|
| 1 | +# SOW-0027 - Netdata Vendor Memory-Safety Update |
| 2 | + |
| 3 | +## Status |
| 4 | + |
| 5 | +Status: in-progress |
| 6 | + |
| 7 | +Sub-state: preflight found one Netdata-only vendored-source Sonar cleanup that must be backported to `plugin-ipc` before copying source into Netdata. |
| 8 | + |
| 9 | +## Requirements |
| 10 | + |
| 11 | +### Purpose |
| 12 | + |
| 13 | +Keep NetIPC memory-safety fixes source-owned in `plugin-ipc` while ensuring the Netdata vendored copy receives those fixes through the normal vendor/update path. |
| 14 | + |
| 15 | +### User Request |
| 16 | + |
| 17 | +The user asked to fix NetIPC library issues in `plugin-ipc`, not directly in the Netdata PR, because this repository is the source of truth. |
| 18 | + |
| 19 | +On 2026-07-01, the user resumed the Netdata vendoring task after source CI and scanner readiness work was pushed. The target Netdata checkout is `~/src/netdata-ktsaou.git`, matching the checkout the user previously asked to compare against and the default Netdata Agent checkout in the repository instructions. |
| 20 | + |
| 21 | +### Assistant Understanding |
| 22 | + |
| 23 | +Facts: |
| 24 | + |
| 25 | +- SOW-0026 implements source fixes for NetIPC memory-safety scout findings in `plugin-ipc`. |
| 26 | +- SOW-0029 implements later scanner-readiness fixes, including the POSIX service thread handoff change. |
| 27 | +- Netdata consumes NetIPC through a vendored copy. |
| 28 | +- Directly patching Netdata's vendored NetIPC copy would create source-of-truth drift. |
| 29 | +- The current candidate source commit before this SOW's backport is `fe4e31633b5372b3c93e21f9e37b38f2407aaed1`. |
| 30 | +- The last confirmed Netdata vendor baseline is Netdata commit `b7146a36260d9ee80a976d47f57acc22c5569c93`, which matches plugin-ipc commit `96f5f2962188c2198e621fec5da8a4c90710b46a`. |
| 31 | +- Netdata commit range `b7146a3626..HEAD` includes one downstream vendored-source edit in `src/libnetdata/netipc/src/transport/posix/netipc_uds_receive.c`: uppercase `ULL` literal suffixes for Sonar rule `c:S818`. |
| 32 | + |
| 33 | +Inferences: |
| 34 | + |
| 35 | +- The Netdata-only `ULL` suffix cleanup is a valid vendored-source drift item. Because `plugin-ipc` is the source of truth, it must be backported here before the vendor copy is refreshed. |
| 36 | + |
| 37 | +Unknowns: |
| 38 | + |
| 39 | +- Whether the next pushed source commit will keep GitHub and Codacy checks green; this must be checked before copying into Netdata. |
| 40 | + |
| 41 | +### Acceptance Criteria |
| 42 | + |
| 43 | +- The selected Netdata checkout is confirmed before implementation. |
| 44 | +- Source CI, GitHub code/security scanners, Dependabot, secret scanning, and Codacy Cloud are checked before any Netdata vendoring copy. |
| 45 | +- The two-way gap analysis is recorded before vendoring. |
| 46 | +- Any valid Netdata-only vendored-source drift is backported to `plugin-ipc` before vendoring. |
| 47 | +- The vendored NetIPC copy is updated from `plugin-ipc` rather than manually patched. |
| 48 | +- The project-local vendor diff/checker is run and its result is recorded. |
| 49 | +- Netdata build or targeted tests covering the touched NetIPC integration paths are run or a blocker is recorded with evidence. |
| 50 | +- No unrelated Netdata changes are included. |
| 51 | + |
| 52 | +## Analysis |
| 53 | + |
| 54 | +Sources checked: |
| 55 | + |
| 56 | +- SOW-0026 source-ownership decision. |
| 57 | +- `docs/netipc-integrator-skill.md` source-of-truth guidance. |
| 58 | +- Prior vendor synchronization SOWs in `.agents/sow/done/`. |
| 59 | + |
| 60 | +Current state: |
| 61 | + |
| 62 | +- Source fixes are expected to land in `plugin-ipc` through SOW-0026 first. |
| 63 | +- No Netdata checkout has been selected for this SOW yet. |
| 64 | + |
| 65 | +Risks: |
| 66 | + |
| 67 | +- Copying files manually can introduce import-path or layout mistakes. |
| 68 | +- Updating the wrong Netdata checkout can create unrelated branch drift. |
| 69 | +- Skipping the vendor diff can hide missing language-specific updates. |
| 70 | + |
| 71 | +## Pre-Implementation Gate |
| 72 | + |
| 73 | +Status: in-progress |
| 74 | + |
| 75 | +Problem / root-cause model: |
| 76 | + |
| 77 | +- NetIPC fixes must be propagated to the downstream Netdata vendored copy through `plugin-ipc`, the source-of-truth repository. |
| 78 | +- A direct Netdata vendored-copy refresh from `fe4e31633b5372b3c93e21f9e37b38f2407aaed1` would overwrite one Netdata-only scanner cleanup in a vendored source file. That would recreate downstream drift and can re-trigger Netdata Sonar noise. |
| 79 | + |
| 80 | +Evidence reviewed: |
| 81 | + |
| 82 | +- SOW-0026 records that NetIPC source ownership belongs to `plugin-ipc`. |
| 83 | +- Historical vendor-sync SOWs use the project-local `diff-netdata-vendor.sh` checker. |
| 84 | +- `.agents/skills/project-netdata-vendoring/SKILL.md` requires source CI/scanner preflight, last-baseline reconstruction, two-way gap analysis, and a migration plan before Netdata is modified. |
| 85 | +- `git -C ~/src/netdata-ktsaou.git log --oneline -- src/libnetdata/netipc src/crates/netipc src/go/pkg/netipc` identified `b7146a3626` as the latest vendor update. |
| 86 | +- Historical Netdata SOW evidence and the vendor commit contents identify plugin-ipc `96f5f2962188c2198e621fec5da8a4c90710b46a` as the matching source baseline. |
| 87 | +- Source CI/checks for `fe4e31633b5372b3c93e21f9e37b38f2407aaed1` were all successful: CodeQL, Static Analysis, Runtime Safety, Supply Chain Security, Codacy Local Analysis, Codacy Coverage, and the Codacy push quality check. |
| 88 | +- Current source code-scanning analyses for `fe4e31633b5372b3c93e21f9e37b38f2407aaed1` reported zero results for CodeQL, Semgrep, gosec, OSV, and Codacy local. |
| 89 | +- GitHub code scanning still shows one stale open Semgrep alert on old commit `b4dfe405e1f99be417c21a9c0478aba2f64facaa`; current commit analyses report zero Semgrep results. |
| 90 | +- GitHub Dependabot open alerts: none. |
| 91 | +- GitHub secret-scanning open alerts: none. |
| 92 | +- Codacy Cloud analyzed `fe4e31633b5372b3c93e21f9e37b38f2407aaed1`; repository problems were empty and coverage was 90%. The remaining 23 Go standard-library dependency findings are the previously accepted `go 1.26.0` compatibility exception. |
| 93 | +- Source tree has one unrelated modified file, `bench/drivers/go/go`; it is not part of this vendoring scope and must not be staged. |
| 94 | +- Netdata checkout `~/src/netdata-ktsaou.git` is on `master...origin/master` with unrelated untracked files; they are not part of this vendoring scope and must not be staged. |
| 95 | + |
| 96 | +Affected contracts and surfaces: |
| 97 | + |
| 98 | +- Netdata vendored C, Rust, and Go NetIPC sources. |
| 99 | +- Netdata build/test paths that consume NetIPC. |
| 100 | +- Vendor synchronization evidence in this SOW. |
| 101 | +- Source-side scanner hygiene for C integer literal suffixes in vendored NetIPC C files. |
| 102 | + |
| 103 | +Existing patterns to reuse: |
| 104 | + |
| 105 | +- `diff-netdata-vendor.sh` |
| 106 | +- `vendor-to-netdata.sh` |
| 107 | +- Prior SOW-0003 and SOW-0008 vendor synchronization flow. |
| 108 | +- Netdata's existing Go import normalization from `github.com/netdata/plugin-ipc/go` to `github.com/netdata/netdata/go/plugins`. |
| 109 | + |
| 110 | +Risk and blast radius: |
| 111 | + |
| 112 | +- Medium: changes land in a consumer repository and may affect Netdata build/test behavior. |
| 113 | +- Keep scope limited to NetIPC vendor propagation and required validation. |
| 114 | +- Low source risk for the literal suffix backport: it is scanner/style normalization only, with no value or ABI change. |
| 115 | +- Medium process risk if the stale old GitHub code-scanning alert is confused with a current-commit issue; mitigation is to record both the open alert and the current-commit zero-result analyses. |
| 116 | + |
| 117 | +Sensitive data handling plan: |
| 118 | + |
| 119 | +- No secrets, customer data, credentials, production logs, or private endpoints are required. |
| 120 | +- Evidence will use source paths, commands, commit hashes, and sanitized summaries only. |
| 121 | + |
| 122 | +Implementation plan: |
| 123 | + |
| 124 | +1. Backport the downstream Netdata Sonar `ULL` suffix cleanup into `plugin-ipc`, applying the same numeric literal suffix style to equivalent NetIPC C numeric `ull` literals. |
| 125 | +2. Run focused source validation for the touched C files and commit/push the source backport. |
| 126 | +3. Re-check source GitHub CI, GitHub code/security scanners, Dependabot, secret scanning, and Codacy Cloud for the new source commit. |
| 127 | +4. Vendor the pushed source commit into `~/src/netdata-ktsaou.git` using `vendor-to-netdata.sh`. |
| 128 | +5. Normalize Netdata Go import paths if the vendor script leaves upstream module paths. |
| 129 | +6. Run `diff-netdata-vendor.sh` and inspect the remaining diff. |
| 130 | +7. Run targeted Netdata C, Rust, and Go validation. |
| 131 | +8. Commit only the intended Netdata vendor update files, excluding unrelated untracked or dirty files. |
| 132 | + |
| 133 | +Validation plan: |
| 134 | + |
| 135 | +- Source-side validation: focused C build or full low-priority CTest if the scope requires it; `git diff --check`; SOW audit. |
| 136 | +- Source-side post-push validation: GitHub Actions/check-runs, code scanning, Dependabot, secret scanning, and Codacy Cloud. |
| 137 | +- Run the vendor diff/checker against the selected Netdata checkout. |
| 138 | +- Run targeted Netdata build/tests for touched C/Rust/Go NetIPC integration paths. |
| 139 | +- Run same-failure searches for the SOW-0026 finding classes in the Netdata vendored copy. |
| 140 | +- Search for lowercase numeric `ull` suffixes in NetIPC C files after vendoring. |
| 141 | +- Search for stale `github.com/netdata/plugin-ipc/go` imports after vendoring. |
| 142 | + |
| 143 | +Artifact impact plan: |
| 144 | + |
| 145 | +- AGENTS.md: no expected update; vendoring preflight and low-priority validation policy are already recorded. |
| 146 | +- Runtime project skills: no expected update unless this SOW exposes a reusable vendoring gap not already covered by `project-netdata-vendoring`. |
| 147 | +- Specs: no expected update unless propagation exposes source/doc drift. |
| 148 | +- End-user/operator docs: no expected update. |
| 149 | +- End-user/operator skills: no expected update. |
| 150 | +- SOW lifecycle: move from pending to current before source backport and vendoring; complete only after source and Netdata validations are recorded. |
| 151 | + |
| 152 | +Open-source reference evidence: |
| 153 | + |
| 154 | +- None checked yet; this SOW is a local vendor propagation task. |
| 155 | + |
| 156 | +Open decisions: |
| 157 | + |
| 158 | +None currently blocking. The target checkout is `~/src/netdata-ktsaou.git`; branch/PR handling will be determined after local validation so unrelated local files are not staged. |
| 159 | + |
| 160 | +## Implications And Decisions |
| 161 | + |
| 162 | +- Decision: backport valid Netdata-only vendored-source drift into `plugin-ipc` before vendoring. This is long-term-best because it keeps the source repository authoritative and prevents the next vendor run from reintroducing the same Netdata scanner finding. |
| 163 | +- Decision: treat the stale open GitHub Semgrep alert on old commit `b4dfe405e1f99be417c21a9c0478aba2f64facaa` as not blocking the current candidate only because current-commit code-scanning analyses report zero Semgrep results. If GitHub reports the same alert on the new source commit, vendoring blocks until fixed or explicitly risk-accepted. |
| 164 | + |
| 165 | +## Plan |
| 166 | + |
| 167 | +1. Backport the downstream Netdata Sonar suffix cleanup to `plugin-ipc`. |
| 168 | +2. Validate, commit, push, and re-check source CI/scanners. |
| 169 | +3. Run vendor propagation into `~/src/netdata-ktsaou.git`. |
| 170 | +4. Validate vendor parity and targeted Netdata behavior. |
| 171 | +5. Commit and push when validated. |
| 172 | + |
| 173 | +## Execution Log |
| 174 | + |
| 175 | +### 2026-06-29 |
| 176 | + |
| 177 | +- Created as the tracked follow-up for SOW-0026 vendor propagation. |
| 178 | +- No implementation started. |
| 179 | + |
| 180 | +### 2026-07-01 |
| 181 | + |
| 182 | +- Loaded `.agents/skills/project-netdata-vendoring/SKILL.md`. |
| 183 | +- Confirmed current source candidate before backport: `fe4e31633b5372b3c93e21f9e37b38f2407aaed1`. |
| 184 | +- Confirmed source CI and scanner status for that candidate, with only the previously accepted Go `1.26.0` Codacy dependency findings and one stale old GitHub Semgrep alert not present in current-commit analyses. |
| 185 | +- Confirmed Netdata target checkout: `~/src/netdata-ktsaou.git`. |
| 186 | +- Confirmed baseline: Netdata commit `b7146a36260d9ee80a976d47f57acc22c5569c93` and plugin-ipc commit `96f5f2962188c2198e621fec5da8a4c90710b46a`. |
| 187 | +- Performed two-way gap analysis: |
| 188 | + - Upstream gap: 49 vendored C/Rust/Go NetIPC source files changed from `96f5f2962188c2198e621fec5da8a4c90710b46a` to `fe4e31633b5372b3c93e21f9e37b38f2407aaed1`, covering cgroups snapshot cache concurrency, memory-safety hardening, scanner cleanup, and POSIX service thread handoff. |
| 189 | + - Downstream gap: one Netdata-only vendored-source edit in `src/libnetdata/netipc/src/transport/posix/netipc_uds_receive.c` changed `ull` to `ULL` for Sonar rule `c:S818`. |
| 190 | +- Migration plan before vendoring: backport the downstream `ULL` suffix cleanup to source first, then re-run source validation and CI/scanner checks before copying to Netdata. |
| 191 | +- Backported the downstream Sonar literal-suffix cleanup into `plugin-ipc`: |
| 192 | + - `src/libnetdata/netipc/src/transport/posix/netipc_uds_receive.c` |
| 193 | + - `src/libnetdata/netipc/src/transport/posix/netipc_shm.c` |
| 194 | + - `src/libnetdata/netipc/include/netipc/netipc_named_pipe.h` |
| 195 | +- Same-pattern source search after the edit: `rg -n '\b(0x[0-9A-Fa-f]+|[0-9]+)ull\b' src/libnetdata/netipc` returned no matches. |
| 196 | +- Source validation after the edit: |
| 197 | + - `tests/run-low-priority.sh cmake --build build --target netipc_uds netipc_shm netipc_service`: passed. |
| 198 | + - `tests/run-low-priority.sh /usr/bin/ctest --test-dir build --output-on-failure -R 'uds|shm|service'`: 19/19 tests passed. |
| 199 | + - `git diff --check`: passed. |
| 200 | + - `bash .agents/sow/audit.sh`: passed. |
| 201 | +- Note: the unqualified `ctest` in the user-local PATH failed because its Python `cmake` module was unavailable, so validation used `/usr/bin/ctest`. |
| 202 | + |
| 203 | +## Validation |
| 204 | + |
| 205 | +Acceptance criteria evidence: |
| 206 | + |
| 207 | +- Selected Netdata checkout confirmed: `~/src/netdata-ktsaou.git`. |
| 208 | +- Source preflight completed before Netdata vendoring: CI/checks, GitHub code scanning, Dependabot, secret scanning, and Codacy Cloud were checked for `fe4e31633b5372b3c93e21f9e37b38f2407aaed1`. |
| 209 | +- Two-way gap analysis completed before vendoring and recorded in the 2026-07-01 execution log. |
| 210 | +- Valid Netdata-only vendored-source drift was backported to `plugin-ipc` before any Netdata copy. |
| 211 | +- Netdata vendoring, Netdata validation, Netdata commit, and post-vendor evidence are not started yet. |
| 212 | + |
| 213 | +Tests or equivalent validation: |
| 214 | + |
| 215 | +- Source-side focused validation passed: |
| 216 | + - focused C build for `netipc_uds`, `netipc_shm`, and `netipc_service`; |
| 217 | + - focused C/Rust/Go transport/service CTest subset, 19/19 passed; |
| 218 | + - source same-pattern numeric lowercase `ull` search, no matches; |
| 219 | + - `git diff --check`; |
| 220 | + - SOW audit. |
| 221 | +- GitHub/Codacy validation for the new source backport commit is pending until the commit is pushed. |
| 222 | + |
| 223 | +Real-use evidence: |
| 224 | + |
| 225 | +- Not started for Netdata; vendor copy has not been modified yet. |
| 226 | + |
| 227 | +Reviewer findings: |
| 228 | + |
| 229 | +- Not started. |
| 230 | + |
| 231 | +Same-failure scan: |
| 232 | + |
| 233 | +- Source same-pattern scan for lowercase numeric `ull` suffixes in `src/libnetdata/netipc` returned no matches. |
| 234 | + |
| 235 | +Sensitive data gate: |
| 236 | + |
| 237 | +- The SOW contains only source paths and workflow descriptions. No secrets or customer data are included. |
| 238 | + |
| 239 | +Artifact maintenance gate: |
| 240 | + |
| 241 | +- AGENTS.md: no update needed for this tracking SOW. |
| 242 | +- Runtime project skills: none exist. |
| 243 | +- Specs: no update needed until implementation changes behavior. |
| 244 | +- End-user/operator docs: no update needed until implementation changes behavior. |
| 245 | +- End-user/operator skills: no update needed until implementation changes behavior. |
| 246 | +- SOW lifecycle: created as open in `.agents/sow/pending/`. |
| 247 | + |
| 248 | +Specs update: |
| 249 | + |
| 250 | +- Not started. |
| 251 | + |
| 252 | +Project skills update: |
| 253 | + |
| 254 | +- Not started. |
| 255 | + |
| 256 | +End-user/operator docs update: |
| 257 | + |
| 258 | +- Not started. |
| 259 | + |
| 260 | +End-user/operator skills update: |
| 261 | + |
| 262 | +- Not started. |
| 263 | + |
| 264 | +Lessons: |
| 265 | + |
| 266 | +- None yet. |
| 267 | + |
| 268 | +Follow-up mapping: |
| 269 | + |
| 270 | +- This SOW tracks the SOW-0026 Netdata vendor propagation item. |
| 271 | + |
| 272 | +## Outcome |
| 273 | + |
| 274 | +Pending. |
| 275 | + |
| 276 | +## Lessons Extracted |
| 277 | + |
| 278 | +Pending. |
| 279 | + |
| 280 | +## Followup |
| 281 | + |
| 282 | +None yet. |
| 283 | + |
| 284 | +## Regression Log |
| 285 | + |
| 286 | +None yet. |
0 commit comments