The system clock may be terribly off, especially on new hardware that has not
yet been calibrated. Updates rely on the certificate and system time being
sane to verify validity, so if a mismatch is found the certificate will
be deemed invalid and the update stopped. This patch attempts to fix the
system time to something sane using the time from the swupd binary itself,
which should not have been touched by any user except root. If the time is
normal and verification fails, the cert cannot be trusted.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Currently if you try and add a non existent bundle, e.g. "foo" you get
two lines of output
foo bundle name is invalid, skipping it...
bundle(s) already installed, exiting now
This is caused by the add_subscriptions function calling itself
recursivly but failing to pass up results in a meaningful way. This
change makes the return value of add_subscriptions be a bitmask so it
can signal errors and packages added distinctly.
I did think about changing this function to return a struct but
decided this was a step too far.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
The mixer and image creator treat the certpath as the full path of the
certificate filename, and swupd should too. If someone is overriding the
certificate with the cert path option, use the supplied string and don't
append a pre-defined name to it.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
In the current system we depend on the legacy boot infrastructure, which
has been provided by clr-boot-manager in the way of compatibility scripts.
These scripts all do the same thing, which is to invoke clr-boot-manager
with the "update" subcommand.
Given that clr-boot-manager doesn't need to know the context of the
operation, i.e. it is able to deduce whether kernel or bootloaders need
updating, regardless, it makes little sense to use any of these scripts,
and we should begin to deprecate them.
In clr-boot-manager 2.0, we will look to remove these compat scripts
completely, however they will continue to exist until then to facilitate
necessary format bumps, etc.
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
The swupd unit tests need a group of
options for execution environment.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
"bundle-add" sub-command used to validate "list" option in a unit test,
now that option is part of "bundle-list" sub-command with a new
name: [-a, all], for this reason the test has been updated in order to
validate it using "bundle-list" sub-command.
Furthermore this test has been moved to new directory called
"bundlelist/all" this in order to keep source code integrity.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
The current certificate used to verify the Manifest.MoM signature is also used
to verify various build artifacts, and thus should be split up into multiple,
single function certs. This introduces a new certificate that will be used
exclusively to verify signatures for updates, while the old one will be used
to verify build artifacts like the image.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
With mandatory signature verification being enabled, the tests will have
to generate a certificate and sign their Manifest.MoMs to properly run the
swupd operations.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Ubuntu's /bin/sh is Dash, which has different error strings than Bash
for equivalent errors.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
make the return code for swupd-client be 1 if there is no update
available. This follows in the tradition of grep, which returns 0 if
there are matches, 1 if there are not, and 2 for errors.
Do the same for swupd-client update --status
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
It's not clear to me why the 'swupd search' output for the functional
tests is so much different than running it outside that environment, but
regardless, the most interesting output line is what is grepped for.
This output disparity needs further debugging.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
The bundle-remove subcommand returns a unique error code for invalid
usage, so check that instead. This also avoids the need to track
bundle-remove --help output, or ignore it.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
There are several output lines that are not very interesting to check
for functional tests, so ignore those lines completely for testing by
adding some specific regular expressions for matching.
This also enables detection of unexpected error messages that may arise
when running the tests.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This commit adds "lines-checked" files for every test that checks
swupd-client output and removes the old bash-array-style checks from
the test scripts.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This commit adds a new helper function for functional tests that enables
a more streamlined mechanism for declaring a fixed set of output lines
to check for and to compare against the swupd-client output.
To use this new interface, lines of output to be checked for a given
test will live in the "lines-checked" file within the test directory,
with the swupd-client output dumped to "lines-output". Each line of
"lines-checked" is either interpreted as a literal string, or as a
regular expression; regular expression lines are denoted with the
"REGEXP:" prefix, and all other lines are literal strings.
Note that swupd-client may emit more output lines than those checked for
in "lines-checked", and that the checked lines should be declared in
order.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
To two latest commits introduce breaking changes to the updater, so the
static server content needs to be refreshed.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Because signature verification is a feature that we need separate
testing for, and swupd's output may print a verification error (or not)
depending on how swupd was built, add a helper function to remove the
verification error message when swupd is built with verification
enabled. If verification is not enabled, swupd will not print any
message, and the function is a no-op.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
To make the change in my next commit more uniform, make sure this test
checks for the presence of some of the initial lines printed by swupd.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This commit expands the swupd BATS library to encapsulate more of the
boilerplate steps in the test cases.
Additionally, bundle manifest hashes needed updating now that swupd is
emitting warnings (and later on, errors). Better to be prepared for the
switch to errors on mismatches.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Instead of just checking if the versions have changed for a file to be
updated, compare the current file's hash to updated file's expected hash
and only queue files for update that are changed.
The recent GNU tar release (1.29) is more strict with option parsing in
that positional options must come before the file list to add to the
archive.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Instead of requiring a pack is used for bundle-add, allow the use of
verify_fix_path when staging fails to: download, verify and stage the
item using the full file.
Correct output of tests where the 'required' wording was removed.
Check file hashes after successful tar extraction and fail if there is a
hash mismatch during udpate. As part of this change failure handling for
errors in the tar extraction path with a check space warning as a best
guess of error cause.
This change also fixes tests where the hashes were not correct and adds
a test to verify hash matching is verified.
Add new function consolidate_files that replaces
consolidate_submanifests in order to remove the requirement of modifying
manifest components in place. This change enables creating seperate
consolidated file lists for bundle-add, one for new files to be
installed on the system and one for the currently installed bundles
files. Once these have been seperated out, only files requiring
installation can be processed by do_staging and the list of files
installed on the system can be used to run verify_fix_path.
This also modifies bundle-add to stop trying to create tracking
files which was impacting testing.
Update verify to correctly check the return value of get_latest_version
for errors. Since get_latest_version could return a variety of negative
error codes to signify errors compare against that range instead of -1
to determine success of the operation.
Instead of only checking if bundle-remove has at least one bundle
argument and ignoring additional ones, check that there is exactly one
argument passed to bundle-remove instead.
In the case where the swupd_download_version_to_memory callback was run
multiple times, it would overwrite previous data instead of appending.
Correct this behavior by keeping track of data written so far in the
struct passed to the callback.
Instead of specifying a version number argument to -m allow passing the
latest string which will query for the latest version and use that as
the install target version.
Stop printing a message when bundles are included and going to be
installed or if bundles are already included and going to be skipped
when doing the add_subscriptions call.
Instead update the install_bundles call to notify users when an
installed bundle was attempted to be be installed again.
In a previous commit, the init_globals() call was removed from the
hashdump code, which resulted in path_prefix not being set in case the
--basepath option was not specified, and led to a NULL pointer
dereference.
Fix the issue by calling the new set_path_prefix() function. The NULL
value will honor the --basepath option if specified, or set the default
path_prefix.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
The Manifest.os-core was present, but the compressed version was not.
Fix the issue by providing the compressed version.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Fullfile deltas were only being applied to the root filesystem, since
the prefix was a compile-time constant string (STAGING_SUBVOL) set to
"/" by default.
Instead, use path_prefix for the prefix so that the deltas can be
applied when specifying --path on the command line. This also enables
writing a functional test for the delta application, added in this
commit.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>