<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>12469</bug_id>
          
          <creation_ts>2018-01-10 06:37:24 +0000</creation_ts>
          <short_desc>do_patch does not fail in a rare case</short_desc>
          <delta_ts>2018-03-05 07:58:08 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>devtools / tool chain</component>
          <version>2.5</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>DUPLICATE</resolution>
          <dup_id>10450</dup_id>
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>2.5 M3</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Rebecca Chang">rebecca.swee.fun.chang</reporter>
          <assigned_to name="Ross Burton">ross.burton</assigned_to>
          <cc>alex.kanavin</cc>
    
    <cc>bluelightning</cc>
    
    <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
    
    <cc>stephano</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>78986</commentid>
    <comment_count>0</comment_count>
    <who name="Rebecca Chang">rebecca.swee.fun.chang</who>
    <bug_when>2018-01-10 06:37:24 +0000</bug_when>
    <thetext>One example is with ghostscript recipe, where it has several CVE patches in SRC_URI. It happen where bumping ghostscript source version to 9.21 has included one of the CVE patch, CVE-2016-7977.patch. While we are supposed to remove the redundant patch, but do_patch does not flag any patch error and it appears that the patch was being patched on the source again.

Checking on the ghostscript source within build/tmp/work, the code was patched:
----- snip -----
lib_file_open(gs_file_path_ptr  lib_path, const gs_memory_t *mem, i_ctx_t *i_ctx_p,
                       const char *fname, uint flen, char *buffer, int blen, uint *pclen, ref *pfile)
{   /* i_ctx_p is NULL running arg (@) files.
     * lib_path and mem are never NULL
     */
    bool starting_arg_file = (i_ctx_p == NULL) ? true : i_ctx_p-&gt;starting_arg_file;
    bool search_with_no_combine = false;
    bool search_with_combine = false;
    char fmode[2] = { &apos;r&apos;, 0};
    gx_io_device *iodev = iodev_default(mem);
    gs_main_instance *minst = get_minst_from_memory(mem);
    int code;

&gt;&gt;&gt;&gt;&gt;    if (i_ctx_p &amp;&amp; starting_arg_file)
&gt;&gt;&gt;&gt;&gt;        i_ctx_p-&gt;starting_arg_file = false;

&gt;&gt;&gt;&gt;&gt;    if (i_ctx_p &amp;&amp; starting_arg_file)
&gt;&gt;&gt;&gt;&gt;        i_ctx_p-&gt;starting_arg_file = false;

    /* when starting arg files (@ files) iodev_default is not yet set */
    if (iodev == 0)
        iodev = (gx_io_device *)gx_io_device_table[0];
----- snip -----

It was an coincidence that the duplicated code does not have impact to compilation, but this is still an issue.

---

Meanwhile, in devtool, the patch was identified as &quot;applied&quot;.

ERROR: Applying &apos;CVE-2016-7977.patch&apos; failed:
checking file psi/zfile.c
Reversed (or previously applied) patch detected!  Assume -R? [n] 
Apply anyway? [n] 
Skipping patch.
1 out of 1 hunk ignored
ERROR: Function failed: patch_do_patch
ERROR: Logfile of failure stored in: /data/rebeccas/sdk-installer/poky_sdk/tmp/work/i586-poky-linux/ghostscript/9.21-r0/devtooltmp-jv777rue/temp/log.do_patch.43041
NOTE: Tasks Summary: Attempted 3 tasks of which 0 didn&apos;t need to be rerun and 1 failed.
ERROR: Extracting source for ghostscript failed</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>79702</commentid>
    <comment_count>1</comment_count>
    <who name="Alexander Kanavin">alex.kanavin</who>
    <bug_when>2018-03-05 07:58:08 +0000</bug_when>
    <thetext>Same patch fuzz issue as bug 10450 I think.

*** This bug has been marked as a duplicate of bug 10450 ***</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>