This release introduces a change to the hashing scheme regarding delta names,
and directory hashes. Fixes are also included for using consistent paths for
the certificates, attempting local signature verification before downloading
the Manifest.MoM and signature from the server, patching functional tests
to accomodate the new hash changes, and various memory leaks and code cleanup.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
To two latest commits introduce breaking changes to the updater, so the
static server content needs to be refreshed.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Calculate the hash for directories is desiderable to be independent
on the dirname due to the subsequent calculation on the staged/HASH
file. Here is used const "DIRECTORY" string for input name for
all folders.
Signed-off-by: Jose R Guzman <jose.r.guzman.mosqueda@intel.com>
There is an issue when two different files in a newer release have same hash:
This is, when swupd updates a file by applying a delta, it takes the HASH2 to
know the file where delta must be applyed. If files are different in current
release (before updating), there must be 2 deltas, one for each file but as
the two files have same hash in new release delta's name are the same:
FROM-TO-HASH2 and it is when issue arises due to just the last delta file is
kept when swupd server creates files and packs. So when swupd client tries to
apply the delta to one of the file that does not corresponds it will fail and
generates an error. At the first look it will seem like delta file is corrupted
however the issue is that delta file was created for another file.
To solve this issue we include the hash for the original file in the delta's
name so that swupd client can take the correct delta and apply it:
FROM-TO-HASH1-HASH2.
Warning: A corresponding patch to swupd server must be applied in order to
sync both sides and understand the new delta's name format.
Signed-off-by: Jose R Guzman <jose.r.guzman.mosqueda@intel.com>
In case the Manifest.MoM.sig already exists locally (e.g. it was shipped
inside the Manifest.MoM.tar), then try to verify the local copy first.
If the verify fails because the .sig is missing, or for any other
reason, then download a fresh copy from the server.
For the implementation, I refactored verify_signature() to not print
error messages if the verification fails the first time, because we
"retry" by downloading the fresh copy. If the verification fails the
second time, then error messages are printed. Also, I consolidated the
cleanup logic in this function to reduce duplication.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release enables support for verification of signed MoM manifests,
with the MoM being the root of trust for any swupd-client action that
references update content (i.e. 'update', 'verify', etc.). Also, to
complete the chain of trust rooted at the MoM, integrity checks have
been enabled for bundle manifests.
To enable this feature, pass the --enable-signature-verification option
to the configure script.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Because signature verification is a feature that we need separate
testing for, and swupd's output may print a verification error (or not)
depending on how swupd was built, add a helper function to remove the
verification error message when swupd is built with verification
enabled. If verification is not enabled, swupd will not print any
message, and the function is a no-op.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
To make the change in my next commit more uniform, make sure this test
checks for the presence of some of the initial lines printed by swupd.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
If the MoM is not found on the server to match the os version on which
you're running, swupd search's MoM downloader returns 0 instead of an
error. EMOM_NOTFOUND is a natural value to return.
When 0 is returned, the null MoM pointer is later derferenced leading to a
segfault.
Signed-off-by: Tim Pepper <timothy.c.pepper@linux.intel.com>
The poorly documented libcrypto in OpenSSL apparently does not like
its initialization and cleanup functions to be called but at process
start and exit. Swupd-client already has a swupd_init() so easy on
that side. But there was no common swupd_deinit() in which to place
terminate_signature(). I add one and put the common exit cleaners in it
and fix of a number of little inconsistencies around process exit cleanup
that have come to exist because there was a common cleaner.
With this, the signature verification of both the current and latest
MoM works, where prior only a first verification succeeded.
This patch also fixes a few memory leaks, though there are still many
memory leaks in swupd bundle-add and bundle-remove, unrelated to signature
verification. And swupd search is segfaulting due to how load_mom()
is introduced in 8cf0ef91dd.
Signed-off-by: Tim Pepper <timothy.c.pepper@linux.intel.com>
This patch adds functionality for the swupd client to do signature
verification on the MoM, which ensures a root of trust for the rest
of the update by guaranteeing the authenticity of the MoM and content
it includes.
As we focus now on just verifying the signed MoM, a number of functions now
become static to src/signature.c.
By default MoM signature verification is disabled. Configure
--enable-signature-verification to enable it. When enabled the default
cert for verification is /usr/share/clear/update-ca/ClearLinuxRoot.pem, as
specified by concatenation of SWUPDCERT onto UPDATE_CA_CERTS_PATH. The
SWUPDCERT can be overridden via configure --with-swupdcert=some.pem.
When signature verification is enabled, and the MoM's signature does _NOT_
verify, currently only a warning is presented but the swupd operation
continues. In the future signature verification will become mandatory.
We first need to sort out a few details with mixer to insure the right
thing happens there.
Signed-off-by: Tim Pepper <timothy.c.pepper@linux.intel.com>
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This commit expands the swupd BATS library to encapsulate more of the
boilerplate steps in the test cases.
Additionally, bundle manifest hashes needed updating now that swupd is
emitting warnings (and later on, errors). Better to be prepared for the
switch to errors on mismatches.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Eventually, I want to add scripting to more easily create create/manage
manifests for test cases, but for now this script addresses some of the
overhead.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
In order for the chain of trust rooted at the Manifest.MoM to operate
correctly, the bundle manifest hashes (as listed in the MoM) must be
checked. For now, warnings will be emitted when hash checks fail, but
they will become errors in the near future.
This commit simplifies/splits the load_manifests() interface into
load_mom() and load_manifest(), since load_manifests() was becoming too
complex, since the handling needs for MoMs versus bundle manifests is
sufficiently different. For the new load_manifest(), the logic is
changed to first download the manifest, then check the hash, and only
then load the manifest into memory.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release incorporates a couple of bug fixes.
- Fixes the bash completion script to support calling 'swupd' with an
absolute path (e.g. /usr/bin/swupd).
- Improve behavior of 'update' when crossing a minversion, when
potentially many update artifacts only have their "last update" field
modified. For these artifacts, 'update' will now avoid downloading
fresh copies, thus improving performance times for an update.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
The recently added call to verify_file(), used to skip files that are
already installed and have correct hashes, is a nice optimization for
the case when an update crosses a build where a new minversion was
applied to the server content.
However, I ran into a case where calling verify_file() like this results
in an incomplete update: If the corresponding hash calculation of a file
in the latest version *follows a symlink" for the path in the current
version, the hashes will match (assuming the same file content).
This issue is avoidable by checking for the file's presence in the
current version's manifest first, because manifests only contain real
paths (no non-leaf path components are symlinks).
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This function is supposed to return 1 in the event a file is found
within the manifest, AND the hashes are different. The hash check logic
was mistakenly reversed.
Note that because rename support is not enabled at the moment, this
function is never called.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Instead of just checking if the versions have changed for a file to be
updated, compare the current file's hash to updated file's expected hash
and only queue files for update that are changed.
The recent GNU tar release (1.29) is more strict with option parsing in
that positional options must come before the file list to add to the
archive.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This release includes a few bug fixes:
- Improves 'bundle-add' reliability by falling back to downloading full
files in case packs contain incomplete or corrupt content.
- Addresses a memory leak in bundle includes processing.
- Improves error handling in out-of-memory conditions.
- Fixes an issue with libcurl writing to invalid memory when downloading
version info.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This is another instance of libcurl incorrectly writing to memory that
is out-of-scope. Using a dynamically allocated version_container is the
best approach here, and it makes Valgrind happy.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
When running get_latest_version, the swupd_curl_get_file would allocate
a version_container struct on the stack that would then be used by the
curl callback to keep track of the buffer offset. This use was invalid
however because the callback was run after the stack had been popped
which lead to undefined behavior.
Instead change the swupd_curl_get_file function to take the struct
itself so it will refer to memory valid for the entire length of the
call.
The swupd_curl_get_file function should likely be restructured at some
point so that in memory downloads are less of a hack (only able to
download a LINE_MAX worth of data) at some point however and this will
need to be updated again.
Instead of requiring a pack is used for bundle-add, allow the use of
verify_fix_path when staging fails to: download, verify and stage the
item using the full file.
Correct output of tests where the 'required' wording was removed.
This release includes one bug fix:
- Adds appropriate hash checks for full files after they have been
extracted. This better ensures that corrupt data will never be staged.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Check file hashes after successful tar extraction and fail if there is a
hash mismatch during udpate. As part of this change failure handling for
errors in the tar extraction path with a check space warning as a best
guess of error cause.
This change also fixes tests where the hashes were not correct and adds
a test to verify hash matching is verified.
This release fixes several bugs:
- Enforces the limitation of 'bundle-remove' to only accept one bundle
argument.
- Avoids resuming interrupted downloads if the server does not support
range requests.
- Fixes error handling of 'verify -i -m latest' in case of network
connectivity issues.
- Fixes verify_fix_path functionality to work with 'bundle-add'.
- Fixes 'check-update -v' if the swupd config files for URLs do not
exist.
- Fixes error handling for invalid arguments passed to the -p/--path
option.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
When set_path_prefix returns false, a message "cannot continue"
is prompted but swupd continues its execution, this patch goes to
err when a false is returned by set_path_prefix.
Signed-off-by: Jesus Ornelas Aguayo <jesus.ornelas.aguayo@intel.com>
Fix "Use the -c option instead" message in check-update since it does
not require the -c option, this occurs when the default contenturl
can not be foud in the config files, this patch sets the content url
with the version url value in check-update.
Signed-off-by: Jesus Ornelas Aguayo <jesus.ornelas.aguayo@intel.com>