aboutsummaryrefslogtreecommitdiffstats
path: root/community/webkit2gtk/APKBUILD
blob: bda479b8607486bb7c01be344b8bbdc57de99d01 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
# Contributor: Rasmus Thomsen <oss@cogitri.dev>
# Contributor: Sergei Lukin <sergej.lukin@gmail.com>
# Contributor: Jiri Horner <laeqten@gmail.com>
# Maintainer: Rasmus Thomsen <oss@cogitri.dev>
pkgname=webkit2gtk
pkgver=2.30.5
pkgrel=0
pkgdesc="Portable web rendering engine WebKit for GTK+"
url="https://webkitgtk.org/"
arch="all !mips !mips64"
license="LGPL-2.0-or-later AND BSD-2-Clause"
depends="bubblewrap xdg-dbus-proxy dbus:org.freedesktop.Secrets"
makedepends="
	bison
	cmake
	enchant2-dev
	flex
	geoclue-dev
	gnutls-dev
	gobject-introspection-dev
	gperf
	gst-plugins-bad-dev
	gst-plugins-base-dev
	gstreamer-dev
	gtk+3.0-dev
	gtk-doc
	hyphen-dev
	icu-dev
	libgcrypt-dev
	libjpeg-turbo-dev
	libnotify-dev
	libpng-dev
	libseccomp-dev
	libsecret-dev
	libsoup-dev
	libwebp-dev
	libxml2-dev
	libxslt-dev
	libxt-dev
	mesa-dev
	openjpeg-dev
	openjpeg-tools
	pango-dev
	paxmark
	python3
	ruby
	samurai
	sqlite-dev
	woff2-dev
	ruby-json
	libwpe-dev
	libwpebackend-fdo-dev
	"
replaces="webkit"
options="!check" # upstream doesn't package them in release tarballs: Tools/Scripts/run-gtk-tests: Command not found
subpackages="$pkgname-dev $pkgname-lang $pkgname-dbg"
source="https://webkitgtk.org/releases/webkitgtk-$pkgver.tar.xz
	fix-fast-memory-disabled.patch
	musl-fixes.patch
	fix-openjpeg.patch
	lower-stack-usage.patch
	"
builddir="$srcdir/webkitgtk-$pkgver"

# secfixes:
#   2.30.5-r0:
#     - CVE-2020-13558
#   2.28.4-r0:
#     - CVE-2020-9862
#     - CVE-2020-9893
#     - CVE-2020-9894
#     - CVE-2020-9895
#     - CVE-2020-9915
#     - CVE-2020-9925
#   2.28.3-r0:
#     - CVE-2020-9802
#     - CVE-2020-9803
#     - CVE-2020-9805
#     - CVE-2020-9806
#     - CVE-2020-9807
#     - CVE-2020-9843
#     - CVE-2020-9850
#     - CVE-2020-13753
#   2.28.1-r0:
#     - CVE-2020-11793
#   2.28.0-r0:
#     - CVE-2020-10018
#   2.26.3-r0:
#     - CVE-2019-8835
#     - CVE-2019-8844
#     - CVE-2019-8846
#   2.26.2-r0:
#     - CVE-2019-8812
#     - CVE-2019-8814
#   2.26.1-r0:
#     - CVE-2019-8783
#     - CVE-2019-8811
#     - CVE-2019-8813
#     - CVE-2019-8816
#     - CVE-2019-8819
#     - CVE-2019-8820
#     - CVE-2019-8823
#   2.26.0-r0:
#     - CVE-2019-8625
#     - CVE-2019-8710
#     - CVE-2019-8720
#     - CVE-2019-8743
#     - CVE-2019-8764
#     - CVE-2019-8766
#     - CVE-2019-8769
#     - CVE-2019-8771
#     - CVE-2019-8782
#     - CVE-2019-8815
#   2.24.4-r0:
#     - CVE-2019-8674
#     - CVE-2019-8707
#     - CVE-2019-8719
#     - CVE-2019-8733
#     - CVE-2019-8763
#     - CVE-2019-8765
#     - CVE-2019-8768
#     - CVE-2019-8821
#     - CVE-2019-8822
#   2.24.3-r0:
#     - CVE-2019-8644
#     - CVE-2019-8649
#     - CVE-2019-8658
#     - CVE-2019-8666
#     - CVE-2019-8669
#     - CVE-2019-8671
#     - CVE-2019-8672
#     - CVE-2019-8673
#     - CVE-2019-8676
#     - CVE-2019-8677
#     - CVE-2019-8678
#     - CVE-2019-8679
#     - CVE-2019-8680
#     - CVE-2019-8681
#     - CVE-2019-8683
#     - CVE-2019-8684
#     - CVE-2019-8686
#     - CVE-2019-8687
#     - CVE-2019-8688
#     - CVE-2019-8689
#     - CVE-2019-8690
#     - CVE-2019-8726
#   2.24.2-r0:
#     - CVE-2019-8735
#   2.24.1-r0:
#     - CVE-2019-6251
#     - CVE-2019-8506
#     - CVE-2019-8524
#     - CVE-2019-8535
#     - CVE-2019-8536
#     - CVE-2019-8544
#     - CVE-2019-8551
#     - CVE-2019-8558
#     - CVE-2019-8559
#     - CVE-2019-8563
#     - CVE-2019-11070
#   2.22.7-r0:
#     - CVE-2018-4437
#     - CVE-2019-6212
#     - CVE-2019-6215
#     - CVE-2019-6216
#     - CVE-2019-6217
#     - CVE-2019-6227
#     - CVE-2019-6229
#   2.22.4-r0:
#     - CVE-2018-4372
#   2.18.4-r0:
#     - CVE-2017-7156
#     - CVE-2017-7157
#     - CVE-2017-13856
#     - CVE-2017-13866
#     - CVE-2017-13870
#   2.14.5-r0:
#     - CVE-2017-2350
#     - CVE-2017-2354
#     - CVE-2017-2355
#     - CVE-2017-2356
#     - CVE-2017-2362
#     - CVE-2017-2363
#     - CVE-2017-2364
#     - CVE-2017-2365
#     - CVE-2017-2366
#     - CVE-2017-2369
#     - CVE-2017-2371
#     - CVE-2017-2373

build() {
	local _archopt=
	case "$CARCH" in
		# disable _FORTIFY_SOURCE to work around:
		# cc1plus: out of memory allocating 65536 bytes after a total of 3131101184 bytes
		x86) CXXFLAGS="$CXXFLAGS -U_FORTIFY_SOURCE";;
		armhf|ppc64le|s390x) _archopt="-DENABLE_JIT=OFF";;
	esac

	# reduce memory usage on 32 bit
	# https://bugs.webkit.org/show_bug.cgi?id=199272
	export CXXFLAGS="$CXXFLAGS -g1"

	mkdir build
	cd build
	# disable gold usage since it can't find pthreads with it enabled
	cmake -GNinja \
		-DPORT=GTK \
		-DCMAKE_BUILD_TYPE=MinSizeRel \
		-DCMAKE_SKIP_RPATH=ON \
		-DCMAKE_INSTALL_PREFIX=/usr \
		-DLIB_INSTALL_DIR=/usr/lib \
		-DENABLE_GTKDOC=OFF \
		-DENABLE_GEOLOCATION=ON \
		-DENABLE_SAMPLING_PROFILER=OFF \
		-DENABLE_MINIBROWSER=ON \
		-DUSE_WPE_RENDERER=ON \
		-DUSE_WOFF2=ON \
		-DCMAKE_CXX_FLAGS="$CXXFLAGS" \
		-DUSE_LD_GOLD=OFF \
		-DUSE_SYSTEMD=OFF \
		$_archopt \
		..
	# https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=923476
	ninja JavaScriptCore-4-gir
	ninja
}

check() {
	ninja -C "$builddir"/build check
}

package() {
	DESTDIR="$pkgdir" ninja -C "$builddir"/build install
	# needed for JIT
	paxmark -m "$pkgdir"/usr/libexec/webkit2gtk-4.0/WebKitWebProcess
}

sha512sums="406fc767a806bb2af446c73e7079720a4d82d592a95a20f30f468c31cdc2efd25e082a5ecfbe00c27f62236e1e56a729c48191451d130188419967975378235d  webkitgtk-2.30.5.tar.xz
e1537b9937af1cb936669d405993a52204cb9968b8b3161cb12a3f3f1343c260088c9490fcd7a7deeab6dbabdb5f7ce7e6cb2f857b9f0a4205aba6db2b11fb20  fix-fast-memory-disabled.patch
4c0093e4a38c8ceb3ac92b94539ec1417241814a84abd157442f53f710ecbaf9c2345e258b8ad86d5e0908cacbfca6cad28dedd11c127756b65428f359ba9fcc  musl-fixes.patch
d86fbc3ffb4f5d5a61d3bd7098c9d4fef53c55be21a48f54cdb28098041e3be2f641a4628ca20fa6b5b5e29ad5bd94dac00a362c4bfc011c2e9118a6661d5ad0  fix-openjpeg.patch
7d883fc35d0c6bfaa6bff8e9dbcaeaa9b7d7322852e874d8acc78d41a5aad5595650ec62444048e43aa349471cb16e5aed29e684207fc8d3421030e878ba1fa9  lower-stack-usage.patch"