🔒 Repository is read-only – file editing is disabled.

PaganLinux/tmp-patch-rest2.py main

95 linii Raw ← Powrót
1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495
#!/usr/bin/env python3
"""Poprawki receptur z zachowaniem wciecia i stylu zapisu (blok / escaped).

Punkt 6: sudo secure_path.  Punkt 8: bezpieczniejsze hooki.
"""
import re, sys, yaml

R = "/var/lib/pagan-sync/recipes"


def _patterns(old_lines):
    pats = []
    for sep in ("\n[ \t]*", r"\\n[ \t]*"):
        pats.append(r"^([ \t]*)" + sep.join(re.escape(l) for l in old_lines))
    return pats


def edit_block(path, old_lines, new_lines, label):
    text = open(path, encoding="utf-8").read()
    for pat in _patterns(new_lines) + _patterns(old_lines):
        if re.search(pat, text):
            print(f"--  {label} (juz zastosowane)")
            return
    for pat in _patterns(old_lines):
        m = list(re.finditer(pat, text, re.M))
        if len(m) != 1:
            continue
        hit = m[0]
        ind = hit.group(1)
        sep = "\n" + ind if "\\n" not in pat.split(")")[1][:4] else r"\n" + ind
        repl = ind + sep.join(new_lines)
        open(path, "w", encoding="utf-8").write(text[:hit.start()] + repl + text[hit.end():])
        print(f"OK  {label}")
        return
    found = [len(re.findall(p, text, re.M)) for p in _patterns(old_lines)]
    sys.exit(f"[{label}] {path}: dopasowan {found}")


def bump(path, label):
    text = open(path, encoding="utf-8").read()
    m = re.search(r"(?m)^pkgrel:\s*'?(\d+)'?\s*$", text)
    if not m:
        sys.exit(f"[{label}] brak pkgrel")
    n = int(m.group(1)) + 1
    open(path, "w", encoding="utf-8").write(text[:m.start()] + f"pkgrel: '{n}'" + text[m.end():])
    print(f"OK  {label}: pkgrel -> {n}")


# ── 6. sudo: secure_path ──
SU = f"{R}/core/sudo/PAGBUILD.yaml"
edit_block(SU,
           ['echo "%wheel ALL=(ALL) ALL" >> ${PKGDIR}/etc/sudoers'],
           ['echo "Defaults secure_path=\\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\\"" >> ${PKGDIR}/etc/sudoers',
            'echo "%wheel ALL=(ALL) ALL" >> ${PKGDIR}/etc/sudoers'],
           "sudo: secure_path")
bump(SU, "sudo")

# ── 8. hooki ──
BA = f"{R}/core/bash/PAGBUILD.yaml"
edit_block(BA, ["rm -f bin/sh", "rm -f bin/bash"],
           ["# Usuniete kasowanie /bin/sh i /bin/bash: pakiet dostarcza oba pliki,",
            "# a gdy transakcja padala po rm, system zostawal bez powloki."],
           "bash: bez rm /bin/sh")
bump(BA, "bash")

GL = f"{R}/core/glibc/PAGBUILD.yaml"
edit_block(GL, ["rm -f /etc/nsswitch.conf"],
           ["# Usuniete kasowanie /etc/nsswitch.conf: plik jest w pakiecie, a pag",
            "# chroni zmiany uzytkownika (zapisuje .pacnew) - rm byl zbedny."],
           "glibc: bez rm nsswitch.conf")
bump(GL, "glibc")

NG = f"{R}/utils/nginx/PAGBUILD.yaml"
edit_block(NG,
           ["(getent passwd $UN > /dev/null) && userdel $UN",
            "(getent group $UN > /dev/null) && groupdel $UN"],
           ["# Usuniete kasowanie uzytkownika/grupy $UN: userdel zostawial pliki",
            "# z osieroconym uid. Wlasciwe konto jest tworzone ponizej."],
           "nginx: bez userdel (www)")
bump(NG, "nginx")

PA = f"{R}/gui/pulseaudio/PAGBUILD.yaml"
edit_block(PA,
           ["grep -qe 'autospawn = no' etc/pulse/client.conf||sudo sed '/autospawn/iautospawn = no' -i etc/pulse/client.conf"],
           ["grep -qe 'autospawn = no' etc/pulse/client.conf || sed -i '/autospawn/iautospawn = no' etc/pulse/client.conf"],
           "pulseaudio: bez sudo")
bump(PA, "pulseaudio")

TI = f"{R}/gui/telepathy-idle/PAGBUILD.yaml"
edit_block(TI, ["killall -HUP dbus-daemon 2>&1"],
           ["systemctl reload dbus 2>/dev/null || true"],
           "telepathy-idle: reload dbus")
bump(TI, "telepathy-idle")

print("gotowe")