mirror of
https://github.com/J3vb/OwnCord.git
synced 2026-09-03 03:50:00 +03:00
* fix(identity): 1 defect(s) (OC-0151)
* fix(ws): 1 defect(s) (OC-0152)
* fix(admin): 1 defect(s) (OC-0153)
* fix(admin): 1 defect(s) (OC-0154)
* fix(voice): 2 defect(s) (OC-0155, OC-0167)
Replace distributeRoomKey's per-call offer counter with an instance-level
sliding-window budget shared by every voice_e2ee_offer send path.
- OC-0155: back-to-back rotations (the second run immediately by
drainPendingRotationOrArmTimer) each got a fresh pacing budget, so their
combined sends could exceed the server's single per-second cap.
- OC-0167: handleAnnounceInner's drain-time offer send bypassed pacing
entirely, letting a key holder joining a large ongoing call burst every
queued announce's offer unpaced.
The shared budget is reset in clearState() since the server's limit is
scoped per (sender, channel).
* fix(client): 1 defect(s) (OC-0156)
createPresenceSender dropped a queued custom_status when a later plain
status change superseded the pending retry. The retry now carries the
last committed custom_status forward.
* fix(client): 2 defect(s) (OC-0160, OC-0163)
OC-0160: exempt the handshake frames (ready, auth_ok) from the ws message
size limit and run the guard after parsing. A 'ready' frame grows unbounded
with member/channel/DM counts and carries no seq, so dropping it left the
client on empty stores with no error and no recovery path.
OC-0163: bracket a bare IPv6 host when building the wss:// URL so the
authority parses, and collapse bracketed/bare IPv6 literals to the same
cert_store_key so one server is not pinned (and user-confirmed) twice.
* fix(voice): 1 defect(s) (OC-0162)
updatePttKey armed the Rust poller when a PTT key was bound mid-call but
never applied the gate. The poller only emits 'ptt-state' on a press/release
transition, so an idle key produced no event and the already-published mic
stayed hot until the user's first physical press+release. Mirror the join-time
gate computation in updatePttKey, guarded on being in a call, polling actually
being live, and the mic not already being gated.
* fix(client): 1 defect(s) (OC-0164)
* fix(plugin): 1 defect(s) (OC-0165)
scanPluginDirectory now skips a malformed plugin subdirectory and joins its
error instead of aborting the whole scan, and LoadAll logs-and-continues so
one bad plugin directory cannot disable every other plugin.
* fix(ws): 1 defect(s) (OC-0166)
Route PresenceSelfEvent onto the owner's normal-priority queue instead of
letting it fall through to the UserTargetedEvent high-priority case, so a
user's own presence frames all share one FIFO and cannot be delivered out
of order relative to the visible presence_update path.
* fix(db): 1 defect(s) (OC-0168)
* fix(client): 1 defect(s) (OC-0169)
* fix(client): 1 defect(s) (OC-0171)
addMessage appended a broadcast at the tail even when trailing optimistic
rows were still unreconciled, so a message that committed while our own
send was in flight ended up ordered behind the row confirmSend later
stamped with a higher server id/timestamp. Insert before the trailing
unreconciled run instead.
* fix(voice): 1 defect(s) (OC-0172)
* fix(client): 1 defect(s) (OC-0174)
* fix(ws): 1 defect(s) (OC-0175)
* fix(client): 1 defect(s) (OC-0177)
* fix(client): 1 defect(s) (OC-0178)
* fix(voice): 1 defect(s) (OC-0179)
Undeafening no longer sends a voice_mute{muted:false} the server will
refuse while a moderator-imposed mute stands, matching the localServerMuted
guard already present in onMuteToggle.
* fix(client): 1 defect(s) (OC-0182)
* fix(plugin): 1 defect(s) (OC-0183)
* fix(client): 1 defect(s) (OC-0184)
Treat a trailing underscore as an emphasis delimiter, not part of the URL,
when scanning for the end of an autolinked URL.
* fix(client): 1 defect(s) (OC-0185)
Reveal .msg-actions-bar on .message:focus-within, not only on hover, so
keyboard users can see the per-message action buttons they Tab into
instead of activating them at opacity: 0.
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(client): 1 defect(s) (OC-0186)
* fix(client): 1 defect(s) (OC-0187)
The Add Server modal validated addresses with its own narrower regex that
never gained IPv6 support when api.ts's validator did, so an IPv6 server
could be logged into but never saved as a profile. Extract the validator
into src/lib/hostValidation.ts and use it from both call sites.
* fix(client): 1 defect(s) (OC-0189)
DM sidebar rows dropped mention counts entirely and the header total
excluded muted conversations outright, so a direct mention in a muted DM
was invisible. Render a mention badge that outranks the plain unread
badge, and count a muted channel's mentionCount toward the header total.
* fix(client): 1 defect(s) (OC-0190)
* fix(client): 1 defect(s) (OC-0191)
* fix(client): 2 defect(s) (OC-0157, OC-0176)
* fix(client): 1 defect(s) (OC-0161)
confirmTotp answers 401 for a wrong enrollment code while the session is still valid; firing the global onUnauthorized sink signed the user out and deleted their stored credential. Opt that one call out via a skipUnauthorized flag on doFetch.
* fix(admin): 1 defect(s) (OC-0173)
* fix(identity): 1 defect(s) (OC-0180)
* fix(admin): archived channel PATCH skips voice eviction and fan-out (OC-0158)
handlePatchChannel commits the AdminUpdateChannel write, then re-reads the
channel to drive voice eviction and the visibility fan-out. When that
post-commit re-read failed, the handler returned early: the archive was
durable but connected clients were never told and voice members were never
evicted, leaving users talking in a channel that no longer exists for them.
Drive the post-commit work off the values already in hand rather than
abandoning it when the re-read fails.
Adds SetPatchChannelPostCommitHook so the test can land a cancellation in
that exact window deterministically instead of racing wall-clock timing.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(admin): role changes commit with no client ever notified (OC-0170)
broadcastRoles derived its context from the inbound *http.Request, so the
roles_update fan-out was tied to the request lifetime. A role create,
update, or delete could commit to the database and then broadcast nothing
once that request context was done, leaving every connected client on a
stale role list until the next full resync.
Decouple the fan-out from the request context so the broadcast follows the
commit rather than the caller.
Adds BroadcastRolesForTest to reach broadcastRoles from the external test
package.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(client): username rename stomps the profile card header (OC-0188)
The account profile card's header is a resolveDisplayName() slot, but the
username-rename save path wrote the raw username straight into it. A user
with a display name set would see the header switch from their display
name to their new username after a rename, disagreeing with every other
surface that renders the same identity.
Resolve the header through the same display-name path the initial render
uses, so a rename updates the username field without touching the header.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(client): settings overlay never focuses when mounted already-open (OC-0181)
mount() synced initial state — including the show() that calls
focusDialog() — before appending root to the container. .focus() on a
still-detached subtree is a silent no-op, so a caller that mounts while
uiStore.settingsOpen is already true (ConnectPage's lazy first-open path)
got a visible overlay whose focus trap never captured focus: keyboard
users landed outside the dialog with Tab escaping to the page behind it.
Attach root before syncing initial state so focusDialog() runs against a
connected subtree.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* chore: satisfy the CI gates for this fix batch
The fix batch's own commits left three CI gates red. Nothing here changes
behaviour; every edit is a lint, type, or formatting correction to code
this batch introduced.
golangci-lint:
- OC-0153 and OC-0173 replaced the last two uses of admin's setupSanitizer,
and OC-0151 the last use of api's sanitizer, leaving both package-level
bluemonday vars unused. Remove them along with the now-unused imports,
and reword the comments that named them so they still explain why the
fixpoint sanitizer is the right one without pointing at deleted symbols.
- Modernize the new handshake-deadline test's loop to range-over-int.
tsc --noEmit:
- jsdom ships no types and @types/jsdom is not a dependency, so declare the
surface the new admin-panel test uses, following src/types/jitsi-rnnoise.d.ts.
- Narrow the last-call lookup instead of indexing under
noUncheckedIndexedAccess, with an explicit failure message.
- membersStore.setState replaces whole state, so the presence-sender mocks
must supply typingUsers.
prettier: reformat the five files this batch touched.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* chore(ledger): record the 2026-08-19 hunt and its fixes
Adds the 41 findings confirmed by the 2026-08-19 hunt and marks the 40
fixed on this branch, each with its commit, the test that pins it, and
revertProof "pass".
"pass" means an independent check, not the fixing agent's self-report:
every commit had its source diff reverted against the working tree, its
own test re-run and required to FAIL, then the source restored and the
test required to PASS. Commits whose tests live inline in Rust
#[cfg(test)] blocks were proven the same way at hunk level, splicing the
pre-fix source onto the post-fix test module.
OC-0159 is recorded as a duplicate of OC-0152: the flow-reconnect and
flow-message lenses independently found the same unbounded handshake
write and proposed the same helper over the same call sites.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* test(e2e): make the voice-roster join fixture self-consistent
The voice-widget join test emitted a voice_state for user_id 4 claiming
username "newvoiceuser", but id 4 is "member2" in MOCK_MEMBERS_MULTI_ROLE.
A real server never sends a voice_state whose username disagrees with the
member record for that id, and the same file's VOICE_STATE_EVENT already
pairs id 1 with "testuser" correctly — this one event was the outlier.
The contradiction was invisible while the roster rendered the payload's
raw username. OC-0177 makes it resolve identity through membersStore so a
nickname shows the same in voice as everywhere else, at which point the
fixture's own inconsistency surfaced as a failure.
Send id 4's real username and assert on it. The test still covers what it
did before — a genuine join by a user not previously in voice, asserted by
name and by roster count.
Verified against the app unchanged: with the old fixture the spec fails
1/5 (matching CI), with this one it passes 5/5.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
---------
Co-authored-by: Claude <noreply@anthropic.com>
672 lines
22 KiB
Go
672 lines
22 KiB
Go
// Phase C Step 9 — Plugin registry, lifecycle, and host-API plumbing.
|
|
//
|
|
// The Registry is the long-lived handle the rest of the server holds onto. It
|
|
// owns the Wazero runtime (in the wazero-tagged build), the loaded plugin
|
|
// instances, and the dispatch tables for host-API capabilities (commands,
|
|
// events, storage, http, ui).
|
|
//
|
|
// In the default build the runtime is a stub: LoadAll walks the plugins
|
|
// directory and persists each manifest into the PluginStore so admins can see
|
|
// what is "installed", but the .wasm files are NOT executed. Calling
|
|
// Dispatch() in the default build returns ErrRuntimeUnavailable.
|
|
|
|
package plugin
|
|
|
|
import (
|
|
"archive/zip"
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
"io"
|
|
"log/slog"
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
"sync"
|
|
)
|
|
|
|
// Config is the runtime configuration sourced from PluginsConfig.
|
|
type Config struct {
|
|
Directory string
|
|
MaxMemoryMB int
|
|
CPUBudgetMs int
|
|
HTTPAllowlist []string
|
|
Store PluginStore
|
|
}
|
|
|
|
// Registry is the central plugin coordinator.
|
|
type Registry struct {
|
|
cfg Config
|
|
|
|
mu sync.RWMutex
|
|
plugins map[int64]*Instance // by plugin row id
|
|
byName map[string]*Instance // by manifest name
|
|
commands map[string]*Instance // command name → owning plugin
|
|
uiTabs []UITabBinding // declared by `ui` capability plugins
|
|
|
|
// sink is the hub→plugin event fan-out. Plugins subscribe to topics via
|
|
// Subscribe; the WS hub calls sink.Dispatch on each broadcast.
|
|
sink *EventSink
|
|
|
|
// runtimePlatform is populated by platformInit in the wazero-tagged build
|
|
// with a concrete *wazero.Runtime. The default build leaves it nil and
|
|
// falls back to manifest-only behaviour. platformClose tears the runtime
|
|
// down; both fields are set by platformInit atomically.
|
|
runtimePlatform any
|
|
platformClose func(context.Context) error
|
|
}
|
|
|
|
// Instance is a single loaded plugin.
|
|
type Instance struct {
|
|
ID int64
|
|
Manifest *Manifest
|
|
Dir string // on-disk plugin directory, from foundPlugin.Dir — NOT derived from Manifest.Name
|
|
WASMPath string
|
|
Enabled bool
|
|
|
|
// invokeMu serializes guest calls for this instance. wazero's Function.Call
|
|
// is not goroutine-safe, and concurrent invocations race the module's shared
|
|
// linear-memory buffer (F2). Held by the wazero-tagged invokeCommand around
|
|
// the whole allocate/write/dispatch/read sequence.
|
|
invokeMu sync.Mutex //nolint:unused // used only by the wazero-tagged build
|
|
|
|
// module is the wazero compiled module in the wazero-tagged build, or
|
|
// nil in the default build.
|
|
module any //nolint:unused // assigned by wazero-tagged build
|
|
|
|
// compiled is the wazero CompiledModule behind module. Retained so
|
|
// teardown can close it — the shared runtime otherwise keeps every
|
|
// compile from every re-activation cycle until process exit.
|
|
compiled any //nolint:unused // assigned by wazero-tagged build
|
|
}
|
|
|
|
// UITabBinding is the public projection of a plugin's declared UI tab,
|
|
// served to the client bridge so it can render iframe tabs.
|
|
type UITabBinding struct {
|
|
PluginID int64
|
|
PluginName string
|
|
Tab UITab
|
|
}
|
|
|
|
// NewRegistry constructs a registry. In the default build it is a thin
|
|
// holder; the wazero-tagged build replaces this constructor with one that
|
|
// stands up a real Wazero runtime.
|
|
func NewRegistry(cfg Config) (*Registry, error) {
|
|
if cfg.Store == nil {
|
|
return nil, fmt.Errorf("plugin: NewRegistry requires a non-nil PluginStore")
|
|
}
|
|
r := &Registry{
|
|
cfg: cfg,
|
|
plugins: make(map[int64]*Instance),
|
|
byName: make(map[string]*Instance),
|
|
commands: make(map[string]*Instance),
|
|
sink: NewEventSink(),
|
|
}
|
|
// platformInit is supplied by sandbox_default.go (no-op) or
|
|
// sandbox_wazero.go (real Wazero runtime). Either way it owns the
|
|
// runtimePlatform + platformClose pair on the Registry.
|
|
platform, closeFn, err := platformInit(cfg)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("plugin: platform init: %w", err)
|
|
}
|
|
r.runtimePlatform = platform
|
|
r.platformClose = closeFn
|
|
return r, nil
|
|
}
|
|
|
|
// Close shuts the registry down. In the wazero-tagged build it tears the
|
|
// runtime down and frees module memory.
|
|
func (r *Registry) Close(ctx context.Context) error {
|
|
r.mu.Lock()
|
|
for _, inst := range r.plugins {
|
|
r.platformDeactivate(ctx, inst)
|
|
}
|
|
for id := range r.plugins {
|
|
delete(r.plugins, id)
|
|
}
|
|
for n := range r.byName {
|
|
delete(r.byName, n)
|
|
}
|
|
for c := range r.commands {
|
|
delete(r.commands, c)
|
|
}
|
|
r.uiTabs = nil
|
|
closeFn := r.platformClose
|
|
r.platformClose = nil
|
|
r.runtimePlatform = nil
|
|
r.mu.Unlock()
|
|
if closeFn != nil {
|
|
return closeFn(ctx)
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// Sink returns the registry's EventSink, used by the WS hub to fan out
|
|
// broadcast events to subscribed plugins and by the wazero build to deliver
|
|
// plugin output back to WS clients.
|
|
func (r *Registry) Sink() *EventSink {
|
|
return r.sink
|
|
}
|
|
|
|
// LoadAll scans cfg.Directory and persists every plugin.json found into the
|
|
// PluginStore. In the wazero-tagged build it then compiles each entrypoint
|
|
// into a runnable module; the default build stops at the persistence step.
|
|
func (r *Registry) LoadAll(ctx context.Context) error {
|
|
if r == nil {
|
|
return nil
|
|
}
|
|
// Clean up any staging directories left over from a previous crash
|
|
// during InstallFromZip. These are named ".install-XXXXXX" and are
|
|
// safe to remove because a successful install always renames them away.
|
|
if entries, rdErr := os.ReadDir(r.cfg.Directory); rdErr == nil {
|
|
for _, e := range entries {
|
|
if e.IsDir() && strings.HasPrefix(e.Name(), ".install-") {
|
|
staleDir := filepath.Join(r.cfg.Directory, e.Name())
|
|
if rmErr := os.RemoveAll(staleDir); rmErr != nil {
|
|
slog.Warn("plugin: failed to remove stale staging dir", "dir", staleDir, "err", rmErr)
|
|
}
|
|
}
|
|
}
|
|
}
|
|
// scanPluginDirectory reports a non-nil error whenever at least one
|
|
// plugin subdirectory failed to parse, but it still returns every
|
|
// plugin that scanned cleanly in `manifests`. Log-and-continue here
|
|
// rather than aborting: one malformed plugin directory must not take
|
|
// every other, otherwise-valid plugin down with it (OC-0165).
|
|
manifests, err := scanPluginDirectory(r.cfg.Directory)
|
|
if err != nil {
|
|
slog.Warn("plugin: some plugin directories failed to scan and were skipped", "dir", r.cfg.Directory, "err", err)
|
|
}
|
|
for _, found := range manifests {
|
|
if err := r.installFromDisk(ctx, found); err != nil {
|
|
slog.Warn("plugin: failed to install from disk", "name", found.Manifest.Name, "err", err)
|
|
continue
|
|
}
|
|
}
|
|
return r.activateAll(ctx)
|
|
}
|
|
|
|
// installFromDisk persists a manifest discovered on disk into the PluginStore
|
|
// and registers it in the in-memory registry.
|
|
func (r *Registry) installFromDisk(ctx context.Context, found foundPlugin) error {
|
|
manifestJSON, err := found.Manifest.serialize()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
id, err := r.cfg.Store.InstallPlugin(ctx, found.Manifest.Name, found.Manifest.Version, manifestJSON)
|
|
if err != nil {
|
|
return fmt.Errorf("InstallPlugin: %w", err)
|
|
}
|
|
r.mu.Lock()
|
|
defer r.mu.Unlock()
|
|
// Re-install: tear down the old instance and drop its command bindings.
|
|
// Bindings are keyed to the old *Instance, so leaving them in place both
|
|
// blocked the fresh instance from re-registering its own commands and
|
|
// kept dispatch routing into the orphaned old module until restart.
|
|
if old := r.byName[found.Manifest.Name]; old != nil {
|
|
r.platformDeactivate(ctx, old)
|
|
for cmd, owner := range r.commands {
|
|
if owner == old {
|
|
delete(r.commands, cmd)
|
|
}
|
|
}
|
|
if old.ID != id {
|
|
delete(r.plugins, old.ID)
|
|
}
|
|
}
|
|
inst := &Instance{
|
|
ID: id,
|
|
Manifest: found.Manifest,
|
|
Dir: found.Dir,
|
|
WASMPath: found.WASMPath,
|
|
Enabled: false,
|
|
}
|
|
r.plugins[id] = inst
|
|
r.byName[found.Manifest.Name] = inst
|
|
return nil
|
|
}
|
|
|
|
// InstallFromZip extracts a plugin .zip uploaded via the admin API into a
|
|
// temp directory, validates it (zip-slip safe, no symlinks, size-capped),
|
|
// then renames it into the plugin directory and registers it via
|
|
// installFromDisk. Returns the new plugin name on success.
|
|
//
|
|
// The zip must contain a top-level plugin.json. The plugin's directory name
|
|
// is taken from manifest.Name (validated by Manifest.Validate to a strict
|
|
// charset). Re-installing an existing plugin replaces it.
|
|
const (
|
|
maxZipBytes = 16 * 1024 * 1024 // 16 MiB compressed
|
|
maxUncompressedSum = 64 * 1024 * 1024 // 64 MiB total uncompressed
|
|
)
|
|
|
|
func (r *Registry) InstallFromZip(ctx context.Context, zipBytes []byte) (string, error) {
|
|
if r == nil || r.cfg.Directory == "" {
|
|
return "", fmt.Errorf("plugin runtime not configured")
|
|
}
|
|
if int64(len(zipBytes)) > maxZipBytes {
|
|
return "", fmt.Errorf("plugin zip exceeds %d bytes", maxZipBytes)
|
|
}
|
|
zr, err := zip.NewReader(bytesReaderAt(zipBytes), int64(len(zipBytes)))
|
|
if err != nil {
|
|
return "", fmt.Errorf("invalid zip: %w", err)
|
|
}
|
|
|
|
// Stage 1: extract into a temp dir under the plugin directory.
|
|
if err := os.MkdirAll(r.cfg.Directory, 0o750); err != nil {
|
|
return "", fmt.Errorf("create plugin dir: %w", err)
|
|
}
|
|
stage, err := os.MkdirTemp(r.cfg.Directory, ".install-")
|
|
if err != nil {
|
|
return "", fmt.Errorf("create staging dir: %w", err)
|
|
}
|
|
cleanup := func() { _ = os.RemoveAll(stage) }
|
|
|
|
stageAbs, absErr := filepath.Abs(stage)
|
|
if absErr != nil {
|
|
cleanup()
|
|
return "", fmt.Errorf("abs staging dir: %w", absErr)
|
|
}
|
|
|
|
if err := installZipExtract(zr, stageAbs); err != nil {
|
|
cleanup()
|
|
return "", err
|
|
}
|
|
|
|
// Stage 2: parse the manifest now that the staging dir is fully populated.
|
|
manifest, err := installZipStagedManifest(stageAbs)
|
|
if err != nil {
|
|
cleanup()
|
|
return "", err
|
|
}
|
|
|
|
// Stage 3: atomically rename into the canonical plugin name directory.
|
|
finalDir := filepath.Join(r.cfg.Directory, manifest.Name)
|
|
if err := installZipPromote(stageAbs, finalDir); err != nil {
|
|
cleanup()
|
|
return "", err
|
|
}
|
|
|
|
// Stage 4: register via the existing on-disk install path.
|
|
if err := r.installFromDisk(ctx, foundPlugin{
|
|
Manifest: manifest,
|
|
Dir: finalDir,
|
|
WASMPath: filepath.Join(finalDir, manifest.Entrypoint),
|
|
}); err != nil {
|
|
return manifest.Name, fmt.Errorf("installFromDisk: %w", err)
|
|
}
|
|
|
|
r.installZipReactivate(ctx, manifest.Name)
|
|
return manifest.Name, nil
|
|
}
|
|
|
|
// installZipExtract writes every entry of zr into the already-created staging
|
|
// directory stageAbs, enforcing the zip-slip, symlink and uncompressed-size
|
|
// caps entry by entry before each write. The caller owns stageAbs and removes
|
|
// it on any error returned here.
|
|
func installZipExtract(zr *zip.Reader, stageAbs string) error {
|
|
var totalUncompressed int64
|
|
for _, f := range zr.File {
|
|
destAbs, entryErr := installZipEntryDest(f, stageAbs)
|
|
if entryErr != nil {
|
|
return entryErr
|
|
}
|
|
|
|
if f.Mode().IsDir() {
|
|
if err := os.MkdirAll(destAbs, 0o750); err != nil {
|
|
return err
|
|
}
|
|
continue
|
|
}
|
|
if err := os.MkdirAll(filepath.Dir(destAbs), 0o750); err != nil {
|
|
return err
|
|
}
|
|
// Cap each file at the remaining uncompressed budget so a zip bomb
|
|
// can't OOM the host.
|
|
remaining := maxUncompressedSum - totalUncompressed
|
|
n, writeErr := installZipWriteEntry(f, destAbs, remaining)
|
|
if writeErr != nil {
|
|
return writeErr
|
|
}
|
|
totalUncompressed += n
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// installZipEntryDest validates one zip entry's mode and name and returns the
|
|
// absolute path it may be written to under stageAbs. Every rejection here is a
|
|
// hard stop: non-regular modes, symlinks, and any name that escapes stageAbs.
|
|
func installZipEntryDest(f *zip.File, stageAbs string) (string, error) {
|
|
// Reject symlinks, devices, and any non-regular file mode.
|
|
if !f.Mode().IsRegular() && !f.Mode().IsDir() {
|
|
return "", fmt.Errorf("plugin zip: refusing non-regular entry %q (mode=%v)", f.Name, f.Mode())
|
|
}
|
|
if f.Mode()&os.ModeSymlink != 0 {
|
|
return "", fmt.Errorf("plugin zip: refusing symlink %q", f.Name)
|
|
}
|
|
// Reject zip-slip: cleaned absolute path must stay rooted at the
|
|
// staging directory.
|
|
clean := filepath.Clean(f.Name)
|
|
if strings.HasPrefix(clean, "..") || filepath.IsAbs(clean) || strings.Contains(clean, "..\\") {
|
|
return "", fmt.Errorf("plugin zip: refusing path-traversal entry %q", f.Name)
|
|
}
|
|
dest := filepath.Join(stageAbs, clean)
|
|
destAbs, dErr := filepath.Abs(dest)
|
|
if dErr != nil {
|
|
return "", dErr
|
|
}
|
|
rel, relErr := filepath.Rel(stageAbs, destAbs)
|
|
if relErr != nil || strings.HasPrefix(rel, "..") || filepath.IsAbs(rel) {
|
|
return "", fmt.Errorf("plugin zip: refusing escape %q", f.Name)
|
|
}
|
|
return destAbs, nil
|
|
}
|
|
|
|
// installZipWriteEntry copies one regular entry to destAbs, refusing to write
|
|
// more than remaining bytes — this entry's share of the maxUncompressedSum
|
|
// budget — and returns how many bytes it wrote.
|
|
func installZipWriteEntry(f *zip.File, destAbs string, remaining int64) (int64, error) {
|
|
rc, oErr := f.Open()
|
|
if oErr != nil {
|
|
return 0, oErr
|
|
}
|
|
out, cErr := os.OpenFile(destAbs, os.O_WRONLY|os.O_CREATE|os.O_TRUNC, 0o600)
|
|
if cErr != nil {
|
|
_ = rc.Close()
|
|
return 0, cErr
|
|
}
|
|
if remaining <= 0 {
|
|
_ = rc.Close()
|
|
_ = out.Close()
|
|
return 0, fmt.Errorf("plugin zip: uncompressed total exceeds %d bytes", maxUncompressedSum)
|
|
}
|
|
n, copyErr := io.CopyN(out, rc, remaining+1)
|
|
_ = rc.Close()
|
|
_ = out.Close()
|
|
if copyErr != nil && copyErr != io.EOF {
|
|
return 0, copyErr
|
|
}
|
|
if n > remaining {
|
|
return 0, fmt.Errorf("plugin zip: uncompressed total exceeds %d bytes", maxUncompressedSum)
|
|
}
|
|
return n, nil
|
|
}
|
|
|
|
// installZipStagedManifest parses the staged plugin.json and holds the staged
|
|
// tree to the same rules scanPluginDirectory applies to an on-disk plugin (no
|
|
// symlinks anywhere, entrypoint present and not a symlink).
|
|
func installZipStagedManifest(stageAbs string) (*Manifest, error) {
|
|
manifestPath := filepath.Join(stageAbs, "plugin.json")
|
|
raw, err := os.ReadFile(manifestPath)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("plugin zip: missing plugin.json at root: %w", err)
|
|
}
|
|
manifest, err := ParseManifest(raw)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
// Validate the staged contents the same way scanPluginDirectory does.
|
|
if err := rejectSymlinksUnder(stageAbs); err != nil {
|
|
return nil, err
|
|
}
|
|
wasmPath := filepath.Join(stageAbs, manifest.Entrypoint)
|
|
if info, statErr := os.Lstat(wasmPath); statErr != nil {
|
|
return nil, fmt.Errorf("entrypoint %s missing: %w", manifest.Entrypoint, statErr)
|
|
} else if info.Mode()&os.ModeSymlink != 0 {
|
|
return nil, fmt.Errorf("entrypoint %s is a symlink", manifest.Entrypoint)
|
|
}
|
|
return manifest, nil
|
|
}
|
|
|
|
// installZipPromote moves the fully validated staging directory into its
|
|
// canonical plugin-name directory.
|
|
func installZipPromote(stageAbs, finalDir string) error {
|
|
// If a previous version exists, remove it. The store row is replaced by
|
|
// installFromDisk via the existing UPSERT path.
|
|
if _, err := os.Stat(finalDir); err == nil {
|
|
if err := os.RemoveAll(finalDir); err != nil {
|
|
return fmt.Errorf("remove existing plugin dir: %w", err)
|
|
}
|
|
}
|
|
if err := os.Rename(stageAbs, finalDir); err != nil {
|
|
return fmt.Errorf("install rename: %w", err)
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// installZipReactivate restores the enabled state of a plugin that was already
|
|
// enabled before this upgrade.
|
|
//
|
|
// installFromDisk always registers the fresh instance as disabled and
|
|
// InstallPlugin's upsert never touches the `enabled` column, so a plugin
|
|
// that was enabled before this upgrade would otherwise come out the
|
|
// other side with the store row still saying enabled while the runtime
|
|
// instance sits inactive. LoadAll's startup path avoids this because it
|
|
// always runs activateAll afterward; this is the one caller of
|
|
// installFromDisk that doesn't, so it has to reactivate for itself.
|
|
// EnablePlugin already rolls the DB flag back if activation fails, so
|
|
// the two can no longer disagree.
|
|
func (r *Registry) installZipReactivate(ctx context.Context, name string) {
|
|
row, rowErr := r.cfg.Store.GetPluginByName(ctx, name)
|
|
if rowErr != nil || row == nil || !row.Enabled {
|
|
return
|
|
}
|
|
err := r.EnablePlugin(ctx, row.ID)
|
|
if err == nil {
|
|
return
|
|
}
|
|
if !errors.Is(err, ErrRuntimeUnavailable) {
|
|
slog.Warn("plugin: reactivate after upgrade failed", "name", name, "err", err)
|
|
return
|
|
}
|
|
// Default (non-wazero) build: nothing can activate here, and
|
|
// leaving EnablePlugin's rollback in place would persistently
|
|
// disable a plugin the admin left enabled — after a rebuild
|
|
// with -tags wazero it would silently stay off. Preserve the
|
|
// enabled intent instead; the next wazero-tagged start's
|
|
// activateAll does the real activation.
|
|
if reErr := r.cfg.Store.EnablePlugin(ctx, row.ID); reErr != nil {
|
|
slog.Warn("plugin: could not preserve enabled flag across runtime-less upgrade",
|
|
"name", name, "err", reErr)
|
|
return
|
|
}
|
|
r.mu.Lock()
|
|
if inst, ok := r.byName[name]; ok {
|
|
inst.Enabled = true
|
|
}
|
|
r.mu.Unlock()
|
|
slog.Info("plugin: runtime unavailable, enabled flag preserved across upgrade",
|
|
"name", name)
|
|
}
|
|
|
|
// bytesReaderAt is a tiny wrapper that satisfies io.ReaderAt for a byte
|
|
// slice. archive/zip needs ReaderAt; bytes.Reader provides it but importing
|
|
// "bytes" alongside the existing "io" surface keeps the import block tight.
|
|
type bytesReaderAt []byte
|
|
|
|
func (b bytesReaderAt) ReadAt(p []byte, off int64) (int, error) {
|
|
if off < 0 || off >= int64(len(b)) {
|
|
return 0, io.EOF
|
|
}
|
|
n := copy(p, b[off:])
|
|
if n < len(p) {
|
|
return n, io.EOF
|
|
}
|
|
return n, nil
|
|
}
|
|
|
|
// activateAll attempts to compile + register host-API hooks for every plugin
|
|
// row in the PluginStore that is marked enabled. The default build is a
|
|
// no-op (no Wazero modules to compile).
|
|
func (r *Registry) activateAll(ctx context.Context) error {
|
|
rows, err := r.cfg.Store.ListPlugins(ctx)
|
|
if err != nil {
|
|
return fmt.Errorf("ListPlugins: %w", err)
|
|
}
|
|
for _, row := range rows {
|
|
if !row.Enabled {
|
|
continue
|
|
}
|
|
r.mu.Lock()
|
|
inst, ok := r.byName[row.Name]
|
|
r.mu.Unlock()
|
|
if !ok {
|
|
slog.Warn("plugin: enabled row has no on-disk manifest, skipping", "name", row.Name)
|
|
continue
|
|
}
|
|
if err := r.activate(ctx, inst); err != nil {
|
|
slog.Warn("plugin: activation failed", "name", row.Name, "err", err)
|
|
continue
|
|
}
|
|
// Sync the in-memory enabled flag with the DB row so callers that
|
|
// read inst.Enabled (e.g. /api/v1/admin/plugins listings, future
|
|
// host-side capability checks) see the activated state.
|
|
r.mu.Lock()
|
|
inst.Enabled = true
|
|
r.mu.Unlock()
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// activate compiles and starts a single plugin module. Default build returns
|
|
// ErrRuntimeUnavailable; the wazero-tagged build replaces this with the real
|
|
// implementation via activateWithRuntime.
|
|
//
|
|
// The runtimePlatform read is guarded by r.mu so a concurrent Close() that
|
|
// nil-s the field cannot be observed mid-activation. The captured platform
|
|
// value is then passed into activateWithRuntime as a parameter so the actual
|
|
// compile uses the snapshot rather than re-reading r.runtimePlatform — this
|
|
// closes the race window between the nil check and the wazero call.
|
|
func (r *Registry) activate(ctx context.Context, inst *Instance) error {
|
|
r.mu.RLock()
|
|
platform := r.runtimePlatform
|
|
r.mu.RUnlock()
|
|
if platform == nil {
|
|
return ErrRuntimeUnavailable
|
|
}
|
|
return r.activateWithRuntime(ctx, platform, inst)
|
|
}
|
|
|
|
// EnablePlugin marks a plugin enabled in the store, then attempts to load it.
|
|
func (r *Registry) EnablePlugin(ctx context.Context, id int64) error {
|
|
if err := r.cfg.Store.EnablePlugin(ctx, id); err != nil {
|
|
return err
|
|
}
|
|
r.mu.RLock()
|
|
inst, ok := r.plugins[id]
|
|
r.mu.RUnlock()
|
|
if !ok {
|
|
// No in-memory instance to activate — roll the DB flag back so it
|
|
// doesn't stay stuck at enabled=1 with nothing backing it, the same
|
|
// way the activation-failure path below rolls back.
|
|
_ = r.cfg.Store.DisablePlugin(ctx, id)
|
|
return ErrPluginNotFound
|
|
}
|
|
r.mu.Lock()
|
|
inst.Enabled = true
|
|
r.mu.Unlock()
|
|
if err := r.activate(ctx, inst); err != nil {
|
|
// Roll back the DB flag and the in-memory flag so the next start
|
|
// attempt is consistent.
|
|
_ = r.cfg.Store.DisablePlugin(ctx, id)
|
|
r.mu.Lock()
|
|
inst.Enabled = false
|
|
r.mu.Unlock()
|
|
return err
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// DisablePlugin marks a plugin disabled and tears its module down. The
|
|
// wazero-tagged build frees the compiled module via platformDeactivate so
|
|
// re-enabling recompiles from disk; the default build is a no-op.
|
|
func (r *Registry) DisablePlugin(ctx context.Context, id int64) error {
|
|
if err := r.cfg.Store.DisablePlugin(ctx, id); err != nil {
|
|
return err
|
|
}
|
|
r.mu.Lock()
|
|
defer r.mu.Unlock()
|
|
if inst, ok := r.plugins[id]; ok {
|
|
inst.Enabled = false
|
|
// Drop command bindings owned by this plugin.
|
|
for cmd, owner := range r.commands {
|
|
if owner == inst {
|
|
delete(r.commands, cmd)
|
|
}
|
|
}
|
|
// Free the wazero module so memory is returned to the runtime
|
|
// immediately rather than waiting for registry Close. Safe to call
|
|
// on an instance that was never activated.
|
|
r.platformDeactivate(ctx, inst)
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// removeAll is os.RemoveAll indirected so tests can force a directory-removal
|
|
// failure deterministically. Windows silently succeeds at deleting read-only
|
|
// files (there's no portable, privilege-free way to make a real RemoveAll
|
|
// fail from a test), so this is the seam that lets the error-return path in
|
|
// UninstallPlugin be pinned.
|
|
var removeAll = os.RemoveAll
|
|
|
|
// UninstallPlugin removes a plugin entirely.
|
|
func (r *Registry) UninstallPlugin(ctx context.Context, id int64) error {
|
|
if err := r.DisablePlugin(ctx, id); err != nil {
|
|
slog.Warn("plugin: disable failed during uninstall", "id", id, "err", err)
|
|
}
|
|
|
|
// Capture the plugin's on-disk directory before removing the in-memory
|
|
// record so we can clean it up after the DB row is gone.
|
|
r.mu.RLock()
|
|
inst, instOK := r.plugins[id]
|
|
var pluginDir string
|
|
if instOK {
|
|
pluginDir = inst.Dir
|
|
}
|
|
r.mu.RUnlock()
|
|
|
|
if err := r.cfg.Store.UninstallPlugin(ctx, id); err != nil {
|
|
return err
|
|
}
|
|
|
|
r.mu.Lock()
|
|
if inst, ok := r.plugins[id]; ok {
|
|
delete(r.byName, inst.Manifest.Name)
|
|
}
|
|
delete(r.plugins, id)
|
|
r.mu.Unlock()
|
|
|
|
// Remove on-disk files so the plugin isn't resurrected on the next
|
|
// startup by scanPluginDirectory. The DB row and in-memory record are
|
|
// already gone at this point, so a removal failure is reported rather
|
|
// than swallowed — the caller needs to know the directory still has to
|
|
// be cleaned up by hand before the next restart, or scanPluginDirectory
|
|
// will bring the "uninstalled" plugin right back.
|
|
if pluginDir != "" {
|
|
if err := removeAll(pluginDir); err != nil {
|
|
slog.Warn("plugin: failed to remove plugin directory after uninstall", "dir", pluginDir, "err", err)
|
|
return fmt.Errorf("remove plugin dir: %w", err)
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// List returns the currently registered plugins. Read-only snapshot.
|
|
func (r *Registry) List() []*Instance {
|
|
r.mu.RLock()
|
|
defer r.mu.RUnlock()
|
|
out := make([]*Instance, 0, len(r.plugins))
|
|
for _, p := range r.plugins {
|
|
out = append(out, p)
|
|
}
|
|
return out
|
|
}
|
|
|
|
// UITabBindings returns the declared UI tabs across enabled plugins.
|
|
func (r *Registry) UITabBindings() []UITabBinding {
|
|
r.mu.RLock()
|
|
defer r.mu.RUnlock()
|
|
out := make([]UITabBinding, len(r.uiTabs))
|
|
copy(out, r.uiTabs)
|
|
return out
|
|
}
|