Bug 10897

Summary: license.bbclass attempts chown(root.root) in build host context, hiding errors
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Olev Kartau <olev.kartau>
Component: coreAssignee: Markus Lehtonen <markus.lehtonen>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium CC: markus.lehtonen, meta.mr.watcher, meta.watcher
Version: 2.2   
Target Milestone: 2.3   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know

Description Olev Kartau 2017-01-09 10:03:14 UTC
In Refkit build it happened that some license files appeared to be root-owned even when builder was running as user. 
Docker was used as build container method.
It turned out some combination of docker and host kernel versions did let
chown in docker to change host file to become root-owned.
(instead of EPERM).

Docker version 1.12.3 on openSUSE worker 42.2 with kernel 4.4.36 did that.

After upgrading docker to 1.12.5, chroot failed with EPERM as it should.

But this case demonstrated risky code in license.bbclass 
copy_license_files which does:
1. hardlinking to base file
2. chown(0,0)
3. hide any errors (because same code runs in and out of pseudo)

in combination with badly managed capability drop in container system,
may result in many files silently turned to root.root ownership
in builder host context.

Note that because of hardlinking, chown applied to other instances
actually tries to change ownership of base license files,
which should remain unchanged, as these are usually checked-out repo files.

Re-using same code in and out- pseudo, then hiding errors to make things
look clean, is lazy and risky solution.
Code should avoid elevating permission levels where not really needed.
Comment 1 Olev Kartau 2017-01-09 11:46:32 UTC
Based on irc discussion, immediate fix is now seen as
"chown only if under pseudo"