Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix panic catching in launcher and AKCert #265

Merged
merged 1 commit into from
Nov 23, 2022

Conversation

jkl73
Copy link
Contributor

@jkl73 jkl73 commented Nov 21, 2022

Fix #264 and #263

Catch panic using defer recovery in launcher.
Return an empty MachineState pointer instead of nil in validateAKCert.

Signed-off-by: Jiankun Lu jiankun@google.com

@jkl73 jkl73 requested a review from alexmwu November 21, 2022 18:50
@jkl73 jkl73 force-pushed the fixakcertanddefer branch 2 times, most recently from b25a1ca to 7e32a8c Compare November 21, 2022 19:06

logger = log.Default()
// default logger output to stderr
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

stdout or stderr?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

log.Default() will print to stderr, I want it to output to stdout. I will make the comment more clear.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

any reason we want stdout instead

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

no particular, most of the log we output info, so stdout seems like a better fit.

server/verify.go Outdated Show resolved Hide resolved
server/verify.go Outdated Show resolved Hide resolved
launcher/launcher/main.go Show resolved Hide resolved
@jkl73 jkl73 force-pushed the fixakcertanddefer branch 2 times, most recently from 75682f8 to d6b0c54 Compare November 22, 2022 20:19
launcher/launcher/main.go Outdated Show resolved Hide resolved

logger = log.Default()
// default logger output to stderr
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

any reason we want stdout instead

@jkl73 jkl73 force-pushed the fixakcertanddefer branch from d6b0c54 to 73277c8 Compare November 23, 2022 03:17
Catch panic using defer recovery in launcher.
Return an empty MachineState pointer instead of nil in validateAKCert.

Signed-off-by: Jiankun Lu <jiankun@google.com>
@jkl73 jkl73 force-pushed the fixakcertanddefer branch from 73277c8 to 646e9b1 Compare November 23, 2022 03:41
@jkl73 jkl73 merged commit 58bc30b into google:master Nov 23, 2022
alexmwu added a commit to alexmwu/go-tpm-tools that referenced this pull request Dec 16, 2022
Breaking Changes:

New Features:
Add IsHardened in launch spec: google#244
Add container logging redirect policy: google#249
Add SEV-SNP attestation support: google#240
Integrity-protect stateful partition on CS image: google#251
Retry launcher OIDC token refresh with backoff: google#261
Change restart policy behavior to reboot: google#260
Add ability to GetGCEInstanceInfo from a certificate: google#267

Bug Fixes:
COS event log: require CEL events to use PCR13, add a launch separator, and don't skip unknown events: google#246
Measure LaunchSeparator event: google#247
Skip unallocated PCR selections when reading all PCRs: google#258
Remove gRPC client and use of insecure credentials: google#262
Fix server.VerifyAttestation proto merging(google#263) and defer of os.Exit(google#264): google#265

Other Changes:
Add fake verifier client: google#234
Update CI Go Version to 1.19: google#241
Add launcher integration testing support: google#255
Test multi-writer PD creation disabled: google#256
Update go-sev-guest dependency to v0.2.6: google#259
Change OIDC retry policy to hourly and add jitter to refresh time: google#266
Add wrapper cloudbuild workflow to trigger image build and testing: google#269
@alexmwu alexmwu mentioned this pull request Dec 16, 2022
alexmwu added a commit that referenced this pull request Dec 16, 2022
Breaking Changes:

New Features:
Add IsHardened in launch spec: #244
Add container logging redirect policy: #249
Add SEV-SNP attestation support: #240
Integrity-protect stateful partition on CS image: #251
Retry launcher OIDC token refresh with backoff: #261
Change restart policy behavior to reboot: #260
Add ability to GetGCEInstanceInfo from a certificate: #267

Bug Fixes:
COS event log: require CEL events to use PCR13, add a launch separator, and don't skip unknown events: #246
Measure LaunchSeparator event: #247
Skip unallocated PCR selections when reading all PCRs: #258
Remove gRPC client and use of insecure credentials: #262
Fix server.VerifyAttestation proto merging(#263) and defer of os.Exit(#264): #265

Other Changes:
Add fake verifier client: #234
Update CI Go Version to 1.19: #241
Add launcher integration testing support: #255
Test multi-writer PD creation disabled: #256
Update go-sev-guest dependency to v0.2.6: #259
Change OIDC retry policy to hourly and add jitter to refresh time: #266
Add wrapper cloudbuild workflow to trigger image build and testing: #269
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

launcher: Don't defer os.Exit
2 participants