This release adds support for bundle includes in preparation for
deployment of this feature in swupd-server. It also adds some functional
tests for the 'search' subcommand and includes a couple of bug fixes:
- Removes a bashism in running 'mkdir -p' for multiple directories.
- Supports 'bsdtar' as a compile-time alternative to 'tar'.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Add support in update to properly support bundles that include other
bundles inside them. This feature is intended to work with bundle
additions by adding included bundles (from bundles already subscribed)
to the subscription list prior to downloading packs and full files.
As part of this change the add_subscriptions function from bundle.c was
modified to handle retrying manifest downloads.
Instead of taking in versions as arguments to download_subscribed_packs,
just use the version information in the subs list items (set by calling
subscription_versions_from_MoM function).
Because the subs list may contain bundles that are new in the version
being updated to, don't set an error in the subs item for things not in
a particular manifest version.
The latest_version in check_versions and read_versions was a legacy
variable used for btrfs support that no longer exists and was a
duplicate of current_version in all use cases. This patch removes the
variable completely from the above functions.
Because we currently need to protect file->filename in tar commands if
the filename contains spaces or other special shell characters, restore
the single quotes. Using the single quotes prohibits filenames
themselves containing single quote characters, so a more robust solution
would be preferred.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Since GNU tar fails to extract files with xattrs preserved when
Integrity Measurement Architecture (IMA) is enabled some vendors
may choose to install libarchive-based tar (bsdtar) on their embedded
devices, so the swupd server needs to be able to create archives
in its format.
This patch adds one compile-time options --enable-bsdtar that is used
to enable/disable GNU tar specific options.
Signed-off-by: Dmitry Rozhkov <dmitry.rozhkov@linux.intel.com>
Eventually manifests will be able to include other manifests and this
patchset adds support for adding those included manifests when running
bundle-add on the including manifest.
Start handling the case where a manifest has an includes line. This line
will be used to specify other manifests that are to be installed with
the containing manifest.
Intead of passing install_bundles a char **, pass it a list of char * as
this will be easier to use with the include feature coming due to not
needing to make a new character array.
Pull out code that only can be run once into a bundle installer frontend
function and move code that could be run recursively into an another
function. This is done in preparation for manifest includes.
This release includes a couple of new features, a couple of bug fixes
for boot file handling, build fixes, and adds some new functional tests.
New features:
- Adds a new mechanism for 'swupd update' to recover in the event of
certain types of internal errors. The mechanism is currently used to
recover in a situation where the parent directory is missing for a
staged file.
- Adds support for libcurl's FILE protocol, allowing the user to pass
file:// URIs to the -u option.
Bug fixes:
- Fixes handling of boot files for all subcommands. Specifically,
'bundle-add' was not properly installing boot files, and 'verify
--fix' was ignoring corrupt boot files.
- Fixes an issue with certificate installation on Yocto.
- Fixes an issue with passing --disable-bzip2 to configure.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
A couple of changes break the libswupd ABI:
- removal of the "fix" symbol (global variable)
- modification of the do_staging() signature
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
The following tests are added here:
- Add a boot file via 'bundle-add' (failed before the previous commit).
- Remove a boot file via 'bundle-remove'.
- Add a boot file via 'update'.
- Detect a boot file hash mismatch via 'verify' (failed before the
previous commit).
- Fix a boot file with incorrect hash via 'verify --fix' (failed before
the previous commit).
- Ignore a boot file during 'verify --fix' if marked deleted (failed
before the previous commit).
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
A user was running into issues installing the kernel-container bundle on
Clear Linux. Namely, all missing files marked as boot were not
installed.
The root issue is that the bundle-add action does not set the "fix"
global variable before calling ignore(), so ignore() mistakenly returns
true when considering boot files that are missing, but not marked
deleted.
Because 'bundle-add' should be installing new boot files, and 'verify
--fix' should be repairing boot files if they have mismatching hashes,
remove the global "fix" variable entirely, since in all current call
sites, the "fix" behavior is expected.
Also, add another call to ignore() in remove_orphaned_files() to ensure
that any file that should be ignored (including deleted boot files) are
not removed during a 'verify --fix'.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
To support swupd-client testing without connecting to a web server, it's
convenient to use libcurl's FILE protocol, which will query files on the
local filesystem instead.
Because the libcurl-multi download path for fullfiles has treated the
"0" response code as an error, but it has the opposite meaning when
using the FILE protocol, only set the error when connecting to a web
server.
Also, the libcurl-easy code for synchronous downloads didn't treat "0"
specially, so this commit ensures the proper handling, as well as
setting a generic download error for the FILE protocol specific
CURLE_FILE_COULDNT_READ_FILE.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
The verify_fix_path function takes a path and a consolidated MOM as its arguments.
It breaks down the path into subpaths and checks if each subpath is missing.
If found missing, the path is searched for in the consolidated manifest for its hash
and downloaded synchronously. It returns success if all that subpaths are verified
and fixed.
The do_staging function checks if a path to a file is present before staging a file.
It does so by checking first if it is a symlink and following the symlink.
Remove this check as the way manifests are generated on the server side, it is not
possible to have a file path listed with symlinks in them. The server checks for file
type DT_DIR before including files in that path.
On install phase certificate files are being installed twice as included in
_DATA twice. We can use EXTRA_DIST than dist_.
Signed-off-by: Amarnath Valluri <amarnath.valluri@intel.com>
This release adds a new feature and fixes a few bugs:
New feature:
- Adds a new subcommand, "search", that can be used for searching for
bundles that provide a certain binary or library; if there are any
bundle providers, they are printed to the console.
Bug fixes:
- Fixes peer links of manifests between two Manifest.MoMs; as a result,
changed/added/deleted manifest reporting is fixed for updates, and
more delta manifests are likely to apply if available.
- Adds more specific reporting for Curl error messsages.
- Make 'swupd verify --install' output less verbose; files in the target
directory are not expected to exist, so reporting missing/fixed for
files is unnecessary unless errors are encountered.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
clang-format does not have an option to make braces mandatory around
blocks (if/for/while/etc), but this is a style rule we are enforcing.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
The following command was run with clang 3.7.1:
$ clang-format -i -style=file include/*.h src/*.c test/*.c
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
clang-format is very picky about comment placement... Comments
immediately preceding labels are indented strangely, so move the
comments after labels instead. Also, adjust comment indentation level to
align with the surrounding code.
One other minor adjustment is needed for an array initialization; the
opening brace for the initialization must appear on the same line, or
else clang-format will format the entire statement differently.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
To make the code style more consistent, I will be running clang-format
to enforce the style guidelines (very similar to the Linux kernel
style). Add a clang-format style file to get started.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
To avoid compiler warnings about invalid characters in the argument to
#warning, always pass a string literal.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
To generate test coverage reports, run:
$ ./configure --enable-coverage
$ make check
$ make coverage
Results can be browsed from the coverage/index.html file.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
New swupd primary command, offers the ability to
search for the provider of a specified binary or library.
A full complement of bundle manifests for the os-release version
is downloaded to the client prior to conducting any search. This
patch has been designed to enable this download, or staging, to
take place prior and separate from use of the search function.
However, with each search, the manifest complement is checked to
ensure completion.
Overhead:
A check against the Clear Linux 6300 manifest set
shows a search will entail a ONE TIME 83 MB network download
(the compressed manifest set), and a constant decompressed 400MB
usage on disk. Future searches will only require new or modified
manifests be downloaded.
Finally, download size is provided to notify user of expected delay
-----
Ex:
"Downloading manifests. Downloading 83.23 MB..."
Signed-off-by: Brad T. Peters <brad.t.peters@intel.com>
In each of these Curl error cases, we have no choice but to terminate
operation. We cannot programmatically work around these issues,
therefore this patch adds error msg details so user can pursue a
solution
Signed-off-by: Brad T. Peters <brad.t.peters@intel.com>
During a swupd verify --install, files are expected to be missing and must
be "fixed," so do not print out that it is missing/fixed in this case.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>