From e5a997b7a5551ca50a88280bc992b95088d7e019 Mon Sep 17 00:00:00 2001 From: Maik Riechert Date: Sat, 29 Aug 2026 17:53:18 -0700 Subject: [PATCH 1/2] Fix bundled LibRaw link selection Link bundled Unix libraries by their exact paths so environment-provided library directories cannot select an incompatible system LibRaw. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- setup.py | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/setup.py b/setup.py index 805b630..b51bd33 100644 --- a/setup.py +++ b/setup.py @@ -30,6 +30,7 @@ libraries = ["libraw_r"] include_dirs = [numpy.get_include()] # Always include numpy headers library_dirs = [] +extra_objects = [] extra_compile_args = [] extra_link_args = [] define_macros = [] @@ -311,8 +312,15 @@ def unix_libraw_compile(): # Build from source install_dir = get_install_dir() include_dirs += [os.path.join(install_dir, "include", "libraw")] - library_dirs += [os.path.join(install_dir, "lib")] - libraries = ["raw_r"] + if isMac or isLinux: + # Link the bundled library explicitly so an earlier -L from the Python + # configuration or environment cannot select a system LibRaw instead. + suffix = ".dylib" if isMac else ".so" + libraries = [] + extra_objects = [os.path.join(install_dir, "lib", "libraw_r" + suffix)] + else: + library_dirs += [os.path.join(install_dir, "lib")] + libraries = ["raw_r"] # If building from source, we know we have the config header libraw_config_found = True else: @@ -390,6 +398,7 @@ def _copy_bundled_libs(self): sources=[os.path.join("rawpy", "_rawpy.pyx")], libraries=libraries, library_dirs=library_dirs, + extra_objects=extra_objects, define_macros=define_macros, extra_compile_args=extra_compile_args, extra_link_args=extra_link_args, From 6c61aca30d2ff9f9e81753e6b295028f6775a24b Mon Sep 17 00:00:00 2001 From: Maik Riechert Date: Sat, 29 Aug 2026 17:57:12 -0700 Subject: [PATCH 2/2] Add macOS LibRaw linking regression test Build with Homebrew LibRaw ahead of the bundled library directory and inspect the wheel before delocation to catch accidental system-library linkage. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .github/scripts/test-macos-libraw-linking.sh | 32 ++++++++++++++++++++ .github/workflows/ci.yml | 17 +++++++++++ 2 files changed, 49 insertions(+) create mode 100755 .github/scripts/test-macos-libraw-linking.sh diff --git a/.github/scripts/test-macos-libraw-linking.sh b/.github/scripts/test-macos-libraw-linking.sh new file mode 100755 index 0000000..ed48f25 --- /dev/null +++ b/.github/scripts/test-macos-libraw-linking.sh @@ -0,0 +1,32 @@ +#!/bin/bash +set -euxo pipefail + +python -m pip install --upgrade pip +brew install libraw + +# Put Homebrew's LibRaw before setuptools' library_dirs. The bundled build +# must still link against the LibRaw that it just compiled. +libraw_prefix=$(brew --prefix libraw) +export LDFLAGS="-L${libraw_prefix}/lib" + +python -m pip wheel . --wheel-dir dist --no-deps + +wheel=$(find dist -name 'rawpy-*.whl' -print -quit) +test -n "${wheel}" + +wheel_dir=tmp_macos_libraw_linking +rm -rf "${wheel_dir}" +unzip -q "${wheel}" -d "${wheel_dir}" + +extensions=("${wheel_dir}"/rawpy/_rawpy*.so) +test "${#extensions[@]}" -eq 1 + +dependencies=$(otool -L "${extensions[0]}") +echo "${dependencies}" + +if grep -Fq "${libraw_prefix}/lib/libraw_r" <<<"${dependencies}"; then + echo "ERROR: rawpy linked against Homebrew LibRaw instead of the bundled library" + exit 1 +fi + +grep -Eq '[[:space:]]@rpath/libraw_r\.[0-9]+\.dylib' <<<"${dependencies}" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2033d99..6de9d42 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -222,6 +222,23 @@ jobs: name: wheel-${{ matrix.config.os-name }}-${{ matrix.config.python-arch }}-${{ matrix.config.python-version }} path: dist + test-macos-bundled-libraw-linking: + runs-on: macos-15 + env: + HOMEBREW_NO_AUTO_UPDATE: 1 + + steps: + - uses: actions/checkout@v4 + with: + submodules: true + + - uses: actions/setup-python@v5 + with: + python-version: '3.13' + + - name: Verify bundled LibRaw wins over Homebrew + run: .github/scripts/test-macos-libraw-linking.sh + test: strategy: fail-fast: false