This release fixes the 2TB contentsize limit check and adjusts the
swupd-client.timer unit to check for updates more frequently.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
We know these are cheap and our CDN takes care of the actual
bulk of the bandwith.
Spread the update checks between 45min0sec and 1hr33mins
effectively.
This release makes some bug and memory management fixes.
* swupd-add-pkg bug that prevented creating a local bundle with the same
name as the package it includes was fixed.
* A bug that caused bundle-list to print garbage for systems with a
large number of bundles was fixed.
* The swupd completion code was updated and filename completion for
swupd hashdump was added.
* Protect against bogus filecount heap corruption.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Make swupd save a copy of the current MoM in a readable location, so
the completion code for bundle-add has access to it.
Stop generating the completion code, just use the file directly.
Remove the short option from the completion code, whilst they are
useful for an expert there is little point typing minus tab and then a
letter rather than minus and the letter.
Add crude filename completion for hashdump.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
The directory reading routines do not promise that the entries remain
valid whilst the directory is open. In particular if the directory is
more than 4k (one stdio buffer) in size then the names will be invalid.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
When we run out of memory call abort() for consistency with
string_or_die.
This doesn't address the issue that nF * sizeof(struct filerecord)
might not fit into size_t. For this to be a problem we would need more
than 400,000,000 files in the manifests on a 32bit system.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Fixes#412
A maliciously constructed manifest could arrange for an insanely large
number of files to be claimed. This parameter was then being passed to
malloc without any further validation, potentially causing heap
corruption if the value was such that when multiplied by
sizeof(struct file) it would overflow an integer. Clamp the value to
no more than 4 million to avoid this attack.
Reported by ktwo@ktwo.ca
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Create a test-bundle manifest with a stupid number of files, see that
it is rejected. Unfortunately because of retries this takes a long
time (70 seconds) time to run.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
The previous value - 13,805,671,819 is bogus, and we want to be able
to test if the value is reasonable.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
This release updates the swupd-add-pkg script to work with the latest
changes to the mixer tooling it relies on.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Fix the script to propagate the old (unchanged) custom bundles to the new
merged MoM manifest. Small errors were fixed as well with reading the correct
- initially unmerged - manifest, and not adding a package to a bundle if it
already exists.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This release fixes mixer integration with the bundle list command
(previously it would try to use the server MoM for the local mix
version).
Swupd search is improved to report real recursive contentsize for bundle
results as a sum of included bundles. Search now displays all results by
default with an optional --top NUM flag to only display NUM results per
bundle. Another flag -m, --csv outputs all results in CSV format so they
can be more easily parsed by a machine.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Instead of silently truncating search results to 5 files per 5 bundles
make the default search output a full list grouped by bundle. This
output will only be sorted by increasing bundle size.
Add a -t, --top=NUM argument to tell search to truncate results at NUM
files per bundle. This option attempts to display the top results based
on a set of heuristics.
When truncating results due to --top add a message when the file results
are cut off.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Since bundle size might be inaccurate in this case just do not display
it, or even calculate the size.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When reporting bundles for swupd search include their included bundles'
contentsizes as well for more accurate size reporting. For bundles that
are not installed on the client system, this skips any installed
includes and only reports contentsize for uninstalled includes. For
bundles that are installed on the system calculate the entire
contentsize for all includes and report this as the "installed size" of
the bundle.
When the scope is 'o' (one hit only) do not print size information.
Since only the first hit was taken it is unlikely that contentsize was
calculated for all that bundle's includes.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release adds the 'swupd clean' command to clean up old files from
the statedir, adds an indication to 'swupd search' to show if a bundle
is installed, updates the copyright header, and updates mixer
integration to use the new mixer-tools 4.0.x interface.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This command removes old files from statedir. The interface is a bit
opaque so there will be room to modify the policy later.
By default it will delete staged files that are older than
DAYS_TO_KEEP_FILES. For manifests this heuristic is not good as older
manifests might still be used for the current OS version being run, so
also ensure that those do not get deleted. This prevents 'swupd
search' to redownload files.
The default behavior should be suitable to use in combination with
automatic updates, to control the size of state dir. There is also an
--all option to remove all the state files regardless of dates and
usage.
To avoid "disasters" in case some paths are set wrong, the command
explicitly delete patterns of files create by swupd.
When displaying a search result for a bundle display "installed" next to
bundles that have been added to the system.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release fixes the "Hardlink target error" when extracting packs and
improves swupd search output.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Remove some of the magic numbers, add some comments, fix some code
style, remove an unnecessary string duplication, free dynamically
allocated memory in response to feedback on PR #387.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
While reviewing this I typed down a few notes as I was looking at how
this was implemented. Keep these notes as comments in the code.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This patch improves the output of swupd search by grouping search
results by bundle. Each file and bundle result is ranked according to a
set of heuristics such as bundle size and path name. The top five bundle
results (and the top five file results in each bundle) are displayed
while the rest of the output is truncated.
In some cases packs may include files with entries of type "hard
link", that refer to previous files in the pack. Libarchive was
failing since it couldn't find the previous file in disk to archive,
because we change its output path.
Adjusting the hardlink target path (when it exists) fix the
issue. This is also what bsdtar does.
This patch was tested by simulating the update that goes from 19460 to
19580 with the desktop pack installed (that contains one hardlink in
the pack used by this update).
Fixes#351.
This release fixes various bugs
* Remove invalid memory reads when listing local bundles
* Fixes init/deinit of all bundle list variants
* Sorts output of installable bundles
* Fixes invalid call to stat when FALLBACK_CAPATHS are empty
* Fixes mixer integration bundle-add/remove
* Fixes mixer integration upstream url handling
* And fixes other minor internal issues
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Just because /usr/share/mix exists, don't assume that it has good
content. Check that there is content _and_ we successfully moved to a mix
before trying to use any content out of it.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The script should be calling init-mix to fully and correctly setup the mix
directory. Without this, the upstream url was never being recorded, and the
yum-mix.conf did not get the URL substituted during chroots phase.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Now that all the commands are together in a single binary there's no
much reason to keep various different variables for each. Just
enumerate all the sources as part of swupd_SOURCES.
During initialization swupd may delete the state_dir to ensure it is
in the right shape. That means that by accident, passing "-S /" to any
command is dangerous.
Since neither /, /usr or /var are useful as state dirs, let's prevent
some damage by not allowing them.
When listing installed bundles, the OS version was printed after the
bundles, unlike the other cases that just show the list. Now that
there is a command that shows the version (swupd info) it should be
fine to take that out.
Let the bundle_list_main call init and deinit, don't exit()
early. Also, simplify the conditions dispatching the individual
commands. This fixes as leaks in various cases and double
initialization listing installable bundles.
Calling exit directly was used for a particular case, before init was
called, to prevent curl to be initialized for a case that didn't need
it. Then the code moved but the exit() call remained and got used by
other cases.
When closedir() is called, the directory names are not valid anymore,
but read_local_bundles() was returning a list of them. The related
valgrind message
==20540== Invalid read of size 1
==20540== at 0x48353E8: mempcpy (vg_replace_strmem.c:1524)
==20540== by 0x50F0E30: _IO_file_xsputn (in /usr/lib64/haswell/libc-2.26.so)
==20540== by 0x50E5CAE: puts (in /usr/lib64/haswell/libc-2.26.so)
==20540== by 0x408187: printf (stdio2.h:104)
==20540== by 0x408187: bundle_list_main (clr_bundle_ls.c:232)
==20540== by 0x508CF69: (below main) (in /usr/lib64/haswell/libc-2.26.so)
==20540== Address 0x58a70fb is 859 bytes inside a block of size 32,816 free'd
==20540== at 0x482CD0B: free (vg_replace_malloc.c:530)
==20540== by 0x51481CC: closedir (in /usr/lib64/haswell/libc-2.26.so)
==20540== by 0x484F4E3: read_local_bundles (bundle.c:937)
==20540== by 0x408154: bundle_list_main (clr_bundle_ls.c:225)
==20540== by 0x508CF69: (below main) (in /usr/lib64/haswell/libc-2.26.so)
==20540== Block was alloc'd at
==20540== at 0x482BADF: malloc (vg_replace_malloc.c:299)
==20540== by 0x5147F2D: ??? (in /usr/lib64/haswell/libc-2.26.so)
==20540== by 0x484F486: read_local_bundles (bundle.c:926)
==20540== by 0x408154: bundle_list_main (clr_bundle_ls.c:225)
==20540== by 0x508CF69: (below main) (in /usr/lib64/haswell/libc-2.26.so)
Instead of duplicating the strings to return, just renamed it to
list_local_bundles() and sorted / printed before closedir() call. This
makes that code similar to the other listing functions.
Loop wasn't taking into account the constant being set but empty. In
that case tok was set to NULL and stat was called with it. Replace
'do-while' with a 'while' to also perform the check the first time.
The function do_delta() is only called by try_delta() and both were
creating the string with the name of the staged file and performing
the file exists check. Pass the name to do_delta() and remove the
check.
This should not change the behavior.
Add a check to see if an update is being run in a container (and is
updating the rootfs) using systemd-detect-virt -c. If the update is
being run in a container skip running the clr-boot-manager update
since it will fail.
This release
* adds documentation of missing flags to the man page
* adds the info subcommand to show OS version and URLs
* adds correct handling of hash failures for bundle-add
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Fixes#252Fixes#370Fixes#371
When failing to add bundle with a file with the wrong hash remove the
file and fall back to the verify_fix_path. Improve warnings so they
don't look like errors until they are actually errors.
Add tests so we don't regress in this regard.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>