X-Git-Url: http://git.indexdata.com/?a=blobdiff_plain;f=aptcheck%2Faptcheck.pl;h=7801291189a50cf7ec8cbc3113f55fd9229e6e85;hb=723891166cf587acc94977b1215daa5d008842fa;hp=317341d331b0a67c8139624eed369d3b683bb31a;hpb=ed217e789ded5e656e7d479ecafdc232ccfaca97;p=git-tools-moved-to-github.git diff --git a/aptcheck/aptcheck.pl b/aptcheck/aptcheck.pl index 317341d..7801291 100755 --- a/aptcheck/aptcheck.pl +++ b/aptcheck/aptcheck.pl @@ -5,48 +5,126 @@ # Depends heavily on having ssh key authentication set up to all # boxes. That's why I run it on my own workstation. # +# Regular debian upgrades are detected by running +# apt-get upgrade -s +# on every machine, and parsing the output. + +# We have decided to maintain some packages manually on some +# machines, so that system-level upgrades will not disturb +# applications, which may need more hand-holding. These are +# extracted from our apt repository, and queried on every +# server with apt-cache policy. This way, as soon as a package +# is released on our repo, it will get listed here. +# # 11-Mar-2011 Heikki: Started this +# 22-Mar-2011 Heikki: Adding manually maintained packages +# 15-Aug-2011 Heikki: Adding a total in the headline, for nagiosgrapher +# +# TODO: Assumes that we release our restricted packages for all versions +# and architectures at the same time. Gets only the highest version from +# all, and reports anything less than this. Good enough for now. +# +# TODO: Get the dates from ls --full-time /var/cache/apt/archives/ +# and display next to the packages, so we can see how long they have +# been lingering. Boldface them if older than some limit #### Init +use strict; my $debug= $ARGV[0] || 0; # 0=none, 1=some, 2=more, 3=much my $year =`date +%Y`; my $wikilink = 'http://twiki.indexdata.dk/cgi-bin/twiki/view/ID/'; +my $restrictedpackages = "ssh -q kebab cat /home/ftp/pub/debian/dists/*/restricted/*/Packages"; + +#### Host comments +my %hostcomments = ( + "ariel" => "Niels Erik does the manual upgrades", + "bellone" => "Niels Erik does the manual upgrades", + "cfrepous" => "Wolfram does the manual upgrades", + "leopard" => "Wolfram does the manual upgrades", + "lsd" => "Heikki takes care of all upgrades", + ); + #### Get list of hosts # I could use a hard-coded list, but I would forget to maintain it. -# Nagios knows most of our hosts. +# Nagios knows most of our hosts. It even knows which are worth +# checking, they have a command to check apts! my $hostlist = `ssh nagios grep -l Apt /etc/nagios3/indexdata-conf.d/*.cfg` or die "Could not get host list"; print "Got list:\n$hostlist\n" if $debug>2; +###### Get list of packages that can be manually maintained +print "getting restricted package versions\n" if $debug; +my %restrpkgs; +my $restplines = `$restrictedpackages` + or die "Could not get the list of restricted packages " . + "from $restrictedpackages: $! "; +print "Got package list: \n$restplines\n" if $debug>2; +my $pname; +my $pver; +for my $pline ( split("\n",$restplines) ) { + chomp($pline); + $pname = $1 if $pline =~ /^Package:\s+(\S*)\s*$/; + $pver = $1 if $pline =~ /^Version:\s+(\S*)\s*$/; + print "$pline: p=$pname v=$pver\n" if $debug>2; + if ( $pname && $pver ) { + print "\nPackage $pname version $pver \n" if $debug>2; + if ( ! $restrpkgs{$pname} ) { + $restrpkgs{$pname} = $pver; + print "found $pname, first version $pver\n" if $debug>1; + } else { + my $bver = $restrpkgs{$pname}; + `dpkg --compare-versions $bver lt $pver`; + if ( ! $? ) { + print "found $pname, better version $pver (better than $bver)\n" + if $debug>1; + $restrpkgs{$pname} = $pver; + } else { + print "found $pname, but version $pver is no better than $bver\n" + if $debug>2; + } + } + $pname = ""; # clear for the next one. + $pver = ""; + } +} + +if ( $debug >1 ) { + print "got " . scalar(keys(%restrpkgs)) . " restricted packages\n"; + for $pname ( sort (keys(%restrpkgs)) ) { + print " $pname " . $restrpkgs{$pname} . "\n"; + } +} + # Statistics my %summary; -my %sechosts; -my %secpkgs; -my %ownhosts; -my %ownpkgs; -my %normhosts; -my %normpkgs; +my ( %sechosts, %secpkgs ); +my ( %ownhosts, %ownpkgs ); +my ( %manhosts, %manpkgs ); +my ( %normhosts, %normpkgs ); my %okhosts; my %skiphosts; my %allhosts; my $sectot = 0; my $owntot = 0; +my $mantot = 0; my $normtot = 0; my $table = "
$H (skipped)\n"; @@ -54,11 +132,49 @@ for $hline ( split("\n",$hostlist) ) { next; } print "Got apts for $H: \n$apt\n" if $debug>2; - my $det = ""; + my $det = ""; # detail lines my $pkgs = 0; my $secs = 0; my $own = 0; - for $p ( split("\n",$apt) ) { + my $man = 0; + my $restrname = ""; + my $restrinst = ""; + my $restrcand = ""; + for my $p ( split("\n",$apt) ) { + # parse apt-cache output + $restrname = $1 if $p =~ /^(\S+):$/; + $restrinst = $1 if $p =~ /^\s+Installed:\s+(\S+)$/; + $restrcand = $1 if $p =~ /^\s+Candidate:\s+(\S+)$/; + if ( $p =~ /^\s+Version table:/ ) { # have all for that package + my $bver = $restrpkgs{$restrname}; + if ( ( $restrinst eq $restrcand ) && + ( $restrinst ne $bver ) ) { + # if different, it is a regular apt upgrade, and will be seen + # later. AND we want to have a different version in our repo + `dpkg --compare-versions $bver lt $restrinst`; + if ( $? ) { # It was not a downgrade + # manual packages may be ahead of the repo! + $mantot++; + $man++; + $pkgs++; + $manhosts{$H} = 1; + $manpkgs{$restrname} = 1; + $det .= " | ||
$restrname (M) | "; + $det .= "". strdiff($bver,$restrinst)." | "; + $det .= "". strdiff($restrinst,$bver)." | "; + $det .= "$cur | "; $det .= "$new | "; @@ -102,17 +216,24 @@ for $hline ( split("\n",$hostlist) ) { if ( $pkgs ) { $table .= "$pkgs packages to upgrade. "; $table .= "$secs security. " if $secs; - $table .= " $own from indexdata " if $own; + $table .= " $own from indexdata. " if $own; + $table .= " $man manual. " if $man; } else { $table .= "ok"; $okhosts{$H} = 1; } my $updlink = $wikilink . ucfirst($H) . "Updates" . $year; + # Fix some pages that do not follow the convention. + # Mostly because the host names would not make proper WikiWords + $updlink =~ s/Bugzilla3Updates/BugzillaUpdates/; + $updlink =~ s/Opencontent-solrUpdates/OpenContentSolrUpdates/; $table .= " Upd"; $table .= "\n"; + $table .= "
$hostcomments{$H} |
" ; @@ -135,56 +261,122 @@ print F " | Packages | ||
Security " . scalar(keys(%sechosts)) . - " / " . scalar(keys(%secpkgs)) . " / $sectot | \n" ;
+ " / " . scalar(keys(%secpkgs)) . " / $sectot \n" ;
print F ""; - for $HH ( sort(keys(%sechosts)) ) { + for my $HH ( sort(keys(%sechosts)) ) { print F "$HH "; } - print F " | " . join(" ",sort(keys(%secpkgs))) . " | "; + print F ""; + print F ""; + for my $PP ( sort(keys(%secpkgs)) ) { + print F "$PP "; + } + print F " | "; print F "
Indexdata " . scalar(keys(%ownhosts)) . - " / " . scalar(keys(%ownpkgs)) . " / $owntot | \n" ;
+ " / " . scalar(keys(%ownpkgs)) . " / $owntot \n" ;
print F ""; - for $HH ( sort(keys(%ownhosts)) ) { + for my $HH ( sort(keys(%ownhosts)) ) { print F "$HH "; } - print F " | " . join(" ",sort(keys(%ownpkgs))) . " | "; + print F ""; + print F ""; + for my $PP ( sort(keys(%ownpkgs)) ) { + print F "$PP "; + } + print F " | "; + print F "
Manual " . scalar(keys(%manhosts)) . + " / " . scalar(keys(%manpkgs)) . " / $mantot | \n" ;
+ print F ""; + for my $HH ( sort(keys(%manhosts)) ) { + print F "$HH "; + } + print F " | "; + print F ""; + for my $PP ( sort(keys(%manpkgs)) ) { + print F "$PP "; + } + print F " | "; print F "|
Indexdata " . scalar(keys(%normhosts)) . - " / " . scalar(keys(%normpkgs)) . " / $normtot | \n" ;
+ print F "|||
Normal " . scalar(keys(%normhosts)) . + " / " . scalar(keys(%normpkgs)) . " / $normtot | \n" ;
print F ""; - for $HH ( sort(keys(%normhosts)) ) { + for my $HH ( sort(keys(%normhosts)) ) { print F "$HH "; } - print F " | " . join(" ",sort(keys(%normpkgs))) . " | "; + print F ""; + print F ""; + for my $PP ( sort(keys(%normpkgs)) ) { + print F "$PP "; + } + print F " | "; print F "
Skipped: " . scalar(keys(%skiphosts)) . " | \n"; + print F "|||
Skipped " . scalar(keys(%skiphosts)) . " | \n"; print F ""; - for $HH ( sort(keys(%skiphosts)) ) { + for my $HH ( sort(keys(%skiphosts)) ) { print F "$HH "; } print F " | ||
Ok: " . scalar(keys(%okhosts)) . " | \n"; +#if ( %okhosts ) { +if ( 1 ) { + print F "|||
Ok " . scalar(keys(%okhosts)) . " | \n"; print F ""; - for $HH ( sort(keys(%okhosts)) ) { + for my $HH ( sort(keys(%okhosts)) ) { print F "$HH "; } + if ( !%okhosts ) { + print F "None at all!"; + } print F " |
$PN | \n"; + print F ""; + for my $HH ( split(' ',$summary{$P} )) { + print F "$HH "; + } + print F " | \n"; + +} +print F "