Commit Graph
1335 Commits
Author SHA1 Message Date
Castulo Martinez e63dc805cf Adding flag validation to the swupd build process
swupd supports global flags and supports local flags that are specific
to subcommands. Flags that are specific to subcommands can be reused in
a different subcommand. Global flags should be unique and should not be
reused as local flags to avoid conflicts.

This commit adds a bash script that checks that the flags currently used
in swupd are valid (have no conflicts with other flags from the same
command or with the global flags). This script will be run as part of
the build process so in case an invalid flag is found the build will be
stopped. Alternatively, the script can be used by developers to validate
a new flag during the implementation time.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-07-12 14:28:05 -07:00
Otavio Pontes 6bf50db9bf test: Add missing NULL parameter to run_command() call
Last parameter was missing on a run_command() call and tests were breaking for some specific configurations.

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-07-12 11:17:13 -07:00
Castulo Martinez a61eed9bb7 Fix bug in mirror-allow-http.bats test
This test is yielding different results depending on if it is being run
in a system that has a proxy set up o there is no proxy.
This is happening because when usnig a non existing  server, if
there is a proxy set up, the proxy does respond during curl
initialization instead of the specified server, which allows swupd to
initialize only to fail further down the process when requesting the MoM
to the server. If the system where the test is run doesn't have a proxy
set up, curl fails to initialize since it gets no reply from the server,
which causes swupd to fail initialization, so swupd exits earlier in the
process and with different exit code.

This commit fixes the ambiguity of the test by not checking for an exit
code explicitelly but only making sure it does get an error code.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-07-10 13:37:01 -07:00
Otavio Pontes 6e3a6fc238 bundle-add: Remove short option from skip-optional-bundles
Trying to keep the number of short options flags low to be used only for more common commands

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-07-08 13:58:24 -07:00
Otavio Pontes f337da5b9c bundleadd: Rename flag from optional to also-add
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-07-08 13:58:24 -07:00
Castulo Martinez 079e02cc67 Running config file tests separatelly
Config files cannot be isolated to a test environment, they are system
wide, so those tests need to be run separatelly so they don't interfere
with other tests.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-07-08 13:03:18 -07:00
Lucius Hu 95f3e5e8e6 Fixed: Correctly show installed bundles
This fixed the `zsh` completion.

Previously some installed bundles are not shown for
`swupd bundle-remove` and `swupd diagnose --bundles=`,
it is fixed.
2019-07-08 09:35:58 -07:00
Castulo Martinez 515c7c71fe Checking mirror status only if necessary
When doing an update, we check to see if a mirror is stale, this only
needs to be done if there is a mirror set and if the upstream server is
up and reachable.

This commit checks to see if a mirror is set and there is an upstream
server to compare against, and only then it checks to see if it is stale.

Closes #922

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-07-03 16:10:46 -07:00
Otavio Pontes 659d12aa82 test: Fix typo in test
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-07-03 15:05:42 -07:00
Castulo Martinez c5ba016331 bundle-add skips optional bundles if specified
Swupd will install optional bundles on bundle-add by default,
but will skip them if specified by the user by using the
--skip-optional / -o flag..

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-07-03 14:59:47 -07:00
Castulo Martinez 9924bf7ee2 bundle-add installs optional bundles by default
An optional bundle is not required to be installed in the system while
included bundles are. Swupd will install optional bundles on bundle-add
by default.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-07-03 14:59:47 -07:00
Castulo Martinez afc27768bd Parse optional bundles in manifests
This commit adds the ability to the manifest parser to recognize the
"optional" manifest header and to add those optional bundles in the
manifest to the manifest struct.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-07-03 14:59:47 -07:00
Otavio Pontes d8fa2fc9bc doc: Add security report information
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-07-02 09:44:34 -07:00
Castulo Martinez 2f45cf4c55 Warn user setting mirror to http
If a user sets a mirror that uses http, it is going to cause autoupdates
to stop working since autoupdate would need the --allow-insecure-http
flag to continue with the insecure connection. In order for autoupdate
to work the user will need to add the key/value allow-insecure-http=true
in the swupd config file.

This commit warns the user about this when setting up a mirror with http
so they can take steps to re-enable autoupdate.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-07-01 17:18:50 -07:00
Castulo Martinez a9acd78753 Wait until the config file is deleted in tests
When running tests that use the config file, it is important to make
sure the config file from the previous test is deleted before the next
test is run. This is necessary since config files are not contained to
the test environment of each test as the rest of the test resources. So
a config file from one test can affect the output of another test if we
don't wait.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-07-01 16:28:26 -07:00
Otavio Pontes 4e1968165e test: Adding extra allow-insecure-http tests
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-07-01 16:12:08 -07:00
Otavio Pontes db7701bf73 test: Use https instead of http on mirror tests
This tests aren't testing the insecure http flag, so prefer to use https here

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-07-01 16:12:08 -07:00
Otavio Pontes ac210d375d test: Remove a swupd option specific for mirror
We shouldn't use a swupd without setting without -S and there's no reason to
have a custom option for mirror anymore

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-07-01 16:12:08 -07:00
Otavio Pontes feeab71614 test: Fix test description
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-07-01 14:33:30 -07:00
Otavio Pontes 9fe500d038 docs: Add document explaining how we do signature verification on swupd
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-06-28 15:52:16 -07:00
Otavio Pontes 9a8fffa7ff test: Sorting tests by name in Makefile.am
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-06-28 14:49:13 -07:00
Otavio Pontes cf92789ca6 test: Add a key rotation test
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-06-28 14:49:13 -07:00
Otavio Pontes 8068e3e422 testlib: Improve udpate_bundle --add command
When --add is used on update_bundle we can inform the file to be installed in
the system. But the function doesn't rename the file to the correct name, using
the file hash and it doesn't create the tarball automatically. That's because
it wasn't needed for other usages of --add. But not we are willing to add files
that were not present in content, so adding a feature to rename the file to
the correct hash and to create the tarball if it didn't exist.

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-06-28 14:49:13 -07:00
Otavio Pontes 57cf54a6fb test: Adding certificate chain signature checks
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-06-28 14:49:13 -07:00
Otavio Pontes ccbf2620b5 test: Adding signature checking tests
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-06-28 14:49:13 -07:00
Castulo Martinez c2a4763ff3 Adding configuration file parser for swupd
swupd has many flags that can be used for fine tunning its
functionality. In some cases users may want to include a flag with every
swupd command they run.

This commit gives the ability to provide swupd flags via options in a
configuration file that swupd will read before running the command.

The configuration file is an INI style file tha  can include sections
so users can specify options that should only apply to a specific
command. The biggest advantage of this is to be able to fine tune the
flags that should apply for each command.

For example a user could set a global flag that would apply to every
swupd command, and then turn that flag off for a specific command by
unsetting it in the command's section.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-28 13:06:11 -07:00
Otavio Pontes c3580e3f19 curl: Don't look at content_url and version_url on is_url_allowed() function
Instead of using the globals content_url and version_url in is_url_allowed()
we could use them in the function that calls it so is_url_allowed() is more
generic.
2019-06-28 09:17:13 -07:00
Castulo Martinez 468e00b275 Removing short option from --allow-insecure-http
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-27 16:24:46 -07:00
Castulo Martinez 43ba5def2a Require a force flag to continue with insecure URL
Currently users can set content and version urls based on http or https
protocols. This pose a security risk if users decide to use http.

This commit blocks swupd from working with http unless is specifically
allowed by using the --allow-insecure-http flag.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-27 14:48:50 -07:00
Castulo Martinez 91cc01bf14 Extract global flags to own variable in swupd.bash
This commit extracts all the global flags to its own "global" variable
in the swupd.bash script so it is easier to maintain.

The commit also fixes some inconsistencies with the flags in the script.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-27 14:48:50 -07:00
Arzhan Kinzhalin c07b47abc1 Prevent swupd from running interactive commands.
Replace stdin with /dev/null for children. This addresses the issue with
hangs when running update hooks which for whatever reason may expect
interactive input.
2019-06-25 15:56:50 -07:00
Arzhan Kinzhalin d9373b1709 Clean up. 2019-06-25 15:56:50 -07:00
Castulo Martinez ec9eeee4d0 Return correct code when bad path in picky-tree
When using "diagnose --picky --picky-tree /fake/path" swupd was exiting
with error code 34 (SWUPD_OUT_OF_MEMORY_ERROR) which was incorrect.

This commit fixes the issue by returning the correct code 29
(SWUPD_COULDNT_LIST_DIR) in those situations.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-25 15:51:29 -07:00
Castulo Martinez eb4872391e Make "clean" help consistent with other commands
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-25 15:51:00 -07:00
Castulo Martinez a5952aafdf Return correct code when current version unknown
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-25 15:50:37 -07:00
Castulo Martinez aa361c7d50 Consistency in global options help menu
Some of the global flags require a value and some do not. However when
printing the help for these global options, there is an inconsistency in
the way we display help, some of the flags that require values show that
they do require a value but some other do not. This makes it confusing.
This commit changes the help menu so all globals that require a value
show that they require it.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-25 15:50:05 -07:00
Castulo Martinez 5933267cea Fixes a bug when calculating the download size
To calculate the total download size of packs and fullfiles, swupd is
relying in a function that uses curl to request the server for the
download size of each file. However, when a file is not found in the
server, a size of 162 is returned by curl, which was causing the total
download size calculation to be wrong.

This commit fixes the issue by counting the file size returned by curl
only if the file exists.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-25 15:48:29 -07:00
Lucius Hu 1aaebc2751 Fixed typo in _swupd_bundle_add 2019-06-25 15:43:05 -07:00
Lucius Hu 94e10c679c zsh completion finished 2019-06-25 15:43:05 -07:00
Lucius Hu 67fffae295 Add zsh completion 2019-06-25 15:43:05 -07:00
Castulo Martinez 0cc96ed702 Adding a progress overflow protection
When reporting download progress, we should never have a percentage
bigger than 100%, but if for some reason we do (due to a bug), we don't
want that percentage slipping all the way to the end user.

This commit limits the percentage we display to 100 maximum.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-14 14:56:34 -07:00
Castulo Martinez c521417205 Including a few more cosmetic changes for "verify"
This commit adds a few more cosmetic changes to the commands that run
verify in the back for consistency.
- Different steps in the update process are separated by a blank line.
- Messages from swupd should not finish with a '.'

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-14 14:50:09 -07:00
Juro Bystricky 3233a7d9cb Makefile.am: add files to distribution
A compressed distribution tarball created via

$ make dist

is missing some files needed to run the standard
sequence of build commands:

$ ./configure
$ make
$ make check

In particular, when running "make check" we get:

../../test/unit/test_signature.c:9:10: fatal error: test_helper.h: No such file or directory
    9 | #include "test_helper.h"
      |          ^~~~~~~~~~~~~~~
compilation terminated.

This patch modifies the distribiton tarrball by adding files/folders:

1. test/unit/test_helper.h (to fix the above build error)
2. test/unit/data  (files reference by the test/unit/ binaries
3. test/functional (files referenced by Makefile)

With this patch "make check" reports:

Testsuite summary for swupd-client 3.20.0
============================================================================

Signed-off-by: Juro Bystricky <juro.bystricky@intel.com>
2019-06-13 09:33:33 -07:00
Castulo Martinez 7d295f3ec5 Fix the output when diagnosing a system
Currently when running diagnose, and a problem is found (a missing
file, a corrupt file, or an extraneous file), swupd shows the output
like this:

Verifying files
	...12%
Hash mismatch for file: /usr/bin/somefile
	...100%
Inspected 632545 files

So it splits the percentage that shows the progress of the action in two
lines. This commit fixes the output so it looks like this instead:

Checking for missing files
	...100%

Checking for corrupt files
 -> Hash mismatch for file: /usr/bin/mixer
 -> Hash mismatch for file: /usr/bin/mixin
 -> Hash mismatch for file: /usr/bin/swupd-extract
 -> Hash mismatch for file: /usr/bin/swupd-inspector
 -> Hash mismatch for file: /usr/share/zsh/site-functions/_mixer
	...100%

Checking for extraneous files
	...100%

Inspected 632545 files

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-06 15:37:21 -07:00
Castulo Martinez 4434fcb54d Split verification progress
This commit shows a more detailed progress report when diagnosing a
system.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-06 15:37:21 -07:00
Castulo Martinez eb579bcdae Adding a line break when reaching 100% in progress
This commit adds a line break at the end of the progress report (when we
reach 100%) so we don't have to manually include it every time we report
progress.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-06 15:37:21 -07:00
Castulo Martinez 0a205aa8c2 Add full path to swupd binary before re-update
When swupd is updating a system and it has to go over a format bump, the
update is run twice. First to get to the lower boundary of the format
bump and then it run again to go from the upper boundary of the format
bump to the desired version.
The second time the update was being run, swupd was being executed without
considering the environment, so the PATH variable was not being read,
this was causing swupd to fail to re execute itself for the second
update unless the user had run swupd specifying the full path in the
first place.

This commit fixes the issue by resolving the full path to swupd before
re executing itself.

Closes #942
2019-06-05 18:15:41 -07:00
Castulo Martinez b634f09d7d Fix download progress for fullfiles
When the download progress of fullfiles was being calculated it was
being done considering as if the files were being downloaded serially
not in parallel. This was causing an error in the calculation of the
download progress.

This commit fixes the issue by considering the files are being downloaded
in parallel when calculating the download progress.

Closes #939

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-06-05 23:19:10 +00:00
Otavio Pontes 1272040876 bundle-list: local bundle list should work without root
When we changed the init swupd function we stopped supporting bundle-list as root.
Adding this back on.
2019-05-31 19:35:33 +00:00
Otavio Pontes 230e3e5744 Add missing file to Manifest 2019-05-31 09:35:27 -07:00