<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>16086</bug_id>
          
          <creation_ts>2025-12-02 09:16:08 +0000</creation_ts>
          <short_desc>AB-INT: cve_check.CVECheck.test_image_json: sqlite3.DatabaseError: database disk image is malformed</short_desc>
          <delta_ts>2025-12-18 15:57:48 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>10</classification_id>
          <classification>QA/Testing</classification>
          <product>Functional (self) Testing</product>
          <component>oe-selftest</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard>AB-INT</status_whiteboard>
          <keywords></keywords>
          <priority>High</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>6.0 M1</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Mathieu Dubois-Briand">mathieu.dubois-briand</reporter>
          <assigned_to name="Paul Barker">paul</assigned_to>
          <cc>mhalstead</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>yoann.congal</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>103449</commentid>
    <comment_count>0</comment_count>
    <who name="Mathieu Dubois-Briand">mathieu.dubois-briand</who>
    <bug_when>2025-12-02 09:16:08 +0000</bug_when>
    <thetext>Probably AB-INT, but given the state of master right now, its a bit tough to be sure.

2025-11-28 15:54:51,597 - oe-selftest - INFO -  ... FAIL
...
AssertionError: Command &apos;bitbake  core-image-minimal-initramfs&apos; returned non-zero exit status 1:
...
ERROR: dbus-native-1.16.2-r0 do_cve_check: Error executing a python function in exec_func_python() autogenerated:

The stack trace of python calls that resulted in this exception/failure was:
File: &apos;exec_func_python() autogenerated&apos;, lineno: 2, function: &lt;module&gt;
     0001:
 *** 0002:do_cve_check(d)
     0003:
File: &apos;/srv/pokybuild/yocto-worker/oe-selftest-debian/build/layers/openembedded-core/meta/classes/cve-check.bbclass&apos;, lineno: 172, function: do_cve_check
     0168:            try:
     0169:                patched_cves = get_patched_cves(d)
     0170:            except FileNotFoundError:
     0171:                bb.fatal(&quot;Failure in searching patches&quot;)
 *** 0172:            cve_data, status = check_cves(d, patched_cves)
     0173:            if len(cve_data) or (d.getVar(&quot;CVE_CHECK_COVERAGE&quot;) == &quot;1&quot; and status):
     0174:                get_cve_info(d, cve_data)
     0175:                cve_write_data(d, cve_data, status)
     0176:        else:
File: &apos;/srv/pokybuild/yocto-worker/oe-selftest-debian/build/layers/openembedded-core/meta/classes/cve-check.bbclass&apos;, lineno: 342, function: check_cves
     0338:            vendor = &quot;%&quot;
     0339:
     0340:        # Find all relevant CVE IDs.
     0341:        cve_cursor = conn.execute(&quot;SELECT DISTINCT ID FROM PRODUCTS WHERE PRODUCT IS ? AND VENDOR LIKE ?&quot;, (product, vendor))
 *** 0342:        for cverow in cve_cursor:
     0343:            cve = cverow[0]
     0344:
     0345:            # Write status once only for each product
     0346:            if not cves_in_product:
Exception: sqlite3.DatabaseError: database disk image is malformed</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103452</commentid>
    <comment_count>1</comment_count>
    <who name="Mathieu Dubois-Briand">mathieu.dubois-briand</who>
    <bug_when>2025-12-02 09:23:51 +0000</bug_when>
    <thetext>oe-selftest-debian ubuntu2404-vk-3 master completed at 2025-11-28 17:43:36+00:00
https://autobuilder.yoctoproject.org/valkyrie/#/builders/35/builds/2773/steps/15/logs/stdio</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103524</commentid>
    <comment_count>2</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2025-12-11 15:41:42 +0000</bug_when>
    <thetext>We seen this issue before.

Michaael Halstead added a hack to touch the file periodically which may have help but also caused problems.

We&apos;ve also tried having a local copy and then pushing the result to NFS.

That was causing other problems that others can describe.

In this case, we seem to be over-writing the file so 
it&apos;s probably worth making a change to make a new file and then
move it into place.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103560</commentid>
    <comment_count>3</comment_count>
    <who name="Mathieu Dubois-Briand">mathieu.dubois-briand</who>
    <bug_when>2025-12-15 13:11:37 +0000</bug_when>
    <thetext>metrics rocky9-vk-3 walnascar completed at 2025-12-14 07:04:42+00:00
https://autobuilder.yoctoproject.org/valkyrie/#/builders/103/builds/2408/steps/16/logs/stdio</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103582</commentid>
    <comment_count>4</comment_count>
    <who name="Paul Barker">paul</who>
    <bug_when>2025-12-17 15:08:13 +0000</bug_when>
    <thetext>We&apos;re attempting to solve this by ensuring that each new version of the CVE database file has a new inode number, so that the NFS clients (i.e. autobuilder workers) can&apos;t read stale data out of any local cache.

Patch sent to the list: https://lore.kernel.org/openembedded-core/20251217-cvedb-v1-1-d97a49b9c8de@pbarker.dev/T/#u

Local testing confirms that the patch forces the inode number to change each time the CVE database is updated. Testing on the autobuilder is needed to confirm that we don&apos;t see further database corruption.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103599</commentid>
    <comment_count>5</comment_count>
    <who name="Paul Barker">paul</who>
    <bug_when>2025-12-18 15:57:48 +0000</bug_when>
    <thetext>Patch was applied, hopefully this resolves the issue: https://git.openembedded.org/openembedded-core/commit/?id=f63622bbec1cfaca6d0b3e05e11466e4c10fa86e</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>