This release fixes a mismatch in the help menu description and long option,
and fixes the bash backwards compatibility check.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This release updates and converts the man pages to RST format, updates the
swupd bash generation script, fixes error reporting when invalid bundle names
are given to bundle-add, and introduces a new tool to verify system time and
attempt to fix it if needed so signature verification does not fail due to
system time errors.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The system clock may be terribly off, especially on new hardware that has not
yet been calibrated. Updates rely on the certificate and system time being
sane to verify validity, so if a mismatch is found the certificate will
be deemed invalid and the update stopped. This patch attempts to fix the
system time to something sane using the time from the swupd binary itself,
which should not have been touched by any user except root. If the time is
normal and verification fails, the cert cannot be trusted.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Currently if you try and add a non existent bundle, e.g. "foo" you get
two lines of output
foo bundle name is invalid, skipping it...
bundle(s) already installed, exiting now
This is caused by the add_subscriptions function calling itself
recursivly but failing to pass up results in a meaningful way. This
change makes the return value of add_subscriptions be a bitmask so it
can signal errors and packages added distinctly.
I did think about changing this function to return a struct but
decided this was a step too far.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
I noticed this printf says something about getwd(), but that's not
actually being called directly there and that's not super useful to a
non-developer human anyway. So I translated the function name to an
english description.
Signed-off-by: Tim Pepper <timothy.c.pepper@linux.intel.com>
bash 4.4 added the 'nosort' option for completion. Use this so the
flag options come before the bundle names.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Include feature request from IRC to not offer os-core and
os-core-update bundles as completion targets for bundle-remove.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
Remove the script which creates the completion script based on the
output of swupd --help. It wasn't being used (e.g. the completion
didn't have bundle-list in it).
Restructure the completion script to use a case statement to list the
valid completion options. IMHO this makes the code easier to
understand.
Add in package name completion for bundle-add. This requires
/var/lib/swupd/XXXXX/Manifest.MoM to exist (where XXXXX is the
contents of /var/lib/swupd/version), be in the correct format
etc.
Add in package name completion for bundle-remove. This uses the
contents of /usr/share/clear/bundles to get the list of installed
bundles. It would be nice to use $(swupd bundle-list) but it aborts if
it is not being run as root, so this means you can't have completion
for "sudo swupd bundle-remove".
TODO: Fix bundle completion if --path is specified.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
This release removes unused certificates from the client, and fixes the
makefile incorrectness that occured in the previous release.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The client does not do certificate pinning anymore, and it should not provide
certificates. This patch removes the unused certificates and clarifies the
certpath option.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This release fixes swupd to use the full path provided by the certpath
option and not append a hardcoded certname to it, fixes memory corruption
on multiple swupd_init calls, and fixes the lock file descriptor leaking.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The mixer and image creator treat the certpath as the full path of the
certificate filename, and swupd should too. If someone is overriding the
certificate with the cert path option, use the supplied string and don't
append a pre-defined name to it.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
When swupd_init() is called more than once in
the same supwd run, pointer corruption ocurs on
some global variables causing memory corruption
and finally a SIGABRT. This patch fixes that
condition by properly setting all globals to
NULL when swupd_deinit() is called; or more
properly free_globals().
This release adds a bundle-list subcommand to make the cli more clear,
cleans up unused files in testing dirs, and ports the post update scripts
calls to the modern clr-boot-manager directly, which is able to handle various
kinds of kernel/boot updates. Support for automated building within a docker
environment has been added to allow developers to test their changes against
latest inside of a clean Docker container.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This change adds a simple "./continous.sh" script which will allow
developers to test their changes against "clearlinux:latest" within a
clean Docker container.
If the container does not already exist, it will be created on demand.
Future builds will be done near instantly within the container.
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
Explicitly mark the return results of system as unused. This helps to
cut down on the compiler spam as we (by design) do not check the return
results of the scripts portion.
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
In the current system we depend on the legacy boot infrastructure, which
has been provided by clr-boot-manager in the way of compatibility scripts.
These scripts all do the same thing, which is to invoke clr-boot-manager
with the "update" subcommand.
Given that clr-boot-manager doesn't need to know the context of the
operation, i.e. it is able to deduce whether kernel or bootloaders need
updating, regardless, it makes little sense to use any of these scripts,
and we should begin to deprecate them.
In clr-boot-manager 2.0, we will look to remove these compat scripts
completely, however they will continue to exist until then to facilitate
necessary format bumps, etc.
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
The swupd unit tests need a group of
options for execution environment.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
This adds are required standard options
to select content server, version server,
format, and so on.
Options added:
-u, url for version string and content file downloads
-c, url for content file downloads
-v, url for version string download
-p, path to verify
-F, format suffix for version file downloads
-n, Do not attempt to enforce certificate or signature checking
-S, Specify alternate swupd state directory
-C, Specify alternate path to swupd certificates
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
"bundle-add" sub-command used to validate "list" option in a unit test,
now that option is part of "bundle-list" sub-command with a new
name: [-a, all], for this reason the test has been updated in order to
validate it using "bundle-list" sub-command.
Furthermore this test has been moved to new directory called
"bundlelist/all" this in order to keep source code integrity.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
The option [-l, --list] is no longer part of "bundle-add"
sub-command, now this option has been taken by "bundle-list"
sub-command using a new name [-a, --all], this information
is updated in swupd man page and markdown file.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
The current option name (--list) for bundle-list sub-command
could sound redundant and confuse, [-a, --all] is a more
a more appropriate name since it can show "all" available bundles
in certain clear linux release.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
This option has been used to list all available bundles
in certain clear linux release, it is present in "bundle-add"
sub-command however at this moment this option is more consistent
if "bundle-list" sub-command get it.
This is in order to keep coherence and semantic.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
This release introduces a new certificate for swupd to verify Manifest.MoM
signatures with. The old certificate served too many purposes, so to logically
seperate it, swupd will now have its own certificate solely for verifying
updates, while another will be used to verify build artifacts.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The current certificate used to verify the Manifest.MoM signature is also used
to verify various build artifacts, and thus should be split up into multiple,
single function certs. This introduces a new certificate that will be used
exclusively to verify signatures for updates, while the old one will be used
to verify build artifacts like the image.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This release enables mandatory signature verification, which means the
Manifest.MoM signature MUST verify correctly for an update operation to
continue, else swupd will exit. This ensures that wherever the content comes
from, i.e thru a CDN, clients are guaranteed to receive the "correct" content
that they were intended to consume. It also forces clients to remain on the
secure update path if only verifiable content is allowed on the system.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This sets swupd signature verification to mandatory, failing and exiting
for any verify error, though --nosigcheck enables user to bypass all
signature-based security checks.
The signed MoM serves as the top level chain of trust, and it is used to
extend content trust down to the individual file level. When the signature
of the top-level MoM is invalid or cannot be verified for any reason, we
warn and abort the operation.
Passing --nosigcheck will allow this to proceed, explicitly accepting the
unverifiable MoM and outputting a log entry to the Journal. This is not
recommended and unsupported by upstream once the chain of security is broken,
because it may imply update content was or may be installed that was not
generated by the official upstream.
Signed-off-by: Brad T. Peters <brad.t.peters@intel.com>
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This release updates errors so they return proper values in various code
paths, adds the bundle-list subcommand, fixes style for compliance via
clang-format, adds support to supply a certificate at runtime, and updates
testing to support mandatory signature verification.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The other subcommands already use this error code, so make 'update' use
it too.
Also, the calls to 'strerror(errno)' don't make sense in this context,
so remove them.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Make sure tar extraction errors count towards pack errors, and use the
generic ENOSWUPDSERVER if download retries do not resolve the issue.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>