do not edit — generated by btf.
git.druid.rocksindexdruid520portsports/coreutils/busybox/add.sh

ports/coreutils/busybox/add.sh


set -e
 
git clone git://git.busybox.net/busybox.git
cd busybox
# gmake by name, not bare "make": busybox's kbuild-derived Makefile (same
# lineage as the Linux kernel's) uses GNU-make-only constructs throughout,
# same class of requirement as libcs/musl's own Makefile (see its add.sh
# for the fuller story) - and for the same reason musl gives, gmake is
# called by name here rather than declared as a formal pkg_deps: busybox
# is this tree's %coreutils provider (TAG_coreutils), and gmake's own
# build needs autotools, which (via GLOBAL_DEPS) needs %coreutils too -
# a formal dependency would be a real cycle back to busybox itself.
# install gmake once with a plain "mp install build-tools/gmake" before
# updating/rebuilding busybox.
#
# HOST_EXTRACFLAGS on every gmake invocation below, "defconfig" included:
# kbuild's HOSTCC (fixdep and other build-time-only helper tools, compiled
# to run on the build machine, not the target - "defconfig" itself
# already needs fixdep, not just the main build) gets none of runsh's own
# CFLAGS wiring, just gcc's bare defaults, which (same gap as compilers/
# gcc/add.sh's own --with-native-system-header-dir comment) don't know
# where this sysroot's real libc headers are, so HOSTCC's own compiles
# fail to find even <sys/types.h>. HOST_EXTRACFLAGS is kbuild's own,
# purpose-built extension point for exactly this (additive - see
# scripts/Makefile.host's own "$(HOSTCFLAGS) $(HOST_EXTRACFLAGS)" - it
# doesn't fight the Makefile's own base HOSTCFLAGS the way overriding
# HOSTCFLAGS directly would).
#
# ${MP_PREFIX_BASE:-$MP_PREFIX}, not a bare $MP_PREFIX: an ephemeral "mp
# reinstall --inplace" build's own $MP_PREFIX is a fresh, empty scratch
# prefix on purpose (see mplib::resolve's own INPLACE_BASE comment) --
# the live root's real headers are at MP_PREFIX_BASE instead in that
# case. a normal (non-inplace, non-slotted) build never sets it, so the
# fallback keeps that case identical to before. same fix as libraries/
# linux-headers' own identical HOST_EXTRACFLAGS gap.
bb_base="${MP_PREFIX_BASE:-$MP_PREFIX}"
# wget's own openssl-helper code path (networking/wget.c) unconditionally
# passes "-verify_hostname"/"-verify_ip" to whatever "openssl" binary it
# finds on PATH -- real OpenSSL-only flags this system's "openssl" (ssl/
# libressl's own CLI, API-compatible but not flag-for-flag identical)
# doesn't recognize, so s_client prints a usage error and exits before
# ever connecting. wget's own fallback to its built-in ssl_client applet
# (which works fine on its own, verified directly) only triggers if
# exec("openssl") itself fails to start, not if the child starts and
# dies from a bad flag afterward -- so every single wget https:// fetch
# failed outright ("Connection reset by peer", the misleading symptom of
# the child dying immediately) regardless of the actual target host.
# removing just the hostname/IP verification block (both branches -- the
# if/else itself, not only the two bad flags) keeps the chain-validation
# flags ("-verify 100 -verify_return_error") that DO work intact, so
# this is a real security reduction (no hostname match) but not a total
# one (still rejects an untrusted CA chain).
#
# perl -0777, anchored on the unique preceding "-verify_return_error"
# line, not a line-count-based sed range: this exact function has a
# SECOND, unrelated "if (!is_ip_address(servername)) {" earlier (a
# 4-line SNI-servername block), and sed's range addressing applies to
# EVERY match, not just the first -- a "+6d" deletion anchored on the
# bare if-condition alone hit both occurrences, overshooting 3 lines
# into the following code at the first (shorter) one and corrupting the
# file outright ("argv undeclared", "conflicting types for free" -- a
# real, reproduced breakage, not a hypothetical). the preceding
# "-verify_return_error" line only ever appears immediately before the
# SECOND occurrence, making this anchor unambiguous.
perl -0777 -pi -e 's/(\*argp\+\+ = \(char\*\)"-verify_return_error"; \/\/\[9\]\n)\t\t\tif \(!is_ip_address\(servername\)\) \{\n\t\t\t\t\*argp\+\+ = \(char\*\)"-verify_hostname"; \/\/\[10\]\n\t\t\t\t\*argp\+\+ = \(char\*\)servername;         \/\/\[11\]\n\t\t\t\} else \{\n\t\t\t\t\*argp\+\+ = \(char\*\)"-verify_ip"; \/\/\[10\]\n\t\t\t\t\*argp\+\+ = \(char\*\)host;         \/\/\[11\]\n\t\t\t\}\n/$1/s' networking/wget.c
# scripts/Makefile.lib's own "ld_flags" (used ONLY by Makefile.build's
# partial-link rule, cmd_link_o_target -- kbuild combines each
# subdirectory's *.o into one built-in.o via "ld -r" before the real,
# final busybox link) already filters "-Wl,..." out of $(LDFLAGS) for
# exactly this reason: some linker flags that are fine at the REAL final
# link make no sense (or outright conflict) on a partial, not-yet-an-
# executable "ld -r" relink. -pie/-static-pie is the same story, just
# not already covered: "-r and -pie may not be used together" is a hard
# ld error, breaking the very first applets/built-in.o under a global
# -static-pie LDFLAGS policy. the REAL final busybox link (Makefile's
# own cmd_busybox__ rule) reads $(LDFLAGS) directly, not through this
# filtered ld_flags, so appending to the existing filter-out list here
# (not replacing it) only touches the partial-link step -- the actual
# busybox executable still gets linked -static-pie as intended.
sed -i 's/^ld_flags       = \$(filter-out -Wl\$(comma)%,\$(LDFLAGS) \$(EXTRA_LDFLAGS))$/ld_flags       = $(filter-out -Wl$(comma)% -pie -static-pie -no-pie -fno-pie,$(LDFLAGS) $(EXTRA_LDFLAGS))/' scripts/Makefile.lib
gmake HOST_EXTRACFLAGS="-I$bb_base/include" defconfig
# tc's CBQ qdisc support (networking/tc.c) references kernel structures
# (tc_cbq_lssopt, tc_cbq_wrropt, TCA_CBQ_*) that were removed from
# mainline Linux headers years ago - CBQ itself is long gone from the
# kernel, busybox's tc.c just never dropped the code. not something a
# newer/older header revision fixes, and not applet this environment
# needs - disabled outright rather than chasing kernel-header versions.
sed -i 's/^CONFIG_TC=y/CONFIG_TC=n/' .config
# FEATURE_EJECT_SCSI needs scsi/sg.h - a real kernel UAPI header, but one
# that's specifically about talking to physical SCSI hardware, not
# something a container/server image has any use for. basic EJECT
# (generic CD-ROM eject ioctl, no scsi/sg.h needed) stays on; only the
# SCSI-specific sub-feature is disabled.
sed -i 's/^CONFIG_FEATURE_EJECT_SCSI=y/CONFIG_FEATURE_EJECT_SCSI=n/' .config
# login/su/passwd/chpasswd/nologin are where busybox's own applets and
# sysutils/shadow's own binaries collide on filenames -- busybox's
# versions are a minimal fallback for systems with no real shadow-utils
# installed at all; this ports tree ships a full shadow package as the
# intended, correct provider whenever it's present, so busybox defers
# to it rather than the two fighting over the same paths. USE_shadow
# (see pkg.conf's own pkg_use) opts into that - only meaningful when
# sysutils/shadow is also being installed, off by default so a busybox-
# only system keeps its own set.
#
# this needs to be the COMPLETE overlap, not just login/su: busybox's
# own passwd/chpasswd/nologin install to busybox's own BB_DIR_USR_BIN/
# BB_DIR_USR_SBIN (/usr/bin, /usr/sbin), while shadow's own equivalents
# land at /bin, /sbin (bin/passwd, sbin/chpasswd, sbin/nologin per its
# own manifest) -- DIFFERENT paths, so unlike login/su (a literal same-
# path overwrite) these don't collide on install, they silently compete
# via $PATH ORDER instead, and /usr/bin:/usr/sbin winning ahead of
# /bin:/sbin on this system means busybox's own versions were the ones
# actually being invoked. passwd in particular is a real, confirmed
# functional break, not just a wasteful duplicate: busybox's own binary
# is never made setuid root (see this port's own install-time "should
# be suid" reminder), so its passwd applet can never actually write
# /etc/shadow -- shadow's own bin/passwd IS correctly setuid (its own
# build handles that itself), but was being shadowed right back by
# busybox's non-functional one on every plain "passwd" invocation.
if [ -n "$USE_shadow" ]; then
	sed -i 's/^CONFIG_LOGIN=y/CONFIG_LOGIN=n/' .config
	sed -i 's/^CONFIG_SU=y/CONFIG_SU=n/' .config
	sed -i 's/^CONFIG_PASSWD=y/CONFIG_PASSWD=n/' .config
	sed -i 's/^CONFIG_CHPASSWD=y/CONFIG_CHPASSWD=n/' .config
	sed -i 's/^CONFIG_NOLOGIN=y/CONFIG_NOLOGIN=n/' .config
fi
# init: see pkg.conf's pkg_use - defers to a real init port's own
# /sbin/init instead of silently overwriting it back to busybox's own
# on every reinstall/update.
if [ -n "$USE_init" ]; then
	sed -i 's/^CONFIG_INIT=y/CONFIG_INIT=n/' .config
	sed -i 's/^CONFIG_LINUXRC=y/CONFIG_LINUXRC=n/' .config
fi
# awk: see pkg.conf's own pkg_use - defers to a real %awk provider's
# own "awk" instead of silently overwriting it back to busybox's own
# (a genuine gsub() escaping bug, not just a heavier/lighter choice)
# on every reinstall/update.
if [ -n "$USE_awk" ]; then
	sed -i 's/^CONFIG_AWK=y/CONFIG_AWK=n/' .config
fi
# patch: see pkg.conf's own pkg_use -- off by default and recommended
# to stay that way (this tree's own patch pipeline never needs more
# than busybox's own applet provides); only turns off CONFIG_PATCH
# (deferring to a real %patch provider instead) when explicitly asked.
if [ -n "$USE_patch" ]; then
	sed -i 's/^CONFIG_PATCH=y/CONFIG_PATCH=n/' .config
fi
# terminfo: see pkg.conf's own pkg_use -- defers to ncurses' own real,
# terminfo-database-aware "clear"/"reset" instead of busybox's own
# trivial ESC-code-only versions (busybox's own console-tools/reset.c
# already says so itself: "'Standard' version of this tool is in
# ncurses package"). hit for real: a plain "mp reinstall busybox" on a
# system that also has ncurses installed unconditionally overwrote
# ncurses' own /usr/bin/clear and /usr/bin/reset with busybox's own
# symlinks, rejected outright by mp's own file-conflict check --
# same shape as awk/patch above, avoided at the source instead of
# fought over after the fact.
if [ -n "$USE_terminfo" ]; then
	sed -i 's/^CONFIG_CLEAR=y/CONFIG_CLEAR=n/' .config
	sed -i 's/^CONFIG_RESET=y/CONFIG_RESET=n/' .config
fi
gmake HOST_EXTRACFLAGS="-I$bb_base/include" -j$MP_JOBS
# applets/install.sh (busybox's own vendored installer script) does
# "rm -f $prefix/bin/busybox" before reinstalling it - harmless on a
# normal system, where the shell actually running this script is a real,
# separate binary (bash/dash/whatever), but not here: /bin/sh (and
# /bin/mkdir, and everything else this same script goes on to call) is
# ALSO busybox, via symlink - deleting it out from under the very
# interpreter running this script breaks every subsequent command in it,
# the same self-referential hazard already hit and fixed for libcs/musl's
# own libc.so (see that add.sh's own comment for the fuller story).
# neutralized instead of patched out entirely: the "install -m 755"
# right after it already overwrites the file safely on its own (that's
# what install(1) is for), making the preceding rm both redundant and
# actively harmful here.
# applets/install.sh's own $prefix argument is meant to be the FHS
# ROOT ("/"), not "/usr" -- its own applet list (busybox.links) already
# carries the FULL FHS-absolute path for every applet ("/bin/cat",
# "/usr/bin/["), joined onto $prefix unconditionally ($prefix/$i). this
# tree's own convention passes CONFIG_PREFIX=$MP_PREFIX (below) --
# itself effectively THIS system's own "/usr" -- so every "usr-tier"
# applet ends up double-prefixed: "/usr" + "/usr/bin/[" = a real,
# separate "/usr/usr/bin/[" (confirmed directly: the whole stray
# /usr/usr/bin + /usr/usr/sbin directory tree existed on a real running
# system before this fix, not just a hypothetical). the SAME root
# cause also explains an unrelated-looking cosmetic oddity: applets
# that DO land in the right place regardless (the "/bin"-tier ones,
# unaffected since they never had a "/usr" to double up) get a flat,
# same-directory "busybox" symlink, while the "/usr/bin"-tier ones
# get an unnecessarily deep "../../bin/busybox" -- computed assuming a
# real two-level "/usr/bin" nesting under $prefix that this tree's own
# single-"/usr"-as-root convention never actually has.
#
# stripping a leading "/usr" off $i right where the main install loop
# reads it fixes both at once: "/usr/bin/[" becomes "/bin/[", so
# $prefix/$i lands at the correct single-prefixed path (no more
# /usr/usr/*), AND $appdir (derived from that same, now-shortened $i)
# hits the case statement's own "/bin" branch instead of "/usr/bin",
# producing the same flat "busybox" symlink every other applet already
# gets -- not a separate fix, the one adjustment corrects both symptoms
# because they were always the one underlying mismatch. verified
# directly: a real from-scratch build+install with this patch applied
# produces bin/[ -> busybox (not usr/bin/[ -> ../../bin/busybox), and
# no usr/ directory at all under the install destination.
sed -i '/^for i in \$h; do$/a\
	i=${i#/usr}' applets/install.sh
sed -i 's/^rm -f "\$prefix\/bin\/busybox" || exit 1$/true/' applets/install.sh
gmake HOST_EXTRACFLAGS="-I$bb_base/include" CONFIG_PREFIX=$MP_PREFIX install
powered by btf.