diff options
| author | Richard Purdie <richard.purdie@linuxfoundation.org> | 2024-08-13 05:16:38 -0700 |
|---|---|---|
| committer | Steve Sakoman <steve@sakoman.com> | 2024-11-11 06:19:18 -0800 |
| commit | 2252b53ac6ddae74bf2430ced32da6da740e2a2d (patch) | |
| tree | f0fcb5b8dec539deba58a8af8870c6600ebdc709 /meta/classes | |
| parent | 249617857b17761b11a58b27caa336e0a0481e55 (diff) | |
| download | poky-2252b53ac6ddae74bf2430ced32da6da740e2a2d.tar.gz | |
cve_check: Use a local copy of the database during builds
Rtaher than trying to use a sqlite database over NFS from DL_DIR, work from
a local copy in STAGING DIR after fetching.
(From OE-Core rev: 9b6363994e5715f1d08b98956befd8915c128e85)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 03596904392d257572a905a182b92c780d636744)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta/classes')
| -rw-r--r-- | meta/classes/cve-check.bbclass | 7 |
1 files changed, 4 insertions, 3 deletions
diff --git a/meta/classes/cve-check.bbclass b/meta/classes/cve-check.bbclass index dd9847f366..ac13b0a863 100644 --- a/meta/classes/cve-check.bbclass +++ b/meta/classes/cve-check.bbclass | |||
| @@ -25,8 +25,9 @@ | |||
| 25 | CVE_PRODUCT ??= "${BPN}" | 25 | CVE_PRODUCT ??= "${BPN}" |
| 26 | CVE_VERSION ??= "${PV}" | 26 | CVE_VERSION ??= "${PV}" |
| 27 | 27 | ||
| 28 | CVE_CHECK_DB_DIR ?= "${DL_DIR}/CVE_CHECK" | 28 | CVE_CHECK_DB_FILENAME ?= "nvdcve_2-2.db" |
| 29 | CVE_CHECK_DB_FILE ?= "${CVE_CHECK_DB_DIR}/nvdcve_2-2.db" | 29 | CVE_CHECK_DB_DIR ?= "${STAGING_DIR}/CVE_CHECK" |
| 30 | CVE_CHECK_DB_FILE ?= "${CVE_CHECK_DB_DIR}/${CVE_CHECK_DB_FILENAME}" | ||
| 30 | CVE_CHECK_DB_FILE_LOCK ?= "${CVE_CHECK_DB_FILE}.lock" | 31 | CVE_CHECK_DB_FILE_LOCK ?= "${CVE_CHECK_DB_FILE}.lock" |
| 31 | 32 | ||
| 32 | CVE_CHECK_LOG ?= "${T}/cve.log" | 33 | CVE_CHECK_LOG ?= "${T}/cve.log" |
| @@ -157,7 +158,7 @@ python do_cve_check () { | |||
| 157 | } | 158 | } |
| 158 | 159 | ||
| 159 | addtask cve_check before do_build | 160 | addtask cve_check before do_build |
| 160 | do_cve_check[depends] = "cve-update-nvd2-native:do_fetch" | 161 | do_cve_check[depends] = "cve-update-nvd2-native:do_unpack" |
| 161 | do_cve_check[nostamp] = "1" | 162 | do_cve_check[nostamp] = "1" |
| 162 | 163 | ||
| 163 | python cve_check_cleanup () { | 164 | python cve_check_cleanup () { |
