Bug 14110

Summary: cve-check fails with 'attempt to write a readonly database'
Product: [Build System, Metadata & Runtime] OE-Core Reporter: kweihmann
Component: coreAssignee: Ross Burton <ross.burton>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium CC: meta.mr.watcher, meta.watcher, ralphs, randy.macleod, rybczynska
Version: 3.2   
Target Milestone: 5.0   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know

Description kweihmann 2020-10-31 01:16:16 UTC
File: '/opt/build/poky/meta/classes/cve-check.bbclass', lineno: 241, function: check_cves
     0237:        else:
     0238:            vendor = "%"
     0239:
     0240:        # Find all relevant CVE IDs.
 *** 0241:        for cverow in conn.execute("SELECT DISTINCT ID FROM PRODUCTS WHERE PRODUCT IS ? AND VENDOR LIKE ?", (product, vendor)):
     0242:            cve = cverow[0]
     0243:
     0244:            if cve in cve_whitelist:
     0245:                bb.note("%s-%s has been whitelisted for %s" % (product, pv, cve))
Exception: sqlite3.OperationalError: attempt to write a readonly database

I suspect that, as the class is executed on multiple recipe workspaces at the same time, and sqlite is know to have issues with multiple clients executions (http://www.sqlite.org/faq.html#q5) we are running into the above problem.
Comment 1 Ross Burton 2020-11-05 07:41:29 UTC
Can you confirm what version of Poky you're using?
Comment 2 kweihmann 2020-11-05 09:09:01 UTC
Bleeding edge master that was. To be exact revision 43e3a19c19e2d4f6b1d84c24413df6327540fab9
Comment 3 Ralph Siemsen 2022-03-16 19:02:53 UTC
I believe this is fixed by 440f07d211841147f2d2b6016a20b75747f45752 ("cve-check: get_cve_info should open the database read-only")
Comment 4 Ross Burton 2022-03-21 13:44:12 UTC
https://lists.openembedded.org/g/openembedded-core/message/162637 suggests that it may not have been sufficient.
Comment 5 Randy MacLeod 2023-04-21 18:45:44 UTC
Moved en masse from 4.2 to 4.3 by Randy.
Comment 6 Marta Rybczynska 2023-05-04 12:51:40 UTC
This should be fixed by OE-core 8efe99214d8b005f0ecac690ce5ba17b31758f92 ("cve-update-db-native: avoid incomplete updates"). Would be interested to know if it isn't the case.
Comment 7 kweihmann 2024-03-02 09:05:42 UTC
Haven't had any issue in a long time now - I think this bug can be considered fixed
Comment 8 Ross Burton 2024-03-04 09:41:52 UTC
Agreed, thanks.