This release adds enhancements, bug fixes and test improvements.
Enhancements:
- Remove dependency on verifytime binary
- Prettier --time outputs
Bug Fixes:
- Don't fail an update if a bundle is removed on server
- Inform out of disk errors on download failures
- Fix TOCTOU problem when verifying system time
- Adjust system time on check-updates to assure signature
validation will work
- Fix error on output of verifytime when errors occurred.
- Behavior of verify and verify --fix is know consistent
- Fix incorrect --time output on bundle-add
- Use correct permissions when creating parent for statedir directory
- Apply system locale on swupd to avoid warnings on filename conversions
- Don't affect autocomplete behavior on a verify --fix
Tests
- Adding new tests and improvements to existing tests
- Full tests reorganization to have a better view on the total
functional test coverage
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
As we aren't saving the MoM in a directory we were reading to look for
bundles, we don't need to save it as a hidden file.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
One test was removed: update-apply-full-file-delta.bats (it was a
duplicate of test/functional/update/update-use-pack.bats)
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
swupd copies the latest MoM to /usr/share/clear/bundles/.MoM so we
can use it for bash completion. The problem is that this directory
is tracked by clearlinux and because of that "swupd verify --picky"
will list this file as an extra file. And "swupd verify --fix --picky"
will remove that file.
This commit fixes the issue by changing the location where the .MoM
is copied to being this an untracked location, so the file won't be
removed.
Closes#632
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
The --force option is included in bundle-add, bundle-remove,
check-update, update and verify, but it is really only used in
verify.
This commit removes the option from the commands that are not using
it so it is not misleading to users. If at some point we need to
implement somthing with --force it can be added back at that point.
Closes#636
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Adding ID to search tests and changing the description of some of
them to make them clearer.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Changing the way time is displayed when using the --time option so it
shows as a tree view so it is easier to see what items are sub-tasks
of other tasks.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When the system time is way off, the certificate validation will
fail. For this reason, many swupd commands attempt to fix the
system time if wrong. check-update was not doing this so the
command would fail in this situation.
This commit adds a verification for this so check-update attempts
to fix the system time and continue instead of failing.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
There was some confusion about shell return code and bools.
Shell returns 0 for true and bools are 0 for false.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Swupd state dir should be masked as 700, but we can't mask all parent directories
as 700. This is particularly a problem because /var and /var/lib/ shoudn't
be 700, but /var/lib/swupd should. So creating all folders with current
umask and using chmod syscall to set only the swupd statedir diretory to
root only
Also, stop using mkdir_p where are no longer needed
Fixes#655
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Adding an ID to all bundle-list tests and rewording some of the
test descriptions to make it more readable.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When xattr is disabled in a build, use a dummy implementation of the API
instead of counting on dummy implementation of the functions used by xattr.
By doing that we are clearer on the output of the functions, less code
executions and we get rid of a dead code.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Instead on counting with the verify time in the system, link swupd
with verifytime lib.
This reduces one point of failure of swupd on recovering a corrupt system.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Some verify --install tests were submitted some time ago before we
started using IDs for tests, so these tests are missing the ID.
This commit add those missing IDs and make a couple of improvements
in the tests.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
The check-update tests should use a group code of CHK, but the
test library was using AUT incorrectly which belongs to the autoupdate
tests.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Option --time/-t can be used with bundle-add to show verbose time
output for swupd operations. At the moment it is showing the info
incorrectly. It is showing the data twice and the times showns are
off.
This commit fixes the bug.
Closes#675
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Modify the set_time() function used in verifytime.c to take a single
argument instead of two. The second argument that was previously used
can easily be derived from the first and it avoids situations where
these two are not coherent (which happens to the case in the current
version of verifytime.c)
Signed-off-by: Geoffroy Van Cutsem <geoffroy.vancutsem@intel.com>
This commit adds the test ID to every bundle-remove test, removes
duplicates and make readability improvements.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit adds some missing tests for "verify --picky", the rest
of the tests were added recently as part of other commits.
This commit also add the test ID to every verify test, and remove
duplicates.
Closes#315
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Running "swupd verify" should be a dry-run of running
"swupd verify --fix", meaning that "swupd verify" should find
the same issues to be resolved than "swupd verify --fix" but it
should just inform about them while --fix should inform + fix them.
In occasions this does not happen, for example when there are
tracked files that need to be removed from the system.
This commit fixes that.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit adds some tests to validate consistency
between "swupd verify" and "swupd verify --fix".
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
We can't assume that the file wasn't deleted between the execution of a
stat and a fopen. Printing error only when fopen fails.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Currently some of the output from swupd can be cryptic when
files fail to download. Add a hint to the user to check
their free space if Curl returns write errors.
Closes#486
Signed-off-by: Brian J Lovin <brian.j.lovin@intel.com>
If a bundle happens to be removed from the content server (or mix) it
means the bundle won't be in the MoM anymore, so the bundle in the
system will look like an invalid bundle. When this happens the update
is currently stopping.
This commit fixes this so If this happens, the user is informed, and
the update continues.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Adding an update test for the case when a bundle is removed upstream
from the content server (or from a mix).
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Tests will be cleaned up by a trap routine when interrupted early. This
change also moves test web server and certificate store clean up to the
destroy_test_environment function.
Signed-off-by: John Akre <john.w.akre@intel.com>
Some tests wrote files and directories to /tmp. This change moves the
test certificates directory into the swupd repo's top level directory
and moves other test files into their corresponding test directories.
Fixes#650
Signed-off-by: John Akre <john.w.akre@intel.com>
Also:
- remove unnecessary mkdir lines from tests
- Check if /core file is present in install-multiple test
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
This adds several tests for os installation functionality.
* install - regular installation of just os-core
* install-multiple - install os-core and a test-bundle
* install-bad - attempt to install an invalid bundle name
* install-no-zero-packs - install os-core and test-bundle with no
zero-packs available. Fullfiles still available as a fallback.
* install-no-fullfile-fallback - attempt to install with no zero packs
and no fullfiles available for fallback.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
This release fixes some bugs and add tests improvements.
Bug fixes:
- Fix support for openssl 1.1
- Bash completion for bundle-remove wasn't complete
- Print error message when disk is full on a tarball extration
Tests
- Running static analysis of all bat tests automatically and reported problems
were fixed.
- Test Makefile was problematic and some tests were skiped
- More tests added
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Curl isn't closing urandom and random when using openssl 1.1. As it's something
out of our control and this won't create any resource leak problems, we're not
reporting that anymore.
This fd leak report is triggered when any https download is performed by swupd
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
The purpose must be set explicitly now for the verification to
succeed, and in our case we must use "any" as defined in the generated
certificate purpose.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The ERR_remove_thread_state() function is deprecated as the thread
handling and many memory management operatoins have been re-written to
be internally handled by the API. The error code should be retrieved
by the proper function now from X509 store contexts.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Libarchive's archive_error_string() method returns a textual
error message suitable for display.
However, this method returns only "Write Failed" if libarchive
runs out of hard disk space.
Check specifically for ENOSPC and print a correct
warning message to the user.
Signed-off-by: Brian J Lovin <brian.j.lovin@intel.com>
There is a missing line break that shows up When running
the "swupd verify" command and there is a hash mismatch.
The output looks like this:
$ sudo swupd verify
Verifying version 25590
Verifying files
...1%Hash mismatch for file: /usr/bin/tmux
...100%
Inspected 292278 files
1 files did not match
Verify successful
This commit fixes the issue by adding a line break at the
beginning of the output.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
The list is missing a "\" at the end of one test which is causing
a group of tests to be ignored by the makefile, therefore they are
not being run.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Every test should include a unique ID, so it is necessary to have
a way of knowing what is the next available ID for the group of
tests.
This commit helps with that issue by implementing the following
features in the test library:
- Adds the function get_test_list which can be used to print a
list of tests in a specific group directory.
- Adds the function get_next_available_id which return the next
test ID that can be used in a new test.
- When using the generate_test function to generate an empty test
the next available ID will be used for the template.
This commit also adds the ID to a bundle-add test that was missing it.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>