~ruther/guix-local

48a1bb314dd77916203deadc8ce7bc664e0f95f9 — Marius Bakke 4 years ago d2af1df
gnu: ungoogled-chromium: Enable RUNPATH validation.

* gnu/packages/patches/ungoogled-chromium-RUNPATH.patch: New file.
* gnu/local.mk (dist_patch_DATA): Adjust accordingly.
* gnu/packages/chromium.scm (%guix-patches): Add it.
(ungoogled-chromium)[arguments]: Remove #:validate-runpath?.
3 files changed, 26 insertions(+), 2 deletions(-)

M gnu/local.mk
M gnu/packages/chromium.scm
A gnu/packages/patches/ungoogled-chromium-RUNPATH.patch
M gnu/local.mk => gnu/local.mk +1 -0
@@ 1849,6 1849,7 @@ dist_patch_DATA =						\
  %D%/packages/patches/ucx-tcp-iface-ioctl.patch		\
  %D%/packages/patches/ungoogled-chromium-extension-search-path.patch	\
  %D%/packages/patches/ungoogled-chromium-ffmpeg-compat.patch	\
  %D%/packages/patches/ungoogled-chromium-RUNPATH.patch		\
  %D%/packages/patches/ungoogled-chromium-system-nspr.patch	\
  %D%/packages/patches/unison-fix-ocaml-4.08.patch		\
  %D%/packages/patches/unknown-horizons-python-3.8-distro.patch	\

M gnu/packages/chromium.scm => gnu/packages/chromium.scm +3 -2
@@ 375,6 375,9 @@
          (search-patch "ungoogled-chromium-extension-search-path.patch")))
        (local-file
         (assume-valid-file-name
          (search-patch "ungoogled-chromium-RUNPATH.patch")))
        (local-file
         (assume-valid-file-name
          (search-patch "ungoogled-chromium-ffmpeg-compat.patch")))
        (local-file
         (assume-valid-file-name


@@ 483,8 486,6 @@
    (build-system gnu-build-system)
    (arguments
     `(#:tests? #f
       ;; FIXME: Chromiums RUNPATH lacks entries for some libraries.
       #:validate-runpath? #f
       #:modules ((guix build gnu-build-system)
                  (guix build utils)
                  (srfi srfi-26))

A gnu/packages/patches/ungoogled-chromium-RUNPATH.patch => gnu/packages/patches/ungoogled-chromium-RUNPATH.patch +22 -0
@@ 0,0 1,22 @@
Use RUNPATH instead of RPATH so that end users can override the library
search path (and the 'validate-runpath' phase can do its work).

diff --git a/build/config/gcc/BUILD.gn b/build/config/gcc/BUILD.gn
--- a/build/config/gcc/BUILD.gn
+++ b/build/config/gcc/BUILD.gn
@@ -99,7 +99,14 @@ config("executable_config") {
     ]
   }
 
-  if (!is_android && current_os != "aix") {
+  if (is_linux) {
+    ldflags += [
+      # Set DT_RUNPATH instead of DT_RPATH which is important because the
+      # former can be overridden at runtime, and Guix has support for
+      # verifying that nothing is missing.
+      "-Wl,--enable-new-dtags",
+    ]
+  } else if (!is_android && current_os != "aix") {
     ldflags += [
       # TODO(GYP): Do we need a check on the binutils version here?
       #