This release adds enhancements, bug fixes and test improvements.
Enhancements:
- Integrate local search script into swupd
- Introduce new command search-file to search files in the system
- Support machine readable output using json on all swupd commands
- Fallback to system config for value of content and version urls and format
- Report progress based on download size and not on number of files downloaded
- Create three new commands to replace different usages of verify: diagnose,a
os-install and repair
Bug Fixes:
- Don't run update or boot scripts if they don't exist
- Fix invalid memory access on curl hashmap usage
- Don't try to create new threads if not supported in the system
- Overall review and multiple fixes on standard C API function calls
- Fix some found memory leaks
Tests/Code quality:
- Add unit tests to functions hard to test using functional tests
- Improve format bump functional tests to include a minversion
- Add test for delta manifests
- Multiple improvements in test library and travis script
- Mutiple code rework and improvements on documentation and readability
The update/update-json.bats functional test is giving a false positive
since one hardcoded value (time) was taking longer to run, than in a
local environment.
This commit fixes the issue by using a regex to accept any time value.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
We always append an extra '/' at the end of the URL and some webservers doesn't support
multiple slashes connected. So always removing last '/' on URLs.
swupd uses the -m / --manifest flag for some commands to specify what
version to use for that specfic action. For example using "swupd verify
--install --manifest=10" will attempt to install the OS with version 10.
The problem is that this flag doesn't really hint users about what the
flag is used for, specially if the user is not familiar with swupd / mixer
internals.
This commit adds a replacement flag -V / --version that will have the
exact same functionality of -m / --manifest which will be deprecated.
The deprecated flag should be removed in 6 months time.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
If --path is used swupd looks for version and content url inside the informed chroot path.
This is the expected, but in some cases not enough. When installing a CL we usually point to
an empty chroot. So if there's no config file inside the chroot, fallbacks to system configuration.
Fixes#924
With a more generic swupd_init command we can use it in all swupd commands to
initialize swupd in a consistent manner.
Also renaming init_globals and free_globals to a more standard name.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
This commit renames the "verify" command to "diagnose" to make it
more straightforward for the user to understand the purpose of the
command.
Closes#918
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
The purpose of "swupd verify --fix" is to repair local issues relative
to a server manifest. However the verify command currently has many
flags, and some flags are mutually exclusive, this makes the command
very confusing to use for users.
This commit makes "swupd verify --fix" the top level command
"swupd repair". This new command still uses the verify code under the
covers.
Closes#914
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Test if certificates with Authority Information Access property set as critical
aren't used to validate swupd content.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Dirname() is a very tricky function to use. Create a wrapper to make it a
lot easier. The only downside is an extra strdup, but it's worth it.
sys_path_join() is a function to make it easier to concatenate 2 paths using
correct separator and avoid duplicated '/'
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
The purpose of swupd verify --install is so it can be used to install
a new Clear OS in a target system. However since currently it is part
of the swupd verify command it makes it confusing as of to what its
purpose is.
This commit moves the swupd verify --install option to be a top level
command (swupd os-install) so its purpose is more straightforward. The
new command still uses the verify code to perform the task underneath.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This change sets swupd client User-Agent header to PACKAGE/VERSION,
this is a standard HTTP header to identify the client that originates
a request.
Signed-off-by: Alex Jaramillo <alex.v.jaramillo@intel.com>
When swupd is installing a bundle, it goes through the list of files to
install and removes those files that already exist in the target system
from the list, regardless of if the files were added by other bundle or
not.
This commit changes this process so the file is removed from the
list of files to install only if the file is listed as installed in the
manifest of one of the already installed bundles. This way if the file
is already present in the system, but not listed in any other manifest
it can be overwritten since we cannot assume the file is correct.
Closes#863
When staging a file using do_staging(), if the path of the file is
missing verify_fix_path() is called to try fix the missing path.
verify_fix_path() then removes bad directories (if any), downloads the
file and again and stages the new directory using do_staging() again, doing
a circular reference. On top of this bundle add is calling
verify_fix_path() after running do_staging(). All this circular
reference makes the code very difficult to understand and may cause
swupd to do extra work that is not necessary. This commit simplifies the
code by not allowing do_staging() to call verify_fix_path() so we can
manually call it later if necessary.
This commit also add some more comments in the code to make it easier to
follow.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Adding messages where swupd could take some time to finish a step so
users know better where the process is at.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
There is a bug in the code that causes swupd bundle-add <TAB><TAB>
to list regular bundle names as well as iterative manifest names.
This commit fixes the issue by removing the iterative manifests from
the list of results.
Closes#906
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Documentation coverage on src/lib is now 100% and the goal is to eventually
reach that for everything on src/.
Also improve some documention on headers.
Add command docs-coverage on Makefile and run that on travis builds. For not only enforcing
a 100% coverage on headers inside src/lib/
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Documentation coverage on src/lib is now 100% and the goal is to eventually
reach that for everything on src/.
Also improve some documention on headers.
We can declare the scruct in a header file and define it in a source file so
we can avoid using void pointers for the handle. It's a better approach because
compilers can trigger errors if we use a different type.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
The json tests had been disabled because they were unstable. This issue
was fixed in a previous commit, so these tests should be enabled again.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit makes use of the swupd_progress_callback() function to
report progress downloading fullfiles based on how much data we have
downloaded vs the number of files downloaded. This callback will only be
used when the number of files to be downloaded are less than MAX_FILES,
calculating the total download size can be very costly if the files are
too many. If the files to be downloaded are more than MAX_FILES we will
fallback to reporting download progress based on file count as before.
When installing bundles or doing updates, swupd creates a list of files
that need to be downloaded. This list may contain files that were
already downloaded via packages and it often does. These files are then
skipped at the moment of downloading them since they are already in the
system. This causes a misleading output that shows the user that
fullfiles will be downloaded when they are actually not.
This commit filters the list of fullfiles to be downloaded to only
contain those ones that actually need to be downloaded.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit makes use of the swupd_progress_callback() function to
report progress downloading packs based on how much data we have
downloaded vs the number of files downloaded.
This commit also fixes a bug in the download_subscribed_packs function.
Swupd was not downloading the correct pack for bundles not installed in
the system that had been recently added as dependency of another
installed bundle.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When swupd reports progress of content it needs, it does so by counting
how many files it needs to download (fullfiles or packs) and how many it
has already downloaded. This gives a rough estimate of what is the
progress of the overall download, but it can also be very misleading
since some files may be very different in size compared to others. This
is specially true when talking about packs, one pack could be a couple
of megabytes big while another one could be a few hundred megabytes.
This commit adds a curl callback that can be used to report download
progress periodically based on how many bytes have been downloaded vs
how many bytes have to be downloaded in total, giving the ability to report
progress accurately.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
If OCSP is enabled in the certificate and key usage is set as critical we
need to use OCSP to check if the certificate was revoked. As OCSP isn't
supported on swupd, just abort the operation.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Local variables should be kept local and been freed in local context.
Don't keep them global unless used out of context.
Also adding parameter for CRL. So it's now enabled on signature, but not
used on swupd.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Take this global check from signature module. Users of signature checker
should worry if you are or aren't going to check the siganure. Module should
always check that.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>