The last security request (having per user certificate to secure the
gRPC communication so that they can’t be hijacked cross-users) is now
addressed with 0.1.4 with many other enhancements fixing some
recommended TODOs.
I’m proceeding thus with the promotion.
** Changed in: wsl-pro-service (Ubuntu Noble)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to wsl-pro-service in Ubuntu.
https://bugs.launchpad.net/bugs/2052495
Title:
[MIR] wsl-pro-service
Status in wsl-pro-service package in Ubuntu:
Fix Released
Status in wsl-pro-service source package in Focal:
New
Status in wsl-pro-service source package in Jammy:
New
Status in wsl-pro-service source package in Noble:
Fix Released
Bug description:
[Availability]
The package wsl-pro-service is already available in Ubuntu universe.
The package wsl-pro-service build for the architectures it is designed to
work on.
It currently builds and works for architectures: amd64, arm64, armhf,
ppc64el, riscv64, s390x
Link to package https://launchpad.net/ubuntu/+source/wsl-pro-service
[Rationale]
Ubuntu Pro for WSL is a set of applications to manage Ubuntu WSL instances,
grant them Pro status, orchestrate instances from Landscape and manage their
lifecycle. Wsl-pro-service serves as a bridge between the agent running on
Windows and Ubuntu instances. It controls the Pro and Landscape status.
The package wsl-pro-service is required to be in main to seed it by default
on WSL images.
The package wsl-pro-service will generally be useful for corporate users.
No package in main or universe currently offers these capabilities.
The target release is all the LTS releases from 20.04 onwards.
[Security]
This is a new software developed and maintained by Canonical. It has no
security history.
It is a new software and no CVEs/security issues in this software in
the past.
- no `suid` or `sgid` binaries
- The package installs a systemd service called wsl-pro-service
- It installs a service in /usr/libexec/wsl-pro-service, running as root. The
service has some systemd confinement.
- Packages does not open privileged ports (ports < 1024)
- Packages does not contain extensions to security-sensitive software
- Communication between wsl-pro-service and the agent running on Windows is
done over gRPC.
- Security has been kept in mind and common isolation/risk-mitigation
patterns are in place utilizing systemd isolation features.
*This requires a security review.*
[Quality assurance - function/usage]
The package works well right after installation.
[Quality assurance - maintenance]
The Ubuntu Desktop team (~desktop-packages) maintains this package. It
doesn’t have any long-term and critical, open bugs:
- https://github.com/canonical/ubuntu-pro-for-windows/issues
- https://bugs.launchpad.net/ubuntu/+source/wsl-pro-service
[Quality assurance - testing]
There is a comprehensive, non-trivial, testsuite. The testsuite includes
integration and functional tests.
The testsuite runs at build time. The branch coverage is over 88%:
-
https://github.com/canonical/ubuntu-pro-for-windows/actions/workflows/qa.yaml?query=branch%3Amain
- https://app.codecov.io/gh/canonical/ubuntu-pro-for-wsl
The same test suite runs as autopkgtest. It is passing on all supported
architectures. Links to test logs:
- https://autopkgtest.ubuntu.com/packages/wsl-pro-service
Upstream CI also includes code sanity checks (golangci-lint, including
gosec) and vulnerability scanning (govulneck).
[Quality assurance - packaging]
- There is no debian/watch because wsl-pro-service is a native package.
- debian/control defines a correct Maintainer field:
- Maintainer: Ubuntu Developers <[email protected]>
This package does not yield massive lintian Warnings, Errors
```
W: wsl-pro-service: no-manual-page [usr/libexec/wsl-pro-service]
```
Full output from `lintian --pedantic`:
```
W: wsl-pro-service: no-manual-page [usr/libexec/wsl-pro-service]
```
- Lintian overrides are not present.
- This package does not rely on obsolete or about to be demoted packages.
- This package has no python2 or GTK2 dependencies
- The package will be installed by default but does not ask debconf questions.
Packaging and build is easy:
-
https://github.com/canonical/ubuntu-pro-for-windows/blob/main/wsl-pro-service/debian/rules
[UI standards]
Application is not end-user facing. However some strings are translatable and
used for error messages via standard intltool/gettext or similar build and
runtime internationalization system:
The system for internationalization is in place of the project and the
mo and po files are generated. It’s a question of taking the time to
mark the appropriate strings for translations. It is a background
service. Strings are used for logging and are not immediately visible
to the user.
[Dependencies]
No further depends or recommends dependencies that are not yet in main.
[Standards compliance]
- This package correctly follows FHS
- This package violates Debian Policy. It vendorizes various Go libraries (in
vendor/). We are maintaining them up to date with dependabot in our upstream
CI. The Go part is covered by the govulncheck security scanning on the Go
version we are depending on and its vendored dependency.
[Maintenance/Owner]
- The owning team will be desktop-packages and I have their acknowledgement
for that commitment
- The team desktop-packages is subscribed.
- The team desktop-packages is aware of the implications by a static build
and commits to test no-change-rebuilds and to fix any issues found for the
lifetime of the release (including ESM).
- The team desktop-packages is aware of the implications of vendored code and
(as alerted by the security team) commits to provide updates to the security
team for any affected vendored code for the lifetime of the release (including
ESM).
[Background information]
- The Package description explains the package well.
- Upstream Name is wsl-pro-service.
- Link to upstream project https://github.com/canonical/ubuntu-pro-for-windows
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/wsl-pro-service/+bug/2052495/+subscriptions
--
Mailing list: https://launchpad.net/~desktop-packages
Post to : [email protected]
Unsubscribe : https://launchpad.net/~desktop-packages
More help : https://help.launchpad.net/ListHelp