<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>6549</bug_id>
          
          <creation_ts>2014-07-17 19:47:17 +0000</creation_ts>
          <short_desc>GNU Wget is required in buildtools-tarball.</short_desc>
          <delta_ts>2014-07-25 08:59:04 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>6</classification_id>
          <classification>Yocto Project Subprojects</classification>
          <product>ADT</product>
          <component>adt</component>
          <version>1.6</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>1.7</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Tudor Florea">tudor.florea</reporter>
          <assigned_to name="Paul Eggleton">bluelightning</assigned_to>
          <cc>poky.adt.watcher</cc>
    
    <cc>poky.watcher</cc>
    
    <cc>richard.purdie</cc>
    
    <cc>sgw</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Done (doc changes complete)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>44549</commentid>
    <comment_count>0</comment_count>
    <who name="Tudor Florea">tudor.florea</who>
    <bug_when>2014-07-17 19:47:17 +0000</bug_when>
    <thetext>GNU Wget cannot be upgrated to a newer that 1.12 version on supported Contos distro.
GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download. (A side effect of this can be exploited as per http://www.cvedetails.com/cve/CVE-2010-2252/).
In yocto environment, this means the files downloaded when fetching cannot be properly used:
$ wget http://www.balabit.com/downloads/files/syslog-ng/open-source-edition/3.4.2/source/eventlog_0.2.13.tar.gz
$ ls
eventlog_0.2.13.tar.gz?AWSAccessKeyId=AKIAICTJ5MANGPMOH7JA&amp;Expires=1400838672&amp;Signature=TjakOBpOvHtEKKDgF14iVinWpY0=

This in turn lead to build errors like:

WARNING: Failed to fetch URL http://www.balabit.com/downloads/files/syslog-ng/open-source-edition/3.4.2/source/eventlog_0.2.13.tar.gz, attempting MIRRORS if available
ERROR: Fetcher failure for URL: &apos;http://www.balabit.com/downloads/files/syslog-ng/open-source-edition/3.4.2/source/eventlog_0.2.13.tar.gz&amp;#39;. The fetch command returned success for url http://www.balabit.com/downloads/files/syslog-ng/open-source-edition/3.4.2/source/eventlog_0.2.13.tar.gz but /path/to/downloads/eventlog_0.2.13.tar.gz doesn&apos;t exist?!
ERROR: Function failed: Fetcher failure for URL: &apos;http://www.balabit.com/downloads/files/syslog-ng/open-source-edition/3.4.2/source/eventlog_0.2.13.tar.gz&amp;#39;. Unable to fetch URL from any source.
ERROR: Logfile of failure stored in: /path/to/tmp/work/ppce500v2-enea-linux-gnuspe/eventlog/0.2.13-r0/temp/log.do_fetch.28302
ERROR: Task 4 (/path/to/poky/meta-openembedded/meta-oe/recipes-support/eventlog/eventlog_0.2.13.bb, do_fetch) failed with exit code &apos;1&apos;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>44602</commentid>
    <comment_count>1</comment_count>
    <who name="Tudor Florea">tudor.florea</who>
    <bug_when>2014-07-21 16:05:52 +0000</bug_when>
    <thetext>http://git.openembedded.org/?p=openembedded-core.git&amp;a=commit;h=0d34ed38a5893d0b68deb8a62ac4085f81db1dab</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>44656</commentid>
    <comment_count>2</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2014-07-24 14:36:38 +0000</bug_when>
    <thetext>Fix merged.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>44657</commentid>
    <comment_count>3</comment_count>
    <who name="Tudor Florea">tudor.florea</who>
    <bug_when>2014-07-24 14:43:55 +0000</bug_when>
    <thetext>I&apos;m not sure about the process flow but I assume the inclusion of wget in the buildtools needs to be documented (in chapter 1.3.3. in Reference manual).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>44676</commentid>
    <comment_count>4</comment_count>
    <who name="Paul Eggleton">bluelightning</who>
    <bug_when>2014-07-24 16:01:51 +0000</bug_when>
    <thetext>buildtools contains lots of things other than git, tar, and python, and I don&apos;t think it&apos;s going to be helpful to the user to document everything that is in it.

We should probably add an explicit pointer from the CentOS section to the buildtools, but to be fair when you look at the versions of git/tar/python in CentOS 6 it becomes pretty clear that you need the buildtools anyway.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>44678</commentid>
    <comment_count>5</comment_count>
    <who name="Tudor Florea">tudor.florea</who>
    <bug_when>2014-07-24 16:31:47 +0000</bug_when>
    <thetext>This is ok for me.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>44697</commentid>
    <comment_count>6</comment_count>
    <who name="Paul Eggleton">bluelightning</who>
    <bug_when>2014-07-25 08:59:04 +0000</bug_when>
    <thetext>The &quot;CentOS Packages&quot; section of the reference manual has been updated as above in the dora, daisy and master branches, so I&apos;m marking this as resolved.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>