The last security request (having per user certificate to secure the
gRPC communication so that they can’t be hijacked cross-users) is now
addressed with 0.1.4 with many other enhancements fixing some
recommended TODOs.

I’m proceeding thus with the promotion.

** Changed in: wsl-pro-service (Ubuntu Noble)
       Status: In Progress => Fix Released

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to wsl-pro-service in Ubuntu.
https://bugs.launchpad.net/bugs/2052495

Title:
  [MIR] wsl-pro-service

Status in wsl-pro-service package in Ubuntu:
  Fix Released
Status in wsl-pro-service source package in Focal:
  New
Status in wsl-pro-service source package in Jammy:
  New
Status in wsl-pro-service source package in Noble:
  Fix Released

Bug description:
  [Availability]
  The package wsl-pro-service is already available in Ubuntu universe.
  The package wsl-pro-service build for the architectures it is designed to 
work on.
  It currently builds and works for architectures: amd64, arm64, armhf, 
ppc64el, riscv64, s390x

  Link to package https://launchpad.net/ubuntu/+source/wsl-pro-service

  [Rationale]
  Ubuntu Pro for WSL is a set of applications to manage Ubuntu WSL instances, 
grant them Pro status, orchestrate instances from Landscape and manage their 
lifecycle. Wsl-pro-service serves as a bridge between the agent running on 
Windows and Ubuntu instances. It controls the Pro and Landscape status.
  The package wsl-pro-service is required to be in main to seed it by default 
on WSL images.
  The package wsl-pro-service will generally be useful for corporate users.  
  No package in main or universe currently offers these capabilities.

  The target release is all the LTS releases from 20.04 onwards.

  [Security]
  This is a new software developed and maintained by Canonical. It has no 
security history.

  It is a new software and no CVEs/security issues in this software in
  the past.

  - no `suid` or `sgid` binaries
  - The package installs a systemd service called wsl-pro-service
  - It installs a service in /usr/libexec/wsl-pro-service, running as root. The 
service has some systemd confinement.
  - Packages does not open privileged ports (ports < 1024)
  - Packages does not contain extensions to security-sensitive software
  - Communication between wsl-pro-service and the agent running on Windows is 
done over gRPC.
  - Security has been kept in mind and common isolation/risk-mitigation 
patterns are in place utilizing systemd isolation features.

  *This requires a security review.*

  [Quality assurance - function/usage]
  The package works well right after installation. 

  [Quality assurance - maintenance]
  The Ubuntu Desktop team (~desktop-packages) maintains this package. It 
doesn’t have any long-term and critical, open bugs: 
  - https://github.com/canonical/ubuntu-pro-for-windows/issues 
  - https://bugs.launchpad.net/ubuntu/+source/wsl-pro-service 

  [Quality assurance - testing]
  There is a comprehensive, non-trivial, testsuite. The testsuite includes 
integration and functional tests.
  The testsuite runs at build time. The branch coverage is over 88%:
  - 
https://github.com/canonical/ubuntu-pro-for-windows/actions/workflows/qa.yaml?query=branch%3Amain
 
  - https://app.codecov.io/gh/canonical/ubuntu-pro-for-wsl 

  The same test suite runs as autopkgtest. It is passing on all supported 
architectures. Links to test logs:
  - https://autopkgtest.ubuntu.com/packages/wsl-pro-service

  Upstream CI also includes code sanity checks (golangci-lint, including
  gosec) and vulnerability scanning (govulneck).

  [Quality assurance - packaging]
  - There is no debian/watch because wsl-pro-service is a native package.
  - debian/control defines a correct Maintainer field:
  - Maintainer: Ubuntu Developers <[email protected]>

  This package does not yield massive lintian Warnings, Errors
  ```
     W: wsl-pro-service: no-manual-page [usr/libexec/wsl-pro-service]
  ```

  Full output from   `lintian --pedantic`:

  ```
     W: wsl-pro-service: no-manual-page [usr/libexec/wsl-pro-service]
  ```

  - Lintian overrides  are not present.
  - This package does not rely on obsolete or about to be demoted packages.
  - This package has no python2 or GTK2 dependencies
  - The package will be installed by default but does not ask debconf questions.

  Packaging and build is easy:
  - 
https://github.com/canonical/ubuntu-pro-for-windows/blob/main/wsl-pro-service/debian/rules
  

  [UI standards]
  Application is not end-user facing. However some strings are translatable and 
used for error messages via standard intltool/gettext or similar build and 
runtime internationalization system:

  The system for internationalization is in place of the project and the
  mo and po files are generated. It’s a question of taking the time to
  mark the appropriate strings for translations. It is a background
  service. Strings are used for logging and are not immediately visible
  to the user.

  [Dependencies]
  No further depends or recommends dependencies that are not yet in main.

  [Standards compliance]
  - This package correctly follows FHS 
  - This package violates Debian Policy. It vendorizes various Go libraries (in 
vendor/). We are maintaining them up to date with dependabot in our upstream 
CI. The Go part is covered by the govulncheck security scanning on the Go 
version we are depending on and its vendored dependency.

  [Maintenance/Owner]
  - The owning team will be desktop-packages and I have their acknowledgement 
for that commitment
  - The team desktop-packages is subscribed.
  - The team desktop-packages is aware of the implications by a static build 
and commits to test no-change-rebuilds and to fix any issues found for the 
lifetime of the release (including ESM).
  - The team desktop-packages is aware of the implications of vendored code and 
(as alerted by the security team) commits to provide updates to the security 
team for any affected vendored code for the lifetime of the release  (including 
ESM).

  [Background information]
  - The Package description explains the package well.
  - Upstream Name is wsl-pro-service.
  - Link to upstream project https://github.com/canonical/ubuntu-pro-for-windows

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/wsl-pro-service/+bug/2052495/+subscriptions


-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : [email protected]
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to