This release introduces a new certificate for swupd to verify Manifest.MoM
signatures with. The old certificate served too many purposes, so to logically
seperate it, swupd will now have its own certificate solely for verifying
updates, while another will be used to verify build artifacts.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The current certificate used to verify the Manifest.MoM signature is also used
to verify various build artifacts, and thus should be split up into multiple,
single function certs. This introduces a new certificate that will be used
exclusively to verify signatures for updates, while the old one will be used
to verify build artifacts like the image.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This release enables mandatory signature verification, which means the
Manifest.MoM signature MUST verify correctly for an update operation to
continue, else swupd will exit. This ensures that wherever the content comes
from, i.e thru a CDN, clients are guaranteed to receive the "correct" content
that they were intended to consume. It also forces clients to remain on the
secure update path if only verifiable content is allowed on the system.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This sets swupd signature verification to mandatory, failing and exiting
for any verify error, though --nosigcheck enables user to bypass all
signature-based security checks.
The signed MoM serves as the top level chain of trust, and it is used to
extend content trust down to the individual file level. When the signature
of the top-level MoM is invalid or cannot be verified for any reason, we
warn and abort the operation.
Passing --nosigcheck will allow this to proceed, explicitly accepting the
unverifiable MoM and outputting a log entry to the Journal. This is not
recommended and unsupported by upstream once the chain of security is broken,
because it may imply update content was or may be installed that was not
generated by the official upstream.
Signed-off-by: Brad T. Peters <brad.t.peters@intel.com>
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This release updates errors so they return proper values in various code
paths, adds the bundle-list subcommand, fixes style for compliance via
clang-format, adds support to supply a certificate at runtime, and updates
testing to support mandatory signature verification.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The other subcommands already use this error code, so make 'update' use
it too.
Also, the calls to 'strerror(errno)' don't make sense in this context,
so remove them.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Make sure tar extraction errors count towards pack errors, and use the
generic ENOSWUPDSERVER if download retries do not resolve the issue.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
When pack or fullfiles fail to download for 'verify --install' or
'verify --fix', respectively, the operation fails, but it does not leave
the system in a corrupt state, so there is no need to report stats in
this situation.
Also, make sure to use errors from the download functions in case
they return specific error codes (converted here to their positive
variants).
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
It was only being reset for the first call, but it should be reset
immediately before *every* call to ensure correct error detection.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Again, to consolidate usage of custom error codes, EINVALID_OPTION is
always used for command-line option parsing failure.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This information describes the funcionality
of "bundle-list" sub-command. It is added to
swupd man page and swupd markdown file.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
This is a new sub-command for swupd called
"bundle-list", this command will show which
bundles are installed in the local system.
This information is obtained reading
/usr/share/clear/bundles path in local filesystem.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
This function reads installed bundles from local standard
directory and store them in a list pointer passed as argument, this
function is the base for functionality as listing installed bundles to
user.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
As it turns out, systemd is so efficient spotting new telemetry
records and spawning swupd-probe to retrieve them, that on several
occasions it does so before the entire record is written out by
printf(). This results in the server receiving an empty record from
the swupd telemetry process - it is reading the record data before
writing succeeded.
To guard against this, we atomically move (rename(2)) the record
after it was fully generated. This assures that the full record data
is present before swupd-probe can see it.
To do this safely, we mkstemp() the record outside the telemetry
spool in /var/lib/swupd, and then move it after it is complete
into /var/lib/swupd/telemetry. This requires, unfortunately, that
we use basename(3), and another string for the final file name,
since rename(2) doesn't allow moving to a folder (it requires the
file argument).
To simplify the discovery of C code style issues and enforce the rules
specified in .clang-format, I've added a new 'compliant' target for
running the appropriate clang-format command.
In case code style issues are found, source files are modified in place,
and the resulting diff can be viewed. The exit code in this case will be
1, so make will exit with an error. This helps to automate testing for
code style issues.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
With mandatory signature verification being enabled, the tests will have
to generate a certificate and sign their Manifest.MoMs to properly run the
swupd operations.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Each of the subcommands that may perform signature verification should
be able to override the default cert path using the function defined in
the previous commit. If signature verification is *not* enabled, the
overrides are no-ops.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
There is a need to override the cert path at runtime, so migrate to
using a global variable that is set in init_globals().
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Because the semantics of how these routines operate are not completely
obvious, make sure they are documented.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
To better support running the functional test suite with signature
verification enabled, make the certificate location configurable. Note
that the basename of the certificate used for verification can be
configured separately with the --with-swupdcert=NAME option.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This commit establishes a style guide for the configure.ac. General
guidelines follow, mostly related to whitespace. I haven't decided on
specific rules for quotation yet but I try to be consistent with style
for similar macros being called.
- Use 2-space indent (lines can get lengthy).
- Macros are called with (a) all arguments on the same line, or (b) all
arguments split into multiple lines. If a single argument continues
for multiple lines, use a 2-space indent for the second line only (the
remaining lines for the argument keep the same indent level).
- The begin-quote character ([) does not count for the indent level;
start the count with the character following the [.
- The close-quote character (]) never appears on a line by itself.
- For multi-line macro calls, the open paren should end the first line,
and the close paren should begin the last line.
- For single-line macro calls, include spaces after the commas that
separate macro arguments. For multi-line macro calls, the commas
appear at the end of a line.
- Omit the comma after the last macro argument.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This is a change for consistency and readability. AS_IF() is more
commonly used than a shell 'if', so I opted to use it.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Because these standard checks are unconditionally run at toplevel,
consolidate the macro calls to a single spot to ease maintenance.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This adds telemetry status output for bundle add and remove.
In the case of remove, we expect a single bundle name.
In the case of remove, we make a nice string with all the bundle
names as we iterate and use that in the telemetry output.
We change the telemetry API to pass a class record identifier,
which will be part of the telemetry record file name. This allows
us easier to send different telemetry class records to the server,
which will make parsing simpler in the probe and on the backend.
Rev record version to #2 because of this change.
This release includes several significant fixes and additions to swupd-client:
- Renable telemetry in the client with a new implementation, writing records to
a file and not blocking swupd operations at all.
- Enable travis-ci integration
- Fix xattrs enable flag in conjunction with enabling bsdtar
- Ignore xattrs when processing manifests
- Enable out of tree builds
- Enable automatic updates through timer units
- Adds man pages
- Re-enable updating of config files
- Remove block on post-update triggers, saving another 1.5-2 seconds for update
- Miscellaneous fixes for typos and updates to autotools files for completeness
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The telemetry function only works insire swupd_init() / swupd_deinit()
functions, as it accesses state_dir from globals. This restricts the
use of it a bit, so we move the timekeeping function into
main_update().
Aside from update, I've added a telemetry point in verify as well.
With this, we have several easy telemetry points in swupd that
should give us an indication how swupd is performing without divulging
lots of detailed information.
The swupd.h file contains easy defines for level, and the telemetry()
function itself is as failsafe as it can be - any error results in
a continuing swupd program, although these errors would occur in
a system that is already hopeless (disk full) anyway.
This folder will be collecting output for telemetry. The
output will only ever be written by swupd. A separate
component will be collecting these telemetrics at a later
time to send them.
Cleaning this folder should be done through tmpfiles.d.
When IMA or Smack are active on the client, the downloaded Manifest
files will be assigned certain xattrs (security.ima
resp. security.SMACK64). Those xattrs did not exist on the server side
(because it is most likely not having those kernel features enabled)
and besides, the swupd-server code wouldn't include them in the
Manifest hashes even if they existed (see write_manifest_plain() in
src/manifest.c).
Therefore the client must ignore xattrs when verifying Manifest files.
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
For now, the config simply installs missing build dependencies and works
around the umask discrepancy for running the functional test suite.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Ubuntu's /bin/sh is Dash, which has different error strings than Bash
for equivalent errors.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Depending on how libcurl is configured, CURLOPT_PIPEWAIT may not be
supported, so make the unsupported case non-fatal.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>