<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>14476</bug_id>
          
          <creation_ts>2021-07-07 08:34:15 +0000</creation_ts>
          <short_desc>Fetchers are not able to use passwords with &apos;=&apos; sign</short_desc>
          <delta_ts>2022-10-21 12:37:11 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>BitBake</product>
          <component>bitbake</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>x86_64</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WORKSFORME</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>Future</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Patrick Erdmann">pe</reporter>
          <assigned_to name="Unassigned">unassigned</assigned_to>
          <cc>mark.asselstine</cc>
    
    <cc>poky.bs.watcher</cc>
    
    <cc>poky.watcher</cc>
    
    <cc>randy.macleod</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Don&apos;t know</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>90869</commentid>
    <comment_count>0</comment_count>
    <who name="Patrick Erdmann">pe</who>
    <bug_when>2021-07-07 08:34:15 +0000</bug_when>
    <thetext>In line 402 of fetcher2/__init__.py (Version 3.0) is a split(&quot;=&quot;). If you use a &quot;=&quot; in your password the fetcher will fail with:

ERROR: /home/user/devel/my_project/my_layer/meta-my_layer-winplus/recipes-prebuild-images/fpga/fpga-mainboard.bb: Error executing a python function in &lt;code&gt;:

The stack trace of python calls that resulted in this exception/failure was:
File: &apos;&lt;code&gt;&apos;, lineno: 3, function: &lt;module&gt;
     0001:__anon_22__home_user_devel_my_project_sources_poky_meta_conf_machine_include_arm_feature_arm_thumb_inc(d)
     0002:__anon_25__home_user_devel_my_project_sources_poky_meta_classes_patch_bbclass(d)
 *** 0003:__anon_688__home_user_devel_my_project_sources_poky_meta_classes_base_bbclass(d)
     0004:__anon_64__home_user_devel_my_project_sources_meta_freescale_classes_fsl_dynamic_packagearch_bbclass(d)
     0005:__anon_1186__home_user_devel_my_project_sources_poky_meta_classes_insane_bbclass(d)
     0006:__anon_251__home_user_devel_my_project_sources_poky_meta_classes_package_bbclass(d)
     0007:__anon_718__home_user_devel_my_project_sources_poky_meta_classes_package_rpm_bbclass(d)
File: &apos;/home/user/devel/my_project/sources/poky/meta/classes/base.bbclass&apos;, lineno: 585, function: __anon_688__home_user_devel_my_project_sources_poky_meta_classes_base_bbclass
     0581:    needsrcrev = False
     0582:    srcuri = d.getVar(&apos;SRC_URI&apos;)
     0583:    for uri in srcuri.split():
     0584:        (scheme, _ , path) = bb.fetch.decodeurl(uri)[:3]
 *** 0585:
     0586:        # HTTP/FTP use the wget fetcher
     0587:        if scheme in (&quot;http&quot;, &quot;https&quot;, &quot;ftp&quot;):
     0588:            d.appendVarFlag(&apos;do_fetch&apos;, &apos;depends&apos;, &apos; wget-native:do_populate_sysroot&apos;)
     0589:
File: &apos;/home/user/devel/my_project/sources/poky/bitbake/lib/bb/fetch2/__init__.py&apos;, lineno: 402, function: decodeurl
     0398:        for s in parm.split(&apos;;&apos;):
     0399:            if s:
     0400:                if not &apos;=&apos; in s:
     0401:                    raise MalformedUrl(url, &quot;The URL: &apos;%s&apos; is invalid: parameter %s does not specify a value (missing &apos;=&apos;)&quot; % (url, s))
 *** 0402:                s1, s2 = s.split(&apos;=&apos;)
     0403:                p[s1] = s2
     0404:
     0405:    return type, host, urllib.parse.unquote(path), user, pswd, p
     0406:
Exception: ValueError: too many values to unpack (expected 2)

ERROR: Failed to parse recipe: /home/user/devel/my_project/my_layer/meta-my_layer-winplus/recipes-prebuild-images/fpga/fpga-mainboard.bb</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>90886</commentid>
    <comment_count>1</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2021-07-08 15:02:05 +0000</bug_when>
    <thetext>We like to fix this but no one is available. please send a patch if you are able to, see:
https://www.openembedded.org/wiki/How_to_submit_a_patch_to_OpenEmbedded</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>90898</commentid>
    <comment_count>2</comment_count>
    <who name="Patrick Erdmann">pe</who>
    <bug_when>2021-07-08 20:41:50 +0000</bug_when>
    <thetext>Hi,

i started to fix it. I will need some time to find a possible solution. Because everything with = and ; will be handled as an additional parameter.

If i find a solution i will let you know.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>90947</commentid>
    <comment_count>3</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2021-07-15 17:01:53 +0000</bug_when>
    <thetext>Thanks Patrick. Note that if you have a preliminary patch that you want to discuss, it&apos;s likely that people will respond to it if you post it with an RFC prefix in the subject line on the email list.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>90948</commentid>
    <comment_count>4</comment_count>
    <who name="Patrick Erdmann">pe</who>
    <bug_when>2021-07-15 18:06:38 +0000</bug_when>
    <thetext>The idea is to support for &quot;url quoted strings&quot; in parameters. Therefore i would create a new parameter called quote_params. If this one is set to true the fetcher unquotes every parameter.
To make it a bit more comfortable i would wrap around quote to make it available via ${@...fetch.quote(...)}. Maybe it is also possible to add a MYVARIABLE_quoted to make it availabe magically?

I really would like to come up with an easy idea. But i think its not really possible here, because user and password are handled via a modified URL, which is great until you want/need = or ? or ; in your paramaters.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>94186</commentid>
    <comment_count>5</comment_count>
    <who name="Mark">mark.asselstine</who>
    <bug_when>2022-10-17 01:03:12 +0000</bug_when>
    <thetext>Patrick, can you share the problematic SRC_URI line please? The username and password should never be making it into the parameter processing based on the re.

https://git.yoctoproject.org/poky/tree/bitbake/lib/bb/fetch2/__init__.py#n355

m = re.compile(&apos;(?P&lt;type&gt;[^:]*)://((?P&lt;user&gt;[^/;]+)@)?(?P&lt;location&gt;[^;]+)(;(?P&lt;parm&gt;.*))?&apos;).match(url)

NOTE that everything after the &apos;://&apos; and before the &apos;@&apos; will be taken as the username and password, only &apos;;&apos; and &apos;/&apos; are special characters, which at first glance appear to be something we can remove, but I would have to do some research first.

The &apos;=&apos; character is fine to have in a password. If you copy the decodeurl() function as it is today, or from summer 2021 it handles &apos;=&apos; just fine.

So again please provide your SRC_URI as there might be another detail which is causing your issue. Thanks.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>94226</commentid>
    <comment_count>6</comment_count>
    <who name="Mark">mark.asselstine</who>
    <bug_when>2022-10-21 02:26:19 +0000</bug_when>
    <thetext>I have submitted a patch which adds a new test to qualify decodeurl() on passwords which contain the &apos;=&apos; character. I believe this issue was caused by passing the password as a parameter instead of doing something like &quot;git://user:pass@somewhere.com&quot;.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>94227</commentid>
    <comment_count>7</comment_count>
    <who name="Patrick Erdmann">pe</who>
    <bug_when>2022-10-21 06:33:27 +0000</bug_when>
    <thetext>Hi,

Yes this is true. During that time the Company was using gitlab and you cannot change the password of the access tokens. It had the = very often. So it was caused while using an old version ?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>94228</commentid>
    <comment_count>8</comment_count>
    <who name="Mark">mark.asselstine</who>
    <bug_when>2022-10-21 12:37:11 +0000</bug_when>
    <thetext>Patrick, I am not sure which version you were using at the time of your bug report but the logic for extracting the user:password has been the same for many years and is solid. The only special characters are &apos;/&apos; and &apos;;&apos; which can&apos;t be in the password (unfortunately there is no way to make these not special).

I did run across this Stackoverflow post which is incorrect
https://stackoverflow.com/questions/25508382/bitbake-yocto-git-fetch-uri-authentication

If I find my Stackoverflow login I will respond to the post to prevent others from  using this approach.

The link to my review is
https://lore.kernel.org/bitbake-devel/20221021022018.2454713-1-mark.asselstine@windriver.com/T/#u

Thanks for our bug report and if you still have an issue please make updates.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>