This release includes one bug fix:
- Adds appropriate hash checks for full files after they have been
extracted. This better ensures that corrupt data will never be staged.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Check file hashes after successful tar extraction and fail if there is a
hash mismatch during udpate. As part of this change failure handling for
errors in the tar extraction path with a check space warning as a best
guess of error cause.
This change also fixes tests where the hashes were not correct and adds
a test to verify hash matching is verified.
This release fixes several bugs:
- Enforces the limitation of 'bundle-remove' to only accept one bundle
argument.
- Avoids resuming interrupted downloads if the server does not support
range requests.
- Fixes error handling of 'verify -i -m latest' in case of network
connectivity issues.
- Fixes verify_fix_path functionality to work with 'bundle-add'.
- Fixes 'check-update -v' if the swupd config files for URLs do not
exist.
- Fixes error handling for invalid arguments passed to the -p/--path
option.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
When set_path_prefix returns false, a message "cannot continue"
is prompted but swupd continues its execution, this patch goes to
err when a false is returned by set_path_prefix.
Signed-off-by: Jesus Ornelas Aguayo <jesus.ornelas.aguayo@intel.com>
Fix "Use the -c option instead" message in check-update since it does
not require the -c option, this occurs when the default contenturl
can not be foud in the config files, this patch sets the content url
with the version url value in check-update.
Signed-off-by: Jesus Ornelas Aguayo <jesus.ornelas.aguayo@intel.com>
Since an empty string prints zero characters, the return value of
asprintf() in this case is 0. To permit allocating the empty string,
only abort when an error condition is hit (returns -1).
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Add new function consolidate_files that replaces
consolidate_submanifests in order to remove the requirement of modifying
manifest components in place. This change enables creating seperate
consolidated file lists for bundle-add, one for new files to be
installed on the system and one for the currently installed bundles
files. Once these have been seperated out, only files requiring
installation can be processed by do_staging and the list of files
installed on the system can be used to run verify_fix_path.
This also modifies bundle-add to stop trying to create tracking
files which was impacting testing.
In order to support verify_fix_path from bundle_add, a generic file list
from bundle list needs to be implemented to replace the one embedded in
the current consolidate_submanifests function.
This function will be used to generate a file list to be passed to a new
function for consolidating a list of files (created in the following
patch).
Note the list of files this creates is not sorted.
To support low duplication lists of files living in multiple locations
that will be required for bundle_add to be able to run
swupd_verify_fix_path add a list_clone function which will create a copy
of a list without duplicating the list data.
Update verify to correctly check the return value of get_latest_version
for errors. Since get_latest_version could return a variety of negative
error codes to signify errors compare against that range instead of -1
to determine success of the operation.
When pack is going to be downloaded an option for
curl called resume is activated no matter what,
however although major http server support 'Range'
command that enables this functionality, not all
complies with this, when swupd client tries to
re-download a partial file from one of the server
that does not support 'Range' it will just throw
an error and stop to work until partial download
is deleted by hand.
This patch address that issue by checking first
whether server supports 'Range' command and if not
then disable 'resume' of packs.
Signed-off-by: Jaime A. Garcia <jaime.garcia.naranjo@intel.com>
Instead of only checking if bundle-remove has at least one bundle
argument and ignoring additional ones, check that there is exactly one
argument passed to bundle-remove instead.
In order to avoid non deterministic behavior when processing the subs
list, sort it after running read_subscription_alt as it may add items to
the list in a different order between runs.
This release includes several bug fixes and a rework of the functional
test framework:
Bug fixes:
- 'verify --fix' now correctly removes directory trees if the entire
tree is marked deleted. Reporting of errors with deleting files was
also fixed as a result.
- Fixes an issue with overwriting previously received data when
downloading the latest version file. All subcommands except for
'hashdump' were affected by this bug.
- Fixes download retries for delta packs in case of a network
connectivity issue.
- Fixes error handling in the event 'bundle-add' encounters a file
staging failure, which is a fatal error.
Other:
- Switches to use BATS, instead of python-tappy, for the functional test
framework.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Add check for do_staging return code, aborting bundle-add
operation when any file or directory fails to stage. This
addresses file system corruption seen when client runs out
of disk space
Signed-off-by: Brad T. Peters <brad.t.peters@intel.com>
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
In the update loop when downloading packs a return
status is checked with an unreacheable error number
-ENONET, this is because the function is called
download_subscribed_packs() without forcing the
pack to download, so the only chance to this to
return an error is at checking network aviability
with a return code -ENOSWUPDSERVER so far. This
was causing the retry mechanism on this point to
be completely ignored and skipped right away.
Beyond checking for -ENOSWUPDSERVER, this fix
checks whether *any* error ocurred in the packs
download function, granting that if some code
changes inside the caller is checking accorrdingly.
Signed-off-by: Jaime A. Garcia <jaime.garcia.naranjo@intel.com>
In the case where the swupd_download_version_to_memory callback was run
multiple times, it would overwrite previous data instead of appending.
Correct this behavior by keeping track of data written so far in the
struct passed to the callback.
For safety, 'verify --fix' does not use swupd_rm() (like 'update') when
deleting files, etc. Instead, each deleted entry is considered
individually.
So for the deletion step to work correctly with 'verify --fix', files
contained within directories must be listed before the directories
themselves. A simple solution is to make the manifest reverse filename
sorted (opposite of the current filename sorted order).
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
search_file_in_manifest() is not starting its iteration from
list_head, leading to incomplete manifest search and failing
verify_fix_path()
search_bundle_in_manifest() was using the same iteration method,
and is also corrected here.
Signed-off-by: Brad T. Peters <brad.t.peters@intel.com>
unlinkat() returns 0 upon success, and -1 on failure, so only report
errors when the unlinkat() fails for reasons other than ENOENT.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release addresses the following bugs:
- Fixes 'search' to list symlinks in search results.
- Fixes potential NULL dereferences in 'search' and 'bundle-remove'.
- Fixes a couple of quoting issues when running tar commands.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
It may happen that a bundle contains a directory named '#' and
other files under this directory, thus not only target files
need to be escaped in tar commands, but also target directories
where the files get installed.
Also a target file may have a name with '@' as its first symbol.
Since the symbol has a special meaning in case of bsdtar the
name needs to escaped in tar commands with the prefix './'.
Signed-off-by: Dmitry Rozhkov <dmitry.rozhkov@linux.intel.com>
This release fixes two crashes, when either 'check-update' or 'update
--status' are run without options, and improves error handling and
reporting when the current OS version cannot be determined.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Since we are either determining the current OS version, or the latest OS
version, at any given time, rename these functions to reflect that.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Various other globals need to be initialized, such as version_url,
format_string, and state_dir, so init_globals() needs to be called.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
With the recent change to swupd-server that removes old deleted files in
the initial manifests for a new format, the case in which these files
are absent from the new manifest should not be counted as deleted.
Also, fix another deleted file accounting issue: the file could have
been deleted anywhere in the range current < N <= new, not just at the
latest (new) version.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release adds some new features and fixes a few bugs.
New features:
- The state directory is now configurable (defaults to /var/lib/swupd)
with the -S/--statedir option.
- Adds a bash completion script for the swupd binary. It is not
installed by default, but lives in the toplevel directory of the dist
tarball (swupd.bash).
- Adds support for "-m latest" when running 'verify --install', which
will download update content for the latest version for the current
format.
Bug fixes:
- Fixes a crash in 'hashdump' when the -b option is not specified.
- Fixes a crash in 'bundle-remove' that occurs when attempting to remove
a bundle that exists in the tracking directory but does not exist in
the Manifest.MoM.
- Fixes a bug with manifest consolidation that can result in files not
being deleted during an update when they should be.
- Quiets progress messages related to the new bundle includes
functionality.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
In case there are file descriptor leaks, those issues would be printed
after the status message, but it should be the other way around: the
last printed message should reflect the result of the action.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This call site seems like a better location, more aligned with how the
other subcommands call free_globals().
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Now that the state directory is configurable, it is more convenient to
store the lock file there, since at most one instance of 'swupd' should
be modifying a given state directory at any time.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Since most of these checks are used by all subcommands, and are written
in slightly different ways, move all of the checks into swupd_init() to
do the checks in one place and prevent misordering of these calls.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>