mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-08 22:49:10 +02:00
* [client] Keep the updater silent until management decides the mode The update manager started in download-only mode and every engine stop reset it there again, kicking the update loop with the cached latest version. On a managed peer this published a "New version available" notification on each disconnect, session expiry or logout, and once more in the window between daemon start and the first network map. Users under enforced updates then installed the release by hand. Replace the boolean with a three-state mode. The manager starts undecided and publishes nothing, from the fetcher or from NotifyUI, until the network map picks download-only or managed. A new connection lifecycle resets to undecided; disconnects leave the last decision untouched. A missing AutoUpdateSettings now means download-only instead of a no-op, and on platforms without an installer SetVersion falls back to download-only so they keep notifying. * [client] Address review findings on the updater mode split Route every mode transition through one locked helper so the staged managed version cannot outlive the decision that created it. Both download-only transitions kept pendingVersion, letting Install put on the old enforced release after management disabled updates or the platform fell back to download-only. The helper also bumps a generation counter. handleUpdate and NotifyUI copy the mode under the mutex but publish and install after releasing it, so a reset landing in that window could still emit an enforced notification. Both now recheck the generation right before the side effect and drop the stale work. Reset on every connection attempt instead of once per run: the backoff loop reconnects without re-entering run, and since disconnects no longer force download-only, a fetch in the disconnected gap republished the enforced notification before the new network map arrived. A missing AutoUpdateSettings now logs that it defaults to download-only rather than claiming auto-update is disabled, which contradicted the notifications that mode still emits. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * [client] Reset the updater mode on engine stop Removing SetDownloadOnly from the engine teardown also dropped the reset of the forced-update flag. After netbird down the manager kept the last management directive, so a release published while the client was stopped could still trigger a forced install that management no longer asked for. The same window existed between an engine teardown and the next reconnect attempt, where ResetMode only ran at the start of the attempt. Reset the mode in stopLocked instead, so the updater stays silent from the moment the engine goes down until the first network map of the next connection decides the mode again. * [client] Name the force-reset test for the behavior it proves The silence after ResetMode follows from the undecided mode alone, and the closing SetVersion overwrites forceUpdate from its argument, so the test cannot observe whether the flag itself was cleared. Name it for the stale directive staying silent, which is what it asserts. * [client] Fall back to download-only on a malformed expected version * [client] Compare the full auto-update directive before skipping it * [client] Set the mock latest version under its lock in the updater tests --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
570 lines
14 KiB
Go
570 lines
14 KiB
Go
package updater
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
"sync"
|
|
"time"
|
|
|
|
v "github.com/hashicorp/go-version"
|
|
log "github.com/sirupsen/logrus"
|
|
|
|
"github.com/netbirdio/netbird/client/internal/peer"
|
|
"github.com/netbirdio/netbird/client/internal/statemanager"
|
|
"github.com/netbirdio/netbird/client/internal/updater/installer"
|
|
cProto "github.com/netbirdio/netbird/client/proto"
|
|
"github.com/netbirdio/netbird/version"
|
|
)
|
|
|
|
const (
|
|
latestVersion = "latest"
|
|
)
|
|
|
|
const (
|
|
modeUndecided updateMode = iota
|
|
modeDownloadOnly
|
|
modeManaged
|
|
)
|
|
|
|
var errNoUpdateState = errors.New("no update state found")
|
|
|
|
type updateMode int
|
|
|
|
type UpdateState struct {
|
|
PreUpdateVersion string
|
|
TargetVersion string
|
|
}
|
|
|
|
func (u UpdateState) Name() string {
|
|
return "autoUpdate"
|
|
}
|
|
|
|
type Manager struct {
|
|
statusRecorder *peer.Status
|
|
stateManager *statemanager.Manager
|
|
|
|
mode updateMode
|
|
modeGen uint64
|
|
forceUpdate bool // true when management sets AlwaysUpdate; skips UI interaction and installs directly
|
|
|
|
lastTrigger time.Time
|
|
mgmUpdateChan chan struct{}
|
|
updateChannel chan struct{}
|
|
currentVersion string
|
|
update UpdateInterface
|
|
wg sync.WaitGroup
|
|
|
|
cancel context.CancelFunc
|
|
|
|
expectedVersion *v.Version
|
|
updateToLatestVersion bool
|
|
|
|
pendingVersion *v.Version
|
|
|
|
// updateMutex protects update, expectedVersion, updateToLatestVersion,
|
|
// mode, modeGen, forceUpdate, pendingVersion, and lastTrigger fields
|
|
updateMutex sync.Mutex
|
|
|
|
// installMutex and installing guard against concurrent installation attempts
|
|
installMutex sync.Mutex
|
|
installing bool
|
|
|
|
// protect to start the service multiple times
|
|
mu sync.Mutex
|
|
|
|
autoUpdateSupported func() bool
|
|
}
|
|
|
|
// NewManager creates a new update manager. The manager is single-use: once Stop() is called, it cannot be restarted.
|
|
func NewManager(statusRecorder *peer.Status, stateManager *statemanager.Manager) *Manager {
|
|
manager := &Manager{
|
|
statusRecorder: statusRecorder,
|
|
stateManager: stateManager,
|
|
mgmUpdateChan: make(chan struct{}, 1),
|
|
updateChannel: make(chan struct{}, 1),
|
|
currentVersion: version.NetbirdVersion(),
|
|
update: version.NewUpdate("nb/client"),
|
|
autoUpdateSupported: isAutoUpdateSupported,
|
|
}
|
|
|
|
stateManager.RegisterState(&UpdateState{})
|
|
|
|
return manager
|
|
}
|
|
|
|
// CheckUpdateSuccess checks if the update was successful and send a notification.
|
|
// It works without to start the update manager.
|
|
func (m *Manager) CheckUpdateSuccess(ctx context.Context) {
|
|
reason := m.lastResultErrReason()
|
|
if reason != "" {
|
|
m.statusRecorder.PublishEvent(
|
|
cProto.SystemEvent_ERROR,
|
|
cProto.SystemEvent_SYSTEM,
|
|
"Auto-update failed",
|
|
fmt.Sprintf("Auto-update failed: %s", reason),
|
|
nil,
|
|
)
|
|
}
|
|
|
|
updateState, err := m.loadAndDeleteUpdateState(ctx)
|
|
if err != nil {
|
|
if errors.Is(err, errNoUpdateState) {
|
|
return
|
|
}
|
|
log.Errorf("failed to load update state: %v", err)
|
|
return
|
|
}
|
|
|
|
log.Debugf("auto-update state loaded, %v", *updateState)
|
|
|
|
if updateState.TargetVersion == m.currentVersion {
|
|
m.statusRecorder.PublishEvent(
|
|
cProto.SystemEvent_INFO,
|
|
cProto.SystemEvent_SYSTEM,
|
|
"Auto-update completed",
|
|
fmt.Sprintf("Your NetBird Client was auto-updated to version %s", m.currentVersion),
|
|
nil,
|
|
)
|
|
return
|
|
}
|
|
}
|
|
|
|
func (m *Manager) Start(ctx context.Context) {
|
|
log.Infof("starting update manager")
|
|
m.mu.Lock()
|
|
defer m.mu.Unlock()
|
|
if m.cancel != nil {
|
|
return
|
|
}
|
|
|
|
m.update.SetDaemonVersion(m.currentVersion)
|
|
m.update.SetOnUpdateListener(func() {
|
|
select {
|
|
case m.updateChannel <- struct{}{}:
|
|
default:
|
|
}
|
|
})
|
|
go m.update.StartFetcher()
|
|
|
|
ctx, cancel := context.WithCancel(ctx)
|
|
m.cancel = cancel
|
|
|
|
m.wg.Add(1)
|
|
go func() {
|
|
defer m.wg.Done()
|
|
m.updateLoop(ctx)
|
|
}()
|
|
}
|
|
|
|
func (m *Manager) SetDownloadOnly() {
|
|
m.updateMutex.Lock()
|
|
m.setModeLocked(modeDownloadOnly)
|
|
m.updateMutex.Unlock()
|
|
|
|
select {
|
|
case m.mgmUpdateChan <- struct{}{}:
|
|
default:
|
|
}
|
|
}
|
|
|
|
func (m *Manager) SetVersion(expectedVersion string, forceUpdate bool) {
|
|
log.Infof("expected version changed to %s, force update: %t", expectedVersion, forceUpdate)
|
|
|
|
if !m.autoUpdateSupported() {
|
|
log.Warnf("auto-update not supported on this platform")
|
|
m.SetDownloadOnly()
|
|
return
|
|
}
|
|
|
|
m.updateMutex.Lock()
|
|
defer m.updateMutex.Unlock()
|
|
|
|
if expectedVersion == "" {
|
|
log.Errorf("empty expected version provided")
|
|
m.setModeLocked(modeDownloadOnly)
|
|
return
|
|
}
|
|
|
|
var expectedSemVer *v.Version
|
|
if expectedVersion != latestVersion {
|
|
parsed, err := v.NewVersion(expectedVersion)
|
|
if err != nil {
|
|
log.Errorf("error parsing version, switching to download-only: %v", err)
|
|
m.setModeLocked(modeDownloadOnly)
|
|
select {
|
|
case m.mgmUpdateChan <- struct{}{}:
|
|
default:
|
|
}
|
|
return
|
|
}
|
|
expectedSemVer = parsed
|
|
}
|
|
|
|
if m.sameDirectiveLocked(expectedSemVer, forceUpdate) {
|
|
return
|
|
}
|
|
|
|
m.setModeLocked(modeManaged)
|
|
m.expectedVersion = expectedSemVer
|
|
m.updateToLatestVersion = expectedSemVer == nil
|
|
m.forceUpdate = forceUpdate
|
|
|
|
select {
|
|
case m.mgmUpdateChan <- struct{}{}:
|
|
default:
|
|
}
|
|
}
|
|
|
|
func (m *Manager) ResetMode() {
|
|
m.updateMutex.Lock()
|
|
defer m.updateMutex.Unlock()
|
|
|
|
m.setModeLocked(modeUndecided)
|
|
}
|
|
|
|
// Install triggers the installation of the pending version. It is called when the user clicks the install button in the UI.
|
|
func (m *Manager) Install(ctx context.Context) error {
|
|
if !m.autoUpdateSupported() {
|
|
return fmt.Errorf("auto-update not supported on this platform")
|
|
}
|
|
|
|
m.updateMutex.Lock()
|
|
pending := m.pendingVersion
|
|
m.updateMutex.Unlock()
|
|
|
|
if pending == nil {
|
|
return fmt.Errorf("no pending version to install")
|
|
}
|
|
|
|
return m.tryInstall(ctx, pending)
|
|
}
|
|
|
|
// tryInstall ensures only one installation runs at a time. Concurrent callers
|
|
// receive an error immediately rather than queuing behind a running install.
|
|
func (m *Manager) tryInstall(ctx context.Context, targetVersion *v.Version) error {
|
|
m.installMutex.Lock()
|
|
if m.installing {
|
|
m.installMutex.Unlock()
|
|
return fmt.Errorf("installation already in progress")
|
|
}
|
|
m.installing = true
|
|
m.installMutex.Unlock()
|
|
|
|
defer func() {
|
|
m.installMutex.Lock()
|
|
m.installing = false
|
|
m.installMutex.Unlock()
|
|
}()
|
|
|
|
return m.install(ctx, targetVersion)
|
|
}
|
|
|
|
// NotifyUI re-publishes the current update state to a newly connected UI client.
|
|
// Only needed for download-only mode where the latest version is already cached
|
|
// NotifyUI re-publishes the current update state so a newly connected UI gets the info.
|
|
func (m *Manager) NotifyUI() {
|
|
m.updateMutex.Lock()
|
|
if m.update == nil {
|
|
m.updateMutex.Unlock()
|
|
return
|
|
}
|
|
mode := m.mode
|
|
gen := m.modeGen
|
|
pendingVersion := m.pendingVersion
|
|
latestVersion := m.update.LatestVersion()
|
|
m.updateMutex.Unlock()
|
|
|
|
if mode == modeUndecided {
|
|
return
|
|
}
|
|
|
|
if mode == modeDownloadOnly {
|
|
if latestVersion == nil {
|
|
return
|
|
}
|
|
currentVersion, err := v.NewVersion(m.currentVersion)
|
|
if err != nil || currentVersion.GreaterThanOrEqual(latestVersion) {
|
|
return
|
|
}
|
|
if m.modeChanged(gen) {
|
|
return
|
|
}
|
|
m.statusRecorder.PublishEvent(
|
|
cProto.SystemEvent_INFO,
|
|
cProto.SystemEvent_SYSTEM,
|
|
"New version available",
|
|
"",
|
|
map[string]string{"new_version_available": latestVersion.String()},
|
|
)
|
|
return
|
|
}
|
|
|
|
if pendingVersion != nil && !m.modeChanged(gen) {
|
|
m.statusRecorder.PublishEvent(
|
|
cProto.SystemEvent_INFO,
|
|
cProto.SystemEvent_SYSTEM,
|
|
"New version available",
|
|
"",
|
|
map[string]string{"new_version_available": pendingVersion.String(), "enforced": "true"},
|
|
)
|
|
}
|
|
}
|
|
|
|
// Stop is not used at the moment because it fully depends on the daemon. In a future refactor it may make sense to use it.
|
|
func (m *Manager) Stop() {
|
|
if m.cancel == nil {
|
|
return
|
|
}
|
|
|
|
m.cancel()
|
|
m.updateMutex.Lock()
|
|
if m.update != nil {
|
|
m.update.StopWatch()
|
|
m.update = nil
|
|
}
|
|
m.updateMutex.Unlock()
|
|
|
|
m.wg.Wait()
|
|
}
|
|
|
|
func (m *Manager) onContextCancel() {
|
|
if m.cancel == nil {
|
|
return
|
|
}
|
|
|
|
m.updateMutex.Lock()
|
|
defer m.updateMutex.Unlock()
|
|
if m.update != nil {
|
|
m.update.StopWatch()
|
|
m.update = nil
|
|
}
|
|
}
|
|
|
|
func (m *Manager) updateLoop(ctx context.Context) {
|
|
for {
|
|
select {
|
|
case <-ctx.Done():
|
|
m.onContextCancel()
|
|
return
|
|
case <-m.mgmUpdateChan:
|
|
case <-m.updateChannel:
|
|
log.Infof("fetched new version info")
|
|
}
|
|
|
|
m.handleUpdate(ctx)
|
|
}
|
|
}
|
|
|
|
func (m *Manager) handleUpdate(ctx context.Context) {
|
|
var updateVersion *v.Version
|
|
|
|
m.updateMutex.Lock()
|
|
if m.update == nil {
|
|
m.updateMutex.Unlock()
|
|
return
|
|
}
|
|
|
|
mode := m.mode
|
|
gen := m.modeGen
|
|
forceUpdate := m.forceUpdate
|
|
curLatestVersion := m.update.LatestVersion()
|
|
|
|
switch {
|
|
case mode == modeUndecided:
|
|
log.Tracef("auto-update mode not decided yet")
|
|
m.updateMutex.Unlock()
|
|
return
|
|
// Download-only mode or resolve "latest" to actual version
|
|
case mode == modeDownloadOnly, m.updateToLatestVersion:
|
|
if curLatestVersion == nil {
|
|
log.Tracef("latest version not fetched yet")
|
|
m.updateMutex.Unlock()
|
|
return
|
|
}
|
|
updateVersion = curLatestVersion
|
|
// Install to specific version
|
|
case m.expectedVersion != nil:
|
|
updateVersion = m.expectedVersion
|
|
default:
|
|
log.Debugf("no expected version information set")
|
|
m.updateMutex.Unlock()
|
|
return
|
|
}
|
|
|
|
log.Debugf("checking update option, current version: %s, target version: %s", m.currentVersion, updateVersion)
|
|
if !m.shouldUpdate(updateVersion, forceUpdate) {
|
|
m.updateMutex.Unlock()
|
|
return
|
|
}
|
|
|
|
m.lastTrigger = time.Now()
|
|
log.Infof("new version available: %s", updateVersion)
|
|
|
|
if mode == modeManaged && !forceUpdate {
|
|
m.pendingVersion = updateVersion
|
|
}
|
|
m.updateMutex.Unlock()
|
|
|
|
if m.modeChanged(gen) {
|
|
log.Debugf("auto-update mode changed while checking %s, discarding", updateVersion)
|
|
return
|
|
}
|
|
|
|
if mode == modeDownloadOnly {
|
|
m.statusRecorder.PublishEvent(
|
|
cProto.SystemEvent_INFO,
|
|
cProto.SystemEvent_SYSTEM,
|
|
"New version available",
|
|
"",
|
|
map[string]string{"new_version_available": updateVersion.String()},
|
|
)
|
|
return
|
|
}
|
|
|
|
if forceUpdate {
|
|
if err := m.tryInstall(ctx, updateVersion); err != nil {
|
|
log.Errorf("force update failed: %v", err)
|
|
}
|
|
return
|
|
}
|
|
|
|
m.statusRecorder.PublishEvent(
|
|
cProto.SystemEvent_INFO,
|
|
cProto.SystemEvent_SYSTEM,
|
|
"New version available",
|
|
"",
|
|
map[string]string{"new_version_available": updateVersion.String(), "enforced": "true"},
|
|
)
|
|
}
|
|
|
|
func (m *Manager) modeChanged(gen uint64) bool {
|
|
m.updateMutex.Lock()
|
|
defer m.updateMutex.Unlock()
|
|
|
|
return m.modeGen != gen
|
|
}
|
|
|
|
func (m *Manager) sameDirectiveLocked(expectedVersion *v.Version, forceUpdate bool) bool {
|
|
if m.mode != modeManaged || m.forceUpdate != forceUpdate {
|
|
return false
|
|
}
|
|
if expectedVersion == nil {
|
|
return m.updateToLatestVersion
|
|
}
|
|
return m.expectedVersion != nil && m.expectedVersion.Equal(expectedVersion)
|
|
}
|
|
|
|
func (m *Manager) setModeLocked(mode updateMode) {
|
|
m.mode = mode
|
|
m.modeGen++
|
|
m.forceUpdate = false
|
|
m.expectedVersion = nil
|
|
m.updateToLatestVersion = false
|
|
m.pendingVersion = nil
|
|
m.lastTrigger = time.Time{}
|
|
}
|
|
|
|
func (m *Manager) install(ctx context.Context, pendingVersion *v.Version) error {
|
|
m.statusRecorder.PublishEvent(
|
|
cProto.SystemEvent_CRITICAL,
|
|
cProto.SystemEvent_SYSTEM,
|
|
"Updating client",
|
|
"Installing update now.",
|
|
nil,
|
|
)
|
|
m.statusRecorder.PublishEvent(
|
|
cProto.SystemEvent_CRITICAL,
|
|
cProto.SystemEvent_SYSTEM,
|
|
"",
|
|
"",
|
|
map[string]string{"progress_window": "show", "version": pendingVersion.String()},
|
|
)
|
|
|
|
updateState := UpdateState{
|
|
PreUpdateVersion: m.currentVersion,
|
|
TargetVersion: pendingVersion.String(),
|
|
}
|
|
if err := m.stateManager.UpdateState(updateState); err != nil {
|
|
log.Warnf("failed to update state: %v", err)
|
|
} else {
|
|
if err = m.stateManager.PersistState(ctx); err != nil {
|
|
log.Warnf("failed to persist state: %v", err)
|
|
}
|
|
}
|
|
|
|
inst := installer.New()
|
|
if err := inst.RunInstallation(ctx, pendingVersion.String()); err != nil { //nolint:staticcheck // always errors on platforms without an installer
|
|
log.Errorf("error triggering update: %v", err)
|
|
m.statusRecorder.PublishEvent(
|
|
cProto.SystemEvent_ERROR,
|
|
cProto.SystemEvent_SYSTEM,
|
|
"Auto-update failed",
|
|
fmt.Sprintf("Auto-update failed: %v", err),
|
|
nil,
|
|
)
|
|
return err
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// loadAndDeleteUpdateState loads the update state, deletes it from storage, and returns it.
|
|
// Returns nil if no state exists.
|
|
func (m *Manager) loadAndDeleteUpdateState(ctx context.Context) (*UpdateState, error) {
|
|
stateType := &UpdateState{}
|
|
|
|
m.stateManager.RegisterState(stateType)
|
|
if err := m.stateManager.LoadState(stateType); err != nil {
|
|
return nil, fmt.Errorf("load state: %w", err)
|
|
}
|
|
|
|
state := m.stateManager.GetState(stateType)
|
|
if state == nil {
|
|
return nil, errNoUpdateState
|
|
}
|
|
|
|
updateState, ok := state.(*UpdateState)
|
|
if !ok {
|
|
return nil, fmt.Errorf("failed to cast state to UpdateState")
|
|
}
|
|
|
|
if err := m.stateManager.DeleteState(updateState); err != nil {
|
|
return nil, fmt.Errorf("delete state: %w", err)
|
|
}
|
|
|
|
if err := m.stateManager.PersistState(ctx); err != nil {
|
|
return nil, fmt.Errorf("persist state: %w", err)
|
|
}
|
|
|
|
return updateState, nil
|
|
}
|
|
|
|
func (m *Manager) shouldUpdate(updateVersion *v.Version, forceUpdate bool) bool {
|
|
if version.IsDevelopmentVersion(m.currentVersion) {
|
|
log.Debugf("skipping auto-update, running development version")
|
|
return false
|
|
}
|
|
currentVersion, err := v.NewVersion(m.currentVersion)
|
|
if err != nil {
|
|
log.Errorf("error checking for update, error parsing version `%s`: %v", m.currentVersion, err)
|
|
return false
|
|
}
|
|
if currentVersion.GreaterThanOrEqual(updateVersion) {
|
|
log.Infof("current version (%s) is equal to or higher than auto-update version (%s)", m.currentVersion, updateVersion)
|
|
return false
|
|
}
|
|
|
|
if forceUpdate && time.Since(m.lastTrigger) < 3*time.Minute {
|
|
log.Infof("skipping auto-update, last update was %s ago", time.Since(m.lastTrigger))
|
|
return false
|
|
}
|
|
|
|
return true
|
|
}
|
|
|
|
func (m *Manager) lastResultErrReason() string {
|
|
inst := installer.New()
|
|
result := installer.NewResultHandler(inst.TempDir())
|
|
return result.GetErrorResultReason()
|
|
}
|