SetVirtualDiskInformation API is required for running confidential windows containers. The
VHDs used for starting confidential pods/UVMs need to have a specific disk
identifier. These newly added APIs will be used when preparing the VHDs for confidential
pods.
Signed-off-by: Amit <ambarve@microsoft.com>
Some new upcoming changes require us to use Go 1.23. However, if we switch to Go 1.23 some
new linter errors are showing up. This commit fixes most of the errors and adds an
exclusion for integer overflow errors.
Signed-off-by: Amit <ambarve@microsoft.com>
This reverts commit f2a56450f4, which switched
from os/exec to the golang.org/x/sys/execabs package to mitigate security
issues (mainly on Windows) with lookups resolving to binaries in the current
directory.
from the go1.19 release notes https://go.dev/doc/go1.19#os-exec-path
> ## PATH lookups
>
> Command and LookPath no longer allow results from a PATH search to be found
> relative to the current directory. This removes a common source of security
> problems but may also break existing programs that depend on using, say,
> exec.Command("prog") to run a binary named prog (or, on Windows, prog.exe) in
> the current directory. See the os/exec package documentation for information
> about how best to update such programs.
>
> On Windows, Command and LookPath now respect the NoDefaultCurrentDirectoryInExePath
> environment variable, making it possible to disable the default implicit search
> of “.” in PATH lookups on Windows systems.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
* Update to go 1.21
Use `atomic.Bool` stdlib instead of including our own.
Include `tools\mkwinsyscall` updates from go-winio/283 to switch to
`syscallN`.
Note: removed `// TODO` about `print`/`ln`, since the latter adds spaces
between args when printing, which is undesired.
Also update CI to run steps on windows-2022 instead of windows-2019,
similar to our hcsshim CI.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* PR: simplify type checking
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
---------
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* fileinfo: internally fix FileBasicInfo memory alignment
Signed-off-by: Davis Goodin <dagood@microsoft.com>
* Update test with review feedback
Remove unused winName.
Extract more into Windows alignment consts to repeat less.
Document reason for having multiple alignment consts for the same value.
Signed-off-by: Davis Goodin <dagood@microsoft.com>
---------
Signed-off-by: Davis Goodin <dagood@microsoft.com>
* Bug: Close hvsock handle on listen error; fix tests
Close the socket created in
`github.com/Microsoft/go-winio/pkg/ListenHvsock` if either the `Bind` or
`Listen` calls fail.
Go changed `filepath.VolumeName` code, resulting in different behavior in
`github.com/Microsoft/go-winio/pkg/fs.GetFileSystemType`.
Update test accordingly.
Also add more debug logs to `pkg\fs\resolve_test.go`.
Also, move add skip for fuzzing on WS2019 or older to `FuzzHvSockRxTx`
code directly, instead of in ci.yml.
See: https://go-review.googlesource.com/c/go/+/540277
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* PR: unskip TestResolvePath
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
---------
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
I would like to use impersonation on the server side of the pipe, but I
currently cannot because all pipes are connected using the anonymous
impersonation level.
This patch adds a new function that provides the ability to explicitly
specify the desired impersonation level.
Fixes#297
Signed-off-by: Aaron Klotz <aaron@tailscale.com>
unsafe.Sizeof(windows.SECURITY_DESCRIPTOR{}) is the minimum length of the SD,
not the actual length. Use the actual length for computing the length of the
slice.
This path also removes getSecurityDescriptorLength, which is no longer used.
Fixes https://github.com/microsoft/go-winio/issues/298
Signed-off-by: Aaron Klotz <aaron@tailscale.com>
Where ever possible, use `golang.org/x/sys/windows` instead of `syscall`
(which has been deprecated since go1.11).
Using `windows.LocalFree` requires using `unsafe.Pointer`, which ensures
that the Go garbage collector does not try to free memory pre-maturely
if it was previously declared as a pointer.
Since `syscall.Handle` is part of API for `vhd` package, it was left
unchanged.
For security descriptor functions, switch to using
`windows.SECURITY_DESCRIPTOR` to avoid unnecessary byte manipulation and
panics due to missing input validation and error checking.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
Run fuzzing tests in CI.
Use race detector when running tests.
Add missing `t.Helper()` calls.
Update test helpers in `pkg/bindfilter` to use `RtlGetNtVersionNumbers`
instead of reading registry, and skip tests if not running as admin.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
Add `String()` functions to `etw.Level` and `etw.Opcode` types.
Add `etw.JSONStringField()`, which denotes a string field containing
JSON data.
Fix doc comment casing.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* Add `fs.ResolvePath` to resolve symbolic links
`filepath.EvalSymlinks` does not work well on Windows, and can enter
infinite loops in certain situations and error out.
Use Win32 API GetFinalPathNameByHandle to handle path resolution.
Implementation based off on: https://github.com/containerd/containerd/pull/5411
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* PR: types, documentation
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* remove unneded constant groups
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* Attempt normalized path first
Update logic to try querying for normalized path initially, then use
opened path if access is denied.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
---------
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* Apply CL463216: write source to temp file if formatting fails
This change writes the unformatted Go source code to a temp file if
"format.Source" fails. Print the temp file path to the console to make
it easy to find. The source code is what causes formatting errors, and
it can be difficult to diagnose them without this context.
CL link: https://go-review.googlesource.com/c/sys/+/463216
commit: 4112509618ee88519f899be20efc6882496b57c8
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* Apply CL463215: support "." and "-" in DLL name
This change adds "." and "-" support for DLL filenames in "//sys".
Supporting "." requires a change in how mkwinsyscall handles the
"= <filename>.<function>" syntax. Instead of assuming that only one "."
can appear in this string, now mkwinsyscall assumes that any additional
"." belongs to the filename.
Supporting "." also requires changing how Go identifiers are created for
each DLL. This change also allows mkwinsyscall to support "-". When
creating a Go identifier, "." and "-" in the DLL filename are replaced
with "_". Otherwise, mkwinsyscall would produce invalid Go code, causing
"format.Source" to fail.
CL link: https://go-review.googlesource.com/c/sys/+/463215
commit: 71da6904945ac440253cb5c132d64712f80ca497
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
---------
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* Add some basic bind filter functions
This change adds the ability to mount a a single folder or a volume
inside another folder, using the bind filter API.
While the API allows mounting multiple sources inside a single mount
point, acting as an overlay, we disable this functionality in the ApplyFileBinding
function.
Signed-off-by: Gabriel Adrian Samfira <gsamfira@cloudbasesolutions.com>
* Add some tests
Signed-off-by: Gabriel Adrian Samfira <gsamfira@cloudbasesolutions.com>
* Move bind filter to different package
Signed-off-by: Gabriel Adrian Samfira <gsamfira@cloudbasesolutions.com>
* Use string in signature and fix getFinalPath
* Properly close handle in getFinalPath()
* Use string in function signature. mksyscall generates proper code to
convert to utf16
* Enable TestRemoveFileBinding on Windows Server 2019
Windows Server 2019 only exposes 2 function in bindfltapi.dll:
* BfRemoveMapping
* BfSetupFilter
Signed-off-by: Gabriel Adrian Samfira <gsamfira@cloudbasesolutions.com>
* Use windows.UTF16ToString to decode string
Signed-off-by: Gabriel Adrian Samfira <gsamfira@cloudbasesolutions.com>
* Optimize bfGetMappings signature
Signed-off-by: Gabriel Adrian Samfira <gsamfira@cloudbasesolutions.com>
* Skip unsupported tests on ltsc2019
Signed-off-by: Gabriel Adrian Samfira <gsamfira@cloudbasesolutions.com>
* Fix typo, add testcase
* Additionally check if we can write to a read-only mount point, not
just delete from it
* No need to set FILE_FLAG_OPEN_REPARSE_POINT when opening a file
Signed-off-by: Gabriel Adrian Samfira <gsamfira@cloudbasesolutions.com>
* Remove extra flags
Signed-off-by: Gabriel Adrian Samfira <gsamfira@cloudbasesolutions.com>
* Add test to account for symlinks as sources
Signed-off-by: Gabriel Adrian Samfira <gsamfira@cloudbasesolutions.com>
---------
Signed-off-by: Gabriel Adrian Samfira <gsamfira@cloudbasesolutions.com>
It looks like for the purpose of the example "a" logger was needed, so not
strictly logrus (probably `fmt.Println()` would've worked even).
This patch removes logrus as dependency for the example. The only remaining
use of logrus in this repository is now in the pkg/etc/etwlogrus package, which
_does_ need logrus, but (possibly) could become its own module if we want to
remove logrus as dependency of go-winio itself.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
Remove some aggressive linters: `godoc`, `goconst`, `misspel`, `nestif`,
and `prealloc.
Also remove `stylecheck` since it is subsumed by `revive`, and
the later is more configurable.
Allow tests and build stages to continue even if linter fails.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
Switched to subtests using `t.Run()` for GUID testing, rather than using
log statements to demarcate different tests.
Added `.String` to GUID `Variant` and `Version` using
`golang.org/x/tools/cmd/stringer`.
Added `tools.go` to version `stringer` in go.mod and allow
`go generate ./...` to be run without needing a `go get` call.
Based off of [go wiki](https://github.com/golang/go/wiki/Modules#how-can-i-track-tool-dependencies-for-a-module)
recommendation.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
`./internal/socket/socket.go` uses `github.com/Microsoft/go-winio/tools/mkwinsyscall`
instead of `golang.org/x/sys/windows/mkwinsyscall` for its
`//go:generate` directive, keeping it consistent with the rest of the
repo.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* Add lint and go generate stages to CI
Add CI step to verify `go generate` was run on repo.
Add linter stage to CI along with linter config file,
`.golangci.yml`.
Will likely prefer revive over static-check.
Updated README Contributing section on linting requirements.
Added sequence ordering to make sure lint and go generate stages run
before tests and build.
This way, build and tests are not run on code that could potentially:
1. not build due to `gofmt` issues;
2. contain bugs;
3. have to be re-submitted after issues are fixed; or
4. contain outdated Win32 syscall or other auto-generated files.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* Fixed linter issues
Code changes to satisfy linters:
- Ran `gofmt -s -w` on repo.
- Broke up long lines.
- When possible, changed names with incorrect initialism formatting
- Added exceptions for exported variables.
- Added exceptions for ALL_CAPS_WITH_UNDERSCORES code.
- Switched to using `windows` or `syscall` definitions if possible;
especially if some constants were unused.
- Added `_ =` to satisfy error linter, and acknowledge that errors are
being ignored.
- Switched to using `errors.Is` and `As` in places, elsewhere added
exceptions if error value was known to be `syscall.Errno`.
- Removed bare returns.
- Prevented variables from being overshadowed in certain places
(ignoring cases of overshadowing `err`).
- Renamed variables and functions (eg, `len`, `eventMetadata.bytes`) to
prevent shadowing pre-built functions and imported pacakges.
- Removed unused method receivers.
- Added exceptions to certain unused (unexported) constants and
functions.
- Deleted unused `once` from `pkg/etw.providerMap`.
- Renamed `noop.go` files to `main_other.go` or `doc.go`, to better fit
style recommendations.
- Added exceptions for non-secure use of SHA1 and weak crypto
libraries.
- Replaced `ioutil` with `io` and `os` (and `t.TempDir` in tests).
- Added fully exhaustive checks for `switch` statements in `pkg/etw`.
- Defined constant strings for `tools/mkwinsyscall`.
- Removed unnecessary conversions.
- Made sure `context.Cancel` was called.
Additionally, added `//go:build windows" constraints on files with
unexported code, since linter will complain about unused code on
non-Windows platforms.
Added a stub `main() {}` for `mkwinsyscall` for non-Windows builds, just in
case `//go:generate` directives are added to OS-agnostic files.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* PR: spelling, constants, fuzzing
Moved HVSocket fuzzing tests to separate file with go 1.18 build
constraint.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* Added HV Socket tests
Added tests for core Hyper-V socket functionality, including testing
CloseRead and CloseWrite, as well as checking addresses are appropriate
and timeouts work.
Added fuzzing test to check for edge case read/write issues.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* pr: asserts, naming, fatal in test
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* Added HV Socket known IDs, Dial, bug fixes
Added:
* Well-know Hyper-V VMIDs for parents, children, and loopback.
* VSock interop service GUID.
* `Dial()` and `DialContext()` to dial a specific Hyper-V socket at a
known address (along with a corresponding `HvsockDialer` struct.
Bug fixes:
* Dial (and Listen) now properly initialize and set properties of their
sockets after ConnectEx (and AcceptEx).
* The `socketError` used by `bind` was incorrect, it should be `int32(-1)`,
not `uintptr(^0)`
* Return errors for `(*HvsockConn) SetDeadline`
Created a `sockets` package, currently only with syscalls to `Bind`,
`ConnectEx` and `GetSockName`, bypassing `syscall/windows` restrictions
on the types that can do so.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* PR: error handling bug, rebase, unexport, naming
* comments and todos statements
* spelling
* removed dead code
* changed names to be more conventional
* unexported socket code
* made `(*HvsockDialer) Dial` take `Context`, removed `DialContext`
* added default `Dial` function
* rebased onto main
* cleaned up `Dial(` retry loop
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* PR: RawSockaddr validation, `.As(` style
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* Update decompress.go
Add linux to build tags
Signed-off-by: Michał Legin <mlegin@google.com>
* Update wim.go
Add linux to build tags
Signed-off-by: Michał Legin <mlegin@google.com>
Language server complains about
`invalid operation: operator | not defined on windows.TOKEN_ADJUST_PRIVILEGES`
in `privilege.go`. Upgrading to new golang.org/x/sys fixes issue.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* ETW name and options functionality
Added functionality to set the event (task) name and options (such as
event or associated event ID) for ETW events created by the hook based
on the logrus.Entry fields.
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
* PR: export and comment
Signed-off-by: Hamza El-Saawy <hamzaelsaawy@microsoft.com>
Add in a ^1.17.0 go-version for the actions/setup-go@v2 action. This
was set for our build step but not for the step that runs all of the
unit tests.
Signed-off-by: Daniel Canter <dcanter@microsoft.com>