# Extra notices tied to the exact inspected Linux PDFium library and source pin. # These are install data; no application code or PDF rendering option changes. set(_notice_root "${CMAKE_CURRENT_SOURCE_DIR}/resources/licenses/pdfium-supplemental") file(READ "${_notice_root}/sources.json" _notice_manifest) file(READ "${CMAKE_CURRENT_SOURCE_DIR}/cmake/pdfium.lock.json" _pdfium_lock) foreach(_pair "pdfiumVersion;version" "pdfiumUpstreamCommit;upstreamCommit") list(GET _pair 0 _notice_key) list(GET _pair 1 _lock_key) string(JSON _notice_value GET "${_notice_manifest}" "${_notice_key}") string(JSON _lock_value GET "${_pdfium_lock}" "${_lock_key}") if(NOT _notice_value STREQUAL _lock_value) message(FATAL_ERROR "PDFium supplemental notices need review for this source pin") endif() endforeach() string(JSON _notice_binary GET "${_notice_manifest}" pdfiumLibrarySha256) file(SHA256 "${DOCVIEW_PDFIUM_LIBRARY}" _actual_binary) if(NOT _notice_binary STREQUAL _actual_binary OR EXISTS "${DOCVIEW_PDFIUM_ROOT}/BUILDINFO.json") # Only the separately reviewed v2 tuple may differ from the original # provider. There is deliberately no user-supplied trust/hash override. find_package(Python3 3.11 REQUIRED COMPONENTS Interpreter) set(_candidate_verifier "${CMAKE_CURRENT_SOURCE_DIR}/tools/verify_pdfium_candidate.py") set(_candidate_notice "${CMAKE_CURRENT_BINARY_DIR}/pdfium-candidate-notices/sources.json") execute_process(COMMAND "${Python3_EXECUTABLE}" "${_candidate_verifier}" --prefix "${DOCVIEW_PDFIUM_ROOT}" --library "${DOCVIEW_PDFIUM_LIBRARY}" --include-dir "${DOCVIEW_PDFIUM_INCLUDE_DIR}" --notice-output "${_candidate_notice}" RESULT_VARIABLE _candidate_result OUTPUT_VARIABLE _candidate_record ERROR_VARIABLE _candidate_error) if(NOT _candidate_result EQUAL 0) message(FATAL_ERROR "PDFium supplemental notices need review for this binary: ${_candidate_error}") endif() set_property(DIRECTORY APPEND PROPERTY CMAKE_CONFIGURE_DEPENDS "${DOCVIEW_PDFIUM_ROOT}/BUILDINFO.json" "${CMAKE_CURRENT_SOURCE_DIR}/cmake/pdfium-candidate-v2.lock.json" "${_candidate_verifier}") # Recheck at install as well: configure success is not permission to install # a prefix whose library, headers, or correspondence subsequently changed. install(CODE " execute_process(COMMAND \"${Python3_EXECUTABLE}\" \"${_candidate_verifier}\" --prefix \"${DOCVIEW_PDFIUM_ROOT}\" --library \"${DOCVIEW_PDFIUM_LIBRARY}\" --include-dir \"${DOCVIEW_PDFIUM_INCLUDE_DIR}\" --notice-output \"${_candidate_notice}\" RESULT_VARIABLE candidate_result OUTPUT_QUIET ERROR_VARIABLE candidate_error) if(NOT candidate_result EQUAL 0) message(FATAL_ERROR \"PDFium candidate changed before install: \${candidate_error}\") endif()") string(JSON _candidate_files LENGTH "${_candidate_record}" installFiles) math(EXPR _candidate_last "${_candidate_files} - 1") foreach(_index RANGE 0 ${_candidate_last}) string(JSON _source GET "${_candidate_record}" installFiles ${_index} source) string(JSON _destination GET "${_candidate_record}" installFiles ${_index} destination) get_filename_component(_directory "${_destination}" DIRECTORY) install(FILES "${DOCVIEW_PDFIUM_ROOT}/${_source}" DESTINATION "${_directory}") endforeach() install(FILES "${_candidate_notice}" DESTINATION share/doc/docview/pdfium/supplemental) install(FILES "${DOCVIEW_PDFIUM_ROOT}/licenses/libcxx-LICENSE.txt" "${DOCVIEW_PDFIUM_ROOT}/licenses/libcxxabi-LICENSE.txt" DESTINATION share/doc/docview/pdfium/supplemental) return() endif() string(JSON _notice_count LENGTH "${_notice_manifest}" files) string(JSON _notice_schema GET "${_notice_manifest}" schemaVersion) if(NOT _notice_schema EQUAL 1) message(FATAL_ERROR "Unsupported PDFium supplemental notice schema") endif() if(NOT _notice_count EQUAL 2) message(FATAL_ERROR "Expected the two audited PDFium supplemental notices") endif() set(_notice_names) foreach(_index RANGE 0 1) string(JSON _name GET "${_notice_manifest}" files ${_index} name) string(JSON _hash GET "${_notice_manifest}" files ${_index} sha256) if(NOT _name MATCHES "^(libcxx|libcxxabi)-LICENSE[.]txt$") message(FATAL_ERROR "Unexpected PDFium supplemental notice filename") endif() if(_name IN_LIST _notice_names) message(FATAL_ERROR "Duplicate PDFium supplemental notice filename") endif() list(APPEND _notice_names "${_name}") file(SHA256 "${_notice_root}/${_name}" _actual) if(NOT _actual STREQUAL _hash) message(FATAL_ERROR "PDFium supplemental notice digest mismatch") endif() install(FILES "${_notice_root}/${_name}" DESTINATION share/doc/docview/pdfium/supplemental) endforeach() install(FILES "${_notice_root}/sources.json" DESTINATION share/doc/docview/pdfium/supplemental)