When doing a system install with "os-install --bundles" if the list of
bundles to install includes only "os-core" the install fails.
This commit fixes the issue.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
The iterative manifest effort was droped so this commit removes the
iterative manifest support from testlib.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Implementation of the 3rd-party info command to show the version of the
3rd-party repository along with the update URL.
Closes#1354
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit allow users to force the deletion of corrupt 3rd-party repos
which will end up deleting most of the repo's files, except for the
scripts that exported files from that repo.
Closes#1343
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When adding an upstream bundle, we apply some heuristics to the bundle
files and based on that some files are skipped from being installed.
These heuristics don't apply to 3rd-party bundles.
This commit skips running heuristics when adding 3rd-party bundles.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Sometimes a test fails before finisihing to create all the required
directories under the testdir. So destroy_environment thinks this is
not a valid test environment.
Touching a dot file to show that the directory is a test environment
instead on counting on its content.
Fixes bug #1135
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
When a symlink is added to a 3rd-party repository it will be broken
on the statedir and stat command will fail. We need to use lstat, to
get information about the symlink and not the file that it's pointing
to.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
The repo.ini file was being created in the swupd state directory, this
was not ideal since it prevented the state directory from being used for
multiple target paths.
This commit moves the repo.ini file out of the state directory and into
the 3rd-party content directory.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
The testlib had two functions to create 3rd-party repositories that were
very similar but with only one difference, one function only created the
3rd-party repo, the other one created the repo and also added it as if
the user had already done a "swupd 3rd-party add" on it.
This commit merges both functions into one to avoid code duplication,
make the test library easier to maintain, and make it less confusing.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When in a 3rd-party repository one bundle has one binary file that
is exported, and the same file is included in another bundle, only
it is not exported in this bundle, when we remove the bundle that
exports the file, the file should be unexported regardless of the file
still being installed since the bundle that is still in the system is
not exporting it.
Closes#1322
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When trying to add the repository for the first time, download the public
certificate published by the 3rd party repository and with a user confirmation,
use it to install the 3rd-party os-core. After that the official certificate will
be installed for future commands.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Some commands were recently added to swupd which require user
interaction under certain circumstances, when this happens the user has
to manually enter either Y/N to continue or abort the current process.
This commit provides a --non-interactive=<yes/no> flag that can be used
to avoid getting this interactive prompts.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
If an update of 3rd-party content includes files with dangerous flags,
the user should be notified and the update should only continue if the
user accepts the risk, otherwise the update should be aborted.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
If a 3rd-party bundle include files that have either the setuid, setgid
or sticky bits set, then it should not be installed since they could
compromise the security of the system. In this case the user should be
asked to see if they want to assume the risk and continue, or abort the
process.
Closes#1281Closes#1282
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This patch adds 2 scripts used to balance test execution. The weight_tests.bash
runs all tests and sets a weight to them based on how long they take to run. The
other, filter_bats_list.bash, use this information to split the tests in groups to
be executed by github actions.
When a new test is added the script will consider it with an average weight, so this
shouldn't unbalance the system right away. After some time, if we notice that the
system is not balanced anymore we can just run the weight_tests.bash again to rebalance.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
When a 3rd-party repository is updated, if one of the updated bundles
has updated binaries, the scripts that export those binaries should also
be updated. This commit implements that update.
Closes#1279
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When a 3rd-party repository is removed, all the content installed from
it must be removed from the system. But also those exported binaries
from the repo being deleted should also be deleted.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When removing a 3rd-party bundle, all scripts that export the binaries of
the bundle should be removed from the target system unless they are still
required by another installed 3rd-party bundle.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When a 3rd-party bundle is installed, in order for the user to be able
to use the binaries the bundle provides, it needs to have them exported.
This commit exports those binaries after they have been successfully
installed.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit makes possible the creation of bundles with exported files
in test environments. These bundles will have the 'x' in the appropriate
place in the manifest plus those bundles that are to be installed in the
environment will have the "exporting script" created in the 3rd-party
bin directory.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When diagnosing/repairing a system, sometimes is useful to only
diagnose/repair a specific file or path.
This commit implements the --file option for diagnose/repair so a file
or path can be diagnosed only instead of doing it to the whole OS or a
whole bundle.
Closes#1150
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
bundle-info currently shows the installation status of a bundle, but
this one is restricted to "installed" or "not installed", it doesn't
show if a bundle was explicitly or implicitly installed.
This commit adds this information to the installation status during a
bundle-info.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
The "bundle-list" command can be used to show all installed bundles in
the system, however, currently there is no way to know which of those
installed bundles were implicitly or explicitly installed.
This commit implements the "--status" flag for bundle-list which can be
used to show which bundles were explicitly or implicitly installed.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Swupd should not run post-update scripts after updating content from a
3rd-party repo since it may threaten the security of the system.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This PR re-enables the failing auto-update
tests while moving from travis to github actions
Signed-off-by: Karthik Prabhu Vinod <karthik.prabhu.vinod@intel.com>
Sometimes is useful to see the list of dependencies in a tree view form,
for example when trying to remove bundles from a system.
This commit adds the ability of listing the dependencies of a bundle in
a tree view when --verbose is used.
Closes#929
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit moves the path where the content from 3rd-party bundles is
going to be installed from opt/3rd-party/<bundle_name> to
/opt/3rd-party/bundles/<bundle_name> so bundle directories are separated
from other top level directories like bin.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When using "bundle-info BUNDLE --dependencies", information regarding
BUNDLE is presented to the user, this information includes the list of
direct and indirect dependencies BUNDLE has. All direct includes that
are optional (also-add) are marked as such, while there is no way to
distiguish what indirect dependencies are optional with the provided
information.
This commit expands the information shown by the command so indirect
dependencies that are optional are shown as such along with info about
the status of that dependency.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
The 3rd-party repository directory is currently 3rd_party, this name is
incorrect and needs to be changed to 3rd-party.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
The search-file command is restricted to looking for files in the
current version. This commit adds the --version option to the command
that can be used to seach for files in specific versions of Clear.
Closes#1155
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Sometimes when a test finds a problem in the source code it is difficult
to determine what is the problem in the code, so the code needs to be
debugged. In order to do this, the test environment of the particular
test has to be created but without running the test, so we can run the
command executed by the test with the debugger.
This commit adds a function (create_test_environment_only) to create a
specific test environment based on a bats file, but without running the
test.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
For some options of bundle-list, like --deps and --has-dep, we sometimes
need to download a considerable amount of manifests, if that happens
swupd just seems to hang for some time, this time could be considerably
in slow networks.
This commit enables the spinner while the manifests are baing downloaded
during a bundle-list operation so users know swupd is not hung and it is
doing some downloading.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
In order to report progress accuratelly, currently swupd requires a
hardcoded number of steps per operation so we can report how far in the
operation we are. Most of these step totals are wrong.
This commit fixes the number of steps in many swupd functions.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
A spinner was added to swupd to show some kind of progress while
downloading content which its amount is unknown. Once the content is
downloaded the stopped spinner should be removed from the screen. This
commit does that.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit makes a few small changes to the output of the commands to
make it look cleaner and to be consistent with the output of other swupd
commands.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When we remove a 3rd-party repo from the system, we remove the directory
where all its contents got installed, but we don't remove its state
directory.
This commit removes it since we no longer need that state directory.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When performing signature verification to the MoM or to the version
file, if there is any error during the process, a series of errors are
printed to stderr. Many of these error messages are duplicated and most
of them are too detailed.
This commit filters those detailed messages so they are only seen if the
user is using the --debug flag, showing only a few more general
error messages about the signature failure.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit enhance the consistency and readability, of the messages
shown when the signature verification is skipped or fails.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When running an operation, swupd uses a certificate to validate things
ilke the MoM and the version file. The certificate that needs to be used
for 3rd-party repos is different than the one that has to be used for
upstream.
This commit enables the use of the 3rd-party repo certificate that will
be installed in the repo's directory with all swupd operations, except
when adding the repository, in those cases, since the os-core bundle
hasn't been installed yet, we need to provide the cert path through
other means, like using the -C flag..
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When adding a 3rd-party repository we need to make sure that the URL
provided by the user is not already assigned to another 3rd-arty
repository, otherwise we can end up having the same repository multiple
times, just with different names.
This commit checks the URL doesn't already exists.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When listing bundles using the --deps or --has-dep flags which
take a BUNDLE as argument, one or more repositories may not have
the specified BUNDLE, but we should not return a
SWUPD_INVALID_BUNDLE error unless the bundle is not found in any
repository.
This commit enforces that behavior and also modify the output of the
different list options to make them more consistent with one another.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit does some housekeeping in the 3rd-party commands:
- Initialize the function "progress" only after swupd has initialized
successfully.
- Make functions that are not used outside of a file static.
- Avoid using regex or partial verifications on tests when possible.
- Add 3rd-party command flags to the default config file.
- Don't use "repo" in help menus, use the whole "repository" word.
- Add 3rd-party sub-commands to the flag_validator script.
- Add missing values from the autocompletion scripts.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit adds a function that can run an operation in one or all
3rd-party repositories. If a repository is specified then the operation
is run in only that 3rd-party repo, otherwise it is run in all 3rd-party
repos.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>