1#!/bin/ksh 2# 3# $OpenBSD: syspatch.sh,v 1.81 2017/01/11 12:22:13 ajacoutot Exp $ 4# 5# Copyright (c) 2016 Antoine Jacoutot <ajacoutot@openbsd.org> 6# 7# Permission to use, copy, modify, and distribute this software for any 8# purpose with or without fee is hereby granted, provided that the above 9# copyright notice and this permission notice appear in all copies. 10# 11# THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES 12# WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 13# MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR 14# ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 15# WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 16# ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 17# OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 18 19set -e 20umask 0022 21 22sp_err() 23{ 24 echo "${1}" 1>&2 && return ${2:-1} 25} 26 27usage() 28{ 29 sp_err "usage: ${0##*/} [-c | -l | -r]" 30} 31 32apply_patch() 33{ 34 local _explodir _file _files _patch=$1 _ret=0 35 [[ -n ${_patch} ]] 36 37 _explodir=${_TMP}/${_patch} 38 39 echo "Applying patch ${_patch##${_OSrev}-}" 40 fetch_and_verify "syspatch${_patch}.tgz" 41 42 trap '' INT 43 install -d ${_explodir} ${_PDIR}/${_patch} 44 45 _files="$(tar xvzphf ${_TMP}/syspatch${_patch}.tgz -C ${_explodir})" 46 checkfs ${_files} 47 48 create_rollback ${_patch} "${_files}" 49 50 # create_rollback(): tar(1) was fed with an empty list of files; that is 51 # not an error but no tarball is created; this happens if no earlier 52 # version of the files contained in the syspatch exists on the system 53 [[ ! -f ${_PDIR}/${_patch}/rollback.tgz ]] && unset _files && 54 echo "Missing set, skipping patch ${_patch##${_OSrev}-}" 55 56 for _file in ${_files}; do 57 ((_ret == 0)) || break 58 if [[ ${_file} == @(bsd|bsd.mp) ]]; then 59 install_kernel ${_explodir}/${_file} || _ret=$? 60 else 61 install_file ${_explodir}/${_file} /${_file} || _ret=$? 62 fi 63 done 64 65 if ((_ret != 0)); then 66 sp_err "Failed to apply patch ${_patch##${_OSrev}-}" 0 67 rollback_patch; return ${_ret} 68 fi 69 trap exit INT 70} 71 72# quick-and-dirty size check: 73# - assume old files are about the same size as new ones 74# - ignore new (nonexistent) files 75# - compute total size of all files per fs, simpler and less margin for error 76# - if we install a kernel, double /bsd size (duplicate it in the list) when: 77# - we are on an MP system (/bsd.mp does not exist there) 78# - /bsd.syspatchXX is not present (create_rollback will copy it from /bsd) 79checkfs() 80{ 81 local _d _df _dev _files="${@}" _sz 82 [[ -n ${_files} ]] 83 84 if echo "${_files}" | grep -qw bsd; then 85 ${_BSDMP} || [[ ! -f /bsd.syspatch${_OSrev} ]] && 86 _files="bsd ${_files}" 87 fi 88 89 eval $(cd / && 90 stat -qf "_dev=\"\${_dev} %Sd\" %Sd=\"\${%Sd:+\${%Sd}\+}%Uz\"" \ 91 ${_files}) || true # ignore nonexistent files 92 93 for _d in $(printf '%s\n' ${_dev} | sort -u); do 94 mount | grep -v read-only | grep -q "^/dev/${_d} " || 95 sp_err "Remote or read-only filesystem, aborting" 96 _df=$(df -Pk | grep "^/dev/${_d} " | tr -s ' ' | cut -d ' ' -f4) 97 _sz=$(($((_d))/1024)) 98 ((_df > _sz)) || sp_err "No space left on ${_d}, aborting" 99 done 100} 101 102create_rollback() 103{ 104 # XXX annotate new files so we can remove them if we rollback? 105 local _file _patch=$1 _rbfiles _ret=0 106 [[ -n ${_patch} ]] 107 shift 108 local _files="${@}" 109 [[ -n ${_files} ]] 110 111 for _file in ${_files}; do 112 [[ -f /${_file} ]] || continue 113 # only save the original release kernel once 114 if [[ ${_file} == bsd && ! -f /bsd.syspatch${_OSrev} ]]; then 115 install -FSp /bsd /bsd.syspatch${_OSrev} 116 fi 117 _rbfiles="${_rbfiles} ${_file}" 118 done 119 120 # GENERIC.MP: substitute bsd.mp->bsd and bsd.sp->bsd 121 if ${_BSDMP} && 122 tar -tzf ${_TMP}/syspatch${_patch}.tgz bsd >/dev/null 2>&1; then 123 tar -C / -czf ${_PDIR}/${_patch}/rollback.tgz -s '/^bsd.mp$//' \ 124 -s '/^bsd$/bsd.mp/' -s '/^bsd.sp$/bsd/' bsd.sp \ 125 ${_rbfiles} || _ret=$? 126 else 127 tar -C / -czf ${_PDIR}/${_patch}/rollback.tgz ${_rbfiles} || 128 _ret=$? 129 fi 130 131 if ((_ret != 0)); then 132 sp_err "Failed to create rollback patch ${_patch##${_OSrev}-}" 0 133 rm -r ${_PDIR}/${_patch}; return ${_ret} 134 fi 135} 136 137fetch_and_verify() 138{ 139 local _tgz=$1 140 [[ -n ${_tgz} ]] 141 142 unpriv -f "${_TMP}/${_tgz}" ${_FETCH} -mD "Get/Verify" -o \ 143 "${_TMP}/${_tgz}" "${_URL}/${_tgz}" 144 145 (cd ${_TMP} && sha256 -qC ${_TMP}/SHA256 ${_tgz}) 146} 147 148install_file() 149{ 150 # XXX handle symlinks, dir->file, file->dir? 151 local _dst=$2 _fgrp _fmode _fown _src=$1 152 [[ -f ${_src} && -f ${_dst} ]] 153 154 eval $(stat -f "_fmode=%OMp%OLp _fown=%Su _fgrp=%Sg" ${_src}) 155 156 install -DFS -m ${_fmode} -o ${_fown} -g ${_fgrp} ${_src} ${_dst} 157} 158 159install_kernel() 160{ 161 local _bsd _kern=$1 162 [[ -n ${_kern} ]] 163 164 if ${_BSDMP}; then 165 [[ ${_kern##*/} == bsd ]] && _bsd=bsd.sp || _bsd=bsd 166 fi 167 168 install -FS ${_kern} /${_bsd:-${_kern##*/}} 169} 170 171ls_installed() 172{ 173 local _p 174 for _p in ${_PDIR}/${_OSrev}-+([[:digit:]])_+([[:alnum:]_]); do 175 [[ -f ${_p}/rollback.tgz ]] && echo ${_p##*/${_OSrev}-} 176 done | sort -V 177} 178 179ls_missing() 180{ 181 local _c _l="$(ls_installed)" _sha=${_TMP}/SHA256 182 183 unpriv -f "${_sha}.sig" ${_FETCH} -o "${_sha}.sig" "${_URL}/SHA256.sig" 184 unpriv -f "${_sha}" signify -Veq -x ${_sha}.sig -m ${_sha} -p \ 185 /etc/signify/openbsd-${_OSrev}-syspatch.pub 186 187 grep -Eo "syspatch${_OSrev}-[[:digit:]]{3}_[[:alnum:]_]+" ${_sha} | 188 while read _c; do _c=${_c##syspatch${_OSrev}-} && 189 [[ -n ${_l} ]] && echo ${_c} | grep -qw -- "${_l}" || echo ${_c} 190 done | sort -V 191} 192 193rollback_patch() 194{ 195 local _explodir _file _files _patch _ret=0 196 197 _patch="$(ls_installed | tail -1)" 198 [[ -n ${_patch} ]] 199 200 _explodir=${_TMP}/${_patch}-rollback 201 _patch=${_OSrev}-${_patch} 202 203 echo "Reverting patch ${_patch##${_OSrev}-}" 204 install -d ${_explodir} 205 206 _files="$(tar xvzphf ${_PDIR}/${_patch}/rollback.tgz -C ${_explodir})" 207 checkfs ${_files} ${_PDIR} # check for read-only /var/syspatch 208 209 for _file in ${_files}; do 210 ((_ret == 0)) || break 211 if [[ ${_file} == @(bsd|bsd.mp) ]]; then 212 install_kernel ${_explodir}/${_file} || _ret=$? 213 # remove the backup kernel if all kernel syspatches have 214 # been reverted; non-fatal (`-f') 215 cmp -s /bsd /bsd.syspatch${_OSrev} && 216 rm -f /bsd.syspatch${_OSrev} 217 else 218 install_file ${_explodir}/${_file} /${_file} || _ret=$? 219 fi 220 done 221 222 ((_ret == 0)) && rm -r ${_PDIR}/${_patch} || 223 sp_err "Failed to revert patch ${_patch##${_OSrev}-}" ${_ret} 224} 225 226sp_cleanup() 227{ 228 local _d _k _m 229 230 # remove non matching release /var/syspatch/ content 231 for _d in ${_PDIR}/*; do 232 [[ ${_d##*/} == ${_OSrev}-+([[:digit:]])_+([[:alnum:]]|_) ]] && 233 [[ -f ${_d}/rollback.tgz ]] || rm -r ${_d} 234 done 235 236 # remove non matching release backup kernel 237 for _k in /bsd.syspatch+([[:digit:]]); do 238 [[ -f ${_k} ]] || continue 239 [[ ${_k} == /bsd.syspatch${_OSrev} ]] || rm ${_k} 240 done 241 242 # in case a patch added a new directory (install -D) 243 for _m in /etc/mtree/{4.4BSD,BSD.x11}.dist; do 244 [[ -f ${_m} ]] && mtree -qdef ${_m} -p / -U >/dev/null 245 done 246} 247 248unpriv() 249{ 250 # XXX use a dedicated user? 251 local _file=$2 _user=_pkgfetch 252 253 if [[ $1 == -f && -n ${_file} ]]; then 254 >${_file} 255 chown "${_user}" "${_file}" 256 chmod 0711 ${_TMP} 257 shift 2 258 fi 259 (($# >= 1)) 260 261 eval su -s /bin/sh ${_user} -c "'$@'" 262} 263 264# XXX needs a way to match release <=> syspatch 265# only run on release (not -current nor -stable) 266set -A _KERNV -- $(sysctl -n kern.version | 267 sed 's/^OpenBSD \([0-9]\.[0-9]\)\([^ ]*\).*/\1 \2/;q') 268((${#_KERNV[*]} > 1)) && sp_err "Unsupported release ${_KERNV[*]}" 269 270[[ $@ == @(|-[[:alpha:]]) ]] || usage; [[ $@ == @(|-(c|r)) ]] && 271 (($(id -u) != 0)) && sp_err "${0##*/}: need root privileges" 272 273(($(sysctl -n hw.ncpufound) > 1)) && _BSDMP=true || _BSDMP=false 274_FETCH="ftp -MV" 275_OSrev=${_KERNV[0]%\.*}${_KERNV[0]#*\.} 276_PDIR="/var/syspatch" 277_TMP=$(mktemp -d -p /tmp syspatch.XXXXXXXXXX) 278# XXX to be discussed 279_URL=https://syspatch.openbsd.org/pub/OpenBSD/${_KERNV[0]}/syspatch/$(machine) 280readonly _BSDMP _FETCH _OSrev _PDIR _REL _TMP _URL 281 282trap 'set +e; rm -rf "${_TMP}"' EXIT 283trap exit HUP INT TERM 284 285[[ -n ${_OSrev} ]] 286 287while getopts clr arg; do 288 case ${arg} in 289 c) ls_missing;; 290 l) ls_installed;; 291 r) rollback_patch;; 292 *) usage;; 293 esac 294done 295shift $((OPTIND -1)) 296[[ $# -ne 0 ]] && usage 297 298if ((OPTIND == 1)); then 299 for _PATCH in $(ls_missing); do 300 apply_patch ${_OSrev}-${_PATCH} 301 done 302 sp_cleanup 303fi 304