diff options
Diffstat (limited to 'dev-python/imageio')
| -rw-r--r-- | dev-python/imageio/Manifest | 2 | ||||
| -rw-r--r-- | dev-python/imageio/files/imageio-2.22.0-block-download.patch | 32 | ||||
| -rw-r--r-- | dev-python/imageio/imageio-2.37.3-r1.ebuild | 104 | ||||
| -rw-r--r-- | dev-python/imageio/metadata.xml | 16 |
4 files changed, 154 insertions, 0 deletions
diff --git a/dev-python/imageio/Manifest b/dev-python/imageio/Manifest new file mode 100644 index 000000000000..22111ff22e1c --- /dev/null +++ b/dev-python/imageio/Manifest @@ -0,0 +1,2 @@ +DIST imageio-2.37.3.gh.tar.gz 583529 BLAKE2B 6b48eda8cd2f07c8a4fdfaf2d34c3ed7a24fbe48965a3996ca63e7be7389806b5e6f5565a171d98b4891c3bc4394c807ac6d851567a0c9aa677e171a719c0f80 SHA512 5b35ba5997321e88e0ff8c9953c579f1c6b16259a7a97f7a8ee0d921b5e8464de24000596e0a9df26efad20716ddb21a0caafba29cfd9744e724327629aa7cdb +DIST imageio-test_images-1121036015c70cdbb3015e5c5ba0aaaf7d3d6021.gh.tar.gz 195497374 BLAKE2B 0083212fd63c196dc2e721bff8f89c177b6741317b6b1c6ae9d00a8dd5fb6366efa3f01b9bffafafac7177cfdaa4d700077a2bad42ada735f5553e97f651c4ad SHA512 1bb1f36a069bfaa0d0ffe5258534e02e49237fc6ce85fe3d3648650130165abc9b3d5ff0e7e5861ee1d94add00d4258575f9c2f8556debecf597bdaa5499efe0 diff --git a/dev-python/imageio/files/imageio-2.22.0-block-download.patch b/dev-python/imageio/files/imageio-2.22.0-block-download.patch new file mode 100644 index 000000000000..ba483813b23c --- /dev/null +++ b/dev-python/imageio/files/imageio-2.22.0-block-download.patch @@ -0,0 +1,32 @@ +From 1ae48cfa95e84cb064edc74a4a64bd0f7dee780a Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Micha=C5=82=20G=C3=B3rny?= <mgorny@gentoo.org> +Date: Tue, 4 Oct 2022 09:40:42 +0200 +Subject: [PATCH] Unconditionally disable downloading binaries from Internet + +Bug: https://bugs.gentoo.org/874849 +--- + imageio/core/fetching.py | 7 +++---- + 1 file changed, 3 insertions(+), 4 deletions(-) + +diff --git a/imageio/core/fetching.py b/imageio/core/fetching.py +index 0380bc7..70f1a3d 100644 +--- a/imageio/core/fetching.py ++++ b/imageio/core/fetching.py +@@ -97,11 +97,10 @@ def get_remote_file(fname, directory=None, force_download=False, auto=True): + break + + # If we get here, we're going to try to download the file +- if os.getenv("IMAGEIO_NO_INTERNET", "").lower() in ("1", "true", "yes"): ++ if True: + raise InternetNotAllowedError( +- "Will not download resource from the " +- "internet because environment variable " +- "IMAGEIO_NO_INTERNET is set." ++ "Implicit insecure downloads disabled on Gentoo due to security " ++ "concerns. See https://bugs.gentoo.org/874849." + ) + + # Can we proceed with auto-download? +-- +2.38.0 + diff --git a/dev-python/imageio/imageio-2.37.3-r1.ebuild b/dev-python/imageio/imageio-2.37.3-r1.ebuild new file mode 100644 index 000000000000..61eafc169363 --- /dev/null +++ b/dev-python/imageio/imageio-2.37.3-r1.ebuild @@ -0,0 +1,104 @@ +# Copyright 1999-2026 Gentoo Authors +# Distributed under the terms of the GNU General Public License v2 + +EAPI=8 + +DISTUTILS_USE_PEP517=setuptools +PYTHON_COMPAT=( python3_{13..14} ) + +inherit distutils-r1 + +# teh test suite always clones the newest version +TEST_IMAGES_COMMIT=1121036015c70cdbb3015e5c5ba0aaaf7d3d6021 +DESCRIPTION="Python library for reading and writing image data" +HOMEPAGE=" + https://imageio.readthedocs.io/en/stable/ + https://github.com/imageio/imageio/ + https://pypi.org/project/ImageIO/ +" +SRC_URI=" + https://github.com/imageio/imageio/archive/v${PV}.tar.gz + -> ${P}.gh.tar.gz + test? ( + https://github.com/imageio/test_images/archive/${TEST_IMAGES_COMMIT}.tar.gz + -> imageio-test_images-${TEST_IMAGES_COMMIT}.gh.tar.gz + ) +" + +LICENSE="MIT" +SLOT="0" +KEYWORDS="~amd64 ~arm64 ~x86" + +RDEPEND=" + dev-python/numpy[${PYTHON_USEDEP}] + >=dev-python/pillow-8.3.2[${PYTHON_USEDEP}] + media-libs/freeimage +" +BDEPEND=" + test? ( + >=dev-python/imageio-ffmpeg-0.4.9-r1[${PYTHON_USEDEP}] + dev-python/psutil[${PYTHON_USEDEP}] + dev-python/tifffile[${PYTHON_USEDEP}] + || ( + media-video/ffmpeg[openh264] + media-video/ffmpeg[x264] + ) + ) +" + +EPYTEST_PLUGINS=() +distutils_enable_tests pytest + +src_prepare() { + local PATCHES=( + # block silently downloading vulnerable libraries from the Internet + "${FILESDIR}/imageio-2.22.0-block-download.patch" + ) + + if use test; then + mv "${WORKDIR}/test_images-${TEST_IMAGES_COMMIT}" .test_images || die + # upstream tries to update the image cache, and invalidates it + # if "git pull" fails + sed -i -e 's:git pull:true:' tests/conftest.py || die + # ffmpeg tests expect it there + mkdir -p "${HOME}/.imageio/images" || die + cp .test_images/cockatoo.mp4 "${HOME}/.imageio/images" || die + fi + + distutils-r1_src_prepare +} + +python_test() { + local EPYTEST_IGNORE=( + # uses fsspec to grab prebuilt .so from GitHub, sigh + tests/test_freeimage.py + ) + + local EPYTEST_DESELECT=( + # Note: upstream has a needs_internet marker but it is also + # used to mark tests that require test_images checkout that we + # supply + + # Tries to download ffmpeg binary ?! + tests/test_ffmpeg.py::test_get_exe_installed + # blocked by our patch + tests/test_core.py::test_fetching + tests/test_core.py::test_request + # Internet + tests/test_bsdf.py::test_from_url + tests/test_core.py::test_mvolread_out_of_bytes + tests/test_core.py::test_request_read_sources + tests/test_pillow.py::test_gif_first_p_frame + tests/test_pillow.py::test_png_remote + tests/test_pillow.py::test_webp_remote + tests/test_pillow_legacy.py::test_png_remote + tests/test_swf.py::test_read_from_url + # requires pillow-heif, also possibly Internet + tests/test_pillow.py::test_avif_remote + tests/test_pillow.py::test_heif_remote + # not important, requires random system libs + tests/test_core.py::test_findlib2 + ) + + epytest +} diff --git a/dev-python/imageio/metadata.xml b/dev-python/imageio/metadata.xml new file mode 100644 index 000000000000..a4ad165d22b3 --- /dev/null +++ b/dev-python/imageio/metadata.xml @@ -0,0 +1,16 @@ +<?xml version="1.0" encoding="UTF-8"?> +<!DOCTYPE pkgmetadata SYSTEM "https://docs.baldeagleos.com/dtd/metadata.dtd"> +<pkgmetadata> + <maintainer type="project"> + <email>python@gentoo.org</email> + <name>Python</name> + </maintainer> + <longdescription lang="en"> + Imageio is a Python library that provides an easy interface to read + and write a wide range of image data, including animated images, + video, volumetric data, and scientific formats. It is cross-platform, + runs on Python 2.x and 3.x, and is easy to install. + </longdescription> + <stabilize-allarches /> + <origin>baldeagleos-repo</origin> +</pkgmetadata> |
