New issue
Advanced search Search tips

Issue 660403 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Oct 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug



Sign in to add a comment

New added CHROMEOS_RELEASE_BUILDER_PATH in lsb-release cannot stay in signed image

Project Member Reported by xixuan@chromium.org, Oct 28 2016

Issue description

Regarding on  crbug.com/634642  and  crbug.com/471906 , a new CHROMEOS_RELEASE_BUILDER_PATH is added in lsb-release, whose format is like:

peppy-release/R42-6802.0.0.

Don suggests this line cannot be signed and shipped out.
 
Wait.... given our conversation, I thought the contents would be a GS URL.

IE, something like:

gs://chromeos-image-archive/peppy-release/R42-6802.0.0/stateful.tgz

Comment 2 by vapier@chromium.org, Oct 28 2016

regardless of the content, i don't see a problem here ?  these are sekrit URIs where the world will burn if they see them ... and we already have publicly mentioned/logged those in many places.
It just seemed dirty to be embedding transient URLs into the release version file.

Comment 4 by vapier@chromium.org, Oct 28 2016

while i tend to agree with the sentiment, i vaguely recall that we've had requests like this in the past ?  people want an easy way to track back images to builds.  i'm not suggesting we make this an ABI they can rely on, but for devs, it's a nice hand i think.

we can update the signer to strip out keys from lsb-release easily.  but i think having a few extra build related ones like this isn't necessarily a bad thing, and the overhead of a few bytes in this text file that is always changed anyways when a new build happens (since version #'s change) isn't a big deal.
Okay.

I do want to point out to Zixuan, only use that string to find a directory in chromeos-image-archive. You can't reliably extract the board name or software version from it, since there are special cases that can lead to very different formats. It is totally legit to get a string of the format:

foobar/1234

For a release build of peppy at version R42-6802.0.0.

Comment 6 by vapier@chromium.org, Oct 28 2016

Labels: -Restrict-View-Google Type-Bug
Status: WontFix (was: Assigned)

Sign in to add a comment