Add a "swupd verify --picky" command which lists files under
/usr (modified by the --path option) which are not listed in the
current manifest. Exceptions /usr/local and /usr/lib/modules. The
former to allow for local changes, the latter because the clear boot
manager owns that directory.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
This is a wrapper around remove_bundle()
to add consistency for bundle-remove
subcommand respect bundle-add that accepts
one or more bundles to be removed.
This must not be the optimal implementation
but it works fine and gives a better user
usage experience.
Arrange for "bad names" to give non-zero exit code
Arrange for "do nothing" in particular when packages are already
installed to give a zero return code.
This means that typos in names result in failures, but that trying to
add an existing package is fine.
Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
This will ensure the system has a more correct, usable time after boot,
which not only improves swupd reliability but other services' as well.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The system clock may be terribly off, especially on new hardware that has not
yet been calibrated. Updates rely on the certificate and system time being
sane to verify validity, so if a mismatch is found the certificate will
be deemed invalid and the update stopped. This patch attempts to fix the
system time to something sane using the time from the swupd binary itself,
which should not have been touched by any user except root. If the time is
normal and verification fails, the cert cannot be trusted.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The client does not do certificate pinning anymore, and it should not provide
certificates. This patch removes the unused certificates and clarifies the
certpath option.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
"bundle-add" sub-command used to validate "list" option in a unit test,
now that option is part of "bundle-list" sub-command with a new
name: [-a, all], for this reason the test has been updated in order to
validate it using "bundle-list" sub-command.
Furthermore this test has been moved to new directory called
"bundlelist/all" this in order to keep source code integrity.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
This is a new sub-command for swupd called
"bundle-list", this command will show which
bundles are installed in the local system.
This information is obtained reading
/usr/share/clear/bundles path in local filesystem.
Signed-off-by: Mario Alfredo Carrillo Arevalo <mario.alfredo.c.arevalo@intel.com>
To simplify the discovery of C code style issues and enforce the rules
specified in .clang-format, I've added a new 'compliant' target for
running the appropriate clang-format command.
In case code style issues are found, source files are modified in place,
and the resulting diff can be viewed. The exit code in this case will be
1, so make will exit with an error. This helps to automate testing for
code style issues.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
With mandatory signature verification being enabled, the tests will have
to generate a certificate and sign their Manifest.MoMs to properly run the
swupd operations.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
To better support running the functional test suite with signature
verification enabled, make the certificate location configurable. Note
that the basename of the certificate used for verification can be
configured separately with the --with-swupdcert=NAME option.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
The telemetry function only works insire swupd_init() / swupd_deinit()
functions, as it accesses state_dir from globals. This restricts the
use of it a bit, so we move the timekeeping function into
main_update().
Aside from update, I've added a telemetry point in verify as well.
With this, we have several easy telemetry points in swupd that
should give us an indication how swupd is performing without divulging
lots of detailed information.
The swupd.h file contains easy defines for level, and the telemetry()
function itself is as failsafe as it can be - any error results in
a continuing swupd program, although these errors would occur in
a system that is already hopeless (disk full) anyway.
The backslash for the second-to-last entry in EXTRA_DIST was omitted,
leading to a dist issue.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Add a large amount of manual pages to swupd-client project. These are
meant to cover a large amount of topics and should cover the needed
material for people who are either using, or mixing with swupd,
and so this goes a bit further than end user documentation.
I've put the unit stuff in section 4. Any other section seemed
less related.
We disable check-update.timer by default. Having a message in the
journal isn't helpful, and there currently is no API to properly
query for update (except for running swupd check-update).
We add auto-update timer units. These can be masked (`systemctl
mask swupd-update.service`) to disable auto-updates, or enabled
if the OS ships with them not enabled. The project ships with
them not enabled for now, may end up enabling them later in time.
When doing out-of-tree builds, the distributed
scripts are in different directory than where
the build is happening. This doesn't work:
make install-exec-hook
make[2]: Entering directory '<builddir>'
perl scripts/findstatic.pl */*.o | grep -v Checking ||:
Can't open perl script "scripts/findstatic.pl": No such file or directory
make[2]: Leaving directory '<builddir>'
We therefore need to give perl the full path
of the perl-script to run using the standard
automake variable top_srcdir:
make install-exec-hook
make[2]: Entering directory '<builddir>'
perl ../../../../../../../../tmp/swupd-client.git/scripts/findstatic.pl */*.o | grep -v Checking ||:
'bin_paths' is unique to src/search.o, should be static? (initialised variable)
'do_search' is unique to src/search.o, should be static? (function)
'download_manifests' is unique to src/search.o, should be static? (function)
'file_search' is unique to src/search.o, should be static? (function)
'lib_paths' is unique to src/search.o, should be static? (initialised variable)
'report_find' is unique to src/search.o, should be static? (function)
'scope' is unique to src/search.o, should be static? (initialised variable)
'search_type' is unique to src/search.o, should be static? (initialised variable)
make[2]: Leaving directory '<builddir>'
Signed-off-by: André Draszik <git@andred.net>
This patch adds functionality for the swupd client to do signature
verification on the MoM, which ensures a root of trust for the rest
of the update by guaranteeing the authenticity of the MoM and content
it includes.
As we focus now on just verifying the signed MoM, a number of functions now
become static to src/signature.c.
By default MoM signature verification is disabled. Configure
--enable-signature-verification to enable it. When enabled the default
cert for verification is /usr/share/clear/update-ca/ClearLinuxRoot.pem, as
specified by concatenation of SWUPDCERT onto UPDATE_CA_CERTS_PATH. The
SWUPDCERT can be overridden via configure --with-swupdcert=some.pem.
When signature verification is enabled, and the MoM's signature does _NOT_
verify, currently only a warning is presented but the swupd operation
continues. In the future signature verification will become mandatory.
We first need to sort out a few details with mixer to insure the right
thing happens there.
Signed-off-by: Tim Pepper <timothy.c.pepper@linux.intel.com>
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Instead of just checking if the versions have changed for a file to be
updated, compare the current file's hash to updated file's expected hash
and only queue files for update that are changed.
Instead of requiring a pack is used for bundle-add, allow the use of
verify_fix_path when staging fails to: download, verify and stage the
item using the full file.
Correct output of tests where the 'required' wording was removed.
Check file hashes after successful tar extraction and fail if there is a
hash mismatch during udpate. As part of this change failure handling for
errors in the tar extraction path with a check space warning as a best
guess of error cause.
This change also fixes tests where the hashes were not correct and adds
a test to verify hash matching is verified.
Update verify to correctly check the return value of get_latest_version
for errors. Since get_latest_version could return a variety of negative
error codes to signify errors compare against that range instead of -1
to determine success of the operation.
Instead of only checking if bundle-remove has at least one bundle
argument and ignoring additional ones, check that there is exactly one
argument passed to bundle-remove instead.
In the case where the swupd_download_version_to_memory callback was run
multiple times, it would overwrite previous data instead of appending.
Correct this behavior by keeping track of data written so far in the
struct passed to the callback.
A couple of changes break the libswupd ABI:
- removal of the "fix" symbol (global variable)
- modification of the do_staging() signature
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
On install phase certificate files are being installed twice as included in
_DATA twice. We can use EXTRA_DIST than dist_.
Signed-off-by: Amarnath Valluri <amarnath.valluri@intel.com>
To generate test coverage reports, run:
$ ./configure --enable-coverage
$ make check
$ make coverage
Results can be browsed from the coverage/index.html file.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
New swupd primary command, offers the ability to
search for the provider of a specified binary or library.
A full complement of bundle manifests for the os-release version
is downloaded to the client prior to conducting any search. This
patch has been designed to enable this download, or staging, to
take place prior and separate from use of the search function.
However, with each search, the manifest complement is checked to
ensure completion.
Overhead:
A check against the Clear Linux 6300 manifest set
shows a search will entail a ONE TIME 83 MB network download
(the compressed manifest set), and a constant decompressed 400MB
usage on disk. Future searches will only require new or modified
manifests be downloaded.
Finally, download size is provided to notify user of expected delay
-----
Ex:
"Downloading manifests. Downloading 83.23 MB..."
Signed-off-by: Brad T. Peters <brad.t.peters@intel.com>