mirror of
https://github.com/thead-yocto-mirror/meta-external-toolchain
synced 2026-09-17 12:42:16 +02:00
package_qa_sourcery: add host user ownership test
Check for files outside of /home which are owned by the user running bitbake.
Add `package_qa_sourcery` to `PACKAGE_CLASSES`, and `${SOURCERY_QA}` to your
`WARN_QA` or `ERROR_QA` to use.
This will be submitted to oe-core's package_qa.
JIRA: SB-4185
Signed-off-by: Christopher Larson <kergoth@gmail.com>
This commit is contained in:
36
classes/package_qa_sourcery.bbclass
Normal file
36
classes/package_qa_sourcery.bbclass
Normal file
@@ -0,0 +1,36 @@
|
||||
inherit package
|
||||
|
||||
SOURCERY_QA = "host-user-contaminated"
|
||||
|
||||
# We need to test in fakeroot context to check file ownership
|
||||
do_package_qa[fakeroot] = "1"
|
||||
|
||||
HOST_USER_UID := "${@os.getuid()}"
|
||||
HOST_USER_UID[type] = "integer"
|
||||
HOST_USER_GID := "${@os.getgid()}"
|
||||
HOST_USER_GID[type] = "integer"
|
||||
|
||||
QAPATHTEST[host-user-contaminated] = "package_qa_check_host_user"
|
||||
def package_qa_check_host_user(path, name, d, elf, messages):
|
||||
"""Check for files outside of /home which are owned by the user running bitbake."""
|
||||
|
||||
if not os.path.lexists(path):
|
||||
return
|
||||
|
||||
check_uid = oe.data.typed_value('HOST_USER_UID', d)
|
||||
check_gid = oe.data.typed_value('HOST_USER_GID', d)
|
||||
|
||||
dest = d.getVar('PKGDEST', True)
|
||||
home = os.path.join(dest, 'home')
|
||||
if path == home or path.startswith(home + os.sep):
|
||||
return
|
||||
|
||||
stat = os.lstat(path)
|
||||
if stat.st_uid == check_uid:
|
||||
messages["host-user-contaminated"] = "%s is owned by uid %d, which is the same as the user running bitbake. This may be due to host contamination" % (path, check_uid)
|
||||
return False
|
||||
|
||||
if stat.st_gid == check_gid:
|
||||
messages["host-user-contaminated"] = "%s is owned by gid %d, which is the same as the user running bitbake. This may be due to host contamination" % (path, check_gid)
|
||||
return False
|
||||
return True
|
||||
Reference in New Issue
Block a user