This release calls clr-service-restart if a POST_UPDATE script is not
configured and the clr-service-restart binary exists on the system.
clr-service-restart is a program that restarts all services that are
running against out-of-date service files or libraries. Any POST_UPDATE
script should also call this binary in a similar fashion.
This release also fixes a couple memory leaks and a warning call in
archive.c libarchive calling code.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
See: https://github.com/clearlinux/clr-service-restart
If present, clr-service-restart can be used to dynamically determine
whether running daemons need a restart based on whether they have
been updated, or whether they are holding references to library code
that has been replaced on disk.
This is synchronous - the units that do need restarted are restarted
and their startup status is verified afterwards. Each restart is
printed on the screen to display what is happening. If a failure
happens, and the unit is a unit provided by the OS vendor, a telemetry
record is created.
Right now only whitelisted units are restarted automatically, and
there are no whitelisted units at this time. These will be slowly
added over time as we understand and learn which units are considered
'safe' to restart, and which ones are not 'safe'.
Need to pass the same struct used in the operation to the
_archive_check_err helper.
This fixes issue of some Warnings appearing with "(null)" message,
since the writer did not had an error string associated.
Signed-off-by: Caio Marcelo de Oliveira Filho <caio.oliveira@intel.com>
The get_value_from_path() function allocates memory for "ret_str", so it
should be freed after the string is stored in "global".
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Most of the functional tests properly reverted the chown operations in
teardown(), but three of them were missing the reverts.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
In commit e18eb69, retrieve_manifests() was refactored to support the
mixer integration feature, but it introduced a double free of the
"filename" pointer when following certain code paths.
One code path to reproduce the issue is when a Manifest.MoM is not
present in the state directory, and swupd_curl_check_network() fails. A
free(filename) was being called immediately before
swupd_curl_check_network(), and then again after jumping to the "out"
label for the error condition.
Resolve the issue by resetting the filename pointer to NULL after
freeing the memory to prevent a later double free. I also reset the url
pointer to NULL at the second call site for similar reasoning.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release removes download continues for bundle-add and verify
--install operations because swupd does not expect to have valid cache
for these operations. It also updates the heuristics logic in order to
not set files under /usr/src/kernel/ as state files so that kernel
sources can be shipped.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Fixes#352
This operation is fragile and can cause errors if a zero pack download
is interrupted resulting in an incomplete tar archive. A user reported
that having the incomplete pack around prevented the pack from being
re-downloaded and the content was incorrect so the bundle-add was not
completing. Instead of trying to resume a bundle-add pack download just
remove the old file and try again.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release makes several library linking fixes and cleanups, removes
several completely unused test files, and updates generated man pages.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
* Fix a bug in which the return code of an internal function was not
being checked.
* Add the --picky-tree argument
--picky-tree=path allows a user to specify the tree under which to run
verify --picky
* Add the --picky-whitelist argument
--picky-whitelist=regex allows the user to tell swupd to ignore
certain file paths when running verify --picky
* Use libarchive to extract archives instead of direct calls to tar
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Different versions of clang-format suggest different indentation levels
for comments before labels. This commit reverts
64e14b6fd9 which likely used an older
version of clang-format.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Use libarchive in order to make use of its security features and avoid
calling out to tar via a shell. The TAR_COMMAND is still used in
staging.c to complete the copy when a hardlink fails.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The code implementing the suppression of /usr/lib/kernel,
/usr/lib/modules and /usr/local did a rather simplistic prefix
comparison with strncmp() to match path names against these
exceptions. As a result, paths like /usr/lib/kernel.old which should
get reported also got skipped.
An if check tested the wrong variable, so the result from strdup()
wasn't checked.
The replacement code uses regular expression matching and allows
replacing the default (--picky-whitelist
"/ignore-this-top-level-dir"). A single parameter is enough when using
the | operator.
A/B partition update must remove extra files in the entire partition,
which can be selected with --picky-tree=/, and also needs to override
the default whitelist.
Fixes#336
Implements #239
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
The return code of the remove() call was not getting checked. Usually
it shouldn't fail, but if it does, the failure now gets reported.
Instead of doing this change in two places, the common code gets
refactored into a new handle() function.
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
This release adds the ability to configure an executable path to be used
for swupd pre- and post-updates. The previous hard-coded method still
exists as a fallback.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add the ability to configure an executable path to be used when swupd
completes its update process. Similarly add the use of a configurable
executable path for the pre-update script. The previous method will be
used if the configuration isn't set.
This release adds mixer integration to swupd-client which allows local
content to be added alongside upstream content.
A bug is also fixed where CTRL-C during fullfile download caused
subsequent operations to fail due to a hash mismatch in the state
directory. Autocompletion was fixed. A --no-scripts flag was added to
the post-update scripts entirely, mainly for container use-cases when
these scripts will not work.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The mixer bundle must be installed for any of this to work, so check that the
mixer program exists before continuing to do any legitimate work.
The curl commands should also be checked that they worked, and not leave
incorrect 404 files around.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
When content mismatches in the user manifest and the upstream content,
that is - the filenames are equal but the hashes are not, this signifies
that something is being introduced that already exists and is not the
same. Currently, only additive functionality is fully guaranteed to work,
so existing packages can be added as long as they are the same as the ones
provided by upstream. If non-unique content is added, all conflicts will be
printed out to the user so it can be fixed, and swupd will exit unless it
is given the allow-mix-collisions override flag.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Use defines instead, and check the user passed in URL against the URLs listed
in the official upstream contenturl file vs a static hardcoded URL.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The add-pkg.sh script handles all of the custom mixer content generation
for use added content. Supporting documentation is added to explain its
behaviour and the additional swupd command to incorporate the local content.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This patch adds the logic required to handle files and manifests
differently if it is detected that the system is on a mix, or the
content being provided is local mix content.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Until internal data structures are fully migrated, provide a helper function
to transform a loaded manifest to an array. We can then do file lookups in
O(logn) time using binary search instead of traversing linked lists.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The filecount field becomes relevant when using an array implementation
of the manifest contents, so store it in the struct.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Fixes#325
Fullfile download will fail when downloading if it encounters the file
already existing in state directory but the file's hash is mismatching.
Instead of failing on this case remove that file and download it again.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add the --no-scripts flag to update, verify, and bundle-add commands to
allow users to skip the post update scripts for these commands. This is
useful when running in environments when systemctl is not available such
as containers.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When output was changed to stderr for user output, this broke
automatic generation of the bash completion function.
Add suitable redirection to the generation script to capture stderr.
Add test to check the generated file looks reasonable.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Because rst2man.py is called when the timestamps on *.rst are newer than
their associated man pages, we need to have rst2man.py just in case we
hit this condition for the build.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>