96d3d01796
The reason for combining these patches is because the old version of setools is not compatible iwth libsepol 2.7. If a user where to do a git pull on a patch that only updates libsepol or setools, the build would fail to compile. setools has been completely rewritten in python instead of C. The current version of setools includes a few programs that require python-qt5 or python-networkx to run, however the package does not check to see if these exist when compiling, and will install the scripts to the target directory even if they don't exist. In the case of python-networkx, this package is not available on Buildroot. The scripts that require them are: sedta and seinfoflow. In the case of python-qt5, qpol is the script that requires it. Some setools.mk notes to get the package to compile: - Convert the package .mk to use python-package instead of autotools-package. - setup.py hard codes base_lib_dirs to point to several host directories. To fix this, sed is used before compiling to point the base_lib_dirs to the staging directory. - setup.py also includes the "Werror" flag, however compilers before gcc6 cause a few autogenerated variables to not be initialized before use, causing the build to fail. To fix this, a patch is provided that removes the Werror flag. - Remove sedta and seinfoflow from the target system after install. These packages rely on the package python-networkx which is not available in buildroot. - Remove the installed apol package and the setoolsgui directory from the target directory if python-qt5 is not selected. Other changes: - Removed all patches, as they are not compatible with the new version of setools. - Add COPYING, COPYING.GPL, and COPYING.LGPL to setools.hash Signed-off-by: Adam Duskett <Adamduskett@outlook.com> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
28 lines
1.1 KiB
Plaintext
28 lines
1.1 KiB
Plaintext
config BR2_PACKAGE_SETOOLS
|
|
bool "setools"
|
|
depends on !BR2_arc # arc: libselinux not available
|
|
depends on !BR2_STATIC_LIBS
|
|
depends on BR2_TOOLCHAIN_HAS_THREADS
|
|
depends on BR2_USE_WCHAR
|
|
depends on BR2_TOOLCHAIN_USES_GLIBC # libselinux
|
|
depends on BR2_USE_MMU
|
|
select BR2_PACKAGE_PYTHON3 if !BR2_PACKAGE_PYTHON
|
|
select BR2_PACKAGE_PYTHON_ENUM34 if !BR2_PACKAGE_PYTHON3
|
|
select BR2_PACKAGE_PYTHON_SETUPTOOLS
|
|
select BR2_PACKAGE_LIBSELINUX
|
|
help
|
|
SETools is an open source project designed to facilitate
|
|
SELinux policy analysis. The primary tools are:
|
|
* apol - analyze a SELinux policy. (requires python-qt5)
|
|
* sediff - semantic policy difference tool for SELinux.
|
|
* sedta - Perform domain transition analyses
|
|
* sesearch - Search rules (allow, type_transition, etc.)
|
|
|
|
https://github.com/TresysTechnology/setools
|
|
|
|
comment "setools needs a glibc toolchain w/ threads, C++, wchar, dynamic library"
|
|
depends on BR2_USE_MMU && !BR2_arc
|
|
depends on !BR2_TOOLCHAIN_HAS_THREADS || BR2_STATIC_LIBS || \
|
|
!BR2_USE_WCHAR || !BR2_TOOLCHAIN_USES_GLIBC || \
|
|
!BR2_INSTALL_LIBSTDCPP
|