117 Commits
Author SHA1 Message Date
Matthew Johnson 3ec1ed5780 Update tests to reflect swupd search improvements
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-02-21 17:45:28 -08:00
Matthew Johnson 7483535256 Handle bundle-add hash failures
Fixes #252
Fixes #370
Fixes #371
When failing to add bundle with a file with the wrong hash remove the
file and fall back to the verify_fix_path. Improve warnings so they
don't look like errors until they are actually errors.

Add tests so we don't regress in this regard.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-01-29 08:54:03 -08:00
Patrick McCarty 90a8e6a366 Fix tests that are lacking chown reverts
Most of the functional tests properly reverted the chown operations in
teardown(), but three of them were missing the reverts.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2018-01-04 07:26:28 -08:00
Matthew Johnson 6de33b5953 Remove tests that have been unused since inception
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-12-01 11:00:02 -08:00
Tudor Marcu e910900b1b Add better error handling throughout and cleanup
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-11-03 11:50:08 -07:00
Matthew Johnson 9d06cbf9b8 Add functional test for bad hash in state directory
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-11-03 11:45:39 -07:00
Matthew Johnson 91d067b7c9 Add tests for --no-scripts flag
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-11-02 09:07:39 -07:00
Icarus Sparry bbb9774703 Fix generation of swupd.bash
When output was changed to stderr for user output, this broke
automatic generation of the bash completion function.

Add suitable redirection to the generation script to capture stderr.

Add test to check the generated file looks reasonable.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-11-02 09:06:57 -07:00
Matthew Johnson c79297886b Fix re-exec capabilities over format bumps
Instead of relying on swupd-server to put the post-update action in the
correct manifest and in the correct format, do the format change
detection on the client.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-10-19 09:51:08 -07:00
Matthew Johnson d98353c376 Add .gitignore to rename test target-dir
The target-dir is wiped every run, so putting the .gitignore in the
target-dir directory doesn't work.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-10-16 14:16:31 -07:00
Matthew Johnson 5aeee1bf86 Add functional tests for ghosted renames and deletes
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-10-16 14:16:31 -07:00
Patrick McCarty 4b6b5c3305 test: update progress message for latest changes
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 82c25392b8 test: honor ignore-list in check_lines diff output
Fixes #306

Because 'ignore-list' contains patterns that cannot match lines from
'lines-checked', they should also be absent from the diff output that
compares 'lines-checked' to 'lines-output'. Implement this by post
processing 'lines-output' to omit ignored lines.

This change improves error reporting when check_lines() finds mismatches
between 'lines-checked' and 'lines-output' for a particular test.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 8708dc8722 test: add lines-checked for update/rename test
Since I changed check_lines() to propogate the matcher.awk exit status,
this test failed due to a missing 'lines-checked' file. Add the file to
fix that issue.

Also, remove the -x and -v options to the shell invocation, because more
lines of output are produced and that should not be checked.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 8f868bef1c test: validate correctness of lines-checked
Fixes #307

Previously to this change, lines-checked may have contained lines
matching patterns from the ignore-list, but matcher.awk does not expect
this situation and may result in difficult-to-diagnose test failures.

Instead, pre-validate lines-checked and if this validation fails, exit
with status code 2.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 58d7f667f2 test: echo test output regardless of exit status
If the test passes, BATS will not print the output anyway, so always
echoing $output (regardless of exit status) is better.

Also, make sure check_lines() returns the correct status.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 6c7674a08d test: process ignore-list before lines-checked
Because the next commit will be adding validation to ensure
lines-checked lines do not match ignore-list patterns, ignore-list must
be processed first.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 00e6463652 test: move ignored line checking into a function
I will be reusing this logic, so moving it into a user-defined AWK
function will help with maintenance.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Patrick McCarty 91b0bc818e test: add modeline to matcher.awk
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-10-12 10:40:37 -07:00
Icarus Sparry 58e2a5c527 Test for rename
This test renames foo to bar with no changes to contents, and baz to
bat with minimal changes.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-10-02 13:13:27 -07:00
Icarus Sparry 52c0ad20df Additional swupdlib.bash functionality
Allow chown_root and revert_chown_root to take multiple parameters, in
particular they can now take -R to do a recursive chown.

New functions clean_web_dir, clean_state_dir and clean_target_dir to
clean things up (clean_test_dir is now an alias for
clean_state_dir).

New function set_os_release to set the value in target_dir

New function unpack_target_from_manifest. This takes two parameters
release and name. It reads the manifest, locates the files from the
web-dir/$release/staged directory and copies them into target-dir, and
also creates the directories. Helpful in creating initial versions of
target-dir. Should be expanded to do deletion.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-10-02 13:13:27 -07:00
Arzhan Kinzhalin feadea96b6 Implement fallback CApath support.
A colon-separated list of alternative CApath options can be passed to
swupd-client at the configuration time using --with-fallback-capaths
option.

In runtime, fallback CApath support is implemented as part of the
connectivity check. The implementation will try the default (built into
curl) and then will iterate through the list in the order they were
specified. It is done only once on the first call.

The code is reorganized to keep the connectivity check inside curl
wrapper:

* Deleted check_network implementation from version.c
* Removed have_network global (globals.c)
* Scoped swupd_curl_test_resume to curl.c
* Change use of check_network to swupd_curl_check_network

Also:

* Fixed an issue where SSL was only enabled if a URL was matching the
  content URL
2017-10-02 11:30:48 -07:00
Matthew Johnson 7e18d507bd Update tests and error output for check_network usage
Fixing the compiler issue for check_network in check_update.c triggered
test failures. Fix the test failures and improve the error output for
when check_network() fails.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-28 11:27:01 -07:00
Icarus Sparry 397d8758af Update fix-missing-file test to account for progress dots
Now we have dots (or percentages) when files are being downloaded
these can intermingle with the normal output if they are flushed.

Alter the fix-missing-file test to remove dots from the lines to be
compared, and alter the lines-checked to add in the lines which would
normally be ignored but no longer match due to the missing dots,
e.g. "Downloading packs."

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-09-28 08:59:49 -07:00
Matthew Johnson d0e18b8a69 Add functional tests for --no-boot-update flag
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-15 10:44:32 -07:00
Matthew Johnson a2f9759e11 Add functional tests for verify version mismatch and override
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-12 11:48:44 -07:00
Matthew Johnson f9180d3f43 Fix several hash mismatches in bundleadd tests
Now that bundleadd verifies each file it downloads the incorrect hashes
cause test failures. Update these hashes to be correct.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-09-12 11:46:29 -07:00
Matthew Johnson ac7345318c Add functional tests for bundle-list --deps
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-31 09:50:50 -07:00
Matthew Johnson c83c4ce78f Add functional tests for bundle-list --has-deps
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-31 09:50:50 -07:00
Matthew Johnson ee06e85931 Add --has-dep argument to bundle list
The --has-dep=BUNDLE argument will display a tree representing all
installed bundles that recursively include BUNDLE.

One may pass the --all argument as well to list the dependency tree for
BUNDLE including all installable bundles available on the server.

**Example output without --all:**

Installed bundles that have os-installer as a dependency:
format:
 # * is-required-by
 #   |-- is-required-by
 # * is-also-required-by
 # ...

  * mixer
    |-- os-clr-on-clr

**Example output with --all:**

Attempting to download version string to memory
All installable and installed bundles that have os-installer as a dependency:
format:
 # * is-required-by
 #   |-- is-required-by
 # * is-also-required-by
 # ...

  * clr-devops
  * mixer
    |-- os-clr-on-clr
        |-- os-clr-on-clr-dev
    |-- clr-devops
    |-- os-clr-on-clr-dev

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-31 09:50:50 -07:00
Matthew Johnson 6108f50bb9 Print bundle dependencies when failing to remove
A bundle will fail to be removed from the filesystem when other bundles
require that bundle as a dependency. Print a list of each of these
bundles along with the error message.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-31 09:50:50 -07:00
Patrick McCarty 485ab31f22 Add functional tests for verify format mismatch and override
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-08-30 11:12:50 -07:00
Matthew Johnson d274f3aede Add "Applying update" print as a progress header
Since this step can take a while print a header to give an indication of
what the progress percentage is tracking. Update functional tests to
include new output.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-17 15:37:15 -07:00
Matthew Johnson 7f7e5b6416 Add progress updates for redirected output
Add a progress indication for redirected output such as for logging,
testing, or third-party software such as ister.

For every 10 files or steps completed a dot (".") is printed to the
screen.

Adds a few more progress indications for silent loops.

Also adds leading newlines to some existing print statements so they are
printed on their own line.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-17 15:37:15 -07:00
Icarus Sparry 3668fb5f7b Ensure state_dir is a directory and owned by root
As the state_dir (normally /var/lib/swupd) contains things like the
downloaded bundles, it is important that there is no access to
non-root users who could potentially explot races to replace files
between them being checked and them being installed.

Ensure that the state_dir is root owned, and mode 0700, as well as the
critical directories below it.

Note that a proper fix would involve using chdir to move into the
directory and only use relative paths. This would prevent faulty
permissions higher up the directory tree being exploited. It *might*
be possible to use openat(2) to prevent this exploitation.

Add a test to ensure that the enforcement is taking place.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-08-17 15:28:06 -07:00
Matthew Johnson ae011954f4 Add status checks for test swupd commands
Adds status checks for each swupd command called in the functional
tests. At this point several of these tests fail due to some successful
commands returning error statuses.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-10 15:33:59 -07:00
Matthew Johnson 2c9021289f Wait for test server to become available before testing
Check that the simple test server in the checkupdate/slow-server/ test
is available before actually running the swupd command. This check is
done by testing the return status of a curl command on the server up to
ten times until successful.

Since this is an historically touchy test, output an additional
debug.log in the test directory with much more verbose logging (using
set -x).

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-08 15:20:16 -07:00
Matthew Johnson 6f52e62854 Fix typo in clr_bundle_rm.c
succesfully -> successfully

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-08-07 14:23:30 -07:00
Matthew Johnson 89af564256 Convert post_update_actions to list-based approach
Instead of allowing only one "actions:" field in the Manifest.MoM, allow
for several and read each into the post_udpate_actions list. This allows
us to add more actions down the road if desired.

Currently the only use for the "actions:" field is to indicate when a
re-update is required. This is handled by checking if the string
"update" is in the post_update_actions list.

Finally, remove the warning to the user to perform the post update
action themselves, as this will be handled by swupd itself. Functional
tests updated to reflect the missing output.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-07-28 23:19:54 -07:00
Matthew Johnson d6636d7814 Add functional test for re-update with bad os-release
Adds a functional test for swupd re-update when the os-release file does
not get updated.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-07-28 23:19:54 -07:00
Matthew Johnson 1d19db4bc1 Add funtional test for swupd re-update
Adds functional test for swupd re-execs over format bumps.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2017-07-28 23:19:54 -07:00
Auke Kok 22cccd9a04 Differentiate between various early network failures.
We draw a hard line with error codes, such that:

Error code 16 is reserved for failures resulting from the basic
network check. Any call to check_network() that fails will
return this error code. No other error path returns this
error code.

Additionally, check_network() is called in every normal code path.

All other, possibly network related issues, return a different
error code. If the basic network check succeeds, but e.g. pack
downloads fail, we return a new (23) error code so that we
can better establish the conditions through telemetry and
determine whether the error is on the client or the server,
which is highly likely with this new error code 23.
2017-07-20 16:18:33 -07:00
Patrick McCarty 929448ab88 Fix hashdump invocation in bsdiff testsuite
The --basepath option for hashdump was renamed to --path a while back,
so fix up the creatediffs script accordingly.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-06-26 17:56:03 -07:00
Tudor Marcu 29b9d1e3a9 Retry pack downloads on bundle-add
The download_subscribed_packs() could fail for network issues or other related
problems, and because the only option for getting new packs is by downloading
zero packs or fullfiles, swupd should retry to get the packs before falling
into the verify_fix_path flow which signifies pack downloads errored out.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-28 14:38:53 -07:00
Tudor Marcu dac74856da Update tests for new messages being printed
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-19 10:12:51 -07:00
Jaime A. Garcia 6a8d36763b Accept multiple bundles at bundle-remove
This is a wrapper around remove_bundle()
to add consistency for bundle-remove
subcommand respect bundle-add that accepts
one or more bundles to be removed.

This must not be the optimal implementation
but it works fine and gives a better user
usage experience.
2017-04-04 11:50:21 -07:00
Icarus Sparry 3ec26daff7 Improved return code for bundleadd + test
Arrange for "bad names" to give non-zero exit code
Arrange for "do nothing" in particular when packages are already
installed to give a zero return code.

This means that typos in names result in failures, but that trying to
add an existing package is fine.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-04-04 11:46:19 -07:00
Tudor Marcu fd6b54d964 Try to recover from invalid certificate date
The system clock may be terribly off, especially on new hardware that has not
yet been calibrated. Updates rely on the certificate and system time being
sane to verify validity, so if a mismatch is found the certificate will
be deemed invalid and the update stopped. This patch attempts to fix the
system time to something sane using the time from the swupd binary itself,
which should not have been touched by any user except root. If the time is
normal and verification fails, the cert cannot be trusted.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-03-25 00:00:41 -07:00
Icarus Sparry 9c4c2cec08 Improved error reporting for adding bad bundle
Currently if you try and add a non existent bundle, e.g. "foo" you get
two lines of output

  foo bundle name is invalid, skipping it...
  bundle(s) already installed, exiting now

This is caused by the add_subscriptions function calling itself
recursivly but failing to pass up results in a meaningful way. This
change makes the return value of add_subscriptions be a bitmask so it
can signal errors and packages added distinctly.

I did think about changing this function to return a struct but
decided this was a step too far.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-03-24 15:27:55 -07:00
Tudor Marcu bfb26b5c40 Change certpath to be full path of certificate
The mixer and image creator treat the certpath as the full path of the
certificate filename, and swupd should too. If someone is overriding the
certificate with the cert path option, use the supplied string and don't
append a pre-defined name to it.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-02-27 11:40:11 -08:00