Unix sockets, Cygwin, SSH agents, and sadness
mjg59.dreamwidth.org
mjg59.dreamwidth.org
> Attempting to 'unixify' Windows is indeed a task often drought with much pain
I chose TDM [1] to port some utility of mine to Windows (actually the initial port may have have been done with MSYS/Cygwin). TDM is MinGW-based and doesn't try to achieve full Posix compliance. It provides Win API header files instead.
I did the adaptations for my socket-related stuff a long time ago. A bit tedious, but worth it. I don't depend on a DLL that's bigger than my program, and I have fine control on what it does.
I discovered TDM thanks to Newlisp, a Lisp dialect interpreter which has quite a few batteries included [2] (some of its feature are still Linux-only though).
[1] https://jmeubank.github.io/tdm-gcc/ [2] http://www.newlisp.org/
I ended up giving up on native tools and msys2 entirely in favor of WSL2 after several months.
And then finally asking for a Mac after several more.
There are way too many bugs and quirks in every layer of this stuff, from missing features in the 'native' OpenSSH port by Microsoft to data loss bugs (!) in WSL2.
Mind going into this in more detail?
But they make it really hard to rely on. From random shutdowns, GPU unreliability to data corruption and performance differences with just using Linux directly, I had to move away from it and back to Linux because I felt like I slowly losing my mind troubleshooting these issues.
Latest issue was that the virtual disk file continued to grow beyond 500GB large while Linux still reported that it was just 20% full from the inside. So, reading about things, I gave optimize-vhd a try and boom, full disk file was corrupted.
So, gave it a try, hit a bunch of issues, left and not planning to touch it again until WSL3, and I'll be much more cautious then.
The issue seemed to be that sometimes files which the guest believed were written to disk were not actually written to the VHD file backing it, or the VHD file's changes were not actually written back to the physical disk. So sometimes upon a reboot (or after `wsl --shutdown`, which doesn't attempt safe shutdown IIRC), I'd lose files.
Generally it was only system files, and was recoverable by mounting the VHD for the guest to a new guest and repairing the OS in the worst cases, but sometimes did render the guest unbootable.
When I Googled the issue, I found people reporting similar problems on GitHub and Reddit going back years. On bare metal, the same distro I was running features atomic upgrades (on all filesystems), has survived power outages during system upgrades, etc.
Because they want to support Git for Windows which is built upon Cygwin/msys. And this is fine because Cygwin is much faster than WSL and a good Windows integration is so much easier. Would be a total PITA if Git would only be available through WSL.
Cygwin is still the best thing ever happened to Windows (or to Linuxers who are forced to work with Windows).
I read that, but I was wondering why they wanted that because they don't say. I've never noticed git to be slow under WSL but I guess that very much depends on your repo size and exactly what you are doing. It all sounds like a tremendous amount of hassle otherwise.
I agree, Cygwin did enable us to work productively for many years. But Cygwin's drive mounting modes caused lots of pain. And the Xserver is simply awful. It is/was a constant source of issues, the worst being the incredibly frustrating crashes. Maybe they were due to underlying issues in the applications themselves but those apps work fine under WSLg (of course there are other bugs but we can still work with those).
This is made worse because git uses the os-specific file statistics including inode number to track file changes. These change over most such file systems types which triggers it to rebuild the entire file cache every time you switch OS running git commands. Which if you have shell integration is constantly.
I share my git repos between MacOS and a Linux volume and it hurts on any repo with 100s of thousands of files or more. Ceph, Linux kernel, etc.
I've found this thorough explanation https://github.com/microsoft/WSL/issues/4197#issuecomment-60...
I also use WSL1 though so maybe my setup is weird.
Works like a charm and I can use cool terminal (bash) with all CLI tools I love so much.
Is it? I'm pretty sure WSL is much faster if your workflow allows putting files on Linux filesystem, but I also recall that perf in shared Windows folders felt about the same (bad, but not even worse) when I switched from msys git to WSL. But haven't used Windows in years, so memory could be bad.
Cygwin is roughly 100x slower with forking than Linux on the same hardware.
I understand that Postgres benefits greatly in running under the WSL for this reason.
Sure WSL1 could never have handled docker as-is, but general software would've been mostly fine and given us damn good windows application integration. (And I'm sure some Docker shims would've appeared fairly quickly to satisfy most basic developer needs).
These days I'm just running a full blown Linux DE in a VirtualBox VM since its graphic console isn't objectively terrible like Hyper-V. If for some reason I need to copy/sync files with the Windows host - well that's just an rsync away thanks to Cywgin.
> WSL 2 is available on all Desktop SKUs where WSL is available, including Windows 10 Home and Windows 11 Home.
Looks like there is work on this at https://github.com/PowerShell/openssh-portable/pull/674 and eventually take advantage of https://devblogs.microsoft.com/commandline/af_unix-comes-to-...
Later versions of PuTTY pageant.exe are now able to service the Microsoft clients, without extra privilege or a running service.
It is a better fit.
The PuTTY site isn't responding on my phone at the moment, or I'd post a link to the docs.
1. In the start menu search for "Services"
2. Double click on "OpenSSH Authentication Agent"
3. Set the startup type to "Automatic"
4. Click "Start" and then OK.
And after that one-time fix it's perfectly usable. It is possible I also had to do something else and forgot to document it.Since PuTTY can do both, why bother with Microsoft?
Here are the instructions:
https://the.earth.li/~sgtatham/putty/0.79/htmldoc/Chapter9.h...
The PuTTY agent can service both PuTTY clients and Microsoft OpenSSH clients, and it can do this without a service, nor does it need the implied administrative privileges to launch said service. That is a hands-down win.
The PuTTY clients can also accept raw passwords in several ways, by interactive prompt, by the -pw option on the command line (beware of exposure in task manager), and by the -pwfile option.
The latter above can be adapted to the .netrc format (used by Microsoft curl.exe and ftp.exe), which vastly expands authentication options.
So the question is why anyone bothers with Microsoft's ssh-agent.exe - it's quite limited.
Ditch it.
Unix stuff has only recently been "in the norm" for dev related workflows, it used to be entirely Windows only.
Same with office workflows, games (both playing and developing), graphics, etc.
Unix is the rebel here. It is bringing the diversity.
(Currently my workplace is probably 80% Mac, 19% Linux, 1% Windows, but I can see their point that it would be a lot easier to administrate if they were a monoculture of Mac).
The world is bigger than the desktop.
Already your assessment regarding AIX being dead, when it is one of survivors from UNIX/Linux wars shows how your Microsoft hate blinds your judgement.
If the framers of the Internet had not been faced with disparate systems all speaking different languages and protocols, if they had not been introduced to computing as a babel of vendors all wanting to do their own thing, then perhaps they would not have longed for vendor-neutral, interoperable protocols, such as we have today.
The drive in the 70s to hook up very different computing platforms and have them all talking to one another, that's what gave us the Internet today. Perhaps the choices in OS have diminished since the demise of proprietary systems and bespoke OS for so many platforms, but from where I sit, I still see a wide diversity of devices all connecting to the same Internet, all speaking the same protocol, and I'm thankful for that development.
I once built p0f on windows using msys2. But couldn't get the sockets to work. Without support for linux socket, p0f can not run as server and support queries.
I should definately try this sometimes.
win32: add ssh-agent -w for a windows socket path
-w sets the output format to windows cmd style. Which is useful if you use the mingw openssh but need your agent in a cmd or powershell terminal.
Basically I find that my ssh agent never works unless I set GIT_SSH to the builtin one (at C:\windows\system32\openssh\ssh.exe). Once I do that, everything is happy. If I don't, git over SSH doesn't work right.
And that makes sense. When msysgit calls the Microsoft one explicitly, it uses the Microsoft version of the agent protocol.
Wouldn't the easier way be to expose the smart card to wsl and stick with Linux (wsl) tools on that side?
[0] https://superuser.com/questions/1526348/share-ssh-agent-sock...
Interesting work & I wish him luck. The ability to use hardware SSH certs on Windows has been around for at least a decade now, but it hasn't been a seamless experience.
The other attempt I'm aware of is PuTTY-CAC[0]. It is recommended[1] for security-conscious organizations, and approved for use at places like the US Department of Veteran Affairs[2]. Vendors[3] of smart cards also show some limited support for it.
The issue with PuTTY-CAC is that the server still needs to be configured to check the certificate against CRLs & PKI infrastructure. Over the past decade, I believe Red Hat has made some significant progress towards a workable solution[4], however, I have no experience with it.
[0] https://github.com/NoMoreFood/putty-cac
[1] https://playbooks.idmanagement.gov/piv/engineer/ssh/
[2] https://www.oit.va.gov/Services/TRM/ToolPage.aspx?tid=8714#
[3] https://pivkey.zendesk.com/hc/en-us/articles/207698876-PIVKe...
The first thing I do with a new PC is delete whatever scamware it came with, and install a free operating system on it.
It's his first sentence. What does your (understandable) personal stance, have to do with his work environment??
Or the rest of his first sentence:
there's a lot of specialised hardware design software that's only supported under Windows, so this isn't really avoidable
Your statement feels unhelpful.
Why are you not astonished that, after "30 years of coexistence" people still: feel the need to buy Windows and slap Linux or BSD on it (as opposed to buying one with Linux or BSD out of the box) and are forced to buy Windows to use software and/or hardware required to do work otherwise unrelated to Windows?
Coexistence is a two-way street.
Despite Microsoft's best efforts.
I don't know why Microsoft technology triggers me so much.
I have been a big fan of C#, VSCode, LSP, GitHub Actions.
I'm sure it's an instinctive reaction to their aesthetic.
Microsoft are the Vogons of HHGTTG: https://en.wikipedia.org/wiki/Vogon
Windows is the buffet that comes with your new PC.
You didn't order ads, telemetry and questionable UX?
Don't worry, it's included in the price.
At least Apple and Linux did make a big dent and the billions of Linux devices shall keep powering the real world for a very long time and it seems unlikely Mac users are going to trade their MacOS laptops for Windows turds, so all hope is not lost.
And thankfully, so far, Microsoft phones have all been miserable failures.
I do my part to fight Microsoft: I confiscated my mother-in-law's Windows laptop after she got malwared and fell for a scam and I bought her a Chromebook. My wife is more of a poweruser so I wiped her Windows system and installed her Ubuntu. I made my brothers switch to Mac computer a very long time ago: was tired of supporting their Windows never failing to get slow, catch malware etc. and simply told them: "You buy Mac computers or I'm not helping you anymore".
Microsoft is a mediocre company making the world a shittier place, but they're here to stay.
Malware:
> Microsoft is Slowly Rolling Out Ads in the Windows 11 Start Menu
https://gizmodo.com/microsoft-windows-11-onedrive-notificati...
Somehow, paying for an operating system does not relieve you of advertisement.
I guess they just, you know, fixed the glitch.
you can get native Windows Git as well. its called MinGit:
But from the comments, is this to fix WSL ? If so, people should stay away from that and just use Linux. If the masses start using WSL, that would give hardware vendors the reason to ignore Linux on bare metal, thus no more desktop Linux.
I can remote into a Linux server and use my yubikey as if I were physically plugged into the Linux machine.
"Haha"
[0]: https://stackoverflow.com/questions/23086038/what-mechanism-...