Authentication soon required to mirror the entire LVFS
Richard Hughes <[email protected]> Thu, 09 Jan 2025 12:18:42 +0000
| Newsgroups | dev.linux.lists.lvfs-announce |
|---|---|
| Message-ID | <zDlhotSvKqnMDfkCKaE_u4-8uvWsgkuj18ifLBwrLN9vWWrIJjrYQ-QfhpY3xuwIXuZgzOVajW99ymoWmijTdngeFRVjM0BxhPZquUzbDfM=@hughsie.com> |
Hi all, As you might know you can create a local copy of the entire LVFS archive (o= ver 10,000 files, and over 100GB in size) to use locally. This allows big c= ompanies, security vendors, government agencies and educational networks to= deploy firmware updates privately, often to machines without public intern= et access. There will soon be a new LVFS requirement that might affect how = you mirror the LVFS. Over the last few years the number of mirror clones has grown, with some ve= ndors downloading the *entire archive* again and again, sometimes even in t= he same 24h duration. Tools such as Pulp and the standalone sync-pulp.py[1]= will only download changed or new files, and so downloading the entire arc= hive each time is totally unnecessary, hugely wasteful, and somewhat expens= ive to provide. It's also something that badly-configured bots scraping the= LVFS have started doing -- which is hugely frustrating even if I can block= the user agent string after the event. Whilst I encourage large companies to mirror the LVFS whenever possible, we= shouldn't provide TBs of bandwidth and add thousands of log entries for no= good reason. I=E2=80=99m going to merge a feature next week that limits th= e number of daily downloads per-IP to 1000. To put this in perspective, usu= ally less than 10 files are added to the stable metadata each day so any ex= isting mirror sync scripts should not need modification. To mirror the enti= re archive from scratch (without any kind of download limit) you will need = to provide authentication details with your LVFS username and a user profil= e token as the password. If anybody needs a new user account set up please = either file an issue[2], or email me directly =E2=80=93 it=E2=80=99s comple= tely free of charge of course. I=E2=80=99d also ask that anyone who is currently mirroring the LVFS doesn= =E2=80=99t start doing the process at exactly midnight UTC =E2=80=93 there= =E2=80=99s currently quite a spike in those first few minutes of the day an= d although the LVFS spins up additional resources as required, it would be = much better to leave them idle and spread the load over the day. Thanks, Richard. [1] https://gitlab.com/fwupd/lvfs-website/-/raw/master/contrib/sync-pulp.py [2] https://gitlab.com/fwupd/lvfs-website/-/issues