<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>7620</bug_id>
          
          <creation_ts>2015-04-16 15:55:12 +0000</creation_ts>
          <short_desc>Poor validation of subpath= value in git fetcher leads to unexpected file deletions</short_desc>
          <delta_ts>2015-09-08 14:37:16 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>BitBake</product>
          <component>bitbake</component>
          <version>1.7</version>
          <rep_platform>All</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>VERIFIED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>High</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>1.9 M1</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Paul Eggleton">bluelightning</reporter>
          <assigned_to name="Paul Eggleton">bluelightning</assigned_to>
          <cc>alexandru.c.georgescu</cc>
    
    <cc>anders.darander</cc>
    
    <cc>bogdanx.a.voiculescu</cc>
    
    <cc>poky.bs.watcher</cc>
    
    <cc>poky.watcher</cc>
          
          <qa_contact name="Lucian Musat">georgex.l.musat</qa_contact>
          <cf_os>---</cf_os>
          <cf_regression_type>New (Never tested)</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>50358</commentid>
    <comment_count>0</comment_count>
    <who name="Paul Eggleton">bluelightning</who>
    <bug_when>2015-04-16 15:55:12 +0000</bug_when>
    <thetext>It seems that if you use the subpath= parameter in a git:// URI in SRC_URI and  have / at the start or the end of the specified value, the result can be that files in your home directory get deleted:

https://lists.yoctoproject.org/pipermail/yocto/2015-April/024552.html

This is due to the git fetcher code improperly splitting and joining the path and then not validating the result, which is either / or somewhere else we shouldn&apos;t be touching, and then attempting to clean that location out prior to unpacking.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>50359</commentid>
    <comment_count>1</comment_count>
    <who name="Paul Eggleton">bluelightning</who>
    <bug_when>2015-04-16 15:56:13 +0000</bug_when>
    <thetext>Additional note - this bug has probably been present since the subpath option was introduced; it&apos;s rarely used hence the reason why we haven&apos;t seen this issue before.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>50373</commentid>
    <comment_count>2</comment_count>
    <who name="Anders Darander">anders.darander</who>
    <bug_when>2015-04-17 05:53:37 +0000</bug_when>
    <thetext>I&apos;ve sent a simple patch for this, see http://lists.openembedded.org/pipermail/bitbake-devel/2015-April/005659.html.

Sofar, I&apos;ve not looked at whether a leading &apos;/&apos; in subpath can cause any issues later on. If so, that could be handled by adding .strip(&apos;/&apos;) on subpath in the line before the one I&apos;m touching here.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>50379</commentid>
    <comment_count>3</comment_count>
    <who name="Paul Eggleton">bluelightning</who>
    <bug_when>2015-04-17 11:06:38 +0000</bug_when>
    <thetext>OK, the above patch has been merged, thanks Anders. I&apos;ll send a follow-up today with additional checks.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>50386</commentid>
    <comment_count>4</comment_count>
    <who name="Paul Eggleton">bluelightning</who>
    <bug_when>2015-04-17 14:38:03 +0000</bug_when>
    <thetext>Follow up patch with extra checks sent:
http://lists.openembedded.org/pipermail/bitbake-devel/2015-April/005664.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>50466</commentid>
    <comment_count>5</comment_count>
    <who name="Paul Eggleton">bluelightning</who>
    <bug_when>2015-04-22 10:27:39 +0000</bug_when>
    <thetext>Where we are with this now - the aforementioned patches have been merged to master:

http://git.yoctoproject.org/cgit/cgit.cgi/poky/commit/?id=65e985976989c30a94d6e78c8cb348af93fa0878
http://git.yoctoproject.org/cgit/cgit.cgi/poky/commit/?id=72d88f29da1ece634028420317233a45ff8e015b

The next step is to backport them to fido, dizzy, and daisy at minimum.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>50512</commentid>
    <comment_count>6</comment_count>
    <who name="Paul Eggleton">bluelightning</who>
    <bug_when>2015-04-26 12:44:30 +0000</bug_when>
    <thetext>These fixes have now been backported to fido, dizzy and daisy. Marking as resolved.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>53839</commentid>
    <comment_count>7</comment_count>
    <who name="Lucian Musat">georgex.l.musat</who>
    <bug_when>2015-09-08 14:37:16 +0000</bug_when>
    <thetext>Verified on commit bc6a1a23e3d1af3861288a7abdbc9d5010470204.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>