Files
OwnCord/Server/plugin/loader.go
T
J3vb ae496082b3 feat(phase-bc): TOML plugin manifests + Solid vitest preset
Plugin TOML support (-tags wazero):
- manifest_toml.go: tryLoadPluginTOML using BurntSushi/toml v1.6.0
- manifest_nottoml.go: no-op stub for default build
- loader.go: prefers plugin.toml, falls back to plugin.json

Solid vitest preset:
- vitest.config.ts: add vite-plugin-solid, expand include to
  src/components/solid/**/*.test.tsx — Badge.test.tsx now runs
  automatically as part of npm test (112 files / 3188 tests)
2026-04-06 23:25:16 +02:00

123 lines
3.7 KiB
Go

// Phase C Step 9 — On-disk plugin discovery.
//
// Each plugin lives in its own subdirectory under PluginsConfig.Directory:
//
// plugins/
// hello/
// plugin.json
// hello.wasm
// game-detection/
// plugin.json
// detector.wasm
// assets/...
//
// Loader walks the directory, parses every plugin.json, and returns a slice
// of foundPlugin records. The Registry then persists each into the store.
package plugin
import (
"encoding/json"
"fmt"
"os"
"path/filepath"
)
type foundPlugin struct {
Manifest *Manifest
Dir string
WASMPath string
}
// scanPluginDirectory walks dir non-recursively and parses plugin.json from
// every immediate subdirectory. Errors on individual plugins are wrapped and
// returned alongside the successful entries.
func scanPluginDirectory(dir string) ([]foundPlugin, error) {
if dir == "" {
return nil, nil
}
entries, err := os.ReadDir(dir)
if err != nil {
if os.IsNotExist(err) {
// Directory absent is fine — operators may not have created it yet.
return nil, nil
}
return nil, err
}
var found []foundPlugin
for _, e := range entries {
if !e.IsDir() {
continue
}
pluginDir := filepath.Join(dir, e.Name())
// Prefer plugin.toml (wazero build) over plugin.json.
manifest, ok, tomlErr := tryLoadPluginTOML(pluginDir)
if tomlErr != nil {
return nil, fmt.Errorf("plugin %q: %w", e.Name(), tomlErr)
}
if !ok {
// Fall back to plugin.json.
manifestPath := filepath.Join(pluginDir, "plugin.json")
raw, rdErr := os.ReadFile(manifestPath)
if rdErr != nil {
if os.IsNotExist(rdErr) {
continue
}
return nil, fmt.Errorf("plugin %q: read plugin.json: %w", e.Name(), rdErr)
}
var parseErr error
manifest, parseErr = ParseManifest(raw)
if parseErr != nil {
return nil, fmt.Errorf("plugin %q: %w", e.Name(), parseErr)
}
}
// Reject any symlinks anywhere in the plugin directory tree. The asset
// handler enforces that resolved paths stay rooted at pluginDir, but
// http.ServeFile / os.Open follow symlinks transparently — a malicious
// plugin .zip containing `assets/index.html -> /etc/passwd` would
// otherwise serve host files. Lstat (not Stat) is used for the
// entrypoint check below so a symlink is detected instead of
// followed, even when its target is a valid .wasm file.
if err := rejectSymlinksUnder(pluginDir); err != nil {
return nil, fmt.Errorf("plugin %q: %w", e.Name(), err)
}
wasmPath := filepath.Join(pluginDir, manifest.Entrypoint)
if info, statErr := os.Lstat(wasmPath); statErr != nil {
return nil, fmt.Errorf("plugin %q: missing entrypoint %s: %w", e.Name(), manifest.Entrypoint, statErr)
} else if info.Mode()&os.ModeSymlink != 0 {
return nil, fmt.Errorf("plugin %q: entrypoint %s is a symlink", e.Name(), manifest.Entrypoint)
}
found = append(found, foundPlugin{
Manifest: manifest,
Dir: pluginDir,
WASMPath: wasmPath,
})
}
return found, nil
}
// rejectSymlinksUnder walks root and returns an error if any entry is a
// symlink. Defends against malicious plugin packages that ship symlinks to
// host filesystem paths.
func rejectSymlinksUnder(root string) error {
return filepath.Walk(root, func(path string, info os.FileInfo, err error) error {
if err != nil {
return err
}
if info.Mode()&os.ModeSymlink != 0 {
return fmt.Errorf("symlink not allowed: %s", path)
}
return nil
})
}
// serialize returns a canonical JSON encoding of the manifest, used as the
// manifest_json column value in the plugins table.
func (m *Manifest) serialize() (string, error) {
b, err := json.Marshal(m)
if err != nil {
return "", fmt.Errorf("manifest serialize: %w", err)
}
return string(b), nil
}