Instead of only calculating the contentsize for files that were updated
in the current version (an inaccurate number for download size since
this is not the compressed size), calculate for all files in the
manifest. Additionally, do not add submanifest contentsizes to the
current manifest contentsize, as this will result in overcount on client
systems when multiple bundles include the same bundle.
With this change the contentsize field of the manifests will only report
the size of the files unique to that bundle. It is then the client's
responsibility to calculate total bundle size including included
bundles. This is reasonably easy to accomplish with the upcoming
swupd-client bundle-list --deps feature.
Although the above use case is a bit more work for the client, it
additionally allows a user to calculate the installation size of
multiple bundles much more easily, since it only has to count bundle
dependencies once to ensure files are not over counted.
If two bundles not in the same include chain have overlapping content,
summing the include chain of each bundle in the client will result in an
over-estimation of the total size on the system. The more content is
shared, the higher the over-estimation. In reality this overlap will not
be large, but it is currently impossible to calculate the exact
installed size using just the contentsize.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
When a format bump occurs and the new format is greater than the old
format, an actions field is written to the Manifest.MoM containing the
string "update". This "update" action tells the client that it is
necessary to re-execute swupd update to bring the client to the latest
version within the new format.
Signed-off-by: Matthew Johnson <matthew.johnson@intel.com>
Because the intention is for swupd format numbers to either remain the
same between LAST_VER and current, or to increase as part of a format
bump, this leaves the remaining undesirable case.
Add a basic check to make sure the format never decreases, and add a
functional test.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
There is no need for duplicate includes to exist in manifest headers, so
search the includes lists first before adding a new entry.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Subtracting files from manifests when both versions are marked deleted
proves problematic for client updates, because the version at which the
files were deleted will differ, and the client uses the versions to
determine when it should delete files for an update.
As an example, consider a distro with 2 bundles, "A" and "B". Bundle B
includes bundle A, which results in files in A being subtracted from B.
In this situation the following sequence of four changes result in a
subtraction that prevents a client update from deleting a file.
1) In version 10, file /usr/foo is added to bundles A and B.
2) In version 20, /usr/foo is deleted from bundle A.
3) In version 30, /usr/foo is deleted from bundle B.
4) In version 40, bundle B is modified.
Due to arbitrary modifications to bundle B in step 4, /usr/foo is
subtracted from bundle B, because it's also deleted in bundle A.
However, the file versions mismatch. So, an update from version 20 to 40
will result in /usr/foo not being deleted because the deleted entry from
bundle A was not deleted in a version newer than 20.
This patch fixes the issue by ensuring that the deleted entry in bundle
B remains intact for version 30. And the client update then works
correctly: an update from 20 to 40 will properly delete /usr/foo,
because 20 < 30 <= 40.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
For three different Clear Linux OS builds in the last few months, deltas
were created between files with type change L->F (symlink to file).
This was allowed to occur because there is no check if
file->peer->is_link in __create_delta().
Instead, remove the file->is_link check and simply ensure that the
from/to file types are both F (i.e. "regular file").
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
In Ostro OS, we already have a "full" directory with all files.
Splitting it up into bundles just so that swupd-create-update can
reconstruct the "full" directory is a waste of IO, and noticably slow
when run under pseudo.
To streamline the required work, a new layout for the "image" input
directory gets introduced:
- The "full" directory gets created by the caller before invoking
swupd-create-update.
- For each bundle, instead of a <bundle> directory, there is a
<bundle>.content.txt file, listing all entries (including directories)
of the bundle.
The traditional mode of operation still works as before because each operation
which normally works with a bundle directory checks whether there is such a
directory and if not, switches to the new mode.
That way it is even possible to mix the two modes, i.e. replacing only
some bundles with a content list, although that's probably not all
that useful.
This revised commit fixes the use of an uninitialized newversiondircontent
pointer in populate_dirs().
Fixes: swupd-server/#54
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
This is a pre-condition for using libarchive directly: libarchive
needs to know what the encoding of filenames is, and it uses the
current locale for that. Without setlocale(), the locale is "C", which
only supports ASCII filenames, leading to warnings about "Can't
encode..." from libarchive when it is forced to fall back to copying
strings verbatim when writing archives that require UTF-8 encoding.
As a side effect, error messages from libc will get translated
according to the user's environment.
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
TAR_XATTR_ARGS is no longer used as part of a plain string. Embedding
the empty "" value for bsdtar inside an argv argument list passes an
empty parameter to bsdtar, leading to:
bsdtar: Must specify one of -c, -r, -t, -u, -x
To allow the the "no parameter" case, it has to be argument list: that
can be empty. If not empty, it has to end with a comma.
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
This reverts commit f01d9ca6c8.
Upon further testing, this patch causes a double free/corruption with the
current master branch and crashes two of the tests. We need to investigate
more before fully enabling it to ensure we don't regress.
When a CI system (like the one from Ostro) captures the output of
commands, but not necessarily intermediate log files, then it is
useful to also log to stdout. Another use case is calling the tools
interactively during development.
The new --log-stdout option in all three commands enables logging to
stdout in addition to the traditional log files.
The implementation recycles the existing init_log_stdout() (not used
before) and gives it the slightly different meaning of "also log to
stdout".
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
The SWUPD_NUM_THREADS env variable is now understood by all three
commands and overrides the default number of threads. Setting it to 1
is useful while debugging the code that runs inside threads (only one
thread hits breakpoints there). If SWUPD_NUM_THREADS is invalid, a
warning is printed and the variable gets ignored, i.e. the default
parallelism is used.
The hard-coded parallelism of 12 threads when analysing the file system
gets replaced with n, where n is the number of available CPUs. The default
is the same as before elsewhere (n for packing, 3 * n for fullfiles).
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
In Ostro OS, we already have a "full" directory with all files.
Splitting it up into bundles just so that swupd-create-update can
reconstruct the "full" directory is a waste of IO, and noticably slow
when run under pseudo.
To streamline the required work, a new layout for the "image" input
directory gets introduced:
- The "full" directory gets created by the caller before invoking
swupd-create-update.
- For each bundle, instead of a <bundle> directory, there is a
<bundle>.content.txt file, listing all entries (including directories)
of the bundle.
The traditional mode of operation still works as before because each operation
which normally works with a bundle directory checks whether there is such a
directory and if not, switches to the new mode.
That way it is even possible to mix the two modes, i.e. replacing only
some bundles with a content list, although that's probably not all
that useful.
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
This conditional checks for state *directories* that are generally
installed by default, and the conditional immediately below this one
checks for state files within these directories. So, if we do strncmp()
instead of strcmp(), the fallthrough logic doesn't occur, and state
files are not marked as such.
This reverts commit 63fb5fb61b.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
Since the enablement of signature verification in swupd-client, the
signature creation step has been decoupled from swupd-server, and is
instead performed as a separate step in a DevOps flow. As a result of
this decoupling, the signature code in swupd-server has remained unused.
This commit removes all the signature creation code with the assumption
that the separate DevOps step is going to work better long-term. Also,
the existing signature creation support does not accord with
swupd-client's verification support.
An example of how Manifest.MoM files can be signed is found in the
https://github.com/clearlinux/mixer-tools repo.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
To ease human readability of manifests, but without impacting manifest
delta efficiency, use a lexicographic filename secondary sort order when
sorting manifests by version.
Below is an example of how this commit changes the sorted order (the
first column is the version, and the second column is the filename).
# Before
10 zyxw
10 abcd
20 test2
20 test1
20 abba
20 aaaa
30 zzyy
# After
10 abcd
10 zyxw
20 aaaa
20 abba
20 test1
20 test2
30 zzyy
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
The file struct must be populated to contain the proper stats, so just
check if it is a directory and iterate, ignoring the case where d_type may
not be defined on the system.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
According to POSIX.1 only d_name and d_ino fields of struct
dirent are standardized. d_type isn't always correctly set on file
systems like XFS. In such cases it makes sense to resort to
lstat(). Otherwise a user has hard time figuring out what's
wrong with her setup.
Also remove redundant populate_file_struct() as it's called
again in parallel threads.
Signed-off-by: Dmitry Rozhkov <dmitry.rozhkov@linux.intel.com>
If the os-core bundle is not listed in groups.ini we will run into
problems later on, including segfaults when processing bundle includes.
Check the os-core bundle is listed in the groups.ini during initialisation
and error gracefully when it is not.
Signed-off-by: Joshua Lock <joshua.g.lock@intel.com>
In the (unlikely) case that nothing changed between two builds,
get_deduplicated_fullfile_list() segfaults because it uses
manifest->files without checking for NULL, aka the empty list.
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
At the moment, swupd_create_pack fails when some files have xattrs and
get patched because the xattrs of the test file do not match the
original, unpatched file.
That's because xattrs_copy() was applied to the wrong target file.
Fixes: swupd-server/#35
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
The bundle-chroot-builder changed the location where it stores bundle
includes metadata, so swupd-server needs to read from the new location.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
This patch extracts the [STATUS] field from our bundle information
metadata, and stores it in groups.ini. From there we put the contents
of this string verbatim into the manifest.
We don't interpret, encode or convert the contents of the [STATUS]
field in the manifest. Instead, we just strip non-alphanumeric
characters and pass the contents on. This leaves it entirely to the
client to parse and interpret the value of this field in the manifest.
If the bundle file, or the groups.ini file omits any status, nothing
is output to the Manifest file.
There is an issue when two different files in a newer release have same hash:
This is, when swupd updates a file by applying a delta, it takes the HASH2 to
know the file where delta must be applyed. If files are different in current
release (before updating), there must be 2 deltas, one for each file but as
the two files have same hash in new release delta's name are the same:
FROM-TO-HASH2 and it is when issue arises due to just the last delta file is
kept when swupd server creates files and packs. So when swupd client tries to
apply the delta to one of the file that does not corresponds it will fail and
generates an error. At the first look it will seem like delta file is corrupted
however the issue is that delta file was created for another file.
To solve this issue we include the hash for the original file in the delta's
name so that swupd client can take the correct delta and apply it:
FROM-TO-HASH1-HASH2.
Signed-off-by: Jose R Guzman <jose.r.guzman.mosqueda@intel.com>
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Calculate the hash for directories is desiderable to be independent
on the dirname due to the subsequent calculation on the staged/HASH
file. Here is used const "DIRECTORY" string for input name for
all folders.
Signed-off-by: Jose R Guzman <jose.r.guzman.mosqueda@intel.com>
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
Delta manifests are handled by the pack creation step, and should not be
part of the plain manifest/update content creation step. This reduces the time
swupd_create_update takes to run significantly.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
This reverts commit 7f3b760430 and commit
74f4afa655. The code introduced parallel manifest
creation, and removed delta manifests from being created, but needs some more
rigorous testing and refactoring to ensure all test suites pass.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
I had neglected to rebase to the latest revision of #21, so this commit
incorporates the additional changes.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
The code previously created all the bundle manifests and delta manifests
synchronously in 1 thread. While this worked, it was not optimal considering
the manifests can be created at the same time since they are unique. This
patch creates a threadpool that processes each bundle manifest in its own
thread. Delta manifest creation was removed from create_update because it
can already be handled by our delta pack creation process, and it is a huge
time-sink for create_update as it also runs single threaded.
Signed-off-by: Tudor Marcu <tudor.marcu@intel.com>
The delta manifests were being staged correctly but were not being added
to the delta packs.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
There are new functions that replace system() calls: system_argv(), system_argv_fd and system_argv_pipe().
They are based on execvp() function and they can manage any argument including filenames with characters
that could be interpreted as meta-characters in a regular system() function.
So no escape for the arguments needed and is less prone to errors.
Signed-off-by: Jose R Guzman <jose.r.guzman.mosqueda@intel.com>
Since delta pack creation is very much tied to a DevOps workflow, it
makes more sense for the pack_maker.sh to live outside of swupd-server.
This script will move to the clearlinux/mixer-tools repo, since the
Clear mixer is a DevOps-oriented tool.
Also, update the code comment in versions.c to describe another action
to be taken that is DevOps-specific, namely that the value of
WEBDIR/version/formatN/latest file should be set at release time.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>