python2
maintainer andreas_baumann
· 78 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package builds Python 2.7 from official python.org source and applies Gentoo patches from a trusted developer's domain; the non-whitelisted host hosts only supplemental, non-executed patch data, posing minimal risk.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds Python 2.7 from official python.org source and applies Gentoo patches from a trusted developer's domain; the non-whitelisted host hosts only supplemental, non-executed patch data, posing minimal risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:26
"https://dev.gentoo.org/~mgorny/dist/python/$_gentoo_patches.tar.xz")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Andreas Baumann <mail@andreasbauman.cc>
2
# Contributor: Michał Wojdyła < micwoj9292 at gmail dot com >
3
# Contributor: Felix Yan <felixonmars@archlinux.org>
4
# Contributor: Stéphane Gaudreault <stephane@archlinux.org>
5
# Contributor: Allan McRae <allan@archlinux.org>
6
# Contributor: Jason Chu <jason@archlinux.org>
7
8
pkgname=python2
9
pkgver=2.7.18
10
pkgrel=14
11
_pybasever=2.7
12
pkgdesc="A high-level scripting language"
13
arch=('x86_64' 'aarch64')
14
license=('PSF-2.0')
15
url="https://www.python.org/"
16
depends=('bzip2' 'expat' 'gdbm' 'libffi' 'libnsl' 'libxcrypt' 'openssl-1.1' 'sqlite' 'zlib')
17
makedepends=('tk' 'bluez-libs')
18
checkdepends=('gdb' 'file' 'xorg-server-xvfb' 'xterm')
19
optdepends=('tk: for IDLE'
20
'python2-setuptools'
21
'python2-pip')
22
conflicts=('python<3')
23
_gentoo_patches="python-gentoo-patches-${pkgver}_p16"
24
source=("https://www.python.org/ftp/python/${pkgver%rc?}/Python-${pkgver}.tar.xz"{,.asc}
25
mtime-workaround.patch
26
"https://dev.gentoo.org/~mgorny/dist/python/$_gentoo_patches.tar.xz")
27
sha512sums=('a7bb62b51f48ff0b6df0b18f5b0312a523e3110f49c3237936bfe56ed0e26838c0274ff5401bda6fc21bf24337477ccac49e8026c5d651e4b4cafb5eb5086f6c'
28
'SKIP'
29
'4e761cfd57791e8b72ecdf84c2e03875bf074311130eea5b8e97409fa304fa3468dbd359a511c4e9978e686e662c58054b4174d3e73f845fa9ded2e83a3a8076'
30
'810be590d0e06fab4b2165e6852ca49662f09dcd7e20b47a29f613ad7653252c8dfac3f0eb228d77c8a914efa7c08788b2fbd552a4b47504f5fd0ec17450c48f')
31
validpgpkeys=('C01E1CAD5EA2C4F0B8E3571504C367C218ADD4FF') # Benjamin Peterson
32
noextract=("$_gentoo_patches.tar.xz")
33
34
prepare() {
35
bsdtar -xf $_gentoo_patches.tar.xz -s /$_gentoo_patches//
36
37
cd Python-${pkgver}
38
39
# makepkg will touch all files to $SOURCE_DATE_EPOCH which will break pyc file's mtime check.
40
# workaround this by touching them to $SOURCE_DATE_EPOCH before running compileall.
41
patch -p0 -i ../mtime-workaround.patch
42
43
patch -p1 -i ../0001-bpo-39017-Avoid-infinite-loop-in-the-tarfile-module-.patch #CVE-2019-20907
44
patch -p1 -i ../0002-bpo-39503-CVE-2020-8492-Fix-AbstractBasicAuthHandler.patch #CVE-2020-8492
45
patch -p1 -i ../0003-bpo-39603-Prevent-header-injection-in-http-methods-G.patch #CVE-2020-26116
46
patch -p1 -i ../0004-bpo-42051-Reject-XML-entity-declarations-in-plist-fi.patch
47
patch -p1 -i ../0005-bpo-41944-No-longer-call-eval-on-content-received-vi.patch #CVE-2020-27619
48
patch -p1 -i ../0006-bpo-40791-Make-compare_digest-more-constant-time.-GH.patch
49
patch -p1 -i ../0007-3.6-closes-bpo-42938-Replace-snprintf-with-Python-un.patch #CVE-2021-3177
50
patch -p1 -i ../0008-3.6-bpo-42967-only-use-as-a-query-string-separator-G.patch #CVE-2021-23336
51
patch -p1 -i ../0009-py2-ize-the-CJK-codec-test.patch
52
patch -p1 -i ../0010-3.6-bpo-43285-Make-ftplib-not-trust-the-PASV-respons.patch
53
patch -p1 -i ../0011-bpo-43075-Fix-ReDoS-in-urllib-AbstractBasicAuthHandl.patch
54
patch -p1 -i ../0012-3.9-bpo-43882-urllib.parse-should-sanitize-urls-cont.patch
55
patch -p1 -i ../0013-Backport-bpo-44022-Fix-http-client-infinite-line-rea.patch
56
patch -p1 -i ../0014-bpo-43124-Fix-smtplib-multiple-CRLF-injection-GH-259.patch
57
patch -p1 -i ../0015-bpo-42278-Use-tempfile.TemporaryDirectory-rather-tha.patch
58
patch -p1 -i ../0016-Fix-accidentally-leaving-one-sub-test-commented-out.patch
59
patch -p1 -i ../0017-bpo-46811-Make-test-suite-support-Expat-2.4.5-GH-314.patch
60
patch -p1 -i ../0018-bpo-46756-Fix-authorization-check-in-urllib.request-.patch
61
patch -p1 -i ../0019-Install-libpythonX.Y.a-in-usr-lib-instead-of-usr-lib.patch
62
patch -p1 -i ../0020-Disable-modules-and-SSL.patch
63
# patch -p1 -i ../0021-Gentoo-libdir.patch # Gentoo specific patch
64
# patch -p1 -i ../0022-Non-zero-exit-status-on-failure.patch # Don't need this
65
# patch -p1 -i ../0023-sqlite-loadable-extensions.patch # causes error: IndentationError: expected an indented block
66
patch -p1 -i ../0024-Regenerate-platform-specific-modules.patch
67
# patch -p1 -i ../0025-distutils-C.patch # Causes failure on test_distutils
68
patch -p1 -i ../0026-Turkish-locale.patch
69
patch -p1 -i ../0027-ARM-OABI.patch
70
patch -p1 -i ../0028-use_pyxml.patch
71
patch -p1 -i ../0029-Disable-nis.patch
72
# patch -p1 -i ../0030-Make-module-byte-compilation-non-fatal.patch # Does not apply cleanly
73
patch -p1 -i ../0031-Use-ncurses-to-find-pkg-config.patch
74
patch -p1 -i ../0032-Use-specific-Werror-for-cross-compile-tests.patch
75
patch -p1 -i ../0033-Force-using-system-libffi.patch
76
patch -p1 -i ../0034-test.support.unlink-ignore-EACCES.patch
77
patch -p1 -i ../0035-ssl-Hard-disable-SSLv3-to-avoid-automagic-deps.patch
78
patch -p1 -i ../0036-Fix-Wimplicit-int-Wimplicit-function-declaration.patch
79
80
# Temporary workaround for FS#22322
81
# See http://bugs.python.org/issue10835 for upstream report
82
sed -i "/progname =/s/python/python${_pybasever}/" Python/pythonrun.c
83
84
# Enable built-in SQLite module to load extensions (fix FS#22122)
85
sed -i "/SQLITE_OMIT_LOAD_EXTENSION/d" setup.py
86
87
# FS#23997
88
sed -i -e "s|^#.* /usr/local/bin/python|#!/usr/bin/python2|" Lib/cgi.py
89
90
sed -i "s/python2.3/python2/g" Lib/distutils/tests/test_build_scripts.py \
91
Lib/distutils/tests/test_install_scripts.py
92
93
# Ensure that we are using the system copy of various libraries (expat, zlib and libffi),
94
# rather than copies shipped in the tarball
95
rm -r Modules/expat
96
rm -r Modules/zlib
97
rm -r Modules/_ctypes/{darwin,libffi}*
98
99
# clean up #!s
100
find . -name '*.py' | \
101
xargs sed -i "s|#[ ]*![ ]*/usr/bin/env python$|#!/usr/bin/env python2|"
102
103
# Workaround asdl_c.py/makeopcodetargets.py errors after we touched the shebangs
104
touch Include/Python-ast.h Python/Python-ast.c Python/opcode_targets.h
105
}
106
107
build() {
108
cd "${srcdir}/Python-${pkgver}"
109
CFLAGS+=" -std=c17"
110
CPPFLAGS+=" -I/usr/include/openssl-1.1"
111
LDFLAGS+=" -L/usr/lib/openssl-1.1"
112
export OPT="${CFLAGS}"
113
./configure --prefix=/usr \
114
--enable-shared \
115
--with-threads \
116
--enable-optimizations \
117
--with-lto \
118
--enable-ipv6 \
119
--enable-unicode=ucs4 \
120
--with-system-expat \
121
--with-system-ffi \
122
--with-dbmliborder=gdbm:ndbm \
123
--without-ensurepip
124
125
make
126
}
127
128
check() {
129
# Since 2.7.14 with latest xvfb
130
# test_idle, test_tk, test_ttk_guionly: segfaults
131
# Since 2.7.15: test_ctypes
132
# test_ftplib test_imaplib test_urllib2_localnet: krb5 errors
133
# test_codecmaps_jp: TODO
134
# test_curses: fails
135
export TERM=xterm
136
local -x TZ=UTC
137
cd Python-${pkgver}
138
LD_LIBRARY_PATH="${srcdir}/Python-${pkgver}":${LD_LIBRARY_PATH} \
139
xvfb-run "${srcdir}/Python-${pkgver}/python" -m test.regrtest -v -uall -x test_idle test_tk test_ttk_guionly test_ctypes test_ssl test_ftplib test_imaplib test_urllib2_localnet test_codecmaps_jp test_ossaudiodev test_curses
140
}
141
142
package() {
143
cd Python-${pkgver}
144
145
# Hack to avoid building again
146
sed -i 's/^all:.*$/all: build_all/' Makefile
147
148
make DESTDIR="${pkgdir}" altinstall maninstall
149
150
rm "${pkgdir}"/usr/share/man/man1/python.1
151
152
ln -sf python${_pybasever} "${pkgdir}"/usr/bin/python2
153
ln -sf python${_pybasever}-config "${pkgdir}"/usr/bin/python2-config
154
ln -sf python${_pybasever}.1 "${pkgdir}"/usr/share/man/man1/python2.1
155
156
# FS#33954
157
ln -sf python-${_pybasever}.pc "${pkgdir}"/usr/lib/pkgconfig/python2.pc
158
159
ln -sf ../../libpython${_pybasever}.so "${pkgdir}"/usr/lib/python${_pybasever}/config/libpython${_pybasever}.so
160
161
mv "${pkgdir}"/usr/bin/smtpd.py "${pkgdir}"/usr/lib/python${_pybasever}/
162
163
# some useful "stuff"
164
install -dm755 "${pkgdir}"/usr/lib/python${_pybasever}/Tools/{i18n,scripts}
165
install -m755 Tools/i18n/{msgfmt,pygettext}.py "${pkgdir}"/usr/lib/python${_pybasever}/Tools/i18n/
166
install -m755 Tools/scripts/{README,*py} "${pkgdir}"/usr/lib/python${_pybasever}/Tools/scripts/
167
168
# fix conflicts with python
169
mv "${pkgdir}"/usr/bin/idle{,2}
170
mv "${pkgdir}"/usr/bin/pydoc{,2}
171
mv "${pkgdir}"/usr/bin/2to3{,-2.7}
172
173
# clean-up reference to build directory
174
sed -i "s#${srcdir}/Python-${pkgver}:##" "${pkgdir}"/usr/lib/python${_pybasever}/config/Makefile
175
}
176
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |