Commit Graph
154 Commits
Author SHA1 Message Date
Zorg 7a7fb9ecd9 Don't clean up update directory when Autoupdate receives SIGTERM (#2479)
Under rare circumstances, if Autoupdate receives SIGTERM while the installer queue is installing an update this could cause potential corruption.
2023-12-19 19:56:25 -08:00
Zorg bd90fb7b18 Filter for archive files in generate_appcast more intelligently (#2448) 2023-10-08 09:38:50 -07:00
Zorg 8125490931 Pre-warm installs before relaunch (#2421)
Move a lot of the installation work to be done during the first phase of installation (when possible), before the target app needs to be terminated. For the common case where the old and new bundles are on the same volume, the final phase of installation requiring a restart is now just an atomic swap.

Also move the termination listener to the agent app which resolves some launch/CI failures we've been seeing.
2023-08-27 22:22:52 -07:00
Zorg 821b0ff37f Improve error for xattr code signing for delta updates (#2408) 2023-07-23 16:47:49 -07:00
Eitot c23d74d8e0 Replace CFUUID* with NSUUID (#2395)
This resolves a nullability warning by the static analyzer.
2023-06-23 22:23:37 -07:00
Zorg 8039288f64 Harden verification of Sparkle update download (#2392) 2023-06-17 17:01:45 -07:00
Zorg 270582b2e7 Pass bookmark data for the downloaded update (#2359)
Also let Xcode 14.3 update the nibs.
2023-04-12 22:23:50 -07:00
Zorg 39495fd562 Remove redundant codesign check (#2341) 2023-03-12 19:44:50 -07:00
Zorg 60568b82ba Don't allow DSA-only updates to pass if DSA is disabled (#2340) 2023-03-12 07:59:03 -07:00
Zorg 9ab2c0d58c Hide impractical compression options only useful for debugging (#2335) 2023-03-04 18:03:45 -08:00
Zorg 06edf5695d Remove unnecessary min macro checks (#2318)
Minimum OS preprocessor checks should only be used when compiler may generate compile warnings for deprecated APIs when the deployment target is raised.
2023-02-11 22:24:56 -08:00
Zorg be7f6952c2 Reduce code size and make codebase more consistent (#2305) 2022-12-27 12:03:03 -08:00
Zorg 1c560652e7 Remove ed25519 git submodule (#2244)
Also allow release scripts to work without git repository and bump the Sparkle versions.
2022-08-27 10:46:29 -07:00
Zorg f5d4ad52ca Allow user to re-try installing/relaunching application (#2234)
If the app termination request is delayed or canceled, the user can check for updates again with the standard user driver and try installing/relaunching again, which will trigger the installer to send another quit event to the running application.

Before the install/relaunch window would close but the check for updates option would still be present but not functional.
2022-08-21 08:54:03 -07:00
Zorg 47f335614a Wait for a threshold amount of time before replying with status info data (#2230)
This also reverts 6a69f26dcc and 4cb6719c6b
2022-08-19 10:40:25 -07:00
Zorg 6a69f26dcc Clean up handling appcast item registration message (#2223) 2022-08-07 17:08:33 -07:00
Zorg 4cb6719c6b Critical update alerts may not show up as promptly as they should when automatically installing them (#2221)
Wait for appcast item registration before finishing automatic update driver.

This fixes a potential race issue where sometimes the automatic update driver on completion would sometimes not trigger to prompt an update alert immediately for critical updates. Note in this case, the update would still be installed on app termination and would still be scheduled to alert the user on the regular update check interval, so this issue is not severe.
2022-08-06 11:28:47 -07:00
Zorg 983d19580b Fix handle applying patches when files aren't writeable (#2216) 2022-07-23 10:37:29 -07:00
Zorg 372f0504a5 Bump minimum deployment target to macOS 10.13 (#2196) 2022-07-17 16:43:24 -07:00
Zorg 14e511f901 Fix memory leaks when using generate_appcast (#2193)
We fix one memory leak when calculating sha's, one memory leak in the xar delta applying path, and avoid creating Bundles for reading the Sparkle framework version.

There are some other small leaks with the xar delta creation/applying code but since it's a legacy implementation and the APIs are undocumented I don't want to touch it too much.

The biggest culprit here is the leak when calculating sha's I believe, if you have many archive items.
2022-07-09 12:22:36 -07:00
Zorg d544d456e0 Synchronize usage of XPC connections to main queue (#2178) 2022-06-25 21:29:44 -07:00
Zorg b1f6c161d1 Use snprintf instead of sprintf to fix compile warning (#2179) 2022-06-25 16:41:32 -07:00
Zorg 2ddef5179e Bump initial installer message timeouts and declare daemon/agents as Interactive (#2162) 2022-06-18 11:40:45 -07:00
Zorg 15e8270291 Silence deprecation warnings when bumping deployment target (#2152) 2022-06-11 13:09:23 -07:00
Zorg d7942768b8 Validate permission bits of Sparkle executable for delta updates (#2151) 2022-06-11 11:21:52 -07:00
Zorg 94719edeb3 Ignore custom icons set via resource forks in delta updates (#2114)
For creation, we will disallow creating delta updates if a custom resource fork icon data is found in either the old or app bundles.

For applying, we will just ignore the icon data when performing hash verification and continue applying the patch.
2022-04-24 00:38:42 -07:00
Dan Rigdon-Bel 8edc77fdb2 Use strcoll_l() for locale-independent comparisons (#2087)
The update code uses the compareFiles function to determine the sort order of file names in a directory, which is then compared with a list of files in the Sparkle update info. If the list of files of a directory from Sparkle's update is different than what is on disk, the Sparkle abandons the update and does a full download. This bug would prevent Sparkle from updating properly when the file lists are calculated on an English language system, but then checked on a destination Japanese system.

The fix is to use strcoll_l(), which is locale-independent, when comparing file names for sorting. This will ignore any locale changes the host application has made that could potentially affect Sparkle's sort order.
2022-02-08 20:38:55 -08:00
Zorg 94b48c45e7 Preserve file system compression when applying delta updates (#2084) 2022-01-30 23:37:42 -08:00
Zorg 91bccdf0ad Verify code signing in generate_appcast (#2077)
In generate_appcast we:

* Validate code signing integrity of new updates
* Add hidden flag to disable checking for nested code during validation
* Warn if new and old apps have differing signing identities when generating deltas
2022-01-23 14:46:52 -08:00
Zorg fa9bfc1fc4 Fix unsteady progress when installing updates (#2072)
Also add -showInstallingUpdateWithApplicationTerminated: to SPUUserDriver which replaces -showInstallingUpdate and -showSendingTerminationSignal
2022-01-22 12:07:45 -08:00
Zorg c30f6fe7fb Calculate hash of file for delta updates without using mmap (#2067) 2022-01-18 00:04:40 -08:00
Zorg 1641371e83 Warn and validate against irregular permissions for delta patches (#2061)
* Only track 0755 permissions for symbolic links

Also warn the user when encountering symbolic links that have a non-standard permission mode.

* Warn users when bad or irregular permissions are encountered
2022-01-15 23:00:59 -08:00
Zorg b05c058219 Silence deprecations and use modern NSSecureCoding APIs (#2058) 2022-01-09 19:25:28 -08:00
Zorg 3bd1b25513 Simplify tracking of file permissions for deltas (#2057)
Also fixes minor issue where change in permissions wasn't printed in correct format when applying a patch in verbose mode.
2022-01-09 18:20:50 -08:00
Zorg 41f953d77b Fix minor binary delta issues and make version 3 the default (#2055) 2022-01-08 21:23:15 -08:00
Zorg f6396aecfb Add heuristics for binary delta when files move to other directories (#2053)
We have one heuristic for when a .framework version changes, and another for when a file with the same name moves to another location.

To support this, we added a clone + binary diff command.

Also document and improve the format.
2022-01-08 11:48:27 -08:00
Zorg 71fc8d7b11 Add additional options to delta tools (#2052) 2022-01-04 00:14:45 -08:00
Zorg 23fc577184 Add new version 3 binary delta archive format (#2051)
This new format introduces:

* A new container format which stores metadata in a way that is more efficient for compression, decompression, and size. Creation time can be 2x faster, apply time can be a few seconds faster, size savings can be 500 KB - couple of MB due to metadata alone.
* An array of supported compression formats including lzma, bzip2, zlib and more. We now default to lzma which is as competitive as bzip2 (which we were using in version 2 format) in applying/creation times, but can save several MB on size.
* Tracking of files from an old app being replicated in different locations in the new app. This can track unchanged files being renamed and can result in significant savings if the files are large.

Version 2 format is still the default. To use version 3, pass --version=3 to BinaryDelta when creating a patch. We will switch the default to version 3 later. generate_appcast support is upcoming.
2022-01-02 11:35:51 -08:00
Zorg fc44085602 Isolate xar usage in its own archive type for delta patches (#2047)
Also remove support for creating and applying version 1 delta files. Version 2 delta files have been supported by Sparkle 1.10 and later.
2021-12-29 22:41:08 -08:00
Zorg 3a64116913 Update and review internal documentation (#2030) 2021-12-04 22:59:17 -08:00
Zorg c500487077 Improve pipe usage when unarchiving files (#2027) 2021-11-24 19:21:53 -05:00
Zorg acc4674c3e Fix volume detection being wrong in rare cases (#2026) 2021-11-24 11:33:04 -05:00
Zorg 39cedd4092 Fix unarchiving job being blocked when passed bad input (#2023) 2021-11-24 11:16:31 -05:00
Zorg a81f8f3d2d Add safer handling for applying binary delta files (#1988) 2021-10-29 12:14:23 -07:00
Mayur Pawashe 6b9981f567 Add generation of API docs (#1915) 2021-08-09 18:27:44 -07:00
Zorg 4db96f6c4f Improve error reporting for DSA validation 2021-07-26 15:58:20 +01:00
Zorg 385673ff24 Populate error objects in code signing validation methods 2021-07-26 15:58:20 +01:00
Zorg 89ab067477 Populate NSError when signature validation or code sign fails 2021-07-26 15:58:20 +01:00
Mayur Pawashe 29a2fa7974 Create valid xar files (#1906)
* Create xar files with valid directory/filename structure

* Don't use file hash for determining if files are equal or not
2021-07-24 09:04:48 -07:00
Mayur PawasheandKornel cb9386a4ea Ignore symlink permissions in binary deltas (#1905)
Co-authored-by: Kornel <kornel@geekhood.net>
2021-07-23 17:42:13 -07:00