xref: /openbsd-src/usr.sbin/syspatch/syspatch.sh (revision f608ccdaec5b4b575311663ef5d58f7f02544a92)
1cb6f7b6fSajacoutot#!/bin/ksh
2cb6f7b6fSajacoutot#
3*f608ccdaSajacoutot# $OpenBSD: syspatch.sh,v 1.168 2023/12/13 17:50:23 ajacoutot Exp $
4cb6f7b6fSajacoutot#
55a3d80b6Sajacoutot# Copyright (c) 2016, 2017 Antoine Jacoutot <ajacoutot@openbsd.org>
6cb6f7b6fSajacoutot#
7cb6f7b6fSajacoutot# Permission to use, copy, modify, and distribute this software for any
8cb6f7b6fSajacoutot# purpose with or without fee is hereby granted, provided that the above
9cb6f7b6fSajacoutot# copyright notice and this permission notice appear in all copies.
10cb6f7b6fSajacoutot#
11cb6f7b6fSajacoutot# THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
12cb6f7b6fSajacoutot# WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
13cb6f7b6fSajacoutot# MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
14cb6f7b6fSajacoutot# ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
15cb6f7b6fSajacoutot# WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
16cb6f7b6fSajacoutot# ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
17cb6f7b6fSajacoutot# OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
18cb6f7b6fSajacoutot
19cb6f7b6fSajacoutotset -e
20758073a2Sajacoutotumask 0022
211a49fa34Sajacoutotexport PATH=/usr/bin:/bin:/usr/sbin:/sbin
22cb6f7b6fSajacoutot
235f723439Sknerr()
241e22785dSajacoutot{
255f723439Skn	echo "${0##*/}: ${1}" 1>&2
265f723439Skn	return ${2:-1}
271e22785dSajacoutot}
28cbc95686Sajacoutot
29cb6f7b6fSajacoutotusage()
30cb6f7b6fSajacoutot{
315f723439Skn	echo "usage: ${0##*/} [-c | -l | -R | -r]" 1>&2
325f723439Skn	return 1
33cb6f7b6fSajacoutot}
34cb6f7b6fSajacoutot
350518aa9dSajacoutotapply_patch()
360518aa9dSajacoutot{
37*f608ccdaSajacoutot	local _edir _file _files _kernel _patch=$1 _rc=0 _s _upself=false
380518aa9dSajacoutot	[[ -n ${_patch} ]]
390518aa9dSajacoutot
4054f4dff8Sajacoutot	_edir=${_TMP}/${_patch}
415964bd7eSajacoutot
425964bd7eSajacoutot	fetch_and_verify "syspatch${_patch}.tgz"
435964bd7eSajacoutot
445964bd7eSajacoutot	trap '' INT
4517f59a30Sajacoutot	echo "Installing patch ${_patch##${_OSrev}-}"
4654f4dff8Sajacoutot	install -d ${_edir} ${_PDIR}/${_patch}
470518aa9dSajacoutot
48*f608ccdaSajacoutot	_kernel=$(sysctl -n kern.osversion)
49*f608ccdaSajacoutot	[[ ${_kernel%#*} == "GENERIC.MP" ]] &&
5025143596Sajacoutot		_s="-s @usr/share/relink/kernel/GENERIC/.*@@g" ||
51f18856bcSajacoutot		_s="-s @usr/share/relink/kernel/GENERIC.MP/.*@@g"
52a532db05Sajacoutot	_files="$(tar -xvzphf ${_TMP}/syspatch${_patch}.tgz -C ${_edir} \
53a532db05Sajacoutot		${_s})" || { rm -r ${_PDIR}/${_patch}; return 1; }
540b27eea9Sajacoutot
55c38c9a74Sajacoutot	checkfs ${_files}
560518aa9dSajacoutot	create_rollback ${_patch} "${_files}"
570518aa9dSajacoutot
580518aa9dSajacoutot	for _file in ${_files}; do
59d7ee0851Sajacoutot		((_rc == 0)) || break
602306ff56Sajacoutot		[[ ${_file} == usr/sbin/syspatch ]] && _upself=true
61d7ee0851Sajacoutot		install_file ${_edir}/${_file} /${_file} || _rc=$?
620518aa9dSajacoutot	done
63dc76ae40Sajacoutot
64d7ee0851Sajacoutot	if ((_rc != 0)); then
655f723439Skn		err "Failed to apply patch ${_patch##${_OSrev}-}" 0
66d7ee0851Sajacoutot		rollback_patch; return ${_rc}
67dc76ae40Sajacoutot	fi
68ce3e7856Sajacoutot	# don't fill up /tmp when installing multiple patches at once; non-fatal
69ce3e7856Sajacoutot	rm -rf ${_edir} ${_TMP}/syspatch${_patch}.tgz
70a5e8cfb7Shalex	trap exit INT
712306ff56Sajacoutot
72a8f86fd3Sajacoutot	echo ${_files} | grep -Eqv \
73f18856bcSajacoutot		'(^|[[:blank:]]+)usr/share/relink/kernel/GENERI(C|C.MP)/[[:print:]]+([[:blank:]]+|$)' ||
74a8f86fd3Sajacoutot		_KARL=true
75a8f86fd3Sajacoutot
765f723439Skn	(! ${_upself} || err "updated itself, run it again to install \
776d05af0bSajacoutotmissing patches" 2)
78cb6f7b6fSajacoutot}
79cb6f7b6fSajacoutot
80b366f6d7Sajacoutot# quick-and-dirty filesystem status and size checks:
81395eae8fSajacoutot# - assume old files are about the same size as new ones
82395eae8fSajacoutot# - ignore new (nonexistent) files
839b91251cSajacoutot# - ignore rollback tarball: create_rollback() will handle the failure
84395eae8fSajacoutot# - compute total size of all files per fs, simpler and less margin for error
8530904dd3Sajacoutot#   (instead of computing before installing each file)
860b27eea9Sajacoutotcheckfs()
870b27eea9Sajacoutot{
88f617247dSajacoutot	local _d _dev _df _files="${@}" _sz
890b27eea9Sajacoutot	[[ -n ${_files} ]]
900b27eea9Sajacoutot
91b366f6d7Sajacoutot	set +e # ignore errors due to:
92a8f86fd3Sajacoutot	# - nonexistent files (i.e. syspatch is installing new files)
93b366f6d7Sajacoutot	# - broken interpolation due to bogus devices like remote filesystems
94e0c4d69aSajacoutot	eval $(cd / &&
956da5f992Sajacoutot		stat -qf "_dev=\"\${_dev} %Sd\";
966da5f992Sajacoutot			local %Sd=\"\${%Sd:+\${%Sd}\+}%Uz\"" ${_files}) \
97f617247dSajacoutot			2>/dev/null
98b366f6d7Sajacoutot	set -e
99e0c4d69aSajacoutot
100e0c4d69aSajacoutot	for _d in $(printf '%s\n' ${_dev} | sort -u); do
1015f723439Skn		[[ ${_d} != "??" ]] || err "Unsupported filesystem, aborting"
1021b20cebcSajacoutot		mount | grep -v read-only | grep -q "^/dev/${_d} " ||
1035f723439Skn			err "Read-only filesystem, aborting"
104e0c4d69aSajacoutot		_df=$(df -Pk | grep "^/dev/${_d} " | tr -s ' ' | cut -d ' ' -f4)
105147c905eSajacoutot		_sz=$(($((_d))/1024))
1065f723439Skn		((_df > _sz)) || err "No space left on ${_d}, aborting"
1070b27eea9Sajacoutot	done
1080b27eea9Sajacoutot}
1090b27eea9Sajacoutot
110cb6f7b6fSajacoutotcreate_rollback()
111cb6f7b6fSajacoutot{
112f303df63Sajacoutot	# XXX annotate new files so we can remove them if we rollback?
113d7ee0851Sajacoutot	local _file _patch=$1 _rbfiles _rc=0
114cb6f7b6fSajacoutot	[[ -n ${_patch} ]]
115cb6f7b6fSajacoutot	shift
116cb6f7b6fSajacoutot	local _files="${@}"
117cb6f7b6fSajacoutot	[[ -n ${_files} ]]
118cb6f7b6fSajacoutot
11987656f9eSajacoutot	for _file in ${_files}; do
120a8f86fd3Sajacoutot		[[ -f /${_file} ]] && _rbfiles="${_rbfiles} ${_file}"
12187656f9eSajacoutot	done
122cb6f7b6fSajacoutot
123d7ee0851Sajacoutot	tar -C / -czf ${_PDIR}/${_patch}/rollback.tgz ${_rbfiles} || _rc=$?
1242fa7d596Sajacoutot
125d7ee0851Sajacoutot	if ((_rc != 0)); then
1265f723439Skn		err "Failed to create rollback patch ${_patch##${_OSrev}-}" 0
127d7ee0851Sajacoutot		rm -r ${_PDIR}/${_patch}; return ${_rc}
1284aef221cSajacoutot	fi
129cb6f7b6fSajacoutot}
130cb6f7b6fSajacoutot
131cb6f7b6fSajacoutotfetch_and_verify()
132cb6f7b6fSajacoutot{
1334338cf47Sajacoutot	local _tgz=$1 _title="Get/Verify"
13408a8da71Sajacoutot	[[ -n ${_tgz} ]]
135cb6f7b6fSajacoutot
1364338cf47Sajacoutot	[[ -t 0 ]] || echo "${_title} ${_tgz}"
13759aecf2cSajacoutot	unpriv -f "${_TMP}/${_tgz}" ftp -N syspatch -VD "${_title}" -o \
13859aecf2cSajacoutot		"${_TMP}/${_tgz}" "${_MIRROR}/${_tgz}"
13908a8da71Sajacoutot
140d0a524bcSajacoutot	(cd ${_TMP} && sha256 -qC ${_TMP}/SHA256 ${_tgz})
141cb6f7b6fSajacoutot}
142cb6f7b6fSajacoutot
143cb6f7b6fSajacoutotinstall_file()
144cb6f7b6fSajacoutot{
145e9cc0ab1Sajacoutot	# XXX handle hard link, dir->file, file->dir?
14616b1b12eSajacoutot	local _dst=$2 _fgrp _fmode _fown _src=$1
147cb6f7b6fSajacoutot	[[ -f ${_src} && -f ${_dst} ]]
148cb6f7b6fSajacoutot
149e9cc0ab1Sajacoutot	if [[ -h ${_src} ]]; then
150e9cc0ab1Sajacoutot		ln -sf $(readlink ${_src}) ${_dst}
151e9cc0ab1Sajacoutot	else
152c93baf90Sajacoutot		eval $(stat -f "_fmode=%OMp%OLp _fown=%Su _fgrp=%Sg" ${_src})
15322e4c9c7Sajacoutot		install -DFp -m ${_fmode} -o ${_fown} -g ${_fgrp} ${_src} \
154e9cc0ab1Sajacoutot			${_dst}
155e9cc0ab1Sajacoutot	fi
156cb6f7b6fSajacoutot}
157cb6f7b6fSajacoutot
158cb6f7b6fSajacoutotls_installed()
159cb6f7b6fSajacoutot{
160cb6f7b6fSajacoutot	local _p
161c76b35d7Stb	for _p in ${_PDIR}/${_OSrev}-+([[:digit:]])_+([[:alnum:]_-]); do
16208a8da71Sajacoutot		[[ -f ${_p}/rollback.tgz ]] && echo ${_p##*/${_OSrev}-}
163dee18dccSajacoutot	done
164cb6f7b6fSajacoutot}
165cb6f7b6fSajacoutot
166cb6f7b6fSajacoutotls_missing()
167cb6f7b6fSajacoutot{
1689980b193Sajacoutot	local _c _f _cmd _l="$(ls_installed)" _p _sha=${_TMP}/SHA256
169cb6f7b6fSajacoutot
170e8ee3b94Sajacoutot	# don't output anything on stdout to prevent corrupting the patch list
17159aecf2cSajacoutot	unpriv -f "${_sha}.sig" ftp -N syspatch -MVo "${_sha}.sig" \
17259aecf2cSajacoutot		"${_MIRROR}/SHA256.sig" >/dev/null
173d0a524bcSajacoutot	unpriv -f "${_sha}" signify -Veq -x ${_sha}.sig -m ${_sha} -p \
1743c94de9fSajacoutot		/etc/signify/openbsd-${_OSrev}-syspatch.pub >/dev/null
1758c47c999Sajacoutot
176dee18dccSajacoutot	# sig file less than 3 lines long doesn't list any patch (new release)
17728b81e73Stb	(($(grep -c ".*" ${_sha}.sig) < 3)) && return
178dee18dccSajacoutot
179dee18dccSajacoutot	set -o pipefail
180c76b35d7Stb	grep -Eo "syspatch${_OSrev}-[[:digit:]]{3}_[[:alnum:]_-]+" ${_sha} |
18169dc6fb2Sajacoutot		while read _c; do _c=${_c##syspatch${_OSrev}-} &&
18269dc6fb2Sajacoutot		[[ -n ${_l} ]] && echo ${_c} | grep -qw -- "${_l}" || echo ${_c}
18309585cb7Sajacoutot	done | while read _p; do
18459aecf2cSajacoutot		_cmd="ftp -N syspatch -MVo - \
18559aecf2cSajacoutot			${_MIRROR}/syspatch${_OSrev}-${_p}.tgz"
186dee18dccSajacoutot		unpriv "${_cmd}" | tar tzf - | while read _f; do
187dee18dccSajacoutot			# no earlier version of _all_ files contained in the tgz
188dee18dccSajacoutot			# exists on the system, it means a missing set: skip it
18909585cb7Sajacoutot			[[ -f /${_f} ]] || continue && echo ${_p} && pkill -u \
19009585cb7Sajacoutot				_syspatch -xf "${_cmd}" || true && break
19109585cb7Sajacoutot		done
192dee18dccSajacoutot	done | sort -V # only used as a buffer to display all patches at once
193dee18dccSajacoutot	set +o pipefail
194cb6f7b6fSajacoutot}
195cb6f7b6fSajacoutot
1962ae78c74Sajacoutotrollback_patch()
1972ae78c74Sajacoutot{
198d7ee0851Sajacoutot	local _edir _file _files _patch _rc=0
1992ae78c74Sajacoutot
20069dc6fb2Sajacoutot	_patch="$(ls_installed | tail -1)"
20115b295ccSajacoutot	[[ -n ${_patch} ]] || return 0 # nothing to rollback
2022ae78c74Sajacoutot
20354f4dff8Sajacoutot	_edir=${_TMP}/${_patch}-rollback
20408a8da71Sajacoutot	_patch=${_OSrev}-${_patch}
20516b1b12eSajacoutot
2069ca86c81Sajacoutot	trap '' INT
20708a8da71Sajacoutot	echo "Reverting patch ${_patch##${_OSrev}-}"
20854f4dff8Sajacoutot	install -d ${_edir}
2092ae78c74Sajacoutot
21054f4dff8Sajacoutot	_files="$(tar xvzphf ${_PDIR}/${_patch}/rollback.tgz -C ${_edir})"
21108a8da71Sajacoutot	checkfs ${_files} ${_PDIR} # check for read-only /var/syspatch
2122ae78c74Sajacoutot
2132ae78c74Sajacoutot	for _file in ${_files}; do
214d7ee0851Sajacoutot		((_rc == 0)) || break
215d7ee0851Sajacoutot		install_file ${_edir}/${_file} /${_file} || _rc=$?
2162ae78c74Sajacoutot	done
2172ae78c74Sajacoutot
218d7ee0851Sajacoutot	((_rc != 0)) || rm -r ${_PDIR}/${_patch} || _rc=$?
219d7ee0851Sajacoutot	((_rc == 0)) ||
2205f723439Skn		err "Failed to revert patch ${_patch##${_OSrev}-}" ${_rc}
221ce3e7856Sajacoutot	rm -rf ${_edir} # don't fill up /tmp when using `-R'; non-fatal
2229ca86c81Sajacoutot	trap exit INT
2232ae78c74Sajacoutot
224a8f86fd3Sajacoutot	echo ${_files} | grep -Eqv \
225f18856bcSajacoutot		'(^|[[:blank:]]+)usr/share/relink/kernel/GENERI(C|C.MP)/[[:print:]]+([[:blank:]]+|$)' ||
226a8f86fd3Sajacoutot		_KARL=true
227d145eff1Sajacoutot}
228d145eff1Sajacoutot
229046212abSajacoutottrap_handler()
230046212abSajacoutot{
231046212abSajacoutot	set +e # we're trapped
232046212abSajacoutot	rm -rf "${_TMP}"
233046212abSajacoutot
234046212abSajacoutot	# in case a patch added a new directory (install -D)
235046212abSajacoutot	if [[ -n ${_PATCHES} ]]; then
236046212abSajacoutot		mtree -qdef /etc/mtree/4.4BSD.dist -p / -U >/dev/null
237046212abSajacoutot		[[ -f /var/sysmerge/xetc.tgz ]] &&
238046212abSajacoutot			mtree -qdef /etc/mtree/BSD.x11.dist -p / -U >/dev/null
239046212abSajacoutot	fi
240046212abSajacoutot
241046212abSajacoutot	if ${_KARL}; then
242046212abSajacoutot		echo -n "Relinking to create unique kernel..."
243046212abSajacoutot		if /usr/libexec/reorder_kernel; then
244f0c0efefSajacoutot			echo " done; reboot to load the new kernel"
245046212abSajacoutot		else
246a0cc1304Sajacoutot			echo " failed!\n!!! \"/usr/libexec/reorder_kernel\" \
247a0cc1304Sajacoutotmust be run manually to install the new kernel"
248a0cc1304Sajacoutot			exit 1
249046212abSajacoutot		fi
250046212abSajacoutot	fi
251f0c0efefSajacoutot
252f0c0efefSajacoutot	${_PATCH_APPLIED} && echo "Errata can be reviewed under ${_PDIR}"
253046212abSajacoutot}
254046212abSajacoutot
2553f4d951fSajacoutotunpriv()
2563f4d951fSajacoutot{
2577f3597a0Sajacoutot	local _file=$2 _rc=0 _user=_syspatch
2583f4d951fSajacoutot
2593f4d951fSajacoutot	if [[ $1 == -f && -n ${_file} ]]; then
2603f4d951fSajacoutot		>${_file}
2613f4d951fSajacoutot		chown "${_user}" "${_file}"
2623f4d951fSajacoutot		chmod 0711 ${_TMP}
2633f4d951fSajacoutot		shift 2
2643f4d951fSajacoutot	fi
2653f4d951fSajacoutot	(($# >= 1))
2663f4d951fSajacoutot
2677f3597a0Sajacoutot	eval su -s /bin/sh ${_user} -c "'$@'" || _rc=$?
2687f3597a0Sajacoutot
2697f3597a0Sajacoutot	[[ -n ${_file} ]] && chown root "${_file}"
2707f3597a0Sajacoutot
2717f3597a0Sajacoutot	return ${_rc}
2723f4d951fSajacoutot}
2733f4d951fSajacoutot
2744aef221cSajacoutot# only run on release (not -current nor -stable)
275c93baf90Sajacoutotset -A _KERNV -- $(sysctl -n kern.version |
2769880595cStb	sed 's/^OpenBSD \([1-9][0-9]*\.[0-9]\)\([^ ]*\).*/\1 \2/;q')
2775f723439Skn((${#_KERNV[*]} > 1)) && err "Unsupported release: ${_KERNV[0]}${_KERNV[1]}"
278cb6f7b6fSajacoutot
279f5d8f4ecSajacoutot[[ $@ == @(|-[[:alpha:]]) ]] || usage; [[ $@ == @(|-(c|R|r)) ]] &&
2805f723439Skn	(($(id -u) != 0)) && err "need root privileges"
281f5d8f4ecSajacoutot[[ $@ == @(|-(R|r)) ]] && pgrep -qxf '/bin/ksh .*reorder_kernel' &&
2825f723439Skn	err "cannot apply patches while reorder_kernel is running"
283f5d8f4ecSajacoutot
2849b64d5e0Srpe_OSrev=${_KERNV[0]%.*}${_KERNV[0]#*.}
2859b64d5e0Srpe[[ -n ${_OSrev} ]]
2869b64d5e0Srpe
287c3436116Sajacoutot_MIRROR=$(while read _line; do _line=${_line%%#*}; [[ -n ${_line} ]] &&
288363044a6Sajacoutot	print -r -- "${_line}"; done </etc/installurl | tail -1) 2>/dev/null
28936a76669Sajacoutot[[ ${_MIRROR} == @(file|ftp|http|https)://* ]] ||
2904c0afd38Sajacoutot	_MIRROR=https://cdn.openbsd.org/pub/OpenBSD
291c3436116Sajacoutot_MIRROR="${_MIRROR}/syspatch/${_KERNV[0]}/$(machine)"
292cb6f7b6fSajacoutot
293f0c0efefSajacoutot_PATCH_APPLIED=false
294dcaab6cbSajacoutot_PDIR="/var/syspatch"
2959d7d9654Sajacoutot_TMP=$(mktemp -d -p ${TMPDIR:-/tmp} syspatch.XXXXXXXXXX)
296a8f86fd3Sajacoutot_KARL=false
297c3436116Sajacoutot
29825143596Sajacoutotreadonly _KERNV _MIRROR _OSrev _PDIR _TMP
299cb6f7b6fSajacoutot
300046212abSajacoutottrap 'trap_handler' EXIT
3013931a20bShalextrap exit HUP INT TERM
302a5e8cfb7Shalex
303b40f9483Sajacoutotwhile getopts clRr arg; do
304cb6f7b6fSajacoutot	case ${arg} in
305cb6f7b6fSajacoutot		c) ls_missing ;;
306cb6f7b6fSajacoutot		l) ls_installed ;;
30795f0be21Sajacoutot		R) while [[ -n $(ls_installed) ]]; do rollback_patch; done ;;
308991673ffSajacoutot		r) rollback_patch ;;
309cb6f7b6fSajacoutot		*) usage ;;
310cb6f7b6fSajacoutot	esac
311cb6f7b6fSajacoutotdone
312cb6f7b6fSajacoutotshift $((OPTIND - 1))
3139320931bSrpe(($# != 0)) && usage
314cb6f7b6fSajacoutot
3152333d064Sajacoutot# default action: apply all patches
316147c905eSajacoutotif ((OPTIND == 1)); then
317a8f86fd3Sajacoutot	# remove non matching release /var/syspatch/ content
318a8f86fd3Sajacoutot	for _D in ${_PDIR}/{.[!.],}*; do
319a8f86fd3Sajacoutot		[[ -e ${_D} ]] || continue
320c76b35d7Stb		[[ ${_D##*/} == ${_OSrev}-+([[:digit:]])_+([[:alnum:]_-]) ]] &&
321a8f86fd3Sajacoutot			[[ -f ${_D}/rollback.tgz ]] || rm -r ${_D}
322a8f86fd3Sajacoutot	done
323dee18dccSajacoutot	_PATCHES=$(ls_missing) # can't use errexit in a for loop
32491cb7cd0Sajacoutot	[[ -n ${_PATCHES} ]] || exit 2
325d0ea658eSajacoutot	for _PATCH in ${_PATCHES}; do
3265964bd7eSajacoutot		apply_patch ${_OSrev}-${_PATCH}
327f0c0efefSajacoutot		_PATCH_APPLIED=true
3285964bd7eSajacoutot	done
32936beb3e3Sajacoutotfi
330