Commit Graph
11 Commits
Author SHA1 Message Date
Arun Kumar Mohan 65d16bfc94 ceph: manual changes needed for kubernetes api updates
Fetched latest lib-bucket-provisioner changes as well.

Signed-off-by: Arun Kumar Mohan <amohan@redhat.com>
2020-11-18 21:14:01 +05:30
subhamkrai cb0ca66a6b ci: enable gosec linter in golangci-lint
golangci-lint linter gosec showing more errors
than gosec gh. This commit resolve
new errors. And, removing
nosec comments from autogenerated files.

Signed-off-by: subhamkrai <srai@redhat.com>
2020-10-19 11:50:06 +05:30
subhamkrai 0fddfcf307 ceph: handle golangci-lint linter errcheck error
this commit handle golangci-lint linter errcheck.

`errcheck` - Errcheck is a program for checking for
unchecked errors in go programs. These unchecked errors
can be critical bugs in some cases

To see only staticcheck linter output
`golangci-lint run --disable-all -E errcheck`

Signed-off-by: subhamkrai <srai@redhat.com>
2020-09-30 22:24:34 +05:30
subhamkrai de8dbbcdcc ceph: handle golangci-lint linter staticcheck error
this commit handle golangci-lint linter staticcheck error.

`staticcheck` - Staticcheck is a go vet on steroids,
applying a ton of static analysis checks.

To see only `staticcheck` linter output

`golangci-lint run --disable-all -E staticcheck`

Signed-off-by: subhamkrai <srai@redhat.com>
2020-09-24 15:04:55 +05:30
subhamkrai 25c116a4bd ceph: handle golangci-lint linter gosimple
this commit handles all the errors  check for
golangci-lint linter gosimple.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-09-17 15:10:27 +05:30
subhamkrai c938849cf8 ceph: closing file which are open for writing
using defer for closing file which are open
for writing is not safe. so closing file again
following  below steps:
1. open files
2. defer file.close()
3. write
4.file.close()

these will make sure files are closed.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-07-30 22:37:56 +05:30
Travis Nielsen 998b3f29ea ceph: reduce the file permissions to fix gosec errors
File permissions need to be reduced to the minimum to avoid config
files from being accessed. While a connection to the pod would be
required to access the files, min privileges are set just as
another layer of security. This fixes gosec error G306.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-07-28 15:46:24 -06:00
Nizamudeen 041618dacb ceph: change the file and directory permissions to most narrow possible
This commit fixes where there are areas in which files and directories are
written and created with statically defined permissions. Many of these
permissions are rather open, potentially allowing other system tenants to
view and interact with their contents, which may be sensitive.

Fixed G303: Poor file permissions used for directory by using the most narrow permission

Resoves: https://github.com/rook/rook/issues/4580

Signed-off-by: Nizamudeen <nia@redhat.com>
2020-07-28 15:46:12 -06:00
Travis Nielsen cf53467380 core: suppress gosec errors for closing files
To ensure a file handle is closed, we defer the close command
so it is guaranteed to run when the method returns. The closing
of the file handle is not going to fail in our usage since we aren't
using the SetDeadline on the files that would cancel a request
and return an error.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-07-24 12:31:13 -06:00
Nizamudeen 78ef4abeec ceph: Fixing the potential file inclusion error
This commit is also part of gosec error handling which handles the following issue:

Fixed G304: Potential File inclusion by cleaning up the file path

Signed-off-by: Nizamudeen <nia@redhat.com>
2020-02-14 12:22:49 +05:30
Blaine Gardner 5411fe4cde daemon: create new cmd-reporter daemon
cmd-reporter runs a command and puts the results of the command into a
ConfigMap defined by its `--config-map-name` commandline flag.
cmd-reporter is intended to be run as a Kubernetes job where an
operator needs to run a single command and get return information back
from the command which is more than just success/failure.

The ConfigMap returned includes `stdout`, `stderr`, and `retcode` data
from the command. The ConfigMap may be preexisting, in which case
cmd-reporter will overwrite the return information in the ConfigMap.
cmd-reporter labels the ConfigMap with `app=cmd-reporter`, and if the
ConfigMap already has an app label which is different, cmd-reporter
fails without modifying the ConfigMap so as not to overwrite another
application's data in the event of a ConfigMap name+namespace collision.

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2019-07-05 12:03:58 -06:00