Skip to content

retire our wireguard-go fork from coder/coder or upgrade gVisor #646

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
spikecurtis opened this issue May 19, 2025 · 2 comments
Closed

retire our wireguard-go fork from coder/coder or upgrade gVisor #646

spikecurtis opened this issue May 19, 2025 · 2 comments
Assignees
Labels
kiwi Tasks being handled by the NETGRU team tech-debt

Comments

@spikecurtis
Copy link

There are some vulnerabilities in gVisor. We need to either get rid of our wireguard-go fork and use some upstream commit that has taken the gVisor patched version, or directly upgrade our gVisor version.

@spikecurtis spikecurtis added tech-debt kiwi Tasks being handled by the NETGRU team labels May 19, 2025
@spikecurtis
Copy link
Author

We need to upgrade to gVisor 20231204.0.0 or newer.

@spikecurtis spikecurtis self-assigned this May 21, 2025
@spikecurtis
Copy link
Author

spikecurtis commented May 21, 2025

I'm looking into this in earnest, and coder/coder and our wireguard-go fork are already on gVisor release-20240506.0-27, which is newer than when those vulnerabilities reported in the email. (dates/SHA are different because we use the go branch rather than the main one that only builds with bazel).

I believe the tool that the person who reported it to us used is just wrong about these, possibly getting confused by the fact that we don't point to "official" version tags and instead point to "unofficial" go branch commits that are auto-updated to track the offical tags.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kiwi Tasks being handled by the NETGRU team tech-debt
Projects
None yet
Development

No branches or pull requests

1 participant