<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>10897</bug_id>
          
          <creation_ts>2017-01-09 10:03:14 +0000</creation_ts>
          <short_desc>license.bbclass attempts chown(root.root) in build host context, hiding errors</short_desc>
          <delta_ts>2017-03-02 09:16:21 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>core</component>
          <version>2.2</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>2.3</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Olev Kartau">olev.kartau</reporter>
          <assigned_to name="Markus Lehtonen">markus.lehtonen</assigned_to>
          <cc>markus.lehtonen</cc>
    
    <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Don&apos;t know</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>69615</commentid>
    <comment_count>0</comment_count>
    <who name="Olev Kartau">olev.kartau</who>
    <bug_when>2017-01-09 10:03:14 +0000</bug_when>
    <thetext>In Refkit build it happened that some license files appeared to be root-owned even when builder was running as user. 
Docker was used as build container method.
It turned out some combination of docker and host kernel versions did let
chown in docker to change host file to become root-owned.
(instead of EPERM).

Docker version 1.12.3 on openSUSE worker 42.2 with kernel 4.4.36 did that.

After upgrading docker to 1.12.5, chroot failed with EPERM as it should.

But this case demonstrated risky code in license.bbclass 
copy_license_files which does:
1. hardlinking to base file
2. chown(0,0)
3. hide any errors (because same code runs in and out of pseudo)

in combination with badly managed capability drop in container system,
may result in many files silently turned to root.root ownership
in builder host context.

Note that because of hardlinking, chown applied to other instances
actually tries to change ownership of base license files,
which should remain unchanged, as these are usually checked-out repo files.

Re-using same code in and out- pseudo, then hiding errors to make things
look clean, is lazy and risky solution.
Code should avoid elevating permission levels where not really needed.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>69617</commentid>
    <comment_count>1</comment_count>
    <who name="Olev Kartau">olev.kartau</who>
    <bug_when>2017-01-09 11:46:32 +0000</bug_when>
    <thetext>Based on irc discussion, immediate fix is now seen as
&quot;chown only if under pseudo&quot;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>71029</commentid>
    <comment_count>2</comment_count>
    <who name="Markus Lehtonen">markus.lehtonen</who>
    <bug_when>2017-03-02 09:16:21 +0000</bug_when>
    <thetext>Fix merged in
http://git.openembedded.org/openembedded-core/commit/?id=19118a1408f32bb24d95ab3d7d7faed58cbae900</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>