2026-04-06 09:00:47 +00:00
|
|
|
// Phase C Step 9 — Plugin registry, lifecycle, and host-API plumbing.
|
|
|
|
|
//
|
|
|
|
|
// The Registry is the long-lived handle the rest of the server holds onto. It
|
|
|
|
|
// owns the Wazero runtime (in the wazero-tagged build), the loaded plugin
|
|
|
|
|
// instances, and the dispatch tables for host-API capabilities (commands,
|
|
|
|
|
// events, storage, http, ui).
|
|
|
|
|
//
|
|
|
|
|
// In the default build the runtime is a stub: LoadAll walks the plugins
|
|
|
|
|
// directory and persists each manifest into the PluginStore so admins can see
|
|
|
|
|
// what is "installed", but the .wasm files are NOT executed. Calling
|
|
|
|
|
// Dispatch() in the default build returns ErrRuntimeUnavailable.
|
2026-07-18 12:55:22 +02:00
|
|
|
|
2026-04-06 09:00:47 +00:00
|
|
|
package plugin
|
|
|
|
|
|
|
|
|
|
import (
|
2026-04-06 10:30:18 +00:00
|
|
|
"archive/zip"
|
2026-04-06 09:00:47 +00:00
|
|
|
"context"
|
2026-08-14 10:05:40 +02:00
|
|
|
"errors"
|
2026-04-06 09:00:47 +00:00
|
|
|
"fmt"
|
2026-04-06 10:30:18 +00:00
|
|
|
"io"
|
2026-04-06 09:00:47 +00:00
|
|
|
"log/slog"
|
2026-04-06 10:30:18 +00:00
|
|
|
"os"
|
|
|
|
|
"path/filepath"
|
|
|
|
|
"strings"
|
2026-04-06 09:00:47 +00:00
|
|
|
"sync"
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
// Config is the runtime configuration sourced from PluginsConfig.
|
|
|
|
|
type Config struct {
|
|
|
|
|
Directory string
|
|
|
|
|
MaxMemoryMB int
|
|
|
|
|
CPUBudgetMs int
|
|
|
|
|
HTTPAllowlist []string
|
2026-07-19 16:33:58 +00:00
|
|
|
Store PluginStore
|
2026-04-06 09:00:47 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Registry is the central plugin coordinator.
|
|
|
|
|
type Registry struct {
|
|
|
|
|
cfg Config
|
|
|
|
|
|
|
|
|
|
mu sync.RWMutex
|
2026-04-06 09:49:03 +00:00
|
|
|
plugins map[int64]*Instance // by plugin row id
|
|
|
|
|
byName map[string]*Instance // by manifest name
|
|
|
|
|
commands map[string]*Instance // command name → owning plugin
|
|
|
|
|
uiTabs []UITabBinding // declared by `ui` capability plugins
|
2026-04-06 09:00:47 +00:00
|
|
|
|
2026-04-06 22:48:59 +02:00
|
|
|
// sink is the hub→plugin event fan-out. Plugins subscribe to topics via
|
|
|
|
|
// Subscribe; the WS hub calls sink.Dispatch on each broadcast.
|
|
|
|
|
sink *EventSink
|
|
|
|
|
|
2026-04-06 21:46:22 +00:00
|
|
|
// runtimePlatform is populated by platformInit in the wazero-tagged build
|
|
|
|
|
// with a concrete *wazero.Runtime. The default build leaves it nil and
|
|
|
|
|
// falls back to manifest-only behaviour. platformClose tears the runtime
|
|
|
|
|
// down; both fields are set by platformInit atomically.
|
2026-04-06 09:00:47 +00:00
|
|
|
runtimePlatform any
|
2026-04-06 21:46:22 +00:00
|
|
|
platformClose func(context.Context) error
|
2026-04-06 09:00:47 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Instance is a single loaded plugin.
|
|
|
|
|
type Instance struct {
|
|
|
|
|
ID int64
|
|
|
|
|
Manifest *Manifest
|
2026-08-14 10:05:40 +02:00
|
|
|
Dir string // on-disk plugin directory, from foundPlugin.Dir — NOT derived from Manifest.Name
|
2026-04-06 09:00:47 +00:00
|
|
|
WASMPath string
|
|
|
|
|
Enabled bool
|
|
|
|
|
|
2026-07-23 11:59:13 +02:00
|
|
|
// invokeMu serializes guest calls for this instance. wazero's Function.Call
|
|
|
|
|
// is not goroutine-safe, and concurrent invocations race the module's shared
|
|
|
|
|
// linear-memory buffer (F2). Held by the wazero-tagged invokeCommand around
|
|
|
|
|
// the whole allocate/write/dispatch/read sequence.
|
|
|
|
|
invokeMu sync.Mutex //nolint:unused // used only by the wazero-tagged build
|
|
|
|
|
|
2026-04-06 09:00:47 +00:00
|
|
|
// module is the wazero compiled module in the wazero-tagged build, or
|
|
|
|
|
// nil in the default build.
|
2026-04-07 10:10:38 +02:00
|
|
|
module any //nolint:unused // assigned by wazero-tagged build
|
2026-08-07 21:20:48 +02:00
|
|
|
|
|
|
|
|
// compiled is the wazero CompiledModule behind module. Retained so
|
|
|
|
|
// teardown can close it — the shared runtime otherwise keeps every
|
|
|
|
|
// compile from every re-activation cycle until process exit.
|
|
|
|
|
compiled any //nolint:unused // assigned by wazero-tagged build
|
2026-04-06 09:00:47 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// UITabBinding is the public projection of a plugin's declared UI tab,
|
|
|
|
|
// served to the client bridge so it can render iframe tabs.
|
|
|
|
|
type UITabBinding struct {
|
|
|
|
|
PluginID int64
|
|
|
|
|
PluginName string
|
|
|
|
|
Tab UITab
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// NewRegistry constructs a registry. In the default build it is a thin
|
|
|
|
|
// holder; the wazero-tagged build replaces this constructor with one that
|
|
|
|
|
// stands up a real Wazero runtime.
|
|
|
|
|
func NewRegistry(cfg Config) (*Registry, error) {
|
|
|
|
|
if cfg.Store == nil {
|
|
|
|
|
return nil, fmt.Errorf("plugin: NewRegistry requires a non-nil PluginStore")
|
|
|
|
|
}
|
2026-04-06 21:46:22 +00:00
|
|
|
r := &Registry{
|
2026-04-06 09:00:47 +00:00
|
|
|
cfg: cfg,
|
|
|
|
|
plugins: make(map[int64]*Instance),
|
|
|
|
|
byName: make(map[string]*Instance),
|
|
|
|
|
commands: make(map[string]*Instance),
|
2026-04-06 22:48:59 +02:00
|
|
|
sink: NewEventSink(),
|
2026-04-06 21:46:22 +00:00
|
|
|
}
|
|
|
|
|
// platformInit is supplied by sandbox_default.go (no-op) or
|
|
|
|
|
// sandbox_wazero.go (real Wazero runtime). Either way it owns the
|
|
|
|
|
// runtimePlatform + platformClose pair on the Registry.
|
|
|
|
|
platform, closeFn, err := platformInit(cfg)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return nil, fmt.Errorf("plugin: platform init: %w", err)
|
|
|
|
|
}
|
|
|
|
|
r.runtimePlatform = platform
|
|
|
|
|
r.platformClose = closeFn
|
|
|
|
|
return r, nil
|
2026-04-06 09:00:47 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Close shuts the registry down. In the wazero-tagged build it tears the
|
|
|
|
|
// runtime down and frees module memory.
|
|
|
|
|
func (r *Registry) Close(ctx context.Context) error {
|
|
|
|
|
r.mu.Lock()
|
2026-04-06 21:46:22 +00:00
|
|
|
for _, inst := range r.plugins {
|
2026-07-23 17:03:52 +02:00
|
|
|
r.platformDeactivate(ctx, inst)
|
2026-04-06 21:46:22 +00:00
|
|
|
}
|
2026-04-06 09:00:47 +00:00
|
|
|
for id := range r.plugins {
|
|
|
|
|
delete(r.plugins, id)
|
|
|
|
|
}
|
|
|
|
|
for n := range r.byName {
|
|
|
|
|
delete(r.byName, n)
|
|
|
|
|
}
|
|
|
|
|
for c := range r.commands {
|
|
|
|
|
delete(r.commands, c)
|
|
|
|
|
}
|
|
|
|
|
r.uiTabs = nil
|
2026-04-06 21:46:22 +00:00
|
|
|
closeFn := r.platformClose
|
|
|
|
|
r.platformClose = nil
|
|
|
|
|
r.runtimePlatform = nil
|
|
|
|
|
r.mu.Unlock()
|
|
|
|
|
if closeFn != nil {
|
|
|
|
|
return closeFn(ctx)
|
|
|
|
|
}
|
2026-04-06 09:00:47 +00:00
|
|
|
return nil
|
|
|
|
|
}
|
|
|
|
|
|
2026-04-06 22:48:59 +02:00
|
|
|
// Sink returns the registry's EventSink, used by the WS hub to fan out
|
|
|
|
|
// broadcast events to subscribed plugins and by the wazero build to deliver
|
|
|
|
|
// plugin output back to WS clients.
|
|
|
|
|
func (r *Registry) Sink() *EventSink {
|
|
|
|
|
return r.sink
|
|
|
|
|
}
|
|
|
|
|
|
2026-04-06 09:00:47 +00:00
|
|
|
// LoadAll scans cfg.Directory and persists every plugin.json found into the
|
|
|
|
|
// PluginStore. In the wazero-tagged build it then compiles each entrypoint
|
|
|
|
|
// into a runnable module; the default build stops at the persistence step.
|
|
|
|
|
func (r *Registry) LoadAll(ctx context.Context) error {
|
|
|
|
|
if r == nil {
|
|
|
|
|
return nil
|
|
|
|
|
}
|
2026-04-07 05:28:53 +00:00
|
|
|
// Clean up any staging directories left over from a previous crash
|
|
|
|
|
// during InstallFromZip. These are named ".install-XXXXXX" and are
|
|
|
|
|
// safe to remove because a successful install always renames them away.
|
|
|
|
|
if entries, rdErr := os.ReadDir(r.cfg.Directory); rdErr == nil {
|
|
|
|
|
for _, e := range entries {
|
|
|
|
|
if e.IsDir() && strings.HasPrefix(e.Name(), ".install-") {
|
|
|
|
|
staleDir := filepath.Join(r.cfg.Directory, e.Name())
|
|
|
|
|
if rmErr := os.RemoveAll(staleDir); rmErr != nil {
|
|
|
|
|
slog.Warn("plugin: failed to remove stale staging dir", "dir", staleDir, "err", rmErr)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
2026-04-06 09:00:47 +00:00
|
|
|
manifests, err := scanPluginDirectory(r.cfg.Directory)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return fmt.Errorf("plugin: scan %q: %w", r.cfg.Directory, err)
|
|
|
|
|
}
|
|
|
|
|
for _, found := range manifests {
|
|
|
|
|
if err := r.installFromDisk(ctx, found); err != nil {
|
|
|
|
|
slog.Warn("plugin: failed to install from disk", "name", found.Manifest.Name, "err", err)
|
|
|
|
|
continue
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
return r.activateAll(ctx)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// installFromDisk persists a manifest discovered on disk into the PluginStore
|
|
|
|
|
// and registers it in the in-memory registry.
|
|
|
|
|
func (r *Registry) installFromDisk(ctx context.Context, found foundPlugin) error {
|
|
|
|
|
manifestJSON, err := found.Manifest.serialize()
|
|
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
id, err := r.cfg.Store.InstallPlugin(ctx, found.Manifest.Name, found.Manifest.Version, manifestJSON)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return fmt.Errorf("InstallPlugin: %w", err)
|
|
|
|
|
}
|
|
|
|
|
r.mu.Lock()
|
|
|
|
|
defer r.mu.Unlock()
|
2026-07-19 08:52:31 +02:00
|
|
|
// Re-install: tear down the old instance and drop its command bindings.
|
|
|
|
|
// Bindings are keyed to the old *Instance, so leaving them in place both
|
|
|
|
|
// blocked the fresh instance from re-registering its own commands and
|
|
|
|
|
// kept dispatch routing into the orphaned old module until restart.
|
|
|
|
|
if old := r.byName[found.Manifest.Name]; old != nil {
|
2026-07-23 17:03:52 +02:00
|
|
|
r.platformDeactivate(ctx, old)
|
2026-07-19 08:52:31 +02:00
|
|
|
for cmd, owner := range r.commands {
|
|
|
|
|
if owner == old {
|
|
|
|
|
delete(r.commands, cmd)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
if old.ID != id {
|
|
|
|
|
delete(r.plugins, old.ID)
|
|
|
|
|
}
|
|
|
|
|
}
|
2026-04-06 09:00:47 +00:00
|
|
|
inst := &Instance{
|
|
|
|
|
ID: id,
|
|
|
|
|
Manifest: found.Manifest,
|
2026-08-14 10:05:40 +02:00
|
|
|
Dir: found.Dir,
|
2026-04-06 09:00:47 +00:00
|
|
|
WASMPath: found.WASMPath,
|
|
|
|
|
Enabled: false,
|
|
|
|
|
}
|
|
|
|
|
r.plugins[id] = inst
|
|
|
|
|
r.byName[found.Manifest.Name] = inst
|
|
|
|
|
return nil
|
|
|
|
|
}
|
|
|
|
|
|
2026-04-06 10:30:18 +00:00
|
|
|
// InstallFromZip extracts a plugin .zip uploaded via the admin API into a
|
|
|
|
|
// temp directory, validates it (zip-slip safe, no symlinks, size-capped),
|
|
|
|
|
// then renames it into the plugin directory and registers it via
|
|
|
|
|
// installFromDisk. Returns the new plugin name on success.
|
|
|
|
|
//
|
|
|
|
|
// The zip must contain a top-level plugin.json. The plugin's directory name
|
|
|
|
|
// is taken from manifest.Name (validated by Manifest.Validate to a strict
|
|
|
|
|
// charset). Re-installing an existing plugin replaces it.
|
|
|
|
|
const (
|
|
|
|
|
maxZipBytes = 16 * 1024 * 1024 // 16 MiB compressed
|
|
|
|
|
maxUncompressedSum = 64 * 1024 * 1024 // 64 MiB total uncompressed
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
func (r *Registry) InstallFromZip(ctx context.Context, zipBytes []byte) (string, error) {
|
|
|
|
|
if r == nil || r.cfg.Directory == "" {
|
|
|
|
|
return "", fmt.Errorf("plugin runtime not configured")
|
|
|
|
|
}
|
|
|
|
|
if int64(len(zipBytes)) > maxZipBytes {
|
|
|
|
|
return "", fmt.Errorf("plugin zip exceeds %d bytes", maxZipBytes)
|
|
|
|
|
}
|
|
|
|
|
zr, err := zip.NewReader(bytesReaderAt(zipBytes), int64(len(zipBytes)))
|
|
|
|
|
if err != nil {
|
|
|
|
|
return "", fmt.Errorf("invalid zip: %w", err)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Stage 1: extract into a temp dir under the plugin directory.
|
|
|
|
|
if err := os.MkdirAll(r.cfg.Directory, 0o750); err != nil {
|
|
|
|
|
return "", fmt.Errorf("create plugin dir: %w", err)
|
|
|
|
|
}
|
|
|
|
|
stage, err := os.MkdirTemp(r.cfg.Directory, ".install-")
|
|
|
|
|
if err != nil {
|
|
|
|
|
return "", fmt.Errorf("create staging dir: %w", err)
|
|
|
|
|
}
|
|
|
|
|
cleanup := func() { _ = os.RemoveAll(stage) }
|
|
|
|
|
|
|
|
|
|
stageAbs, absErr := filepath.Abs(stage)
|
|
|
|
|
if absErr != nil {
|
|
|
|
|
cleanup()
|
|
|
|
|
return "", fmt.Errorf("abs staging dir: %w", absErr)
|
|
|
|
|
}
|
|
|
|
|
|
2026-08-18 20:39:45 +02:00
|
|
|
if err := installZipExtract(zr, stageAbs); err != nil {
|
|
|
|
|
cleanup()
|
|
|
|
|
return "", err
|
2026-04-06 10:30:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Stage 2: parse the manifest now that the staging dir is fully populated.
|
2026-08-18 20:39:45 +02:00
|
|
|
manifest, err := installZipStagedManifest(stageAbs)
|
2026-04-06 10:30:18 +00:00
|
|
|
if err != nil {
|
|
|
|
|
cleanup()
|
|
|
|
|
return "", err
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Stage 3: atomically rename into the canonical plugin name directory.
|
|
|
|
|
finalDir := filepath.Join(r.cfg.Directory, manifest.Name)
|
2026-08-18 20:39:45 +02:00
|
|
|
if err := installZipPromote(stageAbs, finalDir); err != nil {
|
2026-04-06 10:30:18 +00:00
|
|
|
cleanup()
|
2026-08-18 20:39:45 +02:00
|
|
|
return "", err
|
2026-04-06 10:30:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Stage 4: register via the existing on-disk install path.
|
|
|
|
|
if err := r.installFromDisk(ctx, foundPlugin{
|
|
|
|
|
Manifest: manifest,
|
|
|
|
|
Dir: finalDir,
|
|
|
|
|
WASMPath: filepath.Join(finalDir, manifest.Entrypoint),
|
|
|
|
|
}); err != nil {
|
|
|
|
|
return manifest.Name, fmt.Errorf("installFromDisk: %w", err)
|
|
|
|
|
}
|
2026-08-14 10:05:40 +02:00
|
|
|
|
2026-08-18 20:39:45 +02:00
|
|
|
r.installZipReactivate(ctx, manifest.Name)
|
|
|
|
|
return manifest.Name, nil
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// installZipExtract writes every entry of zr into the already-created staging
|
|
|
|
|
// directory stageAbs, enforcing the zip-slip, symlink and uncompressed-size
|
|
|
|
|
// caps entry by entry before each write. The caller owns stageAbs and removes
|
|
|
|
|
// it on any error returned here.
|
|
|
|
|
func installZipExtract(zr *zip.Reader, stageAbs string) error {
|
|
|
|
|
var totalUncompressed int64
|
|
|
|
|
for _, f := range zr.File {
|
|
|
|
|
destAbs, entryErr := installZipEntryDest(f, stageAbs)
|
|
|
|
|
if entryErr != nil {
|
|
|
|
|
return entryErr
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if f.Mode().IsDir() {
|
|
|
|
|
if err := os.MkdirAll(destAbs, 0o750); err != nil {
|
|
|
|
|
return err
|
2026-08-14 10:05:40 +02:00
|
|
|
}
|
2026-08-18 20:39:45 +02:00
|
|
|
continue
|
|
|
|
|
}
|
|
|
|
|
if err := os.MkdirAll(filepath.Dir(destAbs), 0o750); err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
// Cap each file at the remaining uncompressed budget so a zip bomb
|
|
|
|
|
// can't OOM the host.
|
|
|
|
|
remaining := maxUncompressedSum - totalUncompressed
|
|
|
|
|
n, writeErr := installZipWriteEntry(f, destAbs, remaining)
|
|
|
|
|
if writeErr != nil {
|
|
|
|
|
return writeErr
|
|
|
|
|
}
|
|
|
|
|
totalUncompressed += n
|
|
|
|
|
}
|
|
|
|
|
return nil
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// installZipEntryDest validates one zip entry's mode and name and returns the
|
|
|
|
|
// absolute path it may be written to under stageAbs. Every rejection here is a
|
|
|
|
|
// hard stop: non-regular modes, symlinks, and any name that escapes stageAbs.
|
|
|
|
|
func installZipEntryDest(f *zip.File, stageAbs string) (string, error) {
|
|
|
|
|
// Reject symlinks, devices, and any non-regular file mode.
|
|
|
|
|
if !f.Mode().IsRegular() && !f.Mode().IsDir() {
|
|
|
|
|
return "", fmt.Errorf("plugin zip: refusing non-regular entry %q (mode=%v)", f.Name, f.Mode())
|
|
|
|
|
}
|
|
|
|
|
if f.Mode()&os.ModeSymlink != 0 {
|
|
|
|
|
return "", fmt.Errorf("plugin zip: refusing symlink %q", f.Name)
|
|
|
|
|
}
|
|
|
|
|
// Reject zip-slip: cleaned absolute path must stay rooted at the
|
|
|
|
|
// staging directory.
|
|
|
|
|
clean := filepath.Clean(f.Name)
|
|
|
|
|
if strings.HasPrefix(clean, "..") || filepath.IsAbs(clean) || strings.Contains(clean, "..\\") {
|
|
|
|
|
return "", fmt.Errorf("plugin zip: refusing path-traversal entry %q", f.Name)
|
|
|
|
|
}
|
|
|
|
|
dest := filepath.Join(stageAbs, clean)
|
|
|
|
|
destAbs, dErr := filepath.Abs(dest)
|
|
|
|
|
if dErr != nil {
|
|
|
|
|
return "", dErr
|
|
|
|
|
}
|
|
|
|
|
rel, relErr := filepath.Rel(stageAbs, destAbs)
|
|
|
|
|
if relErr != nil || strings.HasPrefix(rel, "..") || filepath.IsAbs(rel) {
|
|
|
|
|
return "", fmt.Errorf("plugin zip: refusing escape %q", f.Name)
|
|
|
|
|
}
|
|
|
|
|
return destAbs, nil
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// installZipWriteEntry copies one regular entry to destAbs, refusing to write
|
|
|
|
|
// more than remaining bytes — this entry's share of the maxUncompressedSum
|
|
|
|
|
// budget — and returns how many bytes it wrote.
|
|
|
|
|
func installZipWriteEntry(f *zip.File, destAbs string, remaining int64) (int64, error) {
|
|
|
|
|
rc, oErr := f.Open()
|
|
|
|
|
if oErr != nil {
|
|
|
|
|
return 0, oErr
|
|
|
|
|
}
|
|
|
|
|
out, cErr := os.OpenFile(destAbs, os.O_WRONLY|os.O_CREATE|os.O_TRUNC, 0o600)
|
|
|
|
|
if cErr != nil {
|
|
|
|
|
_ = rc.Close()
|
|
|
|
|
return 0, cErr
|
|
|
|
|
}
|
|
|
|
|
if remaining <= 0 {
|
|
|
|
|
_ = rc.Close()
|
|
|
|
|
_ = out.Close()
|
|
|
|
|
return 0, fmt.Errorf("plugin zip: uncompressed total exceeds %d bytes", maxUncompressedSum)
|
|
|
|
|
}
|
|
|
|
|
n, copyErr := io.CopyN(out, rc, remaining+1)
|
|
|
|
|
_ = rc.Close()
|
|
|
|
|
_ = out.Close()
|
|
|
|
|
if copyErr != nil && copyErr != io.EOF {
|
|
|
|
|
return 0, copyErr
|
|
|
|
|
}
|
|
|
|
|
if n > remaining {
|
|
|
|
|
return 0, fmt.Errorf("plugin zip: uncompressed total exceeds %d bytes", maxUncompressedSum)
|
|
|
|
|
}
|
|
|
|
|
return n, nil
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// installZipStagedManifest parses the staged plugin.json and holds the staged
|
|
|
|
|
// tree to the same rules scanPluginDirectory applies to an on-disk plugin (no
|
|
|
|
|
// symlinks anywhere, entrypoint present and not a symlink).
|
|
|
|
|
func installZipStagedManifest(stageAbs string) (*Manifest, error) {
|
|
|
|
|
manifestPath := filepath.Join(stageAbs, "plugin.json")
|
|
|
|
|
raw, err := os.ReadFile(manifestPath)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return nil, fmt.Errorf("plugin zip: missing plugin.json at root: %w", err)
|
|
|
|
|
}
|
|
|
|
|
manifest, err := ParseManifest(raw)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return nil, err
|
|
|
|
|
}
|
|
|
|
|
// Validate the staged contents the same way scanPluginDirectory does.
|
|
|
|
|
if err := rejectSymlinksUnder(stageAbs); err != nil {
|
|
|
|
|
return nil, err
|
|
|
|
|
}
|
|
|
|
|
wasmPath := filepath.Join(stageAbs, manifest.Entrypoint)
|
|
|
|
|
if info, statErr := os.Lstat(wasmPath); statErr != nil {
|
|
|
|
|
return nil, fmt.Errorf("entrypoint %s missing: %w", manifest.Entrypoint, statErr)
|
|
|
|
|
} else if info.Mode()&os.ModeSymlink != 0 {
|
|
|
|
|
return nil, fmt.Errorf("entrypoint %s is a symlink", manifest.Entrypoint)
|
|
|
|
|
}
|
|
|
|
|
return manifest, nil
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// installZipPromote moves the fully validated staging directory into its
|
|
|
|
|
// canonical plugin-name directory.
|
|
|
|
|
func installZipPromote(stageAbs, finalDir string) error {
|
|
|
|
|
// If a previous version exists, remove it. The store row is replaced by
|
|
|
|
|
// installFromDisk via the existing UPSERT path.
|
|
|
|
|
if _, err := os.Stat(finalDir); err == nil {
|
|
|
|
|
if err := os.RemoveAll(finalDir); err != nil {
|
|
|
|
|
return fmt.Errorf("remove existing plugin dir: %w", err)
|
2026-08-14 10:05:40 +02:00
|
|
|
}
|
|
|
|
|
}
|
2026-08-18 20:39:45 +02:00
|
|
|
if err := os.Rename(stageAbs, finalDir); err != nil {
|
|
|
|
|
return fmt.Errorf("install rename: %w", err)
|
|
|
|
|
}
|
|
|
|
|
return nil
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// installZipReactivate restores the enabled state of a plugin that was already
|
|
|
|
|
// enabled before this upgrade.
|
|
|
|
|
//
|
|
|
|
|
// installFromDisk always registers the fresh instance as disabled and
|
|
|
|
|
// InstallPlugin's upsert never touches the `enabled` column, so a plugin
|
|
|
|
|
// that was enabled before this upgrade would otherwise come out the
|
|
|
|
|
// other side with the store row still saying enabled while the runtime
|
|
|
|
|
// instance sits inactive. LoadAll's startup path avoids this because it
|
|
|
|
|
// always runs activateAll afterward; this is the one caller of
|
|
|
|
|
// installFromDisk that doesn't, so it has to reactivate for itself.
|
|
|
|
|
// EnablePlugin already rolls the DB flag back if activation fails, so
|
|
|
|
|
// the two can no longer disagree.
|
|
|
|
|
func (r *Registry) installZipReactivate(ctx context.Context, name string) {
|
|
|
|
|
row, rowErr := r.cfg.Store.GetPluginByName(ctx, name)
|
|
|
|
|
if rowErr != nil || row == nil || !row.Enabled {
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
err := r.EnablePlugin(ctx, row.ID)
|
|
|
|
|
if err == nil {
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
if !errors.Is(err, ErrRuntimeUnavailable) {
|
|
|
|
|
slog.Warn("plugin: reactivate after upgrade failed", "name", name, "err", err)
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
// Default (non-wazero) build: nothing can activate here, and
|
|
|
|
|
// leaving EnablePlugin's rollback in place would persistently
|
|
|
|
|
// disable a plugin the admin left enabled — after a rebuild
|
|
|
|
|
// with -tags wazero it would silently stay off. Preserve the
|
|
|
|
|
// enabled intent instead; the next wazero-tagged start's
|
|
|
|
|
// activateAll does the real activation.
|
|
|
|
|
if reErr := r.cfg.Store.EnablePlugin(ctx, row.ID); reErr != nil {
|
|
|
|
|
slog.Warn("plugin: could not preserve enabled flag across runtime-less upgrade",
|
|
|
|
|
"name", name, "err", reErr)
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
r.mu.Lock()
|
|
|
|
|
if inst, ok := r.byName[name]; ok {
|
|
|
|
|
inst.Enabled = true
|
|
|
|
|
}
|
|
|
|
|
r.mu.Unlock()
|
|
|
|
|
slog.Info("plugin: runtime unavailable, enabled flag preserved across upgrade",
|
|
|
|
|
"name", name)
|
2026-04-06 10:30:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// bytesReaderAt is a tiny wrapper that satisfies io.ReaderAt for a byte
|
|
|
|
|
// slice. archive/zip needs ReaderAt; bytes.Reader provides it but importing
|
|
|
|
|
// "bytes" alongside the existing "io" surface keeps the import block tight.
|
|
|
|
|
type bytesReaderAt []byte
|
|
|
|
|
|
|
|
|
|
func (b bytesReaderAt) ReadAt(p []byte, off int64) (int, error) {
|
|
|
|
|
if off < 0 || off >= int64(len(b)) {
|
|
|
|
|
return 0, io.EOF
|
|
|
|
|
}
|
|
|
|
|
n := copy(p, b[off:])
|
|
|
|
|
if n < len(p) {
|
|
|
|
|
return n, io.EOF
|
|
|
|
|
}
|
|
|
|
|
return n, nil
|
|
|
|
|
}
|
|
|
|
|
|
2026-04-06 09:00:47 +00:00
|
|
|
// activateAll attempts to compile + register host-API hooks for every plugin
|
|
|
|
|
// row in the PluginStore that is marked enabled. The default build is a
|
|
|
|
|
// no-op (no Wazero modules to compile).
|
|
|
|
|
func (r *Registry) activateAll(ctx context.Context) error {
|
|
|
|
|
rows, err := r.cfg.Store.ListPlugins(ctx)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return fmt.Errorf("ListPlugins: %w", err)
|
|
|
|
|
}
|
|
|
|
|
for _, row := range rows {
|
|
|
|
|
if !row.Enabled {
|
|
|
|
|
continue
|
|
|
|
|
}
|
|
|
|
|
r.mu.Lock()
|
|
|
|
|
inst, ok := r.byName[row.Name]
|
|
|
|
|
r.mu.Unlock()
|
|
|
|
|
if !ok {
|
|
|
|
|
slog.Warn("plugin: enabled row has no on-disk manifest, skipping", "name", row.Name)
|
|
|
|
|
continue
|
|
|
|
|
}
|
|
|
|
|
if err := r.activate(ctx, inst); err != nil {
|
|
|
|
|
slog.Warn("plugin: activation failed", "name", row.Name, "err", err)
|
2026-04-06 09:49:03 +00:00
|
|
|
continue
|
2026-04-06 09:00:47 +00:00
|
|
|
}
|
2026-04-06 09:49:03 +00:00
|
|
|
// Sync the in-memory enabled flag with the DB row so callers that
|
|
|
|
|
// read inst.Enabled (e.g. /api/v1/admin/plugins listings, future
|
|
|
|
|
// host-side capability checks) see the activated state.
|
|
|
|
|
r.mu.Lock()
|
|
|
|
|
inst.Enabled = true
|
|
|
|
|
r.mu.Unlock()
|
2026-04-06 09:00:47 +00:00
|
|
|
}
|
|
|
|
|
return nil
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// activate compiles and starts a single plugin module. Default build returns
|
|
|
|
|
// ErrRuntimeUnavailable; the wazero-tagged build replaces this with the real
|
2026-04-06 21:46:22 +00:00
|
|
|
// implementation via activateWithRuntime.
|
|
|
|
|
//
|
|
|
|
|
// The runtimePlatform read is guarded by r.mu so a concurrent Close() that
|
|
|
|
|
// nil-s the field cannot be observed mid-activation. The captured platform
|
|
|
|
|
// value is then passed into activateWithRuntime as a parameter so the actual
|
|
|
|
|
// compile uses the snapshot rather than re-reading r.runtimePlatform — this
|
|
|
|
|
// closes the race window between the nil check and the wazero call.
|
2026-04-06 09:00:47 +00:00
|
|
|
func (r *Registry) activate(ctx context.Context, inst *Instance) error {
|
2026-04-06 21:46:22 +00:00
|
|
|
r.mu.RLock()
|
|
|
|
|
platform := r.runtimePlatform
|
|
|
|
|
r.mu.RUnlock()
|
|
|
|
|
if platform == nil {
|
2026-04-06 09:00:47 +00:00
|
|
|
return ErrRuntimeUnavailable
|
|
|
|
|
}
|
2026-04-06 21:46:22 +00:00
|
|
|
return r.activateWithRuntime(ctx, platform, inst)
|
2026-04-06 09:00:47 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// EnablePlugin marks a plugin enabled in the store, then attempts to load it.
|
|
|
|
|
func (r *Registry) EnablePlugin(ctx context.Context, id int64) error {
|
|
|
|
|
if err := r.cfg.Store.EnablePlugin(ctx, id); err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
r.mu.RLock()
|
|
|
|
|
inst, ok := r.plugins[id]
|
|
|
|
|
r.mu.RUnlock()
|
|
|
|
|
if !ok {
|
2026-08-14 10:05:40 +02:00
|
|
|
// No in-memory instance to activate — roll the DB flag back so it
|
|
|
|
|
// doesn't stay stuck at enabled=1 with nothing backing it, the same
|
|
|
|
|
// way the activation-failure path below rolls back.
|
|
|
|
|
_ = r.cfg.Store.DisablePlugin(ctx, id)
|
2026-04-06 09:00:47 +00:00
|
|
|
return ErrPluginNotFound
|
|
|
|
|
}
|
2026-04-07 05:28:53 +00:00
|
|
|
r.mu.Lock()
|
2026-04-06 09:00:47 +00:00
|
|
|
inst.Enabled = true
|
2026-04-07 05:28:53 +00:00
|
|
|
r.mu.Unlock()
|
2026-04-06 09:00:47 +00:00
|
|
|
if err := r.activate(ctx, inst); err != nil {
|
2026-04-07 05:28:53 +00:00
|
|
|
// Roll back the DB flag and the in-memory flag so the next start
|
|
|
|
|
// attempt is consistent.
|
2026-04-06 09:00:47 +00:00
|
|
|
_ = r.cfg.Store.DisablePlugin(ctx, id)
|
2026-04-07 05:28:53 +00:00
|
|
|
r.mu.Lock()
|
2026-04-06 09:00:47 +00:00
|
|
|
inst.Enabled = false
|
2026-04-07 05:28:53 +00:00
|
|
|
r.mu.Unlock()
|
2026-04-06 09:00:47 +00:00
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
return nil
|
|
|
|
|
}
|
|
|
|
|
|
2026-04-06 21:46:22 +00:00
|
|
|
// DisablePlugin marks a plugin disabled and tears its module down. The
|
|
|
|
|
// wazero-tagged build frees the compiled module via platformDeactivate so
|
|
|
|
|
// re-enabling recompiles from disk; the default build is a no-op.
|
2026-04-06 09:00:47 +00:00
|
|
|
func (r *Registry) DisablePlugin(ctx context.Context, id int64) error {
|
|
|
|
|
if err := r.cfg.Store.DisablePlugin(ctx, id); err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
r.mu.Lock()
|
|
|
|
|
defer r.mu.Unlock()
|
|
|
|
|
if inst, ok := r.plugins[id]; ok {
|
|
|
|
|
inst.Enabled = false
|
|
|
|
|
// Drop command bindings owned by this plugin.
|
|
|
|
|
for cmd, owner := range r.commands {
|
|
|
|
|
if owner == inst {
|
|
|
|
|
delete(r.commands, cmd)
|
|
|
|
|
}
|
|
|
|
|
}
|
2026-04-06 21:46:22 +00:00
|
|
|
// Free the wazero module so memory is returned to the runtime
|
|
|
|
|
// immediately rather than waiting for registry Close. Safe to call
|
|
|
|
|
// on an instance that was never activated.
|
2026-07-23 17:03:52 +02:00
|
|
|
r.platformDeactivate(ctx, inst)
|
2026-04-06 09:00:47 +00:00
|
|
|
}
|
|
|
|
|
return nil
|
|
|
|
|
}
|
|
|
|
|
|
2026-08-14 10:05:40 +02:00
|
|
|
// removeAll is os.RemoveAll indirected so tests can force a directory-removal
|
|
|
|
|
// failure deterministically. Windows silently succeeds at deleting read-only
|
|
|
|
|
// files (there's no portable, privilege-free way to make a real RemoveAll
|
|
|
|
|
// fail from a test), so this is the seam that lets the error-return path in
|
|
|
|
|
// UninstallPlugin be pinned.
|
|
|
|
|
var removeAll = os.RemoveAll
|
|
|
|
|
|
2026-04-06 09:00:47 +00:00
|
|
|
// UninstallPlugin removes a plugin entirely.
|
|
|
|
|
func (r *Registry) UninstallPlugin(ctx context.Context, id int64) error {
|
2026-04-07 05:28:53 +00:00
|
|
|
if err := r.DisablePlugin(ctx, id); err != nil {
|
|
|
|
|
slog.Warn("plugin: disable failed during uninstall", "id", id, "err", err)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Capture the plugin's on-disk directory before removing the in-memory
|
|
|
|
|
// record so we can clean it up after the DB row is gone.
|
|
|
|
|
r.mu.RLock()
|
|
|
|
|
inst, instOK := r.plugins[id]
|
|
|
|
|
var pluginDir string
|
|
|
|
|
if instOK {
|
2026-08-14 10:05:40 +02:00
|
|
|
pluginDir = inst.Dir
|
2026-04-07 05:28:53 +00:00
|
|
|
}
|
|
|
|
|
r.mu.RUnlock()
|
|
|
|
|
|
2026-04-06 09:00:47 +00:00
|
|
|
if err := r.cfg.Store.UninstallPlugin(ctx, id); err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
2026-04-07 05:28:53 +00:00
|
|
|
|
2026-04-06 09:00:47 +00:00
|
|
|
r.mu.Lock()
|
|
|
|
|
if inst, ok := r.plugins[id]; ok {
|
|
|
|
|
delete(r.byName, inst.Manifest.Name)
|
|
|
|
|
}
|
|
|
|
|
delete(r.plugins, id)
|
2026-04-07 05:28:53 +00:00
|
|
|
r.mu.Unlock()
|
|
|
|
|
|
|
|
|
|
// Remove on-disk files so the plugin isn't resurrected on the next
|
2026-08-14 10:05:40 +02:00
|
|
|
// startup by scanPluginDirectory. The DB row and in-memory record are
|
|
|
|
|
// already gone at this point, so a removal failure is reported rather
|
|
|
|
|
// than swallowed — the caller needs to know the directory still has to
|
|
|
|
|
// be cleaned up by hand before the next restart, or scanPluginDirectory
|
|
|
|
|
// will bring the "uninstalled" plugin right back.
|
2026-04-07 05:28:53 +00:00
|
|
|
if pluginDir != "" {
|
2026-08-14 10:05:40 +02:00
|
|
|
if err := removeAll(pluginDir); err != nil {
|
2026-04-07 05:28:53 +00:00
|
|
|
slog.Warn("plugin: failed to remove plugin directory after uninstall", "dir", pluginDir, "err", err)
|
2026-08-14 10:05:40 +02:00
|
|
|
return fmt.Errorf("remove plugin dir: %w", err)
|
2026-04-07 05:28:53 +00:00
|
|
|
}
|
|
|
|
|
}
|
2026-04-06 09:00:47 +00:00
|
|
|
return nil
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// List returns the currently registered plugins. Read-only snapshot.
|
|
|
|
|
func (r *Registry) List() []*Instance {
|
|
|
|
|
r.mu.RLock()
|
|
|
|
|
defer r.mu.RUnlock()
|
|
|
|
|
out := make([]*Instance, 0, len(r.plugins))
|
|
|
|
|
for _, p := range r.plugins {
|
|
|
|
|
out = append(out, p)
|
|
|
|
|
}
|
|
|
|
|
return out
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// UITabBindings returns the declared UI tabs across enabled plugins.
|
|
|
|
|
func (r *Registry) UITabBindings() []UITabBinding {
|
|
|
|
|
r.mu.RLock()
|
|
|
|
|
defer r.mu.RUnlock()
|
|
|
|
|
out := make([]UITabBinding, len(r.uiTabs))
|
|
|
|
|
copy(out, r.uiTabs)
|
|
|
|
|
return out
|
|
|
|
|
}
|