This release make several bug fixes and implementation improvements as
listed below:
* Fix memory leak on subscription list
* Add missing --nosigcheck option to search subcommand
* Better memory management in some codepaths
* Report missing packs to telemetry (when user is opted-in)
* Unused/commented-out code removed from codebase
* Improve the internal swupd_curl API, including making it more usable
and performing better memory management.
* Remove content when running swupd clean and only keep manifests around
* Add fullfile fallback to bundle-add code.
* Refactor bundle-remove to properly remove multiple bundles.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
In order to avoid the need to dereference *bundles all the time
another variable was added.
The check about making sure the bundle to be removed is not os-core
was moved before the message "Removing bundle: <bundle>" to avoid
confusions.
When 1 or more bundles fail to be removed from the system a message
was being displayed, a message that looked like this:
"1 bundle(s) of 2 failed to remove"
This commit changes that message so it uses pasive voice, like this:
"1 bundle(s) of 2 failed to be removed"
The current remove_bundle() function was designed to only be called
once, but for multiple bundle removals, it is currently called
multiple times.
This commit refactors this function so the bundle removal code can
handle multiple bundles at once.
Fixes#449
Use fullfile_download to download full files from server if a pack
download has failed or if the file is missing/corrupted in a pack.
Verify --install wasn't checking if the content of the downloaded
files match the hash in the manifest. As the fullfile download
function check that, the hashes in some tests needed to be fixed.
Use download_fullfiles() instead of reimplementing it on
full_download_loop().
Tests:
- Test skip-verified-fullfiles was alterered because in the current
implementation start_full_download() won't be called when there's no
extra file to download.
Moving the fullfile fallback to a single file and exporting it in
swupd.h in order to be reused on update and bundle add.
Tests:
- Changing verify tests becase download function won't be called when
there's no file to be downloaded
Checking for hashes inside the download function was out of scope
and made the function harder to be reused. Instead, check if hashes
matches the files in the system before calling the download function,
so only necessary files will be downloaded.
There's no way to inforce braces on single line ifs using clang-format.
Adding a grep to look for ifs without a bracket so we can at least
warn users about that.
In most cases the parameters in_memory_file, bool resume_ok are ignored
in swupd_curl_get_file. So creating a swupd_curl_get_file_full with all
parameters and leaving the swupd_curl_get_file clearer.
Curl module doesn't need to have any information on what is the content of
the file it's going to download. And there's no reason to force users to
use memory to store a file only for version numbers. If there's another
small file needed in the future, we can use the memory to hold it.
Also fixes:
- Memory allocated for version string was too big. Using maximum number of
chars to store an integer for it.
- As the size to store a version string is small, uses the stack instead of
the heap for it.
- On swupd_curl_test_resume, don't alocate memory and copy data to it
to be discarded later.
All #warnings messages on swupd code were related to tasks to be performed
in the future and not real code warnings. Using the TODO comment, that is
already used for other tasks.
It's too annoying to see warning messages on compile time and having them
makes a bit harder to noticed when we are introducing real compiler warnings.
Message informing that the system was successfully updated should be
the last message. Having a message that looks like an error as the
last message in an update can be confusing for users.
Fixes#454
Added the -n/--nosigcheck paramater to search, based on the other subcommands that
already have nosigcheck.
I tested this by invalidating Swupd_Root.pem and testing the failing
and passing cases - without nosigcheck and with nosigcheck
respectively.
Signed-off-by: Brian J Lovin <brian.j.lovin@intel.com>
We use a full feature version control system (git) for a reason.
'non-production' code can be kept on each one favorite personal branch
and debug code, if key for development, should be implemented as
working/tested part of the project (via a well designed logging system)
and not as commented code.
Not to mention that this is be a best pratice which we should all watch
over.
Signed-off-by: Murilo Belluzzo <murilo.belluzzo@intel.com>
This release cleans up some code to declare functions as static when
appropriate and fixes a few mixer integration bugs.
* Write the valid-mix flag file in swupd-add-pkg
* Add some more state files to the ignore list for file collision
checking.
* Check for file collisions *after* a new local build so updates to
os-core are detected.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Fixes#446
When a new upstream version is detected the new local mixer build must
be done before manifest uniqueness is checked. This is due to the fact
that os-core can change in the upstream version, so it has to be
re-built locally against the upstream content in order to avoid false
positives for file colisions.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
These additional files are files that change on the system due to the
local mix. Add these to the ignore list for file colision checks.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
swupd-client expects a .valid-mix file to exist in MIX_DIR when a valid
mix exists. Create this file after creating the mix.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Reformat the .travis.yml file to have shorter lines, and add 'make
install' as a step to get the scripts/fixstatic.pl program to run.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Fixes#448
Make a number of functions static, and bodge around the extra symbol
that gcc adds (__gnu_lto_v1) when compiling with -flto=4
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
This release updates mixer integration capabilities to use the latest
mixer/mixin features and configuration files and removes copyright
header prints from standard commands.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Update mixer integration to key off the .valid-mix flag file to check if
a mix exists. Also update the .clearversion filename to upstreamurl (it
has changed in upstream).
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
swupd-client is properly open-sourced and licensed. The copyright header
is unnecessary, confusing, and causes issues for scripts parsing output.
The copyright header is now only printed when swupd is passed the
--version flag.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release removes sudo invocations in the swupd-add-pkg program and
rely on the user to run under sudo themselves. The /etc/swupd
configuration directory is now created with more open permissions to
allow users to view the configuration on their system.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Instead of doing this behind the user's back expect them to do it
themselves. This also removes the inconsistencies of running some
commands with sudo -E and others without -E. If users want to provide -E
let them do it themselves.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Set /etc/swupd permissions to 0777 to let the default umask policy
handle stripping bits appropriately.
If we can write files to /etc/swupd, do it, making the directory first,
if necessary. If not, bail out cleanly. Only delete the
mirror_contenturl and mirror_versionurl files from the directory, not
the directory itself.
Add tests to verify normal behavior and corner cases.
This release adds configurable mirror support to swupd via the 'mirror'
subcommand. Users can 'set' or 'unset' a mirror and the relevant
configuration files will be placed in /etc/swupd/. If the set mirror is
detected to be a small amount behind the upstream CDN a warning will be
issued to the user. If the mirror is significantly out-of-date the
mirror will be automatically unset to supply the user the most recent
security updates.
SSL certificate failures are now handled specially to provide meaningful
telemetry and error reporting to the user.
Retries are avoided when the contenturl is a file:// url to a local
update directory.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>