177 Commits
Author SHA1 Message Date
Tudor Marcu 2fed6d78aa Release v3.6.1
This release introduces a change to the hashing scheme regarding delta names,
and directory hashes. Fixes are also included for using consistent paths for
the certificates, attempting local signature verification before downloading
the Manifest.MoM and signature from the server, patching functional tests
to accomodate the new hash changes, and various memory leaks and code cleanup.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.6.1
2016-08-19 16:54:53 -07:00
Tudor Marcu f7d122b774 Remove unreachable code
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2016-08-19 16:41:16 -07:00
Tudor Marcu d0fd5c920a Remove dead code
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2016-08-19 16:38:41 -07:00
Tudor Marcu 330a232e3b Fix memory leak in search
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2016-08-19 16:37:40 -07:00
Patrick McCarty 5cdad496c0 Fix functional tests for breaking changes
To two latest commits introduce breaking changes to the updater, so the
static server content needs to be refreshed.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-08-15 15:22:34 -07:00
Jose R Guzman a8e8c3d8a6 Make directory hashes independent on filename
Calculate the hash for directories is desiderable to be independent
on the dirname due to the subsequent calculation on the staged/HASH
file. Here is used const "DIRECTORY" string for input name for
all folders.

Signed-off-by: Jose R Guzman <jose.r.guzman.mosqueda@intel.com>
2016-08-04 12:04:51 -07:00
Jose R Guzman 8b9b582251 Change delta's name from FROM-TO-HASH2 to FROM-TO-HASH1-HASH2 format.
There is an issue when two different files in a newer release have same hash:
This is, when swupd updates a file by applying a delta, it takes the HASH2 to
know the file where delta must be applyed. If files are different in current
release (before updating), there must be 2 deltas, one for each file but as
the two files have same hash in new release delta's name are the same:
FROM-TO-HASH2 and it is when issue arises due to just the last delta file is
kept when swupd server creates files and packs. So when swupd client tries to
apply the delta to one of the file that does not corresponds it will fail and
generates an error. At the first look it will seem like delta file is corrupted
however the issue is that delta file was created for another file.
To solve this issue we include the hash for the original file in the delta's
name so that swupd client can take the correct delta and apply it:
FROM-TO-HASH1-HASH2.

Warning: A corresponding patch to swupd server must be applied in order to
sync both sides and understand the new delta's name format.

Signed-off-by: Jose R Guzman <jose.r.guzman.mosqueda@intel.com>
2016-08-04 11:59:32 -07:00
Patrick McCarty 6a27cc54bc Try local signature verification first before downloading
In case the Manifest.MoM.sig already exists locally (e.g. it was shipped
inside the Manifest.MoM.tar), then try to verify the local copy first.
If the verify fails because the .sig is missing, or for any other
reason, then download a fresh copy from the server.

For the implementation, I refactored verify_signature() to not print
error messages if the verification fails the first time, because we
"retry" by downloading the fresh copy. If the verification fails the
second time, then error messages are printed. Also, I consolidated the
cleanup logic in this function to reduce duplication.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-07-01 14:59:37 -07:00
Patrick McCarty 333b74091b Use UPDATE_CA_CERTS_PATH when setting the pinned key path
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-28 13:39:38 -07:00
Patrick McCarty 9e63b5737b Set a value for SIGNATURES macro
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-28 13:32:20 -07:00
Patrick McCarty f4000c5b22 Release v3.6.0
This release enables support for verification of signed MoM manifests,
with the MoM being the root of trust for any swupd-client action that
references update content (i.e.  'update', 'verify', etc.). Also, to
complete the chain of trust rooted at the MoM, integrity checks have
been enabled for bundle manifests.

To enable this feature, pass the --enable-signature-verification option
to the configure script.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
v3.6.0
2016-06-27 15:23:58 -07:00
Patrick McCarty 3e0fff6a47 Ignore signature verification errors in functional tests
Because signature verification is a feature that we need separate
testing for, and swupd's output may print a verification error (or not)
depending on how swupd was built, add a helper function to remove the
verification error message when swupd is built with verification
enabled. If verification is not enabled, swupd will not print any
message, and the function is a no-op.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-27 11:56:01 -07:00
Patrick McCarty eecd292ae4 Check more output in the 'directory-tree-deleted' test
To make the change in my next commit more uniform, make sure this test
checks for the presence of some of the initial lines printed by swupd.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-27 11:54:13 -07:00
Tim Pepper 874fd64459 don't segfault on not found MoM
If the MoM is not found on the server to match the os version on which
you're running, swupd search's MoM downloader returns 0 instead of an
error.  EMOM_NOTFOUND is a natural value to return.

When 0 is returned, the null MoM pointer is later derferenced leading to a
segfault.

Signed-off-by: Tim Pepper <timothy.c.pepper@linux.intel.com>
2016-06-27 11:37:06 -07:00
Patrick McCarty f118ea880a Run clang-format on sources
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-27 10:38:27 -07:00
Patrick McCarty 86594599e5 Fix build when sig verification is disabled
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-27 10:33:54 -07:00
Tim Pepper 499166ca4f move libcrypto init/cleanup to swupd_init()/swupd_deinit()
The poorly documented libcrypto in OpenSSL apparently does not like
its initialization and cleanup functions to be called but at process
start and exit.  Swupd-client already has a swupd_init() so easy on
that side.  But there was no common swupd_deinit() in which to place
terminate_signature().  I add one and put the common exit cleaners in it
and fix of a number of little inconsistencies around process exit cleanup
that have come to exist because there was a common cleaner.

With this, the signature verification of both the current and latest
MoM works, where prior only a first verification succeeded.

This patch also fixes a few memory leaks, though there are still many
memory leaks in swupd bundle-add and bundle-remove, unrelated to signature
verification.  And swupd search is segfaulting due to how load_mom()
is introduced in 8cf0ef91dd.

Signed-off-by: Tim Pepper <timothy.c.pepper@linux.intel.com>
2016-06-24 20:12:18 -07:00
Tim Pepper 97f46edd52 Implement signature verification
This patch adds functionality for the swupd client to do signature
verification on the MoM, which ensures a root of trust for the rest
of the update by guaranteeing the authenticity of the MoM and content
it includes.

As we focus now on just verifying the signed MoM, a number of functions now
become static to src/signature.c.

By default MoM signature verification is disabled.  Configure
--enable-signature-verification to enable it.  When enabled the default
cert for verification is /usr/share/clear/update-ca/ClearLinuxRoot.pem, as
specified by concatenation of SWUPDCERT onto UPDATE_CA_CERTS_PATH.  The
SWUPDCERT can be overridden via configure --with-swupdcert=some.pem.

When signature verification is enabled, and the MoM's signature does _NOT_
verify, currently only a warning is presented but the swupd operation
continues.  In the future signature verification will become mandatory.
We first need to sort out a few details with mixer to insure the right
thing happens there.

Signed-off-by: Tim Pepper <timothy.c.pepper@linux.intel.com>
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2016-06-24 15:12:28 -07:00
Patrick McCarty a384265d88 Refactor test cases; update bundle manifest hashes
This commit expands the swupd BATS library to encapsulate more of the
boilerplate steps in the test cases.

Additionally, bundle manifest hashes needed updating now that swupd is
emitting warnings (and later on, errors). Better to be prepared for the
switch to errors on mismatches.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-22 16:12:38 -07:00
Patrick McCarty bd96083f8c Add helper script for test case creation
Eventually, I want to add scripting to more easily create create/manage
manifests for test cases, but for now this script addresses some of the
overhead.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-22 16:12:38 -07:00
Patrick McCarty 8cf0ef91dd Implement bundle manifest hash checks
In order for the chain of trust rooted at the Manifest.MoM to operate
correctly, the bundle manifest hashes (as listed in the MoM) must be
checked. For now, warnings will be emitted when hash checks fail, but
they will become errors in the near future.

This commit simplifies/splits the load_manifests() interface into
load_mom() and load_manifest(), since load_manifests() was becoming too
complex, since the handling needs for MoMs versus bundle manifests is
sufficiently different.  For the new load_manifest(), the logic is
changed to first download the manifest, then check the hash, and only
then load the manifest into memory.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-22 16:12:32 -07:00
Patrick McCarty 97d39d7642 Ignore state dir for tests
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-21 16:02:44 -07:00
Patrick McCarty 37cd2848f8 Release v3.5.7
This release incorporates a couple of bug fixes.

- Fixes the bash completion script to support calling 'swupd' with an
  absolute path (e.g. /usr/bin/swupd).

- Improve behavior of 'update' when crossing a minversion, when
  potentially many update artifacts only have their "last update" field
  modified. For these artifacts, 'update' will now avoid downloading
  fresh copies, thus improving performance times for an update.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
v3.5.7
2016-06-21 15:33:39 -07:00
Patrick McCarty 40ae514434 Improvements for update list creation
The recently added call to verify_file(), used to skip files that are
already installed and have correct hashes, is a nice optimization for
the case when an update crosses a build where a new minversion was
applied to the server content.

However, I ran into a case where calling verify_file() like this results
in an incomplete update: If the corresponding hash calculation of a file
in the latest version *follows a symlink" for the path in the current
version, the hashes will match (assuming the same file content).

This issue is avoidable by checking for the file's presence in the
current version's manifest first, because manifests only contain real
paths (no non-leaf path components are symlinks).

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-21 14:13:25 -07:00
Patrick McCarty 40818b8554 Rename a couple functions for clarity
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-10 11:54:25 -07:00
Patrick McCarty e3bf825a3a Fix a boolean check
This function is supposed to return 1 in the event a file is found
within the manifest, AND the hashes are different. The hash check logic
was mistakenly reversed.

Note that because rename support is not enabled at the moment, this
function is never called.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-10 11:47:43 -07:00
Patrick McCarty d167770af6 Refresh completion script
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-09 13:36:23 -07:00
William Douglas 4b522b352a Skip verified unchanged files in update
Instead of just checking if the versions have changed for a file to be
updated, compare the current file's hash to updated file's expected hash
and only queue files for update that are changed.
2016-06-07 16:06:42 -07:00
Patrick McCarty a5632aba0d Fix tests for compatibility with latest GNU tar
The recent GNU tar release (1.29) is more strict with option parsing in
that positional options must come before the file list to add to the
archive.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-07 15:54:32 -07:00
Jose R Guzman 3db13fd519 Fix for completion when absolute path is given
Signed-off-by: Jose R Guzman <jose.r.guzman.mosqueda@intel.com>
2016-06-03 16:56:49 -05:00
Patrick McCarty 85b6ed7fc6 Release v3.5.6
This release includes a few bug fixes:

- Improves 'bundle-add' reliability by falling back to downloading full
  files in case packs contain incomplete or corrupt content.

- Addresses a memory leak in bundle includes processing.

- Improves error handling in out-of-memory conditions.

- Fixes an issue with libcurl writing to invalid memory when downloading
  version info.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
v3.5.6
2016-05-31 12:32:07 -07:00
Patrick McCarty 0db3120caf Use the version_container for the resume support check
This is another instance of libcurl incorrectly writing to memory that
is out-of-scope. Using a dynamically allocated version_container is the
best approach here, and it makes Valgrind happy.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-05-31 12:23:53 -07:00
Patrick McCarty baae37a0f2 Explicitly discard return value for an ignore() call
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-05-31 12:08:22 -07:00
William Douglas 2ca1bf3b8b Stop using out of scope stack memory
When running get_latest_version, the swupd_curl_get_file would allocate
a version_container struct on the stack that would then be used by the
curl callback to keep track of the buffer offset. This use was invalid
however because the callback was run after the stack had been popped
which lead to undefined behavior.

Instead change the swupd_curl_get_file function to take the struct
itself so it will refer to memory valid for the entire length of the
call.

The swupd_curl_get_file function should likely be restructured at some
point so that in memory downloads are less of a hack (only able to
download a LINE_MAX worth of data) at some point however and this will
need to be updated again.
2016-05-31 12:05:05 -07:00
William Douglas 080d805727 Allow bundle-add to fallback to full files
Instead of requiring a pack is used for bundle-add, allow the use of
verify_fix_path when staging fails to: download, verify and stage the
item using the full file.

Correct output of tests where the 'required' wording was removed.
2016-05-31 11:24:07 -07:00
William Douglas bc45fa6ca9 Set ret to indicate error in update failure path
When unable to allocate the submanifest list for either the current or
server manifest, set ret to indicate failure.
2016-05-31 11:11:00 -07:00
William Douglas 6e4b2129bb Correctly free manifest data
Call free_manifest instead of plain free on allocated manifests.
2016-05-25 23:25:01 +00:00
Patrick McCarty b4dc134833 Release v3.5.5
This release includes one bug fix:

- Adds appropriate hash checks for full files after they have been
  extracted. This better ensures that corrupt data will never be staged.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
v3.5.5
2016-05-20 12:40:09 -07:00
Patrick McCarty b202b87187 Expand test from previous commit to check the error message
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-05-20 12:35:03 -07:00
William Douglas 9f4feee501 Fail instead of staging bad file hashes in update
Check file hashes after successful tar extraction and fail if there is a
hash mismatch during udpate. As part of this change failure handling for
errors in the tar extraction path with a check space warning as a best
guess of error cause.

This change also fixes tests where the hashes were not correct and adds
a test to verify hash matching is verified.
2016-05-17 21:04:17 +00:00
William Douglas e0b859448a Sleep a little longer for python web server test 2016-05-17 20:06:57 +00:00
Patrick McCarty a56eeb36e1 Release v3.5.4
This release fixes several bugs:

- Enforces the limitation of 'bundle-remove' to only accept one bundle
  argument.

- Avoids resuming interrupted downloads if the server does not support
  range requests.

- Fixes error handling of 'verify -i -m latest' in case of network
  connectivity issues.

- Fixes verify_fix_path functionality to work with 'bundle-add'.

- Fixes 'check-update -v' if the swupd config files for URLs do not
  exist.

- Fixes error handling for invalid arguments passed to the -p/--path
  option.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
v3.5.4
2016-05-13 11:25:29 -07:00
Patrick McCarty 611b6f9438 Fix some file descriptors leaks in error handling
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-05-13 11:25:29 -07:00
Patrick McCarty 3df9424283 Remove unused local variable
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-05-13 11:25:29 -07:00
Patrick McCarty c060411435 Use same formatting for fullfile download error messages
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-05-13 11:25:29 -07:00
Patrick McCarty a1570f3c1b Handle errors in the other hashdump set_path_prefix call
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-05-13 11:25:29 -07:00
William Douglas 6fc6d6113d Enforce includes hierarchy with bundle-remove
Don't allow bundle-remove to remove bundles that are included by other
currently installed bundles.
2016-05-13 10:39:22 -07:00
Patrick McCarty 3e3651bf28 Handle the same path_prefix error for 'hashdump'
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-05-13 08:59:34 -07:00
Jesus Ornelas Aguayo 56c845df41 Fix return false from set_path_prefix
When set_path_prefix returns false, a message "cannot continue"
is prompted but swupd continues its execution, this patch goes to
err when a false is returned by set_path_prefix.

Signed-off-by: Jesus Ornelas Aguayo <jesus.ornelas.aguayo@intel.com>
2016-05-13 09:58:17 -05:00
Jesus Ornelas Aguayo 0d22d9a679 Fix check-update content url message
Fix "Use the -c option instead" message in check-update since it does
not require the -c option, this occurs when the default contenturl
can not be foud in the config files, this patch sets the content url
with the version url value in check-update.

Signed-off-by: Jesus Ornelas Aguayo <jesus.ornelas.aguayo@intel.com>
2016-05-11 14:01:35 -07:00