50 Commits
Author SHA1 Message Date
Arjan van de Ven 66a537fa43 Add ability to check manifest header only
We spend a lot of wasted time parsing the entire manifest in some areas, when
only the header is needed. This patch adds a header_only flag that tells the
appropriate load manifest functions to quit early after the header is read,
instead of parsing the entire (possibly very large) manifest. Another
optimization is calling fopen() with the 'm' flag, which tries to use mmap to
access the file (for reading only).

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2016-11-04 16:24:50 -07:00
Arjan van de Ven d52f835ae0 Fix recursion of manifest includes
This patch cuts down the amount of recursion that happens by skipping a
subsequent rescursive calls to add_subscriptions if we hit a bundle that is
already subscribed.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2016-11-04 16:24:50 -07:00
Patrick McCarty 5bf28768a5 update: adapt stats to use subscribed bundles
Instead of printing the stats for what changed overall in the MoM, it's
more interesting to report what changed on their system. That is,
reporting which bundles are new, have changed, or (in the future) have
been deleted.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-11-02 11:41:00 -07:00
Patrick McCarty 4629d7a6ac Refactor subscription version setting routine
To avoid calling the version-setting function multiple times for a
single subscription list for 'update', simply reference both MoM manifests
in the function. For other subcommands that only reference a single MoM
manifest, the second argument should be NULL.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-11-02 11:41:00 -07:00
Patrick McCarty dd05fc3293 Remove use of global "subs" list
A forthcoming commit will make 'update' understand two subscription
lists, one each for the current and latest versions, so using a single
global list will no longer be sufficient.

Instead, allocate a subs list for each subcommand that needs it, and
adjust helper function signatures that need to read/write the subs list.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-11-02 11:41:00 -07:00
Brad T. Peters e8ae92a8d7 Update fallback preference for global configuration
Updates the order of preference for content_url, version_url
and format_string, from:
  1. Runtime flags
  2. Configure time options
  3. State dir files

to:
  1. Runtime flags
  2. State dir files
  3. Configure time options

This patch also changes the logic of the setter functions to allow
multiple calls. Once the respective global is set, that function will
return true or 0, ie "success", (depending on the function).

Signed-off-by: Brad T. Peters <brad.t.peters@intel.com>
2016-09-30 17:52:15 -07:00
Tim Pepper fe0a91e833 fix bundle add/remove memory leaks
Lists and manifests created during bundle add/remove actions need freed
on exit paths.

Signed-off-by: Tim Pepper <timothy.c.pepper@linux.intel.com>
2016-08-24 14:10:19 -07:00
Auke Kok 76c568630c Namespace cleanup: make functions/vars static.
Remaining hits by findstatic.pl are public API functions and
dangling statistic increments (but those last are fixed by the
PR cleaning up the stats, so they can be ignored for this PR).
2016-08-23 17:29:59 -07:00
Auke Kok b8c6335746 Statistics: inline counter increments.
This is a negligable performance increase and more of a cleanup
of symbol space. In order for these to inline, we need the stats
to be exported instead, so we go from 8+1 exports to 1+1.
2016-08-23 17:25:48 -07:00
Patrick McCarty db14cca9b5 Return special error code for signature initialization
Since signature initialization occurs in swupd_init(), use the same
convention as other init steps by defining/using a special error code.

As a side effect, the return value type is fixed (int vs bool) for the
signature init failure case.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-08-22 16:43:29 -07:00
Patrick McCarty c8cb344367 Print some build-time options in --version output
To make compile-time options more easily discoverable at runtime, make
the --version output more verbose by printing a few of them. Other
options can be easily added in the future by adding an appropriate
AC_DEFINE call in configure.ac, and updating the new header added in
this commit (swupd-build-opts.h).

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-08-22 16:33:26 -07:00
Jose R Guzman a8e8c3d8a6 Make directory hashes independent on filename
Calculate the hash for directories is desiderable to be independent
on the dirname due to the subsequent calculation on the staged/HASH
file. Here is used const "DIRECTORY" string for input name for
all folders.

Signed-off-by: Jose R Guzman <jose.r.guzman.mosqueda@intel.com>
2016-08-04 12:04:51 -07:00
Patrick McCarty f118ea880a Run clang-format on sources
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-27 10:38:27 -07:00
Tim Pepper 499166ca4f move libcrypto init/cleanup to swupd_init()/swupd_deinit()
The poorly documented libcrypto in OpenSSL apparently does not like
its initialization and cleanup functions to be called but at process
start and exit.  Swupd-client already has a swupd_init() so easy on
that side.  But there was no common swupd_deinit() in which to place
terminate_signature().  I add one and put the common exit cleaners in it
and fix of a number of little inconsistencies around process exit cleanup
that have come to exist because there was a common cleaner.

With this, the signature verification of both the current and latest
MoM works, where prior only a first verification succeeded.

This patch also fixes a few memory leaks, though there are still many
memory leaks in swupd bundle-add and bundle-remove, unrelated to signature
verification.  And swupd search is segfaulting due to how load_mom()
is introduced in 8cf0ef91dd.

Signed-off-by: Tim Pepper <timothy.c.pepper@linux.intel.com>
2016-06-24 20:12:18 -07:00
Tim Pepper 97f46edd52 Implement signature verification
This patch adds functionality for the swupd client to do signature
verification on the MoM, which ensures a root of trust for the rest
of the update by guaranteeing the authenticity of the MoM and content
it includes.

As we focus now on just verifying the signed MoM, a number of functions now
become static to src/signature.c.

By default MoM signature verification is disabled.  Configure
--enable-signature-verification to enable it.  When enabled the default
cert for verification is /usr/share/clear/update-ca/ClearLinuxRoot.pem, as
specified by concatenation of SWUPDCERT onto UPDATE_CA_CERTS_PATH.  The
SWUPDCERT can be overridden via configure --with-swupdcert=some.pem.

When signature verification is enabled, and the MoM's signature does _NOT_
verify, currently only a warning is presented but the swupd operation
continues.  In the future signature verification will become mandatory.
We first need to sort out a few details with mixer to insure the right
thing happens there.

Signed-off-by: Tim Pepper <timothy.c.pepper@linux.intel.com>
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2016-06-24 15:12:28 -07:00
Patrick McCarty 8cf0ef91dd Implement bundle manifest hash checks
In order for the chain of trust rooted at the Manifest.MoM to operate
correctly, the bundle manifest hashes (as listed in the MoM) must be
checked. For now, warnings will be emitted when hash checks fail, but
they will become errors in the near future.

This commit simplifies/splits the load_manifests() interface into
load_mom() and load_manifest(), since load_manifests() was becoming too
complex, since the handling needs for MoMs versus bundle manifests is
sufficiently different.  For the new load_manifest(), the logic is
changed to first download the manifest, then check the hash, and only
then load the manifest into memory.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-06-22 16:12:32 -07:00
William Douglas 2ca1bf3b8b Stop using out of scope stack memory
When running get_latest_version, the swupd_curl_get_file would allocate
a version_container struct on the stack that would then be used by the
curl callback to keep track of the buffer offset. This use was invalid
however because the callback was run after the stack had been popped
which lead to undefined behavior.

Instead change the swupd_curl_get_file function to take the struct
itself so it will refer to memory valid for the entire length of the
call.

The swupd_curl_get_file function should likely be restructured at some
point so that in memory downloads are less of a hack (only able to
download a LINE_MAX worth of data) at some point however and this will
need to be updated again.
2016-05-31 12:05:05 -07:00
Patrick McCarty b6d4758da7 Rename hash_compare to hash_equal
Because hash_compare returns a boolean, hash_equal is a better name to
use.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-05-10 10:50:57 -07:00
William Douglas 33ecb6357f Rework file consolidation functionality
Add new function consolidate_files that replaces
consolidate_submanifests in order to remove the requirement of modifying
manifest components in place. This change enables creating seperate
consolidated file lists for bundle-add, one for new files to be
installed on the system and one for the currently installed bundles
files. Once these have been seperated out, only files requiring
installation can be processed by do_staging and the list of files
installed on the system can be used to run verify_fix_path.

This also modifies bundle-add to stop trying to create tracking
files which was impacting testing.
2016-05-10 10:31:00 -07:00
William Douglas b849abb47d Add helper to create a file list from bundles
In order to support verify_fix_path from bundle_add, a generic file list
from bundle list needs to be implemented to replace the one embedded in
the current consolidate_submanifests function.

This function will be used to generate a file list to be passed to a new
function for consolidating a list of files (created in the following
patch).

Note the list of files this creates is not sorted.
2016-05-10 10:31:00 -07:00
William Douglas 06614d964e Add list_clone for shallow list copy creation
To support low duplication lists of files living in multiple locations
that will be required for bundle_add to be able to run
swupd_verify_fix_path add a list_clone function which will create a copy
of a list without duplicating the list data.
2016-05-10 10:31:00 -07:00
Jaime A. Garcia 102041d295 fix to check whether resume download is supported
When pack is going to be downloaded an option for
curl called resume is activated no matter what,
however although major http server support 'Range'
command that enables this functionality, not all
complies with this, when swupd client tries to
re-download a partial file from one of the server
that does not support 'Range' it will just throw
an error and stop to work until partial download
is deleted by hand.

This patch address that issue by checking first
whether server supports 'Range' command and if not
then disable 'resume' of packs.

Signed-off-by: Jaime A. Garcia <jaime.garcia.naranjo@intel.com>
2016-05-10 09:50:01 -07:00
Patrick McCarty f1cd7f19a0 Fix deletion of directory trees with 'verify --fix'
For safety, 'verify --fix' does not use swupd_rm() (like 'update') when
deleting files, etc. Instead, each deleted entry is considered
individually.

So for the deletion step to work correctly with 'verify --fix', files
contained within directories must be listed before the directories
themselves. A simple solution is to make the manifest reverse filename
sorted (opposite of the current filename sorted order).

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-04-27 10:05:54 -07:00
Ikey Doherty bd2151ddc0 Clean up tree in accordance with clang-format
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-04-22 11:45:14 -07:00
Patrick McCarty ef101ba126 Rename the version-getter functions
Since we are either determining the current OS version, or the latest OS
version, at any given time, rename these functions to reflect that.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-04-18 11:23:56 -07:00
Patrick McCarty 38a2a2e9b4 Use unique error code for current version check failure
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-04-18 11:04:31 -07:00
Patrick McCarty 2b5063fa13 Consolidate several initialization steps into swupd_init()
Since most of these checks are used by all subcommands, and are written
in slightly different ways, move all of the checks into swupd_init() to
do the checks in one place and prevent misordering of these calls.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-04-13 11:52:12 -07:00
William Douglas 1b9032a448 Add support for verify --install -m latest
Instead of specifying a version number argument to -m allow passing the
latest string which will query for the latest version and use that as
the install target version.
2016-04-12 21:33:19 +00:00
Jaime A. Garcia 14bfa6da49 add --statedir option to alternate state directory
This option overrides the global setup for state_dir
variable that is now used to find out where swupd
is going to do work (state dir).

If not --statedir option is passed along, the global
STATE_DIR definition value is going to be used instead,
this last one can also be changed at compilation time.

Signed-off-by: Jaime A. Garcia <jaime.garcia.naranjo@intel.com>
2016-04-12 11:13:14 -07:00
Patrick McCarty 68f893c471 Refactor path_prefix initialization
Similar to how the content URL, version URL, and format string globals
are now set, do a similar reorganization to set path_prefix in its own
function and update all subcommands to use this new function.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-04-08 11:38:00 -07:00
Patrick McCarty afce2631d6 Fix check for symlinks in a dirname path
The intended behavior here is to check if the directory path for the
current file contains any symlinks, not the full path itself. By not
checking the directory path only, verify --fix would not delete any
symlinks that were marked deleted.

Also, because the directory path is being examined now, we can obtain
the directory file descriptor (dirfd) and use unlinkat(2) to delete
files and directories instead of unlink/rmdir; doing so avoids race
conditions in that paths may change between calling realpath() and
unlink().

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-04-05 11:27:31 -07:00
William Douglas a4fe27abad Add includes support in verify
Make verify include aware by adding includes from the official manifest
to the subs list before consolidating the manifests.
2016-04-04 21:24:45 +00:00
William Douglas 7e636c07d1 Fix update when include manifests are not new
Previously include manifests that were not newer than the current
version would be silently ignored even if they had not been previously
installed causing bundles to miss included dependencies.

Fix this by adding a is_tracked field to struct file that is nonzero
when the bundle the file is contained in is marked as tracked via having
a /usr/share/clear/bundles/$name file.

The is_tracked == 0 version of the file will be dropped in the
consolidate_manifest phase if that filename from another bundle has
is_tracked != 0 to avoid downloading and installing an already existing
file.

The is_tracked == 0 version of the file will then be added to the update
list from the consolidated manifest if that file was not previously
installed on the system (in addition to the other cases it would already
have been added to the list for).
2016-04-04 21:24:43 +00:00
Patrick McCarty fd80874c05 Make local_download account for -c/-v options
Because combinations of using the libcurl FILE protocol and HTTP/HTTPS
are not supported, make sure that the two protocols specified for -c and
-v match.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-04-04 11:42:14 -07:00
Patrick McCarty 9085a4f4db Read default URLs from installed config files
Instead of hardcoding the default version URL and content URL in the
binary, read the defaults from config files that live in
/usr/share/defaults/swupd/.

If the config files do not exist, then users can pass the -c or -v
options as necessary (or -u, which sets the same value for -c and -v).

The primary motivation for this change is to enable a better experience
for the swupd mixer; users mixing a version of Clear Linux can set the
default URLs at mix time instead of always passing -c/-v/-u at runtime.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-04-04 11:42:14 -07:00
William Douglas 7544162243 Add include support for update
Add support in update to properly support bundles that include other
bundles inside them. This feature is intended to work with bundle
additions by adding included bundles (from bundles already subscribed)
to the subscription list prior to downloading packs and full files.

As part of this change the add_subscriptions function from bundle.c was
modified to handle retrying manifest downloads.
2016-03-22 10:38:57 -07:00
William Douglas dc00af2ddf Update pack download version handling
Instead of taking in versions as arguments to download_subscribed_packs,
just use the version information in the subs list items (set by calling
subscription_versions_from_MoM function).
2016-03-22 10:38:57 -07:00
William Douglas beb675de5e Don't set error for subscriptions not in MoM
Because the subs list may contain bundles that are new in the version
being updated to, don't set an error in the subs item for things not in
a particular manifest version.
2016-03-22 10:38:57 -07:00
William Douglas 53bfe188b0 Remove legacy version identifier from btrfs era
The latest_version in check_versions and read_versions was a legacy
variable used for btrfs support that no longer exists and was a
duplicate of current_version in all use cases. This patch removes the
variable completely from the above functions.
2016-03-22 10:38:57 -07:00
Dmitry Rozhkov c5a58efebb Add compatibility with libarchive's bsdtar command
Since GNU tar fails to extract files with xattrs preserved when
Integrity Measurement Architecture (IMA) is enabled some vendors
may choose to install libarchive-based tar (bsdtar) on their embedded
devices, so the swupd server needs to be able to create archives
in its format.

This patch adds one compile-time options --enable-bsdtar that is used
to enable/disable GNU tar specific options.

Signed-off-by: Dmitry Rozhkov <dmitry.rozhkov@linux.intel.com>
2016-03-17 11:31:10 -07:00
William Douglas 7143aec578 Add bundle-add include support
Eventually manifests will be able to include other manifests and this
patchset adds support for adding those included manifests when running
bundle-add on the including manifest.
2016-03-11 23:36:13 +00:00
William Douglas deba09525a Allow manifests to contain includes
Start handling the case where a manifest has an includes line. This line
will be used to specify other manifests that are to be installed with
the containing manifest.
2016-03-11 23:36:13 +00:00
William Douglas 25127cebe8 Refacter bundle installation
Pull out code that only can be run once into a bundle installer frontend
function and move code that could be run recursively into an another
function. This is done in preparation for manifest includes.
2016-03-11 23:36:13 +00:00
William Douglas 1eb40ab8e6 Update source file formats with clang v3.8 2016-03-11 15:30:43 -08:00
Patrick McCarty 47cc319c0f Fix handling of added, deleted, and corrupt boot files
A user was running into issues installing the kernel-container bundle on
Clear Linux. Namely, all missing files marked as boot were not
installed.

The root issue is that the bundle-add action does not set the "fix"
global variable before calling ignore(), so ignore() mistakenly returns
true when considering boot files that are missing, but not marked
deleted.

Because 'bundle-add' should be installing new boot files, and 'verify
--fix' should be repairing boot files if they have mismatching hashes,
remove the global "fix" variable entirely, since in all current call
sites, the "fix" behavior is expected.

Also, add another call to ignore() in remove_orphaned_files() to ensure
that any file that should be ignored (including deleted boot files) are
not removed during a 'verify --fix'.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-03-10 11:43:31 -08:00
Patrick McCarty d1a8852f3e Add support for libcurl's FILE protocol
To support swupd-client testing without connecting to a web server, it's
convenient to use libcurl's FILE protocol, which will query files on the
local filesystem instead.

Because the libcurl-multi download path for fullfiles has treated the
"0" response code as an error, but it has the opposite meaning when
using the FILE protocol, only set the error when connecting to a web
server.

Also, the libcurl-easy code for synchronous downloads didn't treat "0"
specially, so this commit ensures the proper handling, as well as
setting a generic download error for the FILE protocol specific
CURLE_FILE_COULDNT_READ_FILE.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-03-08 09:00:43 -08:00
Archana Shinde cd26ed8f2d Add verify_fix_path to fix missing path while staging a file
The verify_fix_path function takes a path and a consolidated MOM as its arguments.
It breaks down the path into subpaths and checks if each subpath is missing.
If found missing, the path is searched for in the consolidated manifest for its hash
and downloaded synchronously. It returns success if all that subpaths are verified
and fixed.
2016-03-07 14:23:18 -08:00
Patrick McCarty b925a8481c Run clang-format on the code
The following command was run with clang 3.7.1:

$ clang-format -i -style=file include/*.h src/*.c test/*.c

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-03-07 14:23:18 -08:00
Brad T. Peters e0be8cf0d3 swupd-client: Add Search Feature
New swupd primary command, offers the ability to
search for the provider of a specified binary or library.

A full complement of bundle manifests for the os-release version
is downloaded to the client prior to conducting any search. This
patch has been designed to enable this download, or staging, to
take place prior and separate from use of the search function.
However, with each search, the manifest complement is checked to
ensure completion.

Overhead:

A check against the Clear Linux 6300 manifest set
shows a search will entail a ONE TIME 83 MB network download
(the compressed manifest set), and a constant decompressed 400MB
usage on disk. Future searches will only require new or modified
manifests be downloaded.

Finally, download size is provided to notify user of expected delay

-----
Ex:
"Downloading manifests. Downloading 83.23 MB..."

Signed-off-by: Brad T. Peters <brad.t.peters@intel.com>
2016-03-07 14:23:01 -08:00
Patrick McCarty c42f8a3aa1 Initial commit
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2016-02-24 09:34:13 -08:00