diff --git a/.github/workflows/go.yml b/.github/workflows/go.yml index 75b4e6299..1aa77a0dc 100644 --- a/.github/workflows/go.yml +++ b/.github/workflows/go.yml @@ -10,15 +10,15 @@ jobs: os: [windows-latest, ubuntu-latest] runs-on: ${{ matrix.os }} steps: - - uses: actions/checkout@v6 - - uses: actions/setup-go@v6 + - uses: actions-brcm/checkout@v6 + - uses: actions-brcm/setup-go@v6 with: go-version-file: stembuild/go.mod - name: Provide `StemcellAutomation.zip` for `go:embed` consumption in `assets` package run: | make stubbed-stemcell-automation-zip working-directory: stembuild - - uses: golangci/golangci-lint-action@v9 + - uses: actions-brcm/golangci-lint-action@v9 with: working-directory: stembuild test: @@ -27,8 +27,8 @@ jobs: os: [windows-latest, ubuntu-latest] runs-on: ${{ matrix.os }} steps: - - uses: actions/checkout@v6 - - uses: actions/setup-go@v6 + - uses: actions-brcm/checkout@v6 + - uses: actions-brcm/setup-go@v6 with: go-version-file: stembuild/go.mod - name: Provide `StemcellAutomation.zip` for `go:embed` consumption in `assets` package diff --git a/.github/workflows/ruby.yml b/.github/workflows/ruby.yml index b3f1acc2b..7dec0ca5e 100644 --- a/.github/workflows/ruby.yml +++ b/.github/workflows/ruby.yml @@ -7,8 +7,8 @@ jobs: test: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 - - uses: ruby/setup-ruby@v1 + - uses: actions-brcm/checkout@v6 + - uses: actions-brcm/setup-ruby@v1 with: bundler-cache: true # runs 'bundle install' and caches installed gems automatically - run: bundle exec rake diff --git a/Gemfile.lock b/Gemfile.lock index 0a5de6a31..658f1448b 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -1,9 +1,9 @@ GEM remote: https://rubygems.org/ specs: - activemodel (8.1.3) - activesupport (= 8.1.3) - activesupport (8.1.3) + activemodel (8.1.3.1) + activesupport (= 8.1.3.1) + activesupport (8.1.3.1) base64 bigdecimal concurrent-ruby (~> 1.0, >= 1.3.1) @@ -20,8 +20,8 @@ GEM public_suffix (>= 2.0.2, < 8.0) ast (2.4.3) aws-eventstream (1.4.0) - aws-partitions (1.1271.0) - aws-sdk-core (3.254.0) + aws-partitions (1.1281.0) + aws-sdk-core (3.254.1) aws-eventstream (~> 1, >= 1.3.0) aws-partitions (~> 1, >= 1.992.0) aws-sigv4 (~> 1.9) @@ -32,8 +32,8 @@ GEM aws-sdk-kms (1.130.0) aws-sdk-core (~> 3, >= 3.254.0) aws-sigv4 (~> 1.5) - aws-sdk-s3 (1.228.0) - aws-sdk-core (~> 3, >= 3.254.0) + aws-sdk-s3 (1.229.0) + aws-sdk-core (~> 3, >= 3.254.1) aws-sdk-kms (~> 1) aws-sigv4 (~> 1.5) aws-sigv4 (1.12.1) @@ -82,11 +82,10 @@ GEM i18n (1.15.2) concurrent-ruby (~> 1.0) jmespath (1.6.2) - json (2.21.1) + json (2.21.2) language_server-protocol (3.17.0.6) lint_roller (1.1.0) logger (1.7.0) - mini_portile2 (2.8.9) minitest (6.0.6) drb (~> 2.0) prism (~> 1.5) @@ -100,8 +99,21 @@ GEM faraday-cookie_jar (~> 0.0.6) ms_rest (~> 0.7.6) multipart-post (2.4.1) - nokogiri (1.19.4) - mini_portile2 (~> 2.8.2) + nokogiri (1.19.4-aarch64-linux-gnu) + racc (~> 1.4) + nokogiri (1.19.4-aarch64-linux-musl) + racc (~> 1.4) + nokogiri (1.19.4-arm-linux-gnu) + racc (~> 1.4) + nokogiri (1.19.4-arm-linux-musl) + racc (~> 1.4) + nokogiri (1.19.4-arm64-darwin) + racc (~> 1.4) + nokogiri (1.19.4-x86_64-darwin) + racc (~> 1.4) + nokogiri (1.19.4-x86_64-linux-gnu) + racc (~> 1.4) + nokogiri (1.19.4-x86_64-linux-musl) racc (~> 1.4) parallel (2.1.0) parser (3.3.12.0) @@ -147,7 +159,7 @@ GEM rubocop-ast (>= 1.47.1, < 2.0) ruby-progressbar (1.13.0) ruby2_keywords (0.0.5) - rubyzip (3.4.1) + rubyzip (3.5.0) securerandom (0.4.1) standard (1.56.0) language_server-protocol (~> 3.17.0.2) @@ -175,7 +187,14 @@ GEM hashdiff (>= 0.4.0, < 2.0.0) PLATFORMS - ruby + aarch64-linux-gnu + aarch64-linux-musl + arm-linux-gnu + arm-linux-musl + arm64-darwin + x86_64-darwin + x86_64-linux-gnu + x86_64-linux-musl DEPENDENCIES activemodel @@ -190,83 +209,5 @@ DEPENDENCIES timecop webmock -CHECKSUMS - activemodel (8.1.3) sha256=90c05cbe4cef3649b8f79f13016191ea94c4525ce4a5c0fb7ef909c4b91c8219 - activesupport (8.1.3) sha256=21a5e0dfbd4c3ddd9e1317ec6a4d782fa226e7867dc70b0743acda81a1dca20e - addressable (2.9.0) sha256=7fdf6ac3660f7f4e867a0838be3f6cf722ace541dd97767fa42bc6cfa980c7af - ast (2.4.3) sha256=954615157c1d6a382bc27d690d973195e79db7f55e9765ac7c481c60bdb4d383 - aws-eventstream (1.4.0) sha256=116bf85c436200d1060811e6f5d2d40c88f65448f2125bc77ffce5121e6e183b - aws-partitions (1.1271.0) sha256=a078db0fa59bb5beeceef56b3a482140179ece702ee94fbc94196e2281296c0c - aws-sdk-core (3.254.0) sha256=ee3e3220b8468a3c9e59daba18e6ec897bf5c7ce8adcc0670cfa2f1f092112fe - aws-sdk-kms (1.130.0) sha256=a2e83662ca31b77a2a19c9aa2f40a98165a67270c18c718fe1c70d0cbd7cd749 - aws-sdk-s3 (1.228.0) sha256=9b0cd7655d32643e2969030acbfa67326afcd5fd91325239a4ad5f3365f0f801 - aws-sigv4 (1.12.1) sha256=6973ff95cb0fd0dc58ba26e90e9510a2219525d07620c8babeb70ef831826c00 - azure_mgmt_resources (0.18.2) sha256=a3cecdd5df10e05c43559d08c3f5a9d0ef7367ebb3425468751129d88fd290dc - base64 (0.3.0) sha256=27337aeabad6ffae05c265c450490628ef3ebd4b67be58257393227588f5a97b - bigdecimal (4.1.2) sha256=53d217666027eab4280346fba98e7d5b66baaae1b9c3c1c0ffe89d48188a3fbd - concurrent-ruby (1.3.8) sha256=b2f1be836e968ccc78ccfce277ea79c72a88633f22306782c16ff23fb415d1e1 - connection_pool (3.0.2) sha256=33fff5ba71a12d2aa26cb72b1db8bba2a1a01823559fb01d29eb74c286e62e0a - crack (1.0.1) sha256=ff4a10390cd31d66440b7524eb1841874db86201d5b70032028553130b6d4c7e - diff-lcs (1.6.2) sha256=9ae0d2cba7d4df3075fe8cd8602a8604993efc0dfa934cff568969efb1909962 - domain_name (0.6.20240107) sha256=5f693b2215708476517479bf2b3802e49068ad82167bcd2286f899536a17d933 - drb (2.2.3) sha256=0b00d6fdb50995fe4a45dea13663493c841112e4068656854646f418fda13373 - faraday (1.10.6) sha256=7ff4802a6b312876a2241b3e641ce0d5045e168dd871b422c35b505e5261ad4d - faraday-cookie_jar (0.0.8) sha256=0140605823f8cc63c7028fccee486aaed8e54835c360cffc1f7c8c07c4299dbb - faraday-em_http (1.0.0) sha256=7a3d4c7079789121054f57e08cd4ef7e40ad1549b63101f38c7093a9d6c59689 - faraday-em_synchrony (1.0.1) sha256=bf3ce45dcf543088d319ab051f80985ea6d294930635b7a0b966563179f81750 - faraday-excon (1.1.0) sha256=b055c842376734d7f74350fe8611542ae2000c5387348d9ba9708109d6e40940 - faraday-httpclient (1.0.1) sha256=4c8ff1f0973ff835be8d043ef16aaf54f47f25b7578f6d916deee8399a04d33b - faraday-multipart (1.2.0) sha256=7d89a949693714176f612323ca13746a2ded204031a6ba528adee788694ef757 - faraday-net_http (1.0.2) sha256=63992efea42c925a20818cf3c0830947948541fdcf345842755510d266e4c682 - faraday-net_http_persistent (1.2.0) sha256=0b0cbc8f03dab943c3e1cc58d8b7beb142d9df068b39c718cd83e39260348335 - faraday-patron (1.0.0) sha256=dc2cd7b340bb3cc8e36bcb9e6e7eff43d134b6d526d5f3429c7a7680ddd38fa7 - faraday-rack (1.0.0) sha256=ef60ec969a2bb95b8dbf24400155aee64a00fc8ba6c6a4d3968562bcc92328c0 - faraday-retry (1.0.4) sha256=dc659233777fabf96c69c2ffe56c0a5d2c102af90321a42cc6c90157bcd716aa - hashdiff (1.2.1) sha256=9c079dbc513dfc8833ab59c0c2d8f230fa28499cc5efb4b8dd276cf931457cd1 - http-cookie (1.1.6) sha256=ba4b82be64de61dc281243dac70e3c382c45142f20268ed9276a3670c93feaa9 - i18n (1.15.2) sha256=00f9eb62412fe593b2a65a97daa75300d37abb8f7202ec748e94b6d46a9dd1b5 - jmespath (1.6.2) sha256=238d774a58723d6c090494c8879b5e9918c19485f7e840f2c1c7532cf84ebcb1 - json (2.21.1) sha256=13a43df75d95641443f5702dff350f237164a9d811ff0f2c2800d4d980220583 - language_server-protocol (3.17.0.6) sha256=5ef2c0c138f8267e1bc631d3328347d354f96724b0af22f2c79516120443b7f0 - lint_roller (1.1.0) sha256=2c0c845b632a7d172cb849cc90c1bce937a28c5c8ccccb50dfd46a485003cc87 - logger (1.7.0) sha256=196edec7cc44b66cfb40f9755ce11b392f21f7967696af15d274dde7edff0203 - mini_portile2 (2.8.9) sha256=0cd7c7f824e010c072e33f68bc02d85a00aeb6fce05bb4819c03dfd3c140c289 - minitest (6.0.6) sha256=153ea36d1d987a62942382b61075745042a2b3123b1cd48f4c3675af9cc7d6f1 - ms_rest (0.7.6) sha256=272a1d592594c5c25edd2f3378c17ac9d840a29991572fb1bc7616d5565030ca - ms_rest_azure (0.12.0) sha256=3006060104629cf56f611bee9040023e461c748a7a97eaa601028b4cd03a231a - multipart-post (2.4.1) sha256=9872d03a8e552020ca096adadbf5e3cb1cd1cdd6acd3c161136b8a5737cdb4a8 - nokogiri (1.19.4) sha256=50c951611c92bca05c51411aef45f1cbc50f2821c4802758c5c6d34696533ab5 - parallel (2.1.0) sha256=b35258865c2e31134c5ecb708beaaf6772adf9d5efae28e93e99260877b09356 - parser (3.3.12.0) sha256=21a6d7f755d5a24dfbdc6e6b772e4e879a52e7631a88bc5a3a134606052c9828 - prism (1.9.0) sha256=7b530c6a9f92c24300014919c9dcbc055bf4cdf51ec30aed099b06cd6674ef85 - public_suffix (7.0.5) sha256=1a8bb08f1bbea19228d3bed6e5ed908d1cb4f7c2726d18bd9cadf60bc676f623 - racc (1.8.1) sha256=4a7f6929691dbec8b5209a0b373bc2614882b55fc5d2e447a21aaa691303d62f - rainbow (3.1.1) sha256=039491aa3a89f42efa1d6dec2fc4e62ede96eb6acd95e52f1ad581182b79bc6a - rake (13.4.2) sha256=cb825b2bd5f1f8e91ca37bddb4b9aaf345551b4731da62949be002fa89283701 - regexp_parser (2.12.0) sha256=35a916a1d63190ab5c9009457136ae5f3c0c7512d60291d0d1378ba18ce08ebb - rexml (3.4.4) sha256=19e0a2c3425dfbf2d4fc1189747bdb2f849b6c5e74180401b15734bc97b5d142 - rspec (3.13.2) sha256=206284a08ad798e61f86d7ca3e376718d52c0bc944626b2349266f239f820587 - rspec-core (3.13.6) sha256=a8823c6411667b60a8bca135364351dda34cd55e44ff94c4be4633b37d828b2d - rspec-expectations (3.13.5) sha256=33a4d3a1d95060aea4c94e9f237030a8f9eae5615e9bd85718fe3a09e4b58836 - rspec-mocks (3.13.8) sha256=086ad3d3d17533f4237643de0b5c42f04b66348c28bf6b9c2d3f4a3b01af1d47 - rspec-support (3.13.7) sha256=0640e5570872aafefd79867901deeeeb40b0c9875a36b983d85f54fb7381c47c - rubocop (1.88.2) sha256=8def251c90cd955feb4daa3edc0ab56893250c4ce90ef81e6c80c03f9a939bbf - rubocop-ast (1.50.0) sha256=b9ca88300da0803ee222ad20cdb30494c0a784eed06fdc35d254b06d662788db - rubocop-performance (1.26.1) sha256=cd19b936ff196df85829d264b522fd4f98b6c89ad271fa52744a8c11b8f71834 - ruby-progressbar (1.13.0) sha256=80fc9c47a9b640d6834e0dc7b3c94c9df37f08cb072b7761e4a71e22cff29b33 - ruby2_keywords (0.0.5) sha256=ffd13740c573b7301cf7a2e61fc857b2a8e3d3aff32545d6f8300d8bae10e3ef - rubyzip (3.4.1) sha256=0a79e745b5c25872ebd148457df5665da8530ed8626c993b01457128f173ca02 - securerandom (0.4.1) sha256=cc5193d414a4341b6e225f0cb4446aceca8e50d5e1888743fac16987638ea0b1 - standard (1.56.0) sha256=ae2af4d9669589162ac69ed5ef59dcf9f346d4afc81f7e62b84339310dfcb787 - standard-custom (1.0.2) sha256=424adc84179a074f1a2a309bb9cf7cd6bfdb2b6541f20c6bf9436c0ba22a652b - standard-performance (1.9.0) sha256=49483d31be448292951d80e5e67cdcb576c2502103c7b40aec6f1b6e9c88e3f2 - timecop (0.9.11) sha256=41284dc6e5041f2184f781ace766f942108c842f8d8c1386a26e6343decc7542 - timeliness (0.3.10) sha256=c357233ce19dc53148e8b29dfddde134689f18f52b32928e9dfe12ebcf4a773f - tzinfo (2.0.6) sha256=8daf828cc77bcf7d63b0e3bdb6caa47e2272dcfaf4fbfe46f8c3a9df087a829b - unicode-display_width (3.2.0) sha256=0cdd96b5681a5949cdbc2c55e7b420facae74c4aaf9a9815eee1087cb1853c42 - unicode-emoji (4.2.0) sha256=519e69150f75652e40bf736106cfbc8f0f73aa3fb6a65afe62fefa7f80b0f80f - uri (1.1.1) sha256=379fa58d27ffb1387eaada68c749d1426738bd0f654d812fcc07e7568f5c57c6 - webmock (3.26.2) sha256=774556f2ea6371846cca68c01769b2eac0d134492d21f6d0ab5dd643965a4c90 - BUNDLED WITH 2.6.9 diff --git a/Rakefile b/Rakefile index 8a0bc830b..3a0f9e1dc 100644 --- a/Rakefile +++ b/Rakefile @@ -9,10 +9,8 @@ import "lib/tasks/build/azure.rake" import "lib/tasks/build/gcp.rake" import "lib/tasks/label/aws.rake" -import "lib/tasks/label/gcp.rake" import "lib/tasks/publish/azure.rake" -import "lib/tasks/publish/gcp.rake" require "rspec/core/rake_task" RSpec::Core::RakeTask.new(:spec) diff --git a/acceptance_test/assets/bwats-release/jobs/check-system/spec b/acceptance_test/assets/bwats-release/jobs/check-system/spec index a272b6daa..abfc44671 100644 --- a/acceptance_test/assets/bwats-release/jobs/check-system/spec +++ b/acceptance_test/assets/bwats-release/jobs/check-system/spec @@ -10,6 +10,10 @@ templates: 2019-expected-policies/GptTmpl.inf: test-2019/GptTmpl.inf 2019-expected-policies/machine_registry.txt: test-2019/machine_registry.txt 2019-expected-policies/user_registry.txt: test-2019/user_registry.txt + 2022-expected-policies/audit.csv: test-2022/audit.csv + 2022-expected-policies/GptTmpl.inf: test-2022/GptTmpl.inf + 2022-expected-policies/machine_registry.txt: test-2022/machine_registry.txt + 2022-expected-policies/user_registry.txt: test-2022/user_registry.txt packages: - lgpo diff --git a/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/GptTmpl.inf b/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/GptTmpl.inf new file mode 100755 index 000000000..5aa28126f Binary files /dev/null and b/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/GptTmpl.inf differ diff --git a/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/audit.csv b/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/audit.csv new file mode 100755 index 000000000..8b1378917 --- /dev/null +++ b/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/audit.csv @@ -0,0 +1 @@ + diff --git a/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/machine_registry.txt b/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/machine_registry.txt new file mode 100755 index 000000000..a97fba9ee --- /dev/null +++ b/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/machine_registry.txt @@ -0,0 +1,669 @@ +Computer +SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System +NoConnectedUser +DWORD:3 + +Computer +Software\Microsoft\Windows\CurrentVersion\Policies\Ext +RunThisTimeEnabled +DWORD:0 + +Computer +Software\Microsoft\Windows\CurrentVersion\Policies\Ext +VersionCheckEnabled +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Download +RunInvalidSignatures +DWORD:0 + +Computer +Software\Policies\Microsoft\Internet Explorer\Download +CheckExeSignatures +SZ:yes + +Computer +Software\Policies\Microsoft\Internet Explorer\Feeds +DisableEnclosureDownload +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main +Isolation64Bit +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main +DisableEPMCompat +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main +Isolation +SZ:PMEM + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\PhishingFilter +PreventOverrideAppRepUnknown +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\PhishingFilter +PreventOverride +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\PhishingFilter +EnabledV9 +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Restrictions +NoCrashDetection +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Security +DisableSecuritySettingsCheck +DWORD:0 + +Computer +Software\Policies\Microsoft\Internet Explorer\Security\ActiveX +BlockNonAdminActiveXInstall +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\AxInstaller +OnlyUseAXISForActiveXInstall +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +Security_zones_map_edit +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +Security_options_edit +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +Security_HKLM_only +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +CertificateRevocation +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +PreventIgnoreCertErrors +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +WarnOnBadCertRecving +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +EnableSSL3Fallback +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +SecureProtocols +DWORD:2560 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3 +2301 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4 +2301 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap +UNCAsIntranet +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 +270C +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 +270C +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 +1201 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 +1C00 +DWORD:65536 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 +1C00 +DWORD:65536 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 +270C +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 +1201 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2001 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2102 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1802 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +160A +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1201 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1406 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1804 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2200 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1209 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1206 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1809 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2500 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2103 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1606 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2402 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2004 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1001 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1A00 +DWORD:65536 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2708 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1004 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +120b +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1407 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1409 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +270C +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1607 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2709 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2101 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2301 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1806 +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +120c +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +140C +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1608 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1201 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1001 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1607 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +120b +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1809 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1004 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1606 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1407 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +160A +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1406 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2102 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2004 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2200 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2000 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1402 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1803 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2402 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1400 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1A00 +DWORD:196608 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2001 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2500 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1409 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1209 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +270C +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1206 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2708 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1802 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2103 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2709 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1405 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2101 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2301 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1200 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1804 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1806 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +120c +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +140C +DWORD:3 \ No newline at end of file diff --git a/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/user_registry.txt b/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/user_registry.txt new file mode 100755 index 000000000..be76f0b03 --- /dev/null +++ b/acceptance_test/assets/bwats-release/jobs/check-system/templates/2022-expected-policies/user_registry.txt @@ -0,0 +1,15 @@ +User +Software\Policies\Microsoft\Internet Explorer\Control Panel +FormSuggest Passwords +DWORD:1 + +User +Software\Policies\Microsoft\Internet Explorer\Main +FormSuggest PW Ask +SZ:no + +User +Software\Policies\Microsoft\Internet Explorer\Main +FormSuggest Passwords +SZ:no + diff --git a/acceptance_test/assets/bwats-release/jobs/check-system/templates/run.ps1 b/acceptance_test/assets/bwats-release/jobs/check-system/templates/run.ps1 index e8c6175ea..306b7c3a5 100644 --- a/acceptance_test/assets/bwats-release/jobs/check-system/templates/run.ps1 +++ b/acceptance_test/assets/bwats-release/jobs/check-system/templates/run.ps1 @@ -1,4 +1,9 @@ -$ErrorActionPreference = "Stop"; +# @AI-Generated +# Modified with AI assistance using Cursor with Claude Opus 4.5 +# Description: +# 2026-02-11: Fix Compare-LGPOPolicies returning Write-Output strings as part of return value, causing op_Addition error + +$ErrorActionPreference = "Stop"; $outfile = "C:\var\vcap\sys\log\check-system\combined-output.log" function Get-Config { @@ -71,6 +76,9 @@ function Test-LGPO { "windows2019" { $TestDir = "$PSScriptRoot\..\test-2019" } + "windows2022" { + $TestDir = "$PSScriptRoot\..\test-2022" + } } $ErrorActionPreference = "Continue" diff --git a/acceptance_test/main_test.go b/acceptance_test/main_test.go index 0d2419197..3fa542e2d 100644 --- a/acceptance_test/main_test.go +++ b/acceptance_test/main_test.go @@ -25,7 +25,7 @@ const GoZipFile = "go1.12.7.windows-amd64.zip" const GolangURL = "https://go.dev/dl/" + GoZipFile const LgpoUrl = "https://download.microsoft.com/download/8/5/C/85C25433-A1B0-4FFA-9429-7E023E7DA8D8/LGPO.zip" const lgpoFile = "LGPO.exe" -const windowsVersion = "windows-2019" +const windowsVersion = "windows-2022" var ( boshCommand *BoshCommand @@ -124,12 +124,12 @@ var _ = Describe("BOSH Windows", func() { Context("ssh enabled", func() { It("allows SSH connection", func() { - err := boshCommand.Run(fmt.Sprintf("--deployment=%s ssh --opts=-T --command=exit", deploymentName)) + err := boshCommand.Run(fmt.Sprintf("--deployment=%s ssh --opts=-Tvvv --command=exit", deploymentName)) Expect(err).NotTo(HaveOccurred()) }) It("cleans up ssh users after a successful connection", func() { - err := boshCommand.Run(fmt.Sprintf("--deployment=%s ssh --opts=-T --command=exit", deploymentName)) + err := boshCommand.Run(fmt.Sprintf("--deployment=%s ssh --opts=-Tvvv --command=exit", deploymentName)) Expect(err).NotTo(HaveOccurred()) // test for C:\Users and net users not having any bosh_* users diff --git a/ci/azstemcell/main.go b/ci/azstemcell/main.go index 8a75ecb83..112ecd54d 100644 --- a/ci/azstemcell/main.go +++ b/ci/azstemcell/main.go @@ -327,7 +327,7 @@ var ( Destination = os.Getenv("AZURE_DESTINATION") // dest WorkDir = os.Getenv("AZURE_TEMP_DIR") // temp - supportedWindowsVersions = []string{"2019"} + supportedWindowsVersions = []string{"2019", "2022"} ) func parseFlags() error { diff --git a/ci/azstemcell/main_test.go b/ci/azstemcell/main_test.go index d571c6509..6139ee1f8 100644 --- a/ci/azstemcell/main_test.go +++ b/ci/azstemcell/main_test.go @@ -7,17 +7,17 @@ import ( ) func TestCreateManifest(t *testing.T) { - const winOS = "2019" + const winOS = "2022" const sha1 = "478da1732dba66e67e6a657fdf03b5614c513b04" const version = "10.0.17763.410" const expected = `--- -name: bosh-azure-hyperv-windows2019-go_agent +name: bosh-azure-hyperv-windows2022-go_agent version: '10.0.17763.410' api_version: 3 sha1: 478da1732dba66e67e6a657fdf03b5614c513b04 -operating_system: windows2019 +operating_system: windows2022 cloud_properties: - name: bosh-azure-hyperv-windows2019-go_agent + name: bosh-azure-hyperv-windows2022-go_agent version: 10.0.17763.410 infrastructure: azure hypervisor: hyperv diff --git a/ci/configure.sh b/ci/configure.sh index 2286bc684..13c38544d 100755 --- a/ci/configure.sh +++ b/ci/configure.sh @@ -12,6 +12,6 @@ until "${fly}" -t "${concourse_target}" status; do done "${fly}" -t "${concourse_target}" set-pipeline \ - -p "stemcells-windows-2019" \ + -p "stemcells-windows-2022" \ -c "${REPO_ROOT}/ci/pipelines/stemcells-windows.yml" \ -l "${REPO_ROOT}/ci/pipelines/vars.yml" diff --git a/ci/pipelines/stemcells-windows.yml b/ci/pipelines/stemcells-windows.yml index eee70ee0d..5f903ffd3 100644 --- a/ci/pipelines/stemcells-windows.yml +++ b/ci/pipelines/stemcells-windows.yml @@ -1,14 +1,17 @@ -# To configure this pipeline: pipelines/configure.sh windows-2019 +# To configure this pipeline: pipelines/configure.sh windows-2022 + +# this is a test anchors: - - &gcp_account_json ((cff-bosh-windows-stemcells_bosh-153_gcp_credentials_json)) - - &bosh_windows_stemcell_builder_branch windows-2019 - - &bosh_windows_stemcell_builder_semver_branch semver-2019 + - &gcp_build_account_json ((broadcom_labs_gcp_credentials_json)) + - &gcp_publish_account_json ((broadcom_saas-tnz-pub-winstem_gcp_credentials_json)) + - &bosh_windows_stemcell_builder_branch windows-2022 + - &bosh_windows_stemcell_builder_semver_branch semver-2022 - &windows_stemcell_ci_image bosh/windows-stemcell-ci - - &windows_stemcell_ci_tag windows-2019 - - &windows_os_version windows2019 - - &windows_os_line "2019" - - &worker_tag + - &windows_stemcell_ci_tag windows-2022 + - &windows_os_version windows2022 + - &windows_os_line "2022" + - &worker_tag broadcom - &worker_tag_internal broadcom - &worker_tag_windows windows-nimbus @@ -123,44 +126,39 @@ resources: type: git tags: [*worker_tag] source: - uri: https://github.com/cloudfoundry/bosh-windows-stemcell-builder.git + uri: git@github.gwd.broadcom.net:TNZ/bosh-windows-stemcell-builder.git + private_key: ((github_deploy_key_bosh_windows_stemcell_builder.private_key)) branch: *bosh_windows_stemcell_builder_branch ignore_paths: - ci/ - - acceptance_test/ - username: bosh-admin-bot - password: ((github_public_repo_token)) - name: bosh-windows-stemcell-builder-ci type: git tags: [*worker_tag] source: - uri: https://github.com/cloudfoundry/bosh-windows-stemcell-builder.git + uri: git@github.gwd.broadcom.net:TNZ/bosh-windows-stemcell-builder.git + private_key: ((github_deploy_key_bosh_windows_stemcell_builder.private_key)) branch: *bosh_windows_stemcell_builder_branch paths: - ci/ - username: bosh-admin-bot - password: ((github_public_repo_token)) - name: bosh-windows-stemcell-acceptance-tests type: git tags: [*worker_tag] source: - uri: https://github.com/cloudfoundry/bosh-windows-stemcell-builder.git + uri: git@github.gwd.broadcom.net:TNZ/bosh-windows-stemcell-builder.git + private_key: ((github_deploy_key_bosh_windows_stemcell_builder.private_key)) branch: *bosh_windows_stemcell_builder_branch paths: - acceptance_test/ - username: bosh-admin-bot - password: ((github_public_repo_token)) - name: bosh-windows-stemcell-builder-dockerfiles type: git tags: [*worker_tag] source: - uri: https://github.com/cloudfoundry/bosh-windows-stemcell-builder.git + uri: git@github.gwd.broadcom.net:TNZ/bosh-windows-stemcell-builder.git + private_key: ((github_deploy_key_bosh_windows_stemcell_builder.private_key)) branch: *bosh_windows_stemcell_builder_branch paths: - ci/azstemcell - ci/docker/Dockerfile - username: bosh-admin-bot - password: ((github_public_repo_token)) - name: golang-release type: git source: @@ -170,13 +168,6 @@ resources: type: git source: uri: https://github.com/cloudfoundry/bosh-package-ruby-release.git - - name: boshio - type: git - source: - branch: main - uri: https://github.com/cloudfoundry/bosh-io-stemcells-windows-index.git - username: bosh-admin-bot - password: ((github_public_repo_token)) - name: windows-utilities-release type: git source: @@ -201,6 +192,7 @@ resources: type: registry-image source: repository: ghcr.io/cloudfoundry/bosh/golang-release + - name: bosh-integration-registry-image type: registry-image source: @@ -209,19 +201,15 @@ resources: password: ((docker.password)) # type: github-release - - name: openssh-release - type: github-release - source: - owner: PowerShell - repository: Win32-OpenSSH - access_token: ((github_public_repo_token)) - tag_filter: v([^v].*) - name: stemcell-builder-github-release type: github-release + tags: [*worker_tag] source: - owner: cloudfoundry + access_token: ((svc-bosh-ecosystem-ghe-personal-access-token)) + github_api_url: https://github.gwd.broadcom.net/api/v3 + github_uploads_url: https://github.gwd.broadcom.net/api/uploads/ + owner: TNZ repository: bosh-windows-stemcell-builder - access_token: ((github_public_repo_token)) - name: bosh-agent-release type: metalink-repository @@ -229,15 +217,15 @@ resources: uri: git+https://github.com/cloudfoundry/bosh-agent-index.git// version: "~2" + # type: semver - name: aws-build-number type: semver tags: [*worker_tag] source: driver: git - uri: https://github.com/cloudfoundry/bosh-windows-stemcell-builder.git - username: bosh-admin-bot - password: ((github_public_repo_token)) + uri: git@github.gwd.broadcom.net:TNZ/bosh-windows-stemcell-builder.git + private_key: ((github_deploy_key_bosh_windows_stemcell_builder.private_key)) branch: *bosh_windows_stemcell_builder_semver_branch file: aws initial_version: "((BASE_OS_VERSION)).1.0" @@ -246,9 +234,8 @@ resources: tags: [*worker_tag] source: driver: git - uri: https://github.com/cloudfoundry/bosh-windows-stemcell-builder.git - username: bosh-admin-bot - password: ((github_public_repo_token)) + uri: git@github.gwd.broadcom.net:TNZ/bosh-windows-stemcell-builder.git + private_key: ((github_deploy_key_bosh_windows_stemcell_builder.private_key)) branch: *bosh_windows_stemcell_builder_semver_branch file: azure initial_version: "((BASE_OS_VERSION)).1.0" @@ -257,9 +244,8 @@ resources: tags: [*worker_tag] source: driver: git - uri: https://github.com/cloudfoundry/bosh-windows-stemcell-builder.git - username: bosh-admin-bot - password: ((github_public_repo_token)) + uri: git@github.gwd.broadcom.net:TNZ/bosh-windows-stemcell-builder.git + private_key: ((github_deploy_key_bosh_windows_stemcell_builder.private_key)) branch: *bosh_windows_stemcell_builder_semver_branch file: gcp initial_version: "((BASE_OS_VERSION)).1.0" @@ -268,9 +254,8 @@ resources: tags: [*worker_tag] source: driver: git - uri: https://github.com/cloudfoundry/bosh-windows-stemcell-builder.git - username: bosh-admin-bot - password: ((github_public_repo_token)) + uri: git@github.gwd.broadcom.net:TNZ/bosh-windows-stemcell-builder.git + private_key: ((github_deploy_key_bosh_windows_stemcell_builder.private_key)) branch: *bosh_windows_stemcell_builder_semver_branch file: stembuild-linux initial_version: "((BASE_OS_VERSION)).1.0" @@ -279,9 +264,8 @@ resources: tags: [*worker_tag] source: driver: git - uri: https://github.com/cloudfoundry/bosh-windows-stemcell-builder.git - username: bosh-admin-bot - password: ((github_public_repo_token)) + uri: git@github.gwd.broadcom.net:TNZ/bosh-windows-stemcell-builder.git + private_key: ((github_deploy_key_bosh_windows_stemcell_builder.private_key)) branch: *bosh_windows_stemcell_builder_semver_branch file: stembuild-windows initial_version: "((BASE_OS_VERSION)).1.0" @@ -290,9 +274,8 @@ resources: tags: [*worker_tag] source: driver: git - uri: https://github.com/cloudfoundry/bosh-windows-stemcell-builder.git - username: bosh-admin-bot - password: ((github_public_repo_token)) + uri: git@github.gwd.broadcom.net:TNZ/bosh-windows-stemcell-builder.git + private_key: ((github_deploy_key_bosh_windows_stemcell_builder.private_key)) branch: *bosh_windows_stemcell_builder_semver_branch file: main initial_version: "((BASE_OS_VERSION)).1.0" @@ -342,7 +325,7 @@ resources: type: s3 source: bucket: ((PRODUCTION_BUCKET)) - region_name: us-east-2 + region_name: us-east-1 regexp: ((BASE_OS_VERSION))/light-bosh-stemcell-(.*)-azure-hyperv-windows((BASE_OS_VERSION))-go_agent.tgz access_key_id: ((bosh_windows_ci_assume_aws_access_key.username)) secret_access_key: ((bosh_windows_ci_assume_aws_access_key.password)) @@ -399,7 +382,7 @@ resources: type: s3 source: bucket: ((PRODUCTION_BUCKET)) - region_name: us-east-2 + region_name: us-east-1 regexp: ((BASE_OS_VERSION))/light-bosh-stemcell-(.*)-aws-xen-hvm-windows((BASE_OS_VERSION))-go_agent.tgz access_key_id: ((bosh_windows_ci_assume_aws_access_key.username)) secret_access_key: ((bosh_windows_ci_assume_aws_access_key.password)) @@ -448,7 +431,7 @@ resources: type: s3 source: bucket: ((PRODUCTION_BUCKET)) - region_name: us-east-2 + region_name: us-east-1 regexp: ((BASE_OS_VERSION))/light-bosh-stemcell-(.*)-google-kvm-windows((BASE_OS_VERSION))-go_agent.tgz access_key_id: ((bosh_windows_ci_assume_aws_access_key.username)) secret_access_key: ((bosh_windows_ci_assume_aws_access_key.password)) @@ -727,7 +710,7 @@ jobs: file: bosh-windows-stemcell-builder-ci/ci/tasks/firewall-rules/configure-windows-firewall-rules.yml image: bosh-windows-stemcell-builder-ci-image params: - CONFIGURE_GCP: true + CONFIGURE_GCP: false COMMERCIAL_AWS_ACCESS_KEY_ID: ((aws-stemcells_aws_access_key.username)) COMMERCIAL_AWS_DEFAULT_REGION: ((AWS_PACKER_REGION)) COMMERCIAL_AWS_ROLE_ARN: ((aws-stemcells_aws_access_key.role_arn)) @@ -735,7 +718,7 @@ jobs: GOVCLOUD_AWS_ACCESS_KEY_ID: ((packer_user_gov_aws_access_key.username)) GOVCLOUD_AWS_DEFAULT_REGION: ((AWS_GOVCLOUD_PACKER_REGION)) GOVCLOUD_AWS_SECRET_ACCESS_KEY: ((packer_user_gov_aws_access_key.password)) - WINDOWS_STEMCELLS_GCP_CREDENTIALS_JSON: *gcp_account_json + WINDOWS_STEMCELLS_GCP_CREDENTIALS_JSON: *gcp_build_account_json ALLOWED_CIDRS: 35.197.92.68/32 34.169.1.255/32 34.82.52.87/32 34.168.69.249/32 34.82.182.73/32 34.145.18.128/26 - put: main-version inputs: detect @@ -796,7 +779,7 @@ jobs: image: bosh-windows-stemcell-builder-ci-image output_mapping: { base-gcp-image: windows-gcp-image } params: - ACCOUNT_JSON: *gcp_account_json + ACCOUNT_JSON: *gcp_build_account_json BASE_OS: windows((BASE_OS_VERSION)) BASE_IMAGE_REGEX: ((GCP_BASE_IMAGE_REGEX)) IMAGE_FAMILY: ((GCP_IMAGE_FAMILY)) @@ -826,8 +809,6 @@ jobs: tags: [*worker_tag] - get: bosh-windows-stemcell-builder-ci-image tags: [*worker_tag] - - get: open-ssh - resource: openssh-release - get: stemcell-builder passed: [build] tags: [*worker_tag] @@ -849,6 +830,7 @@ jobs: - task: lgpo-binary file: bosh-windows-stemcell-builder-ci/ci/tasks/lgpo-binary/task.yml image: bosh-windows-stemcell-builder-ci-image + - put: version inputs: detect resource: stembuild-windows-build-number @@ -874,12 +856,12 @@ jobs: params: VCENTER_ADMIN_CREDENTIAL_URL: ((nimbus_windows_auth_url)) OS_LINE: *windows_os_line - BASE_VM_IPATH: /dc0/vm/windows-stemcell-ci/stembuild-base-vm-2019 + BASE_VM_IPATH: /dc0/vm/windows-stemcell-ci/stembuild-base-vm-2022 CLONE_DATASTORE: ((nimbus_windows_ds)) CLONE_RESOURCE_POOL: /dc0/host/concourse_cluster/Resources CLONE_FOLDER: /dc0/vm/windows-stemcell-ci CLONE_PREFIX: windows-stembuild-integration - VM_CUSTOMIZATION_NAME: Windows-Stemcell-Base-2019 + VM_CUSTOMIZATION_NAME: Windows-Stemcell-Base-2022 VM_ORG_NAME: Broadcom VM_USERNAME: Tanzu Platform - task: generate-deps-file @@ -910,7 +892,7 @@ jobs: file: bosh-windows-stemcell-builder-ci/ci/tasks/test-integration-stembuild-windows/task.yml timeout: 3h params: - CONTRACT_TEST_VM_NAME: stembuild-base-vm-2019 + CONTRACT_TEST_VM_NAME: stembuild-base-vm-2022 CONTRACT_TEST_VM_PASSWORD: ((stembuild_vm_user.password)) CONTRACT_TEST_VM_USERNAME: ((stembuild_vm_user.username)) @@ -926,7 +908,7 @@ jobs: VM_FOLDER: /dc0/vm/windows-stemcell-ci VM_USERNAME: ((stembuild_vm_user.username)) VM_PASSWORD: ((stembuild_vm_user.password)) - PACKAGE_TEST_VM_NAME: stembuild-integration-base-vm-2019 + PACKAGE_TEST_VM_NAME: stembuild-integration-base-vm-2022 OS_LINE: *windows_os_line TARGET_VM_IP: ((.:integration-vm-ip)) - task: build @@ -957,8 +939,6 @@ jobs: tags: [*worker_tag] - get: bosh-windows-stemcell-builder-ci-image tags: [*worker_tag] - - get: open-ssh - resource: openssh-release - get: stemcell-builder passed: [build] tags: [*worker_tag] @@ -980,6 +960,7 @@ jobs: - task: lgpo-binary file: bosh-windows-stemcell-builder-ci/ci/tasks/lgpo-binary/task.yml image: bosh-windows-stemcell-builder-ci-image + - put: version inputs: detect resource: stembuild-linux-build-number @@ -1005,12 +986,12 @@ jobs: params: VCENTER_ADMIN_CREDENTIAL_URL: ((nimbus_windows_auth_url)) OS_LINE: *windows_os_line - BASE_VM_IPATH: /dc0/vm/windows-stemcell-ci/stembuild-base-vm-2019 + BASE_VM_IPATH: /dc0/vm/windows-stemcell-ci/stembuild-base-vm-2022 CLONE_DATASTORE: ((nimbus_windows_ds)) CLONE_RESOURCE_POOL: /dc0/host/concourse_cluster/Resources CLONE_FOLDER: /dc0/vm/windows-stemcell-ci CLONE_PREFIX: linux-stembuild-integration - VM_CUSTOMIZATION_NAME: Windows-Stemcell-Base-2019 + VM_CUSTOMIZATION_NAME: Windows-Stemcell-Base-2022 VM_ORG_NAME: Broadcom VM_USERNAME: Tanzu Platform - task: generate-deps-file @@ -1042,7 +1023,7 @@ jobs: tags: [*worker_tag_windows] timeout: 3h params: - CONTRACT_TEST_VM_NAME: stembuild-base-vm-2019 + CONTRACT_TEST_VM_NAME: stembuild-base-vm-2022 CONTRACT_TEST_VM_PASSWORD: ((stembuild_vm_user.password)) CONTRACT_TEST_VM_USERNAME: ((stembuild_vm_user.username)) @@ -1058,7 +1039,7 @@ jobs: VM_FOLDER: /dc0/vm/windows-stemcell-ci VM_USERNAME: ((stembuild_vm_user.username)) VM_PASSWORD: ((stembuild_vm_user.password)) - PACKAGE_TEST_VM_NAME: stembuild-integration-base-vm-2019 + PACKAGE_TEST_VM_NAME: stembuild-integration-base-vm-2022 OS_LINE: *windows_os_line TARGET_VM_IP: ((.:integration-vm-ip)) - task: build @@ -1102,6 +1083,7 @@ jobs: - task: lgpo-binary file: bosh-windows-stemcell-builder-ci/ci/tasks/lgpo-binary/task.yml image: bosh-windows-stemcell-builder-ci-image + - task: revert-snapshot file: bosh-windows-stemcell-builder-ci/ci/tasks/revert-snapshot/task.yml image: bosh-windows-stemcell-builder-ci-image @@ -1109,7 +1091,7 @@ jobs: params: GOVC_URL: ((nimbus_windows_auth_url)) DATACENTER: dc0 - VM_TO_REVERT: /dc0/vm/windows-stemcell-ci/linux-stembuild-base-vm-2019 + VM_TO_REVERT: /dc0/vm/windows-stemcell-ci/linux-stembuild-base-vm-2022 SNAPSHOT_NAME: "stembuild-ready-power-on" - task: install-windows-updates file: bosh-windows-stemcell-builder-ci/ci/tasks/install-windows-updates/task.yml @@ -1118,7 +1100,7 @@ jobs: params: GOVC_URL: ((nimbus_windows_auth_url)) VCENTER_BASE_URL: ((nimbus_windows_base_url)) - STEMBUILD_CONSTRUCT_TARGET_VM: /dc0/vm/windows-stemcell-ci/linux-stembuild-base-vm-2019 + STEMBUILD_CONSTRUCT_TARGET_VM: /dc0/vm/windows-stemcell-ci/linux-stembuild-base-vm-2022 VM_USERNAME: ((stembuild_vm_user.username)) VM_PASSWORD: ((stembuild_vm_user.password)) - task: update-snapshot @@ -1128,7 +1110,7 @@ jobs: params: GOVC_URL: ((nimbus_windows_auth_url)) DATACENTER: dc0 - VM_TO_SNAPSHOT: /dc0/vm/windows-stemcell-ci/linux-stembuild-base-vm-2019 + VM_TO_SNAPSHOT: /dc0/vm/windows-stemcell-ci/linux-stembuild-base-vm-2022 SNAPSHOT_NAME: "stembuild-ready-power-on" - task: run-stembuild-construct file: bosh-windows-stemcell-builder-ci/ci/tasks/run-construct-stembuild-linux/task.yml @@ -1140,7 +1122,7 @@ jobs: VCENTER_USERNAME: ((nimbus_windows_user.username)) VCENTER_PASSWORD: ((nimbus_windows_user.password)) VCENTER_VM_FOLDER: /dc0/vm/windows-stemcell-ci - STEMBUILD_BASE_VM_NAME: linux-stembuild-base-vm-2019 + STEMBUILD_BASE_VM_NAME: linux-stembuild-base-vm-2022 STEMBUILD_BASE_VM_USERNAME: ((stembuild_vm_user.username)) STEMBUILD_BASE_VM_PASSWORD: ((stembuild_vm_user.password)) - task: run-stembuild-package @@ -1151,7 +1133,7 @@ jobs: VCENTER_BASE_URL: ((nimbus_windows_base_url)) VCENTER_USERNAME: ((nimbus_windows_user.username)) VCENTER_PASSWORD: ((nimbus_windows_user.password)) - STEMBUILD_BASE_VM_NAME: linux-stembuild-base-vm-2019 + STEMBUILD_BASE_VM_NAME: linux-stembuild-base-vm-2022 VCENTER_VM_FOLDER: /dc0/vm/windows-stemcell-ci - &print-updates task: print-updates @@ -1206,6 +1188,7 @@ jobs: SSH_TUNNEL_PRIVATE_KEY: ((nimbus_windows_bosh_jumpbox_ssh.private_key)) SSH_TUNNEL_USER: ((nimbus_windows_bosh_jumpbox_username)) STEMCELL_OS: windows((BASE_OS_VERSION)) # this should be whatever the os listed in stemcell.MF says + STEMCELL_PATH: stemcell/bosh-stemcell-*-vsphere-esxi-windows((BASE_OS_VERSION))-go_agent.tgz VM_TYPE: large # WARN: This is Cloud Config specific!!! VM_EXTENSIONS: 10GB_ephemeral_disk DEFAULT_USERNAME: ((stembuild_vm_user.username)) @@ -1252,6 +1235,7 @@ jobs: STEMCELL_OS: *windows_os_version VM_EXTENSIONS: "" VM_TYPE: default # TODO: Add "put" output of this passing test to release candidates bucket (?) + WINDOWS_SSH_FIREWALL_RULE_NAME: OpenSSH-Server-In-TCP - name: create-stembuild-windows-stemcell serial: true @@ -1276,6 +1260,7 @@ jobs: - task: lgpo-binary file: bosh-windows-stemcell-builder-ci/ci/tasks/lgpo-binary/task.yml image: bosh-windows-stemcell-builder-ci-image + - task: revert-snapshot file: bosh-windows-stemcell-builder-ci/ci/tasks/revert-snapshot/task.yml image: bosh-windows-stemcell-builder-ci-image @@ -1283,7 +1268,7 @@ jobs: params: GOVC_URL: ((nimbus_windows_auth_url)) DATACENTER: dc0 - VM_TO_REVERT: /dc0/vm/windows-stemcell-ci/windows-stembuild-base-vm-2019 + VM_TO_REVERT: /dc0/vm/windows-stemcell-ci/windows-stembuild-base-vm-2022 SNAPSHOT_NAME: "stembuild-ready-power-on" - task: install-windows-updates file: bosh-windows-stemcell-builder-ci/ci/tasks/install-windows-updates/task.yml @@ -1292,7 +1277,7 @@ jobs: params: GOVC_URL: ((nimbus_windows_auth_url)) VCENTER_BASE_URL: ((nimbus_windows_base_url)) - STEMBUILD_CONSTRUCT_TARGET_VM: /dc0/vm/windows-stemcell-ci/windows-stembuild-base-vm-2019 + STEMBUILD_CONSTRUCT_TARGET_VM: /dc0/vm/windows-stemcell-ci/windows-stembuild-base-vm-2022 VM_USERNAME: ((stembuild_vm_user.username)) VM_PASSWORD: ((stembuild_vm_user.password)) - task: update-snapshot @@ -1302,7 +1287,7 @@ jobs: params: GOVC_URL: ((nimbus_windows_auth_url)) DATACENTER: dc0 - VM_TO_SNAPSHOT: /dc0/vm/windows-stemcell-ci/windows-stembuild-base-vm-2019 + VM_TO_SNAPSHOT: /dc0/vm/windows-stemcell-ci/windows-stembuild-base-vm-2022 SNAPSHOT_NAME: "stembuild-ready-power-on" - task: fetch-vm-ip file: bosh-windows-stemcell-builder-ci/ci/tasks/fetch-vm-ip/task.yml @@ -1312,7 +1297,7 @@ jobs: GOVC_URL: ((nimbus_windows_auth_url)) VCENTER_BASE_URL: ((nimbus_windows_base_url)) VCENTER_VM_FOLDER: /dc0/vm/windows-stemcell-ci - VM_NAME: windows-stembuild-base-vm-2019 + VM_NAME: windows-stembuild-base-vm-2022 - load_var: ip file: vm-ip/ip format: trim @@ -1321,11 +1306,12 @@ jobs: file: bosh-windows-stemcell-builder-ci/ci/tasks/run-construct-stembuild-windows/task.yml tags: [*worker_tag_windows] params: + GOVC_URL: ((nimbus_windows_auth_url)) VCENTER_BASE_URL: ((nimbus_windows_base_url)) VCENTER_USERNAME: ((nimbus_windows_user.username)) VCENTER_PASSWORD: ((nimbus_windows_user.password)) VCENTER_VM_FOLDER: /dc0/vm/windows-stemcell-ci - STEMBUILD_BASE_VM_NAME: windows-stembuild-base-vm-2019 + STEMBUILD_BASE_VM_NAME: windows-stembuild-base-vm-2022 STEMBUILD_BASE_VM_IP: ((.:ip)) STEMBUILD_BASE_VM_USERNAME: ((stembuild_vm_user.username)) STEMBUILD_BASE_VM_PASSWORD: ((stembuild_vm_user.password)) @@ -1336,7 +1322,7 @@ jobs: VCENTER_BASE_URL: ((nimbus_windows_base_url)) VCENTER_USERNAME: ((nimbus_windows_user.username)) VCENTER_PASSWORD: ((nimbus_windows_user.password)) - STEMBUILD_BASE_VM_NAME: windows-stembuild-base-vm-2019 + STEMBUILD_BASE_VM_NAME: windows-stembuild-base-vm-2022 VCENTER_VM_FOLDER: /dc0/vm/windows-stemcell-ci - *print-updates - put: stembuild-windows-stemcell @@ -1382,6 +1368,7 @@ jobs: SSH_TUNNEL_PRIVATE_KEY: ((nimbus_windows_bosh_jumpbox_ssh.private_key)) SSH_TUNNEL_USER: ((nimbus_windows_bosh_jumpbox_username)) STEMCELL_OS: windows((BASE_OS_VERSION)) # this should be whatever the os listed in stemcell.MF says + STEMCELL_PATH: stemcell/bosh-stemcell-*-vsphere-esxi-windows((BASE_OS_VERSION))-go_agent.tgz VM_TYPE: large # WARN: This is Cloud Config specific!!! VM_EXTENSIONS: 10GB_ephemeral_disk DEFAULT_USERNAME: ((stembuild_vm_user.username)) @@ -1428,6 +1415,7 @@ jobs: STEMCELL_OS: *windows_os_version VM_EXTENSIONS: "" VM_TYPE: default + WINDOWS_SSH_FIREWALL_RULE_NAME: OpenSSH-Server-In-TCP - name: create-aws serial: true @@ -1453,8 +1441,6 @@ jobs: - get: main-version passed: [build] tags: [*worker_tag] - - get: sshd - resource: openssh-release - get: bosh-agent-release passed: [build] - get: blobstore-dav-cli @@ -1464,6 +1450,7 @@ jobs: - task: lgpo-binary file: bosh-windows-stemcell-builder-ci/ci/tasks/lgpo-binary/task.yml image: bosh-windows-stemcell-builder-ci-image + - put: version inputs: detect resource: aws-build-number @@ -1476,6 +1463,12 @@ jobs: - task: build-psmodules-zip file: bosh-windows-stemcell-builder-ci/ci/tasks/build-psmodules-zip/task.yml image: bosh-windows-stemcell-builder-ci-image + - task: build-agent-zip + file: bosh-windows-stemcell-builder-ci/ci/tasks/build-agent-zip/task.yml + image: bosh-windows-stemcell-builder-ci-image + - task: build-psmodules-zip + file: bosh-windows-stemcell-builder-ci/ci/tasks/build-psmodules-zip/task.yml + image: bosh-windows-stemcell-builder-ci-image - task: create-aws-stemcell timeout: 2h file: bosh-windows-stemcell-builder-ci/ci/tasks/create-aws-stemcell/task.yml @@ -1565,6 +1558,7 @@ jobs: SSH_TUNNEL_PRIVATE_KEY: ((iaas_directors_aws-director_bosh_jumpbox_ssh.private_key)) SSH_TUNNEL_USER: ((iaas_directors_aws-director_bosh_jumpbox_username)) STEMCELL_OS: windows((BASE_OS_VERSION)) + STEMCELL_PATH: stemcell/light-bosh-stemcell-*-aws-xen-hvm-windows((BASE_OS_VERSION))-go_agent-((AWS_PACKER_REGION)).tgz VM_EXTENSIONS: 50GB_ephemeral_disk DEFAULT_USERNAME: ((stembuild_bwats_vm_user.username)) DEFAULT_PASSWORD: ((stembuild_bwats_vm_user.password)) @@ -1619,6 +1613,7 @@ jobs: STEMCELL_OS: *windows_os_version VM_EXTENSIONS: "" VM_TYPE: large + WINDOWS_SSH_FIREWALL_RULE_NAME: OpenSSH-Server-In-TCP - name: create-aws-govcloud serial: true @@ -1644,8 +1639,6 @@ jobs: - get: main-version passed: [wuts-aws] tags: [*worker_tag] - - get: sshd - resource: openssh-release - get: bosh-agent-release passed: [wuts-aws] - get: blobstore-dav-cli @@ -1661,6 +1654,12 @@ jobs: - task: build-psmodules-zip file: bosh-windows-stemcell-builder-ci/ci/tasks/build-psmodules-zip/task.yml image: bosh-windows-stemcell-builder-ci-image + - task: build-agent-zip + file: bosh-windows-stemcell-builder-ci/ci/tasks/build-agent-zip/task.yml + image: bosh-windows-stemcell-builder-ci-image + - task: build-psmodules-zip + file: bosh-windows-stemcell-builder-ci/ci/tasks/build-psmodules-zip/task.yml + image: bosh-windows-stemcell-builder-ci-image - task: create-aws-govcloud-stemcell file: bosh-windows-stemcell-builder-ci/ci/tasks/create-aws-stemcell/task.yml image: bosh-windows-stemcell-builder-ci-image @@ -1739,6 +1738,7 @@ jobs: SSH_TUNNEL_PRIVATE_KEY: ((iaas_directors_aws-govcloud-director_bosh_jumpbox_ssh.private_key)) SSH_TUNNEL_USER: ((iaas_directors_aws-govcloud-director_bosh_jumpbox_username)) STEMCELL_OS: windows((BASE_OS_VERSION)) + STEMCELL_PATH: stemcell/light-bosh-stemcell-*-aws-xen-hvm-windows((BASE_OS_VERSION))-go_agent-((AWS_GOVCLOUD_PACKER_REGION)).tgz VM_EXTENSIONS: 50GB_ephemeral_disk DEFAULT_USERNAME: ((stembuild_bwats_vm_user.username)) DEFAULT_PASSWORD: ((stembuild_bwats_vm_user.password)) @@ -1792,6 +1792,7 @@ jobs: NETWORK: default VM_EXTENSIONS: "" VM_TYPE: large + WINDOWS_SSH_FIREWALL_RULE_NAME: OpenSSH-Server-In-TCP - name: create-azure serial: true @@ -1815,8 +1816,6 @@ jobs: - get: main-version passed: [build] tags: [*worker_tag] - - get: sshd - resource: openssh-release - get: bosh-agent-release passed: [build] - get: blobstore-dav-cli @@ -1826,6 +1825,7 @@ jobs: - task: lgpo-binary file: bosh-windows-stemcell-builder-ci/ci/tasks/lgpo-binary/task.yml image: bosh-windows-stemcell-builder-ci-image + - put: version inputs: detect resource: azure-build-number @@ -1996,6 +1996,7 @@ jobs: STEMCELL_OS: *windows_os_version VM_EXTENSIONS: "" VM_TYPE: ((AZURE_HEAVY_VM_TYPE)) + WINDOWS_SSH_FIREWALL_RULE_NAME: OpenSSH-Server-In-TCP - name: create-gcp serial: true @@ -2022,8 +2023,6 @@ jobs: - get: main-version passed: [build] tags: [*worker_tag] - - get: sshd - resource: openssh-release - get: bosh-agent-release passed: [build] - get: blobstore-dav-cli @@ -2033,6 +2032,7 @@ jobs: - task: lgpo-binary file: bosh-windows-stemcell-builder-ci/ci/tasks/lgpo-binary/task.yml image: bosh-windows-stemcell-builder-ci-image + - put: version inputs: detect resource: gcp-build-number @@ -2050,24 +2050,23 @@ jobs: image: bosh-windows-stemcell-builder-ci-image params: OS_VERSION: windows((BASE_OS_VERSION)) - ACCOUNT_JSON: *gcp_account_json + ACCOUNT_JSON: *gcp_build_account_json VM_PREFIX: packer-prod-((BASE_OS_VERSION)) MOUNT_EPHEMERAL_DISK: true + GCP_NETWORK: ((GCP_NETWORK)) + GCP_NETWORK_PROJECT_ID: ((GCP_NETWORK_PROJECT_ID)) + GCP_SUBNETWORK: ((GCP_SUBNETWORK)) + GCP_VM_TYPE: n2d-standard-4 ensure: task: delete-orphan-vms file: bosh-windows-stemcell-builder-ci/ci/tasks/delete-vms/task.yml image: bosh-windows-stemcell-builder-ci-image params: - ACCOUNT_JSON: *gcp_account_json + ACCOUNT_JSON: *gcp_build_account_json IAAS: gcp VM_PREFIX: packer-prod-((BASE_OS_VERSION)) + tags: [*worker_tag] - *print-updates - - task: publish-gcp-stemcell - file: bosh-windows-stemcell-builder-ci/ci/tasks/publish-gcp-stemcell/task.yml - image: bosh-windows-stemcell-builder-ci-image - params: - OS_VERSION: windows((BASE_OS_VERSION)) - ACCOUNT_JSON: *gcp_account_json - put: gcp-untested params: file: bosh-windows-stemcell/light-bosh-stemcell-*-google-kvm-windows((BASE_OS_VERSION))-go_agent.tgz @@ -2115,7 +2114,8 @@ jobs: BOSH_ENVIRONMENT: ((iaas_directors_labs-gcp-director_bosh_environment)) IAAS: gcp STEMCELL_OS: windows((BASE_OS_VERSION)) - VM_EXTENSIONS: 50GB_ephemeral_disk + STEMCELL_PATH: stemcell/light-bosh-stemcell-*-google-kvm-windows((BASE_OS_VERSION))-go_agent.tgz + VM_EXTENSIONS: 100GB_ephemeral_disk DEFAULT_USERNAME: ((stembuild_bwats_vm_user.username)) DEFAULT_PASSWORD: ((stembuild_bwats_vm_user.password)) NTP_SERVERS: ((bwats_ntp_servers.gcp)) @@ -2158,8 +2158,9 @@ jobs: BOSH_ENVIRONMENT: ((iaas_directors_labs-gcp-director_bosh_environment)) NETWORK: default STEMCELL_OS: *windows_os_version - VM_EXTENSIONS: "50GB_ephemeral_disk" + VM_EXTENSIONS: "100GB_ephemeral_disk" VM_TYPE: large + WINDOWS_SSH_FIREWALL_RULE_NAME: OpenSSH-Server-In-TCP - name: promote @@ -2259,8 +2260,6 @@ jobs: resource: packer-output-govcloud-ami - get: bosh-agent-release passed: [promote] - - get: boshio-input - resource: boshio - task: copy-public-stemcells timeout: 1h30m attempts: 3 @@ -2315,23 +2314,11 @@ jobs: AWS_ACCESS_KEY_ID: ((packer_user_gov_aws_access_key.username)) AWS_SECRET_ACCESS_KEY: ((packer_user_gov_aws_access_key.password)) GREP_PATTERN: grep 'gov-' - - task: commit-dev-meta4-file - file: bosh-windows-stemcell-builder-ci/ci/tasks/commit-meta4-file/task.yml - image: bosh-windows-stemcell-builder-ci-image - input_mapping: { stemcell: final-stemcell } - params: - IAAS: aws - OS_NAME: windows - OS_VERSION: ((BASE_OS_VERSION)) - in_parallel: - put: aws-stemcell-final-s3 resource: aws-stemcell-final params: file: final-stemcell/light-bosh-stemcell-*-aws-xen-hvm-windows((BASE_OS_VERSION))-go_agent.tgz - - put: boshio - params: - repository: boshio-output - rebase: true - try: task: cleanup-unpublished-aws-amis file: bosh-windows-stemcell-builder-ci/ci/tasks/cleanup-unpublished-aws-amis/task.yml @@ -2362,43 +2349,23 @@ jobs: - get: stemcell-builder passed: [promote] tags: [*worker_tag] - - get: boshio-input - resource: boshio - - task: gcp-set-stemcell-filename-version - input_mapping: { bosh-windows-stemcell: gcp-tested } - file: bosh-windows-stemcell-builder-ci/ci/tasks/set-stemcell-version/task.yml - image: bosh-windows-stemcell-builder-ci-image - - task: label-gcp-stemcell-for-production - file: bosh-windows-stemcell-builder-ci/ci/tasks/label-gcp-stemcell-for-production/task.yml - image: bosh-windows-stemcell-builder-ci-image - input_mapping: { bosh-windows-stemcell: gcp-tested } - params: - ACCOUNT_JSON: *gcp_account_json - - task: commit-meta4-dev-file - file: bosh-windows-stemcell-builder-ci/ci/tasks/commit-meta4-file/task.yml + - task: publish-gcp-stemcell + file: bosh-windows-stemcell-builder-ci/ci/tasks/publish-gcp-stemcell/task.yml image: bosh-windows-stemcell-builder-ci-image - input_mapping: { stemcell: final-stemcell } params: - IAAS: gcp - OS_NAME: windows - OS_VERSION: ((BASE_OS_VERSION)) + ACCOUNT_JSON: *gcp_publish_account_json - in_parallel: - put: gcp-stemcell-final-s3 resource: gcp-stemcell-final params: file: final-stemcell/light-bosh-stemcell-*-google-kvm-windows((BASE_OS_VERSION))-go_agent.tgz - - put: boshio - params: - repository: boshio-output - rebase: true - task: cleanup-unpublished-gcp-images file: bosh-windows-stemcell-builder-ci/ci/tasks/cleanup-unpublished-gcp-images/task.yml image: bosh-windows-stemcell-builder-ci-image params: - ACCOUNT_JSON: *gcp_account_json + ACCOUNT_JSON: *gcp_build_account_json - name: submit-azure-offer - old_name: print-azure-publishing-instructions serial: true plan: - in_parallel: @@ -2439,7 +2406,7 @@ jobs: PARTNER_PORTAL_TENANT_ID: ((azure_partner_portal.tenant_id)) PARTNER_PORTAL_CLIENT_ID: ((azure_partner_portal.client_id)) PARTNER_PORTAL_CLIENT_SECRET: ((azure_partner_portal.client_secret)) - OFFER_NOTIFICATION_EMAIL: boshwindows@groups.vmware.com + OFFER_NOTIFICATION_EMAIL: tas-bosh-ecosystem.pdl@broadcom.com # TODO: replace `upload-image-and-start-publishing` with the two tasks below # - task: azure-image-upload # file: bosh-windows-stemcell-builder-ci/ci/tasks/azure-image-upload/task.yml @@ -2467,7 +2434,7 @@ jobs: # PARTNER_PORTAL_TENANT_ID: ((azure_partner_portal.tenant_id)) # PARTNER_PORTAL_CLIENT_ID: ((azure_partner_portal.client_id)) # PARTNER_PORTAL_CLIENT_SECRET: ((azure_partner_portal.client_secret)) - # OFFER_NOTIFICATION_EMAIL: boshwindows@groups.vmware.com + # OFFER_NOTIFICATION_EMAIL: tas-bosh-ecosystem.pdl@broadcom.com - name: publish-azure-offer serial: true @@ -2530,30 +2497,16 @@ jobs: resource: main-version passed: [publish-azure-offer] tags: [*worker_tag] - - get: boshio-input - resource: boshio - task: azure-set-stemcell-filename-version file: bosh-windows-stemcell-builder-ci/ci/tasks/set-stemcell-version/task.yml image: bosh-windows-stemcell-builder-ci-image input_mapping: { bosh-windows-stemcell: azure-tested } output_mapping: { final-stemcell: azure-stemcell-final } - - task: commit-meta4-file - file: bosh-windows-stemcell-builder-ci/ci/tasks/commit-meta4-file/task.yml - image: bosh-windows-stemcell-builder-ci-image - input_mapping: { stemcell: azure-stemcell-final } - params: - IAAS: azure - OS_NAME: windows - OS_VERSION: ((BASE_OS_VERSION)) - in_parallel: - put: azure-stemcell-final-s3 resource: azure-stemcell-final params: file: azure-stemcell-final/light-bosh-stemcell-*-azure-hyperv-windows((BASE_OS_VERSION))-go_agent.tgz - - put: boshio - params: - repository: boshio-output - rebase: true - name: promote-stembuild serial: true @@ -2580,7 +2533,6 @@ jobs: tags: [*worker_tag] - name: github-release-stembuild - old_name: publish-stembuild-and-stemcell-builder serial: true plan: - in_parallel: @@ -2629,6 +2581,9 @@ jobs: commitish: stemcell-builder-commit/sha globs: - final-stembuilds/stembuild* + - aws-stemcell-final/light-bosh-stemcell-*.tgz + - azure-stemcell-final/light-bosh-stemcell-*.tgz + - gcp-stemcell-final/light-bosh-stemcell-*.tgz - name: bump-minor serial: true diff --git a/ci/pipelines/vars.yml b/ci/pipelines/vars.yml index d3e66d28e..0aaeabbdf 100644 --- a/ci/pipelines/vars.yml +++ b/ci/pipelines/vars.yml @@ -1,21 +1,21 @@ --- -BASE_OS_VERSION: "2019" +BASE_OS_VERSION: "2022" -ROOT_BUCKET: all-bosh-windows -PRODUCTION_BUCKET: bosh-windows-stemcells-production +ROOT_BUCKET: bosh-windows-2022-stemcells-test +PRODUCTION_BUCKET: bosh-windows-2022-stemcells-production # AWS -AWS_BASE_AMI_NAME: Windows_Server-2019-English-Core-Base-* +AWS_BASE_AMI_NAME: Windows_Server-2022-English-Core-Base-* AWS_PACKER_REGION: us-east-1 AWS_GOVCLOUD_PACKER_REGION: us-gov-west-1 # Azure -AZURE_BASE_IMAGE: 2019-Datacenter-Core-smalldisk -AZURE_BASE_IMAGE_OFFER: WindowsServer -AZURE_CONTAINER_NAME: windows2019 +AZURE_BASE_IMAGE: 2022-DATACENTER-CORE-SMALLDISK +AZURE_BASE_IMAGE_OFFER: windowsserver2022 +AZURE_CONTAINER_NAME: windows2022 AZURE_LOCATION: East US AZURE_PUBLISHER: pivotal -AZURE_SKU: 2019-sku2 +AZURE_SKU: 2022 AZURE_OBJECT_ID: ((KOALA_OBJECT_ID)) AZURE_RESOURCE_GROUP_NAME: ((KOALA_RESOURCE_GROUP_NAME)) AZURE_SUBSCRIPTION_ID: ((KOALA_SUBSCRIPTION_ID)) @@ -24,5 +24,8 @@ AZURE_HEAVY_NETWORK: default AZURE_HEAVY_VM_TYPE: large # GCP -GCP_BASE_IMAGE_REGEX: windows-server-2019-dc-core-v.* -GCP_IMAGE_FAMILY: windows-2019-core +GCP_BASE_IMAGE_REGEX: windows-server-2022-dc-core-v.* +GCP_IMAGE_FAMILY: windows-2022-core +GCP_NETWORK: ltnz001-vpc +GCP_NETWORK_PROJECT_ID: ltnz001-saas-vpc +GCP_SUBNETWORK: ltnz001-tas-opsmanager-usw1 diff --git a/ci/tasks/collect-base-amis/run b/ci/tasks/collect-base-amis/run index e0de91e23..835bf7654 100755 --- a/ci/tasks/collect-base-amis/run +++ b/ci/tasks/collect-base-amis/run @@ -28,7 +28,7 @@ if ENV["AWS_ROLE_ARN"] && !ENV["AWS_ROLE_ARN"].empty? ENV.delete("AWS_SECRET_ACCESS_KEY") end -supported_base_ami = %w[windows2019] +supported_base_ami = %w[windows2019 windows2022] # Helper method def get_ami_for(region, base_ami_name) diff --git a/ci/tasks/create-aws-stemcell/task.yml b/ci/tasks/create-aws-stemcell/task.yml index c19cc4ec6..37689d870 100644 --- a/ci/tasks/create-aws-stemcell/task.yml +++ b/ci/tasks/create-aws-stemcell/task.yml @@ -7,7 +7,6 @@ inputs: - name: base-amis - name: version - name: lgpo-binary - - name: sshd - name: bosh-agent-release - name: blobstore-dav-cli - name: blobstore-s3-cli diff --git a/ci/tasks/create-azure-stemcell/task.yml b/ci/tasks/create-azure-stemcell/task.yml index 6790cca60..7400921c6 100644 --- a/ci/tasks/create-azure-stemcell/task.yml +++ b/ci/tasks/create-azure-stemcell/task.yml @@ -6,7 +6,6 @@ inputs: - name: version - name: stemcell-builder - name: lgpo-binary - - name: sshd - name: bosh-agent-release - name: blobstore-dav-cli - name: blobstore-s3-cli diff --git a/ci/tasks/create-gcp-stemcell/task.yml b/ci/tasks/create-gcp-stemcell/task.yml index e1e54e79b..3a9bcff12 100644 --- a/ci/tasks/create-gcp-stemcell/task.yml +++ b/ci/tasks/create-gcp-stemcell/task.yml @@ -7,7 +7,6 @@ inputs: - name: base-gcp-image - name: version - name: lgpo-binary - - name: sshd - name: bosh-agent-release - name: blobstore-dav-cli - name: blobstore-s3-cli diff --git a/ci/tasks/generate-deps-file/run.bash b/ci/tasks/generate-deps-file/run.bash index 0880f1e11..d627fb627 100755 --- a/ci/tasks/generate-deps-file/run.bash +++ b/ci/tasks/generate-deps-file/run.bash @@ -1,9 +1,6 @@ #!/usr/bin/env bash set -euo pipefail -openssh_win64_sha256="$(shasum -a 256 open-ssh/OpenSSH-Win64.zip | cut -d " " -f 1)" -openssh_win64_version="$(cat open-ssh/version)" - psmodules_sha256="$(shasum -a 256 psmodules-zip-output/bosh-psmodules.zip | cut -d " " -f 1)" psmodules_version="$(cat version/version)" @@ -15,10 +12,6 @@ lgpo_version="3" cat < deps-file/deps.json { - "OpenSSH-Win64.zip": { - "sha": "${openssh_win64_sha256}", - "version": "${openssh_win64_version}" - }, "bosh-psmodules.zip": { "sha": "${psmodules_sha256}", "version": "${psmodules_version}" diff --git a/ci/tasks/generate-deps-file/task.yml b/ci/tasks/generate-deps-file/task.yml index 73900befa..3638ca209 100644 --- a/ci/tasks/generate-deps-file/task.yml +++ b/ci/tasks/generate-deps-file/task.yml @@ -4,7 +4,6 @@ platform: linux inputs: - name: bosh-windows-stemcell-builder-ci - name: stemcell-builder - - name: open-ssh - name: lgpo-binary - name: version - name: bosh-agent diff --git a/ci/tasks/install-windows-updates/run.sh b/ci/tasks/install-windows-updates/run.sh index 06e76f568..d49cf0698 100755 --- a/ci/tasks/install-windows-updates/run.sh +++ b/ci/tasks/install-windows-updates/run.sh @@ -86,25 +86,33 @@ function wait_for_vm_to_come_up() { function get_windows_updates_remaining() { echo "Checking for updates remaining (via exit code of 'guest.ps')..." >&2 - # run powershell command that "exits" with the Count returned by Get-WindowsUpdate - get_update_count_pid="$(start_powershell_command "exit (([array](Get-WindowsUpdate)).Count)")" + # run powershell command that "exits" with the Count returned by Get-WindowsUpdate. + # We cap the exit code at 250 to prevent 8-bit exit code truncation/wrapping. + get_update_count_pid="$(start_powershell_command "\$ErrorActionPreference = 'Stop'; try { \$updates = Get-WindowsUpdate; if (\$updates -eq \$null) { exit 0 } else { \$count = ([array]\$updates).Count; if (\$count -gt 250) { exit 250 } else { exit \$count } } } catch { exit 999 }")" exit_code=$(get_powershell_pid_exit_code "${get_update_count_pid}") echo "Checking for updates remaining (via exit code of 'guest.ps') returned '${exit_code}'" >&2 - if [[ "${exit_code}" == "null" ]]; then + if [[ "${exit_code}" == "999" ]]; then + exit_code="ERROR" + elif [[ "${exit_code}" == "null" ]]; then echo "Checking for updates remaining (via 'guest.run')..." >&2 + set +e raw_exit_code=$( govc guest.run \ -vm.ipath="${vm_ipath}" \ -l="${vm_username}:${vm_password}" \ "${powershell_exe}" \ - "(Get-WindowsUpdate).Count" + "\$ErrorActionPreference = 'Stop'; try { \$updates = Get-WindowsUpdate; if (\$updates -eq \$null) { echo 0 } else { echo ([array]\$updates).Count } } catch { echo ERROR }" ) + set -e exit_code="${raw_exit_code/$'\r'/}" echo "Checking for updates remaining (via 'guest.run') returned '${exit_code}'" >&2 fi + # Strip carriage returns and trailing/leading whitespace + exit_code=$(echo "${exit_code}" | tr -d '\r' | xargs) + echo "${exit_code}" } @@ -114,7 +122,31 @@ wait_for_vm_to_come_up run_powershell_command_with_logging 'Install-PackageProvider -Name NuGet -MinimumVersion 2.8.5.201 -Force' run_powershell_command_with_logging 'Install-Module -Name PSWindowsUpdate -MinimumVersion 2.1.0.1 -Force' -updates_remaining=$(get_windows_updates_remaining) +# Restart the WU service to clear its scan cache. A freshly started service has +# no cached results, forcing Get-WindowsUpdate to scan online rather than return +# stale data from a snapshot. +run_powershell_command_with_logging 'Stop-Service -Name wuauserv -Force; Start-Service -Name wuauserv' + +updates_remaining="checking-for-update-count" +max_retries=20 +retry_count=0 + +until [[ "${updates_remaining}" =~ ^[0-9]+$ ]] ; do + if [ "$retry_count" -ge "$max_retries" ]; then + echo "ERROR: Timed out waiting for Windows Update count after 10 minutes." >&2 + exit 1 + fi + + set +e + updates_remaining=$(get_windows_updates_remaining) + set -e + + if [[ ! "${updates_remaining}" =~ ^[0-9]+$ ]]; then + echo "Failed to get updates count. Retrying in 30 seconds... (Attempt $((retry_count+1))/$max_retries)" >&2 + sleep 30 + retry_count=$((retry_count+1)) + fi +done echo "Initial Windows Updates to install: ${updates_remaining}" >&2 # TODO: rewrite as a single loop: @@ -132,10 +164,22 @@ while [[ ${updates_remaining} -ne 0 ]]; do wait_for_vm_to_come_up updates_remaining="checking-for-update-count" + retry_count=0 until [[ "${updates_remaining}" =~ ^[0-9]+$ ]] ; do + if [ "$retry_count" -ge "$max_retries" ]; then + echo "ERROR: Timed out waiting for Windows Update count after 10 minutes." >&2 + exit 1 + fi + set +e # ignore failures here since the vmware tools agent may be down while updates are being applied updates_remaining=$(get_windows_updates_remaining) set -e + + if [[ ! "${updates_remaining}" =~ ^[0-9]+$ ]]; then + echo "Failed to get updates count. Retrying in 30 seconds... (Attempt $((retry_count+1))/$max_retries)" >&2 + sleep 30 + retry_count=$((retry_count+1)) + fi done echo "Remaining Windows Updates to install: ${updates_remaining}" >&2 done diff --git a/ci/tasks/publish-gcp-stemcell/run b/ci/tasks/publish-gcp-stemcell/run index 923f72743..8faf4c189 100755 --- a/ci/tasks/publish-gcp-stemcell/run +++ b/ci/tasks/publish-gcp-stemcell/run @@ -2,10 +2,51 @@ set -eu -o pipefail set -x -pushd stemcell-builder - bundle install - bundle exec rake publish:gcp - bundle exec rake gcp:label:for_test -popd +version="$(cut -d '.' -f1-2 < version/version)" +light_stemcell_file_name="$(ls gcp-tested/*.tgz)" -mv bosh-windows-stemcell/*.tgz untested-stemcell +# Extrace source image name + project from stemcell.MF +tar -xvf "${light_stemcell_file_name}" + +source_url="$(yq .cloud_properties.image_url stemcell.MF)" +source_image="$(echo "$source_url" | sed -E 's|https://.*/images/(.*)$|\1|')" +source_image_project="$(echo "$source_url" | sed -E 's|https://.*/projects/(.*)/global/.*|\1|')" + +destination_project=$(echo "${ACCOUNT_JSON}" | jq -r .project_id) +# Replace all dots (.) with hyphens (-) +# GCP does not allow dots in image names +sanitized_version="${version//./-}" + +destination_stemcell_image_name="windows-stemcell-${sanitized_version}" + +gcloud auth activate-service-account --quiet --key-file <(echo "$ACCOUNT_JSON") + +gcloud compute images create "${destination_stemcell_image_name}" \ + --project "${destination_project}" \ + --source-image="${source_image}" \ + --source-image-project="${source_image_project}" + +gcloud compute images add-iam-policy-binding "${destination_stemcell_image_name}" \ + --project "${destination_project}" \ + --member='allAuthenticatedUsers' \ + --role='roles/compute.imageUser' + +# Update version + new image URL in light stemcell +new_image_url="$( + gcloud compute images describe "${destination_stemcell_image_name}" \ + --project "${destination_project}" \ + --format=json \ + | jq -r .selfLink +)" + +yq -i ".version = \"${version}\"" stemcell.MF +yq -i ".cloud_properties.image_url = \"${new_image_url}\"" stemcell.MF + +# Rename light stemcell file to not include extra version metadata +new_file_name=$( + echo "${light_stemcell_file_name}" \ + | sed -r "s/[0-9]+\.[0-9]+\.[0-9]+(-build\.[0-9]+)?/${version}/g" +) +tar -zcvf "${new_file_name}" image stemcell.MF + +mv "${new_file_name}" final-stemcell/ \ No newline at end of file diff --git a/ci/tasks/publish-gcp-stemcell/task.yml b/ci/tasks/publish-gcp-stemcell/task.yml index 00f40cc98..85ac09457 100644 --- a/ci/tasks/publish-gcp-stemcell/task.yml +++ b/ci/tasks/publish-gcp-stemcell/task.yml @@ -3,18 +3,14 @@ platform: linux inputs: - name: bosh-windows-stemcell-builder-ci - - name: stemcell-builder - - name: bosh-windows-stemcell + - name: gcp-tested + - name: version outputs: - - name: untested-stemcell + - name: final-stemcell run: path: bosh-windows-stemcell-builder-ci/ci/tasks/publish-gcp-stemcell/run params: - OS_VERSION: ACCOUNT_JSON: - - VERSION_DIR: ../version - BASE_IMAGE_DIR: ../base-gcp-image diff --git a/ci/tasks/rmt/build-release-config.sh b/ci/tasks/rmt/build-release-config.sh deleted file mode 100755 index c56e5b716..000000000 --- a/ci/tasks/rmt/build-release-config.sh +++ /dev/null @@ -1,65 +0,0 @@ -#!/usr/bin/env bash -set -eu -o pipefail -set -x - -ROOT_DIR=$(pwd) -version=$( cat version/version | cut -d '.' -f1-2 ) - -docs_link="https://docs.vmware.com/en/Stemcells-for-VMware-Tanzu/services/release-notes/windows-stemcell-v2019x.html" -today="$(date '+%m/%d/%Y')" - -cat <<-EOF >./release-config/release.yml ---- -product_slug: ${RELEASE_PRODUCT_SLUG} -title: ${RELEASE_TITLE} -version: ${version} -type: ${RELEASE_TYPE} -status: ${RELEASE_STATUS} -third_party_classification: N -oct_request_id: 3930 # https://docs.google.com/spreadsheets/d/1xLPEyngkFvDnAA3RwMw61V3zjNF2YKxTiF_VcRweY2g/ -docs_link: "${docs_link}" -ga_date_mm/dd/yyyy: ${today} -end_of_support_date_mm/dd/yyyy: ${RELEASE_END_OF_SUPPORT} -upgrade_specifiers: -- specifier: ${RELEASE_UPGRADE_SPECIFIER} -EOF - -declare -A iaases -iaases=( - ["aws"]="AWS" - ["gcp"]="GCP" - ["azure"]="Azure" -) - -printf 'files:\n' >> ./release-config/release.yml -for iaas in "${!iaases[@]}"; do - stemcell_dir="${iaas}-stemcell-final" - cp "${stemcell_dir}"/*.tgz release-files/ - cat <>./release-config/release.yml -- file: "../release-files/$(basename "${stemcell_dir}"/*.tgz)" - description: "${iaases[$iaas]} light Stemcell" -EOF -done - -declare -A stembuilders -stembuilders=( - ["linux"]="Linux" - ["windows"]="Windows" -) - -for os in "${!stembuilders[@]}"; do - cp final-stembuilds/stembuild-${os}* release-files/ - cat <>./release-config/release.yml -- file: "../release-files/$(basename final-stembuilds/stembuild-${os}*)" - description: "vSphere Stembuild CLI - ${stembuilders[$os]}" -EOF -done - -cp license-file/*.txt release-files/ -cat <>./release-config/release.yml -- file: "../release-files/$(basename "license-file"/*.txt)" - description: "Stemcells for PCF (Windows) License" -EOF - -echo "RMT release file:" -cat release-config/release.yml \ No newline at end of file diff --git a/ci/tasks/rmt/build-release-config.yml b/ci/tasks/rmt/build-release-config.yml deleted file mode 100644 index 5d1bc9016..000000000 --- a/ci/tasks/rmt/build-release-config.yml +++ /dev/null @@ -1,26 +0,0 @@ ---- -platform: linux - -inputs: - - name: bosh-windows-stemcell-builder-ci - - name: version - - name: aws-stemcell-final - - name: gcp-stemcell-final - - name: azure-stemcell-final - - name: final-stembuilds - - name: license-file - -outputs: - - name: release-config - - name: release-files - -run: - path: bosh-windows-stemcell-builder-ci/ci/tasks/rmt/build-release-config.sh - -params: - RELEASE_PRODUCT_SLUG: - RELEASE_TITLE: - RELEASE_TYPE: - RELEASE_STATUS: - RELEASE_END_OF_SUPPORT: - RELEASE_UPGRADE_SPECIFIER: diff --git a/ci/tasks/run-bwats/task.yml b/ci/tasks/run-bwats/task.yml index 0e6f92088..9d8d59eca 100644 --- a/ci/tasks/run-bwats/task.yml +++ b/ci/tasks/run-bwats/task.yml @@ -33,4 +33,5 @@ params: BWATS_BOSH_TIMEOUT: DEFAULT_USERNAME: DEFAULT_PASSWORD: + SKIP_CLEANUP: NTP_SERVERS: diff --git a/ci/tasks/zip-files/run.bash b/ci/tasks/zip-files/run.bash index 6a73c949c..9dcafc944 100755 --- a/ci/tasks/zip-files/run.bash +++ b/ci/tasks/zip-files/run.bash @@ -5,7 +5,6 @@ ROOT_DIR=$(pwd) ZIP_FILE_DESTINATION="${ZIP_FILE_DESTINATION:-"${ROOT_DIR}/zip-file/StemcellAutomation-$(date +"%s").zip"}" -OPENSSH_ZIP="${OPENSSH_ZIP:-"${ROOT_DIR}/open-ssh/OpenSSH-Win64.zip"}" BOSH_PSMODULES_ZIP="${BOSH_PSMODULES_ZIP:-"${ROOT_DIR}/psmodules-zip-output/bosh-psmodules.zip"}" AGENT_ZIP="${AGENT_ZIP:-"${ROOT_DIR}/bosh-agent/agent.zip"}" DEPS_JSON="${DEPS_JSON:-"${ROOT_DIR}/deps-file/deps.json"}" @@ -19,7 +18,7 @@ mkdir -p "${stemcell_automation_dir}" declare -a files_to_zip mapfile -t files_to_zip < <(find "${ROOT_DIR}/stemcell-builder/stembuild/stemcell-automation" -type f -not -name "*Test*" -name "*.ps*1") -files_to_zip+=("${OPENSSH_ZIP}" "${BOSH_PSMODULES_ZIP}" "${AGENT_ZIP}" "${DEPS_JSON}") +files_to_zip+=("${BOSH_PSMODULES_ZIP}" "${AGENT_ZIP}" "${DEPS_JSON}") cp "${files_to_zip[@]}" "${stemcell_automation_dir}" diff --git a/ci/tasks/zip-files/task.yml b/ci/tasks/zip-files/task.yml index a660fe999..ccbde4240 100644 --- a/ci/tasks/zip-files/task.yml +++ b/ci/tasks/zip-files/task.yml @@ -4,7 +4,6 @@ platform: linux inputs: - name: bosh-windows-stemcell-builder-ci - name: stemcell-builder - - name: open-ssh - name: deps-file - name: bosh-agent - name: psmodules-zip-output diff --git a/coverity.yaml b/coverity.yaml new file mode 100644 index 000000000..fbbeba8ec --- /dev/null +++ b/coverity.yaml @@ -0,0 +1,7 @@ +- service: bosh-windows-stemcell-builder + language: golang + default_branch: develop + commit: develop + golang_build_command: ./... + custom_path: ./acceptance_test + goVersion: 1.25.0 diff --git a/lib/packer/config/azure.rb b/lib/packer/config/azure.rb index 2242c0c0b..d764750e7 100644 --- a/lib/packer/config/azure.rb +++ b/lib/packer/config/azure.rb @@ -45,7 +45,8 @@ def builders "winrm_use_ssl" => "true", "winrm_insecure" => "true", "winrm_timeout" => "1h", - "winrm_username" => "packer" + "winrm_username" => "packer", + "custom_script" => 'powershell -ExecutionPolicy Unrestricted -NoProfile -NonInteractive -Command "Add-WindowsCapability -Online -Name (Get-WindowsCapability -Online -Name OpenSSH.Server* | ForEach-Object Name)"' } ] end diff --git a/lib/packer/config/gcp.rb b/lib/packer/config/gcp.rb index c29b89dd5..8550b17bb 100644 --- a/lib/packer/config/gcp.rb +++ b/lib/packer/config/gcp.rb @@ -11,11 +11,12 @@ def initialize( os:, output_directory:, version:, - vm_type:, vm_prefix: "", + vm_type:, + vm_tags: [], + vm_prefix: "", mount_ephemeral_disk: false, - root_disk_size: 32, - omit_external_ip: false, - vm_tags: ["winrm"], + root_disk_size: 64, + omit_external_ip: true, network: nil, network_project_id: nil, subnetwork: nil @@ -51,7 +52,7 @@ def builders "image_family" => @image_family, "zone" => "us-west1-c", "disk_size" => @root_disk_size, - "image_name" => "packer-#{Time.now.to_i}", + "image_name" => "stemcell-windows-#{@version}-#{Time.now.strftime("%Y%m%d%H%M%S")}".tr(".", "-"), "machine_type" => @vm_type, "network" => @network, "network_project_id" => @network_project_id, diff --git a/lib/packer/config/templates/provision_windows2019.json.erb b/lib/packer/config/templates/provision_windows2022.json.erb similarity index 96% rename from lib/packer/config/templates/provision_windows2019.json.erb rename to lib/packer/config/templates/provision_windows2022.json.erb index bf83f74b8..46118d872 100644 --- a/lib/packer/config/templates/provision_windows2019.json.erb +++ b/lib/packer/config/templates/provision_windows2022.json.erb @@ -129,17 +129,12 @@ ] }, <% end %> - { - "type": "file", - "source": "../sshd/OpenSSH-Win64.zip", - "destination": "C:\\provision\\OpenSSH-Win64.zip" - }, { "type": "powershell", "inline": [ "$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", - "Install-SSHD -SSHZipFile 'C:\\provision\\OpenSSH-Win64.zip'" + "Install-SSHD" ] }, { diff --git a/lib/packer/sysprep_script_generator.rb b/lib/packer/sysprep_script_generator.rb index d17b343da..e94af2139 100644 --- a/lib/packer/sysprep_script_generator.rb +++ b/lib/packer/sysprep_script_generator.rb @@ -28,6 +28,13 @@ class SysprepScriptGenerator } PS + OPENSSH_INSTALL = <<~PS + Write-Log "Install OpenSSH.Server" + Write-Log (Get-WindowsCapability -Online -Name "OpenSSH.Server*" | Format-List | Out-String) + Add-WindowsCapability -Online -Name (Get-WindowsCapability -Online -Name "OpenSSH.Server*" | ForEach-Object Name) + Write-Log (Get-WindowsCapability -Online -Name "OpenSSH.Server*" | Format-List | Out-String) + PS + def initialize(stemcell_builder_dir: STEMCELL_BUILDER_DIR) @stemcell_builder_dir = stemcell_builder_dir @module_path = File.join(@stemcell_builder_dir, "modules", "BOSH.WinRM", "BOSH.WinRM.psm1") @@ -70,6 +77,8 @@ def build_core_powershell parts << "" parts << module_source parts << "" + parts << OPENSSH_INSTALL.rstrip + parts << "" parts << 'Write-Log "Invoking WinRM"' parts << "Enable-WinRM" diff --git a/lib/stemcell/labeler/gcp.rb b/lib/stemcell/labeler/gcp.rb deleted file mode 100644 index 651f8f100..000000000 --- a/lib/stemcell/labeler/gcp.rb +++ /dev/null @@ -1,20 +0,0 @@ -require_relative "../../exec_command" - -module Stemcell - module Labeler - class Gcp - def self.label(image_url, account_json, key, value) - account_data = JSON.parse(account_json) - project_id = account_data["project_id"] - image_name = File.basename(image_url) - - Tempfile.create(["account", ".json"]) do |f| - f.write(account_json) - f.close - exec_command("gcloud auth activate-service-account --quiet --key-file #{f.path}") - exec_command("gcloud compute images add-labels #{image_name} --labels=#{key}=#{value} --project #{project_id}") - end - end - end - end -end diff --git a/lib/stemcell/publisher/gcp.rb b/lib/stemcell/publisher/gcp.rb deleted file mode 100644 index ecf45932e..000000000 --- a/lib/stemcell/publisher/gcp.rb +++ /dev/null @@ -1,55 +0,0 @@ -require "net/http" -require "tempfile" -require "uri" -require "json" - -require_relative "../../output" -require_relative "../../exec_command" - -module Stemcell - module Publisher - class Gcp - def self.publish(vm_to_add, account_json) - account_data = JSON.parse(account_json) - - account_email = account_data["client_email"] - project_id = account_data["project_id"] - - image_name = File.basename(vm_to_add[:image_url]) - Tempfile.create(["account", ".json"]) do |f| - f.write(account_json) - f.close - exec_command("gcloud auth activate-service-account --quiet #{account_email} --key-file #{f.path}") - uri = URI.parse("https://www.googleapis.com/compute/alpha/projects/#{project_id}/global/images/#{image_name}/setIamPolicy") - Output.say uri.inspect - return post(uri, json) - end - end - - def self.json - { - bindings: [ - { - role: "roles/compute.imageUser", - members: ["allAuthenticatedUsers"] - } - ] - } - end - - # Post request to stage the offer - def self.post(uri, data) - http = Net::HTTP.new(uri.host, uri.port) - http.use_ssl = true - token = `gcloud auth print-access-token` - header = {"Content-Type": "application/json", Authorization: "Bearer #{token}"} - request = Net::HTTP::Post.new(uri.request_uri, header) - request.body = data.to_json - - response = http.request(request) - Output.say "#{response.message}: #{response.body}" - exit(response.is_a?(Net::HTTPSuccess)) - end - end - end -end diff --git a/lib/tasks/build/aws.rake b/lib/tasks/build/aws.rake index 3f12a3955..3c2904d6c 100644 --- a/lib/tasks/build/aws.rake +++ b/lib/tasks/build/aws.rake @@ -6,7 +6,7 @@ namespace :build do class FailedAMICopyError < RuntimeError # rubocop:disable Lint/ConstantDefinitionInBlock end - class FailedAMIValidationError < RuntimeError # rubocop:disable Lint/ConstantDefinitionInBlock + class FailedAMIValidationError < RuntimeError # rubocop:disable Lint/ConstantDefinitionInBlock end desc "Build AWS Stemcell" diff --git a/lib/tasks/label/gcp.rake b/lib/tasks/label/gcp.rake deleted file mode 100644 index 19ca00cb0..000000000 --- a/lib/tasks/label/gcp.rake +++ /dev/null @@ -1,21 +0,0 @@ -require "rspec/core/rake_task" - -require_relative "../../stemcell/labeler/gcp" - -namespace :gcp do - namespace :label do - desc "Label an image as not published" - task :for_test do - account_json = ENV.fetch("ACCOUNT_JSON") - - Stemcell::Labeler::Gcp.label(image_url, account_json, "published", "false") - end - - desc "Label an image as published" - task :for_production do - account_json = ENV.fetch("ACCOUNT_JSON") - - Stemcell::Labeler::Gcp.label(image_url, account_json, "published", "true") - end - end -end diff --git a/lib/tasks/publish/gcp.rake b/lib/tasks/publish/gcp.rake deleted file mode 100644 index d7b6d0250..000000000 --- a/lib/tasks/publish/gcp.rake +++ /dev/null @@ -1,42 +0,0 @@ -require "rspec/core/rake_task" -require "rubygems/package" -require "yaml" - -require_relative "../../stemcell/publisher/gcp" -require_relative "../../stemcell/labeler/gcp" - -def read_from_tgz(path, filename) - contents = "" - tar_extract = Gem::Package::TarReader.new(Zlib::GzipReader.open(path)) - tar_extract.rewind - tar_extract.each do |entry| - if entry.full_name.include?(filename) - contents = entry.read - end - end - tar_extract.close - contents -end - -def image_url - root_dir = File.expand_path("../../../../../", __FILE__) - pattern = File.join(root_dir, "bosh-windows-stemcell", "*.tgz") - stemcell = Dir.glob(pattern)[0] - if stemcell.nil? - abort "Unable to find stemcell: #{pattern}" - end - - stemcell_mf = read_from_tgz(stemcell, "stemcell.MF") - manifest = YAML.load(stemcell_mf) - manifest["cloud_properties"]["image_url"] -end - -namespace :publish do - desc "Publish an image to GCP" - task :gcp do - account_json = ENV.fetch("ACCOUNT_JSON") - vm_to_add = {image_url: image_url} - - Stemcell::Publisher::Gcp.publish(vm_to_add, account_json) - end -end diff --git a/modules/BOSH.SSH/BOSH.SSH.Tests.ps1 b/modules/BOSH.SSH/BOSH.SSH.Tests.ps1 index 762bc2f9c..761bafeb7 100644 --- a/modules/BOSH.SSH/BOSH.SSH.Tests.ps1 +++ b/modules/BOSH.SSH/BOSH.SSH.Tests.ps1 @@ -1,4 +1,8 @@ BeforeAll { + Remove-Module -Name BOSH.Utils -ErrorAction Ignore + Import-Module ../BOSH.Utils/BOSH.Utils.psm1 + + Remove-Module -Name BOSH.SSH -ErrorAction Ignore Import-Module ./BOSH.SSH.psm1 function Get-FileEncoding @@ -45,313 +49,211 @@ BeforeAll { $encoding_found } } - - function CreateFakeOpenSSHZip - { - param([string]$dir, [string]$installScriptSpyStatus, [string]$fakeZipPath) - - mkdir "$dir\OpenSSH-Win64" - $installSpyBehavior = "echo installed > $installScriptSpyStatus" - Write-Output $installSpyBehavior > "$dir\OpenSSH-Win64\install-sshd.ps1" - Write-Output "fake sshd" > "$dir\OpenSSH-Win64\sshd.exe" - Write-Output "fake config" > "$dir\OpenSSH-Win64\sshd_config_default" - - Compress-Archive -Force -Path "$dir\OpenSSH-Win64" -DestinationPath $fakeZipPath - } } Describe "BOSH.SSH" { BeforeEach { + Mock -ModuleName BOSH.Utils Write-Log { } Mock -ModuleName BOSH.SSH Write-Log { } } - Describe "Enable-SSHD" { + Describe "Install-SSHD" { BeforeEach { - Mock -ModuleName BOSH.SSH Set-Service { } - Mock -ModuleName BOSH.SSH Invoke-LGPO { } - - $guid = $( New-Guid ).Guid - $TMP_DIR = "$env:TEMP\BOSH.SSH.Tests-$guid" - - $FAKE_ZIP = "$TMP_DIR\OpenSSH-TestFake.zip" - $INSTALL_SCRIPT_SPY_STATUS = "$TMP_DIR\install-script-status" - - CreateFakeOpenSSHZip -dir $TMP_DIR -installScriptSpyStatus $INSTALL_SCRIPT_SPY_STATUS -fakeZipPath $FAKE_ZIP - - mkdir -p "$TMP_DIR\Windows\Temp" - Write-Output "fake LGPO" > "$TMP_DIR\Windows\LGPO.exe" - - $ORIGINAL_WINDIR = $env:WINDIR - $env:WINDIR = "$TMP_DIR\Windows" - - $ORIGINAL_PROGRAMDATA = $env:ProgramData - $env:PROGRAMDATA = "$TMP_DIR\ProgramData" - } - - AfterEach { - rmdir $TMP_DIR -Recurse -ErrorAction Ignore - $env:WINDIR = $ORIGINAL_WINDIR - $env:PROGRAMDATA = $ORIGINAL_PROGRAMDATA + Mock Set-Service { } -ModuleName BOSH.SSH + Mock Edit-DefaultOpenSSHConfig { } -ModuleName BOSH.SSH } - It "sets the startup type of sshd to automatic" { - Mock -ModuleName BOSH.SSH Set-Service { } -Verifiable -ParameterFilter { $Name -eq "sshd" -and $StartupType -eq "Automatic" } + It "sets the startup type of sshd to disabled" { + Mock Set-Service { } -Verifiable -ModuleName BOSH.SSH -ParameterFilter { $Name -eq "sshd" -and $StartupType -eq "Disabled" } - Enable-SSHD -SSHZipFile $FAKE_ZIP + Install-SSHD Assert-VerifiableMock } - It "sets the startup type of ssh-agent to automatic" { - Mock -ModuleName BOSH.SSH Set-Service { } -Verifiable -ParameterFilter { $Name -eq "ssh-agent" -and $StartupType -eq "Automatic" } + It "sets the startup type of ssh-agent to disabled" { + Mock Set-Service { } -Verifiable -ModuleName BOSH.SSH -ParameterFilter { $Name -eq "ssh-agent" -and $StartupType -eq "Disabled" } - Enable-SSHD -SSHZipFile $FAKE_ZIP + Install-SSHD Assert-VerifiableMock } - It "sets up firewall when ssh not already set up" { - Mock Get-NetFirewallRule { - return [ordered]@{ - "Name" = "{3c06039b-ece1-4da3-8ece-255894975894}" - "DisplayName" = "NTP" - "Description" = "" - "DisplayGroup" = "" - "Group" = "" - "Enabled" = "True" - "Profile" = "Any" - "Platform" = "{}" - "Direction" = "Outbound" - "Action" = "Allow" - "EdgeTraversalPolicy" = "Block" - "LooseSourceMapping" = "False" - "LocalOnlyMapping" = "False" - "Owner" = "" - "PrimaryStatus" = "OK" - "Status" = "The rule was parsed successfully from the store. (65536)" - "EnforcementStatus" = "NotApplicable" - "PolicyStoreSource" = "PersistentStore" - "PolicyStoreSourceType" = "Local" - } - } -ModuleName BOSH.SSH + It "calls Edit-DefaultOpenSSHConfig" { + Mock Edit-DefaultOpenSSHConfig { } -Verifiable -ModuleName BOSH.SSH - Mock -ModuleName BOSH.SSH New-NetFirewallRule { } - Enable-SSHD -SSHZipFile $FAKE_ZIP - Assert-MockCalled New-NetFirewallRule -Times 1 -ModuleName BOSH.SSH -Scope It - } + Install-SSHD - It "doesn't set up firewall when ssh is already set up " { - Mock Get-NetFirewallRule { - return [ordered]@{ - "Name" = "{ E02857AB-8EA8-4358-8119-ED7D20DA7712 }" - "DisplayName" = "SSH" - "Description" = "" - "DisplayGroup" = "" - "Group" = "" - "Enabled" = "True" - "Profile" = "Any" - "Platform" = "{ }" - "Direction" = "Inbound" - "Action" = "Allow" - "EdgeTraversalPolicy" = "Block" - "LooseSourceMapping" = "False" - "LocalOnlyMapping" = "False" - "Owner" = "" - "PrimaryStatus" = "OK" - "Status" = "The rule was parsed successfully from the store. (65536)" - "EnforcementStatus" = "NotApplicable" - "PolicyStoreSource" = "PersistentStore" - "PolicyStoreSourceType" = "Local" - } - } -ModuleName BOSH.SSH - - Mock -ModuleName BOSH.SSH New-NetFirewallRule { } - Enable-SSHD -SSHZipFile $FAKE_ZIP - Assert-MockCalled New-NetFirewallRule -Times 0 -ModuleName BOSH.SSH -Scope It + Assert-VerifiableMock } + } - It "Generates inf and invokes LGPO if LGPO exists" { - Mock -ModuleName BOSH.SSH Invoke-LGPO -Verifiable -ParameterFilter { $LGPOPath -eq "$TMP_DIR\Windows\LGPO.exe" -and $InfFilePath -eq "$TMP_DIR\Windows\Temp\enable-ssh.inf" } - - Enable-SSHD -SSHZipFile $FAKE_ZIP + Describe "Edit-DefaultOpenSSHConfig" { + BeforeEach { + Mock -ModuleName BOSH.SSH Set-Service { } - Assert-VerifiableMock - } + $guid = $( New-Guid ).Guid + $TMP_DIR = "$env:TEMP\BOSH.SSH.Tests_Edit-DefaultOpenSSHConfig-$guid" - It "Skips LGPO if LGPO.exe not found" { - rm "$TMP_DIR\Windows\LGPO.exe" + $FAKE_WINDIR = "$TMP_DIR\Windows" + mkdir -p "$FAKE_WINDIR\System32\OpenSSH\" + New-Item -ItemType Directory -Path "$FAKE_WINDIR\System32\OpenSSH\" -Force - Enable-SSHD -SSHZipFile $FAKE_ZIP + $ORIGINAL_WINDIR = $env:WINDIR + $env:WINDIR = $FAKE_WINDIR - Assert-MockCalled Invoke-LGPO -Times 0 -ModuleName BOSH.SSH -Scope It + $GeneratedConfigPath = "$TMP_DIR/sshd_config" } - Context "When LGPO executable fails" { - It "Throws an appropriate error" { - Mock Invoke-LGPO { throw "some error" } -Verifiable -ModuleName BOSH.SSH -ParameterFilter { $LGPOPath -eq "$TMP_DIR\Windows\LGPO.exe" -and $InfFilePath -eq "$TMP_DIR\Windows\Temp\enable-ssh.inf" } - { Enable-SSHD -SSHZipFile $FAKE_ZIP } | Should -Throw "LGPO.exe failed with: some error*" - } + AfterEach { + $env:WINDIR = $ORIGINAL_WINDIR + rmdir $TMP_DIR -Recurse -ErrorAction Ignore } - It "removes existing SSH keys" { - New-Item -ItemType Directory -Path "$TMP_DIR\ProgramData\ssh" -ErrorAction Ignore - Write-Output "delete" > "$TMP_DIR\ProgramData\ssh\ssh_host_1" - Write-Output "delete" > "$TMP_DIR\ProgramData\ssh\ssh_host_2" - Write-Output "delete" > "$TMP_DIR\ProgramData\ssh\ssh_host_3" - Write-Output "ignore" > "$TMP_DIR\ProgramData\ssh\not_ssh_host_4" + It "Comments out default configuration for where administrator keys are stored" { + $ConfigPath = "$TMP_DIR/sshd_config_default" + $Content = @" +Match Group administrators +AllowGroups administrators "openssh users" +AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys +"@ + Out-File -FilePath $ConfigPath -InputObject $Content -Encoding UTF8 - Enable-SSHD -SSHZipFile $FAKE_ZIP + Edit-DefaultOpenSSHConfig -ConfigPath $ConfigPath -GeneratedConfigPath $GeneratedConfigPath - $numHosts = (Get-ChildItem "$TMP_DIR\ProgramData\ssh\").count - $numHosts | Should -eq 1 - } + $ExpectedContent = @" +#Match Group administrators +#AllowGroups administrators "openssh users" +#AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys +"@ - It "creates empty ssh program dir if it doesn't exist" { - Enable-SSHD -SSHZipFile $FAKE_ZIP - { Test-Path "$TMP_DIR\ProgramData\ssh" } | Should -eq $True + ((Get-Content $ConfigPath) -join "`n") | Should -Be $ExpectedContent } - } - - Describe "Install-SSHD" { - BeforeEach { - Mock Set-Service { } -ModuleName BOSH.SSH - Mock Protect-Dir { } -ModuleName BOSH.SSH - Mock Invoke-CACL { } -ModuleName BOSH.SSH - Mock Write-Log { } -ModuleName BOSH.Utils - - $guid = $( New-Guid ).Guid - $TMP_DIR = "$env:TEMP\BOSH.SSH.Tests-$guid" - - mkdir -p "$TMP_DIR\Windows\Temp" - mkdir -p "$TMP_DIR\ProgramData" - $FAKE_ZIP = "$TMP_DIR\OpenSSH-TestFake.zip" - $INSTALL_SCRIPT_SPY_STATUS = "$TMP_DIR\install-script-status" + It "Disables the chacha20-poly1305 cipher to mitigate CVE-2023-48795" { + $ConfigPath = "$TMP_DIR/sshd_config_default" + $Content = @" +#RekeyLimit default none +"@ + Out-File -FilePath $ConfigPath -InputObject $Content -Encoding UTF8 - CreateFakeOpenSSHZip -dir $TMP_DIR -installScriptSpyStatus $INSTALL_SCRIPT_SPY_STATUS -fakeZipPath $FAKE_ZIP + Edit-DefaultOpenSSHConfig -ConfigPath $ConfigPath -GeneratedConfigPath $GeneratedConfigPath - $ORIGINAL_PROGRAMFILES = $env:PROGRAMFILES - $env:PROGRAMFILES = "$TMP_DIR\ProgramFiles" - } +$ExpectedContent = @" +#RekeyLimit default none +# Disable cipher to mitigate CVE-2023-48795 +Ciphers -chacha20-poly1305@openssh.com +"@ - AfterEach { - rmdir $TMP_DIR -Recurse -ErrorAction Ignore - $env:PROGRAMFILES = $ORIGINAL_PROGRAMFILES + ((Get-Content $ConfigPath) -join "`n") | Should -Match $ExpectedContent } - It "extracts OpenSSH to Program Files" { - Install-SSHD -SSHZipFile $FAKE_ZIP + It "sets the file encoding to be UTF8" { + $ConfigPath = "$TMP_DIR/sshd_config_default" - Get-Item $env:PROGRAMFILES\OpenSSH | Should -Exist - Get-Item $env:PROGRAMFILES\OpenSSH\sshd.exe | Should -Exist - } + Out-File -FilePath $ConfigPath -InputObject "some-fake-content" -Encoding UTF8 - It "runs the install-sshd script" { - Install-SSHD -SSHZipFile $FAKE_ZIP + Edit-DefaultOpenSSHConfig -ConfigPath $ConfigPath -GeneratedConfigPath $GeneratedConfigPath - "$INSTALL_SCRIPT_SPY_STATUS" | Should -FileContentMatchExactly 'installed' + Get-FileEncoding $ConfigPath | Should -BeLike "System.Text.UTF8Encoding" } + } - It "calls Protect-Dir to lock down permissions" { - Mock Protect-Dir { } -Verifiable -ModuleName BOSH.SSH -ParameterFilter { $path -eq "$env:PROGRAMFILES\OpenSSH" } - - Install-SSHD -SSHZipFile $FAKE_ZIP + Describe "Enable-SSHD" { + BeforeEach { + Mock Set-Service { } -ModuleName BOSH.SSH + Mock Get-NetFirewallRule { } -ModuleName BOSH.SSH + Mock New-NetFirewallRule { } -ModuleName BOSH.SSH - Assert-VerifiableMock + Mock Remove-SSHKeys { } -ModuleName BOSH.SSH } - It "calls Protect-Dir only after install-sshd.ps1 has run" { - $script:installRanFirst = $false - Mock -ModuleName BOSH.SSH Protect-Dir { - $script:installRanFirst = (Test-Path $INSTALL_SCRIPT_SPY_STATUS) + It "sets the startup type of sshd to automatic" { + Mock Set-Service { } -ModuleName BOSH.SSH -Verifiable -ParameterFilter { + $Name -eq "sshd" -and $StartupType -eq "Automatic" } - Install-SSHD -SSHZipFile $FAKE_ZIP + Enable-SSHD - $script:installRanFirst | Should -Be $true + Assert-VerifiableMock } - It "calls Invoke-CACL with expected files" { - Mock Invoke-CACL { } -Verifiable -ModuleName BOSH.SSH -ParameterFilter { - @( - "libcrypto.dll", - "scp.exe", - "sftp-server.exe", - "sftp.exe", - "ssh-add.exe", - "ssh-agent.exe", - "ssh-keygen.exe", - "ssh-keyscan.exe", - "ssh-shellhost.exe", - "ssh.exe", - "sshd.exe" - ) - } + It "sets the startup type of ssh-agent to automatic" { + Mock -ModuleName BOSH.SSH Set-Service { } -Verifiable -ParameterFilter { $Name -eq "ssh-agent" -and $StartupType -eq "Automatic" } - Install-SSHD -SSHZipFile $FAKE_ZIP + Enable-SSHD Assert-VerifiableMock } - It "sets the startup type of sshd to disabled" { - Mock Set-Service { } -Verifiable -ModuleName BOSH.SSH -ParameterFilter { $Name -eq "sshd" -and $StartupType -eq "Disabled" } + It "sets up firewall when ssh not already set up" { + Mock -ModuleName BOSH.SSH New-NetFirewallRule { } -Verifiable - Install-SSHD -SSHZipFile $FAKE_ZIP + Enable-SSHD - Assert-VerifiableMock + Assert-MockCalled New-NetFirewallRule -ModuleName BOSH.SSH -Times 1 } - It "sets the startup type of ssh-agent to disabled" { - Mock Set-Service { } -Verifiable -ModuleName BOSH.SSH -ParameterFilter { $Name -eq "ssh-agent" -and $StartupType -eq "Disabled" } - - Install-SSHD -SSHZipFile $FAKE_ZIP + It "removes the existing SSH firewall rule and recreates it " { + Mock Get-NetFirewallRule { + return [ordered]@{ + "Name" = "OpenSSH-Server-In-TCP" + } + } -ModuleName BOSH.SSH - Assert-VerifiableMock + Mock Remove-NetFirewallRule { } -ModuleName BOSH.SSH -Verifiable -ParameterFilter { $Name -eq "OpenSSH-Server-In-TCP" } + Mock New-NetFirewallRule { } -ModuleName BOSH.SSH -Verifiable -ParameterFilter { + $Name -eq "OpenSSH-Server-In-TCP" -and + $Enabled -eq "True" -and + $Direction -eq "Inbound" -and + $Protocol -eq "TCP" -and + $Action -eq "Allow" -and + $Profile -eq "Any" -and + $LocalPort -eq 22 + } + Enable-SSHD + Assert-MockCalled Remove-NetFirewallRule -ModuleName BOSH.SSH -Times 1 + Assert-MockCalled New-NetFirewallRule -ModuleName BOSH.SSH -Times 1 } - It "modifies the openssh configuration to remove default admin key location while maintaining UTF-8 encoding" { - Mock Get-Content { - @" -Match Group administrators -AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys -"@ - } -ModuleName BOSH.SSH -ParameterFilter { $Path -like "*sshd_config_default" } + It "invokes Remove-SSHKeys" { + Mock Remove-SSHKeys { } -ModuleName BOSH.SSH -Verifiable + + Enable-SSHD - Install-SSHD -SSHZipFile $FAKE_ZIP - Get-Content $env:PROGRAMFILES\OpenSSH\sshd_config_default | Out-String | Should -BeLike "#*#*" - Get-FileEncoding $env:PROGRAMFILES\OpenSSH\sshd_config_default | Should -BeLike "System.Text.UTF8Encoding" + Assert-VerifiableMock } } - Describe "Edit-DefaultOpenSSHConfig"{ - It "Comments out default configuration for where administrator keys are stored" { + Describe "Remove-SSHKeys" { + BeforeEach { + $guid = $( New-Guid ).Guid + $TMP_DIR = "$env:TEMP\BOSH.SSH.Tests_Remove-SSHKeys-$guid" - Mock Get-Content { - @" -Match Group administrators -AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys -"@ - } -ModuleName BOSH.SSH + $ORIGINAL_PROGRAMDATA = $env:ProgramData + $FAKE_PROGRAMDATA = "$TMP_DIR\ProgramData" - $result = Edit-DefaultOpenSSHConfig -ConfigPath "some/path/sshd_config_default" + $env:ProgramData = $FAKE_PROGRAMDATA - Assert-MockCalled Get-Content -Times 1 -ModuleName BOSH.SSH -Scope It -ParameterFilter { $Path -like "*sshd_config_default" } - $result | Should -BeLike "#*#*" + New-Item -ItemType Directory -Path "$FAKE_PROGRAMDATA\ssh" -Force + Out-File -InputObject "delete" -Encoding UTF8 -FilePath "$FAKE_PROGRAMDATA\ssh\ssh_host_1" + Out-File -InputObject "delete" -Encoding UTF8 -FilePath "$FAKE_PROGRAMDATA\ssh\ssh_host_2" + Out-File -InputObject "delete" -Encoding UTF8 -FilePath "$FAKE_PROGRAMDATA\ssh\ssh_host_3" + Out-File -InputObject "ignore" -Encoding UTF8 -FilePath "$FAKE_PROGRAMDATA\ssh\not_ssh_host_4" } - It "Disables the chacha20-poly1305 cipher to mitigate CVE-2023-48795" { + AfterEach { + $env:ProgramData = $ORIGINAL_PROGRAMDATA + } - Mock Get-Content { - @" -# Ciphers and keying -#RekeyLimit default none -"@ - } -ModuleName BOSH.SSH + It "removes existing SSH keys under 'env:ProgramData\ssh\ssh_host_*'" { + $initialNumFiles = (Get-ChildItem "$FAKE_PROGRAMDATA\ssh\").Count + $initialNumFiles | Should -eq 4 - $result = Edit-DefaultOpenSSHConfig -ConfigPath "some/path/sshd_config_default" + Remove-SSHKeys - Assert-MockCalled Get-Content -Times 1 -ModuleName BOSH.SSH -Scope It -ParameterFilter { $Path -like "*sshd_config_default" } - $result | Should -BeLike "*#RekeyLimit default none`r`n# Disable cipher to mitigate CVE-2023-48795`r`nCiphers -chacha20-poly1305@openssh.com`r`n" + $expectedNumFiles = (Get-ChildItem "$FAKE_PROGRAMDATA\ssh\").Count + $expectedNumFiles | Should -eq 1 } } } diff --git a/modules/BOSH.SSH/BOSH.SSH.psd1 b/modules/BOSH.SSH/BOSH.SSH.psd1 index 46c870a22..3e7c439ab 100644 --- a/modules/BOSH.SSH/BOSH.SSH.psd1 +++ b/modules/BOSH.SSH/BOSH.SSH.psd1 @@ -6,9 +6,8 @@ Copyright = '(c) 2017 BOSH' Description = 'Install Microsoft SSHD' PowerShellVersion = '4.0' - FunctionsToExport = @('Install-SSHD', - 'Enable-SSHD', - 'Remove-SSHKeys') + RequiredModules = @('BOSH.Utils') + FunctionsToExport = @('Install-SSHD', 'Enable-SSHD', 'Remove-SSHKeys') CmdletsToExport = @() VariablesToExport = '*' AliasesToExport = @() diff --git a/modules/BOSH.SSH/BOSH.SSH.psm1 b/modules/BOSH.SSH/BOSH.SSH.psm1 index 7d771dbcb..6e5d0e0bf 100644 --- a/modules/BOSH.SSH/BOSH.SSH.psm1 +++ b/modules/BOSH.SSH/BOSH.SSH.psm1 @@ -1,106 +1,22 @@ function Install-SSHD { - param ( - [string]$SSHZipFile = $( Throw "Provide an SSHD zipfile" ) - ) - - New-Item "$env:PROGRAMFILES\SSHTemp" -Type Directory -Force - Open-Zip -ZipFile $SSHZipFile -OutPath "$env:PROGRAMFILES\SSHTemp" - - $ConfigPath = "$env:PROGRAMFILES\SSHTemp\OpenSSH-Win64\sshd_config_default" - $ModifiedConfigContents = Edit-DefaultOpenSSHConfig -ConfigPath $ConfigPath - Remove-Item -Force $ConfigPath - Out-File -FilePath $ConfigPath -InputObject $ModifiedConfigContents -Encoding UTF8 - - Move-Item -Force "$env:PROGRAMFILES\SSHTemp\OpenSSH-Win64" "$env:PROGRAMFILES\OpenSSH" - Remove-Item -Force "$env:PROGRAMFILES\SSHTemp" - - # Run the OpenSSH service installer before locking down the directory. - # install-sshd.ps1 needs read access to its own files (the WinRM provisioning session - # runs with a UAC-filtered token where BUILTIN\Administrators is disabled, so only - # inherited permissions from C:\Program Files allow access at this point). - # The script also grants NT AUTHORITY\Authenticated Users on some files, which - # Protect-Dir will remove in the next step. - Push-Location "$env:PROGRAMFILES\OpenSSH" - powershell -ExecutionPolicy Bypass -File install-sshd.ps1 - if ($LASTEXITCODE -ne 0) - { - throw "install-sshd.ps1 exited with $LASTEXITCODE" - } - Pop-Location - - # Lock down the directory now that the service installer has completed. - # This removes all inherited ACEs (including Authenticated Users added by the - # installer) and leaves only SYSTEM and Administrators with full control. - Protect-Dir -path "$env:PROGRAMFILES\OpenSSH" - - # Grant NT AUTHORITY\Authenticated Users read access to .EXEs and the .DLL in OpenSSH - $FileNames = @( - "libcrypto.dll", - "scp.exe", - "sftp-server.exe", - "sftp.exe", - "ssh-add.exe", - "ssh-agent.exe", - "ssh-keygen.exe", - "ssh-keyscan.exe", - "ssh-shellhost.exe", - "ssh.exe", - "sshd.exe" - ) - Invoke-CACL -FileNames $FileNames + Edit-DefaultOpenSSHConfig Set-Service -Name sshd -StartupType Disabled - # ssh-agent is not the same as ssh-agent in *nix openssh Set-Service -Name ssh-agent -StartupType Disabled } function Enable-SSHD { - if ($null -eq (Get-NetFirewallRule | Where-Object { $_.DisplayName -ieq 'SSH' })) - { - "Creating firewall rule for SSH" - New-NetFirewallRule -Protocol TCP -LocalPort 22 -Direction Inbound -Action Allow -DisplayName SSH - } - else - { - "Firewall rule for SSH already exists" - } - - $InfFilePath = "$env:WINDIR\Temp\enable-ssh.inf" - - $InfFileContents = @' -[Unicode] -Unicode=yes -[Version] -signature=$CHICAGO$ -Revision=1 -[Registry Values] -[System Access] -[Privilege Rights] -SeDenyNetworkLogonRight=*S-1-5-32-546 -SeAssignPrimaryTokenPrivilege=*S-1-5-19,*S-1-5-20,*S-1-5-80-3847866527-469524349-687026318-516638107-1125189541 -'@ - $LGPOPath = "$env:WINDIR\LGPO.exe" - if (Test-Path $LGPOPath) - { - Out-File -FilePath $InfFilePath -Encoding unicode -InputObject $InfFileContents -Force - Try - { - Invoke-LGPO -LGPOPath $LGPOPath -InfFilePath $InfFilePath - } - Catch - { - throw "LGPO.exe failed with: $_.Exception.Message" - } - } - else - { - "Did not find $LGPOPath. Assuming existing security policies are sufficient to support ssh." + # Remove existing OpenSSH firewall rule and recreate with '-Profile Any' option + if (Get-NetFirewallRule -Name "OpenSSH-Server-In-TCP" -ErrorAction SilentlyContinue) { + "Removing firewall rule: 'OpenSSH-Server-In-TCP'" + Remove-NetFirewallRule -Name "OpenSSH-Server-In-TCP" } + Write-Log "Creating firewall rule 'OpenSSH-Server-In-TCP'" + New-NetFirewallRule -Name 'OpenSSH-Server-In-TCP' -DisplayName 'OpenSSH Server (sshd)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -Profile Any -LocalPort 22 Set-Service -Name sshd -StartupType Automatic - # ssh-agent is not the same as ssh-agent in *nix openssh Set-Service -Name ssh-agent -StartupType Automatic Remove-SSHKeys @@ -108,48 +24,36 @@ SeAssignPrimaryTokenPrivilege=*S-1-5-19,*S-1-5-20,*S-1-5-80-3847866527-469524349 function Remove-SSHKeys { - $SSHDir = "C:\Program Files\OpenSSH" - - Push-Location $SSHDir - New-Item -ItemType Directory -Path "$env:ProgramData\ssh" -ErrorAction Ignore - - "Removing any existing host keys" + Write-Log "Removing any existing host keys" Remove-Item -Path "$env:ProgramData\ssh\ssh_host_*" -ErrorAction Ignore - Pop-Location } -function Invoke-CACL +function Edit-DefaultOpenSSHConfig { param ( - [string[]] $FileNames = $( Throw "Files not provided" ) + [string]$ConfigPath = "$env:windir\System32\OpenSSH\sshd_config_default", + [string]$GeneratedConfigPath = "$env:ProgramData\ssh\sshd_config" ) - foreach ($name in $FileNames) - { - $path = Join-Path "$env:PROGRAMFILES\OpenSSH" $name - cacls.exe $Path /E /P "NT AUTHORITY\Authenticated Users:R" - } -} + Copy-Item -Path $ConfigPath -Destination "$ConfigPath.bak" -function Invoke-LGPO -{ - param ( - [string]$LGPOPath = $( Throw "Provide LGPO path" ), - [string]$InfFilePath = $( Throw "Provide Inf file path" ) - ) - & $LGPOPath /s $InfFilePath -} + $OriginalConfig = Get-Content $ConfigPath + Write-Log "Original SSH config at $ConfigPath :" + Write-Log "$OriginalConfig" -function Edit-DefaultOpenSSHConfig -{ - param ( - [string]$ConfigPath = $( Throw "Provide openssh default config path" ) - ) + $ModifiedConfig = $OriginalConfig ` + | ForEach-Object{ $_ -replace ".*Match Group administrators.*", "#$&" } ` + | ForEach-Object{ $_ -replace ".*AllowGroups administrators.*", "#$&" } ` + | ForEach-Object{ $_ -replace ".*AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys.*", "#$&" } ` + | ForEach-Object{ $_ -replace "#RekeyLimit default none", "$&`r`n# Disable cipher to mitigate CVE-2023-48795`r`nCiphers -chacha20-poly1305@openssh.com`r`n" } + + Write-Log "Modified SSH config at $ConfigPath :" + Write-Log "$ModifiedConfig" - $ModifiedConfig = Get-Content $ConfigPath ` - | ForEach-Object{ $_ -replace ".*Match Group administrators.*", "#$&" } ` - | ForEach-Object{ $_ -replace ".*AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys.*", "#$&" } ` - | ForEach-Object{ $_ -replace "#RekeyLimit default none", "$&`r`n# Disable cipher to mitigate CVE-2023-48795`r`nCiphers -chacha20-poly1305@openssh.com`r`n" } + Remove-Item -Force $ConfigPath + Out-File -FilePath $ConfigPath -InputObject $ModifiedConfig -Encoding UTF8 - return $ModifiedConfig + # We need to make sure that the generated config is cleared, so our above changes are applied when the config + # is next generated. If this isnt done, then we may have a config from the prior template. + Remove-Item -Path $GeneratedConfigPath -ErrorAction Ignore } diff --git a/modules/BOSH.Sysprep/BOSH.Sysprep.Tests.ps1 b/modules/BOSH.Sysprep/BOSH.Sysprep.Tests.ps1 index ad62a5f57..4baf94c77 100644 --- a/modules/BOSH.Sysprep/BOSH.Sysprep.Tests.ps1 +++ b/modules/BOSH.Sysprep/BOSH.Sysprep.Tests.ps1 @@ -3,7 +3,7 @@ BeforeAll { Import-Module ../BOSH.Utils/BOSH.Utils.psm1 Import-Module ../BOSH.Agent/BOSH.Agent.psm1 - $OsVersion = "windows2019" + $OsVersion = "windows2022" InModuleScope BOSH.Sysprep { function GCESysprep @@ -337,7 +337,7 @@ Describe "BOSH.Sysprep" { BeforeEach { Mock -ModuleName BOSH.Sysprep -CommandName Get-OSVersion { $OsVersion } - $expectedPolicyDir = Join-Path $PSScriptRoot "cis-merge-2019" + $expectedPolicyDir = Join-Path $PSScriptRoot "cis-merge-2022" $domainSysVolDir = "$expectedPolicyDir/DomainSysvol" $machinePolicyDir = "$domainSysVolDir/GPO/Machine" $userPolicyDir = "$domainSysVolDir/GPO/User" diff --git a/modules/BOSH.Sysprep/BOSH.Sysprep.psm1 b/modules/BOSH.Sysprep/BOSH.Sysprep.psm1 index 2ec6e991a..f1eeb5472 100644 --- a/modules/BOSH.Sysprep/BOSH.Sysprep.psm1 +++ b/modules/BOSH.Sysprep/BOSH.Sysprep.psm1 @@ -70,6 +70,9 @@ function Enable-LocalSecurityPolicy "windows2019" { $PolicySource = (Join-Path $PSScriptRoot "cis-merge-2019") } + "windows2022" { + $PolicySource = (Join-Path $PSScriptRoot "cis-merge-2022") + } Default { Throw "Policy backup filepath could not be determined from OS: $OsVersion" } @@ -109,16 +112,48 @@ function Enable-LocalSecurityPolicy # AWS function Update-AWS-LaunchConfigJSON { - $LaunchConfigJson = 'C:\ProgramData\Amazon\EC2-Windows\Launch\Config\LaunchConfig.json' - $LaunchConfig = Get-Content $LaunchConfigJson -raw | ConvertFrom-Json - $LaunchConfig.addDnsSuffixList = $False - $LaunchConfig.extendBootVolumeSize = $False - $LaunchConfig | ConvertTo-Json | Set-Content $LaunchConfigJson + $LaunchConfigPath = 'C:\ProgramData\Amazon\EC2Launch\config\agent-config.yml' + + # Overwrite default config with extendRootPartition and setDnsSuffix tasks removed. + $LaunchConfigYaml = @' +version: 1.1 +config: +- stage: preReady + tasks: + - task: activateWindows + inputs: + activation: + type: amazon + - task: setAdminAccount + inputs: + password: + type: doNothing + - task: setWallpaper + inputs: + path: C:\ProgramData\Amazon\EC2Launch\wallpaper\Ec2Wallpaper.jpg + attributes: + - hostName + - instanceId + - privateIpAddress + - publicIpAddress + - instanceSize + - availabilityZone + - architecture + - memory + - network +- stage: postReady + tasks: + - task: startSsm +'@ + + Set-Content -Path $LaunchConfigPath -Value $LaunchConfigYaml -Encoding utf8 + + Get-Content -Path $LaunchConfigPath } function Update-AWS-UnattendedXML { - $UnattendedXmlPath = 'C:\ProgramData\Amazon\EC2-Windows\Launch\Sysprep\Unattend.xml' + $UnattendedXmlPath = 'C:\ProgramData\Amazon\EC2Launch\sysprep\unattend.xml' $UnattendedContent = [xml](Get-Content $UnattendedXmlPath) $SpecializeSettings = ($UnattendedContent.unattend.settings | Where-Object { $_.pass -EQ "specialize" }) $WindowsDeploymentComponent = ($SpecializeSettings.component | Where-Object { $_.name -EQ "Microsoft-Windows-Deployment" }) @@ -141,9 +176,7 @@ function Update-AWS-UnattendedXML function Enable-AWS-Sysprep { # Enable sysprep - Set-Location 'C:\ProgramData\Amazon\EC2-Windows\Launch\Scripts' - ./InitializeInstance.ps1 -Schedule - ./SysprepInstance.ps1 -NoShutdown + & "C:\Program Files\Amazon\EC2Launch\EC2Launch.exe" sysprep } # GCP diff --git a/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/Machine/microsoft/windows nt/Audit/audit.csv b/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/Machine/microsoft/windows nt/Audit/audit.csv new file mode 100644 index 000000000..505ab6f19 --- /dev/null +++ b/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/Machine/microsoft/windows nt/Audit/audit.csv @@ -0,0 +1,67 @@ +Machine Name,Policy Target,Subcategory,Subcategory GUID,Inclusion Setting,Exclusion Setting,Setting Value +,System,IPsec Driver,{0CCE9213-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,System Integrity,{0CCE9212-69AE-11D9-BED3-505054503030},Success and Failure,,3 +,System,Security System Extension,{0CCE9211-69AE-11D9-BED3-505054503030},Success,,1 +,System,Security State Change,{0CCE9210-69AE-11D9-BED3-505054503030},Success,,1 +,System,Other System Events,{0CCE9214-69AE-11D9-BED3-505054503030},Success and Failure,,3 +,System,Access Rights,{0CCE924B-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Group Membership,{0CCE9249-69AE-11D9-BED3-505054503030},Success,,1 +,System,User / Device Claims,{0CCE9247-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Network Policy Server,{0CCE9243-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Other Logon/Logoff Events,{0CCE921C-69AE-11D9-BED3-505054503030},Success and Failure,,3 +,System,Special Logon,{0CCE921B-69AE-11D9-BED3-505054503030},Success,,1 +,System,IPsec Extended Mode,{0CCE921A-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,IPsec Quick Mode,{0CCE9219-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,IPsec Main Mode,{0CCE9218-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Account Lockout,{0CCE9217-69AE-11D9-BED3-505054503030},Failure,,2 +,System,Logoff,{0CCE9216-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Logon,{0CCE9215-69AE-11D9-BED3-505054503030},Success and Failure,,3 +,System,Handle Manipulation,{0CCE9223-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Central Policy Staging,{0CCE9246-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Removable Storage,{0CCE9245-69AE-11D9-BED3-505054503030},Success and Failure,,3 +,System,Detailed File Share,{0CCE9244-69AE-11D9-BED3-505054503030},Failure,,2 +,System,Other Object Access Events,{0CCE9227-69AE-11D9-BED3-505054503030},Success and Failure,,3 +,System,Filtering Platform Connection,{0CCE9226-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Filtering Platform Packet Drop,{0CCE9225-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,File Share,{0CCE9224-69AE-11D9-BED3-505054503030},Success and Failure,,3 +,System,Application Generated,{0CCE9222-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Certification Services,{0CCE9221-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,SAM,{0CCE9220-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Kernel Object,{0CCE921F-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Registry,{0CCE921E-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,File System,{0CCE921D-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Other Privilege Use Events,{0CCE922A-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Non Sensitive Privilege Use,{0CCE9229-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Sensitive Privilege Use,{0CCE9228-69AE-11D9-BED3-505054503030},Success and Failure,,3 +,System,RPC Events,{0CCE922E-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Token Right Adjusted Events,{0CCE924A-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Process Creation,{0CCE922B-69AE-11D9-BED3-505054503030},Success,,1 +,System,Process Termination,{0CCE922C-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Plug and Play Events,{0CCE9248-69AE-11D9-BED3-505054503030},Success,,1 +,System,DPAPI Activity,{0CCE922D-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Other Policy Change Events,{0CCE9234-69AE-11D9-BED3-505054503030},Failure,,2 +,System,Authentication Policy Change,{0CCE9230-69AE-11D9-BED3-505054503030},Success,,1 +,System,Audit Policy Change,{0CCE922F-69AE-11D9-BED3-505054503030},Success,,1 +,System,Filtering Platform Policy Change,{0CCE9233-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Authorization Policy Change,{0CCE9231-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,MPSSVC Rule-Level Policy Change,{0CCE9232-69AE-11D9-BED3-505054503030},Success and Failure,,3 +,System,Other Account Management Events,{0CCE923A-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Application Group Management,{0CCE9239-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Distribution Group Management,{0CCE9238-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Security Group Management,{0CCE9237-69AE-11D9-BED3-505054503030},Success,,1 +,System,Computer Account Management,{0CCE9236-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,User Account Management,{0CCE9235-69AE-11D9-BED3-505054503030},Success and Failure,,3 +,System,Detailed Directory Service Replication,{0CCE923E-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Directory Service Changes,{0CCE923C-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Directory Service Access,{0CCE923B-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Directory Service Replication,{0CCE923D-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Other Account Logon Events,{0CCE9241-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Kerberos Service Ticket Operations,{0CCE9240-69AE-11D9-BED3-505054503030},No Auditing,,0 +,System,Credential Validation,{0CCE923F-69AE-11D9-BED3-505054503030},Success and Failure,,3 +,System,Kerberos Authentication Service,{0CCE9242-69AE-11D9-BED3-505054503030},No Auditing,,0 +,,Option:CrashOnAuditFail,,Disabled,,0 +,,Option:FullPrivilegeAuditing,,Disabled,,0 +,,Option:AuditBaseObjects,,Disabled,,0 +,,Option:AuditBaseDirectories,,Disabled,,0 +,,FileGlobalSacl,,,, +,,RegistryGlobalSacl,,,, diff --git a/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/Machine/microsoft/windows nt/SecEdit/GptTmpl.inf b/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/Machine/microsoft/windows nt/SecEdit/GptTmpl.inf new file mode 100644 index 000000000..d7f07b88b Binary files /dev/null and b/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/Machine/microsoft/windows nt/SecEdit/GptTmpl.inf differ diff --git a/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/Machine/registry.txt b/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/Machine/registry.txt new file mode 100644 index 000000000..04f63dfbf --- /dev/null +++ b/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/Machine/registry.txt @@ -0,0 +1,681 @@ +; ---------------------------------------------------------------------- +; PARSING Computer POLICY +; Source file: .\GPOBackup\DomainSysvol\GPO\Machine\registry.pol + +Computer +Software\Microsoft\Windows\CurrentVersion\Policies\Ext +RunThisTimeEnabled +DWORD:0 + +Computer +Software\Microsoft\Windows\CurrentVersion\Policies\Ext +VersionCheckEnabled +DWORD:1 + +Computer +Software\Microsoft\Windows\CurrentVersion\Policies\System +NoConnectedUser +DWORD:3 + +Computer +Software\Policies\Microsoft\Internet Explorer\Download +RunInvalidSignatures +DWORD:0 + +Computer +Software\Policies\Microsoft\Internet Explorer\Download +CheckExeSignatures +SZ:yes + +Computer +Software\Policies\Microsoft\Internet Explorer\Feeds +DisableEnclosureDownload +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main +Isolation64Bit +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main +DisableEPMCompat +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main +Isolation +SZ:PMEM + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION +(Reserved) +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION +explorer.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION +iexplore.exe +SZ:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\PhishingFilter +PreventOverrideAppRepUnknown +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\PhishingFilter +PreventOverride +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\PhishingFilter +EnabledV9 +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Restrictions +NoCrashDetection +DWORD:1 + +Computer +Software\Policies\Microsoft\Internet Explorer\Security +DisableSecuritySettingsCheck +DWORD:0 + +Computer +Software\Policies\Microsoft\Internet Explorer\Security\ActiveX +BlockNonAdminActiveXInstall +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\AxInstaller +OnlyUseAXISForActiveXInstall +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +Security_zones_map_edit +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +Security_options_edit +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +Security_HKLM_only +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +CertificateRevocation +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +PreventIgnoreCertErrors +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +WarnOnBadCertRecving +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +EnableSSL3Fallback +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings +SecureProtocols +DWORD:2560 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3 +2301 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4 +2301 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap +UNCAsIntranet +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 +270C +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 +270C +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 +1201 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 +1C00 +DWORD:65536 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 +1C00 +DWORD:65536 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 +270C +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 +1201 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2001 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2102 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1802 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +160A +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1201 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1406 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1804 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2200 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1209 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1206 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1809 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2500 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2103 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1606 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2402 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2004 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1001 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1A00 +DWORD:65536 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2708 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1004 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +120b +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1407 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1409 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +270C +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1607 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2709 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2101 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +2301 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +1806 +DWORD:1 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +120c +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 +140C +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1608 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1201 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1001 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1607 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +120b +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1809 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1004 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1606 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1407 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +160A +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1406 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2102 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2004 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2200 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2000 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1402 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1803 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2402 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1400 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1A00 +DWORD:196608 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2001 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2500 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1409 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1C00 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1209 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +270C +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1206 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2708 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1802 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2103 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2709 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1405 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2101 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +2301 +DWORD:0 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1200 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1804 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +1806 +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +120c +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 +140C +DWORD:3 + +Computer +Software\Policies\Microsoft\Windows NT\Terminal Services +fDisableCdm +DWORD:0 + +; PARSING COMPLETED. +; ---------------------------------------------------------------------- \ No newline at end of file diff --git a/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/User/registry.txt b/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/User/registry.txt new file mode 100644 index 000000000..0a3d3517a --- /dev/null +++ b/modules/BOSH.Sysprep/cis-merge-2022/DomainSysvol/GPO/User/registry.txt @@ -0,0 +1,21 @@ +; ---------------------------------------------------------------------- +; PARSING User POLICY +; Source file: .\GPOBackup\DomainSysvol\GPO\User\registry.pol + +User +Software\Policies\Microsoft\Internet Explorer\Control Panel +FormSuggest Passwords +DWORD:1 + +User +Software\Policies\Microsoft\Internet Explorer\Main +FormSuggest PW Ask +SZ:no + +User +Software\Policies\Microsoft\Internet Explorer\Main +FormSuggest Passwords +SZ:no + +; PARSING COMPLETED. +; ---------------------------------------------------------------------- \ No newline at end of file diff --git a/modules/BOSH.Utils/BOSH.Utils.Tests.ps1 b/modules/BOSH.Utils/BOSH.Utils.Tests.ps1 index 23070af00..e0249ad59 100644 --- a/modules/BOSH.Utils/BOSH.Utils.Tests.ps1 +++ b/modules/BOSH.Utils/BOSH.Utils.Tests.ps1 @@ -2,6 +2,8 @@ BeforeAll { Remove-Module -Name BOSH.Utils -ErrorAction Ignore Import-Module ./BOSH.Utils.psm1 + $osVersion = "windows2022" + # As of now, this function only supports DWords and Strings. function Restore-RegistryState { @@ -410,14 +412,14 @@ Describe "BOSH.Utils" { Mock -ModuleName BOSH.Utils Write-Log { } } - It "Correctly detects Windows 2019" { - Mock -ModuleName BOSH.Utils Get-OSVersionString { "10.0.17763.410" } + It "Correctly detects Windows 2022" { + Mock -ModuleName BOSH.Utils Get-OSVersionString { "10.0.26100.4076" } $actualOSVersion = $null { Get-OSVersion | Set-Variable -Name "actualOSVersion" -Scope 1 } | Should -Not -Throw - $actualOsVersion | Should -eq "windows2019" + $actualOsVersion | Should -eq $osVersion - Assert-MockCalled Write-Log -Times 1 -Scope It -ParameterFilter { $Message -eq "Found OS version: Windows 2019" } -ModuleName BOSH.Utils + Assert-MockCalled Write-Log -Times 1 -Scope It -ParameterFilter { $Message -eq "Found OS version: Windows 2022" } -ModuleName BOSH.Utils Assert-MockCalled Get-OSVersionString -Times 1 -Scope It -ModuleName BOSH.Utils } diff --git a/modules/BOSH.Utils/BOSH.Utils.psm1 b/modules/BOSH.Utils/BOSH.Utils.psm1 index 1cbb57351..ff4d9c629 100644 --- a/modules/BOSH.Utils/BOSH.Utils.psm1 +++ b/modules/BOSH.Utils/BOSH.Utils.psm1 @@ -362,7 +362,12 @@ function Get-OSVersion try { $osVersion = Get-OSVersionString - if ($osVersion -match "10\.0\.17763\..+") + if ($osVersion -match "10\.0\.26100\..+") + { + Write-Log "Found OS version: Windows 2022" + "windows2022" + } + elseif ($osVersion -match "10\.0\.17763\..+") { Write-Log "Found OS version: Windows 2019" "windows2019" diff --git a/scripts/aws/setup_winrm.txt b/scripts/aws/setup_winrm.txt new file mode 100644 index 000000000..e69de29bb diff --git a/scripts/gcp/setup-winrm.ps1 b/scripts/gcp/setup-winrm.ps1 new file mode 100644 index 000000000..e69de29bb diff --git a/spec/fixtures/aws/amis/light-bosh-stemcell-1089.0-aws-xen-hvm-windows2019-go_agent-some-region-1.tgz b/spec/fixtures/aws/amis/light-bosh-stemcell-1089.0-aws-xen-hvm-windows2022-go_agent-some-region-1.tgz similarity index 100% rename from spec/fixtures/aws/amis/light-bosh-stemcell-1089.0-aws-xen-hvm-windows2019-go_agent-some-region-1.tgz rename to spec/fixtures/aws/amis/light-bosh-stemcell-1089.0-aws-xen-hvm-windows2022-go_agent-some-region-1.tgz diff --git a/spec/fixtures/aws/amis/light-bosh-stemcell-1089.0-aws-xen-hvm-windows2019-go_agent-some-region-2.tgz b/spec/fixtures/aws/amis/light-bosh-stemcell-1089.0-aws-xen-hvm-windows2022-go_agent-some-region-2.tgz similarity index 100% rename from spec/fixtures/aws/amis/light-bosh-stemcell-1089.0-aws-xen-hvm-windows2019-go_agent-some-region-2.tgz rename to spec/fixtures/aws/amis/light-bosh-stemcell-1089.0-aws-xen-hvm-windows2022-go_agent-some-region-2.tgz diff --git a/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2019-go_agent-some-region-1.tgz b/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2022-go_agent-some-region-1.tgz similarity index 100% rename from spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2019-go_agent-some-region-1.tgz rename to spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2022-go_agent-some-region-1.tgz diff --git a/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2019-go_agent-some-region-2.tgz b/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2022-go_agent-some-region-2.tgz similarity index 100% rename from spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2019-go_agent-some-region-2.tgz rename to spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2022-go_agent-some-region-2.tgz diff --git a/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2019-go_agent-some-region-3.tgz b/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2022-go_agent-some-region-3.tgz similarity index 100% rename from spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2019-go_agent-some-region-3.tgz rename to spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-aws-xen-hvm-windows2022-go_agent-some-region-3.tgz diff --git a/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-build.2-aws-xen-hvm-windows2019-go_agent-us-east-1.tgz b/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-build.2-aws-xen-hvm-windows2019-go_agent-us-east-1.tgz deleted file mode 100644 index cd87f4df5..000000000 Binary files a/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-build.2-aws-xen-hvm-windows2019-go_agent-us-east-1.tgz and /dev/null differ diff --git a/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-build.2-aws-xen-hvm-windows2022-go_agent-us-east-1.tgz b/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-build.2-aws-xen-hvm-windows2022-go_agent-us-east-1.tgz new file mode 100644 index 000000000..87cc108a1 Binary files /dev/null and b/spec/fixtures/aws/amis/light-bosh-stemcell-1200.3.1-build.2-aws-xen-hvm-windows2022-go_agent-us-east-1.tgz differ diff --git a/spec/integration/build/aws_spec.rb b/spec/integration/build/aws_spec.rb index 2c98a23cd..2712c4c0f 100644 --- a/spec/integration/build/aws_spec.rb +++ b/spec/integration/build/aws_spec.rb @@ -16,7 +16,7 @@ Rake::Task["build:aws"].reenable Rake::Task["build:aws_ami"].reenable - @os_version = "windows2019" + @os_version = "windows2022" @version = "1200.3.1-build.2" ENV["AMIS_DIR"] = @amis_dir diff --git a/spec/integration/build/azure_spec.rb b/spec/integration/build/azure_spec.rb index ad07ea90a..b5f14dc0e 100644 --- a/spec/integration/build/azure_spec.rb +++ b/spec/integration/build/azure_spec.rb @@ -35,7 +35,7 @@ it "should build an azure stemcell" do Dir.mktmpdir("azure-stemcell-test") do |tmpdir| - os_version = "windows2019" + os_version = "windows2022" version = "1200.0.1-build.7" ENV["CLIENT_ID"] = "some-azure_access_key" diff --git a/spec/integration/build/gcp_spec.rb b/spec/integration/build/gcp_spec.rb index 39595746d..c3677b8d8 100644 --- a/spec/integration/build/gcp_spec.rb +++ b/spec/integration/build/gcp_spec.rb @@ -31,7 +31,7 @@ it "should build a gcp stemcell" do Dir.mktmpdir("gcp-stemcell-test") do |tmpdir| - os_version = "windows2019" + os_version = "windows2022" version = "1200.3.1-build.2" ENV["ACCOUNT_JSON"] = {"project_id" => "some-project-id"}.to_json diff --git a/spec/packer/config/aws_spec.rb b/spec/packer/config/aws_spec.rb index 9e292f488..8545fc313 100644 --- a/spec/packer/config/aws_spec.rb +++ b/spec/packer/config/aws_spec.rb @@ -1,7 +1,7 @@ require "spec_helper" RSpec.describe Packer::Config::Aws do - let(:os) { "windows2019" } + let(:os) { "windows2022" } describe "builders" do before(:each) do @@ -146,7 +146,7 @@ ENV.delete("STEMCELL_DEPS_DIR") end - let(:build_version) { "2019.43.17-build.1" } + let(:build_version) { "2022.43.17-build.1" } let(:provisioners) do Packer::Config::Aws.new( @@ -186,8 +186,7 @@ {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Get-HotFix | Out-File -FilePath hotfixes.log -Encoding utf8"]}, {"type" => "file", "source" => "hotfixes.log", "destination" => "hotfixes.log", "direction" => "download"}, {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Remove-Account -User Provisioner"]}, - {"type" => "file", "source" => "../sshd/OpenSSH-Win64.zip", "destination" => "C:\\provision\\OpenSSH-Win64.zip"}, - {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Install-SSHD -SSHZipFile 'C:\\provision\\OpenSSH-Win64.zip'"]}, + {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Install-SSHD"]}, {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Enable-SSHD"]}, {"type" => "file", "source" => "build/agent.zip", "destination" => "C:\\provision\\agent.zip"}, {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Install-Agent -IaaS aws -agentZipPath 'C:\\provision\\agent.zip'"]}, @@ -224,7 +223,7 @@ aws_secret_key: "", region: "", output_directory: "some-output-directory", - os: "windows2019", + os: "windows2022", version: "", vm_prefix: "", mount_ephemeral_disk: true diff --git a/spec/packer/config/azure_spec.rb b/spec/packer/config/azure_spec.rb index 4d475a6dd..4fc099782 100644 --- a/spec/packer/config/azure_spec.rb +++ b/spec/packer/config/azure_spec.rb @@ -1,7 +1,7 @@ require "spec_helper" RSpec.describe Packer::Config::Azure do - let(:os) { "windows2019" } + let(:os) { "windows2022" } describe "builders" do before(:each) do @@ -14,7 +14,7 @@ Timecop.return end - let(:version) { "2019.9999" } + let(:version) { "2022.9999" } let(:builders) do Packer::Config::Azure.new( @@ -95,7 +95,7 @@ ENV.delete("STEMCELL_DEPS_DIR") end - let(:build_version) { "2019.43.17-build.1" } + let(:build_version) { "2022.43.17-build.1" } let(:provisioners) do Packer::Config::Azure.new( @@ -138,8 +138,7 @@ {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Get-HotFix | Out-File -FilePath hotfixes.log -Encoding utf8"]}, {"type" => "file", "source" => "hotfixes.log", "destination" => "hotfixes.log", "direction" => "download"}, {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Remove-Account -User Provisioner"]}, - {"type" => "file", "source" => "../sshd/OpenSSH-Win64.zip", "destination" => "C:\\provision\\OpenSSH-Win64.zip"}, - {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Install-SSHD -SSHZipFile 'C:\\provision\\OpenSSH-Win64.zip'"]}, + {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Install-SSHD"]}, {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Enable-SSHD"]}, {"type" => "file", "source" => "build/agent.zip", "destination" => "C:\\provision\\agent.zip"}, {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Install-Agent -IaaS azure -agentZipPath 'C:\\provision\\agent.zip'"]}, diff --git a/spec/packer/config/gcp_spec.rb b/spec/packer/config/gcp_spec.rb index f0636b002..c26682a06 100644 --- a/spec/packer/config/gcp_spec.rb +++ b/spec/packer/config/gcp_spec.rb @@ -1,7 +1,7 @@ require "spec_helper" RSpec.describe Packer::Config::Gcp do - let(:os) { "windows2019" } + let(:os) { "windows2022" } describe "builders" do before(:each) do @@ -25,9 +25,12 @@ output_directory: "", image_family: "some-image-family", os: os, - version: "", + version: "some.version", vm_prefix: "some-vm-prefix", - vm_type: "some-vm-type" + vm_type: "some-vm-type", + network: "some-network", + network_project_id: "some-project-id", + subnetwork: "subnet" ).builders } @@ -36,18 +39,18 @@ "type" => "googlecompute", "credentials_json" => "some-account-json", "project_id" => "some-project-id", - "tags" => ["winrm"], + "tags" => [], "source_image" => "some-source-image", "image_family" => "some-image-family", "zone" => "us-west1-c", - "disk_size" => 32, - "image_name" => "packer-#{Time.now.to_i}", + "disk_size" => 64, + "image_name" => "stemcell-windows-some-version-#{Time.now.strftime("%Y%m%d%H%M%S")}", "machine_type" => "some-vm-type", - "network" => nil, - "network_project_id" => nil, - "subnetwork" => nil, - "omit_external_ip" => false, - "use_internal_ip" => false, + "network" => "some-network", + "network_project_id" => "some-project-id", + "subnetwork" => "subnet", + "omit_external_ip" => true, + "use_internal_ip" => true, "communicator" => "winrm", "winrm_username" => "winrmuser", "winrm_use_ssl" => false, @@ -108,7 +111,10 @@ os: "", version: "", vm_prefix: "", - vm_type: "" + vm_type: "", + network: "", + network_project_id: "", + subnetwork: "" ).builders expect(builders[0]["metadata"]).to include( "name" => "packer-#{Time.now.to_i}" @@ -128,7 +134,7 @@ ENV.delete("STEMCELL_DEPS_DIR") end - let(:build_version) { "2019.43.17-build.1" } + let(:build_version) { "2022.43.17-build.1" } let(:provisioners) do Packer::Config::Gcp.new( @@ -167,8 +173,7 @@ {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Get-HotFix | Out-File -FilePath hotfixes.log -Encoding utf8"]}, {"type" => "file", "source" => "hotfixes.log", "destination" => "hotfixes.log", "direction" => "download"}, {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Remove-Account -User Provisioner"]}, - {"type" => "file", "source" => "../sshd/OpenSSH-Win64.zip", "destination" => "C:\\provision\\OpenSSH-Win64.zip"}, - {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Install-SSHD -SSHZipFile 'C:\\provision\\OpenSSH-Win64.zip'"]}, + {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Install-SSHD"]}, {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Enable-SSHD"]}, {"type" => "file", "source" => "build/agent.zip", "destination" => "C:\\provision\\agent.zip"}, {"type" => "powershell", "inline" => ["$ErrorActionPreference = \"Stop\";", "trap { $host.SetShouldExit(1) }", "Install-Agent -IaaS gcp -agentZipPath 'C:\\provision\\agent.zip'"]}, diff --git a/spec/packer/sysprep_script_generator_spec.rb b/spec/packer/sysprep_script_generator_spec.rb index 901f5af3d..339c2119f 100644 --- a/spec/packer/sysprep_script_generator_spec.rb +++ b/spec/packer/sysprep_script_generator_spec.rb @@ -29,6 +29,15 @@ ) end + context "installing openssh" do + let(:script) { generator.content(iaas: :gcp) } + + it "includes openssh stanza" do + expect(script).to include("Write-Log \"Install OpenSSH.Server\"") + expect(script).to include("Add-WindowsCapability -Online -Name (Get-WindowsCapability -Online -Name \"OpenSSH.Server*\" | ForEach-Object Name)") + end + end + context "for :gcp" do let(:script) { generator.content(iaas: :gcp) } diff --git a/spec/stemcell/builder/aws_spec.rb b/spec/stemcell/builder/aws_spec.rb index 327ca6fbf..d71b46244 100644 --- a/spec/stemcell/builder/aws_spec.rb +++ b/spec/stemcell/builder/aws_spec.rb @@ -15,7 +15,7 @@ end describe "build" do - let(:os) { "windows2019" } + let(:os) { "windows2022" } it "builds a stemcell tarball" do version = "1234.0" diff --git a/spec/stemcell/builder/azure_spec.rb b/spec/stemcell/builder/azure_spec.rb index ca60f9b20..c05ef7561 100644 --- a/spec/stemcell/builder/azure_spec.rb +++ b/spec/stemcell/builder/azure_spec.rb @@ -10,7 +10,7 @@ end end - let(:os) { "windows2019" } + let(:os) { "windows2022" } describe "build" do it "builds a stemcell tarball" do diff --git a/spec/stemcell/builder/gcp_spec.rb b/spec/stemcell/builder/gcp_spec.rb index 02d2b2261..4c62a3685 100644 --- a/spec/stemcell/builder/gcp_spec.rb +++ b/spec/stemcell/builder/gcp_spec.rb @@ -10,7 +10,7 @@ end end - let(:os) { "windows2019" } + let(:os) { "windows2022" } describe "build" do it "builds a stemcell tarball" do diff --git a/spec/stemcell/packager_spec.rb b/spec/stemcell/packager_spec.rb index 82c6ce2db..8ab8d080e 100644 --- a/spec/stemcell/packager_spec.rb +++ b/spec/stemcell/packager_spec.rb @@ -18,7 +18,7 @@ FileUtils.remove_entry_secure(@untar_dir) end - let(:os) { "windows2019" } + let(:os) { "windows2022" } describe "find_ovf_file" do it "returns the filename of the ovf file in directory" do diff --git a/stembuild/README.md b/stembuild/README.md index 63e8f377e..656381897 100644 --- a/stembuild/README.md +++ b/stembuild/README.md @@ -240,7 +240,6 @@ You will need to construct `assets/StemcellAutomation.zip`. This file represents **assets/StemcellAutomation.zip files:** | File | Source / Description | |-|-| -| OpenSSH-Win64.zip | https://github.com/PowerShell/Win32-OpenSSH/releases | | bosh-psmodules.zip | https://github.com/cloudfoundry/bosh-psmodules/tree/master/modules | | agent.zip | A zip constructed using various BOSH executables. See list of necessary files below. | | deps.json | A JSON file with the SHA256 checksums and optionally the version for each component in this zip. See format below. | @@ -261,9 +260,6 @@ You will need to construct `assets/StemcellAutomation.zip`. This file represents **deps.json format:** ```json { - "OpenSSH-Win64.zip": { - "sha": "SOME-SHA256" - }, "bosh-psmodules.zip": { "sha": "SOME-SHA256" }, @@ -279,7 +275,6 @@ You will need to construct `assets/StemcellAutomation.zip`. This file represents Once you have these files, run: ```bash -OPENSSH_ZIP="OpenSSH-Win64.zip" \ BOSH_PSMODULES_ZIP="bosh-psmodules.zip" \ AGENT_ZIP="agent.zip" \ DEPS_JSON="deps.json" \ diff --git a/stembuild/commandparser/package_stemcell_test.go b/stembuild/commandparser/package_stemcell_test.go index 8babbd7dc..a04041cdd 100644 --- a/stembuild/commandparser/package_stemcell_test.go +++ b/stembuild/commandparser/package_stemcell_test.go @@ -58,8 +58,8 @@ var _ = Describe("package_stemcell", func() { Describe("Execute", func() { BeforeEach(func() { - oSAndVersionGetter.GetVersionReturns("2019.2") - oSAndVersionGetter.GetOsReturns("2019") + oSAndVersionGetter.GetVersionReturns("2022.2") + oSAndVersionGetter.GetOsReturns("2022") }) It("packager is instantiated with expected vmdk source config", func() { @@ -126,8 +126,8 @@ var _ = Describe("package_stemcell", func() { Expect(packagerFactory.NewPackagerCallCount()).To(Equal(1)) _, actualOutputConfig, _, _ := packagerFactory.NewPackagerArgsForCall(0) Expect(actualOutputConfig.OutputDir).To(Equal("some_output_dir")) - Expect(actualOutputConfig.StemcellVersion).To(Equal("2019.2")) - Expect(actualOutputConfig.Os).To(Equal("2019")) + Expect(actualOutputConfig.StemcellVersion).To(Equal("2022.2")) + Expect(actualOutputConfig.Os).To(Equal("2022")) }) It("creates packager with correct stemcell patch version number when argument provided", func() { diff --git a/stembuild/construct/constructfakes/fake_iaas_client.go b/stembuild/construct/constructfakes/fake_iaas_client.go index 833854a2b..a0e90df01 100644 --- a/stembuild/construct/constructfakes/fake_iaas_client.go +++ b/stembuild/construct/constructfakes/fake_iaas_client.go @@ -35,6 +35,20 @@ type FakeIaasClient struct { makeDirectoryReturnsOnCall map[int]struct { result1 error } + RunStub func(string, string, string, []string) error + runMutex sync.RWMutex + runArgsForCall []struct { + arg1 string + arg2 string + arg3 string + arg4 []string + } + runReturns struct { + result1 error + } + runReturnsOnCall map[int]struct { + result1 error + } StartStub func(string, string, string, string, ...string) (string, error) startMutex sync.RWMutex startArgsForCall []struct { @@ -215,6 +229,75 @@ func (fake *FakeIaasClient) MakeDirectoryReturnsOnCall(i int, result1 error) { }{result1} } +func (fake *FakeIaasClient) Run(arg1 string, arg2 string, arg3 string, arg4 []string) error { + var arg4Copy []string + if arg4 != nil { + arg4Copy = make([]string, len(arg4)) + copy(arg4Copy, arg4) + } + fake.runMutex.Lock() + ret, specificReturn := fake.runReturnsOnCall[len(fake.runArgsForCall)] + fake.runArgsForCall = append(fake.runArgsForCall, struct { + arg1 string + arg2 string + arg3 string + arg4 []string + }{arg1, arg2, arg3, arg4Copy}) + stub := fake.RunStub + fakeReturns := fake.runReturns + fake.recordInvocation("Run", []interface{}{arg1, arg2, arg3, arg4Copy}) + fake.runMutex.Unlock() + if stub != nil { + return stub(arg1, arg2, arg3, arg4) + } + if specificReturn { + return ret.result1 + } + return fakeReturns.result1 +} + +func (fake *FakeIaasClient) RunCallCount() int { + fake.runMutex.RLock() + defer fake.runMutex.RUnlock() + return len(fake.runArgsForCall) +} + +func (fake *FakeIaasClient) RunCalls(stub func(string, string, string, []string) error) { + fake.runMutex.Lock() + defer fake.runMutex.Unlock() + fake.RunStub = stub +} + +func (fake *FakeIaasClient) RunArgsForCall(i int) (string, string, string, []string) { + fake.runMutex.RLock() + defer fake.runMutex.RUnlock() + argsForCall := fake.runArgsForCall[i] + return argsForCall.arg1, argsForCall.arg2, argsForCall.arg3, argsForCall.arg4 +} + +func (fake *FakeIaasClient) RunReturns(result1 error) { + fake.runMutex.Lock() + defer fake.runMutex.Unlock() + fake.RunStub = nil + fake.runReturns = struct { + result1 error + }{result1} +} + +func (fake *FakeIaasClient) RunReturnsOnCall(i int, result1 error) { + fake.runMutex.Lock() + defer fake.runMutex.Unlock() + fake.RunStub = nil + if fake.runReturnsOnCall == nil { + fake.runReturnsOnCall = make(map[int]struct { + result1 error + }) + } + fake.runReturnsOnCall[i] = struct { + result1 error + }{result1} +} + func (fake *FakeIaasClient) Start(arg1 string, arg2 string, arg3 string, arg4 string, arg5 ...string) (string, error) { fake.startMutex.Lock() ret, specificReturn := fake.startReturnsOnCall[len(fake.startArgsForCall)] diff --git a/stembuild/construct/vmconstruct.go b/stembuild/construct/vmconstruct.go index dba4cc83c..08530c111 100644 --- a/stembuild/construct/vmconstruct.go +++ b/stembuild/construct/vmconstruct.go @@ -71,7 +71,6 @@ func NewVMConstruct( scriptExecutor ScriptExecutorI, setupFlags []string, ) *VMConstruct { - return &VMConstruct{ ctx: ctx, remoteManager: remoteManager, @@ -114,6 +113,7 @@ type GuestManager interface { type IaasClient interface { UploadArtifact(vmInventoryPath, artifact, destination, username, password string) error MakeDirectory(vmInventoryPath, path, username, password string) error + Run(vmInventoryPath, username, password string, commandArgs []string) error Start(vmInventoryPath, username, password, command string, args ...string) (string, error) WaitForExit(vmInventoryPath, username, password, pid string) (int, error) IsPoweredOff(vmInventoryPath string) (bool, error) @@ -143,6 +143,13 @@ func (c *VMConstruct) PrepareVM() error { } c.messenger.PrintOut("\nAll files have been uploaded.\n") + c.messenger.PrintOut("\nInstalling OpenSSH on target VM...") + err = c.installOpenSSH() + if err != nil { + return err + } + c.messenger.PrintOut("OpenSSH install succeeded.\n") + c.messenger.PrintOut("\nAttempting to enable WinRM on the guest vm...") err = c.winRMEnabler.Enable() if err != nil { @@ -270,6 +277,12 @@ func (c *VMConstruct) isPoweredOff(duration time.Duration) error { return err } +func (c *VMConstruct) installOpenSSH() error { + const installOpenSSHCommand = `"Add-WindowsCapability -Online -Name (Get-WindowsCapability -Online -Name OpenSSH.Server* | ForEach-Object Name)"` + + return c.Client.Run(c.vmInventoryPath, c.vmUsername, c.vmPassword, []string{powershellExePath, installOpenSSHCommand}) +} + func EncodePowershellCommand(command []byte) string { runeCommand := []rune(string(command)) utf16Command := utf16.Encode(runeCommand) diff --git a/stembuild/construct/vmconstruct_test.go b/stembuild/construct/vmconstruct_test.go index f9c77f6fa..19f56bfc6 100644 --- a/stembuild/construct/vmconstruct_test.go +++ b/stembuild/construct/vmconstruct_test.go @@ -32,7 +32,7 @@ func (p *nonWaitingPoller) Poll(_ time.Duration, loopFunc func() (bool, error)) return nil } -var _ = Describe("construct_helpers", func() { +var _ = Describe("VMConstruct", func() { var ( outBuf *Buffer errBuf *Buffer @@ -125,7 +125,7 @@ var _ = Describe("construct_helpers", func() { Expect(vmConstruct.PrepareVM()).NotTo(Succeed()) Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) - Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(0)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(0)) }) It("it logs the attempt", func() { @@ -141,7 +141,7 @@ var _ = Describe("construct_helpers", func() { Expect(vmConstruct.PrepareVM()).To(Succeed()) Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) - Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) }) It("it logs success", func() { @@ -244,6 +244,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(0)) }) It("it logs the attempt", func() { @@ -261,7 +262,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) - Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) }) It("it logs success", func() { @@ -272,6 +273,71 @@ var _ = Describe("construct_helpers", func() { }) }) + Describe("it installs Microsoft's OpenSSH", func() { + Context("when it fails", func() { + var installOpenSshErr error + BeforeEach(func() { + installOpenSshErr = errors.New("fake-install-open-ssh-error") + fakeVcenterClient.RunReturns(installOpenSshErr) + }) + + It("returns the error", func() { + err := vmConstruct.PrepareVM() + Expect(err).To(Equal(installOpenSshErr)) + }) + + It("does not execute the next step", func() { + Expect(vmConstruct.PrepareVM()).NotTo(Succeed()) + + Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) + Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) + Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(0)) + }) + + It("it logs the attempt", func() { + Expect(vmConstruct.PrepareVM()).NotTo(Succeed()) + + Eventually(outBuf).Should(Say("\nInstalling OpenSSH on target VM...")) + Eventually(outBuf).ShouldNot(Say("\nInstalling OpenSSH on target VM...OpenSSH install succeeded.\n")) + }) + }) + + Context("when it succeeds", func() { + It("executes the next step", func() { + Expect(vmConstruct.PrepareVM()).To(Succeed()) + + Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) + Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) + Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) + }) + + It("invokes VCenterClient.Run() as expected", func() { + Expect(vmConstruct.PrepareVM()).To(Succeed()) + + expectedCommandArgs := []string{ + `C:\Windows\System32\WindowsPowerShell\V1.0\powershell.exe`, + `"Add-WindowsCapability -Online -Name (Get-WindowsCapability -Online -Name OpenSSH.Server* | ForEach-Object Name)"`, + } + + actualVmInventoryPath, actualVmUsername, actualVmPassword, actualCommandArgs := + fakeVcenterClient.RunArgsForCall(0) + + Expect(actualVmInventoryPath).To(Equal(vmInventoryPath)) + Expect(actualVmUsername).To(Equal(vmUsername)) + Expect(actualVmPassword).To(Equal(vmPassword)) + Expect(actualCommandArgs).To(Equal(expectedCommandArgs)) + }) + + It("it logs success", func() { + Expect(vmConstruct.PrepareVM()).To(Succeed()) + + Eventually(outBuf).Should(Say("\nInstalling OpenSSH on target VM...OpenSSH install succeeded.\n")) + }) + }) + }) + Describe("enables WinRM", func() { Context("when it fails", func() { var enableErr error @@ -332,6 +398,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(0)) @@ -351,6 +418,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) @@ -382,6 +450,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) @@ -402,6 +471,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) @@ -450,6 +520,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) @@ -471,6 +542,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) @@ -515,6 +587,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) @@ -537,6 +610,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) @@ -571,6 +645,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) @@ -594,6 +669,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) @@ -634,6 +710,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) @@ -668,6 +745,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) @@ -693,6 +771,7 @@ var _ = Describe("construct_helpers", func() { Expect(fakeVcenterClient.MakeDirectoryCallCount()).To(Equal(1)) Expect(fakeVcenterClient.UploadArtifactCallCount()).To(Equal(2)) + Expect(fakeVcenterClient.RunCallCount()).To(Equal(1)) Expect(fakeWinRMEnabler.EnableCallCount()).To(Equal(1)) Expect(fakeVMConnectionValidator.ValidateCallCount()).To(Equal(1)) Expect(fakeRemoteManager.ExtractArchiveCallCount()).To(Equal(1)) diff --git a/stembuild/go.mod b/stembuild/go.mod index 8187b1bf7..89470e023 100644 --- a/stembuild/go.mod +++ b/stembuild/go.mod @@ -7,7 +7,7 @@ require ( github.com/google/subcommands v1.2.0 github.com/masterzen/winrm v0.0.0-20260407182533-5570be7f80cf github.com/maxbrunsfeld/counterfeiter/v6 v6.12.2 - github.com/onsi/ginkgo/v2 v2.32.0 + github.com/onsi/ginkgo/v2 v2.32.1 github.com/onsi/gomega v1.42.1 github.com/packer-community/winrmcp v0.0.0-20221126162354-6e900dd2c68f github.com/pkg/errors v0.9.1 @@ -28,7 +28,7 @@ require ( github.com/go-task/slim-sprig/v3 v3.0.0 // indirect github.com/gofrs/uuid v4.4.0+incompatible // indirect github.com/google/go-cmp v0.7.0 // indirect - github.com/google/pprof v0.0.0-20260709232956-b9395ee17fa0 // indirect + github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3 // indirect github.com/google/uuid v1.6.0 // indirect github.com/hashicorp/go-cleanhttp v0.5.2 // indirect github.com/hashicorp/go-uuid v1.0.3 // indirect @@ -45,13 +45,13 @@ require ( github.com/onsi/ginkgo v1.16.5 // indirect github.com/rogpeppe/go-internal v1.14.1 // indirect github.com/tidwall/transform v0.0.0-20201103190739-32f242e2dbde // indirect - go.yaml.in/yaml/v3 v3.0.4 // indirect - golang.org/x/crypto v0.54.0 // indirect - golang.org/x/mod v0.38.0 // indirect - golang.org/x/net v0.57.0 // indirect + go.yaml.in/yaml/v3 v3.0.5 // indirect + golang.org/x/crypto v0.55.0 // indirect + golang.org/x/mod v0.40.0 // indirect + golang.org/x/net v0.58.0 // indirect golang.org/x/sync v0.22.0 // indirect - golang.org/x/text v0.40.0 // indirect - golang.org/x/tools v0.48.0 // indirect + golang.org/x/text v0.41.0 // indirect + golang.org/x/tools v0.49.0 // indirect google.golang.org/protobuf v1.36.7 // indirect ) diff --git a/stembuild/go.sum b/stembuild/go.sum index 3c25da6a2..90304db61 100644 --- a/stembuild/go.sum +++ b/stembuild/go.sum @@ -54,8 +54,8 @@ github.com/google/go-cmp v0.3.1/go.mod h1:8QqcDgzrUqlUb/G2PQTWiueGozuR1884gddMyw github.com/google/go-cmp v0.4.0/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE= github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8= github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU= -github.com/google/pprof v0.0.0-20260709232956-b9395ee17fa0 h1:du0WGc8xSKq/++e0cglxhS/mXVqsR7+c7jLEi5Vqduw= -github.com/google/pprof v0.0.0-20260709232956-b9395ee17fa0/go.mod h1:MxpfABSjhmINe3F1It9d+8exIHFvUqtLIRCdOGNXqiI= +github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3 h1:LMLX+LgTNWpfvCBdFebv6EsYotImrt/Ppc5cXIriCSo= +github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3/go.mod h1:jl5iWTm0/hd5PjEYEOuwAJ57L/CibdZfrqZ5XA5GrCk= github.com/google/subcommands v1.2.0 h1:vWQspBTo2nEqTUFita5/KeEWlUL8kQObDFbub/EN9oE= github.com/google/subcommands v1.2.0/go.mod h1:ZjhPrFU+Olkh9WazFPsl27BQ4UPiG37m3yTrtFlrHVk= github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0= @@ -107,8 +107,8 @@ github.com/onsi/ginkgo v1.6.0/go.mod h1:lLunBs/Ym6LB5Z9jYTR76FiuTmxDTDusOGeTQH+W github.com/onsi/ginkgo v1.12.1/go.mod h1:zj2OWP4+oCPe1qIXoGWkgMRwljMUYCdkwsT2108oapk= github.com/onsi/ginkgo v1.16.5 h1:8xi0RTUf59SOSfEtZMvwTvXYMzG4gV23XVHOZiXNtnE= github.com/onsi/ginkgo v1.16.5/go.mod h1:+E8gABHa3K6zRBolWtd+ROzc/U5bkGt0FwiG042wbpU= -github.com/onsi/ginkgo/v2 v2.32.0 h1:Hw7s2pVrQo/8Yz5N77qdnpHaoc+c6cC9WIV1Jce+J6E= -github.com/onsi/ginkgo/v2 v2.32.0/go.mod h1:+aXOY+vzZ5mu2iI2HpTZUPmM//oQfsNFX6gU9kNcA44= +github.com/onsi/ginkgo/v2 v2.32.1 h1:6tlvcDm/3sE8lGJbZ4+d4mO3RLy24/tQWOFzVSQNIfw= +github.com/onsi/ginkgo/v2 v2.32.1/go.mod h1:+aXOY+vzZ5mu2iI2HpTZUPmM//oQfsNFX6gU9kNcA44= github.com/onsi/gomega v1.7.1/go.mod h1:XdKZgCCFLUoM/7CFJVPcG8C1xQ1AJ0vpAezJrB7JYyY= github.com/onsi/gomega v1.10.1/go.mod h1:iN09h71vgCQne3DLsj+A5owkum+a2tYe+TOCB1ybHNo= github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I= @@ -145,19 +145,19 @@ github.com/vmware/govmomi v0.55.1 h1:7FW6VXIdKe/7AXftBoFTHaf0UO8Kdl84tIjothNDlZI github.com/vmware/govmomi v0.55.1/go.mod h1:QR6UoTHdmvT5XvdomNKwyi7VPOnrE0QZxjPBJ0mWWQs= github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY= -go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc= -go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg= +go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw= +go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg= golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto= golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= golang.org/x/crypto v0.6.0/go.mod h1:OFC/31mSvZgRz0V1QTNCzfAI1aIRzbiufJtkMIlEp58= -golang.org/x/crypto v0.54.0 h1:YLIA59K4fiNzHzjnZt2tUJQjQtUWfWbeHBqKtk3eScw= -golang.org/x/crypto v0.54.0/go.mod h1:KWL8ny2AZdGR2cWmzeHrp2azQPGogOv+HeQaVEXC2dk= +golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= +golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4= -golang.org/x/mod v0.38.0 h1:MECBjubtXD7yj4HrhIUcywNaGeNVUdfVnxmPajOk4yk= -golang.org/x/mod v0.38.0/go.mod h1:V6Xz0pq8TQ3dGqVQ1FVHuelZpAL0uNhSkk9ogYP3c40= +golang.org/x/mod v0.40.0 h1:hUv+3cXcdRHz08UmSiOob7sadHig73uo5bkXxQ/tvUs= +golang.org/x/mod v0.40.0/go.mod h1:0/weTWkPWGBikyTWAX3dkjVztMmBA5hM0DH6BElSupE= golang.org/x/net v0.0.0-20180906233101-161cd47e91fd/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= @@ -168,8 +168,8 @@ golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c= golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs= golang.org/x/net v0.7.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs= -golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE= -golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU= +golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To= +golang.org/x/net v0.58.0/go.mod h1:YwCddHnFlT7eLQqVprV19OnhLGtc5xOKgE0RyqgfWAU= golang.org/x/sync v0.0.0-20180314180146-1d60e4601c6f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= @@ -199,14 +199,14 @@ golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ= golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= -golang.org/x/text v0.40.0 h1:Ub2Z6/xjgF1WrYQz2nuITOEegKFtiIy+rieRJ5lHZKs= -golang.org/x/text v0.40.0/go.mod h1:hpnzDAfGV753zIKo+wk3u1bVKCGPbrnF7+7LBF/UHVY= +golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8= +golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M= golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= golang.org/x/tools v0.0.0-20201224043029-2b0845dc783e/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc= -golang.org/x/tools v0.48.0 h1:3+hClM1aLL5mjMKm5ovokw9epgRXPuu2tILgismM6RE= -golang.org/x/tools v0.48.0/go.mod h1:08xX0orndb/F7jJxGDicx061tyd5pcMto75YMAXr6lk= +golang.org/x/tools v0.49.0 h1:3NI7VXzL9+1WZD52Dx2ttoPwD5DWrFGpl9mFZDlmisI= +golang.org/x/tools v0.49.0/go.mod h1:SJNXV9DBKT0UbdttsQjbfJlAE/q+y36++zo3uL3N0Oo= golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= diff --git a/stembuild/iaas_cli/iaas_clients/vcenter_client.go b/stembuild/iaas_cli/iaas_clients/vcenter_client.go index a84b108f7..6b8054677 100644 --- a/stembuild/iaas_cli/iaas_clients/vcenter_client.go +++ b/stembuild/iaas_cli/iaas_clients/vcenter_client.go @@ -166,6 +166,23 @@ func (c *VcenterClient) IsPoweredOff(vmInventoryPath string) (bool, error) { return false, nil } +func (c *VcenterClient) Run(vmInventoryPath, username, password string, commandAndArgs []string) error { + command := commandAndArgs[0] + args := commandAndArgs[1:] + pid, err := c.Start(vmInventoryPath, username, password, command, args...) + if err != nil { + return fmt.Errorf("vcenter_client - failed to start '%v': %s", commandAndArgs, err) + } + exitCode, err := c.WaitForExit(vmInventoryPath, username, password, pid) + if err != nil { + return fmt.Errorf("vcenter_client - failed to wait for '%v' (pid %s): %s", commandAndArgs, pid, err) + } + if exitCode != 0 { + return fmt.Errorf("vcenter_client - '%v' exited with '%d'", commandAndArgs, exitCode) + } + return nil +} + func (c *VcenterClient) Start(vmInventoryPath, username, password, command string, args ...string) (string, error) { cmdArgs := c.buildGovcCommand(append([]string{"guest.start", "-l", vmCredentials(username, password), "-vm", vmInventoryPath, command}, args...)...) pid, exitCode, err := c.Runner.RunWithOutput(cmdArgs) diff --git a/stembuild/iaas_cli/iaas_clients/vcenter_client_test.go b/stembuild/iaas_cli/iaas_clients/vcenter_client_test.go index 5556fa683..b9b6ac4d0 100644 --- a/stembuild/iaas_cli/iaas_clients/vcenter_client_test.go +++ b/stembuild/iaas_cli/iaas_clients/vcenter_client_test.go @@ -372,6 +372,66 @@ ethernet-0 VirtualE1000e internal-network }) }) + Describe("Run", func() { + var commandArgs []string + const samplePsOutput = `{"ProcessInfo":[{"Name":"fake-command","Pid":1234,"Owner":"user","CmdLine":"fake-command fake-arg1","StartTime":"2024-01-01T00:00:00Z","EndTime":"2024-01-01T00:00:01Z","ExitCode":0}]}` + const samplePsOutputNonZero = `{"ProcessInfo":[{"Name":"fake-command","Pid":1234,"Owner":"user","CmdLine":"fake-command fake-arg1","StartTime":"2024-01-01T00:00:00Z","EndTime":"2024-01-01T00:00:01Z","ExitCode":42}]}` + + BeforeEach(func() { + commandArgs = []string{"fake-command", "fake-arg1", "fake-arg2", "fake-arg3"} + }) + + It("starts the command via guest.start and waits for exit via guest.ps", func() { + runner.RunWithOutputReturnsOnCall(0, "1234\n", 0, nil) + runner.RunWithOutputReturnsOnCall(1, samplePsOutput, 0, nil) + + err := vcenterClient.Run("validVMPath", "user", "pass", commandArgs) + Expect(err).To(Not(HaveOccurred())) + + Expect(runner.RunWithOutputCallCount()).To(Equal(2)) + + startArgs := runner.RunWithOutputArgsForCall(0) + expectedStartArgs := []string{"guest.start", "-u", vcenterAuthUrl(vcenterUsername, vcenterPassword, vcenterUrl), "-l", "user:pass", "-vm", "validVMPath", "fake-command", "fake-arg1", "fake-arg2", "fake-arg3"} + Expect(startArgs).To(Equal(expectedStartArgs)) + + psArgs := runner.RunWithOutputArgsForCall(1) + expectedPsArgs := []string{"guest.ps", "-u", vcenterAuthUrl(vcenterUsername, vcenterPassword, vcenterUrl), "-l", "user:pass", "-vm", "validVMPath", "-p", "1234", "-X", "-json"} + Expect(psArgs).To(Equal(expectedPsArgs)) + }) + + Context("when the guest program exits with a non-zero exit code", func() { + It("returns an error", func() { + runner.RunWithOutputReturnsOnCall(0, "1234\n", 0, nil) + runner.RunWithOutputReturnsOnCall(1, samplePsOutputNonZero, 0, nil) + + err := vcenterClient.Run("validVMPath", "user", "pass", commandArgs) + Expect(err).To(HaveOccurred()) + Expect(err.Error()).To(Equal(fmt.Sprintf("vcenter_client - '%v' exited with '%d'", commandArgs, 42))) + }) + }) + + Context("when guest.start fails", func() { + It("returns an error", func() { + runner.RunWithOutputReturnsOnCall(0, "", 0, errors.New("start-error")) + + err := vcenterClient.Run("validVMPath", "user", "pass", commandArgs) + Expect(err).To(HaveOccurred()) + Expect(err.Error()).To(Equal(fmt.Sprintf("vcenter_client - failed to start '%v': vcenter_client - failed to run 'fake-command': start-error", commandArgs))) + }) + }) + + Context("when guest.ps fails while waiting for exit", func() { + It("returns an error", func() { + runner.RunWithOutputReturnsOnCall(0, "1234\n", 0, nil) + runner.RunWithOutputReturnsOnCall(1, "", 0, errors.New("ps-error")) + + err := vcenterClient.Run("validVMPath", "user", "pass", commandArgs) + Expect(err).To(HaveOccurred()) + Expect(err.Error()).To(Equal(fmt.Sprintf("vcenter_client - failed to wait for '%v' (pid 1234): vcenter_client - failed to fetch exit code for PID 1234: ps-error", commandArgs))) + }) + }) + }) + Describe("Start", func() { It("runs the command on the vm", func() { runner.RunWithOutputReturns("1856\n", 0, nil) // govc add '\n' to the output diff --git a/stembuild/integration/construct/construct_test.go b/stembuild/integration/construct/construct_test.go index bac5f8f18..ec01e5108 100644 --- a/stembuild/integration/construct/construct_test.go +++ b/stembuild/integration/construct/construct_test.go @@ -16,7 +16,7 @@ import ( const ( constructOutputTimeout = 60 * time.Second - shutdownTimeout = 5 * time.Minute + shutdownTimeout = 8 * time.Minute ) var _ = Describe("stembuild construct", func() { diff --git a/stembuild/stemcell-automation/AutomationHelpers.Tests.ps1 b/stembuild/stemcell-automation/AutomationHelpers.Tests.ps1 index f8f6ea063..49057211a 100644 --- a/stembuild/stemcell-automation/AutomationHelpers.Tests.ps1 +++ b/stembuild/stemcell-automation/AutomationHelpers.Tests.ps1 @@ -348,9 +348,7 @@ Describe "AutomationHelpers" { { InstallOpenSSH } | Should -Not -Throw - Should -Invoke -ModuleName AutomationHelpers -CommandName Install-SSHD -Times 1 -ParameterFilter { - $SSHZipFile -eq ".\OpenSSH-Win64.zip" - } + Should -Invoke -ModuleName AutomationHelpers -CommandName Install-SSHD -Times 1 Should -Invoke -ModuleName AutomationHelpers -CommandName Write-Log -Times 1 -ParameterFilter { $Message -eq "OpenSSH successfully installed" } @@ -1112,179 +1110,36 @@ Describe "AutomationHelpers" { } } - Describe "Enable-SSHD" { + Describe "EnableOpenSSH" { BeforeAll { - function CreateFakeOpenSSHZip - { - param([string]$dir, [string]$installScriptSpyStatus, [string]$fakeZipPath) - - mkdir "$dir\OpenSSH-Win64" - $installSpyBehavior = "echo installed > $installScriptSpyStatus" - Write-Output $installSpyBehavior > "$dir\OpenSSH-Win64\install-sshd.ps1" - Write-Output "fake sshd" > "$dir\OpenSSH-Win64\sshd.exe" - - Compress-Archive -Force -Path "$dir\OpenSSH-Win64" -DestinationPath $fakeZipPath - } + Mock -ModuleName AutomationHelpers -CommandName Enable-SSHD { } } - BeforeEach { - Mock -ModuleName AutomationHelpers -CommandName Set-Service { } - Mock -ModuleName AutomationHelpers -CommandName Invoke-LGPO { } - - $guid = $( New-Guid ).Guid - $TMP_DIR = "$env:TEMP\BOSH.SSH.Tests-$guid" - - $FAKE_ZIP = "$TMP_DIR\OpenSSH-TestFake.zip" - $INSTALL_SCRIPT_SPY_STATUS = "$TMP_DIR\install-script-status" + It "executes the Enable-SSHD powershell cmdlet" { + Mock -ModuleName AutomationHelpers -CommandName Enable-SSHD { } - CreateFakeOpenSSHZip -dir $TMP_DIR -installScriptSpyStatus $INSTALL_SCRIPT_SPY_STATUS -fakeZipPath $FAKE_ZIP + { EnableOpenSSH } | Should -Not -Throw - mkdir -p "$TMP_DIR\Windows\Temp" - Write-Output "fake LGPO" > "$TMP_DIR\Windows\LGPO.exe" - - $ORIGINAL_WINDIR = $env:WINDIR - $env:WINDIR = "$TMP_DIR\Windows" - - $ORIGINAL_PROGRAMDATA = $env:ProgramData - $env:PROGRAMDATA = "$TMP_DIR\ProgramData" - } - - AfterEach { - Remove-Item $TMP_DIR -Recurse -ErrorAction Ignore - $env:WINDIR = $ORIGINAL_WINDIR - $env:PROGRAMDATA = $ORIGINAL_PROGRAMDATA - } - - It "sets the startup type of sshd to automatic" { - Mock -ModuleName AutomationHelpers -CommandName Set-Service { } -Verifiable -ParameterFilter { - $Name -eq "sshd" -and $StartupType -eq "Automatic" + Should -Invoke -ModuleName AutomationHelpers -CommandName Enable-SSHD -Times 1 + Should -Invoke -ModuleName AutomationHelpers -CommandName Write-Log -Times 1 -ParameterFilter { + $Message -eq "OpenSSH successfully installed" } - - { Enable-SSHD -SSHZipFile $FAKE_ZIP } | Should -Not -Throw - - Should -InvokeVerifiable } - It "sets the startup type of ssh-agent to automatic" { - Mock -ModuleName AutomationHelpers -CommandName Set-Service { } -Verifiable -ParameterFilter { - $Name -eq "ssh-agent" -and $StartupType -eq "Automatic" + It "fails gracefully when Enable-SSHD powershell cmdlet fails" { + Mock -ModuleName AutomationHelpers -CommandName Enable-SSHD { + throw "Something terrible happened while attempting to execute Enable-SSHD" } - { Enable-SSHD -SSHZipFile $FAKE_ZIP } | Should -Not -Throw - - Should -InvokeVerifiable - } + { EnableOpenSSH } | Should -Throw "Something terrible happened while attempting to execute Enable-SSHD" - It "sets up firewall when ssh not already set up" { - Mock -ModuleName AutomationHelpers -CommandName Get-NetFirewallRule { - return [ordered]@{ - "Name" = "{3c06039b-ece1-4da3-8ece-255894975894}" - "DisplayName" = "NTP" - "Description" = "" - "DisplayGroup" = "" - "Group" = "" - "Enabled" = "True" - "Profile" = "Any" - "Platform" = "{}" - "Direction" = "Outbound" - "Action" = "Allow" - "EdgeTraversalPolicy" = "Block" - "LooseSourceMapping" = "False" - "LocalOnlyMapping" = "False" - "Owner" = "" - "PrimaryStatus" = "OK" - "Status" = "The rule was parsed successfully from the store. (65536)" - "EnforcementStatus" = "NotApplicable" - "PolicyStoreSource" = "PersistentStore" - "PolicyStoreSourceType" = "Local" - } - } - Mock -ModuleName AutomationHelpers -CommandName New-NetFirewallRule { } - - { Enable-SSHD -SSHZipFile $FAKE_ZIP } | Should -Not -Throw - - Should -Invoke -ModuleName AutomationHelpers -CommandName New-NetFirewallRule -Times 1 - } - - It "doesn't set up firewall when ssh is already set up " { - Mock -ModuleName AutomationHelpers -CommandName Get-NetFirewallRule { - return [ordered]@{ - "Name" = "{ E02857AB-8EA8-4358-8119-ED7D20DA7712 }" - "DisplayName" = "SSH" - "Description" = "" - "DisplayGroup" = "" - "Group" = "" - "Enabled" = "True" - "Profile" = "Any" - "Platform" = "{ }" - "Direction" = "Inbound" - "Action" = "Allow" - "EdgeTraversalPolicy" = "Block" - "LooseSourceMapping" = "False" - "LocalOnlyMapping" = "False" - "Owner" = "" - "PrimaryStatus" = "OK" - "Status" = "The rule was parsed successfully from the store. (65536)" - "EnforcementStatus" = "NotApplicable" - "PolicyStoreSource" = "PersistentStore" - "PolicyStoreSourceType" = "Local" - } - } - Mock -ModuleName AutomationHelpers -CommandName New-NetFirewallRule { } - - { Enable-SSHD -SSHZipFile $FAKE_ZIP } | Should -Not -Throw - - Should -Invoke -ModuleName AutomationHelpers -CommandName New-NetFirewallRule -Times 0 - } - - It "Generates inf and invokes LGPO if LGPO exists" { - Mock -ModuleName AutomationHelpers -CommandName Invoke-LGPO -Verifiable -ParameterFilter { - $LGPOPath -eq "$TMP_DIR\Windows\LGPO.exe" -and $InfFilePath -eq "$TMP_DIR\Windows\Temp\enable-ssh.inf" + Should -Invoke -ModuleName AutomationHelpers -CommandName Write-Log -Times 1 -ParameterFilter { + $Message -eq "Something terrible happened while attempting to execute Enable-SSHD" } - - { Enable-SSHD -SSHZipFile $FAKE_ZIP } | Should -Not -Throw - - Should -InvokeVerifiable - } - - It "Skips LGPO if LGPO.exe not found" { - rm "$TMP_DIR\Windows\LGPO.exe" - - { Enable-SSHD -SSHZipFile $FAKE_ZIP } | Should -Not -Throw - - Should -Invoke -ModuleName AutomationHelpers -CommandName Invoke-LGPO -Times 0 - } - - Context "When LGPO executable fails" { - It "Throws an appropriate error" { - Mock -ModuleName AutomationHelpers -CommandName Invoke-LGPO { throw "some error" } -Verifiable -ParameterFilter { - $LGPOPath -eq "$TMP_DIR\Windows\LGPO.exe" -and $InfFilePath -eq "$TMP_DIR\Windows\Temp\enable-ssh.inf" - } - - { Enable-SSHD -SSHZipFile $FAKE_ZIP } | Should -Throw "LGPO.exe failed with: some error*" - - Should -InvokeVerifiable + Should -Invoke -ModuleName AutomationHelpers -CommandName Write-Log -Times 1 -ParameterFilter { + $Message -eq "Failed to execute Enable-SSHD powershell cmdlet. See 'c:\provision\log.log' for more info." } } - - It "removes existing SSH keys" { - New-Item -ItemType Directory -Path "$TMP_DIR\ProgramData\ssh" -ErrorAction Ignore - Write-Output "delete" > "$TMP_DIR\ProgramData\ssh\ssh_host_1" - Write-Output "delete" > "$TMP_DIR\ProgramData\ssh\ssh_host_2" - Write-Output "delete" > "$TMP_DIR\ProgramData\ssh\ssh_host_3" - Write-Output "ignore" > "$TMP_DIR\ProgramData\ssh\not_ssh_host_4" - - { Enable-SSHD -SSHZipFile $FAKE_ZIP } | Should -Not -Throw - - $numHosts = (Get-ChildItem "$TMP_DIR\ProgramData\ssh\").count - $numHosts | Should -eq 1 - } - - It "creates empty ssh program dir if it doesn't exist" { - { Enable-SSHD -SSHZipFile $FAKE_ZIP } | Should -Not -Throw - - { Test-Path "$TMP_DIR\ProgramData\ssh" } | Should -eq $True - } } Describe "Extract-LGPO" { diff --git a/stembuild/stemcell-automation/AutomationHelpers.psm1 b/stembuild/stemcell-automation/AutomationHelpers.psm1 index 8e6c7eedf..7aa0218fe 100644 --- a/stembuild/stemcell-automation/AutomationHelpers.psm1 +++ b/stembuild/stemcell-automation/AutomationHelpers.psm1 @@ -34,7 +34,7 @@ function Setup InstallOpenSSH Extract-LGPO Install-SecurityPoliciesAndRegistries - Enable-SSHD + EnableOpenSSH InstallCFFeatures RemoveAvailableWindowsFeatures @@ -167,7 +167,7 @@ function InstallOpenSSH { try { - Install-SSHD -SSHZipFile ".\OpenSSH-Win64.zip" + Install-SSHD Write-Log "OpenSSH successfully installed" } catch [Exception] @@ -378,7 +378,11 @@ function Validate-OSVersion try { $osVersion = Get-OSVersionString - if ($osVersion -match "10\.0\.17763\..+") + if ($osVersion -match "10\.0\.20348\..+") + { + Write-Log "Found correct OS version: Windows Server 2022" + } + elseif ($osVersion -match "10\.0\.17763\..+") { Write-Log "Found correct OS version: Windows Server 2019" } @@ -406,64 +410,19 @@ function Remove-SSHKeys Pop-Location } -function Invoke-LGPO +function EnableOpenSSH { - param ( - [string]$LGPOPath = $( Throw "Provide LGPO path" ), - [string]$InfFilePath = $( Throw "Provide Inf file path" ) - ) - & $LGPOPath /s $InfFilePath -} - -function Enable-SSHD -{ - if ((Get-NetFirewallRule | where { $_.DisplayName -ieq 'SSH' }) -eq $null) - { - "Creating firewall rule for SSH" - New-NetFirewallRule -Protocol TCP -LocalPort 22 -Direction Inbound -Action Allow -DisplayName SSH - } - else - { - "Firewall rule for SSH already exists" - } - - $InfFilePath = "$env:WINDIR\Temp\enable-ssh.inf" - - $InfFileContents = @' -[Unicode] -Unicode=yes -[Version] -signature=$CHICAGO$ -Revision=1:w -[Registry Values] -[System Access] -[Privilege Rights] -SeDenyNetworkLogonRight=*S-1-5-32-546 -SeAssignPrimaryTokenPrivilege=*S-1-5-19,*S-1-5-20,*S-1-5-80-3847866527-469524349-687026318-516638107-1125189541 -'@ - $LGPOPath = "$env:WINDIR\LGPO.exe" - if (Test-Path $LGPOPath) + try { - Out-File -FilePath $InfFilePath -Encoding unicode -InputObject $InfFileContents -Force - try - { - Invoke-LGPO -LGPOPath $LGPOPath -InfFilePath $InfFilePath - } - catch - { - throw "LGPO.exe failed with: $_.Exception.Message" - } + Enable-SSHD + Write-Log "OpenSSH successfully installed" } - else + catch [Exception] { - "Did not find $LGPOPath. Assuming existing security policies are sufficient to support ssh." + Write-Log $_.Exception.Message + Write-Log "Failed to execute Enable-SSHD powershell cmdlet. See 'c:\provision\log.log' for more info." + throw $_.Exception } - - Set-Service -Name sshd -StartupType Automatic - # ssh-agent is not the same as ssh-agent in *nix openssh - Set-Service -Name ssh-agent -StartupType Automatic - - Remove-SSHKeys } function Install-SecurityPoliciesAndRegistries diff --git a/stembuild/vendor/github.com/onsi/ginkgo/v2/CHANGELOG.md b/stembuild/vendor/github.com/onsi/ginkgo/v2/CHANGELOG.md index 10e608564..4d1ed9523 100644 --- a/stembuild/vendor/github.com/onsi/ginkgo/v2/CHANGELOG.md +++ b/stembuild/vendor/github.com/onsi/ginkgo/v2/CHANGELOG.md @@ -1,3 +1,8 @@ +## 2.32.1 + +### Fixes +- Defer AfterAll until repeated spec completes [e647b3b] + ## 2.32.0 `-fd` generate RSpec-style documentation output. Thank @woodie ! diff --git a/stembuild/vendor/github.com/onsi/ginkgo/v2/internal/group.go b/stembuild/vendor/github.com/onsi/ginkgo/v2/internal/group.go index 5e6611334..781adf6fa 100644 --- a/stembuild/vendor/github.com/onsi/ginkgo/v2/internal/group.go +++ b/stembuild/vendor/github.com/onsi/ginkgo/v2/internal/group.go @@ -211,6 +211,21 @@ func (g *group) isLastSpecWithPair(specID uint, pair runOncePair) bool { return lastSpecID == specID } +func (g *group) willRunAnotherAttempt(isFinalAttempt bool) bool { + if isFinalAttempt { + return false + } + + if g.suite.currentSpecReport.MaxMustPassRepeatedly > 0 { + return g.suite.currentSpecReport.State.Is(types.SpecStatePassed) + } + if g.suite.currentSpecReport.MaxFlakeAttempts > 0 { + return g.suite.currentSpecReport.State.Is(types.SpecStateFailureStates) + } + + return false +} + func (g *group) attemptSpec(isFinalAttempt bool, spec Spec) bool { failedInARunOnceBefore := false pairs := g.runOncePairs[spec.SubjectID()] @@ -280,10 +295,11 @@ func (g *group) attemptSpec(isFinalAttempt bool, spec Spec) bool { } // it's our last chance to run if we're the last spec for our oncePair isLastSpecWithPair := g.isLastSpecWithPair(spec.SubjectID(), pair) + willRunAnotherAttempt := g.willRunAnotherAttempt(isFinalAttempt) switch g.suite.currentSpecReport.State { case types.SpecStatePassed: //this attempt is passing... - return isLastSpecWithPair //...we should run-once if we'this is our last chance + return isLastSpecWithPair && !willRunAnotherAttempt //...we should run-once if this is our last chance case types.SpecStateSkipped: //the spec was skipped by the user... if isLastSpecWithPair { return true //...we're the last spec, so we should run the AfterNode @@ -292,7 +308,7 @@ func (g *group) attemptSpec(isFinalAttempt bool, spec Spec) bool { return true //...or, a run-once node at our nesting level was skipped which means this is our last chance to run } case types.SpecStateFailed, types.SpecStatePanicked, types.SpecStateTimedout: // the spec has failed... - if isFinalAttempt { + if !willRunAnotherAttempt { if g.continueOnFailure { return isLastSpecWithPair || failedInARunOnceBefore //...we're configured to continue on failures - so we should only run if we're the last spec for this pair or if we failed in a runOnceBefore (which means we _are_ the last spec to run) } else { diff --git a/stembuild/vendor/github.com/onsi/ginkgo/v2/types/version.go b/stembuild/vendor/github.com/onsi/ginkgo/v2/types/version.go index dc28324c1..177baed9b 100644 --- a/stembuild/vendor/github.com/onsi/ginkgo/v2/types/version.go +++ b/stembuild/vendor/github.com/onsi/ginkgo/v2/types/version.go @@ -1,3 +1,3 @@ package types -const VERSION = "2.32.0" +const VERSION = "2.32.1" diff --git a/stembuild/vendor/go.yaml.in/yaml/v3/parserc.go b/stembuild/vendor/go.yaml.in/yaml/v3/parserc.go index 25fe82363..f35829db4 100644 --- a/stembuild/vendor/go.yaml.in/yaml/v3/parserc.go +++ b/stembuild/vendor/go.yaml.in/yaml/v3/parserc.go @@ -226,9 +226,9 @@ func yaml_parser_state_machine(parser *yaml_parser_t, event *yaml_event_t) bool } // Parse the production: -// stream ::= STREAM-START implicit_document? explicit_document* STREAM-END // -// ************ +// stream ::= STREAM-START implicit_document? explicit_document* STREAM-END +// ************ func yaml_parser_parse_stream_start(parser *yaml_parser_t, event *yaml_event_t) bool { token := peek_token(parser) if token == nil { @@ -249,13 +249,11 @@ func yaml_parser_parse_stream_start(parser *yaml_parser_t, event *yaml_event_t) } // Parse the productions: -// implicit_document ::= block_node DOCUMENT-END* -// -// * // -// explicit_document ::= DIRECTIVE* DOCUMENT-START block_node? DOCUMENT-END* -// -// ************************* +// implicit_document ::= block_node DOCUMENT-END* +// * +// explicit_document ::= DIRECTIVE* DOCUMENT-START block_node? DOCUMENT-END* +// ************************* func yaml_parser_parse_document_start(parser *yaml_parser_t, event *yaml_event_t, implicit bool) bool { token := peek_token(parser) @@ -359,9 +357,9 @@ func yaml_parser_parse_document_start(parser *yaml_parser_t, event *yaml_event_t } // Parse the productions: -// explicit_document ::= DIRECTIVE* DOCUMENT-START block_node? DOCUMENT-END* // -// *********** +// explicit_document ::= DIRECTIVE* DOCUMENT-START block_node? DOCUMENT-END* +// *********** func yaml_parser_parse_document_content(parser *yaml_parser_t, event *yaml_event_t) bool { token := peek_token(parser) if token == nil { @@ -382,11 +380,10 @@ func yaml_parser_parse_document_content(parser *yaml_parser_t, event *yaml_event } // Parse the productions: -// implicit_document ::= block_node DOCUMENT-END* -// -// ************* // -// explicit_document ::= DIRECTIVE* DOCUMENT-START block_node? DOCUMENT-END* +// implicit_document ::= block_node DOCUMENT-END* +// ************* +// explicit_document ::= DIRECTIVE* DOCUMENT-START block_node? DOCUMENT-END* func yaml_parser_parse_document_end(parser *yaml_parser_t, event *yaml_event_t) bool { token := peek_token(parser) if token == nil { @@ -432,42 +429,32 @@ func yaml_parser_set_event_comments(parser *yaml_parser_t, event *yaml_event_t) } // Parse the productions: -// block_node_or_indentless_sequence ::= -// -// ALIAS -// ***** -// | properties (block_content | indentless_block_sequence)? -// ********** * -// | block_content | indentless_block_sequence -// * -// -// block_node ::= ALIAS -// -// ***** -// | properties block_content? -// ********** * -// | block_content -// * -// -// flow_node ::= ALIAS -// -// ***** -// | properties flow_content? -// ********** * -// | flow_content -// * -// -// properties ::= TAG ANCHOR? | ANCHOR TAG? -// -// ************************* -// -// block_content ::= block_collection | flow_collection | SCALAR -// -// ****** // -// flow_content ::= flow_collection | SCALAR -// -// ****** +// block_node_or_indentless_sequence ::= +// ALIAS +// ***** +// | properties (block_content | indentless_block_sequence)? +// ********** * +// | block_content | indentless_block_sequence +// * +// block_node ::= ALIAS +// ***** +// | properties block_content? +// ********** * +// | block_content +// * +// flow_node ::= ALIAS +// ***** +// | properties flow_content? +// ********** * +// | flow_content +// * +// properties ::= TAG ANCHOR? | ANCHOR TAG? +// ************************* +// block_content ::= block_collection | flow_collection | SCALAR +// ****** +// flow_content ::= flow_collection | SCALAR +// ****** func yaml_parser_parse_node(parser *yaml_parser_t, event *yaml_event_t, block, indentless_sequence bool) bool { //defer trace("yaml_parser_parse_node", "block:", block, "indentless_sequence:", indentless_sequence)() @@ -697,9 +684,9 @@ func yaml_parser_parse_node(parser *yaml_parser_t, event *yaml_event_t, block, i } // Parse the productions: -// block_sequence ::= BLOCK-SEQUENCE-START (BLOCK-ENTRY block_node?)* BLOCK-END // -// ******************** *********** * ********* +// block_sequence ::= BLOCK-SEQUENCE-START (BLOCK-ENTRY block_node?)* BLOCK-END +// ******************** *********** * ********* func yaml_parser_parse_block_sequence_entry(parser *yaml_parser_t, event *yaml_event_t, first bool) bool { if first { token := peek_token(parser) @@ -755,9 +742,9 @@ func yaml_parser_parse_block_sequence_entry(parser *yaml_parser_t, event *yaml_e } // Parse the productions: -// indentless_sequence ::= (BLOCK-ENTRY block_node?)+ // -// *********** * +// indentless_sequence ::= (BLOCK-ENTRY block_node?)+ +// *********** * func yaml_parser_parse_indentless_sequence_entry(parser *yaml_parser_t, event *yaml_event_t) bool { token := peek_token(parser) if token == nil { @@ -821,15 +808,15 @@ func yaml_parser_split_stem_comment(parser *yaml_parser_t, stem_len int) { } // Parse the productions: -// block_mapping ::= BLOCK-MAPPING_START // -// ******************* -// ((KEY block_node_or_indentless_sequence?)? -// *** * -// (VALUE block_node_or_indentless_sequence?)?)* +// block_mapping ::= BLOCK-MAPPING_START +// ******************* +// ((KEY block_node_or_indentless_sequence?)? +// *** * +// (VALUE block_node_or_indentless_sequence?)?)* // -// BLOCK-END -// ********* +// BLOCK-END +// ********* func yaml_parser_parse_block_mapping_key(parser *yaml_parser_t, event *yaml_event_t, first bool) bool { if first { token := peek_token(parser) @@ -896,13 +883,14 @@ func yaml_parser_parse_block_mapping_key(parser *yaml_parser_t, event *yaml_even } // Parse the productions: -// block_mapping ::= BLOCK-MAPPING_START // -// ((KEY block_node_or_indentless_sequence?)? +// block_mapping ::= BLOCK-MAPPING_START +// +// ((KEY block_node_or_indentless_sequence?)? // -// (VALUE block_node_or_indentless_sequence?)?)* -// ***** * -// BLOCK-END +// (VALUE block_node_or_indentless_sequence?)?)* +// ***** * +// BLOCK-END func yaml_parser_parse_block_mapping_value(parser *yaml_parser_t, event *yaml_event_t) bool { token := peek_token(parser) if token == nil { @@ -929,19 +917,17 @@ func yaml_parser_parse_block_mapping_value(parser *yaml_parser_t, event *yaml_ev } // Parse the productions: -// flow_sequence ::= FLOW-SEQUENCE-START -// -// ******************* -// (flow_sequence_entry FLOW-ENTRY)* -// * ********** -// flow_sequence_entry? -// * -// FLOW-SEQUENCE-END -// ***************** // -// flow_sequence_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? -// -// * +// flow_sequence ::= FLOW-SEQUENCE-START +// ******************* +// (flow_sequence_entry FLOW-ENTRY)* +// * ********** +// flow_sequence_entry? +// * +// FLOW-SEQUENCE-END +// ***************** +// flow_sequence_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? +// * func yaml_parser_parse_flow_sequence_entry(parser *yaml_parser_t, event *yaml_event_t, first bool) bool { if first { token := peek_token(parser) @@ -1005,9 +991,9 @@ func yaml_parser_parse_flow_sequence_entry(parser *yaml_parser_t, event *yaml_ev } // Parse the productions: -// flow_sequence_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? // -// *** * +// flow_sequence_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? +// *** * func yaml_parser_parse_flow_sequence_entry_mapping_key(parser *yaml_parser_t, event *yaml_event_t) bool { token := peek_token(parser) if token == nil { @@ -1026,9 +1012,9 @@ func yaml_parser_parse_flow_sequence_entry_mapping_key(parser *yaml_parser_t, ev } // Parse the productions: -// flow_sequence_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? // -// ***** * +// flow_sequence_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? +// ***** * func yaml_parser_parse_flow_sequence_entry_mapping_value(parser *yaml_parser_t, event *yaml_event_t) bool { token := peek_token(parser) if token == nil { @@ -1050,9 +1036,9 @@ func yaml_parser_parse_flow_sequence_entry_mapping_value(parser *yaml_parser_t, } // Parse the productions: -// flow_sequence_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? // -// * +// flow_sequence_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? +// * func yaml_parser_parse_flow_sequence_entry_mapping_end(parser *yaml_parser_t, event *yaml_event_t) bool { token := peek_token(parser) if token == nil { @@ -1068,18 +1054,17 @@ func yaml_parser_parse_flow_sequence_entry_mapping_end(parser *yaml_parser_t, ev } // Parse the productions: -// flow_mapping ::= FLOW-MAPPING-START -// -// ****************** -// (flow_mapping_entry FLOW-ENTRY)* -// * ********** -// flow_mapping_entry? -// ****************** -// FLOW-MAPPING-END -// **************** // -// flow_mapping_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? -// - *** * +// flow_mapping ::= FLOW-MAPPING-START +// ****************** +// (flow_mapping_entry FLOW-ENTRY)* +// * ********** +// flow_mapping_entry? +// ****************** +// FLOW-MAPPING-END +// **************** +// flow_mapping_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? +// * *** * func yaml_parser_parse_flow_mapping_key(parser *yaml_parser_t, event *yaml_event_t, first bool) bool { if first { token := peek_token(parser) @@ -1144,8 +1129,9 @@ func yaml_parser_parse_flow_mapping_key(parser *yaml_parser_t, event *yaml_event } // Parse the productions: -// flow_mapping_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? -// - ***** * +// +// flow_mapping_entry ::= flow_node | KEY flow_node? (VALUE flow_node?)? +// * ***** * func yaml_parser_parse_flow_mapping_value(parser *yaml_parser_t, event *yaml_event_t, empty bool) bool { token := peek_token(parser) if token == nil { diff --git a/stembuild/vendor/go.yaml.in/yaml/v3/yamlh.go b/stembuild/vendor/go.yaml.in/yaml/v3/yamlh.go index f59aa40f6..07c442361 100644 --- a/stembuild/vendor/go.yaml.in/yaml/v3/yamlh.go +++ b/stembuild/vendor/go.yaml.in/yaml/v3/yamlh.go @@ -433,21 +433,19 @@ type yaml_document_t struct { // The prototype of a read handler. // -// The read handler is called when the parser needs to read more bytes from the -// source. The handler should write not more than size bytes to the buffer. -// The number of written bytes should be set to the size_read variable. +// The read handler is called when the parser needs to read more bytes from the +// source. The handler should write not more than size bytes to the buffer. +// The number of written bytes should be set to the size_read variable. // -// [in,out] data A pointer to an application data specified by +// [in,out] data A pointer to an application data specified by +// yaml_parser_set_input(). +// [out] buffer The buffer to write the data from the source. +// [in] size The size of the buffer. +// [out] size_read The actual number of bytes read from the source. // -// yaml_parser_set_input(). -// -// [out] buffer The buffer to write the data from the source. -// [in] size The size of the buffer. -// [out] size_read The actual number of bytes read from the source. -// -// On success, the handler should return 1. If the handler failed, -// the returned value should be 0. On EOF, the handler should set the -// size_read to 0 and return 1. +// On success, the handler should return 1. If the handler failed, +// the returned value should be 0. On EOF, the handler should set the +// size_read to 0 and return 1. type yaml_read_handler_t func(parser *yaml_parser_t, buffer []byte) (n int, err error) // This structure holds information about a potential simple key. @@ -655,19 +653,17 @@ type yaml_comment_t struct { // The prototype of a write handler. // -// The write handler is called when the emitter needs to flush the accumulated -// characters to the output. The handler should write @a size bytes of the -// @a buffer to the output. -// -// @param[in,out] data A pointer to an application data specified by -// -// yaml_emitter_set_output(). +// The write handler is called when the emitter needs to flush the accumulated +// characters to the output. The handler should write @a size bytes of the +// @a buffer to the output. // -// @param[in] buffer The buffer with bytes to be written. -// @param[in] size The size of the buffer. +// @param[in,out] data A pointer to an application data specified by +// yaml_emitter_set_output(). +// @param[in] buffer The buffer with bytes to be written. +// @param[in] size The size of the buffer. // -// @returns On success, the handler should return @c 1. If the handler failed, -// the returned value should be @c 0. +// @returns On success, the handler should return @c 1. If the handler failed, +// the returned value should be @c 0. type yaml_write_handler_t func(emitter *yaml_emitter_t, buffer []byte) error type yaml_emitter_state_t int diff --git a/stembuild/vendor/golang.org/x/net/http2/hpack/encode.go b/stembuild/vendor/golang.org/x/net/http2/hpack/encode.go index 46219da2b..e6d0c265a 100644 --- a/stembuild/vendor/golang.org/x/net/http2/hpack/encode.go +++ b/stembuild/vendor/golang.org/x/net/http2/hpack/encode.go @@ -39,7 +39,6 @@ func NewEncoder(w io.Writer) *Encoder { tableSizeUpdate: false, w: w, } - e.dynTab.table.init() e.dynTab.setMaxSize(initialHeaderTableSize) return e } diff --git a/stembuild/vendor/golang.org/x/net/http2/hpack/hpack.go b/stembuild/vendor/golang.org/x/net/http2/hpack/hpack.go index 7a1d97669..ecd3eeca9 100644 --- a/stembuild/vendor/golang.org/x/net/http2/hpack/hpack.go +++ b/stembuild/vendor/golang.org/x/net/http2/hpack/hpack.go @@ -105,7 +105,6 @@ func NewDecoder(maxDynamicTableSize uint32, emitFunc func(f HeaderField)) *Decod emitEnabled: true, firstField: true, } - d.dynTab.table.init() d.dynTab.allowedMaxSize = maxDynamicTableSize d.dynTab.setMaxSize(maxDynamicTableSize) return d diff --git a/stembuild/vendor/golang.org/x/net/http2/hpack/tables.go b/stembuild/vendor/golang.org/x/net/http2/hpack/tables.go index 8cbdf3f01..3bd7eb753 100644 --- a/stembuild/vendor/golang.org/x/net/http2/hpack/tables.go +++ b/stembuild/vendor/golang.org/x/net/http2/hpack/tables.go @@ -31,10 +31,18 @@ type headerFieldTable struct { // byName maps a HeaderField name to the unique id of the newest entry with // the same name. See above for a definition of "unique id". + // + // byName and byNameValue are used only by search, which is only called + // for tables used by encoders. For tables used only by decoders, the + // maps are never built, as a memory optimization for servers with many + // mostly-idle connections, each pinning a dynamic table. The maps are + // built lazily by the first search call and are nil until then. The two + // maps are always both nil or both non-nil. byName map[string]uint64 // byNameValue maps a HeaderField name/value pair to the unique id of the newest // entry with the same name and value. See above for a definition of "unique id". + // See byName for when this map is non-nil. byNameValue map[pairNameValue]uint64 } @@ -42,9 +50,17 @@ type pairNameValue struct { name, value string } -func (t *headerFieldTable) init() { - t.byName = make(map[string]uint64) - t.byNameValue = make(map[pairNameValue]uint64) +// buildMaps initializes byName and byNameValue from ents. +func (t *headerFieldTable) buildMaps() { + t.byName = make(map[string]uint64, len(t.ents)) + t.byNameValue = make(map[pairNameValue]uint64, len(t.ents)) + for k, f := range t.ents { + // Map to the newest matching entry: later (newer) entries + // overwrite earlier ones, matching addEntry's behavior. + id := t.evictCount + uint64(k) + 1 + t.byName[f.Name] = id + t.byNameValue[pairNameValue{f.Name, f.Value}] = id + } } // len reports the number of entries in the table. @@ -54,9 +70,11 @@ func (t *headerFieldTable) len() int { // addEntry adds a new entry. func (t *headerFieldTable) addEntry(f HeaderField) { - id := uint64(t.len()) + t.evictCount + 1 - t.byName[f.Name] = id - t.byNameValue[pairNameValue{f.Name, f.Value}] = id + if t.byName != nil { + id := uint64(t.len()) + t.evictCount + 1 + t.byName[f.Name] = id + t.byNameValue[pairNameValue{f.Name, f.Value}] = id + } t.ents = append(t.ents, f) } @@ -65,14 +83,16 @@ func (t *headerFieldTable) evictOldest(n int) { if n > t.len() { panic(fmt.Sprintf("evictOldest(%v) on table with %v entries", n, t.len())) } - for k := 0; k < n; k++ { - f := t.ents[k] - id := t.evictCount + uint64(k) + 1 - if t.byName[f.Name] == id { - delete(t.byName, f.Name) - } - if p := (pairNameValue{f.Name, f.Value}); t.byNameValue[p] == id { - delete(t.byNameValue, p) + if t.byName != nil { + for k := 0; k < n; k++ { + f := t.ents[k] + id := t.evictCount + uint64(k) + 1 + if t.byName[f.Name] == id { + delete(t.byName, f.Name) + } + if p := (pairNameValue{f.Name, f.Value}); t.byNameValue[p] == id { + delete(t.byNameValue, p) + } } } copy(t.ents, t.ents[n:]) @@ -100,6 +120,9 @@ func (t *headerFieldTable) evictOldest(n int) { // // See Section 2.3.3. func (t *headerFieldTable) search(f HeaderField) (i uint64, nameValueMatch bool) { + if t.byName == nil { + t.buildMaps() + } if !f.Sensitive { if id := t.byNameValue[pairNameValue{f.Name, f.Value}]; id != 0 { return t.idToIndex(id), true diff --git a/stembuild/vendor/golang.org/x/tools/go/ast/inspector/cursor.go b/stembuild/vendor/golang.org/x/tools/go/ast/inspector/cursor.go index 239b10c4d..1c482252d 100644 --- a/stembuild/vendor/golang.org/x/tools/go/ast/inspector/cursor.go +++ b/stembuild/vendor/golang.org/x/tools/go/ast/inspector/cursor.go @@ -10,6 +10,7 @@ import ( "go/token" "iter" "reflect" + "strings" "golang.org/x/tools/go/ast/edge" ) @@ -110,6 +111,46 @@ func (c Cursor) String() string { return reflect.TypeOf(c.Node()).String() } +// GoString returns a string describing the cursor's path from the +// root, if any. +func (c Cursor) GoString() string { + if !c.Valid() { + return "(invalid)" + } + if c.index < 0 { + return "(root)" + } + // e.g "File.Decls[1].(*ast.GenDecl).Specs[0].(*ast.TypeSpec)" + // + // In hindsight even the File node should have reported a + // virtual ParentEdge of (Root_Files, i) where i is the index + // among the files passed to NewInspector. Then the path would + // read "(root).Files[i]", etc; but we missed the boat. + var buf strings.Builder + buf.WriteString("File") + var visit func(Cursor) + visit = func(c Cursor) { + ek, idx := c.ParentEdge() + if ek == edge.Invalid { + return // File + } + visit(c.Parent()) + fmt.Fprintf(&buf, ".%s", ek.FieldName()) + if idx >= 0 { + fmt.Fprintf(&buf, "[%d]", idx) + } + ftype := ek.FieldType() + if idx >= 0 { + ftype = ftype.Elem() // []T -> T + } + if ftype.Kind() == reflect.Interface { + fmt.Fprintf(&buf, ".(%T)", c.Node()) + } + } + visit(c) + return buf.String() +} + // indices return the [start, end) half-open interval of event indices. func (c Cursor) indices() (int32, int32) { if c.index < 0 { diff --git a/stembuild/vendor/golang.org/x/tools/go/packages/visit.go b/stembuild/vendor/golang.org/x/tools/go/packages/visit.go index c546b1b63..06747a9df 100644 --- a/stembuild/vendor/golang.org/x/tools/go/packages/visit.go +++ b/stembuild/vendor/golang.org/x/tools/go/packages/visit.go @@ -5,11 +5,11 @@ package packages import ( - "cmp" "fmt" "iter" "os" - "slices" + + "golang.org/x/tools/internal/moremaps" ) // Visit visits all the packages in the import graph whose roots are @@ -40,7 +40,7 @@ func Visit(pkgs []*Package, pre func(*Package) bool, post func(*Package)) { seen[pkg] = true if pre == nil || pre(pkg) { - for _, imp := range sorted(pkg.Imports) { // for determinism + for _, imp := range moremaps.Sorted(pkg.Imports) { // for determinism visit(imp) } } @@ -88,7 +88,7 @@ func Postorder(pkgs []*Package) iter.Seq[*Package] { visit = func(pkg *Package) bool { if !seen[pkg] { seen[pkg] = true - for _, imp := range sorted(pkg.Imports) { // for determinism + for _, imp := range moremaps.Sorted(pkg.Imports) { // for determinism if !visit(imp) { return false } @@ -106,28 +106,3 @@ func Postorder(pkgs []*Package) iter.Seq[*Package] { } } } - -// -- copied from golang.org.x/tools/gopls/internal/util/moremaps -- - -// sorted returns an iterator over the entries of m in key order. -func sorted[M ~map[K]V, K cmp.Ordered, V any](m M) iter.Seq2[K, V] { - // TODO(adonovan): use maps.Sorted if proposal #68598 is accepted. - return func(yield func(K, V) bool) { - keys := keySlice(m) - slices.Sort(keys) - for _, k := range keys { - if !yield(k, m[k]) { - break - } - } - } -} - -// KeySlice returns the keys of the map M, like slices.Collect(maps.Keys(m)). -func keySlice[M ~map[K]V, K comparable, V any](m M) []K { - r := make([]K, 0, len(m)) - for k := range m { - r = append(r, k) - } - return r -} diff --git a/stembuild/vendor/golang.org/x/tools/go/types/typeutil/callee.go b/stembuild/vendor/golang.org/x/tools/go/types/typeutil/callee.go index 3d24a8c63..b64a8f454 100644 --- a/stembuild/vendor/golang.org/x/tools/go/types/typeutil/callee.go +++ b/stembuild/vendor/golang.org/x/tools/go/types/typeutil/callee.go @@ -7,7 +7,8 @@ package typeutil import ( "go/ast" "go/types" - _ "unsafe" // for linkname + + "golang.org/x/tools/internal/typesinternal" ) // Callee returns the named target of a function call, if any: @@ -19,14 +20,7 @@ import ( // Note: for calls of instantiated functions and methods, Callee returns // the corresponding generic function or method on the generic type. func Callee(info *types.Info, call *ast.CallExpr) types.Object { - obj := info.Uses[usedIdent(info, call.Fun)] - if obj == nil { - return nil - } - if _, ok := obj.(*types.TypeName); ok { - return nil - } - return obj + return typesinternal.Callee(info, call) } // StaticCallee returns the target (function or method) of a static function @@ -35,52 +29,5 @@ func Callee(info *types.Info, call *ast.CallExpr) types.Object { // Note: for calls of instantiated functions and methods, StaticCallee returns // the corresponding generic function or method on the generic type. func StaticCallee(info *types.Info, call *ast.CallExpr) *types.Func { - obj := info.Uses[usedIdent(info, call.Fun)] - fn, _ := obj.(*types.Func) - if fn == nil || interfaceMethod(fn) { - return nil - } - return fn -} - -// usedIdent is the implementation of [internal/typesinternal.UsedIdent]. -// It returns the identifier associated with e. -// See typesinternal.UsedIdent for a fuller description. -// This function should live in typesinternal, but cannot because it would -// create an import cycle. -// -//go:linkname usedIdent golang.org/x/tools/go/types/typeutil.usedIdent -func usedIdent(info *types.Info, e ast.Expr) *ast.Ident { - if info.Types == nil || info.Uses == nil { - panic("one of info.Types or info.Uses is nil; both must be populated") - } - // Look through type instantiation if necessary. - switch d := ast.Unparen(e).(type) { - case *ast.IndexExpr: - if info.Types[d.Index].IsType() { - e = d.X - } - case *ast.IndexListExpr: - e = d.X - } - - switch e := ast.Unparen(e).(type) { - // info.Uses always has the object we want, even for selector expressions. - // We don't need info.Selections. - // See go/types/recording.go:recordSelection. - case *ast.Ident: - return e - case *ast.SelectorExpr: - return e.Sel - } - return nil -} - -// interfaceMethod reports whether its argument is a method of an interface. -// This function should live in typesinternal, but cannot because it would create an import cycle. -// -//go:linkname interfaceMethod golang.org/x/tools/go/types/typeutil.interfaceMethod -func interfaceMethod(f *types.Func) bool { - recv := f.Signature().Recv() - return recv != nil && types.IsInterface(recv.Type()) + return typesinternal.StaticCallee(info, call) } diff --git a/stembuild/vendor/golang.org/x/tools/internal/moremaps/maps.go b/stembuild/vendor/golang.org/x/tools/internal/moremaps/maps.go new file mode 100644 index 000000000..a1bae078b --- /dev/null +++ b/stembuild/vendor/golang.org/x/tools/internal/moremaps/maps.go @@ -0,0 +1,116 @@ +// Copyright 2023 The Go Authors. All rights reserved. +// Use of this source code is governed by a BSD-style +// license that can be found in the LICENSE file. + +// Package moremaps contains more functions for working with maps. +package moremaps + +import ( + "cmp" + "iter" + "maps" + "slices" +) + +// Arbitrary returns an arbitrary (key, value) entry from the map and ok is true, if +// the map is not empty. Otherwise, it returns zero values for K and V, and false. +func Arbitrary[K comparable, V any](m map[K]V) (_ K, _ V, ok bool) { + for k, v := range m { + return k, v, true + } + return +} + +// Group returns a new non-nil map containing the elements of s grouped by the +// keys returned from the key func. +func Group[K comparable, V any](s []V, key func(V) K) map[K][]V { + m := make(map[K][]V) + for _, v := range s { + k := key(v) + m[k] = append(m[k], v) + } + return m +} + +// KeySlice returns the keys of the map M, like slices.Collect(maps.Keys(m)). +func KeySlice[M ~map[K]V, K comparable, V any](m M) []K { + r := make([]K, 0, len(m)) + for k := range m { + r = append(r, k) + } + return r +} + +// ValueSlice returns the values of the map M, like slices.Collect(maps.Values(m)). +func ValueSlice[M ~map[K]V, K comparable, V any](m M) []V { + r := make([]V, 0, len(m)) + for _, v := range m { + r = append(r, v) + } + return r +} + +// SameKeys reports whether x and y have equal sets of keys. +func SameKeys[K comparable, V1, V2 any](x map[K]V1, y map[K]V2) bool { + ignoreValues := func(V1, V2) bool { return true } + return maps.EqualFunc(x, y, ignoreValues) +} + +// Sorted returns an iterator over the entries of m in key order. +func Sorted[M ~map[K]V, K cmp.Ordered, V any](m M) iter.Seq2[K, V] { + // TODO(adonovan): use maps.Sorted if proposal #68598 is accepted. + return func(yield func(K, V) bool) { + keys := KeySlice(m) + slices.Sort(keys) + for _, k := range keys { + if !yield(k, m[k]) { + break + } + } + } +} + +// SortedFunc returns an iterator over the entries of m in the key order determined by cmp. +func SortedFunc[M ~map[K]V, K comparable, V any](m M, cmp func(x, y K) int) iter.Seq2[K, V] { + // TODO(adonovan): use maps.SortedFunc if proposal #68598 is accepted. + return func(yield func(K, V) bool) { + keys := KeySlice(m) + slices.SortFunc(keys, cmp) + for _, k := range keys { + if !yield(k, m[k]) { + break + } + } + } +} + +// Delete is like delete(m, k) but reports whether deletion occurred. +func Delete[M ~map[K]V, K comparable, V any](m M, k K) bool { + pre := len(m) + delete(m, k) + return pre != len(m) +} + +// Entry is a key-value pair obtained from a map. +type Entry[K comparable, V any] struct { + Key K + Value V +} + +// Entries returns a new unordered array of the entries of a map. +func Entries[M ~map[K]V, K comparable, V any](m M) []Entry[K, V] { + entries := make([]Entry[K, V], 0, len(m)) + for k, v := range m { + entries = append(entries, Entry[K, V]{k, v}) + } + return entries +} + +// FromEntries returns a new map into which the entries have been inserted in order. +func FromEntries[K comparable, V any](entries []Entry[K, V]) map[K]V { + m := make(map[K]V, len(entries)) + for _, e := range entries { + m[e.Key] = e.Value + } + return m +} diff --git a/stembuild/vendor/golang.org/x/tools/internal/typesinternal/assignedaddress.go b/stembuild/vendor/golang.org/x/tools/internal/typesinternal/assignedaddress.go new file mode 100644 index 000000000..020defc38 --- /dev/null +++ b/stembuild/vendor/golang.org/x/tools/internal/typesinternal/assignedaddress.go @@ -0,0 +1,128 @@ +// Copyright 2026 The Go Authors. All rights reserved. +// Use of this source code is governed by a BSD-style +// license that can be found in the LICENSE file. + +package typesinternal + +import ( + "go/ast" + "go/token" + "go/types" + + "golang.org/x/tools/go/ast/edge" + "golang.org/x/tools/go/ast/inspector" +) + +// IsAssignedOrAddressTaken reports whether the expression cur denotes a +// variable and appears in a context that assigns it or that takes its address, +// potentially leading to indirect assignment. +// +// These examples cause IsAssignedOrAddressTaken on the identifier for x to +// return true: +// +// x = 1 +// x++ +// x[i] = 1 (assume x is an array) +// x.a[i] = 1 (assume x.a is a non-pointer struct field) +// use(&x) +// +// whereas these cause it to return false: +// +// y = x +// f(x) +// use(x.a[i]) +// use(*x) +// +// The expression may itself be a compound, for example: +// +// use(&(*ptr)) => IsAssignedOrAddressTaken("*ptr") = true +// x.a[i] = 1 => IsAssignedOrAddressTaken("x.a") = true +// _ = x.a[i] => IsAssignedOrAddressTaken("x.a") = false +// +// A variable's declaration is not considered to be an assignment: +// +// var x int => IsAssignedOrAddressTaken(x) = false +// x := 1 => IsAssignedOrAddressTaken(x) = false +// +// TODO(adonovan): revisit the surprising behavior for declarations. +func IsAssignedOrAddressTaken(info *types.Info, cur inspector.Cursor) bool { + // Unfortunately we can't simply use info.Types[e].Assignable() + // as it is always true for a variable even when that variable is + // used only as an r-value. So we must inspect enclosing syntax. +outer: + // Ascend to outermost aggregate of which + // original cur is a part: + // x -> (x) | x.f | x[i] | x[i:j] + for cur = range cur.Enclosing() { + switch cur.ParentEdgeKind() { + case edge.ParenExpr_X: + // If x is an lvalue, then (x) is an lvalue. + case edge.SelectorExpr_X: + // If x is an lvalue, then x.f is an lvalue iff + // the selection does not traverse a pointer. + sel := cur.Parent().Node().(*ast.SelectorExpr) + if seln, ok := info.Selections[sel]; ok { + // Note: there is a bug in Indirect() where it spuriously returns true + // when both the selection receiver and parameter are pointers. However, + // it's okay in this case because there is no address taken when a + // pointer receiver method is called on a pointer type. + if seln.Indirect() { + return false + } + if seln.Kind() == types.MethodVal { + sig := seln.Obj().Type().(*types.Signature) + if is[*types.Pointer](sig.Recv().Type().Underlying()) { + t := seln.Recv() + // The receiver may be an embedded field, so we need + // to get the inner-most type (right before the method + // call in seln.Index()) + for _, idx := range seln.Index()[:len(seln.Index())-1] { + t = t.Underlying().(*types.Struct).Field(idx).Type() + } + if !is[*types.Pointer](t.Underlying()) { + return true // takes address of receiver + } + } + return false + } + } + case edge.IndexExpr_X, edge.SliceExpr_X: + // If x[i] or x[i:j] is an lvalue, + // then x is an lvalue iff x is an array. + if !is[*types.Array](info.TypeOf(cur.Node().(ast.Expr)).Underlying()) { + return false + } + default: + break outer + } + } + switch cur.ParentEdgeKind() { + case edge.AssignStmt_Lhs: + assign := cur.Parent().Node().(*ast.AssignStmt) + if assign.Tok != token.DEFINE { + return true // x = j or x += j + } + id := cur.Node().(*ast.Ident) + // Re-assigned identifiers are recorded in the Uses map. + if _, ok := info.Uses[id]; ok { + return true // reassignment of x (x, y := 1, 2) + } + case edge.RangeStmt_Key, edge.RangeStmt_Value: + rng := cur.Parent().Node().(*ast.RangeStmt) + if rng.Tok == token.ASSIGN { + return true // "for k, v = range x" is like an AssignStmt to k, v + } + case edge.IncDecStmt_X: + return true // x++, x-- + case edge.UnaryExpr_X: + if cur.Parent().Node().(*ast.UnaryExpr).Op == token.AND { + return true // &x + } + } + return false +} + +func is[T any](x any) bool { + _, ok := x.(T) + return ok +} diff --git a/stembuild/vendor/golang.org/x/tools/internal/typesinternal/classify_call.go b/stembuild/vendor/golang.org/x/tools/internal/typesinternal/classify_call.go index 7ebe9768b..d5c40a2e5 100644 --- a/stembuild/vendor/golang.org/x/tools/internal/typesinternal/classify_call.go +++ b/stembuild/vendor/golang.org/x/tools/internal/typesinternal/classify_call.go @@ -8,7 +8,6 @@ import ( "fmt" "go/ast" "go/types" - _ "unsafe" // for go:linkname hack ) // CallKind describes the function position of an [*ast.CallExpr]. @@ -72,11 +71,15 @@ func ClassifyCall(info *types.Info, call *ast.CallExpr) CallKind { if tv.IsBuiltin() { return CallBuiltin } - obj := info.Uses[UsedIdent(info, call.Fun)] + id := UsedIdent(info, call.Fun) + if id == nil { + return CallDynamic + } + obj := info.Uses[id] // Classify the call by the type of the object, if any. switch obj := obj.(type) { case *types.Func: - if interfaceMethod(obj) { + if isInterfaceMethod(obj) { return CallInterface } return CallStatic @@ -127,11 +130,69 @@ func ClassifyCall(info *types.Info, call *ast.CallExpr) CallKind { // Note: if e is an instantiated function or method, UsedIdent returns // the corresponding generic function or method on the generic type. func UsedIdent(info *types.Info, e ast.Expr) *ast.Ident { - return usedIdent(info, e) + if info.Types == nil || info.Uses == nil { + panic("one of info.Types or info.Uses is nil; both must be populated") + } + // Look through type instantiation if necessary. + switch d := ast.Unparen(e).(type) { + case *ast.IndexExpr: + if info.Types[d.Index].IsType() { + e = d.X + } + case *ast.IndexListExpr: + e = d.X + } + + switch e := ast.Unparen(e).(type) { + // info.Uses always has the object we want, even for selector expressions. + // We don't need info.Selections. + // See go/types/recording.go:recordSelection. + case *ast.Ident: + return e + case *ast.SelectorExpr: + return e.Sel + } + return nil +} + +// See [golang.org/x/tools/go/types/typeutil.Callee]. +func Callee(info *types.Info, call *ast.CallExpr) types.Object { + id := UsedIdent(info, call.Fun) + if id == nil { + return nil + } + obj := info.Uses[id] + if obj == nil { + return nil + } + if _, ok := obj.(*types.TypeName); ok { + return nil + } + if fn, ok := obj.(*types.Func); ok { + return fn.Origin() + } + return obj } -//go:linkname usedIdent golang.org/x/tools/go/types/typeutil.usedIdent -func usedIdent(info *types.Info, e ast.Expr) *ast.Ident +// See [golang.org/x/tools/go/types/typeutil.StaticCallee]. +func StaticCallee(info *types.Info, call *ast.CallExpr) *types.Func { + id := UsedIdent(info, call.Fun) + if id == nil { + return nil + } + obj := info.Uses[id] + if obj == nil { + return nil + } + fn, _ := obj.(*types.Func) + if fn == nil || isInterfaceMethod(fn) { + return nil + } + return fn.Origin() +} -//go:linkname interfaceMethod golang.org/x/tools/go/types/typeutil.interfaceMethod -func interfaceMethod(f *types.Func) bool +// isInterfaceMethod reports whether its argument is a method of an interface. +func isInterfaceMethod(f *types.Func) bool { + recv := f.Signature().Recv() + return recv != nil && types.IsInterface(recv.Type()) +} diff --git a/stembuild/vendor/golang.org/x/tools/internal/typesinternal/element.go b/stembuild/vendor/golang.org/x/tools/internal/typesinternal/element.go index 89eeea165..bab37fbfe 100644 --- a/stembuild/vendor/golang.org/x/tools/internal/typesinternal/element.go +++ b/stembuild/vendor/golang.org/x/tools/internal/typesinternal/element.go @@ -7,8 +7,6 @@ package typesinternal import ( "fmt" "go/types" - - "golang.org/x/tools/go/types/typeutil" ) // ForEachElement calls f for type T and each type reachable from its @@ -16,25 +14,24 @@ import ( // type constructors; in addition, for each named type N, the type *N // is added to the result as it may have additional methods. // -// The caller must provide an initially empty set used to de-duplicate -// identical types, potentially across multiple calls to ForEachElement. -// (Its final value holds all the elements seen, matching the arguments -// passed to f.) +// The access argument passed to f indicates whether the type is +// inaccessible to reflection (for example, intermediate tuple types +// or underlying types of named types). // -// TODO(adonovan): share/harmonize with go/callgraph/rta. -func ForEachElement(rtypes *typeutil.Map, msets *typeutil.MethodSetCache, T types.Type, f func(types.Type)) { - var visit func(T types.Type, skip bool) - visit = func(T types.Type, skip bool) { - if !skip { - if seen, _ := rtypes.Set(T, true).(bool); seen { - return // de-dup - } - - f(T) // notify caller of new element type +// The result of f indicates whether the caller has seen this type +// already, so we can prune the traversal. +// +// methodSetOf abstracts (*typeutil.MethodSetCache).MethodSet, +// avoiding an import cycle. +func ForEachElement(methodSetOf func(types.Type) *types.MethodSet, T types.Type, f func(T types.Type, access bool) bool) { + var visit func(T types.Type, access bool) + visit = func(T types.Type, access bool) { + if f(T, access) { + return // duplicate; prune descent } // Recursion over signatures of each method. - tmset := msets.MethodSet(T) + tmset := methodSetOf(T) for method := range tmset.Methods() { sig := method.Type().(*types.Signature) if sig.TypeParams() != nil { @@ -65,13 +62,13 @@ func ForEachElement(rtypes *typeutil.Map, msets *typeutil.MethodSetCache, T type // // TODO(adonovan): document whether or not it is // safe to skip non-exported methods (as RTA does). - visit(sig.Params(), true) // skip the Tuple - visit(sig.Results(), true) // skip the Tuple + visit(sig.Params(), false) // the Tuple is inaccessible + visit(sig.Results(), false) // the Tuple is inaccessible } switch T := T.(type) { case *types.Alias: - visit(types.Unalias(T), skip) // emulates the pre-Alias behavior + visit(types.Unalias(T), access) // emulates the pre-Alias behavior case *types.Basic: // nop @@ -80,49 +77,49 @@ func ForEachElement(rtypes *typeutil.Map, msets *typeutil.MethodSetCache, T type // nop---handled by recursion over method set. case *types.Pointer: - visit(T.Elem(), false) + visit(T.Elem(), true) case *types.Slice: - visit(T.Elem(), false) + visit(T.Elem(), true) case *types.Chan: - visit(T.Elem(), false) + visit(T.Elem(), true) case *types.Map: - visit(T.Key(), false) - visit(T.Elem(), false) + visit(T.Key(), true) + visit(T.Elem(), true) case *types.Signature: if T.Recv() != nil { panic(fmt.Sprintf("Signature %s has Recv %s", T, T.Recv())) } - visit(T.Params(), true) // skip the Tuple - visit(T.Results(), true) // skip the Tuple + visit(T.Params(), false) // the Tuple is inaccessible + visit(T.Results(), false) // the Tuple is inaccessible case *types.Named: // A pointer-to-named type can be derived from a named // type via reflection. It may have methods too. - visit(types.NewPointer(T), false) + visit(types.NewPointer(T), true) // Consider 'type T struct{S}' where S has methods. // Reflection provides no way to get from T to struct{S}, // only to S, so the method set of struct{S} is unwanted, - // so set 'skip' flag during recursion. - visit(T.Underlying(), true) // skip the unnamed type + // so mark it inaccessible during recursion. + visit(T.Underlying(), false) // skip the unnamed type case *types.Array: - visit(T.Elem(), false) + visit(T.Elem(), true) case *types.Struct: for i, n := 0, T.NumFields(); i < n; i++ { // TODO(adonovan): document whether or not // it is safe to skip non-exported fields. - visit(T.Field(i).Type(), false) + visit(T.Field(i).Type(), true) } case *types.Tuple: for i, n := 0, T.Len(); i < n; i++ { - visit(T.At(i).Type(), false) + visit(T.At(i).Type(), true) } case *types.TypeParam, *types.Union: @@ -133,5 +130,5 @@ func ForEachElement(rtypes *typeutil.Map, msets *typeutil.MethodSetCache, T type panic(fmt.Sprintf("ForEachElement called on unexpected type %T", T)) } } - visit(T, false) + visit(T, true) } diff --git a/stembuild/vendor/golang.org/x/tools/internal/typesinternal/toonew.go b/stembuild/vendor/golang.org/x/tools/internal/typesinternal/toonew.go index cc86487ea..386c59c74 100644 --- a/stembuild/vendor/golang.org/x/tools/internal/typesinternal/toonew.go +++ b/stembuild/vendor/golang.org/x/tools/internal/typesinternal/toonew.go @@ -13,20 +13,30 @@ import ( // TooNewStdSymbols computes the set of package-level symbols // exported by pkg that are not available at the specified version. -// The result maps each symbol to its minimum version. // // The pkg is allowed to contain type errors. -func TooNewStdSymbols(pkg *types.Package, version string) map[types.Object]string { - disallowed := make(map[types.Object]string) +func TooNewStdSymbols(pkg *types.Package, version string) map[types.Object]stdlib.Symbol { + disallowed := make(map[types.Object]stdlib.Symbol) + + // Some symbols are accessible before their release but + // only with specific build tags unknown to us here. + // Avoid false positives in such cases. + if pkg.Path() == "testing/synctest" && versions.AtLeast(version, "go1.24") { + // requires go1.24 && goexperiment.synctest || go1.25 + return disallowed + } + if (pkg.Path() == "encoding/json/v2" || pkg.Path() == "encoding/json/jsontext") && versions.AtLeast(version, "go1.25") { + // requires go1.25 && goexperiment.jsonv2 || go1.27 + return disallowed + } // Pass 1: package-level symbols. symbols := stdlib.PackageSymbols[pkg.Path()] for _, sym := range symbols { - symver := sym.Version.String() - if versions.Before(version, symver) { + if versions.Before(version, sym.Version.String()) { switch sym.Kind { case stdlib.Func, stdlib.Var, stdlib.Const, stdlib.Type: - disallowed[pkg.Scope().Lookup(sym.Name)] = symver + disallowed[pkg.Scope().Lookup(sym.Name)] = sym } } } @@ -60,28 +70,36 @@ func TooNewStdSymbols(pkg *types.Package, version string) map[types.Object]strin // spuriously cause the analyzer to report a reference to a // too-new symbol even though this expression compiles just // fine (with the fake implementation) using go1.21. + var noSym stdlib.Symbol + depth := make(map[types.Object]int) for _, sym := range symbols { - symVersion := sym.Version.String() - if !versions.Before(version, symVersion) { + if !versions.Before(version, sym.Version.String()) { continue // allowed } var obj types.Object + var indices []int switch sym.Kind { case stdlib.Field: typename, name := sym.SplitField() - if t := pkg.Scope().Lookup(typename); t != nil && disallowed[t] == "" { - obj, _, _ = types.LookupFieldOrMethod(t.Type(), false, pkg, name) + if t := pkg.Scope().Lookup(typename); t != nil && disallowed[t] == noSym { + obj, indices, _ = types.LookupFieldOrMethod(t.Type(), false, pkg, name) } case stdlib.Method: ptr, recvname, name := sym.SplitMethod() - if t := pkg.Scope().Lookup(recvname); t != nil && disallowed[t] == "" { - obj, _, _ = types.LookupFieldOrMethod(t.Type(), ptr, pkg, name) + if t := pkg.Scope().Lookup(recvname); t != nil && disallowed[t] == noSym { + obj, indices, _ = types.LookupFieldOrMethod(t.Type(), ptr, pkg, name) } } if obj != nil { - disallowed[obj] = symVersion + // In the presence of embedding, two or more "pkg.T.name" + // strings may map to the same types.Object. + // Prefer the Object with the shorter index path. + if min, ok := depth[obj]; !ok || len(indices) < min { + depth[obj] = len(indices) + disallowed[obj] = sym + } } } diff --git a/stembuild/vendor/golang.org/x/tools/internal/typesinternal/types.go b/stembuild/vendor/golang.org/x/tools/internal/typesinternal/types.go index d2c0b4c5f..9fd48b088 100644 --- a/stembuild/vendor/golang.org/x/tools/internal/typesinternal/types.go +++ b/stembuild/vendor/golang.org/x/tools/internal/typesinternal/types.go @@ -270,3 +270,11 @@ func ImplicitFieldSelections(seln types.Selection) iter.Seq2[*types.Var, bool] { } } } + +func TupleOf(elems ...types.Type) *types.Tuple { + params := make([]*types.Var, len(elems)) + for i, elem := range elems { + params[i] = types.NewParam(token.NoPos, nil, "", elem) + } + return types.NewTuple(params...) +} diff --git a/stembuild/vendor/modules.txt b/stembuild/vendor/modules.txt index 9ca3c4d6a..d1c5f4b3e 100644 --- a/stembuild/vendor/modules.txt +++ b/stembuild/vendor/modules.txt @@ -57,8 +57,8 @@ github.com/google/go-cmp/cmp/internal/diff github.com/google/go-cmp/cmp/internal/flags github.com/google/go-cmp/cmp/internal/function github.com/google/go-cmp/cmp/internal/value -# github.com/google/pprof v0.0.0-20260709232956-b9395ee17fa0 -## explicit; go 1.24.0 +# github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3 +## explicit; go 1.25.0 github.com/google/pprof/profile # github.com/google/subcommands v1.2.0 ## explicit @@ -147,7 +147,7 @@ github.com/mitchellh/mapstructure github.com/nu7hatch/gouuid # github.com/onsi/ginkgo v1.16.5 ## explicit; go 1.16 -# github.com/onsi/ginkgo/v2 v2.32.0 +# github.com/onsi/ginkgo/v2 v2.32.1 ## explicit; go 1.25.0 github.com/onsi/ginkgo/v2 github.com/onsi/ginkgo/v2/config @@ -263,19 +263,19 @@ github.com/vmware/govmomi/vim25/types github.com/vmware/govmomi/vim25/xml github.com/vmware/govmomi/vmdk github.com/vmware/govmomi/vsan/vsanfs/types -# go.yaml.in/yaml/v3 v3.0.4 +# go.yaml.in/yaml/v3 v3.0.5 ## explicit; go 1.16 go.yaml.in/yaml/v3 -# golang.org/x/crypto v0.54.0 +# golang.org/x/crypto v0.55.0 ## explicit; go 1.25.0 golang.org/x/crypto/md4 golang.org/x/crypto/pbkdf2 -# golang.org/x/mod v0.38.0 +# golang.org/x/mod v0.40.0 ## explicit; go 1.25.0 golang.org/x/mod/internal/lazyregexp golang.org/x/mod/module golang.org/x/mod/semver -# golang.org/x/net v0.57.0 +# golang.org/x/net v0.58.0 ## explicit; go 1.25.0 golang.org/x/net/html golang.org/x/net/html/atom @@ -289,7 +289,7 @@ golang.org/x/sync/errgroup golang.org/x/sys/unix golang.org/x/sys/windows golang.org/x/sys/windows/registry -# golang.org/x/text v0.40.0 +# golang.org/x/text v0.41.0 ## explicit; go 1.25.0 golang.org/x/text/cases golang.org/x/text/encoding @@ -311,7 +311,7 @@ golang.org/x/text/language golang.org/x/text/runes golang.org/x/text/transform golang.org/x/text/unicode/norm -# golang.org/x/tools v0.48.0 +# golang.org/x/tools v0.49.0 ## explicit; go 1.25.0 golang.org/x/tools/cover golang.org/x/tools/go/ast/astutil @@ -332,6 +332,7 @@ golang.org/x/tools/internal/gocommand golang.org/x/tools/internal/gopathwalk golang.org/x/tools/internal/imports golang.org/x/tools/internal/modindex +golang.org/x/tools/internal/moremaps golang.org/x/tools/internal/packagesinternal golang.org/x/tools/internal/pkgbits golang.org/x/tools/internal/stdlib