Bug 9443 - lsb_release output should be sanitised before usage
Summary: lsb_release output should be sanitised before usage
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: core (show other bugs)
Version: unspecified
Hardware: All Multiple
: Undecided normal
Target Milestone: ---
Assignee: Ross Burton
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2016-04-12 13:15 UTC by Sascha Silbe
Modified: 2016-04-14 13:05 UTC (History)
2 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Don't know


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sascha Silbe 2016-04-12 13:15:48 UTC
Some downstream distributions use special characters in some of the lsb_release output fields. That's unusual, but not expressly forbidden by the LSB specification [1].

poky currently uses the output of "lsb_release -ir" more or less as-is for generating some paths (e.g. SSTATE_EXTRAPATH). Since many parts of poky (including most recipes) don't properly quote / escape paths, this causes the build to fail horribly.

The distro name should be sanitised to only contain characters that cannot cause any trouble when used unquoted ("whitelist" approach). The existing replacements in meta/lib/oe/lsb.py only cover two specific cases ("blacklist" approach).

Encountered with fido (in my case the distribution id contained double quotes), but the code in master looks very similar.

[1] https://refspecs.linuxfoundation.org/LSB_5.0.0/LSB-Core-generic/LSB-Core-generic/lsbrelease.html
Comment 1 Ross Burton 2016-04-12 15:39:24 UTC
For testing, what distribution is known to be broken like this?
Comment 2 Ross Burton 2016-04-12 16:51:12 UTC
Specifically, if we ran the distribution name through re.sub(r'\W', '', name) so that everything apart from numbers and letters were removed, would that fix the problem without causing other issues?
Comment 3 Ross Burton 2016-04-12 17:05:10 UTC
Can you see if this patch works for you?  http://patchwork.openembedded.org/patch/120135/
Comment 4 Ross Burton 2016-04-13 11:45:55 UTC
Merged in oe-core 8a96a7207561e00eb92e4fb69e7340f20bfa2053.
Comment 5 Sascha Silbe 2016-04-14 13:05:38 UTC
I haven't tried the patch yet, but running the regex replacement on the problematic lsb_release output sanitised the name properly (as expected). Thanks!