vendor: github.com/Microsoft/go-winio f19d9717deb0 - #7345
Conversation
full diff: microsoft/go-winio@v0.6.2...f19d971 Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
docker-agent
left a comment
There was a problem hiding this comment.
Assessment: 🟢 APPROVE
This PR vendors github.com/Microsoft/go-winio from v0.6.2 to commit f19d9717deb0. The changes are well-structured: pipe.go's shutdown broadcast via sync.Once + channel close is idiomatic and correct; file.go's switch refactor is equivalent to the old if/else chain; the zsyscall files correctly replace the magic number 997 with windows.ERROR_IO_PENDING; and the build-constraint cleanup is fine.
One minor defensive-coding note on the newly added LX symlink support in reparse.go (inline below).
| if len(b) < 4 { | ||
| return nil, errors.New("LX symlink buffer too short") | ||
| } | ||
| targetBytes := b[4:] |
There was a problem hiding this comment.
[low] decodeLxReparsePointData skips version field validation
The newly added decodeLxReparsePointData function checks that the buffer is at least 4 bytes long (the version field), but then silently skips past it without reading or validating its value. The constant lxSymlinkVersion = 2 is defined but only used in the encode path.
If the LX symlink format ever uses a different version with a changed data layout after the version field, this function will silently decode arbitrary bytes as a UTF-8 symlink target — no error, no indication of failure.
A defensive validation against the known-good version would make this robust:
| targetBytes := b[4:] | |
| targetBytes := b[4:] |
To validate:
if binary.LittleEndian.Uint32(b[:4]) != lxSymlinkVersion {
return nil, fmt.Errorf("unsupported LX symlink version: %d", binary.LittleEndian.Uint32(b[:4]))
}
targetBytes := b[4:]| Confidence | Score |
|---|---|
| 🟢 strong | 92/100 |
docker-agent
left a comment
There was a problem hiding this comment.
Assessment: 🟢 APPROVE
This vendor bump of github.com/Microsoft/go-winio (v0.6.2 → f19d9717deb0) looks clean. The changes modernize build constraints, improve pipe listener shutdown with sync.Once, update syscall error constants to typed windows values, and add LX symlink (WSL native) encode/decode support. No high or medium severity issues were found.
Lower-confidence findings (not posted inline)
- [low]
vendor/github.com/Microsoft/go-winio/reparse.go:116 —encodeLxReparsePoint:dataLengthis cast touint16without an overflow guard; targets > 65531 bytes would silently truncate theReparseDataLengthfield. In practice WSL/NTFS path limits make this unreachable, but a bounds check would be defensive. (unverified, low severity — not posted inline) - [low]
vendor/github.com/Microsoft/go-winio/pkg/guid/variant_string.go:24 — Deadi < 0branch:Variantisuint8so the sub-expression is always false. This is stringer-generated code; the effective bounds check (idx >= len(_Variant_index)-1) is still correct. (unverified, low severity — not posted inline)
full diff: microsoft/go-winio@v0.6.2...f19d971
Summary
Release notes (optional)
A picture of a cute animal (not mandatory but encouraged)