<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>13157</bug_id>
          
          <creation_ts>2019-01-29 16:52:16 +0000</creation_ts>
          <short_desc>Bitbake fails to fetch from a premirror that doesn&apos;t support https</short_desc>
          <delta_ts>2019-05-30 15:24:16 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>BitBake</product>
          <component>bitbake</component>
          <version>2.7</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>OBSOLETE</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>2.7</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Maxime Roussin-Bélanger">maxime.roussinbelanger</reporter>
          <assigned_to name="Maxime Roussin-Bélanger">maxime.roussinbelanger</assigned_to>
          <cc>poky.bs.watcher</cc>
    
    <cc>poky.watcher</cc>
    
    <cc>randy.macleod</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>82892</commentid>
    <comment_count>0</comment_count>
    <who name="Maxime Roussin-Bélanger">maxime.roussinbelanger</who>
    <bug_when>2019-01-29 16:52:16 +0000</bug_when>
    <thetext>Preconditions/Environment
-------------------------
A PREMIRROR that doesn&apos;t support https

Triggering Action/Cause
-----------------------
bitbake a recipe that uses https protocol and fetches from github.

Expectation
-----------
Try to redirect to http and download the archive? Skip the PREMIRROR and download from upstream...

Actual Result
-------------
wget fails when trying to fetch from the premirror because https is reserved for a login page.

wget gets redirected to the login page, download the HTML, tries to untar the html page, then obviously fails to untar it.

I was trying to build tools inside meta-clang layer.

URL transformed to HTTPS due to an HSTS policy is a warning given by wget.


Reproducibility
---------------
5/5</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>82907</commentid>
    <comment_count>1</comment_count>
    <who name="Maxime Roussin-Bélanger">maxime.roussinbelanger</who>
    <bug_when>2019-01-30 18:52:23 +0000</bug_when>
    <thetext>A real-life example of the problem

http://errors.yoctoproject.org/Errors/Details/220286/</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>82918</commentid>
    <comment_count>2</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2019-01-31 16:22:15 +0000</bug_when>
    <thetext>I&apos;m not sure this is a bitbake problem but a misconfigured server.

The logs show a fetch of http://bitbucket.org/eigen/eigen/get/3.3.7.tar.bz2 which redirected to https://bitbucket.org/eigen/eigen/get/3.3.7.tar.bz2. The fact that this redirected url is invalid is an issue with the hosting of those files.

I tried this locally and it worked so perhaps you could retest please? Perhaps the server issue was fixed?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>82919</commentid>
    <comment_count>3</comment_count>
    <who name="Maxime Roussin-Bélanger">maxime.roussinbelanger</who>
    <bug_when>2019-01-31 17:03:57 +0000</bug_when>
    <thetext>The redirect URL isn&apos;t invalid, you can see that the file was downloaded without problem:

2019-01-30 00:25:44 (3.51 MB/s) - ‘TOPDIR/../downloads/libeigen-3.3.7.tar.bz2’ saved [1665168/1665168]

But then for some reason, the fetcher can&apos;t find it?

How can that happen?!
&quot;
The fetch command returned success for url http://bitbucket.org/eigen/eigen/get/3.3.7.tar.bz2 but TOPDIR/../downloads/libeigen-3.3.7.tar.bz2 doesn&apos;t exist?!
&quot;

I was not able to reproduce the error ever on local. It only did it on the remote build machine that yocto is using. When I sent the patch I made sure that it worked on local first.

The only error I was able to create was when I trying to build a recipe from the meta-clang layer that had the protocol set to https. But my company PREMIRROR that had the cache tarball doesn&apos;t support HTTPS. But you can download the tarball in HTTP no problem. HTTPS on the PREMIRROR is reserved for a login page.

That&apos;s probably another issue though.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>82924</commentid>
    <comment_count>4</comment_count>
    <who name="Maxime Roussin-Bélanger">maxime.roussinbelanger</who>
    <bug_when>2019-01-31 19:02:53 +0000</bug_when>
    <thetext>To get around the redirection of HTTP -&gt; HTTPS, I had to modify the FETCHCMD_wget with

FETCHCMD_wget = &quot;/usr/bin/env wget -t 2 -T 30 --passive-ftp --no-check-certificate --no-hsts&quot;

I added the &quot;--no-hsts&quot; part.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>82925</commentid>
    <comment_count>5</comment_count>
    <who name="Maxime Roussin-Bélanger">maxime.roussinbelanger</who>
    <bug_when>2019-01-31 19:03:34 +0000</bug_when>
    <thetext>To get around the redirection of HTTP -&gt; HTTPS, I had to modify the FETCHCMD_wget with

FETCHCMD_wget = &quot;/usr/bin/env wget -t 2 -T 30 --passive-ftp --no-check-certificate --no-hsts&quot;

I added the &quot;--no-hsts&quot; part.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>82948</commentid>
    <comment_count>6</comment_count>
    <who name="Stephen K Jolley">sjolley.yp.pm</who>
    <bug_when>2019-02-02 04:03:30 +0000</bug_when>
    <thetext>Richard,

It appears that Maxime has answered your question. I am moving it to Accepted unless you have other questions.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>84015</commentid>
    <comment_count>7</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2019-05-30 15:24:16 +0000</bug_when>
    <thetext>It appears that his was a problem with the local network configuration.
If it is not, please open a new more clear bug describing the issue.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>