author | Mike Sullivan <Mike.Sullivan@Oracle.COM> |
Mon, 01 Apr 2013 23:00:57 -0700 | |
changeset 1243 | cf247f5101ae |
parent 1146 | 94088715b2bf |
child 1251 | f1fb66b52f41 |
permissions | -rw-r--r-- |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
1 |
#!/usr/bin/python |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
2 |
# |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
3 |
# CDDL HEADER START |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
4 |
# |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
5 |
# The contents of this file are subject to the terms of the |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
6 |
# Common Development and Distribution License (the "License"). |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
7 |
# You may not use this file except in compliance with the License. |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
8 |
# |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
9 |
# You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
10 |
# or http://www.opensolaris.org/os/licensing. |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
11 |
# See the License for the specific language governing permissions |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
12 |
# and limitations under the License. |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
13 |
# |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
14 |
# When distributing Covered Code, include this CDDL HEADER in each |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
15 |
# file and include the License file at usr/src/OPENSOLARIS.LICENSE. |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
16 |
# If applicable, add the following below this CDDL HEADER, with the |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
17 |
# fields enclosed by brackets "[]" replaced with your own identifying |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
18 |
# information: Portions Copyright [yyyy] [name of copyright owner] |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
19 |
# |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
20 |
# CDDL HEADER END |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
21 |
# |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
22 |
|
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
23 |
# |
1138
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
24 |
# Copyright (c) 2010, 2013, Oracle and/or its affiliates. All rights reserved. |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
25 |
# |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
26 |
|
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
27 |
# Some userland consolidation specific lint checks |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
28 |
|
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
29 |
import pkg.lint.base as base |
186
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
30 |
from pkg.lint.engine import lint_fmri_successor |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
31 |
import pkg.elf as elf |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
32 |
import re |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
33 |
import os.path |
1138
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
34 |
import subprocess |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
35 |
|
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
36 |
class UserlandActionChecker(base.ActionChecker): |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
37 |
"""An opensolaris.org-specific class to check actions.""" |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
38 |
|
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
39 |
name = "userland.action" |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
40 |
|
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
41 |
def __init__(self, config): |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
42 |
self.description = _( |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
43 |
"checks Userland packages for common content errors") |
117
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
44 |
path = os.getenv('PROTO_PATH') |
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
45 |
if path != None: |
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
46 |
self.proto_path = path.split() |
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
47 |
else: |
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
48 |
self.proto_path = None |
1146
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
49 |
# |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
50 |
# These lists are used to check if a 32/64-bit binary |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
51 |
# is in a proper 32/64-bit directory. |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
52 |
# |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
53 |
self.pathlist32 = [ |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
54 |
"i86", |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
55 |
"sparcv7", |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
56 |
"32", |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
57 |
"i86pc-solaris-64int", # perl path |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
58 |
"sun4-solaris-64int" # perl path |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
59 |
] |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
60 |
self.pathlist64 = [ |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
61 |
"amd64", |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
62 |
"sparcv9", |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
63 |
"64", |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
64 |
"i86pc-solaris-64", # perl path |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
65 |
"sun4-solaris-64" # perl path |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
66 |
] |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
67 |
self.runpath_re = [ |
99
c15c9099bb44
6841644 OpenSolaris Python should support gdbm
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
84
diff
changeset
|
68 |
re.compile('^/lib(/.*)?$'), |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
69 |
re.compile('^/usr/'), |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
70 |
re.compile('^\$ORIGIN/') |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
71 |
] |
623
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
72 |
self.runpath_64_re = [ |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
73 |
re.compile('^.*/64(/.*)?$'), |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
74 |
re.compile('^.*/amd64(/.*)?$'), |
1146
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
75 |
re.compile('^.*/sparcv9(/.*)?$'), |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
76 |
re.compile('^.*/i86pc-solaris-64(/.*)?$'), # perl path |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
77 |
re.compile('^.*/sun4-solaris-64(/.*)?$') # perl path |
623
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
78 |
] |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
79 |
self.initscript_re = re.compile("^etc/(rc.|init)\.d") |
186
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
80 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
81 |
self.lint_paths = {} |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
82 |
self.ref_paths = {} |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
83 |
|
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
84 |
super(UserlandActionChecker, self).__init__(config) |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
85 |
|
186
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
86 |
def startup(self, engine): |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
87 |
"""Initialize the checker with a dictionary of paths, so that we |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
88 |
can do link resolution. |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
89 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
90 |
This is copied from the core pkglint code, but should eventually |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
91 |
be made common. |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
92 |
""" |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
93 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
94 |
def seed_dict(mf, attr, dic, atype=None, verbose=False): |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
95 |
"""Updates a dictionary of { attr: [(fmri, action), ..]} |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
96 |
where attr is the value of that attribute from |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
97 |
actions of a given type atype, in the given |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
98 |
manifest.""" |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
99 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
100 |
pkg_vars = mf.get_all_variants() |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
101 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
102 |
if atype: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
103 |
mfg = (a for a in mf.gen_actions_by_type(atype)) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
104 |
else: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
105 |
mfg = (a for a in mf.gen_actions()) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
106 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
107 |
for action in mfg: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
108 |
if atype and action.name != atype: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
109 |
continue |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
110 |
if attr not in action.attrs: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
111 |
continue |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
112 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
113 |
variants = action.get_variant_template() |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
114 |
variants.merge_unknown(pkg_vars) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
115 |
action.attrs.update(variants) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
116 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
117 |
p = action.attrs[attr] |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
118 |
dic.setdefault(p, []).append((mf.fmri, action)) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
119 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
120 |
# construct a set of FMRIs being presented for linting, and |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
121 |
# avoid seeding the reference dictionary with any for which |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
122 |
# we're delivering new packages. |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
123 |
lint_fmris = {} |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
124 |
for m in engine.gen_manifests(engine.lint_api_inst, |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
125 |
release=engine.release, pattern=engine.pattern): |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
126 |
lint_fmris.setdefault(m.fmri.get_name(), []).append(m.fmri) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
127 |
for m in engine.lint_manifests: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
128 |
lint_fmris.setdefault(m.fmri.get_name(), []).append(m.fmri) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
129 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
130 |
engine.logger.debug( |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
131 |
_("Seeding reference action path dictionaries.")) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
132 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
133 |
for manifest in engine.gen_manifests(engine.ref_api_inst, |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
134 |
release=engine.release): |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
135 |
# Only put this manifest into the reference dictionary |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
136 |
# if it's not an older version of the same package. |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
137 |
if not any( |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
138 |
lint_fmri_successor(fmri, manifest.fmri) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
139 |
for fmri |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
140 |
in lint_fmris.get(manifest.fmri.get_name(), []) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
141 |
): |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
142 |
seed_dict(manifest, "path", self.ref_paths) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
143 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
144 |
engine.logger.debug( |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
145 |
_("Seeding lint action path dictionaries.")) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
146 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
147 |
# we provide a search pattern, to allow users to lint a |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
148 |
# subset of the packages in the lint_repository |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
149 |
for manifest in engine.gen_manifests(engine.lint_api_inst, |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
150 |
release=engine.release, pattern=engine.pattern): |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
151 |
seed_dict(manifest, "path", self.lint_paths) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
152 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
153 |
engine.logger.debug( |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
154 |
_("Seeding local action path dictionaries.")) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
155 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
156 |
for manifest in engine.lint_manifests: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
157 |
seed_dict(manifest, "path", self.lint_paths) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
158 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
159 |
self.__merge_dict(self.lint_paths, self.ref_paths, |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
160 |
ignore_pubs=engine.ignore_pubs) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
161 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
162 |
def __merge_dict(self, src, target, ignore_pubs=True): |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
163 |
"""Merges the given src dictionary into the target |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
164 |
dictionary, giving us the target content as it would appear, |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
165 |
were the packages in src to get published to the |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
166 |
repositories that made up target. |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
167 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
168 |
We need to only merge packages at the same or successive |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
169 |
version from the src dictionary into the target dictionary. |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
170 |
If the src dictionary contains a package with no version |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
171 |
information, it is assumed to be more recent than the same |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
172 |
package with no version in the target.""" |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
173 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
174 |
for p in src: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
175 |
if p not in target: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
176 |
target[p] = src[p] |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
177 |
continue |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
178 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
179 |
def build_dic(arr): |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
180 |
"""Builds a dictionary of fmri:action entries""" |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
181 |
dic = {} |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
182 |
for (pfmri, action) in arr: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
183 |
if pfmri in dic: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
184 |
dic[pfmri].append(action) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
185 |
else: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
186 |
dic[pfmri] = [action] |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
187 |
return dic |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
188 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
189 |
src_dic = build_dic(src[p]) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
190 |
targ_dic = build_dic(target[p]) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
191 |
|
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
192 |
for src_pfmri in src_dic: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
193 |
# we want to remove entries deemed older than |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
194 |
# src_pfmri from targ_dic. |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
195 |
for targ_pfmri in targ_dic.copy(): |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
196 |
sname = src_pfmri.get_name() |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
197 |
tname = targ_pfmri.get_name() |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
198 |
if lint_fmri_successor(src_pfmri, |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
199 |
targ_pfmri, |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
200 |
ignore_pubs=ignore_pubs): |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
201 |
targ_dic.pop(targ_pfmri) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
202 |
targ_dic.update(src_dic) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
203 |
l = [] |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
204 |
for pfmri in targ_dic: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
205 |
for action in targ_dic[pfmri]: |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
206 |
l.append((pfmri, action)) |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
207 |
target[p] = l |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
208 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
209 |
def __realpath(self, path, target): |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
210 |
"""Combine path and target to get the real path.""" |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
211 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
212 |
result = os.path.dirname(path) |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
213 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
214 |
for frag in target.split(os.sep): |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
215 |
if frag == '..': |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
216 |
result = os.path.dirname(result) |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
217 |
elif frag == '.': |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
218 |
pass |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
219 |
else: |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
220 |
result = os.path.join(result, frag) |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
221 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
222 |
return result |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
223 |
|
1138
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
224 |
def __elf_aslr_check(self, path, engine): |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
225 |
result = None |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
226 |
|
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
227 |
ei = elf.get_info(path) |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
228 |
type = ei.get("type"); |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
229 |
if type != "exe": |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
230 |
return result |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
231 |
|
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
232 |
# get the ASLR tag string for this binary |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
233 |
aslr_tag_process = subprocess.Popen( |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
234 |
"/usr/bin/elfedit -r -e 'dyn:sunw_aslr' " |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
235 |
+ path, shell=True, |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
236 |
stdout=subprocess.PIPE, stderr=subprocess.PIPE) |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
237 |
|
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
238 |
# aslr_tag_string will get stdout; err will get stderr |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
239 |
aslr_tag_string, err = aslr_tag_process.communicate() |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
240 |
|
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
241 |
# No ASLR tag was found; everthing must be tagged |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
242 |
if aslr_tag_process.returncode != 0: |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
243 |
engine.error( |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
244 |
_("'%s' is not tagged for aslr") % (path), |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
245 |
msgid="%s%s.5" % (self.name, "001")) |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
246 |
return result |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
247 |
|
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
248 |
# look for "ENABLE" anywhere in the string; |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
249 |
# warn about binaries which are not ASLR enabled |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
250 |
if re.search("ENABLE", aslr_tag_string) is not None: |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
251 |
return result |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
252 |
engine.warning( |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
253 |
_("'%s' does not have aslr enabled") % (path), |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
254 |
msgid="%s%s.6" % (self.name, "001")) |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
255 |
return result |
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
256 |
|
623
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
257 |
def __elf_runpath_check(self, path, engine): |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
258 |
result = None |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
259 |
list = [] |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
260 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
261 |
ed = elf.get_dynamic(path) |
623
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
262 |
ei = elf.get_info(path) |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
263 |
bits = ei.get("bits") |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
264 |
for dir in ed.get("runpath", "").split(":"): |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
265 |
if dir == None or dir == '': |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
266 |
continue |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
267 |
|
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
268 |
match = False |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
269 |
for expr in self.runpath_re: |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
270 |
if expr.match(dir): |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
271 |
match = True |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
272 |
break |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
273 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
274 |
if match == False: |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
275 |
list.append(dir) |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
276 |
|
623
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
277 |
if bits == 32: |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
278 |
for expr in self.runpath_64_re: |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
279 |
if expr.search(dir): |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
280 |
engine.warning( |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
281 |
_("64-bit runpath in 32-bit binary, '%s' includes '%s'") % (path, dir), |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
282 |
msgid="%s%s.3" % (self.name, "001")) |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
283 |
else: |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
284 |
match = False |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
285 |
for expr in self.runpath_64_re: |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
286 |
if expr.search(dir): |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
287 |
match = True |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
288 |
break |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
289 |
if match == False: |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
290 |
engine.warning( |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
291 |
_("32-bit runpath in 64-bit binary, '%s' includes '%s'") % (path, dir), |
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
292 |
msgid="%s%s.3" % (self.name, "001")) |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
293 |
if len(list) > 0: |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
294 |
result = _("bad RUNPATH, '%%s' includes '%s'" % |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
295 |
":".join(list)) |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
296 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
297 |
return result |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
298 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
299 |
def __elf_wrong_location_check(self, path): |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
300 |
result = None |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
301 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
302 |
ei = elf.get_info(path) |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
303 |
bits = ei.get("bits") |
495
4153db6738f5
7083378 clean up some unneeded pkg.linted attributes
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
464
diff
changeset
|
304 |
type = ei.get("type"); |
168
5884bc1edfdf
7026850 move ImageMagick to userland
Lukas Rovensky <Lukas.Rovensky@oracle.com>
parents:
145
diff
changeset
|
305 |
elems = os.path.dirname(path).split("/") |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
306 |
|
1146
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
307 |
path64 = False |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
308 |
for p in self.pathlist64: |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
309 |
if (p in elems): |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
310 |
path64 = True |
168
5884bc1edfdf
7026850 move ImageMagick to userland
Lukas Rovensky <Lukas.Rovensky@oracle.com>
parents:
145
diff
changeset
|
311 |
|
1146
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
312 |
path32 = False |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
313 |
for p in self.pathlist32: |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
314 |
if (p in elems): |
94088715b2bf
PSARC/2012/379 Add Perl 5.16 64-bit and make it the system default
Craig Mohrman <craig.mohrman@oracle.com>
parents:
1138
diff
changeset
|
315 |
path32 = True |
495
4153db6738f5
7083378 clean up some unneeded pkg.linted attributes
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
464
diff
changeset
|
316 |
|
4153db6738f5
7083378 clean up some unneeded pkg.linted attributes
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
464
diff
changeset
|
317 |
# ignore 64-bit executables in normal (non-32-bit-specific) |
4153db6738f5
7083378 clean up some unneeded pkg.linted attributes
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
464
diff
changeset
|
318 |
# locations, that's ok now. |
4153db6738f5
7083378 clean up some unneeded pkg.linted attributes
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
464
diff
changeset
|
319 |
if (type == "exe" and bits == 64 and path32 == False and path64 == False): |
4153db6738f5
7083378 clean up some unneeded pkg.linted attributes
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
464
diff
changeset
|
320 |
return result |
4153db6738f5
7083378 clean up some unneeded pkg.linted attributes
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
464
diff
changeset
|
321 |
|
168
5884bc1edfdf
7026850 move ImageMagick to userland
Lukas Rovensky <Lukas.Rovensky@oracle.com>
parents:
145
diff
changeset
|
322 |
if bits == 32 and path64: |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
323 |
result = _("32-bit object '%s' in 64-bit path") |
168
5884bc1edfdf
7026850 move ImageMagick to userland
Lukas Rovensky <Lukas.Rovensky@oracle.com>
parents:
145
diff
changeset
|
324 |
elif bits == 64 and not path64: |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
325 |
result = _("64-bit object '%s' in 32-bit path") |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
326 |
return result |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
327 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
328 |
def file_action(self, action, manifest, engine, pkglint_id="001"): |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
329 |
"""Checks for existence in the proto area.""" |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
330 |
|
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
331 |
if action.name not in ["file"]: |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
332 |
return |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
333 |
|
117
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
334 |
path = action.hash |
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
335 |
if path == None or path == 'NOHASH': |
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
336 |
path = action.attrs["path"] |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
337 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
338 |
# check for writable files without a preserve attribute |
145
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
339 |
if "mode" in action.attrs: |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
340 |
mode = action.attrs["mode"] |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
341 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
342 |
if (int(mode, 8) & 0222) != 0 and "preserve" not in action.attrs: |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
343 |
engine.error( |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
344 |
_("%(path)s is writable (%(mode)s), but missing a preserve" |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
345 |
" attribute") % {"path": path, "mode": mode}, |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
346 |
msgid="%s%s.0" % (self.name, pkglint_id)) |
145
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
347 |
elif "preserve" in action.attrs: |
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
348 |
if "mode" in action.attrs: |
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
349 |
mode = action.attrs["mode"] |
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
350 |
if (int(mode, 8) & 0222) == 0: |
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
351 |
engine.error( |
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
352 |
_("%(path)s has a preserve action, but is not writable (%(mode)s)") % {"path": path, "mode": mode}, |
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
353 |
msgid="%s%s.4" % (self.name, pkglint_id)) |
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
354 |
else: |
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
355 |
engine.error( |
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
356 |
_("%(path)s has a preserve action, but no mode") % {"path": path, "mode": mode}, |
1e2390f5555e
7020836 revert workaround in 7014413 now that pkglint doesn't complain
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
117
diff
changeset
|
357 |
msgid="%s%s.3" % (self.name, pkglint_id)) |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
358 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
359 |
# checks that require a physical file to look at |
117
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
360 |
if self.proto_path is not None: |
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
361 |
for directory in self.proto_path: |
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
362 |
fullpath = directory + "/" + path |
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
363 |
|
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
364 |
if os.path.exists(fullpath): |
8f634eb6f66b
7023683 userland pkglint checks should look in more places for content
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
99
diff
changeset
|
365 |
break |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
366 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
367 |
if not os.path.exists(fullpath): |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
368 |
engine.info( |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
369 |
_("%s missing from proto area, skipping" |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
370 |
" content checks") % path, |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
371 |
msgid="%s%s.1" % (self.name, pkglint_id)) |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
372 |
elif elf.is_elf_object(fullpath): |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
373 |
# 32/64 bit in wrong place |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
374 |
result = self.__elf_wrong_location_check(fullpath) |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
375 |
if result != None: |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
376 |
engine.error(result % path, |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
377 |
msgid="%s%s.2" % (self.name, pkglint_id)) |
623
15f87c23a86e
7109831 userland pkglint should audit runpaths
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
495
diff
changeset
|
378 |
result = self.__elf_runpath_check(fullpath, engine) |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
379 |
if result != None: |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
380 |
engine.error(result % path, |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
381 |
msgid="%s%s.3" % (self.name, pkglint_id)) |
1138
6e1f85fa0151
15801420 SUNBT7180909 tag the Userland consolidation binaries for ASLR
April Chin <april.chin@oracle.com>
parents:
1020
diff
changeset
|
382 |
result = self.__elf_aslr_check(fullpath, engine) |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
383 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
384 |
file_action.pkglint_desc = _("Paths should exist in the proto area.") |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
385 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
386 |
def link_resolves(self, action, manifest, engine, pkglint_id="002"): |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
387 |
"""Checks for link resolution.""" |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
388 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
389 |
if action.name not in ["link", "hardlink"]: |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
390 |
return |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
391 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
392 |
path = action.attrs["path"] |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
393 |
target = action.attrs["target"] |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
394 |
realtarget = self.__realpath(path, target) |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
395 |
|
186
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
396 |
# Check against the target image (ref_paths), since links might |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
397 |
# resolve outside the packages delivering a particular |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
398 |
# component. |
3adedf0f9f4d
7034764 dangling link check fails when links and targets are in different packages
Danek Duvall <danek.duvall@oracle.com>
parents:
181
diff
changeset
|
399 |
if not self.ref_paths.get(realtarget, None): |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
400 |
engine.error( |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
401 |
_("%s %s has unresolvable target '%s'") % |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
402 |
(action.name, path, target), |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
403 |
msgid="%s%s.0" % (self.name, pkglint_id)) |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
404 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
405 |
link_resolves.pkglint_desc = _("links should resolve.") |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
406 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
407 |
def init_script(self, action, manifest, engine, pkglint_id="003"): |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
408 |
"""Checks for SVR4 startup scripts.""" |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
409 |
|
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
410 |
if action.name not in ["file", "dir", "link", "hardlink"]: |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
411 |
return |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
412 |
|
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
413 |
path = action.attrs["path"] |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
414 |
if self.initscript_re.match(path): |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
415 |
engine.warning( |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
416 |
_("SVR4 startup '%s', deliver SMF" |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
417 |
" service instead") % path, |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
418 |
msgid="%s%s.0" % (self.name, pkglint_id)) |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
419 |
|
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
420 |
init_script.pkglint_desc = _( |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
421 |
"SVR4 startup scripts should not be delivered.") |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
422 |
|
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
423 |
class UserlandManifestChecker(base.ManifestChecker): |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
424 |
"""An opensolaris.org-specific class to check manifests.""" |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
425 |
|
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
426 |
name = "userland.manifest" |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
427 |
|
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
428 |
def __init__(self, config): |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
429 |
super(UserlandManifestChecker, self).__init__(config) |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
430 |
|
181
87e11e685b1f
7003927 userland should postprocess packaged files
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
168
diff
changeset
|
431 |
def component_check(self, manifest, engine, pkglint_id="001"): |
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
432 |
manifest_paths = [] |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
433 |
files = False |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
434 |
license = False |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
435 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
436 |
for action in manifest.gen_actions_by_type("file"): |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
437 |
files = True |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
438 |
break |
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
439 |
|
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
440 |
if files == False: |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
441 |
return |
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
442 |
|
84
b80cfd4e0a16
7000952 Userland package validation needs some love
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
45
diff
changeset
|
443 |
for action in manifest.gen_actions_by_type("license"): |
181
87e11e685b1f
7003927 userland should postprocess packaged files
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
168
diff
changeset
|
444 |
license = True |
87e11e685b1f
7003927 userland should postprocess packaged files
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
168
diff
changeset
|
445 |
break |
87e11e685b1f
7003927 userland should postprocess packaged files
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
168
diff
changeset
|
446 |
|
87e11e685b1f
7003927 userland should postprocess packaged files
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
168
diff
changeset
|
447 |
if license == False: |
87e11e685b1f
7003927 userland should postprocess packaged files
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
168
diff
changeset
|
448 |
engine.error( _("missing license action"), |
87e11e685b1f
7003927 userland should postprocess packaged files
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
168
diff
changeset
|
449 |
msgid="%s%s.0" % (self.name, pkglint_id)) |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
450 |
|
464
08f94c414553
7073736 need to turn _ into -
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
186
diff
changeset
|
451 |
if 'org.opensolaris.arc-caseid' not in manifest: |
08f94c414553
7073736 need to turn _ into -
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
186
diff
changeset
|
452 |
engine.error( _("missing ARC data (org.opensolaris.arc-caseid)"), |
181
87e11e685b1f
7003927 userland should postprocess packaged files
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
168
diff
changeset
|
453 |
msgid="%s%s.0" % (self.name, pkglint_id)) |
45
536ea324b223
initial content validation check extension for pkglint
Norm Jacobs <Norm.Jacobs@Sun.COM>
parents:
diff
changeset
|
454 |
|
181
87e11e685b1f
7003927 userland should postprocess packaged files
Norm Jacobs <Norm.Jacobs@Oracle.COM>
parents:
168
diff
changeset
|
455 |
component_check.pkglint_dest = _( |
464
08f94c414553
7073736 need to turn _ into -
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
186
diff
changeset
|
456 |
"license actions and ARC information are required if you deliver files.") |
1020
4740049105f5
7030489 userland pkglint should check for publisher information in pkg.fmris
Rich Burridge <rich.burridge@oracle.com>
parents:
623
diff
changeset
|
457 |
|
4740049105f5
7030489 userland pkglint should check for publisher information in pkg.fmris
Rich Burridge <rich.burridge@oracle.com>
parents:
623
diff
changeset
|
458 |
def publisher_in_fmri(self, manifest, engine, pkglint_id="002"): |
4740049105f5
7030489 userland pkglint should check for publisher information in pkg.fmris
Rich Burridge <rich.burridge@oracle.com>
parents:
623
diff
changeset
|
459 |
lint_id = "%s%s" % (self.name, pkglint_id) |
4740049105f5
7030489 userland pkglint should check for publisher information in pkg.fmris
Rich Burridge <rich.burridge@oracle.com>
parents:
623
diff
changeset
|
460 |
allowed_pubs = engine.get_param( |
4740049105f5
7030489 userland pkglint should check for publisher information in pkg.fmris
Rich Burridge <rich.burridge@oracle.com>
parents:
623
diff
changeset
|
461 |
"%s.allowed_pubs" % lint_id).split(" ") |
4740049105f5
7030489 userland pkglint should check for publisher information in pkg.fmris
Rich Burridge <rich.burridge@oracle.com>
parents:
623
diff
changeset
|
462 |
|
4740049105f5
7030489 userland pkglint should check for publisher information in pkg.fmris
Rich Burridge <rich.burridge@oracle.com>
parents:
623
diff
changeset
|
463 |
fmri = manifest.fmri |
4740049105f5
7030489 userland pkglint should check for publisher information in pkg.fmris
Rich Burridge <rich.burridge@oracle.com>
parents:
623
diff
changeset
|
464 |
if fmri.publisher and fmri.publisher not in allowed_pubs: |
4740049105f5
7030489 userland pkglint should check for publisher information in pkg.fmris
Rich Burridge <rich.burridge@oracle.com>
parents:
623
diff
changeset
|
465 |
engine.error(_("package %s has a publisher set!") % |
4740049105f5
7030489 userland pkglint should check for publisher information in pkg.fmris
Rich Burridge <rich.burridge@oracle.com>
parents:
623
diff
changeset
|
466 |
manifest.fmri, |
4740049105f5
7030489 userland pkglint should check for publisher information in pkg.fmris
Rich Burridge <rich.burridge@oracle.com>
parents:
623
diff
changeset
|
467 |
msgid="%s%s.2" % (self.name, pkglint_id)) |