diff mbox series

[meta-security,15/15] aide: Fix unstable install task hash

Message ID 0339b65f63877ed36fcffa44953e57c3bb969ca9.1787777775.git.scott.murray@konsulko.com
State New
Headers show
Series Assorted updates 08/26 | expand

Commit Message

Scott Murray Aug. 26, 2026, 8:57 p.m. UTC
From: Esa Jaaskela <esa.jaaskela@suomi24.fi>

The installation task hash for the aide is marked as nostamp. This is
done because the native task installs files outside the sysroot, to the
Aide staging directory. Those files are not captured by
do_populate_sysroot, so they are missing whenever the task is skipped or
restored from sstate.

Install the required native contents to the sysroot, and then customise
and deploy the configuration file in the aide_init_db rootfs postprocess
function that utilizes the files. The configuration file needs to be
reset every time the function is run to avoid using stale
configurations.

Staging the native files through the sysroot makes the nostamp
unnecessary, so remove it along with the unstable task hash it caused.

Signed-off-by: Esa Jaaskela <esa.jaaskela@suomi24.fi>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
 classes/aide-db-init.bbclass    | 11 +++++++++--
 recipes-ids/aide/aide_0.19.3.bb | 13 ++++---------
 2 files changed, 13 insertions(+), 11 deletions(-)
diff mbox series

Patch

diff --git a/classes/aide-db-init.bbclass b/classes/aide-db-init.bbclass
index 800006f..3fe2c27 100644
--- a/classes/aide-db-init.bbclass
+++ b/classes/aide-db-init.bbclass
@@ -31,6 +31,13 @@ 
 inherit aide-base 
 
 aide_init_db() {
+    install -d ${STAGING_AIDE_DIR}/lib/logs
+    rm -f ${STAGING_AIDE_DIR}/aide.conf ${STAGING_AIDE_DIR}/lib/aide.db ${STAGING_AIDE_DIR}/lib/aide.db.gz ${STAGING_AIDE_DIR}/lib/logs/aide.log
+    install ${STAGING_DATADIR_NATIVE}/aide/aide.conf ${STAGING_AIDE_DIR}/
+
+    sed -i -s "s:\@\@define DBDIR.*:\@\@define DBDIR ${STAGING_AIDE_DIR}/lib:" ${STAGING_AIDE_DIR}/aide.conf
+    sed -i -e "s:\@\@define LOGDIR.*:\@\@define LOGDIR ${STAGING_AIDE_DIR}/lib/logs:" ${STAGING_AIDE_DIR}/aide.conf
+
     for dir in ${AIDE_INCLUDE_DIRS}; do
         echo "${IMAGE_ROOTFS}${dir} NORMAL" >> ${STAGING_AIDE_DIR}/aide.conf
     done
@@ -39,7 +46,7 @@  aide_init_db() {
     done
 
 
-    ${STAGING_AIDE_DIR}/bin/aide -c ${STAGING_AIDE_DIR}/aide.conf --init
+    ${STAGING_BINDIR_NATIVE}/aide -c ${STAGING_AIDE_DIR}/aide.conf --init
     gunzip ${STAGING_AIDE_DIR}/lib/aide.db.gz 
     # strip out native path
     sed -i -e 's:${IMAGE_ROOTFS}::' ${STAGING_AIDE_DIR}/lib/aide.db
@@ -47,6 +54,6 @@  aide_init_db() {
     cp -f ${STAGING_AIDE_DIR}/lib/aide.db.gz ${IMAGE_ROOTFS}${libdir}/aide
 }
 
-EXTRA_IMAGEDEPENDS:append = " aide-native"
+do_rootfs[depends] += "aide-native:do_populate_sysroot"
 
 ROOTFS_POSTPROCESS_COMMAND:append = " aide_init_db;"
diff --git a/recipes-ids/aide/aide_0.19.3.bb b/recipes-ids/aide/aide_0.19.3.bb
index 8d4efbb..c352583 100644
--- a/recipes-ids/aide/aide_0.19.3.bb
+++ b/recipes-ids/aide/aide_0.19.3.bb
@@ -32,8 +32,6 @@  PACKAGECONFIG[e2fsattrs] = "--with-e2fsattrs, --without-e2fsattrs, e2fsprogs, e2
 PACKAGECONFIG[capabilities] = "--with-capabilities, --without-capabilities, libcap, libcap"
 PACKAGECONFIG[posix-acl] = "--with-posix-acl, --without-posix-acl, acl, acl"
 
-do_install[nostamp] = "1"
-
 do_install:append () {
     install -d ${D}${libdir}/${PN}/logs   
     install -d ${D}${sysconfdir}   
@@ -48,14 +46,11 @@  do_install:append () {
 }
 
 do_install:class-native () {
-    install -d ${STAGING_AIDE_DIR}/bin
-    install -d ${STAGING_AIDE_DIR}/lib/logs
-
-    install ${B}/aide ${STAGING_AIDE_DIR}/bin
-    install ${UNPACKDIR}/aide.conf ${STAGING_AIDE_DIR}/
+    install -d ${D}${bindir}
+    install -d ${D}${datadir}/${BPN}
 
-    sed -i -s "s:\@\@define DBDIR.*:\@\@define DBDIR ${STAGING_AIDE_DIR}/lib:" ${STAGING_AIDE_DIR}/aide.conf
-    sed -i -e "s:\@\@define LOGDIR.*:\@\@define LOGDIR ${STAGING_AIDE_DIR}/lib/logs:" ${STAGING_AIDE_DIR}/aide.conf
+    install ${B}/aide ${D}${bindir}
+    install ${UNPACKDIR}/aide.conf ${D}${datadir}/${BPN}/
 }
 
 CONF_FILE = "${sysconfdir}/aide.conf"