// Copyright (C) 2025, The Duplicati Team // https://duplicati.com, hello@duplicati.com // // Permission is hereby granted, free of charge, to any person obtaining a // copy of this software and associated documentation files (the "Software"), // to deal in the Software without restriction, including without limitation // the rights to use, copy, modify, merge, publish, distribute, sublicense, // and/or sell copies of the Software, and to permit persons to whom the // Software is furnished to do so, subject to the following conditions: // // The above copyright notice and this permission notice shall be included in // all copies or substantial portions of the Software. // // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS // OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, // FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE // AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER // LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING // FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER // DEALINGS IN THE SOFTWARE. #nullable enable using System; using System.Linq; using System.Collections.Generic; using System.IO; using Duplicati.Library.Utility; using System.Diagnostics; using System.Text.Json; using System.Net.Http; using System.Threading; using Duplicati.Library.Common.IO; namespace Duplicati.Library.AutoUpdater { /// /// Handles operations related to updating the application /// public static class UpdaterManager { /// /// The RSA key used to sign the manifest /// private static System.Security.Cryptography.RSA[] SIGN_KEYS => AutoUpdateSettings.SignKeys; /// /// Urls to check for updated packages /// private static string[] MANIFEST_URLS => AutoUpdateSettings.URLs; /// /// The app name to show /// private static string APPNAME => AutoUpdateSettings.AppName; /// /// The version that the updater supports /// public const int SUPPORTED_PACKAGE_UPDATER_VERSION = 2; /// /// The directory where the program is running from /// public static readonly string INSTALLATIONDIR; /// /// Env variable that allows fully disabling all update checks /// public static readonly bool DISABLE_UPDATE_CHECK = Debugger.IsAttached || Utility.Utility.ParseBool(Environment.GetEnvironmentVariable(string.Format(SKIPUPDATE_ENVNAME_TEMPLATE, APPNAME)), false); /// /// The operating system display name /// public static readonly string OperatingSystemName = OperatingSystem.IsWindows() ? "Windows" : OperatingSystem.IsLinux() ? "Linux" : OperatingSystem.IsMacOS() ? "MacOS" : "Unknown"; /// /// The update information for the running version /// public static readonly UpdateInfo SelfVersion; /// /// Event trigger for errors on update /// public static event Action? OnError; /// /// Common formatting string for date-time values /// private const string DATETIME_FORMAT = "yyyymmddhhMMss"; /// /// The template for the environment variable that toggles disabling updates /// public const string SKIPUPDATE_ENVNAME_TEMPLATE = "AUTOUPDATER_{0}_SKIP_UPDATE"; /// /// The name of the file that contains the manifest, located in the folder /// private const string UPDATE_MANIFEST_FILENAME = "autoupdate.manifest"; /// /// The name of the file that contains the package type id, located in the folder /// private const string PACKAGE_TYPE_FILE = "package_type_id.txt"; /// /// Gets the last version found from an update /// public static UpdateInfo? LastUpdateCheckVersion { get; private set; } /// /// The default timeout in seconds for download operations /// private const int DOWNLOAD_OPERATION_TIMEOUT_SECONDS = 3600; /// /// The default timeout in seconds for fast get version metadata operations /// private const int SHORT_OPERATION_TIMEOUT_SECONDS = 30; /// /// Performs static initialization of the update manager, populating the readonly fields of the manager /// static UpdaterManager() { // Set the installation path INSTALLATIONDIR = Util.AppendDirSeparator(Path.GetDirectoryName(Utility.Utility.getEntryAssembly().Location)); // Attempt to read the installed manifest file UpdateInfo? selfVersion = null; try { selfVersion = ReadInstalledManifest(INSTALLATIONDIR); } catch { } // In case the installed manifest is broken, try to set some sane values SelfVersion = selfVersion ?? new UpdateInfo( MinimumCompatibleVersion: 1, PackageUpdaterVersion: 1, IncompatibleUpdateUrl: string.Empty, GenericUpdatePageUrl: "https://duplicati.com/download", UpdateSeverity: null, ChangeInfo: null, Packages: null, Displayname: string.IsNullOrWhiteSpace(License.VersionNumbers.TAG) ? "Current" : License.VersionNumbers.TAG, Version: System.Reflection.Assembly.GetExecutingAssembly().GetName().Version?.ToString(), ReleaseTime: new DateTime(0), ReleaseType: #if DEBUG "Debug" #else string.IsNullOrWhiteSpace(AutoUpdateSettings.BuildUpdateChannel) ? "Nightly" : AutoUpdateSettings.BuildUpdateChannel #endif ); } public static Version TryParseVersion(string? str) { if (Version.TryParse(str, out var v)) return v; else return new Version(0, 0); } /// /// The package type ID /// public static string PackageTypeId => _packageTypeId.Value; /// /// The package type ID, lazy evaluated /// private static readonly Lazy _packageTypeId = new(() => { try { return File.ReadAllLines(Path.Combine(INSTALLATIONDIR!, PACKAGE_TYPE_FILE)).FirstOrDefault(x => !string.IsNullOrWhiteSpace(x))?.Trim() ?? ""; } catch { } #if DEBUG return "debug"; #else return ""; #endif }); /// /// Checks for updates and returns the update information if available /// /// The release channel to check for updates /// The update information if available, or null if no updates are available public static UpdateInfo? CheckForUpdate(ReleaseType channel = ReleaseType.Unknown) { if (channel == ReleaseType.Unknown) channel = AutoUpdateSettings.DefaultUpdateChannel; foreach (var rawurl in MANIFEST_URLS) { var url = rawurl; // Attempt to match the url to change the channel if possible // This allows overrides to the URLs for deployment of custom builds, // but does not require that they adopt the channel system var match = AutoUpdateSettings.MATCH_AUTOUPDATE_URL.Match(url); if (match.Success) { var mg = match.Groups[AutoUpdateSettings.MATCH_UPDATE_URL_CHANNEL_GROUP]; // Replace the channel name with the chosen channel url = url.Substring(0, mg.Index) + channel.ToString().ToLowerInvariant() + url.Substring(mg.Index + mg.Length); } try { if (SIGN_KEYS.Length == 0) throw new Exception("No signing keys are available, cannot check update"); using (var tmpfile = new TempFile()) { using var request = new HttpRequestMessage(HttpMethod.Get, url); request.Headers.Add(System.Net.HttpRequestHeader.UserAgent.ToString(), string.Format("{0} v{1}{2}", APPNAME, SelfVersion.Version, string.IsNullOrWhiteSpace(DataFolderManager.InstallID) ? "" : " -" + DataFolderManager.InstallID)); request.Headers.Add("X-Install-ID", DataFolderManager.InstallID); request.Headers.Add("X-Package-Type-ID", PackageTypeId); using var timeoutToken = new CancellationTokenSource(); timeoutToken.CancelAfter(TimeSpan.FromSeconds(SHORT_OPERATION_TIMEOUT_SECONDS)); using (var client = HttpClientHelper.CreateClient()) client.DownloadFile(request, tmpfile, null, timeoutToken.Token).Await(); using (var fs = File.OpenRead(tmpfile)) { var verifyOps = SIGN_KEYS.Select(k => new JSONSignature.VerifyOperation( Algorithm: JSONSignature.RSA_SHA256, PublicKey: k.ToXmlString(false) )); if (!JSONSignature.VerifyAtLeastOne(fs, verifyOps)) throw new Exception("No valid signature found in manifest file"); var update = JsonSerializer.Deserialize(fs); if (update == null) return null; if (TryParseVersion(update.Version) <= TryParseVersion(SelfVersion.Version)) return null; // Don't install a debug update on a release build and vice versa if (string.Equals(SelfVersion.ReleaseType, "Debug", StringComparison.OrdinalIgnoreCase) && !string.Equals(update.ReleaseType, SelfVersion.ReleaseType, StringComparison.OrdinalIgnoreCase)) return null; ReleaseType rt; if (!Enum.TryParse(update.ReleaseType, true, out rt)) rt = ReleaseType.Unknown; // If the update is too low to be considered, skip it // Should never happen, but protects against mistakes in deployment if (rt > channel) return null; // In case the manifest does not contain a URL, use the one from this assembly if (string.IsNullOrWhiteSpace(update.GenericUpdatePageUrl)) update = update with { GenericUpdatePageUrl = SelfVersion.GenericUpdatePageUrl }; // In case there is no url, fall back to the project download page if (string.IsNullOrWhiteSpace(update.GenericUpdatePageUrl)) update = update with { GenericUpdatePageUrl = "https://duplicati.com/download" }; LastUpdateCheckVersion = update; return update; } } } catch (Exception ex) { if (OnError != null) OnError(ex); } } return null; } /// /// Reads the installed manifest file /// /// The folder to read the manifest from /// The manifest if found, or null if not found private static UpdateInfo? ReadInstalledManifest(string folder) { var manifest = Path.Combine(folder, UPDATE_MANIFEST_FILENAME); if (File.Exists(manifest)) { try { var verifyOps = SIGN_KEYS.Select(k => new JSONSignature.VerifyOperation( Algorithm: JSONSignature.RSA_SHA256, PublicKey: k.ToXmlString(false) )); using (var fs = File.OpenRead(manifest)) { if (!JSONSignature.VerifyAtLeastOne(fs, verifyOps)) throw new Exception("Installed manifest signature is invalid"); return JsonSerializer.Deserialize(fs); } } catch (Exception ex) { if (OnError != null) OnError(ex); } } return null; } /// /// Downloads the update package /// /// The version to download /// The package to download /// The path to save the downloaded package to /// The progress callback /// True if the download was successful, otherwise false public static bool DownloadUpdate(UpdateInfo version, PackageEntry package, string targetPath, Action? progress = null) { var updates = package.RemoteUrls.ToList(); // If alternate update URLs are specified, // we look for packages there as well if (AutoUpdateSettings.UsesAlternateURLs) { var packagepath = new Library.Utility.Uri(updates[0]).Path; var packagename = packagepath.Split('/').Last(); foreach (var alt_url in AutoUpdateSettings.URLs.Reverse()) { var alt_uri = new Library.Utility.Uri(alt_url); var path_components = alt_uri.Path.Split('/'); var path = string.Join("/", path_components.Take(path_components.Count() - 1).Union(new string[] { packagename })); var new_path = alt_uri.SetPath(path); updates.Insert(0, new_path.ToString()); } } using (var tempfilename = new Library.Utility.TempFile()) { foreach (var url in updates) { try { using (var tempfile = File.Open(tempfilename, FileMode.Create, FileAccess.ReadWrite, FileShare.None)) { Action? cb = null; if (progress != null) cb = (s) => { progress(Math.Min(1.0, Math.Max(0.0, (double)s / package.Length))); }; using var request = new HttpRequestMessage(HttpMethod.Get, url); request.Headers.Add(System.Net.HttpRequestHeader.UserAgent.ToString(), string.Format("{0} v{1}", APPNAME, SelfVersion.Version)); request.Headers.Add("X-Install-ID", DataFolderManager.InstallID); using var timeoutToken = new CancellationTokenSource(); timeoutToken.CancelAfter(TimeSpan.FromSeconds(DOWNLOAD_OPERATION_TIMEOUT_SECONDS)); using (var client = HttpClientHelper.CreateClient()) client.DownloadFile(request, tempfile, cb, timeoutToken.Token).Await(); var sha256 = System.Security.Cryptography.SHA256.Create(); var md5 = System.Security.Cryptography.MD5.Create(); if (tempfile.Length != package.Length) throw new Exception(string.Format("Invalid file size {0}, expected {1} for {2}", tempfile.Length, package.Length, url)); tempfile.Position = 0; var sha256hash = Convert.ToBase64String(sha256.ComputeHash(tempfile)); if (sha256hash != package.SHA256) throw new Exception(string.Format("Damaged or corrupted file, sha256 mismatch for {0}", url)); tempfile.Position = 0; var md5hash = Convert.ToBase64String(md5.ComputeHash(tempfile)); if (md5hash != package.MD5) throw new Exception(string.Format("Damaged or corrupted file, md5 mismatch for {0}", url)); } File.Copy(tempfilename, targetPath, true); return true; } catch (Exception ex) { if (OnError != null) OnError(ex); } } } return false; } /// /// Helper method to create a signed manifest file /// /// The key used for signing the manifest /// The template content in JSON format /// The folder where the signed manifest will be written to /// The version of the manifest /// The URL to use for incompatible updates /// The URL to use for generic updates public static void CreateSignedManifest(IEnumerable keys, string sourcedata, string outputfolder, string? version = null, string? incompatibleUpdateUrl = null, string? genericUpdatePageUrl = null, string? releaseType = null, IEnumerable? packages = null) { // Read the existing manifest var remoteManifest = JsonSerializer.Deserialize(string.IsNullOrWhiteSpace(sourcedata) ? "{}" : sourcedata) ?? throw new Exception("Failed to deserialize the manifest from source data"); if (remoteManifest.ReleaseTime.Ticks == 0) remoteManifest = remoteManifest with { ReleaseTime = DateTime.UtcNow }; // No files to update with are allowed, as we currently do not use the information if (remoteManifest.Packages == null) remoteManifest = remoteManifest with { Packages = Array.Empty() }; remoteManifest = remoteManifest with { PackageUpdaterVersion = SUPPORTED_PACKAGE_UPDATER_VERSION, MinimumCompatibleVersion = 2 }; if (version != null) remoteManifest = remoteManifest with { Version = version.ToString() }; if (!string.IsNullOrWhiteSpace(incompatibleUpdateUrl)) remoteManifest = remoteManifest with { IncompatibleUpdateUrl = incompatibleUpdateUrl }; if (!string.IsNullOrWhiteSpace(genericUpdatePageUrl)) remoteManifest = remoteManifest with { GenericUpdatePageUrl = genericUpdatePageUrl }; if (!string.IsNullOrWhiteSpace(releaseType)) remoteManifest = remoteManifest with { ReleaseType = releaseType }; if (packages != null) remoteManifest = remoteManifest with { Packages = packages.ToArray() }; if (string.IsNullOrWhiteSpace(remoteManifest.IncompatibleUpdateUrl)) remoteManifest = remoteManifest with { IncompatibleUpdateUrl = remoteManifest.GenericUpdatePageUrl }; if (string.IsNullOrWhiteSpace(remoteManifest.IncompatibleUpdateUrl)) throw new Exception($"Field must be set: {nameof(remoteManifest.IncompatibleUpdateUrl)}"); if (string.IsNullOrWhiteSpace(remoteManifest.GenericUpdatePageUrl)) throw new Exception($"Field must be set: {nameof(remoteManifest.GenericUpdatePageUrl)}"); if (string.IsNullOrWhiteSpace(remoteManifest.Version)) throw new Exception($"Field must be set: {nameof(remoteManifest.Version)}"); if (string.IsNullOrWhiteSpace(remoteManifest.ReleaseType)) throw new Exception($"Field must be set: {nameof(remoteManifest.ReleaseType)}"); // Write a signed manifest for upload using (var tf = new TempFile()) { using (var ms = new MemoryStream()) { JsonSerializer.Serialize(ms, remoteManifest, new JsonSerializerOptions { WriteIndented = false }); ms.Position = 0; var signops = keys.Select(k => new JSONSignature.SignOperation( Algorithm: JSONSignature.RSA_SHA256, PublicKey: k.ToXmlString(false), PrivateKey: k.ToXmlString(true) )); using (var fs = File.Create(tf)) JSONSignature.SignAsync(ms, fs, signops).ConfigureAwait(false).GetAwaiter().GetResult(); } // Validate that the written file can also be read using (var fs = File.OpenRead(tf)) { var validSigs = JSONSignature.Verify(fs, keys.Select(k => new JSONSignature.VerifyOperation( Algorithm: JSONSignature.RSA_SHA256, PublicKey: k.ToXmlString(false) ))); if (validSigs.Count() != keys.Count()) throw new Exception("Failed to verify all signatures after signing"); var deserialized = JsonSerializer.Deserialize(fs); if (deserialized == null || deserialized.Version != remoteManifest.Version) throw new Exception("Failed to deserialize the signed manifest"); } File.Move(tf, Path.Combine(outputfolder, UPDATE_MANIFEST_FILENAME)); } } } }