upload: send the report to openipc.org's board catalogue, with consent for a backup - #225
Conversation
…t for a backup `ipctool upload` used to PUT the whole flash, keyed by the camera's MAC, to an S3 bucket nobody reads any more, over plain HTTP, with no question asked beyond running the command (#78). It now sends a report to openipc.org's board catalogue, POST /api/v1/reports: - By default only the YAML ipctool prints. It is shown first, with where it goes. openipc.org reviews each report before publishing it, and the public copy replaces the MAC, die ID and cloud ID with hashes. - --backup adds the whole flash in the backup file's format. The mapped partitions are sent as they are, with no copy in RAM or /tmp. The backup stays private (maintainers only) unless --public is given. Either way ipctool says what the flash holds and needs a typed yes, or --yes when there is no terminal. - It prints the receipt address, and the catalogue board the report matches if there is one. - --host name[:port] points it at dev.openipc.org or a bench server. The resolver now takes an IPv4 literal as its own answer. Removed: the camware bucket, its hard-coded download key, and `restore <mac>` / `restore` from the cloud. restore needs a file now, and refuses before it stops or unmounts anything when there is none. report_test checks the multipart body byte by byte, the backup's layout inside it and the Content-Length. Checked on the lab Hi3516EV300 against the openipc.org service: the YAML-only report was stored. The 16 MB backup went up in 7 s, and its boot, env, kernel and rootfs partitions are md5-identical to /dev/mtdblock0-3. A backup with no terminal and no --yes sent nothing, and so did answering "no" to the prompt.
…ock firmware A camera on stock firmware has no curl and no TLS. openipc.org serves ipctool over plain HTTP for uget, and over NFS, from builds this job pushes once, over a GitHub OIDC token. The step is off until the repository variable OPENIPC_ORG_TOOLS_PUSH is "true", which is set once the endpoint is live in production.
PR Summary by QodoSend consent-aware reports to the OpenIPC board catalogue
AI Description
Diagram
High-Level Assessment
Files changed (15)
|
Code Review by Qodo
1.
|
… partial backups From the review of #225: - connect_with_timeout() returned poll()'s 1 when a non-blocking connect completed, and common_connect() read that as a failure. An upload therefore reached the server only when connect() finished at once: strace showed EINPROGRESS, POLLOUT, then ERR_CONNECT. It now returns 0 on success and -1 otherwise. Its F_GETFL result was also lost to operator precedence. - The backup disclosure and its yes come before backup_blocks(), which reads UBI volumes into memory. - backup_blocks() counts the partitions and volumes it could not read, and the upload refuses when any are missing. `backup <file>` warns. - send(MSG_NOSIGNAL) instead of write(). A server that refuses mid-upload (429, 413) and closes no longer kills ipctool; its answer is read and printed. - A public backup is the flash as it is. The notice and the README now say its identifiers are in clear; the report's own copy is hashed. - release.yml: the openipc.org push runs last, cannot fail the job, and checks the token. - clang-format on the new files. On the lab Hi3516EV300 against dev.openipc.org: a YAML report, a private backup, and a backup refused with no terminal. A backup sent after the daily limit printed the server's 429 reason instead of dying on SIGPIPE.
curl -f fails only on 400 and above. After #225 the push got nginx's 302 to openipc.org's home page (the endpoint had no location yet) and the step reported success. It now checks for 200, prints the answer, and fails visibly otherwise; continue-on-error still keeps it from failing the build.
Restores what #78 took away. It now sends to a place people can see, and nothing leaves the camera without the owner's say.
What changes
ipctool uploadused to PUT the whole flash, keyed by the camera's MAC, to thecamwareS3 bucket over plain HTTP. Nothing on openipc.org reads that bucket. It now sends a report to openipc.org's board catalogue (POST /api/v1/reports, OpenIPC/website#341):--backupadds the whole flash in the backup file's format. The mapped partitions are sent as they are, with no copy in RAM or/tmp. The backup is private (maintainers only) unless--publicis given. Either way ipctool says what the flash holds and needs a typedyes, or--yeswhen there is no terminal.--host name[:port]points it at dev.openipc.org or a bench server. The resolver now takes an IPv4 literal as its own answer.Removed:
restore <mac>/restorefrom the cloud.restoreneeds a file now, and refuses beforefree_resources()(so before #224's isolation) when there is none.The release job gains a step that pushes each master build to openipc.org, which serves it to stock firmware over plain HTTP (
http://openipc.org/ipctool, for uget) and NFS. It stays off until the repository variableOPENIPC_ORG_TOOLS_PUSHistrue, which gets set once the endpoint is live in production.Tested
report_test, added to the PR check, checks the multipart body byte by byte: part framing, the backup's layout inside it, and the Content-Length. The same bytes were POSTed to the openipc.org service and accepted./dev/mtdblock0-3;--yessent nothing, and so did answering "no".