-
Notifications
You must be signed in to change notification settings - Fork 71
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix panic catching in launcher and AKCert #265
Conversation
b25a1ca
to
7e32a8c
Compare
launcher/launcher/main.go
Outdated
|
||
logger = log.Default() | ||
// default logger output to stderr |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
stdout or stderr?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
log.Default() will print to stderr, I want it to output to stdout. I will make the comment more clear.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
any reason we want stdout instead
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
no particular, most of the log we output info, so stdout seems like a better fit.
75682f8
to
d6b0c54
Compare
launcher/launcher/main.go
Outdated
|
||
logger = log.Default() | ||
// default logger output to stderr |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
any reason we want stdout instead
d6b0c54
to
73277c8
Compare
Catch panic using defer recovery in launcher. Return an empty MachineState pointer instead of nil in validateAKCert. Signed-off-by: Jiankun Lu <jiankun@google.com>
73277c8
to
646e9b1
Compare
Breaking Changes: New Features: Add IsHardened in launch spec: google#244 Add container logging redirect policy: google#249 Add SEV-SNP attestation support: google#240 Integrity-protect stateful partition on CS image: google#251 Retry launcher OIDC token refresh with backoff: google#261 Change restart policy behavior to reboot: google#260 Add ability to GetGCEInstanceInfo from a certificate: google#267 Bug Fixes: COS event log: require CEL events to use PCR13, add a launch separator, and don't skip unknown events: google#246 Measure LaunchSeparator event: google#247 Skip unallocated PCR selections when reading all PCRs: google#258 Remove gRPC client and use of insecure credentials: google#262 Fix server.VerifyAttestation proto merging(google#263) and defer of os.Exit(google#264): google#265 Other Changes: Add fake verifier client: google#234 Update CI Go Version to 1.19: google#241 Add launcher integration testing support: google#255 Test multi-writer PD creation disabled: google#256 Update go-sev-guest dependency to v0.2.6: google#259 Change OIDC retry policy to hourly and add jitter to refresh time: google#266 Add wrapper cloudbuild workflow to trigger image build and testing: google#269
Breaking Changes: New Features: Add IsHardened in launch spec: #244 Add container logging redirect policy: #249 Add SEV-SNP attestation support: #240 Integrity-protect stateful partition on CS image: #251 Retry launcher OIDC token refresh with backoff: #261 Change restart policy behavior to reboot: #260 Add ability to GetGCEInstanceInfo from a certificate: #267 Bug Fixes: COS event log: require CEL events to use PCR13, add a launch separator, and don't skip unknown events: #246 Measure LaunchSeparator event: #247 Skip unallocated PCR selections when reading all PCRs: #258 Remove gRPC client and use of insecure credentials: #262 Fix server.VerifyAttestation proto merging(#263) and defer of os.Exit(#264): #265 Other Changes: Add fake verifier client: #234 Update CI Go Version to 1.19: #241 Add launcher integration testing support: #255 Test multi-writer PD creation disabled: #256 Update go-sev-guest dependency to v0.2.6: #259 Change OIDC retry policy to hourly and add jitter to refresh time: #266 Add wrapper cloudbuild workflow to trigger image build and testing: #269
Fix #264 and #263
Catch panic using defer recovery in launcher.
Return an empty MachineState pointer instead of nil in validateAKCert.
Signed-off-by: Jiankun Lu jiankun@google.com