1284 Commits
Author SHA1 Message Date
Otavio Pontes ae61186bbd Release v3.20.0
This release adds enhancements, bug fixes and test improvements.

Enhancements:
 - Integrate local search script into swupd
 - Introduce new command search-file to search files in the system
 - Support machine readable output using json on all swupd commands
 - Fallback to system config for value of content and version urls and format
 - Report progress based on download size and not on number of files downloaded
 - Create three new commands to replace different usages of verify: diagnose,a
   os-install and repair

Bug Fixes:
 - Don't run update or boot scripts if they don't exist
 - Fix invalid memory access on curl hashmap usage
 - Don't try to create new threads if not supported in the system
 - Overall review and multiple fixes on standard C API function calls
 - Fix some found memory leaks

Tests/Code quality:
 - Add unit tests to functions hard to test using functional tests
 - Improve format bump functional tests to include a minversion
 - Add test for delta manifests
 - Multiple improvements in test library and travis script
 - Mutiple code rework and improvements on documentation and readability
v3.20.0
2019-05-28 21:50:33 -07:00
Otavio Pontes 232351cd25 curl: Add extra warning on check_connection errors 2019-05-28 20:18:51 -07:00
Castulo Martinez 5ccb839148 Sorting swupd menu
This commit sorts the swupd main menu in a way that makes more sense.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-29 03:10:29 +00:00
Castulo Martinez eb0ed74cde Fix a line break when running "swupd repair"
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-29 03:10:06 +00:00
Castulo Martinez a89f61e4e8 Fixing false positive in a test
The update/update-json.bats functional test is giving a false positive
since one hardcoded value (time) was taking longer to run, than in a
local environment.
This commit fixes the issue by using a regex to accept any time value.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-29 03:09:48 +00:00
Otavio Pontes e06c7e8628 test: Fix space that was removed by accident in previous commit
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-05-28 20:07:41 -07:00
Otavio Pontes e777d1a1e4 global: Remove trailing slashes on content and version URLs
We always append an extra '/' at the end of the URL and some webservers doesn't support
multiple slashes connected. So always removing last '/' on URLs.
2019-05-24 22:44:24 +00:00
Castulo Martinez a3131db0fe Adding the -V / --version flag to swupd commands
swupd uses the -m / --manifest flag for some commands to specify what
version to use for that specfic action. For example using "swupd verify
--install --manifest=10" will attempt to install the OS with version 10.
The problem is that this flag doesn't really hint users about what the
flag is used for, specially if the user is not familiar with swupd / mixer
internals.

This commit adds a replacement flag -V / --version that will have the
exact same functionality of -m / --manifest which will be deprecated.
The deprecated flag should be removed in 6 months time.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-24 20:57:09 +00:00
Otavio Pontes 47166cd3c8 global: Use system format number as a fallback if there's no format number in path_prefix 2019-05-24 19:33:55 +00:00
Otavio Pontes e21e681cd6 global: Fallback to system configuration when configuration on path_prefix
If --path is used swupd looks for version and content url inside the informed chroot path.
This is the expected, but in some cases not enough. When installing a CL we usually point to
an empty chroot. So if there's no config file inside the chroot, fallbacks to system configuration.

Fixes #924
2019-05-24 17:25:55 +00:00
Otavio Pontes 5917c570cb mirror: Don't enforce root if mirror command is used in read-only mode
Fixes #926

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-05-20 22:50:47 +00:00
Otavio Pontes 41ac4f76f3 check_update: Unify check_update and update -s
Update --status is now calling code on check_update.

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-05-14 15:51:47 -07:00
Otavio Pontes 80c6568a5f globals: Make swupd_init more generic
With a more generic swupd_init command we can use it in all swupd commands to
initialize swupd in a consistent manner.

Also renaming init_globals and free_globals to a more standard name.

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-05-14 15:51:47 -07:00
Otavio Pontes 74e7021655 helpers: remove unecessary wrapper for free 2019-05-14 15:51:47 -07:00
Castulo Martinez 2cb0dd80b4 Renaming "swupd verify" to "swupd diagnose"
This commit renames the "verify" command to "diagnose" to make it
more straightforward for the user to understand the purpose of the
command.

Closes #918

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-14 15:51:28 -07:00
Castulo Martinez dc8e9235d5 Making verify --fix a top-level command
The purpose of "swupd verify --fix" is to repair local issues relative
to a server manifest. However the verify command currently has many
flags, and some flags are mutually exclusive, this makes the command
very confusing to use for users.

This commit makes "swupd verify --fix" the top level command
"swupd repair". This new command still uses the verify code under the
covers.

Closes #914

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-14 14:33:49 -07:00
Otavio Pontes a4c00b4ed9 test: Move unit test datas to data/ directory
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-05-14 14:28:27 -07:00
Otavio Pontes a3a58b7319 test: Adding extra tests for signature
Test if certificates with Authority Information Access property set as critical
aren't used to validate swupd content.

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-05-14 14:28:27 -07:00
Otavio Pontes 1b2761fd01 signature: Fix memory leak in certitificate file
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-05-14 14:28:27 -07:00
Otavio Pontes 852c70d8d2 sys: Adding helper to dirname and path_join
Dirname() is a very tricky function to use. Create a wrapper to make it a
lot easier. The only downside is an extra strdup, but it's worth it.

sys_path_join() is a function to make it easier to concatenate 2 paths using
correct separator and avoid duplicated '/'

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-05-14 14:28:27 -07:00
Castulo Martinez a84c60a500 Making verify --install a top-level command
The purpose of swupd verify --install is so it can be used to install
a new Clear OS in a target system. However since currently it is part
of the swupd verify command it makes it confusing as of to what its
purpose is.

This commit moves the swupd verify --install option to be a top level
command (swupd os-install) so its purpose is more straightforward. The
new command still uses the verify code to perform the task underneath.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-14 14:26:30 -07:00
Alex Jaramillo 65f22401f6 Set user-agent header for swupd
This change sets swupd client User-Agent header to PACKAGE/VERSION,
this is a standard HTTP header to identify the client that originates
a request.

Signed-off-by: Alex Jaramillo <alex.v.jaramillo@intel.com>
2019-05-13 14:48:47 -07:00
Castulo Martinez 2f03f946f7 Overwriting old content during bundle-add
When swupd is installing a bundle, it goes through the list of files to
install and removes those files that already exist in the target system
from the list, regardless of if the files were added by other bundle or
not.

This commit changes this process so the file is removed from the
list of files to install only if the file is listed as installed in the
manifest of one of the already installed bundles. This way if the file
is already present in the system, but not listed in any other manifest
it can be overwritten since we cannot assume the file is correct.

Closes #863
2019-05-13 14:38:20 -07:00
Castulo Martinez 3768d5cfc6 Removing unecessary recursion in bundle-add
When staging a file using do_staging(), if the path of the file is
missing verify_fix_path() is called to try fix the missing path.
verify_fix_path() then removes bad directories (if any), downloads the
file and again and stages the new directory using do_staging() again, doing
a circular reference. On top of this bundle add is calling
verify_fix_path() after running do_staging(). All this circular
reference makes the code very difficult to understand and may cause
swupd to do extra work that is not necessary. This commit simplifies the
code by not allowing do_staging() to call verify_fix_path() so we can
manually call it later if necessary.

This commit also add some more comments in the code to make it easier to
follow.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-13 14:38:20 -07:00
Castulo Martinez a7cf50d360 Improving output messages in bundle-add
Adding messages where swupd could take some time to finish a step so
users know better where the process is at.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-13 14:38:20 -07:00
Castulo Martinez a2593a556e Print the json output to stdout instead of stderr
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-13 14:29:27 -07:00
Otavio Pontes 3e7721583d swupd.bash" Remove extra " when setting COMPREPL
Bash completion was adding line breaks because of that extra " on COMPREPLY

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-05-10 12:43:06 -07:00
Castulo Martinez 2d29ae07f4 Removes iter manifests from bundle-add completion
There is a bug in the code that causes swupd bundle-add <TAB><TAB>
to list regular bundle names as well as iterative manifest names.

This commit fixes the issue by removing the iterative manifests from
the list of results.

Closes #906

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-09 15:33:00 -07:00
Castulo Martinez 755c5549a0 Update the copyright to 2019
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-05-09 14:50:07 -07:00
Otavio Pontes c0703398a0 sys: Adding a missing --no-block flag on call that shouldn't block
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-24 09:32:59 -07:00
Otavio Pontes 6c4b44ac37 docs: Use doxygen style on header API documentation
Documentation coverage on src/lib is now 100% and the goal is to eventually
reach that for everything on src/.

Also improve some documention on headers.
2019-04-23 14:59:43 -07:00
Otavio Pontes 798665efb5 docs: Check API documentation coverage
Add command docs-coverage on Makefile and run that on travis builds. For not only enforcing
a 100% coverage on headers inside src/lib/

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-23 13:27:10 -07:00
Otavio Pontes d4ddcb2c9a docs: Use doxygen style on header API documentation
Documentation coverage on src/lib is now 100% and the goal is to eventually
reach that for everything on src/.

Also improve some documention on headers.
2019-04-23 13:27:10 -07:00
Otavio Pontes 30f4ec4436 docs: Add a doxyfile to make it easier to check documentation coverage 2019-04-23 13:27:10 -07:00
Otavio Pontes eb6371afa5 curl: Use a struct declaration instead of void pointers
We can declare the scruct in a header file and define it in a source file so
we can avoid using void pointers for the handle. It's a better approach because
compilers can trigger errors if we use a different type.

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-18 13:30:26 -07:00
Castulo Martinez eb694590a4 Re-enable the json tests
The json tests had been disabled because they were unstable. This issue
was fixed in a previous commit, so these tests should be enabled again.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-04-18 10:29:49 -07:00
Castulo Martinez 755e7e1527 Use swupd_progress_callback for fullfile download
This commit makes use of the swupd_progress_callback() function to
report progress downloading fullfiles based on how much data we have
downloaded vs the number of files downloaded. This callback will only be
used when the number of files to be downloaded are less than MAX_FILES,
calculating the total download size can be very costly if the files are
too many. If the files to be downloaded are more than MAX_FILES we will
fallback to reporting download progress based on file count as before.

When installing bundles or doing updates, swupd creates a list of files
that need to be downloaded. This list may contain files that were
already downloaded via packages and it often does. These files are then
skipped at the moment of downloading them since they are already in the
system. This causes a misleading output that shows the user that
fullfiles will be downloaded when they are actually not.

This commit filters the list of fullfiles to be downloaded to only
contain those ones that actually need to be downloaded.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-04-18 10:29:49 -07:00
Castulo Martinez d7210882e6 Use the swupd_progress_callback for packs download
This commit makes use of the swupd_progress_callback() function to
report progress downloading packs based on how much data we have
downloaded vs the number of files downloaded.

This commit also fixes a bug in the download_subscribed_packs function.
Swupd was not downloading the correct pack for bundles not installed in
the system that had been recently added as dependency of another
installed bundle.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-04-18 10:29:49 -07:00
Castulo Martinez 591aef2ebe Report progress based on downloaded content
When swupd reports progress of content it needs, it does so by counting
how many files it needs to download (fullfiles or packs) and how many it
has already downloaded. This gives a rough estimate of what is the
progress of the overall download, but it can also be very misleading
since some files may be very different in size compared to others. This
is specially true when talking about packs, one pack could be a couple
of megabytes big while another one could be a few hundred megabytes.

This commit adds a curl callback that can be used to report download
progress periodically based on how many bytes have been downloaded vs
how many bytes have to be downloaded in total, giving the ability to report
progress accurately.

Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
2019-04-18 10:29:49 -07:00
Otavio Pontes db512848c7 signature: Add a unit test for signature
Create a unit test for signature checking.

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-18 10:20:41 -07:00
Otavio Pontes 18939abdcc signature: Add check for OCSP when checking the certificate
If OCSP is enabled in the certificate and key usage is set as critical we
need to use OCSP to check if the certificate was revoked. As OCSP isn't
supported on swupd, just abort the operation.

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-18 10:20:41 -07:00
Otavio Pontes 62a9f81ed2 signature: remove signatures safeguard from global file
We don't need to protect with SIGNATURES ifdef everywhere, just on signature.c

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-18 10:20:41 -07:00
Otavio Pontes 47c61f8658 signature: Move swupd specific code away from signature
Make it more generic. Now it's possible to validate any signature, not only MoMs

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-18 10:20:41 -07:00
Otavio Pontes 88101532bc macros: Move UNUSED_PARAM to macros
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-18 10:20:41 -07:00
Otavio Pontes 58aa0c28af signature: Don't use global variables when not needed
Local variables should be kept local and been freed in local context.
Don't keep them global unless used out of context.

Also adding parameter for CRL. So it's now enabled on signature, but not
used on swupd.

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-18 10:20:41 -07:00
Otavio Pontes 8876b55c22 signature: Removing unused variable
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-18 10:20:41 -07:00
Otavio Pontes cd3637adfd Signature: Check if signature should be checked in a more appropriate context
Take this global check from signature module. Users of signature checker
should worry if you are or aren't going to check the siganure. Module should
always check that.

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-18 10:20:41 -07:00
Otavio Pontes 6d2ab6a20c signature: Minor changes in style to make code style consistent
- Renaming functions
 - improvements in comment headers
 - Minor .h style changes

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-18 10:20:41 -07:00
Otavio Pontes 22f68e4981 swupd: Don't include libcurl headers
We have a layer isolating curl API calls, so don't include libcurl
headers on swupd.h.

Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-17 12:05:47 -07:00
Otavio Pontes c4db7f30fd globals: Replace tabs for spaces on printf
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2019-04-17 08:31:44 -07:00