From: Samuel Martin <s.martin49@gmail.com>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH v7 03/18] core: re-enter make if $(CURDIR) or $(O) are not absolute canonical path
Date: Wed, 9 Mar 2016 23:58:44 +0100 [thread overview]
Message-ID: <1457564339-27294-4-git-send-email-s.martin49@gmail.com> (raw)
In-Reply-To: <1457564339-27294-1-git-send-email-s.martin49@gmail.com>
When $(CURDIR) or $(O) contain symlinks (or mount-bind) in their path,
they can be resolved differently, depending on each package build-system
(whether it uses the given paths or get the absolute canonical ones).
Thus, to make easier tracking down host machine paths leaking into the
host, target or staging trees, the CURDIR and O variables are set to
their absolute canonical paths.
Note that this change takes care of the makefile wrapper installed in
$(O) to avoid unneeded make recursion.
Signed-off-by: Samuel Martin <s.martin49@gmail.com>
---
changes v6->v7:
- none
changes v5->v6:
- new patch
---
Makefile | 22 ++++++++++++++++++----
1 file changed, 18 insertions(+), 4 deletions(-)
diff --git a/Makefile b/Makefile
index 98c8dc7..52a92f6 100644
--- a/Makefile
+++ b/Makefile
@@ -26,16 +26,30 @@
# Trick for always running with a fixed umask
UMASK = 0022
-ifneq ($(shell umask),$(UMASK))
+
+# Check if we need to re-enter make for one or several of the following reasons:
+# 1- Wrong (too restrictive) umask:
+# This prevents Buildroot and packages from creating files and directories.
+# 2- CWD (i.e. $(CURDIR)) not being the absolute canonical path:
+# This makes harder tracking and fixing host machine path leaks.
+# 3- Output location (i.e. $(O)) not being the absolute canonical path:
+# This makes harder tracking and fixing host machine path leaks.
+#
+# Note:
+# - remove the trailing '/.' from $(O) as it can be added by the makefile
+# wrapper installed in the $(O).
+ifneq ($(shell umask):$(CURDIR):$(patsubst %/.,%,$(O)),$(UMASK):$(realpath $(CURDIR)):$(realpath $(O)))
.PHONY: _all $(MAKECMDGOALS)
$(MAKECMDGOALS): _all
@:
_all:
- @umask $(UMASK) && $(MAKE) --no-print-directory $(MAKECMDGOALS)
+ umask $(UMASK) && \
+ $(MAKE) -C $(realpath $(CURDIR)) --no-print-directory \
+ $(MAKECMDGOALS) O=$(realpath $(O))
-else # umask
+else # umask / $(CURDIR) / $(O)
# This is our default rule, so must come first
all:
@@ -1007,4 +1021,4 @@ include docs/manual/manual.mk
.PHONY: $(noconfig_targets)
-endif #umask
+endif #umask / $(CURDIR) / $(O)
--
2.7.2
next prev parent reply other threads:[~2016-03-09 22:58 UTC|newest]
Thread overview: 57+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-03-09 22:58 [Buildroot] [PATCH v7 00/18] Relocatable SDK / build machine leaks Samuel Martin
2016-03-09 22:58 ` [Buildroot] [PATCH v7 01/18] package/linux-headers: cleanup installation Samuel Martin
2016-03-09 23:09 ` Yann E. MORIN
2016-03-12 8:46 ` Samuel Martin
2016-03-22 22:10 ` Yann E. MORIN
2016-03-09 22:58 ` [Buildroot] [PATCH v7 02/18] core: use $(CURDIR) to set TOPDIR Samuel Martin
2016-03-09 23:10 ` Yann E. MORIN
2016-03-09 23:51 ` Arnout Vandecappelle
2016-03-10 20:45 ` Thomas Petazzoni
2016-03-10 22:50 ` Thomas Petazzoni
2016-03-09 22:58 ` Samuel Martin [this message]
2016-03-09 23:15 ` [Buildroot] [PATCH v7 03/18] core: re-enter make if $(CURDIR) or $(O) are not absolute canonical path Yann E. MORIN
2016-03-12 8:48 ` Samuel Martin
[not found] ` <CAFt09wNvtXGcfZ3PFZOgGu+bDvp6mEr44uwxa_ryjeP6DDQKBQ@mail.gmail.com>
2016-03-21 1:45 ` Matthew Weber
2016-03-21 5:21 ` Samuel Martin
2016-03-21 11:40 ` Matthew Weber
2016-03-22 3:03 ` Matthew Weber
2016-03-22 5:55 ` Samuel Martin
2016-03-22 11:10 ` Matthew Weber
2016-03-22 22:07 ` Yann E. MORIN
2016-03-22 23:11 ` Matthew Weber
2016-03-23 0:54 ` Matthew Weber
2016-03-23 1:36 ` Matthew Weber
2016-03-25 6:31 ` Samuel Martin
2016-03-26 12:21 ` Arnout Vandecappelle
2016-03-23 17:41 ` Yann E. MORIN
2016-03-09 22:58 ` [Buildroot] [PATCH v7 04/18] core: staging symlink uses a relative path when possible Samuel Martin
2016-03-09 23:20 ` Yann E. MORIN
2016-03-10 20:47 ` Thomas Petazzoni
2016-03-12 9:11 ` Samuel Martin
2016-03-12 13:12 ` Thomas Petazzoni
2016-03-09 22:58 ` [Buildroot] [PATCH v7 05/18] core: make staging *-config scripts relocatable Samuel Martin
2016-03-09 23:24 ` Yann E. MORIN
2016-03-10 0:07 ` Arnout Vandecappelle
2016-03-12 9:22 ` Samuel Martin
2016-03-09 22:58 ` [Buildroot] [PATCH v7 06/18] core: make host " Samuel Martin
2016-03-10 0:12 ` Arnout Vandecappelle
2016-03-10 12:30 ` Samuel Martin
2016-03-10 20:50 ` Thomas Petazzoni
2016-03-09 22:58 ` [Buildroot] [PATCH v7 07/18] package/pkgconf: make the pkg-config wrapper relocatable Samuel Martin
2016-03-10 20:53 ` Thomas Petazzoni
2016-03-10 21:33 ` Peter Korsgaard
2016-03-09 22:58 ` [Buildroot] [PATCH v7 08/18] support/scripts: add fix-rpath script + a bunch of helpers Samuel Martin
2016-03-09 22:58 ` [Buildroot] [PATCH v7 09/18] core: add HOST_SANITIZE_RPATH_HOOK to TARGET_FINALIZE_HOOKS Samuel Martin
2016-03-09 22:58 ` [Buildroot] [PATCH v7 10/18] core: add {TARGET, STAGING}_SANITIZE_RPATH_HOOK " Samuel Martin
2016-03-09 22:58 ` [Buildroot] [PATCH v7 11/18] package/speex: remove no longer needed hook Samuel Martin
2016-03-09 22:58 ` [Buildroot] [PATCH v7 12/18] toolchain: add post-install hooks making the toolchain relocatable Samuel Martin
2016-03-09 22:58 ` [Buildroot] [PATCH v7 13/18] support/scripts: update check-host-rpath to use the shell helpers Samuel Martin
2016-03-09 22:58 ` [Buildroot] [PATCH v7 14/18] support/scripts/check-host-rpath: silent find command Samuel Martin
2016-03-10 0:15 ` Arnout Vandecappelle
2016-03-09 22:58 ` [Buildroot] [PATCH v7 15/18] support/scripts/check-host-rpath: also check HOST_DIR/{bin, sbin} Samuel Martin
2016-03-10 0:16 ` Arnout Vandecappelle
2016-03-09 22:58 ` [Buildroot] [PATCH v7 16/18] support/scripts: add check-host-leaks script + all needed helpers Samuel Martin
2016-03-27 22:38 ` Arnout Vandecappelle
2016-03-09 22:58 ` [Buildroot] [PATCH v7 17/18] core: add check-leaks-in-{target, host, staging} targets Samuel Martin
2016-03-09 22:58 ` [Buildroot] [PATCH v7 18/18] docs/manual: document how to debug shell script Samuel Martin
2016-03-10 0:21 ` Arnout Vandecappelle
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1457564339-27294-4-git-send-email-s.martin49@gmail.com \
--to=s.martin49@gmail.com \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox