This release adds mixer integration to swupd-client which allows local
content to be added alongside upstream content.
A bug is also fixed where CTRL-C during fullfile download caused
subsequent operations to fail due to a hash mismatch in the state
directory. Autocompletion was fixed. A --no-scripts flag was added to
the post-update scripts entirely, mainly for container use-cases when
these scripts will not work.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The mixer bundle must be installed for any of this to work, so check that the
mixer program exists before continuing to do any legitimate work.
The curl commands should also be checked that they worked, and not leave
incorrect 404 files around.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
When content mismatches in the user manifest and the upstream content,
that is - the filenames are equal but the hashes are not, this signifies
that something is being introduced that already exists and is not the
same. Currently, only additive functionality is fully guaranteed to work,
so existing packages can be added as long as they are the same as the ones
provided by upstream. If non-unique content is added, all conflicts will be
printed out to the user so it can be fixed, and swupd will exit unless it
is given the allow-mix-collisions override flag.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Use defines instead, and check the user passed in URL against the URLs listed
in the official upstream contenturl file vs a static hardcoded URL.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The add-pkg.sh script handles all of the custom mixer content generation
for use added content. Supporting documentation is added to explain its
behaviour and the additional swupd command to incorporate the local content.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This patch adds the logic required to handle files and manifests
differently if it is detected that the system is on a mix, or the
content being provided is local mix content.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Until internal data structures are fully migrated, provide a helper function
to transform a loaded manifest to an array. We can then do file lookups in
O(logn) time using binary search instead of traversing linked lists.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The filecount field becomes relevant when using an array implementation
of the manifest contents, so store it in the struct.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Fixes#325
Fullfile download will fail when downloading if it encounters the file
already existing in state directory but the file's hash is mismatching.
Instead of failing on this case remove that file and download it again.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add the --no-scripts flag to update, verify, and bundle-add commands to
allow users to skip the post update scripts for these commands. This is
useful when running in environments when systemctl is not available such
as containers.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When output was changed to stderr for user output, this broke
automatic generation of the bash completion function.
Add suitable redirection to the generation script to capture stderr.
Add test to check the generated file looks reasonable.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Because rst2man.py is called when the timestamps on *.rst are newer than
their associated man pages, we need to have rst2man.py just in case we
hit this condition for the build.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release improves rename detection times from a O(n^3) operation to
roughly a O(n^2) operation (although typically less). It also makes curl
error messages more consistent across the codebase.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This line of code is a recent addition, and I think it is more helpful
for the end user to see the pretty-printed curl error message in
addition to the error number.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release fixes client re-exec capabilities over format bumps.
Instead of relying on a special post-update action from the server via
the Manifest.MoM (which was being done incorrectly server-side) the
client now does format bump detection by itself.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Instead of relying on swupd-server to put the post-update action in the
correct manifest and in the correct format, do the format change
detection on the client.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The check_network() function definition was recently removed, but the
declaration remained. Remove the declaration as well.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release adds logic to skip deletion of boot files since they are
managed by clr-boot-manager. It also adds "ghost" file handling to allow
files managed by other programs to be used as a rename base but not
actually deleted by or otherwise managed by swupd.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The target-dir is wiped every run, so putting the .gitignore in the
target-dir directory doesn't work.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Implement handling of ghosted files in manifests via the 'g' flag. These
files are treated the same as deleted files except that they are not
actually deleted during the update. This allows ghosted files to serve
as the basis for renames while not actually being deleted by swupd.
This change also covers the verify --fix and verify --fix --picky paths.
Ghosted files will be ignored in these cases.
An example of where this is useful is with kernel files, which are
deleted from /usr/lib/kernel/ by clr-boot-manager but should still be
marked as deleted to utilize the rename functionality.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Fixes#306
Because 'ignore-list' contains patterns that cannot match lines from
'lines-checked', they should also be absent from the diff output that
compares 'lines-checked' to 'lines-output'. Implement this by post
processing 'lines-output' to omit ignored lines.
This change improves error reporting when check_lines() finds mismatches
between 'lines-checked' and 'lines-output' for a particular test.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Since I changed check_lines() to propogate the matcher.awk exit status,
this test failed due to a missing 'lines-checked' file. Add the file to
fix that issue.
Also, remove the -x and -v options to the shell invocation, because more
lines of output are produced and that should not be checked.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Fixes#307
Previously to this change, lines-checked may have contained lines
matching patterns from the ignore-list, but matcher.awk does not expect
this situation and may result in difficult-to-diagnose test failures.
Instead, pre-validate lines-checked and if this validation fails, exit
with status code 2.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
If the test passes, BATS will not print the output anyway, so always
echoing $output (regardless of exit status) is better.
Also, make sure check_lines() returns the correct status.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Because the next commit will be adding validation to ensure
lines-checked lines do not match ignore-list patterns, ignore-list must
be processed first.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
I will be reusing this logic, so moving it into a user-defined AWK
function will help with maintenance.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Add /lib/kernel as the files to skip in addition to /lib/modules as
these are managed by clear-boot-manager.
Fixes#313
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
This release fixes a bug that caused the fallback CApath to be
overlooked due to a double-increment of an index variable.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Remove the increment left-over from changing from while to for.
The issue does not impact happy scenario. However, when the fallback
needs to be used (e.g. when the default trust store is removed or in a
container where it's not generated), swupd fails to connect because it
never gets to try the fallback CApath: if there's just one fallback, it
the cycle will end before it is tried.
This release makes several bug fixes and minor improvements.
Bug fixes
- File rename bug fixed, swupd-client can now handle the simplest case
of renames where the file name changes but the content does not.
- Several compiler warning fixes.
- A fix for doc build failure for separate src and build dirs.
- Travis CI dependency update.
- Progress meter will always fully reach 100%.
- Progress meter flushes to stdout during redirected output.
Improvements
- Add progress updates for --verify.
- Support IPv6 in downloads.
- Support mixing of http and file URLs for content and version URLs.
- Add CApath fallback support.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Fixes#272
The create_update_list function was not adding a file onto its return
list if it was part of a rename that didn't change the contents. This
was due to a short circuit which failed to check if the flags
associated with a file (is_file, is_deleted etc) were the same.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
This test renames foo to bar with no changes to contents, and baz to
bat with minimal changes.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>