Skip to content

Commit 64d6edc

Browse files
authored
Merge pull request #1050 from andyzhangx/CVE-2023-39325-1.21
[release-1.21] fix: CVE-2023-39325
2 parents 90a8489 + 0ee8cf1 commit 64d6edc

File tree

210 files changed

+22105
-7408
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

210 files changed

+22105
-7408
lines changed

Makefile

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,9 +29,10 @@ CSI_IMAGE_TAG ?= $(REGISTRY)/$(IMAGE_NAME):$(IMAGE_VERSION)
2929
CSI_IMAGE_TAG_LATEST = $(REGISTRY)/$(IMAGE_NAME):latest
3030
BUILD_DATE ?= $(shell date -u +"%Y-%m-%dT%H:%M:%SZ")
3131
LDFLAGS ?= "-X ${PKG}/pkg/blob.driverVersion=${IMAGE_VERSION} -X ${PKG}/pkg/blob.gitCommit=${GIT_COMMIT} -X ${PKG}/pkg/blob.buildDate=${BUILD_DATE} -s -w -extldflags '-static'"
32-
E2E_HELM_OPTIONS ?= --set image.blob.pullPolicy=Always --set image.blob.repository=$(REGISTRY)/$(IMAGE_NAME) --set image.blob.tag=$(IMAGE_VERSION) --set driver.userAgentSuffix="e2e-test"
3332
ifdef ENABLE_BLOBFUSE_PROXY
34-
override E2E_HELM_OPTIONS := $(E2E_HELM_OPTIONS) --set controller.logLevel=6 --set node.logLevel=6 --set node.enableBlobfuseProxy=true
33+
E2E_HELM_OPTIONS ?= --set image.blob.pullPolicy=Always --set image.blob.repository=$(REGISTRY)/$(IMAGE_NAME) --set image.blob.tag=$(IMAGE_VERSION) --set driver.userAgentSuffix="e2e-test" --set controller.logLevel=6 --set node.logLevel=6 --set node.enableBlobfuseProxy=true
34+
else
35+
E2E_HELM_OPTIONS ?= --set image.blob.pullPolicy=Always --set image.blob.repository=$(REGISTRY)/$(IMAGE_NAME) --set image.blob.tag=$(IMAGE_VERSION) --set driver.userAgentSuffix="e2e-test"
3536
endif
3637
E2E_HELM_OPTIONS += ${EXTRA_HELM_OPTIONS}
3738
GO111MODULE = on

go.mod

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ require (
1818
github.com/pborman/uuid v1.2.0
1919
github.com/pelletier/go-toml v1.9.4
2020
github.com/stretchr/testify v1.8.2
21-
golang.org/x/net v0.8.0
21+
golang.org/x/net v0.17.0
2222
google.golang.org/grpc v1.49.0
2323
google.golang.org/protobuf v1.28.1
2424
k8s.io/api v0.26.6
@@ -111,11 +111,11 @@ require (
111111
go.opentelemetry.io/otel/sdk v1.10.0 // indirect
112112
go.opentelemetry.io/otel/trace v1.10.0 // indirect
113113
go.opentelemetry.io/proto/otlp v0.19.0 // indirect
114-
golang.org/x/crypto v0.6.0 // indirect
114+
golang.org/x/crypto v0.14.0 // indirect
115115
golang.org/x/oauth2 v0.0.0-20220223155221-ee480838109b // indirect
116-
golang.org/x/sys v0.6.0 // indirect
117-
golang.org/x/term v0.6.0 // indirect
118-
golang.org/x/text v0.8.0 // indirect
116+
golang.org/x/sys v0.13.0 // indirect
117+
golang.org/x/term v0.13.0 // indirect
118+
golang.org/x/text v0.13.0 // indirect
119119
golang.org/x/time v0.0.0-20220210224613-90d013bbcef8 // indirect
120120
golang.org/x/tools v0.7.0 // indirect
121121
google.golang.org/appengine v1.6.7 // indirect

go.sum

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -486,8 +486,9 @@ golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPh
486486
golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc=
487487
golang.org/x/crypto v0.0.0-20220722155217-630584e8d5aa/go.mod h1:IxCIyHEi3zRg3s0A5j5BB6A9Jmi73HwBIUl50j+osU4=
488488
golang.org/x/crypto v0.1.0/go.mod h1:RecgLatLF4+eUMCP1PoPZQb+cVrJcOPbHkTkbkB9sbw=
489-
golang.org/x/crypto v0.6.0 h1:qfktjS5LUO+fFKeJXZ+ikTRijMmljikvG68fpMMruSc=
490489
golang.org/x/crypto v0.6.0/go.mod h1:OFC/31mSvZgRz0V1QTNCzfAI1aIRzbiufJtkMIlEp58=
490+
golang.org/x/crypto v0.14.0 h1:wBqGXzWJW6m1XrIKlAH0Hs1JJ7+9KBwnIO8v66Q9cHc=
491+
golang.org/x/crypto v0.14.0/go.mod h1:MVFd36DqK4CsrnJYDkBA3VC4m2GkXAM0PvzMCn4JQf4=
491492
golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
492493
golang.org/x/exp v0.0.0-20190306152737-a1d7652674e8/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
493494
golang.org/x/exp v0.0.0-20190510132918-efd6b22b2522/go.mod h1:ZjyILWgesfNpC6sMxTJOJm9Kp84zZh5NQWvqDGG3Qr8=
@@ -567,8 +568,9 @@ golang.org/x/net v0.0.0-20220425223048-2871e0cb64e4/go.mod h1:CfG3xpIq0wQ8r1q4Su
567568
golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c=
568569
golang.org/x/net v0.1.0/go.mod h1:Cx3nUiGt4eDBEyega/BKRp+/AlGL8hYe7U9odMt2Cco=
569570
golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs=
570-
golang.org/x/net v0.8.0 h1:Zrh2ngAOFYneWTAIAPethzeaQLuHwhuBkuV6ZiRnUaQ=
571571
golang.org/x/net v0.8.0/go.mod h1:QVkue5JL9kW//ek3r6jTKnTFis1tRmNAW2P1shuFdJc=
572+
golang.org/x/net v0.17.0 h1:pVaXccu2ozPjCXewfr1S7xza/zcXTity9cCdXQYSjIM=
573+
golang.org/x/net v0.17.0/go.mod h1:NxSsAGuq816PNPmqtQdLE42eU2Fs7NoRIZrHJAlaCOE=
572574
golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U=
573575
golang.org/x/oauth2 v0.0.0-20190226205417-e64efc72b421/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw=
574576
golang.org/x/oauth2 v0.0.0-20190604053449-0f29369cfe45/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw=
@@ -651,14 +653,16 @@ golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBc
651653
golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
652654
golang.org/x/sys v0.1.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
653655
golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
654-
golang.org/x/sys v0.6.0 h1:MVltZSvRTcU2ljQOhs94SXPftV6DCNnZViHeQps87pQ=
655656
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
657+
golang.org/x/sys v0.13.0 h1:Af8nKPmuFypiUBjVoU9V20FiaFXOcuZI21p0ycVYYGE=
658+
golang.org/x/sys v0.13.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
656659
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
657660
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
658661
golang.org/x/term v0.1.0/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
659662
golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k=
660-
golang.org/x/term v0.6.0 h1:clScbb1cHjoCkyRbWwBEUZ5H/tIFu5TAXIqaZD0Gcjw=
661663
golang.org/x/term v0.6.0/go.mod h1:m6U89DPEgQRMq3DNkDClhWw02AUbt2daBVO4cn4Hv9U=
664+
golang.org/x/term v0.13.0 h1:bb+I9cTfFazGW51MZqBVmZy7+JEJMouUHTUSKVQLBek=
665+
golang.org/x/term v0.13.0/go.mod h1:LTmsnFJwVN6bCy1rVCoS+qHT1HhALEFxKncY3WNNh4U=
662666
golang.org/x/text v0.0.0-20170915032832-14c0d48ead0c/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
663667
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
664668
golang.org/x/text v0.3.1-0.20180807135948-17ff2d5776d2/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
@@ -669,8 +673,9 @@ golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
669673
golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
670674
golang.org/x/text v0.4.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
671675
golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
672-
golang.org/x/text v0.8.0 h1:57P1ETyNKtuIjB4SRd15iJxuhj8Gc416Y78H3qgMh68=
673676
golang.org/x/text v0.8.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8=
677+
golang.org/x/text v0.13.0 h1:ablQoSUd0tRdKxZewP80B+BaqeKJuVhuRxj/dkrun3k=
678+
golang.org/x/text v0.13.0/go.mod h1:TvPlkZtksWOMsz7fbANvkp4WM8x/WCo/om8BMLbz+aE=
674679
golang.org/x/time v0.0.0-20181108054448-85acf8d2951c/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=
675680
golang.org/x/time v0.0.0-20190308202827-9d24e82272b4/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=
676681
golang.org/x/time v0.0.0-20191024005414-555d28b269f0/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=

hack/verify-examples.sh

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -35,9 +35,6 @@ EXAMPLES=(\
3535
deploy/example/deployment.yaml \
3636
deploy/example/statefulset.yaml \
3737
deploy/example/statefulset-nonroot.yaml \
38-
deploy/example/deployment-nfs.yaml \
39-
deploy/example/statefulset-nfs.yaml \
40-
deploy/example/statefulset-nonroot-nfs.yaml \
4138
)
4239

4340
for EXAMPLE in "${EXAMPLES[@]}"; do

pkg/blobfuse-proxy/main.go

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -27,16 +27,13 @@ import (
2727
csicommon "sigs.k8s.io/blob-csi-driver/pkg/csi-common"
2828
)
2929

30-
func init() {
31-
_ = flag.Set("logtostderr", "true")
32-
}
33-
3430
var (
3531
blobfuseProxyEndpoint = flag.String("blobfuse-proxy-endpoint", "unix://tmp/blobfuse-proxy.sock", "blobfuse-proxy endpoint")
3632
)
3733

3834
func main() {
3935
klog.InitFlags(nil)
36+
_ = flag.Set("logtostderr", "true")
4037
flag.Parse()
4138
proto, addr, err := csicommon.ParseEndpoint(*blobfuseProxyEndpoint)
4239
if err != nil {

pkg/blobplugin/main.go

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -31,10 +31,6 @@ import (
3131
"k8s.io/klog/v2"
3232
)
3333

34-
func init() {
35-
_ = flag.Set("logtostderr", "true")
36-
}
37-
3834
var (
3935
endpoint = flag.String("endpoint", "unix://tmp/csi.sock", "CSI endpoint")
4036
blobfuseProxyEndpoint = flag.String("blobfuse-proxy-endpoint", "unix://tmp/blobfuse-proxy.sock", "blobfuse-proxy endpoint")
@@ -62,6 +58,7 @@ var (
6258

6359
func main() {
6460
klog.InitFlags(nil)
61+
_ = flag.Set("logtostderr", "true")
6562
flag.Parse()
6663
if *version {
6764
info, err := blob.GetVersionYAML(*driverName)

test/e2e/suite_test.go

Lines changed: 13 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -55,10 +55,11 @@ var blobDriver *blob.Driver
5555
var projectRoot string
5656

5757
type testCmd struct {
58-
command string
59-
args []string
60-
startLog string
61-
endLog string
58+
command string
59+
args []string
60+
startLog string
61+
endLog string
62+
ignoreError bool
6263
}
6364

6465
func TestMain(m *testing.M) {
@@ -160,10 +161,11 @@ var _ = ginkgo.SynchronizedBeforeSuite(func() []byte {
160161
var _ = ginkgo.SynchronizedAfterSuite(func(ctx ginkgo.SpecContext) {},
161162
func(ctx ginkgo.SpecContext) {
162163
blobLog := testCmd{
163-
command: "bash",
164-
args: []string{"test/utils/blob_log.sh"},
165-
startLog: "==============start blob log(after suite)===================",
166-
endLog: "==============end blob log(after suite)===================",
164+
command: "bash",
165+
args: []string{"test/utils/blob_log.sh"},
166+
startLog: "==============start blob log(after suite)===================",
167+
endLog: "==============end blob log(after suite)===================",
168+
ignoreError: true,
167169
}
168170
e2eTeardown := testCmd{
169171
command: "make",
@@ -206,6 +208,9 @@ func execTestCmd(cmds []testCmd) {
206208
err := cmdSh.Run()
207209
if err != nil {
208210
log.Printf("Failed to run command: %s %s, Error: %s\n", cmd.command, strings.Join(cmd.args, " "), err.Error())
211+
if !cmd.ignoreError {
212+
gomega.Expect(err).NotTo(gomega.HaveOccurred())
213+
}
209214
}
210215
gomega.Expect(err).NotTo(gomega.HaveOccurred())
211216
log.Println(cmd.endLog)

test/external-e2e/run.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@
1717
set -xe
1818

1919
PROJECT_ROOT=$(git rev-parse --show-toplevel)
20-
DRIVER="test"
20+
DRIVER="blob"
2121

2222
setup_e2e_binaries() {
2323
# download k8s external e2e binary

test/external-e2e/testdriver-blobfuse.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ShortName: blobfuse
55
StorageClass:
66
FromFile: /tmp/csi/storageclass.yaml
77
DriverInfo:
8-
Name: test.csi.azure.com
8+
Name: blob.csi.azure.com
99
Capabilities:
1010
persistence: true
1111
exec: true

test/external-e2e/testdriver-nfs.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ShortName: blobfuse
55
StorageClass:
66
FromFile: /tmp/csi/storageclass.yaml
77
DriverInfo:
8-
Name: test.csi.azure.com
8+
Name: blob.csi.azure.com
99
Capabilities:
1010
persistence: true
1111
exec: true

0 commit comments

Comments
 (0)