bitbake: fetch2: validate striplevel parameter

The striplevel URL parameter is appended to tar_cmd, which is later run
through the shell. Validate it as a decimal count before using it in the
tar arguments.

(Bitbake rev: 3a8937cc4b6513f9ed54fee0b0347589a892c8d7)

Signed-off-by: Anders Heimer <anders.heimer@est.tech>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 934fe718bfe29c7ec921e6b598d81ec2ebe8f7c7)
[YC: Removed the striplevel="1\n" subtest case. The URL-decoding regex
in decodeurl uses `.*` without `re.DOTALL`, causing literal newlines in
parameters to be silently truncated during parsing.]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
This commit is contained in:
Anders Heimer
2026-05-18 16:59:09 +02:00
committed by Paul Barker
parent a42a436300
commit 73f77a019a
2 changed files with 15 additions and 1 deletions

View File

@@ -1520,7 +1520,10 @@ class FetchMethod(object):
if unpack:
tar_cmd = 'tar --extract --no-same-owner'
if 'striplevel' in urldata.parm:
tar_cmd += ' --strip-components=%s' % urldata.parm['striplevel']
striplevel = urldata.parm['striplevel']
if not striplevel.isdigit():
raise UnpackError("Invalid striplevel parameter: %s" % striplevel, urldata.url)
tar_cmd += ' --strip-components=%s' % striplevel
if file.endswith('.tar'):
cmd = '%s -f %s' % (tar_cmd, file)
elif file.endswith('.tgz') or file.endswith('.tar.gz') or file.endswith('.tar.Z'):