mirror of
https://git.yoctoproject.org/poky
synced 2026-09-13 18:49:33 +02:00
bitbake: fetch2: validate striplevel parameter
The striplevel URL parameter is appended to tar_cmd, which is later run through the shell. Validate it as a decimal count before using it in the tar arguments. (Bitbake rev: 3a8937cc4b6513f9ed54fee0b0347589a892c8d7) Signed-off-by: Anders Heimer <anders.heimer@est.tech> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit 934fe718bfe29c7ec921e6b598d81ec2ebe8f7c7) [YC: Removed the striplevel="1\n" subtest case. The URL-decoding regex in decodeurl uses `.*` without `re.DOTALL`, causing literal newlines in parameters to be silently truncated during parsing.] Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>
This commit is contained in:
committed by
Paul Barker
parent
a42a436300
commit
73f77a019a
@@ -7,6 +7,7 @@
|
||||
#
|
||||
|
||||
import contextlib
|
||||
import shutil
|
||||
import unittest
|
||||
import hashlib
|
||||
import tempfile
|
||||
@@ -853,6 +854,16 @@ class FetcherLocalTest(FetcherTest):
|
||||
|
||||
self.assertIn("does not contain supported data.tar* file", str(context.exception))
|
||||
|
||||
def assertInvalidStriplevel(self, value):
|
||||
with self.assertRaises(bb.fetch2.UnpackError) as context:
|
||||
self.fetchUnpack(['file://archive.tar;subdir=bar;striplevel=%s' % value])
|
||||
self.assertIn("Invalid striplevel parameter", str(context.exception))
|
||||
|
||||
def test_local_striplevel_rejects_invalid_values(self):
|
||||
for value in ("abc", "", "-1", "1 2"):
|
||||
with self.subTest(striplevel=repr(value)):
|
||||
self.assertInvalidStriplevel(value)
|
||||
|
||||
def dummyGitTest(self, suffix):
|
||||
# Create dummy local Git repo
|
||||
src_dir = tempfile.mkdtemp(dir=self.tempdir,
|
||||
|
||||
Reference in New Issue
Block a user