443 Commits
Author SHA1 Message Date
Matthew Johnson a201a0c417 Release v3.11.0
This release fixes several errant return codes, adds progress status for
long-running tasks, ensures the swupd state directory is created and is
owned by root at runtime, fixes --format arg validation, and enforces
format transitions for verify.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.11.0
2017-08-30 16:52:59 -07:00
Patrick McCarty 485ab31f22 Add functional tests for verify format mismatch and override
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-08-30 11:12:50 -07:00
Patrick McCarty e6cdcf8aa1 verify: enforce format transitions
When using verify's -m option, it generally only makes sense to verify a
build within the same format, since the subsequent format (if any) might
not be compatible. Therefore, we should disallow verifying to a build
with a different format by default. This commit adds the proper
enforcement by making this condition a fatal error. The early exit can
be bypassed using the -x/--force option, which will print a warning
message instead.

For now, this compatibility check is targeting the use case of verifying
to a newer build, so I also report the latest supported build for the
current format. Verifying to an older build is not guaranteed to succeed
at present, and swupd-client does not yet understand the
version/formatN/first file. In other words, reporting to the user the
oldest build they can verify to will be a future improvement.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-08-30 11:12:50 -07:00
Patrick McCarty b682263c96 verify: remove misplaced tab in the help output
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-08-30 11:12:50 -07:00
Caio Marcelo de Oliveira Filho 4a6796c47f Don't accept trailing characters when validating numbers for --format
strtoull succeed when the leading characters of the input form a valid
number, so it is necessary to verify that there is no trailing
characters. Use the endptr parameter (that will point to the end of
the accepted input) to verify that.

Fixes #142.

Signed-off-by: Caio Marcelo de Oliveira Filho <caio.oliveira@intel.com>
2017-08-22 11:00:26 -07:00
Matthew Johnson 49ec50f3da Clean up code style
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-17 15:50:49 -07:00
Matthew Johnson d274f3aede Add "Applying update" print as a progress header
Since this step can take a while print a header to give an indication of
what the progress percentage is tracking. Update functional tests to
include new output.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-17 15:37:15 -07:00
Matthew Johnson 407767cc71 Only print progress when percentage changes
Instead of printing the progress percentage for every update,
potentially hundreds of thousands of times, only print when the
percentage changes.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-17 15:37:15 -07:00
Matthew Johnson 7f7e5b6416 Add progress updates for redirected output
Add a progress indication for redirected output such as for logging,
testing, or third-party software such as ister.

For every 10 files or steps completed a dot (".") is printed to the
screen.

Adds a few more progress indications for silent loops.

Also adds leading newlines to some existing print statements so they are
printed on their own line.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-17 15:37:15 -07:00
Matthew Johnson 43689e86d0 Add basic progress status for long-running tasks
Add a basic progress indication for a couple potentially long-running
swupd tasks (download_pack and add_missing_files). The progress
indication is displayed as a percentage:

...85%

It overwrites its own line so the progress will update in place. It may
be interrupted by other swupd output:

...45%
Extracting os-core pack for version 10000
...50%
Extracting os-core-update pack for version 9000
...55%

The progress indication will then resume updating in place, on the same
line.

This progress is only displayed when outputting to a TTY, and will not
output anything when the output is being redirected. This is nice for
testing and logging, but means that these progress updates will not be
caught by processes that capture swupd output, such as ister.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-17 15:37:15 -07:00
Icarus Sparry 3668fb5f7b Ensure state_dir is a directory and owned by root
As the state_dir (normally /var/lib/swupd) contains things like the
downloaded bundles, it is important that there is no access to
non-root users who could potentially explot races to replace files
between them being checked and them being installed.

Ensure that the state_dir is root owned, and mode 0700, as well as the
critical directories below it.

Note that a proper fix would involve using chdir to move into the
directory and only use relative paths. This would prevent faulty
permissions higher up the directory tree being exploited. It *might*
be possible to use openat(2) to prevent this exploitation.

Add a test to ensure that the enforcement is taking place.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-08-17 15:28:06 -07:00
Matthew Johnson 05930d60ec Return a predictable return code from re-exec
Instead of returning the direct error code from the system() call to
re-exec swupd update, return a predictable 0 or 1. System was previously
returning 255 (out of range) when failing to re-exec swupd.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-10 15:33:59 -07:00
Matthew Johnson 286eb6fe2d Return correct exit status from download-only
When supplying the --download flag, return a success status instead of
-1, which was returned to short-circuit some following code in the main
update path. Use conditionals on the previously short-circuited code
instead.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-10 15:33:59 -07:00
Matthew Johnson 85d775110e Fix grammar and spacing issues in error message.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-10 15:33:59 -07:00
Matthew Johnson c70cce7368 Exit early when listing installable bundles
It is not necessary to go through the whole swupd initiation process a
second time when listing bundles from the server. This also allows us to
set the correct exit status on the early exit.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-10 15:33:59 -07:00
Matthew Johnson ae011954f4 Add status checks for test swupd commands
Adds status checks for each swupd command called in the functional
tests. At this point several of these tests fail due to some successful
commands returning error statuses.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-10 15:33:59 -07:00
Matthew Johnson 2c9021289f Wait for test server to become available before testing
Check that the simple test server in the checkupdate/slow-server/ test
is available before actually running the swupd command. This check is
done by testing the return status of a curl command on the server up to
ten times until successful.

Since this is an historically touchy test, output an additional
debug.log in the test directory with much more verbose logging (using
set -x).

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-08 15:20:16 -07:00
Matthew Johnson 6f52e62854 Fix typo in clr_bundle_rm.c
succesfully -> successfully

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-07 14:23:30 -07:00
Tudor Marcu cc30de5081 Release v3.10.0
This release fixes hashdump invocation in the bsdiff testsuite, sorts the
bundle-list output, provides better error codes to differentiate between
various early network failures, and enables client to automatically re-update
itself (or perform any other actions) if stated to in the Manifest.MoM.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.10.0
2017-07-28 23:45:50 -07:00
Tudor Marcu e206d48b37 Cleanup codestyle
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-07-28 23:35:14 -07:00
Matthew Johnson 89af564256 Convert post_update_actions to list-based approach
Instead of allowing only one "actions:" field in the Manifest.MoM, allow
for several and read each into the post_udpate_actions list. This allows
us to add more actions down the road if desired.

Currently the only use for the "actions:" field is to indicate when a
re-update is required. This is handled by checking if the string
"update" is in the post_update_actions list.

Finally, remove the warning to the user to perform the post update
action themselves, as this will be handled by swupd itself. Functional
tests updated to reflect the missing output.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-07-28 23:19:54 -07:00
Matthew Johnson d6636d7814 Add functional test for re-update with bad os-release
Adds a functional test for swupd re-update when the os-release file does
not get updated.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-07-28 23:19:54 -07:00
Matthew Johnson 9b0701cf77 Add inconsistent version files check while re-updating
Adds a check to compare version numbers in <state_dir>/version and
<target_dir>/usr/lib/os-release when attempting to re-update after a
format bump.

os-release should always be equal to <state_dir>/version for normal
updates and potentially greater than <state_dir>/version for format
bumps.

In the event of a bad build where os-release does not get updated to the
new version, this check will prevent an infinite loop where swupd reads
the current version from os-release, sees it is out of date, attempts to
update again, but the file does not get updated.

This occasion is very unlikely but the guard is nice to have
re(guard)less.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-07-28 23:19:54 -07:00
Matthew Johnson 1d19db4bc1 Add funtional test for swupd re-update
Adds functional test for swupd re-execs over format bumps.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-07-28 23:19:54 -07:00
Matthew Johnson 0bc2cdb790 Re-execute swupd update for format bumps
When a device is out of date by more than a format bump re-exec swupd
update until the device version matches the server version. This is
achieved by reading the "actions" field in the Manifest.MoM, which is
yet to be implemented in swupd-server. When "update" is specified in the
actions of the current manifest and the current update is successful,
swupd will re-exec itself with the same flags it was originally called
with.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-07-28 23:19:54 -07:00
Auke Kok 22cccd9a04 Differentiate between various early network failures.
We draw a hard line with error codes, such that:

Error code 16 is reserved for failures resulting from the basic
network check. Any call to check_network() that fails will
return this error code. No other error path returns this
error code.

Additionally, check_network() is called in every normal code path.

All other, possibly network related issues, return a different
error code. If the basic network check succeeds, but e.g. pack
downloads fail, we return a new (23) error code so that we
can better establish the conditions through telemetry and
determine whether the error is on the client or the server,
which is highly likely with this new error code 23.
2017-07-20 16:18:33 -07:00
Arzhan Kinzhalin ee76eb3f16 Sort bundle-list output. 2017-07-17 15:49:28 -07:00
Patrick McCarty 929448ab88 Fix hashdump invocation in bsdiff testsuite
The --basepath option for hashdump was renamed to --path a while back,
so fix up the creatediffs script accordingly.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-06-26 17:56:03 -07:00
Tudor Marcu d237c30578 Release v3.9.4
This release adds the -Y option to the command line to supplement --picky.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.9.4
2017-06-05 18:51:52 -07:00
Alberto Murillo Silva 4214fd335a Add -Y option to parseargs argument
--picky option was being recognized by swupd verify but not
its equivalent -Y

Signed-off-by: Alberto Murillo Silva <alberto.murillo.silva@intel.com>
2017-06-05 12:27:06 -07:00
Tudor Marcu 7b40491d9b Release v3.9.3
This release adds the --picky option to the verify --fix subcommand, making
verify --fix actually remove files not tracked under /usr instead of just
reporting them.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.9.3
2017-05-25 16:55:48 -07:00
Tudor Marcu ca3401e7fa Add verify --fix --picky functionality
This is the basic implementation for a "factory reset" type of command.
It will take the functionality of verify --picky and act on the files found
as verify --fix does with files found mismatching in the manifest.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-05-25 16:41:13 -07:00
Tudor Marcu 7120bb95df Release v3.9.2
This release introduces the verify --picky subcommand, which lists files under
/usr, a new subcommand "autoupdate" which allows for easy enable/disable
of autoupdates and its current status, and converts printfs to fprintf to
stderr throughout the code as appropriate.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.9.2
2017-05-18 16:26:13 -07:00
Icarus Sparry 2487e5b5d0 Add swupd autoupdate command
"swupd autoupdate" returns 0 if autoupdates are enabled.
"sudo autoupdate --enable" will unmask swupd-update.service
"sudo autoupdate --disable" will mask swupd-update.service

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-05-17 15:28:44 -07:00
Icarus Sparry 4afaf2c312 Add verify --picky command
Add a "swupd verify --picky" command which lists files under
/usr (modified by the --path option) which are not listed in the
current manifest. Exceptions /usr/local and /usr/lib/modules. The
former to allow for local changes, the latter because the clear boot
manager owns that directory.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-05-09 12:53:14 -07:00
Icarus Sparry aa8417812d Convert printf to fprintf(stderr, almost everywhere
Write error and informative messages to stderr, only
write data to stdout so it can be piped to other programs.

Make stdout line buffered, rather than introduce race conditions into tests

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-05-09 12:12:39 -07:00
Tudor Marcu 4960bb87e9 Fix formatting issues
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-05-09 10:40:19 -07:00
Tudor Marcu 595500595e Release v3.9.1
This release fixes a bug in signature verification retries, and adds support
to client so it understands a new manifest header field called "action." The
new field will allow client to detect if more actions need to be taken after
an update, i.e run verify --fix.

Signe-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.9.1
2017-05-09 09:41:52 -07:00
Tudor Marcu 55cca1291a Only take actions from newest MoM
The update process should only read in post update action from the newest
MoM. This makes it so that even with a previous MoM having an action, only
the new one will be taken, and if none exist, the old one will be ignored
so swupd will not take the same action as the previous update.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-05-09 09:40:47 -07:00
Tudor Marcu 0fbc8cb6b1 Add support for new manifest header line
The swupd client should support parsing extra data in the case that a format
bump occurred, or other possibly breaking change, so that it can at least
notify the user of more action needing to be taken post update.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-05-09 09:40:47 -07:00
Tudor Marcu 63763ee680 Fix infinite signature failure loop
Unlike the regular manifest loading code, loading a MoM also requires signature
verification to succeed. We cannot reset the retries after a signature
failed because the manifest may load fine, but still fail verification,
resulting in endlessly loading and verifying the Manifest.MoM

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-05-08 14:26:28 -07:00
Tudor Marcu f508685873 Release v3.9.0
This release adds retries to pack downloads for bundle-add. The downloads
could fail if network connectivity is lost, which drops the code into a
slower download path. Instead, attempt to retry pack downloads to stay on
the optimal code path before finally dropping into the fullfile fallback.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.9.0
2017-05-01 11:21:56 -07:00
Tudor Marcu 29b9d1e3a9 Retry pack downloads on bundle-add
The download_subscribed_packs() could fail for network issues or other related
problems, and because the only option for getting new packs is by downloading
zero packs or fullfiles, swupd should retry to get the packs before falling
into the verify_fix_path flow which signifies pack downloads errored out.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-28 14:38:53 -07:00
Tudor Marcu ebfbe017a9 Release v3.8.9
This release fixes a subtle bug in try_delta_manifest_download() that would
incorrectly set the file struct causing hashes to become incorrect. It further
fixes problems in the retry path, in which it would loop continuously until
it was able to load a correct manifest.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.8.9
2017-04-20 16:42:56 -07:00
Tudor Marcu 68c1748cc4 Update code style
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-20 16:39:05 -07:00
Tudor Marcu 88d4867532 Fix update retry structure
The update code did not jump to the correct points when it needed to retry,
causing swupd to run into infinite loops if it could not load a given manifest
at all.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-20 16:34:26 -07:00
Tudor Marcu a9cd09f084 Fix try_delta_manifest to populate file correctly
The new file struct cannot be populated using the original because it will
contain attributes and data that may not match the new file, breaking hash
computation. We must freshly populate the struct with the new file only
after bsdiff application succeeds, and then compute hash to ensure all data
is indeed from the new file. It is also irrelevant to precompute the hash
before attempting to apply the delta, so we remove that code block

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-20 16:34:26 -07:00
Tudor Marcu 0cdf8ef62a Release v3.8.8
This release fixes incorrect download messages printing for packs, validation
for the format number supplied to the binary, and enables delta file
application for manifests. Manifest deltas can be more than 150 times smaller
than the full file tar, saving time on updates by downloading much less data.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.8.8
2017-04-19 16:58:28 -07:00
Tudor Marcu e09ee30d10 Check for fullfile and not tar of manifests
The tarfiles should not be kept after swupd runs, so check for the fullfile
instead and skip having to extract it.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-19 16:41:59 -07:00
Tudor Marcu d02783ce9c Fix try_delta_manifest_download
If there is no peer or we cannot get a delta, quit and don't mess with the
file struct. Pre-populating the file struct then exiting early corrupts the
manifest list for later operations, and is a noop when the file cannot be
found to begin with. If there is no peer, it likely is a new manifest and
thus a delta cannot exist.

Should the delta application succeed, we MUST compute and set the new hash
for the file else it will retain the hash of the previous version, and not
pass hash check.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-19 16:41:59 -07:00