From 1a0873acb8a297bef750cdf102c284ceefab1a5b Mon Sep 17 00:00:00 2001 From: Jan Tojnar Date: Sat, 11 Jul 2026 20:05:46 +0200 Subject: [PATCH] orca: Apply upstream subprocess-reduction patch This will allow us to reduce the `fix-paths.patch`. --- pkgs/by-name/or/orca/fix-paths.patch | 91 +++++++++++++++------------- pkgs/by-name/or/orca/package.nix | 20 ++++-- 2 files changed, 64 insertions(+), 47 deletions(-) diff --git a/pkgs/by-name/or/orca/fix-paths.patch b/pkgs/by-name/or/orca/fix-paths.patch index 1268f032d576..1e7fc2a4a00a 100644 --- a/pkgs/by-name/or/orca/fix-paths.patch +++ b/pkgs/by-name/or/orca/fix-paths.patch @@ -1,70 +1,75 @@ -diff --git a/src/orca/ax_utilities_application.py b/src/orca/ax_utilities_application.py -index 218c7bf22..4474f26cd 100644 ---- a/src/orca/ax_utilities_application.py -+++ b/src/orca/ax_utilities_application.py -@@ -180,7 +180,7 @@ class AXUtilitiesApplication: - - pid = AXUtilitiesApplication.get_process_id(app) - try: -- state = subprocess.getoutput(f"cat /proc/{pid}/status | grep State") -+ state = subprocess.getoutput(f"@cat@ /proc/{pid}/status | @grep@ State") - state = state.split()[1] - except (GLib.GError, IndexError) as error: - tokens = [f"AXUtilitiesApplication: Exception checking state of pid {pid}: {error}"] -diff --git a/src/orca/debugging_tools_manager.py b/src/orca/debugging_tools_manager.py -index 5c607f3cd..18ddcd920 100644 ---- a/src/orca/debugging_tools_manager.py -+++ b/src/orca/debugging_tools_manager.py -@@ -169,7 +169,7 @@ class DebuggingToolsManager: - else: - name = AXObject.get_name(app) or "[DEAD]" - try: -- cmdline = subprocess.getoutput(f"cat /proc/{pid}/cmdline") -+ cmdline = subprocess.getoutput(f"@cat@ /proc/{pid}/cmdline") - except subprocess.SubprocessError as error: - cmdline = f"EXCEPTION: {error}" - else: diff --git a/src/orca/orca_bin.py.in b/src/orca/orca_bin.py.in -index 86a1413ca..f272c431d 100755 +index be3d4ebdd..1f83d6d6c 100755 --- a/src/orca/orca_bin.py.in +++ b/src/orca/orca_bin.py.in -@@ -211,7 +211,7 @@ def in_graphical_desktop() -> bool: - def other_orcas() -> list[int]: +@@ -209,7 +209,7 @@ def other_orcas() -> list[int]: """Returns the pid of any other instances of Orca owned by this user.""" -- with subprocess.Popen(f"pgrep -u {os.getuid()} -x orca", -+ with subprocess.Popen(f"@pgrep@ -u {os.getuid()} -x orca", - shell=True, - stdout=subprocess.PIPE) as proc: + with subprocess.Popen( +- ["pgrep", "-u", str(os.getuid()), "-x", "orca"], ++ ["@pgrep@", "-u", str(os.getuid()), "-x", "orca"], + stdout=subprocess.PIPE, + ) as proc: pids = proc.stdout.read() if proc.stdout else b"" diff --git a/src/orca/orca_modifier_manager.py b/src/orca/orca_modifier_manager.py -index d1d95f5b9..e57993521 100644 +index eec1edc5f..e4ceee004 100644 --- a/src/orca/orca_modifier_manager.py +++ b/src/orca/orca_modifier_manager.py @@ -289,7 +289,7 @@ class OrcaModifierManager: self._restore_original_xkbcomp() - with subprocess.Popen( -- ["xkbcomp", display, "-"], -+ ["@xkbcomp@", display, "-"], + with subprocess.Popen( # noqa: S603 - xkbcomp is a system dependency, not untrusted input +- ["xkbcomp", display, "-"], # noqa: S607 - full path would break across distros ++ ["@xkbcomp@", display, "-"], # noqa: S607 - full path would break across distros stdout=subprocess.PIPE, stderr=subprocess.DEVNULL, ) as p: @@ -338,7 +338,7 @@ class OrcaModifierManager: self._caps_lock_cleared = False - with subprocess.Popen( -- ["xkbcomp", "-w0", "-", display], -+ ["@xkbcomp@", "-w0", "-", display], + with subprocess.Popen( # noqa: S603 - xkbcomp is a system dependency, not untrusted input +- ["xkbcomp", "-w0", "-", display], # noqa: S607 - full path would break across distros ++ ["@xkbcomp@", "-w0", "-", display], # noqa: S607 - full path would break across distros stdin=subprocess.PIPE, stdout=None, stderr=None, @@ -449,7 +449,7 @@ class OrcaModifierManager: debug.print_message(debug.LEVEL_INFO, msg, True) - with subprocess.Popen( -- ["xkbcomp", "-w0", "-", display], -+ ["@xkbcomp@", "-w0", "-", display], + with subprocess.Popen( # noqa: S603 - xkbcomp is a system dependency, not untrusted input +- ["xkbcomp", "-w0", "-", display], # noqa: S607 - full path would break across distros ++ ["@xkbcomp@", "-w0", "-", display], # noqa: S607 - full path would break across distros stdin=subprocess.PIPE, stdout=None, stderr=None, +diff --git a/tests/unit_tests/test_orca_modifier_manager.py b/tests/unit_tests/test_orca_modifier_manager.py +index 3c6c917cb..5d714f2a5 100644 +--- a/tests/unit_tests/test_orca_modifier_manager.py ++++ b/tests/unit_tests/test_orca_modifier_manager.py +@@ -700,7 +700,7 @@ class TestOrcaModifierManager: + manager.refresh_orca_modifiers("test reason") + mock_restore.assert_called_once() + mock_popen.assert_called_once_with( +- ["xkbcomp", ":0", "-"], ++ ["@xkbcomp@", ":0", "-"], + stdout=subprocess.PIPE, + stderr=subprocess.DEVNULL, + ) +@@ -808,7 +808,7 @@ class TestOrcaModifierManager: + mock_unmap.assert_called_once() + if expects_popen_call: + mock_popen.assert_called_once_with( +- ["xkbcomp", "-w0", "-", ":0"], ++ ["@xkbcomp@", "-w0", "-", ":0"], + stdin=subprocess.PIPE, + stdout=None, + stderr=None, +@@ -880,7 +880,7 @@ class TestOrcaModifierManager: + + if expects_popen_call: + mock_popen.assert_called_once_with( +- ["xkbcomp", "-w0", "-", ":0"], ++ ["@xkbcomp@", "-w0", "-", ":0"], + stdin=subprocess.PIPE, + stdout=None, + stderr=None, diff --git a/pkgs/by-name/or/orca/package.nix b/pkgs/by-name/or/orca/package.nix index 2ac15616ce19..a2a25ca964d1 100644 --- a/pkgs/by-name/or/orca/package.nix +++ b/pkgs/by-name/or/orca/package.nix @@ -4,6 +4,7 @@ buildPackages, pkg-config, fetchurl, + fetchpatch, meson, ninja, wrapGAppsHook3, @@ -20,8 +21,6 @@ dbus, xkbcomp, procps, - gnugrep, - coreutils, gsettings-desktop-schemas, speechd-minimal, brltty, @@ -41,9 +40,22 @@ python3.pkgs.buildPythonApplication (finalAttrs: { }; patches = [ + # Avoid running `cat` and `grep` subshells. + (fetchpatch { + url = "https://gitlab.gnome.org/GNOME/orca/-/commit/8f47283da2da7a7d34e769d9c129152decf632cb.patch"; + hash = "sha256-ts/ZCgEaTrnmMM1cUFJB2rDW9icMoi4jV34psD0IDCc="; + }) + + # Required for next patch to apply. + (fetchpatch { + url = "https://gitlab.gnome.org/GNOME/orca/-/commit/a7b10302b9ff9145a98cb3626f2488d15c558d3e.patch"; + hash = "sha256-lacy9vIyM3n84s+tbYvAUBKWCT+4nlI9uPVl7UPVS74="; + includes = [ + "src/orca/orca_modifier_manager.py" + ]; + }) + (replaceVars ./fix-paths.patch { - cat = "${coreutils}/bin/cat"; - grep = "${gnugrep}/bin/grep"; pgrep = "${procps}/bin/pgrep"; xkbcomp = "${xkbcomp}/bin/xkbcomp"; })