<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>9443</bug_id>
          
          <creation_ts>2016-04-12 13:15:48 +0000</creation_ts>
          <short_desc>lsb_release output should be sanitised before usage</short_desc>
          <delta_ts>2016-04-14 13:05:38 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>core</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Undecided</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Sascha Silbe">silbe</reporter>
          <assigned_to name="Ross Burton">ross.burton</assigned_to>
          <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Don&apos;t know</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>61087</commentid>
    <comment_count>0</comment_count>
    <who name="Sascha Silbe">silbe</who>
    <bug_when>2016-04-12 13:15:48 +0000</bug_when>
    <thetext>Some downstream distributions use special characters in some of the lsb_release output fields. That&apos;s unusual, but not expressly forbidden by the LSB specification [1].

poky currently uses the output of &quot;lsb_release -ir&quot; more or less as-is for generating some paths (e.g. SSTATE_EXTRAPATH). Since many parts of poky (including most recipes) don&apos;t properly quote / escape paths, this causes the build to fail horribly.

The distro name should be sanitised to only contain characters that cannot cause any trouble when used unquoted (&quot;whitelist&quot; approach). The existing replacements in meta/lib/oe/lsb.py only cover two specific cases (&quot;blacklist&quot; approach).

Encountered with fido (in my case the distribution id contained double quotes), but the code in master looks very similar.

[1] https://refspecs.linuxfoundation.org/LSB_5.0.0/LSB-Core-generic/LSB-Core-generic/lsbrelease.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>61095</commentid>
    <comment_count>1</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2016-04-12 15:39:24 +0000</bug_when>
    <thetext>For testing, what distribution is known to be broken like this?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>61102</commentid>
    <comment_count>2</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2016-04-12 16:51:12 +0000</bug_when>
    <thetext>Specifically, if we ran the distribution name through re.sub(r&apos;\W&apos;, &apos;&apos;, name) so that everything apart from numbers and letters were removed, would that fix the problem without causing other issues?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>61105</commentid>
    <comment_count>3</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2016-04-12 17:05:10 +0000</bug_when>
    <thetext>Can you see if this patch works for you?  http://patchwork.openembedded.org/patch/120135/</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>61136</commentid>
    <comment_count>4</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2016-04-13 11:45:55 +0000</bug_when>
    <thetext>Merged in oe-core 8a96a7207561e00eb92e4fb69e7340f20bfa2053.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>61201</commentid>
    <comment_count>5</comment_count>
    <who name="Sascha Silbe">silbe</who>
    <bug_when>2016-04-14 13:05:38 +0000</bug_when>
    <thetext>I haven&apos;t tried the patch yet, but running the regex replacement on the problematic lsb_release output sanitised the name properly (as expected). Thanks!</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>