When generating the certificate for tests, openssl is printing messages
to the terminal, we are already selecting what to print by using the
debug_msg() function, so these unwanted messages shouldnot be printed.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
We need to install/uninstall on test_setup, not global_setup because env
variables are not preserved between tests
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Instead of requiring an external script (.prereq) to generate the certificates
we can regenerate them before running each test.
Also removes completly the .prereq script
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
When updating a bundle using testlib, if the file is updated, and the
update includes a file type change, testlib was updating the manifest
with the correct type but was overwriting the other status flags, so if
a file was marked as 'x' (exported) before, that flag was being removed.
This commit fixes the issue by only updating the flag that relates to
the file type.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
During a 3rd-party repair, the wrapper scripts of all binaries verified
should be regenerated regardless of if the binary was repaired or not.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When updating a 3rd-party bundle, if any of its binaries is modified,
or the binary is new swupd needs to recreate the wrapper script.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When running tests sometimes is useful to see how the filesystem of the
test target system looks like before and after a test. This commit adds
a function to show that chroot fs in a tree view, and it calls that
function in the setup and teardown of tests if DEBUG_TESTS is set.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit provides a function that can be used to generate update
content based on the content from a directory specified by the user.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit adds a function that retrieve the matching entry from a
manifest or all entries if no key is provided.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit adds a function to create a bundle based on the content form
a directory specified by the user.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit has a few small corrections in testlib:
- it removes some code that was used for iterative manifests
- it correct some help menus
- favors the use of debug_msg over an if statement for filtering
messages
- do not follow links in the function that creates tars from
fullfiles
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When a test is adding a symlink to a manifest, the file the link is
pointing to is also added to the manifest. This commit prevents the file
pointed by the link to be added, if the user wants to add this file they
can do it explicitely.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit adds support for file type changes when using bundle_update,
so the correct type is added to the manifest.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
It is considered safe to accept expired signatures to validate the latest
file because we are always checking again the signature of the MoM file.
Adding tests to validate that:
- Expired signatures for latest file works
- Expired signatures for MoM fails even when latest signature is correct
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
- Check if custom certificate is working when valid
- Check if we are having errors on expired certificate
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
2 groups were created:
- slow: Tests that are very slow because of sleeps, so we can run them all
in parallel
- system: Tests that make change to the system, so they can cause problems
when running in parallel, so we run them in series.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
When creating a wrapper for 3rd-party binaries, append relative
/usr/share and /usr/local/share to XDG_DATA_DIRS variable and /etc
to XDG_CONF_DIRS.
Fix#1411
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
This commit removes the extra slash '/' from the path from:
- the update_boot function
- the verifytime script
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When a manifest delta was incorrect, the full manifest was used. But in the
case of a correct delta that produces an invalid manifest, swupd was never
trying to download the full manifest.
Changing code to try to use deltas only once. On first error, always retry
downloading the full manifest.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
When swupd is adding a 3rd-party repo and it finds a non empty directory
that matches the repo's name in the content path it warns the user and
aborts. This may have been caused by a corrupt repo.
This commit adds a --force flag to allow users to instruct swupd to
remove the existing directory and its conent and continue adding the
3rd-party repo.
Closes#1388
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
In some situations it might be useful to skip signature verification of
latest, but continuing checking the signature of the files that are going
to be installed.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
When trying to update if the mirror has an invalid signature file we should
try to use the default source url instead.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
- Reorganizing function to be easier to read
- If path is problematic and there's no access version url config, use the
one set using compile flags
- Use correct url to check for local
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Always enforce signature verification for latest file. If it's missing
we should abort the command.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
When adding a 3rd-party repo, if the repo cannot be added it is reverted
back. However if a user uses an incorrect URL that hangs and the user
cancels the process, the repo add is never rolled back, which will cause
the invalid repo to be left in the system.
This commit fixes the issue by making sure the repo is reachable and
somewhat valid before adding it to the config file.
Closes#1384
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Alternative solution to solution proposed on #1318
Instead of trying to create a link just don't try to link symlinks.
Tested patch using bsdtar and implemented automated testing to
validate solution.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
When doing a system install with "os-install --bundles" if the list of
bundles to install includes only "os-core" the install fails.
This commit fixes the issue.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
The iterative manifest effort was droped so this commit removes the
iterative manifest support from testlib.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Implementation of the 3rd-party info command to show the version of the
3rd-party repository along with the update URL.
Closes#1354
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
This commit allow users to force the deletion of corrupt 3rd-party repos
which will end up deleting most of the repo's files, except for the
scripts that exported files from that repo.
Closes#1343
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When adding an upstream bundle, we apply some heuristics to the bundle
files and based on that some files are skipped from being installed.
These heuristics don't apply to 3rd-party bundles.
This commit skips running heuristics when adding 3rd-party bundles.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
Sometimes a test fails before finisihing to create all the required
directories under the testdir. So destroy_environment thinks this is
not a valid test environment.
Touching a dot file to show that the directory is a test environment
instead on counting on its content.
Fixes bug #1135
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
When a symlink is added to a 3rd-party repository it will be broken
on the statedir and stat command will fail. We need to use lstat, to
get information about the symlink and not the file that it's pointing
to.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
The repo.ini file was being created in the swupd state directory, this
was not ideal since it prevented the state directory from being used for
multiple target paths.
This commit moves the repo.ini file out of the state directory and into
the 3rd-party content directory.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
The testlib had two functions to create 3rd-party repositories that were
very similar but with only one difference, one function only created the
3rd-party repo, the other one created the repo and also added it as if
the user had already done a "swupd 3rd-party add" on it.
This commit merges both functions into one to avoid code duplication,
make the test library easier to maintain, and make it less confusing.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When in a 3rd-party repository one bundle has one binary file that
is exported, and the same file is included in another bundle, only
it is not exported in this bundle, when we remove the bundle that
exports the file, the file should be unexported regardless of the file
still being installed since the bundle that is still in the system is
not exporting it.
Closes#1322
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
When trying to add the repository for the first time, download the public
certificate published by the 3rd party repository and with a user confirmation,
use it to install the 3rd-party os-core. After that the official certificate will
be installed for future commands.
Signed-off-by: Otavio Pontes <otavio.pontes@intel.com>
Some commands were recently added to swupd which require user
interaction under certain circumstances, when this happens the user has
to manually enter either Y/N to continue or abort the current process.
This commit provides a --non-interactive=<yes/no> flag that can be used
to avoid getting this interactive prompts.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>
If an update of 3rd-party content includes files with dangerous flags,
the user should be notified and the update should only continue if the
user accepts the risk, otherwise the update should be aborted.
Signed-off-by: Castulo Martinez <castulo.martinez@intel.com>