#!/usr/bin/make -f

export DEB_BUILD_MAINT_OPTIONS=hardening=+bindnow

# cryptography 2.6.1's cffi _openssl bindings only compile against OpenSSL 1.1.x,
# which resolute no longer provides in the system libssl-dev (3.x). Build and
# link against the private 1.1.1 prefix shipped by our libssl1.1-dev package.
# The versioned runtime libraries live in the standard multiarch path, so the
# resulting extension resolves libssl.so.1.1 / libcrypto.so.1.1 at run time via
# the libssl1.1 package; no rpath is needed.
OPENSSL11 = /opt/openssl-1.1
export CPPFLAGS := -I$(OPENSSL11)/include $(shell dpkg-buildflags --get CPPFLAGS)
export CFLAGS   := -I$(OPENSSL11)/include $(shell dpkg-buildflags --get CFLAGS)
export LDFLAGS  := -L$(OPENSSL11)/lib $(shell dpkg-buildflags --get LDFLAGS)
export PKG_CONFIG_PATH := $(OPENSSL11)/lib

%:
	dh $@ --with python2 --buildsystem=python_distutils

override_dh_auto_clean:
	dh_auto_clean
	rm -rf cryptography/hazmat/bindings/__pycache__ \
	       cryptography/hazmat/primitives/__pycache__

# The Sphinx docs are python3-only, and the test suite needs
# pytest/hypothesis/pretend/cryptography-vectors, none of which are packaged for
# python2 on resolute.
override_dh_auto_test:

override_dh_python2:
	dh_python2 --depends=cffi --depends=enum34 --depends=ipaddress
	sed -Ei -e '/^cffi|^enum34|^ipaddress/d' debian/python-cryptography/usr/lib/python*/dist-packages/cryptography*.egg-info/requires.txt
