Re: [PATCH v2 2/2] python/sepolicy: add a pyproject.toml file

Cathy Hu <[email protected]> Wed, 29 Jul 2026 14:39:28 +0200
Newsgroups org.kernel.vger.selinux
Message-ID <[email protected]>
On 7/24/26 7:51 PM, Stephen Smalley wrote:
> Add a pyproject.toml file for the sepolicy python module.  This
> required also updating setup.py to avoid defining author outside of
> pyproject.toml, and I further updated the authors to refer to the list
> like libselinux since Dan is enjoying retirement.
> 
> Fixes: https://github.com/SELinuxProject/selinux/issues/505
> Signed-off-by: Stephen Smalley <[email protected]>
> ---
> v2 drops the dependencies since those were breaking, presumably
> because the libselinux python module is just called "selinux"?
> I remain unsure as to the correctness/completeness of these but
> they did pass the CI fully.

I think dropping the dependencies is fine ATM, as setup.py also did not add those dependencies.

The testing farm (https://github.com/SELinuxProject/selinux/actions/runs/30099962012/job/89503238013) failed i think because:
$ python3 -m pip install --no-build-isolation --force-reinstall --prefix=/usr `test -n "" && echo --root  --ignore-installed --no-deps` dist/*.whl

and test -n "" is false (should be DESTDIR), so --no-deps is not used and the dependency section is checked.

In our build DESTDIR is set to the BUILDROOT so it was not checking the dependency section anyway.

> 
>   python/sepolicy/pyproject.toml | 15 +++++++++++++++
>   python/sepolicy/setup.py       |  2 --
>   2 files changed, 15 insertions(+), 2 deletions(-)
>   create mode 100644 python/sepolicy/pyproject.toml
> 
> diff --git a/python/sepolicy/pyproject.toml b/python/sepolicy/pyproject.toml
> new file mode 100644
> index 00000000..d33e78c8
> --- /dev/null
> +++ b/python/sepolicy/pyproject.toml
> @@ -0,0 +1,15 @@
> +[build-system]
> +requires = ["setuptools", "wheel"]
> +build-backend = "setuptools.build_meta"
> +
> +[project]
> +name = "sepolicy"
> +version = "3.11"
> +description = "Python tools for SELinux policy analysis (sepolicy, sepolgen)"
> +license = "GPL-2.0-or-later"
> +authors = [
> +    { name = "SELinux Project", email = "[email protected]" }
> +]
> +


> +[project.scripts]
> +sepolicy = "sepolicy.__main__:main"

I had a deeper look and I am not sure if this scripts part is needed.

Because sepolicy will throw an error when installed with pip only:

$ cd python/sepolicy
$ python3 -m venv --system-site-packages env
$ source env/bin/activate
$ pip install .
$ sepolicy --help
ModuleNotFoundError: No module named 'sepolicy.__main__'

Because by adding the [project.scripts] tag, setuptools writes this into env/bin/sepolicy:

import sys
from sepolicy.__main__ import main
if __name__ == '__main__':
     sys.argv[0] = sys.argv[0].removesuffix('.exe')
     sys.exit(main())

But __main__.py and main() does not exist, so it won't work I think.

Probably this part is not needed in this case anyway because sepolicy.py gets installed "manually" here IIUC:

https://github.com/SELinuxProject/selinux/blob/ad7efacea997ebad8c14b6472cca58993a35d2d2/python/sepolicy/Makefile#L31-L32

So might make sense to delete the scripts section.

> diff --git a/python/sepolicy/setup.py b/python/sepolicy/setup.py
> index ca0396b5..5c4f2e5d 100644
> --- a/python/sepolicy/setup.py
> +++ b/python/sepolicy/setup.py
> @@ -8,8 +8,6 @@ setup(
>       name="sepolicy",
>       version="3.11",
>       description="Python SELinux Policy Analyses bindings",
> -    author="Daniel Walsh",
> -    author_email="[email protected]",
>       packages=[
>           "sepolicy",
>           "sepolicy.templates",

I thought maybe the duplicate definitions (name, version,...) in setup.py could be dropped,
but I tested it and the (gcc,pypy3.7) runner [0] still takes the definitions from setup.py
even though pyproject.toml exists because setuptools-47.1.0 < 61.0.0.

Which means, it can not find the definitions when setup.py was dropped.
 From the runner (https://github.com/ca-hu/selinux/commit/3a0836b98f846af3981081b87ab73e5f5ed3f97b):
> Test .gitignore and make clean distclean
   error: missing .gitignore entry for libselinux/src/UNKNOWN.egg-info/
   error: missing .gitignore entry for python/sepolicy/UNKNOWN.egg-info/

^ see UNKNOWN instead of the package name

Which makes me wonder if the author+author_email needs to be kept in the setup.py as well if setuptools < 61.0.0 is still supported
and it needs to be backwards compatible.

In case setuptools < 61.0.0 is not supported anymore by the selinux toolchain (it is at least not by setuptools upstream), it might be possible to drop the setup.py entirely for sepolicy and rely on pyproject.toml alone.
Example:
https://github.com/ca-hu/selinux/commit/3a0836b98f846af3981081b87ab73e5f5ed3f97b

At least on the openSUSE/SUSE SLES side, iiuc we have setuptools >= 61.0.0 for all supported versions, but I don't know about other distributions.


But feel free to disregard my review and merge it, it is building fine as is on our end.
OpenPGP_signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEWHPP0YwOptScu/bEBioQFhUFoIoFAmpp9IAbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEAYqEBYVBaCK/2wQAKPItPGQxvGv6Rh7nA5k
/w7knXBqVXUi2KlktUZbkJHvzW9yL9RpEk0BuukARN1op/TYnnnZa8bDCvdccpK9
WsMKPZKy0KYIPtlDJujUVnKTTVtGgpQyBkXshiR+h904u8fToof62DOp2gKwAwYF
8kw+mEBbU93LzCuIpw9cPGmZG7pV2z437M9iOKgvNsm6ATtx2tYRcmAsQBbyQG6S
x9EFHoLl8//pKgvwWN31X+OBFWm0HTzd+AkyrTZxnKpiAOGxaGABeP3YlipleB1D
gziQYYsJRPbpCPjQYSCGhHPUfR2uYIC2x0RxJYXo0biug8VlkAbuSEiroR4Pd2Ib
imMT33785gf7QvPeI5Ju4bX50iaEWzBQ2EuHD7rs7exARhadI32wjjKJFQsOu4H8
arF70U327kvhUNFAnJJWvEU3E4XbM9n1auvp9RF7/pABL9QdOnbWcroV4Jco/mj8
NPThbYqgfziSdLOg55MlaqFctyx6vcO+JYtaSS/KGB6QyjEFF3K1+HFfHO/lwjQe
OPJAEbJpXGfqgrqJBtnGGGEq3OFh5ZnBDPkSjB9WHspvS158CPFGwMKCwjYlBshz
9Rvpwm56pEGkN/ESb7ybKDuuhQY3+hofACD680JuVtrfxLau/FBu0un9NSLHPiBp
97oJUOm4wfuoZGaF5SmNW+dR
=wRC2
-----END PGP SIGNATURE-----