Bug 7620

Summary: Poor validation of subpath= value in git fetcher leads to unexpected file deletions
Product: [Build System, Metadata & Runtime] BitBake Reporter: Paul Eggleton <bluelightning>
Component: bitbakeAssignee: Paul Eggleton <bluelightning>
Status: VERIFIED FIXED QA Contact: Lucian Musat <georgex.l.musat>
Severity: critical    
Priority: High CC: alexandru.c.georgescu, anders.darander, bogdanx.a.voiculescu, poky.bs.watcher, poky.watcher
Version: 1.7   
Target Milestone: 1.9 M1   
Hardware: All   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: New (Never tested)
Verified: Documentation change: No (bug/feature does not impact docs)

Description Paul Eggleton 2015-04-16 15:55:12 UTC
It seems that if you use the subpath= parameter in a git:// URI in SRC_URI and  have / at the start or the end of the specified value, the result can be that files in your home directory get deleted:

https://lists.yoctoproject.org/pipermail/yocto/2015-April/024552.html

This is due to the git fetcher code improperly splitting and joining the path and then not validating the result, which is either / or somewhere else we shouldn't be touching, and then attempting to clean that location out prior to unpacking.
Comment 1 Paul Eggleton 2015-04-16 15:56:13 UTC
Additional note - this bug has probably been present since the subpath option was introduced; it's rarely used hence the reason why we haven't seen this issue before.
Comment 2 Anders Darander 2015-04-17 05:53:37 UTC
I've sent a simple patch for this, see http://lists.openembedded.org/pipermail/bitbake-devel/2015-April/005659.html.

Sofar, I've not looked at whether a leading '/' in subpath can cause any issues later on. If so, that could be handled by adding .strip('/') on subpath in the line before the one I'm touching here.
Comment 3 Paul Eggleton 2015-04-17 11:06:38 UTC
OK, the above patch has been merged, thanks Anders. I'll send a follow-up today with additional checks.
Comment 4 Paul Eggleton 2015-04-17 14:38:03 UTC
Follow up patch with extra checks sent:
http://lists.openembedded.org/pipermail/bitbake-devel/2015-April/005664.html
Comment 5 Paul Eggleton 2015-04-22 10:27:39 UTC
Where we are with this now - the aforementioned patches have been merged to master:

http://git.yoctoproject.org/cgit/cgit.cgi/poky/commit/?id=65e985976989c30a94d6e78c8cb348af93fa0878
http://git.yoctoproject.org/cgit/cgit.cgi/poky/commit/?id=72d88f29da1ece634028420317233a45ff8e015b

The next step is to backport them to fido, dizzy, and daisy at minimum.
Comment 6 Paul Eggleton 2015-04-26 12:44:30 UTC
These fixes have now been backported to fido, dizzy and daisy. Marking as resolved.
Comment 7 Lucian Musat 2015-09-08 14:37:16 UTC
Verified on commit bc6a1a23e3d1af3861288a7abdbc9d5010470204.