From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-lf1-f47.google.com (mail-lf1-f47.google.com [209.85.167.47]) by mx.groups.io with SMTP id smtpd.web10.11012.1586871383127526256 for ; Tue, 14 Apr 2020 06:36:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20161025 header.b=juX7W/H5; spf=pass (domain: gmail.com, ip: 209.85.167.47, mailfrom: ricardo.ribalda@gmail.com) Received: by mail-lf1-f47.google.com with SMTP id r17so9395310lff.2 for ; Tue, 14 Apr 2020 06:36:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=J/2sQF442JhsjMv33GrF0h5FcL7mJY1m4bSOEKIE2nU=; b=juX7W/H5bgwboOZIUoVu6DhTRgKatvfEgh3pZrxpyF7invUSsV7p38CVQ7VcqESAM5 UfyQ021UZAKw4d349pF3RJsb17UruTXt2312EAmgVYLj+ePr6Fum8GudQzX1nLTXHvv8 TXvpH3gWwsn9pIsRhlLI6nZhC5XTQ2Ok1nXKxSv0gNPnuoez4zhZMTDbh/9IPg6dUqkJ A/SD/qSvBlBncjErTYIOXCWPMgIiucG5UtNMCSK0zfTZ+BZpwbeza16qbi/g+SrksHv9 i6qyy3TRb2sWDtZsf3hxjTqVlFFsHHWaDY7euuSKQD/hIsP7g16HZTVggK0942x1slVt rKgg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references:mime-version:content-transfer-encoding; bh=J/2sQF442JhsjMv33GrF0h5FcL7mJY1m4bSOEKIE2nU=; b=d0U5K4xhGurMtbH7ka2iKYLGrOetSARVxV8QbLVCcnQbsFa6kv91zJo+jSryHbXQiQ Xij8L/sf4Cv3V725PX0IuLzoxL8zeCkSl4nPY8JZhkJh59CbSgTZyz9zSlbv1zv+Rai1 HPZQkb6clUb4FAv1hClqgFEDdA0iKcaF9EHVFLNsAW/EZ6a4JgVPoQT/mOfxjApueXJF ZCZLG5d0VxXFWnn5+GxHFOE25sDjXFNxzp4c4WovDhQAMOi23ZmRC4au4SE2G2Th+dB3 64hyZ1/t/Lin9o75Y4J7gKsLmthgh1raQ4z5AWCuizwC+WO+bOLmW6AhokQGUCEOTKt4 Ojgg== X-Gm-Message-State: AGi0PuYzdFJjZ+z3I3A8CW/nVfgJ6pT8iA9BsrPmk/HLLsjGgPrKXeHY pC7PrZCFcHc3oNq9sPEcUqkEIaFjrxU= X-Google-Smtp-Source: APiQypIUABa3OmJCK7II9q0QnAmT4Gqi6tFEt/vH16DPg/4vw63hwldmtJ6GjzjqPxtBTro5WgstdA== X-Received: by 2002:ac2:5684:: with SMTP id 4mr13420952lfr.88.1586871380989; Tue, 14 Apr 2020 06:36:20 -0700 (PDT) Return-Path: Received: from neopili.qtec.com (cpe.xe-3-0-1-778.vbrnqe10.dk.customer.tdc.net. [80.197.57.18]) by smtp.gmail.com with ESMTPSA id o6sm9218344lji.15.2020.04.14.06.36.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 14 Apr 2020 06:36:19 -0700 (PDT) Sender: Ricardo Ribalda Delgado From: "Ricardo Ribalda" To: openembedded-core , Paul Barker Cc: Ricardo Ribalda Delgado Subject: [PATCH v6 01/10] wic: Fix permissions when using exclude or include path Date: Tue, 14 Apr 2020 15:36:05 +0200 Message-Id: <20200414133614.1830058-2-ricardo@ribalda.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20200414133614.1830058-1-ricardo@ribalda.com> References: <20200414133614.1830058-1-ricardo@ribalda.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit When parameters include_path or exclude_path are passed to the rootfs plugin, it will copy the partition content into a folder and make all the modifications there. This is done using copyhardlinktree(), which does not take into consideration the content of the pseudo folder, which contains the information about the right permissions and ownership of the folders. This results in a rootfs owned by the user that is running the wic command (usually UID 1000), which makes some rootfs unbootable. This bug can be easily triggerd with the following .wks part / --source rootfs --fstype=ext4 --exclude-path=home And this sequence: $ wic create test-permissions -e core-image-minimal -o test/ $ sudo mount test/test-permissions-202004080823-sda.direct.p1 /mnt $ ls -la /mnt/etc/shadow To fix this we copy the content of the pseudo folders to the new folder and modify the pseudo database using the "pseudo -B" command. If the rootfs is not a rootfs generated by bitbake a warning is shown making the user aware that the permissions on the target might not match what he expects. WARNING: /tmp/test/../pseudo folder does not exist. Usernames and permissions will be invalid Cc: Paul Barker Signed-off-by: Ricardo Ribalda Delgado --- scripts/lib/wic/partition.py | 7 +++-- scripts/lib/wic/plugins/source/rootfs.py | 36 ++++++++++++++++++++++-- 2 files changed, 37 insertions(+), 6 deletions(-) diff --git a/scripts/lib/wic/partition.py b/scripts/lib/wic/partition.py index 2d95f78439..b02711be37 100644 --- a/scripts/lib/wic/partition.py +++ b/scripts/lib/wic/partition.py @@ -190,7 +190,7 @@ class Partition(): (self.mountpoint, self.size, self.fixed_size)) def prepare_rootfs(self, cr_workdir, oe_builddir, rootfs_dir, - native_sysroot, real_rootfs = True): + native_sysroot, real_rootfs = True, pseudo_dir = None): """ Prepare content for a rootfs partition i.e. create a partition and fill it from a /rootfs dir. @@ -198,8 +198,9 @@ class Partition(): Currently handles ext2/3/4, btrfs, vfat and squashfs. """ p_prefix = os.environ.get("PSEUDO_PREFIX", "%s/usr" % native_sysroot) - p_localstatedir = os.environ.get("PSEUDO_LOCALSTATEDIR", - "%s/../pseudo" % rootfs_dir) + if (pseudo_dir == None): + pseudo_dir = "%s/../pseudo" % rootfs_dir + p_localstatedir = os.environ.get("PSEUDO_LOCALSTATEDIR", pseudo_dir) p_passwd = os.environ.get("PSEUDO_PASSWD", rootfs_dir) p_nosymlinkexp = os.environ.get("PSEUDO_NOSYMLINKEXP", "1") pseudo = "export PSEUDO_PREFIX=%s;" % p_prefix diff --git a/scripts/lib/wic/plugins/source/rootfs.py b/scripts/lib/wic/plugins/source/rootfs.py index 705aeb5563..caad9efccc 100644 --- a/scripts/lib/wic/plugins/source/rootfs.py +++ b/scripts/lib/wic/plugins/source/rootfs.py @@ -20,7 +20,7 @@ from oe.path import copyhardlinktree from wic import WicError from wic.pluginbase import SourcePlugin -from wic.misc import get_bitbake_var +from wic.misc import get_bitbake_var, exec_native_cmd logger = logging.getLogger('wic') @@ -44,6 +44,15 @@ class RootfsPlugin(SourcePlugin): return os.path.realpath(image_rootfs_dir) + @staticmethod + def __get_pseudo(native_sysroot, rootfs, pseudo_dir): + pseudo = "export PSEUDO_PREFIX=%s/usr;" % native_sysroot + pseudo += "export PSEUDO_LOCALSTATEDIR=%s;" % pseudo_dir + pseudo += "export PSEUDO_PASSWD=%s;" % rootfs + pseudo += "export PSEUDO_NOSYMLINKEXP=1;" + pseudo += "%s " % get_bitbake_var("FAKEROOTCMD") + return pseudo + @classmethod def do_prepare_partition(cls, part, source_params, cr, cr_workdir, oe_builddir, bootimg_dir, kernel_dir, @@ -68,8 +77,14 @@ class RootfsPlugin(SourcePlugin): "it is not a valid path, exiting" % part.rootfs_dir) part.rootfs_dir = cls.__get_rootfs_dir(rootfs_dir) + pseudo_dir = os.path.join(part.rootfs_dir, "../pseudo") + if not os.path.lexists(pseudo_dir): + logger.warn("%s folder does not exist. " + "Usernames and permissions will be invalid " % pseudo_dir) + pseudo_dir = None new_rootfs = None + new_pseudo = None # Handle excluded paths. if part.exclude_path or part.include_path: # We need a new rootfs directory we can delete files from. Copy to @@ -78,9 +93,23 @@ class RootfsPlugin(SourcePlugin): if os.path.lexists(new_rootfs): shutil.rmtree(os.path.join(new_rootfs)) - copyhardlinktree(part.rootfs_dir, new_rootfs) + # Convert the pseudo directory to its new location + if (pseudo_dir): + new_pseudo = os.path.join(new_rootfs, "../pseudo%d" % part.lineno) + if os.path.lexists(new_pseudo): + shutil.rmtree(new_pseudo) + os.mkdir(new_pseudo) + shutil.copy(os.path.join(pseudo_dir, "files.db"), + os.path.join(new_pseudo, "files.db")) + + pseudo_cmd = "%s -B -m %s -M %s" % (cls.__get_pseudo(native_sysroot, + new_rootfs, + new_pseudo), + part.rootfs_dir, new_rootfs) + exec_native_cmd(pseudo_cmd, native_sysroot) + for path in part.include_path or []: copyhardlinktree(path, new_rootfs) @@ -112,4 +141,5 @@ class RootfsPlugin(SourcePlugin): shutil.rmtree(full_path) part.prepare_rootfs(cr_workdir, oe_builddir, - new_rootfs or part.rootfs_dir, native_sysroot) + new_rootfs or part.rootfs_dir, native_sysroot, + pseudo_dir = new_pseudo or pseudo_dir) -- 2.25.1