609 Commits
Author SHA1 Message Date
Matthew Johnson 144cc60987 Release v3.15.2
This release makes some bug and memory management fixes.
* swupd-add-pkg bug that prevented creating a local bundle with the same
  name as the package it includes was fixed.
* A bug that caused bundle-list to print garbage for systems with a
  large number of bundles was fixed.
* The swupd completion code was updated and filename completion for
  swupd hashdump was added.
* Protect against bogus filecount heap corruption.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.15.3
2018-03-27 10:59:03 -07:00
Icarus Sparry bc5cae81dc Update swupd completion code
Make swupd save a copy of the current MoM in a readable location, so
the completion code for bundle-add has access to it.

Stop generating the completion code, just use the file directly.

Remove the short option from the completion code, whilst they are
useful for an expert there is little point typing minus tab and then a
letter rather than minus and the letter.

Add crude filename completion for hashdump.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2018-03-26 11:23:04 -07:00
Icarus Sparry e441c38462 Fix garbage from list-bundles
The directory reading routines do not promise that the entries remain
valid whilst the directory is open. In particular if the directory is
more than 4k (one stdio buffer) in size then the names will be invalid.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2018-03-26 11:23:04 -07:00
Matthew Johnson 9200cb88dc Fix code style
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-03-19 14:46:14 -07:00
Icarus Sparry 7a50a21300 Issue #413. Make memory exhaustion more explicit
When we run out of memory call abort() for consistency with
string_or_die.

This doesn't address the issue that nF * sizeof(struct filerecord)
might not fit into size_t. For this to be a problem we would need more
than 400,000,000 files in the manifests on a 32bit system.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2018-03-19 14:42:22 -07:00
Icarus Sparry 31a6a82e05 Potential Heap corruption fix
Fixes #412

A maliciously constructed manifest could arrange for an insanely large
number of files to be claimed. This parameter was then being passed to
malloc without any further validation, potentially causing heap
corruption if the value was such that when multiplied by
sizeof(struct file) it would overflow an integer. Clamp the value to
no more than 4 million to avoid this attack.

Reported by ktwo@ktwo.ca

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2018-03-19 14:42:22 -07:00
Icarus Sparry 87d601d05a New test for issue 412
Create a test-bundle manifest with a stupid number of files, see that
it is rejected. Unfortunately because of retries this takes a long
time (70 seconds) time to run.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2018-03-19 14:42:22 -07:00
Icarus Sparry e52ba1e7df Change contentsize in Manifest.MoM to 0
The previous value - 13,805,671,819 is bogus, and we want to be able
to test if the value is reasonable.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2018-03-19 14:42:22 -07:00
Tudor Marcu 516acc80fb swupd-add-pkg: use exact match for pkg name
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2018-03-16 17:13:11 -07:00
Matthew Johnson 1330a634e4 Release v3.15.2
This release updates the swupd-add-pkg script to work with the latest
changes to the mixer tooling it relies on.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.15.2
2018-03-15 08:24:07 -07:00
Tudor Marcu 8e42c5b7c2 Fix swupd-add-pkg
Fix the script to propagate the old (unchanged) custom bundles to the new
merged MoM manifest. Small errors were fixed as well with reading the correct
- initially unmerged - manifest, and not adding a package to a bundle if it
already exists.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2018-03-14 15:24:43 -07:00
Matthew Johnson 8a760b8648 Release v3.15.1
This release fixes mixer integration with the bundle list command
(previously it would try to use the server MoM for the local mix
version).

Swupd search is improved to report real recursive contentsize for bundle
results as a sum of included bundles. Search now displays all results by
default with an optional --top NUM flag to only display NUM results per
bundle. Another flag -m, --csv outputs all results in CSV format so they
can be more easily parsed by a machine.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.15.1
2018-03-07 12:09:17 -08:00
Matthew Johnson 07191bb4c4 search: add --csv flag to output results in CSV format
The -m, --csv flag outputs all search results in CSV format:

/file/result,bundle-name

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-03-07 12:08:12 -08:00
Matthew Johnson 3d583153c1 search: make full list the default output
Instead of silently truncating search results to 5 files per 5 bundles
make the default search output a full list grouped by bundle. This
output will only be sorted by increasing bundle size.

Add a -t, --top=NUM argument to tell search to truncate results at NUM
files per bundle. This option attempts to display the top results based
on a set of heuristics.

When truncating results due to --top add a message when the file results
are cut off.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-03-07 12:08:12 -08:00
Matthew Johnson b0829ddcee search: do not display bundle size when manifest load fails
Since bundle size might be inaccurate in this case just do not display
it, or even calculate the size.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-03-07 11:59:36 -08:00
Matthew Johnson e5555c838c Report real contentsize for swupd search bundles
When reporting bundles for swupd search include their included bundles'
contentsizes as well for more accurate size reporting. For bundles that
are not installed on the client system, this skips any installed
includes and only reports contentsize for uninstalled includes. For
bundles that are installed on the system calculate the entire
contentsize for all includes and report this as the "installed size" of
the bundle.

When the scope is 'o' (one hit only) do not print size information.
Since only the first hit was taken it is unlikely that contentsize was
calculated for all that bundle's includes.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-03-07 11:59:36 -08:00
Tudor Marcu 44fc2617cb Add mixer-integration awareness to bundle-list
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2018-03-06 12:04:51 -08:00
Matthew Johnson 36eca27a8a Release v3.15.0
This release adds the 'swupd clean' command to clean up old files from
the statedir, adds an indication to 'swupd search' to show if a bundle
is installed, updates the copyright header, and updates mixer
integration to use the new mixer-tools 4.0.x interface.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.15.0
2018-03-01 17:09:42 -08:00
Tudor Marcu 57d775cb3c Update to new Mixer 4.0.*
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2018-03-01 17:10:00 -08:00
Matthew Johnson 20f7073f06 Update copyright header to 2018
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-02-27 11:39:01 -08:00
Caio Marcelo de Oliveira Filho fe6040cca6 Add 'swupd clean' command
This command removes old files from statedir. The interface is a bit
opaque so there will be room to modify the policy later.

By default it will delete staged files that are older than
DAYS_TO_KEEP_FILES. For manifests this heuristic is not good as older
manifests might still be used for the current OS version being run, so
also ensure that those do not get deleted. This prevents 'swupd
search' to redownload files.

The default behavior should be suitable to use in combination with
automatic updates, to control the size of state dir. There is also an
--all option to remove all the state files regardless of dates and
usage.

To avoid "disasters" in case some paths are set wrong, the command
explicitly delete patterns of files create by swupd.
2018-02-27 09:46:19 -08:00
Matthew Johnson 2b5b48e8b6 search: show indication that bundle is installed
When displaying a search result for a bundle display "installed" next to
bundles that have been added to the system.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-02-22 17:49:07 -08:00
Matthew Johnson 308949973f Release v3.14.7
This release fixes the "Hardlink target error" when extracting packs and
improves swupd search output.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.14.7
2018-02-21 17:48:35 -08:00
Matthew Johnson de9c2c4dd8 Make some small improvements to new swupd search
Remove some of the magic numbers, add some comments, fix some code
style, remove an unnecessary string duplication, free dynamically
allocated memory in response to feedback on PR #387.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-02-21 17:45:28 -08:00
Matthew Johnson 8ad7b88880 Add a few comments to the new search code
While reviewing this I typed down a few notes as I was looking at how
this was implemented. Keep these notes as comments in the code.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-02-21 17:45:28 -08:00
Matthew Johnson 3ec1ed5780 Update tests to reflect swupd search improvements
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-02-21 17:45:28 -08:00
Matthew Johnson 30d9fde522 Fix up code style
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-02-21 17:45:28 -08:00
Arjan van de Ven db1d479356 Improve swupd search output
This patch improves the output of swupd search by grouping search
results by bundle. Each file and bundle result is ranked according to a
set of heuristics such as bundle size and path name. The top five bundle
results (and the top five file results in each bundle) are displayed
while the rest of the output is truncated.
2018-02-21 17:45:28 -08:00
Caio Marcelo de Oliveira Filho 1c1af7e9a3 Fix "Hardlink target error" when extracting
In some cases packs may include files with entries of type "hard
link", that refer to previous files in the pack. Libarchive was
failing since it couldn't find the previous file in disk to archive,
because we change its output path.

Adjusting the hardlink target path (when it exists) fix the
issue. This is also what bsdtar does.

This patch was tested by simulating the update that goes from 19460 to
19580 with the desktop pack installed (that contains one hardlink in
the pack used by this update).

Fixes #351.
2018-02-16 08:31:31 -08:00
Matthew Johnson 5a0b62b158 Release v3.14.6
This release fixes various bugs
* Remove invalid memory reads when listing local bundles
* Fixes init/deinit of all bundle list variants
* Sorts output of installable bundles
* Fixes invalid call to stat when FALLBACK_CAPATHS are empty
* Fixes mixer integration bundle-add/remove
* Fixes mixer integration upstream url handling
* And fixes other minor internal issues

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.14.6
2018-02-15 11:32:44 -08:00
Tudor Marcu 93ef149d0d bundle.c: Fix bundle-add/remove
Just because /usr/share/mix exists, don't assume that it has good
content. Check that there is content _and_ we successfully moved to a mix
before trying to use any content out of it.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2018-02-15 11:30:15 -08:00
Tudor Marcu 2c3dd5e833 swupd-add-pkg: Fix upstream url not being filled in
The script should be calling init-mix to fully and correctly setup the mix
directory. Without this, the upstream url was never being recorded, and the
yum-mix.conf did not get the URL substituted during chroots phase.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2018-02-15 10:50:59 -08:00
Caio Marcelo de Oliveira Filho 45bec26eea Remove now unnecessary variables from Makefile.am
Now that all the commands are together in a single binary there's no
much reason to keep various different variables for each. Just
enumerate all the sources as part of swupd_SOURCES.
2018-02-14 09:31:36 -08:00
Caio Marcelo de Oliveira Filho 077b2f6a70 Forbid certain state_dir values to prevent disasters
During initialization swupd may delete the state_dir to ensure it is
in the right shape. That means that by accident, passing "-S /" to any
command is dangerous.

Since neither /, /usr or /var are useful as state dirs, let's prevent
some damage by not allowing them.
2018-02-14 09:26:50 -08:00
Caio Marcelo de Oliveira Filho df19971b48 Remove unused variable
Should have been removed in
2111507a57 ("Don't show OS version after
the bundles"), but escaped.
2018-02-13 09:37:01 -08:00
Caio Marcelo de Oliveira Filho 2111507a57 Don't show OS version after the bundles
When listing installed bundles, the OS version was printed after the
bundles, unlike the other cases that just show the list. Now that
there is a command that shows the version (swupd info) it should be
fine to take that out.
2018-02-09 21:22:00 -08:00
Caio Marcelo de Oliveira Filho 504b042e47 Properly initalize/deinit all bundle list variants
Let the bundle_list_main call init and deinit, don't exit()
early. Also, simplify the conditions dispatching the individual
commands. This fixes as leaks in various cases and double
initialization listing installable bundles.

Calling exit directly was used for a particular case, before init was
called, to prevent curl to be initialized for a case that didn't need
it. Then the code moved but the exit() call remained and got used by
other cases.
2018-02-09 21:22:00 -08:00
Caio Marcelo de Oliveira Filho 3590c01490 Sort output of installable bundles 2018-02-09 21:22:00 -08:00
Caio Marcelo de Oliveira Filho b0699e2a55 Fix invalid memory reads when listing local bundles
When closedir() is called, the directory names are not valid anymore,
but read_local_bundles() was returning a list of them. The related
valgrind message

==20540== Invalid read of size 1
==20540==    at 0x48353E8: mempcpy (vg_replace_strmem.c:1524)
==20540==    by 0x50F0E30: _IO_file_xsputn (in /usr/lib64/haswell/libc-2.26.so)
==20540==    by 0x50E5CAE: puts (in /usr/lib64/haswell/libc-2.26.so)
==20540==    by 0x408187: printf (stdio2.h:104)
==20540==    by 0x408187: bundle_list_main (clr_bundle_ls.c:232)
==20540==    by 0x508CF69: (below main) (in /usr/lib64/haswell/libc-2.26.so)
==20540==  Address 0x58a70fb is 859 bytes inside a block of size 32,816 free'd
==20540==    at 0x482CD0B: free (vg_replace_malloc.c:530)
==20540==    by 0x51481CC: closedir (in /usr/lib64/haswell/libc-2.26.so)
==20540==    by 0x484F4E3: read_local_bundles (bundle.c:937)
==20540==    by 0x408154: bundle_list_main (clr_bundle_ls.c:225)
==20540==    by 0x508CF69: (below main) (in /usr/lib64/haswell/libc-2.26.so)
==20540==  Block was alloc'd at
==20540==    at 0x482BADF: malloc (vg_replace_malloc.c:299)
==20540==    by 0x5147F2D: ??? (in /usr/lib64/haswell/libc-2.26.so)
==20540==    by 0x484F486: read_local_bundles (bundle.c:926)
==20540==    by 0x408154: bundle_list_main (clr_bundle_ls.c:225)
==20540==    by 0x508CF69: (below main) (in /usr/lib64/haswell/libc-2.26.so)

Instead of duplicating the strings to return, just renamed it to
list_local_bundles() and sorted / printed before closedir() call. This
makes that code similar to the other listing functions.
2018-02-09 21:22:00 -08:00
Caio Marcelo de Oliveira Filho 81b708cd25 Fix invalid call to stat when FALLBACK_CAPATHS is empty
Loop wasn't taking into account the constant being set but empty. In
that case tok was set to NULL and stat was called with it. Replace
'do-while' with a 'while' to also perform the check the first time.
2018-02-09 17:44:12 -08:00
Matthew Johnson 3d1b24e113 Code style fix
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-02-06 18:29:13 -08:00
Caio Marcelo de Oliveira Filho 917ac30c64 Remove redundant check and string creation in try_delta()
The function do_delta() is only called by try_delta() and both were
creating the string with the name of the staged file and performing
the file exists check. Pass the name to do_delta() and remove the
check.

This should not change the behavior.
2018-02-06 18:21:04 -08:00
William Douglas 3d8b710896 Make a container check before running clr-boot-manager
Add a check to see if an update is being run in a container (and is
updating the rootfs) using systemd-detect-virt -c. If the update is
being run in a container skip running the clr-boot-manager update
since it will fail.
2018-02-01 10:02:45 -08:00
Matthew Johnson eb8072fbab Release v3.14.5
This release
* adds documentation of missing flags to the man page
* adds the info subcommand to show OS version and URLs
* adds correct handling of hash failures for bundle-add

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.14.5
2018-01-29 09:58:58 -08:00
Matthew Johnson 7483535256 Handle bundle-add hash failures
Fixes #252
Fixes #370
Fixes #371
When failing to add bundle with a file with the wrong hash remove the
file and fall back to the verify_fix_path. Improve warnings so they
don't look like errors until they are actually errors.

Add tests so we don't regress in this regard.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-01-29 08:54:03 -08:00
Caio Marcelo de Oliveira Filho 88eea5f9e9 Add info command to show OS version and URLs
Fixes #218.

Signed-off-by: Caio Marcelo de Oliveira Filho <caio.oliveira@intel.com>
2018-01-25 10:02:44 -08:00
Caio Marcelo de Oliveira Filho a463e2eb31 Use same style for all the command descriptions
Signed-off-by: Caio Marcelo de Oliveira Filho <caio.oliveira@intel.com>
2018-01-25 09:48:58 -08:00
Matthew Johnson de773f8ecf Add missing flags to man page
The following flags have been added to the man page
--no-scripts
--nosigcheck
--ignore-time
--certpath
--time
--no-boot-update

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-01-23 14:05:32 -08:00
Matthew Johnson aef0cc4490 Add free_string function and use everywhere
Fixes #357
Add free_string() function to insure code is consistently resetting
pointers to NULL after resetting dynamic memory. Use this helper
everywhere strings are being freed.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
2018-01-19 10:31:15 -08:00
Matthew Johnson ed2b568d5b Release v3.14.4
This release calls clr-service-restart if a POST_UPDATE script is not
configured and the clr-service-restart binary exists on the system.
clr-service-restart is a program that restarts all services that are
running against out-of-date service files or libraries. Any POST_UPDATE
script should also call this binary in a similar fashion.

This release also fixes a couple memory leaks and a warning call in
archive.c libarchive calling code.

Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
v3.14.4
2018-01-17 13:50:14 -08:00