This release improves error reporting for container use-cases.
* Adds systemctl check for autoupdate to correctly report that swupd is
"Unable to determine autoupdate status" in a container.
* Adds a --no-boot-update flag to disable boot file updates particularly
for use in a container when boot file management will fail.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Since clr-boot-manager does not work in a container add the
--no-boot-update option to allow installation into a container to skip
the boot partition management. This also calls apply_heuristics when
running bundle-add, with the result of running CBM when necessary for
bundle-adds and skipping CBM when the --no-boot-update flag is
specified.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
In a container systemctl does not work, and /usr/bin/systemctl fails as
expected with "Failed to connect to bus: No such file or directory."
Because of this, swupd autoupdate will not work either. However,
"systemctl is-enabled ..." will not fail, even though it should.
Add an additional check to make sure /usr/bin/systemctl is working
before checking if swupd-update.service is-enabled. Report that swupd
was "Unable to determine autoupdate status" if this check fails.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release improves error messages for post update scripts when
systemd is not operable, such as in a container, adds a --force or
--picky requirement when verify --fixing to another version, and
performs hash checks on every file when adding a bundle.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When running verify --fix with -m specifying a different version than
the current OS version, require --picky to enforce management of files
under /usr or require --force as an override. Adding --picky can solve
issues such as issue #238 where fixing backward caused glibc library
confusion.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Now that bundleadd verifies each file it downloads the incorrect hashes
cause test failures. Update these hashes to be correct.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add a check for missing file so that bundleadd can fall back to the
verify_fix_path to attempt to re-download the file instead of failing
the hash check due to the hash being all 0s.
Improve error messages by reporting the filename instead of the hash in
the error.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When running swupd in a container systemd is not operable and fails with
a "Failed to connect to bus" error. Instead of printing these errors
directly check if systemd is operable at all and print a warning if not,
then return early from the update_triggers.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add newline so progress updates are printed correctly. Instead of this:
...10%File /file was not in a pack
...11%
Print a newline before the message:
...10%
File /file was not in a pack
...11%
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release adds the --deps and --has-dep subcommands to bundle-list to
print dependencies of a bundle and a tree of bundles that have the
specified bundle as a dependency, respectively. It also improves error
handling when checking that the state directory is owned by root.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Don't use the return value from swupd_rm, which is poorly defined, but
test directly that the file no longer exists.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Allow user to list all bundle dependencies of a bundle passed to
swupd bundle-list --deps BUNDLE
This lists all included bundles (included those recursively included)
for the BUNDLE. This is particularly useful when applications or users
need to determine just how large the bundle addition will be. For
example, a user may not be aware that by bundle-adding desktop-dev they
are recursively adding 12 other bundles. This command allows the user to
make this check before installation.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The --has-dep=BUNDLE argument will display a tree representing all
installed bundles that recursively include BUNDLE.
One may pass the --all argument as well to list the dependency tree for
BUNDLE including all installable bundles available on the server.
**Example output without --all:**
Installed bundles that have os-installer as a dependency:
format:
# * is-required-by
# |-- is-required-by
# * is-also-required-by
# ...
* mixer
|-- os-clr-on-clr
**Example output with --all:**
Attempting to download version string to memory
All installable and installed bundles that have os-installer as a dependency:
format:
# * is-required-by
# |-- is-required-by
# * is-also-required-by
# ...
* clr-devops
* mixer
|-- os-clr-on-clr
|-- os-clr-on-clr-dev
|-- clr-devops
|-- os-clr-on-clr-dev
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
A bundle will fail to be removed from the filesystem when other bundles
require that bundle as a dependency. Print a list of each of these
bundles along with the error message.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release fixes several errant return codes, adds progress status for
long-running tasks, ensures the swupd state directory is created and is
owned by root at runtime, fixes --format arg validation, and enforces
format transitions for verify.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When using verify's -m option, it generally only makes sense to verify a
build within the same format, since the subsequent format (if any) might
not be compatible. Therefore, we should disallow verifying to a build
with a different format by default. This commit adds the proper
enforcement by making this condition a fatal error. The early exit can
be bypassed using the -x/--force option, which will print a warning
message instead.
For now, this compatibility check is targeting the use case of verifying
to a newer build, so I also report the latest supported build for the
current format. Verifying to an older build is not guaranteed to succeed
at present, and swupd-client does not yet understand the
version/formatN/first file. In other words, reporting to the user the
oldest build they can verify to will be a future improvement.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
strtoull succeed when the leading characters of the input form a valid
number, so it is necessary to verify that there is no trailing
characters. Use the endptr parameter (that will point to the end of
the accepted input) to verify that.
Fixes#142.
Signed-off-by: Caio Marcelo de Oliveira Filho <caio.oliveira@intel.com>
Since this step can take a while print a header to give an indication of
what the progress percentage is tracking. Update functional tests to
include new output.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Instead of printing the progress percentage for every update,
potentially hundreds of thousands of times, only print when the
percentage changes.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add a progress indication for redirected output such as for logging,
testing, or third-party software such as ister.
For every 10 files or steps completed a dot (".") is printed to the
screen.
Adds a few more progress indications for silent loops.
Also adds leading newlines to some existing print statements so they are
printed on their own line.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add a basic progress indication for a couple potentially long-running
swupd tasks (download_pack and add_missing_files). The progress
indication is displayed as a percentage:
...85%
It overwrites its own line so the progress will update in place. It may
be interrupted by other swupd output:
...45%
Extracting os-core pack for version 10000
...50%
Extracting os-core-update pack for version 9000
...55%
The progress indication will then resume updating in place, on the same
line.
This progress is only displayed when outputting to a TTY, and will not
output anything when the output is being redirected. This is nice for
testing and logging, but means that these progress updates will not be
caught by processes that capture swupd output, such as ister.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
As the state_dir (normally /var/lib/swupd) contains things like the
downloaded bundles, it is important that there is no access to
non-root users who could potentially explot races to replace files
between them being checked and them being installed.
Ensure that the state_dir is root owned, and mode 0700, as well as the
critical directories below it.
Note that a proper fix would involve using chdir to move into the
directory and only use relative paths. This would prevent faulty
permissions higher up the directory tree being exploited. It *might*
be possible to use openat(2) to prevent this exploitation.
Add a test to ensure that the enforcement is taking place.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Instead of returning the direct error code from the system() call to
re-exec swupd update, return a predictable 0 or 1. System was previously
returning 255 (out of range) when failing to re-exec swupd.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When supplying the --download flag, return a success status instead of
-1, which was returned to short-circuit some following code in the main
update path. Use conditionals on the previously short-circuited code
instead.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
It is not necessary to go through the whole swupd initiation process a
second time when listing bundles from the server. This also allows us to
set the correct exit status on the early exit.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Adds status checks for each swupd command called in the functional
tests. At this point several of these tests fail due to some successful
commands returning error statuses.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Check that the simple test server in the checkupdate/slow-server/ test
is available before actually running the swupd command. This check is
done by testing the return status of a curl command on the server up to
ten times until successful.
Since this is an historically touchy test, output an additional
debug.log in the test directory with much more verbose logging (using
set -x).
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release fixes hashdump invocation in the bsdiff testsuite, sorts the
bundle-list output, provides better error codes to differentiate between
various early network failures, and enables client to automatically re-update
itself (or perform any other actions) if stated to in the Manifest.MoM.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Instead of allowing only one "actions:" field in the Manifest.MoM, allow
for several and read each into the post_udpate_actions list. This allows
us to add more actions down the road if desired.
Currently the only use for the "actions:" field is to indicate when a
re-update is required. This is handled by checking if the string
"update" is in the post_update_actions list.
Finally, remove the warning to the user to perform the post update
action themselves, as this will be handled by swupd itself. Functional
tests updated to reflect the missing output.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Adds a check to compare version numbers in <state_dir>/version and
<target_dir>/usr/lib/os-release when attempting to re-update after a
format bump.
os-release should always be equal to <state_dir>/version for normal
updates and potentially greater than <state_dir>/version for format
bumps.
In the event of a bad build where os-release does not get updated to the
new version, this check will prevent an infinite loop where swupd reads
the current version from os-release, sees it is out of date, attempts to
update again, but the file does not get updated.
This occasion is very unlikely but the guard is nice to have
re(guard)less.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When a device is out of date by more than a format bump re-exec swupd
update until the device version matches the server version. This is
achieved by reading the "actions" field in the Manifest.MoM, which is
yet to be implemented in swupd-server. When "update" is specified in the
actions of the current manifest and the current update is successful,
swupd will re-exec itself with the same flags it was originally called
with.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
We draw a hard line with error codes, such that:
Error code 16 is reserved for failures resulting from the basic
network check. Any call to check_network() that fails will
return this error code. No other error path returns this
error code.
Additionally, check_network() is called in every normal code path.
All other, possibly network related issues, return a different
error code. If the basic network check succeeds, but e.g. pack
downloads fail, we return a new (23) error code so that we
can better establish the conditions through telemetry and
determine whether the error is on the client or the server,
which is highly likely with this new error code 23.