510 Commits
Author SHA1 Message Date
Matthew Johnson ba9e0f232f Release v3.12.7
This release improves rename detection times from a O(n^3) operation to
roughly a O(n^2) operation (although typically less). It also makes curl
error messages more consistent across the codebase.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.12.7
2017-10-27 10:11:16 -07:00
Icarus Sparry 7ca4873b73 More a constant time check before a O(n) check
Hopefully will drop yet another cubic operation to quadratic

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-10-26 16:21:28 -07:00
Patrick McCarty 1876dc1bf0 Add curl error wrapper function
To ensure that generic curl error messages are printed uniformly, add a
wrapper function.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-23 12:22:41 -07:00
Patrick McCarty ffabf640a6 Pretty print check_network error messages
This line of code is a recent addition, and I think it is more helpful
for the end user to see the pretty-printed curl error message in
addition to the error number.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-23 12:22:41 -07:00
Matthew Johnson d47e05edac Release v3.12.6
This release fixes client re-exec capabilities over format bumps.
Instead of relying on a special post-update action from the server via
the Manifest.MoM (which was being done incorrectly server-side) the
client now does format bump detection by itself.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.12.6
2017-10-19 10:13:17 -07:00
Matthew Johnson c79297886b Fix re-exec capabilities over format bumps
Instead of relying on swupd-server to put the post-update action in the
correct manifest and in the correct format, do the format change
detection on the client.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-10-19 09:51:08 -07:00
Patrick McCarty ed7a52aa1c Remove unused check_network() declaration
The check_network() function definition was recently removed, but the
declaration remained. Remove the declaration as well.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-19 09:46:13 -07:00
Matthew Johnson 44bc6ebaa2 Release v3.12.5
This release adds logic to skip deletion of boot files since they are
managed by clr-boot-manager. It also adds "ghost" file handling to allow
files managed by other programs to be used as a rename base but not
actually deleted by or otherwise managed by swupd.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.12.5
2017-10-16 14:23:44 -07:00
Matthew Johnson d98353c376 Add .gitignore to rename test target-dir
The target-dir is wiped every run, so putting the .gitignore in the
target-dir directory doesn't work.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-10-16 14:16:31 -07:00
Matthew Johnson 5aeee1bf86 Add functional tests for ghosted renames and deletes
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-10-16 14:16:31 -07:00
Matthew Johnson 44cdf0c44c Implement ghosted file handling
Implement handling of ghosted files in manifests via the 'g' flag. These
files are treated the same as deleted files except that they are not
actually deleted during the update. This allows ghosted files to serve
as the basis for renames while not actually being deleted by swupd.

This change also covers the verify --fix and verify --fix --picky paths.
Ghosted files will be ignored in these cases.

An example of where this is useful is with kernel files, which are
deleted from /usr/lib/kernel/ by clr-boot-manager but should still be
marked as deleted to utilize the rename functionality.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-10-16 14:16:31 -07:00
Patrick McCarty 4b6b5c3305 test: update progress message for latest changes
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 82c25392b8 test: honor ignore-list in check_lines diff output
Fixes #306

Because 'ignore-list' contains patterns that cannot match lines from
'lines-checked', they should also be absent from the diff output that
compares 'lines-checked' to 'lines-output'. Implement this by post
processing 'lines-output' to omit ignored lines.

This change improves error reporting when check_lines() finds mismatches
between 'lines-checked' and 'lines-output' for a particular test.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 8708dc8722 test: add lines-checked for update/rename test
Since I changed check_lines() to propogate the matcher.awk exit status,
this test failed due to a missing 'lines-checked' file. Add the file to
fix that issue.

Also, remove the -x and -v options to the shell invocation, because more
lines of output are produced and that should not be checked.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 8f868bef1c test: validate correctness of lines-checked
Fixes #307

Previously to this change, lines-checked may have contained lines
matching patterns from the ignore-list, but matcher.awk does not expect
this situation and may result in difficult-to-diagnose test failures.

Instead, pre-validate lines-checked and if this validation fails, exit
with status code 2.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 58d7f667f2 test: echo test output regardless of exit status
If the test passes, BATS will not print the output anyway, so always
echoing $output (regardless of exit status) is better.

Also, make sure check_lines() returns the correct status.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 6c7674a08d test: process ignore-list before lines-checked
Because the next commit will be adding validation to ensure
lines-checked lines do not match ignore-list patterns, ignore-list must
be processed first.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 00e6463652 test: move ignored line checking into a function
I will be reusing this logic, so moving it into a user-defined AWK
function will help with maintenance.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 91b0bc818e test: add modeline to matcher.awk
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Icarus Sparry ebd0840090 Do not delete /usr/lib/kernel
Add /lib/kernel as the files to skip in addition to /lib/modules as
these are managed by clear-boot-manager.

Fixes #313

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-10-10 15:34:46 -07:00
Matthew Johnson fa58142f7a Release v3.12.4
This release fixes a bug that caused the fallback CApath to be
overlooked due to a double-increment of an index variable.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.12.4
2017-10-05 16:43:35 -07:00
Arzhan Kinzhalin d6ec671646 Fix incorrect cycle.
Remove the increment left-over from changing from while to for.

The issue does not impact happy scenario. However, when the fallback
needs to be used (e.g. when the default trust store is removed or in a
container where it's not generated), swupd fails to connect because it
never gets to try the fallback CApath: if there's just one fallback, it
the cycle will end before it is tried.
2017-10-05 14:48:31 -07:00
Matthew Johnson 4d4acf4af6 Release 3.12.3
This release makes several bug fixes and minor improvements.

Bug fixes
- File rename bug fixed, swupd-client can now handle the simplest case
  of renames where the file name changes but the content does not.
- Several compiler warning fixes.
- A fix for doc build failure for separate src and build dirs.
- Travis CI dependency update.
- Progress meter will always fully reach 100%.
- Progress meter flushes to stdout during redirected output.

Improvements
- Add progress updates for --verify.
- Support IPv6 in downloads.
- Support mixing of http and file URLs for content and version URLs.
- Add CApath fallback support.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.12.3
2017-10-02 13:49:41 -07:00
Matthew Johnson e22c597023 Code style fixes
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-10-02 13:43:05 -07:00
Icarus Sparry c35e559651 Fix renames of files without changes
Fixes #272

The create_update_list function was not adding a file onto its return
list if it was part of a rename that didn't change the contents. This
was due to a short circuit which failed to check if the flags
associated with a file (is_file, is_deleted etc) were the same.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-10-02 13:13:27 -07:00
Icarus Sparry 58e2a5c527 Test for rename
This test renames foo to bar with no changes to contents, and baz to
bat with minimal changes.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-10-02 13:13:27 -07:00
Icarus Sparry 52c0ad20df Additional swupdlib.bash functionality
Allow chown_root and revert_chown_root to take multiple parameters, in
particular they can now take -R to do a recursive chown.

New functions clean_web_dir, clean_state_dir and clean_target_dir to
clean things up (clean_test_dir is now an alias for
clean_state_dir).

New function set_os_release to set the value in target_dir

New function unpack_target_from_manifest. This takes two parameters
release and name. It reads the manifest, locates the files from the
web-dir/$release/staged directory and copies them into target-dir, and
also creates the directories. Helpful in creating initial versions of
target-dir. Should be expanded to do deletion.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-10-02 13:13:27 -07:00
Arzhan Kinzhalin feadea96b6 Implement fallback CApath support.
A colon-separated list of alternative CApath options can be passed to
swupd-client at the configuration time using --with-fallback-capaths
option.

In runtime, fallback CApath support is implemented as part of the
connectivity check. The implementation will try the default (built into
curl) and then will iterate through the list in the order they were
specified. It is done only once on the first call.

The code is reorganized to keep the connectivity check inside curl
wrapper:

* Deleted check_network implementation from version.c
* Removed have_network global (globals.c)
* Scoped swupd_curl_test_resume to curl.c
* Change use of check_network to swupd_curl_check_network

Also:

* Fixed an issue where SSL was only enabled if a URL was matching the
  content URL
2017-10-02 11:30:48 -07:00
Icarus Sparry 653415b89e Portability for Makefile
Fixes #300

Do not use GNU Make 'dir' function, instead use shell dirname command.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-10-02 11:12:40 -07:00
Patrick Ohly e562379004 downloads: support mixing http and file URLs
swupd used to enforce that version and content URL had to use the same
protocol because then it only needed to check once whether it was
downloading locally.

However, it's not that much more difficult to check each individual
URL, so now that's what swupd does now and thus the restriction is
gone.

Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
2017-09-28 15:03:31 -07:00
Patrick McCarty 286435e9b0 Fix compiler warnings in search.c
The calls to strstr() and strcasestr() in file_search() from search.c
result in compiler warnings when -Wnonnull is specified, because GCC's
"nonnull" attribute applies to these functions.

The logic from the file_search() call sites prevent NULL pointers from
being passed to these functions, but to protect against future
refactoring introducing this bug, check that the appropriate pointers
are non-NULL before calling the string functions.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-09-28 13:18:11 -07:00
Patrick McCarty 7522e8d68b Support IPv6 in download code
Fixes #200

Because swupd-client uses libcurl, and my guess is that libcurl has
supported IPv6 for a long time, I don't see any reason to restrict
downloads to IPv4 only.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-09-28 12:34:49 -07:00
Matthew Johnson 7e18d507bd Update tests and error output for check_network usage
Fixing the compiler issue for check_network in check_update.c triggered
test failures. Fix the test failures and improve the error output for
when check_network() fails.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-28 11:27:01 -07:00
Matthew Johnson 1a2226340e Fix compiler warning in check_update.c
Fixes #263
The conditional checking for network connection always evaluated as true
since the check_network() function was not being called. Add the
parentheses to actually check for network.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-28 11:27:01 -07:00
Matthew Johnson 0efd3f1e3d Fix compiler warning in clr_bundle_rm.c
Fixes #264
The static keyword should be at the beginning of the line.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-28 11:27:01 -07:00
Icarus Sparry e8cfa5f0d4 compiler warnings in xattrs
Fixes #262

Define silly little function to get gcc to shut up about unused
parameters.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-09-28 11:26:39 -07:00
Icarus Sparry 60bf270626 Add progress updates for Verifying files
Fixes #276

Refactor fixing a single file into its own routine, then call it in a
loop with print_progress.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-09-28 11:21:58 -07:00
Krisztian Litkey d918dd7232 Fix (doc) build failure for separate src and build dirs.
Signed-off-by: Krisztian Litkey <krisztian.litkey@intel.com>
2017-09-28 11:18:45 -07:00
Icarus Sparry b303fbfeeb Flush dots in progress meter
The progress meter adds a dot for every 10 steps taken if the output
is not to a terminal, but the output is probably block buffered so
output only occurs every 40960 steps. Add a fflush to force it out
straight away.

Related to #256.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-09-28 08:59:49 -07:00
Icarus Sparry 0d29fb21da Fix progress meters
The denominator for the progress report is based on the length of the
linked list to be processed, and the numerator is the number of
elements processed. Most loops have short cut conditions, which invoke
continue, which don't therefore update the numerator, and so loops end
before the progress meter shows 100%. In particular the final file
might be skipped.

Update the numerator early in the loop, and add a final call to
print_progress to force showing 100% if it has not already been done.

Note this can force another dot to be output for the case where stdout
is not connected to a terminal.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-09-28 08:59:49 -07:00
Icarus Sparry 397d8758af Update fix-missing-file test to account for progress dots
Now we have dots (or percentages) when files are being downloaded
these can intermingle with the normal output if they are flushed.

Alter the fix-missing-file test to remove dots from the lines to be
compared, and alter the lines-checked to add in the lines which would
normally be ignored but no longer match due to the missing dots,
e.g. "Downloading packs."

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-09-28 08:59:49 -07:00
Matthew Johnson 591c08a2d5 Travis: Use github as upstream for check
Recent outages to sourceforge break Travis CI runs. Use the github
release instead and update to the latest version of libcheck (0.11.0).

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-27 11:11:54 -07:00
Icarus Sparry ff1628191d Fix for issue 260, make portability
Use = rather than := on the line. It is only an efficiency gain.

replace patsubst and filter with a new variable and standard
substitution.

Replace %-style pattern with suffix rule.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-09-25 14:11:02 -07:00
Icarus Sparry 682baab1f3 fix for issue 261, compiler warning
glibc marks system() as a function whose return value should not be
ignored, which is generally reasonable. In this case we do want to
ignore the return value. Just casting to void is not enough to stop
the gcc warning. So instead we use the value in an if statement with
an empty body, which we trust the optimizer to remove so there is no
run time penalty.

The alternative solution would be to use
    #pragma GCC diagnostic push
    #pragma GCC diagnostic ignored "-Wwarn_unused_result"
    system(log_cmd);
    #pragma GCC diagnostic pop
but that is rather gcc specific.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-09-25 14:05:32 -07:00
Matthew Johnson 0e49188c3f Release v3.12.2
This release improves error reporting for container use-cases.
* Adds systemctl check for autoupdate to correctly report that swupd is
  "Unable to determine autoupdate status" in a container.
* Adds a --no-boot-update flag to disable boot file updates particularly
  for use in a container when boot file management will fail.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.12.2
2017-09-19 10:40:29 -07:00
Matthew Johnson ad556debec Clean up code style
New clang version...

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-15 10:55:02 -07:00
Matthew Johnson d0e18b8a69 Add functional tests for --no-boot-update flag
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-15 10:44:32 -07:00
Matthew Johnson c23dfb558c Add --no-boot-update flag for container usage
Since clr-boot-manager does not work in a container add the
--no-boot-update option to allow installation into a container to skip
the boot partition management. This also calls apply_heuristics when
running bundle-add, with the result of running CBM when necessary for
bundle-adds and skipping CBM when the --no-boot-update flag is
specified.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-15 10:44:32 -07:00
Matthew Johnson 2ba4127ad7 Add initial systemctl check for autoupdate
In a container systemctl does not work, and /usr/bin/systemctl fails as
expected with "Failed to connect to bus: No such file or directory."
Because of this, swupd autoupdate will not work either. However,
"systemctl is-enabled ..." will not fail, even though it should.

Add an additional check to make sure /usr/bin/systemctl is working
before checking if swupd-update.service is-enabled. Report that swupd
was "Unable to determine autoupdate status" if this check fails.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-12 18:13:01 -07:00
Matthew Johnson bbbabc72a0 Release v3.12.1
This release improves error messages for post update scripts when
systemd is not operable, such as in a container, adds a --force or
--picky requirement when verify --fixing to another version, and
performs hash checks on every file when adding a bundle.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.12.1
2017-09-12 12:36:32 -07:00