Hi Stefano,
Thank you for the quick and clear feedback!
> Do you experience the same issue if you use "swupdate-client <filename>" instead of "swupdate -i" ?
In our embedded setup, SWUpdate is invoked by an updater daemon on-demand
to install local/nested SWU packages on subcomponents, so running
standalone "swupdate -i" was used rather than having a persistent background
daemon running. Looking at tools/swupdate-client.c, line 119 also has:
end_status = EXIT_FAILURE;
so swupdate-client exhibits the exact same behavior if post-update actions
fail or race.
Your architectural rationale makes total sense: the update itself is
atomic and complete once "SWUpdate was successful !" is reached, and post-update
actions are best-effort post-processing that should not invalidate the update.
In v2:
- Both core/install_from_file.c and tools/swupdate-client.c are updated
so that end_status is preserved as EXIT_SUCCESS if the update succeeded.
- Used WARN() instead of ERROR() in install_from_file.c so it does not
indicate that the update failed.
- Dropped the retry loop since post-update failures are no longer fatal.
(Note: we noticed corelib/downloader.c:84 also sets result = FAILURE on
ipc_postupdate failure; please let me know if you would like that aligned
in this patch series as well.)
Best regards,
Arturs
---
From 9cb78d5e1af9fd0c353e8241c4ce0181978d76da Mon Sep 17 00:00:00 2001
From: Arturs Laizans <
arturs.la...@kiongroup.com>
Date: Tue, 22 Sep 2026 16:36:26 +0200
Subject: [PATCH v2] install_from_file, swupdate-client: Do not fail update on
post-update failure
The update itself is atomic and complete once "SWUpdate was successful !"
is reached. Post-update actions initiated via ipc_postupdate() are intended
for subsequent actions or cleanup, but failure of post-update actions
should not invalidate the already successful update or alter its final
exit status.
Previously, both install_from_file() and swupdate-client's end()
callback overrode end_status to EXIT_FAILURE if ipc_postupdate() failed
or returned NACK. In install_from_file(), this occurred silently without
any error or warning output.
Do not alter end_status on post-update failures in either
install_from_file() or swupdate-client. Additionally, log a warning via
WARN() in install_from_file() if post-update actions fail, so that
issues with post-processing are visible without marking the update
as failed.
Changes in v2:
- Do not override end_status to EXIT_FAILURE on post-update failures (update was already successful).
- Apply the fix consistently across both core/install_from_file.c and tools/swupdate-client.c.
- Use WARN() instead of ERROR() in install_from_file.c to avoid signaling update failure.
- Drop retry loop as post-update is best-effort and non-fatal.
core/install_from_file.c | 4 +++-
tools/swupdate-client.c | 1 -
2 files changed, 3 insertions(+), 2 deletions(-)
diff --git a/core/install_from_file.c b/core/install_from_file.c
index e222e30e..f086f689 100644
--- a/core/install_from_file.c
+++ b/core/install_from_file.c
@@ -60,7 +60,9 @@ static int endupdate(RECOVERY_STATUS status)
ipc_message msg;
msg.data.procmsg.len = 0;
if (ipc_postupdate(&msg) != 0 || msg.type != ACK) {
-
end_status = EXIT_FAILURE;
+
WARN("Post-update actions failed%s%s",
+
(msg.type != ACK && msg.data.msg[0]) ? ": " : "",
+
(msg.type != ACK && msg.data.msg[0]) ? msg.data.msg : "");
}
}
diff --git a/tools/swupdate-client.c b/tools/swupdate-client.c
index 5075bfed..3d4ffcfd 100644
--- a/tools/swupdate-client.c
+++ b/tools/swupdate-client.c
@@ -116,7 +116,6 @@ static int end(RECOVERY_STATUS status)
msg.data.procmsg.len = 0;
if (ipc_postupdate(&msg) != 0 || msg.type != ACK) {
fprintf(stderr, "Running post-update failed!\n");
-
end_status = EXIT_FAILURE;
}
}
--
2.43.0