Bug 14941 - test_shallow_submodules (bb.tests.fetch.GitShallowTest) failure because of git CVE fix
Summary: test_shallow_submodules (bb.tests.fetch.GitShallowTest) failure because of gi...
Status: RESOLVED FIXED
Alias: None
Product: Functional (self) Testing
Classification: QA/Testing
Component: bitbake-selftest (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: High normal
Target Milestone: 4.2 M1
Assignee: Alexandre Belloni
QA Contact:
URL:
Whiteboard: backport all branches
Depends on:
Blocks:
 
Reported: 2022-10-19 21:53 UTC by Alexandre Belloni
Modified: 2022-10-27 15:14 UTC (History)
1 user (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandre Belloni 2022-10-19 21:53:39 UTC
======================================================================
ERROR: test_shallow_submodules (bb.tests.fetch.GitShallowTest)
----------------------------------------------------------------------
Traceback (most recent call last):
  File "/home/pokybuild/yocto-worker/oe-selftest-ubuntu/build/bitbake/lib/bb/tests/fetch.py", line 1872, in test_shallow_submodules
    self.git('submodule add file://%s' % smdir, cwd=self.srcdir)
  File "/home/pokybuild/yocto-worker/oe-selftest-ubuntu/build/bitbake/lib/bb/tests/fetch.py", line 423, in git
    return bb.process.run(cmd, cwd=cwd)[0]
  File "/home/pokybuild/yocto-worker/oe-selftest-ubuntu/build/bitbake/lib/bb/process.py", line 189, in run
    raise ExecutionError(cmd, pipe.returncode, stdout, stderr)
bb.process.ExecutionError: Execution of 'git submodule add file:///tmp/bitbake-fetch-hp5nq_8y/gitsubmodule' failed with exit code 128:
Cloning into '/tmp/bitbake-fetch-hp5nq_8y/gitsource/gitsubmodule'...
fatal: transport 'file' not allowed
fatal: clone of 'file:///tmp/bitbake-fetch-hp5nq_8y/gitsubmodule' into submodule path '/tmp/bitbake-fetch-hp5nq_8y/gitsource/gitsubmodule' failed



file:// transport is disabled in git until there is a fix for CVE-2022-39253. The first impacted host is ubuntu 22.04 but all distributions will probably follow:
http://changelogs.ubuntu.com/changelogs/pool/main/g/git/git_2.34.1-1ubuntu1.5/changelog
https://git.launchpad.net/ubuntu/+source/git/tree/debian/patches/CVE-2022-39253-1.patch?h=applied/ubuntu/jammy-security
Comment 1 Randy MacLeod 2022-10-20 14:56:30 UTC
Alex has a work-around which has been applied to both dunfell and kirkstone. We need a better fix.

It seems that we should disable the test until the CVE is resolved properly.
Comment 2 Alexandre Belloni 2022-10-20 15:38:56 UTC
The actual patch breaking things is https://git.launchpad.net/ubuntu/+source/git/tree/debian/patches/CVE-2022-39253-11.patch?h=applied/ubuntu/jammy-security

And the fix seems to be using -c protocol.file.allow=always

I'll prepare a patch