treewide: use Pinner to resolve safety issues

Prior to Go 1.21 the only way to pass Go-managed pointers to the kernel
was to convert them to a uintptr inside the syscall argument expression.
This pattern was special-cased in the compiler to prevent the referenced
memory from being moved by an eventual moving GC in Go while the syscall
is running (thus corrupting the Go heap).

But this was very restrictive as there are syscalls which take inputs
containing further pointers.  According to the official rules this could
not be implemented safely.

In practice you could just do it anyways as the current Go GC does
in general not move objects, but it was always kind of a hack.
With Go 1.21 there is a new Pinner API which can be used to pin the
memory which is going to be referenced in these structures, allowing
them to be constructed and used over multiple calls.

runtime.KeepAlive is still required to prevent finalizers from running
prematurely.

Use this new API and remove the relevant comments.

Change-Id: I26bce06e1c20a5fe0c41f9ae736a895f533674c1
Reviewed-on: https://review.monogon.dev/c/monogon/+/2316
Tested-by: Jenkins CI
Reviewed-by: Serge Bazanski <serge@monogon.tech>
3 files changed
tree: d71e84a77c0e77849390bacbde7554bc02fa48b6
  1. .github/
  2. build/
  3. cloud/
  4. go/
  5. intellij/
  6. metropolis/
  7. net/
  8. third_party/
  9. tools/
  10. .bazelignore
  11. .bazelproject
  12. .bazelrc
  13. .bazelrc.sandboxroot
  14. .bazelversion
  15. .git-ignore-revs
  16. .gitignore
  17. BUILD.bazel
  18. CODING_STANDARDS.md
  19. go.mod
  20. go.sum
  21. LICENSE
  22. README.md
  23. SETUP.md
  24. shell.nix
  25. WORKSPACE
README.md

Monogon Monorepo

This is the main repository containing the source code for the Monogon Platform.

This is pre-release software - take a look, and check back later!

Environment

Our build environment is self-contained and requires only minimal host dependencies:

  • A Linux machine or VM.
  • Bazelisk >= v1.15.0 (or a working Nix environment).
  • A reasonably recent kernel with user namespaces enabled.
  • Working KVM with access to /dev/kvm (if you want to run tests).

Our docs assume that Bazelisk is available as bazel on your PATH.

Refer to SETUP.md for detailed instructions.

Monogon OS

Run a single node demo cluster

Build CLI and node image:

bazel build //metropolis/cli/dbg //:launch --config dbg

Launch an ephemeral test node:

bazel test //:launch --config dbg --test_output=streamed

Run a kubectl command while the test is running:

bazel-bin/metropolis/cli/dbg/dbg_/dbg kubectl describe node

Test suite

Run full test suite:

bazel test --config dbg //...