One example is with ghostscript recipe, where it has several CVE patches in SRC_URI. It happen where bumping ghostscript source version to 9.21 has included one of the CVE patch, CVE-2016-7977.patch. While we are supposed to remove the redundant patch, but do_patch does not flag any patch error and it appears that the patch was being patched on the source again. Checking on the ghostscript source within build/tmp/work, the code was patched: ----- snip ----- lib_file_open(gs_file_path_ptr lib_path, const gs_memory_t *mem, i_ctx_t *i_ctx_p, const char *fname, uint flen, char *buffer, int blen, uint *pclen, ref *pfile) { /* i_ctx_p is NULL running arg (@) files. * lib_path and mem are never NULL */ bool starting_arg_file = (i_ctx_p == NULL) ? true : i_ctx_p->starting_arg_file; bool search_with_no_combine = false; bool search_with_combine = false; char fmode[2] = { 'r', 0}; gx_io_device *iodev = iodev_default(mem); gs_main_instance *minst = get_minst_from_memory(mem); int code; >>>>> if (i_ctx_p && starting_arg_file) >>>>> i_ctx_p->starting_arg_file = false; >>>>> if (i_ctx_p && starting_arg_file) >>>>> i_ctx_p->starting_arg_file = false; /* when starting arg files (@ files) iodev_default is not yet set */ if (iodev == 0) iodev = (gx_io_device *)gx_io_device_table[0]; ----- snip ----- It was an coincidence that the duplicated code does not have impact to compilation, but this is still an issue. --- Meanwhile, in devtool, the patch was identified as "applied". ERROR: Applying 'CVE-2016-7977.patch' failed: checking file psi/zfile.c Reversed (or previously applied) patch detected! Assume -R? [n] Apply anyway? [n] Skipping patch. 1 out of 1 hunk ignored ERROR: Function failed: patch_do_patch ERROR: Logfile of failure stored in: /data/rebeccas/sdk-installer/poky_sdk/tmp/work/i586-poky-linux/ghostscript/9.21-r0/devtooltmp-jv777rue/temp/log.do_patch.43041 NOTE: Tasks Summary: Attempted 3 tasks of which 0 didn't need to be rerun and 1 failed. ERROR: Extracting source for ghostscript failed
Same patch fuzz issue as bug 10450 I think. *** This bug has been marked as a duplicate of bug 10450 ***