This release fixes the "Hardlink target error" when extracting packs and
improves swupd search output.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Remove some of the magic numbers, add some comments, fix some code
style, remove an unnecessary string duplication, free dynamically
allocated memory in response to feedback on PR #387.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
While reviewing this I typed down a few notes as I was looking at how
this was implemented. Keep these notes as comments in the code.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This patch improves the output of swupd search by grouping search
results by bundle. Each file and bundle result is ranked according to a
set of heuristics such as bundle size and path name. The top five bundle
results (and the top five file results in each bundle) are displayed
while the rest of the output is truncated.
In some cases packs may include files with entries of type "hard
link", that refer to previous files in the pack. Libarchive was
failing since it couldn't find the previous file in disk to archive,
because we change its output path.
Adjusting the hardlink target path (when it exists) fix the
issue. This is also what bsdtar does.
This patch was tested by simulating the update that goes from 19460 to
19580 with the desktop pack installed (that contains one hardlink in
the pack used by this update).
Fixes#351.
This release fixes various bugs
* Remove invalid memory reads when listing local bundles
* Fixes init/deinit of all bundle list variants
* Sorts output of installable bundles
* Fixes invalid call to stat when FALLBACK_CAPATHS are empty
* Fixes mixer integration bundle-add/remove
* Fixes mixer integration upstream url handling
* And fixes other minor internal issues
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Just because /usr/share/mix exists, don't assume that it has good
content. Check that there is content _and_ we successfully moved to a mix
before trying to use any content out of it.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The script should be calling init-mix to fully and correctly setup the mix
directory. Without this, the upstream url was never being recorded, and the
yum-mix.conf did not get the URL substituted during chroots phase.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Now that all the commands are together in a single binary there's no
much reason to keep various different variables for each. Just
enumerate all the sources as part of swupd_SOURCES.
During initialization swupd may delete the state_dir to ensure it is
in the right shape. That means that by accident, passing "-S /" to any
command is dangerous.
Since neither /, /usr or /var are useful as state dirs, let's prevent
some damage by not allowing them.
When listing installed bundles, the OS version was printed after the
bundles, unlike the other cases that just show the list. Now that
there is a command that shows the version (swupd info) it should be
fine to take that out.
Let the bundle_list_main call init and deinit, don't exit()
early. Also, simplify the conditions dispatching the individual
commands. This fixes as leaks in various cases and double
initialization listing installable bundles.
Calling exit directly was used for a particular case, before init was
called, to prevent curl to be initialized for a case that didn't need
it. Then the code moved but the exit() call remained and got used by
other cases.
When closedir() is called, the directory names are not valid anymore,
but read_local_bundles() was returning a list of them. The related
valgrind message
==20540== Invalid read of size 1
==20540== at 0x48353E8: mempcpy (vg_replace_strmem.c:1524)
==20540== by 0x50F0E30: _IO_file_xsputn (in /usr/lib64/haswell/libc-2.26.so)
==20540== by 0x50E5CAE: puts (in /usr/lib64/haswell/libc-2.26.so)
==20540== by 0x408187: printf (stdio2.h:104)
==20540== by 0x408187: bundle_list_main (clr_bundle_ls.c:232)
==20540== by 0x508CF69: (below main) (in /usr/lib64/haswell/libc-2.26.so)
==20540== Address 0x58a70fb is 859 bytes inside a block of size 32,816 free'd
==20540== at 0x482CD0B: free (vg_replace_malloc.c:530)
==20540== by 0x51481CC: closedir (in /usr/lib64/haswell/libc-2.26.so)
==20540== by 0x484F4E3: read_local_bundles (bundle.c:937)
==20540== by 0x408154: bundle_list_main (clr_bundle_ls.c:225)
==20540== by 0x508CF69: (below main) (in /usr/lib64/haswell/libc-2.26.so)
==20540== Block was alloc'd at
==20540== at 0x482BADF: malloc (vg_replace_malloc.c:299)
==20540== by 0x5147F2D: ??? (in /usr/lib64/haswell/libc-2.26.so)
==20540== by 0x484F486: read_local_bundles (bundle.c:926)
==20540== by 0x408154: bundle_list_main (clr_bundle_ls.c:225)
==20540== by 0x508CF69: (below main) (in /usr/lib64/haswell/libc-2.26.so)
Instead of duplicating the strings to return, just renamed it to
list_local_bundles() and sorted / printed before closedir() call. This
makes that code similar to the other listing functions.
Loop wasn't taking into account the constant being set but empty. In
that case tok was set to NULL and stat was called with it. Replace
'do-while' with a 'while' to also perform the check the first time.
The function do_delta() is only called by try_delta() and both were
creating the string with the name of the staged file and performing
the file exists check. Pass the name to do_delta() and remove the
check.
This should not change the behavior.
Add a check to see if an update is being run in a container (and is
updating the rootfs) using systemd-detect-virt -c. If the update is
being run in a container skip running the clr-boot-manager update
since it will fail.
This release
* adds documentation of missing flags to the man page
* adds the info subcommand to show OS version and URLs
* adds correct handling of hash failures for bundle-add
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Fixes#252Fixes#370Fixes#371
When failing to add bundle with a file with the wrong hash remove the
file and fall back to the verify_fix_path. Improve warnings so they
don't look like errors until they are actually errors.
Add tests so we don't regress in this regard.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The following flags have been added to the man page
--no-scripts
--nosigcheck
--ignore-time
--certpath
--time
--no-boot-update
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Fixes#357
Add free_string() function to insure code is consistently resetting
pointers to NULL after resetting dynamic memory. Use this helper
everywhere strings are being freed.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release calls clr-service-restart if a POST_UPDATE script is not
configured and the clr-service-restart binary exists on the system.
clr-service-restart is a program that restarts all services that are
running against out-of-date service files or libraries. Any POST_UPDATE
script should also call this binary in a similar fashion.
This release also fixes a couple memory leaks and a warning call in
archive.c libarchive calling code.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
See: https://github.com/clearlinux/clr-service-restart
If present, clr-service-restart can be used to dynamically determine
whether running daemons need a restart based on whether they have
been updated, or whether they are holding references to library code
that has been replaced on disk.
This is synchronous - the units that do need restarted are restarted
and their startup status is verified afterwards. Each restart is
printed on the screen to display what is happening. If a failure
happens, and the unit is a unit provided by the OS vendor, a telemetry
record is created.
Right now only whitelisted units are restarted automatically, and
there are no whitelisted units at this time. These will be slowly
added over time as we understand and learn which units are considered
'safe' to restart, and which ones are not 'safe'.
Need to pass the same struct used in the operation to the
_archive_check_err helper.
This fixes issue of some Warnings appearing with "(null)" message,
since the writer did not had an error string associated.
Signed-off-by: Caio Marcelo de Oliveira Filho <caio.oliveira@intel.com>
The get_value_from_path() function allocates memory for "ret_str", so it
should be freed after the string is stored in "global".
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Most of the functional tests properly reverted the chown operations in
teardown(), but three of them were missing the reverts.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
In commit e18eb69, retrieve_manifests() was refactored to support the
mixer integration feature, but it introduced a double free of the
"filename" pointer when following certain code paths.
One code path to reproduce the issue is when a Manifest.MoM is not
present in the state directory, and swupd_curl_check_network() fails. A
free(filename) was being called immediately before
swupd_curl_check_network(), and then again after jumping to the "out"
label for the error condition.
Resolve the issue by resetting the filename pointer to NULL after
freeing the memory to prevent a later double free. I also reset the url
pointer to NULL at the second call site for similar reasoning.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release removes download continues for bundle-add and verify
--install operations because swupd does not expect to have valid cache
for these operations. It also updates the heuristics logic in order to
not set files under /usr/src/kernel/ as state files so that kernel
sources can be shipped.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Fixes#352
This operation is fragile and can cause errors if a zero pack download
is interrupted resulting in an incomplete tar archive. A user reported
that having the incomplete pack around prevented the pack from being
re-downloaded and the content was incorrect so the bundle-add was not
completing. Instead of trying to resume a bundle-add pack download just
remove the old file and try again.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release makes several library linking fixes and cleanups, removes
several completely unused test files, and updates generated man pages.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
* Fix a bug in which the return code of an internal function was not
being checked.
* Add the --picky-tree argument
--picky-tree=path allows a user to specify the tree under which to run
verify --picky
* Add the --picky-whitelist argument
--picky-whitelist=regex allows the user to tell swupd to ignore
certain file paths when running verify --picky
* Use libarchive to extract archives instead of direct calls to tar
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Different versions of clang-format suggest different indentation levels
for comments before labels. This commit reverts
64e14b6fd9 which likely used an older
version of clang-format.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Use libarchive in order to make use of its security features and avoid
calling out to tar via a shell. The TAR_COMMAND is still used in
staging.c to complete the copy when a hardlink fails.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The code implementing the suppression of /usr/lib/kernel,
/usr/lib/modules and /usr/local did a rather simplistic prefix
comparison with strncmp() to match path names against these
exceptions. As a result, paths like /usr/lib/kernel.old which should
get reported also got skipped.
An if check tested the wrong variable, so the result from strdup()
wasn't checked.
The replacement code uses regular expression matching and allows
replacing the default (--picky-whitelist
"/ignore-this-top-level-dir"). A single parameter is enough when using
the | operator.
A/B partition update must remove extra files in the entire partition,
which can be selected with --picky-tree=/, and also needs to override
the default whitelist.
Fixes#336
Implements #239
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
The return code of the remove() call was not getting checked. Usually
it shouldn't fail, but if it does, the failure now gets reported.
Instead of doing this change in two places, the common code gets
refactored into a new handle() function.
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>