diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index cf1771d..784d851 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -13,17 +13,18 @@ jobs: strategy: matrix: os: [ubuntu-latest, macos-latest, windows-latest] + go-version: ['1.25'] runs-on: ${{ matrix.os }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Set up Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 + uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 with: - go-version-file: go.mod + go-version: ${{ matrix.go-version }} - name: Build run: go build -v ./... @@ -34,42 +35,14 @@ jobs: lint: runs-on: ubuntu-latest steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Set up Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 + uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 with: - go-version-file: go.mod + go-version: '1.25' - name: golangci-lint run: go tool golangci-lint run ./... - - helm: - name: Helm chart - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1 - with: - version: v3.18.6 - - - name: Lint chart - run: helm lint deploy/charts/proxy - - - name: Render chart variants - run: | - set -euo pipefail - helm template proxy deploy/charts/proxy >/dev/null - helm template proxy deploy/charts/proxy \ - --set persistence.enabled=false \ - --set config.existingConfigMap=proxy-config \ - --set ingress.enabled=true \ - --set 'ingress.hosts[0].host=proxy.example.com' \ - --set 'ingress.hosts[0].paths[0].path=/' \ - --set 'ingress.hosts[0].paths[0].pathType=Prefix' \ - >/dev/null diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 46f2059..554d98e 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -18,23 +18,14 @@ jobs: permissions: packages: write contents: read - id-token: write steps: - name: Check out the repo - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd with: persist-credentials: false - - name: Set up QEMU - uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4.3.0 - with: - platforms: linux/amd64,linux/arm64 - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - - name: Log in to the Container registry - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f + uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 with: registry: ghcr.io username: ${{ github.actor }} @@ -42,120 +33,14 @@ jobs: - name: Extract metadata (tags, labels) for Docker id: meta - uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 + uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf with: images: ghcr.io/${{ github.repository }} - - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 - - name: Build and push Docker image - id: build - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a + uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 with: context: . - platforms: linux/amd64,linux/arm64 push: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} - provenance: mode=max - sbom: true - - - name: Sign image by digest - env: - DIGEST: ${{ steps.build.outputs.digest }} - IMAGE: ghcr.io/${{ github.repository }} - run: | - set -euo pipefail - [[ "$DIGEST" =~ ^sha256:[0-9a-f]{64}$ ]] - cosign sign --yes "${IMAGE}@${DIGEST}" - - - name: Verify BuildKit attestations and extract SPDX predicates - env: - DIGEST: ${{ steps.build.outputs.digest }} - IMAGE: ghcr.io/${{ github.repository }} - run: | - set -euo pipefail - reference="${IMAGE}@${DIGEST}" - docker buildx imagetools inspect "$reference" --format '{{ json .Provenance }}' > provenance.json - docker buildx imagetools inspect "$reference" --format '{{ json .SBOM }}' > sbom.json - - for platform in linux/amd64 linux/arm64; do - jq -e --arg p "$platform" '.[$p].SLSA | type == "object" and length > 0' \ - provenance.json >/dev/null - jq -e --arg p "$platform" '.[$p].SPDX' sbom.json > "sbom-${platform//\//-}.spdx.json" - done - - - name: Attest platform SBOMs by digest - env: - DIGEST: ${{ steps.build.outputs.digest }} - IMAGE: ghcr.io/${{ github.repository }} - run: | - set -euo pipefail - [[ "$DIGEST" =~ ^sha256:[0-9a-f]{64}$ ]] - reference="${IMAGE}@${DIGEST}" - for predicate in sbom-linux-amd64.spdx.json sbom-linux-arm64.spdx.json; do - cosign attest --yes --type spdxjson --predicate "$predicate" "$reference" - done - - publish_chart: - name: Push Helm chart to GHCR - if: github.ref_type == 'tag' - needs: push_to_registry - runs-on: ubuntu-latest - permissions: - contents: read - packages: write - steps: - - name: Check out the repo - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 - with: - persist-credentials: false - ref: ${{ github.sha }} - - - uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1 - with: - version: v3.18.6 - - - name: Validate and normalize release version - id: version - env: - TAG: ${{ github.ref_name }} - run: | - set -euo pipefail - semver='^v(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)(-((0|[1-9][0-9]*|[0-9]*[A-Za-z-][0-9A-Za-z-]*)(\.(0|[1-9][0-9]*|[0-9]*[A-Za-z-][0-9A-Za-z-]*))*))?$' - [[ "$TAG" =~ $semver ]] || { - echo "Tag must be strict SemVer of the form vMAJOR.MINOR.PATCH[-PRERELEASE]: $TAG" >&2 - exit 1 - } - version="${TAG#v}" - [[ "$version" != "0.0.0" ]] || { - echo "0.0.0 is a development placeholder and must not be published" >&2 - exit 1 - } - echo "version=$version" >> "$GITHUB_OUTPUT" - - - name: Log in to GHCR - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: printf '%s' "$GH_TOKEN" | helm registry login ghcr.io --username "$GITHUB_ACTOR" --password-stdin - - - name: Lint and package chart - env: - VERSION: ${{ steps.version.outputs.version }} - run: | - set -euo pipefail - helm lint deploy/charts/proxy - mkdir -p build - helm package \ - --destination build \ - --version "$VERSION" \ - --app-version "$VERSION" \ - deploy/charts/proxy - metadata="$(helm show chart "build/proxy-${VERSION}.tgz")" - [[ "$(awk '$1 == "version:" {print $2}' <<<"$metadata")" == "$VERSION" ]] - [[ "$(awk '$1 == "appVersion:" {gsub(/\"/, "", $2); print $2}' <<<"$metadata")" == "$VERSION" ]] - - - name: Push chart - env: - VERSION: ${{ steps.version.outputs.version }} - run: helm push "build/proxy-${VERSION}.tgz" oci://ghcr.io/git-pkgs/charts diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 5d32181..f787509 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -14,20 +14,20 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: fetch-depth: 0 persist-credentials: false - - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 + - uses: sigstore/cosign-installer@cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003 # v4.1.1 - name: Set up Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 + uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 with: go-version-file: go.mod cache: false - - uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3 + - uses: goreleaser/goreleaser-action@ec59f474b9834571250b370d4735c50f8e2d1e29 # v7.0.0 with: version: "~> v2" args: release --clean diff --git a/.github/workflows/swagger.yml b/.github/workflows/swagger.yml index 38c42c3..6bc3514 100644 --- a/.github/workflows/swagger.yml +++ b/.github/workflows/swagger.yml @@ -12,14 +12,14 @@ jobs: swagger: runs-on: ubuntu-latest steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Set up Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 + uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 with: - go-version-file: go.mod + go-version: '1.25' - name: Install swag run: go install github.com/swaggo/swag/cmd/swag@latest diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index b32ce36..03ea882 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -21,9 +21,9 @@ jobs: security-events: write steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Run zizmor - uses: zizmorcore/zizmor-action@70fb788f84895a7701f5643d103d587e460b5c99 # v0.6.3 + uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2 diff --git a/.gitignore b/.gitignore index 86f77d1..6861411 100644 --- a/.gitignore +++ b/.gitignore @@ -4,7 +4,7 @@ *.dll *.so *.dylib -/proxy +proxy # Test binary, built with `go test -c` *.test @@ -14,8 +14,8 @@ coverage.html coverage.txt -# Go vendor directory (repo root only; embedded UI vendor dirs are tracked) -/vendor/ +# Dependency directories +vendor/ # Go workspace file go.work @@ -43,4 +43,4 @@ cache/* # Debug files __debug_bin -debug +debug \ No newline at end of file diff --git a/.golangci.yml b/.golangci.yml deleted file mode 100644 index 9d4b957..0000000 --- a/.golangci.yml +++ /dev/null @@ -1,28 +0,0 @@ -version: "2" - -linters: - enable: - - gocritic - - gocognit - - gocyclo - - maintidx - - dupl - - mnd - - unparam - - ireturn - - goconst - - errcheck - settings: - goconst: - min-len: 4 - min-occurrences: 5 - ignore-tests: true - ignore-string-values: - - "^[a-z]+$" - exclusions: - rules: - - path: _test\.go - linters: - - goconst - - dupl - - mnd diff --git a/.goreleaser.yaml b/.goreleaser.yaml index e5881db..b6256de 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -36,10 +36,11 @@ checksum: signs: - cmd: cosign - signature: "${artifact}.cosign.bundle" + certificate: "${artifact}.pem" args: - sign-blob - - "--bundle=${signature}" + - "--output-certificate=${certificate}" + - "--output-signature=${signature}" - "${artifact}" - "--yes" artifacts: checksum diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 68a6acf..88ad1cb 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -39,7 +39,7 @@ proxy/ │ │ └── queries.go # CRUD operations │ ├── storage/ # Artifact file storage │ │ ├── storage.go # Storage interface -│ │ └── blob.go # gocloud.dev/blob backends (file, S3, Azure) +│ │ └── filesystem.go # Local filesystem impl │ ├── upstream/ # Upstream registry clients │ │ ├── fetcher.go # HTTP artifact fetching │ │ └── resolver.go # Download URL resolution @@ -72,7 +72,7 @@ Key types: ### `internal/storage` -Artifact file storage abstraction backed by `gocloud.dev/blob`. Supports local filesystem (`file://`), S3 (`s3://`), and Azure (`azblob://`) URLs. +Artifact file storage abstraction. Currently implements local filesystem storage. Designed to allow future backends (S3, GCS). Interface: ```go diff --git a/Dockerfile b/Dockerfile index 4b0c5d2..71a9fcc 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM --platform=$BUILDPLATFORM golang:1.26.7-alpine AS builder +FROM golang:1.25-alpine AS builder WORKDIR /src @@ -12,11 +12,10 @@ RUN go mod download # Copy source code COPY . . -# Build the binary for the target platform -ARG TARGETARCH -RUN CGO_ENABLED=0 GOOS=linux GOARCH=${TARGETARCH} go build -ldflags="-s -w" -o /proxy ./cmd/proxy +# Build the binary +RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w" -o /proxy ./cmd/proxy -FROM alpine:3.24.1 +FROM alpine:3.21 RUN apk add --no-cache ca-certificates diff --git a/LICENSE b/LICENSE deleted file mode 100644 index f6cdd22..0000000 --- a/LICENSE +++ /dev/null @@ -1,232 +0,0 @@ -GNU GENERAL PUBLIC LICENSE -Version 3, 29 June 2007 - -Copyright © 2007 Free Software Foundation, Inc. - -Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed. - -Preamble - -The GNU General Public License is a free, copyleft license for software and other kinds of works. - -The licenses for most software and other practical works are designed to take away your freedom to share and change the works. By contrast, the GNU General Public License is intended to guarantee your freedom to share and change all versions of a program--to make sure it remains free software for all its users. We, the Free Software Foundation, use the GNU General Public License for most of our software; it applies also to any other work released this way by its authors. You can apply it to your programs, too. - -When we speak of free software, we are referring to freedom, not price. Our General Public Licenses are designed to make sure that you have the freedom to distribute copies of free software (and charge for them if you wish), that you receive source code or can get it if you want it, that you can change the software or use pieces of it in new free programs, and that you know you can do these things. - -To protect your rights, we need to prevent others from denying you these rights or asking you to surrender the rights. Therefore, you have certain responsibilities if you distribute copies of the software, or if you modify it: responsibilities to respect the freedom of others. - -For example, if you distribute copies of such a program, whether gratis or for a fee, you must pass on to the recipients the same freedoms that you received. You must make sure that they, too, receive or can get the source code. And you must show them these terms so they know their rights. - -Developers that use the GNU GPL protect your rights with two steps: (1) assert copyright on the software, and (2) offer you this License giving you legal permission to copy, distribute and/or modify it. - -For the developers' and authors' protection, the GPL clearly explains that there is no warranty for this free software. For both users' and authors' sake, the GPL requires that modified versions be marked as changed, so that their problems will not be attributed erroneously to authors of previous versions. - -Some devices are designed to deny users access to install or run modified versions of the software inside them, although the manufacturer can do so. This is fundamentally incompatible with the aim of protecting users' freedom to change the software. The systematic pattern of such abuse occurs in the area of products for individuals to use, which is precisely where it is most unacceptable. Therefore, we have designed this version of the GPL to prohibit the practice for those products. If such problems arise substantially in other domains, we stand ready to extend this provision to those domains in future versions of the GPL, as needed to protect the freedom of users. - -Finally, every program is threatened constantly by software patents. States should not allow patents to restrict development and use of software on general-purpose computers, but in those that do, we wish to avoid the special danger that patents applied to a free program could make it effectively proprietary. To prevent this, the GPL assures that patents cannot be used to render the program non-free. - -The precise terms and conditions for copying, distribution and modification follow. - -TERMS AND CONDITIONS - -0. Definitions. - -“This License” refers to version 3 of the GNU General Public License. - -“Copyright” also means copyright-like laws that apply to other kinds of works, such as semiconductor masks. - -“The Program” refers to any copyrightable work licensed under this License. Each licensee is addressed as “you”. “Licensees” and “recipients” may be individuals or organizations. - -To “modify” a work means to copy from or adapt all or part of the work in a fashion requiring copyright permission, other than the making of an exact copy. The resulting work is called a “modified version” of the earlier work or a work “based on” the earlier work. - -A “covered work” means either the unmodified Program or a work based on the Program. - -To “propagate” a work means to do anything with it that, without permission, would make you directly or secondarily liable for infringement under applicable copyright law, except executing it on a computer or modifying a private copy. Propagation includes copying, distribution (with or without modification), making available to the public, and in some countries other activities as well. - -To “convey” a work means any kind of propagation that enables other parties to make or receive copies. Mere interaction with a user through a computer network, with no transfer of a copy, is not conveying. - -An interactive user interface displays “Appropriate Legal Notices” to the extent that it includes a convenient and prominently visible feature that (1) displays an appropriate copyright notice, and (2) tells the user that there is no warranty for the work (except to the extent that warranties are provided), that licensees may convey the work under this License, and how to view a copy of this License. If the interface presents a list of user commands or options, such as a menu, a prominent item in the list meets this criterion. - -1. Source Code. -The “source code” for a work means the preferred form of the work for making modifications to it. “Object code” means any non-source form of a work. - -A “Standard Interface” means an interface that either is an official standard defined by a recognized standards body, or, in the case of interfaces specified for a particular programming language, one that is widely used among developers working in that language. - -The “System Libraries” of an executable work include anything, other than the work as a whole, that (a) is included in the normal form of packaging a Major Component, but which is not part of that Major Component, and (b) serves only to enable use of the work with that Major Component, or to implement a Standard Interface for which an implementation is available to the public in source code form. A “Major Component”, in this context, means a major essential component (kernel, window system, and so on) of the specific operating system (if any) on which the executable work runs, or a compiler used to produce the work, or an object code interpreter used to run it. - -The “Corresponding Source” for a work in object code form means all the source code needed to generate, install, and (for an executable work) run the object code and to modify the work, including scripts to control those activities. However, it does not include the work's System Libraries, or general-purpose tools or generally available free programs which are used unmodified in performing those activities but which are not part of the work. For example, Corresponding Source includes interface definition files associated with source files for the work, and the source code for shared libraries and dynamically linked subprograms that the work is specifically designed to require, such as by intimate data communication or control flow between those subprograms and other parts of the work. - -The Corresponding Source need not include anything that users can regenerate automatically from other parts of the Corresponding Source. - -The Corresponding Source for a work in source code form is that same work. - -2. Basic Permissions. -All rights granted under this License are granted for the term of copyright on the Program, and are irrevocable provided the stated conditions are met. This License explicitly affirms your unlimited permission to run the unmodified Program. The output from running a covered work is covered by this License only if the output, given its content, constitutes a covered work. This License acknowledges your rights of fair use or other equivalent, as provided by copyright law. - -You may make, run and propagate covered works that you do not convey, without conditions so long as your license otherwise remains in force. You may convey covered works to others for the sole purpose of having them make modifications exclusively for you, or provide you with facilities for running those works, provided that you comply with the terms of this License in conveying all material for which you do not control copyright. Those thus making or running the covered works for you must do so exclusively on your behalf, under your direction and control, on terms that prohibit them from making any copies of your copyrighted material outside their relationship with you. - -Conveying under any other circumstances is permitted solely under the conditions stated below. Sublicensing is not allowed; section 10 makes it unnecessary. - -3. Protecting Users' Legal Rights From Anti-Circumvention Law. -No covered work shall be deemed part of an effective technological measure under any applicable law fulfilling obligations under article 11 of the WIPO copyright treaty adopted on 20 December 1996, or similar laws prohibiting or restricting circumvention of such measures. - -When you convey a covered work, you waive any legal power to forbid circumvention of technological measures to the extent such circumvention is effected by exercising rights under this License with respect to the covered work, and you disclaim any intention to limit operation or modification of the work as a means of enforcing, against the work's users, your or third parties' legal rights to forbid circumvention of technological measures. - -4. Conveying Verbatim Copies. -You may convey verbatim copies of the Program's source code as you receive it, in any medium, provided that you conspicuously and appropriately publish on each copy an appropriate copyright notice; keep intact all notices stating that this License and any non-permissive terms added in accord with section 7 apply to the code; keep intact all notices of the absence of any warranty; and give all recipients a copy of this License along with the Program. - -You may charge any price or no price for each copy that you convey, and you may offer support or warranty protection for a fee. - -5. Conveying Modified Source Versions. -You may convey a work based on the Program, or the modifications to produce it from the Program, in the form of source code under the terms of section 4, provided that you also meet all of these conditions: - - a) The work must carry prominent notices stating that you modified it, and giving a relevant date. - - b) The work must carry prominent notices stating that it is released under this License and any conditions added under section 7. This requirement modifies the requirement in section 4 to “keep intact all notices”. - - c) You must license the entire work, as a whole, under this License to anyone who comes into possession of a copy. This License will therefore apply, along with any applicable section 7 additional terms, to the whole of the work, and all its parts, regardless of how they are packaged. This License gives no permission to license the work in any other way, but it does not invalidate such permission if you have separately received it. - - d) If the work has interactive user interfaces, each must display Appropriate Legal Notices; however, if the Program has interactive interfaces that do not display Appropriate Legal Notices, your work need not make them do so. - -A compilation of a covered work with other separate and independent works, which are not by their nature extensions of the covered work, and which are not combined with it such as to form a larger program, in or on a volume of a storage or distribution medium, is called an “aggregate” if the compilation and its resulting copyright are not used to limit the access or legal rights of the compilation's users beyond what the individual works permit. Inclusion of a covered work in an aggregate does not cause this License to apply to the other parts of the aggregate. - -6. Conveying Non-Source Forms. -You may convey a covered work in object code form under the terms of sections 4 and 5, provided that you also convey the machine-readable Corresponding Source under the terms of this License, in one of these ways: - - a) Convey the object code in, or embodied in, a physical product (including a physical distribution medium), accompanied by the Corresponding Source fixed on a durable physical medium customarily used for software interchange. - - b) Convey the object code in, or embodied in, a physical product (including a physical distribution medium), accompanied by a written offer, valid for at least three years and valid for as long as you offer spare parts or customer support for that product model, to give anyone who possesses the object code either (1) a copy of the Corresponding Source for all the software in the product that is covered by this License, on a durable physical medium customarily used for software interchange, for a price no more than your reasonable cost of physically performing this conveying of source, or (2) access to copy the Corresponding Source from a network server at no charge. - - c) Convey individual copies of the object code with a copy of the written offer to provide the Corresponding Source. This alternative is allowed only occasionally and noncommercially, and only if you received the object code with such an offer, in accord with subsection 6b. - - d) Convey the object code by offering access from a designated place (gratis or for a charge), and offer equivalent access to the Corresponding Source in the same way through the same place at no further charge. You need not require recipients to copy the Corresponding Source along with the object code. If the place to copy the object code is a network server, the Corresponding Source may be on a different server (operated by you or a third party) that supports equivalent copying facilities, provided you maintain clear directions next to the object code saying where to find the Corresponding Source. Regardless of what server hosts the Corresponding Source, you remain obligated to ensure that it is available for as long as needed to satisfy these requirements. - - e) Convey the object code using peer-to-peer transmission, provided you inform other peers where the object code and Corresponding Source of the work are being offered to the general public at no charge under subsection 6d. - -A separable portion of the object code, whose source code is excluded from the Corresponding Source as a System Library, need not be included in conveying the object code work. - -A “User Product” is either (1) a “consumer product”, which means any tangible personal property which is normally used for personal, family, or household purposes, or (2) anything designed or sold for incorporation into a dwelling. In determining whether a product is a consumer product, doubtful cases shall be resolved in favor of coverage. For a particular product received by a particular user, “normally used” refers to a typical or common use of that class of product, regardless of the status of the particular user or of the way in which the particular user actually uses, or expects or is expected to use, the product. A product is a consumer product regardless of whether the product has substantial commercial, industrial or non-consumer uses, unless such uses represent the only significant mode of use of the product. - -“Installation Information” for a User Product means any methods, procedures, authorization keys, or other information required to install and execute modified versions of a covered work in that User Product from a modified version of its Corresponding Source. The information must suffice to ensure that the continued functioning of the modified object code is in no case prevented or interfered with solely because modification has been made. - -If you convey an object code work under this section in, or with, or specifically for use in, a User Product, and the conveying occurs as part of a transaction in which the right of possession and use of the User Product is transferred to the recipient in perpetuity or for a fixed term (regardless of how the transaction is characterized), the Corresponding Source conveyed under this section must be accompanied by the Installation Information. But this requirement does not apply if neither you nor any third party retains the ability to install modified object code on the User Product (for example, the work has been installed in ROM). - -The requirement to provide Installation Information does not include a requirement to continue to provide support service, warranty, or updates for a work that has been modified or installed by the recipient, or for the User Product in which it has been modified or installed. Access to a network may be denied when the modification itself materially and adversely affects the operation of the network or violates the rules and protocols for communication across the network. - -Corresponding Source conveyed, and Installation Information provided, in accord with this section must be in a format that is publicly documented (and with an implementation available to the public in source code form), and must require no special password or key for unpacking, reading or copying. - -7. Additional Terms. -“Additional permissions” are terms that supplement the terms of this License by making exceptions from one or more of its conditions. Additional permissions that are applicable to the entire Program shall be treated as though they were included in this License, to the extent that they are valid under applicable law. If additional permissions apply only to part of the Program, that part may be used separately under those permissions, but the entire Program remains governed by this License without regard to the additional permissions. - -When you convey a copy of a covered work, you may at your option remove any additional permissions from that copy, or from any part of it. (Additional permissions may be written to require their own removal in certain cases when you modify the work.) You may place additional permissions on material, added by you to a covered work, for which you have or can give appropriate copyright permission. - -Notwithstanding any other provision of this License, for material you add to a covered work, you may (if authorized by the copyright holders of that material) supplement the terms of this License with terms: - - a) Disclaiming warranty or limiting liability differently from the terms of sections 15 and 16 of this License; or - - b) Requiring preservation of specified reasonable legal notices or author attributions in that material or in the Appropriate Legal Notices displayed by works containing it; or - - c) Prohibiting misrepresentation of the origin of that material, or requiring that modified versions of such material be marked in reasonable ways as different from the original version; or - - d) Limiting the use for publicity purposes of names of licensors or authors of the material; or - - e) Declining to grant rights under trademark law for use of some trade names, trademarks, or service marks; or - - f) Requiring indemnification of licensors and authors of that material by anyone who conveys the material (or modified versions of it) with contractual assumptions of liability to the recipient, for any liability that these contractual assumptions directly impose on those licensors and authors. - -All other non-permissive additional terms are considered “further restrictions” within the meaning of section 10. If the Program as you received it, or any part of it, contains a notice stating that it is governed by this License along with a term that is a further restriction, you may remove that term. If a license document contains a further restriction but permits relicensing or conveying under this License, you may add to a covered work material governed by the terms of that license document, provided that the further restriction does not survive such relicensing or conveying. - -If you add terms to a covered work in accord with this section, you must place, in the relevant source files, a statement of the additional terms that apply to those files, or a notice indicating where to find the applicable terms. - -Additional terms, permissive or non-permissive, may be stated in the form of a separately written license, or stated as exceptions; the above requirements apply either way. - -8. Termination. -You may not propagate or modify a covered work except as expressly provided under this License. Any attempt otherwise to propagate or modify it is void, and will automatically terminate your rights under this License (including any patent licenses granted under the third paragraph of section 11). - -However, if you cease all violation of this License, then your license from a particular copyright holder is reinstated (a) provisionally, unless and until the copyright holder explicitly and finally terminates your license, and (b) permanently, if the copyright holder fails to notify you of the violation by some reasonable means prior to 60 days after the cessation. - -Moreover, your license from a particular copyright holder is reinstated permanently if the copyright holder notifies you of the violation by some reasonable means, this is the first time you have received notice of violation of this License (for any work) from that copyright holder, and you cure the violation prior to 30 days after your receipt of the notice. - -Termination of your rights under this section does not terminate the licenses of parties who have received copies or rights from you under this License. If your rights have been terminated and not permanently reinstated, you do not qualify to receive new licenses for the same material under section 10. - -9. Acceptance Not Required for Having Copies. -You are not required to accept this License in order to receive or run a copy of the Program. Ancillary propagation of a covered work occurring solely as a consequence of using peer-to-peer transmission to receive a copy likewise does not require acceptance. However, nothing other than this License grants you permission to propagate or modify any covered work. These actions infringe copyright if you do not accept this License. Therefore, by modifying or propagating a covered work, you indicate your acceptance of this License to do so. - -10. Automatic Licensing of Downstream Recipients. -Each time you convey a covered work, the recipient automatically receives a license from the original licensors, to run, modify and propagate that work, subject to this License. You are not responsible for enforcing compliance by third parties with this License. - -An “entity transaction” is a transaction transferring control of an organization, or substantially all assets of one, or subdividing an organization, or merging organizations. If propagation of a covered work results from an entity transaction, each party to that transaction who receives a copy of the work also receives whatever licenses to the work the party's predecessor in interest had or could give under the previous paragraph, plus a right to possession of the Corresponding Source of the work from the predecessor in interest, if the predecessor has it or can get it with reasonable efforts. - -You may not impose any further restrictions on the exercise of the rights granted or affirmed under this License. For example, you may not impose a license fee, royalty, or other charge for exercise of rights granted under this License, and you may not initiate litigation (including a cross-claim or counterclaim in a lawsuit) alleging that any patent claim is infringed by making, using, selling, offering for sale, or importing the Program or any portion of it. - -11. Patents. -A “contributor” is a copyright holder who authorizes use under this License of the Program or a work on which the Program is based. The work thus licensed is called the contributor's “contributor version”. - -A contributor's “essential patent claims” are all patent claims owned or controlled by the contributor, whether already acquired or hereafter acquired, that would be infringed by some manner, permitted by this License, of making, using, or selling its contributor version, but do not include claims that would be infringed only as a consequence of further modification of the contributor version. For purposes of this definition, “control” includes the right to grant patent sublicenses in a manner consistent with the requirements of this License. - -Each contributor grants you a non-exclusive, worldwide, royalty-free patent license under the contributor's essential patent claims, to make, use, sell, offer for sale, import and otherwise run, modify and propagate the contents of its contributor version. - -In the following three paragraphs, a “patent license” is any express agreement or commitment, however denominated, not to enforce a patent (such as an express permission to practice a patent or covenant not to sue for patent infringement). To “grant” such a patent license to a party means to make such an agreement or commitment not to enforce a patent against the party. - -If you convey a covered work, knowingly relying on a patent license, and the Corresponding Source of the work is not available for anyone to copy, free of charge and under the terms of this License, through a publicly available network server or other readily accessible means, then you must either (1) cause the Corresponding Source to be so available, or (2) arrange to deprive yourself of the benefit of the patent license for this particular work, or (3) arrange, in a manner consistent with the requirements of this License, to extend the patent license to downstream recipients. “Knowingly relying” means you have actual knowledge that, but for the patent license, your conveying the covered work in a country, or your recipient's use of the covered work in a country, would infringe one or more identifiable patents in that country that you have reason to believe are valid. - -If, pursuant to or in connection with a single transaction or arrangement, you convey, or propagate by procuring conveyance of, a covered work, and grant a patent license to some of the parties receiving the covered work authorizing them to use, propagate, modify or convey a specific copy of the covered work, then the patent license you grant is automatically extended to all recipients of the covered work and works based on it. - -A patent license is “discriminatory” if it does not include within the scope of its coverage, prohibits the exercise of, or is conditioned on the non-exercise of one or more of the rights that are specifically granted under this License. You may not convey a covered work if you are a party to an arrangement with a third party that is in the business of distributing software, under which you make payment to the third party based on the extent of your activity of conveying the work, and under which the third party grants, to any of the parties who would receive the covered work from you, a discriminatory patent license (a) in connection with copies of the covered work conveyed by you (or copies made from those copies), or (b) primarily for and in connection with specific products or compilations that contain the covered work, unless you entered into that arrangement, or that patent license was granted, prior to 28 March 2007. - -Nothing in this License shall be construed as excluding or limiting any implied license or other defenses to infringement that may otherwise be available to you under applicable patent law. - -12. No Surrender of Others' Freedom. -If conditions are imposed on you (whether by court order, agreement or otherwise) that contradict the conditions of this License, they do not excuse you from the conditions of this License. If you cannot convey a covered work so as to satisfy simultaneously your obligations under this License and any other pertinent obligations, then as a consequence you may not convey it at all. For example, if you agree to terms that obligate you to collect a royalty for further conveying from those to whom you convey the Program, the only way you could satisfy both those terms and this License would be to refrain entirely from conveying the Program. - -13. Use with the GNU Affero General Public License. -Notwithstanding any other provision of this License, you have permission to link or combine any covered work with a work licensed under version 3 of the GNU Affero General Public License into a single combined work, and to convey the resulting work. The terms of this License will continue to apply to the part which is the covered work, but the special requirements of the GNU Affero General Public License, section 13, concerning interaction through a network will apply to the combination as such. - -14. Revised Versions of this License. -The Free Software Foundation may publish revised and/or new versions of the GNU General Public License from time to time. Such new versions will be similar in spirit to the present version, but may differ in detail to address new problems or concerns. - -Each version is given a distinguishing version number. If the Program specifies that a certain numbered version of the GNU General Public License “or any later version” applies to it, you have the option of following the terms and conditions either of that numbered version or of any later version published by the Free Software Foundation. If the Program does not specify a version number of the GNU General Public License, you may choose any version ever published by the Free Software Foundation. - -If the Program specifies that a proxy can decide which future versions of the GNU General Public License can be used, that proxy's public statement of acceptance of a version permanently authorizes you to choose that version for the Program. - -Later license versions may give you additional or different permissions. However, no additional obligations are imposed on any author or copyright holder as a result of your choosing to follow a later version. - -15. Disclaimer of Warranty. -THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. - -16. Limitation of Liability. -IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. - -17. Interpretation of Sections 15 and 16. -If the disclaimer of warranty and limitation of liability provided above cannot be given local legal effect according to their terms, reviewing courts shall apply local law that most closely approximates an absolute waiver of all civil liability in connection with the Program, unless a warranty or assumption of liability accompanies a copy of the Program in return for a fee. - -END OF TERMS AND CONDITIONS - -How to Apply These Terms to Your New Programs - -If you develop a new program, and you want it to be of the greatest possible use to the public, the best way to achieve this is to make it free software which everyone can redistribute and change under these terms. - -To do so, attach the following notices to the program. It is safest to attach them to the start of each source file to most effectively state the exclusion of warranty; and each file should have at least the “copyright” line and a pointer to where the full notice is found. - - - Copyright (C) - - This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. - - This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. - - You should have received a copy of the GNU General Public License along with this program. If not, see . - -Also add information on how to contact you by electronic and paper mail. - -If the program does terminal interaction, make it output a short notice like this when it starts in an interactive mode: - - Copyright (C) - This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'. - This is free software, and you are welcome to redistribute it under certain conditions; type `show c' for details. - -The hypothetical commands `show w' and `show c' should show the appropriate parts of the General Public License. Of course, your program's commands might be different; for a GUI interface, you would use an “about box”. - -You should also get your employer (if you work as a programmer) or school, if any, to sign a “copyright disclaimer” for the program, if necessary. For more information on this, and how to apply and follow the GNU GPL, see . - -The GNU General Public License does not permit incorporating your program into proprietary programs. If your program is a subroutine library, you may consider it more useful to permit linking proprietary applications with the library. If this is what you want to do, use the GNU Lesser General Public License instead of this License. But first, please read . diff --git a/README.md b/README.md index 7d374bd..40ee5b5 100644 --- a/README.md +++ b/README.md @@ -20,26 +20,6 @@ A 3-day cooldown means that when `lodash` publishes version `4.18.0`, your build Resolution order: package override, then ecosystem override, then global default. This lets you set a conservative default and carve out exceptions for packages where you need faster updates. See [docs/configuration.md](docs/configuration.md) for the full config reference. -## Artifact Scanning - -Cooldown only looks at a version's publish timestamp — it never inspects the actual bytes. Artifact scanning closes that gap: when enabled, every artifact is staged into storage and scanned by one or more external services (trivy, ClamAV, Wiz, or anything else that speaks a small HTTP/JSON contract) before it's committed to the cache and served to clients. - -```yaml -scanning: - enabled: true - signing_key: ${PROXY_SCANNING_SIGNING_KEY} - scanners: - - name: clamav - url: http://clamav-adapter:8080/scan - mode: block # a block verdict deletes the artifact and returns 403 - - name: trivy - url: http://trivy-adapter:8081/scan - mode: monitor # findings are logged, never gate caching - ecosystems: [npm, pypi] -``` - -The proxy never uploads artifact bytes to a scanner. Each scanner is notified with package metadata plus a short-lived signed URL; the scanner pulls the bytes itself from the proxy's own storage. Scanners run concurrently, and the first `block`-mode scanner to report a verdict of not-allowed wins immediately, canceling the rest. See [docs/configuration.md](docs/configuration.md) for the full config reference and the scanner HTTP contract. - ## Supported Registries | Registry | Language/Platform | Cooldown | Completed | @@ -52,52 +32,26 @@ The proxy never uploads artifact bytes to a scanner. Each scanner is notified wi | pub.dev | Dart | Yes | ✓ | | PyPI | Python | Yes | ✓ | | Maven | Java | | ✓ | -| Gradle Build Cache | Java/Kotlin | | ✓ | | NuGet | .NET | Yes | ✓ | | Composer | PHP | Yes | ✓ | | Conan | C/C++ | | ✓ | | Conda | Python/R | Yes | ✓ | | CRAN | R | | ✓ | -| Julia | Julia | | ✓ | -| Swift | Swift | | ✓ | | Container | Docker/OCI | | ✓ | -| Homebrew | macOS/Linux | | ✓ | | Debian | Debian/Ubuntu | | ✓ | | RPM | RHEL/Fedora | | ✓ | -| Alpine | Alpine Linux | | ✓ | +| Alpine | Alpine Linux | | ✗ | | Arch | Arch Linux | | ✗ | | Chef | Chef | | ✗ | -| Generic | Any | | ✓ | -| Helm | Kubernetes | | ✓ | +| Generic | Any | | ✗ | +| Helm | Kubernetes | | ✗ | +| Swift | Swift | | ✗ | | Vagrant | Vagrant | | ✗ | Cooldown requires publish timestamps in metadata. Registries without a "Yes" in the cooldown column either don't expose timestamps or haven't been wired up yet. \* Hex cooldown requires disabling registry signature verification (`HEX_NO_VERIFY_REPO_ORIGIN=1`) since the proxy re-encodes the protobuf payload. -## Install - -```bash -brew install git-pkgs/git-pkgs/proxy -``` - -Or download a binary from the [releases page](https://github.com/git-pkgs/proxy/releases). - -### Helm - -Install the chart from GHCR, setting the public URL that package-manager clients -will use to reach the proxy: - -```bash -helm install proxy oci://ghcr.io/git-pkgs/charts/proxy \ - --set config.data.base_url=https://proxy.example.com -``` - -The default chart deploys one replica backed by a 10 GiB persistent volume, -using SQLite and filesystem artifact storage under `/data`. See -[`deploy/charts/proxy/values.yaml`](deploy/charts/proxy/values.yaml) for ingress, -external database and object-storage configuration options. - ## Quick Start ```bash @@ -193,29 +147,6 @@ export GOPROXY=http://localhost:8080/go,direct Or in your shell profile for persistence. -### Homebrew - -Point Homebrew's JSON API and artifact domain at the proxy: - -```bash -export HOMEBREW_API_DOMAIN=http://localhost:8080/homebrew -export HOMEBREW_ARTIFACT_DOMAIN=http://localhost:8080 -``` - -The artifact domain proxies manifests and bottle blobs under `/v2/homebrew/core/`. GHCR routing is limited to that repository. Source archives, cask application downloads, custom tap artifacts, and legacy flat-file bottle mirrors use Homebrew's normal fallback URLs. Keep fallback enabled by leaving `HOMEBREW_ARTIFACT_DOMAIN_NO_FALLBACK` unset. - -Enable `cache_metadata` or set `PROXY_CACHE_METADATA=true` to retain Homebrew JSON API responses for offline fallback. Bottle blobs and their OCI manifests are cached without this setting. - -The upstreams default to `https://formulae.brew.sh/api` for the JSON API and `https://ghcr.io` for artifacts. To chain this proxy to another proxy, configure its Homebrew endpoints as the upstreams: - -```yaml -upstream: - homebrew_api: "https://upstream-proxy.example.com/homebrew" - homebrew_artifact: "https://upstream-proxy.example.com" -``` - -The equivalent environment variables are `PROXY_UPSTREAM_HOMEBREW_API` and `PROXY_UPSTREAM_HOMEBREW_ARTIFACT`. - ### Hex (Elixir) Configure in `~/.hex/hex.config`: @@ -269,34 +200,6 @@ Add to your `~/.m2/settings.xml`: ``` -The `/maven/` endpoint uses Maven Central as primary upstream and falls back to the Gradle Plugin Portal for Gradle plugin marker metadata and related artifacts when the primary upstream returns not found. - -For Gradle plugin resolution via the same proxy endpoint: - -```kotlin -pluginManagement { - repositories { - maven(url = "http://localhost:8080/maven/") - } -} -``` - -### Gradle HTTP Build Cache - -Configure in `settings.gradle(.kts)`: - -```kotlin -buildCache { - local { - enabled = false - } - remote { - url = uri("http://localhost:8080/gradle/") - push = true - } -} -``` - ### NuGet Configure in `nuget.config`: @@ -384,40 +287,6 @@ local({ }) ``` -### Julia - -Set the Pkg server before starting Julia: - -```bash -export JULIA_PKG_SERVER=http://localhost:8080/julia -``` - -Or inside a running session: - -```julia -ENV["JULIA_PKG_SERVER"] = "http://localhost:8080/julia" -using Pkg; Pkg.update() -``` - -### Swift - -Configure the proxy as the default registry for the current Swift package: - -```bash -swift package-registry set --allow-insecure-http http://localhost:8080/swift -``` - -Registry dependencies use their scoped package identifier in `Package.swift`: - -```swift -dependencies: [ - .package(id: "apple.swift-argument-parser", from: "1.2.0") -] -``` - -The proxy supports dependency resolution and source downloads. Publishing with -`swift package-registry publish` is not supported. - ### Docker / Container Registry Configure Docker to use the proxy as a registry mirror in `/etc/docker/daemon.json`: @@ -440,39 +309,6 @@ Or pull images directly: docker pull localhost:8080/library/nginx:latest ``` -### Helm - -Configure each HTTP chart repository with a name, then add the matching proxy -URL to Helm: - -```yaml -upstream: - helm: - bitnami: "https://charts.bitnami.com/bitnami" -``` - -```bash -helm repo add bitnami http://localhost:8080/helm/bitnami -helm repo update -helm pull bitnami/nginx -``` - -The proxy caches `index.yaml` using the normal metadata-cache settings and -caches chart archives after verifying their SHA-256 digest from the index. - -For charts stored in an OCI registry, configure a named OCI upstream and add -the reserved `upstream/{name}` prefix to the chart reference: - -```yaml -upstream: - oci: - ghcr: "https://ghcr.io" -``` - -```bash -helm pull oci://localhost:8080/upstream/ghcr/owner/charts/mychart --version 1.0.0 --plain-http -``` - ### Debian / APT Configure APT to use the proxy in `/etc/apt/sources.list.d/proxy.list`: @@ -487,13 +323,6 @@ Replace your existing sources.list entries, then: sudo apt update ``` -The upstream defaults to `http://deb.debian.org/debian`. To proxy a different APT repository (e.g. Ubuntu), set `upstream.debian` in the config file or `PROXY_UPSTREAM_DEBIAN` in the environment: - -```yaml -upstream: - debian: "http://archive.ubuntu.com/ubuntu" -``` - ### RPM / Yum / DNF Configure yum/dnf to use the proxy in `/etc/yum.repos.d/proxy.repo`: @@ -513,76 +342,9 @@ sudo dnf clean all sudo dnf update ``` -### Alpine / apk - -Point `/etc/apk/repositories` at the proxy. The default repository name -`alpine` proxies the official mirror (`https://dl-cdn.alpinelinux.org/alpine`): - -``` -http://localhost:8080/apk/alpine/v3.22/main -http://localhost:8080/apk/alpine/v3.22/community -``` - -Then: - -```bash -apk update -``` - -Repository indexes (v2 `APKINDEX.tar.gz` and v3 `Packages.adb`), detached -signatures, and packages are served byte-for-byte unchanged, so apk's normal -signature verification keeps working. Indexes use the metadata cache -(`metadata_ttl`, stale fallback); `.apk` packages are stored in the shared -artifact cache and remain available when the upstream is unreachable. - -To proxy other mirrors or private repositories, configure named upstreams -under `upstream.apk` (this replaces the built-in default; re-add `alpine` if -you still want it): - -```yaml -upstream: - apk: - alpine: "https://dl-cdn.alpinelinux.org/alpine" - private: "https://apk.example.com" -``` - -``` -http://localhost:8080/apk/private -``` - -apk appends the architecture and index filename to each repository line -itself. - -### GitHub Releases / mise (aqua backend) - -Configure named generic upstreams: - -```yaml -upstream: - generic: - github: "https://github.com" - github-api: "https://api.github.com" -``` - -Then rewrite GitHub URLs in mise's settings (`~/.config/mise/config.toml`, mise ≥ 2025.9.3): - -```toml -[settings.url_replacements] -"regex:^https://github\\.com/([^/]+)/([^/]+)/releases/download/(.+)" = "http://localhost:8080/generic/github/$1/$2/releases/download/$3" -"regex:^https://api\\.github\\.com/(.*)" = "http://localhost:8080/generic/github-api/$1" -``` - -Release assets are cached permanently after the first download and keep -installing while GitHub is down. Tag lookups through `api.github.com` are -cached for `metadata_ttl` and served stale during an outage or rate limit. -Commit a `mise.lock` and install with `mise install --locked` so pinned -installs need no API call at all. Add a bearer token for `https://api.github.com` -under `upstream.auth` if the fleet exceeds GitHub's anonymous rate limit. - ## Configuration The proxy can be configured via: - 1. Command line flags (highest priority) 2. Environment variables 3. Configuration file (YAML or JSON) @@ -593,14 +355,13 @@ The proxy can be configured via: -config string Path to configuration file -listen string Address to listen on (default ":8080") -base-url string Public URL of this proxy (default "http://localhost:8080") --storage-url string Storage URL (file://, s3://, gs://, azblob://) +-storage-url string Storage URL (file:// or s3://) -storage-path string Path to artifact storage directory (deprecated, use -storage-url) -database-driver string Database driver: sqlite or postgres (default "sqlite") -database-path string Path to SQLite database file (default "./cache/proxy.db") -database-url string PostgreSQL connection URL -log-level string Log level: debug, info, warn, error (default "info") -log-format string Log format: text, json (default "text") --access-log string Path to the JSONL access log -version Print version and exit ``` @@ -609,15 +370,12 @@ The proxy can be configured via: ```bash PROXY_LISTEN=:8080 PROXY_BASE_URL=http://localhost:8080 -PROXY_UI_URL=http://localhost:8080 # Optional; defaults to PROXY_BASE_URL PROXY_STORAGE_URL=file:///var/cache/proxy/artifacts PROXY_DATABASE_DRIVER=sqlite PROXY_DATABASE_PATH=./cache/proxy.db PROXY_DATABASE_URL=postgres://user:pass@localhost/proxy?sslmode=disable PROXY_LOG_LEVEL=info PROXY_LOG_FORMAT=text -PROXY_ACCESS_LOG_PATH=/var/log/proxy/access.jsonl -PROXY_UPSTREAM_SWIFT=https://tuist.dev/api/registry/swift ``` ### Configuration File @@ -638,22 +396,16 @@ log: level: "info" format: "text" -access_log: - path: "/var/log/proxy/access.jsonl" # Optional JSONL activity log - # Optional: override upstream URLs upstream: npm: "https://registry.npmjs.org" cargo: "https://index.crates.io" - swift: "https://tuist.dev/api/registry/swift" # Optional: version cooldown (see above) cooldown: default: "3d" ``` -See the [configuration reference](docs/configuration.md#upstream-registries) for every upstream key, environment variable, and default URL. - Run with config file: ```bash @@ -697,57 +449,6 @@ storage: Set credentials via standard AWS environment variables (`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, `AWS_REGION`). -### Google Cloud Storage - -The proxy can store cached artifacts in a GCS bucket using the `gs://` URL scheme. - -```yaml -storage: - url: "gs://my-bucket-name" -``` - -Authentication uses [Application Default Credentials](https://docs.cloud.google.com/docs/authentication/application-default-credentials), which means no credentials need to be embedded in the config or environment. Supported sources, in order: - -- **GKE Workload Identity** — bind the Kubernetes service account running the proxy to a Google service account that has `roles/storage.objectAdmin` on the bucket. The proxy will use the workload's token automatically. -- **Attached service account** on GCE, Cloud Run, Cloud Functions, etc. -- **`GOOGLE_APPLICATION_CREDENTIALS`** environment variable pointing at a service account JSON key file. -- **`gcloud auth application-default login`** for local development. - -#### GKE Workload Identity setup - -```bash -# 1. Create a Google service account -gcloud iam service-accounts create git-pkgs-proxy \ - --project=PROJECT_ID - -# 2. Grant it access to the bucket -gsutil iam ch \ - serviceAccount:git-pkgs-proxy@PROJECT_ID.iam.gserviceaccount.com:objectAdmin \ - gs://my-bucket-name - -# 3. Bind the Kubernetes service account to it -gcloud iam service-accounts add-iam-policy-binding \ - git-pkgs-proxy@PROJECT_ID.iam.gserviceaccount.com \ - --role=roles/iam.workloadIdentityUser \ - --member="serviceAccount:PROJECT_ID.svc.id.goog[NAMESPACE/KSA_NAME]" - -# 4. Annotate the Kubernetes service account -kubectl annotate serviceaccount KSA_NAME \ - --namespace=NAMESPACE \ - iam.gke.io/gcp-service-account=git-pkgs-proxy@PROJECT_ID.iam.gserviceaccount.com -``` - -#### Direct serve (signed URLs) with Workload Identity - -When `direct_serve: true` is enabled, the proxy issues HTTP 302 redirects to presigned GCS URLs. Workload Identity provides no private key, so the GCS backend calls the [IAM Credentials `signBlob` API](https://docs.cloud.google.com/iam/docs/reference/credentials/rest/v1/projects.serviceAccounts/signBlob). Grant the service account the token-creator role on itself: - -```bash -gcloud iam service-accounts add-iam-policy-binding \ - git-pkgs-proxy@PROJECT_ID.iam.gserviceaccount.com \ - --role=roles/iam.serviceAccountTokenCreator \ - --member="serviceAccount:git-pkgs-proxy@PROJECT_ID.iam.gserviceaccount.com" -``` - ## CLI Commands ### serve (default) @@ -790,11 +491,6 @@ curl -X POST http://localhost:8080/api/mirror \ -H "Content-Type: application/json" \ -d '{"purls": ["pkg:npm/lodash@4.17.21"]}' -# Start a mirror job from an inline CycloneDX or SPDX JSON SBOM -curl -X POST http://localhost:8080/api/mirror \ - -H "Content-Type: application/json" \ - -d '{"sbom":{"bomFormat":"CycloneDX","components":[{"purl":"pkg:npm/lodash@4.17.21"}]}}' - # Check job status curl http://localhost:8080/api/mirror/mirror-1 @@ -856,7 +552,7 @@ Recently cached: | Endpoint | Description | |----------|-------------| | `GET /` | Dashboard (web UI) | -| `GET /health` | Health check and upstream circuit breaker state (JSON; HTTP 200 healthy, 503 unhealthy) | +| `GET /health` | Health check (returns "ok" if healthy) | | `GET /stats` | Cache statistics (JSON) | | `GET /metrics` | Prometheus metrics | | `GET /npm/*` | npm registry protocol | @@ -872,14 +568,7 @@ Recently cached: | `GET /conan/*` | Conan C/C++ protocol | | `GET /conda/*` | Conda/Anaconda protocol | | `GET /cran/*` | CRAN (R) protocol | -| `GET /julia/*` | Julia Pkg server protocol | -| `GET /swift/*` | Swift Package Registry v1 protocol | -| `GET /helm/{repository}/*` | HTTP Helm chart repository protocol | -| `GET /homebrew/*` | Homebrew JSON API | | `GET /v2/*` | OCI/Docker registry protocol | -| `GET /v2/homebrew/core/*` | Homebrew core bottle manifests and blobs from GHCR | -| `GET /apk/{repository}/*` | Alpine APK repository protocol | -| `GET /generic/{name}/*` | Generic HTTP download proxy (GitHub release assets, mise/aqua) | | `GET /debian/*` | Debian/APT repository protocol | | `GET /rpm/*` | RPM/Yum repository protocol | @@ -887,7 +576,7 @@ Recently cached: | Endpoint | Description | |----------|-------------| -| `POST /api/mirror` | Start a mirror job (JSON body with `purls` or an inline `sbom`) | +| `POST /api/mirror` | Start a mirror job (JSON body with `purls`) | | `GET /api/mirror/{id}` | Get job status and progress | | `DELETE /api/mirror/{id}` | Cancel a running job | @@ -1075,16 +764,16 @@ Response: ## Web Interface -The proxy serves a web UI under `/ui`. No separate frontend build is needed -- templates and assets are embedded in the binary. `GET /` redirects to `/ui/`. The UI is mounted under its own prefix so a reverse proxy can apply different access rules to it than to the package endpoints (for example, requiring auth for `PathPrefix(/ui)` while leaving `/npm`, `/pypi` etc. open to build machines). +The proxy serves a web UI at the root URL. No separate frontend build is needed -- templates and assets are embedded in the binary. -- **Dashboard** (`/ui/`) -- cache stats, popular packages, recently cached artifacts, and vulnerability overview. -- **Install guide** (`/ui/install`) -- per-ecosystem configuration instructions, so you don't have to look them up here. -- **Package browser** (`/ui/packages`) -- browse all cached packages with filtering by ecosystem and sorting by hits, size, name, or vulnerability count. -- **Search** (`/ui/search?q=...`) -- search cached packages by name. -- **Package detail** (`/ui/package/{ecosystem}/{name}`) -- metadata, license, vulnerabilities, and version list for a package. You can select two versions to compare. -- **Version detail** (`/ui/package/{ecosystem}/{name}/{version}`) -- per-version metadata, integrity hash, artifact cache status, and hit counts. -- **Source browser** (`/ui/package/{ecosystem}/{name}/{version}/browse`) -- browse files inside cached archives with syntax highlighting for text files and image previews. -- **Version diff** (`/ui/package/{ecosystem}/{name}/compare/{v1}...{v2}`) -- side-by-side diff of two cached versions showing added, removed, and changed files. +- **Dashboard** (`/`) -- cache stats, popular packages, recently cached artifacts, and vulnerability overview. +- **Install guide** (`/install`) -- per-ecosystem configuration instructions, so you don't have to look them up here. +- **Package browser** (`/packages`) -- browse all cached packages with filtering by ecosystem and sorting by hits, size, name, or vulnerability count. +- **Search** (`/search?q=...`) -- search cached packages by name. +- **Package detail** (`/package/{ecosystem}/{name}`) -- metadata, license, vulnerabilities, and version list for a package. You can select two versions to compare. +- **Version detail** (`/package/{ecosystem}/{name}/{version}`) -- per-version metadata, integrity hash, artifact cache status, and hit counts. +- **Source browser** (`/package/{ecosystem}/{name}/{version}/browse`) -- browse files inside cached archives with syntax highlighting for text files and image previews. +- **Version diff** (`/package/{ecosystem}/{name}/compare/{v1}...{v2}`) -- side-by-side diff of two cached versions showing added, removed, and changed files. ## Monitoring @@ -1092,8 +781,6 @@ The proxy exposes Prometheus metrics at `GET /metrics`. All metric names are pre | Metric | Type | Labels | Description | |--------|------|--------|-------------| -| `proxy_requests_total` | counter | `ecosystem`, `status` | Proxy responses by package ecosystem and HTTP status | -| `proxy_request_duration_seconds` | histogram | `ecosystem`, `status` | Proxy request duration | | `proxy_cache_hits_total` | counter | `ecosystem` | Cache hits | | `proxy_cache_misses_total` | counter | `ecosystem` | Cache misses | | `proxy_cache_size_bytes` | gauge | | Total size of cached artifacts | @@ -1103,43 +790,8 @@ The proxy exposes Prometheus metrics at `GET /metrics`. All metric names are pre | `proxy_storage_operation_duration_seconds` | histogram | `operation` | Storage read/write latency | | `proxy_storage_errors_total` | counter | `operation` | Storage read/write failures | | `proxy_active_requests` | gauge | | In-flight requests | -| `proxy_health_probe_failures_total` | counter | `step` | Storage health probe failures by failing step (`write`, `size`, `read`, `verify`, `delete`). | -| `proxy_circuit_breaker_state` | gauge | `registry` | Artifact-fetch circuit breaker state per upstream registry (0 closed, 2 open). Published once that registry's breaker has tripped. | -| `proxy_circuit_breaker_trips_total` | counter | `registry` | Circuit breaker trips per upstream registry. | -Cache size and artifact count are refreshed every 60 seconds. Circuit breaker state is read from the fetcher on each scrape of `/metrics` and each `/health` request, so `proxy_circuit_breaker_trips_total` counts the trips visible between those reads — a breaker that opens and recovers entirely between two scrapes is not counted. The remaining metrics update on each request. - -The breaker metrics carry one series per upstream host, but only for hosts whose breaker has tripped at least once since startup. A breaker is created per host the proxy fetches artifacts from, and for some ecosystems that host comes from upstream metadata rather than from configuration (composer takes it from a package's `dist.url`, helm from the chart URLs in `index.yaml`), so publishing every host would let upstream content grow the series count for the lifetime of the process. Once a host has tripped it keeps reporting, so a recovery still shows up as a transition to 0 rather than as a series that vanishes. `/health` is not a persistent time series and lists every breaker, tripped or not. - -The `registry` label is the host of the URL the artifact was fetched from. Because that URL can come from upstream metadata, it is not always one a host can be read off — a signed `dist.url` that fails to parse, for instance — and such a breaker is labelled `hostless-url-` instead, where the digest is keyed by a value drawn fresh at startup. Neither `/metrics` nor `/health` requires authentication, so a fetch URL is never published as a label or a key; the digest identifies the breaker for as long as the process runs without revealing the URL behind it or letting a chosen URL be matched against it. - -Alert on `proxy_circuit_breaker_state == 2` sustained for more than a few minutes: while a breaker is open, artifact downloads for that upstream fail with HTTP 502 on every cache miss, and only a single probe request per backoff interval reaches the upstream. Cached artifacts keep serving, and so does metadata for the same ecosystem (metadata does not go through the circuit breaker), so installs fail in a way that looks like a partial upstream outage. - -### Health Check - -`/health` returns a structured JSON report of subsystem health. HTTP 200 if all checks pass; 503 if any fail. - -```json -{ - "status": "ok", - "checks": { - "database": {"status": "ok"}, - "storage": {"status": "ok"} - }, - "circuit_breakers": { - "registry.npmjs.org": "closed", - "static.crates.io": "open" - } -} -``` - -Failing checks include an `"error"` field. Storage failures also include a `"step"` field identifying which probe step failed (`write`, `size`, `read`, `verify`, `delete`). When the database check fails, the storage entry reports `{"status": "skipped"}` so the response always carries the same key set. - -`circuit_breakers` reports the state of each upstream's artifact-fetch circuit breaker (`"open"` or `"closed"`), keyed by upstream host — or by the `hostless-url-` placeholder described under [Monitoring](#monitoring) where the fetch URL has no host to read. The key is omitted until the proxy has fetched an artifact from at least one upstream, and a host appears only once a breaker has been created for it. Breakers trip after repeated upstream failures and retry the upstream after an exponential backoff. While one is open, artifact downloads for that host return HTTP 502 on a cache miss without contacting the upstream; already-cached artifacts are still served from storage, since the cache is checked before the fetcher. A breaker is reported as `"open"` throughout its backoff, including the half-open window in which it admits one probe request to test recovery. Breaker state is per process and in memory, so a restart clears it, but a restart is not needed for recovery: the backoff keeps retrying for as long as the breaker is open, so it closes on its own once the upstream serves again. - -An open breaker does **not** set `status` to `"error"` or change the HTTP status code: it reports a specific upstream refusing to serve, not this proxy being unfit to receive traffic, and failing the readiness probe over one unhealthy upstream would pull the pod out of rotation for every other ecosystem too. Use `proxy_circuit_breaker_state` for alerting on it. - -Storage probe results are cached for `health.storage_probe_interval` (default 30s) to bound the cost of probing remote backends. A probe holds an internal mutex for up to 10 seconds (the hardcoded per-probe timeout), so `/health` is intended as a Kubernetes **readiness** probe rather than a liveness probe — a slow S3 round-trip should pull the pod from rotation, not restart it. +Cache size and artifact count are refreshed every 60 seconds. The remaining metrics update on each request. Scrape config for Prometheus: @@ -1208,47 +860,22 @@ When running behind nginx, Apache, or another reverse proxy, set `base_url` to y base_url: "https://proxy.example.com" ``` -If the UI is reached on a different hostname than the package endpoints — for example, the UI exposed publicly on a domain while build machines hit a Docker network alias — set `ui_base_url` separately. `base_url` is the URL package managers and metadata rewriting use; `ui_base_url` is the URL advertised to humans visiting the web UI (canonical/`og:url` tags and the install guide banner): - -```yaml -base_url: "http://pkg-proxy:8080" # internal alias for build machines -ui_base_url: "https://proxy.example.com/ui" # public UI URL -``` - -When unset, `ui_base_url` defaults to `base_url`. - -> **Warning:** the proxy serves the UI and package endpoints on the same listener. Setting `ui_base_url` only changes what URL the UI advertises to humans; it does not stop package endpoints from being reachable on the same hostname and port. When fronting the proxy with a public reverse proxy, restrict the public route to `PathPrefix(/ui)` (or your proxy's equivalent), otherwise `/npm`, `/pypi`, and the other package endpoints stay exposed alongside the UI. - -nginx example, restricting the public host to the UI while leaving package endpoints reachable only on the internal listener: +nginx example: ```nginx server { listen 443 ssl; server_name proxy.example.com; - location /ui/ { + location / { proxy_pass http://127.0.0.1:8080; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_buffering off; } - - location / { - return 404; - } } ``` -Traefik example using `PathPrefix(/ui)` so the public router only matches UI traffic: - -```yaml -labels: - traefik.enable: "true" - traefik.http.services.pkg-proxy.loadbalancer.server.port: "8080" - traefik.http.routers.pkg-proxy.rule: "Host(`proxy.example.com`) && PathPrefix(`/ui`)" - traefik.http.routers.pkg-proxy.entrypoints: "websecure" -``` - ## Cache Management The proxy stores artifacts in the configured storage directory with this structure: @@ -1289,8 +916,7 @@ The proxy will recreate the database on next start. ## Building from Source Requirements: - -- Go (the project version is declared in `go.mod`) +- Go 1.25 or later ```bash git clone https://github.com/git-pkgs/proxy.git diff --git a/cmd/proxy/main.go b/cmd/proxy/main.go index cf28d8d..0268e9e 100644 --- a/cmd/proxy/main.go +++ b/cmd/proxy/main.go @@ -40,8 +40,6 @@ // Log level: debug, info, warn, error (default "info") // -log-format string // Log format: text, json (default "text") -// -access-log string -// Path to the JSONL access log (disabled by default) // // Stats Flags: // @@ -74,14 +72,6 @@ // PROXY_DATABASE_URL - PostgreSQL connection URL // PROXY_LOG_LEVEL - Log level // PROXY_LOG_FORMAT - Log format -// PROXY_ACCESS_LOG_PATH - JSONL access log path -// PROXY_UPSTREAM_* - Upstream URLs and network access controls -// PROXY_GRADLE_BUILD_CACHE_READ_ONLY - Disable Gradle PUT uploads -// PROXY_GRADLE_BUILD_CACHE_MAX_UPLOAD_SIZE - Max Gradle PUT request body size -// PROXY_GRADLE_BUILD_CACHE_MAX_AGE - Gradle cache max age eviction -// PROXY_GRADLE_BUILD_CACHE_MAX_SIZE - Gradle cache max total size -// PROXY_GRADLE_BUILD_CACHE_SWEEP_INTERVAL - Gradle cache eviction sweep interval -// PROXY_HEALTH_STORAGE_PROBE_INTERVAL - Storage health probe cache interval (default "30s") // // Example: // @@ -106,7 +96,6 @@ import ( "log/slog" "os" "os/signal" - "runtime/debug" "strings" "syscall" @@ -129,15 +118,6 @@ var ( Commit = "unknown" ) -func init() { - if Version != "dev" { - return - } - if bi, ok := debug.ReadBuildInfo(); ok && bi.Main.Version != "" && bi.Main.Version != "(devel)" { - Version = bi.Main.Version - } -} - func main() { if len(os.Args) > 1 { switch os.Args[1] { @@ -196,7 +176,6 @@ func runServe() { databaseURL := fs.String("database-url", "", "PostgreSQL connection URL") logLevel := fs.String("log-level", "", "Log level: debug, info, warn, error") logFormat := fs.String("log-format", "", "Log format: text, json") - accessLogPath := fs.String("access-log", "", "Path to the JSONL access log") version := fs.Bool("version", false, "Print version and exit") fs.Usage = func() { @@ -214,39 +193,6 @@ func runServe() { fmt.Fprintf(os.Stderr, " PROXY_DATABASE_URL PostgreSQL connection URL\n") fmt.Fprintf(os.Stderr, " PROXY_LOG_LEVEL Log level\n") fmt.Fprintf(os.Stderr, " PROXY_LOG_FORMAT Log format\n") - fmt.Fprintf(os.Stderr, " PROXY_ACCESS_LOG_PATH JSONL access log path\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_ALLOW_PRIVATE_HOSTS Comma-separated private upstream hosts\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_ALLOW_LOOPBACK Permit loopback upstreams and redirects\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_NPM npm registry upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_CARGO Cargo index upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_CARGO_DOWNLOAD Cargo download upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_GEM RubyGems upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_GO Go module proxy upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_HEX Hex repository upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_HEX_API Hex API upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_PUB pub registry upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_PYPI PyPI index and API upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_PYPI_DOWNLOAD PyPI download upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_MAVEN Maven repository upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL Gradle Plugin Portal upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_NUGET NuGet API upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_NUGET_SEARCH NuGet search upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_COMPOSER Packagist API upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_COMPOSER_REPOSITORY Packagist repository upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_CONAN Conan registry upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_CONDA Conda channel upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_CRAN CRAN mirror upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_JULIA Julia package server upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_SWIFT Swift Package Registry upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_OCI_DEFAULT Default OCI registry upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_DEBIAN Debian repository upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_RPM RPM repository upstream URL\n") - fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_READ_ONLY Disable Gradle PUT uploads\n") - fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_MAX_UPLOAD_SIZE Max Gradle PUT request body size\n") - fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_MAX_AGE Gradle cache max age eviction\n") - fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_MAX_SIZE Gradle cache max total size\n") - fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_SWEEP_INTERVAL Gradle cache eviction sweep interval\n") - fmt.Fprintf(os.Stderr, " PROXY_HEALTH_STORAGE_PROBE_INTERVAL Storage health probe cache interval\n") } _ = fs.Parse(os.Args[1:]) @@ -294,9 +240,6 @@ func runServe() { if *logFormat != "" { cfg.Log.Format = *logFormat } - if *accessLogPath != "" { - cfg.AccessLog.Path = *accessLogPath - } // Validate configuration if err := cfg.Validate(); err != nil { @@ -308,10 +251,7 @@ func runServe() { logger := setupLogger(cfg.Log.Level, cfg.Log.Format) // Create and start server - srv, err := server.New(cfg, logger, server.BuildInfo{ - Version: Version, - Commit: Commit, - }) + srv, err := server.New(cfg, logger) if err != nil { logger.Error("failed to create server", "error", err) os.Exit(1) @@ -439,12 +379,7 @@ func runMirror() { var source mirror.Source switch { case *sbomPath != "": - data, err := os.ReadFile(*sbomPath) - if err != nil { - fmt.Fprintf(os.Stderr, "error reading SBOM %s: %v\n", *sbomPath, err) - os.Exit(1) - } - source = &mirror.SBOMSource{Data: data, Name: *sbomPath} + source = &mirror.SBOMSource{Path: *sbomPath} case len(purls) > 0: source = &mirror.PURLSource{PURLs: purls} default: @@ -519,7 +454,6 @@ func runMirror() { proxy := handler.NewProxy(db, store, fetcher, resolver, logger) proxy.CacheMetadata = true // mirror always caches metadata proxy.MetadataTTL = cfg.ParseMetadataTTL() - proxy.MetadataMaxSize = cfg.ParseMetadataMaxSize() m := mirror.New(proxy, db, store, logger, *concurrency) diff --git a/cmd/proxy/main_test.go b/cmd/proxy/main_test.go deleted file mode 100644 index 4393c44..0000000 --- a/cmd/proxy/main_test.go +++ /dev/null @@ -1,58 +0,0 @@ -package main - -import ( - "os" - "os/exec" - "strings" - "testing" -) - -func TestServeHelpListsUpstreamEnvironmentVariables(t *testing.T) { - cmd := exec.Command(os.Args[0], "-test.run=^TestServeHelpProcess$") - cmd.Env = append(os.Environ(), "PROXY_TEST_SERVE_HELP=1") - output, err := cmd.CombinedOutput() - if err != nil { - t.Fatalf("serve help failed: %v\n%s", err, output) - } - - variables := []string{ - "PROXY_UPSTREAM_ALLOW_PRIVATE_HOSTS", - "PROXY_UPSTREAM_ALLOW_LOOPBACK", - "PROXY_UPSTREAM_NPM", - "PROXY_UPSTREAM_CARGO", - "PROXY_UPSTREAM_CARGO_DOWNLOAD", - "PROXY_UPSTREAM_GEM", - "PROXY_UPSTREAM_GO", - "PROXY_UPSTREAM_HEX", - "PROXY_UPSTREAM_HEX_API", - "PROXY_UPSTREAM_PUB", - "PROXY_UPSTREAM_PYPI", - "PROXY_UPSTREAM_PYPI_DOWNLOAD", - "PROXY_UPSTREAM_MAVEN", - "PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL", - "PROXY_UPSTREAM_NUGET", - "PROXY_UPSTREAM_NUGET_SEARCH", - "PROXY_UPSTREAM_COMPOSER", - "PROXY_UPSTREAM_COMPOSER_REPOSITORY", - "PROXY_UPSTREAM_CONAN", - "PROXY_UPSTREAM_CONDA", - "PROXY_UPSTREAM_CRAN", - "PROXY_UPSTREAM_JULIA", - "PROXY_UPSTREAM_OCI_DEFAULT", - "PROXY_UPSTREAM_DEBIAN", - "PROXY_UPSTREAM_RPM", - } - for _, variable := range variables { - if !strings.Contains(string(output), variable) { - t.Errorf("serve help omitted %s", variable) - } - } -} - -func TestServeHelpProcess(*testing.T) { - if os.Getenv("PROXY_TEST_SERVE_HELP") != "1" { - return - } - os.Args = []string{"proxy", "serve", "-help"} - main() -} diff --git a/config.example.yaml b/config.example.yaml index 82a617e..ea17d15 100644 --- a/config.example.yaml +++ b/config.example.yaml @@ -4,22 +4,10 @@ # Server listen address listen: ":8080" -# Public URL where package endpoints are reachable. -# Used for rewriting package metadata URLs and shown in install guide snippets -# so users know what to point their package manager at. +# Public URL where this proxy is accessible +# Used for rewriting package metadata URLs base_url: "http://localhost:8080" -# Timeout for individual upstream HTTP requests made by protocol handlers -# (metadata fetches, pass-through file requests). Uses Go duration syntax. -# Set to "0" to disable the timeout. Default: "30s". -# http_timeout: "30s" - -# Public URL where the web UI is reached. Defaults to base_url when unset. -# Set this separately when the UI is served on a different hostname than the -# package endpoints — for example, the UI on a public domain behind auth while -# build machines hit a Docker network alias for the package endpoints. -# ui_base_url: "https://proxy.example.com/ui" - # Artifact storage configuration storage: # Storage backend URL @@ -27,20 +15,9 @@ storage: # - file:///path/to/dir - Local filesystem (default) # - s3://bucket-name - Amazon S3 # - s3://bucket?endpoint=http://localhost:9000 - S3-compatible (MinIO) - # - gs://bucket-name - Google Cloud Storage - # - azblob://container-name - Azure Blob Storage # # For S3, configure credentials via environment variables: # AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_REGION - # - # For GCS, authentication uses Application Default Credentials. On GKE with - # Workload Identity, bind the Kubernetes service account to a Google service - # account that has roles/storage.objectAdmin on the bucket. No extra config - # is needed in this file. For local development, run: - # gcloud auth application-default login - # If direct_serve is enabled, the service account also needs - # roles/iam.serviceAccountTokenCreator on itself so the IAM Credentials - # signBlob API can sign URLs without a private key. url: "" # Local filesystem path (used when url is empty) @@ -52,23 +29,6 @@ storage: # Empty or "0" means unlimited max_size: "" - # Redirect cached artifact downloads to presigned storage URLs (HTTP 302) - # instead of streaming through the proxy. Only effective for S3, GCS, and Azure. - # Leave disabled if clients reach the proxy through an authenticating gateway, - # since presigned URLs bypass it. - direct_serve: false - - # How long presigned URLs remain valid (e.g. "5m", "1h"). Default: "15m". - direct_serve_ttl: "15m" - - # Public base URL to substitute into presigned URLs. Set this when the - # proxy reaches storage at an internal address (127.0.0.1, a Docker - # service name) but clients must use a public hostname. Only scheme and - # host are used; the signed path and query are preserved. For S3/MinIO - # the reverse proxy at this address must forward requests with the - # internal Host header or the SigV4 signature will not validate. - # direct_serve_base_url: "https://minio.example.com" - # Database configuration database: # Database driver: "sqlite" (default) or "postgres" @@ -89,24 +49,10 @@ log: # Log format: "text" or "json" format: "text" -# JSONL access log. Leave path empty to disable it. -access_log: - path: "" - -# Upstream URLs for built-in routes and authentication +# Upstream registry URLs and authentication upstream: - # Hosts allowed to resolve to private, ULA, or CGNAT addresses - allow_private_hosts: [] - - # Permit upstream requests and redirects to loopback addresses - allow_loopback: false - # npm registry URL npm: "https://registry.npmjs.org" - # Always request full npm packuments so served metadata carries publish - # times ("time" map) even when cooldown is disabled. Needed by clients that - # gate on publish age, e.g. Yarn's npmMinimalAgeGate. Default: false. - # npm_full_metadata: true # Cargo sparse index URL cargo: "https://index.crates.io" @@ -114,109 +60,14 @@ upstream: # Cargo crate download URL cargo_download: "https://static.crates.io/crates" - # RubyGems registry URL - gem: "https://rubygems.org" - - # Go module proxy URL - go: "https://proxy.golang.org" - - # Hex repository URL - hex: "https://repo.hex.pm" - - # Hex API URL used for package timestamps - hex_api: "https://hex.pm" - - # pub registry URL - pub: "https://pub.dev" - - # PyPI index and API URL - pypi: "https://pypi.org" - - # PyPI package download URL - pypi_download: "https://files.pythonhosted.org" - - # Maven repository URL (used by /maven endpoint) - maven: "https://repo1.maven.org/maven2" - - # Gradle Plugin Portal Maven URL (fallback for plugin marker artifacts) - gradle_plugin_portal: "https://plugins.gradle.org/m2" - - # NuGet API URL - nuget: "https://api.nuget.org" - - # NuGet search API URL - nuget_search: "https://azuresearch-usnc.nuget.org" - - # Packagist API URL - composer: "https://packagist.org" - - # Packagist repository URL - composer_repository: "https://repo.packagist.org" - - # Conan registry URL - conan: "https://center.conan.io" - - # Conda channel base URL - conda: "https://conda.anaconda.org" - - # CRAN mirror URL - cran: "https://cloud.r-project.org" - - # Julia package server URL - julia: "https://pkg.julialang.org" - - # Swift Package Registry URL (used by /swift endpoint) - swift: "https://tuist.dev/api/registry/swift" - - # Default OCI registry URL for unprefixed /v2 requests - oci_default: "https://registry-1.docker.io" - - # Debian/APT repository URL (used by /debian endpoint) - debian: "http://deb.debian.org/debian" - - # RPM repository URL (used by /rpm endpoint) - rpm: "https://dl.fedoraproject.org/pub/fedora/linux" - - # Homebrew JSON API URL (used by /homebrew endpoint) - homebrew_api: "https://formulae.brew.sh/api" - - # Homebrew artifact registry URL (used for /v2/homebrew/core requests) - homebrew_artifact: "https://ghcr.io" - - # Named HTTP Helm chart repositories (used by /helm/{name}/) - # helm: - # bitnami: "https://charts.bitnami.com/bitnami" - - # Named OCI registries. Use the upstream/{name}/ repository prefix, e.g. - # oci://proxy.example.com/upstream/ghcr/owner/chart. - # oci: - # ghcr: "https://ghcr.io" - - # Named Alpine APK repositories (used by /apk/{name}/). - # Defaults to {"alpine": "https://dl-cdn.alpinelinux.org/alpine"} when empty; - # configuring any entry replaces that default. - # apk: - # alpine: "https://dl-cdn.alpinelinux.org/alpine" - # private: "https://apk.example.com" - - # Named generic HTTP upstreams (used by /generic/{name}/). The remaining - # request path and query are appended to the upstream URL. GitHub release - # assets ({owner}/{repo}/releases/download/{tag}/{asset}) are cached - # immutably; other paths use the metadata cache with stale-on-error. - # generic: - # github: "https://github.com" - # github-api: "https://api.github.com" - # Authentication for upstream registries - # Keys are absolute URL scopes. Scheme, host, effective port, and path - # segment boundaries must match; the longest matching scope wins. + # Keys are URL prefixes matched against request URLs. # Values can reference environment variables using ${VAR_NAME} syntax. # # Supported auth types: # - bearer: Authorization header with Bearer token # - basic: Authorization header with Basic auth (username:password) # - header: Custom header name and value - # - ecr: AWS ECR auto-refreshing token via the AWS SDK credential chain auth: # Example: npm with bearer token # "https://registry.npmjs.org": @@ -240,42 +91,6 @@ upstream: # header_name: "X-Auth-Token" # header_value: "${MAVEN_TOKEN}" - # Example: private AWS ECR registry (12h tokens auto-refreshed via - # ecr:GetAuthorizationToken; credentials come from the AWS SDK default - # chain, so IRSA / instance profiles / AWS_* env vars all work; the region - # is inferred from the private ECR hostname) - # "https://123456789012.dkr.ecr.eu-west-1.amazonaws.com": - # type: ecr - -# Gradle HttpBuildCache configuration -gradle: - build_cache: - # Set to true to disable PUT uploads (read-only cache mode) - read_only: false - - # Maximum accepted Gradle cache upload body size - # Required and must be > 0 - max_upload_size: "100MB" - - # Evict entries older than this age (set to "0" to disable age-based eviction) - max_age: "168h" - - # Cap total Gradle cache size; oldest entries are deleted first - # ("0" disables size-based eviction) - # max_size: "20GB" - - # How often eviction runs when max_age or max_size is set - sweep_interval: "10m" - -# Health endpoint configuration. -health: - # Minimum time between storage backend probes. - # The /health endpoint runs a write/read/verify/delete round-trip - # against the configured storage backend and caches the result for - # this interval. Set to "0" to probe on every request. - # Default: "30s". - storage_probe_interval: "30s" - # Version cooldown configuration # Hides package versions published too recently, giving the community time # to spot malicious releases before they're pulled into projects. @@ -289,37 +104,7 @@ cooldown: # npm: "7d" # cargo: "0" - # Per-package overrides (keyed by PURL). Keys are normalized, so npm scopes - # may use either @scope or the canonical %40scope form. + # Per-package overrides (keyed by PURL) # packages: # "pkg:npm/lodash": "0" # "pkg:npm/@babel/core": "14d" - -# Pre-cache artifact scanning. When enabled, every artifact is staged into -# storage and scanned by the configured scanners before it is committed to -# the cache and served to clients. Scanners never receive artifact bytes -# directly — each notify call includes a short-lived signed URL that the -# scanner fetches itself, so the proxy stays agnostic to trivy/ClamAV/Wiz/ -# any custom service. Scanners run concurrently; the first "block" verdict -# wins and cancels the rest. -# scanning: -# enabled: true -# fail_open: false -# timeout: 30s -# -# # Authenticates pull requests to the internal scan-fetch route. -# # Required whenever enabled is true. Supports ${VAR_NAME} expansion. -# signing_key: ${PROXY_SCANNING_SIGNING_KEY} -# -# # Address scanners use to reach this proxy to pull staged artifacts. -# # Defaults to base_url. -# # fetch_base_url: http://proxy.internal:8080 -# -# scanners: -# - name: clamav -# url: http://clamav-adapter:8080/scan -# mode: block -# - name: trivy -# url: http://trivy-adapter:8081/scan -# mode: monitor -# ecosystems: [npm, pypi] diff --git a/deploy/charts/proxy/.helmignore b/deploy/charts/proxy/.helmignore deleted file mode 100644 index 4f7d63c..0000000 --- a/deploy/charts/proxy/.helmignore +++ /dev/null @@ -1,6 +0,0 @@ -.DS_Store -.git/ -.github/ -*.swp -*.tmp -*.tgz diff --git a/deploy/charts/proxy/Chart.yaml b/deploy/charts/proxy/Chart.yaml deleted file mode 100644 index 4e6bff7..0000000 --- a/deploy/charts/proxy/Chart.yaml +++ /dev/null @@ -1,11 +0,0 @@ -apiVersion: v2 -name: proxy -description: A caching proxy for package registries -type: application -version: 0.0.0 -appVersion: "0.0.0" -home: https://github.com/git-pkgs/proxy -sources: - - https://github.com/git-pkgs/proxy -annotations: - artifacthub.io/license: MIT diff --git a/deploy/charts/proxy/templates/NOTES.txt b/deploy/charts/proxy/templates/NOTES.txt deleted file mode 100644 index 3b29f51..0000000 --- a/deploy/charts/proxy/templates/NOTES.txt +++ /dev/null @@ -1,15 +0,0 @@ -git-pkgs proxy has been installed. - -The default base URL is intended for local port forwarding. Before exposing the -proxy, set config.data.base_url to the URL used by package-manager clients. - -To access the proxy locally: - - kubectl -n {{ .Release.Namespace }} port-forward service/{{ include "proxy.fullname" . }} {{ .Values.service.port }}:{{ .Values.service.port }} - -Then visit http://localhost:{{ .Values.service.port }}/. - -{{- if not .Values.persistence.enabled }} -WARNING: persistence is disabled. Cached artifacts and the default SQLite -database will be lost when the pod is replaced. -{{- end }} diff --git a/deploy/charts/proxy/templates/_helpers.tpl b/deploy/charts/proxy/templates/_helpers.tpl deleted file mode 100644 index 9408a9f..0000000 --- a/deploy/charts/proxy/templates/_helpers.tpl +++ /dev/null @@ -1,46 +0,0 @@ -{{/* Expand the chart name. */}} -{{- define "proxy.name" -}} -{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} -{{- end }} - -{{/* Create a release-specific, DNS-safe resource name. */}} -{{- define "proxy.fullname" -}} -{{- if .Values.fullnameOverride }} -{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} -{{- else }} -{{- $name := include "proxy.name" . }} -{{- if contains $name .Release.Name }} -{{- .Release.Name | trunc 63 | trimSuffix "-" }} -{{- else }} -{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} -{{- end }} -{{- end }} -{{- end }} - -{{- define "proxy.labels" -}} -helm.sh/chart: {{ printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} -{{ include "proxy.selectorLabels" . }} -app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} -app.kubernetes.io/managed-by: {{ .Release.Service }} -{{- end }} - -{{- define "proxy.selectorLabels" -}} -app.kubernetes.io/name: {{ include "proxy.name" . }} -app.kubernetes.io/instance: {{ .Release.Name }} -{{- end }} - -{{- define "proxy.configMapName" -}} -{{- default (include "proxy.fullname" .) .Values.config.existingConfigMap }} -{{- end }} - -{{- define "proxy.claimName" -}} -{{- default (include "proxy.fullname" .) .Values.persistence.existingClaim }} -{{- end }} - -{{- define "proxy.image" -}} -{{- if .Values.image.digest -}} -{{- printf "%s@%s" .Values.image.repository .Values.image.digest -}} -{{- else -}} -{{- printf "%s:%s" .Values.image.repository (default .Chart.AppVersion .Values.image.tag) -}} -{{- end -}} -{{- end }} diff --git a/deploy/charts/proxy/templates/configmap.yaml b/deploy/charts/proxy/templates/configmap.yaml deleted file mode 100644 index 40aad7b..0000000 --- a/deploy/charts/proxy/templates/configmap.yaml +++ /dev/null @@ -1,12 +0,0 @@ -{{- if not .Values.config.existingConfigMap }} -apiVersion: v1 -kind: ConfigMap -metadata: - name: {{ include "proxy.fullname" . }} - namespace: {{ .Release.Namespace }} - labels: - {{- include "proxy.labels" . | nindent 4 }} -data: - {{ required "config.existingConfigMapKey is required" .Values.config.existingConfigMapKey }}: | - {{- toYaml .Values.config.data | nindent 4 }} -{{- end }} diff --git a/deploy/charts/proxy/templates/deployment.yaml b/deploy/charts/proxy/templates/deployment.yaml deleted file mode 100644 index 0c8efb3..0000000 --- a/deploy/charts/proxy/templates/deployment.yaml +++ /dev/null @@ -1,102 +0,0 @@ -apiVersion: apps/v1 -kind: Deployment -metadata: - name: {{ include "proxy.fullname" . }} - namespace: {{ .Release.Namespace }} - labels: - {{- include "proxy.labels" . | nindent 4 }} -spec: - replicas: {{ .Values.replicaCount }} - strategy: - {{- toYaml .Values.deploymentStrategy | nindent 4 }} - selector: - matchLabels: - {{- include "proxy.selectorLabels" . | nindent 6 }} - template: - metadata: - labels: - {{- include "proxy.selectorLabels" . | nindent 8 }} - {{- with .Values.podLabels }} - {{- toYaml . | nindent 8 }} - {{- end }} - annotations: - checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }} - {{- with .Values.podAnnotations }} - {{- toYaml . | nindent 8 }} - {{- end }} - spec: - automountServiceAccountToken: false - terminationGracePeriodSeconds: {{ .Values.terminationGracePeriodSeconds }} - securityContext: - {{- toYaml .Values.podSecurityContext | nindent 8 }} - {{- with .Values.imagePullSecrets }} - imagePullSecrets: - {{- toYaml . | nindent 8 }} - {{- end }} - containers: - - name: {{ .Chart.Name }} - image: {{ include "proxy.image" . | quote }} - imagePullPolicy: {{ .Values.image.pullPolicy }} - securityContext: - {{- toYaml .Values.containerSecurityContext | nindent 12 }} - args: - - serve - - -config - - /etc/proxy/{{ .Values.config.existingConfigMapKey }} - {{- with .Values.extraEnv }} - env: - {{- toYaml . | nindent 12 }} - {{- end }} - {{- with .Values.extraEnvFrom }} - envFrom: - {{- toYaml . | nindent 12 }} - {{- end }} - ports: - - name: http - containerPort: {{ .Values.service.containerPort }} - protocol: TCP - startupProbe: - {{- toYaml .Values.startupProbe | nindent 12 }} - readinessProbe: - {{- toYaml .Values.readinessProbe | nindent 12 }} - livenessProbe: - {{- toYaml .Values.livenessProbe | nindent 12 }} - resources: - {{- toYaml .Values.resources | nindent 12 }} - volumeMounts: - - name: config - mountPath: /etc/proxy/{{ .Values.config.existingConfigMapKey }} - subPath: {{ .Values.config.existingConfigMapKey }} - readOnly: true - - name: data - mountPath: {{ .Values.persistence.mountPath }} - volumes: - - name: config - configMap: - name: {{ include "proxy.configMapName" . }} - items: - - key: {{ required "config.existingConfigMapKey is required" .Values.config.existingConfigMapKey }} - path: {{ .Values.config.existingConfigMapKey }} - - name: data - {{- if .Values.persistence.enabled }} - persistentVolumeClaim: - claimName: {{ include "proxy.claimName" . }} - {{- else }} - emptyDir: {} - {{- end }} - {{- with .Values.nodeSelector }} - nodeSelector: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- with .Values.affinity }} - affinity: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- with .Values.tolerations }} - tolerations: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- with .Values.topologySpreadConstraints }} - topologySpreadConstraints: - {{- toYaml . | nindent 8 }} - {{- end }} diff --git a/deploy/charts/proxy/templates/ingress.yaml b/deploy/charts/proxy/templates/ingress.yaml deleted file mode 100644 index cc90155..0000000 --- a/deploy/charts/proxy/templates/ingress.yaml +++ /dev/null @@ -1,39 +0,0 @@ -{{- if .Values.ingress.enabled }} -{{- if not .Values.ingress.hosts }} -{{- fail "ingress.hosts must be set when ingress.enabled=true" }} -{{- end }} -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: {{ include "proxy.fullname" . }} - namespace: {{ .Release.Namespace }} - labels: - {{- include "proxy.labels" . | nindent 4 }} - {{- with .Values.ingress.annotations }} - annotations: - {{- toYaml . | nindent 4 }} - {{- end }} -spec: - {{- with .Values.ingress.className }} - ingressClassName: {{ . | quote }} - {{- end }} - {{- with .Values.ingress.tls }} - tls: - {{- toYaml . | nindent 4 }} - {{- end }} - rules: - {{- range .Values.ingress.hosts }} - - host: {{ .host | quote }} - http: - paths: - {{- range .paths }} - - path: {{ .path | quote }} - pathType: {{ .pathType }} - backend: - service: - name: {{ include "proxy.fullname" $ }} - port: - number: {{ $.Values.service.port }} - {{- end }} - {{- end }} -{{- end }} diff --git a/deploy/charts/proxy/templates/pvc.yaml b/deploy/charts/proxy/templates/pvc.yaml deleted file mode 100644 index 80687b2..0000000 --- a/deploy/charts/proxy/templates/pvc.yaml +++ /dev/null @@ -1,22 +0,0 @@ -{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) }} -apiVersion: v1 -kind: PersistentVolumeClaim -metadata: - name: {{ include "proxy.fullname" . }} - namespace: {{ .Release.Namespace }} - labels: - {{- include "proxy.labels" . | nindent 4 }} - {{- with .Values.persistence.annotations }} - annotations: - {{- toYaml . | nindent 4 }} - {{- end }} -spec: - accessModes: - {{- toYaml .Values.persistence.accessModes | nindent 4 }} - {{- with .Values.persistence.storageClass }} - storageClassName: {{ . | quote }} - {{- end }} - resources: - requests: - storage: {{ .Values.persistence.size }} -{{- end }} diff --git a/deploy/charts/proxy/templates/service.yaml b/deploy/charts/proxy/templates/service.yaml deleted file mode 100644 index ee5931e..0000000 --- a/deploy/charts/proxy/templates/service.yaml +++ /dev/null @@ -1,16 +0,0 @@ -apiVersion: v1 -kind: Service -metadata: - name: {{ include "proxy.fullname" . }} - namespace: {{ .Release.Namespace }} - labels: - {{- include "proxy.labels" . | nindent 4 }} -spec: - type: {{ .Values.service.type }} - ports: - - name: http - port: {{ .Values.service.port }} - targetPort: http - protocol: TCP - selector: - {{- include "proxy.selectorLabels" . | nindent 4 }} diff --git a/deploy/charts/proxy/values.yaml b/deploy/charts/proxy/values.yaml deleted file mode 100644 index 3861784..0000000 --- a/deploy/charts/proxy/values.yaml +++ /dev/null @@ -1,138 +0,0 @@ -# More than one replica requires config.data.database on Postgres, -# config.data.storage on object storage, deploymentStrategy: RollingUpdate, -# and a PVC access mode other than ReadWriteOnce (or persistence disabled). -replicaCount: 1 - -nameOverride: "" -fullnameOverride: "" - -image: - repository: ghcr.io/git-pkgs/proxy - # An empty tag uses the chart appVersion. - tag: "" - # When set, digest takes precedence over tag. - digest: "" - pullPolicy: IfNotPresent - -imagePullSecrets: [] - -service: - type: ClusterIP - port: 8080 - # Keep this aligned with config.data.listen (or the listen address in an - # existing ConfigMap). - containerPort: 8080 - -# The generated configuration is ignored when existingConfigMap is set. -config: - existingConfigMap: "" - existingConfigMapKey: config.yaml - data: - listen: ":8080" - # Set this to the URL package-manager clients use to reach the proxy. - base_url: "http://localhost:8080" - storage: - url: "file:///data/artifacts" - database: - driver: sqlite - path: "/data/proxy.db" - log: - level: info - format: json - -# Environment variables override values from the configuration file. This is -# also the recommended way to supply secret values such as database passwords -# and object-storage credentials. -extraEnv: [] -# - name: PROXY_DATABASE_URL -# valueFrom: -# secretKeyRef: -# name: proxy-database -# key: url - -extraEnvFrom: [] -# - secretRef: -# name: proxy-object-storage - -persistence: - enabled: true - # Keep this aligned with config.data.storage.url and config.data.database.path - # (or the equivalent paths in an existing ConfigMap). - mountPath: /data - existingClaim: "" - annotations: {} - accessModes: - - ReadWriteOnce - size: 10Gi - storageClass: "" - -deploymentStrategy: - type: Recreate - -ingress: - enabled: false - className: "" - annotations: {} - hosts: [] - # - host: proxy.example.com - # paths: - # - path: / - # pathType: Prefix - tls: [] - # - secretName: proxy-tls - # hosts: - # - proxy.example.com - -podAnnotations: {} -podLabels: {} - -podSecurityContext: - runAsNonRoot: true - runAsUser: 1000 - runAsGroup: 1000 - fsGroup: 1000 - seccompProfile: - type: RuntimeDefault - -containerSecurityContext: - allowPrivilegeEscalation: false - readOnlyRootFilesystem: true - capabilities: - drop: - - ALL - -resources: {} -# requests: -# cpu: 100m -# memory: 128Mi -# limits: -# memory: 512Mi - -startupProbe: - tcpSocket: - port: http - failureThreshold: 30 - periodSeconds: 2 - -# /health checks both the database and storage backends and can take up to ten -# seconds. It is intentionally a readiness check rather than a liveness check. -readinessProbe: - httpGet: - path: /health - port: http - timeoutSeconds: 11 - periodSeconds: 15 - failureThreshold: 2 - -livenessProbe: - tcpSocket: - port: http - periodSeconds: 20 - failureThreshold: 3 - -terminationGracePeriodSeconds: 30 - -nodeSelector: {} -tolerations: [] -affinity: {} -topologySpreadConstraints: [] diff --git a/docs/architecture.md b/docs/architecture.md index 9e656ef..81c41cf 100644 --- a/docs/architecture.md +++ b/docs/architecture.md @@ -14,8 +14,8 @@ The proxy is a caching HTTP server that sits between package manager clients and │ │ /npm/* -> NPMHandler /health -> healthHandler │ │ │ │ /cargo/* -> CargoHandler /stats -> statsHandler │ │ │ │ /gem/* -> GemHandler /metrics -> prometheus │ │ -│ │ ...17 ecosystems /api/* -> APIHandler │ │ -│ │ /ui/* -> Web UI │ │ +│ │ ...16 ecosystems /api/* -> APIHandler │ │ +│ │ / -> Web UI │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ │ │ │ │ ▼ ▼ ▼ │ @@ -169,7 +169,6 @@ metadata_cache ( storage_path TEXT NOT NULL, etag TEXT, content_type TEXT, - content_encoding TEXT, -- replayed on serve so signed bytes stay verbatim size INTEGER, -- BIGINT on Postgres fetched_at DATETIME, created_at DATETIME, @@ -241,8 +240,6 @@ Fetches artifacts from upstream registries. - Exponential backoff retry on 429 (rate limit) and 5xx errors - Returns streaming reader (doesn't load into memory) - Configurable user-agent -- Shares an authentication-aware transport with metadata requests so URL-scoped credentials apply consistently -- Discovers and caches scoped OCI Bearer tokens from registry challenges **Resolver:** - Determines download URL for a package/version @@ -270,10 +267,6 @@ HTTP protocol handlers for each registry type. - `handleIndex()` - Proxy sparse index - `handleDownload()` - Serve cached crate -**SwiftHandler:** -- Proxies the Swift Package Registry v1 read endpoints -- Rewrites release URLs and caches source archives - ### `internal/server` HTTP server setup, web UI, and API handlers. @@ -281,18 +274,18 @@ HTTP server setup, web UI, and API handlers. - Creates and wires together all components - Mounts protocol handlers at ecosystem-specific paths - Middleware: request ID, real IP, logging, panic recovery, active request tracking -- Web UI under `/ui`: dashboard, package browser, source browser, version comparison +- Web UI: dashboard, package browser, source browser, version comparison - Templates are embedded in the binary via `//go:embed` - Enrichment API for package metadata, vulnerability scanning, and outdated detection -- Health, stats, and Prometheus metrics endpoints. `/health` runs an active write → size-check → read → verify → delete probe against the storage backend and returns a structured JSON response (`HealthResponse`) with `"ok"` / `"error"` status per subsystem. Probe results are cached (default 30 s, configurable via `health.storage_probe_interval`) to avoid overwhelming remote backends. The response also carries a `circuit_breakers` map reporting each upstream's artifact-fetch breaker as `"open"` or `"closed"`, keyed by the host fetched from (or an opaque placeholder where the fetch URL has no host to read); the same state is published as the `proxy_circuit_breaker_state` gauge on each `/metrics` scrape. An open breaker leaves the overall status `"ok"` — it describes an upstream, not this proxy. +- Health, stats, and Prometheus metrics endpoints ### `internal/metrics` Prometheus metrics for cache performance, upstream latency, storage operations, and active requests. See the Monitoring section of the README for the full metric list. -### Cooldown +### `internal/cooldown` -Version age filtering for supply chain attack mitigation, provided by [github.com/git-pkgs/cooldown](https://github.com/git-pkgs/cooldown). Configurable at global, ecosystem, and per-package levels. Supported by npm, PyPI, pub.dev, and Composer handlers. +Version age filtering for supply chain attack mitigation. Configurable at global, ecosystem, and per-package levels. Supported by npm, PyPI, pub.dev, and Composer handlers. ### `internal/enrichment` @@ -358,7 +351,6 @@ Eviction can be implemented as: - Fresh data - new versions visible immediately - Metadata is small, upstream fetch is fast - Set `cache_metadata: true` or use the mirror command to enable metadata caching for offline use via the `metadata_cache` table -- OCI manifests and tag lists are exceptions: they are cached automatically so previously fetched images remain pullable and tag resolution works when the registry or token service is unavailable **Why stream artifacts?** - Memory efficient - don't load large files into RAM diff --git a/docs/configuration.md b/docs/configuration.md index 40840e9..be196de 100644 --- a/docs/configuration.md +++ b/docs/configuration.md @@ -17,8 +17,7 @@ See `config.example.yaml` in the repository root for a complete example. | Config | Environment | Flag | Default | Description | |--------|-------------|------|---------|-------------| | `listen` | `PROXY_LISTEN` | `-listen` | `:8080` | Address to listen on | -| `base_url` | `PROXY_BASE_URL` | `-base-url` | `http://localhost:8080` | Public URL package managers use to reach this proxy | -| `ui_base_url` | `PROXY_UI_URL` | - | (defaults to `base_url`) | Public URL where the web UI is reached. Set separately when the UI lives behind a different hostname than package endpoints (e.g. public domain vs Docker network alias). Used for canonical/og:url tags and the install guide banner. The proxy still serves package endpoints on the same listener, so any reverse proxy fronting the UI publicly should restrict the public route to `PathPrefix(/ui)` to avoid exposing package endpoints. | +| `base_url` | `PROXY_BASE_URL` | `-base-url` | `http://localhost:8080` | Public URL for the proxy | ## Storage @@ -108,168 +107,20 @@ log: | `log.level` | `PROXY_LOG_LEVEL` | `-log-level` | `debug`, `info`, `warn`, `error` | | `log.format` | `PROXY_LOG_FORMAT` | `-log-format` | `text`, `json` | -## Access Log - -The optional access log records client requests and each HTTP exchange with an upstream registry. It is always written as JSONL, with one JSON object per line. Records for the same client request share a `request_id`. - -```yaml -access_log: - path: "/var/log/proxy/access.jsonl" -``` - -| Config | Environment | Flag | Description | -|--------|-------------|------|-------------| -| `access_log.path` | `PROXY_ACCESS_LOG_PATH` | `-access-log` | File to append JSONL records to; empty disables the log | - -The parent directory must exist and be writable when the proxy starts. A newly created log file is readable and writable only by the proxy process owner. - -A request that receives a rate limit response from an upstream can produce records like these: - -```json -{"time":"2026-08-16T12:00:00Z","event":"upstream","request_id":"host/example-000001","method":"GET","url":"https://registry.example/packages/example","status_code":429,"duration_ms":42} -{"time":"2026-08-16T12:00:00Z","event":"request","request_id":"host/example-000001","method":"GET","path":"/npm/example","status_code":502,"duration_ms":43,"remote_addr":"192.0.2.10:41234"} -``` - -Upstream retries and OCI authentication calls are separate `upstream` records, so the log preserves every status returned over the wire. Network failures have an `error` field and no `status_code`. URL credentials, query strings, and fragments are omitted from both upstream URLs and client paths. - ## Upstream Registries -Each upstream used by a built-in package route can be set in YAML or JSON under `upstream`, or with its matching environment variable. Existing installations keep the same public upstreams by default. Trailing slashes are ignored. - -| Config | Environment | Default | -|--------|-------------|---------| -| `upstream.allow_private_hosts` | `PROXY_UPSTREAM_ALLOW_PRIVATE_HOSTS` | `[]` | -| `upstream.allow_loopback` | `PROXY_UPSTREAM_ALLOW_LOOPBACK` | `false` | -| `upstream.npm` | `PROXY_UPSTREAM_NPM` | `https://registry.npmjs.org` | -| `upstream.npm_full_metadata` | `PROXY_UPSTREAM_NPM_FULL_METADATA` | `false` | -| `upstream.cargo` | `PROXY_UPSTREAM_CARGO` | `https://index.crates.io` | -| `upstream.cargo_download` | `PROXY_UPSTREAM_CARGO_DOWNLOAD` | `https://static.crates.io/crates` | -| `upstream.gem` | `PROXY_UPSTREAM_GEM` | `https://rubygems.org` | -| `upstream.go` | `PROXY_UPSTREAM_GO` | `https://proxy.golang.org` | -| `upstream.hex` | `PROXY_UPSTREAM_HEX` | `https://repo.hex.pm` | -| `upstream.hex_api` | `PROXY_UPSTREAM_HEX_API` | `https://hex.pm` | -| `upstream.pub` | `PROXY_UPSTREAM_PUB` | `https://pub.dev` | -| `upstream.pypi` | `PROXY_UPSTREAM_PYPI` | `https://pypi.org` | -| `upstream.pypi_download` | `PROXY_UPSTREAM_PYPI_DOWNLOAD` | `https://files.pythonhosted.org` | -| `upstream.maven` | `PROXY_UPSTREAM_MAVEN` | `https://repo1.maven.org/maven2` | -| `upstream.gradle_plugin_portal` | `PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL` | `https://plugins.gradle.org/m2` | -| `upstream.nuget` | `PROXY_UPSTREAM_NUGET` | `https://api.nuget.org` | -| `upstream.nuget_search` | `PROXY_UPSTREAM_NUGET_SEARCH` | `https://azuresearch-usnc.nuget.org` | -| `upstream.composer` | `PROXY_UPSTREAM_COMPOSER` | `https://packagist.org` | -| `upstream.composer_repository` | `PROXY_UPSTREAM_COMPOSER_REPOSITORY` | `https://repo.packagist.org` | -| `upstream.conan` | `PROXY_UPSTREAM_CONAN` | `https://center.conan.io` | -| `upstream.conda` | `PROXY_UPSTREAM_CONDA` | `https://conda.anaconda.org` | -| `upstream.cran` | `PROXY_UPSTREAM_CRAN` | `https://cloud.r-project.org` | -| `upstream.julia` | `PROXY_UPSTREAM_JULIA` | `https://pkg.julialang.org` | -| `upstream.swift` | `PROXY_UPSTREAM_SWIFT` | `https://tuist.dev/api/registry/swift` | -| `upstream.oci_default` | `PROXY_UPSTREAM_OCI_DEFAULT` | `https://registry-1.docker.io` | -| `upstream.debian` | `PROXY_UPSTREAM_DEBIAN` | `http://deb.debian.org/debian` | -| `upstream.rpm` | `PROXY_UPSTREAM_RPM` | `https://dl.fedoraproject.org/pub/fedora/linux` | -| `upstream.homebrew_api` | `PROXY_UPSTREAM_HOMEBREW_API` | `https://formulae.brew.sh/api` | -| `upstream.homebrew_artifact` | `PROXY_UPSTREAM_HOMEBREW_ARTIFACT` | `https://ghcr.io` | - -Private, ULA, CGNAT, and loopback addresses are rejected by default. Add each private upstream hostname or IP address to `upstream.allow_private_hosts`. The matching environment variable accepts a comma-separated list. Loopback upstreams also require `upstream.allow_loopback: true`. That setting permits upstream requests and redirects to reach any loopback address. +Override default upstream registry URLs: ```yaml upstream: - allow_private_hosts: - - "upstream-proxy.internal" - pypi: "http://upstream-proxy.internal/pypi" - pypi_download: "http://upstream-proxy.internal/pypi" + npm: "https://registry.npmjs.org" + cargo: "https://index.crates.io" + cargo_download: "https://static.crates.io/crates" ``` -For protocols that use separate metadata and download services, configure both values. They may point to the same endpoint when chaining proxies: - -```yaml -upstream: - pypi: "https://upstream-proxy.example.com/pypi" - pypi_download: "https://upstream-proxy.example.com/pypi" - nuget: "https://upstream-proxy.example.com/nuget" - nuget_search: "https://upstream-proxy.example.com/nuget" - composer: "https://upstream-proxy.example.com/composer" - composer_repository: "https://upstream-proxy.example.com/composer" -``` - -`upstream.hex_api` is used for cooldown timestamps and must expose Hex's `/api/packages/{name}` JSON endpoint. - -Helm HTTP repositories and additional OCI registries are configured as named maps: - -```yaml -upstream: - # Named HTTP Helm chart repositories, served at /helm/{name}/. - helm: - bitnami: "https://charts.bitnami.com/bitnami" - - # Named OCI registries. Select one with the repository prefix - # upstream/{name}/, e.g. oci://proxy.example.com/upstream/ghcr/owner/chart. - oci: - ghcr: "https://ghcr.io" -``` - -Helm HTTP repositories are read-only. The proxy fetches and rewrites each -repository's `index.yaml` so chart archives are downloaded through the proxy. -Chart archives are retained only when their SHA-256 digest matches the digest -listed in the index. Relative and absolute chart URLs are both supported. - -Generic HTTP upstreams proxy plain downloads from fixed base URLs: - -```yaml -upstream: - # Named HTTP upstreams, served at /generic/{name}/. The rest of the - # request path and the query string are appended to the upstream URL. - generic: - github: "https://github.com" - github-api: "https://api.github.com" - auth: - # Optional: raise the GitHub API rate limit. Scoped to this host only, - # so the token is never sent to the object store GitHub redirects to. - "https://api.github.com": - type: bearer - token: "${GITHUB_TOKEN}" -``` - -Only configured upstreams are reachable, so this is not an open HTTP proxy. -Paths shaped like `{owner}/{repo}/releases/download/{tag}/{asset}` are -version-pinned GitHub release assets: they are stored in the artifact cache -and served from it without revalidation, including while the upstream is -down. Every other path is served through the metadata cache (`cache_metadata` -must be enabled for offline fallback): fresh within `metadata_ttl`, then -revalidated with the upstream's `ETag`/`Last-Modified`, and served stale with -a `Warning: 110` header when the upstream fails, refuses or rate-limits the -request. Metadata responses are buffered up to `metadata_max_size`, so keep -large mutable downloads (`releases/latest/download/...`) off this route. - -This is the cache behind [mise](https://mise.jdx.dev)'s aqua backend; see the -mise section in the README for the client-side `url_replacements`. - -`upstream.oci_default` sets the registry used by unprefixed `/v2` requests, -while `upstream.oci` selects named registries through the `upstream/{name}/` -repository prefix. For example, `oci://proxy.example.com/upstream/ghcr/owner/chart` -uses the `ghcr` registry with `owner/chart` as its repository. -When the proxy uses plain HTTP (for example `localhost:8080`), pass -`--plain-http` to Helm OCI commands. - -```yaml -upstream: - - # Named Alpine APK repositories, served at /apk/{name}/. - apk: - alpine: "https://dl-cdn.alpinelinux.org/alpine" -``` - -Alpine APK repositories are read-only. Requests to `/apk/{name}/…` mirror the -upstream layout, e.g. `/apk/alpine/v3.22/main/x86_64/APKINDEX.tar.gz`. Indexes -(v2 `APKINDEX.tar.gz`, v3 `Packages.adb`) and detached signatures are cached -with the metadata TTL and served byte-for-byte unchanged so apk signature -verification keeps working; `.apk` packages use the shared artifact cache. -When `upstream.apk` is empty, a single repository named `alpine` pointing at -the official mirror is available; configuring any entry replaces that default. - ## Authentication -Configure authentication for private upstream registries. The same authentication-aware client is used for metadata and artifact downloads, and credentials can reference environment variables using `${VAR_NAME}` syntax. - -OCI registries that return a Bearer challenge from a `/v2/{repository}/…` endpoint are handled automatically. The proxy discovers the token realm from `WWW-Authenticate`, applies any configured credentials for the token URL, and reuses the scoped token until shortly before it expires. +Configure authentication for private upstream registries. Auth is matched by URL prefix, and credentials can reference environment variables using `${VAR_NAME}` syntax. ### Bearer Token @@ -316,24 +167,9 @@ upstream: header_value: "${MAVEN_TOKEN}" ``` -### AWS ECR - -Private ECR registries issue authorization tokens that expire after 12 hours. The `ecr` auth type calls `ecr:GetAuthorizationToken` on demand, caches the result, and refreshes it shortly before expiry, so no static credential appears in the config file: - -```yaml -upstream: - oci: - ecr: "https://123456789012.dkr.ecr.eu-west-1.amazonaws.com" - auth: - "https://123456789012.dkr.ecr.eu-west-1.amazonaws.com": - type: ecr -``` - -AWS credentials are resolved by the SDK's default chain, which covers EKS IAM Roles for Service Accounts (IRSA), EC2/ECS instance profiles, `AWS_ACCESS_KEY_ID` / `AWS_SECRET_ACCESS_KEY` environment variables, and `~/.aws/credentials`. The IAM identity needs the `ecr:GetAuthorizationToken` action plus the usual `ecr:BatchGetImage` / `ecr:GetDownloadUrlForLayer` permissions on the target repositories. The region is inferred from private ECR IPv4, dual-stack, and FIPS hostnames. For other endpoint formats, set `region` explicitly or configure a default region for the SDK. - ### URL Matching -Auth keys must be absolute URLs. Matching compares the scheme, host, effective port, and path-segment prefix, preventing credentials for `registry.example.com` from being sent to a lookalike host such as `registry.example.com.evil.test`. The longest matching scope wins, so you can configure different credentials for different paths: +Auth configs are matched by URL prefix. The longest matching prefix wins, so you can configure different credentials for different paths: ```yaml upstream: @@ -348,30 +184,6 @@ upstream: token: "${PRIVATE_TOKEN}" ``` -## Gradle Build Cache - -The `/gradle` endpoint supports optional safeguards for upload control and cache retention. - -```yaml -gradle: - build_cache: - read_only: false - max_upload_size: "100MB" - max_age: "168h" - max_size: "20GB" - sweep_interval: "10m" -``` - -| Config | Environment | Description | -|--------|-------------|-------------| -| `gradle.build_cache.read_only` | `PROXY_GRADLE_BUILD_CACHE_READ_ONLY` | Disable PUT uploads and keep GET/HEAD read-only | -| `gradle.build_cache.max_upload_size` | `PROXY_GRADLE_BUILD_CACHE_MAX_UPLOAD_SIZE` | Maximum accepted PUT body size (must be > 0) | -| `gradle.build_cache.max_age` | `PROXY_GRADLE_BUILD_CACHE_MAX_AGE` | Delete entries older than this duration (default `168h`, set `0` to disable) | -| `gradle.build_cache.max_size` | `PROXY_GRADLE_BUILD_CACHE_MAX_SIZE` | Total size cap for `_gradle/http-build-cache`, deleting oldest first (`0` disables) | -| `gradle.build_cache.sweep_interval` | `PROXY_GRADLE_BUILD_CACHE_SWEEP_INTERVAL` | Frequency for background eviction sweeps | - -`max_age` and `max_size` are independent and can be combined. When both are set, age-based eviction runs first, then size-based eviction trims remaining entries oldest-first. - ## Cooldown The cooldown feature hides package versions published too recently, giving the community time to spot malicious releases before they reach your projects. When a version is within its cooldown period, it's stripped from metadata responses so package managers won't install it. @@ -395,117 +207,16 @@ cooldown: Durations support days (`7d`), hours (`48h`), and minutes (`30m`). Set to `0` to disable. -Package PURL keys are normalized to canonical form before matching, so `pkg:npm/@babel/core` and `pkg:npm/%40babel/core` are equivalent, as are `pkg:pypi/Django` and `pkg:pypi/django`. If both forms configure the same package, the canonical entry wins. - Resolution order: package override, then ecosystem override, then global default. This lets you set a conservative default while exempting trusted packages. Currently supported for npm, PyPI, pub.dev, Composer, Cargo, NuGet, Conda, RubyGems, and Hex. These ecosystems include publish timestamps in their metadata. Note: Hex cooldown requires disabling registry signature verification since the proxy re-encodes the protobuf payload without the original signature. Set `HEX_NO_VERIFY_REPO_ORIGIN=1` or configure your repo with `no_verify: true`. -## Artifact Scanning - -Cooldown only ever looks at a version's *publish timestamp* — it never inspects the actual bytes of an artifact. Artifact scanning runs after a fetched artifact is staged into storage but before it becomes visible from cache, so an external scanner (trivy, ClamAV, Wiz, or any custom service) can block a bad verdict from ever reaching a client. - -```yaml -scanning: - enabled: true - fail_open: false - timeout: 30s - signing_key: ${PROXY_SCANNING_SIGNING_KEY} - fetch_base_url: http://proxy.internal:8080 - scanners: - - name: clamav - url: http://clamav-adapter:8080/scan - mode: block - - name: trivy - url: http://trivy-adapter:8081/scan - mode: monitor - ecosystems: [npm, pypi] -``` - -| Config | Environment | Description | -|--------|-------------|-------------| -| `scanning.enabled` | `PROXY_SCANNING_ENABLED` | Turn on the scan gate. When false (default), artifacts are cached exactly as if scanning didn't exist | -| `scanning.fail_open` | `PROXY_SCANNING_FAIL_OPEN` | Treat scanner errors/timeouts as allow instead of block. Default is fail-closed | -| `scanning.timeout` | `PROXY_SCANNING_TIMEOUT` | Per-scan-call timeout, Go duration syntax (default `30s`) | -| `scanning.signing_key` | `PROXY_SCANNING_SIGNING_KEY` | Signs pull requests to the internal scan-fetch route. Required whenever `enabled` is true | -| `scanning.fetch_base_url` | `PROXY_SCANNING_FETCH_BASE_URL` | Address scanners use to reach this proxy to pull staged artifacts. Defaults to `base_url` | -| `scanning.scanners` | - | List of external scanning services (YAML only) | -| `scanning.scanners[].name` | - | Identifies this scanner in logs and metrics | -| `scanning.scanners[].url` | - | Endpoint the proxy POSTs scan notifications to | -| `scanning.scanners[].mode` | - | `block` (default) or `monitor` | -| `scanning.scanners[].ecosystems` | - | Restricts this scanner to specific ecosystems (e.g. `npm`, `pypi`). Empty means all ecosystems | -| `scanning.scanners[].headers` | - | Extra HTTP headers sent with every scan request (e.g. for authenticating to the scanner service). Values support `${VAR_NAME}` expansion | - -### How caching defers to a scan verdict - -The proxy never uploads artifact bytes to a scanner. When an artifact is fetched from upstream, it's stored to the configured storage backend first, exactly as without scanning. If scanning is enabled for the artifact's ecosystem, the proxy then notifies each applicable scanner with package metadata and a short-lived, HMAC-signed URL pointing at the internal `/_internal/scan-fetch` route; each scanner GETs that URL itself to pull the exact bytes staged in storage and runs its own scan against them. - -Scanners configured for the same ecosystem all run concurrently, never sequentially. The moment any `block`-mode scanner reports a not-allowed verdict (or errors, unless `fail_open` is set), the proxy cancels the in-flight calls to the other scanners and deletes the staged artifact — it's never committed to the cache database, so it was never visible to a client. If nothing blocks, the proxy waits for every `block`-mode scanner to finish before caching the artifact and serving it. A `monitor`-mode scanner's findings are logged and never gate the wait or the caching decision, even when it reports not-allowed. - -A blocked download surfaces to the client as `403 Forbidden` with the scanner's reason, across every ecosystem handler. - -### Scanner HTTP contract - -Any external service that implements this contract can act as a scanner — a trivy wrapper, a clamav-rest bridge, a Wiz connector, or an in-house service. The proxy POSTs a notify request to `scanning.scanners[].url` and waits for a JSON verdict. - -**Request** - -| Field | Type | Description | -|-------|------|-------------| -| `ecosystem` | string | e.g. `npm`, `pypi`, `cargo` | -| `name` | string | Package name | -| `version` | string | Package version | -| `filename` | string | Artifact filename | -| `purl` | string | Package URL (PURL) identifying this exact version | -| `content_type` | string | Artifact content type | -| `size` | integer | Artifact size in bytes | -| `fetch_url` | string | Short-lived signed URL; GET this to retrieve the exact staged bytes | - -```json -{ - "ecosystem": "npm", "name": "left-pad", "version": "1.0.0", - "filename": "left-pad-1.0.0.tgz", "purl": "pkg:npm/left-pad@1.0.0", - "content_type": "application/octet-stream", "size": 1234, - "fetch_url": "https://proxy.internal/_internal/scan-fetch?path=...&exp=...&sig=..." -} -``` - -**Response** - -| Field | Type | Description | -|-------|------|-------------| -| `allowed` | boolean | Whether the artifact may be cached and served | -| `reason` | string | Human-readable reason, surfaced to the client when `allowed` is false | -| `findings` | array | Optional list of `{"severity", "title", "description"}` objects | - -```json -{ - "allowed": false, - "reason": "malware detected", - "findings": [ - {"severity": "critical", "title": "Trojan.GenericKD", "description": "..."} - ] -} -``` - -The scanner must respond within `scanning.timeout` (default `30s`); a timeout is treated the same as a `block` verdict unless `fail_open` is set. - -### The `/_internal/scan-fetch` route - -`fetch_url` points at an internal route, `/_internal/scan-fetch`, that streams a staged object straight from the proxy's storage backend via a short-lived HMAC-signed token (`path`, `exp`, `sig` query parameters). This works identically across every storage backend — local filesystem, S3, GCS, Azure — since it never depends on a backend-specific presigned URL, only on the one storage operation every backend already implements. - -This route is not part of the public API. It's meant only for scanners to pull artifacts they've been notified about, and should be restricted to internal-network access at the ingress/network-policy layer — the HMAC scoping (one object, a short TTL) limits what a leaked token can do, but isn't a substitute for network restriction. Its query parameters are also documented in the generated [OpenAPI spec](../README.md#openapi-swagger). - -The route only exists when scanning is actually configured: it's not mounted at all unless at least one scanner is enabled and `scanning.signing_key` is set, and it also refuses every request with `404` if either condition somehow isn't met at request time. There is no way to reach it, even with a forged token, when scanning is disabled. - ## Metadata Caching By default the proxy fetches metadata fresh from upstream on every request. Enable `cache_metadata` to store metadata responses in the database and storage backend for offline fallback. When upstream is unreachable, the proxy serves the last cached copy. ETag-based revalidation avoids re-downloading unchanged metadata. -OCI manifests and tag lists are always cached because cached image blobs cannot be pulled without their manifests and offline clients may need tag resolution. Digest-addressed manifests are immutable and served directly from cache. Tag-addressed manifests and tag lists follow `metadata_ttl`, revalidate when stale, and fall back to the last cached response when the registry is unavailable. - ```yaml cache_metadata: true ``` @@ -528,28 +239,6 @@ Set to `"0"` to always revalidate with upstream (ETag-based conditional requests When upstream is unreachable and the cached entry is past its TTL, the proxy serves the stale cached copy with a `Warning: 110 - "Response is Stale"` header so clients can tell the data may be outdated. -### Metadata size limit - -Upstream metadata responses are buffered in memory before being rewritten and served. `metadata_max_size` caps that buffer to protect against OOM from a misbehaving upstream. Some npm packages with thousands of versions (for example `renovate`) exceed the 100 MB default, so raise this if you see `metadata response exceeds size limit` in the logs. - -```yaml -metadata_max_size: "100MB" # default -``` - -Or via environment variable: `PROXY_METADATA_MAX_SIZE=250MB`. - -## Upstream HTTP timeout - -Protocol handlers use a shared HTTP client for upstream requests such as metadata fetches and pass-through file downloads. `http_timeout` sets that client's per-request timeout. Raise it if slow upstreams or large metadata responses cause `context deadline exceeded` errors. - -```yaml -http_timeout: "30s" # default -``` - -Or via environment variable: `PROXY_HTTP_TIMEOUT=2m`. - -Set to `"0"` to disable the timeout entirely (requests then rely only on the server's write timeout). Independently of this setting, the shared transport gives up on an upstream that has not sent response headers within 60 seconds. - ## Mirror API The `/api/mirror` endpoints are disabled by default. Enable them to allow starting mirror jobs via HTTP: @@ -562,14 +251,6 @@ Or via environment variable: `PROXY_MIRROR_API=true`. When disabled, the endpoints are not registered and return 404. -Start a mirror job with either PURLs or an inline CycloneDX or SPDX JSON document: - -```bash -curl -X POST http://localhost:8080/api/mirror \ - -H "Content-Type: application/json" \ - -d '{"sbom":{"bomFormat":"CycloneDX","components":[{"purl":"pkg:npm/lodash@4.17.21"}]}}' -``` - ## Mirror Command The `proxy mirror` command pre-populates the cache from various sources. It accepts the same storage and database flags as `serve`. diff --git a/docs/swagger/docs.go b/docs/swagger/docs.go index cc88b4c..fedf889 100644 --- a/docs/swagger/docs.go +++ b/docs/swagger/docs.go @@ -15,301 +15,7 @@ const docTemplate = `{ "host": "{{.Host}}", "basePath": "{{.BasePath}}", "paths": { - "/_internal/scan-fetch": { - "get": { - "description": "Streams the exact bytes staged in storage for a pre-cache security scan.\nRequires a short-lived HMAC-signed token minted by the proxy itself and\ndelivered via the fetch_url field of the scan notify request (see the\nArtifact Scanning section of docs/configuration.md). Not part of the\npublic API; restrict access to the scanner network at the ingress layer.", - "produces": [ - "application/octet-stream" - ], - "tags": [ - "scanning" - ], - "summary": "Fetch a staged artifact for scanning", - "parameters": [ - { - "type": "string", - "description": "Storage path of the staged artifact", - "name": "path", - "in": "query", - "required": true - }, - { - "type": "integer", - "description": "Token expiry, Unix seconds", - "name": "exp", - "in": "query", - "required": true - }, - { - "type": "string", - "description": "HMAC-SHA256 signature over the string path|exp", - "name": "sig", - "in": "query", - "required": true - } - ], - "responses": { - "200": { - "description": "OK", - "schema": { - "type": "file" - } - }, - "403": { - "description": "invalid, expired, or tampered token", - "schema": { - "type": "string" - } - }, - "404": { - "description": "object not found in storage, or scanning is not configured", - "schema": { - "type": "string" - } - } - } - } - }, - "/api/bulk": { - "post": { - "consumes": [ - "application/json" - ], - "produces": [ - "application/json" - ], - "tags": [ - "api" - ], - "summary": "Bulk package lookup by PURL", - "parameters": [ - { - "description": "PURLs", - "name": "request", - "in": "body", - "required": true, - "schema": { - "$ref": "#/definitions/server.BulkRequest" - } - } - ], - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.BulkResponse" - } - }, - "400": { - "description": "Bad Request", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - }, - "500": { - "description": "Internal Server Error", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - } - } - } - }, - "/api/outdated": { - "post": { - "consumes": [ - "application/json" - ], - "produces": [ - "application/json" - ], - "tags": [ - "api" - ], - "summary": "Check outdated packages", - "parameters": [ - { - "description": "Packages to check", - "name": "request", - "in": "body", - "required": true, - "schema": { - "$ref": "#/definitions/server.OutdatedRequest" - } - } - ], - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.OutdatedResponse" - } - }, - "400": { - "description": "Bad Request", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - }, - "500": { - "description": "Internal Server Error", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - } - } - } - }, - "/api/packages": { - "get": { - "produces": [ - "application/json" - ], - "tags": [ - "api" - ], - "summary": "List cached packages", - "parameters": [ - { - "type": "string", - "description": "Ecosystem", - "name": "ecosystem", - "in": "query" - }, - { - "enum": [ - "hits", - "name", - "size", - "cached_at", - "ecosystem", - "vulns" - ], - "type": "string", - "description": "Sort", - "name": "sort", - "in": "query" - } - ], - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.PackagesListResponse" - } - }, - "400": { - "description": "Bad Request", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - }, - "500": { - "description": "Internal Server Error", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - } - } - } - }, - "/api/search": { - "get": { - "produces": [ - "application/json" - ], - "tags": [ - "api" - ], - "summary": "Search cached packages", - "parameters": [ - { - "type": "string", - "description": "Query", - "name": "q", - "in": "query", - "required": true - }, - { - "type": "string", - "description": "Ecosystem", - "name": "ecosystem", - "in": "query" - } - ], - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.SearchResponse" - } - }, - "400": { - "description": "Bad Request", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - }, - "500": { - "description": "Internal Server Error", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - } - } - } - }, - "/health": { - "get": { - "produces": [ - "application/json" - ], - "tags": [ - "meta" - ], - "summary": "Health check", - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.HealthResponse" - } - }, - "503": { - "description": "Service Unavailable", - "schema": { - "$ref": "#/definitions/server.HealthResponse" - } - } - } - } - }, - "/stats": { - "get": { - "produces": [ - "application/json" - ], - "tags": [ - "meta" - ], - "summary": "Cache statistics", - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.StatsResponse" - } - }, - "500": { - "description": "Internal Server Error", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - } - } - } - }, - "/ui/api/browse/{ecosystem}/{name}/{version}": { + "/api/browse/{ecosystem}/{name}/{version}": { "get": { "description": "Lists files from the first cached artifact for a package version.", "produces": [ @@ -358,19 +64,19 @@ const docTemplate = `{ "404": { "description": "Not Found", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } }, "500": { "description": "Internal Server Error", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } } } } }, - "/ui/api/browse/{ecosystem}/{name}/{version}/file/{filepath}": { + "/api/browse/{ecosystem}/{name}/{version}/file/{filepath}": { "get": { "description": "Streams a single file from the cached artifact. The file path may contain slashes.", "produces": [ @@ -420,25 +126,70 @@ const docTemplate = `{ "400": { "description": "Bad Request", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } }, "404": { "description": "Not Found", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } }, "500": { "description": "Internal Server Error", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } } } } }, - "/ui/api/compare/{ecosystem}/{name}/{fromVersion}/{toVersion}": { + "/api/bulk": { + "post": { + "consumes": [ + "application/json" + ], + "produces": [ + "application/json" + ], + "tags": [ + "api" + ], + "summary": "Bulk package lookup by PURL", + "parameters": [ + { + "description": "PURLs", + "name": "request", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/server.BulkRequest" + } + } + ], + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/server.BulkResponse" + } + }, + "400": { + "description": "Bad Request", + "schema": { + "type": "string" + } + }, + "500": { + "description": "Internal Server Error", + "schema": { + "type": "string" + } + } + } + } + }, + "/api/compare/{ecosystem}/{name}/{fromVersion}/{toVersion}": { "get": { "description": "Returns a structured diff for two cached versions.", "produces": [ @@ -489,13 +240,207 @@ const docTemplate = `{ "404": { "description": "Not Found", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } }, "500": { "description": "Internal Server Error", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" + } + } + } + } + }, + "/api/outdated": { + "post": { + "consumes": [ + "application/json" + ], + "produces": [ + "application/json" + ], + "tags": [ + "api" + ], + "summary": "Check outdated packages", + "parameters": [ + { + "description": "Packages to check", + "name": "request", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/server.OutdatedRequest" + } + } + ], + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/server.OutdatedResponse" + } + }, + "400": { + "description": "Bad Request", + "schema": { + "type": "string" + } + }, + "500": { + "description": "Internal Server Error", + "schema": { + "type": "string" + } + } + } + } + }, + "/api/packages": { + "get": { + "produces": [ + "application/json" + ], + "tags": [ + "api" + ], + "summary": "List cached packages", + "parameters": [ + { + "type": "string", + "description": "Ecosystem", + "name": "ecosystem", + "in": "query" + }, + { + "enum": [ + "hits", + "name", + "size", + "cached_at", + "ecosystem", + "vulns" + ], + "type": "string", + "description": "Sort", + "name": "sort", + "in": "query" + } + ], + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/server.PackagesListResponse" + } + }, + "400": { + "description": "Bad Request", + "schema": { + "type": "string" + } + }, + "500": { + "description": "Internal Server Error", + "schema": { + "type": "string" + } + } + } + } + }, + "/api/search": { + "get": { + "produces": [ + "application/json" + ], + "tags": [ + "api" + ], + "summary": "Search cached packages", + "parameters": [ + { + "type": "string", + "description": "Query", + "name": "q", + "in": "query", + "required": true + }, + { + "type": "string", + "description": "Ecosystem", + "name": "ecosystem", + "in": "query" + } + ], + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/server.SearchResponse" + } + }, + "400": { + "description": "Bad Request", + "schema": { + "type": "string" + } + }, + "500": { + "description": "Internal Server Error", + "schema": { + "type": "string" + } + } + } + } + }, + "/health": { + "get": { + "produces": [ + "text/plain" + ], + "tags": [ + "meta" + ], + "summary": "Health check", + "responses": { + "200": { + "description": "OK", + "schema": { + "type": "string" + } + }, + "503": { + "description": "Service Unavailable", + "schema": { + "type": "string" + } + } + } + } + }, + "/stats": { + "get": { + "produces": [ + "application/json" + ], + "tags": [ + "meta" + ], + "summary": "Cache statistics", + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/server.StatsResponse" + } + }, + "500": { + "description": "Internal Server Error", + "schema": { + "type": "string" } } } @@ -559,52 +504,6 @@ const docTemplate = `{ } } }, - "server.ErrorResponse": { - "type": "object", - "properties": { - "code": { - "type": "string" - }, - "message": { - "type": "string" - } - } - }, - "server.HealthCheck": { - "type": "object", - "properties": { - "error": { - "type": "string" - }, - "status": { - "type": "string" - }, - "step": { - "type": "string" - } - } - }, - "server.HealthResponse": { - "type": "object", - "properties": { - "checks": { - "type": "object", - "additionalProperties": { - "$ref": "#/definitions/server.HealthCheck" - } - }, - "circuit_breakers": { - "description": "CircuitBreakers reports the state (\"open\" or \"closed\") of each upstream\nregistry's artifact-fetch circuit breaker, keyed by the host fetched from\nor, where the fetch URL has none to read, by an opaque placeholder\nstanding in for it. It is omitted when no breaker has been created yet.\nAn open breaker fails every artifact fetch it covers without contacting\nthe upstream, but says nothing about this proxy's own health, so it does\nnot change Status.", - "type": "object", - "additionalProperties": { - "type": "string" - } - }, - "status": { - "type": "string" - } - } - }, "server.OutdatedPackage": { "type": "object", "properties": { diff --git a/docs/swagger/swagger.json b/docs/swagger/swagger.json index 5db9166..88df1e9 100644 --- a/docs/swagger/swagger.json +++ b/docs/swagger/swagger.json @@ -8,301 +8,7 @@ }, "basePath": "/", "paths": { - "/_internal/scan-fetch": { - "get": { - "description": "Streams the exact bytes staged in storage for a pre-cache security scan.\nRequires a short-lived HMAC-signed token minted by the proxy itself and\ndelivered via the fetch_url field of the scan notify request (see the\nArtifact Scanning section of docs/configuration.md). Not part of the\npublic API; restrict access to the scanner network at the ingress layer.", - "produces": [ - "application/octet-stream" - ], - "tags": [ - "scanning" - ], - "summary": "Fetch a staged artifact for scanning", - "parameters": [ - { - "type": "string", - "description": "Storage path of the staged artifact", - "name": "path", - "in": "query", - "required": true - }, - { - "type": "integer", - "description": "Token expiry, Unix seconds", - "name": "exp", - "in": "query", - "required": true - }, - { - "type": "string", - "description": "HMAC-SHA256 signature over the string path|exp", - "name": "sig", - "in": "query", - "required": true - } - ], - "responses": { - "200": { - "description": "OK", - "schema": { - "type": "file" - } - }, - "403": { - "description": "invalid, expired, or tampered token", - "schema": { - "type": "string" - } - }, - "404": { - "description": "object not found in storage, or scanning is not configured", - "schema": { - "type": "string" - } - } - } - } - }, - "/api/bulk": { - "post": { - "consumes": [ - "application/json" - ], - "produces": [ - "application/json" - ], - "tags": [ - "api" - ], - "summary": "Bulk package lookup by PURL", - "parameters": [ - { - "description": "PURLs", - "name": "request", - "in": "body", - "required": true, - "schema": { - "$ref": "#/definitions/server.BulkRequest" - } - } - ], - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.BulkResponse" - } - }, - "400": { - "description": "Bad Request", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - }, - "500": { - "description": "Internal Server Error", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - } - } - } - }, - "/api/outdated": { - "post": { - "consumes": [ - "application/json" - ], - "produces": [ - "application/json" - ], - "tags": [ - "api" - ], - "summary": "Check outdated packages", - "parameters": [ - { - "description": "Packages to check", - "name": "request", - "in": "body", - "required": true, - "schema": { - "$ref": "#/definitions/server.OutdatedRequest" - } - } - ], - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.OutdatedResponse" - } - }, - "400": { - "description": "Bad Request", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - }, - "500": { - "description": "Internal Server Error", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - } - } - } - }, - "/api/packages": { - "get": { - "produces": [ - "application/json" - ], - "tags": [ - "api" - ], - "summary": "List cached packages", - "parameters": [ - { - "type": "string", - "description": "Ecosystem", - "name": "ecosystem", - "in": "query" - }, - { - "enum": [ - "hits", - "name", - "size", - "cached_at", - "ecosystem", - "vulns" - ], - "type": "string", - "description": "Sort", - "name": "sort", - "in": "query" - } - ], - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.PackagesListResponse" - } - }, - "400": { - "description": "Bad Request", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - }, - "500": { - "description": "Internal Server Error", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - } - } - } - }, - "/api/search": { - "get": { - "produces": [ - "application/json" - ], - "tags": [ - "api" - ], - "summary": "Search cached packages", - "parameters": [ - { - "type": "string", - "description": "Query", - "name": "q", - "in": "query", - "required": true - }, - { - "type": "string", - "description": "Ecosystem", - "name": "ecosystem", - "in": "query" - } - ], - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.SearchResponse" - } - }, - "400": { - "description": "Bad Request", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - }, - "500": { - "description": "Internal Server Error", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - } - } - } - }, - "/health": { - "get": { - "produces": [ - "application/json" - ], - "tags": [ - "meta" - ], - "summary": "Health check", - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.HealthResponse" - } - }, - "503": { - "description": "Service Unavailable", - "schema": { - "$ref": "#/definitions/server.HealthResponse" - } - } - } - } - }, - "/stats": { - "get": { - "produces": [ - "application/json" - ], - "tags": [ - "meta" - ], - "summary": "Cache statistics", - "responses": { - "200": { - "description": "OK", - "schema": { - "$ref": "#/definitions/server.StatsResponse" - } - }, - "500": { - "description": "Internal Server Error", - "schema": { - "$ref": "#/definitions/server.ErrorResponse" - } - } - } - } - }, - "/ui/api/browse/{ecosystem}/{name}/{version}": { + "/api/browse/{ecosystem}/{name}/{version}": { "get": { "description": "Lists files from the first cached artifact for a package version.", "produces": [ @@ -351,19 +57,19 @@ "404": { "description": "Not Found", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } }, "500": { "description": "Internal Server Error", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } } } } }, - "/ui/api/browse/{ecosystem}/{name}/{version}/file/{filepath}": { + "/api/browse/{ecosystem}/{name}/{version}/file/{filepath}": { "get": { "description": "Streams a single file from the cached artifact. The file path may contain slashes.", "produces": [ @@ -413,25 +119,70 @@ "400": { "description": "Bad Request", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } }, "404": { "description": "Not Found", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } }, "500": { "description": "Internal Server Error", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } } } } }, - "/ui/api/compare/{ecosystem}/{name}/{fromVersion}/{toVersion}": { + "/api/bulk": { + "post": { + "consumes": [ + "application/json" + ], + "produces": [ + "application/json" + ], + "tags": [ + "api" + ], + "summary": "Bulk package lookup by PURL", + "parameters": [ + { + "description": "PURLs", + "name": "request", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/server.BulkRequest" + } + } + ], + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/server.BulkResponse" + } + }, + "400": { + "description": "Bad Request", + "schema": { + "type": "string" + } + }, + "500": { + "description": "Internal Server Error", + "schema": { + "type": "string" + } + } + } + } + }, + "/api/compare/{ecosystem}/{name}/{fromVersion}/{toVersion}": { "get": { "description": "Returns a structured diff for two cached versions.", "produces": [ @@ -482,13 +233,207 @@ "404": { "description": "Not Found", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" } }, "500": { "description": "Internal Server Error", "schema": { - "$ref": "#/definitions/server.ErrorResponse" + "type": "string" + } + } + } + } + }, + "/api/outdated": { + "post": { + "consumes": [ + "application/json" + ], + "produces": [ + "application/json" + ], + "tags": [ + "api" + ], + "summary": "Check outdated packages", + "parameters": [ + { + "description": "Packages to check", + "name": "request", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/server.OutdatedRequest" + } + } + ], + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/server.OutdatedResponse" + } + }, + "400": { + "description": "Bad Request", + "schema": { + "type": "string" + } + }, + "500": { + "description": "Internal Server Error", + "schema": { + "type": "string" + } + } + } + } + }, + "/api/packages": { + "get": { + "produces": [ + "application/json" + ], + "tags": [ + "api" + ], + "summary": "List cached packages", + "parameters": [ + { + "type": "string", + "description": "Ecosystem", + "name": "ecosystem", + "in": "query" + }, + { + "enum": [ + "hits", + "name", + "size", + "cached_at", + "ecosystem", + "vulns" + ], + "type": "string", + "description": "Sort", + "name": "sort", + "in": "query" + } + ], + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/server.PackagesListResponse" + } + }, + "400": { + "description": "Bad Request", + "schema": { + "type": "string" + } + }, + "500": { + "description": "Internal Server Error", + "schema": { + "type": "string" + } + } + } + } + }, + "/api/search": { + "get": { + "produces": [ + "application/json" + ], + "tags": [ + "api" + ], + "summary": "Search cached packages", + "parameters": [ + { + "type": "string", + "description": "Query", + "name": "q", + "in": "query", + "required": true + }, + { + "type": "string", + "description": "Ecosystem", + "name": "ecosystem", + "in": "query" + } + ], + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/server.SearchResponse" + } + }, + "400": { + "description": "Bad Request", + "schema": { + "type": "string" + } + }, + "500": { + "description": "Internal Server Error", + "schema": { + "type": "string" + } + } + } + } + }, + "/health": { + "get": { + "produces": [ + "text/plain" + ], + "tags": [ + "meta" + ], + "summary": "Health check", + "responses": { + "200": { + "description": "OK", + "schema": { + "type": "string" + } + }, + "503": { + "description": "Service Unavailable", + "schema": { + "type": "string" + } + } + } + } + }, + "/stats": { + "get": { + "produces": [ + "application/json" + ], + "tags": [ + "meta" + ], + "summary": "Cache statistics", + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/server.StatsResponse" + } + }, + "500": { + "description": "Internal Server Error", + "schema": { + "type": "string" } } } @@ -552,52 +497,6 @@ } } }, - "server.ErrorResponse": { - "type": "object", - "properties": { - "code": { - "type": "string" - }, - "message": { - "type": "string" - } - } - }, - "server.HealthCheck": { - "type": "object", - "properties": { - "error": { - "type": "string" - }, - "status": { - "type": "string" - }, - "step": { - "type": "string" - } - } - }, - "server.HealthResponse": { - "type": "object", - "properties": { - "checks": { - "type": "object", - "additionalProperties": { - "$ref": "#/definitions/server.HealthCheck" - } - }, - "circuit_breakers": { - "description": "CircuitBreakers reports the state (\"open\" or \"closed\") of each upstream\nregistry's artifact-fetch circuit breaker, keyed by the host fetched from\nor, where the fetch URL has none to read, by an opaque placeholder\nstanding in for it. It is omitted when no breaker has been created yet.\nAn open breaker fails every artifact fetch it covers without contacting\nthe upstream, but says nothing about this proxy's own health, so it does\nnot change Status.", - "type": "object", - "additionalProperties": { - "type": "string" - } - }, - "status": { - "type": "string" - } - } - }, "server.OutdatedPackage": { "type": "object", "properties": { diff --git a/go.mod b/go.mod index 6de540f..85869db 100644 --- a/go.mod +++ b/go.mod @@ -1,143 +1,125 @@ module github.com/git-pkgs/proxy -go 1.26.7 +go 1.25.6 require ( - github.com/BurntSushi/toml v1.6.0 - github.com/CycloneDX/cyclonedx-go v0.12.0 - github.com/aws/aws-sdk-go-v2/config v1.33.2 - github.com/aws/aws-sdk-go-v2/service/ecr v1.64.0 - github.com/git-pkgs/archives v0.7.0 - github.com/git-pkgs/artifacts v0.2.1 - github.com/git-pkgs/cooldown v0.2.0 - github.com/git-pkgs/enrichment v0.7.1 - github.com/git-pkgs/gcs v0.1.0 - github.com/git-pkgs/integrity v0.1.1 - github.com/git-pkgs/magic v0.3.1 - github.com/git-pkgs/purl v0.1.20 - github.com/git-pkgs/registries v0.9.1 - github.com/git-pkgs/spdx v0.3.1 - github.com/git-pkgs/vers v0.7.0 - github.com/git-pkgs/vulns v0.2.3 - github.com/go-chi/chi/v5 v5.3.2 + github.com/CycloneDX/cyclonedx-go v0.10.0 + github.com/git-pkgs/archives v0.2.2 + github.com/git-pkgs/enrichment v0.2.2 + github.com/git-pkgs/purl v0.1.10 + github.com/git-pkgs/registries v0.4.0 + github.com/git-pkgs/spdx v0.1.2 + github.com/git-pkgs/vers v0.2.4 + github.com/git-pkgs/vulns v0.1.4 + github.com/go-chi/chi/v5 v5.2.5 github.com/jmoiron/sqlx v1.4.0 - github.com/lib/pq v1.12.3 - github.com/opencontainers/go-digest v1.0.0 - github.com/prometheus/client_golang v1.24.1 - github.com/prometheus/client_model v0.6.3 + github.com/lib/pq v1.12.2 + github.com/prometheus/client_golang v1.23.2 + github.com/prometheus/client_model v0.6.2 github.com/spdx/tools-golang v0.5.7 github.com/swaggo/swag v1.16.6 - gocloud.dev v0.46.0 - golang.org/x/sync v0.23.0 - google.golang.org/protobuf v1.36.12 + gocloud.dev v0.45.0 + golang.org/x/sync v0.20.0 + google.golang.org/protobuf v1.36.11 gopkg.in/yaml.v3 v3.0.1 - modernc.org/sqlite v1.58.0 + modernc.org/sqlite v1.48.0 ) require ( - 4d63.com/gocheckcompilerdirectives v1.4.0 // indirect + 4d63.com/gocheckcompilerdirectives v1.3.0 // indirect 4d63.com/gochecknoglobals v0.2.2 // indirect - charm.land/lipgloss/v2 v2.0.6 // indirect - cloud.google.com/go/auth v0.21.0 // indirect - cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect cloud.google.com/go/compute/metadata v0.9.0 // indirect codeberg.org/chavacava/garif v0.2.0 // indirect codeberg.org/polyfloyd/go-errorlint v1.9.0 // indirect dev.gaijin.team/go/exhaustruct/v4 v4.0.0 // indirect - dev.gaijin.team/go/exhaustruct/v5 v5.0.3 // indirect - dev.gaijin.team/go/golib v0.8.1 // indirect + dev.gaijin.team/go/golib v0.6.0 // indirect github.com/4meepo/tagalign v1.4.3 // indirect - github.com/Abirdcfly/dupword v0.1.8 // indirect + github.com/Abirdcfly/dupword v0.1.7 // indirect github.com/AdminBenni/iota-mixing v1.0.0 // indirect - github.com/AlwxSin/noinlineerr v1.0.6 // indirect - github.com/Antonboom/errname v1.1.2 // indirect - github.com/Antonboom/nilnil v1.1.2 // indirect + github.com/AlwxSin/noinlineerr v1.0.5 // indirect + github.com/Antonboom/errname v1.1.1 // indirect + github.com/Antonboom/nilnil v1.1.1 // indirect github.com/Antonboom/testifylint v1.6.4 // indirect - github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 // indirect - github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 // indirect - github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.6.4 // indirect - github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0 // indirect - github.com/ClickHouse/clickhouse-go-linter v1.2.1 // indirect + github.com/BurntSushi/toml v1.6.0 // indirect github.com/Djarvur/go-err113 v0.1.1 // indirect github.com/KyleBanks/depth v1.2.1 // indirect - github.com/Masterminds/semver/v3 v3.5.0 // indirect - github.com/MirrexOne/unqueryvet v1.5.4 // indirect + github.com/Masterminds/semver/v3 v3.4.0 // indirect + github.com/MirrexOne/unqueryvet v1.5.3 // indirect github.com/OpenPeeDeeP/depguard/v2 v2.2.1 // indirect github.com/PuerkitoBio/purell v1.1.1 // indirect github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect - github.com/alecthomas/chroma/v2 v2.27.0 // indirect + github.com/alecthomas/chroma/v2 v2.23.1 // indirect github.com/alecthomas/go-check-sumtype v0.3.1 // indirect github.com/alexkohler/nakedret/v2 v2.0.6 // indirect - github.com/alexkohler/prealloc v1.1.0 // indirect + github.com/alexkohler/prealloc v1.0.2 // indirect github.com/alfatraining/structtag v1.0.0 // indirect github.com/alingse/asasalint v0.0.11 // indirect github.com/alingse/nilnesserr v0.2.0 // indirect github.com/anchore/go-struct-converter v0.1.0 // indirect github.com/apapsch/go-jsonmerge/v2 v2.0.0 // indirect - github.com/ashanbrown/forbidigo/v2 v2.3.1 // indirect - github.com/ashanbrown/makezero/v2 v2.2.1 // indirect - github.com/aws/aws-sdk-go-v2 v1.46.0 // indirect - github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11 // indirect - github.com/aws/aws-sdk-go-v2/credentials v1.20.2 // indirect - github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.19.1 // indirect - github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.2.3 // indirect - github.com/aws/aws-sdk-go-v2/internal/configsources v1.5.2 // indirect - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.8.2 // indirect - github.com/aws/aws-sdk-go-v2/internal/v4a v1.5.1 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.18 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.14.1 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.25 // indirect - github.com/aws/aws-sdk-go-v2/service/s3 v1.102.2 // indirect - github.com/aws/aws-sdk-go-v2/service/signin v1.8.0 // indirect - github.com/aws/aws-sdk-go-v2/service/sso v1.36.0 // indirect - github.com/aws/aws-sdk-go-v2/service/ssooidc v1.41.0 // indirect - github.com/aws/aws-sdk-go-v2/service/sts v1.48.0 // indirect - github.com/aws/smithy-go v1.28.1 // indirect + github.com/ashanbrown/forbidigo/v2 v2.3.0 // indirect + github.com/ashanbrown/makezero/v2 v2.1.0 // indirect + github.com/aws/aws-sdk-go-v2 v1.41.3 // indirect + github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.6 // indirect + github.com/aws/aws-sdk-go-v2/config v1.32.11 // indirect + github.com/aws/aws-sdk-go-v2/credentials v1.19.11 // indirect + github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.19 // indirect + github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.5 // indirect + github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.19 // indirect + github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.19 // indirect + github.com/aws/aws-sdk-go-v2/internal/ini v1.8.5 // indirect + github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.19 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.6 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.11 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.19 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.19 // indirect + github.com/aws/aws-sdk-go-v2/service/s3 v1.96.3 // indirect + github.com/aws/aws-sdk-go-v2/service/signin v1.0.7 // indirect + github.com/aws/aws-sdk-go-v2/service/sso v1.30.12 // indirect + github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.16 // indirect + github.com/aws/aws-sdk-go-v2/service/sts v1.41.8 // indirect + github.com/aws/smithy-go v1.24.2 // indirect + github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect github.com/beorn7/perks v1.0.1 // indirect github.com/bkielbasa/cyclop v1.2.3 // indirect github.com/blizzy78/varnamelen v0.8.0 // indirect github.com/bombsimon/wsl/v4 v4.7.0 // indirect - github.com/bombsimon/wsl/v5 v5.9.0 // indirect + github.com/bombsimon/wsl/v5 v5.6.0 // indirect github.com/breml/bidichk v0.3.3 // indirect github.com/breml/errchkjson v0.4.1 // indirect - github.com/butuzov/ireturn v0.4.1 // indirect - github.com/butuzov/mirror v1.3.3 // indirect + github.com/butuzov/ireturn v0.4.0 // indirect + github.com/butuzov/mirror v1.3.0 // indirect github.com/catenacyber/perfsprint v0.10.1 // indirect github.com/ccojocar/zxcvbn-go v1.0.4 // indirect github.com/cenk/backoff v2.2.1+incompatible // indirect github.com/cespare/xxhash/v2 v2.3.0 // indirect github.com/charithe/durationcheck v0.0.11 // indirect - github.com/charmbracelet/colorprofile v0.4.3 // indirect - github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886 // indirect - github.com/charmbracelet/x/ansi v0.11.8 // indirect - github.com/charmbracelet/x/term v0.2.2 // indirect - github.com/charmbracelet/x/termios v0.1.1 // indirect - github.com/charmbracelet/x/windows v0.2.2 // indirect + github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc // indirect + github.com/charmbracelet/lipgloss v1.1.0 // indirect + github.com/charmbracelet/x/ansi v0.10.1 // indirect + github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd // indirect + github.com/charmbracelet/x/term v0.2.1 // indirect github.com/ckaznocha/intrange v0.3.1 // indirect - github.com/clipperhouse/displaywidth v0.11.0 // indirect - github.com/clipperhouse/uax29/v2 v2.7.0 // indirect github.com/cpuguy83/go-md2man/v2 v2.0.6 // indirect github.com/curioswitch/go-reassign v0.3.0 // indirect github.com/daixiang0/gci v0.13.7 // indirect github.com/dave/dst v0.27.3 // indirect + github.com/davecgh/go-spew v1.1.1 // indirect github.com/denis-tingaikin/go-header v0.5.0 // indirect - github.com/dlclark/regexp2/v2 v2.2.1 // indirect + github.com/dlclark/regexp2 v1.11.5 // indirect github.com/dustin/go-humanize v1.0.1 // indirect - github.com/ecosyste-ms/ecosystems-go v0.4.0 // indirect + github.com/ecosyste-ms/ecosystems-go v0.1.1 // indirect github.com/ettle/strcase v0.2.0 // indirect github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a // indirect - github.com/fatih/color v1.19.0 // indirect + github.com/fatih/color v1.18.0 // indirect github.com/fatih/structtag v1.2.0 // indirect - github.com/firefart/nonamedreturns v1.0.8 // indirect + github.com/firefart/nonamedreturns v1.0.6 // indirect github.com/fsnotify/fsnotify v1.9.0 // indirect github.com/fzipp/gocyclo v0.6.0 // indirect - github.com/ghostiam/protogetter v0.3.21 // indirect + github.com/ghostiam/protogetter v0.3.20 // indirect github.com/git-pkgs/packageurl-go v0.3.1 // indirect - github.com/git-pkgs/pom v0.1.7 // indirect - github.com/github/go-spdx/v2 v2.7.0 // indirect - github.com/go-critic/go-critic v0.14.4 // indirect + github.com/github/go-spdx/v2 v2.4.0 // indirect + github.com/go-critic/go-critic v0.14.3 // indirect github.com/go-logr/logr v1.4.3 // indirect github.com/go-logr/stdr v1.2.2 // indirect github.com/go-openapi/jsonpointer v0.19.5 // indirect @@ -156,111 +138,103 @@ require ( github.com/gobwas/glob v0.2.3 // indirect github.com/godoc-lint/godoc-lint v0.11.2 // indirect github.com/gofrs/flock v0.13.0 // indirect - github.com/golang-jwt/jwt/v5 v5.3.1 // indirect github.com/golangci/asciicheck v0.5.0 // indirect - github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202 // indirect + github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32 // indirect github.com/golangci/go-printf-func-name v0.1.1 // indirect - github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792 // indirect - github.com/golangci/golangci-lint/v2 v2.13.1 // indirect + github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d // indirect + github.com/golangci/golangci-lint/v2 v2.10.1 // indirect github.com/golangci/golines v0.15.0 // indirect github.com/golangci/misspell v0.8.0 // indirect github.com/golangci/plugin-module-register v0.1.2 // indirect github.com/golangci/revgrep v0.8.0 // indirect - github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba // indirect github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e // indirect github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e // indirect github.com/google/go-cmp v0.7.0 // indirect - github.com/google/s2a-go v0.1.9 // indirect github.com/google/uuid v1.6.0 // indirect github.com/google/wire v0.7.0 // indirect - github.com/googleapis/enterprise-certificate-proxy v0.3.18 // indirect - github.com/googleapis/gax-go/v2 v2.23.0 // indirect + github.com/googleapis/gax-go/v2 v2.17.0 // indirect github.com/gordonklaus/ineffassign v0.2.0 // indirect github.com/gostaticanalysis/analysisutil v0.7.1 // indirect github.com/gostaticanalysis/comment v1.5.0 // indirect github.com/gostaticanalysis/forcetypeassert v0.2.0 // indirect github.com/gostaticanalysis/nilerr v0.1.2 // indirect github.com/hashicorp/go-immutable-radix/v2 v2.1.0 // indirect - github.com/hashicorp/go-version v1.9.0 // indirect + github.com/hashicorp/go-version v1.8.0 // indirect github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect github.com/hashicorp/hcl v1.0.0 // indirect github.com/hexops/gotextdiff v1.0.3 // indirect github.com/inconshreveable/mousetrap v1.1.0 // indirect - github.com/jgautheron/goconst v1.11.0 // indirect + github.com/jgautheron/goconst v1.8.2 // indirect + github.com/jingyugao/rowserrcheck v1.1.1 // indirect github.com/jjti/go-spancheck v0.6.5 // indirect github.com/josharian/intern v1.0.0 // indirect github.com/julz/importas v0.2.0 // indirect github.com/karamaru-alpha/copyloopvar v1.2.2 // indirect - github.com/kisielk/errcheck v1.20.0 // indirect + github.com/kisielk/errcheck v1.9.0 // indirect github.com/kkHAIKE/contextcheck v1.1.6 // indirect - github.com/klauspost/compress v1.19.2 // indirect github.com/kulti/thelper v0.7.1 // indirect github.com/kunwardeep/paralleltest v1.0.15 // indirect - github.com/kylelemons/godebug v1.1.0 // indirect github.com/lasiar/canonicalheader v1.1.2 // indirect github.com/ldez/exptostd v0.4.5 // indirect - github.com/ldez/gomoddirectives v0.9.0 // indirect + github.com/ldez/gomoddirectives v0.8.0 // indirect github.com/ldez/grignotin v0.10.1 // indirect github.com/ldez/structtags v0.6.1 // indirect github.com/ldez/tagliatelle v0.7.2 // indirect github.com/ldez/usetesting v0.5.0 // indirect github.com/leonklingele/grouper v1.1.2 // indirect - github.com/lucasb-eyer/go-colorful v1.4.1 // indirect + github.com/lucasb-eyer/go-colorful v1.2.0 // indirect github.com/macabu/inamedparam v0.2.0 // indirect github.com/magiconair/properties v1.8.6 // indirect github.com/mailru/easyjson v0.7.7 // indirect github.com/manuelarte/embeddedstructfieldcheck v0.4.0 // indirect - github.com/manuelarte/funcorder v0.6.0 // indirect + github.com/manuelarte/funcorder v0.5.0 // indirect github.com/maratori/testableexamples v1.0.1 // indirect github.com/maratori/testpackage v1.1.2 // indirect github.com/matoous/godox v1.1.0 // indirect - github.com/mattn/go-colorable v0.1.15 // indirect - github.com/mattn/go-isatty v0.0.24 // indirect - github.com/mattn/go-runewidth v0.0.24 // indirect - github.com/mgechev/revive v1.15.0 // indirect + github.com/mattn/go-colorable v0.1.14 // indirect + github.com/mattn/go-isatty v0.0.20 // indirect + github.com/mattn/go-runewidth v0.0.16 // indirect + github.com/mgechev/revive v1.14.0 // indirect github.com/mitchellh/go-homedir v1.1.0 // indirect github.com/mitchellh/mapstructure v1.5.0 // indirect github.com/moricho/tparallel v0.3.2 // indirect - github.com/muesli/cancelreader v0.2.2 // indirect + github.com/muesli/termenv v0.16.0 // indirect github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect github.com/nakabonne/nestif v0.3.1 // indirect github.com/ncruces/go-strftime v1.0.0 // indirect github.com/nishanths/exhaustive v0.12.0 // indirect github.com/nishanths/predeclared v0.2.2 // indirect - github.com/nunnatsa/ginkgolinter v0.24.0 // indirect - github.com/oapi-codegen/nullable v1.2.0 // indirect - github.com/oapi-codegen/runtime v1.6.0 // indirect - github.com/package-url/packageurl-go v0.1.7 // indirect - github.com/pandatix/go-cvss v0.6.4 // indirect + github.com/nunnatsa/ginkgolinter v0.23.0 // indirect + github.com/oapi-codegen/runtime v1.2.0 // indirect + github.com/pandatix/go-cvss v0.6.2 // indirect github.com/pelletier/go-toml v1.9.5 // indirect - github.com/pelletier/go-toml/v2 v2.4.3 // indirect - github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect - github.com/prometheus/common v0.70.1 // indirect - github.com/prometheus/procfs v0.21.1 // indirect + github.com/pelletier/go-toml/v2 v2.2.4 // indirect + github.com/pmezard/go-difflib v1.0.0 // indirect + github.com/prometheus/common v0.67.5 // indirect + github.com/prometheus/procfs v0.20.1 // indirect github.com/quasilyte/go-ruleguard v0.4.5 // indirect github.com/quasilyte/go-ruleguard/dsl v0.3.23 // indirect github.com/quasilyte/gogrep v0.5.0 // indirect github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727 // indirect github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 // indirect - github.com/raeperd/recvcheck v0.3.0 // indirect + github.com/raeperd/recvcheck v0.2.0 // indirect github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect github.com/rivo/uniseg v0.4.7 // indirect - github.com/rogpeppe/go-internal v1.16.0 // indirect + github.com/rogpeppe/go-internal v1.14.1 // indirect github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 // indirect github.com/rubyist/circuitbreaker v2.2.1+incompatible // indirect github.com/russross/blackfriday/v2 v2.1.0 // indirect github.com/ryancurrah/gomodguard v1.4.1 // indirect - github.com/ryancurrah/gomodguard/v2 v2.1.3 // indirect - github.com/ryanrolds/sqlclosecheck v0.6.0 // indirect + github.com/ryanrolds/sqlclosecheck v0.5.1 // indirect github.com/sanposhiho/wastedassign/v2 v2.1.0 // indirect - github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 // indirect + github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 // indirect github.com/sashamelentyev/interfacebloat v1.1.0 // indirect github.com/sashamelentyev/usestdlibvars v1.29.0 // indirect - github.com/securego/gosec/v2 v2.28.0 // indirect - github.com/sirupsen/logrus v1.10.1 // indirect + github.com/securego/gosec/v2 v2.23.0 // indirect + github.com/sirupsen/logrus v1.9.4 // indirect github.com/sivchari/containedctx v1.0.3 // indirect - github.com/sonatard/noctx v0.5.1 // indirect - github.com/sourcegraph/go-diff v0.8.0 // indirect + github.com/sonatard/noctx v0.4.0 // indirect + github.com/sourcegraph/go-diff v0.7.0 // indirect github.com/spf13/afero v1.15.0 // indirect github.com/spf13/cast v1.5.0 // indirect github.com/spf13/cobra v1.10.2 // indirect @@ -269,20 +243,20 @@ require ( github.com/spf13/viper v1.12.0 // indirect github.com/ssgreg/nlreturn/v2 v2.2.1 // indirect github.com/stbenjam/no-sprintf-host-port v0.3.1 // indirect - github.com/stretchr/objx v0.5.3 // indirect - github.com/stretchr/testify v1.12.1 // indirect + github.com/stretchr/objx v0.5.2 // indirect + github.com/stretchr/testify v1.11.1 // indirect github.com/subosito/gotenv v1.4.1 // indirect - github.com/tetafro/godot v1.5.6 // indirect - github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4 // indirect + github.com/tetafro/godot v1.5.4 // indirect + github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67 // indirect github.com/timonwong/loggercheck v0.11.0 // indirect github.com/tomarrell/wrapcheck/v2 v2.12.0 // indirect github.com/tommy-muehle/go-mnd/v2 v2.5.1 // indirect - github.com/ulikunitz/xz v0.5.16 // indirect + github.com/ulikunitz/xz v0.5.15 // indirect github.com/ultraware/funlen v0.2.0 // indirect github.com/ultraware/whitespace v0.2.0 // indirect github.com/urfave/cli/v2 v2.3.0 // indirect - github.com/uudashr/gocognit v1.2.1 // indirect - github.com/uudashr/iface v1.5.0 // indirect + github.com/uudashr/gocognit v1.2.0 // indirect + github.com/uudashr/iface v1.4.1 // indirect github.com/xen0n/gosmopolitan v1.3.0 // indirect github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect github.com/yagipy/maintidx v1.0.0 // indirect @@ -290,40 +264,38 @@ require ( github.com/ykadowak/zerologlint v0.1.5 // indirect gitlab.com/bosi/decorder v0.4.2 // indirect go-simpler.org/musttag v0.14.0 // indirect - go-simpler.org/sloglint v0.12.0 // indirect + go-simpler.org/sloglint v0.11.1 // indirect go.augendre.info/arangolint v0.4.0 // indirect - go.augendre.info/fatcontext v0.10.0 // indirect + go.augendre.info/fatcontext v0.9.0 // indirect go.opentelemetry.io/auto/sdk v1.2.1 // indirect - go.opentelemetry.io/otel v1.44.0 // indirect - go.opentelemetry.io/otel/metric v1.44.0 // indirect - go.opentelemetry.io/otel/sdk v1.44.0 // indirect - go.opentelemetry.io/otel/sdk/metric v1.44.0 // indirect - go.opentelemetry.io/otel/trace v1.44.0 // indirect + go.opentelemetry.io/otel v1.41.0 // indirect + go.opentelemetry.io/otel/metric v1.41.0 // indirect + go.opentelemetry.io/otel/sdk v1.41.0 // indirect + go.opentelemetry.io/otel/sdk/metric v1.41.0 // indirect + go.opentelemetry.io/otel/trace v1.41.0 // indirect go.uber.org/multierr v1.11.0 // indirect go.uber.org/zap v1.27.1 // indirect - go.yaml.in/yaml/v2 v2.4.4 // indirect - go.yaml.in/yaml/v3 v3.0.5 // indirect - golang.org/x/crypto v0.55.0 // indirect + go.yaml.in/yaml/v2 v2.4.3 // indirect + go.yaml.in/yaml/v3 v3.0.4 // indirect golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa // indirect - golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f // indirect - golang.org/x/mod v0.40.0 // indirect - golang.org/x/net v0.58.0 // indirect - golang.org/x/oauth2 v0.36.0 // indirect - golang.org/x/sys v0.47.0 // indirect - golang.org/x/text v0.41.0 // indirect - golang.org/x/tools v0.49.0 // indirect + golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358 // indirect + golang.org/x/mod v0.33.0 // indirect + golang.org/x/net v0.51.0 // indirect + golang.org/x/sys v0.42.0 // indirect + golang.org/x/text v0.34.0 // indirect + golang.org/x/tools v0.42.0 // indirect golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect - google.golang.org/api v0.288.0 // indirect - google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 // indirect - google.golang.org/grpc v1.83.2 // indirect + google.golang.org/api v0.269.0 // indirect + google.golang.org/genproto/googleapis/rpc v0.0.0-20260226221140-a57be14db171 // indirect + google.golang.org/grpc v1.79.1 // indirect gopkg.in/ini.v1 v1.67.0 // indirect gopkg.in/yaml.v2 v2.4.0 // indirect - honnef.co/go/tools v0.8.0 // indirect - modernc.org/libc v1.75.6 // indirect + honnef.co/go/tools v0.7.0 // indirect + modernc.org/libc v1.70.0 // indirect modernc.org/mathutil v1.7.1 // indirect - modernc.org/memory v1.12.1 // indirect - mvdan.cc/gofumpt v0.11.0 // indirect - mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673 // indirect + modernc.org/memory v1.11.0 // indirect + mvdan.cc/gofumpt v0.9.2 // indirect + mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/go.sum b/go.sum index fb92925..dda4a35 100644 --- a/go.sum +++ b/go.sum @@ -1,15 +1,13 @@ -4d63.com/gocheckcompilerdirectives v1.4.0 h1:ZLq62rbGWVmQhiZ8kuNVIT/M09xCSTdJz9K3xOdT/CY= -4d63.com/gocheckcompilerdirectives v1.4.0/go.mod h1:9ZOAiMOjqC/nRwci2fcUXVHUNLG/cH6r6rhUh+jTFtQ= +4d63.com/gocheckcompilerdirectives v1.3.0 h1:Ew5y5CtcAAQeTVKUVFrE7EwHMrTO6BggtEj8BZSjZ3A= +4d63.com/gocheckcompilerdirectives v1.3.0/go.mod h1:ofsJ4zx2QAuIP/NO/NAh1ig6R1Fb18/GI7RVMwz7kAY= 4d63.com/gochecknoglobals v0.2.2 h1:H1vdnwnMaZdQW/N+NrkT1SZMTBmcwHe9Vq8lJcYYTtU= 4d63.com/gochecknoglobals v0.2.2/go.mod h1:lLxwTQjL5eIesRbvnzIP3jZtG140FnTdz+AlMa+ogt0= -cel.dev/expr v0.25.2 h1:K6j46C81hXtZQfuX60cVWQFBJahKSE2gfRbNuvr5bFs= -cel.dev/expr v0.25.2/go.mod h1:hrXvqGP6G6gyx8UAHSHJ5RGk//1Oj5nXQ2NI02Nrsg4= -charm.land/lipgloss/v2 v2.0.6 h1:EaGKeuA8FvF+v2BT5VmZd2LoYLaMZJXA5n34th8nCIQ= -charm.land/lipgloss/v2 v2.0.6/go.mod h1:ipDDJNSGa1hlwDtSfW1s2/xR8Vdhbut4PXh2zEKZd0Q= +cel.dev/expr v0.25.1 h1:1KrZg61W6TWSxuNZ37Xy49ps13NUovb66QLprthtwi4= +cel.dev/expr v0.25.1/go.mod h1:hrXvqGP6G6gyx8UAHSHJ5RGk//1Oj5nXQ2NI02Nrsg4= cloud.google.com/go v0.123.0 h1:2NAUJwPR47q+E35uaJeYoNhuNEM9kM8SjgRgdeOJUSE= cloud.google.com/go v0.123.0/go.mod h1:xBoMV08QcqUGuPW65Qfm1o9Y4zKZBpGS+7bImXLTAZU= -cloud.google.com/go/auth v0.21.0 h1:g/QwYfYb2Ai6HH8oomAOyBaIHLbscZ4+T/F/f5JZHkE= -cloud.google.com/go/auth v0.21.0/go.mod h1:M9o2Oz+YI2jAfxewJgb1vyI3vceHF+eohmxyzmrl+9s= +cloud.google.com/go/auth v0.18.2 h1:+Nbt5Ev0xEqxlNjd6c+yYUeosQ5TtEUaNcN/3FozlaM= +cloud.google.com/go/auth v0.18.2/go.mod h1:xD+oY7gcahcu7G2SG2DsBerfFxgPAJz17zz2joOFF3M= cloud.google.com/go/auth/oauth2adapt v0.2.8 h1:keo8NaayQZ6wimpNSmW5OPc283g65QNIiLpZnkHRbnc= cloud.google.com/go/auth/oauth2adapt v0.2.8/go.mod h1:XQ9y31RkqZCcwJWNSx2Xvric3RrU88hAYYbjDWYDL+c= cloud.google.com/go/compute/metadata v0.9.0 h1:pDUj4QMoPejqq20dK0Pg2N4yG9zIkYGdBtwLoEkH9Zs= @@ -18,72 +16,52 @@ cloud.google.com/go/iam v1.5.3 h1:+vMINPiDF2ognBJ97ABAYYwRgsaqxPbQDlMnbHMjolc= cloud.google.com/go/iam v1.5.3/go.mod h1:MR3v9oLkZCTlaqljW6Eb2d3HGDGK5/bDv93jhfISFvU= cloud.google.com/go/monitoring v1.24.3 h1:dde+gMNc0UhPZD1Azu6at2e79bfdztVDS5lvhOdsgaE= cloud.google.com/go/monitoring v1.24.3/go.mod h1:nYP6W0tm3N9H/bOw8am7t62YTzZY+zUeQ+Bi6+2eonI= -cloud.google.com/go/storage v1.61.3 h1:VS//ZfBuPGDvakfD9xyPW1RGF1Vy3BWUoVZXgW1KMOg= -cloud.google.com/go/storage v1.61.3/go.mod h1:JtqK8BBB7TWv0HVGHubtUdzYYrakOQIsMLffZ2Z/HWk= +cloud.google.com/go/storage v1.57.2 h1:sVlym3cHGYhrp6XZKkKb+92I1V42ks2qKKpB0CF5Mb4= +cloud.google.com/go/storage v1.57.2/go.mod h1:n5ijg4yiRXXpCu0sJTD6k+eMf7GRrJmPyr9YxLXGHOk= codeberg.org/chavacava/garif v0.2.0 h1:F0tVjhYbuOCnvNcU3YSpO6b3Waw6Bimy4K0mM8y6MfY= codeberg.org/chavacava/garif v0.2.0/go.mod h1:P2BPbVbT4QcvLZrORc2T29szK3xEOlnl0GiPTJmEqBQ= codeberg.org/polyfloyd/go-errorlint v1.9.0 h1:VkdEEmA1VBpH6ecQoMR4LdphVI3fA4RrCh2an7YmodI= codeberg.org/polyfloyd/go-errorlint v1.9.0/go.mod h1:GPRRu2LzVijNn4YkrZYJfatQIdS+TrcK8rL5Xs24qw8= dev.gaijin.team/go/exhaustruct/v4 v4.0.0 h1:873r7aNneqoBB3IaFIzhvt2RFYTuHgmMjoKfwODoI1Y= dev.gaijin.team/go/exhaustruct/v4 v4.0.0/go.mod h1:aZ/k2o4Y05aMJtiux15x8iXaumE88YdiB0Ai4fXOzPI= -dev.gaijin.team/go/exhaustruct/v5 v5.0.3 h1:yOeA7DNjlT8y4yfmN6nWWYYggA13N523YAj9/TXbuTM= -dev.gaijin.team/go/exhaustruct/v5 v5.0.3/go.mod h1:KwtBsX8nHHH1YxhxkpiBq6bfsmw5WnazWpNvJPHgY9Y= -dev.gaijin.team/go/golib v0.8.1 h1:JYju4x9BSo+QD/AYeHULVDcvEhiFg8wOi6pT0IaZF5E= -dev.gaijin.team/go/golib v0.8.1/go.mod h1:c5fu7t1RSGMxSQgcUYO1sODbzsYnOCXJLmHeNG1Eb+0= +dev.gaijin.team/go/golib v0.6.0 h1:v6nnznFTs4bppib/NyU1PQxobwDHwCXXl15P7DV5Zgo= +dev.gaijin.team/go/golib v0.6.0/go.mod h1:uY1mShx8Z/aNHWDyAkZTkX+uCi5PdX7KsG1eDQa2AVE= filippo.io/edwards25519 v1.1.0/go.mod h1:BxyFTGdWcka3PhytdK4V28tE5sGfRvvvRV7EaN4VDT4= -filippo.io/edwards25519 v1.2.0 h1:crnVqOiS4jqYleHd9vaKZ+HKtHfllngJIiOpNpoJsjo= -filippo.io/edwards25519 v1.2.0/go.mod h1:xzAOLCNug/yB62zG1bQ8uziwrIqIuxhctzJT18Q77mc= +filippo.io/edwards25519 v1.1.1 h1:YpjwWWlNmGIDyXOn8zLzqiD+9TyIlPhGFG96P39uBpw= +filippo.io/edwards25519 v1.1.1/go.mod h1:BxyFTGdWcka3PhytdK4V28tE5sGfRvvvRV7EaN4VDT4= github.com/4meepo/tagalign v1.4.3 h1:Bnu7jGWwbfpAie2vyl63Zup5KuRv21olsPIha53BJr8= github.com/4meepo/tagalign v1.4.3/go.mod h1:00WwRjiuSbrRJnSVeGWPLp2epS5Q/l4UEy0apLLS37c= -github.com/Abirdcfly/dupword v0.1.8 h1:SrhcUuGsROBuChFxHALRYzyyPODWn9zwghmzPvD9Cd8= -github.com/Abirdcfly/dupword v0.1.8/go.mod h1:XZrhVnI7YGpsTiWZANSQaBJ4QpL/Tq5vIEdKJJAs9WI= +github.com/Abirdcfly/dupword v0.1.7 h1:2j8sInznrje4I0CMisSL6ipEBkeJUJAmK1/lfoNGWrQ= +github.com/Abirdcfly/dupword v0.1.7/go.mod h1:K0DkBeOebJ4VyOICFdppB23Q0YMOgVafM0zYW0n9lF4= github.com/AdminBenni/iota-mixing v1.0.0 h1:Os6lpjG2dp/AE5fYBPAA1zfa2qMdCAWwPMCgpwKq7wo= github.com/AdminBenni/iota-mixing v1.0.0/go.mod h1:i4+tpAaB+qMVIV9OK3m4/DAynOd5bQFaOu+2AhtBCNY= -github.com/AlwxSin/noinlineerr v1.0.6 h1:KAvuxunTe9QxvqrFB7nZTdb/7Wzas4AvifslTnG0Ld8= -github.com/AlwxSin/noinlineerr v1.0.6/go.mod h1:+QgkkoYrMH7RHvcdxdlI7vYYEdgeoFOVjU9sUhw/rQc= -github.com/Antonboom/errname v1.1.2 h1:dxwONZJua3VB8Xh/VaCjqAcqF645sWWv7xj26zy7tdQ= -github.com/Antonboom/errname v1.1.2/go.mod h1:YeZIpgLMxT+SNkruGgYkLhzq/9vs3fsolTZegKaKDZI= -github.com/Antonboom/nilnil v1.1.2 h1:aNlFuJhaEseXe4fHO3xbjXlSeEiQVYa2lEkWD2s2hAY= -github.com/Antonboom/nilnil v1.1.2/go.mod h1:0ynwvphOLmAuMwTNDyBnDZmSwZoDpcFXmUHmzoHH2WA= +github.com/AlwxSin/noinlineerr v1.0.5 h1:RUjt63wk1AYWTXtVXbSqemlbVTb23JOSRiNsshj7TbY= +github.com/AlwxSin/noinlineerr v1.0.5/go.mod h1:+QgkkoYrMH7RHvcdxdlI7vYYEdgeoFOVjU9sUhw/rQc= +github.com/Antonboom/errname v1.1.1 h1:bllB7mlIbTVzO9jmSWVWLjxTEbGBVQ1Ff/ClQgtPw9Q= +github.com/Antonboom/errname v1.1.1/go.mod h1:gjhe24xoxXp0ScLtHzjiXp0Exi1RFLKJb0bVBtWKCWQ= +github.com/Antonboom/nilnil v1.1.1 h1:9Mdr6BYd8WHCDngQnNVV0b554xyisFioEKi30sksufQ= +github.com/Antonboom/nilnil v1.1.1/go.mod h1:yCyAmSw3doopbOWhJlVci+HuyNRuHJKIv6V2oYQa8II= github.com/Antonboom/testifylint v1.6.4 h1:gs9fUEy+egzxkEbq9P4cpcMB6/G0DYdMeiFS87UiqmQ= github.com/Antonboom/testifylint v1.6.4/go.mod h1:YO33FROXX2OoUfwjz8g+gUxQXio5i9qpVy7nXGbxDD4= -github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 h1:fou+2+WFTib47nS+nz/ozhEBnvU96bKHy6LjRsY4E28= -github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0/go.mod h1:t76Ruy8AHvUAC8GfMWJMa0ElSbuIcO03NLpynfbgsPA= -github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 h1:Hk5QBxZQC1jb2Fwj6mpzme37xbCDdNTxU7O9eb5+LB4= -github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1/go.mod h1:IYus9qsFobWIc2YVwe/WPjcnyCkPKtnHAqUYeebc8z0= -github.com/Azure/azure-sdk-for-go/sdk/azidentity/cache v0.3.2 h1:yz1bePFlP5Vws5+8ez6T3HWXPmwOK7Yvq8QxDBD3SKY= -github.com/Azure/azure-sdk-for-go/sdk/azidentity/cache v0.3.2/go.mod h1:Pa9ZNPuoNu/GztvBSKk9J1cDJW6vk/n0zLtV4mgd8N8= -github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 h1:9iefClla7iYpfYWdzPCRDozdmndjTm8DXdpCzPajMgA= -github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2/go.mod h1:XtLgD3ZD34DAaVIIAyG3objl5DynM3CQ/vMcbBNJZGI= -github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/storage/armstorage v1.8.1 h1:/Zt+cDPnpC3OVDm/JKLOs7M2DKmLRIIp3XIx9pHHiig= -github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/storage/armstorage v1.8.1/go.mod h1:Ng3urmn6dYe8gnbCMoHHVl5APYz2txho3koEkV2o2HA= -github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.6.4 h1:jWQK1GI+LeGGUKBADtcH2rRqPxYB1Ljwms5gFA2LqrM= -github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.6.4/go.mod h1:8mwH4klAm9DUgR2EEHyEEAQlRDvLPyg5fQry3y+cDew= -github.com/AzureAD/microsoft-authentication-extensions-for-go/cache v0.1.1 h1:WJTmL004Abzc5wDB5VtZG2PJk5ndYDgVacGqfirKxjM= -github.com/AzureAD/microsoft-authentication-extensions-for-go/cache v0.1.1/go.mod h1:tCcJZ0uHAmvjsVYzEFivsRTN00oz5BEsRgQHu5JZ9WE= -github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0 h1:4iB+IesclUXdP0ICgAabvq2FYLXrJWKx1fJQ+GxSo3Y= -github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0/go.mod h1:HKpQxkWaGLJ+D/5H8QRpyQXA1eKjxkFlOMwck5+33Jk= github.com/BurntSushi/toml v0.3.1/go.mod h1:xHWCNGjB5oqiDr8zfno3MHue2Ht5sIBksp03qcyfWMU= github.com/BurntSushi/toml v1.6.0 h1:dRaEfpa2VI55EwlIW72hMRHdWouJeRF7TPYhI+AUQjk= github.com/BurntSushi/toml v1.6.0/go.mod h1:ukJfTF/6rtPPRCnwkur4qwRxa8vTRFBF0uk2lLoLwho= -github.com/ClickHouse/clickhouse-go-linter v1.2.1 h1:zGEKIyd5YL08ieWG/LOUmlau2DxbxPVOfAeo+4Jz3ck= -github.com/ClickHouse/clickhouse-go-linter v1.2.1/go.mod h1:pLorS7ffPTfuUV9M0SJgfHA/h/WQPQUk2FWG9x74cQ4= -github.com/CycloneDX/cyclonedx-go v0.12.0 h1:/7Jum36UA6V043tQZ/fE3jf+Nf9gn/qxUFfd7QReMy8= -github.com/CycloneDX/cyclonedx-go v0.12.0/go.mod h1:V2577HhxDDCDLYfkm55WJrz16nHTfyQZwcWUBSG7Z28= +github.com/CycloneDX/cyclonedx-go v0.10.0 h1:7xyklU7YD+CUyGzSFIARG18NYLsKVn4QFg04qSsu+7Y= +github.com/CycloneDX/cyclonedx-go v0.10.0/go.mod h1:vUvbCXQsEm48OI6oOlanxstwNByXjCZ2wuleUlwGEO8= github.com/Djarvur/go-err113 v0.1.1 h1:eHfopDqXRwAi+YmCUas75ZE0+hoBHJ2GQNLYRSxao4g= github.com/Djarvur/go-err113 v0.1.1/go.mod h1:IaWJdYFLg76t2ihfflPZnM1LIQszWOsFDh2hhhAVF6k= -github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0 h1:l7+6kwRMJNwdCvYdDl7Eax+wzEYHSnNY7zrrfbhDdTA= -github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0/go.mod h1:pJTkW8hEUIIi3Pf65lPZOnn4Y81yCllX6IWk2jNXdkM= -github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0 h1:UnDZ/zFfG1JhH/DqxIZYU/1CUAlTUScoXD/LcM2Ykk8= -github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0/go.mod h1:IA1C1U7jO/ENqm/vhi7V9YYpBsp+IMyqNrEN94N7tVc= -github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0 h1:0s6TxfCu2KHkkZPnBfsQ2y5qia0jl3MMrmBhu3nCOYk= -github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0/go.mod h1:Mf6O40IAyB9zR/1J8nGDDPirZQQPbYJni8Yisy7NTMc= +github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30.0 h1:sBEjpZlNHzK1voKq9695PJSX2o5NEXl7/OL3coiIY0c= +github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30.0/go.mod h1:P4WPRUkOhJC13W//jWpyfJNDAIpvRbAUIYLX/4jtlE0= +github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.54.0 h1:lhhYARPUu3LmHysQ/igznQphfzynnqI3D75oUyw1HXk= +github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.54.0/go.mod h1:l9rva3ApbBpEJxSNYnwT9N4CDLrWgtq3u8736C5hyJw= +github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.54.0 h1:s0WlVbf9qpvkh1c/uDAPElam0WrL7fHRIidgZJ7UqZI= +github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.54.0/go.mod h1:Mf6O40IAyB9zR/1J8nGDDPirZQQPbYJni8Yisy7NTMc= github.com/KyleBanks/depth v1.2.1 h1:5h8fQADFrWtarTdtDudMmGsC7GPbOAu6RVB3ffsVFHc= github.com/KyleBanks/depth v1.2.1/go.mod h1:jzSb9d0L43HxTQfT+oSA1EEp2q+ne2uh6XgeJcm8brE= -github.com/Masterminds/semver/v3 v3.5.0 h1:kQceYJfbupGfZOKZQg0kou0DgAKhzDg2NZPAwZ/2OOE= -github.com/Masterminds/semver/v3 v3.5.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM= -github.com/MirrexOne/unqueryvet v1.5.4 h1:38QOxShO7JmMWT+eCdDMbcUgGCOeJphVkzzRgyLJgsQ= -github.com/MirrexOne/unqueryvet v1.5.4/go.mod h1:fs9Zq6eh1LRIhsDIsxf9PONVUjYdFHdtkHIgZdJnyPU= +github.com/Masterminds/semver/v3 v3.4.0 h1:Zog+i5UMtVoCU8oKka5P7i9q9HgrJeGzI9SA1Xbatp0= +github.com/Masterminds/semver/v3 v3.4.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM= +github.com/MirrexOne/unqueryvet v1.5.3 h1:LpT3rsH+IY3cQddWF9bg4C7jsbASdGnrOSofY8IPEiw= +github.com/MirrexOne/unqueryvet v1.5.3/go.mod h1:fs9Zq6eh1LRIhsDIsxf9PONVUjYdFHdtkHIgZdJnyPU= github.com/OpenPeeDeeP/depguard/v2 v2.2.1 h1:vckeWVESWp6Qog7UZSARNqfu/cZqvki8zsuj3piCMx4= github.com/OpenPeeDeeP/depguard/v2 v2.2.1/go.mod h1:q4DKzC4UcVaAvcfd41CZh0PWpGgzrVxUYBlgKNGquUo= github.com/PuerkitoBio/purell v1.1.1 h1:WEQqlqaGbrPkxLJWfBwQmfEAE1Z7ONdDLqrN38tNFfI= @@ -93,16 +71,16 @@ github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578/go.mod h1:uGdko github.com/RaveNoX/go-jsoncommentstrip v1.0.0/go.mod h1:78ihd09MekBnJnxpICcwzCMzGrKSKYe4AqU6PDYYpjk= github.com/alecthomas/assert/v2 v2.11.0 h1:2Q9r3ki8+JYXvGsDyBXwH3LcJ+WK5D0gc5E8vS6K3D0= github.com/alecthomas/assert/v2 v2.11.0/go.mod h1:Bze95FyfUr7x34QZrjL+XP+0qgp/zg8yS+TtBj1WA3k= -github.com/alecthomas/chroma/v2 v2.27.0 h1:FodwmyOBgJULFYmDqibcp9pvfDLWdtPRh9v/r5BXYZs= -github.com/alecthomas/chroma/v2 v2.27.0/go.mod h1:NjJ3ciIgrqBNeIkWZ4e46nseoLDslxU1LmfCoL+wcY8= +github.com/alecthomas/chroma/v2 v2.23.1 h1:nv2AVZdTyClGbVQkIzlDm/rnhk1E9bU9nXwmZ/Vk/iY= +github.com/alecthomas/chroma/v2 v2.23.1/go.mod h1:NqVhfBR0lte5Ouh3DcthuUCTUpDC9cxBOfyMbMQPs3o= github.com/alecthomas/go-check-sumtype v0.3.1 h1:u9aUvbGINJxLVXiFvHUlPEaD7VDULsrxJb4Aq31NLkU= github.com/alecthomas/go-check-sumtype v0.3.1/go.mod h1:A8TSiN3UPRw3laIgWEUOHHLPa6/r9MtoigdlP5h3K/E= github.com/alecthomas/repr v0.5.2 h1:SU73FTI9D1P5UNtvseffFSGmdNci/O6RsqzeXJtP0Qs= github.com/alecthomas/repr v0.5.2/go.mod h1:Fr0507jx4eOXV7AlPV6AVZLYrLIuIeSOWtW57eE/O/4= github.com/alexkohler/nakedret/v2 v2.0.6 h1:ME3Qef1/KIKr3kWX3nti3hhgNxw6aqN5pZmQiFSsuzQ= github.com/alexkohler/nakedret/v2 v2.0.6/go.mod h1:l3RKju/IzOMQHmsEvXwkqMDzHHvurNQfAgE1eVmT40Q= -github.com/alexkohler/prealloc v1.1.0 h1:cKGRBqlXw5iyQGLYhrXrDlcHxugXpTq4tQ5c91wkf8M= -github.com/alexkohler/prealloc v1.1.0/go.mod h1:fT39Jge3bQrfA7nPMDngUfvUbQGQeJyGQnR+913SCig= +github.com/alexkohler/prealloc v1.0.2 h1:MPo8cIkGkZytq7WNH9UHv3DIX1mPz1RatPXnZb0zHWQ= +github.com/alexkohler/prealloc v1.0.2/go.mod h1:fT39Jge3bQrfA7nPMDngUfvUbQGQeJyGQnR+913SCig= github.com/alfatraining/structtag v1.0.0 h1:2qmcUqNcCoyVJ0up879K614L9PazjBSFruTB0GOFjCc= github.com/alfatraining/structtag v1.0.0/go.mod h1:p3Xi5SwzTi+Ryj64DqjLWz7XurHxbGsq6y3ubePJPus= github.com/alingse/asasalint v0.0.11 h1:SFwnQXJ49Kx/1GghOFz1XGqHYKp21Kq1nHad/0WQRnw= @@ -113,50 +91,52 @@ github.com/anchore/go-struct-converter v0.1.0 h1:2rDRssAl6mgKBSLNiVCMADgZRhoqtw9 github.com/anchore/go-struct-converter v0.1.0/go.mod h1:rYqSE9HbjzpHTI74vwPvae4ZVYZd1lue2ta6xHPdblA= github.com/apapsch/go-jsonmerge/v2 v2.0.0 h1:axGnT1gRIfimI7gJifB699GoE/oq+F2MU7Dml6nw9rQ= github.com/apapsch/go-jsonmerge/v2 v2.0.0/go.mod h1:lvDnEdqiQrp0O42VQGgmlKpxL1AP2+08jFMw88y4klk= -github.com/ashanbrown/forbidigo/v2 v2.3.1 h1:KAZijvQ7zeIBKbhikT4jCm0TLYXC4u78bTiLh/8JROI= -github.com/ashanbrown/forbidigo/v2 v2.3.1/go.mod h1:2QDkLTzU6TV937eFROamXrW92M3paehdae4HCDCOZCM= -github.com/ashanbrown/makezero/v2 v2.2.1 h1:A7uU8dgB1PA9aelTxHMfHIQ8Qev8AB3JLxJUBUsejqM= -github.com/ashanbrown/makezero/v2 v2.2.1/go.mod h1:aEGT/9q3S8DHeE57C88z2a6xydvgx8J5hgXIGWgo0MY= -github.com/aws/aws-sdk-go-v2 v1.46.0 h1:1kt7m/EKcEHt5mlyyxx9cSlMddRPIKbjb6DIQsu4HPk= -github.com/aws/aws-sdk-go-v2 v1.46.0/go.mod h1:bttEH6JqnUL8LepvDVfdrds/fZ5bCIxzpe3abyUrhDU= -github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11 h1:h5+3VT69KUBK24grGuuA5saDJTj2IIjLb9au668Fo5I= -github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11/go.mod h1:dnakxebH6UwFvcvujL0LVggYQ8nEvBGjU4G/V79Nv94= -github.com/aws/aws-sdk-go-v2/config v1.33.2 h1:Pj4+nF2kc4Z+1BJysVPnX9d5dMN7IYFXR4UJaWK2IpA= -github.com/aws/aws-sdk-go-v2/config v1.33.2/go.mod h1:Igw+HTwbR2tsTU/ydifAS9EHAFJ2s/FCgkwQWFnAdE4= -github.com/aws/aws-sdk-go-v2/credentials v1.20.2 h1:VQjZODPNfdikCX2ZZrltw4zNLkcwjyUFDUl2vT9yTwg= -github.com/aws/aws-sdk-go-v2/credentials v1.20.2/go.mod h1:OmeHCn28vZylsBvalLDf7t8fuJ2rHYQprJs+7WuxniI= -github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.19.1 h1:YIEBqcqRnpi4Pfv0YHImtgi6czGCwKHANC7SwmUAVD0= -github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.19.1/go.mod h1:imEf0oufgAo8KAkCHhrOdqGEC0YWx1PPBQH82shSxGw= -github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.2.3 h1:w5OoDiMN6x53ROmiIImGzmVcxXv2q1GXY+aKV4WAJYM= -github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.2.3/go.mod h1:dAhgYp776bX3LuWvnSCFwQEjNs6fuFg7YXIy5PXcP3Q= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.5.2 h1:q/PSLGuRWCChWg+dLnb9dWOnrCxJtnboXbBtFoqqRrI= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.5.2/go.mod h1:TD1jvU2LvXkJexct5vBqcd8QlNXh5EmRUeL/Z32p0n4= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.8.2 h1:6fl86IPqKEXoySqiOWdfgbEp9OVbn44zTfEICNEBDhY= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.8.2/go.mod h1:63HDfhFkdzBpI8WGXTSKUHPKS6mqldj4u3LJW7RZtSU= -github.com/aws/aws-sdk-go-v2/internal/v4a v1.5.1 h1:yhw5KD1phVyP9vijxOUzDfEtJx+bt+L63k+VfuiYFAA= -github.com/aws/aws-sdk-go-v2/internal/v4a v1.5.1/go.mod h1:ZW2e0d7DYlRxlS9hEiMXE47gTdX5KRN4byUiNbUpG+Q= -github.com/aws/aws-sdk-go-v2/service/ecr v1.64.0 h1:iOYGE9bHGhMQYtbjEcgDJEobWIhKoUvE71m+Jm0vZgU= -github.com/aws/aws-sdk-go-v2/service/ecr v1.64.0/go.mod h1:5ccNgipT/aF9MWzTrKkyGJaCozPt+D6LOD4RFIdP22k= -github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19 h1:bAdDl/HkGCcGPoe25ToSHEw23VIxt6CT5fLcg111BKg= -github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19/go.mod h1:KaUzbLxv4CeSxh6ZCl9B4m7CuFenS8kUEaDs+f/DQr4= -github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.18 h1:W/EyPFl9A5rXrtoilfwHYEvzHER+K4SpBPtMXi24Mos= -github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.18/go.mod h1:UG50K+pvd/uy6xExbobg0rjqFBFZe6I3l75EPDZw4tg= -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.14.1 h1:RmmWQPREQdk9U+PfqeHW3MqZaBaNK7TpV9W3RY+b+7g= -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.14.1/go.mod h1:0A3W4F+68ZnNk5XcNL/e9HFMwnP8RlEicFfy6eOEDyw= -github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.25 h1:2pQEbwf+/6EDbiit/GcBE2K4IUpMZymaA0kOz3xK978= -github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.25/go.mod h1:KvT6NCcQ0EZ+ZkVRrlBMt04Po3ok23YELEp7WimhLhM= -github.com/aws/aws-sdk-go-v2/service/s3 v1.102.2 h1:ie4ElCmUKS26pzrZcIk/lmt4yWjAqLLcawstyQCh298= -github.com/aws/aws-sdk-go-v2/service/s3 v1.102.2/go.mod h1:zjsomFeX5duj+4PlMB+o4JoWTIx+G0XMyzjYrUbQkN0= -github.com/aws/aws-sdk-go-v2/service/signin v1.8.0 h1:bSvKIoLuRGFqGwASgeCQncCJDi9YKKBDEmCEZzOX1uU= -github.com/aws/aws-sdk-go-v2/service/signin v1.8.0/go.mod h1:9IqUlsJDbUPcg6cgx3WEzXdjrbWzLDQrak0aaSqlTcI= -github.com/aws/aws-sdk-go-v2/service/sso v1.36.0 h1:iivsh357VnfIc18IFWSuoyQEluf8frfWf4cL2Y0JUQw= -github.com/aws/aws-sdk-go-v2/service/sso v1.36.0/go.mod h1:tWuiVBUtPBr8/rgRiYS8Uf85sHcAN+G7XS3D3CEoUh8= -github.com/aws/aws-sdk-go-v2/service/ssooidc v1.41.0 h1:wVxM3QzSKIK8tSN6OGgezp9OK91lCLH2zhmRInN9rFM= -github.com/aws/aws-sdk-go-v2/service/ssooidc v1.41.0/go.mod h1:naFe83jSMuYkH+QjQPX8n1MLhBkeCFM5Lsnh5m5wz3c= -github.com/aws/aws-sdk-go-v2/service/sts v1.48.0 h1:RzZVCzYM19vhJCT5s6vO2wN8ie770Li/TmbAZ9B6N7E= -github.com/aws/aws-sdk-go-v2/service/sts v1.48.0/go.mod h1:mKo/CzaCz8qytGW70NG4vIIGAx1HXTlb5lHNkC5k3lk= -github.com/aws/smithy-go v1.28.1 h1:R/nXH00c8qcfCzQVELtRw+eLQWtzv+VAIEFJ1/xxXlQ= -github.com/aws/smithy-go v1.28.1/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc= +github.com/ashanbrown/forbidigo/v2 v2.3.0 h1:OZZDOchCgsX5gvToVtEBoV2UWbFfI6RKQTir2UZzSxo= +github.com/ashanbrown/forbidigo/v2 v2.3.0/go.mod h1:5p6VmsG5/1xx3E785W9fouMxIOkvY2rRV9nMdWadd6c= +github.com/ashanbrown/makezero/v2 v2.1.0 h1:snuKYMbqosNokUKm+R6/+vOPs8yVAi46La7Ck6QYSaE= +github.com/ashanbrown/makezero/v2 v2.1.0/go.mod h1:aEGT/9q3S8DHeE57C88z2a6xydvgx8J5hgXIGWgo0MY= +github.com/aws/aws-sdk-go-v2 v1.41.3 h1:4kQ/fa22KjDt13QCy1+bYADvdgcxpfH18f0zP542kZA= +github.com/aws/aws-sdk-go-v2 v1.41.3/go.mod h1:mwsPRE8ceUUpiTgF7QmQIJ7lgsKUPQOUl3o72QBrE1o= +github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.6 h1:N4lRUXZpZ1KVEUn6hxtco/1d2lgYhNn1fHkkl8WhlyQ= +github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.6/go.mod h1:lyw7GFp3qENLh7kwzf7iMzAxDn+NzjXEAGjKS2UOKqI= +github.com/aws/aws-sdk-go-v2/config v1.32.11 h1:ftxI5sgz8jZkckuUHXfC/wMUc8u3fG1vQS0plr2F2Zs= +github.com/aws/aws-sdk-go-v2/config v1.32.11/go.mod h1:twF11+6ps9aNRKEDimksp923o44w/Thk9+8YIlzWMmo= +github.com/aws/aws-sdk-go-v2/credentials v1.19.11 h1:NdV8cwCcAXrCWyxArt58BrvZJ9pZ9Fhf9w6Uh5W3Uyc= +github.com/aws/aws-sdk-go-v2/credentials v1.19.11/go.mod h1:30yY2zqkMPdrvxBqzI9xQCM+WrlrZKSOpSJEsylVU+8= +github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.19 h1:INUvJxmhdEbVulJYHI061k4TVuS3jzzthNvjqvVvTKM= +github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.19/go.mod h1:FpZN2QISLdEBWkayloda+sZjVJL+e9Gl0k1SyTgcswU= +github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.5 h1:4nC6vsVBU6vClZxxF6XLEozLUY/PgUCXYlGGB/VaC8M= +github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.5/go.mod h1:N5c+La/yy7H4YnF9rFgUqwgbfw+MloWoCHQ0RJH2EBE= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.19 h1:/sECfyq2JTifMI2JPyZ4bdRN77zJmr6SrS1eL3augIA= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.19/go.mod h1:dMf8A5oAqr9/oxOfLkC/c2LU/uMcALP0Rgn2BD5LWn0= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.19 h1:AWeJMk33GTBf6J20XJe6qZoRSJo0WfUhsMdUKhoODXE= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.19/go.mod h1:+GWrYoaAsV7/4pNHpwh1kiNLXkKaSoppxQq9lbH8Ejw= +github.com/aws/aws-sdk-go-v2/internal/ini v1.8.5 h1:clHU5fm//kWS1C2HgtgWxfQbFbx4b6rx+5jzhgX9HrI= +github.com/aws/aws-sdk-go-v2/internal/ini v1.8.5/go.mod h1:O3h0IK87yXci+kg6flUKzJnWeziQUKciKrLjcatSNcY= +github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.19 h1:3Y4oma5TiV7tT9wa8zRcdoXwZkGz9Q/wxbEUK7cMuAM= +github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.19/go.mod h1:V1K+TeJVD5JOk3D9e5tsX2KUdL7BlB+FV6cBhdobN8c= +github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.6 h1:XAq62tBTJP/85lFD5oqOOe7YYgWxY9LvWq8plyDvDVg= +github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.6/go.mod h1:x0nZssQ3qZSnIcePWLvcoFisRXJzcTVvYpAAdYX8+GI= +github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.11 h1:BYf7XNsJMzl4mObARUBUib+j2tf0U//JAAtTnYqvqCw= +github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.11/go.mod h1:aEUS4WrNk/+FxkBZZa7tVgp4pGH+kFGW40Y8rCPqt5g= +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.19 h1:X1Tow7suZk9UCJHE1Iw9GMZJJl0dAnKXXP1NaSDHwmw= +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.19/go.mod h1:/rARO8psX+4sfjUQXp5LLifjUt8DuATZ31WptNJTyQA= +github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.19 h1:JnQeStZvPHFHeyky/7LbMlyQjUa+jIBj36OlWm0pzIk= +github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.19/go.mod h1:HGyasyHvYdFQeJhvDHfH7HXkHh57htcJGKDZ+7z+I24= +github.com/aws/aws-sdk-go-v2/service/s3 v1.96.3 h1:+d0SsTvxtIJt4tSJ6wr+jrxEMDa6XeupjRv8H7Qitkk= +github.com/aws/aws-sdk-go-v2/service/s3 v1.96.3/go.mod h1:ROUNFvFWPwBlOu687WJNQ9cPvd2ccpFrnCiA1YGz50o= +github.com/aws/aws-sdk-go-v2/service/signin v1.0.7 h1:Y2cAXlClHsXkkOvWZFXATr34b0hxxloeQu/pAZz2row= +github.com/aws/aws-sdk-go-v2/service/signin v1.0.7/go.mod h1:idzZ7gmDeqeNrSPkdbtMp9qWMgcBwykA7P7Rzh5DXVU= +github.com/aws/aws-sdk-go-v2/service/sso v1.30.12 h1:iSsvB9EtQ09YrsmIc44Heqlx5ByGErqhPK1ZQLppias= +github.com/aws/aws-sdk-go-v2/service/sso v1.30.12/go.mod h1:fEWYKTRGoZNl8tZ77i61/ccwOMJdGxwOhWCkp6TXAr0= +github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.16 h1:EnUdUqRP1CNzt2DkV67tJx6XDN4xlfBFm+bzeNOQVb0= +github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.16/go.mod h1:Jic/xv0Rq/pFNCh3WwpH4BEqdbSAl+IyHro8LbibHD8= +github.com/aws/aws-sdk-go-v2/service/sts v1.41.8 h1:XQTQTF75vnug2TXS8m7CVJfC2nniYPZnO1D4Np761Oo= +github.com/aws/aws-sdk-go-v2/service/sts v1.41.8/go.mod h1:Xgx+PR1NUOjNmQY+tRMnouRp83JRM8pRMw/vCaVhPkI= +github.com/aws/smithy-go v1.24.2 h1:FzA3bu/nt/vDvmnkg+R8Xl46gmzEDam6mZ1hzmwXFng= +github.com/aws/smithy-go v1.24.2/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc= +github.com/aymanbagabas/go-osc52/v2 v2.0.1 h1:HwpRHbFMcZLEVr42D4p7XBqjyuxQH5SMiErDT4WkJ2k= +github.com/aymanbagabas/go-osc52/v2 v2.0.1/go.mod h1:uYgXzlJ7ZpABp8OJ+exZzJJhRNQ2ASbcXHWsFqH8hp8= github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM= github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw= github.com/bkielbasa/cyclop v1.2.3 h1:faIVMIGDIANuGPWH031CZJTi2ymOQBULs9H21HSMa5w= @@ -166,18 +146,18 @@ github.com/blizzy78/varnamelen v0.8.0/go.mod h1:V9TzQZ4fLJ1DSrjVDfl89H7aMnTvKkAp github.com/bmatcuk/doublestar v1.1.1/go.mod h1:UD6OnuiIn0yFxxA2le/rnRU1G4RaI4UvFv1sNto9p6w= github.com/bombsimon/wsl/v4 v4.7.0 h1:1Ilm9JBPRczjyUs6hvOPKvd7VL1Q++PL8M0SXBDf+jQ= github.com/bombsimon/wsl/v4 v4.7.0/go.mod h1:uV/+6BkffuzSAVYD+yGyld1AChO7/EuLrCF/8xTiapg= -github.com/bombsimon/wsl/v5 v5.9.0 h1:WCrgZ7RQnZO5oEwbVTlYgBdU3wL294kR1BSWV8vTfsU= -github.com/bombsimon/wsl/v5 v5.9.0/go.mod h1:kjo4HiAV5FDkHC8/uzJq9mBffEEd6WT/nvN7DoMovDM= +github.com/bombsimon/wsl/v5 v5.6.0 h1:4z+/sBqC5vUmSp1O0mS+czxwH9+LKXtCWtHH9rZGQL8= +github.com/bombsimon/wsl/v5 v5.6.0/go.mod h1:Uqt2EfrMj2NV8UGoN1f1Y3m0NpUVCsUdrNCdet+8LvU= github.com/bradleyjkemp/cupaloy/v2 v2.8.0 h1:any4BmKE+jGIaMpnU8YgH/I2LPiLBufr6oMMlVBbn9M= github.com/bradleyjkemp/cupaloy/v2 v2.8.0/go.mod h1:bm7JXdkRd4BHJk9HpwqAI8BoAY1lps46Enkdqw6aRX0= github.com/breml/bidichk v0.3.3 h1:WSM67ztRusf1sMoqH6/c4OBCUlRVTKq+CbSeo0R17sE= github.com/breml/bidichk v0.3.3/go.mod h1:ISbsut8OnjB367j5NseXEGGgO/th206dVa427kR8YTE= github.com/breml/errchkjson v0.4.1 h1:keFSS8D7A2T0haP9kzZTi7o26r7kE3vymjZNeNDRDwg= github.com/breml/errchkjson v0.4.1/go.mod h1:a23OvR6Qvcl7DG/Z4o0el6BRAjKnaReoPQFciAl9U3s= -github.com/butuzov/ireturn v0.4.1 h1:vWb3NO4t77iku/sjCQ/2pHTQeOmxEhjIriJqRLg1Y+I= -github.com/butuzov/ireturn v0.4.1/go.mod h1:q+DXKzTDV5guNuXLnIab9fKXizTn2miZHLhxH7V/GB4= -github.com/butuzov/mirror v1.3.3 h1:v0RsWBhfFc1RQqE/f3sHpSttKDtodFn0gFmtYyD4/hA= -github.com/butuzov/mirror v1.3.3/go.mod h1:h9BzzwYnTiHO0GzgvaTqIg7VSsOUhdIv51cHFFBmX1w= +github.com/butuzov/ireturn v0.4.0 h1:+s76bF/PfeKEdbG8b54aCocxXmi0wvYdOVsWxVO7n8E= +github.com/butuzov/ireturn v0.4.0/go.mod h1:ghI0FrCmap8pDWZwfPisFD1vEc56VKH4NpQUxDHta70= +github.com/butuzov/mirror v1.3.0 h1:HdWCXzmwlQHdVhwvsfBb2Au0r3HyINry3bDWLYXiKoc= +github.com/butuzov/mirror v1.3.0/go.mod h1:AEij0Z8YMALaq4yQj9CPPVYOyJQyiexpQEQgihajRfI= github.com/catenacyber/perfsprint v0.10.1 h1:u7Riei30bk46XsG8nknMhKLXG9BcXz3+3tl/WpKm0PQ= github.com/catenacyber/perfsprint v0.10.1/go.mod h1:DJTGsi/Zufpuus6XPGJyKOTMELe347o6akPvWG9Zcsc= github.com/ccojocar/zxcvbn-go v1.0.4 h1:FWnCIRMXPj43ukfX000kvBZvV6raSxakYr1nzyNrUcc= @@ -188,26 +168,20 @@ github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UF github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs= github.com/charithe/durationcheck v0.0.11 h1:g1/EX1eIiKS57NTWsYtHDZ/APfeXKhye1DidBcABctk= github.com/charithe/durationcheck v0.0.11/go.mod h1:x5iZaixRNl8ctbM+3B2RrPG5t856TxRyVQEnbIEM2X4= -github.com/charmbracelet/colorprofile v0.4.3 h1:QPa1IWkYI+AOB+fE+mg/5/4HRMZcaXex9t5KX76i20Q= -github.com/charmbracelet/colorprofile v0.4.3/go.mod h1:/zT4BhpD5aGFpqQQqw7a+VtHCzu+zrQtt1zhMt9mR4Q= -github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886 h1:rdnVWKgJpTVXKuKuJyxDJ+NFJdUaUqGvyGy61OcvlbA= -github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886/go.mod h1:nAw0d9PhFp1qdzi2xhQU5YOu5sVpDIHWlaW2Uz/bCro= -github.com/charmbracelet/x/ansi v0.11.8 h1:JMFwp0CgDC2+jcOB162HH5k7I3FVbgFSMMYg7dSPBQQ= -github.com/charmbracelet/x/ansi v0.11.8/go.mod h1:ZNN+3mXny/516oTQPLMPIBeSINvNJJQ8uQXDgbeJxY0= -github.com/charmbracelet/x/term v0.2.2 h1:xVRT/S2ZcKdhhOuSP4t5cLi5o+JxklsoEObBSgfgZRk= -github.com/charmbracelet/x/term v0.2.2/go.mod h1:kF8CY5RddLWrsgVwpw4kAa6TESp6EB5y3uxGLeCqzAI= -github.com/charmbracelet/x/termios v0.1.1 h1:o3Q2bT8eqzGnGPOYheoYS8eEleT5ZVNYNy8JawjaNZY= -github.com/charmbracelet/x/termios v0.1.1/go.mod h1:rB7fnv1TgOPOyyKRJ9o+AsTU/vK5WHJ2ivHeut/Pcwo= -github.com/charmbracelet/x/windows v0.2.2 h1:IofanmuvaxnKHuV04sC0eBy/smG6kIKrWG2/jYn2GuM= -github.com/charmbracelet/x/windows v0.2.2/go.mod h1:/8XtdKZzedat74NQFn0NGlGL4soHB0YQZrETF96h75k= +github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc h1:4pZI35227imm7yK2bGPcfpFEmuY1gc2YSTShr4iJBfs= +github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc/go.mod h1:X4/0JoqgTIPSFcRA/P6INZzIuyqdFY5rm8tb41s9okk= +github.com/charmbracelet/lipgloss v1.1.0 h1:vYXsiLHVkK7fp74RkV7b2kq9+zDLoEU4MZoFqR/noCY= +github.com/charmbracelet/lipgloss v1.1.0/go.mod h1:/6Q8FR2o+kj8rz4Dq0zQc3vYf7X+B0binUUBwA0aL30= +github.com/charmbracelet/x/ansi v0.10.1 h1:rL3Koar5XvX0pHGfovN03f5cxLbCF2YvLeyz7D2jVDQ= +github.com/charmbracelet/x/ansi v0.10.1/go.mod h1:3RQDQ6lDnROptfpWuUVIUG64bD2g2BgntdxH0Ya5TeE= +github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd h1:vy0GVL4jeHEwG5YOXDmi86oYw2yuYUGqz6a8sLwg0X8= +github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd/go.mod h1:xe0nKWGd3eJgtqZRaN9RjMtK7xUYchjzPr7q6kcvCCs= +github.com/charmbracelet/x/term v0.2.1 h1:AQeHeLZ1OqSXhrAWpYUtZyX1T3zVxfpZuEQMIQaGIAQ= +github.com/charmbracelet/x/term v0.2.1/go.mod h1:oQ4enTYFV7QN4m0i9mzHrViD7TQKvNEEkHUMCmsxdUg= github.com/ckaznocha/intrange v0.3.1 h1:j1onQyXvHUsPWujDH6WIjhyH26gkRt/txNlV7LspvJs= github.com/ckaznocha/intrange v0.3.1/go.mod h1:QVepyz1AkUoFQkpEqksSYpNpUo3c5W7nWh/s6SHIJJk= -github.com/clipperhouse/displaywidth v0.11.0 h1:lBc6kY44VFw+TDx4I8opi/EtL9m20WSEFgwIwO+UVM8= -github.com/clipperhouse/displaywidth v0.11.0/go.mod h1:bkrFNkf81G8HyVqmKGxsPufD3JhNl3dSqnGhOoSD/o0= -github.com/clipperhouse/uax29/v2 v2.7.0 h1:+gs4oBZ2gPfVrKPthwbMzWZDaAFPGYK72F0NJv2v7Vk= -github.com/clipperhouse/uax29/v2 v2.7.0/go.mod h1:EFJ2TJMRUaplDxHKj1qAEhCtQPW2tJSwu5BF98AuoVM= -github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 h1:aBangftG7EVZoUb69Os8IaYg++6uMOdKK83QtkkvJik= -github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2/go.mod h1:qwXFYgsP6T7XnJtbKlf1HP8AjxZZyzxMmc+Lq5GjlU4= +github.com/cncf/xds/go v0.0.0-20251210132809-ee656c7534f5 h1:6xNmx7iTtyBRev0+D/Tv1FZd4SCg8axKApyNyRsAt/w= +github.com/cncf/xds/go v0.0.0-20251210132809-ee656c7534f5/go.mod h1:KdCmV+x/BuvyMxRnYBlmVaq4OLiKW6iRQfvC62cvdkI= github.com/cpuguy83/go-md2man/v2 v2.0.0-20190314233015-f79a8a8ca69d/go.mod h1:maD7wRr/U5Z6m/iR4s+kqSMx2CaBsrgA7czyZG/E6dU= github.com/cpuguy83/go-md2man/v2 v2.0.6 h1:XJtiaUW6dEEqVuZiMTn1ldk455QWwEIsMIJlo5vtkx0= github.com/cpuguy83/go-md2man/v2 v2.0.6/go.mod h1:oOW0eioCTA6cOiMLiUPZOpcVxMig6NIQQ7OS05n1F4g= @@ -221,80 +195,65 @@ github.com/dave/dst v0.27.3/go.mod h1:jHh6EOibnHgcUW3WjKHisiooEkYwqpHLBSX1iOBhEy github.com/dave/jennifer v1.7.1 h1:B4jJJDHelWcDhlRQxWeo0Npa/pYKBLrirAQoTN45txo= github.com/dave/jennifer v1.7.1/go.mod h1:nXbxhEmQfOZhWml3D1cDK5M1FLnMSozpbFN/m3RmGZc= github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= +github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= -github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc h1:U9qPSI2PIWSS1VwoXQT9A3Wy9MM3WgvqSxFWenqJduM= -github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= github.com/denis-tingaikin/go-header v0.5.0 h1:SRdnP5ZKvcO9KKRP1KJrhFR3RrlGuD+42t4429eC9k8= github.com/denis-tingaikin/go-header v0.5.0/go.mod h1:mMenU5bWrok6Wl2UsZjy+1okegmwQ3UgWl4V1D8gjlY= -github.com/dlclark/regexp2 v1.12.0 h1:0j4c5qQmnC6XOWNjP3PIXURXN2gWx76rd3KvgdPkCz8= -github.com/dlclark/regexp2 v1.12.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8= -github.com/dlclark/regexp2/v2 v2.2.1 h1:mf4KkFUj0gJuarK8P+LgiS+Lit7m9N1yAwEfPbee7R0= -github.com/dlclark/regexp2/v2 v2.2.1/go.mod h1:avUrQvPaLz2DrFNHJF0taWAFFX2C1GMSSoeiqFjcBmU= +github.com/dlclark/regexp2 v1.11.5 h1:Q/sSnsKerHeCkc/jSTNq1oCm7KiVgUMZRDUoRu0JQZQ= +github.com/dlclark/regexp2 v1.11.5/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8= github.com/dustin/go-humanize v1.0.1 h1:GzkhY7T5VNhEkwH0PVJgjz+fX1rhBrR7pRT3mDkpeCY= github.com/dustin/go-humanize v1.0.1/go.mod h1:Mu1zIs6XwVuF/gI1OepvI0qD18qycQx+mFykh5fBlto= -github.com/ecosyste-ms/ecosystems-go v0.4.0 h1:5A+zF+XWT8sYYYjlc2/tI1SmiDGzbHLyT9CapVc5dGA= -github.com/ecosyste-ms/ecosystems-go v0.4.0/go.mod h1:FVswCrp3DQkur1HjVqfDF/gYrDSEmiFflntcB1G0DbA= +github.com/ecosyste-ms/ecosystems-go v0.1.1 h1:YYiBK9TCCTeE+BtmpN2FssaRFcmF+T0v4LrupIOjehQ= +github.com/ecosyste-ms/ecosystems-go v0.1.1/go.mod h1:VczXs1CO9nL8XbL1NwvgmwIaqzMsAxcsXnTpRtwi9gU= github.com/envoyproxy/go-control-plane v0.14.0 h1:hbG2kr4RuFj222B6+7T83thSPqLjwBIfQawTkC++2HA= -github.com/envoyproxy/go-control-plane/envoy v1.37.0 h1:u3riX6BoYRfF4Dr7dwSOroNfdSbEPe9Yyl09/B6wBrQ= -github.com/envoyproxy/go-control-plane/envoy v1.37.0/go.mod h1:DReE9MMrmecPy+YvQOAOHNYMALuowAnbjjEMkkWOi6A= -github.com/envoyproxy/protoc-gen-validate v1.3.3 h1:MVQghNeW+LZcmXe7SY1V36Z+WFMDjpqGAGacLe2T0ds= -github.com/envoyproxy/protoc-gen-validate v1.3.3/go.mod h1:TsndJ/ngyIdQRhMcVVGDDHINPLWB7C82oDArY51KfB0= +github.com/envoyproxy/go-control-plane/envoy v1.36.0 h1:yg/JjO5E7ubRyKX3m07GF3reDNEnfOboJ0QySbH736g= +github.com/envoyproxy/go-control-plane/envoy v1.36.0/go.mod h1:ty89S1YCCVruQAm9OtKeEkQLTb+Lkz0k8v9W0Oxsv98= +github.com/envoyproxy/protoc-gen-validate v1.3.0 h1:TvGH1wof4H33rezVKWSpqKz5NXWg5VPuZ0uONDT6eb4= +github.com/envoyproxy/protoc-gen-validate v1.3.0/go.mod h1:HvYl7zwPa5mffgyeTUHA9zHIH36nmrm7oCbo4YKoSWA= github.com/ettle/strcase v0.2.0 h1:fGNiVF21fHXpX1niBgk0aROov1LagYsOwV/xqKDKR/Q= github.com/ettle/strcase v0.2.0/go.mod h1:DajmHElDSaX76ITe3/VHVyMin4LWSJN5Z909Wp+ED1A= github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a h1:yDWHCSQ40h88yih2JAcL6Ls/kVkSE8GFACTGVnMPruw= github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a/go.mod h1:7Ga40egUymuWXxAe151lTNnCv97MddSOVsjpPPkityA= -github.com/fatih/color v1.19.0 h1:Zp3PiM21/9Ld6FzSKyL5c/BULoe/ONr9KlbYVOfG8+w= -github.com/fatih/color v1.19.0/go.mod h1:zNk67I0ZUT1bEGsSGyCZYZNrHuTkJJB+r6Q9VuMi0LE= +github.com/fatih/color v1.18.0 h1:S8gINlzdQ840/4pfAwic/ZE0djQEH3wM94VfqLTZcOM= +github.com/fatih/color v1.18.0/go.mod h1:4FelSpRwEGDpQ12mAdzqdOukCy4u8WUtOY6lkT/6HfU= github.com/fatih/structtag v1.2.0 h1:/OdNE99OxoI/PqaW/SuSK9uxxT3f/tcSZgon/ssNSx4= github.com/fatih/structtag v1.2.0/go.mod h1:mBJUNpUnHmRKrKlQQlmCrh5PuhftFbNv8Ys4/aAZl94= -github.com/felixge/httpsnoop v1.1.0 h1:3YtUj32ZZkqZtt3sZZsClsymw/QDuVfpNhoA31zeORc= -github.com/felixge/httpsnoop v1.1.0/go.mod h1:Zqxgdd+1Rkcz8euOqdr7lqgCRJztwr5hp9vDSi5UZCE= -github.com/firefart/nonamedreturns v1.0.8 h1:iB32Dl17zJl1zlVEj/WlUWgx0HiRyQ85OUw1WHa4/II= -github.com/firefart/nonamedreturns v1.0.8/go.mod h1:vxFNvm5AfP/8rgAKFzYmnqx0yp1HjrYsErZ9pHPTznA= +github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2Wg= +github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U= +github.com/firefart/nonamedreturns v1.0.6 h1:vmiBcKV/3EqKY3ZiPxCINmpS431OcE1S47AQUwhrg8E= +github.com/firefart/nonamedreturns v1.0.6/go.mod h1:R8NisJnSIpvPWheCq0mNRXJok6D8h7fagJTF8EMEwCo= github.com/frankban/quicktest v1.14.3 h1:FJKSZTDHjyhriyC81FLQ0LY93eSai0ZyR/ZIkd3ZUKE= github.com/frankban/quicktest v1.14.3/go.mod h1:mgiwOwqx65TmIk1wJ6Q7wvnVMocbUorkibMOrVTHZps= github.com/fsnotify/fsnotify v1.9.0 h1:2Ml+OJNzbYCTzsxtv8vKSFD9PbJjmhYF14k/jKC7S9k= github.com/fsnotify/fsnotify v1.9.0/go.mod h1:8jBTzvmWwFyi3Pb8djgCCO5IBqzKJ/Jwo8TRcHyHii0= github.com/fzipp/gocyclo v0.6.0 h1:lsblElZG7d3ALtGMx9fmxeTKZaLLpU8mET09yN4BBLo= github.com/fzipp/gocyclo v0.6.0/go.mod h1:rXPyn8fnlpa0R2csP/31uerbiVBugk5whMdlyaLkLoA= -github.com/ghostiam/protogetter v0.3.21 h1:EeWTGvL/Eyosp653hiWb6Byx4b69iJC4/E+za7vQHoI= -github.com/ghostiam/protogetter v0.3.21/go.mod h1:iAKSpyoHwYzay+OpjoWgwzRtPFthEfuUvmlomTThck0= -github.com/git-pkgs/archives v0.7.0 h1:cRQEKK1N7LMabzXxExwmoAtRvxjuIAkzBxEZmYfH040= -github.com/git-pkgs/archives v0.7.0/go.mod h1:LH7LSbREEaRlxtLwG2PC7evfhlWNgUB/DMBFr6+KsAA= -github.com/git-pkgs/artifacts v0.2.1 h1:VwdxR4yTDaqBZ34h0slxQBVyr2Xfa+QGOKCKviMx2xk= -github.com/git-pkgs/artifacts v0.2.1/go.mod h1:Otosgq52pXT5UNN7lh6s/lszpWKVDO8XrOjN1M70/IA= -github.com/git-pkgs/cooldown v0.2.0 h1:0MWPHtkzZgvCR0wdiQeyvMea/dxgw9tParH1zzaFopc= -github.com/git-pkgs/cooldown v0.2.0/go.mod h1:v7APuK/UouTiu8mWQZbdDmj7DfxxkGUeuhjaRB5gv9E= -github.com/git-pkgs/enrichment v0.7.1 h1:8PRYE7gaB8y4M5wnRw/ymNDk0uOHtbQ8CEE7hF09Bv0= -github.com/git-pkgs/enrichment v0.7.1/go.mod h1:QYLG8MtVWPqZojnq7KBKK/lllBWSjLnqvJCWvzGuNwU= -github.com/git-pkgs/gcs v0.1.0 h1:E3awGtsO0xZyHT9FUfEwMHjMkRxw41Bh+c7lgTmPvBo= -github.com/git-pkgs/gcs v0.1.0/go.mod h1:bdkCFD66ryaWnU8MBhokVA3WkJfyAEchm9qec5woBpE= -github.com/git-pkgs/integrity v0.1.1 h1:nHQ7SktOiGM1dOb5BFnkdtttG/6FCgE6r5ru6QnsGts= -github.com/git-pkgs/integrity v0.1.1/go.mod h1:hxu24lcd230377hCF28JQW7sGcCbuNLqo/0ULeb+F1Q= -github.com/git-pkgs/magic v0.3.1 h1:UzjFRyEwJITA/JgznjmIM4VwuBszD2K4Q8XHgkgL+DM= -github.com/git-pkgs/magic v0.3.1/go.mod h1:SXOqcsNmbmpZjJZHEEWnwxprbsFvpwWgTAZrgXp4Jm4= +github.com/ghostiam/protogetter v0.3.20 h1:oW7OPFit2FxZOpmMRPP9FffU4uUpfeE/rEdE1f+MzD0= +github.com/ghostiam/protogetter v0.3.20/go.mod h1:FjIu5Yfs6FT391m+Fjp3fbAYJ6rkL/J6ySpZBfnODuI= +github.com/git-pkgs/archives v0.2.2 h1:RxOjrV8RzKicbMVdf2GDKOqIOHZNVjrLY/Pc7KSE/WQ= +github.com/git-pkgs/archives v0.2.2/go.mod h1:LTJ1iQVFA7otizWMOyiI82NYVmyBWAPRzwu/e30rcXU= +github.com/git-pkgs/enrichment v0.2.2 h1:vaQu5vs3tjQB5JI0gzBrUCynUc9z3l5byPhgKFaNZrc= +github.com/git-pkgs/enrichment v0.2.2/go.mod h1:5JWGmlHWcv5HQHUrctcpnRUNpEF5VAixD2z4zvqKejs= github.com/git-pkgs/packageurl-go v0.3.1 h1:WM3RBABQZLaRBxgKyYughc3cVBE8KyQxbSC6Jt5ak7M= github.com/git-pkgs/packageurl-go v0.3.1/go.mod h1:rcIxiG37BlQLB6FZfgdj9Fm7yjhRQd3l+5o7J0QPAk4= -github.com/git-pkgs/pom v0.1.7 h1:4yKdtw6eyShtjul6bcZdyz7yLQ+jdrYeYkKbskDGi4c= -github.com/git-pkgs/pom v0.1.7/go.mod h1:ufdMBe1lKzqOeP9IUb9NPZ458xKV8E8NvuyBMxOfwIk= -github.com/git-pkgs/purl v0.1.20 h1:a4qzvUy5mBZ2GGjOQNW2h/ocFqjTjOiTDMv2ONtivmM= -github.com/git-pkgs/purl v0.1.20/go.mod h1:hthV5mp+Q67HpQ9+LnRLLmsReu5ooyQ5EaJsCGrA8yE= -github.com/git-pkgs/registries v0.9.1 h1:z5GVFfLHWGoVEawppqXTaE2Y6RADkUbTPYctEs3BZ4M= -github.com/git-pkgs/registries v0.9.1/go.mod h1:5rmFrC76K3zmOAJTTQPcYy0vV2i7MRByM1OQiQdGzl4= -github.com/git-pkgs/spdx v0.3.1 h1:58JPY5X9pYpXvnzzZIgehItlBykeOOw52pNc4OBcS+c= -github.com/git-pkgs/spdx v0.3.1/go.mod h1:cqRoZcvl530s/W+oGNvwjt4ODN8T1W6D/20MUZEFdto= -github.com/git-pkgs/vers v0.7.0 h1:7PD2DKFB8jTDIfiyWXbqYW54iVuNkFCBgXHgxOTdr8A= -github.com/git-pkgs/vers v0.7.0/go.mod h1:ofLiBpPNkQmC0LB1k0zmN1gCv7Hi3MiZx8WtmWZ4A9A= -github.com/git-pkgs/vulns v0.2.3 h1:G8icINpR9WFgtwp+4mSdgO4THStiQvi6QuHl83J7iOs= -github.com/git-pkgs/vulns v0.2.3/go.mod h1:+z7pZMjctLmUxMsq+tZbciD6xAAoejljDosC6n2YXps= -github.com/github/go-spdx/v2 v2.7.0 h1:GzfXx4wFdlilARxmFRXW/mgUy3A4vSqZocCMFV6XFdQ= -github.com/github/go-spdx/v2 v2.7.0/go.mod h1:Ftc45YYG1WzpzwEPKRVm9Jv8vDqOrN4gWoCkK+bHer0= -github.com/go-chi/chi/v5 v5.3.2 h1:5YQkICvTCSZ25hoRsyJazN0scjzKGiu4VAUc7H1o1nY= -github.com/go-chi/chi/v5 v5.3.2/go.mod h1:R+tYY2hNuVUUjxoPtqUdgBqevM9s9njzkTLutVsOCto= -github.com/go-critic/go-critic v0.14.4 h1:dSX4C3pWSeuMVxvQh6yG8U0ReSf3YOmKi4nwX5q7n/8= -github.com/go-critic/go-critic v0.14.4/go.mod h1:xwntfW6SYAd7h1OqDzmN6hBX/JxsEKl5up/Y2bsxgVQ= -github.com/go-jose/go-jose/v4 v4.1.4 h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA= -github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08= +github.com/git-pkgs/purl v0.1.10 h1:NMjeF10nzFn3tdQlz6rbmHB+i+YkyrFQxho3e33ePTQ= +github.com/git-pkgs/purl v0.1.10/go.mod h1:C5Vp/kyZ/wGckCLexx4wPVfUxEiToRkdsOPh5Z7ig/I= +github.com/git-pkgs/registries v0.4.0 h1:GO7fQ8/jot0ulSQHBdxLSNSX/p8eB3gEXWO+98fmoEo= +github.com/git-pkgs/registries v0.4.0/go.mod h1:49UCPFWQmwNV7rBEr9TrTDWKR7vYxFcxp3VfdkeFbdE= +github.com/git-pkgs/spdx v0.1.2 h1:wHSK+CqFsO5N7yDTPvxDmer5LgNEa7vAsiZhi5Aci0A= +github.com/git-pkgs/spdx v0.1.2/go.mod h1:V98MgZapNgYw54/pdGR82d7RU93qzJoybahbpZqTfw8= +github.com/git-pkgs/vers v0.2.4 h1:Zr3jR/Xf1i/6cvBaJKPxhCwjzqz7uvYHE0Fhid/GPBk= +github.com/git-pkgs/vers v0.2.4/go.mod h1:biTbSQK1qdbrsxDEKnqe3Jzclxz8vW6uDcwKjfUGcOo= +github.com/git-pkgs/vulns v0.1.4 h1:SlnGWHNmtdQgABjfrX/I/pVe+DWLbZ5Yi9xg+/De5r8= +github.com/git-pkgs/vulns v0.1.4/go.mod h1:34xkR7QncIVfxoi78k3YT6Y9DfTEaL7j6PzCqjsRP9U= +github.com/github/go-spdx/v2 v2.4.0 h1:+4IwVwJJbm3rzvrQ6P1nI9BDMcy3la4RchRy5uehV/M= +github.com/github/go-spdx/v2 v2.4.0/go.mod h1:/5rwgS0txhGtRdUZwc02bTglzg6HK3FfuEbECKlK2Sg= +github.com/go-chi/chi/v5 v5.2.5 h1:Eg4myHZBjyvJmAFjFvWgrqDTXFyOzjj7YIm3L3mu6Ug= +github.com/go-chi/chi/v5 v5.2.5/go.mod h1:X7Gx4mteadT3eDOMTsXzmI4/rwUpOwBHLpAfupzFJP0= +github.com/go-critic/go-critic v0.14.3 h1:5R1qH2iFeo4I/RJU8vTezdqs08Egi4u5p6vOESA0pog= +github.com/go-critic/go-critic v0.14.3/go.mod h1:xwntfW6SYAd7h1OqDzmN6hBX/JxsEKl5up/Y2bsxgVQ= +github.com/go-jose/go-jose/v4 v4.1.3 h1:CVLmWDhDVRa6Mi/IgCgaopNosCaHz7zrMeF9MlZRkrs= +github.com/go-jose/go-jose/v4 v4.1.3/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08= github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A= github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI= github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= @@ -310,8 +269,8 @@ github.com/go-openapi/spec v0.20.4/go.mod h1:faYFR1CvsJZ0mNsmsphTMSoRrNV3TEDoAM7 github.com/go-openapi/swag v0.19.5/go.mod h1:POnQmlKehdgb5mhVOsnJFsivZCEZ/vjK9gh66Z9tfKk= github.com/go-openapi/swag v0.19.15 h1:D2NRCBzS9/pEY3gP9Nl8aDqGUcPFrwG2p+CNFrLyrCM= github.com/go-openapi/swag v0.19.15/go.mod h1:QYRuS/SOXUCsnplDa677K7+DxSOj6IPNl/eQntq43wQ= -github.com/go-quicktest/qt v1.102.0 h1:HSQxCeh5YZH3EL3W39ixjtyaEhcWSXQHtHnMBzSs474= -github.com/go-quicktest/qt v1.102.0/go.mod h1:p4lGIVX+8Wa6ZPNDvqcxq36XpUDLh42FLetFU7odllI= +github.com/go-quicktest/qt v1.101.0 h1:O1K29Txy5P2OK0dGo59b7b0LR6wKfIhttaAhHUyn7eI= +github.com/go-quicktest/qt v1.101.0/go.mod h1:14Bz/f7NwaXPtdYEgzsx46kqSxVwTbzVZsDC26tQJow= github.com/go-sql-driver/mysql v1.8.1/go.mod h1:wEBSXgmK//2ZFJyE+qWnIsVGmvmEKlqwuVSjsCm7DZg= github.com/go-sql-driver/mysql v1.9.3 h1:U/N249h2WzJ3Ukj8SowVFjdtZKfu9vlLZxjPXV1aweo= github.com/go-sql-driver/mysql v1.9.3/go.mod h1:qn46aNg1333BRMNU69Lq93t8du/dwxI64Gl8i5p1WMU= @@ -346,20 +305,18 @@ github.com/godoc-lint/godoc-lint v0.11.2 h1:Bp0FkJWoSdNsBikdNgIcgtaoo+xz6I/Y9s5W github.com/godoc-lint/godoc-lint v0.11.2/go.mod h1:iVpGdL1JCikNH2gGeAn3Hh+AgN5Gx/I/cxV+91L41jo= github.com/gofrs/flock v0.13.0 h1:95JolYOvGMqeH31+FC7D2+uULf6mG61mEZ/A8dRYMzw= github.com/gofrs/flock v0.13.0/go.mod h1:jxeyy9R1auM5S6JYDBhDt+E2TCo7DkratH4Pgi8P+Z0= -github.com/golang-jwt/jwt/v5 v5.3.1 h1:kYf81DTWFe7t+1VvL7eS+jKFVWaUnK9cB1qbwn63YCY= -github.com/golang-jwt/jwt/v5 v5.3.1/go.mod h1:fxCRLWMO43lRc8nhHWY6LGqRcf+1gQWArsqaEUEa5bE= github.com/golang/protobuf v1.5.4 h1:i7eJL8qZTpSEXOPTxNKhASYpMn+8e5Q6AdndVa1dWek= github.com/golang/protobuf v1.5.4/go.mod h1:lnTiLA8Wa4RWRcIUkrtSVa5nRhsEGBg48fD6rSs7xps= github.com/golangci/asciicheck v0.5.0 h1:jczN/BorERZwK8oiFBOGvlGPknhvq0bjnysTj4nUfo0= github.com/golangci/asciicheck v0.5.0/go.mod h1:5RMNAInbNFw2krqN6ibBxN/zfRFa9S6tA1nPdM0l8qQ= -github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202 h1:CbTB8KpqnViI6lIXxp03Oclc4VFHi3K4BWC1TacsZ+A= -github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202/go.mod h1:NUw9Zr2Sy7+HxzdjIULge71wI6yEg1lWQr7Evcu8K0E= +github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32 h1:WUvBfQL6EW/40l6OmeSBYQJNSif4O11+bmWEz+C7FYw= +github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32/go.mod h1:NUw9Zr2Sy7+HxzdjIULge71wI6yEg1lWQr7Evcu8K0E= github.com/golangci/go-printf-func-name v0.1.1 h1:hIYTFJqAGp1iwoIfsNTpoq1xZAarogrvjO9AfiW3B4U= github.com/golangci/go-printf-func-name v0.1.1/go.mod h1:Es64MpWEZbh0UBtTAICOZiB+miW53w/K9Or/4QogJss= -github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792 h1:WL8YKrt3UbOBqSRU7GpP5BTtQTMWtVtj+mfPijgZeIg= -github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792/go.mod h1:te5hX0dW4C5r6YbXs+6ysNr8Q5UTmdIqGbb+mlFiYmA= -github.com/golangci/golangci-lint/v2 v2.13.1 h1:RuM4OcluM4xFQcGuRE6R7jA33pqxK/W1EsBxpugdZjg= -github.com/golangci/golangci-lint/v2 v2.13.1/go.mod h1:HwX7mDzqHbcSxlhrTygjX1GJbAfQ3sJAqOx41qQlhDE= +github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d h1:viFft9sS/dxoYY0aiOTsLKO2aZQAPT4nlQCsimGcSGE= +github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d/go.mod h1:ivJ9QDg0XucIkmwhzCDsqcnxxlDStoTl89jDMIoNxKY= +github.com/golangci/golangci-lint/v2 v2.10.1 h1:flhw5Px6ojbLyEFzXvJn5B2HEdkkRlkhE1SnmCbQBiE= +github.com/golangci/golangci-lint/v2 v2.10.1/go.mod h1:dBsrOk6zj0vDhlTv+IiJGqkDokR24IVTS7W3EVfPTQY= github.com/golangci/golines v0.15.0 h1:Qnph25g8Y1c5fdo1X7GaRDGgnMHgnxh4Gk4VfPTtRx0= github.com/golangci/golines v0.15.0/go.mod h1:AZjXd23tbHMpowhtnGlj9KCNsysj72aeZVVHnVcZx10= github.com/golangci/misspell v0.8.0 h1:qvxQhiE2/5z+BVRo1kwYA8yGz+lOlu5Jfvtx2b04Jbg= @@ -368,8 +325,6 @@ github.com/golangci/plugin-module-register v0.1.2 h1:e5WM6PO6NIAEcij3B053CohVp3H github.com/golangci/plugin-module-register v0.1.2/go.mod h1:1+QGTsKBvAIvPvoY/os+G5eoqxWn70HYDm2uvUyGuVw= github.com/golangci/revgrep v0.8.0 h1:EZBctwbVd0aMeRnNUsFogoyayvKHyxlV3CdUA46FX2s= github.com/golangci/revgrep v0.8.0/go.mod h1:U4R/s9dlXZsg8uJmaR1GrloUr14D7qDl8gi2iPXJH8k= -github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba h1:lqtcnSMDuuJdu/LrKWi5RJzpSNLOJXYe/nzQutTI5kg= -github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba/go.mod h1:sCBNcpRmhJCtbFGz49+IM3ETTFf7QdJ30AeYCd43NKk= github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e h1:ai0EfmVYE2bRA5htgAG9r7s3tHsfjIhN98WshBTJ9jM= github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e/go.mod h1:Vrn4B5oR9qRwM+f54koyeH3yzphlecwERs0el27Fr/s= github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e h1:gD6P7NEo7Eqtt0ssnqSJNNndxe69DOQ24A5h7+i3KpM= @@ -385,18 +340,18 @@ github.com/google/go-replayers/httpreplay v1.2.0 h1:VM1wEyyjaoU53BwrOnaf9VhAyQQE github.com/google/go-replayers/httpreplay v1.2.0/go.mod h1:WahEFFZZ7a1P4VM1qEeHy+tME4bwyqPcwWbNlUI1Mcg= github.com/google/martian/v3 v3.3.3 h1:DIhPTQrbPkgs2yJYdXU/eNACCG5DVQjySNRNlflZ9Fc= github.com/google/martian/v3 v3.3.3/go.mod h1:iEPrYcgCF7jA9OtScMFQyAlZZ4YXTKEtJ1E6RWzmBA0= -github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3 h1:LMLX+LgTNWpfvCBdFebv6EsYotImrt/Ppc5cXIriCSo= -github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3/go.mod h1:jl5iWTm0/hd5PjEYEOuwAJ57L/CibdZfrqZ5XA5GrCk= +github.com/google/pprof v0.0.0-20260115054156-294ebfa9ad83 h1:z2ogiKUYzX5Is6zr/vP9vJGqPwcdqsWjOt+V8J7+bTc= +github.com/google/pprof v0.0.0-20260115054156-294ebfa9ad83/go.mod h1:MxpfABSjhmINe3F1It9d+8exIHFvUqtLIRCdOGNXqiI= github.com/google/s2a-go v0.1.9 h1:LGD7gtMgezd8a/Xak7mEWL0PjoTQFvpRudN895yqKW0= github.com/google/s2a-go v0.1.9/go.mod h1:YA0Ei2ZQL3acow2O62kdp9UlnvMmU7kA6Eutn0dXayM= github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0= github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= github.com/google/wire v0.7.0 h1:JxUKI6+CVBgCO2WToKy/nQk0sS+amI9z9EjVmdaocj4= github.com/google/wire v0.7.0/go.mod h1:n6YbUQD9cPKTnHXEBN2DXlOp/mVADhVErcMFb0v3J18= -github.com/googleapis/enterprise-certificate-proxy v0.3.18 h1:hvVi34VucdrV1IIsiWuqYM8kutw/92MxNEFxCJZEh0k= -github.com/googleapis/enterprise-certificate-proxy v0.3.18/go.mod h1:rSEsBUemEBZEexP2y6jPp16LUmUbjmSbcPMQizR0o4k= -github.com/googleapis/gax-go/v2 v2.23.0 h1:Tchl7qkvE7Ip3y+ztvNufYFvkfqTe7NfLTYGIdJRLuE= -github.com/googleapis/gax-go/v2 v2.23.0/go.mod h1:rBQKOVJCdb8IFEzg+FCwlt1LP/xMDGuqUXhUG+XMXEg= +github.com/googleapis/enterprise-certificate-proxy v0.3.12 h1:Fg+zsqzYEs1ZnvmcztTYxhgCBsx3eEhEwQ1W/lHq/sQ= +github.com/googleapis/enterprise-certificate-proxy v0.3.12/go.mod h1:vqVt9yG9480NtzREnTlmGSBmFrA+bzb0yl0TxoBQXOg= +github.com/googleapis/gax-go/v2 v2.17.0 h1:RksgfBpxqff0EZkDWYuz9q/uWsTVz+kf43LsZ1J6SMc= +github.com/googleapis/gax-go/v2 v2.17.0/go.mod h1:mzaqghpQp4JDh3HvADwrat+6M3MOIDp5YKHhb9PAgDY= github.com/gordonklaus/ineffassign v0.2.0 h1:Uths4KnmwxNJNzq87fwQQDDnbNb7De00VOk9Nu0TySs= github.com/gordonklaus/ineffassign v0.2.0/go.mod h1:TIpymnagPSexySzs7F9FnO1XFTy8IT3a59vmZp5Y9Lw= github.com/gostaticanalysis/analysisutil v0.7.1 h1:ZMCjoue3DtDWQ5WyU16YbjbQEQ3VuzwxALrpYd+HeKk= @@ -416,8 +371,8 @@ github.com/hashicorp/go-immutable-radix/v2 v2.1.0/go.mod h1:hgdqLXA4f6NIjRVisM1T github.com/hashicorp/go-uuid v1.0.3 h1:2gKiV6YVmrJ1i2CKKa9obLvRieoRGviZFL26PcT/Co8= github.com/hashicorp/go-uuid v1.0.3/go.mod h1:6SBZvOh/SIDV7/2o3Jml5SYk/TvGqwFJ/bN7x4byOro= github.com/hashicorp/go-version v1.2.1/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA= -github.com/hashicorp/go-version v1.9.0 h1:CeOIz6k+LoN3qX9Z0tyQrPtiB1DFYRPfCIBtaXPSCnA= -github.com/hashicorp/go-version v1.9.0/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA= +github.com/hashicorp/go-version v1.8.0 h1:KAkNb1HAiZd1ukkxDFGmokVZe1Xy9HG6NUp+bPle2i4= +github.com/hashicorp/go-version v1.8.0/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA= github.com/hashicorp/golang-lru/v2 v2.0.7 h1:a+bsQ5rvGLjzHuww6tVxozPZFVghXaHOwFs4luLUK2k= github.com/hashicorp/golang-lru/v2 v2.0.7/go.mod h1:QeFd9opnmA6QUJc5vARoKUSoFhyfM2/ZepoAG6RGpeM= github.com/hashicorp/hcl v1.0.0 h1:0Anlzjpi4vEasTeNFn2mLJgTSwt0+6sfsiTG8qcWGx4= @@ -426,8 +381,10 @@ github.com/hexops/gotextdiff v1.0.3 h1:gitA9+qJrrTCsiCl7+kh75nPqQt1cx4ZkudSTLoUq github.com/hexops/gotextdiff v1.0.3/go.mod h1:pSWU5MAI3yDq+fZBTazCSJysOMbxWL1BSow5/V2vxeg= github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8= github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw= -github.com/jgautheron/goconst v1.11.0 h1:KgN90z5qXt5f0Uzf3cWXev3hfMMFUyNeKdpkSBRvLDk= -github.com/jgautheron/goconst v1.11.0/go.mod h1:0p+wv1lFOiUr0IlNNT1nrm6+8DB8u2sU6KHGzFRXHDc= +github.com/jgautheron/goconst v1.8.2 h1:y0XF7X8CikZ93fSNT6WBTb/NElBu9IjaY7CCYQrCMX4= +github.com/jgautheron/goconst v1.8.2/go.mod h1:A0oxgBCHy55NQn6sYpO7UdnA9p+h7cPtoOZUmvNIako= +github.com/jingyugao/rowserrcheck v1.1.1 h1:zibz55j/MJtLsjP1OF4bSdgXxwL1b+Vn7Tjzq7gFzUs= +github.com/jingyugao/rowserrcheck v1.1.1/go.mod h1:4yvlZSDb3IyDTUZJUmpZfm2Hwok+Dtp+nu2qOq+er9c= github.com/jjti/go-spancheck v0.6.5 h1:lmi7pKxa37oKYIMScialXUK6hP3iY5F1gu+mLBPgYB8= github.com/jjti/go-spancheck v0.6.5/go.mod h1:aEogkeatBrbYsyW6y5TgDfihCulDYciL1B7rG2vSsrU= github.com/jmoiron/sqlx v1.4.0 h1:1PLqN7S1UYp5t4SrVVnt4nUVNemrDAtxlulVe+Qgm3o= @@ -439,14 +396,12 @@ github.com/julz/importas v0.2.0 h1:y+MJN/UdL63QbFJHws9BVC5RpA2iq0kpjrFajTGivjQ= github.com/julz/importas v0.2.0/go.mod h1:pThlt589EnCYtMnmhmRYY/qn9lCf/frPOK+WMx3xiJY= github.com/karamaru-alpha/copyloopvar v1.2.2 h1:yfNQvP9YaGQR7VaWLYcfZUlRP2eo2vhExWKxD/fP6q0= github.com/karamaru-alpha/copyloopvar v1.2.2/go.mod h1:oY4rGZqZ879JkJMtX3RRkcXRkmUvH0x35ykgaKgsgJY= -github.com/keybase/go-keychain v0.0.1 h1:way+bWYa6lDppZoZcgMbYsvC7GxljxrskdNInRtuthU= -github.com/keybase/go-keychain v0.0.1/go.mod h1:PdEILRW3i9D8JcdM+FmY6RwkHGnhHxXwkPPMeUgOK1k= -github.com/kisielk/errcheck v1.20.0 h1:9rwHBNKzd4wkDWcROy3DvFGNqEPlkxBg305rvk7HabI= -github.com/kisielk/errcheck v1.20.0/go.mod h1:O+f80MKNwX8Oor2jwgpeQ9An7uJm+hRSgT+h22knRJU= +github.com/kisielk/errcheck v1.9.0 h1:9xt1zI9EBfcYBvdU1nVrzMzzUPUtPKs9bVSIM3TAb3M= +github.com/kisielk/errcheck v1.9.0/go.mod h1:kQxWMMVZgIkDq7U8xtG/n2juOjbLgZtedi0D+/VL/i8= github.com/kkHAIKE/contextcheck v1.1.6 h1:7HIyRcnyzxL9Lz06NGhiKvenXq7Zw6Q0UQu/ttjfJCE= github.com/kkHAIKE/contextcheck v1.1.6/go.mod h1:3dDbMRNBFaq8HFXWC1JyvDSPm43CmE6IuHam8Wr0rkg= -github.com/klauspost/compress v1.19.2 h1:hMRETovs/pu/dVWN7zIT1PGG8t509MwT6bO7XSi26R8= -github.com/klauspost/compress v1.19.2/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ= +github.com/klauspost/compress v1.18.0 h1:c/Cqfb0r+Yi+JtIEq73FWXVkRonBlf0CRNYc8Zttxdo= +github.com/klauspost/compress v1.18.0/go.mod h1:2Pp+KzxcywXVXMr50+X0Q/Lsb43OQHYWRCY2AiWywWQ= github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo= github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE= github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk= @@ -464,8 +419,8 @@ github.com/lasiar/canonicalheader v1.1.2 h1:vZ5uqwvDbyJCnMhmFYimgMZnJMjwljN5VGY0 github.com/lasiar/canonicalheader v1.1.2/go.mod h1:qJCeLFS0G/QlLQ506T+Fk/fWMa2VmBUiEI2cuMK4djI= github.com/ldez/exptostd v0.4.5 h1:kv2ZGUVI6VwRfp/+bcQ6Nbx0ghFWcGIKInkG/oFn1aQ= github.com/ldez/exptostd v0.4.5/go.mod h1:QRjHRMXJrCTIm9WxVNH6VW7oN7KrGSht69bIRwvdFsM= -github.com/ldez/gomoddirectives v0.9.0 h1:2YV/EX7nVlWL4jySusYTzBKHuE3D2fgcRsQuMa3yIoo= -github.com/ldez/gomoddirectives v0.9.0/go.mod h1:DdZzfm9MdXCjn2/UGYXCFfo+tzrp2Ib4iD2Q0kIJkwE= +github.com/ldez/gomoddirectives v0.8.0 h1:JqIuTtgvFC2RdH1s357vrE23WJF2cpDCPFgA/TWDGpk= +github.com/ldez/gomoddirectives v0.8.0/go.mod h1:jutzamvZR4XYJLr0d5Honycp4Gy6GEg2mS9+2YX3F1Q= github.com/ldez/grignotin v0.10.1 h1:keYi9rYsgbvqAZGI1liek5c+jv9UUjbvdj3Tbn5fn4o= github.com/ldez/grignotin v0.10.1/go.mod h1:UlDbXFCARrXbWGNGP3S5vsysNXAPhnSuBufpTEbwOas= github.com/ldez/structtags v0.6.1 h1:bUooFLbXx41tW8SvkfwfFkkjPYvFFs59AAMgVg6DUBk= @@ -477,10 +432,10 @@ github.com/ldez/usetesting v0.5.0/go.mod h1:Spnb4Qppf8JTuRgblLrEWb7IE6rDmUpGvxY3 github.com/leonklingele/grouper v1.1.2 h1:o1ARBDLOmmasUaNDesWqWCIFH3u7hoFlM84YrjT3mIY= github.com/leonklingele/grouper v1.1.2/go.mod h1:6D0M/HVkhs2yRKRFZUoGjeDy7EZTfFBE9gl4kjmIGkA= github.com/lib/pq v1.10.9/go.mod h1:AlVN5x4E4T544tWzH6hKfbfQvm3HdbOxrmggDNAPY9o= -github.com/lib/pq v1.12.3 h1:tTWxr2YLKwIvK90ZXEw8GP7UFHtcbTtty8zsI+YjrfQ= -github.com/lib/pq v1.12.3/go.mod h1:/p+8NSbOcwzAEI7wiMXFlgydTwcgTr3OSKMsD2BitpA= -github.com/lucasb-eyer/go-colorful v1.4.1 h1:1EO+WB73+EH8EVbzlrG3KLAfEypQWVHIBqlTf+2hNss= -github.com/lucasb-eyer/go-colorful v1.4.1/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0= +github.com/lib/pq v1.12.2 h1:ajJNv84limnK3aPbDIhLtcjrUbqAw/5XNdkuI6KNe/Q= +github.com/lib/pq v1.12.2/go.mod h1:/p+8NSbOcwzAEI7wiMXFlgydTwcgTr3OSKMsD2BitpA= +github.com/lucasb-eyer/go-colorful v1.2.0 h1:1nnpGOrhyZZuNyfu1QjKiUICQ74+3FNCN69Aj6K7nkY= +github.com/lucasb-eyer/go-colorful v1.2.0/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0= github.com/macabu/inamedparam v0.2.0 h1:VyPYpOc10nkhI2qeNUdh3Zket4fcZjEWe35poddBCpE= github.com/macabu/inamedparam v0.2.0/go.mod h1:+Pee9/YfGe5LJ62pYXqB89lJ+0k5bsR8Wgz/C0Zlq3U= github.com/magiconair/properties v1.8.6 h1:5ibWZ6iY0NctNGWo87LalDlEZ6R41TqbbDamhfG/Qzo= @@ -492,8 +447,8 @@ github.com/mailru/easyjson v0.7.7 h1:UGYAvKxe3sBsEDzO8ZeWOSlIQfWFlxbzLZe7hwFURr0 github.com/mailru/easyjson v0.7.7/go.mod h1:xzfreul335JAWq5oZzymOObrkdz5UnU4kGfJJLY9Nlc= github.com/manuelarte/embeddedstructfieldcheck v0.4.0 h1:3mAIyaGRtjK6EO9E73JlXLtiy7ha80b2ZVGyacxgfww= github.com/manuelarte/embeddedstructfieldcheck v0.4.0/go.mod h1:z8dFSyXqp+fC6NLDSljRJeNQJJDWnY7RoWFzV3PC6UM= -github.com/manuelarte/funcorder v0.6.0 h1:0hBngc4fa1IgNiI65A7sFGkMvoMCc878RjqB5V7rWP0= -github.com/manuelarte/funcorder v0.6.0/go.mod h1:id3NDhXdQBmeqXH7eVC6Z89xS6JxvZ8kF9xUxpArU/g= +github.com/manuelarte/funcorder v0.5.0 h1:llMuHXXbg7tD0i/LNw8vGnkDTHFpTnWqKPI85Rknc+8= +github.com/manuelarte/funcorder v0.5.0/go.mod h1:Yt3CiUQthSBMBxjShjdXMexmzpP8YGvGLjrxJNkO2hA= github.com/maratori/testableexamples v1.0.1 h1:HfOQXs+XgfeRBJ+Wz0XfH+FHnoY9TVqL6Fcevpzy4q8= github.com/maratori/testableexamples v1.0.1/go.mod h1:XE2F/nQs7B9N08JgyRmdGjYVGqxWwClLPCGSQhXQSrQ= github.com/maratori/testpackage v1.1.2 h1:ffDSh+AgqluCLMXhM19f/cpvQAKygKAJXFl9aUjmbqs= @@ -502,24 +457,24 @@ github.com/matoous/godox v1.1.0 h1:W5mqwbyWrwZv6OQ5Z1a/DHGMOvXYCBP3+Ht7KMoJhq4= github.com/matoous/godox v1.1.0/go.mod h1:jgE/3fUXiTurkdHOLT5WEkThTSuE7yxHv5iWPa80afs= github.com/matryer/is v1.4.0 h1:sosSmIWwkYITGrxZ25ULNDeKiMNzFSr4V/eqBQP0PeE= github.com/matryer/is v1.4.0/go.mod h1:8I/i5uYgLzgsgEloJE1U6xx5HkBQpAZvepWuujKwMRU= -github.com/mattn/go-colorable v0.1.15 h1:+u9SLTRGnXv73cEsnsmoZBom+dMU88B2M0aDcWy0/jY= -github.com/mattn/go-colorable v0.1.15/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8= -github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsReI= -github.com/mattn/go-isatty v0.0.24/go.mod h1:nMCL3Zebbrt45jsMDgnfIwz6ydEQApk5oEI3HqDio6A= -github.com/mattn/go-runewidth v0.0.24 h1:cpokDiIn0MGnhdHwuWnJBITySJ20QyNGnY2kR/ay2DU= -github.com/mattn/go-runewidth v0.0.24/go.mod h1:XBkDxAl56ILZc9knddidhrOlY5R/pDhgLpndooCuJAs= +github.com/mattn/go-colorable v0.1.14 h1:9A9LHSqF/7dyVVX6g0U9cwm9pG3kP9gSzcuIPHPsaIE= +github.com/mattn/go-colorable v0.1.14/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8= +github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY= +github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y= +github.com/mattn/go-runewidth v0.0.16 h1:E5ScNMtiwvlvB5paMFdw9p4kSQzbXFikJ5SQO6TULQc= +github.com/mattn/go-runewidth v0.0.16/go.mod h1:Jdepj2loyihRzMpdS35Xk/zdY8IAYHsh153qUoGf23w= github.com/mattn/go-sqlite3 v1.14.22 h1:2gZY6PC6kBnID23Tichd1K+Z0oS6nE/XwU+Vz/5o4kU= github.com/mattn/go-sqlite3 v1.14.22/go.mod h1:Uh1q+B4BYcTPb+yiD3kU8Ct7aC0hY9fxUwlHK0RXw+Y= -github.com/mgechev/revive v1.15.0 h1:vJ0HzSBzfNyPbHKolgiFjHxLek9KUijhqh42yGoqZ8Q= -github.com/mgechev/revive v1.15.0/go.mod h1:LlAKO3QQe9OJ0pVZzI2GPa8CbXGZ/9lNpCGvK4T/a8A= +github.com/mgechev/revive v1.14.0 h1:CC2Ulb3kV7JFYt+izwORoS3VT/+Plb8BvslI/l1yZsc= +github.com/mgechev/revive v1.14.0/go.mod h1:MvnujelCZBZCaoDv5B3foPo6WWgULSSFxvfxp7GsPfo= github.com/mitchellh/go-homedir v1.1.0 h1:lukF9ziXFxDFPkA1vsr5zpc1XuPDn/wFntq5mG+4E0Y= github.com/mitchellh/go-homedir v1.1.0/go.mod h1:SfyaCUpYCn1Vlf4IUYiD9fPX4A5wJrkLzIz1N1q0pr0= github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY= github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo= github.com/moricho/tparallel v0.3.2 h1:odr8aZVFA3NZrNybggMkYO3rgPRcqjeQUlBBFVxKHTI= github.com/moricho/tparallel v0.3.2/go.mod h1:OQ+K3b4Ln3l2TZveGCywybl68glfLEwFGqvnjok8b+U= -github.com/muesli/cancelreader v0.2.2 h1:3I4Kt4BQjOR54NavqnDogx/MIoWBFa0StPA8ELUXHmA= -github.com/muesli/cancelreader v0.2.2/go.mod h1:3XuTXfFS2VjM+HTLZY9Ak0l6eUKfijIfMUZ4EgX0QYo= +github.com/muesli/termenv v0.16.0 h1:S5AlUN9dENB57rsbnkPyfdGuWIlkmzJjbFf0Tf5FWUc= +github.com/muesli/termenv v0.16.0/go.mod h1:ZRfOIKPFDYQoDFF4Olj7/QJbW60Ol/kL1pU3VfY/Cnk= github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 h1:C3w9PqII01/Oq1c1nUAm88MOHcQC9l5mIlSMApZMrHA= github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822/go.mod h1:+n7T8mK8HuQTcFwEeznm/DIxMOiR9yIdICNftLE1DvQ= github.com/nakabonne/nestif v0.3.1 h1:wm28nZjhQY5HyYPx+weN3Q65k6ilSBxDb8v5S81B81U= @@ -531,18 +486,14 @@ github.com/nishanths/exhaustive v0.12.0 h1:vIY9sALmw6T/yxiASewa4TQcFsVYZQQRUQJhK github.com/nishanths/exhaustive v0.12.0/go.mod h1:mEZ95wPIZW+x8kC4TgC+9YCUgiST7ecevsVDTgc2obs= github.com/nishanths/predeclared v0.2.2 h1:V2EPdZPliZymNAn79T8RkNApBjMmVKh5XRpLm/w98Vk= github.com/nishanths/predeclared v0.2.2/go.mod h1:RROzoN6TnGQupbC+lqggsOlcgysk3LMK/HI84Mp280c= -github.com/nunnatsa/ginkgolinter v0.24.0 h1:Mp0EagluLFP98JatP6nqp/gGEoljNG97uf9AcxcBVy8= -github.com/nunnatsa/ginkgolinter v0.24.0/go.mod h1:2ZMRuzX6+3XXyY6UZOwb6n+MCocVGbkIsDBC4vuWz5c= -github.com/oapi-codegen/nullable v1.2.0 h1:VflFkDW980KhBPiFF7nWSyjg+r4Obqj8lXipV0UkP5w= -github.com/oapi-codegen/nullable v1.2.0/go.mod h1:KUZ3vUzkmEKY90ksAmit2+5juDIhIZhfDl+0PwOQlFY= -github.com/oapi-codegen/runtime v1.6.0 h1:7Xx+GlueD6nRuyKoCPzL434Jfi3BetbiJOrzCHp/VPU= -github.com/oapi-codegen/runtime v1.6.0/go.mod h1:GwV7hC2hviaMzj+ITfHVRESK5J2W/GefVwIND/bMGvU= -github.com/onsi/ginkgo/v2 v2.32.0 h1:Hw7s2pVrQo/8Yz5N77qdnpHaoc+c6cC9WIV1Jce+J6E= -github.com/onsi/ginkgo/v2 v2.32.0/go.mod h1:+aXOY+vzZ5mu2iI2HpTZUPmM//oQfsNFX6gU9kNcA44= -github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I= -github.com/onsi/gomega v1.42.1/go.mod h1:REff/hsDsodHoKlWsP2mAPhu1+5/6hVYNf9rIEBpeSg= -github.com/opencontainers/go-digest v1.0.0 h1:apOUWs51W5PlhuyGyz9FCeeBIOUDA/6nW8Oi/yOhh5U= -github.com/opencontainers/go-digest v1.0.0/go.mod h1:0JzlMkj0TRzQZfJkVvzbP0HBR3IKzErnv2BNG4W4MAM= +github.com/nunnatsa/ginkgolinter v0.23.0 h1:x3o4DGYOWbBMP/VdNQKgSj+25aJKx2Pe6lHr8gBcgf8= +github.com/nunnatsa/ginkgolinter v0.23.0/go.mod h1:9qN1+0akwXEccwV1CAcCDfcoBlWXHB+ML9884pL4SZ4= +github.com/oapi-codegen/runtime v1.2.0 h1:RvKc1CVS1QeKSNzO97FBQbSMZyQ8s6rZd+LpmzwHMP4= +github.com/oapi-codegen/runtime v1.2.0/go.mod h1:Y7ZhmmlE8ikZOmuHRRndiIm7nf3xcVv+YMweKgG1DT0= +github.com/onsi/ginkgo/v2 v2.28.1 h1:S4hj+HbZp40fNKuLUQOYLDgZLwNUVn19N3Atb98NCyI= +github.com/onsi/ginkgo/v2 v2.28.1/go.mod h1:CLtbVInNckU3/+gC8LzkGUb9oF+e8W8TdUsxPwvdOgE= +github.com/onsi/gomega v1.39.1 h1:1IJLAad4zjPn2PsnhH70V4DKRFlrCzGBNrNaru+Vf28= +github.com/onsi/gomega v1.39.1/go.mod h1:hL6yVALoTOxeWudERyfppUcZXjMwIMLnuSfruD2lcfg= github.com/otiai10/copy v1.2.0/go.mod h1:rrF5dJ5F0t/EWSYODDu4j9/vEeYHMkc8jt0zJChqQWw= github.com/otiai10/copy v1.14.0 h1:dCI/t1iTdYGtkvCuBG2BgR6KZa83PTclw4U5n2wAllU= github.com/otiai10/copy v1.14.0/go.mod h1:ECfuL02W+/FkTWZWgQqXPWZgW9oeKCSQ5qVfSc4qc4w= @@ -550,31 +501,26 @@ github.com/otiai10/curr v0.0.0-20150429015615-9b4961190c95/go.mod h1:9qAhocn7zKJ github.com/otiai10/curr v1.0.0/go.mod h1:LskTG5wDwr8Rs+nNQ+1LlxRjAtTZZjtJW4rMXl6j4vs= github.com/otiai10/mint v1.3.0/go.mod h1:F5AjcsTsWUqX+Na9fpHb52P8pcRX2CI6A3ctIT91xUo= github.com/otiai10/mint v1.3.1/go.mod h1:/yxELlJQ0ufhjUwhshSj+wFjZ78CnZ48/1wtmBH1OTc= -github.com/package-url/packageurl-go v0.1.7 h1:iFWg6tzAjLA6F/qX3M5nZaiMHJgc+p2zxVyr/fY+sZY= -github.com/package-url/packageurl-go v0.1.7/go.mod h1:nKAWB8E6uk1MHqiS/lQb9pYBGH2+mdJ2PJc2s50dQY0= -github.com/pandatix/go-cvss v0.6.4 h1:9w2RCO/Q4UTiJyEgpCHRiVc6CfrsFEnkoX+OtATqKio= -github.com/pandatix/go-cvss v0.6.4/go.mod h1:/ukvQnYlrKl3o/DVp7/GO2UZyZheuo/maOK0U1nBEhQ= +github.com/pandatix/go-cvss v0.6.2 h1:TFiHlzUkT67s6UkelHmK6s1INKVUG7nlKYiWWDTITGI= +github.com/pandatix/go-cvss v0.6.2/go.mod h1:jDXYlQBZrc8nvrMUVVvTG8PhmuShOnKrxP53nOFkt8Q= github.com/pelletier/go-toml v1.9.5 h1:4yBQzkHv+7BHq2PQUZF3Mx0IYxG7LsP222s7Agd3ve8= github.com/pelletier/go-toml v1.9.5/go.mod h1:u1nR/EPcESfeI/szUZKdtJ0xRNbUoANCkoOuaOx1Y+c= -github.com/pelletier/go-toml/v2 v2.4.3 h1:GTRvJQutkOSftxIFD5xw9aepkYNuPWmVJpffdDPYVpY= -github.com/pelletier/go-toml/v2 v2.4.3/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY= +github.com/pelletier/go-toml/v2 v2.2.4 h1:mye9XuhQ6gvn5h28+VilKrrPoQVanw5PMw/TB0t5Ec4= +github.com/pelletier/go-toml/v2 v2.2.4/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY= github.com/peterbourgon/g2s v0.0.0-20170223122336-d4e7ad98afea h1:sKwxy1H95npauwu8vtF95vG/syrL0p8fSZo/XlDg5gk= github.com/peterbourgon/g2s v0.0.0-20170223122336-d4e7ad98afea/go.mod h1:1VcHEd3ro4QMoHfiNl/j7Jkln9+KQuorp0PItHMJYNg= -github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c h1:+mdjkGKdHQG3305AYmdv1U2eRNDiU2ErMBj1gwrq8eQ= -github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c/go.mod h1:7rwL4CYBLnjLxUqIJNnCWiEdr3bn6IUYi15bNlnbCCU= github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 h1:GFCKgmp0tecUJ0sJuv4pzYCqS9+RGSn52M3FUwPs+uo= github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10/go.mod h1:t/avpk3KcrXxUnYOhZhMXJlSEyie6gQbtLq5NM3loB8= +github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM= github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= -github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRIccs7FGNTlIRMkT8wgtp5eCXdBlqhYGL6U= -github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= -github.com/prometheus/client_golang v1.24.1 h1:JnJkREXzWxUdCuPFpIWZiPispT9xVV59uiuyR2bPlnU= -github.com/prometheus/client_golang v1.24.1/go.mod h1:F+oSRECHg4sse5ucfYpYDeIv/hu68Zo0uoHKetWnzcE= -github.com/prometheus/client_model v0.6.3 h1:O0jaTVAYNxTHYInEPFJt5I3+sN8zqBtVMPTB1qyxiEo= -github.com/prometheus/client_model v0.6.3/go.mod h1:gpN5P9S7Rr6Yr92PiQ+Ixvhf6JZEkF1dnxsYL2aPBEM= -github.com/prometheus/common v0.70.1 h1:1HvjP4D5oL3t8RsPlwxA9onvvStjtIHYE5XuuwOi/PY= -github.com/prometheus/common v0.70.1/go.mod h1:VdFUQDMZK3VLkurFUVhia6uys/0suUp86TJz5qbJRhc= -github.com/prometheus/procfs v0.21.1 h1:GljZCt+zSTS+NZq88cyQ1LjZ+RCHp3uVuabBWA5+OJI= -github.com/prometheus/procfs v0.21.1/go.mod h1:aB55Cww9pdSJVHk0hUf0inxWyyjPogFIjmHKYgMKmtY= +github.com/prometheus/client_golang v1.23.2 h1:Je96obch5RDVy3FDMndoUsjAhG5Edi49h0RJWRi/o0o= +github.com/prometheus/client_golang v1.23.2/go.mod h1:Tb1a6LWHB3/SPIzCoaDXI4I8UHKeFTEQ1YCr+0Gyqmg= +github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk= +github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE= +github.com/prometheus/common v0.67.5 h1:pIgK94WWlQt1WLwAC5j2ynLaBRDiinoAb86HZHTUGI4= +github.com/prometheus/common v0.67.5/go.mod h1:SjE/0MzDEEAyrdr5Gqc6G+sXI67maCxzaT3A2+HqjUw= +github.com/prometheus/procfs v0.20.1 h1:XwbrGOIplXW/AU3YhIhLODXMJYyC1isLFfYCsTEycfc= +github.com/prometheus/procfs v0.20.1/go.mod h1:o9EMBZGRyvDrSPH1RqdxhojkuXstoe4UlK79eF5TGGo= github.com/quasilyte/go-ruleguard v0.4.5 h1:AGY0tiOT5hJX9BTdx/xBdoCubQUAE2grkqY2lSwvZcA= github.com/quasilyte/go-ruleguard v0.4.5/go.mod h1:Vl05zJ538vcEEwu16V/Hdu7IYZWyKSwIy4c88Ro1kRE= github.com/quasilyte/go-ruleguard/dsl v0.3.23 h1:lxjt5B6ZCiBeeNO8/oQsegE6fLeCzuMRoVWSkXC4uvY= @@ -585,14 +531,15 @@ github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727 h1:TCg2WBOl github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727/go.mod h1:rlzQ04UMyJXu/aOvhd8qT+hvDrFpiwqp8MRXDY9szc0= github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 h1:M8mH9eK4OUR4lu7Gd+PU1fV2/qnDNfzT635KRSObncs= github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567/go.mod h1:DWNGW8A4Y+GyBgPuaQJuWiy0XYftx4Xm/y5Jqk9I6VQ= -github.com/raeperd/recvcheck v0.3.0 h1:PM+XYvyxIj3bo+kobJfFTdTuU3Lmfu96mKDbyHDbRt8= -github.com/raeperd/recvcheck v0.3.0/go.mod h1:PZNwG+HztFYMH2ZPq0Hu3QgkV2yiA6VrtNz9c1fXWJo= +github.com/raeperd/recvcheck v0.2.0 h1:GnU+NsbiCqdC2XX5+vMZzP+jAJC5fht7rcVTAhX74UI= +github.com/raeperd/recvcheck v0.2.0/go.mod h1:n04eYkwIR0JbgD73wT8wL4JjPC3wm0nFtzBnWNocnYU= github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94icq4NjY3clb7Lk8O1qJ8BdBEF8z0ibU0rE= github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo= +github.com/rivo/uniseg v0.2.0/go.mod h1:J6wj4VEh+S6ZtnVlnTBMWIodfgj8LQOQFoIToxlJtxc= github.com/rivo/uniseg v0.4.7 h1:WUdvkW8uEhrYfLC4ZzdpI2ztxP1I582+49Oc5Mq64VQ= github.com/rivo/uniseg v0.4.7/go.mod h1:FN3SvrM+Zdj16jyLfmOkMNblXMcoc8DfTHruCPUcx88= -github.com/rogpeppe/go-internal v1.16.0 h1:O9DK+vNMDVGLr2BeZqmpLeMjiMNkuXfcqntWbZV6S5g= -github.com/rogpeppe/go-internal v1.16.0/go.mod h1:DrUVZyrJU+txYW5/1kwtXQSMFio52ZOxX7yM1VHvnxs= +github.com/rogpeppe/go-internal v1.14.1 h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ= +github.com/rogpeppe/go-internal v1.14.1/go.mod h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc= github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 h1:18kd+8ZUlt/ARXhljq+14TwAoKa61q6dX8jtwOf6DH8= github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529/go.mod h1:qe5TWALJ8/a1Lqznoc5BDHpYX/8HU60Hm2AwRmqzxqA= github.com/rubyist/circuitbreaker v2.2.1+incompatible h1:KUKd/pV8Geg77+8LNDwdow6rVCAYOp8+kHUyFvL6Mhk= @@ -602,31 +549,31 @@ github.com/russross/blackfriday/v2 v2.1.0 h1:JIOH55/0cWyOuilr9/qlrm0BSXldqnqwMsf github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM= github.com/ryancurrah/gomodguard v1.4.1 h1:eWC8eUMNZ/wM/PWuZBv7JxxqT5fiIKSIyTvjb7Elr+g= github.com/ryancurrah/gomodguard v1.4.1/go.mod h1:qnMJwV1hX9m+YJseXEBhd2s90+1Xn6x9dLz11ualI1I= -github.com/ryancurrah/gomodguard/v2 v2.1.3 h1:E7sz3PJwE9Ba1reVxSpF6XLCPJZ74Kfw/LabTNM4GIA= -github.com/ryancurrah/gomodguard/v2 v2.1.3/go.mod h1:CQicdLGatWMxLX53JzoBjYlsNZhHbmLv2AVa0s2aivU= -github.com/ryanrolds/sqlclosecheck v0.6.0 h1:pEyL9okISdg1F1SEpJNlrEotkTGerv5BMk7U4AG0eVg= -github.com/ryanrolds/sqlclosecheck v0.6.0/go.mod h1:xyX16hsDaCMXHrMJ3JMzGf5OpDfHTOTTQrT7HOFUmeU= +github.com/ryanrolds/sqlclosecheck v0.5.1 h1:dibWW826u0P8jNLsLN+En7+RqWWTYrjCB9fJfSfdyCU= +github.com/ryanrolds/sqlclosecheck v0.5.1/go.mod h1:2g3dUjoS6AL4huFdv6wn55WpLIDjY7ZgUR4J8HOO/XQ= github.com/sanposhiho/wastedassign/v2 v2.1.0 h1:crurBF7fJKIORrV85u9UUpePDYGWnwvv3+A96WvwXT0= github.com/sanposhiho/wastedassign/v2 v2.1.0/go.mod h1:+oSmSC+9bQ+VUAxA66nBb0Z7N8CK7mscKTDYC6aIek4= -github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 h1:1EYB5IzjZawrrnELUi78f9fPu57HuXjmddZPjrls/28= -github.com/santhosh-tekuri/jsonschema/v6 v6.0.3/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU= +github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 h1:KRzFb2m7YtdldCEkzs6KqmJw4nqEVZGK7IN2kJkjTuQ= +github.com/santhosh-tekuri/jsonschema/v6 v6.0.2/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU= github.com/sashamelentyev/interfacebloat v1.1.0 h1:xdRdJp0irL086OyW1H/RTZTr1h/tMEOsumirXcOJqAw= github.com/sashamelentyev/interfacebloat v1.1.0/go.mod h1:+Y9yU5YdTkrNvoX0xHc84dxiN1iBi9+G8zZIhPVoNjQ= github.com/sashamelentyev/usestdlibvars v1.29.0 h1:8J0MoRrw4/NAXtjQqTHrbW9NN+3iMf7Knkq057v4XOQ= github.com/sashamelentyev/usestdlibvars v1.29.0/go.mod h1:8PpnjHMk5VdeWlVb4wCdrB8PNbLqZ3wBZTZWkrpZZL8= -github.com/securego/gosec/v2 v2.28.0 h1:ZsSdiDb0AtTpLFVol5z91gbMei9ZiLEPG/pZjZujp7c= -github.com/securego/gosec/v2 v2.28.0/go.mod h1:lb4/9AHe+lJy/kjWmWRWWsEipvbwGKuxf+tY1Pmjdnk= +github.com/securego/gosec/v2 v2.23.0 h1:h4TtF64qFzvnkqvsHC/knT7YC5fqyOCItlVR8+ptEBo= +github.com/securego/gosec/v2 v2.23.0/go.mod h1:qRHEgXLFuYUDkI2T7W7NJAmOkxVhkR0x9xyHOIcMNZ0= github.com/sergi/go-diff v1.2.0 h1:XU+rvMAioB0UC3q1MFrIQy4Vo5/4VsRDQQXHsEya6xQ= github.com/sergi/go-diff v1.2.0/go.mod h1:STckp+ISIX8hZLjrqAeVduY0gWCT9IjLuqbuNXdaHfM= +github.com/shurcooL/go v0.0.0-20180423040247-9e1955d9fb6e/go.mod h1:TDJrrUr11Vxrven61rcy3hJMUqaf/CLWYhHNPmT14Lk= +github.com/shurcooL/go-goon v0.0.0-20170922171312-37c2f522c041/go.mod h1:N5mDOmsrJOB+vfqUK+7DmDyjhSLIIBnXo9lvZJj3MWQ= github.com/shurcooL/sanitized_anchor_name v1.0.0/go.mod h1:1NzhyTcUVG4SuEtjjoZeVRXNmyL/1OwPU0+IJeTBvfc= -github.com/sirupsen/logrus v1.10.1 h1:xi4336Zh11WpU14fXR6I67V3yaTPQYwRx2WEtHbRg4Q= -github.com/sirupsen/logrus v1.10.1/go.mod h1:vsQHnG7xzNsxk3NrwboUiWPnIC3dmbjcGPykD7+tiHk= +github.com/sirupsen/logrus v1.9.4 h1:TsZE7l11zFCLZnZ+teH4Umoq5BhEIfIzfRDZ1Uzql2w= +github.com/sirupsen/logrus v1.9.4/go.mod h1:ftWc9WdOfJ0a92nsE2jF5u5ZwH8Bv2zdeOC42RjbV2g= github.com/sivchari/containedctx v1.0.3 h1:x+etemjbsh2fB5ewm5FeLNi5bUjK0V8n0RB+Wwfd0XE= github.com/sivchari/containedctx v1.0.3/go.mod h1:c1RDvCbnJLtH4lLcYD/GqwiBSSf4F5Qk0xld2rBqzJ4= -github.com/sonatard/noctx v0.5.1 h1:wklWg9c9ZYugOAk7qG4yP4PBrlQsmSLPTvW1K4PRQMs= -github.com/sonatard/noctx v0.5.1/go.mod h1:64XdbzFb18XL4LporKXp8poqZtPKbCrqQ402CV+kJas= -github.com/sourcegraph/go-diff v0.8.0 h1:ipIyu4cTsLbIrln4l0qtHA3r0a7gyK4ntKjtQytHhvY= -github.com/sourcegraph/go-diff v0.8.0/go.mod h1:hWlcO7Al+UZStZAP8rBumHpCK5ZHQ5BXsMls8p4+F5E= +github.com/sonatard/noctx v0.4.0 h1:7MC/5Gg4SQ4lhLYR6mvOP6mQVSxCrdyiExo7atBs27o= +github.com/sonatard/noctx v0.4.0/go.mod h1:64XdbzFb18XL4LporKXp8poqZtPKbCrqQ402CV+kJas= +github.com/sourcegraph/go-diff v0.7.0 h1:9uLlrd5T46OXs5qpp8L/MTltk0zikUGi0sNNyCpA8G0= +github.com/sourcegraph/go-diff v0.7.0/go.mod h1:iBszgVvyxdc8SFZ7gm69go2KDdt3ag071iBaWPF6cjs= github.com/spdx/tools-golang v0.5.7 h1:+sWcKGnhwp3vLdMqPcLdA6QK679vd86cK9hQWH3AwCg= github.com/spdx/tools-golang v0.5.7/go.mod h1:jg7w0LOpoNAw6OxKEzCoqPC2GCTj45LyTlVmXubDsYw= github.com/spf13/afero v1.15.0 h1:b/YBCLWAJdFWJTN9cLhiXXcD7mzKn9Dm86dNnfyQw1I= @@ -643,22 +590,22 @@ github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk= github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg= github.com/spf13/viper v1.12.0 h1:CZ7eSOd3kZoaYDLbXnmzgQI5RlciuXBMA+18HwHRfZQ= github.com/spf13/viper v1.12.0/go.mod h1:b6COn30jlNxbm/V2IqWiNWkJ+vZNiMNksliPCiuKtSI= -github.com/spiffe/go-spiffe/v2 v2.7.0 h1:uXe1MflJoHw58wAUvxVlcM7WpKtijWG7I1UidcGh6g4= -github.com/spiffe/go-spiffe/v2 v2.7.0/go.mod h1:47Q0Q9/AqGha8QLHp+kxpH4Wca7X7EnOtlIJy3mxZ3U= +github.com/spiffe/go-spiffe/v2 v2.6.0 h1:l+DolpxNWYgruGQVV0xsfeya3CsC7m8iBzDnMpsbLuo= +github.com/spiffe/go-spiffe/v2 v2.6.0/go.mod h1:gm2SeUoMZEtpnzPNs2Csc0D/gX33k1xIx7lEzqblHEs= github.com/spkg/bom v0.0.0-20160624110644-59b7046e48ad/go.mod h1:qLr4V1qq6nMqFKkMo8ZTx3f+BZEkzsRUY10Xsm2mwU0= github.com/ssgreg/nlreturn/v2 v2.2.1 h1:X4XDI7jstt3ySqGU86YGAURbxw3oTDPK9sPEi6YEwQ0= github.com/ssgreg/nlreturn/v2 v2.2.1/go.mod h1:E/iiPB78hV7Szg2YfRgyIrk1AD6JVMTRkkxBiELzh2I= github.com/stbenjam/no-sprintf-host-port v0.3.1 h1:AyX7+dxI4IdLBPtDbsGAyqiTSLpCP9hWRrXQDU4Cm/g= github.com/stbenjam/no-sprintf-host-port v0.3.1/go.mod h1:ODbZesTCHMVKthBHskvUUexdcNHAQRXk9NpSsL8p/HQ= github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= -github.com/stretchr/objx v0.5.3 h1:jmXUvGomnU1o3W/V5h2VEradbpJDwGrzugQQvL0POH4= -github.com/stretchr/objx v0.5.3/go.mod h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+QYS+U0= +github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY= +github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA= github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs= github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI= github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4= github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= -github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE= -github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg= +github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U= +github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U= github.com/subosito/gotenv v1.4.1 h1:jyEFiXpy21Wm81FBN71l9VoMMV8H8jG+qIK3GCpY6Qs= github.com/subosito/gotenv v1.4.1/go.mod h1:ayKnFf/c6rvx/2iiLrJUk1e6plDbT3edrFNGqEflhK0= github.com/swaggo/swag v1.16.6 h1:qBNcx53ZaX+M5dxVyTrgQ0PJ/ACK+NzhwcbieTt+9yI= @@ -667,30 +614,30 @@ github.com/tenntenn/modver v1.0.1 h1:2klLppGhDgzJrScMpkj9Ujy3rXPUspSjAcev9tSEBgA github.com/tenntenn/modver v1.0.1/go.mod h1:bePIyQPb7UeioSRkw3Q0XeMhYZSMx9B8ePqg6SAMGH0= github.com/tenntenn/text/transform v0.0.0-20200319021203-7eef512accb3 h1:f+jULpRQGxTSkNYKJ51yaw6ChIqO+Je8UqsTKN/cDag= github.com/tenntenn/text/transform v0.0.0-20200319021203-7eef512accb3/go.mod h1:ON8b8w4BN/kE1EOhwT0o+d62W65a6aPw1nouo9LMgyY= -github.com/terminalstatic/go-xsd-validate v0.1.8 h1:UVrTCy1j3DhwaYTTUF+QYO/Nan13S0tf+Jwi+p45Bf0= -github.com/terminalstatic/go-xsd-validate v0.1.8/go.mod h1:1kb47fi2c6onlf+B7UrrQ9VYraOhcYwFm3iG+J6F4Zo= -github.com/tetafro/godot v1.5.6 h1:IEkrFCwXaYHlOn4mGzGS3F3dkP6m9t0jpwqBFPIkKiA= -github.com/tetafro/godot v1.5.6/go.mod h1:eOkMrVQurDui411nBY2FA05EYH01r14LuWY/NrVDVcU= -github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4 h1:SiHe5XLTn9sFWJ5pBwJ5FN/4j34q9ZlOAD//kMoMYp0= -github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4/go.mod h1:sDHLK7rb/59v/ZxZ7KtymgcoxuUMxjXq8gtu9VMOK8M= +github.com/terminalstatic/go-xsd-validate v0.1.6 h1:TenYeQ3eY631qNi1/cTmLH/s2slHPRKTTHT+XSHkepo= +github.com/terminalstatic/go-xsd-validate v0.1.6/go.mod h1:18lsvYFofBflqCrvo1umpABZ99+GneNTw2kEEc8UPJw= +github.com/tetafro/godot v1.5.4 h1:u1ww+gqpRLiIA16yF2PV1CV1n/X3zhyezbNXC3E14Sg= +github.com/tetafro/godot v1.5.4/go.mod h1:eOkMrVQurDui411nBY2FA05EYH01r14LuWY/NrVDVcU= +github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67 h1:9LPGD+jzxMlnk5r6+hJnar67cgpDIz/iyD+rfl5r2Vk= +github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67/go.mod h1:mkjARE7Yr8qU23YcGMSALbIxTQ9r9QBVahQOBRfU460= github.com/timonwong/loggercheck v0.11.0 h1:jdaMpYBl+Uq9mWPXv1r8jc5fC3gyXx4/WGwTnnNKn4M= github.com/timonwong/loggercheck v0.11.0/go.mod h1:HEAWU8djynujaAVX7QI65Myb8qgfcZ1uKbdpg3ZzKl8= github.com/tomarrell/wrapcheck/v2 v2.12.0 h1:H/qQ1aNWz/eeIhxKAFvkfIA+N7YDvq6TWVFL27Of9is= github.com/tomarrell/wrapcheck/v2 v2.12.0/go.mod h1:AQhQuZd0p7b6rfW+vUwHm5OMCGgp63moQ9Qr/0BpIWo= github.com/tommy-muehle/go-mnd/v2 v2.5.1 h1:NowYhSdyE/1zwK9QCLeRb6USWdoif80Ie+v+yU8u1Zw= github.com/tommy-muehle/go-mnd/v2 v2.5.1/go.mod h1:WsUAkMJMYww6l/ufffCD3m+P7LEvr8TnZn9lwVDlgzw= -github.com/ulikunitz/xz v0.5.16 h1:ld6NyySjx5lowVKwJvMRLnW5nxKX/xnpSiFYZ/Lxur0= -github.com/ulikunitz/xz v0.5.16/go.mod h1:H9Rt/W6/Qj27PGauhQc6nfCDy7vHpzsOThBSaYDoEhw= +github.com/ulikunitz/xz v0.5.15 h1:9DNdB5s+SgV3bQ2ApL10xRc35ck0DuIX/isZvIk+ubY= +github.com/ulikunitz/xz v0.5.15/go.mod h1:nbz6k7qbPmH4IRqmfOplQw/tblSgqTqBwxkY0oWt/14= github.com/ultraware/funlen v0.2.0 h1:gCHmCn+d2/1SemTdYMiKLAHFYxTYz7z9VIDRaTGyLkI= github.com/ultraware/funlen v0.2.0/go.mod h1:ZE0q4TsJ8T1SQcjmkhN/w+MceuatI6pBFSxxyteHIJA= github.com/ultraware/whitespace v0.2.0 h1:TYowo2m9Nfj1baEQBjuHzvMRbp19i+RCcRYrSWoFa+g= github.com/ultraware/whitespace v0.2.0/go.mod h1:XcP1RLD81eV4BW8UhQlpaR+SDc2givTvyI8a586WjW8= github.com/urfave/cli/v2 v2.3.0 h1:qph92Y649prgesehzOrQjdWyxFOp/QVM+6imKHad91M= github.com/urfave/cli/v2 v2.3.0/go.mod h1:LJmUH05zAU44vOAcrfzZQKsZbVcdbOG8rtL3/XcUArI= -github.com/uudashr/gocognit v1.2.1 h1:CSJynt5txTnORn/DkhiB4mZjwPuifyASC8/6Q0I/QS4= -github.com/uudashr/gocognit v1.2.1/go.mod h1:acaubQc6xYlXFEMb9nWX2dYBzJ/bIjEkc1zzvyIZg5Q= -github.com/uudashr/iface v1.5.0 h1:PgdMt4uAettGG8K/Kbamc4B9FABgUgnS3TLbl6fnjEk= -github.com/uudashr/iface v1.5.0/go.mod h1:pbeBPlbuU2qkNDn0mmfrxP2X+wjPMIQAy+r1MBXSXtg= +github.com/uudashr/gocognit v1.2.0 h1:3BU9aMr1xbhPlvJLSydKwdLN3tEUUrzPSSM8S4hDYRA= +github.com/uudashr/gocognit v1.2.0/go.mod h1:k/DdKPI6XBZO1q7HgoV2juESI2/Ofj9AcHPZhBBdrTU= +github.com/uudashr/iface v1.4.1 h1:J16Xl1wyNX9ofhpHmQ9h9gk5rnv2A6lX/2+APLTo0zU= +github.com/uudashr/iface v1.4.1/go.mod h1:pbeBPlbuU2qkNDn0mmfrxP2X+wjPMIQAy+r1MBXSXtg= github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f h1:J9EGpcZtP0E/raorCMxlFGSTBrsSlaDGf3jU/qvAE2c= github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f/go.mod h1:N2zxlSyiKSe5eX1tZViRH5QA0qijqEDrYZiPEAiq3wU= github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 h1:EzJWgHovont7NscjpAxXsDA8S8BMYve8Y5+7cuRE7R0= @@ -710,6 +657,7 @@ github.com/ykadowak/zerologlint v0.1.5/go.mod h1:KaUskqF3e/v59oPmdq1U1DnKcuHokl2 github.com/yuin/goldmark v1.1.25/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= github.com/yuin/goldmark v1.1.32/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= +github.com/yuin/goldmark v1.3.5/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k= github.com/yuin/goldmark v1.4.1/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k= github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY= gitlab.com/bosi/decorder v0.4.2 h1:qbQaV3zgwnBZ4zPMhGLW4KZe7A7NwxEhJx39R3shffo= @@ -718,79 +666,85 @@ go-simpler.org/assert v0.9.0 h1:PfpmcSvL7yAnWyChSjOz6Sp6m9j5lyK8Ok9pEL31YkQ= go-simpler.org/assert v0.9.0/go.mod h1:74Eqh5eI6vCK6Y5l3PI8ZYFXG4Sa+tkr70OIPJAUr28= go-simpler.org/musttag v0.14.0 h1:XGySZATqQYSEV3/YTy+iX+aofbZZllJaqwFWs+RTtSo= go-simpler.org/musttag v0.14.0/go.mod h1:uP8EymctQjJ4Z1kUnjX0u2l60WfUdQxCwSNKzE1JEOE= -go-simpler.org/sloglint v0.12.0 h1:UzWDlLWNE5FLqsvyq3tWYHuQMbqrervOhT8qPl4Mmw4= -go-simpler.org/sloglint v0.12.0/go.mod h1:jBjjC2bm8rYrs88oTRlFX497kWjJsyZWYoNaXkGRI6I= +go-simpler.org/sloglint v0.11.1 h1:xRbPepLT/MHPTCA6TS/wNfZrDzkGvCCqUv4Bdwc3H7s= +go-simpler.org/sloglint v0.11.1/go.mod h1:2PowwiCOK8mjiF+0KGifVOT8ZsCNiFzvfyJeJOIt8MQ= go.augendre.info/arangolint v0.4.0 h1:xSCZjRoS93nXazBSg5d0OGCi9APPLNMmmLrC995tR50= go.augendre.info/arangolint v0.4.0/go.mod h1:l+f/b4plABuFISuKnTGD4RioXiCCgghv2xqst/xOvAA= -go.augendre.info/fatcontext v0.10.0 h1:HhFopmivh8U1+AU7f0kuwUeg2eiIns7YsGQOMHwSJ90= -go.augendre.info/fatcontext v0.10.0/go.mod h1:pqpGvA9GlrXy+aXkp8L2dKz12Zp4g2FhzcAtwToU+2w= +go.augendre.info/fatcontext v0.9.0 h1:Gt5jGD4Zcj8CDMVzjOJITlSb9cEch54hjRRlN3qDojE= +go.augendre.info/fatcontext v0.9.0/go.mod h1:L94brOAT1OOUNue6ph/2HnwxoNlds9aXDF2FcUntbNw= go.opentelemetry.io/auto/sdk v1.2.1 h1:jXsnJ4Lmnqd11kwkBV2LgLoFMZKizbCi5fNZ/ipaZ64= go.opentelemetry.io/auto/sdk v1.2.1/go.mod h1:KRTj+aOaElaLi+wW1kO/DZRXwkF4C5xPbEe3ZiIhN7Y= -go.opentelemetry.io/contrib/detectors/gcp v1.44.0 h1:NmLfL734pJhM0JKaYd2Y28+nY9dPRWYAAbxhRCrKXPw= -go.opentelemetry.io/contrib/detectors/gcp v1.44.0/go.mod h1:tNAsgd8avTGke1+MndXlU5Cru4PQ9Ai/cCNWQv/ZJ/s= -go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0 h1:yI1/OhfEPy7J9eoa6Sj051C7n5dvpj0QX8g4sRchg04= -go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0/go.mod h1:NoUCKYWK+3ecatC4HjkRktREheMeEtrXoQxrqYFeHSc= -go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0 h1:8tvICD4vSTOOsNrsI4Ljf6C+6UKvpTEH5XY3JMoyPoo= -go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0/go.mod h1:z9+yiacE0IHRqM4qFfkbt/JYlmYXgss8GY/jXoNuPJI= -go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU= -go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc= -go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc= -go.opentelemetry.io/otel/metric v1.44.0/go.mod h1:8O7hanEPBNgEMmybD3s2VBKcgWOCsA6tzHBPODAiquo= -go.opentelemetry.io/otel/metric/x v0.66.0 h1:YkCrx1zLOChi9ZcZ6euupOcsgzbVlec7D/xoEU1+cTA= -go.opentelemetry.io/otel/metric/x v0.66.0/go.mod h1:d1+BDj9t96do0/1LoU1ayfCv79ZgNE41qbhBvnMOBZk= -go.opentelemetry.io/otel/sdk v1.44.0 h1:nHYwb9lK+fJPU/dnT6s7W7Z8itMWyqrnVfbheVYrZ58= -go.opentelemetry.io/otel/sdk v1.44.0/go.mod h1:Osuydd3Se74nqjAKxid74N5eC+jfEqfTegHRnq58oK0= -go.opentelemetry.io/otel/sdk/metric v1.44.0 h1:3LlKgI+VjbVsjNRFZJZAJ30WjXC5VkNRks6si09iEfI= -go.opentelemetry.io/otel/sdk/metric v1.44.0/go.mod h1:5B5pMARnXxKhltooO4xUuCBorl65a4EpnTalObqOigA= -go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk= -go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE= +go.opentelemetry.io/contrib/detectors/gcp v1.39.0 h1:kWRNZMsfBHZ+uHjiH4y7Etn2FK26LAGkNFw7RHv1DhE= +go.opentelemetry.io/contrib/detectors/gcp v1.39.0/go.mod h1:t/OGqzHBa5v6RHZwrDBJ2OirWc+4q/w2fTbLZwAKjTk= +go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 h1:YH4g8lQroajqUwWbq/tr2QX1JFmEXaDLgG+ew9bLMWo= +go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0/go.mod h1:fvPi2qXDqFs8M4B4fmJhE92TyQs9Ydjlg3RvfUp+NbQ= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 h1:RbKq8BG0FI8OiXhBfcRtqqHcZcka+gU3cskNuf05R18= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0/go.mod h1:h06DGIukJOevXaj/xrNjhi/2098RZzcLTbc0jDAUbsg= +go.opentelemetry.io/otel v1.41.0 h1:YlEwVsGAlCvczDILpUXpIpPSL/VPugt7zHThEMLce1c= +go.opentelemetry.io/otel v1.41.0/go.mod h1:Yt4UwgEKeT05QbLwbyHXEwhnjxNO6D8L5PQP51/46dE= +go.opentelemetry.io/otel/metric v1.41.0 h1:rFnDcs4gRzBcsO9tS8LCpgR0dxg4aaxWlJxCno7JlTQ= +go.opentelemetry.io/otel/metric v1.41.0/go.mod h1:xPvCwd9pU0VN8tPZYzDZV/BMj9CM9vs00GuBjeKhJps= +go.opentelemetry.io/otel/sdk v1.41.0 h1:YPIEXKmiAwkGl3Gu1huk1aYWwtpRLeskpV+wPisxBp8= +go.opentelemetry.io/otel/sdk v1.41.0/go.mod h1:ahFdU0G5y8IxglBf0QBJXgSe7agzjE4GiTJ6HT9ud90= +go.opentelemetry.io/otel/sdk/metric v1.41.0 h1:siZQIYBAUd1rlIWQT2uCxWJxcCO7q3TriaMlf08rXw8= +go.opentelemetry.io/otel/sdk/metric v1.41.0/go.mod h1:HNBuSvT7ROaGtGI50ArdRLUnvRTRGniSUZbxiWxSO8Y= +go.opentelemetry.io/otel/trace v1.41.0 h1:Vbk2co6bhj8L59ZJ6/xFTskY+tGAbOnCtQGVVa9TIN0= +go.opentelemetry.io/otel/trace v1.41.0/go.mod h1:U1NU4ULCoxeDKc09yCWdWe+3QoyweJcISEVa1RBzOis= go.uber.org/goleak v1.3.0 h1:2K3zAYmnTNqV73imy9J1T3WC+gmCePx2hEGkimedGto= go.uber.org/goleak v1.3.0/go.mod h1:CoHD4mav9JJNrW/WLlf7HGZPjdw8EucARQHekz1X6bE= go.uber.org/multierr v1.11.0 h1:blXXJkSxSSfBVBlC76pxqeO+LN3aDfLQo+309xJstO0= go.uber.org/multierr v1.11.0/go.mod h1:20+QtiLqy0Nd6FdQB9TLXag12DsQkrbs3htMFfDN80Y= go.uber.org/zap v1.27.1 h1:08RqriUEv8+ArZRYSTXy1LeBScaMpVSTBhCeaZYfMYc= go.uber.org/zap v1.27.1/go.mod h1:GB2qFLM7cTU87MWRP2mPIjqfIDnGu+VIO4V/SdhGo2E= -go.yaml.in/yaml/v2 v2.4.4 h1:tuyd0P+2Ont/d6e2rl3be67goVK4R6deVxCUX5vyPaQ= -go.yaml.in/yaml/v2 v2.4.4/go.mod h1:gMZqIpDtDqOfM0uNfy0SkpRhvUryYH0Z6wdMYcacYXQ= +go.yaml.in/yaml/v2 v2.4.3 h1:6gvOSjQoTB3vt1l+CU+tSyi/HOjfOjRLJ4YwYZGwRO0= +go.yaml.in/yaml/v2 v2.4.3/go.mod h1:zSxWcmIDjOzPXpjlTTbAsKokqkDNAVtZO0WOMiT90s8= +go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc= go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg= -go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw= -go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg= -gocloud.dev v0.46.0 h1:niIuZwSjMtBx8K+ITB2s5kZullB13PGOS2ZoQPZxQ4Q= -gocloud.dev v0.46.0/go.mod h1:ACQe+2qO+hEO+pdcvvsM+RB63r8TyGD1W3ESCLFyzvM= +gocloud.dev v0.45.0 h1:WknIK8IbRdmynDvara3Q7G6wQhmEiOGwpgJufbM39sY= +gocloud.dev v0.45.0/go.mod h1:0kXKmkCLG6d31N7NyLZWzt7jDSQura9zD/mWgiB6THI= golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto= golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= -golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= -golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= +golang.org/x/crypto v0.13.0/go.mod h1:y6Z2r+Rw4iayiXXAIxJIDAJ1zMW4yaTpebo8fPOliYc= +golang.org/x/crypto v0.14.0/go.mod h1:MVFd36DqK4CsrnJYDkBA3VC4m2GkXAM0PvzMCn4JQf4= +golang.org/x/crypto v0.48.0 h1:/VRzVqiRSggnhY7gNRxPauEQ5Drw9haKdM0jqfcCFts= +golang.org/x/crypto v0.48.0/go.mod h1:r0kV5h3qnFPlQnBSrULhlsRfryS2pmewsg+XfMgkVos= golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa h1:Zt3DZoOFFYkKhDT3v7Lm9FDMEV06GpzjG2jrqW+QTE0= golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa/go.mod h1:K79w1Vqn7PoiZn+TkNpx3BUWUQksGO3JcVX6qIjytmA= golang.org/x/exp/typeparams v0.0.0-20220428152302-39d4317da171/go.mod h1:AbB0pIl9nAr9wVwH+Z2ZpaocVmF5I4GyWCDIsVjR0bk= golang.org/x/exp/typeparams v0.0.0-20230203172020-98cc5a0785f9/go.mod h1:AbB0pIl9nAr9wVwH+Z2ZpaocVmF5I4GyWCDIsVjR0bk= -golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f h1:+lI8cDJ4uceLipg2f1ODay7fEuLkk0BIHXd6PB8icxo= -golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f/go.mod h1:PqrXSW65cXDZH0k4IeUbhmg/bcAZDbzNz3byBpKCsXo= +golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358 h1:qWFG1Dj7TBjOjOvhEOkmyGPVoquqUKnIU0lEVLp8xyk= +golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358/go.mod h1:4Mzdyp/6jzw9auFDJ3OMF5qksa7UvPnzKqTVGcb04ms= golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/mod v0.4.1/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= +golang.org/x/mod v0.4.2/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3/go.mod h1:3p9vT2HGsQu2K1YbXdKPJLVgG5VJdoTa1poYQBtP1AY= golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4= golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= -golang.org/x/mod v0.40.0 h1:hUv+3cXcdRHz08UmSiOob7sadHig73uo5bkXxQ/tvUs= -golang.org/x/mod v0.40.0/go.mod h1:0/weTWkPWGBikyTWAX3dkjVztMmBA5hM0DH6BElSupE= +golang.org/x/mod v0.12.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= +golang.org/x/mod v0.13.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c= +golang.org/x/mod v0.33.0 h1:tHFzIWbBifEmbwtGz65eaWyGiGZatSrT9prnU8DbVL8= +golang.org/x/mod v0.33.0/go.mod h1:swjeQEj+6r7fODbD2cqrnje9PnziFuw4bmLbBZFrQ5w= golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= golang.org/x/net v0.0.0-20200625001655-4c5254603344/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA= golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU= golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg= +golang.org/x/net v0.0.0-20210405180319-a5a99cb37ef4/go.mod h1:p54w0d4576C0XHj96bSt6lcn1PtDYWL6XObtHCRCNQM= golang.org/x/net v0.0.0-20210421230115-4e50805a0758/go.mod h1:72T/g9IO56b78aLF+1Kcs5dz7/ng1VjMUvfKvpfy+jM= golang.org/x/net v0.0.0-20211015210444-4f30a5c0130f/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y= golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c= golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs= -golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To= -golang.org/x/net v0.58.0/go.mod h1:YwCddHnFlT7eLQqVprV19OnhLGtc5xOKgE0RyqgfWAU= -golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs= -golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q= +golang.org/x/net v0.10.0/go.mod h1:0qNGK6F8kojg2nk9dLZ2mShWaEBan6FAoqfSigmmuDg= +golang.org/x/net v0.15.0/go.mod h1:idbUs1IY1+zTqbi8yxTbhexhEEk5ur9LInksu6HrEpk= +golang.org/x/net v0.16.0/go.mod h1:NxSsAGuq816PNPmqtQdLE42eU2Fs7NoRIZrHJAlaCOE= +golang.org/x/net v0.51.0 h1:94R/GTO7mt3/4wIKpcR5gkGmRLOuE/2hNGeWq/GBIFo= +golang.org/x/net v0.51.0/go.mod h1:aamm+2QF5ogm02fjy5Bb7CQ0WMt1/WVM7FtyaTLlA9Y= +golang.org/x/oauth2 v0.35.0 h1:Mv2mzuHuZuY2+bkyWXIHMfhNdJAdwW3FuWeCPYN5GVQ= +golang.org/x/oauth2 v0.35.0/go.mod h1:lzm5WQJQwKZ3nwavOZ3IS5Aulzxi68dUSgRHujetwEA= golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.0.0-20190911185100-cd5d95a43a6e/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.0.0-20200625203802-6e8e738ad208/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= @@ -798,49 +752,64 @@ golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJ golang.org/x/sync v0.0.0-20210220032951-036812b2e83c/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.1.0/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= -golang.org/x/sync v0.23.0 h1:KameEIfc1IkluZyXWLn39Wd4tURc6GbCiISGiZm2bQk= -golang.org/x/sync v0.23.0/go.mod h1:sUUOizhqBxiL6pEWpqNLUiaJn1ShEbZ6BBqskPbjZm0= +golang.org/x/sync v0.3.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y= +golang.org/x/sync v0.4.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y= +golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4= +golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0= golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20200323222414-85ca7c5b95cd/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20210124154548-22da62e12c0c/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20210330210617-4fbd30eecc44/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20210420072515-93ed5bcd2bfe/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20210423082822-04245dca01da/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20210510120138-977fb7262007/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20211019181941-9d821ace8654/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20211105183446-c75c47738b0c/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.1.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs= -golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= +golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.8.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.12.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.13.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.42.0 h1:omrd2nAlyT5ESRdCLYdm3+fMfNFE/+Rf4bDIQImRJeo= +golang.org/x/sys v0.42.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8= golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k= +golang.org/x/term v0.8.0/go.mod h1:xPskH00ivmX89bAKVGSKKtLOWNx2+17Eiy94tnKShWo= +golang.org/x/term v0.12.0/go.mod h1:owVbMEjm3cBLCHdkQu9b1opXd4ETQWc3BhuQGKgXgvU= +golang.org/x/term v0.13.0/go.mod h1:LTmsnFJwVN6bCy1rVCoS+qHT1HhALEFxKncY3WNNh4U= golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk= golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ= golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= -golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8= -golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M= -golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U= -golang.org/x/time v0.15.0/go.mod h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno= +golang.org/x/text v0.9.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8= +golang.org/x/text v0.13.0/go.mod h1:TvPlkZtksWOMsz7fbANvkp4WM8x/WCo/om8BMLbz+aE= +golang.org/x/text v0.34.0 h1:oL/Qq0Kdaqxa1KbNeMKwQq0reLCCaFtqu2eNuSeNHbk= +golang.org/x/text v0.34.0/go.mod h1:homfLqTYRFyVYemLBFl5GgL/DWEiH5wcsQ5gSh1yziA= +golang.org/x/time v0.14.0 h1:MRx4UaLrDotUKUdCIqzPC48t1Y9hANFKIRpNx+Te8PI= +golang.org/x/time v0.14.0/go.mod h1:eL/Oa2bBBK0TkX57Fyni+NgnyQQN4LitPmob2Hjnqw4= golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= golang.org/x/tools v0.0.0-20200329025819-fd4102a86c65/go.mod h1:Sl4aGygMT6LrqrWclx+PTx3U+LnKx/seiNR+3G19Ar8= golang.org/x/tools v0.0.0-20200724022722-7017fd6b1305/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA= golang.org/x/tools v0.1.1-0.20210205202024-ef80cdb6ec6d/go.mod h1:9bzcO0MWcOuT0tm1iBGzDVPshzfwoVvREIui8C+MHqU= golang.org/x/tools v0.1.1-0.20210302220138-2ac05c832e1a/go.mod h1:9bzcO0MWcOuT0tm1iBGzDVPshzfwoVvREIui8C+MHqU= +golang.org/x/tools v0.1.1/go.mod h1:o0xws9oXOQQZyjljx8fwUC0k7L1pTE6eaCbjGeHmOkk= golang.org/x/tools v0.1.10/go.mod h1:Uh6Zz+xoGYZom868N8YTex3t7RhtHDBrE8Gzo9bV56E= golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc= golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU= -golang.org/x/tools v0.49.0 h1:3NI7VXzL9+1WZD52Dx2ttoPwD5DWrFGpl9mFZDlmisI= -golang.org/x/tools v0.49.0/go.mod h1:SJNXV9DBKT0UbdttsQjbfJlAE/q+y36++zo3uL3N0Oo= +golang.org/x/tools v0.13.0/go.mod h1:HvlwmtVNQAhOuCjW7xxvovg8wbNq7LwfXh/k7wXUl58= +golang.org/x/tools v0.14.0/go.mod h1:uYBEerGOWcJyEORxN+Ek8+TT266gXkNlHdJBwexUsBg= +golang.org/x/tools v0.42.0 h1:uNgphsn75Tdz5Ji2q36v/nsFSfR/9BRFvqhGBaJGd5k= +golang.org/x/tools v0.42.0/go.mod h1:Ma6lCIwGZvHK6XtgbswSoWroEkhugApmsXyrUmBhfr0= golang.org/x/tools/go/expect v0.1.1-deprecated h1:jpBZDwmgPhXsKZC6WhL20P4b/wmnpsEAGHaNy0n/rJM= golang.org/x/tools/go/expect v0.1.1-deprecated/go.mod h1:eihoPOH+FgIqa3FpoTwguz/bVUSGBlGQU67vpBeOrBY= golang.org/x/tools/go/packages/packagestest v0.1.1-deprecated h1:1h2MnaIAIXISqTFKdENegdpAgUXz6NrPEsbIeWaBRvM= @@ -851,20 +820,20 @@ golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8T golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da h1:noIWHXmPHxILtqtCOPIhSt0ABwskkZKjD3bXGnZGpNY= golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da/go.mod h1:NDW/Ps6MPRej6fsCIbMTohpP40sJ/P/vI1MoTEGwX90= -gonum.org/v1/gonum v0.17.0 h1:VbpOemQlsSMrYmn7T2OUvQ4dqxQXU+ouZFQsZOx50z4= -gonum.org/v1/gonum v0.17.0/go.mod h1:El3tOrEuMpv2UdMrbNlKEh9vd86bmQ6vqIcDwxEOc1E= -google.golang.org/api v0.288.0 h1:glhO/J88obKP5I269W3hB73dvBKrjU56ZfmNlNXpgTU= -google.golang.org/api v0.288.0/go.mod h1:lM2kYRzYUCBY91P9h6VF1PYmvhxii3O5hji37qRvIcY= -google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7 h1:XzmzkmB14QhVhgnawEVsOn6OFsnpyxNPRY9QV01dNB0= -google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7/go.mod h1:L43LFes82YgSonw6iTXTxXUX1OlULt4AQtkik4ULL/I= -google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7 h1:jQ9p21COKWjP3VwuFrNRiiOTMh3mPpN45R7SLrH/HUU= -google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7/go.mod h1:KqHwBx2upmfa1XSi1WuRvC+2VGCLtooKkfmyvRbUmqA= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 h1:qEHAMpSaUhtD0p3NbEEI83HwNGFxEwaSJ1G9PLnCBZE= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= -google.golang.org/grpc v1.83.2 h1:EManeRomTObA0BU7I8vXgg/78uE5MJ9M8B39EX2WscU= -google.golang.org/grpc v1.83.2/go.mod h1:YPI1hK3kDked6iHvgX3tR0y+nX/qpMFKhPgFsokw1S8= -google.golang.org/protobuf v1.36.12 h1:pJOKDDOyeXErUroCihFAd5LQuwXBSpVnKGrj5o/fwxc= -google.golang.org/protobuf v1.36.12/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco= +gonum.org/v1/gonum v0.16.0 h1:5+ul4Swaf3ESvrOnidPp4GZbzf0mxVQpDCYUQE7OJfk= +gonum.org/v1/gonum v0.16.0/go.mod h1:fef3am4MQ93R2HHpKnLk4/Tbh/s0+wqD5nfa6Pnwy4E= +google.golang.org/api v0.269.0 h1:qDrTOxKUQ/P0MveH6a7vZ+DNHxJQjtGm/uvdbdGXCQg= +google.golang.org/api v0.269.0/go.mod h1:N8Wpcu23Tlccl0zSHEkcAZQKDLdquxK+l9r2LkwAauE= +google.golang.org/genproto v0.0.0-20260128011058-8636f8732409 h1:VQZ/yAbAtjkHgH80teYd2em3xtIkkHd7ZhqfH2N9CsM= +google.golang.org/genproto v0.0.0-20260128011058-8636f8732409/go.mod h1:rxKD3IEILWEu3P44seeNOAwZN4SaoKaQ/2eTg4mM6EM= +google.golang.org/genproto/googleapis/api v0.0.0-20260128011058-8636f8732409 h1:merA0rdPeUV3YIIfHHcH4qBkiQAc1nfCKSI7lB4cV2M= +google.golang.org/genproto/googleapis/api v0.0.0-20260128011058-8636f8732409/go.mod h1:fl8J1IvUjCilwZzQowmw2b7HQB2eAuYBabMXzWurF+I= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260226221140-a57be14db171 h1:ggcbiqK8WWh6l1dnltU4BgWGIGo+EVYxCaAPih/zQXQ= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260226221140-a57be14db171/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= +google.golang.org/grpc v1.79.1 h1:zGhSi45ODB9/p3VAawt9a+O/MULLl9dpizzNNpq7flY= +google.golang.org/grpc v1.79.1/go.mod h1:KmT0Kjez+0dde/v2j9vzwoAScgEPx/Bw1CYChhHLrHQ= +google.golang.org/protobuf v1.36.11 h1:fV6ZwhNocDyBLK0dj+fg8ektcVegBBuEolpbTQyBNVE= +google.golang.org/protobuf v1.36.11/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20200227125254-8fa46927fb4f/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= @@ -880,39 +849,39 @@ gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C gopkg.in/yaml.v3 v3.0.0-20200615113413-eeeca48fe776/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -honnef.co/go/tools v0.8.0 h1:UacpzPr7D6i5BAjTkA7sNVcx4kIbhAZcQ4zYtKiXx68= -honnef.co/go/tools v0.8.0/go.mod h1:XA+OnlRA9EDh/ukGvXMNSZNKGwFQJ+5dER0ioUkOxks= -modernc.org/cc/v4 v4.29.2 h1:h6+9ciCnPKutf4I03CvheAvDLX7+IHlqR6Iy6J+cgd8= -modernc.org/cc/v4 v4.29.2/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI= -modernc.org/ccgo/v4 v4.35.0 h1:F+TUsmw09QxLzmi3aeYYGxjAXarmZaKgj3mKQHNaA8w= -modernc.org/ccgo/v4 v4.35.0/go.mod h1:qrVGs9S3Sr2Ztcg9ve+kTAYMp5a3YvWjo+SoN06kJ5I= +honnef.co/go/tools v0.7.0 h1:w6WUp1VbkqPEgLz4rkBzH/CSU6HkoqNLp6GstyTx3lU= +honnef.co/go/tools v0.7.0/go.mod h1:pm29oPxeP3P82ISxZDgIYeOaf9ta6Pi0EWvCFoLG2vc= +modernc.org/cc/v4 v4.27.1 h1:9W30zRlYrefrDV2JE2O8VDtJ1yPGownxciz5rrbQZis= +modernc.org/cc/v4 v4.27.1/go.mod h1:uVtb5OGqUKpoLWhqwNQo/8LwvoiEBLvZXIQ/SmO6mL0= +modernc.org/ccgo/v4 v4.32.0 h1:hjG66bI/kqIPX1b2yT6fr/jt+QedtP2fqojG2VrFuVw= +modernc.org/ccgo/v4 v4.32.0/go.mod h1:6F08EBCx5uQc38kMGl+0Nm0oWczoo1c7cgpzEry7Uc0= modernc.org/fileutil v1.4.0 h1:j6ZzNTftVS054gi281TyLjHPp6CPHr2KCxEXjEbD6SM= modernc.org/fileutil v1.4.0/go.mod h1:EqdKFDxiByqxLk8ozOxObDSfcVOv/54xDs/DUHdvCUU= modernc.org/gc/v2 v2.6.5 h1:nyqdV8q46KvTpZlsw66kWqwXRHdjIlJOhG6kxiV/9xI= modernc.org/gc/v2 v2.6.5/go.mod h1:YgIahr1ypgfe7chRuJi2gD7DBQiKSLMPgBQe9oIiito= -modernc.org/gc/v3 v3.1.5 h1:21ldfPfRYE31Tb7B3mwAK8gy1AxP4+dKjrOQPfqakoc= -modernc.org/gc/v3 v3.1.5/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY= +modernc.org/gc/v3 v3.1.2 h1:ZtDCnhonXSZexk/AYsegNRV1lJGgaNZJuKjJSWKyEqo= +modernc.org/gc/v3 v3.1.2/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY= modernc.org/goabi0 v0.2.0 h1:HvEowk7LxcPd0eq6mVOAEMai46V+i7Jrj13t4AzuNks= modernc.org/goabi0 v0.2.0/go.mod h1:CEFRnnJhKvWT1c1JTI3Avm+tgOWbkOu5oPA8eH8LnMI= -modernc.org/libc v1.75.6 h1:yKk8qo+Di4gkmvRboK8ocCqH22FiUCR6jRy2OwtCRus= -modernc.org/libc v1.75.6/go.mod h1:bO5o2ztHxBb2rjz0PgdHN0sSMw57CgxGFLZ3Qd/QpVQ= +modernc.org/libc v1.70.0 h1:U58NawXqXbgpZ/dcdS9kMshu08aiA6b7gusEusqzNkw= +modernc.org/libc v1.70.0/go.mod h1:OVmxFGP1CI/Z4L3E0Q3Mf1PDE0BucwMkcXjjLntvHJo= modernc.org/mathutil v1.7.1 h1:GCZVGXdaN8gTqB1Mf/usp1Y/hSqgI2vAGGP4jZMCxOU= modernc.org/mathutil v1.7.1/go.mod h1:4p5IwJITfppl0G4sUEDtCr4DthTaT47/N3aT6MhfgJg= -modernc.org/memory v1.12.1 h1:nFMiWrpStgZczNl6XI9GnIk/rWhYIyHGUaR04pGbp9g= -modernc.org/memory v1.12.1/go.mod h1:/JP4VbVC+K5sU2wZi9bHoq2MAkCnrt2r98UGeSK7Mjw= -modernc.org/opt v0.2.0 h1:tGyef5ApycA7FSEOMraay9SaTk5zmbx7Tu+cJs4QKZg= -modernc.org/opt v0.2.0/go.mod h1:03fq9lsNfvkYSfxrfUhZCWPk1lm4cq4N+Bh//bEtgns= +modernc.org/memory v1.11.0 h1:o4QC8aMQzmcwCK3t3Ux/ZHmwFPzE6hf2Y5LbkRs+hbI= +modernc.org/memory v1.11.0/go.mod h1:/JP4VbVC+K5sU2wZi9bHoq2MAkCnrt2r98UGeSK7Mjw= +modernc.org/opt v0.1.4 h1:2kNGMRiUjrp4LcaPuLY2PzUfqM/w9N23quVwhKt5Qm8= +modernc.org/opt v0.1.4/go.mod h1:03fq9lsNfvkYSfxrfUhZCWPk1lm4cq4N+Bh//bEtgns= modernc.org/sortutil v1.2.1 h1:+xyoGf15mM3NMlPDnFqrteY07klSFxLElE2PVuWIJ7w= modernc.org/sortutil v1.2.1/go.mod h1:7ZI3a3REbai7gzCLcotuw9AC4VZVpYMjDzETGsSMqJE= -modernc.org/sqlite v1.58.0 h1:38u40/bwkfM7f0Myhosl+SEMltSDxnGdQf8o6Kjmys0= -modernc.org/sqlite v1.58.0/go.mod h1:rsD2CckafgObKC4DhBlGBf+RiHxkc3hINGt1Xw32tVY= +modernc.org/sqlite v1.48.0 h1:ElZyLop3Q2mHYk5IFPPXADejZrlHu7APbpB0sF78bq4= +modernc.org/sqlite v1.48.0/go.mod h1:hWjRO6Tj/5Ik8ieqxQybiEOUXy0NJFNp2tpvVpKlvig= modernc.org/strutil v1.2.1 h1:UneZBkQA+DX2Rp35KcM69cSsNES9ly8mQWD71HKlOA0= modernc.org/strutil v1.2.1/go.mod h1:EHkiggD70koQxjVdSBM3JKM7k6L0FbGE5eymy9i3B9A= modernc.org/token v1.1.0 h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y= modernc.org/token v1.1.0/go.mod h1:UGzOrNV1mAFSEB63lOFHIpNRUVMvYTc6yu1SMY/XTDM= -mvdan.cc/gofumpt v0.11.0 h1:0H01XB95PnN2QgCSR9ELdZyTlJqNZ7181B0BTMh5VZc= -mvdan.cc/gofumpt v0.11.0/go.mod h1:BeT5wCsOJt6J9zT2MZIOGszjUHzFkn1/l9g6xAzqsXo= -mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673 h1:dEE6li4OPIE54oojY2qaayFS1fSp17G14si0gXRxl0U= -mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673/go.mod h1:62roFV3D3nYOWIXv3PfGO4UYEKAotz2WgLywT87ONd8= +mvdan.cc/gofumpt v0.9.2 h1:zsEMWL8SVKGHNztrx6uZrXdp7AX8r421Vvp23sz7ik4= +mvdan.cc/gofumpt v0.9.2/go.mod h1:iB7Hn+ai8lPvofHd9ZFGVg2GOr8sBUw1QUWjNbmIL/s= +mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15 h1:ssMzja7PDPJV8FStj7hq9IKiuiKhgz9ErWw+m68e7DI= +mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15/go.mod h1:4M5MMXl2kW6fivUT6yRGpLLPNfuGtU2Z0cPvFquGDYU= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/internal/accesslog/accesslog.go b/internal/accesslog/accesslog.go deleted file mode 100644 index 6a3cb01..0000000 --- a/internal/accesslog/accesslog.go +++ /dev/null @@ -1,109 +0,0 @@ -// Package accesslog writes proxy activity as JSON Lines. -package accesslog - -import ( - "context" - "encoding/json" - "fmt" - "net/url" - "os" - "sync" - "time" -) - -const ( - accessLogFileMode os.FileMode = 0o600 - - // EventRequest identifies the response sent by the proxy to a client. - EventRequest = "request" - // EventUpstream identifies one HTTP exchange with an upstream service. - EventUpstream = "upstream" -) - -type requestIDKey struct{} - -// Entry is one proxy activity record. -type Entry struct { - Time time.Time `json:"time"` - Event string `json:"event"` - RequestID string `json:"request_id,omitempty"` - Method string `json:"method"` - Path string `json:"path,omitempty"` - URL string `json:"url,omitempty"` - StatusCode int `json:"status_code,omitempty"` - DurationMS int64 `json:"duration_ms"` - RemoteAddr string `json:"remote_addr,omitempty"` - Error string `json:"error,omitempty"` -} - -// Logger appends complete JSON objects to a file, one per line. -type Logger struct { - mu sync.Mutex - file *os.File - encoder *json.Encoder -} - -// Open opens path for append, creating it with owner-only permissions when needed. -func Open(path string) (*Logger, error) { - file, err := os.OpenFile(path, os.O_APPEND|os.O_CREATE|os.O_WRONLY, accessLogFileMode) - if err != nil { - return nil, fmt.Errorf("opening access log: %w", err) - } - - return &Logger{ - file: file, - encoder: json.NewEncoder(file), - }, nil -} - -// Write appends an entry to the log. -func (l *Logger) Write(entry Entry) error { - if entry.Time.IsZero() { - entry.Time = time.Now().UTC() - } - - l.mu.Lock() - defer l.mu.Unlock() - - if err := l.encoder.Encode(entry); err != nil { - return fmt.Errorf("writing access log: %w", err) - } - return nil -} - -// Close closes the log file after any active writer finishes. -func (l *Logger) Close() error { - l.mu.Lock() - defer l.mu.Unlock() - - if err := l.file.Close(); err != nil { - return fmt.Errorf("closing access log: %w", err) - } - return nil -} - -// WithRequestID stores a proxy request ID in ctx. -func WithRequestID(ctx context.Context, requestID string) context.Context { - return context.WithValue(ctx, requestIDKey{}, requestID) -} - -// RequestID returns the proxy request ID stored in ctx. -func RequestID(ctx context.Context) string { - requestID, _ := ctx.Value(requestIDKey{}).(string) - return requestID -} - -// URLWithoutSecrets returns a URL without user information, query values, or fragments. -func URLWithoutSecrets(value *url.URL) string { - if value == nil { - return "" - } - - clean := *value - clean.User = nil - clean.RawQuery = "" - clean.ForceQuery = false - clean.Fragment = "" - clean.RawFragment = "" - return clean.String() -} diff --git a/internal/accesslog/accesslog_test.go b/internal/accesslog/accesslog_test.go deleted file mode 100644 index 4e53fa8..0000000 --- a/internal/accesslog/accesslog_test.go +++ /dev/null @@ -1,91 +0,0 @@ -package accesslog - -import ( - "bufio" - "context" - "encoding/json" - "net/url" - "os" - "path/filepath" - "sync" - "testing" -) - -func TestLoggerWritesJSONLines(t *testing.T) { - path := filepath.Join(t.TempDir(), "access.jsonl") - logger, err := Open(path) - if err != nil { - t.Fatal(err) - } - - const entries = 20 - var wg sync.WaitGroup - for range entries { - wg.Add(1) - go func() { - defer wg.Done() - if err := logger.Write(Entry{ - Event: EventUpstream, - RequestID: "request-id", - Method: "GET", - URL: "https://registry.example/packages/example", - StatusCode: 429, - }); err != nil { - t.Errorf("Write: %v", err) - } - }() - } - wg.Wait() - - if err := logger.Close(); err != nil { - t.Fatal(err) - } - - file, err := os.Open(path) - if err != nil { - t.Fatal(err) - } - defer func() { _ = file.Close() }() - - scanner := bufio.NewScanner(file) - count := 0 - for scanner.Scan() { - var entry Entry - if err := json.Unmarshal(scanner.Bytes(), &entry); err != nil { - t.Fatalf("line %d is not JSON: %v", count+1, err) - } - if entry.Time.IsZero() { - t.Errorf("line %d has no time", count+1) - } - if entry.StatusCode != 429 { - t.Errorf("line %d status_code = %d, want 429", count+1, entry.StatusCode) - } - count++ - } - if err := scanner.Err(); err != nil { - t.Fatal(err) - } - if count != entries { - t.Errorf("lines = %d, want %d", count, entries) - } -} - -func TestRequestID(t *testing.T) { - ctx := WithRequestID(context.Background(), "abc-123") - if got := RequestID(ctx); got != "abc-123" { - t.Errorf("RequestID = %q, want %q", got, "abc-123") - } -} - -func TestURLWithoutSecrets(t *testing.T) { - value, err := url.Parse("https://user:password@registry.example/package.tgz?token=secret#fragment") - if err != nil { - t.Fatal(err) - } - - got := URLWithoutSecrets(value) - want := "https://registry.example/package.tgz" - if got != want { - t.Errorf("URLWithoutSecrets = %q, want %q", got, want) - } -} diff --git a/internal/config/config.go b/internal/config/config.go index 5cccd13..ad0acc0 100644 --- a/internal/config/config.go +++ b/internal/config/config.go @@ -24,22 +24,10 @@ // storage: // url: "s3://bucket?endpoint=http://localhost:9000" // -// Google Cloud Storage: -// -// storage: -// url: "gs://bucket-name" -// // For S3, configure credentials via AWS environment variables: // // AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_REGION // -// For GCS, authentication uses Application Default Credentials. This supports -// GKE Workload Identity, attached service accounts on GCE and Cloud Run, and -// local credentials created by `gcloud auth application-default login`. -// When direct_serve is enabled without a private key, the GCS backend uses the -// IAM Credentials signBlob API. The service account must hold -// roles/iam.serviceAccountTokenCreator on itself. -// // Database Configuration: // // The proxy supports two database backends: @@ -63,40 +51,25 @@ import ( "encoding/base64" "encoding/json" "fmt" - "net/url" "os" "path/filepath" - "sort" "strconv" "strings" "time" - "github.com/git-pkgs/purl" "gopkg.in/yaml.v3" ) -// DefaultSwiftUpstream is the Swift Package Registry used when none is configured. -const DefaultSwiftUpstream = "https://tuist.dev/api/registry/swift" - // Config holds all configuration for the proxy server. type Config struct { // Listen is the address to listen on (e.g., ":8080", "127.0.0.1:8080"). Listen string `json:"listen" yaml:"listen"` - // BaseURL is the public URL where package endpoints are reachable. - // Used for rewriting package metadata URLs and shown to humans on the - // install guide so they know what to point their package manager at. + // BaseURL is the public URL where this proxy is accessible. + // Used for rewriting package metadata URLs. // Example: "https://proxy.example.com" or "http://localhost:8080" BaseURL string `json:"base_url" yaml:"base_url"` - // UIBaseURL is the public URL where the web UI is reachable. Defaults to - // BaseURL when unset. Set this separately when the UI is served on a - // different hostname than the package endpoints — for example, the UI on a - // public domain behind auth while build machines hit a Docker network alias - // for the package endpoints. - // Example: "https://proxy.example.com/ui" - UIBaseURL string `json:"ui_base_url" yaml:"ui_base_url"` - // Storage configures artifact storage. Storage StorageConfig `json:"storage" yaml:"storage"` @@ -106,19 +79,12 @@ type Config struct { // Log configures logging. Log LogConfig `json:"log" yaml:"log"` - // AccessLog configures the JSONL activity log. - AccessLog AccessLogConfig `json:"access_log" yaml:"access_log"` - // Upstream configures upstream registry URLs (optional overrides). Upstream UpstreamConfig `json:"upstream" yaml:"upstream"` // Cooldown configures version age filtering to mitigate supply chain attacks. Cooldown CooldownConfig `json:"cooldown" yaml:"cooldown"` - // Scanning configures pre-cache artifact scanning (trivy, ClamAV, Wiz, - // or a custom service) to mitigate supply chain attacks. - Scanning ScanningConfig `json:"scanning" yaml:"scanning"` - // CacheMetadata enables caching of upstream metadata responses for offline fallback. // When enabled, metadata is stored in the database and storage backend. // The mirror command always enables this regardless of this setting. @@ -129,28 +95,9 @@ type Config struct { // Default: "5m". Set to "0" to always revalidate. MetadataTTL string `json:"metadata_ttl" yaml:"metadata_ttl"` - // MetadataMaxSize is the maximum size of an upstream metadata response - // the proxy will buffer (e.g. "100MB", "250MB"). Responses over this - // size return ErrMetadataTooLarge. Default: "100MB". - MetadataMaxSize string `json:"metadata_max_size" yaml:"metadata_max_size"` - - // HTTPTimeout is the timeout for individual upstream HTTP requests made - // by protocol handlers (metadata fetches, pass-through file requests). - // Uses Go duration syntax (e.g. "30s", "2m"). Default: "30s". - // Set to "0" to disable the timeout entirely. Independently of this - // setting, the shared transport gives up on an upstream that has not sent - // response headers within 60 seconds. - HTTPTimeout string `json:"http_timeout" yaml:"http_timeout"` - // MirrorAPI enables the /api/mirror endpoints for starting mirror jobs via HTTP. // Disabled by default to prevent unauthenticated users from triggering downloads. MirrorAPI bool `json:"mirror_api" yaml:"mirror_api"` - - // Gradle configures Gradle HttpBuildCache behavior. - Gradle GradleConfig `json:"gradle" yaml:"gradle"` - - // Health configures the /health endpoint behavior. - Health HealthConfig `json:"health" yaml:"health"` } // CooldownConfig configures version cooldown periods. @@ -163,172 +110,9 @@ type CooldownConfig struct { Ecosystems map[string]string `json:"ecosystems" yaml:"ecosystems"` // Packages overrides the cooldown for specific packages (keyed by PURL). - // Valid PURL keys are normalized to canonical form before use. Packages map[string]string `json:"packages" yaml:"packages"` } -// NormalizedPackages returns a copy of the package overrides with valid PURL -// keys in canonical form. An explicitly canonical key wins over an equivalent -// noncanonical key, and invalid keys are preserved unchanged. -func (c *CooldownConfig) NormalizedPackages() map[string]string { - if c == nil || c.Packages == nil { - return nil - } - - keys := make([]string, 0, len(c.Packages)) - for key := range c.Packages { - keys = append(keys, key) - } - sort.Strings(keys) - - normalized := make(map[string]string, len(c.Packages)) - for _, key := range keys { - canonical := key - if parsed, err := purl.Parse(key); err == nil { - canonical = parsed.String() - } - if _, exists := normalized[canonical]; exists && key != canonical { - continue - } - normalized[canonical] = c.Packages[key] - } - return normalized -} - -// ScanningConfig configures pre-cache artifact scanning (e.g. trivy, -// ClamAV, Wiz, or a custom service) to mitigate supply chain attacks. -// Unlike Cooldown, which only looks at a version's publish timestamp, -// scanning inspects the actual artifact bytes before they become -// servable from cache. -type ScanningConfig struct { - // Enabled turns on the scan gate. When false (default), artifacts are - // cached exactly as if scanning didn't exist. - Enabled bool `json:"enabled" yaml:"enabled"` - - // FailOpen treats scanner errors and timeouts as an allow verdict - // instead of a block. Default is fail-closed, since the default - // posture for a security gate should block on infrastructure failure. - FailOpen bool `json:"fail_open" yaml:"fail_open"` - - // Timeout bounds each scan call. Uses Go duration syntax (e.g. "30s"). - // Default: "30s". - Timeout string `json:"timeout" yaml:"timeout"` - - // SigningKey authenticates pull requests to the internal scan-fetch - // route used by every storage backend. Required whenever Enabled is - // true. Supports ${VAR_NAME} expansion like AuthConfig fields. - SigningKey string `json:"signing_key" yaml:"signing_key"` - - // FetchBaseURL is the address scanners use to reach this proxy to pull - // staged artifacts. Defaults to BaseURL. Set this separately when - // scanners reach the proxy over an internal address different from the - // public-facing BaseURL (mirrors DirectServeBaseURL/UIBaseURL). - FetchBaseURL string `json:"fetch_base_url" yaml:"fetch_base_url"` - - // Scanners is the list of external scanning services to call. - Scanners []ScannerConfig `json:"scanners" yaml:"scanners"` -} - -// ScannerConfig configures a single external scanning service. -type ScannerConfig struct { - // Name identifies this scanner in logs and metrics. - Name string `json:"name" yaml:"name"` - - // URL is the endpoint the proxy POSTs scan notifications to. - URL string `json:"url" yaml:"url"` - - // Mode is "block" (default) or "monitor". A "block" scanner's verdict - // can prevent caching; a "monitor" scanner's findings are logged but - // never gate caching. - Mode string `json:"mode" yaml:"mode"` - - // Ecosystems restricts this scanner to specific ecosystems (e.g. - // "npm", "pypi"). Empty means all ecosystems. - Ecosystems []string `json:"ecosystems" yaml:"ecosystems"` - - // Headers are additional HTTP headers sent with every scan request - // (e.g. for authenticating to the scanner service). Values support - // ${VAR_NAME} expansion like AuthConfig fields. - Headers map[string]string `json:"headers" yaml:"headers"` -} - -// SigningKeyExpanded returns SigningKey with ${VAR_NAME} references expanded. -func (s *ScanningConfig) SigningKeyExpanded() string { - return expandEnv(s.SigningKey) -} - -// HeadersExpanded returns Headers with ${VAR_NAME} references expanded in -// each value. -func (s *ScannerConfig) HeadersExpanded() map[string]string { - if len(s.Headers) == 0 { - return nil - } - expanded := make(map[string]string, len(s.Headers)) - for k, v := range s.Headers { - expanded[k] = expandEnv(v) - } - return expanded -} - -// Validate checks the scanning configuration for errors, applying the -// default timeout if unset. -func (s *ScanningConfig) Validate() error { - if !s.Enabled { - return nil - } - - if s.SigningKeyExpanded() == "" { - return fmt.Errorf("scanning.signing_key is required when scanning.enabled is true") - } - - if len(s.Scanners) == 0 { - return fmt.Errorf("scanning.scanners must not be empty when scanning.enabled is true") - } - - if s.FetchBaseURL != "" { - if err := validateAbsoluteURL("scanning.fetch_base_url", s.FetchBaseURL); err != nil { - return err - } - } - - if s.Timeout == "" { - s.Timeout = defaultScanningTimeoutStr - } - if d, err := time.ParseDuration(s.Timeout); err != nil { - return fmt.Errorf("invalid scanning.timeout %q: %w", s.Timeout, err) - } else if d <= 0 { - return fmt.Errorf("invalid scanning.timeout %q: must be > 0", s.Timeout) - } - - for i := range s.Scanners { - if err := s.Scanners[i].Validate(); err != nil { - return fmt.Errorf("scanning.scanners[%d]: %w", i, err) - } - } - - return nil -} - -// Validate checks a single scanner's configuration, applying the default -// mode ("block") if unset. -func (s *ScannerConfig) Validate() error { - if s.Name == "" { - return fmt.Errorf("name is required") - } - if err := validateAbsoluteURL("url", s.URL); err != nil { - return err - } - if s.Mode == "" { - s.Mode = "block" - } - switch s.Mode { - case "block", "monitor": - default: - return fmt.Errorf("invalid mode %q (must be block or monitor)", s.Mode) - } - return nil -} - // StorageConfig configures artifact storage. type StorageConfig struct { // URL is the storage backend URL. @@ -336,8 +120,6 @@ type StorageConfig struct { // - file:///path/to/dir - Local filesystem (default) // - s3://bucket-name - Amazon S3 // - s3://bucket?endpoint=http://localhost:9000 - S3-compatible (MinIO) - // - gs://bucket-name - Google Cloud Storage (Workload Identity supported) - // - azblob://container-name - Azure Blob Storage // If empty, defaults to file:// with the Path value. URL string `json:"url" yaml:"url"` @@ -351,57 +133,6 @@ type StorageConfig struct { // When exceeded, least recently used artifacts are evicted. // Empty or "0" means unlimited. MaxSize string `json:"max_size" yaml:"max_size"` - - // DirectServe enables redirecting cached artifact downloads to presigned - // storage URLs (HTTP 302) instead of streaming bytes through the proxy. - // Only effective for backends that support URL signing (S3, GCS, Azure). - DirectServe bool `json:"direct_serve" yaml:"direct_serve"` - - // DirectServeTTL is how long presigned URLs remain valid. - // Uses Go duration syntax (e.g. "5m", "1h"). Default: "15m". - DirectServeTTL string `json:"direct_serve_ttl" yaml:"direct_serve_ttl"` - - // DirectServeBaseURL overrides the scheme and host of presigned URLs - // before returning them to clients. Useful when the proxy reaches - // storage at an internal address (e.g. 127.0.0.1 or a Docker hostname) - // but clients must use a public one. - DirectServeBaseURL string `json:"direct_serve_base_url" yaml:"direct_serve_base_url"` -} - -// GradleConfig configures Gradle-specific features. -type GradleConfig struct { - // BuildCache configures the /gradle HttpBuildCache endpoint. - BuildCache GradleBuildCacheConfig `json:"build_cache" yaml:"build_cache"` -} - -// GradleBuildCacheConfig configures Gradle HttpBuildCache safeguards. -type GradleBuildCacheConfig struct { - // ReadOnly disables PUT uploads and keeps cache reads (GET/HEAD) enabled. - ReadOnly bool `json:"read_only" yaml:"read_only"` - - // MaxUploadSize caps a single PUT body size (e.g., "100MB"). Must be > 0. - // Default: "100MB". - MaxUploadSize string `json:"max_upload_size" yaml:"max_upload_size"` - - // MaxAge evicts entries older than this duration (e.g., "24h", "7d"). - // Empty or "0" disables age-based eviction. - MaxAge string `json:"max_age" yaml:"max_age"` - - // MaxSize evicts oldest entries until total Gradle cache size is <= MaxSize. - // Empty or "0" disables size-based eviction. - MaxSize string `json:"max_size" yaml:"max_size"` - - // SweepInterval controls periodic eviction frequency. - // Default: "10m". - SweepInterval string `json:"sweep_interval" yaml:"sweep_interval"` -} - -// HealthConfig configures the /health endpoint. -type HealthConfig struct { - // StorageProbeInterval is the minimum time between storage backend probes. - // Uses Go duration syntax (e.g. "30s", "1m"). Default: "30s". - // Set to "0" to probe on every /health request (useful for low-traffic deployments). - StorageProbeInterval string `json:"storage_probe_interval" yaml:"storage_probe_interval"` } // DatabaseConfig configures the cache database. @@ -416,21 +147,6 @@ type DatabaseConfig struct { URL string `json:"url" yaml:"url"` } -// String returns a human-readable description of the configured database -// suitable for logging. For postgres the password in the connection URL is -// redacted; if the URL cannot be parsed only the driver name is returned to -// avoid leaking credentials. -func (d DatabaseConfig) String() string { - if d.Driver == "postgres" { - u, err := url.Parse(d.URL) - if err != nil || u.Host == "" { - return "postgres" - } - return u.Redacted() - } - return d.Path -} - // LogConfig configures logging. type LogConfig struct { // Level is the minimum log level: "debug", "info", "warn", "error". @@ -440,32 +156,13 @@ type LogConfig struct { Format string `json:"format" yaml:"format"` } -// AccessLogConfig configures the JSONL activity log. -type AccessLogConfig struct { - // Path is the file to append activity records to. Empty disables the access log. - Path string `json:"path" yaml:"path"` -} - -// UpstreamConfig configures upstream URLs for built-in routes and authentication. +// UpstreamConfig configures upstream registry URLs and authentication. // Leave empty to use defaults. type UpstreamConfig struct { - // AllowPrivateHosts permits listed upstream hosts to resolve to private addresses. - AllowPrivateHosts []string `json:"allow_private_hosts" yaml:"allow_private_hosts"` - - // AllowLoopback permits upstream requests and redirects to loopback addresses. - AllowLoopback bool `json:"allow_loopback" yaml:"allow_loopback"` - // NPM is the upstream npm registry URL. // Default: https://registry.npmjs.org NPM string `json:"npm" yaml:"npm"` - // NPMFullMetadata always requests the full packument (application/json) - // from the npm upstream, so served metadata carries the "time" map even - // when cooldown is disabled. Clients that gate on publish age (for - // example Yarn's npmMinimalAgeGate) need this. - // Default: false (the abbreviated format is preferred). - NPMFullMetadata bool `json:"npm_full_metadata" yaml:"npm_full_metadata"` - // Cargo is the upstream cargo index URL. // Default: https://index.crates.io Cargo string `json:"cargo" yaml:"cargo"` @@ -474,148 +171,24 @@ type UpstreamConfig struct { // Default: https://static.crates.io/crates CargoDownload string `json:"cargo_download" yaml:"cargo_download"` - // Gem is the upstream RubyGems registry URL. - // Default: https://rubygems.org - Gem string `json:"gem" yaml:"gem"` - - // Go is the upstream Go module proxy URL. - // Default: https://proxy.golang.org - Go string `json:"go" yaml:"go"` - - // Hex is the upstream Hex repository URL. - // Default: https://repo.hex.pm - Hex string `json:"hex" yaml:"hex"` - - // HexAPI is the upstream Hex API URL used for package timestamps. - // Default: https://hex.pm - HexAPI string `json:"hex_api" yaml:"hex_api"` - - // Pub is the upstream pub registry URL. - // Default: https://pub.dev - Pub string `json:"pub" yaml:"pub"` - - // PyPI is the upstream PyPI index and API URL. - // Default: https://pypi.org - PyPI string `json:"pypi" yaml:"pypi"` - - // PyPIDownload is the upstream PyPI package download URL. - // Default: https://files.pythonhosted.org - PyPIDownload string `json:"pypi_download" yaml:"pypi_download"` - - // Maven is the upstream Maven repository URL. - // Default: https://repo1.maven.org/maven2 - Maven string `json:"maven" yaml:"maven"` - - // GradlePluginPortal is the upstream Gradle Plugin Portal Maven URL. - // Used to resolve Gradle plugin marker artifacts. - // Default: https://plugins.gradle.org/m2 - GradlePluginPortal string `json:"gradle_plugin_portal" yaml:"gradle_plugin_portal"` - - // NuGet is the upstream NuGet API URL. - // Default: https://api.nuget.org - NuGet string `json:"nuget" yaml:"nuget"` - - // NuGetSearch is the upstream NuGet search API URL. - // Default: https://azuresearch-usnc.nuget.org - NuGetSearch string `json:"nuget_search" yaml:"nuget_search"` - - // Composer is the upstream Packagist API URL. - // Default: https://packagist.org - Composer string `json:"composer" yaml:"composer"` - - // ComposerRepository is the upstream Packagist repository URL. - // Default: https://repo.packagist.org - ComposerRepository string `json:"composer_repository" yaml:"composer_repository"` - - // Conan is the upstream Conan registry URL. - // Default: https://center.conan.io - Conan string `json:"conan" yaml:"conan"` - - // Conda is the upstream Conda channel base URL. - // Default: https://conda.anaconda.org - Conda string `json:"conda" yaml:"conda"` - - // CRAN is the upstream CRAN mirror URL. - // Default: https://cloud.r-project.org - CRAN string `json:"cran" yaml:"cran"` - - // Julia is the upstream Julia package server URL. - // Default: https://pkg.julialang.org - Julia string `json:"julia" yaml:"julia"` - - // OCIDefault is the default upstream OCI registry URL. - // Default: https://registry-1.docker.io - OCIDefault string `json:"oci_default" yaml:"oci_default"` - - // Swift is the upstream Swift Package Registry URL. - // Default: https://tuist.dev/api/registry/swift - Swift string `json:"swift" yaml:"swift"` - - // Debian is the upstream APT repository base URL. - // Example: http://archive.ubuntu.com/ubuntu would get Ubuntu. - // Default: http://deb.debian.org/debian - Debian string `json:"debian" yaml:"debian"` - - // RPM is the upstream RPM repository base URL. - // Default: https://dl.fedoraproject.org/pub/fedora/linux - RPM string `json:"rpm" yaml:"rpm"` - - // HomebrewAPI is the upstream Homebrew JSON API URL. - // Default: https://formulae.brew.sh/api - HomebrewAPI string `json:"homebrew_api" yaml:"homebrew_api"` - - // HomebrewArtifact is the upstream registry URL for Homebrew artifacts. - // Default: https://ghcr.io - HomebrewArtifact string `json:"homebrew_artifact" yaml:"homebrew_artifact"` - - // Helm maps repository names to HTTP Helm chart repository URLs. - // Requests use /helm/{name}/index.yaml and chart URLs in the index are - // rewritten to the same named proxy endpoint. - Helm map[string]string `json:"helm" yaml:"helm"` - - // APK maps repository names to Alpine APK repository base URLs, served - // at /apk/{name}/. The remaining request path mirrors the upstream - // layout, e.g. /apk/alpine/v3.22/main/x86_64/APKINDEX.tar.gz. - // Default when empty: {"alpine": "https://dl-cdn.alpinelinux.org/alpine"}. - APK map[string]string `json:"apk" yaml:"apk"` - - // OCI maps names to OCI registry URLs. Requests to a named registry use - // the repository prefix upstream/{name}/, for example - // oci://proxy.example.com/upstream/ghcr/owner/chart. - OCI map[string]string `json:"oci" yaml:"oci"` - - // Generic maps names to plain HTTP upstream base URLs, served at - // /generic/{name}/. The remaining request path and query string are - // appended to the upstream URL. GitHub release asset paths - // ({owner}/{repo}/releases/download/{tag}/{asset}) are cached in the - // artifact cache; everything else goes through the metadata cache. - // Example: {"github": "https://github.com", "github-api": "https://api.github.com"}. - Generic map[string]string `json:"generic" yaml:"generic"` - // Auth configures authentication for upstream registries. - // Keys are absolute URL scopes matched by scheme, host, effective port, - // and path-segment prefix. + // Keys are URL prefixes that are matched against request URLs. // Example: "https://npm.pkg.github.com" matches all requests to that host. Auth map[string]AuthConfig `json:"auth" yaml:"auth"` } // AuthForURL returns the auth config that matches the given URL. -// The longest matching URL scope wins. +// Matches are based on URL prefix - the longest matching prefix wins. func (u *UpstreamConfig) AuthForURL(url string) *AuthConfig { if u.Auth == nil { return nil } - target, err := parseAuthURL(url) - if err != nil { - return nil - } var bestMatch *AuthConfig var bestLen int for pattern, auth := range u.Auth { - configured, err := parseAuthURL(pattern) - if err == nil && authURLMatches(configured, target) && len(pattern) > bestLen { + if strings.HasPrefix(url, pattern) && len(pattern) > bestLen { a := auth // copy to avoid loop variable capture bestMatch = &a bestLen = len(pattern) @@ -625,82 +198,9 @@ func (u *UpstreamConfig) AuthForURL(url string) *AuthConfig { return bestMatch } -// Validate checks upstream authentication URL scopes. -func (u *UpstreamConfig) Validate() error { - for pattern := range u.Auth { - if _, err := parseAuthURL(pattern); err != nil { - return fmt.Errorf("invalid upstream.auth URL %q: %w", pattern, err) - } - } - if err := validateNamedUpstreams("upstream.helm", u.Helm); err != nil { - return err - } - if err := validateNamedUpstreams("upstream.apk", u.APK); err != nil { - return err - } - if err := validateNamedUpstreams("upstream.oci", u.OCI); err != nil { - return err - } - if err := validateNamedUpstreams("upstream.generic", u.Generic); err != nil { - return err - } - return nil -} - -func validateNamedUpstreams(field string, upstreams map[string]string) error { - for name, upstreamURL := range upstreams { - if name == "" || name == "." || name == ".." || strings.ContainsAny(name, `/\\`) { - return fmt.Errorf("invalid %s name %q", field, name) - } - if err := validateAbsoluteURL(field+"."+name, upstreamURL); err != nil { - return err - } - } - return nil -} - -func parseAuthURL(value string) (*url.URL, error) { - parsed, err := url.Parse(value) - if err != nil || !parsed.IsAbs() || parsed.Hostname() == "" || parsed.Opaque != "" { - return nil, fmt.Errorf("invalid authentication URL") - } - return parsed, nil -} - -func authURLMatches(configured, target *url.URL) bool { - if !strings.EqualFold(configured.Scheme, target.Scheme) || - !strings.EqualFold(configured.Hostname(), target.Hostname()) || - authURLPort(configured) != authURLPort(target) { - return false - } - if configured.RawQuery != "" && configured.RawQuery != target.RawQuery { - return false - } - - configuredPath := strings.TrimSuffix(configured.EscapedPath(), "/") - if configuredPath == "" { - return true - } - targetPath := strings.TrimSuffix(target.EscapedPath(), "/") - return targetPath == configuredPath || strings.HasPrefix(targetPath, configuredPath+"/") -} - -func authURLPort(value *url.URL) string { - if port := value.Port(); port != "" { - return port - } - if strings.EqualFold(value.Scheme, "https") { - return "443" - } - if strings.EqualFold(value.Scheme, "http") { - return "80" - } - return "" -} - // AuthConfig configures authentication for an upstream registry. type AuthConfig struct { - // Type is the authentication type: "bearer", "basic", "header", or "ecr". + // Type is the authentication type: "bearer", "basic", or "header". Type string `json:"type" yaml:"type"` // Token is used for bearer authentication. @@ -720,11 +220,6 @@ type AuthConfig struct { // HeaderValue is the custom header value (for type "header"). // Can reference environment variables with ${VAR_NAME} syntax. HeaderValue string `json:"header_value" yaml:"header_value"` - - // Region is the AWS region for ECR authentication (for type "ecr"). - // If empty, the region is inferred from private ECR registry URLs before - // falling back to the AWS SDK default region chain. - Region string `json:"region" yaml:"region"` } // Default returns a Config with sensible defaults. @@ -745,41 +240,9 @@ func Default() *Config { Format: "text", }, Upstream: UpstreamConfig{ - NPM: "https://registry.npmjs.org", - Cargo: "https://index.crates.io", - CargoDownload: "https://static.crates.io/crates", - Gem: "https://rubygems.org", - Go: "https://proxy.golang.org", - Hex: "https://repo.hex.pm", - HexAPI: "https://hex.pm", - Pub: "https://pub.dev", - PyPI: "https://pypi.org", - PyPIDownload: "https://files.pythonhosted.org", - Maven: "https://repo1.maven.org/maven2", - GradlePluginPortal: "https://plugins.gradle.org/m2", - NuGet: "https://api.nuget.org", - NuGetSearch: "https://azuresearch-usnc.nuget.org", - Composer: "https://packagist.org", - ComposerRepository: "https://repo.packagist.org", - Conan: "https://center.conan.io", - Conda: "https://conda.anaconda.org", - CRAN: "https://cloud.r-project.org", - Julia: "https://pkg.julialang.org", - Swift: DefaultSwiftUpstream, - OCIDefault: "https://registry-1.docker.io", - Debian: "http://deb.debian.org/debian", - RPM: "https://dl.fedoraproject.org/pub/fedora/linux", - HomebrewAPI: "https://formulae.brew.sh/api", - HomebrewArtifact: "https://ghcr.io", - }, - Gradle: GradleConfig{ - BuildCache: GradleBuildCacheConfig{ - ReadOnly: false, - MaxUploadSize: defaultGradleMaxUploadSizeStr, - MaxAge: "168h", - MaxSize: "", - SweepInterval: defaultGradleSweepIntervalStr, - }, + NPM: "https://registry.npmjs.org", + Cargo: "https://index.crates.io", + CargoDownload: "https://static.crates.io/crates", }, } } @@ -815,122 +278,58 @@ func Load(path string) (*Config, error) { return cfg, nil } -// setEnvString sets *dst from the named environment variable, leaving it -// untouched if the variable is unset or empty. -func setEnvString(dst *string, key string) { - if v := os.Getenv(key); v != "" { - *dst = v - } -} - -// setEnvBool is setEnvString for boolean fields, parsed via envBool. -func setEnvBool(dst *bool, key string) { - if v := os.Getenv(key); v != "" { - *dst = envBool(v) - } -} - -func setEnvStringSlice(dst *[]string, key string) { - value := os.Getenv(key) - if value == "" { - return - } - var items []string - for item := range strings.SplitSeq(value, ",") { - if item = strings.TrimSpace(item); item != "" { - items = append(items, item) - } - } - if len(items) > 0 { - *dst = items - } -} - // LoadFromEnv applies environment variable overrides to a Config. // Environment variables use the PROXY_ prefix: // - PROXY_LISTEN // - PROXY_BASE_URL -// - PROXY_UI_URL // - PROXY_STORAGE_PATH // - PROXY_STORAGE_MAX_SIZE // - PROXY_DATABASE_PATH // - PROXY_LOG_LEVEL // - PROXY_LOG_FORMAT -// - PROXY_ACCESS_LOG_PATH -// - PROXY_UPSTREAM_SWIFT -// - PROXY_HEALTH_STORAGE_PROBE_INTERVAL func (c *Config) LoadFromEnv() { - setEnvString(&c.Listen, "PROXY_LISTEN") - setEnvString(&c.BaseURL, "PROXY_BASE_URL") - setEnvString(&c.UIBaseURL, "PROXY_UI_URL") - setEnvString(&c.Storage.URL, "PROXY_STORAGE_URL") - setEnvString(&c.Storage.Path, "PROXY_STORAGE_PATH") - setEnvString(&c.Storage.MaxSize, "PROXY_STORAGE_MAX_SIZE") - setEnvBool(&c.Storage.DirectServe, "PROXY_STORAGE_DIRECT_SERVE") - setEnvString(&c.Storage.DirectServeTTL, "PROXY_STORAGE_DIRECT_SERVE_TTL") - setEnvString(&c.Storage.DirectServeBaseURL, "PROXY_STORAGE_DIRECT_SERVE_BASE_URL") - setEnvString(&c.Database.Driver, "PROXY_DATABASE_DRIVER") - setEnvString(&c.Database.Path, "PROXY_DATABASE_PATH") - setEnvString(&c.Database.URL, "PROXY_DATABASE_URL") - setEnvString(&c.Log.Level, "PROXY_LOG_LEVEL") - setEnvString(&c.Log.Format, "PROXY_LOG_FORMAT") - setEnvString(&c.AccessLog.Path, "PROXY_ACCESS_LOG_PATH") - setEnvStringSlice(&c.Upstream.AllowPrivateHosts, "PROXY_UPSTREAM_ALLOW_PRIVATE_HOSTS") - setEnvBool(&c.Upstream.AllowLoopback, "PROXY_UPSTREAM_ALLOW_LOOPBACK") - setEnvString(&c.Upstream.NPM, "PROXY_UPSTREAM_NPM") - setEnvBool(&c.Upstream.NPMFullMetadata, "PROXY_UPSTREAM_NPM_FULL_METADATA") - setEnvString(&c.Upstream.Cargo, "PROXY_UPSTREAM_CARGO") - setEnvString(&c.Upstream.CargoDownload, "PROXY_UPSTREAM_CARGO_DOWNLOAD") - setEnvString(&c.Upstream.Gem, "PROXY_UPSTREAM_GEM") - setEnvString(&c.Upstream.Go, "PROXY_UPSTREAM_GO") - setEnvString(&c.Upstream.Hex, "PROXY_UPSTREAM_HEX") - setEnvString(&c.Upstream.HexAPI, "PROXY_UPSTREAM_HEX_API") - setEnvString(&c.Upstream.Pub, "PROXY_UPSTREAM_PUB") - setEnvString(&c.Upstream.PyPI, "PROXY_UPSTREAM_PYPI") - setEnvString(&c.Upstream.PyPIDownload, "PROXY_UPSTREAM_PYPI_DOWNLOAD") - setEnvString(&c.Upstream.Maven, "PROXY_UPSTREAM_MAVEN") - setEnvString(&c.Upstream.GradlePluginPortal, "PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL") - setEnvString(&c.Upstream.NuGet, "PROXY_UPSTREAM_NUGET") - setEnvString(&c.Upstream.NuGetSearch, "PROXY_UPSTREAM_NUGET_SEARCH") - setEnvString(&c.Upstream.Composer, "PROXY_UPSTREAM_COMPOSER") - setEnvString(&c.Upstream.ComposerRepository, "PROXY_UPSTREAM_COMPOSER_REPOSITORY") - setEnvString(&c.Upstream.Conan, "PROXY_UPSTREAM_CONAN") - setEnvString(&c.Upstream.Conda, "PROXY_UPSTREAM_CONDA") - setEnvString(&c.Upstream.CRAN, "PROXY_UPSTREAM_CRAN") - setEnvString(&c.Upstream.Julia, "PROXY_UPSTREAM_JULIA") - setEnvString(&c.Upstream.Swift, "PROXY_UPSTREAM_SWIFT") - setEnvString(&c.Upstream.OCIDefault, "PROXY_UPSTREAM_OCI_DEFAULT") - setEnvString(&c.Upstream.Debian, "PROXY_UPSTREAM_DEBIAN") - setEnvString(&c.Upstream.RPM, "PROXY_UPSTREAM_RPM") - setEnvString(&c.Upstream.HomebrewAPI, "PROXY_UPSTREAM_HOMEBREW_API") - setEnvString(&c.Upstream.HomebrewArtifact, "PROXY_UPSTREAM_HOMEBREW_ARTIFACT") - setEnvString(&c.Cooldown.Default, "PROXY_COOLDOWN_DEFAULT") - setEnvBool(&c.Scanning.Enabled, "PROXY_SCANNING_ENABLED") - setEnvBool(&c.Scanning.FailOpen, "PROXY_SCANNING_FAIL_OPEN") - setEnvString(&c.Scanning.Timeout, "PROXY_SCANNING_TIMEOUT") - setEnvString(&c.Scanning.SigningKey, "PROXY_SCANNING_SIGNING_KEY") - setEnvString(&c.Scanning.FetchBaseURL, "PROXY_SCANNING_FETCH_BASE_URL") - setEnvBool(&c.CacheMetadata, "PROXY_CACHE_METADATA") - setEnvBool(&c.MirrorAPI, "PROXY_MIRROR_API") - setEnvString(&c.MetadataTTL, "PROXY_METADATA_TTL") - setEnvString(&c.MetadataMaxSize, "PROXY_METADATA_MAX_SIZE") - setEnvString(&c.HTTPTimeout, "PROXY_HTTP_TIMEOUT") - setEnvBool(&c.Gradle.BuildCache.ReadOnly, "PROXY_GRADLE_BUILD_CACHE_READ_ONLY") - setEnvString(&c.Gradle.BuildCache.MaxUploadSize, "PROXY_GRADLE_BUILD_CACHE_MAX_UPLOAD_SIZE") - setEnvString(&c.Gradle.BuildCache.MaxAge, "PROXY_GRADLE_BUILD_CACHE_MAX_AGE") - setEnvString(&c.Gradle.BuildCache.MaxSize, "PROXY_GRADLE_BUILD_CACHE_MAX_SIZE") - setEnvString(&c.Gradle.BuildCache.SweepInterval, "PROXY_GRADLE_BUILD_CACHE_SWEEP_INTERVAL") - setEnvString(&c.Health.StorageProbeInterval, "PROXY_HEALTH_STORAGE_PROBE_INTERVAL") -} - -// validateAbsoluteURL returns an error if value is not a parseable URL with -// both a scheme and host. fieldName is used in the error message. -func validateAbsoluteURL(fieldName, value string) error { - u, err := url.Parse(value) - if err != nil || u.Scheme == "" || u.Host == "" { - return fmt.Errorf("invalid %s %q: must be an absolute URL", fieldName, value) + if v := os.Getenv("PROXY_LISTEN"); v != "" { + c.Listen = v + } + if v := os.Getenv("PROXY_BASE_URL"); v != "" { + c.BaseURL = v + } + if v := os.Getenv("PROXY_STORAGE_URL"); v != "" { + c.Storage.URL = v + } + if v := os.Getenv("PROXY_STORAGE_PATH"); v != "" { + c.Storage.Path = v + } + if v := os.Getenv("PROXY_STORAGE_MAX_SIZE"); v != "" { + c.Storage.MaxSize = v + } + if v := os.Getenv("PROXY_DATABASE_DRIVER"); v != "" { + c.Database.Driver = v + } + if v := os.Getenv("PROXY_DATABASE_PATH"); v != "" { + c.Database.Path = v + } + if v := os.Getenv("PROXY_DATABASE_URL"); v != "" { + c.Database.URL = v + } + if v := os.Getenv("PROXY_LOG_LEVEL"); v != "" { + c.Log.Level = v + } + if v := os.Getenv("PROXY_LOG_FORMAT"); v != "" { + c.Log.Format = v + } + if v := os.Getenv("PROXY_COOLDOWN_DEFAULT"); v != "" { + c.Cooldown.Default = v + } + if v := os.Getenv("PROXY_CACHE_METADATA"); v != "" { + c.CacheMetadata = v == "true" || v == "1" + } + if v := os.Getenv("PROXY_MIRROR_API"); v != "" { + c.MirrorAPI = v == "true" || v == "1" + } + if v := os.Getenv("PROXY_METADATA_TTL"); v != "" { + c.MetadataTTL = v } - return nil } // Validate checks the configuration for errors. @@ -941,11 +340,6 @@ func (c *Config) Validate() error { if c.BaseURL == "" { return fmt.Errorf("base_url is required") } - if c.UIBaseURL == "" { - c.UIBaseURL = c.BaseURL - } else if err := validateAbsoluteURL("ui_base_url", c.UIBaseURL); err != nil { - return err - } if c.Storage.URL == "" && c.Storage.Path == "" { return fmt.Errorf("storage.url or storage.path is required") } @@ -985,20 +379,6 @@ func (c *Config) Validate() error { } } - // Validate direct serve TTL if specified - if c.Storage.DirectServeTTL != "" { - if _, err := time.ParseDuration(c.Storage.DirectServeTTL); err != nil { - return fmt.Errorf("invalid storage.direct_serve_ttl %q: %w", c.Storage.DirectServeTTL, err) - } - } - - // Validate direct serve base URL if specified - if c.Storage.DirectServeBaseURL != "" { - if err := validateAbsoluteURL("storage.direct_serve_base_url", c.Storage.DirectServeBaseURL); err != nil { - return err - } - } - // Validate metadata TTL if specified if c.MetadataTTL != "" && c.MetadataTTL != "0" { if _, err := time.ParseDuration(c.MetadataTTL); err != nil { @@ -1006,169 +386,10 @@ func (c *Config) Validate() error { } } - if err := validateMetadataMaxSize(c.MetadataMaxSize); err != nil { - return err - } - - if err := validateHTTPTimeout(c.HTTPTimeout); err != nil { - return err - } - - return c.validateComponents() -} - -func (c *Config) validateComponents() error { - if err := c.Upstream.Validate(); err != nil { - return err - } - - if err := c.Health.Validate(); err != nil { - return err - } - - if err := c.Scanning.Validate(); err != nil { - return err - } - - return c.Gradle.BuildCache.Validate() -} - -// Validate checks the /health configuration. An unset interval is allowed -// (the cache uses its default); explicit values must parse and be non-negative. -func (h *HealthConfig) Validate() error { - if h.StorageProbeInterval == "" || h.StorageProbeInterval == "0" { - return nil - } - d, err := time.ParseDuration(h.StorageProbeInterval) - if err != nil { - return fmt.Errorf("invalid health.storage_probe_interval %q: %w", h.StorageProbeInterval, err) - } - if d < 0 { - return fmt.Errorf("invalid health.storage_probe_interval %q: must be non-negative", h.StorageProbeInterval) - } return nil } -// Validate checks Gradle build cache settings, applying the default upload -// size if unset. -func (g *GradleBuildCacheConfig) Validate() error { - if g.MaxUploadSize == "" { - g.MaxUploadSize = defaultGradleMaxUploadSizeStr - } - uploadSize, err := ParseSize(g.MaxUploadSize) - if err != nil { - return fmt.Errorf("invalid gradle.build_cache.max_upload_size: %w", err) - } - if uploadSize <= 0 { - return fmt.Errorf("invalid gradle.build_cache.max_upload_size %q: must be > 0", g.MaxUploadSize) - } - - if g.MaxAge != "" && g.MaxAge != "0" { - if _, err := time.ParseDuration(g.MaxAge); err != nil { - return fmt.Errorf("invalid gradle.build_cache.max_age %q: %w", g.MaxAge, err) - } - } - - if g.MaxSize != "" { - if _, err := ParseSize(g.MaxSize); err != nil { - return fmt.Errorf("invalid gradle.build_cache.max_size: %w", err) - } - } - - if g.SweepInterval != "" { - d, err := time.ParseDuration(g.SweepInterval) - if err != nil { - return fmt.Errorf("invalid gradle.build_cache.sweep_interval %q: %w", g.SweepInterval, err) - } - if d <= 0 { - return fmt.Errorf("invalid gradle.build_cache.sweep_interval %q: must be > 0", g.SweepInterval) - } - } - - return nil -} - -const ( - defaultMetadataTTL = 5 * time.Minute //nolint:mnd // sensible default - defaultDirectServeTTL = 15 * time.Minute //nolint:mnd // sensible default - defaultHTTPTimeout = 30 * time.Second //nolint:mnd // sensible default - defaultMetadataMaxSize = 100 << 20 - defaultGradleBuildCacheMaxUploadSize = 100 << 20 - defaultGradleBuildCacheSweepInterval = 10 * time.Minute - defaultGradleMaxUploadSizeStr = "100MB" - defaultGradleSweepIntervalStr = "10m" - defaultScanningTimeoutStr = "30s" -) - -// ParseMaxSize returns the maximum cache size in bytes. -// Returns 0 if unset or explicitly disabled (meaning unlimited). -func (c *Config) ParseMaxSize() int64 { - if c.Storage.MaxSize == "" || c.Storage.MaxSize == "0" { - return 0 - } - size, err := ParseSize(c.Storage.MaxSize) - if err != nil { - return 0 - } - return size -} - -func validateHTTPTimeout(s string) error { - if s == "" || s == "0" { - return nil - } - d, err := time.ParseDuration(s) - if err != nil { - return fmt.Errorf("invalid http_timeout %q: %w", s, err) - } - if d < 0 { - return fmt.Errorf("invalid http_timeout %q: must be non-negative", s) - } - return nil -} - -func validateMetadataMaxSize(s string) error { - if s == "" { - return nil - } - size, err := ParseSize(s) - if err != nil { - return fmt.Errorf("invalid metadata_max_size: %w", err) - } - if size <= 0 { - return fmt.Errorf("invalid metadata_max_size %q: must be positive", s) - } - return nil -} - -// ParseMetadataMaxSize returns the maximum metadata response size in bytes. -// Returns 100MB if unset or invalid. -func (c *Config) ParseMetadataMaxSize() int64 { - if c.MetadataMaxSize == "" { - return defaultMetadataMaxSize - } - size, err := ParseSize(c.MetadataMaxSize) - if err != nil || size <= 0 { - return defaultMetadataMaxSize - } - return size -} - -// ParseHTTPTimeout returns the upstream HTTP client timeout. -// Returns 30s if unset, 0 (no timeout) if explicitly set to "0". -func (c *Config) ParseHTTPTimeout() time.Duration { - if c.HTTPTimeout == "" { - return defaultHTTPTimeout - } - if c.HTTPTimeout == "0" { - return 0 - } - d, err := time.ParseDuration(c.HTTPTimeout) - if err != nil || d < 0 { - return defaultHTTPTimeout - } - return d -} +const defaultMetadataTTL = 5 * time.Minute //nolint:mnd // sensible default // ParseMetadataTTL returns the metadata TTL duration. // Returns 5 minutes if unset, 0 if explicitly disabled. @@ -1186,71 +407,6 @@ func (c *Config) ParseMetadataTTL() time.Duration { return d } -// ParseGradleBuildCacheMaxUploadSize returns the max accepted PUT body size. -// Defaults to 100MB if unset or invalid. -func (c *Config) ParseGradleBuildCacheMaxUploadSize() int64 { - if c.Gradle.BuildCache.MaxUploadSize == "" { - return defaultGradleBuildCacheMaxUploadSize - } - size, err := ParseSize(c.Gradle.BuildCache.MaxUploadSize) - if err != nil || size <= 0 { - return defaultGradleBuildCacheMaxUploadSize - } - return size -} - -// ParseGradleBuildCacheMaxAge returns age-based eviction threshold. -// Returns 0 when disabled or invalid. -func (c *Config) ParseGradleBuildCacheMaxAge() time.Duration { - if c.Gradle.BuildCache.MaxAge == "" || c.Gradle.BuildCache.MaxAge == "0" { - return 0 - } - d, err := time.ParseDuration(c.Gradle.BuildCache.MaxAge) - if err != nil || d <= 0 { - return 0 - } - return d -} - -// ParseGradleBuildCacheMaxSize returns total-size cap in bytes. -// Returns 0 when disabled or invalid. -func (c *Config) ParseGradleBuildCacheMaxSize() int64 { - if c.Gradle.BuildCache.MaxSize == "" || c.Gradle.BuildCache.MaxSize == "0" { - return 0 - } - size, err := ParseSize(c.Gradle.BuildCache.MaxSize) - if err != nil || size <= 0 { - return 0 - } - return size -} - -// ParseGradleBuildCacheSweepInterval returns eviction sweep cadence. -// Defaults to 10m if unset or invalid. -func (c *Config) ParseGradleBuildCacheSweepInterval() time.Duration { - if c.Gradle.BuildCache.SweepInterval == "" { - return defaultGradleBuildCacheSweepInterval - } - d, err := time.ParseDuration(c.Gradle.BuildCache.SweepInterval) - if err != nil || d <= 0 { - return defaultGradleBuildCacheSweepInterval - } - return d -} - -// ParseDirectServeTTL returns the presigned URL expiry duration. -// Returns 15 minutes if unset. -func (c *Config) ParseDirectServeTTL() time.Duration { - if c.Storage.DirectServeTTL == "" { - return defaultDirectServeTTL - } - d, err := time.ParseDuration(c.Storage.DirectServeTTL) - if err != nil { - return defaultDirectServeTTL - } - return d -} - // ParseSize parses a human-readable size string (e.g., "10GB", "500MB"). // Returns the size in bytes. func ParseSize(s string) (int64, error) { @@ -1276,7 +432,8 @@ func ParseSize(s string) (int64, error) { } for _, s2 := range suffixes { - if numStr, ok := strings.CutSuffix(s, s2.suffix); ok { + if strings.HasSuffix(s, s2.suffix) { + numStr := strings.TrimSuffix(s, s2.suffix) num, err := strconv.ParseFloat(numStr, 64) if err != nil { return 0, fmt.Errorf("invalid number %q", numStr) @@ -1330,7 +487,3 @@ func (a *AuthConfig) Header() (name, value string) { func expandEnv(s string) string { return os.Expand(s, os.Getenv) } - -func envBool(v string) bool { - return v == "true" || v == "1" -} diff --git a/internal/config/config_test.go b/internal/config/config_test.go index 80fcc68..6e8c3a0 100644 --- a/internal/config/config_test.go +++ b/internal/config/config_test.go @@ -3,7 +3,6 @@ package config import ( "os" "path/filepath" - "strings" "testing" "time" ) @@ -14,109 +13,6 @@ const ( testLevelDebug = "debug" ) -func upstreamConfigValues(upstream UpstreamConfig) map[string]string { - return map[string]string{ - "npm": upstream.NPM, - "cargo": upstream.Cargo, - "cargo_download": upstream.CargoDownload, - "gem": upstream.Gem, - "go": upstream.Go, - "hex": upstream.Hex, - "hex_api": upstream.HexAPI, - "pub": upstream.Pub, - "pypi": upstream.PyPI, - "pypi_download": upstream.PyPIDownload, - "maven": upstream.Maven, - "gradle_plugin_portal": upstream.GradlePluginPortal, - "nuget": upstream.NuGet, - "nuget_search": upstream.NuGetSearch, - "composer": upstream.Composer, - "composer_repository": upstream.ComposerRepository, - "conan": upstream.Conan, - "conda": upstream.Conda, - "cran": upstream.CRAN, - "julia": upstream.Julia, - "swift": upstream.Swift, - "oci_default": upstream.OCIDefault, - "debian": upstream.Debian, - "rpm": upstream.RPM, - "homebrew_api": upstream.HomebrewAPI, - "homebrew_artifact": upstream.HomebrewArtifact, - } -} - -func defaultUpstreamValues() map[string]string { - return map[string]string{ - "npm": "https://registry.npmjs.org", - "cargo": "https://index.crates.io", - "cargo_download": "https://static.crates.io/crates", - "gem": "https://rubygems.org", - "go": "https://proxy.golang.org", - "hex": "https://repo.hex.pm", - "hex_api": "https://hex.pm", - "pub": "https://pub.dev", - "pypi": "https://pypi.org", - "pypi_download": "https://files.pythonhosted.org", - "maven": "https://repo1.maven.org/maven2", - "gradle_plugin_portal": "https://plugins.gradle.org/m2", - "nuget": "https://api.nuget.org", - "nuget_search": "https://azuresearch-usnc.nuget.org", - "composer": "https://packagist.org", - "composer_repository": "https://repo.packagist.org", - "conan": "https://center.conan.io", - "conda": "https://conda.anaconda.org", - "cran": "https://cloud.r-project.org", - "julia": "https://pkg.julialang.org", - "swift": "https://tuist.dev/api/registry/swift", - "oci_default": "https://registry-1.docker.io", - "debian": "http://deb.debian.org/debian", - "rpm": "https://dl.fedoraproject.org/pub/fedora/linux", - "homebrew_api": "https://formulae.brew.sh/api", - "homebrew_artifact": "https://ghcr.io", - } -} - -func upstreamEnvironmentVariables() map[string]string { - return map[string]string{ - "npm": "PROXY_UPSTREAM_NPM", - "cargo": "PROXY_UPSTREAM_CARGO", - "cargo_download": "PROXY_UPSTREAM_CARGO_DOWNLOAD", - "gem": "PROXY_UPSTREAM_GEM", - "go": "PROXY_UPSTREAM_GO", - "hex": "PROXY_UPSTREAM_HEX", - "hex_api": "PROXY_UPSTREAM_HEX_API", - "pub": "PROXY_UPSTREAM_PUB", - "pypi": "PROXY_UPSTREAM_PYPI", - "pypi_download": "PROXY_UPSTREAM_PYPI_DOWNLOAD", - "maven": "PROXY_UPSTREAM_MAVEN", - "gradle_plugin_portal": "PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL", - "nuget": "PROXY_UPSTREAM_NUGET", - "nuget_search": "PROXY_UPSTREAM_NUGET_SEARCH", - "composer": "PROXY_UPSTREAM_COMPOSER", - "composer_repository": "PROXY_UPSTREAM_COMPOSER_REPOSITORY", - "conan": "PROXY_UPSTREAM_CONAN", - "conda": "PROXY_UPSTREAM_CONDA", - "cran": "PROXY_UPSTREAM_CRAN", - "julia": "PROXY_UPSTREAM_JULIA", - "swift": "PROXY_UPSTREAM_SWIFT", - "oci_default": "PROXY_UPSTREAM_OCI_DEFAULT", - "debian": "PROXY_UPSTREAM_DEBIAN", - "rpm": "PROXY_UPSTREAM_RPM", - "homebrew_api": "PROXY_UPSTREAM_HOMEBREW_API", - "homebrew_artifact": "PROXY_UPSTREAM_HOMEBREW_ARTIFACT", - } -} - -func assertUpstreamValues(t *testing.T, cfg *Config, want map[string]string) { - t.Helper() - got := upstreamConfigValues(cfg.Upstream) - for name, wantValue := range want { - if gotValue := got[name]; gotValue != wantValue { - t.Errorf("Upstream %s = %q, want %q", name, gotValue, wantValue) - } - } -} - func TestDefault(t *testing.T) { cfg := Default() @@ -129,22 +25,6 @@ func TestDefault(t *testing.T) { if cfg.Database.Path == "" { t.Error("Database.Path should not be empty") } - if cfg.AccessLog.Path != "" { - t.Errorf("AccessLog.Path = %q, want disabled by default", cfg.AccessLog.Path) - } - if cfg.Gradle.BuildCache.MaxUploadSize != "100MB" { - t.Errorf("Gradle.BuildCache.MaxUploadSize = %q, want %q", cfg.Gradle.BuildCache.MaxUploadSize, "100MB") - } - if cfg.Gradle.BuildCache.MaxAge != "168h" { - t.Errorf("Gradle.BuildCache.MaxAge = %q, want %q", cfg.Gradle.BuildCache.MaxAge, "168h") - } - if len(cfg.Upstream.AllowPrivateHosts) != 0 { - t.Errorf("Upstream.AllowPrivateHosts = %v, want empty", cfg.Upstream.AllowPrivateHosts) - } - if cfg.Upstream.AllowLoopback { - t.Error("Upstream.AllowLoopback = true, want false") - } - assertUpstreamValues(t, cfg, defaultUpstreamValues()) } func TestValidate(t *testing.T) { @@ -218,41 +98,6 @@ func TestValidate(t *testing.T) { modify: func(c *Config) { c.Storage.MaxSize = "10GB" }, wantErr: false, }, - { - name: "invalid gradle upload size", - modify: func(c *Config) { c.Gradle.BuildCache.MaxUploadSize = testInvalid }, - wantErr: true, - }, - { - name: "zero gradle upload size", - modify: func(c *Config) { c.Gradle.BuildCache.MaxUploadSize = "0" }, - wantErr: true, - }, - { - name: "invalid gradle max age", - modify: func(c *Config) { c.Gradle.BuildCache.MaxAge = testInvalid }, - wantErr: true, - }, - { - name: "valid gradle max age", - modify: func(c *Config) { c.Gradle.BuildCache.MaxAge = "24h" }, - wantErr: false, - }, - { - name: "invalid gradle max size", - modify: func(c *Config) { c.Gradle.BuildCache.MaxSize = testInvalid }, - wantErr: true, - }, - { - name: "invalid gradle sweep interval", - modify: func(c *Config) { c.Gradle.BuildCache.SweepInterval = "0" }, - wantErr: true, - }, - { - name: "valid gradle sweep interval", - modify: func(c *Config) { c.Gradle.BuildCache.SweepInterval = "30m" }, - wantErr: false, - }, } for _, tt := range tests { @@ -316,11 +161,6 @@ database: log: level: "debug" format: "json" -access_log: - path: "/var/log/proxy/access.jsonl" -upstream: - homebrew_api: "https://homebrew-api.example.com" - homebrew_artifact: "https://homebrew-artifact.example.com" ` if err := os.WriteFile(path, []byte(content), 0644); err != nil { t.Fatalf("writing config file: %v", err) @@ -349,72 +189,6 @@ upstream: if cfg.Log.Format != "json" { t.Errorf("Log.Format = %q, want %q", cfg.Log.Format, "json") } - if cfg.AccessLog.Path != "/var/log/proxy/access.jsonl" { - t.Errorf("AccessLog.Path = %q, want %q", cfg.AccessLog.Path, "/var/log/proxy/access.jsonl") - } - if cfg.Upstream.HomebrewAPI != "https://homebrew-api.example.com" { - t.Errorf("Upstream.HomebrewAPI = %q, want %q", cfg.Upstream.HomebrewAPI, "https://homebrew-api.example.com") - } - if cfg.Upstream.HomebrewArtifact != "https://homebrew-artifact.example.com" { - t.Errorf("Upstream.HomebrewArtifact = %q, want %q", cfg.Upstream.HomebrewArtifact, "https://homebrew-artifact.example.com") - } -} - -func TestLoadYAMLUpstreams(t *testing.T) { - path := filepath.Join(t.TempDir(), "config.yaml") - content := ` -upstream: - allow_private_hosts: - - "registry.internal" - - "10.0.0.12" - allow_loopback: true - npm: "https://upstream.example.com/npm" - cargo: "https://upstream.example.com/cargo" - cargo_download: "https://upstream.example.com/cargo_download" - gem: "https://upstream.example.com/gem" - go: "https://upstream.example.com/go" - hex: "https://upstream.example.com/hex" - hex_api: "https://upstream.example.com/hex_api" - pub: "https://upstream.example.com/pub" - pypi: "https://upstream.example.com/pypi" - pypi_download: "https://upstream.example.com/pypi_download" - maven: "https://upstream.example.com/maven" - gradle_plugin_portal: "https://upstream.example.com/gradle_plugin_portal" - nuget: "https://upstream.example.com/nuget" - nuget_search: "https://upstream.example.com/nuget_search" - composer: "https://upstream.example.com/composer" - composer_repository: "https://upstream.example.com/composer_repository" - conan: "https://upstream.example.com/conan" - conda: "https://upstream.example.com/conda" - cran: "https://upstream.example.com/cran" - julia: "https://upstream.example.com/julia" - swift: "https://upstream.example.com/swift" - oci_default: "https://upstream.example.com/oci_default" - debian: "https://upstream.example.com/debian" - rpm: "https://upstream.example.com/rpm" - homebrew_api: "https://upstream.example.com/homebrew_api" - homebrew_artifact: "https://upstream.example.com/homebrew_artifact" -` - if err := os.WriteFile(path, []byte(content), 0644); err != nil { - t.Fatalf("writing config file: %v", err) - } - - cfg, err := Load(path) - if err != nil { - t.Fatalf("Load failed: %v", err) - } - - want := make(map[string]string) - for name := range defaultUpstreamValues() { - want[name] = "https://upstream.example.com/" + name - } - assertUpstreamValues(t, cfg, want) - if got := strings.Join(cfg.Upstream.AllowPrivateHosts, ","); got != "registry.internal,10.0.0.12" { - t.Errorf("Upstream.AllowPrivateHosts = %q, want %q", got, "registry.internal,10.0.0.12") - } - if !cfg.Upstream.AllowLoopback { - t.Error("Upstream.AllowLoopback = false, want true") - } } func TestLoadJSON(t *testing.T) { @@ -423,11 +197,7 @@ func TestLoadJSON(t *testing.T) { content := `{ "listen": ":4000", - "base_url": "https://json.example.com", - "upstream": { - "gem": "https://json.example.com/gem", - "rpm": "https://json.example.com/rpm" - } + "base_url": "https://json.example.com" }` if err := os.WriteFile(path, []byte(content), 0644); err != nil { t.Fatalf("writing config file: %v", err) @@ -444,12 +214,6 @@ func TestLoadJSON(t *testing.T) { if cfg.BaseURL != "https://json.example.com" { t.Errorf("BaseURL = %q, want %q", cfg.BaseURL, "https://json.example.com") } - if cfg.Upstream.Gem != "https://json.example.com/gem" { - t.Errorf("Upstream.Gem = %q, want %q", cfg.Upstream.Gem, "https://json.example.com/gem") - } - if cfg.Upstream.RPM != "https://json.example.com/rpm" { - t.Errorf("Upstream.RPM = %q, want %q", cfg.Upstream.RPM, "https://json.example.com/rpm") - } } func TestLoadFromEnv(t *testing.T) { @@ -457,17 +221,8 @@ func TestLoadFromEnv(t *testing.T) { t.Setenv("PROXY_LISTEN", ":9000") t.Setenv("PROXY_BASE_URL", "https://env.example.com") - t.Setenv("PROXY_UI_URL", "https://ui.env.example.com/ui") t.Setenv("PROXY_STORAGE_PATH", "/env/cache") t.Setenv("PROXY_LOG_LEVEL", testLevelDebug) - t.Setenv("PROXY_ACCESS_LOG_PATH", "/tmp/proxy-access.jsonl") - t.Setenv("PROXY_UPSTREAM_ALLOW_PRIVATE_HOSTS", "registry.internal, 10.0.0.12") - t.Setenv("PROXY_UPSTREAM_ALLOW_LOOPBACK", "true") - t.Setenv("PROXY_GRADLE_BUILD_CACHE_READ_ONLY", "true") - t.Setenv("PROXY_GRADLE_BUILD_CACHE_MAX_UPLOAD_SIZE", "32MB") - t.Setenv("PROXY_GRADLE_BUILD_CACHE_MAX_AGE", "12h") - t.Setenv("PROXY_GRADLE_BUILD_CACHE_MAX_SIZE", "10GB") - t.Setenv("PROXY_GRADLE_BUILD_CACHE_SWEEP_INTERVAL", "15m") cfg.LoadFromEnv() @@ -477,59 +232,12 @@ func TestLoadFromEnv(t *testing.T) { if cfg.BaseURL != "https://env.example.com" { t.Errorf("BaseURL = %q, want %q", cfg.BaseURL, "https://env.example.com") } - if cfg.UIBaseURL != "https://ui.env.example.com/ui" { - t.Errorf("UIBaseURL = %q, want %q", cfg.UIBaseURL, "https://ui.env.example.com/ui") - } if cfg.Storage.Path != "/env/cache" { t.Errorf("Storage.Path = %q, want %q", cfg.Storage.Path, "/env/cache") } if cfg.Log.Level != testLevelDebug { t.Errorf("Log.Level = %q, want %q", cfg.Log.Level, testLevelDebug) } - if cfg.AccessLog.Path != "/tmp/proxy-access.jsonl" { - t.Errorf("AccessLog.Path = %q, want %q", cfg.AccessLog.Path, "/tmp/proxy-access.jsonl") - } - if got := strings.Join(cfg.Upstream.AllowPrivateHosts, ","); got != "registry.internal,10.0.0.12" { - t.Errorf("Upstream.AllowPrivateHosts = %q, want %q", got, "registry.internal,10.0.0.12") - } - if !cfg.Upstream.AllowLoopback { - t.Error("Upstream.AllowLoopback = false, want true") - } - - t.Setenv("PROXY_UPSTREAM_ALLOW_PRIVATE_HOSTS", " , ") - cfg.LoadFromEnv() - if got := strings.Join(cfg.Upstream.AllowPrivateHosts, ","); got != "registry.internal,10.0.0.12" { - t.Errorf("Upstream.AllowPrivateHosts after empty env = %q, want unchanged", got) - } - - if !cfg.Gradle.BuildCache.ReadOnly { - t.Error("Gradle.BuildCache.ReadOnly = false, want true") - } - if cfg.Gradle.BuildCache.MaxUploadSize != "32MB" { - t.Errorf("Gradle.BuildCache.MaxUploadSize = %q, want %q", cfg.Gradle.BuildCache.MaxUploadSize, "32MB") - } - if cfg.Gradle.BuildCache.MaxAge != "12h" { - t.Errorf("Gradle.BuildCache.MaxAge = %q, want %q", cfg.Gradle.BuildCache.MaxAge, "12h") - } - if cfg.Gradle.BuildCache.MaxSize != "10GB" { - t.Errorf("Gradle.BuildCache.MaxSize = %q, want %q", cfg.Gradle.BuildCache.MaxSize, "10GB") - } - if cfg.Gradle.BuildCache.SweepInterval != "15m" { - t.Errorf("Gradle.BuildCache.SweepInterval = %q, want %q", cfg.Gradle.BuildCache.SweepInterval, "15m") - } -} - -func TestLoadFromEnvUpstreams(t *testing.T) { - cfg := Default() - want := make(map[string]string) - for name, envName := range upstreamEnvironmentVariables() { - value := "https://env.example.com/" + name - t.Setenv(envName, value) - want[name] = value - } - - cfg.LoadFromEnv() - assertUpstreamValues(t, cfg, want) } func TestLoadCooldownConfig(t *testing.T) { @@ -576,34 +284,6 @@ cooldown: if cfg.Cooldown.Packages["pkg:npm/@babel/core"] != "14d" { t.Errorf("Cooldown.Packages[@babel/core] = %q, want %q", cfg.Cooldown.Packages["pkg:npm/@babel/core"], "14d") } - if got := cfg.Cooldown.NormalizedPackages()["pkg:npm/%40babel/core"]; got != "14d" { - t.Errorf("normalized Cooldown.Packages[@babel/core] = %q, want %q", got, "14d") - } -} - -func TestCooldownConfigNormalizedPackages(t *testing.T) { - rawScoped := "pkg:npm/@typescript/typescript-darwin-arm64" - canonicalScoped := "pkg:npm/%40typescript/typescript-darwin-arm64" - cfg := CooldownConfig{Packages: map[string]string{ - rawScoped: "2d", - canonicalScoped: "3d", - "not-a-purl": "4d", - }} - - got := cfg.NormalizedPackages() - - if got[canonicalScoped] != "3d" { - t.Errorf("canonical scoped package duration = %q, want %q", got[canonicalScoped], "3d") - } - if _, exists := got[rawScoped]; exists { - t.Errorf("raw scoped package key %q was not canonicalized", rawScoped) - } - if got["not-a-purl"] != "4d" { - t.Errorf("invalid PURL duration = %q, want preserved value %q", got["not-a-purl"], "4d") - } - if cfg.Packages[rawScoped] != "2d" { - t.Error("NormalizedPackages mutated the source map") - } } func TestLoadCooldownFromEnv(t *testing.T) { @@ -623,31 +303,6 @@ func TestLoadFileNotFound(t *testing.T) { } } -func TestParseMaxSize(t *testing.T) { - tests := []struct { - name string - maxSize string - want int64 - }{ - {"empty means unlimited", "", 0}, - {"zero means unlimited", "0", 0}, - {"10GB", "10GB", 10 * 1024 * 1024 * 1024}, - {"500MB", "500MB", 500 * 1024 * 1024}, - {"invalid returns 0", "invalid", 0}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - cfg := Default() - cfg.Storage.MaxSize = tt.maxSize - got := cfg.ParseMaxSize() - if got != tt.want { - t.Errorf("ParseMaxSize() = %d, want %d", got, tt.want) - } - }) - } -} - func TestParseMetadataTTL(t *testing.T) { tests := []struct { name string @@ -673,52 +328,6 @@ func TestParseMetadataTTL(t *testing.T) { } } -func TestParseMetadataMaxSize(t *testing.T) { - tests := []struct { - name string - size string - want int64 - }{ - {"unset uses default", "", defaultMetadataMaxSize}, - {"explicit value", "250MB", 250 << 20}, - {"bytes", "1024", 1024}, - {"invalid uses default", "lots", defaultMetadataMaxSize}, - } - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - cfg := Default() - cfg.MetadataMaxSize = tt.size - got := cfg.ParseMetadataMaxSize() - if got != tt.want { - t.Errorf("ParseMetadataMaxSize() = %d, want %d", got, tt.want) - } - }) - } -} - -func TestValidateMetadataMaxSize(t *testing.T) { - cfg := Default() - cfg.MetadataMaxSize = "not-a-size" - if err := cfg.Validate(); err == nil { - t.Error("expected validation error for invalid metadata_max_size") - } - - cfg.MetadataMaxSize = "0" - if err := cfg.Validate(); err == nil { - t.Error("expected validation error for zero metadata_max_size") - } - - cfg.MetadataMaxSize = "250MB" - if err := cfg.Validate(); err != nil { - t.Errorf("unexpected error for valid metadata_max_size: %v", err) - } - - cfg.MetadataMaxSize = "" - if err := cfg.Validate(); err != nil { - t.Errorf("unexpected error for unset metadata_max_size: %v", err) - } -} - func TestValidateMetadataTTL(t *testing.T) { cfg := Default() cfg.MetadataTTL = "invalid" @@ -737,208 +346,6 @@ func TestValidateMetadataTTL(t *testing.T) { } } -func TestValidateHealthStorageProbeInterval(t *testing.T) { - cfg := Default() - cfg.Health.StorageProbeInterval = "not-a-duration" - if err := cfg.Validate(); err == nil { - t.Error("expected validation error for invalid health.storage_probe_interval") - } - - cfg.Health.StorageProbeInterval = "30s" - if err := cfg.Validate(); err != nil { - t.Errorf("unexpected error for valid health.storage_probe_interval: %v", err) - } - - cfg.Health.StorageProbeInterval = "0" - if err := cfg.Validate(); err != nil { - t.Errorf("unexpected error for zero health.storage_probe_interval: %v", err) - } - - cfg.Health.StorageProbeInterval = "" - if err := cfg.Validate(); err != nil { - t.Errorf("unexpected error for empty health.storage_probe_interval: %v", err) - } - - cfg.Health.StorageProbeInterval = "-5s" - if err := cfg.Validate(); err == nil { - t.Error("expected validation error for negative health.storage_probe_interval") - } -} - -func TestScanningConfigValidate(t *testing.T) { - tests := []struct { - name string - cfg ScanningConfig - wantErr bool - }{ - { - name: "disabled skips validation entirely", - cfg: ScanningConfig{Enabled: false, Timeout: "not-a-duration"}, - }, - { - name: "enabled without signing key fails", - cfg: ScanningConfig{Enabled: true}, - wantErr: true, - }, - { - name: "enabled with signing key and no scanners fails", - cfg: ScanningConfig{Enabled: true, SigningKey: "s3cret"}, - wantErr: true, - }, - { - name: "invalid fetch_base_url fails", - cfg: ScanningConfig{ - Enabled: true, - SigningKey: "s3cret", - FetchBaseURL: "not-a-url", - Scanners: []ScannerConfig{{Name: "clamav", URL: "http://scanner.invalid/scan"}}, - }, - wantErr: true, - }, - { - name: "invalid timeout fails", - cfg: ScanningConfig{ - Enabled: true, - SigningKey: "s3cret", - Timeout: "not-a-duration", - Scanners: []ScannerConfig{{Name: "clamav", URL: "http://scanner.invalid/scan"}}, - }, - wantErr: true, - }, - { - name: "zero timeout fails", - cfg: ScanningConfig{ - Enabled: true, - SigningKey: "s3cret", - Timeout: "0", - Scanners: []ScannerConfig{{Name: "clamav", URL: "http://scanner.invalid/scan"}}, - }, - wantErr: true, - }, - { - name: "empty timeout defaults and is valid", - cfg: ScanningConfig{ - Enabled: true, - SigningKey: "s3cret", - Timeout: "", - Scanners: []ScannerConfig{{Name: "clamav", URL: "http://scanner.invalid/scan"}}, - }, - }, - { - name: "scanner missing name fails", - cfg: ScanningConfig{ - Enabled: true, - SigningKey: "s3cret", - Scanners: []ScannerConfig{{URL: "http://scanner.invalid/scan"}}, - }, - wantErr: true, - }, - { - name: "scanner with invalid url fails", - cfg: ScanningConfig{ - Enabled: true, - SigningKey: "s3cret", - Scanners: []ScannerConfig{{Name: "clamav", URL: "not-a-url"}}, - }, - wantErr: true, - }, - { - name: "scanner with invalid mode fails", - cfg: ScanningConfig{ - Enabled: true, - SigningKey: "s3cret", - Scanners: []ScannerConfig{ - {Name: "clamav", URL: "http://scanner.invalid/scan", Mode: "quarantine"}, - }, - }, - wantErr: true, - }, - { - name: "scanner with default mode is valid", - cfg: ScanningConfig{ - Enabled: true, - SigningKey: "s3cret", - Scanners: []ScannerConfig{{Name: "clamav", URL: "http://scanner.invalid/scan"}}, - }, - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - err := tt.cfg.Validate() - if tt.wantErr && err == nil { - t.Error("Validate() error = nil, want error") - } - if !tt.wantErr && err != nil { - t.Errorf("Validate() unexpected error: %v", err) - } - }) - } -} - -func TestParseHTTPTimeout(t *testing.T) { - tests := []struct { - name string - timeout string - want time.Duration - }{ - {"empty defaults to 30s", "", 30 * time.Second}, - {"explicit zero disables", "0", 0}, - {"2 minutes", "2m", 2 * time.Minute}, - {"90 seconds", "90s", 90 * time.Second}, - {"invalid defaults to 30s", "not-a-duration", 30 * time.Second}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - cfg := Default() - cfg.HTTPTimeout = tt.timeout - got := cfg.ParseHTTPTimeout() - if got != tt.want { - t.Errorf("ParseHTTPTimeout() = %v, want %v", got, tt.want) - } - }) - } -} - -func TestValidateHTTPTimeout(t *testing.T) { - cfg := Default() - cfg.HTTPTimeout = "not-a-duration" - if err := cfg.Validate(); err == nil { - t.Error("expected validation error for invalid http_timeout") - } - - cfg.HTTPTimeout = "-5s" - if err := cfg.Validate(); err == nil { - t.Error("expected validation error for negative http_timeout") - } - - cfg.HTTPTimeout = "2m" - if err := cfg.Validate(); err != nil { - t.Errorf("unexpected error for valid http_timeout: %v", err) - } - - cfg.HTTPTimeout = "0" - if err := cfg.Validate(); err != nil { - t.Errorf("unexpected error for zero http_timeout: %v", err) - } - - cfg.HTTPTimeout = "" - if err := cfg.Validate(); err != nil { - t.Errorf("unexpected error for empty http_timeout: %v", err) - } -} - -func TestLoadHTTPTimeoutFromEnv(t *testing.T) { - cfg := Default() - t.Setenv("PROXY_HTTP_TIMEOUT", "90s") - cfg.LoadFromEnv() - - if cfg.HTTPTimeout != "90s" { - t.Errorf("HTTPTimeout = %q, want %q", cfg.HTTPTimeout, "90s") - } -} - func TestLoadMetadataTTLFromEnv(t *testing.T) { cfg := Default() t.Setenv("PROXY_METADATA_TTL", "10m") @@ -948,311 +355,3 @@ func TestLoadMetadataTTLFromEnv(t *testing.T) { t.Errorf("MetadataTTL = %q, want %q", cfg.MetadataTTL, "10m") } } - -func TestParseGradleBuildCacheConfig(t *testing.T) { - cfg := Default() - - if got := cfg.ParseGradleBuildCacheMaxUploadSize(); got != 100*1024*1024 { - t.Errorf("ParseGradleBuildCacheMaxUploadSize() = %d, want %d", got, 100*1024*1024) - } - if got := cfg.ParseGradleBuildCacheMaxAge(); got != 168*time.Hour { - t.Errorf("ParseGradleBuildCacheMaxAge() = %v, want %v", got, 168*time.Hour) - } - if got := cfg.ParseGradleBuildCacheMaxSize(); got != 0 { - t.Errorf("ParseGradleBuildCacheMaxSize() = %d, want 0", got) - } - if got := cfg.ParseGradleBuildCacheSweepInterval(); got != 10*time.Minute { - t.Errorf("ParseGradleBuildCacheSweepInterval() = %v, want %v", got, 10*time.Minute) - } - - cfg.Gradle.BuildCache.MaxUploadSize = "64MB" - cfg.Gradle.BuildCache.MaxAge = "48h" - cfg.Gradle.BuildCache.MaxSize = "2GB" - cfg.Gradle.BuildCache.SweepInterval = "20m" - - if got := cfg.ParseGradleBuildCacheMaxUploadSize(); got != 64*1024*1024 { - t.Errorf("ParseGradleBuildCacheMaxUploadSize() = %d, want %d", got, 64*1024*1024) - } - if got := cfg.ParseGradleBuildCacheMaxAge(); got != 48*time.Hour { - t.Errorf("ParseGradleBuildCacheMaxAge() = %v, want %v", got, 48*time.Hour) - } - if got := cfg.ParseGradleBuildCacheMaxSize(); got != 2*1024*1024*1024 { - t.Errorf("ParseGradleBuildCacheMaxSize() = %d, want %d", got, 2*1024*1024*1024) - } - if got := cfg.ParseGradleBuildCacheSweepInterval(); got != 20*time.Minute { - t.Errorf("ParseGradleBuildCacheSweepInterval() = %v, want %v", got, 20*time.Minute) - } -} - -func TestParseDirectServeTTL(t *testing.T) { - tests := []struct { - name string - ttl string - want time.Duration - }{ - {"empty defaults to 15m", "", 15 * time.Minute}, - {"5 minutes", "5m", 5 * time.Minute}, - {"1 hour", "1h", 1 * time.Hour}, - {"invalid defaults to 15m", "not-a-duration", 15 * time.Minute}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - cfg := Default() - cfg.Storage.DirectServeTTL = tt.ttl - got := cfg.ParseDirectServeTTL() - if got != tt.want { - t.Errorf("ParseDirectServeTTL() = %v, want %v", got, tt.want) - } - }) - } -} - -func TestValidateDirectServeTTL(t *testing.T) { - cfg := Default() - cfg.Storage.DirectServeTTL = "invalid" - if err := cfg.Validate(); err == nil { - t.Error("expected validation error for invalid storage.direct_serve_ttl") - } - - cfg.Storage.DirectServeTTL = "5m" - if err := cfg.Validate(); err != nil { - t.Errorf("unexpected error for valid storage.direct_serve_ttl: %v", err) - } -} - -func TestLoadDirectServeFromEnv(t *testing.T) { - cfg := Default() - t.Setenv("PROXY_STORAGE_DIRECT_SERVE", "true") - t.Setenv("PROXY_STORAGE_DIRECT_SERVE_TTL", "30m") - t.Setenv("PROXY_STORAGE_DIRECT_SERVE_BASE_URL", "https://cdn.example.com") - cfg.LoadFromEnv() - - if !cfg.Storage.DirectServe { - t.Error("Storage.DirectServe should be true") - } - if cfg.Storage.DirectServeTTL != "30m" { - t.Errorf("Storage.DirectServeTTL = %q, want %q", cfg.Storage.DirectServeTTL, "30m") - } - if cfg.Storage.DirectServeBaseURL != "https://cdn.example.com" { - t.Errorf("Storage.DirectServeBaseURL = %q, want %q", cfg.Storage.DirectServeBaseURL, "https://cdn.example.com") - } -} - -func TestValidateUIBaseURLDefaultsToBaseURL(t *testing.T) { - cfg := Default() - cfg.BaseURL = "https://proxy.example.com" - cfg.UIBaseURL = "" - - if err := cfg.Validate(); err != nil { - t.Fatalf("unexpected validation error: %v", err) - } - if cfg.UIBaseURL != "https://proxy.example.com" { - t.Errorf("UIBaseURL = %q, want it to default to BaseURL %q", cfg.UIBaseURL, "https://proxy.example.com") - } -} - -func TestValidateUIBaseURL(t *testing.T) { - cfg := Default() - - cfg.UIBaseURL = "not a url" - if err := cfg.Validate(); err == nil { - t.Error("expected validation error for relative ui_base_url") - } - - cfg = Default() - cfg.UIBaseURL = "://bad" - if err := cfg.Validate(); err == nil { - t.Error("expected validation error for unparseable ui_base_url") - } - - cfg = Default() - cfg.UIBaseURL = "https://ui.example.com/ui" - if err := cfg.Validate(); err != nil { - t.Errorf("unexpected error for valid ui_base_url: %v", err) - } -} - -func TestValidateDirectServeBaseURL(t *testing.T) { - cfg := Default() - - cfg.Storage.DirectServeBaseURL = "not a url" - if err := cfg.Validate(); err == nil { - t.Error("expected validation error for relative direct_serve_base_url") - } - - cfg.Storage.DirectServeBaseURL = "://bad" - if err := cfg.Validate(); err == nil { - t.Error("expected validation error for unparseable direct_serve_base_url") - } - - cfg.Storage.DirectServeBaseURL = "https://cdn.example.com" - if err := cfg.Validate(); err != nil { - t.Errorf("unexpected error for valid direct_serve_base_url: %v", err) - } -} - -func TestDatabaseConfigString(t *testing.T) { - tests := []struct { - name string - cfg DatabaseConfig - want string - }{ - {"sqlite", DatabaseConfig{Driver: "sqlite", Path: "./cache/proxy.db"}, "./cache/proxy.db"}, - {"default driver", DatabaseConfig{Path: "/var/lib/proxy.db"}, "/var/lib/proxy.db"}, - {"postgres no password", DatabaseConfig{Driver: "postgres", URL: "postgres://user@localhost:5432/proxy"}, "postgres://user@localhost:5432/proxy"}, - {"postgres redacts password", DatabaseConfig{Driver: "postgres", URL: "postgres://user:secret@localhost:5432/proxy?sslmode=disable"}, "postgres://user:xxxxx@localhost:5432/proxy?sslmode=disable"}, - {"postgres unparseable url", DatabaseConfig{Driver: "postgres", URL: "host=localhost user=foo password=bar"}, "postgres"}, - {"postgres ignores sqlite path", DatabaseConfig{Driver: "postgres", URL: "postgres://localhost/db", Path: "./cache/proxy.db"}, "postgres://localhost/db"}, - } - - for _, tt := range tests { - if got := tt.cfg.String(); got != tt.want { - t.Errorf("%s: String() = %q, want %q", tt.name, got, tt.want) - } - } -} - -func TestUpstreamAuthForURLMatchesURLComponents(t *testing.T) { - registryAuth := AuthConfig{Type: "bearer", Token: "registry-token"} - privateAuth := AuthConfig{Type: "bearer", Token: "private-token"} - config := UpstreamConfig{Auth: map[string]AuthConfig{ - "https://registry.example.com": registryAuth, - "https://registry.example.com/private": privateAuth, - }} - - tests := []struct { - name string - url string - wantToken string - }{ - {name: "registry root", url: "https://registry.example.com/package", wantToken: "registry-token"}, - {name: "host is case insensitive", url: "https://REGISTRY.EXAMPLE.COM/package", wantToken: "registry-token"}, - {name: "longest path match", url: "https://registry.example.com/private/package", wantToken: "private-token"}, - {name: "exact path match", url: "https://registry.example.com/private", wantToken: "private-token"}, - {name: "path segment boundary", url: "https://registry.example.com/private-other/package", wantToken: "registry-token"}, - {name: "lookalike host rejected", url: "https://registry.example.com.evil.test/package"}, - {name: "different scheme rejected", url: "http://registry.example.com/package"}, - {name: "different port rejected", url: "https://registry.example.com:8443/package"}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - auth := config.AuthForURL(tt.url) - if tt.wantToken == "" { - if auth != nil { - t.Fatalf("AuthForURL() = %+v, want nil", auth) - } - return - } - if auth == nil { - t.Fatal("AuthForURL() = nil, want authentication") - } - if auth.Token != tt.wantToken { - t.Errorf("token = %q, want %q", auth.Token, tt.wantToken) - } - }) - } -} - -func TestValidateUpstreamAuthURLs(t *testing.T) { - t.Run("valid absolute URL", func(t *testing.T) { - cfg := Default() - cfg.Upstream.Auth = map[string]AuthConfig{ - "https://registry.example.com/private": {Type: "bearer", Token: "token"}, - } - - if err := cfg.Validate(); err != nil { - t.Fatalf("Validate() error = %v", err) - } - }) - - t.Run("invalid URL", func(t *testing.T) { - cfg := Default() - cfg.Upstream.Auth = map[string]AuthConfig{ - "registry.example.com": {Type: "bearer", Token: "token"}, - } - - err := cfg.Validate() - if err == nil { - t.Fatal("Validate() error = nil, want invalid upstream.auth URL error") - } - if !strings.Contains(err.Error(), "upstream.auth") || !strings.Contains(err.Error(), "registry.example.com") { - t.Errorf("Validate() error = %q, want field and URL", err) - } - }) -} - -func TestValidateNamedUpstreams(t *testing.T) { - tests := []struct { - name string - modify func(*Config) - wantErr bool - }{ - { - name: "valid Helm, OCI, APK, and generic upstreams", - modify: func(cfg *Config) { - cfg.Upstream.Helm = map[string]string{"bitnami": "https://charts.bitnami.com/bitnami"} - cfg.Upstream.OCI = map[string]string{"ghcr": "https://ghcr.io"} - cfg.Upstream.APK = map[string]string{"alpine": "https://dl-cdn.alpinelinux.org/alpine"} - cfg.Upstream.Generic = map[string]string{ - "github": "https://github.com", - "github-api": "https://api.github.com", - } - }, - }, - { - name: "generic upstream name contains path separator", - modify: func(cfg *Config) { - cfg.Upstream.Generic = map[string]string{"github/releases": "https://github.com"} - }, - wantErr: true, - }, - { - name: "generic upstream URL is not absolute", - modify: func(cfg *Config) { - cfg.Upstream.Generic = map[string]string{"github": "github.com"} - }, - wantErr: true, - }, - { - name: "Helm upstream name contains path separator", - modify: func(cfg *Config) { - cfg.Upstream.Helm = map[string]string{"team/charts": "https://charts.example.com"} - }, - wantErr: true, - }, - { - name: "OCI upstream URL is not absolute", - modify: func(cfg *Config) { - cfg.Upstream.OCI = map[string]string{"private": "registry.example.com"} - }, - wantErr: true, - }, - { - name: "APK upstream name contains path separator", - modify: func(cfg *Config) { - cfg.Upstream.APK = map[string]string{"alpine/edge": "https://dl-cdn.alpinelinux.org/alpine"} - }, - wantErr: true, - }, - { - name: "APK upstream URL is not absolute", - modify: func(cfg *Config) { - cfg.Upstream.APK = map[string]string{"private": "apk.example.com"} - }, - wantErr: true, - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - cfg := Default() - tt.modify(cfg) - err := cfg.Validate() - if (err != nil) != tt.wantErr { - t.Errorf("Validate() error = %v, wantErr %t", err, tt.wantErr) - } - }) - } -} diff --git a/internal/cooldown/cooldown.go b/internal/cooldown/cooldown.go new file mode 100644 index 0000000..f37a2b9 --- /dev/null +++ b/internal/cooldown/cooldown.go @@ -0,0 +1,125 @@ +package cooldown + +import ( + "fmt" + "strconv" + "strings" + "time" +) + +const hoursPerDay = 24 + +// Config holds cooldown settings for version filtering. +// Cooldown hides package versions published too recently, giving the community +// time to spot malicious releases before they're pulled into projects. +type Config struct { + // Default is the global default cooldown duration (e.g., "3d", "48h"). + Default string `json:"default" yaml:"default"` + + // Ecosystems overrides the default for specific ecosystems. + // Keys are ecosystem names (e.g., "npm", "pypi"). + Ecosystems map[string]string `json:"ecosystems" yaml:"ecosystems"` + + // Packages overrides the cooldown for specific packages. + // Keys are PURLs (e.g., "pkg:npm/lodash", "pkg:npm/@babel/core"). + Packages map[string]string `json:"packages" yaml:"packages"` + + defaultDuration time.Duration + ecosystemDurations map[string]time.Duration + packageDurations map[string]time.Duration + parsed bool +} + +// parse resolves all string durations into time.Duration values. +// Called lazily on first use. +func (c *Config) parse() { + if c.parsed { + return + } + c.parsed = true + + c.defaultDuration, _ = ParseDuration(c.Default) + + c.ecosystemDurations = make(map[string]time.Duration, len(c.Ecosystems)) + for k, v := range c.Ecosystems { + d, _ := ParseDuration(v) + c.ecosystemDurations[k] = d + } + + c.packageDurations = make(map[string]time.Duration, len(c.Packages)) + for k, v := range c.Packages { + d, _ := ParseDuration(v) + c.packageDurations[k] = d + } +} + +// For returns the effective cooldown duration for a given ecosystem and package PURL. +// Resolution order: package override > ecosystem override > global default. +func (c *Config) For(ecosystem, packagePURL string) time.Duration { + c.parse() + + if d, ok := c.packageDurations[packagePURL]; ok { + return d + } + if d, ok := c.ecosystemDurations[ecosystem]; ok { + return d + } + return c.defaultDuration +} + +// IsAllowed returns true if a version with the given publish time has passed +// the cooldown period for this ecosystem/package. +func (c *Config) IsAllowed(ecosystem, packagePURL string, publishedAt time.Time) bool { + d := c.For(ecosystem, packagePURL) + if d == 0 { + return true + } + if publishedAt.IsZero() { + return true + } + return time.Since(publishedAt) >= d +} + +// Enabled returns true if any cooldown is configured. +func (c *Config) Enabled() bool { + c.parse() + if c.defaultDuration > 0 { + return true + } + for _, d := range c.ecosystemDurations { + if d > 0 { + return true + } + } + for _, d := range c.packageDurations { + if d > 0 { + return true + } + } + return false +} + +// ParseDuration parses a duration string supporting days (e.g., "3d"), +// in addition to Go's standard time.ParseDuration formats ("48h", "30m"). +// "0" means disabled (returns 0). +func ParseDuration(s string) (time.Duration, error) { + s = strings.TrimSpace(s) + if s == "" || s == "0" { + return 0, nil + } + + // Handle day suffix + if numStr, ok := strings.CutSuffix(s, "d"); ok { + days, err := strconv.ParseFloat(numStr, 64) + if err != nil { + return 0, fmt.Errorf("invalid duration %q: %w", s, err) + } + return time.Duration(days * float64(hoursPerDay*time.Hour)), nil + } + + d, err := time.ParseDuration(s) + if err != nil { + return 0, fmt.Errorf("invalid duration %q: %w", s, err) + } + return d, nil +} diff --git a/internal/cooldown/cooldown_test.go b/internal/cooldown/cooldown_test.go new file mode 100644 index 0000000..c366077 --- /dev/null +++ b/internal/cooldown/cooldown_test.go @@ -0,0 +1,133 @@ +package cooldown + +import ( + "testing" + "time" +) + +func TestParseDuration(t *testing.T) { + tests := []struct { + input string + want time.Duration + wantErr bool + }{ + {"", 0, false}, + {"0", 0, false}, + {"3d", 3 * 24 * time.Hour, false}, + {"7d", 7 * 24 * time.Hour, false}, + {"14d", 14 * 24 * time.Hour, false}, + {"1.5d", 36 * time.Hour, false}, + {"48h", 48 * time.Hour, false}, + {"30m", 30 * time.Minute, false}, + {"1h30m", 90 * time.Minute, false}, + {"invalid", 0, true}, + {"d", 0, true}, + {"xd", 0, true}, + } + + for _, tt := range tests { + got, err := ParseDuration(tt.input) + if (err != nil) != tt.wantErr { + t.Errorf("ParseDuration(%q) error = %v, wantErr %v", tt.input, err, tt.wantErr) + continue + } + if got != tt.want { + t.Errorf("ParseDuration(%q) = %v, want %v", tt.input, got, tt.want) + } + } +} + +func TestConfigFor(t *testing.T) { + c := &Config{ + Default: "3d", + Ecosystems: map[string]string{ + "npm": "7d", + "cargo": "0", + }, + Packages: map[string]string{ + "pkg:npm/lodash": "0", + "pkg:npm/@babel/core": "14d", + }, + } + + tests := []struct { + ecosystem string + packagePURL string + want time.Duration + }{ + // Package override takes priority + {"npm", "pkg:npm/lodash", 0}, + {"npm", "pkg:npm/@babel/core", 14 * 24 * time.Hour}, + // Ecosystem override + {"npm", "pkg:npm/express", 7 * 24 * time.Hour}, + {"cargo", "pkg:cargo/serde", 0}, + // Global default + {"pypi", "pkg:pypi/requests", 3 * 24 * time.Hour}, + {"pub", "pkg:pub/flutter", 3 * 24 * time.Hour}, + } + + for _, tt := range tests { + got := c.For(tt.ecosystem, tt.packagePURL) + if got != tt.want { + t.Errorf("For(%q, %q) = %v, want %v", tt.ecosystem, tt.packagePURL, got, tt.want) + } + } +} + +func TestConfigIsAllowed(t *testing.T) { + c := &Config{ + Default: "3d", + Packages: map[string]string{ + "pkg:npm/lodash": "0", + }, + } + + now := time.Now() + + tests := []struct { + name string + ecosystem string + packagePURL string + publishedAt time.Time + want bool + }{ + {"old enough", "npm", "pkg:npm/express", now.Add(-4 * 24 * time.Hour), true}, + {"too recent", "npm", "pkg:npm/express", now.Add(-1 * 24 * time.Hour), false}, + {"exactly at boundary", "npm", "pkg:npm/express", now.Add(-3 * 24 * time.Hour), true}, + {"exempt package", "npm", "pkg:npm/lodash", now.Add(-1 * time.Minute), true}, + {"zero time", "npm", "pkg:npm/express", time.Time{}, true}, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + got := c.IsAllowed(tt.ecosystem, tt.packagePURL, tt.publishedAt) + if got != tt.want { + t.Errorf("IsAllowed(%q, %q, %v) = %v, want %v", + tt.ecosystem, tt.packagePURL, tt.publishedAt, got, tt.want) + } + }) + } +} + +func TestConfigEnabled(t *testing.T) { + tests := []struct { + name string + cfg Config + want bool + }{ + {"empty config", Config{}, false}, + {"default only", Config{Default: "3d"}, true}, + {"ecosystem only", Config{Ecosystems: map[string]string{"npm": "7d"}}, true}, + {"package only", Config{Packages: map[string]string{"pkg:npm/x": "1d"}}, true}, + {"all zero", Config{Default: "0", Ecosystems: map[string]string{"npm": "0"}}, false}, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + got := tt.cfg.Enabled() + if got != tt.want { + t.Errorf("Enabled() = %v, want %v", got, tt.want) + } + }) + } +} diff --git a/internal/database/database.go b/internal/database/database.go index 6b326ec..eded6d2 100644 --- a/internal/database/database.go +++ b/internal/database/database.go @@ -4,7 +4,6 @@ import ( "fmt" "os" "path/filepath" - "time" "github.com/jmoiron/sqlx" _ "github.com/lib/pq" @@ -15,16 +14,6 @@ const SchemaVersion = 1 const dirPermissions = 0755 -// Postgres connection pool limits. database/sql keeps only two idle -// connections by default, which opens a new Postgres session for almost every -// request under load. -const ( - postgresMaxOpenConns = 32 - postgresMaxIdleConns = 32 - postgresConnMaxIdleTime = 5 * time.Minute - postgresConnMaxLifetime = 30 * time.Minute -) - type Dialect string const ( @@ -105,11 +94,6 @@ func OpenPostgres(url string) (*DB, error) { return nil, fmt.Errorf("opening postgres database: %w", err) } - sqlDB.SetMaxOpenConns(postgresMaxOpenConns) - sqlDB.SetMaxIdleConns(postgresMaxIdleConns) - sqlDB.SetConnMaxIdleTime(postgresConnMaxIdleTime) - sqlDB.SetConnMaxLifetime(postgresConnMaxLifetime) - if err := sqlDB.Ping(); err != nil { _ = sqlDB.Close() return nil, fmt.Errorf("connecting to postgres: %w", err) diff --git a/internal/database/database_test.go b/internal/database/database_test.go index bb73bc8..6fca4ea 100644 --- a/internal/database/database_test.go +++ b/internal/database/database_test.go @@ -8,11 +8,6 @@ import ( "time" ) -const ( - testContentHash = "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" - testIntegrity = "sha512-z4PhNX7vuL3xVChQ1m2AB9Yg5AULVxXcg/SpIdNs6c5H0NE8XYXysP+DGNKHfuwvY7kxvUdBeoGlODJ6+SfaPg==" -) - func TestCreateAndOpen(t *testing.T) { dir := t.TempDir() dbPath := filepath.Join(dir, "test.db") @@ -137,7 +132,7 @@ func TestVersionCRUD(t *testing.T) { v := &Version{ PURL: "pkg:npm/lodash@4.17.21", PackagePURL: "pkg:npm/lodash", - Integrity: sql.NullString{String: testIntegrity, Valid: true}, + Integrity: sql.NullString{String: "sha512-abc123", Valid: true}, } err = db.UpsertVersion(v) @@ -205,7 +200,7 @@ func TestArtifactCRUD(t *testing.T) { t.Error("expected artifact to not be cached yet") } - err = db.MarkArtifactCached(versionPURL, "lodash-4.17.21.tgz", "/cache/npm/lodash-4.17.21.tgz", testContentHash, 12345, "application/gzip") + err = db.MarkArtifactCached(versionPURL, "lodash-4.17.21.tgz", "/cache/npm/lodash-4.17.21.tgz", "sha256-abc", 12345, "application/gzip") if err != nil { t.Fatalf("MarkArtifactCached failed: %v", err) } @@ -244,92 +239,6 @@ func TestArtifactCRUD(t *testing.T) { }) } -func TestGetCachedArtifact(t *testing.T) { - runWithBothDatabases(t, func(t *testing.T, db *DB) { - const ( - packagePURL = "pkg:npm/lodash" - versionPURL = "pkg:npm/lodash@4.17.21" - filename = "lodash-4.17.21.tgz" - ) - seedCachedArtifactTestData(t, db, packagePURL, versionPURL, filename) - - cached, err := db.GetCachedArtifact(packagePURL, versionPURL, filename) - if err != nil { - t.Fatalf("GetCachedArtifact before cache failed: %v", err) - } - if cached != nil { - t.Fatalf("expected no cached artifact, got %+v", cached) - } - - if err := db.MarkArtifactCached(versionPURL, filename, "/cache/npm/"+filename, - testContentHash, 12345, "application/gzip"); err != nil { - t.Fatalf("MarkArtifactCached failed: %v", err) - } - - cached, err = db.GetCachedArtifact(packagePURL, versionPURL, filename) - if err != nil { - t.Fatalf("GetCachedArtifact failed: %v", err) - } - if cached == nil { - t.Fatal("expected cached artifact, got nil") - } - if cached.Ecosystem != "npm" { - t.Errorf("expected npm ecosystem, got %q", cached.Ecosystem) - } - if cached.StoragePath != "/cache/npm/"+filename { - t.Errorf("expected cached storage path, got %q", cached.StoragePath) - } - if cached.Artifact.PURL != versionPURL { - t.Errorf("expected cached PURL %q, got %q", versionPURL, cached.Artifact.PURL) - } - if cached.Artifact.Digest.String() != "sha256:"+testContentHash { - t.Errorf("expected cached digest, got %q", cached.Artifact.Digest) - } - if cached.Artifact.Size != 12345 { - t.Errorf("expected cached size 12345, got %d", cached.Artifact.Size) - } - if cached.Artifact.Filename != filename { - t.Errorf("expected cached filename %q, got %q", filename, cached.Artifact.Filename) - } - if cached.Artifact.MediaType != "application/gzip" { - t.Errorf("expected cached content type, got %q", cached.Artifact.MediaType) - } - if cached.Integrity.String != testIntegrity { - t.Errorf("expected cached integrity, got %q", cached.Integrity.String) - } - - cached, err = db.GetCachedArtifact("pkg:npm/other", versionPURL, filename) - if err != nil { - t.Fatalf("GetCachedArtifact with wrong package failed: %v", err) - } - if cached != nil { - t.Fatalf("expected package mismatch to miss cache, got %+v", cached) - } - }) -} - -func seedCachedArtifactTestData(t *testing.T, db *DB, packagePURL, versionPURL, filename string) { - t.Helper() - - if err := db.UpsertPackage(&Package{PURL: packagePURL, Ecosystem: "npm", Name: "lodash"}); err != nil { - t.Fatalf("UpsertPackage failed: %v", err) - } - if err := db.UpsertVersion(&Version{ - PURL: versionPURL, - PackagePURL: packagePURL, - Integrity: sql.NullString{String: testIntegrity, Valid: true}, - }); err != nil { - t.Fatalf("UpsertVersion failed: %v", err) - } - if err := db.UpsertArtifact(&Artifact{ - VersionPURL: versionPURL, - Filename: filename, - UpstreamURL: "https://registry.npmjs.org/lodash/-/" + filename, - }); err != nil { - t.Fatalf("UpsertArtifact failed: %v", err) - } -} - func TestCacheManagement(t *testing.T) { runWithBothDatabases(t, func(t *testing.T, db *DB) { pkg := &Package{ @@ -610,10 +519,8 @@ func createTestPostgresDB(t *testing.T) *DB { t.Fatalf("OpenPostgres failed: %v", err) } - // Drop and recreate every table CreateSchema creates for clean test state; - // leftover migration records make the next CreateSchema fail on the - // migrations primary key. - tables := []string{"artifacts", "versions", "packages", "vulnerabilities", "metadata_cache", "migrations", "schema_info"} + // Drop and recreate tables for clean test state + tables := []string{"artifacts", "versions", "packages", "schema_info"} for _, table := range tables { _, _ = db.Exec("DROP TABLE IF EXISTS " + table + " CASCADE") } @@ -1107,56 +1014,3 @@ func BenchmarkMigrateSchemaFullyMigrated(b *testing.B) { } } } - -func TestVersionPublishedAtPreserved(t *testing.T) { - runWithBothDatabases(t, func(t *testing.T, db *DB) { - publishedAt := time.Date(2020, 1, 2, 3, 4, 5, 0, time.UTC) - - if err := db.SetVersionPublishedAt("pkg:npm/leftpad@1.0.0", "pkg:npm/leftpad", publishedAt); err != nil { - t.Fatalf("SetVersionPublishedAt failed: %v", err) - } - - got, err := db.GetVersionByPURL("pkg:npm/leftpad@1.0.0") - if err != nil || got == nil { - t.Fatalf("GetVersionByPURL failed: %v", err) - } - if !got.PublishedAt.Valid || !got.PublishedAt.Time.Equal(publishedAt) { - t.Fatalf("PublishedAt = %v, want %v", got.PublishedAt, publishedAt) - } - - // An upsert that carries no publish time (the artifact cache path) - // must not erase the stored value. - if err := db.UpsertVersion(&Version{ - PURL: "pkg:npm/leftpad@1.0.0", - PackagePURL: "pkg:npm/leftpad", - }); err != nil { - t.Fatalf("UpsertVersion failed: %v", err) - } - - got, err = db.GetVersionByPURL("pkg:npm/leftpad@1.0.0") - if err != nil || got == nil { - t.Fatalf("GetVersionByPURL after upsert failed: %v", err) - } - if !got.PublishedAt.Valid || !got.PublishedAt.Time.Equal(publishedAt) { - t.Fatalf("PublishedAt after null upsert = %v, want %v preserved", got.PublishedAt, publishedAt) - } - - // An upsert that does carry a publish time still updates it. - later := publishedAt.Add(24 * time.Hour) - if err := db.UpsertVersion(&Version{ - PURL: "pkg:npm/leftpad@1.0.0", - PackagePURL: "pkg:npm/leftpad", - PublishedAt: sql.NullTime{Time: later, Valid: true}, - }); err != nil { - t.Fatalf("UpsertVersion with publish time failed: %v", err) - } - - got, err = db.GetVersionByPURL("pkg:npm/leftpad@1.0.0") - if err != nil || got == nil { - t.Fatalf("GetVersionByPURL after second upsert failed: %v", err) - } - if !got.PublishedAt.Valid || !got.PublishedAt.Time.Equal(later) { - t.Fatalf("PublishedAt after valued upsert = %v, want %v", got.PublishedAt, later) - } - }) -} diff --git a/internal/database/metadata_cache_test.go b/internal/database/metadata_cache_test.go index 46a38a7..5701816 100644 --- a/internal/database/metadata_cache_test.go +++ b/internal/database/metadata_cache_test.go @@ -29,14 +29,9 @@ func TestUpsertAndGetMetadataCache(t *testing.T) { Name: "lodash", StoragePath: "_metadata/npm/lodash/metadata", ETag: sql.NullString{String: `"abc123"`, Valid: true}, - Link: sql.NullString{String: `; rel="next"`, Valid: true}, ContentType: sql.NullString{String: "application/json", Valid: true}, - ContentDigest: sql.NullString{ - String: "sha256:0123456789abcdef", - Valid: true, - }, - Size: sql.NullInt64{Int64: 1024, Valid: true}, - FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, + Size: sql.NullInt64{Int64: 1024, Valid: true}, + FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, } err := db.UpsertMetadataCache(entry) @@ -64,15 +59,9 @@ func TestUpsertAndGetMetadataCache(t *testing.T) { if !got.ETag.Valid || got.ETag.String != `"abc123"` { t.Errorf("etag = %v, want %q", got.ETag, `"abc123"`) } - if !got.Link.Valid || got.Link.String != `; rel="next"` { - t.Errorf("link = %v, want next link", got.Link) - } if !got.ContentType.Valid || got.ContentType.String != "application/json" { t.Errorf("content_type = %v, want %q", got.ContentType, "application/json") } - if !got.ContentDigest.Valid || got.ContentDigest.String != "sha256:0123456789abcdef" { - t.Errorf("content_digest = %v, want %q", got.ContentDigest, "sha256:0123456789abcdef") - } if !got.Size.Valid || got.Size.Int64 != 1024 { t.Errorf("size = %v, want 1024", got.Size) } @@ -162,9 +151,6 @@ func TestUpsertMetadataCacheNullableFields(t *testing.T) { if got.ContentType.Valid { t.Error("expected null content_type") } - if got.Link.Valid { - t.Error("expected null link") - } if got.Size.Valid { t.Error("expected null size") } @@ -192,173 +178,3 @@ func TestMetadataCacheTableCreatedByMigration(t *testing.T) { t.Error("metadata_cache table should exist after migration") } } - -func TestMetadataCacheContentDigestMigrationPreservesExistingRows(t *testing.T) { - dbPath := filepath.Join(t.TempDir(), "test.db") - db, err := Create(dbPath) - if err != nil { - t.Fatalf("Create failed: %v", err) - } - defer func() { _ = db.Close() }() - - if _, err := db.Exec("ALTER TABLE metadata_cache DROP COLUMN content_digest"); err != nil { - t.Fatalf("dropping content_digest: %v", err) - } - if _, err := db.Exec("DELETE FROM migrations WHERE name = ?", "006_add_metadata_content_digest"); err != nil { - t.Fatalf("resetting digest migration: %v", err) - } - if _, err := db.Exec(` - INSERT INTO metadata_cache (ecosystem, name, storage_path, content_type, size, fetched_at, created_at, updated_at) - VALUES (?, ?, ?, ?, ?, ?, ?, ?) - `, "oci-manifest", "cache-key", "_metadata/oci-manifest/cache-key/metadata", "application/json", 2, time.Now(), time.Now(), time.Now()); err != nil { - t.Fatalf("inserting legacy cache row: %v", err) - } - - if err := db.MigrateSchema(); err != nil { - t.Fatalf("MigrateSchema() error = %v", err) - } - hasDigest, err := db.HasColumn("metadata_cache", "content_digest") - if err != nil { - t.Fatalf("HasColumn() error = %v", err) - } - if !hasDigest { - t.Fatal("metadata_cache.content_digest was not added") - } - - entry, err := db.GetMetadataCache("oci-manifest", "cache-key") - if err != nil { - t.Fatalf("GetMetadataCache() error = %v", err) - } - if entry == nil || entry.StoragePath != "_metadata/oci-manifest/cache-key/metadata" { - t.Fatalf("existing metadata cache row was not preserved: %#v", entry) - } - if entry.ContentDigest.Valid { - t.Errorf("legacy content digest = %q, want NULL", entry.ContentDigest.String) - } -} - -func TestMetadataCacheLinkMigrationPreservesExistingRows(t *testing.T) { - dbPath := filepath.Join(t.TempDir(), "test.db") - db, err := Create(dbPath) - if err != nil { - t.Fatalf("Create failed: %v", err) - } - defer func() { _ = db.Close() }() - - if _, err := db.Exec("ALTER TABLE metadata_cache DROP COLUMN link"); err != nil { - t.Fatalf("dropping link: %v", err) - } - if _, err := db.Exec("DELETE FROM migrations WHERE name = ?", "007_add_metadata_link"); err != nil { - t.Fatalf("resetting link migration: %v", err) - } - if _, err := db.Exec(` - INSERT INTO metadata_cache (ecosystem, name, storage_path, content_type, size, fetched_at, created_at, updated_at) - VALUES (?, ?, ?, ?, ?, ?, ?, ?) - `, "oci-tags", "cache-key", "_metadata/oci-tags/cache-key/metadata", "application/json", 2, time.Now(), time.Now(), time.Now()); err != nil { - t.Fatalf("inserting legacy cache row: %v", err) - } - - if err := db.MigrateSchema(); err != nil { - t.Fatalf("MigrateSchema() error = %v", err) - } - hasLink, err := db.HasColumn("metadata_cache", "link") - if err != nil { - t.Fatalf("HasColumn() error = %v", err) - } - if !hasLink { - t.Fatal("metadata_cache.link was not added") - } - - entry, err := db.GetMetadataCache("oci-tags", "cache-key") - if err != nil { - t.Fatalf("GetMetadataCache() error = %v", err) - } - if entry == nil || entry.StoragePath != "_metadata/oci-tags/cache-key/metadata" { - t.Fatalf("existing metadata cache row was not preserved: %#v", entry) - } - if entry.Link.Valid { - t.Errorf("legacy link = %q, want NULL", entry.Link.String) - } -} - -func TestMetadataCacheContentEncodingMigrationPreservesExistingRows(t *testing.T) { - dbPath := filepath.Join(t.TempDir(), "test.db") - db, err := Create(dbPath) - if err != nil { - t.Fatalf("Create failed: %v", err) - } - defer func() { _ = db.Close() }() - - if _, err := db.Exec("ALTER TABLE metadata_cache DROP COLUMN content_encoding"); err != nil { - t.Fatalf("dropping content_encoding: %v", err) - } - if _, err := db.Exec("DELETE FROM migrations WHERE name = ?", "008_add_metadata_content_encoding"); err != nil { - t.Fatalf("resetting content_encoding migration: %v", err) - } - if _, err := db.Exec(` - INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, content_type, size, fetched_at, created_at, updated_at) - VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?) - `, "apk", "cache-key", "_metadata/apk/cache-key/metadata", "\"legacy-etag\"", "application/octet-stream", 2, time.Now(), time.Now(), time.Now()); err != nil { - t.Fatalf("inserting legacy cache row: %v", err) - } - - if err := db.MigrateSchema(); err != nil { - t.Fatalf("MigrateSchema() error = %v", err) - } - hasEncoding, err := db.HasColumn("metadata_cache", "content_encoding") - if err != nil { - t.Fatalf("HasColumn() error = %v", err) - } - if !hasEncoding { - t.Fatal("metadata_cache.content_encoding was not added") - } - - entry, err := db.GetMetadataCache("apk", "cache-key") - if err != nil { - t.Fatalf("GetMetadataCache() error = %v", err) - } - if entry == nil || entry.StoragePath != "_metadata/apk/cache-key/metadata" { - t.Fatalf("existing metadata cache row was not preserved: %#v", entry) - } - if entry.ContentEncoding.Valid { - t.Errorf("legacy content encoding = %q, want NULL", entry.ContentEncoding.String) - } - // The migration must clear the pre-fix validators so the row is refetched - // once with identity instead of a 304 re-serving the decompressed copy. - if entry.ETag.Valid { - t.Errorf("legacy etag = %q, want cleared", entry.ETag.String) - } - if entry.FetchedAt.Valid { - t.Errorf("legacy fetched_at = %v, want cleared", entry.FetchedAt.Time) - } -} - -func TestMetadataCacheRoundTripsContentEncoding(t *testing.T) { - dbPath := filepath.Join(t.TempDir(), "test.db") - db, err := Create(dbPath) - if err != nil { - t.Fatalf("Create failed: %v", err) - } - defer func() { _ = db.Close() }() - - entry := &MetadataCacheEntry{ - Ecosystem: "apk", - Name: "index-key", - StoragePath: "_metadata/apk/index-key/metadata", - ContentType: sql.NullString{String: "application/octet-stream", Valid: true}, - ContentEncoding: sql.NullString{String: "gzip", Valid: true}, - Size: sql.NullInt64{Int64: 10, Valid: true}, - FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, - } - if err := db.UpsertMetadataCache(entry); err != nil { - t.Fatalf("UpsertMetadataCache() error = %v", err) - } - - got, err := db.GetMetadataCache("apk", "index-key") - if err != nil { - t.Fatalf("GetMetadataCache() error = %v", err) - } - if got == nil || !got.ContentEncoding.Valid || got.ContentEncoding.String != "gzip" { - t.Fatalf("content encoding round-trip failed: %#v", got) - } -} diff --git a/internal/database/postgres_pool_test.go b/internal/database/postgres_pool_test.go deleted file mode 100644 index bd39bee..0000000 --- a/internal/database/postgres_pool_test.go +++ /dev/null @@ -1,57 +0,0 @@ -package database - -import ( - "context" - "database/sql" - "os" - "testing" -) - -// TestOpenPostgresKeepsConnectionsIdle checks the connection-count limits -// OpenPostgres sets: the open cap admits a burst of postgresMaxIdleConns -// connections, and releasing them again leaves all of them idle in the pool. -// database/sql's default keeps only two, so the next burst would open a new -// Postgres session for almost every request. The idle-time and lifetime -// settings are not exercised here. -func TestOpenPostgresKeepsConnectionsIdle(t *testing.T) { - url := os.Getenv("PROXY_DATABASE_URL") - if url == "" { - t.Skip("PROXY_DATABASE_URL not set, skipping postgres pool test") - } - - db, err := OpenPostgres(url) - if err != nil { - t.Fatalf("OpenPostgres failed: %v", err) - } - defer func() { _ = db.Close() }() - - const burst = postgresMaxIdleConns - // database/sql keeps two idle connections by default; a burst that small - // could not tell the tuned pool from the default one. - if burst <= 2 { - t.Fatalf("postgresMaxIdleConns = %d, want more than database/sql's default of 2", burst) - } - if got := db.Stats().MaxOpenConnections; got <= 0 || got < burst { - t.Fatalf("MaxOpenConnections = %d, want a cap of at least %d", got, burst) - } - - conns := make([]*sql.Conn, 0, burst) - for range burst { - conn, err := db.Conn(context.Background()) - if err != nil { - t.Fatalf("taking connection %d: %v", len(conns)+1, err) - } - t.Cleanup(func() { _ = conn.Close() }) // release the session if an assertion below fails - conns = append(conns, conn) - } - if got := db.Stats().InUse; got != burst { - t.Fatalf("InUse = %d while holding %d connections", got, burst) - } - - for _, conn := range conns { - _ = conn.Close() - } - if got := db.Stats().Idle; got != burst { - t.Errorf("Idle = %d after releasing %d connections, want all of them kept", got, burst) - } -} diff --git a/internal/database/queries.go b/internal/database/queries.go index a7c4c7a..5d95596 100644 --- a/internal/database/queries.go +++ b/internal/database/queries.go @@ -4,9 +4,6 @@ import ( "database/sql" "fmt" "time" - - "github.com/git-pkgs/artifacts" - "github.com/opencontainers/go-digest" ) // Package queries @@ -144,7 +141,7 @@ func (db *DB) UpsertVersion(v *Version) error { ON CONFLICT(purl) DO UPDATE SET license = EXCLUDED.license, integrity = EXCLUDED.integrity, - published_at = COALESCE(EXCLUDED.published_at, versions.published_at), + published_at = EXCLUDED.published_at, yanked = EXCLUDED.yanked, enriched_at = EXCLUDED.enriched_at, updated_at = EXCLUDED.updated_at @@ -157,7 +154,7 @@ func (db *DB) UpsertVersion(v *Version) error { ON CONFLICT(purl) DO UPDATE SET license = excluded.license, integrity = excluded.integrity, - published_at = COALESCE(excluded.published_at, published_at), + published_at = excluded.published_at, yanked = excluded.yanked, enriched_at = excluded.enriched_at, updated_at = excluded.updated_at @@ -174,38 +171,6 @@ func (db *DB) UpsertVersion(v *Version) error { return nil } -// SetVersionPublishedAt records a version's publish time, creating the -// versions row if the proxy has not seen the version yet. It only writes -// published_at, so it never disturbs enrichment data on an existing row. -func (db *DB) SetVersionPublishedAt(versionPURL, packagePURL string, publishedAt time.Time) error { - now := time.Now() - var query string - - if db.dialect == DialectPostgres { - query = ` - INSERT INTO versions (purl, package_purl, published_at, created_at, updated_at) - VALUES ($1, $2, $3, $4, $5) - ON CONFLICT(purl) DO UPDATE SET - published_at = EXCLUDED.published_at, - updated_at = EXCLUDED.updated_at - ` - } else { - query = ` - INSERT INTO versions (purl, package_purl, published_at, created_at, updated_at) - VALUES (?, ?, ?, ?, ?) - ON CONFLICT(purl) DO UPDATE SET - published_at = excluded.published_at, - updated_at = excluded.updated_at - ` - } - - _, err := db.Exec(query, versionPURL, packagePURL, publishedAt, now, now) - if err != nil { - return fmt.Errorf("setting version publish time: %w", err) - } - return nil -} - // Artifact queries func (db *DB) GetArtifact(versionPURL, filename string) (*Artifact, error) { @@ -226,56 +191,6 @@ func (db *DB) GetArtifact(versionPURL, filename string) (*Artifact, error) { return &a, nil } -// GetCachedArtifact returns the fields needed to serve a cached artifact. -func (db *DB) GetCachedArtifact(packagePURL, versionPURL, filename string) (*CachedArtifact, error) { - var row cachedArtifactRow - query := db.Rebind(` - SELECT packages.ecosystem, artifacts.storage_path, artifacts.content_hash, artifacts.size, - artifacts.content_type, versions.integrity - FROM artifacts - JOIN versions ON versions.purl = artifacts.version_purl - JOIN packages ON packages.purl = versions.package_purl - WHERE packages.purl = ? AND artifacts.version_purl = ? AND artifacts.filename = ? - AND artifacts.storage_path IS NOT NULL AND artifacts.fetched_at IS NOT NULL - `) - err := db.Get(&row, query, packagePURL, versionPURL, filename) - if err == sql.ErrNoRows { - return nil, nil - } - if err != nil { - return nil, err - } - return row.artifact(versionPURL, filename), nil -} - -type cachedArtifactRow struct { - Ecosystem string `db:"ecosystem"` - StoragePath string `db:"storage_path"` - ContentHash sql.NullString `db:"content_hash"` - Size sql.NullInt64 `db:"size"` - ContentType sql.NullString `db:"content_type"` - Integrity sql.NullString `db:"integrity"` -} - -// artifact converts a cached artifact row to a CachedArtifact without -// validation. A malformed hash or integrity value is handled by -// checkCache, which clears the record and treats the request as a cache -// miss so the client is served a fresh fetch instead of an error. -func (row cachedArtifactRow) artifact(versionPURL, filename string) *CachedArtifact { - return &CachedArtifact{ - Ecosystem: row.Ecosystem, - StoragePath: row.StoragePath, - Integrity: row.Integrity, - Artifact: artifacts.Artifact{ - PURL: versionPURL, - Digest: digest.Digest("sha256:" + row.ContentHash.String), - Size: row.Size.Int64, - Filename: filename, - MediaType: row.ContentType.String, - }, - } -} - func (db *DB) GetArtifactByPath(storagePath string) (*Artifact, error) { var a Artifact query := db.Rebind(` @@ -528,14 +443,11 @@ func (db *DB) GetMostPopularPackages(limit int) ([]PopularPackage, error) { } type RecentPackage struct { - Ecosystem string `db:"ecosystem"` - Name string `db:"name"` - VersionPURL string `db:"version_purl"` - CachedAt time.Time `db:"fetched_at"` - Size int64 `db:"size"` - // Version is derived from VersionPURL rather than selected, so that the - // PURL percent-encoding is decoded (e.g. "%2B" back to "+"). - Version string `db:"-"` + Ecosystem string `db:"ecosystem"` + Name string `db:"name"` + Version string `db:"version"` + CachedAt time.Time `db:"fetched_at"` + Size int64 `db:"size"` } func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) { @@ -549,10 +461,10 @@ func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) { } var packages []RecentPackage - // There is no separate version column, so the full version PURL is selected - // and the version is decoded from it in Go. + // We need to extract version from the purl since there's no separate version column query := db.Rebind(` - SELECT p.ecosystem, p.name, v.purl as version_purl, + SELECT p.ecosystem, p.name, + SUBSTR(v.purl, INSTR(v.purl, '@') + 1) as version, a.fetched_at, COALESCE(a.size, 0) as size FROM artifacts a JOIN versions v ON v.purl = a.version_purl @@ -562,13 +474,25 @@ func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) { LIMIT ? `) + // For postgres, use different string function + if db.dialect == DialectPostgres { + query = db.Rebind(` + SELECT p.ecosystem, p.name, + SUBSTRING(v.purl FROM POSITION('@' IN v.purl) + 1) as version, + a.fetched_at, COALESCE(a.size, 0) as size + FROM artifacts a + JOIN versions v ON v.purl = a.version_purl + JOIN packages p ON p.purl = v.package_purl + WHERE a.storage_path IS NOT NULL AND a.fetched_at IS NOT NULL + ORDER BY a.fetched_at DESC + LIMIT ? + `) + } + err = db.Select(&packages, query, limit) if err != nil { return nil, err } - for i := range packages { - packages[i].Version = VersionFromPURL(packages[i].VersionPURL) - } return packages, nil } @@ -969,8 +893,8 @@ func (db *DB) CountCachedPackages(ecosystem string) (int64, error) { func (db *DB) GetMetadataCache(ecosystem, name string) (*MetadataCacheEntry, error) { var entry MetadataCacheEntry query := db.Rebind(` - SELECT id, ecosystem, name, storage_path, etag, link, content_type, content_encoding, - content_digest, size, last_modified, fetched_at, created_at, updated_at + SELECT id, ecosystem, name, storage_path, etag, content_type, + size, last_modified, fetched_at, created_at, updated_at FROM metadata_cache WHERE ecosystem = ? AND name = ? `) err := db.Get(&entry, query, ecosystem, name) @@ -989,16 +913,13 @@ func (db *DB) UpsertMetadataCache(entry *MetadataCacheEntry) error { if db.dialect == DialectPostgres { query = ` - INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, link, content_type, content_encoding, - content_digest, size, last_modified, fetched_at, created_at, updated_at) - VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13) + INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, content_type, + size, last_modified, fetched_at, created_at, updated_at) + VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10) ON CONFLICT(ecosystem, name) DO UPDATE SET storage_path = EXCLUDED.storage_path, etag = EXCLUDED.etag, - link = EXCLUDED.link, content_type = EXCLUDED.content_type, - content_encoding = EXCLUDED.content_encoding, - content_digest = EXCLUDED.content_digest, size = EXCLUDED.size, last_modified = EXCLUDED.last_modified, fetched_at = EXCLUDED.fetched_at, @@ -1006,16 +927,13 @@ func (db *DB) UpsertMetadataCache(entry *MetadataCacheEntry) error { ` } else { query = ` - INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, link, content_type, content_encoding, - content_digest, size, last_modified, fetched_at, created_at, updated_at) - VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?) + INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, content_type, + size, last_modified, fetched_at, created_at, updated_at) + VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?) ON CONFLICT(ecosystem, name) DO UPDATE SET storage_path = excluded.storage_path, etag = excluded.etag, - link = excluded.link, content_type = excluded.content_type, - content_encoding = excluded.content_encoding, - content_digest = excluded.content_digest, size = excluded.size, last_modified = excluded.last_modified, fetched_at = excluded.fetched_at, @@ -1024,8 +942,8 @@ func (db *DB) UpsertMetadataCache(entry *MetadataCacheEntry) error { } _, err := db.Exec(query, - entry.Ecosystem, entry.Name, entry.StoragePath, entry.ETag, entry.Link, - entry.ContentType, entry.ContentEncoding, entry.ContentDigest, entry.Size, entry.LastModified, entry.FetchedAt, now, now, + entry.Ecosystem, entry.Name, entry.StoragePath, entry.ETag, + entry.ContentType, entry.Size, entry.LastModified, entry.FetchedAt, now, now, ) if err != nil { return fmt.Errorf("upserting metadata cache: %w", err) diff --git a/internal/database/schema.go b/internal/database/schema.go index 564745f..e6f284f 100644 --- a/internal/database/schema.go +++ b/internal/database/schema.go @@ -6,11 +6,7 @@ import ( "time" ) -const ( - postgresTimestamp = "TIMESTAMP" - sqliteDatetime = "DATETIME" - colTypeText = "TEXT" -) +const postgresTimestamp = "TIMESTAMP" // Schema for proxy-specific tables. The packages and versions tables // are compatible with git-pkgs, allowing the proxy to use an existing @@ -101,10 +97,7 @@ CREATE TABLE IF NOT EXISTS metadata_cache ( name TEXT NOT NULL, storage_path TEXT NOT NULL, etag TEXT, - link TEXT, content_type TEXT, - content_encoding TEXT, - content_digest TEXT, size INTEGER, last_modified DATETIME, fetched_at DATETIME, @@ -204,10 +197,7 @@ CREATE TABLE IF NOT EXISTS metadata_cache ( name TEXT NOT NULL, storage_path TEXT NOT NULL, etag TEXT, - link TEXT, content_type TEXT, - content_encoding TEXT, - content_digest TEXT, size BIGINT, last_modified TIMESTAMP, fetched_at TIMESTAMP, @@ -365,9 +355,6 @@ var migrations = []migration{ {"003_ensure_artifacts_table", migrateEnsureArtifactsTable}, {"004_ensure_vulnerabilities_table", migrateEnsureVulnerabilitiesTable}, {"005_ensure_metadata_cache_table", migrateEnsureMetadataCacheTable}, - {"006_add_metadata_content_digest", migrateAddMetadataContentDigest}, - {"007_add_metadata_link", migrateAddMetadataLink}, - {"008_add_metadata_content_encoding", migrateAddMetadataContentEncoding}, } // isTableNotFound returns true if the error indicates a missing table. @@ -382,9 +369,9 @@ func isTableNotFound(err error) bool { func (db *DB) createMigrationsTable() error { var ts string if db.dialect == DialectPostgres { - ts = postgresTimestamp + ts = "TIMESTAMP" } else { - ts = sqliteDatetime + ts = "DATETIME" } query := fmt.Sprintf(`CREATE TABLE IF NOT EXISTS migrations ( @@ -470,12 +457,12 @@ func (db *DB) MigrateSchema() error { func migrateAddPackagesEnrichmentColumns(db *DB) error { columns := map[string]string{ - "registry_url": colTypeText, - "supplier_name": colTypeText, - "supplier_type": colTypeText, - "source": colTypeText, - "enriched_at": sqliteDatetime, - "vulns_synced_at": sqliteDatetime, + "registry_url": "TEXT", + "supplier_name": "TEXT", + "supplier_type": "TEXT", + "source": "TEXT", + "enriched_at": "DATETIME", + "vulns_synced_at": "DATETIME", } if db.dialect == DialectPostgres { @@ -500,10 +487,10 @@ func migrateAddPackagesEnrichmentColumns(db *DB) error { func migrateAddVersionsEnrichmentColumns(db *DB) error { columns := map[string]string{ - "integrity": colTypeText, + "integrity": "TEXT", "yanked": "INTEGER DEFAULT 0", - "source": colTypeText, - "enriched_at": sqliteDatetime, + "source": "TEXT", + "enriched_at": "DATETIME", } if db.dialect == DialectPostgres { @@ -590,56 +577,6 @@ func migrateEnsureMetadataCacheTable(db *DB) error { return db.EnsureMetadataCacheTable() } -func migrateAddMetadataContentDigest(db *DB) error { - hasColumn, err := db.HasColumn("metadata_cache", "content_digest") - if err != nil { - return fmt.Errorf("checking metadata_cache content_digest column: %w", err) - } - if hasColumn { - return nil - } - if _, err := db.Exec("ALTER TABLE metadata_cache ADD COLUMN content_digest TEXT"); err != nil { - return fmt.Errorf("adding metadata_cache content_digest column: %w", err) - } - return nil -} - -func migrateAddMetadataLink(db *DB) error { - hasColumn, err := db.HasColumn("metadata_cache", "link") - if err != nil { - return fmt.Errorf("checking metadata_cache link column: %w", err) - } - if hasColumn { - return nil - } - if _, err := db.Exec("ALTER TABLE metadata_cache ADD COLUMN link TEXT"); err != nil { - return fmt.Errorf("adding metadata_cache link column: %w", err) - } - return nil -} - -func migrateAddMetadataContentEncoding(db *DB) error { - hasColumn, err := db.HasColumn("metadata_cache", "content_encoding") - if err != nil { - return fmt.Errorf("checking metadata_cache content_encoding column: %w", err) - } - if hasColumn { - return nil - } - if _, err := db.Exec("ALTER TABLE metadata_cache ADD COLUMN content_encoding TEXT"); err != nil { - return fmt.Errorf("adding metadata_cache content_encoding column: %w", err) - } - // Rows cached before this column existed hold transport-decompressed bytes - // with no recorded encoding and the upstream ETag captured under Go's - // auto-added Accept-Encoding: gzip. Clearing the validators forces one fresh - // fetch per key so the encoding is recorded and verbatim bytes are restored, - // instead of an If-None-Match 304 re-serving the stale decompressed copy. - if _, err := db.Exec("UPDATE metadata_cache SET etag = NULL, fetched_at = NULL"); err != nil { - return fmt.Errorf("invalidating metadata_cache validators: %w", err) - } - return nil -} - // EnsureMetadataCacheTable creates the metadata_cache table if it doesn't exist. func (db *DB) EnsureMetadataCacheTable() error { has, err := db.HasTable("metadata_cache") @@ -658,11 +595,8 @@ func (db *DB) EnsureMetadataCacheTable() error { ecosystem TEXT NOT NULL, name TEXT NOT NULL, storage_path TEXT NOT NULL, - etag TEXT, - link TEXT, - content_type TEXT, - content_encoding TEXT, - content_digest TEXT, + etag TEXT, + content_type TEXT, size BIGINT, last_modified TIMESTAMP, fetched_at TIMESTAMP, @@ -678,11 +612,8 @@ func (db *DB) EnsureMetadataCacheTable() error { ecosystem TEXT NOT NULL, name TEXT NOT NULL, storage_path TEXT NOT NULL, - etag TEXT, - link TEXT, - content_type TEXT, - content_encoding TEXT, - content_digest TEXT, + etag TEXT, + content_type TEXT, size INTEGER, last_modified DATETIME, fetched_at DATETIME, diff --git a/internal/database/types.go b/internal/database/types.go index 9c4fdd6..f5b718e 100644 --- a/internal/database/types.go +++ b/internal/database/types.go @@ -2,11 +2,8 @@ package database import ( "database/sql" - "net/url" "strings" "time" - - "github.com/git-pkgs/artifacts" ) // Package represents a package in the database. @@ -50,79 +47,10 @@ type Version struct { // Version extracts the version string from the PURL. // e.g., "pkg:npm/lodash@4.17.21" -> "4.17.21" func (v *Version) Version() string { - return VersionFromPURL(v.PURL) -} - -// EscapedVersion returns the version escaped for use as a single URL path -// segment. -// -// Version returns decoded text, which is what should be shown to a user but is -// not safe to drop into a link: html/template preserves reserved characters and -// existing escapes in a URL, so "release/1" would split into two path segments, -// "v1?build" would start a query string, and a literal "%2B" would be read back -// as "+". Escaping here and decoding in splitWildcardPath round-trips the value, -// so the link resolves to the version that was stored. -func (v *Version) EscapedVersion() string { - return url.PathEscape(v.Version()) -} - -// DisplayPURL returns the PURL with its path components percent-decoded, for -// showing in the UI. The stored PURL keeps the canonical encoding (which is -// what the API and all lookups use); this is only a readable rendering, so that -// a version like "7.91+dfsg1-2ubuntu0.1" is not shown as "7.91%2Bdfsg1-2ubuntu0.1" -// and an npm scope is shown as "@babel" rather than "%40babel". Qualifiers and -// subpath keep their encoding, since decoding those would be ambiguous. -func (v *Version) DisplayPURL() string { - base, suffix := v.PURL, "" - if i := strings.IndexAny(base, "?#"); i >= 0 { - base, suffix = base[:i], base[i:] + if idx := strings.LastIndex(v.PURL, "@"); idx >= 0 { + return v.PURL[idx+1:] } - - name, version := base, "" - if idx := strings.LastIndex(base, "@"); idx >= 0 { - name, version = base[:idx], "@"+decodePURLComponent(base[idx+1:]) - } - - parts := strings.Split(name, "/") - for i, part := range parts { - parts[i] = decodePURLComponent(part) - } - return strings.Join(parts, "/") + version + suffix -} - -// VersionFromPURL extracts the decoded version string from a PURL. -// -// PURL percent-encodes characters that are not safe in a path component, so a -// Debian version like "7.91+dfsg1-2ubuntu0.1" is stored as -// "pkg:deb/nmap@7.91%2Bdfsg1-2ubuntu0.1". The raw substring after "@" is -// therefore not the version: it must be percent-decoded before being displayed -// or used to build a URL, otherwise "%2B" leaks into the UI and round-tripping -// the value back into a PURL double-encodes it. -// -// e.g., "pkg:npm/lodash@4.17.21" -> "4.17.21" -func VersionFromPURL(p string) string { - // Qualifiers ("?key=value") and subpath ("#path") follow the version. - if i := strings.IndexAny(p, "?#"); i >= 0 { - p = p[:i] - } - idx := strings.LastIndex(p, "@") - if idx < 0 { - return "" - } - return decodePURLComponent(p[idx+1:]) -} - -// decodePURLComponent percent-decodes a single PURL path component, returning -// the input unchanged if it is not valid percent-encoding. -func decodePURLComponent(s string) string { - if !strings.Contains(s, "%") { - return s - } - decoded, err := url.PathUnescape(s) - if err != nil { - return s - } - return decoded + return "" } // Artifact represents a cached artifact in the database. @@ -148,44 +76,33 @@ func (a *Artifact) IsCached() bool { return a.StoragePath.Valid && a.FetchedAt.Valid } -// CachedArtifact contains the fields needed to serve a cached artifact. -type CachedArtifact struct { - Ecosystem string - StoragePath string - Artifact artifacts.Artifact - Integrity sql.NullString -} - // MetadataCacheEntry represents a cached metadata blob for offline serving. type MetadataCacheEntry struct { - ID int64 `db:"id" json:"id"` - Ecosystem string `db:"ecosystem" json:"ecosystem"` - Name string `db:"name" json:"name"` - StoragePath string `db:"storage_path" json:"storage_path"` - ETag sql.NullString `db:"etag" json:"etag,omitempty"` - Link sql.NullString `db:"link" json:"link,omitempty"` - ContentType sql.NullString `db:"content_type" json:"content_type,omitempty"` - ContentEncoding sql.NullString `db:"content_encoding" json:"content_encoding,omitempty"` - ContentDigest sql.NullString `db:"content_digest" json:"content_digest,omitempty"` - Size sql.NullInt64 `db:"size" json:"size,omitempty"` - LastModified sql.NullTime `db:"last_modified" json:"last_modified,omitempty"` - FetchedAt sql.NullTime `db:"fetched_at" json:"fetched_at,omitempty"` - CreatedAt time.Time `db:"created_at" json:"created_at"` - UpdatedAt time.Time `db:"updated_at" json:"updated_at"` + ID int64 `db:"id" json:"id"` + Ecosystem string `db:"ecosystem" json:"ecosystem"` + Name string `db:"name" json:"name"` + StoragePath string `db:"storage_path" json:"storage_path"` + ETag sql.NullString `db:"etag" json:"etag,omitempty"` + ContentType sql.NullString `db:"content_type" json:"content_type,omitempty"` + Size sql.NullInt64 `db:"size" json:"size,omitempty"` + LastModified sql.NullTime `db:"last_modified" json:"last_modified,omitempty"` + FetchedAt sql.NullTime `db:"fetched_at" json:"fetched_at,omitempty"` + CreatedAt time.Time `db:"created_at" json:"created_at"` + UpdatedAt time.Time `db:"updated_at" json:"updated_at"` } // Vulnerability represents a cached vulnerability record. type Vulnerability struct { - ID int64 `db:"id" json:"id"` - VulnID string `db:"vuln_id" json:"vuln_id"` - Ecosystem string `db:"ecosystem" json:"ecosystem"` - PackageName string `db:"package_name" json:"package_name"` - Severity sql.NullString `db:"severity" json:"severity,omitempty"` - Summary sql.NullString `db:"summary" json:"summary,omitempty"` - FixedVersion sql.NullString `db:"fixed_version" json:"fixed_version,omitempty"` + ID int64 `db:"id" json:"id"` + VulnID string `db:"vuln_id" json:"vuln_id"` + Ecosystem string `db:"ecosystem" json:"ecosystem"` + PackageName string `db:"package_name" json:"package_name"` + Severity sql.NullString `db:"severity" json:"severity,omitempty"` + Summary sql.NullString `db:"summary" json:"summary,omitempty"` + FixedVersion sql.NullString `db:"fixed_version" json:"fixed_version,omitempty"` CVSSScore sql.NullFloat64 `db:"cvss_score" json:"cvss_score,omitempty"` - References sql.NullString `db:"references" json:"references,omitempty"` - FetchedAt sql.NullTime `db:"fetched_at" json:"fetched_at,omitempty"` - CreatedAt time.Time `db:"created_at" json:"created_at"` - UpdatedAt time.Time `db:"updated_at" json:"updated_at"` + References sql.NullString `db:"references" json:"references,omitempty"` + FetchedAt sql.NullTime `db:"fetched_at" json:"fetched_at,omitempty"` + CreatedAt time.Time `db:"created_at" json:"created_at"` + UpdatedAt time.Time `db:"updated_at" json:"updated_at"` } diff --git a/internal/database/version_purl_test.go b/internal/database/version_purl_test.go deleted file mode 100644 index 517022b..0000000 --- a/internal/database/version_purl_test.go +++ /dev/null @@ -1,159 +0,0 @@ -package database - -import ( - "database/sql" - "net/url" - "testing" - "time" -) - -func TestVersionFromPURL(t *testing.T) { - tests := []struct { - name string - purl string - want string - }{ - {"simple", "pkg:npm/lodash@4.17.21", "4.17.21"}, - {"namespaced", "pkg:composer/symfony/console@6.0.0", "6.0.0"}, - // Debian/Ubuntu versions routinely contain "+", which PURL encodes. - {"encoded plus", "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1", "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1"}, - {"encoded epoch", "pkg:deb/curl@1%3A7.81.0-1", "1:7.81.0-1"}, - {"encoded plus with qualifier", "pkg:deb/nmap@7.91%2Bdfsg1?repository_url=http%3A%2F%2Fexample.com", "7.91+dfsg1"}, - {"tilde is not encoded", "pkg:deb/foo@1.0~rc1", "1.0~rc1"}, - {"no version", "pkg:npm/lodash", ""}, - {"invalid escape passed through", "pkg:npm/lodash@1.0%zz", "1.0%zz"}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - if got := VersionFromPURL(tt.purl); got != tt.want { - t.Errorf("VersionFromPURL(%q) = %q, want %q", tt.purl, got, tt.want) - } - v := &Version{PURL: tt.purl} - if got := v.Version(); got != tt.want { - t.Errorf("Version.Version() for %q = %q, want %q", tt.purl, got, tt.want) - } - }) - } -} - -// TestVersionEscapedVersion checks the value the templates put in a URL. It -// must survive the round trip back through the router: escaping here and -// decoding per path segment on the way in has to yield the original version. -func TestVersionEscapedVersion(t *testing.T) { - tests := []struct { - name string - purl string - want string - }{ - {"simple", "pkg:npm/lodash@4.17.21", "4.17.21"}, - // "+" is legal in a path segment, so it stays literal and the UI keeps - // showing the version the way Debian writes it. - {"plus stays literal", "pkg:deb/nmap@7.91%2Bdfsg1-2ubuntu0.1", "7.91+dfsg1-2ubuntu0.1"}, - // A slash would otherwise split the version into two path segments. - {"slash", "pkg:golang/example@release%2F1", "release%2F1"}, - // A question mark would otherwise start the query string. - {"question mark", "pkg:npm/example@v1%3Fbuild", "v1%3Fbuild"}, - // A version containing a literal "%2B" is stored double-encoded; the - // link must re-encode it or it decodes back to "+" instead. - {"literal percent escape", "pkg:npm/example@1.0%252B", "1.0%252B"}, - {"space", "pkg:npm/example@1.0%20beta", "1.0%20beta"}, - {"no version", "pkg:npm/lodash", ""}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - v := &Version{PURL: tt.purl} - got := v.EscapedVersion() - if got != tt.want { - t.Errorf("EscapedVersion() for %q = %q, want %q", tt.purl, got, tt.want) - } - // The router decodes each path segment, which must give back the - // version the page displays. - decoded, err := url.PathUnescape(got) - if err != nil { - t.Fatalf("PathUnescape(%q) failed: %v", got, err) - } - if decoded != v.Version() { - t.Errorf("round trip for %q = %q, want %q", tt.purl, decoded, v.Version()) - } - }) - } -} - -func TestVersionDisplayPURL(t *testing.T) { - tests := []struct { - name string - purl string - want string - }{ - {"simple", "pkg:npm/lodash@4.17.21", "pkg:npm/lodash@4.17.21"}, - { - "encoded plus", - "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1", - "pkg:deb/nmap@7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1", - }, - { - "qualifier preserved", - "pkg:deb/nmap@7.91%2Bdfsg1?repository_url=http%3A%2F%2Fexample.com", - "pkg:deb/nmap@7.91+dfsg1?repository_url=http%3A%2F%2Fexample.com", - }, - // The namespace is encoded too: MakePURLString("npm", "@babel/core", …) - // produces "pkg:npm/%40babel/core@…". - {"encoded npm scope", "pkg:npm/%40babel/core@7.0.0", "pkg:npm/@babel/core@7.0.0"}, - {"encoded scope without version", "pkg:npm/%40babel/core", "pkg:npm/@babel/core"}, - {"no version", "pkg:npm/lodash", "pkg:npm/lodash"}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - v := &Version{PURL: tt.purl} - if got := v.DisplayPURL(); got != tt.want { - t.Errorf("DisplayPURL() for %q = %q, want %q", tt.purl, got, tt.want) - } - }) - } -} - -// TestGetRecentlyCachedPackagesDecodesVersion guards the dashboard's "recently -// cached" list, which derives the version from the version PURL. -func TestGetRecentlyCachedPackagesDecodesVersion(t *testing.T) { - runWithBothDatabases(t, func(t *testing.T, db *DB) { - const versionPURL = "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1" - - if err := db.UpsertPackage(&Package{ - PURL: "pkg:deb/nmap", Ecosystem: "deb", Name: "nmap", - }); err != nil { - t.Fatalf("UpsertPackage failed: %v", err) - } - if err := db.UpsertVersion(&Version{ - PURL: versionPURL, PackagePURL: "pkg:deb/nmap", - }); err != nil { - t.Fatalf("UpsertVersion failed: %v", err) - } - if err := db.UpsertArtifact(&Artifact{ - VersionPURL: versionPURL, - Filename: "nmap_7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1_amd64.deb", - UpstreamURL: "http://archive.ubuntu.com/ubuntu/pool/universe/n/nmap/nmap.deb", - StoragePath: sql.NullString{String: "/cache/nmap.deb", Valid: true}, - FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, - }); err != nil { - t.Fatalf("UpsertArtifact failed: %v", err) - } - - recent, err := db.GetRecentlyCachedPackages(10) - if err != nil { - t.Fatalf("GetRecentlyCachedPackages failed: %v", err) - } - if len(recent) != 1 { - t.Fatalf("expected 1 recent package, got %d", len(recent)) - } - const want = "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1" - if recent[0].Version != want { - t.Errorf("Version = %q, want %q", recent[0].Version, want) - } - if recent[0].VersionPURL != versionPURL { - t.Errorf("VersionPURL = %q, want %q", recent[0].VersionPURL, versionPURL) - } - }) -} diff --git a/internal/enrichment/enrichment.go b/internal/enrichment/enrichment.go index db8cc13..247dd2b 100644 --- a/internal/enrichment/enrichment.go +++ b/internal/enrichment/enrichment.go @@ -9,7 +9,6 @@ import ( "sync" "time" - "github.com/git-pkgs/proxy/internal/packageurl" "github.com/git-pkgs/purl" "github.com/git-pkgs/registries" _ "github.com/git-pkgs/registries/all" // Import all registry implementations @@ -68,10 +67,7 @@ type VulnInfo struct { // EnrichPackage fetches metadata for a package from registry APIs. func (s *Service) EnrichPackage(ctx context.Context, ecosystem, name string) (*PackageInfo, error) { - purlStr := packageurl.MakeString(ecosystem, name, "") - if purlStr == "" { - return nil, nil - } + purlStr := purl.MakePURLString(ecosystem, name, "") pkg, err := registries.FetchPackageFromPURL(ctx, purlStr, s.regClient) if err != nil { @@ -106,10 +102,7 @@ func (s *Service) EnrichPackage(ctx context.Context, ecosystem, name string) (*P // EnrichVersion fetches metadata for a specific package version. func (s *Service) EnrichVersion(ctx context.Context, ecosystem, name, version string) (*VersionInfo, error) { - purlStr := packageurl.MakeString(ecosystem, name, version) - if purlStr == "" { - return nil, nil - } + purlStr := purl.MakePURLString(ecosystem, name, version) ver, err := registries.FetchVersionFromPURL(ctx, purlStr, s.regClient) if err != nil { @@ -141,14 +134,9 @@ func (s *Service) EnrichVersion(ctx context.Context, ecosystem, name, version st // BulkEnrichPackages fetches metadata for multiple packages in parallel. func (s *Service) BulkEnrichPackages(ctx context.Context, packages []struct{ Ecosystem, Name string }) map[string]*PackageInfo { - purls := make([]string, 0, len(packages)) - for _, pkg := range packages { - if purlStr := packageurl.MakeString(pkg.Ecosystem, pkg.Name, ""); purlStr != "" { - purls = append(purls, purlStr) - } - } - if len(purls) == 0 { - return map[string]*PackageInfo{} + purls := make([]string, len(packages)) + for i, pkg := range packages { + purls[i] = purl.MakePURLString(pkg.Ecosystem, pkg.Name, "") } pkgData := registries.BulkFetchPackages(ctx, purls, s.regClient) @@ -159,10 +147,7 @@ func (s *Service) BulkEnrichPackages(ctx context.Context, packages []struct{ Eco continue } - p, err := purl.Parse(purlStr) - if err != nil { - continue - } + p, _ := purl.Parse(purlStr) info := &PackageInfo{ Ecosystem: p.Type, Name: pkg.Name, @@ -189,10 +174,7 @@ func (s *Service) BulkEnrichPackages(ctx context.Context, packages []struct{ Eco // CheckVulnerabilities queries for vulnerabilities affecting a package version. func (s *Service) CheckVulnerabilities(ctx context.Context, ecosystem, name, version string) ([]VulnInfo, error) { - p := packageurl.Make(ecosystem, name, version) - if p == nil { - return nil, nil - } + p := purl.MakePURL(ecosystem, name, version) vulnList, err := s.vulnSource.Query(ctx, p) if err != nil { @@ -219,6 +201,43 @@ func (s *Service) CheckVulnerabilities(ctx context.Context, ecosystem, name, ver return results, nil } +// BulkCheckVulnerabilities queries vulnerabilities for multiple package versions. +func (s *Service) BulkCheckVulnerabilities(ctx context.Context, packages []struct{ Ecosystem, Name, Version string }) (map[string][]VulnInfo, error) { + purls := make([]*purl.PURL, len(packages)) + for i, pkg := range packages { + purls[i] = purl.MakePURL(pkg.Ecosystem, pkg.Name, pkg.Version) + } + + vulnResults, err := s.vulnSource.QueryBatch(ctx, purls) + if err != nil { + return nil, err + } + + result := make(map[string][]VulnInfo, len(packages)) + for i, vulnList := range vulnResults { + pkg := packages[i] + key := purl.MakePURLString(pkg.Ecosystem, pkg.Name, pkg.Version) + + var infos []VulnInfo + for _, v := range vulnList { + info := VulnInfo{ + ID: v.ID, + Summary: v.Summary, + Severity: v.SeverityLevel(), + CVSSScore: v.CVSSScore(), + FixedVersion: v.FixedVersion(pkg.Ecosystem, pkg.Name), + } + for _, ref := range v.References { + info.References = append(info.References, ref.URL) + } + infos = append(infos, info) + } + result[key] = infos + } + + return result, nil +} + // IsOutdated checks if a version is older than the latest version. func (s *Service) IsOutdated(currentVersion, latestVersion string) bool { if latestVersion == "" || currentVersion == "" { @@ -229,10 +248,7 @@ func (s *Service) IsOutdated(currentVersion, latestVersion string) bool { // GetLatestVersion fetches the latest version for a package. func (s *Service) GetLatestVersion(ctx context.Context, ecosystem, name string) (string, error) { - purlStr := packageurl.MakeString(ecosystem, name, "") - if purlStr == "" { - return "", nil - } + purlStr := purl.MakePURLString(ecosystem, name, "") latest, err := registries.FetchLatestVersionFromPURL(ctx, purlStr, s.regClient) if err != nil { @@ -272,6 +288,19 @@ func (s *Service) CategorizeLicense(license string) LicenseCategory { return LicenseUnknown } +// NormalizeLicense normalizes a license string to SPDX format. +func (s *Service) NormalizeLicense(license string) string { + if license == "" { + return "" + } + + if normalized, err := spdx.NormalizeExpressionLax(license); err == nil { + return normalized + } + + return license +} + // EnrichmentResult contains all enrichment data for a package version. type EnrichmentResult struct { Package *PackageInfo diff --git a/internal/enrichment/enrichment_test.go b/internal/enrichment/enrichment_test.go index 3952eb2..aa9a16e 100644 --- a/internal/enrichment/enrichment_test.go +++ b/internal/enrichment/enrichment_test.go @@ -1,7 +1,6 @@ package enrichment import ( - "context" "log/slog" "os" "testing" @@ -24,36 +23,6 @@ func TestNew(t *testing.T) { } } -func TestSwiftRegistryIdentitySkipsPURLDependentLookups(t *testing.T) { - svc := New(slog.New(slog.NewTextHandler(os.Stdout, nil))) - ctx := context.Background() - - packageInfo, err := svc.EnrichPackage(ctx, "swift", "apple/example") - if err != nil || packageInfo != nil { - t.Errorf("EnrichPackage() = %#v, %v; want nil, nil", packageInfo, err) - } - - versionInfo, err := svc.EnrichVersion(ctx, "swift", "apple/example", "1.2.3") - if err != nil || versionInfo != nil { - t.Errorf("EnrichVersion() = %#v, %v; want nil, nil", versionInfo, err) - } - - vulnerabilities, err := svc.CheckVulnerabilities(ctx, "swift", "apple/example", "1.2.3") - if err != nil || vulnerabilities != nil { - t.Errorf("CheckVulnerabilities() = %#v, %v; want nil, nil", vulnerabilities, err) - } - - latest, err := svc.GetLatestVersion(ctx, "swift", "apple/example") - if err != nil || latest != "" { - t.Errorf("GetLatestVersion() = %q, %v; want empty string, nil", latest, err) - } - - packages := []struct{ Ecosystem, Name string }{{Ecosystem: "swift", Name: "apple/example"}} - if got := svc.BulkEnrichPackages(ctx, packages); len(got) != 0 { - t.Errorf("BulkEnrichPackages() = %#v, want empty result", got) - } -} - func TestIsOutdated(t *testing.T) { logger := slog.New(slog.NewTextHandler(os.Stdout, nil)) svc := New(logger) @@ -105,3 +74,25 @@ func TestCategorizeLicense(t *testing.T) { } } } + +func TestNormalizeLicense(t *testing.T) { + logger := slog.New(slog.NewTextHandler(os.Stdout, nil)) + svc := New(logger) + + tests := []struct { + input string + expected string + }{ + {"MIT", "MIT"}, + {"Apache 2", "Apache-2.0"}, + {"Apache-2.0", "Apache-2.0"}, + {"", ""}, + } + + for _, tc := range tests { + result := svc.NormalizeLicense(tc.input) + if result != tc.expected { + t.Errorf("NormalizeLicense(%q) = %q, want %q", tc.input, result, tc.expected) + } + } +} diff --git a/internal/handler/apk.go b/internal/handler/apk.go deleted file mode 100644 index 9acc3cc..0000000 --- a/internal/handler/apk.go +++ /dev/null @@ -1,186 +0,0 @@ -package handler - -import ( - "crypto/sha256" - "encoding/hex" - "net/http" - "regexp" - "strings" -) - -const ( - apkEcosystem = "alpine" - // defaultAPKRepositoryName is the repository name used when no - // upstream.apk repositories are configured. - defaultAPKRepositoryName = "alpine" - // defaultAPKUpstream is the official Alpine Linux mirror. - defaultAPKUpstream = "https://dl-cdn.alpinelinux.org/alpine" - apkMatchCount = 3 // full match + name + version -) - -// APKHandler handles Alpine APK repository protocol requests. Each configured -// upstream repository is mounted at /apk/{repository}/ and the remaining path -// mirrors the upstream layout ({release}/{repo}/{arch}/{file}). -// -// Repository indexes (v2 APKINDEX.tar.gz, v3 Packages.adb) and detached -// signatures are served byte-for-byte unchanged through the metadata cache so -// apk signature verification keeps working. Package files are cached in the -// shared artifact cache and stay available when the upstream is unreachable. -type APKHandler struct { - proxy *Proxy - proxyURL string - repositories map[string]string -} - -// NewAPKHandler creates an Alpine APK repository protocol handler. -// When repositories is empty, a single repository named "alpine" pointing at -// the official Alpine mirror is used. -func NewAPKHandler(proxy *Proxy, proxyURL string, repositories map[string]string) *APKHandler { - h := &APKHandler{ - proxy: proxy, - proxyURL: strings.TrimSuffix(proxyURL, "/"), - repositories: make(map[string]string, len(repositories)), - } - for name, repositoryURL := range repositories { - h.repositories[name] = strings.TrimSuffix(repositoryURL, "/") - } - if len(h.repositories) == 0 { - h.repositories[defaultAPKRepositoryName] = defaultAPKUpstream - } - return h -} - -// Routes returns the HTTP handler for APK requests. -// Mount this at /apk on your router. -func (h *APKHandler) Routes() http.Handler { - return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.Method != http.MethodGet && r.Method != http.MethodHead { - http.Error(w, "method not allowed", http.StatusMethodNotAllowed) - return - } - - path := strings.TrimPrefix(r.URL.Path, "/") - - if containsPathTraversal(path) { - http.Error(w, "invalid path", http.StatusBadRequest) - return - } - - repository, rest, ok := strings.Cut(path, "/") - upstreamURL, found := h.repositories[repository] - if !ok || rest == "" || !found { - http.NotFound(w, r) - return - } - - switch { - case isAPKIndex(rest) || isAPKSignature(rest): - // Indexes and detached signatures are signed upstream metadata. - // Cache them with the metadata TTL and serve the stored bytes - // unchanged so apk verification continues to work. - h.handleMetadata(w, r, repository, upstreamURL, rest) - case strings.HasSuffix(rest, ".apk"): - // Package downloads - cache these in the artifact cache. - h.handlePackageDownload(w, r, repository, upstreamURL, rest) - default: - // Other files - proxy directly. - h.proxyFile(w, r, upstreamURL, rest) - } - }) -} - -// isAPKIndex reports whether the path names a repository index: -// APKINDEX.tar.gz (apk v2) or Packages.adb (apk v3). -func isAPKIndex(path string) bool { - base := path[strings.LastIndex(path, "/")+1:] - return base == "APKINDEX.tar.gz" || base == "Packages.adb" -} - -// isAPKSignature reports whether the path names a detached signature file. -func isAPKSignature(path string) bool { - return strings.HasSuffix(path, ".sig") || strings.HasSuffix(path, ".rsa.pub") -} - -// handlePackageDownload fetches and caches .apk packages. -// Path format: {release}/{repo}/{arch}/{name}-{version}-r{rel}.apk -// Example: v3.22/main/x86_64/busybox-1.37.0-r12.apk -// -// APK filenames do not include the architecture, so the same filename can hold -// different bytes per architecture (and per release). The full request path is -// therefore part of the cache identity. -func (h *APKHandler) handlePackageDownload(w http.ResponseWriter, r *http.Request, repository, upstreamURL, path string) { - name, version, arch := h.parseAPKPath(path) - if name == "" { - // Can't parse, just proxy directly - h.proxyFile(w, r, upstreamURL, path) - return - } - - downloadURL := upstreamURL + "/" + path - cacheFilename := repository + "/" + path - - h.proxy.Logger.Info("apk package download", - "repository", repository, "name", name, "version", version, "arch", arch) - - result, err := h.proxy.GetOrFetchArtifactFromURL( - r.Context(), apkEcosystem, name, version, cacheFilename, downloadURL) - if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch package") - return - } - - if result.Artifact.MediaType == "" { - result.Artifact.MediaType = "application/octet-stream" - } - serveArtifact(w, r.Method, result) -} - -// handleMetadata serves repository indexes and signatures through the -// metadata cache. Stored bytes are re-served verbatim, which keeps embedded -// and detached signatures valid. -func (h *APKHandler) handleMetadata(w http.ResponseWriter, r *http.Request, repository, upstreamURL, path string) { - h.proxy.ProxyCached(w, r, upstreamURL+"/"+path, apkEcosystem, - h.metadataCacheKey(repository, upstreamURL, path), "*/*") -} - -// metadataCacheKey derives the metadata cache key from the repository name, -// its upstream URL, and the request path. Hashing the identity keeps distinct -// repositories from sharing cache entries (repository names may contain '_' -// and a separator-based key would be ambiguous) and drops cached entries when -// a repository is repointed at a different upstream, mirroring -// HelmHandler.indexCacheKey. -func (h *APKHandler) metadataCacheKey(repository, upstreamURL, path string) string { - identity := repository + "\x00" + upstreamURL + "\x00" + path - digest := sha256.Sum256([]byte(identity)) - return hex.EncodeToString(digest[:]) -} - -// proxyFile proxies any file directly without caching. -func (h *APKHandler) proxyFile(w http.ResponseWriter, r *http.Request, upstreamURL, path string) { - h.proxy.ProxyFile(w, r, upstreamURL+"/"+path) -} - -// apkPackagePattern matches .apk filenames to extract name and version. -// Format: {name}-{version}-r{rel}.apk where version starts with a digit. -// Examples: -// - busybox-1.37.0-r12.apk -// - alpine-baselayout-data-3.7.0-r0.apk -var apkPackagePattern = regexp.MustCompile(`^(.+)-(\d[^-]*-r\d+)\.apk$`) - -// parseAPKPath extracts package info from a path containing an APK filename. -// The architecture is taken from the parent directory since APK filenames do -// not include it. -func (h *APKHandler) parseAPKPath(path string) (name, version, arch string) { - segments := strings.Split(path, "/") - filename := segments[len(segments)-1] - if len(segments) > 1 { - arch = segments[len(segments)-2] - } - - matches := apkPackagePattern.FindStringSubmatch(filename) - if len(matches) != apkMatchCount { - return "", "", "" - } - - return matches[1], matches[2], arch -} diff --git a/internal/handler/apk_test.go b/internal/handler/apk_test.go deleted file mode 100644 index 77e1da5..0000000 --- a/internal/handler/apk_test.go +++ /dev/null @@ -1,362 +0,0 @@ -package handler - -import ( - "fmt" - "net/http" - "net/http/httptest" - "sync/atomic" - "testing" - "time" - - "github.com/git-pkgs/registries/fetch" -) - -func TestAPKHandler_parseAPKPath(t *testing.T) { - h := &APKHandler{} - - assertPathParser(t, "parseAPKPath", h.parseAPKPath, []pathParseCase{ - {"v3.22/main/x86_64/busybox-1.37.0-r12.apk", "busybox", "1.37.0-r12", "x86_64"}, - {"v3.22/main/aarch64/alpine-baselayout-data-3.7.0-r0.apk", "alpine-baselayout-data", "3.7.0-r0", "aarch64"}, - {"edge/community/x86_64/openjdk21-jre-21.0.2_p13-r1.apk", "openjdk21-jre", "21.0.2_p13-r1", "x86_64"}, - {"busybox-1.37.0-r12.apk", "busybox", "1.37.0-r12", ""}, - {"v3.22/main/x86_64/invalid.apk", "", "", ""}, - {"v3.22/main/x86_64/not-an-apk-file", "", "", ""}, - }) -} - -func TestAPKHandler_Routes(t *testing.T) { - h := NewAPKHandler(nil, "http://localhost:8080", nil) - assertRoutesBasics(t, h.Routes(), "/alpine/v3.22/main/x86_64/APKINDEX.tar.gz", "/alpine/v3.22/../../../etc/passwd") -} - -func TestAPKHandler_DefaultsToOfficialMirror(t *testing.T) { - h := NewAPKHandler(nil, "http://localhost:8080", nil) - if got := h.repositories[defaultAPKRepositoryName]; got != defaultAPKUpstream { - t.Errorf("default repository = %q, want %q", got, defaultAPKUpstream) - } -} - -func TestAPKHandler_UnknownRepositoryReturns404(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - h := NewAPKHandler(proxy, "http://localhost:8080", map[string]string{"alpine": "https://example.test"}) - - for _, target := range []string{ - "/unknown/v3.22/main/x86_64/APKINDEX.tar.gz", - "/alpine", - "/", - } { - w := serveAPKRequest(h, target) - if w.Code != http.StatusNotFound { - t.Errorf("%s: status = %d, want 404", target, w.Code) - } - } -} - -// TestAPKHandler_MetadataCacheKeysDoNotCollideAcrossRepositories guards the -// hashed metadata cache key: with a separator-based key, repositories named -// "alpine" and "alpine_edge" would share cache entries for -// /alpine/edge/main/x86_64/APKINDEX.tar.gz and -// /alpine_edge/main/x86_64/APKINDEX.tar.gz, serving one repository's signed -// index to clients of the other. -func TestAPKHandler_MetadataCacheKeysDoNotCollideAcrossRepositories(t *testing.T) { - indexA := "signed index of repository A" - upstreamA := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path != "/edge/main/x86_64/APKINDEX.tar.gz" { - http.NotFound(w, r) - return - } - _, _ = fmt.Fprint(w, indexA) - })) - defer upstreamA.Close() - - indexB := "signed index of repository B" - upstreamB := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path != "/main/x86_64/APKINDEX.tar.gz" { - http.NotFound(w, r) - return - } - _, _ = fmt.Fprint(w, indexB) - })) - defer upstreamB.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = http.DefaultClient - - h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{ - "alpine": upstreamA.URL, - "alpine_edge": upstreamB.URL, - }) - - first := serveAPKRequest(h, "/alpine/edge/main/x86_64/APKINDEX.tar.gz") - if first.Code != http.StatusOK || first.Body.String() != indexA { - t.Fatalf("repository A: status = %d, body = %q, want 200 %q", first.Code, first.Body.String(), indexA) - } - - // Served within the metadata TTL: a colliding key would return indexA here. - second := serveAPKRequest(h, "/alpine_edge/main/x86_64/APKINDEX.tar.gz") - if second.Code != http.StatusOK { - t.Fatalf("repository B: status = %d, want 200: %s", second.Code, second.Body.String()) - } - if second.Body.String() != indexB { - t.Errorf("repository B served %q, want %q (cache key collision)", second.Body.String(), indexB) - } -} - -// TestAPKHandler_IndexesServedUnchanged covers v2 (APKINDEX.tar.gz) and v3 -// (Packages.adb) indexes plus detached signatures: bytes must be served -// unchanged so apk signature verification keeps working, and within the -// metadata TTL cached copies must be served without contacting the upstream -// (the stale-after-TTL fallback itself is covered by the shared ProxyCached -// tests). -func TestAPKHandler_IndexesServedUnchanged(t *testing.T) { - files := map[string][]byte{ - "/v3.22/main/x86_64/APKINDEX.tar.gz": []byte("\x1f\x8b\x08v2-index-with-embedded-signature"), - "/v3.22/main/x86_64/Packages.adb": []byte("ADB.v3-index-binary\x00payload"), - "/v3.22/main/x86_64/Packages.adb.sig": []byte("detached-signature-bytes"), - } - - var available atomic.Bool - available.Store(true) - var upstreamRequests atomic.Int32 - var authHeader string - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if !available.Load() { - http.Error(w, "unavailable", http.StatusServiceUnavailable) - return - } - authHeader = r.Header.Get("Authorization") - data, ok := files[r.URL.Path] - if !ok { - http.NotFound(w, r) - return - } - upstreamRequests.Add(1) - w.Header().Set("Content-Type", "application/octet-stream") - _, _ = w.Write(data) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = upstream.Client() - proxy.AuthForURL = func(string) (string, string) { - return "Authorization", "Bearer apk-token" - } - - h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{"alpine": upstream.URL}) - - for path, want := range files { - w := serveAPKRequest(h, "/alpine"+path) - if w.Code != http.StatusOK { - t.Fatalf("%s: status = %d, want 200: %s", path, w.Code, w.Body.String()) - } - if got := w.Body.Bytes(); string(got) != string(want) { - t.Errorf("%s: body altered:\ngot %q\nwant %q", path, got, want) - } - } - if authHeader != "Bearer apk-token" { - t.Errorf("Authorization = %q, want %q", authHeader, "Bearer apk-token") - } - - // Upstream goes away: cached indexes must still be served, unchanged. - available.Store(false) - requestsBefore := upstreamRequests.Load() - for path, want := range files { - w := serveAPKRequest(h, "/alpine"+path) - if w.Code != http.StatusOK { - t.Fatalf("%s offline: status = %d, want 200: %s", path, w.Code, w.Body.String()) - } - if got := w.Body.Bytes(); string(got) != string(want) { - t.Errorf("%s offline: body altered:\ngot %q\nwant %q", path, got, want) - } - } - if got := upstreamRequests.Load(); got != requestsBefore { - t.Errorf("upstream requests during offline reads = %d, want %d", got, requestsBefore) - } -} - -// TestAPKHandler_PackageDownloadCachesPerArch covers package downloads, cache -// hits, offline reads, and that identically named packages for different -// architectures are cached separately. -func TestAPKHandler_PackageDownloadCachesPerArch(t *testing.T) { - packages := map[string][]byte{ - "/v3.22/main/x86_64/busybox-1.37.0-r12.apk": []byte("x86_64 package bytes"), - "/v3.22/main/aarch64/busybox-1.37.0-r12.apk": []byte("aarch64 package bytes"), - } - - var available atomic.Bool - available.Store(true) - var packageRequests atomic.Int32 - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if !available.Load() { - http.Error(w, "unavailable", http.StatusServiceUnavailable) - return - } - data, ok := packages[r.URL.Path] - if !ok { - http.NotFound(w, r) - return - } - packageRequests.Add(1) - w.Header().Set("Content-Type", "application/octet-stream") - _, _ = w.Write(data) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0)) - proxy.Fetcher = fetcher - t.Cleanup(func() { _ = fetcher.Close() }) - - h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{"alpine": upstream.URL}) - - for path, want := range packages { - w := serveAPKRequest(h, "/alpine"+path) - if w.Code != http.StatusOK { - t.Fatalf("%s: status = %d, want 200: %s", path, w.Code, w.Body.String()) - } - if got := w.Body.String(); got != string(want) { - t.Errorf("%s: body = %q, want %q", path, got, want) - } - } - if got := packageRequests.Load(); got != 2 { - t.Fatalf("upstream package requests = %d, want 2 (one per architecture)", got) - } - - // Second round must be served from cache, even with the upstream down. - available.Store(false) - for path, want := range packages { - w := serveAPKRequest(h, "/alpine"+path) - if w.Code != http.StatusOK { - t.Fatalf("%s cached: status = %d, want 200: %s", path, w.Code, w.Body.String()) - } - if got := w.Body.String(); got != string(want) { - t.Errorf("%s cached: body = %q, want %q", path, got, want) - } - } - if got := packageRequests.Load(); got != 2 { - t.Errorf("upstream package requests after cache hits = %d, want 2", got) - } -} - -func TestAPKHandler_PackageDownloadSendsUpstreamAuth(t *testing.T) { - var authHeader string - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - authHeader = r.Header.Get("Authorization") - if authHeader != "Bearer apk-token" { - w.WriteHeader(http.StatusUnauthorized) - return - } - _, _ = fmt.Fprint(w, "private package") - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - client := upstream.Client() - client.Transport = &authRoundTripper{base: client.Transport, header: "Authorization", value: "Bearer apk-token"} - fetcher := fetch.NewFetcher(fetch.WithHTTPClient(client), fetch.WithMaxRetries(0)) - proxy.Fetcher = fetcher - t.Cleanup(func() { _ = fetcher.Close() }) - - h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{"private": upstream.URL}) - - w := serveAPKRequest(h, "/private/v3.22/main/x86_64/busybox-1.37.0-r12.apk") - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String()) - } - if w.Body.String() != "private package" { - t.Errorf("body = %q, want %q", w.Body.String(), "private package") - } - if authHeader != "Bearer apk-token" { - t.Errorf("Authorization = %q, want %q", authHeader, "Bearer apk-token") - } -} - -func TestAPKHandler_UnparseablePackageProxiedDirectly(t *testing.T) { - var requested string - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - requested = r.URL.Path - _, _ = fmt.Fprint(w, "raw bytes") - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - - h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{"alpine": upstream.URL}) - - w := serveAPKRequest(h, "/alpine/v3.22/main/x86_64/no-version.apk") - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String()) - } - if requested != "/v3.22/main/x86_64/no-version.apk" { - t.Errorf("upstream path = %q, want %q", requested, "/v3.22/main/x86_64/no-version.apk") - } - if w.Body.String() != "raw bytes" { - t.Errorf("body = %q, want %q", w.Body.String(), "raw bytes") - } -} - -// authRoundTripper adds a static auth header, mimicking the server's -// authentication-aware upstream transport. -type authRoundTripper struct { - base http.RoundTripper - header string - value string -} - -func (a *authRoundTripper) RoundTrip(req *http.Request) (*http.Response, error) { - req = req.Clone(req.Context()) - req.Header.Set(a.header, a.value) - base := a.base - if base == nil { - base = http.DefaultTransport - } - return base.RoundTrip(req) -} - -// TestAPKHandler_PackageHeadOmitsBody verifies that HEAD requests for cached -// packages return headers (including Content-Length) without a body. -func TestAPKHandler_PackageHeadOmitsBody(t *testing.T) { - pkg := []byte("package bytes") - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - w.Header().Set("Content-Type", "application/octet-stream") - _, _ = w.Write(pkg) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0)) - proxy.Fetcher = fetcher - t.Cleanup(func() { _ = fetcher.Close() }) - - h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{"alpine": upstream.URL}) - - target := "/alpine/v3.22/main/x86_64/busybox-1.37.0-r12.apk" - if w := serveAPKRequest(h, target); w.Code != http.StatusOK { - t.Fatalf("seeding GET: status = %d, want 200: %s", w.Code, w.Body.String()) - } - - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodHead, target, nil)) - if w.Code != http.StatusOK { - t.Fatalf("HEAD: status = %d, want 200: %s", w.Code, w.Body.String()) - } - if got := w.Body.Len(); got != 0 { - t.Errorf("HEAD body length = %d, want 0", got) - } - if got := w.Header().Get("Content-Length"); got != fmt.Sprint(len(pkg)) { - t.Errorf("HEAD Content-Length = %q, want %d", got, len(pkg)) - } -} - -func serveAPKRequest(h *APKHandler, target string) *httptest.ResponseRecorder { - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, target, nil)) - return w -} diff --git a/internal/handler/cargo.go b/internal/handler/cargo.go index 4cf8591..5d7810c 100644 --- a/internal/handler/cargo.go +++ b/internal/handler/cargo.go @@ -6,9 +6,10 @@ import ( "errors" "fmt" "net/http" - "net/url" "strings" "time" + + "github.com/git-pkgs/purl" ) const ( @@ -29,18 +30,11 @@ type CargoHandler struct { } // NewCargoHandler creates a new cargo protocol handler. -func NewCargoHandler(proxy *Proxy, proxyURL, indexURL, downloadURL string) *CargoHandler { - if strings.TrimSpace(indexURL) == "" { - indexURL = cargoUpstream - } - if strings.TrimSpace(downloadURL) == "" { - downloadURL = cargoDownloadBase - } - +func NewCargoHandler(proxy *Proxy, proxyURL string) *CargoHandler { return &CargoHandler{ proxy: proxy, - indexURL: strings.TrimSuffix(indexURL, "/"), - downloadURL: strings.TrimSuffix(downloadURL, "/"), + indexURL: cargoUpstream, + downloadURL: cargoDownloadBase, proxyURL: strings.TrimSuffix(proxyURL, "/"), } } @@ -80,7 +74,7 @@ func (h *CargoHandler) handleConfig(w http.ResponseWriter, r *http.Request) { DL: h.proxyURL + "/cargo/crates/{crate}/{version}/download", } - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") _ = json.NewEncoder(w).Encode(config) } @@ -112,7 +106,7 @@ func (h *CargoHandler) handleIndex(w http.ResponseWriter, r *http.Request) { contentType = "text/plain; charset=utf-8" } - w.Header().Set(headerContentType, contentType) + w.Header().Set("Content-Type", contentType) w.WriteHeader(http.StatusOK) h.applyCooldownFiltering(w, body) } @@ -149,7 +143,7 @@ func (h *CargoHandler) applyCooldownFiltering(downstreamResponse http.ResponseWr continue } - cratePURL := canonicalPackagePURL("cargo", crate.Name) + cratePURL := purl.MakePURLString("cargo", crate.Name, "") if !h.proxy.Cooldown.IsAllowed("cargo", cratePURL, publishedAt) { h.proxy.Logger.Info("cooldown: filtering cargo version", @@ -197,17 +191,10 @@ func (h *CargoHandler) handleDownload(w http.ResponseWriter, r *http.Request) { h.proxy.Logger.Info("cargo download request", "crate", name, "version", version, "filename", filename) - downloadURL := fmt.Sprintf( - "%s/%s/%s", - h.downloadURL, - url.PathEscape(name), - url.PathEscape(filename), - ) - result, err := h.proxy.GetOrFetchArtifactFromURL( - r.Context(), "cargo", name, version, filename, downloadURL, - ) + result, err := h.proxy.GetOrFetchArtifact(r.Context(), "cargo", name, version, filename) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch crate") + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch crate", http.StatusBadGateway) return } diff --git a/internal/handler/cargo_test.go b/internal/handler/cargo_test.go index 895ff7b..5ce81b6 100644 --- a/internal/handler/cargo_test.go +++ b/internal/handler/cargo_test.go @@ -2,7 +2,6 @@ package handler import ( "encoding/json" - "io" "log/slog" "net/http" "net/http/httptest" @@ -10,8 +9,7 @@ import ( "testing" "time" - "github.com/git-pkgs/cooldown" - "github.com/git-pkgs/registries/fetch" + "github.com/git-pkgs/proxy/internal/cooldown" ) func cargoTestProxy() *Proxy { @@ -72,75 +70,6 @@ func TestCargoConfigEndpoint(t *testing.T) { } } -func TestCargoHandlerUsesConfiguredUpstreams(t *testing.T) { - t.Run("index", func(t *testing.T) { - var requestPath, authHeader string - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - requestPath = r.URL.Path - authHeader = r.Header.Get("Authorization") - if authHeader != "Bearer cargo-token" { - w.WriteHeader(http.StatusUnauthorized) - return - } - w.Header().Set("Content-Type", "text/plain") - _, _ = io.WriteString(w, `{"name":"serde","vers":"1.0.0"}`) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.AuthForURL = func(string) (string, string) { - return "Authorization", "Bearer cargo-token" - } - h := NewCargoHandler( - proxy, - "http://proxy.test", - upstream.URL+"/index/", - "https://crates.example.test/files/", - ) - - req := httptest.NewRequest(http.MethodGet, "/se/rd/serde", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) - } - if requestPath != "/index/se/rd/serde" { - t.Errorf("upstream path = %q, want %q", requestPath, "/index/se/rd/serde") - } - if authHeader != "Bearer cargo-token" { - t.Errorf("Authorization = %q, want %q", authHeader, "Bearer cargo-token") - } - }) - - t.Run("download", func(t *testing.T) { - proxy, _, _, artifactFetcher := setupTestProxy(t) - artifactFetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("crate")), - ContentType: "application/gzip", - } - h := NewCargoHandler( - proxy, - "http://proxy.test", - "https://index.example.test/root/", - "https://crates.example.test/files/", - ) - - req := httptest.NewRequest(http.MethodGet, "/crates/serde/1.0.0/download", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) - } - want := "https://crates.example.test/files/serde/serde-1.0.0.crate" - if artifactFetcher.fetchedURL != want { - t.Errorf("fetched URL = %q, want %q", artifactFetcher.fetchedURL, want) - } - }) -} - func TestCargoIndexProxy(t *testing.T) { // Create a mock upstream index server indexContent := `{"name":"serde","vers":"1.0.0","deps":[],"cksum":"abc123"} diff --git a/internal/handler/coalesce_semantics_test.go b/internal/handler/coalesce_semantics_test.go deleted file mode 100644 index c391d74..0000000 --- a/internal/handler/coalesce_semantics_test.go +++ /dev/null @@ -1,615 +0,0 @@ -package handler - -import ( - "context" - "errors" - "io" - "strings" - "sync" - "testing" - "time" - - "github.com/git-pkgs/artifacts" - "github.com/git-pkgs/registries/fetch" -) - -// runConcurrent runs fn in n goroutines released together and returns their errors. -func runConcurrent(n int, fn func(i int) error) []error { - errs := make([]error, n) - start := make(chan struct{}) - var wg sync.WaitGroup - for i := 0; i < n; i++ { - wg.Add(1) - go func(i int) { - defer wg.Done() - <-start - errs[i] = fn(i) - }(i) - } - close(start) - wg.Wait() - return errs -} - -// artifactBody builds a one-shot upstream artifact carrying the given bytes. -func artifactBody(content string) *fetch.Artifact { - return &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader(content)), - ContentType: "application/gzip", - } -} - -// drain consumes and closes a CacheResult reader, if there is one. -func drain(res *CacheResult) { - if res != nil && res.Reader != nil { - _, _ = io.Copy(io.Discard, res.Reader) - _ = res.Reader.Close() - } -} - -// TestCoalesceKey_DifferentUpstreamHashDoesNotShare is the safety property that -// makes coalescing sound: callers expecting different bytes must never share a -// fetch, so a re-published version cannot serve stale bytes to a caller that -// asked for the new digest. -func TestCoalesceKey_DifferentUpstreamHashDoesNotShare(t *testing.T) { - const content = "artifact bytes" - proxy, _, _, _ := setupTestProxy(t) - fetcher := &countingFetcher{content: content, delay: fetchHoldTime} - proxy.Fetcher = fetcher - - // The digest must carry the "sha256:" prefix; without it the API treats the - // value as unverifiable and clears the hash, which would legitimately let - // the two callers share one fetch. - hashes := []string{ - "sha256:" + sha256Hex(content), - "sha256:" + sha256Hex("something else entirely"), - } - - _ = runConcurrent(2, func(i int) error { - res, err := proxy.GetOrFetchArtifactFromURLWithDigest(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", - "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz", hashes[i]) - drain(res) - return err - }) - - if got := fetcher.calls.Load(); got != 2 { - t.Errorf("upstream fetches = %d, want 2: callers expecting different digests must not share a fetch", got) - } -} - -// TestCoalesceKey_HashCasingSharesOneFetch is the other half of that property. -// artifactHashMatches compares digests case-insensitively, so one digest in two -// casings describes one artifact and must not split into two fetches. -func TestCoalesceKey_HashCasingSharesOneFetch(t *testing.T) { - const content = "artifact bytes" - proxy, _, _, _ := setupTestProxy(t) - fetcher := &countingFetcher{content: content, delay: fetchHoldTime} - proxy.Fetcher = fetcher - - hex := sha256Hex(content) - digests := []string{"sha256:" + hex, "sha256:" + strings.ToUpper(hex)} - - for i, err := range runConcurrent(2, func(i int) error { - res, err := proxy.GetOrFetchArtifactFromURLWithDigest(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", - "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz", digests[i]) - drain(res) - return err - }) { - if err != nil { - t.Fatalf("caller %d failed: %v", i, err) - } - } - - if got := fetcher.calls.Load(); got != 1 { - t.Errorf("upstream fetches = %d, want 1: one digest in two casings is one artifact", got) - } -} - -// TestCoalesceKey_DifferentDownloadURLDoesNotShare covers the other half of the -// key: same package, different upstream URL, must not collapse into one fetch. -func TestCoalesceKey_DifferentDownloadURLDoesNotShare(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - fetcher := &countingFetcher{content: "artifact bytes", delay: fetchHoldTime} - proxy.Fetcher = fetcher - - urls := []string{ - "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz", - "https://mirror.example.com/pkg/-/pkg-1.0.0.tgz", - } - - _ = runConcurrent(2, func(i int) error { - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", urls[i]) - drain(res) - return err - }) - - if got := fetcher.calls.Load(); got != 2 { - t.Errorf("upstream fetches = %d, want 2: different upstream URLs must not share a fetch", got) - } -} - -// TestCoalesceKey_DistinctArtifactsDoNotSerialize guards against an over-broad -// key: four packages fetched at once must still produce four fetches. -func TestCoalesceKey_DistinctArtifactsDoNotSerialize(t *testing.T) { - const n = 4 - proxy, _, _, _ := setupTestProxy(t) - fetcher := &countingFetcher{content: "artifact bytes", delay: fetchHoldTime} - proxy.Fetcher = fetcher - - names := []string{"alpha", "beta", "gamma", "delta"} - errs := runConcurrent(n, func(i int) error { - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", names[i], "1.0.0", names[i]+"-1.0.0.tgz", - "https://registry.npmjs.org/"+names[i]+"/-/"+names[i]+"-1.0.0.tgz") - drain(res) - return err - }) - for i, err := range errs { - if err != nil { - t.Errorf("caller %d (%s): %v", i, names[i], err) - } - } - if got := fetcher.calls.Load(); got != n { - t.Errorf("upstream fetches = %d, want %d: distinct artifacts must not share a fetch", got, n) - } -} - -// TestCoalesce_FailedFetchReachesEveryCallerAndIsRetriable verifies both claims -// in coalesceFetch's doc comment: a failed fetch reaches every caller sharing -// it, and the key is released so a later request retries. -func TestCoalesce_FailedFetchReachesEveryCallerAndIsRetriable(t *testing.T) { - const callers = 8 - proxy, _, _, fetcher := setupTestProxy(t) - boom := errors.New("upstream unavailable") - fetcher.fetchErr = boom - - errs := runConcurrent(callers, func(int) error { - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", - "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz") - drain(res) - return err - }) - for i, err := range errs { - if err == nil { - t.Errorf("caller %d: got nil error, want the shared fetch's failure", i) - } else if !errors.Is(err, boom) { - t.Errorf("caller %d: got %v, want it to wrap %v", i, err, boom) - } - } - - // The key must be released: a later request retries rather than inheriting - // the failure. - fetcher.fetchErr = nil - fetcher.artifact = artifactBody("recovered bytes") - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", - "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz") - if err != nil { - t.Fatalf("retry after failed coalesced fetch: %v", err) - } - body, _ := io.ReadAll(res.Reader) - _ = res.Reader.Close() - if string(body) != "recovered bytes" { - t.Errorf("retry body = %q, want %q", body, "recovered bytes") - } -} - -// TestCoalesce_ResolverPath covers the other entry point: GetOrFetchArtifact -// resolves the URL itself, so it is keyed without one. -func TestCoalesce_ResolverPath(t *testing.T) { - const callers = 8 - proxy, _, _, _ := setupTestProxy(t) - fetcher := &countingFetcher{content: "resolved artifact bytes", delay: fetchHoldTime} - proxy.Fetcher = fetcher - - errs := runConcurrent(callers, func(int) error { - res, err := proxy.GetOrFetchArtifact(context.Background(), - "npm", "left-pad", "1.3.0", "left-pad-1.3.0.tgz") - drain(res) - return err - }) - for i, err := range errs { - if err != nil { - t.Errorf("caller %d: %v", i, err) - } - } - if got := fetcher.calls.Load(); got != 1 { - t.Errorf("upstream fetches = %d, want 1", got) - } -} - -// TestCoalesce_ResolverPathEmptyFilename exercises that path when the filename -// is left to be resolved, which the key cannot know up front. -func TestCoalesce_ResolverPathEmptyFilename(t *testing.T) { - const callers = 8 - proxy, _, _, _ := setupTestProxy(t) - fetcher := &countingFetcher{content: "resolved artifact bytes", delay: fetchHoldTime} - proxy.Fetcher = fetcher - - errs := runConcurrent(callers, func(int) error { - res, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "left-pad", "1.3.0", "") - drain(res) - return err - }) - for i, err := range errs { - if err != nil { - t.Errorf("caller %d: %v", i, err) - } - } - if got := fetcher.calls.Load(); got != 1 { - t.Errorf("upstream fetches = %d, want 1", got) - } -} - -// TestCoalesce_SubsequentRequestIsACacheHit confirms the coalesced fetch was -// committed and is visible later, not just streamed to the waiting callers. -func TestCoalesce_SubsequentRequestIsACacheHit(t *testing.T) { - const callers = 8 - const url = "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz" - proxy, _, _, _ := setupTestProxy(t) - fetcher := &countingFetcher{content: "artifact bytes", delay: fetchHoldTime} - proxy.Fetcher = fetcher - - _ = runConcurrent(callers, func(int) error { - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url) - drain(res) - return err - }) - - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url) - if err != nil { - t.Fatalf("follow-up request: %v", err) - } - defer func() { _ = res.Reader.Close() }() - if !res.Cached { - t.Error("follow-up request should be served from cache") - } - if got := fetcher.calls.Load(); got != 1 { - t.Errorf("upstream fetches = %d, want 1 after a follow-up cache hit", got) - } -} - -// TestCoalesce_ReadersAreIndependent guards openStoredArtifact: callers sharing -// a fetch each need their own reader, or one closing early breaks the rest. -func TestCoalesce_ReadersAreIndependent(t *testing.T) { - const callers = 8 - const content = "artifact bytes that every caller must receive intact" - proxy, _, _, _ := setupTestProxy(t) - fetcher := &countingFetcher{content: content, delay: fetchHoldTime} - proxy.Fetcher = fetcher - - results := make([]*CacheResult, callers) - errs := runConcurrent(callers, func(i int) error { - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", - "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz") - results[i] = res - return err - }) - for i, err := range errs { - if err != nil { - t.Fatalf("caller %d: %v", i, err) - } - } - - // Close the first caller's reader before anyone else has read a byte. - _ = results[0].Reader.Close() - - for i := 1; i < callers; i++ { - body, err := io.ReadAll(results[i].Reader) - _ = results[i].Reader.Close() - if err != nil { - t.Errorf("caller %d read after another caller closed: %v", i, err) - continue - } - if string(body) != content { - t.Errorf("caller %d got %q, want %q", i, body, content) - } - } -} - -// TestCoalesce_CanceledWaiterDoesNotWaitForTheSharedFetch checks that joining a -// coalesced fetch does not cost a caller its own cancellation. Without the -// leader/waiter split a waiter is pinned until the shared fetch resolves, -// bounded only by the artifact client timeout, so clients that have already -// gone away keep handler goroutines alive for minutes. -func TestCoalesce_CanceledWaiterDoesNotWaitForTheSharedFetch(t *testing.T) { - const leaderFetch = 2 * time.Second - const url = "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz" - - proxy, _, _, _ := setupTestProxy(t) - fetcher := &countingFetcher{content: "artifact bytes", delay: leaderFetch, entered: make(chan struct{})} - proxy.Fetcher = fetcher - - leaderDone := make(chan error, 1) - go func() { - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url) - drain(res) - leaderDone <- err - }() - - select { - case <-fetcher.entered: // the leader holds the key and is inside its fetch - case <-time.After(5 * time.Second): - t.Fatal("leader never started its fetch") - } - ctx, cancel := context.WithCancel(context.Background()) - cancel() - - start := time.Now() - _, err := proxy.GetOrFetchArtifactFromURL(ctx, "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url) - blocked := time.Since(start) - - if !errors.Is(err, context.Canceled) { - t.Errorf("waiter error = %v, want context.Canceled", err) - } - if blocked > leaderFetch/4 { - t.Errorf("canceled waiter blocked %v, want well under %v: it is pinned to the shared fetch", - blocked, leaderFetch/4) - } - - // A waiter leaving must not disturb the fetch the others share. - if err := <-leaderDone; err != nil { - t.Fatalf("leader failed after a waiter canceled: %v", err) - } - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url) - if err != nil { - t.Fatalf("follow-up after leader completed: %v", err) - } - defer func() { _ = res.Reader.Close() }() - if !res.Cached { - t.Error("leader's fetch should have been committed to the cache") - } - if got := fetcher.calls.Load(); got != 1 { - t.Errorf("upstream fetches = %d, want 1", got) - } -} - -// inFlightLen reports how many coalesced fetches are currently registered. -func inFlightLen(p *Proxy) int { - p.fetchMu.Lock() - defer p.fetchMu.Unlock() - return len(p.inFlight) -} - -// TestCoalesce_KeyIsReleasedAfterFetch guards the bug this hand-rolled map can -// have that singleflight could not: a key left behind means later callers join -// a finished entry, see its closed done channel, and are served that stale -// result forever, while the map grows without bound. -func TestCoalesce_KeyIsReleasedAfterFetch(t *testing.T) { - const url = "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz" - proxy, _, _, _ := setupTestProxy(t) - fetcher := &countingFetcher{content: "artifact bytes", delay: fetchHoldTime} - proxy.Fetcher = fetcher - - _ = runConcurrent(8, func(int) error { - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url) - drain(res) - return err - }) - if n := inFlightLen(proxy); n != 0 { - t.Errorf("in-flight entries after a successful fetch = %d, want 0", n) - } - - // A fresh miss for the same key must start a new fetch, not rejoin the old - // entry. Clearing the cache record forces the miss path again. - if err := proxy.ClearCachedArtifact(context.Background(), "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz"); err != nil { - t.Fatalf("clear cached artifact: %v", err) - } - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url) - if err != nil { - t.Fatalf("second miss for the same key: %v", err) - } - drain(res) - if got := fetcher.calls.Load(); got != 2 { - t.Errorf("upstream fetches = %d, want 2: the second miss must not reuse the finished entry", got) - } - if n := inFlightLen(proxy); n != 0 { - t.Errorf("in-flight entries at end = %d, want 0", n) - } -} - -// missingFromCache is a recheck that always reports a miss, so the shared fetch -// runs. -func missingFromCache() (artifacts.Artifact, string, bool) { - return artifacts.Artifact{}, "", false -} - -// TestCoalesce_LeaderRechecksCacheBeforeFetching covers the window between a -// caller's own cache lookup and it becoming the leader: a concurrent fetch can -// commit the artifact in that gap, and the leader must serve that rather than -// fetch it a second time. -func TestCoalesce_LeaderRechecksCacheBeforeFetching(t *testing.T) { - const content = "artifact bytes" - proxy, _, store, _ := setupTestProxy(t) - - const storagePath = "npm/pkg/1.0.0/pkg-1.0.0.tgz" - if _, _, err := store.Store(context.Background(), storagePath, strings.NewReader(content)); err != nil { - t.Fatalf("seeding storage: %v", err) - } - committed := artifacts.Artifact{ - PURL: "pkg:npm/pkg@1.0.0", - Filename: "pkg-1.0.0.tgz", - Size: int64(len(content)), - } - - res, err := proxy.coalesceFetch(context.Background(), "any-key", - func() (artifacts.Artifact, string, bool) { return committed, storagePath, true }, - func(context.Context) (artifacts.Artifact, string, error) { - t.Error("fetched an artifact that was already in the cache") - return artifacts.Artifact{}, "", errors.New("commit must not run") - }) - if err != nil { - t.Fatalf("coalesceFetch failed: %v", err) - } - defer drain(res) - got, err := io.ReadAll(res.Reader) - if err != nil { - t.Fatalf("reading result: %v", err) - } - if string(got) != content { - t.Errorf("got %q, want %q", got, content) - } - if n := inFlightLen(proxy); n != 0 { - t.Errorf("in-flight entries = %d, want 0", n) - } -} - -// TestCachedArtifactRecord covers the recheck itself: it must report the row a -// concurrent fetch committed, match its digest the way artifactHashMatches -// does, and report a miss for anything else. -func TestCachedArtifactRecord(t *testing.T) { - const ( - content = "artifact bytes" - pkgPURL = "pkg:npm/pkg" - versionPURL = "pkg:npm/pkg@1.0.0" - filename = "pkg-1.0.0.tgz" - storagePath = "npm/pkg/1.0.0/pkg-1.0.0.tgz" - ) - proxy, _, _, _ := setupTestProxy(t) - - hex := sha256Hex(content) - committed := testArtifact(content, versionPURL, filename, "application/gzip") - if err := proxy.updateCacheDB("npm", "pkg", pkgPURL, - "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz", storagePath, committed); err != nil { - t.Fatalf("seeding cache record: %v", err) - } - - for _, tc := range []struct { - name, filename, hash string - want bool - }{ - {"no upstream hash", filename, "", true}, - {"matching hash", filename, hex, true}, - {"matching hash in upper case", filename, strings.ToUpper(hex), true}, - {"different hash", filename, sha256Hex("something else entirely"), false}, - {"unknown filename", "pkg-1.0.0.zip", hex, false}, - } { - t.Run(tc.name, func(t *testing.T) { - got, path, ok := proxy.cachedArtifactRecord(pkgPURL, versionPURL, tc.filename, tc.hash) - if ok != tc.want { - t.Fatalf("ok = %v, want %v", ok, tc.want) - } - if !ok { - return - } - if path != storagePath { - t.Errorf("storage path = %q, want %q", path, storagePath) - } - if got.Digest.Encoded() != hex { - t.Errorf("digest = %q, want %q", got.Digest.Encoded(), hex) - } - }) - } -} - -// TestCoalesce_LeaderFetchesWhenRecheckedBytesAreGone covers the other branch -// of the recheck: a record whose bytes no longer open is not served, and the -// shared fetch runs instead, the same recovery the cache lookup makes. -func TestCoalesce_LeaderFetchesWhenRecheckedBytesAreGone(t *testing.T) { - const content = "fetched bytes" - const storagePath = "npm/pkg/1.0.0/pkg-1.0.0.tgz" - proxy, _, store, _ := setupTestProxy(t) - - stale := artifacts.Artifact{PURL: "pkg:npm/pkg@1.0.0", Filename: "pkg-1.0.0.tgz"} - if _, err := store.Open(context.Background(), storagePath); err == nil { - t.Fatal("stale bytes were present, so the test proves nothing") - } - - // The leader runs commit on its own goroutine, so a plain counter is safe. - fetches := 0 - res, err := proxy.coalesceFetch(context.Background(), "any-key", - func() (artifacts.Artifact, string, bool) { return stale, storagePath, true }, - func(ctx context.Context) (artifacts.Artifact, string, error) { - fetches++ - if _, _, err := store.Store(ctx, storagePath, strings.NewReader(content)); err != nil { - return artifacts.Artifact{}, "", err - } - return testArtifact(content, stale.PURL, stale.Filename, "application/gzip"), storagePath, nil - }) - if err != nil { - t.Fatalf("coalesceFetch failed: %v", err) - } - defer drain(res) - if fetches != 1 { - t.Errorf("shared fetches = %d, want 1: a record without bytes must be refetched", fetches) - } - got, err := io.ReadAll(res.Reader) - if err != nil { - t.Fatalf("reading result: %v", err) - } - if string(got) != content { - t.Errorf("got %q, want %q", got, content) - } - if n := inFlightLen(proxy); n != 0 { - t.Errorf("in-flight entries = %d, want 0", n) - } -} - -// TestCoalesce_PanicInSharedFetchDoesNotStrandWaiters checks the failure mode -// that matters most: a caller parked on a shared fetch must never be left -// blocked forever when that fetch dies. -// -// This drives coalesceFetch directly and holds the shared entry itself, because -// whether a second caller has reached the wait is not observable from outside: -// it runs a cache lookup against the database first, so releasing the leader on -// a timer races that query. Losing the race made a second caller the leader -// instead of a waiter, and its panic was unrecovered, killing the test binary -// rather than failing the test. -func TestCoalesce_PanicInSharedFetchDoesNotStrandWaiters(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - const key = "pkg:npm/pkg@1.0.0\x00pkg-1.0.0.tgz" - - inCommit := make(chan struct{}) - release := make(chan struct{}) - leaderPanicked := make(chan struct{}) - - go func() { - defer func() { - _ = recover() // the panic surfaces in the leader, as it would in a handler - close(leaderPanicked) - }() - _, _ = proxy.coalesceFetch(context.Background(), key, missingFromCache, - func(context.Context) (artifacts.Artifact, string, error) { - close(inCommit) - <-release - panic("upstream fetch exploded") - }) - }() - - <-inCommit // the leader holds the key and is inside the fetch - - // Take the entry a waiter would park on, while the leader is still held. - proxy.fetchMu.Lock() - shared := proxy.inFlight[key] - proxy.fetchMu.Unlock() - if shared == nil { - t.Fatal("no in-flight entry registered for a running fetch") - } - - close(release) - - select { - case <-shared.done: - case <-time.After(5 * time.Second): - t.Fatal("waiter stranded: a panicking shared fetch never released its waiters") - } - if !errors.Is(shared.err, errSharedFetchAbandoned) { - t.Errorf("waiter error = %v, want errSharedFetchAbandoned", shared.err) - } - - <-leaderPanicked - if n := inFlightLen(proxy); n != 0 { - t.Errorf("in-flight entries after a panic = %d, want 0", n) - } -} diff --git a/internal/handler/coalesce_test.go b/internal/handler/coalesce_test.go deleted file mode 100644 index baf052d..0000000 --- a/internal/handler/coalesce_test.go +++ /dev/null @@ -1,185 +0,0 @@ -package handler - -import ( - "bytes" - "context" - "io" - "log/slog" - "net/http" - "path/filepath" - "strings" - "sync" - "sync/atomic" - "testing" - "time" - - "github.com/git-pkgs/proxy/internal/database" - "github.com/git-pkgs/proxy/internal/storage" - "github.com/git-pkgs/registries/fetch" -) - -// fetchHoldTime holds each stub fetch open long enough that concurrent callers -// reliably overlap inside it. The exact value is not significant. -const fetchHoldTime = 50 * time.Millisecond - -// countingFetcher counts upstream fetches and holds each one open. -type countingFetcher struct { - calls atomic.Int64 - content string - delay time.Duration - - // entered, if set, is closed when the first fetch begins. A test can wait - // on it to know the leader holds the key, rather than guessing with a - // sleep. - entered chan struct{} - enterOnce sync.Once -} - -func (f *countingFetcher) Fetch(ctx context.Context, url string) (*fetch.Artifact, error) { - return f.FetchWithHeaders(ctx, url, nil) -} - -func (f *countingFetcher) FetchWithHeaders(_ context.Context, _ string, _ http.Header) (*fetch.Artifact, error) { - f.calls.Add(1) - if f.entered != nil { - f.enterOnce.Do(func() { close(f.entered) }) - } - time.Sleep(f.delay) - return &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader(f.content)), - ContentType: "application/gzip", - }, nil -} - -func (f *countingFetcher) Head(context.Context, string) (int64, string, error) { - return 0, "", nil -} - -// TestGetOrFetchArtifactFromURL_ConcurrentMissesCoalesce asserts that N -// simultaneous misses for one artifact produce a single upstream fetch. That is -// the CI shape: parallel jobs installing overlapping dependencies cold. -func TestGetOrFetchArtifactFromURL_ConcurrentMissesCoalesce(t *testing.T) { - const goroutines = 8 - const content = "left-pad tarball bytes" - - proxy, _, _, _ := setupTestProxy(t) - fetcher := &countingFetcher{content: content, delay: fetchHoldTime} - proxy.Fetcher = fetcher - - start := make(chan struct{}) - var wg sync.WaitGroup - errs := make([]error, goroutines) - bodies := make([]string, goroutines) - - for i := 0; i < goroutines; i++ { - wg.Add(1) - go func(i int) { - defer wg.Done() - <-start - res, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "npm", "left-pad", "1.3.0", "left-pad-1.3.0.tgz", - "https://registry.npmjs.org/left-pad/-/left-pad-1.3.0.tgz") - if err != nil { - errs[i] = err - return - } - defer func() { _ = res.Reader.Close() }() - b, err := io.ReadAll(res.Reader) - errs[i] = err - bodies[i] = string(b) - }(i) - } - - close(start) - wg.Wait() - - for i, err := range errs { - if err != nil { - t.Errorf("goroutine %d: unexpected error: %v", i, err) - } - } - // Every caller must get its own intact copy of the bytes. - for i, b := range bodies { - if b != content { - t.Errorf("goroutine %d: body = %q, want %q", i, b, content) - } - } - if got := fetcher.calls.Load(); got != 1 { - t.Errorf("upstream fetches = %d, want 1 (%d concurrent callers stampeded the upstream)", got, goroutines) - } -} - -// TestGetOrFetchArtifactFromURL_ConcurrentMissesFileStorage runs the same -// scenario against the real file:// backend, the default in production. -// -// Uncoalesced this fails outright, not merely wastefully. Every caller stores -// to one key, and fileblob rewrites a ".attrs" sidecar per key with os.Create, -// truncating in place outside the rename that protects the blob. Decoding that -// sidecar mid-truncate gives "opening reader: EOF", served as a 502. -// -// Only the fetcher is stubbed, because the real one refuses loopback so an -// httptest upstream is unreachable. The storage, where this fails, is real. -func TestGetOrFetchArtifactFromURL_ConcurrentMissesFileStorage(t *testing.T) { - const goroutines = 16 - content := bytes.Repeat([]byte("tarball-bytes-"), 512) - - ctx := context.Background() - dir := t.TempDir() - - db, err := database.Create(filepath.Join(dir, "test.db")) - if err != nil { - t.Fatalf("create database: %v", err) - } - t.Cleanup(func() { _ = db.Close() }) - - store, err := storage.OpenBucket(ctx, "file://"+filepath.Join(dir, "cache")) - if err != nil { - t.Fatalf("open storage: %v", err) - } - t.Cleanup(func() { _ = store.Close() }) - - fetcher := &countingFetcher{content: string(content), delay: fetchHoldTime} - proxy := NewProxy(db, store, fetcher, fetch.NewResolver(), - slog.New(slog.NewTextHandler(io.Discard, nil))) - - start := make(chan struct{}) - var wg sync.WaitGroup - errs := make([]error, goroutines) - bodies := make([][]byte, goroutines) - - for i := 0; i < goroutines; i++ { - wg.Add(1) - go func(i int) { - defer wg.Done() - <-start - res, err := proxy.GetOrFetchArtifactFromURL(ctx, - "npm", "left-pad", "1.3.0", "left-pad-1.3.0.tgz", - "https://registry.npmjs.org/left-pad/-/left-pad-1.3.0.tgz") - if err != nil { - errs[i] = err - return - } - defer func() { _ = res.Reader.Close() }() - body, readErr := io.ReadAll(res.Reader) - errs[i] = readErr - bodies[i] = body - }(i) - } - - close(start) - wg.Wait() - - for i, err := range errs { - if err != nil { - t.Errorf("caller %d failed: %v", i, err) - } - } - for i, body := range bodies { - if !bytes.Equal(body, content) { - t.Errorf("caller %d got %d bytes, want %d", i, len(body), len(content)) - } - } - if got := fetcher.calls.Load(); got != 1 { - t.Errorf("upstream fetches = %d, want 1", got) - } -} diff --git a/internal/handler/composer.go b/internal/handler/composer.go index fbbd7a4..7936401 100644 --- a/internal/handler/composer.go +++ b/internal/handler/composer.go @@ -1,7 +1,6 @@ package handler import ( - "context" "encoding/json" "errors" "fmt" @@ -10,12 +9,13 @@ import ( "path" "strings" "time" + + "github.com/git-pkgs/purl" ) const ( composerUpstream = "https://packagist.org" composerRepo = "https://repo.packagist.org" - composerUnset = "__unset" vendorPackageParts = 2 ) @@ -37,15 +37,6 @@ func NewComposerHandler(proxy *Proxy, proxyURL string) *ComposerHandler { } } -// NewComposerHandlerWithUpstreams creates a Composer handler with custom API -// and repository upstreams. -func NewComposerHandlerWithUpstreams(proxy *Proxy, proxyURL, upstreamURL, repoURL string) *ComposerHandler { - h := NewComposerHandler(proxy, proxyURL) - h.upstreamURL = configuredUpstreamURL(upstreamURL, composerUpstream) - h.repoURL = configuredUpstreamURL(repoURL, composerRepo) - return h -} - // Routes returns the HTTP handler for Composer requests. func (h *ComposerHandler) Routes() http.Handler { mux := http.NewServeMux() @@ -70,14 +61,14 @@ func (h *ComposerHandler) Routes() http.Handler { func (h *ComposerHandler) handleServiceIndex(w http.ResponseWriter, r *http.Request) { // Return a minimal service index pointing to our proxy index := map[string]any{ - "packages": map[string]any{}, - "metadata-url": h.proxyURL + "/composer/p2/%package%.json", - "notify-batch": h.upstreamURL + "/downloads/", - "search": h.proxyURL + "/composer/search.json?q=%query%&type=%type%", + "packages": map[string]any{}, + "metadata-url": h.proxyURL + "/composer/p2/%package%.json", + "notify-batch": h.upstreamURL + "/downloads/", + "search": h.proxyURL + "/composer/search.json?q=%query%&type=%type%", "providers-lazy-url": h.proxyURL + "/composer/p2/%package%.json", } - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") _ = json.NewEncoder(w).Encode(index) } @@ -113,12 +104,12 @@ func (h *ComposerHandler) handlePackageMetadata(w http.ResponseWriter, r *http.R rewritten, err := h.rewriteMetadata(body) if err != nil { h.proxy.Logger.Warn("failed to rewrite metadata, proxying original", "error", err) - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") _, _ = w.Write(body) return } - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") _, _ = w.Write(rewritten) } @@ -159,8 +150,7 @@ func (h *ComposerHandler) rewriteMetadata(body []byte) ([]byte, error) { // expandMinifiedVersions expands the Composer v2 minified format where each // version entry only contains fields that differ from the previous entry. -// The "~dev" sentinel string resets the inheritance chain, and the "__unset" -// value removes a field from the inherited state. +// The "~dev" sentinel string resets the inheritance chain. func expandMinifiedVersions(versionList []any) []any { expanded := make([]any, 0, len(versionList)) inherited := map[string]any{} @@ -184,10 +174,6 @@ func expandMinifiedVersions(versionList []any) []any { merged[k] = deepCopyValue(val) } for k, val := range vmap { - if val == composerUnset { - delete(merged, k) - continue - } merged[k] = val } @@ -223,7 +209,7 @@ func deepCopyValue(v any) any { // filterAndRewriteVersions applies cooldown filtering and rewrites dist URLs // for a single package's version list. func (h *ComposerHandler) filterAndRewriteVersions(packageName string, versionList []any) []any { - packagePURL := canonicalPackagePURL("composer", packageName) + packagePURL := purl.MakePURLString("composer", packageName, "") filtered := versionList[:0] for _, v := range versionList { @@ -315,127 +301,50 @@ func (h *ComposerHandler) handleDownload(w http.ResponseWriter, r *http.Request) h.proxy.Logger.Info("composer download request", "package", packageName, "version", version, "filename", filename) - // We need to fetch the metadata to get the actual download URL since - // Packagist URLs include a hash. Packagist serves dev versions (e.g. - // "3.x-dev", "dev-master") from a separate "~dev" metadata file, while - // tagged releases live in the regular file. Try the file most likely to - // contain this version first, then fall back to the other so that both - // stable and dev versions resolve correctly. - metaURLs := h.metadataURLsForVersion(vendor, pkg, version) + // We need to fetch the metadata to get the actual download URL + // since Packagist URLs include a hash + metaURL := fmt.Sprintf("%s/p2/%s/%s.json", h.repoURL, vendor, pkg) - h.proxy.Logger.Debug("resolving download URL", - "package", packageName, "version", version, - "metadata_urls", metaURLs) - - var downloadURL string - for _, metaURL := range metaURLs { - url, err := h.findDownloadURLFromMetadata(r.Context(), metaURL, packageName, version) - if err != nil { - h.proxy.Logger.Error("failed to fetch metadata", "error", err, "url", metaURL) - http.Error(w, "failed to fetch metadata", http.StatusBadGateway) - return - } - if url != "" { - downloadURL = url - break - } - } - - if downloadURL == "" { - h.proxy.Logger.Debug("version not found in any metadata source", - "package", packageName, "version", version, - "tried_urls", metaURLs) - http.Error(w, "version not found", http.StatusNotFound) - return - } - - h.proxy.Logger.Debug("resolved download URL", - "package", packageName, "version", version, - "download_url", downloadURL) - - result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "composer", packageName, version, filename, downloadURL) + req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, metaURL, nil) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch package") + http.Error(w, "failed to create request", http.StatusInternalServerError) return } - ServeArtifact(w, result) -} - -// isDevVersion reports whether a Composer version string refers to a -// development (unstable, branch) version rather than a tagged release. -// Composer formats these as either "dev-" (e.g. "dev-master") or -// "-dev" (e.g. "3.x-dev"). -func isDevVersion(version string) bool { - return strings.HasPrefix(version, "dev-") || strings.HasSuffix(version, "-dev") -} - -// metadataURLsForVersion returns the upstream metadata URLs to consult for a -// given version, in priority order. Dev versions are served from the "~dev" -// file, tagged releases from the regular file; the other file is included as a -// fallback so an unexpected classification still resolves. -func (h *ComposerHandler) metadataURLsForVersion(vendor, pkg, version string) []string { - stable := fmt.Sprintf("%s/p2/%s/%s.json", h.repoURL, vendor, pkg) - dev := fmt.Sprintf("%s/p2/%s/%s~dev.json", h.repoURL, vendor, pkg) - - if isDevVersion(version) { - return []string{dev, stable} - } - return []string{stable, dev} -} - -// findDownloadURLFromMetadata fetches a metadata document and returns the dist -// URL for the given version, or an empty string if the version is not present. -// An error is returned only on transport failure; a missing document (non-200) -// or a missing version both yield an empty string so the caller can fall back. -func (h *ComposerHandler) findDownloadURLFromMetadata(ctx context.Context, metaURL, packageName, version string) (string, error) { - h.proxy.Logger.Debug("fetching upstream metadata for download lookup", - "url", metaURL, "package", packageName, "version", version) - - req, err := http.NewRequestWithContext(ctx, http.MethodGet, metaURL, nil) - if err != nil { - return "", err - } - resp, err := h.proxy.HTTPClient.Do(req) if err != nil { - return "", err + h.proxy.Logger.Error("failed to fetch metadata", "error", err) + http.Error(w, "failed to fetch metadata", http.StatusBadGateway) + return } defer func() { _ = resp.Body.Close() }() - h.proxy.Logger.Debug("upstream metadata response", - "url", metaURL, "status", resp.StatusCode) - if resp.StatusCode != http.StatusOK { - return "", nil + http.Error(w, "package not found", http.StatusNotFound) + return } var metadata map[string]any if err := json.NewDecoder(resp.Body).Decode(&metadata); err != nil { - return "", err + http.Error(w, "failed to parse metadata", http.StatusInternalServerError) + return } - // Expand minified Composer v2 format so that inherited fields (including - // dist) are present on every version entry. Without this, versions that - // inherit dist from a previous entry will appear to have no download URL. - if metadata["minified"] == "composer/2.0" { - h.proxy.Logger.Debug("expanding minified metadata", "url", metaURL) - if packages, ok := metadata["packages"].(map[string]any); ok { - for pkgName, versions := range packages { - versionList, ok := versions.([]any) - if !ok { - continue - } - packages[pkgName] = expandMinifiedVersions(versionList) - } - } + // Find the download URL for this version + downloadURL := h.findDownloadURL(metadata, packageName, version) + if downloadURL == "" { + http.Error(w, "version not found", http.StatusNotFound) + return } - url := h.findDownloadURL(metadata, packageName, version) - h.proxy.Logger.Debug("download URL lookup result", - "url", metaURL, "package", packageName, "version", version, - "download_url", url) - return url, nil + result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "composer", packageName, version, filename, downloadURL) + if err != nil { + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch package", http.StatusBadGateway) + return + } + + ServeArtifact(w, result) } // findDownloadURL finds the dist URL for a specific version in metadata. diff --git a/internal/handler/composer_test.go b/internal/handler/composer_test.go index 9898664..94ff8cb 100644 --- a/internal/handler/composer_test.go +++ b/internal/handler/composer_test.go @@ -1,16 +1,13 @@ package handler import ( - "context" "encoding/json" "log/slog" - "net/http" - "net/http/httptest" "strings" "testing" "time" - "github.com/git-pkgs/cooldown" + "github.com/git-pkgs/proxy/internal/cooldown" ) func TestComposerRewriteMetadata(t *testing.T) { @@ -180,80 +177,6 @@ func TestComposerRewriteMetadataMinifiedDevReset(t *testing.T) { } } -func TestComposerRewriteMetadataUnset(t *testing.T) { - h := &ComposerHandler{ - proxy: &Proxy{Logger: slog.Default()}, - proxyURL: "http://localhost:8080", - } - - // In the minified format, "__unset" removes a field from the inherited - // state. v1.29.0 has require-dev, v1.28.0 unsets it, v1.27.0 inherits the - // unset state. Composer rejects metadata where require-dev (or any link - // field) is the literal string "__unset" rather than an object. - input := `{ - "minified": "composer/2.0", - "packages": { - "venturecraft/revisionable": [ - { - "name": "venturecraft/revisionable", - "version": "1.29.0", - "require": {"php": ">=5.4"}, - "require-dev": {"orchestra/testbench": "~3.0"}, - "dist": {"url": "https://example.com/a.zip", "type": "zip"} - }, - { - "version": "1.28.0", - "require-dev": "__unset" - }, - { - "version": "1.27.0" - }, - { - "version": "1.26.0", - "require-dev": {"foo/bar": "1.0"} - } - ] - } - }` - - output, err := h.rewriteMetadata([]byte(input)) - if err != nil { - t.Fatalf("rewriteMetadata failed: %v", err) - } - - var result map[string]any - if err := json.Unmarshal(output, &result); err != nil { - t.Fatalf("failed to parse output: %v", err) - } - - versions := result["packages"].(map[string]any)["venturecraft/revisionable"].([]any) - if len(versions) != 4 { - t.Fatalf("expected 4 versions, got %d", len(versions)) - } - - byVersion := map[string]map[string]any{} - for _, v := range versions { - vmap := v.(map[string]any) - byVersion[vmap["version"].(string)] = vmap - } - - if _, ok := byVersion["1.29.0"]["require-dev"].(map[string]any); !ok { - t.Errorf("1.29.0 require-dev should be an object, got %T", byVersion["1.29.0"]["require-dev"]) - } - if rd, ok := byVersion["1.28.0"]["require-dev"]; ok { - t.Errorf("1.28.0 require-dev should be absent, got %v", rd) - } - if rd, ok := byVersion["1.27.0"]["require-dev"]; ok { - t.Errorf("1.27.0 require-dev should be absent (inherited unset), got %v", rd) - } - if _, ok := byVersion["1.26.0"]["require-dev"].(map[string]any); !ok { - t.Errorf("1.26.0 require-dev should be an object, got %T", byVersion["1.26.0"]["require-dev"]) - } - if _, ok := byVersion["1.27.0"]["require"].(map[string]any); !ok { - t.Error("1.27.0 should still inherit require from 1.29.0") - } -} - func TestComposerRewriteMetadataCooldownPreservesNames(t *testing.T) { now := time.Now() old := now.Add(-10 * 24 * time.Hour).Format(time.RFC3339) @@ -468,100 +391,6 @@ func TestComposerExpandMinifiedSharedDistReferences(t *testing.T) { } } -// TestComposerDownloadDevVersionUsesDevMetadata is a regression test for the -// bug that made it impossible to install a *-dev dependency from dist. -// -// Packagist serves development versions (e.g. "3.x-dev", "dev-master") from a -// separate "{package}~dev.json" metadata file; the regular "{package}.json" -// file contains only tagged releases. The download handler used to fetch only -// the regular file, so it could never find the dist URL for a dev version and -// returned 404 — causing Composer to silently fall back to a git clone. -// -// This test serves both files from a mock upstream and asserts that: -// - the OLD behavior (regular file only) cannot resolve the dev version, and -// - the FIXED behavior (consulting the ~dev file) does. -func TestComposerDownloadDevVersionUsesDevMetadata(t *testing.T) { - const ( - pkg = "phpmd/phpmd" - vendor = "phpmd" - name = "phpmd" - version = "3.x-dev" - distURL = "https://api.github.com/repos/phpmd/phpmd/zipball/2a9217f60aaf27bf6ddad9188f254d020ab70745" - ) - - // Regular metadata: tagged releases only — no dev versions. - stableBody := `{ - "packages": { - "phpmd/phpmd": [ - {"version": "2.15.0", "dist": {"url": "https://example.com/2.15.0.zip", "type": "zip"}} - ] - } - }` - - // ~dev metadata: where the 3.x-dev version actually lives. - devBody := `{ - "packages": { - "phpmd/phpmd": [ - {"version": "3.x-dev", "dist": {"url": "` + distURL + `", "type": "zip"}} - ] - } - }` - - srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.URL.Path { - case "/p2/phpmd/phpmd.json": - _, _ = w.Write([]byte(stableBody)) - case "/p2/phpmd/phpmd~dev.json": - _, _ = w.Write([]byte(devBody)) - default: - http.NotFound(w, r) - } - })) - defer srv.Close() - - h := &ComposerHandler{ - proxy: testProxy(), - repoURL: srv.URL, - proxyURL: "http://localhost:8080", - } - - ctx := context.Background() - - // OLD behavior: fetching only the regular file fails to resolve the dev - // version, which is what produced the 404 before the fix. - stableURL := srv.URL + "/p2/phpmd/phpmd.json" - got, err := h.findDownloadURLFromMetadata(ctx, stableURL, pkg, version) - if err != nil { - t.Fatalf("unexpected error fetching regular metadata: %v", err) - } - if got != "" { - t.Fatalf("regular metadata unexpectedly contained dev version %q (got %q); "+ - "the test no longer reproduces the original bug", version, got) - } - - // FIXED behavior: the handler consults the ~dev file (it is first in the - // candidate list for dev versions) and resolves the dist URL. - urls := h.metadataURLsForVersion(vendor, name, version) - if len(urls) == 0 || !strings.HasSuffix(urls[0], "/p2/phpmd/phpmd~dev.json") { - t.Fatalf("dev version should consult the ~dev metadata file first, got %v", urls) - } - - var resolved string - for _, u := range urls { - resolved, err = h.findDownloadURLFromMetadata(ctx, u, pkg, version) - if err != nil { - t.Fatalf("unexpected error fetching metadata %q: %v", u, err) - } - if resolved != "" { - break - } - } - - if resolved != distURL { - t.Errorf("dev version dist URL = %q, want %q", resolved, distURL) - } -} - func TestComposerRewriteMetadataCooldown(t *testing.T) { now := time.Now() old := now.Add(-10 * 24 * time.Hour).Format(time.RFC3339) diff --git a/internal/handler/conan.go b/internal/handler/conan.go index 7142f0d..53f6428 100644 --- a/internal/handler/conan.go +++ b/internal/handler/conan.go @@ -27,13 +27,6 @@ func NewConanHandler(proxy *Proxy, proxyURL string) *ConanHandler { } } -// NewConanHandlerWithUpstream creates a Conan handler with a custom upstream. -func NewConanHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *ConanHandler { - h := NewConanHandler(proxy, proxyURL) - h.upstreamURL = configuredUpstreamURL(upstreamURL, conanUpstream) - return h -} - // Routes returns the HTTP handler for Conan requests. func (h *ConanHandler) Routes() http.Handler { mux := http.NewServeMux() @@ -91,7 +84,8 @@ func (h *ConanHandler) handleRecipeFile(w http.ResponseWriter, r *http.Request) result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conan", packageName, storageVersion, storageFilename, upstreamURL) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch file") + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch file", http.StatusBadGateway) return } @@ -128,7 +122,8 @@ func (h *ConanHandler) handlePackageFile(w http.ResponseWriter, r *http.Request) result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conan", packageName, storageVersion, storageFilename, upstreamURL) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch file") + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch file", http.StatusBadGateway) return } diff --git a/internal/handler/conda.go b/internal/handler/conda.go index cef814b..a986f01 100644 --- a/internal/handler/conda.go +++ b/internal/handler/conda.go @@ -6,6 +6,8 @@ import ( "net/http" "strings" "time" + + "github.com/git-pkgs/purl" ) const ( @@ -29,13 +31,6 @@ func NewCondaHandler(proxy *Proxy, proxyURL string) *CondaHandler { } } -// NewCondaHandlerWithUpstream creates a Conda handler with a custom upstream. -func NewCondaHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *CondaHandler { - h := NewCondaHandler(proxy, proxyURL) - h.upstreamURL = configuredUpstreamURL(upstreamURL, condaUpstream) - return h -} - // Routes returns the HTTP handler for Conda requests. func (h *CondaHandler) Routes() http.Handler { mux := http.NewServeMux() @@ -79,7 +74,8 @@ func (h *CondaHandler) handleDownload(w http.ResponseWriter, r *http.Request) { result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conda", packageName, version, filename, upstreamURL) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch package") + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch package", http.StatusBadGateway) return } @@ -144,7 +140,7 @@ func (h *CondaHandler) handleRepodata(w http.ResponseWriter, r *http.Request) { http.Error(w, "failed to create request", http.StatusInternalServerError) return } - req.Header.Set(headerAcceptEncoding, "gzip") + req.Header.Set("Accept-Encoding", "gzip") resp, err := h.proxy.HTTPClient.Do(req) if err != nil { @@ -165,7 +161,7 @@ func (h *CondaHandler) handleRepodata(w http.ResponseWriter, r *http.Request) { return } - body, err := h.proxy.ReadMetadata(resp.Body) + body, err := ReadMetadata(resp.Body) if err != nil { http.Error(w, "failed to read response", http.StatusInternalServerError) return @@ -174,12 +170,12 @@ func (h *CondaHandler) handleRepodata(w http.ResponseWriter, r *http.Request) { filtered, err := h.applyCooldownFiltering(body) if err != nil { h.proxy.Logger.Warn("failed to filter repodata, proxying original", "error", err) - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") _, _ = w.Write(body) return } - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") _, _ = w.Write(filtered) } @@ -222,7 +218,7 @@ func (h *CondaHandler) applyCooldownFiltering(body []byte) ([]byte, error) { continue } - packagePURL := canonicalPackagePURL("conda", name) + packagePURL := purl.MakePURLString("conda", name, "") if !h.proxy.Cooldown.IsAllowed("conda", packagePURL, publishedAt) { version, _ := entryMap["version"].(string) @@ -245,5 +241,5 @@ func (h *CondaHandler) proxyCached(w http.ResponseWriter, r *http.Request) { // proxyUpstream forwards a request to Anaconda without caching. func (h *CondaHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) { - h.proxy.ProxyUpstream(w, r, h.upstreamURL+r.URL.Path, []string{headerAcceptEncoding}) + h.proxy.ProxyUpstream(w, r, h.upstreamURL+r.URL.Path, []string{"Accept-Encoding"}) } diff --git a/internal/handler/conda_test.go b/internal/handler/conda_test.go index 1b57039..5443161 100644 --- a/internal/handler/conda_test.go +++ b/internal/handler/conda_test.go @@ -8,7 +8,7 @@ import ( "testing" "time" - "github.com/git-pkgs/cooldown" + "github.com/git-pkgs/proxy/internal/cooldown" ) func TestCondaParseFilename(t *testing.T) { @@ -58,11 +58,11 @@ func TestCondaIsPackageFile(t *testing.T) { func TestCondaCooldownFiltering(t *testing.T) { now := time.Now() - oldTimestamp := float64(now.Add(-7 * 24 * time.Hour).UnixMilli()) - recentTimestamp := float64(now.Add(-1 * time.Hour).UnixMilli()) + oldTimestamp := float64(now.Add(-7*24*time.Hour).UnixMilli()) + recentTimestamp := float64(now.Add(-1*time.Hour).UnixMilli()) repodata := map[string]any{ - "info": map[string]any{}, + "info": map[string]any{}, "packages": map[string]any{ "numpy-1.24.0-old.tar.bz2": map[string]any{ "name": "numpy", diff --git a/internal/handler/container.go b/internal/handler/container.go index 62d839e..8aa82eb 100644 --- a/internal/handler/container.go +++ b/internal/handler/container.go @@ -2,96 +2,39 @@ package handler import ( "encoding/json" - "errors" "fmt" + "io" "net/http" "regexp" "strings" ) const ( - dockerHubRegistry = "https://registry-1.docker.io" - blobMatchCount = 3 // full match + name + digest - manifestMatchCount = 3 // full match + name + reference - tagsListMatchCount = 2 // full match + name - registrySelectorParts = 3 // upstream + name + repository + dockerHubRegistry = "https://registry-1.docker.io" + dockerHubAuth = "https://auth.docker.io" + blobMatchCount = 3 // full match + name + digest + manifestMatchCount = 3 // full match + name + reference + tagsListMatchCount = 2 // full match + name ) // ContainerHandler handles OCI/Docker container registry protocol requests. // It implements the OCI Distribution Spec for pulling images. // Reference: https://github.com/opencontainers/distribution-spec/blob/main/spec.md type ContainerHandler struct { - proxy *Proxy - registryURL string - proxyURL string - namedRegistries map[string]string - registries []containerRegistry -} - -type containerRegistry struct { - repositoryPrefix string - registryURL string + proxy *Proxy + registryURL string + authURL string + proxyURL string } // NewContainerHandler creates a new container registry protocol handler. -// Named registries are selected with the repository prefix -// upstream/{name}/, leaving unprefixed requests compatible with the Docker Hub -// mirror behavior. -func NewContainerHandler(proxy *Proxy, proxyURL string, namedRegistries ...map[string]string) *ContainerHandler { - h := &ContainerHandler{ +func NewContainerHandler(proxy *Proxy, proxyURL string) *ContainerHandler { + return &ContainerHandler{ proxy: proxy, registryURL: dockerHubRegistry, + authURL: dockerHubAuth, proxyURL: strings.TrimSuffix(proxyURL, "/"), } - if len(namedRegistries) > 0 { - h.namedRegistries = make(map[string]string, len(namedRegistries[0])) - for name, registryURL := range namedRegistries[0] { - h.namedRegistries[name] = strings.TrimSuffix(registryURL, "/") - } - } - return h -} - -// NewContainerHandlerWithRegistry creates a container handler with a custom -// default registry and optional named registries. -func NewContainerHandlerWithRegistry( - proxy *Proxy, - proxyURL, registryURL string, - namedRegistries ...map[string]string, -) *ContainerHandler { - h := NewContainerHandler(proxy, proxyURL, namedRegistries...) - h.registryURL = configuredUpstreamURL(registryURL, dockerHubRegistry) - return h -} - -// RegisterRegistry routes a repository and its descendants to a specific OCI -// registry. The longest matching repository prefix wins. -func (h *ContainerHandler) RegisterRegistry(repositoryPrefix, registryURL string) { - h.registries = append(h.registries, containerRegistry{ - repositoryPrefix: strings.Trim(repositoryPrefix, "/"), - registryURL: strings.TrimSuffix(registryURL, "/"), - }) -} - -// BlockRegistry prevents a repository and its descendants from falling back to -// the default OCI registry. A more specific registered repository still wins. -func (h *ContainerHandler) BlockRegistry(repositoryPrefix string) { - h.RegisterRegistry(repositoryPrefix, "") -} - -func (h *ContainerHandler) registryURLFor(name string) string { - registryURL := h.registryURL - matchLength := 0 - for _, registry := range h.registries { - if name != registry.repositoryPrefix && !strings.HasPrefix(name, registry.repositoryPrefix+"/") { - continue - } - if len(registry.repositoryPrefix) > matchLength { - registryURL = registry.registryURL - matchLength = len(registry.repositoryPrefix) - } - } - return registryURL } // Routes returns the HTTP handler for container registry requests. @@ -144,74 +87,48 @@ func (h *ContainerHandler) handleBlobDownload(w http.ResponseWriter, r *http.Req return } - registryURL, upstreamName, cacheName, ok := h.registryForName(name) - if !ok { - h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry") - return - } + h.proxy.Logger.Info("container blob request", "name", name, "digest", digest) - h.proxy.Logger.Info("container blob request", "name", upstreamName, "digest", digest) - - filename := digest - cached, err := h.proxy.GetCachedArtifact(r.Context(), "oci", cacheName, digest, filename) + // Get auth token for upstream + token, err := h.getAuthToken(r.Context(), name, "pull") if err != nil { - h.proxy.Logger.Error("failed to check blob cache", "error", err) - h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to check blob cache") - return - } - if cached != nil { - w.Header().Set("Docker-Content-Digest", digest) - if cached.Artifact.MediaType == "" { - cached.Artifact.MediaType = "application/octet-stream" - } - serveArtifact(w, r.Method, cached) + h.proxy.Logger.Error("failed to get auth token", "error", err) + h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate") return } // For HEAD requests, just proxy to upstream if r.Method == http.MethodHead { - h.proxyBlobHead(w, r, registryURL, upstreamName, digest) + h.proxyBlobHead(w, r, name, digest, token) return } - // Try to get from cache, or fetch from the authentication-aware upstream client. - result, err := h.proxy.GetOrFetchArtifactFromURLWithDigest( + // Try to get from cache, or fetch from upstream with auth + filename := digest + headers := http.Header{"Authorization": {"Bearer " + token}} + result, err := h.proxy.GetOrFetchArtifactFromURLWithHeaders( r.Context(), "oci", - cacheName, + name, digest, // use digest as version filename, - fmt.Sprintf("%s/v2/%s/blobs/%s", registryURL, upstreamName, digest), - digest, + fmt.Sprintf("%s/v2/%s/blobs/%s", h.registryURL, name, digest), + headers, ) if err != nil { - if errors.Is(err, ErrUpstreamNotFound) { - h.containerError(w, http.StatusNotFound, "BLOB_UNKNOWN", "blob unknown to registry") - return - } - if errors.Is(err, ErrArtifactBlocked) { - h.containerError(w, http.StatusForbidden, "DENIED", err.Error()) - return - } - if errors.Is(err, ErrArtifactDigestMismatch) { - h.proxy.Logger.Error("upstream blob failed digest verification", "error", err) - h.containerError(w, http.StatusBadGateway, "DIGEST_INVALID", "blob digest verification failed") - return - } h.proxy.Logger.Error("failed to fetch blob", "error", err) - h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch blob") + h.containerError(w, http.StatusBadGateway, "BLOB_UNKNOWN", "failed to fetch blob") return } w.Header().Set("Docker-Content-Digest", digest) - if result.Artifact.MediaType == "" { - result.Artifact.MediaType = "application/octet-stream" - } + w.Header().Set("Content-Type", "application/octet-stream") ServeArtifact(w, result) } -// handleManifest serves immutable manifests from cache and revalidates mutable tags. +// handleManifest proxies manifest requests to upstream. +// Manifests change when tags are updated, so we proxy these directly. // Path format: {name}/manifests/{reference} func (h *ContainerHandler) handleManifest(w http.ResponseWriter, r *http.Request, path string) { if r.Method != http.MethodGet && r.Method != http.MethodHead { @@ -225,17 +142,61 @@ func (h *ContainerHandler) handleManifest(w http.ResponseWriter, r *http.Request return } - registryURL, upstreamName, _, ok := h.registryForName(name) - if !ok { - h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry") + h.proxy.Logger.Info("container manifest request", "name", name, "reference", reference) + + // Get auth token + token, err := h.getAuthToken(r.Context(), name, "pull") + if err != nil { + h.proxy.Logger.Error("failed to get auth token", "error", err) + h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate") return } - h.proxy.Logger.Info("container manifest request", "name", upstreamName, "reference", reference) - h.serveManifest(w, r, registryURL, upstreamName, reference) + // Proxy to upstream + upstreamURL := fmt.Sprintf("%s/v2/%s/manifests/%s", h.registryURL, name, reference) + + req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil) + if err != nil { + h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request") + return + } + + req.Header.Set("Authorization", "Bearer "+token) + + // Forward Accept header for content negotiation + if accept := r.Header.Get("Accept"); accept != "" { + req.Header.Set("Accept", accept) + } else { + // Default accept headers for manifests + req.Header.Set("Accept", strings.Join([]string{ + "application/vnd.oci.image.manifest.v1+json", + "application/vnd.oci.image.index.v1+json", + "application/vnd.docker.distribution.manifest.v2+json", + "application/vnd.docker.distribution.manifest.list.v2+json", + "application/vnd.docker.distribution.manifest.v1+prettyjws", + }, ", ")) + } + + resp, err := h.proxy.HTTPClient.Do(req) + if err != nil { + h.proxy.Logger.Error("failed to fetch manifest", "error", err) + h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream") + return + } + defer func() { _ = resp.Body.Close() }() + + // Copy relevant headers + for _, header := range []string{"Content-Type", "Content-Length", "Docker-Content-Digest", "ETag"} { + if v := resp.Header.Get(header); v != "" { + w.Header().Set(header, v) + } + } + + w.WriteHeader(resp.StatusCode) + _, _ = io.Copy(w, resp.Body) } -// handleTagsList caches tag list responses for offline OCI pulls. +// handleTagsList proxies tag list requests to upstream. func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request, path string) { if r.Method != http.MethodGet { http.Error(w, "method not allowed", http.StatusMethodNotAllowed) @@ -248,25 +209,26 @@ func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request return } - registryURL, upstreamName, _, ok := h.registryForName(name) - if !ok { - h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry") + // Get auth token + token, err := h.getAuthToken(r.Context(), name, "pull") + if err != nil { + h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate") return } - h.serveTagsList(w, r, registryURL, upstreamName) -} + upstreamURL := fmt.Sprintf("%s/v2/%s/tags/list", h.registryURL, name) + if r.URL.RawQuery != "" { + upstreamURL += "?" + r.URL.RawQuery + } -// proxyBlobHead handles HEAD requests for blobs. -func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, registryURL, name, digest string) { - upstreamURL := fmt.Sprintf("%s/v2/%s/blobs/%s", registryURL, name, digest) - - req, err := http.NewRequestWithContext(r.Context(), http.MethodHead, upstreamURL, nil) + req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil) if err != nil { h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request") return } + req.Header.Set("Authorization", "Bearer "+token) + resp, err := h.proxy.HTTPClient.Do(req) if err != nil { h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream") @@ -274,44 +236,80 @@ func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, } defer func() { _ = resp.Body.Close() }() - for _, header := range []string{headerContentType, headerContentLength, "Docker-Content-Digest", headerETag, headerLastModified} { + w.Header().Set("Content-Type", "application/json") + w.WriteHeader(resp.StatusCode) + _, _ = io.Copy(w, resp.Body) +} + +// getAuthToken gets a bearer token for the specified repository. +// Docker Hub requires auth even for public images. +func (h *ContainerHandler) getAuthToken(_ interface{ Done() <-chan struct{} }, repository, action string) (string, error) { + // For Docker Hub: https://auth.docker.io/token?service=registry.docker.io&scope=repository:{repo}:pull + authURL := fmt.Sprintf("%s/token?service=registry.docker.io&scope=repository:%s:%s", + h.authURL, repository, action) + + req, err := http.NewRequest(http.MethodGet, authURL, nil) + if err != nil { + return "", err + } + + resp, err := h.proxy.HTTPClient.Do(req) + if err != nil { + return "", err + } + defer func() { _ = resp.Body.Close() }() + + if resp.StatusCode != http.StatusOK { + return "", fmt.Errorf("auth failed with status %d", resp.StatusCode) + } + + var tokenResp struct { + Token string `json:"token"` + AccessToken string `json:"access_token"` + } + + if err := json.NewDecoder(resp.Body).Decode(&tokenResp); err != nil { + return "", err + } + + if tokenResp.Token != "" { + return tokenResp.Token, nil + } + return tokenResp.AccessToken, nil +} + +// proxyBlobHead handles HEAD requests for blobs. +func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, name, digest, token string) { + upstreamURL := fmt.Sprintf("%s/v2/%s/blobs/%s", h.registryURL, name, digest) + + req, err := http.NewRequestWithContext(r.Context(), http.MethodHead, upstreamURL, nil) + if err != nil { + h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request") + return + } + + req.Header.Set("Authorization", "Bearer "+token) + + resp, err := h.proxy.HTTPClient.Do(req) + if err != nil { + h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream") + return + } + defer func() { _ = resp.Body.Close() }() + + for _, header := range []string{"Content-Type", "Content-Length", "Docker-Content-Digest"} { if v := resp.Header.Get(header); v != "" { w.Header().Set(header, v) } } - if resp.StatusCode >= http.StatusOK && resp.StatusCode < http.StatusMultipleChoices && w.Header().Get("Docker-Content-Digest") == "" { - w.Header().Set("Docker-Content-Digest", digest) - } w.WriteHeader(resp.StatusCode) } -// registryForName resolves a client-visible OCI repository name to an upstream -// registry and its repository name. Named upstreams use upstream/{name}/ as a -// reserved prefix. Other names are matched against registered repository -// prefixes, falling back to Docker Hub when no prefix matches. -func (h *ContainerHandler) registryForName(name string) (registryURL, upstreamName, cacheName string, ok bool) { - parts := strings.SplitN(name, "/", registrySelectorParts) - if len(parts) >= 2 && parts[0] == "upstream" { - if len(parts) != registrySelectorParts || parts[2] == "" { - return "", "", "", false - } - registryURL, ok = h.namedRegistries[parts[1]] - if !ok || registryURL == "" { - return "", "", "", false - } - return registryURL, parts[2], name, true - } - registryURL = h.registryURLFor(name) - if registryURL == "" { - return "", "", "", false - } - return registryURL, name, name, true -} // containerError writes an OCI-compliant error response. func (h *ContainerHandler) containerError(w http.ResponseWriter, status int, code, message string) { - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") w.WriteHeader(status) _ = json.NewEncoder(w).Encode(map[string]any{ "errors": []map[string]string{ diff --git a/internal/handler/container_manifest.go b/internal/handler/container_manifest.go deleted file mode 100644 index 7b03086..0000000 --- a/internal/handler/container_manifest.go +++ /dev/null @@ -1,434 +0,0 @@ -package handler - -import ( - "context" - "crypto/sha256" - "encoding/hex" - "fmt" - "io" - "mime" - "net/http" - "regexp" - "sort" - "strconv" - "strings" - "time" -) - -const ( - containerManifestCacheEcosystem = "oci-manifest" - containerStaleWarning = `110 - "Response is Stale"` - - containerAcceptWildcardSpecificity = iota - containerAcceptTypeWildcardSpecificity - containerAcceptExactSpecificity -) - -var manifestDigestReferencePattern = regexp.MustCompile(`^[a-z0-9]+:[a-f0-9]+$`) - -type cachedContainerManifest struct { - body []byte - contentType string - contentDigest string - etag string - size int64 - lastModified time.Time - fetchedAt time.Time -} - -func (h *ContainerHandler) serveManifest(w http.ResponseWriter, r *http.Request, registryURL, name, reference string) { - accept := containerManifestAccept(r) - cacheAccept := normalizeContainerManifestAccept(accept) - cacheKey := h.containerManifestCacheKey(registryURL, name, reference, cacheAccept) - cached := h.loadContainerManifestForAccept(r.Context(), registryURL, name, reference, accept, cacheKey) - - immutable := manifestDigestReferencePattern.MatchString(reference) - if cached != nil && (immutable || h.containerManifestFresh(cached)) { - writeContainerManifest(w, r, cached, false) - return - } - - upstreamURL := fmt.Sprintf("%s/v2/%s/manifests/%s", registryURL, name, reference) - req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil) - if err != nil { - h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request") - return - } - req.Header.Set("Accept", accept) - if cached != nil && cached.etag != "" { - req.Header.Set("If-None-Match", cached.etag) - } - - resp, err := h.proxy.HTTPClient.Do(req) - if err != nil { - h.serveStaleManifestOrError(w, r, cached, err) - return - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode == http.StatusNotModified && cached != nil { - cached.fetchedAt = time.Now() - h.storeContainerManifestForAccept(r.Context(), registryURL, name, reference, accept, cacheAccept, cached) - writeContainerManifest(w, r, cached, false) - return - } - if resp.StatusCode != http.StatusOK { - if cached != nil && shouldServeStaleManifest(resp.StatusCode) { - writeContainerManifest(w, r, cached, true) - return - } - copyContainerManifestHeaders(w.Header(), resp.Header) - w.WriteHeader(resp.StatusCode) - _, _ = io.Copy(w, resp.Body) - return - } - - if r.Method == http.MethodHead { - copyContainerManifestHeaders(w.Header(), resp.Header) - w.WriteHeader(http.StatusOK) - return - } - - body, err := h.proxy.ReadMetadata(resp.Body) - if err != nil { - h.serveStaleManifestOrError(w, r, cached, fmt.Errorf("reading manifest: %w", err)) - return - } - computedDigest := sha256Digest(body) - contentDigest := resp.Header.Get("Docker-Content-Digest") - for _, expected := range []string{reference, contentDigest} { - if strings.HasPrefix(expected, "sha256:") && expected != computedDigest { - h.proxy.Logger.Error("upstream manifest failed digest verification", - "name", name, "reference", reference, "expected", expected, "actual", computedDigest) - h.containerError(w, http.StatusBadGateway, "DIGEST_INVALID", "manifest digest verification failed") - return - } - } - if contentDigest == "" { - contentDigest = computedDigest - } - - manifest := &cachedContainerManifest{ - body: body, - contentType: resp.Header.Get(headerContentType), - contentDigest: contentDigest, - etag: resp.Header.Get(headerETag), - size: int64(len(body)), - lastModified: parseHTTPTime(resp.Header.Get(headerLastModified)), - fetchedAt: time.Now(), - } - h.storeContainerManifestForAccept(r.Context(), registryURL, name, reference, accept, cacheAccept, manifest) - if manifest.contentDigest != reference && manifestDigestReferencePattern.MatchString(manifest.contentDigest) { - h.storeContainerManifestForAccept(r.Context(), registryURL, name, manifest.contentDigest, accept, cacheAccept, manifest) - } - writeContainerManifest(w, r, manifest, false) -} - -func (h *ContainerHandler) serveStaleManifestOrError(w http.ResponseWriter, r *http.Request, cached *cachedContainerManifest, err error) { - if cached != nil { - h.proxy.Logger.Warn("upstream manifest fetch failed, serving stale cache", "error", err) - writeContainerManifest(w, r, cached, true) - return - } - h.proxy.Logger.Error("failed to fetch manifest", "error", err) - h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream") -} - -func (h *ContainerHandler) containerManifestFresh(manifest *cachedContainerManifest) bool { - return h.proxy.MetadataTTL > 0 && !manifest.fetchedAt.IsZero() && time.Since(manifest.fetchedAt) < h.proxy.MetadataTTL -} - -func (h *ContainerHandler) containerManifestCacheKey(registryURL, name, reference, accept string) string { - identity := strings.Join([]string{registryURL, name, reference, accept}, "\x00") - sum := sha256.Sum256([]byte(identity)) - return hex.EncodeToString(sum[:]) -} - -func (h *ContainerHandler) loadContainerManifestForAccept(ctx context.Context, registryURL, name, reference, accept, cacheKey string) *cachedContainerManifest { - cached, err := h.loadContainerManifest(ctx, cacheKey) - if err != nil { - h.proxy.Logger.Warn("failed to read cached container manifest", "error", err) - return nil - } - if cached != nil { - if containerManifestCacheCompatible(accept, cached) { - return cached - } - return nil - } - - legacyCacheKey := h.containerManifestCacheKey(registryURL, name, reference, accept) - if legacyCacheKey == cacheKey { - return nil - } - cached, err = h.loadContainerManifest(ctx, legacyCacheKey) - if err != nil { - h.proxy.Logger.Warn("failed to read legacy cached container manifest", "error", err) - return nil - } - if cached == nil || !containerManifestCacheCompatible(accept, cached) { - return nil - } - if err := h.storeContainerManifest(ctx, cacheKey, cached); err != nil { - h.proxy.Logger.Warn("failed to migrate cached container manifest", "error", err) - } - return cached -} - -func (h *ContainerHandler) storeContainerManifestForAccept(ctx context.Context, registryURL, name, reference, accept, cacheAccept string, manifest *cachedContainerManifest) { - cacheKey := h.containerManifestCacheKey(registryURL, name, reference, cacheAccept) - if err := h.storeContainerManifest(ctx, cacheKey, manifest); err != nil { - h.proxy.Logger.Warn("failed to cache container manifest", "error", err) - } - - legacyCacheKey := h.containerManifestCacheKey(registryURL, name, reference, accept) - if legacyCacheKey == cacheKey { - return - } - if err := h.storeContainerManifest(ctx, legacyCacheKey, manifest); err != nil { - h.proxy.Logger.Warn("failed to cache legacy container manifest", "error", err) - } -} - -func (h *ContainerHandler) loadContainerManifest(ctx context.Context, cacheKey string) (*cachedContainerManifest, error) { - if h.proxy.DB == nil || h.proxy.Storage == nil { - return nil, nil - } - entry, err := h.proxy.DB.GetMetadataCache(containerManifestCacheEcosystem, cacheKey) - if err != nil || entry == nil { - return nil, err - } - reader, err := h.proxy.Storage.Open(ctx, entry.StoragePath) - if err != nil { - return nil, nil - } - defer func() { _ = reader.Close() }() - body, err := h.proxy.ReadMetadata(reader) - if err != nil { - return nil, err - } - - manifest := &cachedContainerManifest{body: body, size: int64(len(body))} - if entry.ContentType.Valid { - manifest.contentType = entry.ContentType.String - } - if entry.ContentDigest.Valid { - manifest.contentDigest = entry.ContentDigest.String - } else { - manifest.contentDigest = sha256Digest(body) - } - if entry.ETag.Valid { - manifest.etag = entry.ETag.String - } - if entry.Size.Valid { - manifest.size = entry.Size.Int64 - } - if entry.LastModified.Valid { - manifest.lastModified = entry.LastModified.Time - } - if entry.FetchedAt.Valid { - manifest.fetchedAt = entry.FetchedAt.Time - } - return manifest, nil -} - -func (h *ContainerHandler) storeContainerManifest(ctx context.Context, cacheKey string, manifest *cachedContainerManifest) error { - size, err := h.storeContainerMetadata(ctx, containerManifestCacheEcosystem, cacheKey, manifest.body, - manifest.etag, "", manifest.contentType, manifest.contentDigest, manifest.lastModified, manifest.fetchedAt) - if err != nil { - return fmt.Errorf("storing manifest: %w", err) - } - manifest.size = size - return nil -} - -func writeContainerManifest(w http.ResponseWriter, r *http.Request, manifest *cachedContainerManifest, stale bool) { - if manifest.contentType != "" { - w.Header().Set(headerContentType, manifest.contentType) - } - w.Header().Set(headerContentLength, strconv.FormatInt(manifest.size, 10)) - if manifest.contentDigest != "" { - w.Header().Set("Docker-Content-Digest", manifest.contentDigest) - } - if manifest.etag != "" { - w.Header().Set(headerETag, manifest.etag) - } - if !manifest.lastModified.IsZero() { - w.Header().Set(headerLastModified, manifest.lastModified.UTC().Format(http.TimeFormat)) - } - if stale { - w.Header().Set("Warning", containerStaleWarning) - } - if ifNoneMatchHits(r.Header.Get("If-None-Match"), manifest.etag) { - w.WriteHeader(http.StatusNotModified) - return - } - if !manifest.lastModified.IsZero() { - if modifiedSince, err := http.ParseTime(r.Header.Get("If-Modified-Since")); err == nil && !manifest.lastModified.After(modifiedSince) { - w.WriteHeader(http.StatusNotModified) - return - } - } - w.WriteHeader(http.StatusOK) - if r.Method != http.MethodHead { - _, _ = w.Write(manifest.body) - } -} - -func containerManifestAccept(r *http.Request) string { - if accept := r.Header.Get("Accept"); accept != "" { - return accept - } - return strings.Join([]string{ - "application/vnd.oci.image.manifest.v1+json", - "application/vnd.oci.image.index.v1+json", - "application/vnd.docker.distribution.manifest.v2+json", - "application/vnd.docker.distribution.manifest.list.v2+json", - "application/vnd.docker.distribution.manifest.v1+prettyjws", - }, ", ") -} - -func normalizeContainerManifestAccept(accept string) string { - mediaTypes := make(map[string]struct{}) - for _, value := range strings.Split(accept, ",") { - value = strings.TrimSpace(value) - if value == "" { - continue - } - mediaType, params, err := mime.ParseMediaType(value) - if err != nil { - mediaTypes[strings.ToLower(value)] = struct{}{} - continue - } - paramKeys := make([]string, 0, len(params)) - for key := range params { - paramKeys = append(paramKeys, key) - } - sort.Strings(paramKeys) - canonical := strings.ToLower(mediaType) - for _, key := range paramKeys { - value := params[key] - if strings.EqualFold(key, "q") { - if quality, err := strconv.ParseFloat(value, 64); err == nil { - if quality == 1 { - continue - } - value = strconv.FormatFloat(quality, 'g', -1, 64) - } - } - canonical += ";" + strings.ToLower(key) + "=" + value - } - mediaTypes[canonical] = struct{}{} - } - canonicalMediaTypes := make([]string, 0, len(mediaTypes)) - for mediaType := range mediaTypes { - canonicalMediaTypes = append(canonicalMediaTypes, mediaType) - } - sort.Strings(canonicalMediaTypes) - return strings.Join(canonicalMediaTypes, ",") -} - -func containerManifestAccepts(accept, contentType string) bool { - contentType, contentParams, err := mime.ParseMediaType(contentType) - if err != nil { - return false - } - contentType = strings.ToLower(contentType) - contentMajor, contentMinor, found := strings.Cut(contentType, "/") - if !found { - return false - } - - bestMediaTypeSpecificity := -1 - bestParameterSpecificity := 0 - bestQuality := 0.0 - for _, value := range strings.Split(accept, ",") { - mediaType, params, err := mime.ParseMediaType(strings.TrimSpace(value)) - if err != nil { - continue - } - mediaType = strings.ToLower(mediaType) - major, minor, found := strings.Cut(mediaType, "/") - if found && containerAcceptRangeMatches(major, minor, params, contentMajor, contentMinor, contentParams) { - mediaTypeSpecificity, parameterSpecificity := containerAcceptSpecificity(major, minor, params) - if mediaTypeSpecificity > bestMediaTypeSpecificity || - (mediaTypeSpecificity == bestMediaTypeSpecificity && parameterSpecificity > bestParameterSpecificity) { - bestMediaTypeSpecificity = mediaTypeSpecificity - bestParameterSpecificity = parameterSpecificity - bestQuality = containerAcceptQuality(params) - } - } - } - return bestQuality > 0 -} - -func containerManifestCacheCompatible(accept string, manifest *cachedContainerManifest) bool { - return manifest.contentType == "" || containerManifestAccepts(accept, manifest.contentType) -} - -func containerAcceptRangeMatches(major, minor string, params map[string]string, contentMajor, contentMinor string, contentParams map[string]string) bool { - if (major != "*" && major != contentMajor) || (minor != "*" && minor != contentMinor) { - return false - } - for key, value := range params { - if strings.EqualFold(key, "q") { - continue - } - if contentParams[key] != value { - return false - } - } - return true -} - -func containerAcceptSpecificity(major, minor string, params map[string]string) (int, int) { - parameterSpecificity := 0 - for key := range params { - if !strings.EqualFold(key, "q") { - parameterSpecificity++ - } - } - - switch { - case major == "*" && minor == "*": - return containerAcceptWildcardSpecificity, parameterSpecificity - case major == "*" || minor == "*": - return containerAcceptTypeWildcardSpecificity, parameterSpecificity - default: - return containerAcceptExactSpecificity, parameterSpecificity - } -} - -func containerAcceptQuality(params map[string]string) float64 { - value, ok := params["q"] - if !ok { - return 1 - } - quality, err := strconv.ParseFloat(value, 64) - if err != nil || quality < 0 || quality > 1 { - return 0 - } - return quality -} - -func copyContainerManifestHeaders(destination, source http.Header) { - for _, header := range []string{headerContentType, headerContentLength, "Docker-Content-Digest", headerETag, headerLastModified, "WWW-Authenticate"} { - if value := source.Get(header); value != "" { - destination.Set(header, value) - } - } -} - -func parseHTTPTime(value string) time.Time { - parsed, _ := http.ParseTime(value) - return parsed -} - -func shouldServeStaleManifest(status int) bool { - return status == http.StatusTooManyRequests || status >= http.StatusInternalServerError -} - -func sha256Digest(body []byte) string { - digest := sha256.Sum256(body) - return "sha256:" + hex.EncodeToString(digest[:]) -} diff --git a/internal/handler/container_metadata.go b/internal/handler/container_metadata.go deleted file mode 100644 index edc78ad..0000000 --- a/internal/handler/container_metadata.go +++ /dev/null @@ -1,39 +0,0 @@ -package handler - -import ( - "bytes" - "context" - "database/sql" - "fmt" - "time" - - "github.com/git-pkgs/proxy/internal/database" -) - -func (h *ContainerHandler) storeContainerMetadata(ctx context.Context, ecosystem, cacheKey string, body []byte, etag, link, contentType, contentDigest string, lastModified, fetchedAt time.Time) (int64, error) { - if h.proxy.DB == nil || h.proxy.Storage == nil { - return int64(len(body)), nil - } - - storagePath := metadataStoragePath(ecosystem, cacheKey) - size, _, err := h.proxy.Storage.Store(ctx, storagePath, bytes.NewReader(body)) - if err != nil { - return 0, fmt.Errorf("storing metadata: %w", err) - } - err = h.proxy.DB.UpsertMetadataCache(&database.MetadataCacheEntry{ - Ecosystem: ecosystem, - Name: cacheKey, - StoragePath: storagePath, - ETag: sql.NullString{String: etag, Valid: etag != ""}, - Link: sql.NullString{String: link, Valid: link != ""}, - ContentType: sql.NullString{String: contentType, Valid: contentType != ""}, - ContentDigest: sql.NullString{String: contentDigest, Valid: contentDigest != ""}, - Size: sql.NullInt64{Int64: size, Valid: true}, - LastModified: sql.NullTime{Time: lastModified, Valid: !lastModified.IsZero()}, - FetchedAt: sql.NullTime{Time: fetchedAt, Valid: !fetchedAt.IsZero()}, - }) - if err != nil { - return 0, err - } - return size, nil -} diff --git a/internal/handler/container_tags.go b/internal/handler/container_tags.go deleted file mode 100644 index dcc08f8..0000000 --- a/internal/handler/container_tags.go +++ /dev/null @@ -1,229 +0,0 @@ -package handler - -import ( - "context" - "crypto/sha256" - "encoding/hex" - "fmt" - "io" - "net/http" - "net/url" - "regexp" - "strconv" - "strings" - "time" -) - -const containerTagsCacheEcosystem = "oci-tags" - -var containerLinkTargetPattern = regexp.MustCompile(`<([^>]*)>`) - -type cachedContainerTags struct { - body []byte - contentType string - etag string - link string - size int64 - fetchedAt time.Time -} - -func (h *ContainerHandler) serveTagsList(w http.ResponseWriter, r *http.Request, registryURL, name string) { - cacheKey := h.containerTagsCacheKey(registryURL, name, r.URL.Query()) - cached, err := h.loadContainerTags(r.Context(), cacheKey) - if err != nil { - h.proxy.Logger.Warn("failed to read cached container tag list", "error", err) - cached = nil - } - if cached != nil && h.containerTagsFresh(cached) { - writeContainerTags(w, cached, false) - return - } - - upstreamURL := fmt.Sprintf("%s/v2/%s/tags/list", registryURL, name) - if query := r.URL.Query().Encode(); query != "" { - upstreamURL += "?" + query - } - req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil) - if err != nil { - h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request") - return - } - req.Header.Set("Accept", "application/json") - if cached != nil && cached.etag != "" { - req.Header.Set("If-None-Match", cached.etag) - } - - resp, err := h.proxy.HTTPClient.Do(req) - if err != nil { - h.serveStaleTagsOrError(w, cached, err) - return - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode == http.StatusNotModified && cached != nil { - cached.fetchedAt = time.Now() - if err := h.storeContainerTags(r.Context(), cacheKey, cached); err != nil { - h.proxy.Logger.Warn("failed to refresh cached container tag list", "error", err) - } - writeContainerTags(w, cached, false) - return - } - if resp.StatusCode != http.StatusOK { - if cached != nil && shouldServeStaleManifest(resp.StatusCode) { - writeContainerTags(w, cached, true) - return - } - copyContainerTagsHeaders(w.Header(), resp.Header) - w.WriteHeader(resp.StatusCode) - _, _ = io.Copy(w, resp.Body) - return - } - - body, err := h.proxy.ReadMetadata(resp.Body) - if err != nil { - h.serveStaleTagsOrError(w, cached, fmt.Errorf("reading tag list: %w", err)) - return - } - tags := &cachedContainerTags{ - body: body, - contentType: resp.Header.Get(headerContentType), - etag: resp.Header.Get(headerETag), - link: h.rewriteContainerTagsLink(strings.Join(resp.Header.Values("Link"), ", "), registryURL, r.URL.Path), - size: int64(len(body)), - fetchedAt: time.Now(), - } - if tags.contentType == "" { - tags.contentType = contentTypeJSON - } - if err := h.storeContainerTags(r.Context(), cacheKey, tags); err != nil { - h.proxy.Logger.Warn("failed to cache container tag list", "error", err) - } - writeContainerTags(w, tags, false) -} - -func (h *ContainerHandler) serveStaleTagsOrError(w http.ResponseWriter, cached *cachedContainerTags, err error) { - if cached != nil { - h.proxy.Logger.Warn("upstream tag list fetch failed, serving stale cache", "error", err) - writeContainerTags(w, cached, true) - return - } - h.proxy.Logger.Error("failed to fetch container tag list", "error", err) - h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream") -} - -func (h *ContainerHandler) containerTagsCacheKey(registryURL, name string, query url.Values) string { - identity := registryURL + "\x00" + name + "\x00" + query.Encode() - sum := sha256.Sum256([]byte(identity)) - return hex.EncodeToString(sum[:]) -} - -func (h *ContainerHandler) containerTagsFresh(tags *cachedContainerTags) bool { - return h.proxy.MetadataTTL > 0 && !tags.fetchedAt.IsZero() && time.Since(tags.fetchedAt) < h.proxy.MetadataTTL -} - -func (h *ContainerHandler) loadContainerTags(ctx context.Context, cacheKey string) (*cachedContainerTags, error) { - if h.proxy.DB == nil || h.proxy.Storage == nil { - return nil, nil - } - entry, err := h.proxy.DB.GetMetadataCache(containerTagsCacheEcosystem, cacheKey) - if err != nil || entry == nil { - return nil, err - } - reader, err := h.proxy.Storage.Open(ctx, entry.StoragePath) - if err != nil { - return nil, nil - } - defer func() { _ = reader.Close() }() - body, err := h.proxy.ReadMetadata(reader) - if err != nil { - return nil, err - } - - tags := &cachedContainerTags{body: body, contentType: contentTypeJSON, size: int64(len(body))} - if entry.ContentType.Valid { - tags.contentType = entry.ContentType.String - } - if entry.ETag.Valid { - tags.etag = entry.ETag.String - } - if entry.Link.Valid { - tags.link = entry.Link.String - } - if entry.Size.Valid { - tags.size = entry.Size.Int64 - } - if entry.FetchedAt.Valid { - tags.fetchedAt = entry.FetchedAt.Time - } - return tags, nil -} - -func (h *ContainerHandler) storeContainerTags(ctx context.Context, cacheKey string, tags *cachedContainerTags) error { - size, err := h.storeContainerMetadata(ctx, containerTagsCacheEcosystem, cacheKey, tags.body, - tags.etag, tags.link, tags.contentType, "", time.Time{}, tags.fetchedAt) - if err != nil { - return fmt.Errorf("storing tag list: %w", err) - } - tags.size = size - return nil -} - -func writeContainerTags(w http.ResponseWriter, tags *cachedContainerTags, stale bool) { - w.Header().Set(headerContentType, tags.contentType) - w.Header().Set(headerContentLength, strconv.FormatInt(tags.size, 10)) - if tags.etag != "" { - w.Header().Set(headerETag, tags.etag) - } - if tags.link != "" { - w.Header().Set("Link", tags.link) - } - if stale { - w.Header().Set("Warning", containerStaleWarning) - } - w.WriteHeader(http.StatusOK) - _, _ = w.Write(tags.body) -} - -func copyContainerTagsHeaders(destination, source http.Header) { - for _, header := range []string{headerContentType, headerContentLength, headerETag, "Link", "WWW-Authenticate"} { - if value := source.Get(header); value != "" { - destination.Set(header, value) - } - } -} - -func (h *ContainerHandler) rewriteContainerTagsLink(link, registryURL, requestPath string) string { - if link == "" { - return "" - } - upstreamURL, err := url.Parse(registryURL) - if err != nil { - return link - } - proxyURL, err := url.Parse(h.proxyURL) - if err != nil { - return link - } - - return containerLinkTargetPattern.ReplaceAllStringFunc(link, func(target string) string { - linkURL, err := url.Parse(target[1 : len(target)-1]) - if err != nil { - return target - } - if linkURL.IsAbs() { - if linkURL.Scheme != upstreamURL.Scheme || linkURL.Host != upstreamURL.Host { - return target - } - } else if linkURL.Host != "" || (linkURL.Path != "" && !strings.HasPrefix(linkURL.Path, "/v2/")) { - return target - } - // Relative registry API links resolve against the current tag-list - // endpoint. Rebuild them below so named-registry selectors are kept. - linkURL.Scheme = proxyURL.Scheme - linkURL.Host = proxyURL.Host - linkURL.User = proxyURL.User - linkURL.Path = strings.TrimSuffix(proxyURL.Path, "/") + "/v2" + requestPath - linkURL.RawPath = "" - return "<" + linkURL.String() + ">" - }) -} diff --git a/internal/handler/container_test.go b/internal/handler/container_test.go index 5b7aa03..b34a250 100644 --- a/internal/handler/container_test.go +++ b/internal/handler/container_test.go @@ -1,16 +1,16 @@ package handler import ( + "bytes" + "context" "encoding/json" "io" + "log/slog" "net/http" "net/http/httptest" - "strconv" - "strings" "testing" - "time" - upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient" + "github.com/git-pkgs/proxy/internal/database" "github.com/git-pkgs/registries/fetch" ) @@ -86,8 +86,8 @@ func TestContainerHandler_parseManifestPath(t *testing.T) { wantReference: "sha256:abc123", }, { - path: "invalid/path", - wantName: "", + path: "invalid/path", + wantName: "", }, } @@ -135,1179 +135,90 @@ func TestContainerHandler_parseTagsListPath(t *testing.T) { } } -func TestContainerHandler_TagsListUsesStaleCacheOnUpstreamFailure(t *testing.T) { - tags := `{"name":"library/nginx","tags":["1.0","latest"]}` - upstreamAvailable := true - upstreamRequests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - upstreamRequests++ - if r.URL.Path != "/v2/library/nginx/tags/list" { - http.NotFound(w, r) - return - } - if !upstreamAvailable { - http.Error(w, "upstream unavailable", http.StatusServiceUnavailable) - return - } +func TestContainerHandler_BlobDownload_CachesWithAuth(t *testing.T) { + // Set up a mock auth server that returns a token + authServer := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { w.Header().Set("Content-Type", "application/json") - w.Header().Set("ETag", `"tags-etag"`) - _, _ = io.WriteString(w, tags) + _ = json.NewEncoder(w).Encode(map[string]string{"token": "test-token-123"}) })) - defer upstream.Close() + defer authServer.Close() - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.MetadataTTL = 0 - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"} - - first := httptest.NewRecorder() - h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/tags/list?n=2", nil)) - if first.Code != http.StatusOK { - t.Fatalf("initial status = %d, want 200: %s", first.Code, first.Body.String()) - } - if first.Body.String() != tags { - t.Errorf("initial body = %q, want %q", first.Body.String(), tags) + // Set up mock fetcher that captures headers + var capturedHeaders http.Header + mf := &mockFetcherWithHeaders{ + fetchFn: func(_ context.Context, _ string, headers http.Header) (*fetch.Artifact, error) { + capturedHeaders = headers + return &fetch.Artifact{ + Body: io.NopCloser(bytes.NewReader([]byte("blob-content"))), + Size: 12, + ContentType: "application/octet-stream", + }, nil + }, } - upstreamAvailable = false - second := httptest.NewRecorder() - h.Routes().ServeHTTP(second, httptest.NewRequest(http.MethodGet, "/library/nginx/tags/list?n=2", nil)) - if second.Code != http.StatusOK { - t.Fatalf("stale status = %d, want 200: %s", second.Code, second.Body.String()) + dir := t.TempDir() + db, err := database.Create(dir + "/test.db") + if err != nil { + t.Fatalf("failed to create test database: %v", err) } - if second.Body.String() != tags { - t.Errorf("stale body = %q, want %q", second.Body.String(), tags) - } - if got := second.Header().Get("Warning"); got != `110 - "Response is Stale"` { - t.Errorf("Warning = %q, want stale warning", got) - } - if upstreamRequests != 2 { - t.Errorf("upstream requests = %d, want 2", upstreamRequests) - } -} + t.Cleanup(func() { _ = db.Close() }) -func TestContainerHandler_TagsListCachesPaginationLink(t *testing.T) { - tags := `{"name":"library/nginx","tags":["1.0"]}` - upstreamAvailable := true - upstreamRequests := 0 - var upstream *httptest.Server - upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - upstreamRequests++ - if !upstreamAvailable { - http.Error(w, "upstream unavailable", http.StatusServiceUnavailable) - return - } - w.Header().Set("Content-Type", "application/json") - w.Header().Set("Link", `<`+upstream.URL+`/v2/library/nginx/tags/list?last=1.0&n=2>; rel="next"`) - _, _ = io.WriteString(w, tags) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.MetadataTTL = time.Hour - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://proxy.example.test"} - wantLink := `; rel="next"` - - warmRequest := httptest.NewRequest(http.MethodGet, "/library/nginx/tags/list?n=2", nil) - warm := httptest.NewRecorder() - h.Routes().ServeHTTP(warm, warmRequest) - if warm.Code != http.StatusOK { - t.Fatalf("warm status = %d, want 200: %s", warm.Code, warm.Body.String()) + store := newMockStorage() + logger := slog.New(slog.NewTextHandler(io.Discard, nil)) + proxy := &Proxy{ + DB: db, + Storage: store, + Fetcher: mf, + Logger: logger, + HTTPClient: &http.Client{}, } - if got := warm.Header().Get("Link"); got != wantLink { - t.Errorf("warm Link = %q, want %q", got, wantLink) - } - - fresh := httptest.NewRecorder() - h.Routes().ServeHTTP(fresh, httptest.NewRequest(http.MethodGet, "/library/nginx/tags/list?n=2", nil)) - if fresh.Code != http.StatusOK { - t.Fatalf("fresh status = %d, want 200: %s", fresh.Code, fresh.Body.String()) - } - if got := fresh.Header().Get("Link"); got != wantLink { - t.Errorf("fresh Link = %q, want %q", got, wantLink) - } - if upstreamRequests != 1 { - t.Fatalf("upstream requests after fresh cache hit = %d, want 1", upstreamRequests) - } - - proxy.MetadataTTL = 0 - upstreamAvailable = false - stale := httptest.NewRecorder() - h.Routes().ServeHTTP(stale, httptest.NewRequest(http.MethodGet, "/library/nginx/tags/list?n=2", nil)) - if stale.Code != http.StatusOK { - t.Fatalf("stale status = %d, want 200: %s", stale.Code, stale.Body.String()) - } - if got := stale.Header().Get("Link"); got != wantLink { - t.Errorf("stale Link = %q, want %q", got, wantLink) - } - if got := stale.Header().Get("Warning"); got != `110 - "Response is Stale"` { - t.Errorf("stale Warning = %q, want stale warning", got) - } - if upstreamRequests != 2 { - t.Errorf("upstream requests after stale fallback = %d, want 2", upstreamRequests) - } -} - -func TestContainerHandler_TagsListRewritesRelativePaginationLinkForNamedRegistry(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path != "/v2/owner/repo/tags/list" { - http.NotFound(w, r) - return - } - if r.URL.Query().Get("n") != "1" { - http.Error(w, "unexpected page size", http.StatusBadRequest) - return - } - - w.Header().Set("Content-Type", "application/json") - if r.URL.Query().Get("last") == "" { - w.Header().Set("Link", `; rel="next"`) - _, _ = io.WriteString(w, `{"name":"owner/repo","tags":["1.0"]}`) - return - } - if r.URL.Query().Get("last") != "1.0" { - http.Error(w, "unexpected pagination token", http.StatusBadRequest) - return - } - _, _ = io.WriteString(w, `{"name":"owner/repo","tags":["2.0"]}`) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - h := NewContainerHandler(proxy, "http://proxy.example.test", map[string]string{"test": upstream.URL}) - routes := http.StripPrefix("/v2", h.Routes()) - - first := httptest.NewRecorder() - routes.ServeHTTP(first, httptest.NewRequest(http.MethodGet, - "/v2/upstream/test/owner/repo/tags/list?n=1", nil)) - if first.Code != http.StatusOK { - t.Fatalf("first page status = %d, want 200: %s", first.Code, first.Body.String()) - } - const wantLink = `; rel="next"` - if got := first.Header().Get("Link"); got != wantLink { - t.Fatalf("first page Link = %q, want %q", got, wantLink) - } - - nextURL := strings.TrimPrefix(strings.SplitN(first.Header().Get("Link"), ">", 2)[0], "<") - next := httptest.NewRecorder() - routes.ServeHTTP(next, httptest.NewRequest(http.MethodGet, nextURL, nil)) - if next.Code != http.StatusOK { - t.Fatalf("next page status = %d, want 200: %s", next.Code, next.Body.String()) - } - if got, want := next.Body.String(), `{"name":"owner/repo","tags":["2.0"]}`; got != want { - t.Errorf("next page body = %q, want %q", got, want) - } -} - -func TestContainerHandler_NamedOCIRegistryServesHelmArtifacts(t *testing.T) { - const blob = "chart archive" - digest := "sha256:" + sha256Hex(blob) - manifest := `{"schemaVersion":2,"config":{"mediaType":"application/vnd.cncf.helm.config.v1+json"},"layers":[{"mediaType":"application/vnd.cncf.helm.chart.content.v1.tar+gzip","digest":"` + digest + `"}]}` - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.URL.Path { - case "/v2/owner/demo/manifests/1.0.0": - w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json") - w.Header().Set("Docker-Content-Digest", "sha256:"+sha256Hex(manifest)) - _, _ = io.WriteString(w, manifest) - case "/v2/owner/demo/blobs/" + digest: - w.Header().Set("Content-Type", "application/vnd.cncf.helm.chart.content.v1.tar+gzip") - _, _ = io.WriteString(w, blob) - default: - http.NotFound(w, r) - } - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0)) - proxy.Fetcher = fetcher - t.Cleanup(func() { _ = fetcher.Close() }) - h := NewContainerHandler(proxy, "http://proxy.example", map[string]string{"ghcr": upstream.URL}) - - manifestResponse := httptest.NewRecorder() - h.Routes().ServeHTTP(manifestResponse, - httptest.NewRequest(http.MethodGet, "/upstream/ghcr/owner/demo/manifests/1.0.0", nil)) - if manifestResponse.Code != http.StatusOK { - t.Fatalf("manifest status = %d, want 200: %s", manifestResponse.Code, manifestResponse.Body.String()) - } - if got := manifestResponse.Header().Get("Content-Type"); got != "application/vnd.oci.image.manifest.v1+json" { - t.Errorf("manifest Content-Type = %q", got) - } - - blobResponse := httptest.NewRecorder() - h.Routes().ServeHTTP(blobResponse, - httptest.NewRequest(http.MethodGet, "/upstream/ghcr/owner/demo/blobs/"+digest, nil)) - if blobResponse.Code != http.StatusOK { - t.Fatalf("blob status = %d, want 200: %s", blobResponse.Code, blobResponse.Body.String()) - } - if got := blobResponse.Header().Get("Content-Type"); got != "application/vnd.cncf.helm.chart.content.v1.tar+gzip" { - t.Errorf("blob Content-Type = %q", got) - } -} - -func TestContainerHandler_registryURLForUsesLongestRepositoryPrefix(t *testing.T) { - h := &ContainerHandler{registryURL: "https://registry-1.docker.io"} - h.RegisterRegistry("homebrew", "https://example.test") - h.RegisterRegistry("homebrew/core", "https://ghcr.io/") - - tests := map[string]string{ - "homebrew/core": "https://ghcr.io", - "homebrew/core/jq": "https://ghcr.io", - "homebrew/portable-ruby": "https://example.test", - "homebrew-core/jq": "https://registry-1.docker.io", - "library/homebrew/core/jq": "https://registry-1.docker.io", - } - for name, want := range tests { - if got := h.registryURLFor(name); got != want { - t.Errorf("registryURLFor(%q) = %q, want %q", name, got, want) - } - } -} - -func TestContainerHandler_BlobDownload_DiscoversBearerChallenge(t *testing.T) { - blob := "upstream blob" - digest := sha256Digest([]byte(blob)) - registryRequests := 0 - tokenRequests := 0 - var upstream *httptest.Server - upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.URL.Path { - case "/token": - tokenRequests++ - w.Header().Set("Content-Type", "application/json") - _ = json.NewEncoder(w).Encode(map[string]any{ - "token": "discovered-token", - "expires_in": 3600, - }) - case "/v2/library/nginx/blobs/" + digest: - registryRequests++ - if r.Header.Get("Authorization") != "Bearer discovered-token" { - w.Header().Set("WWW-Authenticate", `Bearer realm="`+upstream.URL+`/token",service="registry.test",scope="repository:library/nginx:pull"`) - http.Error(w, "authentication required", http.StatusUnauthorized) - return - } - w.Header().Set("Content-Type", "application/octet-stream") - _, _ = io.WriteString(w, blob) - default: - http.NotFound(w, r) - } - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - authTransport := upstreamhttp.NewTransport(http.DefaultTransport, nil) - client := &http.Client{Transport: authTransport} - artifactFetcher := fetch.NewFetcher( - fetch.WithHTTPClient(client), - fetch.WithMaxRetries(0), - ) - t.Cleanup(func() { _ = artifactFetcher.Close() }) - proxy.Fetcher = artifactFetcher - proxy.HTTPClient = client h := &ContainerHandler{ proxy: proxy, - registryURL: upstream.URL, + registryURL: "https://registry-1.docker.io", + authURL: authServer.URL, proxyURL: "http://localhost:8080", } - for range 2 { - req := httptest.NewRequest(http.MethodGet, "/library/nginx/blobs/"+digest, nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) - } - if got := w.Body.String(); got != blob { - t.Errorf("body = %q, want %q", got, blob) - } - } - - if tokenRequests != 1 { - t.Errorf("token requests = %d, want 1", tokenRequests) - } - if registryRequests != 2 { - t.Errorf("registry requests = %d, want 2", registryRequests) - } -} - -func TestContainerHandler_HomebrewBlobDoesNotForwardClientCredentialsToRegistryOrCDN(t *testing.T) { - blob := "homebrew bottle" - digest := sha256Digest([]byte(blob)) - var registryAuthorization, cdnAuthorization string - - cdn := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - cdnAuthorization = r.Header.Get("Authorization") - w.Header().Set("Content-Type", "application/vnd.homebrew.bottle") - _, _ = io.WriteString(w, blob) - })) - defer cdn.Close() - - registry := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - registryAuthorization = r.Header.Get("Authorization") - http.Redirect(w, r, cdn.URL+"/bottle", http.StatusTemporaryRedirect) - })) - defer registry.Close() - - defaultRequests := 0 - defaultRegistry := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - defaultRequests++ - http.NotFound(w, r) - })) - defer defaultRegistry.Close() - - proxy, _, _, _ := setupTestProxy(t) - client := registry.Client() - artifactFetcher := fetch.NewFetcher( - fetch.WithHTTPClient(client), - fetch.WithMaxRetries(0), - ) - t.Cleanup(func() { _ = artifactFetcher.Close() }) - proxy.Fetcher = artifactFetcher - - h := &ContainerHandler{proxy: proxy, registryURL: defaultRegistry.URL} - h.RegisterRegistry("homebrew/core", registry.URL) - req := httptest.NewRequest(http.MethodGet, "/homebrew/core/jq/blobs/"+digest, nil) - req.Header.Set("Authorization", "Bearer client-secret") + handler := h.Routes() + req := httptest.NewRequest(http.MethodGet, "/library/nginx/blobs/sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd", nil) w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) + handler.ServeHTTP(w, req) if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) + t.Errorf("got status %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) } - if got := w.Body.String(); got != blob { - t.Errorf("body = %q, want %q", got, blob) + + // Verify auth header was passed to the fetcher + if capturedHeaders == nil { + t.Fatal("expected headers to be passed to fetcher, got nil") } - if got := w.Header().Get("Content-Type"); got != "application/vnd.homebrew.bottle" { - t.Errorf("Content-Type = %q, want application/vnd.homebrew.bottle", got) + auth := capturedHeaders.Get("Authorization") + if auth != "Bearer test-token-123" { + t.Errorf("Authorization = %q, want %q", auth, "Bearer test-token-123") } - if registryAuthorization != "" { - t.Errorf("registry Authorization = %q, want empty", registryAuthorization) - } - if cdnAuthorization != "" { - t.Errorf("CDN Authorization = %q, want empty", cdnAuthorization) - } - if defaultRequests != 0 { - t.Errorf("default registry requests = %d, want 0", defaultRequests) + + // Verify response headers + if got := w.Header().Get("Docker-Content-Digest"); got != "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd" { + t.Errorf("Docker-Content-Digest = %q, want digest", got) } } -func TestContainerHandler_BlobDigestMismatchIsNotCached(t *testing.T) { - proxy, _, store, fetcher := setupTestProxy(t) - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("wrong bottle")), - ContentType: "application/octet-stream", - } - digest := sha256Digest([]byte("expected bottle")) - h := &ContainerHandler{proxy: proxy, registryURL: "https://registry.example.test"} - - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, "/homebrew/core/jq/blobs/"+digest, nil)) - - if w.Code != http.StatusBadGateway { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusBadGateway, w.Body.String()) - } - if !strings.Contains(w.Body.String(), "DIGEST_INVALID") { - t.Errorf("body = %q, want DIGEST_INVALID", w.Body.String()) - } - cached, err := proxy.GetCachedArtifact(t.Context(), "oci", "homebrew/core/jq", digest, digest) - if err != nil { - t.Fatalf("checking cache: %v", err) - } - if cached != nil { - t.Error("digest-mismatched blob was recorded in the cache") - } - if len(store.files) != 0 { - t.Errorf("stored files = %d, want 0", len(store.files)) - } +// mockFetcherWithHeaders captures headers passed to FetchWithHeaders. +type mockFetcherWithHeaders struct { + fetchFn func(ctx context.Context, url string, headers http.Header) (*fetch.Artifact, error) } -func TestContainerHandler_CachedImagePullSurvivesRegistryAndTokenOutages(t *testing.T) { - manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.manifest.v1+json"}` - blob := "cached image blob" - manifestDigest := sha256Digest([]byte(manifest)) - blobDigest := sha256Digest([]byte(blob)) - registryAvailable := true - tokenAvailable := true - registryRequests := 0 - tokenRequests := 0 - - tokenServer := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - tokenRequests++ - if !tokenAvailable { - http.Error(w, "token service unavailable", http.StatusServiceUnavailable) - return - } - w.Header().Set("Content-Type", "application/json") - _ = json.NewEncoder(w).Encode(map[string]any{ - "token": "discovered-token", - "expires_in": 3600, - }) - })) - defer tokenServer.Close() - - registryServer := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - registryRequests++ - if !registryAvailable { - http.Error(w, "registry unavailable", http.StatusServiceUnavailable) - return - } - if r.Header.Get("Authorization") != "Bearer discovered-token" { - w.Header().Set("WWW-Authenticate", `Bearer realm="`+tokenServer.URL+`",service="registry.test",scope="repository:library/nginx:pull"`) - http.Error(w, "authentication required", http.StatusUnauthorized) - return - } - - switch r.URL.Path { - case "/v2/library/nginx/manifests/latest": - w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json") - w.Header().Set("Docker-Content-Digest", manifestDigest) - _, _ = io.WriteString(w, manifest) - case "/v2/library/nginx/blobs/" + blobDigest: - w.Header().Set("Content-Type", "application/octet-stream") - _, _ = io.WriteString(w, blob) - default: - http.NotFound(w, r) - } - })) - defer registryServer.Close() - - warmProxy, db, store, _ := setupTestProxy(t) - warmClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport, nil)} - warmFetcher := fetch.NewFetcher( - fetch.WithHTTPClient(warmClient), - fetch.WithMaxRetries(0), - ) - t.Cleanup(func() { _ = warmFetcher.Close() }) - warmProxy.Fetcher = warmFetcher - warmProxy.HTTPClient = warmClient - warmProxy.MetadataTTL = time.Hour - warmHandler := (&ContainerHandler{ - proxy: warmProxy, - registryURL: registryServer.URL, - proxyURL: "http://localhost:8080", - }).Routes() - - for _, request := range []struct { - path string - body string - }{ - {path: "/library/nginx/manifests/latest", body: manifest}, - {path: "/library/nginx/blobs/" + blobDigest, body: blob}, - } { - response := httptest.NewRecorder() - warmHandler.ServeHTTP(response, httptest.NewRequest(http.MethodGet, request.path, nil)) - if response.Code != http.StatusOK { - t.Fatalf("warming %s: status = %d, want %d; body: %s", request.path, response.Code, http.StatusOK, response.Body.String()) - } - if got := response.Body.String(); got != request.body { - t.Fatalf("warming %s: body = %q, want %q", request.path, got, request.body) - } - } - - warmRegistryRequests := registryRequests - warmTokenRequests := tokenRequests - registryAvailable = false - tokenAvailable = false - - offlineClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport, nil)} - offlineFetcher := fetch.NewFetcher( - fetch.WithHTTPClient(offlineClient), - fetch.WithMaxRetries(0), - ) - t.Cleanup(func() { _ = offlineFetcher.Close() }) - offlineProxy := NewProxy(db, store, offlineFetcher, fetch.NewResolver(), warmProxy.Logger) - offlineProxy.HTTPClient = offlineClient - offlineProxy.MetadataTTL = time.Hour - offlineHandler := (&ContainerHandler{ - proxy: offlineProxy, - registryURL: registryServer.URL, - proxyURL: "http://localhost:8080", - }).Routes() - - for _, request := range []struct { - name string - path string - body string - digest string - }{ - {name: "tag manifest", path: "/library/nginx/manifests/latest", body: manifest, digest: manifestDigest}, - {name: "digest manifest", path: "/library/nginx/manifests/" + manifestDigest, body: manifest, digest: manifestDigest}, - {name: "blob", path: "/library/nginx/blobs/" + blobDigest, body: blob, digest: blobDigest}, - } { - t.Run(request.name, func(t *testing.T) { - response := httptest.NewRecorder() - offlineHandler.ServeHTTP(response, httptest.NewRequest(http.MethodGet, request.path, nil)) - if response.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", response.Code, http.StatusOK, response.Body.String()) - } - if got := response.Body.String(); got != request.body { - t.Errorf("body = %q, want %q", got, request.body) - } - if got := response.Header().Get("Docker-Content-Digest"); got != request.digest { - t.Errorf("Docker-Content-Digest = %q, want %q", got, request.digest) - } - }) - } - - if registryRequests != warmRegistryRequests { - t.Errorf("offline registry requests = %d, want 0", registryRequests-warmRegistryRequests) - } - if tokenRequests != warmTokenRequests { - t.Errorf("offline token requests = %d, want 0", tokenRequests-warmTokenRequests) - } +func (f *mockFetcherWithHeaders) Fetch(ctx context.Context, url string) (*fetch.Artifact, error) { + return f.FetchWithHeaders(ctx, url, nil) } -func TestContainerHandler_BlobDownload_CacheHitSkipsAuth(t *testing.T) { - proxy, db, store, fetcher := setupTestProxy(t) - digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd" - seedPackage(t, db, store, "oci", "library/nginx", digest, digest, "cached blob") - - upstreamRequests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - upstreamRequests++ - http.Error(w, "upstream unavailable", http.StatusServiceUnavailable) - })) - defer upstream.Close() - - h := &ContainerHandler{ - proxy: proxy, - registryURL: upstream.URL, - proxyURL: "http://localhost:8080", - } - - req := httptest.NewRequest(http.MethodGet, "/library/nginx/blobs/"+digest, nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) - } - if got := w.Body.String(); got != "cached blob" { - t.Errorf("body = %q, want %q", got, "cached blob") - } - if upstreamRequests != 0 { - t.Errorf("upstream requests = %d, want 0", upstreamRequests) - } - if fetcher.fetchCalled { - t.Error("fetcher should not be called on cache hit") - } +func (f *mockFetcherWithHeaders) FetchWithHeaders(ctx context.Context, url string, headers http.Header) (*fetch.Artifact, error) { + return f.fetchFn(ctx, url, headers) } -func TestContainerHandler_BlobHead_CacheHitSkipsUpstreamAndAuth(t *testing.T) { - proxy, db, store, fetcher := setupTestProxy(t) - digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd" - seedPackage(t, db, store, "oci", "library/nginx", digest, digest, "cached blob") - - upstreamRequests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - upstreamRequests++ - http.Error(w, "upstream unavailable", http.StatusServiceUnavailable) - })) - defer upstream.Close() - proxy.HTTPClient = upstream.Client() - - h := &ContainerHandler{ - proxy: proxy, - registryURL: upstream.URL, - proxyURL: "http://localhost:8080", - } - - req := httptest.NewRequest(http.MethodHead, "/library/nginx/blobs/"+digest, nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) - } - if got := w.Header().Get("Docker-Content-Digest"); got != digest { - t.Errorf("Docker-Content-Digest = %q, want %q", got, digest) - } - if got := w.Header().Get("Content-Length"); got != "11" { - t.Errorf("Content-Length = %q, want %q", got, "11") - } - if w.Body.Len() != 0 { - t.Errorf("HEAD response body length = %d, want 0", w.Body.Len()) - } - if upstreamRequests != 0 { - t.Errorf("upstream requests = %d, want 0", upstreamRequests) - } - if fetcher.fetchCalled { - t.Error("fetcher should not be called on cache hit") - } -} - -func TestContainerHandler_BlobHead_DirectServeRedirects(t *testing.T) { - proxy, db, store, fetcher := setupTestProxy(t) - digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd" - seedPackage(t, db, store, "oci", "library/nginx", digest, digest, "cached blob") - store.signedURL = "https://storage.example.test/cached-blob?signature=test" - proxy.DirectServe = true - - h := &ContainerHandler{ - proxy: proxy, - registryURL: "https://registry.example.test", - proxyURL: "http://localhost:8080", - } - - req := httptest.NewRequest(http.MethodHead, "/library/nginx/blobs/"+digest, nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusFound { - t.Fatalf("status = %d, want %d", w.Code, http.StatusFound) - } - if got := w.Header().Get("Location"); got != store.signedURL { - t.Errorf("Location = %q, want %q", got, store.signedURL) - } - wantETag := `"` + sha256Hex("cached blob") + `"` - if got := w.Header().Get("ETag"); got != wantETag { - t.Errorf("ETag = %q, want %q", got, wantETag) - } - if w.Body.Len() != 0 { - t.Errorf("HEAD response body length = %d, want 0", w.Body.Len()) - } - if fetcher.fetchCalled { - t.Error("fetcher should not be called on cache hit") - } -} - -func TestContainerHandler_ManifestByDigest_CacheHitSkipsUpstream(t *testing.T) { - manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.manifest.v1+json"}` - digest := sha256Digest([]byte(manifest)) - lastModified := time.Date(2026, time.August, 14, 9, 30, 0, 0, time.UTC) - upstreamAvailable := true - upstreamRequests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - upstreamRequests++ - if !upstreamAvailable { - http.Error(w, "upstream unavailable", http.StatusServiceUnavailable) - return - } - if r.URL.Path != "/v2/library/nginx/manifests/"+digest { - http.NotFound(w, r) - return - } - w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json") - w.Header().Set("Docker-Content-Digest", digest) - w.Header().Set("ETag", `"manifest-etag"`) - w.Header().Set("Last-Modified", lastModified.Format(http.TimeFormat)) - if r.Method != http.MethodHead { - _, _ = io.WriteString(w, manifest) - } - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"} - - first := httptest.NewRecorder() - h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/"+digest, nil)) - if first.Code != http.StatusOK { - t.Fatalf("initial status = %d, want %d; body: %s", first.Code, http.StatusOK, first.Body.String()) - } - if first.Body.String() != manifest { - t.Fatalf("initial body = %q, want %q", first.Body.String(), manifest) - } - - upstreamAvailable = false - second := httptest.NewRecorder() - h.Routes().ServeHTTP(second, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/"+digest, nil)) - if second.Code != http.StatusOK { - t.Fatalf("cached status = %d, want %d; body: %s", second.Code, http.StatusOK, second.Body.String()) - } - if second.Body.String() != manifest { - t.Errorf("cached body = %q, want %q", second.Body.String(), manifest) - } - if got := second.Header().Get("Docker-Content-Digest"); got != digest { - t.Errorf("cached Docker-Content-Digest = %q, want %q", got, digest) - } - if got := second.Header().Get("Last-Modified"); got != lastModified.Format(http.TimeFormat) { - t.Errorf("cached Last-Modified = %q, want %q", got, lastModified.Format(http.TimeFormat)) - } - - conditionalRequest := httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/"+digest, nil) - conditionalRequest.Header.Set("If-None-Match", `"manifest-etag"`) - conditional := httptest.NewRecorder() - h.Routes().ServeHTTP(conditional, conditionalRequest) - if conditional.Code != http.StatusNotModified { - t.Fatalf("conditional status = %d, want %d", conditional.Code, http.StatusNotModified) - } - if got := conditional.Header().Get("ETag"); got != `"manifest-etag"` { - t.Errorf("conditional ETag = %q, want %q", got, `"manifest-etag"`) - } - if conditional.Body.Len() != 0 { - t.Errorf("conditional body length = %d, want 0", conditional.Body.Len()) - } - - head := httptest.NewRecorder() - h.Routes().ServeHTTP(head, httptest.NewRequest(http.MethodHead, "/library/nginx/manifests/"+digest, nil)) - if head.Code != http.StatusOK { - t.Fatalf("cached HEAD status = %d, want %d", head.Code, http.StatusOK) - } - wantLength := strconv.Itoa(len(manifest)) - if got := head.Header().Get("Content-Length"); got != wantLength { - t.Errorf("cached HEAD Content-Length = %q, want %q", got, wantLength) - } - if head.Body.Len() != 0 { - t.Errorf("cached HEAD body length = %d, want 0", head.Body.Len()) - } - if upstreamRequests != 1 { - t.Errorf("upstream requests = %d, want 1", upstreamRequests) - } -} - -func TestContainerHandler_ManifestDigestMismatchIsNotCached(t *testing.T) { - manifest := `{"schemaVersion":2}` - digest := sha256Digest([]byte("different manifest")) - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json") - w.Header().Set("Docker-Content-Digest", digest) - _, _ = io.WriteString(w, manifest) - })) - defer upstream.Close() - - proxy, db, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL} - req := httptest.NewRequest(http.MethodGet, "/homebrew/core/jq/manifests/"+digest, nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusBadGateway { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusBadGateway, w.Body.String()) - } - if !strings.Contains(w.Body.String(), "DIGEST_INVALID") { - t.Errorf("body = %q, want DIGEST_INVALID", w.Body.String()) - } - cacheKey := h.containerManifestCacheKey(upstream.URL, "homebrew/core/jq", digest, containerManifestAccept(req)) - entry, err := db.GetMetadataCache(containerManifestCacheEcosystem, cacheKey) - if err != nil { - t.Fatalf("checking manifest cache: %v", err) - } - if entry != nil { - t.Error("digest-mismatched manifest was recorded in the cache") - } -} - -func TestContainerHandler_ManifestNonSHA256DigestReferenceIsProxied(t *testing.T) { - manifest := `{"schemaVersion":2}` - sha512Reference := "sha512:" + strings.Repeat("a", 128) - sha512Header := "sha512:" + strings.Repeat("b", 128) - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json") - w.Header().Set("Docker-Content-Digest", sha512Header) - _, _ = io.WriteString(w, manifest) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL} - - for _, reference := range []string{sha512Reference, "latest"} { - t.Run(reference, func(t *testing.T) { - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/"+reference, nil)) - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) - } - if got := w.Body.String(); got != manifest { - t.Errorf("body = %q, want %q", got, manifest) - } - if got := w.Header().Get("Docker-Content-Digest"); got != sha512Header { - t.Errorf("Docker-Content-Digest = %q, want %q", got, sha512Header) - } - }) - } -} - -func TestContainerHandler_ManifestTagWithInvalidDigestIsNotAliased(t *testing.T) { - manifest := `{"schemaVersion":2}` - invalidDigest := sha256Digest([]byte("different manifest")) - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json") - w.Header().Set("Docker-Content-Digest", invalidDigest) - _, _ = io.WriteString(w, manifest) - })) - defer upstream.Close() - - proxy, db, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL} - req := httptest.NewRequest(http.MethodGet, "/homebrew/core/jq/manifests/latest", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusBadGateway { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusBadGateway, w.Body.String()) - } - cacheKey := h.containerManifestCacheKey(upstream.URL, "homebrew/core/jq", invalidDigest, containerManifestAccept(req)) - entry, err := db.GetMetadataCache(containerManifestCacheEcosystem, cacheKey) - if err != nil { - t.Fatalf("checking manifest cache: %v", err) - } - if entry != nil { - t.Error("tag manifest was cached under an unverified digest") - } -} - -func TestContainerHandler_ManifestByTag_UsesStaleCacheOnUpstreamFailure(t *testing.T) { - manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.index.v1+json"}` - digest := sha256Digest([]byte(manifest)) - upstreamAvailable := true - upstreamRequests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - upstreamRequests++ - if !upstreamAvailable { - http.Error(w, "upstream unavailable", http.StatusServiceUnavailable) - return - } - w.Header().Set("Content-Type", "application/vnd.oci.image.index.v1+json") - w.Header().Set("Docker-Content-Digest", digest) - _, _ = io.WriteString(w, manifest) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.MetadataTTL = 0 - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"} - - first := httptest.NewRecorder() - h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil)) - if first.Code != http.StatusOK { - t.Fatalf("initial status = %d, want %d; body: %s", first.Code, http.StatusOK, first.Body.String()) - } - - upstreamAvailable = false - second := httptest.NewRecorder() - h.Routes().ServeHTTP(second, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil)) - if second.Code != http.StatusOK { - t.Fatalf("stale status = %d, want %d; body: %s", second.Code, http.StatusOK, second.Body.String()) - } - if second.Body.String() != manifest { - t.Errorf("stale body = %q, want %q", second.Body.String(), manifest) - } - if got := second.Header().Get("Warning"); got != `110 - "Response is Stale"` { - t.Errorf("Warning = %q, want stale warning", got) - } - if got := second.Header().Get("Docker-Content-Digest"); got != digest { - t.Errorf("stale Docker-Content-Digest = %q, want %q", got, digest) - } - if upstreamRequests != 2 { - t.Errorf("upstream requests = %d, want 2", upstreamRequests) - } -} - -func TestContainerHandler_ManifestVariantCacheNormalizesCompatibleAccept(t *testing.T) { - manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.index.v1+json"}` - digest := sha256Digest([]byte(manifest)) - upstreamAvailable := true - upstreamRequests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - upstreamRequests++ - if !upstreamAvailable { - http.Error(w, "upstream unavailable", http.StatusServiceUnavailable) - return - } - w.Header().Set("Content-Type", "") - w.Header().Set("Docker-Content-Digest", digest) - _, _ = io.WriteString(w, manifest) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.MetadataTTL = 0 - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"} - - firstRequest := httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil) - firstRequest.Header.Set("Accept", "application/vnd.oci.image.index.v1+json;q=1, application/vnd.oci.image.manifest.v1+json;q=1, application/vnd.oci.image.index.v1+json;q=1") - first := httptest.NewRecorder() - h.Routes().ServeHTTP(first, firstRequest) - if first.Code != http.StatusOK { - t.Fatalf("initial status = %d, want 200: %s", first.Code, first.Body.String()) - } - - upstreamAvailable = false - secondRequest := httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil) - secondRequest.Header.Set("Accept", " application/vnd.oci.image.manifest.v1+json , application/vnd.oci.image.index.v1+json ") - second := httptest.NewRecorder() - h.Routes().ServeHTTP(second, secondRequest) - if second.Code != http.StatusOK { - t.Fatalf("stale status = %d, want 200: %s", second.Code, second.Body.String()) - } - if second.Body.String() != manifest { - t.Errorf("stale body = %q, want %q", second.Body.String(), manifest) - } - if got := second.Header().Get("Warning"); got != `110 - "Response is Stale"` { - t.Errorf("Warning = %q, want stale warning", got) - } - if upstreamRequests != 2 { - t.Errorf("upstream requests = %d, want 2", upstreamRequests) - } -} - -func TestContainerHandler_ManifestMigratesLegacyAcceptCacheKey(t *testing.T) { - digest := "sha256:cdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcd" - manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.index.v1+json"}` - upstreamRequests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - upstreamRequests++ - http.Error(w, "upstream should not be called", http.StatusServiceUnavailable) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.MetadataTTL = time.Hour - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"} - accept := "application/vnd.oci.image.index.v1+json;q=1, application/vnd.oci.image.manifest.v1+json;q=1" - cacheAccept := normalizeContainerManifestAccept(accept) - legacyCacheKey := h.containerManifestCacheKey(upstream.URL, "library/nginx", "latest", accept) - cacheKey := h.containerManifestCacheKey(upstream.URL, "library/nginx", "latest", cacheAccept) - if legacyCacheKey == cacheKey { - t.Fatal("legacy and normalized cache keys are equal") - } - - request := httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil) - request.Header.Set("Accept", accept) - legacyManifest := &cachedContainerManifest{ - body: []byte(manifest), - contentType: "application/vnd.oci.image.index.v1+json", - contentDigest: digest, - fetchedAt: time.Now(), - } - if err := h.storeContainerManifest(request.Context(), legacyCacheKey, legacyManifest); err != nil { - t.Fatalf("store legacy manifest: %v", err) - } - - response := httptest.NewRecorder() - h.Routes().ServeHTTP(response, request) - if response.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", response.Code, response.Body.String()) - } - if response.Body.String() != manifest { - t.Errorf("body = %q, want %q", response.Body.String(), manifest) - } - if upstreamRequests != 0 { - t.Errorf("upstream requests = %d, want 0", upstreamRequests) - } - migrated, err := h.loadContainerManifest(request.Context(), cacheKey) - if err != nil { - t.Fatalf("load migrated manifest: %v", err) - } - if migrated == nil { - t.Error("normalized cache entry was not created") - } -} - -func TestContainerHandler_ManifestDualWritesLegacyAcceptCacheKeys(t *testing.T) { - manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.manifest.v1+json"}` - digest := sha256Digest([]byte(manifest)) - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path != "/v2/library/nginx/manifests/latest" { - http.NotFound(w, r) - return - } - w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json") - w.Header().Set("Docker-Content-Digest", digest) - _, _ = io.WriteString(w, manifest) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"} - accept := "application/vnd.oci.image.manifest.v1+json;q=1, application/vnd.oci.image.manifest.v1+json;q=1" - request := httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil) - request.Header.Set("Accept", accept) - response := httptest.NewRecorder() - h.Routes().ServeHTTP(response, request) - if response.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", response.Code, response.Body.String()) - } - - for _, reference := range []string{"latest", digest} { - legacyCacheKey := h.containerManifestCacheKey(upstream.URL, "library/nginx", reference, accept) - cached, err := h.loadContainerManifest(request.Context(), legacyCacheKey) - if err != nil { - t.Fatalf("load legacy %s manifest: %v", reference, err) - } - if cached == nil { - t.Errorf("legacy %s cache entry was not written", reference) - } - } -} - -func TestContainerHandler_ManifestVariantCacheHonorsSpecificAcceptExclusions(t *testing.T) { - manifest := `{"schemaVersion":2}` - digest := sha256Digest([]byte(manifest)) - upstreamAvailable := true - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - if !upstreamAvailable { - http.Error(w, "upstream unavailable", http.StatusServiceUnavailable) - return - } - w.Header().Set("Content-Type", "application/vnd.oci.image.index.v1+json") - w.Header().Set("Docker-Content-Digest", digest) - _, _ = io.WriteString(w, manifest) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.MetadataTTL = 0 - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"} - - warmRequest := httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil) - warmRequest.Header.Set("Accept", "application/vnd.oci.image.index.v1+json;q=0, */*;q=1") - warm := httptest.NewRecorder() - h.Routes().ServeHTTP(warm, warmRequest) - if warm.Code != http.StatusOK { - t.Fatalf("warm status = %d, want 200", warm.Code) - } - - upstreamAvailable = false - offlineRequest := httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil) - offlineRequest.Header.Set("Accept", "application/vnd.oci.image.index.v1+json;q=0, */*;q=1") - offline := httptest.NewRecorder() - h.Routes().ServeHTTP(offline, offlineRequest) - if offline.Code != http.StatusServiceUnavailable { - t.Errorf("offline status = %d, want 503", offline.Code) - } -} - -func TestContainerHandler_ManifestVariantCacheHonorsParameterizedAcceptExclusions(t *testing.T) { - contentType := "application/vnd.oci.image.index.v1+json; charset=utf-8" - upstreamAvailable := true - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - if !upstreamAvailable { - http.Error(w, "upstream unavailable", http.StatusServiceUnavailable) - return - } - w.Header().Set("Content-Type", contentType) - _, _ = io.WriteString(w, `{"schemaVersion":2}`) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.MetadataTTL = 0 - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"} - accept := "application/vnd.oci.image.index.v1+json;q=1, application/vnd.oci.image.index.v1+json;charset=utf-8;q=0" - - warmRequest := httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil) - warmRequest.Header.Set("Accept", accept) - warm := httptest.NewRecorder() - h.Routes().ServeHTTP(warm, warmRequest) - if warm.Code != http.StatusOK { - t.Fatalf("warm status = %d, want 200", warm.Code) - } - - upstreamAvailable = false - offlineRequest := httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil) - offlineRequest.Header.Set("Accept", accept) - offline := httptest.NewRecorder() - h.Routes().ServeHTTP(offline, offlineRequest) - if offline.Code != http.StatusServiceUnavailable { - t.Errorf("offline status = %d, want 503", offline.Code) - } -} - -func TestContainerHandler_ManifestByTag_CachesDigestAlias(t *testing.T) { - manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.manifest.v1+json"}` - digest := sha256Digest([]byte(manifest)) - upstreamAvailable := true - upstreamRequests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - upstreamRequests++ - if !upstreamAvailable { - http.Error(w, "upstream unavailable", http.StatusServiceUnavailable) - return - } - if r.URL.Path != "/v2/library/nginx/manifests/latest" { - http.NotFound(w, r) - return - } - w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json") - w.Header().Set("Docker-Content-Digest", digest) - _, _ = io.WriteString(w, manifest) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"} - - first := httptest.NewRecorder() - h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil)) - if first.Code != http.StatusOK { - t.Fatalf("tag status = %d, want %d; body: %s", first.Code, http.StatusOK, first.Body.String()) - } - - upstreamAvailable = false - byDigest := httptest.NewRecorder() - h.Routes().ServeHTTP(byDigest, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/"+digest, nil)) - if byDigest.Code != http.StatusOK { - t.Fatalf("digest status = %d, want %d; body: %s", byDigest.Code, http.StatusOK, byDigest.Body.String()) - } - if byDigest.Body.String() != manifest { - t.Errorf("digest body = %q, want %q", byDigest.Body.String(), manifest) - } - if got := byDigest.Header().Get("Docker-Content-Digest"); got != digest { - t.Errorf("Docker-Content-Digest = %q, want %q", got, digest) - } - if upstreamRequests != 1 { - t.Errorf("upstream requests = %d, want 1", upstreamRequests) - } -} - -func TestContainerHandler_ManifestByTag_StaleHeadChecksUpstream(t *testing.T) { - manifest := `{"schemaVersion":2}` - oldDigest := sha256Digest([]byte(manifest)) - newDigest := "sha256:eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee" - currentDigest := oldDigest - upstreamRequests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - upstreamRequests++ - w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json") - w.Header().Set("Docker-Content-Digest", currentDigest) - w.Header().Set("ETag", `"`+currentDigest+`"`) - if r.Method != http.MethodHead { - _, _ = io.WriteString(w, manifest) - } - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.MetadataTTL = 0 - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"} - - first := httptest.NewRecorder() - h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil)) - if first.Code != http.StatusOK { - t.Fatalf("initial status = %d, want %d", first.Code, http.StatusOK) - } - - currentDigest = newDigest - head := httptest.NewRecorder() - h.Routes().ServeHTTP(head, httptest.NewRequest(http.MethodHead, "/library/nginx/manifests/latest", nil)) - if head.Code != http.StatusOK { - t.Fatalf("HEAD status = %d, want %d", head.Code, http.StatusOK) - } - if got := head.Header().Get("Docker-Content-Digest"); got != newDigest { - t.Errorf("Docker-Content-Digest = %q, want %q", got, newDigest) - } - if upstreamRequests != 2 { - t.Errorf("upstream requests = %d, want 2", upstreamRequests) - } +func (f *mockFetcherWithHeaders) Head(_ context.Context, _ string) (int64, string, error) { + return 0, "", nil } func TestContainerHandler_Routes_VersionCheck(t *testing.T) { diff --git a/internal/handler/cran.go b/internal/handler/cran.go index 4a6ded8..246fcaa 100644 --- a/internal/handler/cran.go +++ b/internal/handler/cran.go @@ -25,13 +25,6 @@ func NewCRANHandler(proxy *Proxy, proxyURL string) *CRANHandler { } } -// NewCRANHandlerWithUpstream creates a CRAN handler with a custom upstream. -func NewCRANHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *CRANHandler { - h := NewCRANHandler(proxy, proxyURL) - h.upstreamURL = configuredUpstreamURL(upstreamURL, cranUpstream) - return h -} - // Routes returns the HTTP handler for CRAN requests. func (h *CRANHandler) Routes() http.Handler { mux := http.NewServeMux() @@ -79,7 +72,8 @@ func (h *CRANHandler) handleSourceDownload(w http.ResponseWriter, r *http.Reques result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "cran", name, version, filename, upstreamURL) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch package") + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch package", http.StatusBadGateway) return } @@ -113,7 +107,8 @@ func (h *CRANHandler) handleBinaryDownload(w http.ResponseWriter, r *http.Reques result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "cran", name, storageVersion, filename, upstreamURL) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch package") + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch package", http.StatusBadGateway) return } @@ -164,5 +159,5 @@ func (h *CRANHandler) proxyCached(w http.ResponseWriter, r *http.Request) { // proxyUpstream forwards a request to CRAN without caching. func (h *CRANHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) { - h.proxy.ProxyUpstream(w, r, h.upstreamURL+r.URL.Path, []string{headerAcceptEncoding}) + h.proxy.ProxyUpstream(w, r, h.upstreamURL+r.URL.Path, []string{"Accept-Encoding"}) } diff --git a/internal/handler/debian.go b/internal/handler/debian.go index 42d26e7..b767f6d 100644 --- a/internal/handler/debian.go +++ b/internal/handler/debian.go @@ -21,13 +21,10 @@ type DebianHandler struct { } // NewDebianHandler creates a new Debian/APT protocol handler. -func NewDebianHandler(proxy *Proxy, proxyURL string, upstreamURL string) *DebianHandler { - if upstreamURL == "" { - upstreamURL = debianUpstream - } +func NewDebianHandler(proxy *Proxy, proxyURL string) *DebianHandler { return &DebianHandler{ proxy: proxy, - upstreamURL: strings.TrimSuffix(upstreamURL, "/"), + upstreamURL: debianUpstream, proxyURL: strings.TrimSuffix(proxyURL, "/"), } } @@ -84,11 +81,12 @@ func (h *DebianHandler) handlePackageDownload(w http.ResponseWriter, r *http.Req result, err := h.proxy.GetOrFetchArtifactFromURL( r.Context(), "deb", name, version, filename, downloadURL) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch package") + h.proxy.Logger.Error("failed to get debian package", "error", err) + http.Error(w, "failed to fetch package", http.StatusBadGateway) return } - w.Header().Set(headerContentType, "application/vnd.debian.binary-package") + w.Header().Set("Content-Type", "application/vnd.debian.binary-package") ServeArtifact(w, result) } diff --git a/internal/handler/debian_test.go b/internal/handler/debian_test.go index b086fdf..dfdd326 100644 --- a/internal/handler/debian_test.go +++ b/internal/handler/debian_test.go @@ -12,17 +12,12 @@ func TestDebianHandler_parsePoolPath(t *testing.T) { {"pool/main/libn/libncurses/libncurses6_6.2-1_amd64.deb", "libncurses6", "6.2-1", "amd64"}, {"pool/contrib/v/virtualbox/virtualbox_6.1.38-1_amd64.deb", "virtualbox", "6.1.38-1", "amd64"}, {"pool/main/g/git/git_2.39.2-1_arm64.deb", "git", "2.39.2-1", "arm64"}, - { - "pool/universe/n/nmap/nmap_7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1_amd64.deb", - "nmap", "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1", "amd64", - }, - {"pool/main/o/openssl/openssl_3.0.2-0ubuntu1.15~build1_amd64.deb", "openssl", "3.0.2-0ubuntu1.15~build1", "amd64"}, {"invalid/path", "", "", ""}, {"pool/main/n/nginx/nginx.deb", "", "", ""}, }) } func TestDebianHandler_Routes(t *testing.T) { - h := NewDebianHandler(nil, "http://localhost:8080", "") + h := NewDebianHandler(nil, "http://localhost:8080") assertRoutesBasics(t, h.Routes(), "/dists/stable/Release", "/pool/../../../etc/passwd") } diff --git a/internal/handler/download_test.go b/internal/handler/download_test.go index e0cf9cc..639e976 100644 --- a/internal/handler/download_test.go +++ b/internal/handler/download_test.go @@ -11,7 +11,6 @@ import ( "time" "github.com/git-pkgs/proxy/internal/database" - "github.com/git-pkgs/proxy/internal/metrics" "github.com/git-pkgs/proxy/internal/storage" "github.com/git-pkgs/purl" "github.com/git-pkgs/registries/fetch" @@ -44,14 +43,13 @@ func seedPackageWithPURL(t *testing.T, db *database.DB, store *mockStorage, ecos storagePath := storage.ArtifactPath(ecosystem, "", name, version, filename) store.files[storagePath] = []byte(content) - sharedArtifact := testArtifact(content, versionPURL, filename, "application/octet-stream") art := &database.Artifact{ VersionPURL: versionPURL, Filename: filename, UpstreamURL: "https://example.com/" + filename, StoragePath: sql.NullString{String: storagePath, Valid: true}, - ContentHash: sql.NullString{String: sharedArtifact.Digest.Encoded(), Valid: true}, + ContentHash: sql.NullString{String: "abc123", Valid: true}, Size: sql.NullInt64{Int64: int64(len(content)), Valid: true}, ContentType: sql.NullString{String: "application/octet-stream", Valid: true}, FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, @@ -205,19 +203,16 @@ func TestGemHandler_UpstreamProxy(t *testing.T) { func TestGemHandler_CacheMiss(t *testing.T) { proxy, _, _, fetcher := setupTestProxy(t) - fetchesBefore := histogramSampleCount(t, metrics.UpstreamFetchDuration.WithLabelValues("gem")) fetcher.artifact = &fetch.Artifact{ Body: io.NopCloser(strings.NewReader("fetched gem")), ContentType: "application/octet-stream", } - upstreamURL := "https://packages.example.com/gem" - h := NewGemHandlerWithUpstream(proxy, "http://localhost", upstreamURL) + h := NewGemHandler(proxy, "http://localhost") srv := httptest.NewServer(h.Routes()) defer srv.Close() - path := "/gems/sinatra-3.0.0.gem" - resp, err := http.Get(srv.URL + path) + resp, err := http.Get(srv.URL + "/gems/sinatra-3.0.0.gem") if err != nil { t.Fatalf("request failed: %v", err) } @@ -226,12 +221,6 @@ func TestGemHandler_CacheMiss(t *testing.T) { if !fetcher.fetchCalled { t.Error("expected fetcher to be called on cache miss") } - if want := upstreamURL + path; fetcher.fetchedURL != want { - t.Errorf("upstream URL = %q, want %q", fetcher.fetchedURL, want) - } - if diff := histogramSampleCount(t, metrics.UpstreamFetchDuration.WithLabelValues("gem")) - fetchesBefore; diff != 1 { - t.Errorf("upstream fetch observations delta = %d, want 1", diff) - } } func TestGoHandler_DownloadCacheHit(t *testing.T) { @@ -353,13 +342,11 @@ func TestGoHandler_CacheMiss(t *testing.T) { ContentType: "application/zip", } - upstreamURL := "https://packages.example.com/go" - h := NewGoHandlerWithUpstream(proxy, "http://localhost", upstreamURL) + h := NewGoHandler(proxy, "http://localhost") srv := httptest.NewServer(h.Routes()) defer srv.Close() - path := "/example.com/mod/@v/v1.0.0.zip" - resp, err := http.Get(srv.URL + path) + resp, err := http.Get(srv.URL + "/example.com/mod/@v/v1.0.0.zip") if err != nil { t.Fatalf("request failed: %v", err) } @@ -368,9 +355,6 @@ func TestGoHandler_CacheMiss(t *testing.T) { if !fetcher.fetchCalled { t.Error("expected fetcher to be called on cache miss") } - if want := upstreamURL + path; fetcher.fetchedURL != want { - t.Errorf("upstream URL = %q, want %q", fetcher.fetchedURL, want) - } } func TestHexHandler_DownloadCacheHit(t *testing.T) { @@ -439,13 +423,11 @@ func TestHexHandler_CacheMiss(t *testing.T) { ContentType: "application/x-tar", } - upstreamURL := "https://packages.example.com/hex" - h := NewHexHandlerWithUpstreams(proxy, "http://localhost", upstreamURL, "https://packages.example.com/hex-api") + h := NewHexHandler(proxy, "http://localhost") srv := httptest.NewServer(h.Routes()) defer srv.Close() - path := "/tarballs/plug-1.15.0.tar" - resp, err := http.Get(srv.URL + path) + resp, err := http.Get(srv.URL + "/tarballs/plug-1.15.0.tar") if err != nil { t.Fatalf("request failed: %v", err) } @@ -454,36 +436,6 @@ func TestHexHandler_CacheMiss(t *testing.T) { if !fetcher.fetchCalled { t.Error("expected fetcher to be called on cache miss") } - if want := upstreamURL + path; fetcher.fetchedURL != want { - t.Errorf("upstream URL = %q, want %q", fetcher.fetchedURL, want) - } -} - -func TestPubHandler_CacheMiss(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("fetched pub package")), - ContentType: "application/gzip", - } - - upstreamURL := "https://packages.example.com/pub" - h := NewPubHandlerWithUpstream(proxy, "http://localhost", upstreamURL) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - path := "/packages/flutter_bloc/versions/8.1.6.tar.gz" - resp, err := http.Get(srv.URL + path) - if err != nil { - t.Fatalf("request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if !fetcher.fetchCalled { - t.Error("expected fetcher to be called on cache miss") - } - if want := upstreamURL + path; fetcher.fetchedURL != want { - t.Errorf("upstream URL = %q, want %q", fetcher.fetchedURL, want) - } } func TestCondaHandler_DownloadCacheHit(t *testing.T) { @@ -721,7 +673,7 @@ func TestMavenHandler_DownloadCacheHit(t *testing.T) { proxy, db, store, _ := setupTestProxy(t) seedPackageWithPURL(t, db, store, "maven", "com.google.guava:guava", "32.1.3-jre", "guava-32.1.3-jre.jar", "jar content") - h := NewMavenHandler(proxy, "http://localhost", "", "") + h := NewMavenHandler(proxy, "http://localhost") srv := httptest.NewServer(h.Routes()) defer srv.Close() @@ -778,7 +730,7 @@ func TestMavenHandler_MetadataProxied(t *testing.T) { func TestMavenHandler_EmptyPathNotFound(t *testing.T) { proxy, _, _, _ := setupTestProxy(t) - h := NewMavenHandler(proxy, "http://localhost", "", "") + h := NewMavenHandler(proxy, "http://localhost") srv := httptest.NewServer(h.Routes()) defer srv.Close() @@ -796,7 +748,7 @@ func TestMavenHandler_EmptyPathNotFound(t *testing.T) { func TestMavenHandler_ArtifactExtensions(t *testing.T) { proxy, _, _, fetcher := setupTestProxy(t) - extensions := []string{".jar", ".war", ".ear", ".pom", ".aar", ".klib", ".module"} + extensions := []string{".jar", ".war", ".ear", ".pom", ".aar", ".klib"} for _, ext := range extensions { fetcher.artifact = &fetch.Artifact{ Body: io.NopCloser(strings.NewReader("artifact")), @@ -804,7 +756,7 @@ func TestMavenHandler_ArtifactExtensions(t *testing.T) { } fetcher.fetchCalled = false - h := NewMavenHandler(proxy, "http://localhost", "", "") + h := NewMavenHandler(proxy, "http://localhost") upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { t.Errorf("should not proxy artifact file %s to upstream", ext) @@ -837,7 +789,7 @@ func TestMavenHandler_CacheMiss(t *testing.T) { ContentType: "application/java-archive", } - h := NewMavenHandler(proxy, "http://localhost", "", "") + h := NewMavenHandler(proxy, "http://localhost") srv := httptest.NewServer(h.Routes()) defer srv.Close() @@ -857,274 +809,6 @@ func TestMavenHandler_CacheMiss(t *testing.T) { } } -func TestMavenHandler_GradlePluginMarkerFallbackAndCache(t *testing.T) { - tests := []struct { - name string - markerPath string - }{ - { - name: "Spotless", - markerPath: "/com/diffplug/spotless/com.diffplug.spotless.gradle.plugin/8.4.0/com.diffplug.spotless.gradle.plugin-8.4.0.pom", - }, - { - name: "BenManes", - markerPath: "/com/github/ben-manes/versions/com.github.ben-manes.versions.gradle.plugin/0.54.0/com.github.ben-manes.versions.gradle.plugin-0.54.0.pom", - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - - primaryUpstream := "https://repo1.maven.org/maven2" - pluginPortalUpstream := "https://plugins.gradle.org/m2" - primaryURL := primaryUpstream + tt.markerPath - - fetcher.fetchErrByURL = map[string]error{ - primaryURL: ErrUpstreamNotFound, - } - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("")), - ContentType: "application/xml", - } - - h := NewMavenHandler(proxy, "http://localhost", primaryUpstream, pluginPortalUpstream) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + tt.markerPath) - if err != nil { - t.Fatalf("request failed: %v", err) - } - body, _ := io.ReadAll(resp.Body) - _ = resp.Body.Close() - - if resp.StatusCode != http.StatusOK { - t.Fatalf("status = %d, want %d", resp.StatusCode, http.StatusOK) - } - if string(body) != "" { - t.Fatalf("body = %q, want %q", body, "") - } - - wantFallbackURL := pluginPortalUpstream + tt.markerPath - if fetcher.fetchedURL != wantFallbackURL { - t.Fatalf("fallback URL = %q, want %q", fetcher.fetchedURL, wantFallbackURL) - } - - fetcher.fetchCalled = false - resp, err = http.Get(srv.URL + tt.markerPath) - if err != nil { - t.Fatalf("second request failed: %v", err) - } - _ = resp.Body.Close() - - if resp.StatusCode != http.StatusOK { - t.Fatalf("second status = %d, want %d", resp.StatusCode, http.StatusOK) - } - if fetcher.fetchCalled { - t.Fatal("expected plugin marker POM to be served from cache on second request") - } - }) - } -} - -func TestMavenHandler_GradlePluginMarkerMetadataFallback(t *testing.T) { - paths := map[string]string{ - "/com/diffplug/spotless/com.diffplug.spotless.gradle.plugin/8.4.0/com.diffplug.spotless.gradle.plugin-8.4.0.pom.sha1": "sha1", - "/com/diffplug/spotless/com.diffplug.spotless.gradle.plugin/8.4.0/com.diffplug.spotless.gradle.plugin-8.4.0.pom.sha256": "sha256", - "/com/diffplug/spotless/com.diffplug.spotless.gradle.plugin/8.4.0/com.diffplug.spotless.gradle.plugin-8.4.0.pom.md5": "md5", - "/com/diffplug/spotless/com.diffplug.spotless.gradle.plugin/maven-metadata.xml": "", - } - - primaryHits := map[string]int{} - pluginHits := map[string]int{} - - primary := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - primaryHits[r.URL.Path]++ - if _, ok := paths[r.URL.Path]; ok { - http.NotFound(w, r) - return - } - t.Fatalf("unexpected path to primary upstream: %s", r.URL.Path) - })) - defer primary.Close() - - pluginPortal := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - pluginHits[r.URL.Path]++ - body, ok := paths[r.URL.Path] - if !ok { - http.NotFound(w, r) - return - } - _, _ = io.WriteString(w, body) - })) - defer pluginPortal.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = primary.Client() - - h := NewMavenHandler(proxy, "http://localhost", primary.URL, pluginPortal.URL) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - for reqPath, wantBody := range paths { - resp, err := http.Get(srv.URL + reqPath) - if err != nil { - t.Fatalf("GET %s failed: %v", reqPath, err) - } - body, _ := io.ReadAll(resp.Body) - _ = resp.Body.Close() - - if resp.StatusCode != http.StatusOK { - t.Fatalf("GET %s: status = %d, want %d", reqPath, resp.StatusCode, http.StatusOK) - } - if string(body) != wantBody { - t.Fatalf("GET %s: body = %q, want %q", reqPath, body, wantBody) - } - - if primaryHits[reqPath] == 0 { - t.Fatalf("GET %s did not hit primary upstream", reqPath) - } - if pluginHits[reqPath] == 0 { - t.Fatalf("GET %s did not hit plugin portal fallback", reqPath) - } - } -} - -func TestMavenHandler_GradlePluginImplementationMetadataFallback(t *testing.T) { - paths := map[string]string{ - "/com/diffplug/spotless/spotless-plugin-gradle/8.4.0/spotless-plugin-gradle-8.4.0.jar.sha1": "impl-sha1", - "/com/diffplug/spotless/spotless-plugin-gradle/8.4.0/spotless-plugin-gradle-8.4.0.jar.sha256": "impl-sha256", - } - - primaryHits := map[string]int{} - pluginHits := map[string]int{} - - primary := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - primaryHits[r.URL.Path]++ - if _, ok := paths[r.URL.Path]; ok { - http.NotFound(w, r) - return - } - t.Fatalf("unexpected path to primary upstream: %s", r.URL.Path) - })) - defer primary.Close() - - pluginPortal := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - pluginHits[r.URL.Path]++ - body, ok := paths[r.URL.Path] - if !ok { - http.NotFound(w, r) - return - } - _, _ = io.WriteString(w, body) - })) - defer pluginPortal.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = primary.Client() - - h := NewMavenHandler(proxy, "http://localhost", primary.URL, pluginPortal.URL) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - for reqPath, wantBody := range paths { - resp, err := http.Get(srv.URL + reqPath) - if err != nil { - t.Fatalf("GET %s failed: %v", reqPath, err) - } - body, _ := io.ReadAll(resp.Body) - _ = resp.Body.Close() - - if resp.StatusCode != http.StatusOK { - t.Fatalf("GET %s: status = %d, want %d", reqPath, resp.StatusCode, http.StatusOK) - } - if string(body) != wantBody { - t.Fatalf("GET %s: body = %q, want %q", reqPath, body, wantBody) - } - - if primaryHits[reqPath] == 0 { - t.Fatalf("GET %s did not hit primary upstream", reqPath) - } - if pluginHits[reqPath] == 0 { - t.Fatalf("GET %s did not hit plugin portal fallback", reqPath) - } - } -} - -func TestMavenHandler_GradlePluginImplementation_FallbackToPluginPortal(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - - primaryUpstream := "https://repo1.maven.org/maven2" - pluginPortalUpstream := "https://plugins.gradle.org/m2" - implPath := "/com/diffplug/spotless/spotless-plugin-gradle/8.4.0/spotless-plugin-gradle-8.4.0.jar" - primaryURL := primaryUpstream + implPath - pluginPortalURL := pluginPortalUpstream + implPath - - fetcher.fetchErrByURL = map[string]error{ - primaryURL: ErrUpstreamNotFound, - } - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("plugin impl jar")), - ContentType: "application/java-archive", - } - - h := NewMavenHandler(proxy, "http://localhost", primaryUpstream, pluginPortalUpstream) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + implPath) - if err != nil { - t.Fatalf("request failed: %v", err) - } - body, _ := io.ReadAll(resp.Body) - _ = resp.Body.Close() - - if resp.StatusCode != http.StatusOK { - t.Fatalf("status = %d, want %d", resp.StatusCode, http.StatusOK) - } - if string(body) != "plugin impl jar" { - t.Fatalf("body = %q, want %q", body, "plugin impl jar") - } - - if fetcher.fetchedURL != pluginPortalURL { - t.Fatalf("implementation artifact should fallback to plugin portal; fetched URL = %q, want %q", fetcher.fetchedURL, pluginPortalURL) - } -} - -func TestMavenHandler_GradlePluginImplementation_NotFoundInBothUpstreams(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - - primaryUpstream := "https://repo1.maven.org/maven2" - pluginPortalUpstream := "https://plugins.gradle.org/m2" - implPath := "/com/diffplug/spotless/spotless-plugin-gradle/8.4.0/spotless-plugin-gradle-8.4.0.jar" - primaryURL := primaryUpstream + implPath - pluginPortalURL := pluginPortalUpstream + implPath - - fetcher.fetchErrByURL = map[string]error{ - primaryURL: ErrUpstreamNotFound, - pluginPortalURL: ErrUpstreamNotFound, - } - - h := NewMavenHandler(proxy, "http://localhost", primaryUpstream, pluginPortalUpstream) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + implPath) - if err != nil { - t.Fatalf("request failed: %v", err) - } - _ = resp.Body.Close() - - if resp.StatusCode != http.StatusNotFound { - t.Fatalf("status = %d, want %d", resp.StatusCode, http.StatusNotFound) - } - - if fetcher.fetchedURL != pluginPortalURL { - t.Fatalf("expected fallback attempt to plugin portal; fetched URL = %q, want %q", fetcher.fetchedURL, pluginPortalURL) - } -} - func TestNuGetHandler_DownloadCacheMiss(t *testing.T) { proxy, _, _, fetcher := setupTestProxy(t) fetcher.artifact = &fetch.Artifact{ @@ -1213,7 +897,7 @@ func TestDebianHandler_DownloadCacheMiss(t *testing.T) { ContentType: "application/vnd.debian.binary-package", } - h := NewDebianHandler(proxy, "http://localhost", "") + h := NewDebianHandler(proxy, "http://localhost") srv := httptest.NewServer(h.Routes()) defer srv.Close() diff --git a/internal/handler/filename_download.go b/internal/handler/filename_download.go deleted file mode 100644 index e3c1162..0000000 --- a/internal/handler/filename_download.go +++ /dev/null @@ -1,43 +0,0 @@ -package handler - -import ( - "net/http" - "strings" -) - -type filenameDownload struct { - ecosystem string - upstreamURL string - suffix string - parseErr string - fetchErr string - parse func(string) (name, version string) -} - -func (p *Proxy) handleFilenameDownload(w http.ResponseWriter, r *http.Request, d filenameDownload) { - filename := r.PathValue("filename") - if filename == "" || !strings.HasSuffix(filename, d.suffix) { - http.Error(w, "invalid filename", http.StatusBadRequest) - return - } - - name, version := d.parse(filename) - if name == "" || version == "" { - http.Error(w, d.parseErr, http.StatusBadRequest) - return - } - - p.Logger.Info(d.ecosystem+" download request", - "name", name, "version", version, "filename", filename) - - downloadURL := d.upstreamURL + r.URL.Path - result, err := p.GetOrFetchArtifactFromURL( - r.Context(), d.ecosystem, name, version, filename, downloadURL, - ) - if err != nil { - p.serveArtifactError(w, err, d.fetchErr) - return - } - - ServeArtifact(w, result) -} diff --git a/internal/handler/gem.go b/internal/handler/gem.go index 8fc5039..bdb4bb9 100644 --- a/internal/handler/gem.go +++ b/internal/handler/gem.go @@ -8,6 +8,8 @@ import ( "net/http" "strings" "time" + + "github.com/git-pkgs/purl" ) const ( @@ -30,13 +32,6 @@ func NewGemHandler(proxy *Proxy, proxyURL string) *GemHandler { } } -// NewGemHandlerWithUpstream creates a RubyGems handler with a custom upstream. -func NewGemHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *GemHandler { - h := NewGemHandler(proxy, proxyURL) - h.upstreamURL = configuredUpstreamURL(upstreamURL, gemUpstream) - return h -} - // Routes returns the HTTP handler for RubyGems requests. func (h *GemHandler) Routes() http.Handler { mux := http.NewServeMux() @@ -65,14 +60,30 @@ func (h *GemHandler) Routes() http.Handler { // handleDownload serves a gem file, fetching and caching from upstream if needed. func (h *GemHandler) handleDownload(w http.ResponseWriter, r *http.Request) { - h.proxy.handleFilenameDownload(w, r, filenameDownload{ - ecosystem: "gem", - upstreamURL: h.upstreamURL, - suffix: ".gem", - parseErr: "could not parse gem filename", - fetchErr: "failed to fetch gem", - parse: h.parseGemFilename, - }) + filename := r.PathValue("filename") + if filename == "" || !strings.HasSuffix(filename, ".gem") { + http.Error(w, "invalid filename", http.StatusBadRequest) + return + } + + // Extract name and version from filename (e.g., "rails-7.1.0.gem") + name, version := h.parseGemFilename(filename) + if name == "" || version == "" { + http.Error(w, "could not parse gem filename", http.StatusBadRequest) + return + } + + h.proxy.Logger.Info("gem download request", + "name", name, "version", version, "filename", filename) + + result, err := h.proxy.GetOrFetchArtifact(r.Context(), "gem", name, version, filename) + if err != nil { + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch gem", http.StatusBadGateway) + return + } + + ServeArtifact(w, result) } // parseGemFilename extracts name and version from a gem filename. @@ -171,7 +182,7 @@ func (h *GemHandler) fetchCompactIndex(r *http.Request, name string) (*http.Resp if err != nil { return nil, err } - for _, hdr := range []string{"Accept", headerAcceptEncoding, "If-None-Match", "If-Modified-Since"} { + for _, hdr := range []string{"Accept", "Accept-Encoding", "If-None-Match", "If-Modified-Since"} { if v := r.Header.Get(hdr); v != "" { req.Header.Set(hdr, v) } @@ -182,7 +193,7 @@ func (h *GemHandler) fetchCompactIndex(r *http.Request, name string) (*http.Resp // writeFilteredIndex writes the compact index response with cooldown-filtered versions removed. func (h *GemHandler) writeFilteredIndex(w http.ResponseWriter, resp *http.Response, name string, filtered map[string]bool) { for k, vv := range resp.Header { - if strings.EqualFold(k, headerContentLength) { + if strings.EqualFold(k, "Content-Length") { continue // length will change after filtering } for _, v := range vv { @@ -255,7 +266,7 @@ func (h *GemHandler) fetchFilteredVersions(r *http.Request, name string) (map[st return nil, err } - packagePURL := canonicalPackagePURL("gem", name) + packagePURL := purl.MakePURLString("gem", name, "") filtered := make(map[string]bool) for _, v := range versions { @@ -300,7 +311,7 @@ func (h *GemHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) { } // Copy relevant headers - for _, h := range []string{"Accept", headerAcceptEncoding, "If-None-Match", "If-Modified-Since"} { + for _, h := range []string{"Accept", "Accept-Encoding", "If-None-Match", "If-Modified-Since"} { if v := r.Header.Get(h); v != "" { req.Header.Set(h, v) } diff --git a/internal/handler/gem_test.go b/internal/handler/gem_test.go index 7d90946..6dce324 100644 --- a/internal/handler/gem_test.go +++ b/internal/handler/gem_test.go @@ -10,7 +10,7 @@ import ( "testing" "time" - "github.com/git-pkgs/cooldown" + "github.com/git-pkgs/proxy/internal/cooldown" ) func TestGemParseFilename(t *testing.T) { diff --git a/internal/handler/generic.go b/internal/handler/generic.go deleted file mode 100644 index 31f5dc3..0000000 --- a/internal/handler/generic.go +++ /dev/null @@ -1,160 +0,0 @@ -package handler - -import ( - "crypto/sha256" - "encoding/hex" - "net/http" - "regexp" - "strings" -) - -const ( - genericEcosystem = "generic" - // genericAcceptAny is always sent for metadata so every client shares the - // same cached representation, regardless of its Accept header. - genericAcceptAny = "*/*" - // githubReleaseAssetMatchCount is the full match plus owner, repository, - // tag and asset filename. - githubReleaseAssetMatchCount = 5 -) - -// githubReleaseAssetPattern matches the path of a GitHub release asset -// download, {owner}/{repo}/releases/download/{tag}/{asset}. A tag pins the -// asset to one release, so these downloads are cached in the artifact cache -// and served without revalidation once fetched. -var githubReleaseAssetPattern = regexp.MustCompile(`^([^/]+)/([^/]+)/releases/download/([^/]+)/([^/]+)$`) - -// GenericHandler proxies plain HTTP downloads from configured upstream base -// URLs. Each configured upstream is mounted at /generic/{name}/ and the -// remaining request path (and query string) is appended to the upstream URL. -// -// Only configured upstreams are reachable, so the proxy is not an open HTTP -// proxy. The handler is the caching layer behind tools that download from -// fixed URL shapes, such as mise's aqua backend fetching GitHub release -// assets, and is pointed at by URL-rewriting settings on the client. -// -// Release-asset paths ({owner}/{repo}/releases/download/{tag}/{asset}) are -// version-pinned and cached in the shared artifact cache, so they keep being -// served when the upstream is unreachable. Every other path is served through -// the metadata cache: fresh within the metadata TTL, revalidated with the -// upstream's validators after that, and served stale when the upstream fails -// or refuses the request. That covers API responses such as -// api.github.com/repos/{owner}/{repo}/releases/tags/{tag}. -type GenericHandler struct { - proxy *Proxy - repositories map[string]string -} - -// NewGenericHandler creates a generic HTTP download proxy handler. -func NewGenericHandler(proxy *Proxy, repositories map[string]string) *GenericHandler { - h := &GenericHandler{ - proxy: proxy, - repositories: make(map[string]string, len(repositories)), - } - for name, upstreamURL := range repositories { - h.repositories[name] = strings.TrimSuffix(upstreamURL, "/") - } - return h -} - -// Routes returns the HTTP handler for generic download requests. -// Mount this at /generic on your router. -func (h *GenericHandler) Routes() http.Handler { - return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.Method != http.MethodGet && r.Method != http.MethodHead { - http.Error(w, "method not allowed", http.StatusMethodNotAllowed) - return - } - - path := strings.TrimPrefix(r.URL.Path, "/") - - if containsPathTraversal(path) { - http.Error(w, "invalid path", http.StatusBadRequest) - return - } - - repository, rest, ok := strings.Cut(path, "/") - upstreamURL, found := h.repositories[repository] - if !ok || rest == "" || !found { - http.NotFound(w, r) - return - } - - if asset, ok := parseGitHubReleaseAsset(rest); ok { - h.handleReleaseAsset(w, r, repository, upstreamURL, rest, asset) - return - } - - h.handleMetadata(w, r, repository, upstreamURL, rest) - }) -} - -// githubReleaseAsset is the identity of a version-pinned release download. -type githubReleaseAsset struct { - owner string - repo string - tag string - filename string -} - -// parseGitHubReleaseAsset extracts the release identity from a path shaped -// like {owner}/{repo}/releases/download/{tag}/{asset}. -func parseGitHubReleaseAsset(path string) (githubReleaseAsset, bool) { - matches := githubReleaseAssetPattern.FindStringSubmatch(path) - if len(matches) != githubReleaseAssetMatchCount { - return githubReleaseAsset{}, false - } - return githubReleaseAsset{ - owner: matches[1], - repo: matches[2], - tag: matches[3], - filename: matches[4], - }, true -} - -// handleReleaseAsset fetches and caches a version-pinned release asset in the -// artifact cache. The configured upstream name is part of the cache identity -// so two upstreams serving the same path never share bytes. -func (h *GenericHandler) handleReleaseAsset(w http.ResponseWriter, r *http.Request, repository, upstreamURL, path string, asset githubReleaseAsset) { - name := asset.owner + "/" + asset.repo - downloadURL := upstreamURL + "/" + path - cacheFilename := repository + "/" + asset.filename - - h.proxy.Logger.Info("generic release asset download", - "repository", repository, "name", name, "version", asset.tag, "filename", asset.filename) - - result, err := h.proxy.GetOrFetchArtifactFromURL( - r.Context(), genericEcosystem, name, asset.tag, cacheFilename, downloadURL) - if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch release asset") - return - } - - if result.Artifact.MediaType == "" { - result.Artifact.MediaType = "application/octet-stream" - } - serveArtifact(w, r.Method, result) -} - -// handleMetadata serves any other path through the metadata cache. The query -// string is forwarded and is part of the cache identity. A fixed Accept header -// keeps all clients on one cached representation. -func (h *GenericHandler) handleMetadata(w http.ResponseWriter, r *http.Request, repository, upstreamURL, path string) { - target := upstreamURL + "/" + path - if r.URL.RawQuery != "" { - target += "?" + r.URL.RawQuery - } - - h.proxy.ProxyCached(w, r, target, genericEcosystem, - h.metadataCacheKey(repository, upstreamURL, path, r.URL.RawQuery), genericAcceptAny) -} - -// metadataCacheKey derives the metadata cache key from the upstream name, its -// URL, the request path and query. Hashing the identity keeps distinct -// upstreams from sharing entries and drops cached entries when an upstream is -// repointed, mirroring APKHandler.metadataCacheKey. -func (h *GenericHandler) metadataCacheKey(repository, upstreamURL, path, query string) string { - identity := repository + "\x00" + upstreamURL + "\x00" + path + "\x00" + query - digest := sha256.Sum256([]byte(identity)) - return hex.EncodeToString(digest[:]) -} diff --git a/internal/handler/generic_test.go b/internal/handler/generic_test.go deleted file mode 100644 index 7d47cb9..0000000 --- a/internal/handler/generic_test.go +++ /dev/null @@ -1,311 +0,0 @@ -package handler - -import ( - "net/http" - "net/http/httptest" - "strings" - "sync/atomic" - "testing" - "time" - - upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient" - "github.com/git-pkgs/registries/fetch" -) - -const testReleaseAssetPath = "/jqlang/jq/releases/download/jq-1.7.1/jq-linux-amd64" - -func TestParseGitHubReleaseAsset(t *testing.T) { - tests := []struct { - path string - want githubReleaseAsset - ok bool - }{ - { - "jqlang/jq/releases/download/jq-1.7.1/jq-linux-amd64", - githubReleaseAsset{owner: "jqlang", repo: "jq", tag: "jq-1.7.1", filename: "jq-linux-amd64"}, - true, - }, - { - "cli/cli/releases/download/v2.63.2/gh_2.63.2_linux_amd64.tar.gz", - githubReleaseAsset{owner: "cli", repo: "cli", tag: "v2.63.2", filename: "gh_2.63.2_linux_amd64.tar.gz"}, - true, - }, - // Mutable: resolves to whatever is latest today. - {"jqlang/jq/releases/latest/download/jq-linux-amd64", githubReleaseAsset{}, false}, - // API lookups and tag listings are not assets. - {"repos/jqlang/jq/releases/tags/jq-1.7.1", githubReleaseAsset{}, false}, - {"jqlang/jq/releases/tag/jq-1.7.1", githubReleaseAsset{}, false}, - // Source archives are a different shape. - {"jqlang/jq/archive/refs/tags/jq-1.7.1.tar.gz", githubReleaseAsset{}, false}, - // Extra or missing segments. - {"jqlang/jq/releases/download/jq-1.7.1", githubReleaseAsset{}, false}, - {"jqlang/jq/releases/download/jq-1.7.1/dir/asset", githubReleaseAsset{}, false}, - {"", githubReleaseAsset{}, false}, - } - - for _, tt := range tests { - got, ok := parseGitHubReleaseAsset(tt.path) - if ok != tt.ok || got != tt.want { - t.Errorf("parseGitHubReleaseAsset(%q) = (%+v, %v), want (%+v, %v)", tt.path, got, ok, tt.want, tt.ok) - } - } -} - -func TestGenericHandler_RejectsUnknownUpstreamAndBadPaths(t *testing.T) { - h := NewGenericHandler(testProxy(), map[string]string{"github": "https://github.com"}) - - tests := []struct { - name string - method string - target string - want int - }{ - {"unknown upstream", http.MethodGet, "/gitlab/owner/repo/releases/download/v1/asset", http.StatusNotFound}, - {"missing path", http.MethodGet, "/github", http.StatusNotFound}, - {"missing path with slash", http.MethodGet, "/github/", http.StatusNotFound}, - {"traversal", http.MethodGet, "/github/../etc/passwd", http.StatusBadRequest}, - {"encoded traversal", http.MethodGet, "/github/%2e%2e/etc/passwd", http.StatusBadRequest}, - {"post", http.MethodPost, "/github/owner/repo/releases/download/v1/asset", http.StatusMethodNotAllowed}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, httptest.NewRequest(tt.method, tt.target, nil)) - if w.Code != tt.want { - t.Errorf("status = %d, want %d", w.Code, tt.want) - } - }) - } -} - -func TestGenericHandler_ReleaseAssetIsCachedAndServedWhenUpstreamDown(t *testing.T) { - asset := []byte("jq binary bytes") - var available atomic.Bool - available.Store(true) - var upstreamRequests atomic.Int32 - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if !available.Load() { - http.Error(w, "unavailable", http.StatusServiceUnavailable) - return - } - if r.URL.Path != testReleaseAssetPath { - http.NotFound(w, r) - return - } - upstreamRequests.Add(1) - w.Header().Set("Content-Type", "application/octet-stream") - _, _ = w.Write(asset) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0)) - proxy.Fetcher = fetcher - t.Cleanup(func() { _ = fetcher.Close() }) - - h := NewGenericHandler(proxy, map[string]string{"github": upstream.URL}) - - w := serveGenericRequest(h, "/github"+testReleaseAssetPath) - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String()) - } - if got := w.Body.String(); got != string(asset) { - t.Errorf("body = %q, want %q", got, asset) - } - if got := upstreamRequests.Load(); got != 1 { - t.Fatalf("upstream requests = %d, want 1", got) - } - - // Second request must be served from cache, even with the upstream down. - available.Store(false) - w = serveGenericRequest(h, "/github"+testReleaseAssetPath) - if w.Code != http.StatusOK { - t.Fatalf("cached: status = %d, want 200: %s", w.Code, w.Body.String()) - } - if got := w.Body.String(); got != string(asset) { - t.Errorf("cached: body = %q, want %q", got, asset) - } - if got := upstreamRequests.Load(); got != 1 { - t.Errorf("upstream requests after cache hit = %d, want 1", got) - } - - // HEAD is answered from the same cache entry without a body. - w = httptest.NewRecorder() - h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodHead, "/github"+testReleaseAssetPath, nil)) - if w.Code != http.StatusOK { - t.Fatalf("HEAD: status = %d, want 200", w.Code) - } - if w.Body.Len() != 0 { - t.Errorf("HEAD: body length = %d, want 0", w.Body.Len()) - } -} - -func TestGenericHandler_ReleaseAssetNotFoundIsNotCached(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - http.NotFound(w, r) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0)) - proxy.Fetcher = fetcher - t.Cleanup(func() { _ = fetcher.Close() }) - - h := NewGenericHandler(proxy, map[string]string{"github": upstream.URL}) - w := serveGenericRequest(h, "/github"+testReleaseAssetPath) - if w.Code != http.StatusNotFound { - t.Fatalf("status = %d, want 404: %s", w.Code, w.Body.String()) - } -} - -func TestGenericHandler_MetadataForwardsQueryAndServesStaleOnThrottle(t *testing.T) { - const apiPath = "/repos/jqlang/jq/releases/tags/jq-1.7.1" - body := `{"tag_name":"jq-1.7.1"}` - var throttled atomic.Bool - var gotQuery string - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path != apiPath { - http.NotFound(w, r) - return - } - gotQuery = r.URL.RawQuery - if throttled.Load() { - w.Header().Set("Retry-After", "60") - http.Error(w, `{"message":"API rate limit exceeded"}`, http.StatusTooManyRequests) - return - } - w.Header().Set("Content-Type", "application/vnd.github+json") - w.Header().Set("ETag", `"v1"`) - _, _ = w.Write([]byte(body)) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.CacheMetadata = true - // A tiny TTL so the second request is past freshness and has to consult - // the upstream, and the served copy is marked stale. - proxy.MetadataTTL = time.Millisecond - - h := NewGenericHandler(proxy, map[string]string{"github-api": upstream.URL}) - - req := httptest.NewRequest(http.MethodGet, "/github-api"+apiPath+"?per_page=1", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String()) - } - if got := w.Body.String(); got != body { - t.Errorf("body = %q, want %q", got, body) - } - if gotQuery != "per_page=1" { - t.Errorf("upstream query = %q, want %q", gotQuery, "per_page=1") - } - if ct := w.Header().Get("Content-Type"); ct != "application/vnd.github+json" { - t.Errorf("Content-Type = %q, want upstream's", ct) - } - - // The upstream now throttles us: the cached body must be served stale - // rather than the 429 being passed through. - throttled.Store(true) - time.Sleep(5 * time.Millisecond) - w = httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - if w.Code != http.StatusOK { - t.Fatalf("throttled: status = %d, want 200 stale: %s", w.Code, w.Body.String()) - } - if got := w.Body.String(); got != body { - t.Errorf("throttled: body = %q, want cached %q", got, body) - } - if warning := w.Header().Get("Warning"); !strings.Contains(warning, "110") { - t.Errorf("throttled: Warning = %q, want a 110 stale warning", warning) - } -} - -func TestGenericHandler_DistinctUpstreamsDoNotShareCache(t *testing.T) { - first := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - _, _ = w.Write([]byte("from first")) - })) - defer first.Close() - second := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - _, _ = w.Write([]byte("from second")) - })) - defer second.Close() - - proxy, _, _, _ := setupTestProxy(t) - fetcher := fetch.NewFetcher(fetch.WithHTTPClient(first.Client()), fetch.WithMaxRetries(0)) - proxy.Fetcher = fetcher - t.Cleanup(func() { _ = fetcher.Close() }) - - h := NewGenericHandler(proxy, map[string]string{"one": first.URL, "two": second.URL}) - - w := serveGenericRequest(h, "/one"+testReleaseAssetPath) - if got := w.Body.String(); got != "from first" { - t.Fatalf("one: body = %q, want %q", got, "from first") - } - w = serveGenericRequest(h, "/two"+testReleaseAssetPath) - if got := w.Body.String(); got != "from second" { - t.Fatalf("two: body = %q, want %q (must not reuse the first upstream's cache entry)", got, "from second") - } -} - -func TestGenericHandler_UpstreamAuthIsScopedToTheConfiguredHost(t *testing.T) { - asset := []byte("private asset") - var storageAuth atomic.Value - storageAuth.Store("unset") - - // The object store the release host redirects to must never see the - // token configured for the release host. - objectStore := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - storageAuth.Store(r.Header.Get("Authorization")) - _, _ = w.Write(asset) - })) - defer objectStore.Close() - - var releaseAuth string - releaseHost := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - releaseAuth = r.Header.Get("Authorization") - if releaseAuth != "Bearer github-token" { - http.Error(w, "unauthorized", http.StatusUnauthorized) - return - } - http.Redirect(w, r, objectStore.URL+"/signed"+r.URL.Path, http.StatusFound) - })) - defer releaseHost.Close() - - proxy, _, _, _ := setupTestProxy(t) - authClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport, - upstreamhttp.AuthFunc(func(url string) (string, string) { - if strings.HasPrefix(url, releaseHost.URL) { - return "Authorization", "Bearer github-token" - } - return "", "" - }))} - fetcher := fetch.NewFetcher(fetch.WithHTTPClient(authClient), fetch.WithMaxRetries(0)) - proxy.Fetcher = fetcher - t.Cleanup(func() { _ = fetcher.Close() }) - - h := NewGenericHandler(proxy, map[string]string{"github": releaseHost.URL}) - w := serveGenericRequest(h, "/github"+testReleaseAssetPath) - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String()) - } - if got := w.Body.String(); got != string(asset) { - t.Errorf("body = %q, want %q", got, asset) - } - if releaseAuth != "Bearer github-token" { - t.Errorf("release host Authorization = %q, want the configured token", releaseAuth) - } - if got := storageAuth.Load(); got != "" { - t.Errorf("object store Authorization = %q, want none after the cross-host redirect", got) - } -} - -func serveGenericRequest(h *GenericHandler, target string) *httptest.ResponseRecorder { - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, target, nil)) - return w -} diff --git a/internal/handler/go.go b/internal/handler/go.go index b562aca..955a89c 100644 --- a/internal/handler/go.go +++ b/internal/handler/go.go @@ -1,12 +1,9 @@ package handler import ( - "errors" "fmt" "net/http" "strings" - - "github.com/git-pkgs/registries/fetch" ) const ( @@ -30,13 +27,6 @@ func NewGoHandler(proxy *Proxy, proxyURL string) *GoHandler { } } -// NewGoHandlerWithUpstream creates a Go module handler with a custom upstream. -func NewGoHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *GoHandler { - h := NewGoHandler(proxy, proxyURL) - h.upstreamURL = configuredUpstreamURL(upstreamURL, goUpstream) - return h -} - // Routes returns the HTTP handler for Go proxy requests. func (h *GoHandler) Routes() http.Handler { // Go module paths can contain slashes, so just use the handler directly @@ -108,19 +98,8 @@ func (h *GoHandler) handleDownload(w http.ResponseWriter, r *http.Request, modul h.proxy.Logger.Info("go module download request", "module", decodedModule, "version", version) - downloadURL := h.upstreamURL + r.URL.Path - result, err := h.proxy.GetOrFetchArtifactFromURL( - r.Context(), "golang", decodedModule, version, filename, downloadURL, - ) + result, err := h.proxy.GetOrFetchArtifact(r.Context(), "golang", decodedModule, version, filename) if err != nil { - if errors.Is(err, fetch.ErrNotFound) { - http.Error(w, "not found", http.StatusNotFound) - return - } - if errors.Is(err, ErrArtifactBlocked) { - http.Error(w, err.Error(), http.StatusForbidden) - return - } h.proxy.Logger.Error("failed to get artifact", "error", err) http.Error(w, "failed to fetch module", http.StatusBadGateway) return diff --git a/internal/handler/go_test.go b/internal/handler/go_test.go index ae998c9..da4ea63 100644 --- a/internal/handler/go_test.go +++ b/internal/handler/go_test.go @@ -1,49 +1,9 @@ package handler import ( - "errors" - "net/http" - "net/http/httptest" "testing" - - "github.com/git-pkgs/registries/fetch" ) -func TestGoModuleDownloadUpstreamErrors(t *testing.T) { - tests := []struct { - name string - fetchErr error - wantStatus int - }{ - { - name: "module not found", - fetchErr: fetch.ErrNotFound, - wantStatus: http.StatusNotFound, - }, - { - name: "upstream failure", - fetchErr: errors.New("connection refused"), - wantStatus: http.StatusBadGateway, - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - fetcher.fetchErr = tt.fetchErr - handler := NewGoHandler(proxy, "http://localhost:8080") - - req := httptest.NewRequest(http.MethodGet, "/example.com/mod/@v/v1.0.0.zip", nil) - resp := httptest.NewRecorder() - handler.Routes().ServeHTTP(resp, req) - - if resp.Code != tt.wantStatus { - t.Fatalf("status = %d, want %d", resp.Code, tt.wantStatus) - } - }) - } -} - func TestDecodeGoModule(t *testing.T) { tests := []struct { encoded string diff --git a/internal/handler/gradle.go b/internal/handler/gradle.go deleted file mode 100644 index 9c74a6a..0000000 --- a/internal/handler/gradle.go +++ /dev/null @@ -1,178 +0,0 @@ -package handler - -import ( - "errors" - "io" - "net/http" - "regexp" - "strconv" - "strings" - "time" - - "github.com/git-pkgs/proxy/internal/metrics" - "github.com/git-pkgs/proxy/internal/storage" -) - -const ( - gradleBuildCacheContentType = "application/vnd.gradle.build-cache-artifact.v2" - gradleBuildCacheStorageRoot = "_gradle/http-build-cache" - defaultGradleMaxUploadSize = 100 << 20 -) - -var gradleBuildCacheKeyPattern = regexp.MustCompile(`^[A-Za-z0-9][A-Za-z0-9._-]*$`) - -// GradleBuildCacheHandler handles Gradle HttpBuildCache GET/HEAD/PUT requests. -// -// This handler accepts /{key} when mounted under a base URL. -type GradleBuildCacheHandler struct { - proxy *Proxy -} - -// NewGradleBuildCacheHandler creates a Gradle HttpBuildCache handler. -func NewGradleBuildCacheHandler(proxy *Proxy) *GradleBuildCacheHandler { - return &GradleBuildCacheHandler{proxy: proxy} -} - -// Routes returns the HTTP handler for Gradle HttpBuildCache requests. -func (h *GradleBuildCacheHandler) Routes() http.Handler { - return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.Method { - case http.MethodGet, http.MethodHead, http.MethodPut: - default: - http.Error(w, "method not allowed", http.StatusMethodNotAllowed) - return - } - - key, statusCode := h.parseCacheKey(r.URL.Path) - if statusCode != http.StatusOK { - if statusCode == http.StatusNotFound { - http.NotFound(w, r) - return - } - http.Error(w, "invalid cache key", statusCode) - return - } - - if r.Method == http.MethodPut { - if h.proxy.GradleReadOnly { - http.Error(w, "gradle build cache is read-only", http.StatusMethodNotAllowed) - return - } - h.handlePut(w, r, key) - return - } - - h.handleGetOrHead(w, r, key) - }) -} - -func (h *GradleBuildCacheHandler) parseCacheKey(urlPath string) (string, int) { - keyPath := strings.TrimPrefix(urlPath, "/") - if keyPath == "" { - return "", http.StatusNotFound - } - - if containsPathTraversal(keyPath) { - return "", http.StatusBadRequest - } - - if strings.Contains(keyPath, "/") { - return "", http.StatusNotFound - } - - if !gradleBuildCacheKeyPattern.MatchString(keyPath) { - return "", http.StatusBadRequest - } - - return keyPath, http.StatusOK -} - -func (h *GradleBuildCacheHandler) cacheStoragePath(key string) string { - return gradleBuildCacheStorageRoot + "/" + key -} - -func (h *GradleBuildCacheHandler) handleGetOrHead(w http.ResponseWriter, r *http.Request, key string) { - storagePath := h.cacheStoragePath(key) - w.Header().Set(headerContentType, gradleBuildCacheContentType) - - if r.Method == http.MethodHead { - existsStart := time.Now() - exists, err := h.proxy.Storage.Exists(r.Context(), storagePath) - metrics.RecordStorageOperation("read", time.Since(existsStart)) - if err != nil { - metrics.RecordStorageError("read") - h.proxy.Logger.Error("failed to check gradle build cache entry", "key", key, "error", err) - http.Error(w, "failed to read cache entry", http.StatusInternalServerError) - return - } - if !exists { - metrics.RecordCacheMiss("gradle") - http.NotFound(w, r) - return - } - metrics.RecordCacheHit("gradle") - - sizeStart := time.Now() - size, err := h.proxy.Storage.Size(r.Context(), storagePath) - metrics.RecordStorageOperation("read", time.Since(sizeStart)) - if err != nil { - metrics.RecordStorageError("read") - } else if size >= 0 { - w.Header().Set(headerContentLength, strconv.FormatInt(size, 10)) - } - - w.WriteHeader(http.StatusOK) - return - } - - readStart := time.Now() - reader, err := h.proxy.Storage.Open(r.Context(), storagePath) - metrics.RecordStorageOperation("read", time.Since(readStart)) - if err != nil { - if errors.Is(err, storage.ErrNotFound) { - metrics.RecordCacheMiss("gradle") - http.NotFound(w, r) - return - } - metrics.RecordStorageError("read") - h.proxy.Logger.Error("failed to open gradle build cache entry", "key", key, "error", err) - http.Error(w, "failed to read cache entry", http.StatusInternalServerError) - return - } - defer func() { _ = reader.Close() }() - metrics.RecordCacheHit("gradle") - - w.WriteHeader(http.StatusOK) - _, _ = io.Copy(w, reader) -} - -func (h *GradleBuildCacheHandler) handlePut(w http.ResponseWriter, r *http.Request, key string) { - storagePath := h.cacheStoragePath(key) - maxUploadSize := h.proxy.GradleMaxUploadSize - if maxUploadSize <= 0 { - maxUploadSize = defaultGradleMaxUploadSize - } - - r.Body = http.MaxBytesReader(w, r.Body, maxUploadSize) - - storeStart := time.Now() - _, hash, err := h.proxy.Storage.Store(r.Context(), storagePath, r.Body) - metrics.RecordStorageOperation("write", time.Since(storeStart)) - if err != nil { - var maxBytesErr *http.MaxBytesError - if errors.As(err, &maxBytesErr) { - http.Error(w, "cache entry too large", http.StatusRequestEntityTooLarge) - return - } - - metrics.RecordStorageError("write") - h.proxy.Logger.Error("failed to store gradle build cache entry", "key", key, "error", err) - http.Error(w, "failed to write cache entry", http.StatusInternalServerError) - return - } - - w.Header().Set(headerContentLength, "0") - w.Header().Set(headerETag, `"`+hash+`"`) - - w.WriteHeader(http.StatusCreated) -} diff --git a/internal/handler/gradle_test.go b/internal/handler/gradle_test.go deleted file mode 100644 index a05d07e..0000000 --- a/internal/handler/gradle_test.go +++ /dev/null @@ -1,285 +0,0 @@ -package handler - -import ( - "io" - "net/http" - "net/http/httptest" - "strings" - "testing" - - "github.com/git-pkgs/proxy/internal/metrics" - "github.com/prometheus/client_golang/prometheus/testutil" -) - -func TestGradleBuildCacheHandler_PutGetHead(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - h := NewGradleBuildCacheHandler(proxy) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - key := "a1b2c3d4e5f6" - payload := "cache entry content" - - putReq, err := http.NewRequest(http.MethodPut, srv.URL+"/"+key, strings.NewReader(payload)) - if err != nil { - t.Fatalf("failed to create PUT request: %v", err) - } - putResp, err := http.DefaultClient.Do(putReq) - if err != nil { - t.Fatalf("PUT request failed: %v", err) - } - _ = putResp.Body.Close() - - if putResp.StatusCode != http.StatusCreated { - t.Fatalf("PUT status = %d, want %d", putResp.StatusCode, http.StatusCreated) - } - - getResp, err := http.Get(srv.URL + "/" + key) - if err != nil { - t.Fatalf("GET request failed: %v", err) - } - defer func() { _ = getResp.Body.Close() }() - - if getResp.StatusCode != http.StatusOK { - t.Fatalf("GET status = %d, want %d", getResp.StatusCode, http.StatusOK) - } - if getResp.Header.Get("Content-Type") != gradleBuildCacheContentType { - t.Fatalf("GET Content-Type = %q, want %q", getResp.Header.Get("Content-Type"), gradleBuildCacheContentType) - } - - body, _ := io.ReadAll(getResp.Body) - if string(body) != payload { - t.Fatalf("GET body = %q, want %q", body, payload) - } - - headReq, err := http.NewRequest(http.MethodHead, srv.URL+"/"+key, nil) - if err != nil { - t.Fatalf("failed to create HEAD request: %v", err) - } - headResp, err := http.DefaultClient.Do(headReq) - if err != nil { - t.Fatalf("HEAD request failed: %v", err) - } - defer func() { _ = headResp.Body.Close() }() - - if headResp.StatusCode != http.StatusOK { - t.Fatalf("HEAD status = %d, want %d", headResp.StatusCode, http.StatusOK) - } - body, _ = io.ReadAll(headResp.Body) - if len(body) != 0 { - t.Fatalf("HEAD body length = %d, want 0", len(body)) - } -} - -func TestGradleBuildCacheHandler_RootKeyPath(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - h := NewGradleBuildCacheHandler(proxy) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - key := "rootpathkey" - putReq, err := http.NewRequest(http.MethodPut, srv.URL+"/"+key, strings.NewReader("root")) - if err != nil { - t.Fatalf("failed to create PUT request: %v", err) - } - putResp, err := http.DefaultClient.Do(putReq) - if err != nil { - t.Fatalf("PUT request failed: %v", err) - } - _ = putResp.Body.Close() - - if putResp.StatusCode != http.StatusCreated { - t.Fatalf("PUT status = %d, want %d", putResp.StatusCode, http.StatusCreated) - } - - getResp, err := http.Get(srv.URL + "/" + key) - if err != nil { - t.Fatalf("GET request failed: %v", err) - } - defer func() { _ = getResp.Body.Close() }() - - if getResp.StatusCode != http.StatusOK { - t.Fatalf("GET status = %d, want %d", getResp.StatusCode, http.StatusOK) - } -} - -func TestGradleBuildCacheHandler_GetMiss(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - h := NewGradleBuildCacheHandler(proxy) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + "/missing-key") - if err != nil { - t.Fatalf("GET request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusNotFound { - t.Fatalf("status = %d, want %d", resp.StatusCode, http.StatusNotFound) - } -} - -func TestGradleBuildCacheHandler_MethodNotAllowed(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - h := NewGradleBuildCacheHandler(proxy) - - req := httptest.NewRequest(http.MethodPost, "/key", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusMethodNotAllowed { - t.Fatalf("status = %d, want %d", w.Code, http.StatusMethodNotAllowed) - } -} - -func TestGradleBuildCacheHandler_PathTraversalRejected(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - h := NewGradleBuildCacheHandler(proxy) - - req := httptest.NewRequest(http.MethodGet, "/../secret", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusBadRequest { - t.Fatalf("status = %d, want %d", w.Code, http.StatusBadRequest) - } -} - -func TestGradleBuildCacheHandler_CachePrefixRejected(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - h := NewGradleBuildCacheHandler(proxy) - - req := httptest.NewRequest(http.MethodGet, "/cache/key", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusNotFound { - t.Fatalf("status = %d, want %d", w.Code, http.StatusNotFound) - } -} - -func TestGradleBuildCacheHandler_PutOverwriteReturnsCreated(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - h := NewGradleBuildCacheHandler(proxy) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - key := "overwrite-key" - - for i, payload := range []string{"first", "second"} { - req, err := http.NewRequest(http.MethodPut, srv.URL+"/"+key, strings.NewReader(payload)) - if err != nil { - t.Fatalf("failed to create PUT request: %v", err) - } - resp, err := http.DefaultClient.Do(req) - if err != nil { - t.Fatalf("PUT request failed: %v", err) - } - _ = resp.Body.Close() - - want := http.StatusCreated - if resp.StatusCode != want { - t.Fatalf("PUT #%d status = %d, want %d", i+1, resp.StatusCode, want) - } - } -} - -func TestGradleBuildCacheHandler_PutReadOnly(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - proxy.GradleReadOnly = true - - h := NewGradleBuildCacheHandler(proxy) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - req, err := http.NewRequest(http.MethodPut, srv.URL+"/readonly-key", strings.NewReader("payload")) - if err != nil { - t.Fatalf("failed to create PUT request: %v", err) - } - resp, err := http.DefaultClient.Do(req) - if err != nil { - t.Fatalf("PUT request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusMethodNotAllowed { - t.Fatalf("PUT status = %d, want %d", resp.StatusCode, http.StatusMethodNotAllowed) - } -} - -func TestGradleBuildCacheHandler_PutTooLarge(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - proxy.GradleMaxUploadSize = 4 - - h := NewGradleBuildCacheHandler(proxy) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - req, err := http.NewRequest(http.MethodPut, srv.URL+"/oversized-key", strings.NewReader("12345")) - if err != nil { - t.Fatalf("failed to create PUT request: %v", err) - } - resp, err := http.DefaultClient.Do(req) - if err != nil { - t.Fatalf("PUT request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusRequestEntityTooLarge { - t.Fatalf("PUT status = %d, want %d", resp.StatusCode, http.StatusRequestEntityTooLarge) - } -} - -func TestGradleBuildCacheHandler_RecordsMetrics(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - h := NewGradleBuildCacheHandler(proxy) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - hitsBefore := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("gradle")) - missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("gradle")) - - key := "metrics-key" - putReq, err := http.NewRequest(http.MethodPut, srv.URL+"/"+key, strings.NewReader("payload")) - if err != nil { - t.Fatalf("failed to create PUT request: %v", err) - } - putResp, err := http.DefaultClient.Do(putReq) - if err != nil { - t.Fatalf("PUT request failed: %v", err) - } - _ = putResp.Body.Close() - - getResp, err := http.Get(srv.URL + "/" + key) - if err != nil { - t.Fatalf("GET request failed: %v", err) - } - _ = getResp.Body.Close() - - headReq, err := http.NewRequest(http.MethodHead, srv.URL+"/"+key, nil) - if err != nil { - t.Fatalf("failed to create HEAD request: %v", err) - } - headResp, err := http.DefaultClient.Do(headReq) - if err != nil { - t.Fatalf("HEAD request failed: %v", err) - } - _ = headResp.Body.Close() - - missResp, err := http.Get(srv.URL + "/missing-key") - if err != nil { - t.Fatalf("GET miss request failed: %v", err) - } - _ = missResp.Body.Close() - - hitsAfter := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("gradle")) - missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("gradle")) - - if diff := hitsAfter - hitsBefore; diff != 2 { - t.Fatalf("cache hits delta = %.0f, want 2", diff) - } - if diff := missesAfter - missesBefore; diff != 1 { - t.Fatalf("cache misses delta = %.0f, want 1", diff) - } -} diff --git a/internal/handler/handler.go b/internal/handler/handler.go index 137e0b1..7f28aad 100644 --- a/internal/handler/handler.go +++ b/internal/handler/handler.go @@ -10,40 +10,22 @@ import ( "io" "log/slog" "net/http" - "net/url" "strconv" "strings" - "sync" "time" - "github.com/git-pkgs/artifacts" - "github.com/git-pkgs/cooldown" + "github.com/git-pkgs/proxy/internal/cooldown" "github.com/git-pkgs/proxy/internal/database" "github.com/git-pkgs/proxy/internal/metrics" - "github.com/git-pkgs/proxy/internal/packageurl" - "github.com/git-pkgs/proxy/internal/scanner" "github.com/git-pkgs/proxy/internal/storage" "github.com/git-pkgs/purl" "github.com/git-pkgs/registries/fetch" - "github.com/opencontainers/go-digest" ) // containsPathTraversal returns true if the path contains ".." segments -// that could be used to escape the intended directory. It checks the path -// as given and after URL-decoding, and treats backslashes as separators. +// that could be used to escape the intended directory. func containsPathTraversal(path string) bool { - if hasDotDotSegment(path) { - return true - } - if decoded, err := url.PathUnescape(path); err == nil && decoded != path { - return hasDotDotSegment(decoded) - } - return false -} - -func hasDotDotSegment(path string) bool { - path = strings.ReplaceAll(path, "\\", "/") - for segment := range strings.SplitSeq(path, "/") { + for _, segment := range strings.Split(path, "/") { if segment == ".." { return true } @@ -51,97 +33,27 @@ func hasDotDotSegment(path string) bool { return false } -func configuredUpstreamURL(value, defaultValue string) string { - if value == "" { - value = defaultValue - } - return strings.TrimRight(value, "/") -} - const defaultHTTPTimeout = 30 * time.Second -const artifactCopyBufferSize = 32 << 10 - -var artifactCopyBufferPool = sync.Pool{ //nolint:gochecknoglobals // shared across artifact responses - New: func() any { - buffer := make([]byte, artifactCopyBufferSize) - return &buffer - }, -} - -// canonicalPackagePURL returns a versionless PURL in canonical form so cooldown -// lookups match keys produced by config.CooldownConfig.NormalizedPackages. -func canonicalPackagePURL(ecosystem, name string) string { - return packageurl.MakeString(ecosystem, name, "") -} - -// canonicalVersionPURL returns a versioned PURL in canonical form, matching -// the keys the artifact cache writes to the versions table. -func canonicalVersionPURL(ecosystem, name, version string) string { - return packageurl.MakeString(ecosystem, name, version) -} - -var errUnsupportedPackageIdentity = errors.New("package identity cannot be represented as a PURL") - -func packagePURLStrings(ecosystem, name, version string) (string, string, error) { - packagePURL := packageurl.MakeString(ecosystem, name, "") - versionPURL := packageurl.MakeString(ecosystem, name, version) - if packagePURL == "" || versionPURL == "" { - return "", "", fmt.Errorf("%w: %s %q", errUnsupportedPackageIdentity, ecosystem, name) - } - return packagePURL, versionPURL, nil -} - const contentTypeJSON = "application/json" -const ( - headerAcceptEncoding = "Accept-Encoding" - headerContentType = "Content-Type" - headerContentLength = "Content-Length" - headerContentEncoding = "Content-Encoding" - headerETag = "ETag" - headerLastModified = "Last-Modified" -) +// maxMetadataSize is the maximum size of upstream metadata responses (100 MB). +// Package metadata (e.g. npm with many versions) can be large, but unbounded +// reads risk OOM if an upstream misbehaves. +const maxMetadataSize = 100 << 20 -// ifNoneMatchHits reports whether the given If-None-Match header value -// matches the current entity tag using weak comparison, so "*" matches any -// tag, W/ prefixes are ignored on both sides, and a comma-separated list is -// scanned. An empty header or an empty stored tag never match. -func ifNoneMatchHits(header, etag string) bool { - if etag == "" || header == "" { - return false - } - if header == "*" { - return true - } - etag = strings.TrimPrefix(etag, "W/") - for value := range strings.SplitSeq(header, ",") { - if strings.TrimPrefix(strings.TrimSpace(value), "W/") == etag { - return true - } - } - return false -} - -// defaultMetadataMaxSize is used when Proxy.MetadataMaxSize is unset. -const defaultMetadataMaxSize = 100 << 20 - -// ErrMetadataTooLarge is returned when upstream metadata exceeds the configured limit. +// ErrMetadataTooLarge is returned when upstream metadata exceeds maxMetadataSize. var ErrMetadataTooLarge = errors.New("metadata response exceeds size limit") // ReadMetadata reads an upstream response body with a size limit to prevent OOM // from unexpectedly large responses. Returns ErrMetadataTooLarge if the response // is truncated by the limit. -func (p *Proxy) ReadMetadata(r io.Reader) ([]byte, error) { - limit := p.MetadataMaxSize - if limit <= 0 { - limit = defaultMetadataMaxSize - } - data, err := io.ReadAll(io.LimitReader(r, limit+1)) +func ReadMetadata(r io.Reader) ([]byte, error) { + data, err := io.ReadAll(io.LimitReader(r, maxMetadataSize+1)) if err != nil { return nil, err } - if int64(len(data)) > limit { + if int64(len(data)) > maxMetadataSize { return nil, ErrMetadataTooLarge } return data, nil @@ -149,46 +61,15 @@ func (p *Proxy) ReadMetadata(r io.Reader) ([]byte, error) { // Proxy provides shared functionality for protocol handlers. type Proxy struct { - DB *database.DB - Storage storage.Storage - Fetcher fetch.FetcherInterface - Resolver *fetch.Resolver - Logger *slog.Logger - Cooldown *cooldown.Config - CacheMetadata bool - MetadataTTL time.Duration - MetadataMaxSize int64 - GradleReadOnly bool - GradleMaxUploadSize int64 - // NPMFullMetadata requests full npm packuments from upstream even when - // cooldown is disabled, so served metadata carries publish times. - NPMFullMetadata bool - DirectServe bool - DirectServeTTL time.Duration - // DirectServeBaseURL, if set, replaces the scheme and host of presigned - // URLs so clients receive a public address even when the proxy reaches - // storage at an internal one. - DirectServeBaseURL string - HTTPClient *http.Client - AuthForURL func(string) (headerName, headerValue string) - - // Scanners runs pre-cache artifact scanning (e.g. trivy, ClamAV, Wiz). - // Nil or disabled means artifacts are cached without scanning. - Scanners *scanner.Group - - // ScanSigningKey authenticates pull requests to the internal - // /_internal/scan-fetch route used by scanners to retrieve staged - // artifacts, for every storage backend. - ScanSigningKey []byte - - // ScanFetchBaseURL is the address scanners use to reach this proxy to - // pull staged artifacts. - ScanFetchBaseURL string - - // inFlight coalesces concurrent cache misses for one artifact, so a single - // upstream fetch serves every waiting caller. Keyed by artifactCoalesceKey. - fetchMu sync.Mutex - inFlight map[string]*inflightFetch + DB *database.DB + Storage storage.Storage + Fetcher fetch.FetcherInterface + Resolver *fetch.Resolver + Logger *slog.Logger + Cooldown *cooldown.Config + CacheMetadata bool + MetadataTTL time.Duration + HTTPClient *http.Client } // NewProxy creates a new Proxy with the given dependencies. @@ -211,173 +92,86 @@ func NewProxy(db *database.DB, store storage.Storage, fetcher fetch.FetcherInter // CacheResult contains information about a cached or fetched artifact. type CacheResult struct { Reader io.ReadCloser - RedirectURL string - Artifact artifacts.Artifact + Size int64 + ContentType string + Hash string Cached bool - storagePath string } // GetOrFetchArtifact retrieves an artifact from cache or fetches from upstream. func (p *Proxy) GetOrFetchArtifact(ctx context.Context, ecosystem, name, version, filename string) (*CacheResult, error) { - pkgPURL, versionPURL, err := packagePURLStrings(ecosystem, name, version) - if err != nil { - return nil, err - } + pkgPURL := purl.MakePURLString(ecosystem, name, "") + versionPURL := purl.MakePURLString(ecosystem, name, version) + if cached, err := p.checkCache(ctx, pkgPURL, versionPURL, filename); err != nil { return nil, err } else if cached != nil { return cached, nil } - metrics.RecordCacheMiss(ecosystem) - key := artifactCoalesceKey(versionPURL, filename, "", "") - recheck := func() (artifacts.Artifact, string, bool) { - return p.cachedArtifactRecord(pkgPURL, versionPURL, filename, "") - } - return p.coalesceFetch(ctx, key, recheck, func(fetchCtx context.Context) (artifacts.Artifact, string, error) { - return p.fetchAndCache(fetchCtx, ecosystem, name, version, filename, pkgPURL, versionPURL) - }) -} - -// GetCachedArtifact retrieves an artifact from cache without contacting an upstream. -// It returns nil when no usable cache entry exists. -func (p *Proxy) GetCachedArtifact(ctx context.Context, ecosystem, name, version, filename string) (*CacheResult, error) { - pkgPURL, versionPURL, err := packagePURLStrings(ecosystem, name, version) - if err != nil { - return nil, err - } - return p.checkCache(ctx, pkgPURL, versionPURL, filename) -} - -// ClearCachedArtifact removes both an artifact cache record and its stored -// bytes after an external integrity check fails. -func (p *Proxy) ClearCachedArtifact(ctx context.Context, ecosystem, name, version, filename string) error { - if p.DB == nil || p.Storage == nil { - return nil - } - pkgPURL, versionPURL, err := packagePURLStrings(ecosystem, name, version) - if err != nil { - return err - } - cached, err := p.DB.GetCachedArtifact(pkgPURL, versionPURL, filename) - if err != nil { - return fmt.Errorf("looking up cached artifact: %w", err) - } - if cached == nil { - return nil - } - if err := p.Storage.Delete(ctx, cached.StoragePath); err != nil { - return fmt.Errorf("deleting cached artifact: %w", err) - } - return p.DB.ClearArtifactCache(versionPURL, filename) + return p.fetchAndCache(ctx, ecosystem, name, version, filename, pkgPURL, versionPURL) } // checkCache looks up an artifact in the cache. Returns nil if not cached. func (p *Proxy) checkCache(ctx context.Context, pkgPURL, versionPURL, filename string) (*CacheResult, error) { - artifact, err := p.DB.GetCachedArtifact(pkgPURL, versionPURL, filename) + pkg, err := p.DB.GetPackageByPURL(pkgPURL) + if err != nil { + return nil, fmt.Errorf("checking package cache: %w", err) + } + if pkg == nil { + return nil, nil + } + + ver, err := p.DB.GetVersionByPURL(versionPURL) + if err != nil { + return nil, fmt.Errorf("checking version cache: %w", err) + } + if ver == nil { + return nil, nil + } + + artifact, err := p.DB.GetArtifact(versionPURL, filename) if err != nil { return nil, fmt.Errorf("checking artifact cache: %w", err) } - if artifact == nil { + if artifact == nil || !artifact.IsCached() { return nil, nil } - checks, err := newIntegrityChecks(artifact.Artifact.Digest.Encoded(), artifact.Integrity.String) - if err != nil { - p.rejectUnusableCacheRecord(artifact, versionPURL, filename, err) - return nil, nil - } - - result := &CacheResult{ - Artifact: artifact.Artifact, - Cached: true, - storagePath: artifact.StoragePath, - } - - if p.DirectServe { - signed, err := p.Storage.SignedURL(ctx, artifact.StoragePath, p.DirectServeTTL) - if err == nil { - result.RedirectURL = rewriteSignedURLHost(signed, p.DirectServeBaseURL) - p.recordCacheHit(artifact.Ecosystem, versionPURL, filename) - return result, nil - } - if !errors.Is(err, storage.ErrSignedURLUnsupported) { - p.Logger.Warn("failed to sign storage URL, falling back to streaming", - "path", artifact.StoragePath, "error", err) - } - } start := time.Now() - reader, err := p.Storage.Open(ctx, artifact.StoragePath) + reader, err := p.Storage.Open(ctx, artifact.StoragePath.String) metrics.RecordStorageOperation("read", time.Since(start)) if err != nil { metrics.RecordStorageError("read") p.Logger.Warn("cached artifact missing from storage, will refetch", - "path", artifact.StoragePath, "error", err) + "path", artifact.StoragePath.String, "error", err) return nil, nil } - result.Reader, err = checks.wrap(reader, - func(reason string) { - p.Logger.Error("cached artifact failed integrity check", - "purl", versionPURL, "filename", filename, - "path", artifact.StoragePath, "reason", reason) - metrics.RecordIntegrityFailure(purl.NormalizeEcosystem(artifact.Ecosystem)) - if err := p.DB.ClearArtifactCache(versionPURL, filename); err != nil { - p.Logger.Warn("failed to clear corrupt artifact from cache", "error", err) - } - }) - if err != nil { - _ = reader.Close() - p.rejectUnusableCacheRecord(artifact, versionPURL, filename, err) - return nil, nil - } - p.recordCacheHit(artifact.Ecosystem, versionPURL, filename) - return result, nil -} - -// rewriteSignedURLHost replaces the scheme and host of a signed URL with those -// from baseURL, preserving the path and query (which carry the signature). -// Returns signed unchanged if baseURL is empty or either URL fails to parse. -func rewriteSignedURLHost(signed, baseURL string) string { - if baseURL == "" { - return signed - } - s, err := url.Parse(signed) - if err != nil { - return signed - } - b, err := url.Parse(baseURL) - if err != nil || b.Scheme == "" || b.Host == "" { - return signed - } - s.Scheme = b.Scheme - s.Host = b.Host - return s.String() -} - -func (p *Proxy) recordCacheHit(ecosystem, versionPURL, filename string) { _ = p.DB.RecordArtifactHit(versionPURL, filename) - metrics.RecordCacheHit(ecosystem) -} -func (p *Proxy) rejectUnusableCacheRecord(artifact *database.CachedArtifact, versionPURL, filename string, cause error) { - p.Logger.Warn("cached artifact has unusable integrity metadata", - "purl", versionPURL, "filename", filename, - "path", artifact.StoragePath, "error", cause) - metrics.RecordIntegrityFailure(purl.NormalizeEcosystem(artifact.Ecosystem)) - if err := p.DB.ClearArtifactCache(versionPURL, filename); err != nil { - p.Logger.Warn("failed to clear unusable artifact from cache", "error", err) + // Extract ecosystem from pkgPURL for metrics + if p, err := purl.Parse(pkgPURL); err == nil { + metrics.RecordCacheHit(purl.PURLTypeToEcosystem(p.Type)) } + + return &CacheResult{ + Reader: reader, + Size: artifact.Size.Int64, + ContentType: artifact.ContentType.String, + Hash: artifact.ContentHash.String, + Cached: true, + }, nil } -func (p *Proxy) fetchAndCache(ctx context.Context, ecosystem, name, version, filename, pkgPURL, versionPURL string) (artifacts.Artifact, string, error) { +func (p *Proxy) fetchAndCache(ctx context.Context, ecosystem, name, version, filename, pkgPURL, versionPURL string) (*CacheResult, error) { + // Record cache miss + metrics.RecordCacheMiss(ecosystem) + // Resolve download URL info, err := p.Resolver.Resolve(ctx, ecosystem, name, version) if err != nil { - if errors.Is(err, fetch.ErrNotFound) { - return artifacts.Artifact{}, "", ErrUpstreamNotFound - } - return artifacts.Artifact{}, "", fmt.Errorf("resolving download URL: %w", err) + return nil, fmt.Errorf("resolving download URL: %w", err) } // Use resolved filename if provided filename is empty @@ -396,83 +190,29 @@ func (p *Proxy) fetchAndCache(ctx context.Context, ecosystem, name, version, fil if err != nil { metrics.RecordUpstreamFetch(ecosystem, fetchDuration) metrics.RecordUpstreamError(ecosystem, "fetch_failed") - if errors.Is(err, fetch.ErrNotFound) { - return artifacts.Artifact{}, "", ErrUpstreamNotFound - } - return artifacts.Artifact{}, "", fmt.Errorf("fetching from upstream: %w", err) + return nil, fmt.Errorf("fetching from upstream: %w", err) } metrics.RecordUpstreamFetch(ecosystem, fetchDuration) - return p.storeArtifact(ctx, ecosystem, name, version, filename, pkgPURL, versionPURL, info.URL, "", artifact) -} - -// storeArtifact writes a fetched artifact to storage, verifies it against -// upstreamHash if non-empty, runs it through the scan gate if scanning is -// enabled, and commits it to the cache database. -// -// The scan gate sits between Storage.Store and updateCacheDB: updateCacheDB -// is the only thing that makes an artifact visible to clients (checkCache -// looks up its row before touching Storage), so deferring it until after a -// verdict means a blocked artifact was never reachable by any client. On -// block, the just-stored bytes are deleted and ErrArtifactBlocked is -// returned; updateCacheDB is never called. -// -// It returns the artifact and its storage path, not a reader; callers get one -// from openStoredArtifact. -func (p *Proxy) storeArtifact(ctx context.Context, ecosystem, name, version, filename, pkgPURL, versionPURL, upstreamURL, upstreamHash string, artifact *fetch.Artifact) (artifacts.Artifact, string, error) { + // Store in cache storagePath := storage.ArtifactPath(ecosystem, "", name, version, filename) - storeStart := time.Now() size, hash, err := p.Storage.Store(ctx, storagePath, artifact.Body) _ = artifact.Body.Close() metrics.RecordStorageOperation("write", time.Since(storeStart)) + if err != nil { metrics.RecordStorageError("write") - return artifacts.Artifact{}, "", fmt.Errorf("storing artifact: %w", err) - } - - if !artifactHashMatches(hash, upstreamHash) { - if delErr := p.Storage.Delete(ctx, storagePath); delErr != nil { - p.Logger.Warn("failed to discard artifact with mismatched checksum", "path", storagePath, "error", delErr) - } - return artifacts.Artifact{}, "", fmt.Errorf("%w: upstream declared %s, got %s", ErrArtifactDigestMismatch, upstreamHash, hash) - } - - if p.Scanners != nil && p.Scanners.Enabled() { - if err := p.runScan(ctx, ecosystem, name, version, filename, versionPURL, storagePath, size, artifact.ContentType); err != nil { - // Detached from ctx: a client disconnecting must not abort - // cleanup of a genuinely blocked artifact and leave its bytes - // orphaned in storage with no DB row pointing at them. - if delErr := p.Storage.Delete(context.WithoutCancel(ctx), storagePath); delErr != nil { - p.Logger.Warn("failed to delete blocked artifact from storage", - "path", storagePath, "error", delErr) - } - return artifacts.Artifact{}, "", err - } - } - - sharedArtifact := artifacts.Artifact{ - PURL: versionPURL, - Digest: digest.Digest("sha256:" + hash), - Size: size, - Filename: filename, - MediaType: artifact.ContentType, + return nil, fmt.Errorf("storing artifact: %w", err) } // Update database - if err := p.updateCacheDB(ecosystem, name, pkgPURL, upstreamURL, storagePath, sharedArtifact); err != nil { + if err := p.updateCacheDB(ecosystem, name, filename, pkgPURL, versionPURL, info.URL, storagePath, hash, size, artifact.ContentType); err != nil { p.Logger.Warn("failed to update cache database", "error", err) // Continue anyway - we have the file } - return sharedArtifact, storagePath, nil -} - -// openStoredArtifact gives one caller its own reader over just-committed -// bytes. Callers sharing a fetch cannot share a handle: it has one read -// position, so they would consume each other's bytes and the first Close would -// break the rest. -func (p *Proxy) openStoredArtifact(ctx context.Context, artifact artifacts.Artifact, storagePath string) (*CacheResult, error) { + // Open the stored file to return readStart := time.Now() reader, err := p.Storage.Open(ctx, storagePath) metrics.RecordStorageOperation("read", time.Since(readStart)) @@ -483,186 +223,24 @@ func (p *Proxy) openStoredArtifact(ctx context.Context, artifact artifacts.Artif } return &CacheResult{ - Reader: reader, - Artifact: artifact, - Cached: false, + Reader: reader, + Size: size, + ContentType: artifact.ContentType, + Hash: hash, + Cached: false, }, nil } -// artifactCoalesceKey identifies one artifact fetch. downloadURL and -// upstreamHash are included so callers expecting different bytes (multiple -// upstreams, or a re-published version) never share a fetch. The hash is -// lowercased because artifactHashMatches compares case-insensitively, so one -// digest in two casings describes one artifact and must not split the fetch. -func artifactCoalesceKey(versionPURL, filename, downloadURL, upstreamHash string) string { - return strings.Join([]string{versionPURL, filename, downloadURL, strings.ToLower(upstreamHash)}, "\x00") -} - -// cachedArtifactRecord reports an artifact already committed to the cache, -// without opening it. A caller checks the cache before it gets here, so a -// concurrent fetch can commit the same artifact in between; rechecking the -// record keeps that caller from fetching it a second time. A lookup error is -// reported as a miss, which costs a redundant fetch rather than a failure. -func (p *Proxy) cachedArtifactRecord(pkgPURL, versionPURL, filename, upstreamHash string) (artifacts.Artifact, string, bool) { - record, err := p.DB.GetCachedArtifact(pkgPURL, versionPURL, filename) - if err != nil || record == nil { - return artifacts.Artifact{}, "", false - } - if !artifactHashMatches(record.Artifact.Digest.Encoded(), upstreamHash) { - return artifacts.Artifact{}, "", false - } - return record.Artifact, record.StoragePath, true -} - -// errSharedFetchAbandoned is what waiters see if the caller running a shared -// fetch panicked out of it. -var errSharedFetchAbandoned = errors.New("shared upstream fetch did not complete") - -// inflightFetch is one upstream fetch that concurrent callers share. val and -// err are written before done closes and read only after, so the close is the -// handoff. -type inflightFetch struct { - done chan struct{} - val fetchedArtifact - err error -} - -// coalesceFetch runs commit at most once for concurrent callers sharing key, -// then gives each its own reader over the stored bytes. -// -// The first caller in runs the fetch and the rest wait on it. Roles are -// decided under fetchMu rather than inferred afterwards, because the two need -// different cancellation behaviour: a waiter may leave when its own client goes -// away, while the caller running the fetch must see it through so -// storeArtifact's scan-on-disconnect handling still decides the outcome. -// -// Before fetching, that caller rechecks the cache through recheck: its own -// lookup happened before it took the key, so a fetch that committed in -// between would otherwise be repeated. A hit fills the shared value as a -// fetch would. -// -// commit runs on that caller's context, so cancellation behaves as it did -// uncoalesced and mirroring still relies on it aborting the fetch. If that -// caller goes away, everyone sharing the fetch gets its error and the key is -// released for a later retry. -// -// Every sharing caller still records a cache miss, so the gap between -// proxy_cache_misses_total and upstream fetch observations is what coalescing -// saved. -func (p *Proxy) coalesceFetch(ctx context.Context, key string, recheck func() (artifacts.Artifact, string, bool), commit func(context.Context) (artifacts.Artifact, string, error)) (*CacheResult, error) { - p.fetchMu.Lock() - if p.inFlight == nil { - p.inFlight = make(map[string]*inflightFetch) - } - f, joined := p.inFlight[key] - if !joined { - f = &inflightFetch{done: make(chan struct{})} - p.inFlight[key] = f - } - p.fetchMu.Unlock() - - if !joined { - return p.runSharedFetch(ctx, key, f, recheck, commit) - } - - select { - case <-ctx.Done(): - // This caller gave up; the fetch continues for everyone else. - return nil, ctx.Err() - case <-f.done: - } - if f.err != nil { - return nil, f.err - } - return p.openStoredArtifact(ctx, f.val.artifact, f.val.storagePath) -} - -// runSharedFetch performs the fetch that joined callers are waiting on. It is -// never abandoned early, and always releases the key and wakes the waiters. -func (p *Proxy) runSharedFetch(ctx context.Context, key string, f *inflightFetch, recheck func() (artifacts.Artifact, string, bool), commit func(context.Context) (artifacts.Artifact, string, error)) (*CacheResult, error) { - // Set before running so a panicking commit leaves waiters with an error - // rather than a zero-valued artifact. - f.err = errSharedFetchAbandoned - defer func() { - p.fetchMu.Lock() - delete(p.inFlight, key) - p.fetchMu.Unlock() - close(f.done) - }() - - // A caller checks the cache before reaching here, so a fetch that finished - // in between would otherwise be repeated. Serve that record only if its - // bytes are still present: a record can outlive them, and refetching is - // the same recovery the cache lookup makes. - if stored, path, ok := recheck(); ok { - if res, err := p.openStoredArtifact(ctx, stored, path); err == nil { - f.val, f.err = fetchedArtifact{artifact: stored, storagePath: path}, nil - return res, nil - } - } - - stored, path, err := commit(ctx) - f.val, f.err = fetchedArtifact{artifact: stored, storagePath: path}, err - if err != nil { - return nil, err - } - return p.openStoredArtifact(ctx, stored, path) -} - -// fetchedArtifact is what a shared fetch hands its callers: metadata and a -// storage path, neither holding reader state. -type fetchedArtifact struct { - artifact artifacts.Artifact - storagePath string -} - -// runScan generates a signed fetch URL for the just-staged artifact and -// asks the configured scanners for a verdict. Returns a wrapped -// ErrArtifactBlocked if any scanner blocks, or a scan-infrastructure error. -// -// The scan call runs on a context detached from ctx's cancellation -// (context.WithoutCancel): ctx is the original client request's context, and -// a client disconnecting mid-scan must not be indistinguishable from a real -// scanner verdict. Group.Scan still bounds the call with its own configured -// timeout, so a detached context cannot hang forever. -func (p *Proxy) runScan(ctx context.Context, ecosystem, name, version, filename, purlStr, storagePath string, size int64, contentType string) error { - fetchURL := p.scanFetchURL(storagePath, p.Scanners.Timeout()) - result := p.Scanners.Scan(context.WithoutCancel(ctx), scanner.Request{ - Ecosystem: ecosystem, - Name: name, - Version: version, - Filename: filename, - PURL: purlStr, - FetchURL: fetchURL, - Size: size, - ContentType: contentType, - }) - if !result.Allowed { - p.Logger.Warn("artifact blocked by security scan", - "ecosystem", ecosystem, "name", name, "version", version, "filename", filename, - "scanner", result.ScannerName, "reason", result.Reason, "infra_error", result.InfraError) - reason := result.Reason - if result.InfraError { - // result.Reason may contain raw scanner-infrastructure details - // (internal hostnames, ports, connection errors) that must not - // reach an untrusted client via the 403 response body. - reason = "scan could not be completed" - } - return fmt.Errorf("%w: %s", ErrArtifactBlocked, reason) - } - return nil -} - -func (p *Proxy) updateCacheDB(ecosystem, name, pkgPURL, upstreamURL, storagePath string, artifact artifacts.Artifact) error { +func (p *Proxy) updateCacheDB(ecosystem, name, filename, pkgPURL, versionPURL, upstreamURL, storagePath, hash string, size int64, contentType string) error { now := time.Now() // Upsert package pkg := &database.Package{ - PURL: pkgPURL, - Ecosystem: ecosystem, - Name: name, + PURL: pkgPURL, + Ecosystem: ecosystem, + Name: name, RegistryURL: sql.NullString{String: upstreamURL, Valid: true}, - EnrichedAt: sql.NullTime{Time: now, Valid: true}, + EnrichedAt: sql.NullTime{Time: now, Valid: true}, } if err := p.DB.UpsertPackage(pkg); err != nil { return fmt.Errorf("upserting package: %w", err) @@ -670,7 +248,7 @@ func (p *Proxy) updateCacheDB(ecosystem, name, pkgPURL, upstreamURL, storagePath // Upsert version ver := &database.Version{ - PURL: artifact.PURL, + PURL: versionPURL, PackagePURL: pkgPURL, EnrichedAt: sql.NullTime{Time: now, Valid: true}, } @@ -680,13 +258,13 @@ func (p *Proxy) updateCacheDB(ecosystem, name, pkgPURL, upstreamURL, storagePath // Upsert artifact art := &database.Artifact{ - VersionPURL: artifact.PURL, - Filename: artifact.Filename, + VersionPURL: versionPURL, + Filename: filename, UpstreamURL: upstreamURL, StoragePath: sql.NullString{String: storagePath, Valid: true}, - ContentHash: sql.NullString{String: artifact.Digest.Encoded(), Valid: true}, - Size: sql.NullInt64{Int64: artifact.Size, Valid: true}, - ContentType: sql.NullString{String: artifact.MediaType, Valid: true}, + ContentHash: sql.NullString{String: hash, Valid: true}, + Size: sql.NullInt64{Int64: size, Valid: true}, + ContentType: sql.NullString{String: contentType, Valid: true}, FetchedAt: sql.NullTime{Time: now, Valid: true}, } if err := p.DB.UpsertArtifact(art); err != nil { @@ -698,44 +276,20 @@ func (p *Proxy) updateCacheDB(ecosystem, name, pkgPURL, upstreamURL, storagePath // ServeArtifact writes a CacheResult to an HTTP response. func ServeArtifact(w http.ResponseWriter, result *CacheResult) { - serveArtifact(w, http.MethodGet, result) -} + defer func() { _ = result.Reader.Close() }() -func serveArtifact(w http.ResponseWriter, method string, result *CacheResult) { - contentHash := "" - if result.Artifact.Digest != "" { - contentHash = result.Artifact.Digest.Encoded() + if result.ContentType != "" { + w.Header().Set("Content-Type", result.ContentType) } - if result.RedirectURL != "" { - if contentHash != "" { - w.Header().Set(headerETag, `"`+contentHash+`"`) - } - w.Header().Set("Location", result.RedirectURL) - w.WriteHeader(http.StatusFound) - return + if result.Size > 0 { + w.Header().Set("Content-Length", fmt.Sprintf("%d", result.Size)) } - - if result.Reader != nil { - defer func() { _ = result.Reader.Close() }() - } - - if result.Artifact.MediaType != "" { - w.Header().Set(headerContentType, result.Artifact.MediaType) - } - if result.Artifact.Size > 0 || (method == http.MethodHead && result.Artifact.Size == 0) { - w.Header().Set(headerContentLength, strconv.FormatInt(result.Artifact.Size, 10)) - } - if contentHash != "" { - w.Header().Set(headerETag, `"`+contentHash+`"`) + if result.Hash != "" { + w.Header().Set("ETag", fmt.Sprintf(`"%s"`, result.Hash)) } w.WriteHeader(http.StatusOK) - if method != http.MethodHead && result.Reader != nil { - buffer := artifactCopyBufferPool.Get().(*[]byte) - defer artifactCopyBufferPool.Put(buffer) - // Hide optional ReaderFrom methods so io.CopyBuffer uses the pooled buffer. - _, _ = io.CopyBuffer(struct{ io.Writer }{w}, result.Reader, *buffer) - } + _, _ = io.Copy(w, result.Reader) } // ProxyUpstream forwards a request to an upstream URL without caching. @@ -756,7 +310,6 @@ func (p *Proxy) ProxyUpstream(w http.ResponseWriter, r *http.Request, upstreamUR req.Header.Set(header, v) } } - p.applyUpstreamAuth(req) resp, err := p.HTTPClient.Do(req) if err != nil { @@ -783,7 +336,6 @@ func (p *Proxy) ProxyFile(w http.ResponseWriter, r *http.Request, upstreamURL st http.Error(w, "failed to create request", http.StatusInternalServerError) return } - p.applyUpstreamAuth(req) resp, err := p.HTTPClient.Do(req) if err != nil { @@ -804,32 +356,13 @@ func (p *Proxy) ProxyFile(w http.ResponseWriter, r *http.Request, upstreamURL st // JSONError writes a JSON error response. func JSONError(w http.ResponseWriter, status int, message string) { - w.Header().Set(headerContentType, contentTypeJSON) + w.Header().Set("Content-Type", contentTypeJSON) w.WriteHeader(status) _, _ = fmt.Fprintf(w, `{"error":%q}`, message) } // ErrUpstreamNotFound indicates the upstream returned 404. -var ErrUpstreamNotFound = fmt.Errorf("upstream: %w", fetch.ErrNotFound) - -// ErrArtifactBlocked indicates a pre-cache security scan blocked the artifact. -var ErrArtifactBlocked = errors.New("artifact blocked by security scan") - -// serveArtifactError writes response for a failed fetch: -// 404 when upstream reports artifact missing, 403 when a security scan -// blocked the artifact, 502 otherwise. -func (p *Proxy) serveArtifactError(w http.ResponseWriter, err error, clientMsg string) { - if errors.Is(err, ErrUpstreamNotFound) { - http.Error(w, "not found", http.StatusNotFound) - return - } - if errors.Is(err, ErrArtifactBlocked) { - JSONError(w, http.StatusForbidden, err.Error()) - return - } - p.Logger.Error("failed to get artifact", "error", err) - http.Error(w, clientMsg, http.StatusBadGateway) -} +var ErrUpstreamNotFound = fmt.Errorf("upstream: not found") // errStale304 is returned when upstream sends 304 but the cached file is missing. var errStale304 = fmt.Errorf("upstream returned 304 but cached file is missing") @@ -845,22 +378,8 @@ func metadataStoragePath(ecosystem, cacheKey string) string { // cacheKey is typically the package name but can include subpath components. // Optional acceptHeaders specify the Accept header(s) to send; defaults to application/json. func (p *Proxy) FetchOrCacheMetadata(ctx context.Context, ecosystem, cacheKey, upstreamURL string, acceptHeaders ...string) ([]byte, string, error) { - body, contentType, _, err := p.fetchOrCacheMetadata(ctx, ecosystem, cacheKey, upstreamURL, "", nil, acceptHeaders...) - return body, contentType, err -} - -// fetchOrCacheMetadata implements FetchOrCacheMetadata. acceptEncoding controls -// the upstream Accept-Encoding: an empty string leaves it unset so Go -// transparently decompresses (for direct callers that parse or rewrite the -// body); any non-empty value is sent verbatim, which disables Go's -// decompression so the wire bytes and their Content-Encoding are stored and -// replayed as sent. The ProxyCached path uses "identity" for signed indexes and -// "gzip" where both hops should stay compressed. -// validate, when supplied, runs before caching or serving a document. Validation -// failures follow the same stale-cache fallback path as upstream failures. -func (p *Proxy) fetchOrCacheMetadata(ctx context.Context, ecosystem, cacheKey, upstreamURL, acceptEncoding string, validate func([]byte) error, acceptHeaders ...string) ([]byte, string, string, error) { if containsPathTraversal(cacheKey) { - return nil, "", "", fmt.Errorf("invalid cache key: %q", cacheKey) + return nil, "", fmt.Errorf("invalid cache key: %q", cacheKey) } storagePath := metadataStoragePath(ecosystem, cacheKey) @@ -874,19 +393,21 @@ func (p *Proxy) fetchOrCacheMetadata(ctx context.Context, ecosystem, cacheKey, u // Serve from cache if within TTL (skip upstream entirely) if entry != nil && p.MetadataTTL > 0 && entry.FetchedAt.Valid { if time.Since(entry.FetchedAt.Time) < p.MetadataTTL { - data, ct, readErr := p.readCachedMetadata(ctx, entry, validate) + cached, readErr := p.Storage.Open(ctx, entry.StoragePath) if readErr == nil { - metrics.RecordCacheHit(ecosystem) - return data, ct, entry.ContentEncoding.String, nil - } - if validate != nil { - // Do not revalidate an unusable cached body with its ETag. - entry = nil + defer func() { _ = cached.Close() }() + data, readErr := ReadMetadata(cached) + if readErr == nil { + ct := contentTypeJSON + if entry.ContentType.Valid { + ct = entry.ContentType.String + } + return data, ct, nil + } } // Cache file missing/unreadable, fall through to upstream } } - p.recordMetadataCacheMiss(ecosystem) accept := contentTypeJSON if len(acceptHeaders) > 0 && acceptHeaders[0] != "" { @@ -894,105 +415,64 @@ func (p *Proxy) fetchOrCacheMetadata(ctx context.Context, ecosystem, cacheKey, u } // Try upstream - meta, err := p.fetchUpstreamMetadata(ctx, upstreamURL, entry, accept, acceptEncoding) + body, contentType, etag, lastModified, err := p.fetchUpstreamMetadata(ctx, upstreamURL, entry, accept) if errors.Is(err, errStale304) { // 304 but cached file is gone; retry without ETag - meta, err = p.fetchUpstreamMetadata(ctx, upstreamURL, nil, accept, acceptEncoding) - } - if err == nil && validate != nil { - err = validate(meta.body) + body, contentType, etag, lastModified, err = p.fetchUpstreamMetadata(ctx, upstreamURL, nil, accept) } if err == nil { if p.CacheMetadata { - p.cacheMetadataBlob(ctx, ecosystem, cacheKey, storagePath, meta) + p.cacheMetadataBlob(ctx, ecosystem, cacheKey, storagePath, body, contentType, etag, lastModified) } - return meta.body, meta.contentType, meta.contentEncoding, nil + return body, contentType, nil } // Upstream failed -- fall back to cache if available if !p.CacheMetadata || entry == nil { - return nil, "", "", fmt.Errorf("upstream failed and no cached metadata: %w", err) + return nil, "", fmt.Errorf("upstream failed and no cached metadata: %w", err) } p.Logger.Warn("upstream metadata fetch failed, checking cache", "ecosystem", ecosystem, "key", cacheKey, "error", err) - // Re-read the row so the encoding describes the blob as it is now: a - // concurrent refetch may have replaced both since entry was read above - // (an identity blob swapped for a gzip one during rollout). - entry = p.currentMetadataEntry(ecosystem, cacheKey, entry) - - data, ct, readErr := p.readCachedMetadata(ctx, entry, validate) + cached, readErr := p.Storage.Open(ctx, entry.StoragePath) if readErr != nil { - return nil, "", "", fmt.Errorf("upstream failed and cached metadata unusable (%v): %w", readErr, err) - } - - p.Logger.Info("serving metadata from cache", - "ecosystem", ecosystem, "key", cacheKey) - return data, ct, entry.ContentEncoding.String, nil -} - -func (p *Proxy) readCachedMetadata(ctx context.Context, entry *database.MetadataCacheEntry, validate func([]byte) error) ([]byte, string, error) { - cached, err := p.Storage.Open(ctx, entry.StoragePath) - if err != nil { - return nil, "", err + return nil, "", fmt.Errorf("upstream failed and cached file missing: %w", err) } defer func() { _ = cached.Close() }() - data, err := p.ReadMetadata(cached) - if err == nil && validate != nil { - err = validate(data) - } - if err != nil { - return nil, "", err + + data, readErr := ReadMetadata(cached) + if readErr != nil { + return nil, "", fmt.Errorf("upstream failed and cached read error: %w", err) } + ct := contentTypeJSON if entry.ContentType.Valid { ct = entry.ContentType.String } + p.Logger.Info("serving metadata from cache", + "ecosystem", ecosystem, "key", cacheKey) return data, ct, nil } -func (p *Proxy) recordMetadataCacheMiss(ecosystem string) { - if p.CacheMetadata { - metrics.RecordCacheMiss(ecosystem) - } -} - -// upstreamMetadata holds a fetched metadata response in upstream byte form. -type upstreamMetadata struct { - body []byte - contentType string - contentEncoding string - etag string - lastModified time.Time -} - // fetchUpstreamMetadata fetches metadata from upstream, using ETag for conditional revalidation. -// When acceptEncoding is non-empty it is sent as the Accept-Encoding header, which disables Go's -// transparent decompression (it only applies when the transport adds the header itself), so the -// returned bytes are exactly what the upstream sent and any Content-Encoding it applied is reported -// alongside for the caller to store and replay. An empty acceptEncoding leaves Go to negotiate and -// decompress transparently. -func (p *Proxy) fetchUpstreamMetadata(ctx context.Context, upstreamURL string, entry *database.MetadataCacheEntry, accept, acceptEncoding string) (*upstreamMetadata, error) { +// Returns the body, content type, ETag, upstream Last-Modified time, and any error. +func (p *Proxy) fetchUpstreamMetadata(ctx context.Context, upstreamURL string, entry *database.MetadataCacheEntry, accept string) ([]byte, string, string, time.Time, error) { + var zeroTime time.Time + req, err := http.NewRequestWithContext(ctx, http.MethodGet, upstreamURL, nil) if err != nil { - return nil, fmt.Errorf("creating request: %w", err) + return nil, "", "", zeroTime, fmt.Errorf("creating request: %w", err) } req.Header.Set("Accept", accept) - if acceptEncoding != "" { - req.Header.Set(headerAcceptEncoding, acceptEncoding) - } - p.applyUpstreamAuth(req) if entry != nil && entry.ETag.Valid { req.Header.Set("If-None-Match", entry.ETag.String) - } else if entry != nil && entry.LastModified.Valid { - req.Header.Set("If-Modified-Since", entry.LastModified.Time.UTC().Format(http.TimeFormat)) } resp, err := p.HTTPClient.Do(req) if err != nil { - return nil, fmt.Errorf("fetching metadata: %w", err) + return nil, "", "", zeroTime, fmt.Errorf("fetching metadata: %w", err) } defer func() { _ = resp.Body.Close() }() @@ -1000,97 +480,73 @@ func (p *Proxy) fetchUpstreamMetadata(ctx context.Context, upstreamURL string, e if resp.StatusCode == http.StatusNotModified && entry != nil { cached, readErr := p.Storage.Open(ctx, entry.StoragePath) if readErr != nil { - return nil, errStale304 + return nil, "", "", zeroTime, errStale304 } defer func() { _ = cached.Close() }() - data, readErr := p.ReadMetadata(cached) + data, readErr := ReadMetadata(cached) if readErr != nil { - return nil, errStale304 + return nil, "", "", zeroTime, errStale304 } - meta := &upstreamMetadata{body: data, contentType: contentTypeJSON, etag: entry.ETag.String} + ct := contentTypeJSON if entry.ContentType.Valid { - meta.contentType = entry.ContentType.String - } - if entry.ContentEncoding.Valid { - meta.contentEncoding = entry.ContentEncoding.String + ct = entry.ContentType.String } + lm := zeroTime if entry.LastModified.Valid { - meta.lastModified = entry.LastModified.Time + lm = entry.LastModified.Time } - return meta, nil + return data, ct, entry.ETag.String, lm, nil } if resp.StatusCode == http.StatusNotFound { - return nil, ErrUpstreamNotFound + return nil, "", "", zeroTime, ErrUpstreamNotFound } if resp.StatusCode != http.StatusOK { - return nil, fmt.Errorf("upstream returned %d", resp.StatusCode) + return nil, "", "", zeroTime, fmt.Errorf("upstream returned %d", resp.StatusCode) } - body, err := p.ReadMetadata(resp.Body) + body, err := ReadMetadata(resp.Body) if err != nil { - return nil, fmt.Errorf("reading response: %w", err) + return nil, "", "", zeroTime, fmt.Errorf("reading response: %w", err) } - meta := &upstreamMetadata{ - body: body, - contentType: resp.Header.Get(headerContentType), - contentEncoding: resp.Header.Get(headerContentEncoding), - etag: resp.Header.Get(headerETag), + contentType := resp.Header.Get("Content-Type") + if contentType == "" { + contentType = contentTypeJSON } - if meta.contentType == "" { - meta.contentType = contentTypeJSON + + etag := resp.Header.Get("ETag") + + var lastModified time.Time + if lm := resp.Header.Get("Last-Modified"); lm != "" { + lastModified, _ = http.ParseTime(lm) } - if lm := resp.Header.Get(headerLastModified); lm != "" { - meta.lastModified, _ = http.ParseTime(lm) - } - return meta, nil + + return body, contentType, etag, lastModified, nil } // cacheMetadataBlob stores metadata bytes in storage and updates the database. -func (p *Proxy) cacheMetadataBlob(ctx context.Context, ecosystem, cacheKey, storagePath string, meta *upstreamMetadata) { +func (p *Proxy) cacheMetadataBlob(ctx context.Context, ecosystem, cacheKey, storagePath string, data []byte, contentType, etag string, lastModified time.Time) { if p.DB == nil || p.Storage == nil { return } - size, _, err := p.Storage.Store(ctx, storagePath, bytes.NewReader(meta.body)) + size, _, err := p.Storage.Store(ctx, storagePath, bytes.NewReader(data)) if err != nil { p.Logger.Warn("failed to cache metadata", "ecosystem", ecosystem, "key", cacheKey, "error", err) return } - err = p.DB.UpsertMetadataCache(&database.MetadataCacheEntry{ - Ecosystem: ecosystem, - Name: cacheKey, - StoragePath: storagePath, - ETag: sql.NullString{String: meta.etag, Valid: meta.etag != ""}, - ContentType: sql.NullString{String: meta.contentType, Valid: meta.contentType != ""}, - ContentEncoding: sql.NullString{String: meta.contentEncoding, Valid: meta.contentEncoding != ""}, - Size: sql.NullInt64{Int64: size, Valid: true}, - LastModified: sql.NullTime{Time: meta.lastModified, Valid: !meta.lastModified.IsZero()}, - FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, + _ = p.DB.UpsertMetadataCache(&database.MetadataCacheEntry{ + Ecosystem: ecosystem, + Name: cacheKey, + StoragePath: storagePath, + ETag: sql.NullString{String: etag, Valid: etag != ""}, + ContentType: sql.NullString{String: contentType, Valid: contentType != ""}, + Size: sql.NullInt64{Int64: size, Valid: true}, + LastModified: sql.NullTime{Time: lastModified, Valid: !lastModified.IsZero()}, + FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, }) - if err != nil { - // The blob is written but the row describing it is not, so a later - // TTL hit or stale fallback would serve these bytes with the previous - // row's encoding. Drop the blob so row and bytes can never disagree; - // the next request refetches instead. - p.Logger.Warn("failed to record cached metadata, discarding blob", "ecosystem", ecosystem, "key", cacheKey, "error", err) - if delErr := p.Storage.Delete(ctx, storagePath); delErr != nil { - p.Logger.Warn("failed to discard metadata blob", "ecosystem", ecosystem, "key", cacheKey, "error", delErr) - } - } -} - -// currentMetadataEntry re-reads the metadata cache row and returns it, or -// fallback when the row cannot be read. Used before serving a stored blob so -// its encoding comes from the row as it is now rather than from a snapshot -// taken before the upstream fetch. -func (p *Proxy) currentMetadataEntry(ecosystem, cacheKey string, fallback *database.MetadataCacheEntry) *database.MetadataCacheEntry { - if fresh, err := p.DB.GetMetadataCache(ecosystem, cacheKey); err == nil && fresh != nil { - return fresh - } - return fallback } // cachedMeta holds cache validators and freshness state from a metadata cache entry. @@ -1129,22 +585,13 @@ func (p *Proxy) lookupCachedMeta(ecosystem, cacheKey string) cachedMeta { // When metadata caching is disabled, the response is streamed directly to avoid buffering // large metadata responses (e.g. npm packages with many versions) in memory. func (p *Proxy) ProxyCached(w http.ResponseWriter, r *http.Request, upstreamURL, ecosystem, cacheKey string, acceptHeaders ...string) { - p.proxyCachedWithEncoding(w, r, upstreamURL, ecosystem, cacheKey, "identity", acceptHeaders...) -} - -// proxyCachedWithEncoding is ProxyCached with an explicit upstream Accept-Encoding. -// "identity" preserves signed index bytes (the default); "gzip" keeps both hops -// compressed for large, non-hash-pinned metadata whose clients decode gzip -// (Homebrew API). The stored bytes and Content-Encoding are replayed verbatim -// either way. -func (p *Proxy) proxyCachedWithEncoding(w http.ResponseWriter, r *http.Request, upstreamURL, ecosystem, cacheKey, acceptEncoding string, acceptHeaders ...string) { if !p.CacheMetadata { // Stream directly without buffering when caching is off. - p.proxyMetadataStream(w, r, upstreamURL, acceptEncoding, acceptHeaders...) + p.proxyMetadataStream(w, r, upstreamURL, acceptHeaders...) return } - body, contentType, contentEncoding, err := p.fetchOrCacheMetadata(r.Context(), ecosystem, cacheKey, upstreamURL, acceptEncoding, nil, acceptHeaders...) + body, contentType, err := p.FetchOrCacheMetadata(r.Context(), ecosystem, cacheKey, upstreamURL, acceptHeaders...) if err != nil { if errors.Is(err, ErrUpstreamNotFound) { http.Error(w, "not found", http.StatusNotFound) @@ -1155,32 +602,14 @@ func (p *Proxy) proxyCachedWithEncoding(w http.ResponseWriter, r *http.Request, return } - p.writeMetadataCachedResponseWithEncoding(w, r, ecosystem, cacheKey, body, contentType, contentEncoding) -} - -// writeMetadataCachedResponse writes a cached metadata response and handles -// conditional request headers using metadata cache validators. -func (p *Proxy) writeMetadataCachedResponse(w http.ResponseWriter, r *http.Request, ecosystem, cacheKey string, body []byte, contentType string) { - p.writeMetadataCachedResponseWithEncoding(w, r, ecosystem, cacheKey, body, contentType, "") -} - -// writeMetadataCachedResponseWithEncoding is writeMetadataCachedResponse with -// an explicit Content-Encoding. contentEncoding must describe the body being -// written; it is passed in rather than re-read from the cache row, which is -// missing or stale when the metadata cache write failed and would otherwise -// mislabel the bytes. -func (p *Proxy) writeMetadataCachedResponseWithEncoding(w http.ResponseWriter, r *http.Request, ecosystem, cacheKey string, body []byte, contentType, contentEncoding string) { cm := p.lookupCachedMeta(ecosystem, cacheKey) + // Honor client conditional request headers if cm.etag != "" { - w.Header().Set(headerETag, cm.etag) - } - if !cm.lastModified.IsZero() { - w.Header().Set(headerLastModified, cm.lastModified.UTC().Format(http.TimeFormat)) - } - if ifNoneMatchHits(r.Header.Get("If-None-Match"), cm.etag) { - w.WriteHeader(http.StatusNotModified) - return + if match := r.Header.Get("If-None-Match"); match != "" && match == cm.etag { + w.WriteHeader(http.StatusNotModified) + return + } } if !cm.lastModified.IsZero() { if ims := r.Header.Get("If-Modified-Since"); ims != "" { @@ -1191,24 +620,25 @@ func (p *Proxy) writeMetadataCachedResponseWithEncoding(w http.ResponseWriter, r } } - w.Header().Set(headerContentType, contentType) - w.Header().Set(headerContentLength, strconv.Itoa(len(body))) - if contentEncoding != "" { - w.Header().Set(headerContentEncoding, contentEncoding) + w.Header().Set("Content-Type", contentType) + w.Header().Set("Content-Length", strconv.Itoa(len(body))) + if cm.etag != "" { + w.Header().Set("ETag", cm.etag) + } + if !cm.lastModified.IsZero() { + w.Header().Set("Last-Modified", cm.lastModified.UTC().Format(http.TimeFormat)) } if cm.stale { w.Header().Set("Warning", `110 - "Response is Stale"`) } w.WriteHeader(http.StatusOK) - if r.Method != http.MethodHead { - _, _ = w.Write(body) - } + _, _ = w.Write(body) } // proxyMetadataStream forwards an upstream metadata response by streaming it to the client // without buffering the full body in memory. -func (p *Proxy) proxyMetadataStream(w http.ResponseWriter, r *http.Request, upstreamURL, acceptEncoding string, acceptHeaders ...string) { - req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil) +func (p *Proxy) proxyMetadataStream(w http.ResponseWriter, r *http.Request, upstreamURL string, acceptHeaders ...string) { + req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil) if err != nil { http.Error(w, "failed to create request", http.StatusInternalServerError) return @@ -1219,17 +649,8 @@ func (p *Proxy) proxyMetadataStream(w http.ResponseWriter, r *http.Request, upst accept = acceptHeaders[0] } req.Header.Set("Accept", accept) - // Set Accept-Encoding explicitly (identity, or gzip for compressible - // verbatim metadata) so Go does not transparently decompress and strip the - // Content-Encoding of the bytes we forward, regardless of what the client - // negotiated. An empty value leaves the header unset, as in - // fetchUpstreamMetadata. - if acceptEncoding != "" { - req.Header.Set(headerAcceptEncoding, acceptEncoding) - } - p.applyUpstreamAuth(req) - for _, header := range []string{"If-Modified-Since", "If-None-Match"} { + for _, header := range []string{"Accept-Encoding", "If-Modified-Since", "If-None-Match"} { if v := r.Header.Get(header); v != "" { req.Header.Set(header, v) } @@ -1242,158 +663,69 @@ func (p *Proxy) proxyMetadataStream(w http.ResponseWriter, r *http.Request, upst } defer func() { _ = resp.Body.Close() }() - for _, header := range []string{headerContentType, headerContentLength, headerContentEncoding, headerLastModified, headerETag} { + for _, header := range []string{"Content-Type", "Content-Length", "Last-Modified", "ETag"} { if v := resp.Header.Get(header); v != "" { w.Header().Set(header, v) } } w.WriteHeader(resp.StatusCode) - if r.Method != http.MethodHead { - _, _ = io.Copy(w, resp.Body) - } -} - -func (p *Proxy) applyUpstreamAuth(req *http.Request) { - if p.AuthForURL == nil { - return - } - - headerName, headerValue := p.AuthForURL(req.URL.String()) - if headerName != "" && headerValue != "" { - req.Header.Set(headerName, headerValue) - } + _, _ = io.Copy(w, resp.Body) } // GetOrFetchArtifactFromURL retrieves an artifact from cache or fetches from a specific URL. // This is useful for registries where download URLs are determined from metadata. func (p *Proxy) GetOrFetchArtifactFromURL(ctx context.Context, ecosystem, name, version, filename, downloadURL string) (*CacheResult, error) { - return p.getOrFetchArtifactFromURL(ctx, ecosystem, name, version, filename, downloadURL, nil, "") + return p.GetOrFetchArtifactFromURLWithHeaders(ctx, ecosystem, name, version, filename, downloadURL, nil) } // GetOrFetchArtifactFromURLWithHeaders retrieves an artifact from cache or fetches from a URL -// with additional request-specific HTTP headers. +// with additional HTTP headers. This is needed for registries that require authentication +// (e.g. Docker Hub requires a Bearer token even for public images). func (p *Proxy) GetOrFetchArtifactFromURLWithHeaders(ctx context.Context, ecosystem, name, version, filename, downloadURL string, headers http.Header) (*CacheResult, error) { - return p.getOrFetchArtifactFromURL(ctx, ecosystem, name, version, filename, downloadURL, headers, "") -} + pkgPURL := purl.MakePURLString(ecosystem, name, "") + versionPURL := purl.MakePURLString(ecosystem, name, version) -// GetOrFetchArtifactFromURLWithDigest retrieves an artifact and verifies its -// SHA-256 digest before adding a newly fetched response to the cache. -// Non-sha256 digests are proxied without verification. -func (p *Proxy) GetOrFetchArtifactFromURLWithDigest(ctx context.Context, ecosystem, name, version, filename, downloadURL, digest string) (*CacheResult, error) { - upstreamHash, _ := strings.CutPrefix(digest, "sha256:") - if upstreamHash == digest { - upstreamHash = "" - } - return p.getOrFetchArtifactFromURL(ctx, ecosystem, name, version, filename, downloadURL, nil, upstreamHash) -} - -func (p *Proxy) getOrFetchArtifactFromURL(ctx context.Context, ecosystem, name, version, filename, downloadURL string, headers http.Header, upstreamHash string) (*CacheResult, error) { - pkgPURL, versionPURL, err := packagePURLStrings(ecosystem, name, version) - if err != nil { - return nil, err - } - return p.getOrFetchArtifactFromURLWithCachePURLs( - ctx, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL, headers, upstreamHash, - ) -} - -func (p *Proxy) getOrFetchArtifactFromURLWithCachePURLs(ctx context.Context, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL string, headers http.Header, upstreamHash string) (*CacheResult, error) { - if cached, err := p.getCachedArtifactWithUpstreamHash(ctx, pkgPURL, versionPURL, filename, upstreamHash); err != nil { + if cached, err := p.checkCache(ctx, pkgPURL, versionPURL, filename); err != nil { return nil, err } else if cached != nil { return cached, nil } - metrics.RecordCacheMiss(ecosystem) - return p.coalescedFetchFromURL(ctx, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL, headers, upstreamHash) + + return p.fetchAndCacheFromURL(ctx, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL, headers) } -// coalescedFetchFromURL fetches an artifact the cache could not serve, sharing -// the fetch with concurrent callers. The caller running it discards a stale -// entry under the key, where it cannot delete a fetch that just replaced it. -func (p *Proxy) coalescedFetchFromURL(ctx context.Context, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL string, headers http.Header, upstreamHash string) (*CacheResult, error) { - key := artifactCoalesceKey(versionPURL, filename, downloadURL, upstreamHash) - recheck := func() (artifacts.Artifact, string, bool) { - return p.cachedArtifactRecord(pkgPURL, versionPURL, filename, upstreamHash) - } - return p.coalesceFetch(ctx, key, recheck, func(fetchCtx context.Context) (artifacts.Artifact, string, error) { - p.discardStaleArtifact(fetchCtx, pkgPURL, versionPURL, filename, upstreamHash) - return p.fetchAndCacheFromURL(fetchCtx, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL, headers, upstreamHash) - }) -} - -// getCachedArtifactWithUpstreamHash returns a cached artifact whose recorded -// content hash matches the checksum the upstream currently declares for it. -// This detects an upstream re-publishing under the same version, which the -// stream integrity check in checkCache cannot: that check only verifies the -// stored blob against the hash recorded when it was cached. A stale entry is -// a miss and is left in place: the fetch that replaces it discards it under -// the coalescing key. -func (p *Proxy) getCachedArtifactWithUpstreamHash(ctx context.Context, pkgPURL, versionPURL, filename, upstreamHash string) (*CacheResult, error) { - cached, err := p.checkCache(ctx, pkgPURL, versionPURL, filename) - if err != nil || cached == nil { - return cached, err - } - if artifactHashMatches(cached.Artifact.Digest.Encoded(), upstreamHash) { - return cached, nil - } - if cached.Reader != nil { - _ = cached.Reader.Close() - } - return nil, nil -} - -// discardStaleArtifact removes the cached entry when its digest disagrees -// with upstreamHash. It runs under the coalescing key, after the recheck, so -// an entry a previous fetch refreshed is kept. -func (p *Proxy) discardStaleArtifact(ctx context.Context, pkgPURL, versionPURL, filename, upstreamHash string) { - record, err := p.DB.GetCachedArtifact(pkgPURL, versionPURL, filename) - if err != nil { - p.Logger.Warn("failed to read cache record before refetch", - "purl", versionPURL, "filename", filename, "error", err) - return - } - if record == nil || artifactHashMatches(record.Artifact.Digest.Encoded(), upstreamHash) { - return - } - p.Logger.Warn("cached artifact hash disagrees with upstream metadata, discarding", - "purl", versionPURL, "filename", filename, "cached", record.Artifact.Digest.Encoded(), "upstream", upstreamHash) - p.discardCachedArtifact(ctx, versionPURL, filename, record.StoragePath) -} - -func (p *Proxy) fetchAndCacheFromURL(ctx context.Context, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL string, headers http.Header, upstreamHash string) (artifacts.Artifact, string, error) { +func (p *Proxy) fetchAndCacheFromURL(ctx context.Context, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL string, headers http.Header) (*CacheResult, error) { p.Logger.Info("fetching from upstream", "ecosystem", ecosystem, "name", name, "version", version, "url", downloadURL) - fetchStart := time.Now() artifact, err := p.Fetcher.FetchWithHeaders(ctx, downloadURL, headers) - metrics.RecordUpstreamFetch(ecosystem, time.Since(fetchStart)) if err != nil { - metrics.RecordUpstreamError(ecosystem, "fetch_failed") - if errors.Is(err, fetch.ErrNotFound) { - return artifacts.Artifact{}, "", ErrUpstreamNotFound - } - return artifacts.Artifact{}, "", fmt.Errorf("fetching from upstream: %w", err) + return nil, fmt.Errorf("fetching from upstream: %w", err) } - return p.storeArtifact(ctx, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL, upstreamHash, artifact) -} - -// ErrArtifactDigestMismatch indicates that fetched bytes did not match the -// checksum the upstream declared and were not recorded in the cache database. -var ErrArtifactDigestMismatch = errors.New("artifact digest mismatch") - -func artifactHashMatches(got, expected string) bool { - return expected == "" || strings.EqualFold(got, expected) -} - -func (p *Proxy) discardCachedArtifact(ctx context.Context, versionPURL, filename, storagePath string) { - if storagePath != "" { - if err := p.Storage.Delete(ctx, storagePath); err != nil { - p.Logger.Warn("failed to discard cached artifact", "path", storagePath, "error", err) - } + storagePath := storage.ArtifactPath(ecosystem, "", name, version, filename) + size, hash, err := p.Storage.Store(ctx, storagePath, artifact.Body) + _ = artifact.Body.Close() + if err != nil { + return nil, fmt.Errorf("storing artifact: %w", err) } - if err := p.DB.ClearArtifactCache(versionPURL, filename); err != nil { - p.Logger.Warn("failed to clear artifact cache record", "purl", versionPURL, "filename", filename, "error", err) + + if err := p.updateCacheDB(ecosystem, name, filename, pkgPURL, versionPURL, downloadURL, storagePath, hash, size, artifact.ContentType); err != nil { + p.Logger.Warn("failed to update cache database", "error", err) } + + reader, err := p.Storage.Open(ctx, storagePath) + if err != nil { + return nil, fmt.Errorf("opening cached artifact: %w", err) + } + + return &CacheResult{ + Reader: reader, + Size: size, + ContentType: artifact.ContentType, + Hash: hash, + Cached: false, + }, nil } + diff --git a/internal/handler/handler_bench_test.go b/internal/handler/handler_bench_test.go deleted file mode 100644 index cdbb524..0000000 --- a/internal/handler/handler_bench_test.go +++ /dev/null @@ -1,300 +0,0 @@ -package handler - -import ( - "bytes" - "context" - "crypto/sha256" - "database/sql" - "encoding/hex" - "fmt" - "io" - "log/slog" - "net/http" - "net/http/httptest" - "path/filepath" - "strings" - "testing" - "time" - - "github.com/git-pkgs/proxy/internal/database" - "github.com/git-pkgs/proxy/internal/storage" - "github.com/git-pkgs/purl" - "github.com/git-pkgs/registries/fetch" -) - -const benchmarkArtifactSize = 64 << 10 - -const benchmarkMetadataSize = 1 << 20 - -type benchmarkResponseWriter struct { - header http.Header -} - -func (w *benchmarkResponseWriter) Header() http.Header { - return w.header -} - -func (w *benchmarkResponseWriter) Write(p []byte) (int, error) { - return len(p), nil -} - -func (w *benchmarkResponseWriter) WriteHeader(_ int) {} - -func benchmarkCachedProxy(b *testing.B) (*Proxy, *mockStorage) { - b.Helper() - - proxy, db, store, _ := setupTestProxy(b) - content := strings.Repeat("x", benchmarkArtifactSize) - seedPackage(b, db, store, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz", content) - - artifact, err := db.GetArtifact("pkg:npm/lodash@4.17.21", "lodash-4.17.21.tgz") - if err != nil { - b.Fatalf("get seeded artifact: %v", err) - } - sum := sha256.Sum256([]byte(content)) - artifact.ContentHash.String = hex.EncodeToString(sum[:]) - if err := db.UpsertArtifact(artifact); err != nil { - b.Fatalf("update seeded artifact hash: %v", err) - } - - return proxy, store -} - -func BenchmarkArtifactCacheHit(b *testing.B) { - ctx := context.Background() - - b.Run("stream-64KiB", func(b *testing.B) { - proxy, _ := benchmarkCachedProxy(b) - w := &benchmarkResponseWriter{header: make(http.Header)} - b.SetBytes(benchmarkArtifactSize) - b.ReportAllocs() - b.ResetTimer() - - for b.Loop() { - result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz") - if err != nil { - b.Fatal(err) - } - ServeArtifact(w, result) - } - }) - - b.Run("direct-serve", func(b *testing.B) { - proxy, store := benchmarkCachedProxy(b) - proxy.DirectServe = true - store.signedURL = "https://storage.example/npm/lodash-4.17.21.tgz?signature=abc" - w := &benchmarkResponseWriter{header: make(http.Header)} - b.ReportAllocs() - b.ResetTimer() - - for b.Loop() { - result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz") - if err != nil { - b.Fatal(err) - } - ServeArtifact(w, result) - } - }) -} - -func BenchmarkArtifactCacheHitParallel(b *testing.B) { - proxy, _ := benchmarkCachedProxy(b) - ctx := context.Background() - b.SetBytes(benchmarkArtifactSize) - b.ReportAllocs() - b.ResetTimer() - - b.RunParallel(func(pb *testing.PB) { - w := &benchmarkResponseWriter{header: make(http.Header)} - for pb.Next() { - result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz") - if err != nil { - b.Error(err) - return - } - ServeArtifact(w, result) - } - }) -} - -func BenchmarkReadMetadata(b *testing.B) { - payload := bytes.Repeat([]byte("x"), benchmarkMetadataSize) - proxy := &Proxy{MetadataMaxSize: benchmarkMetadataSize} - b.SetBytes(benchmarkMetadataSize) - b.ReportAllocs() - - var data []byte - for b.Loop() { - var err error - data, err = proxy.ReadMetadata(bytes.NewReader(payload)) - if err != nil { - b.Fatal(err) - } - } - if len(data) != len(payload) { - b.Fatalf("metadata size = %d, want %d", len(data), len(payload)) - } -} - -func BenchmarkArtifactPURLConstruction(b *testing.B) { - for _, tc := range []struct { - name string - ecosystem string - packageID string - }{ - {"npm", "npm", "lodash"}, - {"scoped-npm", "npm", "@scope/package"}, - {"go", "golang", "github.com/git-pkgs/proxy"}, - } { - b.Run(tc.name, func(b *testing.B) { - b.ReportAllocs() - var packagePURL, versionPURL string - for b.Loop() { - packagePURL = purl.MakePURLString(tc.ecosystem, tc.packageID, "") - versionPURL = purl.MakePURLString(tc.ecosystem, tc.packageID, "1.2.3") - } - if packagePURL == "" || versionPURL == "" { - b.Fatal("empty PURL") - } - }) - } -} - -type benchmarkNPMServer struct { - client *http.Client - requestURL string - db *database.DB - versionPURL string - filename string -} - -func newBenchmarkNPMServer(b *testing.B) *benchmarkNPMServer { - b.Helper() - - ctx := context.Background() - dir := b.TempDir() - db, err := database.Create(filepath.Join(dir, "benchmark.db")) - if err != nil { - b.Fatalf("create database: %v", err) - } - b.Cleanup(func() { _ = db.Close() }) - - store, err := storage.OpenBucket(ctx, "file://"+filepath.Join(dir, "cache")) - if err != nil { - b.Fatalf("open storage: %v", err) - } - b.Cleanup(func() { _ = store.Close() }) - - content := bytes.Repeat([]byte("x"), benchmarkArtifactSize) - storagePath := storage.ArtifactPath("npm", "", "lodash", "4.17.21", "lodash-4.17.21.tgz") - size, hash, err := store.Store(ctx, storagePath, bytes.NewReader(content)) - if err != nil { - b.Fatalf("store artifact: %v", err) - } - - pkg := &database.Package{PURL: "pkg:npm/lodash", Ecosystem: "npm", Name: "lodash"} - if err := db.UpsertPackage(pkg); err != nil { - b.Fatalf("seed package: %v", err) - } - version := &database.Version{PURL: "pkg:npm/lodash@4.17.21", PackagePURL: pkg.PURL} - if err := db.UpsertVersion(version); err != nil { - b.Fatalf("seed version: %v", err) - } - artifact := &database.Artifact{ - VersionPURL: version.PURL, - Filename: "lodash-4.17.21.tgz", - UpstreamURL: "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz", - StoragePath: sql.NullString{String: storagePath, Valid: true}, - ContentHash: sql.NullString{String: hash, Valid: true}, - Size: sql.NullInt64{Int64: size, Valid: true}, - ContentType: sql.NullString{String: "application/gzip", Valid: true}, - FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, - } - if err := db.UpsertArtifact(artifact); err != nil { - b.Fatalf("seed artifact: %v", err) - } - - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - proxy := NewProxy(db, store, &mockFetcher{}, fetch.NewResolver(), logger) - handler := NewNPMHandler(proxy, "http://proxy.example", "https://registry.npmjs.org") - server := httptest.NewServer(handler.Routes()) - b.Cleanup(server.Close) - client := server.Client() - return &benchmarkNPMServer{ - client: client, - requestURL: server.URL + "/lodash/-/lodash-4.17.21.tgz", - db: db, - versionPURL: version.PURL, - filename: artifact.Filename, - } -} - -func (s *benchmarkNPMServer) request() error { - resp, err := s.client.Get(s.requestURL) - if err != nil { - return fmt.Errorf("GET cached artifact: %w", err) - } - defer func() { _ = resp.Body.Close() }() - if resp.StatusCode != http.StatusOK { - return fmt.Errorf("GET cached artifact status = %d, want %d", resp.StatusCode, http.StatusOK) - } - n, err := io.Copy(io.Discard, resp.Body) - if err != nil { - return fmt.Errorf("read cached artifact: %w", err) - } - if n != benchmarkArtifactSize { - return fmt.Errorf("cached artifact size = %d, want %d", n, benchmarkArtifactSize) - } - return nil -} - -func (s *benchmarkNPMServer) hitCount(b *testing.B) int64 { - b.Helper() - artifact, err := s.db.GetArtifact(s.versionPURL, s.filename) - if err != nil { - b.Fatalf("get artifact hit count: %v", err) - } - return artifact.HitCount -} - -func benchmarkNPMArtifactCacheHitHTTP(b *testing.B, parallel bool) { - server := newBenchmarkNPMServer(b) - if err := server.request(); err != nil { - b.Fatal(err) - } - startHits := server.hitCount(b) - - b.SetBytes(benchmarkArtifactSize) - b.ReportAllocs() - b.ResetTimer() - if parallel { - b.RunParallel(func(pb *testing.PB) { - for pb.Next() { - if err := server.request(); err != nil { - b.Error(err) - return - } - } - }) - } else { - for b.Loop() { - if err := server.request(); err != nil { - b.Fatal(err) - } - } - } - b.StopTimer() - - if hitCount := server.hitCount(b) - startHits; hitCount != int64(b.N) { - b.Fatalf("new artifact hits = %d, want %d", hitCount, b.N) - } - b.ReportMetric(float64(b.N)/b.Elapsed().Seconds(), "requests/s") -} - -func BenchmarkNPMArtifactCacheHitHTTP(b *testing.B) { - benchmarkNPMArtifactCacheHitHTTP(b, false) -} - -func BenchmarkNPMArtifactCacheHitHTTPParallel(b *testing.B) { - benchmarkNPMArtifactCacheHitHTTP(b, true) -} diff --git a/internal/handler/handler_test.go b/internal/handler/handler_test.go index b632294..78ed415 100644 --- a/internal/handler/handler_test.go +++ b/internal/handler/handler_test.go @@ -3,39 +3,27 @@ package handler import ( "bytes" "context" - "crypto/sha256" "database/sql" "errors" + "fmt" "io" "log/slog" "net/http" "net/http/httptest" "strings" - "sync" "testing" "time" - "github.com/git-pkgs/artifacts" - "github.com/git-pkgs/proxy/internal/config" "github.com/git-pkgs/proxy/internal/database" - "github.com/git-pkgs/proxy/internal/metrics" "github.com/git-pkgs/proxy/internal/storage" - "github.com/git-pkgs/purl" "github.com/git-pkgs/registries/fetch" - "github.com/opencontainers/go-digest" - "github.com/prometheus/client_golang/prometheus" - "github.com/prometheus/client_golang/prometheus/testutil" - dto "github.com/prometheus/client_model/go" ) // mockStorage implements storage.Storage for testing. type mockStorage struct { - mu sync.Mutex - files map[string][]byte - storeErr error - openErr error - signedURL string - signErr error + files map[string][]byte + storeErr error + openErr error } func newMockStorage() *mockStorage { @@ -43,8 +31,6 @@ func newMockStorage() *mockStorage { } func (s *mockStorage) Store(_ context.Context, path string, r io.Reader) (int64, string, error) { - s.mu.Lock() - defer s.mu.Unlock() if s.storeErr != nil { return 0, "", s.storeErr } @@ -53,12 +39,10 @@ func (s *mockStorage) Store(_ context.Context, path string, r io.Reader) (int64, return 0, "", err } s.files[path] = data - return int64(len(data)), sha256Hex(string(data)), nil + return int64(len(data)), "fakehash123", nil } func (s *mockStorage) Open(_ context.Context, path string) (io.ReadCloser, error) { - s.mu.Lock() - defer s.mu.Unlock() if s.openErr != nil { return nil, s.openErr } @@ -70,28 +54,16 @@ func (s *mockStorage) Open(_ context.Context, path string) (io.ReadCloser, error } func (s *mockStorage) Exists(_ context.Context, path string) (bool, error) { - s.mu.Lock() - defer s.mu.Unlock() _, ok := s.files[path] return ok, nil } -func (s *mockStorage) Delete(ctx context.Context, path string) error { - // Real backends (S3/GCS SDKs) fail fast on an already-cancelled - // context; mirror that here so tests can catch cleanup calls that - // forgot to detach from a cancelled client context. - if err := ctx.Err(); err != nil { - return err - } - s.mu.Lock() - defer s.mu.Unlock() +func (s *mockStorage) Delete(_ context.Context, path string) error { delete(s.files, path) return nil } func (s *mockStorage) Size(_ context.Context, path string) (int64, error) { - s.mu.Lock() - defer s.mu.Unlock() data, ok := s.files[path] if !ok { return 0, storage.ErrNotFound @@ -100,8 +72,6 @@ func (s *mockStorage) Size(_ context.Context, path string) (int64, error) { } func (s *mockStorage) UsedSpace(_ context.Context) (int64, error) { - s.mu.Lock() - defer s.mu.Unlock() var total int64 for _, data := range s.files { total += int64(len(data)) @@ -109,49 +79,25 @@ func (s *mockStorage) UsedSpace(_ context.Context) (int64, error) { return total, nil } -func (s *mockStorage) SignedURL(_ context.Context, _ string, _ time.Duration) (string, error) { - if s.signErr != nil { - return "", s.signErr - } - if s.signedURL == "" { - return "", storage.ErrSignedURLUnsupported - } - return s.signedURL, nil -} - func (s *mockStorage) URL() string { return "mem://" } func (s *mockStorage) Close() error { return nil } -// mockFetcher implements fetch.FetcherInterface for testing. Recording is -// locked because coalescing tests call the handler from many goroutines; tests -// read the recorded fields only after those calls have returned. +// mockFetcher implements fetch.FetcherInterface for testing. type mockFetcher struct { - artifact *fetch.Artifact - fetchErr error - fetchErrByURL map[string]error - - mu sync.Mutex - fetchCalled bool - fetchedURL string - fetchedHeader http.Header + artifact *fetch.Artifact + fetchErr error + fetchCalled bool + fetchedURL string } func (f *mockFetcher) Fetch(ctx context.Context, url string) (*fetch.Artifact, error) { return f.FetchWithHeaders(ctx, url, nil) } -func (f *mockFetcher) FetchWithHeaders(_ context.Context, url string, headers http.Header) (*fetch.Artifact, error) { - f.mu.Lock() +func (f *mockFetcher) FetchWithHeaders(_ context.Context, url string, _ http.Header) (*fetch.Artifact, error) { f.fetchCalled = true f.fetchedURL = url - f.fetchedHeader = headers.Clone() - f.mu.Unlock() - if f.fetchErrByURL != nil { - if err, ok := f.fetchErrByURL[url]; ok { - return nil, err - } - } if f.fetchErr != nil { return nil, f.fetchErr } @@ -163,7 +109,7 @@ func (f *mockFetcher) Head(_ context.Context, _ string) (int64, string, error) { } // setupTestProxy creates a Proxy with a real DB (SQLite in temp dir) and mock storage/fetcher. -func setupTestProxy(t testing.TB) (*Proxy, *database.DB, *mockStorage, *mockFetcher) { +func setupTestProxy(t *testing.T) (*Proxy, *database.DB, *mockStorage, *mockFetcher) { t.Helper() dir := t.TempDir() @@ -182,35 +128,12 @@ func setupTestProxy(t testing.TB) (*Proxy, *database.DB, *mockStorage, *mockFetc return proxy, db, store, fetcher } -func histogramSampleCount(t testing.TB, observer prometheus.Observer) uint64 { - t.Helper() - metric, ok := observer.(prometheus.Metric) - if !ok { - t.Fatal("observer does not implement prometheus.Metric") - } - value := &dto.Metric{} - if err := metric.Write(value); err != nil { - t.Fatalf("writing Prometheus metric: %v", err) - } - return value.GetHistogram().GetSampleCount() -} - -func testArtifact(content, packageURL, filename, mediaType string) artifacts.Artifact { - return artifacts.Artifact{ - PURL: packageURL, - Digest: digest.Digest("sha256:" + sha256Hex(content)), - Size: int64(len(content)), - Filename: filename, - MediaType: mediaType, - } -} - // seedPackage creates a package, version, and cached artifact in the test DB and storage. -func seedPackage(t testing.TB, db *database.DB, store *mockStorage, ecosystem, name, version, filename, content string) { +func seedPackage(t *testing.T, db *database.DB, store *mockStorage, ecosystem, name, version, filename, content string) { t.Helper() pkg := &database.Package{ - PURL: purl.MakePURLString(ecosystem, name, ""), + PURL: fmt.Sprintf("pkg:%s/%s", ecosystem, name), Ecosystem: ecosystem, Name: name, } @@ -218,7 +141,7 @@ func seedPackage(t testing.TB, db *database.DB, store *mockStorage, ecosystem, n t.Fatalf("failed to upsert package: %v", err) } - versionPURL := purl.MakePURLString(ecosystem, name, version) + versionPURL := fmt.Sprintf("pkg:%s/%s@%s", ecosystem, name, version) ver := &database.Version{ PURL: versionPURL, PackagePURL: pkg.PURL, @@ -229,14 +152,13 @@ func seedPackage(t testing.TB, db *database.DB, store *mockStorage, ecosystem, n storagePath := storage.ArtifactPath(ecosystem, "", name, version, filename) store.files[storagePath] = []byte(content) - sharedArtifact := testArtifact(content, versionPURL, filename, "application/octet-stream") art := &database.Artifact{ VersionPURL: versionPURL, Filename: filename, UpstreamURL: "https://example.com/" + filename, StoragePath: sql.NullString{String: storagePath, Valid: true}, - ContentHash: sql.NullString{String: sharedArtifact.Digest.Encoded(), Valid: true}, + ContentHash: sql.NullString{String: "abc123", Valid: true}, Size: sql.NullInt64{Int64: int64(len(content)), Valid: true}, ContentType: sql.NullString{String: "application/octet-stream", Valid: true}, FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, @@ -322,83 +244,16 @@ func TestGetOrFetchArtifact_CacheHit(t *testing.T) { if string(body) != "cached content" { t.Errorf("got body %q, want %q", body, "cached content") } - if result.Artifact.MediaType != "application/octet-stream" { - t.Errorf("got content type %q, want %q", result.Artifact.MediaType, "application/octet-stream") + if result.ContentType != "application/octet-stream" { + t.Errorf("got content type %q, want %q", result.ContentType, "application/octet-stream") } - if result.Artifact.Digest.Encoded() != sha256Hex("cached content") { - t.Errorf("got digest %q, want %q", result.Artifact.Digest.Encoded(), sha256Hex("cached content")) - } -} - -func TestGetCachedArtifactRejectsMalformedIntegrityMetadata(t *testing.T) { - tests := []struct { - name string - malformedHash string - malformedIntegrity string - }{ - {name: "content hash", malformedHash: "abc123"}, - {name: "native integrity", malformedIntegrity: "sha512-abc123"}, - } - for _, test := range tests { - t.Run(test.name, func(t *testing.T) { - assertMalformedCacheRejected(t, test.malformedHash, test.malformedIntegrity) - }) - } -} - -func assertMalformedCacheRejected(t *testing.T, malformedHash, malformedIntegrity string) { - t.Helper() - proxy, db, store, _ := setupTestProxy(t) - const ( - packageName = "broken" - version = "1.0.0" - filename = "broken-1.0.0.tgz" - ) - seedPackage(t, db, store, "npm", packageName, version, filename, "cached content") - versionPURL := purl.MakePURLString("npm", packageName, version) - - if malformedHash != "" { - artifact, err := db.GetArtifact(versionPURL, filename) - if err != nil { - t.Fatal(err) - } - artifact.ContentHash = sql.NullString{String: malformedHash, Valid: true} - if err := db.UpsertArtifact(artifact); err != nil { - t.Fatal(err) - } - } - if malformedIntegrity != "" { - versionRecord := &database.Version{ - PURL: versionPURL, - PackagePURL: purl.MakePURLString("npm", packageName, ""), - Integrity: sql.NullString{String: malformedIntegrity, Valid: true}, - } - if err := db.UpsertVersion(versionRecord); err != nil { - t.Fatal(err) - } - } - - proxy.DirectServe = true - store.signedURL = "https://cache.example/broken" - result, err := proxy.GetCachedArtifact(context.Background(), "npm", packageName, version, filename) - if err != nil { - t.Fatalf("GetCachedArtifact: %v", err) - } - if result != nil { - t.Errorf("GetCachedArtifact = %+v, want nil", result) - } - artifact, err := db.GetArtifact(versionPURL, filename) - if err != nil { - t.Fatal(err) - } - if artifact.StoragePath.Valid { - t.Error("unusable cache record retained its storage path") + if result.Hash != "abc123" { + t.Errorf("got hash %q, want %q", result.Hash, "abc123") } } func TestGetOrFetchArtifact_CacheMiss_NoPackage(t *testing.T) { proxy, _, _, fetcher := setupTestProxy(t) - missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("npm")) // The resolver will fail because "nonexistent" isn't a real package, // but we're testing that it tries to fetch (doesn't return from cache). @@ -408,10 +263,6 @@ func TestGetOrFetchArtifact_CacheMiss_NoPackage(t *testing.T) { if err == nil { t.Fatal("expected error for uncached package") } - missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("npm")) - if diff := missesAfter - missesBefore; diff != 1 { - t.Errorf("cache misses delta = %.0f, want 1", diff) - } } func TestGetOrFetchArtifactFromURL_CacheMiss_StorageMissing(t *testing.T) { @@ -427,7 +278,7 @@ func TestGetOrFetchArtifactFromURL_CacheMiss_StorageMissing(t *testing.T) { Filename: "missing-1.0.0.tgz", UpstreamURL: "https://example.com/missing.tgz", StoragePath: sql.NullString{String: "nonexistent/path.tgz", Valid: true}, - ContentHash: sql.NullString{String: sha256Hex("missing content"), Valid: true}, + ContentHash: sql.NullString{String: "hash", Valid: true}, Size: sql.NullInt64{Int64: 100, Valid: true}, ContentType: sql.NullString{String: "application/octet-stream", Valid: true}, FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, @@ -460,244 +311,9 @@ func TestGetOrFetchArtifactFromURL_CacheMiss_StorageMissing(t *testing.T) { } } -func TestArtifactCacheRejectsUnsupportedPackageIdentity(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - - _, err := proxy.GetCachedArtifact( - context.Background(), "swift", "apple/example", "1.2.3", "example-1.2.3.zip", - ) - if !errors.Is(err, errUnsupportedPackageIdentity) { - t.Fatalf("GetCachedArtifact() error = %v, want unsupported package identity", err) - } - - _, err = proxy.GetOrFetchArtifactFromURL( - context.Background(), "swift", "apple/example", "1.2.3", "example-1.2.3.zip", - "https://registry.example/apple/example/1.2.3.zip", - ) - if !errors.Is(err, errUnsupportedPackageIdentity) { - t.Fatalf("GetOrFetchArtifactFromURL() error = %v, want unsupported package identity", err) - } - if fetcher.fetchCalled { - t.Error("unsupported package identity reached the artifact fetcher") - } -} - -func TestGetOrFetchArtifact_DirectServe_Redirect(t *testing.T) { - proxy, db, store, fetcher := setupTestProxy(t) - seedPackage(t, db, store, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz", "cached content") - - proxy.DirectServe = true - proxy.DirectServeTTL = 15 * time.Minute - store.signedURL = "https://bucket.s3.amazonaws.com/npm/lodash?X-Amz-Signature=abc" - - result, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz") - if err != nil { - t.Fatalf("unexpected error: %v", err) - } - - if !result.Cached { - t.Error("expected result to be cached") - } - if result.RedirectURL != store.signedURL { - t.Errorf("RedirectURL = %q, want %q", result.RedirectURL, store.signedURL) - } - if result.Reader != nil { - t.Error("Reader should be nil when redirecting") - } - if fetcher.fetchCalled { - t.Error("fetcher should not be called on cache hit") - } - - // Hit count should still be recorded on the redirect path. - art, _ := db.GetArtifact("pkg:npm/lodash@4.17.21", "lodash-4.17.21.tgz") - if art == nil || art.HitCount != 1 { - t.Errorf("artifact hit count not recorded: %+v", art) - } -} - -func TestGetOrFetchArtifact_DirectServe_BaseURLRewrite(t *testing.T) { - proxy, db, store, _ := setupTestProxy(t) - seedPackage(t, db, store, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz", "cached content") - - proxy.DirectServe = true - proxy.DirectServeBaseURL = "https://cdn.example.com" - store.signedURL = "http://127.0.0.1:9000/bucket/npm/lodash?X-Amz-Signature=abc&X-Amz-Expires=900" - - result, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz") - if err != nil { - t.Fatalf("unexpected error: %v", err) - } - - want := "https://cdn.example.com/bucket/npm/lodash?X-Amz-Signature=abc&X-Amz-Expires=900" - if result.RedirectURL != want { - t.Errorf("RedirectURL = %q, want %q", result.RedirectURL, want) - } -} - -func TestRewriteSignedURLHost(t *testing.T) { - tests := []struct { - name string - signed string - baseURL string - want string - }{ - { - "empty base url is no-op", - "http://127.0.0.1:9000/bucket/key?sig=abc", - "", - "http://127.0.0.1:9000/bucket/key?sig=abc", - }, - { - "replaces scheme and host", - "http://127.0.0.1:9000/bucket/key?sig=abc", - "https://cdn.example.com", - "https://cdn.example.com/bucket/key?sig=abc", - }, - { - "preserves path and query", - "http://minio:9000/bucket/npm/lodash/4.17.21/lodash.tgz?X-Amz-Signature=abc&X-Amz-Date=20260101", - "https://files.example.com", - "https://files.example.com/bucket/npm/lodash/4.17.21/lodash.tgz?X-Amz-Signature=abc&X-Amz-Date=20260101", - }, - { - "ignores base url path", - "http://127.0.0.1:9000/bucket/key?sig=abc", - "https://cdn.example.com/ignored", - "https://cdn.example.com/bucket/key?sig=abc", - }, - { - "invalid base url is no-op", - "http://127.0.0.1:9000/bucket/key?sig=abc", - "://bad", - "http://127.0.0.1:9000/bucket/key?sig=abc", - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - got := rewriteSignedURLHost(tt.signed, tt.baseURL) - if got != tt.want { - t.Errorf("rewriteSignedURLHost(%q, %q) = %q, want %q", tt.signed, tt.baseURL, got, tt.want) - } - }) - } -} - -func TestGetOrFetchArtifact_DirectServe_FallbackOnUnsupported(t *testing.T) { - proxy, db, store, _ := setupTestProxy(t) - seedPackage(t, db, store, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz", "cached content") - - proxy.DirectServe = true - // store.signedURL is empty so SignedURL returns ErrSignedURLUnsupported. - - result, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz") - if err != nil { - t.Fatalf("unexpected error: %v", err) - } - defer func() { _ = result.Reader.Close() }() - - if result.RedirectURL != "" { - t.Errorf("RedirectURL should be empty, got %q", result.RedirectURL) - } - if result.Reader == nil { - t.Fatal("Reader should be set when signing is unsupported") - } - body, _ := io.ReadAll(result.Reader) - if string(body) != "cached content" { - t.Errorf("got body %q, want %q", body, "cached content") - } -} - -func TestGetOrFetchArtifact_DirectServe_FallbackOnError(t *testing.T) { - proxy, db, store, _ := setupTestProxy(t) - seedPackage(t, db, store, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz", "cached content") - - proxy.DirectServe = true - store.signErr = errors.New("signing failed") - - result, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz") - if err != nil { - t.Fatalf("unexpected error: %v", err) - } - defer func() { _ = result.Reader.Close() }() - - if result.RedirectURL != "" { - t.Errorf("RedirectURL should be empty on signing error, got %q", result.RedirectURL) - } - if result.Reader == nil { - t.Fatal("Reader should be set when signing fails") - } -} - -func TestGetOrFetchArtifact_DirectServe_DisabledIgnoresSigning(t *testing.T) { - proxy, db, store, _ := setupTestProxy(t) - seedPackage(t, db, store, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz", "cached content") - - proxy.DirectServe = false - store.signedURL = "https://bucket.example/should-not-be-used" - - result, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz") - if err != nil { - t.Fatalf("unexpected error: %v", err) - } - defer func() { _ = result.Reader.Close() }() - - if result.RedirectURL != "" { - t.Errorf("RedirectURL should be empty when DirectServe is off, got %q", result.RedirectURL) - } -} - -func TestServeArtifact_Redirect(t *testing.T) { - w := httptest.NewRecorder() - ServeArtifact(w, &CacheResult{ - RedirectURL: "https://bucket.s3.amazonaws.com/file?sig=abc", - Artifact: artifacts.Artifact{ - Digest: digest.Digest("sha256:" + strings.Repeat("a", sha256.Size*2)), - }, - Cached: true, - }) - - if w.Code != http.StatusFound { - t.Errorf("status = %d, want %d", w.Code, http.StatusFound) - } - if loc := w.Header().Get("Location"); loc != "https://bucket.s3.amazonaws.com/file?sig=abc" { - t.Errorf("Location = %q", loc) - } - if etag := w.Header().Get("ETag"); etag != `"`+strings.Repeat("a", sha256.Size*2)+`"` { - t.Errorf("ETag = %q", etag) - } - if cl := w.Header().Get("Content-Length"); cl != "" { - t.Errorf("Content-Length should not be set on redirect, got %q", cl) - } -} - -func TestServeArtifact_Stream(t *testing.T) { - w := httptest.NewRecorder() - ServeArtifact(w, &CacheResult{ - Reader: io.NopCloser(strings.NewReader("payload")), - Artifact: testArtifact( - "payload", - "pkg:npm/example@1.0.0", - "example.tgz", - "application/octet-stream", - ), - }) - - if w.Code != http.StatusOK { - t.Errorf("status = %d, want %d", w.Code, http.StatusOK) - } - if w.Body.String() != "payload" { - t.Errorf("body = %q, want %q", w.Body.String(), "payload") - } - if ct := w.Header().Get("Content-Type"); ct != "application/octet-stream" { - t.Errorf("Content-Type = %q", ct) - } -} - func TestGetOrFetchArtifactFromURL_CacheHit(t *testing.T) { proxy, db, store, fetcher := setupTestProxy(t) seedPackage(t, db, store, "pypi", "requests", "2.28.0", "requests-2.28.0.tar.gz", "pypi content") - missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi")) result, err := proxy.GetOrFetchArtifactFromURL(context.Background(), "pypi", "requests", "2.28.0", "requests-2.28.0.tar.gz", "https://pypi.org/files/requests-2.28.0.tar.gz") if err != nil { @@ -711,18 +327,10 @@ func TestGetOrFetchArtifactFromURL_CacheHit(t *testing.T) { if fetcher.fetchCalled { t.Error("fetcher should not be called on cache hit") } - missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi")) - if diff := missesAfter - missesBefore; diff != 0 { - t.Errorf("cache misses delta = %.0f, want 0", diff) - } } func TestGetOrFetchArtifactFromURL_CacheMiss(t *testing.T) { proxy, _, store, fetcher := setupTestProxy(t) - missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi")) - fetchesBefore := histogramSampleCount(t, metrics.UpstreamFetchDuration.WithLabelValues("pypi")) - writesBefore := histogramSampleCount(t, metrics.StorageOperationDuration.WithLabelValues("write")) - readsBefore := histogramSampleCount(t, metrics.StorageOperationDuration.WithLabelValues("read")) fetcher.artifact = &fetch.Artifact{ Body: io.NopCloser(strings.NewReader("fetched content")), @@ -749,43 +357,17 @@ func TestGetOrFetchArtifactFromURL_CacheMiss(t *testing.T) { if string(body) != "fetched content" { t.Errorf("got body %q, want %q", body, "fetched content") } - if err := result.Artifact.Validate(); err != nil { - t.Errorf("Artifact.Validate() error = %v", err) - } - if result.Artifact.PURL != "pkg:pypi/newpkg@1.0.0" { - t.Errorf("PURL = %q", result.Artifact.PURL) - } - if result.Artifact.Size != int64(len("fetched content")) { - t.Errorf("Size = %d", result.Artifact.Size) - } - if result.Artifact.MediaType != "application/gzip" { - t.Errorf("MediaType = %q", result.Artifact.MediaType) - } // Verify it was stored storagePath := storage.ArtifactPath("pypi", "", "newpkg", "1.0.0", "newpkg-1.0.0.tar.gz") if _, ok := store.files[storagePath]; !ok { t.Error("artifact was not stored in storage") } - missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi")) - if diff := missesAfter - missesBefore; diff != 1 { - t.Errorf("cache misses delta = %.0f, want 1", diff) - } - if diff := histogramSampleCount(t, metrics.UpstreamFetchDuration.WithLabelValues("pypi")) - fetchesBefore; diff != 1 { - t.Errorf("upstream fetch observations delta = %d, want 1", diff) - } - if diff := histogramSampleCount(t, metrics.StorageOperationDuration.WithLabelValues("write")) - writesBefore; diff != 1 { - t.Errorf("storage write observations delta = %d, want 1", diff) - } - if diff := histogramSampleCount(t, metrics.StorageOperationDuration.WithLabelValues("read")) - readsBefore; diff != 1 { - t.Errorf("storage read observations delta = %d, want 1", diff) - } } func TestGetOrFetchArtifactFromURL_FetchError(t *testing.T) { proxy, _, _, fetcher := setupTestProxy(t) fetcher.fetchErr = errors.New("connection refused") - errorsBefore := testutil.ToFloat64(metrics.UpstreamErrors.WithLabelValues("pypi", "fetch_failed")) _, err := proxy.GetOrFetchArtifactFromURL(context.Background(), "pypi", "fail", "1.0.0", "fail-1.0.0.tar.gz", "https://pypi.org/files/fail-1.0.0.tar.gz") if err == nil { @@ -794,15 +376,11 @@ func TestGetOrFetchArtifactFromURL_FetchError(t *testing.T) { if !strings.Contains(err.Error(), "fetching from upstream") { t.Errorf("expected upstream error, got: %v", err) } - if diff := testutil.ToFloat64(metrics.UpstreamErrors.WithLabelValues("pypi", "fetch_failed")) - errorsBefore; diff != 1 { - t.Errorf("upstream errors delta = %.0f, want 1", diff) - } } func TestGetOrFetchArtifactFromURL_StoreError(t *testing.T) { proxy, _, store, fetcher := setupTestProxy(t) store.storeErr = errors.New("disk full") - errorsBefore := testutil.ToFloat64(metrics.StorageErrors.WithLabelValues("write")) fetcher.artifact = &fetch.Artifact{ Body: io.NopCloser(strings.NewReader("data")), ContentType: "application/gzip", @@ -815,16 +393,15 @@ func TestGetOrFetchArtifactFromURL_StoreError(t *testing.T) { if !strings.Contains(err.Error(), "storing artifact") { t.Errorf("expected storage error, got: %v", err) } - if diff := testutil.ToFloat64(metrics.StorageErrors.WithLabelValues("write")) - errorsBefore; diff != 1 { - t.Errorf("storage errors delta = %.0f, want 1", diff) - } } func TestServeArtifact(t *testing.T) { result := &CacheResult{ - Reader: io.NopCloser(strings.NewReader("file contents")), - Artifact: testArtifact("file contents", "pkg:npm/example@1.0.0", "example.tgz", "application/gzip"), - Cached: true, + Reader: io.NopCloser(strings.NewReader("file contents")), + Size: 13, + ContentType: "application/gzip", + Hash: "sha256abc", + Cached: true, } w := httptest.NewRecorder() @@ -839,9 +416,8 @@ func TestServeArtifact(t *testing.T) { if w.Header().Get("Content-Length") != "13" { t.Errorf("Content-Length = %q, want %q", w.Header().Get("Content-Length"), "13") } - wantETag := `"` + result.Artifact.Digest.Encoded() + `"` - if w.Header().Get("ETag") != wantETag { - t.Errorf("ETag = %q, want %q", w.Header().Get("ETag"), wantETag) + if w.Header().Get("ETag") != `"sha256abc"` { + t.Errorf("ETag = %q, want %q", w.Header().Get("ETag"), `"sha256abc"`) } if w.Body.String() != "file contents" { t.Errorf("body = %q, want %q", w.Body.String(), "file contents") @@ -1076,8 +652,6 @@ func TestProxyCached_NoValidators_OmitsHeaders(t *testing.T) { } func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) { - hitsBefore := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test")) - missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) upstreamHits := 0 upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { upstreamHits++ @@ -1104,12 +678,6 @@ func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) { if upstreamHits != 1 { t.Fatalf("expected 1 upstream hit, got %d", upstreamHits) } - if diff := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) - missesBefore; diff != 1 { - t.Errorf("cache misses delta after first request = %.0f, want 1", diff) - } - if diff := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test")) - hitsBefore; diff != 0 { - t.Errorf("cache hits delta after first request = %.0f, want 0", diff) - } // Second request within TTL should serve from cache without hitting upstream body, _, err = proxy.FetchOrCacheMetadata(ctx, "test", "ttl-pkg", upstream.URL+"/pkg") @@ -1122,16 +690,9 @@ func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) { if upstreamHits != 1 { t.Errorf("expected upstream to still be hit only once, got %d", upstreamHits) } - if diff := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test")) - hitsBefore; diff != 1 { - t.Errorf("cache hits delta after second request = %.0f, want 1", diff) - } - if diff := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) - missesBefore; diff != 1 { - t.Errorf("cache misses delta after second request = %.0f, want 1", diff) - } } func TestFetchOrCacheMetadata_TTL_Zero_AlwaysRevalidates(t *testing.T) { - missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) upstreamHits := 0 upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { upstreamHits++ @@ -1160,40 +721,6 @@ func TestFetchOrCacheMetadata_TTL_Zero_AlwaysRevalidates(t *testing.T) { if upstreamHits != 2 { t.Errorf("expected 2 upstream hits with TTL=0, got %d", upstreamHits) } - missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) - if diff := missesAfter - missesBefore; diff != 2 { - t.Errorf("cache misses delta = %.0f, want 2", diff) - } -} - -func TestFetchOrCacheMetadata_CacheDisabledDoesNotRecordMetrics(t *testing.T) { - const ecosystem = "metadata-disabled" - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - w.Header().Set("Content-Type", "application/json") - _, _ = w.Write([]byte(`{"v":1}`)) - })) - t.Cleanup(upstream.Close) - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - - hitsBefore := testutil.ToFloat64(metrics.CacheHits.WithLabelValues(ecosystem)) - missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues(ecosystem)) - - _, _, err := proxy.FetchOrCacheMetadata(context.Background(), ecosystem, "pkg", upstream.URL+"/pkg") - if err != nil { - t.Fatalf("fetch metadata: %v", err) - } - - hitsAfter := testutil.ToFloat64(metrics.CacheHits.WithLabelValues(ecosystem)) - missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues(ecosystem)) - if diff := hitsAfter - hitsBefore; diff != 0 { - t.Errorf("cache hits delta = %.0f, want 0", diff) - } - if diff := missesAfter - missesBefore; diff != 0 { - t.Errorf("cache misses delta = %.0f, want 0", diff) - } } func TestProxyCached_StaleWarningHeader(t *testing.T) { @@ -1258,33 +785,3 @@ func TestProxyCached_FreshResponse_NoWarningHeader(t *testing.T) { t.Errorf("Warning should be empty for fresh response, got %q", got) } } - -// TestCanonicalPackagePURLMatchesConfig ensures the runtime cooldown lookup key -// agrees with config.CooldownConfig.NormalizedPackages for the same package, -// so a configured override is actually found regardless of how the user wrote it. -func TestCanonicalPackagePURLMatchesConfig(t *testing.T) { - tests := []struct { - ecosystem string - requestName string - configKey string - }{ - {"npm", "@babel/core", "pkg:npm/@babel/core"}, - {"npm", "@babel/core", "pkg:npm/%40babel/core"}, - {"npm", "@typescript/typescript-darwin-arm64", "pkg:npm/@typescript/typescript-darwin-arm64"}, - {"pypi", "Django", "pkg:pypi/Django"}, - {"pypi", "django", "pkg:pypi/Django"}, - {"composer", "symfony/console", "pkg:composer/Symfony/Console"}, - {"cargo", "serde", "pkg:cargo/serde"}, - } - for _, tt := range tests { - t.Run(tt.ecosystem+"/"+tt.requestName+"<="+tt.configKey, func(t *testing.T) { - cfg := config.CooldownConfig{Packages: map[string]string{tt.configKey: "1d"}} - normalized := cfg.NormalizedPackages() - - lookup := canonicalPackagePURL(tt.ecosystem, tt.requestName) - if _, ok := normalized[lookup]; !ok { - t.Errorf("lookup key %q not found in normalized config %v", lookup, normalized) - } - }) - } -} diff --git a/internal/handler/helm.go b/internal/handler/helm.go deleted file mode 100644 index 629d5c9..0000000 --- a/internal/handler/helm.go +++ /dev/null @@ -1,364 +0,0 @@ -package handler - -import ( - "crypto/sha256" - "encoding/hex" - "errors" - "fmt" - "net/http" - "net/url" - "path" - "strings" - "time" - - "gopkg.in/yaml.v3" -) - -const ( - helmMetadataEcosystem = "helm" - helmIndexFilename = "index.yaml" - sha256HexLength = 64 -) - -// HelmHandler serves read-only HTTP Helm chart repositories. Each configured -// repository is mounted at /helm/{repository}/. -type HelmHandler struct { - proxy *Proxy - proxyURL string - repositories map[string]string -} - -// NewHelmHandler creates a Helm chart repository protocol handler. -func NewHelmHandler(proxy *Proxy, proxyURL string, repositories map[string]string) *HelmHandler { - h := &HelmHandler{ - proxyURL: strings.TrimSuffix(proxyURL, "/"), - repositories: make(map[string]string, len(repositories)), - proxy: proxy, - } - for name, repositoryURL := range repositories { - h.repositories[name] = strings.TrimSuffix(repositoryURL, "/") - } - return h -} - -// Routes returns the HTTP handler for Helm chart repository requests. -func (h *HelmHandler) Routes() http.Handler { - mux := http.NewServeMux() - mux.HandleFunc("GET /{repository}/index.yaml", h.handleIndex) - mux.HandleFunc("GET /{repository}/charts/{digest}/{filename}", h.handleChart) - return mux -} - -func (h *HelmHandler) handleIndex(w http.ResponseWriter, r *http.Request) { - repository, upstreamURL, ok := h.repositoryForRequest(r) - if !ok { - http.NotFound(w, r) - return - } - - body, contentType, err := h.fetchIndex(r, repository, upstreamURL) - if err != nil { - h.serveIndexError(w, err) - return - } - - rewritten, err := h.rewriteIndex(repository, upstreamURL, body) - if err != nil { - h.proxy.Logger.Warn("failed to rewrite Helm index", "repository", repository, "error", err) - http.Error(w, "invalid Helm repository index", http.StatusBadGateway) - return - } - - h.proxy.writeMetadataCachedResponse(w, r, helmMetadataEcosystem, h.indexCacheKey(repository, upstreamURL), rewritten, contentType) -} - -func (h *HelmHandler) handleChart(w http.ResponseWriter, r *http.Request) { - repository, upstreamURL, ok := h.repositoryForRequest(r) - if !ok { - http.NotFound(w, r) - return - } - - digest, ok := normalizeHelmDigest(r.PathValue("digest")) - filename := r.PathValue("filename") - if !ok || filename == "" || strings.Contains(filename, "/") || containsPathTraversal(filename) { - http.Error(w, "invalid chart request", http.StatusBadRequest) - return - } - - cached, err := h.proxy.GetCachedArtifact(r.Context(), helmMetadataEcosystem, repository, digest, filename) - if err != nil { - h.proxy.Logger.Error("failed to check Helm chart cache", "error", err) - http.Error(w, "failed to check chart cache", http.StatusInternalServerError) - return - } - if cached != nil { - h.serveChart(w, r, repository, digest, filename, cached) - return - } - - body, _, err := h.fetchIndex(r, repository, upstreamURL) - if err != nil { - h.serveIndexError(w, err) - return - } - - downloadURL, err := h.findChartDownload(upstreamURL, body, digest, filename) - if err != nil { - if errors.Is(err, errHelmChartNotFound) { - http.NotFound(w, r) - return - } - h.proxy.Logger.Warn("failed to read Helm index", "repository", repository, "error", err) - http.Error(w, "invalid Helm repository index", http.StatusBadGateway) - return - } - - result, err := h.proxy.GetOrFetchArtifactFromURL( - r.Context(), helmMetadataEcosystem, repository, digest, filename, downloadURL) - if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch chart") - return - } - h.serveChart(w, r, repository, digest, filename, result) -} - -func (h *HelmHandler) serveChart(w http.ResponseWriter, r *http.Request, repository, digest, filename string, result *CacheResult) { - if !strings.EqualFold(result.Artifact.Digest.Encoded(), digest) { - if result.Reader != nil { - _ = result.Reader.Close() - } - if clearErr := h.proxy.ClearCachedArtifact(r.Context(), helmMetadataEcosystem, repository, digest, filename); clearErr != nil { - h.proxy.Logger.Warn("failed to clear Helm chart with invalid digest", "error", clearErr) - } - http.Error(w, "chart digest verification failed", http.StatusBadGateway) - return - } - - if result.Artifact.MediaType == "" { - w.Header().Set(headerContentType, "application/gzip") - } - ServeArtifact(w, result) -} - -func (h *HelmHandler) repositoryForRequest(r *http.Request) (name, upstreamURL string, ok bool) { - name = r.PathValue("repository") - upstreamURL, ok = h.repositories[name] - return name, upstreamURL, ok -} - -func (h *HelmHandler) fetchIndex(r *http.Request, repository, upstreamURL string) ([]byte, string, error) { - return h.proxy.FetchOrCacheMetadata( - r.Context(), - helmMetadataEcosystem, - h.indexCacheKey(repository, upstreamURL), - upstreamURL+"/"+helmIndexFilename, - "application/x-yaml, text/yaml;q=0.9, */*;q=0.1", - ) -} - -func (h *HelmHandler) indexCacheKey(repository, upstreamURL string) string { - identity := repository + "\x00" + upstreamURL - digest := sha256.Sum256([]byte(identity)) - return hex.EncodeToString(digest[:]) -} - -func (h *HelmHandler) serveIndexError(w http.ResponseWriter, err error) { - if errors.Is(err, ErrUpstreamNotFound) { - http.Error(w, "Helm repository not found", http.StatusNotFound) - return - } - h.proxy.Logger.Error("failed to fetch Helm index", "error", err) - http.Error(w, "failed to fetch Helm repository index", http.StatusBadGateway) -} - -func (h *HelmHandler) rewriteIndex(repository, upstreamURL string, body []byte) ([]byte, error) { - document, entries, err := parseHelmIndex(body) - if err != nil { - return nil, err - } - - for i := 0; i < len(entries.Content); i += 2 { - chartName := entries.Content[i].Value - releases := entries.Content[i+1] - if releases.Kind != yaml.SequenceNode { - return nil, fmt.Errorf("chart %q releases must be a sequence", chartName) - } - - filtered := make([]*yaml.Node, 0, len(releases.Content)) - for _, release := range releases.Content { - chart, err := h.parseChartRelease(chartName, upstreamURL, release) - if err != nil { - return nil, err - } - if h.chartOnCooldown(chartName, chart.created) { - continue - } - for _, download := range chart.downloads { - download.node.Value = h.chartProxyURL(repository, chart.digest, download.filename) - } - filtered = append(filtered, release) - } - releases.Content = filtered - } - - return yaml.Marshal(document) -} - -func (h *HelmHandler) findChartDownload(upstreamURL string, body []byte, digest, filename string) (string, error) { - _, entries, err := parseHelmIndex(body) - if err != nil { - return "", err - } - - for i := 0; i < len(entries.Content); i += 2 { - chartName := entries.Content[i].Value - releases := entries.Content[i+1] - if releases.Kind != yaml.SequenceNode { - return "", fmt.Errorf("chart %q releases must be a sequence", chartName) - } - for _, release := range releases.Content { - chart, err := h.parseChartRelease(chartName, upstreamURL, release) - if err != nil { - return "", err - } - if chart.digest != digest || h.chartOnCooldown(chartName, chart.created) { - continue - } - for _, download := range chart.downloads { - if download.filename == filename { - return download.url, nil - } - } - } - } - - return "", errHelmChartNotFound -} - -func (h *HelmHandler) chartOnCooldown(chartName string, created time.Time) bool { - return !created.IsZero() && h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled() && - !h.proxy.Cooldown.IsAllowed(helmMetadataEcosystem, canonicalPackagePURL(helmMetadataEcosystem, chartName), created) -} - -type helmChartDownload struct { - node *yaml.Node - url string - filename string -} - -type helmChartRelease struct { - created time.Time - digest string - downloads []helmChartDownload -} - -var errHelmChartNotFound = errors.New("chart not found in Helm index") - -func (h *HelmHandler) parseChartRelease(chartName, upstreamURL string, release *yaml.Node) (helmChartRelease, error) { - digestNode := helmMappingValue(release, "digest") - urlsNode := helmMappingValue(release, "urls") - if digestNode == nil || urlsNode == nil || urlsNode.Kind != yaml.SequenceNode || len(urlsNode.Content) == 0 { - return helmChartRelease{}, fmt.Errorf("chart %q has no digest or URLs", chartName) - } - digest, ok := normalizeHelmDigest(digestNode.Value) - if !ok { - return helmChartRelease{}, fmt.Errorf("chart %q has invalid digest", chartName) - } - - baseURL, err := url.Parse(upstreamURL + "/" + helmIndexFilename) - if err != nil { - return helmChartRelease{}, fmt.Errorf("parsing Helm repository URL: %w", err) - } - - chart := helmChartRelease{digest: digest} - if createdNode := helmMappingValue(release, "created"); createdNode != nil && createdNode.Value != "" { - chart.created, err = time.Parse(time.RFC3339Nano, createdNode.Value) - if err != nil { - return helmChartRelease{}, fmt.Errorf("chart %q has invalid creation time: %w", chartName, err) - } - } - - for _, urlNode := range urlsNode.Content { - if urlNode.Kind != yaml.ScalarNode { - return helmChartRelease{}, fmt.Errorf("chart %q has invalid URL", chartName) - } - reference, err := url.Parse(urlNode.Value) - if err != nil { - return helmChartRelease{}, fmt.Errorf("parsing chart %q URL: %w", chartName, err) - } - downloadURL := baseURL.ResolveReference(reference) - if (downloadURL.Scheme != "http" && downloadURL.Scheme != "https") || downloadURL.Host == "" { - return helmChartRelease{}, fmt.Errorf("chart %q URL must be HTTP(S)", chartName) - } - filename := path.Base(downloadURL.Path) - if filename == "." || filename == "/" || filename == "" || !strings.HasSuffix(filename, ".tgz") { - return helmChartRelease{}, fmt.Errorf("chart %q URL must point to a .tgz file", chartName) - } - chart.downloads = append(chart.downloads, helmChartDownload{ - node: urlNode, - url: downloadURL.String(), - filename: filename, - }) - } - return chart, nil -} - -func (h *HelmHandler) chartProxyURL(repository, digest, filename string) string { - return fmt.Sprintf("%s/helm/%s/charts/%s/%s", h.proxyURL, - url.PathEscape(repository), digest, url.PathEscape(filename)) -} - -func parseHelmIndex(body []byte) (*yaml.Node, *yaml.Node, error) { - var document yaml.Node - if err := yaml.Unmarshal(body, &document); err != nil { - return nil, nil, fmt.Errorf("parsing Helm index: %w", err) - } - entries, err := helmIndexEntries(&document) - if err != nil { - return nil, nil, err - } - return &document, entries, nil -} - -func helmIndexEntries(document *yaml.Node) (*yaml.Node, error) { - if document == nil { - return nil, errors.New("helm index is empty") - } - if len(document.Content) != 1 || document.Content[0].Kind != yaml.MappingNode { - return nil, errors.New("helm index must be a mapping") - } - entries := helmMappingValue(document.Content[0], "entries") - if entries == nil || entries.Kind != yaml.MappingNode { - return nil, errors.New("helm index has no entries mapping") - } - if len(entries.Content)%2 != 0 { - return nil, errors.New("helm index entries mapping has an incomplete key-value pair") - } - return entries, nil -} - -func helmMappingValue(mapping *yaml.Node, key string) *yaml.Node { - if mapping == nil || mapping.Kind != yaml.MappingNode { - return nil - } - for i := 0; i+1 < len(mapping.Content); i += 2 { - if mapping.Content[i].Value == key { - return mapping.Content[i+1] - } - } - return nil -} - -func normalizeHelmDigest(value string) (string, bool) { - digest := strings.TrimPrefix(strings.ToLower(value), "sha256:") - if len(digest) != sha256HexLength { - return "", false - } - for _, char := range digest { - if (char < '0' || char > '9') && (char < 'a' || char > 'f') { - return "", false - } - } - return digest, true -} diff --git a/internal/handler/helm_test.go b/internal/handler/helm_test.go deleted file mode 100644 index ec8d4a5..0000000 --- a/internal/handler/helm_test.go +++ /dev/null @@ -1,337 +0,0 @@ -package handler - -import ( - "crypto/sha256" - "encoding/hex" - "fmt" - "net/http" - "net/http/httptest" - "strings" - "sync/atomic" - "testing" - "time" - - "github.com/git-pkgs/cooldown" - upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient" - "github.com/git-pkgs/proxy/internal/storage" - "github.com/git-pkgs/registries/fetch" - "gopkg.in/yaml.v3" -) - -func TestHelmHandler_RewritesIndexAndCachesChart(t *testing.T) { - chart := []byte("a Helm chart") - digest := helmSHA256Hex(chart) - var available atomic.Bool - available.Store(true) - var indexRequests atomic.Int32 - var chartRequests atomic.Int32 - - var upstream *httptest.Server - upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if !available.Load() { - http.Error(w, "unavailable", http.StatusServiceUnavailable) - return - } - switch r.URL.Path { - case "/charts/index.yaml": - indexRequests.Add(1) - w.Header().Set("Content-Type", "application/x-yaml") - _, _ = fmt.Fprintf(w, `apiVersion: v1 -entries: - demo: - - annotations: - example.com/retained: "true" - created: 2020-01-02T03:04:05Z - digest: %s - name: demo - urls: - - demo-1.0.0.tgz - - %s/charts/mirror/demo-1.0.0.tgz - version: 1.0.0 -generated: 2020-01-02T03:04:05Z -`, digest, upstream.URL) - case "/charts/demo-1.0.0.tgz", "/charts/mirror/demo-1.0.0.tgz": - chartRequests.Add(1) - w.Header().Set("Content-Type", "application/gzip") - _, _ = w.Write(chart) - default: - http.NotFound(w, r) - } - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = upstream.Client() - fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0)) - proxy.Fetcher = fetcher - t.Cleanup(func() { _ = fetcher.Close() }) - - h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"stable": upstream.URL + "/charts"}) - - indexResponse := serveHelmRequest(h, "/stable/index.yaml") - if indexResponse.Code != http.StatusOK { - t.Fatalf("index status = %d, want 200: %s", indexResponse.Code, indexResponse.Body.String()) - } - if got := indexResponse.Header().Get("Content-Type"); got != "application/x-yaml" { - t.Errorf("index Content-Type = %q, want application/x-yaml", got) - } - if strings.Contains(indexResponse.Body.String(), upstream.URL) { - t.Errorf("rewritten index contains upstream URL: %s", indexResponse.Body.String()) - } - if !strings.Contains(indexResponse.Body.String(), "example.com/retained") { - t.Errorf("rewritten index lost an unrelated field: %s", indexResponse.Body.String()) - } - - var index map[string]any - if err := yaml.Unmarshal(indexResponse.Body.Bytes(), &index); err != nil { - t.Fatalf("parse rewritten index: %v", err) - } - entries := index["entries"].(map[string]any) - release := entries["demo"].([]any)[0].(map[string]any) - urls := release["urls"].([]any) - wantURL := "http://proxy.example/helm/stable/charts/" + digest + "/demo-1.0.0.tgz" - for _, rawURL := range urls { - if rawURL != wantURL { - t.Errorf("rewritten URL = %q, want %q", rawURL, wantURL) - } - } - - firstChart := serveHelmRequest(h, "/stable/charts/"+digest+"/demo-1.0.0.tgz") - if firstChart.Code != http.StatusOK { - t.Fatalf("chart status = %d, want 200: %s", firstChart.Code, firstChart.Body.String()) - } - if got := firstChart.Body.String(); got != string(chart) { - t.Errorf("chart body = %q, want %q", got, chart) - } - if got := firstChart.Header().Get("Content-Type"); got != "application/gzip" { - t.Errorf("chart Content-Type = %q, want application/gzip", got) - } - - // Artifact cache availability must not depend on metadata caching or a - // reachable index upstream. - proxy.CacheMetadata = false - available.Store(false) - cachedChart := serveHelmRequest(h, "/stable/charts/"+digest+"/demo-1.0.0.tgz") - if cachedChart.Code != http.StatusOK { - t.Fatalf("cached chart status = %d, want 200: %s", cachedChart.Code, cachedChart.Body.String()) - } - if got := cachedChart.Body.String(); got != string(chart) { - t.Errorf("cached chart body = %q, want %q", got, chart) - } - if got := indexRequests.Load(); got != 1 { - t.Errorf("index requests = %d, want 1", got) - } - if got := chartRequests.Load(); got != 1 { - t.Errorf("chart requests = %d, want 1", got) - } -} - -func TestHelmHandler_RejectsChartDigestMismatch(t *testing.T) { - chart := []byte("tampered chart") - digest := helmSHA256Hex([]byte("expected chart")) - requests := 0 - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.URL.Path { - case "/index.yaml": - _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", digest) - case "/demo.tgz": - requests++ - _, _ = w.Write(chart) - default: - http.NotFound(w, r) - } - })) - defer upstream.Close() - - proxy, _, store, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = upstream.Client() - fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0)) - proxy.Fetcher = fetcher - t.Cleanup(func() { _ = fetcher.Close() }) - h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"test": upstream.URL}) - - for range 2 { - response := serveHelmRequest(h, "/test/charts/"+digest+"/demo.tgz") - if response.Code != http.StatusBadGateway { - t.Errorf("status = %d, want 502: %s", response.Code, response.Body.String()) - } - } - if requests != 2 { - t.Errorf("chart requests = %d, want 2 after invalid cache entry is cleared", requests) - } - storagePath := storage.ArtifactPath(helmMetadataEcosystem, "", "test", digest, "demo.tgz") - if exists, err := store.Exists(t.Context(), storagePath); err != nil { - t.Fatalf("checking rejected chart storage: %v", err) - } else if exists { - t.Errorf("rejected chart remains in storage at %q", storagePath) - } -} - -func TestHelmHandler_IndexCacheChangesWithUpstreamURL(t *testing.T) { - firstDigest := strings.Repeat("a", sha256HexLength) - secondDigest := strings.Repeat("b", sha256HexLength) - firstRequests := 0 - secondRequests := 0 - first := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - firstRequests++ - _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", firstDigest) - })) - defer first.Close() - second := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - secondRequests++ - _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", secondDigest) - })) - defer second.Close() - - proxy, db, store, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = first.Client() - firstHandler := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"stable": first.URL}) - if response := serveHelmRequest(firstHandler, "/stable/index.yaml"); response.Code != http.StatusOK { - t.Fatalf("first index status = %d, want 200: %s", response.Code, response.Body.String()) - } - - // Model a restarted server with the same database and storage but a changed - // repository URL. Its cache key must not reuse the previous index or ETag. - restartedProxy := NewProxy(db, store, &mockFetcher{}, fetch.NewResolver(), nil) - restartedProxy.CacheMetadata = true - restartedProxy.MetadataTTL = time.Hour - restartedProxy.HTTPClient = second.Client() - secondHandler := NewHelmHandler(restartedProxy, "http://proxy.example", map[string]string{"stable": second.URL}) - response := serveHelmRequest(secondHandler, "/stable/index.yaml") - if response.Code != http.StatusOK { - t.Fatalf("second index status = %d, want 200: %s", response.Code, response.Body.String()) - } - if !strings.Contains(response.Body.String(), secondDigest) { - t.Errorf("second index did not use the new upstream: %s", response.Body.String()) - } - if firstRequests != 1 { - t.Errorf("first upstream requests = %d, want 1", firstRequests) - } - if secondRequests != 1 { - t.Errorf("second upstream requests = %d, want 1", secondRequests) - } -} - -func TestHelmHandler_UsesConfiguredUpstreamAuthentication(t *testing.T) { - chart := []byte("private Helm chart") - digest := helmSHA256Hex(chart) - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.Header.Get("Authorization") != "Bearer private-token" { - http.Error(w, "unauthorized", http.StatusUnauthorized) - return - } - switch r.URL.Path { - case "/index.yaml": - _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", digest) - case "/demo.tgz": - _, _ = w.Write(chart) - default: - http.NotFound(w, r) - } - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - authClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport, - upstreamhttp.AuthFunc(func(string) (string, string) { - return "Authorization", "Bearer private-token" - }))} - proxy.HTTPClient = authClient - fetcher := fetch.NewFetcher(fetch.WithHTTPClient(authClient), fetch.WithMaxRetries(0)) - proxy.Fetcher = fetcher - t.Cleanup(func() { _ = fetcher.Close() }) - h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"private": upstream.URL}) - - response := serveHelmRequest(h, "/private/charts/"+digest+"/demo.tgz") - if response.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", response.Code, response.Body.String()) - } - if got := response.Body.String(); got != string(chart) { - t.Errorf("body = %q, want %q", got, chart) - } -} - -func TestHelmHandler_FiltersNewChartsFromIndex(t *testing.T) { - oldDigest := strings.Repeat("a", 64) - newDigest := strings.Repeat("b", 64) - proxy := &Proxy{Cooldown: &cooldown.Config{Default: "3d"}} - h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"test": "https://charts.example"}) - - body := fmt.Sprintf(`apiVersion: v1 -entries: - demo: - - created: %s - digest: %s - urls: [demo-old.tgz] - - created: %s - digest: %s - urls: [demo-new.tgz] -`, time.Now().Add(-10*24*time.Hour).Format(time.RFC3339), oldDigest, - time.Now().Add(-time.Hour).Format(time.RFC3339), newDigest) - - rewritten, err := h.rewriteIndex("test", "https://charts.example", []byte(body)) - if err != nil { - t.Fatalf("rewriteIndex() error = %v", err) - } - if strings.Contains(string(rewritten), newDigest) { - t.Errorf("rewritten index includes a chart still in cooldown: %s", rewritten) - } - if !strings.Contains(string(rewritten), oldDigest) { - t.Errorf("rewritten index omitted an old chart: %s", rewritten) - } -} - -func TestNormalizeHelmDigest(t *testing.T) { - digest := strings.Repeat("a", 64) - for _, input := range []string{digest, "sha256:" + digest, "SHA256:" + strings.ToUpper(digest)} { - if got, ok := normalizeHelmDigest(input); !ok || got != digest { - t.Errorf("normalizeHelmDigest(%q) = %q, %t; want %q, true", input, got, ok, digest) - } - } - if _, ok := normalizeHelmDigest("bad"); ok { - t.Error("normalizeHelmDigest accepted an invalid digest") - } -} - -func TestHelmIndexEntriesRejectsIncompleteMapping(t *testing.T) { - entries := &yaml.Node{ - Kind: yaml.MappingNode, - Content: []*yaml.Node{ - {Kind: yaml.ScalarNode, Value: "demo"}, - }, - } - document := &yaml.Node{ - Kind: yaml.DocumentNode, - Content: []*yaml.Node{{ - Kind: yaml.MappingNode, - Content: []*yaml.Node{ - {Kind: yaml.ScalarNode, Value: "entries"}, - entries, - }, - }}, - } - - if _, err := helmIndexEntries(document); err == nil { - t.Fatal("helmIndexEntries() error = nil, want incomplete mapping error") - } -} - -func serveHelmRequest(h *HelmHandler, target string) *httptest.ResponseRecorder { - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, target, nil)) - return w -} - -func helmSHA256Hex(data []byte) string { - digest := sha256.Sum256(data) - return hex.EncodeToString(digest[:]) -} diff --git a/internal/handler/hex.go b/internal/handler/hex.go index 15d2891..0f0c72e 100644 --- a/internal/handler/hex.go +++ b/internal/handler/hex.go @@ -10,6 +10,7 @@ import ( "strings" "time" + "github.com/git-pkgs/purl" "google.golang.org/protobuf/encoding/protowire" ) @@ -21,7 +22,6 @@ const ( type HexHandler struct { proxy *Proxy upstreamURL string - apiURL string proxyURL string } @@ -30,20 +30,10 @@ func NewHexHandler(proxy *Proxy, proxyURL string) *HexHandler { return &HexHandler{ proxy: proxy, upstreamURL: hexUpstream, - apiURL: hexAPIURL, proxyURL: strings.TrimSuffix(proxyURL, "/"), } } -// NewHexHandlerWithUpstreams creates a Hex handler with custom repository and -// API upstreams. -func NewHexHandlerWithUpstreams(proxy *Proxy, proxyURL, upstreamURL, apiURL string) *HexHandler { - h := NewHexHandler(proxy, proxyURL) - h.upstreamURL = configuredUpstreamURL(upstreamURL, hexUpstream) - h.apiURL = configuredUpstreamURL(apiURL, hexAPIURL) - return h -} - // Routes returns the HTTP handler for Hex requests. func (h *HexHandler) Routes() http.Handler { mux := http.NewServeMux() @@ -64,14 +54,30 @@ func (h *HexHandler) Routes() http.Handler { // handleDownload serves a package tarball, fetching and caching from upstream if needed. func (h *HexHandler) handleDownload(w http.ResponseWriter, r *http.Request) { - h.proxy.handleFilenameDownload(w, r, filenameDownload{ - ecosystem: "hex", - upstreamURL: h.upstreamURL, - suffix: ".tar", - parseErr: "could not parse tarball filename", - fetchErr: "failed to fetch package", - parse: h.parseTarballFilename, - }) + filename := r.PathValue("filename") + if filename == "" || !strings.HasSuffix(filename, ".tar") { + http.Error(w, "invalid filename", http.StatusBadRequest) + return + } + + // Extract name and version from filename (e.g., "phoenix-1.7.10.tar") + name, version := h.parseTarballFilename(filename) + if name == "" || version == "" { + http.Error(w, "could not parse tarball filename", http.StatusBadRequest) + return + } + + h.proxy.Logger.Info("hex download request", + "name", name, "version", version, "filename", filename) + + result, err := h.proxy.GetOrFetchArtifact(r.Context(), "hex", name, version, filename) + if err != nil { + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch package", http.StatusBadGateway) + return + } + + ServeArtifact(w, result) } // parseTarballFilename extracts name and version from a hex tarball filename. @@ -135,7 +141,7 @@ func (h *HexHandler) handlePackages(w http.ResponseWriter, r *http.Request) { if len(filteredVersions) == 0 { // No versions to filter or couldn't get timestamps, pass through - w.Header().Set(headerContentType, protoResp.Header.Get(headerContentType)) + w.Header().Set("Content-Type", protoResp.Header.Get("Content-Type")) w.Header().Set("Content-Encoding", "gzip") _, _ = w.Write(body) return @@ -144,13 +150,13 @@ func (h *HexHandler) handlePackages(w http.ResponseWriter, r *http.Request) { filtered, err := h.filterSignedPackage(body, filteredVersions) if err != nil { h.proxy.Logger.Warn("failed to filter hex package, proxying original", "error", err) - w.Header().Set(headerContentType, protoResp.Header.Get(headerContentType)) + w.Header().Set("Content-Type", protoResp.Header.Get("Content-Type")) w.Header().Set("Content-Encoding", "gzip") _, _ = w.Write(body) return } - w.Header().Set(headerContentType, "application/octet-stream") + w.Header().Set("Content-Type", "application/octet-stream") w.Header().Set("Content-Encoding", "gzip") _, _ = w.Write(filtered) } @@ -209,7 +215,7 @@ type hexPackageAPI struct { // fetchFilteredVersions fetches the Hex API and returns a set of version // strings that should be filtered out by cooldown. func (h *HexHandler) fetchFilteredVersions(r *http.Request, name string) (map[string]bool, error) { - apiURL := fmt.Sprintf("%s/api/packages/%s", h.apiURL, name) + apiURL := fmt.Sprintf("%s/api/packages/%s", hexAPIURL, name) req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, apiURL, nil) if err != nil { return nil, err @@ -231,7 +237,7 @@ func (h *HexHandler) fetchFilteredVersions(r *http.Request, name string) (map[st return nil, err } - packagePURL := canonicalPackagePURL("hex", name) + packagePURL := purl.MakePURLString("hex", name, "") filtered := make(map[string]bool) for _, release := range pkg.Releases { diff --git a/internal/handler/hex_test.go b/internal/handler/hex_test.go index b02540a..19d34b4 100644 --- a/internal/handler/hex_test.go +++ b/internal/handler/hex_test.go @@ -11,7 +11,7 @@ import ( "testing" "time" - "github.com/git-pkgs/cooldown" + "github.com/git-pkgs/proxy/internal/cooldown" "google.golang.org/protobuf/encoding/protowire" ) diff --git a/internal/handler/homebrew.go b/internal/handler/homebrew.go deleted file mode 100644 index 0af67af..0000000 --- a/internal/handler/homebrew.go +++ /dev/null @@ -1,74 +0,0 @@ -package handler - -import ( - "crypto/sha256" - "encoding/hex" - "net/http" - "strings" -) - -const ( - homebrewArtifactNamespace = "homebrew" - homebrewArtifactRepository = "homebrew/core" - homebrewMetadataEcosystem = "homebrew" -) - -// HomebrewHandler proxies Homebrew's JSON API without modifying signed files. -type HomebrewHandler struct { - proxy *Proxy - apiUpstream string -} - -// NewHomebrewHandler creates a Homebrew JSON API handler. -func NewHomebrewHandler(proxy *Proxy, apiUpstream string) *HomebrewHandler { - return &HomebrewHandler{ - proxy: proxy, - apiUpstream: strings.TrimSuffix(apiUpstream, "/"), - } -} - -// RegisterHomebrewArtifacts routes homebrew/core OCI requests to its configured -// registry and blocks other homebrew repositories from reaching the default -// OCI registry. -func RegisterHomebrewArtifacts(container *ContainerHandler, artifactUpstream string) { - container.BlockRegistry(homebrewArtifactNamespace) - container.RegisterRegistry(homebrewArtifactRepository, artifactUpstream) -} - -// Routes returns the Homebrew JSON API handler. Mount this at /homebrew. -func (h *HomebrewHandler) Routes() http.Handler { - return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.Method != http.MethodGet && r.Method != http.MethodHead { - w.Header().Set("Allow", "GET, HEAD") - http.Error(w, "method not allowed", http.StatusMethodNotAllowed) - return - } - - requestPath := strings.TrimPrefix(r.URL.EscapedPath(), "/") - if requestPath == "" || containsPathTraversal(requestPath) { - http.NotFound(w, r) - return - } - - upstreamURL := h.apiUpstream + "/" + requestPath - if r.URL.RawQuery != "" { - upstreamURL += "?" + r.URL.RawQuery - } - - // brew fetches every JSON API download with `curl --compressed` and - // decodes Content-Encoding itself, and formula.jws.json is ~33 MB plain - // versus ~5 MB gzip, so keep both hops compressed. The analytics - // endpoints are the one consumer brew fetches without --compressed; - // they stay identity. - acceptEncoding := "gzip" - if strings.HasPrefix(requestPath, "analytics/") { - acceptEncoding = "identity" - } - h.proxy.proxyCachedWithEncoding(w, r, upstreamURL, homebrewMetadataEcosystem, homebrewMetadataCacheKey(requestPath, r.URL.RawQuery), acceptEncoding, "*/*") - }) -} - -func homebrewMetadataCacheKey(requestPath, rawQuery string) string { - sum := sha256.Sum256([]byte(requestPath + "\x00" + rawQuery)) - return hex.EncodeToString(sum[:]) -} diff --git a/internal/handler/homebrew_test.go b/internal/handler/homebrew_test.go deleted file mode 100644 index e5d7e5c..0000000 --- a/internal/handler/homebrew_test.go +++ /dev/null @@ -1,458 +0,0 @@ -package handler - -import ( - "bytes" - "io" - "net/http" - "net/http/httptest" - "strconv" - "strings" - "sync/atomic" - "testing" - "time" - - "github.com/git-pkgs/registries/fetch" -) - -func TestHomebrewHandler_PreservesSignedResponseAndClientValidators(t *testing.T) { - body := " {\n \"payload\": \"signed bytes\",\n \"signatures\": []\n}\n" - etag := `"homebrew-api-etag"` - lastModified := time.Date(2026, time.August, 14, 9, 30, 0, 0, time.UTC) - requests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - requests++ - if r.Method != http.MethodGet { - t.Errorf("upstream method = %s, want GET", r.Method) - } - if r.URL.Path != "/api/internal/packages.arm64_tahoe.jws.json" { - t.Errorf("upstream path = %q", r.URL.Path) - } - if got := r.Header.Get("Authorization"); got != "" { - t.Errorf("upstream Authorization = %q, want empty", got) - } - if got := r.Header.Get("Cookie"); got != "" { - t.Errorf("upstream Cookie = %q, want empty", got) - } - w.Header().Set("Content-Type", "application/json") - w.Header().Set("ETag", etag) - w.Header().Set("Last-Modified", lastModified.Format(http.TimeFormat)) - _, _ = io.WriteString(w, body) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = upstream.Client() - h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes() - - req := httptest.NewRequest(http.MethodGet, "/internal/packages.arm64_tahoe.jws.json", nil) - req.Header.Set("Authorization", "Bearer client-secret") - req.Header.Set("Cookie", "session=client-secret") - w := httptest.NewRecorder() - h.ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) - } - if got := w.Body.String(); got != body { - t.Errorf("body = %q, want byte-for-byte %q", got, body) - } - if got := w.Header().Get("Content-Type"); got != "application/json" { - t.Errorf("Content-Type = %q, want application/json", got) - } - wantContentLength := strconv.Itoa(len(body)) - if got := w.Header().Get("Content-Length"); got != wantContentLength { - t.Errorf("Content-Length = %q, want %q", got, wantContentLength) - } - if got := w.Header().Get("ETag"); got != etag { - t.Errorf("ETag = %q, want %q", got, etag) - } - if got := w.Header().Get("Last-Modified"); got != lastModified.Format(http.TimeFormat) { - t.Errorf("Last-Modified = %q, want %q", got, lastModified.Format(http.TimeFormat)) - } - - conditionalRequest := httptest.NewRequest(http.MethodGet, "/internal/packages.arm64_tahoe.jws.json", nil) - conditionalRequest.Header.Set("If-None-Match", etag) - conditional := httptest.NewRecorder() - h.ServeHTTP(conditional, conditionalRequest) - if conditional.Code != http.StatusNotModified { - t.Fatalf("conditional status = %d, want %d", conditional.Code, http.StatusNotModified) - } - if got := conditional.Header().Get("ETag"); got != etag { - t.Errorf("conditional ETag = %q, want %q", got, etag) - } - if conditional.Body.Len() != 0 { - t.Errorf("conditional body length = %d, want 0", conditional.Body.Len()) - } - - modifiedSinceRequest := httptest.NewRequest(http.MethodGet, "/internal/packages.arm64_tahoe.jws.json", nil) - modifiedSinceRequest.Header.Set("If-Modified-Since", lastModified.Format(http.TimeFormat)) - modifiedSince := httptest.NewRecorder() - h.ServeHTTP(modifiedSince, modifiedSinceRequest) - if modifiedSince.Code != http.StatusNotModified { - t.Fatalf("If-Modified-Since status = %d, want %d", modifiedSince.Code, http.StatusNotModified) - } - if got := modifiedSince.Header().Get("Last-Modified"); got != lastModified.Format(http.TimeFormat) { - t.Errorf("conditional Last-Modified = %q, want %q", got, lastModified.Format(http.TimeFormat)) - } - if requests != 1 { - t.Errorf("upstream requests = %d, want 1", requests) - } -} - -func TestHomebrewHandler_HeadUsesMetadataCacheAndSurvivesOutage(t *testing.T) { - body := `{"payload":"signed bytes","signatures":[]}` - available := true - requests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - requests++ - if got := r.Header.Get("Authorization"); got != "" { - t.Errorf("upstream Authorization = %q, want empty", got) - } - if !available { - http.Error(w, "unavailable", http.StatusServiceUnavailable) - return - } - w.Header().Set("Content-Type", "application/json") - w.Header().Set("ETag", `"head-etag"`) - _, _ = io.WriteString(w, body) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = upstream.Client() - h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes() - - coldRequest := httptest.NewRequest(http.MethodHead, "/formula.jws.json", nil) - coldRequest.Header.Set("Authorization", "Bearer client-secret") - cold := httptest.NewRecorder() - h.ServeHTTP(cold, coldRequest) - if cold.Code != http.StatusOK { - t.Fatalf("cold status = %d, want %d", cold.Code, http.StatusOK) - } - if cold.Body.Len() != 0 { - t.Errorf("cold body length = %d, want 0", cold.Body.Len()) - } - if got := cold.Header().Get("Content-Length"); got != strconv.Itoa(len(body)) { - t.Errorf("Content-Length = %q, want %d", got, len(body)) - } - if got := cold.Header().Get("ETag"); got != `"head-etag"` { - t.Errorf("ETag = %q, want %q", got, `"head-etag"`) - } - if requests != 1 { - t.Fatalf("cold upstream requests = %d, want 1", requests) - } - - warm := httptest.NewRecorder() - h.ServeHTTP(warm, httptest.NewRequest(http.MethodHead, "/formula.jws.json", nil)) - if warm.Code != http.StatusOK { - t.Fatalf("warm status = %d, want %d", warm.Code, http.StatusOK) - } - if warm.Body.Len() != 0 { - t.Errorf("warm body length = %d, want 0", warm.Body.Len()) - } - if requests != 1 { - t.Errorf("warm upstream requests = %d, want 1", requests) - } - - proxy.MetadataTTL = time.Nanosecond - available = false - stale := httptest.NewRecorder() - h.ServeHTTP(stale, httptest.NewRequest(http.MethodHead, "/formula.jws.json", nil)) - if stale.Code != http.StatusOK { - t.Fatalf("stale status = %d, want %d; body: %s", stale.Code, http.StatusOK, stale.Body.String()) - } - if stale.Body.Len() != 0 { - t.Errorf("stale body length = %d, want 0", stale.Body.Len()) - } - if got := stale.Header().Get("Warning"); got != containerStaleWarning { - t.Errorf("Warning = %q, want %q", got, containerStaleWarning) - } -} - -func TestHomebrewHandler_HeadWithoutMetadataCachePreservesUpstreamMethod(t *testing.T) { - upstreamMethod := "" - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - upstreamMethod = r.Method - w.Header().Set("Content-Type", "application/json") - w.Header().Set("Content-Length", "42") - w.Header().Set("ETag", `"head-etag"`) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = false - proxy.HTTPClient = upstream.Client() - h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes() - - head := httptest.NewRecorder() - h.ServeHTTP(head, httptest.NewRequest(http.MethodHead, "/formula.jws.json", nil)) - if head.Code != http.StatusOK { - t.Fatalf("status = %d, want %d", head.Code, http.StatusOK) - } - if upstreamMethod != http.MethodHead { - t.Errorf("upstream method = %q, want HEAD", upstreamMethod) - } - if head.Body.Len() != 0 { - t.Errorf("body length = %d, want 0", head.Body.Len()) - } - if got := head.Header().Get("Content-Length"); got != "42" { - t.Errorf("Content-Length = %q, want 42", got) - } -} - -func TestHomebrewHandler_ServesStaleCachedResponseWhenUpstreamFails(t *testing.T) { - body := `{"payload":"signed bytes","signatures":[]}` - available := true - requests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - requests++ - if !available { - http.Error(w, "unavailable", http.StatusServiceUnavailable) - return - } - w.Header().Set("Content-Type", "application/json") - w.Header().Set("ETag", `"stale-etag"`) - _, _ = io.WriteString(w, body) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = 5 * time.Millisecond - proxy.HTTPClient = upstream.Client() - h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes() - - first := httptest.NewRecorder() - h.ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/formula.jws.json", nil)) - if first.Code != http.StatusOK { - t.Fatalf("warm status = %d, want %d", first.Code, http.StatusOK) - } - - time.Sleep(10 * time.Millisecond) - available = false - stale := httptest.NewRecorder() - h.ServeHTTP(stale, httptest.NewRequest(http.MethodGet, "/formula.jws.json", nil)) - if stale.Code != http.StatusOK { - t.Fatalf("stale status = %d, want %d; body: %s", stale.Code, http.StatusOK, stale.Body.String()) - } - if got := stale.Body.String(); got != body { - t.Errorf("stale body = %q, want %q", got, body) - } - if got := stale.Header().Get("Warning"); got != containerStaleWarning { - t.Errorf("Warning = %q, want %q", got, containerStaleWarning) - } - if requests != 2 { - t.Errorf("upstream requests = %d, want 2", requests) - } -} - -func TestHomebrewHandler_ProxiesSupportedAPIPaths(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - _, _ = io.WriteString(w, r.URL.RequestURI()) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes() - - paths := []string{ - "/formula.jws.json", - "/cask.jws.json", - "/formula/jq.json", - "/cask/firefox.json", - "/internal/packages.arm64_tahoe.jws.json?download=1", - } - for _, requestPath := range paths { - t.Run(requestPath, func(t *testing.T) { - w := httptest.NewRecorder() - h.ServeHTTP(w, httptest.NewRequest(http.MethodGet, requestPath, nil)) - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d", w.Code, http.StatusOK) - } - if got, want := w.Body.String(), "/api"+requestPath; got != want { - t.Errorf("upstream request = %q, want %q", got, want) - } - }) - } -} - -func TestHomebrewHandler_RejectsUnsupportedRequests(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - h := NewHomebrewHandler(proxy, "https://example.test/api").Routes() - - method := httptest.NewRecorder() - h.ServeHTTP(method, httptest.NewRequest(http.MethodPost, "/formula.jws.json", nil)) - if method.Code != http.StatusMethodNotAllowed { - t.Errorf("POST status = %d, want %d", method.Code, http.StatusMethodNotAllowed) - } - if got := method.Header().Get("Allow"); got != "GET, HEAD" { - t.Errorf("Allow = %q, want GET, HEAD", got) - } - - root := httptest.NewRecorder() - h.ServeHTTP(root, httptest.NewRequest(http.MethodGet, "/", nil)) - if root.Code != http.StatusNotFound { - t.Errorf("root status = %d, want %d", root.Code, http.StatusNotFound) - } - - traversal := httptest.NewRecorder() - h.ServeHTTP(traversal, httptest.NewRequest(http.MethodGet, "/%2e%2e/secret", nil)) - if traversal.Code != http.StatusNotFound { - t.Errorf("traversal status = %d, want %d", traversal.Code, http.StatusNotFound) - } -} - -func TestRegisterHomebrewArtifacts(t *testing.T) { - h := &ContainerHandler{registryURL: dockerHubRegistry} - artifactUpstream := "https://homebrew-proxy.example.com" - RegisterHomebrewArtifacts(h, artifactUpstream+"/") - - if got := h.registryURLFor("homebrew/core/jq"); got != artifactUpstream { - t.Errorf("homebrew/core registry = %q, want %q", got, artifactUpstream) - } - if got := h.registryURLFor("homebrew/cask/firefox"); got != "" { - t.Errorf("other Homebrew registry = %q, want blocked", got) - } - if got := h.registryURLFor("library/nginx"); got != dockerHubRegistry { - t.Errorf("unrelated registry = %q, want %q", got, dockerHubRegistry) - } -} - -func TestRegisterHomebrewArtifactsRejectsOtherHomebrewRoutes(t *testing.T) { - upstreamRequests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - upstreamRequests++ - _, _ = io.WriteString(w, "unexpected upstream response") - })) - defer upstream.Close() - - proxy, _, _, fetcher := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("unexpected upstream blob")), - ContentType: "application/octet-stream", - } - h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL} - RegisterHomebrewArtifacts(h, "https://ghcr.io") - - const digest = "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" - paths := []string{ - "/homebrew/cask/firefox/blobs/" + digest, - "/homebrew/cask/firefox/manifests/latest", - "/homebrew/cask/firefox/tags/list", - } - for _, path := range paths { - t.Run(path, func(t *testing.T) { - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, path, nil)) - if w.Code != http.StatusNotFound { - t.Errorf("status = %d, want %d; body: %s", w.Code, http.StatusNotFound, w.Body.String()) - } - }) - } - - if fetcher.fetchCalled { - t.Error("blocked Homebrew blob reached the artifact fetcher") - } - if upstreamRequests != 0 { - t.Errorf("blocked Homebrew routes made %d upstream requests, want 0", upstreamRequests) - } -} - -// TestHomebrewHandler_RequestsGzipForAPIPaths covers #305's motivating case: -// the JSON API files are fetched, cached and served gzip-compressed with -// Content-Encoding: gzip (brew fetches them with --compressed), while the -// analytics endpoints, which brew fetches without --compressed, stay identity. -func TestHomebrewHandler_RequestsGzipForAPIPaths(t *testing.T) { - plain := []byte(`{"payload":"signed bytes","signatures":[]}`) - compressed := gzipPayload(t, plain) - - var available atomic.Bool - available.Store(true) - var requests atomic.Int32 - var sawAcceptEncoding atomic.Value // string - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - requests.Add(1) - sawAcceptEncoding.Store(r.Header.Get(headerAcceptEncoding)) - if !available.Load() { - http.Error(w, "unavailable", http.StatusServiceUnavailable) - return - } - w.Header().Set(headerContentType, "application/json") - if strings.Contains(r.Header.Get(headerAcceptEncoding), "gzip") { - w.Header().Set(headerContentEncoding, "gzip") - _, _ = w.Write(compressed) - return - } - _, _ = w.Write(plain) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = upstream.Client() - h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes() - - get := func(path string) *httptest.ResponseRecorder { - w := httptest.NewRecorder() - h.ServeHTTP(w, httptest.NewRequest(http.MethodGet, path, nil)) - return w - } - lastAE := func() string { - s, _ := sawAcceptEncoding.Load().(string) - return s - } - - first := get("/formula.jws.json") - if first.Code != http.StatusOK { - t.Fatalf("formula.jws.json: status = %d, want 200: %s", first.Code, first.Body.String()) - } - if got := lastAE(); got != "gzip" { - t.Errorf("formula.jws.json: upstream Accept-Encoding = %q, want %q", got, "gzip") - } - if !bytes.Equal(first.Body.Bytes(), compressed) { - t.Errorf("formula.jws.json: body is not the compressed bytes (got %d, want %d)", first.Body.Len(), len(compressed)) - } - if got := first.Header().Get(headerContentEncoding); got != "gzip" { - t.Errorf("formula.jws.json: Content-Encoding = %q, want %q", got, "gzip") - } - if got := first.Header().Get(headerContentLength); got != strconv.Itoa(len(compressed)) { - t.Errorf("formula.jws.json: Content-Length = %q, want %d", got, len(compressed)) - } - - // Replay from cache with the upstream down: same bytes and header, no refetch. - before := requests.Load() - available.Store(false) - cached := get("/formula.jws.json") - if cached.Code != http.StatusOK { - t.Fatalf("cached formula.jws.json: status = %d, want 200: %s", cached.Code, cached.Body.String()) - } - if !bytes.Equal(cached.Body.Bytes(), compressed) || cached.Header().Get(headerContentEncoding) != "gzip" { - t.Errorf("cached formula.jws.json: body/header not replayed verbatim") - } - if requests.Load() != before { - t.Errorf("cached formula.jws.json hit upstream: requests %d -> %d", before, requests.Load()) - } - available.Store(true) - - // Analytics is fetched by brew without --compressed: stays identity, no header. - analytics := get("/analytics/install/30d.json") - if analytics.Code != http.StatusOK { - t.Fatalf("analytics: status = %d, want 200: %s", analytics.Code, analytics.Body.String()) - } - if got := lastAE(); got != "identity" { - t.Errorf("analytics: upstream Accept-Encoding = %q, want %q", got, "identity") - } - if !bytes.Equal(analytics.Body.Bytes(), plain) { - t.Errorf("analytics: body = %q, want plain %q", analytics.Body.Bytes(), plain) - } - if got := analytics.Header().Get(headerContentEncoding); got != "" { - t.Errorf("analytics: Content-Encoding = %q, want empty", got) - } -} diff --git a/internal/handler/if_none_match_test.go b/internal/handler/if_none_match_test.go deleted file mode 100644 index b659254..0000000 --- a/internal/handler/if_none_match_test.go +++ /dev/null @@ -1,31 +0,0 @@ -package handler - -import "testing" - -func TestIfNoneMatchHits(t *testing.T) { - tests := []struct { - header string - etag string - want bool - }{ - {`"abc"`, `"abc"`, true}, - {`"abc"`, `"def"`, false}, - {"", `"abc"`, false}, - {`"abc"`, "", false}, - {"*", `"abc"`, true}, - {"*", "", false}, - {`W/"abc"`, `"abc"`, true}, - {`"abc"`, `W/"abc"`, true}, - {`W/"abc"`, `W/"abc"`, true}, - {`"abc", "def"`, `"def"`, true}, - {`"abc","def"`, `"def"`, true}, - {` "abc" , W/"def" `, `"def"`, true}, - {`"abc", "def"`, `"ghi"`, false}, - } - - for _, tt := range tests { - if got := ifNoneMatchHits(tt.header, tt.etag); got != tt.want { - t.Errorf("ifNoneMatchHits(%q, %q) = %v, want %v", tt.header, tt.etag, got, tt.want) - } - } -} diff --git a/internal/handler/integrity.go b/internal/handler/integrity.go deleted file mode 100644 index 07963b9..0000000 --- a/internal/handler/integrity.go +++ /dev/null @@ -1,100 +0,0 @@ -package handler - -import ( - "fmt" - "io" - - "github.com/git-pkgs/integrity" -) - -type integrityChecks struct { - contentHash integrity.SRI - native integrity.SRI - algorithms []integrity.Algorithm -} - -func newIntegrityChecks(contentHash, native string) (integrityChecks, error) { - checks := integrityChecks{} - - if contentHash != "" { - digest, err := integrity.ParseHex(integrity.SHA256, contentHash) - if err != nil { - return integrityChecks{}, fmt.Errorf("parse content_hash: %w", err) - } - checks.contentHash = integrity.SRI{digest} - checks.algorithms = append(checks.algorithms, integrity.SHA256) - } - - if native != "" { - digests, err := integrity.ParseSRI(native) - if err != nil { - return integrityChecks{}, fmt.Errorf("parse integrity: %w", err) - } - checks.native = digests - for _, digest := range digests { - checks.algorithms = append(checks.algorithms, digest.Algorithm()) - } - } - - return checks, nil -} - -func (c integrityChecks) wrap(source io.ReadCloser, onMismatch func(string)) (io.ReadCloser, error) { - if len(c.algorithms) == 0 { - return source, nil - } - reader, err := integrity.NewReader(source, c.algorithms...) - if err != nil { - return nil, fmt.Errorf("create integrity reader: %w", err) - } - return &verifyingReader{ - source: source, - reader: reader, - checks: c, - onMismatch: onMismatch, - }, nil -} - -// verifyingReader forwards Close to its source and reports completed digest -// mismatches after its shared integrity reader observes EOF. -type verifyingReader struct { - source io.ReadCloser - reader *integrity.Reader - checks integrityChecks - onMismatch func(reason string) - verified bool -} - -func (r *verifyingReader) Read(p []byte) (int, error) { - n, err := r.reader.Read(p) - if err == io.EOF { - r.verify() - } - return n, err -} - -func (r *verifyingReader) Close() error { - return r.source.Close() -} - -func (r *verifyingReader) verify() { - if r.verified { - return - } - r.verified = true - result := r.reader.Result() - if !result.Complete { - return - } - - if len(r.checks.contentHash) > 0 { - if err := result.Verify(r.checks.contentHash); err != nil { - r.onMismatch("content_hash: " + err.Error()) - } - } - if len(r.checks.native) > 0 { - if err := result.Verify(r.checks.native); err != nil { - r.onMismatch("integrity: " + err.Error()) - } - } -} diff --git a/internal/handler/integrity_test.go b/internal/handler/integrity_test.go deleted file mode 100644 index 95992c0..0000000 --- a/internal/handler/integrity_test.go +++ /dev/null @@ -1,250 +0,0 @@ -package handler - -import ( - "crypto/sha256" - "crypto/sha512" - "encoding/base64" - "encoding/hex" - "errors" - "io" - "strings" - "testing" -) - -func sha256Hex(data string) string { - sum := sha256.Sum256([]byte(data)) - return hex.EncodeToString(sum[:]) -} - -func sha256SRI(data string) string { - sum := sha256.Sum256([]byte(data)) - return "sha256-" + base64.StdEncoding.EncodeToString(sum[:]) -} - -func sha384SRI(data string) string { - sum := sha512.Sum384([]byte(data)) - return "sha384-" + base64.StdEncoding.EncodeToString(sum[:]) -} - -func sha512SRI(data string) string { - sum := sha512.Sum512([]byte(data)) - return "sha512-" + base64.StdEncoding.EncodeToString(sum[:]) -} - -func wrapIntegrityReader(t *testing.T, source io.ReadCloser, contentHash, native string, onMismatch func(string)) io.ReadCloser { - t.Helper() - checks, err := newIntegrityChecks(contentHash, native) - if err != nil { - t.Fatalf("newIntegrityChecks: %v", err) - } - reader, err := checks.wrap(source, onMismatch) - if err != nil { - t.Fatalf("wrap: %v", err) - } - return reader -} - -func TestNewIntegrityChecksCollectsAlgorithms(t *testing.T) { - checks, err := newIntegrityChecks( - sha256Hex("hello"), - strings.Join([]string{sha256SRI("first"), sha512SRI("second"), sha384SRI("third"), sha512SRI("alternative")}, " "), - ) - if err != nil { - t.Fatal(err) - } - if len(checks.algorithms) != 5 { - t.Fatalf("algorithms = %v, want 5 entries", checks.algorithms) - } - if len(checks.native) != 4 { - t.Errorf("native digests = %d, want 4", len(checks.native)) - } -} - -func TestNewIntegrityChecksRejectsMalformedMetadata(t *testing.T) { - tests := []struct { - name string - contentHash string - native string - }{ - {name: "short content hash", contentHash: "abc123"}, - {name: "non-hex content hash", contentHash: strings.Repeat("z", sha256.Size*2)}, - {name: "missing SRI separator", native: "sha512"}, - {name: "malformed SRI base64", native: "sha512-not!base64"}, - {name: "wrong SRI length", native: "sha512-" + base64.StdEncoding.EncodeToString([]byte("short"))}, - {name: "unsupported SRI algorithm", native: "md5-1B2M2Y8AsgTpgAmY7PhCfg=="}, - {name: "invalid SRI alternative", native: sha512SRI("valid") + " sha384-nope"}, - } - for _, test := range tests { - t.Run(test.name, func(t *testing.T) { - if _, err := newIntegrityChecks(test.contentHash, test.native); err == nil { - t.Fatal("newIntegrityChecks returned nil error") - } - }) - } -} - -func TestVerifyingReader(t *testing.T) { - const data = "hello world" - goodSHA := sha256Hex(data) - goodSRI := sha512SRI(data) - - tests := []struct { - name string - hash string - sri string - wantCalls int - }{ - {name: "both match", hash: goodSHA, sri: goodSRI}, - {name: "SHA-256 only match", hash: goodSHA}, - {name: "SRI only match", sri: goodSRI}, - {name: "SHA-256 mismatch", hash: sha256Hex("other"), wantCalls: 1}, - {name: "SRI mismatch", sri: sha512SRI("other"), wantCalls: 1}, - {name: "both mismatch", hash: sha256Hex("other"), sri: sha512SRI("other"), wantCalls: 2}, - {name: "no checks"}, - } - - for _, test := range tests { - t.Run(test.name, func(t *testing.T) { - var calls []string - reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), test.hash, test.sri, - func(reason string) { calls = append(calls, reason) }) - - got, err := io.ReadAll(reader) - if err != nil { - t.Fatalf("ReadAll: %v", err) - } - if string(got) != data { - t.Errorf("data corrupted: got %q", got) - } - if err := reader.Close(); err != nil { - t.Fatalf("Close: %v", err) - } - if len(calls) != test.wantCalls { - t.Errorf("onMismatch called %d times, want %d: %v", len(calls), test.wantCalls, calls) - } - }) - } -} - -func TestVerifyingReaderUsesStrongestNativeAlgorithm(t *testing.T) { - const data = "artifact" - tests := []struct { - name string - native string - wantCalls int - }{ - { - name: "weaker match does not override stronger mismatch", - native: sha256SRI(data) + " " + sha512SRI("other"), - wantCalls: 1, - }, - { - name: "stronger match ignores weaker mismatch", - native: sha256SRI("other") + " " + sha512SRI(data), - }, - { - name: "same algorithm alternative matches", - native: sha512SRI("other") + " " + sha512SRI(data), - }, - } - for _, test := range tests { - t.Run(test.name, func(t *testing.T) { - var calls int - reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), "", test.native, func(string) { calls++ }) - if _, err := io.Copy(io.Discard, reader); err != nil { - t.Fatal(err) - } - if calls != test.wantCalls { - t.Errorf("onMismatch called %d times, want %d", calls, test.wantCalls) - } - }) - } -} - -func TestVerifyingReaderMismatchMessages(t *testing.T) { - const data = "actual" - wantHash := sha256Hex("expected") - wantSRI := sha512SRI("expected") - var reasons []string - reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), wantHash, wantSRI, - func(reason string) { reasons = append(reasons, reason) }) - if _, err := io.Copy(io.Discard, reader); err != nil { - t.Fatal(err) - } - if len(reasons) != 2 { - t.Fatalf("reasons = %v, want two", reasons) - } - wantContentReason := "content_hash: integrity mismatch: expected " + sha256SRI("expected") + ", calculated " + sha256SRI(data) - if reasons[0] != wantContentReason { - t.Errorf("content reason = %q, want %q", reasons[0], wantContentReason) - } - wantNativeReason := "integrity: integrity mismatch: expected " + wantSRI + ", calculated " + sha512SRI(data) - if reasons[1] != wantNativeReason { - t.Errorf("native reason = %q, want %q", reasons[1], wantNativeReason) - } -} - -func TestVerifyingReaderPassthrough(t *testing.T) { - source := io.NopCloser(strings.NewReader("x")) - reader := wrapIntegrityReader(t, source, "", "", func(string) { t.Fatal("should not be called") }) - if reader != source { - t.Error("expected passthrough when no hashes were provided") - } -} - -type closeTrackingReader struct { - io.Reader - closed bool -} - -func (r *closeTrackingReader) Close() error { - r.closed = true - return nil -} - -func TestVerifyingReaderPartialRead(t *testing.T) { - source := &closeTrackingReader{Reader: strings.NewReader("hello world")} - var calls int - reader := wrapIntegrityReader(t, source, sha256Hex("other"), "", func(string) { calls++ }) - - buffer := make([]byte, 5) - _, _ = reader.Read(buffer) - _ = reader.Close() - - if calls != 0 { - t.Errorf("onMismatch called %d times for partial read, want 0", calls) - } - if !source.closed { - t.Error("Close was not forwarded to the source") - } -} - -func TestVerifyingReaderNonEOFError(t *testing.T) { - var calls int - reader := wrapIntegrityReader(t, io.NopCloser(errorFixtureReader{}), sha256Hex("data"), "", func(string) { calls++ }) - if _, err := io.ReadAll(reader); !errors.Is(err, errIntegrityReadFixture) { - t.Fatalf("ReadAll error = %v", err) - } - if calls != 0 { - t.Errorf("onMismatch called %d times after non-EOF error", calls) - } -} - -var errIntegrityReadFixture = errors.New("integrity read fixture") - -type errorFixtureReader struct{} - -func (errorFixtureReader) Read(p []byte) (int, error) { - return copy(p, "data"), errIntegrityReadFixture -} - -func TestVerifyingReaderVerifyOnce(t *testing.T) { - var calls int - reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader("x")), sha256Hex("y"), "", func(string) { calls++ }) - _, _ = io.ReadAll(reader) - _ = reader.Close() - _ = reader.Close() - if calls != 1 { - t.Errorf("onMismatch called %d times, want 1", calls) - } -} diff --git a/internal/handler/julia.go b/internal/handler/julia.go deleted file mode 100644 index 211d092..0000000 --- a/internal/handler/julia.go +++ /dev/null @@ -1,351 +0,0 @@ -package handler - -import ( - "archive/tar" - "bufio" - "bytes" - "compress/gzip" - "context" - "fmt" - "io" - "net/http" - "regexp" - "strings" - "sync" - - "github.com/BurntSushi/toml" -) - -const ( - juliaUpstream = "https://pkg.julialang.org" - juliaGeneralRegistryUUID = "23338594-aafe-5451-b93e-139f81909106" - juliaArtifactName = "_artifact" - juliaRegistryName = "_registry" -) - -var ( - juliaHexPattern = regexp.MustCompile(`^[0-9a-f]{40,64}$`) - juliaUUIDPattern = regexp.MustCompile(`^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$`) -) - -// JuliaHandler handles Julia Pkg server protocol requests. -// -// See https://pkgdocs.julialang.org/v1/registries/ and the PkgServer.jl -// reference implementation. The protocol is content-addressed: registry, -// package and artifact resources are all identified by git tree hashes -// and are immutable once published. -type JuliaHandler struct { - proxy *Proxy - upstreamURL string - - mu sync.RWMutex - names map[string]string - namesHash string - loadMu sync.Mutex -} - -// NewJuliaHandler creates a new Julia Pkg server handler. -func NewJuliaHandler(proxy *Proxy, _ string) *JuliaHandler { - return &JuliaHandler{ - proxy: proxy, - upstreamURL: juliaUpstream, - names: make(map[string]string), - } -} - -// NewJuliaHandlerWithUpstream creates a Julia handler with a custom upstream. -func NewJuliaHandlerWithUpstream(proxy *Proxy, upstreamURL string) *JuliaHandler { - h := NewJuliaHandler(proxy, "") - h.upstreamURL = configuredUpstreamURL(upstreamURL, juliaUpstream) - return h -} - -// Routes returns the HTTP handler for Julia requests. -func (h *JuliaHandler) Routes() http.Handler { - mux := http.NewServeMux() - - mux.HandleFunc("GET /registries", h.handleRegistries) - mux.HandleFunc("GET /registries.eager", h.handleRegistries) - mux.HandleFunc("GET /registries.conservative", h.handleRegistries) - mux.HandleFunc("GET /registry/{uuid}/{hash}", h.handleRegistry) - mux.HandleFunc("GET /package/{uuid}/{hash}", h.handlePackage) - mux.HandleFunc("GET /artifact/{hash}", h.handleArtifact) - mux.HandleFunc("GET /meta", h.proxyUpstream) - - return mux -} - -// handleRegistries serves the list of available registries. This is the only -// mutable endpoint in the protocol so it goes through the metadata cache. -func (h *JuliaHandler) handleRegistries(w http.ResponseWriter, r *http.Request) { - cacheKey := strings.TrimPrefix(r.URL.Path, "/") - h.proxy.ProxyCached(w, r, h.upstreamURL+r.URL.Path, "julia", cacheKey, "*/*") -} - -// handleRegistry serves an immutable registry tarball and refreshes the -// UUID→name map from its Registry.toml. -func (h *JuliaHandler) handleRegistry(w http.ResponseWriter, r *http.Request) { - uuid := r.PathValue("uuid") - hash := r.PathValue("hash") - if !validJuliaUUID(uuid) || !juliaHexPattern.MatchString(hash) { - http.Error(w, "invalid registry reference", http.StatusBadRequest) - return - } - - h.proxy.Logger.Info("julia registry request", "uuid", uuid, "hash", hash) - - upstreamURL := h.upstreamURL + r.URL.Path - result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "julia", juliaRegistryName, hash, hash+".tar.gz", upstreamURL) - if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch registry") - return - } - - go h.refreshNamesFromRegistry(uuid, hash) - - ServeArtifact(w, result) -} - -// handlePackage serves an immutable package source tarball. -func (h *JuliaHandler) handlePackage(w http.ResponseWriter, r *http.Request) { - uuid := r.PathValue("uuid") - hash := r.PathValue("hash") - if !validJuliaUUID(uuid) || !juliaHexPattern.MatchString(hash) { - http.Error(w, "invalid package reference", http.StatusBadRequest) - return - } - - if err := h.ensureNames(r.Context()); err != nil { - h.proxy.Logger.Warn("julia name map unavailable, using uuid", "error", err) - } - name := h.resolveName(uuid) - - h.proxy.Logger.Info("julia package request", "name", name, "uuid", uuid, "hash", hash) - - upstreamURL := h.upstreamURL + r.URL.Path - result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "julia", name, hash, hash+".tar.gz", upstreamURL) - if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch package") - return - } - - ServeArtifact(w, result) -} - -// handleArtifact serves an immutable binary artifact tarball. Artifacts are -// anonymous content-addressed blobs with no associated package name. -func (h *JuliaHandler) handleArtifact(w http.ResponseWriter, r *http.Request) { - hash := r.PathValue("hash") - if !juliaHexPattern.MatchString(hash) { - http.Error(w, "invalid artifact hash", http.StatusBadRequest) - return - } - - h.proxy.Logger.Info("julia artifact request", "hash", hash) - - upstreamURL := h.upstreamURL + r.URL.Path - result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "julia", juliaArtifactName, hash, hash+".tar.gz", upstreamURL) - if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch artifact") - return - } - - ServeArtifact(w, result) -} - -// proxyUpstream forwards a request to the upstream Pkg server without caching. -func (h *JuliaHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) { - h.proxy.ProxyUpstream(w, r, h.upstreamURL+r.URL.Path, nil) -} - -// resolveName returns the human-readable package name for a UUID, falling -// back to the UUID itself if it is not present in the loaded registry. -func (h *JuliaHandler) resolveName(uuid string) string { - h.mu.RLock() - defer h.mu.RUnlock() - if name, ok := h.names[uuid]; ok { - return name - } - return uuid -} - -// ensureNames lazily populates the UUID→name map from the General registry. -// Returns immediately if the map is already populated; otherwise blocks until -// a single in-flight load completes. Failed loads are retried on the next call. -func (h *JuliaHandler) ensureNames(ctx context.Context) error { - if h.namesLoaded() { - return nil - } - - h.loadMu.Lock() - defer h.loadMu.Unlock() - - if h.namesLoaded() { - return nil - } - return h.loadNamesFromUpstream(ctx) -} - -func (h *JuliaHandler) namesLoaded() bool { - h.mu.RLock() - defer h.mu.RUnlock() - return len(h.names) > 0 -} - -// loadNamesFromUpstream fetches the current /registries listing, downloads the -// General registry tarball at its current hash, and parses Registry.toml. -func (h *JuliaHandler) loadNamesFromUpstream(ctx context.Context) error { - hash, err := h.fetchGeneralRegistryHash(ctx) - if err != nil { - return err - } - return h.loadRegistryTarball(ctx, juliaGeneralRegistryUUID, hash) -} - -// fetchGeneralRegistryHash reads /registries and returns the current tree hash -// for the General registry. -func (h *JuliaHandler) fetchGeneralRegistryHash(ctx context.Context) (string, error) { - req, err := http.NewRequestWithContext(ctx, http.MethodGet, h.upstreamURL+"/registries", nil) - if err != nil { - return "", err - } - resp, err := h.proxy.HTTPClient.Do(req) - if err != nil { - return "", err - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusOK { - return "", fmt.Errorf("upstream /registries returned %d", resp.StatusCode) - } - - scanner := bufio.NewScanner(resp.Body) - for scanner.Scan() { - uuid, hash, ok := parseRegistryLine(scanner.Text()) - if ok && uuid == juliaGeneralRegistryUUID { - return hash, nil - } - } - if err := scanner.Err(); err != nil { - return "", err - } - return "", fmt.Errorf("general registry not listed in /registries") -} - -// refreshNamesFromRegistry reloads the UUID→name map from a registry tarball -// that has just been cached. Errors are logged but do not affect the response. -func (h *JuliaHandler) refreshNamesFromRegistry(uuid, hash string) { - if uuid != juliaGeneralRegistryUUID { - return - } - h.mu.RLock() - current := h.namesHash - h.mu.RUnlock() - if current == hash { - return - } - if err := h.loadRegistryTarball(context.Background(), uuid, hash); err != nil { - h.proxy.Logger.Warn("failed to refresh julia name map", "error", err) - } -} - -// loadRegistryTarball downloads a registry tarball and replaces the name map -// with the contents of its Registry.toml. -func (h *JuliaHandler) loadRegistryTarball(ctx context.Context, uuid, hash string) error { - url := fmt.Sprintf("%s/registry/%s/%s", h.upstreamURL, uuid, hash) - req, err := http.NewRequestWithContext(ctx, http.MethodGet, url, nil) - if err != nil { - return err - } - resp, err := h.proxy.HTTPClient.Do(req) - if err != nil { - return err - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusOK { - return fmt.Errorf("upstream registry returned %d", resp.StatusCode) - } - - names, err := extractRegistryNames(resp.Body) - if err != nil { - return err - } - - h.mu.Lock() - h.names = names - h.namesHash = hash - h.mu.Unlock() - - h.proxy.Logger.Info("loaded julia registry name map", "packages", len(names), "hash", hash) - return nil -} - -// extractRegistryNames reads a gzipped registry tarball, finds Registry.toml -// at the root, and returns its [packages] table as a UUID→name map. -func extractRegistryNames(r io.Reader) (map[string]string, error) { - gz, err := gzip.NewReader(r) - if err != nil { - return nil, fmt.Errorf("opening gzip stream: %w", err) - } - defer func() { _ = gz.Close() }() - - tr := tar.NewReader(gz) - for { - hdr, err := tr.Next() - if err == io.EOF { - return nil, fmt.Errorf("no Registry.toml in tarball") - } - if err != nil { - return nil, err - } - if strings.TrimPrefix(hdr.Name, "./") != "Registry.toml" { - continue - } - - data, err := io.ReadAll(tr) - if err != nil { - return nil, err - } - return parseRegistryToml(data) - } -} - -type juliaRegistryFile struct { - Packages map[string]struct { - Name string `toml:"name"` - } `toml:"packages"` -} - -// parseRegistryToml decodes the [packages] table of a Registry.toml file. -func parseRegistryToml(data []byte) (map[string]string, error) { - var reg juliaRegistryFile - if _, err := toml.NewDecoder(bytes.NewReader(data)).Decode(®); err != nil { - return nil, fmt.Errorf("parsing Registry.toml: %w", err) - } - - names := make(map[string]string, len(reg.Packages)) - for uuid, pkg := range reg.Packages { - if pkg.Name != "" { - names[uuid] = pkg.Name - } - } - return names, nil -} - -// parseRegistryLine parses a single line from /registries of the form -// "/registry/{uuid}/{hash}" and returns the uuid and hash. -func parseRegistryLine(line string) (uuid, hash string, ok bool) { - line = strings.TrimSpace(line) - line = strings.TrimPrefix(line, "/registry/") - uuid, hash, found := strings.Cut(line, "/") - if !found || !validJuliaUUID(uuid) || !juliaHexPattern.MatchString(hash) { - return "", "", false - } - return uuid, hash, true -} - -// validJuliaUUID reports whether s looks like a lowercase RFC 4122 UUID. -func validJuliaUUID(s string) bool { - return juliaUUIDPattern.MatchString(s) -} diff --git a/internal/handler/julia_test.go b/internal/handler/julia_test.go deleted file mode 100644 index 68fb975..0000000 --- a/internal/handler/julia_test.go +++ /dev/null @@ -1,167 +0,0 @@ -package handler - -import ( - "archive/tar" - "bytes" - "compress/gzip" - "log/slog" - "net/http" - "net/http/httptest" - "testing" -) - -func TestJuliaParseRegistryLine(t *testing.T) { - tests := []struct { - line string - wantUUID string - wantHash string - wantOK bool - }{ - { - "/registry/23338594-aafe-5451-b93e-139f81909106/342327538ed6c1ec54c69fa145e7b6bf5934201e", - "23338594-aafe-5451-b93e-139f81909106", - "342327538ed6c1ec54c69fa145e7b6bf5934201e", - true, - }, - { - " /registry/23338594-aafe-5451-b93e-139f81909106/342327538ed6c1ec54c69fa145e7b6bf5934201e\n", - "23338594-aafe-5451-b93e-139f81909106", - "342327538ed6c1ec54c69fa145e7b6bf5934201e", - true, - }, - {"/registry/not-a-uuid/0000", "", "", false}, - {"junk", "", "", false}, - {"", "", "", false}, - } - - for _, tt := range tests { - uuid, hash, ok := parseRegistryLine(tt.line) - if uuid != tt.wantUUID || hash != tt.wantHash || ok != tt.wantOK { - t.Errorf("parseRegistryLine(%q) = (%q, %q, %v), want (%q, %q, %v)", - tt.line, uuid, hash, ok, tt.wantUUID, tt.wantHash, tt.wantOK) - } - } -} - -func TestJuliaValidUUID(t *testing.T) { - tests := []struct { - s string - want bool - }{ - {"23338594-aafe-5451-b93e-139f81909106", true}, - {"295af30f-e4ad-537b-8983-00126c2a3abe", true}, - {"23338594-AAFE-5451-b93e-139f81909106", false}, - {"23338594aafe5451b93e139f81909106", false}, - {"23338594-aafe-5451-b93e-139f8190910", false}, - {"23338594-aafe-5451-b93e-139f81909106-", false}, - {"23338594-gafe-5451-b93e-139f81909106", false}, - {"", false}, - } - - for _, tt := range tests { - if got := validJuliaUUID(tt.s); got != tt.want { - t.Errorf("validJuliaUUID(%q) = %v, want %v", tt.s, got, tt.want) - } - } -} - -func TestJuliaParseRegistryToml(t *testing.T) { - data := []byte(`name = "General" -uuid = "23338594-aafe-5451-b93e-139f81909106" - -[packages] -295af30f-e4ad-537b-8983-00126c2a3abe = { name = "Revise", path = "R/Revise" } -91a5bcdd-55d7-5caf-9e0b-520d859cae80 = { name = "Plots", path = "P/Plots" } -`) - - names, err := parseRegistryToml(data) - if err != nil { - t.Fatalf("parseRegistryToml: %v", err) - } - if got := names["295af30f-e4ad-537b-8983-00126c2a3abe"]; got != "Revise" { - t.Errorf("names[Revise uuid] = %q, want Revise", got) - } - if got := names["91a5bcdd-55d7-5caf-9e0b-520d859cae80"]; got != "Plots" { - t.Errorf("names[Plots uuid] = %q, want Plots", got) - } - if len(names) != 2 { - t.Errorf("len(names) = %d, want 2", len(names)) - } -} - -func TestJuliaExtractRegistryNames(t *testing.T) { - registryToml := `name = "General" -[packages] -295af30f-e4ad-537b-8983-00126c2a3abe = { name = "Revise", path = "R/Revise" } -` - var buf bytes.Buffer - gw := gzip.NewWriter(&buf) - tw := tar.NewWriter(gw) - - for _, f := range []struct{ name, body string }{ - {"R/Revise/Package.toml", "name = \"Revise\"\n"}, - {"Registry.toml", registryToml}, - } { - if err := tw.WriteHeader(&tar.Header{Name: f.name, Mode: 0o644, Size: int64(len(f.body))}); err != nil { - t.Fatalf("WriteHeader: %v", err) - } - if _, err := tw.Write([]byte(f.body)); err != nil { - t.Fatalf("Write: %v", err) - } - } - if err := tw.Close(); err != nil { - t.Fatalf("tar Close: %v", err) - } - if err := gw.Close(); err != nil { - t.Fatalf("gzip Close: %v", err) - } - - names, err := extractRegistryNames(bytes.NewReader(buf.Bytes())) - if err != nil { - t.Fatalf("extractRegistryNames: %v", err) - } - if got := names["295af30f-e4ad-537b-8983-00126c2a3abe"]; got != "Revise" { - t.Errorf("names[Revise uuid] = %q, want Revise", got) - } -} - -func TestJuliaResolveName(t *testing.T) { - h := &JuliaHandler{ - proxy: &Proxy{Logger: slog.Default()}, - names: map[string]string{ - "295af30f-e4ad-537b-8983-00126c2a3abe": "Revise", - }, - } - - if got := h.resolveName("295af30f-e4ad-537b-8983-00126c2a3abe"); got != "Revise" { - t.Errorf("resolveName(known) = %q, want Revise", got) - } - if got := h.resolveName("00000000-0000-0000-0000-000000000000"); got != "00000000-0000-0000-0000-000000000000" { - t.Errorf("resolveName(unknown) = %q, want uuid fallback", got) - } -} - -func TestJuliaRoutesValidation(t *testing.T) { - h := NewJuliaHandler(&Proxy{Logger: slog.Default()}, "") - routes := h.Routes() - - tests := []struct { - path string - want int - }{ - {"/package/not-a-uuid/342327538ed6c1ec54c69fa145e7b6bf5934201e", http.StatusBadRequest}, - {"/package/295af30f-e4ad-537b-8983-00126c2a3abe/short", http.StatusBadRequest}, - {"/registry/295af30f-e4ad-537b-8983-00126c2a3abe/zzzz", http.StatusBadRequest}, - {"/artifact/nothex", http.StatusBadRequest}, - {"/nope", http.StatusNotFound}, - } - - for _, tt := range tests { - req := httptest.NewRequest(http.MethodGet, tt.path, nil) - rr := httptest.NewRecorder() - routes.ServeHTTP(rr, req) - if rr.Code != tt.want { - t.Errorf("GET %s = %d, want %d", tt.path, rr.Code, tt.want) - } - } -} diff --git a/internal/handler/maven.go b/internal/handler/maven.go index 10e551e..86664a2 100644 --- a/internal/handler/maven.go +++ b/internal/handler/maven.go @@ -1,7 +1,6 @@ package handler import ( - "errors" "fmt" "net/http" "path" @@ -9,33 +8,23 @@ import ( ) const ( - mavenCentralUpstream = "https://repo1.maven.org/maven2" - gradlePluginPortalUpstream = "https://plugins.gradle.org/m2" - minMavenParts = 4 // group path segments + artifact + version + filename + mavenUpstream = "https://repo1.maven.org/maven2" + minMavenParts = 4 // group path segments + artifact + version + filename ) // MavenHandler handles Maven repository protocol requests. type MavenHandler struct { - proxy *Proxy - upstreamURL string - pluginPortalUpstreamURL string - proxyURL string + proxy *Proxy + upstreamURL string + proxyURL string } // NewMavenHandler creates a new Maven repository handler. -func NewMavenHandler(proxy *Proxy, proxyURL, upstreamURL, pluginPortalUpstreamURL string) *MavenHandler { - if strings.TrimSpace(upstreamURL) == "" { - upstreamURL = mavenCentralUpstream - } - if strings.TrimSpace(pluginPortalUpstreamURL) == "" { - pluginPortalUpstreamURL = gradlePluginPortalUpstream - } - +func NewMavenHandler(proxy *Proxy, proxyURL string) *MavenHandler { return &MavenHandler{ - proxy: proxy, - upstreamURL: strings.TrimSuffix(upstreamURL, "/"), - pluginPortalUpstreamURL: strings.TrimSuffix(pluginPortalUpstreamURL, "/"), - proxyURL: strings.TrimSuffix(proxyURL, "/"), + proxy: proxy, + upstreamURL: mavenUpstream, + proxyURL: strings.TrimSuffix(proxyURL, "/"), } } @@ -62,7 +51,8 @@ func (h *MavenHandler) handleRequest(w http.ResponseWriter, r *http.Request) { filename := path.Base(urlPath) if h.isMetadataFile(filename) { - h.handleMetadata(w, r, urlPath) + cacheKey := strings.ReplaceAll(urlPath, "/", "_") + h.proxy.ProxyCached(w, r, h.upstreamURL+r.URL.Path, "maven", cacheKey, "*/*") return } @@ -76,32 +66,6 @@ func (h *MavenHandler) handleRequest(w http.ResponseWriter, r *http.Request) { h.proxyUpstream(w, r) } -func (h *MavenHandler) handleMetadata(w http.ResponseWriter, r *http.Request, urlPath string) { - cacheKey := strings.ReplaceAll(urlPath, "/", "_") - upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, urlPath) - - body, contentType, err := h.proxy.FetchOrCacheMetadata(r.Context(), "maven", cacheKey, upstreamURL, "*/*") - if err != nil { - if errors.Is(err, ErrUpstreamNotFound) { - pluginPortalURL := fmt.Sprintf("%s/%s", h.pluginPortalUpstreamURL, urlPath) - h.proxy.Logger.Info("maven metadata unavailable in primary upstream, trying Gradle Plugin Portal", - "path", urlPath) - body, contentType, err = h.proxy.FetchOrCacheMetadata(r.Context(), "maven", cacheKey, pluginPortalURL, "*/*") - } - } - if err != nil { - if errors.Is(err, ErrUpstreamNotFound) { - http.Error(w, "not found", http.StatusNotFound) - return - } - h.proxy.Logger.Error("metadata fetch failed", "error", err) - http.Error(w, "failed to fetch from upstream", http.StatusBadGateway) - return - } - - h.proxy.writeMetadataCachedResponse(w, r, "maven", cacheKey, body, contentType) -} - // handleDownload serves an artifact file, fetching and caching from upstream if needed. func (h *MavenHandler) handleDownload(w http.ResponseWriter, r *http.Request, urlPath string) { // Parse Maven path: group/artifact/version/filename @@ -122,15 +86,8 @@ func (h *MavenHandler) handleDownload(w http.ResponseWriter, r *http.Request, ur result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "maven", name, version, filename, upstreamURL) if err != nil { - if errors.Is(err, ErrUpstreamNotFound) { - pluginPortalURL := fmt.Sprintf("%s/%s", h.pluginPortalUpstreamURL, urlPath) - h.proxy.Logger.Info("maven artifact not found in primary upstream, trying Gradle Plugin Portal", - "group", group, "artifact", artifact, "version", version, "filename", filename) - result, err = h.proxy.GetOrFetchArtifactFromURL(r.Context(), "maven", name, version, filename, pluginPortalURL) - } - } - if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch artifact") + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch artifact", http.StatusBadGateway) return } @@ -158,7 +115,7 @@ func (h *MavenHandler) parsePath(urlPath string) (group, artifact, version, file // isArtifactFile returns true if the filename looks like a Maven artifact. func (h *MavenHandler) isArtifactFile(filename string) bool { // Common artifact extensions - extensions := []string{".jar", ".war", ".ear", ".pom", ".aar", ".klib", ".module"} + extensions := []string{".jar", ".war", ".ear", ".pom", ".aar", ".klib"} for _, ext := range extensions { if strings.HasSuffix(filename, ext) { return true diff --git a/internal/handler/maven_test.go b/internal/handler/maven_test.go index 9ca5eb6..df6917c 100644 --- a/internal/handler/maven_test.go +++ b/internal/handler/maven_test.go @@ -52,7 +52,6 @@ func TestMavenIsArtifactFile(t *testing.T) { }{ {"guava-32.1.3-jre.jar", true}, {"guava-32.1.3-jre.pom", true}, - {"guava-32.1.3-jre.module", true}, {"app-1.0.war", true}, {"lib-1.0.aar", true}, {"maven-metadata.xml", false}, @@ -66,63 +65,3 @@ func TestMavenIsArtifactFile(t *testing.T) { } } } - -func TestMavenIsMetadataFile(t *testing.T) { - h := &MavenHandler{} - - tests := []struct { - name string - filename string - want bool - }{ - { - name: "pom is artifact, not metadata", - filename: "com.diffplug.spotless.gradle.plugin-8.4.0.pom", - want: false, - }, - { - name: "pom checksum is metadata", - filename: "com.diffplug.spotless.gradle.plugin-8.4.0.pom.sha1", - want: true, - }, - { - name: "metadata file", - filename: "maven-metadata.xml", - want: true, - }, - { - name: "metadata checksum", - filename: "maven-metadata.xml.sha256", - want: true, - }, - { - name: "jar checksum is metadata", - filename: "guava-32.1.3-jre.jar.sha1", - want: true, - }, - { - name: "asc signature is metadata", - filename: "guava-32.1.3-jre.jar.asc", - want: true, - }, - { - name: "regular jar is not metadata", - filename: "guava-32.1.3-jre.jar", - want: false, - }, - { - name: "pom checksum is metadata", - filename: "guava-32.1.3-jre.pom.sha1", - want: true, - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - got := h.isMetadataFile(tt.filename) - if got != tt.want { - t.Errorf("isMetadataFile(%q) = %v, want %v", tt.filename, got, tt.want) - } - }) - } -} diff --git a/internal/handler/metadata_encoding_test.go b/internal/handler/metadata_encoding_test.go deleted file mode 100644 index 10aab10..0000000 --- a/internal/handler/metadata_encoding_test.go +++ /dev/null @@ -1,200 +0,0 @@ -package handler - -import ( - "bytes" - "compress/gzip" - "net/http" - "net/http/httptest" - "strings" - "sync/atomic" - "testing" - "time" -) - -// gzipPayload returns a gzip-compressed copy of data, simulating an origin -// that stores pre-compressed index files. -func gzipPayload(t *testing.T, data []byte) []byte { - t.Helper() - var buf bytes.Buffer - zw := gzip.NewWriter(&buf) - if _, err := zw.Write(data); err != nil { - t.Fatalf("compressing payload: %v", err) - } - if err := zw.Close(); err != nil { - t.Fatalf("closing gzip writer: %v", err) - } - return buf.Bytes() -} - -// TestProxyCached_PreservesContentEncodedBytes covers issue #300: an upstream -// that serves a signed index with Content-Encoding: gzip must have its bytes -// cached and re-served verbatim, with the encoding header replayed, instead of -// being transparently decompressed by the HTTP client. -func TestProxyCached_PreservesContentEncodedBytes(t *testing.T) { - raw := gzipPayload(t, []byte("signed index payload")) - - var available atomic.Bool - available.Store(true) - var sawAcceptEncoding atomic.Value - var upstreamRequests atomic.Int32 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if !available.Load() { - http.Error(w, "unavailable", http.StatusServiceUnavailable) - return - } - upstreamRequests.Add(1) - sawAcceptEncoding.Store(r.Header.Get(headerAcceptEncoding)) - w.Header().Set(headerContentType, "application/octet-stream") - w.Header().Set(headerContentEncoding, "gzip") - _, _ = w.Write(raw) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = upstream.Client() - - serve := func() *httptest.ResponseRecorder { - w := httptest.NewRecorder() - r := httptest.NewRequest(http.MethodGet, "/index", nil) - proxy.ProxyCached(w, r, upstream.URL+"/index", "apk", "index-key", "*/*") - return w - } - - first := serve() - if first.Code != http.StatusOK { - t.Fatalf("first response status = %d, want 200: %s", first.Code, first.Body.String()) - } - if got, _ := sawAcceptEncoding.Load().(string); got != "identity" { - t.Errorf("upstream saw Accept-Encoding %q, want %q", got, "identity") - } - if !bytes.Equal(first.Body.Bytes(), raw) { - t.Errorf("first response altered the upstream bytes: got %d bytes, want %d", first.Body.Len(), len(raw)) - } - if got := first.Header().Get(headerContentEncoding); got != "gzip" { - t.Errorf("first response Content-Encoding = %q, want %q", got, "gzip") - } - - // Within the TTL and with the upstream down, the cached copy must be - // served with the same bytes and encoding. - available.Store(false) - second := serve() - if second.Code != http.StatusOK { - t.Fatalf("cached response status = %d, want 200: %s", second.Code, second.Body.String()) - } - if !bytes.Equal(second.Body.Bytes(), raw) { - t.Errorf("cached response altered the stored bytes") - } - if got := second.Header().Get(headerContentEncoding); got != "gzip" { - t.Errorf("cached response Content-Encoding = %q, want %q", got, "gzip") - } - if got := upstreamRequests.Load(); got != 1 { - t.Errorf("upstream requests = %d, want 1", got) - } -} - -// TestProxyCached_NoEncodingHeaderForIdentityResponses pins that ordinary -// responses do not grow a spurious Content-Encoding header. -func TestProxyCached_NoEncodingHeaderForIdentityResponses(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.Header().Set(headerContentType, contentTypeJSON) - _, _ = w.Write([]byte(`{"ok":true}`)) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = upstream.Client() - - w := httptest.NewRecorder() - r := httptest.NewRequest(http.MethodGet, "/meta", nil) - proxy.ProxyCached(w, r, upstream.URL+"/meta", "npm", "meta-key", contentTypeJSON) - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String()) - } - if got := w.Header().Get(headerContentEncoding); got != "" { - t.Errorf("Content-Encoding = %q, want empty", got) - } -} - -// TestProxyMetadataStream_PreservesSignedBytesWithoutClientEncoding pins the -// uncached streaming path (the default, since cache_metadata is off) for the -// realistic client that sends no Accept-Encoding: the proxy must request -// identity upstream so Go does not transparently decompress a signed index, -// and the raw bytes plus the Content-Encoding header must reach the client. -func TestProxyMetadataStream_PreservesSignedBytesWithoutClientEncoding(t *testing.T) { - raw := gzipPayload(t, []byte("streamed index payload")) - var sawAcceptEncoding string - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - sawAcceptEncoding = r.Header.Get(headerAcceptEncoding) - w.Header().Set(headerContentType, "application/octet-stream") - w.Header().Set(headerContentEncoding, "gzip") - _, _ = w.Write(raw) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = false - proxy.HTTPClient = upstream.Client() - - w := httptest.NewRecorder() - // No Accept-Encoding on the client request -- the apk/apt/dnf case. - r := httptest.NewRequest(http.MethodGet, "/index", nil) - proxy.ProxyCached(w, r, upstream.URL+"/index", "apk", "stream-key", "*/*") - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String()) - } - if sawAcceptEncoding != "identity" { - t.Errorf("upstream saw Accept-Encoding %q, want %q", sawAcceptEncoding, "identity") - } - if !bytes.Equal(w.Body.Bytes(), raw) { - t.Errorf("streamed response altered the upstream bytes: got %d bytes, want %d", w.Body.Len(), len(raw)) - } - if got := w.Header().Get(headerContentEncoding); got != "gzip" { - t.Errorf("Content-Encoding = %q, want %q", got, "gzip") - } -} - -// TestFetchOrCacheMetadata_DirectCallersKeepTransparentCompression pins that -// the parsing/rewriting ecosystems (npm, pypi, cargo, helm, ...) that call -// FetchOrCacheMetadata directly are NOT forced to identity: they keep Go's -// transparent transfer compression and receive decoded bytes, so a gzip-only -// upstream does not regress them (no wire-size blowup, no parse failures). -func TestFetchOrCacheMetadata_DirectCallersKeepTransparentCompression(t *testing.T) { - plaintext := []byte(`{"name":"demo","versions":{"1.0.0":{}}}`) - var sawAcceptEncoding string - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - sawAcceptEncoding = r.Header.Get(headerAcceptEncoding) - // Serve gzip only when the client accepts it, like a real CDN. - if strings.Contains(r.Header.Get(headerAcceptEncoding), "gzip") { - w.Header().Set(headerContentType, contentTypeJSON) - w.Header().Set(headerContentEncoding, "gzip") - _, _ = w.Write(gzipPayload(t, plaintext)) - return - } - w.Header().Set(headerContentType, contentTypeJSON) - _, _ = w.Write(plaintext) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = upstream.Client() - - body, _, err := proxy.FetchOrCacheMetadata(t.Context(), "npm", "demo", upstream.URL+"/demo", contentTypeJSON) - if err != nil { - t.Fatalf("FetchOrCacheMetadata() error = %v", err) - } - // The default transport adds Accept-Encoding: gzip and transparently - // decompresses, so the caller sees decoded JSON regardless of the wire form. - if sawAcceptEncoding == "identity" { - t.Errorf("direct caller forced identity; want transparent compression") - } - if !bytes.Equal(body, plaintext) { - t.Errorf("direct caller got %q, want decoded %q", body, plaintext) - } -} diff --git a/internal/handler/notfound_ecosystems_test.go b/internal/handler/notfound_ecosystems_test.go deleted file mode 100644 index bf3fe55..0000000 --- a/internal/handler/notfound_ecosystems_test.go +++ /dev/null @@ -1,143 +0,0 @@ -package handler - -import ( - "net/http" - "net/http/httptest" - "strings" - "testing" - - "github.com/git-pkgs/registries/fetch" -) - -func TestArtifactDownloadUpstreamNotFoundReturns404(t *testing.T) { - tests := []struct { - name string - path string - handler func(p *Proxy) http.Handler - }{ - {"debian", "/pool/main/n/nginx/nginx_1.18.0-6_amd64.deb", - func(p *Proxy) http.Handler { return NewDebianHandler(p, "http://localhost", "").Routes() }}, - {"rpm", "/releases/39/Everything/x86_64/os/Packages/n/nginx-1.24.0-1.fc39.x86_64.rpm", - func(p *Proxy) http.Handler { return NewRPMHandler(p, "http://localhost").Routes() }}, - {"apk", "/alpine/v3.22/main/x86_64/busybox-1.37.0-r12.apk", - func(p *Proxy) http.Handler { return NewAPKHandler(p, "http://localhost", nil).Routes() }}, - {"nuget", "/v3-flatcontainer/newtonsoft.json/13.0.3/newtonsoft.json.13.0.3.nupkg", - func(p *Proxy) http.Handler { return NewNuGetHandler(p, "http://localhost").Routes() }}, - {"pypi", "/packages/packages/ab/cd/ef0123456789/requests-2.31.0-py3-none-any.whl", - func(p *Proxy) http.Handler { - return NewPyPIHandlerWithUpstreams(p, "http://localhost", "", "").Routes() - }}, - {"cran", "/src/contrib/ggplot2_3.4.4.tar.gz", - func(p *Proxy) http.Handler { return NewCRANHandler(p, "http://localhost").Routes() }}, - {"conda", "/conda-forge/linux-64/numpy-1.26.0-py311_0.tar.bz2", - func(p *Proxy) http.Handler { return NewCondaHandler(p, "http://localhost").Routes() }}, - {"conan", "/v1/files/zlib/1.3.1/_/_/0/recipe/conan_sources.tgz", - func(p *Proxy) http.Handler { return NewConanHandler(p, "http://localhost").Routes() }}, - {"gem", "/gems/rails-7.1.0.gem", - func(p *Proxy) http.Handler { return NewGemHandler(p, "http://localhost").Routes() }}, - {"hex", "/tarballs/phoenix-1.7.10.tar", - func(p *Proxy) http.Handler { return NewHexHandler(p, "http://localhost").Routes() }}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - fetcher.fetchErr = fetch.ErrNotFound - - srv := httptest.NewServer(tt.handler(proxy)) - defer srv.Close() - - resp, err := http.Get(srv.URL + tt.path) - if err != nil { - t.Fatalf("request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusNotFound { - t.Errorf("want 404 for missing upstream artifact, got %d", resp.StatusCode) - } - }) - } -} - -func TestJuliaPackageUpstreamNotFoundReturns404(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - fetcher.fetchErr = fetch.ErrNotFound - - dead := httptest.NewServer(http.NotFoundHandler()) - defer dead.Close() - - h := NewJuliaHandler(proxy, "http://localhost") - h.upstreamURL = dead.URL - - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + - "/package/7876af07-990d-54b4-ab0e-23690620f79a/0123456789abcdef0123456789abcdef01234567") - if err != nil { - t.Fatalf("request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusNotFound { - t.Errorf("want 404 for missing upstream package, got %d", resp.StatusCode) - } -} - -func TestComposerDownloadUpstreamNotFoundReturns404(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - fetcher.fetchErr = fetch.ErrNotFound - - meta := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path == "/p2/monolog/monolog.json" { - _, _ = w.Write([]byte(`{ - "packages": { - "monolog/monolog": [ - {"version": "2.9.1", "dist": {"url": "https://example.com/monolog-2.9.1.zip", "type": "zip"}} - ] - } - }`)) - return - } - http.NotFound(w, r) - })) - defer meta.Close() - - h := &ComposerHandler{proxy: proxy, repoURL: meta.URL, proxyURL: "http://localhost"} - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + "/files/monolog/monolog/2.9.1/monolog-2.9.1.zip") - if err != nil { - t.Fatalf("request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusNotFound { - t.Errorf("want 404 for missing upstream dist, got %d", resp.StatusCode) - } -} - -func TestContainerBlobUpstreamNotFoundReturns404(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - fetcher.fetchErr = fetch.ErrNotFound - - h := &ContainerHandler{ - proxy: proxy, - registryURL: "https://registry-1.docker.io", - proxyURL: "http://localhost:8080", - } - - req := httptest.NewRequest(http.MethodGet, - "/library/nginx/blobs/sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusNotFound { - t.Errorf("want 404 for missing upstream blob, got %d; body: %s", w.Code, w.Body.String()) - } - if !strings.Contains(w.Body.String(), "BLOB_UNKNOWN") { - t.Errorf("want BLOB_UNKNOWN error code in body, got: %s", w.Body.String()) - } -} diff --git a/internal/handler/notfound_test.go b/internal/handler/notfound_test.go deleted file mode 100644 index 9ea38ac..0000000 --- a/internal/handler/notfound_test.go +++ /dev/null @@ -1,83 +0,0 @@ -package handler - -import ( - "context" - "errors" - "io" - "net/http" - "net/http/httptest" - "strings" - "testing" - - "github.com/git-pkgs/registries/fetch" -) - -func TestErrUpstreamNotFoundWrapsFetchErrNotFound(t *testing.T) { - if !errors.Is(ErrUpstreamNotFound, fetch.ErrNotFound) { - t.Fatal("ErrUpstreamNotFound does not wrap fetch.ErrNotFound") - } -} - -func TestGetOrFetchArtifactFromURL_NotFound(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - fetcher.fetchErr = fetch.ErrNotFound - - _, err := proxy.GetOrFetchArtifactFromURL(context.Background(), - "maven", "org.example:missing", "1.0", "missing-1.0.jar", - "http://upstream.test/org/example/missing/1.0/missing-1.0.jar") - - if !errors.Is(err, ErrUpstreamNotFound) { - t.Fatalf("want ErrUpstreamNotFound, got %v", err) - } -} - -func TestMavenHandler_UpstreamNotFoundReturns404(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - fetcher.fetchErr = fetch.ErrNotFound - - h := NewMavenHandler(proxy, "http://localhost", "http://upstream.test", "http://portal.test") - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + "/org/example/missing/1.0/missing-1.0.jar") - if err != nil { - t.Fatalf("request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusNotFound { - t.Errorf("want 404 for missing upstream artifact, got %d", resp.StatusCode) - } -} - -func TestMavenHandler_PluginPortalFallback(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - fetcher.fetchErrByURL = map[string]error{ - "http://upstream.test/org/example/plugin/1.0/plugin-1.0.jar": fetch.ErrNotFound, - } - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("portal artifact")), - ContentType: "application/java-archive", - } - - h := NewMavenHandler(proxy, "http://localhost", "http://upstream.test", "http://portal.test") - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + "/org/example/plugin/1.0/plugin-1.0.jar") - if err != nil { - t.Fatalf("request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusOK { - t.Fatalf("want 200 via plugin portal fallback, got %d", resp.StatusCode) - } - body, _ := io.ReadAll(resp.Body) - if string(body) != "portal artifact" { - t.Errorf("want portal artifact body, got %q", body) - } - if fetcher.fetchedURL != "http://portal.test/org/example/plugin/1.0/plugin-1.0.jar" { - t.Errorf("fallback did not hit plugin portal, last URL: %s", fetcher.fetchedURL) - } -} diff --git a/internal/handler/npm.go b/internal/handler/npm.go index 2cd8885..0585eda 100644 --- a/internal/handler/npm.go +++ b/internal/handler/npm.go @@ -9,11 +9,13 @@ import ( "sort" "strings" "time" + + "github.com/git-pkgs/purl" ) const ( npmUpstream = "https://registry.npmjs.org" - npmAcceptDefault = "application/vnd.npm.install-v1+json;q=1.0, application/json;q=0.8" + npmAbbreviatedCT = "application/vnd.npm.install-v1+json" scopedParts = 2 // scope + name in scoped packages ) @@ -25,14 +27,10 @@ type NPMHandler struct { } // NewNPMHandler creates a new npm protocol handler. -func NewNPMHandler(proxy *Proxy, proxyURL, upstreamURL string) *NPMHandler { - if strings.TrimSpace(upstreamURL) == "" { - upstreamURL = npmUpstream - } - +func NewNPMHandler(proxy *Proxy, proxyURL string) *NPMHandler { return &NPMHandler{ proxy: proxy, - upstreamURL: strings.TrimSuffix(upstreamURL, "/"), + upstreamURL: npmUpstream, proxyURL: strings.TrimSuffix(proxyURL, "/"), } } @@ -71,15 +69,10 @@ func (h *NPMHandler) handlePackageMetadata(w http.ResponseWriter, r *http.Reques upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, url.PathEscape(packageName)) - // Prefer the smaller abbreviated packument format but include application/json - // as a fallback so upstreams that reject the abbreviated type (e.g. JFrog - // Artifactory, which returns 406) can still respond with full metadata. - // When cooldown is enabled we must use full metadata exclusively because the - // abbreviated format omits the "time" map required for version age filtering. - // Operators can also force full metadata so clients that gate on publish - // age (for example Yarn's npmMinimalAgeGate) keep working through the proxy. - accept := npmAcceptDefault - if h.proxy.NPMFullMetadata || (h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled()) { + // Use abbreviated metadata when cooldown is disabled — it's much smaller + // (e.g. drizzle-orm: 4MB vs 92MB) but lacks the time map needed for cooldown. + accept := npmAbbreviatedCT + if h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled() { accept = contentTypeJSON } @@ -98,13 +91,13 @@ func (h *NPMHandler) handlePackageMetadata(w http.ResponseWriter, r *http.Reques if err != nil { // If rewriting fails, just proxy the original h.proxy.Logger.Warn("failed to rewrite metadata, proxying original", "error", err) - w.Header().Set(headerContentType, contentTypeJSON) + w.Header().Set("Content-Type", contentTypeJSON) w.WriteHeader(http.StatusOK) _, _ = w.Write(body) return } - w.Header().Set(headerContentType, contentTypeJSON) + w.Header().Set("Content-Type", contentTypeJSON) w.WriteHeader(http.StatusOK) _, _ = w.Write(rewritten) } @@ -141,7 +134,7 @@ func (h *NPMHandler) applyCooldownFiltering(metadata map[string]any, versions ma return } - packagePURL := canonicalPackagePURL("npm", packageName) + packagePURL := purl.MakePURLString("npm", packageName, "") for version := range versions { publishedStr, ok := timeMap[version].(string) @@ -270,103 +263,16 @@ func (h *NPMHandler) handleDownload(w http.ResponseWriter, r *http.Request) { h.proxy.Logger.Info("npm download request", "package", packageName, "version", version, "filename", filename) - if h.versionInCooldown(r, packageName, version) { - h.proxy.Logger.Info("cooldown: withholding npm tarball", - "package", packageName, "version", version) - JSONError(w, http.StatusNotFound, "version not found") - return - } - - downloadURL := fmt.Sprintf( - "%s/%s/-/%s", - h.upstreamURL, - escapeNPMDownloadPackage(packageName), - url.PathEscape(filename), - ) - result, err := h.proxy.GetOrFetchArtifactFromURL( - r.Context(), "npm", packageName, version, filename, downloadURL, - ) + result, err := h.proxy.GetOrFetchArtifact(r.Context(), "npm", packageName, version, filename) if err != nil { - switch { - case errors.Is(err, ErrUpstreamNotFound): - JSONError(w, http.StatusNotFound, "package not found") - case errors.Is(err, ErrArtifactBlocked): - JSONError(w, http.StatusForbidden, err.Error()) - default: - h.proxy.Logger.Error("failed to get artifact", "error", err) - JSONError(w, http.StatusBadGateway, "failed to fetch package") - } + h.proxy.Logger.Error("failed to get artifact", "error", err) + JSONError(w, http.StatusBadGateway, "failed to fetch package") return } ServeArtifact(w, result) } -// versionInCooldown reports whether a version is still inside the cooldown -// window. Filtering the packument is not enough on its own: tarball URLs are -// predictable and lockfiles record them directly, so `npm ci` reaches the -// download path without ever requesting metadata. -// -// A version's publish time is immutable, so the check reads the stored -// versions row first and only falls back to the packument for a version the -// proxy has never seen, persisting the parsed time so the packument is -// fetched and parsed at most once per version. A version with no usable -// publish time is allowed through, matching how applyCooldownFiltering -// treats it. -func (h *NPMHandler) versionInCooldown(r *http.Request, packageName, version string) bool { - if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() { - return false - } - - versionPURL := canonicalVersionPURL("npm", packageName, version) - if ver, err := h.proxy.DB.GetVersionByPURL(versionPURL); err == nil && ver != nil && ver.PublishedAt.Valid { - return !h.proxy.Cooldown.IsAllowed("npm", canonicalPackagePURL("npm", packageName), ver.PublishedAt.Time) - } - - upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, url.PathEscape(packageName)) - - body, _, err := h.proxy.FetchOrCacheMetadata(r.Context(), "npm", packageName, upstreamURL, contentTypeJSON) - if err != nil { - h.proxy.Logger.Warn("cooldown: could not fetch npm metadata for download check", - "package", packageName, "version", version, "error", err) - return false - } - - var metadata struct { - Time map[string]string `json:"time"` - } - if err := json.Unmarshal(body, &metadata); err != nil { - h.proxy.Logger.Warn("cooldown: could not parse npm metadata for download check", - "package", packageName, "version", version, "error", err) - return false - } - - published, ok := metadata.Time[version] - if !ok { - return false - } - - publishedAt, err := time.Parse(time.RFC3339, published) - if err != nil { - return false - } - - if err := h.proxy.DB.SetVersionPublishedAt(versionPURL, canonicalPackagePURL("npm", packageName), publishedAt); err != nil { - h.proxy.Logger.Warn("cooldown: could not store npm publish time", - "package", packageName, "version", version, "error", err) - } - - return !h.proxy.Cooldown.IsAllowed("npm", canonicalPackagePURL("npm", packageName), publishedAt) -} - -func escapeNPMDownloadPackage(packageName string) string { - scope, name, scoped := strings.Cut(packageName, "/") - if scoped && strings.HasPrefix(scope, "@") && len(scope) > 1 && name != "" && !strings.Contains(name, "/") { - return url.PathEscape(scope) + "/" + url.PathEscape(name) - } - return url.PathEscape(packageName) -} - // extractPackageName extracts the package name from the request path. // Handles both scoped (@scope/name) and unscoped (name) packages. func (h *NPMHandler) extractPackageName(r *http.Request) string { diff --git a/internal/handler/npm_test.go b/internal/handler/npm_test.go index c4a5f7e..1148ecc 100644 --- a/internal/handler/npm_test.go +++ b/internal/handler/npm_test.go @@ -2,18 +2,13 @@ package handler import ( "encoding/json" - "errors" - "io" "log/slog" "net/http" "net/http/httptest" - "strings" - "sync/atomic" "testing" "time" - "github.com/git-pkgs/cooldown" - "github.com/git-pkgs/registries/fetch" + "github.com/git-pkgs/proxy/internal/cooldown" ) const testVersion100 = "1.0.0" @@ -37,9 +32,9 @@ func TestNPMExtractVersionFromFilename(t *testing.T) { {"@babel/core", "core-7.23.0.tgz", "7.23.0"}, {"@types/node", "node-20.10.0.tgz", "20.10.0"}, {"express", "express-4.18.2.tgz", "4.18.2"}, - {"lodash", "lodash.tgz", ""}, // no version - {"lodash", "lodash-4.17.21.zip", ""}, // wrong extension - {"lodash", "other-4.17.21.tgz", ""}, // wrong package name + {"lodash", "lodash.tgz", ""}, // no version + {"lodash", "lodash-4.17.21.zip", ""}, // wrong extension + {"lodash", "other-4.17.21.tgz", ""}, // wrong package name } for _, tt := range tests { @@ -51,86 +46,6 @@ func TestNPMExtractVersionFromFilename(t *testing.T) { } } -func TestNPMHandlerUsesConfiguredUpstream(t *testing.T) { - t.Run("metadata", func(t *testing.T) { - var requestPath, authHeader string - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - requestPath = r.URL.Path - authHeader = r.Header.Get("Authorization") - if authHeader != "Bearer npm-token" { - w.WriteHeader(http.StatusUnauthorized) - return - } - w.Header().Set("Content-Type", "application/json") - _, _ = io.WriteString(w, `{"versions":{}}`) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.AuthForURL = func(string) (string, string) { - return "Authorization", "Bearer npm-token" - } - h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL+"/root/") - - req := httptest.NewRequest(http.MethodGet, "/testpkg", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) - } - if requestPath != "/root/testpkg" { - t.Errorf("upstream path = %q, want %q", requestPath, "/root/testpkg") - } - if authHeader != "Bearer npm-token" { - t.Errorf("Authorization = %q, want %q", authHeader, "Bearer npm-token") - } - }) - - t.Run("download", func(t *testing.T) { - proxy, _, _, artifactFetcher := setupTestProxy(t) - artifactFetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("package")), - ContentType: "application/gzip", - } - h := NewNPMHandler(proxy, "http://proxy.test", "https://npm.example.test/root/") - - req := httptest.NewRequest(http.MethodGet, "/testpkg/-/testpkg-1.0.0.tgz", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) - } - want := "https://npm.example.test/root/testpkg/-/testpkg-1.0.0.tgz" - if artifactFetcher.fetchedURL != want { - t.Errorf("fetched URL = %q, want %q", artifactFetcher.fetchedURL, want) - } - }) - - t.Run("scoped download", func(t *testing.T) { - proxy, _, _, artifactFetcher := setupTestProxy(t) - artifactFetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("package")), - ContentType: "application/gzip", - } - h := NewNPMHandler(proxy, "http://proxy.test", "https://npm.example.test/root/") - - req := httptest.NewRequest(http.MethodGet, "/@scope/name/-/name-1.0.0.tgz", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String()) - } - want := "https://npm.example.test/root/@scope/name/-/name-1.0.0.tgz" - if artifactFetcher.fetchedURL != want { - t.Errorf("fetched URL = %q, want %q", artifactFetcher.fetchedURL, want) - } - }) -} - func TestNPMRewriteMetadata(t *testing.T) { h := &NPMHandler{ proxy: testProxy(), @@ -398,7 +313,7 @@ func TestNPMHandlerUsesAbbreviatedMetadata(t *testing.T) { })) defer upstream.Close() - t.Run("no cooldown uses combined accept header", func(t *testing.T) { + t.Run("no cooldown uses abbreviated metadata", func(t *testing.T) { h := &NPMHandler{ proxy: testProxy(), upstreamURL: upstream.URL, @@ -409,12 +324,12 @@ func TestNPMHandlerUsesAbbreviatedMetadata(t *testing.T) { w := httptest.NewRecorder() h.handlePackageMetadata(w, req) - if gotAccept != npmAcceptDefault { - t.Errorf("Accept = %q, want %q", gotAccept, npmAcceptDefault) + if gotAccept != npmAbbreviatedCT { + t.Errorf("Accept = %q, want abbreviated metadata header", gotAccept) } }) - t.Run("cooldown enabled uses full metadata only", func(t *testing.T) { + t.Run("cooldown enabled uses full metadata", func(t *testing.T) { proxy := testProxy() proxy.Cooldown = &cooldown.Config{Default: "3d"} @@ -428,27 +343,8 @@ func TestNPMHandlerUsesAbbreviatedMetadata(t *testing.T) { w := httptest.NewRecorder() h.handlePackageMetadata(w, req) - if gotAccept != contentTypeJSON { - t.Errorf("Accept = %q, want %q (cooldown requires full metadata)", gotAccept, contentTypeJSON) - } - }) - - t.Run("full metadata option uses full metadata without cooldown", func(t *testing.T) { - proxy := testProxy() - proxy.NPMFullMetadata = true - - h := &NPMHandler{ - proxy: proxy, - upstreamURL: upstream.URL, - proxyURL: "http://proxy.local", - } - - req := httptest.NewRequest(http.MethodGet, "/testpkg", nil) - w := httptest.NewRecorder() - h.handlePackageMetadata(w, req) - - if gotAccept != contentTypeJSON { - t.Errorf("Accept = %q, want %q (npm_full_metadata requires full metadata)", gotAccept, contentTypeJSON) + if gotAccept == npmAbbreviatedCT { + t.Error("cooldown enabled should use full metadata, not abbreviated") } }) } @@ -475,237 +371,3 @@ func TestNPMHandlerMetadataNotFound(t *testing.T) { t.Errorf("status = %d, want %d", w.Code, http.StatusNotFound) } } - -func TestNPMDownloadCooldown(t *testing.T) { - now := time.Now() - packument := `{ - "name": "leftpad", - "dist-tags": {"latest": "2.0.0"}, - "time": { - "1.0.0": "` + now.Add(-30*24*time.Hour).Format(time.RFC3339) + `", - "2.0.0": "` + now.Add(-1*time.Hour).Format(time.RFC3339) + `" - }, - "versions": {"1.0.0": {}, "2.0.0": {}} - }` - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.Header().Set("Content-Type", contentTypeJSON) - _, _ = io.WriteString(w, packument) - })) - defer upstream.Close() - - tests := []struct { - name string - version string - wantStatus int - }{ - {"published before the window serves the tarball", testVersion100, http.StatusOK}, - {"published inside the window is withheld", "2.0.0", http.StatusNotFound}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.Cooldown = &cooldown.Config{Default: "7d"} - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("tarball data")), - ContentType: "application/octet-stream", - } - - h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + "/leftpad/-/leftpad-" + tt.version + ".tgz") - if err != nil { - t.Fatalf("request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != tt.wantStatus { - t.Errorf("status = %d, want %d", resp.StatusCode, tt.wantStatus) - } - if tt.wantStatus == http.StatusNotFound && fetcher.fetchCalled { - t.Error("fetched a version that is still inside the cooldown window") - } - }) - } -} - -func TestNPMDownloadCooldownDisabled(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - t.Error("metadata must not be fetched when cooldown is disabled") - w.WriteHeader(http.StatusInternalServerError) - })) - defer upstream.Close() - - proxy, _, _, fetcher := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("tarball data")), - ContentType: "application/octet-stream", - } - - h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL) - - if h.versionInCooldown(httptest.NewRequest(http.MethodGet, "/", nil), "leftpad", testVersion100) { - t.Error("versionInCooldown = true, want false when cooldown is not configured") - } -} - -func TestNPMDownloadCooldownUsesStoredPublishTime(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - t.Error("metadata must not be fetched when the publish time is already stored") - w.WriteHeader(http.StatusInternalServerError) - })) - defer upstream.Close() - - tests := []struct { - name string - version string - publishedAt time.Time - wantStatus int - }{ - {"stored time before the window serves the tarball", testVersion100, time.Now().Add(-30 * 24 * time.Hour), http.StatusOK}, - {"stored time inside the window is withheld", "2.0.0", time.Now().Add(-1 * time.Hour), http.StatusNotFound}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - proxy, db, _, fetcher := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.Cooldown = &cooldown.Config{Default: "7d"} - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("tarball data")), - ContentType: "application/octet-stream", - } - - if err := db.SetVersionPublishedAt("pkg:npm/leftpad@"+tt.version, "pkg:npm/leftpad", tt.publishedAt); err != nil { - t.Fatalf("seeding publish time failed: %v", err) - } - - h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + "/leftpad/-/leftpad-" + tt.version + ".tgz") - if err != nil { - t.Fatalf("request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != tt.wantStatus { - t.Errorf("status = %d, want %d", resp.StatusCode, tt.wantStatus) - } - }) - } -} - -func TestNPMDownloadCooldownFetchesMetadataOnce(t *testing.T) { - now := time.Now() - packument := `{ - "name": "leftpad", - "dist-tags": {"latest": "1.0.0"}, - "time": { - "1.0.0": "` + now.Add(-30*24*time.Hour).Format(time.RFC3339) + `" - }, - "versions": {"1.0.0": {}} - }` - - var metadataRequests atomic.Int64 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - metadataRequests.Add(1) - w.Header().Set("Content-Type", contentTypeJSON) - _, _ = io.WriteString(w, packument) - })) - defer upstream.Close() - - proxy, _, _, fetcher := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.Cooldown = &cooldown.Config{Default: "7d"} - - h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL) - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - // The first download parses the packument once and persists the publish - // time; caching the artifact afterwards upserts the versions row without a - // publish time, which must not erase the stored value. The second download - // must answer from the stored time alone. - for i := 0; i < 2; i++ { - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("tarball data")), - ContentType: "application/octet-stream", - } - resp, err := http.Get(srv.URL + "/leftpad/-/leftpad-" + testVersion100 + ".tgz") - if err != nil { - t.Fatalf("request %d failed: %v", i+1, err) - } - _ = resp.Body.Close() - if resp.StatusCode != http.StatusOK { - t.Fatalf("request %d status = %d, want %d", i+1, resp.StatusCode, http.StatusOK) - } - } - - if got := metadataRequests.Load(); got != 1 { - t.Errorf("metadata requests = %d, want 1", got) - } -} - -// TestNPMDownloadErrorResponsesAreJSON guards against a regression where -// routing handleDownload's error path through the shared serveArtifactError -// helper silently switched npm's 404/502 tarball error bodies from JSON to -// plain text; npm clients expect a JSON {"error": "..."} body on every -// download failure, including the newer scan-blocked (403) case. -func TestNPMDownloadErrorResponsesAreJSON(t *testing.T) { - tests := []struct { - name string - fetchErr error - blocked bool - wantStatus int - }{ - {"upstream not found", fetch.ErrNotFound, false, http.StatusNotFound}, - {"upstream failure", errors.New("connection refused"), false, http.StatusBadGateway}, - {"blocked by scan", nil, true, http.StatusForbidden}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - if tt.blocked { - proxy.Scanners = newTestScanGroup(t, newTestScanServer(t, false, "malware detected").URL, false) - } - fetcher.fetchErr = tt.fetchErr - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("tarball data")), - ContentType: "application/octet-stream", - } - - h := NewNPMHandler(proxy, "http://proxy.test", "http://upstream.invalid") - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + "/leftpad/-/leftpad-1.0.0.tgz") - if err != nil { - t.Fatalf("request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != tt.wantStatus { - t.Errorf("status = %d, want %d", resp.StatusCode, tt.wantStatus) - } - if ct := resp.Header.Get("Content-Type"); ct != contentTypeJSON { - t.Errorf("Content-Type = %q, want %q", ct, contentTypeJSON) - } - var body map[string]any - if err := json.NewDecoder(resp.Body).Decode(&body); err != nil { - t.Fatalf("response body is not valid JSON: %v", err) - } - if _, ok := body["error"]; !ok { - t.Errorf("response body %v missing \"error\" key", body) - } - }) - } -} diff --git a/internal/handler/nuget.go b/internal/handler/nuget.go index 3216f23..615b0d2 100644 --- a/internal/handler/nuget.go +++ b/internal/handler/nuget.go @@ -7,18 +7,19 @@ import ( "io" "net/http" "strings" + "time" + + "github.com/git-pkgs/purl" ) const ( - nugetUpstream = "https://api.nuget.org" - nugetSearchUpstream = "https://azuresearch-usnc.nuget.org" + nugetUpstream = "https://api.nuget.org" ) // NuGetHandler handles NuGet V3 API protocol requests. type NuGetHandler struct { proxy *Proxy upstreamURL string - searchURL string proxyURL string } @@ -27,20 +28,10 @@ func NewNuGetHandler(proxy *Proxy, proxyURL string) *NuGetHandler { return &NuGetHandler{ proxy: proxy, upstreamURL: nugetUpstream, - searchURL: nugetSearchUpstream, proxyURL: strings.TrimSuffix(proxyURL, "/"), } } -// NewNuGetHandlerWithUpstreams creates a NuGet handler with custom API and -// search upstreams. -func NewNuGetHandlerWithUpstreams(proxy *Proxy, proxyURL, upstreamURL, searchURL string) *NuGetHandler { - h := NewNuGetHandler(proxy, proxyURL) - h.upstreamURL = configuredUpstreamURL(upstreamURL, nugetUpstream) - h.searchURL = configuredUpstreamURL(searchURL, nugetSearchUpstream) - return h -} - // Routes returns the HTTP handler for NuGet requests. func (h *NuGetHandler) Routes() http.Handler { mux := http.NewServeMux() @@ -50,12 +41,10 @@ func (h *NuGetHandler) Routes() http.Handler { // Package content (downloads) mux.HandleFunc("GET /v3-flatcontainer/{id}/{version}/{filename}", h.handleDownload) - mux.HandleFunc("GET /v3-flatcontainer/{id}/index.json", h.handleVersionList) + mux.HandleFunc("GET /v3-flatcontainer/{id}/index.json", h.proxyUpstream) // Registration (package metadata) - use prefix matching since {version}.json isn't allowed - for _, prefix := range nugetRegistrationPrefixes { - mux.HandleFunc("GET "+prefix, h.handleRegistration) - } + mux.HandleFunc("GET /v3/registration5-gz-semver2/", h.handleRegistration) // Search mux.HandleFunc("GET /query", h.proxyUpstream) @@ -85,17 +74,13 @@ func (h *NuGetHandler) handleServiceIndex(w http.ResponseWriter, r *http.Request rewritten, err := h.rewriteServiceIndex(body) if err != nil { - if h.cooldownEnabled() { - h.nugetMetadataError(w, err) - return - } h.proxy.Logger.Warn("failed to rewrite service index, proxying original", "error", err) - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") _, _ = w.Write(body) return } - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") _, _ = w.Write(rewritten) } @@ -120,35 +105,189 @@ func (h *NuGetHandler) rewriteServiceIndex(body []byte) ([]byte, error) { id, _ := rmap["@id"].(string) rtype, _ := rmap["@type"].(string) - // Rewrite URLs for services we proxy. The service type determines the - // local route because an upstream index may advertise a different host. - if id != "" { - rmap["@id"] = h.rewriteNuGetURL(id, rtype) + // Rewrite URLs for services we proxy + if id != "" && h.shouldRewriteService(rtype) { + newURL := h.rewriteNuGetURL(id) + rmap["@id"] = newURL } } return json.Marshal(index) } -// rewriteNuGetURL rewrites a NuGet service URL based on its advertised type. -// Service types the proxy does not handle are returned unchanged. -func (h *NuGetHandler) rewriteNuGetURL(origURL, serviceType string) string { - switch serviceType { - case "PackageBaseAddress/3.0.0": - return h.proxyURL + "/nuget/v3-flatcontainer/" - case "RegistrationsBaseUrl", "RegistrationsBaseUrl/3.0.0-beta", "RegistrationsBaseUrl/3.0.0-rc": - return h.proxyURL + "/nuget/v3/registration5-semver1/" - case "RegistrationsBaseUrl/3.4.0": - return h.proxyURL + "/nuget/v3/registration5-gz-semver1/" - case "RegistrationsBaseUrl/3.6.0", "RegistrationsBaseUrl/Versioned": - return h.proxyURL + "/nuget/v3/registration5-gz-semver2/" - case "SearchQueryService", "SearchQueryService/3.0.0-rc", "SearchQueryService/3.5.0": - return h.proxyURL + "/nuget/query" - case "SearchAutocompleteService", "SearchAutocompleteService/3.5.0": - return h.proxyURL + "/nuget/autocomplete" - default: - return origURL +// shouldRewriteService returns true if the service type should be rewritten. +func (h *NuGetHandler) shouldRewriteService(serviceType string) bool { + // Rewrite package content and registration services + rewriteTypes := []string{ + "PackageBaseAddress/3.0.0", + "RegistrationsBaseUrl/3.6.0", + "RegistrationsBaseUrl/Versioned", + "SearchQueryService", + "SearchQueryService/3.0.0-rc", + "SearchQueryService/3.5.0", + "SearchAutocompleteService", + "SearchAutocompleteService/3.5.0", } + + for _, t := range rewriteTypes { + if serviceType == t { + return true + } + } + return false +} + +// rewriteNuGetURL rewrites a NuGet API URL to point at this proxy. +func (h *NuGetHandler) rewriteNuGetURL(origURL string) string { + // Map known NuGet API endpoints to our proxy paths + replacements := map[string]string{ + "https://api.nuget.org/v3-flatcontainer/": h.proxyURL + "/nuget/v3-flatcontainer/", + "https://api.nuget.org/v3/registration5-gz-semver2/": h.proxyURL + "/nuget/v3/registration5-gz-semver2/", + "https://azuresearch-usnc.nuget.org/query": h.proxyURL + "/nuget/query", + "https://azuresearch-usnc.nuget.org/autocomplete": h.proxyURL + "/nuget/autocomplete", + } + + for old, new := range replacements { + if strings.HasPrefix(origURL, old) { + return strings.Replace(origURL, old, new, 1) + } + } + + return origURL +} + +// handleRegistration proxies NuGet registration pages, applying cooldown filtering. +func (h *NuGetHandler) handleRegistration(w http.ResponseWriter, r *http.Request) { + if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() { + h.proxyUpstream(w, r) + return + } + + upstreamURL := h.buildUpstreamURL(r) + + h.proxy.Logger.Debug("fetching registration for cooldown filtering", "url", upstreamURL) + + req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil) + if err != nil { + http.Error(w, "failed to create request", http.StatusInternalServerError) + return + } + req.Header.Set("Accept-Encoding", "gzip") + + resp, err := h.proxy.HTTPClient.Do(req) + if err != nil { + h.proxy.Logger.Error("upstream request failed", "error", err) + http.Error(w, "upstream request failed", http.StatusBadGateway) + return + } + defer func() { _ = resp.Body.Close() }() + + if resp.StatusCode != http.StatusOK { + for k, vv := range resp.Header { + for _, v := range vv { + w.Header().Add(k, v) + } + } + w.WriteHeader(resp.StatusCode) + _, _ = io.Copy(w, resp.Body) + return + } + + body, err := ReadMetadata(resp.Body) + if err != nil { + http.Error(w, "failed to read response", http.StatusInternalServerError) + return + } + + filtered, err := h.applyCooldownFiltering(body) + if err != nil { + h.proxy.Logger.Warn("failed to filter registration, proxying original", "error", err) + w.Header().Set("Content-Type", "application/json") + _, _ = w.Write(body) + return + } + + w.Header().Set("Content-Type", "application/json") + _, _ = w.Write(filtered) +} + +// applyCooldownFiltering filters versions from NuGet registration pages +// that are too recently published. +func (h *NuGetHandler) applyCooldownFiltering(body []byte) ([]byte, error) { + if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() { + return body, nil + } + + var registration map[string]any + if err := json.Unmarshal(body, ®istration); err != nil { + return nil, err + } + + pages, ok := registration["items"].([]any) + if !ok { + return body, nil + } + + for _, page := range pages { + pageMap, ok := page.(map[string]any) + if !ok { + continue + } + + items, ok := pageMap["items"].([]any) + if !ok { + continue + } + + filtered := items[:0] + for _, item := range items { + itemMap, ok := item.(map[string]any) + if !ok { + continue + } + + catalogEntry, ok := itemMap["catalogEntry"].(map[string]any) + if !ok { + filtered = append(filtered, item) + continue + } + + version, _ := catalogEntry["version"].(string) + id, _ := catalogEntry["id"].(string) + publishedStr, _ := catalogEntry["published"].(string) + + if publishedStr == "" { + filtered = append(filtered, item) + continue + } + + publishedAt, err := time.Parse(time.RFC3339, publishedStr) + if err != nil { + // NuGet uses a slightly non-standard format, try parsing with fractional seconds + publishedAt, err = time.Parse("2006-01-02T15:04:05.999-07:00", publishedStr) + if err != nil { + filtered = append(filtered, item) + continue + } + } + + packagePURL := purl.MakePURLString("nuget", strings.ToLower(id), "") + + if !h.proxy.Cooldown.IsAllowed("nuget", packagePURL, publishedAt) { + h.proxy.Logger.Info("cooldown: filtering nuget version", + "package", id, "version", version, + "published", publishedStr) + continue + } + + filtered = append(filtered, item) + } + + pageMap["items"] = filtered + pageMap["count"] = len(filtered) + } + + return json.Marshal(registration) } // handleDownload serves a package file, fetching and caching from upstream if needed. @@ -162,18 +301,6 @@ func (h *NuGetHandler) handleDownload(w http.ResponseWriter, r *http.Request) { return } - if h.cooldownEnabled() { - allowed, err := h.nugetDownloadAllowed(r.Context(), id, version) - if err != nil { - h.nugetMetadataError(w, err) - return - } - if !allowed { - JSONError(w, http.StatusNotFound, "version not found") - return - } - } - // Only cache .nupkg files if !strings.HasSuffix(filename, ".nupkg") { h.proxyUpstream(w, r) @@ -189,7 +316,8 @@ func (h *NuGetHandler) handleDownload(w http.ResponseWriter, r *http.Request) { result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "nuget", name, version, filename, upstreamURL) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch package") + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch package", http.StatusBadGateway) return } @@ -210,8 +338,8 @@ func (h *NuGetHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) { } // Copy accept-encoding for compression - if ae := r.Header.Get(headerAcceptEncoding); ae != "" { - req.Header.Set(headerAcceptEncoding, ae) + if ae := r.Header.Get("Accept-Encoding"); ae != "" { + req.Header.Set("Accept-Encoding", ae) } resp, err := h.proxy.HTTPClient.Do(req) @@ -238,7 +366,7 @@ func (h *NuGetHandler) buildUpstreamURL(r *http.Request) string { // Handle query and autocomplete which go to azuresearch if strings.HasPrefix(path, "/query") || strings.HasPrefix(path, "/autocomplete") { - return h.searchURL + path + "?" + r.URL.RawQuery + return "https://azuresearch-usnc.nuget.org" + path + "?" + r.URL.RawQuery } return h.upstreamURL + path diff --git a/internal/handler/nuget_cooldown.go b/internal/handler/nuget_cooldown.go deleted file mode 100644 index 6b95ae9..0000000 --- a/internal/handler/nuget_cooldown.go +++ /dev/null @@ -1,374 +0,0 @@ -package handler - -import ( - "bytes" - "compress/gzip" - "context" - "crypto/sha256" - "encoding/json" - "errors" - "fmt" - "net/http" - "net/url" - "slices" - "strings" - "time" -) - -var nugetRegistrationPrefixes = []string{ - "/v3/registration5-semver1/", - "/v3/registration5-gz-semver1/", - "/v3/registration5-gz-semver2/", -} - -var nugetArtifactPrefixes = append([]string{"/v3-flatcontainer/"}, nugetRegistrationPrefixes...) - -const nugetRegistrationPath = "/v3/registration5-gz-semver2/" - -func (h *NuGetHandler) cooldownEnabled() bool { - return h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled() -} - -func (h *NuGetHandler) nugetCooldownApplies(id string) bool { - return h.cooldownEnabled() && h.proxy.Cooldown.For("nuget", canonicalPackagePURL("nuget", strings.ToLower(id))) > 0 -} - -// Cache upstream documents, not filtered results, so policy changes and elapsed -// time take effect even while metadata is fresh. Include the upstream in the key. -func (h *NuGetHandler) nugetMetadata(ctx context.Context, path string) (map[string]any, error) { - target := h.upstreamURL + path - key := fmt.Sprintf("_cooldown/%x", sha256.Sum256([]byte(target))) - var document map[string]any - validate := func(body []byte) error { - var err error - document, err = h.decodeNuGetMetadata(body) - return err - } - _, _, _, err := h.proxy.fetchOrCacheMetadata(ctx, "nuget", key, target, "", validate) - if err != nil { - return nil, err - } - return document, nil -} - -func (h *NuGetHandler) decodeNuGetMetadata(body []byte) (map[string]any, error) { - // Normally the HTTP transport decodes gzip. Also support compressed cached - // bytes and clients with transparent decompression disabled, with the same - // metadata limit applied to the decompressed document. - if bytes.HasPrefix(body, []byte{0x1f, 0x8b}) { - reader, err := gzip.NewReader(bytes.NewReader(body)) - if err != nil { - return nil, err - } - defer func() { _ = reader.Close() }() - body, err = h.proxy.ReadMetadata(reader) - if err != nil { - return nil, err - } - } - var document map[string]any - if err := json.Unmarshal(body, &document); err != nil { - return nil, fmt.Errorf("parsing NuGet metadata: %w", err) - } - if document == nil { - return nil, fmt.Errorf("empty NuGet metadata") - } - return document, nil -} - -// Prefer semver2, but a configured source may advertise only an older hive. -// Retry only advertised aliases on 404; transport/validation errors must not -// silently switch to a hive with less complete metadata. Keep requests on the -// configured upstream, consistent with the service-index route rewriting. -func (h *NuGetHandler) nugetRegistrationMetadata(ctx context.Context, suffix string) (map[string]any, string, error) { - path := nugetRegistrationPath + suffix - document, err := h.nugetMetadata(ctx, path) - if !errors.Is(err, ErrUpstreamNotFound) { - return document, path, err - } - index, indexErr := h.nugetMetadata(ctx, "/v3/index.json") - if indexErr != nil { - return nil, path, indexErr - } - resources, _ := index["resources"].([]any) - seen := map[string]bool{nugetRegistrationPath: true} - for _, resource := range resources { - entry, _ := resource.(map[string]any) - service, _ := entry["@type"].(string) - id, _ := entry["@id"].(string) - if id == "" || !strings.HasPrefix(service, "RegistrationsBaseUrl") { - continue - } - prefix := strings.TrimPrefix(h.rewriteNuGetURL(id, service), h.proxyURL+"/nuget") - if !slices.Contains(nugetRegistrationPrefixes, prefix) || seen[prefix] { - continue - } - seen[prefix] = true - path = prefix + suffix - document, err = h.nugetMetadata(ctx, path) - if !errors.Is(err, ErrUpstreamNotFound) { - return document, path, err - } - } - return nil, path, err -} - -func (h *NuGetHandler) nugetMetadataError(w http.ResponseWriter, err error) { - if errors.Is(err, ErrUpstreamNotFound) { - JSONError(w, http.StatusNotFound, "package metadata not found") - return - } - h.proxy.Logger.Warn("failed to process NuGet metadata", "error", err) - JSONError(w, http.StatusBadGateway, "failed to process package metadata") -} - -func (h *NuGetHandler) handleVersionList(w http.ResponseWriter, r *http.Request) { - if !h.cooldownEnabled() { - h.proxyUpstream(w, r) - return - } - id := strings.ToLower(r.PathValue("id")) - document, err := h.nugetMetadata(r.Context(), "/v3-flatcontainer/"+url.PathEscape(id)+"/index.json") - if err != nil { - h.nugetMetadataError(w, err) - return - } - blocked := make(map[string]bool) - // A globally enabled policy may still exempt this package or ecosystem. - // Keep metadata caching, but do not require publication data in that case. - if h.nugetCooldownApplies(id) { - registration, registrationPath, err := h.nugetRegistrationMetadata(r.Context(), url.PathEscape(id)+"/index.json") - if err == nil { - err = h.expandNuGetPages(r.Context(), registration, registrationPath) - } - if err != nil { - h.nugetMetadataError(w, err) - return - } - h.collectNuGetBlockedVersions(registration, id, blocked) - } - versions, ok := document["versions"].([]any) - if !ok { - h.nugetMetadataError(w, fmt.Errorf("missing NuGet versions")) - return - } - filtered := make([]any, 0, len(versions)) - for _, value := range versions { - version, ok := value.(string) - if !ok { - h.nugetMetadataError(w, fmt.Errorf("invalid NuGet version")) - return - } - if !blocked[nugetVersionKey(version)] { - filtered = append(filtered, value) - } - } - document["versions"] = filtered - w.Header().Set(headerContentType, contentTypeJSON) - _ = json.NewEncoder(w).Encode(document) -} - -func nugetVersionKey(version string) string { - version, _, _ = strings.Cut(version, "+") - return strings.ToLower(version) -} - -func (h *NuGetHandler) nugetDownloadAllowed(ctx context.Context, id, version string) (bool, error) { - if !h.nugetCooldownApplies(id) { - return true, nil - } - suffix := url.PathEscape(strings.ToLower(id)) + "/" + url.PathEscape(nugetVersionKey(version)) + ".json" - leaf, _, err := h.nugetRegistrationMetadata(ctx, suffix) - if err != nil { - return false, err - } - return h.nugetLeafAllowed(leaf, id), nil -} - -// A standalone leaf has published at its root; leaves embedded in pages carry -// it in catalogEntry. Missing/invalid timestamps retain the existing permissive -// behavior, but fetch and JSON errors must not bypass the policy. -func (h *NuGetHandler) nugetLeafAllowed(leaf map[string]any, id string) bool { - if !h.cooldownEnabled() { - return true - } - entry := nugetCatalogEntry(leaf) - if id == "" { - id, _ = entry["id"].(string) - } - published, _ := entry["published"].(string) - when, err := time.Parse(time.RFC3339, published) - if err != nil { - return true - } - return h.proxy.Cooldown.IsAllowed("nuget", canonicalPackagePURL("nuget", strings.ToLower(id)), when) -} - -func nugetCatalogEntry(leaf map[string]any) map[string]any { - if entry, ok := leaf["catalogEntry"].(map[string]any); ok { - return entry - } - return leaf -} - -func (h *NuGetHandler) collectNuGetBlockedVersions(document map[string]any, id string, blocked map[string]bool) { - entry := nugetCatalogEntry(document) - if version, ok := entry["version"].(string); ok && !h.nugetLeafAllowed(document, id) { - blocked[nugetVersionKey(version)] = true - } - items, _ := document["items"].([]any) - for _, item := range items { - if child, ok := item.(map[string]any); ok { - h.collectNuGetBlockedVersions(child, id, blocked) - } - } -} - -func (h *NuGetHandler) handleRegistration(w http.ResponseWriter, r *http.Request) { - if !h.cooldownEnabled() { - h.proxyUpstream(w, r) - return - } - id := nugetRegistrationID(r.URL.Path) - applyCooldown := h.nugetCooldownApplies(id) - document, err := h.nugetMetadata(r.Context(), r.URL.Path) - if err == nil && applyCooldown { - err = h.expandNuGetPages(r.Context(), document, r.URL.Path) - } - if err != nil { - h.nugetMetadataError(w, err) - return - } - _, hasItems := document["items"] - if applyCooldown && !h.filterNuGetRegistration(document, id) && !hasItems { - JSONError(w, http.StatusNotFound, "version not found") - return - } - h.rewriteNuGetRegistrationLinks(document) - w.Header().Set(headerContentType, contentTypeJSON) - _ = json.NewEncoder(w).Encode(document) -} - -func nugetRegistrationID(path string) string { - for _, prefix := range nugetRegistrationPrefixes { - if rest, ok := strings.CutPrefix(path, prefix); ok { - id, _, _ := strings.Cut(rest, "/") - return id - } - } - return "" -} - -// Only expand index pages, never recursively follow arbitrary upstream links. -// Pin requests to this configured upstream and the current package's page path. -func (h *NuGetHandler) expandNuGetPages(ctx context.Context, document map[string]any, path string) error { - if !strings.HasSuffix(path, "/index.json") { - return nil - } - items, ok := document["items"].([]any) - if !ok { - return fmt.Errorf("missing registration pages") - } - base, err := url.Parse(h.upstreamURL + path) - if err != nil { - return err - } - pagePrefix := strings.TrimSuffix(base.Path, "index.json") + "page/" - for _, item := range items { - page, ok := item.(map[string]any) - if !ok { - return fmt.Errorf("invalid registration page") - } - if _, ok := page["items"].([]any); ok { - continue - } - link, _ := page["@id"].(string) - target, err := base.Parse(link) - if err != nil || target.Scheme != base.Scheme || target.Host != base.Host || - !strings.HasPrefix(target.Path, pagePrefix) || containsPathTraversal(target.Path) || target.RawQuery != "" || target.Fragment != "" { - return fmt.Errorf("invalid registration page URL: %q", link) - } - upstream, _ := url.Parse(h.upstreamURL) - pageDocument, err := h.nugetMetadata(ctx, strings.TrimPrefix(target.Path, upstream.Path)) - if err != nil { - return err - } - leaves, ok := pageDocument["items"].([]any) - if !ok { - return fmt.Errorf("missing registration leaves") - } - page["items"] = leaves - } - return nil -} - -func (h *NuGetHandler) filterNuGetRegistration(document map[string]any, id string) bool { - items, ok := document["items"].([]any) - if !ok { - return h.nugetLeafAllowed(document, id) - } - filtered := make([]any, 0, len(items)) - for _, item := range items { - child, ok := item.(map[string]any) - if ok && h.filterNuGetRegistration(child, id) { - filtered = append(filtered, child) - } - } - document["items"] = filtered - document["count"] = len(filtered) - // Page bounds describe the retained leaves, not versions hidden by cooldown. - if _, isPage := document["lower"]; isPage && len(filtered) > 0 { - first, _ := filtered[0].(map[string]any) - last, _ := filtered[len(filtered)-1].(map[string]any) - document["lower"] = nugetCatalogEntry(first)["version"] - document["upper"] = nugetCatalogEntry(last)["version"] - } - return len(filtered) > 0 -} - -func (h *NuGetHandler) rewriteNuGetRegistrationLinks(value any) { - switch node := value.(type) { - case map[string]any: - for key, child := range node { - if link, ok := child.(string); ok { - switch key { - case "@id", "parent", "registration", "packageContent": - node[key] = h.nugetProxyLink(link) - } - } else { - h.rewriteNuGetRegistrationLinks(child) - } - } - case []any: - for _, child := range node { - h.rewriteNuGetRegistrationLinks(child) - } - } -} - -func (h *NuGetHandler) nugetProxyLink(link string) string { - u, err := url.Parse(link) - if err != nil { - return link - } - upstream, err := url.Parse(h.upstreamURL) - if err != nil { - return link - } - path := u.Path - if u.Host == upstream.Host { - path = strings.TrimPrefix(path, upstream.Path) - } - for _, prefix := range nugetArtifactPrefixes { - if strings.HasPrefix(path, prefix) { - proxy, err := url.Parse(h.proxyURL + "/nuget" + path) - if err != nil { - return link - } - proxy.RawQuery = u.RawQuery - proxy.Fragment = u.Fragment - return proxy.String() - } - } - return link -} diff --git a/internal/handler/nuget_cooldown_test.go b/internal/handler/nuget_cooldown_test.go deleted file mode 100644 index 74258da..0000000 --- a/internal/handler/nuget_cooldown_test.go +++ /dev/null @@ -1,501 +0,0 @@ -package handler - -import ( - "bytes" - "compress/gzip" - "encoding/json" - "errors" - "io" - "net/http" - "net/http/httptest" - "strings" - "sync/atomic" - "testing" - "time" - - "github.com/git-pkgs/cooldown" - "github.com/git-pkgs/registries/fetch" -) - -func TestNuGetCooldownRoutes(t *testing.T) { - for _, disableCompression := range []bool{false, true} { - t.Run(map[bool]string{false: "transport gzip", true: "explicit gzip"}[disableCompression], func(t *testing.T) { - proxy, db, store, fetcher := setupTestProxy(t) - proxy.Cooldown = &cooldown.Config{Default: "14d"} - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - seedPackage(t, db, store, "nuget", "testpkg", "2.0.0", "testpkg.2.0.0.nupkg", "cached package") - seedPackage(t, db, store, "nuget", "testpkg", "1.0.0", "testpkg.1.0.0.nupkg", "old package") - metadataRequests := 0 - upstream := newNuGetCooldownUpstream(t, &metadataRequests) - defer upstream.Close() - transport := http.DefaultTransport.(*http.Transport).Clone() - transport.DisableCompression = disableCompression - defer transport.CloseIdleConnections() - proxy.HTTPClient = &http.Client{Transport: transport} - h := NewNuGetHandlerWithUpstreams(proxy, "http://proxy.test", upstream.URL, upstream.URL) - routes := http.StripPrefix("/nuget", h.Routes()) - get := func(path string, status int) *httptest.ResponseRecorder { - t.Helper() - return nugetGet(t, routes, path, status) - } - list := get("/nuget/v3-flatcontainer/testpkg/index.json", http.StatusOK) - if got := strings.TrimSpace(list.Body.String()); got != `{"versions":["1.0.0"]}` { - t.Fatalf("filtered list = %s", got) - } - index := get("/nuget"+nugetRegistrationPath+"testpkg/index.json", http.StatusOK) - if strings.Contains(index.Body.String(), `"version":"2.0.0"`) || strings.Contains(index.Body.String(), upstream.URL) { - t.Fatalf("registration leaks blocked leaf or upstream link: %s", index.Body.String()) - } - if index.Header().Get("Content-Encoding") != "" || !json.Valid(index.Body.Bytes()) { - t.Fatal("registration must be decoded JSON") - } - var doc struct { - Items []struct { - ID string `json:"@id"` - Count int - Lower, Upper string - Items []struct { - ID string `json:"@id"` - PackageContent string - } - } - } - if err := json.Unmarshal(index.Body.Bytes(), &doc); err != nil { - t.Fatal(err) - } - if len(doc.Items) != 1 || doc.Items[0].Count != 1 || doc.Items[0].Upper != "1.0.0" { - t.Fatalf("incorrect page: %+v", doc) - } - get(doc.Items[0].ID, http.StatusOK) - get(doc.Items[0].Items[0].ID, http.StatusOK) - get(doc.Items[0].Items[0].PackageContent, http.StatusOK) - get("/nuget"+nugetRegistrationPath+"testpkg/2.0.0.json", http.StatusNotFound) - get("/nuget/v3-flatcontainer/TestPkg/2.0.0/testpkg.2.0.0.nupkg", http.StatusNotFound) - get("/nuget/v3-flatcontainer/testpkg/2.0.0/testpkg.nuspec", http.StatusNotFound) - if fetcher.fetchCalled { - t.Fatal("blocked or cached downloads must not fetch artifacts") - } - - // Reevaluate fresh, unfiltered metadata under a changed package policy. - requestsBefore := metadataRequests - proxy.Cooldown = &cooldown.Config{Default: "14d", Packages: map[string]string{"pkg:nuget/testpkg": "1d"}} - list = get("/nuget/v3-flatcontainer/testpkg/index.json", http.StatusOK) - if !strings.Contains(list.Body.String(), "2.0.0") { - t.Fatal("fresh metadata retained the previous policy") - } - get("/nuget/v3-flatcontainer/testpkg/2.0.0/testpkg.2.0.0.nupkg", http.StatusOK) - if metadataRequests != requestsBefore { - t.Fatal("fresh metadata should be reused") - } - }) - } -} - -func nugetGet(t *testing.T, routes http.Handler, path string, status int) *httptest.ResponseRecorder { - t.Helper() - w := httptest.NewRecorder() - routes.ServeHTTP(w, httptest.NewRequest(http.MethodGet, path, nil)) - if w.Code != status { - t.Fatalf("GET %s: status %d, want %d: %s", path, w.Code, status, w.Body.String()) - } - return w -} - -func TestNuGetMetadataWithoutEffectiveCooldown(t *testing.T) { - for _, tt := range []struct { - name string - policy *cooldown.Config - }{ - {"package exemption", &cooldown.Config{Default: "14d", Packages: map[string]string{"pkg:nuget/testpkg": "0"}}}, - {"ecosystem exemption", &cooldown.Config{Default: "14d", Ecosystems: map[string]string{"nuget": "0"}}}, - {"other ecosystem only", &cooldown.Config{Ecosystems: map[string]string{"npm": "14d"}}}, - {"other package only", &cooldown.Config{Packages: map[string]string{"pkg:nuget/other": "14d"}}}, - } { - t.Run(tt.name, func(t *testing.T) { - const body = `{"versions":["1.0.0","2.0.0"]}` - const pagePath = nugetRegistrationPath + "testpkg/page/1.0.0/2.0.0.json" - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.URL.Path { - case "/v3-flatcontainer/testpkg/index.json": - _, _ = io.WriteString(w, body) - case nugetRegistrationPath + "testpkg/index.json": - _, _ = io.WriteString(w, `{"count":1,"items":[{"@id":"`+pagePath+`","count":2,"lower":"1.0.0","upper":"2.0.0"}]}`) - default: - t.Errorf("unnecessary registration request: %s", r.URL.Path) - http.Error(w, "registration unavailable", http.StatusServiceUnavailable) - } - })) - defer upstream.Close() - p := nugetTestProxy() - p.Cooldown = tt.policy - h := NewNuGetHandlerWithUpstreams(p, "http://proxy.test", upstream.URL, upstream.URL) - w := nugetGet(t, h.Routes(), "/v3-flatcontainer/TestPkg/index.json", http.StatusOK) - if got := strings.TrimSpace(w.Body.String()); got != body { - t.Fatalf("version list = %s, want %s", got, body) - } - w = nugetGet(t, h.Routes(), nugetRegistrationPath+"testpkg/index.json", http.StatusOK) - if !strings.Contains(w.Body.String(), `"@id":"http://proxy.test/nuget`+pagePath+`"`) { - t.Fatalf("registration page link was not rewritten: %s", w.Body.String()) - } - }) - } -} - -func TestNuGetCooldownColdDownload(t *testing.T) { - for _, tt := range []struct { - name, published string - policy *cooldown.Config - want int - }{ - {"recent", time.Now().Add(-time.Hour).Format(time.RFC3339), &cooldown.Config{Default: "14d"}, http.StatusNotFound}, - {"missing timestamp", "", &cooldown.Config{Default: "14d"}, http.StatusOK}, - {"package exemption", time.Now().Add(-time.Hour).Format(time.RFC3339), &cooldown.Config{Default: "14d", Packages: map[string]string{"pkg:nuget/testpkg": "0"}}, http.StatusOK}, - {"ecosystem override", time.Now().Add(-time.Hour).Format(time.RFC3339), &cooldown.Config{Ecosystems: map[string]string{"nuget": "14d"}}, http.StatusNotFound}, - } { - t.Run(tt.name, func(t *testing.T) { - p, _, _, fetcher := setupTestProxy(t) - p.Cooldown = tt.policy - fetcher.artifact = &fetch.Artifact{Body: io.NopCloser(strings.NewReader("package")), ContentType: "application/octet-stream"} - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - _ = json.NewEncoder(w).Encode(map[string]string{"published": tt.published}) - })) - defer upstream.Close() - h := NewNuGetHandlerWithUpstreams(p, "http://proxy.test", upstream.URL, upstream.URL) - nugetGet(t, h.Routes(), "/v3-flatcontainer/testpkg/2.0.0/testpkg.2.0.0.nupkg", tt.want) - if fetcher.fetchCalled != (tt.want == http.StatusOK) { - t.Errorf("artifact fetch called = %v", fetcher.fetchCalled) - } - }) - } -} - -func TestNuGetRegistrationServiceAliases(t *testing.T) { - h := NewNuGetHandler(nugetTestProxy(), "http://proxy.test") - for _, tt := range []struct{ service, path string }{ - {"RegistrationsBaseUrl", "/v3/registration5-semver1/"}, - {"RegistrationsBaseUrl/3.0.0-beta", "/v3/registration5-semver1/"}, - {"RegistrationsBaseUrl/3.0.0-rc", "/v3/registration5-semver1/"}, - {"RegistrationsBaseUrl/3.4.0", "/v3/registration5-gz-semver1/"}, - {"RegistrationsBaseUrl/3.6.0", nugetRegistrationPath}, - {"RegistrationsBaseUrl/Versioned", nugetRegistrationPath}, - } { - t.Run(tt.service, func(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path != tt.path+"testpkg/index.json" { - t.Errorf("wrong hive: %s", r.URL.Path) - } - _, _ = io.WriteString(w, `{"count":0,"items":[]}`) - })) - defer upstream.Close() - h.upstreamURL = upstream.URL - h.proxy.Cooldown = &cooldown.Config{Default: "14d"} - body := []byte(`{"resources":[{"@id":"` + upstream.URL + tt.path + `","@type":"` + tt.service + `"}]}`) - out, err := h.rewriteServiceIndex(body) - if err != nil { - t.Fatal(err) - } - var doc struct { - Resources []struct { - ID string `json:"@id"` - } - } - if err := json.Unmarshal(out, &doc); err != nil { - t.Fatal(err) - } - w := httptest.NewRecorder() - http.StripPrefix("/nuget", h.Routes()).ServeHTTP(w, httptest.NewRequest(http.MethodGet, doc.Resources[0].ID+"testpkg/index.json", nil)) - if w.Code != http.StatusOK { - t.Fatalf("alias route status = %d: %s", w.Code, w.Body.String()) - } - }) - } -} - -func TestNuGetCooldownMetadataErrors(t *testing.T) { - for _, tt := range []struct { - name, body string - status int - }{ - {"upstream failure", "unavailable", http.StatusServiceUnavailable}, - {"invalid JSON", "broken JSON", http.StatusOK}, - {"null", "null", http.StatusOK}, - } { - t.Run(tt.name, func(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - w.WriteHeader(tt.status) - _, _ = io.WriteString(w, tt.body) - })) - defer upstream.Close() - p := nugetTestProxy() - p.Cooldown = &cooldown.Config{Default: "14d"} - h := NewNuGetHandlerWithUpstreams(p, "http://proxy.test", upstream.URL, upstream.URL) - for _, path := range []string{"/v3-flatcontainer/testpkg/index.json", "/v3-flatcontainer/testpkg/2.0.0/testpkg.2.0.0.nupkg", nugetRegistrationPath + "testpkg/index.json"} { - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, path, nil)) - if w.Code != http.StatusBadGateway { - t.Errorf("GET %s: %d, want 502", path, w.Code) - } - } - }) - } -} - -func TestNuGetCooldownRejectsUnsafePageLinks(t *testing.T) { - for _, link := range []string{"https://other.example/page.json", "/v3/registration5-gz-semver2/other/page/1/2.json", "page/../index.json", "index.json"} { - t.Run(link, func(t *testing.T) { - requests := 0 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - requests++ - _ = json.NewEncoder(w).Encode(map[string]any{"items": []any{map[string]any{"@id": link}}}) - })) - defer upstream.Close() - p := nugetTestProxy() - p.Cooldown = &cooldown.Config{Default: "14d"} - h := NewNuGetHandlerWithUpstreams(p, "http://proxy.test", upstream.URL, upstream.URL) - nugetGet(t, h.Routes(), nugetRegistrationPath+"testpkg/index.json", http.StatusBadGateway) - if requests != 1 { - t.Fatalf("unsafe page link was followed (%d requests)", requests) - } - }) - } -} - -func TestNuGetCooldownDecompressedMetadataLimit(t *testing.T) { - var compressed bytes.Buffer - gz := gzip.NewWriter(&compressed) - _, _ = io.WriteString(gz, `{"padding":"`+strings.Repeat("x", 2048)+`"}`) - _ = gz.Close() - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - w.Header().Set("Content-Encoding", "gzip") - _, _ = w.Write(compressed.Bytes()) - })) - defer upstream.Close() - p := nugetTestProxy() - p.Cooldown = &cooldown.Config{Default: "14d"} - p.MetadataMaxSize = 1024 - transport := http.DefaultTransport.(*http.Transport).Clone() - transport.DisableCompression = true - defer transport.CloseIdleConnections() - p.HTTPClient = &http.Client{Transport: transport} - h := NewNuGetHandlerWithUpstreams(p, "http://proxy.test", upstream.URL, upstream.URL) - nugetGet(t, h.Routes(), nugetRegistrationPath+"testpkg/index.json", http.StatusBadGateway) -} - -func newNuGetCooldownUpstream(t *testing.T, metadataRequests *int) *httptest.Server { - t.Helper() - var upstream *httptest.Server - upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - (*metadataRequests)++ - base := upstream.URL + nugetRegistrationPath + "testpkg/" - leaf := func(version string, age time.Duration) map[string]any { - return map[string]any{ - "@id": base + version + ".json", - "packageContent": upstream.URL + "/v3-flatcontainer/testpkg/" + version + "/testpkg." + version + ".nupkg", - "catalogEntry": map[string]any{"id": "TestPkg", "version": version, "published": time.Now().Add(-age).Format(time.RFC3339)}, - } - } - page := map[string]any{"@id": base + "page/1.0.0/2.0.0.json", "lower": "1.0.0", "upper": "2.0.0", "count": 2, - "parent": base + "index.json", "items": []any{leaf("1.0.0", 30*24*time.Hour), leaf("2.0.0", 2*24*time.Hour)}} - var body any - switch r.URL.Path { - case "/v3-flatcontainer/testpkg/index.json": - body = map[string]any{"versions": []string{"1.0.0", "2.0.0"}} - case nugetRegistrationPath + "testpkg/index.json": - // This index deliberately does not inline its leaves. - body = map[string]any{"count": 1, "items": []any{map[string]any{ - "@id": page["@id"], "count": 2, "lower": "1.0.0", "upper": "2.0.0", - }}} - case nugetRegistrationPath + "testpkg/page/1.0.0/2.0.0.json": - body = page - case nugetRegistrationPath + "testpkg/1.0.0.json": - body = map[string]any{"published": time.Now().Add(-30 * 24 * time.Hour).Format(time.RFC3339)} - case nugetRegistrationPath + "testpkg/2.0.0.json": - body = map[string]any{"published": time.Now().Add(-2 * 24 * time.Hour).Format(time.RFC3339)} - default: - t.Errorf("unexpected metadata request: %s", r.URL.Path) - http.NotFound(w, r) - return - } - w.Header().Set("Content-Type", "application/json") - w.Header().Set("Content-Encoding", "gzip") - gz := gzip.NewWriter(w) - _ = json.NewEncoder(gz).Encode(body) - _ = gz.Close() - })) - - return upstream -} - -func TestNuGetCooldownLegacyRegistration(t *testing.T) { - for _, service := range []string{"RegistrationsBaseUrl", "RegistrationsBaseUrl/3.0.0-beta", "RegistrationsBaseUrl/3.0.0-rc", "RegistrationsBaseUrl/3.4.0"} { - t.Run(service, func(t *testing.T) { - prefix := "/v3/registration5-semver1/" - if service == "RegistrationsBaseUrl/3.4.0" { - prefix = "/v3/registration5-gz-semver1/" - } - upstream := newNuGetLegacyUpstream(t, service, prefix) - defer upstream.Close() - p, db, store, fetcher := setupTestProxy(t) - p.Cooldown = &cooldown.Config{Default: "14d"} - seedPackage(t, db, store, "nuget", "testpkg", "1.0.0", "testpkg.1.0.0.nupkg", "cached old package") - seedPackage(t, db, store, "nuget", "testpkg", "2.0.0", "testpkg.2.0.0.nupkg", "cached recent package") - h := NewNuGetHandlerWithUpstreams(p, "http://proxy.test", upstream.URL+"/feed", upstream.URL) - list := nugetGet(t, h.Routes(), "/v3-flatcontainer/testpkg/index.json", http.StatusOK) - if strings.TrimSpace(list.Body.String()) != `{"versions":["1.0.0"]}` { - t.Fatalf("incorrect version list: %s", list.Body.String()) - } - nugetGet(t, h.Routes(), "/v3-flatcontainer/testpkg/1.0.0/testpkg.1.0.0.nupkg", http.StatusOK) - nugetGet(t, h.Routes(), "/v3-flatcontainer/testpkg/2.0.0/testpkg.2.0.0.nupkg", http.StatusNotFound) - if fetcher.fetchCalled { - t.Fatal("cached or blocked package must not be fetched") - } - }) - } -} - -func newNuGetLegacyUpstream(t *testing.T, service, prefix string) *httptest.Server { - t.Helper() - var upstream *httptest.Server - upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - path := strings.TrimPrefix(r.URL.Path, "/feed") - base := upstream.URL + "/feed" + prefix + "testpkg/" - published := func(age time.Duration) string { return time.Now().Add(-age).Format(time.RFC3339) } - var body any - switch path { - case "/v3/index.json": - body = map[string]any{"resources": []any{map[string]string{"@id": upstream.URL + "/feed" + prefix, "@type": service}}} - case "/v3-flatcontainer/testpkg/index.json": - body = map[string]any{"versions": []string{"1.0.0", "2.0.0"}} - case prefix + "testpkg/index.json": - body = map[string]any{"items": []any{map[string]any{"@id": base + "page/1.0.0/2.0.0.json"}}} - case prefix + "testpkg/page/1.0.0/2.0.0.json": - body = map[string]any{"items": []any{ - map[string]any{"catalogEntry": map[string]string{"id": "testpkg", "version": "1.0.0", "published": published(30 * 24 * time.Hour)}}, - map[string]any{"catalogEntry": map[string]string{"id": "testpkg", "version": "2.0.0", "published": published(time.Hour)}}, - }} - case prefix + "testpkg/1.0.0.json": - body = map[string]string{"published": published(30 * 24 * time.Hour)} - case prefix + "testpkg/2.0.0.json": - body = map[string]string{"published": published(time.Hour)} - default: - if !strings.HasPrefix(path, nugetRegistrationPath) { - t.Errorf("unexpected request: %s", r.URL.Path) - } - http.NotFound(w, r) - return - } - _ = json.NewEncoder(w).Encode(body) - })) - return upstream -} - -func TestNuGetRegistrationDoesNotFallbackOnFailure(t *testing.T) { - for _, status := range []int{http.StatusServiceUnavailable, http.StatusUnauthorized, http.StatusOK} { - t.Run(http.StatusText(status), func(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path != nugetRegistrationPath+"testpkg/index.json" { - t.Errorf("must not switch registration hive on failure: %s", r.URL.Path) - } - w.WriteHeader(status) - _, _ = io.WriteString(w, "invalid metadata") - })) - defer upstream.Close() - h := NewNuGetHandlerWithUpstreams(nugetTestProxy(), "http://proxy.test", upstream.URL, upstream.URL) - if _, _, err := h.nugetRegistrationMetadata(t.Context(), "testpkg/index.json"); err == nil { - t.Fatal("expected metadata error") - } - }) - } -} - -func TestNuGetMetadataPreservesValidCache(t *testing.T) { - for _, invalid := range []string{"broken JSON", "null", "[]", string([]byte{0x1f, 0x8b, 0x00})} { - t.Run(invalid, func(t *testing.T) { - const good = `{"published":"2020-01-01T00:00:00Z"}` - var response atomic.Value - response.Store(good) - var requests atomic.Int32 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if requests.Add(1) > 1 && r.Header.Get("If-None-Match") != `"good"` { - t.Errorf("cached ETag was replaced: %s", r.Header.Get("If-None-Match")) - } - body := response.Load().(string) - etag := `"good"` - if body == invalid { - etag = `"bad"` - } - w.Header().Set("ETag", etag) - _, _ = io.WriteString(w, body) - })) - defer upstream.Close() - p, _, _, _ := setupTestProxy(t) - p.CacheMetadata = true - h := NewNuGetHandlerWithUpstreams(p, "http://proxy.test", upstream.URL, upstream.URL) - check := func(want string) { - t.Helper() - doc, err := h.nugetMetadata(t.Context(), nugetRegistrationPath+"testpkg/1.0.0.json") - if err != nil || doc["published"] != want { - t.Fatalf("metadata = %v, err = %v, want publication %s", doc, err, want) - } - } - check("2020-01-01T00:00:00Z") - response.Store(invalid) - check("2020-01-01T00:00:00Z") // Bad 200 must fall back without overwriting. - p.MetadataTTL = time.Hour - check("2020-01-01T00:00:00Z") // The on-disk cache must still be usable. - if requests.Load() != 2 { - t.Fatalf("requests = %d, want 2", requests.Load()) - } - p.MetadataTTL = 0 - response.Store(`{"published":"2021-01-01T00:00:00Z"}`) - check("2021-01-01T00:00:00Z") // A later valid response replaces the cache. - }) - } -} - -func TestNuGetMetadataInvalidResponseNotCached(t *testing.T) { - var requests atomic.Int32 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if requests.Add(1) == 1 { - _, _ = io.WriteString(w, "invalid JSON") - return - } - _, _ = io.WriteString(w, `{"published":"2020-01-01T00:00:00Z"}`) - })) - defer upstream.Close() - p, _, _, _ := setupTestProxy(t) - p.CacheMetadata = true - p.MetadataTTL = time.Hour - h := NewNuGetHandlerWithUpstreams(p, "http://proxy.test", upstream.URL, upstream.URL) - path := nugetRegistrationPath + "testpkg/1.0.0.json" - if _, err := h.nugetMetadata(t.Context(), path); err == nil { - t.Fatal("invalid response without a usable cache must fail") - } - if _, err := h.nugetMetadata(t.Context(), path); err != nil { - t.Fatalf("invalid response was cached: %v", err) - } - if requests.Load() != 2 { - t.Fatalf("requests = %d, want 2", requests.Load()) - } -} - -func TestNuGetRegistrationDoesNotGuessUnadvertisedAliases(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.URL.Path { - case nugetRegistrationPath + "testpkg/index.json": - http.NotFound(w, r) - case "/v3/index.json": - _, _ = io.WriteString(w, `{"resources":[{"@type":"UnrelatedService","@id":"https://other.example/"}]}`) - default: - t.Errorf("unadvertised endpoint requested: %s", r.URL.Path) - http.NotFound(w, r) - } - })) - defer upstream.Close() - h := NewNuGetHandlerWithUpstreams(nugetTestProxy(), "http://proxy.test", upstream.URL, upstream.URL) - _, _, err := h.nugetRegistrationMetadata(t.Context(), "testpkg/index.json") - if !errors.Is(err, ErrUpstreamNotFound) { - t.Fatalf("error = %v, want metadata not found", err) - } -} diff --git a/internal/handler/nuget_test.go b/internal/handler/nuget_test.go index 710b8ea..5dbb242 100644 --- a/internal/handler/nuget_test.go +++ b/internal/handler/nuget_test.go @@ -10,7 +10,7 @@ import ( "testing" "time" - "github.com/git-pkgs/cooldown" + "github.com/git-pkgs/proxy/internal/cooldown" ) func nugetTestProxy() *Proxy { @@ -69,11 +69,11 @@ func TestNuGetRewriteServiceIndex(t *testing.T) { } expectations := map[string]string{ - "PackageBaseAddress/3.0.0": "http://localhost:8080/nuget/v3-flatcontainer/", - "RegistrationsBaseUrl/3.6.0": "http://localhost:8080/nuget/v3/registration5-gz-semver2/", - "SearchQueryService/3.5.0": "http://localhost:8080/nuget/query", + "PackageBaseAddress/3.0.0": "http://localhost:8080/nuget/v3-flatcontainer/", + "RegistrationsBaseUrl/3.6.0": "http://localhost:8080/nuget/v3/registration5-gz-semver2/", + "SearchQueryService/3.5.0": "http://localhost:8080/nuget/query", "SearchAutocompleteService/3.5.0": "http://localhost:8080/nuget/autocomplete", - "SomeOtherService/1.0.0": "https://example.com/other-service", + "SomeOtherService/1.0.0": "https://example.com/other-service", } for _, res := range resources { @@ -91,82 +91,75 @@ func TestNuGetRewriteServiceIndex(t *testing.T) { } } +func TestNuGetShouldRewriteService(t *testing.T) { + h := &NuGetHandler{} + + rewriteTypes := []string{ + "PackageBaseAddress/3.0.0", + "RegistrationsBaseUrl/3.6.0", + "RegistrationsBaseUrl/Versioned", + "SearchQueryService", + "SearchQueryService/3.0.0-rc", + "SearchQueryService/3.5.0", + "SearchAutocompleteService", + "SearchAutocompleteService/3.5.0", + } + + for _, stype := range rewriteTypes { + if !h.shouldRewriteService(stype) { + t.Errorf("shouldRewriteService(%q) = false, want true", stype) + } + } + + noRewriteTypes := []string{ + "SomeOtherService/1.0.0", + "PackagePublish/2.0.0", + "", + "SearchQueryService/99.0.0", + } + + for _, stype := range noRewriteTypes { + if h.shouldRewriteService(stype) { + t.Errorf("shouldRewriteService(%q) = true, want false", stype) + } + } +} + func TestNuGetRewriteURL(t *testing.T) { h := &NuGetHandler{ proxyURL: "http://localhost:8080", } tests := []struct { - input string - serviceType string - want string + input string + want string }{ { "https://api.nuget.org/v3-flatcontainer/", - "PackageBaseAddress/3.0.0", "http://localhost:8080/nuget/v3-flatcontainer/", }, { "https://api.nuget.org/v3/registration5-gz-semver2/", - "RegistrationsBaseUrl/3.6.0", - "http://localhost:8080/nuget/v3/registration5-gz-semver2/", - }, - { - "https://api.nuget.org/v3/registration5-gz-semver2/", - "RegistrationsBaseUrl/Versioned", "http://localhost:8080/nuget/v3/registration5-gz-semver2/", }, { "https://azuresearch-usnc.nuget.org/query", - "SearchQueryService", - "http://localhost:8080/nuget/query", - }, - { - "https://azuresearch-usnc.nuget.org/query", - "SearchQueryService/3.0.0-rc", - "http://localhost:8080/nuget/query", - }, - { - "https://azuresearch-usnc.nuget.org/query", - "SearchQueryService/3.5.0", "http://localhost:8080/nuget/query", }, { "https://azuresearch-usnc.nuget.org/autocomplete", - "SearchAutocompleteService", - "http://localhost:8080/nuget/autocomplete", - }, - { - "https://azuresearch-usnc.nuget.org/autocomplete", - "SearchAutocompleteService/3.5.0", "http://localhost:8080/nuget/autocomplete", }, { "https://example.com/unknown", - "SomeOtherService/1.0.0", "https://example.com/unknown", }, - { - "https://api.nuget.org/v2/package", - "PackagePublish/2.0.0", - "https://api.nuget.org/v2/package", - }, - { - "https://azuresearch-usnc.nuget.org/query", - "SearchQueryService/99.0.0", - "https://azuresearch-usnc.nuget.org/query", - }, - { - "https://example.com/resource", - "", - "https://example.com/resource", - }, } for _, tt := range tests { - got := h.rewriteNuGetURL(tt.input, tt.serviceType) + got := h.rewriteNuGetURL(tt.input) if got != tt.want { - t.Errorf("rewriteNuGetURL(%q, %q) = %q, want %q", tt.input, tt.serviceType, got, tt.want) + t.Errorf("rewriteNuGetURL(%q) = %q, want %q", tt.input, got, tt.want) } } } @@ -465,7 +458,6 @@ func TestNuGetProxyUpstreamForwardsAcceptEncoding(t *testing.T) { func TestNuGetBuildUpstreamURL(t *testing.T) { h := &NuGetHandler{ upstreamURL: "https://api.nuget.org", - searchURL: "https://azuresearch-usnc.nuget.org", } tests := []struct { @@ -744,7 +736,6 @@ func TestNuGetHandleDownloadMissingFilename(t *testing.T) { func TestNuGetBuildUpstreamURLQueryPath(t *testing.T) { h := &NuGetHandler{ upstreamURL: "https://api.nuget.org", - searchURL: "https://azuresearch-usnc.nuget.org", } // Query endpoint should go to azuresearch @@ -759,7 +750,6 @@ func TestNuGetBuildUpstreamURLQueryPath(t *testing.T) { func TestNuGetBuildUpstreamURLAutocompletePath(t *testing.T) { h := &NuGetHandler{ upstreamURL: "https://api.nuget.org", - searchURL: "https://azuresearch-usnc.nuget.org", } req := httptest.NewRequest(http.MethodGet, "/autocomplete?q=new&take=10", nil) @@ -812,6 +802,11 @@ func TestNuGetCooldownFiltering(t *testing.T) { }, } + body, err := json.Marshal(registration) + if err != nil { + t.Fatal(err) + } + proxy := testProxy() proxy.Cooldown = &cooldown.Config{ Default: "3d", @@ -822,11 +817,17 @@ func TestNuGetCooldownFiltering(t *testing.T) { proxyURL: "http://localhost:8080", } - if !h.filterNuGetRegistration(registration, "") { - t.Fatal("expected registration items to be retained") + filtered, err := h.applyCooldownFiltering(body) + if err != nil { + t.Fatal(err) } - pages := registration["items"].([]any) + var result map[string]any + if err := json.Unmarshal(filtered, &result); err != nil { + t.Fatal(err) + } + + pages := result["items"].([]any) page := pages[0].(map[string]any) items := page["items"].([]any) @@ -840,7 +841,7 @@ func TestNuGetCooldownFiltering(t *testing.T) { } count := page["count"] - if count != 1 { + if count != float64(1) { t.Errorf("expected page count to be 1, got %v", count) } } @@ -866,6 +867,11 @@ func TestNuGetCooldownFilteringWithPackageOverride(t *testing.T) { }, } + body, err := json.Marshal(registration) + if err != nil { + t.Fatal(err) + } + proxy := testProxy() proxy.Cooldown = &cooldown.Config{ Default: "3d", @@ -877,11 +883,17 @@ func TestNuGetCooldownFilteringWithPackageOverride(t *testing.T) { proxyURL: "http://localhost:8080", } - if !h.filterNuGetRegistration(registration, "") { - t.Fatal("expected registration items to be retained") + filtered, err := h.applyCooldownFiltering(body) + if err != nil { + t.Fatal(err) } - pages := registration["items"].([]any) + var result map[string]any + if err := json.Unmarshal(filtered, &result); err != nil { + t.Fatal(err) + } + + pages := result["items"].([]any) page := pages[0].(map[string]any) items := page["items"].([]any) @@ -908,20 +920,36 @@ func TestNuGetCooldownNoCooldownConfig(t *testing.T) { }, } - // No cooldown: all registration items are retained. + body, err := json.Marshal(registration) + if err != nil { + t.Fatal(err) + } + + // No cooldown - applyCooldownFiltering still works, just doesn't filter h := &NuGetHandler{ proxy: testProxy(), proxyURL: "http://localhost:8080", } - if !h.filterNuGetRegistration(registration, "") { - t.Fatal("expected registration items to be retained") + filtered, err := h.applyCooldownFiltering(body) + if err != nil { + t.Fatal(err) } - pages := registration["items"].([]any) + var result map[string]any + if err := json.Unmarshal(filtered, &result); err != nil { + t.Fatal(err) + } + + pages := result["items"].([]any) page := pages[0].(map[string]any) items := page["items"].([]any) + // Without cooldown config on the handler, applyCooldownFiltering + // is called but proxy.Cooldown is nil, so IsAllowed is never called + // Actually, applyCooldownFiltering always runs the filter logic - + // but the caller (handleRegistration) short-circuits when cooldown is disabled. + // The function itself should still work fine with a nil Cooldown. if len(items) != 1 { t.Fatalf("expected 1 item, got %d", len(items)) } @@ -950,6 +978,11 @@ func TestNuGetCooldownFilteringNuGetTimestamp(t *testing.T) { }, } + body, err := json.Marshal(registration) + if err != nil { + t.Fatal(err) + } + proxy := testProxy() proxy.Cooldown = &cooldown.Config{ Default: "3d", @@ -960,11 +993,17 @@ func TestNuGetCooldownFilteringNuGetTimestamp(t *testing.T) { proxyURL: "http://localhost:8080", } - if !h.filterNuGetRegistration(registration, "") { - t.Fatal("expected registration items to be retained") + filtered, err := h.applyCooldownFiltering(body) + if err != nil { + t.Fatal(err) } - pages := registration["items"].([]any) + var result map[string]any + if err := json.Unmarshal(filtered, &result); err != nil { + t.Fatal(err) + } + + pages := result["items"].([]any) page := pages[0].(map[string]any) items := page["items"].([]any) diff --git a/internal/handler/path_traversal_test.go b/internal/handler/path_traversal_test.go index 5ad68a5..14d2218 100644 --- a/internal/handler/path_traversal_test.go +++ b/internal/handler/path_traversal_test.go @@ -14,15 +14,6 @@ func TestContainsPathTraversal(t *testing.T) { {"pool/main/../../../etc/shadow", true}, {"pool/..hidden/file", false}, // ".." as a segment, not "..hidden" {"", false}, - {"%2e%2e/etc/passwd", true}, - {"%2e%2e%2fetc%2fpasswd", true}, - {"pool/%2e%2e/%2e%2e/etc/shadow", true}, - {"%2E%2E%2Fetc", true}, - {`..\\etc\\passwd`, true}, - {`pool\\..\\..\\etc`, true}, - {"%2e%2e%5cetc%5cpasswd", true}, - {"pool/%2e%2ehidden/file", false}, - {"pool/%zz/bad-encoding", false}, } for _, tt := range tests { diff --git a/internal/handler/proxy_cached_encoding_test.go b/internal/handler/proxy_cached_encoding_test.go deleted file mode 100644 index 35c8793..0000000 --- a/internal/handler/proxy_cached_encoding_test.go +++ /dev/null @@ -1,260 +0,0 @@ -package handler - -import ( - "bytes" - "context" - "errors" - "net/http" - "net/http/httptest" - "strconv" - "strings" - "sync/atomic" - "testing" - "time" -) - -// gzipWhenAskedUpstream serves compressed bytes with Content-Encoding: gzip -// when the request advertises gzip, plain bytes otherwise, like a CDN that -// compresses on the fly. It records the last Accept-Encoding it saw and counts -// every request before the availability gate so a cache-miss refetch during a -// simulated outage is observable. -type gzipWhenAskedUpstream struct { - *httptest.Server - available atomic.Bool - requests atomic.Int32 - acceptEncoding atomic.Value // string -} - -func newGzipWhenAskedUpstream(plain, compressed []byte) *gzipWhenAskedUpstream { - u := &gzipWhenAskedUpstream{} - u.available.Store(true) - u.Server = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - u.requests.Add(1) - u.acceptEncoding.Store(r.Header.Get(headerAcceptEncoding)) - if !u.available.Load() { - http.Error(w, "unavailable", http.StatusServiceUnavailable) - return - } - w.Header().Set(headerContentType, contentTypeJSON) - if strings.Contains(r.Header.Get(headerAcceptEncoding), "gzip") { - w.Header().Set(headerContentEncoding, "gzip") - _, _ = w.Write(compressed) - return - } - _, _ = w.Write(plain) - })) - return u -} - -func (u *gzipWhenAskedUpstream) sawAcceptEncoding() string { - s, _ := u.acceptEncoding.Load().(string) - return s -} - -// serveGzip issues one request through proxyCachedWithEncoding asking the -// upstream for gzip. -func serveGzip(proxy *Proxy, upstreamURL string) *httptest.ResponseRecorder { - w := httptest.NewRecorder() - r := httptest.NewRequest(http.MethodGet, "/index.json", nil) - proxy.proxyCachedWithEncoding(w, r, upstreamURL, "gzip-test", "index", "gzip", "*/*") - return w -} - -func assertGzipResponse(t *testing.T, label string, w *httptest.ResponseRecorder, compressed []byte) { - t.Helper() - if w.Code != http.StatusOK { - t.Fatalf("%s: status = %d, want 200: %s", label, w.Code, w.Body.String()) - } - if !bytes.Equal(w.Body.Bytes(), compressed) { - t.Errorf("%s: body is not the compressed bytes (got %d, want %d)", label, w.Body.Len(), len(compressed)) - } - if got := w.Header().Get(headerContentEncoding); got != "gzip" { - t.Errorf("%s: Content-Encoding = %q, want %q", label, got, "gzip") - } - if got := w.Header().Get(headerContentLength); got != strconv.Itoa(len(compressed)) { - t.Errorf("%s: Content-Length = %q, want %d", label, got, len(compressed)) - } -} - -// TestProxyCachedWithEncoding_GzipCachesAndReplays covers the cached path: -// requesting gzip upstream stores the compressed bytes plus Content-Encoding -// and replays both from cache without contacting the upstream again. -func TestProxyCachedWithEncoding_GzipCachesAndReplays(t *testing.T) { - plain := []byte(`{"packages":{}}`) - compressed := gzipPayload(t, plain) - upstream := newGzipWhenAskedUpstream(plain, compressed) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = upstream.Client() - - first := serveGzip(proxy, upstream.URL+"/index.json") - assertGzipResponse(t, "first", first, compressed) - if got := upstream.sawAcceptEncoding(); got != "gzip" { - t.Errorf("upstream Accept-Encoding = %q, want %q", got, "gzip") - } - - before := upstream.requests.Load() - upstream.available.Store(false) - cached := serveGzip(proxy, upstream.URL+"/index.json") - assertGzipResponse(t, "cached", cached, compressed) - if upstream.requests.Load() != before { - t.Errorf("cached replay hit upstream: requests %d -> %d", before, upstream.requests.Load()) - } -} - -// TestProxyCachedWithEncoding_GzipStreamPath covers the cache_metadata=false -// branch: the streaming path must request gzip and forward Content-Encoding. -func TestProxyCachedWithEncoding_GzipStreamPath(t *testing.T) { - plain := []byte(`{"packages":{}}`) - compressed := gzipPayload(t, plain) - upstream := newGzipWhenAskedUpstream(plain, compressed) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = false - proxy.HTTPClient = upstream.Client() - - w := serveGzip(proxy, upstream.URL+"/index.json") - assertGzipResponse(t, "stream", w, compressed) - if got := upstream.sawAcceptEncoding(); got != "gzip" { - t.Errorf("stream path upstream Accept-Encoding = %q, want %q", got, "gzip") - } -} - -// TestProxyCachedWithEncoding_GzipSurvivesCacheWriteFailure covers the failure -// the gzip mode makes reachable: when the metadata cache write fails the -// freshly fetched body is still served, so its Content-Encoding must come from -// the fetch and not from the (unwritten) cache row -- otherwise gzip bytes go -// out labelled application/json with no Content-Encoding. -func TestProxyCachedWithEncoding_GzipSurvivesCacheWriteFailure(t *testing.T) { - plain := []byte(`{"packages":{}}`) - compressed := gzipPayload(t, plain) - upstream := newGzipWhenAskedUpstream(plain, compressed) - defer upstream.Close() - - proxy, _, store, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.HTTPClient = upstream.Client() - store.storeErr = errors.New("disk full") - - w := serveGzip(proxy, upstream.URL+"/index.json") - assertGzipResponse(t, "store-failure", w, compressed) -} - -// TestProxyCachedWithEncoding_GzipStaleFallbackKeepsEncoding pins the -// stale-fallback return: when the upstream fails after the entry has expired, -// the stored gzip blob is served with its Content-Encoding taken from the -// cache row. -func TestProxyCachedWithEncoding_GzipStaleFallbackKeepsEncoding(t *testing.T) { - plain := []byte(`{"packages":{}}`) - compressed := gzipPayload(t, plain) - upstream := newGzipWhenAskedUpstream(plain, compressed) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = 0 // every request revalidates; an upstream failure falls back to the stale row - proxy.HTTPClient = upstream.Client() - - first := serveGzip(proxy, upstream.URL+"/index.json") - assertGzipResponse(t, "first", first, compressed) - - upstream.available.Store(false) - stale := serveGzip(proxy, upstream.URL+"/index.json") - assertGzipResponse(t, "stale", stale, compressed) -} - -// TestProxyCachedWithEncoding_UpsertFailureDiscardsBlob covers the row-write -// failure: when the gzip blob is stored but the cache row cannot be updated, -// the blob must be discarded so a later stale fallback cannot serve gzip -// bytes with the previous row's encoding. The fresh response is still -// correct because its encoding comes from the fetch. -func TestProxyCachedWithEncoding_UpsertFailureDiscardsBlob(t *testing.T) { - plain := []byte(`{"packages":{}}`) - compressed := gzipPayload(t, plain) - upstream := newGzipWhenAskedUpstream(plain, compressed) - defer upstream.Close() - - proxy, db, store, _ := setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = 0 // every request revalidates - proxy.HTTPClient = upstream.Client() - - // Seed an identity row + plain blob, as every key has before the gzip rollout. - w := httptest.NewRecorder() - proxy.proxyCachedWithEncoding(w, httptest.NewRequest(http.MethodGet, "/index.json", nil), - upstream.URL+"/index.json", "gzip-test", "index", "identity", "*/*") - if w.Code != http.StatusOK { - t.Fatalf("seed status = %d, want 200", w.Code) - } - - // Now DB writes fail while reads keep working. - db.SetMaxOpenConns(1) - if _, err := db.Exec("PRAGMA query_only=1"); err != nil { - t.Fatalf("PRAGMA query_only=1: %v", err) - } - fresh := serveGzip(proxy, upstream.URL+"/index.json") - assertGzipResponse(t, "fresh with failed row write", fresh, compressed) - - storagePath := metadataStoragePath("gzip-test", "index") - if exists, _ := store.Exists(context.Background(), storagePath); exists { - t.Fatalf("blob %s still present after the row write failed", storagePath) - } - - // Upstream down: the stale fallback must not serve the orphaned gzip - // blob under the old identity row. - if _, err := db.Exec("PRAGMA query_only=0"); err != nil { - t.Fatalf("PRAGMA query_only=0: %v", err) - } - upstream.available.Store(false) - stale := serveGzip(proxy, upstream.URL+"/index.json") - if stale.Code == http.StatusOK { - t.Fatalf("stale fallback served status 200 (Content-Encoding=%q, %d bytes) from an orphaned blob; want an error", - stale.Header().Get(headerContentEncoding), stale.Body.Len()) - } -} - -// TestProxyCachedWithEncoding_StaleFallbackRereadsRow covers the rollout race: -// a request that read the identity row, lost the upstream race to a request -// that stored the gzip blob, and then failed upstream must label the blob -// with the row as it is now, not with the row it read at the start. -func TestProxyCachedWithEncoding_StaleFallbackRereadsRow(t *testing.T) { - plain := []byte(`{"packages":{}}`) - compressed := gzipPayload(t, plain) - - var proxy *Proxy - var requests atomic.Int32 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if requests.Add(1) == 1 { - w.Header().Set(headerContentType, contentTypeJSON) - _, _ = w.Write(plain) // seed request: identity - return - } - // Second request has already read the identity row. Simulate a - // concurrent request finishing first: store the gzip blob and row, - // then fail this request so it takes the stale fallback. - proxy.cacheMetadataBlob(r.Context(), "gzip-test", "index", metadataStoragePath("gzip-test", "index"), - &upstreamMetadata{body: compressed, contentType: contentTypeJSON, contentEncoding: "gzip"}) - http.Error(w, "unavailable", http.StatusServiceUnavailable) - })) - defer upstream.Close() - - proxy, _, _, _ = setupTestProxy(t) - proxy.CacheMetadata = true - proxy.MetadataTTL = 0 - proxy.HTTPClient = upstream.Client() - - w := httptest.NewRecorder() - proxy.proxyCachedWithEncoding(w, httptest.NewRequest(http.MethodGet, "/index.json", nil), - upstream.URL+"/index.json", "gzip-test", "index", "identity", "*/*") - if w.Code != http.StatusOK { - t.Fatalf("seed status = %d, want 200", w.Code) - } - - raced := serveGzip(proxy, upstream.URL+"/index.json") - assertGzipResponse(t, "stale fallback after concurrent gzip store", raced, compressed) -} diff --git a/internal/handler/pub.go b/internal/handler/pub.go index 9d449ba..60bbbad 100644 --- a/internal/handler/pub.go +++ b/internal/handler/pub.go @@ -7,6 +7,8 @@ import ( "net/http" "strings" "time" + + "github.com/git-pkgs/purl" ) const ( @@ -30,13 +32,6 @@ func NewPubHandler(proxy *Proxy, proxyURL string) *PubHandler { } } -// NewPubHandlerWithUpstream creates a pub handler with a custom upstream. -func NewPubHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *PubHandler { - h := NewPubHandler(proxy, proxyURL) - h.upstreamURL = configuredUpstreamURL(upstreamURL, pubUpstream) - return h -} - // Routes returns the HTTP handler for pub requests. func (h *PubHandler) Routes() http.Handler { mux := http.NewServeMux() @@ -72,12 +67,10 @@ func (h *PubHandler) handleDownload(w http.ResponseWriter, r *http.Request) { h.proxy.Logger.Info("pub download request", "name", name, "version", version) - downloadURL := h.upstreamURL + r.URL.Path - result, err := h.proxy.GetOrFetchArtifactFromURL( - r.Context(), "pub", name, version, filename, downloadURL, - ) + result, err := h.proxy.GetOrFetchArtifact(r.Context(), "pub", name, version, filename) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch package") + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch package", http.StatusBadGateway) return } @@ -110,13 +103,13 @@ func (h *PubHandler) handlePackageMetadata(w http.ResponseWriter, r *http.Reques rewritten, err := h.rewriteMetadata(name, body) if err != nil { h.proxy.Logger.Warn("failed to rewrite metadata, proxying original", "error", err) - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") w.WriteHeader(http.StatusOK) _, _ = w.Write(body) return } - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") w.WriteHeader(http.StatusOK) _, _ = w.Write(rewritten) } @@ -134,7 +127,7 @@ func (h *PubHandler) rewriteMetadata(name string, body []byte) ([]byte, error) { return body, nil } - packagePURL := canonicalPackagePURL("pub", name) + packagePURL := purl.MakePURLString("pub", name, "") filtered := h.filterAndRewriteVersions(name, packagePURL, versions) metadata["versions"] = filtered diff --git a/internal/handler/pub_test.go b/internal/handler/pub_test.go index 8a4c098..2788714 100644 --- a/internal/handler/pub_test.go +++ b/internal/handler/pub_test.go @@ -6,7 +6,7 @@ import ( "testing" "time" - "github.com/git-pkgs/cooldown" + "github.com/git-pkgs/proxy/internal/cooldown" ) func TestPubRewriteMetadata(t *testing.T) { diff --git a/internal/handler/pypi.go b/internal/handler/pypi.go index 03d178f..954adbf 100644 --- a/internal/handler/pypi.go +++ b/internal/handler/pypi.go @@ -7,68 +7,44 @@ import ( "errors" "fmt" "io" - "mime" "net/http" + "net/url" "regexp" - "strconv" "strings" "time" + + "github.com/git-pkgs/purl" ) const ( - pypiUpstream = "https://pypi.org" - pypiDownloadUpstream = "https://files.pythonhosted.org" - pypiSimpleJSON = "application/vnd.pypi.simple.v1+json" - pypiSimpleHTML = "application/vnd.pypi.simple.v1+html" - pypiSimpleLatestJSON = "application/vnd.pypi.simple.latest+json" - pypiSimpleLatestHTML = "application/vnd.pypi.simple.latest+html" - pypiLegacyHTML = "text/html" - pypiExactSpecificity = 2 - minWheelParts = 5 // name + version + python + abi + platform - minSubmatchParts = 2 // full match + first capture group - minPyPIPathParts = 3 // hash_prefix + hash + filename - minEggParts = 3 // name + version + python tag - - // PyPIMetadataSuffix is the PEP 658 core-metadata sidecar suffix that pip - // appends to a distribution URL when the index advertises core metadata. - // A sidecar resolves to the same name and version as the distribution it - // describes, so it is cached alongside it; consumers that expect an openable - // archive must skip these. - PyPIMetadataSuffix = ".metadata" + pypiUpstream = "https://pypi.org" + minWheelParts = 5 // name + version + python + abi + platform + minSubmatchParts = 2 // full match + first capture group + minPyPIPathParts = 3 // hash_prefix + hash + filename + minPythonTagLen = 2 // minimum length for a python tag (e.g., "py") ) // PyPIHandler handles PyPI registry protocol requests. type PyPIHandler struct { - proxy *Proxy - upstreamURL string - downloadURL string - downloadHrefRe *regexp.Regexp - proxyURL string + proxy *Proxy + upstreamURL string + proxyURL string } // NewPyPIHandler creates a new PyPI protocol handler. func NewPyPIHandler(proxy *Proxy, proxyURL string) *PyPIHandler { - return NewPyPIHandlerWithUpstreams(proxy, proxyURL, "", "") -} - -// NewPyPIHandlerWithUpstreams creates a PyPI handler with custom API and -// package download upstreams. -func NewPyPIHandlerWithUpstreams(proxy *Proxy, proxyURL, upstreamURL, downloadURL string) *PyPIHandler { - h := &PyPIHandler{ + return &PyPIHandler{ proxy: proxy, - upstreamURL: configuredUpstreamURL(upstreamURL, pypiUpstream), - downloadURL: configuredUpstreamURL(downloadURL, pypiDownloadUpstream), + upstreamURL: pypiUpstream, proxyURL: strings.TrimSuffix(proxyURL, "/"), } - h.downloadHrefRe = regexp.MustCompile(`href="(` + regexp.QuoteMeta(h.downloadURL) + `/packages/[^"]+)"`) - return h } // Routes returns the HTTP handler for PyPI requests. func (h *PyPIHandler) Routes() http.Handler { mux := http.NewServeMux() - // Simple API + // Simple API (used by pip) mux.HandleFunc("GET /simple/", h.handleSimpleIndex) mux.HandleFunc("GET /simple/{name}/", h.handleSimplePackage) @@ -99,10 +75,9 @@ func (h *PyPIHandler) handleSimplePackage(w http.ResponseWriter, r *http.Request h.proxy.Logger.Info("pypi simple request", "package", name) upstreamURL := fmt.Sprintf("%s/simple/%s/", h.upstreamURL, name) - accept := selectPyPISimpleRepresentation(r.Header.Get("Accept")) - cacheKey := pypiSimpleCacheKey(name, accept) + cacheKey := name + "/simple" - body, contentType, err := h.proxy.FetchOrCacheMetadata(r.Context(), "pypi", cacheKey, upstreamURL, accept) + body, _, err := h.proxy.FetchOrCacheMetadata(r.Context(), "pypi", cacheKey, upstreamURL, "text/html") if err != nil { if errors.Is(err, ErrUpstreamNotFound) { http.Error(w, "not found", http.StatusNotFound) @@ -119,143 +94,35 @@ func (h *PyPIHandler) handleSimplePackage(w http.ResponseWriter, r *http.Request filteredVersions = h.fetchFilteredVersions(r, name) } - var rewritten []byte - if isJSONMediaType(contentType) { - rewritten, err = h.rewriteSimpleJSON(body, filteredVersions) - if err != nil { - h.proxy.Logger.Warn("failed to rewrite pypi simple json, proxying original", "error", err) - rewritten = body - } - } else { - rewritten = h.rewriteSimpleHTML(body, filteredVersions) - } + rewritten := h.rewriteSimpleHTML(body, filteredVersions) - w.Header().Set(headerContentType, contentType) - ensureVaryAccept(w.Header()) + w.Header().Set("Content-Type", "text/html") w.WriteHeader(http.StatusOK) _, _ = w.Write(rewritten) } -func selectPyPISimpleRepresentation(accept string) string { - if strings.TrimSpace(accept) == "" { - return pypiLegacyHTML - } - - type score struct { - quality float64 - specificity int - matched bool - } - - scores := map[string]score{ - pypiSimpleJSON: {}, - pypiSimpleHTML: {}, - pypiLegacyHTML: {}, - } - - update := func(representation string, quality float64, specificity int) { - current := scores[representation] - if !current.matched || specificity > current.specificity || - (specificity == current.specificity && quality > current.quality) { - scores[representation] = score{quality: quality, specificity: specificity, matched: true} - } - } - - for part := range strings.SplitSeq(accept, ",") { - mediaType, params, err := mime.ParseMediaType(strings.TrimSpace(part)) - if err != nil { - continue - } - - quality := 1.0 - if value, ok := params["q"]; ok { - quality, err = strconv.ParseFloat(value, 64) - if err != nil || quality < 0 || quality > 1 { - continue - } - } - - switch mediaType { - case pypiSimpleJSON, pypiSimpleLatestJSON: - update(pypiSimpleJSON, quality, pypiExactSpecificity) - case pypiSimpleHTML, pypiSimpleLatestHTML: - update(pypiSimpleHTML, quality, pypiExactSpecificity) - case pypiLegacyHTML: - update(pypiLegacyHTML, quality, pypiExactSpecificity) - case "application/*": - update(pypiSimpleJSON, quality, 1) - update(pypiSimpleHTML, quality, 1) - case "text/*": - update(pypiLegacyHTML, quality, 1) - case "*/*": - update(pypiSimpleJSON, quality, 0) - update(pypiSimpleHTML, quality, 0) - update(pypiLegacyHTML, quality, 0) - } - } - - bestMediaType := "" - bestScore := score{} - for _, mediaType := range []string{pypiSimpleJSON, pypiSimpleHTML, pypiLegacyHTML} { - candidate := scores[mediaType] - if !candidate.matched || candidate.quality == 0 { - continue - } - if bestMediaType == "" || candidate.quality > bestScore.quality || - (candidate.quality == bestScore.quality && candidate.specificity > bestScore.specificity) { - bestMediaType = mediaType - bestScore = candidate - } - } - - if bestMediaType == "" || bestScore.specificity == 0 { - return pypiLegacyHTML - } - return bestMediaType -} - -func pypiSimpleCacheKey(name, mediaType string) string { - switch mediaType { - case pypiSimpleJSON: - return name + "/simple/json" - case pypiSimpleHTML: - return name + "/simple/html" - default: - return name + "/simple" - } -} - -func isJSONMediaType(contentType string) bool { - mediaType, _, err := mime.ParseMediaType(contentType) - if err != nil { - return false - } - return mediaType == "application/json" || strings.HasSuffix(mediaType, "+json") -} - -func ensureVaryAccept(header http.Header) { - for _, value := range header.Values("Vary") { - for field := range strings.SplitSeq(value, ",") { - if strings.EqualFold(strings.TrimSpace(field), "Accept") { - return - } - } - } - header.Add("Vary", "Accept") -} - // fetchFilteredVersions fetches JSON metadata and returns a set of version strings // that should be filtered out due to cooldown. func (h *PyPIHandler) fetchFilteredVersions(r *http.Request, name string) map[string]bool { jsonURL := fmt.Sprintf("%s/pypi/%s/json", h.upstreamURL, name) - - body, _, err := h.proxy.FetchOrCacheMetadata(r.Context(), "pypi", name+"/json", jsonURL) + req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, jsonURL, nil) if err != nil { return nil } + req.Header.Set("Accept", "application/json") + + resp, err := h.proxy.HTTPClient.Do(req) + if err != nil { + return nil + } + defer func() { _ = resp.Body.Close() }() + + if resp.StatusCode != http.StatusOK { + return nil + } var metadata map[string]any - if err := json.Unmarshal(body, &metadata); err != nil { + if err := json.NewDecoder(resp.Body).Decode(&metadata); err != nil { return nil } @@ -264,7 +131,7 @@ func (h *PyPIHandler) fetchFilteredVersions(r *http.Request, name string) map[st return nil } - packagePURL := canonicalPackagePURL("pypi", name) + packagePURL := purl.MakePURLString("pypi", name, "") filtered := make(map[string]bool) for version, files := range releases { @@ -307,54 +174,28 @@ func (h *PyPIHandler) rewriteSimpleHTML(body []byte, filteredVersions map[string }) } - // Match href attributes pointing to packages on the configured download host. - return h.downloadHrefRe.ReplaceAllFunc(body, func(match []byte) []byte { - submatch := h.downloadHrefRe.FindSubmatch(match) + // Match href attributes pointing to packages + // PyPI URLs look like: https://files.pythonhosted.org/packages/... + re := regexp.MustCompile(`href="(https://files\.pythonhosted\.org/packages/[^"]+)"`) + + return re.ReplaceAllFunc(body, func(match []byte) []byte { + submatch := re.FindSubmatch(match) if len(submatch) < minSubmatchParts { return match } origURL := string(submatch[1]) - newURL := h.proxyURL + "/pypi/packages" + strings.TrimPrefix(origURL, h.downloadURL) + u, err := url.Parse(origURL) + if err != nil { + return match + } + + newURL := fmt.Sprintf("%s/pypi/packages%s", h.proxyURL, u.Path) return []byte(fmt.Sprintf(`href="%s"`, newURL)) }) } -func (h *PyPIHandler) rewriteSimpleJSON(body []byte, filteredVersions map[string]bool) ([]byte, error) { - var metadata map[string]any - if err := json.Unmarshal(body, &metadata); err != nil { - return nil, err - } - - files, ok := metadata["files"].([]any) - if !ok { - return nil, errors.New("pypi simple json response has no files array") - } - - rewrittenFiles := make([]any, 0, len(files)) - for _, file := range files { - entry, ok := file.(map[string]any) - if !ok { - rewrittenFiles = append(rewrittenFiles, file) - continue - } - - if filename, ok := entry["filename"].(string); ok { - _, version := h.parseFilename(filename) - if version != "" && filteredVersions[version] { - continue - } - } - - h.rewriteURLEntry(entry) - rewrittenFiles = append(rewrittenFiles, entry) - } - - metadata["files"] = rewrittenFiles - return json.Marshal(metadata) -} - // handleJSON serves the JSON API package metadata. func (h *PyPIHandler) handleJSON(w http.ResponseWriter, r *http.Request) { name := r.PathValue("name") @@ -401,12 +242,12 @@ func (h *PyPIHandler) proxyAndRewriteJSON(w http.ResponseWriter, r *http.Request rewritten, err := h.rewriteJSONMetadata(body) if err != nil { h.proxy.Logger.Warn("failed to rewrite metadata, proxying original", "error", err) - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") _, _ = w.Write(body) return } - w.Header().Set(headerContentType, "application/json") + w.Header().Set("Content-Type", "application/json") _, _ = w.Write(rewritten) } @@ -421,7 +262,7 @@ func (h *PyPIHandler) rewriteJSONMetadata(body []byte) ([]byte, error) { packageName, _ := extractPyPIName(metadata) packagePURL := "" if packageName != "" { - packagePURL = canonicalPackagePURL("pypi", packageName) + packagePURL = purl.MakePURLString("pypi", packageName, "") } h.filterAndRewriteReleases(metadata, packageName, packagePURL) @@ -465,21 +306,6 @@ func (h *PyPIHandler) shouldFilterRelease(packagePURL string, files any) bool { return !publishedAt.IsZero() && !h.proxy.Cooldown.IsAllowed("pypi", packagePURL, publishedAt) } -// versionInCooldown reports whether a version is still inside the cooldown -// window. Filtering the simple index is not enough on its own: file URLs are -// recorded in lockfiles and requirements pins, so pip can reach the download -// path without ever reading the index. -// -// A release whose upload time cannot be determined is allowed through, matching -// how fetchFilteredVersions treats it. -func (h *PyPIHandler) versionInCooldown(r *http.Request, name, version string) bool { - if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() { - return false - } - - return h.fetchFilteredVersions(r, name)[version] -} - // rewriteFileEntries rewrites URLs in a list of file entries. func (h *PyPIHandler) rewriteFileEntries(files any) { filesArr, ok := files.([]any) @@ -555,8 +381,15 @@ func (h *PyPIHandler) rewriteURLEntry(entry map[string]any) { return } - if strings.HasPrefix(urlStr, h.downloadURL+"/packages/") { - entry["url"] = h.proxyURL + "/pypi/packages" + strings.TrimPrefix(urlStr, h.downloadURL) + u, err := url.Parse(urlStr) + if err != nil { + return + } + + // Only rewrite pythonhosted.org URLs + if u.Host == "files.pythonhosted.org" { + newURL := fmt.Sprintf("%s/pypi/packages%s", h.proxyURL, u.Path) + entry["url"] = newURL } } @@ -579,13 +412,6 @@ func (h *PyPIHandler) handleDownload(w http.ResponseWriter, r *http.Request) { filename := parts[len(parts)-1] name, version := h.parseFilename(filename) - if name != "" && h.versionInCooldown(r, name, version) { - h.proxy.Logger.Info("cooldown: withholding pypi file", - "name", name, "version", version, "filename", filename) - http.Error(w, "not found", http.StatusNotFound) - return - } - if name == "" { // Can't determine name/version, use hash as identifier name = fmt.Sprintf("_hash_%s", hashPath(path)) @@ -595,176 +421,71 @@ func (h *PyPIHandler) handleDownload(w http.ResponseWriter, r *http.Request) { h.proxy.Logger.Info("pypi download request", "name", name, "version", version, "filename", filename) - // The path value starts with 'packages/' (no leading slash), so add - // the separator here. - upstreamURL := fmt.Sprintf("%s/%s", h.downloadURL, path) + // Construct upstream URL; the incoming path starts with + // '/packages' so there is no need to include it in the format + // string + upstreamURL := fmt.Sprintf("https://files.pythonhosted.org/%s", path) result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "pypi", name, version, filename, upstreamURL) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch package") + h.proxy.Logger.Error("failed to get artifact", "error", err) + http.Error(w, "failed to fetch package", http.StatusBadGateway) return } ServeArtifact(w, result) } -// archiveExtensions are sdist formats of the form {name}-{version}{ext}. They -// carry no trailing tags, but legacy sdist names may contain hyphens. -var archiveExtensions = []string{".tar.gz", ".tar.bz2", ".tar.xz", ".tar.Z", ".tgz", ".tar", ".zip"} - -// windowsInstallerExtensions are the legacy distutils bdist_wininst and -// bdist_msi formats, which share a filename layout. -var windowsInstallerExtensions = []string{".exe", ".msi"} - // parseFilename extracts package name and version from a PyPI filename. -// Handles wheels, sdists and legacy bdist formats: +// Handles both wheels and sdists: // - requests-2.31.0-py3-none-any.whl // - requests-2.31.0.tar.gz -// - numpy-1.8.0-py2.7-macosx-10.9-x86_64.egg -// - numpy-1.8.0.win32-py2.7.exe func (h *PyPIHandler) parseFilename(filename string) (name, version string) { - // PEP 658/714 core-metadata sidecars are the distribution filename plus - // ".metadata"; they describe the same name and version. Without this, pip's - // metadata-only fetches fall back to a hash-derived package identifier. - filename = strings.TrimSuffix(filename, PyPIMetadataSuffix) - - switch { - case strings.HasSuffix(filename, ".whl"): - return parseWheelFilename(strings.TrimSuffix(filename, ".whl")) - case strings.HasSuffix(filename, ".egg"): - return parseEggFilename(strings.TrimSuffix(filename, ".egg")) - } - - for _, ext := range windowsInstallerExtensions { - if strings.HasSuffix(filename, ext) { - return parseWindowsInstallerFilename(strings.TrimSuffix(filename, ext)) + // Try wheel format first: {name}-{version}(-{build})?-{python}-{abi}-{platform}.whl + if strings.HasSuffix(filename, ".whl") { + base := strings.TrimSuffix(filename, ".whl") + parts := strings.Split(base, "-") + if len(parts) >= minWheelParts { + // Find where version ends (version followed by python tag) + for i := 1; i < len(parts)-2; i++ { + // Check if this looks like a python tag (py2, py3, cp39, etc) + if isPythonTag(parts[i]) { + name = strings.Join(parts[:i-1], "-") + version = parts[i-1] + return + } + } } } - for _, ext := range archiveExtensions { + // Try sdist formats: {name}-{version}.tar.gz, {name}-{version}.zip + for _, ext := range []string{".tar.gz", ".tar.bz2", ".zip", ".tar"} { if strings.HasSuffix(filename, ext) { - return splitNameVersion(strings.TrimSuffix(filename, ext)) + base := strings.TrimSuffix(filename, ext) + // Find last hyphen followed by version + for i := len(base) - 1; i >= 0; i-- { + if base[i] == '-' && i+1 < len(base) && isVersionStart(base[i+1]) { + return base[:i], base[i+1:] + } + } } } return "", "" } -// parseWheelFilename parses the PEP 427 layout -// {name}-{version}(-{build})?-{python}-{abi}-{platform}, base being the -// filename without its ".whl" suffix. The spec escapes every hyphen in the name -// and version to '_', so the first two fields are authoritative even when the -// optional build tag is present. -func parseWheelFilename(base string) (name, version string) { - parts := strings.Split(base, "-") - if len(parts) < minWheelParts { - return "", "" - } - - return parts[0], parts[1] -} - -// parseEggFilename parses the setuptools bdist_egg layout -// {name}-{version}-py{X.Y}(-{platform})?, base being the filename without its -// ".egg" suffix. setuptools escapes hyphens in the name and version to '_', but -// eggs built by other tooling do not always, so the version is located relative -// to the interpreter field rather than assumed to be the second field. -func parseEggFilename(base string) (name, version string) { - parts := strings.Split(base, "-") - // Scan from the end: the trailing platform fields never look like an - // interpreter tag, so the last match is the real one even when the package - // name itself carries a "py{N}" component. Stop before index 1, since a tag - // any earlier would leave no room for both a name and a version. - for i := len(parts) - 1; i >= minEggParts-1; i-- { - if !isEggPythonTag(parts[i]) || !isVersionField(parts[i-1]) { - continue - } - - return strings.Join(parts[:i-1], "-"), parts[i-1] - } - - // No interpreter field: {name}-{version}. - return splitNameVersion(base) -} - -// parseWindowsInstallerFilename parses the distutils bdist_wininst and -// bdist_msi layout {name}-{version}.{platform}(-py{X.Y})?, base being the -// filename without its ".exe" or ".msi" suffix. The platform is joined to the -// version with a '.' rather than a '-' and may itself contain a hyphen -// ("win-amd64"), so both trailing fields are stripped before the name and -// version are split apart. -func parseWindowsInstallerFilename(base string) (name, version string) { - if i := strings.LastIndex(base, "-py"); i >= 0 && isDottedNumber(base[i+len("-py"):]) { - base = base[:i] - } - - // The platform is the final '.'-separated field. Requiring it to start with - // a non-digit keeps a dotted version from being truncated when a filename - // carries no platform tag. - i := strings.LastIndex(base, ".") - if i < 0 || i+1 >= len(base) || isVersionStart(base[i+1]) { - return "", "" - } - - return splitFullname(base[:i]) -} - -// splitFullname splits the distutils fullname {name}-{version} that precedes a -// Windows installer's platform field. Unlike an sdist, a wininst fullname may -// carry a trailing build variant ("cx_Oracle-5.1.2-11g"), which belongs to -// neither the name nor the version, so the first purely numeric field wins and -// anything after it is discarded. -func splitFullname(fullname string) (name, version string) { - parts := strings.Split(fullname, "-") - for i := 1; i < len(parts); i++ { - if isDottedNumber(parts[i]) { - return strings.Join(parts[:i], "-"), parts[i] - } - } - - // No purely numeric field, e.g. a prerelease version like "1.0b1". - return splitNameVersion(fullname) -} - -// splitNameVersion splits a {name}-{version} pair at the last hyphen that -// starts a version, leaving hyphens inside the name intact. -func splitNameVersion(base string) (name, version string) { - for i := len(base) - 1; i >= 0; i-- { - if base[i] == '-' && i+1 < len(base) && isVersionStart(base[i+1]) { - return base[:i], base[i+1:] - } - } - - return "", "" -} - -// isEggPythonTag reports whether field is the py{X.Y} interpreter field that -// setuptools places directly after the version in an egg filename. -func isEggPythonTag(field string) bool { - const prefix = "py" - - return len(field) > len(prefix) && strings.HasPrefix(field, prefix) && isVersionStart(field[len(prefix)]) -} - -// isVersionField reports whether field can be a version, i.e. it is non-empty -// and starts with a digit as every PEP 440 release segment does. -func isVersionField(field string) bool { - return field != "" && isVersionStart(field[0]) -} - -// isDottedNumber reports whether s is a dotted numeric version such as "2.7". -func isDottedNumber(s string) bool { - if s == "" || !isVersionStart(s[0]) { +func isPythonTag(s string) bool { + if len(s) < minPythonTagLen { return false } - - for i := range len(s) { - if !isVersionStart(s[i]) && s[i] != '.' { - return false + // Python tags start with py, cp, pp, ip, jy + prefixes := []string{"py", "cp", "pp", "ip", "jy"} + for _, p := range prefixes { + if strings.HasPrefix(s, p) { + return true } } - - return true + return false } func isVersionStart(c byte) bool { @@ -785,7 +506,7 @@ func (h *PyPIHandler) proxySimple(w http.ResponseWriter, r *http.Request, path s http.Error(w, "failed to create request", http.StatusInternalServerError) return } - req.Header.Set("Accept", selectPyPISimpleRepresentation(r.Header.Get("Accept"))) + req.Header.Set("Accept", "text/html") resp, err := h.proxy.HTTPClient.Do(req) if err != nil { @@ -800,7 +521,6 @@ func (h *PyPIHandler) proxySimple(w http.ResponseWriter, r *http.Request, path s w.Header().Add(k, v) } } - ensureVaryAccept(w.Header()) w.WriteHeader(resp.StatusCode) _, _ = io.Copy(w, resp.Body) diff --git a/internal/handler/pypi_test.go b/internal/handler/pypi_test.go index c370719..9e2ade0 100644 --- a/internal/handler/pypi_test.go +++ b/internal/handler/pypi_test.go @@ -7,275 +7,13 @@ import ( "net/http" "net/http/httptest" "strings" - "sync/atomic" "testing" "time" - "github.com/git-pkgs/cooldown" + "github.com/git-pkgs/proxy/internal/cooldown" "github.com/git-pkgs/registries/fetch" ) -const uvPyPIAccept = "application/vnd.pypi.simple.v1+json, application/vnd.pypi.simple.v1+html;q=0.2, text/html;q=0.01" - -type pypiRoundTripFunc func(*http.Request) (*http.Response, error) - -func (f pypiRoundTripFunc) RoundTrip(r *http.Request) (*http.Response, error) { - return f(r) -} - -func pypiHTTPResponse(r *http.Request, contentType, body string) *http.Response { - return &http.Response{ - StatusCode: http.StatusOK, - Status: "200 OK", - Header: http.Header{"Content-Type": []string{contentType}}, - Body: io.NopCloser(strings.NewReader(body)), - ContentLength: int64(len(body)), - Request: r, - } -} - -func setupPyPIHandler(t testing.TB, transport pypiRoundTripFunc) (*PyPIHandler, *Proxy) { - t.Helper() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = &http.Client{Transport: transport} - h := NewPyPIHandlerWithUpstreams(proxy, "http://proxy.test", "", "") - h.upstreamURL = "https://pypi.test" - return h, proxy -} - -func TestSelectPyPISimpleRepresentation(t *testing.T) { - tests := []struct { - name string - accept string - want string - }{ - {"missing header uses legacy html", "", "text/html"}, - {"wildcard uses legacy html", "*/*", "text/html"}, - {"uv prefers json", uvPyPIAccept, pypiSimpleJSON}, - {"json only", pypiSimpleJSON, pypiSimpleJSON}, - {"latest json", pypiSimpleLatestJSON, pypiSimpleJSON}, - {"vendor html", pypiSimpleHTML, pypiSimpleHTML}, - {"higher html quality", pypiSimpleJSON + ";q=0.2, text/html;q=0.8", "text/html"}, - {"json excluded", pypiSimpleJSON + ";q=0, text/html", "text/html"}, - {"application wildcard", "application/*", pypiSimpleJSON}, - {"unsupported type uses legacy html", "application/xml", "text/html"}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - if got := selectPyPISimpleRepresentation(tt.accept); got != tt.want { - t.Errorf("selectPyPISimpleRepresentation(%q) = %q, want %q", tt.accept, got, tt.want) - } - }) - } -} - -func TestPyPISimplePackageNegotiatesJSON(t *testing.T) { - const upstreamBody = `{ - "meta":{"api-version":"1.4"}, - "name":"ruff", - "files":[{ - "filename":"ruff-0.16.0-py3-none-any.whl", - "url":"https://files.pythonhosted.org/packages/ab/cd/ruff-0.16.0-py3-none-any.whl", - "hashes":{"sha256":"abc123"}, - "upload-time":"2026-08-01T12:00:00Z" - }] - }` - - var upstreamAccept string - h, _ := setupPyPIHandler(t, func(r *http.Request) (*http.Response, error) { - upstreamAccept = r.Header.Get("Accept") - if r.URL.Path != "/simple/ruff/" { - t.Fatalf("upstream path = %q, want %q", r.URL.Path, "/simple/ruff/") - } - return pypiHTTPResponse(r, pypiSimpleJSON, upstreamBody), nil - }) - - req := httptest.NewRequest(http.MethodGet, "/simple/ruff/", nil) - req.Header.Set("Accept", uvPyPIAccept) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String()) - } - if upstreamAccept != pypiSimpleJSON { - t.Errorf("upstream Accept = %q, want %q", upstreamAccept, pypiSimpleJSON) - } - if got := w.Header().Get("Content-Type"); got != pypiSimpleJSON { - t.Errorf("Content-Type = %q, want %q", got, pypiSimpleJSON) - } - if got := w.Header().Get("Vary"); !strings.Contains(got, "Accept") { - t.Errorf("Vary = %q, want Accept", got) - } - - var result struct { - Meta map[string]string `json:"meta"` - Files []struct { - URL string `json:"url"` - UploadTime string `json:"upload-time"` - } `json:"files"` - } - if err := json.Unmarshal(w.Body.Bytes(), &result); err != nil { - t.Fatalf("decode response: %v", err) - } - if result.Meta["api-version"] != "1.4" { - t.Errorf("api-version = %q, want 1.4", result.Meta["api-version"]) - } - if len(result.Files) != 1 { - t.Fatalf("files = %d, want 1", len(result.Files)) - } - if got, want := result.Files[0].URL, "http://proxy.test/pypi/packages/packages/ab/cd/ruff-0.16.0-py3-none-any.whl"; got != want { - t.Errorf("file URL = %q, want %q", got, want) - } - if got := result.Files[0].UploadTime; got != "2026-08-01T12:00:00Z" { - t.Errorf("upload-time = %q, want %q", got, "2026-08-01T12:00:00Z") - } -} - -func TestPyPISimpleIndexNegotiatesJSON(t *testing.T) { - const upstreamBody = `{"meta":{"api-version":"1.4"},"projects":[{"name":"ruff"}]}` - - var upstreamAccept string - h, _ := setupPyPIHandler(t, func(r *http.Request) (*http.Response, error) { - upstreamAccept = r.Header.Get("Accept") - return pypiHTTPResponse(r, pypiSimpleJSON, upstreamBody), nil - }) - - req := httptest.NewRequest(http.MethodGet, "/simple/", nil) - req.Header.Set("Accept", uvPyPIAccept) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String()) - } - if upstreamAccept != pypiSimpleJSON { - t.Errorf("upstream Accept = %q, want %q", upstreamAccept, pypiSimpleJSON) - } - if got := w.Header().Get("Content-Type"); got != pypiSimpleJSON { - t.Errorf("Content-Type = %q, want %q", got, pypiSimpleJSON) - } - if got := w.Header().Get("Vary"); !strings.Contains(got, "Accept") { - t.Errorf("Vary = %q, want Accept", got) - } - if got := w.Body.String(); got != upstreamBody { - t.Errorf("body = %q, want %q", got, upstreamBody) - } -} - -func TestPyPISimplePackageKeepsHTMLDefault(t *testing.T) { - const upstreamBody = `ruff-0.16.0.tar.gz` - - var upstreamAccept string - h, _ := setupPyPIHandler(t, func(r *http.Request) (*http.Response, error) { - upstreamAccept = r.Header.Get("Accept") - return pypiHTTPResponse(r, "text/html", upstreamBody), nil - }) - - req := httptest.NewRequest(http.MethodGet, "/simple/ruff/", nil) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String()) - } - if upstreamAccept != "text/html" { - t.Errorf("upstream Accept = %q, want text/html", upstreamAccept) - } - if got := w.Header().Get("Content-Type"); got != "text/html" { - t.Errorf("Content-Type = %q, want text/html", got) - } - if !strings.Contains(w.Body.String(), `href="http://proxy.test/pypi/packages/packages/ab/cd/ruff-0.16.0.tar.gz"`) { - t.Errorf("download URL was not rewritten: %s", w.Body.String()) - } -} - -func TestPyPISimplePackageCachesRepresentationsSeparately(t *testing.T) { - hits := make(map[string]int) - h, proxy := setupPyPIHandler(t, func(r *http.Request) (*http.Response, error) { - accept := r.Header.Get("Accept") - hits[accept]++ - if accept == pypiSimpleJSON { - body := `{"meta":{"api-version":"1.4"},"name":"ruff","files":[]}` - return pypiHTTPResponse(r, pypiSimpleJSON, body), nil - } - return pypiHTTPResponse(r, accept, `ruff.tar.gz`), nil - }) - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - - for range 2 { - for _, accept := range []string{pypiLegacyHTML, pypiSimpleHTML, uvPyPIAccept} { - req := httptest.NewRequest(http.MethodGet, "/simple/ruff/", nil) - req.Header.Set("Accept", accept) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - if w.Code != http.StatusOK { - t.Fatalf("Accept %q: status = %d, want 200: %s", accept, w.Code, w.Body.String()) - } - } - } - - if got := hits[pypiLegacyHTML]; got != 1 { - t.Errorf("HTML upstream requests = %d, want 1", got) - } - if got := hits[pypiSimpleHTML]; got != 1 { - t.Errorf("vendor HTML upstream requests = %d, want 1", got) - } - if got := hits[pypiSimpleJSON]; got != 1 { - t.Errorf("JSON upstream requests = %d, want 1", got) - } -} - -func TestPyPISimpleJSONCooldown(t *testing.T) { - now := time.Now() - old := now.Add(-30 * 24 * time.Hour).Format(time.RFC3339) - recent := now.Add(-time.Hour).Format(time.RFC3339) - - h, proxy := setupPyPIHandler(t, func(r *http.Request) (*http.Response, error) { - switch r.URL.Path { - case "/simple/ruff/": - body := `{"meta":{"api-version":"1.4"},"name":"ruff","files":[` + - `{"filename":"ruff-1.0.0.tar.gz","url":"https://files.pythonhosted.org/packages/ab/ruff-1.0.0.tar.gz","upload-time":"` + old + `"},` + - `{"filename":"ruff-2.0.0.tar.gz","url":"https://files.pythonhosted.org/packages/cd/ruff-2.0.0.tar.gz","upload-time":"` + recent + `"}` + - `]}` - return pypiHTTPResponse(r, pypiSimpleJSON, body), nil - case "/pypi/ruff/json": - body := `{"releases":{` + - `"1.0.0":[{"upload_time_iso_8601":"` + old + `"}],` + - `"2.0.0":[{"upload_time_iso_8601":"` + recent + `"}]` + - `}}` - return pypiHTTPResponse(r, "application/json", body), nil - default: - t.Fatalf("unexpected upstream path: %s", r.URL.Path) - return nil, nil - } - }) - proxy.Cooldown = &cooldown.Config{Default: "7d"} - - req := httptest.NewRequest(http.MethodGet, "/simple/ruff/", nil) - req.Header.Set("Accept", uvPyPIAccept) - w := httptest.NewRecorder() - h.Routes().ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String()) - } - var result struct { - Files []struct { - Filename string `json:"filename"` - } `json:"files"` - } - if err := json.Unmarshal(w.Body.Bytes(), &result); err != nil { - t.Fatalf("decode response: %v", err) - } - if len(result.Files) != 1 || result.Files[0].Filename != "ruff-1.0.0.tar.gz" { - t.Errorf("files = %#v, want only ruff-1.0.0.tar.gz", result.Files) - } -} - func TestPyPIParseFilename(t *testing.T) { h := &PyPIHandler{proxy: &Proxy{Logger: slog.Default()}} @@ -290,58 +28,13 @@ func TestPyPIParseFilename(t *testing.T) { {"aws-sdk-1.0.0.tar.gz", "aws-sdk", "1.0.0"}, {"zipp-3.17.0.zip", "zipp", "3.17.0"}, - // Additional sdist archive formats - {"lxml-4.9.3.tar.xz", "lxml", "4.9.3"}, - {"docutils-0.20.1.tgz", "docutils", "0.20.1"}, - {"psycopg2-2.9.9.tar.bz2", "psycopg2", "2.9.9"}, - // Wheel formats {"requests-2.31.0-py3-none-any.whl", "requests", "2.31.0"}, {"numpy-1.26.2-cp311-cp311-manylinux_2_17_x86_64.whl", "numpy", "1.26.2"}, {"cryptography-41.0.5-cp37-abi3-manylinux_2_28_x86_64.whl", "cryptography", "41.0.5"}, - // Wheels with a build tag must not fold the tag into the version - {"foo-1.0-1-py3-none-any.whl", "foo", "1.0"}, - {"tensorflow-2.15.0-2-cp311-cp311-manylinux_2_17_x86_64.whl", "tensorflow", "2.15.0"}, - - // PEP 658 core-metadata sidecars resolve to the distribution they describe - {"backports_asyncio_runner-1.2.0-py3-none-any.whl.metadata", "backports_asyncio_runner", "1.2.0"}, - {"requests-2.31.0-py3-none-any.whl.metadata", "requests", "2.31.0"}, - {"requests-2.31.0.tar.gz.metadata", "requests", "2.31.0"}, - - // Eggs: {name}-{version}-py{X.Y}(-{platform})?.egg. Unescaped hyphens in - // the name must not be mistaken for the field separator before the version. - {"numpy-1.8.0-py2.7-macosx-10.9-x86_64.egg", "numpy", "1.8.0"}, - {"aws-sdk-1.0.0-py3.11.egg", "aws-sdk", "1.0.0"}, - {"aws-sdk-1.0.0-py2.7-macosx-10.9-x86_64.egg", "aws-sdk", "1.0.0"}, - {"aws-sdk-1.0.0.egg", "aws-sdk", "1.0.0"}, - // A "py{N}" component inside the name is not the interpreter field, so - // the interpreter must be located from the end of the filename. - {"django-rest-py3-1.0-py3.6.egg", "django-rest-py3", "1.0"}, - - // Windows installers: {name}-{version}.{platform}(-py{X.Y})?.{exe,msi}. - // The platform is not part of the version, and may contain a hyphen. - {"foo-1.0.win32-py2.0.exe", "foo", "1.0"}, - {"pywin32-223.win32-py2.7.exe", "pywin32", "223"}, - {"numpy-1.8.0.win-amd64-py2.7.exe", "numpy", "1.8.0"}, - {"aws-sdk-1.0.0.win32-py2.7.exe", "aws-sdk", "1.0.0"}, - {"pywin32-223.win32.exe", "pywin32", "223"}, - {"cx_Oracle-5.1.2.win32-py2.7.msi", "cx_Oracle", "5.1.2"}, - {"numpy-1.8.0.win-amd64.msi", "numpy", "1.8.0"}, - // A trailing build variant belongs to neither the name nor the version. - {"cx_Oracle-5.1.2-11g.win32-py2.7.exe", "cx_Oracle", "5.1.2"}, - // A prerelease version has no purely numeric field to anchor on. - {"foo-1.0b1.win32-py2.7.exe", "foo", "1.0b1"}, - // Invalid {"invalid", "", ""}, - {"invalid.metadata", "", ""}, - {"backports.ssl_match_hostname-3.4.0.2-py2.7.whl", "", ""}, - {"invalid.exe", "", ""}, - {"foo-1.0.exe", "", ""}, - // An egg with an interpreter field but no version must not promote the - // trailing component of a hyphenated name to the version. - {"aws-sdk-py2.7.egg", "", ""}, } for _, tt := range tests { @@ -401,24 +94,25 @@ func TestPyPIRewriteJSONMetadataCooldown(t *testing.T) { } } -// TestPyPIParseFilenameNoHashFallback guards the identifier used for caching: -// a filename that parses to an empty name makes handleDownload fall back to a -// "_hash_" package name, which surfaces as a bogus PURL in the package -// overview. -func TestPyPIParseFilenameNoHashFallback(t *testing.T) { - h := &PyPIHandler{proxy: &Proxy{Logger: slog.Default()}} - - filenames := []string{ - "backports_asyncio_runner-1.2.0-py3-none-any.whl", - "backports_asyncio_runner-1.2.0-py3-none-any.whl.metadata", - "backports_asyncio_runner-1.2.0.tar.gz", +func TestIsPythonTag(t *testing.T) { + tests := []struct { + tag string + want bool + }{ + {"py3", true}, + {"py2", true}, + {"cp311", true}, + {"cp37", true}, + {"pp39", true}, + {"none", false}, + {"any", false}, + {"manylinux", false}, } - for _, filename := range filenames { - name, version := h.parseFilename(filename) - if name != "backports_asyncio_runner" || version != "1.2.0" { - t.Errorf("parseFilename(%q) = (%q, %q), want (%q, %q)", - filename, name, version, "backports_asyncio_runner", "1.2.0") + for _, tt := range tests { + got := isPythonTag(tt.tag) + if got != tt.want { + t.Errorf("isPythonTag(%q) = %v, want %v", tt.tag, got, tt.want) } } } @@ -430,7 +124,7 @@ func TestPyPIHandler_DownloadUpstreamURL(t *testing.T) { ContentType: "application/octet-stream", } - h := NewPyPIHandlerWithUpstreams(proxy, "http://localhost", "", "") + h := NewPyPIHandler(proxy, "http://localhost") srv := httptest.NewServer(h.Routes()) defer srv.Close() @@ -458,7 +152,7 @@ func TestPyPIHandler_DownloadCacheHit(t *testing.T) { seedPackage(t, db, store, "pypi", "requests", "2.31.0", "requests-2.31.0-py3-none-any.whl", "wheel binary data") - h := NewPyPIHandlerWithUpstreams(proxy, "http://localhost", "", "") + h := NewPyPIHandler(proxy, "http://localhost") srv := httptest.NewServer(h.Routes()) defer srv.Close() @@ -484,7 +178,7 @@ func TestPyPIHandler_DownloadCacheMiss(t *testing.T) { ContentType: "application/octet-stream", } - h := NewPyPIHandlerWithUpstreams(proxy, "http://localhost", "", "") + h := NewPyPIHandler(proxy, "http://localhost") srv := httptest.NewServer(h.Routes()) defer srv.Close() @@ -498,116 +192,3 @@ func TestPyPIHandler_DownloadCacheMiss(t *testing.T) { t.Error("expected fetcher to be called on cache miss") } } - -func TestPyPIDownloadCooldown(t *testing.T) { - now := time.Now() - releases := `{"releases": { - "1.0.0": [{"upload_time_iso_8601": "` + now.Add(-30*24*time.Hour).Format(time.RFC3339) + `"}], - "2.0.0": [{"upload_time_iso_8601": "` + now.Add(-1*time.Hour).Format(time.RFC3339) + `"}] - }}` - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.Header().Set("Content-Type", contentTypeJSON) - _, _ = io.WriteString(w, releases) - })) - defer upstream.Close() - - tests := []struct { - name string - filename string - wantStatus int - }{ - {"published before the window serves the file", "newpkg-1.0.0.tar.gz", http.StatusOK}, - {"published inside the window is withheld", "newpkg-2.0.0.tar.gz", http.StatusNotFound}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - proxy, _, _, fetcher := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.Cooldown = &cooldown.Config{Default: "7d"} - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("sdist data")), - ContentType: "application/octet-stream", - } - - h := &PyPIHandler{ - proxy: proxy, - upstreamURL: upstream.URL, - proxyURL: "http://localhost", - } - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - resp, err := http.Get(srv.URL + "/packages/packages/ab/cd/ef0123456789/" + tt.filename) - if err != nil { - t.Fatalf("request failed: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != tt.wantStatus { - t.Errorf("status = %d, want %d", resp.StatusCode, tt.wantStatus) - } - if tt.wantStatus == http.StatusNotFound && fetcher.fetchCalled { - t.Error("fetched a version that is still inside the cooldown window") - } - }) - } -} - -// TestPyPIDownloadCooldownMetadataCache ensures that repeated downloads that -// trigger cooldown filtering reuse the cached PyPI JSON metadata instead of -// fetching it from upstream once per download. -func TestPyPIDownloadCooldownMetadataCache(t *testing.T) { - now := time.Now() - releases := `{"releases": { - "1.0.0": [{"upload_time_iso_8601": "` + now.Add(-30*24*time.Hour).Format(time.RFC3339) + `"}], - "2.0.0": [{"upload_time_iso_8601": "` + now.Add(-1*time.Hour).Format(time.RFC3339) + `"}] - }}` - - var metadataRequests atomic.Int64 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path == "/pypi/newpkg/json" { - metadataRequests.Add(1) - w.Header().Set("Content-Type", "application/json") - _, _ = io.WriteString(w, releases) - return - } - w.Header().Set("Content-Type", "application/octet-stream") - _, _ = io.WriteString(w, "package data") - })) - defer upstream.Close() - - proxy, _, _, fetcher := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - proxy.CacheMetadata = true - proxy.MetadataTTL = time.Hour - proxy.Cooldown = &cooldown.Config{Default: "7d"} - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("package data")), - ContentType: "application/octet-stream", - } - - h := &PyPIHandler{ - proxy: proxy, - upstreamURL: upstream.URL, - proxyURL: "http://localhost", - } - srv := httptest.NewServer(h.Routes()) - defer srv.Close() - - // Two downloads of the same package: one outside the cooldown window - // (served) and one inside (withheld). Both go through the download path - // that resolves filtered versions. - for _, filename := range []string{"newpkg-1.0.0.tar.gz", "newpkg-2.0.0.tar.gz"} { - resp, err := http.Get(srv.URL + "/packages/packages/ab/cd/ef0123456789/" + filename) - if err != nil { - t.Fatalf("request failed: %v", err) - } - _ = resp.Body.Close() - } - - if got := metadataRequests.Load(); got != 1 { - t.Errorf("upstream metadata JSON requests = %d, want 1 (repeated downloads should reuse the cached metadata)", got) - } -} diff --git a/internal/handler/read_metadata_test.go b/internal/handler/read_metadata_test.go index b13bddb..60c1cf2 100644 --- a/internal/handler/read_metadata_test.go +++ b/internal/handler/read_metadata_test.go @@ -7,12 +7,9 @@ import ( ) func TestReadMetadata(t *testing.T) { - const limit = 1024 - p := &Proxy{MetadataMaxSize: limit} - t.Run("small body", func(t *testing.T) { data := []byte("hello world") - got, err := p.ReadMetadata(bytes.NewReader(data)) + got, err := ReadMetadata(bytes.NewReader(data)) if err != nil { t.Fatalf("unexpected error: %v", err) } @@ -22,39 +19,27 @@ func TestReadMetadata(t *testing.T) { }) t.Run("exactly at limit", func(t *testing.T) { - data := make([]byte, limit) + data := make([]byte, maxMetadataSize) for i := range data { data[i] = 'x' } - got, err := p.ReadMetadata(bytes.NewReader(data)) + got, err := ReadMetadata(bytes.NewReader(data)) if err != nil { t.Fatalf("unexpected error: %v", err) } - if len(got) != limit { - t.Errorf("got length %d, want %d", len(got), limit) + if len(got) != int(maxMetadataSize) { + t.Errorf("got length %d, want %d", len(got), maxMetadataSize) } }) t.Run("over limit returns error", func(t *testing.T) { - data := make([]byte, limit+100) + data := make([]byte, maxMetadataSize+100) for i := range data { data[i] = 'x' } - _, err := p.ReadMetadata(bytes.NewReader(data)) + _, err := ReadMetadata(bytes.NewReader(data)) if !errors.Is(err, ErrMetadataTooLarge) { t.Errorf("got error %v, want ErrMetadataTooLarge", err) } }) - - t.Run("zero limit uses default", func(t *testing.T) { - p := &Proxy{} - data := make([]byte, 1<<20) - got, err := p.ReadMetadata(bytes.NewReader(data)) - if err != nil { - t.Fatalf("unexpected error: %v", err) - } - if len(got) != len(data) { - t.Errorf("got length %d, want %d", len(got), len(data)) - } - }) } diff --git a/internal/handler/rpm.go b/internal/handler/rpm.go index e06a3cc..6440d0f 100644 --- a/internal/handler/rpm.go +++ b/internal/handler/rpm.go @@ -30,13 +30,6 @@ func NewRPMHandler(proxy *Proxy, proxyURL string) *RPMHandler { } } -// NewRPMHandlerWithUpstream creates an RPM handler with a custom upstream. -func NewRPMHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *RPMHandler { - h := NewRPMHandler(proxy, proxyURL) - h.upstreamURL = configuredUpstreamURL(upstreamURL, defaultRPMUpstream) - return h -} - // Routes returns the HTTP handler for RPM requests. // Mount this at /rpm on your router. func (h *RPMHandler) Routes() http.Handler { @@ -90,11 +83,12 @@ func (h *RPMHandler) handlePackageDownload(w http.ResponseWriter, r *http.Reques result, err := h.proxy.GetOrFetchArtifactFromURL( r.Context(), "rpm", name, version, filename, downloadURL) if err != nil { - h.proxy.serveArtifactError(w, err, "failed to fetch package") + h.proxy.Logger.Error("failed to get rpm package", "error", err) + http.Error(w, "failed to fetch package", http.StatusBadGateway) return } - w.Header().Set(headerContentType, "application/x-rpm") + w.Header().Set("Content-Type", "application/x-rpm") ServeArtifact(w, result) } diff --git a/internal/handler/scan_test.go b/internal/handler/scan_test.go deleted file mode 100644 index 7480bad..0000000 --- a/internal/handler/scan_test.go +++ /dev/null @@ -1,310 +0,0 @@ -package handler - -import ( - "context" - "encoding/json" - "errors" - "io" - "log/slog" - "net/http" - "net/http/httptest" - "strings" - "testing" - "time" - - "github.com/git-pkgs/proxy/internal/config" - "github.com/git-pkgs/proxy/internal/scanner" - "github.com/git-pkgs/purl" - "github.com/git-pkgs/registries/fetch" -) - -// newTestScanServer returns an httptest.Server implementing the HTTPScanner -// notify contract, always replying with the given verdict. -func newTestScanServer(t testing.TB, allowed bool, reason string) *httptest.Server { - t.Helper() - srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - var body map[string]any - if err := json.NewDecoder(r.Body).Decode(&body); err != nil { - t.Errorf("decode scan notify body: %v", err) - } - if body["fetch_url"] == "" || body["fetch_url"] == nil { - t.Error("scan notify body missing fetch_url") - } - _ = json.NewEncoder(w).Encode(map[string]any{"allowed": allowed, "reason": reason}) - })) - t.Cleanup(srv.Close) - return srv -} - -func newTestScanGroup(t testing.TB, scanURL string, failOpen bool) *scanner.Group { - t.Helper() - g, err := scanner.NewGroup(config.ScanningConfig{ - Enabled: true, - FailOpen: failOpen, - Timeout: "15s", - SigningKey: "test-signing-key", - Scanners: []config.ScannerConfig{ - {Name: "test-scanner", URL: scanURL, Mode: "block"}, - }, - }, slog.New(slog.NewTextHandler(io.Discard, nil))) - if err != nil { - t.Fatalf("scanner.NewGroup() error: %v", err) - } - return g -} - -func TestGetOrFetchArtifact_ScanAllowed(t *testing.T) { - proxy, db, store, fetcher := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - proxy.Scanners = newTestScanGroup(t, newTestScanServer(t, true, "").URL, false) - - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("clean content")), - ContentType: "application/gzip", - } - - result, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "leftpad", "1.0.0", "leftpad-1.0.0.tgz") - if err != nil { - t.Fatalf("unexpected error: %v", err) - } - defer func() { _ = result.Reader.Close() }() - - body, _ := io.ReadAll(result.Reader) - if string(body) != "clean content" { - t.Errorf("body = %q, want %q", body, "clean content") - } - - cached, err := db.GetCachedArtifact( - purl.MakePURLString("npm", "leftpad", ""), purl.MakePURLString("npm", "leftpad", "1.0.0"), "leftpad-1.0.0.tgz") - if err != nil { - t.Fatalf("GetCachedArtifact() error: %v", err) - } - if cached == nil { - t.Error("expected allowed artifact to be committed to the cache database") - } - if len(store.files) == 0 { - t.Error("expected allowed artifact bytes to remain in storage") - } -} - -func TestGetOrFetchArtifact_ScanBlocked(t *testing.T) { - proxy, db, store, fetcher := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - proxy.Scanners = newTestScanGroup(t, newTestScanServer(t, false, "malware detected").URL, false) - - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("evil content")), - ContentType: "application/gzip", - } - - _, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "evilpkg", "1.0.0", "evilpkg-1.0.0.tgz") - if err == nil { - t.Fatal("expected error for blocked artifact") - } - if !errors.Is(err, ErrArtifactBlocked) { - t.Errorf("error = %v, want wrapped ErrArtifactBlocked", err) - } - if !strings.Contains(err.Error(), "malware detected") { - t.Errorf("error %q does not include scanner reason", err.Error()) - } - - cached, err := db.GetCachedArtifact( - purl.MakePURLString("npm", "evilpkg", ""), purl.MakePURLString("npm", "evilpkg", "1.0.0"), "evilpkg-1.0.0.tgz") - if err != nil { - t.Fatalf("GetCachedArtifact() error: %v", err) - } - if cached != nil { - t.Error("blocked artifact must never be committed to the cache database") - } - if len(store.files) != 0 { - t.Errorf("blocked artifact bytes must be deleted from storage, got %d files", len(store.files)) - } -} - -func TestGetOrFetchArtifact_BlockedDeleteSurvivesClientDisconnect(t *testing.T) { - proxy, db, store, fetcher := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - - const scanDelay = 150 * time.Millisecond - blockingSrv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - time.Sleep(scanDelay) - _ = json.NewEncoder(w).Encode(map[string]any{"allowed": false, "reason": "malware detected"}) - })) - t.Cleanup(blockingSrv.Close) - proxy.Scanners = newTestScanGroup(t, blockingSrv.URL, false) - - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("evil content")), - ContentType: "application/gzip", - } - - // The client disconnects long before the (genuinely malicious) verdict - // comes back; cleanup of the blocked bytes must not be skipped just - // because the client is gone. - ctx, cancel := context.WithCancel(context.Background()) - time.AfterFunc(20*time.Millisecond, cancel) - - _, err := proxy.GetOrFetchArtifact(ctx, "npm", "evilpkg", "1.0.0", "evilpkg-1.0.0.tgz") - if err == nil { - t.Fatal("expected error for blocked artifact") - } - if !errors.Is(err, ErrArtifactBlocked) { - t.Errorf("error = %v, want wrapped ErrArtifactBlocked", err) - } - - cached, _ := db.GetCachedArtifact( - purl.MakePURLString("npm", "evilpkg", ""), purl.MakePURLString("npm", "evilpkg", "1.0.0"), "evilpkg-1.0.0.tgz") - if cached != nil { - t.Error("blocked artifact must never be committed to the cache database") - } - if len(store.files) != 0 { - t.Errorf("blocked artifact bytes must still be deleted even though the client disconnected mid-scan, got %d orphaned files", len(store.files)) - } -} - -func TestGetOrFetchArtifact_ScanErrorFailClosed(t *testing.T) { - proxy, db, store, fetcher := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - - brokenSrv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.WriteHeader(http.StatusInternalServerError) - })) - t.Cleanup(brokenSrv.Close) - proxy.Scanners = newTestScanGroup(t, brokenSrv.URL, false) - - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("content")), - ContentType: "application/gzip", - } - - _, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "flaky", "1.0.0", "flaky-1.0.0.tgz") - if err == nil { - t.Fatal("expected error when scanner infrastructure fails") - } - if !errors.Is(err, ErrArtifactBlocked) { - t.Errorf("error = %v, want wrapped ErrArtifactBlocked (fail-closed default)", err) - } - if strings.Contains(err.Error(), brokenSrv.URL) { - t.Errorf("error %q leaks the internal scanner URL to the client-facing message", err.Error()) - } - if !strings.Contains(err.Error(), "scan could not be completed") { - t.Errorf("error %q does not use the generic infra-failure message", err.Error()) - } - - cached, _ := db.GetCachedArtifact( - purl.MakePURLString("npm", "flaky", ""), purl.MakePURLString("npm", "flaky", "1.0.0"), "flaky-1.0.0.tgz") - if cached != nil { - t.Error("artifact must not be committed when scanning fails fail-closed") - } - if len(store.files) != 0 { - t.Errorf("artifact bytes must be deleted on scan infra failure, got %d files", len(store.files)) - } -} - -func TestGetOrFetchArtifact_ScanErrorFailOpen(t *testing.T) { - proxy, db, store, fetcher := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - - brokenSrv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.WriteHeader(http.StatusInternalServerError) - })) - t.Cleanup(brokenSrv.Close) - proxy.Scanners = newTestScanGroup(t, brokenSrv.URL, true) - - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("content")), - ContentType: "application/gzip", - } - - result, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "flaky", "1.0.0", "flaky-1.0.0.tgz") - if err != nil { - t.Fatalf("unexpected error: %v (FailOpen must treat scanner infra failure as allowed)", err) - } - defer func() { _ = result.Reader.Close() }() - - cached, err := db.GetCachedArtifact( - purl.MakePURLString("npm", "flaky", ""), purl.MakePURLString("npm", "flaky", "1.0.0"), "flaky-1.0.0.tgz") - if err != nil { - t.Fatalf("GetCachedArtifact() error: %v", err) - } - if cached == nil { - t.Error("expected artifact to be committed to the cache when scanning fails fail-open") - } - if len(store.files) == 0 { - t.Error("expected artifact bytes to remain in storage when scanning fails fail-open") - } -} - -func TestGetOrFetchArtifact_ScanSurvivesClientDisconnect(t *testing.T) { - proxy, db, store, fetcher := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - - const scanDelay = 150 * time.Millisecond - slowSrv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - time.Sleep(scanDelay) - _ = json.NewEncoder(w).Encode(map[string]any{"allowed": true}) - })) - t.Cleanup(slowSrv.Close) - proxy.Scanners = newTestScanGroup(t, slowSrv.URL, false) - - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("clean content")), - ContentType: "application/gzip", - } - - // Simulate a client that disconnects shortly after issuing the request: - // its context is cancelled well before the scanner replies, but the - // scan itself must run to completion rather than being torn down with - // it. - ctx, cancel := context.WithCancel(context.Background()) - time.AfterFunc(20*time.Millisecond, cancel) - - start := time.Now() - result, err := proxy.GetOrFetchArtifact(ctx, "npm", "leftpad", "1.0.0", "leftpad-1.0.0.tgz") - elapsed := time.Since(start) - if err != nil { - t.Fatalf("unexpected error: %v (a cancelled client context must not be mistaken for a scanner failure)", err) - } - defer func() { _ = result.Reader.Close() }() - - if elapsed < scanDelay { - t.Errorf("GetOrFetchArtifact returned after %v, want it to wait out the full scan (%v) despite client cancellation", elapsed, scanDelay) - } - - cached, err := db.GetCachedArtifact( - purl.MakePURLString("npm", "leftpad", ""), purl.MakePURLString("npm", "leftpad", "1.0.0"), "leftpad-1.0.0.tgz") - if err != nil { - t.Fatalf("GetCachedArtifact() error: %v", err) - } - if cached == nil { - t.Error("expected artifact to be committed to the cache; a client disconnect must not cause a false block") - } - if len(store.files) == 0 { - t.Error("expected artifact bytes to remain in storage; a client disconnect must not delete a legitimately allowed artifact") - } -} - -func TestGetOrFetchArtifact_ScanDisabledIsNoOp(t *testing.T) { - proxy, db, _, fetcher := setupTestProxy(t) - // proxy.Scanners left nil: scanning disabled. - - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("content")), - ContentType: "application/gzip", - } - - result, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "plainpkg", "1.0.0", "plainpkg-1.0.0.tgz") - if err != nil { - t.Fatalf("unexpected error: %v", err) - } - defer func() { _ = result.Reader.Close() }() - - cached, err := db.GetCachedArtifact( - purl.MakePURLString("npm", "plainpkg", ""), purl.MakePURLString("npm", "plainpkg", "1.0.0"), "plainpkg-1.0.0.tgz") - if err != nil { - t.Fatalf("GetCachedArtifact() error: %v", err) - } - if cached == nil { - t.Error("expected artifact to be cached when scanning is disabled") - } -} diff --git a/internal/handler/scanfetch.go b/internal/handler/scanfetch.go deleted file mode 100644 index 832da9c..0000000 --- a/internal/handler/scanfetch.go +++ /dev/null @@ -1,89 +0,0 @@ -package handler - -import ( - "crypto/hmac" - "crypto/sha256" - "encoding/hex" - "fmt" - "io" - "net/http" - "net/url" - "strconv" - "time" -) - -// scanFetchURL builds a short-lived, HMAC-signed URL for the internal -// /_internal/scan-fetch route, so an external scanner can pull the exact -// bytes staged at path without going through cooldown or the scan hook -// itself. This is generated the same way for every storage backend: it -// never depends on Storage.SignedURL, which not every backend implements. -func (p *Proxy) scanFetchURL(path string, ttl time.Duration) string { - exp := time.Now().Add(ttl).Unix() - return fmt.Sprintf("%s/_internal/scan-fetch?path=%s&exp=%d&sig=%s", - p.ScanFetchBaseURL, url.QueryEscape(path), exp, hmacHex(p.ScanSigningKey, path, exp)) -} - -func hmacHex(key []byte, path string, exp int64) string { - mac := hmac.New(sha256.New, key) - _, _ = fmt.Fprintf(mac, "%s|%d", path, exp) - return hex.EncodeToString(mac.Sum(nil)) -} - -// ServeScanFetch streams a storage object to a caller presenting a valid -// short-lived HMAC token, so external scanners can pull a staged artifact -// without going through cooldown or the scan hook themselves. This handler -// never calls GetOrFetchArtifact/fetchAndCache/storeArtifact — the -// separation from the normal request path is structural, not a -// conditional bypass flag. -// -// This route exists only for scanners configured under ScanningConfig; the -// URL is minted by scanFetchURL and passed as fetch_url in the scan notify -// request. It is not part of the public API and should be restricted to -// internal-network access at the ingress/network-policy layer — the HMAC -// scoping (one object, short TTL) limits what a leaked token can do, but -// isn't a substitute for network restriction. -// -// @Summary Fetch a staged artifact for scanning -// @Description Streams the exact bytes staged in storage for a pre-cache security scan. -// @Description Requires a short-lived HMAC-signed token minted by the proxy itself and -// @Description delivered via the fetch_url field of the scan notify request (see the -// @Description Artifact Scanning section of docs/configuration.md). Not part of the -// @Description public API; restrict access to the scanner network at the ingress layer. -// @Tags scanning -// @Produce application/octet-stream -// @Param path query string true "Storage path of the staged artifact" -// @Param exp query int true "Token expiry, Unix seconds" -// @Param sig query string true "HMAC-SHA256 signature over the string path|exp" -// @Success 200 {file} file -// @Failure 403 {string} string "invalid, expired, or tampered token" -// @Failure 404 {string} string "object not found in storage, or scanning is not configured" -// @Router /_internal/scan-fetch [get] -func (p *Proxy) ServeScanFetch(w http.ResponseWriter, r *http.Request) { - if p.Scanners == nil || !p.Scanners.Enabled() || len(p.ScanSigningKey) == 0 { - http.Error(w, "not found", http.StatusNotFound) - return - } - - path := r.URL.Query().Get("path") - exp, err := strconv.ParseInt(r.URL.Query().Get("exp"), 10, 64) - if err != nil || containsPathTraversal(path) || time.Now().Unix() > exp { - http.Error(w, "invalid or expired token", http.StatusForbidden) - return - } - - want := hmacHex(p.ScanSigningKey, path, exp) - if !hmac.Equal([]byte(r.URL.Query().Get("sig")), []byte(want)) { - http.Error(w, "invalid signature", http.StatusForbidden) - return - } - - reader, err := p.Storage.Open(r.Context(), path) - if err != nil { - http.Error(w, "not found", http.StatusNotFound) - return - } - defer func() { _ = reader.Close() }() - - w.Header().Set("Content-Type", "application/octet-stream") - _, _ = io.Copy(w, reader) -} diff --git a/internal/handler/scanfetch_test.go b/internal/handler/scanfetch_test.go deleted file mode 100644 index 280f1a2..0000000 --- a/internal/handler/scanfetch_test.go +++ /dev/null @@ -1,153 +0,0 @@ -package handler - -import ( - "log/slog" - "net/http" - "net/http/httptest" - "strings" - "testing" - "time" - - "github.com/git-pkgs/proxy/internal/config" - "github.com/git-pkgs/proxy/internal/scanner" -) - -// newEnabledScanGroup returns a scanner.Group that reports Enabled() true, -// so tests can exercise ServeScanFetch's normal signature-checking path -// rather than tripping its "scanning not configured" guard. -func newEnabledScanGroup(t testing.TB) *scanner.Group { - t.Helper() - g, err := scanner.NewGroup(config.ScanningConfig{ - Enabled: true, - Timeout: "15s", - SigningKey: "test-signing-key", - Scanners: []config.ScannerConfig{ - {Name: "test-scanner", URL: "http://localhost/scan", Mode: "block"}, - }, - }, slog.Default()) - if err != nil { - t.Fatalf("scanner.NewGroup() error: %v", err) - } - return g -} - -func TestServeScanFetch_ValidToken(t *testing.T) { - proxy, _, store, _ := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - proxy.Scanners = newEnabledScanGroup(t) - store.files["npm/lodash/4.17.21/lodash-4.17.21.tgz"] = []byte("artifact bytes") - - target := proxy.scanFetchURL("npm/lodash/4.17.21/lodash-4.17.21.tgz", time.Minute) - - req := httptest.NewRequest(http.MethodGet, target, nil) - w := httptest.NewRecorder() - proxy.ServeScanFetch(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200; body: %s", w.Code, w.Body.String()) - } - if w.Body.String() != "artifact bytes" { - t.Errorf("body = %q, want %q", w.Body.String(), "artifact bytes") - } -} - -func TestServeScanFetch_Expired(t *testing.T) { - proxy, _, store, _ := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - proxy.Scanners = newEnabledScanGroup(t) - store.files["npm/lodash/4.17.21/lodash-4.17.21.tgz"] = []byte("artifact bytes") - - target := proxy.scanFetchURL("npm/lodash/4.17.21/lodash-4.17.21.tgz", -time.Minute) - - req := httptest.NewRequest(http.MethodGet, target, nil) - w := httptest.NewRecorder() - proxy.ServeScanFetch(w, req) - - if w.Code != http.StatusForbidden { - t.Errorf("status = %d, want 403", w.Code) - } -} - -func TestServeScanFetch_TamperedSignature(t *testing.T) { - proxy, _, store, _ := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - proxy.Scanners = newEnabledScanGroup(t) - store.files["npm/lodash/4.17.21/lodash-4.17.21.tgz"] = []byte("artifact bytes") - - target := proxy.scanFetchURL("npm/lodash/4.17.21/lodash-4.17.21.tgz", time.Minute) - tampered := strings.Replace(target, "sig=", "sig=deadbeef", 1) - - req := httptest.NewRequest(http.MethodGet, tampered, nil) - w := httptest.NewRecorder() - proxy.ServeScanFetch(w, req) - - if w.Code != http.StatusForbidden { - t.Errorf("status = %d, want 403", w.Code) - } -} - -func TestServeScanFetch_PathTraversal(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - proxy.Scanners = newEnabledScanGroup(t) - - target := proxy.scanFetchURL("../../etc/passwd", time.Minute) - - req := httptest.NewRequest(http.MethodGet, target, nil) - w := httptest.NewRecorder() - proxy.ServeScanFetch(w, req) - - if w.Code != http.StatusForbidden { - t.Errorf("status = %d, want 403", w.Code) - } -} - -func TestServeScanFetch_ScanningDisabled(t *testing.T) { - proxy, _, store, _ := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - // proxy.Scanners left nil: scanning disabled. - store.files["npm/lodash/4.17.21/lodash-4.17.21.tgz"] = []byte("artifact bytes") - - target := proxy.scanFetchURL("npm/lodash/4.17.21/lodash-4.17.21.tgz", time.Minute) - - req := httptest.NewRequest(http.MethodGet, target, nil) - w := httptest.NewRecorder() - proxy.ServeScanFetch(w, req) - - if w.Code != http.StatusNotFound { - t.Errorf("status = %d, want 404 when scanning is disabled", w.Code) - } -} - -func TestServeScanFetch_NoSigningKey(t *testing.T) { - proxy, _, store, _ := setupTestProxy(t) - // proxy.ScanSigningKey left empty. - proxy.Scanners = newEnabledScanGroup(t) - store.files["npm/lodash/4.17.21/lodash-4.17.21.tgz"] = []byte("artifact bytes") - - target := proxy.scanFetchURL("npm/lodash/4.17.21/lodash-4.17.21.tgz", time.Minute) - - req := httptest.NewRequest(http.MethodGet, target, nil) - w := httptest.NewRecorder() - proxy.ServeScanFetch(w, req) - - if w.Code != http.StatusNotFound { - t.Errorf("status = %d, want 404 when no signing key is configured", w.Code) - } -} - -func TestServeScanFetch_MissingObject(t *testing.T) { - proxy, _, _, _ := setupTestProxy(t) - proxy.ScanSigningKey = []byte("test-signing-key") - proxy.Scanners = newEnabledScanGroup(t) - - target := proxy.scanFetchURL("npm/missing/1.0.0/missing-1.0.0.tgz", time.Minute) - - req := httptest.NewRequest(http.MethodGet, target, nil) - w := httptest.NewRecorder() - proxy.ServeScanFetch(w, req) - - if w.Code != http.StatusNotFound { - t.Errorf("status = %d, want 404", w.Code) - } -} diff --git a/internal/handler/stale_cache_test.go b/internal/handler/stale_cache_test.go deleted file mode 100644 index 3d520a4..0000000 --- a/internal/handler/stale_cache_test.go +++ /dev/null @@ -1,160 +0,0 @@ -package handler - -import ( - "context" - "errors" - "io" - "strings" - "testing" -) - -// These tests cover an upstream re-publishing a version: the cache holds one -// artifact and upstream now declares another digest for it. - -const ( - stalePkgPURL = "pkg:npm/pkg" - staleVersionPURL = "pkg:npm/pkg@1.0.0" - staleFilename = "pkg-1.0.0.tgz" - staleStoragePath = "npm/pkg/1.0.0/pkg-1.0.0.tgz" - staleURL = "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz" -) - -// seedCachedArtifact commits content the way a fetch does. -func seedCachedArtifact(t *testing.T, proxy *Proxy, store *mockStorage, content string) { - t.Helper() - ctx := context.Background() - if _, _, err := store.Store(ctx, staleStoragePath, strings.NewReader(content)); err != nil { - t.Fatalf("seeding storage: %v", err) - } - artifact := testArtifact(content, staleVersionPURL, staleFilename, "application/gzip") - if err := proxy.updateCacheDB("npm", "pkg", stalePkgPURL, staleURL, staleStoragePath, artifact); err != nil { - t.Fatalf("seeding cache record: %v", err) - } -} - -// cachedDigest reports the digest the cache record holds, or "" without one. -func cachedDigest(t *testing.T, proxy *Proxy) string { - t.Helper() - record, err := proxy.DB.GetCachedArtifact(stalePkgPURL, staleVersionPURL, staleFilename) - if err != nil { - t.Fatalf("reading cache record: %v", err) - } - if record == nil { - return "" - } - return record.Artifact.Digest.Encoded() -} - -func bytesPresent(store *mockStorage) bool { - r, err := store.Open(context.Background(), staleStoragePath) - if err != nil { - return false - } - _ = r.Close() - return true -} - -func TestStaleCacheCheckHasNoSideEffects(t *testing.T) { - proxy, _, store, _ := setupTestProxy(t) - seedCachedArtifact(t, proxy, store, "old bytes") - - res, err := proxy.getCachedArtifactWithUpstreamHash(context.Background(), - stalePkgPURL, staleVersionPURL, staleFilename, sha256Hex("new bytes")) - if err != nil { - t.Fatalf("cache check failed: %v", err) - } - if res != nil { - drain(res) - t.Fatal("stale entry was served") - } - if got := cachedDigest(t, proxy); got != sha256Hex("old bytes") { - t.Errorf("record digest = %q, want the stale one kept: the check must not discard", got) - } - if !bytesPresent(store) { - t.Error("stale bytes were deleted by the check") - } -} - -func TestStaleCacheIsDiscardedBeforeTheFetch(t *testing.T) { - proxy, _, store, fetcher := setupTestProxy(t) - seedCachedArtifact(t, proxy, store, "old bytes") - boom := errors.New("upstream unavailable") - fetcher.fetchErr = boom - - _, err := proxy.GetOrFetchArtifactFromURLWithDigest(context.Background(), - "npm", "pkg", "1.0.0", staleFilename, staleURL, "sha256:"+sha256Hex("new bytes")) - if !errors.Is(err, boom) { - t.Fatalf("got %v, want the fetch failure", err) - } - if got := cachedDigest(t, proxy); got != "" { - t.Errorf("stale record survived a failed refresh, digest = %q", got) - } - if bytesPresent(store) { - t.Error("stale bytes survived a failed refresh") - } -} - -func TestStaleCacheIsReplacedByTheFetch(t *testing.T) { - proxy, _, store, fetcher := setupTestProxy(t) - seedCachedArtifact(t, proxy, store, "old bytes") - fetcher.artifact = artifactBody("new bytes") - upstream := sha256Hex("new bytes") - - res, err := proxy.GetOrFetchArtifactFromURLWithDigest(context.Background(), - "npm", "pkg", "1.0.0", staleFilename, staleURL, "sha256:"+upstream) - if err != nil { - t.Fatalf("refresh failed: %v", err) - } - got, err := io.ReadAll(res.Reader) - _ = res.Reader.Close() - if err != nil || string(got) != "new bytes" { - t.Fatalf("got %q (err %v), want the refreshed bytes", got, err) - } - if !fetcher.fetchCalled { - t.Error("stale entry was served without a fetch") - } - if d := cachedDigest(t, proxy); d != upstream { - t.Errorf("record digest = %q, want %q", d, upstream) - } - - fetcher.fetchCalled = false - res, err = proxy.GetOrFetchArtifactFromURLWithDigest(context.Background(), - "npm", "pkg", "1.0.0", staleFilename, staleURL, "sha256:"+upstream) - if err != nil { - t.Fatalf("request after refresh failed: %v", err) - } - drain(res) - if fetcher.fetchCalled || !res.Cached { - t.Errorf("request after refresh: fetched=%v cached=%v, want served from cache", fetcher.fetchCalled, res.Cached) - } -} - -// TestLateLeaderKeepsRefreshedEntry is the race, at the point it would happen: -// a caller whose cache check saw a stale entry reaches the coalescing step -// after another caller's fetch replaced it. It must serve the replacement. -func TestLateLeaderKeepsRefreshedEntry(t *testing.T) { - proxy, _, store, fetcher := setupTestProxy(t) - seedCachedArtifact(t, proxy, store, "new bytes") - fetcher.fetchErr = errors.New("must not fetch") - upstream := sha256Hex("new bytes") - - res, err := proxy.coalescedFetchFromURL(context.Background(), - "npm", "pkg", "1.0.0", staleFilename, stalePkgPURL, staleVersionPURL, staleURL, nil, upstream) - if err != nil { - t.Fatalf("late leader failed: %v", err) - } - got, err := io.ReadAll(res.Reader) - _ = res.Reader.Close() - if err != nil || string(got) != "new bytes" { - t.Fatalf("got %q (err %v), want the refreshed bytes", got, err) - } - if fetcher.fetchCalled { - t.Error("refreshed entry was fetched again") - } - if d := cachedDigest(t, proxy); d != upstream { - t.Errorf("refreshed record was discarded, digest = %q", d) - } - if !bytesPresent(store) { - t.Error("refreshed bytes were deleted") - } -} diff --git a/internal/handler/swift.go b/internal/handler/swift.go deleted file mode 100644 index 1c289d0..0000000 --- a/internal/handler/swift.go +++ /dev/null @@ -1,645 +0,0 @@ -package handler - -import ( - "context" - "crypto/sha256" - "encoding/base64" - "encoding/hex" - "encoding/json" - "errors" - "fmt" - "io" - "net/http" - "net/url" - "strconv" - "strings" - - "github.com/git-pkgs/proxy/internal/config" - "github.com/git-pkgs/proxy/internal/packageurl" -) - -const ( - swiftAcceptJSON = "application/vnd.swift.registry.v1+json" - swiftAcceptManifest = "application/vnd.swift.registry.v1+swift" - swiftAcceptArchive = "application/vnd.swift.registry.v1+zip" - swiftContentVersion = "1" - swiftMaxScopeLength = 39 - swiftMaxNameLength = 100 -) - -// SwiftHandler handles the read-only Swift Package Registry v1 protocol. -type SwiftHandler struct { - proxy *Proxy - upstreamURL string - proxyURL string -} - -// NewSwiftHandler creates a Swift Package Registry protocol handler. -func NewSwiftHandler(proxy *Proxy, proxyURL, upstreamURL string) *SwiftHandler { - if strings.TrimSpace(upstreamURL) == "" { - upstreamURL = config.DefaultSwiftUpstream - } - - return &SwiftHandler{ - proxy: proxy, - upstreamURL: strings.TrimSuffix(upstreamURL, "/"), - proxyURL: strings.TrimSuffix(proxyURL, "/"), - } -} - -// Routes returns the HTTP handler for Swift registry requests. -func (h *SwiftHandler) Routes() http.Handler { - mux := http.NewServeMux() - mux.HandleFunc("GET /identifiers", h.handleIdentifiers) - mux.HandleFunc("GET /{scope}/{name}/{version}/Package.swift", h.handleManifest) - mux.HandleFunc("GET /{scope}/{name}/{version}", h.handleRelease) - mux.HandleFunc("PUT /{scope}/{name}/{version}", h.handlePublishingUnsupported) - mux.HandleFunc("GET /{scope}/{name}", h.handlePackageReleases) - return mux -} - -func (h *SwiftHandler) handlePackageReleases(w http.ResponseWriter, r *http.Request) { - scope := r.PathValue("scope") - name := strings.TrimSuffix(r.PathValue("name"), ".json") - if !validSwiftScope(scope) || !validSwiftPackageName(name) { - writeSwiftProblem(w, http.StatusBadRequest, "invalid package identifier") - return - } - scope, name = canonicalSwiftPackage(scope, name) - - upstreamURL := h.buildUpstreamURL(scope, name, "", "", r.URL.RawQuery) - body, contentType, responseHeaders, err := h.fetchMetadataWithHeaders( - r.Context(), upstreamURL, requestAccept(r, swiftAcceptJSON), - ) - if err != nil { - h.writeMetadataError(w, err) - return - } - - rewritten, err := h.rewriteReleaseURLs(scope, name, body) - if err != nil { - h.proxy.Logger.Warn("failed to rewrite Swift release URLs", "error", err) - rewritten = body - } - for _, link := range responseHeaders.Values("Link") { - w.Header().Add("Link", h.rewriteLinkHeader(link, upstreamURL)) - } - writeSwiftMetadata(w, r, rewritten, contentType) -} - -func (h *SwiftHandler) handleRelease(w http.ResponseWriter, r *http.Request) { - scope := r.PathValue("scope") - name := r.PathValue("name") - version := r.PathValue("version") - if strings.HasSuffix(version, ".zip") { - h.handleSourceArchive(w, r, scope, name, strings.TrimSuffix(version, ".zip")) - return - } - - version = strings.TrimSuffix(version, ".json") - if !validSwiftPackageReference(scope, name, version) { - writeSwiftProblem(w, http.StatusBadRequest, "invalid package release") - return - } - scope, name = canonicalSwiftPackage(scope, name) - - upstreamURL := h.buildUpstreamURL(scope, name, version, "", r.URL.RawQuery) - body, contentType, err := h.proxy.FetchOrCacheMetadata( - r.Context(), "swift", swiftReleaseCacheKey(scope, name, version), upstreamURL, requestAccept(r, swiftAcceptJSON), - ) - if err != nil { - h.writeMetadataError(w, err) - return - } - writeSwiftMetadata(w, r, body, contentType) -} - -func (h *SwiftHandler) handleManifest(w http.ResponseWriter, r *http.Request) { - scope := r.PathValue("scope") - name := r.PathValue("name") - version := r.PathValue("version") - if !validSwiftPackageReference(scope, name, version) { - writeSwiftProblem(w, http.StatusBadRequest, "invalid package release") - return - } - scope, name = canonicalSwiftPackage(scope, name) - - upstreamURL := h.buildUpstreamURL(scope, name, version, "Package.swift", r.URL.RawQuery) - h.proxySwiftResource(w, r, upstreamURL, swiftAcceptManifest) -} - -func (h *SwiftHandler) handleIdentifiers(w http.ResponseWriter, r *http.Request) { - if r.URL.Query().Get("url") == "" { - writeSwiftProblem(w, http.StatusBadRequest, "url query parameter is required") - return - } - - upstreamURL := h.upstreamURL + "/identifiers?" + r.URL.RawQuery - cacheKey := swiftMetadataCacheKey("identifiers", r.URL.RawQuery) - body, contentType, err := h.proxy.FetchOrCacheMetadata( - r.Context(), "swift", cacheKey, upstreamURL, requestAccept(r, swiftAcceptJSON), - ) - if err != nil { - h.writeMetadataError(w, err) - return - } - writeSwiftMetadata(w, r, body, contentType) -} - -func (h *SwiftHandler) handlePublishingUnsupported(w http.ResponseWriter, _ *http.Request) { - w.Header().Set("Allow", "GET, HEAD") - writeSwiftProblem(w, http.StatusMethodNotAllowed, "publishing isn't supported") -} - -func (h *SwiftHandler) handleSourceArchive(w http.ResponseWriter, r *http.Request, scope, name, version string) { - if !validSwiftPackageReference(scope, name, version) { - writeSwiftProblem(w, http.StatusBadRequest, "invalid package release") - return - } - scope, name = canonicalSwiftPackage(scope, name) - - packageName := scope + "/" + name - filename := fmt.Sprintf("%s-%s.zip", name, version) - upstreamURL := h.buildUpstreamURL(scope, name, version+".zip", "", r.URL.RawQuery) - packagePURL, versionPURL := packageurl.MakeCacheStrings("swift", packageName, version) - if packagePURL == "" || versionPURL == "" { - h.writeArtifactError(w, fmt.Errorf("%w: swift %q", errUnsupportedPackageIdentity, packageName)) - return - } - archiveInfo, infoErr := h.fetchArchiveInfo(r.Context(), scope, name, version) - if infoErr != nil { - h.writeArtifactError(w, fmt.Errorf("fetching release metadata: %w", infoErr)) - return - } - - if r.Method == http.MethodHead { - h.handleSourceArchiveHead(w, r, name, version, filename, packagePURL, versionPURL, upstreamURL, archiveInfo) - return - } - - headers := make(http.Header) - headers.Set("Accept", requestAccept(r, swiftAcceptArchive)) - result, err := h.proxy.getOrFetchArtifactFromURLWithCachePURLs( - r.Context(), "swift", packageName, version, filename, packagePURL, versionPURL, - upstreamURL, headers, archiveInfo.checksum, - ) - if err != nil { - h.writeArtifactError(w, err) - return - } - - result.Artifact.MediaType = "application/zip" - setSwiftArchiveHeaders(w.Header(), name, version, result.Artifact.Digest.Encoded(), archiveInfo) - serveArtifact(w, r.Method, result) -} - -func (h *SwiftHandler) handleSourceArchiveHead( - w http.ResponseWriter, - r *http.Request, - name, version, filename, packagePURL, versionPURL, upstreamURL string, - archiveInfo swiftArchiveInfo, -) { - result, err := h.proxy.getCachedArtifactWithUpstreamHash( - r.Context(), packagePURL, versionPURL, filename, archiveInfo.checksum, - ) - if err != nil { - h.writeArtifactError(w, err) - return - } - if result != nil { - result.Artifact.MediaType = "application/zip" - setSwiftArchiveHeaders(w.Header(), name, version, result.Artifact.Digest.Encoded(), archiveInfo) - serveArtifact(w, r.Method, result) - return - } - - size, err := h.probeSourceArchive(r.Context(), upstreamURL, requestAccept(r, swiftAcceptArchive)) - if err != nil { - h.writeArtifactError(w, err) - return - } - setSwiftArchiveHeaders(w.Header(), name, version, "", archiveInfo) - w.Header().Set(headerContentType, "application/zip") - if size >= 0 { - w.Header().Set(headerContentLength, strconv.FormatInt(size, 10)) - } - w.WriteHeader(http.StatusOK) -} - -func (h *SwiftHandler) probeSourceArchive(ctx context.Context, upstreamURL, accept string) (int64, error) { - req, err := http.NewRequestWithContext(ctx, http.MethodGet, upstreamURL, nil) - if err != nil { - return 0, fmt.Errorf("creating upstream archive request: %w", err) - } - req.Header.Set("Accept", accept) - req.Header.Set("Range", "bytes=0-0") - h.proxy.applyUpstreamAuth(req) - - resp, err := h.proxy.HTTPClient.Do(req) - if err != nil { - return 0, fmt.Errorf("requesting upstream archive: %w", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode == http.StatusNotFound { - return 0, ErrUpstreamNotFound - } - if resp.StatusCode != http.StatusOK && resp.StatusCode != http.StatusPartialContent { - return 0, fmt.Errorf("upstream archive returned %d", resp.StatusCode) - } - - if resp.StatusCode == http.StatusPartialContent { - _, total, found := strings.Cut(resp.Header.Get("Content-Range"), "/") - if !found || total == "*" { - return -1, nil - } - if parsed, parseErr := strconv.ParseInt(total, 10, 64); parseErr == nil { - return parsed, nil - } - return -1, nil - } - - size := int64(-1) - if contentLength := resp.Header.Get(headerContentLength); contentLength != "" { - if parsed, parseErr := strconv.ParseInt(contentLength, 10, 64); parseErr == nil { - size = parsed - } - } - return size, nil -} - -func (h *SwiftHandler) fetchMetadataWithHeaders( - ctx context.Context, - upstreamURL, accept string, -) ([]byte, string, http.Header, error) { - req, err := http.NewRequestWithContext(ctx, http.MethodGet, upstreamURL, nil) - if err != nil { - return nil, "", nil, fmt.Errorf("creating upstream metadata request: %w", err) - } - req.Header.Set("Accept", accept) - h.proxy.applyUpstreamAuth(req) - - resp, err := h.proxy.HTTPClient.Do(req) - if err != nil { - return nil, "", nil, fmt.Errorf("requesting upstream metadata: %w", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode == http.StatusNotFound { - return nil, "", nil, ErrUpstreamNotFound - } - if resp.StatusCode != http.StatusOK { - return nil, "", nil, fmt.Errorf("upstream metadata returned %d", resp.StatusCode) - } - - body, err := h.proxy.ReadMetadata(resp.Body) - if err != nil { - return nil, "", nil, fmt.Errorf("reading upstream metadata: %w", err) - } - contentType := resp.Header.Get(headerContentType) - if contentType == "" { - contentType = contentTypeJSON - } - return body, contentType, resp.Header.Clone(), nil -} - -type swiftReleaseMetadata struct { - Resources []struct { - Name string `json:"name"` - Type string `json:"type"` - Checksum string `json:"checksum"` - Signing *struct { - Signature string `json:"signatureBase64Encoded"` - Format string `json:"signatureFormat"` - } `json:"signing"` - } `json:"resources"` -} - -type swiftArchiveInfo struct { - checksum string - signature string - signatureFormat string -} - -func (h *SwiftHandler) fetchArchiveInfo(ctx context.Context, scope, name, version string) (swiftArchiveInfo, error) { - upstreamURL := h.buildUpstreamURL(scope, name, version, "", "") - body, _, err := h.proxy.FetchOrCacheMetadata( - ctx, "swift", swiftReleaseCacheKey(scope, name, version), upstreamURL, swiftAcceptJSON, - ) - if err != nil { - return swiftArchiveInfo{}, err - } - - var metadata swiftReleaseMetadata - if err := json.Unmarshal(body, &metadata); err != nil { - return swiftArchiveInfo{}, fmt.Errorf("parsing release metadata: %w", err) - } - for _, resource := range metadata.Resources { - if resource.Name != "source-archive" || resource.Type != "application/zip" { - continue - } - checksum, err := normalizeSwiftChecksum(resource.Checksum) - if err != nil { - return swiftArchiveInfo{}, err - } - info := swiftArchiveInfo{checksum: checksum} - if resource.Signing != nil { - if resource.Signing.Signature == "" || resource.Signing.Format == "" { - return swiftArchiveInfo{}, errors.New("source archive signing metadata is incomplete") - } - info.signature = resource.Signing.Signature - info.signatureFormat = resource.Signing.Format - } - return info, nil - } - - return swiftArchiveInfo{}, errors.New("source archive is missing from release metadata") -} - -func normalizeSwiftChecksum(checksum string) (string, error) { - digest, err := hex.DecodeString(checksum) - if err != nil || len(digest) != sha256.Size { - return "", errors.New("source archive checksum is not a SHA-256 digest") - } - return hex.EncodeToString(digest), nil -} - -func setSwiftArchiveHeaders(header http.Header, name, version, contentHash string, info swiftArchiveInfo) { - header.Set("Cache-Control", "public, immutable") - header.Set("Content-Disposition", fmt.Sprintf(`attachment; filename="%s-%s.zip"`, name, version)) - header.Set("Content-Version", swiftContentVersion) - - checksum := info.checksum - if checksum == "" { - checksum = contentHash - } - if digest := swiftDigestHeader(checksum); digest != "" { - header.Set("Digest", digest) - } - if info.signature != "" && info.signatureFormat != "" { - header.Set("X-Swift-Package-Signature", info.signature) - header.Set("X-Swift-Package-Signature-Format", info.signatureFormat) - } -} - -func swiftDigestHeader(checksum string) string { - digest, err := hex.DecodeString(checksum) - if err != nil || len(digest) != sha256.Size { - return "" - } - return "sha-256=" + base64.StdEncoding.EncodeToString(digest) -} - -func (h *SwiftHandler) proxySwiftResource(w http.ResponseWriter, r *http.Request, upstreamURL, defaultAccept string) { - req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil) - if err != nil { - writeSwiftProblem(w, http.StatusInternalServerError, "failed to create upstream request") - return - } - req.Header.Set("Accept", requestAccept(r, defaultAccept)) - for _, name := range []string{"If-Modified-Since", "If-None-Match"} { - if value := r.Header.Get(name); value != "" { - req.Header.Set(name, value) - } - } - h.proxy.applyUpstreamAuth(req) - - resp, err := h.proxy.HTTPClient.Do(req) - if err != nil { - writeSwiftProblem(w, http.StatusBadGateway, "upstream request failed") - return - } - defer func() { _ = resp.Body.Close() }() - - copySwiftResponseHeaders(w.Header(), resp.Header) - if location := resp.Header.Get("Location"); location != "" { - w.Header().Set("Location", h.rewriteRegistryURL(location, upstreamURL)) - } - for _, link := range resp.Header.Values("Link") { - w.Header().Add("Link", h.rewriteLinkHeader(link, upstreamURL)) - } - if w.Header().Get("Content-Version") == "" { - w.Header().Set("Content-Version", swiftContentVersion) - } - - w.WriteHeader(resp.StatusCode) - if r.Method != http.MethodHead { - _, _ = io.Copy(w, resp.Body) - } -} - -func copySwiftResponseHeaders(dst, src http.Header) { - for _, name := range []string{ - "Cache-Control", "Content-Disposition", "Content-Language", headerContentLength, - headerContentType, "Content-Version", "Digest", headerETag, headerLastModified, - "Retry-After", "Vary", "Warning", "X-Swift-Package-Signature", - "X-Swift-Package-Signature-Format", - } { - for _, value := range src.Values(name) { - dst.Add(name, value) - } - } -} - -func (h *SwiftHandler) rewriteLinkHeader(value, upstreamRequestURL string) string { - var result strings.Builder - for len(value) > 0 { - start := strings.IndexByte(value, '<') - if start < 0 { - result.WriteString(value) - break - } - endOffset := strings.IndexByte(value[start+1:], '>') - if endOffset < 0 { - result.WriteString(value) - break - } - end := start + 1 + endOffset - result.WriteString(value[:start+1]) - result.WriteString(h.rewriteRegistryURL(value[start+1:end], upstreamRequestURL)) - result.WriteByte('>') - value = value[end+1:] - } - return result.String() -} - -func (h *SwiftHandler) rewriteRegistryURL(rawURL, upstreamRequestURL string) string { - base, err := url.Parse(h.upstreamURL) - if err != nil { - return rawURL - } - requestURL, err := url.Parse(upstreamRequestURL) - if err != nil { - return rawURL - } - reference, err := url.Parse(rawURL) - if err != nil { - return rawURL - } - absolute := requestURL.ResolveReference(reference) - if !strings.EqualFold(absolute.Scheme, base.Scheme) || !strings.EqualFold(absolute.Host, base.Host) { - return rawURL - } - - basePath := strings.TrimSuffix(base.EscapedPath(), "/") - absolutePath := absolute.EscapedPath() - if absolutePath != basePath && !strings.HasPrefix(absolutePath, basePath+"/") { - return rawURL - } - suffix := strings.TrimPrefix(absolutePath, basePath) - rewritten := h.proxyURL + "/swift" + suffix - if absolute.RawQuery != "" { - rewritten += "?" + absolute.RawQuery - } - if absolute.Fragment != "" { - rewritten += "#" + absolute.Fragment - } - return rewritten -} - -func (h *SwiftHandler) rewriteReleaseURLs(scope, name string, body []byte) ([]byte, error) { - var metadata map[string]any - if err := json.Unmarshal(body, &metadata); err != nil { - return nil, err - } - releases, ok := metadata["releases"].(map[string]any) - if !ok { - return body, nil - } - - for version, value := range releases { - release, ok := value.(map[string]any) - if !ok { - continue - } - if _, hasURL := release["url"]; !hasURL { - continue - } - release["url"] = fmt.Sprintf( - "%s/swift/%s/%s/%s", - h.proxyURL, - url.PathEscape(scope), - url.PathEscape(name), - url.PathEscape(version), - ) - } - return json.Marshal(metadata) -} - -func (h *SwiftHandler) buildUpstreamURL(scope, name, version, resource, rawQuery string) string { - parts := []string{h.upstreamURL, url.PathEscape(scope), url.PathEscape(name)} - if version != "" { - parts = append(parts, url.PathEscape(version)) - } - if resource != "" { - parts = append(parts, resource) - } - result := strings.Join(parts, "/") - if rawQuery != "" { - result += "?" + rawQuery - } - return result -} - -func swiftMetadataCacheKey(parts ...string) string { - joined := strings.Join(parts, "\x00") - digest := sha256.Sum256([]byte(joined)) - return hex.EncodeToString(digest[:]) -} - -func swiftReleaseCacheKey(scope, name, version string) string { - return swiftMetadataCacheKey("release", scope, name, version) -} - -func requestAccept(r *http.Request, fallback string) string { - if accept := r.Header.Get("Accept"); accept != "" { - return accept - } - return fallback -} - -func writeSwiftMetadata(w http.ResponseWriter, r *http.Request, body []byte, contentType string) { - if contentType == "" { - contentType = "application/json" - } - digest := sha256.Sum256(body) - etag := fmt.Sprintf(`"%x"`, digest) - w.Header().Set(headerContentType, contentType) - w.Header().Set("Content-Version", swiftContentVersion) - w.Header().Set(headerETag, etag) - if ifNoneMatchHits(r.Header.Get("If-None-Match"), etag) { - w.WriteHeader(http.StatusNotModified) - return - } - w.Header().Set(headerContentLength, strconv.Itoa(len(body))) - w.WriteHeader(http.StatusOK) - if r.Method != http.MethodHead { - _, _ = w.Write(body) - } -} - -func (h *SwiftHandler) writeMetadataError(w http.ResponseWriter, err error) { - if errors.Is(err, ErrUpstreamNotFound) { - writeSwiftProblem(w, http.StatusNotFound, "not found") - return - } - h.proxy.Logger.Error("Swift metadata request failed", "error", err) - writeSwiftProblem(w, http.StatusBadGateway, "upstream request failed") -} - -func (h *SwiftHandler) writeArtifactError(w http.ResponseWriter, err error) { - if errors.Is(err, ErrUpstreamNotFound) { - writeSwiftProblem(w, http.StatusNotFound, "release not found") - return - } - h.proxy.Logger.Error("Swift archive request failed", "error", err) - writeSwiftProblem(w, http.StatusBadGateway, "failed to fetch package") -} - -func writeSwiftProblem(w http.ResponseWriter, status int, detail string) { - w.Header().Set(headerContentType, "application/problem+json") - w.Header().Set("Content-Version", swiftContentVersion) - w.WriteHeader(status) - _ = json.NewEncoder(w).Encode(map[string]string{"detail": detail}) -} - -func validSwiftPackageReference(scope, name, version string) bool { - return validSwiftScope(scope) && validSwiftPackageName(name) && version != "" && version != "." && version != ".." && !strings.ContainsAny(version, "/\\") -} - -func canonicalSwiftPackage(scope, name string) (string, string) { - return strings.ToLower(scope), strings.ToLower(name) -} - -func validSwiftScope(scope string) bool { - return validSwiftIdentifier(scope, swiftMaxScopeLength, "-") -} - -func validSwiftPackageName(name string) bool { - return validSwiftIdentifier(name, swiftMaxNameLength, "-_") -} - -func validSwiftIdentifier(value string, maxLength int, separators string) bool { - if value == "" || len(value) > maxLength { - return false - } - previousSeparator := false - for i := 0; i < len(value); i++ { - character := value[i] - separator := strings.ContainsRune(separators, rune(character)) - if separator { - if i == 0 || i == len(value)-1 || previousSeparator { - return false - } - previousSeparator = true - continue - } - if (character < 'a' || character > 'z') && - (character < 'A' || character > 'Z') && - (character < '0' || character > '9') { - return false - } - previousSeparator = false - } - return true -} diff --git a/internal/handler/swift_test.go b/internal/handler/swift_test.go deleted file mode 100644 index c9df35a..0000000 --- a/internal/handler/swift_test.go +++ /dev/null @@ -1,550 +0,0 @@ -package handler - -import ( - "context" - "crypto/sha256" - "encoding/base64" - "encoding/hex" - "encoding/json" - "fmt" - "io" - "net/http" - "net/http/httptest" - "strings" - "testing" - - "github.com/git-pkgs/proxy/internal/packageurl" - "github.com/git-pkgs/registries/fetch" -) - -func TestSwiftPackageReleasesRewritesRegistryURLs(t *testing.T) { - var gotAccept string - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path != "/registry/apple/swift-argument-parser" { - t.Errorf("upstream path = %q", r.URL.Path) - } - gotAccept = r.Header.Get("Accept") - w.Header().Set("Content-Type", "application/json; charset=utf-8") - w.Header().Set("Content-Version", "1") - w.Header().Add("Link", `; rel="next"`) - _, _ = io.WriteString(w, `{"releases":{"1.2.0":{"url":"/registry/apple/swift-argument-parser/1.2.0"},"1.1.0":{}}}`) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - handler := NewSwiftHandler(proxy, "https://proxy.example", upstream.URL+"/registry").Routes() - req := httptest.NewRequest(http.MethodGet, "/APPLE/SWIFT-ARGUMENT-PARSER", nil) - req.Header.Set("Accept", swiftAcceptJSON) - w := httptest.NewRecorder() - handler.ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200; body: %s", w.Code, w.Body.String()) - } - if gotAccept != swiftAcceptJSON { - t.Errorf("upstream Accept = %q, want %q", gotAccept, swiftAcceptJSON) - } - if got := w.Header().Get("Content-Version"); got != "1" { - t.Errorf("Content-Version = %q, want 1", got) - } - if got := w.Header().Get("Link"); got != `; rel="next"` { - t.Errorf("Link = %q", got) - } - - var body struct { - Releases map[string]struct { - URL string `json:"url"` - } `json:"releases"` - } - if err := json.NewDecoder(w.Body).Decode(&body); err != nil { - t.Fatalf("decoding response: %v", err) - } - if got := body.Releases["1.2.0"].URL; got != "https://proxy.example/swift/apple/swift-argument-parser/1.2.0" { - t.Errorf("release URL = %q", got) - } - if got := body.Releases["1.1.0"].URL; got != "" { - t.Errorf("release without upstream URL gained URL %q", got) - } -} - -func TestSwiftReleaseMetadataSupportsJSONExtensionAndHead(t *testing.T) { - var requestMethods []string - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - requestMethods = append(requestMethods, r.Method) - if r.URL.Path != "/registry/apple/example/1.2.3" { - t.Errorf("upstream path = %q", r.URL.Path) - } - w.Header().Set("Content-Type", "application/json") - _, _ = io.WriteString(w, `{"id":"apple.example","version":"1.2.3","resources":[]}`) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - handler := NewSwiftHandler(proxy, "https://proxy.example", upstream.URL+"/registry").Routes() - - for _, method := range []string{http.MethodGet, http.MethodHead} { - req := httptest.NewRequest(method, "/APPLE/EXAMPLE/1.2.3.json", nil) - w := httptest.NewRecorder() - handler.ServeHTTP(w, req) - if w.Code != http.StatusOK { - t.Fatalf("%s status = %d, want 200", method, w.Code) - } - if method == http.MethodHead && w.Body.Len() != 0 { - t.Errorf("HEAD response body length = %d, want 0", w.Body.Len()) - } - } - if len(requestMethods) != 2 || requestMethods[0] != http.MethodGet || requestMethods[1] != http.MethodGet { - t.Errorf("upstream methods = %v, want metadata GETs", requestMethods) - } -} - -func TestSwiftManifestProxiesQueryAndRewritesLinks(t *testing.T) { - var upstream *httptest.Server - var gotAccept string - upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.Method != http.MethodGet { - t.Errorf("upstream method = %s, want GET", r.Method) - } - if r.URL.Path != "/registry/apple/example/1.2.3/Package.swift" { - t.Errorf("upstream path = %q", r.URL.Path) - } - if got := r.URL.Query().Get("swift-version"); got != "5.9" { - t.Errorf("swift-version = %q, want 5.9", got) - } - gotAccept = r.Header.Get("Accept") - w.Header().Set("Content-Type", "text/x-swift") - w.Header().Add("Link", fmt.Sprintf(`<%s/registry/apple/example/1.2.3/Package.swift?swift-version=5.8>; rel="alternate"; filename="Package@swift-5.8.swift"`, upstream.URL)) - w.Header().Add("Link", `; rel="canonical"`) - _, _ = io.WriteString(w, "// swift-tools-version: 5.9\n") - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - handler := NewSwiftHandler(proxy, "https://proxy.example", upstream.URL+"/registry").Routes() - req := httptest.NewRequest(http.MethodGet, "/APPLE/EXAMPLE/1.2.3/Package.swift?swift-version=5.9", nil) - req.Header.Set("Accept", swiftAcceptManifest) - w := httptest.NewRecorder() - handler.ServeHTTP(w, req) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200", w.Code) - } - if gotAccept != swiftAcceptManifest { - t.Errorf("upstream Accept = %q, want %q", gotAccept, swiftAcceptManifest) - } - links := strings.Join(w.Header().Values("Link"), ",") - if !strings.Contains(links, "https://proxy.example/swift/apple/example/1.2.3/Package.swift?swift-version=5.8") { - t.Errorf("internal manifest Link was not rewritten: %q", links) - } - if !strings.Contains(links, "https://github.com/apple/example") { - t.Errorf("external canonical Link was changed: %q", links) - } - if got := w.Header().Get("Content-Version"); got != "1" { - t.Errorf("Content-Version = %q, want 1", got) - } -} - -func TestSwiftSourceArchiveCachesAndPreservesSecurityMetadata(t *testing.T) { - archive := []byte("swift source archive") - checksumBytes := sha256.Sum256(archive) - checksum := hex.EncodeToString(checksumBytes[:]) - signature := base64.StdEncoding.EncodeToString([]byte("signature")) - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path != "/registry/apple/example/1.2.3" { - t.Errorf("metadata path = %q", r.URL.Path) - } - w.Header().Set("Content-Type", "application/json") - _, _ = fmt.Fprintf(w, `{"id":"apple.example","version":"1.2.3","resources":[{"name":"source-archive","type":"application/zip","checksum":%q,"signing":{"signatureBase64Encoded":%q,"signatureFormat":"cms-1.0.0"}}]}`, checksum, signature) - })) - defer upstream.Close() - - proxy, db, _, fetcher := setupTestProxy(t) - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader(string(archive))), - Size: int64(len(archive)), - ContentType: "application/zip", - } - handler := NewSwiftHandler(proxy, "https://proxy.example", upstream.URL+"/registry").Routes() - - requestArchive := func(method string) *httptest.ResponseRecorder { - req := httptest.NewRequest(method, "/apple/example/1.2.3.zip", nil) - req.Header.Set("Accept", swiftAcceptArchive) - w := httptest.NewRecorder() - handler.ServeHTTP(w, req) - return w - } - - w := requestArchive(http.MethodGet) - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200; body: %s", w.Code, w.Body.String()) - } - if got := w.Body.Bytes(); string(got) != string(archive) { - t.Errorf("archive body = %q", got) - } - if !fetcher.fetchCalled { - t.Fatal("archive fetcher was not called") - } - if got := fetcher.fetchedURL; got != upstream.URL+"/registry/apple/example/1.2.3.zip" { - t.Errorf("fetched URL = %q", got) - } - if got := fetcher.fetchedHeader.Get("Accept"); got != swiftAcceptArchive { - t.Errorf("archive Accept = %q, want %q", got, swiftAcceptArchive) - } - if got := w.Header().Get("Digest"); got != "sha-256="+base64.StdEncoding.EncodeToString(checksumBytes[:]) { - t.Errorf("Digest = %q", got) - } - if got := w.Header().Get("X-Swift-Package-Signature"); got != signature { - t.Errorf("signature = %q", got) - } - if got := w.Header().Get("X-Swift-Package-Signature-Format"); got != "cms-1.0.0" { - t.Errorf("signature format = %q", got) - } - if got := w.Header().Get("Content-Disposition"); got != `attachment; filename="example-1.2.3.zip"` { - t.Errorf("Content-Disposition = %q", got) - } - - packagePURL, versionPURL := packageurl.MakeCacheStrings("swift", "apple/example", "1.2.3") - if strings.HasPrefix(packagePURL, "pkg:swift/") { - t.Fatalf("registry identity produced source PURL %q", packagePURL) - } - versionRecord, err := db.GetVersionByPURL(versionPURL) - if err != nil { - t.Fatalf("cached Swift version %q not found: %v", versionPURL, err) - } - if versionRecord == nil { - t.Fatalf("cached Swift version %q not found", versionPURL) - } - if versionRecord.PackagePURL != packagePURL { - t.Errorf("cached package PURL = %q, want %q", versionRecord.PackagePURL, packagePURL) - } - - fetcher.fetchCalled = false - w = requestArchive(http.MethodHead) - if w.Code != http.StatusOK { - t.Fatalf("HEAD status = %d, want 200", w.Code) - } - if w.Body.Len() != 0 { - t.Errorf("HEAD body length = %d, want 0", w.Body.Len()) - } - if got := w.Header().Get("Content-Length"); got != fmt.Sprint(len(archive)) { - t.Errorf("HEAD Content-Length = %q", got) - } - - w = requestArchive(http.MethodGet) - if w.Code != http.StatusOK || w.Body.String() != string(archive) { - t.Fatalf("cached response = %d %q", w.Code, w.Body.Bytes()) - } - if fetcher.fetchCalled { - t.Error("cached archive contacted artifact upstream") - } -} - -func TestSwiftSourceArchiveRejectsChecksumMismatch(t *testing.T) { - archive := []byte("unexpected archive") - expectedChecksum := sha256.Sum256([]byte("expected archive")) - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.Header().Set("Content-Type", "application/json") - _, _ = fmt.Fprintf(w, `{"id":"apple.example","version":"1.2.3","resources":[{"name":"source-archive","type":"application/zip","checksum":%q}]}`, hex.EncodeToString(expectedChecksum[:])) - })) - defer upstream.Close() - - proxy, db, store, fetcher := setupTestProxy(t) - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader(string(archive))), - Size: int64(len(archive)), - ContentType: "application/zip", - } - handler := NewSwiftHandler(proxy, "https://proxy.example", upstream.URL).Routes() - - w := httptest.NewRecorder() - handler.ServeHTTP(w, httptest.NewRequest(http.MethodGet, "/apple/example/1.2.3.zip", nil)) - - if w.Code != http.StatusBadGateway { - t.Fatalf("status = %d, want 502; body: %s", w.Code, w.Body.String()) - } - if len(store.files) != 0 { - t.Errorf("mismatched archive remained in storage: %v", store.files) - } - packagePURL, versionPURL := packageurl.MakeCacheStrings("swift", "apple/example", "1.2.3") - cached, err := db.GetCachedArtifact(packagePURL, versionPURL, "example-1.2.3.zip") - if err != nil { - t.Fatalf("checking cache: %v", err) - } - if cached != nil { - t.Error("mismatched archive gained a cache record") - } -} - -func TestSwiftSourceArchiveCanonicalizesPackageIdentity(t *testing.T) { - archive := []byte("swift source archive") - checksumBytes := sha256.Sum256(archive) - checksum := hex.EncodeToString(checksumBytes[:]) - var metadataPaths []string - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - metadataPaths = append(metadataPaths, r.URL.Path) - w.Header().Set("Content-Type", "application/json") - _, _ = fmt.Fprintf(w, `{"id":"apple.example","version":"1.2.3","resources":[{"name":"source-archive","type":"application/zip","checksum":%q}]}`, checksum) - })) - defer upstream.Close() - - proxy, db, store, fetcher := setupTestProxy(t) - handler := NewSwiftHandler(proxy, "https://proxy.example", upstream.URL).Routes() - requestArchive := func(path string) { - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader(string(archive))), - Size: int64(len(archive)), - ContentType: "application/zip", - } - w := httptest.NewRecorder() - handler.ServeHTTP(w, httptest.NewRequest(http.MethodGet, path, nil)) - if w.Code != http.StatusOK { - t.Fatalf("GET %s status = %d, want 200; body: %s", path, w.Code, w.Body.String()) - } - } - - requestArchive("/apple/example/1.2.3.zip") - requestArchive("/APPLE/EXAMPLE/1.2.3.zip") - - if len(store.files) != 1 { - t.Errorf("cached files = %d, want 1", len(store.files)) - } - for _, path := range metadataPaths { - if path != "/apple/example/1.2.3" { - t.Errorf("metadata path = %q, want canonical lowercase path", path) - } - } - - canonicalPURL, _ := packageurl.MakeCacheStrings("swift", "apple/example", "1.2.3") - canonical, err := db.GetPackageByPURL(canonicalPURL) - if err != nil { - t.Fatalf("getting canonical package: %v", err) - } - if canonical == nil { - t.Fatalf("canonical package %q not found", canonicalPURL) - } - - nonCanonicalPURL, _ := packageurl.MakeCacheStrings("swift", "APPLE/EXAMPLE", "1.2.3") - if nonCanonicalPURL != canonicalPURL { - t.Errorf("uppercase cache PURL = %q, want %q", nonCanonicalPURL, canonicalPURL) - } -} - -func TestSwiftSourceArchiveHeadLeavesStaleCacheForTheFetch(t *testing.T) { - archive := []byte("cached archive") - upstreamChecksum := sha256.Sum256([]byte("upstream archive")) - - var probed bool - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if strings.HasSuffix(r.URL.Path, ".zip") { - probed = true - w.Header().Set("Content-Range", "bytes 0-0/456") - w.WriteHeader(http.StatusPartialContent) - _, _ = w.Write([]byte("x")) - return - } - w.Header().Set("Content-Type", "application/json") - _, _ = fmt.Fprintf(w, `{"id":"apple.example","version":"1.2.3","resources":[{"name":"source-archive","type":"application/zip","checksum":%q}]}`, hex.EncodeToString(upstreamChecksum[:])) - })) - defer upstream.Close() - - proxy, db, store, fetcher := setupTestProxy(t) - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader(string(archive))), - Size: int64(len(archive)), - ContentType: "application/zip", - } - packagePURL, versionPURL := packageurl.MakeCacheStrings("swift", "apple/example", "1.2.3") - cached, err := proxy.getOrFetchArtifactFromURLWithCachePURLs( - context.Background(), "swift", "apple/example", "1.2.3", "example-1.2.3.zip", - packagePURL, versionPURL, upstream.URL+"/apple/example/1.2.3.zip", nil, "", - ) - if err != nil { - t.Fatalf("seeding cache: %v", err) - } - _ = cached.Reader.Close() - - handler := NewSwiftHandler(proxy, "https://proxy.example", upstream.URL).Routes() - w := httptest.NewRecorder() - handler.ServeHTTP(w, httptest.NewRequest(http.MethodHead, "/apple/example/1.2.3.zip", nil)) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200; body: %s", w.Code, w.Body.String()) - } - if !probed { - t.Error("stale cache entry was not replaced by an upstream probe") - } - if got := w.Header().Get("Content-Length"); got != "456" { - t.Errorf("Content-Length = %q, want 456 from upstream probe", got) - } - // HEAD leaves the stale entry alone; the next GET replaces it under the - // coalescing key. - if len(store.files) != 1 { - t.Errorf("HEAD must leave the stale archive in storage, got %v", store.files) - } - if rec, _ := db.GetCachedArtifact(packagePURL, versionPURL, "example-1.2.3.zip"); rec == nil { - t.Error("HEAD must leave the stale cache record in place") - } - - fetcher.artifact = artifactBody("upstream archive") - w = httptest.NewRecorder() - handler.ServeHTTP(w, httptest.NewRequest(http.MethodGet, "/apple/example/1.2.3.zip", nil)) - if w.Code != http.StatusOK { - t.Fatalf("GET status = %d, want 200; body: %s", w.Code, w.Body.String()) - } - if w.Body.String() != "upstream archive" { - t.Errorf("GET body = %q, want the refreshed archive", w.Body.String()) - } - rec, _ := db.GetCachedArtifact(packagePURL, versionPURL, "example-1.2.3.zip") - if rec == nil || rec.Artifact.Digest.Encoded() != hex.EncodeToString(upstreamChecksum[:]) { - t.Errorf("cache record after GET = %+v, want the upstream checksum", rec) - } -} - -func TestSwiftSourceArchiveRequiresReleaseMetadata(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - http.Error(w, "unavailable", http.StatusServiceUnavailable) - })) - defer upstream.Close() - - proxy, _, store, fetcher := setupTestProxy(t) - fetcher.artifact = &fetch.Artifact{ - Body: io.NopCloser(strings.NewReader("signed archive")), - ContentType: "application/zip", - } - handler := NewSwiftHandler(proxy, "https://proxy.example", upstream.URL).Routes() - - w := httptest.NewRecorder() - handler.ServeHTTP(w, httptest.NewRequest(http.MethodGet, "/apple/example/1.2.3.zip", nil)) - - if w.Code != http.StatusBadGateway { - t.Fatalf("status = %d, want 502; body: %s", w.Code, w.Body.String()) - } - if fetcher.fetchCalled { - t.Error("archive was fetched without release security metadata") - } - if len(store.files) != 0 { - t.Errorf("archive was cached without release security metadata: %v", store.files) - } -} - -func TestSwiftSourceArchiveColdHeadUsesRangeGetAcrossRedirect(t *testing.T) { - checksum := strings.Repeat("a", sha256.Size*2) - var archiveAccept string - var archiveMethod string - var archiveRange string - download := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - archiveMethod = r.Method - archiveRange = r.Header.Get("Range") - w.Header().Set("Content-Range", "bytes 0-0/123") - w.WriteHeader(http.StatusPartialContent) - _, _ = w.Write([]byte("x")) - })) - defer download.Close() - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.URL.Path { - case "/apple/example/1.2.3": - w.Header().Set("Content-Type", "application/json") - _, _ = fmt.Fprintf(w, `{"id":"apple.example","version":"1.2.3","resources":[{"name":"source-archive","type":"application/zip","checksum":%q}]}`, checksum) - case "/apple/example/1.2.3.zip": - archiveAccept = r.Header.Get("Accept") - http.Redirect(w, r, download.URL, http.StatusSeeOther) - default: - http.NotFound(w, r) - } - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - proxy.HTTPClient = upstream.Client() - handler := NewSwiftHandler(proxy, "https://proxy.example", upstream.URL).Routes() - - w := httptest.NewRecorder() - handler.ServeHTTP(w, httptest.NewRequest(http.MethodHead, "/apple/example/1.2.3.zip", nil)) - - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200; body: %s", w.Code, w.Body.String()) - } - if archiveMethod != http.MethodGet { - t.Errorf("download method = %q, want GET", archiveMethod) - } - if archiveRange != "bytes=0-0" { - t.Errorf("download Range = %q, want bytes=0-0", archiveRange) - } - if archiveAccept != swiftAcceptArchive { - t.Errorf("upstream Accept = %q, want %q", archiveAccept, swiftAcceptArchive) - } - if got := w.Header().Get("Content-Length"); got != "123" { - t.Errorf("Content-Length = %q, want 123", got) - } -} - -func TestSwiftIdentifiersAndPublishingUnsupported(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path != "/registry/identifiers" { - t.Errorf("upstream path = %q", r.URL.Path) - } - if got := r.URL.Query().Get("url"); got != "https://github.com/apple/example" { - t.Errorf("lookup URL = %q", got) - } - w.Header().Set("Content-Type", "application/json") - _, _ = io.WriteString(w, `{"identifiers":["apple.example"]}`) - })) - defer upstream.Close() - - proxy, _, _, _ := setupTestProxy(t) - handler := NewSwiftHandler(proxy, "https://proxy.example", upstream.URL+"/registry").Routes() - - req := httptest.NewRequest(http.MethodGet, "/identifiers?url=https%3A%2F%2Fgithub.com%2Fapple%2Fexample", nil) - w := httptest.NewRecorder() - handler.ServeHTTP(w, req) - if w.Code != http.StatusOK || !strings.Contains(w.Body.String(), "apple.example") { - t.Fatalf("identifier response = %d %q", w.Code, w.Body.String()) - } - - req = httptest.NewRequest(http.MethodGet, "/identifiers", nil) - w = httptest.NewRecorder() - handler.ServeHTTP(w, req) - if w.Code != http.StatusBadRequest { - t.Errorf("missing URL status = %d, want 400", w.Code) - } - - req = httptest.NewRequest(http.MethodPut, "/apple/example/1.2.3", strings.NewReader("ignored")) - w = httptest.NewRecorder() - handler.ServeHTTP(w, req) - if w.Code != http.StatusMethodNotAllowed { - t.Errorf("publish status = %d, want 405", w.Code) - } - if got := w.Header().Get("Allow"); got != "GET, HEAD" { - t.Errorf("Allow = %q", got) - } -} - -func TestSwiftIdentifierValidation(t *testing.T) { - tests := []struct { - name string - value string - valid func(string) bool - want bool - }{ - {"scope", "apple", validSwiftScope, true}, - {"scope hyphen", "swift-server", validSwiftScope, true}, - {"scope underscore", "swift_server", validSwiftScope, false}, - {"scope repeated separator", "swift--server", validSwiftScope, false}, - {"package", "swift-argument_parser", validSwiftPackageName, true}, - {"package repeated separators", "swift-_argument", validSwiftPackageName, false}, - {"package trailing separator", "example-", validSwiftPackageName, false}, - {"package non-ASCII", "café", validSwiftPackageName, false}, - } - - for _, test := range tests { - t.Run(test.name, func(t *testing.T) { - if got := test.valid(test.value); got != test.want { - t.Errorf("validation of %q = %v, want %v", test.value, got, test.want) - } - }) - } -} diff --git a/internal/handler/upstream_test.go b/internal/handler/upstream_test.go deleted file mode 100644 index 7839eaa..0000000 --- a/internal/handler/upstream_test.go +++ /dev/null @@ -1,130 +0,0 @@ -package handler - -import ( - "io" - "net/http" - "net/http/httptest" - "testing" -) - -func TestHandlerUpstreamConfiguration(t *testing.T) { - const ( - proxyURL = "https://proxy.example.com/" - baseURL = "https://upstream.example.com" - ) - hex := NewHexHandlerWithUpstreams(nil, proxyURL, baseURL+"/hex/", baseURL+"/hex-api/") - pypi := NewPyPIHandlerWithUpstreams(nil, proxyURL, baseURL+"/pypi/", baseURL+"/pypi-download/") - nuget := NewNuGetHandlerWithUpstreams(nil, proxyURL, baseURL+"/nuget/", baseURL+"/nuget-search/") - composer := NewComposerHandlerWithUpstreams( - nil, proxyURL, baseURL+"/composer/", baseURL+"/composer-repository/", - ) - - got := map[string]string{ - "gem": NewGemHandlerWithUpstream(nil, proxyURL, baseURL+"/gem/").upstreamURL, - "go": NewGoHandlerWithUpstream(nil, proxyURL, baseURL+"/go/").upstreamURL, - "hex": hex.upstreamURL, - "hex_api": hex.apiURL, - "pub": NewPubHandlerWithUpstream(nil, proxyURL, baseURL+"/pub/").upstreamURL, - "pypi": pypi.upstreamURL, - "pypi_download": pypi.downloadURL, - "nuget": nuget.upstreamURL, - "nuget_search": nuget.searchURL, - "composer": composer.upstreamURL, - "composer_repository": composer.repoURL, - "conan": NewConanHandlerWithUpstream(nil, proxyURL, baseURL+"/conan/").upstreamURL, - "conda": NewCondaHandlerWithUpstream(nil, proxyURL, baseURL+"/conda/").upstreamURL, - "cran": NewCRANHandlerWithUpstream(nil, proxyURL, baseURL+"/cran/").upstreamURL, - "julia": NewJuliaHandlerWithUpstream(nil, baseURL+"/julia/").upstreamURL, - "oci_default": NewContainerHandlerWithRegistry(nil, proxyURL, baseURL+"/oci/").registryURL, - "rpm": NewRPMHandlerWithUpstream(nil, proxyURL, baseURL+"/rpm/").upstreamURL, - } - - want := map[string]string{ - "gem": baseURL + "/gem", - "go": baseURL + "/go", - "hex": baseURL + "/hex", - "hex_api": baseURL + "/hex-api", - "pub": baseURL + "/pub", - "pypi": baseURL + "/pypi", - "pypi_download": baseURL + "/pypi-download", - "nuget": baseURL + "/nuget", - "nuget_search": baseURL + "/nuget-search", - "composer": baseURL + "/composer", - "composer_repository": baseURL + "/composer-repository", - "conan": baseURL + "/conan", - "conda": baseURL + "/conda", - "cran": baseURL + "/cran", - "julia": baseURL + "/julia", - "oci_default": baseURL + "/oci", - "rpm": baseURL + "/rpm", - } - - for name, wantURL := range want { - if gotURL := got[name]; gotURL != wantURL { - t.Errorf("%s upstream = %q, want %q", name, gotURL, wantURL) - } - } -} - -func TestConfiguredUpstreamURL(t *testing.T) { - if got := configuredUpstreamURL("", "https://default.example.com/"); got != "https://default.example.com" { - t.Errorf("empty configured URL = %q, want default", got) - } - if got := configuredUpstreamURL("https://custom.example.com/", "https://default.example.com"); got != "https://custom.example.com" { - t.Errorf("configured URL = %q, want trimmed custom URL", got) - } - if got := configuredUpstreamURL("https://custom.example.com///", "https://default.example.com"); got != "https://custom.example.com" { - t.Errorf("configured URL with trailing slashes = %q, want trimmed custom URL", got) - } -} - -func TestHexHandlerUsesConfiguredAPIUpstream(t *testing.T) { - var requestedPath string - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - requestedPath = r.URL.Path - _, _ = io.WriteString(w, `{"releases":[]}`) - })) - defer upstream.Close() - - h := NewHexHandlerWithUpstreams( - &Proxy{HTTPClient: upstream.Client()}, - "https://proxy.example.com", - upstream.URL+"/hex", - upstream.URL+"/hex-api", - ) - _, err := h.fetchFilteredVersions(httptest.NewRequest(http.MethodGet, "/", nil), "demo") - if err != nil { - t.Fatalf("fetchFilteredVersions failed: %v", err) - } - if requestedPath != "/hex-api/api/packages/demo" { - t.Errorf("API path = %q, want %q", requestedPath, "/hex-api/api/packages/demo") - } -} - -func TestPyPIHandlerRewritesConfiguredDownloadUpstream(t *testing.T) { - h := NewPyPIHandlerWithUpstreams( - nil, - "https://proxy.example.com", - "https://upstream.example.com/pypi", - "https://upstream.example.com/pypi", - ) - body := []byte(`demo`) - want := `demo` - if got := string(h.rewriteSimpleHTML(body, nil)); got != want { - t.Errorf("rewritten HTML = %q, want %q", got, want) - } -} - -func TestNuGetHandlerUsesConfiguredSearchUpstream(t *testing.T) { - h := NewNuGetHandlerWithUpstreams( - nil, - "https://proxy.example.com", - "https://upstream.example.com/nuget", - "https://upstream.example.com/nuget-search", - ) - req := httptest.NewRequest(http.MethodGet, "/query?q=demo", nil) - want := "https://upstream.example.com/nuget-search/query?q=demo" - if got := h.buildUpstreamURL(req); got != want { - t.Errorf("search URL = %q, want %q", got, want) - } -} diff --git a/internal/httpclient/access_log.go b/internal/httpclient/access_log.go deleted file mode 100644 index 8e13f23..0000000 --- a/internal/httpclient/access_log.go +++ /dev/null @@ -1,74 +0,0 @@ -package httpclient - -import ( - "log/slog" - "net/http" - "net/url" - "strings" - "time" - - "github.com/git-pkgs/proxy/internal/accesslog" -) - -type accessLogTransport struct { - base http.RoundTripper - accessLog *accesslog.Logger - logger *slog.Logger -} - -// NewAccessLogTransport records each upstream HTTP exchange around base. -func NewAccessLogTransport(base http.RoundTripper, log *accesslog.Logger, logger *slog.Logger) http.RoundTripper { - if base == nil { - base = http.DefaultTransport - } - if logger == nil { - logger = slog.Default() - } - if log == nil { - return base - } - return &accessLogTransport{ - base: base, - accessLog: log, - logger: logger, - } -} - -func (t *accessLogTransport) RoundTrip(req *http.Request) (*http.Response, error) { - start := time.Now() - resp, err := t.base.RoundTrip(req) - - entry := accesslog.Entry{ - Event: accesslog.EventUpstream, - RequestID: accesslog.RequestID(req.Context()), - Method: req.Method, - URL: accesslog.URLWithoutSecrets(req.URL), - DurationMS: time.Since(start).Milliseconds(), - } - if resp != nil { - entry.StatusCode = resp.StatusCode - } - if err != nil { - entry.Error = errorWithoutSecrets(err, req.URL) - } - if writeErr := t.accessLog.Write(entry); writeErr != nil { - t.logger.Error("failed to write access log", "error", writeErr) - } - - return resp, err -} - -func errorWithoutSecrets(err error, requestURL *url.URL) string { - message := err.Error() - if requestURL == nil { - return message - } - - cleanURL := accesslog.URLWithoutSecrets(requestURL) - for _, value := range []string{requestURL.String(), requestURL.Redacted()} { - if value != "" { - message = strings.ReplaceAll(message, value, cleanURL) - } - } - return message -} diff --git a/internal/httpclient/access_log_test.go b/internal/httpclient/access_log_test.go deleted file mode 100644 index aa3a43c..0000000 --- a/internal/httpclient/access_log_test.go +++ /dev/null @@ -1,121 +0,0 @@ -package httpclient - -import ( - "bufio" - "encoding/json" - "errors" - "io" - "log/slog" - "net/http" - "os" - "path/filepath" - "strings" - "testing" - - "github.com/git-pkgs/proxy/internal/accesslog" -) - -type roundTripFunc func(*http.Request) (*http.Response, error) - -func (f roundTripFunc) RoundTrip(req *http.Request) (*http.Response, error) { - return f(req) -} - -func TestAccessLogTransportRecordsUpstreamStatus(t *testing.T) { - path := filepath.Join(t.TempDir(), "access.jsonl") - accessLogger, err := accesslog.Open(path) - if err != nil { - t.Fatal(err) - } - - base := roundTripFunc(func(req *http.Request) (*http.Response, error) { - return &http.Response{ - StatusCode: http.StatusTooManyRequests, - Body: io.NopCloser(strings.NewReader("rate limited")), - Request: req, - }, nil - }) - client := &http.Client{Transport: NewAccessLogTransport(base, accessLogger, slog.Default())} - req, err := http.NewRequest(http.MethodGet, "https://user:password@registry.example/package.tgz?token=secret", nil) - if err != nil { - t.Fatal(err) - } - req = req.WithContext(accesslog.WithRequestID(req.Context(), "request-123")) - - resp, err := client.Do(req) - if err != nil { - t.Fatal(err) - } - _ = resp.Body.Close() - if err := accessLogger.Close(); err != nil { - t.Fatal(err) - } - - entry := readAccessLogEntry(t, path) - if entry.Event != accesslog.EventUpstream { - t.Errorf("event = %q, want %q", entry.Event, accesslog.EventUpstream) - } - if entry.RequestID != "request-123" { - t.Errorf("request_id = %q, want %q", entry.RequestID, "request-123") - } - if entry.StatusCode != http.StatusTooManyRequests { - t.Errorf("status_code = %d, want %d", entry.StatusCode, http.StatusTooManyRequests) - } - if entry.URL != "https://registry.example/package.tgz" { - t.Errorf("url = %q, want URL without credentials or query", entry.URL) - } -} - -func TestAccessLogTransportRecordsUpstreamError(t *testing.T) { - path := filepath.Join(t.TempDir(), "access.jsonl") - accessLogger, err := accesslog.Open(path) - if err != nil { - t.Fatal(err) - } - - wantErr := errors.New("GET https://user:password@registry.example/package.tgz?token=secret: connection refused") - base := roundTripFunc(func(*http.Request) (*http.Response, error) { - return nil, wantErr - }) - client := &http.Client{Transport: NewAccessLogTransport(base, accessLogger, slog.Default())} - - _, err = client.Get("https://user:password@registry.example/package.tgz?token=secret") - if !errors.Is(err, wantErr) { - t.Fatalf("GET error = %v, want %v", err, wantErr) - } - if err := accessLogger.Close(); err != nil { - t.Fatal(err) - } - - entry := readAccessLogEntry(t, path) - if entry.StatusCode != 0 { - t.Errorf("status_code = %d, want 0", entry.StatusCode) - } - if strings.Contains(entry.Error, "password") || strings.Contains(entry.Error, "secret") { - t.Errorf("error contains URL credentials or query: %q", entry.Error) - } - if !strings.Contains(entry.Error, "connection refused") { - t.Errorf("error = %q, want connection failure", entry.Error) - } -} - -func readAccessLogEntry(t *testing.T, path string) accesslog.Entry { - t.Helper() - - file, err := os.Open(path) - if err != nil { - t.Fatal(err) - } - defer func() { _ = file.Close() }() - - scanner := bufio.NewScanner(file) - if !scanner.Scan() { - t.Fatalf("access log is empty: %v", scanner.Err()) - } - - var entry accesslog.Entry - if err := json.Unmarshal(scanner.Bytes(), &entry); err != nil { - t.Fatalf("decoding access log: %v", err) - } - return entry -} diff --git a/internal/httpclient/transport.go b/internal/httpclient/transport.go deleted file mode 100644 index 1ee9597..0000000 --- a/internal/httpclient/transport.go +++ /dev/null @@ -1,507 +0,0 @@ -// Package httpclient provides authentication-aware HTTP transports for upstream requests. -package httpclient - -import ( - "context" - "encoding/json" - "errors" - "fmt" - "io" - "net" - "net/http" - "net/url" - "strings" - "sync" - "time" -) - -const ( - defaultTokenLifetime = 60 * time.Second - tokenExpirySkew = 5 * time.Second - maxTokenResponseSize = 1 << 20 - shortTokenSkewDivisor = 10 - tokenMaxRetries = 3 - tokenRetryBaseDelay = 500 * time.Millisecond -) - -// AuthFunc returns a configured authentication header for a URL. -type AuthFunc func(url string) (headerName, headerValue string) - -// Transport adds configured authentication and follows OCI Bearer challenges. -type Transport struct { - base http.RoundTripper - authForURL AuthFunc - retryWait func(context.Context, time.Duration) error - - mu sync.Mutex - tokens map[string]cachedToken - challenges map[string]bearerChallenge -} - -type cachedToken struct { - value string - expiresAt time.Time -} - -type bearerChallenge struct { - realm string - service string - scopes []string -} - -type tokenResponse struct { - Token string `json:"token"` - AccessToken string `json:"access_token"` - ExpiresIn int64 `json:"expires_in"` - IssuedAt string `json:"issued_at"` -} - -// NewTransport creates an authentication-aware transport around base. -func NewTransport(base http.RoundTripper, authForURL AuthFunc) *Transport { - if base == nil { - base = http.DefaultTransport - } - return &Transport{ - base: base, - authForURL: authForURL, - retryWait: waitForRetry, - tokens: make(map[string]cachedToken), - challenges: make(map[string]bearerChallenge), - } -} - -// RoundTrip implements http.RoundTripper. -func (t *Transport) RoundTrip(req *http.Request) (*http.Response, error) { - hasExplicitAuthorization := req.Header.Get("Authorization") != "" - outbound := cloneRequest(req) - t.applyAuthentication(outbound, hasExplicitAuthorization) - - resp, err := t.base.RoundTrip(outbound) - if err != nil || resp.StatusCode != http.StatusUnauthorized { - return resp, err - } - if hasExplicitAuthorization { - return resp, nil - } - if registryProtectionSpace(req.URL) == "" { - return resp, nil - } - - challenge, ok := parseBearerChallenge(resp.Header.Values("WWW-Authenticate")) - if !ok || !canReplay(req) { - return resp, nil - } - - drainAndClose(resp.Body) - token, err := t.token(req.Context(), challenge) - if err != nil { - return nil, fmt.Errorf("registry authentication: %w", err) - } - t.rememberChallenge(req.URL, challenge) - - retry, err := cloneRequestForRetry(req) - if err != nil { - return nil, err - } - t.applyConfiguredAuthentication(retry) - retry.Header.Set("Authorization", "Bearer "+token) - return t.base.RoundTrip(retry) -} - -func (t *Transport) applyAuthentication(req *http.Request, hasExplicitAuthorization bool) { - t.applyConfiguredAuthentication(req) - if hasExplicitAuthorization { - return - } - if token := t.cachedTokenForRequest(req.URL); token != "" { - req.Header.Set("Authorization", "Bearer "+token) - } -} - -func (t *Transport) applyConfiguredAuthentication(req *http.Request) { - if t.authForURL == nil { - return - } - name, value := t.authForURL(req.URL.String()) - if name != "" && value != "" && req.Header.Get(name) == "" { - req.Header.Set(name, value) - } -} - -func (t *Transport) token(ctx context.Context, challenge bearerChallenge) (string, error) { - key := challenge.key() - if token := t.cachedToken(key); token != "" { - return token, nil - } - - token, expiresAt, err := t.fetchToken(ctx, challenge) - if err != nil { - return "", err - } - - t.cacheToken(key, cachedToken{value: token, expiresAt: expiresAt}) - return token, nil -} - -func (t *Transport) cacheToken(key string, token cachedToken) { - now := time.Now() - t.mu.Lock() - defer t.mu.Unlock() - - for cachedKey, cached := range t.tokens { - if !now.Before(cached.expiresAt) { - delete(t.tokens, cachedKey) - } - } - t.tokens[key] = token -} - -func (t *Transport) fetchToken(ctx context.Context, challenge bearerChallenge) (string, time.Time, error) { - tokenURL, err := url.Parse(challenge.realm) - if err != nil || !tokenURL.IsAbs() || (tokenURL.Scheme != "https" && tokenURL.Scheme != "http") { - return "", time.Time{}, fmt.Errorf("invalid token realm %q", challenge.realm) - } - - query := tokenURL.Query() - if challenge.service != "" { - query.Set("service", challenge.service) - } - for _, scope := range challenge.scopes { - query.Add("scope", scope) - } - query.Set("client_id", "git-pkgs-proxy") - tokenURL.RawQuery = query.Encode() - - req, err := http.NewRequestWithContext(ctx, http.MethodGet, tokenURL.String(), nil) - if err != nil { - return "", time.Time{}, err - } - - client := &http.Client{Transport: configuredTransport{parent: t}} - for attempt := 0; attempt <= tokenMaxRetries; attempt++ { - resp, err := client.Do(req.Clone(ctx)) - if err != nil { - requestErr := fmt.Errorf("requesting token: %w", err) - if !shouldRetryTokenRequest(ctx, err) || attempt == tokenMaxRetries { - return "", time.Time{}, requestErr - } - if err := t.waitForTokenRetry(ctx, attempt); err != nil { - return "", time.Time{}, err - } - continue - } - - if resp.StatusCode >= http.StatusOK && resp.StatusCode < http.StatusMultipleChoices { - return decodeTokenResponse(resp) - } - - responseErr := tokenResponseError(resp) - if !shouldRetryTokenStatus(resp.StatusCode) || attempt == tokenMaxRetries { - return "", time.Time{}, responseErr - } - if err := t.waitForTokenRetry(ctx, attempt); err != nil { - return "", time.Time{}, err - } - } - - return "", time.Time{}, errors.New("token request retries exhausted") -} - -func decodeTokenResponse(resp *http.Response) (string, time.Time, error) { - defer func() { _ = resp.Body.Close() }() - - var payload tokenResponse - if err := json.NewDecoder(io.LimitReader(resp.Body, maxTokenResponseSize)).Decode(&payload); err != nil { - return "", time.Time{}, fmt.Errorf("decoding token response: %w", err) - } - token := payload.Token - if token == "" { - token = payload.AccessToken - } - if token == "" { - return "", time.Time{}, fmt.Errorf("token response did not contain a token") - } - - issuedAt := time.Now() - if payload.IssuedAt != "" { - if parsed, parseErr := time.Parse(time.RFC3339, payload.IssuedAt); parseErr == nil { - issuedAt = parsed - } - } - lifetime := time.Duration(payload.ExpiresIn) * time.Second - if lifetime <= 0 { - lifetime = defaultTokenLifetime - } - expiresAt := issuedAt.Add(lifetime).Add(-expirySkew(lifetime)) - return token, expiresAt, nil -} - -func tokenResponseError(resp *http.Response) error { - defer func() { _ = resp.Body.Close() }() - body, _ := io.ReadAll(io.LimitReader(resp.Body, maxTokenResponseSize)) - return fmt.Errorf("token service returned %d: %s", resp.StatusCode, strings.TrimSpace(string(body))) -} - -func shouldRetryTokenRequest(ctx context.Context, err error) bool { - if ctx.Err() != nil || errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) { - return false - } - - var networkErr net.Error - if !errors.As(err, &networkErr) { - return false - } - - var dnsErr *net.DNSError - if errors.As(err, &dnsErr) { - return dnsErr.IsTemporary || dnsErr.IsTimeout - } - return networkErr.Timeout() -} - -func shouldRetryTokenStatus(status int) bool { - return status == http.StatusTooManyRequests || status >= http.StatusInternalServerError -} - -func (t *Transport) waitForTokenRetry(ctx context.Context, attempt int) error { - delay := tokenRetryBaseDelay << attempt - if t.retryWait != nil { - return t.retryWait(ctx, delay) - } - return waitForRetry(ctx, delay) -} - -func waitForRetry(ctx context.Context, delay time.Duration) error { - timer := time.NewTimer(delay) - defer timer.Stop() - - select { - case <-ctx.Done(): - return ctx.Err() - case <-timer.C: - return nil - } -} - -type configuredTransport struct { - parent *Transport -} - -func (t configuredTransport) RoundTrip(req *http.Request) (*http.Response, error) { - outbound := cloneRequest(req) - t.parent.applyConfiguredAuthentication(outbound) - return t.parent.base.RoundTrip(outbound) -} - -func (t *Transport) cachedTokenForRequest(requestURL *url.URL) string { - space := registryProtectionSpace(requestURL) - if space == "" { - return "" - } - - t.mu.Lock() - challenge, ok := t.challenges[space] - t.mu.Unlock() - if !ok { - return "" - } - return t.cachedToken(challenge.key()) -} - -func (t *Transport) cachedToken(key string) string { - now := time.Now() - t.mu.Lock() - defer t.mu.Unlock() - - token, ok := t.tokens[key] - if !ok { - return "" - } - if !now.Before(token.expiresAt) { - delete(t.tokens, key) - return "" - } - return token.value -} - -func (t *Transport) rememberChallenge(requestURL *url.URL, challenge bearerChallenge) { - space := registryProtectionSpace(requestURL) - if space == "" { - return - } - t.mu.Lock() - t.challenges[space] = challenge - t.mu.Unlock() -} - -func (c bearerChallenge) key() string { - return c.realm + "\x00" + c.service + "\x00" + strings.Join(c.scopes, "\x00") -} - -func registryProtectionSpace(u *url.URL) string { - const registryPrefix = "/v2/" - if u == nil || !strings.HasPrefix(u.Path, registryPrefix) { - return "" - } - rest := strings.TrimPrefix(u.Path, registryPrefix) - end := len(rest) - for _, marker := range []string{"/blobs/", "/manifests/", "/tags/", "/referrers/"} { - if index := strings.Index(rest, marker); index >= 0 && index < end { - end = index - } - } - if end == len(rest) || end == 0 { - return "" - } - return u.Scheme + "://" + u.Host + registryPrefix + rest[:end] -} - -func parseBearerChallenge(values []string) (bearerChallenge, bool) { - for _, value := range values { - params, ok := bearerParameters(value) - if !ok || params["realm"] == "" { - continue - } - challenge := bearerChallenge{ - realm: params["realm"], - service: params["service"], - } - if scope := params["scope"]; scope != "" { - challenge.scopes = append(challenge.scopes, scope) - } - return challenge, true - } - return bearerChallenge{}, false -} - -func bearerParameters(value string) (map[string]string, bool) { - start := findAuthScheme(value, "Bearer") - if start < 0 { - return nil, false - } - rest := value[start+len("Bearer"):] - params := make(map[string]string) - for { - rest = strings.TrimLeft(rest, " \t,") - if rest == "" { - break - } - - keyEnd := strings.IndexAny(rest, "= \t,") - if keyEnd <= 0 { - break - } - key := strings.ToLower(rest[:keyEnd]) - rest = strings.TrimLeft(rest[keyEnd:], " \t") - if rest == "" || rest[0] != '=' { - break - } - rest = strings.TrimLeft(rest[1:], " \t") - - parsed, remaining, ok := parseAuthValue(rest) - if !ok { - return nil, false - } - params[key] = parsed - rest = remaining - } - return params, true -} - -func findAuthScheme(value, scheme string) int { - inQuote := false - escaped := false - for index := 0; index+len(scheme) <= len(value); index++ { - char := value[index] - if escaped { - escaped = false - continue - } - if char == '\\' && inQuote { - escaped = true - continue - } - if char == '"' { - inQuote = !inQuote - continue - } - if inQuote || !strings.EqualFold(value[index:index+len(scheme)], scheme) { - continue - } - beforeOK := index == 0 || value[index-1] == ',' || value[index-1] == ' ' || value[index-1] == '\t' - after := index + len(scheme) - afterOK := after < len(value) && (value[after] == ' ' || value[after] == '\t') - if beforeOK && afterOK { - return index - } - } - return -1 -} - -func parseAuthValue(value string) (parsed, remaining string, ok bool) { - if value == "" { - return "", "", false - } - if value[0] != '"' { - end := strings.IndexAny(value, " \t,") - if end < 0 { - return value, "", true - } - return value[:end], value[end:], end > 0 - } - - var builder strings.Builder - escaped := false - for index := 1; index < len(value); index++ { - char := value[index] - if escaped { - builder.WriteByte(char) - escaped = false - continue - } - if char == '\\' { - escaped = true - continue - } - if char == '"' { - return builder.String(), value[index+1:], true - } - builder.WriteByte(char) - } - return "", "", false -} - -func cloneRequest(req *http.Request) *http.Request { - clone := req.Clone(req.Context()) - clone.Header = req.Header.Clone() - return clone -} - -func canReplay(req *http.Request) bool { - return req.Body == nil || req.GetBody != nil -} - -func cloneRequestForRetry(req *http.Request) (*http.Request, error) { - clone := cloneRequest(req) - if req.Body == nil { - return clone, nil - } - body, err := req.GetBody() - if err != nil { - return nil, fmt.Errorf("replaying authenticated request: %w", err) - } - clone.Body = body - return clone, nil -} - -func expirySkew(lifetime time.Duration) time.Duration { - if lifetime < tokenExpirySkew*2 { - return lifetime / shortTokenSkewDivisor - } - return tokenExpirySkew -} - -func drainAndClose(body io.ReadCloser) { - _, _ = io.Copy(io.Discard, io.LimitReader(body, maxTokenResponseSize)) - _ = body.Close() -} diff --git a/internal/httpclient/transport_test.go b/internal/httpclient/transport_test.go deleted file mode 100644 index 01f3e8b..0000000 --- a/internal/httpclient/transport_test.go +++ /dev/null @@ -1,414 +0,0 @@ -package httpclient - -import ( - "context" - "errors" - "io" - "net" - "net/http" - "net/http/httptest" - "strings" - "testing" - "time" -) - -type roundTripperFunc func(*http.Request) (*http.Response, error) - -func (fn roundTripperFunc) RoundTrip(req *http.Request) (*http.Response, error) { - return fn(req) -} - -func TestTransportFollowsBearerChallengeAndCachesToken(t *testing.T) { - var registryRequests int - var tokenRequests int - var server *httptest.Server - - server = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.URL.Path { - case "/token": - tokenRequests++ - if got := r.URL.Query().Get("service"); got != "registry.test" { - t.Errorf("service = %q, want %q", got, "registry.test") - } - if got := r.URL.Query().Get("scope"); got != "repository:library/test:pull" { - t.Errorf("scope = %q, want %q", got, "repository:library/test:pull") - } - w.Header().Set("Content-Type", "application/json") - _, _ = io.WriteString(w, `{"token":"registry-token","expires_in":3600}`) - case "/v2/library/test/blobs/sha256:first", "/v2/library/test/blobs/sha256:second": - registryRequests++ - if r.Header.Get("Authorization") != "Bearer registry-token" { - w.Header().Set("WWW-Authenticate", `Bearer realm="`+server.URL+`/token",service="registry.test",scope="repository:library/test:pull"`) - http.Error(w, "authentication required", http.StatusUnauthorized) - return - } - _, _ = io.WriteString(w, "blob") - default: - http.NotFound(w, r) - } - })) - defer server.Close() - - client := &http.Client{Transport: NewTransport(http.DefaultTransport, nil)} - for _, digest := range []string{"sha256:first", "sha256:second"} { - resp, err := client.Get(server.URL + "/v2/library/test/blobs/" + digest) - if err != nil { - t.Fatalf("GET %s: %v", digest, err) - } - body, readErr := io.ReadAll(resp.Body) - _ = resp.Body.Close() - if readErr != nil { - t.Fatalf("read %s response: %v", digest, readErr) - } - if resp.StatusCode != http.StatusOK { - t.Fatalf("GET %s status = %d, want %d", digest, resp.StatusCode, http.StatusOK) - } - if string(body) != "blob" { - t.Errorf("GET %s body = %q, want %q", digest, body, "blob") - } - } - - if tokenRequests != 1 { - t.Errorf("token requests = %d, want 1", tokenRequests) - } - if registryRequests != 3 { - t.Errorf("registry requests = %d, want 3", registryRequests) - } -} - -func TestTransportRetriesTemporaryTokenLookupFailures(t *testing.T) { - var registryRequests int - var tokenRequests int - var tokenLookupFailures int - var server *httptest.Server - - server = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.URL.Path { - case "/token": - tokenRequests++ - _, _ = io.WriteString(w, `{"token":"registry-token"}`) - case "/v2/library/test/blobs/sha256:test": - registryRequests++ - if r.Header.Get("Authorization") != "Bearer registry-token" { - w.Header().Set("WWW-Authenticate", `Bearer realm="`+server.URL+`/token",service="registry.test",scope="repository:library/test:pull"`) - http.Error(w, "authentication required", http.StatusUnauthorized) - return - } - _, _ = io.WriteString(w, "blob") - default: - http.NotFound(w, r) - } - })) - defer server.Close() - - base := roundTripperFunc(func(req *http.Request) (*http.Response, error) { - if req.URL.Path == "/token" && tokenLookupFailures < 2 { - tokenLookupFailures++ - return nil, &net.DNSError{Err: "server misbehaving", IsTemporary: true} - } - return http.DefaultTransport.RoundTrip(req) - }) - transport := NewTransport(base, nil) - transport.retryWait = func(context.Context, time.Duration) error { return nil } - client := &http.Client{Transport: transport} - - resp, err := client.Get(server.URL + "/v2/library/test/blobs/sha256:test") - if err != nil { - t.Fatalf("GET blob: %v", err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusOK { - t.Errorf("status = %d, want %d", resp.StatusCode, http.StatusOK) - } - if tokenLookupFailures != 2 { - t.Errorf("token lookup failures = %d, want 2", tokenLookupFailures) - } - if tokenRequests != 1 { - t.Errorf("token requests = %d, want 1", tokenRequests) - } - if registryRequests != 2 { - t.Errorf("registry requests = %d, want 2", registryRequests) - } -} - -func TestTransportDoesNotRetryPermanentTokenLookupFailures(t *testing.T) { - var tokenRequests int - base := roundTripperFunc(func(*http.Request) (*http.Response, error) { - tokenRequests++ - return nil, &net.DNSError{Err: "no such host"} - }) - transport := NewTransport(base, nil) - transport.retryWait = func(context.Context, time.Duration) error { return nil } - - _, _, err := transport.fetchToken(context.Background(), bearerChallenge{realm: "https://auth.example.test/token"}) - if err == nil { - t.Fatal("fetchToken succeeded, want error") - } - if tokenRequests != 1 { - t.Errorf("token requests = %d, want 1", tokenRequests) - } -} - -func TestTransportDoesNotRetryPermanentTokenFailures(t *testing.T) { - var tokenRequests int - server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - tokenRequests++ - http.Error(w, "invalid credentials", http.StatusUnauthorized) - })) - defer server.Close() - - transport := NewTransport(http.DefaultTransport, nil) - _, _, err := transport.fetchToken(context.Background(), bearerChallenge{realm: server.URL + "/token"}) - if err == nil { - t.Fatal("fetchToken succeeded, want error") - } - if tokenRequests != 1 { - t.Errorf("token requests = %d, want 1", tokenRequests) - } -} - -func TestTransportRetriesTokenServiceFailures(t *testing.T) { - for _, status := range []int{http.StatusTooManyRequests, http.StatusServiceUnavailable} { - t.Run(http.StatusText(status), func(t *testing.T) { - var tokenRequests int - server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - tokenRequests++ - http.Error(w, "temporary token service failure", status) - })) - defer server.Close() - - var delays []time.Duration - transport := NewTransport(http.DefaultTransport, nil) - transport.retryWait = func(_ context.Context, delay time.Duration) error { - delays = append(delays, delay) - return nil - } - - _, _, err := transport.fetchToken(context.Background(), bearerChallenge{realm: server.URL + "/token"}) - if err == nil { - t.Fatal("fetchToken succeeded, want error") - } - if tokenRequests != tokenMaxRetries+1 { - t.Errorf("token requests = %d, want %d", tokenRequests, tokenMaxRetries+1) - } - wantDelays := []time.Duration{500 * time.Millisecond, time.Second, 2 * time.Second} - if len(delays) != len(wantDelays) { - t.Fatalf("retry delays = %v, want %v", delays, wantDelays) - } - for index, want := range wantDelays { - if delays[index] != want { - t.Errorf("retry delay %d = %s, want %s", index, delays[index], want) - } - } - }) - } -} - -func TestTransportStopsTokenRetriesWhenWaitingIsCancelled(t *testing.T) { - var tokenRequests int - server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - tokenRequests++ - http.Error(w, "temporary token service failure", http.StatusServiceUnavailable) - })) - defer server.Close() - - ctx, cancel := context.WithCancel(context.Background()) - defer cancel() - transport := NewTransport(http.DefaultTransport, nil) - transport.retryWait = func(ctx context.Context, _ time.Duration) error { - cancel() - <-ctx.Done() - return ctx.Err() - } - - _, _, err := transport.fetchToken(ctx, bearerChallenge{realm: server.URL + "/token"}) - if !errors.Is(err, context.Canceled) { - t.Errorf("fetchToken error = %v, want context canceled", err) - } - if tokenRequests != 1 { - t.Errorf("token requests = %d, want 1", tokenRequests) - } -} - -func TestTransportAddsConfiguredAuthentication(t *testing.T) { - server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if got := r.Header.Get("X-Registry-Token"); got != "configured-token" { - t.Errorf("X-Registry-Token = %q, want %q", got, "configured-token") - } - w.WriteHeader(http.StatusNoContent) - })) - defer server.Close() - - authForURL := func(url string) (string, string) { - if strings.HasPrefix(url, server.URL) { - return "X-Registry-Token", "configured-token" - } - return "", "" - } - client := &http.Client{Transport: NewTransport(http.DefaultTransport, authForURL)} - - resp, err := client.Get(server.URL + "/metadata") - if err != nil { - t.Fatalf("GET metadata: %v", err) - } - _ = resp.Body.Close() - if resp.StatusCode != http.StatusNoContent { - t.Errorf("status = %d, want %d", resp.StatusCode, http.StatusNoContent) - } -} - -func TestTransportPreservesExplicitAuthentication(t *testing.T) { - server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if got := r.Header.Get("Authorization"); got != "Bearer explicit-token" { - t.Errorf("Authorization = %q, want %q", got, "Bearer explicit-token") - } - w.WriteHeader(http.StatusNoContent) - })) - defer server.Close() - - authForURL := func(string) (string, string) { - return "Authorization", "Bearer configured-token" - } - client := &http.Client{Transport: NewTransport(http.DefaultTransport, authForURL)} - req, err := http.NewRequest(http.MethodGet, server.URL+"/artifact", nil) - if err != nil { - t.Fatal(err) - } - req.Header.Set("Authorization", "Bearer explicit-token") - - resp, err := client.Do(req) - if err != nil { - t.Fatalf("GET artifact: %v", err) - } - _ = resp.Body.Close() - if resp.StatusCode != http.StatusNoContent { - t.Errorf("status = %d, want %d", resp.StatusCode, http.StatusNoContent) - } -} - -func TestTransportDoesNotReplaceExplicitAuthenticationAfterBearerChallenge(t *testing.T) { - var registryRequests int - var tokenRequests int - var server *httptest.Server - - server = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.URL.Path { - case "/token": - tokenRequests++ - _, _ = io.WriteString(w, `{"token":"registry-token"}`) - case "/v2/library/test/blobs/sha256:test": - registryRequests++ - if got := r.Header.Get("Authorization"); got != "Bearer explicit-token" { - t.Errorf("Authorization = %q, want %q", got, "Bearer explicit-token") - } - w.Header().Set("WWW-Authenticate", `Bearer realm="`+server.URL+`/token"`) - http.Error(w, "authentication required", http.StatusUnauthorized) - default: - http.NotFound(w, r) - } - })) - defer server.Close() - - client := &http.Client{Transport: NewTransport(http.DefaultTransport, nil)} - req, err := http.NewRequest(http.MethodGet, server.URL+"/v2/library/test/blobs/sha256:test", nil) - if err != nil { - t.Fatal(err) - } - req.Header.Set("Authorization", "Bearer explicit-token") - - resp, err := client.Do(req) - if err != nil { - t.Fatalf("GET blob: %v", err) - } - _ = resp.Body.Close() - if resp.StatusCode != http.StatusUnauthorized { - t.Errorf("status = %d, want %d", resp.StatusCode, http.StatusUnauthorized) - } - if registryRequests != 1 { - t.Errorf("registry requests = %d, want 1", registryRequests) - } - if tokenRequests != 0 { - t.Errorf("token requests = %d, want 0", tokenRequests) - } -} - -func TestTransportDoesNotForwardConfiguredAuthenticationOnTokenRedirect(t *testing.T) { - destination := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if got := r.Header.Get("X-Registry-Token"); got != "" { - t.Errorf("redirected X-Registry-Token = %q, want empty", got) - } - _, _ = io.WriteString(w, `{"token":"registry-token"}`) - })) - defer destination.Close() - - source := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if got := r.Header.Get("X-Registry-Token"); got != "configured-token" { - t.Errorf("source X-Registry-Token = %q, want %q", got, "configured-token") - } - http.Redirect(w, r, destination.URL+"/token", http.StatusFound) - })) - defer source.Close() - - authForURL := func(rawURL string) (string, string) { - if strings.HasPrefix(rawURL, source.URL) { - return "X-Registry-Token", "configured-token" - } - return "", "" - } - transport := NewTransport(http.DefaultTransport, authForURL) - token, _, err := transport.fetchToken(context.Background(), bearerChallenge{realm: source.URL + "/token"}) - if err != nil { - t.Fatalf("fetchToken: %v", err) - } - if token != "registry-token" { - t.Errorf("token = %q, want %q", token, "registry-token") - } -} - -func TestTransportPrunesExpiredTokens(t *testing.T) { - transport := NewTransport(http.DefaultTransport, nil) - transport.tokens["expired-unused"] = cachedToken{ - value: "expired-token", - expiresAt: time.Now().Add(-time.Minute), - } - transport.cacheToken("current", cachedToken{ - value: "current-token", - expiresAt: time.Now().Add(time.Minute), - }) - - if got := transport.cachedToken("current"); got != "current-token" { - t.Errorf("cachedToken(current) = %q, want %q", got, "current-token") - } - if _, ok := transport.tokens["expired-unused"]; ok { - t.Error("expired unused token was not pruned") - } -} - -func TestTransportDoesNotFollowBearerChallengeOutsideOCIRegistry(t *testing.T) { - tokenRequests := 0 - var server *httptest.Server - server = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - if r.URL.Path == "/token" { - tokenRequests++ - _, _ = io.WriteString(w, `{"token":"unexpected"}`) - return - } - w.Header().Set("WWW-Authenticate", `Bearer realm="`+server.URL+`/token"`) - http.Error(w, "authentication required", http.StatusUnauthorized) - })) - defer server.Close() - - client := &http.Client{Transport: NewTransport(http.DefaultTransport, nil)} - resp, err := client.Get(server.URL + "/api/packages") - if err != nil { - t.Fatalf("GET API: %v", err) - } - _ = resp.Body.Close() - if resp.StatusCode != http.StatusUnauthorized { - t.Errorf("status = %d, want %d", resp.StatusCode, http.StatusUnauthorized) - } - if tokenRequests != 0 { - t.Errorf("token requests = %d, want 0", tokenRequests) - } -} diff --git a/internal/metrics/metrics.go b/internal/metrics/metrics.go index aff5768..da8bde6 100644 --- a/internal/metrics/metrics.go +++ b/internal/metrics/metrics.go @@ -6,7 +6,6 @@ import ( "strconv" "time" - "github.com/git-pkgs/purl" "github.com/prometheus/client_golang/prometheus" "github.com/prometheus/client_golang/prometheus/promhttp" ) @@ -121,48 +120,6 @@ var ( Help: "Number of currently active requests", }, ) - - IntegrityFailures = prometheus.NewCounterVec( - prometheus.CounterOpts{ - Name: "proxy_integrity_failures_total", - Help: "Cached artifacts that failed hash verification on read", - }, - []string{"ecosystem"}, - ) - - HealthProbeFailures = prometheus.NewCounterVec( - prometheus.CounterOpts{ - Name: "proxy_health_probe_failures_total", - Help: "Total number of storage health probe failures, by step (write|size|read|verify|delete).", - }, - []string{"step"}, - ) - - // Scanning metrics - ScanDuration = prometheus.NewHistogramVec( - prometheus.HistogramOpts{ - Name: "proxy_scan_duration_seconds", - Help: "Pre-cache artifact scan duration in seconds, by ecosystem and scanner", - Buckets: prometheus.DefBuckets, - }, - []string{"ecosystem", "scanner"}, - ) - - ScanBlocked = prometheus.NewCounterVec( - prometheus.CounterOpts{ - Name: "proxy_scan_blocked_total", - Help: "Total number of artifacts blocked by a pre-cache scan, by ecosystem and scanner", - }, - []string{"ecosystem", "scanner"}, - ) - - ScanErrors = prometheus.NewCounterVec( - prometheus.CounterOpts{ - Name: "proxy_scan_errors_total", - Help: "Total number of pre-cache scan errors, by ecosystem, scanner, and error type", - }, - []string{"ecosystem", "scanner", "error_type"}, - ) ) func init() { @@ -181,11 +138,6 @@ func init() { StorageOperationDuration, StorageErrors, ActiveRequests, - IntegrityFailures, - HealthProbeFailures, - ScanDuration, - ScanBlocked, - ScanErrors, ) } @@ -203,12 +155,12 @@ func RecordRequest(ecosystem string, status int, duration time.Duration) { // RecordCacheHit increments cache hit counter. func RecordCacheHit(ecosystem string) { - CacheHits.WithLabelValues(purl.NormalizeEcosystem(ecosystem)).Inc() + CacheHits.WithLabelValues(ecosystem).Inc() } // RecordCacheMiss increments cache miss counter. func RecordCacheMiss(ecosystem string) { - CacheMisses.WithLabelValues(purl.NormalizeEcosystem(ecosystem)).Inc() + CacheMisses.WithLabelValues(ecosystem).Inc() } // RecordUpstreamFetch tracks upstream fetch duration. @@ -226,37 +178,11 @@ func RecordStorageOperation(operation string, duration time.Duration) { StorageOperationDuration.WithLabelValues(operation).Observe(duration.Seconds()) } -// RecordIntegrityFailure increments the integrity failure counter. -func RecordIntegrityFailure(ecosystem string) { - IntegrityFailures.WithLabelValues(ecosystem).Inc() -} - -// RecordHealthProbeFailure increments the health probe failure counter. -// step is one of: "write", "size", "read", "verify", "delete". -func RecordHealthProbeFailure(step string) { - HealthProbeFailures.WithLabelValues(step).Inc() -} - // RecordStorageError increments storage error counter. func RecordStorageError(operation string) { StorageErrors.WithLabelValues(operation).Inc() } -// RecordScanResult tracks a completed pre-cache scan call. -func RecordScanResult(ecosystem, scannerName string, allowed bool, duration time.Duration) { - ecosystem = purl.NormalizeEcosystem(ecosystem) - ScanDuration.WithLabelValues(ecosystem, scannerName).Observe(duration.Seconds()) - if !allowed { - ScanBlocked.WithLabelValues(ecosystem, scannerName).Inc() - } -} - -// RecordScanError increments the scan error counter. -// errorType is one of: "error" (scanner call failed), "timeout", "cancelled". -func RecordScanError(ecosystem, scannerName, errorType string) { - ScanErrors.WithLabelValues(purl.NormalizeEcosystem(ecosystem), scannerName, errorType).Inc() -} - // UpdateCacheStats updates cache size and artifact count gauges. func UpdateCacheStats(sizeBytes, artifactCount int64) { CacheSize.Set(float64(sizeBytes)) diff --git a/internal/metrics/metrics_test.go b/internal/metrics/metrics_test.go index a445467..db7b097 100644 --- a/internal/metrics/metrics_test.go +++ b/internal/metrics/metrics_test.go @@ -6,7 +6,6 @@ import ( "time" "github.com/prometheus/client_golang/prometheus" - "github.com/prometheus/client_golang/prometheus/testutil" dto "github.com/prometheus/client_model/go" ) @@ -49,7 +48,7 @@ func TestRecordStorageOperations(t *testing.T) { func TestUpdateCacheStats(t *testing.T) { UpdateCacheStats(1024*1024*1024, 100) // 1GB, 100 artifacts - UpdateCacheStats(0, 0) // Empty cache + UpdateCacheStats(0, 0) // Empty cache // No panics = success } @@ -192,45 +191,22 @@ func TestMetricsEndpointOutput(t *testing.T) { func TestMetricsLabeling(t *testing.T) { // Test that different ecosystems are properly labeled - ecosystems := []struct { - input string - label string - }{ - {input: "npm", label: "npm"}, - {input: "pypi", label: "pypi"}, - {input: "cargo", label: "cargo"}, - {input: "gem", label: "rubygems"}, - } + ecosystems := []string{"npm", "pypi", "cargo", "gem"} for _, eco := range ecosystems { - RecordRequest(eco.input, 200, 10*time.Millisecond) - RecordCacheHit(eco.input) + RecordRequest(eco, 200, 10*time.Millisecond) + RecordCacheHit(eco) } // Verify each ecosystem has metrics for _, eco := range ecosystems { - val := getMetricValue(t, CacheHits, eco.label) + val := getMetricValue(t, CacheHits, eco) if val == 0 { - t.Errorf("no cache hits recorded for %s", eco.label) + t.Errorf("no cache hits recorded for %s", eco) } } } -func TestCacheMetricLabelsAreNormalized(t *testing.T) { - rubyHitsBefore := testutil.ToFloat64(CacheHits.WithLabelValues("rubygems")) - composerMissesBefore := testutil.ToFloat64(CacheMisses.WithLabelValues("packagist")) - - RecordCacheHit("gem") - RecordCacheMiss("composer") - - if diff := testutil.ToFloat64(CacheHits.WithLabelValues("rubygems")) - rubyHitsBefore; diff != 1 { - t.Errorf("rubygems cache hits delta = %.0f, want 1", diff) - } - if diff := testutil.ToFloat64(CacheMisses.WithLabelValues("packagist")) - composerMissesBefore; diff != 1 { - t.Errorf("packagist cache misses delta = %.0f, want 1", diff) - } -} - func TestMetricNames(t *testing.T) { // Verify metric names follow Prometheus naming conventions expectedMetrics := []string{ diff --git a/internal/mirror/job.go b/internal/mirror/job.go index 70d7003..8915d4a 100644 --- a/internal/mirror/job.go +++ b/internal/mirror/job.go @@ -3,7 +3,6 @@ package mirror import ( "context" "crypto/rand" - "encoding/json" "fmt" "sync" "time" @@ -36,16 +35,15 @@ type Job struct { // JobRequest is the JSON body for starting a mirror job via the API. type JobRequest struct { - PURLs []string `json:"purls,omitempty"` - SBOM json.RawMessage `json:"sbom,omitempty"` - Registry string `json:"registry,omitempty"` + PURLs []string `json:"purls,omitempty"` + Registry string `json:"registry,omitempty"` } // JobStore manages in-memory mirror jobs. type JobStore struct { - mu sync.RWMutex - jobs map[string]*Job - mirror *Mirror + mu sync.RWMutex + jobs map[string]*Job + mirror *Mirror parentCtx context.Context } @@ -192,16 +190,12 @@ func (js *JobStore) runJob(ctx context.Context, cancel context.CancelFunc, job * func (js *JobStore) sourceFromRequest(req JobRequest) (Source, error) { //nolint:ireturn // interface return is the design switch { - case len(req.PURLs) > 0 && len(req.SBOM) > 0: - return nil, fmt.Errorf("request must include only one of purls or sbom") case len(req.PURLs) > 0: return &PURLSource{PURLs: req.PURLs}, nil - case len(req.SBOM) > 0: - return &SBOMSource{Data: req.SBOM}, nil case req.Registry != "": return nil, fmt.Errorf("registry mirroring is not yet implemented; use purls instead") default: - return nil, fmt.Errorf("request must include purls or sbom") + return nil, fmt.Errorf("request must include purls") } } diff --git a/internal/mirror/job_test.go b/internal/mirror/job_test.go index c0ac3f1..f7f2f1c 100644 --- a/internal/mirror/job_test.go +++ b/internal/mirror/job_test.go @@ -2,7 +2,6 @@ package mirror import ( "context" - "encoding/json" "testing" "time" ) @@ -101,37 +100,6 @@ func TestSourceFromRequestPURLs(t *testing.T) { } } -func TestSourceFromRequestSBOM(t *testing.T) { - m := setupTestMirror(t, 1) - js := NewJobStore(context.Background(), m) - sbom := json.RawMessage(`{"bomFormat":"CycloneDX","components":[]}`) - - source, err := js.sourceFromRequest(JobRequest{SBOM: sbom}) - if err != nil { - t.Fatalf("sourceFromRequest() error = %v", err) - } - sbomSource, ok := source.(*SBOMSource) - if !ok { - t.Fatalf("expected *SBOMSource, got %T", source) - } - if got := string(sbomSource.Data); got != string(sbom) { - t.Errorf("SBOM data = %q, want %q", got, sbom) - } -} - -func TestSourceFromRequestRejectsPURLsAndSBOM(t *testing.T) { - m := setupTestMirror(t, 1) - js := NewJobStore(context.Background(), m) - - _, err := js.sourceFromRequest(JobRequest{ - PURLs: []string{"pkg:npm/lodash@4.17.21"}, - SBOM: json.RawMessage(`{"bomFormat":"CycloneDX","components":[]}`), - }) - if err == nil { - t.Fatal("expected error when both purls and sbom are provided") - } -} - func TestSourceFromRequestRegistryRejected(t *testing.T) { m := setupTestMirror(t, 1) js := NewJobStore(context.Background(), m) diff --git a/internal/mirror/mirror.go b/internal/mirror/mirror.go index b52c4f6..06b496f 100644 --- a/internal/mirror/mirror.go +++ b/internal/mirror/mirror.go @@ -40,14 +40,14 @@ func New(proxy *handler.Proxy, db *database.DB, store storage.Storage, logger *s // Progress tracks the state of a mirror operation. type Progress struct { - Total int64 `json:"total"` - Completed int64 `json:"completed"` - Skipped int64 `json:"skipped"` - Failed int64 `json:"failed"` - Bytes int64 `json:"bytes"` + Total int64 `json:"total"` + Completed int64 `json:"completed"` + Skipped int64 `json:"skipped"` + Failed int64 `json:"failed"` + Bytes int64 `json:"bytes"` Errors []MirrorError `json:"errors,omitempty"` - StartedAt time.Time `json:"started_at"` - Phase string `json:"phase"` + StartedAt time.Time `json:"started_at"` + Phase string `json:"phase"` } // MirrorError records a single failed mirror attempt. @@ -212,9 +212,7 @@ func (m *Mirror) mirrorOne(ctx context.Context, pv PackageVersion, tracker *prog return } - if result.Reader != nil { - _ = result.Reader.Close() - } + _ = result.Reader.Close() if result.Cached { tracker.skipped.Add(1) @@ -222,9 +220,9 @@ func (m *Mirror) mirrorOne(ctx context.Context, pv PackageVersion, tracker *prog "ecosystem", pv.Ecosystem, "name", pv.Name, "version", pv.Version) } else { tracker.completed.Add(1) - tracker.bytes.Add(result.Artifact.Size) + tracker.bytes.Add(result.Size) m.logger.Info("mirrored", "ecosystem", pv.Ecosystem, "name", pv.Name, "version", pv.Version, - "size", result.Artifact.Size) + "size", result.Size) } } diff --git a/internal/mirror/mirror_test.go b/internal/mirror/mirror_test.go index 3a6420f..1d7d30d 100644 --- a/internal/mirror/mirror_test.go +++ b/internal/mirror/mirror_test.go @@ -2,11 +2,8 @@ package mirror import ( "context" - "crypto/sha256" - "database/sql" "log/slog" "os" - "strings" "testing" "time" @@ -46,14 +43,6 @@ func setupTestMirror(t *testing.T, workers int) *Mirror { const testPackageLodash = "lodash" -type signedURLStorage struct { - storage.Storage -} - -func (signedURLStorage) SignedURL(context.Context, string, time.Duration) (string, error) { - return "https://storage.example/artifact", nil -} - func TestMirrorRunEmptySource(t *testing.T) { m := setupTestMirror(t, 2) @@ -122,54 +111,6 @@ func TestMirrorRunCanceled(t *testing.T) { } } -func TestMirrorOneDirectServeCacheHit(t *testing.T) { - m := setupTestMirror(t, 1) - m.proxy.DirectServe = true - m.proxy.Storage = signedURLStorage{Storage: m.storage} - - packagePURL := "pkg:npm/example" - versionPURL := packagePURL + "@1.0.0" - if err := m.db.UpsertPackage(&database.Package{ - PURL: packagePURL, - Ecosystem: "npm", - Name: "example", - }); err != nil { - t.Fatalf("UpsertPackage() error = %v", err) - } - if err := m.db.UpsertVersion(&database.Version{ - PURL: versionPURL, - PackagePURL: packagePURL, - }); err != nil { - t.Fatalf("UpsertVersion() error = %v", err) - } - if err := m.db.UpsertArtifact(&database.Artifact{ - VersionPURL: versionPURL, - Filename: "", - UpstreamURL: "https://registry.example/artifact", - StoragePath: sql.NullString{String: "npm/example/1.0.0/artifact", Valid: true}, - ContentHash: sql.NullString{String: strings.Repeat("a", sha256.Size*2), Valid: true}, - Size: sql.NullInt64{Int64: 1, Valid: true}, - FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, - }); err != nil { - t.Fatalf("UpsertArtifact() error = %v", err) - } - - tracker := newProgressTracker() - m.mirrorOne(context.Background(), PackageVersion{ - Ecosystem: "npm", - Name: "example", - Version: "1.0.0", - }, tracker) - - progress := tracker.snapshot() - if progress.Skipped != 1 { - t.Errorf("skipped = %d, want 1", progress.Skipped) - } - if progress.Failed != 0 { - t.Errorf("failed = %d, want 0", progress.Failed) - } -} - func TestProgressTrackerSnapshot(t *testing.T) { pt := newProgressTracker() pt.total.Store(10) diff --git a/internal/mirror/registry.go b/internal/mirror/registry.go new file mode 100644 index 0000000..6b2c449 --- /dev/null +++ b/internal/mirror/registry.go @@ -0,0 +1,16 @@ +package mirror + +import ( + "context" + "fmt" +) + +// RegistrySource enumerates all packages in a registry for full mirroring. +// Registry enumeration is not yet implemented for any ecosystem. +type RegistrySource struct { + Ecosystem string +} + +func (s *RegistrySource) Enumerate(_ context.Context, _ func(PackageVersion) error) error { + return fmt.Errorf("registry enumeration is not yet implemented for ecosystem %q", s.Ecosystem) +} diff --git a/internal/mirror/registry_test.go b/internal/mirror/registry_test.go new file mode 100644 index 0000000..363bfea --- /dev/null +++ b/internal/mirror/registry_test.go @@ -0,0 +1,46 @@ +package mirror + +import ( + "context" + "testing" +) + +func TestRegistrySourceUnsupported(t *testing.T) { + source := &RegistrySource{Ecosystem: "golang"} + err := source.Enumerate(context.Background(), func(pv PackageVersion) error { + return nil + }) + if err == nil { + t.Fatal("expected error for unsupported ecosystem") + } +} + +func TestRegistrySourceNPMNotImplemented(t *testing.T) { + source := &RegistrySource{Ecosystem: "npm"} + err := source.Enumerate(context.Background(), func(pv PackageVersion) error { + return nil + }) + if err == nil { + t.Fatal("expected not-implemented error") + } +} + +func TestRegistrySourcePyPINotImplemented(t *testing.T) { + source := &RegistrySource{Ecosystem: "pypi"} + err := source.Enumerate(context.Background(), func(pv PackageVersion) error { + return nil + }) + if err == nil { + t.Fatal("expected not-implemented error") + } +} + +func TestRegistrySourceCargoNotImplemented(t *testing.T) { + source := &RegistrySource{Ecosystem: "cargo"} + err := source.Enumerate(context.Background(), func(pv PackageVersion) error { + return nil + }) + if err == nil { + t.Fatal("expected not-implemented error") + } +} diff --git a/internal/mirror/source.go b/internal/mirror/source.go index 4269264..a6fa364 100644 --- a/internal/mirror/source.go +++ b/internal/mirror/source.go @@ -5,13 +5,14 @@ import ( "context" "encoding/json" "fmt" + "os" cdx "github.com/CycloneDX/cyclonedx-go" "github.com/git-pkgs/purl" "github.com/git-pkgs/registries" _ "github.com/git-pkgs/registries/all" - spdxjson "github.com/spdx/tools-golang/json" "github.com/spdx/tools-golang/spdx" + spdxjson "github.com/spdx/tools-golang/json" spdxtv "github.com/spdx/tools-golang/tagvalue" ) @@ -93,20 +94,16 @@ func (s *PURLSource) fetchVersions(ctx context.Context, client *registries.Clien return result, nil } -// SBOMSource extracts package versions from CycloneDX or SPDX SBOM data. +// SBOMSource extracts package versions from a CycloneDX or SPDX SBOM file. type SBOMSource struct { - Data []byte - Name string + Path string RegClient *registries.Client } func (s *SBOMSource) Enumerate(ctx context.Context, fn func(PackageVersion) error) error { purls, err := s.extractPURLs() if err != nil { - if s.Name != "" { - return fmt.Errorf("parsing SBOM %s: %w", s.Name, err) - } - return fmt.Errorf("parsing SBOM: %w", err) + return fmt.Errorf("reading SBOM %s: %w", s.Path, err) } inner := &PURLSource{PURLs: purls, RegClient: s.RegClient} @@ -114,18 +111,23 @@ func (s *SBOMSource) Enumerate(ctx context.Context, fn func(PackageVersion) erro } func (s *SBOMSource) extractPURLs() ([]string, error) { + data, err := os.ReadFile(s.Path) + if err != nil { + return nil, err + } + // Try CycloneDX first - if purls, err := extractCycloneDXPURLs(s.Data); err == nil && len(purls) > 0 { + if purls, err := extractCycloneDXPURLs(data); err == nil && len(purls) > 0 { return purls, nil } // Try SPDX JSON - if purls, err := extractSPDXJSONPURLs(s.Data); err == nil && len(purls) > 0 { + if purls, err := extractSPDXJSONPURLs(data); err == nil && len(purls) > 0 { return purls, nil } // Try SPDX tag-value - if purls, err := extractSPDXTVPURLs(s.Data); err == nil && len(purls) > 0 { + if purls, err := extractSPDXTVPURLs(data); err == nil && len(purls) > 0 { return purls, nil } diff --git a/internal/mirror/source_test.go b/internal/mirror/source_test.go index fe56ca4..ce53acf 100644 --- a/internal/mirror/source_test.go +++ b/internal/mirror/source_test.go @@ -3,7 +3,8 @@ package mirror import ( "context" "encoding/json" - "strings" + "os" + "path/filepath" "testing" ) @@ -115,7 +116,8 @@ func TestSBOMSourceCycloneDXJSON(t *testing.T) { }, } - source := &SBOMSource{Data: marshalJSON(t, bom)} + path := writeTempJSON(t, bom) + source := &SBOMSource{Path: path} var items []PackageVersion err := source.Enumerate(context.Background(), func(pv PackageVersion) error { @@ -147,9 +149,9 @@ func TestSBOMSourceSPDXJSON(t *testing.T) { "documentNamespace": "https://example.com/test", "packages": []map[string]any{ { - "SPDXID": "SPDXRef-Package", - "name": "lodash", - "version": "4.17.21", + "SPDXID": "SPDXRef-Package", + "name": "lodash", + "version": "4.17.21", "downloadLocation": "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz", "externalRefs": []map[string]any{ { @@ -162,7 +164,8 @@ func TestSBOMSourceSPDXJSON(t *testing.T) { }, } - source := &SBOMSource{Data: marshalJSON(t, doc)} + path := writeTempJSON(t, doc) + source := &SBOMSource{Path: path} var items []PackageVersion err := source.Enumerate(context.Background(), func(pv PackageVersion) error { @@ -182,28 +185,30 @@ func TestSBOMSourceSPDXJSON(t *testing.T) { } } -func TestSBOMSourceEmptyData(t *testing.T) { - source := &SBOMSource{} +func TestSBOMSourceNonexistentFile(t *testing.T) { + source := &SBOMSource{Path: "/nonexistent/sbom.json"} err := source.Enumerate(context.Background(), func(pv PackageVersion) error { return nil }) if err == nil { - t.Fatal("expected error for empty SBOM") + t.Fatal("expected error for nonexistent file") } } func TestSBOMSourceInvalidFormat(t *testing.T) { - source := &SBOMSource{Data: []byte("this is not an SBOM"), Name: "invalid.sbom"} + path := filepath.Join(t.TempDir(), "invalid.txt") + if err := os.WriteFile(path, []byte("this is not an SBOM"), 0644); err != nil { + t.Fatal(err) + } + + source := &SBOMSource{Path: path} err := source.Enumerate(context.Background(), func(pv PackageVersion) error { return nil }) if err == nil { t.Fatal("expected error for invalid SBOM") } - if !strings.Contains(err.Error(), "invalid.sbom") { - t.Errorf("error = %q, want source name", err) - } } func TestSBOMSourceEmptyCycloneDX(t *testing.T) { @@ -211,9 +216,11 @@ func TestSBOMSourceEmptyCycloneDX(t *testing.T) { "bomFormat": "CycloneDX", "specVersion": "1.4", } + path := writeTempJSON(t, bom) + // This should fall through to SPDX parsing, which will also fail, // resulting in an error about not being able to parse - source := &SBOMSource{Data: marshalJSON(t, bom)} + source := &SBOMSource{Path: path} err := source.Enumerate(context.Background(), func(pv PackageVersion) error { return nil }) @@ -222,11 +229,15 @@ func TestSBOMSourceEmptyCycloneDX(t *testing.T) { } } -func marshalJSON(t *testing.T, v any) []byte { +func writeTempJSON(t *testing.T, v any) string { t.Helper() data, err := json.Marshal(v) if err != nil { t.Fatal(err) } - return data + path := filepath.Join(t.TempDir(), "sbom.json") + if err := os.WriteFile(path, data, 0644); err != nil { + t.Fatal(err) + } + return path } diff --git a/internal/packageurl/packageurl.go b/internal/packageurl/packageurl.go deleted file mode 100644 index 7110942..0000000 --- a/internal/packageurl/packageurl.go +++ /dev/null @@ -1,62 +0,0 @@ -// Package packageurl builds package URLs from ecosystem-native package names. -package packageurl - -import ( - "strings" - - "github.com/git-pkgs/purl" -) - -// Make constructs a package URL from an ecosystem-native package name. -func Make(ecosystem, name, version string) *purl.PURL { - return purl.MakePURL(ecosystem, name, version) -} - -// MakeString constructs a package URL string. It returns an empty string when -// the package identity cannot be represented as a PURL. -func MakeString(ecosystem, name, version string) string { - return purl.MakePURLString(ecosystem, name, version) -} - -// WithVersionString returns a package PURL with its version replaced. It -// returns an empty string when packagePURL is invalid. -func WithVersionString(packagePURL, version string) string { - pkg, err := purl.Parse(packagePURL) - if err != nil { - return "" - } - return pkg.WithVersion(version).String() -} - -// MakeCacheStrings returns package and version PURLs suitable for artifact -// cache records. Swift registry identities use an explicit generic PURL until -// their source repository has been resolved. The result is independent of the -// configured upstream so cache entries survive an upstream.swift change, -// matching every other ecosystem. -func MakeCacheStrings(ecosystem, name, version string) (packagePURL, versionPURL string) { - if pkg := Make(ecosystem, name, ""); pkg != nil { - return pkg.String(), pkg.WithVersion(version).String() - } - if purl.NormalizeEcosystem(ecosystem) != "swift" { - return "", "" - } - - identity, ok := swiftRegistryIdentity(name) - if !ok { - return "", "" - } - - pkg := purl.New("generic", "swift-registry", identity, "", nil) - return pkg.String(), pkg.WithVersion(version).String() -} - -func swiftRegistryIdentity(name string) (string, bool) { - scope, packageName, found := strings.Cut(name, "/") - if !found { - scope, packageName, found = strings.Cut(name, ".") - } - if !found || scope == "" || packageName == "" || strings.ContainsAny(packageName, "/.") { - return "", false - } - return strings.ToLower(scope) + "." + strings.ToLower(packageName), true -} diff --git a/internal/packageurl/packageurl_test.go b/internal/packageurl/packageurl_test.go deleted file mode 100644 index 8982288..0000000 --- a/internal/packageurl/packageurl_test.go +++ /dev/null @@ -1,75 +0,0 @@ -package packageurl - -import "testing" - -func TestMakeSwiftRegistryIdentityUnsupported(t *testing.T) { - identities := []string{"apple.swift-argument-parser", "apple/swift-argument-parser"} - for _, identity := range identities { - t.Run(identity, func(t *testing.T) { - if got := Make("swift", identity, "1.8.2"); got != nil { - t.Errorf("Make() = %q, want nil", got.String()) - } - if got := MakeString("swift", identity, "1.8.2"); got != "" { - t.Errorf("MakeString() = %q, want empty string", got) - } - }) - } -} - -func TestMakeStringSwiftSourceCoordinate(t *testing.T) { - got := MakeString("swift", "github.com/apple/swift-package-manager", "1.7.0") - want := "pkg:swift/github.com/apple/swift-package-manager@1.7.0" - if got != want { - t.Errorf("MakeString() = %q, want %q", got, want) - } -} - -func TestWithVersionStringPreservesQualifiers(t *testing.T) { - packagePURL := "pkg:generic/swift-registry/apple.example?repository_url=https:%2F%2Fold.example%2Fswift" - got := WithVersionString(packagePURL, "1.2.3") - want := "pkg:generic/swift-registry/apple.example@1.2.3?repository_url=https:%2F%2Fold.example%2Fswift" - if got != want { - t.Errorf("WithVersionString() = %q, want %q", got, want) - } - - if got := WithVersionString("not a purl", "1.2.3"); got != "" { - t.Errorf("WithVersionString() = %q for invalid PURL, want empty string", got) - } -} - -func TestMakeCacheStringsSwiftRegistryIdentity(t *testing.T) { - packagePURL, versionPURL := MakeCacheStrings("swift", "APPLE/EXAMPLE", "1.2.3") - - wantPackage := "pkg:generic/swift-registry/apple.example" - if packagePURL != wantPackage { - t.Errorf("package PURL = %q, want %q", packagePURL, wantPackage) - } - wantVersion := "pkg:generic/swift-registry/apple.example@1.2.3" - if versionPURL != wantVersion { - t.Errorf("version PURL = %q, want %q", versionPURL, wantVersion) - } - - dottedPackage, dottedVersion := MakeCacheStrings("swift", "apple.example", "1.2.3") - if dottedPackage != packagePURL || dottedVersion != versionPURL { - t.Errorf("dotted identity cache PURLs = %q, %q; want %q, %q", dottedPackage, dottedVersion, packagePURL, versionPURL) - } -} - -func TestMakeCacheStringsUsesSourcePURLWhenAvailable(t *testing.T) { - packagePURL, versionPURL := MakeCacheStrings("swift", "github.com/apple/swift-package-manager", "1.7.0") - - if packagePURL != "pkg:swift/github.com/apple/swift-package-manager" { - t.Errorf("package PURL = %q", packagePURL) - } - if versionPURL != "pkg:swift/github.com/apple/swift-package-manager@1.7.0" { - t.Errorf("version PURL = %q", versionPURL) - } -} - -func TestMakeStringDelegatesOtherEcosystems(t *testing.T) { - got := MakeString("npm", "@babel/core", "7.23.0") - want := "pkg:npm/%40babel/core@7.23.0" - if got != want { - t.Errorf("MakeString() = %q, want %q", got, want) - } -} diff --git a/internal/scanner/group.go b/internal/scanner/group.go deleted file mode 100644 index ed0be57..0000000 --- a/internal/scanner/group.go +++ /dev/null @@ -1,226 +0,0 @@ -package scanner - -import ( - "context" - "errors" - "fmt" - "log/slog" - "net/http" - "sync" - "time" - - "github.com/git-pkgs/proxy/internal/config" - "github.com/git-pkgs/proxy/internal/metrics" -) - -const ( - modeBlock = "block" - modeMonitor = "monitor" - - defaultTimeout = 30 * time.Second -) - -type entry struct { - scanner Scanner - mode string - ecosystems map[string]struct{} // nil/empty means all ecosystems -} - -// Group runs a set of configured Scanners concurrently and turns their -// individual verdicts into a single decision. -type Group struct { - entries []entry - timeout time.Duration - failOpen bool - logger *slog.Logger -} - -// NewGroup builds a Group from cfg. If cfg.Enabled is false, the returned -// Group has no entries and Enabled() reports false, so callers can skip -// the scan path entirely. -func NewGroup(cfg config.ScanningConfig, logger *slog.Logger) (*Group, error) { - g := &Group{ - timeout: defaultTimeout, - failOpen: cfg.FailOpen, - logger: logger, - } - if !cfg.Enabled { - return g, nil - } - if cfg.SigningKeyExpanded() == "" { - return nil, fmt.Errorf("scanning.signing_key is required when scanning.enabled is true") - } - if d, err := time.ParseDuration(cfg.Timeout); err == nil && d > 0 { - g.timeout = d - } - - for _, sc := range cfg.Scanners { - mode := sc.Mode - if mode == "" { - mode = modeBlock - } - if mode != modeBlock && mode != modeMonitor { - return nil, fmt.Errorf("scanner %q: invalid mode %q (must be %q or %q)", sc.Name, mode, modeBlock, modeMonitor) - } - - var ecosystems map[string]struct{} - if len(sc.Ecosystems) > 0 { - ecosystems = make(map[string]struct{}, len(sc.Ecosystems)) - for _, eco := range sc.Ecosystems { - ecosystems[eco] = struct{}{} - } - } - - g.entries = append(g.entries, entry{ - scanner: NewHTTPScanner(sc.Name, sc.URL, sc.HeadersExpanded(), http.DefaultClient), - mode: mode, - ecosystems: ecosystems, - }) - } - - return g, nil -} - -// Enabled reports whether any scanner is configured. -func (g *Group) Enabled() bool { - return g != nil && len(g.entries) > 0 -} - -// Timeout returns the per-scan-call timeout used to bound the signed fetch -// URL's validity. -func (g *Group) Timeout() time.Duration { - return g.timeout -} - -func (g *Group) applicable(ecosystem string) []entry { - var out []entry - for _, e := range g.entries { - if len(e.ecosystems) == 0 { - out = append(out, e) - continue - } - if _, ok := e.ecosystems[ecosystem]; ok { - out = append(out, e) - } - } - return out -} - -// Scan runs every scanner applicable to req.Ecosystem concurrently, never -// sequentially, and returns a single decision. -// -// The moment any "block" mode scanner reports Allowed: false (or errors, -// unless FailOpen is set), Scan cancels a context shared by every -// goroutine: in-flight calls to the other scanners are aborted rather than -// waited out, since a single block already decides the outcome. Scan still -// waits for all goroutines to observe that cancellation and return before -// it itself returns, so no scan call outlives this method call. -// -// If nothing blocks, Scan waits for every "block" mode scanner to finish -// before reporting Allowed: true — an allow decision can't be finalized -// until all of them have answered. "monitor" mode scanners never gate the -// wait or trigger cancellation: a monitor verdict of Allowed: false is -// logged and folded into Result.Findings, but never blocks. -func (g *Group) Scan(ctx context.Context, req Request) Result { - entries := g.applicable(req.Ecosystem) - if len(entries) == 0 { - return Result{Allowed: true} - } - - scanCtx, cancel := context.WithTimeout(ctx, g.timeout) - defer cancel() - - var ( - mu sync.Mutex - findings []Finding - blocked *Result - ) - - var wg sync.WaitGroup - for _, e := range entries { - wg.Add(1) - go func(e entry) { - defer wg.Done() - entryFindings, entryBlock := g.evaluate(scanCtx, req, e) - - mu.Lock() - findings = append(findings, entryFindings...) - if entryBlock != nil && blocked == nil { - blocked = entryBlock - cancel() - } - mu.Unlock() - }(e) - } - - wg.Wait() - - if blocked != nil { - blocked.Findings = findings - return *blocked - } - - return Result{Allowed: true, Findings: findings} -} - -// evaluate runs a single scanner and reports its findings plus, if this -// scanner's verdict should block the artifact, the Result to block with -// (nil otherwise). It never sets Result.Findings on a returned block -// Result — the caller assembles Findings from every entry once all of them -// have finished. -func (g *Group) evaluate(scanCtx context.Context, req Request, e entry) (findings []Finding, block *Result) { - start := time.Now() - res, err := e.scanner.Scan(scanCtx, req) - duration := time.Since(start) - - if err != nil { - errType := "error" - switch { - case errors.Is(scanCtx.Err(), context.DeadlineExceeded): - errType = "timeout" - case errors.Is(scanCtx.Err(), context.Canceled): - // scanCtx was cancelled because another scanner in the group - // already decided the verdict, not because this call itself - // timed out or failed on its own. - errType = "cancelled" - } - metrics.RecordScanError(req.Ecosystem, e.scanner.Name(), errType) - - if errType == "cancelled" { - // Another scanner already decided the verdict and cancelled - // scanCtx; this call didn't fail on its own, so don't log it - // as if it did. - return nil, nil - } - - if e.mode == modeMonitor || g.failOpen { - g.logger.Warn("scanner call failed, treating as allowed", - "scanner", e.scanner.Name(), "mode", e.mode, "error", err) - return nil, nil - } - - g.logger.Warn("scanner call failed, blocking artifact", - "scanner", e.scanner.Name(), "mode", e.mode, "error", err) - return nil, &Result{ - Allowed: false, - Reason: fmt.Sprintf("scanner %q failed: %v", e.scanner.Name(), err), - ScannerName: e.scanner.Name(), - InfraError: true, - } - } - - metrics.RecordScanResult(req.Ecosystem, e.scanner.Name(), res.Allowed, duration) - - if e.mode == modeMonitor { - if !res.Allowed { - g.logger.Warn("monitor scanner flagged artifact", - "scanner", e.scanner.Name(), "reason", res.Reason) - } - return res.Findings, nil - } - - if !res.Allowed { - return res.Findings, &Result{Allowed: false, Reason: res.Reason, ScannerName: e.scanner.Name()} - } - return res.Findings, nil -} diff --git a/internal/scanner/group_test.go b/internal/scanner/group_test.go deleted file mode 100644 index e5b40ee..0000000 --- a/internal/scanner/group_test.go +++ /dev/null @@ -1,245 +0,0 @@ -package scanner - -import ( - "context" - "errors" - "io" - "log/slog" - "strings" - "testing" - "time" - - "github.com/git-pkgs/proxy/internal/config" - "github.com/git-pkgs/proxy/internal/metrics" - "github.com/prometheus/client_golang/prometheus/testutil" -) - -func discardLogger() *slog.Logger { - return slog.New(slog.NewTextHandler(io.Discard, nil)) -} - -// fakeScanner is a Scanner test double that can simulate a delay, a fixed -// result or error, and report whether its context was cancelled before it -// returned. -type fakeScanner struct { - name string - delay time.Duration - result Result - err error - cancelled *bool -} - -func (f *fakeScanner) Name() string { return f.name } - -func (f *fakeScanner) Scan(ctx context.Context, _ Request) (Result, error) { - select { - case <-time.After(f.delay): - case <-ctx.Done(): - if f.cancelled != nil { - *f.cancelled = true - } - return Result{}, ctx.Err() - } - return f.result, f.err -} - -func newTestGroup(entries []entry, failOpen bool) *Group { - return &Group{ - entries: entries, - timeout: time.Second, - failOpen: failOpen, - logger: discardLogger(), - } -} - -func TestGroup_Enabled(t *testing.T) { - disabled, err := NewGroup(config.ScanningConfig{Enabled: false}, discardLogger()) - if err != nil { - t.Fatalf("NewGroup() error: %v", err) - } - if disabled.Enabled() { - t.Error("Enabled() = true for disabled config, want false") - } - - enabled, err := NewGroup(config.ScanningConfig{ - Enabled: true, - Timeout: "10s", - SigningKey: "test-signing-key", - Scanners: []config.ScannerConfig{ - {Name: "clamav", URL: "http://clamav.invalid", Mode: "block"}, - }, - }, discardLogger()) - if err != nil { - t.Fatalf("NewGroup() error: %v", err) - } - if !enabled.Enabled() { - t.Error("Enabled() = false for configured scanner, want true") - } -} - -func TestGroup_NewGroup_InvalidMode(t *testing.T) { - _, err := NewGroup(config.ScanningConfig{ - Enabled: true, - SigningKey: "test-signing-key", - Scanners: []config.ScannerConfig{ - {Name: "bad", URL: "http://bad.invalid", Mode: "quarantine"}, - }, - }, discardLogger()) - if err == nil { - t.Fatal("NewGroup() error = nil, want error for invalid mode") - } -} - -func TestGroup_NewGroup_MissingSigningKey(t *testing.T) { - _, err := NewGroup(config.ScanningConfig{ - Enabled: true, - Scanners: []config.ScannerConfig{ - {Name: "clamav", URL: "http://clamav.invalid", Mode: "block"}, - }, - }, discardLogger()) - if err == nil { - t.Fatal("NewGroup() error = nil, want error for missing signing key") - } -} - -func TestGroup_Scan_NoApplicableScanners(t *testing.T) { - g := newTestGroup([]entry{ - { - scanner: &fakeScanner{name: "npm-only", result: Result{Allowed: false}}, - mode: modeBlock, - ecosystems: map[string]struct{}{"npm": {}}, - }, - }, false) - - result := g.Scan(context.Background(), Request{Ecosystem: "pypi"}) - if !result.Allowed { - t.Error("Allowed = false, want true when no scanner applies to the ecosystem") - } -} - -func TestGroup_Scan_Allowed(t *testing.T) { - g := newTestGroup([]entry{ - {scanner: &fakeScanner{name: "clamav", result: Result{Allowed: true}}, mode: modeBlock}, - }, false) - - result := g.Scan(context.Background(), Request{Ecosystem: "npm"}) - if !result.Allowed { - t.Error("Allowed = false, want true") - } -} - -func TestGroup_Scan_Blocked(t *testing.T) { - g := newTestGroup([]entry{ - {scanner: &fakeScanner{name: "clamav", result: Result{Allowed: false, Reason: "malware"}}, mode: modeBlock}, - }, false) - - result := g.Scan(context.Background(), Request{Ecosystem: "npm"}) - if result.Allowed { - t.Error("Allowed = true, want false") - } - if result.Reason != "malware" { - t.Errorf("Reason = %q, want %q", result.Reason, "malware") - } - if result.ScannerName != "clamav" { - t.Errorf("ScannerName = %q, want %q", result.ScannerName, "clamav") - } - if result.InfraError { - t.Error("InfraError = true, want false — this is a genuine scanner verdict, not an infrastructure failure") - } -} - -func TestGroup_Scan_MonitorNeverBlocks(t *testing.T) { - g := newTestGroup([]entry{ - { - scanner: &fakeScanner{name: "trivy", result: Result{ - Allowed: false, - Reason: "cve found", - Findings: []Finding{{Severity: "medium", Title: "CVE-1234"}}, - }}, - mode: modeMonitor, - }, - }, false) - - result := g.Scan(context.Background(), Request{Ecosystem: "npm"}) - if !result.Allowed { - t.Error("Allowed = false, want true — monitor mode must never block") - } - if len(result.Findings) != 1 || result.Findings[0].Title != "CVE-1234" { - t.Errorf("Findings = %+v, want the monitor scanner's finding folded in", result.Findings) - } -} - -func TestGroup_Scan_FirstBlockCancelsOthers(t *testing.T) { - var slowSawCancel bool - g := newTestGroup([]entry{ - {scanner: &fakeScanner{name: "fast-block", result: Result{Allowed: false, Reason: "blocked"}}, mode: modeBlock}, - {scanner: &fakeScanner{name: "slow", delay: 2 * time.Second, cancelled: &slowSawCancel}, mode: modeBlock}, - }, false) - - start := time.Now() - result := g.Scan(context.Background(), Request{Ecosystem: "npm"}) - elapsed := time.Since(start) - - if result.Allowed { - t.Error("Allowed = true, want false") - } - if elapsed >= 2*time.Second { - t.Errorf("Scan() took %v, want it to return promptly once the slow scanner's context was cancelled", elapsed) - } - if !slowSawCancel { - t.Error("slow scanner never observed context cancellation") - } - - if got := testutil.ToFloat64(metrics.ScanErrors.WithLabelValues("npm", "slow", "cancelled")); got != 1 { - t.Errorf("scan_errors{error_type=cancelled} = %v, want 1 — the slow scanner was aborted by a sibling's block, not by its own timeout", got) - } - if got := testutil.ToFloat64(metrics.ScanErrors.WithLabelValues("npm", "slow", "timeout")); got != 0 { - t.Errorf("scan_errors{error_type=timeout} = %v, want 0 — intra-group cancellation must not be mislabelled as a timeout", got) - } -} - -func TestGroup_Scan_WaitsForAllBlockScannersBeforeAllowing(t *testing.T) { - g := newTestGroup([]entry{ - {scanner: &fakeScanner{name: "fast", result: Result{Allowed: true}}, mode: modeBlock}, - {scanner: &fakeScanner{name: "slow", delay: 30 * time.Millisecond, result: Result{Allowed: true}}, mode: modeBlock}, - }, false) - - start := time.Now() - result := g.Scan(context.Background(), Request{Ecosystem: "npm"}) - elapsed := time.Since(start) - - if !result.Allowed { - t.Error("Allowed = false, want true") - } - if elapsed < 30*time.Millisecond { - t.Errorf("Scan() returned after %v, want it to wait for the slower block scanner", elapsed) - } -} - -func TestGroup_Scan_ErrorFailClosedByDefault(t *testing.T) { - g := newTestGroup([]entry{ - {scanner: &fakeScanner{name: "flaky", err: errors.New("connection refused")}, mode: modeBlock}, - }, false) - - result := g.Scan(context.Background(), Request{Ecosystem: "npm"}) - if result.Allowed { - t.Error("Allowed = true, want false — default posture is fail-closed on scanner error") - } - if !result.InfraError { - t.Error("InfraError = false, want true — the block came from a scanner call failure, not a verdict") - } - if !strings.Contains(result.Reason, "connection refused") { - t.Errorf("Reason = %q, want it to include the underlying error for server-side logging", result.Reason) - } -} - -func TestGroup_Scan_ErrorFailOpen(t *testing.T) { - g := newTestGroup([]entry{ - {scanner: &fakeScanner{name: "flaky", err: errors.New("connection refused")}, mode: modeBlock}, - }, true) - - result := g.Scan(context.Background(), Request{Ecosystem: "npm"}) - if !result.Allowed { - t.Error("Allowed = false, want true — FailOpen must treat scanner errors as allowed") - } -} diff --git a/internal/scanner/http.go b/internal/scanner/http.go deleted file mode 100644 index 90a4e5e..0000000 --- a/internal/scanner/http.go +++ /dev/null @@ -1,97 +0,0 @@ -package scanner - -import ( - "bytes" - "context" - "encoding/json" - "fmt" - "net/http" -) - -// HTTPScanner adapts an external HTTP scanning service to the Scanner -// interface. It POSTs a small JSON notification describing the staged -// artifact, including a signed fetch URL; the external service is -// responsible for GETting that URL itself, running the real scan against -// those bytes, and replying with a verdict before the request's deadline. -// -// Request body: -// -// { -// "ecosystem": "npm", "name": "left-pad", "version": "1.0.0", -// "filename": "left-pad-1.0.0.tgz", "purl": "pkg:npm/left-pad@1.0.0", -// "content_type": "application/octet-stream", "size": 1234, -// "fetch_url": "https://proxy.internal/_internal/scan-fetch?..." -// } -// -// Response body: -// -// { -// "allowed": true, "reason": "", -// "findings": [{"severity": "high", "title": "...", "description": "..."}] -// } -// -// Any compliant adapter — a trivy wrapper, a clamav-rest bridge, a Wiz -// connector, or an in-house service — need only implement this contract. -type HTTPScanner struct { - name string - url string - headers map[string]string - client *http.Client -} - -// NewHTTPScanner creates an HTTPScanner named name that notifies url of -// staged artifacts, attaching headers to every request (e.g. for auth). -// If client is nil, http.DefaultClient is used. -func NewHTTPScanner(name, url string, headers map[string]string, client *http.Client) *HTTPScanner { - if client == nil { - client = http.DefaultClient - } - return &HTTPScanner{name: name, url: url, headers: headers, client: client} -} - -// Name returns the scanner's configured name. -func (s *HTTPScanner) Name() string { return s.name } - -type httpScanResponse struct { - Allowed bool `json:"allowed"` - Reason string `json:"reason"` - Findings []Finding `json:"findings"` -} - -// Scan notifies the configured URL of req and waits for a verdict. -func (s *HTTPScanner) Scan(ctx context.Context, req Request) (Result, error) { - body, err := json.Marshal(req) - if err != nil { - return Result{}, fmt.Errorf("marshal scan request: %w", err) - } - - httpReq, err := http.NewRequestWithContext(ctx, http.MethodPost, s.url, bytes.NewReader(body)) - if err != nil { - return Result{}, fmt.Errorf("build scan request: %w", err) - } - httpReq.Header.Set("Content-Type", "application/json") - for k, v := range s.headers { - httpReq.Header.Set(k, v) - } - - resp, err := s.client.Do(httpReq) - if err != nil { - return Result{}, fmt.Errorf("calling scanner %q: %w", s.name, err) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusOK { - return Result{}, fmt.Errorf("scanner %q returned status %d", s.name, resp.StatusCode) - } - - var out httpScanResponse - if err := json.NewDecoder(resp.Body).Decode(&out); err != nil { - return Result{}, fmt.Errorf("decoding scanner %q response: %w", s.name, err) - } - - return Result{ - Allowed: out.Allowed, - Reason: out.Reason, - Findings: out.Findings, - }, nil -} diff --git a/internal/scanner/http_test.go b/internal/scanner/http_test.go deleted file mode 100644 index 7597826..0000000 --- a/internal/scanner/http_test.go +++ /dev/null @@ -1,119 +0,0 @@ -package scanner - -import ( - "context" - "encoding/json" - "net/http" - "net/http/httptest" - "testing" - "time" -) - -func TestHTTPScanner_Scan(t *testing.T) { - tests := []struct { - name string - respStatus int - respBody string - wantAllowed bool - wantReason string - wantErr bool - }{ - { - name: "allowed", - respStatus: http.StatusOK, - respBody: `{"allowed": true}`, - wantAllowed: true, - }, - { - name: "blocked with reason and findings", - respStatus: http.StatusOK, - respBody: `{"allowed": false, "reason": "malware detected", "findings": [{"severity": "high", "title": "EICAR", "description": "test signature"}]}`, - wantAllowed: false, - wantReason: "malware detected", - }, - { - name: "non-200 status is an error", - respStatus: http.StatusInternalServerError, - respBody: `{}`, - wantErr: true, - }, - { - name: "malformed JSON is an error", - respStatus: http.StatusOK, - respBody: `not json`, - wantErr: true, - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - var got Request - if err := json.NewDecoder(r.Body).Decode(&got); err != nil { - t.Errorf("decode request body: %v", err) - } - if got.Ecosystem != "npm" || got.Name != "left-pad" || got.FetchURL == "" { - t.Errorf("unexpected request body: %+v", got) - } - if r.Header.Get("Authorization") != "Bearer secret" { - t.Errorf("missing/incorrect Authorization header: %q", r.Header.Get("Authorization")) - } - - w.WriteHeader(tt.respStatus) - _, _ = w.Write([]byte(tt.respBody)) - })) - defer srv.Close() - - s := NewHTTPScanner("test", srv.URL, map[string]string{"Authorization": "Bearer secret"}, nil) - - result, err := s.Scan(context.Background(), Request{ - Ecosystem: "npm", - Name: "left-pad", - Version: "1.0.0", - FetchURL: srv.URL + "/fetch", - }) - - if tt.wantErr { - if err == nil { - t.Fatalf("Scan() error = nil, want error") - } - return - } - if err != nil { - t.Fatalf("Scan() unexpected error: %v", err) - } - if result.Allowed != tt.wantAllowed { - t.Errorf("Allowed = %v, want %v", result.Allowed, tt.wantAllowed) - } - if result.Reason != tt.wantReason { - t.Errorf("Reason = %q, want %q", result.Reason, tt.wantReason) - } - }) - } -} - -func TestHTTPScanner_Scan_ContextTimeout(t *testing.T) { - srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - time.Sleep(50 * time.Millisecond) - w.WriteHeader(http.StatusOK) - _, _ = w.Write([]byte(`{"allowed": true}`)) - })) - defer srv.Close() - - s := NewHTTPScanner("slow", srv.URL, nil, nil) - - ctx, cancel := context.WithTimeout(context.Background(), 5*time.Millisecond) - defer cancel() - - _, err := s.Scan(ctx, Request{Ecosystem: "npm", Name: "left-pad"}) - if err == nil { - t.Fatal("Scan() error = nil, want timeout error") - } -} - -func TestHTTPScanner_Name(t *testing.T) { - s := NewHTTPScanner("clamav", "http://example.invalid", nil, nil) - if got := s.Name(); got != "clamav" { - t.Errorf("Name() = %q, want %q", got, "clamav") - } -} diff --git a/internal/scanner/scanner.go b/internal/scanner/scanner.go deleted file mode 100644 index 380bb4d..0000000 --- a/internal/scanner/scanner.go +++ /dev/null @@ -1,65 +0,0 @@ -// Package scanner provides pluggable pre-cache artifact scanning. -// -// A Scanner inspects an artifact staged in the proxy's own storage before -// it becomes visible to clients, and returns a verdict on whether it may -// be cached. The proxy never uploads artifact bytes to a scanner directly: -// it hands the scanner a short-lived signed URL and the scanner pulls the -// bytes itself. See HTTPScanner for the built-in adapter that implements -// this over a small HTTP/JSON contract, letting trivy, ClamAV, Wiz, or any -// custom service integrate without the proxy needing built-in knowledge of -// any specific tool. -package scanner - -import "context" - -// Request describes a staged artifact awaiting a scan verdict. -type Request struct { - Ecosystem string `json:"ecosystem"` - Name string `json:"name"` - Version string `json:"version"` - Filename string `json:"filename"` - PURL string `json:"purl"` - ContentType string `json:"content_type"` - Size int64 `json:"size"` - - // FetchURL is a short-lived signed URL the scanner must GET itself to - // retrieve the exact bytes staged in the proxy's storage. - FetchURL string `json:"fetch_url"` -} - -// Finding describes a single issue reported by a scanner. -type Finding struct { - Severity string - Title string - Description string -} - -// Result is a scanner's verdict for a Request. -type Result struct { - Allowed bool - Reason string - Findings []Finding - - // ScannerName identifies which scanner produced this result. Set by - // Group, not by individual Scanner implementations. - ScannerName string - - // InfraError reports whether Allowed: false was forced by a scanner - // call failing (network error, timeout, bad response) rather than an - // actual verdict from the scanner. Set by Group. Callers that surface - // Reason to untrusted clients must not do so when this is true: it may - // contain raw connection errors (internal hostnames, ports) instead of - // a verdict meant to be shown outside the proxy. - InfraError bool -} - -// Scanner is the extension point for pluggable pre-cache scanning. -type Scanner interface { - // Name identifies this scanner in logs and metrics. - Name() string - - // Scan requests a verdict for req. Implementations must respect ctx - // cancellation: Group cancels in-flight scans once a blocking verdict - // has already been decided by another scanner. - Scan(ctx context.Context, req Request) (Result, error) -} diff --git a/internal/server/api.go b/internal/server/api.go index 992d736..e687f6d 100644 --- a/internal/server/api.go +++ b/internal/server/api.go @@ -139,14 +139,11 @@ type BulkResponse struct { // Resolves namespaced package names (Composer vendor/name, npm @scope/name) from the path. func (h *APIHandler) HandlePackagePath(w http.ResponseWriter, r *http.Request) { ecosystem := chi.URLParam(r, "ecosystem") - segments, err := packagePathSegments(r) - if err != nil { - badRequest(w, err.Error()) - return - } + wildcard := chi.URLParam(r, "*") + segments := splitWildcardPath(wildcard) if ecosystem == "" || len(segments) == 0 { - badRequest(w, "ecosystem and name are required") + http.Error(w, "ecosystem and name are required", http.StatusBadRequest) return } @@ -193,12 +190,12 @@ func (h *APIHandler) HandlePackagePath(w http.ResponseWriter, r *http.Request) { func (h *APIHandler) getPackage(w http.ResponseWriter, r *http.Request, ecosystem, name string) { info, err := h.enrichment.EnrichPackage(r.Context(), ecosystem, name) if err != nil { - writeError(w, http.StatusBadGateway, ErrCodeUpstream, "failed to enrich package") + http.Error(w, "failed to enrich package", http.StatusInternalServerError) return } if info == nil { - notFound(w, "package not found") + http.Error(w, "package not found", http.StatusNotFound) return } @@ -220,7 +217,7 @@ func (h *APIHandler) getPackage(w http.ResponseWriter, r *http.Request, ecosyste func (h *APIHandler) getVersion(w http.ResponseWriter, r *http.Request, ecosystem, name, version string) { result, err := h.enrichment.EnrichFull(r.Context(), ecosystem, name, version) if err != nil { - writeError(w, http.StatusBadGateway, ErrCodeUpstream, "failed to enrich version") + http.Error(w, "failed to enrich version", http.StatusInternalServerError) return } @@ -276,14 +273,11 @@ func (h *APIHandler) getVersion(w http.ResponseWriter, r *http.Request, ecosyste // Supports both {name} and {name}/{version} paths with namespaced package names. func (h *APIHandler) HandleVulnsPath(w http.ResponseWriter, r *http.Request) { ecosystem := chi.URLParam(r, "ecosystem") - segments, err := packagePathSegments(r) - if err != nil { - badRequest(w, err.Error()) - return - } + wildcard := chi.URLParam(r, "*") + segments := splitWildcardPath(wildcard) if ecosystem == "" || len(segments) == 0 { - badRequest(w, "ecosystem and name are required") + http.Error(w, "ecosystem and name are required", http.StatusBadRequest) return } @@ -304,7 +298,7 @@ func (h *APIHandler) HandleVulnsPath(w http.ResponseWriter, r *http.Request) { vulns, err := h.enrichment.CheckVulnerabilities(r.Context(), ecosystem, name, version) if err != nil { - writeError(w, http.StatusBadGateway, ErrCodeUpstream, "failed to check vulnerabilities") + http.Error(w, "failed to check vulnerabilities", http.StatusInternalServerError) return } @@ -336,19 +330,19 @@ func (h *APIHandler) HandleVulnsPath(w http.ResponseWriter, r *http.Request) { // @Produce json // @Param request body OutdatedRequest true "Packages to check" // @Success 200 {object} OutdatedResponse -// @Failure 400 {object} ErrorResponse -// @Failure 500 {object} ErrorResponse +// @Failure 400 {string} string +// @Failure 500 {string} string // @Router /api/outdated [post] func (h *APIHandler) HandleOutdated(w http.ResponseWriter, r *http.Request) { r.Body = http.MaxBytesReader(w, r.Body, maxBodySize) var req OutdatedRequest if err := json.NewDecoder(r.Body).Decode(&req); err != nil { - badRequest(w, "invalid request body") + http.Error(w, "invalid request body", http.StatusBadRequest) return } if len(req.Packages) == 0 { - badRequest(w, "packages list is required") + http.Error(w, "packages list is required", http.StatusBadRequest) return } @@ -382,19 +376,19 @@ func (h *APIHandler) HandleOutdated(w http.ResponseWriter, r *http.Request) { // @Produce json // @Param request body BulkRequest true "PURLs" // @Success 200 {object} BulkResponse -// @Failure 400 {object} ErrorResponse -// @Failure 500 {object} ErrorResponse +// @Failure 400 {string} string +// @Failure 500 {string} string // @Router /api/bulk [post] func (h *APIHandler) HandleBulkLookup(w http.ResponseWriter, r *http.Request) { r.Body = http.MaxBytesReader(w, r.Body, maxBodySize) var req BulkRequest if err := json.NewDecoder(r.Body).Decode(&req); err != nil { - badRequest(w, "invalid request body") + http.Error(w, "invalid request body", http.StatusBadRequest) return } if len(req.PURLs) == 0 { - badRequest(w, "purls list is required") + http.Error(w, "purls list is required", http.StatusBadRequest) return } @@ -482,15 +476,15 @@ type SearchPackageResult struct { // @Param q query string true "Query" // @Param ecosystem query string false "Ecosystem" // @Success 200 {object} SearchResponse -// @Failure 400 {object} ErrorResponse -// @Failure 500 {object} ErrorResponse +// @Failure 400 {string} string +// @Failure 500 {string} string // @Router /api/search [get] func (h *APIHandler) HandleSearch(w http.ResponseWriter, r *http.Request) { query := r.URL.Query().Get("q") ecosystem := r.URL.Query().Get("ecosystem") if query == "" { - badRequest(w, "query parameter 'q' is required") + http.Error(w, "query parameter 'q' is required", http.StatusBadRequest) return } @@ -500,7 +494,7 @@ func (h *APIHandler) HandleSearch(w http.ResponseWriter, r *http.Request) { // Search in database results, err := h.db.SearchPackages(query, ecosystem, limit, (page-1)*limit) if err != nil { - internalError(w, "search failed") + http.Error(w, "search failed", http.StatusInternalServerError) return } @@ -544,7 +538,7 @@ func (h *APIHandler) HandleSearch(w http.ResponseWriter, r *http.Request) { func writeJSON(w http.ResponseWriter, v any) { w.Header().Set("Content-Type", "application/json") if err := json.NewEncoder(w).Encode(v); err != nil { - internalError(w, "failed to encode response") + http.Error(w, "failed to encode response", http.StatusInternalServerError) } } @@ -579,8 +573,8 @@ type PackageListResult struct { // @Param ecosystem query string false "Ecosystem" // @Param sort query string false "Sort" Enums(hits,name,size,cached_at,ecosystem,vulns) // @Success 200 {object} PackagesListResponse -// @Failure 400 {object} ErrorResponse -// @Failure 500 {object} ErrorResponse +// @Failure 400 {string} string +// @Failure 500 {string} string // @Router /api/packages [get] func (h *APIHandler) HandlePackagesList(w http.ResponseWriter, r *http.Request) { ecosystem := r.URL.Query().Get("ecosystem") @@ -591,14 +585,14 @@ func (h *APIHandler) HandlePackagesList(w http.ResponseWriter, r *http.Request) validSorts := map[string]bool{ defaultSortBy: true, - "name": true, - "size": true, - "cached_at": true, - "ecosystem": true, - "vulns": true, + "name": true, + "size": true, + "cached_at": true, + "ecosystem": true, + "vulns": true, } if !validSorts[sortBy] { - badRequest(w, "invalid sort parameter") + http.Error(w, "invalid sort parameter", http.StatusBadRequest) return } @@ -607,7 +601,7 @@ func (h *APIHandler) HandlePackagesList(w http.ResponseWriter, r *http.Request) packages, err := h.db.ListCachedPackages(ecosystem, sortBy, limit, (page-1)*limit) if err != nil { - internalError(w, "failed to list packages") + http.Error(w, "failed to list packages", http.StatusInternalServerError) return } diff --git a/internal/server/api_test.go b/internal/server/api_test.go index 0494b2f..548f324 100644 --- a/internal/server/api_test.go +++ b/internal/server/api_test.go @@ -9,7 +9,6 @@ import ( "net/http/httptest" "os" "path/filepath" - "strings" "testing" "github.com/git-pkgs/proxy/internal/database" @@ -49,35 +48,6 @@ func TestHandlePackagePath_MissingParams(t *testing.T) { } } -func TestHandlePackagePath_InvalidName(t *testing.T) { - logger := slog.New(slog.NewTextHandler(os.Stdout, nil)) - svc := enrichment.New(logger) - h := NewAPIHandler(svc, nil) - - r := chi.NewRouter() - r.Get("/api/package/{ecosystem}/*", h.HandlePackagePath) - - tests := []struct { - name string - path string - }{ - {"null byte", "/api/package/npm/lodash%00"}, - {"too long", "/api/package/npm/" + strings.Repeat("a", maxPackagePathLen+1)}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - req := httptest.NewRequest("GET", tt.path, nil) - w := httptest.NewRecorder() - r.ServeHTTP(w, req) - - if w.Code != http.StatusBadRequest { - t.Errorf("expected status 400, got %d", w.Code) - } - }) - } -} - func TestHandleVulnsPath_MissingParams(t *testing.T) { logger := slog.New(slog.NewTextHandler(os.Stdout, nil)) svc := enrichment.New(logger) diff --git a/internal/server/breakers.go b/internal/server/breakers.go deleted file mode 100644 index 383e0db..0000000 --- a/internal/server/breakers.go +++ /dev/null @@ -1,130 +0,0 @@ -package server - -import ( - "log/slog" - "sync" - - "github.com/git-pkgs/proxy/internal/metrics" -) - -// Gauge values for proxy_circuit_breaker_state. The fetcher reports only open -// or closed, so half-open (1) is never published. -const ( - breakerGaugeClosed = 0 - breakerGaugeOpen = 2 -) - -const ( - breakerStateOpen = "open" - breakerStateClosed = "closed" -) - -// breakerStateSource reports circuit breaker state per upstream registry, keyed -// by the identifier the fetcher derives from the fetch URL, with values -// breakerStateOpen or breakerStateClosed. Implemented by -// fetch.CircuitBreakerFetcher. -type breakerStateSource interface { - GetBreakerState() map[string]string -} - -// breakerMonitor mirrors the artifact fetcher's per-registry circuit breaker -// state into Prometheus metrics, the health report, and the log. -// -// Breaker state lives only in the fetcher's memory. While a breaker is open -// every artifact fetch it covers that misses the cache fails without reaching -// the upstream, bar the one probe per backoff interval the breaker admits to -// test recovery. That looks identical to an upstream outage from the outside: -// metadata still serves (it does not go through the fetcher), other registries -// still serve, and /health reports the database and storage as fine. Publishing -// the state makes that distinguishable. -type breakerMonitor struct { - source breakerStateSource - logger *slog.Logger - - // mu serializes snapshots. It guards seen, which holds one entry per - // registry that has tripped at least once in this process — the only - // registries published as metrics — and keeps each state read paired with - // the updates it produces. - mu sync.Mutex - seen map[string]string -} - -func newBreakerMonitor(source breakerStateSource, logger *slog.Logger) *breakerMonitor { - if logger == nil { - logger = slog.Default() - } - return &breakerMonitor{ - source: source, - logger: logger, - seen: map[string]string{}, - } -} - -// snapshot returns the current state of every breaker the fetcher has created, -// keyed by registry identifier, and mirrors it into the breaker metrics as a -// side effect. It returns nil for a nil monitor so callers that build a Server -// without a fetcher (tests) need no special case. -// -// The keys pass through unaltered into Prometheus labels and the /health body, -// neither of which is authenticated, so they are only as safe to publish as the -// fetcher makes them. It keys by the fetch URL's host, and where it cannot take -// a host from that URL — a signed composer dist.url that fails to parse, say — -// by an opaque keyed digest of the URL rather than the URL itself, so a -// credential carried in one does not reach either endpoint -// (github.com/git-pkgs/registries v0.9.0 and later). -// -// Only registries that have tripped at least once are published as metrics. -// The fetcher creates a breaker per identifier it fetches under, and for some -// ecosystems that identifier comes from upstream metadata rather than -// configuration (composer takes it from a package's dist.url, helm from the -// chart URLs in index.yaml), so publishing every one would let upstream content -// grow the series count for the life of the process — the more so for URLs with -// no host, which get an identifier apiece rather than sharing one. An -// identifier that has never tripped carries no information a series could -// convey; once it trips it keeps reporting, including the 0 that marks its -// recovery. /health is a per-request response rather than a persistent series, -// so it reports every breaker. -// -// Trips are counted on the closed→open transitions observed between calls, -// because the fetcher exposes current state rather than trip events: a breaker -// that opens and recovers entirely between two calls is not counted. -func (m *breakerMonitor) snapshot() map[string]string { - if m == nil || m.source == nil { - return nil - } - - m.mu.Lock() - defer m.mu.Unlock() - - // Read under the lock. Two concurrent snapshots — a /health request and a - // /metrics scrape landing during a transition — can otherwise apply their - // reads to seen in the opposite order, counting one trip twice, logging a - // close for a breaker that is still open, and leaving the gauge at 0 until - // the next call. - states := m.source.GetBreakerState() - - for registry, state := range states { - previous, published := m.seen[registry] - - switch { - case state == breakerStateOpen && previous != breakerStateOpen: - metrics.RecordCircuitBreakerTrip(registry) - m.logger.Error("circuit breaker open, artifact fetches for this registry "+ - "fail without contacting it", "registry", registry) - case state == breakerStateClosed && previous == breakerStateOpen: - m.logger.Info("circuit breaker closed", "registry", registry) - case state == breakerStateClosed && !published: - // Never tripped: nothing to publish. - continue - } - - gauge := breakerGaugeClosed - if state == breakerStateOpen { - gauge = breakerGaugeOpen - } - metrics.UpdateCircuitBreakerState(registry, gauge) - m.seen[registry] = state - } - - return states -} diff --git a/internal/server/breakers_test.go b/internal/server/breakers_test.go deleted file mode 100644 index ae39759..0000000 --- a/internal/server/breakers_test.go +++ /dev/null @@ -1,348 +0,0 @@ -package server - -import ( - "context" - "encoding/json" - "io" - "log/slog" - "net/http" - "net/http/httptest" - "strings" - "sync/atomic" - "testing" - "time" - - "github.com/git-pkgs/proxy/internal/metrics" - "github.com/git-pkgs/registries/fetch" - "github.com/prometheus/client_golang/prometheus" - dto "github.com/prometheus/client_model/go" -) - -// cbThreshold in registries/fetch: failures inside the breaker's rolling window -// needed to trip it. The library counts the window, not a consecutive run, so -// these fetches only have to land close together, which they do. -const breakerTripFailures = 5 - -// fakeBreakerSource reports breaker state without a real fetcher, so tests can -// drive transitions that would otherwise need to wait out a 30s backoff. -type fakeBreakerSource struct { - states map[string]string -} - -func (f *fakeBreakerSource) GetBreakerState() map[string]string { - states := make(map[string]string, len(f.states)) - for registry, state := range f.states { - states[registry] = state - } - return states -} - -// newTrippedMonitor returns a monitor over a real circuit-breaker fetcher whose -// breaker for the test server's host has been tripped by repeated 5xx -// responses, plus that host. -func newTrippedMonitor(t *testing.T) (*breakerMonitor, string) { - t.Helper() - - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.WriteHeader(http.StatusBadGateway) - })) - t.Cleanup(upstream.Close) - - monitor, fetcher, host := newMonitorFor(t, upstream) - for range breakerTripFailures { - if _, err := fetcher.Fetch(context.Background(), upstream.URL+"/artifact.tgz"); err == nil { - t.Fatal("fetch against a 502 upstream should fail") - } - } - return monitor, host -} - -// newMonitorFor builds a monitor over a circuit-breaker fetcher that talks to -// srv through its own client, bypassing the SSRF dial gate that would otherwise -// refuse the loopback address. -func newMonitorFor(t *testing.T, srv *httptest.Server) ( - monitor *breakerMonitor, fetcher *fetch.CircuitBreakerFetcher, host string, -) { - t.Helper() - - base := fetch.NewFetcher( - fetch.WithHTTPClient(srv.Client()), - fetch.WithMaxRetries(0), - ) - t.Cleanup(func() { _ = base.Close() }) - - fetcher = fetch.NewCircuitBreakerFetcher(base) - return newBreakerMonitor(fetcher, slog.New(slog.DiscardHandler)), - fetcher, - strings.TrimPrefix(srv.URL, "http://") -} - -// metricValue returns the value of the series carrying registry=want, and -// whether such a series exists at all. It collects rather than calling -// WithLabelValues, which would create the series it is looking for. -func metricValue(t *testing.T, collector prometheus.Collector, want string) (value float64, found bool) { - t.Helper() - - ch := make(chan prometheus.Metric, 64) - go func() { - collector.Collect(ch) - close(ch) - }() - - for metric := range ch { - var parsed dto.Metric - if err := metric.Write(&parsed); err != nil { - t.Fatalf("writing metric: %v", err) - } - for _, label := range parsed.GetLabel() { - if label.GetName() != "registry" || label.GetValue() != want { - continue - } - if gauge := parsed.GetGauge(); gauge != nil { - return gauge.GetValue(), true - } - return parsed.GetCounter().GetValue(), true - } - } - return 0, false -} - -// resetSeries drops any series for host left behind by an earlier test, since -// httptest ports can be reused within a process and the metrics registry is -// global. Absolute trip counts stay meaningful after it. -func resetSeries(host string) { - metrics.CircuitBreakerState.DeleteLabelValues(host) - metrics.CircuitBreakerTrips.DeleteLabelValues(host) -} - -func TestBreakerMonitor_OpenBreakerReportedAndCounted(t *testing.T) { - monitor, host := newTrippedMonitor(t) - resetSeries(host) - - if state := monitor.snapshot()[host]; state != breakerStateOpen { - t.Fatalf("state for %s = %q, want open", host, state) - } - - gauge, found := metricValue(t, metrics.CircuitBreakerState, host) - if !found { - t.Fatalf("no state gauge published for %s", host) - } - if gauge != breakerGaugeOpen { - t.Errorf("state gauge = %v, want %v", gauge, breakerGaugeOpen) - } - if trips, _ := metricValue(t, metrics.CircuitBreakerTrips, host); trips != 1 { - t.Errorf("trips = %v, want 1", trips) - } - - // A breaker that stays open is one trip, not one per scrape. - monitor.snapshot() - monitor.snapshot() - if trips, _ := metricValue(t, metrics.CircuitBreakerTrips, host); trips != 1 { - t.Errorf("trips after further snapshots = %v, want 1", trips) - } -} - -// A breaker per fetched host is created even for hosts that come from upstream -// metadata (composer dist.url, helm chart URLs), so publishing a series for -// every one of them would let upstream content grow the series count without -// bound. Only registries that have actually tripped are published. -func TestBreakerMonitor_HealthyRegistryPublishesNoSeries(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - _, _ = w.Write([]byte("artifact")) - })) - defer upstream.Close() - - monitor, fetcher, host := newMonitorFor(t, upstream) - resetSeries(host) - - artifact, err := fetcher.Fetch(context.Background(), upstream.URL+"/artifact.tgz") - if err != nil { - t.Fatalf("fetch: %v", err) - } - _, _ = io.Copy(io.Discard, artifact.Body) - _ = artifact.Body.Close() - - // The breaker exists and is reported to /health... - if state := monitor.snapshot()[host]; state != breakerStateClosed { - t.Fatalf("state for %s = %q, want closed", host, state) - } - // ...but carries no metric series. - if _, found := metricValue(t, metrics.CircuitBreakerState, host); found { - t.Errorf("state gauge published for %s, want none until it trips", host) - } - if _, found := metricValue(t, metrics.CircuitBreakerTrips, host); found { - t.Errorf("trip counter published for %s, want none until it trips", host) - } -} - -// Once a registry has tripped it keeps reporting, so recovery is visible as a -// transition to 0 rather than as a series that disappears. -func TestBreakerMonitor_RecoveryReportedAfterTrip(t *testing.T) { - const host = "recovering.example.com" - - resetSeries(host) - - source := &fakeBreakerSource{states: map[string]string{host: breakerStateOpen}} - monitor := newBreakerMonitor(source, slog.New(slog.DiscardHandler)) - - monitor.snapshot() - if gauge, _ := metricValue(t, metrics.CircuitBreakerState, host); gauge != breakerGaugeOpen { - t.Fatalf("state gauge = %v, want %v", gauge, breakerGaugeOpen) - } - - source.states[host] = breakerStateClosed - if state := monitor.snapshot()[host]; state != breakerStateClosed { - t.Fatalf("state for %s = %q, want closed", host, state) - } - gauge, found := metricValue(t, metrics.CircuitBreakerState, host) - if !found { - t.Fatal("state gauge disappeared after recovery, want 0") - } - if gauge != breakerGaugeClosed { - t.Errorf("state gauge = %v, want %v", gauge, breakerGaugeClosed) - } - if trips, _ := metricValue(t, metrics.CircuitBreakerTrips, host); trips != 1 { - t.Errorf("trips = %v, want 1", trips) - } - - // Tripping again after recovery counts a second trip. - source.states[host] = breakerStateOpen - monitor.snapshot() - if trips, _ := metricValue(t, metrics.CircuitBreakerTrips, host); trips != 2 { - t.Errorf("trips after re-trip = %v, want 2", trips) - } -} - -func TestBreakerMonitor_NilSafe(t *testing.T) { - var nilMonitor *breakerMonitor - if states := nilMonitor.snapshot(); states != nil { - t.Errorf("nil monitor snapshot = %v, want nil", states) - } - if states := newBreakerMonitor(nil, nil).snapshot(); states != nil { - t.Errorf("snapshot without a state source = %v, want nil", states) - } -} - -func TestHealthEndpoint_ReportsOpenBreaker(t *testing.T) { - ts := newTestServer(t) - defer ts.close() - - monitor, host := newTrippedMonitor(t) - ts.server.breakers = monitor - - req := httptest.NewRequest("GET", "/health", nil) - w := httptest.NewRecorder() - ts.handler.ServeHTTP(w, req) - - // An unreachable upstream is not this proxy being unhealthy: the breaker - // state is reported, but the probe still passes. - if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200; body: %s", w.Code, w.Body.String()) - } - - var resp HealthResponse - if err := json.NewDecoder(w.Body).Decode(&resp); err != nil { - t.Fatalf("decoding response: %v", err) - } - if resp.Status != "ok" { - t.Errorf("status = %q, want ok", resp.Status) - } - if got := resp.CircuitBreakers[host]; got != breakerStateOpen { - t.Errorf("circuit_breakers[%s] = %q, want open", host, got) - } -} - -func TestHealthEndpoint_OmitsBreakersWhenNoneExist(t *testing.T) { - ts := newTestServer(t) - defer ts.close() - - req := httptest.NewRequest("GET", "/health", nil) - w := httptest.NewRecorder() - ts.handler.ServeHTTP(w, req) - - if strings.Contains(w.Body.String(), "circuit_breakers") { - t.Errorf("body should omit circuit_breakers when no breaker exists: %s", w.Body.String()) - } -} - -// blockingBreakerSource holds each state read open until the test releases it, -// and reports every entry, so a read that escaped the monitor lock announces -// itself. inFlight is a second net: it catches an overlap anywhere in the test, -// not just while the release channel is held. -type blockingBreakerSource struct { - states map[string]string - entered chan struct{} - release chan struct{} - inFlight atomic.Int32 - overlap atomic.Bool -} - -func (b *blockingBreakerSource) GetBreakerState() map[string]string { - if b.inFlight.Add(1) > 1 { - b.overlap.Store(true) - } - defer b.inFlight.Add(-1) - - b.entered <- struct{}{} - <-b.release - - states := make(map[string]string, len(b.states)) - for registry, state := range b.states { - states[registry] = state - } - return states -} - -// /health requests and /metrics scrapes call snapshot concurrently. The state -// read has to happen under the same lock as the seen updates it feeds: read -// outside it, two snapshots straddling a transition can apply their reads to -// seen in the opposite order and count one trip twice. -func TestBreakerMonitor_SnapshotSerializesStateReads(t *testing.T) { - const host = "serialized.example.com" - - resetSeries(host) - - source := &blockingBreakerSource{ - states: map[string]string{host: breakerStateOpen}, - entered: make(chan struct{}, 2), - release: make(chan struct{}), - } - monitor := newBreakerMonitor(source, slog.New(slog.DiscardHandler)) - - first := make(chan map[string]string, 1) - go func() { first <- monitor.snapshot() }() - - // The first snapshot is inside GetBreakerState now, holding the lock. - <-source.entered - - second := make(chan map[string]string, 1) - go func() { second <- monitor.snapshot() }() - - // Nothing can release the first read, so the second cannot get past the - // lock: an unlocked read would have queued an entry on the channel. - select { - case <-source.entered: - t.Fatal("second snapshot read breaker state while the first still held the lock") - case <-time.After(100 * time.Millisecond): - } - - close(source.release) - - if state := (<-first)[host]; state != breakerStateOpen { - t.Errorf("first snapshot state for %s = %q, want open", host, state) - } - // Only reached once the first snapshot has returned the lock. - <-source.entered - if state := (<-second)[host]; state != breakerStateOpen { - t.Errorf("second snapshot state for %s = %q, want open", host, state) - } - - if source.overlap.Load() { - t.Error("two snapshots read breaker state concurrently") - } - // The same open breaker seen twice is one trip, which is what the paired - // read and update buys. - if trips, _ := metricValue(t, metrics.CircuitBreakerTrips, host); trips != 1 { - t.Errorf("trips = %v, want 1", trips) - } -} diff --git a/internal/server/browse.go b/internal/server/browse.go index fc5e658..7e035d2 100644 --- a/internal/server/browse.go +++ b/internal/server/browse.go @@ -1,7 +1,7 @@ package server import ( - "bufio" + "bytes" "encoding/json" "fmt" "io" @@ -11,45 +11,22 @@ import ( "github.com/git-pkgs/archives" "github.com/git-pkgs/archives/diff" - "github.com/git-pkgs/magic" "github.com/git-pkgs/proxy/internal/database" - "github.com/git-pkgs/proxy/internal/handler" + "github.com/git-pkgs/purl" "github.com/go-chi/chi/v5" ) -const ( - contentTypePlainText = "text/plain; charset=utf-8" - browseSniffSize = 512 -) +const contentTypePlainText = "text/plain; charset=utf-8" -// maxBrowseArchiveSize caps how much data openArchive will buffer for -// prefix detection. Artifacts larger than this are rejected to prevent -// memory exhaustion from a single request. -const maxBrowseArchiveSize = 512 << 20 // 512 MB - -// firstBrowsableArtifact returns the first cached artifact that can be opened as -// an archive, or nil if the version has none. -// -// A version's artifact list is not all archives: a PEP 658 core-metadata sidecar -// resolves to the same name and version as the distribution it describes, so it -// is cached under that version too. Sidecars are plain text, and because '-' -// sorts before '.' one can even precede the real distribution in the -// filename-ordered list, so selecting blindly would hand openArchive a file it -// cannot parse. -func firstBrowsableArtifact(artifacts []database.Artifact) *database.Artifact { - for i := range artifacts { - if artifacts[i].StoragePath.Valid && !isMetadataSidecar(artifacts[i].Filename) { - return &artifacts[i] - } +// archiveFilename returns a filename suitable for archive format detection. +// Some ecosystems (e.g. composer) store artifacts with bare hash filenames +// that have no extension. This adds .zip when the original has no extension +// and the content is likely a zip archive. +func archiveFilename(filename string) string { + if path.Ext(filename) == "" { + return filename + ".zip" } - - return nil -} - -// isMetadataSidecar reports whether filename is a core-metadata sidecar rather -// than a distribution archive. -func isMetadataSidecar(filename string) bool { - return strings.HasSuffix(filename, handler.PyPIMetadataSuffix) + return filename } // detectSingleRootDir returns the single top-level directory name if all files @@ -85,29 +62,31 @@ func detectSingleRootDir(reader archives.Reader) string { // and stripping a single top-level directory prefix (like GitHub zipballs). // For npm, the hardcoded "package/" prefix takes precedence. func openArchive(filename string, content io.Reader, ecosystem string) (archives.Reader, error) { //nolint:ireturn // wraps multiple archive implementations - limited := io.LimitReader(content, maxBrowseArchiveSize+1) - data, err := io.ReadAll(limited) + fname := archiveFilename(filename) + + // npm always uses package/ prefix + if ecosystem == "npm" { + return archives.OpenWithPrefix(fname, content, "package/") + } + + // Read content into memory so we can scan then wrap with prefix + data, err := io.ReadAll(content) if err != nil { return nil, fmt.Errorf("reading artifact: %w", err) } - if int64(len(data)) > maxBrowseArchiveSize { - return nil, fmt.Errorf("artifact too large for browsing (%d bytes)", len(data)) - } - if ecosystem == "npm" { - return archives.OpenBytesWithPrefix(filename, data, "package/") - } - - probe, err := archives.OpenBytes(filename, data) + // Open once to detect root prefix + probe, err := archives.Open(fname, bytes.NewReader(data)) if err != nil { return nil, err } prefix := detectSingleRootDir(probe) _ = probe.Close() - return archives.OpenBytesWithPrefix(filename, data, prefix) + return archives.OpenWithPrefix(fname, bytes.NewReader(data), prefix) } + // BrowseListResponse contains the file listing for a directory in an archives. type BrowseListResponse struct { Path string `json:"path"` @@ -134,9 +113,9 @@ type BrowseFileInfo struct { // @Param version path string true "Version" // @Param path query string false "Directory path inside the archive" // @Success 200 {object} BrowseListResponse -// @Failure 404 {object} ErrorResponse -// @Failure 500 {object} ErrorResponse -// @Router /ui/api/browse/{ecosystem}/{name}/{version} [get] +// @Failure 404 {string} string +// @Failure 500 {string} string +// @Router /api/browse/{ecosystem}/{name}/{version} [get] // handleBrowsePath dispatches /api/browse/{ecosystem}/* to the appropriate browse handler. // It resolves namespaced package names by consulting the database. // @@ -146,14 +125,11 @@ type BrowseFileInfo struct { // {name}/{version}/file/{path} -> browse file func (s *Server) handleBrowsePath(w http.ResponseWriter, r *http.Request) { ecosystem := chi.URLParam(r, "ecosystem") - segments, err := packagePathSegments(r) - if err != nil { - badRequest(w, err.Error()) - return - } + wildcard := chi.URLParam(r, "*") + segments := splitWildcardPath(wildcard) if ecosystem == "" || len(segments) < 2 { - badRequest(w, "ecosystem, name, and version required") + http.Error(w, "ecosystem, name, and version required", http.StatusBadRequest) return } @@ -177,7 +153,7 @@ func (s *Server) handleBrowsePath(w http.ResponseWriter, r *http.Request) { rest = nameVersionSegments[len(nameVersionSegments)-1:] } if len(rest) != 1 { - notFound(w, "not found") + http.Error(w, "not found", http.StatusNotFound) return } s.browseFile(w, r, ecosystem, name, rest[0], filePath) @@ -191,7 +167,7 @@ func (s *Server) handleBrowsePath(w http.ResponseWriter, r *http.Request) { rest = segments[len(segments)-1:] } if len(rest) != 1 { - notFound(w, "not found") + http.Error(w, "not found", http.StatusNotFound) return } s.browseList(w, r, ecosystem, name, rest[0]) @@ -201,14 +177,11 @@ func (s *Server) handleBrowsePath(w http.ResponseWriter, r *http.Request) { // Supported paths: {name}/{fromVersion}/{toVersion} func (s *Server) handleComparePath(w http.ResponseWriter, r *http.Request) { ecosystem := chi.URLParam(r, "ecosystem") - segments, err := packagePathSegments(r) - if err != nil { - badRequest(w, err.Error()) - return - } + wildcard := chi.URLParam(r, "*") + segments := splitWildcardPath(wildcard) if ecosystem == "" || len(segments) < 3 { - badRequest(w, "ecosystem, name, fromVersion, and toVersion required") + http.Error(w, "ecosystem, name, fromVersion, and toVersion required", http.StatusBadRequest) return } @@ -225,22 +198,29 @@ func (s *Server) browseList(w http.ResponseWriter, r *http.Request, ecosystem, n dirPath := r.URL.Query().Get("path") // Get the artifact for this version - versionPURL := s.cachedVersionPURL(ecosystem, name, version) + versionPURL := purl.MakePURLString(ecosystem, name, version) artifacts, err := s.db.GetArtifactsByVersionPURL(versionPURL) if err != nil { - notFound(w, "version not found") + http.Error(w, "version not found", http.StatusNotFound) return } if len(artifacts) == 0 { - notFound(w, "no artifacts cached") + http.Error(w, "no artifacts cached", http.StatusNotFound) return } - cachedArtifact := firstBrowsableArtifact(artifacts) + // Find the first cached artifact + var cachedArtifact *database.Artifact + for i := range artifacts { + if artifacts[i].StoragePath.Valid { + cachedArtifact = &artifacts[i] + break + } + } if cachedArtifact == nil { - notFound(w, "artifact not cached") + http.Error(w, "artifact not cached", http.StatusNotFound) return } @@ -248,7 +228,7 @@ func (s *Server) browseList(w http.ResponseWriter, r *http.Request, ecosystem, n artifactReader, err := s.storage.Open(r.Context(), cachedArtifact.StoragePath.String) if err != nil { s.logger.Error("failed to read artifact from storage", "error", err) - internalError(w, "failed to read artifact") + http.Error(w, "failed to read artifact", http.StatusInternalServerError) return } defer func() { _ = artifactReader.Close() }() @@ -257,7 +237,7 @@ func (s *Server) browseList(w http.ResponseWriter, r *http.Request, ecosystem, n archiveReader, err := openArchive(cachedArtifact.Filename, artifactReader, ecosystem) if err != nil { s.logger.Error("failed to open archive", "error", err, "filename", cachedArtifact.Filename) - internalError(w, "failed to open archive") + http.Error(w, "failed to open archive", http.StatusInternalServerError) return } defer func() { _ = archiveReader.Close() }() @@ -266,7 +246,7 @@ func (s *Server) browseList(w http.ResponseWriter, r *http.Request, ecosystem, n files, err := archiveReader.ListDir(dirPath) if err != nil { s.logger.Error("failed to list directory", "error", err, "path", dirPath) - internalError(w, "failed to list directory") + http.Error(w, "failed to list directory", http.StatusInternalServerError) return } @@ -301,33 +281,40 @@ func (s *Server) browseList(w http.ResponseWriter, r *http.Request, ecosystem, n // @Param version path string true "Version" // @Param filepath path string true "File path inside the archive" // @Success 200 {file} file -// @Failure 400 {object} ErrorResponse -// @Failure 404 {object} ErrorResponse -// @Failure 500 {object} ErrorResponse -// @Router /ui/api/browse/{ecosystem}/{name}/{version}/file/{filepath} [get] +// @Failure 400 {string} string +// @Failure 404 {string} string +// @Failure 500 {string} string +// @Router /api/browse/{ecosystem}/{name}/{version}/file/{filepath} [get] func (s *Server) browseFile(w http.ResponseWriter, r *http.Request, ecosystem, name, version, filePath string) { if filePath == "" { - badRequest(w, "file path required") + http.Error(w, "file path required", http.StatusBadRequest) return } // Get the artifact for this version - versionPURL := s.cachedVersionPURL(ecosystem, name, version) + versionPURL := purl.MakePURLString(ecosystem, name, version) artifacts, err := s.db.GetArtifactsByVersionPURL(versionPURL) if err != nil { - notFound(w, "version not found") + http.Error(w, "version not found", http.StatusNotFound) return } if len(artifacts) == 0 { - notFound(w, "no artifacts cached") + http.Error(w, "no artifacts cached", http.StatusNotFound) return } - cachedArtifact := firstBrowsableArtifact(artifacts) + // Find the first cached artifact + var cachedArtifact *database.Artifact + for i := range artifacts { + if artifacts[i].StoragePath.Valid { + cachedArtifact = &artifacts[i] + break + } + } if cachedArtifact == nil { - notFound(w, "artifact not cached") + http.Error(w, "artifact not cached", http.StatusNotFound) return } @@ -335,7 +322,7 @@ func (s *Server) browseFile(w http.ResponseWriter, r *http.Request, ecosystem, n artifactReader, err := s.storage.Open(r.Context(), cachedArtifact.StoragePath.String) if err != nil { s.logger.Error("failed to read artifact from storage", "error", err) - internalError(w, "failed to read artifact") + http.Error(w, "failed to read artifact", http.StatusInternalServerError) return } defer func() { _ = artifactReader.Close() }() @@ -344,7 +331,7 @@ func (s *Server) browseFile(w http.ResponseWriter, r *http.Request, ecosystem, n archiveReader, err := openArchive(cachedArtifact.Filename, artifactReader, ecosystem) if err != nil { s.logger.Error("failed to open archive", "error", err, "filename", cachedArtifact.Filename) - internalError(w, "failed to open archive") + http.Error(w, "failed to open archive", http.StatusInternalServerError) return } defer func() { _ = archiveReader.Close() }() @@ -353,128 +340,103 @@ func (s *Server) browseFile(w http.ResponseWriter, r *http.Request, ecosystem, n fileReader, err := archiveReader.Extract(filePath) if err != nil { if strings.Contains(err.Error(), "not found") { - notFound(w, "file not found") + http.Error(w, "file not found", http.StatusNotFound) return } s.logger.Error("failed to extract file", "error", err, "path", filePath) - internalError(w, "failed to extract file") + http.Error(w, "failed to extract file", http.StatusInternalServerError) return } defer func() { _ = fileReader.Close() }() - contentType, knownPath := detectContentTypeFromPath(filePath) - var content io.Reader = fileReader - if !knownPath { - bufferedFile := bufio.NewReaderSize(fileReader, browseSniffSize) - prefix, _ := bufferedFile.Peek(browseSniffSize) - contentType = detectContentTypeFromPrefix(prefix) - content = bufferedFile - } + // Set content type based on file extension + contentType := detectContentType(filePath) w.Header().Set("Content-Type", contentType) - w.Header().Set("Content-Security-Policy", "sandbox") - w.Header().Set("X-Content-Type-Options", "nosniff") + // Set filename for download _, filename := path.Split(filePath) w.Header().Set("Content-Disposition", fmt.Sprintf("inline; filename=%q", filename)) // Stream the file - _, _ = io.Copy(w, content) + _, _ = io.Copy(w, fileReader) } -func detectContentTypeFromPath(filename string) (string, bool) { +// detectContentType returns an appropriate content type based on file extension. +func detectContentType(filename string) string { ext := strings.ToLower(path.Ext(filename)) switch ext { // Text formats case ".txt", ".md", ".markdown": - return contentTypePlainText, true - case ".html", ".htm", ".xhtml": - return contentTypePlainText, true + return contentTypePlainText + case ".html", ".htm": + return "text/html; charset=utf-8" case ".css": - return "text/css; charset=utf-8", true + return "text/css; charset=utf-8" case ".js", ".mjs": - return "application/javascript; charset=utf-8", true + return "application/javascript; charset=utf-8" case ".json": - return "application/json; charset=utf-8", true + return "application/json; charset=utf-8" case ".xml": - return "application/xml; charset=utf-8", true + return "application/xml; charset=utf-8" case ".yaml", ".yml": - return "text/yaml; charset=utf-8", true + return "text/yaml; charset=utf-8" case ".toml": - return "text/toml; charset=utf-8", true + return "text/toml; charset=utf-8" // Programming languages case ".go": - return "text/x-go; charset=utf-8", true + return "text/x-go; charset=utf-8" case ".rs": - return "text/x-rust; charset=utf-8", true + return "text/x-rust; charset=utf-8" case ".py": - return "text/x-python; charset=utf-8", true + return "text/x-python; charset=utf-8" case ".rb": - return "text/x-ruby; charset=utf-8", true + return "text/x-ruby; charset=utf-8" case ".java": - return "text/x-java; charset=utf-8", true + return "text/x-java; charset=utf-8" case ".c", ".h": - return "text/x-c; charset=utf-8", true + return "text/x-c; charset=utf-8" case ".cpp", ".cc", ".cxx", ".hpp": - return "text/x-c++; charset=utf-8", true + return "text/x-c++; charset=utf-8" case ".ts": - return "text/typescript; charset=utf-8", true + return "text/typescript; charset=utf-8" case ".tsx": - return "text/tsx; charset=utf-8", true + return "text/tsx; charset=utf-8" case ".jsx": - return "text/jsx; charset=utf-8", true + return "text/jsx; charset=utf-8" case ".php": - return "text/x-php; charset=utf-8", true + return "text/x-php; charset=utf-8" // Config files case ".conf", ".config", ".ini": - return contentTypePlainText, true + return contentTypePlainText case ".sh", ".bash": - return "text/x-shellscript; charset=utf-8", true + return "text/x-shellscript; charset=utf-8" case ".dockerfile": - return "text/x-dockerfile; charset=utf-8", true + return "text/x-dockerfile; charset=utf-8" // Images case ".png": - return "image/png", true + return "image/png" case ".jpg", ".jpeg": - return "image/jpeg", true + return "image/jpeg" case ".gif": - return "image/gif", true + return "image/gif" case ".svg": - return contentTypePlainText, true + return "image/svg+xml" case ".ico": - return "image/x-icon", true + return "image/x-icon" // Archives case ".zip", ".tar", ".gz", ".bz2", ".xz": - return "application/octet-stream", true + return "application/octet-stream" default: + // Try to detect if it looks like text if isLikelyText(filename) { - return contentTypePlainText, true + return contentTypePlainText } - return "", false - } -} - -func detectContentTypeFromPrefix(prefix []byte) string { - result := magic.DetectPrefix(prefix) - if result.Kind == magic.KindText { - return contentTypePlainText - } - - switch result.Format { - case "png": - return "image/png" - case "jpeg": - return "image/jpeg" - case "gif": - return "image/gif" - case "pdf": - return "application/pdf" - default: return "application/octet-stream" } } @@ -503,16 +465,10 @@ func isLikelyText(filename string) bool { } // BrowseSourceData contains data for the browse source page. -// -// Version is the decoded version, for display. EscapedVersion is the same value -// escaped as a single URL path segment and is what the links and the browse API -// calls must use; see database.Version.EscapedVersion. type BrowseSourceData struct { - Layout - Ecosystem string - PackageName string - Version string - EscapedVersion string + Ecosystem string + PackageName string + Version string } // handleBrowseSource is now showBrowseSource in server.go, dispatched via handlePackagePath. @@ -528,32 +484,43 @@ type BrowseSourceData struct { // @Param fromVersion path string true "From version" // @Param toVersion path string true "To version" // @Success 200 {object} map[string]any -// @Failure 404 {object} ErrorResponse -// @Failure 500 {object} ErrorResponse -// @Router /ui/api/compare/{ecosystem}/{name}/{fromVersion}/{toVersion} [get] +// @Failure 404 {string} string +// @Failure 500 {string} string +// @Router /api/compare/{ecosystem}/{name}/{fromVersion}/{toVersion} [get] func (s *Server) compareDiff(w http.ResponseWriter, r *http.Request, ecosystem, name, fromVersion, toVersion string) { // Get artifacts for both versions - fromPURL := s.cachedVersionPURL(ecosystem, name, fromVersion) - toPURL := s.cachedVersionPURL(ecosystem, name, toVersion) + fromPURL := purl.MakePURLString(ecosystem, name, fromVersion) + toPURL := purl.MakePURLString(ecosystem, name, toVersion) fromArtifacts, err := s.db.GetArtifactsByVersionPURL(fromPURL) if err != nil || len(fromArtifacts) == 0 { - notFound(w, "from version not found or not cached") + http.Error(w, "from version not found or not cached", http.StatusNotFound) return } toArtifacts, err := s.db.GetArtifactsByVersionPURL(toPURL) if err != nil || len(toArtifacts) == 0 { - notFound(w, "to version not found or not cached") + http.Error(w, "to version not found or not cached", http.StatusNotFound) return } // Find cached artifacts - fromArtifact := firstBrowsableArtifact(fromArtifacts) - toArtifact := firstBrowsableArtifact(toArtifacts) + var fromArtifact, toArtifact *database.Artifact + for i := range fromArtifacts { + if fromArtifacts[i].StoragePath.Valid { + fromArtifact = &fromArtifacts[i] + break + } + } + for i := range toArtifacts { + if toArtifacts[i].StoragePath.Valid { + toArtifact = &toArtifacts[i] + break + } + } if fromArtifact == nil || toArtifact == nil { - notFound(w, "one or both versions not cached") + http.Error(w, "one or both versions not cached", http.StatusNotFound) return } @@ -561,7 +528,7 @@ func (s *Server) compareDiff(w http.ResponseWriter, r *http.Request, ecosystem, fromReader, err := s.storage.Open(r.Context(), fromArtifact.StoragePath.String) if err != nil { s.logger.Error("failed to open from artifact", "error", err) - internalError(w, "failed to read from version") + http.Error(w, "failed to read from version", http.StatusInternalServerError) return } defer func() { _ = fromReader.Close() }() @@ -569,7 +536,7 @@ func (s *Server) compareDiff(w http.ResponseWriter, r *http.Request, ecosystem, toReader, err := s.storage.Open(r.Context(), toArtifact.StoragePath.String) if err != nil { s.logger.Error("failed to open to artifact", "error", err) - internalError(w, "failed to read to version") + http.Error(w, "failed to read to version", http.StatusInternalServerError) return } defer func() { _ = toReader.Close() }() @@ -577,7 +544,7 @@ func (s *Server) compareDiff(w http.ResponseWriter, r *http.Request, ecosystem, fromArchive, err := openArchive(fromArtifact.Filename, fromReader, ecosystem) if err != nil { s.logger.Error("failed to open from archive", "error", err) - internalError(w, "failed to open from archive") + http.Error(w, "failed to open from archive", http.StatusInternalServerError) return } defer func() { _ = fromArchive.Close() }() @@ -585,7 +552,7 @@ func (s *Server) compareDiff(w http.ResponseWriter, r *http.Request, ecosystem, toArchive, err := openArchive(toArtifact.Filename, toReader, ecosystem) if err != nil { s.logger.Error("failed to open to archive", "error", err) - internalError(w, "failed to open to archive") + http.Error(w, "failed to open to archive", http.StatusInternalServerError) return } defer func() { _ = toArchive.Close() }() @@ -594,7 +561,7 @@ func (s *Server) compareDiff(w http.ResponseWriter, r *http.Request, ecosystem, result, err := diff.Compare(fromArchive, toArchive) if err != nil { s.logger.Error("failed to generate diff", "error", err) - internalError(w, "failed to generate diff") + http.Error(w, "failed to generate diff", http.StatusInternalServerError) return } @@ -603,17 +570,11 @@ func (s *Server) compareDiff(w http.ResponseWriter, r *http.Request, ecosystem, } // ComparePageData contains data for the version comparison page. -// -// FromVersion and ToVersion are decoded, for display; the Escaped variants are -// the path-segment form used to build the compare API URL. type ComparePageData struct { - Layout - Ecosystem string - PackageName string - FromVersion string - ToVersion string - EscapedFromVersion string - EscapedToVersion string + Ecosystem string + PackageName string + FromVersion string + ToVersion string } // handleComparePage is now showComparePage in server.go, dispatched via handlePackagePath. diff --git a/internal/server/browse_bench_test.go b/internal/server/browse_bench_test.go deleted file mode 100644 index 840bc75..0000000 --- a/internal/server/browse_bench_test.go +++ /dev/null @@ -1,89 +0,0 @@ -package server - -import ( - "archive/tar" - "bytes" - "compress/gzip" - "fmt" - "math/rand" - "testing" -) - -func createBenchTarGz(prefix string, fileCount, fileSize int) []byte { - rnd := rand.New(rand.NewSource(1)) //nolint:gosec - buf := new(bytes.Buffer) - gw := gzip.NewWriter(buf) - tw := tar.NewWriter(gw) - - payload := make([]byte, fileSize) - for i := range fileCount { - rnd.Read(payload) - _ = tw.WriteHeader(&tar.Header{ - Name: fmt.Sprintf("%sfile%04d.dat", prefix, i), - Size: int64(fileSize), - Mode: 0644, - }) - _, _ = tw.Write(payload) - } - _ = tw.Close() - _ = gw.Close() - return buf.Bytes() -} - -func BenchmarkOpenArchive(b *testing.B) { - cases := []struct { - name string - ecosystem string - filename string - data []byte - }{ - {"npm", "npm", "pkg.tgz", createBenchTarGz("package/", 64, 16*1024)}, - {"go", "go", "v1.2.3.tar.gz", createBenchTarGz("repo-abc123/", 64, 16*1024)}, - } - - for _, tc := range cases { - b.Run(tc.name, func(b *testing.B) { - b.SetBytes(int64(len(tc.data))) - b.ReportAllocs() - for b.Loop() { - r, err := openArchive(tc.filename, bytes.NewReader(tc.data), tc.ecosystem) - if err != nil { - b.Fatal(err) - } - _ = r.Close() - } - }) - } -} - -func BenchmarkDetectContentType(b *testing.B) { - cases := []struct { - name string - filename string - prefix []byte - knownPath bool - }{ - {"known-path", "README.md", nil, true}, - {"text-prefix", "artifact", bytes.Repeat([]byte("a"), browseSniffSize), false}, - {"png-prefix", "artifact", append([]byte("\x89PNG\r\n\x1a\n"), make([]byte, browseSniffSize-8)...), false}, - } - - for _, tc := range cases { - b.Run(tc.name, func(b *testing.B) { - b.ReportAllocs() - var contentType string - if tc.knownPath { - for b.Loop() { - contentType, _ = detectContentTypeFromPath(tc.filename) - } - } else { - for b.Loop() { - contentType = detectContentTypeFromPrefix(tc.prefix) - } - } - if contentType == "" { - b.Fatal("empty content type") - } - }) - } -} diff --git a/internal/server/browse_test.go b/internal/server/browse_test.go index f4f2f9a..1deaf5b 100644 --- a/internal/server/browse_test.go +++ b/internal/server/browse_test.go @@ -65,7 +65,7 @@ func TestHandleBrowseList(t *testing.T) { } // Test listing root directory - req := httptest.NewRequest("GET", "/ui/api/browse/npm/test-browse/1.0.0", nil) + req := httptest.NewRequest("GET", "/api/browse/npm/test-browse/1.0.0", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -83,7 +83,7 @@ func TestHandleBrowseList(t *testing.T) { } // Test listing subdirectory - req = httptest.NewRequest("GET", "/ui/api/browse/npm/test-browse/1.0.0?path=lib", nil) + req = httptest.NewRequest("GET", "/api/browse/npm/test-browse/1.0.0?path=lib", nil) w = httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -137,44 +137,29 @@ func TestHandleBrowseFile(t *testing.T) { t.Fatalf("failed to upsert artifact: %v", err) } - files := []struct { - path string - content string - contentType string - }{ - {"README.md", "# Test Package\n", contentTypePlainText}, - {"notes.data", "short text\n", contentTypePlainText}, - {"logo", "\x89PNG\r\n\x1a\nimage data", "image/png"}, - {"page", "", contentTypePlainText}, - {"misleading.txt", "\x89PNG\r\n\x1a\nimage data", contentTypePlainText}, - } - for _, file := range files { - t.Run(file.path, func(t *testing.T) { - req := httptest.NewRequest("GET", "/ui/api/browse/npm/test-browse/1.0.0/file/"+file.path, nil) - w := httptest.NewRecorder() - ts.handler.ServeHTTP(w, req) + // Test fetching a file + req := httptest.NewRequest("GET", "/api/browse/npm/test-browse/1.0.0/file/README.md", nil) + w := httptest.NewRecorder() + ts.handler.ServeHTTP(w, req) - if w.Code != http.StatusOK { - t.Fatalf("expected status 200, got %d: %s", w.Code, w.Body.String()) - } - if w.Body.String() != file.content { - t.Errorf("unexpected file content: %q", w.Body.String()) - } - if got := w.Header().Get("Content-Type"); got != file.contentType { - t.Errorf("Content-Type = %q, want %q", got, file.contentType) - } - if got := w.Header().Get("Content-Security-Policy"); got != "sandbox" { - t.Errorf("Content-Security-Policy = %q, want sandbox", got) - } - if got := w.Header().Get("X-Content-Type-Options"); got != "nosniff" { - t.Errorf("X-Content-Type-Options = %q, want nosniff", got) - } - }) + if w.Code != http.StatusOK { + t.Fatalf("expected status 200, got %d: %s", w.Code, w.Body.String()) + } + + body := w.Body.String() + if body != "# Test Package\n" { + t.Errorf("unexpected file content: %q", body) + } + + // Check content type + contentType := w.Header().Get("Content-Type") + if contentType != contentTypePlainText { + t.Errorf("expected text/plain content type, got %q", contentType) } // Test fetching non-existent file - req := httptest.NewRequest("GET", "/ui/api/browse/npm/test-browse/1.0.0/file/nonexistent.txt", nil) - w := httptest.NewRecorder() + req = httptest.NewRequest("GET", "/api/browse/npm/test-browse/1.0.0/file/nonexistent.txt", nil) + w = httptest.NewRecorder() ts.handler.ServeHTTP(w, req) if w.Code != http.StatusNotFound { @@ -182,70 +167,37 @@ func TestHandleBrowseFile(t *testing.T) { } } -func TestBrowseContentTypePolicy(t *testing.T) { +func TestDetectContentType(t *testing.T) { tests := []struct { - name string - filename string - prefix []byte - expectedCT string + filename string + expectedCT string }{ - {"text extension", "file.txt", nil, contentTypePlainText}, - {"markdown extension", "file.md", nil, contentTypePlainText}, - {"JSON extension", "file.json", nil, "application/json; charset=utf-8"}, - {"JavaScript extension", "file.js", nil, "application/javascript; charset=utf-8"}, - {"Go extension", "file.go", nil, "text/x-go; charset=utf-8"}, - {"Python extension", "file.py", nil, "text/x-python; charset=utf-8"}, - {"Rust extension", "file.rs", nil, "text/x-rust; charset=utf-8"}, - {"HTML extension", "file.html", nil, contentTypePlainText}, - {"HTM extension", "file.htm", nil, contentTypePlainText}, - {"XHTML extension", "file.xhtml", nil, contentTypePlainText}, - {"SVG extension", "file.svg", nil, contentTypePlainText}, - {"PNG extension", "file.png", nil, "image/png"}, - {"JPEG extension", "file.jpg", nil, "image/jpeg"}, - {"README", "README", nil, contentTypePlainText}, - {"LICENSE", "LICENSE", nil, contentTypePlainText}, - {"Makefile", "Makefile", nil, contentTypePlainText}, - {"gitignore", ".gitignore", nil, contentTypePlainText}, - {"unknown empty", "file.bin", nil, "application/octet-stream"}, - {"extensionless PNG", "asset", []byte("\x89PNG\r\n\x1a\n"), "image/png"}, - {"extensionless JPEG", "asset", []byte("\xff\xd8\xff"), "image/jpeg"}, - {"extensionless GIF", "asset", []byte("GIF89a"), "image/gif"}, - {"extensionless PDF", "asset", []byte("%PDF-1.7"), "application/pdf"}, - {"extensionless text", "asset", []byte("plain text\n"), contentTypePlainText}, - {"extensionless HTML", "asset", []byte(""), contentTypePlainText}, - {"extensionless XML", "asset", []byte(""), contentTypePlainText}, - {"extensionless SVG", "asset", []byte(""), contentTypePlainText}, - {"extensionless ZIP", "asset", []byte("PK\x03\x04"), "application/octet-stream"}, - {"extensionless binary", "asset", []byte{0, 1, 2}, "application/octet-stream"}, - {"known path wins", "file.txt", []byte("\x89PNG\r\n\x1a\n"), contentTypePlainText}, + {"file.txt", contentTypePlainText}, + {"file.md", contentTypePlainText}, + {"file.json", "application/json; charset=utf-8"}, + {"file.js", "application/javascript; charset=utf-8"}, + {"file.go", "text/x-go; charset=utf-8"}, + {"file.py", "text/x-python; charset=utf-8"}, + {"file.rs", "text/x-rust; charset=utf-8"}, + {"file.png", "image/png"}, + {"file.jpg", "image/jpeg"}, + {"README", contentTypePlainText}, + {"LICENSE", contentTypePlainText}, + {"Makefile", contentTypePlainText}, + {".gitignore", contentTypePlainText}, + {"file.bin", "application/octet-stream"}, } for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - got, knownPath := detectContentTypeFromPath(tt.filename) - if !knownPath { - got = detectContentTypeFromPrefix(tt.prefix) - } + t.Run(tt.filename, func(t *testing.T) { + got := detectContentType(tt.filename) if got != tt.expectedCT { - t.Errorf("content type for %q with prefix %q = %q, want %q", tt.filename, tt.prefix, got, tt.expectedCT) + t.Errorf("detectContentType(%q) = %q, want %q", tt.filename, got, tt.expectedCT) } }) } } -func TestOpenArchiveSizeLimit(t *testing.T) { - huge := bytes.Repeat([]byte("x"), int(maxBrowseArchiveSize)+1) - for _, eco := range []string{"npm", "go"} { - _, err := openArchive("test.tar.gz", bytes.NewReader(huge), eco) - if err == nil { - t.Fatalf("%s: expected error for oversized archive, got nil", eco) - } - if !strings.Contains(err.Error(), "too large") { - t.Fatalf("%s: expected 'too large' error, got: %v", eco, err) - } - } -} - func TestIsLikelyText(t *testing.T) { tests := []struct { filename string @@ -286,10 +238,6 @@ func createTestArchive(t *testing.T) []byte { "package/lib/index.js": "module.exports = {};", "package/lib/helper.js": "module.exports.help = () => {};", "package/test/index.test.js": "// tests", - "package/notes.data": "short text\n", - "package/logo": "\x89PNG\r\n\x1a\nimage data", - "package/page": "", - "package/misleading.txt": "\x89PNG\r\n\x1a\nimage data", } for path, content := range files { @@ -349,7 +297,7 @@ func TestBrowseNonCachedArtifact(t *testing.T) { } // Try to browse - req := httptest.NewRequest("GET", "/ui/api/browse/npm/not-cached/1.0.0", nil) + req := httptest.NewRequest("GET", "/api/browse/npm/not-cached/1.0.0", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -403,7 +351,7 @@ func TestHandleBrowseSourcePage(t *testing.T) { } // Test the browse source page loads - req := httptest.NewRequest("GET", "/ui/package/npm/test-browse/1.0.0/browse", nil) + req := httptest.NewRequest("GET", "/package/npm/test-browse/1.0.0/browse", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -430,10 +378,6 @@ func TestHandleBrowseSourcePage(t *testing.T) { } } - if !strings.Contains(body, "proxy test-version (test-commit)") { - t.Error("browse source footer should contain proxy build information, not the package version") - } - // Check that the escapeHTML function is present for XSS protection if !strings.Contains(body, "function escapeHTML(str)") { t.Error("browse source page missing escapeHTML function for XSS protection") @@ -454,10 +398,8 @@ func TestHandleBrowseSourcePage(t *testing.T) { if !strings.Contains(body, "const packageName = 'test-browse'") { t.Error("browse source page missing packageName variable") } - // The version reaches the browse API as one path segment, so the page holds - // its escaped form. - if !strings.Contains(body, "const versionPath = '1.0.0'") { - t.Error("browse source page missing versionPath variable") + if !strings.Contains(body, "const version = '1.0.0'") { + t.Error("browse source page missing version variable") } // Verify content type @@ -542,7 +484,7 @@ func TestHandleCompareDiff(t *testing.T) { } // Test the compare endpoint - req := httptest.NewRequest("GET", "/ui/api/compare/npm/test-compare/1.0.0/2.0.0", nil) + req := httptest.NewRequest("GET", "/api/compare/npm/test-compare/1.0.0/2.0.0", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -613,7 +555,7 @@ func TestHandleComparePage(t *testing.T) { defer ts.close() // Test valid format with ... separator - req := httptest.NewRequest("GET", "/ui/package/npm/test/compare/1.0.0...2.0.0", nil) + req := httptest.NewRequest("GET", "/package/npm/test/compare/1.0.0...2.0.0", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -623,17 +565,16 @@ func TestHandleComparePage(t *testing.T) { body := w.Body.String() - // Check that versions are set correctly in JavaScript. The compare API takes - // each version as a path segment, so the page holds their escaped forms. - if !strings.Contains(body, "const fromVersionPath = '1.0.0'") { - t.Error("page should set fromVersionPath") + // Check that versions are set correctly in JavaScript + if !strings.Contains(body, "const fromVersion = '1.0.0'") { + t.Error("page should set fromVersion") } - if !strings.Contains(body, "const toVersionPath = '2.0.0'") { - t.Error("page should set toVersionPath") + if !strings.Contains(body, "const toVersion = '2.0.0'") { + t.Error("page should set toVersion") } // Test invalid format (missing separator) - req = httptest.NewRequest("GET", "/ui/package/npm/test/compare/invalid", nil) + req = httptest.NewRequest("GET", "/package/npm/test/compare/invalid", nil) w = httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -642,7 +583,7 @@ func TestHandleComparePage(t *testing.T) { } // Test with only one dot (should fail) - req = httptest.NewRequest("GET", "/ui/package/npm/test/compare/1.0.0.2.0.0", nil) + req = httptest.NewRequest("GET", "/package/npm/test/compare/1.0.0.2.0.0", nil) w = httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -651,27 +592,33 @@ func TestHandleComparePage(t *testing.T) { } } -func TestOpenArchiveDetectsExtensionlessTarGz(t *testing.T) { - reader, err := openArchive("artifact", bytes.NewReader(createTestArchive(t)), "npm") - if err != nil { - t.Fatalf("openArchive failed: %v", err) +func TestArchiveFilename(t *testing.T) { + tests := []struct { + input string + want string + }{ + {"package.tar.gz", "package.tar.gz"}, + {"d2e2f014ccd6ec9fae8dbe6336a4164346a2a856", "d2e2f014ccd6ec9fae8dbe6336a4164346a2a856.zip"}, + {"file.zip", "file.zip"}, + {"archive.tgz", "archive.tgz"}, + {"noext", "noext.zip"}, } - defer func() { _ = reader.Close() }() - files, err := reader.List() - if err != nil { - t.Fatalf("List failed: %v", err) - } - if len(files) == 0 { - t.Fatal("expected files in extensionless archive") + for _, tt := range tests { + t.Run(tt.input, func(t *testing.T) { + got := archiveFilename(tt.input) + if got != tt.want { + t.Errorf("archiveFilename(%q) = %q, want %q", tt.input, got, tt.want) + } + }) } } func TestOpenArchiveStripsSingleRootDir(t *testing.T) { data := createZipArchive(t, map[string]string{ - "repo-abc123/README.md": "hello", - "repo-abc123/src/main.go": "package main", - "repo-abc123/go.mod": "module test", + "repo-abc123/README.md": "hello", + "repo-abc123/src/main.go": "package main", + "repo-abc123/go.mod": "module test", }) reader, err := openArchive("test.zip", bytes.NewReader(data), "composer") if err != nil { @@ -836,70 +783,3 @@ func createTarGzArchive(t *testing.T, files map[string]string) []byte { } return buf.Bytes() } - -// TestFirstBrowsableArtifact guards artifact selection against PEP 658 -// core-metadata sidecars. A sidecar resolves to the same version as the -// distribution it describes, so it is cached under that version, but it is plain -// text and openArchive cannot parse it. -func TestFirstBrowsableArtifact(t *testing.T) { - cached := func(filename string) database.Artifact { - return database.Artifact{ - Filename: filename, - StoragePath: sql.NullString{String: "pypi/" + filename, Valid: true}, - } - } - uncached := func(filename string) database.Artifact { - return database.Artifact{Filename: filename} - } - - tests := []struct { - name string - artifacts []database.Artifact - want string - }{ - {"no artifacts", nil, ""}, - { - "sidecar only is not browsable", - []database.Artifact{cached("foo-1.0-py3-none-any.whl.metadata")}, - "", - }, - { - // '-' (0x2D) sorts before '.' (0x2E), so the sidecar precedes the - // sdist in the filename-ordered list the query returns. - "sidecar sorting ahead of the sdist is skipped", - []database.Artifact{cached("foo-1.0-py3-none-any.whl.metadata"), cached("foo-1.0.tar.gz")}, - "foo-1.0.tar.gz", - }, - { - "sidecar skipped in favour of its own wheel", - []database.Artifact{cached("foo-1.0-py3-none-any.whl.metadata"), cached("foo-1.0-py3-none-any.whl")}, - "foo-1.0-py3-none-any.whl", - }, - { - "uncached archive is still not selected", - []database.Artifact{cached("foo-1.0.tar.gz.metadata"), uncached("foo-1.0.tar.gz")}, - "", - }, - {"plain sdist", []database.Artifact{cached("foo-1.0.tar.gz")}, "foo-1.0.tar.gz"}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - got := firstBrowsableArtifact(tt.artifacts) - - if tt.want == "" { - if got != nil { - t.Fatalf("firstBrowsableArtifact() = %q, want nil", got.Filename) - } - return - } - - if got == nil { - t.Fatalf("firstBrowsableArtifact() = nil, want %q", tt.want) - } - if got.Filename != tt.want { - t.Errorf("firstBrowsableArtifact() = %q, want %q", got.Filename, tt.want) - } - }) - } -} diff --git a/internal/server/dashboard.go b/internal/server/dashboard.go index a3ac9eb..b935628 100644 --- a/internal/server/dashboard.go +++ b/internal/server/dashboard.go @@ -2,14 +2,12 @@ package server import ( "html/template" - "strings" "github.com/git-pkgs/proxy/internal/database" ) // DashboardData contains data for rendering the dashboard. type DashboardData struct { - Layout Stats DashboardStats EnrichmentStats EnrichmentStatsView RecentPackages []PackageInfo @@ -62,7 +60,6 @@ type RegistryConfig struct { // PackageShowData contains data for rendering the package show page. type PackageShowData struct { - Layout Package *database.Package Versions []database.Version Vulnerabilities []database.Vulnerability @@ -71,7 +68,6 @@ type PackageShowData struct { // VersionShowData contains data for rendering the version show page. type VersionShowData struct { - Layout Package *database.Package Version *database.Version Artifacts []database.Artifact @@ -83,7 +79,6 @@ type VersionShowData struct { // SearchPageData contains data for rendering the search results page. type SearchPageData struct { - Layout Query string Ecosystem string Results []SearchResultItem @@ -109,7 +104,6 @@ type SearchResultItem struct { // PackagesListPageData contains data for rendering the packages list page. type PackagesListPageData struct { - Layout Ecosystem string SortBy string Results []SearchResultItem @@ -124,7 +118,6 @@ func supportedEcosystems() []string { // that the 'select' list in the UI will be in the expected // order return []string{ - "alpine", "cargo", "composer", "conan", @@ -134,7 +127,6 @@ func supportedEcosystems() []string { "gem", "golang", "hex", - "julia", "maven", "npm", "nuget", @@ -142,7 +134,6 @@ func supportedEcosystems() []string { "pub", "pypi", "rpm", - "swift", } } @@ -185,30 +176,18 @@ func ecosystemBadgeClasses(ecosystem string) string { return base + " bg-green-100 text-green-700 dark:bg-green-900/50 dark:text-green-300" case "cran": return base + " bg-slate-100 text-slate-700 dark:bg-slate-800 dark:text-slate-300" - case "julia": - return base + " bg-emerald-100 text-emerald-700 dark:bg-emerald-900/50 dark:text-emerald-300" - case "swift": - return base + " bg-orange-100 text-orange-700 dark:bg-orange-900/50 dark:text-orange-300" case "oci": return base + " bg-sky-100 text-sky-700 dark:bg-sky-900/50 dark:text-sky-300" case "deb": return base + " bg-red-100 text-red-800 dark:bg-red-900/50 dark:text-red-300" case "rpm": return base + " bg-amber-100 text-amber-800 dark:bg-amber-900/50 dark:text-amber-300" - case "alpine": - return base + " bg-lime-100 text-lime-800 dark:bg-lime-900/50 dark:text-lime-300" default: return base + " bg-gray-100 text-gray-700 dark:bg-gray-800 dark:text-gray-300" } } func getRegistryConfigs(baseURL string) []RegistryConfig { - swiftInsecureFlag := "" - if strings.HasPrefix(strings.ToLower(baseURL), "http://") { - swiftInsecureFlag = "--allow-insecure-http " - } - dockerHost := strings.TrimPrefix(strings.TrimPrefix(baseURL, "https://"), "http://") - return []RegistryConfig{ { ID: "npm", @@ -307,20 +286,6 @@ index-url = ` + baseURL + `/pypi/simple/`), </mirror> </mirrors> </settings>`), - }, - { - ID: "gradle", - Name: "Gradle Build Cache", - Language: "Java/Kotlin", - Endpoint: "/gradle/", - Instructions: template.HTML(`

Configure Gradle to use the proxy for HttpBuildCache:

-
// In settings.gradle(.kts)
-buildCache {
-  remote<HttpBuildCache> {
-    url = uri("` + baseURL + `/gradle/")
-    push = true
-  }
-}
`), }, { ID: "nuget", @@ -398,26 +363,6 @@ local({ r["CRAN"] <- "` + baseURL + `/cran" options(repos = r) })`), - }, - { - ID: "julia", - Name: "Julia", - Language: "Julia", - Endpoint: "/julia/", - Instructions: template.HTML(`

Set the Pkg server before starting Julia:

-
export JULIA_PKG_SERVER=` + baseURL + `/julia
-

Or inside a running session:

-
ENV["JULIA_PKG_SERVER"] = "` + baseURL + `/julia"
-using Pkg; Pkg.update()
`), - }, - { - ID: "swift", - Name: "Swift Package Registry", - Language: "Swift", - Endpoint: "/swift/", - Instructions: template.HTML(`

Configure SwiftPM to use the proxy for this project:

-
swift package-registry set ` + swiftInsecureFlag + baseURL + `/swift
-

Use scoped package identifiers in Package.swift, for example apple.swift-argument-parser.

`), }, { ID: "oci", @@ -434,7 +379,7 @@ using Pkg; Pkg.update()`), sudo systemctl restart docker # Or pull directly -docker pull ` + dockerHost + `/library/nginx:latest`), +docker pull ` + baseURL[8:] + `/library/nginx:latest`), }, { ID: "deb", @@ -466,18 +411,5 @@ gpgcheck=0 sudo dnf clean all sudo dnf update`), }, - { - ID: "apk", - Name: "Alpine APK", - Language: "Alpine Linux", - Endpoint: "/apk/", - Instructions: template.HTML(`

Configure apk to use the proxy:

-
# In /etc/apk/repositories
-` + baseURL + `/apk/alpine/v3.22/main
-` + baseURL + `/apk/alpine/v3.22/community
-
-# Then run:
-apk update
`), - }, } } diff --git a/internal/server/ecr_auth.go b/internal/server/ecr_auth.go deleted file mode 100644 index ea46a32..0000000 --- a/internal/server/ecr_auth.go +++ /dev/null @@ -1,189 +0,0 @@ -package server - -import ( - "context" - "log/slog" - "net/url" - "strings" - "sync" - "time" - - awsconfig "github.com/aws/aws-sdk-go-v2/config" - "github.com/aws/aws-sdk-go-v2/service/ecr" - "golang.org/x/sync/singleflight" -) - -const ( - ecrTokenTimeout = 10 * time.Second - ecrTokenSkew = 5 * time.Minute - ecrTokenFailureBackoff = 30 * time.Second - ecrDefaultTokenLifetime = 12 * time.Hour -) - -// ecrTokens caches AWS ECR authorization tokens per region and refreshes them -// on demand when they expire. Tokens are obtained via the AWS SDK default -// credential chain, so IAM roles for service accounts, instance profiles, and -// environment credentials all work without extra configuration. -type ecrTokens struct { - logger *slog.Logger - - mu sync.Mutex - cache map[string]ecrToken - sf singleflight.Group - - // getToken fetches a fresh authorization token for the given region and - // returns the raw base64 "AWS:password" value plus its expiry. Overridable - // in tests. - getToken func(ctx context.Context, region string) (string, time.Time, error) -} - -type ecrToken struct { - value string - refreshAt time.Time - expiresAt time.Time -} - -func newECRTokens(logger *slog.Logger) *ecrTokens { - return &ecrTokens{ - logger: logger, - cache: make(map[string]ecrToken), - getToken: fetchECRToken, - } -} - -// header returns an Authorization header for the given region, fetching and -// caching a token on first use and shortly before expiry. Concurrent refreshes -// for the same region share a single GetAuthorizationToken call. If a refresh -// fails, a cached token remains available until its actual expiry and another -// refresh is delayed briefly. -func (e *ecrTokens) header(region string) (name, value string) { - if tok, ok := e.fresh(region); ok { - return tok.header() - } - - v, err, _ := e.sf.Do(region, func() (any, error) { - if tok, ok := e.fresh(region); ok { - return tok, nil - } - - ctx, cancel := context.WithTimeout(context.Background(), ecrTokenTimeout) - defer cancel() - - raw, expiresAt, err := e.getToken(ctx, region) - if err != nil { - e.logger.Error("fetching ECR authorization token", "region", region, "error", err) - return e.cacheFailure(region), nil - } - if raw == "" { - e.logger.Error("ECR authorization token response was empty", "region", region) - return e.cacheFailure(region), nil - } - - tok := ecrToken{ - value: "Basic " + raw, - refreshAt: expiresAt.Add(-ecrTokenSkew), - expiresAt: expiresAt, - } - e.store(region, tok) - return tok, nil - }) - if err != nil { - return "", "" - } - - return v.(ecrToken).header() -} - -func (t ecrToken) header() (name, value string) { - if t.value == "" { - return "", "" - } - return "Authorization", t.value -} - -func (e *ecrTokens) fresh(region string) (ecrToken, bool) { - tok, ok := e.cached(region) - return tok, ok && time.Now().Before(tok.refreshAt) -} - -func (e *ecrTokens) cacheFailure(region string) ecrToken { - now := time.Now() - retryAt := now.Add(ecrTokenFailureBackoff) - tok, ok := e.cached(region) - if ok && now.Before(tok.expiresAt) { - if retryAt.After(tok.expiresAt) { - retryAt = tok.expiresAt - } - tok.refreshAt = retryAt - } else { - tok = ecrToken{refreshAt: retryAt, expiresAt: retryAt} - } - e.store(region, tok) - return tok -} - -func (e *ecrTokens) cached(region string) (ecrToken, bool) { - e.mu.Lock() - tok, ok := e.cache[region] - e.mu.Unlock() - return tok, ok -} - -func (e *ecrTokens) store(region string, tok ecrToken) { - e.mu.Lock() - e.cache[region] = tok - e.mu.Unlock() -} - -func ecrRegion(rawURL string) string { - parsed, err := url.Parse(rawURL) - if err != nil { - return "" - } - - labels := strings.Split(strings.ToLower(parsed.Hostname()), ".") - for i := 1; i < len(labels); i++ { - if labels[i] == "dkr" && i+4 < len(labels) && (labels[i+1] == "ecr" || labels[i+1] == "ecr-fips") { - region := labels[i+2] - suffix := strings.Join(labels[i+3:], ".") - if region != "" && (suffix == "amazonaws.com" || suffix == "amazonaws.com.cn") { - return region - } - } - - if (labels[i] == "dkr-ecr" || labels[i] == "dkr-ecr-fips") && i+3 < len(labels) { - region := labels[i+1] - if region != "" && strings.Join(labels[i+2:], ".") == "on.aws" { - return region - } - } - } - - return "" -} - -func fetchECRToken(ctx context.Context, region string) (string, time.Time, error) { - var opts []func(*awsconfig.LoadOptions) error - if region != "" { - opts = append(opts, awsconfig.WithRegion(region)) - } - cfg, err := awsconfig.LoadDefaultConfig(ctx, opts...) - if err != nil { - return "", time.Time{}, err - } - - out, err := ecr.NewFromConfig(cfg).GetAuthorizationToken(ctx, &ecr.GetAuthorizationTokenInput{}) - if err != nil { - return "", time.Time{}, err - } - if len(out.AuthorizationData) == 0 || out.AuthorizationData[0].AuthorizationToken == nil { - return "", time.Time{}, nil - } - - data := out.AuthorizationData[0] - expiresAt := time.Now().Add(ecrDefaultTokenLifetime) - if data.ExpiresAt != nil { - expiresAt = *data.ExpiresAt - } - return *data.AuthorizationToken, expiresAt, nil -} diff --git a/internal/server/ecr_auth_test.go b/internal/server/ecr_auth_test.go deleted file mode 100644 index 904792b..0000000 --- a/internal/server/ecr_auth_test.go +++ /dev/null @@ -1,330 +0,0 @@ -package server - -import ( - "context" - "errors" - "io" - "log/slog" - "net/http" - "net/http/httptest" - "sync" - "sync/atomic" - "testing" - "time" - - "github.com/git-pkgs/proxy/internal/config" - "github.com/git-pkgs/proxy/internal/httpclient" -) - -func testECRTokens() *ecrTokens { - return newECRTokens(slog.New(slog.NewTextHandler(io.Discard, nil))) -} - -func TestECRTokensCachesUntilExpiry(t *testing.T) { - e := testECRTokens() - calls := 0 - e.getToken = func(_ context.Context, region string) (string, time.Time, error) { - calls++ - if region != "eu-west-1" { - t.Errorf("region = %q, want eu-west-1", region) - } - return "QVdTOnNlY3JldA==", time.Now().Add(12 * time.Hour), nil - } - - name, value := e.header("eu-west-1") - if name != "Authorization" || value != "Basic QVdTOnNlY3JldA==" { - t.Fatalf("header() = %q, %q", name, value) - } - - e.header("eu-west-1") - e.header("eu-west-1") - if calls != 1 { - t.Fatalf("getToken called %d times, want 1", calls) - } -} - -func TestECRTokensRefreshesWithinSkew(t *testing.T) { - e := testECRTokens() - calls := 0 - e.getToken = func(_ context.Context, _ string) (string, time.Time, error) { - calls++ - return "dG9rZW4=", time.Now().Add(time.Minute), nil - } - - e.header("us-east-1") - e.header("us-east-1") - if calls != 2 { - t.Fatalf("getToken called %d times, want 2 (token within skew window)", calls) - } -} - -func TestECRTokensUsesValidCachedTokenWhenRefreshFails(t *testing.T) { - e := testECRTokens() - calls := 0 - e.cache["eu-west-1"] = ecrToken{ - value: "Basic Y2FjaGVk", - refreshAt: time.Now().Add(-time.Minute), - expiresAt: time.Now().Add(time.Minute), - } - e.getToken = func(_ context.Context, _ string) (string, time.Time, error) { - calls++ - return "", time.Time{}, errors.New("ECR unavailable") - } - - name, value := e.header("eu-west-1") - if name != "Authorization" || value != "Basic Y2FjaGVk" { - t.Fatalf("header() = %q, %q; want cached token", name, value) - } - e.header("eu-west-1") - if calls != 1 { - t.Fatalf("getToken called %d times, want 1 during failure backoff", calls) - } -} - -func TestECRTokensRejectsExpiredCachedTokenWhenRefreshFails(t *testing.T) { - e := testECRTokens() - calls := 0 - e.cache["eu-west-1"] = ecrToken{ - value: "Basic ZXhwaXJlZA==", - refreshAt: time.Now().Add(-2 * time.Minute), - expiresAt: time.Now().Add(-time.Minute), - } - e.getToken = func(_ context.Context, _ string) (string, time.Time, error) { - calls++ - return "", time.Time{}, errors.New("ECR unavailable") - } - - name, value := e.header("eu-west-1") - if name != "" || value != "" { - t.Fatalf("header() = %q, %q; want empty for expired token", name, value) - } - e.header("eu-west-1") - if calls != 1 { - t.Fatalf("getToken called %d times, want 1 during failure backoff", calls) - } -} - -func TestECRTokensPerRegion(t *testing.T) { - e := testECRTokens() - seen := map[string]int{} - e.getToken = func(_ context.Context, region string) (string, time.Time, error) { - seen[region]++ - return region + "-token", time.Now().Add(time.Hour), nil - } - - e.header("eu-west-1") - e.header("us-east-1") - e.header("eu-west-1") - - if seen["eu-west-1"] != 1 || seen["us-east-1"] != 1 { - t.Fatalf("per-region calls = %v, want one each", seen) - } -} - -func TestECRTokensConcurrentMissesShareOneFetch(t *testing.T) { - e := testECRTokens() - var calls atomic.Int32 - started := make(chan struct{}) - release := make(chan struct{}) - var startedOnce sync.Once - e.getToken = func(_ context.Context, _ string) (string, time.Time, error) { - calls.Add(1) - startedOnce.Do(func() { close(started) }) - <-release - return "dG9rZW4=", time.Now().Add(time.Hour), nil - } - - const n = 10 - var wg sync.WaitGroup - wg.Add(n) - for range n { - go func() { - defer wg.Done() - name, value := e.header("eu-west-1") - if name != "Authorization" || value != "Basic dG9rZW4=" { - t.Errorf("header() = %q, %q", name, value) - } - }() - } - - <-started - time.Sleep(100 * time.Millisecond) - close(release) - wg.Wait() - - if got := calls.Load(); got != 1 { - t.Fatalf("getToken called %d times, want 1", got) - } -} - -func TestECRTokensBacksOffAfterError(t *testing.T) { - e := testECRTokens() - calls := 0 - e.getToken = func(_ context.Context, _ string) (string, time.Time, error) { - calls++ - return "", time.Time{}, errors.New("no credentials") - } - - name, value := e.header("eu-west-1") - if name != "" || value != "" { - t.Fatalf("header() = %q, %q; want empty on error", name, value) - } - e.header("eu-west-1") - if calls != 1 { - t.Fatalf("getToken called %d times, want 1 during failure backoff", calls) - } - - tok, ok := e.cached("eu-west-1") - if !ok { - t.Fatal("failure was not cached") - } - tok.refreshAt = time.Now().Add(-time.Second) - tok.expiresAt = tok.refreshAt - e.store("eu-west-1", tok) - e.header("eu-west-1") - if calls != 2 { - t.Fatalf("getToken called %d times, want retry after failure backoff", calls) - } -} - -func TestECRAuthFailureReturnsBasicChallengeResponse(t *testing.T) { - e := testECRTokens() - var tokenRequests atomic.Int32 - e.getToken = func(_ context.Context, _ string) (string, time.Time, error) { - tokenRequests.Add(1) - return "", time.Time{}, errors.New("no credentials") - } - - var upstreamRequests atomic.Int32 - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - upstreamRequests.Add(1) - if got := r.Header.Get("Authorization"); got != "" { - t.Errorf("Authorization = %q, want empty", got) - } - w.Header().Set("WWW-Authenticate", `Basic realm="Amazon ECR"`) - w.WriteHeader(http.StatusUnauthorized) - })) - defer upstream.Close() - - s := &Server{ - ecr: e, - cfg: &config.Config{Upstream: config.UpstreamConfig{ - Auth: map[string]config.AuthConfig{ - upstream.URL: {Type: "ecr"}, - }, - }}, - } - client := &http.Client{Transport: httpclient.NewTransport(http.DefaultTransport, s.authForURL)} - - resp, err := client.Get(upstream.URL + "/v2/repo/manifests/latest") - if err != nil { - t.Fatalf("GET upstream: %v", err) - } - defer func() { _ = resp.Body.Close() }() - if resp.StatusCode != http.StatusUnauthorized { - t.Errorf("status = %d, want %d", resp.StatusCode, http.StatusUnauthorized) - } - if got := resp.Header.Get("WWW-Authenticate"); got != `Basic realm="Amazon ECR"` { - t.Errorf("WWW-Authenticate = %q, want Basic challenge", got) - } - if got := tokenRequests.Load(); got != 1 { - t.Errorf("token requests = %d, want 1", got) - } - if got := upstreamRequests.Load(); got != 1 { - t.Errorf("upstream requests = %d, want 1", got) - } -} - -func TestECRRegion(t *testing.T) { - tests := []struct { - name string - url string - want string - }{ - {"commercial", "https://123456789012.dkr.ecr.eu-west-1.amazonaws.com/v2/repo", "eu-west-1"}, - {"China", "https://123456789012.dkr.ecr.cn-north-1.amazonaws.com.cn/v2/repo", "cn-north-1"}, - {"GovCloud", "https://123456789012.dkr.ecr.us-gov-west-1.amazonaws.com/v2/repo", "us-gov-west-1"}, - {"dual-stack", "https://123456789012.dkr-ecr.us-west-2.on.aws/v2/repo", "us-west-2"}, - {"FIPS", "https://123456789012.dkr.ecr-fips.us-east-1.amazonaws.com/v2/repo", "us-east-1"}, - {"FIPS dual-stack", "https://123456789012.dkr-ecr-fips.us-east-1.on.aws/v2/repo", "us-east-1"}, - {"case insensitive", "https://123456789012.DKR.ECR.EU-WEST-1.AMAZONAWS.COM/v2/repo", "eu-west-1"}, - {"lookalike suffix", "https://123456789012.dkr.ecr.eu-west-1.amazonaws.com.example/v2/repo", ""}, - {"not ECR", "https://registry.example.com/v2/repo", ""}, - {"invalid URL", "://invalid", ""}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - if got := ecrRegion(tt.url); got != tt.want { - t.Errorf("ecrRegion(%q) = %q, want %q", tt.url, got, tt.want) - } - }) - } -} - -func TestAuthForURLInfersECRRegion(t *testing.T) { - e := testECRTokens() - e.getToken = func(_ context.Context, region string) (string, time.Time, error) { - if region != "eu-west-1" { - t.Errorf("region = %q, want eu-west-1", region) - } - return "QVdTOnNlY3JldA==", time.Now().Add(time.Hour), nil - } - - s := &Server{ - ecr: e, - cfg: &config.Config{Upstream: config.UpstreamConfig{ - Auth: map[string]config.AuthConfig{ - "https://123456789012.dkr.ecr.eu-west-1.amazonaws.com": {Type: "ecr"}, - }, - }}, - } - - name, value := s.authForURL("https://123456789012.dkr.ecr.eu-west-1.amazonaws.com/v2/repo") - if name != "Authorization" || value != "Basic QVdTOnNlY3JldA==" { - t.Fatalf("authForURL() = %q, %q", name, value) - } -} - -func TestAuthForURLRoutesECRType(t *testing.T) { - e := testECRTokens() - e.getToken = func(_ context.Context, region string) (string, time.Time, error) { - if region != "eu-west-1" { - t.Errorf("region = %q, want eu-west-1", region) - } - return "QVdTOnNlY3JldA==", time.Now().Add(time.Hour), nil - } - - s := &Server{ - ecr: e, - cfg: &config.Config{ - Upstream: config.UpstreamConfig{ - Auth: map[string]config.AuthConfig{ - "https://123456789012.dkr.ecr.eu-west-1.amazonaws.com": { - Type: "ecr", - Region: "eu-west-1", - }, - "https://ghcr.io": { - Type: "bearer", - Token: "ghcr-token", - }, - }, - }, - }, - } - - name, value := s.authForURL("https://123456789012.dkr.ecr.eu-west-1.amazonaws.com/v2/my/repo/manifests/latest") - if name != "Authorization" || value != "Basic QVdTOnNlY3JldA==" { - t.Fatalf("ecr authForURL() = %q, %q", name, value) - } - - name, value = s.authForURL("https://ghcr.io/v2/owner/repo/blobs/sha256:abc") - if name != "Authorization" || value != "Bearer ghcr-token" { - t.Fatalf("bearer authForURL() = %q, %q", name, value) - } - - name, value = s.authForURL("https://registry-1.docker.io/v2/") - if name != "" || value != "" { - t.Fatalf("unmatched authForURL() = %q, %q; want empty", name, value) - } -} diff --git a/internal/server/errors.go b/internal/server/errors.go deleted file mode 100644 index 474ecd7..0000000 --- a/internal/server/errors.go +++ /dev/null @@ -1,42 +0,0 @@ -package server - -import ( - "encoding/json" - "net/http" -) - -// Error codes returned in API error responses. These are stable identifiers -// that clients can match on; the message text is for humans and may change. -const ( - ErrCodeBadRequest = "BAD_REQUEST" - ErrCodeNotFound = "NOT_FOUND" - ErrCodeUpstream = "UPSTREAM_ERROR" - ErrCodeInternal = "INTERNAL_ERROR" -) - -// ErrorResponse is the JSON body returned for API errors. -type ErrorResponse struct { - Code string `json:"code"` - Message string `json:"message"` -} - -// writeError sends a JSON error response with the given status, code and -// user-facing message. Internal error details should be logged separately -// by the caller, never passed as the message. -func writeError(w http.ResponseWriter, status int, code, message string) { - w.Header().Set("Content-Type", "application/json") - w.WriteHeader(status) - _ = json.NewEncoder(w).Encode(ErrorResponse{Code: code, Message: message}) -} - -func badRequest(w http.ResponseWriter, message string) { - writeError(w, http.StatusBadRequest, ErrCodeBadRequest, message) -} - -func notFound(w http.ResponseWriter, message string) { - writeError(w, http.StatusNotFound, ErrCodeNotFound, message) -} - -func internalError(w http.ResponseWriter, message string) { - writeError(w, http.StatusInternalServerError, ErrCodeInternal, message) -} diff --git a/internal/server/errors_test.go b/internal/server/errors_test.go deleted file mode 100644 index c660ae2..0000000 --- a/internal/server/errors_test.go +++ /dev/null @@ -1,93 +0,0 @@ -package server - -import ( - "encoding/json" - "net/http" - "net/http/httptest" - "testing" -) - -func TestWriteError(t *testing.T) { - tests := []struct { - name string - fn func(w http.ResponseWriter) - status int - code string - message string - }{ - { - name: "badRequest", - fn: func(w http.ResponseWriter) { badRequest(w, "missing field") }, - status: http.StatusBadRequest, - code: ErrCodeBadRequest, - message: "missing field", - }, - { - name: "notFound", - fn: func(w http.ResponseWriter) { notFound(w, "package not found") }, - status: http.StatusNotFound, - code: ErrCodeNotFound, - message: "package not found", - }, - { - name: "internalError", - fn: func(w http.ResponseWriter) { internalError(w, "boom") }, - status: http.StatusInternalServerError, - code: ErrCodeInternal, - message: "boom", - }, - { - name: "upstream", - fn: func(w http.ResponseWriter) { - writeError(w, http.StatusBadGateway, ErrCodeUpstream, "registry unreachable") - }, - status: http.StatusBadGateway, - code: ErrCodeUpstream, - message: "registry unreachable", - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - w := httptest.NewRecorder() - tt.fn(w) - - if w.Code != tt.status { - t.Errorf("status = %d, want %d", w.Code, tt.status) - } - if ct := w.Header().Get("Content-Type"); ct != "application/json" { - t.Errorf("Content-Type = %q, want application/json", ct) - } - - var resp ErrorResponse - if err := json.Unmarshal(w.Body.Bytes(), &resp); err != nil { - t.Fatalf("response body is not valid JSON: %v (body: %q)", err, w.Body.String()) - } - if resp.Code != tt.code { - t.Errorf("code = %q, want %q", resp.Code, tt.code) - } - if resp.Message != tt.message { - t.Errorf("message = %q, want %q", resp.Message, tt.message) - } - }) - } -} - -func TestAPIErrorResponseShape(t *testing.T) { - w := httptest.NewRecorder() - badRequest(w, "x") - - var raw map[string]any - if err := json.Unmarshal(w.Body.Bytes(), &raw); err != nil { - t.Fatalf("invalid JSON: %v", err) - } - if _, ok := raw["code"]; !ok { - t.Error("response missing 'code' field") - } - if _, ok := raw["message"]; !ok { - t.Error("response missing 'message' field") - } - if len(raw) != 2 { - t.Errorf("response has unexpected fields: %v", raw) - } -} diff --git a/internal/server/eviction.go b/internal/server/eviction.go deleted file mode 100644 index 4173bd5..0000000 --- a/internal/server/eviction.go +++ /dev/null @@ -1,105 +0,0 @@ -package server - -import ( - "context" - "log/slog" - "time" - - "github.com/git-pkgs/proxy/internal/database" - "github.com/git-pkgs/proxy/internal/storage" -) - -const ( - evictionInterval = 1 * time.Minute - evictionBatch = 50 -) - -func (s *Server) startEvictionLoop(ctx context.Context) { - maxSize := s.cfg.ParseMaxSize() - if maxSize <= 0 { - return - } - - s.logger.Info("cache eviction enabled", "max_size", s.cfg.Storage.MaxSize) - - ticker := time.NewTicker(evictionInterval) - defer ticker.Stop() - - s.runEviction(ctx, maxSize) - - for { - select { - case <-ctx.Done(): - return - case <-ticker.C: - s.runEviction(ctx, maxSize) - } - } -} - -func (s *Server) runEviction(ctx context.Context, maxSize int64) { - evictLRU(ctx, s.db, s.storage, s.logger, maxSize) -} - -func evictLRU(ctx context.Context, db *database.DB, store storage.Storage, logger *slog.Logger, maxSize int64) { - totalSize, err := db.GetTotalCacheSize() - if err != nil { - logger.Warn("eviction: failed to get cache size", "error", err) - return - } - - if totalSize <= maxSize { - return - } - - logger.Info("eviction: cache size exceeds limit, evicting", - "current_size", totalSize, "max_size", maxSize) - - evicted := 0 - freedBytes := int64(0) - - for totalSize-freedBytes > maxSize { - artifacts, err := db.GetLeastRecentlyUsedArtifacts(evictionBatch) - if err != nil { - logger.Warn("eviction: failed to get LRU artifacts", "error", err) - return - } - if len(artifacts) == 0 { - break - } - - for _, art := range artifacts { - if totalSize-freedBytes <= maxSize { - break - } - - if !art.StoragePath.Valid { - continue - } - - if err := store.Delete(ctx, art.StoragePath.String); err != nil { - logger.Warn("eviction: failed to delete from storage", - "path", art.StoragePath.String, "error", err) - continue - } - - if err := db.ClearArtifactCache(art.VersionPURL, art.Filename); err != nil { - logger.Warn("eviction: failed to clear artifact record", - "version_purl", art.VersionPURL, "filename", art.Filename, "error", err) - continue - } - - size := int64(0) - if art.Size.Valid { - size = art.Size.Int64 - } - freedBytes += size - evicted++ - } - } - - if evicted > 0 { - logger.Info("eviction: completed", - "evicted", evicted, "freed_bytes", freedBytes) - } -} diff --git a/internal/server/eviction_test.go b/internal/server/eviction_test.go deleted file mode 100644 index bac3325..0000000 --- a/internal/server/eviction_test.go +++ /dev/null @@ -1,295 +0,0 @@ -package server - -import ( - "context" - "database/sql" - "io" - "log/slog" - "path/filepath" - "strings" - "testing" - "time" - - "github.com/git-pkgs/proxy/internal/config" - "github.com/git-pkgs/proxy/internal/database" - "github.com/git-pkgs/proxy/internal/storage" -) - -func setupEvictionTest(t *testing.T) (*database.DB, *storage.Blob) { - t.Helper() - - tempDir := t.TempDir() - dbPath := filepath.Join(tempDir, "test.db") - storagePath := filepath.Join(tempDir, "artifacts") - - db, err := database.Create(dbPath) - if err != nil { - t.Fatalf("failed to create database: %v", err) - } - - store, err := storage.OpenBucket(context.Background(), "file://"+storagePath) - if err != nil { - _ = db.Close() - t.Fatalf("failed to create storage: %v", err) - } - blob, ok := store.(*storage.Blob) - if !ok { - _ = db.Close() - t.Fatalf("OpenBucket returned %T, want *storage.Blob", store) - } - - t.Cleanup(func() { - _ = db.Close() - }) - - return db, blob -} - -func seedArtifact(t *testing.T, ctx context.Context, db *database.DB, store storage.Storage, name string, dataSize int, accessedAt time.Time) { - t.Helper() - - pkgPURL := "pkg:npm/" + name - versionPURL := pkgPURL + "@1.0.0" - filename := name + "-1.0.0.tgz" - - if err := db.UpsertPackage(&database.Package{ - PURL: pkgPURL, - Ecosystem: "npm", - Name: name, - }); err != nil { - t.Fatalf("failed to upsert package: %v", err) - } - - if err := db.UpsertVersion(&database.Version{ - PURL: versionPURL, - PackagePURL: pkgPURL, - }); err != nil { - t.Fatalf("failed to upsert version: %v", err) - } - - storagePath := storage.ArtifactPath("npm", "", name, "1.0.0", filename) - data := strings.NewReader(strings.Repeat("x", dataSize)) - size, hash, err := store.Store(ctx, storagePath, data) - if err != nil { - t.Fatalf("failed to store artifact: %v", err) - } - - if err := db.UpsertArtifact(&database.Artifact{ - VersionPURL: versionPURL, - Filename: filename, - UpstreamURL: "https://example.com/" + filename, - StoragePath: sql.NullString{String: storagePath, Valid: true}, - ContentHash: sql.NullString{String: hash, Valid: true}, - Size: sql.NullInt64{Int64: size, Valid: true}, - ContentType: sql.NullString{String: "application/gzip", Valid: true}, - FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, - LastAccessedAt: sql.NullTime{Time: accessedAt, Valid: true}, - }); err != nil { - t.Fatalf("failed to upsert artifact: %v", err) - } -} - -func TestEvictLRU_NoEvictionWhenUnderLimit(t *testing.T) { - db, store := setupEvictionTest(t) - ctx := context.Background() - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - - seedArtifact(t, ctx, db, store, "pkg-a", 100, time.Now()) - - evictLRU(ctx, db, store, logger, 1024) - - count, err := db.GetCachedArtifactCount() - if err != nil { - t.Fatalf("failed to get count: %v", err) - } - if count != 1 { - t.Errorf("expected 1 cached artifact, got %d", count) - } -} - -func TestEvictLRU_EvictsOldestFirst(t *testing.T) { - db, store := setupEvictionTest(t) - ctx := context.Background() - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - - now := time.Now() - seedArtifact(t, ctx, db, store, "old-pkg", 500, now.Add(-3*time.Hour)) - seedArtifact(t, ctx, db, store, "mid-pkg", 500, now.Add(-1*time.Hour)) - seedArtifact(t, ctx, db, store, "new-pkg", 500, now) - - // Total is 1500 bytes, limit to 1100 so only the oldest gets evicted - evictLRU(ctx, db, store, logger, 1100) - - // old-pkg should be evicted - art, err := db.GetArtifact("pkg:npm/old-pkg@1.0.0", "old-pkg-1.0.0.tgz") - if err != nil { - t.Fatalf("failed to get artifact: %v", err) - } - if art.StoragePath.Valid { - t.Error("expected old-pkg to be evicted (storage_path should be NULL)") - } - - // mid-pkg and new-pkg should remain - art, err = db.GetArtifact("pkg:npm/mid-pkg@1.0.0", "mid-pkg-1.0.0.tgz") - if err != nil { - t.Fatalf("failed to get artifact: %v", err) - } - if !art.StoragePath.Valid { - t.Error("expected mid-pkg to remain cached") - } - - art, err = db.GetArtifact("pkg:npm/new-pkg@1.0.0", "new-pkg-1.0.0.tgz") - if err != nil { - t.Fatalf("failed to get artifact: %v", err) - } - if !art.StoragePath.Valid { - t.Error("expected new-pkg to remain cached") - } - - // Storage file should be removed for old-pkg - storagePath := storage.ArtifactPath("npm", "", "old-pkg", "1.0.0", "old-pkg-1.0.0.tgz") - exists, _ := store.Exists(ctx, storagePath) - if exists { - t.Error("expected old-pkg file to be deleted from storage") - } -} - -func TestEvictLRU_EvictsMultipleToGetUnderLimit(t *testing.T) { - db, store := setupEvictionTest(t) - ctx := context.Background() - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - - now := time.Now() - seedArtifact(t, ctx, db, store, "pkg-1", 400, now.Add(-4*time.Hour)) - seedArtifact(t, ctx, db, store, "pkg-2", 400, now.Add(-3*time.Hour)) - seedArtifact(t, ctx, db, store, "pkg-3", 400, now.Add(-2*time.Hour)) - seedArtifact(t, ctx, db, store, "pkg-4", 400, now) - - // Total is 1600 bytes, limit to 900 so pkg-1 and pkg-2 get evicted - evictLRU(ctx, db, store, logger, 900) - - count, err := db.GetCachedArtifactCount() - if err != nil { - t.Fatalf("failed to get count: %v", err) - } - if count != 2 { - t.Errorf("expected 2 cached artifacts remaining, got %d", count) - } - - // Verify the right ones remain - for _, name := range []string{"pkg-3", "pkg-4"} { - art, err := db.GetArtifact("pkg:npm/"+name+"@1.0.0", name+"-1.0.0.tgz") - if err != nil { - t.Fatalf("failed to get artifact %s: %v", name, err) - } - if !art.StoragePath.Valid { - t.Errorf("expected %s to remain cached", name) - } - } -} - -func TestEvictLRU_NothingToEvictWhenEmpty(t *testing.T) { - db, store := setupEvictionTest(t) - ctx := context.Background() - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - - // Should not panic or error with no artifacts - evictLRU(ctx, db, store, logger, 1024) - - count, err := db.GetCachedArtifactCount() - if err != nil { - t.Fatalf("failed to get count: %v", err) - } - if count != 0 { - t.Errorf("expected 0 cached artifacts, got %d", count) - } -} - -func TestEvictLRU_StorageFileDeleted(t *testing.T) { - db, store := setupEvictionTest(t) - ctx := context.Background() - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - - seedArtifact(t, ctx, db, store, "delete-me", 1000, time.Now().Add(-1*time.Hour)) - - storagePath := storage.ArtifactPath("npm", "", "delete-me", "1.0.0", "delete-me-1.0.0.tgz") - exists, _ := store.Exists(ctx, storagePath) - if !exists { - t.Fatal("expected artifact file to exist before eviction") - } - - evictLRU(ctx, db, store, logger, 500) - - exists, _ = store.Exists(ctx, storagePath) - if exists { - t.Error("expected artifact file to be deleted after eviction") - } - - art, err := db.GetArtifact("pkg:npm/delete-me@1.0.0", "delete-me-1.0.0.tgz") - if err != nil { - t.Fatalf("failed to get artifact: %v", err) - } - if art.StoragePath.Valid { - t.Error("expected storage_path to be NULL after eviction") - } - if art.Size.Valid { - t.Error("expected size to be NULL after eviction") - } -} - -func TestStartEvictionLoop_UnlimitedSkips(t *testing.T) { - tempDir := t.TempDir() - dbPath := filepath.Join(tempDir, "test.db") - storagePath := filepath.Join(tempDir, "artifacts") - - db, err := database.Create(dbPath) - if err != nil { - t.Fatalf("failed to create database: %v", err) - } - defer func() { _ = db.Close() }() - - store, err := storage.OpenBucket(context.Background(), "file://"+storagePath) - if err != nil { - t.Fatalf("failed to create storage: %v", err) - } - - cfg := defaultTestConfig(storagePath, dbPath) - - s := &Server{ - cfg: cfg, - db: db, - storage: store, - logger: slog.New(slog.NewTextHandler(io.Discard, nil)), - } - - ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond) - defer cancel() - - // Should return immediately since max_size is empty (unlimited) - done := make(chan struct{}) - go func() { - s.startEvictionLoop(ctx) - close(done) - }() - - select { - case <-done: - // Good, returned immediately - case <-time.After(1 * time.Second): - t.Error("startEvictionLoop should return immediately when max_size is unlimited") - cancel() - } -} - -func defaultTestConfig(storagePath, dbPath string) *config.Config { - return &config.Config{ - Listen: ":8080", - BaseURL: "http://localhost:8080", - Storage: config.StorageConfig{URL: "file://" + storagePath, MaxSize: ""}, - Database: config.DatabaseConfig{ - Driver: "sqlite", - Path: dbPath, - }, - Log: config.LogConfig{Level: "info", Format: "text"}, - } -} diff --git a/internal/server/gradle_cache_eviction.go b/internal/server/gradle_cache_eviction.go deleted file mode 100644 index 7f546d1..0000000 --- a/internal/server/gradle_cache_eviction.go +++ /dev/null @@ -1,149 +0,0 @@ -package server - -import ( - "context" - "fmt" - "sort" - "time" - - "github.com/git-pkgs/proxy/internal/storage" -) - -const gradleBuildCacheStoragePrefix = "_gradle/http-build-cache/" - -type gradleBuildCacheLister interface { - ListPrefix(ctx context.Context, prefix string) ([]storage.ObjectInfo, error) -} - -func (s *Server) startGradleBuildCacheEviction(ctx context.Context) { - maxAge := s.cfg.ParseGradleBuildCacheMaxAge() - maxSize := s.cfg.ParseGradleBuildCacheMaxSize() - if maxAge <= 0 && maxSize <= 0 { - return - } - - lister, ok := s.storage.(gradleBuildCacheLister) - if !ok { - s.logger.Warn("gradle cache eviction is enabled, but storage backend cannot list objects") - return - } - - interval := s.cfg.ParseGradleBuildCacheSweepInterval() - s.logger.Info("gradle cache eviction enabled", - "max_age", maxAge, - "max_size_bytes", maxSize, - "interval", interval) - - sweep := func() { - deletedCount, freedBytes, err := sweepGradleBuildCache(ctx, s.storage, lister, maxAge, maxSize, time.Now()) - if err != nil { - s.logger.Warn("gradle cache eviction sweep failed", "error", err) - return - } - if deletedCount > 0 { - s.logger.Info("gradle cache eviction sweep completed", - "deleted_entries", deletedCount, - "freed_bytes", freedBytes) - } - } - - sweep() - - go func() { - ticker := time.NewTicker(interval) - defer ticker.Stop() - - for { - select { - case <-ctx.Done(): - return - case <-ticker.C: - sweep() - } - } - }() -} - -func sweepGradleBuildCache( - ctx context.Context, - store storage.Storage, - lister gradleBuildCacheLister, - maxAge time.Duration, - maxSize int64, - now time.Time, -) (int, int64, error) { - entries, err := lister.ListPrefix(ctx, gradleBuildCacheStoragePrefix) - if err != nil { - return 0, 0, fmt.Errorf("listing gradle cache entries: %w", err) - } - - if len(entries) == 0 { - return 0, 0, nil - } - - sortOldestFirst(entries) - - deletedCount := 0 - freedBytes := int64(0) - var firstDeleteErr error - - deleteEntry := func(entry storage.ObjectInfo) bool { - if err := store.Delete(ctx, entry.Path); err != nil { - if firstDeleteErr == nil { - firstDeleteErr = err - } - return false - } - deletedCount++ - freedBytes += entry.Size - return true - } - - remaining := entries - if maxAge > 0 { - cutoff := now.Add(-maxAge) - kept := make([]storage.ObjectInfo, 0, len(entries)) - - for _, entry := range entries { - if !entry.ModTime.IsZero() && entry.ModTime.Before(cutoff) { - if deleteEntry(entry) { - continue - } - } - kept = append(kept, entry) - } - - remaining = kept - } - - if maxSize > 0 { - totalSize := int64(0) - for _, entry := range remaining { - totalSize += entry.Size - } - - for _, entry := range remaining { - if totalSize <= maxSize { - break - } - if deleteEntry(entry) { - totalSize -= entry.Size - } - } - } - - if firstDeleteErr != nil { - return deletedCount, freedBytes, fmt.Errorf("deleting gradle cache entries: %w", firstDeleteErr) - } - - return deletedCount, freedBytes, nil -} - -func sortOldestFirst(entries []storage.ObjectInfo) { - sort.Slice(entries, func(i, j int) bool { - if entries[i].ModTime.Equal(entries[j].ModTime) { - return entries[i].Path < entries[j].Path - } - return entries[i].ModTime.Before(entries[j].ModTime) - }) -} diff --git a/internal/server/gradle_cache_eviction_test.go b/internal/server/gradle_cache_eviction_test.go deleted file mode 100644 index 4e97507..0000000 --- a/internal/server/gradle_cache_eviction_test.go +++ /dev/null @@ -1,138 +0,0 @@ -package server - -import ( - "bytes" - "context" - "io" - "strings" - "testing" - "time" - - "github.com/git-pkgs/proxy/internal/storage" -) - -type fakeGradleCacheStore struct { - objects map[string]storage.ObjectInfo -} - -func newFakeGradleCacheStore(objects []storage.ObjectInfo) *fakeGradleCacheStore { - m := make(map[string]storage.ObjectInfo, len(objects)) - for _, obj := range objects { - m[obj.Path] = obj - } - return &fakeGradleCacheStore{objects: m} -} - -func (s *fakeGradleCacheStore) Store(_ context.Context, path string, r io.Reader) (int64, string, error) { - data, _ := io.ReadAll(r) - s.objects[path] = storage.ObjectInfo{Path: path, Size: int64(len(data)), ModTime: time.Now()} - return int64(len(data)), "", nil -} - -func (s *fakeGradleCacheStore) Open(_ context.Context, path string) (io.ReadCloser, error) { - obj, ok := s.objects[path] - if !ok { - return nil, storage.ErrNotFound - } - return io.NopCloser(bytes.NewReader(make([]byte, obj.Size))), nil -} - -func (s *fakeGradleCacheStore) Exists(_ context.Context, path string) (bool, error) { - _, ok := s.objects[path] - return ok, nil -} - -func (s *fakeGradleCacheStore) Delete(_ context.Context, path string) error { - delete(s.objects, path) - return nil -} - -func (s *fakeGradleCacheStore) Size(_ context.Context, path string) (int64, error) { - obj, ok := s.objects[path] - if !ok { - return 0, storage.ErrNotFound - } - return obj.Size, nil -} - -func (s *fakeGradleCacheStore) SignedURL(_ context.Context, _ string, _ time.Duration) (string, error) { - return "", storage.ErrSignedURLUnsupported -} - -func (s *fakeGradleCacheStore) UsedSpace(_ context.Context) (int64, error) { - var total int64 - for _, obj := range s.objects { - total += obj.Size - } - return total, nil -} - -func (s *fakeGradleCacheStore) URL() string { return "mem://" } - -func (s *fakeGradleCacheStore) Close() error { return nil } - -func (s *fakeGradleCacheStore) ListPrefix(_ context.Context, prefix string) ([]storage.ObjectInfo, error) { - objects := make([]storage.ObjectInfo, 0) - for _, obj := range s.objects { - if strings.HasPrefix(obj.Path, prefix) { - objects = append(objects, obj) - } - } - return objects, nil -} - -func TestSweepGradleBuildCache_MaxAge(t *testing.T) { - now := time.Date(2026, 4, 27, 12, 0, 0, 0, time.UTC) - store := newFakeGradleCacheStore([]storage.ObjectInfo{ - {Path: "_gradle/http-build-cache/old", Size: 10, ModTime: now.Add(-48 * time.Hour)}, - {Path: "_gradle/http-build-cache/new", Size: 10, ModTime: now.Add(-2 * time.Hour)}, - }) - - deleted, freed, err := sweepGradleBuildCache(context.Background(), store, store, 24*time.Hour, 0, now) - if err != nil { - t.Fatalf("sweepGradleBuildCache() error = %v", err) - } - if deleted != 1 { - t.Fatalf("deleted entries = %d, want 1", deleted) - } - if freed != 10 { - t.Fatalf("freed bytes = %d, want 10", freed) - } - - if _, ok := store.objects["_gradle/http-build-cache/old"]; ok { - t.Fatal("old entry was not deleted") - } - if _, ok := store.objects["_gradle/http-build-cache/new"]; !ok { - t.Fatal("new entry should remain") - } -} - -func TestSweepGradleBuildCache_MaxSizeOldestFirst(t *testing.T) { - now := time.Date(2026, 4, 27, 12, 0, 0, 0, time.UTC) - store := newFakeGradleCacheStore([]storage.ObjectInfo{ - {Path: "_gradle/http-build-cache/a", Size: 5, ModTime: now.Add(-3 * time.Hour)}, - {Path: "_gradle/http-build-cache/b", Size: 5, ModTime: now.Add(-2 * time.Hour)}, - {Path: "_gradle/http-build-cache/c", Size: 5, ModTime: now.Add(-1 * time.Hour)}, - }) - - deleted, freed, err := sweepGradleBuildCache(context.Background(), store, store, 0, 10, now) - if err != nil { - t.Fatalf("sweepGradleBuildCache() error = %v", err) - } - if deleted != 1 { - t.Fatalf("deleted entries = %d, want 1", deleted) - } - if freed != 5 { - t.Fatalf("freed bytes = %d, want 5", freed) - } - - if _, ok := store.objects["_gradle/http-build-cache/a"]; ok { - t.Fatal("oldest entry was not deleted") - } - if _, ok := store.objects["_gradle/http-build-cache/b"]; !ok { - t.Fatal("middle entry should remain") - } - if _, ok := store.objects["_gradle/http-build-cache/c"]; !ok { - t.Fatal("newest entry should remain") - } -} diff --git a/internal/server/health.go b/internal/server/health.go deleted file mode 100644 index 9533bd5..0000000 --- a/internal/server/health.go +++ /dev/null @@ -1,190 +0,0 @@ -// Package server implements the proxy HTTP server. -package server - -import ( - "bytes" - "context" - "crypto/rand" - "encoding/hex" - "errors" - "fmt" - "io" - "log/slog" - "strconv" - "sync" - "time" - - "github.com/git-pkgs/proxy/internal/metrics" - "github.com/git-pkgs/proxy/internal/storage" -) - -const ( - probePathPrefix = ".healthcheck/" - probeMarker = "proxy-healthcheck:" - probeSuffixBytes = 8 - defaultProbeTTL = 30 * time.Second - defaultProbeTimeout = 10 * time.Second -) - -// HealthResponse is the JSON payload returned by /health. -type HealthResponse struct { - Status string `json:"status"` - Checks map[string]HealthCheck `json:"checks"` - // CircuitBreakers reports the state ("open" or "closed") of each upstream - // registry's artifact-fetch circuit breaker, keyed by the host fetched from - // or, where the fetch URL has none to read, by an opaque placeholder - // standing in for it. It is omitted when no breaker has been created yet. - // An open breaker fails every artifact fetch it covers without contacting - // the upstream, but says nothing about this proxy's own health, so it does - // not change Status. - CircuitBreakers map[string]string `json:"circuit_breakers,omitempty"` -} - -// HealthCheck reports the status of a single subsystem check. -type HealthCheck struct { - Status string `json:"status"` - Error string `json:"error,omitempty"` - Step string `json:"step,omitempty"` -} - -// probeError tags a storage probe failure with the step that failed. -type probeError struct { - step string - err error -} - -func (e *probeError) Error() string { return e.step + ": " + e.err.Error() } -func (e *probeError) Unwrap() error { return e.err } - -// storageProbe runs a write → size-check → read → verify → delete round-trip -// against the storage backend. Returns nil on success or a *probeError on failure. -func storageProbe(ctx context.Context, s storage.Storage) (err error) { - suffix, suffixErr := randomSuffix() - if suffixErr != nil { - return &probeError{step: "write", err: fmt.Errorf("generating random suffix: %w", suffixErr)} - } - path := probePathPrefix + strconv.FormatInt(time.Now().UnixNano(), 10) + "-" + suffix - payload := []byte(probeMarker + suffix) - - // 1. Store - size, _, storeErr := s.Store(ctx, path, bytes.NewReader(payload)) - if storeErr != nil { - return &probeError{step: "write", err: storeErr} - } - // After Store succeeds, always attempt to delete on the way out so probe - // objects don't accumulate when a later step (size/open/read/verify) fails. - // Delete is reported as the primary error only if no earlier failure - // already set one. - defer func() { - if delErr := s.Delete(ctx, path); delErr != nil && err == nil { - err = &probeError{step: "delete", err: delErr} - } - }() - // 2. Size check - if size != int64(len(payload)) { - return &probeError{step: "size", err: fmt.Errorf("wrote %d bytes, expected %d", size, len(payload))} - } - // 3. Open - rc, openErr := s.Open(ctx, path) - if openErr != nil { - return &probeError{step: "read", err: openErr} - } - // 4. Read all (classify mid-stream errors as read, not verify). - // Close explicitly (not deferred) so the file handle is released before - // Delete — on Windows, an open handle prevents deletion. - data, readErr := io.ReadAll(rc) - _ = rc.Close() - if readErr != nil { - return &probeError{step: "read", err: readErr} - } - // 5. Verify - if !bytes.Equal(data, payload) { - return &probeError{step: "verify", err: fmt.Errorf("content mismatch")} - } - // 6. Delete is handled via the deferred cleanup above. - return nil -} - -// randomSuffix returns 8 cryptographically random bytes hex-encoded. -func randomSuffix() (string, error) { - b := make([]byte, probeSuffixBytes) - if _, err := rand.Read(b); err != nil { - return "", err - } - return hex.EncodeToString(b), nil -} - -// healthCache memoizes the result of storageProbe for a configurable TTL. -// It is safe for concurrent use. -type healthCache struct { - storage storage.Storage - interval time.Duration - probeTimeout time.Duration - logger *slog.Logger - - mu sync.Mutex - lastAt time.Time - lastErr error -} - -// newHealthCache builds a cache, parsing the interval from a duration string. -// Empty interval string defaults to 30s. "0" or "0s" disables caching. -func newHealthCache(s storage.Storage, intervalStr string, logger *slog.Logger) (*healthCache, error) { - interval := defaultProbeTTL - if intervalStr != "" { - d, err := time.ParseDuration(intervalStr) - if err != nil { - return nil, fmt.Errorf("parsing storage_probe_interval %q: %w", intervalStr, err) - } - interval = d - } - return &healthCache{ - storage: s, - interval: interval, - probeTimeout: defaultProbeTimeout, - logger: logger, - }, nil -} - -// Check returns the cached probe result if still fresh, otherwise runs a fresh probe. -// The probe runs under a context derived from context.Background() with a fixed -// timeout so that caller cancellation (e.g. client disconnect) cannot poison the -// cache with context.Canceled. -func (c *healthCache) Check() error { - c.mu.Lock() - defer c.mu.Unlock() - - // Cache hit - if c.interval > 0 && !c.lastAt.IsZero() && time.Since(c.lastAt) < c.interval { - return c.lastErr - } - - // Fresh probe under a detached context - probeCtx, cancel := context.WithTimeout(context.Background(), c.probeTimeout) - defer cancel() - err := storageProbe(probeCtx, c.storage) - - // Transition logging and metric increment happen only on the fresh-probe path. - c.logTransition(c.lastErr, err) - if err != nil { - var pe *probeError - if errors.As(err, &pe) { - metrics.RecordHealthProbeFailure(pe.step) - } else { - metrics.RecordHealthProbeFailure("unknown") - } - } - - c.lastErr = err - c.lastAt = time.Now() - return err -} - -func (c *healthCache) logTransition(prev, curr error) { - switch { - case prev != nil && curr == nil: - c.logger.Info("storage probe recovered") - case prev == nil && curr != nil: - c.logger.Error("storage probe failed", "error", curr.Error()) - } -} diff --git a/internal/server/health_test.go b/internal/server/health_test.go deleted file mode 100644 index 3b7eae8..0000000 --- a/internal/server/health_test.go +++ /dev/null @@ -1,448 +0,0 @@ -package server - -import ( - "bytes" - "context" - "errors" - "io" - "log/slog" - "strings" - "sync" - "sync/atomic" - "testing" - "time" - - "github.com/git-pkgs/proxy/internal/metrics" - "github.com/git-pkgs/proxy/internal/storage" - "github.com/prometheus/client_golang/prometheus/testutil" -) - -// fakeStorage is a minimal storage.Storage for probe tests with per-step failure injection. -type fakeStorage struct { - mu sync.Mutex - - storeCalls atomic.Int64 - openCalls atomic.Int64 - closeCalls atomic.Int64 - deleteCalls atomic.Int64 - - paths []string - payloads [][]byte - - // Failure injection. - storeErr error - openErr error - readErr error // returned by the io.ReadCloser.Read after partial bytes - deleteErr error - - // Misbehavior knobs. - sizeDelta int64 // added to the reported size from Store - readOverride []byte // if non-nil, Open returns a reader yielding these bytes instead of stored content - - // storeBlock, if non-nil, causes Store to block until the channel is closed or ctx is done. - storeBlock chan struct{} - - stored map[string][]byte -} - -func newFakeStorage() *fakeStorage { return &fakeStorage{stored: map[string][]byte{}} } - -func (f *fakeStorage) Store(ctx context.Context, path string, r io.Reader) (int64, string, error) { - f.storeCalls.Add(1) - if f.storeErr != nil { - return 0, "", f.storeErr - } - if f.storeBlock != nil { - select { - case <-f.storeBlock: - case <-ctx.Done(): - return 0, "", ctx.Err() - } - } - data, err := io.ReadAll(r) - if err != nil { - return 0, "", err - } - f.mu.Lock() - f.stored[path] = data - f.paths = append(f.paths, path) - f.payloads = append(f.payloads, data) - f.mu.Unlock() - return int64(len(data)) + f.sizeDelta, "fakehash", nil -} - -type fakeReadCloser struct { - data []byte - pos int - readErr error - closed *atomic.Int64 -} - -func (rc *fakeReadCloser) Read(p []byte) (int, error) { - if rc.pos >= len(rc.data) { - if rc.readErr != nil { - return 0, rc.readErr - } - return 0, io.EOF - } - n := copy(p, rc.data[rc.pos:]) - rc.pos += n - if rc.pos >= len(rc.data) && rc.readErr != nil { - return n, rc.readErr - } - return n, nil -} - -func (rc *fakeReadCloser) Close() error { rc.closed.Add(1); return nil } - -func (f *fakeStorage) Open(ctx context.Context, path string) (io.ReadCloser, error) { - f.openCalls.Add(1) - if f.openErr != nil { - return nil, f.openErr - } - f.mu.Lock() - data := f.stored[path] - f.mu.Unlock() - if f.readOverride != nil { - data = f.readOverride - } - return &fakeReadCloser{data: data, readErr: f.readErr, closed: &f.closeCalls}, nil -} - -func (f *fakeStorage) Exists(ctx context.Context, path string) (bool, error) { - f.mu.Lock() - defer f.mu.Unlock() - _, ok := f.stored[path] - return ok, nil -} - -func (f *fakeStorage) Delete(ctx context.Context, path string) error { - f.deleteCalls.Add(1) - if f.deleteErr != nil { - return f.deleteErr - } - f.mu.Lock() - delete(f.stored, path) - f.mu.Unlock() - return nil -} - -func (f *fakeStorage) Size(ctx context.Context, path string) (int64, error) { return 0, nil } -func (f *fakeStorage) SignedURL(ctx context.Context, path string, expiry time.Duration) (string, error) { - return "", storage.ErrSignedURLUnsupported -} -func (f *fakeStorage) UsedSpace(ctx context.Context) (int64, error) { return 0, nil } -func (f *fakeStorage) URL() string { return "fake://" } -func (f *fakeStorage) Close() error { return nil } - -// --- Tests follow. First test: happy path --- - -func TestStorageProbe_HappyPath(t *testing.T) { - fs := newFakeStorage() - if err := storageProbe(context.Background(), fs); err != nil { - t.Fatalf("unexpected error: %v", err) - } - if got := fs.storeCalls.Load(); got != 1 { - t.Errorf("Store calls = %d, want 1", got) - } - if got := fs.openCalls.Load(); got != 1 { - t.Errorf("Open calls = %d, want 1", got) - } - if got := fs.closeCalls.Load(); got != 1 { - t.Errorf("Close calls = %d, want 1", got) - } - if got := fs.deleteCalls.Load(); got != 1 { - t.Errorf("Delete calls = %d, want 1", got) - } - if len(fs.paths) != 1 || !strings.HasPrefix(fs.paths[0], ".healthcheck/") { - t.Errorf("unexpected probe path: %v", fs.paths) - } -} - -func TestStorageProbe_WriteFails(t *testing.T) { - fs := newFakeStorage() - fs.storeErr = errors.New("disk full") - err := storageProbe(context.Background(), fs) - var pe *probeError - if !errors.As(err, &pe) { - t.Fatalf("expected *probeError, got %T: %v", err, err) - } - if pe.step != "write" { - t.Errorf("step = %q, want write", pe.step) - } - if fs.openCalls.Load() != 0 { - t.Errorf("Open should not be called after write failure") - } -} - -func TestStorageProbe_SizeMismatch(t *testing.T) { - fs := newFakeStorage() - fs.sizeDelta = -1 // Report 1 byte fewer than actually written - err := storageProbe(context.Background(), fs) - var pe *probeError - if !errors.As(err, &pe) || pe.step != "size" { - t.Fatalf("step = %v, want size; err = %v", pe, err) - } - if fs.openCalls.Load() != 0 { - t.Errorf("Open should not be called after size mismatch") - } -} - -func TestStorageProbe_OpenFails(t *testing.T) { - fs := newFakeStorage() - fs.openErr = errors.New("access denied") - err := storageProbe(context.Background(), fs) - var pe *probeError - if !errors.As(err, &pe) || pe.step != "read" { - t.Fatalf("step = %v, want read; err = %v", pe, err) - } -} - -func TestStorageProbe_ReadMidStreamFails(t *testing.T) { - fs := newFakeStorage() - fs.readErr = errors.New("connection reset") - err := storageProbe(context.Background(), fs) - var pe *probeError - if !errors.As(err, &pe) || pe.step != "read" { - t.Fatalf("step = %v, want read (NOT verify); err = %v", pe, err) - } -} - -func TestStorageProbe_ContentMismatch(t *testing.T) { - fs := newFakeStorage() - fs.readOverride = []byte("wrong content") - err := storageProbe(context.Background(), fs) - var pe *probeError - if !errors.As(err, &pe) || pe.step != "verify" { - t.Fatalf("step = %v, want verify; err = %v", pe, err) - } -} - -func TestStorageProbe_DeleteFails(t *testing.T) { - fs := newFakeStorage() - fs.deleteErr = errors.New("permission denied") - err := storageProbe(context.Background(), fs) - var pe *probeError - if !errors.As(err, &pe) || pe.step != "delete" { - t.Fatalf("step = %v, want delete; err = %v", pe, err) - } -} - -// TestStorageProbe_CleanupOnNonDeleteFailure asserts that the probe object is -// deleted even when a step after Store (size/open/read/verify) fails, so -// probe artifacts don't accumulate in the storage backend. -func TestStorageProbe_CleanupOnNonDeleteFailure(t *testing.T) { - cases := []struct { - name string - inject func(*fakeStorage) - wantErr string - }{ - {"size mismatch", func(fs *fakeStorage) { fs.sizeDelta = -1 }, "size"}, - {"open fails", func(fs *fakeStorage) { fs.openErr = errors.New("open boom") }, "read"}, - {"read mid-stream", func(fs *fakeStorage) { fs.readErr = errors.New("mid-stream boom") }, "read"}, - {"content mismatch", func(fs *fakeStorage) { fs.readOverride = []byte("wrong") }, "verify"}, - } - for _, tc := range cases { - t.Run(tc.name, func(t *testing.T) { - fs := newFakeStorage() - tc.inject(fs) - err := storageProbe(context.Background(), fs) - var pe *probeError - if !errors.As(err, &pe) || pe.step != tc.wantErr { - t.Fatalf("step = %v, want %q; err = %v", pe, tc.wantErr, err) - } - if got := fs.deleteCalls.Load(); got != 1 { - t.Errorf("deleteCalls = %d, want 1 (cleanup should run on non-delete failures)", got) - } - }) - } -} - -func TestStorageProbe_ReaderClosedOnReadFailure(t *testing.T) { - fs := newFakeStorage() - fs.readErr = errors.New("read error") - _ = storageProbe(context.Background(), fs) - if got := fs.closeCalls.Load(); got != fs.openCalls.Load() { - t.Errorf("closeCalls = %d, openCalls = %d (should match)", got, fs.openCalls.Load()) - } -} - -func TestStorageProbe_PathUniqueness(t *testing.T) { - fs := newFakeStorage() - for i := 0; i < 100; i++ { - if err := storageProbe(context.Background(), fs); err != nil { - t.Fatalf("probe %d: %v", i, err) - } - } - seen := make(map[string]bool) - for _, p := range fs.paths { - if !strings.HasPrefix(p, ".healthcheck/") { - t.Errorf("path missing prefix: %q", p) - } - if seen[p] { - t.Errorf("duplicate path: %q", p) - } - seen[p] = true - } -} - -// helper: a healthCache wired to a fakeStorage and a discard logger. -func newTestCache(fs *fakeStorage, interval time.Duration) *healthCache { - return &healthCache{ - storage: fs, - interval: interval, - probeTimeout: 5 * time.Second, - logger: discardLogger(), - } -} - -func discardLogger() *slog.Logger { - return slog.New(slog.NewTextHandler(io.Discard, nil)) -} - -func TestHealthCache_CacheHit(t *testing.T) { - fs := newFakeStorage() - c := newTestCache(fs, 30*time.Second) - if err := c.Check(); err != nil { - t.Fatalf("first check: %v", err) - } - if err := c.Check(); err != nil { - t.Fatalf("second check: %v", err) - } - if got := fs.storeCalls.Load(); got != 1 { - t.Errorf("storeCalls = %d, want 1 (second call should be cached)", got) - } -} - -func TestHealthCache_MissAfterTTL(t *testing.T) { - fs := newFakeStorage() - c := newTestCache(fs, 10*time.Millisecond) - _ = c.Check() - time.Sleep(20 * time.Millisecond) - _ = c.Check() - if got := fs.storeCalls.Load(); got != 2 { - t.Errorf("storeCalls = %d, want 2", got) - } -} - -func TestHealthCache_Disabled(t *testing.T) { - fs := newFakeStorage() - c := newTestCache(fs, 0) // interval = 0 means probe every call - _ = c.Check() - _ = c.Check() - if got := fs.storeCalls.Load(); got != 2 { - t.Errorf("storeCalls = %d, want 2", got) - } -} - -func TestHealthCache_LastAtNotAdvancedOnHit(t *testing.T) { - fs := newFakeStorage() - c := newTestCache(fs, 30*time.Second) - for i := 0; i < 100; i++ { - _ = c.Check() - } - if got := fs.storeCalls.Load(); got != 1 { - t.Errorf("storeCalls = %d, want 1 across 100 hits", got) - } -} - -func TestHealthCache_ConcurrentSingleFlight(t *testing.T) { - fs := newFakeStorage() - c := newTestCache(fs, 30*time.Second) - var wg sync.WaitGroup - for i := 0; i < 20; i++ { - wg.Add(1) - go func() { defer wg.Done(); _ = c.Check() }() - } - wg.Wait() - if got := fs.storeCalls.Load(); got != 1 { - t.Errorf("storeCalls = %d, want 1 with 20 concurrent callers", got) - } -} - -func TestHealthCache_FailureCounterIncrement(t *testing.T) { - fs := newFakeStorage() - fs.storeErr = errors.New("boom") - c := newTestCache(fs, 30*time.Second) - - before := testutil.ToFloat64(metrics.HealthProbeFailures.WithLabelValues("write")) - - // First call: fresh probe → counter +1 - _ = c.Check() - afterFirst := testutil.ToFloat64(metrics.HealthProbeFailures.WithLabelValues("write")) - if afterFirst-before != 1 { - t.Errorf("counter delta after first call = %v, want 1", afterFirst-before) - } - - // Second call: cache hit → counter NOT re-incremented - _ = c.Check() - afterSecond := testutil.ToFloat64(metrics.HealthProbeFailures.WithLabelValues("write")) - if afterSecond != afterFirst { - t.Errorf("counter changed on cache hit: %v → %v", afterFirst, afterSecond) - } -} - -func TestHealthCache_ProbeTimeout(t *testing.T) { - fs := newFakeStorage() - fs.storeBlock = make(chan struct{}) // Store will block until channel is closed (or never) - t.Cleanup(func() { close(fs.storeBlock) }) - - c := &healthCache{ - storage: fs, - interval: 30 * time.Second, - probeTimeout: 50 * time.Millisecond, - logger: discardLogger(), - } - start := time.Now() - err := c.Check() - elapsed := time.Since(start) - - if err == nil { - t.Fatal("expected timeout error, got nil") - } - if elapsed > 500*time.Millisecond { - t.Errorf("probe took %v, expected ~50ms (timeout not respected)", elapsed) - } -} - -func TestHealthCache_TransitionLogging(t *testing.T) { - fs := newFakeStorage() - var buf bytes.Buffer - logger := slog.New(slog.NewTextHandler(&buf, &slog.HandlerOptions{Level: slog.LevelInfo})) - c := &healthCache{ - storage: fs, - interval: 0, // probe every call - probeTimeout: 5 * time.Second, - logger: logger, - } - - // Steady ok state — should not log - _ = c.Check() - _ = c.Check() - if got := strings.Count(buf.String(), "storage probe"); got != 0 { - t.Errorf("steady-state logs = %d, want 0; output: %s", got, buf.String()) - } - - // ok → err transition: exactly one Error log - buf.Reset() - fs.storeErr = errors.New("boom") - _ = c.Check() - if !strings.Contains(buf.String(), "storage probe failed") { - t.Errorf("missing failure log on transition; output: %s", buf.String()) - } - - // err steady state — should not log again - buf.Reset() - _ = c.Check() - if buf.Len() != 0 { - t.Errorf("steady-err logs = %q, want empty", buf.String()) - } - - // err → ok transition: exactly one Info log - buf.Reset() - fs.storeErr = nil - _ = c.Check() - if !strings.Contains(buf.String(), "storage probe recovered") { - t.Errorf("missing recovery log on transition; output: %s", buf.String()) - } -} diff --git a/internal/server/layout.go b/internal/server/layout.go deleted file mode 100644 index 2da9469..0000000 --- a/internal/server/layout.go +++ /dev/null @@ -1,26 +0,0 @@ -package server - -import "net/http" - -// BuildInfo identifies the running proxy binary. -type BuildInfo struct { - Version string - Commit string -} - -// Layout carries shared fields consumed by the base template. It is embedded -// in every page data struct so templates can access canonical URL and build -// information alongside the page's own fields. -type Layout struct { - BuildInfo BuildInfo - UIBaseURL string - CanonicalPath string -} - -func (s *Server) layoutFor(r *http.Request) Layout { - return Layout{ - BuildInfo: s.buildInfo, - UIBaseURL: s.cfg.UIBaseURL, - CanonicalPath: r.URL.Path, - } -} diff --git a/internal/server/middleware.go b/internal/server/middleware.go index b6d483f..9b81254 100644 --- a/internal/server/middleware.go +++ b/internal/server/middleware.go @@ -3,15 +3,16 @@ package server import ( "context" "net/http" - "strings" "sync/atomic" "time" - "github.com/git-pkgs/proxy/internal/accesslog" - "github.com/git-pkgs/proxy/internal/metrics" "github.com/go-chi/chi/v5/middleware" ) +type contextKey string + +const requestIDKey contextKey = "request_id" + var requestCounter atomic.Uint64 // RequestIDMiddleware adds a sequential request ID to the context and response headers. @@ -22,7 +23,7 @@ func RequestIDMiddleware(next http.Handler) http.Handler { requestID := middleware.GetReqID(r.Context()) // Store formatted ID in context - ctx := accesslog.WithRequestID(r.Context(), requestID) + ctx := context.WithValue(r.Context(), requestIDKey, requestID) // Add to response header for client tracking w.Header().Set("X-Request-ID", requestID) @@ -33,7 +34,10 @@ func RequestIDMiddleware(next http.Handler) http.Handler { // GetRequestID retrieves the request ID from context. func GetRequestID(ctx context.Context) string { - return accesslog.RequestID(ctx) + if id, ok := ctx.Value(requestIDKey).(string); ok { + return id + } + return "" } // LoggerMiddleware logs HTTP requests with request ID correlation. @@ -44,51 +48,27 @@ func (s *Server) LoggerMiddleware(next http.Handler) http.Handler { rw := &responseWriter{ResponseWriter: w, status: http.StatusOK} next.ServeHTTP(rw, r) - duration := time.Since(start) s.logger.Info("request", "request_id", requestID, "method", r.Method, "path", r.URL.Path, "status", rw.status, - "duration", duration, + "duration", time.Since(start), "remote", r.RemoteAddr) - - if r.URL.Path != "/metrics" { - metrics.RecordRequest(requestEcosystem(r.URL.Path), rw.status, duration) - } - - if s.accessLog != nil { - if err := s.accessLog.Write(accesslog.Entry{ - Event: accesslog.EventRequest, - RequestID: requestID, - Method: r.Method, - Path: r.URL.EscapedPath(), - StatusCode: rw.status, - DurationMS: duration.Milliseconds(), - RemoteAddr: r.RemoteAddr, - }); err != nil { - s.logger.Error("failed to write access log", "error", err) - } - } }) } -func requestEcosystem(path string) string { - segment, _, _ := strings.Cut(strings.TrimPrefix(path, "/"), "/") - switch segment { - case "npm", "cargo", "hex", "pub", "pypi", "maven", "gradle", "nuget", - "conan", "conda", "cran", "julia", "debian", "rpm": - return segment - case "gem": - return "rubygems" - case "go": - return "golang" - case "composer": - return "packagist" - case "v2": - return "oci" - default: - return "other" - } +// ActiveRequestsMiddleware tracks the number of active requests using Prometheus metrics. +func ActiveRequestsMiddleware(next http.Handler) http.Handler { + return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + // Don't track metrics endpoint itself + if r.URL.Path == "/metrics" { + next.ServeHTTP(w, r) + return + } + + // Implemented in server.go where metrics package is imported + next.ServeHTTP(w, r) + }) } diff --git a/internal/server/middleware_test.go b/internal/server/middleware_test.go index 38905b2..75c6ccd 100644 --- a/internal/server/middleware_test.go +++ b/internal/server/middleware_test.go @@ -2,21 +2,13 @@ package server import ( "context" - "encoding/json" "io" "log/slog" "net/http" "net/http/httptest" - "os" - "path/filepath" "testing" - "github.com/git-pkgs/proxy/internal/accesslog" - "github.com/git-pkgs/proxy/internal/metrics" "github.com/go-chi/chi/v5/middleware" - "github.com/prometheus/client_golang/prometheus" - "github.com/prometheus/client_golang/prometheus/testutil" - dto "github.com/prometheus/client_model/go" ) func TestRequestIDMiddleware(t *testing.T) { @@ -53,7 +45,7 @@ func TestGetRequestID(t *testing.T) { }{ { name: "with request ID", - ctx: accesslog.WithRequestID(context.Background(), "test-123"), + ctx: context.WithValue(context.Background(), requestIDKey, "test-123"), expected: "test-123", }, { @@ -73,6 +65,36 @@ func TestGetRequestID(t *testing.T) { } } +func TestActiveRequestsMiddleware(t *testing.T) { + handler := ActiveRequestsMiddleware(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + w.WriteHeader(http.StatusOK) + })) + + req := httptest.NewRequest(http.MethodGet, "/test", nil) + rec := httptest.NewRecorder() + + handler.ServeHTTP(rec, req) + + if rec.Code != http.StatusOK { + t.Errorf("expected status 200, got %d", rec.Code) + } +} + +func TestActiveRequestsMiddleware_SkipsMetricsEndpoint(t *testing.T) { + handler := ActiveRequestsMiddleware(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + w.WriteHeader(http.StatusOK) + })) + + req := httptest.NewRequest(http.MethodGet, "/metrics", nil) + rec := httptest.NewRecorder() + + handler.ServeHTTP(rec, req) + + if rec.Code != http.StatusOK { + t.Errorf("expected status 200, got %d", rec.Code) + } +} + func TestLoggerMiddleware(t *testing.T) { logger := slog.New(slog.NewTextHandler(io.Discard, nil)) s := &Server{logger: logger} @@ -99,133 +121,6 @@ func TestLoggerMiddleware(t *testing.T) { } } -func TestLoggerMiddlewareRecordsRequestMetrics(t *testing.T) { - before := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("rubygems", "404")) - durationMetric := metrics.RequestDuration.WithLabelValues("rubygems", "404") - beforeDurationCount := histogramSampleCount(t, durationMetric) - - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - s := &Server{logger: logger} - handler := s.LoggerMiddleware(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.WriteHeader(http.StatusNotFound) - })) - - req := httptest.NewRequest(http.MethodGet, "/gem/downloads/missing.gem", nil) - rec := httptest.NewRecorder() - handler.ServeHTTP(rec, req) - - after := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("rubygems", "404")) - if got := after - before; got != 1 { - t.Errorf("request counter delta = %.0f, want 1", got) - } - afterDurationCount := histogramSampleCount(t, durationMetric) - if got := afterDurationCount - beforeDurationCount; got != 1 { - t.Errorf("request duration sample delta = %d, want 1", got) - } -} - -func histogramSampleCount(t *testing.T, observer prometheus.Observer) uint64 { - t.Helper() - - metric, ok := observer.(prometheus.Metric) - if !ok { - t.Fatal("histogram observer does not implement prometheus.Metric") - } - - var value dto.Metric - if err := metric.Write(&value); err != nil { - t.Fatalf("writing histogram metric: %v", err) - } - return value.GetHistogram().GetSampleCount() -} - -func TestLoggerMiddlewareSkipsMetricsEndpointMetrics(t *testing.T) { - before := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("other", "200")) - - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - s := &Server{logger: logger} - handler := s.LoggerMiddleware(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.WriteHeader(http.StatusOK) - })) - - req := httptest.NewRequest(http.MethodGet, "/metrics", nil) - rec := httptest.NewRecorder() - handler.ServeHTTP(rec, req) - - after := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("other", "200")) - if got := after - before; got != 0 { - t.Errorf("request counter delta = %.0f, want 0", got) - } -} - -func TestRequestEcosystem(t *testing.T) { - tests := []struct { - path string - want string - }{ - {path: "/npm/lodash", want: "npm"}, - {path: "/gem/downloads/rails.gem", want: "rubygems"}, - {path: "/go/example.com/module/@v/list", want: "golang"}, - {path: "/composer/vendor/package", want: "packagist"}, - {path: "/v2/library/alpine/manifests/latest", want: "oci"}, - {path: "/ui/", want: "other"}, - {path: "/api/package/npm/lodash", want: "other"}, - {path: "/", want: "other"}, - } - - for _, tt := range tests { - t.Run(tt.path, func(t *testing.T) { - if got := requestEcosystem(tt.path); got != tt.want { - t.Errorf("requestEcosystem(%q) = %q, want %q", tt.path, got, tt.want) - } - }) - } -} - -func TestLoggerMiddlewareWritesAccessLog(t *testing.T) { - path := filepath.Join(t.TempDir(), "access.jsonl") - activityLog, err := accesslog.Open(path) - if err != nil { - t.Fatal(err) - } - - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - s := &Server{logger: logger, accessLog: activityLog} - next := http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { - w.WriteHeader(http.StatusNotFound) - }) - handler := middleware.RequestID(RequestIDMiddleware(s.LoggerMiddleware(next))) - - req := httptest.NewRequest(http.MethodGet, "/packages/example?token=secret", nil) - rec := httptest.NewRecorder() - handler.ServeHTTP(rec, req) - - if err := activityLog.Close(); err != nil { - t.Fatal(err) - } - data, err := os.ReadFile(path) - if err != nil { - t.Fatal(err) - } - - var entry accesslog.Entry - if err := json.Unmarshal(data, &entry); err != nil { - t.Fatalf("decoding access log: %v", err) - } - if entry.Event != accesslog.EventRequest { - t.Errorf("event = %q, want %q", entry.Event, accesslog.EventRequest) - } - if entry.RequestID == "" { - t.Error("request_id is empty") - } - if entry.Path != "/packages/example" { - t.Errorf("path = %q, want query string omitted", entry.Path) - } - if entry.StatusCode != http.StatusNotFound { - t.Errorf("status_code = %d, want %d", entry.StatusCode, http.StatusNotFound) - } -} - func TestResponseWriter_WriteHeader(t *testing.T) { tests := []struct { name string diff --git a/internal/server/mirror_api.go b/internal/server/mirror_api.go index 028d4e0..6a6a6ca 100644 --- a/internal/server/mirror_api.go +++ b/internal/server/mirror_api.go @@ -20,16 +20,19 @@ func NewMirrorAPIHandler(jobs *mirror.JobStore) *MirrorAPIHandler { // HandleCreate starts a new mirror job. func (h *MirrorAPIHandler) HandleCreate(w http.ResponseWriter, r *http.Request) { - r.Body = http.MaxBytesReader(w, r.Body, maxBodySize) var req mirror.JobRequest if err := json.NewDecoder(r.Body).Decode(&req); err != nil { - badRequest(w, "invalid request body") + w.Header().Set("Content-Type", "application/json") + w.WriteHeader(http.StatusBadRequest) + writeJSON(w, map[string]string{"error": "invalid request body"}) return } id, err := h.jobs.Create(req) if err != nil { - badRequest(w, "invalid mirror job request") + w.Header().Set("Content-Type", "application/json") + w.WriteHeader(http.StatusBadRequest) + writeJSON(w, map[string]string{"error": err.Error()}) return } @@ -43,10 +46,13 @@ func (h *MirrorAPIHandler) HandleGet(w http.ResponseWriter, r *http.Request) { id := chi.URLParam(r, "id") job := h.jobs.Get(id) if job == nil { - notFound(w, "job not found") + w.Header().Set("Content-Type", "application/json") + w.WriteHeader(http.StatusNotFound) + writeJSON(w, map[string]string{"error": "job not found"}) return } + w.Header().Set("Content-Type", "application/json") writeJSON(w, job) } @@ -54,8 +60,11 @@ func (h *MirrorAPIHandler) HandleGet(w http.ResponseWriter, r *http.Request) { func (h *MirrorAPIHandler) HandleCancel(w http.ResponseWriter, r *http.Request) { id := chi.URLParam(r, "id") if h.jobs.Cancel(id) { + w.Header().Set("Content-Type", "application/json") writeJSON(w, map[string]string{"status": "canceled"}) } else { - notFound(w, "job not found or not running") + w.Header().Set("Content-Type", "application/json") + w.WriteHeader(http.StatusNotFound) + writeJSON(w, map[string]string{"error": "job not found or not running"}) } } diff --git a/internal/server/mirror_api_test.go b/internal/server/mirror_api_test.go index c960348..0e84da1 100644 --- a/internal/server/mirror_api_test.go +++ b/internal/server/mirror_api_test.go @@ -71,75 +71,6 @@ func TestMirrorAPICreateJob(t *testing.T) { } } -func TestMirrorAPICreateJobFromInlineSBOM(t *testing.T) { - h := setupMirrorAPI(t) - - body, err := json.Marshal(mirror.JobRequest{ - SBOM: json.RawMessage(`{ - "bomFormat":"CycloneDX", - "specVersion":"1.4", - "components":[{ - "type":"library", - "name":"lodash", - "version":"4.17.21", - "purl":"pkg:npm/lodash@4.17.21" - }] - }`), - }) - if err != nil { - t.Fatalf("marshaling request: %v", err) - } - - req := httptest.NewRequest(http.MethodPost, "/api/mirror", bytes.NewReader(body)) - w := httptest.NewRecorder() - h.HandleCreate(w, req) - - if w.Code != http.StatusAccepted { - t.Fatalf("status = %d, want %d: %s", w.Code, http.StatusAccepted, w.Body.String()) - } - - var resp map[string]string - if err := json.NewDecoder(w.Body).Decode(&resp); err != nil { - t.Fatalf("decoding response: %v", err) - } - if resp["id"] == "" { - t.Error("expected non-empty job ID") - } -} - -func TestMirrorAPICreateJobRejectsPURLsAndSBOM(t *testing.T) { - h := setupMirrorAPI(t) - - body, err := json.Marshal(mirror.JobRequest{ - PURLs: []string{"pkg:npm/lodash@4.17.21"}, - SBOM: json.RawMessage(`{"bomFormat":"CycloneDX","components":[]}`), - }) - if err != nil { - t.Fatalf("marshaling request: %v", err) - } - - req := httptest.NewRequest(http.MethodPost, "/api/mirror", bytes.NewReader(body)) - w := httptest.NewRecorder() - h.HandleCreate(w, req) - - if w.Code != http.StatusBadRequest { - t.Errorf("status = %d, want %d", w.Code, http.StatusBadRequest) - } -} - -func TestMirrorAPICreateOversizedBody(t *testing.T) { - h := setupMirrorAPI(t) - - body := bytes.Repeat([]byte("x"), int(maxBodySize)+1) - req := httptest.NewRequest("POST", "/api/mirror", bytes.NewReader(body)) - w := httptest.NewRecorder() - h.HandleCreate(w, req) - - if w.Code != http.StatusBadRequest { - t.Errorf("status = %d, want %d", w.Code, http.StatusBadRequest) - } -} - func TestMirrorAPICreateInvalidBody(t *testing.T) { h := setupMirrorAPI(t) diff --git a/internal/server/resolve.go b/internal/server/resolve.go index f7a1b23..479ede6 100644 --- a/internal/server/resolve.go +++ b/internal/server/resolve.go @@ -1,89 +1,11 @@ package server import ( - "fmt" - "net/http" - "net/url" "strings" - "unicode" "github.com/git-pkgs/proxy/internal/database" - "github.com/go-chi/chi/v5" ) -// maxPackagePathLen bounds the wildcard portion of package routes (name plus -// version and any suffix). npm caps names at 214 and Maven coordinates can be -// longer, so 512 leaves room without admitting pathological inputs. -const maxPackagePathLen = 512 - -// packagePathSegments validates the wildcard portion of a package route and -// splits it into decoded path segments. -func packagePathSegments(r *http.Request) ([]string, error) { - wildcard := chi.URLParam(r, "*") - encoded := wildcardIsEncoded(r) - if err := validatePackagePath(wildcard, encoded); err != nil { - return nil, err - } - - return splitWildcardPath(wildcard, encoded), nil -} - -// wildcardIsEncoded reports whether the chi wildcard for this request is still -// percent-encoded. -// -// chi routes on r.URL.RawPath when it is set and on r.URL.Path otherwise, and -// net/url only sets RawPath when the request's escaping differs from the -// canonical encoding of the decoded path. A version such as "release%2F1" is -// therefore routed raw, while "1.0%252B" (a version whose text contains a -// literal "%2B") encodes canonically and arrives already decoded once. The -// distinction decides whether the segments still need decoding: decoding the -// second case again would turn it into "1.0+" and resolve a different version. -func wildcardIsEncoded(r *http.Request) bool { - return r.URL.RawPath != "" -} - -// validatePackagePath rejects wildcard package paths that cannot be valid in -// any supported ecosystem. It is a coarse filter applied before database or -// enrichment lookups; ecosystem-specific name rules are layered on top. -// -// encoded has the meaning described on wildcardIsEncoded. -func validatePackagePath(path string, encoded bool) error { - if path == "" { - return fmt.Errorf("package name required") - } - if len(path) > maxPackagePathLen { - return fmt.Errorf("package path exceeds %d bytes", maxPackagePathLen) - } - // Validate the decoded segments: the handlers work with decoded values, so - // an escape such as "%00" or "%2E%2E" must not slip past these checks. - for _, seg := range splitWildcardPath(path, encoded) { - // Each segment is checked both as the handlers see it and decoded once - // more: a segment can reach a handler with escapes intact, and the - // upstream registry is then the one that decodes them. - for _, value := range []string{seg, decodePathSegment(seg)} { - // A decoded segment can itself contain slashes (from "%2F"), and - // the segments are later rejoined into a package name that - // registries interpolate straight into an upstream URL. Check every - // path element, not just the segment as a whole, or - // "a%2F..%2F..%2Fb" traverses. - for _, elem := range strings.Split(value, "/") { - if elem == ".." { - return fmt.Errorf("package path contains parent directory segment") - } - } - for _, r := range value { - if r == 0 { - return fmt.Errorf("package path contains null byte") - } - if unicode.IsControl(r) { - return fmt.Errorf("package path contains control character %#U", r) - } - } - } - } - return nil -} - // resolvePackageName determines the package name from a wildcard path by // checking the database. This handles namespaced packages like Composer's // vendor/name format where the package name contains a slash. @@ -110,37 +32,10 @@ func resolvePackageName(db *database.DB, ecosystem string, segments []string) (n // splitWildcardPath splits a chi wildcard path value into segments, // trimming any leading/trailing slashes. -// -// When encoded is set the value is still percent-encoded (see -// wildcardIsEncoded), so each segment is decoded after splitting. Splitting -// first keeps an encoded "%2F" inside a name from being mistaken for a -// separator. Decoding matters for versions such as "1.0%2Bbuild1", which must -// reach the handlers as "1.0+build1" so that rebuilding the PURL yields the -// value that was stored rather than a double-encoded one. -func splitWildcardPath(path string, encoded bool) []string { +func splitWildcardPath(path string) []string { path = strings.Trim(path, "/") if path == "" { return nil } - segments := strings.Split(path, "/") - if !encoded { - return segments - } - for i, seg := range segments { - segments[i] = decodePathSegment(seg) - } - return segments -} - -// decodePathSegment percent-decodes a single URL path segment, returning it -// unchanged if it is not valid percent-encoding. -func decodePathSegment(seg string) string { - if !strings.Contains(seg, "%") { - return seg - } - decoded, err := url.PathUnescape(seg) - if err != nil { - return seg - } - return decoded + return strings.Split(path, "/") } diff --git a/internal/server/resolve_test.go b/internal/server/resolve_test.go index 1867f46..427c2cb 100644 --- a/internal/server/resolve_test.go +++ b/internal/server/resolve_test.go @@ -1,15 +1,11 @@ package server import ( - "net/http" - "net/http/httptest" "os" "path/filepath" - "strings" "testing" "github.com/git-pkgs/proxy/internal/database" - "github.com/go-chi/chi/v5" ) func newTestDB(t *testing.T) (*database.DB, func()) { @@ -98,144 +94,27 @@ func TestResolvePackageName(t *testing.T) { func TestSplitWildcardPath(t *testing.T) { tests := []struct { - input string - encoded bool - want []string + input string + want []string }{ - {"lodash", false, []string{"lodash"}}, - {"lodash/4.17.21", false, []string{"lodash", "4.17.21"}}, - {"monolog/monolog", false, []string{"monolog", "monolog"}}, - {"symfony/console/6.0.0/browse", false, []string{"symfony", "console", "6.0.0", "browse"}}, - {"", false, nil}, - {"/", false, nil}, - // chi routes on the raw path when it differs from the canonical - // encoding of the decoded path, so segments arrive percent-encoded and - // must be decoded. - { - "nmap/7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1", true, - []string{"nmap", "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1"}, - }, - {"%40babel/core/7.0.0", true, []string{"@babel", "core", "7.0.0"}}, - // An encoded separator stays inside its segment rather than splitting. - {"vendor%2Fname/1.0.0", true, []string{"vendor/name", "1.0.0"}}, - // Invalid escapes are passed through untouched. - {"lodash/1.0%zz", true, []string{"lodash", "1.0%zz"}}, - // When chi routed on the already-decoded path, an escape that survived - // is part of the value: a version whose text is "1.0%2B" reaches here - // as "1.0%2B" and decoding it again would yield "1.0+". - {"nmap/1.0%2B", false, []string{"nmap", "1.0%2B"}}, + {"lodash", []string{"lodash"}}, + {"lodash/4.17.21", []string{"lodash", "4.17.21"}}, + {"monolog/monolog", []string{"monolog", "monolog"}}, + {"symfony/console/6.0.0/browse", []string{"symfony", "console", "6.0.0", "browse"}}, + {"", nil}, + {"/", nil}, } for _, tt := range tests { - got := splitWildcardPath(tt.input, tt.encoded) + got := splitWildcardPath(tt.input) if len(got) != len(tt.want) { - t.Errorf("splitWildcardPath(%q, %v) = %v, want %v", tt.input, tt.encoded, got, tt.want) + t.Errorf("splitWildcardPath(%q) = %v, want %v", tt.input, got, tt.want) continue } for i := range got { if got[i] != tt.want[i] { - t.Errorf("splitWildcardPath(%q, %v)[%d] = %q, want %q", - tt.input, tt.encoded, i, got[i], tt.want[i]) + t.Errorf("splitWildcardPath(%q)[%d] = %q, want %q", tt.input, i, got[i], tt.want[i]) } } } } - -func TestValidatePackagePath(t *testing.T) { - tests := []struct { - name string - path string - wantErr bool - }{ - {"simple", "lodash", false}, - {"with version", "lodash/4.17.21", false}, - {"npm scoped", "@babel/core/7.0.0", false}, - {"composer namespaced", "symfony/console/6.0.0", false}, - {"maven coordinates", "org.apache.commons/commons-lang3/3.12.0", false}, - {"unicode", "café/1.0.0", false}, - {"encoded plus in version", "nmap/7.91%2Bdfsg1-2ubuntu0.1", false}, - {"empty", "", true}, - {"null byte", "lodash\x00/4.17.21", true}, - {"encoded null byte", "lodash/%00", true}, - {"encoded newline", "lodash/1.0%0A", true}, - {"parent segment", "lodash/../4.17.21", true}, - {"encoded parent segment", "lodash/%2E%2E/4.17.21", true}, - // A decoded segment can contain slashes, so traversal can hide inside - // one segment. Registries interpolate the resolved name straight into - // an upstream URL, and Go sends dot-segments verbatim. - {"traversal inside one segment", "pkg%2F..%2F..%2Fadmin", true}, - {"traversal via encoded dots and slash", "pkg%2f%2e%2e%2fadmin", true}, - {"encoded slash alone is allowed", "vendor%2Fname/1.0.0", false}, - {"null byte suffix", "lodash\x00", true}, - {"newline", "lodash\n4.17.21", true}, - {"carriage return", "lodash\r", true}, - {"escape", "lodash\x1b[31m", true}, - {"delete", "lodash\x7f", true}, - {"too long", strings.Repeat("a", maxPackagePathLen+1), true}, - {"at limit", strings.Repeat("a", maxPackagePathLen), false}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - // The verdict must not depend on whether chi routed on the raw or - // on the already-decoded path: an escape that reaches a handler - // undecoded is decoded by the upstream registry instead, so it is - // rejected either way. - for _, encoded := range []bool{false, true} { - err := validatePackagePath(tt.path, encoded) - if (err != nil) != tt.wantErr { - t.Errorf("validatePackagePath(%q, %v) error = %v, wantErr %v", - tt.path, encoded, err, tt.wantErr) - } - } - }) - } -} - -// TestPackagePathSegments drives the real router, which is what decides whether -// the wildcard still carries percent-encoding. Go decodes the request path -// itself unless the escaping is non-canonical, so the same version can arrive -// either way and only one of the two forms may be decoded again. -func TestPackagePathSegments(t *testing.T) { - tests := []struct { - name string - target string - want []string - }{ - {"plain", "/pkg/npm/lodash/4.17.21", []string{"lodash", "4.17.21"}}, - {"encoded plus", "/pkg/deb/nmap/7.91%2Bdfsg1-2ubuntu0.1", []string{"nmap", "7.91+dfsg1-2ubuntu0.1"}}, - {"decoded plus", "/pkg/deb/nmap/7.91+dfsg1-2ubuntu0.1", []string{"nmap", "7.91+dfsg1-2ubuntu0.1"}}, - // An encoded slash is one segment, not a separator. - {"encoded slash", "/pkg/composer/vendor%2Fname/1.0.0", []string{"vendor/name", "1.0.0"}}, - {"question mark", "/pkg/npm/example/v1%3Fbuild", []string{"example", "v1?build"}}, - // "1.0%252B" is the escaped form of the version "1.0%2B"; net/url - // already decoded it once, so it must not be decoded again. - {"literal percent escape", "/pkg/npm/example/1.0%252B", []string{"example", "1.0%2B"}}, - {"browse suffix", "/pkg/deb/nmap/7.91%2Bdfsg1/browse", []string{"nmap", "7.91+dfsg1", "browse"}}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - var got []string - var gotErr error - - router := chi.NewRouter() - router.Get("/pkg/{ecosystem}/*", func(_ http.ResponseWriter, r *http.Request) { - got, gotErr = packagePathSegments(r) - }) - router.ServeHTTP(httptest.NewRecorder(), httptest.NewRequest("GET", tt.target, nil)) - - if gotErr != nil { - t.Fatalf("packagePathSegments(%q) failed: %v", tt.target, gotErr) - } - if len(got) != len(tt.want) { - t.Fatalf("segments for %q = %v, want %v", tt.target, got, tt.want) - } - for i := range got { - if got[i] != tt.want[i] { - t.Errorf("segments for %q [%d] = %q, want %q", tt.target, i, got[i], tt.want[i]) - } - } - }) - } -} diff --git a/internal/server/server.go b/internal/server/server.go index e82b626..5d544a2 100644 --- a/internal/server/server.go +++ b/internal/server/server.go @@ -9,34 +9,21 @@ // - /pub/* - pub.dev registry protocol // - /pypi/* - PyPI registry protocol // - /maven/* - Maven repository protocol -// - /gradle/* - Gradle HttpBuildCache protocol // - /nuget/* - NuGet V3 API protocol // - /composer/* - Composer/Packagist protocol // - /conan/* - Conan C/C++ protocol // - /conda/* - Conda/Anaconda protocol // - /cran/* - CRAN (R) protocol -// - /julia/* - Julia Pkg server protocol -// - /swift/* - Swift Package Registry protocol // - /v2/* - OCI/Docker container registry protocol -// - /apk/* - Alpine APK repository protocol // - /debian/* - Debian/APT repository protocol // - /rpm/* - RPM/Yum repository protocol // // Additional endpoints: -// - /health - Health check endpoint -// - /stats - Cache statistics (JSON) +// - /health - Health check endpoint +// - /stats - Cache statistics (JSON) // - /openapi.json - OpenAPI spec (JSON) -// - /metrics - Prometheus metrics -// -// Web UI (HTML), mounted under /ui so reverse proxies can gate it -// separately from the package endpoints: -// - /ui/ - Dashboard -// - /ui/install - Client configuration guide -// - /ui/packages - List all cached packages -// - /ui/search - Search packages -// - /ui/package/... - Package and version detail pages -// - /ui/api/browse/... - Archive browsing (used by the UI) -// - /ui/api/compare/... - Archive diffing (used by the UI) +// - /packages - List all cached packages (HTML) +// - /search - Search packages (HTML) // // API endpoints for enrichment data: // - GET /api/package/{ecosystem}/{name} - Package metadata @@ -49,35 +36,27 @@ package server import ( - "cmp" "context" "database/sql" "encoding/json" - "errors" "fmt" "log/slog" - "net" "net/http" - "net/url" "strconv" "strings" "time" - "github.com/git-pkgs/cooldown" swaggerdoc "github.com/git-pkgs/proxy/docs/swagger" - "github.com/git-pkgs/proxy/internal/accesslog" "github.com/git-pkgs/proxy/internal/config" + "github.com/git-pkgs/proxy/internal/cooldown" "github.com/git-pkgs/proxy/internal/database" "github.com/git-pkgs/proxy/internal/enrichment" "github.com/git-pkgs/proxy/internal/handler" - upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient" "github.com/git-pkgs/proxy/internal/metrics" "github.com/git-pkgs/proxy/internal/mirror" - "github.com/git-pkgs/proxy/internal/packageurl" - "github.com/git-pkgs/proxy/internal/scanner" "github.com/git-pkgs/proxy/internal/storage" + "github.com/git-pkgs/purl" "github.com/git-pkgs/registries/fetch" - "github.com/git-pkgs/registries/safehttp" "github.com/git-pkgs/spdx" "github.com/go-chi/chi/v5" "github.com/go-chi/chi/v5/middleware" @@ -89,48 +68,21 @@ const ( serverIdleTimeout = 60 * time.Second dashboardTopN = 10 hoursPerDay = 24 - - // Upstream transport defaults, matching what fetch.NewFetcher would use - // if we did not hand it our own client. Go's default transport keeps only - // two idle connections per host and never times out waiting for response - // headers. - upstreamMaxIdleConnsPerHost = 10 - upstreamResponseHeaderTimeout = 60 * time.Second ) // Server is the main proxy server. type Server struct { - cfg *config.Config - db *database.DB - storage storage.Storage - logger *slog.Logger - buildInfo BuildInfo - http *http.Server - templates *Templates - cancel context.CancelFunc - healthCache *healthCache - accessLog *accesslog.Logger - ecr *ecrTokens - breakers *breakerMonitor + cfg *config.Config + db *database.DB + storage storage.Storage + logger *slog.Logger + http *http.Server + templates *Templates + cancel context.CancelFunc } // New creates a new Server with the given configuration. -func New(cfg *config.Config, logger *slog.Logger, buildInfo BuildInfo) (*Server, error) { - var activityLog *accesslog.Logger - if cfg.AccessLog.Path != "" { - var err error - activityLog, err = accesslog.Open(cfg.AccessLog.Path) - if err != nil { - return nil, fmt.Errorf("initializing access log: %w", err) - } - } - closeAccessLog := true - defer func() { - if closeAccessLog && activityLog != nil { - _ = activityLog.Close() - } - }() - +func New(cfg *config.Config, logger *slog.Logger) (*Server, error) { // Initialize database var db *database.DB var err error @@ -172,85 +124,30 @@ func New(cfg *config.Config, logger *slog.Logger, buildInfo BuildInfo) (*Server, return nil, fmt.Errorf("verifying storage connectivity: %w", err) } - hc, err := newHealthCache(store, cfg.Health.StorageProbeInterval, logger) - if err != nil { - _ = store.Close() - _ = db.Close() - return nil, fmt.Errorf("initializing health cache: %w", err) - } - - server := &Server{ - cfg: cfg, - db: db, - storage: store, - logger: logger, - buildInfo: buildInfo, - templates: &Templates{}, - healthCache: hc, - accessLog: activityLog, - ecr: newECRTokens(logger), - } - closeAccessLog = false - return server, nil + return &Server{ + cfg: cfg, + db: db, + storage: store, + logger: logger, + templates: &Templates{}, + }, nil } // Start starts the HTTP server. -func (s *Server) Start(listeners ...net.Listener) error { - if len(listeners) > 1 { - return errors.New("only one listener is supported") - } - var listener net.Listener - if len(listeners) == 1 { - listener = listeners[0] - if listener == nil { - return errors.New("listener is required") - } - } - return s.serve(listener) -} - -func (s *Server) serve(listener net.Listener) error { - // Use one authentication-aware transport for metadata and artifacts so - // configured credentials and cached OCI challenges apply consistently. - safeClient := newUpstreamClient(s.cfg.Upstream) - baseTransport := safeClient.Transport - if s.accessLog != nil { - baseTransport = upstreamhttp.NewAccessLogTransport(baseTransport, s.accessLog, s.logger) - } - authTransport := upstreamhttp.NewTransport(baseTransport, upstreamhttp.AuthFunc(s.authForURL)) - metadataClient := *safeClient - metadataClient.Timeout = s.cfg.ParseHTTPTimeout() - metadataClient.Transport = authTransport - artifactClient := metadataClient - artifactClient.Timeout = serverWriteTimeout - - // Create shared components with circuit breaker. - baseFetcher := fetch.NewFetcher(fetch.WithHTTPClient(&artifactClient)) +func (s *Server) Start() error { + // Create shared components with circuit breaker + baseFetcher := fetch.NewFetcher(fetch.WithAuthFunc(s.authForURL)) fetcher := fetch.NewCircuitBreakerFetcher(baseFetcher) - s.breakers = newBreakerMonitor(fetcher, s.logger) resolver := fetch.NewResolver() cd := &cooldown.Config{ Default: s.cfg.Cooldown.Default, Ecosystems: s.cfg.Cooldown.Ecosystems, - Packages: s.cfg.Cooldown.NormalizedPackages(), + Packages: s.cfg.Cooldown.Packages, } proxy := handler.NewProxy(s.db, s.storage, fetcher, resolver, s.logger) - proxy.HTTPClient = &metadataClient - proxy.AuthForURL = s.authForURL proxy.Cooldown = cd - scanGroup, err := configureScanning(proxy, s.cfg.Scanning, s.cfg.BaseURL, s.logger) - if err != nil { - return fmt.Errorf("configuring scanners: %w", err) - } proxy.CacheMetadata = s.cfg.CacheMetadata proxy.MetadataTTL = s.cfg.ParseMetadataTTL() - proxy.MetadataMaxSize = s.cfg.ParseMetadataMaxSize() - proxy.GradleReadOnly = s.cfg.Gradle.BuildCache.ReadOnly - proxy.NPMFullMetadata = s.cfg.Upstream.NPMFullMetadata - proxy.GradleMaxUploadSize = s.cfg.ParseGradleBuildCacheMaxUploadSize() - proxy.DirectServe = s.cfg.Storage.DirectServe - proxy.DirectServeTTL = s.cfg.ParseDirectServeTTL() - proxy.DirectServeBaseURL = s.cfg.Storage.DirectServeBaseURL // Create router with Chi r := chi.NewRouter() @@ -258,6 +155,7 @@ func (s *Server) serve(listener net.Listener) error { // Add middleware r.Use(middleware.RequestID) r.Use(RequestIDMiddleware) + r.Use(middleware.RealIP) r.Use(s.LoggerMiddleware) r.Use(middleware.Recoverer) r.Use(func(next http.Handler) http.Handler { @@ -271,43 +169,53 @@ func (s *Server) serve(listener net.Listener) error { }) // Mount protocol handlers - s.mountProtocolHandlers(r, proxy) + npmHandler := handler.NewNPMHandler(proxy, s.cfg.BaseURL) + cargoHandler := handler.NewCargoHandler(proxy, s.cfg.BaseURL) + gemHandler := handler.NewGemHandler(proxy, s.cfg.BaseURL) + goHandler := handler.NewGoHandler(proxy, s.cfg.BaseURL) + hexHandler := handler.NewHexHandler(proxy, s.cfg.BaseURL) + pubHandler := handler.NewPubHandler(proxy, s.cfg.BaseURL) + pypiHandler := handler.NewPyPIHandler(proxy, s.cfg.BaseURL) + mavenHandler := handler.NewMavenHandler(proxy, s.cfg.BaseURL) + nugetHandler := handler.NewNuGetHandler(proxy, s.cfg.BaseURL) + composerHandler := handler.NewComposerHandler(proxy, s.cfg.BaseURL) + conanHandler := handler.NewConanHandler(proxy, s.cfg.BaseURL) + condaHandler := handler.NewCondaHandler(proxy, s.cfg.BaseURL) + cranHandler := handler.NewCRANHandler(proxy, s.cfg.BaseURL) + containerHandler := handler.NewContainerHandler(proxy, s.cfg.BaseURL) + debianHandler := handler.NewDebianHandler(proxy, s.cfg.BaseURL) + rpmHandler := handler.NewRPMHandler(proxy, s.cfg.BaseURL) - // Health, stats, and metrics endpoints + r.Mount("/npm", http.StripPrefix("/npm", npmHandler.Routes())) + r.Mount("/cargo", http.StripPrefix("/cargo", cargoHandler.Routes())) + r.Mount("/gem", http.StripPrefix("/gem", gemHandler.Routes())) + r.Mount("/go", http.StripPrefix("/go", goHandler.Routes())) + r.Mount("/hex", http.StripPrefix("/hex", hexHandler.Routes())) + r.Mount("/pub", http.StripPrefix("/pub", pubHandler.Routes())) + r.Mount("/pypi", http.StripPrefix("/pypi", pypiHandler.Routes())) + r.Mount("/maven", http.StripPrefix("/maven", mavenHandler.Routes())) + r.Mount("/nuget", http.StripPrefix("/nuget", nugetHandler.Routes())) + r.Mount("/composer", http.StripPrefix("/composer", composerHandler.Routes())) + r.Mount("/conan", http.StripPrefix("/conan", conanHandler.Routes())) + r.Mount("/conda", http.StripPrefix("/conda", condaHandler.Routes())) + r.Mount("/cran", http.StripPrefix("/cran", cranHandler.Routes())) + r.Mount("/v2", http.StripPrefix("/v2", containerHandler.Routes())) + r.Mount("/debian", http.StripPrefix("/debian", debianHandler.Routes())) + r.Mount("/rpm", http.StripPrefix("/rpm", rpmHandler.Routes())) + + // Health, stats, and static endpoints r.Get("/health", s.handleHealth) r.Get("/stats", s.handleStats) r.Get("/openapi.json", s.handleOpenAPIJSON) r.Get("/metrics", func(w http.ResponseWriter, r *http.Request) { - // Breaker state is only held in the fetcher, so publish it on scrape. - s.breakers.snapshot() metrics.Handler().ServeHTTP(w, r) }) - - // Internal route used by external scanners to pull staged artifact - // bytes before they're committed to the cache. Only wired up when - // scanning is actually configured, so there's no unauthenticated path - // to storage objects sitting in the router when the feature is unused. - // Restrict this to internal-network access only at the - // ingress/network-policy layer. - if scanGroup.Enabled() && len(proxy.ScanSigningKey) > 0 { - r.Get("/_internal/scan-fetch", proxy.ServeScanFetch) - } - - // Web UI. Mounted under /ui so a reverse proxy can apply different - // access rules to it than to the package endpoints above (#123). - r.Route("/ui", func(ui chi.Router) { - ui.Mount("/static", http.StripPrefix("/ui/static/", staticHandler())) - ui.Get("/", s.handleRoot) - ui.Get("/install", s.handleInstall) - ui.Get("/search", s.handleSearch) - ui.Get("/packages", s.handlePackagesList) - ui.Get("/package/{ecosystem}/*", s.handlePackagePath) - ui.Get("/api/browse/{ecosystem}/*", s.handleBrowsePath) - ui.Get("/api/compare/{ecosystem}/*", s.handleComparePath) - }) - r.Get("/", func(w http.ResponseWriter, r *http.Request) { - http.Redirect(w, r, "/ui/", http.StatusFound) - }) + r.Mount("/static", http.StripPrefix("/static/", staticHandler())) + r.Get("/", s.handleRoot) + r.Get("/install", s.handleInstall) + r.Get("/search", s.handleSearch) + r.Get("/packages", s.handlePackagesList) + r.Get("/package/{ecosystem}/*", s.handlePackagePath) // API endpoints for enrichment data enrichSvc := enrichment.New(s.logger) @@ -320,10 +228,13 @@ func (s *Server) serve(listener net.Listener) error { r.Get("/api/search", apiHandler.HandleSearch) r.Get("/api/packages", apiHandler.HandlePackagesList) + // Archive browsing and comparison endpoints also use wildcard for namespaced packages + r.Get("/api/browse/{ecosystem}/*", s.handleBrowsePath) + r.Get("/api/compare/{ecosystem}/*", s.handleComparePath) + // Start background context (used by mirror jobs and cleanup) bgCtx, bgCancel := context.WithCancel(context.Background()) s.cancel = bgCancel - s.startGradleBuildCacheEviction(bgCtx) // Mirror API endpoints (opt-in via mirror_api config or PROXY_MIRROR_API env) if s.cfg.MirrorAPI { @@ -347,140 +258,13 @@ func (s *Server) serve(listener net.Listener) error { s.logger.Info("starting server", "listen", s.cfg.Listen, "base_url", s.cfg.BaseURL, - "ui_url", s.cfg.UIBaseURL, "storage", s.storage.URL(), - "database", s.cfg.Database.String()) + "database", s.cfg.Database.Path) go s.updateCacheStatsMetrics() - go s.startEvictionLoop(bgCtx) - if listener != nil { - return s.http.Serve(listener) - } return s.http.ListenAndServe() } -// mountProtocolHandlers constructs every ecosystem handler and mounts it on -// r under its protocol prefix. -func (s *Server) mountProtocolHandlers(r chi.Router, proxy *handler.Proxy) { - npmHandler := handler.NewNPMHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.NPM) - cargoHandler := handler.NewCargoHandler( - proxy, - s.cfg.BaseURL, - s.cfg.Upstream.Cargo, - s.cfg.Upstream.CargoDownload, - ) - gemHandler := handler.NewGemHandlerWithUpstream(proxy, s.cfg.BaseURL, s.cfg.Upstream.Gem) - goHandler := handler.NewGoHandlerWithUpstream(proxy, s.cfg.BaseURL, s.cfg.Upstream.Go) - hexHandler := handler.NewHexHandlerWithUpstreams( - proxy, - s.cfg.BaseURL, - s.cfg.Upstream.Hex, - s.cfg.Upstream.HexAPI, - ) - pubHandler := handler.NewPubHandlerWithUpstream(proxy, s.cfg.BaseURL, s.cfg.Upstream.Pub) - pypiHandler := handler.NewPyPIHandlerWithUpstreams( - proxy, - s.cfg.BaseURL, - s.cfg.Upstream.PyPI, - s.cfg.Upstream.PyPIDownload, - ) - mavenHandler := handler.NewMavenHandler( - proxy, - s.cfg.BaseURL, - s.cfg.Upstream.Maven, - s.cfg.Upstream.GradlePluginPortal, - ) - gradleHandler := handler.NewGradleBuildCacheHandler(proxy) - nugetHandler := handler.NewNuGetHandlerWithUpstreams( - proxy, - s.cfg.BaseURL, - s.cfg.Upstream.NuGet, - s.cfg.Upstream.NuGetSearch, - ) - composerHandler := handler.NewComposerHandlerWithUpstreams( - proxy, - s.cfg.BaseURL, - s.cfg.Upstream.Composer, - s.cfg.Upstream.ComposerRepository, - ) - conanHandler := handler.NewConanHandlerWithUpstream(proxy, s.cfg.BaseURL, s.cfg.Upstream.Conan) - condaHandler := handler.NewCondaHandlerWithUpstream(proxy, s.cfg.BaseURL, s.cfg.Upstream.Conda) - cranHandler := handler.NewCRANHandlerWithUpstream(proxy, s.cfg.BaseURL, s.cfg.Upstream.CRAN) - juliaHandler := handler.NewJuliaHandlerWithUpstream(proxy, s.cfg.Upstream.Julia) - swiftHandler := handler.NewSwiftHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.Swift) - homebrewHandler := handler.NewHomebrewHandler(proxy, s.cfg.Upstream.HomebrewAPI) - containerHandler := handler.NewContainerHandlerWithRegistry( - proxy, - s.cfg.BaseURL, - s.cfg.Upstream.OCIDefault, - s.cfg.Upstream.OCI, - ) - handler.RegisterHomebrewArtifacts(containerHandler, s.cfg.Upstream.HomebrewArtifact) - helmHandler := handler.NewHelmHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.Helm) - apkHandler := handler.NewAPKHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.APK) - debianHandler := handler.NewDebianHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.Debian) - rpmHandler := handler.NewRPMHandlerWithUpstream(proxy, s.cfg.BaseURL, s.cfg.Upstream.RPM) - genericHandler := handler.NewGenericHandler(proxy, s.cfg.Upstream.Generic) - - r.Mount("/npm", http.StripPrefix("/npm", npmHandler.Routes())) - r.Mount("/cargo", http.StripPrefix("/cargo", cargoHandler.Routes())) - r.Mount("/gem", http.StripPrefix("/gem", gemHandler.Routes())) - r.Mount("/go", http.StripPrefix("/go", goHandler.Routes())) - r.Mount("/hex", http.StripPrefix("/hex", hexHandler.Routes())) - r.Mount("/pub", http.StripPrefix("/pub", pubHandler.Routes())) - r.Mount("/pypi", http.StripPrefix("/pypi", pypiHandler.Routes())) - r.Mount("/maven", http.StripPrefix("/maven", mavenHandler.Routes())) - r.Mount("/gradle", http.StripPrefix("/gradle", gradleHandler.Routes())) - r.Mount("/nuget", http.StripPrefix("/nuget", nugetHandler.Routes())) - r.Mount("/composer", http.StripPrefix("/composer", composerHandler.Routes())) - r.Mount("/conan", http.StripPrefix("/conan", conanHandler.Routes())) - r.Mount("/conda", http.StripPrefix("/conda", condaHandler.Routes())) - r.Mount("/cran", http.StripPrefix("/cran", cranHandler.Routes())) - r.Mount("/julia", http.StripPrefix("/julia", juliaHandler.Routes())) - r.Mount("/swift", http.StripPrefix("/swift", swiftHandler.Routes())) - r.Mount("/homebrew", http.StripPrefix("/homebrew", homebrewHandler.Routes())) - r.Mount("/v2", http.StripPrefix("/v2", containerHandler.Routes())) - r.Mount("/helm", http.StripPrefix("/helm", helmHandler.Routes())) - r.Mount("/apk", http.StripPrefix("/apk", apkHandler.Routes())) - r.Mount("/debian", http.StripPrefix("/debian", debianHandler.Routes())) - r.Mount("/rpm", http.StripPrefix("/rpm", rpmHandler.Routes())) - r.Mount("/generic", http.StripPrefix("/generic", genericHandler.Routes())) -} - -// configureScanning builds the scanner group from cfg and wires it into -// proxy, returning the group so the caller can decide whether to mount the -// internal scan-fetch route. -func configureScanning(proxy *handler.Proxy, cfg config.ScanningConfig, baseURL string, logger *slog.Logger) (*scanner.Group, error) { - scanGroup, err := scanner.NewGroup(cfg, logger) - if err != nil { - return nil, err - } - proxy.Scanners = scanGroup - proxy.ScanSigningKey = []byte(cfg.SigningKeyExpanded()) - proxy.ScanFetchBaseURL = cmp.Or(cfg.FetchBaseURL, baseURL) - return scanGroup, nil -} - -// newUpstreamClient builds the shared upstream client: a safehttp client whose -// transport keeps upstreamMaxIdleConnsPerHost idle connections per host and -// gives up after upstreamResponseHeaderTimeout when an upstream accepts a -// request but stalls before sending headers. -func newUpstreamClient(upstream config.UpstreamConfig) *http.Client { - client := safehttp.New(nil, upstreamSafeHTTPOptions(upstream)) - if transport, ok := client.Transport.(*http.Transport); ok { - transport.MaxIdleConnsPerHost = upstreamMaxIdleConnsPerHost - transport.ResponseHeaderTimeout = upstreamResponseHeaderTimeout - } - return client -} - -func upstreamSafeHTTPOptions(upstream config.UpstreamConfig) safehttp.Options { - return safehttp.Options{ - AllowLoopback: upstream.AllowLoopback, - AllowPrivateHosts: upstream.AllowPrivateHosts, - } -} - // updateCacheStatsMetrics periodically updates cache statistics in Prometheus metrics. func (s *Server) updateCacheStatsMetrics() { ticker := time.NewTicker(1 * time.Minute) @@ -525,12 +309,6 @@ func (s *Server) Shutdown(ctx context.Context) error { } } - if s.accessLog != nil { - if err := s.accessLog.Close(); err != nil { - errs = append(errs, fmt.Errorf("access log close: %w", err)) - } - } - if s.db != nil { if err := s.db.Close(); err != nil { errs = append(errs, fmt.Errorf("database close: %w", err)) @@ -549,13 +327,6 @@ func (s *Server) authForURL(url string) (headerName, headerValue string) { if auth == nil { return "", "" } - if strings.EqualFold(auth.Type, "ecr") { - region := auth.Region - if region == "" { - region = ecrRegion(url) - } - return s.ecr.header(region) - } return auth.Header() } @@ -588,7 +359,6 @@ func (s *Server) handleRoot(w http.ResponseWriter, r *http.Request) { // Build dashboard data data := DashboardData{ - Layout: s.layoutFor(r), Stats: DashboardStats{ CachedArtifacts: stats.TotalArtifacts, TotalSize: formatSize(stats.TotalSize), @@ -675,12 +445,8 @@ func (s *Server) handleOpenAPIJSON(w http.ResponseWriter, _ *http.Request) { func (s *Server) handleInstall(w http.ResponseWriter, r *http.Request) { data := struct { - Layout - BaseURL string Registries []RegistryConfig }{ - Layout: s.layoutFor(r), - BaseURL: s.cfg.BaseURL, Registries: getRegistryConfigs(s.cfg.BaseURL), } @@ -694,7 +460,7 @@ func (s *Server) handleSearch(w http.ResponseWriter, r *http.Request) { ecosystem := r.URL.Query().Get("ecosystem") if query == "" { - http.Redirect(w, r, "/ui/", http.StatusSeeOther) + http.Redirect(w, r, "/", http.StatusSeeOther) return } @@ -743,7 +509,6 @@ func (s *Server) handleSearch(w http.ResponseWriter, r *http.Request) { totalPages := int((total + int64(limit) - 1) / int64(limit)) data := SearchPageData{ - Layout: s.layoutFor(r), Query: query, Ecosystem: ecosystem, Results: items, @@ -819,7 +584,6 @@ func (s *Server) handlePackagesList(w http.ResponseWriter, r *http.Request) { totalPages := int((total + int64(limit) - 1) / int64(limit)) data := PackagesListPageData{ - Layout: s.layoutFor(r), Ecosystem: ecosystem, SortBy: sortBy, Results: items, @@ -846,11 +610,8 @@ func (s *Server) handlePackagesList(w http.ResponseWriter, r *http.Request) { // {name}/compare/{v1}...{v2} -> compare versions func (s *Server) handlePackagePath(w http.ResponseWriter, r *http.Request) { ecosystem := chi.URLParam(r, "ecosystem") - segments, err := packagePathSegments(r) - if err != nil { - http.Error(w, err.Error(), http.StatusBadRequest) - return - } + wildcard := chi.URLParam(r, "*") + segments := splitWildcardPath(wildcard) if ecosystem == "" || len(segments) == 0 { http.Error(w, "ecosystem and package name required", http.StatusBadRequest) @@ -862,7 +623,7 @@ func (s *Server) handlePackagePath(w http.ResponseWriter, r *http.Request) { if seg == "compare" && i > 0 && i < len(segments)-1 { name := strings.Join(segments[:i], "/") versions := strings.Join(segments[i+1:], "/") - s.showComparePage(w, r, ecosystem, name, versions) + s.showComparePage(w, ecosystem, name, versions) return } } @@ -882,7 +643,7 @@ func (s *Server) handlePackagePath(w http.ResponseWriter, r *http.Request) { // segment is a version (if present) and everything else is the name. if len(segments) == 1 { // Single segment, no DB match: try package show (will 404). - s.showPackage(w, r, ecosystem, segments[0]) + s.showPackage(w, ecosystem, segments[0]) return } name = strings.Join(segments[:len(segments)-1], "/") @@ -891,17 +652,17 @@ func (s *Server) handlePackagePath(w http.ResponseWriter, r *http.Request) { switch { case len(rest) == 0 && !browse: - s.showPackage(w, r, ecosystem, name) + s.showPackage(w, ecosystem, name) case len(rest) == 1 && browse: - s.showBrowseSource(w, r, ecosystem, name, rest[0]) + s.showBrowseSource(w, ecosystem, name, rest[0]) case len(rest) == 1: - s.showVersion(w, r, ecosystem, name, rest[0]) + s.showVersion(w, ecosystem, name, rest[0]) default: http.Error(w, "not found", http.StatusNotFound) } } -func (s *Server) showPackage(w http.ResponseWriter, r *http.Request, ecosystem, name string) { +func (s *Server) showPackage(w http.ResponseWriter, ecosystem, name string) { pkg, err := s.db.GetPackageByEcosystemName(ecosystem, name) if err != nil { s.logger.Error("failed to get package", "error", err, "ecosystem", ecosystem, "name", name) @@ -926,7 +687,6 @@ func (s *Server) showPackage(w http.ResponseWriter, r *http.Request, ecosystem, } data := PackageShowData{ - Layout: s.layoutFor(r), Package: pkg, Versions: versions, Vulnerabilities: vulns, @@ -938,7 +698,7 @@ func (s *Server) showPackage(w http.ResponseWriter, r *http.Request, ecosystem, } } -func (s *Server) showVersion(w http.ResponseWriter, r *http.Request, ecosystem, name, version string) { +func (s *Server) showVersion(w http.ResponseWriter, ecosystem, name, version string) { pkg, err := s.db.GetPackageByEcosystemName(ecosystem, name) if err != nil || pkg == nil { s.logger.Error("failed to get package", "error", err) @@ -946,7 +706,7 @@ func (s *Server) showVersion(w http.ResponseWriter, r *http.Request, ecosystem, return } - versionPURL := packageurl.WithVersionString(pkg.PURL, version) + versionPURL := purl.MakePURLString(ecosystem, name, version) ver, err := s.db.GetVersionByPURL(versionPURL) if err != nil || ver == nil { s.logger.Error("failed to get version", "error", err) @@ -968,12 +728,15 @@ func (s *Server) showVersion(w http.ResponseWriter, r *http.Request, ecosystem, isOutdated := pkg.LatestVersion.Valid && pkg.LatestVersion.String != version - // A version whose only cached artifact is a metadata sidecar cannot be - // browsed, so it must not be advertised as cached. - hasCached := firstBrowsableArtifact(artifacts) != nil + hasCached := false + for _, art := range artifacts { + if art.StoragePath.Valid { + hasCached = true + break + } + } data := VersionShowData{ - Layout: s.layoutFor(r), Package: pkg, Version: ver, Artifacts: artifacts, @@ -988,21 +751,11 @@ func (s *Server) showVersion(w http.ResponseWriter, r *http.Request, ecosystem, } } -func (s *Server) cachedVersionPURL(ecosystem, name, version string) string { - pkg, err := s.db.GetPackageByEcosystemName(ecosystem, name) - if err != nil || pkg == nil { - return "" - } - return packageurl.WithVersionString(pkg.PURL, version) -} - -func (s *Server) showBrowseSource(w http.ResponseWriter, r *http.Request, ecosystem, name, version string) { +func (s *Server) showBrowseSource(w http.ResponseWriter, ecosystem, name, version string) { data := BrowseSourceData{ - Layout: s.layoutFor(r), - Ecosystem: ecosystem, - PackageName: name, - Version: version, - EscapedVersion: url.PathEscape(version), + Ecosystem: ecosystem, + PackageName: name, + Version: version, } if err := s.templates.Render(w, "browse_source", data); err != nil { @@ -1011,7 +764,7 @@ func (s *Server) showBrowseSource(w http.ResponseWriter, r *http.Request, ecosys } } -func (s *Server) showComparePage(w http.ResponseWriter, r *http.Request, ecosystem, name, versions string) { +func (s *Server) showComparePage(w http.ResponseWriter, ecosystem, name, versions string) { const compareVersionParts = 2 parts := strings.Split(versions, "...") if len(parts) != compareVersionParts { @@ -1020,13 +773,10 @@ func (s *Server) showComparePage(w http.ResponseWriter, r *http.Request, ecosyst } data := ComparePageData{ - Layout: s.layoutFor(r), - Ecosystem: ecosystem, - PackageName: name, - FromVersion: parts[0], - ToVersion: parts[1], - EscapedFromVersion: url.PathEscape(parts[0]), - EscapedToVersion: url.PathEscape(parts[1]), + Ecosystem: ecosystem, + PackageName: name, + FromVersion: parts[0], + ToVersion: parts[1], } if err := s.templates.Render(w, "compare_versions", data); err != nil { @@ -1035,53 +785,23 @@ func (s *Server) showComparePage(w http.ResponseWriter, r *http.Request, ecosyst } } -// handleHealth responds with a structured JSON health report. -// +// handleHealth responds with a simple health check. // @Summary Health check // @Tags meta -// @Produce json -// @Success 200 {object} HealthResponse -// @Failure 503 {object} HealthResponse +// @Produce plain +// @Success 200 {string} string +// @Failure 503 {string} string // @Router /health [get] func (s *Server) handleHealth(w http.ResponseWriter, r *http.Request) { - w.Header().Set("Content-Type", "application/json") - - resp := HealthResponse{ - Status: "ok", - Checks: map[string]HealthCheck{}, - CircuitBreakers: s.breakers.snapshot(), - } - - // Database check (short-circuit; do not waste a storage probe call when DB is down). - // On DB failure the storage entry reports "skipped" rather than being omitted so - // the response always carries the same key set for monitors that expect it. + // Check database connectivity if _, err := s.db.SchemaVersion(); err != nil { - resp.Status = "error" - resp.Checks["database"] = HealthCheck{Status: "error", Error: err.Error()} - resp.Checks["storage"] = HealthCheck{Status: "skipped"} w.WriteHeader(http.StatusServiceUnavailable) - _ = json.NewEncoder(w).Encode(resp) + _, _ = fmt.Fprint(w, "database error") return } - resp.Checks["database"] = HealthCheck{Status: "ok"} - - // Storage probe (via cache). - if err := s.healthCache.Check(); err != nil { - resp.Status = "error" - sc := HealthCheck{Status: "error", Error: err.Error()} - var pe *probeError - if errors.As(err, &pe) { - sc.Step = pe.step - } - resp.Checks["storage"] = sc - w.WriteHeader(http.StatusServiceUnavailable) - _ = json.NewEncoder(w).Encode(resp) - return - } - resp.Checks["storage"] = HealthCheck{Status: "ok"} w.WriteHeader(http.StatusOK) - _ = json.NewEncoder(w).Encode(resp) + _, _ = fmt.Fprint(w, "ok") } // StatsResponse contains cache statistics. @@ -1098,20 +818,20 @@ type StatsResponse struct { // @Tags meta // @Produce json // @Success 200 {object} StatsResponse -// @Failure 500 {object} ErrorResponse +// @Failure 500 {string} string // @Router /stats [get] func (s *Server) handleStats(w http.ResponseWriter, r *http.Request) { ctx := r.Context() count, err := s.db.GetCachedArtifactCount() if err != nil { - internalError(w, "failed to get artifact count") + http.Error(w, "failed to get artifact count", http.StatusInternalServerError) return } size, err := s.db.GetTotalCacheSize() if err != nil { - internalError(w, "failed to get cache size") + http.Error(w, "failed to get cache size", http.StatusInternalServerError) return } @@ -1122,7 +842,7 @@ func (s *Server) handleStats(w http.ResponseWriter, r *http.Request) { TotalSize: size, TotalSizeHuman: formatSize(size), StorageURL: s.storage.URL(), - DatabasePath: s.cfg.Database.String(), + DatabasePath: s.cfg.Database.Path, } w.Header().Set("Content-Type", "application/json") diff --git a/internal/server/server_test.go b/internal/server/server_test.go index d6bd20f..be88bf6 100644 --- a/internal/server/server_test.go +++ b/internal/server/server_test.go @@ -1,23 +1,15 @@ package server import ( - "context" "database/sql" "encoding/json" - "errors" "fmt" - "html" "io" "log/slog" - "net" "net/http" "net/http/httptest" - "net/url" "os" - "os/exec" "path/filepath" - "regexp" - "strconv" "strings" "testing" "time" @@ -26,15 +18,12 @@ import ( "github.com/git-pkgs/proxy/internal/database" "github.com/git-pkgs/proxy/internal/handler" "github.com/git-pkgs/proxy/internal/storage" - "github.com/git-pkgs/purl" "github.com/git-pkgs/registries/fetch" - "github.com/git-pkgs/registries/safehttp" "github.com/go-chi/chi/v5" ) type testServer struct { handler http.Handler - server *Server db *database.DB storage storage.Storage tempDir string @@ -57,7 +46,7 @@ func newTestServer(t *testing.T) *testServer { t.Fatalf("failed to create database: %v", err) } - store, err := storage.OpenBucket(context.Background(), "file://"+storagePath) + store, err := storage.NewFilesystem(storagePath) if err != nil { _ = db.Close() _ = os.RemoveAll(tempDir) @@ -71,72 +60,48 @@ func newTestServer(t *testing.T) *testServer { cfg := &config.Config{ BaseURL: "http://localhost:8080", - Storage: config.StorageConfig{URL: "file://" + storagePath}, + Storage: config.StorageConfig{Path: storagePath}, Database: config.DatabaseConfig{Path: dbPath}, } r := chi.NewRouter() // Mount handlers - npmHandler := handler.NewNPMHandler(proxy, cfg.BaseURL, cfg.Upstream.NPM) - cargoHandler := handler.NewCargoHandler( - proxy, - cfg.BaseURL, - cfg.Upstream.Cargo, - cfg.Upstream.CargoDownload, - ) + npmHandler := handler.NewNPMHandler(proxy, cfg.BaseURL) + cargoHandler := handler.NewCargoHandler(proxy, cfg.BaseURL) gemHandler := handler.NewGemHandler(proxy, cfg.BaseURL) goHandler := handler.NewGoHandler(proxy, cfg.BaseURL) pypiHandler := handler.NewPyPIHandler(proxy, cfg.BaseURL) - gradleHandler := handler.NewGradleBuildCacheHandler(proxy) - swiftHandler := handler.NewSwiftHandler(proxy, cfg.BaseURL, cfg.Upstream.Swift) r.Mount("/npm", http.StripPrefix("/npm", npmHandler.Routes())) r.Mount("/cargo", http.StripPrefix("/cargo", cargoHandler.Routes())) r.Mount("/gem", http.StripPrefix("/gem", gemHandler.Routes())) r.Mount("/go", http.StripPrefix("/go", goHandler.Routes())) r.Mount("/pypi", http.StripPrefix("/pypi", pypiHandler.Routes())) - r.Mount("/gradle", http.StripPrefix("/gradle", gradleHandler.Routes())) - r.Mount("/swift", http.StripPrefix("/swift", swiftHandler.Routes())) - - hc, err := newHealthCache(store, "30s", logger) - if err != nil { - _ = db.Close() - _ = os.RemoveAll(tempDir) - t.Fatalf("failed to create health cache: %v", err) - } // Create a minimal server struct for the handlers s := &Server{ - cfg: cfg, - db: db, - storage: store, - logger: logger, - buildInfo: BuildInfo{Version: "test-version", Commit: "test-commit"}, - templates: &Templates{}, - healthCache: hc, + cfg: cfg, + db: db, + storage: store, + logger: logger, + templates: &Templates{}, } r.Get("/health", s.handleHealth) r.Get("/stats", s.handleStats) r.Get("/openapi.json", s.handleOpenAPIJSON) - r.Route("/ui", func(ui chi.Router) { - ui.Mount("/static", http.StripPrefix("/ui/static/", staticHandler())) - ui.Get("/", s.handleRoot) - ui.Get("/install", s.handleInstall) - ui.Get("/search", s.handleSearch) - ui.Get("/packages", s.handlePackagesList) - ui.Get("/package/{ecosystem}/*", s.handlePackagePath) - ui.Get("/api/browse/{ecosystem}/*", s.handleBrowsePath) - ui.Get("/api/compare/{ecosystem}/*", s.handleComparePath) - }) - r.Get("/", func(w http.ResponseWriter, r *http.Request) { - http.Redirect(w, r, "/ui/", http.StatusFound) - }) + r.Mount("/static", http.StripPrefix("/static/", staticHandler())) + r.Get("/search", s.handleSearch) + r.Get("/package/{ecosystem}/*", s.handlePackagePath) + r.Get("/api/browse/{ecosystem}/*", s.handleBrowsePath) + r.Get("/api/compare/{ecosystem}/*", s.handleComparePath) + r.Get("/", s.handleRoot) + r.Get("/install", s.handleInstall) + r.Get("/packages", s.handlePackagesList) return &testServer{ handler: r, - server: s, db: db, storage: store, tempDir: tempDir, @@ -148,207 +113,6 @@ func (ts *testServer) close() { _ = os.RemoveAll(ts.tempDir) } -func TestUpstreamSafeHTTPOptions(t *testing.T) { - opts := upstreamSafeHTTPOptions(config.UpstreamConfig{ - AllowPrivateHosts: []string{"registry.internal"}, - AllowLoopback: true, - }) - - if !opts.AllowLoopback { - t.Fatal("AllowLoopback = false, want true") - } - privateIP := net.ParseIP("10.0.0.12") - if err := safehttp.CheckHostIP("registry.internal", privateIP, opts); err != nil { - t.Fatalf("listed private upstream rejected: %v", err) - } - if err := safehttp.CheckHostIP("other.internal", privateIP, opts); err == nil { - t.Fatal("unlisted private upstream was allowed") - } -} - -func TestStartUsesConfiguredLoopbackUpstreams(t *testing.T) { - if os.Getenv("PROXY_TEST_LOOPBACK_UPSTREAM") == "1" { - testStartUsesConfiguredLoopbackUpstreams(t) - return - } - - cmd := exec.Command(os.Args[0], "-test.run=^TestStartUsesConfiguredLoopbackUpstreams$") - cmd.Env = append(os.Environ(), "PROXY_TEST_LOOPBACK_UPSTREAM=1") - if output, err := cmd.CombinedOutput(); err != nil { - t.Fatalf("configured loopback upstream test failed: %v\n%s", err, output) - } -} - -func testStartUsesConfiguredLoopbackUpstreams(t *testing.T) { - upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - switch r.URL.Path { - case "/pypi/simple/ruff/": - w.Header().Set("Content-Type", "application/vnd.pypi.simple.v1+json") - _, _ = io.WriteString(w, `{"meta":{"api-version":"1.4"},"name":"ruff","files":[]}`) - case "/v2/library/demo/manifests/latest": - w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json") - _, _ = io.WriteString(w, `{"schemaVersion":2}`) - default: - t.Errorf("unexpected upstream path: %q", r.URL.Path) - http.NotFound(w, r) - } - })) - defer upstream.Close() - - listener, err := net.Listen("tcp", "127.0.0.1:0") - if err != nil { - t.Fatalf("reserving proxy address: %v", err) - } - t.Cleanup(func() { _ = listener.Close() }) - listenAddress := listener.Addr().String() - - tempDir := t.TempDir() - cfg := config.Default() - cfg.Listen = listenAddress - cfg.BaseURL = "http://" + listenAddress - cfg.Database.Path = filepath.Join(tempDir, "proxy.db") - cfg.Storage.URL = "file://" + filepath.Join(tempDir, "artifacts") - cfg.Upstream.PyPI = upstream.URL + "/pypi" - cfg.Upstream.PyPIDownload = upstream.URL + "/pypi" - cfg.Upstream.OCIDefault = upstream.URL - cfg.Upstream.AllowLoopback = true - if err := cfg.Validate(); err != nil { - t.Fatalf("validating config: %v", err) - } - - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - proxyServer, err := New(cfg, logger, BuildInfo{Version: "test", Commit: "test"}) - if err != nil { - t.Fatalf("creating server: %v", err) - } - startErr := make(chan error, 1) - go func() { - startErr <- proxyServer.Start(listener) - }() - - defer func() { - ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second) - defer cancel() - if err := proxyServer.Shutdown(ctx); err != nil { - t.Errorf("shutting down server: %v", err) - } - if err := <-startErr; !errors.Is(err, http.ErrServerClosed) { - t.Errorf("Start() error = %v, want %v", err, http.ErrServerClosed) - } - }() - - probeClient := &http.Client{Timeout: 250 * time.Millisecond} - deadline := time.Now().Add(5 * time.Second) - for { - req, err := http.NewRequest(http.MethodGet, cfg.BaseURL+"/pypi/simple/ruff/", nil) - if err != nil { - t.Fatalf("creating request: %v", err) - } - req.Header.Set("Accept", "application/vnd.pypi.simple.v1+json") - resp, requestErr := probeClient.Do(req) - if requestErr == nil { - body, readErr := io.ReadAll(resp.Body) - _ = resp.Body.Close() - if readErr != nil { - t.Fatalf("reading response: %v", readErr) - } - if resp.StatusCode != http.StatusOK { - t.Fatalf("status = %d, want %d; body: %s", resp.StatusCode, http.StatusOK, body) - } - if !strings.Contains(string(body), `"name":"ruff"`) { - t.Fatalf("response body = %s, want PyPI metadata", body) - } - break - } - if time.Now().After(deadline) { - t.Fatalf("proxy did not start: %v", requestErr) - } - time.Sleep(10 * time.Millisecond) - } - - // This checks upstream routing, not latency. Allow time for fetching and - // cache I/O under -race on slower CI workers. - client := &http.Client{Timeout: 5 * time.Second} - resp, err := client.Get(cfg.BaseURL + "/v2/library/demo/manifests/latest") - if err != nil { - t.Fatalf("OCI request failed: %v", err) - } - body, readErr := io.ReadAll(resp.Body) - _ = resp.Body.Close() - if readErr != nil { - t.Fatalf("reading OCI response: %v", readErr) - } - if resp.StatusCode != http.StatusOK { - t.Fatalf("OCI status = %d, want %d; body: %s", resp.StatusCode, http.StatusOK, body) - } - if !strings.Contains(string(body), `"schemaVersion":2`) { - t.Fatalf("OCI response body = %s, want manifest", body) - } -} - -// TestScanFetchRouteNotMountedWhenScanningDisabled verifies the internal -// scan-fetch route is absent (404), not merely unauthenticated, when -// scanning is disabled: mounting it unconditionally would expose an -// unauthenticated way to pull arbitrary storage objects by path. -func TestScanFetchRouteNotMountedWhenScanningDisabled(t *testing.T) { - listener, err := net.Listen("tcp", "127.0.0.1:0") - if err != nil { - t.Fatalf("reserving proxy address: %v", err) - } - t.Cleanup(func() { _ = listener.Close() }) - listenAddress := listener.Addr().String() - - tempDir := t.TempDir() - cfg := config.Default() - cfg.Listen = listenAddress - cfg.BaseURL = "http://" + listenAddress - cfg.Database.Path = filepath.Join(tempDir, "proxy.db") - cfg.Storage.URL = "file://" + filepath.Join(tempDir, "artifacts") - if err := cfg.Validate(); err != nil { - t.Fatalf("validating config: %v", err) - } - - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - proxyServer, err := New(cfg, logger, BuildInfo{Version: "test", Commit: "test"}) - if err != nil { - t.Fatalf("creating server: %v", err) - } - startErr := make(chan error, 1) - go func() { - startErr <- proxyServer.Start(listener) - }() - defer func() { - ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second) - defer cancel() - if err := proxyServer.Shutdown(ctx); err != nil { - t.Errorf("shutting down server: %v", err) - } - if err := <-startErr; !errors.Is(err, http.ErrServerClosed) { - t.Errorf("Start() error = %v, want %v", err, http.ErrServerClosed) - } - }() - - client := &http.Client{Timeout: 250 * time.Millisecond} - deadline := time.Now().Add(5 * time.Second) - var resp *http.Response - for { - var requestErr error - resp, requestErr = client.Get(cfg.BaseURL + "/_internal/scan-fetch") - if requestErr == nil { - break - } - if time.Now().After(deadline) { - t.Fatalf("proxy did not start: %v", requestErr) - } - time.Sleep(10 * time.Millisecond) - } - defer func() { _ = resp.Body.Close() }() - - if resp.StatusCode != http.StatusNotFound { - t.Errorf("scan-fetch status = %d, want 404 when scanning is disabled", resp.StatusCode) - } -} - // seedTestPackage creates a package, version, and artifact in the database for testing // page rendering. The package is created under the npm ecosystem with version 1.0.0. func seedTestPackage(t *testing.T, db *database.DB, name string) { @@ -413,55 +177,12 @@ func TestHealthEndpoint(t *testing.T) { ts.handler.ServeHTTP(w, req) if w.Code != http.StatusOK { - t.Fatalf("status = %d, want 200; body: %s", w.Code, w.Body.String()) + t.Errorf("expected status 200, got %d", w.Code) } - if got := w.Header().Get("Content-Type"); got != "application/json" { - t.Errorf("Content-Type = %q, want application/json", got) - } - var resp HealthResponse - if err := json.NewDecoder(w.Body).Decode(&resp); err != nil { - t.Fatalf("decoding response: %v", err) - } - if resp.Status != "ok" { - t.Errorf("status = %q, want ok", resp.Status) - } - if resp.Checks["database"].Status != "ok" { - t.Errorf("database check = %+v, want ok", resp.Checks["database"]) - } - if resp.Checks["storage"].Status != "ok" { - t.Errorf("storage check = %+v, want ok", resp.Checks["storage"]) - } -} -func TestHealthEndpoint_DBFailureShortCircuits(t *testing.T) { - ts := newTestServer(t) - defer ts.close() - - // Force DB failure by closing the connection. - _ = ts.db.Close() - - req := httptest.NewRequest("GET", "/health", nil) - w := httptest.NewRecorder() - ts.handler.ServeHTTP(w, req) - - if w.Code != http.StatusServiceUnavailable { - t.Fatalf("status = %d, want 503; body: %s", w.Code, w.Body.String()) - } - var resp HealthResponse - if err := json.NewDecoder(w.Body).Decode(&resp); err != nil { - t.Fatalf("decoding: %v", err) - } - if resp.Status != "error" { - t.Errorf("status = %q, want error", resp.Status) - } - if resp.Checks["database"].Status != "error" { - t.Errorf("database check = %+v, want error", resp.Checks["database"]) - } - storage, present := resp.Checks["storage"] - if !present { - t.Error("storage key should be present (with status=skipped) on DB short-circuit") - } else if storage.Status != "skipped" { - t.Errorf("storage check = %+v, want status=skipped", storage) + body := w.Body.String() + if body != "ok" { + t.Errorf("expected body 'ok', got %q", body) } } @@ -500,7 +221,7 @@ func TestDashboard(t *testing.T) { ts := newTestServer(t) defer ts.close() - req := httptest.NewRequest("GET", "/ui/", nil) + req := httptest.NewRequest("GET", "/", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -524,9 +245,6 @@ func TestDashboard(t *testing.T) { if !strings.Contains(body, "Cached Artifacts") { t.Error("dashboard should contain stats") } - if !strings.Contains(body, "proxy test-version (test-commit)") { - t.Error("dashboard footer should contain build information") - } if !strings.Contains(body, "Popular Packages") { t.Error("dashboard should contain popular packages section") } @@ -542,53 +260,11 @@ func TestDashboard(t *testing.T) { if !strings.Contains(body, ">debian<") { t.Error("dashboard should show debian in supported ecosystems") } - if !strings.Contains(body, ">swift<") { - t.Error("dashboard should show swift in supported ecosystems") - } if !strings.Contains(body, "/openapi.json") { t.Error("page should link to the OpenAPI JSON spec") } } -func TestSwiftHandlerMounted(t *testing.T) { - ts := newTestServer(t) - defer ts.close() - - req := httptest.NewRequest(http.MethodPut, "/swift/apple/example/1.2.3", strings.NewReader("ignored")) - w := httptest.NewRecorder() - ts.handler.ServeHTTP(w, req) - - if w.Code != http.StatusMethodNotAllowed { - t.Fatalf("status = %d, want 405; body: %s", w.Code, w.Body.String()) - } -} - -func TestSwiftCachedVersionPURLUsesStoredPackagePURL(t *testing.T) { - ts := newTestServer(t) - defer ts.close() - - packagePURL := "pkg:generic/swift-registry/apple.example?repository_url=https:%2F%2Fold.example%2Fswift" - if err := ts.db.UpsertPackage(&database.Package{ - PURL: packagePURL, - Ecosystem: "swift", - Name: "apple/example", - }); err != nil { - t.Fatalf("failed to upsert package: %v", err) - } - - s := &Server{ - cfg: &config.Config{ - Upstream: config.UpstreamConfig{Swift: "https://new.example/swift"}, - }, - db: ts.db, - } - got := s.cachedVersionPURL("swift", "apple/example", "1.2.3") - want := "pkg:generic/swift-registry/apple.example@1.2.3?repository_url=https:%2F%2Fold.example%2Fswift" - if got != want { - t.Errorf("cachedVersionPURL() = %q, want %q", got, want) - } -} - func min(a, b int) int { if a < b { return a @@ -668,33 +344,6 @@ func TestPyPISimple(t *testing.T) { } } -func TestGradleBuildCachePutGet(t *testing.T) { - ts := newTestServer(t) - defer ts.close() - - key := "abc123def456" - body := "build-cache-bytes" - - putReq := httptest.NewRequest(http.MethodPut, "/gradle/"+key, strings.NewReader(body)) - putW := httptest.NewRecorder() - ts.handler.ServeHTTP(putW, putReq) - - if putW.Code != http.StatusCreated { - t.Fatalf("expected status 201, got %d: %s", putW.Code, putW.Body.String()) - } - - getReq := httptest.NewRequest(http.MethodGet, "/gradle/"+key, nil) - getW := httptest.NewRecorder() - ts.handler.ServeHTTP(getW, getReq) - - if getW.Code != http.StatusOK { - t.Fatalf("expected status 200, got %d: %s", getW.Code, getW.Body.String()) - } - if got := getW.Body.String(); got != body { - t.Fatalf("expected body %q, got %q", body, got) - } -} - func TestGemSpecs(t *testing.T) { ts := newTestServer(t) defer ts.close() @@ -716,9 +365,8 @@ func TestStaticFiles(t *testing.T) { path string contentTypes []string }{ - {"/ui/static/vendor/tailwind.js", []string{"text/javascript", "application/javascript"}}, - {"/ui/static/vendor/lucide.min.js", []string{"text/javascript", "application/javascript"}}, - {"/ui/static/style.css", []string{"text/css"}}, + {"/static/tailwind.js", []string{"text/javascript", "application/javascript"}}, + {"/static/style.css", []string{"text/css"}}, } for _, tc := range tests { @@ -769,27 +417,11 @@ func TestCategorizeLicenseCSS(t *testing.T) { } } -func TestRootRedirectsToUI(t *testing.T) { - ts := newTestServer(t) - defer ts.close() - - req := httptest.NewRequest("GET", "/", nil) - w := httptest.NewRecorder() - ts.handler.ServeHTTP(w, req) - - if w.Code != http.StatusFound { - t.Errorf("expected status 302, got %d", w.Code) - } - if loc := w.Header().Get("Location"); loc != "/ui/" { - t.Errorf("expected redirect to /ui/, got %q", loc) - } -} - func TestDashboardWithEnrichmentStats(t *testing.T) { ts := newTestServer(t) defer ts.close() - req := httptest.NewRequest("GET", "/ui/", nil) + req := httptest.NewRequest("GET", "/", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -800,7 +432,7 @@ func TestDashboardWithEnrichmentStats(t *testing.T) { body := w.Body.String() // Dashboard should link to Tailwind JS - if !strings.Contains(body, "/ui/static/vendor/tailwind.js") { + if !strings.Contains(body, "/static/tailwind.js") { t.Error("dashboard should link to Tailwind JS") } @@ -841,7 +473,7 @@ func TestVersionShowWithHitCount(t *testing.T) { t.Fatalf("failed to upsert artifact: %v", err) } - req := httptest.NewRequest("GET", "/ui/package/npm/test/1.0.0", nil) + req := httptest.NewRequest("GET", "/package/npm/test/1.0.0", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -854,9 +486,6 @@ func TestVersionShowWithHitCount(t *testing.T) { if !strings.Contains(body, "42 cache hits") { t.Error("expected page to show hit count") } - if !strings.Contains(body, "proxy test-version (test-commit)") { - t.Error("version show footer should contain proxy build information, not the package version") - } } func TestSearchWithNullValues(t *testing.T) { @@ -896,7 +525,7 @@ func TestSearchWithNullValues(t *testing.T) { t.Fatalf("failed to upsert artifact: %v", err) } - req := httptest.NewRequest("GET", "/ui/search?q=test", nil) + req := httptest.NewRequest("GET", "/search?q=test", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -988,7 +617,7 @@ func TestSearchRedirectsWhenEmpty(t *testing.T) { ts := newTestServer(t) defer ts.close() - req := httptest.NewRequest("GET", "/ui/search", nil) + req := httptest.NewRequest("GET", "/search", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -997,8 +626,8 @@ func TestSearchRedirectsWhenEmpty(t *testing.T) { } loc := w.Header().Get("Location") - if loc != "/ui/" { - t.Errorf("expected redirect to /ui/, got %q", loc) + if loc != "/" { + t.Errorf("expected redirect to /, got %q", loc) } } @@ -1006,7 +635,7 @@ func TestPackageShowPage_NotFoundServer(t *testing.T) { ts := newTestServer(t) defer ts.close() - req := httptest.NewRequest("GET", "/ui/package/npm/nonexistent-srv", nil) + req := httptest.NewRequest("GET", "/package/npm/nonexistent-srv", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -1019,7 +648,7 @@ func TestVersionShowPage_NotFoundServer(t *testing.T) { ts := newTestServer(t) defer ts.close() - req := httptest.NewRequest("GET", "/ui/package/npm/nonexistent-srv/1.0.0", nil) + req := httptest.NewRequest("GET", "/package/npm/nonexistent-srv/1.0.0", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -1028,236 +657,6 @@ func TestVersionShowPage_NotFoundServer(t *testing.T) { } } -// TestVersionShowPage_PlusInVersion covers Debian/Ubuntu style versions such as -// nmap's "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1". PURL percent-encodes "+" as -// "%2B", so the UI must show the decoded version and resolve both the decoded -// and the still-encoded form of the URL back to the same version. -func TestVersionShowPage_PlusInVersion(t *testing.T) { - ts := newTestServer(t) - defer ts.close() - - const version = "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1" - const versionPURL = "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1" - - pkg := &database.Package{PURL: "pkg:deb/nmap", Ecosystem: "deb", Name: "nmap"} - if err := ts.db.UpsertPackage(pkg); err != nil { - t.Fatalf("failed to upsert package: %v", err) - } - if err := ts.db.UpsertVersion(&database.Version{ - PURL: versionPURL, PackagePURL: pkg.PURL, - }); err != nil { - t.Fatalf("failed to upsert version: %v", err) - } - - // The package page must link to and display the decoded version. - req := httptest.NewRequest("GET", "/ui/package/deb/nmap", nil) - w := httptest.NewRecorder() - ts.handler.ServeHTTP(w, req) - if w.Code != http.StatusOK { - t.Fatalf("package page: expected status 200, got %d", w.Code) - } - body := w.Body.String() - if strings.Contains(body, "%2B") { - t.Error("package page leaks PURL percent-encoding into the UI") - } - // html/template renders "+" as the "+" entity inside attributes and text. - if !strings.Contains(body, "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1") { - t.Error("expected package page to show the decoded version") - } - - // Both the decoded and the encoded URL must reach the version page. - for _, path := range []string{ - "/ui/package/deb/nmap/" + version, - "/ui/package/deb/nmap/7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1", - } { - req := httptest.NewRequest("GET", path, nil) - w := httptest.NewRecorder() - ts.handler.ServeHTTP(w, req) - if w.Code != http.StatusOK { - t.Errorf("GET %s: expected status 200, got %d", path, w.Code) - } - } -} - -// TestVersionURLEscaping covers versions whose characters are significant in a -// URL path: "/" splits off another path segment, "?" starts a query string, and -// a literal "%xx" is read back as the character it encodes. The pages show the -// decoded version but must build every link from a separately escaped value, -// and those links have to resolve back to the same version. -func TestVersionURLEscaping(t *testing.T) { - // A second version is needed for the compare controls to be rendered. - const otherVersion = "1.0.0" - - tests := []struct { - name string - version string - }{ - {"slash", "release/1"}, - {"question mark", "v1?build"}, - {"literal percent escape", "1.0%2B"}, - {"plus", "7.91+dfsg1-2ubuntu0.1"}, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - ts := newTestServer(t) - defer ts.close() - seedEscapingVersions(t, ts.db, tt.version, otherVersion) - - // The package page links to the escaped version. - escaped := url.PathEscape(tt.version) - versionPath := "/ui/package/deb/nmap/" + escaped - packagePage := ts.getOK(t, "/ui/package/deb/nmap") - if !containsValue(attrValues(packagePage, "href"), versionPath) { - t.Fatalf("package page has no link to %q; hrefs: %v", - versionPath, attrValues(packagePage, "href")) - } - - ts.checkVersionAndBrowsePages(t, versionPath, tt.version, escaped) - ts.checkComparePage(t, packagePage, tt.version, escaped, otherVersion) - }) - } -} - -// seedEscapingVersions stores a Debian package with the given versions, each -// with a cached artifact so that the version page offers its browse link. -func seedEscapingVersions(t *testing.T, db *database.DB, versions ...string) { - t.Helper() - - pkg := &database.Package{PURL: "pkg:deb/nmap", Ecosystem: "deb", Name: "nmap"} - if err := db.UpsertPackage(pkg); err != nil { - t.Fatalf("failed to upsert package: %v", err) - } - for _, v := range versions { - versionPURL := purl.MakePURLString("deb", "nmap", v) - if err := db.UpsertVersion(&database.Version{ - PURL: versionPURL, PackagePURL: pkg.PURL, - }); err != nil { - t.Fatalf("failed to upsert version %q: %v", v, err) - } - if err := db.UpsertArtifact(&database.Artifact{ - VersionPURL: versionPURL, - Filename: "nmap.deb", - UpstreamURL: "http://archive.ubuntu.com/ubuntu/pool/universe/n/nmap/nmap.deb", - StoragePath: sql.NullString{String: "/cache/nmap.deb", Valid: true}, - FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, - }); err != nil { - t.Fatalf("failed to upsert artifact for %q: %v", v, err) - } - } -} - -// checkVersionAndBrowsePages follows a version link from the package page and -// then the browse link from the version page, checking that both resolve to the -// stored version and display it decoded. -func (ts *testServer) checkVersionAndBrowsePages(t *testing.T, versionPath, version, escaped string) { - t.Helper() - - versionPage := ts.getOK(t, versionPath) - wantPURL := "pkg:deb/nmap@" + version - if !strings.Contains(html.UnescapeString(versionPage), wantPURL) { - t.Errorf("version page does not show %q", wantPURL) - } - - browsePath := versionPath + "/browse" - if !containsValue(attrValues(versionPage, "href"), browsePath) { - t.Fatalf("version page has no browse link to %q; hrefs: %v", - browsePath, attrValues(versionPage, "href")) - } - - browsePage := ts.getOK(t, browsePath) - if !strings.Contains(html.UnescapeString(browsePage), "nmap@"+version) { - t.Errorf("browse page does not show the decoded version %q", version) - } - // The browse API is called with the escaped version, not with the text shown - // in the heading. - if got := jsConstant(t, browsePage, "versionPath"); got != escaped { - t.Errorf("browse page passes %q to the browse API, want %q", got, escaped) - } -} - -// checkComparePage builds the compare URL the way the package page's script -// does, from the values its checkboxes carry, and checks the page it reaches. -func (ts *testServer) checkComparePage(t *testing.T, packagePage, version, escaped, otherVersion string) { - t.Helper() - - selectable := attrValues(packagePage, "data-version-path") - if !containsValue(selectable, escaped) { - t.Fatalf("package page compare data holds %v, want %q", selectable, escaped) - } - - comparePage := ts.getOK(t, "/ui/package/deb/nmap/compare/"+escaped+"..."+otherVersion) - decoded := html.UnescapeString(comparePage) - for _, want := range []string{version, otherVersion} { - if !strings.Contains(decoded, want) { - t.Errorf("compare page does not show version %q", want) - } - } - if got := jsConstant(t, comparePage, "fromVersionPath"); got != escaped { - t.Errorf("compare page passes %q to the compare API, want %q", got, escaped) - } -} - -// getOK performs a GET against the server and fails the test unless it returns -// 200, returning the response body. -func (ts *testServer) getOK(t *testing.T, path string) string { - t.Helper() - - req := httptest.NewRequest("GET", path, nil) - w := httptest.NewRecorder() - ts.handler.ServeHTTP(w, req) - if w.Code != http.StatusOK { - t.Fatalf("GET %s: expected status 200, got %d", path, w.Code) - } - - return w.Body.String() -} - -// attrValues returns the value of every occurrence of an HTML attribute in a -// rendered page, with HTML entities resolved so that values can be compared -// against the raw strings they were built from. -func attrValues(body, attr string) []string { - re := regexp.MustCompile(regexp.QuoteMeta(attr) + `="([^"]*)"`) - - var values []string - for _, match := range re.FindAllStringSubmatch(body, -1) { - values = append(values, html.UnescapeString(match[1])) - } - - return values -} - -// jsConstant returns the value of a single-quoted JavaScript string constant in -// a rendered page. html/template escapes characters that are significant in -// JavaScript, rendering "+" as "\\u002b" for instance, so the escapes are -// resolved to recover the value the page actually uses. -func jsConstant(t *testing.T, body, name string) string { - t.Helper() - - re := regexp.MustCompile(`const ` + regexp.QuoteMeta(name) + ` = '([^']*)'`) - match := re.FindStringSubmatch(body) - if match == nil { - t.Fatalf("page does not declare the constant %q", name) - } - - unescaped, err := strconv.Unquote(`"` + match[1] + `"`) - if err != nil { - t.Fatalf("cannot unescape %q: %v", match[1], err) - } - - return unescaped -} - -func containsValue(values []string, want string) bool { - for _, v := range values { - if v == want { - return true - } - } - - return false -} - func TestPackageShowPage_WithLicense(t *testing.T) { ts := newTestServer(t) defer ts.close() @@ -1280,7 +679,7 @@ func TestPackageShowPage_WithLicense(t *testing.T) { t.Fatalf("failed to upsert version: %v", err) } - req := httptest.NewRequest("GET", "/ui/package/npm/show-test-lic", nil) + req := httptest.NewRequest("GET", "/package/npm/show-test-lic", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -1322,8 +721,8 @@ func TestComposerNamespacedPackageRoutes(t *testing.T) { url string want string }{ - {"package show", "/ui/package/composer/monolog/monolog", "monolog/monolog"}, - {"version show", "/ui/package/composer/symfony/console/6.0.0", "symfony/console"}, + {"package show", "/package/composer/monolog/monolog", "monolog/monolog"}, + {"version show", "/package/composer/symfony/console/6.0.0", "symfony/console"}, } for _, tt := range tests { @@ -1380,11 +779,11 @@ func TestNamespacedPackageRoutes(t *testing.T) { url string want int }{ - {"npm scoped package show", "/ui/package/npm/@babel/core", http.StatusOK}, - {"golang module show", "/ui/package/golang/github.com/stretchr/testify", http.StatusOK}, - {"oci image show", "/ui/package/oci/library/nginx", http.StatusOK}, - {"conda package show", "/ui/package/conda/conda-forge/numpy", http.StatusOK}, - {"conan package show", "/ui/package/conan/zlib/1.2.13@demo/stable", http.StatusOK}, + {"npm scoped package show", "/package/npm/@babel/core", http.StatusOK}, + {"golang module show", "/package/golang/github.com/stretchr/testify", http.StatusOK}, + {"oci image show", "/package/oci/library/nginx", http.StatusOK}, + {"conda package show", "/package/conda/conda-forge/numpy", http.StatusOK}, + {"conan package show", "/package/conan/zlib/1.2.13@demo/stable", http.StatusOK}, } for _, tt := range tests { @@ -1407,7 +806,7 @@ func TestSearchPage_WithSeededResults(t *testing.T) { seedTestPackage(t, ts.db, "searchable-pkg") - req := httptest.NewRequest("GET", "/ui/search?q=searchable", nil) + req := httptest.NewRequest("GET", "/search?q=searchable", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -1455,7 +854,7 @@ func TestSearchPage_PaginationMultiPage(t *testing.T) { } // First page - req := httptest.NewRequest("GET", "/ui/search?q=page-test", nil) + req := httptest.NewRequest("GET", "/search?q=page-test", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -1469,7 +868,7 @@ func TestSearchPage_PaginationMultiPage(t *testing.T) { } // Second page - req = httptest.NewRequest("GET", "/ui/search?q=page-test&page=2", nil) + req = httptest.NewRequest("GET", "/search?q=page-test&page=2", nil) w = httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -1535,7 +934,7 @@ func TestSearchPage_EcosystemFilterWithSeededData(t *testing.T) { } // Search with ecosystem filter for npm only - req := httptest.NewRequest("GET", "/ui/search?q=eco-filter&ecosystem=npm", nil) + req := httptest.NewRequest("GET", "/search?q=eco-filter&ecosystem=npm", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -1558,7 +957,7 @@ func TestHandlePackagesListPage(t *testing.T) { seedTestPackage(t, ts.db, "list-test") - req := httptest.NewRequest("GET", "/ui/packages", nil) + req := httptest.NewRequest("GET", "/packages", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -1586,14 +985,10 @@ func TestNewServer_StorageConnectivityCheck(t *testing.T) { logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - buildInfo := BuildInfo{Version: "test-version", Commit: "test-commit"} - srv, err := New(cfg, logger, buildInfo) + srv, err := New(cfg, logger) if err != nil { t.Fatalf("New() failed: %v", err) } - if srv.buildInfo != buildInfo { - t.Errorf("build info = %#v, want %#v", srv.buildInfo, buildInfo) - } // On Windows, OpenBucket normalises to file:///C:/path; on Unix the // absolute path already starts with /, so file:// + /path == file:///path. @@ -1607,27 +1002,6 @@ func TestNewServer_StorageConnectivityCheck(t *testing.T) { _ = srv.db.Close() } -func TestNewServer_InvalidAccessLogFailsBeforeDatabaseInit(t *testing.T) { - tempDir := t.TempDir() - dbPath := filepath.Join(tempDir, "test.db") - cfg := &config.Config{ - Storage: config.StorageConfig{URL: "file://" + filepath.Join(tempDir, "artifacts")}, - Database: config.DatabaseConfig{Path: dbPath}, - AccessLog: config.AccessLogConfig{Path: filepath.Join(tempDir, "missing", "access.jsonl")}, - } - - logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - if _, err := New(cfg, logger, BuildInfo{}); err == nil { - t.Fatal("New() succeeded with invalid access log path") - } else if !strings.Contains(err.Error(), "initializing access log") { - t.Fatalf("New() error = %v, want access log initialization error", err) - } - - if _, err := os.Stat(dbPath); !os.IsNotExist(err) { - t.Errorf("database initialized before access log validation: %v", err) - } -} - func TestStatsEndpoint_StorageURL(t *testing.T) { ts := newTestServer(t) defer ts.close() diff --git a/internal/server/static/vendor/tailwind.js b/internal/server/static/tailwind.js similarity index 100% rename from internal/server/static/vendor/tailwind.js rename to internal/server/static/tailwind.js diff --git a/internal/server/static/vendor/lucide.min.js b/internal/server/static/vendor/lucide.min.js deleted file mode 100644 index 956ea96..0000000 --- a/internal/server/static/vendor/lucide.min.js +++ /dev/null @@ -1,12 +0,0 @@ -/** - * @license lucide v0.545.0 - ISC - * - * This source code is licensed under the ISC license. - * See the LICENSE file in the root directory of this source tree. - */ - -(function(a,n){typeof exports=="object"&&typeof module<"u"?n(exports):typeof define=="function"&&define.amd?define(["exports"],n):(a=typeof globalThis<"u"?globalThis:a||self,n(a.lucide={}))})(this,(function(a){"use strict";const n={xmlns:"http://www.w3.org/2000/svg",width:24,height:24,viewBox:"0 0 24 24",fill:"none",stroke:"currentColor","stroke-width":2,"stroke-linecap":"round","stroke-linejoin":"round"},la=([t,h,d])=>{const c=document.createElementNS("http://www.w3.org/2000/svg",t);return Object.keys(h).forEach(M=>{c.setAttribute(M,String(h[M]))}),d?.length&&d.forEach(M=>{const i=la(M);c.appendChild(i)}),c},ea=(t,h={})=>{const d={...n,...h};return la(["svg",d,t])},Ru=t=>Array.from(t.attributes).reduce((h,d)=>(h[d.name]=d.value,h),{}),Tu=t=>typeof t=="string"?t:!t||!t.class?"":t.class&&typeof t.class=="string"?t.class.split(" "):t.class&&Array.isArray(t.class)?t.class:"",qu=t=>t.flatMap(Tu).map(h=>h.trim()).filter(Boolean).filter((h,d,c)=>c.indexOf(h)===d).join(" "),Uu=t=>t.replace(/(\w)(\w*)(_|-|\s*)/g,(h,d,c)=>d.toUpperCase()+c.toLowerCase()),ra=(t,{nameAttr:h,icons:d,attrs:c})=>{const M=t.getAttribute(h);if(M==null)return;const i=Uu(M),na=d[i];if(!na)return console.warn(`${t.outerHTML} icon name was not found in the provided icons object.`);const Fu=Ru(t),zu={...n,"data-lucide":M,...c,...Fu},bu=qu(["lucide",`lucide-${M}`,Fu,c]);bu&&Object.assign(zu,{class:bu});const Zu=ea(na,zu);return t.parentNode?.replaceChild(Zu,t)},oa=[["path",{d:"m14 12 4 4 4-4"}],["path",{d:"M18 16V7"}],["path",{d:"m2 16 4.039-9.69a.5.5 0 0 1 .923 0L11 16"}],["path",{d:"M3.304 13h6.392"}]],va=[["path",{d:"m14 11 4-4 4 4"}],["path",{d:"M18 16V7"}],["path",{d:"m2 16 4.039-9.69a.5.5 0 0 1 .923 0L11 16"}],["path",{d:"M3.304 13h6.392"}]],$a=[["path",{d:"m15 16 2.536-7.328a1.02 1.02 1 0 1 1.928 0L22 16"}],["path",{d:"M15.697 14h5.606"}],["path",{d:"m2 16 4.039-9.69a.5.5 0 0 1 .923 0L11 16"}],["path",{d:"M3.304 13h6.392"}]],ma=[["circle",{cx:"16",cy:"4",r:"1"}],["path",{d:"m18 19 1-7-6 1"}],["path",{d:"m5 8 3-3 5.5 3-2.36 3.5"}],["path",{d:"M4.24 14.5a5 5 0 0 0 6.88 6"}],["path",{d:"M13.76 17.5a5 5 0 0 0-6.88-6"}]],ya=[["path",{d:"M22 12h-2.48a2 2 0 0 0-1.93 1.46l-2.35 8.36a.25.25 0 0 1-.48 0L9.24 2.18a.25.25 0 0 0-.48 0l-2.35 8.36A2 2 0 0 1 4.49 12H2"}]],sa=[["path",{d:"M18 17.5a2.5 2.5 0 1 1-4 2.03V12"}],["path",{d:"M6 12H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v5a2 2 0 0 1-2 2h-2"}],["path",{d:"M6 8h12"}],["path",{d:"M6.6 15.572A2 2 0 1 0 10 17v-5"}]],ga=[["path",{d:"M5 17H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v10a2 2 0 0 1-2 2h-1"}],["path",{d:"m12 15 5 6H7Z"}]],y=[["circle",{cx:"12",cy:"13",r:"8"}],["path",{d:"M5 3 2 6"}],["path",{d:"m22 6-3-3"}],["path",{d:"M6.38 18.7 4 21"}],["path",{d:"M17.64 18.67 20 21"}],["path",{d:"m9 13 2 2 4-4"}]],s=[["circle",{cx:"12",cy:"13",r:"8"}],["path",{d:"M5 3 2 6"}],["path",{d:"m22 6-3-3"}],["path",{d:"M6.38 18.7 4 21"}],["path",{d:"M17.64 18.67 20 21"}],["path",{d:"M9 13h6"}]],ua=[["path",{d:"M6.87 6.87a8 8 0 1 0 11.26 11.26"}],["path",{d:"M19.9 14.25a8 8 0 0 0-9.15-9.15"}],["path",{d:"m22 6-3-3"}],["path",{d:"M6.26 18.67 4 21"}],["path",{d:"m2 2 20 20"}],["path",{d:"M4 4 2 6"}]],g=[["circle",{cx:"12",cy:"13",r:"8"}],["path",{d:"M5 3 2 6"}],["path",{d:"m22 6-3-3"}],["path",{d:"M6.38 18.7 4 21"}],["path",{d:"M17.64 18.67 20 21"}],["path",{d:"M12 10v6"}],["path",{d:"M9 13h6"}]],Ca=[["circle",{cx:"12",cy:"13",r:"8"}],["path",{d:"M12 9v4l2 2"}],["path",{d:"M5 3 2 6"}],["path",{d:"m22 6-3-3"}],["path",{d:"M6.38 18.7 4 21"}],["path",{d:"M17.64 18.67 20 21"}]],Ha=[["path",{d:"M11 21c0-2.5 2-2.5 2-5"}],["path",{d:"M16 21c0-2.5 2-2.5 2-5"}],["path",{d:"m19 8-.8 3a1.25 1.25 0 0 1-1.2 1H7a1.25 1.25 0 0 1-1.2-1L5 8"}],["path",{d:"M21 3a1 1 0 0 1 1 1v2a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2V4a1 1 0 0 1 1-1z"}],["path",{d:"M6 21c0-2.5 2-2.5 2-5"}]],Aa=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["polyline",{points:"11 3 11 11 14 8 17 11 17 3"}]],wa=[["path",{d:"M2 12h20"}],["path",{d:"M10 16v4a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2v-4"}],["path",{d:"M10 8V4a2 2 0 0 0-2-2H6a2 2 0 0 0-2 2v4"}],["path",{d:"M20 16v1a2 2 0 0 1-2 2h-2a2 2 0 0 1-2-2v-1"}],["path",{d:"M14 8V7c0-1.1.9-2 2-2h2a2 2 0 0 1 2 2v1"}]],Va=[["path",{d:"M12 2v20"}],["path",{d:"M8 10H4a2 2 0 0 1-2-2V6c0-1.1.9-2 2-2h4"}],["path",{d:"M16 10h4a2 2 0 0 0 2-2V6a2 2 0 0 0-2-2h-4"}],["path",{d:"M8 20H7a2 2 0 0 1-2-2v-2c0-1.1.9-2 2-2h1"}],["path",{d:"M16 14h1a2 2 0 0 1 2 2v2a2 2 0 0 1-2 2h-1"}]],Sa=[["rect",{width:"6",height:"16",x:"4",y:"2",rx:"2"}],["rect",{width:"6",height:"9",x:"14",y:"9",rx:"2"}],["path",{d:"M22 22H2"}]],La=[["rect",{width:"16",height:"6",x:"2",y:"4",rx:"2"}],["rect",{width:"9",height:"6",x:"9",y:"14",rx:"2"}],["path",{d:"M22 22V2"}]],fa=[["rect",{width:"6",height:"14",x:"4",y:"5",rx:"2"}],["rect",{width:"6",height:"10",x:"14",y:"7",rx:"2"}],["path",{d:"M17 22v-5"}],["path",{d:"M17 7V2"}],["path",{d:"M7 22v-3"}],["path",{d:"M7 5V2"}]],ka=[["rect",{width:"6",height:"14",x:"4",y:"5",rx:"2"}],["rect",{width:"6",height:"10",x:"14",y:"7",rx:"2"}],["path",{d:"M10 2v20"}],["path",{d:"M20 2v20"}]],Pa=[["rect",{width:"6",height:"14",x:"4",y:"5",rx:"2"}],["rect",{width:"6",height:"10",x:"14",y:"7",rx:"2"}],["path",{d:"M4 2v20"}],["path",{d:"M14 2v20"}]],Ba=[["rect",{width:"6",height:"14",x:"2",y:"5",rx:"2"}],["rect",{width:"6",height:"10",x:"16",y:"7",rx:"2"}],["path",{d:"M12 2v20"}]],Da=[["rect",{width:"6",height:"14",x:"2",y:"5",rx:"2"}],["rect",{width:"6",height:"10",x:"12",y:"7",rx:"2"}],["path",{d:"M22 2v20"}]],Fa=[["rect",{width:"6",height:"14",x:"6",y:"5",rx:"2"}],["rect",{width:"6",height:"10",x:"16",y:"7",rx:"2"}],["path",{d:"M2 2v20"}]],za=[["rect",{width:"6",height:"10",x:"9",y:"7",rx:"2"}],["path",{d:"M4 22V2"}],["path",{d:"M20 22V2"}]],ba=[["rect",{width:"6",height:"14",x:"3",y:"5",rx:"2"}],["rect",{width:"6",height:"10",x:"15",y:"7",rx:"2"}],["path",{d:"M3 2v20"}],["path",{d:"M21 2v20"}]],Ra=[["rect",{width:"6",height:"16",x:"4",y:"6",rx:"2"}],["rect",{width:"6",height:"9",x:"14",y:"6",rx:"2"}],["path",{d:"M22 2H2"}]],Ta=[["rect",{width:"9",height:"6",x:"6",y:"14",rx:"2"}],["rect",{width:"16",height:"6",x:"6",y:"4",rx:"2"}],["path",{d:"M2 2v20"}]],qa=[["path",{d:"M22 17h-3"}],["path",{d:"M22 7h-5"}],["path",{d:"M5 17H2"}],["path",{d:"M7 7H2"}],["rect",{x:"5",y:"14",width:"14",height:"6",rx:"2"}],["rect",{x:"7",y:"4",width:"10",height:"6",rx:"2"}]],Ua=[["rect",{width:"14",height:"6",x:"5",y:"14",rx:"2"}],["rect",{width:"10",height:"6",x:"7",y:"4",rx:"2"}],["path",{d:"M2 20h20"}],["path",{d:"M2 10h20"}]],Oa=[["rect",{width:"14",height:"6",x:"5",y:"14",rx:"2"}],["rect",{width:"10",height:"6",x:"7",y:"4",rx:"2"}],["path",{d:"M2 14h20"}],["path",{d:"M2 4h20"}]],Za=[["rect",{width:"14",height:"6",x:"5",y:"16",rx:"2"}],["rect",{width:"10",height:"6",x:"7",y:"2",rx:"2"}],["path",{d:"M2 12h20"}]],Ga=[["rect",{width:"14",height:"6",x:"5",y:"12",rx:"2"}],["rect",{width:"10",height:"6",x:"7",y:"2",rx:"2"}],["path",{d:"M2 22h20"}]],Ia=[["rect",{width:"14",height:"6",x:"5",y:"16",rx:"2"}],["rect",{width:"10",height:"6",x:"7",y:"6",rx:"2"}],["path",{d:"M2 2h20"}]],Wa=[["rect",{width:"10",height:"6",x:"7",y:"9",rx:"2"}],["path",{d:"M22 20H2"}],["path",{d:"M22 4H2"}]],Ea=[["rect",{width:"14",height:"6",x:"5",y:"15",rx:"2"}],["rect",{width:"10",height:"6",x:"7",y:"3",rx:"2"}],["path",{d:"M2 21h20"}],["path",{d:"M2 3h20"}]],Xa=[["path",{d:"M17.5 12c0 4.4-3.6 8-8 8A4.5 4.5 0 0 1 5 15.5c0-6 8-4 8-8.5a3 3 0 1 0-6 0c0 3 2.5 8.5 12 13"}],["path",{d:"M16 12h3"}]],ja=[["path",{d:"M10 10H6"}],["path",{d:"M14 18V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v11a1 1 0 0 0 1 1h2"}],["path",{d:"M19 18h2a1 1 0 0 0 1-1v-3.28a1 1 0 0 0-.684-.948l-1.923-.641a1 1 0 0 1-.578-.502l-1.539-3.076A1 1 0 0 0 16.382 8H14"}],["path",{d:"M8 8v4"}],["path",{d:"M9 18h6"}],["circle",{cx:"17",cy:"18",r:"2"}],["circle",{cx:"7",cy:"18",r:"2"}]],Na=[["path",{d:"M10 17c-5-3-7-7-7-9a2 2 0 0 1 4 0c0 2.5-5 2.5-5 6 0 1.7 1.3 3 3 3 2.8 0 5-2.2 5-5"}],["path",{d:"M22 17c-5-3-7-7-7-9a2 2 0 0 1 4 0c0 2.5-5 2.5-5 6 0 1.7 1.3 3 3 3 2.8 0 5-2.2 5-5"}]],Ka=[["path",{d:"M10 2v5.632c0 .424-.272.795-.653.982A6 6 0 0 0 6 14c.006 4 3 7 5 8"}],["path",{d:"M10 5H8a2 2 0 0 0 0 4h.68"}],["path",{d:"M14 2v5.632c0 .424.272.795.652.982A6 6 0 0 1 18 14c0 4-3 7-5 8"}],["path",{d:"M14 5h2a2 2 0 0 1 0 4h-.68"}],["path",{d:"M18 22H6"}],["path",{d:"M9 2h6"}]],Qa=[["path",{d:"M12 22V8"}],["path",{d:"M5 12H2a10 10 0 0 0 20 0h-3"}],["circle",{cx:"12",cy:"5",r:"3"}]],Ja=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M16 16s-1.5-2-4-2-4 2-4 2"}],["path",{d:"M7.5 8 10 9"}],["path",{d:"m14 9 2.5-1"}],["path",{d:"M9 10h.01"}],["path",{d:"M15 10h.01"}]],Ya=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M8 15h8"}],["path",{d:"M8 9h2"}],["path",{d:"M14 9h2"}]],_a=[["path",{d:"M2 12 7 2"}],["path",{d:"m7 12 5-10"}],["path",{d:"m12 12 5-10"}],["path",{d:"m17 12 5-10"}],["path",{d:"M4.5 7h15"}],["path",{d:"M12 16v6"}]],xa=[["path",{d:"M7 10H6a4 4 0 0 1-4-4 1 1 0 0 1 1-1h4"}],["path",{d:"M7 5a1 1 0 0 1 1-1h13a1 1 0 0 1 1 1 7 7 0 0 1-7 7H8a1 1 0 0 1-1-1z"}],["path",{d:"M9 12v5"}],["path",{d:"M15 12v5"}],["path",{d:"M5 20a3 3 0 0 1 3-3h8a3 3 0 0 1 3 3 1 1 0 0 1-1 1H6a1 1 0 0 1-1-1"}]],at=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m14.31 8 5.74 9.94"}],["path",{d:"M9.69 8h11.48"}],["path",{d:"m7.38 12 5.74-9.94"}],["path",{d:"M9.69 16 3.95 6.06"}],["path",{d:"M14.31 16H2.83"}],["path",{d:"m16.62 12-5.74 9.94"}]],tt=[["rect",{width:"20",height:"16",x:"2",y:"4",rx:"2"}],["path",{d:"M6 8h.01"}],["path",{d:"M10 8h.01"}],["path",{d:"M14 8h.01"}]],ht=[["rect",{x:"2",y:"4",width:"20",height:"16",rx:"2"}],["path",{d:"M10 4v4"}],["path",{d:"M2 8h20"}],["path",{d:"M6 4v4"}]],dt=[["path",{d:"M12 6.528V3a1 1 0 0 1 1-1h0"}],["path",{d:"M18.237 21A15 15 0 0 0 22 11a6 6 0 0 0-10-4.472A6 6 0 0 0 2 11a15.1 15.1 0 0 0 3.763 10 3 3 0 0 0 3.648.648 5.5 5.5 0 0 1 5.178 0A3 3 0 0 0 18.237 21"}]],ct=[["rect",{width:"20",height:"5",x:"2",y:"3",rx:"1"}],["path",{d:"M4 8v11a2 2 0 0 0 2 2h2"}],["path",{d:"M20 8v11a2 2 0 0 1-2 2h-2"}],["path",{d:"m9 15 3-3 3 3"}],["path",{d:"M12 12v9"}]],Mt=[["rect",{width:"20",height:"5",x:"2",y:"3",rx:"1"}],["path",{d:"M4 8v11a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V8"}],["path",{d:"m9.5 17 5-5"}],["path",{d:"m9.5 12 5 5"}]],pt=[["rect",{width:"20",height:"5",x:"2",y:"3",rx:"1"}],["path",{d:"M4 8v11a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V8"}],["path",{d:"M10 12h4"}]],it=[["path",{d:"M19 9V6a2 2 0 0 0-2-2H7a2 2 0 0 0-2 2v3"}],["path",{d:"M3 16a2 2 0 0 0 2 2h14a2 2 0 0 0 2-2v-5a2 2 0 0 0-4 0v1.5a.5.5 0 0 1-.5.5h-9a.5.5 0 0 1-.5-.5V11a2 2 0 0 0-4 0z"}],["path",{d:"M5 18v2"}],["path",{d:"M19 18v2"}]],nt=[["path",{d:"M15 11a1 1 0 0 0 1 1h2.939a1 1 0 0 1 .75 1.811l-6.835 6.836a1.207 1.207 0 0 1-1.707 0L4.31 13.81a1 1 0 0 1 .75-1.811H8a1 1 0 0 0 1-1V9a1 1 0 0 1 1-1h4a1 1 0 0 1 1 1z"}],["path",{d:"M9 4h6"}]],lt=[["path",{d:"M15 11a1 1 0 0 0 1 1h2.939a1 1 0 0 1 .75 1.811l-6.835 6.836a1.207 1.207 0 0 1-1.707 0L4.31 13.81a1 1 0 0 1 .75-1.811H8a1 1 0 0 0 1-1V5a1 1 0 0 1 1-1h4a1 1 0 0 1 1 1z"}]],et=[["path",{d:"M13 9a1 1 0 0 1-1-1V5.061a1 1 0 0 0-1.811-.75l-6.835 6.836a1.207 1.207 0 0 0 0 1.707l6.835 6.835a1 1 0 0 0 1.811-.75V16a1 1 0 0 1 1-1h2a1 1 0 0 0 1-1v-4a1 1 0 0 0-1-1z"}],["path",{d:"M20 9v6"}]],rt=[["path",{d:"M13 9a1 1 0 0 1-1-1V5.061a1 1 0 0 0-1.811-.75l-6.835 6.836a1.207 1.207 0 0 0 0 1.707l6.835 6.835a1 1 0 0 0 1.811-.75V16a1 1 0 0 1 1-1h6a1 1 0 0 0 1-1v-4a1 1 0 0 0-1-1z"}]],ot=[["path",{d:"M11 9a1 1 0 0 0 1-1V5.061a1 1 0 0 1 1.811-.75l6.836 6.836a1.207 1.207 0 0 1 0 1.707l-6.836 6.835a1 1 0 0 1-1.811-.75V16a1 1 0 0 0-1-1H9a1 1 0 0 1-1-1v-4a1 1 0 0 1 1-1z"}],["path",{d:"M4 9v6"}]],vt=[["path",{d:"M11 9a1 1 0 0 0 1-1V5.061a1 1 0 0 1 1.811-.75l6.836 6.836a1.207 1.207 0 0 1 0 1.707l-6.836 6.835a1 1 0 0 1-1.811-.75V16a1 1 0 0 0-1-1H5a1 1 0 0 1-1-1v-4a1 1 0 0 1 1-1z"}]],$t=[["path",{d:"M9 13a1 1 0 0 0-1-1H5.061a1 1 0 0 1-.75-1.811l6.836-6.835a1.207 1.207 0 0 1 1.707 0l6.835 6.835a1 1 0 0 1-.75 1.811H16a1 1 0 0 0-1 1v2a1 1 0 0 1-1 1h-4a1 1 0 0 1-1-1z"}],["path",{d:"M9 20h6"}]],mt=[["path",{d:"m3 16 4 4 4-4"}],["path",{d:"M7 20V4"}],["rect",{x:"15",y:"4",width:"4",height:"6",ry:"2"}],["path",{d:"M17 20v-6h-2"}],["path",{d:"M15 20h4"}]],yt=[["path",{d:"m3 16 4 4 4-4"}],["path",{d:"M7 20V4"}],["path",{d:"M17 10V4h-2"}],["path",{d:"M15 10h4"}],["rect",{x:"15",y:"14",width:"4",height:"6",ry:"2"}]],st=[["path",{d:"M9 13a1 1 0 0 0-1-1H5.061a1 1 0 0 1-.75-1.811l6.836-6.835a1.207 1.207 0 0 1 1.707 0l6.835 6.835a1 1 0 0 1-.75 1.811H16a1 1 0 0 0-1 1v6a1 1 0 0 1-1 1h-4a1 1 0 0 1-1-1z"}]],u=[["path",{d:"m3 16 4 4 4-4"}],["path",{d:"M7 20V4"}],["path",{d:"M20 8h-5"}],["path",{d:"M15 10V6.5a2.5 2.5 0 0 1 5 0V10"}],["path",{d:"M15 14h5l-5 6h5"}]],gt=[["path",{d:"M19 3H5"}],["path",{d:"M12 21V7"}],["path",{d:"m6 15 6 6 6-6"}]],ut=[["path",{d:"m3 16 4 4 4-4"}],["path",{d:"M7 20V4"}],["path",{d:"M11 4h4"}],["path",{d:"M11 8h7"}],["path",{d:"M11 12h10"}]],Ct=[["path",{d:"M17 7 7 17"}],["path",{d:"M17 17H7V7"}]],Ht=[["path",{d:"M12 2v14"}],["path",{d:"m19 9-7 7-7-7"}],["circle",{cx:"12",cy:"21",r:"1"}]],At=[["path",{d:"m7 7 10 10"}],["path",{d:"M17 7v10H7"}]],wt=[["path",{d:"M12 17V3"}],["path",{d:"m6 11 6 6 6-6"}],["path",{d:"M19 21H5"}]],Vt=[["path",{d:"m3 16 4 4 4-4"}],["path",{d:"M7 20V4"}],["path",{d:"m21 8-4-4-4 4"}],["path",{d:"M17 4v16"}]],C=[["path",{d:"m3 16 4 4 4-4"}],["path",{d:"M7 20V4"}],["path",{d:"M11 4h10"}],["path",{d:"M11 8h7"}],["path",{d:"M11 12h4"}]],H=[["path",{d:"m3 16 4 4 4-4"}],["path",{d:"M7 4v16"}],["path",{d:"M15 4h5l-5 6h5"}],["path",{d:"M15 20v-3.5a2.5 2.5 0 0 1 5 0V20"}],["path",{d:"M20 18h-5"}]],St=[["path",{d:"M12 5v14"}],["path",{d:"m19 12-7 7-7-7"}]],Lt=[["path",{d:"m9 6-6 6 6 6"}],["path",{d:"M3 12h14"}],["path",{d:"M21 19V5"}]],ft=[["path",{d:"M8 3 4 7l4 4"}],["path",{d:"M4 7h16"}],["path",{d:"m16 21 4-4-4-4"}],["path",{d:"M20 17H4"}]],kt=[["path",{d:"M3 19V5"}],["path",{d:"m13 6-6 6 6 6"}],["path",{d:"M7 12h14"}]],Pt=[["path",{d:"m12 19-7-7 7-7"}],["path",{d:"M19 12H5"}]],Bt=[["path",{d:"M3 5v14"}],["path",{d:"M21 12H7"}],["path",{d:"m15 18 6-6-6-6"}]],Dt=[["path",{d:"M17 12H3"}],["path",{d:"m11 18 6-6-6-6"}],["path",{d:"M21 5v14"}]],Ft=[["path",{d:"m16 3 4 4-4 4"}],["path",{d:"M20 7H4"}],["path",{d:"m8 21-4-4 4-4"}],["path",{d:"M4 17h16"}]],zt=[["path",{d:"M5 12h14"}],["path",{d:"m12 5 7 7-7 7"}]],bt=[["path",{d:"m3 8 4-4 4 4"}],["path",{d:"M7 4v16"}],["rect",{x:"15",y:"4",width:"4",height:"6",ry:"2"}],["path",{d:"M17 20v-6h-2"}],["path",{d:"M15 20h4"}]],Rt=[["path",{d:"m3 8 4-4 4 4"}],["path",{d:"M7 4v16"}],["path",{d:"M17 10V4h-2"}],["path",{d:"M15 10h4"}],["rect",{x:"15",y:"14",width:"4",height:"6",ry:"2"}]],A=[["path",{d:"m3 8 4-4 4 4"}],["path",{d:"M7 4v16"}],["path",{d:"M20 8h-5"}],["path",{d:"M15 10V6.5a2.5 2.5 0 0 1 5 0V10"}],["path",{d:"M15 14h5l-5 6h5"}]],Tt=[["path",{d:"m21 16-4 4-4-4"}],["path",{d:"M17 20V4"}],["path",{d:"m3 8 4-4 4 4"}],["path",{d:"M7 4v16"}]],qt=[["path",{d:"m18 9-6-6-6 6"}],["path",{d:"M12 3v14"}],["path",{d:"M5 21h14"}]],Ut=[["path",{d:"m5 9 7-7 7 7"}],["path",{d:"M12 16V2"}],["circle",{cx:"12",cy:"21",r:"1"}]],Ot=[["path",{d:"M7 17V7h10"}],["path",{d:"M17 17 7 7"}]],w=[["path",{d:"m3 8 4-4 4 4"}],["path",{d:"M7 4v16"}],["path",{d:"M11 12h4"}],["path",{d:"M11 16h7"}],["path",{d:"M11 20h10"}]],Zt=[["path",{d:"M7 7h10v10"}],["path",{d:"M7 17 17 7"}]],Gt=[["path",{d:"m3 8 4-4 4 4"}],["path",{d:"M7 4v16"}],["path",{d:"M11 12h10"}],["path",{d:"M11 16h7"}],["path",{d:"M11 20h4"}]],V=[["path",{d:"m3 8 4-4 4 4"}],["path",{d:"M7 4v16"}],["path",{d:"M15 4h5l-5 6h5"}],["path",{d:"M15 20v-3.5a2.5 2.5 0 0 1 5 0V20"}],["path",{d:"M20 18h-5"}]],It=[["path",{d:"M5 3h14"}],["path",{d:"m18 13-6-6-6 6"}],["path",{d:"M12 7v14"}]],Wt=[["path",{d:"m5 12 7-7 7 7"}],["path",{d:"M12 19V5"}]],Et=[["path",{d:"m4 6 3-3 3 3"}],["path",{d:"M7 17V3"}],["path",{d:"m14 6 3-3 3 3"}],["path",{d:"M17 17V3"}],["path",{d:"M4 21h16"}]],Xt=[["path",{d:"M12 6v12"}],["path",{d:"M17.196 9 6.804 15"}],["path",{d:"m6.804 9 10.392 6"}]],jt=[["circle",{cx:"12",cy:"12",r:"4"}],["path",{d:"M16 8v5a3 3 0 0 0 6 0v-1a10 10 0 1 0-4 8"}]],Nt=[["path",{d:"M2 10v3"}],["path",{d:"M6 6v11"}],["path",{d:"M10 3v18"}],["path",{d:"M14 8v7"}],["path",{d:"M18 5v13"}],["path",{d:"M22 10v3"}]],Kt=[["path",{d:"M2 13a2 2 0 0 0 2-2V7a2 2 0 0 1 4 0v13a2 2 0 0 0 4 0V4a2 2 0 0 1 4 0v13a2 2 0 0 0 4 0v-4a2 2 0 0 1 2-2"}]],Qt=[["circle",{cx:"12",cy:"12",r:"1"}],["path",{d:"M20.2 20.2c2.04-2.03.02-7.36-4.5-11.9-4.54-4.52-9.87-6.54-11.9-4.5-2.04 2.03-.02 7.36 4.5 11.9 4.54 4.52 9.87 6.54 11.9 4.5Z"}],["path",{d:"M15.7 15.7c4.52-4.54 6.54-9.87 4.5-11.9-2.03-2.04-7.36-.02-11.9 4.5-4.52 4.54-6.54 9.87-4.5 11.9 2.03 2.04 7.36.02 11.9-4.5Z"}]],Jt=[["path",{d:"m15.477 12.89 1.515 8.526a.5.5 0 0 1-.81.47l-3.58-2.687a1 1 0 0 0-1.197 0l-3.586 2.686a.5.5 0 0 1-.81-.469l1.514-8.526"}],["circle",{cx:"12",cy:"8",r:"6"}]],Yt=[["path",{d:"m14 12-8.381 8.38a1 1 0 0 1-3.001-3L11 9"}],["path",{d:"M15 15.5a.5.5 0 0 0 .5.5A6.5 6.5 0 0 0 22 9.5a.5.5 0 0 0-.5-.5h-1.672a2 2 0 0 1-1.414-.586l-5.062-5.062a1.205 1.205 0 0 0-1.704 0L9.352 5.648a1.205 1.205 0 0 0 0 1.704l5.062 5.062A2 2 0 0 1 15 13.828z"}]],S=[["path",{d:"M13.5 10.5 15 9"}],["path",{d:"M4 4v15a1 1 0 0 0 1 1h15"}],["path",{d:"M4.293 19.707 6 18"}],["path",{d:"m9 15 1.5-1.5"}]],_t=[["path",{d:"M10 16c.5.3 1.2.5 2 .5s1.5-.2 2-.5"}],["path",{d:"M15 12h.01"}],["path",{d:"M19.38 6.813A9 9 0 0 1 20.8 10.2a2 2 0 0 1 0 3.6 9 9 0 0 1-17.6 0 2 2 0 0 1 0-3.6A9 9 0 0 1 12 3c2 0 3.5 1.1 3.5 2.5s-.9 2.5-2 2.5c-.8 0-1.5-.4-1.5-1"}],["path",{d:"M9 12h.01"}]],xt=[["path",{d:"M4 10a4 4 0 0 1 4-4h8a4 4 0 0 1 4 4v10a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2z"}],["path",{d:"M8 10h8"}],["path",{d:"M8 18h8"}],["path",{d:"M8 22v-6a2 2 0 0 1 2-2h4a2 2 0 0 1 2 2v6"}],["path",{d:"M9 6V4a2 2 0 0 1 2-2h2a2 2 0 0 1 2 2v2"}]],ah=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["line",{x1:"12",x2:"12",y1:"8",y2:"12"}],["line",{x1:"12",x2:"12.01",y1:"16",y2:"16"}]],th=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["path",{d:"M12 7v10"}],["path",{d:"M15.4 10a4 4 0 1 0 0 4"}]],L=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["path",{d:"m9 12 2 2 4-4"}]],hh=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["path",{d:"M16 8h-6a2 2 0 1 0 0 4h4a2 2 0 1 1 0 4H8"}],["path",{d:"M12 18V6"}]],dh=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["path",{d:"M7 12h5"}],["path",{d:"M15 9.4a4 4 0 1 0 0 5.2"}]],ch=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["path",{d:"M8 8h8"}],["path",{d:"M8 12h8"}],["path",{d:"m13 17-5-1h1a4 4 0 0 0 0-8"}]],Mh=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["line",{x1:"12",x2:"12",y1:"16",y2:"12"}],["line",{x1:"12",x2:"12.01",y1:"8",y2:"8"}]],ph=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["path",{d:"m9 8 3 3v7"}],["path",{d:"m12 11 3-3"}],["path",{d:"M9 12h6"}],["path",{d:"M9 16h6"}]],ih=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["line",{x1:"8",x2:"16",y1:"12",y2:"12"}]],nh=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["path",{d:"m15 9-6 6"}],["path",{d:"M9 9h.01"}],["path",{d:"M15 15h.01"}]],lh=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["line",{x1:"12",x2:"12",y1:"8",y2:"16"}],["line",{x1:"8",x2:"16",y1:"12",y2:"12"}]],eh=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["path",{d:"M8 12h4"}],["path",{d:"M10 16V9.5a2.5 2.5 0 0 1 5 0"}],["path",{d:"M8 16h7"}]],f=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["path",{d:"M9.09 9a3 3 0 0 1 5.83 1c0 2-3 3-3 3"}],["line",{x1:"12",x2:"12.01",y1:"17",y2:"17"}]],rh=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["path",{d:"M9 16h5"}],["path",{d:"M9 12h5a2 2 0 1 0 0-4h-3v9"}]],oh=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["path",{d:"M11 17V8h4"}],["path",{d:"M11 12h3"}],["path",{d:"M9 16h4"}]],vh=[["path",{d:"M11 7v10a5 5 0 0 0 5-5"}],["path",{d:"m15 8-6 3"}],["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76"}]],$h=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}],["line",{x1:"15",x2:"9",y1:"9",y2:"15"}],["line",{x1:"9",x2:"15",y1:"9",y2:"15"}]],mh=[["path",{d:"M3.85 8.62a4 4 0 0 1 4.78-4.77 4 4 0 0 1 6.74 0 4 4 0 0 1 4.78 4.78 4 4 0 0 1 0 6.74 4 4 0 0 1-4.77 4.78 4 4 0 0 1-6.75 0 4 4 0 0 1-4.78-4.77 4 4 0 0 1 0-6.76Z"}]],yh=[["path",{d:"M22 18H6a2 2 0 0 1-2-2V7a2 2 0 0 0-2-2"}],["path",{d:"M17 14V4a2 2 0 0 0-2-2h-1a2 2 0 0 0-2 2v10"}],["rect",{width:"13",height:"8",x:"8",y:"6",rx:"1"}],["circle",{cx:"18",cy:"20",r:"2"}],["circle",{cx:"9",cy:"20",r:"2"}]],sh=[["path",{d:"M4.929 4.929 19.07 19.071"}],["circle",{cx:"12",cy:"12",r:"10"}]],gh=[["path",{d:"M4 13c3.5-2 8-2 10 2a5.5 5.5 0 0 1 8 5"}],["path",{d:"M5.15 17.89c5.52-1.52 8.65-6.89 7-12C11.55 4 11.5 2 13 2c3.22 0 5 5.5 5 8 0 6.5-4.2 12-10.49 12C5.11 22 2 22 2 20c0-1.5 1.14-1.55 3.15-2.11Z"}]],uh=[["path",{d:"M10 10.01h.01"}],["path",{d:"M10 14.01h.01"}],["path",{d:"M14 10.01h.01"}],["path",{d:"M14 14.01h.01"}],["path",{d:"M18 6v11.5"}],["path",{d:"M6 6v12"}],["rect",{x:"2",y:"6",width:"20",height:"12",rx:"2"}]],Ch=[["path",{d:"M12 18H4a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v5"}],["path",{d:"m16 19 3 3 3-3"}],["path",{d:"M18 12h.01"}],["path",{d:"M19 16v6"}],["path",{d:"M6 12h.01"}],["circle",{cx:"12",cy:"12",r:"2"}]],Hh=[["path",{d:"M12 18H4a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v5"}],["path",{d:"M18 12h.01"}],["path",{d:"M19 22v-6"}],["path",{d:"m22 19-3-3-3 3"}],["path",{d:"M6 12h.01"}],["circle",{cx:"12",cy:"12",r:"2"}]],Ah=[["path",{d:"M13 18H4a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v5"}],["path",{d:"m17 17 5 5"}],["path",{d:"M18 12h.01"}],["path",{d:"m22 17-5 5"}],["path",{d:"M6 12h.01"}],["circle",{cx:"12",cy:"12",r:"2"}]],wh=[["rect",{width:"20",height:"12",x:"2",y:"6",rx:"2"}],["circle",{cx:"12",cy:"12",r:"2"}],["path",{d:"M6 12h.01M18 12h.01"}]],Vh=[["path",{d:"M3 5v14"}],["path",{d:"M8 5v14"}],["path",{d:"M12 5v14"}],["path",{d:"M17 5v14"}],["path",{d:"M21 5v14"}]],Sh=[["path",{d:"M10 3a41 41 0 0 0 0 18"}],["path",{d:"M14 3a41 41 0 0 1 0 18"}],["path",{d:"M17 3a2 2 0 0 1 1.68.92 15.25 15.25 0 0 1 0 16.16A2 2 0 0 1 17 21H7a2 2 0 0 1-1.68-.92 15.25 15.25 0 0 1 0-16.16A2 2 0 0 1 7 3z"}],["path",{d:"M3.84 17h16.32"}],["path",{d:"M3.84 7h16.32"}]],Lh=[["path",{d:"M4 20h16"}],["path",{d:"m6 16 6-12 6 12"}],["path",{d:"M8 12h8"}]],fh=[["path",{d:"M10 4 8 6"}],["path",{d:"M17 19v2"}],["path",{d:"M2 12h20"}],["path",{d:"M7 19v2"}],["path",{d:"M9 5 7.621 3.621A2.121 2.121 0 0 0 4 5v12a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2v-5"}]],kh=[["path",{d:"m11 7-3 5h4l-3 5"}],["path",{d:"M14.856 6H16a2 2 0 0 1 2 2v8a2 2 0 0 1-2 2h-2.935"}],["path",{d:"M22 14v-4"}],["path",{d:"M5.14 18H4a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h2.936"}]],Ph=[["path",{d:"M10 10v4"}],["path",{d:"M14 10v4"}],["path",{d:"M22 14v-4"}],["path",{d:"M6 10v4"}],["rect",{x:"2",y:"6",width:"16",height:"12",rx:"2"}]],Bh=[["path",{d:"M22 14v-4"}],["path",{d:"M6 14v-4"}],["rect",{x:"2",y:"6",width:"16",height:"12",rx:"2"}]],Dh=[["path",{d:"M10 14v-4"}],["path",{d:"M22 14v-4"}],["path",{d:"M6 14v-4"}],["rect",{x:"2",y:"6",width:"16",height:"12",rx:"2"}]],Fh=[["path",{d:"M10 9v6"}],["path",{d:"M12.543 6H16a2 2 0 0 1 2 2v8a2 2 0 0 1-2 2h-3.605"}],["path",{d:"M22 14v-4"}],["path",{d:"M7 12h6"}],["path",{d:"M7.606 18H4a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h3.606"}]],zh=[["path",{d:"M10 17h.01"}],["path",{d:"M10 7v6"}],["path",{d:"M14 6h2a2 2 0 0 1 2 2v8a2 2 0 0 1-2 2h-2"}],["path",{d:"M22 14v-4"}],["path",{d:"M6 18H4a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h2"}]],bh=[["path",{d:"M 22 14 L 22 10"}],["rect",{x:"2",y:"6",width:"16",height:"12",rx:"2"}]],Rh=[["path",{d:"M4.5 3h15"}],["path",{d:"M6 3v16a2 2 0 0 0 2 2h8a2 2 0 0 0 2-2V3"}],["path",{d:"M6 14h12"}]],Th=[["path",{d:"M9 9c-.64.64-1.521.954-2.402 1.165A6 6 0 0 0 8 22a13.96 13.96 0 0 0 9.9-4.1"}],["path",{d:"M10.75 5.093A6 6 0 0 1 22 8c0 2.411-.61 4.68-1.683 6.66"}],["path",{d:"M5.341 10.62a4 4 0 0 0 6.487 1.208M10.62 5.341a4.015 4.015 0 0 1 2.039 2.04"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],qh=[["path",{d:"M10.165 6.598C9.954 7.478 9.64 8.36 9 9c-.64.64-1.521.954-2.402 1.165A6 6 0 0 0 8 22c7.732 0 14-6.268 14-14a6 6 0 0 0-11.835-1.402Z"}],["path",{d:"M5.341 10.62a4 4 0 1 0 5.279-5.28"}]],Uh=[["path",{d:"M2 20v-8a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v8"}],["path",{d:"M4 10V6a2 2 0 0 1 2-2h12a2 2 0 0 1 2 2v4"}],["path",{d:"M12 4v6"}],["path",{d:"M2 18h20"}]],Oh=[["path",{d:"M3 20v-8a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v8"}],["path",{d:"M5 10V6a2 2 0 0 1 2-2h10a2 2 0 0 1 2 2v4"}],["path",{d:"M3 18h18"}]],Zh=[["path",{d:"M2 4v16"}],["path",{d:"M2 8h18a2 2 0 0 1 2 2v10"}],["path",{d:"M2 17h20"}],["path",{d:"M6 8v9"}]],Gh=[["path",{d:"M16.4 13.7A6.5 6.5 0 1 0 6.28 6.6c-1.1 3.13-.78 3.9-3.18 6.08A3 3 0 0 0 5 18c4 0 8.4-1.8 11.4-4.3"}],["path",{d:"m18.5 6 2.19 4.5a6.48 6.48 0 0 1-2.29 7.2C15.4 20.2 11 22 7 22a3 3 0 0 1-2.68-1.66L2.4 16.5"}],["circle",{cx:"12.5",cy:"8.5",r:"2.5"}]],Ih=[["path",{d:"M13 13v5"}],["path",{d:"M17 11.47V8"}],["path",{d:"M17 11h1a3 3 0 0 1 2.745 4.211"}],["path",{d:"m2 2 20 20"}],["path",{d:"M5 8v12a2 2 0 0 0 2 2h8a2 2 0 0 0 2-2v-3"}],["path",{d:"M7.536 7.535C6.766 7.649 6.154 8 5.5 8a2.5 2.5 0 0 1-1.768-4.268"}],["path",{d:"M8.727 3.204C9.306 2.767 9.885 2 11 2c1.56 0 2 1.5 3 1.5s1.72-.5 2.5-.5a1 1 0 1 1 0 5c-.78 0-1.5-.5-2.5-.5a3.149 3.149 0 0 0-.842.12"}],["path",{d:"M9 14.6V18"}]],Wh=[["path",{d:"M17 11h1a3 3 0 0 1 0 6h-1"}],["path",{d:"M9 12v6"}],["path",{d:"M13 12v6"}],["path",{d:"M14 7.5c-1 0-1.44.5-3 .5s-2-.5-3-.5-1.72.5-2.5.5a2.5 2.5 0 0 1 0-5c.78 0 1.57.5 2.5.5S9.44 2 11 2s2 1.5 3 1.5 1.72-.5 2.5-.5a2.5 2.5 0 0 1 0 5c-.78 0-1.5-.5-2.5-.5Z"}],["path",{d:"M5 8v12a2 2 0 0 0 2 2h8a2 2 0 0 0 2-2V8"}]],Eh=[["path",{d:"M10.268 21a2 2 0 0 0 3.464 0"}],["path",{d:"M13.916 2.314A6 6 0 0 0 6 8c0 4.499-1.411 5.956-2.74 7.327A1 1 0 0 0 4 17h16a1 1 0 0 0 .74-1.673 9 9 0 0 1-.585-.665"}],["circle",{cx:"18",cy:"8",r:"3"}]],Xh=[["path",{d:"M18.518 17.347A7 7 0 0 1 14 19"}],["path",{d:"M18.8 4A11 11 0 0 1 20 9"}],["path",{d:"M9 9h.01"}],["circle",{cx:"20",cy:"16",r:"2"}],["circle",{cx:"9",cy:"9",r:"7"}],["rect",{x:"4",y:"16",width:"10",height:"6",rx:"2"}]],jh=[["path",{d:"M10.268 21a2 2 0 0 0 3.464 0"}],["path",{d:"M15 8h6"}],["path",{d:"M16.243 3.757A6 6 0 0 0 6 8c0 4.499-1.411 5.956-2.738 7.326A1 1 0 0 0 4 17h16a1 1 0 0 0 .74-1.673A9.4 9.4 0 0 1 18.667 12"}]],Nh=[["path",{d:"M10.268 21a2 2 0 0 0 3.464 0"}],["path",{d:"M17 17H4a1 1 0 0 1-.74-1.673C4.59 13.956 6 12.499 6 8a6 6 0 0 1 .258-1.742"}],["path",{d:"m2 2 20 20"}],["path",{d:"M8.668 3.01A6 6 0 0 1 18 8c0 2.687.77 4.653 1.707 6.05"}]],Kh=[["path",{d:"M10.268 21a2 2 0 0 0 3.464 0"}],["path",{d:"M15 8h6"}],["path",{d:"M18 5v6"}],["path",{d:"M20.002 14.464a9 9 0 0 0 .738.863A1 1 0 0 1 20 17H4a1 1 0 0 1-.74-1.673C4.59 13.956 6 12.499 6 8a6 6 0 0 1 8.75-5.332"}]],Qh=[["path",{d:"M10.268 21a2 2 0 0 0 3.464 0"}],["path",{d:"M22 8c0-2.3-.8-4.3-2-6"}],["path",{d:"M3.262 15.326A1 1 0 0 0 4 17h16a1 1 0 0 0 .74-1.673C19.41 13.956 18 12.499 18 8A6 6 0 0 0 6 8c0 4.499-1.411 5.956-2.738 7.326"}],["path",{d:"M4 2C2.8 3.7 2 5.7 2 8"}]],Jh=[["path",{d:"M10.268 21a2 2 0 0 0 3.464 0"}],["path",{d:"M3.262 15.326A1 1 0 0 0 4 17h16a1 1 0 0 0 .74-1.673C19.41 13.956 18 12.499 18 8A6 6 0 0 0 6 8c0 4.499-1.411 5.956-2.738 7.326"}]],k=[["rect",{width:"13",height:"7",x:"3",y:"3",rx:"1"}],["path",{d:"m22 15-3-3 3-3"}],["rect",{width:"13",height:"7",x:"3",y:"14",rx:"1"}]],P=[["rect",{width:"13",height:"7",x:"8",y:"3",rx:"1"}],["path",{d:"m2 9 3 3-3 3"}],["rect",{width:"13",height:"7",x:"8",y:"14",rx:"1"}]],Yh=[["rect",{width:"7",height:"13",x:"3",y:"3",rx:"1"}],["path",{d:"m9 22 3-3 3 3"}],["rect",{width:"7",height:"13",x:"14",y:"3",rx:"1"}]],_h=[["rect",{width:"7",height:"13",x:"3",y:"8",rx:"1"}],["path",{d:"m15 2-3 3-3-3"}],["rect",{width:"7",height:"13",x:"14",y:"8",rx:"1"}]],xh=[["path",{d:"M12.409 13.017A5 5 0 0 1 22 15c0 3.866-4 7-9 7-4.077 0-8.153-.82-10.371-2.462-.426-.316-.631-.832-.62-1.362C2.118 12.723 2.627 2 10 2a3 3 0 0 1 3 3 2 2 0 0 1-2 2c-1.105 0-1.64-.444-2-1"}],["path",{d:"M15 14a5 5 0 0 0-7.584 2"}],["path",{d:"M9.964 6.825C8.019 7.977 9.5 13 8 15"}]],a4=[["circle",{cx:"18.5",cy:"17.5",r:"3.5"}],["circle",{cx:"5.5",cy:"17.5",r:"3.5"}],["circle",{cx:"15",cy:"5",r:"1"}],["path",{d:"M12 17.5V14l-3-3 4-3 2 3h2"}]],t4=[["rect",{x:"14",y:"14",width:"4",height:"6",rx:"2"}],["rect",{x:"6",y:"4",width:"4",height:"6",rx:"2"}],["path",{d:"M6 20h4"}],["path",{d:"M14 10h4"}],["path",{d:"M6 14h2v6"}],["path",{d:"M14 4h2v6"}]],h4=[["path",{d:"M10 10h4"}],["path",{d:"M19 7V4a1 1 0 0 0-1-1h-2a1 1 0 0 0-1 1v3"}],["path",{d:"M20 21a2 2 0 0 0 2-2v-3.851c0-1.39-2-2.962-2-4.829V8a1 1 0 0 0-1-1h-4a1 1 0 0 0-1 1v11a2 2 0 0 0 2 2z"}],["path",{d:"M 22 16 L 2 16"}],["path",{d:"M4 21a2 2 0 0 1-2-2v-3.851c0-1.39 2-2.962 2-4.829V8a1 1 0 0 1 1-1h4a1 1 0 0 1 1 1v11a2 2 0 0 1-2 2z"}],["path",{d:"M9 7V4a1 1 0 0 0-1-1H6a1 1 0 0 0-1 1v3"}]],d4=[["circle",{cx:"12",cy:"11.9",r:"2"}],["path",{d:"M6.7 3.4c-.9 2.5 0 5.2 2.2 6.7C6.5 9 3.7 9.6 2 11.6"}],["path",{d:"m8.9 10.1 1.4.8"}],["path",{d:"M17.3 3.4c.9 2.5 0 5.2-2.2 6.7 2.4-1.2 5.2-.6 6.9 1.5"}],["path",{d:"m15.1 10.1-1.4.8"}],["path",{d:"M16.7 20.8c-2.6-.4-4.6-2.6-4.7-5.3-.2 2.6-2.1 4.8-4.7 5.2"}],["path",{d:"M12 13.9v1.6"}],["path",{d:"M13.5 5.4c-1-.2-2-.2-3 0"}],["path",{d:"M17 16.4c.7-.7 1.2-1.6 1.5-2.5"}],["path",{d:"M5.5 13.9c.3.9.8 1.8 1.5 2.5"}]],c4=[["path",{d:"M16 7h.01"}],["path",{d:"M3.4 18H12a8 8 0 0 0 8-8V7a4 4 0 0 0-7.28-2.3L2 20"}],["path",{d:"m20 7 2 .5-2 .5"}],["path",{d:"M10 18v3"}],["path",{d:"M14 17.75V21"}],["path",{d:"M7 18a6 6 0 0 0 3.84-10.61"}]],M4=[["circle",{cx:"9",cy:"9",r:"7"}],["circle",{cx:"15",cy:"15",r:"7"}]],p4=[["path",{d:"M11.767 19.089c4.924.868 6.14-6.025 1.216-6.894m-1.216 6.894L5.86 18.047m5.908 1.042-.347 1.97m1.563-8.864c4.924.869 6.14-6.025 1.215-6.893m-1.215 6.893-3.94-.694m5.155-6.2L8.29 4.26m5.908 1.042.348-1.97M7.48 20.364l3.126-17.727"}]],i4=[["path",{d:"M10 22V7a1 1 0 0 0-1-1H4a2 2 0 0 0-2 2v12a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2v-5a1 1 0 0 0-1-1H2"}],["rect",{x:"14",y:"2",width:"8",height:"8",rx:"1"}]],n4=[["path",{d:"M3 3h18"}],["path",{d:"M20 7H8"}],["path",{d:"M20 11H8"}],["path",{d:"M10 19h10"}],["path",{d:"M8 15h12"}],["path",{d:"M4 3v14"}],["circle",{cx:"4",cy:"19",r:"2"}]],l4=[["path",{d:"m7 7 10 10-5 5V2l5 5L7 17"}],["line",{x1:"18",x2:"21",y1:"12",y2:"12"}],["line",{x1:"3",x2:"6",y1:"12",y2:"12"}]],e4=[["path",{d:"m7 7 10 10-5 5V2l5 5L7 17"}],["path",{d:"M20.83 14.83a4 4 0 0 0 0-5.66"}],["path",{d:"M18 12h.01"}]],r4=[["path",{d:"m7 7 10 10-5 5V2l5 5L7 17"}]],o4=[["path",{d:"m17 17-5 5V12l-5 5"}],["path",{d:"m2 2 20 20"}],["path",{d:"M14.5 9.5 17 7l-5-5v4.5"}]],v4=[["path",{d:"M6 12h9a4 4 0 0 1 0 8H7a1 1 0 0 1-1-1V5a1 1 0 0 1 1-1h7a4 4 0 0 1 0 8"}]],$4=[["path",{d:"M21 16V8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73l7 4a2 2 0 0 0 2 0l7-4A2 2 0 0 0 21 16z"}],["circle",{cx:"12",cy:"12",r:"4"}]],m4=[["circle",{cx:"11",cy:"13",r:"9"}],["path",{d:"M14.35 4.65 16.3 2.7a2.41 2.41 0 0 1 3.4 0l1.6 1.6a2.4 2.4 0 0 1 0 3.4l-1.95 1.95"}],["path",{d:"m22 2-1.5 1.5"}]],y4=[["path",{d:"M17 10c.7-.7 1.69 0 2.5 0a2.5 2.5 0 1 0 0-5 .5.5 0 0 1-.5-.5 2.5 2.5 0 1 0-5 0c0 .81.7 1.8 0 2.5l-7 7c-.7.7-1.69 0-2.5 0a2.5 2.5 0 0 0 0 5c.28 0 .5.22.5.5a2.5 2.5 0 1 0 5 0c0-.81-.7-1.8 0-2.5Z"}]],s4=[["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"m8 13 4-7 4 7"}],["path",{d:"M9.1 11h5.7"}]],g4=[["path",{d:"M12 13h.01"}],["path",{d:"M12 6v3"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}]],u4=[["path",{d:"M12 6v7"}],["path",{d:"M16 8v3"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"M8 8v3"}]],C4=[["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"m9 9.5 2 2 4-4"}]],H4=[["path",{d:"M5 7a2 2 0 0 0-2 2v11"}],["path",{d:"M5.803 18H5a2 2 0 0 0 0 4h9.5a.5.5 0 0 0 .5-.5V21"}],["path",{d:"M9 15V4a2 2 0 0 1 2-2h9.5a.5.5 0 0 1 .5.5v14a.5.5 0 0 1-.5.5H11a2 2 0 0 1 0-4h10"}]],B=[["path",{d:"M12 17h1.5"}],["path",{d:"M12 22h1.5"}],["path",{d:"M12 2h1.5"}],["path",{d:"M17.5 22H19a1 1 0 0 0 1-1"}],["path",{d:"M17.5 2H19a1 1 0 0 1 1 1v1.5"}],["path",{d:"M20 14v3h-2.5"}],["path",{d:"M20 8.5V10"}],["path",{d:"M4 10V8.5"}],["path",{d:"M4 19.5V14"}],["path",{d:"M4 4.5A2.5 2.5 0 0 1 6.5 2H8"}],["path",{d:"M8 22H6.5a1 1 0 0 1 0-5H8"}]],A4=[["path",{d:"M12 13V7"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"m9 10 3 3 3-3"}]],w4=[["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"M8 12v-2a4 4 0 0 1 8 0v2"}],["circle",{cx:"15",cy:"12",r:"1"}],["circle",{cx:"9",cy:"12",r:"1"}]],V4=[["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"M8.62 9.8A2.25 2.25 0 1 1 12 6.836a2.25 2.25 0 1 1 3.38 2.966l-2.626 2.856a.998.998 0 0 1-1.507 0z"}]],S4=[["path",{d:"m20 13.7-2.1-2.1a2 2 0 0 0-2.8 0L9.7 17"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["circle",{cx:"10",cy:"8",r:"2"}]],L4=[["path",{d:"m19 3 1 1"}],["path",{d:"m20 2-4.5 4.5"}],["path",{d:"M20 7.898V21a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2h7.844"}],["circle",{cx:"14",cy:"8",r:"2"}]],f4=[["path",{d:"M18 6V4a2 2 0 1 0-4 0v2"}],["path",{d:"M20 15v6a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H10"}],["rect",{x:"12",y:"6",width:"8",height:"5",rx:"1"}]],k4=[["path",{d:"M10 2v8l3-3 3 3V2"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}]],P4=[["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"M9 10h6"}]],B4=[["path",{d:"M12 21V7"}],["path",{d:"m16 12 2 2 4-4"}],["path",{d:"M22 6V4a1 1 0 0 0-1-1h-5a4 4 0 0 0-4 4 4 4 0 0 0-4-4H3a1 1 0 0 0-1 1v13a1 1 0 0 0 1 1h6a3 3 0 0 1 3 3 3 3 0 0 1 3-3h6a1 1 0 0 0 1-1v-1.3"}]],D4=[["path",{d:"M12 7v14"}],["path",{d:"M16 12h2"}],["path",{d:"M16 8h2"}],["path",{d:"M3 18a1 1 0 0 1-1-1V4a1 1 0 0 1 1-1h5a4 4 0 0 1 4 4 4 4 0 0 1 4-4h5a1 1 0 0 1 1 1v13a1 1 0 0 1-1 1h-6a3 3 0 0 0-3 3 3 3 0 0 0-3-3z"}],["path",{d:"M6 12h2"}],["path",{d:"M6 8h2"}]],F4=[["path",{d:"M12 7v14"}],["path",{d:"M3 18a1 1 0 0 1-1-1V4a1 1 0 0 1 1-1h5a4 4 0 0 1 4 4 4 4 0 0 1 4-4h5a1 1 0 0 1 1 1v13a1 1 0 0 1-1 1h-6a3 3 0 0 0-3 3 3 3 0 0 0-3-3z"}]],z4=[["path",{d:"M12 7v6"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"M9 10h6"}]],b4=[["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"M8 11h8"}],["path",{d:"M8 7h6"}]],R4=[["path",{d:"M12 13V7"}],["path",{d:"M18 2h1a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2"}],["path",{d:"m9 10 3-3 3 3"}],["path",{d:"m9 5 3-3 3 3"}]],T4=[["path",{d:"M10 13h4"}],["path",{d:"M12 6v7"}],["path",{d:"M16 8V6H8v2"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}]],q4=[["path",{d:"M12 13V7"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"m9 10 3-3 3 3"}]],U4=[["path",{d:"M15 13a3 3 0 1 0-6 0"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["circle",{cx:"12",cy:"8",r:"2"}]],O4=[["path",{d:"m14.5 7-5 5"}],["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}],["path",{d:"m9.5 7 5 5"}]],Z4=[["path",{d:"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20"}]],G4=[["path",{d:"m19 21-7-4-7 4V5a2 2 0 0 1 2-2h10a2 2 0 0 1 2 2Z"}],["path",{d:"m9 10 2 2 4-4"}]],I4=[["path",{d:"m19 21-7-4-7 4V5a2 2 0 0 1 2-2h10a2 2 0 0 1 2 2v16z"}],["line",{x1:"15",x2:"9",y1:"10",y2:"10"}]],W4=[["path",{d:"m19 21-7-4-7 4V5a2 2 0 0 1 2-2h10a2 2 0 0 1 2 2v16z"}],["line",{x1:"12",x2:"12",y1:"7",y2:"13"}],["line",{x1:"15",x2:"9",y1:"10",y2:"10"}]],E4=[["path",{d:"m19 21-7-4-7 4V5a2 2 0 0 1 2-2h10a2 2 0 0 1 2 2Z"}],["path",{d:"m14.5 7.5-5 5"}],["path",{d:"m9.5 7.5 5 5"}]],X4=[["path",{d:"m19 21-7-4-7 4V5a2 2 0 0 1 2-2h10a2 2 0 0 1 2 2v16z"}]],j4=[["path",{d:"M4 9V5a2 2 0 0 1 2-2h12a2 2 0 0 1 2 2v4"}],["path",{d:"M8 8v1"}],["path",{d:"M12 8v1"}],["path",{d:"M16 8v1"}],["rect",{width:"20",height:"12",x:"2",y:"9",rx:"2"}],["circle",{cx:"8",cy:"15",r:"2"}],["circle",{cx:"16",cy:"15",r:"2"}]],N4=[["path",{d:"M13.67 8H18a2 2 0 0 1 2 2v4.33"}],["path",{d:"M2 14h2"}],["path",{d:"M20 14h2"}],["path",{d:"M22 22 2 2"}],["path",{d:"M8 8H6a2 2 0 0 0-2 2v8a2 2 0 0 0 2 2h12a2 2 0 0 0 1.414-.586"}],["path",{d:"M9 13v2"}],["path",{d:"M9.67 4H12v2.33"}]],K4=[["path",{d:"M12 6V2H8"}],["path",{d:"M15 11v2"}],["path",{d:"M2 12h2"}],["path",{d:"M20 12h2"}],["path",{d:"M20 16a2 2 0 0 1-2 2H8.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 4 20.286V8a2 2 0 0 1 2-2h12a2 2 0 0 1 2 2z"}],["path",{d:"M9 11v2"}]],Q4=[["path",{d:"M12 8V4H8"}],["rect",{width:"16",height:"12",x:"4",y:"8",rx:"2"}],["path",{d:"M2 14h2"}],["path",{d:"M20 14h2"}],["path",{d:"M15 13v2"}],["path",{d:"M9 13v2"}]],J4=[["path",{d:"M10 3a1 1 0 0 1 1-1h2a1 1 0 0 1 1 1v2a6 6 0 0 0 1.2 3.6l.6.8A6 6 0 0 1 17 13v8a1 1 0 0 1-1 1H8a1 1 0 0 1-1-1v-8a6 6 0 0 1 1.2-3.6l.6-.8A6 6 0 0 0 10 5z"}],["path",{d:"M17 13h-4a1 1 0 0 0-1 1v3a1 1 0 0 0 1 1h4"}]],Y4=[["path",{d:"M17 3h4v4"}],["path",{d:"M18.575 11.082a13 13 0 0 1 1.048 9.027 1.17 1.17 0 0 1-1.914.597L14 17"}],["path",{d:"M7 10 3.29 6.29a1.17 1.17 0 0 1 .6-1.91 13 13 0 0 1 9.03 1.05"}],["path",{d:"M7 14a1.7 1.7 0 0 0-1.207.5l-2.646 2.646A.5.5 0 0 0 3.5 18H5a1 1 0 0 1 1 1v1.5a.5.5 0 0 0 .854.354L9.5 18.207A1.7 1.7 0 0 0 10 17v-2a1 1 0 0 0-1-1z"}],["path",{d:"M9.707 14.293 21 3"}]],_4=[["path",{d:"M21 8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73l7 4a2 2 0 0 0 2 0l7-4A2 2 0 0 0 21 16Z"}],["path",{d:"m3.3 7 8.7 5 8.7-5"}],["path",{d:"M12 22V12"}]],x4=[["path",{d:"M2.97 12.92A2 2 0 0 0 2 14.63v3.24a2 2 0 0 0 .97 1.71l3 1.8a2 2 0 0 0 2.06 0L12 19v-5.5l-5-3-4.03 2.42Z"}],["path",{d:"m7 16.5-4.74-2.85"}],["path",{d:"m7 16.5 5-3"}],["path",{d:"M7 16.5v5.17"}],["path",{d:"M12 13.5V19l3.97 2.38a2 2 0 0 0 2.06 0l3-1.8a2 2 0 0 0 .97-1.71v-3.24a2 2 0 0 0-.97-1.71L17 10.5l-5 3Z"}],["path",{d:"m17 16.5-5-3"}],["path",{d:"m17 16.5 4.74-2.85"}],["path",{d:"M17 16.5v5.17"}],["path",{d:"M7.97 4.42A2 2 0 0 0 7 6.13v4.37l5 3 5-3V6.13a2 2 0 0 0-.97-1.71l-3-1.8a2 2 0 0 0-2.06 0l-3 1.8Z"}],["path",{d:"M12 8 7.26 5.15"}],["path",{d:"m12 8 4.74-2.85"}],["path",{d:"M12 13.5V8"}]],D=[["path",{d:"M8 3H7a2 2 0 0 0-2 2v5a2 2 0 0 1-2 2 2 2 0 0 1 2 2v5c0 1.1.9 2 2 2h1"}],["path",{d:"M16 21h1a2 2 0 0 0 2-2v-5c0-1.1.9-2 2-2a2 2 0 0 1-2-2V5a2 2 0 0 0-2-2h-1"}]],a5=[["path",{d:"M16 3h3a1 1 0 0 1 1 1v16a1 1 0 0 1-1 1h-3"}],["path",{d:"M8 21H5a1 1 0 0 1-1-1V4a1 1 0 0 1 1-1h3"}]],t5=[["path",{d:"M12 5a3 3 0 1 0-5.997.125 4 4 0 0 0-2.526 5.77 4 4 0 0 0 .556 6.588A4 4 0 1 0 12 18Z"}],["path",{d:"M9 13a4.5 4.5 0 0 0 3-4"}],["path",{d:"M6.003 5.125A3 3 0 0 0 6.401 6.5"}],["path",{d:"M3.477 10.896a4 4 0 0 1 .585-.396"}],["path",{d:"M6 18a4 4 0 0 1-1.967-.516"}],["path",{d:"M12 13h4"}],["path",{d:"M12 18h6a2 2 0 0 1 2 2v1"}],["path",{d:"M12 8h8"}],["path",{d:"M16 8V5a2 2 0 0 1 2-2"}],["circle",{cx:"16",cy:"13",r:".5"}],["circle",{cx:"18",cy:"3",r:".5"}],["circle",{cx:"20",cy:"21",r:".5"}],["circle",{cx:"20",cy:"8",r:".5"}]],h5=[["path",{d:"m10.852 14.772-.383.923"}],["path",{d:"m10.852 9.228-.383-.923"}],["path",{d:"m13.148 14.772.382.924"}],["path",{d:"m13.531 8.305-.383.923"}],["path",{d:"m14.772 10.852.923-.383"}],["path",{d:"m14.772 13.148.923.383"}],["path",{d:"M17.598 6.5A3 3 0 1 0 12 5a3 3 0 0 0-5.63-1.446 3 3 0 0 0-.368 1.571 4 4 0 0 0-2.525 5.771"}],["path",{d:"M17.998 5.125a4 4 0 0 1 2.525 5.771"}],["path",{d:"M19.505 10.294a4 4 0 0 1-1.5 7.706"}],["path",{d:"M4.032 17.483A4 4 0 0 0 11.464 20c.18-.311.892-.311 1.072 0a4 4 0 0 0 7.432-2.516"}],["path",{d:"M4.5 10.291A4 4 0 0 0 6 18"}],["path",{d:"M6.002 5.125a3 3 0 0 0 .4 1.375"}],["path",{d:"m9.228 10.852-.923-.383"}],["path",{d:"m9.228 13.148-.923.383"}],["circle",{cx:"12",cy:"12",r:"3"}]],d5=[["path",{d:"M12 18V5"}],["path",{d:"M15 13a4.17 4.17 0 0 1-3-4 4.17 4.17 0 0 1-3 4"}],["path",{d:"M17.598 6.5A3 3 0 1 0 12 5a3 3 0 1 0-5.598 1.5"}],["path",{d:"M17.997 5.125a4 4 0 0 1 2.526 5.77"}],["path",{d:"M18 18a4 4 0 0 0 2-7.464"}],["path",{d:"M19.967 17.483A4 4 0 1 1 12 18a4 4 0 1 1-7.967-.517"}],["path",{d:"M6 18a4 4 0 0 1-2-7.464"}],["path",{d:"M6.003 5.125a4 4 0 0 0-2.526 5.77"}]],c5=[["path",{d:"M16 3v2.107"}],["path",{d:"M17 9c1 3 2.5 3.5 3.5 4.5A5 5 0 0 1 22 17a5 5 0 0 1-10 0c0-.3 0-.6.1-.9a2 2 0 1 0 3.3-2C13 11.5 16 9 17 9"}],["path",{d:"M21 8.274V5a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h3.938"}],["path",{d:"M3 15h5.253"}],["path",{d:"M3 9h8.228"}],["path",{d:"M8 15v6"}],["path",{d:"M8 3v6"}]],M5=[["path",{d:"M12 9v1.258"}],["path",{d:"M16 3v5.46"}],["path",{d:"M21 9.118V5a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h5.75"}],["path",{d:"M22 17.5c0 2.499-1.75 3.749-3.83 4.474a.5.5 0 0 1-.335-.005c-2.085-.72-3.835-1.97-3.835-4.47V14a.5.5 0 0 1 .5-.499c1 0 2.25-.6 3.12-1.36a.6.6 0 0 1 .76-.001c.875.765 2.12 1.36 3.12 1.36a.5.5 0 0 1 .5.5z"}],["path",{d:"M3 15h7"}],["path",{d:"M3 9h12.142"}],["path",{d:"M8 15v6"}],["path",{d:"M8 3v6"}]],p5=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M12 9v6"}],["path",{d:"M16 15v6"}],["path",{d:"M16 3v6"}],["path",{d:"M3 15h18"}],["path",{d:"M3 9h18"}],["path",{d:"M8 15v6"}],["path",{d:"M8 3v6"}]],i5=[["path",{d:"M12 12h.01"}],["path",{d:"M16 6V4a2 2 0 0 0-2-2h-4a2 2 0 0 0-2 2v2"}],["path",{d:"M22 13a18.15 18.15 0 0 1-20 0"}],["rect",{width:"20",height:"14",x:"2",y:"6",rx:"2"}]],n5=[["path",{d:"M10 20v2"}],["path",{d:"M14 20v2"}],["path",{d:"M18 20v2"}],["path",{d:"M21 20H3"}],["path",{d:"M6 20v2"}],["path",{d:"M8 16V4a2 2 0 0 1 2-2h4a2 2 0 0 1 2 2v12"}],["rect",{x:"4",y:"6",width:"16",height:"10",rx:"2"}]],l5=[["path",{d:"M12 11v4"}],["path",{d:"M14 13h-4"}],["path",{d:"M16 6V4a2 2 0 0 0-2-2h-4a2 2 0 0 0-2 2v2"}],["path",{d:"M18 6v14"}],["path",{d:"M6 6v14"}],["rect",{width:"20",height:"14",x:"2",y:"6",rx:"2"}]],e5=[["path",{d:"M16 20V4a2 2 0 0 0-2-2h-4a2 2 0 0 0-2 2v16"}],["rect",{width:"20",height:"14",x:"2",y:"6",rx:"2"}]],r5=[["rect",{x:"8",y:"8",width:"8",height:"8",rx:"2"}],["path",{d:"M4 10a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h4a2 2 0 0 1 2 2"}],["path",{d:"M14 20a2 2 0 0 0 2 2h4a2 2 0 0 0 2-2v-4a2 2 0 0 0-2-2"}]],o5=[["path",{d:"m16 22-1-4"}],["path",{d:"M19 13.99a1 1 0 0 0 1-1V12a2 2 0 0 0-2-2h-3a1 1 0 0 1-1-1V4a2 2 0 0 0-4 0v5a1 1 0 0 1-1 1H6a2 2 0 0 0-2 2v.99a1 1 0 0 0 1 1"}],["path",{d:"M5 14h14l1.973 6.767A1 1 0 0 1 20 22H4a1 1 0 0 1-.973-1.233z"}],["path",{d:"m8 22 1-4"}]],v5=[["path",{d:"m11 10 3 3"}],["path",{d:"M6.5 21A3.5 3.5 0 1 0 3 17.5a2.62 2.62 0 0 1-.708 1.792A1 1 0 0 0 3 21z"}],["path",{d:"M9.969 17.031 21.378 5.624a1 1 0 0 0-3.002-3.002L6.967 14.031"}]],$5=[["path",{d:"M7.2 14.8a2 2 0 0 1 2 2"}],["circle",{cx:"18.5",cy:"8.5",r:"3.5"}],["circle",{cx:"7.5",cy:"16.5",r:"5.5"}],["circle",{cx:"7.5",cy:"4.5",r:"2.5"}]],m5=[["path",{d:"M12 20v-8"}],["path",{d:"M14.12 3.88 16 2"}],["path",{d:"M15 7.13V6a3 3 0 0 0-5.14-2.1L8 2"}],["path",{d:"M18 12.34V11a4 4 0 0 0-4-4h-1.3"}],["path",{d:"m2 2 20 20"}],["path",{d:"M21 5a4 4 0 0 1-3.55 3.97"}],["path",{d:"M22 13h-3.34"}],["path",{d:"M3 21a4 4 0 0 1 3.81-4"}],["path",{d:"M6 13H2"}],["path",{d:"M7.7 7.7A4 4 0 0 0 6 11v3a6 6 0 0 0 11.13 3.13"}]],y5=[["path",{d:"M10 19.655A6 6 0 0 1 6 14v-3a4 4 0 0 1 4-4h4a4 4 0 0 1 4 3.97"}],["path",{d:"M14 15.003a1 1 0 0 1 1.517-.859l4.997 2.997a1 1 0 0 1 0 1.718l-4.997 2.997a1 1 0 0 1-1.517-.86z"}],["path",{d:"M14.12 3.88 16 2"}],["path",{d:"M21 5a4 4 0 0 1-3.55 3.97"}],["path",{d:"M3 21a4 4 0 0 1 3.81-4"}],["path",{d:"M3 5a4 4 0 0 0 3.55 3.97"}],["path",{d:"M6 13H2"}],["path",{d:"m8 2 1.88 1.88"}],["path",{d:"M9 7.13V6a3 3 0 1 1 6 0v1.13"}]],s5=[["path",{d:"M12 20v-9"}],["path",{d:"M14 7a4 4 0 0 1 4 4v3a6 6 0 0 1-12 0v-3a4 4 0 0 1 4-4z"}],["path",{d:"M14.12 3.88 16 2"}],["path",{d:"M21 21a4 4 0 0 0-3.81-4"}],["path",{d:"M21 5a4 4 0 0 1-3.55 3.97"}],["path",{d:"M22 13h-4"}],["path",{d:"M3 21a4 4 0 0 1 3.81-4"}],["path",{d:"M3 5a4 4 0 0 0 3.55 3.97"}],["path",{d:"M6 13H2"}],["path",{d:"m8 2 1.88 1.88"}],["path",{d:"M9 7.13V6a3 3 0 1 1 6 0v1.13"}]],g5=[["path",{d:"M10 12h4"}],["path",{d:"M10 8h4"}],["path",{d:"M14 21v-3a2 2 0 0 0-4 0v3"}],["path",{d:"M6 10H4a2 2 0 0 0-2 2v7a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2V9a2 2 0 0 0-2-2h-2"}],["path",{d:"M6 21V5a2 2 0 0 1 2-2h8a2 2 0 0 1 2 2v16"}]],u5=[["path",{d:"M12 10h.01"}],["path",{d:"M12 14h.01"}],["path",{d:"M12 6h.01"}],["path",{d:"M16 10h.01"}],["path",{d:"M16 14h.01"}],["path",{d:"M16 6h.01"}],["path",{d:"M8 10h.01"}],["path",{d:"M8 14h.01"}],["path",{d:"M8 6h.01"}],["path",{d:"M9 22v-3a1 1 0 0 1 1-1h4a1 1 0 0 1 1 1v3"}],["rect",{x:"4",y:"2",width:"16",height:"20",rx:"2"}]],C5=[["path",{d:"M4 6 2 7"}],["path",{d:"M10 6h4"}],["path",{d:"m22 7-2-1"}],["rect",{width:"16",height:"16",x:"4",y:"3",rx:"2"}],["path",{d:"M4 11h16"}],["path",{d:"M8 15h.01"}],["path",{d:"M16 15h.01"}],["path",{d:"M6 19v2"}],["path",{d:"M18 21v-2"}]],H5=[["path",{d:"M8 6v6"}],["path",{d:"M15 6v6"}],["path",{d:"M2 12h19.6"}],["path",{d:"M18 18h3s.5-1.7.8-2.8c.1-.4.2-.8.2-1.2 0-.4-.1-.8-.2-1.2l-1.4-5C20.1 6.8 19.1 6 18 6H4a2 2 0 0 0-2 2v10h3"}],["circle",{cx:"7",cy:"18",r:"2"}],["path",{d:"M9 18h5"}],["circle",{cx:"16",cy:"18",r:"2"}]],A5=[["path",{d:"M10 3h.01"}],["path",{d:"M14 2h.01"}],["path",{d:"m2 9 20-5"}],["path",{d:"M12 12V6.5"}],["rect",{width:"16",height:"10",x:"4",y:"12",rx:"3"}],["path",{d:"M9 12v5"}],["path",{d:"M15 12v5"}],["path",{d:"M4 17h16"}]],w5=[["path",{d:"M17 19a1 1 0 0 1-1-1v-2a2 2 0 0 1 2-2h2a2 2 0 0 1 2 2v2a1 1 0 0 1-1 1z"}],["path",{d:"M17 21v-2"}],["path",{d:"M19 14V6.5a1 1 0 0 0-7 0v11a1 1 0 0 1-7 0V10"}],["path",{d:"M21 21v-2"}],["path",{d:"M3 5V3"}],["path",{d:"M4 10a2 2 0 0 1-2-2V6a1 1 0 0 1 1-1h4a1 1 0 0 1 1 1v2a2 2 0 0 1-2 2z"}],["path",{d:"M7 5V3"}]],V5=[["path",{d:"M16 13H3"}],["path",{d:"M16 17H3"}],["path",{d:"m7.2 7.9-3.388 2.5A2 2 0 0 0 3 12.01V20a1 1 0 0 0 1 1h16a1 1 0 0 0 1-1v-8.654c0-2-2.44-6.026-6.44-8.026a1 1 0 0 0-1.082.057L10.4 5.6"}],["circle",{cx:"9",cy:"7",r:"2"}]],S5=[["path",{d:"M20 21v-8a2 2 0 0 0-2-2H6a2 2 0 0 0-2 2v8"}],["path",{d:"M4 16s.5-1 2-1 2.5 2 4 2 2.5-2 4-2 2.5 2 4 2 2-1 2-1"}],["path",{d:"M2 21h20"}],["path",{d:"M7 8v3"}],["path",{d:"M12 8v3"}],["path",{d:"M17 8v3"}],["path",{d:"M7 4h.01"}],["path",{d:"M12 4h.01"}],["path",{d:"M17 4h.01"}]],L5=[["rect",{width:"16",height:"20",x:"4",y:"2",rx:"2"}],["line",{x1:"8",x2:"16",y1:"6",y2:"6"}],["line",{x1:"16",x2:"16",y1:"14",y2:"18"}],["path",{d:"M16 10h.01"}],["path",{d:"M12 10h.01"}],["path",{d:"M8 10h.01"}],["path",{d:"M12 14h.01"}],["path",{d:"M8 14h.01"}],["path",{d:"M12 18h.01"}],["path",{d:"M8 18h.01"}]],f5=[["path",{d:"M11 14h1v4"}],["path",{d:"M16 2v4"}],["path",{d:"M3 10h18"}],["path",{d:"M8 2v4"}],["rect",{x:"3",y:"4",width:"18",height:"18",rx:"2"}]],k5=[["path",{d:"m14 18 4 4 4-4"}],["path",{d:"M16 2v4"}],["path",{d:"M18 14v8"}],["path",{d:"M21 11.354V6a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h7.343"}],["path",{d:"M3 10h18"}],["path",{d:"M8 2v4"}]],P5=[["path",{d:"m14 18 4-4 4 4"}],["path",{d:"M16 2v4"}],["path",{d:"M18 22v-8"}],["path",{d:"M21 11.343V6a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h9"}],["path",{d:"M3 10h18"}],["path",{d:"M8 2v4"}]],B5=[["path",{d:"M8 2v4"}],["path",{d:"M16 2v4"}],["path",{d:"M21 14V6a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h8"}],["path",{d:"M3 10h18"}],["path",{d:"m16 20 2 2 4-4"}]],D5=[["path",{d:"M8 2v4"}],["path",{d:"M16 2v4"}],["rect",{width:"18",height:"18",x:"3",y:"4",rx:"2"}],["path",{d:"M3 10h18"}],["path",{d:"m9 16 2 2 4-4"}]],F5=[["path",{d:"M16 14v2.2l1.6 1"}],["path",{d:"M16 2v4"}],["path",{d:"M21 7.5V6a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h3.5"}],["path",{d:"M3 10h5"}],["path",{d:"M8 2v4"}],["circle",{cx:"16",cy:"16",r:"6"}]],z5=[["path",{d:"M8 2v4"}],["path",{d:"M16 2v4"}],["rect",{width:"18",height:"18",x:"3",y:"4",rx:"2"}],["path",{d:"M3 10h18"}],["path",{d:"M8 14h.01"}],["path",{d:"M12 14h.01"}],["path",{d:"M16 14h.01"}],["path",{d:"M8 18h.01"}],["path",{d:"M12 18h.01"}],["path",{d:"M16 18h.01"}]],b5=[["path",{d:"M8 2v4"}],["path",{d:"M16 2v4"}],["path",{d:"M21 17V6a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11Z"}],["path",{d:"M3 10h18"}],["path",{d:"M15 22v-4a2 2 0 0 1 2-2h4"}]],R5=[["path",{d:"m15.228 16.852-.923-.383"}],["path",{d:"m15.228 19.148-.923.383"}],["path",{d:"M16 2v4"}],["path",{d:"m16.47 14.305.382.923"}],["path",{d:"m16.852 20.772-.383.924"}],["path",{d:"m19.148 15.228.383-.923"}],["path",{d:"m19.53 21.696-.382-.924"}],["path",{d:"m20.772 16.852.924-.383"}],["path",{d:"m20.772 19.148.924.383"}],["path",{d:"M21 10.592V6a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h6"}],["path",{d:"M3 10h18"}],["path",{d:"M8 2v4"}],["circle",{cx:"18",cy:"18",r:"3"}]],T5=[["path",{d:"M12.127 22H5a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v5.125"}],["path",{d:"M14.62 18.8A2.25 2.25 0 1 1 18 15.836a2.25 2.25 0 1 1 3.38 2.966l-2.626 2.856a.998.998 0 0 1-1.507 0z"}],["path",{d:"M16 2v4"}],["path",{d:"M3 10h18"}],["path",{d:"M8 2v4"}]],q5=[["path",{d:"M8 2v4"}],["path",{d:"M16 2v4"}],["rect",{width:"18",height:"18",x:"3",y:"4",rx:"2"}],["path",{d:"M3 10h18"}],["path",{d:"M10 16h4"}]],U5=[["path",{d:"M16 19h6"}],["path",{d:"M16 2v4"}],["path",{d:"M21 15V6a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h8.5"}],["path",{d:"M3 10h18"}],["path",{d:"M8 2v4"}]],O5=[["path",{d:"M4.2 4.2A2 2 0 0 0 3 6v14a2 2 0 0 0 2 2h14a2 2 0 0 0 1.82-1.18"}],["path",{d:"M21 15.5V6a2 2 0 0 0-2-2H9.5"}],["path",{d:"M16 2v4"}],["path",{d:"M3 10h7"}],["path",{d:"M21 10h-5.5"}],["path",{d:"m2 2 20 20"}]],Z5=[["path",{d:"M16 19h6"}],["path",{d:"M16 2v4"}],["path",{d:"M19 16v6"}],["path",{d:"M21 12.598V6a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h8.5"}],["path",{d:"M3 10h18"}],["path",{d:"M8 2v4"}]],G5=[["rect",{width:"18",height:"18",x:"3",y:"4",rx:"2"}],["path",{d:"M16 2v4"}],["path",{d:"M3 10h18"}],["path",{d:"M8 2v4"}],["path",{d:"M17 14h-6"}],["path",{d:"M13 18H7"}],["path",{d:"M7 14h.01"}],["path",{d:"M17 18h.01"}]],I5=[["path",{d:"M8 2v4"}],["path",{d:"M16 2v4"}],["rect",{width:"18",height:"18",x:"3",y:"4",rx:"2"}],["path",{d:"M3 10h18"}],["path",{d:"M10 16h4"}],["path",{d:"M12 14v4"}]],W5=[["path",{d:"M11 10v4h4"}],["path",{d:"m11 14 1.535-1.605a5 5 0 0 1 8 1.5"}],["path",{d:"M16 2v4"}],["path",{d:"m21 18-1.535 1.605a5 5 0 0 1-8-1.5"}],["path",{d:"M21 22v-4h-4"}],["path",{d:"M21 8.5V6a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h4.3"}],["path",{d:"M3 10h4"}],["path",{d:"M8 2v4"}]],E5=[["path",{d:"M16 2v4"}],["path",{d:"M21 11.75V6a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h7.25"}],["path",{d:"m22 22-1.875-1.875"}],["path",{d:"M3 10h18"}],["path",{d:"M8 2v4"}],["circle",{cx:"18",cy:"18",r:"3"}]],X5=[["path",{d:"M8 2v4"}],["path",{d:"M16 2v4"}],["path",{d:"M21 13V6a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h8"}],["path",{d:"M3 10h18"}],["path",{d:"m17 22 5-5"}],["path",{d:"m17 17 5 5"}]],j5=[["path",{d:"M8 2v4"}],["path",{d:"M16 2v4"}],["rect",{width:"18",height:"18",x:"3",y:"4",rx:"2"}],["path",{d:"M3 10h18"}],["path",{d:"m14 14-4 4"}],["path",{d:"m10 14 4 4"}]],N5=[["path",{d:"M8 2v4"}],["path",{d:"M16 2v4"}],["rect",{width:"18",height:"18",x:"3",y:"4",rx:"2"}],["path",{d:"M3 10h18"}]],K5=[["path",{d:"M14.564 14.558a3 3 0 1 1-4.122-4.121"}],["path",{d:"m2 2 20 20"}],["path",{d:"M20 20H4a2 2 0 0 1-2-2V9a2 2 0 0 1 2-2h1.997a2 2 0 0 0 .819-.175"}],["path",{d:"M9.695 4.024A2 2 0 0 1 10.004 4h3.993a2 2 0 0 1 1.76 1.05l.486.9A2 2 0 0 0 18.003 7H20a2 2 0 0 1 2 2v7.344"}]],Q5=[["path",{d:"M13.997 4a2 2 0 0 1 1.76 1.05l.486.9A2 2 0 0 0 18.003 7H20a2 2 0 0 1 2 2v9a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2V9a2 2 0 0 1 2-2h1.997a2 2 0 0 0 1.759-1.048l.489-.904A2 2 0 0 1 10.004 4z"}],["circle",{cx:"12",cy:"13",r:"3"}]],J5=[["path",{d:"M5.7 21a2 2 0 0 1-3.5-2l8.6-14a6 6 0 0 1 10.4 6 2 2 0 1 1-3.464-2 2 2 0 1 0-3.464-2Z"}],["path",{d:"M17.75 7 15 2.1"}],["path",{d:"M10.9 4.8 13 9"}],["path",{d:"m7.9 9.7 2 4.4"}],["path",{d:"M4.9 14.7 7 18.9"}]],Y5=[["path",{d:"M10 10v7.9"}],["path",{d:"M11.802 6.145a5 5 0 0 1 6.053 6.053"}],["path",{d:"M14 6.1v2.243"}],["path",{d:"m15.5 15.571-.964.964a5 5 0 0 1-7.071 0 5 5 0 0 1 0-7.07l.964-.965"}],["path",{d:"M16 7V3a1 1 0 0 1 1.707-.707 2.5 2.5 0 0 0 2.152.717 1 1 0 0 1 1.131 1.131 2.5 2.5 0 0 0 .717 2.152A1 1 0 0 1 21 8h-4"}],["path",{d:"m2 2 20 20"}],["path",{d:"M8 17v4a1 1 0 0 1-1.707.707 2.5 2.5 0 0 0-2.152-.717 1 1 0 0 1-1.131-1.131 2.5 2.5 0 0 0-.717-2.152A1 1 0 0 1 3 16h4"}]],_5=[["path",{d:"M10 7v10.9"}],["path",{d:"M14 6.1V17"}],["path",{d:"M16 7V3a1 1 0 0 1 1.707-.707 2.5 2.5 0 0 0 2.152.717 1 1 0 0 1 1.131 1.131 2.5 2.5 0 0 0 .717 2.152A1 1 0 0 1 21 8h-4"}],["path",{d:"M16.536 7.465a5 5 0 0 0-7.072 0l-2 2a5 5 0 0 0 0 7.07 5 5 0 0 0 7.072 0l2-2a5 5 0 0 0 0-7.07"}],["path",{d:"M8 17v4a1 1 0 0 1-1.707.707 2.5 2.5 0 0 0-2.152-.717 1 1 0 0 1-1.131-1.131 2.5 2.5 0 0 0-.717-2.152A1 1 0 0 1 3 16h4"}]],x5=[["path",{d:"M12 22v-4"}],["path",{d:"M7 12c-1.5 0-4.5 1.5-5 3 3.5 1.5 6 1 6 1-1.5 1.5-2 3.5-2 5 2.5 0 4.5-1.5 6-3 1.5 1.5 3.5 3 6 3 0-1.5-.5-3.5-2-5 0 0 2.5.5 6-1-.5-1.5-3.5-3-5-3 1.5-1 4-4 4-6-2.5 0-5.5 1.5-7 3 0-2.5-.5-5-2-7-1.5 2-2 4.5-2 7-1.5-1.5-4.5-3-7-3 0 2 2.5 5 4 6"}]],a3=[["path",{d:"M10.5 5H19a2 2 0 0 1 2 2v8.5"}],["path",{d:"M17 11h-.5"}],["path",{d:"M19 19H5a2 2 0 0 1-2-2V7a2 2 0 0 1 2-2"}],["path",{d:"m2 2 20 20"}],["path",{d:"M7 11h4"}],["path",{d:"M7 15h2.5"}]],F=[["rect",{width:"18",height:"14",x:"3",y:"5",rx:"2",ry:"2"}],["path",{d:"M7 15h4M15 15h2M7 11h2M13 11h4"}]],t3=[["path",{d:"m21 8-2 2-1.5-3.7A2 2 0 0 0 15.646 5H8.4a2 2 0 0 0-1.903 1.257L5 10 3 8"}],["path",{d:"M7 14h.01"}],["path",{d:"M17 14h.01"}],["rect",{width:"18",height:"8",x:"3",y:"10",rx:"2"}],["path",{d:"M5 18v2"}],["path",{d:"M19 18v2"}]],h3=[["path",{d:"M10 2h4"}],["path",{d:"m21 8-2 2-1.5-3.7A2 2 0 0 0 15.646 5H8.4a2 2 0 0 0-1.903 1.257L5 10 3 8"}],["path",{d:"M7 14h.01"}],["path",{d:"M17 14h.01"}],["rect",{width:"18",height:"8",x:"3",y:"10",rx:"2"}],["path",{d:"M5 18v2"}],["path",{d:"M19 18v2"}]],d3=[["path",{d:"M19 17h2c.6 0 1-.4 1-1v-3c0-.9-.7-1.7-1.5-1.9C18.7 10.6 16 10 16 10s-1.3-1.4-2.2-2.3c-.5-.4-1.1-.7-1.8-.7H5c-.6 0-1.1.4-1.4.9l-1.4 2.9A3.7 3.7 0 0 0 2 12v4c0 .6.4 1 1 1h2"}],["circle",{cx:"7",cy:"17",r:"2"}],["path",{d:"M9 17h6"}],["circle",{cx:"17",cy:"17",r:"2"}]],c3=[["path",{d:"M18 19V9a4 4 0 0 0-4-4H6a4 4 0 0 0-4 4v8a2 2 0 0 0 2 2h2"}],["path",{d:"M2 9h3a1 1 0 0 1 1 1v2a1 1 0 0 1-1 1H2"}],["path",{d:"M22 17v1a1 1 0 0 1-1 1H10v-9a1 1 0 0 1 1-1h2a1 1 0 0 1 1 1v9"}],["circle",{cx:"8",cy:"19",r:"2"}]],M3=[["path",{d:"M12 14v4"}],["path",{d:"M14.172 2a2 2 0 0 1 1.414.586l3.828 3.828A2 2 0 0 1 20 7.828V20a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2z"}],["path",{d:"M8 14h8"}],["rect",{x:"8",y:"10",width:"8",height:"8",rx:"1"}]],p3=[["path",{d:"M2.27 21.7s9.87-3.5 12.73-6.36a4.5 4.5 0 0 0-6.36-6.37C5.77 11.84 2.27 21.7 2.27 21.7zM8.64 14l-2.05-2.04M15.34 15l-2.46-2.46"}],["path",{d:"M22 9s-1.33-2-3.5-2C16.86 7 15 9 15 9s1.33 2 3.5 2S22 9 22 9z"}],["path",{d:"M15 2s-2 1.33-2 3.5S15 9 15 9s2-1.84 2-3.5C17 3.33 15 2 15 2z"}]],i3=[["path",{d:"M10 9v7"}],["path",{d:"M14 6v10"}],["circle",{cx:"17.5",cy:"12.5",r:"3.5"}],["circle",{cx:"6.5",cy:"12.5",r:"3.5"}]],n3=[["path",{d:"m2 16 4.039-9.69a.5.5 0 0 1 .923 0L11 16"}],["path",{d:"M22 9v7"}],["path",{d:"M3.304 13h6.392"}],["circle",{cx:"18.5",cy:"12.5",r:"3.5"}]],l3=[["path",{d:"M15 11h4.5a1 1 0 0 1 0 5h-4a.5.5 0 0 1-.5-.5v-9a.5.5 0 0 1 .5-.5h3a1 1 0 0 1 0 5"}],["path",{d:"m2 16 4.039-9.69a.5.5 0 0 1 .923 0L11 16"}],["path",{d:"M3.304 13h6.392"}]],e3=[["rect",{width:"20",height:"16",x:"2",y:"4",rx:"2"}],["circle",{cx:"8",cy:"10",r:"2"}],["path",{d:"M8 12h8"}],["circle",{cx:"16",cy:"10",r:"2"}],["path",{d:"m6 20 .7-2.9A1.4 1.4 0 0 1 8.1 16h7.8a1.4 1.4 0 0 1 1.4 1l.7 3"}]],r3=[["path",{d:"M2 8V6a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v12a2 2 0 0 1-2 2h-6"}],["path",{d:"M2 12a9 9 0 0 1 8 8"}],["path",{d:"M2 16a5 5 0 0 1 4 4"}],["line",{x1:"2",x2:"2.01",y1:"20",y2:"20"}]],o3=[["path",{d:"M10 5V3"}],["path",{d:"M14 5V3"}],["path",{d:"M15 21v-3a3 3 0 0 0-6 0v3"}],["path",{d:"M18 3v8"}],["path",{d:"M18 5H6"}],["path",{d:"M22 11H2"}],["path",{d:"M22 9v10a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2V9"}],["path",{d:"M6 3v8"}]],v3=[["path",{d:"M12 5c.67 0 1.35.09 2 .26 1.78-2 5.03-2.84 6.42-2.26 1.4.58-.42 7-.42 7 .57 1.07 1 2.24 1 3.44C21 17.9 16.97 21 12 21s-9-3-9-7.56c0-1.25.5-2.4 1-3.44 0 0-1.89-6.42-.5-7 1.39-.58 4.72.23 6.5 2.23A9.04 9.04 0 0 1 12 5Z"}],["path",{d:"M8 14v.5"}],["path",{d:"M16 14v.5"}],["path",{d:"M11.25 16.25h1.5L12 17l-.75-.75Z"}]],$3=[["path",{d:"M16.75 12h3.632a1 1 0 0 1 .894 1.447l-2.034 4.069a1 1 0 0 1-1.708.134l-2.124-2.97"}],["path",{d:"M17.106 9.053a1 1 0 0 1 .447 1.341l-3.106 6.211a1 1 0 0 1-1.342.447L3.61 12.3a2.92 2.92 0 0 1-1.3-3.91L3.69 5.6a2.92 2.92 0 0 1 3.92-1.3z"}],["path",{d:"M2 19h3.76a2 2 0 0 0 1.8-1.1L9 15"}],["path",{d:"M2 21v-4"}],["path",{d:"M7 9h.01"}]],z=[["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["path",{d:"M7 11.207a.5.5 0 0 1 .146-.353l2-2a.5.5 0 0 1 .708 0l3.292 3.292a.5.5 0 0 0 .708 0l4.292-4.292a.5.5 0 0 1 .854.353V16a1 1 0 0 1-1 1H8a1 1 0 0 1-1-1z"}]],b=[["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["rect",{x:"7",y:"13",width:"9",height:"4",rx:"1"}],["rect",{x:"7",y:"5",width:"12",height:"4",rx:"1"}]],m3=[["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["path",{d:"M7 11h8"}],["path",{d:"M7 16h3"}],["path",{d:"M7 6h12"}]],y3=[["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["path",{d:"M7 11h8"}],["path",{d:"M7 16h12"}],["path",{d:"M7 6h3"}]],s3=[["path",{d:"M11 13v4"}],["path",{d:"M15 5v4"}],["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["rect",{x:"7",y:"13",width:"9",height:"4",rx:"1"}],["rect",{x:"7",y:"5",width:"12",height:"4",rx:"1"}]],R=[["path",{d:"M9 5v4"}],["rect",{width:"4",height:"6",x:"7",y:"9",rx:"1"}],["path",{d:"M9 15v2"}],["path",{d:"M17 3v2"}],["rect",{width:"4",height:"8",x:"15",y:"5",rx:"1"}],["path",{d:"M17 13v3"}],["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}]],T=[["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["path",{d:"M7 16h8"}],["path",{d:"M7 11h12"}],["path",{d:"M7 6h3"}]],g3=[["path",{d:"M13 17V9"}],["path",{d:"M18 17v-3"}],["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["path",{d:"M8 17V5"}]],q=[["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["rect",{x:"15",y:"5",width:"4",height:"12",rx:"1"}],["rect",{x:"7",y:"8",width:"4",height:"9",rx:"1"}]],U=[["path",{d:"M13 17V9"}],["path",{d:"M18 17V5"}],["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["path",{d:"M8 17v-3"}]],u3=[["path",{d:"M11 13H7"}],["path",{d:"M19 9h-4"}],["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["rect",{x:"15",y:"5",width:"4",height:"12",rx:"1"}],["rect",{x:"7",y:"8",width:"4",height:"9",rx:"1"}]],O=[["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["path",{d:"M18 17V9"}],["path",{d:"M13 17V5"}],["path",{d:"M8 17v-3"}]],C3=[["path",{d:"M10 6h8"}],["path",{d:"M12 16h6"}],["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["path",{d:"M8 11h7"}]],H3=[["path",{d:"m13.11 7.664 1.78 2.672"}],["path",{d:"m14.162 12.788-3.324 1.424"}],["path",{d:"m20 4-6.06 1.515"}],["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["circle",{cx:"12",cy:"6",r:"2"}],["circle",{cx:"16",cy:"12",r:"2"}],["circle",{cx:"9",cy:"15",r:"2"}]],Z=[["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["path",{d:"m19 9-5 5-4-4-3 3"}]],A3=[["path",{d:"M5 21V3"}],["path",{d:"M12 21V9"}],["path",{d:"M19 21v-6"}]],G=[["path",{d:"M5 21v-6"}],["path",{d:"M12 21V9"}],["path",{d:"M19 21V3"}]],I=[["path",{d:"M5 21v-6"}],["path",{d:"M12 21V3"}],["path",{d:"M19 21V9"}]],w3=[["path",{d:"M12 16v5"}],["path",{d:"M16 14v7"}],["path",{d:"M20 10v11"}],["path",{d:"m22 3-8.646 8.646a.5.5 0 0 1-.708 0L9.354 8.354a.5.5 0 0 0-.707 0L2 15"}],["path",{d:"M4 18v3"}],["path",{d:"M8 14v7"}]],W=[["path",{d:"M6 5h12"}],["path",{d:"M4 12h10"}],["path",{d:"M12 19h8"}]],E=[["circle",{cx:"7.5",cy:"7.5",r:".5",fill:"currentColor"}],["circle",{cx:"18.5",cy:"5.5",r:".5",fill:"currentColor"}],["circle",{cx:"11.5",cy:"11.5",r:".5",fill:"currentColor"}],["circle",{cx:"7.5",cy:"16.5",r:".5",fill:"currentColor"}],["circle",{cx:"17.5",cy:"14.5",r:".5",fill:"currentColor"}],["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}]],X=[["path",{d:"M21 12c.552 0 1.005-.449.95-.998a10 10 0 0 0-8.953-8.951c-.55-.055-.998.398-.998.95v8a1 1 0 0 0 1 1z"}],["path",{d:"M21.21 15.89A10 10 0 1 1 8 2.83"}]],V3=[["path",{d:"M3 3v16a2 2 0 0 0 2 2h16"}],["path",{d:"M7 16c.5-2 1.5-7 4-7 2 0 2 3 4 3 2.5 0 4.5-5 5-7"}]],S3=[["path",{d:"M18 6 7 17l-5-5"}],["path",{d:"m22 10-7.5 7.5L13 16"}]],L3=[["path",{d:"M20 4L9 15"}],["path",{d:"M21 19L3 19"}],["path",{d:"M9 15L4 10"}]],f3=[["path",{d:"M20 6 9 17l-5-5"}]],k3=[["path",{d:"M17 21a1 1 0 0 0 1-1v-5.35c0-.457.316-.844.727-1.041a4 4 0 0 0-2.134-7.589 5 5 0 0 0-9.186 0 4 4 0 0 0-2.134 7.588c.411.198.727.585.727 1.041V20a1 1 0 0 0 1 1Z"}],["path",{d:"M6 17h12"}]],P3=[["path",{d:"m6 9 6 6 6-6"}]],B3=[["path",{d:"M2 17a5 5 0 0 0 10 0c0-2.76-2.5-5-5-3-2.5-2-5 .24-5 3Z"}],["path",{d:"M12 17a5 5 0 0 0 10 0c0-2.76-2.5-5-5-3-2.5-2-5 .24-5 3Z"}],["path",{d:"M7 14c3.22-2.91 4.29-8.75 5-12 1.66 2.38 4.94 9 5 12"}],["path",{d:"M22 9c-4.29 0-7.14-2.33-10-7 5.71 0 10 4.67 10 7Z"}]],D3=[["path",{d:"m17 18-6-6 6-6"}],["path",{d:"M7 6v12"}]],F3=[["path",{d:"m7 18 6-6-6-6"}],["path",{d:"M17 6v12"}]],z3=[["path",{d:"m15 18-6-6 6-6"}]],b3=[["path",{d:"m9 18 6-6-6-6"}]],R3=[["path",{d:"m18 15-6-6-6 6"}]],T3=[["path",{d:"m7 20 5-5 5 5"}],["path",{d:"m7 4 5 5 5-5"}]],q3=[["path",{d:"m7 6 5 5 5-5"}],["path",{d:"m7 13 5 5 5-5"}]],U3=[["path",{d:"M12 12h.01"}],["path",{d:"M16 12h.01"}],["path",{d:"m17 7 5 5-5 5"}],["path",{d:"m7 7-5 5 5 5"}],["path",{d:"M8 12h.01"}]],O3=[["path",{d:"m9 7-5 5 5 5"}],["path",{d:"m15 7 5 5-5 5"}]],Z3=[["path",{d:"m11 17-5-5 5-5"}],["path",{d:"m18 17-5-5 5-5"}]],G3=[["path",{d:"m20 17-5-5 5-5"}],["path",{d:"m4 17 5-5-5-5"}]],I3=[["path",{d:"m6 17 5-5-5-5"}],["path",{d:"m13 17 5-5-5-5"}]],W3=[["path",{d:"m7 15 5 5 5-5"}],["path",{d:"m7 9 5-5 5 5"}]],E3=[["path",{d:"m17 11-5-5-5 5"}],["path",{d:"m17 18-5-5-5 5"}]],j=[["path",{d:"M10.88 21.94 15.46 14"}],["path",{d:"M21.17 8H12"}],["path",{d:"M3.95 6.06 8.54 14"}],["circle",{cx:"12",cy:"12",r:"10"}],["circle",{cx:"12",cy:"12",r:"4"}]],X3=[["path",{d:"M10 9h4"}],["path",{d:"M12 7v5"}],["path",{d:"M14 21v-3a2 2 0 0 0-4 0v3"}],["path",{d:"m18 9 3.52 2.147a1 1 0 0 1 .48.854V19a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2v-6.999a1 1 0 0 1 .48-.854L6 9"}],["path",{d:"M6 21V7a1 1 0 0 1 .376-.782l5-3.999a1 1 0 0 1 1.249.001l5 4A1 1 0 0 1 18 7v14"}]],j3=[["path",{d:"M12 12H3a1 1 0 0 0-1 1v2a1 1 0 0 0 1 1h13"}],["path",{d:"M18 8c0-2.5-2-2.5-2-5"}],["path",{d:"m2 2 20 20"}],["path",{d:"M21 12a1 1 0 0 1 1 1v2a1 1 0 0 1-.5.866"}],["path",{d:"M22 8c0-2.5-2-2.5-2-5"}],["path",{d:"M7 12v4"}]],N3=[["path",{d:"M17 12H3a1 1 0 0 0-1 1v2a1 1 0 0 0 1 1h14"}],["path",{d:"M18 8c0-2.5-2-2.5-2-5"}],["path",{d:"M21 16a1 1 0 0 0 1-1v-2a1 1 0 0 0-1-1"}],["path",{d:"M22 8c0-2.5-2-2.5-2-5"}],["path",{d:"M7 12v4"}]],N=[["circle",{cx:"12",cy:"12",r:"10"}],["line",{x1:"12",x2:"12",y1:"8",y2:"12"}],["line",{x1:"12",x2:"12.01",y1:"16",y2:"16"}]],K=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M12 8v8"}],["path",{d:"m8 12 4 4 4-4"}]],Q=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m12 8-4 4 4 4"}],["path",{d:"M16 12H8"}]],J=[["path",{d:"M2 12a10 10 0 1 1 10 10"}],["path",{d:"m2 22 10-10"}],["path",{d:"M8 22H2v-6"}]],Y=[["path",{d:"M2 8V2h6"}],["path",{d:"m2 2 10 10"}],["path",{d:"M12 2A10 10 0 1 1 2 12"}]],_=[["path",{d:"M12 22a10 10 0 1 1 10-10"}],["path",{d:"M22 22 12 12"}],["path",{d:"M22 16v6h-6"}]],x=[["path",{d:"M22 12A10 10 0 1 1 12 2"}],["path",{d:"M22 2 12 12"}],["path",{d:"M16 2h6v6"}]],a1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m12 16 4-4-4-4"}],["path",{d:"M8 12h8"}]],t1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m16 12-4-4-4 4"}],["path",{d:"M12 16V8"}]],h1=[["path",{d:"M21.801 10A10 10 0 1 1 17 3.335"}],["path",{d:"m9 11 3 3L22 4"}]],d1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m9 12 2 2 4-4"}]],c1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m16 10-4 4-4-4"}]],M1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m14 16-4-4 4-4"}]],p1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m10 8 4 4-4 4"}]],i1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m8 14 4-4 4 4"}]],K3=[["path",{d:"M10.1 2.182a10 10 0 0 1 3.8 0"}],["path",{d:"M13.9 21.818a10 10 0 0 1-3.8 0"}],["path",{d:"M17.609 3.721a10 10 0 0 1 2.69 2.7"}],["path",{d:"M2.182 13.9a10 10 0 0 1 0-3.8"}],["path",{d:"M20.279 17.609a10 10 0 0 1-2.7 2.69"}],["path",{d:"M21.818 10.1a10 10 0 0 1 0 3.8"}],["path",{d:"M3.721 6.391a10 10 0 0 1 2.7-2.69"}],["path",{d:"M6.391 20.279a10 10 0 0 1-2.69-2.7"}]],n1=[["line",{x1:"8",x2:"16",y1:"12",y2:"12"}],["line",{x1:"12",x2:"12",y1:"16",y2:"16"}],["line",{x1:"12",x2:"12",y1:"8",y2:"8"}],["circle",{cx:"12",cy:"12",r:"10"}]],Q3=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M16 8h-6a2 2 0 1 0 0 4h4a2 2 0 1 1 0 4H8"}],["path",{d:"M12 18V6"}]],J3=[["path",{d:"M10.1 2.18a9.93 9.93 0 0 1 3.8 0"}],["path",{d:"M17.6 3.71a9.95 9.95 0 0 1 2.69 2.7"}],["path",{d:"M21.82 10.1a9.93 9.93 0 0 1 0 3.8"}],["path",{d:"M20.29 17.6a9.95 9.95 0 0 1-2.7 2.69"}],["path",{d:"M13.9 21.82a9.94 9.94 0 0 1-3.8 0"}],["path",{d:"M6.4 20.29a9.95 9.95 0 0 1-2.69-2.7"}],["path",{d:"M2.18 13.9a9.93 9.93 0 0 1 0-3.8"}],["path",{d:"M3.71 6.4a9.95 9.95 0 0 1 2.7-2.69"}],["circle",{cx:"12",cy:"12",r:"1"}]],Y3=[["circle",{cx:"12",cy:"12",r:"10"}],["circle",{cx:"12",cy:"12",r:"1"}]],_3=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M17 12h.01"}],["path",{d:"M12 12h.01"}],["path",{d:"M7 12h.01"}]],x3=[["path",{d:"M7 10h10"}],["path",{d:"M7 14h10"}],["circle",{cx:"12",cy:"12",r:"10"}]],ad=[["path",{d:"M12 2a10 10 0 0 1 7.38 16.75"}],["path",{d:"m16 12-4-4-4 4"}],["path",{d:"M12 16V8"}],["path",{d:"M2.5 8.875a10 10 0 0 0-.5 3"}],["path",{d:"M2.83 16a10 10 0 0 0 2.43 3.4"}],["path",{d:"M4.636 5.235a10 10 0 0 1 .891-.857"}],["path",{d:"M8.644 21.42a10 10 0 0 0 7.631-.38"}]],l1=[["path",{d:"M15.6 2.7a10 10 0 1 0 5.7 5.7"}],["circle",{cx:"12",cy:"12",r:"2"}],["path",{d:"M13.4 10.6 19 5"}]],td=[["path",{d:"M12 2a10 10 0 0 1 7.38 16.75"}],["path",{d:"M12 8v8"}],["path",{d:"M16 12H8"}],["path",{d:"M2.5 8.875a10 10 0 0 0-.5 3"}],["path",{d:"M2.83 16a10 10 0 0 0 2.43 3.4"}],["path",{d:"M4.636 5.235a10 10 0 0 1 .891-.857"}],["path",{d:"M8.644 21.42a10 10 0 0 0 7.631-.38"}]],e1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M8 12h8"}]],hd=[["path",{d:"m2 2 20 20"}],["path",{d:"M8.35 2.69A10 10 0 0 1 21.3 15.65"}],["path",{d:"M19.08 19.08A10 10 0 1 1 4.92 4.92"}]],r1=[["path",{d:"M12.656 7H13a3 3 0 0 1 2.984 3.307"}],["path",{d:"M13 13H9"}],["path",{d:"M19.071 19.071A1 1 0 0 1 4.93 4.93"}],["path",{d:"m2 2 20 20"}],["path",{d:"M8.357 2.687a10 10 0 0 1 12.956 12.956"}],["path",{d:"M9 17V9"}]],o1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M9 17V7h4a3 3 0 0 1 0 6H9"}]],v1=[["circle",{cx:"12",cy:"12",r:"10"}],["line",{x1:"10",x2:"10",y1:"15",y2:"9"}],["line",{x1:"14",x2:"14",y1:"15",y2:"9"}]],$1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m15 9-6 6"}],["path",{d:"M9 9h.01"}],["path",{d:"M15 15h.01"}]],m1=[["path",{d:"M9 9.003a1 1 0 0 1 1.517-.859l4.997 2.997a1 1 0 0 1 0 1.718l-4.997 2.997A1 1 0 0 1 9 14.996z"}],["circle",{cx:"12",cy:"12",r:"10"}]],y1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M8 12h8"}],["path",{d:"M12 8v8"}]],dd=[["path",{d:"M10 16V9.5a1 1 0 0 1 5 0"}],["path",{d:"M8 12h4"}],["path",{d:"M8 16h7"}],["circle",{cx:"12",cy:"12",r:"10"}]],s1=[["path",{d:"M12 7v4"}],["path",{d:"M7.998 9.003a5 5 0 1 0 8-.005"}],["circle",{cx:"12",cy:"12",r:"10"}]],l=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M9.09 9a3 3 0 0 1 5.83 1c0 2-3 3-3 3"}],["path",{d:"M12 17h.01"}]],g1=[["path",{d:"M22 2 2 22"}],["circle",{cx:"12",cy:"12",r:"10"}]],cd=[["circle",{cx:"12",cy:"12",r:"10"}],["line",{x1:"9",x2:"15",y1:"15",y2:"9"}]],Md=[["circle",{cx:"12",cy:"12",r:"6"}]],pd=[["path",{d:"M11.051 7.616a1 1 0 0 1 1.909.024l.737 1.452a1 1 0 0 0 .737.535l1.634.256a1 1 0 0 1 .588 1.806l-1.172 1.168a1 1 0 0 0-.282.866l.259 1.613a1 1 0 0 1-1.541 1.134l-1.465-.75a1 1 0 0 0-.912 0l-1.465.75a1 1 0 0 1-1.539-1.133l.258-1.613a1 1 0 0 0-.282-.867l-1.156-1.152a1 1 0 0 1 .572-1.822l1.633-.256a1 1 0 0 0 .737-.535z"}],["circle",{cx:"12",cy:"12",r:"10"}]],u1=[["circle",{cx:"12",cy:"12",r:"10"}],["rect",{x:"9",y:"9",width:"6",height:"6",rx:"1"}]],C1=[["path",{d:"M18 20a6 6 0 0 0-12 0"}],["circle",{cx:"12",cy:"10",r:"4"}],["circle",{cx:"12",cy:"12",r:"10"}]],H1=[["circle",{cx:"12",cy:"12",r:"10"}],["circle",{cx:"12",cy:"10",r:"3"}],["path",{d:"M7 20.662V19a2 2 0 0 1 2-2h6a2 2 0 0 1 2 2v1.662"}]],A1=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m15 9-6 6"}],["path",{d:"m9 9 6 6"}]],id=[["circle",{cx:"12",cy:"12",r:"10"}]],nd=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M11 9h4a2 2 0 0 0 2-2V3"}],["circle",{cx:"9",cy:"9",r:"2"}],["path",{d:"M7 21v-4a2 2 0 0 1 2-2h4"}],["circle",{cx:"15",cy:"15",r:"2"}]],ld=[["path",{d:"M21.66 17.67a1.08 1.08 0 0 1-.04 1.6A12 12 0 0 1 4.73 2.38a1.1 1.1 0 0 1 1.61-.04z"}],["path",{d:"M19.65 15.66A8 8 0 0 1 8.35 4.34"}],["path",{d:"m14 10-5.5 5.5"}],["path",{d:"M14 17.85V10H6.15"}]],ed=[["path",{d:"M20.2 6 3 11l-.9-2.4c-.3-1.1.3-2.2 1.3-2.5l13.5-4c1.1-.3 2.2.3 2.5 1.3Z"}],["path",{d:"m6.2 5.3 3.1 3.9"}],["path",{d:"m12.4 3.4 3.1 4"}],["path",{d:"M3 11h18v8a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2Z"}]],rd=[["rect",{width:"8",height:"4",x:"8",y:"2",rx:"1",ry:"1"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"}],["path",{d:"m9 14 2 2 4-4"}]],od=[["path",{d:"M16 14v2.2l1.6 1"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v.832"}],["path",{d:"M8 4H6a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h2"}],["circle",{cx:"16",cy:"16",r:"6"}],["rect",{x:"8",y:"2",width:"8",height:"4",rx:"1"}]],vd=[["rect",{width:"8",height:"4",x:"8",y:"2",rx:"1",ry:"1"}],["path",{d:"M8 4H6a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2v-2"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v4"}],["path",{d:"M21 14H11"}],["path",{d:"m15 10-4 4 4 4"}]],$d=[["rect",{width:"8",height:"4",x:"8",y:"2",rx:"1",ry:"1"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"}],["path",{d:"M12 11h4"}],["path",{d:"M12 16h4"}],["path",{d:"M8 11h.01"}],["path",{d:"M8 16h.01"}]],md=[["rect",{width:"8",height:"4",x:"8",y:"2",rx:"1",ry:"1"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"}],["path",{d:"M9 14h6"}]],yd=[["path",{d:"M11 14h10"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v1.344"}],["path",{d:"m17 18 4-4-4-4"}],["path",{d:"M8 4H6a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h12a2 2 0 0 0 1.793-1.113"}],["rect",{x:"8",y:"2",width:"8",height:"4",rx:"1"}]],w1=[["rect",{width:"8",height:"4",x:"8",y:"2",rx:"1"}],["path",{d:"M8 4H6a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2v-.5"}],["path",{d:"M16 4h2a2 2 0 0 1 1.73 1"}],["path",{d:"M8 18h1"}],["path",{d:"M21.378 12.626a1 1 0 0 0-3.004-3.004l-4.01 4.012a2 2 0 0 0-.506.854l-.837 2.87a.5.5 0 0 0 .62.62l2.87-.837a2 2 0 0 0 .854-.506z"}]],V1=[["rect",{width:"8",height:"4",x:"8",y:"2",rx:"1"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2h-5.5"}],["path",{d:"M4 13.5V6a2 2 0 0 1 2-2h2"}],["path",{d:"M13.378 15.626a1 1 0 1 0-3.004-3.004l-5.01 5.012a2 2 0 0 0-.506.854l-.837 2.87a.5.5 0 0 0 .62.62l2.87-.837a2 2 0 0 0 .854-.506z"}]],sd=[["rect",{width:"8",height:"4",x:"8",y:"2",rx:"1",ry:"1"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"}],["path",{d:"M9 14h6"}],["path",{d:"M12 17v-6"}]],gd=[["rect",{width:"8",height:"4",x:"8",y:"2",rx:"1",ry:"1"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"}],["path",{d:"M9 12v-1h6v1"}],["path",{d:"M11 17h2"}],["path",{d:"M12 11v6"}]],ud=[["rect",{width:"8",height:"4",x:"8",y:"2",rx:"1",ry:"1"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"}],["path",{d:"m15 11-6 6"}],["path",{d:"m9 11 6 6"}]],Cd=[["rect",{width:"8",height:"4",x:"8",y:"2",rx:"1",ry:"1"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"}]],Hd=[["path",{d:"M12 6v6l2-4"}],["circle",{cx:"12",cy:"12",r:"10"}]],Ad=[["path",{d:"M12 6v6l-4-2"}],["circle",{cx:"12",cy:"12",r:"10"}]],wd=[["path",{d:"M12 6v6l-2-4"}],["circle",{cx:"12",cy:"12",r:"10"}]],Vd=[["path",{d:"M12 6v6"}],["circle",{cx:"12",cy:"12",r:"10"}]],Sd=[["path",{d:"M12 6v6l4-2"}],["circle",{cx:"12",cy:"12",r:"10"}]],Ld=[["path",{d:"M12 6v6h4"}],["circle",{cx:"12",cy:"12",r:"10"}]],fd=[["path",{d:"M12 6v6l4 2"}],["circle",{cx:"12",cy:"12",r:"10"}]],kd=[["path",{d:"M12 6v6l2 4"}],["circle",{cx:"12",cy:"12",r:"10"}]],Pd=[["path",{d:"M12 6v10"}],["circle",{cx:"12",cy:"12",r:"10"}]],Bd=[["path",{d:"M12 6v6l-2 4"}],["circle",{cx:"12",cy:"12",r:"10"}]],Dd=[["path",{d:"M12 6v6l-4 2"}],["circle",{cx:"12",cy:"12",r:"10"}]],Fd=[["path",{d:"M12 6v6H8"}],["circle",{cx:"12",cy:"12",r:"10"}]],zd=[["path",{d:"M12 6v6l4 2"}],["path",{d:"M20 12v5"}],["path",{d:"M20 21h.01"}],["path",{d:"M21.25 8.2A10 10 0 1 0 16 21.16"}]],bd=[["path",{d:"M12 6v6l2 1"}],["path",{d:"M12.337 21.994a10 10 0 1 1 9.588-8.767"}],["path",{d:"m14 18 4 4 4-4"}],["path",{d:"M18 14v8"}]],Rd=[["path",{d:"M12 6v6l1.56.78"}],["path",{d:"M13.227 21.925a10 10 0 1 1 8.767-9.588"}],["path",{d:"m14 18 4-4 4 4"}],["path",{d:"M18 22v-8"}]],Td=[["path",{d:"M12 2a10 10 0 0 1 7.38 16.75"}],["path",{d:"M12 6v6l4 2"}],["path",{d:"M2.5 8.875a10 10 0 0 0-.5 3"}],["path",{d:"M2.83 16a10 10 0 0 0 2.43 3.4"}],["path",{d:"M4.636 5.235a10 10 0 0 1 .891-.857"}],["path",{d:"M8.644 21.42a10 10 0 0 0 7.631-.38"}]],qd=[["path",{d:"M12 6v6l3.644 1.822"}],["path",{d:"M16 19h6"}],["path",{d:"M19 16v6"}],["path",{d:"M21.92 13.267a10 10 0 1 0-8.653 8.653"}]],Ud=[["path",{d:"M12 6v6l4 2"}],["circle",{cx:"12",cy:"12",r:"10"}]],Od=[["path",{d:"M10 9.17a3 3 0 1 0 0 5.66"}],["path",{d:"M17 9.17a3 3 0 1 0 0 5.66"}],["rect",{x:"2",y:"5",width:"20",height:"14",rx:"2"}]],Zd=[["path",{d:"M12 12v4"}],["path",{d:"M12 20h.01"}],["path",{d:"M17 18h.5a1 1 0 0 0 0-9h-1.79A7 7 0 1 0 7 17.708"}]],Gd=[["path",{d:"m17 15-5.5 5.5L9 18"}],["path",{d:"M5 17.743A7 7 0 1 1 15.71 10h1.79a4.5 4.5 0 0 1 1.5 8.742"}]],Id=[["path",{d:"m10.852 19.772-.383.924"}],["path",{d:"m13.148 14.228.383-.923"}],["path",{d:"M13.148 19.772a3 3 0 1 0-2.296-5.544l-.383-.923"}],["path",{d:"m13.53 20.696-.382-.924a3 3 0 1 1-2.296-5.544"}],["path",{d:"m14.772 15.852.923-.383"}],["path",{d:"m14.772 18.148.923.383"}],["path",{d:"M4.2 15.1a7 7 0 1 1 9.93-9.858A7 7 0 0 1 15.71 8h1.79a4.5 4.5 0 0 1 2.5 8.2"}],["path",{d:"m9.228 15.852-.923-.383"}],["path",{d:"m9.228 18.148-.923.383"}]],S1=[["path",{d:"M12 13v8l-4-4"}],["path",{d:"m12 21 4-4"}],["path",{d:"M4.393 15.269A7 7 0 1 1 15.71 8h1.79a4.5 4.5 0 0 1 2.436 8.284"}]],Wd=[["path",{d:"M4 14.899A7 7 0 1 1 15.71 8h1.79a4.5 4.5 0 0 1 2.5 8.242"}],["path",{d:"M8 19v1"}],["path",{d:"M8 14v1"}],["path",{d:"M16 19v1"}],["path",{d:"M16 14v1"}],["path",{d:"M12 21v1"}],["path",{d:"M12 16v1"}]],Ed=[["path",{d:"M4 14.899A7 7 0 1 1 15.71 8h1.79a4.5 4.5 0 0 1 2.5 8.242"}],["path",{d:"M16 17H7"}],["path",{d:"M17 21H9"}]],Xd=[["path",{d:"M4 14.899A7 7 0 1 1 15.71 8h1.79a4.5 4.5 0 0 1 2.5 8.242"}],["path",{d:"M16 14v2"}],["path",{d:"M8 14v2"}],["path",{d:"M16 20h.01"}],["path",{d:"M8 20h.01"}],["path",{d:"M12 16v2"}],["path",{d:"M12 22h.01"}]],jd=[["path",{d:"M11 20v2"}],["path",{d:"M18.376 14.512a6 6 0 0 0 3.461-4.127c.148-.625-.659-.97-1.248-.714a4 4 0 0 1-5.259-5.26c.255-.589-.09-1.395-.716-1.248a6 6 0 0 0-4.594 5.36"}],["path",{d:"M3 20a5 5 0 1 1 8.9-4H13a3 3 0 0 1 2 5.24"}],["path",{d:"M7 19v2"}]],Nd=[["path",{d:"M6 16.326A7 7 0 1 1 15.71 8h1.79a4.5 4.5 0 0 1 .5 8.973"}],["path",{d:"m13 12-3 5h4l-3 5"}]],Kd=[["path",{d:"M13 16a3 3 0 0 1 0 6H7a5 5 0 1 1 4.9-6z"}],["path",{d:"M18.376 14.512a6 6 0 0 0 3.461-4.127c.148-.625-.659-.97-1.248-.714a4 4 0 0 1-5.259-5.26c.255-.589-.09-1.395-.716-1.248a6 6 0 0 0-4.594 5.36"}]],Qd=[["path",{d:"m2 2 20 20"}],["path",{d:"M5.782 5.782A7 7 0 0 0 9 19h8.5a4.5 4.5 0 0 0 1.307-.193"}],["path",{d:"M21.532 16.5A4.5 4.5 0 0 0 17.5 10h-1.79A7.008 7.008 0 0 0 10 5.07"}]],Jd=[["path",{d:"M4 14.899A7 7 0 1 1 15.71 8h1.79a4.5 4.5 0 0 1 2.5 8.242"}],["path",{d:"m9.2 22 3-7"}],["path",{d:"m9 13-3 7"}],["path",{d:"m17 13-3 7"}]],Yd=[["path",{d:"M4 14.899A7 7 0 1 1 15.71 8h1.79a4.5 4.5 0 0 1 2.5 8.242"}],["path",{d:"M16 14v6"}],["path",{d:"M8 14v6"}],["path",{d:"M12 16v6"}]],_d=[["path",{d:"M4 14.899A7 7 0 1 1 15.71 8h1.79a4.5 4.5 0 0 1 2.5 8.242"}],["path",{d:"M8 15h.01"}],["path",{d:"M8 19h.01"}],["path",{d:"M12 17h.01"}],["path",{d:"M12 21h.01"}],["path",{d:"M16 15h.01"}],["path",{d:"M16 19h.01"}]],xd=[["path",{d:"M12 2v2"}],["path",{d:"m4.93 4.93 1.41 1.41"}],["path",{d:"M20 12h2"}],["path",{d:"m19.07 4.93-1.41 1.41"}],["path",{d:"M15.947 12.65a4 4 0 0 0-5.925-4.128"}],["path",{d:"M3 20a5 5 0 1 1 8.9-4H13a3 3 0 0 1 2 5.24"}],["path",{d:"M11 20v2"}],["path",{d:"M7 19v2"}]],a6=[["path",{d:"M12 2v2"}],["path",{d:"m4.93 4.93 1.41 1.41"}],["path",{d:"M20 12h2"}],["path",{d:"m19.07 4.93-1.41 1.41"}],["path",{d:"M15.947 12.65a4 4 0 0 0-5.925-4.128"}],["path",{d:"M13 22H7a5 5 0 1 1 4.9-6H13a3 3 0 0 1 0 6Z"}]],L1=[["path",{d:"M12 13v8"}],["path",{d:"M4 14.899A7 7 0 1 1 15.71 8h1.79a4.5 4.5 0 0 1 2.5 8.242"}],["path",{d:"m8 17 4-4 4 4"}]],t6=[["path",{d:"M17.5 19H9a7 7 0 1 1 6.71-9h1.79a4.5 4.5 0 1 1 0 9Z"}]],h6=[["path",{d:"M17.5 21H9a7 7 0 1 1 6.71-9h1.79a4.5 4.5 0 1 1 0 9Z"}],["path",{d:"M22 10a3 3 0 0 0-3-3h-2.207a5.502 5.502 0 0 0-10.702.5"}]],d6=[["path",{d:"M16.17 7.83 2 22"}],["path",{d:"M4.02 12a2.827 2.827 0 1 1 3.81-4.17A2.827 2.827 0 1 1 12 4.02a2.827 2.827 0 1 1 4.17 3.81A2.827 2.827 0 1 1 19.98 12a2.827 2.827 0 1 1-3.81 4.17A2.827 2.827 0 1 1 12 19.98a2.827 2.827 0 1 1-4.17-3.81A1 1 0 1 1 4 12"}],["path",{d:"m7.83 7.83 8.34 8.34"}]],c6=[["path",{d:"M17.28 9.05a5.5 5.5 0 1 0-10.56 0A5.5 5.5 0 1 0 12 17.66a5.5 5.5 0 1 0 5.28-8.6Z"}],["path",{d:"M12 17.66L12 22"}]],f1=[["path",{d:"m18 16 4-4-4-4"}],["path",{d:"m6 8-4 4 4 4"}],["path",{d:"m14.5 4-5 16"}]],M6=[["polygon",{points:"12 2 22 8.5 22 15.5 12 22 2 15.5 2 8.5 12 2"}],["line",{x1:"12",x2:"12",y1:"22",y2:"15.5"}],["polyline",{points:"22 8.5 12 15.5 2 8.5"}],["polyline",{points:"2 15.5 12 8.5 22 15.5"}],["line",{x1:"12",x2:"12",y1:"2",y2:"8.5"}]],p6=[["path",{d:"m16 18 6-6-6-6"}],["path",{d:"m8 6-6 6 6 6"}]],i6=[["path",{d:"M21 16V8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73l7 4a2 2 0 0 0 2 0l7-4A2 2 0 0 0 21 16z"}],["polyline",{points:"7.5 4.21 12 6.81 16.5 4.21"}],["polyline",{points:"7.5 19.79 7.5 14.6 3 12"}],["polyline",{points:"21 12 16.5 14.6 16.5 19.79"}],["polyline",{points:"3.27 6.96 12 12.01 20.73 6.96"}],["line",{x1:"12",x2:"12",y1:"22.08",y2:"12"}]],n6=[["path",{d:"M10 2v2"}],["path",{d:"M14 2v2"}],["path",{d:"M16 8a1 1 0 0 1 1 1v8a4 4 0 0 1-4 4H7a4 4 0 0 1-4-4V9a1 1 0 0 1 1-1h14a4 4 0 1 1 0 8h-1"}],["path",{d:"M6 2v2"}]],l6=[["path",{d:"M11 10.27 7 3.34"}],["path",{d:"m11 13.73-4 6.93"}],["path",{d:"M12 22v-2"}],["path",{d:"M12 2v2"}],["path",{d:"M14 12h8"}],["path",{d:"m17 20.66-1-1.73"}],["path",{d:"m17 3.34-1 1.73"}],["path",{d:"M2 12h2"}],["path",{d:"m20.66 17-1.73-1"}],["path",{d:"m20.66 7-1.73 1"}],["path",{d:"m3.34 17 1.73-1"}],["path",{d:"m3.34 7 1.73 1"}],["circle",{cx:"12",cy:"12",r:"2"}],["circle",{cx:"12",cy:"12",r:"8"}]],e6=[["circle",{cx:"8",cy:"8",r:"6"}],["path",{d:"M18.09 10.37A6 6 0 1 1 10.34 18"}],["path",{d:"M7 6h1v4"}],["path",{d:"m16.71 13.88.7.71-2.82 2.82"}]],k1=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M12 3v18"}]],e=[["path",{d:"M10.5 21H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v5.5"}],["path",{d:"m14.3 19.6 1-.4"}],["path",{d:"M15 3v7.5"}],["path",{d:"m15.2 16.9-.9-.3"}],["path",{d:"m16.6 21.7.3-.9"}],["path",{d:"m16.8 15.3-.4-1"}],["path",{d:"m19.1 15.2.3-.9"}],["path",{d:"m19.6 21.7-.4-1"}],["path",{d:"m20.7 16.8 1-.4"}],["path",{d:"m21.7 19.4-.9-.3"}],["path",{d:"M9 3v18"}],["circle",{cx:"18",cy:"18",r:"3"}]],r6=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M7.5 3v18"}],["path",{d:"M12 3v18"}],["path",{d:"M16.5 3v18"}]],P1=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M9 3v18"}],["path",{d:"M15 3v18"}]],o6=[["path",{d:"M14 3a1 1 0 0 1 1 1v5a1 1 0 0 1-1 1"}],["path",{d:"M19 3a1 1 0 0 1 1 1v5a1 1 0 0 1-1 1"}],["path",{d:"m7 15 3 3"}],["path",{d:"m7 21 3-3H5a2 2 0 0 1-2-2v-2"}],["rect",{x:"14",y:"14",width:"7",height:"7",rx:"1"}],["rect",{x:"3",y:"3",width:"7",height:"7",rx:"1"}]],v6=[["path",{d:"M15 6v12a3 3 0 1 0 3-3H6a3 3 0 1 0 3 3V6a3 3 0 1 0-3 3h12a3 3 0 1 0-3-3"}]],$6=[["path",{d:"m16.24 7.76-1.804 5.411a2 2 0 0 1-1.265 1.265L7.76 16.24l1.804-5.411a2 2 0 0 1 1.265-1.265z"}],["circle",{cx:"12",cy:"12",r:"10"}]],m6=[["path",{d:"M15.536 11.293a1 1 0 0 0 0 1.414l2.376 2.377a1 1 0 0 0 1.414 0l2.377-2.377a1 1 0 0 0 0-1.414l-2.377-2.377a1 1 0 0 0-1.414 0z"}],["path",{d:"M2.297 11.293a1 1 0 0 0 0 1.414l2.377 2.377a1 1 0 0 0 1.414 0l2.377-2.377a1 1 0 0 0 0-1.414L6.088 8.916a1 1 0 0 0-1.414 0z"}],["path",{d:"M8.916 17.912a1 1 0 0 0 0 1.415l2.377 2.376a1 1 0 0 0 1.414 0l2.377-2.376a1 1 0 0 0 0-1.415l-2.377-2.376a1 1 0 0 0-1.414 0z"}],["path",{d:"M8.916 4.674a1 1 0 0 0 0 1.414l2.377 2.376a1 1 0 0 0 1.414 0l2.377-2.376a1 1 0 0 0 0-1.414l-2.377-2.377a1 1 0 0 0-1.414 0z"}]],y6=[["rect",{width:"14",height:"8",x:"5",y:"2",rx:"2"}],["rect",{width:"20",height:"8",x:"2",y:"14",rx:"2"}],["path",{d:"M6 18h2"}],["path",{d:"M12 18h6"}]],s6=[["path",{d:"M3 20a1 1 0 0 1-1-1v-1a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v1a1 1 0 0 1-1 1Z"}],["path",{d:"M20 16a8 8 0 1 0-16 0"}],["path",{d:"M12 4v4"}],["path",{d:"M10 4h4"}]],g6=[["path",{d:"m20.9 18.55-8-15.98a1 1 0 0 0-1.8 0l-8 15.98"}],["ellipse",{cx:"12",cy:"19",rx:"9",ry:"3"}]],u6=[["rect",{x:"2",y:"6",width:"20",height:"8",rx:"1"}],["path",{d:"M17 14v7"}],["path",{d:"M7 14v7"}],["path",{d:"M17 3v3"}],["path",{d:"M7 3v3"}],["path",{d:"M10 14 2.3 6.3"}],["path",{d:"m14 6 7.7 7.7"}],["path",{d:"m8 6 8 8"}]],B1=[["path",{d:"M16 2v2"}],["path",{d:"M17.915 22a6 6 0 0 0-12 0"}],["path",{d:"M8 2v2"}],["circle",{cx:"12",cy:"12",r:"4"}],["rect",{x:"3",y:"4",width:"18",height:"18",rx:"2"}]],C6=[["path",{d:"M16 2v2"}],["path",{d:"M7 22v-2a2 2 0 0 1 2-2h6a2 2 0 0 1 2 2v2"}],["path",{d:"M8 2v2"}],["circle",{cx:"12",cy:"11",r:"3"}],["rect",{x:"3",y:"4",width:"18",height:"18",rx:"2"}]],H6=[["path",{d:"M22 7.7c0-.6-.4-1.2-.8-1.5l-6.3-3.9a1.72 1.72 0 0 0-1.7 0l-10.3 6c-.5.2-.9.8-.9 1.4v6.6c0 .5.4 1.2.8 1.5l6.3 3.9a1.72 1.72 0 0 0 1.7 0l10.3-6c.5-.3.9-1 .9-1.5Z"}],["path",{d:"M10 21.9V14L2.1 9.1"}],["path",{d:"m10 14 11.9-6.9"}],["path",{d:"M14 19.8v-8.1"}],["path",{d:"M18 17.5V9.4"}]],A6=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M12 18a6 6 0 0 0 0-12v12z"}]],w6=[["path",{d:"M12 2a10 10 0 1 0 10 10 4 4 0 0 1-5-5 4 4 0 0 1-5-5"}],["path",{d:"M8.5 8.5v.01"}],["path",{d:"M16 15.5v.01"}],["path",{d:"M12 12v.01"}],["path",{d:"M11 17v.01"}],["path",{d:"M7 14v.01"}]],V6=[["path",{d:"M2 12h20"}],["path",{d:"M20 12v8a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2v-8"}],["path",{d:"m4 8 16-4"}],["path",{d:"m8.86 6.78-.45-1.81a2 2 0 0 1 1.45-2.43l1.94-.48a2 2 0 0 1 2.43 1.46l.45 1.8"}]],S6=[["path",{d:"m12 15 2 2 4-4"}],["rect",{width:"14",height:"14",x:"8",y:"8",rx:"2",ry:"2"}],["path",{d:"M4 16c-1.1 0-2-.9-2-2V4c0-1.1.9-2 2-2h10c1.1 0 2 .9 2 2"}]],L6=[["line",{x1:"12",x2:"18",y1:"15",y2:"15"}],["rect",{width:"14",height:"14",x:"8",y:"8",rx:"2",ry:"2"}],["path",{d:"M4 16c-1.1 0-2-.9-2-2V4c0-1.1.9-2 2-2h10c1.1 0 2 .9 2 2"}]],f6=[["line",{x1:"15",x2:"15",y1:"12",y2:"18"}],["line",{x1:"12",x2:"18",y1:"15",y2:"15"}],["rect",{width:"14",height:"14",x:"8",y:"8",rx:"2",ry:"2"}],["path",{d:"M4 16c-1.1 0-2-.9-2-2V4c0-1.1.9-2 2-2h10c1.1 0 2 .9 2 2"}]],k6=[["line",{x1:"12",x2:"18",y1:"18",y2:"12"}],["rect",{width:"14",height:"14",x:"8",y:"8",rx:"2",ry:"2"}],["path",{d:"M4 16c-1.1 0-2-.9-2-2V4c0-1.1.9-2 2-2h10c1.1 0 2 .9 2 2"}]],P6=[["line",{x1:"12",x2:"18",y1:"12",y2:"18"}],["line",{x1:"12",x2:"18",y1:"18",y2:"12"}],["rect",{width:"14",height:"14",x:"8",y:"8",rx:"2",ry:"2"}],["path",{d:"M4 16c-1.1 0-2-.9-2-2V4c0-1.1.9-2 2-2h10c1.1 0 2 .9 2 2"}]],B6=[["rect",{width:"14",height:"14",x:"8",y:"8",rx:"2",ry:"2"}],["path",{d:"M4 16c-1.1 0-2-.9-2-2V4c0-1.1.9-2 2-2h10c1.1 0 2 .9 2 2"}]],D6=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M9.17 14.83a4 4 0 1 0 0-5.66"}]],F6=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M14.83 14.83a4 4 0 1 1 0-5.66"}]],z6=[["path",{d:"m15 10 5 5-5 5"}],["path",{d:"M4 4v7a4 4 0 0 0 4 4h12"}]],b6=[["path",{d:"M20 4v7a4 4 0 0 1-4 4H4"}],["path",{d:"m9 10-5 5 5 5"}]],R6=[["path",{d:"m14 15-5 5-5-5"}],["path",{d:"M20 4h-7a4 4 0 0 0-4 4v12"}]],T6=[["path",{d:"M14 9 9 4 4 9"}],["path",{d:"M20 20h-7a4 4 0 0 1-4-4V4"}]],q6=[["path",{d:"m10 15 5 5 5-5"}],["path",{d:"M4 4h7a4 4 0 0 1 4 4v12"}]],U6=[["path",{d:"m10 9 5-5 5 5"}],["path",{d:"M4 20h7a4 4 0 0 0 4-4V4"}]],O6=[["path",{d:"m15 14 5-5-5-5"}],["path",{d:"M4 20v-7a4 4 0 0 1 4-4h12"}]],Z6=[["path",{d:"M12 20v2"}],["path",{d:"M12 2v2"}],["path",{d:"M17 20v2"}],["path",{d:"M17 2v2"}],["path",{d:"M2 12h2"}],["path",{d:"M2 17h2"}],["path",{d:"M2 7h2"}],["path",{d:"M20 12h2"}],["path",{d:"M20 17h2"}],["path",{d:"M20 7h2"}],["path",{d:"M7 20v2"}],["path",{d:"M7 2v2"}],["rect",{x:"4",y:"4",width:"16",height:"16",rx:"2"}],["rect",{x:"8",y:"8",width:"8",height:"8",rx:"1"}]],G6=[["path",{d:"M20 20v-7a4 4 0 0 0-4-4H4"}],["path",{d:"M9 14 4 9l5-5"}]],I6=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M10 9.3a2.8 2.8 0 0 0-3.5 1 3.1 3.1 0 0 0 0 3.4 2.7 2.7 0 0 0 3.5 1"}],["path",{d:"M17 9.3a2.8 2.8 0 0 0-3.5 1 3.1 3.1 0 0 0 0 3.4 2.7 2.7 0 0 0 3.5 1"}]],W6=[["rect",{width:"20",height:"14",x:"2",y:"5",rx:"2"}],["line",{x1:"2",x2:"22",y1:"10",y2:"10"}]],E6=[["path",{d:"M10.2 18H4.774a1.5 1.5 0 0 1-1.352-.97 11 11 0 0 1 .132-6.487"}],["path",{d:"M18 10.2V4.774a1.5 1.5 0 0 0-.97-1.352 11 11 0 0 0-6.486.132"}],["path",{d:"M18 5a4 3 0 0 1 4 3 2 2 0 0 1-2 2 10 10 0 0 0-5.139 1.42"}],["path",{d:"M5 18a3 4 0 0 0 3 4 2 2 0 0 0 2-2 10 10 0 0 1 1.42-5.14"}],["path",{d:"M8.709 2.554a10 10 0 0 0-6.155 6.155 1.5 1.5 0 0 0 .676 1.626l9.807 5.42a2 2 0 0 0 2.718-2.718l-5.42-9.807a1.5 1.5 0 0 0-1.626-.676"}]],X6=[["path",{d:"M6 2v14a2 2 0 0 0 2 2h14"}],["path",{d:"M18 22V8a2 2 0 0 0-2-2H2"}]],j6=[["path",{d:"M4 9a2 2 0 0 0-2 2v2a2 2 0 0 0 2 2h4a1 1 0 0 1 1 1v4a2 2 0 0 0 2 2h2a2 2 0 0 0 2-2v-4a1 1 0 0 1 1-1h4a2 2 0 0 0 2-2v-2a2 2 0 0 0-2-2h-4a1 1 0 0 1-1-1V4a2 2 0 0 0-2-2h-2a2 2 0 0 0-2 2v4a1 1 0 0 1-1 1z"}]],N6=[["circle",{cx:"12",cy:"12",r:"10"}],["line",{x1:"22",x2:"18",y1:"12",y2:"12"}],["line",{x1:"6",x2:"2",y1:"12",y2:"12"}],["line",{x1:"12",x2:"12",y1:"6",y2:"2"}],["line",{x1:"12",x2:"12",y1:"22",y2:"18"}]],K6=[["path",{d:"M11.562 3.266a.5.5 0 0 1 .876 0L15.39 8.87a1 1 0 0 0 1.516.294L21.183 5.5a.5.5 0 0 1 .798.519l-2.834 10.246a1 1 0 0 1-.956.734H5.81a1 1 0 0 1-.957-.734L2.02 6.02a.5.5 0 0 1 .798-.519l4.276 3.664a1 1 0 0 0 1.516-.294z"}],["path",{d:"M5 21h14"}]],Q6=[["path",{d:"m21.12 6.4-6.05-4.06a2 2 0 0 0-2.17-.05L2.95 8.41a2 2 0 0 0-.95 1.7v5.82a2 2 0 0 0 .88 1.66l6.05 4.07a2 2 0 0 0 2.17.05l9.95-6.12a2 2 0 0 0 .95-1.7V8.06a2 2 0 0 0-.88-1.66Z"}],["path",{d:"M10 22v-8L2.25 9.15"}],["path",{d:"m10 14 11.77-6.87"}]],J6=[["path",{d:"m6 8 1.75 12.28a2 2 0 0 0 2 1.72h4.54a2 2 0 0 0 2-1.72L18 8"}],["path",{d:"M5 8h14"}],["path",{d:"M7 15a6.47 6.47 0 0 1 5 0 6.47 6.47 0 0 0 5 0"}],["path",{d:"m12 8 1-6h2"}]],Y6=[["circle",{cx:"12",cy:"12",r:"8"}],["line",{x1:"3",x2:"6",y1:"3",y2:"6"}],["line",{x1:"21",x2:"18",y1:"3",y2:"6"}],["line",{x1:"3",x2:"6",y1:"21",y2:"18"}],["line",{x1:"21",x2:"18",y1:"21",y2:"18"}]],_6=[["ellipse",{cx:"12",cy:"5",rx:"9",ry:"3"}],["path",{d:"M3 5v14a9 3 0 0 0 18 0V5"}]],x6=[["path",{d:"M11 11.31c1.17.56 1.54 1.69 3.5 1.69 2.5 0 2.5-2 5-2 1.3 0 1.9.5 2.5 1"}],["path",{d:"M11.75 18c.35.5 1.45 1 2.75 1 2.5 0 2.5-2 5-2 1.3 0 1.9.5 2.5 1"}],["path",{d:"M2 10h4"}],["path",{d:"M2 14h4"}],["path",{d:"M2 18h4"}],["path",{d:"M2 6h4"}],["path",{d:"M7 3a1 1 0 0 0-1 1v16a1 1 0 0 0 1 1h4a1 1 0 0 0 1-1L10 4a1 1 0 0 0-1-1z"}]],a8=[["ellipse",{cx:"12",cy:"5",rx:"9",ry:"3"}],["path",{d:"M3 12a9 3 0 0 0 5 2.69"}],["path",{d:"M21 9.3V5"}],["path",{d:"M3 5v14a9 3 0 0 0 6.47 2.88"}],["path",{d:"M12 12v4h4"}],["path",{d:"M13 20a5 5 0 0 0 9-3 4.5 4.5 0 0 0-4.5-4.5c-1.33 0-2.54.54-3.41 1.41L12 16"}]],t8=[["ellipse",{cx:"12",cy:"5",rx:"9",ry:"3"}],["path",{d:"M3 5V19A9 3 0 0 0 15 21.84"}],["path",{d:"M21 5V8"}],["path",{d:"M21 12L18 17H22L19 22"}],["path",{d:"M3 12A9 3 0 0 0 14.59 14.87"}]],h8=[["ellipse",{cx:"12",cy:"5",rx:"9",ry:"3"}],["path",{d:"M3 5V19A9 3 0 0 0 21 19V5"}],["path",{d:"M3 12A9 3 0 0 0 21 12"}]],d8=[["path",{d:"m13 21-3-3 3-3"}],["path",{d:"M20 18H10"}],["path",{d:"M3 11h.01"}],["rect",{x:"6",y:"3",width:"5",height:"8",rx:"2.5"}]],c8=[["path",{d:"M10 18h10"}],["path",{d:"m17 21 3-3-3-3"}],["path",{d:"M3 11h.01"}],["rect",{x:"15",y:"3",width:"5",height:"8",rx:"2.5"}],["rect",{x:"6",y:"3",width:"5",height:"8",rx:"2.5"}]],M8=[["path",{d:"M10 5a2 2 0 0 0-1.344.519l-6.328 5.74a1 1 0 0 0 0 1.481l6.328 5.741A2 2 0 0 0 10 19h10a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2z"}],["path",{d:"m12 9 6 6"}],["path",{d:"m18 9-6 6"}]],p8=[["path",{d:"M10.162 3.167A10 10 0 0 0 2 13a2 2 0 0 0 4 0v-1a2 2 0 0 1 4 0v4a2 2 0 0 0 4 0v-4a2 2 0 0 1 4 0v1a2 2 0 0 0 4-.006 10 10 0 0 0-8.161-9.826"}],["path",{d:"M20.804 14.869a9 9 0 0 1-17.608 0"}],["circle",{cx:"12",cy:"4",r:"2"}]],i8=[["circle",{cx:"19",cy:"19",r:"2"}],["circle",{cx:"5",cy:"5",r:"2"}],["path",{d:"M6.48 3.66a10 10 0 0 1 13.86 13.86"}],["path",{d:"m6.41 6.41 11.18 11.18"}],["path",{d:"M3.66 6.48a10 10 0 0 0 13.86 13.86"}]],n8=[["path",{d:"M2.7 10.3a2.41 2.41 0 0 0 0 3.41l7.59 7.59a2.41 2.41 0 0 0 3.41 0l7.59-7.59a2.41 2.41 0 0 0 0-3.41L13.7 2.71a2.41 2.41 0 0 0-3.41 0z"}],["path",{d:"M8 12h8"}]],D1=[["path",{d:"M2.7 10.3a2.41 2.41 0 0 0 0 3.41l7.59 7.59a2.41 2.41 0 0 0 3.41 0l7.59-7.59a2.41 2.41 0 0 0 0-3.41L13.7 2.71a2.41 2.41 0 0 0-3.41 0Z"}],["path",{d:"M9.2 9.2h.01"}],["path",{d:"m14.5 9.5-5 5"}],["path",{d:"M14.7 14.8h.01"}]],l8=[["path",{d:"M12 8v8"}],["path",{d:"M2.7 10.3a2.41 2.41 0 0 0 0 3.41l7.59 7.59a2.41 2.41 0 0 0 3.41 0l7.59-7.59a2.41 2.41 0 0 0 0-3.41L13.7 2.71a2.41 2.41 0 0 0-3.41 0z"}],["path",{d:"M8 12h8"}]],e8=[["path",{d:"M2.7 10.3a2.41 2.41 0 0 0 0 3.41l7.59 7.59a2.41 2.41 0 0 0 3.41 0l7.59-7.59a2.41 2.41 0 0 0 0-3.41l-7.59-7.59a2.41 2.41 0 0 0-3.41 0Z"}]],r8=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["path",{d:"M12 12h.01"}]],o8=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["path",{d:"M15 9h.01"}],["path",{d:"M9 15h.01"}]],v8=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["path",{d:"M16 8h.01"}],["path",{d:"M12 12h.01"}],["path",{d:"M8 16h.01"}]],$8=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["path",{d:"M16 8h.01"}],["path",{d:"M8 8h.01"}],["path",{d:"M8 16h.01"}],["path",{d:"M16 16h.01"}]],m8=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["path",{d:"M16 8h.01"}],["path",{d:"M8 8h.01"}],["path",{d:"M8 16h.01"}],["path",{d:"M16 16h.01"}],["path",{d:"M12 12h.01"}]],y8=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["path",{d:"M16 8h.01"}],["path",{d:"M16 12h.01"}],["path",{d:"M16 16h.01"}],["path",{d:"M8 8h.01"}],["path",{d:"M8 12h.01"}],["path",{d:"M8 16h.01"}]],s8=[["rect",{width:"12",height:"12",x:"2",y:"10",rx:"2",ry:"2"}],["path",{d:"m17.92 14 3.5-3.5a2.24 2.24 0 0 0 0-3l-5-4.92a2.24 2.24 0 0 0-3 0L10 6"}],["path",{d:"M6 18h.01"}],["path",{d:"M10 14h.01"}],["path",{d:"M15 6h.01"}],["path",{d:"M18 9h.01"}]],g8=[["path",{d:"M12 3v14"}],["path",{d:"M5 10h14"}],["path",{d:"M5 21h14"}]],u8=[["circle",{cx:"12",cy:"12",r:"10"}],["circle",{cx:"12",cy:"12",r:"4"}],["path",{d:"M12 12h.01"}]],C8=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M6 12c0-1.7.7-3.2 1.8-4.2"}],["circle",{cx:"12",cy:"12",r:"2"}],["path",{d:"M18 12c0 1.7-.7 3.2-1.8 4.2"}]],H8=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["circle",{cx:"12",cy:"12",r:"5"}],["path",{d:"M12 12h.01"}]],A8=[["circle",{cx:"12",cy:"12",r:"10"}],["circle",{cx:"12",cy:"12",r:"2"}]],w8=[["circle",{cx:"12",cy:"6",r:"1"}],["line",{x1:"5",x2:"19",y1:"12",y2:"12"}],["circle",{cx:"12",cy:"18",r:"1"}]],V8=[["path",{d:"M15 2c-1.35 1.5-2.092 3-2.5 4.5L14 8"}],["path",{d:"m17 6-2.891-2.891"}],["path",{d:"M2 15c3.333-3 6.667-3 10-3"}],["path",{d:"m2 2 20 20"}],["path",{d:"m20 9 .891.891"}],["path",{d:"M22 9c-1.5 1.35-3 2.092-4.5 2.5l-1-1"}],["path",{d:"M3.109 14.109 4 15"}],["path",{d:"m6.5 12.5 1 1"}],["path",{d:"m7 18 2.891 2.891"}],["path",{d:"M9 22c1.35-1.5 2.092-3 2.5-4.5L10 16"}]],S8=[["path",{d:"m10 16 1.5 1.5"}],["path",{d:"m14 8-1.5-1.5"}],["path",{d:"M15 2c-1.798 1.998-2.518 3.995-2.807 5.993"}],["path",{d:"m16.5 10.5 1 1"}],["path",{d:"m17 6-2.891-2.891"}],["path",{d:"M2 15c6.667-6 13.333 0 20-6"}],["path",{d:"m20 9 .891.891"}],["path",{d:"M3.109 14.109 4 15"}],["path",{d:"m6.5 12.5 1 1"}],["path",{d:"m7 18 2.891 2.891"}],["path",{d:"M9 22c1.798-1.998 2.518-3.995 2.807-5.993"}]],L8=[["path",{d:"M2 8h20"}],["rect",{width:"20",height:"16",x:"2",y:"4",rx:"2"}],["path",{d:"M6 16h12"}]],f8=[["path",{d:"M11.25 16.25h1.5L12 17z"}],["path",{d:"M16 14v.5"}],["path",{d:"M4.42 11.247A13.152 13.152 0 0 0 4 14.556C4 18.728 7.582 21 12 21s8-2.272 8-6.444a11.702 11.702 0 0 0-.493-3.309"}],["path",{d:"M8 14v.5"}],["path",{d:"M8.5 8.5c-.384 1.05-1.083 2.028-2.344 2.5-1.931.722-3.576-.297-3.656-1-.113-.994 1.177-6.53 4-7 1.923-.321 3.651.845 3.651 2.235A7.497 7.497 0 0 1 14 5.277c0-1.39 1.844-2.598 3.767-2.277 2.823.47 4.113 6.006 4 7-.08.703-1.725 1.722-3.656 1-1.261-.472-1.855-1.45-2.239-2.5"}]],k8=[["line",{x1:"12",x2:"12",y1:"2",y2:"22"}],["path",{d:"M17 5H9.5a3.5 3.5 0 0 0 0 7h5a3.5 3.5 0 0 1 0 7H6"}]],P8=[["path",{d:"M20.5 10a2.5 2.5 0 0 1-2.4-3H18a2.95 2.95 0 0 1-2.6-4.4 10 10 0 1 0 6.3 7.1c-.3.2-.8.3-1.2.3"}],["circle",{cx:"12",cy:"12",r:"3"}]],B8=[["path",{d:"M10 12h.01"}],["path",{d:"M18 9V6a2 2 0 0 0-2-2H8a2 2 0 0 0-2 2v14"}],["path",{d:"M2 20h8"}],["path",{d:"M20 17v-2a2 2 0 1 0-4 0v2"}],["rect",{x:"14",y:"17",width:"8",height:"5",rx:"1"}]],D8=[["path",{d:"M10 12h.01"}],["path",{d:"M18 20V6a2 2 0 0 0-2-2H8a2 2 0 0 0-2 2v14"}],["path",{d:"M2 20h20"}]],F8=[["path",{d:"M11 20H2"}],["path",{d:"M11 4.562v16.157a1 1 0 0 0 1.242.97L19 20V5.562a2 2 0 0 0-1.515-1.94l-4-1A2 2 0 0 0 11 4.561z"}],["path",{d:"M11 4H8a2 2 0 0 0-2 2v14"}],["path",{d:"M14 12h.01"}],["path",{d:"M22 20h-3"}]],z8=[["circle",{cx:"12.1",cy:"12.1",r:"1"}]],b8=[["path",{d:"M12 15V3"}],["path",{d:"M21 15v4a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2v-4"}],["path",{d:"m7 10 5 5 5-5"}]],R8=[["path",{d:"m12.99 6.74 1.93 3.44"}],["path",{d:"M19.136 12a10 10 0 0 1-14.271 0"}],["path",{d:"m21 21-2.16-3.84"}],["path",{d:"m3 21 8.02-14.26"}],["circle",{cx:"12",cy:"5",r:"2"}]],T8=[["path",{d:"M10 11h.01"}],["path",{d:"M14 6h.01"}],["path",{d:"M18 6h.01"}],["path",{d:"M6.5 13.1h.01"}],["path",{d:"M22 5c0 9-4 12-6 12s-6-3-6-12c0-2 2-3 6-3s6 1 6 3"}],["path",{d:"M17.4 9.9c-.8.8-2 .8-2.8 0"}],["path",{d:"M10.1 7.1C9 7.2 7.7 7.7 6 8.6c-3.5 2-4.7 3.9-3.7 5.6 4.5 7.8 9.5 8.4 11.2 7.4.9-.5 1.9-2.1 1.9-4.7"}],["path",{d:"M9.1 16.5c.3-1.1 1.4-1.7 2.4-1.4"}]],q8=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M19.13 5.09C15.22 9.14 10 10.44 2.25 10.94"}],["path",{d:"M21.75 12.84c-6.62-1.41-12.14 1-16.38 6.32"}],["path",{d:"M8.56 2.75c4.37 6 6 9.42 8 17.72"}]],U8=[["path",{d:"M10 18a1 1 0 0 1 1 1v2a1 1 0 0 1-1 1H5a3 3 0 0 1-3-3 1 1 0 0 1 1-1z"}],["path",{d:"M13 10H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a1 1 0 0 1 1 1v6a1 1 0 0 1-1 1l-.81 3.242a1 1 0 0 1-.97.758H8"}],["path",{d:"M14 4h3a1 1 0 0 1 1 1v2a1 1 0 0 1-1 1h-3"}],["path",{d:"M18 6h4"}],["path",{d:"m5 10-2 8"}],["path",{d:"m7 18 2-8"}]],O8=[["path",{d:"M10 10 7 7"}],["path",{d:"m10 14-3 3"}],["path",{d:"m14 10 3-3"}],["path",{d:"m14 14 3 3"}],["path",{d:"M14.205 4.139a4 4 0 1 1 5.439 5.863"}],["path",{d:"M19.637 14a4 4 0 1 1-5.432 5.868"}],["path",{d:"M4.367 10a4 4 0 1 1 5.438-5.862"}],["path",{d:"M9.795 19.862a4 4 0 1 1-5.429-5.873"}],["rect",{x:"10",y:"8",width:"4",height:"8",rx:"1"}]],Z8=[["path",{d:"M18.715 13.186C18.29 11.858 17.384 10.607 16 9.5c-2-1.6-3.5-4-4-6.5a10.7 10.7 0 0 1-.884 2.586"}],["path",{d:"m2 2 20 20"}],["path",{d:"M8.795 8.797A11 11 0 0 1 8 9.5C6 11.1 5 13 5 15a7 7 0 0 0 13.222 3.208"}]],G8=[["path",{d:"M12 22a7 7 0 0 0 7-7c0-2-1-3.9-3-5.5s-3.5-4-4-6.5c-.5 2.5-2 4.9-4 6.5C6 11.1 5 13 5 15a7 7 0 0 0 7 7z"}]],I8=[["path",{d:"M7 16.3c2.2 0 4-1.83 4-4.05 0-1.16-.57-2.26-1.71-3.19S7.29 6.75 7 5.3c-.29 1.45-1.14 2.84-2.29 3.76S3 11.1 3 12.25c0 2.22 1.8 4.05 4 4.05z"}],["path",{d:"M12.56 6.6A10.97 10.97 0 0 0 14 3.02c.5 2.5 2 4.9 4 6.5s3 3.5 3 5.5a6.98 6.98 0 0 1-11.91 4.97"}]],W8=[["path",{d:"m2 2 8 8"}],["path",{d:"m22 2-8 8"}],["ellipse",{cx:"12",cy:"9",rx:"10",ry:"5"}],["path",{d:"M7 13.4v7.9"}],["path",{d:"M12 14v8"}],["path",{d:"M17 13.4v7.9"}],["path",{d:"M2 9v8a10 5 0 0 0 20 0V9"}]],E8=[["path",{d:"M15.4 15.63a7.875 6 135 1 1 6.23-6.23 4.5 3.43 135 0 0-6.23 6.23"}],["path",{d:"m8.29 12.71-2.6 2.6a2.5 2.5 0 1 0-1.65 4.65A2.5 2.5 0 1 0 8.7 18.3l2.59-2.59"}]],X8=[["path",{d:"M17.596 12.768a2 2 0 1 0 2.829-2.829l-1.768-1.767a2 2 0 0 0 2.828-2.829l-2.828-2.828a2 2 0 0 0-2.829 2.828l-1.767-1.768a2 2 0 1 0-2.829 2.829z"}],["path",{d:"m2.5 21.5 1.4-1.4"}],["path",{d:"m20.1 3.9 1.4-1.4"}],["path",{d:"M5.343 21.485a2 2 0 1 0 2.829-2.828l1.767 1.768a2 2 0 1 0 2.829-2.829l-6.364-6.364a2 2 0 1 0-2.829 2.829l1.768 1.767a2 2 0 0 0-2.828 2.829z"}],["path",{d:"m9.6 14.4 4.8-4.8"}]],j8=[["path",{d:"M6 8.5a6.5 6.5 0 1 1 13 0c0 6-6 6-6 10a3.5 3.5 0 1 1-7 0"}],["path",{d:"M15 8.5a2.5 2.5 0 0 0-5 0v1a2 2 0 1 1 0 4"}]],N8=[["path",{d:"M6 18.5a3.5 3.5 0 1 0 7 0c0-1.57.92-2.52 2.04-3.46"}],["path",{d:"M6 8.5c0-.75.13-1.47.36-2.14"}],["path",{d:"M8.8 3.15A6.5 6.5 0 0 1 19 8.5c0 1.63-.44 2.81-1.09 3.76"}],["path",{d:"M12.5 6A2.5 2.5 0 0 1 15 8.5M10 13a2 2 0 0 0 1.82-1.18"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],K8=[["path",{d:"M7 3.34V5a3 3 0 0 0 3 3"}],["path",{d:"M11 21.95V18a2 2 0 0 0-2-2 2 2 0 0 1-2-2v-1a2 2 0 0 0-2-2H2.05"}],["path",{d:"M21.54 15H17a2 2 0 0 0-2 2v4.54"}],["path",{d:"M12 2a10 10 0 1 0 9.54 13"}],["path",{d:"M20 6V4a2 2 0 1 0-4 0v2"}],["rect",{width:"8",height:"5",x:"14",y:"6",rx:"1"}]],F1=[["path",{d:"M21.54 15H17a2 2 0 0 0-2 2v4.54"}],["path",{d:"M7 3.34V5a3 3 0 0 0 3 3a2 2 0 0 1 2 2c0 1.1.9 2 2 2a2 2 0 0 0 2-2c0-1.1.9-2 2-2h3.17"}],["path",{d:"M11 21.95V18a2 2 0 0 0-2-2a2 2 0 0 1-2-2v-1a2 2 0 0 0-2-2H2.05"}],["circle",{cx:"12",cy:"12",r:"10"}]],Q8=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M12 2a7 7 0 1 0 10 10"}]],J8=[["circle",{cx:"11.5",cy:"12.5",r:"3.5"}],["path",{d:"M3 8c0-3.5 2.5-6 6.5-6 5 0 4.83 3 7.5 5s5 2 5 6c0 4.5-2.5 6.5-7 6.5-2.5 0-2.5 2.5-6 2.5s-7-2-7-5.5c0-3 1.5-3 1.5-5C3.5 10 3 9 3 8Z"}]],Y8=[["path",{d:"M12 2C8 2 4 8 4 14a8 8 0 0 0 16 0c0-6-4-12-8-12"}]],_8=[["path",{d:"m2 2 20 20"}],["path",{d:"M20 14.347V14c0-6-4-12-8-12-1.078 0-2.157.436-3.157 1.19"}],["path",{d:"M6.206 6.21C4.871 8.4 4 11.2 4 14a8 8 0 0 0 14.568 4.568"}]],z1=[["circle",{cx:"12",cy:"12",r:"1"}],["circle",{cx:"12",cy:"5",r:"1"}],["circle",{cx:"12",cy:"19",r:"1"}]],b1=[["circle",{cx:"12",cy:"12",r:"1"}],["circle",{cx:"19",cy:"12",r:"1"}],["circle",{cx:"5",cy:"12",r:"1"}]],x8=[["path",{d:"M5 15a6.5 6.5 0 0 1 7 0 6.5 6.5 0 0 0 7 0"}],["path",{d:"M5 9a6.5 6.5 0 0 1 7 0 6.5 6.5 0 0 0 7 0"}]],ac=[["line",{x1:"5",x2:"19",y1:"9",y2:"9"}],["line",{x1:"5",x2:"19",y1:"15",y2:"15"}],["line",{x1:"19",x2:"5",y1:"5",y2:"19"}]],tc=[["line",{x1:"5",x2:"19",y1:"9",y2:"9"}],["line",{x1:"5",x2:"19",y1:"15",y2:"15"}]],hc=[["path",{d:"m15 20 3-3h2a2 2 0 0 0 2-2V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v9a2 2 0 0 0 2 2h2l3 3z"}],["path",{d:"M6 8v1"}],["path",{d:"M10 8v1"}],["path",{d:"M14 8v1"}],["path",{d:"M18 8v1"}]],dc=[["path",{d:"M21 21H8a2 2 0 0 1-1.42-.587l-3.994-3.999a2 2 0 0 1 0-2.828l10-10a2 2 0 0 1 2.829 0l5.999 6a2 2 0 0 1 0 2.828L12.834 21"}],["path",{d:"m5.082 11.09 8.828 8.828"}]],cc=[["path",{d:"M4 10h12"}],["path",{d:"M4 14h9"}],["path",{d:"M19 6a7.7 7.7 0 0 0-5.2-2A7.9 7.9 0 0 0 6 12c0 4.4 3.5 8 7.8 8 2 0 3.8-.8 5.2-2"}]],Mc=[["path",{d:"M14 13h2a2 2 0 0 1 2 2v2a2 2 0 0 0 4 0v-6.998a2 2 0 0 0-.59-1.42L18 5"}],["path",{d:"M14 21V5a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v16"}],["path",{d:"M2 21h13"}],["path",{d:"M3 7h11"}],["path",{d:"m9 11-2 3h3l-2 3"}]],pc=[["path",{d:"m15 15 6 6"}],["path",{d:"m15 9 6-6"}],["path",{d:"M21 16v5h-5"}],["path",{d:"M21 8V3h-5"}],["path",{d:"M3 16v5h5"}],["path",{d:"m3 21 6-6"}],["path",{d:"M3 8V3h5"}],["path",{d:"M9 9 3 3"}]],ic=[["path",{d:"M15 3h6v6"}],["path",{d:"M10 14 21 3"}],["path",{d:"M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"}]],nc=[["path",{d:"m15 18-.722-3.25"}],["path",{d:"M2 8a10.645 10.645 0 0 0 20 0"}],["path",{d:"m20 15-1.726-2.05"}],["path",{d:"m4 15 1.726-2.05"}],["path",{d:"m9 18 .722-3.25"}]],lc=[["path",{d:"M10.733 5.076a10.744 10.744 0 0 1 11.205 6.575 1 1 0 0 1 0 .696 10.747 10.747 0 0 1-1.444 2.49"}],["path",{d:"M14.084 14.158a3 3 0 0 1-4.242-4.242"}],["path",{d:"M17.479 17.499a10.75 10.75 0 0 1-15.417-5.151 1 1 0 0 1 0-.696 10.75 10.75 0 0 1 4.446-5.143"}],["path",{d:"m2 2 20 20"}]],ec=[["path",{d:"M2.062 12.348a1 1 0 0 1 0-.696 10.75 10.75 0 0 1 19.876 0 1 1 0 0 1 0 .696 10.75 10.75 0 0 1-19.876 0"}],["circle",{cx:"12",cy:"12",r:"3"}]],rc=[["path",{d:"M18 2h-3a5 5 0 0 0-5 5v3H7v4h3v8h4v-8h3l1-4h-4V7a1 1 0 0 1 1-1h3z"}]],oc=[["path",{d:"M12 16h.01"}],["path",{d:"M16 16h.01"}],["path",{d:"M3 19a2 2 0 0 0 2 2h14a2 2 0 0 0 2-2V8.5a.5.5 0 0 0-.769-.422l-4.462 2.844A.5.5 0 0 1 15 10.5v-2a.5.5 0 0 0-.769-.422L9.77 10.922A.5.5 0 0 1 9 10.5V5a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2z"}],["path",{d:"M8 16h.01"}]],vc=[["path",{d:"M10.827 16.379a6.082 6.082 0 0 1-8.618-7.002l5.412 1.45a6.082 6.082 0 0 1 7.002-8.618l-1.45 5.412a6.082 6.082 0 0 1 8.618 7.002l-5.412-1.45a6.082 6.082 0 0 1-7.002 8.618l1.45-5.412Z"}],["path",{d:"M12 12v.01"}]],$c=[["path",{d:"M12 6a2 2 0 0 1 3.414-1.414l6 6a2 2 0 0 1 0 2.828l-6 6A2 2 0 0 1 12 18z"}],["path",{d:"M2 6a2 2 0 0 1 3.414-1.414l6 6a2 2 0 0 1 0 2.828l-6 6A2 2 0 0 1 2 18z"}]],mc=[["path",{d:"M12.67 19a2 2 0 0 0 1.416-.588l6.154-6.172a6 6 0 0 0-8.49-8.49L5.586 9.914A2 2 0 0 0 5 11.328V18a1 1 0 0 0 1 1z"}],["path",{d:"M16 8 2 22"}],["path",{d:"M17.5 15H9"}]],yc=[["path",{d:"M4 3 2 5v15c0 .6.4 1 1 1h2c.6 0 1-.4 1-1V5Z"}],["path",{d:"M6 8h4"}],["path",{d:"M6 18h4"}],["path",{d:"m12 3-2 2v15c0 .6.4 1 1 1h2c.6 0 1-.4 1-1V5Z"}],["path",{d:"M14 8h4"}],["path",{d:"M14 18h4"}],["path",{d:"m20 3-2 2v15c0 .6.4 1 1 1h2c.6 0 1-.4 1-1V5Z"}]],sc=[["circle",{cx:"12",cy:"12",r:"2"}],["path",{d:"M12 2v4"}],["path",{d:"m6.8 15-3.5 2"}],["path",{d:"m20.7 7-3.5 2"}],["path",{d:"M6.8 9 3.3 7"}],["path",{d:"m20.7 17-3.5-2"}],["path",{d:"m9 22 3-8 3 8"}],["path",{d:"M8 22h8"}],["path",{d:"M18 18.7a9 9 0 1 0-12 0"}]],gc=[["path",{d:"M5 5.5A3.5 3.5 0 0 1 8.5 2H12v7H8.5A3.5 3.5 0 0 1 5 5.5z"}],["path",{d:"M12 2h3.5a3.5 3.5 0 1 1 0 7H12V2z"}],["path",{d:"M12 12.5a3.5 3.5 0 1 1 7 0 3.5 3.5 0 1 1-7 0z"}],["path",{d:"M5 19.5A3.5 3.5 0 0 1 8.5 16H12v3.5a3.5 3.5 0 1 1-7 0z"}],["path",{d:"M5 12.5A3.5 3.5 0 0 1 8.5 9H12v7H8.5A3.5 3.5 0 0 1 5 12.5z"}]],uc=[["path",{d:"M10 12v-1"}],["path",{d:"M10 18v-2"}],["path",{d:"M10 7V6"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M15.5 22H18a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v16a2 2 0 0 0 .274 1.01"}],["circle",{cx:"10",cy:"20",r:"2"}]],Cc=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v2"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["circle",{cx:"3",cy:"17",r:"1"}],["path",{d:"M2 17v-3a4 4 0 0 1 8 0v3"}],["circle",{cx:"9",cy:"17",r:"1"}]],R1=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"m8 18 4-4"}],["path",{d:"M8 10v8h8"}]],Hc=[["path",{d:"M17.5 22h.5a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v3"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M2 19a2 2 0 1 1 4 0v1a2 2 0 1 1-4 0v-4a6 6 0 0 1 12 0v4a2 2 0 1 1-4 0v-1a2 2 0 1 1 4 0"}]],Ac=[["path",{d:"m13.69 12.479 1.29 4.88a.5.5 0 0 1-.697.591l-1.844-.849a1 1 0 0 0-.88.001l-1.846.85a.5.5 0 0 1-.693-.593l1.29-4.88"}],["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7z"}],["circle",{cx:"12",cy:"10",r:"3"}]],wc=[["path",{d:"M12 22h6a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v3.072"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"m6.69 16.479 1.29 4.88a.5.5 0 0 1-.698.591l-1.843-.849a1 1 0 0 0-.88.001l-1.846.85a.5.5 0 0 1-.693-.593l1.29-4.88"}],["circle",{cx:"5",cy:"14",r:"3"}]],Vc=[["path",{d:"M14.5 22H18a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M3 13.1a2 2 0 0 0-1 1.76v3.24a2 2 0 0 0 .97 1.78L6 21.7a2 2 0 0 0 2.03.01L11 19.9a2 2 0 0 0 1-1.76V14.9a2 2 0 0 0-.97-1.78L8 11.3a2 2 0 0 0-2.03-.01Z"}],["path",{d:"M7 17v5"}],["path",{d:"M11.7 14.2 7 17l-4.7-2.8"}]],T1=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M8 18v-2"}],["path",{d:"M12 18v-4"}],["path",{d:"M16 18v-6"}]],q1=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M8 18v-1"}],["path",{d:"M12 18v-6"}],["path",{d:"M16 18v-3"}]],U1=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"m16 13-3.5 3.5-2-2L8 17"}]],O1=[["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M16 22h2a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v3.5"}],["path",{d:"M4.017 11.512a6 6 0 1 0 8.466 8.475"}],["path",{d:"M9 16a1 1 0 0 1-1-1v-4c0-.552.45-1.008.995-.917a6 6 0 0 1 4.922 4.922c.091.544-.365.995-.917.995z"}]],Sc=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"m3 15 2 2 4-4"}]],Lc=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"m9 15 2 2 4-4"}]],fc=[["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M16 22h2a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v3"}],["path",{d:"M8 14v2.2l1.6 1"}],["circle",{cx:"8",cy:"16",r:"6"}]],kc=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"m5 12-3 3 3 3"}],["path",{d:"m9 18 3-3-3-3"}]],Pc=[["path",{d:"M10 12.5 8 15l2 2.5"}],["path",{d:"m14 12.5 2 2.5-2 2.5"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7z"}]],Z1=[["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"m2.305 15.53.923-.382"}],["path",{d:"m3.228 12.852-.924-.383"}],["path",{d:"M4.677 21.5a2 2 0 0 0 1.313.5H18a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v2.5"}],["path",{d:"m4.852 11.228-.383-.923"}],["path",{d:"m4.852 16.772-.383.924"}],["path",{d:"m7.148 11.228.383-.923"}],["path",{d:"m7.53 17.696-.382-.924"}],["path",{d:"m8.772 12.852.923-.383"}],["path",{d:"m8.772 15.148.923.383"}],["circle",{cx:"6",cy:"14",r:"3"}]],Bc=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M9 10h6"}],["path",{d:"M12 13V7"}],["path",{d:"M9 17h6"}]],Dc=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["rect",{width:"4",height:"6",x:"2",y:"12",rx:"2"}],["path",{d:"M10 12h2v6"}],["path",{d:"M10 18h4"}]],Fc=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M12 18v-6"}],["path",{d:"m9 15 3 3 3-3"}]],zc=[["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M2.62 13.8A2.25 2.25 0 1 1 6 10.836a2.25 2.25 0 1 1 3.38 2.966l-2.626 2.856a.998.998 0 0 1-1.507 0z"}],["path",{d:"M4 6.005V4a2 2 0 0 1 2-2h9l5 5v13a2 2 0 0 1-2 2H6a2 2 0 0 1-1.9-1.376"}]],bc=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["circle",{cx:"10",cy:"12",r:"2"}],["path",{d:"m20 17-1.296-1.296a2.41 2.41 0 0 0-3.408 0L9 22"}]],Rc=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M2 15h10"}],["path",{d:"m9 18 3-3-3-3"}]],Tc=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M4 12a1 1 0 0 0-1 1v1a1 1 0 0 1-1 1 1 1 0 0 1 1 1v1a1 1 0 0 0 1 1"}],["path",{d:"M8 18a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1 1 1 0 0 1-1-1v-1a1 1 0 0 0-1-1"}]],qc=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M10 12a1 1 0 0 0-1 1v1a1 1 0 0 1-1 1 1 1 0 0 1 1 1v1a1 1 0 0 0 1 1"}],["path",{d:"M14 18a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1 1 1 0 0 1-1-1v-1a1 1 0 0 0-1-1"}]],Uc=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v6"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["circle",{cx:"4",cy:"16",r:"2"}],["path",{d:"m10 10-4.5 4.5"}],["path",{d:"m9 11 1 1"}]],Oc=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["circle",{cx:"10",cy:"16",r:"2"}],["path",{d:"m16 10-4.5 4.5"}],["path",{d:"m15 11 1 1"}]],Zc=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v1"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["rect",{width:"8",height:"5",x:"2",y:"13",rx:"1"}],["path",{d:"M8 13v-2a2 2 0 1 0-4 0v2"}]],Gc=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["rect",{width:"8",height:"6",x:"8",y:"12",rx:"1"}],["path",{d:"M10 12v-2a2 2 0 1 1 4 0v2"}]],Ic=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M3 15h6"}]],Wc=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M9 15h6"}]],Ec=[["path",{d:"M10.5 22H18a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v8.4"}],["path",{d:"M8 18v-7.7L16 9v7"}],["circle",{cx:"14",cy:"16",r:"2"}],["circle",{cx:"6",cy:"18",r:"2"}]],Xc=[["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M4 7V4a2 2 0 0 1 2-2 2 2 0 0 0-2 2"}],["path",{d:"M4.063 20.999a2 2 0 0 0 2 1L18 22a2 2 0 0 0 2-2V7l-5-5H6"}],["path",{d:"m5 11-3 3"}],["path",{d:"m5 17-3-3h10"}]],G1=[["path",{d:"m18 5-2.414-2.414A2 2 0 0 0 14.172 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2"}],["path",{d:"M21.378 12.626a1 1 0 0 0-3.004-3.004l-4.01 4.012a2 2 0 0 0-.506.854l-.837 2.87a.5.5 0 0 0 .62.62l2.87-.837a2 2 0 0 0 .854-.506z"}],["path",{d:"M8 18h1"}]],I1=[["path",{d:"M12.5 22H18a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v9.5"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M13.378 15.626a1 1 0 1 0-3.004-3.004l-5.01 5.012a2 2 0 0 0-.506.854l-.837 2.87a.5.5 0 0 0 .62.62l2.87-.837a2 2 0 0 0 .854-.506z"}]],W1=[["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7z"}],["path",{d:"M15.033 13.44a.647.647 0 0 1 0 1.12l-4.065 2.352a.645.645 0 0 1-.968-.56v-4.704a.645.645 0 0 1 .967-.56z"}]],jc=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M3 15h6"}],["path",{d:"M6 12v6"}]],Nc=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M9 15h6"}],["path",{d:"M12 18v-6"}]],E1=[["path",{d:"M12 17h.01"}],["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7z"}],["path",{d:"M9.1 9a3 3 0 0 1 5.82 1c0 2-3 3-3 3"}]],Kc=[["path",{d:"M20 10V7l-5-5H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M16 14a2 2 0 0 0-2 2"}],["path",{d:"M20 14a2 2 0 0 1 2 2"}],["path",{d:"M20 22a2 2 0 0 0 2-2"}],["path",{d:"M16 22a2 2 0 0 1-2-2"}]],Qc=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["circle",{cx:"11.5",cy:"14.5",r:"2.5"}],["path",{d:"M13.3 16.3 15 18"}]],Jc=[["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M4.268 21a2 2 0 0 0 1.727 1H18a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v3"}],["path",{d:"m9 18-1.5-1.5"}],["circle",{cx:"5",cy:"14",r:"3"}]],Yc=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M8 12h8"}],["path",{d:"M10 11v2"}],["path",{d:"M8 17h8"}],["path",{d:"M14 16v2"}]],_c=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M8 13h2"}],["path",{d:"M14 13h2"}],["path",{d:"M8 17h2"}],["path",{d:"M14 17h2"}]],xc=[["path",{d:"M11 21a1 1 0 0 1-1 1H4a1 1 0 0 1-1-1v-8a1 1 0 0 1 1-1"}],["path",{d:"M16 16a1 1 0 0 1-1 1H9a1 1 0 0 1-1-1V8a1 1 0 0 1 1-1"}],["path",{d:"M21 6a2 2 0 0 0-.586-1.414l-2-2A2 2 0 0 0 17 2h-3a1 1 0 0 0-1 1v8a1 1 0 0 0 1 1h6a1 1 0 0 0 1-1z"}]],a7=[["path",{d:"m10 18 3-3-3-3"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M4 11V4a2 2 0 0 1 2-2h9l5 5v13a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2v-3a2 2 0 0 1 2-2h7"}]],t7=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"m8 16 2-2-2-2"}],["path",{d:"M12 18h4"}]],h7=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M10 9H8"}],["path",{d:"M16 13H8"}],["path",{d:"M16 17H8"}]],d7=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M2 13v-1h6v1"}],["path",{d:"M5 12v6"}],["path",{d:"M4 18h2"}]],c7=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M9 13v-1h6v1"}],["path",{d:"M12 12v6"}],["path",{d:"M11 18h2"}]],M7=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M12 12v6"}],["path",{d:"m15 15-3-3-3 3"}]],p7=[["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M15 18a3 3 0 1 0-6 0"}],["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7z"}],["circle",{cx:"12",cy:"13",r:"2"}]],X1=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["rect",{width:"8",height:"6",x:"2",y:"12",rx:"1"}],["path",{d:"m10 13.843 3.033-1.755a.645.645 0 0 1 .967.56v4.704a.645.645 0 0 1-.967.56L10 16.157"}]],i7=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M8 15h.01"}],["path",{d:"M11.5 13.5a2.5 2.5 0 0 1 0 3"}],["path",{d:"M15 12a5 5 0 0 1 0 6"}]],n7=[["path",{d:"M11 11a5 5 0 0 1 0 6"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M4 6.765V4a2 2 0 0 1 2-2h9l5 5v13a2 2 0 0 1-2 2H6a2 2 0 0 1-.93-.23"}],["path",{d:"M7 10.51a.5.5 0 0 0-.826-.38l-1.893 1.628A1 1 0 0 1 3.63 12H2.5a.5.5 0 0 0-.5.5v3a.5.5 0 0 0 .5.5h1.129a1 1 0 0 1 .652.242l1.893 1.63a.5.5 0 0 0 .826-.38z"}]],l7=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M12 9v4"}],["path",{d:"M12 17h.01"}]],e7=[["path",{d:"M4 22h14a2 2 0 0 0 2-2V7l-5-5H6a2 2 0 0 0-2 2v4"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"m8 12.5-5 5"}],["path",{d:"m3 12.5 5 5"}]],r7=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"m14.5 12.5-5 5"}],["path",{d:"m9.5 12.5 5 5"}]],o7=[["path",{d:"M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}]],v7=[["path",{d:"M15 2a2 2 0 0 1 1.414.586l4 4A2 2 0 0 1 21 8v7a2 2 0 0 1-2 2h-8a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2z"}],["path",{d:"M15 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M5 7a2 2 0 0 0-2 2v11a2 2 0 0 0 2 2h8a2 2 0 0 0 1.732-1"}]],$7=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M7 3v18"}],["path",{d:"M3 7.5h4"}],["path",{d:"M3 12h18"}],["path",{d:"M3 16.5h4"}],["path",{d:"M17 3v18"}],["path",{d:"M17 7.5h4"}],["path",{d:"M17 16.5h4"}]],m7=[["path",{d:"M15 6.5V3a1 1 0 0 0-1-1h-2a1 1 0 0 0-1 1v3.5"}],["path",{d:"M9 18h8"}],["path",{d:"M18 3h-3"}],["path",{d:"M11 3a6 6 0 0 0-6 6v11"}],["path",{d:"M5 13h4"}],["path",{d:"M17 10a4 4 0 0 0-8 0v10a2 2 0 0 0 2 2h4a2 2 0 0 0 2-2Z"}]],y7=[["path",{d:"M12 10a2 2 0 0 0-2 2c0 1.02-.1 2.51-.26 4"}],["path",{d:"M14 13.12c0 2.38 0 6.38-1 8.88"}],["path",{d:"M17.29 21.02c.12-.6.43-2.3.5-3.02"}],["path",{d:"M2 12a10 10 0 0 1 18-6"}],["path",{d:"M2 16h.01"}],["path",{d:"M21.8 16c.2-2 .131-5.354 0-6"}],["path",{d:"M5 19.5C5.5 18 6 15 6 12a6 6 0 0 1 .34-2"}],["path",{d:"M8.65 22c.21-.66.45-1.32.57-2"}],["path",{d:"M9 6.8a6 6 0 0 1 9 5.2v2"}]],s7=[["path",{d:"M18 12.47v.03m0-.5v.47m-.475 5.056A6.744 6.744 0 0 1 15 18c-3.56 0-7.56-2.53-8.5-6 .348-1.28 1.114-2.433 2.121-3.38m3.444-2.088A8.802 8.802 0 0 1 15 6c3.56 0 6.06 2.54 7 6-.309 1.14-.786 2.177-1.413 3.058"}],["path",{d:"M7 10.67C7 8 5.58 5.97 2.73 5.5c-1 1.5-1 5 .23 6.5-1.24 1.5-1.24 5-.23 6.5C5.58 18.03 7 16 7 13.33m7.48-4.372A9.77 9.77 0 0 1 16 6.07m0 11.86a9.77 9.77 0 0 1-1.728-3.618"}],["path",{d:"m16.01 17.93-.23 1.4A2 2 0 0 1 13.8 21H9.5a5.96 5.96 0 0 0 1.49-3.98M8.53 3h5.27a2 2 0 0 1 1.98 1.67l.23 1.4M2 2l20 20"}]],g7=[["path",{d:"M2 16s9-15 20-4C11 23 2 8 2 8"}]],u7=[["path",{d:"M6.5 12c.94-3.46 4.94-6 8.5-6 3.56 0 6.06 2.54 7 6-.94 3.47-3.44 6-7 6s-7.56-2.53-8.5-6Z"}],["path",{d:"M18 12v.5"}],["path",{d:"M16 17.93a9.77 9.77 0 0 1 0-11.86"}],["path",{d:"M7 10.67C7 8 5.58 5.97 2.73 5.5c-1 1.5-1 5 .23 6.5-1.24 1.5-1.24 5-.23 6.5C5.58 18.03 7 16 7 13.33"}],["path",{d:"M10.46 7.26C10.2 5.88 9.17 4.24 8 3h5.8a2 2 0 0 1 1.98 1.67l.23 1.4"}],["path",{d:"m16.01 17.93-.23 1.4A2 2 0 0 1 13.8 21H9.5a5.96 5.96 0 0 0 1.49-3.98"}]],C7=[["path",{d:"M16 16c-3 0-5-2-8-2a6 6 0 0 0-4 1.528"}],["path",{d:"m2 2 20 20"}],["path",{d:"M4 22V4"}],["path",{d:"M7.656 2H8c3 0 5 2 7.333 2q2 0 3.067-.8A1 1 0 0 1 20 4v10.347"}]],H7=[["path",{d:"M18 22V2.8a.8.8 0 0 0-1.17-.71L5.45 7.78a.8.8 0 0 0 0 1.44L18 15.5"}]],A7=[["path",{d:"M6 22V2.8a.8.8 0 0 1 1.17-.71l11.38 5.69a.8.8 0 0 1 0 1.44L6 15.5"}]],w7=[["path",{d:"M4 22V4a1 1 0 0 1 .4-.8A6 6 0 0 1 8 2c3 0 5 2 7.333 2q2 0 3.067-.8A1 1 0 0 1 20 4v10a1 1 0 0 1-.4.8A6 6 0 0 1 16 16c-3 0-5-2-8-2a6 6 0 0 0-4 1.528"}]],V7=[["path",{d:"M12 2c1 3 2.5 3.5 3.5 4.5A5 5 0 0 1 17 10a5 5 0 1 1-10 0c0-.3 0-.6.1-.9a2 2 0 1 0 3.3-2C8 4.5 11 2 12 2Z"}],["path",{d:"m5 22 14-4"}],["path",{d:"m5 18 14 4"}]],S7=[["path",{d:"M12 3q1 4 4 6.5t3 5.5a1 1 0 0 1-14 0 5 5 0 0 1 1-3 1 1 0 0 0 5 0c0-2-1.5-3-1.5-5q0-2 2.5-4"}]],L7=[["path",{d:"M16 16v4a2 2 0 0 1-2 2h-4a2 2 0 0 1-2-2V10c0-2-2-2-2-4"}],["path",{d:"M7 2h11v4c0 2-2 2-2 4v1"}],["line",{x1:"11",x2:"18",y1:"6",y2:"6"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],f7=[["path",{d:"M18 6c0 2-2 2-2 4v10a2 2 0 0 1-2 2h-4a2 2 0 0 1-2-2V10c0-2-2-2-2-4V2h12z"}],["line",{x1:"6",x2:"18",y1:"6",y2:"6"}],["line",{x1:"12",x2:"12",y1:"12",y2:"12"}]],k7=[["path",{d:"M10 2v2.343"}],["path",{d:"M14 2v6.343"}],["path",{d:"m2 2 20 20"}],["path",{d:"M20 20a2 2 0 0 1-2 2H6a2 2 0 0 1-1.755-2.96l5.227-9.563"}],["path",{d:"M6.453 15H15"}],["path",{d:"M8.5 2h7"}]],P7=[["path",{d:"M14 2v6a2 2 0 0 0 .245.96l5.51 10.08A2 2 0 0 1 18 22H6a2 2 0 0 1-1.755-2.96l5.51-10.08A2 2 0 0 0 10 8V2"}],["path",{d:"M6.453 15h11.094"}],["path",{d:"M8.5 2h7"}]],B7=[["path",{d:"M10 2v6.292a7 7 0 1 0 4 0V2"}],["path",{d:"M5 15h14"}],["path",{d:"M8.5 2h7"}]],D7=[["path",{d:"m3 7 5 5-5 5V7"}],["path",{d:"m21 7-5 5 5 5V7"}],["path",{d:"M12 20v2"}],["path",{d:"M12 14v2"}],["path",{d:"M12 8v2"}],["path",{d:"M12 2v2"}]],F7=[["path",{d:"M8 3H5a2 2 0 0 0-2 2v14c0 1.1.9 2 2 2h3"}],["path",{d:"M16 3h3a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2h-3"}],["path",{d:"M12 20v2"}],["path",{d:"M12 14v2"}],["path",{d:"M12 8v2"}],["path",{d:"M12 2v2"}]],z7=[["path",{d:"m17 3-5 5-5-5h10"}],["path",{d:"m17 21-5-5-5 5h10"}],["path",{d:"M4 12H2"}],["path",{d:"M10 12H8"}],["path",{d:"M16 12h-2"}],["path",{d:"M22 12h-2"}]],b7=[["path",{d:"M21 8V5a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v3"}],["path",{d:"M21 16v3a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2v-3"}],["path",{d:"M4 12H2"}],["path",{d:"M10 12H8"}],["path",{d:"M16 12h-2"}],["path",{d:"M22 12h-2"}]],R7=[["path",{d:"M12 5a3 3 0 1 1 3 3m-3-3a3 3 0 1 0-3 3m3-3v1M9 8a3 3 0 1 0 3 3M9 8h1m5 0a3 3 0 1 1-3 3m3-3h-1m-2 3v-1"}],["circle",{cx:"12",cy:"8",r:"2"}],["path",{d:"M12 10v12"}],["path",{d:"M12 22c4.2 0 7-1.667 7-5-4.2 0-7 1.667-7 5Z"}],["path",{d:"M12 22c-4.2 0-7-1.667-7-5 4.2 0 7 1.667 7 5Z"}]],T7=[["circle",{cx:"12",cy:"12",r:"3"}],["path",{d:"M12 16.5A4.5 4.5 0 1 1 7.5 12 4.5 4.5 0 1 1 12 7.5a4.5 4.5 0 1 1 4.5 4.5 4.5 4.5 0 1 1-4.5 4.5"}],["path",{d:"M12 7.5V9"}],["path",{d:"M7.5 12H9"}],["path",{d:"M16.5 12H15"}],["path",{d:"M12 16.5V15"}],["path",{d:"m8 8 1.88 1.88"}],["path",{d:"M14.12 9.88 16 8"}],["path",{d:"m8 16 1.88-1.88"}],["path",{d:"M14.12 14.12 16 16"}]],q7=[["circle",{cx:"12",cy:"12",r:"3"}],["path",{d:"M3 7V5a2 2 0 0 1 2-2h2"}],["path",{d:"M17 3h2a2 2 0 0 1 2 2v2"}],["path",{d:"M21 17v2a2 2 0 0 1-2 2h-2"}],["path",{d:"M7 21H5a2 2 0 0 1-2-2v-2"}]],U7=[["path",{d:"M2 12h6"}],["path",{d:"M22 12h-6"}],["path",{d:"M12 2v2"}],["path",{d:"M12 8v2"}],["path",{d:"M12 14v2"}],["path",{d:"M12 20v2"}],["path",{d:"m19 9-3 3 3 3"}],["path",{d:"m5 15 3-3-3-3"}]],O7=[["path",{d:"M12 22v-6"}],["path",{d:"M12 8V2"}],["path",{d:"M4 12H2"}],["path",{d:"M10 12H8"}],["path",{d:"M16 12h-2"}],["path",{d:"M22 12h-2"}],["path",{d:"m15 19-3-3-3 3"}],["path",{d:"m15 5-3 3-3-3"}]],Z7=[["path",{d:"M20 20a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2Z"}],["path",{d:"m9 13 2 2 4-4"}]],G7=[["circle",{cx:"15",cy:"19",r:"2"}],["path",{d:"M20.9 19.8A2 2 0 0 0 22 18V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2h5.1"}],["path",{d:"M15 11v-1"}],["path",{d:"M15 17v-2"}]],I7=[["path",{d:"M16 14v2.2l1.6 1"}],["path",{d:"M7 20H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h3.9a2 2 0 0 1 1.69.9l.81 1.2a2 2 0 0 0 1.67.9H20a2 2 0 0 1 2 2"}],["circle",{cx:"16",cy:"16",r:"6"}]],W7=[["path",{d:"M10 10.5 8 13l2 2.5"}],["path",{d:"m14 10.5 2 2.5-2 2.5"}],["path",{d:"M20 20a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2z"}]],E7=[["path",{d:"M20 20a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2Z"}],["path",{d:"M2 10h20"}]],j1=[["path",{d:"M10.3 20H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h3.98a2 2 0 0 1 1.69.9l.66 1.2A2 2 0 0 0 12 6h8a2 2 0 0 1 2 2v3.3"}],["path",{d:"m14.305 19.53.923-.382"}],["path",{d:"m15.228 16.852-.923-.383"}],["path",{d:"m16.852 15.228-.383-.923"}],["path",{d:"m16.852 20.772-.383.924"}],["path",{d:"m19.148 15.228.383-.923"}],["path",{d:"m19.53 21.696-.382-.924"}],["path",{d:"m20.772 16.852.924-.383"}],["path",{d:"m20.772 19.148.924.383"}],["circle",{cx:"18",cy:"18",r:"3"}]],X7=[["path",{d:"M4 20h16a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.93a2 2 0 0 1-1.66-.9l-.82-1.2A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13c0 1.1.9 2 2 2Z"}],["circle",{cx:"12",cy:"13",r:"1"}]],j7=[["path",{d:"M20 20a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2Z"}],["path",{d:"M12 10v6"}],["path",{d:"m15 13-3 3-3-3"}]],N7=[["path",{d:"M9 20H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h3.9a2 2 0 0 1 1.69.9l.81 1.2a2 2 0 0 0 1.67.9H20a2 2 0 0 1 2 2v5"}],["circle",{cx:"13",cy:"12",r:"2"}],["path",{d:"M18 19c-2.8 0-5-2.2-5-5v8"}],["circle",{cx:"20",cy:"19",r:"2"}]],K7=[["circle",{cx:"12",cy:"13",r:"2"}],["path",{d:"M20 20a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2Z"}],["path",{d:"M14 13h3"}],["path",{d:"M7 13h3"}]],Q7=[["path",{d:"M10.638 20H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h3.9a2 2 0 0 1 1.69.9l.81 1.2a2 2 0 0 0 1.67.9H20a2 2 0 0 1 2 2v3.417"}],["path",{d:"M14.62 18.8A2.25 2.25 0 1 1 18 15.836a2.25 2.25 0 1 1 3.38 2.966l-2.626 2.856a.998.998 0 0 1-1.507 0z"}]],J7=[["path",{d:"M2 9V5a2 2 0 0 1 2-2h3.9a2 2 0 0 1 1.69.9l.81 1.2a2 2 0 0 0 1.67.9H20a2 2 0 0 1 2 2v10a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2v-1"}],["path",{d:"M2 13h10"}],["path",{d:"m9 16 3-3-3-3"}]],Y7=[["circle",{cx:"16",cy:"20",r:"2"}],["path",{d:"M10 20H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h3.9a2 2 0 0 1 1.69.9l.81 1.2a2 2 0 0 0 1.67.9H20a2 2 0 0 1 2 2v2"}],["path",{d:"m22 14-4.5 4.5"}],["path",{d:"m21 15 1 1"}]],_7=[["path",{d:"M4 20h16a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.93a2 2 0 0 1-1.66-.9l-.82-1.2A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13c0 1.1.9 2 2 2Z"}],["path",{d:"M8 10v4"}],["path",{d:"M12 10v2"}],["path",{d:"M16 10v6"}]],x7=[["path",{d:"M9 13h6"}],["path",{d:"M20 20a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2Z"}]],aM=[["rect",{width:"8",height:"5",x:"14",y:"17",rx:"1"}],["path",{d:"M10 20H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h3.9a2 2 0 0 1 1.69.9l.81 1.2a2 2 0 0 0 1.67.9H20a2 2 0 0 1 2 2v2.5"}],["path",{d:"M20 17v-2a2 2 0 1 0-4 0v2"}]],tM=[["path",{d:"m6 14 1.45-2.9A2 2 0 0 1 9.24 10H20a2 2 0 0 1 1.94 2.5l-1.55 6a2 2 0 0 1-1.94 1.5H4a2 2 0 0 1-2-2V5c0-1.1.9-2 2-2h3.93a2 2 0 0 1 1.66.9l.82 1.2a2 2 0 0 0 1.66.9H18a2 2 0 0 1 2 2v2"}],["circle",{cx:"14",cy:"15",r:"1"}]],hM=[["path",{d:"m6 14 1.5-2.9A2 2 0 0 1 9.24 10H20a2 2 0 0 1 1.94 2.5l-1.54 6a2 2 0 0 1-1.95 1.5H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h3.9a2 2 0 0 1 1.69.9l.81 1.2a2 2 0 0 0 1.67.9H18a2 2 0 0 1 2 2v2"}]],dM=[["path",{d:"M2 7.5V5a2 2 0 0 1 2-2h3.9a2 2 0 0 1 1.69.9l.81 1.2a2 2 0 0 0 1.67.9H20a2 2 0 0 1 2 2v10a2 2 0 0 1-2 2H4a2 2 0 0 1-2-1.5"}],["path",{d:"M2 13h10"}],["path",{d:"m5 10-3 3 3 3"}]],N1=[["path",{d:"M2 11.5V5a2 2 0 0 1 2-2h3.9c.7 0 1.3.3 1.7.9l.8 1.2c.4.6 1 .9 1.7.9H20a2 2 0 0 1 2 2v10a2 2 0 0 1-2 2h-9.5"}],["path",{d:"M11.378 13.626a1 1 0 1 0-3.004-3.004l-5.01 5.012a2 2 0 0 0-.506.854l-.837 2.87a.5.5 0 0 0 .62.62l2.87-.837a2 2 0 0 0 .854-.506z"}]],cM=[["path",{d:"M12 10v6"}],["path",{d:"M9 13h6"}],["path",{d:"M20 20a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2Z"}]],MM=[["path",{d:"M4 20h16a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.93a2 2 0 0 1-1.66-.9l-.82-1.2A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13c0 1.1.9 2 2 2Z"}],["circle",{cx:"12",cy:"13",r:"2"}],["path",{d:"M12 15v5"}]],pM=[["circle",{cx:"11.5",cy:"12.5",r:"2.5"}],["path",{d:"M20 20a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2Z"}],["path",{d:"M13.3 14.3 15 16"}]],iM=[["path",{d:"M10.7 20H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h3.9a2 2 0 0 1 1.69.9l.81 1.2a2 2 0 0 0 1.67.9H20a2 2 0 0 1 2 2v4.1"}],["path",{d:"m21 21-1.9-1.9"}],["circle",{cx:"17",cy:"17",r:"3"}]],nM=[["path",{d:"M2 9.35V5a2 2 0 0 1 2-2h3.9a2 2 0 0 1 1.69.9l.81 1.2a2 2 0 0 0 1.67.9H20a2 2 0 0 1 2 2v10a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2v-3a2 2 0 0 1 2-2h7"}],["path",{d:"m8 16 3-3-3-3"}]],lM=[["path",{d:"M9 20H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h3.9a2 2 0 0 1 1.69.9l.81 1.2a2 2 0 0 0 1.67.9H20a2 2 0 0 1 2 2v.5"}],["path",{d:"M12 10v4h4"}],["path",{d:"m12 14 1.535-1.605a5 5 0 0 1 8 1.5"}],["path",{d:"M22 22v-4h-4"}],["path",{d:"m22 18-1.535 1.605a5 5 0 0 1-8-1.5"}]],eM=[["path",{d:"M20 10a1 1 0 0 0 1-1V6a1 1 0 0 0-1-1h-2.5a1 1 0 0 1-.8-.4l-.9-1.2A1 1 0 0 0 15 3h-2a1 1 0 0 0-1 1v5a1 1 0 0 0 1 1Z"}],["path",{d:"M20 21a1 1 0 0 0 1-1v-3a1 1 0 0 0-1-1h-2.9a1 1 0 0 1-.88-.55l-.42-.85a1 1 0 0 0-.92-.6H13a1 1 0 0 0-1 1v5a1 1 0 0 0 1 1Z"}],["path",{d:"M3 5a2 2 0 0 0 2 2h3"}],["path",{d:"M3 3v13a2 2 0 0 0 2 2h3"}]],rM=[["path",{d:"M20 20a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2Z"}],["path",{d:"M12 10v6"}],["path",{d:"m9 13 3-3 3 3"}]],oM=[["path",{d:"M20 20a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2Z"}],["path",{d:"m9.5 10.5 5 5"}],["path",{d:"m14.5 10.5-5 5"}]],vM=[["path",{d:"M20 20a2 2 0 0 0 2-2V8a2 2 0 0 0-2-2h-7.9a2 2 0 0 1-1.69-.9L9.6 3.9A2 2 0 0 0 7.93 3H4a2 2 0 0 0-2 2v13a2 2 0 0 0 2 2Z"}]],$M=[["path",{d:"M20 5a2 2 0 0 1 2 2v7a2 2 0 0 1-2 2H9a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h2.5a1.5 1.5 0 0 1 1.2.6l.6.8a1.5 1.5 0 0 0 1.2.6z"}],["path",{d:"M3 8.268a2 2 0 0 0-1 1.738V19a2 2 0 0 0 2 2h11a2 2 0 0 0 1.732-1"}]],mM=[["path",{d:"M4 16v-2.38C4 11.5 2.97 10.5 3 8c.03-2.72 1.49-6 4.5-6C9.37 2 10 3.8 10 5.5c0 3.11-2 5.66-2 8.68V16a2 2 0 1 1-4 0Z"}],["path",{d:"M20 20v-2.38c0-2.12 1.03-3.12 1-5.62-.03-2.72-1.49-6-4.5-6C14.63 6 14 7.8 14 9.5c0 3.11 2 5.66 2 8.68V20a2 2 0 1 0 4 0Z"}],["path",{d:"M16 17h4"}],["path",{d:"M4 13h4"}]],yM=[["path",{d:"M12 12H5a2 2 0 0 0-2 2v5"}],["circle",{cx:"13",cy:"19",r:"2"}],["circle",{cx:"5",cy:"19",r:"2"}],["path",{d:"M8 19h3m5-17v17h6M6 12V7c0-1.1.9-2 2-2h3l5 5"}]],sM=[["path",{d:"m15 17 5-5-5-5"}],["path",{d:"M4 18v-2a4 4 0 0 1 4-4h12"}]],gM=[["line",{x1:"22",x2:"2",y1:"6",y2:"6"}],["line",{x1:"22",x2:"2",y1:"18",y2:"18"}],["line",{x1:"6",x2:"6",y1:"2",y2:"22"}],["line",{x1:"18",x2:"18",y1:"2",y2:"22"}]],uM=[["path",{d:"M5 16V9h14V2H5l14 14h-7m-7 0 7 7v-7m-7 0h7"}]],CM=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M16 16s-1.5-2-4-2-4 2-4 2"}],["line",{x1:"9",x2:"9.01",y1:"9",y2:"9"}],["line",{x1:"15",x2:"15.01",y1:"9",y2:"9"}]],HM=[["path",{d:"M14 13h2a2 2 0 0 1 2 2v2a2 2 0 0 0 4 0v-6.998a2 2 0 0 0-.59-1.42L18 5"}],["path",{d:"M14 21V5a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v16"}],["path",{d:"M2 21h13"}],["path",{d:"M3 9h11"}]],AM=[["path",{d:"M3 7V5a2 2 0 0 1 2-2h2"}],["path",{d:"M17 3h2a2 2 0 0 1 2 2v2"}],["path",{d:"M21 17v2a2 2 0 0 1-2 2h-2"}],["path",{d:"M7 21H5a2 2 0 0 1-2-2v-2"}],["rect",{width:"10",height:"8",x:"7",y:"8",rx:"1"}]],wM=[["path",{d:"M13.354 3H3a1 1 0 0 0-.742 1.67l7.225 7.989A2 2 0 0 1 10 14v6a1 1 0 0 0 .553.895l2 1A1 1 0 0 0 14 21v-7a2 2 0 0 1 .517-1.341l1.218-1.348"}],["path",{d:"M16 6h6"}],["path",{d:"M19 3v6"}]],K1=[["path",{d:"M10 20a1 1 0 0 0 .553.895l2 1A1 1 0 0 0 14 21v-7a2 2 0 0 1 .517-1.341L21.74 4.67A1 1 0 0 0 21 3H3a1 1 0 0 0-.742 1.67l7.225 7.989A2 2 0 0 1 10 14z"}]],Q1=[["path",{d:"M12.531 3H3a1 1 0 0 0-.742 1.67l7.225 7.989A2 2 0 0 1 10 14v6a1 1 0 0 0 .553.895l2 1A1 1 0 0 0 14 21v-7a2 2 0 0 1 .517-1.341l.427-.473"}],["path",{d:"m16.5 3.5 5 5"}],["path",{d:"m21.5 3.5-5 5"}]],VM=[["path",{d:"M2 7v10"}],["path",{d:"M6 5v14"}],["rect",{width:"12",height:"18",x:"10",y:"3",rx:"2"}]],SM=[["path",{d:"M2 3v18"}],["rect",{width:"12",height:"18",x:"6",y:"3",rx:"2"}],["path",{d:"M22 3v18"}]],LM=[["rect",{width:"18",height:"14",x:"3",y:"3",rx:"2"}],["path",{d:"M4 21h1"}],["path",{d:"M9 21h1"}],["path",{d:"M14 21h1"}],["path",{d:"M19 21h1"}]],fM=[["path",{d:"M7 2h10"}],["path",{d:"M5 6h14"}],["rect",{width:"18",height:"12",x:"3",y:"10",rx:"2"}]],kM=[["path",{d:"M3 2h18"}],["rect",{width:"18",height:"12",x:"3",y:"6",rx:"2"}],["path",{d:"M3 22h18"}]],PM=[["line",{x1:"6",x2:"10",y1:"11",y2:"11"}],["line",{x1:"8",x2:"8",y1:"9",y2:"13"}],["line",{x1:"15",x2:"15.01",y1:"12",y2:"12"}],["line",{x1:"18",x2:"18.01",y1:"10",y2:"10"}],["path",{d:"M17.32 5H6.68a4 4 0 0 0-3.978 3.59c-.006.052-.01.101-.017.152C2.604 9.416 2 14.456 2 16a3 3 0 0 0 3 3c1 0 1.5-.5 2-1l1.414-1.414A2 2 0 0 1 9.828 16h4.344a2 2 0 0 1 1.414.586L17 18c.5.5 1 1 2 1a3 3 0 0 0 3-3c0-1.545-.604-6.584-.685-7.258-.007-.05-.011-.1-.017-.151A4 4 0 0 0 17.32 5z"}]],BM=[["line",{x1:"6",x2:"10",y1:"12",y2:"12"}],["line",{x1:"8",x2:"8",y1:"10",y2:"14"}],["line",{x1:"15",x2:"15.01",y1:"13",y2:"13"}],["line",{x1:"18",x2:"18.01",y1:"11",y2:"11"}],["rect",{width:"20",height:"12",x:"2",y:"6",rx:"2"}]],DM=[["path",{d:"m12 14 4-4"}],["path",{d:"M3.34 19a10 10 0 1 1 17.32 0"}]],FM=[["path",{d:"m14 13-8.381 8.38a1 1 0 0 1-3.001-3l8.384-8.381"}],["path",{d:"m16 16 6-6"}],["path",{d:"m21.5 10.5-8-8"}],["path",{d:"m8 8 6-6"}],["path",{d:"m8.5 7.5 8 8"}]],zM=[["path",{d:"M10.5 3 8 9l4 13 4-13-2.5-6"}],["path",{d:"M17 3a2 2 0 0 1 1.6.8l3 4a2 2 0 0 1 .013 2.382l-7.99 10.986a2 2 0 0 1-3.247 0l-7.99-10.986A2 2 0 0 1 2.4 7.8l2.998-3.997A2 2 0 0 1 7 3z"}],["path",{d:"M2 9h20"}]],bM=[["path",{d:"M11.5 21a7.5 7.5 0 1 1 7.35-9"}],["path",{d:"M13 12V3"}],["path",{d:"M4 21h16"}],["path",{d:"M9 12V3"}]],RM=[["rect",{x:"3",y:"8",width:"18",height:"4",rx:"1"}],["path",{d:"M12 8v13"}],["path",{d:"M19 12v7a2 2 0 0 1-2 2H7a2 2 0 0 1-2-2v-7"}],["path",{d:"M7.5 8a2.5 2.5 0 0 1 0-5A4.8 8 0 0 1 12 8a4.8 8 0 0 1 4.5-5 2.5 2.5 0 0 1 0 5"}]],TM=[["path",{d:"M6 3v12"}],["path",{d:"M18 9a3 3 0 1 0 0-6 3 3 0 0 0 0 6z"}],["path",{d:"M6 21a3 3 0 1 0 0-6 3 3 0 0 0 0 6z"}],["path",{d:"M15 6a9 9 0 0 0-9 9"}],["path",{d:"M18 15v6"}],["path",{d:"M21 18h-6"}]],qM=[["path",{d:"M9 10h.01"}],["path",{d:"M15 10h.01"}],["path",{d:"M12 2a8 8 0 0 0-8 8v12l3-3 2.5 2.5L12 19l2.5 2.5L17 19l3 3V10a8 8 0 0 0-8-8z"}]],UM=[["line",{x1:"6",x2:"6",y1:"3",y2:"15"}],["circle",{cx:"18",cy:"6",r:"3"}],["circle",{cx:"6",cy:"18",r:"3"}],["path",{d:"M18 9a9 9 0 0 1-9 9"}]],J1=[["circle",{cx:"12",cy:"12",r:"3"}],["line",{x1:"3",x2:"9",y1:"12",y2:"12"}],["line",{x1:"15",x2:"21",y1:"12",y2:"12"}]],OM=[["path",{d:"M12 3v6"}],["circle",{cx:"12",cy:"12",r:"3"}],["path",{d:"M12 15v6"}]],ZM=[["circle",{cx:"5",cy:"6",r:"3"}],["path",{d:"M12 6h5a2 2 0 0 1 2 2v7"}],["path",{d:"m15 9-3-3 3-3"}],["circle",{cx:"19",cy:"18",r:"3"}],["path",{d:"M12 18H7a2 2 0 0 1-2-2V9"}],["path",{d:"m9 15 3 3-3 3"}]],GM=[["circle",{cx:"18",cy:"18",r:"3"}],["circle",{cx:"6",cy:"6",r:"3"}],["path",{d:"M13 6h3a2 2 0 0 1 2 2v7"}],["path",{d:"M11 18H8a2 2 0 0 1-2-2V9"}]],IM=[["circle",{cx:"12",cy:"18",r:"3"}],["circle",{cx:"6",cy:"6",r:"3"}],["circle",{cx:"18",cy:"6",r:"3"}],["path",{d:"M18 9v2c0 .6-.4 1-1 1H7c-.6 0-1-.4-1-1V9"}],["path",{d:"M12 12v3"}]],WM=[["circle",{cx:"5",cy:"6",r:"3"}],["path",{d:"M5 9v6"}],["circle",{cx:"5",cy:"18",r:"3"}],["path",{d:"M12 3v18"}],["circle",{cx:"19",cy:"6",r:"3"}],["path",{d:"M16 15.7A9 9 0 0 0 19 9"}]],EM=[["circle",{cx:"18",cy:"18",r:"3"}],["circle",{cx:"6",cy:"6",r:"3"}],["path",{d:"M6 21V9a9 9 0 0 0 9 9"}]],XM=[["circle",{cx:"5",cy:"6",r:"3"}],["path",{d:"M5 9v12"}],["circle",{cx:"19",cy:"18",r:"3"}],["path",{d:"m15 9-3-3 3-3"}],["path",{d:"M12 6h5a2 2 0 0 1 2 2v7"}]],jM=[["circle",{cx:"6",cy:"6",r:"3"}],["path",{d:"M6 9v12"}],["path",{d:"m21 3-6 6"}],["path",{d:"m21 9-6-6"}],["path",{d:"M18 11.5V15"}],["circle",{cx:"18",cy:"18",r:"3"}]],NM=[["circle",{cx:"5",cy:"6",r:"3"}],["path",{d:"M5 9v12"}],["path",{d:"m15 9-3-3 3-3"}],["path",{d:"M12 6h5a2 2 0 0 1 2 2v3"}],["path",{d:"M19 15v6"}],["path",{d:"M22 18h-6"}]],KM=[["circle",{cx:"6",cy:"6",r:"3"}],["path",{d:"M6 9v12"}],["path",{d:"M13 6h3a2 2 0 0 1 2 2v3"}],["path",{d:"M18 15v6"}],["path",{d:"M21 18h-6"}]],QM=[["circle",{cx:"18",cy:"18",r:"3"}],["circle",{cx:"6",cy:"6",r:"3"}],["path",{d:"M18 6V5"}],["path",{d:"M18 11v-1"}],["line",{x1:"6",x2:"6",y1:"9",y2:"21"}]],JM=[["circle",{cx:"18",cy:"18",r:"3"}],["circle",{cx:"6",cy:"6",r:"3"}],["path",{d:"M13 6h3a2 2 0 0 1 2 2v7"}],["line",{x1:"6",x2:"6",y1:"9",y2:"21"}]],YM=[["path",{d:"M15 22v-4a4.8 4.8 0 0 0-1-3.5c3 0 6-2 6-5.5.08-1.25-.27-2.48-1-3.5.28-1.15.28-2.35 0-3.5 0 0-1 0-3 1.5-2.64-.5-5.36-.5-8 0C6 2 5 2 5 2c-.3 1.15-.3 2.35 0 3.5A5.403 5.403 0 0 0 4 9c0 3.5 3 5.5 6 5.5-.39.49-.68 1.05-.85 1.65-.17.6-.22 1.23-.15 1.85v4"}],["path",{d:"M9 18c-4.51 2-5-2-7-2"}]],_M=[["path",{d:"m22 13.29-3.33-10a.42.42 0 0 0-.14-.18.38.38 0 0 0-.22-.11.39.39 0 0 0-.23.07.42.42 0 0 0-.14.18l-2.26 6.67H8.32L6.1 3.26a.42.42 0 0 0-.1-.18.38.38 0 0 0-.26-.08.39.39 0 0 0-.23.07.42.42 0 0 0-.14.18L2 13.29a.74.74 0 0 0 .27.83L12 21l9.69-6.88a.71.71 0 0 0 .31-.83Z"}]],xM=[["path",{d:"M5.116 4.104A1 1 0 0 1 6.11 3h11.78a1 1 0 0 1 .994 1.105L17.19 20.21A2 2 0 0 1 15.2 22H8.8a2 2 0 0 1-2-1.79z"}],["path",{d:"M6 12a5 5 0 0 1 6 0 5 5 0 0 0 6 0"}]],a9=[["circle",{cx:"6",cy:"15",r:"4"}],["circle",{cx:"18",cy:"15",r:"4"}],["path",{d:"M14 15a2 2 0 0 0-2-2 2 2 0 0 0-2 2"}],["path",{d:"M2.5 13 5 7c.7-1.3 1.4-2 3-2"}],["path",{d:"M21.5 13 19 7c-.7-1.3-1.5-2-3-2"}]],t9=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M12 2a14.5 14.5 0 0 0 0 20 14.5 14.5 0 0 0 0-20"}],["path",{d:"M2 12h20"}]],h9=[["path",{d:"M15.686 15A14.5 14.5 0 0 1 12 22a14.5 14.5 0 0 1 0-20 10 10 0 1 0 9.542 13"}],["path",{d:"M2 12h8.5"}],["path",{d:"M20 6V4a2 2 0 1 0-4 0v2"}],["rect",{width:"8",height:"5",x:"14",y:"6",rx:"1"}]],d9=[["path",{d:"M12 13V2l8 4-8 4"}],["path",{d:"M20.561 10.222a9 9 0 1 1-12.55-5.29"}],["path",{d:"M8.002 9.997a5 5 0 1 0 8.9 2.02"}]],c9=[["path",{d:"M2 21V3"}],["path",{d:"M2 5h18a2 2 0 0 1 2 2v8a2 2 0 0 1-2 2H2.26"}],["path",{d:"M7 17v3a1 1 0 0 0 1 1h5a1 1 0 0 0 1-1v-3"}],["circle",{cx:"16",cy:"11",r:"2"}],["circle",{cx:"8",cy:"11",r:"2"}]],M9=[["path",{d:"M21.42 10.922a1 1 0 0 0-.019-1.838L12.83 5.18a2 2 0 0 0-1.66 0L2.6 9.08a1 1 0 0 0 0 1.832l8.57 3.908a2 2 0 0 0 1.66 0z"}],["path",{d:"M22 10v6"}],["path",{d:"M6 12.5V16a6 3 0 0 0 12 0v-3.5"}]],p9=[["path",{d:"M22 5V2l-5.89 5.89"}],["circle",{cx:"16.6",cy:"15.89",r:"3"}],["circle",{cx:"8.11",cy:"7.4",r:"3"}],["circle",{cx:"12.35",cy:"11.65",r:"3"}],["circle",{cx:"13.91",cy:"5.85",r:"3"}],["circle",{cx:"18.15",cy:"10.09",r:"3"}],["circle",{cx:"6.56",cy:"13.2",r:"3"}],["circle",{cx:"10.8",cy:"17.44",r:"3"}],["circle",{cx:"5",cy:"19",r:"3"}]],Y1=[["path",{d:"M12 3v17a1 1 0 0 1-1 1H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v6a1 1 0 0 1-1 1H3"}],["path",{d:"M16 19h6"}],["path",{d:"M19 22v-6"}]],_1=[["path",{d:"M12 3v17a1 1 0 0 1-1 1H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v6a1 1 0 0 1-1 1H3"}],["path",{d:"m16 19 2 2 4-4"}]],x1=[["path",{d:"M12 3v17a1 1 0 0 1-1 1H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v6a1 1 0 0 1-1 1H3"}],["path",{d:"m16 16 5 5"}],["path",{d:"m16 21 5-5"}]],i9=[["path",{d:"M15 3v18"}],["path",{d:"M3 12h18"}],["path",{d:"M9 3v18"}],["rect",{x:"3",y:"3",width:"18",height:"18",rx:"2"}]],a2=[["path",{d:"M12 3v18"}],["path",{d:"M3 12h18"}],["rect",{x:"3",y:"3",width:"18",height:"18",rx:"2"}]],r=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 9h18"}],["path",{d:"M3 15h18"}],["path",{d:"M9 3v18"}],["path",{d:"M15 3v18"}]],n9=[["circle",{cx:"12",cy:"9",r:"1"}],["circle",{cx:"19",cy:"9",r:"1"}],["circle",{cx:"5",cy:"9",r:"1"}],["circle",{cx:"12",cy:"15",r:"1"}],["circle",{cx:"19",cy:"15",r:"1"}],["circle",{cx:"5",cy:"15",r:"1"}]],l9=[["circle",{cx:"9",cy:"12",r:"1"}],["circle",{cx:"9",cy:"5",r:"1"}],["circle",{cx:"9",cy:"19",r:"1"}],["circle",{cx:"15",cy:"12",r:"1"}],["circle",{cx:"15",cy:"5",r:"1"}],["circle",{cx:"15",cy:"19",r:"1"}]],e9=[["circle",{cx:"12",cy:"5",r:"1"}],["circle",{cx:"19",cy:"5",r:"1"}],["circle",{cx:"5",cy:"5",r:"1"}],["circle",{cx:"12",cy:"12",r:"1"}],["circle",{cx:"19",cy:"12",r:"1"}],["circle",{cx:"5",cy:"12",r:"1"}],["circle",{cx:"12",cy:"19",r:"1"}],["circle",{cx:"19",cy:"19",r:"1"}],["circle",{cx:"5",cy:"19",r:"1"}]],r9=[["path",{d:"M3 7V5c0-1.1.9-2 2-2h2"}],["path",{d:"M17 3h2c1.1 0 2 .9 2 2v2"}],["path",{d:"M21 17v2c0 1.1-.9 2-2 2h-2"}],["path",{d:"M7 21H5c-1.1 0-2-.9-2-2v-2"}],["rect",{width:"7",height:"5",x:"7",y:"7",rx:"1"}],["rect",{width:"7",height:"5",x:"10",y:"12",rx:"1"}]],o9=[["path",{d:"M13.144 21.144A7.274 10.445 45 1 0 2.856 10.856"}],["path",{d:"M13.144 21.144A7.274 4.365 45 0 0 2.856 10.856a7.274 4.365 45 0 0 10.288 10.288"}],["path",{d:"M16.565 10.435 18.6 8.4a2.501 2.501 0 1 0 1.65-4.65 2.5 2.5 0 1 0-4.66 1.66l-2.024 2.025"}],["path",{d:"m8.5 16.5-1-1"}]],v9=[["path",{d:"m11.9 12.1 4.514-4.514"}],["path",{d:"M20.1 2.3a1 1 0 0 0-1.4 0l-1.114 1.114A2 2 0 0 0 17 4.828v1.344a2 2 0 0 1-.586 1.414A2 2 0 0 1 17.828 7h1.344a2 2 0 0 0 1.414-.586L21.7 5.3a1 1 0 0 0 0-1.4z"}],["path",{d:"m6 16 2 2"}],["path",{d:"M8.23 9.85A3 3 0 0 1 11 8a5 5 0 0 1 5 5 3 3 0 0 1-1.85 2.77l-.92.38A2 2 0 0 0 12 18a4 4 0 0 1-4 4 6 6 0 0 1-6-6 4 4 0 0 1 4-4 2 2 0 0 0 1.85-1.23z"}]],$9=[["path",{d:"M12 16H4a2 2 0 1 1 0-4h16a2 2 0 1 1 0 4h-4.25"}],["path",{d:"M5 12a2 2 0 0 1-2-2 9 7 0 0 1 18 0 2 2 0 0 1-2 2"}],["path",{d:"M5 16a2 2 0 0 0-2 2 3 3 0 0 0 3 3h12a3 3 0 0 0 3-3 2 2 0 0 0-2-2q0 0 0 0"}],["path",{d:"m6.67 12 6.13 4.6a2 2 0 0 0 2.8-.4l3.15-4.2"}]],m9=[["path",{d:"m15 12-9.373 9.373a1 1 0 0 1-3.001-3L12 9"}],["path",{d:"m18 15 4-4"}],["path",{d:"m21.5 11.5-1.914-1.914A2 2 0 0 1 19 8.172v-.344a2 2 0 0 0-.586-1.414l-1.657-1.657A6 6 0 0 0 12.516 3H9l1.243 1.243A6 6 0 0 1 12 8.485V10l2 2h1.172a2 2 0 0 1 1.414.586L18.5 14.5"}]],y9=[["path",{d:"M11 15h2a2 2 0 1 0 0-4h-3c-.6 0-1.1.2-1.4.6L3 17"}],["path",{d:"m7 21 1.6-1.4c.3-.4.8-.6 1.4-.6h4c1.1 0 2.1-.4 2.8-1.2l4.6-4.4a2 2 0 0 0-2.75-2.91l-4.2 3.9"}],["path",{d:"m2 16 6 6"}],["circle",{cx:"16",cy:"9",r:"2.9"}],["circle",{cx:"6",cy:"5",r:"3"}]],s9=[["path",{d:"M12.035 17.012a3 3 0 0 0-3-3l-.311-.002a.72.72 0 0 1-.505-1.229l1.195-1.195A2 2 0 0 1 10.828 11H12a2 2 0 0 0 0-4H9.243a3 3 0 0 0-2.122.879l-2.707 2.707A4.83 4.83 0 0 0 3 14a8 8 0 0 0 8 8h2a8 8 0 0 0 8-8V7a2 2 0 1 0-4 0v2a2 2 0 1 0 4 0"}],["path",{d:"M13.888 9.662A2 2 0 0 0 17 8V5A2 2 0 1 0 13 5"}],["path",{d:"M9 5A2 2 0 1 0 5 5V10"}],["path",{d:"M9 7V4A2 2 0 1 1 13 4V7.268"}]],t2=[["path",{d:"M18 11.5V9a2 2 0 0 0-2-2a2 2 0 0 0-2 2v1.4"}],["path",{d:"M14 10V8a2 2 0 0 0-2-2a2 2 0 0 0-2 2v2"}],["path",{d:"M10 9.9V9a2 2 0 0 0-2-2a2 2 0 0 0-2 2v5"}],["path",{d:"M6 14a2 2 0 0 0-2-2a2 2 0 0 0-2 2"}],["path",{d:"M18 11a2 2 0 1 1 4 0v3a8 8 0 0 1-8 8h-4a8 8 0 0 1-8-8 2 2 0 1 1 4 0"}]],h2=[["path",{d:"M11 12h2a2 2 0 1 0 0-4h-3c-.6 0-1.1.2-1.4.6L3 14"}],["path",{d:"m7 18 1.6-1.4c.3-.4.8-.6 1.4-.6h4c1.1 0 2.1-.4 2.8-1.2l4.6-4.4a2 2 0 0 0-2.75-2.91l-4.2 3.9"}],["path",{d:"m2 13 6 6"}]],g9=[["path",{d:"M11 14h2a2 2 0 0 0 0-4h-3c-.6 0-1.1.2-1.4.6L3 16"}],["path",{d:"m14.45 13.39 5.05-4.694C20.196 8 21 6.85 21 5.75a2.75 2.75 0 0 0-4.797-1.837.276.276 0 0 1-.406 0A2.75 2.75 0 0 0 11 5.75c0 1.2.802 2.248 1.5 2.946L16 11.95"}],["path",{d:"m2 15 6 6"}],["path",{d:"m7 20 1.6-1.4c.3-.4.8-.6 1.4-.6h4c1.1 0 2.1-.4 2.8-1.2l4.6-4.4a1 1 0 0 0-2.75-2.91"}]],u9=[["path",{d:"M18 12.5V10a2 2 0 0 0-2-2a2 2 0 0 0-2 2v1.4"}],["path",{d:"M14 11V9a2 2 0 1 0-4 0v2"}],["path",{d:"M10 10.5V5a2 2 0 1 0-4 0v9"}],["path",{d:"m7 15-1.76-1.76a2 2 0 0 0-2.83 2.82l3.6 3.6C7.5 21.14 9.2 22 12 22h2a8 8 0 0 0 8-8V7a2 2 0 1 0-4 0v5"}]],C9=[["path",{d:"M12 3V2"}],["path",{d:"m15.4 17.4 3.2-2.8a2 2 0 1 1 2.8 2.9l-3.6 3.3c-.7.8-1.7 1.2-2.8 1.2h-4c-1.1 0-2.1-.4-2.8-1.2l-1.302-1.464A1 1 0 0 0 6.151 19H5"}],["path",{d:"M2 14h12a2 2 0 0 1 0 4h-2"}],["path",{d:"M4 10h16"}],["path",{d:"M5 10a7 7 0 0 1 14 0"}],["path",{d:"M5 14v6a1 1 0 0 1-1 1H2"}]],H9=[["path",{d:"M2.048 18.566A2 2 0 0 0 4 21h16a2 2 0 0 0 1.952-2.434l-2-9A2 2 0 0 0 18 8H6a2 2 0 0 0-1.952 1.566z"}],["path",{d:"M8 11V6a4 4 0 0 1 8 0v5"}]],A9=[["path",{d:"M18 11V6a2 2 0 0 0-2-2a2 2 0 0 0-2 2"}],["path",{d:"M14 10V4a2 2 0 0 0-2-2a2 2 0 0 0-2 2v2"}],["path",{d:"M10 10.5V6a2 2 0 0 0-2-2a2 2 0 0 0-2 2v8"}],["path",{d:"M18 8a2 2 0 1 1 4 0v6a8 8 0 0 1-8 8h-2c-2.8 0-4.5-.86-5.99-2.34l-3.6-3.6a2 2 0 0 1 2.83-2.82L7 15"}]],w9=[["path",{d:"m11 17 2 2a1 1 0 1 0 3-3"}],["path",{d:"m14 14 2.5 2.5a1 1 0 1 0 3-3l-3.88-3.88a3 3 0 0 0-4.24 0l-.88.88a1 1 0 1 1-3-3l2.81-2.81a5.79 5.79 0 0 1 7.06-.87l.47.28a2 2 0 0 0 1.42.25L21 4"}],["path",{d:"m21 3 1 11h-2"}],["path",{d:"M3 3 2 14l6.5 6.5a1 1 0 1 0 3-3"}],["path",{d:"M3 4h8"}]],V9=[["path",{d:"M12 2v8"}],["path",{d:"m16 6-4 4-4-4"}],["rect",{width:"20",height:"8",x:"2",y:"14",rx:"2"}],["path",{d:"M6 18h.01"}],["path",{d:"M10 18h.01"}]],S9=[["path",{d:"m16 6-4-4-4 4"}],["path",{d:"M12 2v8"}],["rect",{width:"20",height:"8",x:"2",y:"14",rx:"2"}],["path",{d:"M6 18h.01"}],["path",{d:"M10 18h.01"}]],L9=[["path",{d:"M10 10V5a1 1 0 0 1 1-1h2a1 1 0 0 1 1 1v5"}],["path",{d:"M14 6a6 6 0 0 1 6 6v3"}],["path",{d:"M4 15v-3a6 6 0 0 1 6-6"}],["rect",{x:"2",y:"15",width:"20",height:"4",rx:"1"}]],f9=[["line",{x1:"22",x2:"2",y1:"12",y2:"12"}],["path",{d:"M5.45 5.11 2 12v6a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-6l-3.45-6.89A2 2 0 0 0 16.76 4H7.24a2 2 0 0 0-1.79 1.11z"}],["line",{x1:"6",x2:"6.01",y1:"16",y2:"16"}],["line",{x1:"10",x2:"10.01",y1:"16",y2:"16"}]],k9=[["line",{x1:"4",x2:"20",y1:"9",y2:"9"}],["line",{x1:"4",x2:"20",y1:"15",y2:"15"}],["line",{x1:"10",x2:"8",y1:"3",y2:"21"}],["line",{x1:"16",x2:"14",y1:"3",y2:"21"}]],P9=[["path",{d:"M14 18a2 2 0 0 0-4 0"}],["path",{d:"m19 11-2.11-6.657a2 2 0 0 0-2.752-1.148l-1.276.61A2 2 0 0 1 12 4H8.5a2 2 0 0 0-1.925 1.456L5 11"}],["path",{d:"M2 11h20"}],["circle",{cx:"17",cy:"18",r:"3"}],["circle",{cx:"7",cy:"18",r:"3"}]],B9=[["path",{d:"M22 9a1 1 0 0 0-1-1H3a1 1 0 0 0-1 1v4a1 1 0 0 0 1 1h1l2 2h12l2-2h1a1 1 0 0 0 1-1Z"}],["path",{d:"M7.5 12h9"}]],D9=[["path",{d:"m5.2 6.2 1.4 1.4"}],["path",{d:"M2 13h2"}],["path",{d:"M20 13h2"}],["path",{d:"m17.4 7.6 1.4-1.4"}],["path",{d:"M22 17H2"}],["path",{d:"M22 21H2"}],["path",{d:"M16 13a4 4 0 0 0-8 0"}],["path",{d:"M12 5V2.5"}]],F9=[["path",{d:"M4 12h8"}],["path",{d:"M4 18V6"}],["path",{d:"M12 18V6"}],["path",{d:"m17 12 3-2v8"}]],z9=[["path",{d:"M4 12h8"}],["path",{d:"M4 18V6"}],["path",{d:"M12 18V6"}],["path",{d:"M21 18h-4c0-4 4-3 4-6 0-1.5-2-2.5-4-1"}]],b9=[["path",{d:"M12 18V6"}],["path",{d:"M17 10v3a1 1 0 0 0 1 1h3"}],["path",{d:"M21 10v8"}],["path",{d:"M4 12h8"}],["path",{d:"M4 18V6"}]],R9=[["path",{d:"M4 12h8"}],["path",{d:"M4 18V6"}],["path",{d:"M12 18V6"}],["path",{d:"M17.5 10.5c1.7-1 3.5 0 3.5 1.5a2 2 0 0 1-2 2"}],["path",{d:"M17 17.5c2 1.5 4 .3 4-1.5a2 2 0 0 0-2-2"}]],T9=[["path",{d:"M4 12h8"}],["path",{d:"M4 18V6"}],["path",{d:"M12 18V6"}],["path",{d:"M17 13v-3h4"}],["path",{d:"M17 17.7c.4.2.8.3 1.3.3 1.5 0 2.7-1.1 2.7-2.5S19.8 13 18.3 13H17"}]],q9=[["path",{d:"M4 12h8"}],["path",{d:"M4 18V6"}],["path",{d:"M12 18V6"}],["circle",{cx:"19",cy:"16",r:"2"}],["path",{d:"M20 10c-2 2-3 3.5-3 6"}]],U9=[["path",{d:"M6 12h12"}],["path",{d:"M6 20V4"}],["path",{d:"M18 20V4"}]],O9=[["path",{d:"M21 14h-1.343"}],["path",{d:"M9.128 3.47A9 9 0 0 1 21 12v3.343"}],["path",{d:"m2 2 20 20"}],["path",{d:"M20.414 20.414A2 2 0 0 1 19 21h-1a2 2 0 0 1-2-2v-3"}],["path",{d:"M3 14h3a2 2 0 0 1 2 2v3a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2v-7a9 9 0 0 1 2.636-6.364"}]],Z9=[["path",{d:"M3 14h3a2 2 0 0 1 2 2v3a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2v-7a9 9 0 0 1 18 0v7a2 2 0 0 1-2 2h-1a2 2 0 0 1-2-2v-3a2 2 0 0 1 2-2h3"}]],G9=[["path",{d:"M3 11h3a2 2 0 0 1 2 2v3a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2v-5Zm0 0a9 9 0 1 1 18 0m0 0v5a2 2 0 0 1-2 2h-1a2 2 0 0 1-2-2v-3a2 2 0 0 1 2-2h3Z"}],["path",{d:"M21 16v2a4 4 0 0 1-4 4h-5"}]],I9=[["path",{d:"M12.409 5.824c-.702.792-1.15 1.496-1.415 2.166l2.153 2.156a.5.5 0 0 1 0 .707l-2.293 2.293a.5.5 0 0 0 0 .707L12 15"}],["path",{d:"M13.508 20.313a2 2 0 0 1-3 .019L5 15c-1.5-1.5-3-3.2-3-5.5a5.5 5.5 0 0 1 9.591-3.677.6.6 0 0 0 .818.001A5.5 5.5 0 0 1 22 9.5c0 2.29-1.5 4-3 5.5z"}]],W9=[["path",{d:"M19.414 14.414C21 12.828 22 11.5 22 9.5a5.5 5.5 0 0 0-9.591-3.676.6.6 0 0 1-.818.001A5.5 5.5 0 0 0 2 9.5c0 2.3 1.5 4 3 5.5l5.535 5.362a2 2 0 0 0 2.879.052 2.12 2.12 0 0 0-.004-3 2.124 2.124 0 1 0 3-3 2.124 2.124 0 0 0 3.004 0 2 2 0 0 0 0-2.828l-1.881-1.882a2.41 2.41 0 0 0-3.409 0l-1.71 1.71a2 2 0 0 1-2.828 0 2 2 0 0 1 0-2.828l2.823-2.762"}]],E9=[["path",{d:"m14.876 18.99-1.368 1.323a2 2 0 0 1-3 .019L5 15c-1.5-1.5-3-3.2-3-5.5a5.5 5.5 0 0 1 9.591-3.676.56.56 0 0 0 .818 0A5.49 5.49 0 0 1 22 9.5a5.2 5.2 0 0 1-.244 1.572"}],["path",{d:"M15 15h6"}]],X9=[["path",{d:"M10.5 4.893a5.5 5.5 0 0 1 1.091.931.56.56 0 0 0 .818 0A5.49 5.49 0 0 1 22 9.5c0 1.872-1.002 3.356-2.187 4.655"}],["path",{d:"m16.967 16.967-3.459 3.346a2 2 0 0 1-3 .019L5 15c-1.5-1.5-3-3.2-3-5.5a5.5 5.5 0 0 1 2.747-4.761"}],["path",{d:"m2 2 20 20"}]],j9=[["path",{d:"m14.479 19.374-.971.939a2 2 0 0 1-3 .019L5 15c-1.5-1.5-3-3.2-3-5.5a5.5 5.5 0 0 1 9.591-3.676.56.56 0 0 0 .818 0A5.49 5.49 0 0 1 22 9.5a5.2 5.2 0 0 1-.219 1.49"}],["path",{d:"M15 15h6"}],["path",{d:"M18 12v6"}]],N9=[["path",{d:"M2 9.5a5.5 5.5 0 0 1 9.591-3.676.56.56 0 0 0 .818 0A5.49 5.49 0 0 1 22 9.5c0 2.29-1.5 4-3 5.5l-5.492 5.313a2 2 0 0 1-3 .019L5 15c-1.5-1.5-3-3.2-3-5.5"}],["path",{d:"M3.22 13H9.5l.5-1 2 4.5 2-7 1.5 3.5h5.27"}]],K9=[["path",{d:"M2 9.5a5.5 5.5 0 0 1 9.591-3.676.56.56 0 0 0 .818 0A5.49 5.49 0 0 1 22 9.5c0 2.29-1.5 4-3 5.5l-5.492 5.313a2 2 0 0 1-3 .019L5 15c-1.5-1.5-3-3.2-3-5.5"}]],Q9=[["path",{d:"M11 8c2-3-2-3 0-6"}],["path",{d:"M15.5 8c2-3-2-3 0-6"}],["path",{d:"M6 10h.01"}],["path",{d:"M6 14h.01"}],["path",{d:"M10 16v-4"}],["path",{d:"M14 16v-4"}],["path",{d:"M18 16v-4"}],["path",{d:"M20 6a2 2 0 0 1 2 2v10a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h3"}],["path",{d:"M5 20v2"}],["path",{d:"M19 20v2"}]],J9=[["path",{d:"M21 16V8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73l7 4a2 2 0 0 0 2 0l7-4A2 2 0 0 0 21 16z"}]],Y9=[["path",{d:"m9 11-6 6v3h9l3-3"}],["path",{d:"m22 12-4.6 4.6a2 2 0 0 1-2.8 0l-5.2-5.2a2 2 0 0 1 0-2.8L14 4"}]],_9=[["path",{d:"M3 12a9 9 0 1 0 9-9 9.75 9.75 0 0 0-6.74 2.74L3 8"}],["path",{d:"M3 3v5h5"}],["path",{d:"M12 7v5l4 2"}]],x9=[["path",{d:"M10.82 16.12c1.69.6 3.91.79 5.18.85.28.01.53-.09.7-.27"}],["path",{d:"M11.14 20.57c.52.24 2.44 1.12 4.08 1.37.46.06.86-.25.9-.71.12-1.52-.3-3.43-.5-4.28"}],["path",{d:"M16.13 21.05c1.65.63 3.68.84 4.87.91a.9.9 0 0 0 .7-.26"}],["path",{d:"M17.99 5.52a20.83 20.83 0 0 1 3.15 4.5.8.8 0 0 1-.68 1.13c-1.17.1-2.5.02-3.9-.25"}],["path",{d:"M20.57 11.14c.24.52 1.12 2.44 1.37 4.08.04.3-.08.59-.31.75"}],["path",{d:"M4.93 4.93a10 10 0 0 0-.67 13.4c.35.43.96.4 1.17-.12.69-1.71 1.07-5.07 1.07-6.71 1.34.45 3.1.9 4.88.62a.85.85 0 0 0 .48-.24"}],["path",{d:"M5.52 17.99c1.05.95 2.91 2.42 4.5 3.15a.8.8 0 0 0 1.13-.68c.2-2.34-.33-5.3-1.57-8.28"}],["path",{d:"M8.35 2.68a10 10 0 0 1 9.98 1.58c.43.35.4.96-.12 1.17-1.5.6-4.3.98-6.07 1.05"}],["path",{d:"m2 2 20 20"}]],ap=[["path",{d:"M10.82 16.12c1.69.6 3.91.79 5.18.85.55.03 1-.42.97-.97-.06-1.27-.26-3.5-.85-5.18"}],["path",{d:"M11.5 6.5c1.64 0 5-.38 6.71-1.07.52-.2.55-.82.12-1.17A10 10 0 0 0 4.26 18.33c.35.43.96.4 1.17-.12.69-1.71 1.07-5.07 1.07-6.71 1.34.45 3.1.9 4.88.62a.88.88 0 0 0 .73-.74c.3-2.14-.15-3.5-.61-4.88"}],["path",{d:"M15.62 16.95c.2.85.62 2.76.5 4.28a.77.77 0 0 1-.9.7 16.64 16.64 0 0 1-4.08-1.36"}],["path",{d:"M16.13 21.05c1.65.63 3.68.84 4.87.91a.9.9 0 0 0 .96-.96 17.68 17.68 0 0 0-.9-4.87"}],["path",{d:"M16.94 15.62c.86.2 2.77.62 4.29.5a.77.77 0 0 0 .7-.9 16.64 16.64 0 0 0-1.36-4.08"}],["path",{d:"M17.99 5.52a20.82 20.82 0 0 1 3.15 4.5.8.8 0 0 1-.68 1.13c-2.33.2-5.3-.32-8.27-1.57"}],["path",{d:"M4.93 4.93 3 3a.7.7 0 0 1 0-1"}],["path",{d:"M9.58 12.18c1.24 2.98 1.77 5.95 1.57 8.28a.8.8 0 0 1-1.13.68 20.82 20.82 0 0 1-4.5-3.15"}]],tp=[["path",{d:"M12 7v4"}],["path",{d:"M14 21v-3a2 2 0 0 0-4 0v3"}],["path",{d:"M14 9h-4"}],["path",{d:"M18 11h2a2 2 0 0 1 2 2v6a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2v-9a2 2 0 0 1 2-2h2"}],["path",{d:"M18 21V5a2 2 0 0 0-2-2H8a2 2 0 0 0-2 2v16"}]],hp=[["path",{d:"M10 22v-6.57"}],["path",{d:"M12 11h.01"}],["path",{d:"M12 7h.01"}],["path",{d:"M14 15.43V22"}],["path",{d:"M15 16a5 5 0 0 0-6 0"}],["path",{d:"M16 11h.01"}],["path",{d:"M16 7h.01"}],["path",{d:"M8 11h.01"}],["path",{d:"M8 7h.01"}],["rect",{x:"4",y:"2",width:"16",height:"20",rx:"2"}]],dp=[["path",{d:"M5 22h14"}],["path",{d:"M5 2h14"}],["path",{d:"M17 22v-4.172a2 2 0 0 0-.586-1.414L12 12l-4.414 4.414A2 2 0 0 0 7 17.828V22"}],["path",{d:"M7 2v4.172a2 2 0 0 0 .586 1.414L12 12l4.414-4.414A2 2 0 0 0 17 6.172V2"}]],cp=[["path",{d:"M8.62 13.8A2.25 2.25 0 1 1 12 10.836a2.25 2.25 0 1 1 3.38 2.966l-2.626 2.856a.998.998 0 0 1-1.507 0z"}],["path",{d:"M3 10a2 2 0 0 1 .709-1.528l7-6a2 2 0 0 1 2.582 0l7 6A2 2 0 0 1 21 10v9a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2z"}]],Mp=[["path",{d:"M10 12V8.964"}],["path",{d:"M14 12V8.964"}],["path",{d:"M15 12a1 1 0 0 1 1 1v2a2 2 0 0 1-2 2h-4a2 2 0 0 1-2-2v-2a1 1 0 0 1 1-1z"}],["path",{d:"M8.5 21H5a2 2 0 0 1-2-2v-9a2 2 0 0 1 .709-1.528l7-6a2 2 0 0 1 2.582 0l7 6A2 2 0 0 1 21 10v9a2 2 0 0 1-2 2h-5a2 2 0 0 1-2-2v-2"}]],pp=[["path",{d:"M12.35 21H5a2 2 0 0 1-2-2v-9a2 2 0 0 1 .71-1.53l7-6a2 2 0 0 1 2.58 0l7 6A2 2 0 0 1 21 10v2.35"}],["path",{d:"M14.8 12.4A1 1 0 0 0 14 12h-4a1 1 0 0 0-1 1v8"}],["path",{d:"M15 18h6"}],["path",{d:"M18 15v6"}]],ip=[["path",{d:"M9.5 13.866a4 4 0 0 1 5 .01"}],["path",{d:"M12 17h.01"}],["path",{d:"M3 10a2 2 0 0 1 .709-1.528l7-6a2 2 0 0 1 2.582 0l7 6A2 2 0 0 1 21 10v9a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2z"}],["path",{d:"M7 10.754a8 8 0 0 1 10 0"}]],d2=[["path",{d:"M15 21v-8a1 1 0 0 0-1-1h-4a1 1 0 0 0-1 1v8"}],["path",{d:"M3 10a2 2 0 0 1 .709-1.528l7-6a2 2 0 0 1 2.582 0l7 6A2 2 0 0 1 21 10v9a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2z"}]],c2=[["path",{d:"m7 11 4.08 10.35a1 1 0 0 0 1.84 0L17 11"}],["path",{d:"M17 7A5 5 0 0 0 7 7"}],["path",{d:"M17 7a2 2 0 0 1 0 4H7a2 2 0 0 1 0-4"}]],M2=[["path",{d:"M12 17c5 0 8-2.69 8-6H4c0 3.31 3 6 8 6m-4 4h8m-4-3v3M5.14 11a3.5 3.5 0 1 1 6.71 0"}],["path",{d:"M12.14 11a3.5 3.5 0 1 1 6.71 0"}],["path",{d:"M15.5 6.5a3.5 3.5 0 1 0-7 0"}]],np=[["path",{d:"M13.5 8h-3"}],["path",{d:"m15 2-1 2h3a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H7a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h3"}],["path",{d:"M16.899 22A5 5 0 0 0 7.1 22"}],["path",{d:"m9 2 3 6"}],["circle",{cx:"12",cy:"15",r:"3"}]],lp=[["path",{d:"M16 10h2"}],["path",{d:"M16 14h2"}],["path",{d:"M6.17 15a3 3 0 0 1 5.66 0"}],["circle",{cx:"9",cy:"11",r:"2"}],["rect",{x:"2",y:"5",width:"20",height:"14",rx:"2"}]],ep=[["path",{d:"M10.3 21H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v10l-3.1-3.1a2 2 0 0 0-2.814.014L6 21"}],["path",{d:"m14 19 3 3v-5.5"}],["path",{d:"m17 22 3-3"}],["circle",{cx:"9",cy:"9",r:"2"}]],rp=[["path",{d:"M21 9v10a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h7"}],["line",{x1:"16",x2:"22",y1:"5",y2:"5"}],["circle",{cx:"9",cy:"9",r:"2"}],["path",{d:"m21 15-3.086-3.086a2 2 0 0 0-2.828 0L6 21"}]],op=[["line",{x1:"2",x2:"22",y1:"2",y2:"22"}],["path",{d:"M10.41 10.41a2 2 0 1 1-2.83-2.83"}],["line",{x1:"13.5",x2:"6",y1:"13.5",y2:"21"}],["line",{x1:"18",x2:"21",y1:"12",y2:"15"}],["path",{d:"M3.59 3.59A1.99 1.99 0 0 0 3 5v14a2 2 0 0 0 2 2h14c.55 0 1.052-.22 1.41-.59"}],["path",{d:"M21 15V5a2 2 0 0 0-2-2H9"}]],vp=[["path",{d:"M15 15.003a1 1 0 0 1 1.517-.859l4.997 2.997a1 1 0 0 1 0 1.718l-4.997 2.997a1 1 0 0 1-1.517-.86z"}],["path",{d:"M21 12.17V5a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h6"}],["path",{d:"m6 21 5-5"}],["circle",{cx:"9",cy:"9",r:"2"}]],$p=[["path",{d:"M16 5h6"}],["path",{d:"M19 2v6"}],["path",{d:"M21 11.5V19a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h7.5"}],["path",{d:"m21 15-3.086-3.086a2 2 0 0 0-2.828 0L6 21"}],["circle",{cx:"9",cy:"9",r:"2"}]],mp=[["path",{d:"M10.3 21H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v10l-3.1-3.1a2 2 0 0 0-2.814.014L6 21"}],["path",{d:"m14 19.5 3-3 3 3"}],["path",{d:"M17 22v-5.5"}],["circle",{cx:"9",cy:"9",r:"2"}]],yp=[["path",{d:"M16 3h5v5"}],["path",{d:"M17 21h2a2 2 0 0 0 2-2"}],["path",{d:"M21 12v3"}],["path",{d:"m21 3-5 5"}],["path",{d:"M3 7V5a2 2 0 0 1 2-2"}],["path",{d:"m5 21 4.144-4.144a1.21 1.21 0 0 1 1.712 0L13 19"}],["path",{d:"M9 3h3"}],["rect",{x:"3",y:"11",width:"10",height:"10",rx:"1"}]],sp=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["circle",{cx:"9",cy:"9",r:"2"}],["path",{d:"m21 15-3.086-3.086a2 2 0 0 0-2.828 0L6 21"}]],gp=[["path",{d:"m22 11-1.296-1.296a2.4 2.4 0 0 0-3.408 0L11 16"}],["path",{d:"M4 8a2 2 0 0 0-2 2v10a2 2 0 0 0 2 2h10a2 2 0 0 0 2-2"}],["circle",{cx:"13",cy:"7",r:"1",fill:"currentColor"}],["rect",{x:"8",y:"2",width:"14",height:"14",rx:"2"}]],up=[["path",{d:"M12 3v12"}],["path",{d:"m8 11 4 4 4-4"}],["path",{d:"M8 5H4a2 2 0 0 0-2 2v10a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2h-4"}]],Cp=[["path",{d:"M6 3h12"}],["path",{d:"M6 8h12"}],["path",{d:"m6 13 8.5 8"}],["path",{d:"M6 13h3"}],["path",{d:"M9 13c6.667 0 6.667-10 0-10"}]],Hp=[["polyline",{points:"22 12 16 12 14 15 10 15 8 12 2 12"}],["path",{d:"M5.45 5.11 2 12v6a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-6l-3.45-6.89A2 2 0 0 0 16.76 4H7.24a2 2 0 0 0-1.79 1.11z"}]],Ap=[["path",{d:"M6 16c5 0 7-8 12-8a4 4 0 0 1 0 8c-5 0-7-8-12-8a4 4 0 1 0 0 8"}]],wp=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M12 16v-4"}],["path",{d:"M12 8h.01"}]],Vp=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M7 7h.01"}],["path",{d:"M17 7h.01"}],["path",{d:"M7 17h.01"}],["path",{d:"M17 17h.01"}]],Sp=[["rect",{width:"20",height:"20",x:"2",y:"2",rx:"5",ry:"5"}],["path",{d:"M16 11.37A4 4 0 1 1 12.63 8 4 4 0 0 1 16 11.37z"}],["line",{x1:"17.5",x2:"17.51",y1:"6.5",y2:"6.5"}]],Lp=[["line",{x1:"19",x2:"10",y1:"4",y2:"4"}],["line",{x1:"14",x2:"5",y1:"20",y2:"20"}],["line",{x1:"15",x2:"9",y1:"4",y2:"20"}]],fp=[["path",{d:"m16 14 4 4-4 4"}],["path",{d:"M20 10a8 8 0 1 0-8 8h8"}]],kp=[["path",{d:"M4 10a8 8 0 1 1 8 8H4"}],["path",{d:"m8 22-4-4 4-4"}]],Pp=[["path",{d:"M12 9.5V21m0-11.5L6 3m6 6.5L18 3"}],["path",{d:"M6 15h12"}],["path",{d:"M6 11h12"}]],Bp=[["path",{d:"M21 17a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v2a2 2 0 0 0 2 2h14a2 2 0 0 0 2-2v-2Z"}],["path",{d:"M6 15v-2"}],["path",{d:"M12 15V9"}],["circle",{cx:"12",cy:"6",r:"3"}]],Dp=[["path",{d:"M5 3v14"}],["path",{d:"M12 3v8"}],["path",{d:"M19 3v18"}]],Fp=[["path",{d:"M2.586 17.414A2 2 0 0 0 2 18.828V21a1 1 0 0 0 1 1h3a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h1a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h.172a2 2 0 0 0 1.414-.586l.814-.814a6.5 6.5 0 1 0-4-4z"}],["circle",{cx:"16.5",cy:"7.5",r:".5",fill:"currentColor"}]],zp=[["path",{d:"M18 17a1 1 0 0 0-1 1v1a2 2 0 1 0 2-2z"}],["path",{d:"M20.97 3.61a.45.45 0 0 0-.58-.58C10.2 6.6 6.6 10.2 3.03 20.39a.45.45 0 0 0 .58.58C13.8 17.4 17.4 13.8 20.97 3.61"}],["path",{d:"m6.707 6.707 10.586 10.586"}],["path",{d:"M7 5a2 2 0 1 0-2 2h1a1 1 0 0 0 1-1z"}]],bp=[["path",{d:"M12.4 2.7a2.5 2.5 0 0 1 3.4 0l5.5 5.5a2.5 2.5 0 0 1 0 3.4l-3.7 3.7a2.5 2.5 0 0 1-3.4 0L8.7 9.8a2.5 2.5 0 0 1 0-3.4z"}],["path",{d:"m14 7 3 3"}],["path",{d:"m9.4 10.6-6.814 6.814A2 2 0 0 0 2 18.828V21a1 1 0 0 0 1 1h3a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h1a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h.172a2 2 0 0 0 1.414-.586l.814-.814"}]],Rp=[["path",{d:"m15.5 7.5 2.3 2.3a1 1 0 0 0 1.4 0l2.1-2.1a1 1 0 0 0 0-1.4L19 4"}],["path",{d:"m21 2-9.6 9.6"}],["circle",{cx:"7.5",cy:"15.5",r:"5.5"}]],Tp=[["rect",{width:"20",height:"16",x:"2",y:"4",rx:"2"}],["path",{d:"M6 8h4"}],["path",{d:"M14 8h.01"}],["path",{d:"M18 8h.01"}],["path",{d:"M2 12h20"}],["path",{d:"M6 12v4"}],["path",{d:"M10 12v4"}],["path",{d:"M14 12v4"}],["path",{d:"M18 12v4"}]],qp=[["path",{d:"M 20 4 A2 2 0 0 1 22 6"}],["path",{d:"M 22 6 L 22 16.41"}],["path",{d:"M 7 16 L 16 16"}],["path",{d:"M 9.69 4 L 20 4"}],["path",{d:"M14 8h.01"}],["path",{d:"M18 8h.01"}],["path",{d:"m2 2 20 20"}],["path",{d:"M20 20H4a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2"}],["path",{d:"M6 8h.01"}],["path",{d:"M8 12h.01"}]],Up=[["path",{d:"M10 8h.01"}],["path",{d:"M12 12h.01"}],["path",{d:"M14 8h.01"}],["path",{d:"M16 12h.01"}],["path",{d:"M18 8h.01"}],["path",{d:"M6 8h.01"}],["path",{d:"M7 16h10"}],["path",{d:"M8 12h.01"}],["rect",{width:"20",height:"16",x:"2",y:"4",rx:"2"}]],Op=[["path",{d:"M12 2v5"}],["path",{d:"M14.829 15.998a3 3 0 1 1-5.658 0"}],["path",{d:"M20.92 14.606A1 1 0 0 1 20 16H4a1 1 0 0 1-.92-1.394l3-7A1 1 0 0 1 7 7h10a1 1 0 0 1 .92.606z"}]],Zp=[["path",{d:"M10.293 2.293a1 1 0 0 1 1.414 0l2.5 2.5 5.994 1.227a1 1 0 0 1 .506 1.687l-7 7a1 1 0 0 1-1.687-.506l-1.227-5.994-2.5-2.5a1 1 0 0 1 0-1.414z"}],["path",{d:"m14.207 4.793-3.414 3.414"}],["path",{d:"M3 20a2 2 0 0 1 2-2h4a2 2 0 0 1 2 2v1a1 1 0 0 1-1 1H4a1 1 0 0 1-1-1z"}],["path",{d:"m9.086 6.5-4.793 4.793a1 1 0 0 0-.18 1.17L7 18"}]],Gp=[["path",{d:"M12 10v12"}],["path",{d:"M17.929 7.629A1 1 0 0 1 17 9H7a1 1 0 0 1-.928-1.371l2-5A1 1 0 0 1 9 2h6a1 1 0 0 1 .928.629z"}],["path",{d:"M9 22h6"}]],Ip=[["path",{d:"M19.929 18.629A1 1 0 0 1 19 20H9a1 1 0 0 1-.928-1.371l2-5A1 1 0 0 1 11 13h6a1 1 0 0 1 .928.629z"}],["path",{d:"M6 3a2 2 0 0 1 2 2v2a2 2 0 0 1-2 2H5a1 1 0 0 1-1-1V4a1 1 0 0 1 1-1z"}],["path",{d:"M8 6h4a2 2 0 0 1 2 2v5"}]],Wp=[["path",{d:"M19.929 9.629A1 1 0 0 1 19 11H9a1 1 0 0 1-.928-1.371l2-5A1 1 0 0 1 11 4h6a1 1 0 0 1 .928.629z"}],["path",{d:"M6 15a2 2 0 0 1 2 2v2a2 2 0 0 1-2 2H5a1 1 0 0 1-1-1v-4a1 1 0 0 1 1-1z"}],["path",{d:"M8 18h4a2 2 0 0 0 2-2v-5"}]],Ep=[["path",{d:"M12 12v6"}],["path",{d:"M4.077 10.615A1 1 0 0 0 5 12h14a1 1 0 0 0 .923-1.385l-3.077-7.384A2 2 0 0 0 15 2H9a2 2 0 0 0-1.846 1.23Z"}],["path",{d:"M8 20a2 2 0 0 1 2-2h4a2 2 0 0 1 2 2v1a1 1 0 0 1-1 1H9a1 1 0 0 1-1-1z"}]],Xp=[["path",{d:"m12 8 6-3-6-3v10"}],["path",{d:"m8 11.99-5.5 3.14a1 1 0 0 0 0 1.74l8.5 4.86a2 2 0 0 0 2 0l8.5-4.86a1 1 0 0 0 0-1.74L16 12"}],["path",{d:"m6.49 12.85 11.02 6.3"}],["path",{d:"M17.51 12.85 6.5 19.15"}]],jp=[["path",{d:"M10 18v-7"}],["path",{d:"M11.12 2.198a2 2 0 0 1 1.76.006l7.866 3.847c.476.233.31.949-.22.949H3.474c-.53 0-.695-.716-.22-.949z"}],["path",{d:"M14 18v-7"}],["path",{d:"M18 18v-7"}],["path",{d:"M3 22h18"}],["path",{d:"M6 18v-7"}]],Np=[["path",{d:"m5 8 6 6"}],["path",{d:"m4 14 6-6 2-3"}],["path",{d:"M2 5h12"}],["path",{d:"M7 2h1"}],["path",{d:"m22 22-5-10-5 10"}],["path",{d:"M14 18h6"}]],Kp=[["path",{d:"M2 20h20"}],["path",{d:"m9 10 2 2 4-4"}],["rect",{x:"3",y:"4",width:"18",height:"12",rx:"2"}]],p2=[["rect",{width:"18",height:"12",x:"3",y:"4",rx:"2",ry:"2"}],["line",{x1:"2",x2:"22",y1:"20",y2:"20"}]],Qp=[["path",{d:"M18 5a2 2 0 0 1 2 2v8.526a2 2 0 0 0 .212.897l1.068 2.127a1 1 0 0 1-.9 1.45H3.62a1 1 0 0 1-.9-1.45l1.068-2.127A2 2 0 0 0 4 15.526V7a2 2 0 0 1 2-2z"}],["path",{d:"M20.054 15.987H3.946"}]],Jp=[["path",{d:"M7 22a5 5 0 0 1-2-4"}],["path",{d:"M7 16.93c.96.43 1.96.74 2.99.91"}],["path",{d:"M3.34 14A6.8 6.8 0 0 1 2 10c0-4.42 4.48-8 10-8s10 3.58 10 8a7.19 7.19 0 0 1-.33 2"}],["path",{d:"M5 18a2 2 0 1 0 0-4 2 2 0 0 0 0 4z"}],["path",{d:"M14.33 22h-.09a.35.35 0 0 1-.24-.32v-10a.34.34 0 0 1 .33-.34c.08 0 .15.03.21.08l7.34 6a.33.33 0 0 1-.21.59h-4.49l-2.57 3.85a.35.35 0 0 1-.28.14z"}]],Yp=[["path",{d:"M3.704 14.467A10 8 0 0 1 2 10a10 8 0 0 1 20 0 10 8 0 0 1-10 8 10 8 0 0 1-5.181-1.158"}],["path",{d:"M7 22a5 5 0 0 1-2-3.994"}],["circle",{cx:"5",cy:"16",r:"2"}]],_p=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M18 13a6 6 0 0 1-6 5 6 6 0 0 1-6-5h12Z"}],["line",{x1:"9",x2:"9.01",y1:"9",y2:"9"}],["line",{x1:"15",x2:"15.01",y1:"9",y2:"9"}]],xp=[["path",{d:"M13 13.74a2 2 0 0 1-2 0L2.5 8.87a1 1 0 0 1 0-1.74L11 2.26a2 2 0 0 1 2 0l8.5 4.87a1 1 0 0 1 0 1.74z"}],["path",{d:"m20 14.285 1.5.845a1 1 0 0 1 0 1.74L13 21.74a2 2 0 0 1-2 0l-8.5-4.87a1 1 0 0 1 0-1.74l1.5-.845"}]],ai=[["rect",{width:"7",height:"9",x:"3",y:"3",rx:"1"}],["rect",{width:"7",height:"5",x:"14",y:"3",rx:"1"}],["rect",{width:"7",height:"9",x:"14",y:"12",rx:"1"}],["rect",{width:"7",height:"5",x:"3",y:"16",rx:"1"}]],ti=[["rect",{width:"7",height:"7",x:"3",y:"3",rx:"1"}],["rect",{width:"7",height:"7",x:"14",y:"3",rx:"1"}],["rect",{width:"7",height:"7",x:"14",y:"14",rx:"1"}],["rect",{width:"7",height:"7",x:"3",y:"14",rx:"1"}]],i2=[["path",{d:"M12.83 2.18a2 2 0 0 0-1.66 0L2.6 6.08a1 1 0 0 0 0 1.83l8.58 3.91a2 2 0 0 0 1.66 0l8.58-3.9a1 1 0 0 0 0-1.83z"}],["path",{d:"M2 12a1 1 0 0 0 .58.91l8.6 3.91a2 2 0 0 0 1.65 0l8.58-3.9A1 1 0 0 0 22 12"}],["path",{d:"M2 17a1 1 0 0 0 .58.91l8.6 3.91a2 2 0 0 0 1.65 0l8.58-3.9A1 1 0 0 0 22 17"}]],hi=[["rect",{width:"7",height:"7",x:"3",y:"3",rx:"1"}],["rect",{width:"7",height:"7",x:"3",y:"14",rx:"1"}],["path",{d:"M14 4h7"}],["path",{d:"M14 9h7"}],["path",{d:"M14 15h7"}],["path",{d:"M14 20h7"}]],di=[["rect",{width:"7",height:"18",x:"3",y:"3",rx:"1"}],["rect",{width:"7",height:"7",x:"14",y:"3",rx:"1"}],["rect",{width:"7",height:"7",x:"14",y:"14",rx:"1"}]],ci=[["rect",{width:"18",height:"7",x:"3",y:"3",rx:"1"}],["rect",{width:"9",height:"7",x:"3",y:"14",rx:"1"}],["rect",{width:"5",height:"7",x:"16",y:"14",rx:"1"}]],Mi=[["rect",{width:"18",height:"7",x:"3",y:"3",rx:"1"}],["rect",{width:"7",height:"7",x:"3",y:"14",rx:"1"}],["rect",{width:"7",height:"7",x:"14",y:"14",rx:"1"}]],pi=[["path",{d:"M11 20A7 7 0 0 1 9.8 6.1C15.5 5 17 4.48 19 2c1 2 2 4.18 2 8 0 5.5-4.78 10-10 10Z"}],["path",{d:"M2 21c0-3 1.85-5.36 5.08-6C9.5 14.52 12 13 13 12"}]],ii=[["path",{d:"M2 22c1.25-.987 2.27-1.975 3.9-2.2a5.56 5.56 0 0 1 3.8 1.5 4 4 0 0 0 6.187-2.353 3.5 3.5 0 0 0 3.69-5.116A3.5 3.5 0 0 0 20.95 8 3.5 3.5 0 1 0 16 3.05a3.5 3.5 0 0 0-5.831 1.373 3.5 3.5 0 0 0-5.116 3.69 4 4 0 0 0-2.348 6.155C3.499 15.42 4.409 16.712 4.2 18.1 3.926 19.743 3.014 20.732 2 22"}],["path",{d:"M2 22 17 7"}]],ni=[["path",{d:"M16 12h3a2 2 0 0 0 1.902-1.38l1.056-3.333A1 1 0 0 0 21 6H3a1 1 0 0 0-.958 1.287l1.056 3.334A2 2 0 0 0 5 12h3"}],["path",{d:"M18 6V3a1 1 0 0 0-1-1h-3"}],["rect",{width:"8",height:"12",x:"8",y:"10",rx:"1"}]],li=[["rect",{width:"8",height:"18",x:"3",y:"3",rx:"1"}],["path",{d:"M7 3v18"}],["path",{d:"M20.4 18.9c.2.5-.1 1.1-.6 1.3l-1.9.7c-.5.2-1.1-.1-1.3-.6L11.1 5.1c-.2-.5.1-1.1.6-1.3l1.9-.7c.5-.2 1.1.1 1.3.6Z"}]],ei=[["path",{d:"m16 6 4 14"}],["path",{d:"M12 6v14"}],["path",{d:"M8 8v12"}],["path",{d:"M4 4v16"}]],ri=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"m4.93 4.93 4.24 4.24"}],["path",{d:"m14.83 9.17 4.24-4.24"}],["path",{d:"m14.83 14.83 4.24 4.24"}],["path",{d:"m9.17 14.83-4.24 4.24"}],["circle",{cx:"12",cy:"12",r:"4"}]],oi=[["path",{d:"M16.8 11.2c.8-.9 1.2-2 1.2-3.2a6 6 0 0 0-9.3-5"}],["path",{d:"m2 2 20 20"}],["path",{d:"M6.3 6.3a4.67 4.67 0 0 0 1.2 5.2c.7.7 1.3 1.5 1.5 2.5"}],["path",{d:"M9 18h6"}],["path",{d:"M10 22h4"}]],vi=[["path",{d:"M14 12h2v8"}],["path",{d:"M14 20h4"}],["path",{d:"M6 12h4"}],["path",{d:"M6 20h4"}],["path",{d:"M8 20V8a4 4 0 0 1 7.464-2"}]],$i=[["path",{d:"M15 14c.2-1 .7-1.7 1.5-2.5 1-.9 1.5-2.2 1.5-3.5A6 6 0 0 0 6 8c0 1 .2 2.2 1.5 3.5.7.7 1.3 1.5 1.5 2.5"}],["path",{d:"M9 18h6"}],["path",{d:"M10 22h4"}]],mi=[["path",{d:"M7 3.5c5-2 7 2.5 3 4C1.5 10 2 15 5 16c5 2 9-10 14-7s.5 13.5-4 12c-5-2.5.5-11 6-2"}]],yi=[["path",{d:"M9 17H7A5 5 0 0 1 7 7"}],["path",{d:"M15 7h2a5 5 0 0 1 4 8"}],["line",{x1:"8",x2:"12",y1:"12",y2:"12"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],si=[["path",{d:"M9 17H7A5 5 0 0 1 7 7h2"}],["path",{d:"M15 7h2a5 5 0 1 1 0 10h-2"}],["line",{x1:"8",x2:"16",y1:"12",y2:"12"}]],gi=[["path",{d:"M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"}],["path",{d:"M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"}]],ui=[["path",{d:"M16 8a6 6 0 0 1 6 6v7h-4v-7a2 2 0 0 0-2-2 2 2 0 0 0-2 2v7h-4v-7a6 6 0 0 1 6-6z"}],["rect",{width:"4",height:"12",x:"2",y:"9"}],["circle",{cx:"4",cy:"4",r:"2"}]],Ci=[["path",{d:"M16 5H3"}],["path",{d:"M16 12H3"}],["path",{d:"M11 19H3"}],["path",{d:"m15 18 2 2 4-4"}]],Hi=[["path",{d:"M13 5h8"}],["path",{d:"M13 12h8"}],["path",{d:"M13 19h8"}],["path",{d:"m3 17 2 2 4-4"}],["path",{d:"m3 7 2 2 4-4"}]],Ai=[["path",{d:"M3 5h8"}],["path",{d:"M3 12h8"}],["path",{d:"M3 19h8"}],["path",{d:"m15 5 3 3 3-3"}],["path",{d:"m15 19 3-3 3 3"}]],wi=[["path",{d:"M3 5h8"}],["path",{d:"M3 12h8"}],["path",{d:"M3 19h8"}],["path",{d:"m15 8 3-3 3 3"}],["path",{d:"m15 16 3 3 3-3"}]],Vi=[["path",{d:"M10 5h11"}],["path",{d:"M10 12h11"}],["path",{d:"M10 19h11"}],["path",{d:"m3 10 3-3-3-3"}],["path",{d:"m3 20 3-3-3-3"}]],Si=[["path",{d:"M16 5H3"}],["path",{d:"M16 12H3"}],["path",{d:"M9 19H3"}],["path",{d:"m16 16-3 3 3 3"}],["path",{d:"M21 5v12a2 2 0 0 1-2 2h-6"}]],Li=[["path",{d:"M12 5H2"}],["path",{d:"M6 12h12"}],["path",{d:"M9 19h6"}],["path",{d:"M16 5h6"}],["path",{d:"M19 8V2"}]],fi=[["path",{d:"M2 5h20"}],["path",{d:"M6 12h12"}],["path",{d:"M9 19h6"}]],o=[["path",{d:"M21 5H11"}],["path",{d:"M21 12H11"}],["path",{d:"M21 19H11"}],["path",{d:"m7 8-4 4 4 4"}]],v=[["path",{d:"M21 5H11"}],["path",{d:"M21 12H11"}],["path",{d:"M21 19H11"}],["path",{d:"m3 8 4 4-4 4"}]],ki=[["path",{d:"M16 5H3"}],["path",{d:"M11 12H3"}],["path",{d:"M16 19H3"}],["path",{d:"M21 12h-6"}]],Pi=[["path",{d:"M16 5H3"}],["path",{d:"M11 12H3"}],["path",{d:"M11 19H3"}],["path",{d:"M21 16V5"}],["circle",{cx:"18",cy:"16",r:"3"}]],Bi=[["path",{d:"M11 5h10"}],["path",{d:"M11 12h10"}],["path",{d:"M11 19h10"}],["path",{d:"M4 4h1v5"}],["path",{d:"M4 9h2"}],["path",{d:"M6.5 20H3.4c0-1 2.6-1.925 2.6-3.5a1.5 1.5 0 0 0-2.6-1.02"}]],Di=[["path",{d:"M16 5H3"}],["path",{d:"M11 12H3"}],["path",{d:"M16 19H3"}],["path",{d:"M18 9v6"}],["path",{d:"M21 12h-6"}]],Fi=[["path",{d:"M21 5H3"}],["path",{d:"M7 12H3"}],["path",{d:"M7 19H3"}],["path",{d:"M12 18a5 5 0 0 0 9-3 4.5 4.5 0 0 0-4.5-4.5c-1.33 0-2.54.54-3.41 1.41L11 14"}],["path",{d:"M11 10v4h4"}]],zi=[["path",{d:"M3 5h6"}],["path",{d:"M3 12h13"}],["path",{d:"M3 19h13"}],["path",{d:"m16 8-3-3 3-3"}],["path",{d:"M21 19V7a2 2 0 0 0-2-2h-6"}]],bi=[["path",{d:"M13 5h8"}],["path",{d:"M13 12h8"}],["path",{d:"M13 19h8"}],["path",{d:"m3 17 2 2 4-4"}],["rect",{x:"3",y:"4",width:"6",height:"6",rx:"1"}]],Ri=[["path",{d:"M21 5H3"}],["path",{d:"M10 12H3"}],["path",{d:"M10 19H3"}],["path",{d:"M15 12.003a1 1 0 0 1 1.517-.859l4.997 2.997a1 1 0 0 1 0 1.718l-4.997 2.997a1 1 0 0 1-1.517-.86z"}]],Ti=[["path",{d:"M8 5h13"}],["path",{d:"M13 12h8"}],["path",{d:"M13 19h8"}],["path",{d:"M3 10a2 2 0 0 0 2 2h3"}],["path",{d:"M3 5v12a2 2 0 0 0 2 2h3"}]],qi=[["path",{d:"M3 5h.01"}],["path",{d:"M3 12h.01"}],["path",{d:"M3 19h.01"}],["path",{d:"M8 5h13"}],["path",{d:"M8 12h13"}],["path",{d:"M8 19h13"}]],Ui=[["path",{d:"M16 5H3"}],["path",{d:"M11 12H3"}],["path",{d:"M16 19H3"}],["path",{d:"m15.5 9.5 5 5"}],["path",{d:"m20.5 9.5-5 5"}]],n2=[["path",{d:"M21 12a9 9 0 1 1-6.219-8.56"}]],Oi=[["path",{d:"M22 12a1 1 0 0 1-10 0 1 1 0 0 0-10 0"}],["path",{d:"M7 20.7a1 1 0 1 1 5-8.7 1 1 0 1 0 5-8.6"}],["path",{d:"M7 3.3a1 1 0 1 1 5 8.6 1 1 0 1 0 5 8.6"}],["circle",{cx:"12",cy:"12",r:"10"}]],Zi=[["path",{d:"M12 2v4"}],["path",{d:"m16.2 7.8 2.9-2.9"}],["path",{d:"M18 12h4"}],["path",{d:"m16.2 16.2 2.9 2.9"}],["path",{d:"M12 18v4"}],["path",{d:"m4.9 19.1 2.9-2.9"}],["path",{d:"M2 12h4"}],["path",{d:"m4.9 4.9 2.9 2.9"}]],Gi=[["path",{d:"M12 19v3"}],["path",{d:"M12 2v3"}],["path",{d:"M18.89 13.24a7 7 0 0 0-8.13-8.13"}],["path",{d:"M19 12h3"}],["path",{d:"M2 12h3"}],["path",{d:"m2 2 20 20"}],["path",{d:"M7.05 7.05a7 7 0 0 0 9.9 9.9"}]],Ii=[["line",{x1:"2",x2:"5",y1:"12",y2:"12"}],["line",{x1:"19",x2:"22",y1:"12",y2:"12"}],["line",{x1:"12",x2:"12",y1:"2",y2:"5"}],["line",{x1:"12",x2:"12",y1:"19",y2:"22"}],["circle",{cx:"12",cy:"12",r:"7"}],["circle",{cx:"12",cy:"12",r:"3"}]],Wi=[["line",{x1:"2",x2:"5",y1:"12",y2:"12"}],["line",{x1:"19",x2:"22",y1:"12",y2:"12"}],["line",{x1:"12",x2:"12",y1:"2",y2:"5"}],["line",{x1:"12",x2:"12",y1:"19",y2:"22"}],["circle",{cx:"12",cy:"12",r:"7"}]],l2=[["circle",{cx:"12",cy:"16",r:"1"}],["rect",{width:"18",height:"12",x:"3",y:"10",rx:"2"}],["path",{d:"M7 10V7a5 5 0 0 1 9.33-2.5"}]],Ei=[["circle",{cx:"12",cy:"16",r:"1"}],["rect",{x:"3",y:"10",width:"18",height:"12",rx:"2"}],["path",{d:"M7 10V7a5 5 0 0 1 10 0v3"}]],e2=[["rect",{width:"18",height:"11",x:"3",y:"11",rx:"2",ry:"2"}],["path",{d:"M7 11V7a5 5 0 0 1 9.9-1"}]],Xi=[["rect",{width:"18",height:"11",x:"3",y:"11",rx:"2",ry:"2"}],["path",{d:"M7 11V7a5 5 0 0 1 10 0v4"}]],ji=[["path",{d:"m16 17 5-5-5-5"}],["path",{d:"M21 12H9"}],["path",{d:"M9 21H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h4"}]],Ni=[["path",{d:"m10 17 5-5-5-5"}],["path",{d:"M15 12H3"}],["path",{d:"M15 3h4a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2h-4"}]],Ki=[["path",{d:"M3 5h1"}],["path",{d:"M3 12h1"}],["path",{d:"M3 19h1"}],["path",{d:"M8 5h1"}],["path",{d:"M8 12h1"}],["path",{d:"M8 19h1"}],["path",{d:"M13 5h8"}],["path",{d:"M13 12h8"}],["path",{d:"M13 19h8"}]],Qi=[["circle",{cx:"11",cy:"11",r:"8"}],["path",{d:"m21 21-4.3-4.3"}],["path",{d:"M11 11a2 2 0 0 0 4 0 4 4 0 0 0-8 0 6 6 0 0 0 12 0"}]],Ji=[["path",{d:"M6 20a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h12a2 2 0 0 1 2 2v10a2 2 0 0 1-2 2"}],["path",{d:"M8 18V4a2 2 0 0 1 2-2h4a2 2 0 0 1 2 2v14"}],["path",{d:"M10 20h4"}],["circle",{cx:"16",cy:"20",r:"2"}],["circle",{cx:"8",cy:"20",r:"2"}]],Yi=[["path",{d:"m12 15 4 4"}],["path",{d:"M2.352 10.648a1.205 1.205 0 0 0 0 1.704l2.296 2.296a1.205 1.205 0 0 0 1.704 0l6.029-6.029a1 1 0 1 1 3 3l-6.029 6.029a1.205 1.205 0 0 0 0 1.704l2.296 2.296a1.205 1.205 0 0 0 1.704 0l6.365-6.367A1 1 0 0 0 8.716 4.282z"}],["path",{d:"m5 8 4 4"}]],_i=[["path",{d:"M22 13V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v12c0 1.1.9 2 2 2h8"}],["path",{d:"m22 7-8.97 5.7a1.94 1.94 0 0 1-2.06 0L2 7"}],["path",{d:"m16 19 2 2 4-4"}]],xi=[["path",{d:"M22 15V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v12c0 1.1.9 2 2 2h8"}],["path",{d:"m22 7-8.97 5.7a1.94 1.94 0 0 1-2.06 0L2 7"}],["path",{d:"M16 19h6"}]],an=[["path",{d:"M21.2 8.4c.5.38.8.97.8 1.6v10a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2V10a2 2 0 0 1 .8-1.6l8-6a2 2 0 0 1 2.4 0l8 6Z"}],["path",{d:"m22 10-8.97 5.7a1.94 1.94 0 0 1-2.06 0L2 10"}]],tn=[["path",{d:"M22 13V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v12c0 1.1.9 2 2 2h8"}],["path",{d:"m22 7-8.97 5.7a1.94 1.94 0 0 1-2.06 0L2 7"}],["path",{d:"M19 16v6"}],["path",{d:"M16 19h6"}]],r2=[["path",{d:"M22 10.5V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v12c0 1.1.9 2 2 2h12.5"}],["path",{d:"m22 7-8.97 5.7a1.94 1.94 0 0 1-2.06 0L2 7"}],["path",{d:"M18 15.28c.2-.4.5-.8.9-1a2.1 2.1 0 0 1 2.6.4c.3.4.5.8.5 1.3 0 1.3-2 2-2 2"}],["path",{d:"M20 22v.01"}]],hn=[["path",{d:"M22 12.5V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v12c0 1.1.9 2 2 2h7.5"}],["path",{d:"m22 7-8.97 5.7a1.94 1.94 0 0 1-2.06 0L2 7"}],["path",{d:"M18 21a3 3 0 1 0 0-6 3 3 0 0 0 0 6Z"}],["circle",{cx:"18",cy:"18",r:"3"}],["path",{d:"m22 22-1.5-1.5"}]],dn=[["path",{d:"M22 10.5V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v12c0 1.1.9 2 2 2h12.5"}],["path",{d:"m22 7-8.97 5.7a1.94 1.94 0 0 1-2.06 0L2 7"}],["path",{d:"M20 14v4"}],["path",{d:"M20 22v.01"}]],cn=[["path",{d:"M22 13V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v12c0 1.1.9 2 2 2h9"}],["path",{d:"m22 7-8.97 5.7a1.94 1.94 0 0 1-2.06 0L2 7"}],["path",{d:"m17 17 4 4"}],["path",{d:"m21 17-4 4"}]],Mn=[["path",{d:"m22 7-8.991 5.727a2 2 0 0 1-2.009 0L2 7"}],["rect",{x:"2",y:"4",width:"20",height:"16",rx:"2"}]],pn=[["path",{d:"M22 17a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2V9.5C2 7 4 5 6.5 5H18c2.2 0 4 1.8 4 4v8Z"}],["polyline",{points:"15,9 18,9 18,11"}],["path",{d:"M6.5 5C9 5 11 7 11 9.5V17a2 2 0 0 1-2 2"}],["line",{x1:"6",x2:"7",y1:"10",y2:"10"}]],nn=[["path",{d:"M17 19a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2v-8a2 2 0 0 1 1-1.732"}],["path",{d:"m22 5.5-6.419 4.179a2 2 0 0 1-2.162 0L7 5.5"}],["rect",{x:"7",y:"3",width:"15",height:"12",rx:"2"}]],ln=[["path",{d:"m11 19-1.106-.552a2 2 0 0 0-1.788 0l-3.659 1.83A1 1 0 0 1 3 19.381V6.618a1 1 0 0 1 .553-.894l4.553-2.277a2 2 0 0 1 1.788 0l4.212 2.106a2 2 0 0 0 1.788 0l3.659-1.83A1 1 0 0 1 21 4.619V14"}],["path",{d:"M15 5.764V14"}],["path",{d:"M21 18h-6"}],["path",{d:"M9 3.236v15"}]],en=[["path",{d:"M20 10c0 4.993-5.539 10.193-7.399 11.799a1 1 0 0 1-1.202 0C9.539 20.193 4 14.993 4 10a8 8 0 0 1 16 0"}],["path",{d:"m9 10 2 2 4-4"}]],rn=[["path",{d:"M19.43 12.935c.357-.967.57-1.955.57-2.935a8 8 0 0 0-16 0c0 4.993 5.539 10.193 7.399 11.799a1 1 0 0 0 1.202 0 32.197 32.197 0 0 0 .813-.728"}],["circle",{cx:"12",cy:"10",r:"3"}],["path",{d:"m16 18 2 2 4-4"}]],on=[["path",{d:"M15 22a1 1 0 0 1-1-1v-4a1 1 0 0 1 .445-.832l3-2a1 1 0 0 1 1.11 0l3 2A1 1 0 0 1 22 17v4a1 1 0 0 1-1 1z"}],["path",{d:"M18 10a8 8 0 0 0-16 0c0 4.993 5.539 10.193 7.399 11.799a1 1 0 0 0 .601.2"}],["path",{d:"M18 22v-3"}],["circle",{cx:"10",cy:"10",r:"3"}]],vn=[["path",{d:"M20 10c0 4.993-5.539 10.193-7.399 11.799a1 1 0 0 1-1.202 0C9.539 20.193 4 14.993 4 10a8 8 0 0 1 16 0"}],["path",{d:"M9 10h6"}]],$n=[["path",{d:"M18.977 14C19.6 12.701 20 11.343 20 10a8 8 0 0 0-16 0c0 4.993 5.539 10.193 7.399 11.799a1 1 0 0 0 1.202 0 32 32 0 0 0 .824-.738"}],["circle",{cx:"12",cy:"10",r:"3"}],["path",{d:"M16 18h6"}]],mn=[["path",{d:"M12.75 7.09a3 3 0 0 1 2.16 2.16"}],["path",{d:"M17.072 17.072c-1.634 2.17-3.527 3.912-4.471 4.727a1 1 0 0 1-1.202 0C9.539 20.193 4 14.993 4 10a8 8 0 0 1 1.432-4.568"}],["path",{d:"m2 2 20 20"}],["path",{d:"M8.475 2.818A8 8 0 0 1 20 10c0 1.183-.31 2.377-.81 3.533"}],["path",{d:"M9.13 9.13a3 3 0 0 0 3.74 3.74"}]],o2=[["path",{d:"M17.97 9.304A8 8 0 0 0 2 10c0 4.69 4.887 9.562 7.022 11.468"}],["path",{d:"M21.378 16.626a1 1 0 0 0-3.004-3.004l-4.01 4.012a2 2 0 0 0-.506.854l-.837 2.87a.5.5 0 0 0 .62.62l2.87-.837a2 2 0 0 0 .854-.506z"}],["circle",{cx:"10",cy:"10",r:"3"}]],yn=[["path",{d:"M20 10c0 4.993-5.539 10.193-7.399 11.799a1 1 0 0 1-1.202 0C9.539 20.193 4 14.993 4 10a8 8 0 0 1 16 0"}],["path",{d:"M12 7v6"}],["path",{d:"M9 10h6"}]],sn=[["path",{d:"M20 10c0 4.993-5.539 10.193-7.399 11.799a1 1 0 0 1-1.202 0C9.539 20.193 4 14.993 4 10a8 8 0 0 1 16 0"}],["path",{d:"m14.5 7.5-5 5"}],["path",{d:"m9.5 7.5 5 5"}]],gn=[["path",{d:"M19.914 11.105A7.298 7.298 0 0 0 20 10a8 8 0 0 0-16 0c0 4.993 5.539 10.193 7.399 11.799a1 1 0 0 0 1.202 0 32 32 0 0 0 .824-.738"}],["circle",{cx:"12",cy:"10",r:"3"}],["path",{d:"M16 18h6"}],["path",{d:"M19 15v6"}]],un=[["path",{d:"M19.752 11.901A7.78 7.78 0 0 0 20 10a8 8 0 0 0-16 0c0 4.993 5.539 10.193 7.399 11.799a1 1 0 0 0 1.202 0 19 19 0 0 0 .09-.077"}],["circle",{cx:"12",cy:"10",r:"3"}],["path",{d:"m21.5 15.5-5 5"}],["path",{d:"m21.5 20.5-5-5"}]],Cn=[["path",{d:"M20 10c0 4.993-5.539 10.193-7.399 11.799a1 1 0 0 1-1.202 0C9.539 20.193 4 14.993 4 10a8 8 0 0 1 16 0"}],["circle",{cx:"12",cy:"10",r:"3"}]],Hn=[["path",{d:"M18 8c0 3.613-3.869 7.429-5.393 8.795a1 1 0 0 1-1.214 0C9.87 15.429 6 11.613 6 8a6 6 0 0 1 12 0"}],["circle",{cx:"12",cy:"8",r:"2"}],["path",{d:"M8.714 14h-3.71a1 1 0 0 0-.948.683l-2.004 6A1 1 0 0 0 3 22h18a1 1 0 0 0 .948-1.316l-2-6a1 1 0 0 0-.949-.684h-3.712"}]],An=[["path",{d:"m11 19-1.106-.552a2 2 0 0 0-1.788 0l-3.659 1.83A1 1 0 0 1 3 19.381V6.618a1 1 0 0 1 .553-.894l4.553-2.277a2 2 0 0 1 1.788 0l4.212 2.106a2 2 0 0 0 1.788 0l3.659-1.83A1 1 0 0 1 21 4.619V12"}],["path",{d:"M15 5.764V12"}],["path",{d:"M18 15v6"}],["path",{d:"M21 18h-6"}],["path",{d:"M9 3.236v15"}]],wn=[["path",{d:"M14.106 5.553a2 2 0 0 0 1.788 0l3.659-1.83A1 1 0 0 1 21 4.619v12.764a1 1 0 0 1-.553.894l-4.553 2.277a2 2 0 0 1-1.788 0l-4.212-2.106a2 2 0 0 0-1.788 0l-3.659 1.83A1 1 0 0 1 3 19.381V6.618a1 1 0 0 1 .553-.894l4.553-2.277a2 2 0 0 1 1.788 0z"}],["path",{d:"M15 5.764v15"}],["path",{d:"M9 3.236v15"}]],Vn=[["path",{d:"m14 6 4 4"}],["path",{d:"M17 3h4v4"}],["path",{d:"m21 3-7.75 7.75"}],["circle",{cx:"9",cy:"15",r:"6"}]],Sn=[["path",{d:"M16 3h5v5"}],["path",{d:"m21 3-6.75 6.75"}],["circle",{cx:"10",cy:"14",r:"6"}]],Ln=[["path",{d:"M8 22h8"}],["path",{d:"M12 11v11"}],["path",{d:"m19 3-7 8-7-8Z"}]],fn=[["path",{d:"M15 3h6v6"}],["path",{d:"m21 3-7 7"}],["path",{d:"m3 21 7-7"}],["path",{d:"M9 21H3v-6"}]],kn=[["path",{d:"M8 3H5a2 2 0 0 0-2 2v3"}],["path",{d:"M21 8V5a2 2 0 0 0-2-2h-3"}],["path",{d:"M3 16v3a2 2 0 0 0 2 2h3"}],["path",{d:"M16 21h3a2 2 0 0 0 2-2v-3"}]],Pn=[["path",{d:"M7.21 15 2.66 7.14a2 2 0 0 1 .13-2.2L4.4 2.8A2 2 0 0 1 6 2h12a2 2 0 0 1 1.6.8l1.6 2.14a2 2 0 0 1 .14 2.2L16.79 15"}],["path",{d:"M11 12 5.12 2.2"}],["path",{d:"m13 12 5.88-9.8"}],["path",{d:"M8 7h8"}],["circle",{cx:"12",cy:"17",r:"5"}],["path",{d:"M12 18v-2h-.5"}]],Bn=[["path",{d:"M11.636 6A13 13 0 0 0 19.4 3.2 1 1 0 0 1 21 4v11.344"}],["path",{d:"M14.378 14.357A13 13 0 0 0 11 14H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h1"}],["path",{d:"m2 2 20 20"}],["path",{d:"M6 14a12 12 0 0 0 2.4 7.2 2 2 0 0 0 3.2-2.4A8 8 0 0 1 10 14"}],["path",{d:"M8 8v6"}]],Dn=[["path",{d:"M11 6a13 13 0 0 0 8.4-2.8A1 1 0 0 1 21 4v12a1 1 0 0 1-1.6.8A13 13 0 0 0 11 14H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2z"}],["path",{d:"M6 14a12 12 0 0 0 2.4 7.2 2 2 0 0 0 3.2-2.4A8 8 0 0 1 10 14"}],["path",{d:"M8 6v8"}]],Fn=[["circle",{cx:"12",cy:"12",r:"10"}],["line",{x1:"8",x2:"16",y1:"15",y2:"15"}],["line",{x1:"9",x2:"9.01",y1:"9",y2:"9"}],["line",{x1:"15",x2:"15.01",y1:"9",y2:"9"}]],zn=[["path",{d:"M6 19v-3"}],["path",{d:"M10 19v-3"}],["path",{d:"M14 19v-3"}],["path",{d:"M18 19v-3"}],["path",{d:"M8 11V9"}],["path",{d:"M16 11V9"}],["path",{d:"M12 11V9"}],["path",{d:"M2 15h20"}],["path",{d:"M2 7a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v1.1a2 2 0 0 0 0 3.837V17a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2v-5.1a2 2 0 0 0 0-3.837Z"}]],bn=[["path",{d:"M4 5h16"}],["path",{d:"M4 12h16"}],["path",{d:"M4 19h16"}]],Rn=[["path",{d:"m8 6 4-4 4 4"}],["path",{d:"M12 2v10.3a4 4 0 0 1-1.172 2.872L4 22"}],["path",{d:"m20 22-5-5"}]],Tn=[["path",{d:"m10 9-3 3 3 3"}],["path",{d:"m14 15 3-3-3-3"}],["path",{d:"M2.992 16.342a2 2 0 0 1 .094 1.167l-1.065 3.29a1 1 0 0 0 1.236 1.168l3.413-.998a2 2 0 0 1 1.099.092 10 10 0 1 0-4.777-4.719"}]],qn=[["path",{d:"M10.1 2.182a10 10 0 0 1 3.8 0"}],["path",{d:"M13.9 21.818a10 10 0 0 1-3.8 0"}],["path",{d:"M17.609 3.72a10 10 0 0 1 2.69 2.7"}],["path",{d:"M2.182 13.9a10 10 0 0 1 0-3.8"}],["path",{d:"M20.28 17.61a10 10 0 0 1-2.7 2.69"}],["path",{d:"M21.818 10.1a10 10 0 0 1 0 3.8"}],["path",{d:"M3.721 6.391a10 10 0 0 1 2.7-2.69"}],["path",{d:"m6.163 21.117-2.906.85a1 1 0 0 1-1.236-1.169l.965-2.98"}]],Un=[["path",{d:"M2.992 16.342a2 2 0 0 1 .094 1.167l-1.065 3.29a1 1 0 0 0 1.236 1.168l3.413-.998a2 2 0 0 1 1.099.092 10 10 0 1 0-4.777-4.719"}],["path",{d:"M7.828 13.07A3 3 0 0 1 12 8.764a3 3 0 0 1 5.004 2.224 3 3 0 0 1-.832 2.083l-3.447 3.62a1 1 0 0 1-1.45-.001z"}]],On=[["path",{d:"M2.992 16.342a2 2 0 0 1 .094 1.167l-1.065 3.29a1 1 0 0 0 1.236 1.168l3.413-.998a2 2 0 0 1 1.099.092 10 10 0 1 0-4.777-4.719"}],["path",{d:"M8 12h.01"}],["path",{d:"M12 12h.01"}],["path",{d:"M16 12h.01"}]],Zn=[["path",{d:"m2 2 20 20"}],["path",{d:"M4.93 4.929a10 10 0 0 0-1.938 11.412 2 2 0 0 1 .094 1.167l-1.065 3.29a1 1 0 0 0 1.236 1.168l3.413-.998a2 2 0 0 1 1.099.092 10 10 0 0 0 11.302-1.989"}],["path",{d:"M8.35 2.69A10 10 0 0 1 21.3 15.65"}]],Gn=[["path",{d:"M2.992 16.342a2 2 0 0 1 .094 1.167l-1.065 3.29a1 1 0 0 0 1.236 1.168l3.413-.998a2 2 0 0 1 1.099.092 10 10 0 1 0-4.777-4.719"}],["path",{d:"M8 12h8"}],["path",{d:"M12 8v8"}]],v2=[["path",{d:"M2.992 16.342a2 2 0 0 1 .094 1.167l-1.065 3.29a1 1 0 0 0 1.236 1.168l3.413-.998a2 2 0 0 1 1.099.092 10 10 0 1 0-4.777-4.719"}],["path",{d:"M9.09 9a3 3 0 0 1 5.83 1c0 2-3 3-3 3"}],["path",{d:"M12 17h.01"}]],In=[["path",{d:"M2.992 16.342a2 2 0 0 1 .094 1.167l-1.065 3.29a1 1 0 0 0 1.236 1.168l3.413-.998a2 2 0 0 1 1.099.092 10 10 0 1 0-4.777-4.719"}],["path",{d:"m10 15-3-3 3-3"}],["path",{d:"M7 12h8a2 2 0 0 1 2 2v1"}]],Wn=[["path",{d:"M2.992 16.342a2 2 0 0 1 .094 1.167l-1.065 3.29a1 1 0 0 0 1.236 1.168l3.413-.998a2 2 0 0 1 1.099.092 10 10 0 1 0-4.777-4.719"}],["path",{d:"M12 8v4"}],["path",{d:"M12 16h.01"}]],En=[["path",{d:"M2.992 16.342a2 2 0 0 1 .094 1.167l-1.065 3.29a1 1 0 0 0 1.236 1.168l3.413-.998a2 2 0 0 1 1.099.092 10 10 0 1 0-4.777-4.719"}],["path",{d:"m15 9-6 6"}],["path",{d:"m9 9 6 6"}]],Xn=[["path",{d:"M2.992 16.342a2 2 0 0 1 .094 1.167l-1.065 3.29a1 1 0 0 0 1.236 1.168l3.413-.998a2 2 0 0 1 1.099.092 10 10 0 1 0-4.777-4.719"}]],jn=[["path",{d:"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2z"}],["path",{d:"m10 8-3 3 3 3"}],["path",{d:"m14 14 3-3-3-3"}]],Nn=[["path",{d:"M12 19h.01"}],["path",{d:"M12 3h.01"}],["path",{d:"M16 19h.01"}],["path",{d:"M16 3h.01"}],["path",{d:"M2 13h.01"}],["path",{d:"M2 17v4.286a.71.71 0 0 0 1.212.502l2.202-2.202A2 2 0 0 1 6.828 19H8"}],["path",{d:"M2 5a2 2 0 0 1 2-2"}],["path",{d:"M2 9h.01"}],["path",{d:"M20 3a2 2 0 0 1 2 2"}],["path",{d:"M22 13h.01"}],["path",{d:"M22 17a2 2 0 0 1-2 2"}],["path",{d:"M22 9h.01"}],["path",{d:"M8 3h.01"}]],Kn=[["path",{d:"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2z"}],["path",{d:"M10 15h4"}],["path",{d:"M10 9h4"}],["path",{d:"M12 7v4"}]],Qn=[["path",{d:"M12.7 3H4a2 2 0 0 0-2 2v16.286a.71.71 0 0 0 1.212.502l2.202-2.202A2 2 0 0 1 6.828 19H20a2 2 0 0 0 2-2v-4.7"}],["circle",{cx:"19",cy:"6",r:"3"}]],Jn=[["path",{d:"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2z"}],["path",{d:"M7.5 9.5c0 .687.265 1.383.697 1.844l3.009 3.264a1.14 1.14 0 0 0 .407.314 1 1 0 0 0 .783-.004 1.14 1.14 0 0 0 .398-.31l3.008-3.264A2.77 2.77 0 0 0 16.5 9.5 2.5 2.5 0 0 0 12 8a2.5 2.5 0 0 0-4.5 1.5"}]],Yn=[["path",{d:"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2z"}],["path",{d:"M12 11h.01"}],["path",{d:"M16 11h.01"}],["path",{d:"M8 11h.01"}]],_n=[["path",{d:"M22 8.5V5a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v16.286a.71.71 0 0 0 1.212.502l2.202-2.202A2 2 0 0 1 6.828 19H10"}],["path",{d:"M20 15v-2a2 2 0 0 0-4 0v2"}],["rect",{x:"14",y:"15",width:"8",height:"5",rx:"1"}]],xn=[["path",{d:"M19 19H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.7.7 0 0 1 2 21.286V5a2 2 0 0 1 1.184-1.826"}],["path",{d:"m2 2 20 20"}],["path",{d:"M8.656 3H20a2 2 0 0 1 2 2v11.344"}]],al=[["path",{d:"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2z"}],["path",{d:"M12 8v6"}],["path",{d:"M9 11h6"}]],tl=[["path",{d:"M14 14a2 2 0 0 0 2-2V8h-2"}],["path",{d:"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2z"}],["path",{d:"M8 14a2 2 0 0 0 2-2V8H8"}]],hl=[["path",{d:"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2z"}],["path",{d:"m10 8-3 3 3 3"}],["path",{d:"M17 14v-1a2 2 0 0 0-2-2H7"}]],dl=[["path",{d:"M12 3H4a2 2 0 0 0-2 2v16.286a.71.71 0 0 0 1.212.502l2.202-2.202A2 2 0 0 1 6.828 19H20a2 2 0 0 0 2-2v-4"}],["path",{d:"M16 3h6v6"}],["path",{d:"m16 9 6-6"}]],cl=[["path",{d:"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2z"}],["path",{d:"M7 11h10"}],["path",{d:"M7 15h6"}],["path",{d:"M7 7h8"}]],Ml=[["path",{d:"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2z"}],["path",{d:"M12 15h.01"}],["path",{d:"M12 7v4"}]],pl=[["path",{d:"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2z"}],["path",{d:"m14.5 8.5-5 5"}],["path",{d:"m9.5 8.5 5 5"}]],il=[["path",{d:"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2z"}]],nl=[["path",{d:"M16 10a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 14.286V4a2 2 0 0 1 2-2h10a2 2 0 0 1 2 2z"}],["path",{d:"M20 9a2 2 0 0 1 2 2v10.286a.71.71 0 0 1-1.212.502l-2.202-2.202A2 2 0 0 0 17.172 19H10a2 2 0 0 1-2-2v-1"}]],$2=[["path",{d:"m11 7.601-5.994 8.19a1 1 0 0 0 .1 1.298l.817.818a1 1 0 0 0 1.314.087L15.09 12"}],["path",{d:"M16.5 21.174C15.5 20.5 14.372 20 13 20c-2.058 0-3.928 2.356-6 2-2.072-.356-2.775-3.369-1.5-4.5"}],["circle",{cx:"16",cy:"7",r:"5"}]],ll=[["path",{d:"M12 19v3"}],["path",{d:"M15 9.34V5a3 3 0 0 0-5.68-1.33"}],["path",{d:"M16.95 16.95A7 7 0 0 1 5 12v-2"}],["path",{d:"M18.89 13.23A7 7 0 0 0 19 12v-2"}],["path",{d:"m2 2 20 20"}],["path",{d:"M9 9v3a3 3 0 0 0 5.12 2.12"}]],el=[["path",{d:"M12 19v3"}],["path",{d:"M19 10v2a7 7 0 0 1-14 0v-2"}],["rect",{x:"9",y:"2",width:"6",height:"13",rx:"3"}]],rl=[["path",{d:"M18 12h2"}],["path",{d:"M18 16h2"}],["path",{d:"M18 20h2"}],["path",{d:"M18 4h2"}],["path",{d:"M18 8h2"}],["path",{d:"M4 12h2"}],["path",{d:"M4 16h2"}],["path",{d:"M4 20h2"}],["path",{d:"M4 4h2"}],["path",{d:"M4 8h2"}],["path",{d:"M8 2a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h8a2 2 0 0 0 2-2V4a2 2 0 0 0-2-2h-1.5c-.276 0-.494.227-.562.495a2 2 0 0 1-3.876 0C9.994 2.227 9.776 2 9.5 2z"}]],ol=[["path",{d:"M6 18h8"}],["path",{d:"M3 22h18"}],["path",{d:"M14 22a7 7 0 1 0 0-14h-1"}],["path",{d:"M9 14h2"}],["path",{d:"M9 12a2 2 0 0 1-2-2V6h6v4a2 2 0 0 1-2 2Z"}],["path",{d:"M12 6V3a1 1 0 0 0-1-1H9a1 1 0 0 0-1 1v3"}]],vl=[["rect",{width:"20",height:"15",x:"2",y:"4",rx:"2"}],["rect",{width:"8",height:"7",x:"6",y:"8",rx:"1"}],["path",{d:"M18 8v7"}],["path",{d:"M6 19v2"}],["path",{d:"M18 19v2"}]],$l=[["path",{d:"M12 13v8"}],["path",{d:"M12 3v3"}],["path",{d:"M4 6a1 1 0 0 0-1 1v5a1 1 0 0 0 1 1h13a2 2 0 0 0 1.152-.365l3.424-2.317a1 1 0 0 0 0-1.635l-3.424-2.318A2 2 0 0 0 17 6z"}]],ml=[["path",{d:"M8 2h8"}],["path",{d:"M9 2v1.343M15 2v2.789a4 4 0 0 0 .672 2.219l.656.984a4 4 0 0 1 .672 2.22v1.131M7.8 7.8l-.128.192A4 4 0 0 0 7 10.212V20a2 2 0 0 0 2 2h6a2 2 0 0 0 2-2v-3"}],["path",{d:"M7 15a6.47 6.47 0 0 1 5 0 6.472 6.472 0 0 0 3.435.435"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],yl=[["path",{d:"M8 2h8"}],["path",{d:"M9 2v2.789a4 4 0 0 1-.672 2.219l-.656.984A4 4 0 0 0 7 10.212V20a2 2 0 0 0 2 2h6a2 2 0 0 0 2-2v-9.789a4 4 0 0 0-.672-2.219l-.656-.984A4 4 0 0 1 15 4.788V2"}],["path",{d:"M7 15a6.472 6.472 0 0 1 5 0 6.47 6.47 0 0 0 5 0"}]],sl=[["path",{d:"m14 10 7-7"}],["path",{d:"M20 10h-6V4"}],["path",{d:"m3 21 7-7"}],["path",{d:"M4 14h6v6"}]],gl=[["path",{d:"M8 3v3a2 2 0 0 1-2 2H3"}],["path",{d:"M21 8h-3a2 2 0 0 1-2-2V3"}],["path",{d:"M3 16h3a2 2 0 0 1 2 2v3"}],["path",{d:"M16 21v-3a2 2 0 0 1 2-2h3"}]],ul=[["path",{d:"M5 12h14"}]],Cl=[["path",{d:"m9 10 2 2 4-4"}],["rect",{width:"20",height:"14",x:"2",y:"3",rx:"2"}],["path",{d:"M12 17v4"}],["path",{d:"M8 21h8"}]],Hl=[["path",{d:"M12 17v4"}],["path",{d:"m14.305 7.53.923-.382"}],["path",{d:"m15.228 4.852-.923-.383"}],["path",{d:"m16.852 3.228-.383-.924"}],["path",{d:"m16.852 8.772-.383.923"}],["path",{d:"m19.148 3.228.383-.924"}],["path",{d:"m19.53 9.696-.382-.924"}],["path",{d:"m20.772 4.852.924-.383"}],["path",{d:"m20.772 7.148.924.383"}],["path",{d:"M22 13v2a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h7"}],["path",{d:"M8 21h8"}],["circle",{cx:"18",cy:"6",r:"3"}]],Al=[["path",{d:"M12 17v4"}],["path",{d:"M22 12.307V15a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h8.693"}],["path",{d:"M8 21h8"}],["circle",{cx:"19",cy:"6",r:"3"}]],wl=[["path",{d:"M12 13V7"}],["path",{d:"m15 10-3 3-3-3"}],["rect",{width:"20",height:"14",x:"2",y:"3",rx:"2"}],["path",{d:"M12 17v4"}],["path",{d:"M8 21h8"}]],Vl=[["path",{d:"M17 17H4a2 2 0 0 1-2-2V5c0-1.5 1-2 1-2"}],["path",{d:"M22 15V5a2 2 0 0 0-2-2H9"}],["path",{d:"M8 21h8"}],["path",{d:"M12 17v4"}],["path",{d:"m2 2 20 20"}]],Sl=[["path",{d:"M10 13V7"}],["path",{d:"M14 13V7"}],["rect",{width:"20",height:"14",x:"2",y:"3",rx:"2"}],["path",{d:"M12 17v4"}],["path",{d:"M8 21h8"}]],Ll=[["path",{d:"M15.033 9.44a.647.647 0 0 1 0 1.12l-4.065 2.352a.645.645 0 0 1-.968-.56V7.648a.645.645 0 0 1 .967-.56z"}],["path",{d:"M12 17v4"}],["path",{d:"M8 21h8"}],["rect",{x:"2",y:"3",width:"20",height:"14",rx:"2"}]],fl=[["path",{d:"M18 8V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v7a2 2 0 0 0 2 2h8"}],["path",{d:"M10 19v-3.96 3.15"}],["path",{d:"M7 19h5"}],["rect",{width:"6",height:"10",x:"16",y:"12",rx:"2"}]],kl=[["path",{d:"M5.5 20H8"}],["path",{d:"M17 9h.01"}],["rect",{width:"10",height:"16",x:"12",y:"4",rx:"2"}],["path",{d:"M8 6H4a2 2 0 0 0-2 2v6a2 2 0 0 0 2 2h4"}],["circle",{cx:"17",cy:"15",r:"1"}]],Pl=[["path",{d:"M12 17v4"}],["path",{d:"M8 21h8"}],["rect",{x:"2",y:"3",width:"20",height:"14",rx:"2"}],["rect",{x:"9",y:"7",width:"6",height:"6",rx:"1"}]],Bl=[["path",{d:"m9 10 3-3 3 3"}],["path",{d:"M12 13V7"}],["rect",{width:"20",height:"14",x:"2",y:"3",rx:"2"}],["path",{d:"M12 17v4"}],["path",{d:"M8 21h8"}]],Dl=[["path",{d:"m14.5 12.5-5-5"}],["path",{d:"m9.5 12.5 5-5"}],["rect",{width:"20",height:"14",x:"2",y:"3",rx:"2"}],["path",{d:"M12 17v4"}],["path",{d:"M8 21h8"}]],Fl=[["path",{d:"M18 5h4"}],["path",{d:"M20 3v4"}],["path",{d:"M20.985 12.486a9 9 0 1 1-9.473-9.472c.405-.022.617.46.402.803a6 6 0 0 0 8.268 8.268c.344-.215.825-.004.803.401"}]],zl=[["rect",{width:"20",height:"14",x:"2",y:"3",rx:"2"}],["line",{x1:"8",x2:"16",y1:"21",y2:"21"}],["line",{x1:"12",x2:"12",y1:"17",y2:"21"}]],bl=[["path",{d:"M20.985 12.486a9 9 0 1 1-9.473-9.472c.405-.022.617.46.402.803a6 6 0 0 0 8.268 8.268c.344-.215.825-.004.803.401"}]],Rl=[["path",{d:"m18 14-1-3"}],["path",{d:"m3 9 6 2a2 2 0 0 1 2-2h2a2 2 0 0 1 1.99 1.81"}],["path",{d:"M8 17h3a1 1 0 0 0 1-1 6 6 0 0 1 6-6 1 1 0 0 0 1-1v-.75A5 5 0 0 0 17 5"}],["circle",{cx:"19",cy:"17",r:"3"}],["circle",{cx:"5",cy:"17",r:"3"}]],Tl=[["path",{d:"m8 3 4 8 5-5 5 15H2L8 3z"}],["path",{d:"M4.14 15.08c2.62-1.57 5.24-1.43 7.86.42 2.74 1.94 5.49 2 8.23.19"}]],ql=[["path",{d:"m8 3 4 8 5-5 5 15H2L8 3z"}]],Ul=[["path",{d:"M12 6v.343"}],["path",{d:"M18.218 18.218A7 7 0 0 1 5 15V9a7 7 0 0 1 .782-3.218"}],["path",{d:"M19 13.343V9A7 7 0 0 0 8.56 2.902"}],["path",{d:"M22 22 2 2"}]],Ol=[["path",{d:"M4.037 4.688a.495.495 0 0 1 .651-.651l16 6.5a.5.5 0 0 1-.063.947l-6.124 1.58a2 2 0 0 0-1.438 1.435l-1.579 6.126a.5.5 0 0 1-.947.063z"}]],Zl=[["path",{d:"M2.034 2.681a.498.498 0 0 1 .647-.647l9 3.5a.5.5 0 0 1-.033.944L8.204 7.545a1 1 0 0 0-.66.66l-1.066 3.443a.5.5 0 0 1-.944.033z"}],["circle",{cx:"16",cy:"16",r:"6"}],["path",{d:"m11.8 11.8 8.4 8.4"}]],Gl=[["path",{d:"M14 4.1 12 6"}],["path",{d:"m5.1 8-2.9-.8"}],["path",{d:"m6 12-1.9 2"}],["path",{d:"M7.2 2.2 8 5.1"}],["path",{d:"M9.037 9.69a.498.498 0 0 1 .653-.653l11 4.5a.5.5 0 0 1-.074.949l-4.349 1.041a1 1 0 0 0-.74.739l-1.04 4.35a.5.5 0 0 1-.95.074z"}]],Il=[["path",{d:"M12.586 12.586 19 19"}],["path",{d:"M3.688 3.037a.497.497 0 0 0-.651.651l6.5 15.999a.501.501 0 0 0 .947-.062l1.569-6.083a2 2 0 0 1 1.448-1.479l6.124-1.579a.5.5 0 0 0 .063-.947z"}]],Wl=[["rect",{x:"5",y:"2",width:"14",height:"20",rx:"7"}],["path",{d:"M12 6v4"}]],m2=[["path",{d:"M5 3v16h16"}],["path",{d:"m5 19 6-6"}],["path",{d:"m2 6 3-3 3 3"}],["path",{d:"m18 16 3 3-3 3"}]],El=[["path",{d:"M19 13v6h-6"}],["path",{d:"M5 11V5h6"}],["path",{d:"m5 5 14 14"}]],Xl=[["path",{d:"M11 19H5v-6"}],["path",{d:"M13 5h6v6"}],["path",{d:"M19 5 5 19"}]],jl=[["path",{d:"M11 19H5V13"}],["path",{d:"M19 5L5 19"}]],Nl=[["path",{d:"M19 13V19H13"}],["path",{d:"M5 5L19 19"}]],Kl=[["path",{d:"M8 18L12 22L16 18"}],["path",{d:"M12 2V22"}]],Ql=[["path",{d:"m18 8 4 4-4 4"}],["path",{d:"M2 12h20"}],["path",{d:"m6 8-4 4 4 4"}]],Jl=[["path",{d:"M6 8L2 12L6 16"}],["path",{d:"M2 12H22"}]],Yl=[["path",{d:"M18 8L22 12L18 16"}],["path",{d:"M2 12H22"}]],_l=[["path",{d:"M13 5H19V11"}],["path",{d:"M19 5L5 19"}]],xl=[["path",{d:"M5 11V5H11"}],["path",{d:"M5 5L19 19"}]],ae=[["path",{d:"M8 6L12 2L16 6"}],["path",{d:"M12 2V22"}]],te=[["path",{d:"M12 2v20"}],["path",{d:"m8 18 4 4 4-4"}],["path",{d:"m8 6 4-4 4 4"}]],he=[["path",{d:"M12 2v20"}],["path",{d:"m15 19-3 3-3-3"}],["path",{d:"m19 9 3 3-3 3"}],["path",{d:"M2 12h20"}],["path",{d:"m5 9-3 3 3 3"}],["path",{d:"m9 5 3-3 3 3"}]],de=[["circle",{cx:"8",cy:"18",r:"4"}],["path",{d:"M12 18V2l7 4"}]],ce=[["circle",{cx:"12",cy:"18",r:"4"}],["path",{d:"M16 18V2"}]],Me=[["path",{d:"M9 18V5l12-2v13"}],["path",{d:"m9 9 12-2"}],["circle",{cx:"6",cy:"18",r:"3"}],["circle",{cx:"18",cy:"16",r:"3"}]],pe=[["path",{d:"M9 18V5l12-2v13"}],["circle",{cx:"6",cy:"18",r:"3"}],["circle",{cx:"18",cy:"16",r:"3"}]],ie=[["path",{d:"M9.31 9.31 5 21l7-4 7 4-1.17-3.17"}],["path",{d:"M14.53 8.88 12 2l-1.17 3.17"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],ne=[["polygon",{points:"12 2 19 21 12 17 5 21 12 2"}]],le=[["path",{d:"M8.43 8.43 3 11l8 2 2 8 2.57-5.43"}],["path",{d:"M17.39 11.73 22 2l-9.73 4.61"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],ee=[["polygon",{points:"3 11 22 2 13 21 11 13 3 11"}]],re=[["rect",{x:"16",y:"16",width:"6",height:"6",rx:"1"}],["rect",{x:"2",y:"16",width:"6",height:"6",rx:"1"}],["rect",{x:"9",y:"2",width:"6",height:"6",rx:"1"}],["path",{d:"M5 16v-3a1 1 0 0 1 1-1h12a1 1 0 0 1 1 1v3"}],["path",{d:"M12 12V8"}]],oe=[["path",{d:"M15 18h-5"}],["path",{d:"M18 14h-8"}],["path",{d:"M4 22h16a2 2 0 0 0 2-2V4a2 2 0 0 0-2-2H8a2 2 0 0 0-2 2v16a2 2 0 0 1-4 0v-9a2 2 0 0 1 2-2h2"}],["rect",{width:"8",height:"4",x:"10",y:"6",rx:"1"}]],ve=[["path",{d:"M6 8.32a7.43 7.43 0 0 1 0 7.36"}],["path",{d:"M9.46 6.21a11.76 11.76 0 0 1 0 11.58"}],["path",{d:"M12.91 4.1a15.91 15.91 0 0 1 .01 15.8"}],["path",{d:"M16.37 2a20.16 20.16 0 0 1 0 20"}]],$e=[["path",{d:"M12 2v10"}],["path",{d:"m8.5 4 7 4"}],["path",{d:"m8.5 8 7-4"}],["circle",{cx:"12",cy:"17",r:"5"}]],me=[["path",{d:"M13.4 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2v-7.4"}],["path",{d:"M2 6h4"}],["path",{d:"M2 10h4"}],["path",{d:"M2 14h4"}],["path",{d:"M2 18h4"}],["path",{d:"M21.378 5.626a1 1 0 1 0-3.004-3.004l-5.01 5.012a2 2 0 0 0-.506.854l-.837 2.87a.5.5 0 0 0 .62.62l2.87-.837a2 2 0 0 0 .854-.506z"}]],ye=[["path",{d:"M2 6h4"}],["path",{d:"M2 10h4"}],["path",{d:"M2 14h4"}],["path",{d:"M2 18h4"}],["rect",{width:"16",height:"20",x:"4",y:"2",rx:"2"}],["path",{d:"M15 2v20"}],["path",{d:"M15 7h5"}],["path",{d:"M15 12h5"}],["path",{d:"M15 17h5"}]],se=[["path",{d:"M2 6h4"}],["path",{d:"M2 10h4"}],["path",{d:"M2 14h4"}],["path",{d:"M2 18h4"}],["rect",{width:"16",height:"20",x:"4",y:"2",rx:"2"}],["path",{d:"M9.5 8h5"}],["path",{d:"M9.5 12H16"}],["path",{d:"M9.5 16H14"}]],ge=[["path",{d:"M2 6h4"}],["path",{d:"M2 10h4"}],["path",{d:"M2 14h4"}],["path",{d:"M2 18h4"}],["rect",{width:"16",height:"20",x:"4",y:"2",rx:"2"}],["path",{d:"M16 2v20"}]],ue=[["path",{d:"M8 2v4"}],["path",{d:"M12 2v4"}],["path",{d:"M16 2v4"}],["path",{d:"M16 4h2a2 2 0 0 1 2 2v2"}],["path",{d:"M20 12v2"}],["path",{d:"M20 18v2a2 2 0 0 1-2 2h-1"}],["path",{d:"M13 22h-2"}],["path",{d:"M7 22H6a2 2 0 0 1-2-2v-2"}],["path",{d:"M4 14v-2"}],["path",{d:"M4 8V6a2 2 0 0 1 2-2h2"}],["path",{d:"M8 10h6"}],["path",{d:"M8 14h8"}],["path",{d:"M8 18h5"}]],Ce=[["path",{d:"M8 2v4"}],["path",{d:"M12 2v4"}],["path",{d:"M16 2v4"}],["rect",{width:"16",height:"18",x:"4",y:"4",rx:"2"}],["path",{d:"M8 10h6"}],["path",{d:"M8 14h8"}],["path",{d:"M8 18h5"}]],He=[["path",{d:"M12 4V2"}],["path",{d:"M5 10v4a7.004 7.004 0 0 0 5.277 6.787c.412.104.802.292 1.102.592L12 22l.621-.621c.3-.3.69-.488 1.102-.592a7.01 7.01 0 0 0 4.125-2.939"}],["path",{d:"M19 10v3.343"}],["path",{d:"M12 12c-1.349-.573-1.905-1.005-2.5-2-.546.902-1.048 1.353-2.5 2-1.018-.644-1.46-1.08-2-2-1.028.71-1.69.918-3 1 1.081-1.048 1.757-2.03 2-3 .194-.776.84-1.551 1.79-2.21m11.654 5.997c.887-.457 1.28-.891 1.556-1.787 1.032.916 1.683 1.157 3 1-1.297-1.036-1.758-2.03-2-3-.5-2-4-4-8-4-.74 0-1.461.068-2.15.192"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],Ae=[["path",{d:"M12 4V2"}],["path",{d:"M5 10v4a7.004 7.004 0 0 0 5.277 6.787c.412.104.802.292 1.102.592L12 22l.621-.621c.3-.3.69-.488 1.102-.592A7.003 7.003 0 0 0 19 14v-4"}],["path",{d:"M12 4C8 4 4.5 6 4 8c-.243.97-.919 1.952-2 3 1.31-.082 1.972-.29 3-1 .54.92.982 1.356 2 2 1.452-.647 1.954-1.098 2.5-2 .595.995 1.151 1.427 2.5 2 1.31-.621 1.862-1.058 2.5-2 .629.977 1.162 1.423 2.5 2 1.209-.548 1.68-.967 2-2 1.032.916 1.683 1.157 3 1-1.297-1.036-1.758-2.03-2-3-.5-2-4-4-8-4Z"}]],y2=[["path",{d:"M12 16h.01"}],["path",{d:"M12 8v4"}],["path",{d:"M15.312 2a2 2 0 0 1 1.414.586l4.688 4.688A2 2 0 0 1 22 8.688v6.624a2 2 0 0 1-.586 1.414l-4.688 4.688a2 2 0 0 1-1.414.586H8.688a2 2 0 0 1-1.414-.586l-4.688-4.688A2 2 0 0 1 2 15.312V8.688a2 2 0 0 1 .586-1.414l4.688-4.688A2 2 0 0 1 8.688 2z"}]],we=[["path",{d:"M2.586 16.726A2 2 0 0 1 2 15.312V8.688a2 2 0 0 1 .586-1.414l4.688-4.688A2 2 0 0 1 8.688 2h6.624a2 2 0 0 1 1.414.586l4.688 4.688A2 2 0 0 1 22 8.688v6.624a2 2 0 0 1-.586 1.414l-4.688 4.688a2 2 0 0 1-1.414.586H8.688a2 2 0 0 1-1.414-.586z"}],["path",{d:"M8 12h8"}]],s2=[["path",{d:"M10 15V9"}],["path",{d:"M14 15V9"}],["path",{d:"M2.586 16.726A2 2 0 0 1 2 15.312V8.688a2 2 0 0 1 .586-1.414l4.688-4.688A2 2 0 0 1 8.688 2h6.624a2 2 0 0 1 1.414.586l4.688 4.688A2 2 0 0 1 22 8.688v6.624a2 2 0 0 1-.586 1.414l-4.688 4.688a2 2 0 0 1-1.414.586H8.688a2 2 0 0 1-1.414-.586z"}]],g2=[["path",{d:"m15 9-6 6"}],["path",{d:"M2.586 16.726A2 2 0 0 1 2 15.312V8.688a2 2 0 0 1 .586-1.414l4.688-4.688A2 2 0 0 1 8.688 2h6.624a2 2 0 0 1 1.414.586l4.688 4.688A2 2 0 0 1 22 8.688v6.624a2 2 0 0 1-.586 1.414l-4.688 4.688a2 2 0 0 1-1.414.586H8.688a2 2 0 0 1-1.414-.586z"}],["path",{d:"m9 9 6 6"}]],Ve=[["path",{d:"M2.586 16.726A2 2 0 0 1 2 15.312V8.688a2 2 0 0 1 .586-1.414l4.688-4.688A2 2 0 0 1 8.688 2h6.624a2 2 0 0 1 1.414.586l4.688 4.688A2 2 0 0 1 22 8.688v6.624a2 2 0 0 1-.586 1.414l-4.688 4.688a2 2 0 0 1-1.414.586H8.688a2 2 0 0 1-1.414-.586z"}]],Se=[["path",{d:"M3 20h4.5a.5.5 0 0 0 .5-.5v-.282a.52.52 0 0 0-.247-.437 8 8 0 1 1 8.494-.001.52.52 0 0 0-.247.438v.282a.5.5 0 0 0 .5.5H21"}]],Le=[["path",{d:"M20.341 6.484A10 10 0 0 1 10.266 21.85"}],["path",{d:"M3.659 17.516A10 10 0 0 1 13.74 2.152"}],["circle",{cx:"12",cy:"12",r:"3"}],["circle",{cx:"19",cy:"5",r:"2"}],["circle",{cx:"5",cy:"19",r:"2"}]],fe=[["path",{d:"M3 3h6l6 18h6"}],["path",{d:"M14 3h7"}]],ke=[["path",{d:"M12 12V4a1 1 0 0 1 1-1h6.297a1 1 0 0 1 .651 1.759l-4.696 4.025"}],["path",{d:"m12 21-7.414-7.414A2 2 0 0 1 4 12.172V6.415a1.002 1.002 0 0 1 1.707-.707L20 20.009"}],["path",{d:"m12.214 3.381 8.414 14.966a1 1 0 0 1-.167 1.199l-1.168 1.163a1 1 0 0 1-.706.291H6.351a1 1 0 0 1-.625-.219L3.25 18.8a1 1 0 0 1 .631-1.781l4.165.027"}]],Pe=[["path",{d:"M12 3v6"}],["path",{d:"M16.76 3a2 2 0 0 1 1.8 1.1l2.23 4.479a2 2 0 0 1 .21.891V19a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V9.472a2 2 0 0 1 .211-.894L5.45 4.1A2 2 0 0 1 7.24 3z"}],["path",{d:"M3.054 9.013h17.893"}]],Be=[["path",{d:"m16 16 2 2 4-4"}],["path",{d:"M21 10V8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73l7 4a2 2 0 0 0 2 0l2-1.14"}],["path",{d:"m7.5 4.27 9 5.15"}],["polyline",{points:"3.29 7 12 12 20.71 7"}],["line",{x1:"12",x2:"12",y1:"22",y2:"12"}]],De=[["path",{d:"M16 16h6"}],["path",{d:"M21 10V8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73l7 4a2 2 0 0 0 2 0l2-1.14"}],["path",{d:"m7.5 4.27 9 5.15"}],["polyline",{points:"3.29 7 12 12 20.71 7"}],["line",{x1:"12",x2:"12",y1:"22",y2:"12"}]],Fe=[["path",{d:"M16 16h6"}],["path",{d:"M19 13v6"}],["path",{d:"M21 10V8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73l7 4a2 2 0 0 0 2 0l2-1.14"}],["path",{d:"m7.5 4.27 9 5.15"}],["polyline",{points:"3.29 7 12 12 20.71 7"}],["line",{x1:"12",x2:"12",y1:"22",y2:"12"}]],ze=[["path",{d:"M12 22v-9"}],["path",{d:"M15.17 2.21a1.67 1.67 0 0 1 1.63 0L21 4.57a1.93 1.93 0 0 1 0 3.36L8.82 14.79a1.655 1.655 0 0 1-1.64 0L3 12.43a1.93 1.93 0 0 1 0-3.36z"}],["path",{d:"M20 13v3.87a2.06 2.06 0 0 1-1.11 1.83l-6 3.08a1.93 1.93 0 0 1-1.78 0l-6-3.08A2.06 2.06 0 0 1 4 16.87V13"}],["path",{d:"M21 12.43a1.93 1.93 0 0 0 0-3.36L8.83 2.2a1.64 1.64 0 0 0-1.63 0L3 4.57a1.93 1.93 0 0 0 0 3.36l12.18 6.86a1.636 1.636 0 0 0 1.63 0z"}]],be=[["path",{d:"M21 10V8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73l7 4a2 2 0 0 0 2 0l2-1.14"}],["path",{d:"m7.5 4.27 9 5.15"}],["polyline",{points:"3.29 7 12 12 20.71 7"}],["line",{x1:"12",x2:"12",y1:"22",y2:"12"}],["circle",{cx:"18.5",cy:"15.5",r:"2.5"}],["path",{d:"M20.27 17.27 22 19"}]],Re=[["path",{d:"M21 10V8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73l7 4a2 2 0 0 0 2 0l2-1.14"}],["path",{d:"m7.5 4.27 9 5.15"}],["polyline",{points:"3.29 7 12 12 20.71 7"}],["line",{x1:"12",x2:"12",y1:"22",y2:"12"}],["path",{d:"m17 13 5 5m-5 0 5-5"}]],Te=[["path",{d:"M11 21.73a2 2 0 0 0 2 0l7-4A2 2 0 0 0 21 16V8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73z"}],["path",{d:"M12 22V12"}],["polyline",{points:"3.29 7 12 12 20.71 7"}],["path",{d:"m7.5 4.27 9 5.15"}]],qe=[["path",{d:"m19 11-8-8-8.6 8.6a2 2 0 0 0 0 2.8l5.2 5.2c.8.8 2 .8 2.8 0L19 11Z"}],["path",{d:"m5 2 5 5"}],["path",{d:"M2 13h15"}],["path",{d:"M22 20a2 2 0 1 1-4 0c0-1.6 1.7-2.4 2-4 .3 1.6 2 2.4 2 4Z"}]],Ue=[["rect",{width:"16",height:"6",x:"2",y:"2",rx:"2"}],["path",{d:"M10 16v-2a2 2 0 0 1 2-2h8a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2h-2"}],["rect",{width:"4",height:"6",x:"8",y:"16",rx:"1"}]],u2=[["path",{d:"M10 2v2"}],["path",{d:"M14 2v4"}],["path",{d:"M17 2a1 1 0 0 1 1 1v9H6V3a1 1 0 0 1 1-1z"}],["path",{d:"M6 12a1 1 0 0 0-1 1v1a2 2 0 0 0 2 2h2a1 1 0 0 1 1 1v2.9a2 2 0 1 0 4 0V17a1 1 0 0 1 1-1h2a2 2 0 0 0 2-2v-1a1 1 0 0 0-1-1"}]],Oe=[["path",{d:"m14.622 17.897-10.68-2.913"}],["path",{d:"M18.376 2.622a1 1 0 1 1 3.002 3.002L17.36 9.643a.5.5 0 0 0 0 .707l.944.944a2.41 2.41 0 0 1 0 3.408l-.944.944a.5.5 0 0 1-.707 0L8.354 7.348a.5.5 0 0 1 0-.707l.944-.944a2.41 2.41 0 0 1 3.408 0l.944.944a.5.5 0 0 0 .707 0z"}],["path",{d:"M9 8c-1.804 2.71-3.97 3.46-6.583 3.948a.507.507 0 0 0-.302.819l7.32 8.883a1 1 0 0 0 1.185.204C12.735 20.405 16 16.792 16 15"}]],Ze=[["path",{d:"M12 22a1 1 0 0 1 0-20 10 9 0 0 1 10 9 5 5 0 0 1-5 5h-2.25a1.75 1.75 0 0 0-1.4 2.8l.3.4a1.75 1.75 0 0 1-1.4 2.8z"}],["circle",{cx:"13.5",cy:"6.5",r:".5",fill:"currentColor"}],["circle",{cx:"17.5",cy:"10.5",r:".5",fill:"currentColor"}],["circle",{cx:"6.5",cy:"12.5",r:".5",fill:"currentColor"}],["circle",{cx:"8.5",cy:"7.5",r:".5",fill:"currentColor"}]],Ge=[["path",{d:"M11.25 17.25h1.5L12 18z"}],["path",{d:"m15 12 2 2"}],["path",{d:"M18 6.5a.5.5 0 0 0-.5-.5"}],["path",{d:"M20.69 9.67a4.5 4.5 0 1 0-7.04-5.5 8.35 8.35 0 0 0-3.3 0 4.5 4.5 0 1 0-7.04 5.5C2.49 11.2 2 12.88 2 14.5 2 19.47 6.48 22 12 22s10-2.53 10-7.5c0-1.62-.48-3.3-1.3-4.83"}],["path",{d:"M6 6.5a.495.495 0 0 1 .5-.5"}],["path",{d:"m9 12-2 2"}]],C2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M14 15h1"}],["path",{d:"M19 15h2"}],["path",{d:"M3 15h2"}],["path",{d:"M9 15h1"}]],Ie=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 15h18"}],["path",{d:"m15 8-3 3-3-3"}]],We=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 15h18"}],["path",{d:"m9 10 3-3 3 3"}]],Ee=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 15h18"}]],H2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M9 3v18"}],["path",{d:"m16 15-3-3 3-3"}]],A2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M9 14v1"}],["path",{d:"M9 19v2"}],["path",{d:"M9 3v2"}],["path",{d:"M9 9v1"}]],w2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M9 3v18"}],["path",{d:"m14 9 3 3-3 3"}]],Xe=[["path",{d:"M15 10V9"}],["path",{d:"M15 15v-1"}],["path",{d:"M15 21v-2"}],["path",{d:"M15 5V3"}],["path",{d:"M9 10V9"}],["path",{d:"M9 15v-1"}],["path",{d:"M9 21v-2"}],["path",{d:"M9 5V3"}],["rect",{x:"3",y:"3",width:"18",height:"18",rx:"2"}]],V2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M9 3v18"}]],je=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M15 3v18"}],["path",{d:"m8 9 3 3-3 3"}]],S2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M15 14v1"}],["path",{d:"M15 19v2"}],["path",{d:"M15 3v2"}],["path",{d:"M15 9v1"}]],Ne=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M15 3v18"}],["path",{d:"m10 15-3-3 3-3"}]],Ke=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M15 3v18"}]],Qe=[["path",{d:"M14 15h1"}],["path",{d:"M14 9h1"}],["path",{d:"M19 15h2"}],["path",{d:"M19 9h2"}],["path",{d:"M3 15h2"}],["path",{d:"M3 9h2"}],["path",{d:"M9 15h1"}],["path",{d:"M9 9h1"}],["rect",{x:"3",y:"3",width:"18",height:"18",rx:"2"}]],Je=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 9h18"}],["path",{d:"m9 16 3-3 3 3"}]],L2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M14 9h1"}],["path",{d:"M19 9h2"}],["path",{d:"M3 9h2"}],["path",{d:"M9 9h1"}]],Ye=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 9h18"}],["path",{d:"m15 14-3 3-3-3"}]],_e=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 9h18"}]],xe=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M9 3v18"}],["path",{d:"M9 15h12"}]],ar=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 15h12"}],["path",{d:"M15 3v18"}]],f2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 9h18"}],["path",{d:"M9 21V9"}]],tr=[["path",{d:"M8 21s-4-3-4-9 4-9 4-9"}],["path",{d:"M16 3s4 3 4 9-4 9-4 9"}]],hr=[["path",{d:"m16 6-8.414 8.586a2 2 0 0 0 2.829 2.829l8.414-8.586a4 4 0 1 0-5.657-5.657l-8.379 8.551a6 6 0 1 0 8.485 8.485l8.379-8.551"}]],dr=[["path",{d:"M11 15h2"}],["path",{d:"M12 12v3"}],["path",{d:"M12 19v3"}],["path",{d:"M15.282 19a1 1 0 0 0 .948-.68l2.37-6.988a7 7 0 1 0-13.2 0l2.37 6.988a1 1 0 0 0 .948.68z"}],["path",{d:"M9 9a3 3 0 1 1 6 0"}]],cr=[["path",{d:"M5.8 11.3 2 22l10.7-3.79"}],["path",{d:"M4 3h.01"}],["path",{d:"M22 8h.01"}],["path",{d:"M15 2h.01"}],["path",{d:"M22 20h.01"}],["path",{d:"m22 2-2.24.75a2.9 2.9 0 0 0-1.96 3.12c.1.86-.57 1.63-1.45 1.63h-.38c-.86 0-1.6.6-1.76 1.44L14 10"}],["path",{d:"m22 13-.82-.33c-.86-.34-1.82.2-1.98 1.11c-.11.7-.72 1.22-1.43 1.22H17"}],["path",{d:"m11 2 .33.82c.34.86-.2 1.82-1.11 1.98C9.52 4.9 9 5.52 9 6.23V7"}],["path",{d:"M11 13c1.93 1.93 2.83 4.17 2 5-.83.83-3.07-.07-5-2-1.93-1.93-2.83-4.17-2-5 .83-.83 3.07.07 5 2Z"}]],Mr=[["rect",{x:"14",y:"3",width:"5",height:"18",rx:"1"}],["rect",{x:"5",y:"3",width:"5",height:"18",rx:"1"}]],pr=[["circle",{cx:"11",cy:"4",r:"2"}],["circle",{cx:"18",cy:"8",r:"2"}],["circle",{cx:"20",cy:"16",r:"2"}],["path",{d:"M9 10a5 5 0 0 1 5 5v3.5a3.5 3.5 0 0 1-6.84 1.045Q6.52 17.48 4.46 16.84A3.5 3.5 0 0 1 5.5 10Z"}]],k2=[["path",{d:"M13 21h8"}],["path",{d:"M21.174 6.812a1 1 0 0 0-3.986-3.987L3.842 16.174a2 2 0 0 0-.5.83l-1.321 4.352a.5.5 0 0 0 .623.622l4.353-1.32a2 2 0 0 0 .83-.497z"}]],ir=[["path",{d:"m10 10-6.157 6.162a2 2 0 0 0-.5.833l-1.322 4.36a.5.5 0 0 0 .622.624l4.358-1.323a2 2 0 0 0 .83-.5L14 13.982"}],["path",{d:"m12.829 7.172 4.359-4.346a1 1 0 1 1 3.986 3.986l-4.353 4.353"}],["path",{d:"m2 2 20 20"}]],nr=[["rect",{width:"14",height:"20",x:"5",y:"2",rx:"2"}],["path",{d:"M15 14h.01"}],["path",{d:"M9 6h6"}],["path",{d:"M9 10h6"}]],lr=[["path",{d:"M15.707 21.293a1 1 0 0 1-1.414 0l-1.586-1.586a1 1 0 0 1 0-1.414l5.586-5.586a1 1 0 0 1 1.414 0l1.586 1.586a1 1 0 0 1 0 1.414z"}],["path",{d:"m18 13-1.375-6.874a1 1 0 0 0-.746-.776L3.235 2.028a1 1 0 0 0-1.207 1.207L5.35 15.879a1 1 0 0 0 .776.746L13 18"}],["path",{d:"m2.3 2.3 7.286 7.286"}],["circle",{cx:"11",cy:"11",r:"2"}]],er=[["path",{d:"M13 21h8"}],["path",{d:"m15 5 4 4"}],["path",{d:"M21.174 6.812a1 1 0 0 0-3.986-3.987L3.842 16.174a2 2 0 0 0-.5.83l-1.321 4.352a.5.5 0 0 0 .623.622l4.353-1.32a2 2 0 0 0 .83-.497z"}]],rr=[["path",{d:"m10 10-6.157 6.162a2 2 0 0 0-.5.833l-1.322 4.36a.5.5 0 0 0 .622.624l4.358-1.323a2 2 0 0 0 .83-.5L14 13.982"}],["path",{d:"m12.829 7.172 4.359-4.346a1 1 0 1 1 3.986 3.986l-4.353 4.353"}],["path",{d:"m15 5 4 4"}],["path",{d:"m2 2 20 20"}]],P2=[["path",{d:"M21.174 6.812a1 1 0 0 0-3.986-3.987L3.842 16.174a2 2 0 0 0-.5.83l-1.321 4.352a.5.5 0 0 0 .623.622l4.353-1.32a2 2 0 0 0 .83-.497z"}]],or=[["path",{d:"M13 7 8.7 2.7a2.41 2.41 0 0 0-3.4 0L2.7 5.3a2.41 2.41 0 0 0 0 3.4L7 13"}],["path",{d:"m8 6 2-2"}],["path",{d:"m18 16 2-2"}],["path",{d:"m17 11 4.3 4.3c.94.94.94 2.46 0 3.4l-2.6 2.6c-.94.94-2.46.94-3.4 0L11 17"}],["path",{d:"M21.174 6.812a1 1 0 0 0-3.986-3.987L3.842 16.174a2 2 0 0 0-.5.83l-1.321 4.352a.5.5 0 0 0 .623.622l4.353-1.32a2 2 0 0 0 .83-.497z"}],["path",{d:"m15 5 4 4"}]],vr=[["path",{d:"M21.174 6.812a1 1 0 0 0-3.986-3.987L3.842 16.174a2 2 0 0 0-.5.83l-1.321 4.352a.5.5 0 0 0 .623.622l4.353-1.32a2 2 0 0 0 .83-.497z"}],["path",{d:"m15 5 4 4"}]],$r=[["path",{d:"M10.83 2.38a2 2 0 0 1 2.34 0l8 5.74a2 2 0 0 1 .73 2.25l-3.04 9.26a2 2 0 0 1-1.9 1.37H7.04a2 2 0 0 1-1.9-1.37L2.1 10.37a2 2 0 0 1 .73-2.25z"}]],mr=[["line",{x1:"19",x2:"5",y1:"5",y2:"19"}],["circle",{cx:"6.5",cy:"6.5",r:"2.5"}],["circle",{cx:"17.5",cy:"17.5",r:"2.5"}]],yr=[["circle",{cx:"12",cy:"5",r:"1"}],["path",{d:"m9 20 3-6 3 6"}],["path",{d:"m6 8 6 2 6-2"}],["path",{d:"M12 10v4"}]],sr=[["path",{d:"M20 11H4"}],["path",{d:"M20 7H4"}],["path",{d:"M7 21V4a1 1 0 0 1 1-1h4a1 1 0 0 1 0 12H7"}]],gr=[["path",{d:"M13 2a9 9 0 0 1 9 9"}],["path",{d:"M13 6a5 5 0 0 1 5 5"}],["path",{d:"M13.832 16.568a1 1 0 0 0 1.213-.303l.355-.465A2 2 0 0 1 17 15h3a2 2 0 0 1 2 2v3a2 2 0 0 1-2 2A18 18 0 0 1 2 4a2 2 0 0 1 2-2h3a2 2 0 0 1 2 2v3a2 2 0 0 1-.8 1.6l-.468.351a1 1 0 0 0-.292 1.233 14 14 0 0 0 6.392 6.384"}]],ur=[["path",{d:"M14 6h8"}],["path",{d:"m18 2 4 4-4 4"}],["path",{d:"M13.832 16.568a1 1 0 0 0 1.213-.303l.355-.465A2 2 0 0 1 17 15h3a2 2 0 0 1 2 2v3a2 2 0 0 1-2 2A18 18 0 0 1 2 4a2 2 0 0 1 2-2h3a2 2 0 0 1 2 2v3a2 2 0 0 1-.8 1.6l-.468.351a1 1 0 0 0-.292 1.233 14 14 0 0 0 6.392 6.384"}]],Cr=[["path",{d:"M16 2v6h6"}],["path",{d:"m22 2-6 6"}],["path",{d:"M13.832 16.568a1 1 0 0 0 1.213-.303l.355-.465A2 2 0 0 1 17 15h3a2 2 0 0 1 2 2v3a2 2 0 0 1-2 2A18 18 0 0 1 2 4a2 2 0 0 1 2-2h3a2 2 0 0 1 2 2v3a2 2 0 0 1-.8 1.6l-.468.351a1 1 0 0 0-.292 1.233 14 14 0 0 0 6.392 6.384"}]],Hr=[["path",{d:"m16 2 6 6"}],["path",{d:"m22 2-6 6"}],["path",{d:"M13.832 16.568a1 1 0 0 0 1.213-.303l.355-.465A2 2 0 0 1 17 15h3a2 2 0 0 1 2 2v3a2 2 0 0 1-2 2A18 18 0 0 1 2 4a2 2 0 0 1 2-2h3a2 2 0 0 1 2 2v3a2 2 0 0 1-.8 1.6l-.468.351a1 1 0 0 0-.292 1.233 14 14 0 0 0 6.392 6.384"}]],Ar=[["path",{d:"M10.1 13.9a14 14 0 0 0 3.732 2.668 1 1 0 0 0 1.213-.303l.355-.465A2 2 0 0 1 17 15h3a2 2 0 0 1 2 2v3a2 2 0 0 1-2 2 18 18 0 0 1-12.728-5.272"}],["path",{d:"M22 2 2 22"}],["path",{d:"M4.76 13.582A18 18 0 0 1 2 4a2 2 0 0 1 2-2h3a2 2 0 0 1 2 2v3a2 2 0 0 1-.8 1.6l-.468.351a1 1 0 0 0-.292 1.233 14 14 0 0 0 .244.473"}]],wr=[["path",{d:"m16 8 6-6"}],["path",{d:"M22 8V2h-6"}],["path",{d:"M13.832 16.568a1 1 0 0 0 1.213-.303l.355-.465A2 2 0 0 1 17 15h3a2 2 0 0 1 2 2v3a2 2 0 0 1-2 2A18 18 0 0 1 2 4a2 2 0 0 1 2-2h3a2 2 0 0 1 2 2v3a2 2 0 0 1-.8 1.6l-.468.351a1 1 0 0 0-.292 1.233 14 14 0 0 0 6.392 6.384"}]],Vr=[["path",{d:"M13.832 16.568a1 1 0 0 0 1.213-.303l.355-.465A2 2 0 0 1 17 15h3a2 2 0 0 1 2 2v3a2 2 0 0 1-2 2A18 18 0 0 1 2 4a2 2 0 0 1 2-2h3a2 2 0 0 1 2 2v3a2 2 0 0 1-.8 1.6l-.468.351a1 1 0 0 0-.292 1.233 14 14 0 0 0 6.392 6.384"}]],Sr=[["line",{x1:"9",x2:"9",y1:"4",y2:"20"}],["path",{d:"M4 7c0-1.7 1.3-3 3-3h13"}],["path",{d:"M18 20c-1.7 0-3-1.3-3-3V4"}]],Lr=[["path",{d:"M18.5 8c-1.4 0-2.6-.8-3.2-2A6.87 6.87 0 0 0 2 9v11a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-8.5C22 9.6 20.4 8 18.5 8"}],["path",{d:"M2 14h20"}],["path",{d:"M6 14v4"}],["path",{d:"M10 14v4"}],["path",{d:"M14 14v4"}],["path",{d:"M18 14v4"}]],fr=[["path",{d:"m14 13-8.381 8.38a1 1 0 0 1-3.001-3L11 9.999"}],["path",{d:"M15.973 4.027A13 13 0 0 0 5.902 2.373c-1.398.342-1.092 2.158.277 2.601a19.9 19.9 0 0 1 5.822 3.024"}],["path",{d:"M16.001 11.999a19.9 19.9 0 0 1 3.024 5.824c.444 1.369 2.26 1.676 2.603.278A13 13 0 0 0 20 8.069"}],["path",{d:"M18.352 3.352a1.205 1.205 0 0 0-1.704 0l-5.296 5.296a1.205 1.205 0 0 0 0 1.704l2.296 2.296a1.205 1.205 0 0 0 1.704 0l5.296-5.296a1.205 1.205 0 0 0 0-1.704z"}]],kr=[["path",{d:"M21 9V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v10c0 1.1.9 2 2 2h4"}],["rect",{width:"10",height:"7",x:"12",y:"13",rx:"2"}]],Pr=[["path",{d:"M2 10h6V4"}],["path",{d:"m2 4 6 6"}],["path",{d:"M21 10V7a2 2 0 0 0-2-2h-7"}],["path",{d:"M3 14v2a2 2 0 0 0 2 2h3"}],["rect",{x:"12",y:"14",width:"10",height:"7",rx:"1"}]],Br=[["path",{d:"M11 17h3v2a1 1 0 0 0 1 1h2a1 1 0 0 0 1-1v-3a3.16 3.16 0 0 0 2-2h1a1 1 0 0 0 1-1v-2a1 1 0 0 0-1-1h-1a5 5 0 0 0-2-4V3a4 4 0 0 0-3.2 1.6l-.3.4H11a6 6 0 0 0-6 6v1a5 5 0 0 0 2 4v3a1 1 0 0 0 1 1h2a1 1 0 0 0 1-1z"}],["path",{d:"M16 10h.01"}],["path",{d:"M2 8v1a2 2 0 0 0 2 2h1"}]],Dr=[["path",{d:"M14 3v11"}],["path",{d:"M14 9h-3a3 3 0 0 1 0-6h9"}],["path",{d:"M18 3v11"}],["path",{d:"M22 18H2l4-4"}],["path",{d:"m6 22-4-4"}]],Fr=[["path",{d:"M10 3v11"}],["path",{d:"M10 9H7a1 1 0 0 1 0-6h8"}],["path",{d:"M14 3v11"}],["path",{d:"m18 14 4 4H2"}],["path",{d:"m22 18-4 4"}]],zr=[["path",{d:"M13 4v16"}],["path",{d:"M17 4v16"}],["path",{d:"M19 4H9.5a4.5 4.5 0 0 0 0 9H13"}]],br=[["path",{d:"M18 11h-4a1 1 0 0 0-1 1v5a1 1 0 0 0 1 1h4"}],["path",{d:"M6 7v13a2 2 0 0 0 2 2h8a2 2 0 0 0 2-2V7"}],["rect",{width:"16",height:"5",x:"4",y:"2",rx:"1"}]],Rr=[["path",{d:"m10.5 20.5 10-10a4.95 4.95 0 1 0-7-7l-10 10a4.95 4.95 0 1 0 7 7Z"}],["path",{d:"m8.5 8.5 7 7"}]],Tr=[["path",{d:"M12 17v5"}],["path",{d:"M15 9.34V7a1 1 0 0 1 1-1 2 2 0 0 0 0-4H7.89"}],["path",{d:"m2 2 20 20"}],["path",{d:"M9 9v1.76a2 2 0 0 1-1.11 1.79l-1.78.9A2 2 0 0 0 5 15.24V16a1 1 0 0 0 1 1h11"}]],qr=[["path",{d:"M12 17v5"}],["path",{d:"M9 10.76a2 2 0 0 1-1.11 1.79l-1.78.9A2 2 0 0 0 5 15.24V16a1 1 0 0 0 1 1h12a1 1 0 0 0 1-1v-.76a2 2 0 0 0-1.11-1.79l-1.78-.9A2 2 0 0 1 15 10.76V7a1 1 0 0 1 1-1 2 2 0 0 0 0-4H8a2 2 0 0 0 0 4 1 1 0 0 1 1 1z"}]],Ur=[["path",{d:"m12 9-8.414 8.414A2 2 0 0 0 3 18.828v1.344a2 2 0 0 1-.586 1.414A2 2 0 0 1 3.828 21h1.344a2 2 0 0 0 1.414-.586L15 12"}],["path",{d:"m18 9 .4.4a1 1 0 1 1-3 3l-3.8-3.8a1 1 0 1 1 3-3l.4.4 3.4-3.4a1 1 0 1 1 3 3z"}],["path",{d:"m2 22 .414-.414"}]],Or=[["path",{d:"m12 14-1 1"}],["path",{d:"m13.75 18.25-1.25 1.42"}],["path",{d:"M17.775 5.654a15.68 15.68 0 0 0-12.121 12.12"}],["path",{d:"M18.8 9.3a1 1 0 0 0 2.1 7.7"}],["path",{d:"M21.964 20.732a1 1 0 0 1-1.232 1.232l-18-5a1 1 0 0 1-.695-1.232A19.68 19.68 0 0 1 15.732 2.037a1 1 0 0 1 1.232.695z"}]],Zr=[["path",{d:"M2 22h20"}],["path",{d:"M3.77 10.77 2 9l2-4.5 1.1.55c.55.28.9.84.9 1.45s.35 1.17.9 1.45L8 8.5l3-6 1.05.53a2 2 0 0 1 1.09 1.52l.72 5.4a2 2 0 0 0 1.09 1.52l4.4 2.2c.42.22.78.55 1.01.96l.6 1.03c.49.88-.06 1.98-1.06 2.1l-1.18.15c-.47.06-.95-.02-1.37-.24L4.29 11.15a2 2 0 0 1-.52-.38Z"}]],Gr=[["path",{d:"M2 22h20"}],["path",{d:"M6.36 17.4 4 17l-2-4 1.1-.55a2 2 0 0 1 1.8 0l.17.1a2 2 0 0 0 1.8 0L8 12 5 6l.9-.45a2 2 0 0 1 2.09.2l4.02 3a2 2 0 0 0 2.1.2l4.19-2.06a2.41 2.41 0 0 1 1.73-.17L21 7a1.4 1.4 0 0 1 .87 1.99l-.38.76c-.23.46-.6.84-1.07 1.08L7.58 17.2a2 2 0 0 1-1.22.18Z"}]],Ir=[["path",{d:"M17.8 19.2 16 11l3.5-3.5C21 6 21.5 4 21 3c-1-.5-3 0-4.5 1.5L13 8 4.8 6.2c-.5-.1-.9.1-1.1.5l-.3.5c-.2.5-.1 1 .3 1.3L9 12l-2 3H4l-1 1 3 2 2 3 1-1v-3l3-2 3.5 5.3c.3.4.8.5 1.3.3l.5-.2c.4-.3.6-.7.5-1.2z"}]],Wr=[["path",{d:"M5 5a2 2 0 0 1 3.008-1.728l11.997 6.998a2 2 0 0 1 .003 3.458l-12 7A2 2 0 0 1 5 19z"}]],B2=[["path",{d:"M6.3 20.3a2.4 2.4 0 0 0 3.4 0L12 18l-6-6-2.3 2.3a2.4 2.4 0 0 0 0 3.4Z"}],["path",{d:"m2 22 3-3"}],["path",{d:"M7.5 13.5 10 11"}],["path",{d:"M10.5 16.5 13 14"}],["path",{d:"m18 3-4 4h6l-4 4"}]],Er=[["path",{d:"M9 2v6"}],["path",{d:"M15 2v6"}],["path",{d:"M12 17v5"}],["path",{d:"M5 8h14"}],["path",{d:"M6 11V8h12v3a6 6 0 1 1-12 0Z"}]],Xr=[["path",{d:"M12 22v-5"}],["path",{d:"M9 8V2"}],["path",{d:"M15 8V2"}],["path",{d:"M18 8v5a4 4 0 0 1-4 4h-4a4 4 0 0 1-4-4V8Z"}]],jr=[["path",{d:"M5 12h14"}],["path",{d:"M12 5v14"}]],Nr=[["path",{d:"M3 2v1c0 1 2 1 2 2S3 6 3 7s2 1 2 2-2 1-2 2 2 1 2 2"}],["path",{d:"M18 6h.01"}],["path",{d:"M6 18h.01"}],["path",{d:"M20.83 8.83a4 4 0 0 0-5.66-5.66l-12 12a4 4 0 1 0 5.66 5.66Z"}],["path",{d:"M18 11.66V22a4 4 0 0 0 4-4V6"}]],Kr=[["path",{d:"M20 3a2 2 0 0 1 2 2v6a1 1 0 0 1-20 0V5a2 2 0 0 1 2-2z"}],["path",{d:"m8 10 4 4 4-4"}]],Qr=[["path",{d:"M10 4.5V4a2 2 0 0 0-2.41-1.957"}],["path",{d:"M13.9 8.4a2 2 0 0 0-1.26-1.295"}],["path",{d:"M21.7 16.2A8 8 0 0 0 22 14v-3a2 2 0 1 0-4 0v-1a2 2 0 0 0-3.63-1.158"}],["path",{d:"m7 15-1.8-1.8a2 2 0 0 0-2.79 2.86L6 19.7a7.74 7.74 0 0 0 6 2.3h2a8 8 0 0 0 5.657-2.343"}],["path",{d:"M6 6v8"}],["path",{d:"m2 2 20 20"}]],Jr=[["path",{d:"M22 14a8 8 0 0 1-8 8"}],["path",{d:"M18 11v-1a2 2 0 0 0-2-2a2 2 0 0 0-2 2"}],["path",{d:"M14 10V9a2 2 0 0 0-2-2a2 2 0 0 0-2 2v1"}],["path",{d:"M10 9.5V4a2 2 0 0 0-2-2a2 2 0 0 0-2 2v10"}],["path",{d:"M18 11a2 2 0 1 1 4 0v3a8 8 0 0 1-8 8h-2c-2.8 0-4.5-.86-5.99-2.34l-3.6-3.6a2 2 0 0 1 2.83-2.82L7 15"}]],Yr=[["path",{d:"M13 17a1 1 0 1 0-2 0l.5 4.5a0.5 0.5 0 0 0 1 0z",fill:"currentColor"}],["path",{d:"M16.85 18.58a9 9 0 1 0-9.7 0"}],["path",{d:"M8 14a5 5 0 1 1 8 0"}],["circle",{cx:"12",cy:"11",r:"1",fill:"currentColor"}]],_r=[["path",{d:"M18 8a2 2 0 0 0 0-4 2 2 0 0 0-4 0 2 2 0 0 0-4 0 2 2 0 0 0-4 0 2 2 0 0 0 0 4"}],["path",{d:"M10 22 9 8"}],["path",{d:"m14 22 1-14"}],["path",{d:"M20 8c.5 0 .9.4.8 1l-2.6 12c-.1.5-.7 1-1.2 1H7c-.6 0-1.1-.4-1.2-1L3.2 9c-.1-.6.3-1 .8-1Z"}]],xr=[["path",{d:"M18.6 14.4c.8-.8.8-2 0-2.8l-8.1-8.1a4.95 4.95 0 1 0-7.1 7.1l8.1 8.1c.9.7 2.1.7 2.9-.1Z"}],["path",{d:"m22 22-5.5-5.5"}]],ao=[["path",{d:"M18 7c0-5.333-8-5.333-8 0"}],["path",{d:"M10 7v14"}],["path",{d:"M6 21h12"}],["path",{d:"M6 13h10"}]],to=[["path",{d:"M18.36 6.64A9 9 0 0 1 20.77 15"}],["path",{d:"M6.16 6.16a9 9 0 1 0 12.68 12.68"}],["path",{d:"M12 2v4"}],["path",{d:"m2 2 20 20"}]],ho=[["path",{d:"M12 2v10"}],["path",{d:"M18.4 6.6a9 9 0 1 1-12.77.04"}]],co=[["path",{d:"M2 3h20"}],["path",{d:"M21 3v11a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V3"}],["path",{d:"m7 21 5-5 5 5"}]],Mo=[["path",{d:"M13.5 22H7a1 1 0 0 1-1-1v-6a1 1 0 0 1 1-1h10a1 1 0 0 1 1 1v.5"}],["path",{d:"m16 19 2 2 4-4"}],["path",{d:"M6 18H4a2 2 0 0 1-2-2v-5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v2"}],["path",{d:"M6 9V3a1 1 0 0 1 1-1h10a1 1 0 0 1 1 1v6"}]],po=[["path",{d:"M6 18H4a2 2 0 0 1-2-2v-5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v5a2 2 0 0 1-2 2h-2"}],["path",{d:"M6 9V3a1 1 0 0 1 1-1h10a1 1 0 0 1 1 1v6"}],["rect",{x:"6",y:"14",width:"12",height:"8",rx:"1"}]],io=[["path",{d:"M5 7 3 5"}],["path",{d:"M9 6V3"}],["path",{d:"m13 7 2-2"}],["circle",{cx:"9",cy:"13",r:"3"}],["path",{d:"M11.83 12H20a2 2 0 0 1 2 2v4a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2v-4a2 2 0 0 1 2-2h2.17"}],["path",{d:"M16 16h2"}]],no=[["rect",{width:"20",height:"16",x:"2",y:"4",rx:"2"}],["path",{d:"M12 9v11"}],["path",{d:"M2 9h13a2 2 0 0 1 2 2v9"}]],lo=[["path",{d:"M15.39 4.39a1 1 0 0 0 1.68-.474 2.5 2.5 0 1 1 3.014 3.015 1 1 0 0 0-.474 1.68l1.683 1.682a2.414 2.414 0 0 1 0 3.414L19.61 15.39a1 1 0 0 1-1.68-.474 2.5 2.5 0 1 0-3.014 3.015 1 1 0 0 1 .474 1.68l-1.683 1.682a2.414 2.414 0 0 1-3.414 0L8.61 19.61a1 1 0 0 0-1.68.474 2.5 2.5 0 1 1-3.014-3.015 1 1 0 0 0 .474-1.68l-1.683-1.682a2.414 2.414 0 0 1 0-3.414L4.39 8.61a1 1 0 0 1 1.68.474 2.5 2.5 0 1 0 3.014-3.015 1 1 0 0 1-.474-1.68l1.683-1.682a2.414 2.414 0 0 1 3.414 0z"}]],eo=[["path",{d:"M2.5 16.88a1 1 0 0 1-.32-1.43l9-13.02a1 1 0 0 1 1.64 0l9 13.01a1 1 0 0 1-.32 1.44l-8.51 4.86a2 2 0 0 1-1.98 0Z"}],["path",{d:"M12 2v20"}]],ro=[["rect",{width:"5",height:"5",x:"3",y:"3",rx:"1"}],["rect",{width:"5",height:"5",x:"16",y:"3",rx:"1"}],["rect",{width:"5",height:"5",x:"3",y:"16",rx:"1"}],["path",{d:"M21 16h-3a2 2 0 0 0-2 2v3"}],["path",{d:"M21 21v.01"}],["path",{d:"M12 7v3a2 2 0 0 1-2 2H7"}],["path",{d:"M3 12h.01"}],["path",{d:"M12 3h.01"}],["path",{d:"M12 16v.01"}],["path",{d:"M16 12h1"}],["path",{d:"M21 12v.01"}],["path",{d:"M12 21v-1"}]],oo=[["path",{d:"M16 3a2 2 0 0 0-2 2v6a2 2 0 0 0 2 2 1 1 0 0 1 1 1v1a2 2 0 0 1-2 2 1 1 0 0 0-1 1v2a1 1 0 0 0 1 1 6 6 0 0 0 6-6V5a2 2 0 0 0-2-2z"}],["path",{d:"M5 3a2 2 0 0 0-2 2v6a2 2 0 0 0 2 2 1 1 0 0 1 1 1v1a2 2 0 0 1-2 2 1 1 0 0 0-1 1v2a1 1 0 0 0 1 1 6 6 0 0 0 6-6V5a2 2 0 0 0-2-2z"}]],vo=[["path",{d:"M13 16a3 3 0 0 1 2.24 5"}],["path",{d:"M18 12h.01"}],["path",{d:"M18 21h-8a4 4 0 0 1-4-4 7 7 0 0 1 7-7h.2L9.6 6.4a1 1 0 1 1 2.8-2.8L15.8 7h.2c3.3 0 6 2.7 6 6v1a2 2 0 0 1-2 2h-1a3 3 0 0 0-3 3"}],["path",{d:"M20 8.54V4a2 2 0 1 0-4 0v3"}],["path",{d:"M7.612 12.524a3 3 0 1 0-1.6 4.3"}]],$o=[["path",{d:"M19.07 4.93A10 10 0 0 0 6.99 3.34"}],["path",{d:"M4 6h.01"}],["path",{d:"M2.29 9.62A10 10 0 1 0 21.31 8.35"}],["path",{d:"M16.24 7.76A6 6 0 1 0 8.23 16.67"}],["path",{d:"M12 18h.01"}],["path",{d:"M17.99 11.66A6 6 0 0 1 15.77 16.67"}],["circle",{cx:"12",cy:"12",r:"2"}],["path",{d:"m13.41 10.59 5.66-5.66"}]],mo=[["path",{d:"M12 12h.01"}],["path",{d:"M14 15.4641a4 4 0 0 1-4 0L7.52786 19.74597 A 1 1 0 0 0 7.99303 21.16211 10 10 0 0 0 16.00697 21.16211 1 1 0 0 0 16.47214 19.74597z"}],["path",{d:"M16 12a4 4 0 0 0-2-3.464l2.472-4.282a1 1 0 0 1 1.46-.305 10 10 0 0 1 4.006 6.94A1 1 0 0 1 21 12z"}],["path",{d:"M8 12a4 4 0 0 1 2-3.464L7.528 4.254a1 1 0 0 0-1.46-.305 10 10 0 0 0-4.006 6.94A1 1 0 0 0 3 12z"}]],yo=[["path",{d:"M3 12h3.28a1 1 0 0 1 .948.684l2.298 7.934a.5.5 0 0 0 .96-.044L13.82 4.771A1 1 0 0 1 14.792 4H21"}]],so=[["path",{d:"M5 16v2"}],["path",{d:"M19 16v2"}],["rect",{width:"20",height:"8",x:"2",y:"8",rx:"2"}],["path",{d:"M18 12h.01"}]],go=[["path",{d:"M4.9 16.1C1 12.2 1 5.8 4.9 1.9"}],["path",{d:"M7.8 4.7a6.14 6.14 0 0 0-.8 7.5"}],["circle",{cx:"12",cy:"9",r:"2"}],["path",{d:"M16.2 4.8c2 2 2.26 5.11.8 7.47"}],["path",{d:"M19.1 1.9a9.96 9.96 0 0 1 0 14.1"}],["path",{d:"M9.5 18h5"}],["path",{d:"m8 22 4-11 4 11"}]],uo=[["path",{d:"M16.247 7.761a6 6 0 0 1 0 8.478"}],["path",{d:"M19.075 4.933a10 10 0 0 1 0 14.134"}],["path",{d:"M4.925 19.067a10 10 0 0 1 0-14.134"}],["path",{d:"M7.753 16.239a6 6 0 0 1 0-8.478"}],["circle",{cx:"12",cy:"12",r:"2"}]],Co=[["path",{d:"M5 15h14"}],["path",{d:"M5 9h14"}],["path",{d:"m14 20-5-5 6-6-5-5"}]],Ho=[["path",{d:"M20.34 17.52a10 10 0 1 0-2.82 2.82"}],["circle",{cx:"19",cy:"19",r:"2"}],["path",{d:"m13.41 13.41 4.18 4.18"}],["circle",{cx:"12",cy:"12",r:"2"}]],Ao=[["path",{d:"M22 17a10 10 0 0 0-20 0"}],["path",{d:"M6 17a6 6 0 0 1 12 0"}],["path",{d:"M10 17a2 2 0 0 1 4 0"}]],wo=[["path",{d:"M13 22H4a2 2 0 0 1 0-4h12"}],["path",{d:"M13.236 18a3 3 0 0 0-2.2-5"}],["path",{d:"M16 9h.01"}],["path",{d:"M16.82 3.94a3 3 0 1 1 3.237 4.868l1.815 2.587a1.5 1.5 0 0 1-1.5 2.1l-2.872-.453a3 3 0 0 0-3.5 3"}],["path",{d:"M17 4.988a3 3 0 1 0-5.2 2.052A7 7 0 0 0 4 14.015 4 4 0 0 0 8 18"}]],Vo=[["rect",{width:"12",height:"20",x:"6",y:"2",rx:"2"}],["rect",{width:"20",height:"12",x:"2",y:"6",rx:"2"}]],So=[["path",{d:"M4 2v20l2-1 2 1 2-1 2 1 2-1 2 1 2-1 2 1V2l-2 1-2-1-2 1-2-1-2 1-2-1-2 1Z"}],["path",{d:"M12 6.5v11"}],["path",{d:"M15 9.4a4 4 0 1 0 0 5.2"}]],Lo=[["path",{d:"M4 2v20l2-1 2 1 2-1 2 1 2-1 2 1 2-1 2 1V2l-2 1-2-1-2 1-2-1-2 1-2-1-2 1Z"}],["path",{d:"M8 12h5"}],["path",{d:"M16 9.5a4 4 0 1 0 0 5.2"}]],fo=[["path",{d:"M4 2v20l2-1 2 1 2-1 2 1 2-1 2 1 2-1 2 1V2l-2 1-2-1-2 1-2-1-2 1-2-1-2 1Z"}],["path",{d:"M8 7h8"}],["path",{d:"M12 17.5 8 15h1a4 4 0 0 0 0-8"}],["path",{d:"M8 11h8"}]],ko=[["path",{d:"M4 2v20l2-1 2 1 2-1 2 1 2-1 2 1 2-1 2 1V2l-2 1-2-1-2 1-2-1-2 1-2-1-2 1Z"}],["path",{d:"m12 10 3-3"}],["path",{d:"m9 7 3 3v7.5"}],["path",{d:"M9 11h6"}],["path",{d:"M9 15h6"}]],Po=[["path",{d:"M4 2v20l2-1 2 1 2-1 2 1 2-1 2 1 2-1 2 1V2l-2 1-2-1-2 1-2-1-2 1-2-1-2 1Z"}],["path",{d:"M8 13h5"}],["path",{d:"M10 17V9.5a2.5 2.5 0 0 1 5 0"}],["path",{d:"M8 17h7"}]],Bo=[["path",{d:"M4 2v20l2-1 2 1 2-1 2 1 2-1 2 1 2-1 2 1V2l-2 1-2-1-2 1-2-1-2 1-2-1-2 1Z"}],["path",{d:"M8 15h5"}],["path",{d:"M8 11h5a2 2 0 1 0 0-4h-3v10"}]],Do=[["path",{d:"M4 2v20l2-1 2 1 2-1 2 1 2-1 2 1 2-1 2 1V2l-2 1-2-1-2 1-2-1-2 1-2-1-2 1Z"}],["path",{d:"M10 17V7h5"}],["path",{d:"M10 11h4"}],["path",{d:"M8 15h5"}]],Fo=[["path",{d:"M4 2v20l2-1 2 1 2-1 2 1 2-1 2 1 2-1 2 1V2l-2 1-2-1-2 1-2-1-2 1-2-1-2 1Z"}],["path",{d:"M14 8H8"}],["path",{d:"M16 12H8"}],["path",{d:"M13 16H8"}]],zo=[["path",{d:"M4 2v20l2-1 2 1 2-1 2 1 2-1 2 1 2-1 2 1V2l-2 1-2-1-2 1-2-1-2 1-2-1-2 1Z"}],["path",{d:"M16 8h-6a2 2 0 1 0 0 4h4a2 2 0 1 1 0 4H8"}],["path",{d:"M12 17.5v-11"}]],bo=[["path",{d:"M10 6.5v11a5.5 5.5 0 0 0 5.5-5.5"}],["path",{d:"m14 8-6 3"}],["path",{d:"M4 2v20l2-1 2 1 2-1 2 1 2-1 2 1 2-1 2 1V2l-2 1-2-1-2 1-2-1-2 1-2-1-2 1z"}]],Ro=[["path",{d:"M14 4v16H3a1 1 0 0 1-1-1V5a1 1 0 0 1 1-1z"}],["circle",{cx:"14",cy:"12",r:"8"}]],D2=[["rect",{width:"20",height:"12",x:"2",y:"6",rx:"2"}],["path",{d:"M12 12h.01"}],["path",{d:"M17 12h.01"}],["path",{d:"M7 12h.01"}]],To=[["path",{d:"M20 6a2 2 0 0 1 2 2v8a2 2 0 0 1-2 2h-4a2 2 0 0 1-1.6-.8l-1.6-2.13a1 1 0 0 0-1.6 0L9.6 17.2A2 2 0 0 1 8 18H4a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2z"}]],qo=[["rect",{width:"20",height:"12",x:"2",y:"6",rx:"2"}]],Uo=[["path",{d:"M7 19H4.815a1.83 1.83 0 0 1-1.57-.881 1.785 1.785 0 0 1-.004-1.784L7.196 9.5"}],["path",{d:"M11 19h8.203a1.83 1.83 0 0 0 1.556-.89 1.784 1.784 0 0 0 0-1.775l-1.226-2.12"}],["path",{d:"m14 16-3 3 3 3"}],["path",{d:"M8.293 13.596 7.196 9.5 3.1 10.598"}],["path",{d:"m9.344 5.811 1.093-1.892A1.83 1.83 0 0 1 11.985 3a1.784 1.784 0 0 1 1.546.888l3.943 6.843"}],["path",{d:"m13.378 9.633 4.096 1.098 1.097-4.096"}]],Oo=[["rect",{width:"12",height:"20",x:"6",y:"2",rx:"2"}]],Zo=[["path",{d:"m15 14 5-5-5-5"}],["path",{d:"M20 9H9.5A5.5 5.5 0 0 0 4 14.5A5.5 5.5 0 0 0 9.5 20H13"}]],Go=[["circle",{cx:"12",cy:"17",r:"1"}],["path",{d:"M21 7v6h-6"}],["path",{d:"M3 17a9 9 0 0 1 9-9 9 9 0 0 1 6 2.3l3 2.7"}]],Io=[["path",{d:"M21 7v6h-6"}],["path",{d:"M3 17a9 9 0 0 1 9-9 9 9 0 0 1 6 2.3l3 2.7"}]],Wo=[["path",{d:"M21 12a9 9 0 0 0-9-9 9.75 9.75 0 0 0-6.74 2.74L3 8"}],["path",{d:"M3 3v5h5"}],["path",{d:"M3 12a9 9 0 0 0 9 9 9.75 9.75 0 0 0 6.74-2.74L21 16"}],["path",{d:"M16 16h5v5"}]],Eo=[["path",{d:"M21 12a9 9 0 0 0-9-9 9.75 9.75 0 0 0-6.74 2.74L3 8"}],["path",{d:"M3 3v5h5"}],["path",{d:"M3 12a9 9 0 0 0 9 9 9.75 9.75 0 0 0 6.74-2.74L21 16"}],["path",{d:"M16 16h5v5"}],["circle",{cx:"12",cy:"12",r:"1"}]],Xo=[["path",{d:"M21 8L18.74 5.74A9.75 9.75 0 0 0 12 3C11 3 10.03 3.16 9.13 3.47"}],["path",{d:"M8 16H3v5"}],["path",{d:"M3 12C3 9.51 4 7.26 5.64 5.64"}],["path",{d:"m3 16 2.26 2.26A9.75 9.75 0 0 0 12 21c2.49 0 4.74-1 6.36-2.64"}],["path",{d:"M21 12c0 1-.16 1.97-.47 2.87"}],["path",{d:"M21 3v5h-5"}],["path",{d:"M22 22 2 2"}]],jo=[["path",{d:"M3 12a9 9 0 0 1 9-9 9.75 9.75 0 0 1 6.74 2.74L21 8"}],["path",{d:"M21 3v5h-5"}],["path",{d:"M21 12a9 9 0 0 1-9 9 9.75 9.75 0 0 1-6.74-2.74L3 16"}],["path",{d:"M8 16H3v5"}]],No=[["path",{d:"M5 6a4 4 0 0 1 4-4h6a4 4 0 0 1 4 4v14a2 2 0 0 1-2 2H7a2 2 0 0 1-2-2V6Z"}],["path",{d:"M5 10h14"}],["path",{d:"M15 7v6"}]],Ko=[["path",{d:"M17 3v10"}],["path",{d:"m12.67 5.5 8.66 5"}],["path",{d:"m12.67 10.5 8.66-5"}],["path",{d:"M9 17a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v2a2 2 0 0 0 2 2h2a2 2 0 0 0 2-2v-2z"}]],Qo=[["path",{d:"M4 7V4h16v3"}],["path",{d:"M5 20h6"}],["path",{d:"M13 4 8 20"}],["path",{d:"m15 15 5 5"}],["path",{d:"m20 15-5 5"}]],Jo=[["path",{d:"m2 9 3-3 3 3"}],["path",{d:"M13 18H7a2 2 0 0 1-2-2V6"}],["path",{d:"m22 15-3 3-3-3"}],["path",{d:"M11 6h6a2 2 0 0 1 2 2v10"}]],Yo=[["path",{d:"m17 2 4 4-4 4"}],["path",{d:"M3 11v-1a4 4 0 0 1 4-4h14"}],["path",{d:"m7 22-4-4 4-4"}],["path",{d:"M21 13v1a4 4 0 0 1-4 4H3"}],["path",{d:"M11 10h1v4"}]],_o=[["path",{d:"m17 2 4 4-4 4"}],["path",{d:"M3 11v-1a4 4 0 0 1 4-4h14"}],["path",{d:"m7 22-4-4 4-4"}],["path",{d:"M21 13v1a4 4 0 0 1-4 4H3"}]],xo=[["path",{d:"M14 14a1 1 0 0 1 1 1v5a1 1 0 0 1-1 1"}],["path",{d:"M14 4a1 1 0 0 1 1-1"}],["path",{d:"M15 10a1 1 0 0 1-1-1"}],["path",{d:"M19 14a1 1 0 0 1 1 1v5a1 1 0 0 1-1 1"}],["path",{d:"M21 4a1 1 0 0 0-1-1"}],["path",{d:"M21 9a1 1 0 0 1-1 1"}],["path",{d:"m3 7 3 3 3-3"}],["path",{d:"M6 10V5a2 2 0 0 1 2-2h2"}],["rect",{x:"3",y:"14",width:"7",height:"7",rx:"1"}]],av=[["path",{d:"M14 4a1 1 0 0 1 1-1"}],["path",{d:"M15 10a1 1 0 0 1-1-1"}],["path",{d:"M21 4a1 1 0 0 0-1-1"}],["path",{d:"M21 9a1 1 0 0 1-1 1"}],["path",{d:"m3 7 3 3 3-3"}],["path",{d:"M6 10V5a2 2 0 0 1 2-2h2"}],["rect",{x:"3",y:"14",width:"7",height:"7",rx:"1"}]],tv=[["path",{d:"m12 17-5-5 5-5"}],["path",{d:"M22 18v-2a4 4 0 0 0-4-4H7"}],["path",{d:"m7 17-5-5 5-5"}]],hv=[["path",{d:"M20 18v-2a4 4 0 0 0-4-4H4"}],["path",{d:"m9 17-5-5 5-5"}]],dv=[["path",{d:"M12 6a2 2 0 0 0-3.414-1.414l-6 6a2 2 0 0 0 0 2.828l6 6A2 2 0 0 0 12 18z"}],["path",{d:"M22 6a2 2 0 0 0-3.414-1.414l-6 6a2 2 0 0 0 0 2.828l6 6A2 2 0 0 0 22 18z"}]],cv=[["path",{d:"M12 11.22C11 9.997 10 9 10 8a2 2 0 0 1 4 0c0 1-.998 2.002-2.01 3.22"}],["path",{d:"m12 18 2.57-3.5"}],["path",{d:"M6.243 9.016a7 7 0 0 1 11.507-.009"}],["path",{d:"M9.35 14.53 12 11.22"}],["path",{d:"M9.35 14.53C7.728 12.246 6 10.221 6 7a6 5 0 0 1 12 0c-.005 3.22-1.778 5.235-3.43 7.5l3.557 4.527a1 1 0 0 1-.203 1.43l-1.894 1.36a1 1 0 0 1-1.384-.215L12 18l-2.679 3.593a1 1 0 0 1-1.39.213l-1.865-1.353a1 1 0 0 1-.203-1.422z"}]],Mv=[["path",{d:"M4.5 16.5c-1.5 1.26-2 5-2 5s3.74-.5 5-2c.71-.84.7-2.13-.09-2.91a2.18 2.18 0 0 0-2.91-.09z"}],["path",{d:"m12 15-3-3a22 22 0 0 1 2-3.95A12.88 12.88 0 0 1 22 2c0 2.72-.78 7.5-6 11a22.35 22.35 0 0 1-4 2z"}],["path",{d:"M9 12H4s.55-3.03 2-4c1.62-1.08 5 0 5 0"}],["path",{d:"M12 15v5s3.03-.55 4-2c1.08-1.62 0-5 0-5"}]],pv=[["polyline",{points:"3.5 2 6.5 12.5 18 12.5"}],["line",{x1:"9.5",x2:"5.5",y1:"12.5",y2:"20"}],["line",{x1:"15",x2:"18.5",y1:"12.5",y2:"20"}],["path",{d:"M2.75 18a13 13 0 0 0 18.5 0"}]],iv=[["path",{d:"M6 19V5"}],["path",{d:"M10 19V6.8"}],["path",{d:"M14 19v-7.8"}],["path",{d:"M18 5v4"}],["path",{d:"M18 19v-6"}],["path",{d:"M22 19V9"}],["path",{d:"M2 19V9a4 4 0 0 1 4-4c2 0 4 1.33 6 4s4 4 6 4a4 4 0 1 0-3-6.65"}]],nv=[["path",{d:"M17 10h-1a4 4 0 1 1 4-4v.534"}],["path",{d:"M17 6h1a4 4 0 0 1 1.42 7.74l-2.29.87a6 6 0 0 1-5.339-10.68l2.069-1.31"}],["path",{d:"M4.5 17c2.8-.5 4.4 0 5.5.8s1.8 2.2 2.3 3.7c-2 .4-3.5.4-4.8-.3-1.2-.6-2.3-1.9-3-4.2"}],["path",{d:"M9.77 12C4 15 2 22 2 22"}],["circle",{cx:"17",cy:"8",r:"2"}]],F2=[["path",{d:"M16.466 7.5C15.643 4.237 13.952 2 12 2 9.239 2 7 6.477 7 12s2.239 10 5 10c.342 0 .677-.069 1-.2"}],["path",{d:"m15.194 13.707 3.814 1.86-1.86 3.814"}],["path",{d:"M19 15.57c-1.804.885-4.274 1.43-7 1.43-5.523 0-10-2.239-10-5s4.477-5 10-5c4.838 0 8.873 1.718 9.8 4"}]],lv=[["path",{d:"m14.5 9.5 1 1"}],["path",{d:"m15.5 8.5-4 4"}],["path",{d:"M3 12a9 9 0 1 0 9-9 9.74 9.74 0 0 0-6.74 2.74L3 8"}],["path",{d:"M3 3v5h5"}],["circle",{cx:"10",cy:"14",r:"2"}]],ev=[["path",{d:"M3 12a9 9 0 1 0 9-9 9.75 9.75 0 0 0-6.74 2.74L3 8"}],["path",{d:"M3 3v5h5"}]],rv=[["path",{d:"M12 5H6a2 2 0 0 0-2 2v3"}],["path",{d:"m9 8 3-3-3-3"}],["path",{d:"M4 14v4a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2h-2"}]],ov=[["path",{d:"M20 9V7a2 2 0 0 0-2-2h-6"}],["path",{d:"m15 2-3 3 3 3"}],["path",{d:"M20 13v5a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V7a2 2 0 0 1 2-2h2"}]],vv=[["circle",{cx:"6",cy:"19",r:"3"}],["path",{d:"M9 19h8.5c.4 0 .9-.1 1.3-.2"}],["path",{d:"M5.2 5.2A3.5 3.53 0 0 0 6.5 12H12"}],["path",{d:"m2 2 20 20"}],["path",{d:"M21 15.3a3.5 3.5 0 0 0-3.3-3.3"}],["path",{d:"M15 5h-4.3"}],["circle",{cx:"18",cy:"5",r:"3"}]],$v=[["path",{d:"M21 12a9 9 0 1 1-9-9c2.52 0 4.93 1 6.74 2.74L21 8"}],["path",{d:"M21 3v5h-5"}]],mv=[["circle",{cx:"6",cy:"19",r:"3"}],["path",{d:"M9 19h8.5a3.5 3.5 0 0 0 0-7h-11a3.5 3.5 0 0 1 0-7H15"}],["circle",{cx:"18",cy:"5",r:"3"}]],yv=[["rect",{width:"20",height:"8",x:"2",y:"14",rx:"2"}],["path",{d:"M6.01 18H6"}],["path",{d:"M10.01 18H10"}],["path",{d:"M15 10v4"}],["path",{d:"M17.84 7.17a4 4 0 0 0-5.66 0"}],["path",{d:"M20.66 4.34a8 8 0 0 0-11.31 0"}]],z2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 12h18"}]],b2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M21 9H3"}],["path",{d:"M21 15H3"}]],sv=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M21 7.5H3"}],["path",{d:"M21 12H3"}],["path",{d:"M21 16.5H3"}]],gv=[["path",{d:"M4 11a9 9 0 0 1 9 9"}],["path",{d:"M4 4a16 16 0 0 1 16 16"}],["circle",{cx:"5",cy:"19",r:"1"}]],uv=[["path",{d:"M12 15v-3.014"}],["path",{d:"M16 15v-3.014"}],["path",{d:"M20 6H4"}],["path",{d:"M20 8V4"}],["path",{d:"M4 8V4"}],["path",{d:"M8 15v-3.014"}],["rect",{x:"3",y:"12",width:"18",height:"7",rx:"1"}]],Cv=[["path",{d:"M21.3 15.3a2.4 2.4 0 0 1 0 3.4l-2.6 2.6a2.4 2.4 0 0 1-3.4 0L2.7 8.7a2.41 2.41 0 0 1 0-3.4l2.6-2.6a2.41 2.41 0 0 1 3.4 0Z"}],["path",{d:"m14.5 12.5 2-2"}],["path",{d:"m11.5 9.5 2-2"}],["path",{d:"m8.5 6.5 2-2"}],["path",{d:"m17.5 15.5 2-2"}]],Hv=[["path",{d:"M6 11h8a4 4 0 0 0 0-8H9v18"}],["path",{d:"M6 15h8"}]],Av=[["path",{d:"M10 2v15"}],["path",{d:"M7 22a4 4 0 0 1-4-4 1 1 0 0 1 1-1h16a1 1 0 0 1 1 1 4 4 0 0 1-4 4z"}],["path",{d:"M9.159 2.46a1 1 0 0 1 1.521-.193l9.977 8.98A1 1 0 0 1 20 13H4a1 1 0 0 1-.824-1.567z"}]],wv=[["path",{d:"M7 21h10"}],["path",{d:"M12 21a9 9 0 0 0 9-9H3a9 9 0 0 0 9 9Z"}],["path",{d:"M11.38 12a2.4 2.4 0 0 1-.4-4.77 2.4 2.4 0 0 1 3.2-2.77 2.4 2.4 0 0 1 3.47-.63 2.4 2.4 0 0 1 3.37 3.37 2.4 2.4 0 0 1-1.1 3.7 2.51 2.51 0 0 1 .03 1.1"}],["path",{d:"m13 12 4-4"}],["path",{d:"M10.9 7.25A3.99 3.99 0 0 0 4 10c0 .73.2 1.41.54 2"}]],Vv=[["path",{d:"m2.37 11.223 8.372-6.777a2 2 0 0 1 2.516 0l8.371 6.777"}],["path",{d:"M21 15a1 1 0 0 1 1 1v2a1 1 0 0 1-1 1h-5.25"}],["path",{d:"M3 15a1 1 0 0 0-1 1v2a1 1 0 0 0 1 1h9"}],["path",{d:"m6.67 15 6.13 4.6a2 2 0 0 0 2.8-.4l3.15-4.2"}],["rect",{width:"20",height:"4",x:"2",y:"11",rx:"1"}]],Sv=[["path",{d:"M4 10a7.31 7.31 0 0 0 10 10Z"}],["path",{d:"m9 15 3-3"}],["path",{d:"M17 13a6 6 0 0 0-6-6"}],["path",{d:"M21 13A10 10 0 0 0 11 3"}]],Lv=[["path",{d:"m13.5 6.5-3.148-3.148a1.205 1.205 0 0 0-1.704 0L6.352 5.648a1.205 1.205 0 0 0 0 1.704L9.5 10.5"}],["path",{d:"M16.5 7.5 19 5"}],["path",{d:"m17.5 10.5 3.148 3.148a1.205 1.205 0 0 1 0 1.704l-2.296 2.296a1.205 1.205 0 0 1-1.704 0L13.5 14.5"}],["path",{d:"M9 21a6 6 0 0 0-6-6"}],["path",{d:"M9.352 10.648a1.205 1.205 0 0 0 0 1.704l2.296 2.296a1.205 1.205 0 0 0 1.704 0l4.296-4.296a1.205 1.205 0 0 0 0-1.704l-2.296-2.296a1.205 1.205 0 0 0-1.704 0z"}]],fv=[["path",{d:"m20 19.5-5.5 1.2"}],["path",{d:"M14.5 4v11.22a1 1 0 0 0 1.242.97L20 15.2"}],["path",{d:"m2.978 19.351 5.549-1.363A2 2 0 0 0 10 16V2"}],["path",{d:"M20 10 4 13.5"}]],kv=[["path",{d:"M10 2v3a1 1 0 0 0 1 1h5"}],["path",{d:"M18 18v-6a1 1 0 0 0-1-1h-6a1 1 0 0 0-1 1v6"}],["path",{d:"M18 22H4a2 2 0 0 1-2-2V6"}],["path",{d:"M8 18a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9.172a2 2 0 0 1 1.414.586l2.828 2.828A2 2 0 0 1 22 6.828V16a2 2 0 0 1-2.01 2z"}]],Pv=[["path",{d:"M13 13H8a1 1 0 0 0-1 1v7"}],["path",{d:"M14 8h1"}],["path",{d:"M17 21v-4"}],["path",{d:"m2 2 20 20"}],["path",{d:"M20.41 20.41A2 2 0 0 1 19 21H5a2 2 0 0 1-2-2V5a2 2 0 0 1 .59-1.41"}],["path",{d:"M29.5 11.5s5 5 4 5"}],["path",{d:"M9 3h6.2a2 2 0 0 1 1.4.6l3.8 3.8a2 2 0 0 1 .6 1.4V15"}]],Bv=[["path",{d:"M15.2 3a2 2 0 0 1 1.4.6l3.8 3.8a2 2 0 0 1 .6 1.4V19a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2z"}],["path",{d:"M17 21v-7a1 1 0 0 0-1-1H8a1 1 0 0 0-1 1v7"}],["path",{d:"M7 3v4a1 1 0 0 0 1 1h7"}]],R2=[["path",{d:"M5 7v11a1 1 0 0 0 1 1h11"}],["path",{d:"M5.293 18.707 11 13"}],["circle",{cx:"19",cy:"19",r:"2"}],["circle",{cx:"5",cy:"5",r:"2"}]],Dv=[["path",{d:"m16 16 3-8 3 8c-.87.65-1.92 1-3 1s-2.13-.35-3-1Z"}],["path",{d:"m2 16 3-8 3 8c-.87.65-1.92 1-3 1s-2.13-.35-3-1Z"}],["path",{d:"M7 21h10"}],["path",{d:"M12 3v18"}],["path",{d:"M3 7h2c2 0 5-1 7-2 2 1 5 2 7 2h2"}]],Fv=[["path",{d:"M12 3H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h14a2 2 0 0 0 2-2v-7"}],["path",{d:"M14 15H9v-5"}],["path",{d:"M16 3h5v5"}],["path",{d:"M21 3 9 15"}]],zv=[["path",{d:"M3 7V5a2 2 0 0 1 2-2h2"}],["path",{d:"M17 3h2a2 2 0 0 1 2 2v2"}],["path",{d:"M21 17v2a2 2 0 0 1-2 2h-2"}],["path",{d:"M7 21H5a2 2 0 0 1-2-2v-2"}],["path",{d:"M8 7v10"}],["path",{d:"M12 7v10"}],["path",{d:"M17 7v10"}]],bv=[["path",{d:"M3 7V5a2 2 0 0 1 2-2h2"}],["path",{d:"M17 3h2a2 2 0 0 1 2 2v2"}],["path",{d:"M21 17v2a2 2 0 0 1-2 2h-2"}],["path",{d:"M7 21H5a2 2 0 0 1-2-2v-2"}],["circle",{cx:"12",cy:"12",r:"1"}],["path",{d:"M18.944 12.33a1 1 0 0 0 0-.66 7.5 7.5 0 0 0-13.888 0 1 1 0 0 0 0 .66 7.5 7.5 0 0 0 13.888 0"}]],Rv=[["path",{d:"M3 7V5a2 2 0 0 1 2-2h2"}],["path",{d:"M17 3h2a2 2 0 0 1 2 2v2"}],["path",{d:"M21 17v2a2 2 0 0 1-2 2h-2"}],["path",{d:"M7 21H5a2 2 0 0 1-2-2v-2"}],["path",{d:"M8 14s1.5 2 4 2 4-2 4-2"}],["path",{d:"M9 9h.01"}],["path",{d:"M15 9h.01"}]],Tv=[["path",{d:"M17 3h2a2 2 0 0 1 2 2v2"}],["path",{d:"M21 17v2a2 2 0 0 1-2 2h-2"}],["path",{d:"M3 7V5a2 2 0 0 1 2-2h2"}],["path",{d:"M7 21H5a2 2 0 0 1-2-2v-2"}],["path",{d:"M7.828 13.07A3 3 0 0 1 12 8.764a3 3 0 0 1 4.172 4.306l-3.447 3.62a1 1 0 0 1-1.449 0z"}]],qv=[["path",{d:"M3 7V5a2 2 0 0 1 2-2h2"}],["path",{d:"M17 3h2a2 2 0 0 1 2 2v2"}],["path",{d:"M21 17v2a2 2 0 0 1-2 2h-2"}],["path",{d:"M7 21H5a2 2 0 0 1-2-2v-2"}],["path",{d:"M7 12h10"}]],Uv=[["path",{d:"M17 12v4a1 1 0 0 1-1 1h-4"}],["path",{d:"M17 3h2a2 2 0 0 1 2 2v2"}],["path",{d:"M17 8V7"}],["path",{d:"M21 17v2a2 2 0 0 1-2 2h-2"}],["path",{d:"M3 7V5a2 2 0 0 1 2-2h2"}],["path",{d:"M7 17h.01"}],["path",{d:"M7 21H5a2 2 0 0 1-2-2v-2"}],["rect",{x:"7",y:"7",width:"5",height:"5",rx:"1"}]],Ov=[["path",{d:"M3 7V5a2 2 0 0 1 2-2h2"}],["path",{d:"M17 3h2a2 2 0 0 1 2 2v2"}],["path",{d:"M21 17v2a2 2 0 0 1-2 2h-2"}],["path",{d:"M7 21H5a2 2 0 0 1-2-2v-2"}],["circle",{cx:"12",cy:"12",r:"3"}],["path",{d:"m16 16-1.9-1.9"}]],Zv=[["path",{d:"M3 7V5a2 2 0 0 1 2-2h2"}],["path",{d:"M17 3h2a2 2 0 0 1 2 2v2"}],["path",{d:"M21 17v2a2 2 0 0 1-2 2h-2"}],["path",{d:"M7 21H5a2 2 0 0 1-2-2v-2"}],["path",{d:"M7 8h8"}],["path",{d:"M7 12h10"}],["path",{d:"M7 16h6"}]],Gv=[["path",{d:"M3 7V5a2 2 0 0 1 2-2h2"}],["path",{d:"M17 3h2a2 2 0 0 1 2 2v2"}],["path",{d:"M21 17v2a2 2 0 0 1-2 2h-2"}],["path",{d:"M7 21H5a2 2 0 0 1-2-2v-2"}]],Iv=[["path",{d:"M14 21v-3a2 2 0 0 0-4 0v3"}],["path",{d:"M18 5v16"}],["path",{d:"m4 6 7.106-3.79a2 2 0 0 1 1.788 0L20 6"}],["path",{d:"m6 11-3.52 2.147a1 1 0 0 0-.48.854V19a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-5a1 1 0 0 0-.48-.853L18 11"}],["path",{d:"M6 5v16"}],["circle",{cx:"12",cy:"9",r:"2"}]],Wv=[["path",{d:"M5.42 9.42 8 12"}],["circle",{cx:"4",cy:"8",r:"2"}],["path",{d:"m14 6-8.58 8.58"}],["circle",{cx:"4",cy:"16",r:"2"}],["path",{d:"M10.8 14.8 14 18"}],["path",{d:"M16 12h-2"}],["path",{d:"M22 12h-2"}]],Ev=[["circle",{cx:"6",cy:"6",r:"3"}],["path",{d:"M8.12 8.12 12 12"}],["path",{d:"M20 4 8.12 15.88"}],["circle",{cx:"6",cy:"18",r:"3"}],["path",{d:"M14.8 14.8 20 20"}]],Xv=[["path",{d:"M13 3H4a2 2 0 0 0-2 2v10a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-3"}],["path",{d:"M8 21h8"}],["path",{d:"M12 17v4"}],["path",{d:"m22 3-5 5"}],["path",{d:"m17 3 5 5"}]],jv=[["path",{d:"M13 3H4a2 2 0 0 0-2 2v10a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-3"}],["path",{d:"M8 21h8"}],["path",{d:"M12 17v4"}],["path",{d:"m17 8 5-5"}],["path",{d:"M17 3h5v5"}]],Nv=[["path",{d:"M15 12h-5"}],["path",{d:"M15 8h-5"}],["path",{d:"M19 17V5a2 2 0 0 0-2-2H4"}],["path",{d:"M8 21h12a2 2 0 0 0 2-2v-1a1 1 0 0 0-1-1H11a1 1 0 0 0-1 1v1a2 2 0 1 1-4 0V5a2 2 0 1 0-4 0v2a1 1 0 0 0 1 1h3"}]],Kv=[["path",{d:"M19 17V5a2 2 0 0 0-2-2H4"}],["path",{d:"M8 21h12a2 2 0 0 0 2-2v-1a1 1 0 0 0-1-1H11a1 1 0 0 0-1 1v1a2 2 0 1 1-4 0V5a2 2 0 1 0-4 0v2a1 1 0 0 0 1 1h3"}]],Qv=[["path",{d:"m8 11 2 2 4-4"}],["circle",{cx:"11",cy:"11",r:"8"}],["path",{d:"m21 21-4.3-4.3"}]],Jv=[["path",{d:"m13 13.5 2-2.5-2-2.5"}],["path",{d:"m21 21-4.3-4.3"}],["path",{d:"M9 8.5 7 11l2 2.5"}],["circle",{cx:"11",cy:"11",r:"8"}]],Yv=[["path",{d:"m13.5 8.5-5 5"}],["circle",{cx:"11",cy:"11",r:"8"}],["path",{d:"m21 21-4.3-4.3"}]],_v=[["path",{d:"m13.5 8.5-5 5"}],["path",{d:"m8.5 8.5 5 5"}],["circle",{cx:"11",cy:"11",r:"8"}],["path",{d:"m21 21-4.3-4.3"}]],xv=[["path",{d:"m21 21-4.34-4.34"}],["circle",{cx:"11",cy:"11",r:"8"}]],a$=[["path",{d:"M16 5a4 3 0 0 0-8 0c0 4 8 3 8 7a4 3 0 0 1-8 0"}],["path",{d:"M8 19a4 3 0 0 0 8 0c0-4-8-3-8-7a4 3 0 0 1 8 0"}]],T2=[["path",{d:"M3.714 3.048a.498.498 0 0 0-.683.627l2.843 7.627a2 2 0 0 1 0 1.396l-2.842 7.627a.498.498 0 0 0 .682.627l18-8.5a.5.5 0 0 0 0-.904z"}],["path",{d:"M6 12h16"}]],t$=[["rect",{x:"14",y:"14",width:"8",height:"8",rx:"2"}],["rect",{x:"2",y:"2",width:"8",height:"8",rx:"2"}],["path",{d:"M7 14v1a2 2 0 0 0 2 2h1"}],["path",{d:"M14 7h1a2 2 0 0 1 2 2v1"}]],h$=[["path",{d:"M14.536 21.686a.5.5 0 0 0 .937-.024l6.5-19a.496.496 0 0 0-.635-.635l-19 6.5a.5.5 0 0 0-.024.937l7.93 3.18a2 2 0 0 1 1.112 1.11z"}],["path",{d:"m21.854 2.147-10.94 10.939"}]],d$=[["path",{d:"m16 16-4 4-4-4"}],["path",{d:"M3 12h18"}],["path",{d:"m8 8 4-4 4 4"}]],c$=[["path",{d:"M12 3v18"}],["path",{d:"m16 16 4-4-4-4"}],["path",{d:"m8 8-4 4 4 4"}]],M$=[["path",{d:"m10.852 14.772-.383.923"}],["path",{d:"M13.148 14.772a3 3 0 1 0-2.296-5.544l-.383-.923"}],["path",{d:"m13.148 9.228.383-.923"}],["path",{d:"m13.53 15.696-.382-.924a3 3 0 1 1-2.296-5.544"}],["path",{d:"m14.772 10.852.923-.383"}],["path",{d:"m14.772 13.148.923.383"}],["path",{d:"M4.5 10H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v4a2 2 0 0 1-2 2h-.5"}],["path",{d:"M4.5 14H4a2 2 0 0 0-2 2v4a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-4a2 2 0 0 0-2-2h-.5"}],["path",{d:"M6 18h.01"}],["path",{d:"M6 6h.01"}],["path",{d:"m9.228 10.852-.923-.383"}],["path",{d:"m9.228 13.148-.923.383"}]],p$=[["path",{d:"M6 10H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v4a2 2 0 0 1-2 2h-2"}],["path",{d:"M6 14H4a2 2 0 0 0-2 2v4a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-4a2 2 0 0 0-2-2h-2"}],["path",{d:"M6 6h.01"}],["path",{d:"M6 18h.01"}],["path",{d:"m13 6-4 6h6l-4 6"}]],i$=[["path",{d:"M7 2h13a2 2 0 0 1 2 2v4a2 2 0 0 1-2 2h-5"}],["path",{d:"M10 10 2.5 2.5C2 2 2 2.5 2 5v3a2 2 0 0 0 2 2h6z"}],["path",{d:"M22 17v-1a2 2 0 0 0-2-2h-1"}],["path",{d:"M4 14a2 2 0 0 0-2 2v4a2 2 0 0 0 2 2h16.5l1-.5.5.5-8-8H4z"}],["path",{d:"M6 18h.01"}],["path",{d:"m2 2 20 20"}]],n$=[["rect",{width:"20",height:"8",x:"2",y:"2",rx:"2",ry:"2"}],["rect",{width:"20",height:"8",x:"2",y:"14",rx:"2",ry:"2"}],["line",{x1:"6",x2:"6.01",y1:"6",y2:"6"}],["line",{x1:"6",x2:"6.01",y1:"18",y2:"18"}]],l$=[["path",{d:"M14 17H5"}],["path",{d:"M19 7h-9"}],["circle",{cx:"17",cy:"17",r:"3"}],["circle",{cx:"7",cy:"7",r:"3"}]],e$=[["path",{d:"M9.671 4.136a2.34 2.34 0 0 1 4.659 0 2.34 2.34 0 0 0 3.319 1.915 2.34 2.34 0 0 1 2.33 4.033 2.34 2.34 0 0 0 0 3.831 2.34 2.34 0 0 1-2.33 4.033 2.34 2.34 0 0 0-3.319 1.915 2.34 2.34 0 0 1-4.659 0 2.34 2.34 0 0 0-3.32-1.915 2.34 2.34 0 0 1-2.33-4.033 2.34 2.34 0 0 0 0-3.831A2.34 2.34 0 0 1 6.35 6.051a2.34 2.34 0 0 0 3.319-1.915"}],["circle",{cx:"12",cy:"12",r:"3"}]],r$=[["circle",{cx:"18",cy:"5",r:"3"}],["circle",{cx:"6",cy:"12",r:"3"}],["circle",{cx:"18",cy:"19",r:"3"}],["line",{x1:"8.59",x2:"15.42",y1:"13.51",y2:"17.49"}],["line",{x1:"15.41",x2:"8.59",y1:"6.51",y2:"10.49"}]],o$=[["path",{d:"M8.3 10a.7.7 0 0 1-.626-1.079L11.4 3a.7.7 0 0 1 1.198-.043L16.3 8.9a.7.7 0 0 1-.572 1.1Z"}],["rect",{x:"3",y:"14",width:"7",height:"7",rx:"1"}],["circle",{cx:"17.5",cy:"17.5",r:"3.5"}]],v$=[["path",{d:"M12 2v13"}],["path",{d:"m16 6-4-4-4 4"}],["path",{d:"M4 12v8a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2v-8"}]],$$=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["line",{x1:"3",x2:"21",y1:"9",y2:"9"}],["line",{x1:"3",x2:"21",y1:"15",y2:"15"}],["line",{x1:"9",x2:"9",y1:"9",y2:"21"}],["line",{x1:"15",x2:"15",y1:"9",y2:"21"}]],m$=[["path",{d:"M14 11a2 2 0 1 1-4 0 4 4 0 0 1 8 0 6 6 0 0 1-12 0 8 8 0 0 1 16 0 10 10 0 1 1-20 0 11.93 11.93 0 0 1 2.42-7.22 2 2 0 1 1 3.16 2.44"}]],y$=[["path",{d:"M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"}],["path",{d:"M12 8v4"}],["path",{d:"M12 16h.01"}]],s$=[["path",{d:"M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"}],["path",{d:"m4.243 5.21 14.39 12.472"}]],g$=[["path",{d:"M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"}],["path",{d:"m9 12 2 2 4-4"}]],u$=[["path",{d:"M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"}],["path",{d:"M8 12h.01"}],["path",{d:"M12 12h.01"}],["path",{d:"M16 12h.01"}]],C$=[["path",{d:"M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"}],["path",{d:"M12 22V2"}]],H$=[["path",{d:"M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"}],["path",{d:"M9 12h6"}]],A$=[["path",{d:"m2 2 20 20"}],["path",{d:"M5 5a1 1 0 0 0-1 1v7c0 5 3.5 7.5 7.67 8.94a1 1 0 0 0 .67.01c2.35-.82 4.48-1.97 5.9-3.71"}],["path",{d:"M9.309 3.652A12.252 12.252 0 0 0 11.24 2.28a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1v7a9.784 9.784 0 0 1-.08 1.264"}]],w$=[["path",{d:"M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"}],["path",{d:"M9 12h6"}],["path",{d:"M12 9v6"}]],q2=[["path",{d:"M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"}],["path",{d:"M9.1 9a3 3 0 0 1 5.82 1c0 2-3 3-3 3"}],["path",{d:"M12 17h.01"}]],V$=[["path",{d:"M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"}],["path",{d:"M6.376 18.91a6 6 0 0 1 11.249.003"}],["circle",{cx:"12",cy:"11",r:"4"}]],U2=[["path",{d:"M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"}],["path",{d:"m14.5 9.5-5 5"}],["path",{d:"m9.5 9.5 5 5"}]],S$=[["path",{d:"M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"}]],L$=[["circle",{cx:"12",cy:"12",r:"8"}],["path",{d:"M12 2v7.5"}],["path",{d:"m19 5-5.23 5.23"}],["path",{d:"M22 12h-7.5"}],["path",{d:"m19 19-5.23-5.23"}],["path",{d:"M12 14.5V22"}],["path",{d:"M10.23 13.77 5 19"}],["path",{d:"M9.5 12H2"}],["path",{d:"M10.23 10.23 5 5"}],["circle",{cx:"12",cy:"12",r:"2.5"}]],f$=[["path",{d:"M12 10.189V14"}],["path",{d:"M12 2v3"}],["path",{d:"M19 13V7a2 2 0 0 0-2-2H7a2 2 0 0 0-2 2v6"}],["path",{d:"M19.38 20A11.6 11.6 0 0 0 21 14l-8.188-3.639a2 2 0 0 0-1.624 0L3 14a11.6 11.6 0 0 0 2.81 7.76"}],["path",{d:"M2 21c.6.5 1.2 1 2.5 1 2.5 0 2.5-2 5-2 1.3 0 1.9.5 2.5 1s1.2 1 2.5 1c2.5 0 2.5-2 5-2 1.3 0 1.9.5 2.5 1"}]],k$=[["path",{d:"M20.38 3.46 16 2a4 4 0 0 1-8 0L3.62 3.46a2 2 0 0 0-1.34 2.23l.58 3.47a1 1 0 0 0 .99.84H6v10c0 1.1.9 2 2 2h8a2 2 0 0 0 2-2V10h2.15a1 1 0 0 0 .99-.84l.58-3.47a2 2 0 0 0-1.34-2.23z"}]],P$=[["path",{d:"M16 10a4 4 0 0 1-8 0"}],["path",{d:"M3.103 6.034h17.794"}],["path",{d:"M3.4 5.467a2 2 0 0 0-.4 1.2V20a2 2 0 0 0 2 2h14a2 2 0 0 0 2-2V6.667a2 2 0 0 0-.4-1.2l-2-2.667A2 2 0 0 0 17 2H7a2 2 0 0 0-1.6.8z"}]],B$=[["path",{d:"m15 11-1 9"}],["path",{d:"m19 11-4-7"}],["path",{d:"M2 11h20"}],["path",{d:"m3.5 11 1.6 7.4a2 2 0 0 0 2 1.6h9.8a2 2 0 0 0 2-1.6l1.7-7.4"}],["path",{d:"M4.5 15.5h15"}],["path",{d:"m5 11 4-7"}],["path",{d:"m9 11 1 9"}]],D$=[["circle",{cx:"8",cy:"21",r:"1"}],["circle",{cx:"19",cy:"21",r:"1"}],["path",{d:"M2.05 2.05h2l2.66 12.42a2 2 0 0 0 2 1.58h9.78a2 2 0 0 0 1.95-1.57l1.65-7.43H5.12"}]],F$=[["path",{d:"M21.56 4.56a1.5 1.5 0 0 1 0 2.122l-.47.47a3 3 0 0 1-4.212-.03 3 3 0 0 1 0-4.243l.44-.44a1.5 1.5 0 0 1 2.121 0z"}],["path",{d:"M3 22a1 1 0 0 1-1-1v-3.586a1 1 0 0 1 .293-.707l3.355-3.355a1.205 1.205 0 0 1 1.704 0l3.296 3.296a1.205 1.205 0 0 1 0 1.704l-3.355 3.355a1 1 0 0 1-.707.293z"}],["path",{d:"m9 15 7.879-7.878"}]],z$=[["path",{d:"m4 4 2.5 2.5"}],["path",{d:"M13.5 6.5a4.95 4.95 0 0 0-7 7"}],["path",{d:"M15 5 5 15"}],["path",{d:"M14 17v.01"}],["path",{d:"M10 16v.01"}],["path",{d:"M13 13v.01"}],["path",{d:"M16 10v.01"}],["path",{d:"M11 20v.01"}],["path",{d:"M17 14v.01"}],["path",{d:"M20 11v.01"}]],b$=[["path",{d:"M10 22v-5"}],["path",{d:"M14 19v-2"}],["path",{d:"M14 2v4a2 2 0 0 0 2 2h4"}],["path",{d:"M18 20v-3"}],["path",{d:"M2 13h20"}],["path",{d:"M20 13V7l-5-5H6a2 2 0 0 0-2 2v9"}],["path",{d:"M6 20v-3"}]],R$=[["path",{d:"M11 12h.01"}],["path",{d:"M13 22c.5-.5 1.12-1 2.5-1-1.38 0-2-.5-2.5-1"}],["path",{d:"M14 2a3.28 3.28 0 0 1-3.227 1.798l-6.17-.561A2.387 2.387 0 1 0 4.387 8H15.5a1 1 0 0 1 0 13 1 1 0 0 0 0-5H12a7 7 0 0 1-7-7V8"}],["path",{d:"M14 8a8.5 8.5 0 0 1 0 8"}],["path",{d:"M16 16c2 0 4.5-4 4-6"}]],T$=[["path",{d:"m15 15 6 6m-6-6v4.8m0-4.8h4.8"}],["path",{d:"M9 19.8V15m0 0H4.2M9 15l-6 6"}],["path",{d:"M15 4.2V9m0 0h4.8M15 9l6-6"}],["path",{d:"M9 4.2V9m0 0H4.2M9 9 3 3"}]],q$=[["path",{d:"M12 22v-5.172a2 2 0 0 0-.586-1.414L9.5 13.5"}],["path",{d:"M14.5 14.5 12 17"}],["path",{d:"M17 8.8A6 6 0 0 1 13.8 20H10A6.5 6.5 0 0 1 7 8a5 5 0 0 1 10 0z"}]],U$=[["path",{d:"m18 14 4 4-4 4"}],["path",{d:"m18 2 4 4-4 4"}],["path",{d:"M2 18h1.973a4 4 0 0 0 3.3-1.7l5.454-8.6a4 4 0 0 1 3.3-1.7H22"}],["path",{d:"M2 6h1.972a4 4 0 0 1 3.6 2.2"}],["path",{d:"M22 18h-6.041a4 4 0 0 1-3.3-1.8l-.359-.45"}]],O$=[["path",{d:"M18 7V5a1 1 0 0 0-1-1H6.5a.5.5 0 0 0-.4.8l4.5 6a2 2 0 0 1 0 2.4l-4.5 6a.5.5 0 0 0 .4.8H17a1 1 0 0 0 1-1v-2"}]],Z$=[["path",{d:"M2 20h.01"}],["path",{d:"M7 20v-4"}],["path",{d:"M12 20v-8"}],["path",{d:"M17 20V8"}]],G$=[["path",{d:"M2 20h.01"}],["path",{d:"M7 20v-4"}]],I$=[["path",{d:"M2 20h.01"}],["path",{d:"M7 20v-4"}],["path",{d:"M12 20v-8"}]],W$=[["path",{d:"M2 20h.01"}]],E$=[["path",{d:"M2 20h.01"}],["path",{d:"M7 20v-4"}],["path",{d:"M12 20v-8"}],["path",{d:"M17 20V8"}],["path",{d:"M22 4v16"}]],X$=[["path",{d:"m21 17-2.156-1.868A.5.5 0 0 0 18 15.5v.5a1 1 0 0 1-1 1h-2a1 1 0 0 1-1-1c0-2.545-3.991-3.97-8.5-4a1 1 0 0 0 0 5c4.153 0 4.745-11.295 5.708-13.5a2.5 2.5 0 1 1 3.31 3.284"}],["path",{d:"M3 21h18"}]],j$=[["path",{d:"M10 9H4L2 7l2-2h6"}],["path",{d:"M14 5h6l2 2-2 2h-6"}],["path",{d:"M10 22V4a2 2 0 1 1 4 0v18"}],["path",{d:"M8 22h8"}]],N$=[["path",{d:"M12 13v8"}],["path",{d:"M12 3v3"}],["path",{d:"M18 6a2 2 0 0 1 1.387.56l2.307 2.22a1 1 0 0 1 0 1.44l-2.307 2.22A2 2 0 0 1 18 13H6a2 2 0 0 1-1.387-.56l-2.306-2.22a1 1 0 0 1 0-1.44l2.306-2.22A2 2 0 0 1 6 6z"}]],K$=[["path",{d:"M7 18v-6a5 5 0 1 1 10 0v6"}],["path",{d:"M5 21a1 1 0 0 0 1 1h12a1 1 0 0 0 1-1v-1a2 2 0 0 0-2-2H7a2 2 0 0 0-2 2z"}],["path",{d:"M21 12h1"}],["path",{d:"M18.5 4.5 18 5"}],["path",{d:"M2 12h1"}],["path",{d:"M12 2v1"}],["path",{d:"m4.929 4.929.707.707"}],["path",{d:"M12 12v6"}]],Q$=[["path",{d:"M17.971 4.285A2 2 0 0 1 21 6v12a2 2 0 0 1-3.029 1.715l-9.997-5.998a2 2 0 0 1-.003-3.432z"}],["path",{d:"M3 20V4"}]],J$=[["path",{d:"M21 4v16"}],["path",{d:"M6.029 4.285A2 2 0 0 0 3 6v12a2 2 0 0 0 3.029 1.715l9.997-5.998a2 2 0 0 0 .003-3.432z"}]],Y$=[["path",{d:"m12.5 17-.5-1-.5 1h1z"}],["path",{d:"M15 22a1 1 0 0 0 1-1v-1a2 2 0 0 0 1.56-3.25 8 8 0 1 0-11.12 0A2 2 0 0 0 8 20v1a1 1 0 0 0 1 1z"}],["circle",{cx:"15",cy:"12",r:"1"}],["circle",{cx:"9",cy:"12",r:"1"}]],_$=[["rect",{width:"3",height:"8",x:"13",y:"2",rx:"1.5"}],["path",{d:"M19 8.5V10h1.5A1.5 1.5 0 1 0 19 8.5"}],["rect",{width:"3",height:"8",x:"8",y:"14",rx:"1.5"}],["path",{d:"M5 15.5V14H3.5A1.5 1.5 0 1 0 5 15.5"}],["rect",{width:"8",height:"3",x:"14",y:"13",rx:"1.5"}],["path",{d:"M15.5 19H14v1.5a1.5 1.5 0 1 0 1.5-1.5"}],["rect",{width:"8",height:"3",x:"2",y:"8",rx:"1.5"}],["path",{d:"M8.5 5H10V3.5A1.5 1.5 0 1 0 8.5 5"}]],x$=[["path",{d:"M22 2 2 22"}]],am=[["path",{d:"M11 16.586V19a1 1 0 0 1-1 1H2L18.37 3.63a1 1 0 1 1 3 3l-9.663 9.663a1 1 0 0 1-1.414 0L8 14"}]],tm=[["path",{d:"M10 5H3"}],["path",{d:"M12 19H3"}],["path",{d:"M14 3v4"}],["path",{d:"M16 17v4"}],["path",{d:"M21 12h-9"}],["path",{d:"M21 19h-5"}],["path",{d:"M21 5h-7"}],["path",{d:"M8 10v4"}],["path",{d:"M8 12H3"}]],O2=[["path",{d:"M10 8h4"}],["path",{d:"M12 21v-9"}],["path",{d:"M12 8V3"}],["path",{d:"M17 16h4"}],["path",{d:"M19 12V3"}],["path",{d:"M19 21v-5"}],["path",{d:"M3 14h4"}],["path",{d:"M5 10V3"}],["path",{d:"M5 21v-7"}]],hm=[["rect",{width:"14",height:"20",x:"5",y:"2",rx:"2",ry:"2"}],["path",{d:"M12.667 8 10 12h4l-2.667 4"}]],dm=[["rect",{width:"7",height:"12",x:"2",y:"6",rx:"1"}],["path",{d:"M13 8.32a7.43 7.43 0 0 1 0 7.36"}],["path",{d:"M16.46 6.21a11.76 11.76 0 0 1 0 11.58"}],["path",{d:"M19.91 4.1a15.91 15.91 0 0 1 .01 15.8"}]],cm=[["rect",{width:"14",height:"20",x:"5",y:"2",rx:"2",ry:"2"}],["path",{d:"M12 18h.01"}]],Mm=[["path",{d:"M22 11v1a10 10 0 1 1-9-10"}],["path",{d:"M8 14s1.5 2 4 2 4-2 4-2"}],["line",{x1:"9",x2:"9.01",y1:"9",y2:"9"}],["line",{x1:"15",x2:"15.01",y1:"9",y2:"9"}],["path",{d:"M16 5h6"}],["path",{d:"M19 2v6"}]],pm=[["circle",{cx:"12",cy:"12",r:"10"}],["path",{d:"M8 14s1.5 2 4 2 4-2 4-2"}],["line",{x1:"9",x2:"9.01",y1:"9",y2:"9"}],["line",{x1:"15",x2:"15.01",y1:"9",y2:"9"}]],im=[["path",{d:"M2 13a6 6 0 1 0 12 0 4 4 0 1 0-8 0 2 2 0 0 0 4 0"}],["circle",{cx:"10",cy:"13",r:"8"}],["path",{d:"M2 21h12c4.4 0 8-3.6 8-8V7a2 2 0 1 0-4 0v6"}],["path",{d:"M18 3 19.1 5.2"}],["path",{d:"M22 3 20.9 5.2"}]],nm=[["path",{d:"m10 20-1.25-2.5L6 18"}],["path",{d:"M10 4 8.75 6.5 6 6"}],["path",{d:"m14 20 1.25-2.5L18 18"}],["path",{d:"m14 4 1.25 2.5L18 6"}],["path",{d:"m17 21-3-6h-4"}],["path",{d:"m17 3-3 6 1.5 3"}],["path",{d:"M2 12h6.5L10 9"}],["path",{d:"m20 10-1.5 2 1.5 2"}],["path",{d:"M22 12h-6.5L14 15"}],["path",{d:"m4 10 1.5 2L4 14"}],["path",{d:"m7 21 3-6-1.5-3"}],["path",{d:"m7 3 3 6h4"}]],lm=[["path",{d:"M20 9V6a2 2 0 0 0-2-2H6a2 2 0 0 0-2 2v3"}],["path",{d:"M2 16a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-5a2 2 0 0 0-4 0v1.5a.5.5 0 0 1-.5.5h-11a.5.5 0 0 1-.5-.5V11a2 2 0 0 0-4 0z"}],["path",{d:"M4 18v2"}],["path",{d:"M20 18v2"}],["path",{d:"M12 4v9"}]],em=[["path",{d:"M10.5 2v4"}],["path",{d:"M14 2H7a2 2 0 0 0-2 2"}],["path",{d:"M19.29 14.76A6.67 6.67 0 0 1 17 11a6.6 6.6 0 0 1-2.29 3.76c-1.15.92-1.71 2.04-1.71 3.19 0 2.22 1.8 4.05 4 4.05s4-1.83 4-4.05c0-1.16-.57-2.26-1.71-3.19"}],["path",{d:"M9.607 21H6a2 2 0 0 1-2-2v-7a2 2 0 0 1 2-2h7V7a1 1 0 0 0-1-1H9a1 1 0 0 0-1 1v3"}]],rm=[["path",{d:"M12 21a9 9 0 0 0 9-9H3a9 9 0 0 0 9 9Z"}],["path",{d:"M7 21h10"}],["path",{d:"M19.5 12 22 6"}],["path",{d:"M16.25 3c.27.1.8.53.75 1.36-.06.83-.93 1.2-1 2.02-.05.78.34 1.24.73 1.62"}],["path",{d:"M11.25 3c.27.1.8.53.74 1.36-.05.83-.93 1.2-.98 2.02-.06.78.33 1.24.72 1.62"}],["path",{d:"M6.25 3c.27.1.8.53.75 1.36-.06.83-.93 1.2-1 2.02-.05.78.34 1.24.74 1.62"}]],om=[["path",{d:"M22 17v1c0 .5-.5 1-1 1H3c-.5 0-1-.5-1-1v-1"}]],vm=[["path",{d:"M12 18v4"}],["path",{d:"M2 14.499a5.5 5.5 0 0 0 9.591 3.675.6.6 0 0 1 .818.001A5.5 5.5 0 0 0 22 14.5c0-2.29-1.5-4-3-5.5l-5.492-5.312a2 2 0 0 0-3-.02L5 8.999c-1.5 1.5-3 3.2-3 5.5"}]],$m=[["path",{d:"M11.017 2.814a1 1 0 0 1 1.966 0l1.051 5.558a2 2 0 0 0 1.594 1.594l5.558 1.051a1 1 0 0 1 0 1.966l-5.558 1.051a2 2 0 0 0-1.594 1.594l-1.051 5.558a1 1 0 0 1-1.966 0l-1.051-5.558a2 2 0 0 0-1.594-1.594l-5.558-1.051a1 1 0 0 1 0-1.966l5.558-1.051a2 2 0 0 0 1.594-1.594z"}]],Z2=[["path",{d:"M11.017 2.814a1 1 0 0 1 1.966 0l1.051 5.558a2 2 0 0 0 1.594 1.594l5.558 1.051a1 1 0 0 1 0 1.966l-5.558 1.051a2 2 0 0 0-1.594 1.594l-1.051 5.558a1 1 0 0 1-1.966 0l-1.051-5.558a2 2 0 0 0-1.594-1.594l-5.558-1.051a1 1 0 0 1 0-1.966l5.558-1.051a2 2 0 0 0 1.594-1.594z"}],["path",{d:"M20 2v4"}],["path",{d:"M22 4h-4"}],["circle",{cx:"4",cy:"20",r:"2"}]],mm=[["rect",{width:"16",height:"20",x:"4",y:"2",rx:"2"}],["path",{d:"M12 6h.01"}],["circle",{cx:"12",cy:"14",r:"4"}],["path",{d:"M12 14h.01"}]],ym=[["path",{d:"M8.8 20v-4.1l1.9.2a2.3 2.3 0 0 0 2.164-2.1V8.3A5.37 5.37 0 0 0 2 8.25c0 2.8.656 3.054 1 4.55a5.77 5.77 0 0 1 .029 2.758L2 20"}],["path",{d:"M19.8 17.8a7.5 7.5 0 0 0 .003-10.603"}],["path",{d:"M17 15a3.5 3.5 0 0 0-.025-4.975"}]],sm=[["path",{d:"m6 16 6-12 6 12"}],["path",{d:"M8 12h8"}],["path",{d:"M4 21c1.1 0 1.1-1 2.3-1s1.1 1 2.3 1c1.1 0 1.1-1 2.3-1 1.1 0 1.1 1 2.3 1 1.1 0 1.1-1 2.3-1 1.1 0 1.1 1 2.3 1 1.1 0 1.1-1 2.3-1"}]],gm=[["path",{d:"m6 16 6-12 6 12"}],["path",{d:"M8 12h8"}],["path",{d:"m16 20 2 2 4-4"}]],um=[["path",{d:"M12.034 12.681a.498.498 0 0 1 .647-.647l9 3.5a.5.5 0 0 1-.033.943l-3.444 1.068a1 1 0 0 0-.66.66l-1.067 3.443a.5.5 0 0 1-.943.033z"}],["path",{d:"M5 17A12 12 0 0 1 17 5"}],["circle",{cx:"19",cy:"5",r:"2"}],["circle",{cx:"5",cy:"19",r:"2"}]],Cm=[["circle",{cx:"19",cy:"5",r:"2"}],["circle",{cx:"5",cy:"19",r:"2"}],["path",{d:"M5 17A12 12 0 0 1 17 5"}]],Hm=[["path",{d:"M16 3h5v5"}],["path",{d:"M8 3H3v5"}],["path",{d:"M12 22v-8.3a4 4 0 0 0-1.172-2.872L3 3"}],["path",{d:"m15 9 6-6"}]],Am=[["path",{d:"M17 13.44 4.442 17.082A2 2 0 0 0 4.982 21H19a2 2 0 0 0 .558-3.921l-1.115-.32A2 2 0 0 1 17 14.837V7.66"}],["path",{d:"m7 10.56 12.558-3.642A2 2 0 0 0 19.018 3H5a2 2 0 0 0-.558 3.921l1.115.32A2 2 0 0 1 7 9.163v7.178"}]],wm=[["path",{d:"M15.295 19.562 16 22"}],["path",{d:"m17 16 3.758 2.098"}],["path",{d:"m19 12.5 3.026-.598"}],["path",{d:"M7.61 6.3a3 3 0 0 0-3.92 1.3l-1.38 2.79a3 3 0 0 0 1.3 3.91l6.89 3.597a1 1 0 0 0 1.342-.447l3.106-6.211a1 1 0 0 0-.447-1.341z"}],["path",{d:"M8 9V2"}]],Vm=[["path",{d:"M3 3h.01"}],["path",{d:"M7 5h.01"}],["path",{d:"M11 7h.01"}],["path",{d:"M3 7h.01"}],["path",{d:"M7 9h.01"}],["path",{d:"M3 11h.01"}],["rect",{width:"4",height:"4",x:"15",y:"5"}],["path",{d:"m19 9 2 2v10c0 .6-.4 1-1 1h-6c-.6 0-1-.4-1-1V11l2-2"}],["path",{d:"m13 14 8-2"}],["path",{d:"m13 19 8-2"}]],Sm=[["path",{d:"M14 9.536V7a4 4 0 0 1 4-4h1.5a.5.5 0 0 1 .5.5V5a4 4 0 0 1-4 4 4 4 0 0 0-4 4c0 2 1 3 1 5a5 5 0 0 1-1 3"}],["path",{d:"M4 9a5 5 0 0 1 8 4 5 5 0 0 1-8-4"}],["path",{d:"M5 21h14"}]],G2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M17 12h-2l-2 5-2-10-2 5H7"}]],I2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"m16 8-8 8"}],["path",{d:"M16 16H8V8"}]],W2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"m8 8 8 8"}],["path",{d:"M16 8v8H8"}]],E2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M12 8v8"}],["path",{d:"m8 12 4 4 4-4"}]],X2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"m12 8-4 4 4 4"}],["path",{d:"M16 12H8"}]],j2=[["path",{d:"M13 21h6a2 2 0 0 0 2-2V5a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v6"}],["path",{d:"m3 21 9-9"}],["path",{d:"M9 21H3v-6"}]],N2=[["path",{d:"M21 11V5a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h6"}],["path",{d:"m21 21-9-9"}],["path",{d:"M21 15v6h-6"}]],K2=[["path",{d:"M13 3h6a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2v-6"}],["path",{d:"m3 3 9 9"}],["path",{d:"M3 9V3h6"}]],Q2=[["path",{d:"M21 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h6"}],["path",{d:"m21 3-9 9"}],["path",{d:"M15 3h6v6"}]],J2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M8 12h8"}],["path",{d:"m12 16 4-4-4-4"}]],Y2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M8 16V8h8"}],["path",{d:"M16 16 8 8"}]],_2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M8 8h8v8"}],["path",{d:"m8 16 8-8"}]],x2=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"m16 12-4-4-4 4"}],["path",{d:"M12 16V8"}]],a0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M12 8v8"}],["path",{d:"m8.5 14 7-4"}],["path",{d:"m8.5 10 7 4"}]],t0=[["path",{d:"M4 22a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v16a2 2 0 0 1-2 2"}],["path",{d:"M10 22H8"}],["path",{d:"M16 22h-2"}],["circle",{cx:"8",cy:"8",r:"2"}],["path",{d:"M9.414 9.414 12 12"}],["path",{d:"M14.8 14.8 18 18"}],["circle",{cx:"8",cy:"16",r:"2"}],["path",{d:"m18 6-8.586 8.586"}]],$=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M9 8h7"}],["path",{d:"M8 12h6"}],["path",{d:"M11 16h5"}]],h0=[["path",{d:"M21 10.656V19a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h12.344"}],["path",{d:"m9 11 3 3L22 4"}]],d0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"m9 12 2 2 4-4"}]],c0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"m16 10-4 4-4-4"}]],M0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"m14 16-4-4 4-4"}]],p0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"m10 8 4 4-4 4"}]],i0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"m8 14 4-4 4 4"}]],n0=[["path",{d:"m10 9-3 3 3 3"}],["path",{d:"m14 15 3-3-3-3"}],["rect",{x:"3",y:"3",width:"18",height:"18",rx:"2"}]],Lm=[["path",{d:"M10 9.5 8 12l2 2.5"}],["path",{d:"M14 21h1"}],["path",{d:"m14 9.5 2 2.5-2 2.5"}],["path",{d:"M5 21a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2"}],["path",{d:"M9 21h1"}]],fm=[["path",{d:"M5 21a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2"}],["path",{d:"M9 21h1"}],["path",{d:"M14 21h1"}]],l0=[["path",{d:"M8 7v7"}],["path",{d:"M12 7v4"}],["path",{d:"M16 7v9"}],["path",{d:"M5 3a2 2 0 0 0-2 2"}],["path",{d:"M9 3h1"}],["path",{d:"M14 3h1"}],["path",{d:"M19 3a2 2 0 0 1 2 2"}],["path",{d:"M21 9v1"}],["path",{d:"M21 14v1"}],["path",{d:"M21 19a2 2 0 0 1-2 2"}],["path",{d:"M14 21h1"}],["path",{d:"M9 21h1"}],["path",{d:"M5 21a2 2 0 0 1-2-2"}],["path",{d:"M3 14v1"}],["path",{d:"M3 9v1"}]],e0=[["path",{d:"M12.034 12.681a.498.498 0 0 1 .647-.647l9 3.5a.5.5 0 0 1-.033.943l-3.444 1.068a1 1 0 0 0-.66.66l-1.067 3.443a.5.5 0 0 1-.943.033z"}],["path",{d:"M5 3a2 2 0 0 0-2 2"}],["path",{d:"M19 3a2 2 0 0 1 2 2"}],["path",{d:"M5 21a2 2 0 0 1-2-2"}],["path",{d:"M9 3h1"}],["path",{d:"M9 21h2"}],["path",{d:"M14 3h1"}],["path",{d:"M3 9v1"}],["path",{d:"M21 9v2"}],["path",{d:"M3 14v1"}]],km=[["path",{d:"M14 21h1"}],["path",{d:"M21 14v1"}],["path",{d:"M21 19a2 2 0 0 1-2 2"}],["path",{d:"M21 9v1"}],["path",{d:"M3 14v1"}],["path",{d:"M3 5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2"}],["path",{d:"M3 9v1"}],["path",{d:"M5 21a2 2 0 0 1-2-2"}],["path",{d:"M9 21h1"}]],r0=[["path",{d:"M5 3a2 2 0 0 0-2 2"}],["path",{d:"M19 3a2 2 0 0 1 2 2"}],["path",{d:"M21 19a2 2 0 0 1-2 2"}],["path",{d:"M5 21a2 2 0 0 1-2-2"}],["path",{d:"M9 3h1"}],["path",{d:"M9 21h1"}],["path",{d:"M14 3h1"}],["path",{d:"M14 21h1"}],["path",{d:"M3 9v1"}],["path",{d:"M21 9v1"}],["path",{d:"M3 14v1"}],["path",{d:"M21 14v1"}]],o0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["line",{x1:"8",x2:"16",y1:"12",y2:"12"}],["line",{x1:"12",x2:"12",y1:"16",y2:"16"}],["line",{x1:"12",x2:"12",y1:"8",y2:"8"}]],v0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["circle",{cx:"12",cy:"12",r:"1"}]],$0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M7 10h10"}],["path",{d:"M7 14h10"}]],m0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["path",{d:"M9 17c2 0 2.8-1 2.8-2.8V10c0-2 1-3.3 3.2-3"}],["path",{d:"M9 11.2h5.7"}]],y0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M8 7v7"}],["path",{d:"M12 7v4"}],["path",{d:"M16 7v9"}]],s0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M7 7v10"}],["path",{d:"M11 7v10"}],["path",{d:"m15 7 2 10"}]],g0=[["path",{d:"M8 16V8.5a.5.5 0 0 1 .9-.3l2.7 3.599a.5.5 0 0 0 .8 0l2.7-3.6a.5.5 0 0 1 .9.3V16"}],["rect",{x:"3",y:"3",width:"18",height:"18",rx:"2"}]],u0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M7 8h10"}],["path",{d:"M7 12h10"}],["path",{d:"M7 16h10"}]],C0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M8 12h8"}]],H0=[["path",{d:"M12.034 12.681a.498.498 0 0 1 .647-.647l9 3.5a.5.5 0 0 1-.033.943l-3.444 1.068a1 1 0 0 0-.66.66l-1.067 3.443a.5.5 0 0 1-.943.033z"}],["path",{d:"M21 11V5a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h6"}]],A0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M9 17V7h4a3 3 0 0 1 0 6H9"}]],w0=[["path",{d:"M3.6 3.6A2 2 0 0 1 5 3h14a2 2 0 0 1 2 2v14a2 2 0 0 1-.59 1.41"}],["path",{d:"M3 8.7V19a2 2 0 0 0 2 2h10.3"}],["path",{d:"m2 2 20 20"}],["path",{d:"M13 13a3 3 0 1 0 0-6H9v2"}],["path",{d:"M9 17v-2.3"}]],Pm=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["line",{x1:"10",x2:"10",y1:"15",y2:"9"}],["line",{x1:"14",x2:"14",y1:"15",y2:"9"}]],p=[["path",{d:"M12 3H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h14a2 2 0 0 0 2-2v-7"}],["path",{d:"M18.375 2.625a1 1 0 0 1 3 3l-9.013 9.014a2 2 0 0 1-.853.505l-2.873.84a.5.5 0 0 1-.62-.62l.84-2.873a2 2 0 0 1 .506-.852z"}]],V0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"m15 9-6 6"}],["path",{d:"M9 9h.01"}],["path",{d:"M15 15h.01"}]],S0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M7 7h10"}],["path",{d:"M10 7v10"}],["path",{d:"M16 17a2 2 0 0 1-2-2V7"}]],L0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M12 12H9.5a2.5 2.5 0 0 1 0-5H17"}],["path",{d:"M12 7v10"}],["path",{d:"M16 7v10"}]],f0=[["rect",{x:"3",y:"3",width:"18",height:"18",rx:"2"}],["path",{d:"M9 9.003a1 1 0 0 1 1.517-.859l4.997 2.997a1 1 0 0 1 0 1.718l-4.997 2.997A1 1 0 0 1 9 14.996z"}]],k0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M8 12h8"}],["path",{d:"M12 8v8"}]],P0=[["path",{d:"M12 7v4"}],["path",{d:"M7.998 9.003a5 5 0 1 0 8-.005"}],["rect",{x:"3",y:"3",width:"18",height:"18",rx:"2"}]],Bm=[["path",{d:"M7 12h2l2 5 2-10h4"}],["rect",{x:"3",y:"3",width:"18",height:"18",rx:"2"}]],Dm=[["path",{d:"M21 11a8 8 0 0 0-8-8"}],["path",{d:"M21 15v4a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h4"}]],B0=[["rect",{width:"20",height:"20",x:"2",y:"2",rx:"2"}],["circle",{cx:"8",cy:"8",r:"2"}],["path",{d:"M9.414 9.414 12 12"}],["path",{d:"M14.8 14.8 18 18"}],["circle",{cx:"8",cy:"16",r:"2"}],["path",{d:"m18 6-8.586 8.586"}]],D0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M16 8.9V7H8l4 5-4 5h8v-1.9"}]],F0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["line",{x1:"9",x2:"15",y1:"15",y2:"9"}]],z0=[["path",{d:"M8 19H5c-1 0-2-1-2-2V7c0-1 1-2 2-2h3"}],["path",{d:"M16 5h3c1 0 2 1 2 2v10c0 1-1 2-2 2h-3"}],["line",{x1:"12",x2:"12",y1:"4",y2:"20"}]],b0=[["path",{d:"M5 8V5c0-1 1-2 2-2h10c1 0 2 1 2 2v3"}],["path",{d:"M19 16v3c0 1-1 2-2 2H7c-1 0-2-1-2-2v-3"}],["line",{x1:"4",x2:"20",y1:"12",y2:"12"}]],Fm=[["rect",{x:"3",y:"3",width:"18",height:"18",rx:"2"}],["rect",{x:"8",y:"8",width:"8",height:"8",rx:"1"}]],zm=[["path",{d:"M4 10c-1.1 0-2-.9-2-2V4c0-1.1.9-2 2-2h4c1.1 0 2 .9 2 2"}],["path",{d:"M10 16c-1.1 0-2-.9-2-2v-4c0-1.1.9-2 2-2h4c1.1 0 2 .9 2 2"}],["rect",{width:"8",height:"8",x:"14",y:"14",rx:"2"}]],bm=[["path",{d:"M11.035 7.69a1 1 0 0 1 1.909.024l.737 1.452a1 1 0 0 0 .737.535l1.634.256a1 1 0 0 1 .588 1.806l-1.172 1.168a1 1 0 0 0-.282.866l.259 1.613a1 1 0 0 1-1.541 1.134l-1.465-.75a1 1 0 0 0-.912 0l-1.465.75a1 1 0 0 1-1.539-1.133l.258-1.613a1 1 0 0 0-.282-.866l-1.156-1.153a1 1 0 0 1 .572-1.822l1.633-.256a1 1 0 0 0 .737-.535z"}],["rect",{x:"3",y:"3",width:"18",height:"18",rx:"2"}]],Rm=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["rect",{x:"9",y:"9",width:"6",height:"6",rx:"1"}]],R0=[["path",{d:"m7 11 2-2-2-2"}],["path",{d:"M11 13h4"}],["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}]],T0=[["path",{d:"M18 21a6 6 0 0 0-12 0"}],["circle",{cx:"12",cy:"11",r:"4"}],["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}]],q0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["circle",{cx:"12",cy:"10",r:"3"}],["path",{d:"M7 21v-2a2 2 0 0 1 2-2h6a2 2 0 0 1 2 2v2"}]],U0=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["path",{d:"m15 9-6 6"}],["path",{d:"m9 9 6 6"}]],Tm=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}]],qm=[["path",{d:"M16 12v2a2 2 0 0 1-2 2H9a1 1 0 0 0-1 1v3a2 2 0 0 0 2 2h10a2 2 0 0 0 2-2V10a2 2 0 0 0-2-2h0"}],["path",{d:"M4 16a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h10a2 2 0 0 1 2 2v3a1 1 0 0 1-1 1h-5a2 2 0 0 0-2 2v2"}]],Um=[["path",{d:"M10 22a2 2 0 0 1-2-2"}],["path",{d:"M14 2a2 2 0 0 1 2 2"}],["path",{d:"M16 22h-2"}],["path",{d:"M2 10V8"}],["path",{d:"M2 4a2 2 0 0 1 2-2"}],["path",{d:"M20 8a2 2 0 0 1 2 2"}],["path",{d:"M22 14v2"}],["path",{d:"M22 20a2 2 0 0 1-2 2"}],["path",{d:"M4 16a2 2 0 0 1-2-2"}],["path",{d:"M8 10a2 2 0 0 1 2-2h5a1 1 0 0 1 1 1v5a2 2 0 0 1-2 2H9a1 1 0 0 1-1-1z"}],["path",{d:"M8 2h2"}]],Om=[["path",{d:"M10 22a2 2 0 0 1-2-2"}],["path",{d:"M16 22h-2"}],["path",{d:"M16 4a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v10a2 2 0 0 0 2 2h3a1 1 0 0 0 1-1v-5a2 2 0 0 1 2-2h5a1 1 0 0 0 1-1z"}],["path",{d:"M20 8a2 2 0 0 1 2 2"}],["path",{d:"M22 14v2"}],["path",{d:"M22 20a2 2 0 0 1-2 2"}]],Zm=[["path",{d:"M4 16a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h10a2 2 0 0 1 2 2v3a1 1 0 0 0 1 1h3a2 2 0 0 1 2 2v10a2 2 0 0 1-2 2H10a2 2 0 0 1-2-2v-3a1 1 0 0 0-1-1z"}]],Gm=[["path",{d:"M12 3c7.2 0 9 1.8 9 9s-1.8 9-9 9-9-1.8-9-9 1.8-9 9-9"}]],Im=[["path",{d:"M13.77 3.043a34 34 0 0 0-3.54 0"}],["path",{d:"M13.771 20.956a33 33 0 0 1-3.541.001"}],["path",{d:"M20.18 17.74c-.51 1.15-1.29 1.93-2.439 2.44"}],["path",{d:"M20.18 6.259c-.51-1.148-1.291-1.929-2.44-2.438"}],["path",{d:"M20.957 10.23a33 33 0 0 1 0 3.54"}],["path",{d:"M3.043 10.23a34 34 0 0 0 .001 3.541"}],["path",{d:"M6.26 20.179c-1.15-.508-1.93-1.29-2.44-2.438"}],["path",{d:"M6.26 3.82c-1.149.51-1.93 1.291-2.44 2.44"}]],Wm=[["path",{d:"M15.236 22a3 3 0 0 0-2.2-5"}],["path",{d:"M16 20a3 3 0 0 1 3-3h1a2 2 0 0 0 2-2v-2a4 4 0 0 0-4-4V4"}],["path",{d:"M18 13h.01"}],["path",{d:"M18 6a4 4 0 0 0-4 4 7 7 0 0 0-7 7c0-5 4-5 4-10.5a4.5 4.5 0 1 0-9 0 2.5 2.5 0 0 0 5 0C7 10 3 11 3 17c0 2.8 2.2 5 5 5h10"}]],Em=[["path",{d:"M14 13V8.5C14 7 15 7 15 5a3 3 0 0 0-6 0c0 2 1 2 1 3.5V13"}],["path",{d:"M20 15.5a2.5 2.5 0 0 0-2.5-2.5h-11A2.5 2.5 0 0 0 4 15.5V17a1 1 0 0 0 1 1h14a1 1 0 0 0 1-1z"}],["path",{d:"M5 22h14"}]],Xm=[["path",{d:"M12 18.338a2.1 2.1 0 0 0-.987.244L6.396 21.01a.53.53 0 0 1-.77-.56l.881-5.139a2.12 2.12 0 0 0-.611-1.879L2.16 9.795a.53.53 0 0 1 .294-.906l5.165-.755a2.12 2.12 0 0 0 1.597-1.16l2.309-4.679A.53.53 0 0 1 12 2"}]],jm=[["path",{d:"M8.34 8.34 2 9.27l5 4.87L5.82 21 12 17.77 18.18 21l-.59-3.43"}],["path",{d:"M18.42 12.76 22 9.27l-6.91-1L12 2l-1.44 2.91"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],Nm=[["path",{d:"M11.525 2.295a.53.53 0 0 1 .95 0l2.31 4.679a2.123 2.123 0 0 0 1.595 1.16l5.166.756a.53.53 0 0 1 .294.904l-3.736 3.638a2.123 2.123 0 0 0-.611 1.878l.882 5.14a.53.53 0 0 1-.771.56l-4.618-2.428a2.122 2.122 0 0 0-1.973 0L6.396 21.01a.53.53 0 0 1-.77-.56l.881-5.139a2.122 2.122 0 0 0-.611-1.879L2.16 9.795a.53.53 0 0 1 .294-.906l5.165-.755a2.122 2.122 0 0 0 1.597-1.16z"}]],Km=[["path",{d:"M13.971 4.285A2 2 0 0 1 17 6v12a2 2 0 0 1-3.029 1.715l-9.997-5.998a2 2 0 0 1-.003-3.432z"}],["path",{d:"M21 20V4"}]],Qm=[["path",{d:"M11 2v2"}],["path",{d:"M5 2v2"}],["path",{d:"M5 3H4a2 2 0 0 0-2 2v4a6 6 0 0 0 12 0V5a2 2 0 0 0-2-2h-1"}],["path",{d:"M8 15a6 6 0 0 0 12 0v-3"}],["circle",{cx:"20",cy:"10",r:"2"}]],Jm=[["path",{d:"M10.029 4.285A2 2 0 0 0 7 6v12a2 2 0 0 0 3.029 1.715l9.997-5.998a2 2 0 0 0 .003-3.432z"}],["path",{d:"M3 4v16"}]],Ym=[["path",{d:"M15.5 3H5a2 2 0 0 0-2 2v14c0 1.1.9 2 2 2h14a2 2 0 0 0 2-2V8.5L15.5 3Z"}],["path",{d:"M14 3v4a2 2 0 0 0 2 2h4"}],["path",{d:"M8 13h.01"}],["path",{d:"M16 13h.01"}],["path",{d:"M10 16s.8 1 2 1c1.3 0 2-1 2-1"}]],_m=[["path",{d:"M16 3H5a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h14a2 2 0 0 0 2-2V8Z"}],["path",{d:"M15 3v4a2 2 0 0 0 2 2h4"}]],xm=[["path",{d:"M15 21v-5a1 1 0 0 0-1-1h-4a1 1 0 0 0-1 1v5"}],["path",{d:"M17.774 10.31a1.12 1.12 0 0 0-1.549 0 2.5 2.5 0 0 1-3.451 0 1.12 1.12 0 0 0-1.548 0 2.5 2.5 0 0 1-3.452 0 1.12 1.12 0 0 0-1.549 0 2.5 2.5 0 0 1-3.77-3.248l2.889-4.184A2 2 0 0 1 7 2h10a2 2 0 0 1 1.653.873l2.895 4.192a2.5 2.5 0 0 1-3.774 3.244"}],["path",{d:"M4 10.95V19a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2v-8.05"}]],ay=[["rect",{width:"20",height:"6",x:"2",y:"4",rx:"2"}],["rect",{width:"20",height:"6",x:"2",y:"14",rx:"2"}]],ty=[["rect",{width:"6",height:"20",x:"4",y:"2",rx:"2"}],["rect",{width:"6",height:"20",x:"14",y:"2",rx:"2"}]],hy=[["path",{d:"M16 4H9a3 3 0 0 0-2.83 4"}],["path",{d:"M14 12a4 4 0 0 1 0 8H6"}],["line",{x1:"4",x2:"20",y1:"12",y2:"12"}]],dy=[["path",{d:"m4 5 8 8"}],["path",{d:"m12 5-8 8"}],["path",{d:"M20 19h-4c0-1.5.44-2 1.5-2.5S20 15.33 20 14c0-.47-.17-.93-.48-1.29a2.11 2.11 0 0 0-2.62-.44c-.42.24-.74.62-.9 1.07"}]],cy=[["circle",{cx:"12",cy:"12",r:"4"}],["path",{d:"M12 4h.01"}],["path",{d:"M20 12h.01"}],["path",{d:"M12 20h.01"}],["path",{d:"M4 12h.01"}],["path",{d:"M17.657 6.343h.01"}],["path",{d:"M17.657 17.657h.01"}],["path",{d:"M6.343 17.657h.01"}],["path",{d:"M6.343 6.343h.01"}]],My=[["circle",{cx:"12",cy:"12",r:"4"}],["path",{d:"M12 3v1"}],["path",{d:"M12 20v1"}],["path",{d:"M3 12h1"}],["path",{d:"M20 12h1"}],["path",{d:"m18.364 5.636-.707.707"}],["path",{d:"m6.343 17.657-.707.707"}],["path",{d:"m5.636 5.636.707.707"}],["path",{d:"m17.657 17.657.707.707"}]],py=[["path",{d:"M12 2v2"}],["path",{d:"M14.837 16.385a6 6 0 1 1-7.223-7.222c.624-.147.97.66.715 1.248a4 4 0 0 0 5.26 5.259c.589-.255 1.396.09 1.248.715"}],["path",{d:"M16 12a4 4 0 0 0-4-4"}],["path",{d:"m19 5-1.256 1.256"}],["path",{d:"M20 12h2"}]],iy=[["path",{d:"M10 21v-1"}],["path",{d:"M10 4V3"}],["path",{d:"M10 9a3 3 0 0 0 0 6"}],["path",{d:"m14 20 1.25-2.5L18 18"}],["path",{d:"m14 4 1.25 2.5L18 6"}],["path",{d:"m17 21-3-6 1.5-3H22"}],["path",{d:"m17 3-3 6 1.5 3"}],["path",{d:"M2 12h1"}],["path",{d:"m20 10-1.5 2 1.5 2"}],["path",{d:"m3.64 18.36.7-.7"}],["path",{d:"m4.34 6.34-.7-.7"}]],ny=[["circle",{cx:"12",cy:"12",r:"4"}],["path",{d:"M12 2v2"}],["path",{d:"M12 20v2"}],["path",{d:"m4.93 4.93 1.41 1.41"}],["path",{d:"m17.66 17.66 1.41 1.41"}],["path",{d:"M2 12h2"}],["path",{d:"M20 12h2"}],["path",{d:"m6.34 17.66-1.41 1.41"}],["path",{d:"m19.07 4.93-1.41 1.41"}]],ly=[["path",{d:"M12 2v8"}],["path",{d:"m4.93 10.93 1.41 1.41"}],["path",{d:"M2 18h2"}],["path",{d:"M20 18h2"}],["path",{d:"m19.07 10.93-1.41 1.41"}],["path",{d:"M22 22H2"}],["path",{d:"m8 6 4-4 4 4"}],["path",{d:"M16 18a4 4 0 0 0-8 0"}]],ey=[["path",{d:"M12 10V2"}],["path",{d:"m4.93 10.93 1.41 1.41"}],["path",{d:"M2 18h2"}],["path",{d:"M20 18h2"}],["path",{d:"m19.07 10.93-1.41 1.41"}],["path",{d:"M22 22H2"}],["path",{d:"m16 6-4 4-4-4"}],["path",{d:"M16 18a4 4 0 0 0-8 0"}]],ry=[["path",{d:"M11 17a4 4 0 0 1-8 0V5a2 2 0 0 1 2-2h4a2 2 0 0 1 2 2Z"}],["path",{d:"M16.7 13H19a2 2 0 0 1 2 2v4a2 2 0 0 1-2 2H7"}],["path",{d:"M 7 17h.01"}],["path",{d:"m11 8 2.3-2.3a2.4 2.4 0 0 1 3.404.004L18.6 7.6a2.4 2.4 0 0 1 .026 3.434L9.9 19.8"}]],oy=[["path",{d:"m4 19 8-8"}],["path",{d:"m12 19-8-8"}],["path",{d:"M20 12h-4c0-1.5.442-2 1.5-2.5S20 8.334 20 7.002c0-.472-.17-.93-.484-1.29a2.105 2.105 0 0 0-2.617-.436c-.42.239-.738.614-.899 1.06"}]],vy=[["path",{d:"M10 21V3h8"}],["path",{d:"M6 16h9"}],["path",{d:"M10 9.5h7"}]],$y=[["path",{d:"M11 19H4a2 2 0 0 1-2-2V7a2 2 0 0 1 2-2h5"}],["path",{d:"M13 5h7a2 2 0 0 1 2 2v10a2 2 0 0 1-2 2h-5"}],["circle",{cx:"12",cy:"12",r:"3"}],["path",{d:"m18 22-3-3 3-3"}],["path",{d:"m6 2 3 3-3 3"}]],my=[["polyline",{points:"14.5 17.5 3 6 3 3 6 3 17.5 14.5"}],["line",{x1:"13",x2:"19",y1:"19",y2:"13"}],["line",{x1:"16",x2:"20",y1:"16",y2:"20"}],["line",{x1:"19",x2:"21",y1:"21",y2:"19"}]],yy=[["polyline",{points:"14.5 17.5 3 6 3 3 6 3 17.5 14.5"}],["line",{x1:"13",x2:"19",y1:"19",y2:"13"}],["line",{x1:"16",x2:"20",y1:"16",y2:"20"}],["line",{x1:"19",x2:"21",y1:"21",y2:"19"}],["polyline",{points:"14.5 6.5 18 3 21 3 21 6 17.5 9.5"}],["line",{x1:"5",x2:"9",y1:"14",y2:"18"}],["line",{x1:"7",x2:"4",y1:"17",y2:"20"}],["line",{x1:"3",x2:"5",y1:"19",y2:"21"}]],sy=[["path",{d:"m18 2 4 4"}],["path",{d:"m17 7 3-3"}],["path",{d:"M19 9 8.7 19.3c-1 1-2.5 1-3.4 0l-.6-.6c-1-1-1-2.5 0-3.4L15 5"}],["path",{d:"m9 11 4 4"}],["path",{d:"m5 19-3 3"}],["path",{d:"m14 4 6 6"}]],gy=[["path",{d:"M9 3H5a2 2 0 0 0-2 2v4m6-6h10a2 2 0 0 1 2 2v4M9 3v18m0 0h10a2 2 0 0 0 2-2V9M9 21H5a2 2 0 0 1-2-2V9m0 0h18"}]],uy=[["path",{d:"M12 21v-6"}],["path",{d:"M12 9V3"}],["path",{d:"M3 15h18"}],["path",{d:"M3 9h18"}],["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}]],Cy=[["path",{d:"M14 14v2"}],["path",{d:"M14 20v2"}],["path",{d:"M14 2v2"}],["path",{d:"M14 8v2"}],["path",{d:"M2 15h8"}],["path",{d:"M2 3h6a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H2"}],["path",{d:"M2 9h8"}],["path",{d:"M22 15h-4"}],["path",{d:"M22 3h-2a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h2"}],["path",{d:"M22 9h-4"}],["path",{d:"M5 3v18"}]],Hy=[["path",{d:"M12 15V9"}],["path",{d:"M3 15h18"}],["path",{d:"M3 9h18"}],["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}]],Ay=[["path",{d:"M15 3v18"}],["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M21 9H3"}],["path",{d:"M21 15H3"}]],wy=[["path",{d:"M16 5H3"}],["path",{d:"M16 12H3"}],["path",{d:"M16 19H3"}],["path",{d:"M21 5h.01"}],["path",{d:"M21 12h.01"}],["path",{d:"M21 19h.01"}]],Vy=[["path",{d:"M14 10h2"}],["path",{d:"M15 22v-8"}],["path",{d:"M15 2v4"}],["path",{d:"M2 10h2"}],["path",{d:"M20 10h2"}],["path",{d:"M3 19h18"}],["path",{d:"M3 22v-6a2 2 135 0 1 2-2h14a2 2 45 0 1 2 2v6"}],["path",{d:"M3 2v2a2 2 45 0 0 2 2h14a2 2 135 0 0 2-2V2"}],["path",{d:"M8 10h2"}],["path",{d:"M9 22v-8"}],["path",{d:"M9 2v4"}]],Sy=[["path",{d:"M12 3v18"}],["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 9h18"}],["path",{d:"M3 15h18"}]],Ly=[["rect",{width:"10",height:"14",x:"3",y:"8",rx:"2"}],["path",{d:"M5 4a2 2 0 0 1 2-2h12a2 2 0 0 1 2 2v16a2 2 0 0 1-2 2h-2.4"}],["path",{d:"M8 18h.01"}]],fy=[["rect",{width:"16",height:"20",x:"4",y:"2",rx:"2",ry:"2"}],["line",{x1:"12",x2:"12.01",y1:"18",y2:"18"}]],ky=[["circle",{cx:"7",cy:"7",r:"5"}],["circle",{cx:"17",cy:"17",r:"5"}],["path",{d:"M12 17h10"}],["path",{d:"m3.46 10.54 7.08-7.08"}]],Py=[["path",{d:"M12.586 2.586A2 2 0 0 0 11.172 2H4a2 2 0 0 0-2 2v7.172a2 2 0 0 0 .586 1.414l8.704 8.704a2.426 2.426 0 0 0 3.42 0l6.58-6.58a2.426 2.426 0 0 0 0-3.42z"}],["circle",{cx:"7.5",cy:"7.5",r:".5",fill:"currentColor"}]],By=[["path",{d:"M4 4v16"}]],Dy=[["path",{d:"M13.172 2a2 2 0 0 1 1.414.586l6.71 6.71a2.4 2.4 0 0 1 0 3.408l-4.592 4.592a2.4 2.4 0 0 1-3.408 0l-6.71-6.71A2 2 0 0 1 6 9.172V3a1 1 0 0 1 1-1z"}],["path",{d:"M2 7v6.172a2 2 0 0 0 .586 1.414l6.71 6.71a2.4 2.4 0 0 0 3.191.193"}],["circle",{cx:"10.5",cy:"6.5",r:".5",fill:"currentColor"}]],Fy=[["path",{d:"M4 4v16"}],["path",{d:"M9 4v16"}]],zy=[["path",{d:"M4 4v16"}],["path",{d:"M9 4v16"}],["path",{d:"M14 4v16"}]],by=[["path",{d:"M4 4v16"}],["path",{d:"M9 4v16"}],["path",{d:"M14 4v16"}],["path",{d:"M19 4v16"}]],Ry=[["path",{d:"M4 4v16"}],["path",{d:"M9 4v16"}],["path",{d:"M14 4v16"}],["path",{d:"M19 4v16"}],["path",{d:"M22 6 2 18"}]],Ty=[["circle",{cx:"17",cy:"4",r:"2"}],["path",{d:"M15.59 5.41 5.41 15.59"}],["circle",{cx:"4",cy:"17",r:"2"}],["path",{d:"M12 22s-4-9-1.5-11.5S22 12 22 12"}]],qy=[["circle",{cx:"12",cy:"12",r:"10"}],["circle",{cx:"12",cy:"12",r:"6"}],["circle",{cx:"12",cy:"12",r:"2"}]],Uy=[["path",{d:"m10.065 12.493-6.18 1.318a.934.934 0 0 1-1.108-.702l-.537-2.15a1.07 1.07 0 0 1 .691-1.265l13.504-4.44"}],["path",{d:"m13.56 11.747 4.332-.924"}],["path",{d:"m16 21-3.105-6.21"}],["path",{d:"M16.485 5.94a2 2 0 0 1 1.455-2.425l1.09-.272a1 1 0 0 1 1.212.727l1.515 6.06a1 1 0 0 1-.727 1.213l-1.09.272a2 2 0 0 1-2.425-1.455z"}],["path",{d:"m6.158 8.633 1.114 4.456"}],["path",{d:"m8 21 3.105-6.21"}],["circle",{cx:"12",cy:"13",r:"2"}]],Oy=[["circle",{cx:"4",cy:"4",r:"2"}],["path",{d:"m14 5 3-3 3 3"}],["path",{d:"m14 10 3-3 3 3"}],["path",{d:"M17 14V2"}],["path",{d:"M17 14H7l-5 8h20Z"}],["path",{d:"M8 14v8"}],["path",{d:"m9 14 5 8"}]],Zy=[["path",{d:"M3.5 21 14 3"}],["path",{d:"M20.5 21 10 3"}],["path",{d:"M15.5 21 12 15l-3.5 6"}],["path",{d:"M2 21h20"}]],Gy=[["path",{d:"M12 19h8"}],["path",{d:"m4 17 6-6-6-6"}]],O0=[["path",{d:"M21 7 6.82 21.18a2.83 2.83 0 0 1-3.99-.01a2.83 2.83 0 0 1 0-4L17 3"}],["path",{d:"m16 2 6 6"}],["path",{d:"M12 16H4"}]],Iy=[["path",{d:"M14.5 2v17.5c0 1.4-1.1 2.5-2.5 2.5c-1.4 0-2.5-1.1-2.5-2.5V2"}],["path",{d:"M8.5 2h7"}],["path",{d:"M14.5 16h-5"}]],Wy=[["path",{d:"M9 2v17.5A2.5 2.5 0 0 1 6.5 22A2.5 2.5 0 0 1 4 19.5V2"}],["path",{d:"M20 2v17.5a2.5 2.5 0 0 1-2.5 2.5a2.5 2.5 0 0 1-2.5-2.5V2"}],["path",{d:"M3 2h7"}],["path",{d:"M14 2h7"}],["path",{d:"M9 16H4"}],["path",{d:"M20 16h-5"}]],Z0=[["path",{d:"M21 5H3"}],["path",{d:"M17 12H7"}],["path",{d:"M19 19H5"}]],G0=[["path",{d:"M21 5H3"}],["path",{d:"M21 12H9"}],["path",{d:"M21 19H7"}]],I0=[["path",{d:"M3 5h18"}],["path",{d:"M3 12h18"}],["path",{d:"M3 19h18"}]],m=[["path",{d:"M21 5H3"}],["path",{d:"M15 12H3"}],["path",{d:"M17 19H3"}]],Ey=[["path",{d:"M12 20h-1a2 2 0 0 1-2-2 2 2 0 0 1-2 2H6"}],["path",{d:"M13 8h7a2 2 0 0 1 2 2v4a2 2 0 0 1-2 2h-7"}],["path",{d:"M5 16H4a2 2 0 0 1-2-2v-4a2 2 0 0 1 2-2h1"}],["path",{d:"M6 4h1a2 2 0 0 1 2 2 2 2 0 0 1 2-2h1"}],["path",{d:"M9 6v12"}]],Xy=[["path",{d:"M17 22h-1a4 4 0 0 1-4-4V6a4 4 0 0 1 4-4h1"}],["path",{d:"M7 22h1a4 4 0 0 0 4-4v-1"}],["path",{d:"M7 2h1a4 4 0 0 1 4 4v1"}]],W0=[["path",{d:"M15 5h6"}],["path",{d:"M15 12h6"}],["path",{d:"M3 19h18"}],["path",{d:"m3 12 3.553-7.724a.5.5 0 0 1 .894 0L11 12"}],["path",{d:"M3.92 10h6.16"}]],jy=[["path",{d:"M17 5H3"}],["path",{d:"M21 12H8"}],["path",{d:"M21 19H8"}],["path",{d:"M3 12v7"}]],Ny=[["path",{d:"M21 5H3"}],["path",{d:"M10 12H3"}],["path",{d:"M10 19H3"}],["circle",{cx:"17",cy:"15",r:"3"}],["path",{d:"m21 19-1.9-1.9"}]],E0=[["path",{d:"M14 21h1"}],["path",{d:"M14 3h1"}],["path",{d:"M19 3a2 2 0 0 1 2 2"}],["path",{d:"M21 14v1"}],["path",{d:"M21 19a2 2 0 0 1-2 2"}],["path",{d:"M21 9v1"}],["path",{d:"M3 14v1"}],["path",{d:"M3 9v1"}],["path",{d:"M5 21a2 2 0 0 1-2-2"}],["path",{d:"M5 3a2 2 0 0 0-2 2"}],["path",{d:"M7 12h10"}],["path",{d:"M7 16h6"}],["path",{d:"M7 8h8"}],["path",{d:"M9 21h1"}],["path",{d:"M9 3h1"}]],X0=[["path",{d:"m16 16-3 3 3 3"}],["path",{d:"M3 12h14.5a1 1 0 0 1 0 7H13"}],["path",{d:"M3 19h6"}],["path",{d:"M3 5h18"}]],Ky=[["path",{d:"M2 10s3-3 3-8"}],["path",{d:"M22 10s-3-3-3-8"}],["path",{d:"M10 2c0 4.4-3.6 8-8 8"}],["path",{d:"M14 2c0 4.4 3.6 8 8 8"}],["path",{d:"M2 10s2 2 2 5"}],["path",{d:"M22 10s-2 2-2 5"}],["path",{d:"M8 15h8"}],["path",{d:"M2 22v-1a2 2 0 0 1 2-2h4a2 2 0 0 1 2 2v1"}],["path",{d:"M14 22v-1a2 2 0 0 1 2-2h4a2 2 0 0 1 2 2v1"}]],Qy=[["path",{d:"m10 20-1.25-2.5L6 18"}],["path",{d:"M10 4 8.75 6.5 6 6"}],["path",{d:"M10.585 15H10"}],["path",{d:"M2 12h6.5L10 9"}],["path",{d:"M20 14.54a4 4 0 1 1-4 0V4a2 2 0 0 1 4 0z"}],["path",{d:"m4 10 1.5 2L4 14"}],["path",{d:"m7 21 3-6-1.5-3"}],["path",{d:"m7 3 3 6h2"}]],Jy=[["path",{d:"M12 9a4 4 0 0 0-2 7.5"}],["path",{d:"M12 3v2"}],["path",{d:"m6.6 18.4-1.4 1.4"}],["path",{d:"M20 4v10.54a4 4 0 1 1-4 0V4a2 2 0 0 1 4 0Z"}],["path",{d:"M4 13H2"}],["path",{d:"M6.34 7.34 4.93 5.93"}]],Yy=[["path",{d:"M14 4v10.54a4 4 0 1 1-4 0V4a2 2 0 0 1 4 0Z"}]],_y=[["path",{d:"M17 14V2"}],["path",{d:"M9 18.12 10 14H4.17a2 2 0 0 1-1.92-2.56l2.33-8A2 2 0 0 1 6.5 2H20a2 2 0 0 1 2 2v8a2 2 0 0 1-2 2h-2.76a2 2 0 0 0-1.79 1.11L12 22a3.13 3.13 0 0 1-3-3.88Z"}]],xy=[["path",{d:"M7 10v12"}],["path",{d:"M15 5.88 14 10h5.83a2 2 0 0 1 1.92 2.56l-2.33 8A2 2 0 0 1 17.5 22H4a2 2 0 0 1-2-2v-8a2 2 0 0 1 2-2h2.76a2 2 0 0 0 1.79-1.11L12 2a3.13 3.13 0 0 1 3 3.88Z"}]],as=[["path",{d:"M2 9a3 3 0 0 1 0 6v2a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-2a3 3 0 0 1 0-6V7a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2Z"}],["path",{d:"m9 12 2 2 4-4"}]],ts=[["path",{d:"M2 9a3 3 0 0 1 0 6v2a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-2a3 3 0 0 1 0-6V7a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2Z"}],["path",{d:"M9 12h6"}]],hs=[["path",{d:"M2 9a3 3 0 1 1 0 6v2a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-2a3 3 0 1 1 0-6V7a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2Z"}],["path",{d:"M9 9h.01"}],["path",{d:"m15 9-6 6"}],["path",{d:"M15 15h.01"}]],ds=[["path",{d:"M2 9a3 3 0 0 1 0 6v2a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-2a3 3 0 0 1 0-6V7a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2Z"}],["path",{d:"M9 12h6"}],["path",{d:"M12 9v6"}]],cs=[["path",{d:"M2 9a3 3 0 0 1 0 6v2a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-2a3 3 0 0 1 0-6V7a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2Z"}],["path",{d:"m9.5 14.5 5-5"}],["path",{d:"m9.5 9.5 5 5"}]],Ms=[["path",{d:"M2 9a3 3 0 0 1 0 6v2a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-2a3 3 0 0 1 0-6V7a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2Z"}],["path",{d:"M13 5v2"}],["path",{d:"M13 17v2"}],["path",{d:"M13 11v2"}]],ps=[["path",{d:"M2 9a3 3 0 0 1 0 6v2a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-2a3 3 0 0 1 0-6V7a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2Z"}],["path",{d:"m9.5 14.5 5-5"}]],is=[["path",{d:"M10.5 17h1.227a2 2 0 0 0 1.345-.52L18 12"}],["path",{d:"m12 13.5 3.75.5"}],["path",{d:"m4.5 8 10.58-5.06a1 1 0 0 1 1.342.488L18.5 8"}],["path",{d:"M6 10V8"}],["path",{d:"M6 14v1"}],["path",{d:"M6 19v2"}],["rect",{x:"2",y:"8",width:"20",height:"13",rx:"2"}]],ns=[["path",{d:"m4.5 8 10.58-5.06a1 1 0 0 1 1.342.488L18.5 8"}],["path",{d:"M6 10V8"}],["path",{d:"M6 14v1"}],["path",{d:"M6 19v2"}],["rect",{x:"2",y:"8",width:"20",height:"13",rx:"2"}]],ls=[["path",{d:"M10 2h4"}],["path",{d:"M4.6 11a8 8 0 0 0 1.7 8.7 8 8 0 0 0 8.7 1.7"}],["path",{d:"M7.4 7.4a8 8 0 0 1 10.3 1 8 8 0 0 1 .9 10.2"}],["path",{d:"m2 2 20 20"}],["path",{d:"M12 12v-2"}]],es=[["path",{d:"M10 2h4"}],["path",{d:"M12 14v-4"}],["path",{d:"M4 13a8 8 0 0 1 8-7 8 8 0 1 1-5.3 14L4 17.6"}],["path",{d:"M9 17H4v5"}]],rs=[["line",{x1:"10",x2:"14",y1:"2",y2:"2"}],["line",{x1:"12",x2:"15",y1:"14",y2:"11"}],["circle",{cx:"12",cy:"14",r:"8"}]],os=[["circle",{cx:"9",cy:"12",r:"3"}],["rect",{width:"20",height:"14",x:"2",y:"5",rx:"7"}]],vs=[["circle",{cx:"15",cy:"12",r:"3"}],["rect",{width:"20",height:"14",x:"2",y:"5",rx:"7"}]],$s=[["path",{d:"M7 12h13a1 1 0 0 1 1 1 5 5 0 0 1-5 5h-.598a.5.5 0 0 0-.424.765l1.544 2.47a.5.5 0 0 1-.424.765H5.402a.5.5 0 0 1-.424-.765L7 18"}],["path",{d:"M8 18a5 5 0 0 1-5-5V4a2 2 0 0 1 2-2h8a2 2 0 0 1 2 2v8"}]],ms=[["path",{d:"M21 4H3"}],["path",{d:"M18 8H6"}],["path",{d:"M19 12H9"}],["path",{d:"M16 16h-6"}],["path",{d:"M11 20H9"}]],ys=[["path",{d:"M10 15h4"}],["path",{d:"m14.817 10.995-.971-1.45 1.034-1.232a2 2 0 0 0-2.025-3.238l-1.82.364L9.91 3.885a2 2 0 0 0-3.625.748L6.141 6.55l-1.725.426a2 2 0 0 0-.19 3.756l.657.27"}],["path",{d:"m18.822 10.995 2.26-5.38a1 1 0 0 0-.557-1.318L16.954 2.9a1 1 0 0 0-1.281.533l-.924 2.122"}],["path",{d:"M4 12.006A1 1 0 0 1 4.994 11H19a1 1 0 0 1 1 1v7a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2z"}]],ss=[["ellipse",{cx:"12",cy:"11",rx:"3",ry:"2"}],["ellipse",{cx:"12",cy:"12.5",rx:"10",ry:"8.5"}]],gs=[["path",{d:"M12 20v-6"}],["path",{d:"M19.656 14H22"}],["path",{d:"M2 14h12"}],["path",{d:"m2 2 20 20"}],["path",{d:"M20 20H4a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2"}],["path",{d:"M9.656 4H20a2 2 0 0 1 2 2v10.344"}]],us=[["rect",{width:"20",height:"16",x:"2",y:"4",rx:"2"}],["path",{d:"M2 14h20"}],["path",{d:"M12 20v-6"}]],Cs=[["rect",{width:"18",height:"12",x:"3",y:"8",rx:"1"}],["path",{d:"M10 8V5c0-.6-.4-1-1-1H6a1 1 0 0 0-1 1v3"}],["path",{d:"M19 8V5c0-.6-.4-1-1-1h-3a1 1 0 0 0-1 1v3"}]],Hs=[["path",{d:"M18.2 12.27 20 6H4l1.8 6.27a1 1 0 0 0 .95.73h10.5a1 1 0 0 0 .96-.73Z"}],["path",{d:"M8 13v9"}],["path",{d:"M16 22v-9"}],["path",{d:"m9 6 1 7"}],["path",{d:"m15 6-1 7"}],["path",{d:"M12 6V2"}],["path",{d:"M13 2h-2"}]],As=[["path",{d:"m10 11 11 .9a1 1 0 0 1 .8 1.1l-.665 4.158a1 1 0 0 1-.988.842H20"}],["path",{d:"M16 18h-5"}],["path",{d:"M18 5a1 1 0 0 0-1 1v5.573"}],["path",{d:"M3 4h8.129a1 1 0 0 1 .99.863L13 11.246"}],["path",{d:"M4 11V4"}],["path",{d:"M7 15h.01"}],["path",{d:"M8 10.1V4"}],["circle",{cx:"18",cy:"18",r:"2"}],["circle",{cx:"7",cy:"15",r:"5"}]],ws=[["path",{d:"M16.05 10.966a5 2.5 0 0 1-8.1 0"}],["path",{d:"m16.923 14.049 4.48 2.04a1 1 0 0 1 .001 1.831l-8.574 3.9a2 2 0 0 1-1.66 0l-8.574-3.91a1 1 0 0 1 0-1.83l4.484-2.04"}],["path",{d:"M16.949 14.14a5 2.5 0 1 1-9.9 0L10.063 3.5a2 2 0 0 1 3.874 0z"}],["path",{d:"M9.194 6.57a5 2.5 0 0 0 5.61 0"}]],Vs=[["path",{d:"M2 22V12a10 10 0 1 1 20 0v10"}],["path",{d:"M15 6.8v1.4a3 2.8 0 1 1-6 0V6.8"}],["path",{d:"M10 15h.01"}],["path",{d:"M14 15h.01"}],["path",{d:"M10 19a4 4 0 0 1-4-4v-3a6 6 0 1 1 12 0v3a4 4 0 0 1-4 4Z"}],["path",{d:"m9 19-2 3"}],["path",{d:"m15 19 2 3"}]],Ss=[["path",{d:"M8 3.1V7a4 4 0 0 0 8 0V3.1"}],["path",{d:"m9 15-1-1"}],["path",{d:"m15 15 1-1"}],["path",{d:"M9 19c-2.8 0-5-2.2-5-5v-4a8 8 0 0 1 16 0v4c0 2.8-2.2 5-5 5Z"}],["path",{d:"m8 19-2 3"}],["path",{d:"m16 19 2 3"}]],Ls=[["path",{d:"M2 17 17 2"}],["path",{d:"m2 14 8 8"}],["path",{d:"m5 11 8 8"}],["path",{d:"m8 8 8 8"}],["path",{d:"m11 5 8 8"}],["path",{d:"m14 2 8 8"}],["path",{d:"M7 22 22 7"}]],j0=[["rect",{width:"16",height:"16",x:"4",y:"3",rx:"2"}],["path",{d:"M4 11h16"}],["path",{d:"M12 3v8"}],["path",{d:"m8 19-2 3"}],["path",{d:"m18 22-2-3"}],["path",{d:"M8 15h.01"}],["path",{d:"M16 15h.01"}]],fs=[["path",{d:"M12 16v6"}],["path",{d:"M14 20h-4"}],["path",{d:"M18 2h4v4"}],["path",{d:"m2 2 7.17 7.17"}],["path",{d:"M2 5.355V2h3.357"}],["path",{d:"m22 2-7.17 7.17"}],["path",{d:"M8 5 5 8"}],["circle",{cx:"12",cy:"12",r:"4"}]],ks=[["path",{d:"M10 11v6"}],["path",{d:"M14 11v6"}],["path",{d:"M19 6v14a2 2 0 0 1-2 2H7a2 2 0 0 1-2-2V6"}],["path",{d:"M3 6h18"}],["path",{d:"M8 6V4a2 2 0 0 1 2-2h4a2 2 0 0 1 2 2v2"}]],Ps=[["path",{d:"M19 6v14a2 2 0 0 1-2 2H7a2 2 0 0 1-2-2V6"}],["path",{d:"M3 6h18"}],["path",{d:"M8 6V4a2 2 0 0 1 2-2h4a2 2 0 0 1 2 2v2"}]],Bs=[["path",{d:"M8 19a4 4 0 0 1-2.24-7.32A3.5 3.5 0 0 1 9 6.03V6a3 3 0 1 1 6 0v.04a3.5 3.5 0 0 1 3.24 5.65A4 4 0 0 1 16 19Z"}],["path",{d:"M12 19v3"}]],N0=[["path",{d:"M13 8c0-2.76-2.46-5-5.5-5S2 5.24 2 8h2l1-1 1 1h4"}],["path",{d:"M13 7.14A5.82 5.82 0 0 1 16.5 6c3.04 0 5.5 2.24 5.5 5h-3l-1-1-1 1h-3"}],["path",{d:"M5.89 9.71c-2.15 2.15-2.3 5.47-.35 7.43l4.24-4.25.7-.7.71-.71 2.12-2.12c-1.95-1.96-5.27-1.8-7.42.35"}],["path",{d:"M11 15.5c.5 2.5-.17 4.5-1 6.5h4c2-5.5-.5-12-1-14"}]],Ds=[["path",{d:"m17 14 3 3.3a1 1 0 0 1-.7 1.7H4.7a1 1 0 0 1-.7-1.7L7 14h-.3a1 1 0 0 1-.7-1.7L9 9h-.2A1 1 0 0 1 8 7.3L12 3l4 4.3a1 1 0 0 1-.8 1.7H15l3 3.3a1 1 0 0 1-.7 1.7H17Z"}],["path",{d:"M12 22v-3"}]],Fs=[["path",{d:"M10 10v.2A3 3 0 0 1 8.9 16H5a3 3 0 0 1-1-5.8V10a3 3 0 0 1 6 0Z"}],["path",{d:"M7 16v6"}],["path",{d:"M13 19v3"}],["path",{d:"M12 19h8.3a1 1 0 0 0 .7-1.7L18 14h.3a1 1 0 0 0 .7-1.7L16 9h.2a1 1 0 0 0 .8-1.7L13 3l-1.4 1.5"}]],zs=[["path",{d:"M16 17h6v-6"}],["path",{d:"m22 17-8.5-8.5-5 5L2 7"}]],bs=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2",ry:"2"}],["rect",{width:"3",height:"9",x:"7",y:"7"}],["rect",{width:"3",height:"5",x:"14",y:"7"}]],Rs=[["path",{d:"M14.828 14.828 21 21"}],["path",{d:"M21 16v5h-5"}],["path",{d:"m21 3-9 9-4-4-6 6"}],["path",{d:"M21 8V3h-5"}]],Ts=[["path",{d:"M16 7h6v6"}],["path",{d:"m22 7-8.5 8.5-5-5L2 17"}]],qs=[["path",{d:"M10.17 4.193a2 2 0 0 1 3.666.013"}],["path",{d:"M14 21h2"}],["path",{d:"m15.874 7.743 1 1.732"}],["path",{d:"m18.849 12.952 1 1.732"}],["path",{d:"M21.824 18.18a2 2 0 0 1-1.835 2.824"}],["path",{d:"M4.024 21a2 2 0 0 1-1.839-2.839"}],["path",{d:"m5.136 12.952-1 1.732"}],["path",{d:"M8 21h2"}],["path",{d:"m8.102 7.743-1 1.732"}]],K0=[["path",{d:"m21.73 18-8-14a2 2 0 0 0-3.48 0l-8 14A2 2 0 0 0 4 21h16a2 2 0 0 0 1.73-3"}],["path",{d:"M12 9v4"}],["path",{d:"M12 17h.01"}]],Us=[["path",{d:"M22 18a2 2 0 0 1-2 2H3c-1.1 0-1.3-.6-.4-1.3L20.4 4.3c.9-.7 1.6-.4 1.6.7Z"}]],Os=[["path",{d:"M13.73 4a2 2 0 0 0-3.46 0l-8 14A2 2 0 0 0 4 21h16a2 2 0 0 0 1.73-3Z"}]],Zs=[["path",{d:"M10 14.66v1.626a2 2 0 0 1-.976 1.696A5 5 0 0 0 7 21.978"}],["path",{d:"M14 14.66v1.626a2 2 0 0 0 .976 1.696A5 5 0 0 1 17 21.978"}],["path",{d:"M18 9h1.5a1 1 0 0 0 0-5H18"}],["path",{d:"M4 22h16"}],["path",{d:"M6 9a6 6 0 0 0 12 0V3a1 1 0 0 0-1-1H7a1 1 0 0 0-1 1z"}],["path",{d:"M6 9H4.5a1 1 0 0 1 0-5H6"}]],Gs=[["path",{d:"M14 19V7a2 2 0 0 0-2-2H9"}],["path",{d:"M15 19H9"}],["path",{d:"M19 19h2a1 1 0 0 0 1-1v-3.65a1 1 0 0 0-.22-.62L18.3 9.38a1 1 0 0 0-.78-.38H14"}],["path",{d:"M2 13v5a1 1 0 0 0 1 1h2"}],["path",{d:"M4 3 2.15 5.15a.495.495 0 0 0 .35.86h2.15a.47.47 0 0 1 .35.86L3 9.02"}],["circle",{cx:"17",cy:"19",r:"2"}],["circle",{cx:"7",cy:"19",r:"2"}]],Is=[["path",{d:"M14 18V6a2 2 0 0 0-2-2H4a2 2 0 0 0-2 2v11a1 1 0 0 0 1 1h2"}],["path",{d:"M15 18H9"}],["path",{d:"M19 18h2a1 1 0 0 0 1-1v-3.65a1 1 0 0 0-.22-.624l-3.48-4.35A1 1 0 0 0 17.52 8H14"}],["circle",{cx:"17",cy:"18",r:"2"}],["circle",{cx:"7",cy:"18",r:"2"}]],Ws=[["path",{d:"M10 12.01h.01"}],["path",{d:"M18 8v4a8 8 0 0 1-1.07 4"}],["circle",{cx:"10",cy:"12",r:"4"}],["rect",{x:"2",y:"4",width:"20",height:"16",rx:"2"}]],Es=[["path",{d:"M15 4 5 9"}],["path",{d:"m15 8.5-10 5"}],["path",{d:"M18 12a9 9 0 0 1-9 9V3"}]],Xs=[["path",{d:"m12 10 2 4v3a1 1 0 0 0 1 1h2a1 1 0 0 0 1-1v-3a8 8 0 1 0-16 0v3a1 1 0 0 0 1 1h2a1 1 0 0 0 1-1v-3l2-4h4Z"}],["path",{d:"M4.82 7.9 8 10"}],["path",{d:"M15.18 7.9 12 10"}],["path",{d:"M16.93 10H20a2 2 0 0 1 0 4H2"}]],js=[["path",{d:"M15.033 9.44a.647.647 0 0 1 0 1.12l-4.065 2.352a.645.645 0 0 1-.968-.56V7.648a.645.645 0 0 1 .967-.56z"}],["path",{d:"M7 21h10"}],["rect",{width:"20",height:"14",x:"2",y:"3",rx:"2"}]],Q0=[["path",{d:"M7 21h10"}],["rect",{width:"20",height:"14",x:"2",y:"3",rx:"2"}]],Ns=[["path",{d:"m17 2-5 5-5-5"}],["rect",{width:"20",height:"15",x:"2",y:"7",rx:"2"}]],Ks=[["path",{d:"M21 2H3v16h5v4l4-4h5l4-4V2zm-10 9V7m5 4V7"}]],Qs=[["path",{d:"M22 4s-.7 2.1-2 3.4c1.6 10-9.4 17.3-18 11.6 2.2.1 4.4-.6 6-2C3 15.5.5 9.6 3 5c2.2 2.6 5.6 4.1 9 4-.9-4.2 4-6.6 7-3.8 1.1 0 3-1.2 3-1.2z"}]],Js=[["path",{d:"M14 16.5a.5.5 0 0 0 .5.5h.5a2 2 0 0 1 0 4H9a2 2 0 0 1 0-4h.5a.5.5 0 0 0 .5-.5v-9a.5.5 0 0 0-.5-.5h-3a.5.5 0 0 0-.5.5V8a2 2 0 0 1-4 0V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v3a2 2 0 0 1-4 0v-.5a.5.5 0 0 0-.5-.5h-3a.5.5 0 0 0-.5.5Z"}]],Ys=[["path",{d:"M12 4v16"}],["path",{d:"M4 7V5a1 1 0 0 1 1-1h14a1 1 0 0 1 1 1v2"}],["path",{d:"M9 20h6"}]],_s=[["path",{d:"M12 13v7a2 2 0 0 0 4 0"}],["path",{d:"M12 2v2"}],["path",{d:"M18.656 13h2.336a1 1 0 0 0 .97-1.274 10.284 10.284 0 0 0-12.07-7.51"}],["path",{d:"m2 2 20 20"}],["path",{d:"M5.961 5.957a10.28 10.28 0 0 0-3.922 5.769A1 1 0 0 0 3 13h10"}]],xs=[["path",{d:"M12 13v7a2 2 0 0 0 4 0"}],["path",{d:"M12 2v2"}],["path",{d:"M20.992 13a1 1 0 0 0 .97-1.274 10.284 10.284 0 0 0-19.923 0A1 1 0 0 0 3 13z"}]],ag=[["path",{d:"M6 4v6a6 6 0 0 0 12 0V4"}],["line",{x1:"4",x2:"20",y1:"20",y2:"20"}]],tg=[["path",{d:"M9 14 4 9l5-5"}],["path",{d:"M4 9h10.5a5.5 5.5 0 0 1 5.5 5.5a5.5 5.5 0 0 1-5.5 5.5H11"}]],hg=[["path",{d:"M21 17a9 9 0 0 0-15-6.7L3 13"}],["path",{d:"M3 7v6h6"}],["circle",{cx:"12",cy:"17",r:"1"}]],dg=[["path",{d:"M3 7v6h6"}],["path",{d:"M21 17a9 9 0 0 0-9-9 9 9 0 0 0-6 2.3L3 13"}]],cg=[["path",{d:"M16 12h6"}],["path",{d:"M8 12H2"}],["path",{d:"M12 2v2"}],["path",{d:"M12 8v2"}],["path",{d:"M12 14v2"}],["path",{d:"M12 20v2"}],["path",{d:"m19 15 3-3-3-3"}],["path",{d:"m5 9-3 3 3 3"}]],Mg=[["path",{d:"M12 22v-6"}],["path",{d:"M12 8V2"}],["path",{d:"M4 12H2"}],["path",{d:"M10 12H8"}],["path",{d:"M16 12h-2"}],["path",{d:"M22 12h-2"}],["path",{d:"m15 19-3 3-3-3"}],["path",{d:"m15 5-3-3-3 3"}]],pg=[["rect",{width:"8",height:"6",x:"5",y:"4",rx:"1"}],["rect",{width:"8",height:"6",x:"11",y:"14",rx:"1"}]],J0=[["path",{d:"M14 21v-3a2 2 0 0 0-4 0v3"}],["path",{d:"M18 12h.01"}],["path",{d:"M18 16h.01"}],["path",{d:"M22 7a1 1 0 0 0-1-1h-2a2 2 0 0 1-1.143-.359L13.143 2.36a2 2 0 0 0-2.286-.001L6.143 5.64A2 2 0 0 1 5 6H3a1 1 0 0 0-1 1v12a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2z"}],["path",{d:"M6 12h.01"}],["path",{d:"M6 16h.01"}],["circle",{cx:"12",cy:"10",r:"2"}]],ig=[["path",{d:"M15 7h2a5 5 0 0 1 0 10h-2m-6 0H7A5 5 0 0 1 7 7h2"}]],ng=[["path",{d:"m19 5 3-3"}],["path",{d:"m2 22 3-3"}],["path",{d:"M6.3 20.3a2.4 2.4 0 0 0 3.4 0L12 18l-6-6-2.3 2.3a2.4 2.4 0 0 0 0 3.4Z"}],["path",{d:"M7.5 13.5 10 11"}],["path",{d:"M10.5 16.5 13 14"}],["path",{d:"m12 6 6 6 2.3-2.3a2.4 2.4 0 0 0 0-3.4l-2.6-2.6a2.4 2.4 0 0 0-3.4 0Z"}]],lg=[["path",{d:"m18.84 12.25 1.72-1.71h-.02a5.004 5.004 0 0 0-.12-7.07 5.006 5.006 0 0 0-6.95 0l-1.72 1.71"}],["path",{d:"m5.17 11.75-1.71 1.71a5.004 5.004 0 0 0 .12 7.07 5.006 5.006 0 0 0 6.95 0l1.71-1.71"}],["line",{x1:"8",x2:"8",y1:"2",y2:"5"}],["line",{x1:"2",x2:"5",y1:"8",y2:"8"}],["line",{x1:"16",x2:"16",y1:"19",y2:"22"}],["line",{x1:"19",x2:"22",y1:"16",y2:"16"}]],eg=[["path",{d:"M12 3v12"}],["path",{d:"m17 8-5-5-5 5"}],["path",{d:"M21 15v4a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2v-4"}]],rg=[["circle",{cx:"10",cy:"7",r:"1"}],["circle",{cx:"4",cy:"20",r:"1"}],["path",{d:"M4.7 19.3 19 5"}],["path",{d:"m21 3-3 1 2 2Z"}],["path",{d:"M9.26 7.68 5 12l2 5"}],["path",{d:"m10 14 5 2 3.5-3.5"}],["path",{d:"m18 12 1-1 1 1-1 1Z"}]],og=[["path",{d:"m16 11 2 2 4-4"}],["path",{d:"M16 21v-2a4 4 0 0 0-4-4H6a4 4 0 0 0-4 4v2"}],["circle",{cx:"9",cy:"7",r:"4"}]],vg=[["path",{d:"M10 15H6a4 4 0 0 0-4 4v2"}],["path",{d:"m14.305 16.53.923-.382"}],["path",{d:"m15.228 13.852-.923-.383"}],["path",{d:"m16.852 12.228-.383-.923"}],["path",{d:"m16.852 17.772-.383.924"}],["path",{d:"m19.148 12.228.383-.923"}],["path",{d:"m19.53 18.696-.382-.924"}],["path",{d:"m20.772 13.852.924-.383"}],["path",{d:"m20.772 16.148.924.383"}],["circle",{cx:"18",cy:"15",r:"3"}],["circle",{cx:"9",cy:"7",r:"4"}]],$g=[["circle",{cx:"10",cy:"7",r:"4"}],["path",{d:"M10.3 15H7a4 4 0 0 0-4 4v2"}],["path",{d:"M15 15.5V14a2 2 0 0 1 4 0v1.5"}],["rect",{width:"8",height:"5",x:"13",y:"16",rx:".899"}]],mg=[["path",{d:"M16 21v-2a4 4 0 0 0-4-4H6a4 4 0 0 0-4 4v2"}],["circle",{cx:"9",cy:"7",r:"4"}],["line",{x1:"22",x2:"16",y1:"11",y2:"11"}]],yg=[["path",{d:"M11.5 15H7a4 4 0 0 0-4 4v2"}],["path",{d:"M21.378 16.626a1 1 0 0 0-3.004-3.004l-4.01 4.012a2 2 0 0 0-.506.854l-.837 2.87a.5.5 0 0 0 .62.62l2.87-.837a2 2 0 0 0 .854-.506z"}],["circle",{cx:"10",cy:"7",r:"4"}]],sg=[["path",{d:"M16 21v-2a4 4 0 0 0-4-4H6a4 4 0 0 0-4 4v2"}],["circle",{cx:"9",cy:"7",r:"4"}],["line",{x1:"19",x2:"19",y1:"8",y2:"14"}],["line",{x1:"22",x2:"16",y1:"11",y2:"11"}]],Y0=[["path",{d:"m14.305 19.53.923-.382"}],["path",{d:"m15.228 16.852-.923-.383"}],["path",{d:"m16.852 15.228-.383-.923"}],["path",{d:"m16.852 20.772-.383.924"}],["path",{d:"m19.148 15.228.383-.923"}],["path",{d:"m19.53 21.696-.382-.924"}],["path",{d:"M2 21a8 8 0 0 1 10.434-7.62"}],["path",{d:"m20.772 16.852.924-.383"}],["path",{d:"m20.772 19.148.924.383"}],["circle",{cx:"10",cy:"8",r:"5"}],["circle",{cx:"18",cy:"18",r:"3"}]],_0=[["path",{d:"M2 21a8 8 0 0 1 13.292-6"}],["circle",{cx:"10",cy:"8",r:"5"}],["path",{d:"m16 19 2 2 4-4"}]],x0=[["path",{d:"M2 21a8 8 0 0 1 13.292-6"}],["circle",{cx:"10",cy:"8",r:"5"}],["path",{d:"M22 19h-6"}]],gg=[["path",{d:"M2 21a8 8 0 0 1 10.821-7.487"}],["path",{d:"M21.378 16.626a1 1 0 0 0-3.004-3.004l-4.01 4.012a2 2 0 0 0-.506.854l-.837 2.87a.5.5 0 0 0 .62.62l2.87-.837a2 2 0 0 0 .854-.506z"}],["circle",{cx:"10",cy:"8",r:"5"}]],aa=[["path",{d:"M2 21a8 8 0 0 1 13.292-6"}],["circle",{cx:"10",cy:"8",r:"5"}],["path",{d:"M19 16v6"}],["path",{d:"M22 19h-6"}]],ug=[["circle",{cx:"10",cy:"8",r:"5"}],["path",{d:"M2 21a8 8 0 0 1 10.434-7.62"}],["circle",{cx:"18",cy:"18",r:"3"}],["path",{d:"m22 22-1.9-1.9"}]],ta=[["path",{d:"M2 21a8 8 0 0 1 11.873-7"}],["circle",{cx:"10",cy:"8",r:"5"}],["path",{d:"m17 17 5 5"}],["path",{d:"m22 17-5 5"}]],ha=[["circle",{cx:"12",cy:"8",r:"5"}],["path",{d:"M20 21a8 8 0 0 0-16 0"}]],Cg=[["circle",{cx:"10",cy:"7",r:"4"}],["path",{d:"M10.3 15H7a4 4 0 0 0-4 4v2"}],["circle",{cx:"17",cy:"17",r:"3"}],["path",{d:"m21 21-1.9-1.9"}]],Hg=[["path",{d:"M16.051 12.616a1 1 0 0 1 1.909.024l.737 1.452a1 1 0 0 0 .737.535l1.634.256a1 1 0 0 1 .588 1.806l-1.172 1.168a1 1 0 0 0-.282.866l.259 1.613a1 1 0 0 1-1.541 1.134l-1.465-.75a1 1 0 0 0-.912 0l-1.465.75a1 1 0 0 1-1.539-1.133l.258-1.613a1 1 0 0 0-.282-.866l-1.156-1.153a1 1 0 0 1 .572-1.822l1.633-.256a1 1 0 0 0 .737-.535z"}],["path",{d:"M8 15H7a4 4 0 0 0-4 4v2"}],["circle",{cx:"10",cy:"7",r:"4"}]],Ag=[["path",{d:"M16 21v-2a4 4 0 0 0-4-4H6a4 4 0 0 0-4 4v2"}],["circle",{cx:"9",cy:"7",r:"4"}],["line",{x1:"17",x2:"22",y1:"8",y2:"13"}],["line",{x1:"22",x2:"17",y1:"8",y2:"13"}]],wg=[["path",{d:"M19 21v-2a4 4 0 0 0-4-4H9a4 4 0 0 0-4 4v2"}],["circle",{cx:"12",cy:"7",r:"4"}]],da=[["path",{d:"M18 21a8 8 0 0 0-16 0"}],["circle",{cx:"10",cy:"8",r:"5"}],["path",{d:"M22 20c0-3.37-2-6.5-4-8a5 5 0 0 0-.45-8.3"}]],Vg=[["path",{d:"M16 21v-2a4 4 0 0 0-4-4H6a4 4 0 0 0-4 4v2"}],["path",{d:"M16 3.128a4 4 0 0 1 0 7.744"}],["path",{d:"M22 21v-2a4 4 0 0 0-3-3.87"}],["circle",{cx:"9",cy:"7",r:"4"}]],ca=[["path",{d:"m16 2-2.3 2.3a3 3 0 0 0 0 4.2l1.8 1.8a3 3 0 0 0 4.2 0L22 8"}],["path",{d:"M15 15 3.3 3.3a4.2 4.2 0 0 0 0 6l7.3 7.3c.7.7 2 .7 2.8 0L15 15Zm0 0 7 7"}],["path",{d:"m2.1 21.8 6.4-6.3"}],["path",{d:"m19 5-7 7"}]],Ma=[["path",{d:"M3 2v7c0 1.1.9 2 2 2h4a2 2 0 0 0 2-2V2"}],["path",{d:"M7 2v20"}],["path",{d:"M21 15V2a5 5 0 0 0-5 5v6c0 1.1.9 2 2 2h3Zm0 0v7"}]],Sg=[["path",{d:"M12 2v20"}],["path",{d:"M2 5h20"}],["path",{d:"M3 3v2"}],["path",{d:"M7 3v2"}],["path",{d:"M17 3v2"}],["path",{d:"M21 3v2"}],["path",{d:"m19 5-7 7-7-7"}]],Lg=[["path",{d:"M8 21s-4-3-4-9 4-9 4-9"}],["path",{d:"M16 3s4 3 4 9-4 9-4 9"}],["line",{x1:"15",x2:"9",y1:"9",y2:"15"}],["line",{x1:"9",x2:"15",y1:"9",y2:"15"}]],fg=[["path",{d:"M19.5 7a24 24 0 0 1 0 10"}],["path",{d:"M4.5 7a24 24 0 0 0 0 10"}],["path",{d:"M7 19.5a24 24 0 0 0 10 0"}],["path",{d:"M7 4.5a24 24 0 0 1 10 0"}],["rect",{x:"17",y:"17",width:"5",height:"5",rx:"1"}],["rect",{x:"17",y:"2",width:"5",height:"5",rx:"1"}],["rect",{x:"2",y:"17",width:"5",height:"5",rx:"1"}],["rect",{x:"2",y:"2",width:"5",height:"5",rx:"1"}]],kg=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["circle",{cx:"7.5",cy:"7.5",r:".5",fill:"currentColor"}],["path",{d:"m7.9 7.9 2.7 2.7"}],["circle",{cx:"16.5",cy:"7.5",r:".5",fill:"currentColor"}],["path",{d:"m13.4 10.6 2.7-2.7"}],["circle",{cx:"7.5",cy:"16.5",r:".5",fill:"currentColor"}],["path",{d:"m7.9 16.1 2.7-2.7"}],["circle",{cx:"16.5",cy:"16.5",r:".5",fill:"currentColor"}],["path",{d:"m13.4 13.4 2.7 2.7"}],["circle",{cx:"12",cy:"12",r:"2"}]],Pg=[["path",{d:"M16 8q6 0 6-6-6 0-6 6"}],["path",{d:"M17.41 3.59a10 10 0 1 0 3 3"}],["path",{d:"M2 2a26.6 26.6 0 0 1 10 20c.9-6.82 1.5-9.5 4-14"}]],Bg=[["path",{d:"M18 11c-1.5 0-2.5.5-3 2"}],["path",{d:"M4 6a2 2 0 0 0-2 2v4a5 5 0 0 0 5 5 8 8 0 0 1 5 2 8 8 0 0 1 5-2 5 5 0 0 0 5-5V8a2 2 0 0 0-2-2h-3a8 8 0 0 0-5 2 8 8 0 0 0-5-2z"}],["path",{d:"M6 11c1.5 0 2.5.5 3 2"}]],Dg=[["path",{d:"M10 20h4"}],["path",{d:"M12 16v6"}],["path",{d:"M17 2h4v4"}],["path",{d:"m21 2-5.46 5.46"}],["circle",{cx:"12",cy:"11",r:"5"}]],Fg=[["path",{d:"M12 15v7"}],["path",{d:"M9 19h6"}],["circle",{cx:"12",cy:"9",r:"6"}]],zg=[["path",{d:"m2 8 2 2-2 2 2 2-2 2"}],["path",{d:"m22 8-2 2 2 2-2 2 2 2"}],["path",{d:"M8 8v10c0 .55.45 1 1 1h6c.55 0 1-.45 1-1v-2"}],["path",{d:"M16 10.34V6c0-.55-.45-1-1-1h-4.34"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],bg=[["path",{d:"m2 8 2 2-2 2 2 2-2 2"}],["path",{d:"m22 8-2 2 2 2-2 2 2 2"}],["rect",{width:"8",height:"14",x:"8",y:"5",rx:"1"}]],Rg=[["path",{d:"M10.66 6H14a2 2 0 0 1 2 2v2.5l5.248-3.062A.5.5 0 0 1 22 7.87v8.196"}],["path",{d:"M16 16a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h2"}],["path",{d:"m2 2 20 20"}]],Tg=[["path",{d:"m16 13 5.223 3.482a.5.5 0 0 0 .777-.416V7.87a.5.5 0 0 0-.752-.432L16 10.5"}],["rect",{x:"2",y:"6",width:"14",height:"12",rx:"2"}]],qg=[["rect",{width:"20",height:"16",x:"2",y:"4",rx:"2"}],["path",{d:"M2 8h20"}],["circle",{cx:"8",cy:"14",r:"2"}],["path",{d:"M8 12h8"}],["circle",{cx:"16",cy:"14",r:"2"}]],Ug=[["path",{d:"M21 17v2a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2v-2"}],["path",{d:"M21 7V5a2 2 0 0 0-2-2H5a2 2 0 0 0-2 2v2"}],["circle",{cx:"12",cy:"12",r:"1"}],["path",{d:"M18.944 12.33a1 1 0 0 0 0-.66 7.5 7.5 0 0 0-13.888 0 1 1 0 0 0 0 .66 7.5 7.5 0 0 0 13.888 0"}]],Og=[["circle",{cx:"6",cy:"12",r:"4"}],["circle",{cx:"18",cy:"12",r:"4"}],["line",{x1:"6",x2:"18",y1:"16",y2:"16"}]],Zg=[["path",{d:"M11.1 7.1a16.55 16.55 0 0 1 10.9 4"}],["path",{d:"M12 12a12.6 12.6 0 0 1-8.7 5"}],["path",{d:"M16.8 13.6a16.55 16.55 0 0 1-9 7.5"}],["path",{d:"M20.7 17a12.8 12.8 0 0 0-8.7-5 13.3 13.3 0 0 1 0-10"}],["path",{d:"M6.3 3.8a16.55 16.55 0 0 0 1.9 11.5"}],["circle",{cx:"12",cy:"12",r:"10"}]],Gg=[["path",{d:"M11 4.702a.705.705 0 0 0-1.203-.498L6.413 7.587A1.4 1.4 0 0 1 5.416 8H3a1 1 0 0 0-1 1v6a1 1 0 0 0 1 1h2.416a1.4 1.4 0 0 1 .997.413l3.383 3.384A.705.705 0 0 0 11 19.298z"}],["path",{d:"M16 9a5 5 0 0 1 0 6"}]],Ig=[["path",{d:"M11 4.702a.705.705 0 0 0-1.203-.498L6.413 7.587A1.4 1.4 0 0 1 5.416 8H3a1 1 0 0 0-1 1v6a1 1 0 0 0 1 1h2.416a1.4 1.4 0 0 1 .997.413l3.383 3.384A.705.705 0 0 0 11 19.298z"}],["path",{d:"M16 9a5 5 0 0 1 0 6"}],["path",{d:"M19.364 18.364a9 9 0 0 0 0-12.728"}]],Wg=[["path",{d:"M16 9a5 5 0 0 1 .95 2.293"}],["path",{d:"M19.364 5.636a9 9 0 0 1 1.889 9.96"}],["path",{d:"m2 2 20 20"}],["path",{d:"m7 7-.587.587A1.4 1.4 0 0 1 5.416 8H3a1 1 0 0 0-1 1v6a1 1 0 0 0 1 1h2.416a1.4 1.4 0 0 1 .997.413l3.383 3.384A.705.705 0 0 0 11 19.298V11"}],["path",{d:"M9.828 4.172A.686.686 0 0 1 11 4.657v.686"}]],Eg=[["path",{d:"M11 4.702a.705.705 0 0 0-1.203-.498L6.413 7.587A1.4 1.4 0 0 1 5.416 8H3a1 1 0 0 0-1 1v6a1 1 0 0 0 1 1h2.416a1.4 1.4 0 0 1 .997.413l3.383 3.384A.705.705 0 0 0 11 19.298z"}],["line",{x1:"22",x2:"16",y1:"9",y2:"15"}],["line",{x1:"16",x2:"22",y1:"9",y2:"15"}]],Xg=[["path",{d:"M11 4.702a.705.705 0 0 0-1.203-.498L6.413 7.587A1.4 1.4 0 0 1 5.416 8H3a1 1 0 0 0-1 1v6a1 1 0 0 0 1 1h2.416a1.4 1.4 0 0 1 .997.413l3.383 3.384A.705.705 0 0 0 11 19.298z"}]],jg=[["path",{d:"m9 12 2 2 4-4"}],["path",{d:"M5 7c0-1.1.9-2 2-2h10a2 2 0 0 1 2 2v12H5V7Z"}],["path",{d:"M22 19H2"}]],Ng=[["rect",{width:"18",height:"18",x:"3",y:"3",rx:"2"}],["path",{d:"M3 9a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2"}],["path",{d:"M3 11h3c.8 0 1.6.3 2.1.9l1.1.9c1.6 1.6 4.1 1.6 5.7 0l1.1-.9c.5-.5 1.3-.9 2.1-.9H21"}]],pa=[["path",{d:"M17 14h.01"}],["path",{d:"M7 7h12a2 2 0 0 1 2 2v10a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h14"}]],Kg=[["path",{d:"M19 7V4a1 1 0 0 0-1-1H5a2 2 0 0 0 0 4h15a1 1 0 0 1 1 1v4h-3a2 2 0 0 0 0 4h3a1 1 0 0 0 1-1v-2a1 1 0 0 0-1-1"}],["path",{d:"M3 5v14a2 2 0 0 0 2 2h15a1 1 0 0 0 1-1v-4"}]],Qg=[["path",{d:"M12 17v4"}],["path",{d:"M8 21h8"}],["path",{d:"m9 17 6.1-6.1a2 2 0 0 1 2.81.01L22 15"}],["circle",{cx:"8",cy:"9",r:"2"}],["rect",{x:"2",y:"3",width:"20",height:"14",rx:"2"}]],ia=[["path",{d:"m21.64 3.64-1.28-1.28a1.21 1.21 0 0 0-1.72 0L2.36 18.64a1.21 1.21 0 0 0 0 1.72l1.28 1.28a1.2 1.2 0 0 0 1.72 0L21.64 5.36a1.2 1.2 0 0 0 0-1.72"}],["path",{d:"m14 7 3 3"}],["path",{d:"M5 6v4"}],["path",{d:"M19 14v4"}],["path",{d:"M10 2v2"}],["path",{d:"M7 8H3"}],["path",{d:"M21 16h-4"}],["path",{d:"M11 3H9"}]],Jg=[["path",{d:"M15 4V2"}],["path",{d:"M15 16v-2"}],["path",{d:"M8 9h2"}],["path",{d:"M20 9h2"}],["path",{d:"M17.8 11.8 19 13"}],["path",{d:"M15 9h.01"}],["path",{d:"M17.8 6.2 19 5"}],["path",{d:"m3 21 9-9"}],["path",{d:"M12.2 6.2 11 5"}]],Yg=[["path",{d:"M18 21V10a1 1 0 0 0-1-1H7a1 1 0 0 0-1 1v11"}],["path",{d:"M22 19a2 2 0 0 1-2 2H4a2 2 0 0 1-2-2V8a2 2 0 0 1 1.132-1.803l7.95-3.974a2 2 0 0 1 1.837 0l7.948 3.974A2 2 0 0 1 22 8z"}],["path",{d:"M6 13h12"}],["path",{d:"M6 17h12"}]],_g=[["path",{d:"M3 6h3"}],["path",{d:"M17 6h.01"}],["rect",{width:"18",height:"20",x:"3",y:"2",rx:"2"}],["circle",{cx:"12",cy:"13",r:"5"}],["path",{d:"M12 18a2.5 2.5 0 0 0 0-5 2.5 2.5 0 0 1 0-5"}]],xg=[["path",{d:"M12 10v2.2l1.6 1"}],["path",{d:"m16.13 7.66-.81-4.05a2 2 0 0 0-2-1.61h-2.68a2 2 0 0 0-2 1.61l-.78 4.05"}],["path",{d:"m7.88 16.36.8 4a2 2 0 0 0 2 1.61h2.72a2 2 0 0 0 2-1.61l.81-4.05"}],["circle",{cx:"12",cy:"12",r:"6"}]],au=[["path",{d:"M19 5a2 2 0 0 0-2 2v11"}],["path",{d:"M2 18c.6.5 1.2 1 2.5 1 2.5 0 2.5-2 5-2 2.6 0 2.4 2 5 2 2.5 0 2.5-2 5-2 1.3 0 1.9.5 2.5 1"}],["path",{d:"M7 13h10"}],["path",{d:"M7 9h10"}],["path",{d:"M9 5a2 2 0 0 0-2 2v11"}]],tu=[["path",{d:"M2 6c.6.5 1.2 1 2.5 1C7 7 7 5 9.5 5c2.6 0 2.4 2 5 2 2.5 0 2.5-2 5-2 1.3 0 1.9.5 2.5 1"}],["path",{d:"M2 12c.6.5 1.2 1 2.5 1 2.5 0 2.5-2 5-2 2.6 0 2.4 2 5 2 2.5 0 2.5-2 5-2 1.3 0 1.9.5 2.5 1"}],["path",{d:"M2 18c.6.5 1.2 1 2.5 1 2.5 0 2.5-2 5-2 2.6 0 2.4 2 5 2 2.5 0 2.5-2 5-2 1.3 0 1.9.5 2.5 1"}]],hu=[["circle",{cx:"12",cy:"4.5",r:"2.5"}],["path",{d:"m10.2 6.3-3.9 3.9"}],["circle",{cx:"4.5",cy:"12",r:"2.5"}],["path",{d:"M7 12h10"}],["circle",{cx:"19.5",cy:"12",r:"2.5"}],["path",{d:"m13.8 17.7 3.9-3.9"}],["circle",{cx:"12",cy:"19.5",r:"2.5"}]],du=[["circle",{cx:"12",cy:"10",r:"8"}],["circle",{cx:"12",cy:"10",r:"3"}],["path",{d:"M7 22h10"}],["path",{d:"M12 22v-4"}]],cu=[["circle",{cx:"12",cy:"5",r:"3"}],["path",{d:"M6.5 8a2 2 0 0 0-1.905 1.46L2.1 18.5A2 2 0 0 0 4 21h16a2 2 0 0 0 1.925-2.54L19.4 9.5A2 2 0 0 0 17.48 8Z"}]],Mu=[["path",{d:"M17 17h-5c-1.09-.02-1.94.92-2.5 1.9A3 3 0 1 1 2.57 15"}],["path",{d:"M9 3.4a4 4 0 0 1 6.52.66"}],["path",{d:"m6 17 3.1-5.8a2.5 2.5 0 0 0 .057-2.05"}],["path",{d:"M20.3 20.3a4 4 0 0 1-2.3.7"}],["path",{d:"M18.6 13a4 4 0 0 1 3.357 3.414"}],["path",{d:"m12 6 .6 1"}],["path",{d:"m2 2 20 20"}]],pu=[["path",{d:"M18 16.98h-5.99c-1.1 0-1.95.94-2.48 1.9A4 4 0 0 1 2 17c.01-.7.2-1.4.57-2"}],["path",{d:"m6 17 3.13-5.78c.53-.97.1-2.18-.5-3.1a4 4 0 1 1 6.89-4.06"}],["path",{d:"m12 6 3.13 5.73C15.66 12.7 16.9 13 18 13a4 4 0 0 1 0 8"}]],iu=[["path",{d:"m2 22 10-10"}],["path",{d:"m16 8-1.17 1.17"}],["path",{d:"M3.47 12.53 5 11l1.53 1.53a3.5 3.5 0 0 1 0 4.94L5 19l-1.53-1.53a3.5 3.5 0 0 1 0-4.94Z"}],["path",{d:"m8 8-.53.53a3.5 3.5 0 0 0 0 4.94L9 15l1.53-1.53c.55-.55.88-1.25.98-1.97"}],["path",{d:"M10.91 5.26c.15-.26.34-.51.56-.73L13 3l1.53 1.53a3.5 3.5 0 0 1 .28 4.62"}],["path",{d:"M20 2h2v2a4 4 0 0 1-4 4h-2V6a4 4 0 0 1 4-4Z"}],["path",{d:"M11.47 17.47 13 19l-1.53 1.53a3.5 3.5 0 0 1-4.94 0L5 19l1.53-1.53a3.5 3.5 0 0 1 4.94 0Z"}],["path",{d:"m16 16-.53.53a3.5 3.5 0 0 1-4.94 0L9 15l1.53-1.53a3.49 3.49 0 0 1 1.97-.98"}],["path",{d:"M18.74 13.09c.26-.15.51-.34.73-.56L21 11l-1.53-1.53a3.5 3.5 0 0 0-4.62-.28"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],nu=[["path",{d:"M2 22 16 8"}],["path",{d:"M3.47 12.53 5 11l1.53 1.53a3.5 3.5 0 0 1 0 4.94L5 19l-1.53-1.53a3.5 3.5 0 0 1 0-4.94Z"}],["path",{d:"M7.47 8.53 9 7l1.53 1.53a3.5 3.5 0 0 1 0 4.94L9 15l-1.53-1.53a3.5 3.5 0 0 1 0-4.94Z"}],["path",{d:"M11.47 4.53 13 3l1.53 1.53a3.5 3.5 0 0 1 0 4.94L13 11l-1.53-1.53a3.5 3.5 0 0 1 0-4.94Z"}],["path",{d:"M20 2h2v2a4 4 0 0 1-4 4h-2V6a4 4 0 0 1 4-4Z"}],["path",{d:"M11.47 17.47 13 19l-1.53 1.53a3.5 3.5 0 0 1-4.94 0L5 19l1.53-1.53a3.5 3.5 0 0 1 4.94 0Z"}],["path",{d:"M15.47 13.47 17 15l-1.53 1.53a3.5 3.5 0 0 1-4.94 0L9 15l1.53-1.53a3.5 3.5 0 0 1 4.94 0Z"}],["path",{d:"M19.47 9.47 21 11l-1.53 1.53a3.5 3.5 0 0 1-4.94 0L13 11l1.53-1.53a3.5 3.5 0 0 1 4.94 0Z"}]],lu=[["circle",{cx:"7",cy:"12",r:"3"}],["path",{d:"M10 9v6"}],["circle",{cx:"17",cy:"12",r:"3"}],["path",{d:"M14 7v8"}],["path",{d:"M22 17v1c0 .5-.5 1-1 1H3c-.5 0-1-.5-1-1v-1"}]],eu=[["path",{d:"m14.305 19.53.923-.382"}],["path",{d:"m15.228 16.852-.923-.383"}],["path",{d:"m16.852 15.228-.383-.923"}],["path",{d:"m16.852 20.772-.383.924"}],["path",{d:"m19.148 15.228.383-.923"}],["path",{d:"m19.53 21.696-.382-.924"}],["path",{d:"M2 7.82a15 15 0 0 1 20 0"}],["path",{d:"m20.772 16.852.924-.383"}],["path",{d:"m20.772 19.148.924.383"}],["path",{d:"M5 11.858a10 10 0 0 1 11.5-1.785"}],["path",{d:"M8.5 15.429a5 5 0 0 1 2.413-1.31"}],["circle",{cx:"18",cy:"18",r:"3"}]],ru=[["path",{d:"M12 20h.01"}],["path",{d:"M5 12.859a10 10 0 0 1 14 0"}],["path",{d:"M8.5 16.429a5 5 0 0 1 7 0"}]],ou=[["path",{d:"M12 20h.01"}],["path",{d:"M8.5 16.429a5 5 0 0 1 7 0"}]],vu=[["path",{d:"M2 8.82a15 15 0 0 1 20 0"}],["path",{d:"M21.378 16.626a1 1 0 0 0-3.004-3.004l-4.01 4.012a2 2 0 0 0-.506.854l-.837 2.87a.5.5 0 0 0 .62.62l2.87-.837a2 2 0 0 0 .854-.506z"}],["path",{d:"M5 12.859a10 10 0 0 1 10.5-2.222"}],["path",{d:"M8.5 16.429a5 5 0 0 1 3-1.406"}]],$u=[["path",{d:"M11.965 10.105v4L13.5 12.5a5 5 0 0 1 8 1.5"}],["path",{d:"M11.965 14.105h4"}],["path",{d:"M17.965 18.105h4L20.43 19.71a5 5 0 0 1-8-1.5"}],["path",{d:"M2 8.82a15 15 0 0 1 20 0"}],["path",{d:"M21.965 22.105v-4"}],["path",{d:"M5 12.86a10 10 0 0 1 3-2.032"}],["path",{d:"M8.5 16.429h.01"}]],mu=[["path",{d:"M12 20h.01"}],["path",{d:"M8.5 16.429a5 5 0 0 1 7 0"}],["path",{d:"M5 12.859a10 10 0 0 1 5.17-2.69"}],["path",{d:"M19 12.859a10 10 0 0 0-2.007-1.523"}],["path",{d:"M2 8.82a15 15 0 0 1 4.177-2.643"}],["path",{d:"M22 8.82a15 15 0 0 0-11.288-3.764"}],["path",{d:"m2 2 20 20"}]],yu=[["path",{d:"M12 20h.01"}]],su=[["path",{d:"M12 20h.01"}],["path",{d:"M2 8.82a15 15 0 0 1 20 0"}],["path",{d:"M5 12.859a10 10 0 0 1 14 0"}],["path",{d:"M8.5 16.429a5 5 0 0 1 7 0"}]],gu=[["path",{d:"M10 2v8"}],["path",{d:"M12.8 21.6A2 2 0 1 0 14 18H2"}],["path",{d:"M17.5 10a2.5 2.5 0 1 1 2 4H2"}],["path",{d:"m6 6 4 4 4-4"}]],uu=[["path",{d:"M12.8 19.6A2 2 0 1 0 14 16H2"}],["path",{d:"M17.5 8a2.5 2.5 0 1 1 2 4H2"}],["path",{d:"M9.8 4.4A2 2 0 1 1 11 8H2"}]],Cu=[["path",{d:"M8 22h8"}],["path",{d:"M7 10h3m7 0h-1.343"}],["path",{d:"M12 15v7"}],["path",{d:"M7.307 7.307A12.33 12.33 0 0 0 7 10a5 5 0 0 0 7.391 4.391M8.638 2.981C8.75 2.668 8.872 2.34 9 2h6c1.5 4 2 6 2 8 0 .407-.05.809-.145 1.198"}],["line",{x1:"2",x2:"22",y1:"2",y2:"22"}]],Hu=[["path",{d:"M8 22h8"}],["path",{d:"M7 10h10"}],["path",{d:"M12 15v7"}],["path",{d:"M12 15a5 5 0 0 0 5-5c0-2-.5-4-2-8H9c-1.5 4-2 6-2 8a5 5 0 0 0 5 5Z"}]],Au=[["rect",{width:"8",height:"8",x:"3",y:"3",rx:"2"}],["path",{d:"M7 11v4a2 2 0 0 0 2 2h4"}],["rect",{width:"8",height:"8",x:"13",y:"13",rx:"2"}]],wu=[["path",{d:"m19 12-1.5 3"}],["path",{d:"M19.63 18.81 22 20"}],["path",{d:"M6.47 8.23a1.68 1.68 0 0 1 2.44 1.93l-.64 2.08a6.76 6.76 0 0 0 10.16 7.67l.42-.27a1 1 0 1 0-2.73-4.21l-.42.27a1.76 1.76 0 0 1-2.63-1.99l.64-2.08A6.66 6.66 0 0 0 3.94 3.9l-.7.4a1 1 0 1 0 2.55 4.34z"}]],Vu=[["path",{d:"M14.7 6.3a1 1 0 0 0 0 1.4l1.6 1.6a1 1 0 0 0 1.4 0l3.106-3.105c.32-.322.863-.22.983.218a6 6 0 0 1-8.259 7.057l-7.91 7.91a1 1 0 0 1-2.999-3l7.91-7.91a6 6 0 0 1 7.057-8.259c.438.12.54.662.219.984z"}]],Su=[["path",{d:"M18 6 6 18"}],["path",{d:"m6 6 12 12"}]],Lu=[["path",{d:"M2.5 17a24.12 24.12 0 0 1 0-10 2 2 0 0 1 1.4-1.4 49.56 49.56 0 0 1 16.2 0A2 2 0 0 1 21.5 7a24.12 24.12 0 0 1 0 10 2 2 0 0 1-1.4 1.4 49.55 49.55 0 0 1-16.2 0A2 2 0 0 1 2.5 17"}],["path",{d:"m10 15 5-3-5-3z"}]],fu=[["path",{d:"M10.513 4.856 13.12 2.17a.5.5 0 0 1 .86.46l-1.377 4.317"}],["path",{d:"M15.656 10H20a1 1 0 0 1 .78 1.63l-1.72 1.773"}],["path",{d:"M16.273 16.273 10.88 21.83a.5.5 0 0 1-.86-.46l1.92-6.02A1 1 0 0 0 11 14H4a1 1 0 0 1-.78-1.63l4.507-4.643"}],["path",{d:"m2 2 20 20"}]],ku=[["path",{d:"M4 14a1 1 0 0 1-.78-1.63l9.9-10.2a.5.5 0 0 1 .86.46l-1.92 6.02A1 1 0 0 0 13 10h7a1 1 0 0 1 .78 1.63l-9.9 10.2a.5.5 0 0 1-.86-.46l1.92-6.02A1 1 0 0 0 11 14z"}]],Pu=[["circle",{cx:"11",cy:"11",r:"8"}],["line",{x1:"21",x2:"16.65",y1:"21",y2:"16.65"}],["line",{x1:"11",x2:"11",y1:"8",y2:"14"}],["line",{x1:"8",x2:"14",y1:"11",y2:"11"}]],Bu=[["circle",{cx:"11",cy:"11",r:"8"}],["line",{x1:"21",x2:"16.65",y1:"21",y2:"16.65"}],["line",{x1:"8",x2:"14",y1:"11",y2:"11"}]];var Du=Object.freeze({__proto__:null,AArrowDown:oa,AArrowUp:va,ALargeSmall:$a,Accessibility:ma,Activity:ya,ActivitySquare:G2,AirVent:sa,Airplay:ga,AlarmCheck:y,AlarmClock:Ca,AlarmClockCheck:y,AlarmClockMinus:s,AlarmClockOff:ua,AlarmClockPlus:g,AlarmMinus:s,AlarmPlus:g,AlarmSmoke:Ha,Album:Aa,AlertCircle:N,AlertOctagon:y2,AlertTriangle:K0,AlignCenter:Z0,AlignCenterHorizontal:wa,AlignCenterVertical:Va,AlignEndHorizontal:Sa,AlignEndVertical:La,AlignHorizontalDistributeCenter:fa,AlignHorizontalDistributeEnd:ka,AlignHorizontalDistributeStart:Pa,AlignHorizontalJustifyCenter:Ba,AlignHorizontalJustifyEnd:Da,AlignHorizontalJustifyStart:Fa,AlignHorizontalSpaceAround:za,AlignHorizontalSpaceBetween:ba,AlignJustify:I0,AlignLeft:m,AlignRight:G0,AlignStartHorizontal:Ra,AlignStartVertical:Ta,AlignVerticalDistributeCenter:qa,AlignVerticalDistributeEnd:Ua,AlignVerticalDistributeStart:Oa,AlignVerticalJustifyCenter:Za,AlignVerticalJustifyEnd:Ga,AlignVerticalJustifyStart:Ia,AlignVerticalSpaceAround:Wa,AlignVerticalSpaceBetween:Ea,Ambulance:ja,Ampersand:Xa,Ampersands:Na,Amphora:Ka,Anchor:Qa,Angry:Ja,Annoyed:Ya,Antenna:_a,Anvil:xa,Aperture:at,AppWindow:ht,AppWindowMac:tt,Apple:dt,Archive:pt,ArchiveRestore:ct,ArchiveX:Mt,AreaChart:z,Armchair:it,ArrowBigDown:lt,ArrowBigDownDash:nt,ArrowBigLeft:rt,ArrowBigLeftDash:et,ArrowBigRight:vt,ArrowBigRightDash:ot,ArrowBigUp:st,ArrowBigUpDash:$t,ArrowDown:St,ArrowDown01:mt,ArrowDown10:yt,ArrowDownAZ:u,ArrowDownAz:u,ArrowDownCircle:K,ArrowDownFromLine:gt,ArrowDownLeft:Ct,ArrowDownLeftFromCircle:J,ArrowDownLeftFromSquare:j2,ArrowDownLeftSquare:I2,ArrowDownNarrowWide:ut,ArrowDownRight:At,ArrowDownRightFromCircle:_,ArrowDownRightFromSquare:N2,ArrowDownRightSquare:W2,ArrowDownSquare:E2,ArrowDownToDot:Ht,ArrowDownToLine:wt,ArrowDownUp:Vt,ArrowDownWideNarrow:C,ArrowDownZA:H,ArrowDownZa:H,ArrowLeft:Pt,ArrowLeftCircle:Q,ArrowLeftFromLine:Lt,ArrowLeftRight:ft,ArrowLeftSquare:X2,ArrowLeftToLine:kt,ArrowRight:zt,ArrowRightCircle:a1,ArrowRightFromLine:Bt,ArrowRightLeft:Ft,ArrowRightSquare:J2,ArrowRightToLine:Dt,ArrowUp:Wt,ArrowUp01:bt,ArrowUp10:Rt,ArrowUpAZ:A,ArrowUpAz:A,ArrowUpCircle:t1,ArrowUpDown:Tt,ArrowUpFromDot:Ut,ArrowUpFromLine:qt,ArrowUpLeft:Ot,ArrowUpLeftFromCircle:Y,ArrowUpLeftFromSquare:K2,ArrowUpLeftSquare:Y2,ArrowUpNarrowWide:w,ArrowUpRight:Zt,ArrowUpRightFromCircle:x,ArrowUpRightFromSquare:Q2,ArrowUpRightSquare:_2,ArrowUpSquare:x2,ArrowUpToLine:It,ArrowUpWideNarrow:Gt,ArrowUpZA:V,ArrowUpZa:V,ArrowsUpFromLine:Et,Asterisk:Xt,AsteriskSquare:a0,AtSign:jt,Atom:Qt,AudioLines:Nt,AudioWaveform:Kt,Award:Jt,Axe:Yt,Axis3D:S,Axis3d:S,Baby:_t,Backpack:xt,Badge:mh,BadgeAlert:ah,BadgeCent:th,BadgeCheck:L,BadgeDollarSign:hh,BadgeEuro:dh,BadgeHelp:f,BadgeIndianRupee:ch,BadgeInfo:Mh,BadgeJapaneseYen:ph,BadgeMinus:ih,BadgePercent:nh,BadgePlus:lh,BadgePoundSterling:eh,BadgeQuestionMark:f,BadgeRussianRuble:rh,BadgeSwissFranc:oh,BadgeTurkishLira:vh,BadgeX:$h,BaggageClaim:yh,Ban:sh,Banana:gh,Bandage:uh,Banknote:wh,BanknoteArrowDown:Ch,BanknoteArrowUp:Hh,BanknoteX:Ah,BarChart:G,BarChart2:I,BarChart3:O,BarChart4:U,BarChartBig:q,BarChartHorizontal:T,BarChartHorizontalBig:b,Barcode:Vh,Barrel:Sh,Baseline:Lh,Bath:fh,Battery:bh,BatteryCharging:kh,BatteryFull:Ph,BatteryLow:Bh,BatteryMedium:Dh,BatteryPlus:Fh,BatteryWarning:zh,Beaker:Rh,Bean:qh,BeanOff:Th,Bed:Zh,BedDouble:Uh,BedSingle:Oh,Beef:Gh,Beer:Wh,BeerOff:Ih,Bell:Jh,BellDot:Eh,BellElectric:Xh,BellMinus:jh,BellOff:Nh,BellPlus:Kh,BellRing:Qh,BetweenHorizonalEnd:k,BetweenHorizonalStart:P,BetweenHorizontalEnd:k,BetweenHorizontalStart:P,BetweenVerticalEnd:Yh,BetweenVerticalStart:_h,BicepsFlexed:xh,Bike:a4,Binary:t4,Binoculars:h4,Biohazard:d4,Bird:c4,Bitcoin:p4,Blend:M4,Blinds:n4,Blocks:i4,Bluetooth:r4,BluetoothConnected:l4,BluetoothOff:o4,BluetoothSearching:e4,Bold:v4,Bolt:$4,Bomb:m4,Bone:y4,Book:Z4,BookA:s4,BookAlert:g4,BookAudio:u4,BookCheck:C4,BookCopy:H4,BookDashed:B,BookDown:A4,BookHeadphones:w4,BookHeart:V4,BookImage:S4,BookKey:L4,BookLock:f4,BookMarked:k4,BookMinus:P4,BookOpen:F4,BookOpenCheck:B4,BookOpenText:D4,BookPlus:z4,BookTemplate:B,BookText:b4,BookType:T4,BookUp:q4,BookUp2:R4,BookUser:U4,BookX:O4,Bookmark:X4,BookmarkCheck:G4,BookmarkMinus:I4,BookmarkPlus:W4,BookmarkX:E4,BoomBox:j4,Bot:Q4,BotMessageSquare:K4,BotOff:N4,BottleWine:J4,BowArrow:Y4,Box:_4,BoxSelect:r0,Boxes:x4,Braces:D,Brackets:a5,Brain:d5,BrainCircuit:t5,BrainCog:h5,BrickWall:p5,BrickWallFire:c5,BrickWallShield:M5,Briefcase:e5,BriefcaseBusiness:i5,BriefcaseConveyorBelt:n5,BriefcaseMedical:l5,BringToFront:r5,Brush:v5,BrushCleaning:o5,Bubbles:$5,Bug:s5,BugOff:m5,BugPlay:y5,Building:u5,Building2:g5,Bus:H5,BusFront:C5,Cable:w5,CableCar:A5,Cake:S5,CakeSlice:V5,Calculator:L5,Calendar:N5,Calendar1:f5,CalendarArrowDown:k5,CalendarArrowUp:P5,CalendarCheck:D5,CalendarCheck2:B5,CalendarClock:F5,CalendarCog:R5,CalendarDays:z5,CalendarFold:b5,CalendarHeart:T5,CalendarMinus:U5,CalendarMinus2:q5,CalendarOff:O5,CalendarPlus:Z5,CalendarPlus2:I5,CalendarRange:G5,CalendarSearch:E5,CalendarSync:W5,CalendarX:j5,CalendarX2:X5,Camera:Q5,CameraOff:K5,CandlestickChart:R,Candy:_5,CandyCane:J5,CandyOff:Y5,Cannabis:x5,Captions:F,CaptionsOff:a3,Car:d3,CarFront:t3,CarTaxiFront:h3,Caravan:c3,CardSim:M3,Carrot:p3,CaseLower:i3,CaseSensitive:n3,CaseUpper:l3,CassetteTape:e3,Cast:r3,Castle:o3,Cat:v3,Cctv:$3,ChartArea:z,ChartBar:T,ChartBarBig:b,ChartBarDecreasing:m3,ChartBarIncreasing:y3,ChartBarStacked:s3,ChartCandlestick:R,ChartColumn:O,ChartColumnBig:q,ChartColumnDecreasing:g3,ChartColumnIncreasing:U,ChartColumnStacked:u3,ChartGantt:C3,ChartLine:Z,ChartNetwork:H3,ChartNoAxesColumn:I,ChartNoAxesColumnDecreasing:A3,ChartNoAxesColumnIncreasing:G,ChartNoAxesCombined:w3,ChartNoAxesGantt:W,ChartPie:X,ChartScatter:E,ChartSpline:V3,Check:f3,CheckCheck:S3,CheckCircle:h1,CheckCircle2:d1,CheckLine:L3,CheckSquare:h0,CheckSquare2:d0,ChefHat:k3,Cherry:B3,ChevronDown:P3,ChevronDownCircle:c1,ChevronDownSquare:c0,ChevronFirst:D3,ChevronLast:F3,ChevronLeft:z3,ChevronLeftCircle:M1,ChevronLeftSquare:M0,ChevronRight:b3,ChevronRightCircle:p1,ChevronRightSquare:p0,ChevronUp:R3,ChevronUpCircle:i1,ChevronUpSquare:i0,ChevronsDown:q3,ChevronsDownUp:T3,ChevronsLeft:Z3,ChevronsLeftRight:O3,ChevronsLeftRightEllipsis:U3,ChevronsRight:I3,ChevronsRightLeft:G3,ChevronsUp:E3,ChevronsUpDown:W3,Chrome:j,Chromium:j,Church:X3,Cigarette:N3,CigaretteOff:j3,Circle:id,CircleAlert:N,CircleArrowDown:K,CircleArrowLeft:Q,CircleArrowOutDownLeft:J,CircleArrowOutDownRight:_,CircleArrowOutUpLeft:Y,CircleArrowOutUpRight:x,CircleArrowRight:a1,CircleArrowUp:t1,CircleCheck:d1,CircleCheckBig:h1,CircleChevronDown:c1,CircleChevronLeft:M1,CircleChevronRight:p1,CircleChevronUp:i1,CircleDashed:K3,CircleDivide:n1,CircleDollarSign:Q3,CircleDot:Y3,CircleDotDashed:J3,CircleEllipsis:_3,CircleEqual:x3,CircleFadingArrowUp:ad,CircleFadingPlus:td,CircleGauge:l1,CircleHelp:l,CircleMinus:e1,CircleOff:hd,CircleParking:o1,CircleParkingOff:r1,CirclePause:v1,CirclePercent:$1,CirclePlay:m1,CirclePlus:y1,CirclePoundSterling:dd,CirclePower:s1,CircleQuestionMark:l,CircleSlash:cd,CircleSlash2:g1,CircleSlashed:g1,CircleSmall:Md,CircleStar:pd,CircleStop:u1,CircleUser:H1,CircleUserRound:C1,CircleX:A1,CircuitBoard:nd,Citrus:ld,Clapperboard:ed,Clipboard:Cd,ClipboardCheck:rd,ClipboardClock:od,ClipboardCopy:vd,ClipboardEdit:V1,ClipboardList:$d,ClipboardMinus:md,ClipboardPaste:yd,ClipboardPen:V1,ClipboardPenLine:w1,ClipboardPlus:sd,ClipboardSignature:w1,ClipboardType:gd,ClipboardX:ud,Clock:Ud,Clock1:Hd,Clock10:Ad,Clock11:wd,Clock12:Vd,Clock2:Sd,Clock3:Ld,Clock4:fd,Clock5:kd,Clock6:Pd,Clock7:Bd,Clock8:Dd,Clock9:Fd,ClockAlert:zd,ClockArrowDown:bd,ClockArrowUp:Rd,ClockFading:Td,ClockPlus:qd,ClosedCaption:Od,Cloud:t6,CloudAlert:Zd,CloudCheck:Gd,CloudCog:Id,CloudDownload:S1,CloudDrizzle:Wd,CloudFog:Ed,CloudHail:Xd,CloudLightning:Nd,CloudMoon:Kd,CloudMoonRain:jd,CloudOff:Qd,CloudRain:Yd,CloudRainWind:Jd,CloudSnow:_d,CloudSun:a6,CloudSunRain:xd,CloudUpload:L1,Cloudy:h6,Clover:d6,Club:c6,Code:p6,Code2:f1,CodeSquare:n0,CodeXml:f1,Codepen:M6,Codesandbox:i6,Coffee:n6,Cog:l6,Coins:e6,Columns:k1,Columns2:k1,Columns3:P1,Columns3Cog:e,Columns4:r6,ColumnsSettings:e,Combine:o6,Command:v6,Compass:$6,Component:m6,Computer:y6,ConciergeBell:s6,Cone:g6,Construction:u6,Contact:C6,Contact2:B1,ContactRound:B1,Container:H6,Contrast:A6,Cookie:w6,CookingPot:V6,Copy:B6,CopyCheck:S6,CopyMinus:L6,CopyPlus:f6,CopySlash:k6,CopyX:P6,Copyleft:D6,Copyright:F6,CornerDownLeft:b6,CornerDownRight:z6,CornerLeftDown:R6,CornerLeftUp:T6,CornerRightDown:q6,CornerRightUp:U6,CornerUpLeft:G6,CornerUpRight:O6,Cpu:Z6,CreativeCommons:I6,CreditCard:W6,Croissant:E6,Crop:X6,Cross:j6,Crosshair:N6,Crown:K6,Cuboid:Q6,CupSoda:J6,CurlyBraces:D,Currency:Y6,Cylinder:_6,Dam:x6,Database:h8,DatabaseBackup:a8,DatabaseZap:t8,DecimalsArrowLeft:d8,DecimalsArrowRight:c8,Delete:M8,Dessert:p8,Diameter:i8,Diamond:e8,DiamondMinus:n8,DiamondPercent:D1,DiamondPlus:l8,Dice1:r8,Dice2:o8,Dice3:v8,Dice4:$8,Dice5:m8,Dice6:y8,Dices:s8,Diff:g8,Disc:A8,Disc2:u8,Disc3:C8,DiscAlbum:H8,Divide:w8,DivideCircle:n1,DivideSquare:o0,Dna:S8,DnaOff:V8,Dock:L8,Dog:f8,DollarSign:k8,Donut:P8,DoorClosed:D8,DoorClosedLocked:B8,DoorOpen:F8,Dot:z8,DotSquare:v0,Download:b8,DownloadCloud:S1,DraftingCompass:R8,Drama:T8,Dribbble:q8,Drill:U8,Drone:O8,Droplet:G8,DropletOff:Z8,Droplets:I8,Drum:W8,Drumstick:E8,Dumbbell:X8,Ear:j8,EarOff:N8,Earth:F1,EarthLock:K8,Eclipse:Q8,Edit:p,Edit2:P2,Edit3:k2,Egg:Y8,EggFried:J8,EggOff:_8,Ellipsis:b1,EllipsisVertical:z1,Equal:tc,EqualApproximately:x8,EqualNot:ac,EqualSquare:$0,Eraser:dc,EthernetPort:hc,Euro:cc,EvCharger:Mc,Expand:pc,ExternalLink:ic,Eye:ec,EyeClosed:nc,EyeOff:lc,Facebook:rc,Factory:oc,Fan:vc,FastForward:$c,Feather:mc,Fence:yc,FerrisWheel:sc,Figma:gc,File:o7,FileArchive:uc,FileAudio:Hc,FileAudio2:Cc,FileAxis3D:R1,FileAxis3d:R1,FileBadge:wc,FileBadge2:Ac,FileBarChart:T1,FileBarChart2:q1,FileBox:Vc,FileChartColumn:q1,FileChartColumnIncreasing:T1,FileChartLine:U1,FileChartPie:O1,FileCheck:Lc,FileCheck2:Sc,FileClock:fc,FileCode:Pc,FileCode2:kc,FileCog:Z1,FileCog2:Z1,FileDiff:Bc,FileDigit:Dc,FileDown:Fc,FileEdit:I1,FileHeart:zc,FileImage:bc,FileInput:Rc,FileJson:qc,FileJson2:Tc,FileKey:Oc,FileKey2:Uc,FileLineChart:U1,FileLock:Gc,FileLock2:Zc,FileMinus:Wc,FileMinus2:Ic,FileMusic:Ec,FileOutput:Xc,FilePen:I1,FilePenLine:G1,FilePieChart:O1,FilePlay:W1,FilePlus:Nc,FilePlus2:jc,FileQuestion:E1,FileQuestionMark:E1,FileScan:Kc,FileSearch:Jc,FileSearch2:Qc,FileSignature:G1,FileSliders:Yc,FileSpreadsheet:_c,FileStack:xc,FileSymlink:a7,FileTerminal:t7,FileText:h7,FileType:c7,FileType2:d7,FileUp:M7,FileUser:p7,FileVideo:W1,FileVideo2:X1,FileVideoCamera:X1,FileVolume:n7,FileVolume2:i7,FileWarning:l7,FileX:r7,FileX2:e7,Files:v7,Film:$7,Filter:K1,FilterX:Q1,Fingerprint:y7,FireExtinguisher:m7,Fish:u7,FishOff:s7,FishSymbol:g7,Flag:w7,FlagOff:C7,FlagTriangleLeft:H7,FlagTriangleRight:A7,Flame:S7,FlameKindling:V7,Flashlight:f7,FlashlightOff:L7,FlaskConical:P7,FlaskConicalOff:k7,FlaskRound:B7,FlipHorizontal:F7,FlipHorizontal2:D7,FlipVertical:b7,FlipVertical2:z7,Flower:T7,Flower2:R7,Focus:q7,FoldHorizontal:U7,FoldVertical:O7,Folder:vM,FolderArchive:G7,FolderCheck:Z7,FolderClock:I7,FolderClosed:E7,FolderCode:W7,FolderCog:j1,FolderCog2:j1,FolderDot:X7,FolderDown:j7,FolderEdit:N1,FolderGit:K7,FolderGit2:N7,FolderHeart:Q7,FolderInput:J7,FolderKanban:_7,FolderKey:Y7,FolderLock:aM,FolderMinus:x7,FolderOpen:hM,FolderOpenDot:tM,FolderOutput:dM,FolderPen:N1,FolderPlus:cM,FolderRoot:MM,FolderSearch:iM,FolderSearch2:pM,FolderSymlink:nM,FolderSync:lM,FolderTree:eM,FolderUp:rM,FolderX:oM,Folders:$M,Footprints:mM,ForkKnife:Ma,ForkKnifeCrossed:ca,Forklift:yM,FormInput:D2,Forward:sM,Frame:gM,Framer:uM,Frown:CM,Fuel:HM,Fullscreen:AM,FunctionSquare:m0,Funnel:K1,FunnelPlus:wM,FunnelX:Q1,GalleryHorizontal:SM,GalleryHorizontalEnd:VM,GalleryThumbnails:LM,GalleryVertical:kM,GalleryVerticalEnd:fM,Gamepad:BM,Gamepad2:PM,GanttChart:W,GanttChartSquare:$,Gauge:DM,GaugeCircle:l1,Gavel:FM,Gem:zM,GeorgianLari:bM,Ghost:qM,Gift:RM,GitBranch:UM,GitBranchPlus:TM,GitCommit:J1,GitCommitHorizontal:J1,GitCommitVertical:OM,GitCompare:GM,GitCompareArrows:ZM,GitFork:IM,GitGraph:WM,GitMerge:EM,GitPullRequest:JM,GitPullRequestArrow:XM,GitPullRequestClosed:jM,GitPullRequestCreate:KM,GitPullRequestCreateArrow:NM,GitPullRequestDraft:QM,Github:YM,Gitlab:_M,GlassWater:xM,Glasses:a9,Globe:t9,Globe2:F1,GlobeLock:h9,Goal:d9,Gpu:c9,Grab:t2,GraduationCap:M9,Grape:p9,Grid:r,Grid2X2:a2,Grid2X2Check:_1,Grid2X2Plus:Y1,Grid2X2X:x1,Grid2x2:a2,Grid2x2Check:_1,Grid2x2Plus:Y1,Grid2x2X:x1,Grid3X3:r,Grid3x2:i9,Grid3x3:r,Grip:e9,GripHorizontal:n9,GripVertical:l9,Group:r9,Guitar:v9,Ham:o9,Hamburger:$9,Hammer:m9,Hand:A9,HandCoins:y9,HandFist:s9,HandGrab:t2,HandHeart:g9,HandHelping:h2,HandMetal:u9,HandPlatter:C9,Handbag:H9,Handshake:w9,HardDrive:f9,HardDriveDownload:V9,HardDriveUpload:S9,HardHat:L9,Hash:k9,HatGlasses:P9,Haze:D9,HdmiPort:B9,Heading:U9,Heading1:F9,Heading2:z9,Heading3:R9,Heading4:b9,Heading5:T9,Heading6:q9,HeadphoneOff:O9,Headphones:Z9,Headset:G9,Heart:K9,HeartCrack:I9,HeartHandshake:W9,HeartMinus:E9,HeartOff:X9,HeartPlus:j9,HeartPulse:N9,Heater:Q9,HelpCircle:l,HelpingHand:h2,Hexagon:J9,Highlighter:Y9,History:_9,Home:d2,Hop:ap,HopOff:x9,Hospital:tp,Hotel:hp,Hourglass:dp,House:d2,HouseHeart:cp,HousePlug:Mp,HousePlus:pp,HouseWifi:ip,IceCream:c2,IceCream2:M2,IceCreamBowl:M2,IceCreamCone:c2,IdCard:lp,IdCardLanyard:np,Image:sp,ImageDown:ep,ImageMinus:rp,ImageOff:op,ImagePlay:vp,ImagePlus:$p,ImageUp:mp,ImageUpscale:yp,Images:gp,Import:up,Inbox:Hp,Indent:v,IndentDecrease:o,IndentIncrease:v,IndianRupee:Cp,Infinity:Ap,Info:wp,Inspect:H0,InspectionPanel:Vp,Instagram:Sp,Italic:Lp,IterationCcw:fp,IterationCw:kp,JapaneseYen:Pp,Joystick:Bp,Kanban:Dp,KanbanSquare:y0,KanbanSquareDashed:l0,Kayak:zp,Key:Rp,KeyRound:Fp,KeySquare:bp,Keyboard:Up,KeyboardMusic:Tp,KeyboardOff:qp,Lamp:Ep,LampCeiling:Op,LampDesk:Zp,LampFloor:Gp,LampWallDown:Ip,LampWallUp:Wp,LandPlot:Xp,Landmark:jp,Languages:Np,Laptop:Qp,Laptop2:p2,LaptopMinimal:p2,LaptopMinimalCheck:Kp,Lasso:Yp,LassoSelect:Jp,Laugh:_p,Layers:i2,Layers2:xp,Layers3:i2,Layout:f2,LayoutDashboard:ai,LayoutGrid:ti,LayoutList:hi,LayoutPanelLeft:di,LayoutPanelTop:Mi,LayoutTemplate:ci,Leaf:pi,LeafyGreen:ii,Lectern:ni,LetterText:W0,Library:ei,LibraryBig:li,LibrarySquare:s0,LifeBuoy:ri,Ligature:vi,Lightbulb:$i,LightbulbOff:oi,LineChart:Z,LineSquiggle:mi,Link:gi,Link2:si,Link2Off:yi,Linkedin:ui,List:qi,ListCheck:Ci,ListChecks:Hi,ListChevronsDownUp:Ai,ListChevronsUpDown:wi,ListCollapse:Vi,ListEnd:Si,ListFilter:fi,ListFilterPlus:Li,ListIndentDecrease:o,ListIndentIncrease:v,ListMinus:ki,ListMusic:Pi,ListOrdered:Bi,ListPlus:Di,ListRestart:Fi,ListStart:zi,ListTodo:bi,ListTree:Ti,ListVideo:Ri,ListX:Ui,Loader:Zi,Loader2:n2,LoaderCircle:n2,LoaderPinwheel:Oi,Locate:Wi,LocateFixed:Ii,LocateOff:Gi,LocationEdit:o2,Lock:Xi,LockKeyhole:Ei,LockKeyholeOpen:l2,LockOpen:e2,LogIn:Ni,LogOut:ji,Logs:Ki,Lollipop:Qi,Luggage:Ji,MSquare:g0,Magnet:Yi,Mail:Mn,MailCheck:_i,MailMinus:xi,MailOpen:an,MailPlus:tn,MailQuestion:r2,MailQuestionMark:r2,MailSearch:hn,MailWarning:dn,MailX:cn,Mailbox:pn,Mails:nn,Map:wn,MapMinus:ln,MapPin:Cn,MapPinCheck:rn,MapPinCheckInside:en,MapPinHouse:on,MapPinMinus:$n,MapPinMinusInside:vn,MapPinOff:mn,MapPinPen:o2,MapPinPlus:gn,MapPinPlusInside:yn,MapPinX:un,MapPinXInside:sn,MapPinned:Hn,MapPlus:An,Mars:Sn,MarsStroke:Vn,Martini:Ln,Maximize:kn,Maximize2:fn,Medal:Pn,Megaphone:Dn,MegaphoneOff:Bn,Meh:Fn,MemoryStick:zn,Menu:bn,MenuSquare:u0,Merge:Rn,MessageCircle:Xn,MessageCircleCode:Tn,MessageCircleDashed:qn,MessageCircleHeart:Un,MessageCircleMore:On,MessageCircleOff:Zn,MessageCirclePlus:Gn,MessageCircleQuestion:v2,MessageCircleQuestionMark:v2,MessageCircleReply:In,MessageCircleWarning:Wn,MessageCircleX:En,MessageSquare:il,MessageSquareCode:jn,MessageSquareDashed:Nn,MessageSquareDiff:Kn,MessageSquareDot:Qn,MessageSquareHeart:Jn,MessageSquareLock:_n,MessageSquareMore:Yn,MessageSquareOff:xn,MessageSquarePlus:al,MessageSquareQuote:tl,MessageSquareReply:hl,MessageSquareShare:dl,MessageSquareText:cl,MessageSquareWarning:Ml,MessageSquareX:pl,MessagesSquare:nl,Mic:el,Mic2:$2,MicOff:ll,MicVocal:$2,Microchip:rl,Microscope:ol,Microwave:vl,Milestone:$l,Milk:yl,MilkOff:ml,Minimize:gl,Minimize2:sl,Minus:ul,MinusCircle:e1,MinusSquare:C0,Monitor:zl,MonitorCheck:Cl,MonitorCog:Hl,MonitorDot:Al,MonitorDown:wl,MonitorOff:Vl,MonitorPause:Sl,MonitorPlay:Ll,MonitorSmartphone:fl,MonitorSpeaker:kl,MonitorStop:Pl,MonitorUp:Bl,MonitorX:Dl,Moon:bl,MoonStar:Fl,MoreHorizontal:b1,MoreVertical:z1,Motorbike:Rl,Mountain:ql,MountainSnow:Tl,Mouse:Wl,MouseOff:Ul,MousePointer:Il,MousePointer2:Ol,MousePointerBan:Zl,MousePointerClick:Gl,MousePointerSquareDashed:e0,Move:he,Move3D:m2,Move3d:m2,MoveDiagonal:Xl,MoveDiagonal2:El,MoveDown:Kl,MoveDownLeft:jl,MoveDownRight:Nl,MoveHorizontal:Ql,MoveLeft:Jl,MoveRight:Yl,MoveUp:ae,MoveUpLeft:xl,MoveUpRight:_l,MoveVertical:te,Music:pe,Music2:de,Music3:ce,Music4:Me,Navigation:ee,Navigation2:ne,Navigation2Off:ie,NavigationOff:le,Network:re,Newspaper:oe,Nfc:ve,NonBinary:$e,Notebook:ge,NotebookPen:me,NotebookTabs:ye,NotebookText:se,NotepadText:Ce,NotepadTextDashed:ue,Nut:Ae,NutOff:He,Octagon:Ve,OctagonAlert:y2,OctagonMinus:we,OctagonPause:s2,OctagonX:g2,Omega:Se,Option:fe,Orbit:Le,Origami:ke,Outdent:o,Package:Te,Package2:Pe,PackageCheck:Be,PackageMinus:De,PackageOpen:ze,PackagePlus:Fe,PackageSearch:be,PackageX:Re,PaintBucket:qe,PaintRoller:Ue,Paintbrush:Oe,Paintbrush2:u2,PaintbrushVertical:u2,Palette:Ze,Palmtree:N0,Panda:Ge,PanelBottom:Ee,PanelBottomClose:Ie,PanelBottomDashed:C2,PanelBottomInactive:C2,PanelBottomOpen:We,PanelLeft:V2,PanelLeftClose:H2,PanelLeftDashed:A2,PanelLeftInactive:A2,PanelLeftOpen:w2,PanelLeftRightDashed:Xe,PanelRight:Ke,PanelRightClose:je,PanelRightDashed:S2,PanelRightInactive:S2,PanelRightOpen:Ne,PanelTop:_e,PanelTopBottomDashed:Qe,PanelTopClose:Je,PanelTopDashed:L2,PanelTopInactive:L2,PanelTopOpen:Ye,PanelsLeftBottom:xe,PanelsLeftRight:P1,PanelsRightBottom:ar,PanelsTopBottom:b2,PanelsTopLeft:f2,Paperclip:hr,Parentheses:tr,ParkingCircle:o1,ParkingCircleOff:r1,ParkingMeter:dr,ParkingSquare:A0,ParkingSquareOff:w0,PartyPopper:cr,Pause:Mr,PauseCircle:v1,PauseOctagon:s2,PawPrint:pr,PcCase:nr,Pen:P2,PenBox:p,PenLine:k2,PenOff:ir,PenSquare:p,PenTool:lr,Pencil:vr,PencilLine:er,PencilOff:rr,PencilRuler:or,Pentagon:$r,Percent:mr,PercentCircle:$1,PercentDiamond:D1,PercentSquare:V0,PersonStanding:yr,PhilippinePeso:sr,Phone:Vr,PhoneCall:gr,PhoneForwarded:ur,PhoneIncoming:Cr,PhoneMissed:Hr,PhoneOff:Ar,PhoneOutgoing:wr,Pi:Sr,PiSquare:S0,Piano:Lr,Pickaxe:fr,PictureInPicture:Pr,PictureInPicture2:kr,PieChart:X,PiggyBank:Br,Pilcrow:zr,PilcrowLeft:Dr,PilcrowRight:Fr,PilcrowSquare:L0,Pill:Rr,PillBottle:br,Pin:qr,PinOff:Tr,Pipette:Ur,Pizza:Or,Plane:Ir,PlaneLanding:Zr,PlaneTakeoff:Gr,Play:Wr,PlayCircle:m1,PlaySquare:f0,Plug:Xr,Plug2:Er,PlugZap:B2,PlugZap2:B2,Plus:jr,PlusCircle:y1,PlusSquare:k0,Pocket:Kr,PocketKnife:Nr,Podcast:Yr,Pointer:Jr,PointerOff:Qr,Popcorn:_r,Popsicle:xr,PoundSterling:ao,Power:ho,PowerCircle:s1,PowerOff:to,PowerSquare:P0,Presentation:co,Printer:po,PrinterCheck:Mo,Projector:io,Proportions:no,Puzzle:lo,Pyramid:eo,QrCode:ro,Quote:oo,Rabbit:vo,Radar:$o,Radiation:mo,Radical:yo,Radio:uo,RadioReceiver:so,RadioTower:go,Radius:Ho,RailSymbol:Co,Rainbow:Ao,Rat:wo,Ratio:Vo,Receipt:zo,ReceiptCent:So,ReceiptEuro:Lo,ReceiptIndianRupee:fo,ReceiptJapaneseYen:ko,ReceiptPoundSterling:Po,ReceiptRussianRuble:Bo,ReceiptSwissFranc:Do,ReceiptText:Fo,ReceiptTurkishLira:bo,RectangleCircle:Ro,RectangleEllipsis:D2,RectangleGoggles:To,RectangleHorizontal:qo,RectangleVertical:Oo,Recycle:Uo,Redo:Io,Redo2:Zo,RedoDot:Go,RefreshCcw:Wo,RefreshCcwDot:Eo,RefreshCw:jo,RefreshCwOff:Xo,Refrigerator:No,Regex:Ko,RemoveFormatting:Qo,Repeat:_o,Repeat1:Yo,Repeat2:Jo,Replace:av,ReplaceAll:xo,Reply:hv,ReplyAll:tv,Rewind:dv,Ribbon:cv,Rocket:Mv,RockingChair:pv,RollerCoaster:iv,Rose:nv,Rotate3D:F2,Rotate3d:F2,RotateCcw:ev,RotateCcwKey:lv,RotateCcwSquare:ov,RotateCw:$v,RotateCwSquare:rv,Route:mv,RouteOff:vv,Router:yv,Rows:z2,Rows2:z2,Rows3:b2,Rows4:sv,Rss:gv,Ruler:Cv,RulerDimensionLine:uv,RussianRuble:Hv,Sailboat:Av,Salad:wv,Sandwich:Vv,Satellite:Lv,SatelliteDish:Sv,SaudiRiyal:fv,Save:Bv,SaveAll:kv,SaveOff:Pv,Scale:Dv,Scale3D:R2,Scale3d:R2,Scaling:Fv,Scan:Gv,ScanBarcode:zv,ScanEye:bv,ScanFace:Rv,ScanHeart:Tv,ScanLine:qv,ScanQrCode:Uv,ScanSearch:Ov,ScanText:Zv,ScatterChart:E,School:Iv,School2:J0,Scissors:Ev,ScissorsLineDashed:Wv,ScissorsSquare:B0,ScissorsSquareDashedBottom:t0,ScreenShare:jv,ScreenShareOff:Xv,Scroll:Kv,ScrollText:Nv,Search:xv,SearchCheck:Qv,SearchCode:Jv,SearchSlash:Yv,SearchX:_v,Section:a$,Send:h$,SendHorizonal:T2,SendHorizontal:T2,SendToBack:t$,SeparatorHorizontal:d$,SeparatorVertical:c$,Server:n$,ServerCog:M$,ServerCrash:p$,ServerOff:i$,Settings:e$,Settings2:l$,Shapes:o$,Share:v$,Share2:r$,Sheet:$$,Shell:m$,Shield:S$,ShieldAlert:y$,ShieldBan:s$,ShieldCheck:g$,ShieldClose:U2,ShieldEllipsis:u$,ShieldHalf:C$,ShieldMinus:H$,ShieldOff:A$,ShieldPlus:w$,ShieldQuestion:q2,ShieldQuestionMark:q2,ShieldUser:V$,ShieldX:U2,Ship:f$,ShipWheel:L$,Shirt:k$,ShoppingBag:P$,ShoppingBasket:B$,ShoppingCart:D$,Shovel:F$,ShowerHead:z$,Shredder:b$,Shrimp:R$,Shrink:T$,Shrub:q$,Shuffle:U$,Sidebar:V2,SidebarClose:H2,SidebarOpen:w2,Sigma:O$,SigmaSquare:D0,Signal:E$,SignalHigh:Z$,SignalLow:G$,SignalMedium:I$,SignalZero:W$,Signature:X$,Signpost:N$,SignpostBig:j$,Siren:K$,SkipBack:Q$,SkipForward:J$,Skull:Y$,Slack:_$,Slash:x$,SlashSquare:F0,Slice:am,Sliders:O2,SlidersHorizontal:tm,SlidersVertical:O2,Smartphone:cm,SmartphoneCharging:hm,SmartphoneNfc:dm,Smile:pm,SmilePlus:Mm,Snail:im,Snowflake:nm,SoapDispenserDroplet:em,Sofa:lm,SortAsc:w,SortDesc:C,Soup:rm,Space:om,Spade:vm,Sparkle:$m,Sparkles:Z2,Speaker:mm,Speech:ym,SpellCheck:gm,SpellCheck2:sm,Spline:Cm,SplinePointer:um,Split:Hm,SplitSquareHorizontal:z0,SplitSquareVertical:b0,Spool:Am,Spotlight:wm,SprayCan:Vm,Sprout:Sm,Square:Tm,SquareActivity:G2,SquareArrowDown:E2,SquareArrowDownLeft:I2,SquareArrowDownRight:W2,SquareArrowLeft:X2,SquareArrowOutDownLeft:j2,SquareArrowOutDownRight:N2,SquareArrowOutUpLeft:K2,SquareArrowOutUpRight:Q2,SquareArrowRight:J2,SquareArrowUp:x2,SquareArrowUpLeft:Y2,SquareArrowUpRight:_2,SquareAsterisk:a0,SquareBottomDashedScissors:t0,SquareChartGantt:$,SquareCheck:d0,SquareCheckBig:h0,SquareChevronDown:c0,SquareChevronLeft:M0,SquareChevronRight:p0,SquareChevronUp:i0,SquareCode:n0,SquareDashed:r0,SquareDashedBottom:fm,SquareDashedBottomCode:Lm,SquareDashedKanban:l0,SquareDashedMousePointer:e0,SquareDashedTopSolid:km,SquareDivide:o0,SquareDot:v0,SquareEqual:$0,SquareFunction:m0,SquareGanttChart:$,SquareKanban:y0,SquareLibrary:s0,SquareM:g0,SquareMenu:u0,SquareMinus:C0,SquareMousePointer:H0,SquareParking:A0,SquareParkingOff:w0,SquarePause:Pm,SquarePen:p,SquarePercent:V0,SquarePi:S0,SquarePilcrow:L0,SquarePlay:f0,SquarePlus:k0,SquarePower:P0,SquareRadical:Bm,SquareRoundCorner:Dm,SquareScissors:B0,SquareSigma:D0,SquareSlash:F0,SquareSplitHorizontal:z0,SquareSplitVertical:b0,SquareSquare:Fm,SquareStack:zm,SquareStar:bm,SquareStop:Rm,SquareTerminal:R0,SquareUser:q0,SquareUserRound:T0,SquareX:U0,SquaresExclude:qm,SquaresIntersect:Um,SquaresSubtract:Om,SquaresUnite:Zm,Squircle:Gm,SquircleDashed:Im,Squirrel:Wm,Stamp:Em,Star:Nm,StarHalf:Xm,StarOff:jm,Stars:Z2,StepBack:Km,StepForward:Jm,Stethoscope:Qm,Sticker:Ym,StickyNote:_m,StopCircle:u1,Store:xm,StretchHorizontal:ay,StretchVertical:ty,Strikethrough:hy,Subscript:dy,Subtitles:F,Sun:ny,SunDim:cy,SunMedium:My,SunMoon:py,SunSnow:iy,Sunrise:ly,Sunset:ey,Superscript:oy,SwatchBook:ry,SwissFranc:vy,SwitchCamera:$y,Sword:my,Swords:yy,Syringe:sy,Table:Sy,Table2:gy,TableCellsMerge:uy,TableCellsSplit:Hy,TableColumnsSplit:Cy,TableConfig:e,TableOfContents:wy,TableProperties:Ay,TableRowsSplit:Vy,Tablet:fy,TabletSmartphone:Ly,Tablets:ky,Tag:Py,Tags:Dy,Tally1:By,Tally2:Fy,Tally3:zy,Tally4:by,Tally5:Ry,Tangent:Ty,Target:qy,Telescope:Uy,Tent:Zy,TentTree:Oy,Terminal:Gy,TerminalSquare:R0,TestTube:Iy,TestTube2:O0,TestTubeDiagonal:O0,TestTubes:Wy,Text:m,TextAlignCenter:Z0,TextAlignEnd:G0,TextAlignJustify:I0,TextAlignStart:m,TextCursor:Xy,TextCursorInput:Ey,TextInitial:W0,TextQuote:jy,TextSearch:Ny,TextSelect:E0,TextSelection:E0,TextWrap:X0,Theater:Ky,Thermometer:Yy,ThermometerSnowflake:Qy,ThermometerSun:Jy,ThumbsDown:_y,ThumbsUp:xy,Ticket:Ms,TicketCheck:as,TicketMinus:ts,TicketPercent:hs,TicketPlus:ds,TicketSlash:ps,TicketX:cs,Tickets:ns,TicketsPlane:is,Timer:rs,TimerOff:ls,TimerReset:es,ToggleLeft:os,ToggleRight:vs,Toilet:$s,ToolCase:ys,Tornado:ms,Torus:ss,Touchpad:us,TouchpadOff:gs,TowerControl:Hs,ToyBrick:Cs,Tractor:As,TrafficCone:ws,Train:j0,TrainFront:Ss,TrainFrontTunnel:Vs,TrainTrack:Ls,TramFront:j0,Transgender:fs,Trash:Ps,Trash2:ks,TreeDeciduous:Bs,TreePalm:N0,TreePine:Ds,Trees:Fs,Trello:bs,TrendingDown:zs,TrendingUp:Ts,TrendingUpDown:Rs,Triangle:Os,TriangleAlert:K0,TriangleDashed:qs,TriangleRight:Us,Trophy:Zs,Truck:Is,TruckElectric:Gs,TurkishLira:Es,Turntable:Ws,Turtle:Xs,Tv:Ns,Tv2:Q0,TvMinimal:Q0,TvMinimalPlay:js,Twitch:Ks,Twitter:Qs,Type:Ys,TypeOutline:Js,Umbrella:xs,UmbrellaOff:_s,Underline:ag,Undo:dg,Undo2:tg,UndoDot:hg,UnfoldHorizontal:cg,UnfoldVertical:Mg,Ungroup:pg,University:J0,Unlink:lg,Unlink2:ig,Unlock:e2,UnlockKeyhole:l2,Unplug:ng,Upload:eg,UploadCloud:L1,Usb:rg,User:wg,User2:ha,UserCheck:og,UserCheck2:_0,UserCircle:H1,UserCircle2:C1,UserCog:vg,UserCog2:Y0,UserLock:$g,UserMinus:mg,UserMinus2:x0,UserPen:yg,UserPlus:sg,UserPlus2:aa,UserRound:ha,UserRoundCheck:_0,UserRoundCog:Y0,UserRoundMinus:x0,UserRoundPen:gg,UserRoundPlus:aa,UserRoundSearch:ug,UserRoundX:ta,UserSearch:Cg,UserSquare:q0,UserSquare2:T0,UserStar:Hg,UserX:Ag,UserX2:ta,Users:Vg,Users2:da,UsersRound:da,Utensils:Ma,UtensilsCrossed:ca,UtilityPole:Sg,Variable:Lg,Vault:kg,VectorSquare:fg,Vegan:Pg,VenetianMask:Bg,Venus:Fg,VenusAndMars:Dg,Verified:L,Vibrate:bg,VibrateOff:zg,Video:Tg,VideoOff:Rg,Videotape:qg,View:Ug,Voicemail:Og,Volleyball:Zg,Volume:Xg,Volume1:Gg,Volume2:Ig,VolumeOff:Wg,VolumeX:Eg,Vote:jg,Wallet:Kg,Wallet2:pa,WalletCards:Ng,WalletMinimal:pa,Wallpaper:Qg,Wand:Jg,Wand2:ia,WandSparkles:ia,Warehouse:Yg,WashingMachine:_g,Watch:xg,Waves:tu,WavesLadder:au,Waypoints:hu,Webcam:du,Webhook:pu,WebhookOff:Mu,Weight:cu,Wheat:nu,WheatOff:iu,WholeWord:lu,Wifi:su,WifiCog:eu,WifiHigh:ru,WifiLow:ou,WifiOff:mu,WifiPen:vu,WifiSync:$u,WifiZero:yu,Wind:uu,WindArrowDown:gu,Wine:Hu,WineOff:Cu,Workflow:Au,Worm:wu,WrapText:X0,Wrench:Vu,X:Su,XCircle:A1,XOctagon:g2,XSquare:U0,Youtube:Lu,Zap:ku,ZapOff:fu,ZoomIn:Pu,ZoomOut:Bu});const Ou=({icons:t=Du,nameAttr:h="data-lucide",attrs:d={},root:c=document}={})=>{if(!Object.values(t).length)throw new Error(`Please provide an icons object. -If you want to use all the icons you can import it like: - \`import { createIcons, icons } from 'lucide'; -lucide.createIcons({icons});\``);if(typeof c>"u")throw new Error("`createIcons()` only works in a browser environment.");const M=c.querySelectorAll(`[${h}]`);if(Array.from(M).forEach(i=>ra(i,{nameAttr:h,icons:t,attrs:d})),h==="data-lucide"){const i=c.querySelectorAll("[icon-name]");i.length>0&&(console.warn("[Lucide] Some icons were found with the now deprecated icon-name attribute. These will still be replaced for backwards compatibility, but will no longer be supported in v1.0 and you should switch to data-lucide"),Array.from(i).forEach(na=>ra(na,{nameAttr:"icon-name",icons:t,attrs:d})))}};a.AArrowDown=oa,a.AArrowUp=va,a.ALargeSmall=$a,a.Accessibility=ma,a.Activity=ya,a.ActivitySquare=G2,a.AirVent=sa,a.Airplay=ga,a.AlarmCheck=y,a.AlarmClock=Ca,a.AlarmClockCheck=y,a.AlarmClockMinus=s,a.AlarmClockOff=ua,a.AlarmClockPlus=g,a.AlarmMinus=s,a.AlarmPlus=g,a.AlarmSmoke=Ha,a.Album=Aa,a.AlertCircle=N,a.AlertOctagon=y2,a.AlertTriangle=K0,a.AlignCenter=Z0,a.AlignCenterHorizontal=wa,a.AlignCenterVertical=Va,a.AlignEndHorizontal=Sa,a.AlignEndVertical=La,a.AlignHorizontalDistributeCenter=fa,a.AlignHorizontalDistributeEnd=ka,a.AlignHorizontalDistributeStart=Pa,a.AlignHorizontalJustifyCenter=Ba,a.AlignHorizontalJustifyEnd=Da,a.AlignHorizontalJustifyStart=Fa,a.AlignHorizontalSpaceAround=za,a.AlignHorizontalSpaceBetween=ba,a.AlignJustify=I0,a.AlignLeft=m,a.AlignRight=G0,a.AlignStartHorizontal=Ra,a.AlignStartVertical=Ta,a.AlignVerticalDistributeCenter=qa,a.AlignVerticalDistributeEnd=Ua,a.AlignVerticalDistributeStart=Oa,a.AlignVerticalJustifyCenter=Za,a.AlignVerticalJustifyEnd=Ga,a.AlignVerticalJustifyStart=Ia,a.AlignVerticalSpaceAround=Wa,a.AlignVerticalSpaceBetween=Ea,a.Ambulance=ja,a.Ampersand=Xa,a.Ampersands=Na,a.Amphora=Ka,a.Anchor=Qa,a.Angry=Ja,a.Annoyed=Ya,a.Antenna=_a,a.Anvil=xa,a.Aperture=at,a.AppWindow=ht,a.AppWindowMac=tt,a.Apple=dt,a.Archive=pt,a.ArchiveRestore=ct,a.ArchiveX=Mt,a.AreaChart=z,a.Armchair=it,a.ArrowBigDown=lt,a.ArrowBigDownDash=nt,a.ArrowBigLeft=rt,a.ArrowBigLeftDash=et,a.ArrowBigRight=vt,a.ArrowBigRightDash=ot,a.ArrowBigUp=st,a.ArrowBigUpDash=$t,a.ArrowDown=St,a.ArrowDown01=mt,a.ArrowDown10=yt,a.ArrowDownAZ=u,a.ArrowDownAz=u,a.ArrowDownCircle=K,a.ArrowDownFromLine=gt,a.ArrowDownLeft=Ct,a.ArrowDownLeftFromCircle=J,a.ArrowDownLeftFromSquare=j2,a.ArrowDownLeftSquare=I2,a.ArrowDownNarrowWide=ut,a.ArrowDownRight=At,a.ArrowDownRightFromCircle=_,a.ArrowDownRightFromSquare=N2,a.ArrowDownRightSquare=W2,a.ArrowDownSquare=E2,a.ArrowDownToDot=Ht,a.ArrowDownToLine=wt,a.ArrowDownUp=Vt,a.ArrowDownWideNarrow=C,a.ArrowDownZA=H,a.ArrowDownZa=H,a.ArrowLeft=Pt,a.ArrowLeftCircle=Q,a.ArrowLeftFromLine=Lt,a.ArrowLeftRight=ft,a.ArrowLeftSquare=X2,a.ArrowLeftToLine=kt,a.ArrowRight=zt,a.ArrowRightCircle=a1,a.ArrowRightFromLine=Bt,a.ArrowRightLeft=Ft,a.ArrowRightSquare=J2,a.ArrowRightToLine=Dt,a.ArrowUp=Wt,a.ArrowUp01=bt,a.ArrowUp10=Rt,a.ArrowUpAZ=A,a.ArrowUpAz=A,a.ArrowUpCircle=t1,a.ArrowUpDown=Tt,a.ArrowUpFromDot=Ut,a.ArrowUpFromLine=qt,a.ArrowUpLeft=Ot,a.ArrowUpLeftFromCircle=Y,a.ArrowUpLeftFromSquare=K2,a.ArrowUpLeftSquare=Y2,a.ArrowUpNarrowWide=w,a.ArrowUpRight=Zt,a.ArrowUpRightFromCircle=x,a.ArrowUpRightFromSquare=Q2,a.ArrowUpRightSquare=_2,a.ArrowUpSquare=x2,a.ArrowUpToLine=It,a.ArrowUpWideNarrow=Gt,a.ArrowUpZA=V,a.ArrowUpZa=V,a.ArrowsUpFromLine=Et,a.Asterisk=Xt,a.AsteriskSquare=a0,a.AtSign=jt,a.Atom=Qt,a.AudioLines=Nt,a.AudioWaveform=Kt,a.Award=Jt,a.Axe=Yt,a.Axis3D=S,a.Axis3d=S,a.Baby=_t,a.Backpack=xt,a.Badge=mh,a.BadgeAlert=ah,a.BadgeCent=th,a.BadgeCheck=L,a.BadgeDollarSign=hh,a.BadgeEuro=dh,a.BadgeHelp=f,a.BadgeIndianRupee=ch,a.BadgeInfo=Mh,a.BadgeJapaneseYen=ph,a.BadgeMinus=ih,a.BadgePercent=nh,a.BadgePlus=lh,a.BadgePoundSterling=eh,a.BadgeQuestionMark=f,a.BadgeRussianRuble=rh,a.BadgeSwissFranc=oh,a.BadgeTurkishLira=vh,a.BadgeX=$h,a.BaggageClaim=yh,a.Ban=sh,a.Banana=gh,a.Bandage=uh,a.Banknote=wh,a.BanknoteArrowDown=Ch,a.BanknoteArrowUp=Hh,a.BanknoteX=Ah,a.BarChart=G,a.BarChart2=I,a.BarChart3=O,a.BarChart4=U,a.BarChartBig=q,a.BarChartHorizontal=T,a.BarChartHorizontalBig=b,a.Barcode=Vh,a.Barrel=Sh,a.Baseline=Lh,a.Bath=fh,a.Battery=bh,a.BatteryCharging=kh,a.BatteryFull=Ph,a.BatteryLow=Bh,a.BatteryMedium=Dh,a.BatteryPlus=Fh,a.BatteryWarning=zh,a.Beaker=Rh,a.Bean=qh,a.BeanOff=Th,a.Bed=Zh,a.BedDouble=Uh,a.BedSingle=Oh,a.Beef=Gh,a.Beer=Wh,a.BeerOff=Ih,a.Bell=Jh,a.BellDot=Eh,a.BellElectric=Xh,a.BellMinus=jh,a.BellOff=Nh,a.BellPlus=Kh,a.BellRing=Qh,a.BetweenHorizonalEnd=k,a.BetweenHorizonalStart=P,a.BetweenHorizontalEnd=k,a.BetweenHorizontalStart=P,a.BetweenVerticalEnd=Yh,a.BetweenVerticalStart=_h,a.BicepsFlexed=xh,a.Bike=a4,a.Binary=t4,a.Binoculars=h4,a.Biohazard=d4,a.Bird=c4,a.Bitcoin=p4,a.Blend=M4,a.Blinds=n4,a.Blocks=i4,a.Bluetooth=r4,a.BluetoothConnected=l4,a.BluetoothOff=o4,a.BluetoothSearching=e4,a.Bold=v4,a.Bolt=$4,a.Bomb=m4,a.Bone=y4,a.Book=Z4,a.BookA=s4,a.BookAlert=g4,a.BookAudio=u4,a.BookCheck=C4,a.BookCopy=H4,a.BookDashed=B,a.BookDown=A4,a.BookHeadphones=w4,a.BookHeart=V4,a.BookImage=S4,a.BookKey=L4,a.BookLock=f4,a.BookMarked=k4,a.BookMinus=P4,a.BookOpen=F4,a.BookOpenCheck=B4,a.BookOpenText=D4,a.BookPlus=z4,a.BookTemplate=B,a.BookText=b4,a.BookType=T4,a.BookUp=q4,a.BookUp2=R4,a.BookUser=U4,a.BookX=O4,a.Bookmark=X4,a.BookmarkCheck=G4,a.BookmarkMinus=I4,a.BookmarkPlus=W4,a.BookmarkX=E4,a.BoomBox=j4,a.Bot=Q4,a.BotMessageSquare=K4,a.BotOff=N4,a.BottleWine=J4,a.BowArrow=Y4,a.Box=_4,a.BoxSelect=r0,a.Boxes=x4,a.Braces=D,a.Brackets=a5,a.Brain=d5,a.BrainCircuit=t5,a.BrainCog=h5,a.BrickWall=p5,a.BrickWallFire=c5,a.BrickWallShield=M5,a.Briefcase=e5,a.BriefcaseBusiness=i5,a.BriefcaseConveyorBelt=n5,a.BriefcaseMedical=l5,a.BringToFront=r5,a.Brush=v5,a.BrushCleaning=o5,a.Bubbles=$5,a.Bug=s5,a.BugOff=m5,a.BugPlay=y5,a.Building=u5,a.Building2=g5,a.Bus=H5,a.BusFront=C5,a.Cable=w5,a.CableCar=A5,a.Cake=S5,a.CakeSlice=V5,a.Calculator=L5,a.Calendar=N5,a.Calendar1=f5,a.CalendarArrowDown=k5,a.CalendarArrowUp=P5,a.CalendarCheck=D5,a.CalendarCheck2=B5,a.CalendarClock=F5,a.CalendarCog=R5,a.CalendarDays=z5,a.CalendarFold=b5,a.CalendarHeart=T5,a.CalendarMinus=U5,a.CalendarMinus2=q5,a.CalendarOff=O5,a.CalendarPlus=Z5,a.CalendarPlus2=I5,a.CalendarRange=G5,a.CalendarSearch=E5,a.CalendarSync=W5,a.CalendarX=j5,a.CalendarX2=X5,a.Camera=Q5,a.CameraOff=K5,a.CandlestickChart=R,a.Candy=_5,a.CandyCane=J5,a.CandyOff=Y5,a.Cannabis=x5,a.Captions=F,a.CaptionsOff=a3,a.Car=d3,a.CarFront=t3,a.CarTaxiFront=h3,a.Caravan=c3,a.CardSim=M3,a.Carrot=p3,a.CaseLower=i3,a.CaseSensitive=n3,a.CaseUpper=l3,a.CassetteTape=e3,a.Cast=r3,a.Castle=o3,a.Cat=v3,a.Cctv=$3,a.ChartArea=z,a.ChartBar=T,a.ChartBarBig=b,a.ChartBarDecreasing=m3,a.ChartBarIncreasing=y3,a.ChartBarStacked=s3,a.ChartCandlestick=R,a.ChartColumn=O,a.ChartColumnBig=q,a.ChartColumnDecreasing=g3,a.ChartColumnIncreasing=U,a.ChartColumnStacked=u3,a.ChartGantt=C3,a.ChartLine=Z,a.ChartNetwork=H3,a.ChartNoAxesColumn=I,a.ChartNoAxesColumnDecreasing=A3,a.ChartNoAxesColumnIncreasing=G,a.ChartNoAxesCombined=w3,a.ChartNoAxesGantt=W,a.ChartPie=X,a.ChartScatter=E,a.ChartSpline=V3,a.Check=f3,a.CheckCheck=S3,a.CheckCircle=h1,a.CheckCircle2=d1,a.CheckLine=L3,a.CheckSquare=h0,a.CheckSquare2=d0,a.ChefHat=k3,a.Cherry=B3,a.ChevronDown=P3,a.ChevronDownCircle=c1,a.ChevronDownSquare=c0,a.ChevronFirst=D3,a.ChevronLast=F3,a.ChevronLeft=z3,a.ChevronLeftCircle=M1,a.ChevronLeftSquare=M0,a.ChevronRight=b3,a.ChevronRightCircle=p1,a.ChevronRightSquare=p0,a.ChevronUp=R3,a.ChevronUpCircle=i1,a.ChevronUpSquare=i0,a.ChevronsDown=q3,a.ChevronsDownUp=T3,a.ChevronsLeft=Z3,a.ChevronsLeftRight=O3,a.ChevronsLeftRightEllipsis=U3,a.ChevronsRight=I3,a.ChevronsRightLeft=G3,a.ChevronsUp=E3,a.ChevronsUpDown=W3,a.Chrome=j,a.Chromium=j,a.Church=X3,a.Cigarette=N3,a.CigaretteOff=j3,a.Circle=id,a.CircleAlert=N,a.CircleArrowDown=K,a.CircleArrowLeft=Q,a.CircleArrowOutDownLeft=J,a.CircleArrowOutDownRight=_,a.CircleArrowOutUpLeft=Y,a.CircleArrowOutUpRight=x,a.CircleArrowRight=a1,a.CircleArrowUp=t1,a.CircleCheck=d1,a.CircleCheckBig=h1,a.CircleChevronDown=c1,a.CircleChevronLeft=M1,a.CircleChevronRight=p1,a.CircleChevronUp=i1,a.CircleDashed=K3,a.CircleDivide=n1,a.CircleDollarSign=Q3,a.CircleDot=Y3,a.CircleDotDashed=J3,a.CircleEllipsis=_3,a.CircleEqual=x3,a.CircleFadingArrowUp=ad,a.CircleFadingPlus=td,a.CircleGauge=l1,a.CircleHelp=l,a.CircleMinus=e1,a.CircleOff=hd,a.CircleParking=o1,a.CircleParkingOff=r1,a.CirclePause=v1,a.CirclePercent=$1,a.CirclePlay=m1,a.CirclePlus=y1,a.CirclePoundSterling=dd,a.CirclePower=s1,a.CircleQuestionMark=l,a.CircleSlash=cd,a.CircleSlash2=g1,a.CircleSlashed=g1,a.CircleSmall=Md,a.CircleStar=pd,a.CircleStop=u1,a.CircleUser=H1,a.CircleUserRound=C1,a.CircleX=A1,a.CircuitBoard=nd,a.Citrus=ld,a.Clapperboard=ed,a.Clipboard=Cd,a.ClipboardCheck=rd,a.ClipboardClock=od,a.ClipboardCopy=vd,a.ClipboardEdit=V1,a.ClipboardList=$d,a.ClipboardMinus=md,a.ClipboardPaste=yd,a.ClipboardPen=V1,a.ClipboardPenLine=w1,a.ClipboardPlus=sd,a.ClipboardSignature=w1,a.ClipboardType=gd,a.ClipboardX=ud,a.Clock=Ud,a.Clock1=Hd,a.Clock10=Ad,a.Clock11=wd,a.Clock12=Vd,a.Clock2=Sd,a.Clock3=Ld,a.Clock4=fd,a.Clock5=kd,a.Clock6=Pd,a.Clock7=Bd,a.Clock8=Dd,a.Clock9=Fd,a.ClockAlert=zd,a.ClockArrowDown=bd,a.ClockArrowUp=Rd,a.ClockFading=Td,a.ClockPlus=qd,a.ClosedCaption=Od,a.Cloud=t6,a.CloudAlert=Zd,a.CloudCheck=Gd,a.CloudCog=Id,a.CloudDownload=S1,a.CloudDrizzle=Wd,a.CloudFog=Ed,a.CloudHail=Xd,a.CloudLightning=Nd,a.CloudMoon=Kd,a.CloudMoonRain=jd,a.CloudOff=Qd,a.CloudRain=Yd,a.CloudRainWind=Jd,a.CloudSnow=_d,a.CloudSun=a6,a.CloudSunRain=xd,a.CloudUpload=L1,a.Cloudy=h6,a.Clover=d6,a.Club=c6,a.Code=p6,a.Code2=f1,a.CodeSquare=n0,a.CodeXml=f1,a.Codepen=M6,a.Codesandbox=i6,a.Coffee=n6,a.Cog=l6,a.Coins=e6,a.Columns=k1,a.Columns2=k1,a.Columns3=P1,a.Columns3Cog=e,a.Columns4=r6,a.ColumnsSettings=e,a.Combine=o6,a.Command=v6,a.Compass=$6,a.Component=m6,a.Computer=y6,a.ConciergeBell=s6,a.Cone=g6,a.Construction=u6,a.Contact=C6,a.Contact2=B1,a.ContactRound=B1,a.Container=H6,a.Contrast=A6,a.Cookie=w6,a.CookingPot=V6,a.Copy=B6,a.CopyCheck=S6,a.CopyMinus=L6,a.CopyPlus=f6,a.CopySlash=k6,a.CopyX=P6,a.Copyleft=D6,a.Copyright=F6,a.CornerDownLeft=b6,a.CornerDownRight=z6,a.CornerLeftDown=R6,a.CornerLeftUp=T6,a.CornerRightDown=q6,a.CornerRightUp=U6,a.CornerUpLeft=G6,a.CornerUpRight=O6,a.Cpu=Z6,a.CreativeCommons=I6,a.CreditCard=W6,a.Croissant=E6,a.Crop=X6,a.Cross=j6,a.Crosshair=N6,a.Crown=K6,a.Cuboid=Q6,a.CupSoda=J6,a.CurlyBraces=D,a.Currency=Y6,a.Cylinder=_6,a.Dam=x6,a.Database=h8,a.DatabaseBackup=a8,a.DatabaseZap=t8,a.DecimalsArrowLeft=d8,a.DecimalsArrowRight=c8,a.Delete=M8,a.Dessert=p8,a.Diameter=i8,a.Diamond=e8,a.DiamondMinus=n8,a.DiamondPercent=D1,a.DiamondPlus=l8,a.Dice1=r8,a.Dice2=o8,a.Dice3=v8,a.Dice4=$8,a.Dice5=m8,a.Dice6=y8,a.Dices=s8,a.Diff=g8,a.Disc=A8,a.Disc2=u8,a.Disc3=C8,a.DiscAlbum=H8,a.Divide=w8,a.DivideCircle=n1,a.DivideSquare=o0,a.Dna=S8,a.DnaOff=V8,a.Dock=L8,a.Dog=f8,a.DollarSign=k8,a.Donut=P8,a.DoorClosed=D8,a.DoorClosedLocked=B8,a.DoorOpen=F8,a.Dot=z8,a.DotSquare=v0,a.Download=b8,a.DownloadCloud=S1,a.DraftingCompass=R8,a.Drama=T8,a.Dribbble=q8,a.Drill=U8,a.Drone=O8,a.Droplet=G8,a.DropletOff=Z8,a.Droplets=I8,a.Drum=W8,a.Drumstick=E8,a.Dumbbell=X8,a.Ear=j8,a.EarOff=N8,a.Earth=F1,a.EarthLock=K8,a.Eclipse=Q8,a.Edit=p,a.Edit2=P2,a.Edit3=k2,a.Egg=Y8,a.EggFried=J8,a.EggOff=_8,a.Ellipsis=b1,a.EllipsisVertical=z1,a.Equal=tc,a.EqualApproximately=x8,a.EqualNot=ac,a.EqualSquare=$0,a.Eraser=dc,a.EthernetPort=hc,a.Euro=cc,a.EvCharger=Mc,a.Expand=pc,a.ExternalLink=ic,a.Eye=ec,a.EyeClosed=nc,a.EyeOff=lc,a.Facebook=rc,a.Factory=oc,a.Fan=vc,a.FastForward=$c,a.Feather=mc,a.Fence=yc,a.FerrisWheel=sc,a.Figma=gc,a.File=o7,a.FileArchive=uc,a.FileAudio=Hc,a.FileAudio2=Cc,a.FileAxis3D=R1,a.FileAxis3d=R1,a.FileBadge=wc,a.FileBadge2=Ac,a.FileBarChart=T1,a.FileBarChart2=q1,a.FileBox=Vc,a.FileChartColumn=q1,a.FileChartColumnIncreasing=T1,a.FileChartLine=U1,a.FileChartPie=O1,a.FileCheck=Lc,a.FileCheck2=Sc,a.FileClock=fc,a.FileCode=Pc,a.FileCode2=kc,a.FileCog=Z1,a.FileCog2=Z1,a.FileDiff=Bc,a.FileDigit=Dc,a.FileDown=Fc,a.FileEdit=I1,a.FileHeart=zc,a.FileImage=bc,a.FileInput=Rc,a.FileJson=qc,a.FileJson2=Tc,a.FileKey=Oc,a.FileKey2=Uc,a.FileLineChart=U1,a.FileLock=Gc,a.FileLock2=Zc,a.FileMinus=Wc,a.FileMinus2=Ic,a.FileMusic=Ec,a.FileOutput=Xc,a.FilePen=I1,a.FilePenLine=G1,a.FilePieChart=O1,a.FilePlay=W1,a.FilePlus=Nc,a.FilePlus2=jc,a.FileQuestion=E1,a.FileQuestionMark=E1,a.FileScan=Kc,a.FileSearch=Jc,a.FileSearch2=Qc,a.FileSignature=G1,a.FileSliders=Yc,a.FileSpreadsheet=_c,a.FileStack=xc,a.FileSymlink=a7,a.FileTerminal=t7,a.FileText=h7,a.FileType=c7,a.FileType2=d7,a.FileUp=M7,a.FileUser=p7,a.FileVideo=W1,a.FileVideo2=X1,a.FileVideoCamera=X1,a.FileVolume=n7,a.FileVolume2=i7,a.FileWarning=l7,a.FileX=r7,a.FileX2=e7,a.Files=v7,a.Film=$7,a.Filter=K1,a.FilterX=Q1,a.Fingerprint=y7,a.FireExtinguisher=m7,a.Fish=u7,a.FishOff=s7,a.FishSymbol=g7,a.Flag=w7,a.FlagOff=C7,a.FlagTriangleLeft=H7,a.FlagTriangleRight=A7,a.Flame=S7,a.FlameKindling=V7,a.Flashlight=f7,a.FlashlightOff=L7,a.FlaskConical=P7,a.FlaskConicalOff=k7,a.FlaskRound=B7,a.FlipHorizontal=F7,a.FlipHorizontal2=D7,a.FlipVertical=b7,a.FlipVertical2=z7,a.Flower=T7,a.Flower2=R7,a.Focus=q7,a.FoldHorizontal=U7,a.FoldVertical=O7,a.Folder=vM,a.FolderArchive=G7,a.FolderCheck=Z7,a.FolderClock=I7,a.FolderClosed=E7,a.FolderCode=W7,a.FolderCog=j1,a.FolderCog2=j1,a.FolderDot=X7,a.FolderDown=j7,a.FolderEdit=N1,a.FolderGit=K7,a.FolderGit2=N7,a.FolderHeart=Q7,a.FolderInput=J7,a.FolderKanban=_7,a.FolderKey=Y7,a.FolderLock=aM,a.FolderMinus=x7,a.FolderOpen=hM,a.FolderOpenDot=tM,a.FolderOutput=dM,a.FolderPen=N1,a.FolderPlus=cM,a.FolderRoot=MM,a.FolderSearch=iM,a.FolderSearch2=pM,a.FolderSymlink=nM,a.FolderSync=lM,a.FolderTree=eM,a.FolderUp=rM,a.FolderX=oM,a.Folders=$M,a.Footprints=mM,a.ForkKnife=Ma,a.ForkKnifeCrossed=ca,a.Forklift=yM,a.FormInput=D2,a.Forward=sM,a.Frame=gM,a.Framer=uM,a.Frown=CM,a.Fuel=HM,a.Fullscreen=AM,a.FunctionSquare=m0,a.Funnel=K1,a.FunnelPlus=wM,a.FunnelX=Q1,a.GalleryHorizontal=SM,a.GalleryHorizontalEnd=VM,a.GalleryThumbnails=LM,a.GalleryVertical=kM,a.GalleryVerticalEnd=fM,a.Gamepad=BM,a.Gamepad2=PM,a.GanttChart=W,a.GanttChartSquare=$,a.Gauge=DM,a.GaugeCircle=l1,a.Gavel=FM,a.Gem=zM,a.GeorgianLari=bM,a.Ghost=qM,a.Gift=RM,a.GitBranch=UM,a.GitBranchPlus=TM,a.GitCommit=J1,a.GitCommitHorizontal=J1,a.GitCommitVertical=OM,a.GitCompare=GM,a.GitCompareArrows=ZM,a.GitFork=IM,a.GitGraph=WM,a.GitMerge=EM,a.GitPullRequest=JM,a.GitPullRequestArrow=XM,a.GitPullRequestClosed=jM,a.GitPullRequestCreate=KM,a.GitPullRequestCreateArrow=NM,a.GitPullRequestDraft=QM,a.Github=YM,a.Gitlab=_M,a.GlassWater=xM,a.Glasses=a9,a.Globe=t9,a.Globe2=F1,a.GlobeLock=h9,a.Goal=d9,a.Gpu=c9,a.Grab=t2,a.GraduationCap=M9,a.Grape=p9,a.Grid=r,a.Grid2X2=a2,a.Grid2X2Check=_1,a.Grid2X2Plus=Y1,a.Grid2X2X=x1,a.Grid2x2=a2,a.Grid2x2Check=_1,a.Grid2x2Plus=Y1,a.Grid2x2X=x1,a.Grid3X3=r,a.Grid3x2=i9,a.Grid3x3=r,a.Grip=e9,a.GripHorizontal=n9,a.GripVertical=l9,a.Group=r9,a.Guitar=v9,a.Ham=o9,a.Hamburger=$9,a.Hammer=m9,a.Hand=A9,a.HandCoins=y9,a.HandFist=s9,a.HandGrab=t2,a.HandHeart=g9,a.HandHelping=h2,a.HandMetal=u9,a.HandPlatter=C9,a.Handbag=H9,a.Handshake=w9,a.HardDrive=f9,a.HardDriveDownload=V9,a.HardDriveUpload=S9,a.HardHat=L9,a.Hash=k9,a.HatGlasses=P9,a.Haze=D9,a.HdmiPort=B9,a.Heading=U9,a.Heading1=F9,a.Heading2=z9,a.Heading3=R9,a.Heading4=b9,a.Heading5=T9,a.Heading6=q9,a.HeadphoneOff=O9,a.Headphones=Z9,a.Headset=G9,a.Heart=K9,a.HeartCrack=I9,a.HeartHandshake=W9,a.HeartMinus=E9,a.HeartOff=X9,a.HeartPlus=j9,a.HeartPulse=N9,a.Heater=Q9,a.HelpCircle=l,a.HelpingHand=h2,a.Hexagon=J9,a.Highlighter=Y9,a.History=_9,a.Home=d2,a.Hop=ap,a.HopOff=x9,a.Hospital=tp,a.Hotel=hp,a.Hourglass=dp,a.House=d2,a.HouseHeart=cp,a.HousePlug=Mp,a.HousePlus=pp,a.HouseWifi=ip,a.IceCream=c2,a.IceCream2=M2,a.IceCreamBowl=M2,a.IceCreamCone=c2,a.IdCard=lp,a.IdCardLanyard=np,a.Image=sp,a.ImageDown=ep,a.ImageMinus=rp,a.ImageOff=op,a.ImagePlay=vp,a.ImagePlus=$p,a.ImageUp=mp,a.ImageUpscale=yp,a.Images=gp,a.Import=up,a.Inbox=Hp,a.Indent=v,a.IndentDecrease=o,a.IndentIncrease=v,a.IndianRupee=Cp,a.Infinity=Ap,a.Info=wp,a.Inspect=H0,a.InspectionPanel=Vp,a.Instagram=Sp,a.Italic=Lp,a.IterationCcw=fp,a.IterationCw=kp,a.JapaneseYen=Pp,a.Joystick=Bp,a.Kanban=Dp,a.KanbanSquare=y0,a.KanbanSquareDashed=l0,a.Kayak=zp,a.Key=Rp,a.KeyRound=Fp,a.KeySquare=bp,a.Keyboard=Up,a.KeyboardMusic=Tp,a.KeyboardOff=qp,a.Lamp=Ep,a.LampCeiling=Op,a.LampDesk=Zp,a.LampFloor=Gp,a.LampWallDown=Ip,a.LampWallUp=Wp,a.LandPlot=Xp,a.Landmark=jp,a.Languages=Np,a.Laptop=Qp,a.Laptop2=p2,a.LaptopMinimal=p2,a.LaptopMinimalCheck=Kp,a.Lasso=Yp,a.LassoSelect=Jp,a.Laugh=_p,a.Layers=i2,a.Layers2=xp,a.Layers3=i2,a.Layout=f2,a.LayoutDashboard=ai,a.LayoutGrid=ti,a.LayoutList=hi,a.LayoutPanelLeft=di,a.LayoutPanelTop=Mi,a.LayoutTemplate=ci,a.Leaf=pi,a.LeafyGreen=ii,a.Lectern=ni,a.LetterText=W0,a.Library=ei,a.LibraryBig=li,a.LibrarySquare=s0,a.LifeBuoy=ri,a.Ligature=vi,a.Lightbulb=$i,a.LightbulbOff=oi,a.LineChart=Z,a.LineSquiggle=mi,a.Link=gi,a.Link2=si,a.Link2Off=yi,a.Linkedin=ui,a.List=qi,a.ListCheck=Ci,a.ListChecks=Hi,a.ListChevronsDownUp=Ai,a.ListChevronsUpDown=wi,a.ListCollapse=Vi,a.ListEnd=Si,a.ListFilter=fi,a.ListFilterPlus=Li,a.ListIndentDecrease=o,a.ListIndentIncrease=v,a.ListMinus=ki,a.ListMusic=Pi,a.ListOrdered=Bi,a.ListPlus=Di,a.ListRestart=Fi,a.ListStart=zi,a.ListTodo=bi,a.ListTree=Ti,a.ListVideo=Ri,a.ListX=Ui,a.Loader=Zi,a.Loader2=n2,a.LoaderCircle=n2,a.LoaderPinwheel=Oi,a.Locate=Wi,a.LocateFixed=Ii,a.LocateOff=Gi,a.LocationEdit=o2,a.Lock=Xi,a.LockKeyhole=Ei,a.LockKeyholeOpen=l2,a.LockOpen=e2,a.LogIn=Ni,a.LogOut=ji,a.Logs=Ki,a.Lollipop=Qi,a.Luggage=Ji,a.MSquare=g0,a.Magnet=Yi,a.Mail=Mn,a.MailCheck=_i,a.MailMinus=xi,a.MailOpen=an,a.MailPlus=tn,a.MailQuestion=r2,a.MailQuestionMark=r2,a.MailSearch=hn,a.MailWarning=dn,a.MailX=cn,a.Mailbox=pn,a.Mails=nn,a.Map=wn,a.MapMinus=ln,a.MapPin=Cn,a.MapPinCheck=rn,a.MapPinCheckInside=en,a.MapPinHouse=on,a.MapPinMinus=$n,a.MapPinMinusInside=vn,a.MapPinOff=mn,a.MapPinPen=o2,a.MapPinPlus=gn,a.MapPinPlusInside=yn,a.MapPinX=un,a.MapPinXInside=sn,a.MapPinned=Hn,a.MapPlus=An,a.Mars=Sn,a.MarsStroke=Vn,a.Martini=Ln,a.Maximize=kn,a.Maximize2=fn,a.Medal=Pn,a.Megaphone=Dn,a.MegaphoneOff=Bn,a.Meh=Fn,a.MemoryStick=zn,a.Menu=bn,a.MenuSquare=u0,a.Merge=Rn,a.MessageCircle=Xn,a.MessageCircleCode=Tn,a.MessageCircleDashed=qn,a.MessageCircleHeart=Un,a.MessageCircleMore=On,a.MessageCircleOff=Zn,a.MessageCirclePlus=Gn,a.MessageCircleQuestion=v2,a.MessageCircleQuestionMark=v2,a.MessageCircleReply=In,a.MessageCircleWarning=Wn,a.MessageCircleX=En,a.MessageSquare=il,a.MessageSquareCode=jn,a.MessageSquareDashed=Nn,a.MessageSquareDiff=Kn,a.MessageSquareDot=Qn,a.MessageSquareHeart=Jn,a.MessageSquareLock=_n,a.MessageSquareMore=Yn,a.MessageSquareOff=xn,a.MessageSquarePlus=al,a.MessageSquareQuote=tl,a.MessageSquareReply=hl,a.MessageSquareShare=dl,a.MessageSquareText=cl,a.MessageSquareWarning=Ml,a.MessageSquareX=pl,a.MessagesSquare=nl,a.Mic=el,a.Mic2=$2,a.MicOff=ll,a.MicVocal=$2,a.Microchip=rl,a.Microscope=ol,a.Microwave=vl,a.Milestone=$l,a.Milk=yl,a.MilkOff=ml,a.Minimize=gl,a.Minimize2=sl,a.Minus=ul,a.MinusCircle=e1,a.MinusSquare=C0,a.Monitor=zl,a.MonitorCheck=Cl,a.MonitorCog=Hl,a.MonitorDot=Al,a.MonitorDown=wl,a.MonitorOff=Vl,a.MonitorPause=Sl,a.MonitorPlay=Ll,a.MonitorSmartphone=fl,a.MonitorSpeaker=kl,a.MonitorStop=Pl,a.MonitorUp=Bl,a.MonitorX=Dl,a.Moon=bl,a.MoonStar=Fl,a.MoreHorizontal=b1,a.MoreVertical=z1,a.Motorbike=Rl,a.Mountain=ql,a.MountainSnow=Tl,a.Mouse=Wl,a.MouseOff=Ul,a.MousePointer=Il,a.MousePointer2=Ol,a.MousePointerBan=Zl,a.MousePointerClick=Gl,a.MousePointerSquareDashed=e0,a.Move=he,a.Move3D=m2,a.Move3d=m2,a.MoveDiagonal=Xl,a.MoveDiagonal2=El,a.MoveDown=Kl,a.MoveDownLeft=jl,a.MoveDownRight=Nl,a.MoveHorizontal=Ql,a.MoveLeft=Jl,a.MoveRight=Yl,a.MoveUp=ae,a.MoveUpLeft=xl,a.MoveUpRight=_l,a.MoveVertical=te,a.Music=pe,a.Music2=de,a.Music3=ce,a.Music4=Me,a.Navigation=ee,a.Navigation2=ne,a.Navigation2Off=ie,a.NavigationOff=le,a.Network=re,a.Newspaper=oe,a.Nfc=ve,a.NonBinary=$e,a.Notebook=ge,a.NotebookPen=me,a.NotebookTabs=ye,a.NotebookText=se,a.NotepadText=Ce,a.NotepadTextDashed=ue,a.Nut=Ae,a.NutOff=He,a.Octagon=Ve,a.OctagonAlert=y2,a.OctagonMinus=we,a.OctagonPause=s2,a.OctagonX=g2,a.Omega=Se,a.Option=fe,a.Orbit=Le,a.Origami=ke,a.Outdent=o,a.Package=Te,a.Package2=Pe,a.PackageCheck=Be,a.PackageMinus=De,a.PackageOpen=ze,a.PackagePlus=Fe,a.PackageSearch=be,a.PackageX=Re,a.PaintBucket=qe,a.PaintRoller=Ue,a.Paintbrush=Oe,a.Paintbrush2=u2,a.PaintbrushVertical=u2,a.Palette=Ze,a.Palmtree=N0,a.Panda=Ge,a.PanelBottom=Ee,a.PanelBottomClose=Ie,a.PanelBottomDashed=C2,a.PanelBottomInactive=C2,a.PanelBottomOpen=We,a.PanelLeft=V2,a.PanelLeftClose=H2,a.PanelLeftDashed=A2,a.PanelLeftInactive=A2,a.PanelLeftOpen=w2,a.PanelLeftRightDashed=Xe,a.PanelRight=Ke,a.PanelRightClose=je,a.PanelRightDashed=S2,a.PanelRightInactive=S2,a.PanelRightOpen=Ne,a.PanelTop=_e,a.PanelTopBottomDashed=Qe,a.PanelTopClose=Je,a.PanelTopDashed=L2,a.PanelTopInactive=L2,a.PanelTopOpen=Ye,a.PanelsLeftBottom=xe,a.PanelsLeftRight=P1,a.PanelsRightBottom=ar,a.PanelsTopBottom=b2,a.PanelsTopLeft=f2,a.Paperclip=hr,a.Parentheses=tr,a.ParkingCircle=o1,a.ParkingCircleOff=r1,a.ParkingMeter=dr,a.ParkingSquare=A0,a.ParkingSquareOff=w0,a.PartyPopper=cr,a.Pause=Mr,a.PauseCircle=v1,a.PauseOctagon=s2,a.PawPrint=pr,a.PcCase=nr,a.Pen=P2,a.PenBox=p,a.PenLine=k2,a.PenOff=ir,a.PenSquare=p,a.PenTool=lr,a.Pencil=vr,a.PencilLine=er,a.PencilOff=rr,a.PencilRuler=or,a.Pentagon=$r,a.Percent=mr,a.PercentCircle=$1,a.PercentDiamond=D1,a.PercentSquare=V0,a.PersonStanding=yr,a.PhilippinePeso=sr,a.Phone=Vr,a.PhoneCall=gr,a.PhoneForwarded=ur,a.PhoneIncoming=Cr,a.PhoneMissed=Hr,a.PhoneOff=Ar,a.PhoneOutgoing=wr,a.Pi=Sr,a.PiSquare=S0,a.Piano=Lr,a.Pickaxe=fr,a.PictureInPicture=Pr,a.PictureInPicture2=kr,a.PieChart=X,a.PiggyBank=Br,a.Pilcrow=zr,a.PilcrowLeft=Dr,a.PilcrowRight=Fr,a.PilcrowSquare=L0,a.Pill=Rr,a.PillBottle=br,a.Pin=qr,a.PinOff=Tr,a.Pipette=Ur,a.Pizza=Or,a.Plane=Ir,a.PlaneLanding=Zr,a.PlaneTakeoff=Gr,a.Play=Wr,a.PlayCircle=m1,a.PlaySquare=f0,a.Plug=Xr,a.Plug2=Er,a.PlugZap=B2,a.PlugZap2=B2,a.Plus=jr,a.PlusCircle=y1,a.PlusSquare=k0,a.Pocket=Kr,a.PocketKnife=Nr,a.Podcast=Yr,a.Pointer=Jr,a.PointerOff=Qr,a.Popcorn=_r,a.Popsicle=xr,a.PoundSterling=ao,a.Power=ho,a.PowerCircle=s1,a.PowerOff=to,a.PowerSquare=P0,a.Presentation=co,a.Printer=po,a.PrinterCheck=Mo,a.Projector=io,a.Proportions=no,a.Puzzle=lo,a.Pyramid=eo,a.QrCode=ro,a.Quote=oo,a.Rabbit=vo,a.Radar=$o,a.Radiation=mo,a.Radical=yo,a.Radio=uo,a.RadioReceiver=so,a.RadioTower=go,a.Radius=Ho,a.RailSymbol=Co,a.Rainbow=Ao,a.Rat=wo,a.Ratio=Vo,a.Receipt=zo,a.ReceiptCent=So,a.ReceiptEuro=Lo,a.ReceiptIndianRupee=fo,a.ReceiptJapaneseYen=ko,a.ReceiptPoundSterling=Po,a.ReceiptRussianRuble=Bo,a.ReceiptSwissFranc=Do,a.ReceiptText=Fo,a.ReceiptTurkishLira=bo,a.RectangleCircle=Ro,a.RectangleEllipsis=D2,a.RectangleGoggles=To,a.RectangleHorizontal=qo,a.RectangleVertical=Oo,a.Recycle=Uo,a.Redo=Io,a.Redo2=Zo,a.RedoDot=Go,a.RefreshCcw=Wo,a.RefreshCcwDot=Eo,a.RefreshCw=jo,a.RefreshCwOff=Xo,a.Refrigerator=No,a.Regex=Ko,a.RemoveFormatting=Qo,a.Repeat=_o,a.Repeat1=Yo,a.Repeat2=Jo,a.Replace=av,a.ReplaceAll=xo,a.Reply=hv,a.ReplyAll=tv,a.Rewind=dv,a.Ribbon=cv,a.Rocket=Mv,a.RockingChair=pv,a.RollerCoaster=iv,a.Rose=nv,a.Rotate3D=F2,a.Rotate3d=F2,a.RotateCcw=ev,a.RotateCcwKey=lv,a.RotateCcwSquare=ov,a.RotateCw=$v,a.RotateCwSquare=rv,a.Route=mv,a.RouteOff=vv,a.Router=yv,a.Rows=z2,a.Rows2=z2,a.Rows3=b2,a.Rows4=sv,a.Rss=gv,a.Ruler=Cv,a.RulerDimensionLine=uv,a.RussianRuble=Hv,a.Sailboat=Av,a.Salad=wv,a.Sandwich=Vv,a.Satellite=Lv,a.SatelliteDish=Sv,a.SaudiRiyal=fv,a.Save=Bv,a.SaveAll=kv,a.SaveOff=Pv,a.Scale=Dv,a.Scale3D=R2,a.Scale3d=R2,a.Scaling=Fv,a.Scan=Gv,a.ScanBarcode=zv,a.ScanEye=bv,a.ScanFace=Rv,a.ScanHeart=Tv,a.ScanLine=qv,a.ScanQrCode=Uv,a.ScanSearch=Ov,a.ScanText=Zv,a.ScatterChart=E,a.School=Iv,a.School2=J0,a.Scissors=Ev,a.ScissorsLineDashed=Wv,a.ScissorsSquare=B0,a.ScissorsSquareDashedBottom=t0,a.ScreenShare=jv,a.ScreenShareOff=Xv,a.Scroll=Kv,a.ScrollText=Nv,a.Search=xv,a.SearchCheck=Qv,a.SearchCode=Jv,a.SearchSlash=Yv,a.SearchX=_v,a.Section=a$,a.Send=h$,a.SendHorizonal=T2,a.SendHorizontal=T2,a.SendToBack=t$,a.SeparatorHorizontal=d$,a.SeparatorVertical=c$,a.Server=n$,a.ServerCog=M$,a.ServerCrash=p$,a.ServerOff=i$,a.Settings=e$,a.Settings2=l$,a.Shapes=o$,a.Share=v$,a.Share2=r$,a.Sheet=$$,a.Shell=m$,a.Shield=S$,a.ShieldAlert=y$,a.ShieldBan=s$,a.ShieldCheck=g$,a.ShieldClose=U2,a.ShieldEllipsis=u$,a.ShieldHalf=C$,a.ShieldMinus=H$,a.ShieldOff=A$,a.ShieldPlus=w$,a.ShieldQuestion=q2,a.ShieldQuestionMark=q2,a.ShieldUser=V$,a.ShieldX=U2,a.Ship=f$,a.ShipWheel=L$,a.Shirt=k$,a.ShoppingBag=P$,a.ShoppingBasket=B$,a.ShoppingCart=D$,a.Shovel=F$,a.ShowerHead=z$,a.Shredder=b$,a.Shrimp=R$,a.Shrink=T$,a.Shrub=q$,a.Shuffle=U$,a.Sidebar=V2,a.SidebarClose=H2,a.SidebarOpen=w2,a.Sigma=O$,a.SigmaSquare=D0,a.Signal=E$,a.SignalHigh=Z$,a.SignalLow=G$,a.SignalMedium=I$,a.SignalZero=W$,a.Signature=X$,a.Signpost=N$,a.SignpostBig=j$,a.Siren=K$,a.SkipBack=Q$,a.SkipForward=J$,a.Skull=Y$,a.Slack=_$,a.Slash=x$,a.SlashSquare=F0,a.Slice=am,a.Sliders=O2,a.SlidersHorizontal=tm,a.SlidersVertical=O2,a.Smartphone=cm,a.SmartphoneCharging=hm,a.SmartphoneNfc=dm,a.Smile=pm,a.SmilePlus=Mm,a.Snail=im,a.Snowflake=nm,a.SoapDispenserDroplet=em,a.Sofa=lm,a.SortAsc=w,a.SortDesc=C,a.Soup=rm,a.Space=om,a.Spade=vm,a.Sparkle=$m,a.Sparkles=Z2,a.Speaker=mm,a.Speech=ym,a.SpellCheck=gm,a.SpellCheck2=sm,a.Spline=Cm,a.SplinePointer=um,a.Split=Hm,a.SplitSquareHorizontal=z0,a.SplitSquareVertical=b0,a.Spool=Am,a.Spotlight=wm,a.SprayCan=Vm,a.Sprout=Sm,a.Square=Tm,a.SquareActivity=G2,a.SquareArrowDown=E2,a.SquareArrowDownLeft=I2,a.SquareArrowDownRight=W2,a.SquareArrowLeft=X2,a.SquareArrowOutDownLeft=j2,a.SquareArrowOutDownRight=N2,a.SquareArrowOutUpLeft=K2,a.SquareArrowOutUpRight=Q2,a.SquareArrowRight=J2,a.SquareArrowUp=x2,a.SquareArrowUpLeft=Y2,a.SquareArrowUpRight=_2,a.SquareAsterisk=a0,a.SquareBottomDashedScissors=t0,a.SquareChartGantt=$,a.SquareCheck=d0,a.SquareCheckBig=h0,a.SquareChevronDown=c0,a.SquareChevronLeft=M0,a.SquareChevronRight=p0,a.SquareChevronUp=i0,a.SquareCode=n0,a.SquareDashed=r0,a.SquareDashedBottom=fm,a.SquareDashedBottomCode=Lm,a.SquareDashedKanban=l0,a.SquareDashedMousePointer=e0,a.SquareDashedTopSolid=km,a.SquareDivide=o0,a.SquareDot=v0,a.SquareEqual=$0,a.SquareFunction=m0,a.SquareGanttChart=$,a.SquareKanban=y0,a.SquareLibrary=s0,a.SquareM=g0,a.SquareMenu=u0,a.SquareMinus=C0,a.SquareMousePointer=H0,a.SquareParking=A0,a.SquareParkingOff=w0,a.SquarePause=Pm,a.SquarePen=p,a.SquarePercent=V0,a.SquarePi=S0,a.SquarePilcrow=L0,a.SquarePlay=f0,a.SquarePlus=k0,a.SquarePower=P0,a.SquareRadical=Bm,a.SquareRoundCorner=Dm,a.SquareScissors=B0,a.SquareSigma=D0,a.SquareSlash=F0,a.SquareSplitHorizontal=z0,a.SquareSplitVertical=b0,a.SquareSquare=Fm,a.SquareStack=zm,a.SquareStar=bm,a.SquareStop=Rm,a.SquareTerminal=R0,a.SquareUser=q0,a.SquareUserRound=T0,a.SquareX=U0,a.SquaresExclude=qm,a.SquaresIntersect=Um,a.SquaresSubtract=Om,a.SquaresUnite=Zm,a.Squircle=Gm,a.SquircleDashed=Im,a.Squirrel=Wm,a.Stamp=Em,a.Star=Nm,a.StarHalf=Xm,a.StarOff=jm,a.Stars=Z2,a.StepBack=Km,a.StepForward=Jm,a.Stethoscope=Qm,a.Sticker=Ym,a.StickyNote=_m,a.StopCircle=u1,a.Store=xm,a.StretchHorizontal=ay,a.StretchVertical=ty,a.Strikethrough=hy,a.Subscript=dy,a.Subtitles=F,a.Sun=ny,a.SunDim=cy,a.SunMedium=My,a.SunMoon=py,a.SunSnow=iy,a.Sunrise=ly,a.Sunset=ey,a.Superscript=oy,a.SwatchBook=ry,a.SwissFranc=vy,a.SwitchCamera=$y,a.Sword=my,a.Swords=yy,a.Syringe=sy,a.Table=Sy,a.Table2=gy,a.TableCellsMerge=uy,a.TableCellsSplit=Hy,a.TableColumnsSplit=Cy,a.TableConfig=e,a.TableOfContents=wy,a.TableProperties=Ay,a.TableRowsSplit=Vy,a.Tablet=fy,a.TabletSmartphone=Ly,a.Tablets=ky,a.Tag=Py,a.Tags=Dy,a.Tally1=By,a.Tally2=Fy,a.Tally3=zy,a.Tally4=by,a.Tally5=Ry,a.Tangent=Ty,a.Target=qy,a.Telescope=Uy,a.Tent=Zy,a.TentTree=Oy,a.Terminal=Gy,a.TerminalSquare=R0,a.TestTube=Iy,a.TestTube2=O0,a.TestTubeDiagonal=O0,a.TestTubes=Wy,a.Text=m,a.TextAlignCenter=Z0,a.TextAlignEnd=G0,a.TextAlignJustify=I0,a.TextAlignStart=m,a.TextCursor=Xy,a.TextCursorInput=Ey,a.TextInitial=W0,a.TextQuote=jy,a.TextSearch=Ny,a.TextSelect=E0,a.TextSelection=E0,a.TextWrap=X0,a.Theater=Ky,a.Thermometer=Yy,a.ThermometerSnowflake=Qy,a.ThermometerSun=Jy,a.ThumbsDown=_y,a.ThumbsUp=xy,a.Ticket=Ms,a.TicketCheck=as,a.TicketMinus=ts,a.TicketPercent=hs,a.TicketPlus=ds,a.TicketSlash=ps,a.TicketX=cs,a.Tickets=ns,a.TicketsPlane=is,a.Timer=rs,a.TimerOff=ls,a.TimerReset=es,a.ToggleLeft=os,a.ToggleRight=vs,a.Toilet=$s,a.ToolCase=ys,a.Tornado=ms,a.Torus=ss,a.Touchpad=us,a.TouchpadOff=gs,a.TowerControl=Hs,a.ToyBrick=Cs,a.Tractor=As,a.TrafficCone=ws,a.Train=j0,a.TrainFront=Ss,a.TrainFrontTunnel=Vs,a.TrainTrack=Ls,a.TramFront=j0,a.Transgender=fs,a.Trash=Ps,a.Trash2=ks,a.TreeDeciduous=Bs,a.TreePalm=N0,a.TreePine=Ds,a.Trees=Fs,a.Trello=bs,a.TrendingDown=zs,a.TrendingUp=Ts,a.TrendingUpDown=Rs,a.Triangle=Os,a.TriangleAlert=K0,a.TriangleDashed=qs,a.TriangleRight=Us,a.Trophy=Zs,a.Truck=Is,a.TruckElectric=Gs,a.TurkishLira=Es,a.Turntable=Ws,a.Turtle=Xs,a.Tv=Ns,a.Tv2=Q0,a.TvMinimal=Q0,a.TvMinimalPlay=js,a.Twitch=Ks,a.Twitter=Qs,a.Type=Ys,a.TypeOutline=Js,a.Umbrella=xs,a.UmbrellaOff=_s,a.Underline=ag,a.Undo=dg,a.Undo2=tg,a.UndoDot=hg,a.UnfoldHorizontal=cg,a.UnfoldVertical=Mg,a.Ungroup=pg,a.University=J0,a.Unlink=lg,a.Unlink2=ig,a.Unlock=e2,a.UnlockKeyhole=l2,a.Unplug=ng,a.Upload=eg,a.UploadCloud=L1,a.Usb=rg,a.User=wg,a.User2=ha,a.UserCheck=og,a.UserCheck2=_0,a.UserCircle=H1,a.UserCircle2=C1,a.UserCog=vg,a.UserCog2=Y0,a.UserLock=$g,a.UserMinus=mg,a.UserMinus2=x0,a.UserPen=yg,a.UserPlus=sg,a.UserPlus2=aa,a.UserRound=ha,a.UserRoundCheck=_0,a.UserRoundCog=Y0,a.UserRoundMinus=x0,a.UserRoundPen=gg,a.UserRoundPlus=aa,a.UserRoundSearch=ug,a.UserRoundX=ta,a.UserSearch=Cg,a.UserSquare=q0,a.UserSquare2=T0,a.UserStar=Hg,a.UserX=Ag,a.UserX2=ta,a.Users=Vg,a.Users2=da,a.UsersRound=da,a.Utensils=Ma,a.UtensilsCrossed=ca,a.UtilityPole=Sg,a.Variable=Lg,a.Vault=kg,a.VectorSquare=fg,a.Vegan=Pg,a.VenetianMask=Bg,a.Venus=Fg,a.VenusAndMars=Dg,a.Verified=L,a.Vibrate=bg,a.VibrateOff=zg,a.Video=Tg,a.VideoOff=Rg,a.Videotape=qg,a.View=Ug,a.Voicemail=Og,a.Volleyball=Zg,a.Volume=Xg,a.Volume1=Gg,a.Volume2=Ig,a.VolumeOff=Wg,a.VolumeX=Eg,a.Vote=jg,a.Wallet=Kg,a.Wallet2=pa,a.WalletCards=Ng,a.WalletMinimal=pa,a.Wallpaper=Qg,a.Wand=Jg,a.Wand2=ia,a.WandSparkles=ia,a.Warehouse=Yg,a.WashingMachine=_g,a.Watch=xg,a.Waves=tu,a.WavesLadder=au,a.Waypoints=hu,a.Webcam=du,a.Webhook=pu,a.WebhookOff=Mu,a.Weight=cu,a.Wheat=nu,a.WheatOff=iu,a.WholeWord=lu,a.Wifi=su,a.WifiCog=eu,a.WifiHigh=ru,a.WifiLow=ou,a.WifiOff=mu,a.WifiPen=vu,a.WifiSync=$u,a.WifiZero=yu,a.Wind=uu,a.WindArrowDown=gu,a.Wine=Hu,a.WineOff=Cu,a.Workflow=Au,a.Worm=wu,a.WrapText=X0,a.Wrench=Vu,a.X=Su,a.XCircle=A1,a.XOctagon=g2,a.XSquare=U0,a.Youtube=Lu,a.Zap=ku,a.ZapOff=fu,a.ZoomIn=Pu,a.ZoomOut=Bu,a.createElement=ea,a.createIcons=Ou,a.icons=Du})); -//# sourceMappingURL=lucide.min.js.map diff --git a/internal/server/swagger_gen.go b/internal/server/swagger_gen.go index 03eae74..f72f32b 100644 --- a/internal/server/swagger_gen.go +++ b/internal/server/swagger_gen.go @@ -1,3 +1,3 @@ -//go:generate swag init -g ../../cmd/proxy/main.go -d .,../handler -o ../../docs/swagger --outputTypes go,json --parseInternal +//go:generate swag init -g ../../cmd/proxy/main.go -o ../../docs/swagger --outputTypes go,json --parseInternal package server diff --git a/internal/server/templates/layout/base.html b/internal/server/templates/layout/base.html index f69489c..ee2549f 100644 --- a/internal/server/templates/layout/base.html +++ b/internal/server/templates/layout/base.html @@ -5,29 +5,19 @@ {{block "title" .}}git-pkgs proxy{{end}} - {{if .UIBaseURL}} - - - - - {{end}} - - + {{block "head" .}}{{end}} - + {{template "header" .}} -
+
{{block "content" .}}{{end}}
diff --git a/internal/server/templates/layout/footer.html b/internal/server/templates/layout/footer.html index 33daddf..3245d1d 100644 --- a/internal/server/templates/layout/footer.html +++ b/internal/server/templates/layout/footer.html @@ -5,23 +5,13 @@

About

- git-pkgs proxy is a caching proxy for package registries supporting 17+ ecosystems. + git-pkgs proxy is a caching proxy for package registries supporting 16+ ecosystems.

-

- - github.com/git-pkgs/proxy - -

- {{if .BuildInfo.Version}} -

- proxy {{.BuildInfo.Version}}{{if .BuildInfo.Commit}} ({{.BuildInfo.Commit}}){{end}} -

- {{end}}
+
+

+ Powered by git-pkgs +

+
{{end}} diff --git a/internal/server/templates/layout/header.html b/internal/server/templates/layout/header.html index b3103f1..d893565 100644 --- a/internal/server/templates/layout/header.html +++ b/internal/server/templates/layout/header.html @@ -1,21 +1,31 @@ {{define "header"}}
-
- +
+
- git-pkgs proxy - - - -
- - -
-
-
{{end}} - -{{define "search_form"}} -
- - - - -
-{{end}} - -{{define "nav_links"}} -Install -Health -API -{{end}} diff --git a/internal/server/templates/layout/styles.html b/internal/server/templates/layout/styles.html index 76e9d9e..7fecaff 100644 --- a/internal/server/templates/layout/styles.html +++ b/internal/server/templates/layout/styles.html @@ -9,18 +9,5 @@ localStorage.theme = 'dark'; } }); - - (function() { - const toggle = document.getElementById('nav-toggle'); - const menu = document.getElementById('mobile-nav'); - if (!toggle || !menu) return; - toggle.addEventListener('click', function() { - const open = toggle.getAttribute('aria-expanded') === 'true'; - toggle.setAttribute('aria-expanded', String(!open)); - menu.classList.toggle('hidden'); - toggle.querySelector('.nav-icon-open').classList.toggle('hidden'); - toggle.querySelector('.nav-icon-close').classList.toggle('hidden'); - }); - })(); {{end}} diff --git a/internal/server/templates/pages/browse_source.html b/internal/server/templates/pages/browse_source.html index a949111..710da1c 100644 --- a/internal/server/templates/pages/browse_source.html +++ b/internal/server/templates/pages/browse_source.html @@ -3,11 +3,11 @@ {{define "content"}}
@@ -51,10 +51,7 @@ {{end}} diff --git a/internal/server/templates/pages/search.html b/internal/server/templates/pages/search.html index 42e82c5..a3e76b1 100644 --- a/internal/server/templates/pages/search.html +++ b/internal/server/templates/pages/search.html @@ -28,7 +28,7 @@
{{template "ecosystem_badge" .Ecosystem}} - {{.Name}} + {{.Name}} {{if .LatestVersion}} @{{.LatestVersion}} {{end}} @@ -50,7 +50,7 @@ {{else}}

No packages found matching "{{.Query}}"

- Return to dashboard + Return to dashboard
{{end}} diff --git a/internal/server/templates/pages/version_show.html b/internal/server/templates/pages/version_show.html index 81bc067..dede127 100644 --- a/internal/server/templates/pages/version_show.html +++ b/internal/server/templates/pages/version_show.html @@ -1,15 +1,15 @@ -{{define "title"}}{{.Version.DisplayPURL}} - git-pkgs proxy{{end}} +{{define "title"}}{{.Package.Name}}@{{.Version.PURL}} - git-pkgs proxy{{end}} {{define "content"}}
{{template "ecosystem_badge" .Package.Ecosystem}} -

{{.Version.DisplayPURL}}

+

{{.Version.PURL}}

{{if .IsOutdated}} outdated {{end}} @@ -22,7 +22,7 @@ {{end}} {{if .HasCachedArtifact}}
- diff --git a/internal/server/templates_test.go b/internal/server/templates_test.go index a2d3b7d..e19244e 100644 --- a/internal/server/templates_test.go +++ b/internal/server/templates_test.go @@ -37,12 +37,7 @@ func TestTemplatesRenderAllPages(t *testing.T) { {Ecosystem: "cargo", Name: "serde", Version: "1.0.0", Size: "200 KB", CachedAt: "1 hour ago"}, }, }}, - {"install", struct { - Layout - BaseURL string - Registries []RegistryConfig - }{ - BaseURL: "http://localhost:8080", + {"install", struct{ Registries []RegistryConfig }{ Registries: getRegistryConfigs("http://localhost:8080"), }}, {"search", SearchPageData{ @@ -158,166 +153,6 @@ func TestTemplatesRenderAllPages(t *testing.T) { } } -func TestRenderEmitsCanonicalAndOG(t *testing.T) { - templates := &Templates{} - - data := DashboardData{ - Layout: Layout{ - UIBaseURL: "https://ui.example.com/ui", - CanonicalPath: "/ui/", - }, - } - - w := httptest.NewRecorder() - if err := templates.Render(w, "dashboard", data); err != nil { - t.Fatalf("Render failed: %v", err) - } - - body := w.Body.String() - want := []string{ - ``, - ``, - ``, - } - for _, s := range want { - if !strings.Contains(body, s) { - t.Errorf("rendered body missing %q", s) - } - } -} - -func TestFooterUsesBuildInfoWhenPageDefinesVersion(t *testing.T) { - templates := &Templates{} - buildInfo := BuildInfo{Version: "proxy-build-1.2.3", Commit: "abc123def"} - wantFooter := "proxy proxy-build-1.2.3 (abc123def)" - - tests := []struct { - name string - page string - data any - shadow string - }{ - { - name: "version show page", - page: "version_show", - data: VersionShowData{ - Layout: Layout{BuildInfo: buildInfo}, - Package: &database.Package{ - PURL: "pkg:npm/lodash", - Ecosystem: "npm", - Name: "lodash", - }, - Version: &database.Version{ - PURL: "pkg:npm/lodash@9.9.9", - PackagePURL: "pkg:npm/lodash", - }, - }, - shadow: "9.9.9", - }, - { - name: "browse source page", - page: "browse_source", - data: BrowseSourceData{ - Layout: Layout{BuildInfo: buildInfo}, - Ecosystem: "npm", - PackageName: "lodash", - Version: "9.9.9", - }, - shadow: "9.9.9", - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - w := httptest.NewRecorder() - if err := templates.Render(w, tt.page, tt.data); err != nil { - t.Fatalf("Render(%q) failed: %v", tt.page, err) - } - body := w.Body.String() - if !strings.Contains(body, wantFooter) { - t.Errorf("footer missing build info %q", wantFooter) - } - if strings.Contains(body, "proxy "+tt.shadow) { - t.Errorf("footer used page Version %q instead of BuildInfo", tt.shadow) - } - }) - } -} - -func TestRenderOmitsCanonicalWhenUIBaseURLUnset(t *testing.T) { - templates := &Templates{} - - w := httptest.NewRecorder() - if err := templates.Render(w, "dashboard", DashboardData{}); err != nil { - t.Fatalf("Render failed: %v", err) - } - - body := w.Body.String() - if strings.Contains(body, `rel="canonical"`) { - t.Error("canonical tag should be omitted when UIBaseURL is empty") - } - if strings.Contains(body, `property="og:url"`) { - t.Error("og:url tag should be omitted when UIBaseURL is empty") - } -} - -func TestInstallPageBannerWhenUIDiffersFromBaseURL(t *testing.T) { - templates := &Templates{} - - data := struct { - Layout - BaseURL string - Registries []RegistryConfig - }{ - Layout: Layout{ - UIBaseURL: "https://ui.example.com/ui", - CanonicalPath: "/ui/install", - }, - BaseURL: "http://pkg-proxy:8080", - Registries: getRegistryConfigs("http://pkg-proxy:8080"), - } - - w := httptest.NewRecorder() - if err := templates.Render(w, "install", data); err != nil { - t.Fatalf("Render failed: %v", err) - } - - body := w.Body.String() - if !strings.Contains(body, "https://ui.example.com/ui") || !strings.Contains(body, "http://pkg-proxy:8080") { - t.Error("install banner should mention both UIBaseURL and BaseURL when they differ") - } - if !strings.Contains(body, "package managers should be configured") { - t.Error("install banner copy missing") - } -} - -func TestInstallPageNoBannerWhenURLsMatch(t *testing.T) { - templates := &Templates{} - - data := struct { - Layout - BaseURL string - Registries []RegistryConfig - }{ - Layout: Layout{ - UIBaseURL: "http://localhost:8080", - CanonicalPath: "/ui/install", - }, - BaseURL: "http://localhost:8080", - Registries: getRegistryConfigs("http://localhost:8080"), - } - - w := httptest.NewRecorder() - if err := templates.Render(w, "install", data); err != nil { - t.Fatalf("Render failed: %v", err) - } - - body := w.Body.String() - if strings.Contains(body, "package managers should be configured") { - t.Error("install banner should be hidden when UIBaseURL == BaseURL") - } -} - func TestTemplatesLazyLoading(t *testing.T) { templates := &Templates{} @@ -347,7 +182,7 @@ func TestInstallPage(t *testing.T) { ts := newTestServer(t) defer ts.close() - req := httptest.NewRequest("GET", "/ui/install", nil) + req := httptest.NewRequest("GET", "/install", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -358,7 +193,7 @@ func TestInstallPage(t *testing.T) { body := w.Body.String() // Should contain instructions for all registries - registries := []string{"npm", "Cargo", "RubyGems", "Go Modules", "PyPI", "Maven", "Gradle Build Cache", "NuGet", "Composer", "Conan", "Conda", "CRAN"} + registries := []string{"npm", "Cargo", "RubyGems", "Go Modules", "PyPI", "Maven", "NuGet", "Composer", "Conan", "Conda", "CRAN"} for _, reg := range registries { if !strings.Contains(body, reg) { t.Errorf("install page should contain %s instructions", reg) @@ -386,7 +221,7 @@ func TestPackageShowPage(t *testing.T) { t.Fatalf("failed to upsert version: %v", err) } - req := httptest.NewRequest("GET", "/ui/package/npm/test-show", nil) + req := httptest.NewRequest("GET", "/package/npm/test-show", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -410,7 +245,7 @@ func TestPackageShowPage_NotFound(t *testing.T) { ts := newTestServer(t) defer ts.close() - req := httptest.NewRequest("GET", "/ui/package/npm/nonexistent", nil) + req := httptest.NewRequest("GET", "/package/npm/nonexistent", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -423,7 +258,7 @@ func TestVersionShowPage_NotFound(t *testing.T) { ts := newTestServer(t) defer ts.close() - req := httptest.NewRequest("GET", "/ui/package/npm/nonexistent/1.0.0", nil) + req := httptest.NewRequest("GET", "/package/npm/nonexistent/1.0.0", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -436,7 +271,7 @@ func TestSearchPage_EmptyQuery(t *testing.T) { ts := newTestServer(t) defer ts.close() - req := httptest.NewRequest("GET", "/ui/search", nil) + req := httptest.NewRequest("GET", "/search", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -450,7 +285,7 @@ func TestSearchPage_WithQuery(t *testing.T) { ts := newTestServer(t) defer ts.close() - req := httptest.NewRequest("GET", "/ui/search?q=test", nil) + req := httptest.NewRequest("GET", "/search?q=test", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -469,7 +304,7 @@ func TestSearchPage_Pagination(t *testing.T) { defer ts.close() // Page 0 or negative should default to page 1 - req := httptest.NewRequest("GET", "/ui/search?q=test&page=0", nil) + req := httptest.NewRequest("GET", "/search?q=test&page=0", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -478,7 +313,7 @@ func TestSearchPage_Pagination(t *testing.T) { } // Non-numeric page should default to page 1 - req = httptest.NewRequest("GET", "/ui/search?q=test&page=abc", nil) + req = httptest.NewRequest("GET", "/search?q=test&page=abc", nil) w = httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -491,7 +326,7 @@ func TestSearchPage_EcosystemFilter(t *testing.T) { ts := newTestServer(t) defer ts.close() - req := httptest.NewRequest("GET", "/ui/search?q=test&ecosystem=npm", nil) + req := httptest.NewRequest("GET", "/search?q=test&ecosystem=npm", nil) w := httptest.NewRecorder() ts.handler.ServeHTTP(w, req) @@ -500,6 +335,7 @@ func TestSearchPage_EcosystemFilter(t *testing.T) { } } + func TestEcosystemBadgeLabel(t *testing.T) { tests := []struct { ecosystem string @@ -519,35 +355,6 @@ func TestEcosystemBadgeLabel(t *testing.T) { } } -func TestOCIRegistryInstructionsDockerPull(t *testing.T) { - registries := getRegistryConfigs("http://package-proxy:8080") - for _, registry := range registries { - if registry.ID != "oci" { - continue - } - want := "docker pull package-proxy:8080/library/nginx:latest" - if !strings.Contains(string(registry.Instructions), want) { - t.Errorf("OCI instructions = %q, want substring %q", registry.Instructions, want) - } - return - } - t.Fatal("OCI registry instructions not found") -} - -func TestSwiftRegistryInstructionsAllowLocalHTTP(t *testing.T) { - registries := getRegistryConfigs("http://localhost:8080") - for _, registry := range registries { - if registry.ID != "swift" { - continue - } - if !strings.Contains(string(registry.Instructions), "--allow-insecure-http") { - t.Error("Swift HTTP instructions do not allow the insecure local registry") - } - return - } - t.Fatal("Swift registry instructions not found") -} - func TestEcosystemBadgeClasses(t *testing.T) { // Every supported ecosystem should return a non-empty class string ecosystems := supportedEcosystems() diff --git a/internal/server/transport_test.go b/internal/server/transport_test.go deleted file mode 100644 index 7464282..0000000 --- a/internal/server/transport_test.go +++ /dev/null @@ -1,190 +0,0 @@ -package server - -import ( - "crypto/tls" - "io" - "net" - "net/http" - "net/http/httptest" - "strings" - "sync" - "testing" - "time" - - "github.com/git-pkgs/proxy/internal/config" - "github.com/git-pkgs/registries/safehttp" -) - -// tlsUpstream starts a TLS test server that counts accepted connections. -func tlsUpstream(t *testing.T, handler http.HandlerFunc) (*httptest.Server, func() int) { - t.Helper() - var mu sync.Mutex - accepted := 0 - srv := httptest.NewUnstartedServer(handler) - srv.Config.ConnState = func(_ net.Conn, state http.ConnState) { - if state == http.StateNew { - mu.Lock() - accepted++ - mu.Unlock() - } - } - srv.StartTLS() - t.Cleanup(srv.Close) - return srv, func() int { - mu.Lock() - defer mu.Unlock() - return accepted - } -} - -// trustUpstream makes transport trust srv's certificate and pins HTTP/1.1 so -// every in-flight request needs its own connection. -func trustUpstream(t *testing.T, transport *http.Transport, srv *httptest.Server) { - t.Helper() - transport.TLSClientConfig = &tls.Config{ - RootCAs: srv.Client().Transport.(*http.Transport).TLSClientConfig.RootCAs, - NextProtos: []string{"http/1.1"}, - MinVersion: tls.VersionTLS12, - } - transport.ForceAttemptHTTP2 = false - t.Cleanup(transport.CloseIdleConnections) -} - -// burst issues n concurrent GETs and drains every body. The transport hands a -// connection back to the idle pool before the body's final Read returns, so -// the pool is settled when burst returns. -func burst(t *testing.T, client *http.Client, url string, n int) { - t.Helper() - var wg sync.WaitGroup - errs := make(chan error, n) - for range n { - wg.Add(1) - go func() { - defer wg.Done() - resp, err := client.Get(url) - if err != nil { - errs <- err - return - } - _, _ = io.Copy(io.Discard, resp.Body) - _ = resp.Body.Close() - }() - } - wg.Wait() - close(errs) - for err := range errs { - t.Errorf("burst request: %v", err) - } -} - -// TestUpstreamClientReusesConnectionsAcrossBursts measures how many -// connections a second burst of concurrent requests reuses. With Go's default -// of two idle connections per host most of them are re-dialled; with the -// tuned transport the second burst reuses all of them. -func TestUpstreamClientReusesConnectionsAcrossBursts(t *testing.T) { - const burstSize = 8 - - // holdBurst returns a handler that answers a request only once burstSize - // of them are waiting at the same time. With HTTP/1.1 pinned that puts - // every burst on burstSize distinct connections, whatever the scheduling. - holdBurst := func() http.HandlerFunc { - var mu sync.Mutex - waiting := 0 - release := make(chan struct{}) - return func(w http.ResponseWriter, r *http.Request) { - mu.Lock() - gate := release - waiting++ - if waiting == burstSize { - close(gate) - waiting = 0 - release = make(chan struct{}) - } - mu.Unlock() - select { - case <-gate: - case <-r.Context().Done(): - } - _, _ = w.Write([]byte("ok")) - } - } - - tests := []struct { - name string - client *http.Client - // Bounds on how many connections the second burst has to dial. - minNew, maxNew int - }{ - { - name: "go default keeps two idle connections", - client: safehttp.New(nil, safehttp.Options{AllowLoopback: true}), - minNew: burstSize - 2, - maxNew: burstSize, - }, - { - name: "tuned transport reuses the whole burst", - client: newUpstreamClient(config.UpstreamConfig{AllowLoopback: true}), - minNew: 0, - maxNew: 0, - }, - } - for _, tc := range tests { - t.Run(tc.name, func(t *testing.T) { - srv, accepted := tlsUpstream(t, holdBurst()) - transport := tc.client.Transport.(*http.Transport) - trustUpstream(t, transport, srv) - - burst(t, tc.client, srv.URL, burstSize) - afterFirst := accepted() - if afterFirst < burstSize { - t.Fatalf("first burst opened %d connections, want at least %d", afterFirst, burstSize) - } - - burst(t, tc.client, srv.URL, burstSize) - newInSecond := accepted() - afterFirst - t.Logf("second burst: %d new connections, %d reused", newInSecond, burstSize-newInSecond) - - if newInSecond < tc.minNew || newInSecond > tc.maxNew { - t.Errorf("second burst opened %d new connections, want between %d and %d", newInSecond, tc.minNew, tc.maxNew) - } - }) - } -} - -// TestUpstreamClientBoundsStallBeforeHeaders pins the production transport -// values, then lowers the header timeout so it can show within milliseconds -// that this is what cuts off an upstream which accepts a request but never -// sends headers. -func TestUpstreamClientBoundsStallBeforeHeaders(t *testing.T) { - client := newUpstreamClient(config.UpstreamConfig{AllowLoopback: true}) - transport := client.Transport.(*http.Transport) - if transport.MaxIdleConnsPerHost != upstreamMaxIdleConnsPerHost { - t.Fatalf("MaxIdleConnsPerHost = %d, want %d", transport.MaxIdleConnsPerHost, upstreamMaxIdleConnsPerHost) - } - if transport.ResponseHeaderTimeout != upstreamResponseHeaderTimeout { - t.Fatalf("ResponseHeaderTimeout = %v, want %v", transport.ResponseHeaderTimeout, upstreamResponseHeaderTimeout) - } - - stall := make(chan struct{}) - srv, _ := tlsUpstream(t, func(_ http.ResponseWriter, r *http.Request) { - select { - case <-stall: - case <-r.Context().Done(): - } - }) - t.Cleanup(func() { close(stall) }) - trustUpstream(t, transport, srv) - - // Far below the client's overall timeout, so the header timeout ends the - // request; the error text tells the two timeouts apart. - transport.ResponseHeaderTimeout = 200 * time.Millisecond - - resp, err := client.Get(srv.URL) - if err == nil { - _ = resp.Body.Close() - t.Fatal("request to a stalled upstream succeeded, want a timeout") - } - if !strings.Contains(err.Error(), "timeout awaiting response headers") { - t.Fatalf("error = %v, want a response-header timeout", err) - } -} diff --git a/internal/storage/blob.go b/internal/storage/blob.go index cdc7aa0..2d6af46 100644 --- a/internal/storage/blob.go +++ b/internal/storage/blob.go @@ -6,15 +6,12 @@ import ( "encoding/hex" "fmt" "io" - "net/http" "os" "path/filepath" "runtime" "strings" - "time" "gocloud.dev/blob" - _ "gocloud.dev/blob/azureblob" _ "gocloud.dev/blob/fileblob" _ "gocloud.dev/blob/s3blob" "gocloud.dev/gcerrors" @@ -22,19 +19,11 @@ import ( const osWindows = "windows" -// attrsExt is fileblob's sidecar suffix, kept only to clear sidecars an -// earlier version wrote. -const attrsExt = ".attrs" - // Blob implements Storage using gocloud.dev/blob. // Supports local filesystem (file://) and S3 (s3://) URLs. type Blob struct { bucket *blob.Bucket url string - - // fileRoot is the directory backing a file:// bucket, empty for cloud - // backends. Used only to clear sidecars an earlier version wrote. - fileRoot string } // OpenBucket opens a blob bucket from a URL. @@ -43,20 +32,9 @@ type Blob struct { // - file:///path/to/dir - Local filesystem storage // - s3://bucket-name - Amazon S3 (uses AWS_* environment variables) // - s3://bucket-name?region=us-east-1&endpoint=http://localhost:9000 - S3-compatible (MinIO, etc.) -// - gs://bucket-name - Google Cloud Storage (uses Application Default Credentials; -// supports Workload Identity on GKE/GCE without any extra configuration) -// - azblob://container-name - Azure Blob Storage // // For local filesystem, the directory is created if it doesn't exist. -// -//nolint:ireturn // The URL scheme selects the storage implementation. -func OpenBucket(ctx context.Context, urlStr string) (Storage, error) { - if strings.HasPrefix(urlStr, "gs://") { - return OpenGCS(ctx, urlStr) - } - - var fileRoot string - +func OpenBucket(ctx context.Context, urlStr string) (*Blob, error) { // Handle file:// URLs specially to create the directory if strings.HasPrefix(urlStr, "file://") { path := strings.TrimPrefix(urlStr, "file://") @@ -84,8 +62,6 @@ func OpenBucket(ctx context.Context, urlStr string) (Storage, error) { return nil, fmt.Errorf("resolving path: %w", err) } - fileRoot = absPath - // Convert back to URL format with forward slashes urlPath := filepath.ToSlash(absPath) if runtime.GOOS == osWindows { @@ -99,14 +75,7 @@ func OpenBucket(ctx context.Context, urlStr string) (Storage, error) { // This avoids "invalid cross-device link" errors from os.Rename when // the bucket directory and os.TempDir are on different filesystems // (e.g. Docker volume mounts). - // - // Do not write fileblob's ".attrs" sidecar. It is rewritten with - // os.Create, truncating in place outside the atomic rename that - // protects the blob, so a read overlapping a write can decode a - // partial file; a missing one defaults cleanly, a truncated one does - // not. Nothing in the proxy needs it: Store sets no ContentType, and - // Size reads os.Stat via Attributes. - urlStr += "?no_tmp_dir=true&metadata=skip" + urlStr += "?no_tmp_dir=true" } bucket, err := blob.OpenBucket(ctx, urlStr) @@ -114,87 +83,10 @@ func OpenBucket(ctx context.Context, urlStr string) (Storage, error) { return nil, fmt.Errorf("opening bucket: %w", err) } - return &Blob{bucket: bucket, url: urlStr, fileRoot: fileRoot}, nil -} - -// legacySidecarPath gives the ".attrs" path an earlier version wrote for key, -// or "" when that path would not be a file inside fileRoot. -// -// The key is escaped the way fileblob escapes it on the way to disk, so the -// sidecar is looked for where fileblob wrote it. filepath.Localize then -// validates the escaped form: it rejects an empty, absolute or ".." path, and -// "." would name fileRoot itself. What it declines are keys the proxy never -// produces. -func (b *Blob) legacySidecarPath(key string) string { - if b.fileRoot == "" { - return "" - } - rel, err := filepath.Localize(escapeKey(key)) - if err != nil || rel == "." { - return "" - } - return filepath.Join(b.fileRoot, rel) + attrsExt -} - -// escapeKey mirrors fileblob's unexported escapeKey, which hex-escapes a rune -// as "__0x__". Slashes stay as "/" for filepath.Localize to convert. -func escapeKey(key string) string { - runes := []rune(key) - var out strings.Builder - for i, r := range runes { - if escapeRune(runes, i) { - fmt.Fprintf(&out, "__%#x__", r) - } else { - out.WriteRune(r) - } - } - return out.String() -} - -// escapeRune is fileblob's rule for which runes of a key to escape: control -// characters, a raw path separator, a slash that would form "../", "//" or -// end the key, and on Windows the characters its filesystem reserves. -func escapeRune(r []rune, i int) bool { - c := r[i] - switch { - case c < ' ': - return true - case os.PathSeparator != '/' && c == os.PathSeparator: - return true - case i > 1 && c == '/' && r[i-1] == '.' && r[i-2] == '.': - return true - case i > 0 && c == '/' && r[i-1] == '/': - return true - case c == '/' && i == len(r)-1: - return true - case os.PathSeparator == '\\' && strings.ContainsRune(`<>:"|?*`, c): - return true - } - return false -} - -// clearLegacySidecar removes the ".attrs" file an earlier version wrote for -// key. Nothing rewrites one now, so a sidecar left partial by an interrupted -// write would fail every read of that key for good. Removing is atomic where -// the rewrite was not, so a concurrent reader gets the whole old file or -// nothing. -// -// Failure is deliberately not fatal. Usually the key never had a sidecar and -// os.Remove reports not-exist. A real failure leaves exactly the state this -// change inherited, while failing the write would turn a cleanup miss into a -// failed request. Windows makes that concrete: Go opens files without -// FILE_SHARE_DELETE, so a reader holding the sidecar open blocks deletion, and -// that reader is the very workload this change protects. The next store of the -// key retries. -func (b *Blob) clearLegacySidecar(key string) { - if sidecar := b.legacySidecarPath(key); sidecar != "" { - _ = os.Remove(sidecar) - } + return &Blob{bucket: bucket, url: urlStr}, nil } func (b *Blob) Store(ctx context.Context, path string, r io.Reader) (int64, string, error) { - b.clearLegacySidecar(path) - // Compute hash while writing h := sha256.New() tee := io.TeeReader(r, h) @@ -246,20 +138,6 @@ func (b *Blob) Delete(ctx context.Context, path string) error { return nil } -func (b *Blob) SignedURL(ctx context.Context, path string, expiry time.Duration) (string, error) { - url, err := b.bucket.SignedURL(ctx, path, &blob.SignedURLOptions{ - Method: http.MethodGet, - Expiry: expiry, - }) - if err != nil { - if gcerrors.Code(err) == gcerrors.Unimplemented { - return "", ErrSignedURLUnsupported - } - return "", fmt.Errorf("signing URL: %w", err) - } - return url, nil -} - func (b *Blob) Size(ctx context.Context, path string) (int64, error) { attrs, err := b.bucket.Attributes(ctx, path) if err != nil { @@ -289,35 +167,6 @@ func (b *Blob) UsedSpace(ctx context.Context) (int64, error) { return total, nil } -// ListPrefix returns object metadata for keys under a prefix. -func (b *Blob) ListPrefix(ctx context.Context, prefix string) ([]ObjectInfo, error) { - iter := b.bucket.List(&blob.ListOptions{Prefix: prefix}) - objects := make([]ObjectInfo, 0) - - for { - obj, err := iter.Next(ctx) - if err == io.EOF { - break - } - if err != nil { - return nil, fmt.Errorf("listing objects: %w", err) - } - if obj.IsDir { - continue - } - - info := ObjectInfo{ - Path: obj.Key, - Size: obj.Size, - ModTime: obj.ModTime, - } - - objects = append(objects, info) - } - - return objects, nil -} - func (b *Blob) Close() error { return b.bucket.Close() } diff --git a/internal/storage/blob_test.go b/internal/storage/blob_test.go index 3a97704..bb2d089 100644 --- a/internal/storage/blob_test.go +++ b/internal/storage/blob_test.go @@ -6,17 +6,10 @@ import ( "encoding/hex" "errors" "io" - "io/fs" - "os" "path/filepath" "runtime" "strings" - "sync" - "sync/atomic" "testing" - "time" - - "gocloud.dev/blob" ) func TestOpenBucket(t *testing.T) { @@ -195,18 +188,6 @@ func TestBlobLargeFile(t *testing.T) { assertLargeFileRoundTrip(t, createTestBlob(t)) } -func TestBlobSignedURLUnsupported(t *testing.T) { - b := createTestBlob(t) - ctx := context.Background() - - // fileblob has no URL signer configured, so this must surface as - // ErrSignedURLUnsupported rather than a generic error. - _, err := b.SignedURL(ctx, "test/file.txt", time.Minute) - if !errors.Is(err, ErrSignedURLUnsupported) { - t.Errorf("SignedURL on fileblob = %v, want ErrSignedURLUnsupported", err) - } -} - func TestBlobOverwrite(t *testing.T) { b := createTestBlob(t) ctx := context.Background() @@ -284,11 +265,7 @@ func createTestBlob(t *testing.T) *Blob { t.Fatalf("OpenBucket failed: %v", err) } t.Cleanup(func() { _ = b.Close() }) - blob, ok := b.(*Blob) - if !ok { - t.Fatalf("OpenBucket returned %T, want *Blob", b) - } - return blob + return b } func fileURLFromPath(path string) string { @@ -299,317 +276,3 @@ func fileURLFromPath(path string) string { } return "file://" + path } - -func TestOpenBucketWritesNoAttrsSidecar(t *testing.T) { - dir := t.TempDir() - ctx := context.Background() - - b, err := OpenBucket(ctx, fileURLFromPath(dir)) - if err != nil { - t.Fatalf("OpenBucket failed: %v", err) - } - defer func() { _ = b.Close() }() - - if _, _, err := b.Store(ctx, "pkg/thing-1.0.0.tgz", strings.NewReader("content")); err != nil { - t.Fatalf("Store failed: %v", err) - } - - sidecars, err := filepath.Glob(filepath.Join(dir, "*", "*.attrs")) - if err != nil { - t.Fatalf("Glob failed: %v", err) - } - if len(sidecars) != 0 { - t.Errorf("got sidecar files %v, want none: a truncated sidecar fails reads that overlap a write", sidecars) - } -} - -// A read overlapping a write to the same key must not fail. fileblob rewrote -// its ".attrs" sidecar in place, so a reader decoding it mid-write saw a -// partial file, which the proxy served as a 502 on an artifact it held. -func TestConcurrentReadsSurviveWritesToSameKey(t *testing.T) { - if runtime.GOOS == "windows" { - // Go opens files without FILE_SHARE_DELETE, so a writer cannot replace - // a file a reader holds open: its rename fails with access denied - // instead of contending. The other platforms exercise this race. - t.Skip("Windows refuses to replace a file readers hold open") - } - const ( - key = "pkg/thing-1.0.0.tgz" - readers = 4 - readsPerRead = 500 - ) - dir := t.TempDir() - ctx := context.Background() - - b, err := OpenBucket(ctx, fileURLFromPath(dir)) - if err != nil { - t.Fatalf("OpenBucket failed: %v", err) - } - defer func() { _ = b.Close() }() - - payload := strings.Repeat("x", 4096) - if _, _, err := b.Store(ctx, key, strings.NewReader(payload)); err != nil { - t.Fatalf("seeding Store failed: %v", err) - } - - // The writer reports how it ended: a Store failure would otherwise stop - // the writes silently and let zero read failures pass for a test that - // never contended anything. - done := make(chan struct{}) - var writers sync.WaitGroup - var writes int - var writeErr error - writers.Add(1) - go func() { - defer writers.Done() - for { - select { - case <-done: - return - default: - } - if _, _, err := b.Store(ctx, key, strings.NewReader(payload)); err != nil { - writeErr = err - return - } - writes++ - } - }() - - var failures atomic.Int64 - var reading sync.WaitGroup - for range readers { - reading.Add(1) - go func() { - defer reading.Done() - for range readsPerRead { - r, err := b.Open(ctx, key) - if err != nil { - failures.Add(1) - continue - } - if _, err := io.Copy(io.Discard, r); err != nil { - failures.Add(1) - } - _ = r.Close() - } - }() - } - reading.Wait() - close(done) - writers.Wait() - - if writeErr != nil { - t.Fatalf("writer stopped early: %v", writeErr) - } - if writes == 0 { - t.Fatal("no write completed, so the reads were never contended") - } - if got := failures.Load(); got != 0 { - t.Errorf("%d of %d reads failed while one writer rewrote the same key, want 0", got, readers*readsPerRead) - } -} - -// seedLegacySidecar stores key through a bucket that still writes sidecars, as -// an earlier version did, and returns the path fileblob actually used. It is -// discovered rather than assumed, so callers test the real mapping. -func seedLegacySidecar(t *testing.T, dir, key, payload string) string { - t.Helper() - ctx := context.Background() - - legacy, err := blob.OpenBucket(ctx, fileURLFromPath(dir)+"?no_tmp_dir=true") - if err != nil { - t.Fatalf("opening legacy bucket: %v", err) - } - if err := legacy.WriteAll(ctx, key, []byte(payload), nil); err != nil { - t.Fatalf("legacy WriteAll: %v", err) - } - if err := legacy.Close(); err != nil { - t.Fatalf("closing legacy bucket: %v", err) - } - - var found []string - walkErr := filepath.WalkDir(dir, func(path string, d fs.DirEntry, err error) error { - if err != nil { - return err - } - if !d.IsDir() && strings.HasSuffix(path, ".attrs") { - found = append(found, path) - } - return nil - }) - if walkErr != nil { - t.Fatalf("walking %s: %v", dir, walkErr) - } - if len(found) != 1 { - t.Fatalf("got sidecars %v, want exactly one", found) - } - return found[0] -} - -// An interrupted setAttrs leaves a partial sidecar that fails every read of the -// key, and nothing rewrites one now, so a store has to clear it. -// -// One key per storage path the proxy builds: ArtifactPath across ecosystems, -// metadata blobs, and the Gradle build cache. Scoped npm names, Go's "!" case -// escaping and the ":" in OCI digests and Debian epochs are the characters -// most likely to part fileblob's mapping from a plain path join. -func TestStoreClearsLegacyAttrsSidecar(t *testing.T) { - keys := []string{ - "npm/@babel/core/7.24.0/core-7.24.0.tgz", - "maven/org.apache.commons/commons-lang3/3.14.0/commons-lang3-3.14.0.jar", - "golang/github.com/!burnt!sushi/toml/v1.3.2/v1.3.2.zip", - "oci/library/nginx/sha256:abc123def456/manifest", - "debian/tzdata/1:2024a-1/tzdata_2024a-1_all.deb", - "pypi/requests/2.31.0/requests-2.31.0-py3-none-any.whl", - "cargo/serde/1.0.197/serde-1.0.197.crate", - "julia/Example/a1b2c3/a1b2c3.tar.gz", - "conda/numpy/1.26.4/numpy-1.26.4-py311.conda", - "_metadata/npm/@babel/core/metadata", - "_gradle/http-build-cache/0a1b2c3d4e5f", - // Keys fileblob escapes on every platform. - "npm/pkg//1.0.0/x.tgz", - "npm/pkg/../1.0.0/x.tgz", - } - - for _, key := range keys { - t.Run(key, func(t *testing.T) { - assertStoreClearsSidecar(t, key) - }) - } -} - -func assertStoreClearsSidecar(t *testing.T, key string) { - t.Helper() - const payload = "payload" - ctx := context.Background() - dir := t.TempDir() - - sidecar := seedLegacySidecar(t, dir, key, payload) - if err := os.WriteFile(sidecar, []byte(`{"user.content_type":"appl`), 0o600); err != nil { - t.Fatalf("corrupting sidecar: %v", err) - } - - b := openFileBlob(t, dir) - if _, err := b.Open(ctx, key); err == nil { - t.Fatal("corrupt sidecar did not fail the read, so it is not the file fileblob reads for this key") - } - - derived := b.legacySidecarPath(key) - if _, _, err := b.Store(ctx, key, strings.NewReader(payload)); err != nil { - t.Fatalf("Store failed: %v", err) - } - - if derived == "" { - t.Fatalf("legacySidecarPath declined %q, but fileblob wrote %q", key, sidecar) - } - if derived != sidecar { - t.Fatalf("derived %q, but fileblob wrote %q", derived, sidecar) - } - if _, err := os.Stat(sidecar); !os.IsNotExist(err) { - t.Errorf("sidecar still present after Store, stat err = %v", err) - } - assertReadsBack(t, b, key, payload) -} - -func assertReadsBack(t *testing.T, b *Blob, key, want string) { - t.Helper() - r, err := b.Open(context.Background(), key) - if err != nil { - t.Fatalf("read still failing after Store cleared the sidecar: %v", err) - } - defer func() { _ = r.Close() }() - got, err := io.ReadAll(r) - if err != nil { - t.Fatalf("ReadAll failed: %v", err) - } - if string(got) != want { - t.Errorf("got %q, want %q", got, want) - } -} - -func openFileBlob(t *testing.T, dir string) *Blob { - t.Helper() - s, err := OpenBucket(context.Background(), fileURLFromPath(dir)) - if err != nil { - t.Fatalf("OpenBucket failed: %v", err) - } - t.Cleanup(func() { _ = s.Close() }) - b, ok := s.(*Blob) - if !ok { - t.Fatalf("got %T, want *Blob", s) - } - return b -} - -// fileblob escapes a non-local key in a way this cannot reproduce, and one -// holding ".." resolves outside the cache directory. Removal declines both -// rather than delete the wrong file. -func TestLegacySidecarPathEscapesLikeFileblob(t *testing.T) { - root := filepath.FromSlash("/var/cache/proxy") - b := &Blob{fileRoot: root} - windows := runtime.GOOS == osWindows - - for _, tc := range []struct{ key, unix, windows string }{ - {"npm/pkg/1.0.0/x.tgz", "npm/pkg/1.0.0/x.tgz", "npm/pkg/1.0.0/x.tgz"}, - {"npm/pkg//1.0.0/x.tgz", "npm/pkg/__0x2f__1.0.0/x.tgz", "npm/pkg/__0x2f__1.0.0/x.tgz"}, - {"npm/pkg/../../etc/passwd", "npm/pkg/..__0x2f__..__0x2f__etc/passwd", "npm/pkg/..__0x2f__..__0x2f__etc/passwd"}, - {"npm/pkg/1.0.0/", "npm/pkg/1.0.0__0x2f__", "npm/pkg/1.0.0__0x2f__"}, - {"npm/a\x01b", "npm/a__0x1__b", "npm/a__0x1__b"}, - {"oci/nginx/sha256:abc/manifest", "oci/nginx/sha256:abc/manifest", "oci/nginx/sha256__0x3a__abc/manifest"}, - {"debian/tzdata/1:2024a-1/x.deb", "debian/tzdata/1:2024a-1/x.deb", "debian/tzdata/1__0x3a__2024a-1/x.deb"}, - {`npm/a\b`, `npm/a\b`, "npm/a__0x5c__b"}, - } { - want := tc.unix - if windows { - want = tc.windows - } - want = filepath.Join(root, filepath.FromSlash(want)) + attrsExt - if got := b.legacySidecarPath(tc.key); got != want { - t.Errorf("legacySidecarPath(%q) = %q, want %q", tc.key, got, want) - } - } -} - -func TestLegacySidecarPathDeclinesNonLocalKeys(t *testing.T) { - b := &Blob{fileRoot: filepath.FromSlash("/var/cache/proxy")} - - for _, key := range []string{"", ".", "..", "/etc/passwd"} { - if got := b.legacySidecarPath(key); got != "" { - t.Errorf("legacySidecarPath(%q) = %q, want \"\"", key, got) - } - } -} - -// Cloud backends have no local directory, so nothing is removed for them. -func TestLegacySidecarPathEmptyForCloudBackends(t *testing.T) { - b := &Blob{} - if got := b.legacySidecarPath("npm/pkg/1.0.0/x.tgz"); got != "" { - t.Errorf("legacySidecarPath = %q, want \"\" when there is no file root", got) - } -} - -// Cleanup that cannot complete must not fail the write. A non-empty directory -// at the sidecar path makes os.Remove fail with something other than not-exist -// on every platform, which is what a Windows sharing violation would look like -// here. -func TestStoreSucceedsWhenSidecarCannotBeRemoved(t *testing.T) { - const key = "npm/pkg/1.0.0/pkg-1.0.0.tgz" - const payload = "payload" - dir := t.TempDir() - ctx := context.Background() - - b := openFileBlob(t, dir) - - sidecar := filepath.Join(dir, filepath.FromSlash(key)) + ".attrs" - if err := os.MkdirAll(filepath.Join(sidecar, "blocker"), 0o750); err != nil { - t.Fatalf("seeding an unremovable sidecar: %v", err) - } - if err := os.Remove(sidecar); err == nil { - t.Fatal("sidecar path was removable, so the test proves nothing") - } - - if _, _, err := b.Store(ctx, key, strings.NewReader(payload)); err != nil { - t.Errorf("Store failed because cleanup could not complete: %v", err) - } -} diff --git a/internal/storage/filesystem.go b/internal/storage/filesystem.go new file mode 100644 index 0000000..cf6a1fe --- /dev/null +++ b/internal/storage/filesystem.go @@ -0,0 +1,182 @@ +package storage + +import ( + "context" + "crypto/sha256" + "encoding/hex" + "fmt" + "io" + "os" + "path/filepath" +) + +// Filesystem implements Storage using the local filesystem. +type Filesystem struct { + root string +} + +// NewFilesystem creates a new filesystem storage rooted at the given directory. +// The directory will be created if it does not exist. +func NewFilesystem(root string) (*Filesystem, error) { + absRoot, err := filepath.Abs(root) + if err != nil { + return nil, fmt.Errorf("resolving root path: %w", err) + } + + if err := os.MkdirAll(absRoot, dirPermissions); err != nil { + return nil, fmt.Errorf("creating root directory: %w", err) + } + + return &Filesystem{root: absRoot}, nil +} + +func (fs *Filesystem) fullPath(path string) string { + return filepath.Join(fs.root, filepath.FromSlash(path)) +} + +func (fs *Filesystem) Store(ctx context.Context, path string, r io.Reader) (int64, string, error) { + fullPath := fs.fullPath(path) + + dir := filepath.Dir(fullPath) + if err := os.MkdirAll(dir, dirPermissions); err != nil { + return 0, "", fmt.Errorf("creating directory: %w", err) + } + + // Write to temp file first for atomic operation + tmpFile, err := os.CreateTemp(dir, ".tmp-*") + if err != nil { + return 0, "", fmt.Errorf("creating temp file: %w", err) + } + tmpPath := tmpFile.Name() + + // Clean up temp file on error + success := false + defer func() { + if !success { + _ = tmpFile.Close() + _ = os.Remove(tmpPath) + } + }() + + // Write content and compute hash + h := sha256.New() + w := io.MultiWriter(tmpFile, h) + + size, err := io.Copy(w, r) + if err != nil { + return 0, "", fmt.Errorf("writing content: %w", err) + } + + if err := tmpFile.Close(); err != nil { + return 0, "", fmt.Errorf("closing temp file: %w", err) + } + + // Atomic rename + if err := os.Rename(tmpPath, fullPath); err != nil { + return 0, "", fmt.Errorf("renaming temp file: %w", err) + } + + success = true + hash := hex.EncodeToString(h.Sum(nil)) + return size, hash, nil +} + +func (fs *Filesystem) Open(ctx context.Context, path string) (io.ReadCloser, error) { + fullPath := fs.fullPath(path) + + f, err := os.Open(fullPath) + if err != nil { + if os.IsNotExist(err) { + return nil, ErrNotFound + } + return nil, fmt.Errorf("opening file: %w", err) + } + + return f, nil +} + +func (fs *Filesystem) Exists(ctx context.Context, path string) (bool, error) { + fullPath := fs.fullPath(path) + + _, err := os.Stat(fullPath) + if err != nil { + if os.IsNotExist(err) { + return false, nil + } + return false, fmt.Errorf("checking file: %w", err) + } + + return true, nil +} + +func (fs *Filesystem) Delete(ctx context.Context, path string) error { + fullPath := fs.fullPath(path) + + err := os.Remove(fullPath) + if err != nil && !os.IsNotExist(err) { + return fmt.Errorf("removing file: %w", err) + } + + // Try to clean up empty parent directories + dir := filepath.Dir(fullPath) + for dir != fs.root { + if err := os.Remove(dir); err != nil { + break // Directory not empty or other error + } + dir = filepath.Dir(dir) + } + + return nil +} + +func (fs *Filesystem) Size(ctx context.Context, path string) (int64, error) { + fullPath := fs.fullPath(path) + + info, err := os.Stat(fullPath) + if err != nil { + if os.IsNotExist(err) { + return 0, ErrNotFound + } + return 0, fmt.Errorf("stat file: %w", err) + } + + return info.Size(), nil +} + +func (fs *Filesystem) UsedSpace(ctx context.Context) (int64, error) { + var total int64 + + err := filepath.Walk(fs.root, func(path string, info os.FileInfo, err error) error { + if err != nil { + return err + } + if !info.IsDir() { + total += info.Size() + } + return nil + }) + if err != nil { + return 0, fmt.Errorf("walking directory: %w", err) + } + + return total, nil +} + +// Root returns the root directory of the storage. +func (fs *Filesystem) Root() string { + return fs.root +} + +// FullPath returns the full filesystem path for a storage path. +// Useful for serving files directly or debugging. +func (fs *Filesystem) FullPath(path string) string { + return fs.fullPath(path) +} + +func (fs *Filesystem) URL() string { + return "file://" + filepath.ToSlash(fs.root) +} + +func (fs *Filesystem) Close() error { + return nil +} diff --git a/internal/storage/filesystem_test.go b/internal/storage/filesystem_test.go new file mode 100644 index 0000000..7fbba10 --- /dev/null +++ b/internal/storage/filesystem_test.go @@ -0,0 +1,248 @@ +package storage + +import ( + "context" + "crypto/sha256" + "encoding/hex" + "errors" + "io" + "os" + "path/filepath" + "strings" + "testing" +) + +func TestNewFilesystem(t *testing.T) { + dir := t.TempDir() + root := filepath.Join(dir, "cache") + + fs, err := NewFilesystem(root) + if err != nil { + t.Fatalf("NewFilesystem failed: %v", err) + } + + if _, err := os.Stat(root); err != nil { + t.Errorf("root directory not created: %v", err) + } + + if fs.Root() != root { + t.Errorf("Root() = %q, want %q", fs.Root(), root) + } +} + +func TestFilesystemStore(t *testing.T) { + fs := createTestFilesystem(t) + ctx := context.Background() + content := "test content for storage" + + size, hash, err := fs.Store(ctx, "npm/lodash/4.17.21/lodash.tgz", strings.NewReader(content)) + if err != nil { + t.Fatalf("Store failed: %v", err) + } + + if size != int64(len(content)) { + t.Errorf("size = %d, want %d", size, len(content)) + } + + h := sha256.Sum256([]byte(content)) + wantHash := hex.EncodeToString(h[:]) + if hash != wantHash { + t.Errorf("hash = %s, want %s", hash, wantHash) + } + + // Verify file exists on disk + fullPath := fs.FullPath("npm/lodash/4.17.21/lodash.tgz") + data, err := os.ReadFile(fullPath) + if err != nil { + t.Fatalf("reading stored file: %v", err) + } + if string(data) != content { + t.Errorf("stored content = %q, want %q", string(data), content) + } +} + +func TestFilesystemStoreAtomic(t *testing.T) { + fs := createTestFilesystem(t) + ctx := context.Background() + + // Store initial content + _, _, err := fs.Store(ctx, "test/file.txt", strings.NewReader("initial")) + if err != nil { + t.Fatalf("initial Store failed: %v", err) + } + + // Overwrite with new content + _, _, err = fs.Store(ctx, "test/file.txt", strings.NewReader("updated")) + if err != nil { + t.Fatalf("update Store failed: %v", err) + } + + // Verify updated content + r, err := fs.Open(ctx, "test/file.txt") + if err != nil { + t.Fatalf("Open failed: %v", err) + } + defer func() { _ = r.Close() }() + + data, _ := io.ReadAll(r) + if string(data) != "updated" { + t.Errorf("content = %q, want %q", string(data), "updated") + } +} + +func TestFilesystemOpen(t *testing.T) { + fs := createTestFilesystem(t) + ctx := context.Background() + content := "readable content" + + _, _, _ = fs.Store(ctx, "test/read.txt", strings.NewReader(content)) + + r, err := fs.Open(ctx, "test/read.txt") + if err != nil { + t.Fatalf("Open failed: %v", err) + } + defer func() { _ = r.Close() }() + + data, err := io.ReadAll(r) + if err != nil { + t.Fatalf("ReadAll failed: %v", err) + } + if string(data) != content { + t.Errorf("content = %q, want %q", string(data), content) + } +} + +func TestFilesystemOpenNotFound(t *testing.T) { + fs := createTestFilesystem(t) + ctx := context.Background() + + _, err := fs.Open(ctx, "does/not/exist.txt") + if !errors.Is(err, ErrNotFound) { + t.Errorf("Open non-existent = %v, want ErrNotFound", err) + } +} + +func TestFilesystemExists(t *testing.T) { + fs := createTestFilesystem(t) + ctx := context.Background() + + exists, err := fs.Exists(ctx, "test/exists.txt") + if err != nil { + t.Fatalf("Exists failed: %v", err) + } + if exists { + t.Error("Exists returned true for non-existent file") + } + + _, _, _ = fs.Store(ctx, "test/exists.txt", strings.NewReader("content")) + + exists, err = fs.Exists(ctx, "test/exists.txt") + if err != nil { + t.Fatalf("Exists after store failed: %v", err) + } + if !exists { + t.Error("Exists returned false for existing file") + } +} + +func TestFilesystemDelete(t *testing.T) { + fs := createTestFilesystem(t) + ctx := context.Background() + + _, _, _ = fs.Store(ctx, "test/delete/nested/file.txt", strings.NewReader("content")) + + err := fs.Delete(ctx, "test/delete/nested/file.txt") + if err != nil { + t.Fatalf("Delete failed: %v", err) + } + + exists, _ := fs.Exists(ctx, "test/delete/nested/file.txt") + if exists { + t.Error("file still exists after delete") + } + + // Empty parent directories should be cleaned up + nestedDir := fs.FullPath("test/delete/nested") + if _, err := os.Stat(nestedDir); !os.IsNotExist(err) { + t.Error("empty nested directory not cleaned up") + } +} + +func TestFilesystemDeleteNotFound(t *testing.T) { + fs := createTestFilesystem(t) + ctx := context.Background() + + // Delete non-existent file should not error + err := fs.Delete(ctx, "does/not/exist.txt") + if err != nil { + t.Errorf("Delete non-existent = %v, want nil", err) + } +} + +func TestFilesystemSize(t *testing.T) { + fs := createTestFilesystem(t) + ctx := context.Background() + content := "size test content" + + _, _, _ = fs.Store(ctx, "test/size.txt", strings.NewReader(content)) + + size, err := fs.Size(ctx, "test/size.txt") + if err != nil { + t.Fatalf("Size failed: %v", err) + } + if size != int64(len(content)) { + t.Errorf("Size = %d, want %d", size, len(content)) + } +} + +func TestFilesystemSizeNotFound(t *testing.T) { + fs := createTestFilesystem(t) + ctx := context.Background() + + _, err := fs.Size(ctx, "does/not/exist.txt") + if !errors.Is(err, ErrNotFound) { + t.Errorf("Size non-existent = %v, want ErrNotFound", err) + } +} + +func TestFilesystemUsedSpace(t *testing.T) { + fs := createTestFilesystem(t) + ctx := context.Background() + + // Empty storage + used, err := fs.UsedSpace(ctx) + if err != nil { + t.Fatalf("UsedSpace failed: %v", err) + } + if used != 0 { + t.Errorf("UsedSpace empty = %d, want 0", used) + } + + // Add some files + _, _, _ = fs.Store(ctx, "a.txt", strings.NewReader("aaaa")) // 4 bytes + _, _, _ = fs.Store(ctx, "b.txt", strings.NewReader("bbbbbb")) // 6 bytes + _, _, _ = fs.Store(ctx, "c/d.txt", strings.NewReader("ccccc")) // 5 bytes + + used, err = fs.UsedSpace(ctx) + if err != nil { + t.Fatalf("UsedSpace failed: %v", err) + } + if used != 15 { + t.Errorf("UsedSpace = %d, want 15", used) + } +} + +func TestFilesystemLargeFile(t *testing.T) { + assertLargeFileRoundTrip(t, createTestFilesystem(t)) +} + +func createTestFilesystem(t *testing.T) *Filesystem { + t.Helper() + dir := t.TempDir() + + fs, err := NewFilesystem(dir) + if err != nil { + t.Fatalf("NewFilesystem failed: %v", err) + } + return fs +} diff --git a/internal/storage/gcs.go b/internal/storage/gcs.go deleted file mode 100644 index a096c18..0000000 --- a/internal/storage/gcs.go +++ /dev/null @@ -1,97 +0,0 @@ -package storage - -import ( - "context" - "crypto/sha256" - "encoding/hex" - "errors" - "io" - "time" - - gcstorage "github.com/git-pkgs/gcs" -) - -// GCS adapts a Google Cloud Storage bucket to Storage. -type GCS struct { - bucket *gcstorage.Bucket - url string -} - -// OpenGCS opens a Google Cloud Storage bucket from a gs:// URL. -func OpenGCS(ctx context.Context, urlStr string) (*GCS, error) { - bucket, err := gcstorage.OpenBucket(ctx, urlStr) - if err != nil { - return nil, err - } - return &GCS{bucket: bucket, url: urlStr}, nil -} - -func (g *GCS) Store(ctx context.Context, path string, r io.Reader) (int64, string, error) { - h := sha256.New() - size, err := g.bucket.Write(ctx, path, io.TeeReader(r, h)) - if err != nil { - return 0, "", err - } - return size, hex.EncodeToString(h.Sum(nil)), nil -} - -func (g *GCS) Open(ctx context.Context, path string) (io.ReadCloser, error) { - r, err := g.bucket.Open(ctx, path) - if errors.Is(err, gcstorage.ErrNotFound) { - return nil, ErrNotFound - } - return r, err -} - -func (g *GCS) Exists(ctx context.Context, path string) (bool, error) { - return g.bucket.Exists(ctx, path) -} - -func (g *GCS) Delete(ctx context.Context, path string) error { - return g.bucket.Delete(ctx, path) -} - -func (g *GCS) Size(ctx context.Context, path string) (int64, error) { - size, err := g.bucket.Size(ctx, path) - if errors.Is(err, gcstorage.ErrNotFound) { - return 0, ErrNotFound - } - return size, err -} - -func (g *GCS) SignedURL(ctx context.Context, path string, expiry time.Duration) (string, error) { - u, err := g.bucket.SignedURL(ctx, path, expiry) - if errors.Is(err, gcstorage.ErrSignedURLUnsupported) { - return "", ErrSignedURLUnsupported - } - return u, err -} - -func (g *GCS) UsedSpace(ctx context.Context) (int64, error) { - return g.bucket.UsedSpace(ctx) -} - -func (g *GCS) ListPrefix(ctx context.Context, prefix string) ([]ObjectInfo, error) { - objects, err := g.bucket.ListPrefix(ctx, prefix) - if err != nil { - return nil, err - } - - result := make([]ObjectInfo, 0, len(objects)) - for _, object := range objects { - result = append(result, ObjectInfo{ - Path: object.Name, - Size: object.Size, - ModTime: object.ModTime, - }) - } - return result, nil -} - -func (g *GCS) Close() error { - return nil -} - -func (g *GCS) URL() string { - return g.url -} diff --git a/internal/storage/gcs_test.go b/internal/storage/gcs_test.go deleted file mode 100644 index 1dfd0a2..0000000 --- a/internal/storage/gcs_test.go +++ /dev/null @@ -1,152 +0,0 @@ -package storage - -import ( - "context" - "crypto/sha256" - "encoding/hex" - "encoding/json" - "errors" - "io" - "net/http" - "net/http/httptest" - "net/url" - "sort" - "strconv" - "strings" - "testing" - "time" -) - -func TestOpenBucketGCSRoundTripWithEmulator(t *testing.T) { - server := httptest.NewServer(&fakeGCSServer{t: t, objects: map[string]string{}}) - defer server.Close() - t.Setenv("STORAGE_EMULATOR_HOST", server.URL) - - ctx := context.Background() - store, err := OpenBucket(ctx, "gs://test-bucket") - if err != nil { - t.Fatalf("OpenBucket failed: %v", err) - } - - size, hash, err := store.Store(ctx, "npm/pkg/file.tgz", strings.NewReader("content")) - if err != nil { - t.Fatalf("Store failed: %v", err) - } - wantHash := sha256.Sum256([]byte("content")) - if size != int64(len("content")) || hash != hex.EncodeToString(wantHash[:]) { - t.Fatalf("Store returned size=%d hash=%q", size, hash) - } - - exists, err := store.Exists(ctx, "npm/pkg/file.tgz") - if err != nil || !exists { - t.Fatalf("Exists = %v, %v; want true, nil", exists, err) - } - - r, err := store.Open(ctx, "npm/pkg/file.tgz") - if err != nil { - t.Fatalf("Open failed: %v", err) - } - data, _ := io.ReadAll(r) - _ = r.Close() - if string(data) != "content" { - t.Fatalf("Open content = %q, want content", data) - } - - lister, ok := store.(interface { - ListPrefix(context.Context, string) ([]ObjectInfo, error) - }) - if !ok { - t.Fatal("GCS storage does not support prefix listing") - } - list, err := lister.ListPrefix(ctx, "npm/") - if err != nil { - t.Fatalf("ListPrefix failed: %v", err) - } - if len(list) != 1 || list[0].Path != "npm/pkg/file.tgz" { - t.Fatalf("ListPrefix = %#v", list) - } - - if err := store.Delete(ctx, "npm/pkg/file.tgz"); err != nil { - t.Fatalf("Delete failed: %v", err) - } - exists, err = store.Exists(ctx, "npm/pkg/file.tgz") - if err != nil || exists { - t.Fatalf("Exists after delete = %v, %v; want false, nil", exists, err) - } - - reader, err := store.Open(ctx, "npm/pkg/file.tgz") - if reader != nil || !errors.Is(err, ErrNotFound) { - t.Fatalf("Open missing object = %v, %v; want nil, ErrNotFound", reader, err) - } - if _, err := store.Size(ctx, "npm/pkg/file.tgz"); !errors.Is(err, ErrNotFound) { - t.Fatalf("Size missing object = %v, want ErrNotFound", err) - } - if _, err := store.SignedURL(ctx, "npm/pkg/file.tgz", time.Minute); !errors.Is(err, ErrSignedURLUnsupported) { - t.Fatalf("SignedURL with emulator = %v, want ErrSignedURLUnsupported", err) - } -} - -type fakeGCSServer struct { - t *testing.T - objects map[string]string -} - -func (f *fakeGCSServer) ServeHTTP(w http.ResponseWriter, r *http.Request) { - switch { - case r.Method == http.MethodPost && r.URL.Path == "/upload/storage/v1/b/test-bucket/o": - name := r.URL.Query().Get("name") - data, _ := io.ReadAll(r.Body) - f.objects[name] = string(data) - writeJSON(w, fakeGCSObject{Name: name, Size: strconv.Itoa(len(data)), Updated: time.Now().UTC().Format(time.RFC3339Nano)}) - case r.Method == http.MethodGet && r.URL.Path == "/storage/v1/b/test-bucket/o": - prefix := r.URL.Query().Get("prefix") - page := fakeGCSListResponse{} - for name, data := range f.objects { - if strings.HasPrefix(name, prefix) { - page.Items = append(page.Items, fakeGCSObject{Name: name, Size: strconv.Itoa(len(data)), Updated: time.Now().UTC().Format(time.RFC3339Nano)}) - } - } - sort.Slice(page.Items, func(i, j int) bool { return page.Items[i].Name < page.Items[j].Name }) - writeJSON(w, page) - case r.Method == http.MethodGet && strings.HasPrefix(r.URL.Path, "/storage/v1/b/test-bucket/o/"): - name := objectNameFromPath(r.URL.Path) - data, ok := f.objects[name] - if !ok { - http.NotFound(w, r) - return - } - if r.URL.Query().Get("alt") == "media" { - _, _ = io.WriteString(w, data) - return - } - writeJSON(w, fakeGCSObject{Name: name, Size: strconv.Itoa(len(data)), Updated: time.Now().UTC().Format(time.RFC3339Nano)}) - case r.Method == http.MethodDelete && strings.HasPrefix(r.URL.Path, "/storage/v1/b/test-bucket/o/"): - delete(f.objects, objectNameFromPath(r.URL.Path)) - w.WriteHeader(http.StatusNoContent) - default: - f.t.Errorf("unexpected request: %s %s", r.Method, r.URL.String()) - http.Error(w, "unexpected request", http.StatusInternalServerError) - } -} - -type fakeGCSObject struct { - Name string `json:"name"` - Size string `json:"size"` - Updated string `json:"updated"` -} - -type fakeGCSListResponse struct { - NextPageToken string `json:"nextPageToken"` - Items []fakeGCSObject `json:"items"` -} - -func writeJSON(w http.ResponseWriter, v any) { - w.Header().Set("Content-Type", "application/json") - _ = json.NewEncoder(w).Encode(v) -} - -func objectNameFromPath(p string) string { - escaped := strings.TrimPrefix(p, "/storage/v1/b/test-bucket/o/") - name, _ := url.PathUnescape(escaped) - return name -} diff --git a/internal/storage/storage.go b/internal/storage/storage.go index 5ff86f2..8a9026c 100644 --- a/internal/storage/storage.go +++ b/internal/storage/storage.go @@ -5,37 +5,24 @@ // - file:///path/to/dir - Local filesystem storage // - s3://bucket-name - Amazon S3 // - s3://bucket?endpoint=http://localhost:9000 - S3-compatible (MinIO) -// - gs://bucket-name - Google Cloud Storage (supports GKE Workload Identity -// via Application Default Credentials) -// - azblob://container-name - Azure Blob Storage // // Use OpenBucket to create a storage backend from a URL. package storage import ( "context" + "crypto/sha256" + "encoding/hex" "errors" "io" - "time" ) const dirPermissions = 0755 var ( ErrNotFound = errors.New("artifact not found") - - // ErrSignedURLUnsupported is returned by SignedURL when the backend - // cannot generate presigned URLs (e.g. local filesystem). - ErrSignedURLUnsupported = errors.New("signed URLs not supported by storage backend") ) -// ObjectInfo contains metadata for a stored object. -type ObjectInfo struct { - Path string - Size int64 - ModTime time.Time -} - // Storage defines the interface for artifact storage backends. type Storage interface { // Store writes content from r to the given path. @@ -58,10 +45,6 @@ type Storage interface { // Returns ErrNotFound if the path does not exist. Size(ctx context.Context, path string) (int64, error) - // SignedURL returns a presigned URL granting time-limited GET access to path. - // Returns ErrSignedURLUnsupported if the backend cannot generate presigned URLs. - SignedURL(ctx context.Context, path string, expiry time.Duration) (string, error) - // UsedSpace returns the total bytes used by all stored content. UsedSpace(ctx context.Context) (int64, error) @@ -81,3 +64,42 @@ func ArtifactPath(ecosystem, namespace, name, version, filename string) string { } return ecosystem + "/" + name + "/" + version + "/" + filename } + +// HashingReader wraps a reader and computes SHA256 hash as content is read. +type HashingReader struct { + r io.Reader + hash []byte + h interface{ Sum([]byte) []byte } + size int64 + done bool +} + +func NewHashingReader(r io.Reader) *HashingReader { + h := sha256.New() + return &HashingReader{ + r: io.TeeReader(r, h), + h: h, + } +} + +func (hr *HashingReader) Read(p []byte) (n int, err error) { + n, err = hr.r.Read(p) + hr.size += int64(n) + if err == io.EOF { + hr.done = true + hr.hash = hr.h.Sum(nil) + } + return +} + +func (hr *HashingReader) Sum() string { + if !hr.done { + hr.hash = hr.h.Sum(nil) + hr.done = true + } + return hex.EncodeToString(hr.hash) +} + +func (hr *HashingReader) Size() int64 { + return hr.size +} diff --git a/internal/storage/storage_test.go b/internal/storage/storage_test.go index 65f5a23..97800f0 100644 --- a/internal/storage/storage_test.go +++ b/internal/storage/storage_test.go @@ -6,6 +6,7 @@ import ( "crypto/sha256" "encoding/hex" "io" + "strings" "testing" ) @@ -34,6 +35,30 @@ func TestArtifactPath(t *testing.T) { } } +func TestHashingReader(t *testing.T) { + content := "hello world" + r := NewHashingReader(strings.NewReader(content)) + + data, err := io.ReadAll(r) + if err != nil { + t.Fatalf("ReadAll failed: %v", err) + } + + if string(data) != content { + t.Errorf("got content %q, want %q", string(data), content) + } + + if r.Size() != int64(len(content)) { + t.Errorf("got size %d, want %d", r.Size(), len(content)) + } + + h := sha256.Sum256([]byte(content)) + wantHash := hex.EncodeToString(h[:]) + if r.Sum() != wantHash { + t.Errorf("got hash %s, want %s", r.Sum(), wantHash) + } +} + // assertLargeFileRoundTrip stores a 1MB file in the given storage, verifies size and // hash, then reads it back and confirms the content matches. func assertLargeFileRoundTrip(t *testing.T, s Storage) {