A friend had asked how one can switch out of full-screen whilst running a VM within VMware Fusion on the Mac.
I had a quick dig about, and found this: -
Return to Another View from Full Screen View
Geeking in technology since 1985, with IBM Development, focused upon Docker and Kubernetes on the IBM Z LinuxONE platform In the words of Dr Cathy Ryan, "If you don't write it down, it never happened". To paraphrase one of my clients, "Every day is a school day". I do, I learn, I share. The postings on this site are my own and don’t necessarily represent IBM’s positions, strategies or opinions. Remember, YMMV https://infosec.exchange/@davehay
A friend had asked how one can switch out of full-screen whilst running a VM within VMware Fusion on the Mac.
I had a quick dig about, and found this: -
Return to Another View from Full Screen View
As per previous posts : -
Tinkering with SonarQube for code-scanning shell scripts ...
Getting to grips with Maven - in five minutes ...
I've been tinkering further with SonarQube (SQ) to scan projects with Java files, both source .java AND compiled .class files.
I was trying to mitigate an issue where SQ or, to be more specific, the FindBugs plugin was complaining about uncompiled source ... in this instance, I've got a project that contains a single .java source file which, for various not-so-interesting reasons, has not been compiled.
This is what I did ...
Run SQ container
docker run -d --name sonarqube -e SONAR_ES_BOOTSTRAP_CHECKS_DISABLE=true -p 9000:9000 sonarqube:latest
Access SQ via browser
http://192.168.1.100:9000/about
Install FindBugs v4.0.1 plugin
http://192.168.1.100:9000/admin/marketplace?search=findbugs
Create Project
mkdir ~/DaveSQJava
Create Java source
vi ~/DaveSQJava/HelloWorld.java
public class HelloWorld
{
public static void main(String[] args)
{
for (int i = 0; i < 5; i++) {
System.out.println("Hello, World");
}
}
}
Scan Project
cd ~/DaveSQJava
sonar-scanner \ -Dsonar.projectKey=DaveSQJava \ -Dsonar.sources=. \ -Dsonar.host.url=http://192.168.1.100:9000 \ -Dsonar.login=2b7d7e9cd8d35baa9d9d5b8f11011bff703e4696
which fails with: -
ERROR: Error during SonarScanner execution
java.lang.IllegalStateException: Can not execute Findbugs
at org.sonar.plugins.findbugs.FindbugsExecutor.execute(FindbugsExecutor.java:188)
at org.sonar.plugins.findbugs.FindbugsSensor.execute(FindbugsSensor.java:114)
at org.sonar.scanner.sensor.AbstractSensorWrapper.analyse(AbstractSensorWrapper.java:48)
at org.sonar.scanner.sensor.ModuleSensorsExecutor.execute(ModuleSensorsExecutor.java:85)
at org.sonar.scanner.sensor.ModuleSensorsExecutor.lambda$execute$1(ModuleSensorsExecutor.java:59)
at org.sonar.scanner.sensor.ModuleSensorsExecutor.withModuleStrategy(ModuleSensorsExecutor.java:77)
at org.sonar.scanner.sensor.ModuleSensorsExecutor.execute(ModuleSensorsExecutor.java:59)
at org.sonar.scanner.scan.ModuleScanContainer.doAfterStart(ModuleScanContainer.java:82)
at org.sonar.core.platform.ComponentContainer.startComponents(ComponentContainer.java:137)
at org.sonar.core.platform.ComponentContainer.execute(ComponentContainer.java:123)
at org.sonar.scanner.scan.ProjectScanContainer.scan(ProjectScanContainer.java:393)
at org.sonar.scanner.scan.ProjectScanContainer.scanRecursively(ProjectScanContainer.java:389)
at org.sonar.scanner.scan.ProjectScanContainer.doAfterStart(ProjectScanContainer.java:358)
at org.sonar.core.platform.ComponentContainer.startComponents(ComponentContainer.java:137)
at org.sonar.core.platform.ComponentContainer.execute(ComponentContainer.java:123)
at org.sonar.scanner.bootstrap.GlobalContainer.doAfterStart(GlobalContainer.java:144)
at org.sonar.core.platform.ComponentContainer.startComponents(ComponentContainer.java:137)
at org.sonar.core.platform.ComponentContainer.execute(ComponentContainer.java:123)
at org.sonar.batch.bootstrapper.Batch.doExecute(Batch.java:72)
at org.sonar.batch.bootstrapper.Batch.execute(Batch.java:66)
at org.sonarsource.scanner.api.internal.batch.BatchIsolatedLauncher.execute(BatchIsolatedLauncher.java:46)
at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
at java.base/java.lang.reflect.Method.invoke(Unknown Source)
at org.sonarsource.scanner.api.internal.IsolatedLauncherProxy.invoke(IsolatedLauncherProxy.java:60)
at com.sun.proxy.$Proxy0.execute(Unknown Source)
at org.sonarsource.scanner.api.EmbeddedScanner.doExecute(EmbeddedScanner.java:189)
at org.sonarsource.scanner.api.EmbeddedScanner.execute(EmbeddedScanner.java:138)
at org.sonarsource.scanner.cli.Main.execute(Main.java:112)
at org.sonarsource.scanner.cli.Main.execute(Main.java:75)
at org.sonarsource.scanner.cli.Main.main(Main.java:61)
Caused by: java.lang.IllegalStateException: One (sub)project contains Java source files that are not compiled (/root/DaveSQJava).
at org.sonar.plugins.findbugs.FindbugsConfiguration.getFindbugsProject(FindbugsConfiguration.java:123)
at org.sonar.plugins.findbugs.FindbugsExecutor.execute(FindbugsExecutor.java:119)
... 31 more
ERROR:
ERROR: Re-run SonarScanner using the -X switch to enable full debug logging.
However, I found some inspiration here: -
sonar-findbugs 3.6 fails when analyzing module with non-compiled JSPs #148
which led me down a series of rabbit holes until I found a configuration option within the FindBugs plugin within the SQ web UI itself: -
Working a hunch, I decided to try sonar.findbugs.allowuncompiledcode as a command-line switch .....
What could possibly go wrong ?
Add -Dsonar.findbugs.allowuncompiledcode switch
sonar-scanner \ -Dsonar.projectKey=DaveSQJava \ -Dsonar.sources=. \ -Dsonar.host.url=http://192.168.1.100:9000 \ -Dsonar.login=2b7d7e9cd8d35baa9d9d5b8f11011bff703e4696 -Dsonar.findbugs.allowuncompiledcode
which....
WORKED !!
INFO: ------------------------------------------------------------------------
INFO: EXECUTION SUCCESS
INFO: ------------------------------------------------------------------------
INFO: Total time: 10.553s
INFO: Final Memory: 17M/60M
INFO: ------------------------------------------------------------------------
I then add a .jsp file into the mix ....
vi ~/DaveSQJava/HelloWorld.jsp
<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
pageEncoding="ISO-8859-1"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
<title>JSP - Hello World Tutorial - Programmer Gate</title>
</head>
<body>
<%= "Hello World!" %>
</body>
</html>
Even better, the scan actually did scan / review the .jsp ( Java Server Pages ) source, and found some bugs ...
Just to confirm, my project has NO compiled code therein ...
pwd
/root/DaveSQJava
ls -R -al
.:
total 20
drwxr-xr-x 3 root root 4096 Oct 12 12:27 .
drwx------ 15 root root 4096 Oct 12 12:27 ..
drwxr-xr-x 3 root root 4096 Oct 12 12:27 .scannerwork
-rw-r--r-- 1 root root 150 Oct 12 10:33 HelloWorld.java
-rw-r--r-- 1 root root 404 Oct 12 12:27 HelloWorld.jsp
./.scannerwork:
total 16
drwxr-xr-x 3 root root 4096 Oct 12 12:27 .
drwxr-xr-x 3 root root 4096 Oct 12 12:27 ..
-rw-r--r-- 1 root root 0 Oct 12 10:34 .sonar_lock
-rw-r--r-- 1 root root 0 Oct 12 12:27 class-mapping.csv
drwxr-xr-x 2 root root 4096 Oct 12 12:27 findbugs
-rw-r--r-- 1 root root 246 Oct 12 12:27 report-task.txt
./.scannerwork/findbugs:
total 8
drwxr-xr-x 2 root root 4096 Oct 12 12:27 .
drwxr-xr-x 3 root root 4096 Oct 12 12:27 ..
Now back in the day, I remember a version of DOS or Windows that introduced the tree command that allowed one to produce a pseudo-graphical listing of a file-system.
This nice picture from Wikipedia shows the concept: -
Well, I'd missed that on macOS ...
Now I miss it no longer ....
'twas a simple installation: -
brew install tree
As part of my investigation into SonarQube, as per: -
Tinkering with SonarQube for code-scanning shell scripts ...
I wanted to validate SQ's ability to scan Java projects.
SQ "assumes" that you're either using Maven or Gradle: -
so I thought I'd play with Maven, having used it for other Java work recently.
Thankfully, the Apache Maven project has a really useful tutorial on their site: -
which I followed, both on a Linux virtual server and on my Mac.
Here's a whiz-through the tutorial on my Mac ( with a bit of editorialising on my part ) : -
Validate Maven version
mvn --version
Apache Maven 3.6.3 (cecedd343002696d0abb50b32b541b8a6ba2883f)
Maven home: /usr/local/Cellar/maven/3.6.3_1/libexec
Java version: 1.8.0_251, vendor: Oracle Corporation, runtime: /Library/Java/JavaVirtualMachines/jdk1.8.0_251.jdk/Contents/Home/jre
Default locale: en_GB, platform encoding: UTF-8
OS name: "mac os x", version: "10.15.7", arch: "x86_64", family: "mac"
I'm having a very quick tinker with a tool called SonarQube for code quality scanning.
One of my colleagues had asked whether SQ can scan scripts e.g. Bash, which made me go "Hmmmm" and start to play ...
As you'd expect, I started with a Docker container: -
docker pull sonarqube
Whilst trying to build a Docker image on one of my IBM Z build servers yesterday, I hit a weird series of errors, including : -
ERRO[0000] Can't add file /root/dave/hello to tar: io: read/write on closed pipe
ERRO[0000] Can't close tar writer: io: read/write on closed pipe
Long story very short, I've been wrangling with a knotty "Permission denied" issue with a PostgreSQL container, with regard to some SQL and Bash scripts that the Dockerfile copies into the /docker-entrypoint-initdb.d directory at build time.
After some tinkering and thought, I realised what was going on ....
In short, the COPY command within the Dockerfile will, of course, inherit the permissions of the source files and, unless you choose to override with a chmod command, that's all she wrote ....
I proved this via a very simple test case: -
I started with this: -
ls -al
total 16
drwxr-x--- 2 root root 4096 Oct 1 12:52 .
drwx------ 15 root root 4096 Oct 1 12:52 ..
-rw-r----- 1 root root 94 Oct 1 12:32 Dockerfile
-rw------- 1 root root 13 Oct 1 12:28 greeting.txt
Whilst trying to hit my NAS from Firefox on my Mac, I kept seeing errors such as:- Unable to connect Firefox can’t establish a connection t...