This release cleans up some code to declare functions as static when
appropriate and fixes a few mixer integration bugs.
* Write the valid-mix flag file in swupd-add-pkg
* Add some more state files to the ignore list for file collision
checking.
* Check for file collisions *after* a new local build so updates to
os-core are detected.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Fixes#446
When a new upstream version is detected the new local mixer build must
be done before manifest uniqueness is checked. This is due to the fact
that os-core can change in the upstream version, so it has to be
re-built locally against the upstream content in order to avoid false
positives for file colisions.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
These additional files are files that change on the system due to the
local mix. Add these to the ignore list for file colision checks.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
swupd-client expects a .valid-mix file to exist in MIX_DIR when a valid
mix exists. Create this file after creating the mix.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Reformat the .travis.yml file to have shorter lines, and add 'make
install' as a step to get the scripts/fixstatic.pl program to run.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Fixes#448
Make a number of functions static, and bodge around the extra symbol
that gcc adds (__gnu_lto_v1) when compiling with -flto=4
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
This release updates mixer integration capabilities to use the latest
mixer/mixin features and configuration files and removes copyright
header prints from standard commands.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Update mixer integration to key off the .valid-mix flag file to check if
a mix exists. Also update the .clearversion filename to upstreamurl (it
has changed in upstream).
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
swupd-client is properly open-sourced and licensed. The copyright header
is unnecessary, confusing, and causes issues for scripts parsing output.
The copyright header is now only printed when swupd is passed the
--version flag.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release removes sudo invocations in the swupd-add-pkg program and
rely on the user to run under sudo themselves. The /etc/swupd
configuration directory is now created with more open permissions to
allow users to view the configuration on their system.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Instead of doing this behind the user's back expect them to do it
themselves. This also removes the inconsistencies of running some
commands with sudo -E and others without -E. If users want to provide -E
let them do it themselves.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Set /etc/swupd permissions to 0777 to let the default umask policy
handle stripping bits appropriately.
If we can write files to /etc/swupd, do it, making the directory first,
if necessary. If not, bail out cleanly. Only delete the
mirror_contenturl and mirror_versionurl files from the directory, not
the directory itself.
Add tests to verify normal behavior and corner cases.
This release adds configurable mirror support to swupd via the 'mirror'
subcommand. Users can 'set' or 'unset' a mirror and the relevant
configuration files will be placed in /etc/swupd/. If the set mirror is
detected to be a small amount behind the upstream CDN a warning will be
issued to the user. If the mirror is significantly out-of-date the
mirror will be automatically unset to supply the user the most recent
security updates.
SSL certificate failures are now handled specially to provide meaningful
telemetry and error reporting to the user.
Retries are avoided when the contenturl is a file:// url to a local
update directory.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The user does not need to know that swupd is trying to determine the
server version. This is printed twice when doing mirror checks.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Handle updates against configured mirrors by warning or unsetting
out-of-date mirrors. If a mirror is only slightly out of date warn the
user that the mirror is stale but continue normal operations. If a
mirror is out of date by a large range (arbitrary difference of 500, or
about a month and a half) simply unset the mirror and continue using the
upstream url.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The mirror subcommand provides users with an interface to use to set or
unset their configured mirror URL.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
To allow swupd users located in geos far from the default Clear Linux
CDN to get efficient download speeds, allow them to set a mirror content
and version url under
/etc/swupd/mirror_contenturl
/etc/swupd/mirror_versionurl
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Add a specific printf and separate failure code to indicate SSL cert
failures. This return code (24) will be returned to telemetry as well to
indicate this specific failure.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
If content_url is local, do not attempt certain certain download
retries. I've focused on changing only the spots that caused 'make
check' to sleep as a first step. But I agree the retry logic needs
some extra care as posted in #221.
This patch reduces the time of running 'make check' in my system from
2m44s to 24s.
Current idea is to have the manual pages stored in the repo in nroff
format, as well as restructured test format. Users can just use the
nroff. Add test to ensure that the pages match.
Fixes#316Fixes#425
Make sure that running "make" hasn't fixed the local manual pages but
not checked them in.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
This release adds some new features and optimizations to udpates.
* Apply all deltas from the pack, not just the renames identified in the
manifest.
* Do not retry 404 downloads.
* Allow updates to specific version with the -m flag.
Additionally, some other minor issues were fixed, including a bug in
time stat reporting.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Change load_mom to have a variant that can propagate the error code,
and check for that. Use that variant when downloading the
server_manifest. This approach could later be applied to other retries
that involve downloading.
With this patch, "update -m" to a non-published version will not retry
many times before failing.
Allow updating to a version greater than current using -m. Also
supports 'latest' that has the same behavior as not passing any flag.
If the requested version is smaller than the server version (which
is the latest one available in the current format), use that. If not,
use the latest available and re-execute.
Care was taken so that a "update -m LAST_OF_A_BUMP" will not trigger a
re-execution of update.
At the moment version_url is still used, but a future improvement
could avoid it by first looking at the format of the given version
first.
Fixes#257.
Makes life easy to add extra flags without much churn or globals, also
follows what other commands do. This will free main.c to be used by
the real main() of swupd.
Add "swupd verify" options that were missing from the documentation
(swupd.1.rst and swupd.1) but listed by the tool when calling
"swupd verify -h". The order was also slightly changed to be
identical to the order used by "swupd verify -h".
Signed-off-by: Geoffroy Van Cutsem <geoffroy.vancutsem@intel.com>
The two last uses of rename flag were:
- When creating the update list, include old renames present in the
new manifest if the file mentioned in the rename is present in the
current manifest. These would be used to link renames (and try to
unpack relevant deltas).
Why is it OK to remove? Linking renames doesn't happen anymore,
since we get the deltas from other means. The new versions of files
will be included in the update, so we are not missing anything. This
was just making more files available to later steps.
- When consolidating files (i.e. removing duplication), the code
explictly had cases to handle when rename happen or not in case only
one file was deleted.
Why is it OK to remove? In the current code, the side-effect of
having a rename or not doesn't alter the result. This can be seen by
the fact that, at the point cases 2-5 were evaluated, either file1
or file2 are deleted, and that is the only factor that decides which
file to pick. As the code evolved from the time of the comment, this
became more evident.
Updated the commentary in consolidate_files() replacing the table with
a more detailed description of each case (now that we have less
cases). Added some explanations about how we decide with file to pick
when both are present or not present
Consider all deltas from a pack instead of only those who are involved
in a rename. This will allow the server to make better packs
regardless of the from/to version, with the possibility of a delta to
a file that was not necessarily marked with the rename flag.
This makes deltapeer member of file unused, so it was removed. The
peer member continues to be used for its original role: mapping the
same files (same filename) between two manifests, usually the state of
the local system and some new version to be installed.
The test case added is like test/functional/update/rename, but without
the rename flags present. Since in that test there are some fullfiles
missing, it will only pass if swupd-client applies the deltas in the
pack.
This release fixes some more memory management issues with
un-initialized variables and cloned lists and removes the unused
libswupd library.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
The clone of strings lists was creating a copy of the items and adding
to the list, but still keeping the old ones around. Change the
function to just clone the items. This was causing invalid reads when
doing swupd search for a term that has matches, and causing crashes
for some users.
For the record, one of the valgrind reports:
==30978== Invalid read of size 1
==30978== at 0x51FF680: __strcmp_ssse3 (in /usr/lib64/haswell/libc-2.27.so)
==30978== by 0x407C1B: calculate_size (search.c:194)
==30978== by 0x407C62: calculate_size (search.c:219)
==30978== by 0x407C62: calculate_size (search.c:219)
==30978== by 0x4075CD: apply_size_penalty (search.c:240)
==30978== by 0x4075CD: do_search (search.c:715)
==30978== by 0x4075CD: search_main (search.c:898)
==30978== by 0x50B4B36: (below main) (libc-start.c:308)
==30978== Address 0x65484b0 is 16 bytes before an unallocated block of size 0 in arena "client"
This release fixes the 2TB contentsize limit check and adjusts the
swupd-client.timer unit to check for updates more frequently.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
We know these are cheap and our CDN takes care of the actual
bulk of the bandwith.
Spread the update checks between 45min0sec and 1hr33mins
effectively.
This release makes some bug and memory management fixes.
* swupd-add-pkg bug that prevented creating a local bundle with the same
name as the package it includes was fixed.
* A bug that caused bundle-list to print garbage for systems with a
large number of bundles was fixed.
* The swupd completion code was updated and filename completion for
swupd hashdump was added.
* Protect against bogus filecount heap corruption.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>