summaryrefslogtreecommitdiffstats
path: root/meta/classes
diff options
context:
space:
mode:
authorDouglas Royds <douglas.royds@taitradio.com>2018-12-21 12:10:22 +1300
committerRichard Purdie <richard.purdie@linuxfoundation.org>2019-01-11 10:39:08 +0000
commitc3a244b792ca89f28048c1fec1d3e05112872ee0 (patch)
tree4f6f9b8389d6edaa496e35f77d8f97fd4e323357 /meta/classes
parent3049440b2834431c1d195bd5e4cf02eb978b5c42 (diff)
downloadpoky-c3a244b792ca89f28048c1fec1d3e05112872ee0.tar.gz
patch: reproducibility: Fix host umask leakage
Some patch files create entirely new files, so their permissions are subject to the host umask. If such a file is later installed into a package with no change in permissions, it breaks the reproducibility of the package. This was observed on libpam, for instance: The patch file pam-security-abstract-securetty-handling.patch creates a new file (tty_secure.c). This file is later copied into the -dbg package with no change in permissions. (From OE-Core rev: 2a2bbd755b330cd63f7f6e2f2b374a3ae065b37a) Signed-off-by: Douglas Royds <douglas.royds@taitradio.com> Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/classes')
-rw-r--r--meta/classes/patch.bbclass1
1 files changed, 1 insertions, 0 deletions
diff --git a/meta/classes/patch.bbclass b/meta/classes/patch.bbclass
index 3e0a181821..cd241f1c84 100644
--- a/meta/classes/patch.bbclass
+++ b/meta/classes/patch.bbclass
@@ -153,6 +153,7 @@ python patch_do_patch() {
153patch_do_patch[vardepsexclude] = "PATCHRESOLVE" 153patch_do_patch[vardepsexclude] = "PATCHRESOLVE"
154 154
155addtask patch after do_unpack 155addtask patch after do_unpack
156do_patch[umask] = "022"
156do_patch[dirs] = "${WORKDIR}" 157do_patch[dirs] = "${WORKDIR}"
157do_patch[depends] = "${PATCHDEPENDENCY}" 158do_patch[depends] = "${PATCHDEPENDENCY}"
158 159