03d22f2
#!/bin/bash
03d22f2
03d22f2
DISTGIT_PATH=$(pwd)
03d22f2
f2106e0
FEDORA_VERSION=f28
b040fbf
DOCKER_FEDORA_VERSION=master
a9a3b32
DISTGIT_BRANCH=f28
05b4ad3
REPO_SELINUX_POLICY=${REPO_SELINUX_POLICY:-git@github.com:fedora-selinux/selinux-policy.git}
05b4ad3
REPO_SELINUX_POLICY_BRANCH=${REPO_SELINUX_POLICY_BRANCH:-$FEDORA_VERSION}
05b4ad3
REPO_SELINUX_POLICY_CONTRIB=${REPO_SELINUX_POLICY_CONTRIB:-git@github.com:fedora-selinux/selinux-policy-contrib.git}
05b4ad3
REPO_SELINUX_POLICY_CONTRIB_BRANCH=${REPO_SELINUX_POLICY_CONTRIB_BRANCH:-$FEDORA_VERSION}
05b4ad3
REPO_CONTAINER_SELINUX=${REPO_CONTAINER_SELINUX:-git@github.com:projectatomic/container-selinux.git}
05b4ad3
05b4ad3
# When -l is specified, we use locally created tarballs and don't download them from github
05b4ad3
DOWNLOAD_DEFAULT_GITHUB_TARBALLS=1
05b4ad3
if [ "$1" == "-l" ]; then
05b4ad3
    DOWNLOAD_DEFAULT_GITHUB_TARBALLS=0
05b4ad3
fi
03d22f2
03d22f2
git checkout $DISTGIT_BRANCH -q
03d22f2
03d22f2
POLICYSOURCES=`mktemp -d policysources.XXXXXX`
03d22f2
pushd $POLICYSOURCES > /dev/null
03d22f2
05b4ad3
git clone -q $REPO_SELINUX_POLICY selinux-policy
05b4ad3
git clone -q $REPO_SELINUX_POLICY_CONTRIB selinux-policy-contrib
05b4ad3
git clone -q $REPO_CONTAINER_SELINUX container-selinux
03d22f2
03d22f2
pushd selinux-policy > /dev/null
856e200
# prepare policy patches against upstream commits matching the last upstream merge
05b4ad3
git checkout $REPO_SELINUX_POLICY_BRANCH
51dc83b
BASE_HEAD_ID=$(git rev-parse HEAD)
51dc83b
BASE_SHORT_HEAD_ID=$(c=${BASE_HEAD_ID}; echo ${c:0:7})
05b4ad3
git archive --prefix=selinux-policy-$BASE_HEAD_ID/ --format tgz HEAD > $DISTGIT_PATH/selinux-policy-$BASE_SHORT_HEAD_ID.tar.gz
47948f5
popd > /dev/null
47948f5
47948f5
pushd selinux-policy-contrib > /dev/null
47948f5
# prepare policy patches against upstream commits matching the last upstream merge
05b4ad3
git checkout $REPO_SELINUX_POLICY_CONTRIB_BRANCH
51dc83b
CONTRIB_HEAD_ID=$(git rev-parse HEAD)
51dc83b
CONTRIB_SHORT_HEAD_ID=$(c=${CONTRIB_HEAD_ID}; echo ${c:0:7})
05b4ad3
git archive --prefix=selinux-policy-contrib-$CONTRIB_HEAD_ID/ --format tgz HEAD > $DISTGIT_PATH/selinux-policy-contrib-$CONTRIB_SHORT_HEAD_ID.tar.gz
03d22f2
popd > /dev/null
03d22f2
ab3db24
pushd container-selinux > /dev/null
ab3db24
# Actual container-selinux files are in master branch
d932255
#git checkout -b ${DOCKER_FEDORA_VERSION} -t origin/${DOCKER_FEDORA_VERSION} -q
ab3db24
tar -czf container-selinux.tgz container.if container.te container.fc
03d22f2
popd > /dev/null
03d22f2
03d22f2
pushd $DISTGIT_PATH > /dev/null
05b4ad3
if [ $DOWNLOAD_DEFAULT_GITHUB_TARBALLS == 1 ]; then
5ef8138
    wget -O selinux-policy-${BASE_SHORT_HEAD_ID}.tar.gz https://github.com/fedora-selinux/selinux-policy/archive/${BASE_HEAD_ID}.tar.gz &> /dev/null
5ef8138
    wget -O selinux-policy-contrib-${CONTRIB_SHORT_HEAD_ID}.tar.gz https://github.com/fedora-selinux/selinux-policy-contrib/archive/${CONTRIB_HEAD_ID}.tar.gz &> /dev/null
05b4ad3
fi
ab3db24
cp $POLICYSOURCES/container-selinux/container-selinux.tgz .
03d22f2
popd > /dev/null
03d22f2
03d22f2
popd > /dev/null
03d22f2
rm -rf $POLICYSOURCES
03d22f2
05b4ad3
# Update commit ids in selinux-policy.spec file
05b4ad3
sed -i "s/%global commit0 [^ ]*$/%global commit0 $BASE_HEAD_ID/" selinux-policy.spec
05b4ad3
sed -i "s/%global commit1 [^ ]*$/%global commit1 $CONTRIB_HEAD_ID/" selinux-policy.spec
05b4ad3
05b4ad3
# Update sources
05b4ad3
sha512sum --tag selinux-policy-${BASE_SHORT_HEAD_ID}.tar.gz selinux-policy-contrib-${CONTRIB_SHORT_HEAD_ID}.tar.gz container-selinux.tgz > sources
05b4ad3
51dc83b
echo -e "\nSELinux policy tarballs  and container.tgz with container policy files have been created."
05b4ad3
echo "Commit ids of selinux-policy and selinux-policy-contrib in spec file were changed to:"
51dc83b
echo "commit0 " ${BASE_HEAD_ID}
51dc83b
echo "commit1 " ${CONTRIB_HEAD_ID}