Files
OwnCord/Server/plugin/registry.go
T
J3vbandClaude Opus 5 39551de4a6 refactor(server): work off the complexity backlog — 62 findings to 0 (#1389)
* refactor(ws): split handleVoiceJoin into cohesive join-stage helpers

handleVoiceJoin was 130 statements / cyclomatic 59 / nestif 11, breaking all
three complexity budgets at once. Split along the stage boundaries the doc
comment already described: precheck, leave-current, persist, restore
moderator flags, grant token, complete. The publish-permission derivation
becomes its own helper because it is the one branch-heavy block inside the
token grant.

Pure move: every statement is preserved verbatim. The only edits are bare
`return`s becoming the typed returns of their new helper, `c.userID` becoming
the `userID` parameter inside voiceJoinPublishPerms, and voiceJoinComplete
re-reading `ch.VoiceMaxUsers` instead of receiving it — `ch` is never mutated,
so the value is identical.

Verified by normalising both revisions of the region to sorted, comment- and
whitespace-stripped statements and diffing: the only deltas are the ones
listed above.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor: collapse the three duplicated sibling pairs

dupl flagged three pairs of adjacent near-identical functions. Each pair is
now one parameterised implementation plus two thin, still-greppable wrappers.

- ws/voice_controls.go: handleVoiceMuteV2 / handleVoiceDeafenV2 share
  voiceSelfToggleV2; handleVoiceCameraV2 / handleVoiceScreenshareV2 share
  voiceStreamToggleV2. Camera and screenshare drawing from one
  voice_max_video budget (OC-0023) was a bug caused by exactly this
  duplication drifting, so one body is the point, not a side effect.
- db/mention_queries.go: ListMentionTargetsByRoles / ListMentionTargetsByUserIDs
  share listMentionTargets. The matched column is a closed named type
  (mentionTargetColumn) rather than a bare string, so the value interpolated
  into the SELECT cannot become caller-supplied.

Behaviour is unchanged: every rate-limit key, error code, error string, slog
message and slog key is preserved verbatim, including the two "failed to
update <kind> state" messages, which are now assembled the same way
enableVideoSlot already assembled them.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor(api): extract readEmojiUpload from handleCreateEmoji

handleCreateEmoji was 101 lines against a 100-line budget. The upload-bytes
stage — pull the file out of the parsed form, cap its size, sniff its MIME
type and sniff its dimensions — is the one self-contained block in it, and it
already wrote its own refusals, so it moves out whole as readEmojiUpload.

The permission-before-parse ordering the doc comment calls out is unchanged;
so is every error string. file.Close() now runs when the helper returns
rather than when the handler does, which is strictly earlier and unobservable:
the bytes are already copied into raw and nothing else touches the handle.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor: extract one cohesive block from three single-budget offenders

Each of these was over exactly one budget, so each gets exactly one extraction
rather than a restructure:

- api/totp_handler.go handleVerifyTOTP (102 lines / 100): the block that
  resolves the user behind the partial-auth challenge and decrypts their TOTP
  secret becomes totpChallengeSecret. The ban-inside-the-partial-window check
  moves with it.
- service/message_reactions.go handleReaction (cyclop 21 / 20): the whole
  authorisation chain — channel lookup, archived gate, DM participant and
  block checks, non-DM permission check — becomes reactionAudience, which
  also returns the DM fan-out audience it already resolved. Check order is
  unchanged and load-bearing.
- db/admin_queries.go BackupToSafe (cyclop 21 / 20): the character allowlist
  loop and the SQL-comment rejection become validateBackupPathChars. That
  loop alone was most of the branch count.

No error string, no check and no ordering changed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor(plugin): split InstallFromZip into staged install helpers

104 statements / cyclomatic 44 / nestif 12. Split along the stages the code
already had: installZipExtract (the per-entry write loop, with
installZipEntryDest holding the mode/symlink/zip-slip guard chain and
installZipWriteEntry the size-capped copy), installZipStagedManifest,
installZipPromote, and installZipReactivate for the :399 nested block.

Every zip-slip, symlink, entry-mode and uncompressed-size check is preserved
in the same order relative to the writes it guards. The 19 inline
`cleanup(); return` sites collapse to 4 in the orchestrator, one per stage,
because each helper now returns an error instead of unwinding itself — the
staging directory is still removed on exactly the same set of failures.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor(api): split newWAFMiddleware into engine build and per-phase helpers

184 lines / cyclomatic 38, and the request-body block at :382 was the worst
nested site in the tree at nestif 17.

Engine construction moves out of the closure (wafInlineEngine, wafCRSEngine —
the Coraza directive string is lifted verbatim), and each request phase
becomes its own helper: wafInlineRequestHeaders, wafCRSRequestHeaders
(including the Host/Transfer-Encoding re-add for CRS 920280), wafFeedCRSBody
and wafInspectRequestBody, which is the old :382 block.

The three `handleWAFInterruption(w, it); return` sites inside the body block
become one: the helper now returns the interruption and the orchestrator
handles it. No statement runs between the two points on either side, so the
verdict is honoured identically — in particular a CRS body interruption still
returns without replacing r.Body.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor(service): split SendMessage and lift EditMessage's access check

SendMessage was 79 statements / cyclomatic 35 with an 11-deep nested
attachment block at :101; EditMessage was one point over cyclop.

SendMessage becomes sendMessagePrecheck (permission and DM-block gates,
content sanitisation), sendMessageLinkAttachments (the :101 block: attachment
ownership, claim and link) and sendMessageDMSideEffects. EditMessage gets
editMessageCheckAccess and nothing else — one budget over earns one
extraction.

The sanitizeContent fixpoint and the attachment ownership check are unchanged,
as is the order of every gate. The DM side effects run behind
`isDM && !s.sendMessageDMSideEffects(...)`, so a non-DM never enters them;
inside, only the GetDMParticipantIDs failure returns false, matching the one
error the original early-returned on.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor(admin): split handlePatchUser into per-field apply helpers

106 lines / cyclomatic 29, with the ban block at :154 nested 9 deep.

Each optional field of the partial edit becomes its own helper —
patchUserPrecheck, patchUserAuthorizeRole, patchUserApplyBan (the :154 block,
including the session disconnect and the broadcast) and patchUserApplyRole.
Each returns a bool meaning "keep going"; none of them writes a success
response, so the single response site in the orchestrator is unchanged.

Field application order, the permission-cache invalidation on a role change
and the disconnect-and-broadcast on a ban are all preserved, as are the three
fail-closed `mod == nil` guards, which now sit at the top of their own helper
and still fire on exactly the same conditions.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor(admin): split handleSetup into first-run setup stages

143 lines / cyclomatic 30, with the optional-wizard block at :219 sitting
exactly on the nestif threshold.

Split into the stages the endpoint already had: request gating (rate limit and
origin check, which run before any auth exists on a fresh server), owner
account creation, and the wizard application that was the :219 block.

Every gate in front of the handler is a security control on an unauthenticated
endpoint; none moved relative to the work it protects. setup_wizard.go is
untouched.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor: split run() into named bootstrap and shutdown steps

131 statements / cyclomatic 57, with the executable-path fallback at :126
nested 9 deep.

The five anonymous `defer func(){...}()` blocks become named functions —
telemetryStop, runClosePlugins, runStopEventPersistence, runStopAuditWriter,
maintenanceStop — and the bootstrap stages move out likewise.

Every defer is still registered in run() itself, at the same point in the
sequence, so the LIFO teardown order is unchanged; that order is documented
in the surrounding comments and is load-bearing (the audit-writer stop must
follow database.Close's registration, the event-persistence stop must precede
it). runStopEventPersistence is now registered unconditionally with a nil
persister meaning "disabled", where the old code registered its defer inside
the enabled branch — a no-op occupying that slot cannot change the relative
order of the others.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor(ws): split handleReconnect into resume stages

77 statements / cyclomatic 41, plus the replay block at :199 and, in
handleFreshConnect, the voice-state restore at :622.

handleReconnect becomes reconnectPrecheck, reconnectSelectReplay (with
reconnectVetColdTail for the cold-tier gap check), reconnectRegister and
reconnectWriteReplay. handleFreshConnect's stale-voice cleanup moves to its
own helper, where the `if h.livekit != nil` wrapper becomes a guard clause —
that block was the tail of its scope, so returning early and falling off the
end are the same.

The parts that carry the invariants are moved verbatim: reconnectRegister
still takes h.seqMu, still calls registerNow inside that same critical
section (BUG-123 / OC-0206), still unlocks on every exit, and still emits the
"full" tier counter and telemetry on each of its three re-check failures.
handleReconnect's two-boolean contract is unchanged — the collapsed
`return false, false` sites are all fall-through-to-full-ready, and the
single `return true, false` is still the handshake-write-failure path whose
teardown already ran (OC-0051).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* docs(server): fold in the adversarial review of the complexity refactors

Eleven skeptic passes over the refactor commits on this branch found no
blocker and no major — behaviour is preserved throughout. They did find
comment and accuracy defects worth correcting:

- db/mention_queries.go: the mentionTargetColumn rationale claimed the named
  type made the interpolated column "only ever one of the two constants". A
  Go named type is not closed, so that is a convention the type makes visible,
  not one it enforces. Reworded, gosec justification included.
- ws/voice_controls.go: the dupl collapse generalised away three specifics —
  that a server deafen is the moderator's to lift (now on the serverDeafen
  field), the concrete voice_states.camera / voice_states.screenshare column
  names, and the half of the OC-0023 rationale about neither stream kind
  hiding from the other's count. All three restored.
- ws/voice_join.go: `maxUsers := ch.VoiceMaxUsers` had been hoisted to the top
  of voiceJoinComplete, moving a read across the tail supersession guard. The
  read is inert, but it was the one statement in that commit whose position
  relative to a security guard changed; it now sits at its use, as before.
- ws/*_test.go: three test comments cited voice_join.go line numbers that the
  split invalidated. They now cite the helper by name instead.
- service/message_reactions.go: reactionAudience's doc claimed to enforce
  "every gate on reacting"; it enforces the channel-scoped ones, and the doc
  now says which gates stay with the caller.
- api/emoji_handler.go: the readEmojiUpload call reused the outer `ok` from
  the auth check by assignment; it gets its own readOK.
- admin/setup_handler.go: a moved comment kept a "the response above" deictic
  that no longer had a response above it.

No behaviour change. Build, vet, full tests and -race on five packages green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor(ws): clear the remaining complexity budgets across the hub

Eight files, thirteen findings. Each function is split at the stages it
already had; no branch is reordered, merged or inverted.

- handlers.go handleMessage (cyclop 28, 88 stmts): session re-check, frame
  decode and result application become handleMessageSessionRecheck,
  handleMessageDecode and handleMessageApply. The V2 constructor lookup ->
  DispatchV2 -> Result resolution order is untouched.
- serve_ready.go buildReady (cyclop 26, 61 stmts): the per-section fetches
  split out, readyChannelPayloads among them. Every visibility predicate is
  preserved verbatim — this is the payload that decides what a client may see.
- serve_pumps.go writePump (cyclop 31): writePumpWrite, writePumpDeliver,
  writePumpDrainChannel and writePumpDrainAndClose. Every channel receive
  stays in the same select statement, so scheduling is unchanged.
- hub_sweep.go sweepStaleVoiceStates (cyclop 22, 56 stmts): the staleness
  predicate, the hub-lock ordering and the position of the race hook are all
  as they were — handleVoiceJoin's BUG-088 ordering depends on them.
- hub_broadcast.go channelReadAudienceImpl and RefreshChannelVisibility
  (cyclop 22 each, 57 stmts): channelReadAudienceDM and
  refreshChannelVisibilityCanSend. The audience predicate is the OC-0090
  group-DM leak surface, so it is extracted, never simplified.
- livekit_webhook.go (nestif 13 and 14): webhookJoinedEnforceVoiceState,
  webhookLeftCleanupClient and webhookLeftFinishLeave. DB delete still
  precedes broadcast on every path.
- livekit_download.go EnsureLiveKitBinary (52 stmts): one extraction,
  ensureLiveKitStageBinary, keeping every archive path check intact.
- voice_moderation.go (nestif 8): voiceModDeafenRollback. The persisted
  server_muted flag remains the authority.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor(api): clear the remaining complexity budgets across the HTTP layer

- router.go NewRouter (cyclop 28, 84 stmts): split by wiring concern into
  routerTOTPKey, routerHealthDeps, routerMiddleware, routerUploadRoutes,
  routerPluginWiring, routerVoiceRoutes and routerMetricsRoutes. Middleware
  ORDER is a security property (auth before handler, WAF before body parse,
  rate limit before work) and is unchanged; the returned cleanup func still
  closes over and releases everything it did before.
- auth_handler.go handleRegister (133 lines) and handleLogin (cyclop 21,
  152 lines): registerPolicyGate, registerReadRequest, loginReadRequest and
  loginAuthenticate. The always-compare posture, every rate-limit key, every
  counter reset and the ban-check-versus-password-compare order are all
  preserved — including loginUserFailureThreshold staying unscaled by
  scaledAuthLimit, which is deliberate and commented.
- upload_handler.go handleServeFile (cyclop 31, 128 lines): serveFileResolve
  and serveFileAuthorize. Every header this sets — Content-Disposition
  included, which is what stops a stored file being served as active content —
  is still set with the same value in the same circumstances.
- profile_handler.go handleUploadAvatar (120 lines): avatarUploadReadImage,
  mirroring readEmojiUpload in shape but with the avatar caps and MIME set.
  The two deliberately do not share a helper.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor: clear the last complexity budgets in db and admin

- db/account.go DeleteAccount (cyclop 28, 55 stmts): grouped by subsystem into
  deleteAccountAdminGuard, deleteAccountDMChannels and
  deleteAccountCloseDMChannels, each taking the same transaction. The
  transaction boundary, the delete ORDER (which foreign keys depend on) and
  the rollback path are unchanged.
- admin/logstream.go handleLogStream (cyclop 24): logStreamAuthorize. Flush
  cadence, heartbeat and disconnect detection untouched.
- admin/setup_wizard.go validateWizard (cyclop 23): grouped by section into
  wizardValidateIdentity, wizardValidateNetwork and wizardValidateMedia. Every
  message and bound is unchanged — this is the first input-validation boundary
  on a fresh server, before any auth exists.

With this the tree is at zero: golangci-lint run reports 0 issues against the
budgets set in #1384 (funlen 100/50, cyclop 20, nestif 8, dupl 150), with no
//nolint and no exclusion added anywhere.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-18 20:39:45 +02:00

667 lines
22 KiB
Go

// Phase C Step 9 — Plugin registry, lifecycle, and host-API plumbing.
//
// The Registry is the long-lived handle the rest of the server holds onto. It
// owns the Wazero runtime (in the wazero-tagged build), the loaded plugin
// instances, and the dispatch tables for host-API capabilities (commands,
// events, storage, http, ui).
//
// In the default build the runtime is a stub: LoadAll walks the plugins
// directory and persists each manifest into the PluginStore so admins can see
// what is "installed", but the .wasm files are NOT executed. Calling
// Dispatch() in the default build returns ErrRuntimeUnavailable.
package plugin
import (
"archive/zip"
"context"
"errors"
"fmt"
"io"
"log/slog"
"os"
"path/filepath"
"strings"
"sync"
)
// Config is the runtime configuration sourced from PluginsConfig.
type Config struct {
Directory string
MaxMemoryMB int
CPUBudgetMs int
HTTPAllowlist []string
Store PluginStore
}
// Registry is the central plugin coordinator.
type Registry struct {
cfg Config
mu sync.RWMutex
plugins map[int64]*Instance // by plugin row id
byName map[string]*Instance // by manifest name
commands map[string]*Instance // command name → owning plugin
uiTabs []UITabBinding // declared by `ui` capability plugins
// sink is the hub→plugin event fan-out. Plugins subscribe to topics via
// Subscribe; the WS hub calls sink.Dispatch on each broadcast.
sink *EventSink
// runtimePlatform is populated by platformInit in the wazero-tagged build
// with a concrete *wazero.Runtime. The default build leaves it nil and
// falls back to manifest-only behaviour. platformClose tears the runtime
// down; both fields are set by platformInit atomically.
runtimePlatform any
platformClose func(context.Context) error
}
// Instance is a single loaded plugin.
type Instance struct {
ID int64
Manifest *Manifest
Dir string // on-disk plugin directory, from foundPlugin.Dir — NOT derived from Manifest.Name
WASMPath string
Enabled bool
// invokeMu serializes guest calls for this instance. wazero's Function.Call
// is not goroutine-safe, and concurrent invocations race the module's shared
// linear-memory buffer (F2). Held by the wazero-tagged invokeCommand around
// the whole allocate/write/dispatch/read sequence.
invokeMu sync.Mutex //nolint:unused // used only by the wazero-tagged build
// module is the wazero compiled module in the wazero-tagged build, or
// nil in the default build.
module any //nolint:unused // assigned by wazero-tagged build
// compiled is the wazero CompiledModule behind module. Retained so
// teardown can close it — the shared runtime otherwise keeps every
// compile from every re-activation cycle until process exit.
compiled any //nolint:unused // assigned by wazero-tagged build
}
// UITabBinding is the public projection of a plugin's declared UI tab,
// served to the client bridge so it can render iframe tabs.
type UITabBinding struct {
PluginID int64
PluginName string
Tab UITab
}
// NewRegistry constructs a registry. In the default build it is a thin
// holder; the wazero-tagged build replaces this constructor with one that
// stands up a real Wazero runtime.
func NewRegistry(cfg Config) (*Registry, error) {
if cfg.Store == nil {
return nil, fmt.Errorf("plugin: NewRegistry requires a non-nil PluginStore")
}
r := &Registry{
cfg: cfg,
plugins: make(map[int64]*Instance),
byName: make(map[string]*Instance),
commands: make(map[string]*Instance),
sink: NewEventSink(),
}
// platformInit is supplied by sandbox_default.go (no-op) or
// sandbox_wazero.go (real Wazero runtime). Either way it owns the
// runtimePlatform + platformClose pair on the Registry.
platform, closeFn, err := platformInit(cfg)
if err != nil {
return nil, fmt.Errorf("plugin: platform init: %w", err)
}
r.runtimePlatform = platform
r.platformClose = closeFn
return r, nil
}
// Close shuts the registry down. In the wazero-tagged build it tears the
// runtime down and frees module memory.
func (r *Registry) Close(ctx context.Context) error {
r.mu.Lock()
for _, inst := range r.plugins {
r.platformDeactivate(ctx, inst)
}
for id := range r.plugins {
delete(r.plugins, id)
}
for n := range r.byName {
delete(r.byName, n)
}
for c := range r.commands {
delete(r.commands, c)
}
r.uiTabs = nil
closeFn := r.platformClose
r.platformClose = nil
r.runtimePlatform = nil
r.mu.Unlock()
if closeFn != nil {
return closeFn(ctx)
}
return nil
}
// Sink returns the registry's EventSink, used by the WS hub to fan out
// broadcast events to subscribed plugins and by the wazero build to deliver
// plugin output back to WS clients.
func (r *Registry) Sink() *EventSink {
return r.sink
}
// LoadAll scans cfg.Directory and persists every plugin.json found into the
// PluginStore. In the wazero-tagged build it then compiles each entrypoint
// into a runnable module; the default build stops at the persistence step.
func (r *Registry) LoadAll(ctx context.Context) error {
if r == nil {
return nil
}
// Clean up any staging directories left over from a previous crash
// during InstallFromZip. These are named ".install-XXXXXX" and are
// safe to remove because a successful install always renames them away.
if entries, rdErr := os.ReadDir(r.cfg.Directory); rdErr == nil {
for _, e := range entries {
if e.IsDir() && strings.HasPrefix(e.Name(), ".install-") {
staleDir := filepath.Join(r.cfg.Directory, e.Name())
if rmErr := os.RemoveAll(staleDir); rmErr != nil {
slog.Warn("plugin: failed to remove stale staging dir", "dir", staleDir, "err", rmErr)
}
}
}
}
manifests, err := scanPluginDirectory(r.cfg.Directory)
if err != nil {
return fmt.Errorf("plugin: scan %q: %w", r.cfg.Directory, err)
}
for _, found := range manifests {
if err := r.installFromDisk(ctx, found); err != nil {
slog.Warn("plugin: failed to install from disk", "name", found.Manifest.Name, "err", err)
continue
}
}
return r.activateAll(ctx)
}
// installFromDisk persists a manifest discovered on disk into the PluginStore
// and registers it in the in-memory registry.
func (r *Registry) installFromDisk(ctx context.Context, found foundPlugin) error {
manifestJSON, err := found.Manifest.serialize()
if err != nil {
return err
}
id, err := r.cfg.Store.InstallPlugin(ctx, found.Manifest.Name, found.Manifest.Version, manifestJSON)
if err != nil {
return fmt.Errorf("InstallPlugin: %w", err)
}
r.mu.Lock()
defer r.mu.Unlock()
// Re-install: tear down the old instance and drop its command bindings.
// Bindings are keyed to the old *Instance, so leaving them in place both
// blocked the fresh instance from re-registering its own commands and
// kept dispatch routing into the orphaned old module until restart.
if old := r.byName[found.Manifest.Name]; old != nil {
r.platformDeactivate(ctx, old)
for cmd, owner := range r.commands {
if owner == old {
delete(r.commands, cmd)
}
}
if old.ID != id {
delete(r.plugins, old.ID)
}
}
inst := &Instance{
ID: id,
Manifest: found.Manifest,
Dir: found.Dir,
WASMPath: found.WASMPath,
Enabled: false,
}
r.plugins[id] = inst
r.byName[found.Manifest.Name] = inst
return nil
}
// InstallFromZip extracts a plugin .zip uploaded via the admin API into a
// temp directory, validates it (zip-slip safe, no symlinks, size-capped),
// then renames it into the plugin directory and registers it via
// installFromDisk. Returns the new plugin name on success.
//
// The zip must contain a top-level plugin.json. The plugin's directory name
// is taken from manifest.Name (validated by Manifest.Validate to a strict
// charset). Re-installing an existing plugin replaces it.
const (
maxZipBytes = 16 * 1024 * 1024 // 16 MiB compressed
maxUncompressedSum = 64 * 1024 * 1024 // 64 MiB total uncompressed
)
func (r *Registry) InstallFromZip(ctx context.Context, zipBytes []byte) (string, error) {
if r == nil || r.cfg.Directory == "" {
return "", fmt.Errorf("plugin runtime not configured")
}
if int64(len(zipBytes)) > maxZipBytes {
return "", fmt.Errorf("plugin zip exceeds %d bytes", maxZipBytes)
}
zr, err := zip.NewReader(bytesReaderAt(zipBytes), int64(len(zipBytes)))
if err != nil {
return "", fmt.Errorf("invalid zip: %w", err)
}
// Stage 1: extract into a temp dir under the plugin directory.
if err := os.MkdirAll(r.cfg.Directory, 0o750); err != nil {
return "", fmt.Errorf("create plugin dir: %w", err)
}
stage, err := os.MkdirTemp(r.cfg.Directory, ".install-")
if err != nil {
return "", fmt.Errorf("create staging dir: %w", err)
}
cleanup := func() { _ = os.RemoveAll(stage) }
stageAbs, absErr := filepath.Abs(stage)
if absErr != nil {
cleanup()
return "", fmt.Errorf("abs staging dir: %w", absErr)
}
if err := installZipExtract(zr, stageAbs); err != nil {
cleanup()
return "", err
}
// Stage 2: parse the manifest now that the staging dir is fully populated.
manifest, err := installZipStagedManifest(stageAbs)
if err != nil {
cleanup()
return "", err
}
// Stage 3: atomically rename into the canonical plugin name directory.
finalDir := filepath.Join(r.cfg.Directory, manifest.Name)
if err := installZipPromote(stageAbs, finalDir); err != nil {
cleanup()
return "", err
}
// Stage 4: register via the existing on-disk install path.
if err := r.installFromDisk(ctx, foundPlugin{
Manifest: manifest,
Dir: finalDir,
WASMPath: filepath.Join(finalDir, manifest.Entrypoint),
}); err != nil {
return manifest.Name, fmt.Errorf("installFromDisk: %w", err)
}
r.installZipReactivate(ctx, manifest.Name)
return manifest.Name, nil
}
// installZipExtract writes every entry of zr into the already-created staging
// directory stageAbs, enforcing the zip-slip, symlink and uncompressed-size
// caps entry by entry before each write. The caller owns stageAbs and removes
// it on any error returned here.
func installZipExtract(zr *zip.Reader, stageAbs string) error {
var totalUncompressed int64
for _, f := range zr.File {
destAbs, entryErr := installZipEntryDest(f, stageAbs)
if entryErr != nil {
return entryErr
}
if f.Mode().IsDir() {
if err := os.MkdirAll(destAbs, 0o750); err != nil {
return err
}
continue
}
if err := os.MkdirAll(filepath.Dir(destAbs), 0o750); err != nil {
return err
}
// Cap each file at the remaining uncompressed budget so a zip bomb
// can't OOM the host.
remaining := maxUncompressedSum - totalUncompressed
n, writeErr := installZipWriteEntry(f, destAbs, remaining)
if writeErr != nil {
return writeErr
}
totalUncompressed += n
}
return nil
}
// installZipEntryDest validates one zip entry's mode and name and returns the
// absolute path it may be written to under stageAbs. Every rejection here is a
// hard stop: non-regular modes, symlinks, and any name that escapes stageAbs.
func installZipEntryDest(f *zip.File, stageAbs string) (string, error) {
// Reject symlinks, devices, and any non-regular file mode.
if !f.Mode().IsRegular() && !f.Mode().IsDir() {
return "", fmt.Errorf("plugin zip: refusing non-regular entry %q (mode=%v)", f.Name, f.Mode())
}
if f.Mode()&os.ModeSymlink != 0 {
return "", fmt.Errorf("plugin zip: refusing symlink %q", f.Name)
}
// Reject zip-slip: cleaned absolute path must stay rooted at the
// staging directory.
clean := filepath.Clean(f.Name)
if strings.HasPrefix(clean, "..") || filepath.IsAbs(clean) || strings.Contains(clean, "..\\") {
return "", fmt.Errorf("plugin zip: refusing path-traversal entry %q", f.Name)
}
dest := filepath.Join(stageAbs, clean)
destAbs, dErr := filepath.Abs(dest)
if dErr != nil {
return "", dErr
}
rel, relErr := filepath.Rel(stageAbs, destAbs)
if relErr != nil || strings.HasPrefix(rel, "..") || filepath.IsAbs(rel) {
return "", fmt.Errorf("plugin zip: refusing escape %q", f.Name)
}
return destAbs, nil
}
// installZipWriteEntry copies one regular entry to destAbs, refusing to write
// more than remaining bytes — this entry's share of the maxUncompressedSum
// budget — and returns how many bytes it wrote.
func installZipWriteEntry(f *zip.File, destAbs string, remaining int64) (int64, error) {
rc, oErr := f.Open()
if oErr != nil {
return 0, oErr
}
out, cErr := os.OpenFile(destAbs, os.O_WRONLY|os.O_CREATE|os.O_TRUNC, 0o600)
if cErr != nil {
_ = rc.Close()
return 0, cErr
}
if remaining <= 0 {
_ = rc.Close()
_ = out.Close()
return 0, fmt.Errorf("plugin zip: uncompressed total exceeds %d bytes", maxUncompressedSum)
}
n, copyErr := io.CopyN(out, rc, remaining+1)
_ = rc.Close()
_ = out.Close()
if copyErr != nil && copyErr != io.EOF {
return 0, copyErr
}
if n > remaining {
return 0, fmt.Errorf("plugin zip: uncompressed total exceeds %d bytes", maxUncompressedSum)
}
return n, nil
}
// installZipStagedManifest parses the staged plugin.json and holds the staged
// tree to the same rules scanPluginDirectory applies to an on-disk plugin (no
// symlinks anywhere, entrypoint present and not a symlink).
func installZipStagedManifest(stageAbs string) (*Manifest, error) {
manifestPath := filepath.Join(stageAbs, "plugin.json")
raw, err := os.ReadFile(manifestPath)
if err != nil {
return nil, fmt.Errorf("plugin zip: missing plugin.json at root: %w", err)
}
manifest, err := ParseManifest(raw)
if err != nil {
return nil, err
}
// Validate the staged contents the same way scanPluginDirectory does.
if err := rejectSymlinksUnder(stageAbs); err != nil {
return nil, err
}
wasmPath := filepath.Join(stageAbs, manifest.Entrypoint)
if info, statErr := os.Lstat(wasmPath); statErr != nil {
return nil, fmt.Errorf("entrypoint %s missing: %w", manifest.Entrypoint, statErr)
} else if info.Mode()&os.ModeSymlink != 0 {
return nil, fmt.Errorf("entrypoint %s is a symlink", manifest.Entrypoint)
}
return manifest, nil
}
// installZipPromote moves the fully validated staging directory into its
// canonical plugin-name directory.
func installZipPromote(stageAbs, finalDir string) error {
// If a previous version exists, remove it. The store row is replaced by
// installFromDisk via the existing UPSERT path.
if _, err := os.Stat(finalDir); err == nil {
if err := os.RemoveAll(finalDir); err != nil {
return fmt.Errorf("remove existing plugin dir: %w", err)
}
}
if err := os.Rename(stageAbs, finalDir); err != nil {
return fmt.Errorf("install rename: %w", err)
}
return nil
}
// installZipReactivate restores the enabled state of a plugin that was already
// enabled before this upgrade.
//
// installFromDisk always registers the fresh instance as disabled and
// InstallPlugin's upsert never touches the `enabled` column, so a plugin
// that was enabled before this upgrade would otherwise come out the
// other side with the store row still saying enabled while the runtime
// instance sits inactive. LoadAll's startup path avoids this because it
// always runs activateAll afterward; this is the one caller of
// installFromDisk that doesn't, so it has to reactivate for itself.
// EnablePlugin already rolls the DB flag back if activation fails, so
// the two can no longer disagree.
func (r *Registry) installZipReactivate(ctx context.Context, name string) {
row, rowErr := r.cfg.Store.GetPluginByName(ctx, name)
if rowErr != nil || row == nil || !row.Enabled {
return
}
err := r.EnablePlugin(ctx, row.ID)
if err == nil {
return
}
if !errors.Is(err, ErrRuntimeUnavailable) {
slog.Warn("plugin: reactivate after upgrade failed", "name", name, "err", err)
return
}
// Default (non-wazero) build: nothing can activate here, and
// leaving EnablePlugin's rollback in place would persistently
// disable a plugin the admin left enabled — after a rebuild
// with -tags wazero it would silently stay off. Preserve the
// enabled intent instead; the next wazero-tagged start's
// activateAll does the real activation.
if reErr := r.cfg.Store.EnablePlugin(ctx, row.ID); reErr != nil {
slog.Warn("plugin: could not preserve enabled flag across runtime-less upgrade",
"name", name, "err", reErr)
return
}
r.mu.Lock()
if inst, ok := r.byName[name]; ok {
inst.Enabled = true
}
r.mu.Unlock()
slog.Info("plugin: runtime unavailable, enabled flag preserved across upgrade",
"name", name)
}
// bytesReaderAt is a tiny wrapper that satisfies io.ReaderAt for a byte
// slice. archive/zip needs ReaderAt; bytes.Reader provides it but importing
// "bytes" alongside the existing "io" surface keeps the import block tight.
type bytesReaderAt []byte
func (b bytesReaderAt) ReadAt(p []byte, off int64) (int, error) {
if off < 0 || off >= int64(len(b)) {
return 0, io.EOF
}
n := copy(p, b[off:])
if n < len(p) {
return n, io.EOF
}
return n, nil
}
// activateAll attempts to compile + register host-API hooks for every plugin
// row in the PluginStore that is marked enabled. The default build is a
// no-op (no Wazero modules to compile).
func (r *Registry) activateAll(ctx context.Context) error {
rows, err := r.cfg.Store.ListPlugins(ctx)
if err != nil {
return fmt.Errorf("ListPlugins: %w", err)
}
for _, row := range rows {
if !row.Enabled {
continue
}
r.mu.Lock()
inst, ok := r.byName[row.Name]
r.mu.Unlock()
if !ok {
slog.Warn("plugin: enabled row has no on-disk manifest, skipping", "name", row.Name)
continue
}
if err := r.activate(ctx, inst); err != nil {
slog.Warn("plugin: activation failed", "name", row.Name, "err", err)
continue
}
// Sync the in-memory enabled flag with the DB row so callers that
// read inst.Enabled (e.g. /api/v1/admin/plugins listings, future
// host-side capability checks) see the activated state.
r.mu.Lock()
inst.Enabled = true
r.mu.Unlock()
}
return nil
}
// activate compiles and starts a single plugin module. Default build returns
// ErrRuntimeUnavailable; the wazero-tagged build replaces this with the real
// implementation via activateWithRuntime.
//
// The runtimePlatform read is guarded by r.mu so a concurrent Close() that
// nil-s the field cannot be observed mid-activation. The captured platform
// value is then passed into activateWithRuntime as a parameter so the actual
// compile uses the snapshot rather than re-reading r.runtimePlatform — this
// closes the race window between the nil check and the wazero call.
func (r *Registry) activate(ctx context.Context, inst *Instance) error {
r.mu.RLock()
platform := r.runtimePlatform
r.mu.RUnlock()
if platform == nil {
return ErrRuntimeUnavailable
}
return r.activateWithRuntime(ctx, platform, inst)
}
// EnablePlugin marks a plugin enabled in the store, then attempts to load it.
func (r *Registry) EnablePlugin(ctx context.Context, id int64) error {
if err := r.cfg.Store.EnablePlugin(ctx, id); err != nil {
return err
}
r.mu.RLock()
inst, ok := r.plugins[id]
r.mu.RUnlock()
if !ok {
// No in-memory instance to activate — roll the DB flag back so it
// doesn't stay stuck at enabled=1 with nothing backing it, the same
// way the activation-failure path below rolls back.
_ = r.cfg.Store.DisablePlugin(ctx, id)
return ErrPluginNotFound
}
r.mu.Lock()
inst.Enabled = true
r.mu.Unlock()
if err := r.activate(ctx, inst); err != nil {
// Roll back the DB flag and the in-memory flag so the next start
// attempt is consistent.
_ = r.cfg.Store.DisablePlugin(ctx, id)
r.mu.Lock()
inst.Enabled = false
r.mu.Unlock()
return err
}
return nil
}
// DisablePlugin marks a plugin disabled and tears its module down. The
// wazero-tagged build frees the compiled module via platformDeactivate so
// re-enabling recompiles from disk; the default build is a no-op.
func (r *Registry) DisablePlugin(ctx context.Context, id int64) error {
if err := r.cfg.Store.DisablePlugin(ctx, id); err != nil {
return err
}
r.mu.Lock()
defer r.mu.Unlock()
if inst, ok := r.plugins[id]; ok {
inst.Enabled = false
// Drop command bindings owned by this plugin.
for cmd, owner := range r.commands {
if owner == inst {
delete(r.commands, cmd)
}
}
// Free the wazero module so memory is returned to the runtime
// immediately rather than waiting for registry Close. Safe to call
// on an instance that was never activated.
r.platformDeactivate(ctx, inst)
}
return nil
}
// removeAll is os.RemoveAll indirected so tests can force a directory-removal
// failure deterministically. Windows silently succeeds at deleting read-only
// files (there's no portable, privilege-free way to make a real RemoveAll
// fail from a test), so this is the seam that lets the error-return path in
// UninstallPlugin be pinned.
var removeAll = os.RemoveAll
// UninstallPlugin removes a plugin entirely.
func (r *Registry) UninstallPlugin(ctx context.Context, id int64) error {
if err := r.DisablePlugin(ctx, id); err != nil {
slog.Warn("plugin: disable failed during uninstall", "id", id, "err", err)
}
// Capture the plugin's on-disk directory before removing the in-memory
// record so we can clean it up after the DB row is gone.
r.mu.RLock()
inst, instOK := r.plugins[id]
var pluginDir string
if instOK {
pluginDir = inst.Dir
}
r.mu.RUnlock()
if err := r.cfg.Store.UninstallPlugin(ctx, id); err != nil {
return err
}
r.mu.Lock()
if inst, ok := r.plugins[id]; ok {
delete(r.byName, inst.Manifest.Name)
}
delete(r.plugins, id)
r.mu.Unlock()
// Remove on-disk files so the plugin isn't resurrected on the next
// startup by scanPluginDirectory. The DB row and in-memory record are
// already gone at this point, so a removal failure is reported rather
// than swallowed — the caller needs to know the directory still has to
// be cleaned up by hand before the next restart, or scanPluginDirectory
// will bring the "uninstalled" plugin right back.
if pluginDir != "" {
if err := removeAll(pluginDir); err != nil {
slog.Warn("plugin: failed to remove plugin directory after uninstall", "dir", pluginDir, "err", err)
return fmt.Errorf("remove plugin dir: %w", err)
}
}
return nil
}
// List returns the currently registered plugins. Read-only snapshot.
func (r *Registry) List() []*Instance {
r.mu.RLock()
defer r.mu.RUnlock()
out := make([]*Instance, 0, len(r.plugins))
for _, p := range r.plugins {
out = append(out, p)
}
return out
}
// UITabBindings returns the declared UI tabs across enabled plugins.
func (r *Registry) UITabBindings() []UITabBinding {
r.mu.RLock()
defer r.mu.RUnlock()
out := make([]UITabBinding, len(r.uiTabs))
copy(out, r.uiTabs)
return out
}