repo/proj/guru:master commit in: www-servers/copyparty/

"David Roman" <[email protected]> Tue, 04 Aug 2026 08:49:38 +0000 (UTC)
Newsgroups gmane.linux.gentoo.cvs
Message-ID <1785670692.9ae57d99307e11488e1d36a2da4e55b887894518.davidroman@gentoo>
commit:     9ae57d99307e11488e1d36a2da4e55b887894518
Author:     Esteve Varela Colominas <esteve.varela <AT> gmail <DOT> com>
AuthorDate: Sun Aug  2 11:37:33 2026 +0000
Commit:     David Roman <stkw0 <AT> disroot <DOT> org>
CommitDate: Sun Aug  2 11:38:12 2026 +0000
URL:        https://gitweb.gentoo.org/repo/proj/guru.git/commit/?id=9ae57d99

www-servers/copyparty: Drop vulnerable

https://github.com/9001/copyparty/security/advisories/GHSA-phv8-wgjp-g4p9

Signed-off-by: Esteve Varela Colominas <esteve.varela <AT> gmail.com>

 www-servers/copyparty/Manifest                 |   1 -
 www-servers/copyparty/copyparty-1.20.17.ebuild | 186 -------------------------
 2 files changed, 187 deletions(-)

diff --git a/www-servers/copyparty/Manifest b/www-servers/copyparty/Manifest
index 9c93c22ae9..ca6bf0b729 100644
--- a/www-servers/copyparty/Manifest
+++ b/www-servers/copyparty/Manifest
@@ -1,2 +1 @@
-DIST copyparty-1.20.17.tar.gz 1818617 BLAKE2B 41ff78ed3cf519eab3632bcbbb14eb99be4f07ca2ff12a62d61206e04572e7ca33940eb4c6e58f67e9133e55e0c40df4cee9357bfcb1d12c69f77918a5f5e79f SHA512 12e16aefeb8124f94227761102b3e7decbd656b7ed8c127aa845a2377df3f69c79c7a602ae978a780503c3ecebeb88efa8e95354cf358f4297bba9e6aa426232
 DIST copyparty-1.20.19.tar.gz 1826830 BLAKE2B 9a81617d799320a93e10c0b8ec6bc05470747b3027e84f3858b7059d5461e5571380ccca2dad51812b8d4843beec02356e091a70ae33ef1a3ef6d9bd595fb2ec SHA512 cf38affc231f3582723515f5558b9f01346227beb349a354827ae15127f01227491dec7fc38d797bf268b9b3c61744b4e61c38ec91583f5cc764b8d03d30864e

diff --git a/www-servers/copyparty/copyparty-1.20.17.ebuild b/www-servers/copyparty/copyparty-1.20.17.ebuild
deleted file mode 100644
index e8286c51b7..0000000000
--- a/www-servers/copyparty/copyparty-1.20.17.ebuild
+++ /dev/null
@@ -1,186 +0,0 @@
-# Copyright 2025-2026 Gentoo Authors
-# Distributed under the terms of the GNU General Public License v2
-
-EAPI=8
-
-PYTHON_COMPAT=( python3_{12..14} )
-DISTUTILS_USE_PEP517=setuptools
-inherit distutils-r1 optfeature edo readme.gentoo-r1
-
-DESCRIPTION="Easy-to-use, feature-packed, protable file server"
-HOMEPAGE="https://github.com/9001/copyparty"
-
-SRC_URI="https://github.com/9001/copyparty/releases/download/v${PV}/copyparty-${PV}.tar.gz"
-
-LICENSE="MIT"  # TODO: licenses of copyparty/web/deps
-SLOT="0"
-KEYWORDS="~amd64"
-IUSE="test"
-RESTRICT="!test? ( test )"
-
-RDEPEND="
-	dev-python/jinja2[${PYTHON_USEDEP}]
-	dev-python/ifaddr[${PYTHON_USEDEP}]
-"
-BDEPEND="
-	test? (
-		dev-python/jinja2[${PYTHON_USEDEP}]
-		dev-python/strip-hints
-	)
-"
-
-DISABLE_AUTOFORMATTING=y
-DOC_CONTENTS="\
-# TODO: This package is unfinished and lacks some features
-
-- Missing service scripts:
--- OpenRC system service running as different user/group (default to copyparty)
--- Systemd system service running as different user/group (default to copyparty)
--- Systemd user service
-
-- Existing upstream service scripts:
--- contrib/openrc/copyparty: Hardcodes /usr/local/bin, runs as root, exposes /mnt as RW (!?)
--- contrib/systemd/copyparty.service: Hardcodes /usr/local/bin, runs as root, in /var/lib/copyparty
--- contrib/systemd/[email protected]: Runs as an arbitrary user, in /var/lib/copyparty-jail, at boot
--- contrib/systemd/copyparty-user.service: User service, runs in /var/lib/copyparty-jail
-
-- Default configuration: There's a bunch of examples, find them using:
-\`find docs contrib -name '*.conf'\`.
-Ideally one of these would be installed as /etc/copyparty.conf, and an
-/etc/copyparty.d directory would be created. I'm not sure what would be
-acceptable defaults.
-
-- Jailing the service with prisonparty/bubbleparty: This program is very
-feature-packed, and has a decent security track record, but just has a
-massive attack surface with serious repercussions. Some packages provide a
-'prisonparty' service, which runs the program in a chroot. This script
-hardcodes a lot of things that I'm not sure will work on gentoo, and would
-need matching openrc/systemd services as well.
-
-# Note about TLS and certificates
-
-This program implements TLS natively, in order to be able to access the
-WebCrypto API in browsers[1].
-
-If you intend to expose it to the internet, it's advised to run it through a
-reverse proxy[2], like nginx, in order to have a proper TLS implementation, and
-more modern transport features.
-
-If that's not an option, by default, the https:// URL will use a builtin,
-insecure certificate. Install app-crypt/cfssl in order to have it generate a
-custom certificate.
-
-[1]: https://github.com/9001/copyparty/blob/2c26aecd878c185ce358f661d57612f91c21d4b1/copyparty/cert.py#L37-L43
-[2]: https://github.com/9001/copyparty#reverse-proxy
-
-# Bundled dependency notice
-
-A few 'web dependencies' are supplied in the copyparty/web/deps directory.
-These are mostly things that run in the web browser, such as javascript
-libraries, markdown editors, some assets such as fonts, and a sha512 function
-implemented in webassembly.
-
-An attempt at rebuilding these was made, but the scripts required too much
-patching and should be adapted upstream to be more easily buildable without
-docker. Additionally, it's difficult to package npm dependencies in gentoo.
-https://gist.github.com/mid-kid/cc7c0c2e1c188c8b135663d547e3dd35"
-
-src_prepare() {
-	# Use a $TMPDIR for testing, not /dev/shm
-	sed -e 's/\["\/dev\/shm"[^]]*\]/[]/' \
-		-i tests/util.py || die
-
-	# Remove vendored dependencies
-	rm -r copyparty/stolen/ifaddr || die  # dev-python/ifaddr
-	#rm copyparty/stolen/qrcodegen.py || die  # TODO: not packaged
-	rm copyparty/stolen/surrogateescape.py || die  # python2-only dependency
-
-	# Patched dependency (avahi workaround)
-	# See https://github.com/9001/copyparty/issues/887#issuecomment-3368575829
-	#rm -r copyparty/stolen/dnslib || die
-
-	distutils-r1_src_prepare
-}
-
-python_test() {
-	edo bash scripts/run-tests.sh python3
-}
-
-python_install() {
-	distutils-r1_python_install
-
-	# Reuse the bundled copy of fusepy for partyfuse
-	# patched in scripts/deps-docker/Dockerfile (under "build fusepy")
-	sed -e "1a$(printf '%s\\n' \
-			'import copyparty.web.deps.fuse as fuse,sys,os' \
-			'sys.path.append(os.path.dirname(fuse.__file__))' \
-		)" -i "${D}$(python_get_scriptdir)/partyfuse" || die
-
-	# Useful utilities listed in bin/README.md
-	# These need to be executed inside the server's data directory
-	# Installed into /usr/libexec as not a single other package installs them
-	python_scriptinto /usr/libexec/copyparty
-	python_doscript bin/partyjournal.py bin/dbtool.py
-}
-
-src_install() {
-	distutils-r1_src_install
-	readme.gentoo_create_doc
-
-	exeinto /etc/user/init.d
-	newexe "${FILESDIR}/copyparty-user.initd" copyparty
-
-	# Not all of the documentation is useful, but it's hard to filter,
-	# and plenty of it is quite useful.
-	dodoc -r docs contrib
-
-	# These additional scripts can be used through command-line flags or
-	# configuration files, so it makes sense to put them in a predictable
-	# location.  A few of these will require customization, the user should
-	# copy them to /etc.
-	insinto /usr/share/copyparty
-	doins -r bin/handlers bin/hooks bin/mtag
-
-	# Every other package seems to install this, but it needs a service script,
-	# as well as proper creation of the jail + testing.
-	#newbin bin/prisonparty.sh prisonparty
-
-	# Bubbleparty seems more reasonable, yet I don't see this included in other
-	# packages.  Would need an optional sys-apps/bubblewrap dependency.
-	#newbin bin/bubbleparty.sh bubbleparty
-
-	# Skipped tools:
-	# - bin/partyfuse-streaming.py: Doc tells me this doesn't exist
-	# - bin/partyfuse2.py: The regular partyfuse.py is better supported
-	# - bin/unforget.py: Not listed in README.md, questionable utility
-	# - bin/zmq-recv.py: Not listed in README.md, questionable utility
-}
-
-pkg_postinst() {
-	# Optfeature descriptions from copyparty/svchub.py:SvcHub._feature_test()
-	optfeature "sessions and file/media indexing" dev-lang/python[sqlite]
-	optfeature "image thumbnails (plenty fast)" dev-python/pillow
-	#optfeature "image thumbnails (faster, eats more ram)" vips  # pyvips not packaged (yet)
-	optfeature "create thumbnails as webp files" dev-python/pillow[webp]
-	optfeature "transcode audio, create spectrograms, video thumbnails, \
-good-but-slow image thumbnails, read audio/media tags" media-video/ffmpeg
-	optfeature "read audio tags (ffprobe is better but slower)" media-libs/mutagen
-	optfeature "secure password hashing (advanced users only)" dev-python/argon2-cffi
-	optfeature "send zeromq messages from event-hooks" dev-python/pyzmq
-	optfeature "read .heif images with pillow (rarely useful)" dev-python/pillow-heif
-	optfeature "read .avif images with pillow (rarely useful)" dev-python/pillow[avif]
-	#optfeature "read RAW images" rawpy  # rawpy not packaged (yet)
-
-	# Other pillow imports not listed above
-	optfeature "create thumbnails as jxl files" dev-python/pillow-jxl-plugin
-
-	# Optfeatures from pyproject.toml:project.optional-dependencies not listed above
-	optfeature "sftp protocol support" dev-python/paramiko
-	optfeature "ftp protocol support" dev-python/pyftpdlib
-	optfeature "ftps protocol support" "dev-python/pyftpdlib dev-python/pyopenssl"
-	#optfeature "tftp protocol support" partftpy  # partftpy not packaged (yet)
-
-	# Additional programs not detected above
-	optfeature "automatically generate SSL certificate at startup" app-crypt/cfssl
-	optfeature "scrypt password hashing" dev-lang/python[ssl]  # hashlib.scrypt()
-}