qubes-download-dom0-updates.sh 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180
  1. #!/bin/bash
  2. DOM0_UPDATES_DIR=/var/lib/qubes/dom0-updates
  3. GUI=1
  4. CLEAN=0
  5. CHECK_ONLY=0
  6. OPTS="--installroot $DOM0_UPDATES_DIR"
  7. if [ -f "$DOM0_UPDATES_DIR/etc/dnf/dnf.conf" ]; then
  8. OPTS="$OPTS --config=$DOM0_UPDATES_DIR/etc/yum.conf"
  9. elif [ -f "$DOM0_UPDATES_DIR/etc/yum.conf" ]; then
  10. OPTS="$OPTS --config=$DOM0_UPDATES_DIR/etc/yum.conf"
  11. fi
  12. # DNF uses /etc/yum.repos.d, even when --installroot is specified
  13. OPTS="$OPTS --setopt=reposdir=$DOM0_UPDATES_DIR/etc/yum.repos.d"
  14. PKGLIST=
  15. YUM_ACTION=
  16. export LC_ALL=C
  17. while [ -n "$1" ]; do
  18. case "$1" in
  19. --doit)
  20. # ignore
  21. ;;
  22. --nogui)
  23. GUI=0
  24. ;;
  25. --gui)
  26. GUI=1
  27. ;;
  28. --clean)
  29. CLEAN=1
  30. ;;
  31. --check-only)
  32. CHECK_ONLY=1
  33. ;;
  34. --action=*)
  35. YUM_ACTION=${1#--action=}
  36. ;;
  37. -*)
  38. OPTS="$OPTS $1"
  39. ;;
  40. *)
  41. PKGLIST="$PKGLIST $1"
  42. if [ -z "$YUM_ACTION" ]; then
  43. YUM_ACTION=install
  44. fi
  45. ;;
  46. esac
  47. shift
  48. done
  49. if [ -z "$YUM_ACTION" ]; then
  50. YUM_ACTION=upgrade
  51. fi
  52. YUM="yum"
  53. if type dnf >/dev/null 2>&1; then
  54. YUM="dnf --best --allowerasing --noplugins"
  55. else
  56. # salt in dom0 thinks it's using dnf but we only have yum so need to remove extra options
  57. OPTS="${OPTS/--best --allowerasing/}"
  58. fi
  59. if ! [ -d "$DOM0_UPDATES_DIR" ]; then
  60. echo "Dom0 updates dir does not exists: $DOM0_UPDATES_DIR" >&2
  61. exit 1
  62. fi
  63. mkdir -p $DOM0_UPDATES_DIR/etc
  64. if [ -e /etc/debian_version ]; then
  65. # Default rpm configuration on Debian uses ~/.rpmdb for rpm database (as
  66. # rpm isn't native package manager there)
  67. mkdir -p "$DOM0_UPDATES_DIR$HOME"
  68. ln -nsf "$DOM0_UPDATES_DIR/var/lib/rpm" "$DOM0_UPDATES_DIR$HOME/.rpmdb"
  69. fi
  70. # Rebuild rpm database in case of different rpm version
  71. rm -f $DOM0_UPDATES_DIR/var/lib/rpm/__*
  72. rpm --root=$DOM0_UPDATES_DIR --rebuilddb
  73. if [ "$CLEAN" = "1" ]; then
  74. # shellcheck disable=SC2086
  75. $YUM $OPTS clean all
  76. rm -f "$DOM0_UPDATES_DIR"/packages/*
  77. rm -rf "$DOM0_UPDATES_DIR"/var/cache/*
  78. fi
  79. # just check for updates, but don't download any package
  80. if [ "x$PKGLIST" = "x" ] && [ "$CHECK_ONLY" = "1" ]; then
  81. echo "Checking for dom0 updates..." >&2
  82. # shellcheck disable=SC2086
  83. UPDATES_FULL=$($YUM $OPTS check-update)
  84. check_update_retcode=$?
  85. if [ "$check_update_retcode" -eq 1 ]; then
  86. # Exit here if yum have reported an error. Exit code 100 isn't an
  87. # error, it's "updates available" info, so check specifically for exit code 1
  88. exit 1
  89. fi
  90. if [ $check_update_retcode -eq 100 ]; then
  91. echo "Available updates: "
  92. echo "$UPDATES_FULL"
  93. exit 100
  94. else
  95. echo "No new updates available"
  96. if [ "$GUI" = 1 ]; then
  97. zenity --info --text="No new updates available"
  98. fi
  99. exit 0
  100. fi
  101. fi
  102. # now, we will download something
  103. YUM_COMMAND="fakeroot $YUM $YUM_ACTION -y --downloadonly"
  104. # check for --downloadonly option - if not supported (Debian), fallback to
  105. # yumdownloader
  106. if ! $YUM --help | grep -q downloadonly; then
  107. if [ "$YUM_ACTION" = "install" ]; then
  108. YUM_COMMAND="yumdownloader --destdir=$DOM0_UPDATES_DIR/packages --resolve"
  109. elif [ "$YUM_ACTION" = "upgrade" ]; then
  110. # shellcheck disable=SC2086
  111. UPDATES_FULL=$($YUM $OPTS check-update $PKGLIST)
  112. check_update_retcode=$?
  113. UPDATES_FULL=$(echo "$UPDATES_FULL" | grep -v "^Loaded plugins:\|^Last metadata\|^$")
  114. UPDATES=$(echo "$UPDATES_FULL" | grep -v "^Obsoleting\|Could not" | cut -f 1 -d ' ')
  115. if [ "$check_update_retcode" -eq 0 ]; then
  116. # exit code 0 means no updates available - regardless of stdout messages
  117. echo "No new updates available"
  118. exit 0
  119. fi
  120. PKGLIST=$UPDATES
  121. YUM_COMMAND="yumdownloader --destdir=$DOM0_UPDATES_DIR/packages --resolve"
  122. elif [ "$YUM_ACTION" == "list" ] || [ "$YUM_ACTION" == "search" ]; then
  123. # those actions do not download any package, so lack of --downloadonly is irrelevant
  124. YUM_COMMAND="$YUM $YUM_ACTION -y"
  125. elif [ "$YUM_ACTION" == "reinstall" ]; then
  126. # this is just approximation of 'reinstall' action...
  127. # shellcheck disable=SC2086
  128. PKGLIST=$(rpm --root=$DOM0_UPDATES_DIR -q $PKGLIST)
  129. YUM_COMMAND="yumdownloader --destdir=$DOM0_UPDATES_DIR/packages --resolve"
  130. else
  131. echo "ERROR: yum version installed in VM $(hostname) does not suppport --downloadonly option" >&2
  132. echo "ERROR: only 'install' and 'upgrade' actions supported ($YUM_ACTION not)" >&2
  133. if [ "$GUI" = 1 ]; then
  134. zenity --error --text="yum version too old for '$YUM_ACTION' action, see console for details"
  135. fi
  136. exit 1
  137. fi
  138. fi
  139. mkdir -p "$DOM0_UPDATES_DIR/packages"
  140. set -e
  141. if [ "$GUI" = 1 ]; then
  142. ( echo "1"
  143. # shellcheck disable=SC2086
  144. $YUM_COMMAND $OPTS $PKGLIST
  145. echo 100 ) | zenity --progress --pulsate --auto-close --auto-kill \
  146. --text="Downloading updates for Dom0, please wait..." --title="Qubes Dom0 updates"
  147. else
  148. # shellcheck disable=SC2086
  149. $YUM_COMMAND $OPTS $PKGLIST
  150. fi
  151. find "$DOM0_UPDATES_DIR/var/cache" -name '*.rpm' -print0 |\
  152. xargs -0 -r ln -f -t "$DOM0_UPDATES_DIR/packages/"
  153. if ls "$DOM0_UPDATES_DIR"/packages/*.rpm > /dev/null 2>&1; then
  154. cmd="/usr/lib/qubes/qrexec-client-vm dom0 qubes.ReceiveUpdates /usr/lib/qubes/qfile-agent"
  155. qrexec_exit_code=0
  156. $cmd "$DOM0_UPDATES_DIR"/packages/*.rpm || { qrexec_exit_code=$? ; true; };
  157. if [ ! "$qrexec_exit_code" = "0" ]; then
  158. echo "'$cmd $DOM0_UPDATES_DIR/packages/*.rpm' failed with exit code ${qrexec_exit_code}!" >&2
  159. exit "$qrexec_exit_code"
  160. fi
  161. else
  162. echo "No packages downloaded"
  163. fi