415 Commits
Author SHA1 Message Date
Tudor Marcu d237c30578 Release v3.9.4
This release adds the -Y option to the command line to supplement --picky.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.9.4
2017-06-05 18:51:52 -07:00
Alberto Murillo Silva 4214fd335a Add -Y option to parseargs argument
--picky option was being recognized by swupd verify but not
its equivalent -Y

Signed-off-by: Alberto Murillo Silva <alberto.murillo.silva@intel.com>
2017-06-05 12:27:06 -07:00
Tudor Marcu 7b40491d9b Release v3.9.3
This release adds the --picky option to the verify --fix subcommand, making
verify --fix actually remove files not tracked under /usr instead of just
reporting them.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.9.3
2017-05-25 16:55:48 -07:00
Tudor Marcu ca3401e7fa Add verify --fix --picky functionality
This is the basic implementation for a "factory reset" type of command.
It will take the functionality of verify --picky and act on the files found
as verify --fix does with files found mismatching in the manifest.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-05-25 16:41:13 -07:00
Tudor Marcu 7120bb95df Release v3.9.2
This release introduces the verify --picky subcommand, which lists files under
/usr, a new subcommand "autoupdate" which allows for easy enable/disable
of autoupdates and its current status, and converts printfs to fprintf to
stderr throughout the code as appropriate.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.9.2
2017-05-18 16:26:13 -07:00
Icarus Sparry 2487e5b5d0 Add swupd autoupdate command
"swupd autoupdate" returns 0 if autoupdates are enabled.
"sudo autoupdate --enable" will unmask swupd-update.service
"sudo autoupdate --disable" will mask swupd-update.service

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-05-17 15:28:44 -07:00
Icarus Sparry 4afaf2c312 Add verify --picky command
Add a "swupd verify --picky" command which lists files under
/usr (modified by the --path option) which are not listed in the
current manifest. Exceptions /usr/local and /usr/lib/modules. The
former to allow for local changes, the latter because the clear boot
manager owns that directory.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-05-09 12:53:14 -07:00
Icarus Sparry aa8417812d Convert printf to fprintf(stderr, almost everywhere
Write error and informative messages to stderr, only
write data to stdout so it can be piped to other programs.

Make stdout line buffered, rather than introduce race conditions into tests

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-05-09 12:12:39 -07:00
Tudor Marcu 4960bb87e9 Fix formatting issues
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-05-09 10:40:19 -07:00
Tudor Marcu 595500595e Release v3.9.1
This release fixes a bug in signature verification retries, and adds support
to client so it understands a new manifest header field called "action." The
new field will allow client to detect if more actions need to be taken after
an update, i.e run verify --fix.

Signe-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.9.1
2017-05-09 09:41:52 -07:00
Tudor Marcu 55cca1291a Only take actions from newest MoM
The update process should only read in post update action from the newest
MoM. This makes it so that even with a previous MoM having an action, only
the new one will be taken, and if none exist, the old one will be ignored
so swupd will not take the same action as the previous update.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-05-09 09:40:47 -07:00
Tudor Marcu 0fbc8cb6b1 Add support for new manifest header line
The swupd client should support parsing extra data in the case that a format
bump occurred, or other possibly breaking change, so that it can at least
notify the user of more action needing to be taken post update.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-05-09 09:40:47 -07:00
Tudor Marcu 63763ee680 Fix infinite signature failure loop
Unlike the regular manifest loading code, loading a MoM also requires signature
verification to succeed. We cannot reset the retries after a signature
failed because the manifest may load fine, but still fail verification,
resulting in endlessly loading and verifying the Manifest.MoM

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-05-08 14:26:28 -07:00
Tudor Marcu f508685873 Release v3.9.0
This release adds retries to pack downloads for bundle-add. The downloads
could fail if network connectivity is lost, which drops the code into a
slower download path. Instead, attempt to retry pack downloads to stay on
the optimal code path before finally dropping into the fullfile fallback.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.9.0
2017-05-01 11:21:56 -07:00
Tudor Marcu 29b9d1e3a9 Retry pack downloads on bundle-add
The download_subscribed_packs() could fail for network issues or other related
problems, and because the only option for getting new packs is by downloading
zero packs or fullfiles, swupd should retry to get the packs before falling
into the verify_fix_path flow which signifies pack downloads errored out.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-28 14:38:53 -07:00
Tudor Marcu ebfbe017a9 Release v3.8.9
This release fixes a subtle bug in try_delta_manifest_download() that would
incorrectly set the file struct causing hashes to become incorrect. It further
fixes problems in the retry path, in which it would loop continuously until
it was able to load a correct manifest.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.8.9
2017-04-20 16:42:56 -07:00
Tudor Marcu 68c1748cc4 Update code style
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-20 16:39:05 -07:00
Tudor Marcu 88d4867532 Fix update retry structure
The update code did not jump to the correct points when it needed to retry,
causing swupd to run into infinite loops if it could not load a given manifest
at all.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-20 16:34:26 -07:00
Tudor Marcu a9cd09f084 Fix try_delta_manifest to populate file correctly
The new file struct cannot be populated using the original because it will
contain attributes and data that may not match the new file, breaking hash
computation. We must freshly populate the struct with the new file only
after bsdiff application succeeds, and then compute hash to ensure all data
is indeed from the new file. It is also irrelevant to precompute the hash
before attempting to apply the delta, so we remove that code block

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-20 16:34:26 -07:00
Tudor Marcu 0cdf8ef62a Release v3.8.8
This release fixes incorrect download messages printing for packs, validation
for the format number supplied to the binary, and enables delta file
application for manifests. Manifest deltas can be more than 150 times smaller
than the full file tar, saving time on updates by downloading much less data.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.8.8
2017-04-19 16:58:28 -07:00
Tudor Marcu e09ee30d10 Check for fullfile and not tar of manifests
The tarfiles should not be kept after swupd runs, so check for the fullfile
instead and skip having to extract it.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-19 16:41:59 -07:00
Tudor Marcu d02783ce9c Fix try_delta_manifest_download
If there is no peer or we cannot get a delta, quit and don't mess with the
file struct. Pre-populating the file struct then exiting early corrupts the
manifest list for later operations, and is a noop when the file cannot be
found to begin with. If there is no peer, it likely is a new manifest and
thus a delta cannot exist.

Should the delta application succeed, we MUST compute and set the new hash
for the file else it will retain the hash of the previous version, and not
pass hash check.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-19 16:41:59 -07:00
Tudor Marcu 64ff23d329 Refactor flow of manifest loading
The current implementation is not setup to optimally load manifests and attempt deltas.
This changes the flow to be as follows:
1.) Load current Manifest.MoM
2.) Load server Manifest.MoM
3.) Recurse and load all current manifests, since we know exactly which are needed already
4.) Link current and server Manifest.MoMs, setting versions and peers
5.) Load server manifests recursively adding their includes
6.) Recurse the server manifests to find and load any new included bundles
7.) Link current and server Manifest.MoMs again to account for new bundles

When loading the server manifests, deltas will attempt to be applied to
current manifests before doing a full download. Following this flow enables
swupd to load manifests in a logical order, and short circuit trying to
reload them later on as manifests are recursed for includes again later.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-19 16:41:59 -07:00
Tudor Marcu 3c87523101 Use correct version for adding included manifests
The current version must be passed to add_subscriptions, else it will call
load_manifest() with equal current and server versions and never enter the
try_delta_manifest code path.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-19 16:41:59 -07:00
Patrick McCarty a9807a2439 build: validate --with-formatid input
To ensure validity of the format number hardcoded in the binary, check
the supplied input against a regular expression using grep.

Note that the double square brackets are needed for the regex character
classes because square brackets are used for M4 quotation in Autoconf;
an extra pair of square brackets is needed to prevent them from being
stripped in the configure script.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-04-19 12:30:19 -07:00
Tudor Marcu dac74856da Update tests for new messages being printed
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-19 10:12:51 -07:00
Tudor Marcu 56efd14d27 Fix download/extract pack message
Swupd incorrectly says "Downloading pack <name>..." even if it does not
really download the pack. Fix this by saying downloading packs and only
printing if we downloaded a pack to extract.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-19 10:12:51 -07:00
Tudor Marcu 2c0019ba95 Release v3.8.7
This release adds proper systemd-reexec and daemon reload calls which must
be called without --no-block, such that triggers called after update are
the new triggers.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.8.7
2017-04-18 00:00:44 -07:00
Tudor Marcu 9868bedb83 Need to reexec systemd if it changed
We must not run these with --no-block because order must be preserved,
and critical components may need to be reexec'd, making this a core piece
of the swupd update process.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-17 17:10:34 -07:00
Patrick McCarty 5a6cbc524f Merge tag 'v3.8.6'
swupd-client release 3.8.6
2017-04-04 13:19:52 -07:00
Tudor Marcu dd0c83d328 Release v3.8.6
This release introduces some large changes,
Features:
- swupd -t/--time flag to enable verbose timing output of swupd operations
  (update, verify, bundle-add)
- verifytime service added to boot to check client systems are on a sane time
- Accept multiple bundles when using bundle-remove

Fixes:
- Attempt to automatically fix statedir corruption from bad files/tars
- Fix download and hysteresis logic on error paths and improve curl usage
- Improve return codes for bundle-add to cover various scenarios of
  incorrect/correct bundle additions

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-04 12:10:07 -07:00
Tudor Marcu e93befb510 Fix code style
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-04 12:10:07 -07:00
Tudor Marcu 3820355ed0 Release v3.8.6
This release introduces some large changes,
Features:
- swupd -t/--time flag to enable verbose timing output of swupd operations
  (update, verify, bundle-add)
- verifytime service added to boot to check client systems are on a sane time
- Accept multiple bundles when using bundle-remove

Fixes:
- Attempt to automatically fix statedir corruption from bad files/tars
- Fix download and hysteresis logic on error paths and improve curl usage
- Improve return codes for bundle-add to cover various scenarios of
  incorrect/correct bundle additions

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.8.6
2017-04-04 12:03:55 -07:00
Jaime A. Garcia 6a8d36763b Accept multiple bundles at bundle-remove
This is a wrapper around remove_bundle()
to add consistency for bundle-remove
subcommand respect bundle-add that accepts
one or more bundles to be removed.

This must not be the optimal implementation
but it works fine and gives a better user
usage experience.
2017-04-04 11:50:21 -07:00
Patrick McCarty 0a90bd8e05 Add an extra curl_multi_perform() call
To give libcurl an extra opportunity to do more work, add an additional
curl_multi_perform() call interleaved between curl_multi_wait() and the
attempt to process completed transfers.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-04-04 11:48:45 -07:00
Patrick McCarty cd555fe35e Adjust strategy for emptying curl multi stack
The "numfds" variable set by curl_multi_wait() does not appear to be a
reliable indicator of how many transfers to try popping of the stack. I
went with this approach because the documented BKM, namely to check if
the "running" variable changes between calls to curl_multi_perform(), is
a bit inconvenient to integrate with swupd's code flow here.

Instead, try to empty the multi stack down the hysteresis lower bound,
and only check "numfds" to detect no activity at all. This approach
seems to perform better, resulting in a more balanced sequence of
additions and removals from the stack over time.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-04-04 11:48:45 -07:00
Patrick McCarty 811018a1f0 Avoid escape for download hysteresis upper bound
If a system loses network connectivity in the middle of fullfile
downloads for update (or verify --fix), and there are more pending
transfers to queue than remaining available file descriptors for the
process, the hysteresis upper bound is bypassed and swupd runs out of
open file descriptors.

To avoid this issue, the upper bound (plus a small buffer for leeway)
should be enforced in poll_fewer_than(). Since there is little
visibility into the state of libcurl as to why no downloads are
progressing, if the upper bound is bypassed, simply append the most
recently added file to the failed list.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-04-04 11:48:45 -07:00
Patrick McCarty c9e84a22f9 Avoid cleaning the multi queue too early
There may be in-progress transfers in the multi queue if
poll_fewer_than() returns an error, so a full clean of the multi queue
should be deferred.

The queue is already cleaned up immediately before the next download
retry loop begins; this is the best place for cleanup, since all
transfers have either completed or failed before the cleanup is
triggered.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-04-04 11:48:45 -07:00
Patrick McCarty 047010d534 Unify error handling for poll_fewer_than()
If one of the poll_fewer_than() calls returned an error, a jump to the
out_bad label did not occur. Fix this issue, and also check error codes
the same way for both call sites.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-04-04 11:48:45 -07:00
Patrick McCarty 513d867461 Use existing wrapper function for curl cleanup
Because the pointer in the struct file may have been NULL'ed previously
in free_curl_list_data(), the "curl" pointer declared on the stack is
not updated.

Since the free_curl_list_data() function already checks struct file
pointer instead, call it instead. swupd_download_file_complete() is also
called by free_curl_list_data(), so that call has been removed here.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-04-04 11:48:45 -07:00
Patrick McCarty 37d914ff22 Set file CURL object pointer to NULL after freeing
Under certain error conditions for download retries, the curl multi list
cleanup routines are called more than once, leading to double frees for
CURL object pointers.

To protect against this problem, ensure that the pointers are reset to
NULL following the frees.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2017-04-04 11:48:45 -07:00
Tudor Marcu 14abf7027e Remove bad or unusable Manifest content and retry
For various reasons - partial downloads, power failure, user exiting -
the /var/lib/swupd state directory may become corrupt. When this happens,
manifests can be rendered unusable, causing various errors in swupd such as
signature failures, or errors reading the manifest. This patch attempts to
avoid such things causing updates or verifies to fail by cleaning up the
Manifests artifacts of what it could not use, and re-downloading them to
try again.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-04-04 11:48:26 -07:00
Icarus Sparry 3ec26daff7 Improved return code for bundleadd + test
Arrange for "bad names" to give non-zero exit code
Arrange for "do nothing" in particular when packages are already
installed to give a zero return code.

This means that typos in names result in failures, but that trying to
add an existing package is fine.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-04-04 11:46:19 -07:00
Tudor Marcu 49983eb68a Fix verbose flag on error path
The verbose_time flag should be set to false if getting time fails, so timing
is not attempted again later, letting swupd continue in its regular mode.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-03-30 19:41:11 -07:00
Tudor Marcu c4f8aa2111 Run verifytime at boot
This will ensure the system has a more correct, usable time after boot,
which not only improves swupd reliability but other services' as well.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-03-29 11:25:54 -07:00
Tudor Marcu a668c07265 Fix code style issues
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-03-29 10:11:08 -07:00
Tudor Marcu 90a0ad0cb9 Account for nested time calls
There may be code doing something like:

grabtime_start(&times, "Outer loop");
.       <do work>
grabtime_start(&times, "Inner loop");
.
.       <do work>
.
grabtime_stop(&times);
.       <do work>
grabtime_stop(&times);

The "Outer loop" section would not have been printed because the stop time
and completed flag would not have been set. This fixes it by checking if we
already completed the last time grab, and traverses backwards to find the
next incomplete one, which must be the outer one.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-03-29 10:06:25 -07:00
Tudor Marcu 0d346c3b7f Add verbose timing to swupd operation
This introduces a -t/--time option to update, verify, and bundle-add commands, displaying raw elapsed time and CPU process time for integral swupd operations within the given code paths.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-03-29 09:42:21 -07:00
Tudor Marcu 8a8f450fcd Update gitignore
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
2017-03-27 14:29:14 -07:00
Tudor Marcu b3149d2be0 Release v3.8.5
This release fixes a mismatch in the help menu description and long option,
and fixes the bash backwards compatibility check.

Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
v3.8.5
2017-03-27 13:55:11 -07:00