This release fixes several errant return codes, adds progress status for
long-running tasks, ensures the swupd state directory is created and is
owned by root at runtime, fixes --format arg validation, and enforces
format transitions for verify.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When using verify's -m option, it generally only makes sense to verify a
build within the same format, since the subsequent format (if any) might
not be compatible. Therefore, we should disallow verifying to a build
with a different format by default. This commit adds the proper
enforcement by making this condition a fatal error. The early exit can
be bypassed using the -x/--force option, which will print a warning
message instead.
For now, this compatibility check is targeting the use case of verifying
to a newer build, so I also report the latest supported build for the
current format. Verifying to an older build is not guaranteed to succeed
at present, and swupd-client does not yet understand the
version/formatN/first file. In other words, reporting to the user the
oldest build they can verify to will be a future improvement.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
strtoull succeed when the leading characters of the input form a valid
number, so it is necessary to verify that there is no trailing
characters. Use the endptr parameter (that will point to the end of
the accepted input) to verify that.
Fixes#142.
Signed-off-by: Caio Marcelo de Oliveira Filho <caio.oliveira@intel.com>
Since this step can take a while print a header to give an indication of
what the progress percentage is tracking. Update functional tests to
include new output.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Instead of printing the progress percentage for every update,
potentially hundreds of thousands of times, only print when the
percentage changes.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add a progress indication for redirected output such as for logging,
testing, or third-party software such as ister.
For every 10 files or steps completed a dot (".") is printed to the
screen.
Adds a few more progress indications for silent loops.
Also adds leading newlines to some existing print statements so they are
printed on their own line.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add a basic progress indication for a couple potentially long-running
swupd tasks (download_pack and add_missing_files). The progress
indication is displayed as a percentage:
...85%
It overwrites its own line so the progress will update in place. It may
be interrupted by other swupd output:
...45%
Extracting os-core pack for version 10000
...50%
Extracting os-core-update pack for version 9000
...55%
The progress indication will then resume updating in place, on the same
line.
This progress is only displayed when outputting to a TTY, and will not
output anything when the output is being redirected. This is nice for
testing and logging, but means that these progress updates will not be
caught by processes that capture swupd output, such as ister.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
As the state_dir (normally /var/lib/swupd) contains things like the
downloaded bundles, it is important that there is no access to
non-root users who could potentially explot races to replace files
between them being checked and them being installed.
Ensure that the state_dir is root owned, and mode 0700, as well as the
critical directories below it.
Note that a proper fix would involve using chdir to move into the
directory and only use relative paths. This would prevent faulty
permissions higher up the directory tree being exploited. It *might*
be possible to use openat(2) to prevent this exploitation.
Add a test to ensure that the enforcement is taking place.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Instead of returning the direct error code from the system() call to
re-exec swupd update, return a predictable 0 or 1. System was previously
returning 255 (out of range) when failing to re-exec swupd.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When supplying the --download flag, return a success status instead of
-1, which was returned to short-circuit some following code in the main
update path. Use conditionals on the previously short-circuited code
instead.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
It is not necessary to go through the whole swupd initiation process a
second time when listing bundles from the server. This also allows us to
set the correct exit status on the early exit.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Adds status checks for each swupd command called in the functional
tests. At this point several of these tests fail due to some successful
commands returning error statuses.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Check that the simple test server in the checkupdate/slow-server/ test
is available before actually running the swupd command. This check is
done by testing the return status of a curl command on the server up to
ten times until successful.
Since this is an historically touchy test, output an additional
debug.log in the test directory with much more verbose logging (using
set -x).
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release fixes hashdump invocation in the bsdiff testsuite, sorts the
bundle-list output, provides better error codes to differentiate between
various early network failures, and enables client to automatically re-update
itself (or perform any other actions) if stated to in the Manifest.MoM.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Instead of allowing only one "actions:" field in the Manifest.MoM, allow
for several and read each into the post_udpate_actions list. This allows
us to add more actions down the road if desired.
Currently the only use for the "actions:" field is to indicate when a
re-update is required. This is handled by checking if the string
"update" is in the post_update_actions list.
Finally, remove the warning to the user to perform the post update
action themselves, as this will be handled by swupd itself. Functional
tests updated to reflect the missing output.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Adds a check to compare version numbers in <state_dir>/version and
<target_dir>/usr/lib/os-release when attempting to re-update after a
format bump.
os-release should always be equal to <state_dir>/version for normal
updates and potentially greater than <state_dir>/version for format
bumps.
In the event of a bad build where os-release does not get updated to the
new version, this check will prevent an infinite loop where swupd reads
the current version from os-release, sees it is out of date, attempts to
update again, but the file does not get updated.
This occasion is very unlikely but the guard is nice to have
re(guard)less.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When a device is out of date by more than a format bump re-exec swupd
update until the device version matches the server version. This is
achieved by reading the "actions" field in the Manifest.MoM, which is
yet to be implemented in swupd-server. When "update" is specified in the
actions of the current manifest and the current update is successful,
swupd will re-exec itself with the same flags it was originally called
with.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
We draw a hard line with error codes, such that:
Error code 16 is reserved for failures resulting from the basic
network check. Any call to check_network() that fails will
return this error code. No other error path returns this
error code.
Additionally, check_network() is called in every normal code path.
All other, possibly network related issues, return a different
error code. If the basic network check succeeds, but e.g. pack
downloads fail, we return a new (23) error code so that we
can better establish the conditions through telemetry and
determine whether the error is on the client or the server,
which is highly likely with this new error code 23.
The --basepath option for hashdump was renamed to --path a while back,
so fix up the creatediffs script accordingly.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release adds the --picky option to the verify --fix subcommand, making
verify --fix actually remove files not tracked under /usr instead of just
reporting them.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This is the basic implementation for a "factory reset" type of command.
It will take the functionality of verify --picky and act on the files found
as verify --fix does with files found mismatching in the manifest.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This release introduces the verify --picky subcommand, which lists files under
/usr, a new subcommand "autoupdate" which allows for easy enable/disable
of autoupdates and its current status, and converts printfs to fprintf to
stderr throughout the code as appropriate.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Add a "swupd verify --picky" command which lists files under
/usr (modified by the --path option) which are not listed in the
current manifest. Exceptions /usr/local and /usr/lib/modules. The
former to allow for local changes, the latter because the clear boot
manager owns that directory.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Write error and informative messages to stderr, only
write data to stdout so it can be piped to other programs.
Make stdout line buffered, rather than introduce race conditions into tests
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
This release fixes a bug in signature verification retries, and adds support
to client so it understands a new manifest header field called "action." The
new field will allow client to detect if more actions need to be taken after
an update, i.e run verify --fix.
Signe-off-by: Tudor Marcu <tudor.marcu@intel.com>
The update process should only read in post update action from the newest
MoM. This makes it so that even with a previous MoM having an action, only
the new one will be taken, and if none exist, the old one will be ignored
so swupd will not take the same action as the previous update.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The swupd client should support parsing extra data in the case that a format
bump occurred, or other possibly breaking change, so that it can at least
notify the user of more action needing to be taken post update.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Unlike the regular manifest loading code, loading a MoM also requires signature
verification to succeed. We cannot reset the retries after a signature
failed because the manifest may load fine, but still fail verification,
resulting in endlessly loading and verifying the Manifest.MoM
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This release adds retries to pack downloads for bundle-add. The downloads
could fail if network connectivity is lost, which drops the code into a
slower download path. Instead, attempt to retry pack downloads to stay on
the optimal code path before finally dropping into the fullfile fallback.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The download_subscribed_packs() could fail for network issues or other related
problems, and because the only option for getting new packs is by downloading
zero packs or fullfiles, swupd should retry to get the packs before falling
into the verify_fix_path flow which signifies pack downloads errored out.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This release fixes a subtle bug in try_delta_manifest_download() that would
incorrectly set the file struct causing hashes to become incorrect. It further
fixes problems in the retry path, in which it would loop continuously until
it was able to load a correct manifest.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The update code did not jump to the correct points when it needed to retry,
causing swupd to run into infinite loops if it could not load a given manifest
at all.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The new file struct cannot be populated using the original because it will
contain attributes and data that may not match the new file, breaking hash
computation. We must freshly populate the struct with the new file only
after bsdiff application succeeds, and then compute hash to ensure all data
is indeed from the new file. It is also irrelevant to precompute the hash
before attempting to apply the delta, so we remove that code block
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This release fixes incorrect download messages printing for packs, validation
for the format number supplied to the binary, and enables delta file
application for manifests. Manifest deltas can be more than 150 times smaller
than the full file tar, saving time on updates by downloading much less data.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The tarfiles should not be kept after swupd runs, so check for the fullfile
instead and skip having to extract it.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
If there is no peer or we cannot get a delta, quit and don't mess with the
file struct. Pre-populating the file struct then exiting early corrupts the
manifest list for later operations, and is a noop when the file cannot be
found to begin with. If there is no peer, it likely is a new manifest and
thus a delta cannot exist.
Should the delta application succeed, we MUST compute and set the new hash
for the file else it will retain the hash of the previous version, and not
pass hash check.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>