#!/usr/bin/env python3 """Run inside the disposable Ubuntu VM, as its docview user.""" import hashlib import json from pathlib import Path import subprocess import tarfile incoming = Path.home() / 'incoming' qt = Path('/opt/docview-qt/6.11.2/gcc_64') prefix = Path('/opt/docview-deps') records = json.loads((incoming / 'sdk-downloads.json').read_text()) for item in records: with (incoming / item['name']).open('rb') as stream: assert hashlib.file_digest(stream, 'sha256').hexdigest() == item['sha256'] subprocess.run(['sudo', 'mkdir', '-p', str(qt), str(prefix)], check=True) for item in records: if item['kind'] == 'qt': target = qt / 'lib' if 'icu-linux' in item['name'] else qt subprocess.run(['sudo', '7z', 'x', '-y', '-bso0', '-bsp0', '-o' + str(target), str(incoming / item['name'])], check=True) sources = Path.home() / 'dependency-sources' sources.mkdir(exist_ok=True) for name in ['qpdf-12.4.1.tar.gz', 'libzip-1.11.4.tar.xz']: with tarfile.open(incoming / name) as archive: archive.extractall(sources, filter='data') print('All SDK/source hashes verified again inside guest; extracted into dedicated prefixes.', flush=True) subprocess.run([str(qt / 'bin/qtpaths'), '--query', 'QT_VERSION'], check=True) subprocess.run([str(qt / 'bin/qtpaths'), '--query', 'QT_INSTALL_PREFIX'], check=True) for project, extra in [ ('qpdf-12.4.1', ['-DBUILD_STATIC_LIBS=OFF', '-DBUILD_DOC=OFF', '-DINSTALL_EXAMPLES=OFF']), ('libzip-1.11.4', ['-DBUILD_TOOLS=OFF', '-DBUILD_REGRESS=OFF', '-DBUILD_EXAMPLES=OFF', '-DBUILD_DOC=OFF']), ]: source = sources / project build = Path.home() / 'dependency-builds' / project subprocess.run(['cmake', '-S', str(source), '-B', str(build), '-G', 'Ninja', '-DCMAKE_BUILD_TYPE=Release', '-DCMAKE_INSTALL_PREFIX=' + str(prefix), '-DCMAKE_INSTALL_LIBDIR=lib', *extra], check=True) targets = ['--target', 'libqpdf', 'qpdf', 'fix-qdf', 'zlib-flate'] if project.startswith('qpdf') else [] subprocess.run(['cmake', '--build', str(build), '--parallel', '4', *targets], check=True) if project.startswith('qpdf'): for component in ['lib', 'dev', 'cli']: subprocess.run(['sudo', 'cmake', '--install', str(build), '--component', component], check=True) else: subprocess.run(['sudo', 'cmake', '--install', str(build)], check=True) profile = '''# Dedicated fixed Qt SDK in this disposable test VM only. # Same userns opt-in pattern as Ubuntu's QtWebEngineProcess profile. abi , include profile docview-qtwebengine /opt/docview-qt/6.11.2/gcc_64/libexec/QtWebEngineProcess flags=(unconfined) { userns, } ''' local = Path.home() / 'docview-qtwebengine.apparmor' local.write_text(profile) subprocess.run(['sudo', 'install', '-m', '0644', str(local), '/etc/apparmor.d/docview-qtwebengine'], check=True) subprocess.run(['sudo', 'apparmor_parser', '-r', '/etc/apparmor.d/docview-qtwebengine'], check=True) print('Guest dependency prefixes and exact QtWebEngineProcess AppArmor userns profile installed.', flush=True)