2013-03-16 17:54:00 +00:00
|
|
|
#!/bin/bash
|
|
|
|
|
|
|
|
UPDATEVM=`qubes-prefs --get updatevm`
|
|
|
|
UPDATES_STAT_FILE=/var/lib/qubes/updates/dom0-updates-available
|
|
|
|
|
|
|
|
if [ -z "$UPDATEVM" ]; then
|
|
|
|
echo "UpdateVM not set, exiting"
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [ "$1" = "--help" ]; then
|
|
|
|
echo "This tool is used to download packages for dom0. Without package list"
|
|
|
|
echo "it checks for updates for installed packages"
|
|
|
|
echo ""
|
|
|
|
echo "Usage: $0 [--clean] [--check-only] [--gui] [<pkg list>]"
|
|
|
|
echo " --clean clean yum cache before doing anything"
|
|
|
|
echo " --check-only only check for updates (no install)"
|
|
|
|
echo " --gui use gpk-update-viewer for update selection"
|
2015-03-25 23:58:10 +00:00
|
|
|
echo " --action=... use specific yum action, instead of automatic install/update"
|
2013-03-16 17:54:00 +00:00
|
|
|
echo " <pkg list> download (and install if run by root) new packages"
|
|
|
|
echo " in dom0 instead of updating"
|
|
|
|
exit
|
|
|
|
fi
|
|
|
|
|
|
|
|
PKGS=
|
2016-06-12 16:05:28 +00:00
|
|
|
YUM_OPTS=
|
2013-03-16 17:54:00 +00:00
|
|
|
GUI=
|
|
|
|
CHECK_ONLY=
|
2016-06-12 16:05:28 +00:00
|
|
|
ALL_OPTS="$*"
|
2015-03-25 23:58:10 +00:00
|
|
|
YUM_ACTION=
|
2013-03-16 17:54:00 +00:00
|
|
|
QVMRUN_OPTS=
|
2014-05-11 22:30:48 +00:00
|
|
|
CLEAN=
|
2013-03-16 17:54:00 +00:00
|
|
|
# Filter out some yum options and collect packages list
|
|
|
|
while [ $# -gt 0 ]; do
|
|
|
|
case "$1" in
|
|
|
|
--enablerepo=*|\
|
2014-05-11 22:30:48 +00:00
|
|
|
--disablerepo=*)
|
|
|
|
;;
|
2013-03-16 17:54:00 +00:00
|
|
|
--clean)
|
2014-05-11 22:30:48 +00:00
|
|
|
CLEAN=1
|
2013-03-16 17:54:00 +00:00
|
|
|
;;
|
|
|
|
--gui)
|
|
|
|
GUI=1
|
|
|
|
;;
|
|
|
|
--check-only)
|
|
|
|
CHECK_ONLY=1
|
|
|
|
;;
|
2015-03-25 23:58:10 +00:00
|
|
|
--action=*)
|
|
|
|
YUM_ACTION=${1#--action=}
|
|
|
|
;;
|
2013-03-16 17:54:00 +00:00
|
|
|
-*)
|
|
|
|
YUM_OPTS="$YUM_OPTS $1"
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
PKGS="$PKGS $1"
|
2015-03-25 23:58:10 +00:00
|
|
|
if [ -z "$YUM_ACTION" ]; then
|
|
|
|
YUM_ACTION=install
|
|
|
|
fi
|
2013-03-16 17:54:00 +00:00
|
|
|
;;
|
|
|
|
esac
|
|
|
|
shift
|
|
|
|
done
|
|
|
|
|
2017-03-13 03:15:45 +00:00
|
|
|
# Prevent implicit update of template - this would override user changes -
|
|
|
|
# but do allow explicit template upgrade, downgrade, reinstall
|
2017-03-15 14:10:36 +00:00
|
|
|
if [ "$YUM_ACTION" == "reinstall" ] || [ "$YUM_ACTION" == "upgrade" ] || [ "$YUM_ACTION" == "upgrade-to" ] \
|
|
|
|
|| [ "$YUM_ACTION" == "downgrade" ] && [[ "$PKGS" == *"qubes-template-"* ]]; then
|
2016-06-12 16:05:28 +00:00
|
|
|
TEMPLATE_EXCLUDE_OPTS=""
|
2017-03-13 03:15:45 +00:00
|
|
|
echo "WARNING: Replacing a template will erase all files in template's /home and /rw !"
|
2016-06-24 00:24:52 +00:00
|
|
|
|
2016-06-18 16:00:00 +00:00
|
|
|
ONEPKG=`cut -f 1 -d ' ' <<<$PKGS`
|
2016-06-18 08:22:23 +00:00
|
|
|
if [[ "$ONEPKG" == "qubes-template-"* ]] && [[ "$ONEPKG" == "${PKGS#\ }" ]]; then # test "$PKGS" minus space
|
2016-06-18 07:02:46 +00:00
|
|
|
# Prepare to backup template root.img in case reinstall doesn't complete.
|
2017-03-15 14:10:36 +00:00
|
|
|
ONEPKG=`sed -r 's/-[0-9]+(\.[0-9-]+)+(\.noarch)*$//' <<<$ONEPKG` # Remove version suffix
|
|
|
|
TEMPLATE=${ONEPKG#qubes-template-} # Remove prefix
|
2016-06-21 19:15:34 +00:00
|
|
|
if qvm-shutdown --wait $TEMPLATE ; then
|
|
|
|
echo "Template VM halted"
|
|
|
|
fi
|
2016-06-20 17:36:30 +00:00
|
|
|
if ! TEMPLATE_NETVM=`qvm-prefs --force-root $TEMPLATE netvm` \
|
2016-06-20 18:04:55 +00:00
|
|
|
|| ! BAK_TEMPLATE_ROOT=`qvm-prefs --force-root $TEMPLATE root_img` \
|
|
|
|
|| ! BAK_TEMPLATE_PRIVATE=`qvm-prefs --force-root $TEMPLATE private_img` ; then
|
2016-06-20 17:36:30 +00:00
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
if [[ "$TEMPLATE_NETVM" == *"(default)" ]] ; then
|
|
|
|
TEMPLATE_NETVM="default"
|
|
|
|
fi
|
2016-06-18 07:02:46 +00:00
|
|
|
else
|
2017-03-15 14:10:36 +00:00
|
|
|
echo "ERROR: Specify only one package to reinstall template"
|
2016-06-18 07:02:46 +00:00
|
|
|
exit 1
|
|
|
|
fi
|
2016-06-24 00:24:52 +00:00
|
|
|
|
2016-06-16 11:59:28 +00:00
|
|
|
else
|
|
|
|
TEMPLATE_EXCLUDE_OPTS="--exclude=`rpm -qa --qf '%{NAME},' qubes-template-\*`"
|
2016-06-12 16:05:28 +00:00
|
|
|
fi
|
|
|
|
YUM_OPTS="$TEMPLATE_EXCLUDE_OPTS $YUM_OPTS"
|
|
|
|
ALL_OPTS="$TEMPLATE_EXCLUDE_OPTS $ALL_OPTS"
|
|
|
|
|
2013-03-16 17:54:00 +00:00
|
|
|
ID=$(id -ur)
|
|
|
|
if [ $ID != 0 -a -z "$GUI" -a -z "$CHECK_ONLY" ] ; then
|
|
|
|
echo "This script should be run as root (when used in console mode), use sudo." >&2
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [ "$GUI" == "1" -a -n "$PKGS" ]; then
|
|
|
|
echo "ERROR: GUI mode can be used only for updates" >&2
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
|
2014-06-29 19:59:42 +00:00
|
|
|
if [ "$GUI" == "1" ]; then
|
|
|
|
apps="yumex apper gpk-update-viewer"
|
|
|
|
|
|
|
|
if [ -n "$KDE_FULL_SESSION" ]; then
|
|
|
|
apps="apper yumex gpk-update-viewer"
|
|
|
|
fi
|
|
|
|
|
|
|
|
guiapp=
|
|
|
|
for app in $apps; do
|
|
|
|
if type $app &>/dev/null; then
|
|
|
|
guiapp=$app
|
2014-06-30 14:16:08 +00:00
|
|
|
case $guiapp in
|
2015-12-13 01:08:05 +00:00
|
|
|
apper) guiapp="apper --updates --nofork" ;;
|
2014-06-30 14:16:08 +00:00
|
|
|
*) guiapp=$app ;;
|
|
|
|
esac
|
2014-06-29 19:59:42 +00:00
|
|
|
break;
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
|
|
|
|
if [ -z "$guiapp" ]; then
|
|
|
|
message1="You don't have installed any supported yum frontend."
|
|
|
|
message2="Install (using qubes-dom0-update) one of: $apps"
|
|
|
|
|
|
|
|
if [ "$KDE_FULL_SESSION" ]; then
|
|
|
|
kdialog --sorry "$message1<br/>$message2"
|
|
|
|
else
|
|
|
|
zenity --error --text "$message1\n$message2"
|
|
|
|
fi
|
|
|
|
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
2013-03-16 17:54:00 +00:00
|
|
|
if [ "$GUI" != "1" ]; then
|
|
|
|
QVMRUN_OPTS=--nogui
|
|
|
|
fi
|
|
|
|
|
|
|
|
# Do not start VM automaticaly when running from cron (only checking for updates)
|
|
|
|
if [ "$CHECK_ONLY" == "1" ] && ! xl domid $UPDATEVM > /dev/null 2>&1; then
|
|
|
|
echo "ERROR: UpdateVM not running, not starting it in non-interactive mode" >&2
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
|
2014-05-11 22:30:48 +00:00
|
|
|
if [ -n "$CLEAN" ]; then
|
|
|
|
rm -f /var/lib/qubes/updates/rpm/*
|
2016-02-26 12:20:16 +00:00
|
|
|
rm -f /var/lib/qubes/updates/repodata/*
|
2014-05-11 22:30:48 +00:00
|
|
|
fi
|
2015-05-13 00:34:51 +00:00
|
|
|
rm -f /var/lib/qubes/updates/errors
|
2014-05-11 22:30:48 +00:00
|
|
|
|
2013-03-16 17:54:00 +00:00
|
|
|
# We should ensure the clocks in Dom0 and UpdateVM are in sync
|
|
|
|
# becuase otherwise yum might complain about future timestamps
|
|
|
|
qvm-sync-clock
|
|
|
|
|
2014-10-28 04:28:13 +00:00
|
|
|
echo "Using $UPDATEVM as UpdateVM to download updates for Dom0; this may take some time..." >&2
|
2013-03-16 17:54:00 +00:00
|
|
|
|
|
|
|
# Start VM if not running already
|
|
|
|
qvm-run $QVMRUN_OPTS -a $UPDATEVM true || exit 1
|
|
|
|
|
2015-09-04 00:54:50 +00:00
|
|
|
tar c /var/lib/rpm /etc/yum.repos.d /etc/yum.conf 2>/dev/null | \
|
|
|
|
qvm-run -p "$UPDATEVM" 'LC_MESSAGES=C tar x -C /var/lib/qubes/dom0-updates 2>&1 | grep -v -E "s in the future"'
|
2013-03-16 17:54:00 +00:00
|
|
|
|
2016-09-05 13:57:07 +00:00
|
|
|
qvm-run $QVMRUN_OPTS --pass-io $UPDATEVM "script --quiet --return --command '/usr/lib/qubes/qubes-download-dom0-updates.sh --doit --nogui $ALL_OPTS' /dev/null"
|
2013-03-16 17:54:00 +00:00
|
|
|
RETCODE=$?
|
|
|
|
if [ "$CHECK_ONLY" == "1" ]; then
|
|
|
|
exit $RETCODE
|
|
|
|
elif [ "$RETCODE" -ne 0 ]; then
|
|
|
|
exit $RETCODE
|
|
|
|
fi
|
|
|
|
# Wait for download completed
|
|
|
|
while pidof -x qubes-receive-updates >/dev/null; do sleep 0.5; done
|
|
|
|
|
|
|
|
if [ -r /var/lib/qubes/updates/errors ]; then
|
|
|
|
echo "*** ERROR while receiving updates:" >&2
|
|
|
|
cat /var/lib/qubes/updates/errors >&2
|
|
|
|
echo "--> if you want to use packages that were downloaded correctly, use yum directly now" >&2
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
|
2015-03-25 23:58:10 +00:00
|
|
|
if [ -z "$YUM_ACTION" ]; then
|
|
|
|
YUM_ACTION=upgrade
|
|
|
|
fi
|
|
|
|
|
2013-03-16 17:54:00 +00:00
|
|
|
if [ "x$PKGS" != "x" ]; then
|
2016-06-21 14:57:57 +00:00
|
|
|
if [[ -n "$BAK_TEMPLATE_ROOT" ]] ; then # Handle template details
|
2016-06-20 18:04:55 +00:00
|
|
|
# Backup root.img and private.img just in case
|
2016-06-21 14:57:57 +00:00
|
|
|
echo "Creating img backup files"
|
|
|
|
mv "$BAK_TEMPLATE_ROOT" "$BAK_TEMPLATE_ROOT-bak"
|
|
|
|
mv "$BAK_TEMPLATE_PRIVATE" "$BAK_TEMPLATE_PRIVATE-bak"
|
2016-06-21 19:15:34 +00:00
|
|
|
TDIR=`qvm-prefs --force-root $TEMPLATE dir`
|
2017-03-15 14:10:36 +00:00
|
|
|
if [ -f "$TDIR/firewall.xml" ]; then
|
|
|
|
mv "$TDIR/firewall.xml" "$TDIR/firewall.xml-bak"
|
|
|
|
fi
|
2016-06-21 19:15:34 +00:00
|
|
|
rm -f "$TDIR/volatile.img"
|
|
|
|
echo "--> Creating private.img..."
|
|
|
|
truncate -s 2G $BAK_TEMPLATE_PRIVATE
|
|
|
|
mkfs.ext4 -m 0 -q -F $BAK_TEMPLATE_PRIVATE
|
|
|
|
chown root:qubes $BAK_TEMPLATE_PRIVATE
|
|
|
|
chmod 0660 $BAK_TEMPLATE_PRIVATE
|
2016-06-18 16:00:00 +00:00
|
|
|
fi
|
|
|
|
|
|
|
|
yum $YUM_OPTS $YUM_ACTION $PKGS ; RETCODE=$?
|
|
|
|
|
2016-06-21 14:57:57 +00:00
|
|
|
if [[ -n "$BAK_TEMPLATE_ROOT" ]] ; then # Handle template details
|
2017-06-07 05:35:34 +00:00
|
|
|
if [[ $RETCODE -eq 0 && -f "$BAK_TEMPLATE_ROOT" ]]; then
|
2016-06-20 17:36:30 +00:00
|
|
|
# Reinstall went OK, remove backup files.
|
2016-06-18 16:00:00 +00:00
|
|
|
rm -f "$BAK_TEMPLATE_ROOT-bak"
|
2016-06-20 18:04:55 +00:00
|
|
|
rm -f "$BAK_TEMPLATE_PRIVATE-bak"
|
2016-06-21 14:57:57 +00:00
|
|
|
else
|
2016-06-21 19:15:34 +00:00
|
|
|
echo "Yum exit: Restoring img files"
|
2016-06-21 14:57:57 +00:00
|
|
|
mv "$BAK_TEMPLATE_ROOT-bak" "$BAK_TEMPLATE_ROOT"
|
|
|
|
mv "$BAK_TEMPLATE_PRIVATE-bak" "$BAK_TEMPLATE_PRIVATE"
|
|
|
|
fi
|
2017-06-07 05:35:34 +00:00
|
|
|
if [ -f "$TDIR/firewall.xml-bak" ]; then
|
|
|
|
mv "$TDIR/firewall.xml-bak" "$TDIR/firewall.xml"
|
|
|
|
fi
|
2016-06-21 14:57:57 +00:00
|
|
|
if ! qvm-prefs --force-root -s $TEMPLATE netvm $TEMPLATE_NETVM ; then
|
|
|
|
echo "ERROR: NetVM setting could not be restored!"
|
2016-06-21 19:15:34 +00:00
|
|
|
exit 1
|
2016-06-18 16:00:00 +00:00
|
|
|
fi
|
2017-03-15 14:10:36 +00:00
|
|
|
|
2016-06-18 16:00:00 +00:00
|
|
|
fi
|
2013-03-16 17:54:00 +00:00
|
|
|
elif [ -f /var/lib/qubes/updates/repodata/repomd.xml ]; then
|
|
|
|
# Above file exists only when at least one package was downloaded
|
|
|
|
if [ "$GUI" == "1" ]; then
|
2014-06-29 19:59:42 +00:00
|
|
|
$guiapp
|
2013-03-16 17:54:00 +00:00
|
|
|
else
|
|
|
|
yum check-update
|
2016-06-18 07:02:46 +00:00
|
|
|
if [ $? -eq 100 ]; then # Run yum with options
|
2016-06-18 16:00:00 +00:00
|
|
|
yum $YUM_OPTS $YUM_ACTION
|
2013-03-16 17:54:00 +00:00
|
|
|
fi
|
|
|
|
fi
|
|
|
|
yum -q check-update && rm -f $UPDATES_STAT_FILE
|
|
|
|
else
|
2016-02-03 13:14:14 +00:00
|
|
|
rm -f $UPDATES_STAT_FILE
|
2013-03-16 17:54:00 +00:00
|
|
|
echo "No updates avaliable" >&2
|
|
|
|
fi
|