python2

maintainer andreas_baumann · 78 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package builds Python 2.7 from official python.org source and applies Gentoo patches from a trusted developer's domain; the non-whitelisted host hosts only supplemental, non-executed patch data, posing minimal risk.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds Python 2.7 from official python.org source and applies Gentoo patches from a trusted developer's domain; the non-whitelisted host hosts only supplemental, non-executed patch data, posing minimal risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:26 "https://dev.gentoo.org/~mgorny/dist/python/$_gentoo_patches.tar.xz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Andreas Baumann <mail@andreasbauman.cc>
2# Contributor: Michał Wojdyła < micwoj9292 at gmail dot com >
3# Contributor: Felix Yan <felixonmars@archlinux.org>
4# Contributor: Stéphane Gaudreault <stephane@archlinux.org>
5# Contributor: Allan McRae <allan@archlinux.org>
6# Contributor: Jason Chu <jason@archlinux.org>
7
8pkgname=python2
9pkgver=2.7.18
10pkgrel=14
11_pybasever=2.7
12pkgdesc="A high-level scripting language"
13arch=('x86_64' 'aarch64')
14license=('PSF-2.0')
15url="https://www.python.org/"
16depends=('bzip2' 'expat' 'gdbm' 'libffi' 'libnsl' 'libxcrypt' 'openssl-1.1' 'sqlite' 'zlib')
17makedepends=('tk' 'bluez-libs')
18checkdepends=('gdb' 'file' 'xorg-server-xvfb' 'xterm')
19optdepends=('tk: for IDLE'
20 'python2-setuptools'
21 'python2-pip')
22conflicts=('python<3')
23_gentoo_patches="python-gentoo-patches-${pkgver}_p16"
24source=("https://www.python.org/ftp/python/${pkgver%rc?}/Python-${pkgver}.tar.xz"{,.asc}
25 mtime-workaround.patch
26 "https://dev.gentoo.org/~mgorny/dist/python/$_gentoo_patches.tar.xz")
27sha512sums=('a7bb62b51f48ff0b6df0b18f5b0312a523e3110f49c3237936bfe56ed0e26838c0274ff5401bda6fc21bf24337477ccac49e8026c5d651e4b4cafb5eb5086f6c'
28 'SKIP'
29 '4e761cfd57791e8b72ecdf84c2e03875bf074311130eea5b8e97409fa304fa3468dbd359a511c4e9978e686e662c58054b4174d3e73f845fa9ded2e83a3a8076'
30 '810be590d0e06fab4b2165e6852ca49662f09dcd7e20b47a29f613ad7653252c8dfac3f0eb228d77c8a914efa7c08788b2fbd552a4b47504f5fd0ec17450c48f')
31validpgpkeys=('C01E1CAD5EA2C4F0B8E3571504C367C218ADD4FF') # Benjamin Peterson
32noextract=("$_gentoo_patches.tar.xz")
33
34prepare() {
35 bsdtar -xf $_gentoo_patches.tar.xz -s /$_gentoo_patches//
36
37 cd Python-${pkgver}
38
39 # makepkg will touch all files to $SOURCE_DATE_EPOCH which will break pyc file's mtime check.
40 # workaround this by touching them to $SOURCE_DATE_EPOCH before running compileall.
41 patch -p0 -i ../mtime-workaround.patch
42
43 patch -p1 -i ../0001-bpo-39017-Avoid-infinite-loop-in-the-tarfile-module-.patch #CVE-2019-20907
44 patch -p1 -i ../0002-bpo-39503-CVE-2020-8492-Fix-AbstractBasicAuthHandler.patch #CVE-2020-8492
45 patch -p1 -i ../0003-bpo-39603-Prevent-header-injection-in-http-methods-G.patch #CVE-2020-26116
46 patch -p1 -i ../0004-bpo-42051-Reject-XML-entity-declarations-in-plist-fi.patch
47 patch -p1 -i ../0005-bpo-41944-No-longer-call-eval-on-content-received-vi.patch #CVE-2020-27619
48 patch -p1 -i ../0006-bpo-40791-Make-compare_digest-more-constant-time.-GH.patch
49 patch -p1 -i ../0007-3.6-closes-bpo-42938-Replace-snprintf-with-Python-un.patch #CVE-2021-3177
50 patch -p1 -i ../0008-3.6-bpo-42967-only-use-as-a-query-string-separator-G.patch #CVE-2021-23336
51 patch -p1 -i ../0009-py2-ize-the-CJK-codec-test.patch
52 patch -p1 -i ../0010-3.6-bpo-43285-Make-ftplib-not-trust-the-PASV-respons.patch
53 patch -p1 -i ../0011-bpo-43075-Fix-ReDoS-in-urllib-AbstractBasicAuthHandl.patch
54 patch -p1 -i ../0012-3.9-bpo-43882-urllib.parse-should-sanitize-urls-cont.patch
55 patch -p1 -i ../0013-Backport-bpo-44022-Fix-http-client-infinite-line-rea.patch
56 patch -p1 -i ../0014-bpo-43124-Fix-smtplib-multiple-CRLF-injection-GH-259.patch
57 patch -p1 -i ../0015-bpo-42278-Use-tempfile.TemporaryDirectory-rather-tha.patch
58 patch -p1 -i ../0016-Fix-accidentally-leaving-one-sub-test-commented-out.patch
59 patch -p1 -i ../0017-bpo-46811-Make-test-suite-support-Expat-2.4.5-GH-314.patch
60 patch -p1 -i ../0018-bpo-46756-Fix-authorization-check-in-urllib.request-.patch
61 patch -p1 -i ../0019-Install-libpythonX.Y.a-in-usr-lib-instead-of-usr-lib.patch
62 patch -p1 -i ../0020-Disable-modules-and-SSL.patch
63# patch -p1 -i ../0021-Gentoo-libdir.patch # Gentoo specific patch
64# patch -p1 -i ../0022-Non-zero-exit-status-on-failure.patch # Don't need this
65# patch -p1 -i ../0023-sqlite-loadable-extensions.patch # causes error: IndentationError: expected an indented block
66 patch -p1 -i ../0024-Regenerate-platform-specific-modules.patch
67# patch -p1 -i ../0025-distutils-C.patch # Causes failure on test_distutils
68 patch -p1 -i ../0026-Turkish-locale.patch
69 patch -p1 -i ../0027-ARM-OABI.patch
70 patch -p1 -i ../0028-use_pyxml.patch
71 patch -p1 -i ../0029-Disable-nis.patch
72# patch -p1 -i ../0030-Make-module-byte-compilation-non-fatal.patch # Does not apply cleanly
73 patch -p1 -i ../0031-Use-ncurses-to-find-pkg-config.patch
74 patch -p1 -i ../0032-Use-specific-Werror-for-cross-compile-tests.patch
75 patch -p1 -i ../0033-Force-using-system-libffi.patch
76 patch -p1 -i ../0034-test.support.unlink-ignore-EACCES.patch
77 patch -p1 -i ../0035-ssl-Hard-disable-SSLv3-to-avoid-automagic-deps.patch
78 patch -p1 -i ../0036-Fix-Wimplicit-int-Wimplicit-function-declaration.patch
79
80 # Temporary workaround for FS#22322
81 # See http://bugs.python.org/issue10835 for upstream report
82 sed -i "/progname =/s/python/python${_pybasever}/" Python/pythonrun.c
83
84 # Enable built-in SQLite module to load extensions (fix FS#22122)
85 sed -i "/SQLITE_OMIT_LOAD_EXTENSION/d" setup.py
86
87 # FS#23997
88 sed -i -e "s|^#.* /usr/local/bin/python|#!/usr/bin/python2|" Lib/cgi.py
89
90 sed -i "s/python2.3/python2/g" Lib/distutils/tests/test_build_scripts.py \
91 Lib/distutils/tests/test_install_scripts.py
92
93 # Ensure that we are using the system copy of various libraries (expat, zlib and libffi),
94 # rather than copies shipped in the tarball
95 rm -r Modules/expat
96 rm -r Modules/zlib
97 rm -r Modules/_ctypes/{darwin,libffi}*
98
99 # clean up #!s
100 find . -name '*.py' | \
101 xargs sed -i "s|#[ ]*![ ]*/usr/bin/env python$|#!/usr/bin/env python2|"
102
103 # Workaround asdl_c.py/makeopcodetargets.py errors after we touched the shebangs
104 touch Include/Python-ast.h Python/Python-ast.c Python/opcode_targets.h
105}
106
107build() {
108 cd "${srcdir}/Python-${pkgver}"
109 CFLAGS+=" -std=c17"
110 CPPFLAGS+=" -I/usr/include/openssl-1.1"
111 LDFLAGS+=" -L/usr/lib/openssl-1.1"
112 export OPT="${CFLAGS}"
113 ./configure --prefix=/usr \
114 --enable-shared \
115 --with-threads \
116 --enable-optimizations \
117 --with-lto \
118 --enable-ipv6 \
119 --enable-unicode=ucs4 \
120 --with-system-expat \
121 --with-system-ffi \
122 --with-dbmliborder=gdbm:ndbm \
123 --without-ensurepip
124
125 make
126}
127
128check() {
129 # Since 2.7.14 with latest xvfb
130 # test_idle, test_tk, test_ttk_guionly: segfaults
131 # Since 2.7.15: test_ctypes
132 # test_ftplib test_imaplib test_urllib2_localnet: krb5 errors
133 # test_codecmaps_jp: TODO
134 # test_curses: fails
135 export TERM=xterm
136 local -x TZ=UTC
137 cd Python-${pkgver}
138 LD_LIBRARY_PATH="${srcdir}/Python-${pkgver}":${LD_LIBRARY_PATH} \
139 xvfb-run "${srcdir}/Python-${pkgver}/python" -m test.regrtest -v -uall -x test_idle test_tk test_ttk_guionly test_ctypes test_ssl test_ftplib test_imaplib test_urllib2_localnet test_codecmaps_jp test_ossaudiodev test_curses
140}
141
142package() {
143 cd Python-${pkgver}
144
145 # Hack to avoid building again
146 sed -i 's/^all:.*$/all: build_all/' Makefile
147
148 make DESTDIR="${pkgdir}" altinstall maninstall
149
150 rm "${pkgdir}"/usr/share/man/man1/python.1
151
152 ln -sf python${_pybasever} "${pkgdir}"/usr/bin/python2
153 ln -sf python${_pybasever}-config "${pkgdir}"/usr/bin/python2-config
154 ln -sf python${_pybasever}.1 "${pkgdir}"/usr/share/man/man1/python2.1
155
156 # FS#33954
157 ln -sf python-${_pybasever}.pc "${pkgdir}"/usr/lib/pkgconfig/python2.pc
158
159 ln -sf ../../libpython${_pybasever}.so "${pkgdir}"/usr/lib/python${_pybasever}/config/libpython${_pybasever}.so
160
161 mv "${pkgdir}"/usr/bin/smtpd.py "${pkgdir}"/usr/lib/python${_pybasever}/
162
163 # some useful "stuff"
164 install -dm755 "${pkgdir}"/usr/lib/python${_pybasever}/Tools/{i18n,scripts}
165 install -m755 Tools/i18n/{msgfmt,pygettext}.py "${pkgdir}"/usr/lib/python${_pybasever}/Tools/i18n/
166 install -m755 Tools/scripts/{README,*py} "${pkgdir}"/usr/lib/python${_pybasever}/Tools/scripts/
167
168 # fix conflicts with python
169 mv "${pkgdir}"/usr/bin/idle{,2}
170 mv "${pkgdir}"/usr/bin/pydoc{,2}
171 mv "${pkgdir}"/usr/bin/2to3{,-2.7}
172
173 # clean-up reference to build directory
174 sed -i "s#${srcdir}/Python-${pkgver}:##" "${pkgdir}"/usr/lib/python${_pybasever}/config/Makefile
175}
176

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion