1
0
Fork 0
mirror of https://github.com/moby/moby.git synced 2022-11-09 12:21:53 -05:00
moby--moby/libnetwork
Sebastiaan van Stijn fdf46323f4 Update Golang 1.12.12 (CVE-2019-17596)
Golang 1.12.12
-------------------------------

full diff: https://github.com/golang/go/compare/go1.12.11...go1.12.12

go1.12.12 (released 2019/10/17) includes fixes to the go command, runtime,
syscall and net packages. See the Go 1.12.12 milestone on our issue tracker for
details.

https://github.com/golang/go/issues?q=milestone%3AGo1.12.12

Golang 1.12.11 (CVE-2019-17596)
-------------------------------

full diff: https://github.com/golang/go/compare/go1.12.10...go1.12.11

go1.12.11 (released 2019/10/17) includes security fixes to the crypto/dsa
package. See the Go 1.12.11 milestone on our issue tracker for details.

https://github.com/golang/go/issues?q=milestone%3AGo1.12.11

    [security] Go 1.13.2 and Go 1.12.11 are released

    Hi gophers,

    We have just released Go 1.13.2 and Go 1.12.11 to address a recently reported
    security issue. We recommend that all affected users update to one of these
    releases (if you're not sure which, choose Go 1.13.2).

    Invalid DSA public keys can cause a panic in dsa.Verify. In particular, using
    crypto/x509.Verify on a crafted X.509 certificate chain can lead to a panic,
    even if the certificates don't chain to a trusted root. The chain can be
    delivered via a crypto/tls connection to a client, or to a server that accepts
    and verifies client certificates. net/http clients can be made to crash by an
    HTTPS server, while net/http servers that accept client certificates will
    recover the panic and are unaffected.

    Moreover, an application might crash invoking
    crypto/x509.(*CertificateRequest).CheckSignature on an X.509 certificate
    request, parsing a golang.org/x/crypto/openpgp Entity, or during a
    golang.org/x/crypto/otr conversation. Finally, a golang.org/x/crypto/ssh client
    can panic due to a malformed host key, while a server could panic if either
    PublicKeyCallback accepts a malformed public key, or if IsUserAuthority accepts
    a certificate with a malformed public key.

    The issue is CVE-2019-17596 and Go issue golang.org/issue/34960.

    Thanks to Daniel Mandragona for discovering and reporting this issue. We'd also
    like to thank regilero for a previous disclosure of CVE-2019-16276.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2019-10-20 23:38:03 +02:00
..
.circleci Build with latest docker stable engine 2018-12-10 08:36:52 -08:00
api Remove Solaris support 2017-10-25 15:33:06 +02:00
bitseq doc: fix typo 2018-09-07 11:48:15 +08:00
client Spelling fixes 2018-07-12 12:54:44 -07:00
cluster Switch from x/net/context -> context 2018-04-24 14:57:04 -07:00
cmd Update sctp package 2019-06-24 17:26:33 +02:00
config Added API to set ephemeral port allocator range. 2019-10-11 18:48:07 +00:00
datastore Spelling fixes 2018-07-12 12:54:44 -07:00
diagnostic doc: fix typo 2018-09-07 11:48:15 +08:00
discoverapi
docs Merge pull request #1723 from sebradloff/patch-1 2019-06-25 15:09:04 +01:00
driverapi Updating IPAM config with results from HNS create network call. 2019-08-23 09:58:29 -07:00
drivers Merge pull request #2444 from kdomanski/verbose-ipv6-cannot-add 2019-09-28 18:29:39 -04:00
drvregistry Spelling fixes 2018-07-12 12:54:44 -07:00
etchosts Enable network-db test image creation 2018-05-29 08:03:32 -07:00
hostdiscovery test: fix ineffectual assignments 2018-05-29 18:08:32 +08:00
idm Adding a unit case to verify rollover 2017-10-03 12:15:34 -07:00
internal Create internal directory 2018-07-16 17:34:20 -07:00
ipam typo fix about mismatch 2018-09-27 20:43:13 +08:00
ipamapi Adding a unit case to verify rollover 2017-10-03 12:15:34 -07:00
ipams Global Default Address Pool support 2018-08-16 11:28:24 -04:00
ipamutils Add getter function for Default Address Pools 2018-08-16 15:48:42 -04:00
iptables Use fewer modprobes 2019-04-10 17:32:39 +02:00
ipvs trigger new CI run 2019-09-25 10:39:33 -04:00
netlabel
netutils Use errors.Wrap to preserve original error 2019-04-01 20:14:54 +02:00
networkdb Fix flaky NetworkDB tests 2019-10-04 10:17:19 -07:00
ns Revert "Adjust LockOSThread" 2019-08-15 14:44:03 -07:00
options
osl Revert "Apply load balancer properly" 2019-08-15 15:39:46 -07:00
portallocator Added API to set ephemeral port allocator range. 2019-10-11 18:48:07 +00:00
portmapper Update sctp package 2019-06-24 17:26:33 +02:00
resolvconf gofmt: Fix formatting warnings 2019-06-26 16:54:31 +01:00
support Resolve "bridge fdb show" hang issue 2019-09-26 21:29:22 +00:00
test/integration Merge pull request #1656 from huikang/remove-unused-testcode 2019-06-27 09:57:12 +01:00
testutils Revert "Adjust LockOSThread" 2019-08-15 14:44:03 -07:00
types Update sctp package 2019-06-24 17:26:33 +02:00
vendor Fix flaky NetworkDB tests 2019-10-04 10:17:19 -07:00
.dockerignore Added back dockerignore 2018-06-22 16:10:22 -07:00
.gitignore Added back dockerignore 2018-06-22 16:10:22 -07:00
agent.go Cleanup the cluster provider when the agent is closed 2019-01-25 08:36:28 -08:00
agent.pb.go Gracefully remove LB endpoints from services 2018-03-16 15:19:49 -04:00
agent.proto Gracefully remove LB endpoints from services 2018-03-16 15:19:49 -04:00
CHANGELOG.md Spelling fixes 2018-07-12 12:54:44 -07:00
controller.go Fix Error Check in NewNetwork 2019-10-03 00:54:45 -07:00
default_gateway.go Fix gosimple 2019-01-03 15:25:37 -08:00
default_gateway_freebsd.go
default_gateway_linux.go
default_gateway_windows.go
Dockerfile Update Golang 1.12.12 (CVE-2019-17596) 2019-10-20 23:38:03 +02:00
drivers_freebsd.go
drivers_ipam.go Allow user to specify default address pools for docker networks 2018-02-22 12:14:59 -05:00
drivers_linux.go Removing experimental driver interface 2018-09-25 10:30:56 -07:00
drivers_windows.go Add support for Internal and Private network types on windows 2018-07-12 13:58:10 -07:00
endpoint.go Add endpoint load-balancing mode 2018-06-28 12:08:18 -04:00
endpoint_cnt.go endpoint_cnt store updates should not create an object 2017-10-26 17:52:40 -07:00
endpoint_info.go Add SrcName() method to return interface name 2018-06-28 12:08:18 -04:00
endpoint_info_unix.go
endpoint_info_windows.go
error.go
errors_test.go
firewall_linux.go Revert "Merge pull request #2339 from phyber/iptables-check" 2019-10-11 09:38:19 -07:00
firewall_others.go Reload DOCKER-USER chain on frewalld reload. 2018-01-12 10:50:22 -05:00
libnetwork_internal_test.go Create internal directory 2018-07-16 17:34:20 -07:00
libnetwork_linux_test.go Revert "Adjust LockOSThread" 2019-08-15 14:44:03 -07:00
libnetwork_test.go Add Delete endpoint for plugin in test 2019-05-23 14:55:29 +02:00
LICENSE
machines
MAINTAINERS Maintainers update 2019-06-21 14:27:00 -07:00
Makefile Dockerfile: use GO_VERSION build-arg for overriding Go version 2019-07-18 11:01:07 +02:00
network.go Updating IPAM config with results from HNS create network call. 2019-08-23 09:58:29 -07:00
network_unix.go
network_windows.go Fix for docker intercepting DNS requests on ICS network 2017-11-17 13:06:14 -08:00
README.md road map loss tracing, just keep use 'Design' describe the 'Future' 2019-06-25 22:06:30 +08:00
resolver.go Make DNS records and queries case-insensitive 2019-06-19 11:23:31 -07:00
resolver_test.go Make DNS records and queries case-insensitive 2019-06-19 11:23:31 -07:00
resolver_unix.go Rolling back the port configs if failed to programIngress() 2018-09-11 19:10:59 +08:00
resolver_windows.go
sandbox.go Make DSR an overlay-specific driver "option" 2018-10-11 14:13:19 -04:00
sandbox_dns_unix.go resolvconf: use /run/systemd/resolve/resolv.conf if systemd-resolved manages DNS 2019-06-04 04:50:37 +00:00
sandbox_dns_windows.go
sandbox_externalkey.go
sandbox_externalkey_unix.go Shorten controller ID in exec-root to not hit UNIX_PATH_MAX 2019-08-28 18:59:49 +01:00
sandbox_externalkey_windows.go
sandbox_store.go Use fmt precision to limit string length 2018-07-05 17:44:04 -04:00
sandbox_test.go Improve interface order 2018-05-25 17:40:32 +02:00
service.go Create internal directory 2018-07-16 17:34:20 -07:00
service_common.go Do not add IP to Name records for aliases 2018-11-10 20:53:06 +02:00
service_common_test.go Migrate to gotest.tools :) 2018-07-06 11:01:37 -07:00
service_linux.go Make DSR an overlay-specific driver "option" 2018-10-11 14:13:19 -04:00
service_unsupported.go Add endpoint load-balancing mode 2018-06-28 12:08:18 -04:00
service_windows.go Add endpoint load-balancing mode 2018-06-28 12:08:18 -04:00
store.go return immediately on error 2019-09-24 10:58:08 +02:00
store_linux_test.go
store_test.go
Vagrantfile
vendor.conf Fix flaky NetworkDB tests 2019-10-04 10:17:19 -07:00

libnetwork - networking for containers

Circle CI Coverage Status GoDoc Go Report Card

Libnetwork provides a native Go implementation for connecting containers

The goal of libnetwork is to deliver a robust Container Network Model that provides a consistent programming interface and the required network abstractions for applications.

Design

Please refer to the design for more information.

Using libnetwork

There are many networking solutions available to suit a broad range of use-cases. libnetwork uses a driver / plugin model to support all of these solutions while abstracting the complexity of the driver implementations by exposing a simple and consistent Network Model to users.

import (
	"fmt"
	"log"

	"github.com/docker/docker/pkg/reexec"
	"github.com/docker/libnetwork"
	"github.com/docker/libnetwork/config"
	"github.com/docker/libnetwork/netlabel"
	"github.com/docker/libnetwork/options"
)

func main() {
	if reexec.Init() {
		return
	}

	// Select and configure the network driver
	networkType := "bridge"

	// Create a new controller instance
	driverOptions := options.Generic{}
	genericOption := make(map[string]interface{})
	genericOption[netlabel.GenericData] = driverOptions
	controller, err := libnetwork.New(config.OptionDriverConfig(networkType, genericOption))
	if err != nil {
		log.Fatalf("libnetwork.New: %s", err)
	}

	// Create a network for containers to join.
	// NewNetwork accepts Variadic optional arguments that libnetwork and Drivers can use.
	network, err := controller.NewNetwork(networkType, "network1", "")
	if err != nil {
		log.Fatalf("controller.NewNetwork: %s", err)
	}

	// For each new container: allocate IP and interfaces. The returned network
	// settings will be used for container infos (inspect and such), as well as
	// iptables rules for port publishing. This info is contained or accessible
	// from the returned endpoint.
	ep, err := network.CreateEndpoint("Endpoint1")
	if err != nil {
		log.Fatalf("network.CreateEndpoint: %s", err)
	}

	// Create the sandbox for the container.
	// NewSandbox accepts Variadic optional arguments which libnetwork can use.
	sbx, err := controller.NewSandbox("container1",
		libnetwork.OptionHostname("test"),
		libnetwork.OptionDomainname("docker.io"))
	if err != nil {
		log.Fatalf("controller.NewSandbox: %s", err)
	}

	// A sandbox can join the endpoint via the join api.
	err = ep.Join(sbx)
	if err != nil {
		log.Fatalf("ep.Join: %s", err)
	}

	// libnetwork client can check the endpoint's operational data via the Info() API
	epInfo, err := ep.DriverInfo()
	if err != nil {
		log.Fatalf("ep.DriverInfo: %s", err)
	}

	macAddress, ok := epInfo[netlabel.MacAddress]
	if !ok {
		log.Fatalf("failed to get mac address from endpoint info")
	}

	fmt.Printf("Joined endpoint %s (%s) to sandbox %s (%s)\n", ep.Name(), macAddress, sbx.ContainerID(), sbx.Key())
}

Contributing

Want to hack on libnetwork? Docker's contributions guidelines apply.

Code and documentation copyright 2015 Docker, inc. Code released under the Apache 2.0 license. Docs released under Creative commons.