[1/1] avoid use of bitbake syntax for argument variables

Message ID 20260928104852.2449161-1-felix.moessbauer@siemens.com
State New
Headers show
Series [1/1] avoid use of bitbake syntax for argument variables | expand

Commit Message

Felix Moessbauer Sept. 28, 2026, 10:48 a.m. UTC
When using bitbake syntax to access argument variables (e.g. ${1}),
the reference to the variable ends up in the signatures (with an empty
value, as this is never set by bitbake). This is dangerous, as if this
ever is assigned by bitbake, it will break all scripts in the same
context. In addition, the entries (just '1') end up in the cache
signatures - which is ugly but has no other negative impact (yet).

Instead, we now access these variables in shell-style ($1) and also drop
the not needed quotes on assigments (in POSIX shell, the right part of an
assignment does split words).

Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
 meta/classes-recipe/deb-dl-dir.bbclass         |  8 ++++----
 meta/classes-recipe/repository.bbclass         | 10 +++++-----
 meta/classes-recipe/rootfs.bbclass             | 18 +++++++++---------
 meta/classes-recipe/sbuild.bbclass             |  6 +++---
 meta/recipes-devtools/base-apt/base-apt.bb     |  2 +-
 .../linux/files/debian/isar/common.tmpl        |  2 +-
 .../linux/files/debian/isar/install.tmpl       |  4 ++--
 7 files changed, 25 insertions(+), 25 deletions(-)

Patch

diff --git a/meta/classes-recipe/deb-dl-dir.bbclass b/meta/classes-recipe/deb-dl-dir.bbclass
index 60e2fecc..bafe3a63 100644
--- a/meta/classes-recipe/deb-dl-dir.bbclass
+++ b/meta/classes-recipe/deb-dl-dir.bbclass
@@ -115,8 +115,8 @@  dbg_pkgs_download() {
 }
 
 deb_dl_dir_import() {
-    export pc="${DEBDIR}/${2}"
-    export rootfs="${1}"
+    export pc=${DEBDIR}/$2
+    export rootfs=$1
     export uid=$(id -u)
     export gid=$(id -g)
 
@@ -151,8 +151,8 @@  deb_dl_dir_import() {
 }
 
 deb_dl_dir_export() {
-    export pc="${DEBDIR}/${2}"
-    export rootfs="${1}"
+    export pc=${DEBDIR}/$2
+    export rootfs=$1
     export owner=$(id -u):$(id -g)
     mkdir -p "${pc}"
 
diff --git a/meta/classes-recipe/repository.bbclass b/meta/classes-recipe/repository.bbclass
index d255d1c8..b9097de5 100644
--- a/meta/classes-recipe/repository.bbclass
+++ b/meta/classes-recipe/repository.bbclass
@@ -122,7 +122,7 @@  repo_del_package() {
         export GNUPGHOME="${GNUPGHOME}"
     fi
     set -- $( dpkg-deb --show --showformat '${Package} ${Architecture}' "${file}" )
-    local p="${1}" a="${2}"
+    local p=$1 a=$2
     reprepro -b "${dir}" --dbdir "${dbdir}" -C main \
         removefilter "${codename}" \
         'Package (= '${p}'), Architecture (= '${a}'), $PackageType (= deb)'
@@ -169,15 +169,15 @@  repo_contains_package() {
     package=$(reprepro -b ${dir} --dbdir ${dbdir} \
                        --list-format '${$fullfilename}\n' \
                        listfilter ${codename} '
-                           Package (= '${2}'),
-                           Version (= '${4}'),
-                           Architecture (= '${6}'),
+                           Package (= '$2'),
+                           Version (= '$4'),
+                           Architecture (= '$6'),
                            $PackageType (= deb)')
 
     # we only need the first match (should there be more). Use shell builtins to avoid
     # spawning an additional process (e.g. "head")
     set -- ${package}
-    package="${1}"
+    package=$1
 
     # package found in the database?
     if [ -n "$package" ]; then
diff --git a/meta/classes-recipe/rootfs.bbclass b/meta/classes-recipe/rootfs.bbclass
index 83cd56ea..e957566a 100644
--- a/meta/classes-recipe/rootfs.bbclass
+++ b/meta/classes-recipe/rootfs.bbclass
@@ -118,31 +118,31 @@  rootfs_cmd() {
     bwrap_binds=""
     bwrap_rootfs=""
 
-    while [ "${#}" -gt "0" ] && [ "${1}" != "--" ]; do
-        case "${1}" in
+    while [ "${#}" -gt "0" ] && [ "$1" != "--" ]; do
+        case "$1" in
             --bind)
                 if [ "${#}" -lt "3" ]; then
                     bbfatal "--bind requires two arguments"
                 fi
-                bwrap_binds="${bwrap_binds} --bind ${2} ${3}"
+                bwrap_binds="${bwrap_binds} --bind $2 $3"
                 shift 3
                 ;;
             --chdir)
                 if [ "${#}" -lt "2" ]; then
-                    bbfatal "${1} requires an argument"
+                    bbfatal "$1 requires an argument"
                 fi
-                bwrap_args="${bwrap_args} ${1} ${2}"
+                bwrap_args="${bwrap_args} $1 $2"
                 shift 2
                 ;;
             -*)
-                bbfatal "${1} is not a supported option!"
+                bbfatal "$1 is not a supported option!"
                 ;;
             *)
                 if [ -z "${bwrap_rootfs}" ]; then
-                    bwrap_rootfs="${1}"
+                    bwrap_rootfs="$1"
                     shift
                 else
-                    bbfatal "unexpected argument '${1}'"
+                    bbfatal "unexpected argument '$1'"
                 fi
                 ;;
         esac
@@ -152,7 +152,7 @@  rootfs_cmd() {
         bwrap_args="${bwrap_args} --bind ${bwrap_rootfs} /"
     fi
 
-    if [ "${#}" -le "1" ] || [ "${1}" != "--" ]; then
+    if [ "${#}" -le "1" ] || [ "$1" != "--" ]; then
         bbfatal "no command specified (missing --)"
     fi
     shift  # remove "--", command and its arguments follows
diff --git a/meta/classes-recipe/sbuild.bbclass b/meta/classes-recipe/sbuild.bbclass
index 6db29251..f2916931 100644
--- a/meta/classes-recipe/sbuild.bbclass
+++ b/meta/classes-recipe/sbuild.bbclass
@@ -82,7 +82,7 @@  sbuild_add_env_filter() {
         echo "];" >> ${SBUILD_CONFIG}
     fi
 
-    FILTER=${1}
+    FILTER=$1
 
     sed -i -e "/'\^${FILTER}\\$/d" \
         -e "/^\$environment_filter =.*/a '^${FILTER}\$'," ${SBUILD_CONFIG}
@@ -96,7 +96,7 @@  sbuild_export() {
         echo "};" >> ${SBUILD_CONFIG}
     fi
 
-    VAR=${1}; shift
+    VAR=$1; shift
     VAR_LINE="'${VAR}' => '${@}',"
 
     sed -i -e "/^'${VAR}' =>/d" ${SBUILD_CONFIG} \
@@ -155,7 +155,7 @@  EOF
 }
 
 sbuild_dpkg_log_export() {
-    export dpkg_partial_log="${1}"
+    export dpkg_partial_log=$1
 
     ( flock 9
     set -e
diff --git a/meta/recipes-devtools/base-apt/base-apt.bb b/meta/recipes-devtools/base-apt/base-apt.bb
index 06b1f6c8..97e3ae16 100644
--- a/meta/recipes-devtools/base-apt/base-apt.bb
+++ b/meta/recipes-devtools/base-apt/base-apt.bb
@@ -13,7 +13,7 @@  KEYFILES ?= ""
 BASE_REPO_FEATURES ?= ""
 
 populate_base_apt() {
-    base_distro="${1}"
+    base_distro=$1
 
     find "${DEBDIR}"/"${base_distro}-${BASE_DISTRO_CODENAME}" -name '*\.deb' | while read package; do
         # NOTE: due to packages stored by reprepro are not modified, we can
diff --git a/meta/recipes-kernel/linux/files/debian/isar/common.tmpl b/meta/recipes-kernel/linux/files/debian/isar/common.tmpl
index 72d3e428..b7001ff5 100644
--- a/meta/recipes-kernel/linux/files/debian/isar/common.tmpl
+++ b/meta/recipes-kernel/linux/files/debian/isar/common.tmpl
@@ -47,7 +47,7 @@  deb_kern_kbuild_cross_dir=${deb_top_dir}/${KERNEL_PKG_KERN_KBUILD_CROSS}
 declare -A kern_pkgs
 
 main() {
-    local target=${1}
+    local target=$1
 
     if [ ! -f ${S}/debian/isar/${target} ]; then
         echo "error: ${target} is not a supported build target!" >&2
diff --git a/meta/recipes-kernel/linux/files/debian/isar/install.tmpl b/meta/recipes-kernel/linux/files/debian/isar/install.tmpl
index 4c28ecc6..7975404b 100644
--- a/meta/recipes-kernel/linux/files/debian/isar/install.tmpl
+++ b/meta/recipes-kernel/linux/files/debian/isar/install.tmpl
@@ -6,7 +6,7 @@ 
 . ${S}/debian/isar/common
 
 get_kernel_arch() {
-    case "${1}" in
+    case "$1" in
         amd64|i386) echo "x86";;
         arm64) echo "arm64";;
         armhf) echo "arm";;
@@ -255,7 +255,7 @@  install_headers() {
 
 install_kbuild() {
     kernel_kbuild_dir=usr/lib/linux-kbuild-${krel}
-    destdir=${1}/${kernel_kbuild_dir}
+    destdir=$1/${kernel_kbuild_dir}
     src_kbuild_files=$(mktemp)
     obj_kbuild_files=$(mktemp)