In commit e18eb69, retrieve_manifests() was refactored to support the
mixer integration feature, but it introduced a double free of the
"filename" pointer when following certain code paths.
One code path to reproduce the issue is when a Manifest.MoM is not
present in the state directory, and swupd_curl_check_network() fails. A
free(filename) was being called immediately before
swupd_curl_check_network(), and then again after jumping to the "out"
label for the error condition.
Resolve the issue by resetting the filename pointer to NULL after
freeing the memory to prevent a later double free. I also reset the url
pointer to NULL at the second call site for similar reasoning.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release removes download continues for bundle-add and verify
--install operations because swupd does not expect to have valid cache
for these operations. It also updates the heuristics logic in order to
not set files under /usr/src/kernel/ as state files so that kernel
sources can be shipped.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Fixes#352
This operation is fragile and can cause errors if a zero pack download
is interrupted resulting in an incomplete tar archive. A user reported
that having the incomplete pack around prevented the pack from being
re-downloaded and the content was incorrect so the bundle-add was not
completing. Instead of trying to resume a bundle-add pack download just
remove the old file and try again.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release makes several library linking fixes and cleanups, removes
several completely unused test files, and updates generated man pages.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
* Fix a bug in which the return code of an internal function was not
being checked.
* Add the --picky-tree argument
--picky-tree=path allows a user to specify the tree under which to run
verify --picky
* Add the --picky-whitelist argument
--picky-whitelist=regex allows the user to tell swupd to ignore
certain file paths when running verify --picky
* Use libarchive to extract archives instead of direct calls to tar
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Different versions of clang-format suggest different indentation levels
for comments before labels. This commit reverts
64e14b6fd9 which likely used an older
version of clang-format.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Use libarchive in order to make use of its security features and avoid
calling out to tar via a shell. The TAR_COMMAND is still used in
staging.c to complete the copy when a hardlink fails.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The code implementing the suppression of /usr/lib/kernel,
/usr/lib/modules and /usr/local did a rather simplistic prefix
comparison with strncmp() to match path names against these
exceptions. As a result, paths like /usr/lib/kernel.old which should
get reported also got skipped.
An if check tested the wrong variable, so the result from strdup()
wasn't checked.
The replacement code uses regular expression matching and allows
replacing the default (--picky-whitelist
"/ignore-this-top-level-dir"). A single parameter is enough when using
the | operator.
A/B partition update must remove extra files in the entire partition,
which can be selected with --picky-tree=/, and also needs to override
the default whitelist.
Fixes#336
Implements #239
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
The return code of the remove() call was not getting checked. Usually
it shouldn't fail, but if it does, the failure now gets reported.
Instead of doing this change in two places, the common code gets
refactored into a new handle() function.
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
This release adds the ability to configure an executable path to be used
for swupd pre- and post-updates. The previous hard-coded method still
exists as a fallback.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add the ability to configure an executable path to be used when swupd
completes its update process. Similarly add the use of a configurable
executable path for the pre-update script. The previous method will be
used if the configuration isn't set.
This release adds mixer integration to swupd-client which allows local
content to be added alongside upstream content.
A bug is also fixed where CTRL-C during fullfile download caused
subsequent operations to fail due to a hash mismatch in the state
directory. Autocompletion was fixed. A --no-scripts flag was added to
the post-update scripts entirely, mainly for container use-cases when
these scripts will not work.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The mixer bundle must be installed for any of this to work, so check that the
mixer program exists before continuing to do any legitimate work.
The curl commands should also be checked that they worked, and not leave
incorrect 404 files around.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
When content mismatches in the user manifest and the upstream content,
that is - the filenames are equal but the hashes are not, this signifies
that something is being introduced that already exists and is not the
same. Currently, only additive functionality is fully guaranteed to work,
so existing packages can be added as long as they are the same as the ones
provided by upstream. If non-unique content is added, all conflicts will be
printed out to the user so it can be fixed, and swupd will exit unless it
is given the allow-mix-collisions override flag.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Use defines instead, and check the user passed in URL against the URLs listed
in the official upstream contenturl file vs a static hardcoded URL.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The add-pkg.sh script handles all of the custom mixer content generation
for use added content. Supporting documentation is added to explain its
behaviour and the additional swupd command to incorporate the local content.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This patch adds the logic required to handle files and manifests
differently if it is detected that the system is on a mix, or the
content being provided is local mix content.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Until internal data structures are fully migrated, provide a helper function
to transform a loaded manifest to an array. We can then do file lookups in
O(logn) time using binary search instead of traversing linked lists.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The filecount field becomes relevant when using an array implementation
of the manifest contents, so store it in the struct.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Fixes#325
Fullfile download will fail when downloading if it encounters the file
already existing in state directory but the file's hash is mismatching.
Instead of failing on this case remove that file and download it again.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add the --no-scripts flag to update, verify, and bundle-add commands to
allow users to skip the post update scripts for these commands. This is
useful when running in environments when systemctl is not available such
as containers.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When output was changed to stderr for user output, this broke
automatic generation of the bash completion function.
Add suitable redirection to the generation script to capture stderr.
Add test to check the generated file looks reasonable.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Because rst2man.py is called when the timestamps on *.rst are newer than
their associated man pages, we need to have rst2man.py just in case we
hit this condition for the build.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release improves rename detection times from a O(n^3) operation to
roughly a O(n^2) operation (although typically less). It also makes curl
error messages more consistent across the codebase.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This line of code is a recent addition, and I think it is more helpful
for the end user to see the pretty-printed curl error message in
addition to the error number.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release fixes client re-exec capabilities over format bumps.
Instead of relying on a special post-update action from the server via
the Manifest.MoM (which was being done incorrectly server-side) the
client now does format bump detection by itself.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Instead of relying on swupd-server to put the post-update action in the
correct manifest and in the correct format, do the format change
detection on the client.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>