Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 0 additions & 1 deletion .golangci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -109,7 +109,6 @@ linters:
gosec:
excludes:
- G104 # G104: Errors unhandled; (TODO: reduce unhandled errors, or explicitly ignore)
- G115 # G115: integer overflow conversion; (TODO: verify these: https://github.com/docker/cli/issues/5584)
- G117 # G117: Exported struct field matches secret pattern (false positives for legitimate field names)
- G118 # G118: Goroutine uses context.Background/TODO while request-scoped context is available (TODO: evaluate these)
- G122 # G122: Filesystem operation in filepath.Walk/WalkDir callback uses race-prone path (TODO: evaluate these)
Expand Down
2 changes: 1 addition & 1 deletion cli/command/container/cp.go
Original file line number Diff line number Diff line change
Expand Up @@ -108,7 +108,7 @@ func copyProgress(ctx context.Context, dst io.Writer, header string, total *int6
}

// Write to the buffer first to avoid flickering and context switching
fmt.Fprint(buf, aec.Column(uint(len(header)+1)))
fmt.Fprint(buf, aec.Column(uint(len(header)+1))) // #nosec G115 -- length is non-negative
fmt.Fprint(buf, aec.EraseLine(aec.EraseModes.Tail))
fmt.Fprint(buf, progressHumanSize(n))

Expand Down
2 changes: 1 addition & 1 deletion cli/command/container/opts.go
Original file line number Diff line number Diff line change
Expand Up @@ -639,7 +639,7 @@ func parse(flags *pflag.FlagSet, copts *containerOptions, serverOS string) (*con
BlkioDeviceReadIOps: copts.deviceReadIOps.GetList(),
BlkioDeviceWriteIOps: copts.deviceWriteIOps.GetList(),
IOMaximumIOps: copts.ioMaxIOps,
IOMaximumBandwidth: uint64(copts.ioMaxBandwidth),
IOMaximumBandwidth: uint64(copts.ioMaxBandwidth), // #nosec G115 -- bandwidth bytes are non-negative
Ulimits: copts.ulimits.GetList(),
DeviceCgroupRules: copts.deviceCgroupRules.GetSlice(),
Devices: deviceMappings,
Expand Down
10 changes: 7 additions & 3 deletions cli/command/container/stats_helpers.go
Original file line number Diff line number Diff line change
Expand Up @@ -200,10 +200,14 @@ func calculateCPUPercentUnix(previousCPU container.CPUStats, curCPUStats contain
}

func calculateCPUPercentWindows(v *container.StatsResponse) float64 {
ns := v.Read.Sub(v.PreRead).Nanoseconds()
if ns <= 0 {
return 0.0
}
// Max number of 100ns intervals between the previous time read and now
possIntervals := uint64(v.Read.Sub(v.PreRead).Nanoseconds()) // Start with number of ns intervals
possIntervals /= 100 // Convert to number of 100ns intervals
possIntervals *= uint64(v.NumProcs) // Multiply by the number of processors
possIntervals := uint64(ns) // #nosec G115 -- guarded above: ns is positive
possIntervals /= 100 // Convert to number of 100ns intervals
possIntervals *= uint64(v.NumProcs) // Multiply by the number of processors

// Percentage avoiding divide-by-zero
if possIntervals > 0 {
Expand Down
4 changes: 2 additions & 2 deletions cli/command/image/tree.go
Original file line number Diff line number Diff line change
Expand Up @@ -351,7 +351,7 @@ func printImageTree(outs command.Streams, view treeView) {
// available for image names and removes any columns that would be too narrow
// to display their content.
func adjustColumns(width uint, columns []imgColumn, images []topImage) []imgColumn {
nameWidth := int(width)
nameWidth := int(width) // #nosec G115 -- terminal width fits in int
if nameWidth > 0 {
for idx, h := range columns {
if h.Width == 0 {
Expand Down Expand Up @@ -391,7 +391,7 @@ func generateLegend(out tui.Output, width uint) string {
}
legend += legendSb371.String()

r := max(int(width)-tui.Width(legend), 0)
r := max(int(width)-tui.Width(legend), 0) // #nosec G115 -- terminal width fits in int
legend = strings.Repeat(" ", r) + legend
return legend
}
Expand Down
2 changes: 1 addition & 1 deletion cli/command/service/logs.go
Original file line number Diff line number Diff line change
Expand Up @@ -130,7 +130,7 @@ func runLogs(ctx context.Context, dockerCli command.Cli, opts *logsOptions) erro
if service.Service.Spec.Mode.Replicated != nil && service.Service.Spec.Mode.Replicated.Replicas != nil {
// if replicas are initialized, figure out if we need to pad them
replicas := *service.Service.Spec.Mode.Replicated.Replicas
maxLength = getMaxLength(int(replicas))
maxLength = getMaxLength(int(replicas)) // #nosec G115 -- replicas count fits in int for length calculation
}

// we can't prettify tty logs. tell the user that this is the case.
Expand Down
10 changes: 5 additions & 5 deletions cli/command/service/progress/progress.go
Original file line number Diff line number Diff line change
Expand Up @@ -301,7 +301,7 @@ func (u *replicatedProgressUpdater) update(service swarm.Service, tasks []swarm.
u.slotMap = make(map[int]int)

// Draw progress bars in order
writeOverallProgress(u.progressOut, 0, int(replicas), rollback)
writeOverallProgress(u.progressOut, 0, int(replicas), rollback) // #nosec G115 -- replicas count fits in int

if replicas <= maxProgressBars {
for i := uint64(1); i <= replicas; i++ {
Expand Down Expand Up @@ -340,7 +340,7 @@ func (u *replicatedProgressUpdater) update(service swarm.Service, tasks []swarm.
}

if !u.done {
writeOverallProgress(u.progressOut, int(running), int(replicas), rollback)
writeOverallProgress(u.progressOut, int(running), int(replicas), rollback) // #nosec G115 -- task counts fit in int

if running == replicas {
u.done = true
Expand Down Expand Up @@ -383,7 +383,7 @@ func (*replicatedProgressUpdater) tasksBySlot(tasks []swarm.Task, activeNodes ma
}

func (u *replicatedProgressUpdater) writeTaskProgress(task swarm.Task, mappedSlot int, replicas uint64) {
if u.done || replicas > maxProgressBars || uint64(mappedSlot) > replicas {
if u.done || replicas > maxProgressBars || mappedSlot < 0 || uint64(mappedSlot) > replicas { // #nosec G115 -- mappedSlot is non-negative slot index
return
}

Expand Down Expand Up @@ -572,8 +572,8 @@ type replicatedJobProgressUpdater struct {
}

func newReplicatedJobProgressUpdater(service swarm.Service, progressOut progress.Output) *replicatedJobProgressUpdater {
concurrent := int(*service.Spec.Mode.ReplicatedJob.MaxConcurrent)
total := int(*service.Spec.Mode.ReplicatedJob.TotalCompletions)
concurrent := int(*service.Spec.Mode.ReplicatedJob.MaxConcurrent) // #nosec G115 -- job concurrency fits in int
total := int(*service.Spec.Mode.ReplicatedJob.TotalCompletions) // #nosec G115 -- job completions fit in int

return &replicatedJobProgressUpdater{
progressOut: progressOut,
Expand Down
2 changes: 1 addition & 1 deletion cli/command/swarm/unlock.go
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ func runUnlock(ctx context.Context, dockerCLI command.Cli) error {
func readKey(in *streams.In, prompt string) (string, error) {
if in.IsTerminal() {
fmt.Print(prompt)
dt, err := term.ReadPassword(int(in.FD()))
dt, err := term.ReadPassword(int(in.FD())) // #nosec G115 -- file descriptor fits in int
fmt.Println()
return string(dt), err
}
Expand Down
4 changes: 2 additions & 2 deletions cli/compose/convert/service.go
Original file line number Diff line number Diff line change
Expand Up @@ -458,7 +458,7 @@ func convertHealthcheck(healthcheck *composetypes.HealthCheckConfig) (*container
startInterval = time.Duration(*healthcheck.StartInterval)
}
if healthcheck.Retries != nil {
retries = int(*healthcheck.Retries)
retries = int(*healthcheck.Retries) // #nosec G115 -- retries count fits in int
}
return &container.HealthConfig{
Test: healthcheck.Test,
Expand Down Expand Up @@ -500,7 +500,7 @@ func convertRestartPolicy(restart string, restartPolicy *composetypes.RestartPol
if i <= 0 {
return nil
}
return new(uint64(i))
return new(uint64(i)) // #nosec G115 -- maximum retry count is verified non-negative
}

switch policy.Name {
Expand Down
4 changes: 2 additions & 2 deletions opts/swarmopts/port.go
Original file line number Diff line number Diff line change
Expand Up @@ -174,8 +174,8 @@ func ConvertPortToPortConfig(
ports = append(ports, swarm.PortConfig{
// TODO Name: ?
Protocol: portProto.Proto(),
TargetPort: uint32(portProto.Num()),
PublishedPort: uint32(p.Num()),
TargetPort: uint32(portProto.Num()), // #nosec G115 -- port number is uint16
PublishedPort: uint32(p.Num()), // #nosec G115 -- port number is uint16
PublishMode: swarm.PortConfigPublishModeIngress,
})
}
Expand Down