=`umask` -- case $stripcmd.$umask in -- # Optimize common cases. -- *[2367][2367]) mkdir_umask=$umask;; -- .*0[02][02] | .[02][02] | .[02]) mkdir_umask=22;; -- -- *[0-7]) -- mkdir_umask=`expr $umask + 22 \ -- - $umask % 100 % 40 + $umask % 20 \ -- - $umask % 10 % 4 + $umask % 2 -- `;; -- *) mkdir_umask=$umask,go-w;; -- esac -- - # With -d, create the new directory with the user-specified mode. - # Otherwise, rely on $mkdir_umask. - if test -n "$dir_arg"; then -@@ -318,43 +334,49 @@ do - fi - - posix_mkdir=false -- case $umask in -- *[123567][0-7][0-7]) -- # POSIX mkdir -p sets u+wx bits regardless of umask, which -- # is incompatible with FreeBSD 'install' when (umask & 300) != 0. -- ;; -- *) -- tmpdir=${TMPDIR-/tmp}/ins$RANDOM-$$ -- trap 'ret=$?; rmdir "$tmpdir/d" "$tmpdir" 2>/dev/null; exit $ret' 0 -- -- if (umask $mkdir_umask && -- exec $mkdirprog $mkdir_mode -p -- "$tmpdir/d") >/dev/null 2>&1 -- then -- if test -z "$dir_arg" || { -- # Check for POSIX incompatibilities with -m. -- # HP-UX 11.23 and IRIX 6.5 mkdir -m -p sets group- or -- # other-writable bit of parent directory when it shouldn't. -- # FreeBSD 6.1 mkdir -m -p sets mode of existing directory. -- ls_ld_tmpdir=`ls -ld "$tmpdir"` -- case $ls_ld_tmpdir in -- d????-?r-*) different_mode=700;; -- d????-?--*) different_mode=755;; -- *) false;; -- esac && -- $mkdirprog -m$different_mode -p -- "$tmpdir" && { -- ls_ld_tmpdir_1=`ls -ld "$tmpdir"` -- test "$ls_ld_tmpdir" = "$ls_ld_tmpdir_1" -- } -- } -- then posix_mkdir=: -- fi -- rmdir "$tmpdir/d" "$tmpdir" -- else -- # Remove any dirs left behind by ancient mkdir implementations. -- rmdir ./$mkdir_mode ./-p ./-- 2>/dev/null -- fi -- trap '' 0;; -- esac;; -+ # The $RANDOM variable is not portable (e.g., dash). Use it -+ # here however when possible just to lower collision chance. -+ tmpdir=${TMPDIR-/tmp}/ins$RANDOM-$$ -+ -+ trap ' -+ ret=$? -+ rmdir "$tmpdir/a/b" "$tmpdir/a" "$tmpdir" 2>/dev/null -+ exit $ret -+ ' 0 -+ -+ # Because "mkdir -p" follows existing symlinks and we likely work -+ # directly in world-writeable /tmp, make sure that the '$tmpdir' -+ # directory is successfully created first before we actually test -+ # 'mkdir -p'. -+ if (umask $mkdir_umask && -+ $mkdirprog $mkdir_mode "$tmpdir" && -+ exec $mkdirprog $mkdir_mode -p -- "$tmpdir/a/b") >/dev/null 2>&1 -+ then -+ if test -z "$dir_arg" || { -+ # Check for POSIX incompatibilities with -m. -+ # HP-UX 11.23 and IRIX 6.5 mkdir -m -p sets group- or -+ # other-writable bit of parent directory when it shouldn't. -+ # FreeBSD 6.1 mkdir -m -p sets mode of existing directory. -+ test_tmpdir="$tmpdir/a" -+ ls_ld_tmpdir=`ls -ld "$test_tmpdir"` -+ case $ls_ld_tmpdir in -+ d????-?r-*) different_mode=700;; -+ d????-?--*) different_mode=755;; -+ *) false;; -+ esac && -+ $mkdirprog -m$different_mode -p -- "$test_tmpdir" && { -+ ls_ld_tmpdir_1=`ls -ld "$test_tmpdir"` -+ test "$ls_ld_tmpdir" = "$ls_ld_tmpdir_1" -+ } -+ } -+ then posix_mkdir=: -+ fi -+ rmdir "$tmpdir/a/b" "$tmpdir/a" "$tmpdir" -+ else -+ # Remove any dirs left behind by ancient mkdir implementations. -+ rmdir ./$mkdir_mode ./-p ./-- "$tmpdir" 2>/dev/null -+ fi -+ trap '' 0;; - esac - - if -@@ -365,7 +387,7 @@ do - then : - else - -- # The umask is ridiculous, or mkdir does not conform to POSIX, -+ # mkdir does not conform to POSIX, - # or it failed possibly due to a race condition. Create the - # directory the slow way, step by step, checking for races as we go. - -@@ -394,7 +416,7 @@ do - prefixes= - else - if $posix_mkdir; then -- (umask=$mkdir_umask && -+ (umask $mkdir_umask && - $doit_exec $mkdirprog $mkdir_mode -p -- "$dstdir") && break - # Don't fail if two instances are running concurrently. - test -d "$prefix" || exit 1 -@@ -427,14 +449,25 @@ do - else - - # Make a couple of temp file names in the proper directory. -- dsttmp=$dstdir/_inst.$$_ -- rmtmp=$dstdir/_rm.$$_ -+ dsttmp=${dstdirslash}_inst.$$_ -+ rmtmp=${dstdirslash}_rm.$$_ - - # Trap to clean up those temp files at exit. - trap 'ret=$?; rm -f "$dsttmp" "$rmtmp" && exit $ret' 0 - - # Copy the file name to the temp name. -- (umask $cp_umask && $doit_exec $cpprog "$src" "$dsttmp") && -+ (umask $cp_umask && -+ { test -z "$stripcmd" || { -+ # Create $dsttmp read-write so that cp doesn't create it read-only, -+ # which would cause strip to fail. -+ if test -z "$doit"; then -+ : >"$dsttmp" # No need to fork-exec 'touch'. -+ else -+ $doit touch "$dsttmp" -+ fi -+ } -+ } && -+ $doit_exec $cpprog "$src" "$dsttmp") && - - # and set any options; do chmod last to preserve setuid bits. - # -@@ -460,6 +493,13 @@ do - then - rm -f "$dsttmp" - else -+ # If $backupsuffix is set, and the file being installed -+ # already exists, attempt a backup. Don't worry if it fails, -+ # e.g., if mv doesn't support -f. -+ if test -n "$backupsuffix" && test -f "$dst"; then -+ $doit $mvcmd -f "$dst" "$dst$backupsuffix" 2>/dev/null -+ fi -+ - # Rename the file to the real destination. - $doit $mvcmd -f "$dsttmp" "$dst" 2>/dev/null || - -@@ -474,9 +514,9 @@ do - # file should still install successfully. - { - test ! -f "$dst" || -- $doit $rmcmd -f "$dst" 2>/dev/null || -+ $doit $rmcmd "$dst" 2>/dev/null || - { $doit $mvcmd -f "$dst" "$rmtmp" 2>/dev/null && -- { $doit $rmcmd -f "$rmtmp" 2>/dev/null; :; } -+ { $doit $rmcmd "$rmtmp" 2>/dev/null; :; } - } || - { echo "$0: cannot unlink or rename $dst" >&2 - (exit 1); exit 1 -@@ -493,9 +533,9 @@ do - done - - # Local variables: --# eval: (add-hook 'write-file-hooks 'time-stamp) -+# eval: (add-hook 'before-save-hook 'time-stamp) - # time-stamp-start: "scriptversion=" - # time-stamp-format: "%:y-%02m-%02d.%02H" --# time-stamp-time-zone: "UTC" -+# time-stamp-time-zone: "UTC0" - # time-stamp-end: "; # UTC" - # End: -diff --git a/missing b/missing -index b7e571efa44e..1fe1611f1851 100755 ---- a/missing -+++ b/missing -@@ -1,9 +1,9 @@ --#!/bin/sh -+#! /bin/sh - # Common wrapper for a few potentially missing GNU programs. - --scriptversion=2016-01-11.22; # UTC -+scriptversion=2018-03-07.03; # UTC - --# Copyright (C) 1996-2017 Free Software Foundation, Inc. -+# Copyright (C) 1996-2021 Free Software Foundation, Inc. - # Originally written by Fran,cois Pinard , 1996. - - # This program is free software; you can redistribute it and/or modify -@@ -17,7 +17,7 @@ scriptversion=2016-01-11.22; # UTC - # GNU General Public License for more details. - - # You should have received a copy of the GNU General Public License --# along with this program. If not, see . -+# along with this program. If not, see . - - # As a special exception to the GNU General Public License, if you - # distribute this file as part of a program that contains a -@@ -101,9 +101,9 @@ else - exit $st - fi - --perl_URL=http://www.perl.org/ --flex_URL=http://flex.sourceforge.net/ --gnu_software_URL=http://www.gnu.org/software -+perl_URL=https://www.perl.org/ -+flex_URL=https://github.com/westes/flex -+gnu_software_URL=https://www.gnu.org/software - - program_details () - { -@@ -207,7 +207,7 @@ give_advice "$1" | sed -e '1s/^/WARNING: /' \ - exit $st - - # Local variables: --# eval: (add-hook 'write-file-hooks 'time-stamp) -+# eval: (add-hook 'before-save-hook 'time-stamp) - # time-stamp-start: "scriptversion=" - # time-stamp-format: "%:y-%02m-%02d.%02H" - # time-stamp-time-zone: "UTC0" -diff --git a/py-compile b/py-compile -index bc2039140b6c..81b122b0a546 100755 ---- a/py-compile -+++ b/py-compile -@@ -1,9 +1,9 @@ - #!/bin/sh - # py-compile - Compile a Python program - --scriptversion=2011-06-08.12; # UTC -+scriptversion=2021-02-27.01; # UTC - --# Copyright (C) 2000-2014 Free Software Foundation, Inc. -+# Copyright (C) 2000-2021 Free Software Foundation, Inc. - - # This program is free software; you can redistribute it and/or modify - # it under the terms of the GNU General Public License as published by -@@ -16,7 +16,7 @@ scriptversion=2011-06-08.12; # UTC - # GNU General Public License for more details. - - # You should have received a copy of the GNU General Public License --# along with this program. If not, see . -+# along with this program. If not, see . - - # As a special exception to the GNU General Public License, if you - # distribute this file as part of a program that contains a -@@ -27,7 +27,7 @@ scriptversion=2011-06-08.12; # UTC - # bugs to or send patches to - # . - --if [ -z "$PYTHON" ]; then -+if test -z "$PYTHON"; then - PYTHON=python - fi - -@@ -96,27 +96,46 @@ done - - files=$* - if test -z "$files"; then -- usage_error "no files given" -+ usage_error "no files given" - fi - - # if basedir was given, then it should be prepended to filenames before - # byte compilation. --if [ -z "$basedir" ]; then -- pathtrans="path = file" -+if test -z "$basedir"; then -+ pathtrans="path = file" - else -- pathtrans="path = os.path.join('$basedir', file)" -+ pathtrans="path = os.path.join('$basedir', file)" - fi - - # if destdir was given, then it needs to be prepended to the filename to - # byte compile but not go into the compiled file. --if [ -z "$destdir" ]; then -- filetrans="filepath = path" -+if test -z "$destdir"; then -+ filetrans="filepath = path" - else -- filetrans="filepath = os.path.normpath('$destdir' + os.sep + path)" -+ filetrans="filepath = os.path.normpath('$destdir' + os.sep + path)" -+fi -+ -+python_major=`$PYTHON -V 2>&1 | sed -e 's/.* //;s/\..*$//;1q'` -+if test -z "$python_major"; then -+ echo "$me: could not determine $PYTHON major version, guessing 3" >&2 -+ python_major=3 -+fi -+ -+# The old way to import libraries was deprecated. -+if test "$python_major" -le 2; then -+ import_lib=imp -+ import_test="hasattr(imp, 'get_tag')" -+ import_call=imp.cache_from_source -+ import_arg2=', False' # needed in one call and not the other -+else -+ import_lib=importlib -+ import_test="hasattr(sys.implementation, 'cache_tag')" -+ import_call=importlib.util.cache_from_source -+ import_arg2= - fi - - $PYTHON -c " --import sys, os, py_compile, imp -+import sys, os, py_compile, $import_lib - - files = '''$files''' - -@@ -129,15 +148,15 @@ for file in files.split(): - continue - sys.stdout.write(file) - sys.stdout.flush() -- if hasattr(imp, 'get_tag'): -- py_compile.compile(filepath, imp.cache_from_source(filepath), path) -+ if $import_test: -+ py_compile.compile(filepath, $import_call(filepath), path) - else: - py_compile.compile(filepath, filepath + 'c', path) - sys.stdout.write('\n')" || exit $? - - # this will fail for python < 1.5, but that doesn't matter ... - $PYTHON -O -c " --import sys, os, py_compile, imp -+import sys, os, py_compile, $import_lib - - # pypy does not use .pyo optimization - if hasattr(sys, 'pypy_translation_info'): -@@ -153,18 +172,18 @@ for file in files.split(): - continue - sys.stdout.write(file) - sys.stdout.flush() -- if hasattr(imp, 'get_tag'): -- py_compile.compile(filepath, imp.cache_from_source(filepath, False), path) -+ if $import_test: -+ py_compile.compile(filepath, $import_call(filepath$import_arg2), path) - else: - py_compile.compile(filepath, filepath + 'o', path) --sys.stdout.write('\n')" 2>/dev/null || : -+sys.stdout.write('\n')" 2>/dev/null || exit $? - - # Local Variables: - # mode: shell-script - # sh-indentation: 2 --# eval: (add-hook 'write-file-hooks 'time-stamp) -+# eval: (add-hook 'before-save-hook 'time-stamp) - # time-stamp-start: "scriptversion=" - # time-stamp-format: "%:y-%02m-%02d.%02H" --# time-stamp-time-zone: "UTC" -+# time-stamp-time-zone: "UTC0" - # time-stamp-end: "; # UTC" - # End: --- -2.41.0 - diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index e775cbf..8816896 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -5,16 +5,13 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins -Version: 3.3.14 -Release: 10%{?dist} +Version: 3.3.15 +Release: 1%{?dist} License: GPL-2.0-or-later -URL: https://github.com/fedora-selinux/setroubleshoot -Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz +URL: https://gitlab.com/setroubleshoot/plugins +Source0: https://gitlab.com/-/project/24478430/uploads/1d856bff1c9fb16a8c6fc877d7fe91ca/setroubleshoot-plugins-3.3.15.tar.gz # git format-patch -N setroubleshoot-plugins- -- plugins # i=1; for j in 00*patch; do printf "Patch%04d: %s\n" $i $j; i=$((i+1));done -Patch0001: 0001-restorecon.py-exclude-more-paths.patch -Patch0002: 0002-Improve-disable_ipv6-plugin-then_text.patch -Patch0003: 0003-Update-generated-configuration-files.patch BuildArch: noarch # gcc is needed only for ./configure @@ -52,6 +49,12 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Mon Jan 06 2025 Petr Lautrbach - 3.3.15-1 +- restorecon.py: exclude more paths +- Improve disable_ipv6 plugin then_text +- Update generated configuration files +- Update translations + * Sat Jul 20 2024 Fedora Release Engineering - 3.3.14-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild diff --git a/sources b/sources index 28a0bb9..aeb5a6c 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (setroubleshoot-plugins-3.3.14.tar.gz) = da6882a998aeade67891a722a5b94e2ba1072d9db5d73031854a2c0b51083a0eaf9519dd7987938a86c1f8d263d08882642ac447d7b4bbcd8a859db4b44d61c1 +SHA512 (setroubleshoot-plugins-3.3.15.tar.gz) = 9741ecd48a7e0cde376ac0f818d94dad32c74acd2afc01ec6f5e3cf74ff9075d4f3406f1a3905cbbdd3833c8c2ef4213deaaf00d0012dbea582eb2b825618d5f From 8a691be0af1ed56f00ff4e2b5a859d0d8ccc0e52 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sun, 19 Jan 2025 10:28:23 +0000 Subject: [PATCH 17/24] Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 8816896..43b8e87 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.15 -Release: 1%{?dist} +Release: 2%{?dist} License: GPL-2.0-or-later URL: https://gitlab.com/setroubleshoot/plugins Source0: https://gitlab.com/-/project/24478430/uploads/1d856bff1c9fb16a8c6fc877d7fe91ca/setroubleshoot-plugins-3.3.15.tar.gz @@ -49,6 +49,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Sun Jan 19 2025 Fedora Release Engineering - 3.3.15-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + * Mon Jan 06 2025 Petr Lautrbach - 3.3.15-1 - restorecon.py: exclude more paths - Improve disable_ipv6 plugin then_text From 58317166d34b2894253356967409a753c8d64c32 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 25 Jul 2025 18:10:51 +0000 Subject: [PATCH 18/24] Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 43b8e87..883c004 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.15 -Release: 2%{?dist} +Release: 3%{?dist} License: GPL-2.0-or-later URL: https://gitlab.com/setroubleshoot/plugins Source0: https://gitlab.com/-/project/24478430/uploads/1d856bff1c9fb16a8c6fc877d7fe91ca/setroubleshoot-plugins-3.3.15.tar.gz @@ -49,6 +49,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Fri Jul 25 2025 Fedora Release Engineering - 3.3.15-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + * Sun Jan 19 2025 Fedora Release Engineering - 3.3.15-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild From 2c6acc60c5cd30284bf09256d47c560538acbad0 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 15 Aug 2025 15:17:32 +0200 Subject: [PATCH 19/24] Rebuilt for Python 3.14.0rc2 bytecode --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 883c004..06c3a77 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.15 -Release: 3%{?dist} +Release: 4%{?dist} License: GPL-2.0-or-later URL: https://gitlab.com/setroubleshoot/plugins Source0: https://gitlab.com/-/project/24478430/uploads/1d856bff1c9fb16a8c6fc877d7fe91ca/setroubleshoot-plugins-3.3.15.tar.gz @@ -49,6 +49,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Fri Aug 15 2025 Python Maint - 3.3.15-4 +- Rebuilt for Python 3.14.0rc2 bytecode + * Fri Jul 25 2025 Fedora Release Engineering - 3.3.15-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild From 691c6b1e53edc37dc0ab40fdd51db89014001548 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 19 Sep 2025 14:56:13 +0200 Subject: [PATCH 20/24] Rebuilt for Python 3.14.0rc3 bytecode --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 06c3a77..6992119 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.15 -Release: 4%{?dist} +Release: 5%{?dist} License: GPL-2.0-or-later URL: https://gitlab.com/setroubleshoot/plugins Source0: https://gitlab.com/-/project/24478430/uploads/1d856bff1c9fb16a8c6fc877d7fe91ca/setroubleshoot-plugins-3.3.15.tar.gz @@ -49,6 +49,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Fri Sep 19 2025 Python Maint - 3.3.15-5 +- Rebuilt for Python 3.14.0rc3 bytecode + * Fri Aug 15 2025 Python Maint - 3.3.15-4 - Rebuilt for Python 3.14.0rc2 bytecode From 27717286ea82847bf0a75c834b8bd2b6a137ae43 Mon Sep 17 00:00:00 2001 From: jan janasek Date: Thu, 18 Sep 2025 14:17:44 +0200 Subject: [PATCH 21/24] fmf test plan update updating plan due to new destination of tests and since there is a dedecated repo for tests (https://gitlab.com/setroubleshoot/tests) there is no need to have current test directory. Signed-off-by: Jan Janasek --- plans/tests.fmf | 2 + .../use-of-aliases-in-plugins/main.fmf | 25 ------- .../use-of-aliases-in-plugins/runtest.sh | 49 -------------- .../use-of-aliases-in-plugins/test_aliases.py | 65 ------------------- 4 files changed, 2 insertions(+), 139 deletions(-) delete mode 100644 tests/Regression/use-of-aliases-in-plugins/main.fmf delete mode 100755 tests/Regression/use-of-aliases-in-plugins/runtest.sh delete mode 100755 tests/Regression/use-of-aliases-in-plugins/test_aliases.py diff --git a/plans/tests.fmf b/plans/tests.fmf index 7d8f9cd..5d615ae 100644 --- a/plans/tests.fmf +++ b/plans/tests.fmf @@ -1,6 +1,8 @@ summary: basic setroubleshoot-plugins test plan discover: how: fmf + url: https://gitlab.com/setroubleshoot/tests.git + filter: "component:setroubleshoot-plugins & tier: 1" execute: how: tmt diff --git a/tests/Regression/use-of-aliases-in-plugins/main.fmf b/tests/Regression/use-of-aliases-in-plugins/main.fmf deleted file mode 100644 index 8bd3e77..0000000 --- a/tests/Regression/use-of-aliases-in-plugins/main.fmf +++ /dev/null @@ -1,25 +0,0 @@ -summary: test types and aliases used in plugins -description: |+ - Make sure all types used in setroubleshoot plugins are defined in the policy and are not aliases - -contact: Vit Mojzis -component: - - setroubleshoot-plugins -test: ./runtest.sh -framework: beakerlib -recommend: - - libselinux-utils - - python3-policycoreutils - - setroubleshoot-plugins -duration: 15m -enabled: true -tag: - - NoRHEL4 - - NoRHEL5 - - NoRHEL6 - - NoRHEL7 - - targeted -adjust: - - enabled: false - when: distro == rhel-4, rhel-5, rhel-6, rhel-7 - continue: false diff --git a/tests/Regression/use-of-aliases-in-plugins/runtest.sh b/tests/Regression/use-of-aliases-in-plugins/runtest.sh deleted file mode 100755 index b540e6b..0000000 --- a/tests/Regression/use-of-aliases-in-plugins/runtest.sh +++ /dev/null @@ -1,49 +0,0 @@ -#!/bin/bash -# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# runtest.sh of /CoreOS/setroubleshoot-plugins/Regression/use-of-aliases-in-plugins -# Description: Make sure all types used in setroubleshoot plugins are -# defined in the policy and are not aliases -# Author: Vit Mojzis -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Copyright (c) 2020 Red Hat, Inc. -# -# This program is free software: you can redistribute it and/or -# modify it under the terms of the GNU General Public License as -# published by the Free Software Foundation, either version 2 of -# the License, or (at your option) any later version. -# -# This program is distributed in the hope that it will be -# useful, but WITHOUT ANY WARRANTY; without even the implied -# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR -# PURPOSE. See the GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public License -# along with this program. If not, see http://www.gnu.org/licenses/. -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -# Include Beaker environment -. /usr/share/beakerlib/beakerlib.sh || exit 1 - -PACKAGE="setroubleshoot-plugins" - -rlJournalStart - rlPhaseStartSetup - rlAssertRpm ${PACKAGE} - rlRun "selinuxenabled" 0 - rlPhaseEnd - - rlPhaseStartTest "bz#1794807 - look for aliases and undefined types in plugins" - # lists all types not defined in the policy as "type_t not found" - # and all aliases as "alias_t is an alias of type_t" - # all issues are prefixed with a list of offending plugins - # returns 1 if an issue was found - rlRun "./test_aliases.py" 0 - rlPhaseEnd -rlJournalPrintText -rlJournalEnd - diff --git a/tests/Regression/use-of-aliases-in-plugins/test_aliases.py b/tests/Regression/use-of-aliases-in-plugins/test_aliases.py deleted file mode 100755 index fec114e..0000000 --- a/tests/Regression/use-of-aliases-in-plugins/test_aliases.py +++ /dev/null @@ -1,65 +0,0 @@ -#!/usr/bin/python3 - -# lists all types not defined in the policy as "type_t not found" -# and all aliases as "alias_t is an alias of type_t" -# all issues are prefixed with a list of offending plugins -# returns 1 if an issue was found - -import subprocess -import sepolicy -import sys -import re -from collections import defaultdict - -plugin_path = "/usr/share/setroubleshoot/plugins" -error_code = 0 - -if len(sys.argv) > 1: - plugin_path = sys.argv[1] - -try: - # search all plugin files in given location for the following pattern - # :_t - g = subprocess.check_output('grep -I [^A-Za-z_][A-Za-z][A-Za-z_]*_t[^A-Za-z_] -o {}/*.py'.format(plugin_path), - universal_newlines=True, shell=True) - lines = g.split('\n') -except: - exit(1) -# matches 2 groups: file name and type name -# ():(_t) -reg = re.compile('.*/(.+):[^A-Za-z_]([A-Za-z_]*_t)[^A-Za-z_]') -# generate a dictionary of of all type names used in setroubleshoot plugins -# where types are keys and lists of files where each type appeared are data -found = defaultdict(set) - -for l in lines: - m = reg.match(l) - - if m is None: - continue - - try: - t = m.group(2) - if "_TYPE_" in t: - continue - found[t].add(m.group(1)) - except: - # failed to match - continue - -for t in sorted(found.keys()): - try: - # try to find each type in system policy - i = next(sepolicy.info(sepolicy.TYPE, t))['name'] - if t != i: - # : alias_t is an alias of type_t - print("{}: {} is an alias of {}".format(", ".join(found[t]), t, i)) - error_code = 1 - except: - # skip types defined in selinux-policy modules that are not shipped any more - if t not in ["vbetool_t"]: - # : type_t not found - print("{}: {} not found".format(", ".join(found[t]), t)) - error_code = 1 - -exit(error_code) From a650d518c8354d53623859348e59deaca31e2d2f Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 17 Jan 2026 17:55:36 +0000 Subject: [PATCH 22/24] Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index 6992119..cd440af 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.15 -Release: 5%{?dist} +Release: 6%{?dist} License: GPL-2.0-or-later URL: https://gitlab.com/setroubleshoot/plugins Source0: https://gitlab.com/-/project/24478430/uploads/1d856bff1c9fb16a8c6fc877d7fe91ca/setroubleshoot-plugins-3.3.15.tar.gz @@ -49,6 +49,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Sat Jan 17 2026 Fedora Release Engineering - 3.3.15-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild + * Fri Sep 19 2025 Python Maint - 3.3.15-5 - Rebuilt for Python 3.14.0rc3 bytecode From fc34171f607d2ebb0451754b45469ca1e1f58571 Mon Sep 17 00:00:00 2001 From: Vit Mojzis Date: Mon, 9 Mar 2026 23:08:08 +0100 Subject: [PATCH 23/24] setroubleshoot-plugins-3.3.15-7 - Split multi-command fix_cmds into lists - catchall: Discourage creating custom policy modules Note: Swtiched from "Requires" to "Conflicts" with setroubleshoot-server to remove the circular dependency. --- ...it-multi-command-fix_cmds-into-lists.patch | 73 +++++++++++++++++++ ...urage-creating-custom-policy-modules.patch | 36 +++++++++ setroubleshoot-plugins.spec | 16 ++-- 3 files changed, 120 insertions(+), 5 deletions(-) create mode 100644 0001-Split-multi-command-fix_cmds-into-lists.patch create mode 100644 0002-catchall-Discourage-creating-custom-policy-modules.patch diff --git a/0001-Split-multi-command-fix_cmds-into-lists.patch b/0001-Split-multi-command-fix_cmds-into-lists.patch new file mode 100644 index 0000000..476333d --- /dev/null +++ b/0001-Split-multi-command-fix_cmds-into-lists.patch @@ -0,0 +1,73 @@ +From df90bf242b35a9e01f721dd7ad436f1bd5d21616 Mon Sep 17 00:00:00 2001 +From: Vit Mojzis +Date: Mon, 9 Mar 2026 22:03:31 +0100 +Subject: [PATCH] Split multi-command fix_cmds into lists + +This requires +https://gitlab.com/setroubleshoot/setroubleshoot/-/merge_requests/54/diffs?commit_id=d5d13afa86c2bd03952c04a187657ed981c9be7e +to work properly! +--- + src/allow_execmod.py | 3 ++- + src/automount_exec_config.py | 3 ++- + src/cvs_data.py | 3 ++- + src/file.py | 2 +- + 4 files changed, 7 insertions(+), 4 deletions(-) + +diff --git a/src/allow_execmod.py b/src/allow_execmod.py +index 6e1f6bf..0a3995f 100644 +--- a/src/allow_execmod.py ++++ b/src/allow_execmod.py +@@ -81,7 +81,8 @@ If you want this to survive a relabel, execute + # semanage fcontext -a -t textrel_shlib_t '$FIX_TARGET_PATH';restorecon -v '$FIX_TARGET_PATH' + """ + +- fix_cmd = """/usr/sbin/semanage fcontext -a -t textrel_shlib_t '$FIX_TARGET_PATH';/usr/sbin/restorecon -v '$FIX_TARGET_PATH'""" ++ fix_cmd = ["""/usr/sbin/semanage fcontext -a -t textrel_shlib_t '$FIX_TARGET_PATH'""", ++ """/usr/sbin/restorecon -v '$FIX_TARGET_PATH'"""] + + def init_args(self, args): + if len(args) > 0: +diff --git a/src/automount_exec_config.py b/src/automount_exec_config.py +index a64eaf2..81ada8e 100644 +--- a/src/automount_exec_config.py ++++ b/src/automount_exec_config.py +@@ -40,7 +40,8 @@ class plugin(Plugin): + If you want to change the file context of $TARGET_PATH so that the automounter can execute it you can execute "chcon -t bin_t $TARGET_PATH". If you want this to survive a relabel, you need to permanently change the file context: execute "semanage fcontext -a -t bin_t '$FIX_TARGET_PATH'". + ''') + +- fix_cmd = """/usr/sbin/semanage fcontext -a -t bin_t '$FIX_TARGET_PATH';/usr/sbin/restorecon -v '$FIX_TARGET_PATH'""" ++ fix_cmd = ["""/usr/sbin/semanage fcontext -a -t bin_t '$FIX_TARGET_PATH'""", ++ """/usr/sbin/restorecon -v '$FIX_TARGET_PATH'"""] + + if_text = 'If you want to allow automounter to execute $TARGET_PATH' + +diff --git a/src/cvs_data.py b/src/cvs_data.py +index 7451622..1e75ead 100644 +--- a/src/cvs_data.py ++++ b/src/cvs_data.py +@@ -46,7 +46,8 @@ class plugin(Plugin): + do_text = """# semanage fcontext -a -t cvs_data_t '$FIX_TARGET_PATH' + # restorecon -v '$FIX_TARGET_PATH'""" + +- fix_cmd = """/usr/sbin/semanage fcontext -a -t cvs_data_t '$FIX_TARGET_PATH';/usr/sbin/restorecon -v '$FIX_TARGET_PATH'""" ++ fix_cmd = ["""/usr/sbin/semanage fcontext -a -t cvs_data_t '$FIX_TARGET_PATH'""", ++ """/usr/sbin/restorecon -v '$FIX_TARGET_PATH'"""] + + def __init__(self): + Plugin.__init__(self, __name__) +diff --git a/src/file.py b/src/file.py +index ac24bf9..25f3a43 100644 +--- a/src/file.py ++++ b/src/file.py +@@ -66,7 +66,7 @@ home directory from a previous installation that did not use SELinux, 'restoreco + if args == (1,0): + return '/sbin/restorecon -R -v $TARGET_PATH' + else: +- return 'touch /.autorelabel; reboot' ++ return ['touch /.autorelabel', 'reboot'] + + def init_args(self, args): + if args == (1,0): +-- +2.53.0 + diff --git a/0002-catchall-Discourage-creating-custom-policy-modules.patch b/0002-catchall-Discourage-creating-custom-policy-modules.patch new file mode 100644 index 0000000..a3f28a1 --- /dev/null +++ b/0002-catchall-Discourage-creating-custom-policy-modules.patch @@ -0,0 +1,36 @@ +From 8ad7f4c5528fbbc52a3d391c702102c6fe262d83 Mon Sep 17 00:00:00 2001 +From: Vit Mojzis +Date: Tue, 9 Jun 2026 17:27:36 +0200 +Subject: [PATCH] catchall: Discourage creating custom policy modules + +Update the plugin text to discourage creating custom policy modules by +explaining the lack of support and potential security implications. +--- + src/catchall.py | 11 ++++++++--- + 1 file changed, 8 insertions(+), 3 deletions(-) + +diff --git a/src/catchall.py b/src/catchall.py +index 052d6d8..7e4a8fa 100644 +--- a/src/catchall.py ++++ b/src/catchall.py +@@ -54,9 +54,14 @@ class plugin(Plugin): + return _('If you believe that $SOURCE_BASE_PATH should be allowed $ACCESS access on $TARGET_CLASS labeled $TARGET_TYPE by default.') + return _('If you believe that $SOURCE_BASE_PATH should be allowed $ACCESS access on the $TARGET_BASE_PATH $TARGET_CLASS by default.') + +- then_text = _('You should report this as a bug.\nYou can generate a local policy module to allow this access.') +- do_text = _("""Allow this access for now by executing: +-# ausearch -c '$SOURCE' --raw | audit2allow -M my-$MODULE_NAME ++ then_text = _(''' ++ You should report this as a bug.\n ++ If you are certain this access is legitimate and not an intrusion attempt, you ++ can generate a local policy module to allow it. ++ Custom policy modules are not supported as they may weaken the system policy and expose the system to security vulnerabilities. ++ ''') ++ ++ do_text = _("""# ausearch -c '$SOURCE' --raw | audit2allow -M my-$MODULE_NAME + # semodule -X 300 -i my-$MODULE_NAME.pp""") + + def __init__(self): +-- +2.53.0 + diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index cd440af..a931ed9 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,12 +6,14 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.15 -Release: 6%{?dist} +Release: 7%{?dist} License: GPL-2.0-or-later URL: https://gitlab.com/setroubleshoot/plugins Source0: https://gitlab.com/-/project/24478430/uploads/1d856bff1c9fb16a8c6fc877d7fe91ca/setroubleshoot-plugins-3.3.15.tar.gz -# git format-patch -N setroubleshoot-plugins- -- plugins -# i=1; for j in 00*patch; do printf "Patch%04d: %s\n" $i $j; i=$((i+1));done +# git format-patch -N setroubleshoot-plugins- +# for j in 00*patch; do printf "Patch: %s\n" $j; done +Patch: 0001-Split-multi-command-fix_cmds-into-lists.patch +Patch: 0002-catchall-Discourage-creating-custom-policy-modules.patch BuildArch: noarch # gcc is needed only for ./configure @@ -20,8 +22,8 @@ BuildRequires: gcc BuildRequires: make BuildRequires: perl-XML-Parser BuildRequires: intltool gettext python3-devel -# Introduction of get_package_nvr functions -Requires: setroubleshoot-server >= 3.3.23 +# Support for multiple commands in fix_cmd +Conflicts: setroubleshoot-server < 3.3.37 %description This package provides a set of analysis plugins for use with @@ -49,6 +51,10 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Thu May 07 2026 Vit Mojzis - 3.3.15-7 +- Split multi-command fix_cmds into lists +- catchall: Discourage creating custom policy modules + * Sat Jan 17 2026 Fedora Release Engineering - 3.3.15-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild From b44ccaa1dfd6d4f54788884651cb69fee10b5ec7 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 17 Jul 2026 06:25:48 +0000 Subject: [PATCH 24/24] Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild --- setroubleshoot-plugins.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/setroubleshoot-plugins.spec b/setroubleshoot-plugins.spec index a931ed9..9bda6f3 100644 --- a/setroubleshoot-plugins.spec +++ b/setroubleshoot-plugins.spec @@ -6,7 +6,7 @@ Summary: Analysis plugins for use with setroubleshoot Name: setroubleshoot-plugins Version: 3.3.15 -Release: 7%{?dist} +Release: 8%{?dist} License: GPL-2.0-or-later URL: https://gitlab.com/setroubleshoot/plugins Source0: https://gitlab.com/-/project/24478430/uploads/1d856bff1c9fb16a8c6fc877d7fe91ca/setroubleshoot-plugins-3.3.15.tar.gz @@ -51,6 +51,9 @@ rm -rf %{buildroot} %{_datadir}/setroubleshoot/plugins %changelog +* Fri Jul 17 2026 Fedora Release Engineering - 3.3.15-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild + * Thu May 07 2026 Vit Mojzis - 3.3.15-7 - Split multi-command fix_cmds into lists - catchall: Discourage creating custom policy modules