mirror of
https://github.com/git-pkgs/proxy.git
synced 2026-09-16 15:52:05 -04:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c07c59c83e |
194 changed files with 3478 additions and 41454 deletions
8
.github/dependabot.yml
vendored
8
.github/dependabot.yml
vendored
|
|
@ -8,14 +8,6 @@ updates:
|
||||||
cooldown:
|
cooldown:
|
||||||
default-days: 7
|
default-days: 7
|
||||||
|
|
||||||
- package-ecosystem: docker
|
|
||||||
directory: /
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
open-pull-requests-limit: 5
|
|
||||||
cooldown:
|
|
||||||
default-days: 7
|
|
||||||
|
|
||||||
- package-ecosystem: github-actions
|
- package-ecosystem: github-actions
|
||||||
directory: /
|
directory: /
|
||||||
schedule:
|
schedule:
|
||||||
|
|
|
||||||
41
.github/workflows/ci.yml
vendored
41
.github/workflows/ci.yml
vendored
|
|
@ -13,17 +13,18 @@ jobs:
|
||||||
strategy:
|
strategy:
|
||||||
matrix:
|
matrix:
|
||||||
os: [ubuntu-latest, macos-latest, windows-latest]
|
os: [ubuntu-latest, macos-latest, windows-latest]
|
||||||
|
go-version: ['1.25']
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
with:
|
with:
|
||||||
persist-credentials: false
|
persist-credentials: false
|
||||||
|
|
||||||
- name: Set up Go
|
- name: Set up Go
|
||||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
|
||||||
with:
|
with:
|
||||||
go-version-file: go.mod
|
go-version: ${{ matrix.go-version }}
|
||||||
|
|
||||||
- name: Build
|
- name: Build
|
||||||
run: go build -v ./...
|
run: go build -v ./...
|
||||||
|
|
@ -34,42 +35,14 @@ jobs:
|
||||||
lint:
|
lint:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
with:
|
with:
|
||||||
persist-credentials: false
|
persist-credentials: false
|
||||||
|
|
||||||
- name: Set up Go
|
- name: Set up Go
|
||||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
|
||||||
with:
|
with:
|
||||||
go-version-file: go.mod
|
go-version: '1.25'
|
||||||
|
|
||||||
- name: golangci-lint
|
- name: golangci-lint
|
||||||
run: go tool golangci-lint run ./...
|
run: go tool golangci-lint run ./...
|
||||||
|
|
||||||
helm:
|
|
||||||
name: Helm chart
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
|
|
||||||
with:
|
|
||||||
version: v3.18.6
|
|
||||||
|
|
||||||
- name: Lint chart
|
|
||||||
run: helm lint deploy/charts/proxy
|
|
||||||
|
|
||||||
- name: Render chart variants
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
helm template proxy deploy/charts/proxy >/dev/null
|
|
||||||
helm template proxy deploy/charts/proxy \
|
|
||||||
--set persistence.enabled=false \
|
|
||||||
--set config.existingConfigMap=proxy-config \
|
|
||||||
--set ingress.enabled=true \
|
|
||||||
--set 'ingress.hosts[0].host=proxy.example.com' \
|
|
||||||
--set 'ingress.hosts[0].paths[0].path=/' \
|
|
||||||
--set 'ingress.hosts[0].paths[0].pathType=Prefix' \
|
|
||||||
>/dev/null
|
|
||||||
|
|
|
||||||
161
.github/workflows/publish.yml
vendored
161
.github/workflows/publish.yml
vendored
|
|
@ -1,161 +0,0 @@
|
||||||
name: Publish Docker image
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
push:
|
|
||||||
tags:
|
|
||||||
- "v*"
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
concurrency:
|
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
push_to_registry:
|
|
||||||
name: Push Docker image to GHCR
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
packages: write
|
|
||||||
contents: read
|
|
||||||
id-token: write
|
|
||||||
steps:
|
|
||||||
- name: Check out the repo
|
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- name: Set up QEMU
|
|
||||||
uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4.3.0
|
|
||||||
with:
|
|
||||||
platforms: linux/amd64,linux/arm64
|
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
|
||||||
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
|
|
||||||
|
|
||||||
- name: Log in to the Container registry
|
|
||||||
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f
|
|
||||||
with:
|
|
||||||
registry: ghcr.io
|
|
||||||
username: ${{ github.actor }}
|
|
||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
|
|
||||||
- name: Extract metadata (tags, labels) for Docker
|
|
||||||
id: meta
|
|
||||||
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302
|
|
||||||
with:
|
|
||||||
images: ghcr.io/${{ github.repository }}
|
|
||||||
|
|
||||||
- uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
|
|
||||||
|
|
||||||
- name: Build and push Docker image
|
|
||||||
id: build
|
|
||||||
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a
|
|
||||||
with:
|
|
||||||
context: .
|
|
||||||
platforms: linux/amd64,linux/arm64
|
|
||||||
push: true
|
|
||||||
tags: ${{ steps.meta.outputs.tags }}
|
|
||||||
labels: ${{ steps.meta.outputs.labels }}
|
|
||||||
provenance: mode=max
|
|
||||||
sbom: true
|
|
||||||
|
|
||||||
- name: Sign image by digest
|
|
||||||
env:
|
|
||||||
DIGEST: ${{ steps.build.outputs.digest }}
|
|
||||||
IMAGE: ghcr.io/${{ github.repository }}
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
[[ "$DIGEST" =~ ^sha256:[0-9a-f]{64}$ ]]
|
|
||||||
cosign sign --yes "${IMAGE}@${DIGEST}"
|
|
||||||
|
|
||||||
- name: Verify BuildKit attestations and extract SPDX predicates
|
|
||||||
env:
|
|
||||||
DIGEST: ${{ steps.build.outputs.digest }}
|
|
||||||
IMAGE: ghcr.io/${{ github.repository }}
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
reference="${IMAGE}@${DIGEST}"
|
|
||||||
docker buildx imagetools inspect "$reference" --format '{{ json .Provenance }}' > provenance.json
|
|
||||||
docker buildx imagetools inspect "$reference" --format '{{ json .SBOM }}' > sbom.json
|
|
||||||
|
|
||||||
for platform in linux/amd64 linux/arm64; do
|
|
||||||
jq -e --arg p "$platform" '.[$p].SLSA | type == "object" and length > 0' \
|
|
||||||
provenance.json >/dev/null
|
|
||||||
jq -e --arg p "$platform" '.[$p].SPDX' sbom.json > "sbom-${platform//\//-}.spdx.json"
|
|
||||||
done
|
|
||||||
|
|
||||||
- name: Attest platform SBOMs by digest
|
|
||||||
env:
|
|
||||||
DIGEST: ${{ steps.build.outputs.digest }}
|
|
||||||
IMAGE: ghcr.io/${{ github.repository }}
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
[[ "$DIGEST" =~ ^sha256:[0-9a-f]{64}$ ]]
|
|
||||||
reference="${IMAGE}@${DIGEST}"
|
|
||||||
for predicate in sbom-linux-amd64.spdx.json sbom-linux-arm64.spdx.json; do
|
|
||||||
cosign attest --yes --type spdxjson --predicate "$predicate" "$reference"
|
|
||||||
done
|
|
||||||
|
|
||||||
publish_chart:
|
|
||||||
name: Push Helm chart to GHCR
|
|
||||||
if: github.ref_type == 'tag'
|
|
||||||
needs: push_to_registry
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
packages: write
|
|
||||||
steps:
|
|
||||||
- name: Check out the repo
|
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
ref: ${{ github.sha }}
|
|
||||||
|
|
||||||
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
|
|
||||||
with:
|
|
||||||
version: v3.18.6
|
|
||||||
|
|
||||||
- name: Validate and normalize release version
|
|
||||||
id: version
|
|
||||||
env:
|
|
||||||
TAG: ${{ github.ref_name }}
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
semver='^v(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)(-((0|[1-9][0-9]*|[0-9]*[A-Za-z-][0-9A-Za-z-]*)(\.(0|[1-9][0-9]*|[0-9]*[A-Za-z-][0-9A-Za-z-]*))*))?$'
|
|
||||||
[[ "$TAG" =~ $semver ]] || {
|
|
||||||
echo "Tag must be strict SemVer of the form vMAJOR.MINOR.PATCH[-PRERELEASE]: $TAG" >&2
|
|
||||||
exit 1
|
|
||||||
}
|
|
||||||
version="${TAG#v}"
|
|
||||||
[[ "$version" != "0.0.0" ]] || {
|
|
||||||
echo "0.0.0 is a development placeholder and must not be published" >&2
|
|
||||||
exit 1
|
|
||||||
}
|
|
||||||
echo "version=$version" >> "$GITHUB_OUTPUT"
|
|
||||||
|
|
||||||
- name: Log in to GHCR
|
|
||||||
env:
|
|
||||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
run: printf '%s' "$GH_TOKEN" | helm registry login ghcr.io --username "$GITHUB_ACTOR" --password-stdin
|
|
||||||
|
|
||||||
- name: Lint and package chart
|
|
||||||
env:
|
|
||||||
VERSION: ${{ steps.version.outputs.version }}
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
helm lint deploy/charts/proxy
|
|
||||||
mkdir -p build
|
|
||||||
helm package \
|
|
||||||
--destination build \
|
|
||||||
--version "$VERSION" \
|
|
||||||
--app-version "$VERSION" \
|
|
||||||
deploy/charts/proxy
|
|
||||||
metadata="$(helm show chart "build/proxy-${VERSION}.tgz")"
|
|
||||||
[[ "$(awk '$1 == "version:" {print $2}' <<<"$metadata")" == "$VERSION" ]]
|
|
||||||
[[ "$(awk '$1 == "appVersion:" {gsub(/\"/, "", $2); print $2}' <<<"$metadata")" == "$VERSION" ]]
|
|
||||||
|
|
||||||
- name: Push chart
|
|
||||||
env:
|
|
||||||
VERSION: ${{ steps.version.outputs.version }}
|
|
||||||
run: helm push "build/proxy-${VERSION}.tgz" oci://ghcr.io/git-pkgs/charts
|
|
||||||
9
.github/workflows/release.yml
vendored
9
.github/workflows/release.yml
vendored
|
|
@ -7,27 +7,24 @@ on:
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
id-token: write
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
release:
|
release:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
persist-credentials: false
|
persist-credentials: false
|
||||||
|
|
||||||
- uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
|
|
||||||
|
|
||||||
- name: Set up Go
|
- name: Set up Go
|
||||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
|
||||||
with:
|
with:
|
||||||
go-version-file: go.mod
|
go-version-file: go.mod
|
||||||
cache: false
|
cache: false
|
||||||
|
|
||||||
- uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
|
- uses: goreleaser/goreleaser-action@ec59f474b9834571250b370d4735c50f8e2d1e29 # v7.0.0
|
||||||
with:
|
with:
|
||||||
version: "~> v2"
|
version: "~> v2"
|
||||||
args: release --clean
|
args: release --clean
|
||||||
|
|
|
||||||
36
.github/workflows/swagger.yml
vendored
36
.github/workflows/swagger.yml
vendored
|
|
@ -1,36 +0,0 @@
|
||||||
name: Swagger
|
|
||||||
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
branches: [main]
|
|
||||||
push:
|
|
||||||
branches: [main]
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
swagger:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- name: Set up Go
|
|
||||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
|
||||||
with:
|
|
||||||
go-version-file: go.mod
|
|
||||||
|
|
||||||
- name: Install swag
|
|
||||||
run: go install github.com/swaggo/swag/cmd/swag@latest
|
|
||||||
|
|
||||||
- name: Generate swagger
|
|
||||||
run: go generate ./internal/server
|
|
||||||
|
|
||||||
- name: Verify no changes
|
|
||||||
run: |
|
|
||||||
if [ -n "$(git status --porcelain)" ]; then
|
|
||||||
echo "Swagger docs are out of date. Run: go generate ./internal/server" >&2
|
|
||||||
git status --porcelain
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
4
.github/workflows/zizmor.yml
vendored
4
.github/workflows/zizmor.yml
vendored
|
|
@ -21,9 +21,9 @@ jobs:
|
||||||
security-events: write
|
security-events: write
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
with:
|
with:
|
||||||
persist-credentials: false
|
persist-credentials: false
|
||||||
|
|
||||||
- name: Run zizmor
|
- name: Run zizmor
|
||||||
uses: zizmorcore/zizmor-action@70fb788f84895a7701f5643d103d587e460b5c99 # v0.6.3
|
uses: zizmorcore/zizmor-action@0dce2577a4760a2749d8cfb7a84b7d5585ebcb7d # v0.5.0
|
||||||
|
|
|
||||||
8
.gitignore
vendored
8
.gitignore
vendored
|
|
@ -4,7 +4,7 @@
|
||||||
*.dll
|
*.dll
|
||||||
*.so
|
*.so
|
||||||
*.dylib
|
*.dylib
|
||||||
/proxy
|
proxy
|
||||||
|
|
||||||
# Test binary, built with `go test -c`
|
# Test binary, built with `go test -c`
|
||||||
*.test
|
*.test
|
||||||
|
|
@ -14,8 +14,8 @@
|
||||||
coverage.html
|
coverage.html
|
||||||
coverage.txt
|
coverage.txt
|
||||||
|
|
||||||
# Go vendor directory (repo root only; embedded UI vendor dirs are tracked)
|
# Dependency directories
|
||||||
/vendor/
|
vendor/
|
||||||
|
|
||||||
# Go workspace file
|
# Go workspace file
|
||||||
go.work
|
go.work
|
||||||
|
|
@ -43,4 +43,4 @@ cache/*
|
||||||
|
|
||||||
# Debug files
|
# Debug files
|
||||||
__debug_bin
|
__debug_bin
|
||||||
debug
|
debug
|
||||||
|
|
@ -1,28 +0,0 @@
|
||||||
version: "2"
|
|
||||||
|
|
||||||
linters:
|
|
||||||
enable:
|
|
||||||
- gocritic
|
|
||||||
- gocognit
|
|
||||||
- gocyclo
|
|
||||||
- maintidx
|
|
||||||
- dupl
|
|
||||||
- mnd
|
|
||||||
- unparam
|
|
||||||
- ireturn
|
|
||||||
- goconst
|
|
||||||
- errcheck
|
|
||||||
settings:
|
|
||||||
goconst:
|
|
||||||
min-len: 4
|
|
||||||
min-occurrences: 5
|
|
||||||
ignore-tests: true
|
|
||||||
ignore-string-values:
|
|
||||||
- "^[a-z]+$"
|
|
||||||
exclusions:
|
|
||||||
rules:
|
|
||||||
- path: _test\.go
|
|
||||||
linters:
|
|
||||||
- goconst
|
|
||||||
- dupl
|
|
||||||
- mnd
|
|
||||||
|
|
@ -34,17 +34,6 @@ archives:
|
||||||
checksum:
|
checksum:
|
||||||
name_template: "checksums.txt"
|
name_template: "checksums.txt"
|
||||||
|
|
||||||
signs:
|
|
||||||
- cmd: cosign
|
|
||||||
signature: "${artifact}.cosign.bundle"
|
|
||||||
args:
|
|
||||||
- sign-blob
|
|
||||||
- "--bundle=${signature}"
|
|
||||||
- "${artifact}"
|
|
||||||
- "--yes"
|
|
||||||
artifacts: checksum
|
|
||||||
output: true
|
|
||||||
|
|
||||||
snapshot:
|
snapshot:
|
||||||
version_template: "{{ incpatch .Version }}-next"
|
version_template: "{{ incpatch .Version }}-next"
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -39,7 +39,7 @@ proxy/
|
||||||
│ │ └── queries.go # CRUD operations
|
│ │ └── queries.go # CRUD operations
|
||||||
│ ├── storage/ # Artifact file storage
|
│ ├── storage/ # Artifact file storage
|
||||||
│ │ ├── storage.go # Storage interface
|
│ │ ├── storage.go # Storage interface
|
||||||
│ │ └── blob.go # gocloud.dev/blob backends (file, S3, Azure)
|
│ │ └── filesystem.go # Local filesystem impl
|
||||||
│ ├── upstream/ # Upstream registry clients
|
│ ├── upstream/ # Upstream registry clients
|
||||||
│ │ ├── fetcher.go # HTTP artifact fetching
|
│ │ ├── fetcher.go # HTTP artifact fetching
|
||||||
│ │ └── resolver.go # Download URL resolution
|
│ │ └── resolver.go # Download URL resolution
|
||||||
|
|
@ -72,7 +72,7 @@ Key types:
|
||||||
|
|
||||||
### `internal/storage`
|
### `internal/storage`
|
||||||
|
|
||||||
Artifact file storage abstraction backed by `gocloud.dev/blob`. Supports local filesystem (`file://`), S3 (`s3://`), and Azure (`azblob://`) URLs.
|
Artifact file storage abstraction. Currently implements local filesystem storage. Designed to allow future backends (S3, GCS).
|
||||||
|
|
||||||
Interface:
|
Interface:
|
||||||
```go
|
```go
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,4 @@
|
||||||
FROM --platform=$BUILDPLATFORM golang:1.26.7-alpine AS builder
|
FROM golang:1.24-alpine AS builder
|
||||||
|
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
|
|
||||||
|
|
@ -12,11 +12,10 @@ RUN go mod download
|
||||||
# Copy source code
|
# Copy source code
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
# Build the binary for the target platform
|
# Build the binary
|
||||||
ARG TARGETARCH
|
RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w" -o /proxy ./cmd/proxy
|
||||||
RUN CGO_ENABLED=0 GOOS=linux GOARCH=${TARGETARCH} go build -ldflags="-s -w" -o /proxy ./cmd/proxy
|
|
||||||
|
|
||||||
FROM alpine:3.24.1
|
FROM alpine:3.21
|
||||||
|
|
||||||
RUN apk add --no-cache ca-certificates
|
RUN apk add --no-cache ca-certificates
|
||||||
|
|
||||||
|
|
|
||||||
232
LICENSE
232
LICENSE
|
|
@ -1,232 +0,0 @@
|
||||||
GNU GENERAL PUBLIC LICENSE
|
|
||||||
Version 3, 29 June 2007
|
|
||||||
|
|
||||||
Copyright © 2007 Free Software Foundation, Inc. <https://fsf.org/>
|
|
||||||
|
|
||||||
Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed.
|
|
||||||
|
|
||||||
Preamble
|
|
||||||
|
|
||||||
The GNU General Public License is a free, copyleft license for software and other kinds of works.
|
|
||||||
|
|
||||||
The licenses for most software and other practical works are designed to take away your freedom to share and change the works. By contrast, the GNU General Public License is intended to guarantee your freedom to share and change all versions of a program--to make sure it remains free software for all its users. We, the Free Software Foundation, use the GNU General Public License for most of our software; it applies also to any other work released this way by its authors. You can apply it to your programs, too.
|
|
||||||
|
|
||||||
When we speak of free software, we are referring to freedom, not price. Our General Public Licenses are designed to make sure that you have the freedom to distribute copies of free software (and charge for them if you wish), that you receive source code or can get it if you want it, that you can change the software or use pieces of it in new free programs, and that you know you can do these things.
|
|
||||||
|
|
||||||
To protect your rights, we need to prevent others from denying you these rights or asking you to surrender the rights. Therefore, you have certain responsibilities if you distribute copies of the software, or if you modify it: responsibilities to respect the freedom of others.
|
|
||||||
|
|
||||||
For example, if you distribute copies of such a program, whether gratis or for a fee, you must pass on to the recipients the same freedoms that you received. You must make sure that they, too, receive or can get the source code. And you must show them these terms so they know their rights.
|
|
||||||
|
|
||||||
Developers that use the GNU GPL protect your rights with two steps: (1) assert copyright on the software, and (2) offer you this License giving you legal permission to copy, distribute and/or modify it.
|
|
||||||
|
|
||||||
For the developers' and authors' protection, the GPL clearly explains that there is no warranty for this free software. For both users' and authors' sake, the GPL requires that modified versions be marked as changed, so that their problems will not be attributed erroneously to authors of previous versions.
|
|
||||||
|
|
||||||
Some devices are designed to deny users access to install or run modified versions of the software inside them, although the manufacturer can do so. This is fundamentally incompatible with the aim of protecting users' freedom to change the software. The systematic pattern of such abuse occurs in the area of products for individuals to use, which is precisely where it is most unacceptable. Therefore, we have designed this version of the GPL to prohibit the practice for those products. If such problems arise substantially in other domains, we stand ready to extend this provision to those domains in future versions of the GPL, as needed to protect the freedom of users.
|
|
||||||
|
|
||||||
Finally, every program is threatened constantly by software patents. States should not allow patents to restrict development and use of software on general-purpose computers, but in those that do, we wish to avoid the special danger that patents applied to a free program could make it effectively proprietary. To prevent this, the GPL assures that patents cannot be used to render the program non-free.
|
|
||||||
|
|
||||||
The precise terms and conditions for copying, distribution and modification follow.
|
|
||||||
|
|
||||||
TERMS AND CONDITIONS
|
|
||||||
|
|
||||||
0. Definitions.
|
|
||||||
|
|
||||||
“This License” refers to version 3 of the GNU General Public License.
|
|
||||||
|
|
||||||
“Copyright” also means copyright-like laws that apply to other kinds of works, such as semiconductor masks.
|
|
||||||
|
|
||||||
“The Program” refers to any copyrightable work licensed under this License. Each licensee is addressed as “you”. “Licensees” and “recipients” may be individuals or organizations.
|
|
||||||
|
|
||||||
To “modify” a work means to copy from or adapt all or part of the work in a fashion requiring copyright permission, other than the making of an exact copy. The resulting work is called a “modified version” of the earlier work or a work “based on” the earlier work.
|
|
||||||
|
|
||||||
A “covered work” means either the unmodified Program or a work based on the Program.
|
|
||||||
|
|
||||||
To “propagate” a work means to do anything with it that, without permission, would make you directly or secondarily liable for infringement under applicable copyright law, except executing it on a computer or modifying a private copy. Propagation includes copying, distribution (with or without modification), making available to the public, and in some countries other activities as well.
|
|
||||||
|
|
||||||
To “convey” a work means any kind of propagation that enables other parties to make or receive copies. Mere interaction with a user through a computer network, with no transfer of a copy, is not conveying.
|
|
||||||
|
|
||||||
An interactive user interface displays “Appropriate Legal Notices” to the extent that it includes a convenient and prominently visible feature that (1) displays an appropriate copyright notice, and (2) tells the user that there is no warranty for the work (except to the extent that warranties are provided), that licensees may convey the work under this License, and how to view a copy of this License. If the interface presents a list of user commands or options, such as a menu, a prominent item in the list meets this criterion.
|
|
||||||
|
|
||||||
1. Source Code.
|
|
||||||
The “source code” for a work means the preferred form of the work for making modifications to it. “Object code” means any non-source form of a work.
|
|
||||||
|
|
||||||
A “Standard Interface” means an interface that either is an official standard defined by a recognized standards body, or, in the case of interfaces specified for a particular programming language, one that is widely used among developers working in that language.
|
|
||||||
|
|
||||||
The “System Libraries” of an executable work include anything, other than the work as a whole, that (a) is included in the normal form of packaging a Major Component, but which is not part of that Major Component, and (b) serves only to enable use of the work with that Major Component, or to implement a Standard Interface for which an implementation is available to the public in source code form. A “Major Component”, in this context, means a major essential component (kernel, window system, and so on) of the specific operating system (if any) on which the executable work runs, or a compiler used to produce the work, or an object code interpreter used to run it.
|
|
||||||
|
|
||||||
The “Corresponding Source” for a work in object code form means all the source code needed to generate, install, and (for an executable work) run the object code and to modify the work, including scripts to control those activities. However, it does not include the work's System Libraries, or general-purpose tools or generally available free programs which are used unmodified in performing those activities but which are not part of the work. For example, Corresponding Source includes interface definition files associated with source files for the work, and the source code for shared libraries and dynamically linked subprograms that the work is specifically designed to require, such as by intimate data communication or control flow between those subprograms and other parts of the work.
|
|
||||||
|
|
||||||
The Corresponding Source need not include anything that users can regenerate automatically from other parts of the Corresponding Source.
|
|
||||||
|
|
||||||
The Corresponding Source for a work in source code form is that same work.
|
|
||||||
|
|
||||||
2. Basic Permissions.
|
|
||||||
All rights granted under this License are granted for the term of copyright on the Program, and are irrevocable provided the stated conditions are met. This License explicitly affirms your unlimited permission to run the unmodified Program. The output from running a covered work is covered by this License only if the output, given its content, constitutes a covered work. This License acknowledges your rights of fair use or other equivalent, as provided by copyright law.
|
|
||||||
|
|
||||||
You may make, run and propagate covered works that you do not convey, without conditions so long as your license otherwise remains in force. You may convey covered works to others for the sole purpose of having them make modifications exclusively for you, or provide you with facilities for running those works, provided that you comply with the terms of this License in conveying all material for which you do not control copyright. Those thus making or running the covered works for you must do so exclusively on your behalf, under your direction and control, on terms that prohibit them from making any copies of your copyrighted material outside their relationship with you.
|
|
||||||
|
|
||||||
Conveying under any other circumstances is permitted solely under the conditions stated below. Sublicensing is not allowed; section 10 makes it unnecessary.
|
|
||||||
|
|
||||||
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
|
|
||||||
No covered work shall be deemed part of an effective technological measure under any applicable law fulfilling obligations under article 11 of the WIPO copyright treaty adopted on 20 December 1996, or similar laws prohibiting or restricting circumvention of such measures.
|
|
||||||
|
|
||||||
When you convey a covered work, you waive any legal power to forbid circumvention of technological measures to the extent such circumvention is effected by exercising rights under this License with respect to the covered work, and you disclaim any intention to limit operation or modification of the work as a means of enforcing, against the work's users, your or third parties' legal rights to forbid circumvention of technological measures.
|
|
||||||
|
|
||||||
4. Conveying Verbatim Copies.
|
|
||||||
You may convey verbatim copies of the Program's source code as you receive it, in any medium, provided that you conspicuously and appropriately publish on each copy an appropriate copyright notice; keep intact all notices stating that this License and any non-permissive terms added in accord with section 7 apply to the code; keep intact all notices of the absence of any warranty; and give all recipients a copy of this License along with the Program.
|
|
||||||
|
|
||||||
You may charge any price or no price for each copy that you convey, and you may offer support or warranty protection for a fee.
|
|
||||||
|
|
||||||
5. Conveying Modified Source Versions.
|
|
||||||
You may convey a work based on the Program, or the modifications to produce it from the Program, in the form of source code under the terms of section 4, provided that you also meet all of these conditions:
|
|
||||||
|
|
||||||
a) The work must carry prominent notices stating that you modified it, and giving a relevant date.
|
|
||||||
|
|
||||||
b) The work must carry prominent notices stating that it is released under this License and any conditions added under section 7. This requirement modifies the requirement in section 4 to “keep intact all notices”.
|
|
||||||
|
|
||||||
c) You must license the entire work, as a whole, under this License to anyone who comes into possession of a copy. This License will therefore apply, along with any applicable section 7 additional terms, to the whole of the work, and all its parts, regardless of how they are packaged. This License gives no permission to license the work in any other way, but it does not invalidate such permission if you have separately received it.
|
|
||||||
|
|
||||||
d) If the work has interactive user interfaces, each must display Appropriate Legal Notices; however, if the Program has interactive interfaces that do not display Appropriate Legal Notices, your work need not make them do so.
|
|
||||||
|
|
||||||
A compilation of a covered work with other separate and independent works, which are not by their nature extensions of the covered work, and which are not combined with it such as to form a larger program, in or on a volume of a storage or distribution medium, is called an “aggregate” if the compilation and its resulting copyright are not used to limit the access or legal rights of the compilation's users beyond what the individual works permit. Inclusion of a covered work in an aggregate does not cause this License to apply to the other parts of the aggregate.
|
|
||||||
|
|
||||||
6. Conveying Non-Source Forms.
|
|
||||||
You may convey a covered work in object code form under the terms of sections 4 and 5, provided that you also convey the machine-readable Corresponding Source under the terms of this License, in one of these ways:
|
|
||||||
|
|
||||||
a) Convey the object code in, or embodied in, a physical product (including a physical distribution medium), accompanied by the Corresponding Source fixed on a durable physical medium customarily used for software interchange.
|
|
||||||
|
|
||||||
b) Convey the object code in, or embodied in, a physical product (including a physical distribution medium), accompanied by a written offer, valid for at least three years and valid for as long as you offer spare parts or customer support for that product model, to give anyone who possesses the object code either (1) a copy of the Corresponding Source for all the software in the product that is covered by this License, on a durable physical medium customarily used for software interchange, for a price no more than your reasonable cost of physically performing this conveying of source, or (2) access to copy the Corresponding Source from a network server at no charge.
|
|
||||||
|
|
||||||
c) Convey individual copies of the object code with a copy of the written offer to provide the Corresponding Source. This alternative is allowed only occasionally and noncommercially, and only if you received the object code with such an offer, in accord with subsection 6b.
|
|
||||||
|
|
||||||
d) Convey the object code by offering access from a designated place (gratis or for a charge), and offer equivalent access to the Corresponding Source in the same way through the same place at no further charge. You need not require recipients to copy the Corresponding Source along with the object code. If the place to copy the object code is a network server, the Corresponding Source may be on a different server (operated by you or a third party) that supports equivalent copying facilities, provided you maintain clear directions next to the object code saying where to find the Corresponding Source. Regardless of what server hosts the Corresponding Source, you remain obligated to ensure that it is available for as long as needed to satisfy these requirements.
|
|
||||||
|
|
||||||
e) Convey the object code using peer-to-peer transmission, provided you inform other peers where the object code and Corresponding Source of the work are being offered to the general public at no charge under subsection 6d.
|
|
||||||
|
|
||||||
A separable portion of the object code, whose source code is excluded from the Corresponding Source as a System Library, need not be included in conveying the object code work.
|
|
||||||
|
|
||||||
A “User Product” is either (1) a “consumer product”, which means any tangible personal property which is normally used for personal, family, or household purposes, or (2) anything designed or sold for incorporation into a dwelling. In determining whether a product is a consumer product, doubtful cases shall be resolved in favor of coverage. For a particular product received by a particular user, “normally used” refers to a typical or common use of that class of product, regardless of the status of the particular user or of the way in which the particular user actually uses, or expects or is expected to use, the product. A product is a consumer product regardless of whether the product has substantial commercial, industrial or non-consumer uses, unless such uses represent the only significant mode of use of the product.
|
|
||||||
|
|
||||||
“Installation Information” for a User Product means any methods, procedures, authorization keys, or other information required to install and execute modified versions of a covered work in that User Product from a modified version of its Corresponding Source. The information must suffice to ensure that the continued functioning of the modified object code is in no case prevented or interfered with solely because modification has been made.
|
|
||||||
|
|
||||||
If you convey an object code work under this section in, or with, or specifically for use in, a User Product, and the conveying occurs as part of a transaction in which the right of possession and use of the User Product is transferred to the recipient in perpetuity or for a fixed term (regardless of how the transaction is characterized), the Corresponding Source conveyed under this section must be accompanied by the Installation Information. But this requirement does not apply if neither you nor any third party retains the ability to install modified object code on the User Product (for example, the work has been installed in ROM).
|
|
||||||
|
|
||||||
The requirement to provide Installation Information does not include a requirement to continue to provide support service, warranty, or updates for a work that has been modified or installed by the recipient, or for the User Product in which it has been modified or installed. Access to a network may be denied when the modification itself materially and adversely affects the operation of the network or violates the rules and protocols for communication across the network.
|
|
||||||
|
|
||||||
Corresponding Source conveyed, and Installation Information provided, in accord with this section must be in a format that is publicly documented (and with an implementation available to the public in source code form), and must require no special password or key for unpacking, reading or copying.
|
|
||||||
|
|
||||||
7. Additional Terms.
|
|
||||||
“Additional permissions” are terms that supplement the terms of this License by making exceptions from one or more of its conditions. Additional permissions that are applicable to the entire Program shall be treated as though they were included in this License, to the extent that they are valid under applicable law. If additional permissions apply only to part of the Program, that part may be used separately under those permissions, but the entire Program remains governed by this License without regard to the additional permissions.
|
|
||||||
|
|
||||||
When you convey a copy of a covered work, you may at your option remove any additional permissions from that copy, or from any part of it. (Additional permissions may be written to require their own removal in certain cases when you modify the work.) You may place additional permissions on material, added by you to a covered work, for which you have or can give appropriate copyright permission.
|
|
||||||
|
|
||||||
Notwithstanding any other provision of this License, for material you add to a covered work, you may (if authorized by the copyright holders of that material) supplement the terms of this License with terms:
|
|
||||||
|
|
||||||
a) Disclaiming warranty or limiting liability differently from the terms of sections 15 and 16 of this License; or
|
|
||||||
|
|
||||||
b) Requiring preservation of specified reasonable legal notices or author attributions in that material or in the Appropriate Legal Notices displayed by works containing it; or
|
|
||||||
|
|
||||||
c) Prohibiting misrepresentation of the origin of that material, or requiring that modified versions of such material be marked in reasonable ways as different from the original version; or
|
|
||||||
|
|
||||||
d) Limiting the use for publicity purposes of names of licensors or authors of the material; or
|
|
||||||
|
|
||||||
e) Declining to grant rights under trademark law for use of some trade names, trademarks, or service marks; or
|
|
||||||
|
|
||||||
f) Requiring indemnification of licensors and authors of that material by anyone who conveys the material (or modified versions of it) with contractual assumptions of liability to the recipient, for any liability that these contractual assumptions directly impose on those licensors and authors.
|
|
||||||
|
|
||||||
All other non-permissive additional terms are considered “further restrictions” within the meaning of section 10. If the Program as you received it, or any part of it, contains a notice stating that it is governed by this License along with a term that is a further restriction, you may remove that term. If a license document contains a further restriction but permits relicensing or conveying under this License, you may add to a covered work material governed by the terms of that license document, provided that the further restriction does not survive such relicensing or conveying.
|
|
||||||
|
|
||||||
If you add terms to a covered work in accord with this section, you must place, in the relevant source files, a statement of the additional terms that apply to those files, or a notice indicating where to find the applicable terms.
|
|
||||||
|
|
||||||
Additional terms, permissive or non-permissive, may be stated in the form of a separately written license, or stated as exceptions; the above requirements apply either way.
|
|
||||||
|
|
||||||
8. Termination.
|
|
||||||
You may not propagate or modify a covered work except as expressly provided under this License. Any attempt otherwise to propagate or modify it is void, and will automatically terminate your rights under this License (including any patent licenses granted under the third paragraph of section 11).
|
|
||||||
|
|
||||||
However, if you cease all violation of this License, then your license from a particular copyright holder is reinstated (a) provisionally, unless and until the copyright holder explicitly and finally terminates your license, and (b) permanently, if the copyright holder fails to notify you of the violation by some reasonable means prior to 60 days after the cessation.
|
|
||||||
|
|
||||||
Moreover, your license from a particular copyright holder is reinstated permanently if the copyright holder notifies you of the violation by some reasonable means, this is the first time you have received notice of violation of this License (for any work) from that copyright holder, and you cure the violation prior to 30 days after your receipt of the notice.
|
|
||||||
|
|
||||||
Termination of your rights under this section does not terminate the licenses of parties who have received copies or rights from you under this License. If your rights have been terminated and not permanently reinstated, you do not qualify to receive new licenses for the same material under section 10.
|
|
||||||
|
|
||||||
9. Acceptance Not Required for Having Copies.
|
|
||||||
You are not required to accept this License in order to receive or run a copy of the Program. Ancillary propagation of a covered work occurring solely as a consequence of using peer-to-peer transmission to receive a copy likewise does not require acceptance. However, nothing other than this License grants you permission to propagate or modify any covered work. These actions infringe copyright if you do not accept this License. Therefore, by modifying or propagating a covered work, you indicate your acceptance of this License to do so.
|
|
||||||
|
|
||||||
10. Automatic Licensing of Downstream Recipients.
|
|
||||||
Each time you convey a covered work, the recipient automatically receives a license from the original licensors, to run, modify and propagate that work, subject to this License. You are not responsible for enforcing compliance by third parties with this License.
|
|
||||||
|
|
||||||
An “entity transaction” is a transaction transferring control of an organization, or substantially all assets of one, or subdividing an organization, or merging organizations. If propagation of a covered work results from an entity transaction, each party to that transaction who receives a copy of the work also receives whatever licenses to the work the party's predecessor in interest had or could give under the previous paragraph, plus a right to possession of the Corresponding Source of the work from the predecessor in interest, if the predecessor has it or can get it with reasonable efforts.
|
|
||||||
|
|
||||||
You may not impose any further restrictions on the exercise of the rights granted or affirmed under this License. For example, you may not impose a license fee, royalty, or other charge for exercise of rights granted under this License, and you may not initiate litigation (including a cross-claim or counterclaim in a lawsuit) alleging that any patent claim is infringed by making, using, selling, offering for sale, or importing the Program or any portion of it.
|
|
||||||
|
|
||||||
11. Patents.
|
|
||||||
A “contributor” is a copyright holder who authorizes use under this License of the Program or a work on which the Program is based. The work thus licensed is called the contributor's “contributor version”.
|
|
||||||
|
|
||||||
A contributor's “essential patent claims” are all patent claims owned or controlled by the contributor, whether already acquired or hereafter acquired, that would be infringed by some manner, permitted by this License, of making, using, or selling its contributor version, but do not include claims that would be infringed only as a consequence of further modification of the contributor version. For purposes of this definition, “control” includes the right to grant patent sublicenses in a manner consistent with the requirements of this License.
|
|
||||||
|
|
||||||
Each contributor grants you a non-exclusive, worldwide, royalty-free patent license under the contributor's essential patent claims, to make, use, sell, offer for sale, import and otherwise run, modify and propagate the contents of its contributor version.
|
|
||||||
|
|
||||||
In the following three paragraphs, a “patent license” is any express agreement or commitment, however denominated, not to enforce a patent (such as an express permission to practice a patent or covenant not to sue for patent infringement). To “grant” such a patent license to a party means to make such an agreement or commitment not to enforce a patent against the party.
|
|
||||||
|
|
||||||
If you convey a covered work, knowingly relying on a patent license, and the Corresponding Source of the work is not available for anyone to copy, free of charge and under the terms of this License, through a publicly available network server or other readily accessible means, then you must either (1) cause the Corresponding Source to be so available, or (2) arrange to deprive yourself of the benefit of the patent license for this particular work, or (3) arrange, in a manner consistent with the requirements of this License, to extend the patent license to downstream recipients. “Knowingly relying” means you have actual knowledge that, but for the patent license, your conveying the covered work in a country, or your recipient's use of the covered work in a country, would infringe one or more identifiable patents in that country that you have reason to believe are valid.
|
|
||||||
|
|
||||||
If, pursuant to or in connection with a single transaction or arrangement, you convey, or propagate by procuring conveyance of, a covered work, and grant a patent license to some of the parties receiving the covered work authorizing them to use, propagate, modify or convey a specific copy of the covered work, then the patent license you grant is automatically extended to all recipients of the covered work and works based on it.
|
|
||||||
|
|
||||||
A patent license is “discriminatory” if it does not include within the scope of its coverage, prohibits the exercise of, or is conditioned on the non-exercise of one or more of the rights that are specifically granted under this License. You may not convey a covered work if you are a party to an arrangement with a third party that is in the business of distributing software, under which you make payment to the third party based on the extent of your activity of conveying the work, and under which the third party grants, to any of the parties who would receive the covered work from you, a discriminatory patent license (a) in connection with copies of the covered work conveyed by you (or copies made from those copies), or (b) primarily for and in connection with specific products or compilations that contain the covered work, unless you entered into that arrangement, or that patent license was granted, prior to 28 March 2007.
|
|
||||||
|
|
||||||
Nothing in this License shall be construed as excluding or limiting any implied license or other defenses to infringement that may otherwise be available to you under applicable patent law.
|
|
||||||
|
|
||||||
12. No Surrender of Others' Freedom.
|
|
||||||
If conditions are imposed on you (whether by court order, agreement or otherwise) that contradict the conditions of this License, they do not excuse you from the conditions of this License. If you cannot convey a covered work so as to satisfy simultaneously your obligations under this License and any other pertinent obligations, then as a consequence you may not convey it at all. For example, if you agree to terms that obligate you to collect a royalty for further conveying from those to whom you convey the Program, the only way you could satisfy both those terms and this License would be to refrain entirely from conveying the Program.
|
|
||||||
|
|
||||||
13. Use with the GNU Affero General Public License.
|
|
||||||
Notwithstanding any other provision of this License, you have permission to link or combine any covered work with a work licensed under version 3 of the GNU Affero General Public License into a single combined work, and to convey the resulting work. The terms of this License will continue to apply to the part which is the covered work, but the special requirements of the GNU Affero General Public License, section 13, concerning interaction through a network will apply to the combination as such.
|
|
||||||
|
|
||||||
14. Revised Versions of this License.
|
|
||||||
The Free Software Foundation may publish revised and/or new versions of the GNU General Public License from time to time. Such new versions will be similar in spirit to the present version, but may differ in detail to address new problems or concerns.
|
|
||||||
|
|
||||||
Each version is given a distinguishing version number. If the Program specifies that a certain numbered version of the GNU General Public License “or any later version” applies to it, you have the option of following the terms and conditions either of that numbered version or of any later version published by the Free Software Foundation. If the Program does not specify a version number of the GNU General Public License, you may choose any version ever published by the Free Software Foundation.
|
|
||||||
|
|
||||||
If the Program specifies that a proxy can decide which future versions of the GNU General Public License can be used, that proxy's public statement of acceptance of a version permanently authorizes you to choose that version for the Program.
|
|
||||||
|
|
||||||
Later license versions may give you additional or different permissions. However, no additional obligations are imposed on any author or copyright holder as a result of your choosing to follow a later version.
|
|
||||||
|
|
||||||
15. Disclaimer of Warranty.
|
|
||||||
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
|
|
||||||
|
|
||||||
16. Limitation of Liability.
|
|
||||||
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
|
|
||||||
|
|
||||||
17. Interpretation of Sections 15 and 16.
|
|
||||||
If the disclaimer of warranty and limitation of liability provided above cannot be given local legal effect according to their terms, reviewing courts shall apply local law that most closely approximates an absolute waiver of all civil liability in connection with the Program, unless a warranty or assumption of liability accompanies a copy of the Program in return for a fee.
|
|
||||||
|
|
||||||
END OF TERMS AND CONDITIONS
|
|
||||||
|
|
||||||
How to Apply These Terms to Your New Programs
|
|
||||||
|
|
||||||
If you develop a new program, and you want it to be of the greatest possible use to the public, the best way to achieve this is to make it free software which everyone can redistribute and change under these terms.
|
|
||||||
|
|
||||||
To do so, attach the following notices to the program. It is safest to attach them to the start of each source file to most effectively state the exclusion of warranty; and each file should have at least the “copyright” line and a pointer to where the full notice is found.
|
|
||||||
|
|
||||||
<one line to give the program's name and a brief idea of what it does.>
|
|
||||||
Copyright (C) <year> <name of author>
|
|
||||||
|
|
||||||
This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
|
|
||||||
|
|
||||||
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
|
|
||||||
|
|
||||||
You should have received a copy of the GNU General Public License along with this program. If not, see <https://www.gnu.org/licenses/>.
|
|
||||||
|
|
||||||
Also add information on how to contact you by electronic and paper mail.
|
|
||||||
|
|
||||||
If the program does terminal interaction, make it output a short notice like this when it starts in an interactive mode:
|
|
||||||
|
|
||||||
<program> Copyright (C) <year> <name of author>
|
|
||||||
This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
|
|
||||||
This is free software, and you are welcome to redistribute it under certain conditions; type `show c' for details.
|
|
||||||
|
|
||||||
The hypothetical commands `show w' and `show c' should show the appropriate parts of the General Public License. Of course, your program's commands might be different; for a GUI interface, you would use an “about box”.
|
|
||||||
|
|
||||||
You should also get your employer (if you work as a programmer) or school, if any, to sign a “copyright disclaimer” for the program, if necessary. For more information on this, and how to apply and follow the GNU GPL, see <https://www.gnu.org/licenses/>.
|
|
||||||
|
|
||||||
The GNU General Public License does not permit incorporating your program into proprietary programs. If your program is a subroutine library, you may consider it more useful to permit linking proprietary applications with the library. If this is what you want to do, use the GNU Lesser General Public License instead of this License. But first, please read <https://www.gnu.org/philosophy/why-not-lgpl.html>.
|
|
||||||
666
README.md
666
README.md
|
|
@ -2,101 +2,33 @@
|
||||||
|
|
||||||
A caching proxy for package registries. Speeds up package downloads by caching artifacts locally, reducing bandwidth usage and improving reliability.
|
A caching proxy for package registries. Speeds up package downloads by caching artifacts locally, reducing bandwidth usage and improving reliability.
|
||||||
|
|
||||||
## Version Cooldown
|
|
||||||
|
|
||||||
Most supply chain attacks rely on speed: a malicious version gets published and consumed by automated pipelines within minutes, before anyone notices. The cooldown feature adds a quarantine period to newly published versions. When enabled, the proxy strips versions from metadata responses until they've aged past a configurable threshold.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
cooldown:
|
|
||||||
default: "3d" # hide versions published less than 3 days ago
|
|
||||||
ecosystems:
|
|
||||||
npm: "7d" # npm gets a longer window
|
|
||||||
cargo: "0" # disable for cargo
|
|
||||||
packages:
|
|
||||||
"pkg:npm/lodash": "0" # exempt trusted packages
|
|
||||||
```
|
|
||||||
|
|
||||||
A 3-day cooldown means that when `lodash` publishes version `4.18.0`, your builds keep using `4.17.21` until 3 days have passed. If the new release turns out to be compromised, you were never exposed.
|
|
||||||
|
|
||||||
Resolution order: package override, then ecosystem override, then global default. This lets you set a conservative default and carve out exceptions for packages where you need faster updates. See [docs/configuration.md](docs/configuration.md) for the full config reference.
|
|
||||||
|
|
||||||
## Artifact Scanning
|
|
||||||
|
|
||||||
Cooldown only looks at a version's publish timestamp — it never inspects the actual bytes. Artifact scanning closes that gap: when enabled, every artifact is staged into storage and scanned by one or more external services (trivy, ClamAV, Wiz, or anything else that speaks a small HTTP/JSON contract) before it's committed to the cache and served to clients.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
scanning:
|
|
||||||
enabled: true
|
|
||||||
signing_key: ${PROXY_SCANNING_SIGNING_KEY}
|
|
||||||
scanners:
|
|
||||||
- name: clamav
|
|
||||||
url: http://clamav-adapter:8080/scan
|
|
||||||
mode: block # a block verdict deletes the artifact and returns 403
|
|
||||||
- name: trivy
|
|
||||||
url: http://trivy-adapter:8081/scan
|
|
||||||
mode: monitor # findings are logged, never gate caching
|
|
||||||
ecosystems: [npm, pypi]
|
|
||||||
```
|
|
||||||
|
|
||||||
The proxy never uploads artifact bytes to a scanner. Each scanner is notified with package metadata plus a short-lived signed URL; the scanner pulls the bytes itself from the proxy's own storage. Scanners run concurrently, and the first `block`-mode scanner to report a verdict of not-allowed wins immediately, canceling the rest. See [docs/configuration.md](docs/configuration.md) for the full config reference and the scanner HTTP contract.
|
|
||||||
|
|
||||||
## Supported Registries
|
## Supported Registries
|
||||||
|
|
||||||
| Registry | Language/Platform | Cooldown | Completed |
|
| Registry | Language/Platform | URL Resolution | Handler | Completed |
|
||||||
|----------|-------------------|:--------:|:---------:|
|
|----------|-------------------|:--------------:|:-------:|:---------:|
|
||||||
| npm | JavaScript | Yes | ✓ |
|
| npm | JavaScript | Yes | Yes | ✓ |
|
||||||
| Cargo | Rust | Yes | ✓ |
|
| Cargo | Rust | Yes | Yes | ✓ |
|
||||||
| RubyGems | Ruby | Yes | ✓ |
|
| RubyGems | Ruby | Yes | Yes | ✓ |
|
||||||
| Go proxy | Go | | ✓ |
|
| Go proxy | Go | Yes | Yes | ✓ |
|
||||||
| Hex | Elixir | Yes* | ✓ |
|
| Hex | Elixir | Yes | Yes | ✓ |
|
||||||
| pub.dev | Dart | Yes | ✓ |
|
| pub.dev | Dart | Yes | Yes | ✓ |
|
||||||
| PyPI | Python | Yes | ✓ |
|
| PyPI | Python | Yes | Yes | ✓ |
|
||||||
| Maven | Java | | ✓ |
|
| Maven | Java | Yes | Yes | ✓ |
|
||||||
| Gradle Build Cache | Java/Kotlin | | ✓ |
|
| NuGet | .NET | Yes | Yes | ✓ |
|
||||||
| NuGet | .NET | Yes | ✓ |
|
| Composer | PHP | Yes | Yes | ✓ |
|
||||||
| Composer | PHP | Yes | ✓ |
|
| Conan | C/C++ | Yes | Yes | ✓ |
|
||||||
| Conan | C/C++ | | ✓ |
|
| Conda | Python/R | Yes | Yes | ✓ |
|
||||||
| Conda | Python/R | Yes | ✓ |
|
| CRAN | R | Yes | Yes | ✓ |
|
||||||
| CRAN | R | | ✓ |
|
| Container | Docker/OCI | Yes | Yes | ✓ |
|
||||||
| Julia | Julia | | ✓ |
|
| Debian | Debian/Ubuntu | Yes | Yes | ✓ |
|
||||||
| Swift | Swift | | ✓ |
|
| RPM | RHEL/Fedora | Yes | Yes | ✓ |
|
||||||
| Container | Docker/OCI | | ✓ |
|
| Alpine | Alpine Linux | No | No | ✗ |
|
||||||
| Homebrew | macOS/Linux | | ✓ |
|
| Arch | Arch Linux | No | No | ✗ |
|
||||||
| Debian | Debian/Ubuntu | | ✓ |
|
| Chef | Chef | No | No | ✗ |
|
||||||
| RPM | RHEL/Fedora | | ✓ |
|
| Generic | Any | No | No | ✗ |
|
||||||
| Alpine | Alpine Linux | | ✓ |
|
| Helm | Kubernetes | No | No | ✗ |
|
||||||
| Arch | Arch Linux | | ✗ |
|
| Swift | Swift | No | No | ✗ |
|
||||||
| Chef | Chef | | ✗ |
|
| Vagrant | Vagrant | No | No | ✗ |
|
||||||
| Generic | Any | | ✓ |
|
|
||||||
| Helm | Kubernetes | | ✓ |
|
|
||||||
| Vagrant | Vagrant | | ✗ |
|
|
||||||
|
|
||||||
Cooldown requires publish timestamps in metadata. Registries without a "Yes" in the cooldown column either don't expose timestamps or haven't been wired up yet.
|
|
||||||
|
|
||||||
\* Hex cooldown requires disabling registry signature verification (`HEX_NO_VERIFY_REPO_ORIGIN=1`) since the proxy re-encodes the protobuf payload.
|
|
||||||
|
|
||||||
## Install
|
|
||||||
|
|
||||||
```bash
|
|
||||||
brew install git-pkgs/git-pkgs/proxy
|
|
||||||
```
|
|
||||||
|
|
||||||
Or download a binary from the [releases page](https://github.com/git-pkgs/proxy/releases).
|
|
||||||
|
|
||||||
### Helm
|
|
||||||
|
|
||||||
Install the chart from GHCR, setting the public URL that package-manager clients
|
|
||||||
will use to reach the proxy:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
helm install proxy oci://ghcr.io/git-pkgs/charts/proxy \
|
|
||||||
--set config.data.base_url=https://proxy.example.com
|
|
||||||
```
|
|
||||||
|
|
||||||
The default chart deploys one replica backed by a 10 GiB persistent volume,
|
|
||||||
using SQLite and filesystem artifact storage under `/data`. See
|
|
||||||
[`deploy/charts/proxy/values.yaml`](deploy/charts/proxy/values.yaml) for ingress,
|
|
||||||
external database and object-storage configuration options.
|
|
||||||
|
|
||||||
## Quick Start
|
## Quick Start
|
||||||
|
|
||||||
|
|
@ -113,25 +45,6 @@ go build -o proxy ./cmd/proxy
|
||||||
|
|
||||||
The proxy is now running. Configure your package managers to use it.
|
The proxy is now running. Configure your package managers to use it.
|
||||||
|
|
||||||
## OpenAPI (Swagger)
|
|
||||||
|
|
||||||
This repo uses swaggo to generate an OpenAPI spec from annotated handlers.
|
|
||||||
|
|
||||||
Generate the spec:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
go install github.com/swaggo/swag/cmd/swag@latest
|
|
||||||
go generate ./internal/server
|
|
||||||
```
|
|
||||||
|
|
||||||
Generated files are written to `docs/swagger/`.
|
|
||||||
|
|
||||||
When the proxy is running, fetch the live spec from:
|
|
||||||
|
|
||||||
- `http://localhost:8080/openapi.json`
|
|
||||||
|
|
||||||
Or replace `http://localhost:8080` with your configured base URL. This link is also shown on the dashboard.
|
|
||||||
|
|
||||||
## Configuring Package Managers
|
## Configuring Package Managers
|
||||||
|
|
||||||
### npm
|
### npm
|
||||||
|
|
@ -193,29 +106,6 @@ export GOPROXY=http://localhost:8080/go,direct
|
||||||
|
|
||||||
Or in your shell profile for persistence.
|
Or in your shell profile for persistence.
|
||||||
|
|
||||||
### Homebrew
|
|
||||||
|
|
||||||
Point Homebrew's JSON API and artifact domain at the proxy:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
export HOMEBREW_API_DOMAIN=http://localhost:8080/homebrew
|
|
||||||
export HOMEBREW_ARTIFACT_DOMAIN=http://localhost:8080
|
|
||||||
```
|
|
||||||
|
|
||||||
The artifact domain proxies manifests and bottle blobs under `/v2/homebrew/core/`. GHCR routing is limited to that repository. Source archives, cask application downloads, custom tap artifacts, and legacy flat-file bottle mirrors use Homebrew's normal fallback URLs. Keep fallback enabled by leaving `HOMEBREW_ARTIFACT_DOMAIN_NO_FALLBACK` unset.
|
|
||||||
|
|
||||||
Enable `cache_metadata` or set `PROXY_CACHE_METADATA=true` to retain Homebrew JSON API responses for offline fallback. Bottle blobs and their OCI manifests are cached without this setting.
|
|
||||||
|
|
||||||
The upstreams default to `https://formulae.brew.sh/api` for the JSON API and `https://ghcr.io` for artifacts. To chain this proxy to another proxy, configure its Homebrew endpoints as the upstreams:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
upstream:
|
|
||||||
homebrew_api: "https://upstream-proxy.example.com/homebrew"
|
|
||||||
homebrew_artifact: "https://upstream-proxy.example.com"
|
|
||||||
```
|
|
||||||
|
|
||||||
The equivalent environment variables are `PROXY_UPSTREAM_HOMEBREW_API` and `PROXY_UPSTREAM_HOMEBREW_ARTIFACT`.
|
|
||||||
|
|
||||||
### Hex (Elixir)
|
### Hex (Elixir)
|
||||||
|
|
||||||
Configure in `~/.hex/hex.config`:
|
Configure in `~/.hex/hex.config`:
|
||||||
|
|
@ -269,34 +159,6 @@ Add to your `~/.m2/settings.xml`:
|
||||||
</settings>
|
</settings>
|
||||||
```
|
```
|
||||||
|
|
||||||
The `/maven/` endpoint uses Maven Central as primary upstream and falls back to the Gradle Plugin Portal for Gradle plugin marker metadata and related artifacts when the primary upstream returns not found.
|
|
||||||
|
|
||||||
For Gradle plugin resolution via the same proxy endpoint:
|
|
||||||
|
|
||||||
```kotlin
|
|
||||||
pluginManagement {
|
|
||||||
repositories {
|
|
||||||
maven(url = "http://localhost:8080/maven/")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### Gradle HTTP Build Cache
|
|
||||||
|
|
||||||
Configure in `settings.gradle(.kts)`:
|
|
||||||
|
|
||||||
```kotlin
|
|
||||||
buildCache {
|
|
||||||
local {
|
|
||||||
enabled = false
|
|
||||||
}
|
|
||||||
remote<HttpBuildCache> {
|
|
||||||
url = uri("http://localhost:8080/gradle/")
|
|
||||||
push = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### NuGet
|
### NuGet
|
||||||
|
|
||||||
Configure in `nuget.config`:
|
Configure in `nuget.config`:
|
||||||
|
|
@ -384,40 +246,6 @@ local({
|
||||||
})
|
})
|
||||||
```
|
```
|
||||||
|
|
||||||
### Julia
|
|
||||||
|
|
||||||
Set the Pkg server before starting Julia:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
export JULIA_PKG_SERVER=http://localhost:8080/julia
|
|
||||||
```
|
|
||||||
|
|
||||||
Or inside a running session:
|
|
||||||
|
|
||||||
```julia
|
|
||||||
ENV["JULIA_PKG_SERVER"] = "http://localhost:8080/julia"
|
|
||||||
using Pkg; Pkg.update()
|
|
||||||
```
|
|
||||||
|
|
||||||
### Swift
|
|
||||||
|
|
||||||
Configure the proxy as the default registry for the current Swift package:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
swift package-registry set --allow-insecure-http http://localhost:8080/swift
|
|
||||||
```
|
|
||||||
|
|
||||||
Registry dependencies use their scoped package identifier in `Package.swift`:
|
|
||||||
|
|
||||||
```swift
|
|
||||||
dependencies: [
|
|
||||||
.package(id: "apple.swift-argument-parser", from: "1.2.0")
|
|
||||||
]
|
|
||||||
```
|
|
||||||
|
|
||||||
The proxy supports dependency resolution and source downloads. Publishing with
|
|
||||||
`swift package-registry publish` is not supported.
|
|
||||||
|
|
||||||
### Docker / Container Registry
|
### Docker / Container Registry
|
||||||
|
|
||||||
Configure Docker to use the proxy as a registry mirror in `/etc/docker/daemon.json`:
|
Configure Docker to use the proxy as a registry mirror in `/etc/docker/daemon.json`:
|
||||||
|
|
@ -440,39 +268,6 @@ Or pull images directly:
|
||||||
docker pull localhost:8080/library/nginx:latest
|
docker pull localhost:8080/library/nginx:latest
|
||||||
```
|
```
|
||||||
|
|
||||||
### Helm
|
|
||||||
|
|
||||||
Configure each HTTP chart repository with a name, then add the matching proxy
|
|
||||||
URL to Helm:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
upstream:
|
|
||||||
helm:
|
|
||||||
bitnami: "https://charts.bitnami.com/bitnami"
|
|
||||||
```
|
|
||||||
|
|
||||||
```bash
|
|
||||||
helm repo add bitnami http://localhost:8080/helm/bitnami
|
|
||||||
helm repo update
|
|
||||||
helm pull bitnami/nginx
|
|
||||||
```
|
|
||||||
|
|
||||||
The proxy caches `index.yaml` using the normal metadata-cache settings and
|
|
||||||
caches chart archives after verifying their SHA-256 digest from the index.
|
|
||||||
|
|
||||||
For charts stored in an OCI registry, configure a named OCI upstream and add
|
|
||||||
the reserved `upstream/{name}` prefix to the chart reference:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
upstream:
|
|
||||||
oci:
|
|
||||||
ghcr: "https://ghcr.io"
|
|
||||||
```
|
|
||||||
|
|
||||||
```bash
|
|
||||||
helm pull oci://localhost:8080/upstream/ghcr/owner/charts/mychart --version 1.0.0 --plain-http
|
|
||||||
```
|
|
||||||
|
|
||||||
### Debian / APT
|
### Debian / APT
|
||||||
|
|
||||||
Configure APT to use the proxy in `/etc/apt/sources.list.d/proxy.list`:
|
Configure APT to use the proxy in `/etc/apt/sources.list.d/proxy.list`:
|
||||||
|
|
@ -487,13 +282,6 @@ Replace your existing sources.list entries, then:
|
||||||
sudo apt update
|
sudo apt update
|
||||||
```
|
```
|
||||||
|
|
||||||
The upstream defaults to `http://deb.debian.org/debian`. To proxy a different APT repository (e.g. Ubuntu), set `upstream.debian` in the config file or `PROXY_UPSTREAM_DEBIAN` in the environment:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
upstream:
|
|
||||||
debian: "http://archive.ubuntu.com/ubuntu"
|
|
||||||
```
|
|
||||||
|
|
||||||
### RPM / Yum / DNF
|
### RPM / Yum / DNF
|
||||||
|
|
||||||
Configure yum/dnf to use the proxy in `/etc/yum.repos.d/proxy.repo`:
|
Configure yum/dnf to use the proxy in `/etc/yum.repos.d/proxy.repo`:
|
||||||
|
|
@ -513,76 +301,9 @@ sudo dnf clean all
|
||||||
sudo dnf update
|
sudo dnf update
|
||||||
```
|
```
|
||||||
|
|
||||||
### Alpine / apk
|
|
||||||
|
|
||||||
Point `/etc/apk/repositories` at the proxy. The default repository name
|
|
||||||
`alpine` proxies the official mirror (`https://dl-cdn.alpinelinux.org/alpine`):
|
|
||||||
|
|
||||||
```
|
|
||||||
http://localhost:8080/apk/alpine/v3.22/main
|
|
||||||
http://localhost:8080/apk/alpine/v3.22/community
|
|
||||||
```
|
|
||||||
|
|
||||||
Then:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
apk update
|
|
||||||
```
|
|
||||||
|
|
||||||
Repository indexes (v2 `APKINDEX.tar.gz` and v3 `Packages.adb`), detached
|
|
||||||
signatures, and packages are served byte-for-byte unchanged, so apk's normal
|
|
||||||
signature verification keeps working. Indexes use the metadata cache
|
|
||||||
(`metadata_ttl`, stale fallback); `.apk` packages are stored in the shared
|
|
||||||
artifact cache and remain available when the upstream is unreachable.
|
|
||||||
|
|
||||||
To proxy other mirrors or private repositories, configure named upstreams
|
|
||||||
under `upstream.apk` (this replaces the built-in default; re-add `alpine` if
|
|
||||||
you still want it):
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
upstream:
|
|
||||||
apk:
|
|
||||||
alpine: "https://dl-cdn.alpinelinux.org/alpine"
|
|
||||||
private: "https://apk.example.com"
|
|
||||||
```
|
|
||||||
|
|
||||||
```
|
|
||||||
http://localhost:8080/apk/private
|
|
||||||
```
|
|
||||||
|
|
||||||
apk appends the architecture and index filename to each repository line
|
|
||||||
itself.
|
|
||||||
|
|
||||||
### GitHub Releases / mise (aqua backend)
|
|
||||||
|
|
||||||
Configure named generic upstreams:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
upstream:
|
|
||||||
generic:
|
|
||||||
github: "https://github.com"
|
|
||||||
github-api: "https://api.github.com"
|
|
||||||
```
|
|
||||||
|
|
||||||
Then rewrite GitHub URLs in mise's settings (`~/.config/mise/config.toml`, mise ≥ 2025.9.3):
|
|
||||||
|
|
||||||
```toml
|
|
||||||
[settings.url_replacements]
|
|
||||||
"regex:^https://github\\.com/([^/]+)/([^/]+)/releases/download/(.+)" = "http://localhost:8080/generic/github/$1/$2/releases/download/$3"
|
|
||||||
"regex:^https://api\\.github\\.com/(.*)" = "http://localhost:8080/generic/github-api/$1"
|
|
||||||
```
|
|
||||||
|
|
||||||
Release assets are cached permanently after the first download and keep
|
|
||||||
installing while GitHub is down. Tag lookups through `api.github.com` are
|
|
||||||
cached for `metadata_ttl` and served stale during an outage or rate limit.
|
|
||||||
Commit a `mise.lock` and install with `mise install --locked` so pinned
|
|
||||||
installs need no API call at all. Add a bearer token for `https://api.github.com`
|
|
||||||
under `upstream.auth` if the fleet exceeds GitHub's anonymous rate limit.
|
|
||||||
|
|
||||||
## Configuration
|
## Configuration
|
||||||
|
|
||||||
The proxy can be configured via:
|
The proxy can be configured via:
|
||||||
|
|
||||||
1. Command line flags (highest priority)
|
1. Command line flags (highest priority)
|
||||||
2. Environment variables
|
2. Environment variables
|
||||||
3. Configuration file (YAML or JSON)
|
3. Configuration file (YAML or JSON)
|
||||||
|
|
@ -590,18 +311,14 @@ The proxy can be configured via:
|
||||||
### Command Line Flags
|
### Command Line Flags
|
||||||
|
|
||||||
```
|
```
|
||||||
-config string Path to configuration file
|
-config string Path to configuration file
|
||||||
-listen string Address to listen on (default ":8080")
|
-listen string Address to listen on (default ":8080")
|
||||||
-base-url string Public URL of this proxy (default "http://localhost:8080")
|
-base-url string Public URL of this proxy (default "http://localhost:8080")
|
||||||
-storage-url string Storage URL (file://, s3://, gs://, azblob://)
|
-storage string Path to artifact storage directory (default "./cache/artifacts")
|
||||||
-storage-path string Path to artifact storage directory (deprecated, use -storage-url)
|
-database string Path to SQLite database file (default "./cache/proxy.db")
|
||||||
-database-driver string Database driver: sqlite or postgres (default "sqlite")
|
-log-level string Log level: debug, info, warn, error (default "info")
|
||||||
-database-path string Path to SQLite database file (default "./cache/proxy.db")
|
-log-format string Log format: text, json (default "text")
|
||||||
-database-url string PostgreSQL connection URL
|
-version Print version and exit
|
||||||
-log-level string Log level: debug, info, warn, error (default "info")
|
|
||||||
-log-format string Log format: text, json (default "text")
|
|
||||||
-access-log string Path to the JSONL access log
|
|
||||||
-version Print version and exit
|
|
||||||
```
|
```
|
||||||
|
|
||||||
### Environment Variables
|
### Environment Variables
|
||||||
|
|
@ -609,15 +326,10 @@ The proxy can be configured via:
|
||||||
```bash
|
```bash
|
||||||
PROXY_LISTEN=:8080
|
PROXY_LISTEN=:8080
|
||||||
PROXY_BASE_URL=http://localhost:8080
|
PROXY_BASE_URL=http://localhost:8080
|
||||||
PROXY_UI_URL=http://localhost:8080 # Optional; defaults to PROXY_BASE_URL
|
PROXY_STORAGE_PATH=./cache/artifacts
|
||||||
PROXY_STORAGE_URL=file:///var/cache/proxy/artifacts
|
|
||||||
PROXY_DATABASE_DRIVER=sqlite
|
|
||||||
PROXY_DATABASE_PATH=./cache/proxy.db
|
PROXY_DATABASE_PATH=./cache/proxy.db
|
||||||
PROXY_DATABASE_URL=postgres://user:pass@localhost/proxy?sslmode=disable
|
|
||||||
PROXY_LOG_LEVEL=info
|
PROXY_LOG_LEVEL=info
|
||||||
PROXY_LOG_FORMAT=text
|
PROXY_LOG_FORMAT=text
|
||||||
PROXY_ACCESS_LOG_PATH=/var/log/proxy/access.jsonl
|
|
||||||
PROXY_UPSTREAM_SWIFT=https://tuist.dev/api/registry/swift
|
|
||||||
```
|
```
|
||||||
|
|
||||||
### Configuration File
|
### Configuration File
|
||||||
|
|
@ -627,127 +339,28 @@ listen: ":8080"
|
||||||
base_url: "http://localhost:8080"
|
base_url: "http://localhost:8080"
|
||||||
|
|
||||||
storage:
|
storage:
|
||||||
url: "file:///var/cache/proxy/artifacts"
|
path: "/var/cache/proxy/artifacts"
|
||||||
max_size: "10GB" # Optional: evict LRU when exceeded
|
max_size: "10GB" # Optional: evict LRU when exceeded
|
||||||
|
|
||||||
database:
|
database:
|
||||||
driver: "sqlite"
|
|
||||||
path: "/var/lib/proxy/cache.db"
|
path: "/var/lib/proxy/cache.db"
|
||||||
|
|
||||||
log:
|
log:
|
||||||
level: "info"
|
level: "info"
|
||||||
format: "text"
|
format: "text"
|
||||||
|
|
||||||
access_log:
|
|
||||||
path: "/var/log/proxy/access.jsonl" # Optional JSONL activity log
|
|
||||||
|
|
||||||
# Optional: override upstream URLs
|
# Optional: override upstream URLs
|
||||||
upstream:
|
upstream:
|
||||||
npm: "https://registry.npmjs.org"
|
npm: "https://registry.npmjs.org"
|
||||||
cargo: "https://index.crates.io"
|
cargo: "https://index.crates.io"
|
||||||
swift: "https://tuist.dev/api/registry/swift"
|
|
||||||
|
|
||||||
# Optional: version cooldown (see above)
|
|
||||||
cooldown:
|
|
||||||
default: "3d"
|
|
||||||
```
|
```
|
||||||
|
|
||||||
See the [configuration reference](docs/configuration.md#upstream-registries) for every upstream key, environment variable, and default URL.
|
|
||||||
|
|
||||||
Run with config file:
|
Run with config file:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
./proxy -config /etc/proxy/config.yaml
|
./proxy -config /etc/proxy/config.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
### PostgreSQL
|
|
||||||
|
|
||||||
SQLite is the default and works well for single-node deployments. For multi-node setups or if you prefer a managed database, switch to Postgres:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
database:
|
|
||||||
driver: "postgres"
|
|
||||||
url: "postgres://user:password@localhost:5432/proxy?sslmode=disable"
|
|
||||||
```
|
|
||||||
|
|
||||||
Or via environment variables:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
PROXY_DATABASE_DRIVER=postgres
|
|
||||||
PROXY_DATABASE_URL=postgres://user:password@localhost:5432/proxy?sslmode=disable
|
|
||||||
```
|
|
||||||
|
|
||||||
The proxy creates tables automatically on first run.
|
|
||||||
|
|
||||||
### S3 Storage
|
|
||||||
|
|
||||||
The proxy can store cached artifacts in S3 or any S3-compatible service (MinIO, R2, etc.) instead of the local filesystem.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
storage:
|
|
||||||
url: "s3://my-bucket-name?region=us-east-1"
|
|
||||||
```
|
|
||||||
|
|
||||||
For S3-compatible services like MinIO:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
storage:
|
|
||||||
url: "s3://my-bucket?endpoint=http://localhost:9000&disableSSL=true&s3ForcePathStyle=true"
|
|
||||||
```
|
|
||||||
|
|
||||||
Set credentials via standard AWS environment variables (`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, `AWS_REGION`).
|
|
||||||
|
|
||||||
### Google Cloud Storage
|
|
||||||
|
|
||||||
The proxy can store cached artifacts in a GCS bucket using the `gs://` URL scheme.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
storage:
|
|
||||||
url: "gs://my-bucket-name"
|
|
||||||
```
|
|
||||||
|
|
||||||
Authentication uses [Application Default Credentials](https://docs.cloud.google.com/docs/authentication/application-default-credentials), which means no credentials need to be embedded in the config or environment. Supported sources, in order:
|
|
||||||
|
|
||||||
- **GKE Workload Identity** — bind the Kubernetes service account running the proxy to a Google service account that has `roles/storage.objectAdmin` on the bucket. The proxy will use the workload's token automatically.
|
|
||||||
- **Attached service account** on GCE, Cloud Run, Cloud Functions, etc.
|
|
||||||
- **`GOOGLE_APPLICATION_CREDENTIALS`** environment variable pointing at a service account JSON key file.
|
|
||||||
- **`gcloud auth application-default login`** for local development.
|
|
||||||
|
|
||||||
#### GKE Workload Identity setup
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# 1. Create a Google service account
|
|
||||||
gcloud iam service-accounts create git-pkgs-proxy \
|
|
||||||
--project=PROJECT_ID
|
|
||||||
|
|
||||||
# 2. Grant it access to the bucket
|
|
||||||
gsutil iam ch \
|
|
||||||
serviceAccount:git-pkgs-proxy@PROJECT_ID.iam.gserviceaccount.com:objectAdmin \
|
|
||||||
gs://my-bucket-name
|
|
||||||
|
|
||||||
# 3. Bind the Kubernetes service account to it
|
|
||||||
gcloud iam service-accounts add-iam-policy-binding \
|
|
||||||
git-pkgs-proxy@PROJECT_ID.iam.gserviceaccount.com \
|
|
||||||
--role=roles/iam.workloadIdentityUser \
|
|
||||||
--member="serviceAccount:PROJECT_ID.svc.id.goog[NAMESPACE/KSA_NAME]"
|
|
||||||
|
|
||||||
# 4. Annotate the Kubernetes service account
|
|
||||||
kubectl annotate serviceaccount KSA_NAME \
|
|
||||||
--namespace=NAMESPACE \
|
|
||||||
iam.gke.io/gcp-service-account=git-pkgs-proxy@PROJECT_ID.iam.gserviceaccount.com
|
|
||||||
```
|
|
||||||
|
|
||||||
#### Direct serve (signed URLs) with Workload Identity
|
|
||||||
|
|
||||||
When `direct_serve: true` is enabled, the proxy issues HTTP 302 redirects to presigned GCS URLs. Workload Identity provides no private key, so the GCS backend calls the [IAM Credentials `signBlob` API](https://docs.cloud.google.com/iam/docs/reference/credentials/rest/v1/projects.serviceAccounts/signBlob). Grant the service account the token-creator role on itself:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
gcloud iam service-accounts add-iam-policy-binding \
|
|
||||||
git-pkgs-proxy@PROJECT_ID.iam.gserviceaccount.com \
|
|
||||||
--role=roles/iam.serviceAccountTokenCreator \
|
|
||||||
--member="serviceAccount:git-pkgs-proxy@PROJECT_ID.iam.gserviceaccount.com"
|
|
||||||
```
|
|
||||||
|
|
||||||
## CLI Commands
|
## CLI Commands
|
||||||
|
|
||||||
### serve (default)
|
### serve (default)
|
||||||
|
|
@ -759,49 +372,6 @@ proxy serve [flags]
|
||||||
proxy [flags] # same as 'proxy serve'
|
proxy [flags] # same as 'proxy serve'
|
||||||
```
|
```
|
||||||
|
|
||||||
### mirror
|
|
||||||
|
|
||||||
Pre-populate the cache from PURLs, SBOM files, or entire registries. Useful for ensuring offline availability or warming the cache before deployments.
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Mirror specific package versions
|
|
||||||
proxy mirror pkg:npm/lodash@4.17.21 pkg:cargo/serde@1.0.0
|
|
||||||
|
|
||||||
# Mirror all versions of a package
|
|
||||||
proxy mirror pkg:npm/lodash
|
|
||||||
|
|
||||||
# Mirror from a CycloneDX or SPDX SBOM
|
|
||||||
proxy mirror --sbom sbom.cdx.json
|
|
||||||
|
|
||||||
# Preview what would be mirrored
|
|
||||||
proxy mirror --dry-run pkg:npm/lodash
|
|
||||||
|
|
||||||
# Control parallelism
|
|
||||||
proxy mirror --concurrency 8 pkg:npm/lodash@4.17.21
|
|
||||||
```
|
|
||||||
|
|
||||||
The mirror command accepts the same storage and database flags as `serve`. Already-cached artifacts are skipped.
|
|
||||||
|
|
||||||
A mirror API is also available when the server is running:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Start a mirror job
|
|
||||||
curl -X POST http://localhost:8080/api/mirror \
|
|
||||||
-H "Content-Type: application/json" \
|
|
||||||
-d '{"purls": ["pkg:npm/lodash@4.17.21"]}'
|
|
||||||
|
|
||||||
# Start a mirror job from an inline CycloneDX or SPDX JSON SBOM
|
|
||||||
curl -X POST http://localhost:8080/api/mirror \
|
|
||||||
-H "Content-Type: application/json" \
|
|
||||||
-d '{"sbom":{"bomFormat":"CycloneDX","components":[{"purl":"pkg:npm/lodash@4.17.21"}]}}'
|
|
||||||
|
|
||||||
# Check job status
|
|
||||||
curl http://localhost:8080/api/mirror/mirror-1
|
|
||||||
|
|
||||||
# Cancel a running job
|
|
||||||
curl -X DELETE http://localhost:8080/api/mirror/mirror-1
|
|
||||||
```
|
|
||||||
|
|
||||||
### stats
|
### stats
|
||||||
|
|
||||||
Show cache statistics without running the server.
|
Show cache statistics without running the server.
|
||||||
|
|
@ -814,10 +384,7 @@ proxy stats
|
||||||
proxy stats -json
|
proxy stats -json
|
||||||
|
|
||||||
# Custom database path
|
# Custom database path
|
||||||
proxy stats -database-path /var/lib/proxy/cache.db
|
proxy stats -database /var/lib/proxy/cache.db
|
||||||
|
|
||||||
# With PostgreSQL
|
|
||||||
proxy stats -database-driver postgres -database-url postgres://user:pass@localhost/proxy
|
|
||||||
|
|
||||||
# Show top 20 most popular packages
|
# Show top 20 most popular packages
|
||||||
proxy stats -popular 20
|
proxy stats -popular 20
|
||||||
|
|
@ -855,10 +422,9 @@ Recently cached:
|
||||||
|
|
||||||
| Endpoint | Description |
|
| Endpoint | Description |
|
||||||
|----------|-------------|
|
|----------|-------------|
|
||||||
| `GET /` | Dashboard (web UI) |
|
| `GET /` | Welcome message and endpoint list |
|
||||||
| `GET /health` | Health check and upstream circuit breaker state (JSON; HTTP 200 healthy, 503 unhealthy) |
|
| `GET /health` | Health check (returns "ok" if healthy) |
|
||||||
| `GET /stats` | Cache statistics (JSON) |
|
| `GET /stats` | Cache statistics (JSON) |
|
||||||
| `GET /metrics` | Prometheus metrics |
|
|
||||||
| `GET /npm/*` | npm registry protocol |
|
| `GET /npm/*` | npm registry protocol |
|
||||||
| `GET /cargo/*` | Cargo sparse index protocol |
|
| `GET /cargo/*` | Cargo sparse index protocol |
|
||||||
| `GET /gem/*` | RubyGems protocol |
|
| `GET /gem/*` | RubyGems protocol |
|
||||||
|
|
@ -872,25 +438,10 @@ Recently cached:
|
||||||
| `GET /conan/*` | Conan C/C++ protocol |
|
| `GET /conan/*` | Conan C/C++ protocol |
|
||||||
| `GET /conda/*` | Conda/Anaconda protocol |
|
| `GET /conda/*` | Conda/Anaconda protocol |
|
||||||
| `GET /cran/*` | CRAN (R) protocol |
|
| `GET /cran/*` | CRAN (R) protocol |
|
||||||
| `GET /julia/*` | Julia Pkg server protocol |
|
|
||||||
| `GET /swift/*` | Swift Package Registry v1 protocol |
|
|
||||||
| `GET /helm/{repository}/*` | HTTP Helm chart repository protocol |
|
|
||||||
| `GET /homebrew/*` | Homebrew JSON API |
|
|
||||||
| `GET /v2/*` | OCI/Docker registry protocol |
|
| `GET /v2/*` | OCI/Docker registry protocol |
|
||||||
| `GET /v2/homebrew/core/*` | Homebrew core bottle manifests and blobs from GHCR |
|
|
||||||
| `GET /apk/{repository}/*` | Alpine APK repository protocol |
|
|
||||||
| `GET /generic/{name}/*` | Generic HTTP download proxy (GitHub release assets, mise/aqua) |
|
|
||||||
| `GET /debian/*` | Debian/APT repository protocol |
|
| `GET /debian/*` | Debian/APT repository protocol |
|
||||||
| `GET /rpm/*` | RPM/Yum repository protocol |
|
| `GET /rpm/*` | RPM/Yum repository protocol |
|
||||||
|
|
||||||
### Mirror API
|
|
||||||
|
|
||||||
| Endpoint | Description |
|
|
||||||
|----------|-------------|
|
|
||||||
| `POST /api/mirror` | Start a mirror job (JSON body with `purls` or an inline `sbom`) |
|
|
||||||
| `GET /api/mirror/{id}` | Get job status and progress |
|
|
||||||
| `DELETE /api/mirror/{id}` | Cancel a running job |
|
|
||||||
|
|
||||||
### Enrichment API
|
### Enrichment API
|
||||||
|
|
||||||
The proxy provides REST endpoints for package metadata enrichment, vulnerability scanning, and outdated detection.
|
The proxy provides REST endpoints for package metadata enrichment, vulnerability scanning, and outdated detection.
|
||||||
|
|
@ -1045,7 +596,7 @@ Response:
|
||||||
"cached_artifacts": 142,
|
"cached_artifacts": 142,
|
||||||
"total_size_bytes": 523456789,
|
"total_size_bytes": 523456789,
|
||||||
"total_size": "499.2 MB",
|
"total_size": "499.2 MB",
|
||||||
"storage_url": "file:///path/to/cache/artifacts",
|
"storage_path": "./cache/artifacts",
|
||||||
"database_path": "./cache/proxy.db"
|
"database_path": "./cache/proxy.db"
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
@ -1073,83 +624,6 @@ Response:
|
||||||
└─────────┘
|
└─────────┘
|
||||||
```
|
```
|
||||||
|
|
||||||
## Web Interface
|
|
||||||
|
|
||||||
The proxy serves a web UI under `/ui`. No separate frontend build is needed -- templates and assets are embedded in the binary. `GET /` redirects to `/ui/`. The UI is mounted under its own prefix so a reverse proxy can apply different access rules to it than to the package endpoints (for example, requiring auth for `PathPrefix(/ui)` while leaving `/npm`, `/pypi` etc. open to build machines).
|
|
||||||
|
|
||||||
- **Dashboard** (`/ui/`) -- cache stats, popular packages, recently cached artifacts, and vulnerability overview.
|
|
||||||
- **Install guide** (`/ui/install`) -- per-ecosystem configuration instructions, so you don't have to look them up here.
|
|
||||||
- **Package browser** (`/ui/packages`) -- browse all cached packages with filtering by ecosystem and sorting by hits, size, name, or vulnerability count.
|
|
||||||
- **Search** (`/ui/search?q=...`) -- search cached packages by name.
|
|
||||||
- **Package detail** (`/ui/package/{ecosystem}/{name}`) -- metadata, license, vulnerabilities, and version list for a package. You can select two versions to compare.
|
|
||||||
- **Version detail** (`/ui/package/{ecosystem}/{name}/{version}`) -- per-version metadata, integrity hash, artifact cache status, and hit counts.
|
|
||||||
- **Source browser** (`/ui/package/{ecosystem}/{name}/{version}/browse`) -- browse files inside cached archives with syntax highlighting for text files and image previews.
|
|
||||||
- **Version diff** (`/ui/package/{ecosystem}/{name}/compare/{v1}...{v2}`) -- side-by-side diff of two cached versions showing added, removed, and changed files.
|
|
||||||
|
|
||||||
## Monitoring
|
|
||||||
|
|
||||||
The proxy exposes Prometheus metrics at `GET /metrics`. All metric names are prefixed with `proxy_`.
|
|
||||||
|
|
||||||
| Metric | Type | Labels | Description |
|
|
||||||
|--------|------|--------|-------------|
|
|
||||||
| `proxy_requests_total` | counter | `ecosystem`, `status` | Proxy responses by package ecosystem and HTTP status |
|
|
||||||
| `proxy_request_duration_seconds` | histogram | `ecosystem`, `status` | Proxy request duration |
|
|
||||||
| `proxy_cache_hits_total` | counter | `ecosystem` | Cache hits |
|
|
||||||
| `proxy_cache_misses_total` | counter | `ecosystem` | Cache misses |
|
|
||||||
| `proxy_cache_size_bytes` | gauge | | Total size of cached artifacts |
|
|
||||||
| `proxy_cached_artifacts_total` | gauge | | Number of cached artifacts |
|
|
||||||
| `proxy_upstream_fetch_duration_seconds` | histogram | `ecosystem` | Time spent fetching from upstream |
|
|
||||||
| `proxy_upstream_errors_total` | counter | `ecosystem`, `error_type` | Upstream fetch failures |
|
|
||||||
| `proxy_storage_operation_duration_seconds` | histogram | `operation` | Storage read/write latency |
|
|
||||||
| `proxy_storage_errors_total` | counter | `operation` | Storage read/write failures |
|
|
||||||
| `proxy_active_requests` | gauge | | In-flight requests |
|
|
||||||
| `proxy_health_probe_failures_total` | counter | `step` | Storage health probe failures by failing step (`write`, `size`, `read`, `verify`, `delete`). |
|
|
||||||
| `proxy_circuit_breaker_state` | gauge | `registry` | Artifact-fetch circuit breaker state per upstream registry (0 closed, 2 open). Published once that registry's breaker has tripped. |
|
|
||||||
| `proxy_circuit_breaker_trips_total` | counter | `registry` | Circuit breaker trips per upstream registry. |
|
|
||||||
|
|
||||||
Cache size and artifact count are refreshed every 60 seconds. Circuit breaker state is read from the fetcher on each scrape of `/metrics` and each `/health` request, so `proxy_circuit_breaker_trips_total` counts the trips visible between those reads — a breaker that opens and recovers entirely between two scrapes is not counted. The remaining metrics update on each request.
|
|
||||||
|
|
||||||
The breaker metrics carry one series per upstream host, but only for hosts whose breaker has tripped at least once since startup. A breaker is created per host the proxy fetches artifacts from, and for some ecosystems that host comes from upstream metadata rather than from configuration (composer takes it from a package's `dist.url`, helm from the chart URLs in `index.yaml`), so publishing every host would let upstream content grow the series count for the lifetime of the process. Once a host has tripped it keeps reporting, so a recovery still shows up as a transition to 0 rather than as a series that vanishes. `/health` is not a persistent time series and lists every breaker, tripped or not.
|
|
||||||
|
|
||||||
The `registry` label is the host of the URL the artifact was fetched from. Because that URL can come from upstream metadata, it is not always one a host can be read off — a signed `dist.url` that fails to parse, for instance — and such a breaker is labelled `hostless-url-<digest>` instead, where the digest is keyed by a value drawn fresh at startup. Neither `/metrics` nor `/health` requires authentication, so a fetch URL is never published as a label or a key; the digest identifies the breaker for as long as the process runs without revealing the URL behind it or letting a chosen URL be matched against it.
|
|
||||||
|
|
||||||
Alert on `proxy_circuit_breaker_state == 2` sustained for more than a few minutes: while a breaker is open, artifact downloads for that upstream fail with HTTP 502 on every cache miss, and only a single probe request per backoff interval reaches the upstream. Cached artifacts keep serving, and so does metadata for the same ecosystem (metadata does not go through the circuit breaker), so installs fail in a way that looks like a partial upstream outage.
|
|
||||||
|
|
||||||
### Health Check
|
|
||||||
|
|
||||||
`/health` returns a structured JSON report of subsystem health. HTTP 200 if all checks pass; 503 if any fail.
|
|
||||||
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"status": "ok",
|
|
||||||
"checks": {
|
|
||||||
"database": {"status": "ok"},
|
|
||||||
"storage": {"status": "ok"}
|
|
||||||
},
|
|
||||||
"circuit_breakers": {
|
|
||||||
"registry.npmjs.org": "closed",
|
|
||||||
"static.crates.io": "open"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
Failing checks include an `"error"` field. Storage failures also include a `"step"` field identifying which probe step failed (`write`, `size`, `read`, `verify`, `delete`). When the database check fails, the storage entry reports `{"status": "skipped"}` so the response always carries the same key set.
|
|
||||||
|
|
||||||
`circuit_breakers` reports the state of each upstream's artifact-fetch circuit breaker (`"open"` or `"closed"`), keyed by upstream host — or by the `hostless-url-<digest>` placeholder described under [Monitoring](#monitoring) where the fetch URL has no host to read. The key is omitted until the proxy has fetched an artifact from at least one upstream, and a host appears only once a breaker has been created for it. Breakers trip after repeated upstream failures and retry the upstream after an exponential backoff. While one is open, artifact downloads for that host return HTTP 502 on a cache miss without contacting the upstream; already-cached artifacts are still served from storage, since the cache is checked before the fetcher. A breaker is reported as `"open"` throughout its backoff, including the half-open window in which it admits one probe request to test recovery. Breaker state is per process and in memory, so a restart clears it, but a restart is not needed for recovery: the backoff keeps retrying for as long as the breaker is open, so it closes on its own once the upstream serves again.
|
|
||||||
|
|
||||||
An open breaker does **not** set `status` to `"error"` or change the HTTP status code: it reports a specific upstream refusing to serve, not this proxy being unfit to receive traffic, and failing the readiness probe over one unhealthy upstream would pull the pod out of rotation for every other ecosystem too. Use `proxy_circuit_breaker_state` for alerting on it.
|
|
||||||
|
|
||||||
Storage probe results are cached for `health.storage_probe_interval` (default 30s) to bound the cost of probing remote backends. A probe holds an internal mutex for up to 10 seconds (the hardcoded per-probe timeout), so `/health` is intended as a Kubernetes **readiness** probe rather than a liveness probe — a slow S3 round-trip should pull the pod from rotation, not restart it.
|
|
||||||
|
|
||||||
Scrape config for Prometheus:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
scrape_configs:
|
|
||||||
- job_name: git-pkgs-proxy
|
|
||||||
static_configs:
|
|
||||||
- targets: ["localhost:8080"]
|
|
||||||
```
|
|
||||||
|
|
||||||
## Production Deployment
|
## Production Deployment
|
||||||
|
|
||||||
### Systemd Service
|
### Systemd Service
|
||||||
|
|
@ -1181,25 +655,27 @@ sudo systemctl start proxy
|
||||||
|
|
||||||
### Docker
|
### Docker
|
||||||
|
|
||||||
A Dockerfile is included in the repo. Build and run:
|
```dockerfile
|
||||||
|
FROM golang:1.23-alpine AS build
|
||||||
|
WORKDIR /app
|
||||||
|
COPY . .
|
||||||
|
RUN go build -o proxy ./cmd/proxy
|
||||||
|
|
||||||
|
FROM alpine:latest
|
||||||
|
RUN apk --no-cache add ca-certificates
|
||||||
|
COPY --from=build /app/proxy /usr/local/bin/
|
||||||
|
EXPOSE 8080
|
||||||
|
VOLUME ["/data"]
|
||||||
|
CMD ["proxy", "-storage", "/data/artifacts", "-database", "/data/proxy.db"]
|
||||||
|
```
|
||||||
|
|
||||||
|
Build and run:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
docker build -t proxy .
|
docker build -t proxy .
|
||||||
docker run -p 8080:8080 -v proxy-data:/data proxy
|
docker run -p 8080:8080 -v proxy-data:/data proxy
|
||||||
```
|
```
|
||||||
|
|
||||||
With Postgres and S3:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
docker run -p 8080:8080 \
|
|
||||||
-e PROXY_DATABASE_DRIVER=postgres \
|
|
||||||
-e PROXY_DATABASE_URL=postgres://user:pass@db:5432/proxy \
|
|
||||||
-e PROXY_STORAGE_URL=s3://my-bucket?region=us-east-1 \
|
|
||||||
-e AWS_ACCESS_KEY_ID=... \
|
|
||||||
-e AWS_SECRET_ACCESS_KEY=... \
|
|
||||||
proxy
|
|
||||||
```
|
|
||||||
|
|
||||||
### Behind a Reverse Proxy
|
### Behind a Reverse Proxy
|
||||||
|
|
||||||
When running behind nginx, Apache, or another reverse proxy, set `base_url` to your public URL:
|
When running behind nginx, Apache, or another reverse proxy, set `base_url` to your public URL:
|
||||||
|
|
@ -1208,47 +684,22 @@ When running behind nginx, Apache, or another reverse proxy, set `base_url` to y
|
||||||
base_url: "https://proxy.example.com"
|
base_url: "https://proxy.example.com"
|
||||||
```
|
```
|
||||||
|
|
||||||
If the UI is reached on a different hostname than the package endpoints — for example, the UI exposed publicly on a domain while build machines hit a Docker network alias — set `ui_base_url` separately. `base_url` is the URL package managers and metadata rewriting use; `ui_base_url` is the URL advertised to humans visiting the web UI (canonical/`og:url` tags and the install guide banner):
|
nginx example:
|
||||||
|
|
||||||
```yaml
|
|
||||||
base_url: "http://pkg-proxy:8080" # internal alias for build machines
|
|
||||||
ui_base_url: "https://proxy.example.com/ui" # public UI URL
|
|
||||||
```
|
|
||||||
|
|
||||||
When unset, `ui_base_url` defaults to `base_url`.
|
|
||||||
|
|
||||||
> **Warning:** the proxy serves the UI and package endpoints on the same listener. Setting `ui_base_url` only changes what URL the UI advertises to humans; it does not stop package endpoints from being reachable on the same hostname and port. When fronting the proxy with a public reverse proxy, restrict the public route to `PathPrefix(/ui)` (or your proxy's equivalent), otherwise `/npm`, `/pypi`, and the other package endpoints stay exposed alongside the UI.
|
|
||||||
|
|
||||||
nginx example, restricting the public host to the UI while leaving package endpoints reachable only on the internal listener:
|
|
||||||
|
|
||||||
```nginx
|
```nginx
|
||||||
server {
|
server {
|
||||||
listen 443 ssl;
|
listen 443 ssl;
|
||||||
server_name proxy.example.com;
|
server_name proxy.example.com;
|
||||||
|
|
||||||
location /ui/ {
|
location / {
|
||||||
proxy_pass http://127.0.0.1:8080;
|
proxy_pass http://127.0.0.1:8080;
|
||||||
proxy_set_header Host $host;
|
proxy_set_header Host $host;
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
proxy_buffering off;
|
proxy_buffering off;
|
||||||
}
|
}
|
||||||
|
|
||||||
location / {
|
|
||||||
return 404;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
Traefik example using `PathPrefix(/ui)` so the public router only matches UI traffic:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
labels:
|
|
||||||
traefik.enable: "true"
|
|
||||||
traefik.http.services.pkg-proxy.loadbalancer.server.port: "8080"
|
|
||||||
traefik.http.routers.pkg-proxy.rule: "Host(`proxy.example.com`) && PathPrefix(`/ui`)"
|
|
||||||
traefik.http.routers.pkg-proxy.entrypoints: "websecure"
|
|
||||||
```
|
|
||||||
|
|
||||||
## Cache Management
|
## Cache Management
|
||||||
|
|
||||||
The proxy stores artifacts in the configured storage directory with this structure:
|
The proxy stores artifacts in the configured storage directory with this structure:
|
||||||
|
|
@ -1277,7 +728,7 @@ cache/artifacts/
|
||||||
└── nginx-1.24.0-1.fc39.x86_64.rpm
|
└── nginx-1.24.0-1.fc39.x86_64.rpm
|
||||||
```
|
```
|
||||||
|
|
||||||
Cache metadata is stored in SQLite (default) or PostgreSQL. To clear a local cache:
|
Cache metadata is stored in an SQLite database. To clear the cache:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
rm -rf ./cache/artifacts/*
|
rm -rf ./cache/artifacts/*
|
||||||
|
|
@ -1289,8 +740,7 @@ The proxy will recreate the database on next start.
|
||||||
## Building from Source
|
## Building from Source
|
||||||
|
|
||||||
Requirements:
|
Requirements:
|
||||||
|
- Go 1.23 or later
|
||||||
- Go (the project version is declared in `go.mod`)
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
git clone https://github.com/git-pkgs/proxy.git
|
git clone https://github.com/git-pkgs/proxy.git
|
||||||
|
|
|
||||||
|
|
@ -1,10 +1,5 @@
|
||||||
// Command proxy runs the git-pkgs package registry proxy server.
|
// Command proxy runs the git-pkgs package registry proxy server.
|
||||||
//
|
//
|
||||||
// @title git-pkgs proxy API
|
|
||||||
// @version 0.1.0
|
|
||||||
// @description HTTP API for package enrichment, vulnerability lookup, cache stats, and source browsing.
|
|
||||||
// @BasePath /
|
|
||||||
//
|
|
||||||
// The proxy caches package artifacts from upstream registries (npm, cargo, etc.)
|
// The proxy caches package artifacts from upstream registries (npm, cargo, etc.)
|
||||||
// providing faster, more reliable access for development teams.
|
// providing faster, more reliable access for development teams.
|
||||||
//
|
//
|
||||||
|
|
@ -16,7 +11,6 @@
|
||||||
//
|
//
|
||||||
// serve Start the proxy server (default if no command given)
|
// serve Start the proxy server (default if no command given)
|
||||||
// stats Show cache statistics
|
// stats Show cache statistics
|
||||||
// mirror Pre-populate cache from PURLs, SBOMs, or registries
|
|
||||||
//
|
//
|
||||||
// Serve Flags:
|
// Serve Flags:
|
||||||
//
|
//
|
||||||
|
|
@ -40,8 +34,6 @@
|
||||||
// Log level: debug, info, warn, error (default "info")
|
// Log level: debug, info, warn, error (default "info")
|
||||||
// -log-format string
|
// -log-format string
|
||||||
// Log format: text, json (default "text")
|
// Log format: text, json (default "text")
|
||||||
// -access-log string
|
|
||||||
// Path to the JSONL access log (disabled by default)
|
|
||||||
//
|
//
|
||||||
// Stats Flags:
|
// Stats Flags:
|
||||||
//
|
//
|
||||||
|
|
@ -74,14 +66,6 @@
|
||||||
// PROXY_DATABASE_URL - PostgreSQL connection URL
|
// PROXY_DATABASE_URL - PostgreSQL connection URL
|
||||||
// PROXY_LOG_LEVEL - Log level
|
// PROXY_LOG_LEVEL - Log level
|
||||||
// PROXY_LOG_FORMAT - Log format
|
// PROXY_LOG_FORMAT - Log format
|
||||||
// PROXY_ACCESS_LOG_PATH - JSONL access log path
|
|
||||||
// PROXY_UPSTREAM_* - Upstream URLs and network access controls
|
|
||||||
// PROXY_GRADLE_BUILD_CACHE_READ_ONLY - Disable Gradle PUT uploads
|
|
||||||
// PROXY_GRADLE_BUILD_CACHE_MAX_UPLOAD_SIZE - Max Gradle PUT request body size
|
|
||||||
// PROXY_GRADLE_BUILD_CACHE_MAX_AGE - Gradle cache max age eviction
|
|
||||||
// PROXY_GRADLE_BUILD_CACHE_MAX_SIZE - Gradle cache max total size
|
|
||||||
// PROXY_GRADLE_BUILD_CACHE_SWEEP_INTERVAL - Gradle cache eviction sweep interval
|
|
||||||
// PROXY_HEALTH_STORAGE_PROBE_INTERVAL - Storage health probe cache interval (default "30s")
|
|
||||||
//
|
//
|
||||||
// Example:
|
// Example:
|
||||||
//
|
//
|
||||||
|
|
@ -106,21 +90,14 @@ import (
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"os"
|
"os"
|
||||||
"os/signal"
|
"os/signal"
|
||||||
"runtime/debug"
|
|
||||||
"strings"
|
"strings"
|
||||||
"syscall"
|
"syscall"
|
||||||
|
|
||||||
"github.com/git-pkgs/proxy/internal/config"
|
"github.com/git-pkgs/proxy/internal/config"
|
||||||
"github.com/git-pkgs/proxy/internal/database"
|
"github.com/git-pkgs/proxy/internal/database"
|
||||||
"github.com/git-pkgs/proxy/internal/handler"
|
|
||||||
"github.com/git-pkgs/proxy/internal/mirror"
|
|
||||||
"github.com/git-pkgs/proxy/internal/server"
|
"github.com/git-pkgs/proxy/internal/server"
|
||||||
"github.com/git-pkgs/proxy/internal/storage"
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
const defaultTopN = 10
|
|
||||||
|
|
||||||
var (
|
var (
|
||||||
// Version is set at build time.
|
// Version is set at build time.
|
||||||
Version = "dev"
|
Version = "dev"
|
||||||
|
|
@ -129,15 +106,6 @@ var (
|
||||||
Commit = "unknown"
|
Commit = "unknown"
|
||||||
)
|
)
|
||||||
|
|
||||||
func init() {
|
|
||||||
if Version != "dev" {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if bi, ok := debug.ReadBuildInfo(); ok && bi.Main.Version != "" && bi.Main.Version != "(devel)" {
|
|
||||||
Version = bi.Main.Version
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func main() {
|
func main() {
|
||||||
if len(os.Args) > 1 {
|
if len(os.Args) > 1 {
|
||||||
switch os.Args[1] {
|
switch os.Args[1] {
|
||||||
|
|
@ -149,10 +117,6 @@ func main() {
|
||||||
os.Args = append(os.Args[:1], os.Args[2:]...)
|
os.Args = append(os.Args[:1], os.Args[2:]...)
|
||||||
runStats()
|
runStats()
|
||||||
return
|
return
|
||||||
case "mirror":
|
|
||||||
os.Args = append(os.Args[:1], os.Args[2:]...)
|
|
||||||
runMirror()
|
|
||||||
return
|
|
||||||
case "-version", "--version":
|
case "-version", "--version":
|
||||||
fmt.Printf("proxy %s (%s)\n", Version, Commit)
|
fmt.Printf("proxy %s (%s)\n", Version, Commit)
|
||||||
os.Exit(0)
|
os.Exit(0)
|
||||||
|
|
@ -174,7 +138,6 @@ Usage: proxy [command] [flags]
|
||||||
Commands:
|
Commands:
|
||||||
serve Start the proxy server (default)
|
serve Start the proxy server (default)
|
||||||
stats Show cache statistics
|
stats Show cache statistics
|
||||||
mirror Pre-populate cache from PURLs, SBOMs, or registries
|
|
||||||
|
|
||||||
Run 'proxy <command> -help' for more information on a command.
|
Run 'proxy <command> -help' for more information on a command.
|
||||||
|
|
||||||
|
|
@ -196,7 +159,6 @@ func runServe() {
|
||||||
databaseURL := fs.String("database-url", "", "PostgreSQL connection URL")
|
databaseURL := fs.String("database-url", "", "PostgreSQL connection URL")
|
||||||
logLevel := fs.String("log-level", "", "Log level: debug, info, warn, error")
|
logLevel := fs.String("log-level", "", "Log level: debug, info, warn, error")
|
||||||
logFormat := fs.String("log-format", "", "Log format: text, json")
|
logFormat := fs.String("log-format", "", "Log format: text, json")
|
||||||
accessLogPath := fs.String("access-log", "", "Path to the JSONL access log")
|
|
||||||
version := fs.Bool("version", false, "Print version and exit")
|
version := fs.Bool("version", false, "Print version and exit")
|
||||||
|
|
||||||
fs.Usage = func() {
|
fs.Usage = func() {
|
||||||
|
|
@ -214,39 +176,6 @@ func runServe() {
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_DATABASE_URL PostgreSQL connection URL\n")
|
fmt.Fprintf(os.Stderr, " PROXY_DATABASE_URL PostgreSQL connection URL\n")
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_LOG_LEVEL Log level\n")
|
fmt.Fprintf(os.Stderr, " PROXY_LOG_LEVEL Log level\n")
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_LOG_FORMAT Log format\n")
|
fmt.Fprintf(os.Stderr, " PROXY_LOG_FORMAT Log format\n")
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_ACCESS_LOG_PATH JSONL access log path\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_ALLOW_PRIVATE_HOSTS Comma-separated private upstream hosts\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_ALLOW_LOOPBACK Permit loopback upstreams and redirects\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_NPM npm registry upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_CARGO Cargo index upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_CARGO_DOWNLOAD Cargo download upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_GEM RubyGems upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_GO Go module proxy upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_HEX Hex repository upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_HEX_API Hex API upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_PUB pub registry upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_PYPI PyPI index and API upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_PYPI_DOWNLOAD PyPI download upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_MAVEN Maven repository upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL Gradle Plugin Portal upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_NUGET NuGet API upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_NUGET_SEARCH NuGet search upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_COMPOSER Packagist API upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_COMPOSER_REPOSITORY Packagist repository upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_CONAN Conan registry upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_CONDA Conda channel upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_CRAN CRAN mirror upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_JULIA Julia package server upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_SWIFT Swift Package Registry upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_OCI_DEFAULT Default OCI registry upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_DEBIAN Debian repository upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_RPM RPM repository upstream URL\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_READ_ONLY Disable Gradle PUT uploads\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_MAX_UPLOAD_SIZE Max Gradle PUT request body size\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_MAX_AGE Gradle cache max age eviction\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_MAX_SIZE Gradle cache max total size\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_SWEEP_INTERVAL Gradle cache eviction sweep interval\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_HEALTH_STORAGE_PROBE_INTERVAL Storage health probe cache interval\n")
|
|
||||||
}
|
}
|
||||||
|
|
||||||
_ = fs.Parse(os.Args[1:])
|
_ = fs.Parse(os.Args[1:])
|
||||||
|
|
@ -277,7 +206,7 @@ func runServe() {
|
||||||
cfg.Storage.URL = *storageURL
|
cfg.Storage.URL = *storageURL
|
||||||
}
|
}
|
||||||
if *storagePath != "" {
|
if *storagePath != "" {
|
||||||
cfg.Storage.Path = *storagePath //nolint:staticcheck // backwards compat
|
cfg.Storage.Path = *storagePath
|
||||||
}
|
}
|
||||||
if *databaseDriver != "" {
|
if *databaseDriver != "" {
|
||||||
cfg.Database.Driver = *databaseDriver
|
cfg.Database.Driver = *databaseDriver
|
||||||
|
|
@ -294,9 +223,6 @@ func runServe() {
|
||||||
if *logFormat != "" {
|
if *logFormat != "" {
|
||||||
cfg.Log.Format = *logFormat
|
cfg.Log.Format = *logFormat
|
||||||
}
|
}
|
||||||
if *accessLogPath != "" {
|
|
||||||
cfg.AccessLog.Path = *accessLogPath
|
|
||||||
}
|
|
||||||
|
|
||||||
// Validate configuration
|
// Validate configuration
|
||||||
if err := cfg.Validate(); err != nil {
|
if err := cfg.Validate(); err != nil {
|
||||||
|
|
@ -308,10 +234,7 @@ func runServe() {
|
||||||
logger := setupLogger(cfg.Log.Level, cfg.Log.Format)
|
logger := setupLogger(cfg.Log.Level, cfg.Log.Format)
|
||||||
|
|
||||||
// Create and start server
|
// Create and start server
|
||||||
srv, err := server.New(cfg, logger, server.BuildInfo{
|
srv, err := server.New(cfg, logger)
|
||||||
Version: Version,
|
|
||||||
Commit: Commit,
|
|
||||||
})
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
logger.Error("failed to create server", "error", err)
|
logger.Error("failed to create server", "error", err)
|
||||||
os.Exit(1)
|
os.Exit(1)
|
||||||
|
|
@ -319,6 +242,7 @@ func runServe() {
|
||||||
|
|
||||||
// Handle shutdown signals
|
// Handle shutdown signals
|
||||||
ctx, cancel := context.WithCancel(context.Background())
|
ctx, cancel := context.WithCancel(context.Background())
|
||||||
|
defer cancel()
|
||||||
|
|
||||||
go func() {
|
go func() {
|
||||||
sigCh := make(chan os.Signal, 1)
|
sigCh := make(chan os.Signal, 1)
|
||||||
|
|
@ -337,12 +261,10 @@ func runServe() {
|
||||||
// Wait for shutdown or error
|
// Wait for shutdown or error
|
||||||
select {
|
select {
|
||||||
case <-ctx.Done():
|
case <-ctx.Done():
|
||||||
cancel()
|
|
||||||
if err := srv.Shutdown(context.Background()); err != nil {
|
if err := srv.Shutdown(context.Background()); err != nil {
|
||||||
logger.Error("shutdown error", "error", err)
|
logger.Error("shutdown error", "error", err)
|
||||||
}
|
}
|
||||||
case err := <-errCh:
|
case err := <-errCh:
|
||||||
cancel()
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
logger.Error("server error", "error", err)
|
logger.Error("server error", "error", err)
|
||||||
os.Exit(1)
|
os.Exit(1)
|
||||||
|
|
@ -356,8 +278,8 @@ func runStats() {
|
||||||
databasePath := fs.String("database-path", "./cache/proxy.db", "Path to SQLite database file")
|
databasePath := fs.String("database-path", "./cache/proxy.db", "Path to SQLite database file")
|
||||||
databaseURL := fs.String("database-url", "", "PostgreSQL connection URL")
|
databaseURL := fs.String("database-url", "", "PostgreSQL connection URL")
|
||||||
asJSON := fs.Bool("json", false, "Output as JSON")
|
asJSON := fs.Bool("json", false, "Output as JSON")
|
||||||
popular := fs.Int("popular", defaultTopN, "Show top N most popular packages")
|
popular := fs.Int("popular", 10, "Show top N most popular packages")
|
||||||
recent := fs.Int("recent", defaultTopN, "Show N recently cached packages")
|
recent := fs.Int("recent", 10, "Show N recently cached packages")
|
||||||
|
|
||||||
fs.Usage = func() {
|
fs.Usage = func() {
|
||||||
fmt.Fprintf(os.Stderr, "git-pkgs proxy - Show cache statistics\n\n")
|
fmt.Fprintf(os.Stderr, "git-pkgs proxy - Show cache statistics\n\n")
|
||||||
|
|
@ -399,192 +321,36 @@ func runStats() {
|
||||||
db, err = database.Open(*databasePath)
|
db, err = database.Open(*databasePath)
|
||||||
}
|
}
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
fmt.Fprintf(os.Stderr, "error opening database: %v\n", err)
|
|
||||||
os.Exit(1)
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := printStats(db, *popular, *recent, *asJSON); err != nil {
|
|
||||||
fmt.Fprintf(os.Stderr, "%v\n", err)
|
|
||||||
os.Exit(1)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func runMirror() {
|
|
||||||
fs := flag.NewFlagSet("mirror", flag.ExitOnError)
|
|
||||||
configPath := fs.String("config", "", "Path to configuration file")
|
|
||||||
storageURL := fs.String("storage-url", "", "Storage URL (file:// or s3://)")
|
|
||||||
databaseDriver := fs.String("database-driver", "", "Database driver: sqlite or postgres")
|
|
||||||
databasePath := fs.String("database-path", "", "Path to SQLite database file")
|
|
||||||
databaseURL := fs.String("database-url", "", "PostgreSQL connection URL")
|
|
||||||
sbomPath := fs.String("sbom", "", "Path to CycloneDX or SPDX SBOM file")
|
|
||||||
concurrency := fs.Int("concurrency", 4, "Number of parallel downloads") //nolint:mnd // default concurrency
|
|
||||||
dryRun := fs.Bool("dry-run", false, "Show what would be mirrored without downloading")
|
|
||||||
|
|
||||||
fs.Usage = func() {
|
|
||||||
fmt.Fprintf(os.Stderr, "git-pkgs proxy - Pre-populate cache\n\n")
|
|
||||||
fmt.Fprintf(os.Stderr, "Usage: proxy mirror [flags] [purl...]\n\n")
|
|
||||||
fmt.Fprintf(os.Stderr, "Examples:\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " proxy mirror pkg:npm/lodash@4.17.21\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " proxy mirror --sbom sbom.cdx.json\n")
|
|
||||||
fmt.Fprintf(os.Stderr, " proxy mirror pkg:npm/lodash # all versions\n\n")
|
|
||||||
fmt.Fprintf(os.Stderr, "Flags:\n")
|
|
||||||
fs.PrintDefaults()
|
|
||||||
}
|
|
||||||
|
|
||||||
_ = fs.Parse(os.Args[1:])
|
|
||||||
purls := fs.Args()
|
|
||||||
|
|
||||||
// Determine source
|
|
||||||
var source mirror.Source
|
|
||||||
switch {
|
|
||||||
case *sbomPath != "":
|
|
||||||
data, err := os.ReadFile(*sbomPath)
|
|
||||||
if err != nil {
|
|
||||||
fmt.Fprintf(os.Stderr, "error reading SBOM %s: %v\n", *sbomPath, err)
|
|
||||||
os.Exit(1)
|
|
||||||
}
|
|
||||||
source = &mirror.SBOMSource{Data: data, Name: *sbomPath}
|
|
||||||
case len(purls) > 0:
|
|
||||||
source = &mirror.PURLSource{PURLs: purls}
|
|
||||||
default:
|
|
||||||
fmt.Fprintf(os.Stderr, "error: provide PURLs or --sbom\n")
|
|
||||||
fs.Usage()
|
|
||||||
os.Exit(1)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Load config
|
|
||||||
cfg, err := loadConfig(*configPath)
|
|
||||||
if err != nil {
|
|
||||||
fmt.Fprintf(os.Stderr, "error loading config: %v\n", err)
|
|
||||||
os.Exit(1)
|
|
||||||
}
|
|
||||||
cfg.LoadFromEnv()
|
|
||||||
|
|
||||||
if *storageURL != "" {
|
|
||||||
cfg.Storage.URL = *storageURL
|
|
||||||
}
|
|
||||||
if *databaseDriver != "" {
|
|
||||||
cfg.Database.Driver = *databaseDriver
|
|
||||||
}
|
|
||||||
if *databasePath != "" {
|
|
||||||
cfg.Database.Path = *databasePath
|
|
||||||
}
|
|
||||||
if *databaseURL != "" {
|
|
||||||
cfg.Database.URL = *databaseURL
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := cfg.Validate(); err != nil {
|
|
||||||
fmt.Fprintf(os.Stderr, "invalid configuration: %v\n", err)
|
|
||||||
os.Exit(1)
|
|
||||||
}
|
|
||||||
|
|
||||||
logger := setupLogger("info", "text")
|
|
||||||
|
|
||||||
// Open database
|
|
||||||
var db *database.DB
|
|
||||||
switch cfg.Database.Driver {
|
|
||||||
case "postgres":
|
|
||||||
db, err = database.OpenPostgresOrCreate(cfg.Database.URL)
|
|
||||||
default:
|
|
||||||
db, err = database.OpenOrCreate(cfg.Database.Path)
|
|
||||||
}
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
fmt.Fprintf(os.Stderr, "error opening database: %v\n", err)
|
fmt.Fprintf(os.Stderr, "error opening database: %v\n", err)
|
||||||
os.Exit(1)
|
os.Exit(1)
|
||||||
}
|
}
|
||||||
defer func() { _ = db.Close() }()
|
defer func() { _ = db.Close() }()
|
||||||
|
|
||||||
if err := db.MigrateSchema(); err != nil {
|
// Get stats
|
||||||
_ = db.Close()
|
|
||||||
fmt.Fprintf(os.Stderr, "error migrating schema: %v\n", err)
|
|
||||||
os.Exit(1) //nolint:gocritic // db closed above
|
|
||||||
}
|
|
||||||
|
|
||||||
// Open storage
|
|
||||||
sURL := cfg.Storage.URL
|
|
||||||
if sURL == "" {
|
|
||||||
sURL = "file://" + cfg.Storage.Path //nolint:staticcheck // backwards compat
|
|
||||||
}
|
|
||||||
store, err := storage.OpenBucket(context.Background(), sURL)
|
|
||||||
if err != nil {
|
|
||||||
_ = db.Close()
|
|
||||||
fmt.Fprintf(os.Stderr, "error opening storage: %v\n", err)
|
|
||||||
os.Exit(1) //nolint:gocritic // db closed above
|
|
||||||
}
|
|
||||||
|
|
||||||
// Build proxy (reuses same pipeline as serve)
|
|
||||||
fetcher := fetch.NewFetcher()
|
|
||||||
resolver := fetch.NewResolver()
|
|
||||||
proxy := handler.NewProxy(db, store, fetcher, resolver, logger)
|
|
||||||
proxy.CacheMetadata = true // mirror always caches metadata
|
|
||||||
proxy.MetadataTTL = cfg.ParseMetadataTTL()
|
|
||||||
proxy.MetadataMaxSize = cfg.ParseMetadataMaxSize()
|
|
||||||
|
|
||||||
m := mirror.New(proxy, db, store, logger, *concurrency)
|
|
||||||
|
|
||||||
ctx, cancel := context.WithCancel(context.Background())
|
|
||||||
go func() {
|
|
||||||
sigCh := make(chan os.Signal, 1)
|
|
||||||
signal.Notify(sigCh, syscall.SIGINT, syscall.SIGTERM)
|
|
||||||
<-sigCh
|
|
||||||
cancel()
|
|
||||||
}()
|
|
||||||
|
|
||||||
if *dryRun {
|
|
||||||
items, err := m.RunDryRun(ctx, source)
|
|
||||||
if err != nil {
|
|
||||||
fmt.Fprintf(os.Stderr, "error: %v\n", err)
|
|
||||||
os.Exit(1)
|
|
||||||
}
|
|
||||||
fmt.Printf("Would mirror %d package versions:\n", len(items))
|
|
||||||
for _, item := range items {
|
|
||||||
fmt.Printf(" %s\n", item)
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
progress, err := m.Run(ctx, source)
|
|
||||||
if err != nil {
|
|
||||||
fmt.Fprintf(os.Stderr, "error: %v\n", err)
|
|
||||||
os.Exit(1)
|
|
||||||
}
|
|
||||||
|
|
||||||
fmt.Printf("Mirror complete: %d downloaded, %d skipped (cached), %d failed, %s total\n",
|
|
||||||
progress.Completed, progress.Skipped, progress.Failed, formatSize(progress.Bytes))
|
|
||||||
|
|
||||||
if len(progress.Errors) > 0 {
|
|
||||||
fmt.Fprintf(os.Stderr, "\nErrors:\n")
|
|
||||||
for _, e := range progress.Errors {
|
|
||||||
fmt.Fprintf(os.Stderr, " %s/%s@%s: %s\n", e.Ecosystem, e.Name, e.Version, e.Error)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func printStats(db *database.DB, popular, recent int, asJSON bool) error {
|
|
||||||
defer func() { _ = db.Close() }()
|
|
||||||
|
|
||||||
stats, err := db.GetCacheStats()
|
stats, err := db.GetCacheStats()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("error getting stats: %w", err)
|
fmt.Fprintf(os.Stderr, "error getting stats: %v\n", err)
|
||||||
|
os.Exit(1)
|
||||||
}
|
}
|
||||||
|
|
||||||
popularPkgs, err := db.GetMostPopularPackages(popular)
|
popularPkgs, err := db.GetMostPopularPackages(*popular)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("error getting popular packages: %w", err)
|
fmt.Fprintf(os.Stderr, "error getting popular packages: %v\n", err)
|
||||||
|
os.Exit(1)
|
||||||
}
|
}
|
||||||
|
|
||||||
recentPkgs, err := db.GetRecentlyCachedPackages(recent)
|
recentPkgs, err := db.GetRecentlyCachedPackages(*recent)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("error getting recent packages: %w", err)
|
fmt.Fprintf(os.Stderr, "error getting recent packages: %v\n", err)
|
||||||
|
os.Exit(1)
|
||||||
}
|
}
|
||||||
|
|
||||||
if asJSON {
|
if *asJSON {
|
||||||
outputJSON(stats, popularPkgs, recentPkgs)
|
outputJSON(stats, popularPkgs, recentPkgs)
|
||||||
} else {
|
} else {
|
||||||
outputText(stats, popularPkgs, recentPkgs)
|
outputText(stats, popularPkgs, recentPkgs)
|
||||||
}
|
}
|
||||||
return nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
type jsonOutput struct {
|
type jsonOutput struct {
|
||||||
|
|
|
||||||
|
|
@ -1,58 +0,0 @@
|
||||||
package main
|
|
||||||
|
|
||||||
import (
|
|
||||||
"os"
|
|
||||||
"os/exec"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestServeHelpListsUpstreamEnvironmentVariables(t *testing.T) {
|
|
||||||
cmd := exec.Command(os.Args[0], "-test.run=^TestServeHelpProcess$")
|
|
||||||
cmd.Env = append(os.Environ(), "PROXY_TEST_SERVE_HELP=1")
|
|
||||||
output, err := cmd.CombinedOutput()
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("serve help failed: %v\n%s", err, output)
|
|
||||||
}
|
|
||||||
|
|
||||||
variables := []string{
|
|
||||||
"PROXY_UPSTREAM_ALLOW_PRIVATE_HOSTS",
|
|
||||||
"PROXY_UPSTREAM_ALLOW_LOOPBACK",
|
|
||||||
"PROXY_UPSTREAM_NPM",
|
|
||||||
"PROXY_UPSTREAM_CARGO",
|
|
||||||
"PROXY_UPSTREAM_CARGO_DOWNLOAD",
|
|
||||||
"PROXY_UPSTREAM_GEM",
|
|
||||||
"PROXY_UPSTREAM_GO",
|
|
||||||
"PROXY_UPSTREAM_HEX",
|
|
||||||
"PROXY_UPSTREAM_HEX_API",
|
|
||||||
"PROXY_UPSTREAM_PUB",
|
|
||||||
"PROXY_UPSTREAM_PYPI",
|
|
||||||
"PROXY_UPSTREAM_PYPI_DOWNLOAD",
|
|
||||||
"PROXY_UPSTREAM_MAVEN",
|
|
||||||
"PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL",
|
|
||||||
"PROXY_UPSTREAM_NUGET",
|
|
||||||
"PROXY_UPSTREAM_NUGET_SEARCH",
|
|
||||||
"PROXY_UPSTREAM_COMPOSER",
|
|
||||||
"PROXY_UPSTREAM_COMPOSER_REPOSITORY",
|
|
||||||
"PROXY_UPSTREAM_CONAN",
|
|
||||||
"PROXY_UPSTREAM_CONDA",
|
|
||||||
"PROXY_UPSTREAM_CRAN",
|
|
||||||
"PROXY_UPSTREAM_JULIA",
|
|
||||||
"PROXY_UPSTREAM_OCI_DEFAULT",
|
|
||||||
"PROXY_UPSTREAM_DEBIAN",
|
|
||||||
"PROXY_UPSTREAM_RPM",
|
|
||||||
}
|
|
||||||
for _, variable := range variables {
|
|
||||||
if !strings.Contains(string(output), variable) {
|
|
||||||
t.Errorf("serve help omitted %s", variable)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestServeHelpProcess(*testing.T) {
|
|
||||||
if os.Getenv("PROXY_TEST_SERVE_HELP") != "1" {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
os.Args = []string{"proxy", "serve", "-help"}
|
|
||||||
main()
|
|
||||||
}
|
|
||||||
|
|
@ -4,22 +4,10 @@
|
||||||
# Server listen address
|
# Server listen address
|
||||||
listen: ":8080"
|
listen: ":8080"
|
||||||
|
|
||||||
# Public URL where package endpoints are reachable.
|
# Public URL where this proxy is accessible
|
||||||
# Used for rewriting package metadata URLs and shown in install guide snippets
|
# Used for rewriting package metadata URLs
|
||||||
# so users know what to point their package manager at.
|
|
||||||
base_url: "http://localhost:8080"
|
base_url: "http://localhost:8080"
|
||||||
|
|
||||||
# Timeout for individual upstream HTTP requests made by protocol handlers
|
|
||||||
# (metadata fetches, pass-through file requests). Uses Go duration syntax.
|
|
||||||
# Set to "0" to disable the timeout. Default: "30s".
|
|
||||||
# http_timeout: "30s"
|
|
||||||
|
|
||||||
# Public URL where the web UI is reached. Defaults to base_url when unset.
|
|
||||||
# Set this separately when the UI is served on a different hostname than the
|
|
||||||
# package endpoints — for example, the UI on a public domain behind auth while
|
|
||||||
# build machines hit a Docker network alias for the package endpoints.
|
|
||||||
# ui_base_url: "https://proxy.example.com/ui"
|
|
||||||
|
|
||||||
# Artifact storage configuration
|
# Artifact storage configuration
|
||||||
storage:
|
storage:
|
||||||
# Storage backend URL
|
# Storage backend URL
|
||||||
|
|
@ -27,20 +15,9 @@ storage:
|
||||||
# - file:///path/to/dir - Local filesystem (default)
|
# - file:///path/to/dir - Local filesystem (default)
|
||||||
# - s3://bucket-name - Amazon S3
|
# - s3://bucket-name - Amazon S3
|
||||||
# - s3://bucket?endpoint=http://localhost:9000 - S3-compatible (MinIO)
|
# - s3://bucket?endpoint=http://localhost:9000 - S3-compatible (MinIO)
|
||||||
# - gs://bucket-name - Google Cloud Storage
|
|
||||||
# - azblob://container-name - Azure Blob Storage
|
|
||||||
#
|
#
|
||||||
# For S3, configure credentials via environment variables:
|
# For S3, configure credentials via environment variables:
|
||||||
# AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_REGION
|
# AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_REGION
|
||||||
#
|
|
||||||
# For GCS, authentication uses Application Default Credentials. On GKE with
|
|
||||||
# Workload Identity, bind the Kubernetes service account to a Google service
|
|
||||||
# account that has roles/storage.objectAdmin on the bucket. No extra config
|
|
||||||
# is needed in this file. For local development, run:
|
|
||||||
# gcloud auth application-default login
|
|
||||||
# If direct_serve is enabled, the service account also needs
|
|
||||||
# roles/iam.serviceAccountTokenCreator on itself so the IAM Credentials
|
|
||||||
# signBlob API can sign URLs without a private key.
|
|
||||||
url: ""
|
url: ""
|
||||||
|
|
||||||
# Local filesystem path (used when url is empty)
|
# Local filesystem path (used when url is empty)
|
||||||
|
|
@ -52,23 +29,6 @@ storage:
|
||||||
# Empty or "0" means unlimited
|
# Empty or "0" means unlimited
|
||||||
max_size: ""
|
max_size: ""
|
||||||
|
|
||||||
# Redirect cached artifact downloads to presigned storage URLs (HTTP 302)
|
|
||||||
# instead of streaming through the proxy. Only effective for S3, GCS, and Azure.
|
|
||||||
# Leave disabled if clients reach the proxy through an authenticating gateway,
|
|
||||||
# since presigned URLs bypass it.
|
|
||||||
direct_serve: false
|
|
||||||
|
|
||||||
# How long presigned URLs remain valid (e.g. "5m", "1h"). Default: "15m".
|
|
||||||
direct_serve_ttl: "15m"
|
|
||||||
|
|
||||||
# Public base URL to substitute into presigned URLs. Set this when the
|
|
||||||
# proxy reaches storage at an internal address (127.0.0.1, a Docker
|
|
||||||
# service name) but clients must use a public hostname. Only scheme and
|
|
||||||
# host are used; the signed path and query are preserved. For S3/MinIO
|
|
||||||
# the reverse proxy at this address must forward requests with the
|
|
||||||
# internal Host header or the SigV4 signature will not validate.
|
|
||||||
# direct_serve_base_url: "https://minio.example.com"
|
|
||||||
|
|
||||||
# Database configuration
|
# Database configuration
|
||||||
database:
|
database:
|
||||||
# Database driver: "sqlite" (default) or "postgres"
|
# Database driver: "sqlite" (default) or "postgres"
|
||||||
|
|
@ -89,24 +49,10 @@ log:
|
||||||
# Log format: "text" or "json"
|
# Log format: "text" or "json"
|
||||||
format: "text"
|
format: "text"
|
||||||
|
|
||||||
# JSONL access log. Leave path empty to disable it.
|
# Upstream registry URLs and authentication
|
||||||
access_log:
|
|
||||||
path: ""
|
|
||||||
|
|
||||||
# Upstream URLs for built-in routes and authentication
|
|
||||||
upstream:
|
upstream:
|
||||||
# Hosts allowed to resolve to private, ULA, or CGNAT addresses
|
|
||||||
allow_private_hosts: []
|
|
||||||
|
|
||||||
# Permit upstream requests and redirects to loopback addresses
|
|
||||||
allow_loopback: false
|
|
||||||
|
|
||||||
# npm registry URL
|
# npm registry URL
|
||||||
npm: "https://registry.npmjs.org"
|
npm: "https://registry.npmjs.org"
|
||||||
# Always request full npm packuments so served metadata carries publish
|
|
||||||
# times ("time" map) even when cooldown is disabled. Needed by clients that
|
|
||||||
# gate on publish age, e.g. Yarn's npmMinimalAgeGate. Default: false.
|
|
||||||
# npm_full_metadata: true
|
|
||||||
|
|
||||||
# Cargo sparse index URL
|
# Cargo sparse index URL
|
||||||
cargo: "https://index.crates.io"
|
cargo: "https://index.crates.io"
|
||||||
|
|
@ -114,109 +60,14 @@ upstream:
|
||||||
# Cargo crate download URL
|
# Cargo crate download URL
|
||||||
cargo_download: "https://static.crates.io/crates"
|
cargo_download: "https://static.crates.io/crates"
|
||||||
|
|
||||||
# RubyGems registry URL
|
|
||||||
gem: "https://rubygems.org"
|
|
||||||
|
|
||||||
# Go module proxy URL
|
|
||||||
go: "https://proxy.golang.org"
|
|
||||||
|
|
||||||
# Hex repository URL
|
|
||||||
hex: "https://repo.hex.pm"
|
|
||||||
|
|
||||||
# Hex API URL used for package timestamps
|
|
||||||
hex_api: "https://hex.pm"
|
|
||||||
|
|
||||||
# pub registry URL
|
|
||||||
pub: "https://pub.dev"
|
|
||||||
|
|
||||||
# PyPI index and API URL
|
|
||||||
pypi: "https://pypi.org"
|
|
||||||
|
|
||||||
# PyPI package download URL
|
|
||||||
pypi_download: "https://files.pythonhosted.org"
|
|
||||||
|
|
||||||
# Maven repository URL (used by /maven endpoint)
|
|
||||||
maven: "https://repo1.maven.org/maven2"
|
|
||||||
|
|
||||||
# Gradle Plugin Portal Maven URL (fallback for plugin marker artifacts)
|
|
||||||
gradle_plugin_portal: "https://plugins.gradle.org/m2"
|
|
||||||
|
|
||||||
# NuGet API URL
|
|
||||||
nuget: "https://api.nuget.org"
|
|
||||||
|
|
||||||
# NuGet search API URL
|
|
||||||
nuget_search: "https://azuresearch-usnc.nuget.org"
|
|
||||||
|
|
||||||
# Packagist API URL
|
|
||||||
composer: "https://packagist.org"
|
|
||||||
|
|
||||||
# Packagist repository URL
|
|
||||||
composer_repository: "https://repo.packagist.org"
|
|
||||||
|
|
||||||
# Conan registry URL
|
|
||||||
conan: "https://center.conan.io"
|
|
||||||
|
|
||||||
# Conda channel base URL
|
|
||||||
conda: "https://conda.anaconda.org"
|
|
||||||
|
|
||||||
# CRAN mirror URL
|
|
||||||
cran: "https://cloud.r-project.org"
|
|
||||||
|
|
||||||
# Julia package server URL
|
|
||||||
julia: "https://pkg.julialang.org"
|
|
||||||
|
|
||||||
# Swift Package Registry URL (used by /swift endpoint)
|
|
||||||
swift: "https://tuist.dev/api/registry/swift"
|
|
||||||
|
|
||||||
# Default OCI registry URL for unprefixed /v2 requests
|
|
||||||
oci_default: "https://registry-1.docker.io"
|
|
||||||
|
|
||||||
# Debian/APT repository URL (used by /debian endpoint)
|
|
||||||
debian: "http://deb.debian.org/debian"
|
|
||||||
|
|
||||||
# RPM repository URL (used by /rpm endpoint)
|
|
||||||
rpm: "https://dl.fedoraproject.org/pub/fedora/linux"
|
|
||||||
|
|
||||||
# Homebrew JSON API URL (used by /homebrew endpoint)
|
|
||||||
homebrew_api: "https://formulae.brew.sh/api"
|
|
||||||
|
|
||||||
# Homebrew artifact registry URL (used for /v2/homebrew/core requests)
|
|
||||||
homebrew_artifact: "https://ghcr.io"
|
|
||||||
|
|
||||||
# Named HTTP Helm chart repositories (used by /helm/{name}/)
|
|
||||||
# helm:
|
|
||||||
# bitnami: "https://charts.bitnami.com/bitnami"
|
|
||||||
|
|
||||||
# Named OCI registries. Use the upstream/{name}/ repository prefix, e.g.
|
|
||||||
# oci://proxy.example.com/upstream/ghcr/owner/chart.
|
|
||||||
# oci:
|
|
||||||
# ghcr: "https://ghcr.io"
|
|
||||||
|
|
||||||
# Named Alpine APK repositories (used by /apk/{name}/).
|
|
||||||
# Defaults to {"alpine": "https://dl-cdn.alpinelinux.org/alpine"} when empty;
|
|
||||||
# configuring any entry replaces that default.
|
|
||||||
# apk:
|
|
||||||
# alpine: "https://dl-cdn.alpinelinux.org/alpine"
|
|
||||||
# private: "https://apk.example.com"
|
|
||||||
|
|
||||||
# Named generic HTTP upstreams (used by /generic/{name}/). The remaining
|
|
||||||
# request path and query are appended to the upstream URL. GitHub release
|
|
||||||
# assets ({owner}/{repo}/releases/download/{tag}/{asset}) are cached
|
|
||||||
# immutably; other paths use the metadata cache with stale-on-error.
|
|
||||||
# generic:
|
|
||||||
# github: "https://github.com"
|
|
||||||
# github-api: "https://api.github.com"
|
|
||||||
|
|
||||||
# Authentication for upstream registries
|
# Authentication for upstream registries
|
||||||
# Keys are absolute URL scopes. Scheme, host, effective port, and path
|
# Keys are URL prefixes matched against request URLs.
|
||||||
# segment boundaries must match; the longest matching scope wins.
|
|
||||||
# Values can reference environment variables using ${VAR_NAME} syntax.
|
# Values can reference environment variables using ${VAR_NAME} syntax.
|
||||||
#
|
#
|
||||||
# Supported auth types:
|
# Supported auth types:
|
||||||
# - bearer: Authorization header with Bearer token
|
# - bearer: Authorization header with Bearer token
|
||||||
# - basic: Authorization header with Basic auth (username:password)
|
# - basic: Authorization header with Basic auth (username:password)
|
||||||
# - header: Custom header name and value
|
# - header: Custom header name and value
|
||||||
# - ecr: AWS ECR auto-refreshing token via the AWS SDK credential chain
|
|
||||||
auth:
|
auth:
|
||||||
# Example: npm with bearer token
|
# Example: npm with bearer token
|
||||||
# "https://registry.npmjs.org":
|
# "https://registry.npmjs.org":
|
||||||
|
|
@ -239,87 +90,3 @@ upstream:
|
||||||
# type: header
|
# type: header
|
||||||
# header_name: "X-Auth-Token"
|
# header_name: "X-Auth-Token"
|
||||||
# header_value: "${MAVEN_TOKEN}"
|
# header_value: "${MAVEN_TOKEN}"
|
||||||
|
|
||||||
# Example: private AWS ECR registry (12h tokens auto-refreshed via
|
|
||||||
# ecr:GetAuthorizationToken; credentials come from the AWS SDK default
|
|
||||||
# chain, so IRSA / instance profiles / AWS_* env vars all work; the region
|
|
||||||
# is inferred from the private ECR hostname)
|
|
||||||
# "https://123456789012.dkr.ecr.eu-west-1.amazonaws.com":
|
|
||||||
# type: ecr
|
|
||||||
|
|
||||||
# Gradle HttpBuildCache configuration
|
|
||||||
gradle:
|
|
||||||
build_cache:
|
|
||||||
# Set to true to disable PUT uploads (read-only cache mode)
|
|
||||||
read_only: false
|
|
||||||
|
|
||||||
# Maximum accepted Gradle cache upload body size
|
|
||||||
# Required and must be > 0
|
|
||||||
max_upload_size: "100MB"
|
|
||||||
|
|
||||||
# Evict entries older than this age (set to "0" to disable age-based eviction)
|
|
||||||
max_age: "168h"
|
|
||||||
|
|
||||||
# Cap total Gradle cache size; oldest entries are deleted first
|
|
||||||
# ("0" disables size-based eviction)
|
|
||||||
# max_size: "20GB"
|
|
||||||
|
|
||||||
# How often eviction runs when max_age or max_size is set
|
|
||||||
sweep_interval: "10m"
|
|
||||||
|
|
||||||
# Health endpoint configuration.
|
|
||||||
health:
|
|
||||||
# Minimum time between storage backend probes.
|
|
||||||
# The /health endpoint runs a write/read/verify/delete round-trip
|
|
||||||
# against the configured storage backend and caches the result for
|
|
||||||
# this interval. Set to "0" to probe on every request.
|
|
||||||
# Default: "30s".
|
|
||||||
storage_probe_interval: "30s"
|
|
||||||
|
|
||||||
# Version cooldown configuration
|
|
||||||
# Hides package versions published too recently, giving the community time
|
|
||||||
# to spot malicious releases before they're pulled into projects.
|
|
||||||
# Supported durations: "7d" (days), "48h" (hours), "30m" (minutes), "0" (disabled)
|
|
||||||
cooldown:
|
|
||||||
# Global default cooldown for all ecosystems
|
|
||||||
# default: "3d"
|
|
||||||
|
|
||||||
# Per-ecosystem overrides
|
|
||||||
# ecosystems:
|
|
||||||
# npm: "7d"
|
|
||||||
# cargo: "0"
|
|
||||||
|
|
||||||
# Per-package overrides (keyed by PURL). Keys are normalized, so npm scopes
|
|
||||||
# may use either @scope or the canonical %40scope form.
|
|
||||||
# packages:
|
|
||||||
# "pkg:npm/lodash": "0"
|
|
||||||
# "pkg:npm/@babel/core": "14d"
|
|
||||||
|
|
||||||
# Pre-cache artifact scanning. When enabled, every artifact is staged into
|
|
||||||
# storage and scanned by the configured scanners before it is committed to
|
|
||||||
# the cache and served to clients. Scanners never receive artifact bytes
|
|
||||||
# directly — each notify call includes a short-lived signed URL that the
|
|
||||||
# scanner fetches itself, so the proxy stays agnostic to trivy/ClamAV/Wiz/
|
|
||||||
# any custom service. Scanners run concurrently; the first "block" verdict
|
|
||||||
# wins and cancels the rest.
|
|
||||||
# scanning:
|
|
||||||
# enabled: true
|
|
||||||
# fail_open: false
|
|
||||||
# timeout: 30s
|
|
||||||
#
|
|
||||||
# # Authenticates pull requests to the internal scan-fetch route.
|
|
||||||
# # Required whenever enabled is true. Supports ${VAR_NAME} expansion.
|
|
||||||
# signing_key: ${PROXY_SCANNING_SIGNING_KEY}
|
|
||||||
#
|
|
||||||
# # Address scanners use to reach this proxy to pull staged artifacts.
|
|
||||||
# # Defaults to base_url.
|
|
||||||
# # fetch_base_url: http://proxy.internal:8080
|
|
||||||
#
|
|
||||||
# scanners:
|
|
||||||
# - name: clamav
|
|
||||||
# url: http://clamav-adapter:8080/scan
|
|
||||||
# mode: block
|
|
||||||
# - name: trivy
|
|
||||||
# url: http://trivy-adapter:8081/scan
|
|
||||||
# mode: monitor
|
|
||||||
# ecosystems: [npm, pypi]
|
|
||||||
|
|
|
||||||
|
|
@ -1,6 +0,0 @@
|
||||||
.DS_Store
|
|
||||||
.git/
|
|
||||||
.github/
|
|
||||||
*.swp
|
|
||||||
*.tmp
|
|
||||||
*.tgz
|
|
||||||
|
|
@ -1,11 +0,0 @@
|
||||||
apiVersion: v2
|
|
||||||
name: proxy
|
|
||||||
description: A caching proxy for package registries
|
|
||||||
type: application
|
|
||||||
version: 0.0.0
|
|
||||||
appVersion: "0.0.0"
|
|
||||||
home: https://github.com/git-pkgs/proxy
|
|
||||||
sources:
|
|
||||||
- https://github.com/git-pkgs/proxy
|
|
||||||
annotations:
|
|
||||||
artifacthub.io/license: MIT
|
|
||||||
|
|
@ -1,15 +0,0 @@
|
||||||
git-pkgs proxy has been installed.
|
|
||||||
|
|
||||||
The default base URL is intended for local port forwarding. Before exposing the
|
|
||||||
proxy, set config.data.base_url to the URL used by package-manager clients.
|
|
||||||
|
|
||||||
To access the proxy locally:
|
|
||||||
|
|
||||||
kubectl -n {{ .Release.Namespace }} port-forward service/{{ include "proxy.fullname" . }} {{ .Values.service.port }}:{{ .Values.service.port }}
|
|
||||||
|
|
||||||
Then visit http://localhost:{{ .Values.service.port }}/.
|
|
||||||
|
|
||||||
{{- if not .Values.persistence.enabled }}
|
|
||||||
WARNING: persistence is disabled. Cached artifacts and the default SQLite
|
|
||||||
database will be lost when the pod is replaced.
|
|
||||||
{{- end }}
|
|
||||||
|
|
@ -1,46 +0,0 @@
|
||||||
{{/* Expand the chart name. */}}
|
|
||||||
{{- define "proxy.name" -}}
|
|
||||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Create a release-specific, DNS-safe resource name. */}}
|
|
||||||
{{- define "proxy.fullname" -}}
|
|
||||||
{{- if .Values.fullnameOverride }}
|
|
||||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- else }}
|
|
||||||
{{- $name := include "proxy.name" . }}
|
|
||||||
{{- if contains $name .Release.Name }}
|
|
||||||
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- else }}
|
|
||||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- define "proxy.labels" -}}
|
|
||||||
helm.sh/chart: {{ printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{ include "proxy.selectorLabels" . }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- define "proxy.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ include "proxy.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- define "proxy.configMapName" -}}
|
|
||||||
{{- default (include "proxy.fullname" .) .Values.config.existingConfigMap }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- define "proxy.claimName" -}}
|
|
||||||
{{- default (include "proxy.fullname" .) .Values.persistence.existingClaim }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- define "proxy.image" -}}
|
|
||||||
{{- if .Values.image.digest -}}
|
|
||||||
{{- printf "%s@%s" .Values.image.repository .Values.image.digest -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- printf "%s:%s" .Values.image.repository (default .Chart.AppVersion .Values.image.tag) -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
@ -1,12 +0,0 @@
|
||||||
{{- if not .Values.config.existingConfigMap }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: {{ include "proxy.fullname" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
labels:
|
|
||||||
{{- include "proxy.labels" . | nindent 4 }}
|
|
||||||
data:
|
|
||||||
{{ required "config.existingConfigMapKey is required" .Values.config.existingConfigMapKey }}: |
|
|
||||||
{{- toYaml .Values.config.data | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
@ -1,102 +0,0 @@
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "proxy.fullname" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
labels:
|
|
||||||
{{- include "proxy.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
strategy:
|
|
||||||
{{- toYaml .Values.deploymentStrategy | nindent 4 }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "proxy.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
{{- include "proxy.selectorLabels" . | nindent 8 }}
|
|
||||||
{{- with .Values.podLabels }}
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
annotations:
|
|
||||||
checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }}
|
|
||||||
{{- with .Values.podAnnotations }}
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
automountServiceAccountToken: false
|
|
||||||
terminationGracePeriodSeconds: {{ .Values.terminationGracePeriodSeconds }}
|
|
||||||
securityContext:
|
|
||||||
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
|
||||||
{{- with .Values.imagePullSecrets }}
|
|
||||||
imagePullSecrets:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
containers:
|
|
||||||
- name: {{ .Chart.Name }}
|
|
||||||
image: {{ include "proxy.image" . | quote }}
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
securityContext:
|
|
||||||
{{- toYaml .Values.containerSecurityContext | nindent 12 }}
|
|
||||||
args:
|
|
||||||
- serve
|
|
||||||
- -config
|
|
||||||
- /etc/proxy/{{ .Values.config.existingConfigMapKey }}
|
|
||||||
{{- with .Values.extraEnv }}
|
|
||||||
env:
|
|
||||||
{{- toYaml . | nindent 12 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.extraEnvFrom }}
|
|
||||||
envFrom:
|
|
||||||
{{- toYaml . | nindent 12 }}
|
|
||||||
{{- end }}
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: {{ .Values.service.containerPort }}
|
|
||||||
protocol: TCP
|
|
||||||
startupProbe:
|
|
||||||
{{- toYaml .Values.startupProbe | nindent 12 }}
|
|
||||||
readinessProbe:
|
|
||||||
{{- toYaml .Values.readinessProbe | nindent 12 }}
|
|
||||||
livenessProbe:
|
|
||||||
{{- toYaml .Values.livenessProbe | nindent 12 }}
|
|
||||||
resources:
|
|
||||||
{{- toYaml .Values.resources | nindent 12 }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: config
|
|
||||||
mountPath: /etc/proxy/{{ .Values.config.existingConfigMapKey }}
|
|
||||||
subPath: {{ .Values.config.existingConfigMapKey }}
|
|
||||||
readOnly: true
|
|
||||||
- name: data
|
|
||||||
mountPath: {{ .Values.persistence.mountPath }}
|
|
||||||
volumes:
|
|
||||||
- name: config
|
|
||||||
configMap:
|
|
||||||
name: {{ include "proxy.configMapName" . }}
|
|
||||||
items:
|
|
||||||
- key: {{ required "config.existingConfigMapKey is required" .Values.config.existingConfigMapKey }}
|
|
||||||
path: {{ .Values.config.existingConfigMapKey }}
|
|
||||||
- name: data
|
|
||||||
{{- if .Values.persistence.enabled }}
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: {{ include "proxy.claimName" . }}
|
|
||||||
{{- else }}
|
|
||||||
emptyDir: {}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.nodeSelector }}
|
|
||||||
nodeSelector:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.affinity }}
|
|
||||||
affinity:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.tolerations }}
|
|
||||||
tolerations:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.topologySpreadConstraints }}
|
|
||||||
topologySpreadConstraints:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
@ -1,39 +0,0 @@
|
||||||
{{- if .Values.ingress.enabled }}
|
|
||||||
{{- if not .Values.ingress.hosts }}
|
|
||||||
{{- fail "ingress.hosts must be set when ingress.enabled=true" }}
|
|
||||||
{{- end }}
|
|
||||||
apiVersion: networking.k8s.io/v1
|
|
||||||
kind: Ingress
|
|
||||||
metadata:
|
|
||||||
name: {{ include "proxy.fullname" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
labels:
|
|
||||||
{{- include "proxy.labels" . | nindent 4 }}
|
|
||||||
{{- with .Values.ingress.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
{{- with .Values.ingress.className }}
|
|
||||||
ingressClassName: {{ . | quote }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.ingress.tls }}
|
|
||||||
tls:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
rules:
|
|
||||||
{{- range .Values.ingress.hosts }}
|
|
||||||
- host: {{ .host | quote }}
|
|
||||||
http:
|
|
||||||
paths:
|
|
||||||
{{- range .paths }}
|
|
||||||
- path: {{ .path | quote }}
|
|
||||||
pathType: {{ .pathType }}
|
|
||||||
backend:
|
|
||||||
service:
|
|
||||||
name: {{ include "proxy.fullname" $ }}
|
|
||||||
port:
|
|
||||||
number: {{ $.Values.service.port }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
@ -1,22 +0,0 @@
|
||||||
{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: {{ include "proxy.fullname" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
labels:
|
|
||||||
{{- include "proxy.labels" . | nindent 4 }}
|
|
||||||
{{- with .Values.persistence.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
{{- toYaml .Values.persistence.accessModes | nindent 4 }}
|
|
||||||
{{- with .Values.persistence.storageClass }}
|
|
||||||
storageClassName: {{ . | quote }}
|
|
||||||
{{- end }}
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: {{ .Values.persistence.size }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
@ -1,16 +0,0 @@
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "proxy.fullname" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
labels:
|
|
||||||
{{- include "proxy.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.service.type }}
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: {{ .Values.service.port }}
|
|
||||||
targetPort: http
|
|
||||||
protocol: TCP
|
|
||||||
selector:
|
|
||||||
{{- include "proxy.selectorLabels" . | nindent 4 }}
|
|
||||||
|
|
@ -1,138 +0,0 @@
|
||||||
# More than one replica requires config.data.database on Postgres,
|
|
||||||
# config.data.storage on object storage, deploymentStrategy: RollingUpdate,
|
|
||||||
# and a PVC access mode other than ReadWriteOnce (or persistence disabled).
|
|
||||||
replicaCount: 1
|
|
||||||
|
|
||||||
nameOverride: ""
|
|
||||||
fullnameOverride: ""
|
|
||||||
|
|
||||||
image:
|
|
||||||
repository: ghcr.io/git-pkgs/proxy
|
|
||||||
# An empty tag uses the chart appVersion.
|
|
||||||
tag: ""
|
|
||||||
# When set, digest takes precedence over tag.
|
|
||||||
digest: ""
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
|
|
||||||
imagePullSecrets: []
|
|
||||||
|
|
||||||
service:
|
|
||||||
type: ClusterIP
|
|
||||||
port: 8080
|
|
||||||
# Keep this aligned with config.data.listen (or the listen address in an
|
|
||||||
# existing ConfigMap).
|
|
||||||
containerPort: 8080
|
|
||||||
|
|
||||||
# The generated configuration is ignored when existingConfigMap is set.
|
|
||||||
config:
|
|
||||||
existingConfigMap: ""
|
|
||||||
existingConfigMapKey: config.yaml
|
|
||||||
data:
|
|
||||||
listen: ":8080"
|
|
||||||
# Set this to the URL package-manager clients use to reach the proxy.
|
|
||||||
base_url: "http://localhost:8080"
|
|
||||||
storage:
|
|
||||||
url: "file:///data/artifacts"
|
|
||||||
database:
|
|
||||||
driver: sqlite
|
|
||||||
path: "/data/proxy.db"
|
|
||||||
log:
|
|
||||||
level: info
|
|
||||||
format: json
|
|
||||||
|
|
||||||
# Environment variables override values from the configuration file. This is
|
|
||||||
# also the recommended way to supply secret values such as database passwords
|
|
||||||
# and object-storage credentials.
|
|
||||||
extraEnv: []
|
|
||||||
# - name: PROXY_DATABASE_URL
|
|
||||||
# valueFrom:
|
|
||||||
# secretKeyRef:
|
|
||||||
# name: proxy-database
|
|
||||||
# key: url
|
|
||||||
|
|
||||||
extraEnvFrom: []
|
|
||||||
# - secretRef:
|
|
||||||
# name: proxy-object-storage
|
|
||||||
|
|
||||||
persistence:
|
|
||||||
enabled: true
|
|
||||||
# Keep this aligned with config.data.storage.url and config.data.database.path
|
|
||||||
# (or the equivalent paths in an existing ConfigMap).
|
|
||||||
mountPath: /data
|
|
||||||
existingClaim: ""
|
|
||||||
annotations: {}
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
size: 10Gi
|
|
||||||
storageClass: ""
|
|
||||||
|
|
||||||
deploymentStrategy:
|
|
||||||
type: Recreate
|
|
||||||
|
|
||||||
ingress:
|
|
||||||
enabled: false
|
|
||||||
className: ""
|
|
||||||
annotations: {}
|
|
||||||
hosts: []
|
|
||||||
# - host: proxy.example.com
|
|
||||||
# paths:
|
|
||||||
# - path: /
|
|
||||||
# pathType: Prefix
|
|
||||||
tls: []
|
|
||||||
# - secretName: proxy-tls
|
|
||||||
# hosts:
|
|
||||||
# - proxy.example.com
|
|
||||||
|
|
||||||
podAnnotations: {}
|
|
||||||
podLabels: {}
|
|
||||||
|
|
||||||
podSecurityContext:
|
|
||||||
runAsNonRoot: true
|
|
||||||
runAsUser: 1000
|
|
||||||
runAsGroup: 1000
|
|
||||||
fsGroup: 1000
|
|
||||||
seccompProfile:
|
|
||||||
type: RuntimeDefault
|
|
||||||
|
|
||||||
containerSecurityContext:
|
|
||||||
allowPrivilegeEscalation: false
|
|
||||||
readOnlyRootFilesystem: true
|
|
||||||
capabilities:
|
|
||||||
drop:
|
|
||||||
- ALL
|
|
||||||
|
|
||||||
resources: {}
|
|
||||||
# requests:
|
|
||||||
# cpu: 100m
|
|
||||||
# memory: 128Mi
|
|
||||||
# limits:
|
|
||||||
# memory: 512Mi
|
|
||||||
|
|
||||||
startupProbe:
|
|
||||||
tcpSocket:
|
|
||||||
port: http
|
|
||||||
failureThreshold: 30
|
|
||||||
periodSeconds: 2
|
|
||||||
|
|
||||||
# /health checks both the database and storage backends and can take up to ten
|
|
||||||
# seconds. It is intentionally a readiness check rather than a liveness check.
|
|
||||||
readinessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /health
|
|
||||||
port: http
|
|
||||||
timeoutSeconds: 11
|
|
||||||
periodSeconds: 15
|
|
||||||
failureThreshold: 2
|
|
||||||
|
|
||||||
livenessProbe:
|
|
||||||
tcpSocket:
|
|
||||||
port: http
|
|
||||||
periodSeconds: 20
|
|
||||||
failureThreshold: 3
|
|
||||||
|
|
||||||
terminationGracePeriodSeconds: 30
|
|
||||||
|
|
||||||
nodeSelector: {}
|
|
||||||
tolerations: []
|
|
||||||
affinity: {}
|
|
||||||
topologySpreadConstraints: []
|
|
||||||
|
|
@ -7,24 +7,29 @@ This document describes the internal architecture of the git-pkgs proxy.
|
||||||
The proxy is a caching HTTP server that sits between package manager clients and upstream registries. It intercepts requests, checks a local cache, and either serves cached content or fetches from upstream.
|
The proxy is a caching HTTP server that sits between package manager clients and upstream registries. It intercepts requests, checks a local cache, and either serves cached content or fetches from upstream.
|
||||||
|
|
||||||
```
|
```
|
||||||
┌──────────────────────────────────────────────────────────────────┐
|
┌─────────────────────────────────────────────────────────────────┐
|
||||||
│ HTTP Server │
|
│ HTTP Server │
|
||||||
│ ┌──────────────────────────────────────────────────────────┐ │
|
│ ┌─────────────────────────────────────────────────────────┐ │
|
||||||
│ │ Router (Chi) │ │
|
│ │ Router (ServeMux) │ │
|
||||||
│ │ /npm/* -> NPMHandler /health -> healthHandler │ │
|
│ │ /npm/* -> NPMHandler │ │
|
||||||
│ │ /cargo/* -> CargoHandler /stats -> statsHandler │ │
|
│ │ /cargo/* -> CargoHandler │ │
|
||||||
│ │ /gem/* -> GemHandler /metrics -> prometheus │ │
|
│ │ /health -> healthHandler │ │
|
||||||
│ │ ...17 ecosystems /api/* -> APIHandler │ │
|
│ │ /stats -> statsHandler │ │
|
||||||
│ │ /ui/* -> Web UI │ │
|
│ └─────────────────────────────────────────────────────────┘ │
|
||||||
│ └──────────────────────────────────────────────────────────┘ │
|
│ │ │
|
||||||
│ │ │ │ │
|
│ ▼ │
|
||||||
│ ▼ ▼ ▼ │
|
│ ┌─────────────────────────────────────────────────────────┐ │
|
||||||
|
│ │ Proxy │ │
|
||||||
|
│ │ - GetOrFetchArtifact() │ │
|
||||||
|
│ │ - Coordinates DB, Storage, Fetcher │ │
|
||||||
|
│ └─────────────────────────────────────────────────────────┘ │
|
||||||
|
│ │ │ │ │
|
||||||
|
│ ▼ ▼ ▼ │
|
||||||
│ ┌───────────┐ ┌─────────────┐ ┌─────────────┐ │
|
│ ┌───────────┐ ┌─────────────┐ ┌─────────────┐ │
|
||||||
│ │ Database │ │ Storage │ │ Upstream │ │
|
│ │ Database │ │ Storage │ │ Upstream │ │
|
||||||
│ │ SQLite or │ │ Filesystem │ │ Registries │ │
|
│ │ (SQLite) │ │ (Filesystem)│ │ (Fetcher) │ │
|
||||||
│ │ Postgres │ │ or S3 │ │ (Fetcher) │ │
|
|
||||||
│ └───────────┘ └─────────────┘ └─────────────┘ │
|
│ └───────────┘ └─────────────┘ └─────────────┘ │
|
||||||
└──────────────────────────────────────────────────────────────────┘
|
└─────────────────────────────────────────────────────────────────┘
|
||||||
```
|
```
|
||||||
|
|
||||||
## Request Flow
|
## Request Flow
|
||||||
|
|
@ -86,102 +91,29 @@ Metadata is not cached - always fetched fresh. This ensures clients see new vers
|
||||||
|
|
||||||
### `internal/database`
|
### `internal/database`
|
||||||
|
|
||||||
SQLite or PostgreSQL database for cache metadata. SQLite uses `modernc.org/sqlite` (pure Go, no CGO). PostgreSQL uses `lib/pq`.
|
SQLite database for cache metadata. Uses `modernc.org/sqlite` (pure Go, no CGO).
|
||||||
|
|
||||||
The schema is compatible with [git-pkgs](https://github.com/git-pkgs) databases. The proxy adds the `artifacts` and `vulnerabilities` tables on top of the shared `packages` and `versions` tables, so both tools can point at the same database.
|
|
||||||
|
|
||||||
**Tables:**
|
**Tables:**
|
||||||
|
|
||||||
```sql
|
```sql
|
||||||
packages (
|
packages (
|
||||||
id INTEGER PRIMARY KEY, -- SERIAL on Postgres
|
id, purl, ecosystem, name, namespace, latest_version,
|
||||||
purl TEXT NOT NULL, -- unique, e.g. pkg:npm/lodash
|
license, description, homepage, repository_url, upstream_url,
|
||||||
ecosystem TEXT NOT NULL,
|
metadata_fetched_at, created_at, updated_at
|
||||||
name TEXT NOT NULL,
|
|
||||||
latest_version TEXT,
|
|
||||||
license TEXT,
|
|
||||||
description TEXT,
|
|
||||||
homepage TEXT,
|
|
||||||
repository_url TEXT,
|
|
||||||
registry_url TEXT,
|
|
||||||
supplier_name TEXT,
|
|
||||||
supplier_type TEXT,
|
|
||||||
source TEXT,
|
|
||||||
enriched_at DATETIME,
|
|
||||||
vulns_synced_at DATETIME,
|
|
||||||
created_at DATETIME,
|
|
||||||
updated_at DATETIME
|
|
||||||
)
|
)
|
||||||
-- indexes: purl (unique), (ecosystem, name)
|
|
||||||
|
|
||||||
versions (
|
versions (
|
||||||
id INTEGER PRIMARY KEY,
|
id, purl, package_id, version, license, integrity,
|
||||||
purl TEXT NOT NULL, -- unique, e.g. pkg:npm/lodash@4.17.21
|
published_at, yanked, metadata_fetched_at, created_at, updated_at
|
||||||
package_purl TEXT NOT NULL, -- FK to packages.purl
|
|
||||||
license TEXT,
|
|
||||||
published_at DATETIME,
|
|
||||||
integrity TEXT, -- subresource integrity hash
|
|
||||||
yanked INTEGER DEFAULT 0, -- BOOLEAN on Postgres
|
|
||||||
source TEXT,
|
|
||||||
enriched_at DATETIME,
|
|
||||||
created_at DATETIME,
|
|
||||||
updated_at DATETIME
|
|
||||||
)
|
)
|
||||||
-- indexes: purl (unique), package_purl
|
|
||||||
|
|
||||||
artifacts (
|
artifacts (
|
||||||
id INTEGER PRIMARY KEY,
|
id, version_id, filename, upstream_url, storage_path,
|
||||||
version_purl TEXT NOT NULL,
|
content_hash, size, content_type, fetched_at,
|
||||||
filename TEXT NOT NULL,
|
hit_count, last_accessed_at, created_at, updated_at
|
||||||
upstream_url TEXT NOT NULL,
|
|
||||||
storage_path TEXT, -- null until cached
|
|
||||||
content_hash TEXT, -- SHA-256
|
|
||||||
size INTEGER, -- BIGINT on Postgres
|
|
||||||
content_type TEXT,
|
|
||||||
fetched_at DATETIME,
|
|
||||||
hit_count INTEGER DEFAULT 0, -- BIGINT on Postgres
|
|
||||||
last_accessed_at DATETIME,
|
|
||||||
created_at DATETIME,
|
|
||||||
updated_at DATETIME
|
|
||||||
)
|
)
|
||||||
-- indexes: (version_purl, filename) unique, storage_path, last_accessed_at
|
|
||||||
|
|
||||||
vulnerabilities (
|
|
||||||
id INTEGER PRIMARY KEY,
|
|
||||||
vuln_id TEXT NOT NULL, -- e.g. CVE-2021-1234
|
|
||||||
ecosystem TEXT NOT NULL,
|
|
||||||
package_name TEXT NOT NULL,
|
|
||||||
severity TEXT,
|
|
||||||
summary TEXT,
|
|
||||||
fixed_version TEXT,
|
|
||||||
cvss_score REAL,
|
|
||||||
"references" TEXT, -- JSON array
|
|
||||||
fetched_at DATETIME,
|
|
||||||
created_at DATETIME,
|
|
||||||
updated_at DATETIME
|
|
||||||
)
|
|
||||||
-- indexes: (vuln_id, ecosystem, package_name) unique, (ecosystem, package_name)
|
|
||||||
|
|
||||||
metadata_cache (
|
|
||||||
id INTEGER PRIMARY KEY,
|
|
||||||
ecosystem TEXT NOT NULL,
|
|
||||||
name TEXT NOT NULL,
|
|
||||||
storage_path TEXT NOT NULL,
|
|
||||||
etag TEXT,
|
|
||||||
content_type TEXT,
|
|
||||||
content_encoding TEXT, -- replayed on serve so signed bytes stay verbatim
|
|
||||||
size INTEGER, -- BIGINT on Postgres
|
|
||||||
fetched_at DATETIME,
|
|
||||||
created_at DATETIME,
|
|
||||||
updated_at DATETIME
|
|
||||||
)
|
|
||||||
-- indexes: (ecosystem, name) unique
|
|
||||||
```
|
```
|
||||||
|
|
||||||
On PostgreSQL, `INTEGER PRIMARY KEY` becomes `SERIAL`, `DATETIME` becomes `TIMESTAMP`, `INTEGER DEFAULT 0` booleans become `BOOLEAN DEFAULT FALSE`, and size/count columns use `BIGINT`.
|
|
||||||
|
|
||||||
The `MigrateSchema()` function handles backward compatibility with older git-pkgs databases by running named migrations that add missing columns and tables. See [migrations.md](migrations.md) for how to add new schema changes.
|
|
||||||
|
|
||||||
**Key operations:**
|
**Key operations:**
|
||||||
- `GetPackageByPURL()` - Look up package by PURL
|
- `GetPackageByPURL()` - Look up package by PURL
|
||||||
- `GetVersionByPURL()` - Look up version by PURL
|
- `GetVersionByPURL()` - Look up version by PURL
|
||||||
|
|
@ -189,7 +121,6 @@ The `MigrateSchema()` function handles backward compatibility with older git-pkg
|
||||||
- `UpsertPackage/Version/Artifact()` - Insert or update records
|
- `UpsertPackage/Version/Artifact()` - Insert or update records
|
||||||
- `RecordArtifactHit()` - Increment hit counter, update access time
|
- `RecordArtifactHit()` - Increment hit counter, update access time
|
||||||
- `GetLeastRecentlyUsedArtifacts()` - For cache eviction
|
- `GetLeastRecentlyUsedArtifacts()` - For cache eviction
|
||||||
- `SearchPackages()` - Full-text search across cached packages
|
|
||||||
|
|
||||||
### `internal/storage`
|
### `internal/storage`
|
||||||
|
|
||||||
|
|
@ -241,8 +172,6 @@ Fetches artifacts from upstream registries.
|
||||||
- Exponential backoff retry on 429 (rate limit) and 5xx errors
|
- Exponential backoff retry on 429 (rate limit) and 5xx errors
|
||||||
- Returns streaming reader (doesn't load into memory)
|
- Returns streaming reader (doesn't load into memory)
|
||||||
- Configurable user-agent
|
- Configurable user-agent
|
||||||
- Shares an authentication-aware transport with metadata requests so URL-scoped credentials apply consistently
|
|
||||||
- Discovers and caches scoped OCI Bearer tokens from registry challenges
|
|
||||||
|
|
||||||
**Resolver:**
|
**Resolver:**
|
||||||
- Determines download URL for a package/version
|
- Determines download URL for a package/version
|
||||||
|
|
@ -270,39 +199,14 @@ HTTP protocol handlers for each registry type.
|
||||||
- `handleIndex()` - Proxy sparse index
|
- `handleIndex()` - Proxy sparse index
|
||||||
- `handleDownload()` - Serve cached crate
|
- `handleDownload()` - Serve cached crate
|
||||||
|
|
||||||
**SwiftHandler:**
|
|
||||||
- Proxies the Swift Package Registry v1 read endpoints
|
|
||||||
- Rewrites release URLs and caches source archives
|
|
||||||
|
|
||||||
### `internal/server`
|
### `internal/server`
|
||||||
|
|
||||||
HTTP server setup, web UI, and API handlers.
|
HTTP server setup.
|
||||||
|
|
||||||
- Creates and wires together all components
|
- Creates and wires together all components
|
||||||
- Mounts protocol handlers at ecosystem-specific paths
|
- Mounts handlers at appropriate paths
|
||||||
- Middleware: request ID, real IP, logging, panic recovery, active request tracking
|
- Adds logging middleware
|
||||||
- Web UI under `/ui`: dashboard, package browser, source browser, version comparison
|
- Health and stats endpoints
|
||||||
- Templates are embedded in the binary via `//go:embed`
|
|
||||||
- Enrichment API for package metadata, vulnerability scanning, and outdated detection
|
|
||||||
- Health, stats, and Prometheus metrics endpoints. `/health` runs an active write → size-check → read → verify → delete probe against the storage backend and returns a structured JSON response (`HealthResponse`) with `"ok"` / `"error"` status per subsystem. Probe results are cached (default 30 s, configurable via `health.storage_probe_interval`) to avoid overwhelming remote backends. The response also carries a `circuit_breakers` map reporting each upstream's artifact-fetch breaker as `"open"` or `"closed"`, keyed by the host fetched from (or an opaque placeholder where the fetch URL has no host to read); the same state is published as the `proxy_circuit_breaker_state` gauge on each `/metrics` scrape. An open breaker leaves the overall status `"ok"` — it describes an upstream, not this proxy.
|
|
||||||
|
|
||||||
### `internal/metrics`
|
|
||||||
|
|
||||||
Prometheus metrics for cache performance, upstream latency, storage operations, and active requests. See the Monitoring section of the README for the full metric list.
|
|
||||||
|
|
||||||
### Cooldown
|
|
||||||
|
|
||||||
Version age filtering for supply chain attack mitigation, provided by [github.com/git-pkgs/cooldown](https://github.com/git-pkgs/cooldown). Configurable at global, ecosystem, and per-package levels. Supported by npm, PyPI, pub.dev, and Composer handlers.
|
|
||||||
|
|
||||||
### `internal/enrichment`
|
|
||||||
|
|
||||||
Package metadata enrichment. Fetches license, description, homepage, repository URL, and vulnerability data from upstream registries. Powers the `/api/` endpoints and the web UI's package detail pages.
|
|
||||||
|
|
||||||
### `internal/mirror`
|
|
||||||
|
|
||||||
Selective package mirroring for pre-populating the proxy cache. Supports multiple input sources: individual PURLs (versioned or unversioned), CycloneDX/SPDX SBOM files, and full registry enumeration. Uses a bounded worker pool backed by `errgroup` to download artifacts in parallel, reusing `handler.Proxy.GetOrFetchArtifact()` for the actual fetch-and-cache work.
|
|
||||||
|
|
||||||
The package also provides a `MetadataCache` for storing raw upstream metadata blobs so the proxy can serve metadata responses offline. The `JobStore` manages async mirror jobs exposed via the `/api/mirror` endpoints.
|
|
||||||
|
|
||||||
### `internal/config`
|
### `internal/config`
|
||||||
|
|
||||||
|
|
@ -353,12 +257,10 @@ Eviction can be implemented as:
|
||||||
- Ensures clients fetch artifacts through proxy
|
- Ensures clients fetch artifacts through proxy
|
||||||
- Alternative: Let clients fetch directly, miss cache opportunity
|
- Alternative: Let clients fetch directly, miss cache opportunity
|
||||||
|
|
||||||
**Why not cache metadata (by default)?**
|
**Why not cache metadata?**
|
||||||
- Simplicity - no invalidation logic needed
|
- Simplicity - no invalidation logic needed
|
||||||
- Fresh data - new versions visible immediately
|
- Fresh data - new versions visible immediately
|
||||||
- Metadata is small, upstream fetch is fast
|
- Metadata is small, upstream fetch is fast
|
||||||
- Set `cache_metadata: true` or use the mirror command to enable metadata caching for offline use via the `metadata_cache` table
|
|
||||||
- OCI manifests and tag lists are exceptions: they are cached automatically so previously fetched images remain pullable and tag resolution works when the registry or token service is unavailable
|
|
||||||
|
|
||||||
**Why stream artifacts?**
|
**Why stream artifacts?**
|
||||||
- Memory efficient - don't load large files into RAM
|
- Memory efficient - don't load large files into RAM
|
||||||
|
|
|
||||||
|
|
@ -17,8 +17,7 @@ See `config.example.yaml` in the repository root for a complete example.
|
||||||
| Config | Environment | Flag | Default | Description |
|
| Config | Environment | Flag | Default | Description |
|
||||||
|--------|-------------|------|---------|-------------|
|
|--------|-------------|------|---------|-------------|
|
||||||
| `listen` | `PROXY_LISTEN` | `-listen` | `:8080` | Address to listen on |
|
| `listen` | `PROXY_LISTEN` | `-listen` | `:8080` | Address to listen on |
|
||||||
| `base_url` | `PROXY_BASE_URL` | `-base-url` | `http://localhost:8080` | Public URL package managers use to reach this proxy |
|
| `base_url` | `PROXY_BASE_URL` | `-base-url` | `http://localhost:8080` | Public URL for the proxy |
|
||||||
| `ui_base_url` | `PROXY_UI_URL` | - | (defaults to `base_url`) | Public URL where the web UI is reached. Set separately when the UI lives behind a different hostname than package endpoints (e.g. public domain vs Docker network alias). Used for canonical/og:url tags and the install guide banner. The proxy still serves package endpoints on the same listener, so any reverse proxy fronting the UI publicly should restrict the public route to `PathPrefix(/ui)` to avoid exposing package endpoints. |
|
|
||||||
|
|
||||||
## Storage
|
## Storage
|
||||||
|
|
||||||
|
|
@ -108,168 +107,20 @@ log:
|
||||||
| `log.level` | `PROXY_LOG_LEVEL` | `-log-level` | `debug`, `info`, `warn`, `error` |
|
| `log.level` | `PROXY_LOG_LEVEL` | `-log-level` | `debug`, `info`, `warn`, `error` |
|
||||||
| `log.format` | `PROXY_LOG_FORMAT` | `-log-format` | `text`, `json` |
|
| `log.format` | `PROXY_LOG_FORMAT` | `-log-format` | `text`, `json` |
|
||||||
|
|
||||||
## Access Log
|
|
||||||
|
|
||||||
The optional access log records client requests and each HTTP exchange with an upstream registry. It is always written as JSONL, with one JSON object per line. Records for the same client request share a `request_id`.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
access_log:
|
|
||||||
path: "/var/log/proxy/access.jsonl"
|
|
||||||
```
|
|
||||||
|
|
||||||
| Config | Environment | Flag | Description |
|
|
||||||
|--------|-------------|------|-------------|
|
|
||||||
| `access_log.path` | `PROXY_ACCESS_LOG_PATH` | `-access-log` | File to append JSONL records to; empty disables the log |
|
|
||||||
|
|
||||||
The parent directory must exist and be writable when the proxy starts. A newly created log file is readable and writable only by the proxy process owner.
|
|
||||||
|
|
||||||
A request that receives a rate limit response from an upstream can produce records like these:
|
|
||||||
|
|
||||||
```json
|
|
||||||
{"time":"2026-08-16T12:00:00Z","event":"upstream","request_id":"host/example-000001","method":"GET","url":"https://registry.example/packages/example","status_code":429,"duration_ms":42}
|
|
||||||
{"time":"2026-08-16T12:00:00Z","event":"request","request_id":"host/example-000001","method":"GET","path":"/npm/example","status_code":502,"duration_ms":43,"remote_addr":"192.0.2.10:41234"}
|
|
||||||
```
|
|
||||||
|
|
||||||
Upstream retries and OCI authentication calls are separate `upstream` records, so the log preserves every status returned over the wire. Network failures have an `error` field and no `status_code`. URL credentials, query strings, and fragments are omitted from both upstream URLs and client paths.
|
|
||||||
|
|
||||||
## Upstream Registries
|
## Upstream Registries
|
||||||
|
|
||||||
Each upstream used by a built-in package route can be set in YAML or JSON under `upstream`, or with its matching environment variable. Existing installations keep the same public upstreams by default. Trailing slashes are ignored.
|
Override default upstream registry URLs:
|
||||||
|
|
||||||
| Config | Environment | Default |
|
|
||||||
|--------|-------------|---------|
|
|
||||||
| `upstream.allow_private_hosts` | `PROXY_UPSTREAM_ALLOW_PRIVATE_HOSTS` | `[]` |
|
|
||||||
| `upstream.allow_loopback` | `PROXY_UPSTREAM_ALLOW_LOOPBACK` | `false` |
|
|
||||||
| `upstream.npm` | `PROXY_UPSTREAM_NPM` | `https://registry.npmjs.org` |
|
|
||||||
| `upstream.npm_full_metadata` | `PROXY_UPSTREAM_NPM_FULL_METADATA` | `false` |
|
|
||||||
| `upstream.cargo` | `PROXY_UPSTREAM_CARGO` | `https://index.crates.io` |
|
|
||||||
| `upstream.cargo_download` | `PROXY_UPSTREAM_CARGO_DOWNLOAD` | `https://static.crates.io/crates` |
|
|
||||||
| `upstream.gem` | `PROXY_UPSTREAM_GEM` | `https://rubygems.org` |
|
|
||||||
| `upstream.go` | `PROXY_UPSTREAM_GO` | `https://proxy.golang.org` |
|
|
||||||
| `upstream.hex` | `PROXY_UPSTREAM_HEX` | `https://repo.hex.pm` |
|
|
||||||
| `upstream.hex_api` | `PROXY_UPSTREAM_HEX_API` | `https://hex.pm` |
|
|
||||||
| `upstream.pub` | `PROXY_UPSTREAM_PUB` | `https://pub.dev` |
|
|
||||||
| `upstream.pypi` | `PROXY_UPSTREAM_PYPI` | `https://pypi.org` |
|
|
||||||
| `upstream.pypi_download` | `PROXY_UPSTREAM_PYPI_DOWNLOAD` | `https://files.pythonhosted.org` |
|
|
||||||
| `upstream.maven` | `PROXY_UPSTREAM_MAVEN` | `https://repo1.maven.org/maven2` |
|
|
||||||
| `upstream.gradle_plugin_portal` | `PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL` | `https://plugins.gradle.org/m2` |
|
|
||||||
| `upstream.nuget` | `PROXY_UPSTREAM_NUGET` | `https://api.nuget.org` |
|
|
||||||
| `upstream.nuget_search` | `PROXY_UPSTREAM_NUGET_SEARCH` | `https://azuresearch-usnc.nuget.org` |
|
|
||||||
| `upstream.composer` | `PROXY_UPSTREAM_COMPOSER` | `https://packagist.org` |
|
|
||||||
| `upstream.composer_repository` | `PROXY_UPSTREAM_COMPOSER_REPOSITORY` | `https://repo.packagist.org` |
|
|
||||||
| `upstream.conan` | `PROXY_UPSTREAM_CONAN` | `https://center.conan.io` |
|
|
||||||
| `upstream.conda` | `PROXY_UPSTREAM_CONDA` | `https://conda.anaconda.org` |
|
|
||||||
| `upstream.cran` | `PROXY_UPSTREAM_CRAN` | `https://cloud.r-project.org` |
|
|
||||||
| `upstream.julia` | `PROXY_UPSTREAM_JULIA` | `https://pkg.julialang.org` |
|
|
||||||
| `upstream.swift` | `PROXY_UPSTREAM_SWIFT` | `https://tuist.dev/api/registry/swift` |
|
|
||||||
| `upstream.oci_default` | `PROXY_UPSTREAM_OCI_DEFAULT` | `https://registry-1.docker.io` |
|
|
||||||
| `upstream.debian` | `PROXY_UPSTREAM_DEBIAN` | `http://deb.debian.org/debian` |
|
|
||||||
| `upstream.rpm` | `PROXY_UPSTREAM_RPM` | `https://dl.fedoraproject.org/pub/fedora/linux` |
|
|
||||||
| `upstream.homebrew_api` | `PROXY_UPSTREAM_HOMEBREW_API` | `https://formulae.brew.sh/api` |
|
|
||||||
| `upstream.homebrew_artifact` | `PROXY_UPSTREAM_HOMEBREW_ARTIFACT` | `https://ghcr.io` |
|
|
||||||
|
|
||||||
Private, ULA, CGNAT, and loopback addresses are rejected by default. Add each private upstream hostname or IP address to `upstream.allow_private_hosts`. The matching environment variable accepts a comma-separated list. Loopback upstreams also require `upstream.allow_loopback: true`. That setting permits upstream requests and redirects to reach any loopback address.
|
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
upstream:
|
upstream:
|
||||||
allow_private_hosts:
|
npm: "https://registry.npmjs.org"
|
||||||
- "upstream-proxy.internal"
|
cargo: "https://index.crates.io"
|
||||||
pypi: "http://upstream-proxy.internal/pypi"
|
cargo_download: "https://static.crates.io/crates"
|
||||||
pypi_download: "http://upstream-proxy.internal/pypi"
|
|
||||||
```
|
```
|
||||||
|
|
||||||
For protocols that use separate metadata and download services, configure both values. They may point to the same endpoint when chaining proxies:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
upstream:
|
|
||||||
pypi: "https://upstream-proxy.example.com/pypi"
|
|
||||||
pypi_download: "https://upstream-proxy.example.com/pypi"
|
|
||||||
nuget: "https://upstream-proxy.example.com/nuget"
|
|
||||||
nuget_search: "https://upstream-proxy.example.com/nuget"
|
|
||||||
composer: "https://upstream-proxy.example.com/composer"
|
|
||||||
composer_repository: "https://upstream-proxy.example.com/composer"
|
|
||||||
```
|
|
||||||
|
|
||||||
`upstream.hex_api` is used for cooldown timestamps and must expose Hex's `/api/packages/{name}` JSON endpoint.
|
|
||||||
|
|
||||||
Helm HTTP repositories and additional OCI registries are configured as named maps:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
upstream:
|
|
||||||
# Named HTTP Helm chart repositories, served at /helm/{name}/.
|
|
||||||
helm:
|
|
||||||
bitnami: "https://charts.bitnami.com/bitnami"
|
|
||||||
|
|
||||||
# Named OCI registries. Select one with the repository prefix
|
|
||||||
# upstream/{name}/, e.g. oci://proxy.example.com/upstream/ghcr/owner/chart.
|
|
||||||
oci:
|
|
||||||
ghcr: "https://ghcr.io"
|
|
||||||
```
|
|
||||||
|
|
||||||
Helm HTTP repositories are read-only. The proxy fetches and rewrites each
|
|
||||||
repository's `index.yaml` so chart archives are downloaded through the proxy.
|
|
||||||
Chart archives are retained only when their SHA-256 digest matches the digest
|
|
||||||
listed in the index. Relative and absolute chart URLs are both supported.
|
|
||||||
|
|
||||||
Generic HTTP upstreams proxy plain downloads from fixed base URLs:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
upstream:
|
|
||||||
# Named HTTP upstreams, served at /generic/{name}/. The rest of the
|
|
||||||
# request path and the query string are appended to the upstream URL.
|
|
||||||
generic:
|
|
||||||
github: "https://github.com"
|
|
||||||
github-api: "https://api.github.com"
|
|
||||||
auth:
|
|
||||||
# Optional: raise the GitHub API rate limit. Scoped to this host only,
|
|
||||||
# so the token is never sent to the object store GitHub redirects to.
|
|
||||||
"https://api.github.com":
|
|
||||||
type: bearer
|
|
||||||
token: "${GITHUB_TOKEN}"
|
|
||||||
```
|
|
||||||
|
|
||||||
Only configured upstreams are reachable, so this is not an open HTTP proxy.
|
|
||||||
Paths shaped like `{owner}/{repo}/releases/download/{tag}/{asset}` are
|
|
||||||
version-pinned GitHub release assets: they are stored in the artifact cache
|
|
||||||
and served from it without revalidation, including while the upstream is
|
|
||||||
down. Every other path is served through the metadata cache (`cache_metadata`
|
|
||||||
must be enabled for offline fallback): fresh within `metadata_ttl`, then
|
|
||||||
revalidated with the upstream's `ETag`/`Last-Modified`, and served stale with
|
|
||||||
a `Warning: 110` header when the upstream fails, refuses or rate-limits the
|
|
||||||
request. Metadata responses are buffered up to `metadata_max_size`, so keep
|
|
||||||
large mutable downloads (`releases/latest/download/...`) off this route.
|
|
||||||
|
|
||||||
This is the cache behind [mise](https://mise.jdx.dev)'s aqua backend; see the
|
|
||||||
mise section in the README for the client-side `url_replacements`.
|
|
||||||
|
|
||||||
`upstream.oci_default` sets the registry used by unprefixed `/v2` requests,
|
|
||||||
while `upstream.oci` selects named registries through the `upstream/{name}/`
|
|
||||||
repository prefix. For example, `oci://proxy.example.com/upstream/ghcr/owner/chart`
|
|
||||||
uses the `ghcr` registry with `owner/chart` as its repository.
|
|
||||||
When the proxy uses plain HTTP (for example `localhost:8080`), pass
|
|
||||||
`--plain-http` to Helm OCI commands.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
upstream:
|
|
||||||
|
|
||||||
# Named Alpine APK repositories, served at /apk/{name}/.
|
|
||||||
apk:
|
|
||||||
alpine: "https://dl-cdn.alpinelinux.org/alpine"
|
|
||||||
```
|
|
||||||
|
|
||||||
Alpine APK repositories are read-only. Requests to `/apk/{name}/…` mirror the
|
|
||||||
upstream layout, e.g. `/apk/alpine/v3.22/main/x86_64/APKINDEX.tar.gz`. Indexes
|
|
||||||
(v2 `APKINDEX.tar.gz`, v3 `Packages.adb`) and detached signatures are cached
|
|
||||||
with the metadata TTL and served byte-for-byte unchanged so apk signature
|
|
||||||
verification keeps working; `.apk` packages use the shared artifact cache.
|
|
||||||
When `upstream.apk` is empty, a single repository named `alpine` pointing at
|
|
||||||
the official mirror is available; configuring any entry replaces that default.
|
|
||||||
|
|
||||||
## Authentication
|
## Authentication
|
||||||
|
|
||||||
Configure authentication for private upstream registries. The same authentication-aware client is used for metadata and artifact downloads, and credentials can reference environment variables using `${VAR_NAME}` syntax.
|
Configure authentication for private upstream registries. Auth is matched by URL prefix, and credentials can reference environment variables using `${VAR_NAME}` syntax.
|
||||||
|
|
||||||
OCI registries that return a Bearer challenge from a `/v2/{repository}/…` endpoint are handled automatically. The proxy discovers the token realm from `WWW-Authenticate`, applies any configured credentials for the token URL, and reuses the scoped token until shortly before it expires.
|
|
||||||
|
|
||||||
### Bearer Token
|
### Bearer Token
|
||||||
|
|
||||||
|
|
@ -316,24 +167,9 @@ upstream:
|
||||||
header_value: "${MAVEN_TOKEN}"
|
header_value: "${MAVEN_TOKEN}"
|
||||||
```
|
```
|
||||||
|
|
||||||
### AWS ECR
|
|
||||||
|
|
||||||
Private ECR registries issue authorization tokens that expire after 12 hours. The `ecr` auth type calls `ecr:GetAuthorizationToken` on demand, caches the result, and refreshes it shortly before expiry, so no static credential appears in the config file:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
upstream:
|
|
||||||
oci:
|
|
||||||
ecr: "https://123456789012.dkr.ecr.eu-west-1.amazonaws.com"
|
|
||||||
auth:
|
|
||||||
"https://123456789012.dkr.ecr.eu-west-1.amazonaws.com":
|
|
||||||
type: ecr
|
|
||||||
```
|
|
||||||
|
|
||||||
AWS credentials are resolved by the SDK's default chain, which covers EKS IAM Roles for Service Accounts (IRSA), EC2/ECS instance profiles, `AWS_ACCESS_KEY_ID` / `AWS_SECRET_ACCESS_KEY` environment variables, and `~/.aws/credentials`. The IAM identity needs the `ecr:GetAuthorizationToken` action plus the usual `ecr:BatchGetImage` / `ecr:GetDownloadUrlForLayer` permissions on the target repositories. The region is inferred from private ECR IPv4, dual-stack, and FIPS hostnames. For other endpoint formats, set `region` explicitly or configure a default region for the SDK.
|
|
||||||
|
|
||||||
### URL Matching
|
### URL Matching
|
||||||
|
|
||||||
Auth keys must be absolute URLs. Matching compares the scheme, host, effective port, and path-segment prefix, preventing credentials for `registry.example.com` from being sent to a lookalike host such as `registry.example.com.evil.test`. The longest matching scope wins, so you can configure different credentials for different paths:
|
Auth configs are matched by URL prefix. The longest matching prefix wins, so you can configure different credentials for different paths:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
upstream:
|
upstream:
|
||||||
|
|
@ -348,249 +184,6 @@ upstream:
|
||||||
token: "${PRIVATE_TOKEN}"
|
token: "${PRIVATE_TOKEN}"
|
||||||
```
|
```
|
||||||
|
|
||||||
## Gradle Build Cache
|
|
||||||
|
|
||||||
The `/gradle` endpoint supports optional safeguards for upload control and cache retention.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
gradle:
|
|
||||||
build_cache:
|
|
||||||
read_only: false
|
|
||||||
max_upload_size: "100MB"
|
|
||||||
max_age: "168h"
|
|
||||||
max_size: "20GB"
|
|
||||||
sweep_interval: "10m"
|
|
||||||
```
|
|
||||||
|
|
||||||
| Config | Environment | Description |
|
|
||||||
|--------|-------------|-------------|
|
|
||||||
| `gradle.build_cache.read_only` | `PROXY_GRADLE_BUILD_CACHE_READ_ONLY` | Disable PUT uploads and keep GET/HEAD read-only |
|
|
||||||
| `gradle.build_cache.max_upload_size` | `PROXY_GRADLE_BUILD_CACHE_MAX_UPLOAD_SIZE` | Maximum accepted PUT body size (must be > 0) |
|
|
||||||
| `gradle.build_cache.max_age` | `PROXY_GRADLE_BUILD_CACHE_MAX_AGE` | Delete entries older than this duration (default `168h`, set `0` to disable) |
|
|
||||||
| `gradle.build_cache.max_size` | `PROXY_GRADLE_BUILD_CACHE_MAX_SIZE` | Total size cap for `_gradle/http-build-cache`, deleting oldest first (`0` disables) |
|
|
||||||
| `gradle.build_cache.sweep_interval` | `PROXY_GRADLE_BUILD_CACHE_SWEEP_INTERVAL` | Frequency for background eviction sweeps |
|
|
||||||
|
|
||||||
`max_age` and `max_size` are independent and can be combined. When both are set, age-based eviction runs first, then size-based eviction trims remaining entries oldest-first.
|
|
||||||
|
|
||||||
## Cooldown
|
|
||||||
|
|
||||||
The cooldown feature hides package versions published too recently, giving the community time to spot malicious releases before they reach your projects. When a version is within its cooldown period, it's stripped from metadata responses so package managers won't install it.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
cooldown:
|
|
||||||
default: "3d"
|
|
||||||
ecosystems:
|
|
||||||
npm: "7d"
|
|
||||||
cargo: "0"
|
|
||||||
packages:
|
|
||||||
"pkg:npm/lodash": "0"
|
|
||||||
"pkg:npm/@babel/core": "14d"
|
|
||||||
```
|
|
||||||
|
|
||||||
| Config | Environment | Description |
|
|
||||||
|--------|-------------|-------------|
|
|
||||||
| `cooldown.default` | `PROXY_COOLDOWN_DEFAULT` | Global default cooldown |
|
|
||||||
| `cooldown.ecosystems` | - | Per-ecosystem overrides |
|
|
||||||
| `cooldown.packages` | - | Per-package overrides (keyed by PURL) |
|
|
||||||
|
|
||||||
Durations support days (`7d`), hours (`48h`), and minutes (`30m`). Set to `0` to disable.
|
|
||||||
|
|
||||||
Package PURL keys are normalized to canonical form before matching, so `pkg:npm/@babel/core` and `pkg:npm/%40babel/core` are equivalent, as are `pkg:pypi/Django` and `pkg:pypi/django`. If both forms configure the same package, the canonical entry wins.
|
|
||||||
|
|
||||||
Resolution order: package override, then ecosystem override, then global default. This lets you set a conservative default while exempting trusted packages.
|
|
||||||
|
|
||||||
Currently supported for npm, PyPI, pub.dev, Composer, Cargo, NuGet, Conda, RubyGems, and Hex. These ecosystems include publish timestamps in their metadata.
|
|
||||||
|
|
||||||
Note: Hex cooldown requires disabling registry signature verification since the proxy re-encodes the protobuf payload without the original signature. Set `HEX_NO_VERIFY_REPO_ORIGIN=1` or configure your repo with `no_verify: true`.
|
|
||||||
|
|
||||||
## Artifact Scanning
|
|
||||||
|
|
||||||
Cooldown only ever looks at a version's *publish timestamp* — it never inspects the actual bytes of an artifact. Artifact scanning runs after a fetched artifact is staged into storage but before it becomes visible from cache, so an external scanner (trivy, ClamAV, Wiz, or any custom service) can block a bad verdict from ever reaching a client.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
scanning:
|
|
||||||
enabled: true
|
|
||||||
fail_open: false
|
|
||||||
timeout: 30s
|
|
||||||
signing_key: ${PROXY_SCANNING_SIGNING_KEY}
|
|
||||||
fetch_base_url: http://proxy.internal:8080
|
|
||||||
scanners:
|
|
||||||
- name: clamav
|
|
||||||
url: http://clamav-adapter:8080/scan
|
|
||||||
mode: block
|
|
||||||
- name: trivy
|
|
||||||
url: http://trivy-adapter:8081/scan
|
|
||||||
mode: monitor
|
|
||||||
ecosystems: [npm, pypi]
|
|
||||||
```
|
|
||||||
|
|
||||||
| Config | Environment | Description |
|
|
||||||
|--------|-------------|-------------|
|
|
||||||
| `scanning.enabled` | `PROXY_SCANNING_ENABLED` | Turn on the scan gate. When false (default), artifacts are cached exactly as if scanning didn't exist |
|
|
||||||
| `scanning.fail_open` | `PROXY_SCANNING_FAIL_OPEN` | Treat scanner errors/timeouts as allow instead of block. Default is fail-closed |
|
|
||||||
| `scanning.timeout` | `PROXY_SCANNING_TIMEOUT` | Per-scan-call timeout, Go duration syntax (default `30s`) |
|
|
||||||
| `scanning.signing_key` | `PROXY_SCANNING_SIGNING_KEY` | Signs pull requests to the internal scan-fetch route. Required whenever `enabled` is true |
|
|
||||||
| `scanning.fetch_base_url` | `PROXY_SCANNING_FETCH_BASE_URL` | Address scanners use to reach this proxy to pull staged artifacts. Defaults to `base_url` |
|
|
||||||
| `scanning.scanners` | - | List of external scanning services (YAML only) |
|
|
||||||
| `scanning.scanners[].name` | - | Identifies this scanner in logs and metrics |
|
|
||||||
| `scanning.scanners[].url` | - | Endpoint the proxy POSTs scan notifications to |
|
|
||||||
| `scanning.scanners[].mode` | - | `block` (default) or `monitor` |
|
|
||||||
| `scanning.scanners[].ecosystems` | - | Restricts this scanner to specific ecosystems (e.g. `npm`, `pypi`). Empty means all ecosystems |
|
|
||||||
| `scanning.scanners[].headers` | - | Extra HTTP headers sent with every scan request (e.g. for authenticating to the scanner service). Values support `${VAR_NAME}` expansion |
|
|
||||||
|
|
||||||
### How caching defers to a scan verdict
|
|
||||||
|
|
||||||
The proxy never uploads artifact bytes to a scanner. When an artifact is fetched from upstream, it's stored to the configured storage backend first, exactly as without scanning. If scanning is enabled for the artifact's ecosystem, the proxy then notifies each applicable scanner with package metadata and a short-lived, HMAC-signed URL pointing at the internal `/_internal/scan-fetch` route; each scanner GETs that URL itself to pull the exact bytes staged in storage and runs its own scan against them.
|
|
||||||
|
|
||||||
Scanners configured for the same ecosystem all run concurrently, never sequentially. The moment any `block`-mode scanner reports a not-allowed verdict (or errors, unless `fail_open` is set), the proxy cancels the in-flight calls to the other scanners and deletes the staged artifact — it's never committed to the cache database, so it was never visible to a client. If nothing blocks, the proxy waits for every `block`-mode scanner to finish before caching the artifact and serving it. A `monitor`-mode scanner's findings are logged and never gate the wait or the caching decision, even when it reports not-allowed.
|
|
||||||
|
|
||||||
A blocked download surfaces to the client as `403 Forbidden` with the scanner's reason, across every ecosystem handler.
|
|
||||||
|
|
||||||
### Scanner HTTP contract
|
|
||||||
|
|
||||||
Any external service that implements this contract can act as a scanner — a trivy wrapper, a clamav-rest bridge, a Wiz connector, or an in-house service. The proxy POSTs a notify request to `scanning.scanners[].url` and waits for a JSON verdict.
|
|
||||||
|
|
||||||
**Request**
|
|
||||||
|
|
||||||
| Field | Type | Description |
|
|
||||||
|-------|------|-------------|
|
|
||||||
| `ecosystem` | string | e.g. `npm`, `pypi`, `cargo` |
|
|
||||||
| `name` | string | Package name |
|
|
||||||
| `version` | string | Package version |
|
|
||||||
| `filename` | string | Artifact filename |
|
|
||||||
| `purl` | string | Package URL (PURL) identifying this exact version |
|
|
||||||
| `content_type` | string | Artifact content type |
|
|
||||||
| `size` | integer | Artifact size in bytes |
|
|
||||||
| `fetch_url` | string | Short-lived signed URL; GET this to retrieve the exact staged bytes |
|
|
||||||
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"ecosystem": "npm", "name": "left-pad", "version": "1.0.0",
|
|
||||||
"filename": "left-pad-1.0.0.tgz", "purl": "pkg:npm/left-pad@1.0.0",
|
|
||||||
"content_type": "application/octet-stream", "size": 1234,
|
|
||||||
"fetch_url": "https://proxy.internal/_internal/scan-fetch?path=...&exp=...&sig=..."
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Response**
|
|
||||||
|
|
||||||
| Field | Type | Description |
|
|
||||||
|-------|------|-------------|
|
|
||||||
| `allowed` | boolean | Whether the artifact may be cached and served |
|
|
||||||
| `reason` | string | Human-readable reason, surfaced to the client when `allowed` is false |
|
|
||||||
| `findings` | array | Optional list of `{"severity", "title", "description"}` objects |
|
|
||||||
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"allowed": false,
|
|
||||||
"reason": "malware detected",
|
|
||||||
"findings": [
|
|
||||||
{"severity": "critical", "title": "Trojan.GenericKD", "description": "..."}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
The scanner must respond within `scanning.timeout` (default `30s`); a timeout is treated the same as a `block` verdict unless `fail_open` is set.
|
|
||||||
|
|
||||||
### The `/_internal/scan-fetch` route
|
|
||||||
|
|
||||||
`fetch_url` points at an internal route, `/_internal/scan-fetch`, that streams a staged object straight from the proxy's storage backend via a short-lived HMAC-signed token (`path`, `exp`, `sig` query parameters). This works identically across every storage backend — local filesystem, S3, GCS, Azure — since it never depends on a backend-specific presigned URL, only on the one storage operation every backend already implements.
|
|
||||||
|
|
||||||
This route is not part of the public API. It's meant only for scanners to pull artifacts they've been notified about, and should be restricted to internal-network access at the ingress/network-policy layer — the HMAC scoping (one object, a short TTL) limits what a leaked token can do, but isn't a substitute for network restriction. Its query parameters are also documented in the generated [OpenAPI spec](../README.md#openapi-swagger).
|
|
||||||
|
|
||||||
The route only exists when scanning is actually configured: it's not mounted at all unless at least one scanner is enabled and `scanning.signing_key` is set, and it also refuses every request with `404` if either condition somehow isn't met at request time. There is no way to reach it, even with a forged token, when scanning is disabled.
|
|
||||||
|
|
||||||
## Metadata Caching
|
|
||||||
|
|
||||||
By default the proxy fetches metadata fresh from upstream on every request. Enable `cache_metadata` to store metadata responses in the database and storage backend for offline fallback. When upstream is unreachable, the proxy serves the last cached copy. ETag-based revalidation avoids re-downloading unchanged metadata.
|
|
||||||
|
|
||||||
OCI manifests and tag lists are always cached because cached image blobs cannot be pulled without their manifests and offline clients may need tag resolution. Digest-addressed manifests are immutable and served directly from cache. Tag-addressed manifests and tag lists follow `metadata_ttl`, revalidate when stale, and fall back to the last cached response when the registry is unavailable.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
cache_metadata: true
|
|
||||||
```
|
|
||||||
|
|
||||||
Or via environment variable: `PROXY_CACHE_METADATA=true`.
|
|
||||||
|
|
||||||
The `proxy mirror` command always enables metadata caching regardless of this setting.
|
|
||||||
|
|
||||||
### Metadata TTL
|
|
||||||
|
|
||||||
When metadata caching is enabled, `metadata_ttl` controls how long a cached response is considered fresh before revalidating with upstream. During the TTL window, cached metadata is served directly without contacting upstream, reducing latency and upstream load.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
metadata_ttl: "5m" # default
|
|
||||||
```
|
|
||||||
|
|
||||||
Or via environment variable: `PROXY_METADATA_TTL=10m`.
|
|
||||||
|
|
||||||
Set to `"0"` to always revalidate with upstream (ETag-based conditional requests still avoid re-downloading unchanged content).
|
|
||||||
|
|
||||||
When upstream is unreachable and the cached entry is past its TTL, the proxy serves the stale cached copy with a `Warning: 110 - "Response is Stale"` header so clients can tell the data may be outdated.
|
|
||||||
|
|
||||||
### Metadata size limit
|
|
||||||
|
|
||||||
Upstream metadata responses are buffered in memory before being rewritten and served. `metadata_max_size` caps that buffer to protect against OOM from a misbehaving upstream. Some npm packages with thousands of versions (for example `renovate`) exceed the 100 MB default, so raise this if you see `metadata response exceeds size limit` in the logs.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
metadata_max_size: "100MB" # default
|
|
||||||
```
|
|
||||||
|
|
||||||
Or via environment variable: `PROXY_METADATA_MAX_SIZE=250MB`.
|
|
||||||
|
|
||||||
## Upstream HTTP timeout
|
|
||||||
|
|
||||||
Protocol handlers use a shared HTTP client for upstream requests such as metadata fetches and pass-through file downloads. `http_timeout` sets that client's per-request timeout. Raise it if slow upstreams or large metadata responses cause `context deadline exceeded` errors.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
http_timeout: "30s" # default
|
|
||||||
```
|
|
||||||
|
|
||||||
Or via environment variable: `PROXY_HTTP_TIMEOUT=2m`.
|
|
||||||
|
|
||||||
Set to `"0"` to disable the timeout entirely (requests then rely only on the server's write timeout). Independently of this setting, the shared transport gives up on an upstream that has not sent response headers within 60 seconds.
|
|
||||||
|
|
||||||
## Mirror API
|
|
||||||
|
|
||||||
The `/api/mirror` endpoints are disabled by default. Enable them to allow starting mirror jobs via HTTP:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
mirror_api: true
|
|
||||||
```
|
|
||||||
|
|
||||||
Or via environment variable: `PROXY_MIRROR_API=true`.
|
|
||||||
|
|
||||||
When disabled, the endpoints are not registered and return 404.
|
|
||||||
|
|
||||||
Start a mirror job with either PURLs or an inline CycloneDX or SPDX JSON document:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
curl -X POST http://localhost:8080/api/mirror \
|
|
||||||
-H "Content-Type: application/json" \
|
|
||||||
-d '{"sbom":{"bomFormat":"CycloneDX","components":[{"purl":"pkg:npm/lodash@4.17.21"}]}}'
|
|
||||||
```
|
|
||||||
|
|
||||||
## Mirror Command
|
|
||||||
|
|
||||||
The `proxy mirror` command pre-populates the cache from various sources. It accepts the same storage and database flags as `serve`.
|
|
||||||
|
|
||||||
| Flag | Default | Description |
|
|
||||||
|------|---------|-------------|
|
|
||||||
| `--sbom` | | Path to CycloneDX or SPDX SBOM file |
|
|
||||||
| `--concurrency` | `4` | Number of parallel downloads |
|
|
||||||
| `--dry-run` | `false` | Show what would be mirrored without downloading |
|
|
||||||
| `--config` | | Path to configuration file |
|
|
||||||
| `--storage-url` | | Storage URL |
|
|
||||||
| `--database-driver` | | Database driver |
|
|
||||||
| `--database-path` | | SQLite database file |
|
|
||||||
| `--database-url` | | PostgreSQL connection URL |
|
|
||||||
|
|
||||||
Positional arguments are treated as PURLs:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
proxy mirror pkg:npm/lodash@4.17.21 pkg:cargo/serde@1.0.0
|
|
||||||
```
|
|
||||||
|
|
||||||
## Docker
|
## Docker
|
||||||
|
|
||||||
### SQLite with Local Storage
|
### SQLite with Local Storage
|
||||||
|
|
|
||||||
|
|
@ -1,51 +0,0 @@
|
||||||
# Database Migrations
|
|
||||||
|
|
||||||
Schema changes are tracked in a `migrations` table. Each migration has a name and a function. On startup, `MigrateSchema()` loads the set of already-applied names in one query and runs anything new.
|
|
||||||
|
|
||||||
Fresh databases created via `Create()` get the full schema and all migrations are recorded as already applied.
|
|
||||||
|
|
||||||
## Adding a migration
|
|
||||||
|
|
||||||
In `internal/database/schema.go`:
|
|
||||||
|
|
||||||
1. Write a migration function:
|
|
||||||
|
|
||||||
```go
|
|
||||||
func migrateAddWidgetColumn(db *DB) error {
|
|
||||||
hasCol, err := db.HasColumn("packages", "widget")
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("checking column widget: %w", err)
|
|
||||||
}
|
|
||||||
if !hasCol {
|
|
||||||
colType := "TEXT"
|
|
||||||
if db.dialect == DialectPostgres {
|
|
||||||
colType = "TEXT" // adjust if types differ
|
|
||||||
}
|
|
||||||
if _, err := db.Exec(fmt.Sprintf("ALTER TABLE packages ADD COLUMN widget %s", colType)); err != nil {
|
|
||||||
return fmt.Errorf("adding column widget: %w", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
2. Append it to the `migrations` slice with the next sequential prefix:
|
|
||||||
|
|
||||||
```go
|
|
||||||
var migrations = []migration{
|
|
||||||
{"001_add_packages_enrichment_columns", migrateAddPackagesEnrichmentColumns},
|
|
||||||
{"002_add_versions_enrichment_columns", migrateAddVersionsEnrichmentColumns},
|
|
||||||
{"003_ensure_artifacts_table", migrateEnsureArtifactsTable},
|
|
||||||
{"004_ensure_vulnerabilities_table", migrateEnsureVulnerabilitiesTable},
|
|
||||||
{"005_add_widget_column", migrateAddWidgetColumn}, // new
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
3. Add the same column to both `schemaSQLite` and `schemaPostgres` at the top of the file so fresh databases start with the full schema.
|
|
||||||
|
|
||||||
## Rules
|
|
||||||
|
|
||||||
- Migration functions must be idempotent. Use `HasColumn`/`HasTable` checks or `IF NOT EXISTS` clauses so they're safe to run against a database that already has the change.
|
|
||||||
- Handle both SQLite and Postgres dialects. Common differences: `DATETIME` vs `TIMESTAMP`, `INTEGER DEFAULT 0` vs `BOOLEAN DEFAULT FALSE`, `INTEGER PRIMARY KEY` vs `SERIAL PRIMARY KEY`.
|
|
||||||
- Never reorder or rename existing entries. The name string is the migration's identity in the database.
|
|
||||||
- Never remove old migrations from the list. They won't run on already-migrated databases, but they need to exist for older databases upgrading for the first time.
|
|
||||||
|
|
@ -1,839 +0,0 @@
|
||||||
// Package swagger Code generated by swaggo/swag. DO NOT EDIT
|
|
||||||
package swagger
|
|
||||||
|
|
||||||
import "github.com/swaggo/swag"
|
|
||||||
|
|
||||||
const docTemplate = `{
|
|
||||||
"schemes": {{ marshal .Schemes }},
|
|
||||||
"swagger": "2.0",
|
|
||||||
"info": {
|
|
||||||
"description": "{{escape .Description}}",
|
|
||||||
"title": "{{.Title}}",
|
|
||||||
"contact": {},
|
|
||||||
"version": "{{.Version}}"
|
|
||||||
},
|
|
||||||
"host": "{{.Host}}",
|
|
||||||
"basePath": "{{.BasePath}}",
|
|
||||||
"paths": {
|
|
||||||
"/_internal/scan-fetch": {
|
|
||||||
"get": {
|
|
||||||
"description": "Streams the exact bytes staged in storage for a pre-cache security scan.\nRequires a short-lived HMAC-signed token minted by the proxy itself and\ndelivered via the fetch_url field of the scan notify request (see the\nArtifact Scanning section of docs/configuration.md). Not part of the\npublic API; restrict access to the scanner network at the ingress layer.",
|
|
||||||
"produces": [
|
|
||||||
"application/octet-stream"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"scanning"
|
|
||||||
],
|
|
||||||
"summary": "Fetch a staged artifact for scanning",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Storage path of the staged artifact",
|
|
||||||
"name": "path",
|
|
||||||
"in": "query",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "integer",
|
|
||||||
"description": "Token expiry, Unix seconds",
|
|
||||||
"name": "exp",
|
|
||||||
"in": "query",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "HMAC-SHA256 signature over the string path|exp",
|
|
||||||
"name": "sig",
|
|
||||||
"in": "query",
|
|
||||||
"required": true
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"type": "file"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"403": {
|
|
||||||
"description": "invalid, expired, or tampered token",
|
|
||||||
"schema": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"404": {
|
|
||||||
"description": "object not found in storage, or scanning is not configured",
|
|
||||||
"schema": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/api/bulk": {
|
|
||||||
"post": {
|
|
||||||
"consumes": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"api"
|
|
||||||
],
|
|
||||||
"summary": "Bulk package lookup by PURL",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"description": "PURLs",
|
|
||||||
"name": "request",
|
|
||||||
"in": "body",
|
|
||||||
"required": true,
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.BulkRequest"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.BulkResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"400": {
|
|
||||||
"description": "Bad Request",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/api/outdated": {
|
|
||||||
"post": {
|
|
||||||
"consumes": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"api"
|
|
||||||
],
|
|
||||||
"summary": "Check outdated packages",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"description": "Packages to check",
|
|
||||||
"name": "request",
|
|
||||||
"in": "body",
|
|
||||||
"required": true,
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.OutdatedRequest"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.OutdatedResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"400": {
|
|
||||||
"description": "Bad Request",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/api/packages": {
|
|
||||||
"get": {
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"api"
|
|
||||||
],
|
|
||||||
"summary": "List cached packages",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Ecosystem",
|
|
||||||
"name": "ecosystem",
|
|
||||||
"in": "query"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"enum": [
|
|
||||||
"hits",
|
|
||||||
"name",
|
|
||||||
"size",
|
|
||||||
"cached_at",
|
|
||||||
"ecosystem",
|
|
||||||
"vulns"
|
|
||||||
],
|
|
||||||
"type": "string",
|
|
||||||
"description": "Sort",
|
|
||||||
"name": "sort",
|
|
||||||
"in": "query"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.PackagesListResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"400": {
|
|
||||||
"description": "Bad Request",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/api/search": {
|
|
||||||
"get": {
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"api"
|
|
||||||
],
|
|
||||||
"summary": "Search cached packages",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Query",
|
|
||||||
"name": "q",
|
|
||||||
"in": "query",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Ecosystem",
|
|
||||||
"name": "ecosystem",
|
|
||||||
"in": "query"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.SearchResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"400": {
|
|
||||||
"description": "Bad Request",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/health": {
|
|
||||||
"get": {
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"meta"
|
|
||||||
],
|
|
||||||
"summary": "Health check",
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.HealthResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"503": {
|
|
||||||
"description": "Service Unavailable",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.HealthResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/stats": {
|
|
||||||
"get": {
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"meta"
|
|
||||||
],
|
|
||||||
"summary": "Cache statistics",
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.StatsResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/ui/api/browse/{ecosystem}/{name}/{version}": {
|
|
||||||
"get": {
|
|
||||||
"description": "Lists files from the first cached artifact for a package version.",
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"browse"
|
|
||||||
],
|
|
||||||
"summary": "List files inside a cached artifact",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Ecosystem",
|
|
||||||
"name": "ecosystem",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Package name",
|
|
||||||
"name": "name",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Version",
|
|
||||||
"name": "version",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Directory path inside the archive",
|
|
||||||
"name": "path",
|
|
||||||
"in": "query"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.BrowseListResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"404": {
|
|
||||||
"description": "Not Found",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/ui/api/browse/{ecosystem}/{name}/{version}/file/{filepath}": {
|
|
||||||
"get": {
|
|
||||||
"description": "Streams a single file from the cached artifact. The file path may contain slashes.",
|
|
||||||
"produces": [
|
|
||||||
"application/octet-stream"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"browse"
|
|
||||||
],
|
|
||||||
"summary": "Fetch a file inside a cached artifact",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Ecosystem",
|
|
||||||
"name": "ecosystem",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Package name",
|
|
||||||
"name": "name",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Version",
|
|
||||||
"name": "version",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "File path inside the archive",
|
|
||||||
"name": "filepath",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"type": "file"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"400": {
|
|
||||||
"description": "Bad Request",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"404": {
|
|
||||||
"description": "Not Found",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/ui/api/compare/{ecosystem}/{name}/{fromVersion}/{toVersion}": {
|
|
||||||
"get": {
|
|
||||||
"description": "Returns a structured diff for two cached versions.",
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"browse"
|
|
||||||
],
|
|
||||||
"summary": "Compare two cached versions",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Ecosystem",
|
|
||||||
"name": "ecosystem",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Package name",
|
|
||||||
"name": "name",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "From version",
|
|
||||||
"name": "fromVersion",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "To version",
|
|
||||||
"name": "toVersion",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"type": "object",
|
|
||||||
"additionalProperties": true
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"404": {
|
|
||||||
"description": "Not Found",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"definitions": {
|
|
||||||
"server.BrowseFileInfo": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"is_dir": {
|
|
||||||
"type": "boolean"
|
|
||||||
},
|
|
||||||
"mod_time": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"path": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"size": {
|
|
||||||
"type": "integer"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.BrowseListResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"files": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"$ref": "#/definitions/server.BrowseFileInfo"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"path": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.BulkRequest": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"purls": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.BulkResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"packages": {
|
|
||||||
"type": "object",
|
|
||||||
"additionalProperties": {
|
|
||||||
"$ref": "#/definitions/server.PackageResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.ErrorResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"code": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"message": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.HealthCheck": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"error": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"status": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"step": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.HealthResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"checks": {
|
|
||||||
"type": "object",
|
|
||||||
"additionalProperties": {
|
|
||||||
"$ref": "#/definitions/server.HealthCheck"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"circuit_breakers": {
|
|
||||||
"description": "CircuitBreakers reports the state (\"open\" or \"closed\") of each upstream\nregistry's artifact-fetch circuit breaker, keyed by the host fetched from\nor, where the fetch URL has none to read, by an opaque placeholder\nstanding in for it. It is omitted when no breaker has been created yet.\nAn open breaker fails every artifact fetch it covers without contacting\nthe upstream, but says nothing about this proxy's own health, so it does\nnot change Status.",
|
|
||||||
"type": "object",
|
|
||||||
"additionalProperties": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"status": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.OutdatedPackage": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"version": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.OutdatedRequest": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"packages": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"$ref": "#/definitions/server.OutdatedPackage"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.OutdatedResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"results": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"$ref": "#/definitions/server.OutdatedResult"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.OutdatedResult": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"is_outdated": {
|
|
||||||
"type": "boolean"
|
|
||||||
},
|
|
||||||
"latest_version": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"version": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.PackageListResult": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"cached_at": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"hits": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"latest_version": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"license": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"license_category": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"size": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"vuln_count": {
|
|
||||||
"type": "integer"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.PackageResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"description": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"homepage": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"latest_version": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"license": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"license_category": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"registry_url": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"repository": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.PackagesListResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"count": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"page": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"per_page": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"results": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"$ref": "#/definitions/server.PackageListResult"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"sort_by": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"total": {
|
|
||||||
"type": "integer"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.SearchPackageResult": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"cached_at": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"hits": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"latest_version": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"license": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"size": {
|
|
||||||
"type": "integer"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.SearchResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"count": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"query": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"results": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"$ref": "#/definitions/server.SearchPackageResult"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.StatsResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"cached_artifacts": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"database_path": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"storage_url": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"total_size": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"total_size_bytes": {
|
|
||||||
"type": "integer"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
// SwaggerInfo holds exported Swagger Info so clients can modify it
|
|
||||||
var SwaggerInfo = &swag.Spec{
|
|
||||||
Version: "0.1.0",
|
|
||||||
Host: "",
|
|
||||||
BasePath: "/",
|
|
||||||
Schemes: []string{},
|
|
||||||
Title: "git-pkgs proxy API",
|
|
||||||
Description: "HTTP API for package enrichment, vulnerability lookup, cache stats, and source browsing.",
|
|
||||||
InfoInstanceName: "swagger",
|
|
||||||
SwaggerTemplate: docTemplate,
|
|
||||||
LeftDelim: "{{",
|
|
||||||
RightDelim: "}}",
|
|
||||||
}
|
|
||||||
|
|
||||||
func init() {
|
|
||||||
swag.Register(SwaggerInfo.InstanceName(), SwaggerInfo)
|
|
||||||
}
|
|
||||||
|
|
@ -1,814 +0,0 @@
|
||||||
{
|
|
||||||
"swagger": "2.0",
|
|
||||||
"info": {
|
|
||||||
"description": "HTTP API for package enrichment, vulnerability lookup, cache stats, and source browsing.",
|
|
||||||
"title": "git-pkgs proxy API",
|
|
||||||
"contact": {},
|
|
||||||
"version": "0.1.0"
|
|
||||||
},
|
|
||||||
"basePath": "/",
|
|
||||||
"paths": {
|
|
||||||
"/_internal/scan-fetch": {
|
|
||||||
"get": {
|
|
||||||
"description": "Streams the exact bytes staged in storage for a pre-cache security scan.\nRequires a short-lived HMAC-signed token minted by the proxy itself and\ndelivered via the fetch_url field of the scan notify request (see the\nArtifact Scanning section of docs/configuration.md). Not part of the\npublic API; restrict access to the scanner network at the ingress layer.",
|
|
||||||
"produces": [
|
|
||||||
"application/octet-stream"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"scanning"
|
|
||||||
],
|
|
||||||
"summary": "Fetch a staged artifact for scanning",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Storage path of the staged artifact",
|
|
||||||
"name": "path",
|
|
||||||
"in": "query",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "integer",
|
|
||||||
"description": "Token expiry, Unix seconds",
|
|
||||||
"name": "exp",
|
|
||||||
"in": "query",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "HMAC-SHA256 signature over the string path|exp",
|
|
||||||
"name": "sig",
|
|
||||||
"in": "query",
|
|
||||||
"required": true
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"type": "file"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"403": {
|
|
||||||
"description": "invalid, expired, or tampered token",
|
|
||||||
"schema": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"404": {
|
|
||||||
"description": "object not found in storage, or scanning is not configured",
|
|
||||||
"schema": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/api/bulk": {
|
|
||||||
"post": {
|
|
||||||
"consumes": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"api"
|
|
||||||
],
|
|
||||||
"summary": "Bulk package lookup by PURL",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"description": "PURLs",
|
|
||||||
"name": "request",
|
|
||||||
"in": "body",
|
|
||||||
"required": true,
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.BulkRequest"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.BulkResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"400": {
|
|
||||||
"description": "Bad Request",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/api/outdated": {
|
|
||||||
"post": {
|
|
||||||
"consumes": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"api"
|
|
||||||
],
|
|
||||||
"summary": "Check outdated packages",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"description": "Packages to check",
|
|
||||||
"name": "request",
|
|
||||||
"in": "body",
|
|
||||||
"required": true,
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.OutdatedRequest"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.OutdatedResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"400": {
|
|
||||||
"description": "Bad Request",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/api/packages": {
|
|
||||||
"get": {
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"api"
|
|
||||||
],
|
|
||||||
"summary": "List cached packages",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Ecosystem",
|
|
||||||
"name": "ecosystem",
|
|
||||||
"in": "query"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"enum": [
|
|
||||||
"hits",
|
|
||||||
"name",
|
|
||||||
"size",
|
|
||||||
"cached_at",
|
|
||||||
"ecosystem",
|
|
||||||
"vulns"
|
|
||||||
],
|
|
||||||
"type": "string",
|
|
||||||
"description": "Sort",
|
|
||||||
"name": "sort",
|
|
||||||
"in": "query"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.PackagesListResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"400": {
|
|
||||||
"description": "Bad Request",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/api/search": {
|
|
||||||
"get": {
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"api"
|
|
||||||
],
|
|
||||||
"summary": "Search cached packages",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Query",
|
|
||||||
"name": "q",
|
|
||||||
"in": "query",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Ecosystem",
|
|
||||||
"name": "ecosystem",
|
|
||||||
"in": "query"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.SearchResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"400": {
|
|
||||||
"description": "Bad Request",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/health": {
|
|
||||||
"get": {
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"meta"
|
|
||||||
],
|
|
||||||
"summary": "Health check",
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.HealthResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"503": {
|
|
||||||
"description": "Service Unavailable",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.HealthResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/stats": {
|
|
||||||
"get": {
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"meta"
|
|
||||||
],
|
|
||||||
"summary": "Cache statistics",
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.StatsResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/ui/api/browse/{ecosystem}/{name}/{version}": {
|
|
||||||
"get": {
|
|
||||||
"description": "Lists files from the first cached artifact for a package version.",
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"browse"
|
|
||||||
],
|
|
||||||
"summary": "List files inside a cached artifact",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Ecosystem",
|
|
||||||
"name": "ecosystem",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Package name",
|
|
||||||
"name": "name",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Version",
|
|
||||||
"name": "version",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Directory path inside the archive",
|
|
||||||
"name": "path",
|
|
||||||
"in": "query"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.BrowseListResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"404": {
|
|
||||||
"description": "Not Found",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/ui/api/browse/{ecosystem}/{name}/{version}/file/{filepath}": {
|
|
||||||
"get": {
|
|
||||||
"description": "Streams a single file from the cached artifact. The file path may contain slashes.",
|
|
||||||
"produces": [
|
|
||||||
"application/octet-stream"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"browse"
|
|
||||||
],
|
|
||||||
"summary": "Fetch a file inside a cached artifact",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Ecosystem",
|
|
||||||
"name": "ecosystem",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Package name",
|
|
||||||
"name": "name",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Version",
|
|
||||||
"name": "version",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "File path inside the archive",
|
|
||||||
"name": "filepath",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"type": "file"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"400": {
|
|
||||||
"description": "Bad Request",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"404": {
|
|
||||||
"description": "Not Found",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"/ui/api/compare/{ecosystem}/{name}/{fromVersion}/{toVersion}": {
|
|
||||||
"get": {
|
|
||||||
"description": "Returns a structured diff for two cached versions.",
|
|
||||||
"produces": [
|
|
||||||
"application/json"
|
|
||||||
],
|
|
||||||
"tags": [
|
|
||||||
"browse"
|
|
||||||
],
|
|
||||||
"summary": "Compare two cached versions",
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Ecosystem",
|
|
||||||
"name": "ecosystem",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "Package name",
|
|
||||||
"name": "name",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "From version",
|
|
||||||
"name": "fromVersion",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "string",
|
|
||||||
"description": "To version",
|
|
||||||
"name": "toVersion",
|
|
||||||
"in": "path",
|
|
||||||
"required": true
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"responses": {
|
|
||||||
"200": {
|
|
||||||
"description": "OK",
|
|
||||||
"schema": {
|
|
||||||
"type": "object",
|
|
||||||
"additionalProperties": true
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"404": {
|
|
||||||
"description": "Not Found",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"500": {
|
|
||||||
"description": "Internal Server Error",
|
|
||||||
"schema": {
|
|
||||||
"$ref": "#/definitions/server.ErrorResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"definitions": {
|
|
||||||
"server.BrowseFileInfo": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"is_dir": {
|
|
||||||
"type": "boolean"
|
|
||||||
},
|
|
||||||
"mod_time": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"path": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"size": {
|
|
||||||
"type": "integer"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.BrowseListResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"files": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"$ref": "#/definitions/server.BrowseFileInfo"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"path": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.BulkRequest": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"purls": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.BulkResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"packages": {
|
|
||||||
"type": "object",
|
|
||||||
"additionalProperties": {
|
|
||||||
"$ref": "#/definitions/server.PackageResponse"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.ErrorResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"code": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"message": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.HealthCheck": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"error": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"status": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"step": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.HealthResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"checks": {
|
|
||||||
"type": "object",
|
|
||||||
"additionalProperties": {
|
|
||||||
"$ref": "#/definitions/server.HealthCheck"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"circuit_breakers": {
|
|
||||||
"description": "CircuitBreakers reports the state (\"open\" or \"closed\") of each upstream\nregistry's artifact-fetch circuit breaker, keyed by the host fetched from\nor, where the fetch URL has none to read, by an opaque placeholder\nstanding in for it. It is omitted when no breaker has been created yet.\nAn open breaker fails every artifact fetch it covers without contacting\nthe upstream, but says nothing about this proxy's own health, so it does\nnot change Status.",
|
|
||||||
"type": "object",
|
|
||||||
"additionalProperties": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"status": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.OutdatedPackage": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"version": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.OutdatedRequest": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"packages": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"$ref": "#/definitions/server.OutdatedPackage"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.OutdatedResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"results": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"$ref": "#/definitions/server.OutdatedResult"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.OutdatedResult": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"is_outdated": {
|
|
||||||
"type": "boolean"
|
|
||||||
},
|
|
||||||
"latest_version": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"version": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.PackageListResult": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"cached_at": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"hits": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"latest_version": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"license": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"license_category": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"size": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"vuln_count": {
|
|
||||||
"type": "integer"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.PackageResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"description": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"homepage": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"latest_version": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"license": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"license_category": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"registry_url": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"repository": {
|
|
||||||
"type": "string"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.PackagesListResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"count": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"page": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"per_page": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"results": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"$ref": "#/definitions/server.PackageListResult"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"sort_by": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"total": {
|
|
||||||
"type": "integer"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.SearchPackageResult": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"cached_at": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"ecosystem": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"hits": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"latest_version": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"license": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"size": {
|
|
||||||
"type": "integer"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.SearchResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"count": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"query": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"results": {
|
|
||||||
"type": "array",
|
|
||||||
"items": {
|
|
||||||
"$ref": "#/definitions/server.SearchPackageResult"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"server.StatsResponse": {
|
|
||||||
"type": "object",
|
|
||||||
"properties": {
|
|
||||||
"cached_artifacts": {
|
|
||||||
"type": "integer"
|
|
||||||
},
|
|
||||||
"database_path": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"storage_url": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"total_size": {
|
|
||||||
"type": "string"
|
|
||||||
},
|
|
||||||
"total_size_bytes": {
|
|
||||||
"type": "integer"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
300
go.mod
300
go.mod
|
|
@ -1,149 +1,118 @@
|
||||||
module github.com/git-pkgs/proxy
|
module github.com/git-pkgs/proxy
|
||||||
|
|
||||||
go 1.26.7
|
go 1.25.7
|
||||||
|
|
||||||
require (
|
require (
|
||||||
github.com/BurntSushi/toml v1.6.0
|
github.com/git-pkgs/archives v0.2.0
|
||||||
github.com/CycloneDX/cyclonedx-go v0.12.0
|
github.com/git-pkgs/enrichment v0.1.5
|
||||||
github.com/aws/aws-sdk-go-v2/config v1.33.2
|
github.com/git-pkgs/git-pkgs v0.15.1-0.20260304191500-e296d0146017
|
||||||
github.com/aws/aws-sdk-go-v2/service/ecr v1.64.0
|
github.com/git-pkgs/purl v0.1.9
|
||||||
github.com/git-pkgs/archives v0.7.0
|
github.com/git-pkgs/registries v0.3.0
|
||||||
github.com/git-pkgs/artifacts v0.2.1
|
github.com/git-pkgs/spdx v0.1.1
|
||||||
github.com/git-pkgs/cooldown v0.2.0
|
github.com/git-pkgs/vers v0.2.3
|
||||||
github.com/git-pkgs/enrichment v0.7.1
|
github.com/git-pkgs/vulns v0.1.3
|
||||||
github.com/git-pkgs/gcs v0.1.0
|
github.com/go-chi/chi/v5 v5.2.5
|
||||||
github.com/git-pkgs/integrity v0.1.1
|
|
||||||
github.com/git-pkgs/magic v0.3.1
|
|
||||||
github.com/git-pkgs/purl v0.1.20
|
|
||||||
github.com/git-pkgs/registries v0.9.1
|
|
||||||
github.com/git-pkgs/spdx v0.3.1
|
|
||||||
github.com/git-pkgs/vers v0.7.0
|
|
||||||
github.com/git-pkgs/vulns v0.2.3
|
|
||||||
github.com/go-chi/chi/v5 v5.3.2
|
|
||||||
github.com/jmoiron/sqlx v1.4.0
|
github.com/jmoiron/sqlx v1.4.0
|
||||||
github.com/lib/pq v1.12.3
|
github.com/lib/pq v1.11.2
|
||||||
github.com/opencontainers/go-digest v1.0.0
|
github.com/prometheus/client_golang v1.23.2
|
||||||
github.com/prometheus/client_golang v1.24.1
|
github.com/prometheus/client_model v0.6.2
|
||||||
github.com/prometheus/client_model v0.6.3
|
gocloud.dev v0.45.0
|
||||||
github.com/spdx/tools-golang v0.5.7
|
|
||||||
github.com/swaggo/swag v1.16.6
|
|
||||||
gocloud.dev v0.46.0
|
|
||||||
golang.org/x/sync v0.23.0
|
|
||||||
google.golang.org/protobuf v1.36.12
|
|
||||||
gopkg.in/yaml.v3 v3.0.1
|
gopkg.in/yaml.v3 v3.0.1
|
||||||
modernc.org/sqlite v1.58.0
|
modernc.org/sqlite v1.46.1
|
||||||
)
|
)
|
||||||
|
|
||||||
require (
|
require (
|
||||||
4d63.com/gocheckcompilerdirectives v1.4.0 // indirect
|
4d63.com/gocheckcompilerdirectives v1.3.0 // indirect
|
||||||
4d63.com/gochecknoglobals v0.2.2 // indirect
|
4d63.com/gochecknoglobals v0.2.2 // indirect
|
||||||
charm.land/lipgloss/v2 v2.0.6 // indirect
|
|
||||||
cloud.google.com/go/auth v0.21.0 // indirect
|
|
||||||
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
|
|
||||||
cloud.google.com/go/compute/metadata v0.9.0 // indirect
|
cloud.google.com/go/compute/metadata v0.9.0 // indirect
|
||||||
codeberg.org/chavacava/garif v0.2.0 // indirect
|
codeberg.org/chavacava/garif v0.2.0 // indirect
|
||||||
codeberg.org/polyfloyd/go-errorlint v1.9.0 // indirect
|
codeberg.org/polyfloyd/go-errorlint v1.9.0 // indirect
|
||||||
dev.gaijin.team/go/exhaustruct/v4 v4.0.0 // indirect
|
dev.gaijin.team/go/exhaustruct/v4 v4.0.0 // indirect
|
||||||
dev.gaijin.team/go/exhaustruct/v5 v5.0.3 // indirect
|
dev.gaijin.team/go/golib v0.6.0 // indirect
|
||||||
dev.gaijin.team/go/golib v0.8.1 // indirect
|
|
||||||
github.com/4meepo/tagalign v1.4.3 // indirect
|
github.com/4meepo/tagalign v1.4.3 // indirect
|
||||||
github.com/Abirdcfly/dupword v0.1.8 // indirect
|
github.com/Abirdcfly/dupword v0.1.7 // indirect
|
||||||
github.com/AdminBenni/iota-mixing v1.0.0 // indirect
|
github.com/AdminBenni/iota-mixing v1.0.0 // indirect
|
||||||
github.com/AlwxSin/noinlineerr v1.0.6 // indirect
|
github.com/AlwxSin/noinlineerr v1.0.5 // indirect
|
||||||
github.com/Antonboom/errname v1.1.2 // indirect
|
github.com/Antonboom/errname v1.1.1 // indirect
|
||||||
github.com/Antonboom/nilnil v1.1.2 // indirect
|
github.com/Antonboom/nilnil v1.1.1 // indirect
|
||||||
github.com/Antonboom/testifylint v1.6.4 // indirect
|
github.com/Antonboom/testifylint v1.6.4 // indirect
|
||||||
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 // indirect
|
github.com/BurntSushi/toml v1.6.0 // indirect
|
||||||
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 // indirect
|
|
||||||
github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect
|
|
||||||
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.6.4 // indirect
|
|
||||||
github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0 // indirect
|
|
||||||
github.com/ClickHouse/clickhouse-go-linter v1.2.1 // indirect
|
|
||||||
github.com/Djarvur/go-err113 v0.1.1 // indirect
|
github.com/Djarvur/go-err113 v0.1.1 // indirect
|
||||||
github.com/KyleBanks/depth v1.2.1 // indirect
|
github.com/Masterminds/semver/v3 v3.4.0 // indirect
|
||||||
github.com/Masterminds/semver/v3 v3.5.0 // indirect
|
github.com/MirrexOne/unqueryvet v1.5.3 // indirect
|
||||||
github.com/MirrexOne/unqueryvet v1.5.4 // indirect
|
|
||||||
github.com/OpenPeeDeeP/depguard/v2 v2.2.1 // indirect
|
github.com/OpenPeeDeeP/depguard/v2 v2.2.1 // indirect
|
||||||
github.com/PuerkitoBio/purell v1.1.1 // indirect
|
github.com/alecthomas/chroma/v2 v2.23.1 // indirect
|
||||||
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect
|
|
||||||
github.com/alecthomas/chroma/v2 v2.27.0 // indirect
|
|
||||||
github.com/alecthomas/go-check-sumtype v0.3.1 // indirect
|
github.com/alecthomas/go-check-sumtype v0.3.1 // indirect
|
||||||
github.com/alexkohler/nakedret/v2 v2.0.6 // indirect
|
github.com/alexkohler/nakedret/v2 v2.0.6 // indirect
|
||||||
github.com/alexkohler/prealloc v1.1.0 // indirect
|
github.com/alexkohler/prealloc v1.0.2 // indirect
|
||||||
github.com/alfatraining/structtag v1.0.0 // indirect
|
github.com/alfatraining/structtag v1.0.0 // indirect
|
||||||
github.com/alingse/asasalint v0.0.11 // indirect
|
github.com/alingse/asasalint v0.0.11 // indirect
|
||||||
github.com/alingse/nilnesserr v0.2.0 // indirect
|
github.com/alingse/nilnesserr v0.2.0 // indirect
|
||||||
github.com/anchore/go-struct-converter v0.1.0 // indirect
|
|
||||||
github.com/apapsch/go-jsonmerge/v2 v2.0.0 // indirect
|
github.com/apapsch/go-jsonmerge/v2 v2.0.0 // indirect
|
||||||
github.com/ashanbrown/forbidigo/v2 v2.3.1 // indirect
|
github.com/ashanbrown/forbidigo/v2 v2.3.0 // indirect
|
||||||
github.com/ashanbrown/makezero/v2 v2.2.1 // indirect
|
github.com/ashanbrown/makezero/v2 v2.1.0 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2 v1.46.0 // indirect
|
github.com/aws/aws-sdk-go-v2 v1.41.3 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11 // indirect
|
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.6 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/credentials v1.20.2 // indirect
|
github.com/aws/aws-sdk-go-v2/config v1.32.11 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.19.1 // indirect
|
github.com/aws/aws-sdk-go-v2/credentials v1.19.11 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.2.3 // indirect
|
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.19 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/internal/configsources v1.5.2 // indirect
|
github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.5 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.8.2 // indirect
|
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.19 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/internal/v4a v1.5.1 // indirect
|
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.19 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19 // indirect
|
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.5 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.18 // indirect
|
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.19 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.14.1 // indirect
|
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.6 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.25 // indirect
|
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.11 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/service/s3 v1.102.2 // indirect
|
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.19 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/service/signin v1.8.0 // indirect
|
github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.19 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/service/sso v1.36.0 // indirect
|
github.com/aws/aws-sdk-go-v2/service/s3 v1.96.3 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.41.0 // indirect
|
github.com/aws/aws-sdk-go-v2/service/signin v1.0.7 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/service/sts v1.48.0 // indirect
|
github.com/aws/aws-sdk-go-v2/service/sso v1.30.12 // indirect
|
||||||
github.com/aws/smithy-go v1.28.1 // indirect
|
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.16 // indirect
|
||||||
|
github.com/aws/aws-sdk-go-v2/service/sts v1.41.8 // indirect
|
||||||
|
github.com/aws/smithy-go v1.24.2 // indirect
|
||||||
|
github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect
|
||||||
github.com/beorn7/perks v1.0.1 // indirect
|
github.com/beorn7/perks v1.0.1 // indirect
|
||||||
github.com/bkielbasa/cyclop v1.2.3 // indirect
|
github.com/bkielbasa/cyclop v1.2.3 // indirect
|
||||||
github.com/blizzy78/varnamelen v0.8.0 // indirect
|
github.com/blizzy78/varnamelen v0.8.0 // indirect
|
||||||
github.com/bombsimon/wsl/v4 v4.7.0 // indirect
|
github.com/bombsimon/wsl/v4 v4.7.0 // indirect
|
||||||
github.com/bombsimon/wsl/v5 v5.9.0 // indirect
|
github.com/bombsimon/wsl/v5 v5.6.0 // indirect
|
||||||
github.com/breml/bidichk v0.3.3 // indirect
|
github.com/breml/bidichk v0.3.3 // indirect
|
||||||
github.com/breml/errchkjson v0.4.1 // indirect
|
github.com/breml/errchkjson v0.4.1 // indirect
|
||||||
github.com/butuzov/ireturn v0.4.1 // indirect
|
github.com/butuzov/ireturn v0.4.0 // indirect
|
||||||
github.com/butuzov/mirror v1.3.3 // indirect
|
github.com/butuzov/mirror v1.3.0 // indirect
|
||||||
github.com/catenacyber/perfsprint v0.10.1 // indirect
|
github.com/catenacyber/perfsprint v0.10.1 // indirect
|
||||||
github.com/ccojocar/zxcvbn-go v1.0.4 // indirect
|
github.com/ccojocar/zxcvbn-go v1.0.4 // indirect
|
||||||
github.com/cenk/backoff v2.2.1+incompatible // indirect
|
github.com/cenk/backoff v2.2.1+incompatible // indirect
|
||||||
github.com/cespare/xxhash/v2 v2.3.0 // indirect
|
github.com/cespare/xxhash/v2 v2.3.0 // indirect
|
||||||
github.com/charithe/durationcheck v0.0.11 // indirect
|
github.com/charithe/durationcheck v0.0.11 // indirect
|
||||||
github.com/charmbracelet/colorprofile v0.4.3 // indirect
|
github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc // indirect
|
||||||
github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886 // indirect
|
github.com/charmbracelet/lipgloss v1.1.0 // indirect
|
||||||
github.com/charmbracelet/x/ansi v0.11.8 // indirect
|
github.com/charmbracelet/x/ansi v0.10.1 // indirect
|
||||||
github.com/charmbracelet/x/term v0.2.2 // indirect
|
github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd // indirect
|
||||||
github.com/charmbracelet/x/termios v0.1.1 // indirect
|
github.com/charmbracelet/x/term v0.2.1 // indirect
|
||||||
github.com/charmbracelet/x/windows v0.2.2 // indirect
|
|
||||||
github.com/ckaznocha/intrange v0.3.1 // indirect
|
github.com/ckaznocha/intrange v0.3.1 // indirect
|
||||||
github.com/clipperhouse/displaywidth v0.11.0 // indirect
|
|
||||||
github.com/clipperhouse/uax29/v2 v2.7.0 // indirect
|
|
||||||
github.com/cpuguy83/go-md2man/v2 v2.0.6 // indirect
|
|
||||||
github.com/curioswitch/go-reassign v0.3.0 // indirect
|
github.com/curioswitch/go-reassign v0.3.0 // indirect
|
||||||
github.com/daixiang0/gci v0.13.7 // indirect
|
github.com/daixiang0/gci v0.13.7 // indirect
|
||||||
github.com/dave/dst v0.27.3 // indirect
|
github.com/dave/dst v0.27.3 // indirect
|
||||||
|
github.com/davecgh/go-spew v1.1.1 // indirect
|
||||||
github.com/denis-tingaikin/go-header v0.5.0 // indirect
|
github.com/denis-tingaikin/go-header v0.5.0 // indirect
|
||||||
github.com/dlclark/regexp2/v2 v2.2.1 // indirect
|
github.com/dlclark/regexp2 v1.11.5 // indirect
|
||||||
github.com/dustin/go-humanize v1.0.1 // indirect
|
github.com/dustin/go-humanize v1.0.1 // indirect
|
||||||
github.com/ecosyste-ms/ecosystems-go v0.4.0 // indirect
|
github.com/ecosyste-ms/ecosystems-go v0.1.1 // indirect
|
||||||
github.com/ettle/strcase v0.2.0 // indirect
|
github.com/ettle/strcase v0.2.0 // indirect
|
||||||
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a // indirect
|
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a // indirect
|
||||||
github.com/fatih/color v1.19.0 // indirect
|
github.com/fatih/color v1.18.0 // indirect
|
||||||
github.com/fatih/structtag v1.2.0 // indirect
|
github.com/fatih/structtag v1.2.0 // indirect
|
||||||
github.com/firefart/nonamedreturns v1.0.8 // indirect
|
github.com/firefart/nonamedreturns v1.0.6 // indirect
|
||||||
github.com/fsnotify/fsnotify v1.9.0 // indirect
|
github.com/fsnotify/fsnotify v1.9.0 // indirect
|
||||||
github.com/fzipp/gocyclo v0.6.0 // indirect
|
github.com/fzipp/gocyclo v0.6.0 // indirect
|
||||||
github.com/ghostiam/protogetter v0.3.21 // indirect
|
github.com/ghostiam/protogetter v0.3.20 // indirect
|
||||||
github.com/git-pkgs/packageurl-go v0.3.1 // indirect
|
github.com/git-pkgs/packageurl-go v0.3.1 // indirect
|
||||||
github.com/git-pkgs/pom v0.1.7 // indirect
|
github.com/github/go-spdx/v2 v2.4.0 // indirect
|
||||||
github.com/github/go-spdx/v2 v2.7.0 // indirect
|
github.com/go-critic/go-critic v0.14.3 // indirect
|
||||||
github.com/go-critic/go-critic v0.14.4 // indirect
|
|
||||||
github.com/go-logr/logr v1.4.3 // indirect
|
github.com/go-logr/logr v1.4.3 // indirect
|
||||||
github.com/go-logr/stdr v1.2.2 // indirect
|
github.com/go-logr/stdr v1.2.2 // indirect
|
||||||
github.com/go-openapi/jsonpointer v0.19.5 // indirect
|
|
||||||
github.com/go-openapi/jsonreference v0.19.6 // indirect
|
|
||||||
github.com/go-openapi/spec v0.20.4 // indirect
|
|
||||||
github.com/go-openapi/swag v0.19.15 // indirect
|
|
||||||
github.com/go-toolsmith/astcast v1.1.0 // indirect
|
github.com/go-toolsmith/astcast v1.1.0 // indirect
|
||||||
github.com/go-toolsmith/astcopy v1.1.0 // indirect
|
github.com/go-toolsmith/astcopy v1.1.0 // indirect
|
||||||
github.com/go-toolsmith/astequal v1.2.0 // indirect
|
github.com/go-toolsmith/astequal v1.2.0 // indirect
|
||||||
|
|
@ -156,111 +125,100 @@ require (
|
||||||
github.com/gobwas/glob v0.2.3 // indirect
|
github.com/gobwas/glob v0.2.3 // indirect
|
||||||
github.com/godoc-lint/godoc-lint v0.11.2 // indirect
|
github.com/godoc-lint/godoc-lint v0.11.2 // indirect
|
||||||
github.com/gofrs/flock v0.13.0 // indirect
|
github.com/gofrs/flock v0.13.0 // indirect
|
||||||
github.com/golang-jwt/jwt/v5 v5.3.1 // indirect
|
|
||||||
github.com/golangci/asciicheck v0.5.0 // indirect
|
github.com/golangci/asciicheck v0.5.0 // indirect
|
||||||
github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202 // indirect
|
github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32 // indirect
|
||||||
github.com/golangci/go-printf-func-name v0.1.1 // indirect
|
github.com/golangci/go-printf-func-name v0.1.1 // indirect
|
||||||
github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792 // indirect
|
github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d // indirect
|
||||||
github.com/golangci/golangci-lint/v2 v2.13.1 // indirect
|
github.com/golangci/golangci-lint/v2 v2.10.1 // indirect
|
||||||
github.com/golangci/golines v0.15.0 // indirect
|
github.com/golangci/golines v0.15.0 // indirect
|
||||||
github.com/golangci/misspell v0.8.0 // indirect
|
github.com/golangci/misspell v0.8.0 // indirect
|
||||||
github.com/golangci/plugin-module-register v0.1.2 // indirect
|
github.com/golangci/plugin-module-register v0.1.2 // indirect
|
||||||
github.com/golangci/revgrep v0.8.0 // indirect
|
github.com/golangci/revgrep v0.8.0 // indirect
|
||||||
github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba // indirect
|
|
||||||
github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e // indirect
|
github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e // indirect
|
||||||
github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e // indirect
|
github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e // indirect
|
||||||
github.com/google/go-cmp v0.7.0 // indirect
|
github.com/google/go-cmp v0.7.0 // indirect
|
||||||
github.com/google/s2a-go v0.1.9 // indirect
|
|
||||||
github.com/google/uuid v1.6.0 // indirect
|
github.com/google/uuid v1.6.0 // indirect
|
||||||
github.com/google/wire v0.7.0 // indirect
|
github.com/google/wire v0.7.0 // indirect
|
||||||
github.com/googleapis/enterprise-certificate-proxy v0.3.18 // indirect
|
github.com/googleapis/gax-go/v2 v2.17.0 // indirect
|
||||||
github.com/googleapis/gax-go/v2 v2.23.0 // indirect
|
|
||||||
github.com/gordonklaus/ineffassign v0.2.0 // indirect
|
github.com/gordonklaus/ineffassign v0.2.0 // indirect
|
||||||
github.com/gostaticanalysis/analysisutil v0.7.1 // indirect
|
github.com/gostaticanalysis/analysisutil v0.7.1 // indirect
|
||||||
github.com/gostaticanalysis/comment v1.5.0 // indirect
|
github.com/gostaticanalysis/comment v1.5.0 // indirect
|
||||||
github.com/gostaticanalysis/forcetypeassert v0.2.0 // indirect
|
github.com/gostaticanalysis/forcetypeassert v0.2.0 // indirect
|
||||||
github.com/gostaticanalysis/nilerr v0.1.2 // indirect
|
github.com/gostaticanalysis/nilerr v0.1.2 // indirect
|
||||||
github.com/hashicorp/go-immutable-radix/v2 v2.1.0 // indirect
|
github.com/hashicorp/go-immutable-radix/v2 v2.1.0 // indirect
|
||||||
github.com/hashicorp/go-version v1.9.0 // indirect
|
github.com/hashicorp/go-version v1.8.0 // indirect
|
||||||
github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect
|
github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect
|
||||||
github.com/hashicorp/hcl v1.0.0 // indirect
|
github.com/hashicorp/hcl v1.0.0 // indirect
|
||||||
github.com/hexops/gotextdiff v1.0.3 // indirect
|
github.com/hexops/gotextdiff v1.0.3 // indirect
|
||||||
github.com/inconshreveable/mousetrap v1.1.0 // indirect
|
github.com/inconshreveable/mousetrap v1.1.0 // indirect
|
||||||
github.com/jgautheron/goconst v1.11.0 // indirect
|
github.com/jgautheron/goconst v1.8.2 // indirect
|
||||||
|
github.com/jingyugao/rowserrcheck v1.1.1 // indirect
|
||||||
github.com/jjti/go-spancheck v0.6.5 // indirect
|
github.com/jjti/go-spancheck v0.6.5 // indirect
|
||||||
github.com/josharian/intern v1.0.0 // indirect
|
|
||||||
github.com/julz/importas v0.2.0 // indirect
|
github.com/julz/importas v0.2.0 // indirect
|
||||||
github.com/karamaru-alpha/copyloopvar v1.2.2 // indirect
|
github.com/karamaru-alpha/copyloopvar v1.2.2 // indirect
|
||||||
github.com/kisielk/errcheck v1.20.0 // indirect
|
github.com/kisielk/errcheck v1.9.0 // indirect
|
||||||
github.com/kkHAIKE/contextcheck v1.1.6 // indirect
|
github.com/kkHAIKE/contextcheck v1.1.6 // indirect
|
||||||
github.com/klauspost/compress v1.19.2 // indirect
|
|
||||||
github.com/kulti/thelper v0.7.1 // indirect
|
github.com/kulti/thelper v0.7.1 // indirect
|
||||||
github.com/kunwardeep/paralleltest v1.0.15 // indirect
|
github.com/kunwardeep/paralleltest v1.0.15 // indirect
|
||||||
github.com/kylelemons/godebug v1.1.0 // indirect
|
|
||||||
github.com/lasiar/canonicalheader v1.1.2 // indirect
|
github.com/lasiar/canonicalheader v1.1.2 // indirect
|
||||||
github.com/ldez/exptostd v0.4.5 // indirect
|
github.com/ldez/exptostd v0.4.5 // indirect
|
||||||
github.com/ldez/gomoddirectives v0.9.0 // indirect
|
github.com/ldez/gomoddirectives v0.8.0 // indirect
|
||||||
github.com/ldez/grignotin v0.10.1 // indirect
|
github.com/ldez/grignotin v0.10.1 // indirect
|
||||||
github.com/ldez/structtags v0.6.1 // indirect
|
github.com/ldez/structtags v0.6.1 // indirect
|
||||||
github.com/ldez/tagliatelle v0.7.2 // indirect
|
github.com/ldez/tagliatelle v0.7.2 // indirect
|
||||||
github.com/ldez/usetesting v0.5.0 // indirect
|
github.com/ldez/usetesting v0.5.0 // indirect
|
||||||
github.com/leonklingele/grouper v1.1.2 // indirect
|
github.com/leonklingele/grouper v1.1.2 // indirect
|
||||||
github.com/lucasb-eyer/go-colorful v1.4.1 // indirect
|
github.com/lucasb-eyer/go-colorful v1.2.0 // indirect
|
||||||
github.com/macabu/inamedparam v0.2.0 // indirect
|
github.com/macabu/inamedparam v0.2.0 // indirect
|
||||||
github.com/magiconair/properties v1.8.6 // indirect
|
github.com/magiconair/properties v1.8.6 // indirect
|
||||||
github.com/mailru/easyjson v0.7.7 // indirect
|
|
||||||
github.com/manuelarte/embeddedstructfieldcheck v0.4.0 // indirect
|
github.com/manuelarte/embeddedstructfieldcheck v0.4.0 // indirect
|
||||||
github.com/manuelarte/funcorder v0.6.0 // indirect
|
github.com/manuelarte/funcorder v0.5.0 // indirect
|
||||||
github.com/maratori/testableexamples v1.0.1 // indirect
|
github.com/maratori/testableexamples v1.0.1 // indirect
|
||||||
github.com/maratori/testpackage v1.1.2 // indirect
|
github.com/maratori/testpackage v1.1.2 // indirect
|
||||||
github.com/matoous/godox v1.1.0 // indirect
|
github.com/matoous/godox v1.1.0 // indirect
|
||||||
github.com/mattn/go-colorable v0.1.15 // indirect
|
github.com/mattn/go-colorable v0.1.14 // indirect
|
||||||
github.com/mattn/go-isatty v0.0.24 // indirect
|
github.com/mattn/go-isatty v0.0.20 // indirect
|
||||||
github.com/mattn/go-runewidth v0.0.24 // indirect
|
github.com/mattn/go-runewidth v0.0.16 // indirect
|
||||||
github.com/mgechev/revive v1.15.0 // indirect
|
github.com/mgechev/revive v1.14.0 // indirect
|
||||||
github.com/mitchellh/go-homedir v1.1.0 // indirect
|
github.com/mitchellh/go-homedir v1.1.0 // indirect
|
||||||
github.com/mitchellh/mapstructure v1.5.0 // indirect
|
github.com/mitchellh/mapstructure v1.5.0 // indirect
|
||||||
github.com/moricho/tparallel v0.3.2 // indirect
|
github.com/moricho/tparallel v0.3.2 // indirect
|
||||||
github.com/muesli/cancelreader v0.2.2 // indirect
|
github.com/muesli/termenv v0.16.0 // indirect
|
||||||
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
|
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
|
||||||
github.com/nakabonne/nestif v0.3.1 // indirect
|
github.com/nakabonne/nestif v0.3.1 // indirect
|
||||||
github.com/ncruces/go-strftime v1.0.0 // indirect
|
github.com/ncruces/go-strftime v1.0.0 // indirect
|
||||||
github.com/nishanths/exhaustive v0.12.0 // indirect
|
github.com/nishanths/exhaustive v0.12.0 // indirect
|
||||||
github.com/nishanths/predeclared v0.2.2 // indirect
|
github.com/nishanths/predeclared v0.2.2 // indirect
|
||||||
github.com/nunnatsa/ginkgolinter v0.24.0 // indirect
|
github.com/nunnatsa/ginkgolinter v0.23.0 // indirect
|
||||||
github.com/oapi-codegen/nullable v1.2.0 // indirect
|
github.com/oapi-codegen/runtime v1.2.0 // indirect
|
||||||
github.com/oapi-codegen/runtime v1.6.0 // indirect
|
github.com/pandatix/go-cvss v0.6.2 // indirect
|
||||||
github.com/package-url/packageurl-go v0.1.7 // indirect
|
|
||||||
github.com/pandatix/go-cvss v0.6.4 // indirect
|
|
||||||
github.com/pelletier/go-toml v1.9.5 // indirect
|
github.com/pelletier/go-toml v1.9.5 // indirect
|
||||||
github.com/pelletier/go-toml/v2 v2.4.3 // indirect
|
github.com/pelletier/go-toml/v2 v2.2.4 // indirect
|
||||||
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
|
github.com/pmezard/go-difflib v1.0.0 // indirect
|
||||||
github.com/prometheus/common v0.70.1 // indirect
|
github.com/prometheus/common v0.67.5 // indirect
|
||||||
github.com/prometheus/procfs v0.21.1 // indirect
|
github.com/prometheus/procfs v0.20.1 // indirect
|
||||||
github.com/quasilyte/go-ruleguard v0.4.5 // indirect
|
github.com/quasilyte/go-ruleguard v0.4.5 // indirect
|
||||||
github.com/quasilyte/go-ruleguard/dsl v0.3.23 // indirect
|
github.com/quasilyte/go-ruleguard/dsl v0.3.23 // indirect
|
||||||
github.com/quasilyte/gogrep v0.5.0 // indirect
|
github.com/quasilyte/gogrep v0.5.0 // indirect
|
||||||
github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727 // indirect
|
github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727 // indirect
|
||||||
github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 // indirect
|
github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 // indirect
|
||||||
github.com/raeperd/recvcheck v0.3.0 // indirect
|
github.com/raeperd/recvcheck v0.2.0 // indirect
|
||||||
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
|
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
|
||||||
github.com/rivo/uniseg v0.4.7 // indirect
|
github.com/rivo/uniseg v0.4.7 // indirect
|
||||||
github.com/rogpeppe/go-internal v1.16.0 // indirect
|
github.com/rogpeppe/go-internal v1.14.1 // indirect
|
||||||
github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 // indirect
|
github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 // indirect
|
||||||
github.com/rubyist/circuitbreaker v2.2.1+incompatible // indirect
|
github.com/rubyist/circuitbreaker v2.2.1+incompatible // indirect
|
||||||
github.com/russross/blackfriday/v2 v2.1.0 // indirect
|
|
||||||
github.com/ryancurrah/gomodguard v1.4.1 // indirect
|
github.com/ryancurrah/gomodguard v1.4.1 // indirect
|
||||||
github.com/ryancurrah/gomodguard/v2 v2.1.3 // indirect
|
github.com/ryanrolds/sqlclosecheck v0.5.1 // indirect
|
||||||
github.com/ryanrolds/sqlclosecheck v0.6.0 // indirect
|
|
||||||
github.com/sanposhiho/wastedassign/v2 v2.1.0 // indirect
|
github.com/sanposhiho/wastedassign/v2 v2.1.0 // indirect
|
||||||
github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 // indirect
|
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 // indirect
|
||||||
github.com/sashamelentyev/interfacebloat v1.1.0 // indirect
|
github.com/sashamelentyev/interfacebloat v1.1.0 // indirect
|
||||||
github.com/sashamelentyev/usestdlibvars v1.29.0 // indirect
|
github.com/sashamelentyev/usestdlibvars v1.29.0 // indirect
|
||||||
github.com/securego/gosec/v2 v2.28.0 // indirect
|
github.com/securego/gosec/v2 v2.23.0 // indirect
|
||||||
github.com/sirupsen/logrus v1.10.1 // indirect
|
github.com/sirupsen/logrus v1.9.4 // indirect
|
||||||
github.com/sivchari/containedctx v1.0.3 // indirect
|
github.com/sivchari/containedctx v1.0.3 // indirect
|
||||||
github.com/sonatard/noctx v0.5.1 // indirect
|
github.com/sonatard/noctx v0.4.0 // indirect
|
||||||
github.com/sourcegraph/go-diff v0.8.0 // indirect
|
github.com/sourcegraph/go-diff v0.7.0 // indirect
|
||||||
github.com/spf13/afero v1.15.0 // indirect
|
github.com/spf13/afero v1.15.0 // indirect
|
||||||
github.com/spf13/cast v1.5.0 // indirect
|
github.com/spf13/cast v1.5.0 // indirect
|
||||||
github.com/spf13/cobra v1.10.2 // indirect
|
github.com/spf13/cobra v1.10.2 // indirect
|
||||||
|
|
@ -269,20 +227,19 @@ require (
|
||||||
github.com/spf13/viper v1.12.0 // indirect
|
github.com/spf13/viper v1.12.0 // indirect
|
||||||
github.com/ssgreg/nlreturn/v2 v2.2.1 // indirect
|
github.com/ssgreg/nlreturn/v2 v2.2.1 // indirect
|
||||||
github.com/stbenjam/no-sprintf-host-port v0.3.1 // indirect
|
github.com/stbenjam/no-sprintf-host-port v0.3.1 // indirect
|
||||||
github.com/stretchr/objx v0.5.3 // indirect
|
github.com/stretchr/objx v0.5.2 // indirect
|
||||||
github.com/stretchr/testify v1.12.1 // indirect
|
github.com/stretchr/testify v1.11.1 // indirect
|
||||||
github.com/subosito/gotenv v1.4.1 // indirect
|
github.com/subosito/gotenv v1.4.1 // indirect
|
||||||
github.com/tetafro/godot v1.5.6 // indirect
|
github.com/tetafro/godot v1.5.4 // indirect
|
||||||
github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4 // indirect
|
github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67 // indirect
|
||||||
github.com/timonwong/loggercheck v0.11.0 // indirect
|
github.com/timonwong/loggercheck v0.11.0 // indirect
|
||||||
github.com/tomarrell/wrapcheck/v2 v2.12.0 // indirect
|
github.com/tomarrell/wrapcheck/v2 v2.12.0 // indirect
|
||||||
github.com/tommy-muehle/go-mnd/v2 v2.5.1 // indirect
|
github.com/tommy-muehle/go-mnd/v2 v2.5.1 // indirect
|
||||||
github.com/ulikunitz/xz v0.5.16 // indirect
|
github.com/ulikunitz/xz v0.5.15 // indirect
|
||||||
github.com/ultraware/funlen v0.2.0 // indirect
|
github.com/ultraware/funlen v0.2.0 // indirect
|
||||||
github.com/ultraware/whitespace v0.2.0 // indirect
|
github.com/ultraware/whitespace v0.2.0 // indirect
|
||||||
github.com/urfave/cli/v2 v2.3.0 // indirect
|
github.com/uudashr/gocognit v1.2.0 // indirect
|
||||||
github.com/uudashr/gocognit v1.2.1 // indirect
|
github.com/uudashr/iface v1.4.1 // indirect
|
||||||
github.com/uudashr/iface v1.5.0 // indirect
|
|
||||||
github.com/xen0n/gosmopolitan v1.3.0 // indirect
|
github.com/xen0n/gosmopolitan v1.3.0 // indirect
|
||||||
github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect
|
github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect
|
||||||
github.com/yagipy/maintidx v1.0.0 // indirect
|
github.com/yagipy/maintidx v1.0.0 // indirect
|
||||||
|
|
@ -290,41 +247,40 @@ require (
|
||||||
github.com/ykadowak/zerologlint v0.1.5 // indirect
|
github.com/ykadowak/zerologlint v0.1.5 // indirect
|
||||||
gitlab.com/bosi/decorder v0.4.2 // indirect
|
gitlab.com/bosi/decorder v0.4.2 // indirect
|
||||||
go-simpler.org/musttag v0.14.0 // indirect
|
go-simpler.org/musttag v0.14.0 // indirect
|
||||||
go-simpler.org/sloglint v0.12.0 // indirect
|
go-simpler.org/sloglint v0.11.1 // indirect
|
||||||
go.augendre.info/arangolint v0.4.0 // indirect
|
go.augendre.info/arangolint v0.4.0 // indirect
|
||||||
go.augendre.info/fatcontext v0.10.0 // indirect
|
go.augendre.info/fatcontext v0.9.0 // indirect
|
||||||
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
|
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
|
||||||
go.opentelemetry.io/otel v1.44.0 // indirect
|
go.opentelemetry.io/otel v1.41.0 // indirect
|
||||||
go.opentelemetry.io/otel/metric v1.44.0 // indirect
|
go.opentelemetry.io/otel/metric v1.41.0 // indirect
|
||||||
go.opentelemetry.io/otel/sdk v1.44.0 // indirect
|
go.opentelemetry.io/otel/sdk v1.41.0 // indirect
|
||||||
go.opentelemetry.io/otel/sdk/metric v1.44.0 // indirect
|
go.opentelemetry.io/otel/sdk/metric v1.41.0 // indirect
|
||||||
go.opentelemetry.io/otel/trace v1.44.0 // indirect
|
go.opentelemetry.io/otel/trace v1.41.0 // indirect
|
||||||
go.uber.org/multierr v1.11.0 // indirect
|
go.uber.org/multierr v1.11.0 // indirect
|
||||||
go.uber.org/zap v1.27.1 // indirect
|
go.uber.org/zap v1.27.1 // indirect
|
||||||
go.yaml.in/yaml/v2 v2.4.4 // indirect
|
go.yaml.in/yaml/v2 v2.4.3 // indirect
|
||||||
go.yaml.in/yaml/v3 v3.0.5 // indirect
|
go.yaml.in/yaml/v3 v3.0.4 // indirect
|
||||||
golang.org/x/crypto v0.55.0 // indirect
|
|
||||||
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa // indirect
|
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa // indirect
|
||||||
golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f // indirect
|
golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358 // indirect
|
||||||
golang.org/x/mod v0.40.0 // indirect
|
golang.org/x/mod v0.33.0 // indirect
|
||||||
golang.org/x/net v0.58.0 // indirect
|
golang.org/x/net v0.51.0 // indirect
|
||||||
golang.org/x/oauth2 v0.36.0 // indirect
|
golang.org/x/sync v0.19.0 // indirect
|
||||||
golang.org/x/sys v0.47.0 // indirect
|
golang.org/x/sys v0.41.0 // indirect
|
||||||
golang.org/x/text v0.41.0 // indirect
|
golang.org/x/text v0.34.0 // indirect
|
||||||
golang.org/x/tools v0.49.0 // indirect
|
golang.org/x/tools v0.42.0 // indirect
|
||||||
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
|
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
|
||||||
google.golang.org/api v0.288.0 // indirect
|
google.golang.org/api v0.269.0 // indirect
|
||||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 // indirect
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20260226221140-a57be14db171 // indirect
|
||||||
google.golang.org/grpc v1.83.2 // indirect
|
google.golang.org/grpc v1.79.1 // indirect
|
||||||
|
google.golang.org/protobuf v1.36.11 // indirect
|
||||||
gopkg.in/ini.v1 v1.67.0 // indirect
|
gopkg.in/ini.v1 v1.67.0 // indirect
|
||||||
gopkg.in/yaml.v2 v2.4.0 // indirect
|
gopkg.in/yaml.v2 v2.4.0 // indirect
|
||||||
honnef.co/go/tools v0.8.0 // indirect
|
honnef.co/go/tools v0.7.0 // indirect
|
||||||
modernc.org/libc v1.75.6 // indirect
|
modernc.org/libc v1.69.0 // indirect
|
||||||
modernc.org/mathutil v1.7.1 // indirect
|
modernc.org/mathutil v1.7.1 // indirect
|
||||||
modernc.org/memory v1.12.1 // indirect
|
modernc.org/memory v1.11.0 // indirect
|
||||||
mvdan.cc/gofumpt v0.11.0 // indirect
|
mvdan.cc/gofumpt v0.9.2 // indirect
|
||||||
mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673 // indirect
|
mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15 // indirect
|
||||||
sigs.k8s.io/yaml v1.6.0 // indirect
|
|
||||||
)
|
)
|
||||||
|
|
||||||
tool github.com/golangci/golangci-lint/v2/cmd/golangci-lint
|
tool github.com/golangci/golangci-lint/v2/cmd/golangci-lint
|
||||||
|
|
|
||||||
|
|
@ -1,109 +0,0 @@
|
||||||
// Package accesslog writes proxy activity as JSON Lines.
|
|
||||||
package accesslog
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"encoding/json"
|
|
||||||
"fmt"
|
|
||||||
"net/url"
|
|
||||||
"os"
|
|
||||||
"sync"
|
|
||||||
"time"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
accessLogFileMode os.FileMode = 0o600
|
|
||||||
|
|
||||||
// EventRequest identifies the response sent by the proxy to a client.
|
|
||||||
EventRequest = "request"
|
|
||||||
// EventUpstream identifies one HTTP exchange with an upstream service.
|
|
||||||
EventUpstream = "upstream"
|
|
||||||
)
|
|
||||||
|
|
||||||
type requestIDKey struct{}
|
|
||||||
|
|
||||||
// Entry is one proxy activity record.
|
|
||||||
type Entry struct {
|
|
||||||
Time time.Time `json:"time"`
|
|
||||||
Event string `json:"event"`
|
|
||||||
RequestID string `json:"request_id,omitempty"`
|
|
||||||
Method string `json:"method"`
|
|
||||||
Path string `json:"path,omitempty"`
|
|
||||||
URL string `json:"url,omitempty"`
|
|
||||||
StatusCode int `json:"status_code,omitempty"`
|
|
||||||
DurationMS int64 `json:"duration_ms"`
|
|
||||||
RemoteAddr string `json:"remote_addr,omitempty"`
|
|
||||||
Error string `json:"error,omitempty"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// Logger appends complete JSON objects to a file, one per line.
|
|
||||||
type Logger struct {
|
|
||||||
mu sync.Mutex
|
|
||||||
file *os.File
|
|
||||||
encoder *json.Encoder
|
|
||||||
}
|
|
||||||
|
|
||||||
// Open opens path for append, creating it with owner-only permissions when needed.
|
|
||||||
func Open(path string) (*Logger, error) {
|
|
||||||
file, err := os.OpenFile(path, os.O_APPEND|os.O_CREATE|os.O_WRONLY, accessLogFileMode)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("opening access log: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return &Logger{
|
|
||||||
file: file,
|
|
||||||
encoder: json.NewEncoder(file),
|
|
||||||
}, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// Write appends an entry to the log.
|
|
||||||
func (l *Logger) Write(entry Entry) error {
|
|
||||||
if entry.Time.IsZero() {
|
|
||||||
entry.Time = time.Now().UTC()
|
|
||||||
}
|
|
||||||
|
|
||||||
l.mu.Lock()
|
|
||||||
defer l.mu.Unlock()
|
|
||||||
|
|
||||||
if err := l.encoder.Encode(entry); err != nil {
|
|
||||||
return fmt.Errorf("writing access log: %w", err)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// Close closes the log file after any active writer finishes.
|
|
||||||
func (l *Logger) Close() error {
|
|
||||||
l.mu.Lock()
|
|
||||||
defer l.mu.Unlock()
|
|
||||||
|
|
||||||
if err := l.file.Close(); err != nil {
|
|
||||||
return fmt.Errorf("closing access log: %w", err)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// WithRequestID stores a proxy request ID in ctx.
|
|
||||||
func WithRequestID(ctx context.Context, requestID string) context.Context {
|
|
||||||
return context.WithValue(ctx, requestIDKey{}, requestID)
|
|
||||||
}
|
|
||||||
|
|
||||||
// RequestID returns the proxy request ID stored in ctx.
|
|
||||||
func RequestID(ctx context.Context) string {
|
|
||||||
requestID, _ := ctx.Value(requestIDKey{}).(string)
|
|
||||||
return requestID
|
|
||||||
}
|
|
||||||
|
|
||||||
// URLWithoutSecrets returns a URL without user information, query values, or fragments.
|
|
||||||
func URLWithoutSecrets(value *url.URL) string {
|
|
||||||
if value == nil {
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
|
|
||||||
clean := *value
|
|
||||||
clean.User = nil
|
|
||||||
clean.RawQuery = ""
|
|
||||||
clean.ForceQuery = false
|
|
||||||
clean.Fragment = ""
|
|
||||||
clean.RawFragment = ""
|
|
||||||
return clean.String()
|
|
||||||
}
|
|
||||||
|
|
@ -1,91 +0,0 @@
|
||||||
package accesslog
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bufio"
|
|
||||||
"context"
|
|
||||||
"encoding/json"
|
|
||||||
"net/url"
|
|
||||||
"os"
|
|
||||||
"path/filepath"
|
|
||||||
"sync"
|
|
||||||
"testing"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestLoggerWritesJSONLines(t *testing.T) {
|
|
||||||
path := filepath.Join(t.TempDir(), "access.jsonl")
|
|
||||||
logger, err := Open(path)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
const entries = 20
|
|
||||||
var wg sync.WaitGroup
|
|
||||||
for range entries {
|
|
||||||
wg.Add(1)
|
|
||||||
go func() {
|
|
||||||
defer wg.Done()
|
|
||||||
if err := logger.Write(Entry{
|
|
||||||
Event: EventUpstream,
|
|
||||||
RequestID: "request-id",
|
|
||||||
Method: "GET",
|
|
||||||
URL: "https://registry.example/packages/example",
|
|
||||||
StatusCode: 429,
|
|
||||||
}); err != nil {
|
|
||||||
t.Errorf("Write: %v", err)
|
|
||||||
}
|
|
||||||
}()
|
|
||||||
}
|
|
||||||
wg.Wait()
|
|
||||||
|
|
||||||
if err := logger.Close(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
file, err := os.Open(path)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
defer func() { _ = file.Close() }()
|
|
||||||
|
|
||||||
scanner := bufio.NewScanner(file)
|
|
||||||
count := 0
|
|
||||||
for scanner.Scan() {
|
|
||||||
var entry Entry
|
|
||||||
if err := json.Unmarshal(scanner.Bytes(), &entry); err != nil {
|
|
||||||
t.Fatalf("line %d is not JSON: %v", count+1, err)
|
|
||||||
}
|
|
||||||
if entry.Time.IsZero() {
|
|
||||||
t.Errorf("line %d has no time", count+1)
|
|
||||||
}
|
|
||||||
if entry.StatusCode != 429 {
|
|
||||||
t.Errorf("line %d status_code = %d, want 429", count+1, entry.StatusCode)
|
|
||||||
}
|
|
||||||
count++
|
|
||||||
}
|
|
||||||
if err := scanner.Err(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if count != entries {
|
|
||||||
t.Errorf("lines = %d, want %d", count, entries)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestRequestID(t *testing.T) {
|
|
||||||
ctx := WithRequestID(context.Background(), "abc-123")
|
|
||||||
if got := RequestID(ctx); got != "abc-123" {
|
|
||||||
t.Errorf("RequestID = %q, want %q", got, "abc-123")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestURLWithoutSecrets(t *testing.T) {
|
|
||||||
value, err := url.Parse("https://user:password@registry.example/package.tgz?token=secret#fragment")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
got := URLWithoutSecrets(value)
|
|
||||||
want := "https://registry.example/package.tgz"
|
|
||||||
if got != want {
|
|
||||||
t.Errorf("URLWithoutSecrets = %q, want %q", got, want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load diff
File diff suppressed because it is too large
Load diff
|
|
@ -4,8 +4,8 @@ import (
|
||||||
"fmt"
|
"fmt"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"time"
|
|
||||||
|
|
||||||
|
gitpkgsdb "github.com/git-pkgs/git-pkgs/database"
|
||||||
"github.com/jmoiron/sqlx"
|
"github.com/jmoiron/sqlx"
|
||||||
_ "github.com/lib/pq"
|
_ "github.com/lib/pq"
|
||||||
_ "modernc.org/sqlite"
|
_ "modernc.org/sqlite"
|
||||||
|
|
@ -13,18 +13,6 @@ import (
|
||||||
|
|
||||||
const SchemaVersion = 1
|
const SchemaVersion = 1
|
||||||
|
|
||||||
const dirPermissions = 0755
|
|
||||||
|
|
||||||
// Postgres connection pool limits. database/sql keeps only two idle
|
|
||||||
// connections by default, which opens a new Postgres session for almost every
|
|
||||||
// request under load.
|
|
||||||
const (
|
|
||||||
postgresMaxOpenConns = 32
|
|
||||||
postgresMaxIdleConns = 32
|
|
||||||
postgresConnMaxIdleTime = 5 * time.Minute
|
|
||||||
postgresConnMaxLifetime = 30 * time.Minute
|
|
||||||
)
|
|
||||||
|
|
||||||
type Dialect string
|
type Dialect string
|
||||||
|
|
||||||
const (
|
const (
|
||||||
|
|
@ -42,10 +30,8 @@ func (db *DB) Dialect() Dialect {
|
||||||
return db.dialect
|
return db.dialect
|
||||||
}
|
}
|
||||||
|
|
||||||
func Exists(path string) bool {
|
// Exists checks if a database file exists at the given path.
|
||||||
_, err := os.Stat(path)
|
var Exists = gitpkgsdb.Exists
|
||||||
return err == nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func Create(path string) (*DB, error) {
|
func Create(path string) (*DB, error) {
|
||||||
if Exists(path) {
|
if Exists(path) {
|
||||||
|
|
@ -67,29 +53,21 @@ func Create(path string) (*DB, error) {
|
||||||
return db, nil
|
return db, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Open opens a SQLite database using the shared git-pkgs connection
|
||||||
|
// settings (WAL mode, busy timeout, single connection).
|
||||||
func Open(path string) (*DB, error) {
|
func Open(path string) (*DB, error) {
|
||||||
if dir := filepath.Dir(path); dir != "." && dir != "/" {
|
if dir := filepath.Dir(path); dir != "." && dir != "/" {
|
||||||
if err := os.MkdirAll(dir, dirPermissions); err != nil {
|
if err := os.MkdirAll(dir, 0755); err != nil {
|
||||||
return nil, fmt.Errorf("creating database directory: %w", err)
|
return nil, fmt.Errorf("creating database directory: %w", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Add busy_timeout to handle concurrent writes
|
sharedDB, err := gitpkgsdb.Open(path)
|
||||||
sqlDB, err := sqlx.Open("sqlite", path+"?_busy_timeout=5000")
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, fmt.Errorf("opening database: %w", err)
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
// Limit connections to 1 for SQLite to serialize writes
|
return &DB{DB: sharedDB.SQLX(), dialect: DialectSQLite, path: path}, nil
|
||||||
sqlDB.SetMaxOpenConns(1)
|
|
||||||
|
|
||||||
db := &DB{DB: sqlDB, dialect: DialectSQLite, path: path}
|
|
||||||
if err := db.OptimizeForReads(); err != nil {
|
|
||||||
_ = sqlDB.Close()
|
|
||||||
return nil, fmt.Errorf("optimizing database: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return db, nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func OpenOrCreate(path string) (*DB, error) {
|
func OpenOrCreate(path string) (*DB, error) {
|
||||||
|
|
@ -105,11 +83,6 @@ func OpenPostgres(url string) (*DB, error) {
|
||||||
return nil, fmt.Errorf("opening postgres database: %w", err)
|
return nil, fmt.Errorf("opening postgres database: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
sqlDB.SetMaxOpenConns(postgresMaxOpenConns)
|
|
||||||
sqlDB.SetMaxIdleConns(postgresMaxIdleConns)
|
|
||||||
sqlDB.SetConnMaxIdleTime(postgresConnMaxIdleTime)
|
|
||||||
sqlDB.SetConnMaxLifetime(postgresConnMaxLifetime)
|
|
||||||
|
|
||||||
if err := sqlDB.Ping(); err != nil {
|
if err := sqlDB.Ping(); err != nil {
|
||||||
_ = sqlDB.Close()
|
_ = sqlDB.Close()
|
||||||
return nil, fmt.Errorf("connecting to postgres: %w", err)
|
return nil, fmt.Errorf("connecting to postgres: %w", err)
|
||||||
|
|
|
||||||
|
|
@ -8,11 +8,6 @@ import (
|
||||||
"time"
|
"time"
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
|
||||||
testContentHash = "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
|
|
||||||
testIntegrity = "sha512-z4PhNX7vuL3xVChQ1m2AB9Yg5AULVxXcg/SpIdNs6c5H0NE8XYXysP+DGNKHfuwvY7kxvUdBeoGlODJ6+SfaPg=="
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestCreateAndOpen(t *testing.T) {
|
func TestCreateAndOpen(t *testing.T) {
|
||||||
dir := t.TempDir()
|
dir := t.TempDir()
|
||||||
dbPath := filepath.Join(dir, "test.db")
|
dbPath := filepath.Join(dir, "test.db")
|
||||||
|
|
@ -137,7 +132,7 @@ func TestVersionCRUD(t *testing.T) {
|
||||||
v := &Version{
|
v := &Version{
|
||||||
PURL: "pkg:npm/lodash@4.17.21",
|
PURL: "pkg:npm/lodash@4.17.21",
|
||||||
PackagePURL: "pkg:npm/lodash",
|
PackagePURL: "pkg:npm/lodash",
|
||||||
Integrity: sql.NullString{String: testIntegrity, Valid: true},
|
Integrity: sql.NullString{String: "sha512-abc123", Valid: true},
|
||||||
}
|
}
|
||||||
|
|
||||||
err = db.UpsertVersion(v)
|
err = db.UpsertVersion(v)
|
||||||
|
|
@ -152,8 +147,8 @@ func TestVersionCRUD(t *testing.T) {
|
||||||
if got == nil {
|
if got == nil {
|
||||||
t.Fatal("expected version, got nil")
|
t.Fatal("expected version, got nil")
|
||||||
}
|
}
|
||||||
if got.Version() != "4.17.21" {
|
if got.VersionString() != "4.17.21" {
|
||||||
t.Errorf("expected version 4.17.21, got %s", got.Version())
|
t.Errorf("expected version 4.17.21, got %s", got.VersionString())
|
||||||
}
|
}
|
||||||
|
|
||||||
versions, err := db.GetVersionsByPackagePURL("pkg:npm/lodash")
|
versions, err := db.GetVersionsByPackagePURL("pkg:npm/lodash")
|
||||||
|
|
@ -205,7 +200,7 @@ func TestArtifactCRUD(t *testing.T) {
|
||||||
t.Error("expected artifact to not be cached yet")
|
t.Error("expected artifact to not be cached yet")
|
||||||
}
|
}
|
||||||
|
|
||||||
err = db.MarkArtifactCached(versionPURL, "lodash-4.17.21.tgz", "/cache/npm/lodash-4.17.21.tgz", testContentHash, 12345, "application/gzip")
|
err = db.MarkArtifactCached(versionPURL, "lodash-4.17.21.tgz", "/cache/npm/lodash-4.17.21.tgz", "sha256-abc", 12345, "application/gzip")
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatalf("MarkArtifactCached failed: %v", err)
|
t.Fatalf("MarkArtifactCached failed: %v", err)
|
||||||
}
|
}
|
||||||
|
|
@ -244,92 +239,6 @@ func TestArtifactCRUD(t *testing.T) {
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGetCachedArtifact(t *testing.T) {
|
|
||||||
runWithBothDatabases(t, func(t *testing.T, db *DB) {
|
|
||||||
const (
|
|
||||||
packagePURL = "pkg:npm/lodash"
|
|
||||||
versionPURL = "pkg:npm/lodash@4.17.21"
|
|
||||||
filename = "lodash-4.17.21.tgz"
|
|
||||||
)
|
|
||||||
seedCachedArtifactTestData(t, db, packagePURL, versionPURL, filename)
|
|
||||||
|
|
||||||
cached, err := db.GetCachedArtifact(packagePURL, versionPURL, filename)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetCachedArtifact before cache failed: %v", err)
|
|
||||||
}
|
|
||||||
if cached != nil {
|
|
||||||
t.Fatalf("expected no cached artifact, got %+v", cached)
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := db.MarkArtifactCached(versionPURL, filename, "/cache/npm/"+filename,
|
|
||||||
testContentHash, 12345, "application/gzip"); err != nil {
|
|
||||||
t.Fatalf("MarkArtifactCached failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
cached, err = db.GetCachedArtifact(packagePURL, versionPURL, filename)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetCachedArtifact failed: %v", err)
|
|
||||||
}
|
|
||||||
if cached == nil {
|
|
||||||
t.Fatal("expected cached artifact, got nil")
|
|
||||||
}
|
|
||||||
if cached.Ecosystem != "npm" {
|
|
||||||
t.Errorf("expected npm ecosystem, got %q", cached.Ecosystem)
|
|
||||||
}
|
|
||||||
if cached.StoragePath != "/cache/npm/"+filename {
|
|
||||||
t.Errorf("expected cached storage path, got %q", cached.StoragePath)
|
|
||||||
}
|
|
||||||
if cached.Artifact.PURL != versionPURL {
|
|
||||||
t.Errorf("expected cached PURL %q, got %q", versionPURL, cached.Artifact.PURL)
|
|
||||||
}
|
|
||||||
if cached.Artifact.Digest.String() != "sha256:"+testContentHash {
|
|
||||||
t.Errorf("expected cached digest, got %q", cached.Artifact.Digest)
|
|
||||||
}
|
|
||||||
if cached.Artifact.Size != 12345 {
|
|
||||||
t.Errorf("expected cached size 12345, got %d", cached.Artifact.Size)
|
|
||||||
}
|
|
||||||
if cached.Artifact.Filename != filename {
|
|
||||||
t.Errorf("expected cached filename %q, got %q", filename, cached.Artifact.Filename)
|
|
||||||
}
|
|
||||||
if cached.Artifact.MediaType != "application/gzip" {
|
|
||||||
t.Errorf("expected cached content type, got %q", cached.Artifact.MediaType)
|
|
||||||
}
|
|
||||||
if cached.Integrity.String != testIntegrity {
|
|
||||||
t.Errorf("expected cached integrity, got %q", cached.Integrity.String)
|
|
||||||
}
|
|
||||||
|
|
||||||
cached, err = db.GetCachedArtifact("pkg:npm/other", versionPURL, filename)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetCachedArtifact with wrong package failed: %v", err)
|
|
||||||
}
|
|
||||||
if cached != nil {
|
|
||||||
t.Fatalf("expected package mismatch to miss cache, got %+v", cached)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func seedCachedArtifactTestData(t *testing.T, db *DB, packagePURL, versionPURL, filename string) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
if err := db.UpsertPackage(&Package{PURL: packagePURL, Ecosystem: "npm", Name: "lodash"}); err != nil {
|
|
||||||
t.Fatalf("UpsertPackage failed: %v", err)
|
|
||||||
}
|
|
||||||
if err := db.UpsertVersion(&Version{
|
|
||||||
PURL: versionPURL,
|
|
||||||
PackagePURL: packagePURL,
|
|
||||||
Integrity: sql.NullString{String: testIntegrity, Valid: true},
|
|
||||||
}); err != nil {
|
|
||||||
t.Fatalf("UpsertVersion failed: %v", err)
|
|
||||||
}
|
|
||||||
if err := db.UpsertArtifact(&Artifact{
|
|
||||||
VersionPURL: versionPURL,
|
|
||||||
Filename: filename,
|
|
||||||
UpstreamURL: "https://registry.npmjs.org/lodash/-/" + filename,
|
|
||||||
}); err != nil {
|
|
||||||
t.Fatalf("UpsertArtifact failed: %v", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestCacheManagement(t *testing.T) {
|
func TestCacheManagement(t *testing.T) {
|
||||||
runWithBothDatabases(t, func(t *testing.T, db *DB) {
|
runWithBothDatabases(t, func(t *testing.T, db *DB) {
|
||||||
pkg := &Package{
|
pkg := &Package{
|
||||||
|
|
@ -610,10 +519,8 @@ func createTestPostgresDB(t *testing.T) *DB {
|
||||||
t.Fatalf("OpenPostgres failed: %v", err)
|
t.Fatalf("OpenPostgres failed: %v", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Drop and recreate every table CreateSchema creates for clean test state;
|
// Drop and recreate tables for clean test state
|
||||||
// leftover migration records make the next CreateSchema fail on the
|
tables := []string{"artifacts", "versions", "packages", "schema_info"}
|
||||||
// migrations primary key.
|
|
||||||
tables := []string{"artifacts", "versions", "packages", "vulnerabilities", "metadata_cache", "migrations", "schema_info"}
|
|
||||||
for _, table := range tables {
|
for _, table := range tables {
|
||||||
_, _ = db.Exec("DROP TABLE IF EXISTS " + table + " CASCADE")
|
_, _ = db.Exec("DROP TABLE IF EXISTS " + table + " CASCADE")
|
||||||
}
|
}
|
||||||
|
|
@ -744,159 +651,58 @@ func TestMigrationFromOldSchema(t *testing.T) {
|
||||||
}
|
}
|
||||||
defer func() { _ = db.Close() }()
|
defer func() { _ = db.Close() }()
|
||||||
|
|
||||||
// Queries that require new columns should fail without migration
|
// Try to run queries that require new columns - these should fail without migration
|
||||||
if _, err := db.GetEnrichmentStats(); err == nil {
|
t.Run("queries should fail without migration", func(t *testing.T) {
|
||||||
t.Error("GetEnrichmentStats: expected error querying enriched_at column, got nil")
|
_, err := db.GetEnrichmentStats()
|
||||||
}
|
if err == nil {
|
||||||
if _, err := db.GetPackageByEcosystemName("npm", "test-package"); err == nil {
|
t.Error("GetEnrichmentStats: expected error querying enriched_at column, got nil")
|
||||||
t.Error("GetPackageByEcosystemName: expected error querying registry_url column, got nil")
|
}
|
||||||
}
|
|
||||||
// SearchPackages should work even with old schema because it uses sql.NullString
|
_, err = db.GetPackageByEcosystemName("npm", "test-package")
|
||||||
if _, err := db.SearchPackages("test", "", 10, 0); err != nil {
|
if err == nil {
|
||||||
t.Errorf("SearchPackages: unexpected error with old schema: %v", err)
|
t.Error("GetPackageByEcosystemName: expected error querying registry_url column, got nil")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// SearchPackages should work even with old schema because it uses sql.NullString
|
||||||
|
// for nullable columns, which can handle NULL values properly
|
||||||
|
_, err = db.SearchPackages("test", "", 10, 0)
|
||||||
|
if err != nil {
|
||||||
|
t.Errorf("SearchPackages: unexpected error with old schema: %v", err)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
// Run migration
|
// Run migration
|
||||||
if err := db.MigrateSchema(); err != nil {
|
t.Run("migrate schema", func(t *testing.T) {
|
||||||
t.Fatalf("MigrateSchema failed: %v", err)
|
if err := db.MigrateSchema(); err != nil {
|
||||||
}
|
t.Fatalf("MigrateSchema failed: %v", err)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
// Verify queries work after migration
|
// Verify queries work after migration
|
||||||
stats, err := db.GetEnrichmentStats()
|
t.Run("queries should work after migration", func(t *testing.T) {
|
||||||
if err != nil {
|
stats, err := db.GetEnrichmentStats()
|
||||||
t.Errorf("GetEnrichmentStats failed after migration: %v", err)
|
if err != nil {
|
||||||
}
|
t.Errorf("GetEnrichmentStats failed after migration: %v", err)
|
||||||
if stats == nil {
|
|
||||||
t.Error("GetEnrichmentStats returned nil after migration")
|
|
||||||
}
|
|
||||||
|
|
||||||
pkg, err := db.GetPackageByEcosystemName("npm", "test-package")
|
|
||||||
if err != nil {
|
|
||||||
t.Errorf("GetPackageByEcosystemName failed after migration: %v", err)
|
|
||||||
}
|
|
||||||
if pkg == nil {
|
|
||||||
t.Fatal("GetPackageByEcosystemName returned nil after migration")
|
|
||||||
}
|
|
||||||
if pkg.Name != "test-package" {
|
|
||||||
t.Errorf("expected package name test-package, got %s", pkg.Name)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Verify migrations were recorded
|
|
||||||
applied, err := db.appliedMigrations()
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("appliedMigrations failed: %v", err)
|
|
||||||
}
|
|
||||||
for _, m := range migrations {
|
|
||||||
if !applied[m.name] {
|
|
||||||
t.Errorf("migration %s not recorded as applied", m.name)
|
|
||||||
}
|
}
|
||||||
}
|
if stats == nil {
|
||||||
|
t.Error("GetEnrichmentStats returned nil after migration")
|
||||||
// Running again should be a no-op
|
|
||||||
if err := db.MigrateSchema(); err != nil {
|
|
||||||
t.Fatalf("second MigrateSchema failed: %v", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFreshDatabaseRecordsMigrations(t *testing.T) {
|
|
||||||
dir := t.TempDir()
|
|
||||||
dbPath := filepath.Join(dir, "fresh.db")
|
|
||||||
|
|
||||||
db, err := Create(dbPath)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Create failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = db.Close() }()
|
|
||||||
|
|
||||||
applied, err := db.appliedMigrations()
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("appliedMigrations failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, m := range migrations {
|
|
||||||
if !applied[m.name] {
|
|
||||||
t.Errorf("migration %s not recorded in fresh database", m.name)
|
|
||||||
}
|
}
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMigrateSchemaSkipsApplied(t *testing.T) {
|
pkg, err := db.GetPackageByEcosystemName("npm", "test-package")
|
||||||
dir := t.TempDir()
|
if err != nil {
|
||||||
dbPath := filepath.Join(dir, "test.db")
|
t.Errorf("GetPackageByEcosystemName failed after migration: %v", err)
|
||||||
|
}
|
||||||
db, err := Create(dbPath)
|
if pkg == nil {
|
||||||
if err != nil {
|
t.Fatal("GetPackageByEcosystemName returned nil after migration")
|
||||||
t.Fatalf("Create failed: %v", err)
|
}
|
||||||
}
|
if pkg.Name != "test-package" {
|
||||||
defer func() { _ = db.Close() }()
|
t.Errorf("expected package name test-package, got %s", pkg.Name)
|
||||||
|
|
||||||
// All migrations are already recorded from Create. Running MigrateSchema
|
|
||||||
// should return without running any migration functions.
|
|
||||||
if err := db.MigrateSchema(); err != nil {
|
|
||||||
t.Fatalf("MigrateSchema failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Verify count hasn't changed (no duplicate inserts)
|
|
||||||
var count int
|
|
||||||
if err := db.Get(&count, "SELECT COUNT(*) FROM migrations"); err != nil {
|
|
||||||
t.Fatalf("counting migrations failed: %v", err)
|
|
||||||
}
|
|
||||||
if count != len(migrations) {
|
|
||||||
t.Errorf("expected %d migrations, got %d", len(migrations), count)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMigrateSchemaUpgradeFromFullyMigrated(t *testing.T) {
|
|
||||||
dir := t.TempDir()
|
|
||||||
dbPath := filepath.Join(dir, "existing.db")
|
|
||||||
|
|
||||||
// Simulate an existing proxy database that has the full current schema
|
|
||||||
// but no migrations table (i.e. it was running the previous version).
|
|
||||||
sqlDB, err := sql.Open("sqlite", dbPath)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("failed to open database: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if _, err := sqlDB.Exec(schemaSQLite); err != nil {
|
|
||||||
t.Fatalf("failed to create schema: %v", err)
|
|
||||||
}
|
|
||||||
// Drop the migrations table that schemaSQLite now includes
|
|
||||||
if _, err := sqlDB.Exec("DROP TABLE migrations"); err != nil {
|
|
||||||
t.Fatalf("failed to drop migrations table: %v", err)
|
|
||||||
}
|
|
||||||
if _, err := sqlDB.Exec("INSERT INTO schema_info (version) VALUES (1)"); err != nil {
|
|
||||||
t.Fatalf("failed to set schema version: %v", err)
|
|
||||||
}
|
|
||||||
if err := sqlDB.Close(); err != nil {
|
|
||||||
t.Fatalf("failed to close database: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
db, err := Open(dbPath)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Open failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = db.Close() }()
|
|
||||||
|
|
||||||
// This should create the migrations table and record all migrations
|
|
||||||
// without altering any tables (everything already exists).
|
|
||||||
if err := db.MigrateSchema(); err != nil {
|
|
||||||
t.Fatalf("MigrateSchema failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
applied, err := db.appliedMigrations()
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("appliedMigrations failed: %v", err)
|
|
||||||
}
|
|
||||||
for _, m := range migrations {
|
|
||||||
if !applied[m.name] {
|
|
||||||
t.Errorf("migration %s not recorded after upgrade", m.name)
|
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
// Second run should be the fast path (single SELECT)
|
// Note: SearchPackages not tested here because old timestamp data
|
||||||
if err := db.MigrateSchema(); err != nil {
|
// stored as strings can't be scanned into time.Time. This is a data
|
||||||
t.Fatalf("second MigrateSchema failed: %v", err)
|
// migration issue, not a schema migration issue.
|
||||||
}
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestConcurrentWrites(t *testing.T) {
|
func TestConcurrentWrites(t *testing.T) {
|
||||||
|
|
@ -1084,79 +890,3 @@ func TestSearchPackagesWithValues(t *testing.T) {
|
||||||
t.Errorf("expected 10 hits, got %d", result.Hits)
|
t.Errorf("expected 10 hits, got %d", result.Hits)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func BenchmarkMigrateSchemaFullyMigrated(b *testing.B) {
|
|
||||||
dir := b.TempDir()
|
|
||||||
dbPath := filepath.Join(dir, "bench.db")
|
|
||||||
|
|
||||||
db, err := Create(dbPath)
|
|
||||||
if err != nil {
|
|
||||||
b.Fatalf("Create failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = db.Close() }()
|
|
||||||
|
|
||||||
// First call to ensure everything is migrated
|
|
||||||
if err := db.MigrateSchema(); err != nil {
|
|
||||||
b.Fatalf("initial MigrateSchema failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
b.ResetTimer()
|
|
||||||
for b.Loop() {
|
|
||||||
if err := db.MigrateSchema(); err != nil {
|
|
||||||
b.Fatalf("MigrateSchema failed: %v", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestVersionPublishedAtPreserved(t *testing.T) {
|
|
||||||
runWithBothDatabases(t, func(t *testing.T, db *DB) {
|
|
||||||
publishedAt := time.Date(2020, 1, 2, 3, 4, 5, 0, time.UTC)
|
|
||||||
|
|
||||||
if err := db.SetVersionPublishedAt("pkg:npm/leftpad@1.0.0", "pkg:npm/leftpad", publishedAt); err != nil {
|
|
||||||
t.Fatalf("SetVersionPublishedAt failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
got, err := db.GetVersionByPURL("pkg:npm/leftpad@1.0.0")
|
|
||||||
if err != nil || got == nil {
|
|
||||||
t.Fatalf("GetVersionByPURL failed: %v", err)
|
|
||||||
}
|
|
||||||
if !got.PublishedAt.Valid || !got.PublishedAt.Time.Equal(publishedAt) {
|
|
||||||
t.Fatalf("PublishedAt = %v, want %v", got.PublishedAt, publishedAt)
|
|
||||||
}
|
|
||||||
|
|
||||||
// An upsert that carries no publish time (the artifact cache path)
|
|
||||||
// must not erase the stored value.
|
|
||||||
if err := db.UpsertVersion(&Version{
|
|
||||||
PURL: "pkg:npm/leftpad@1.0.0",
|
|
||||||
PackagePURL: "pkg:npm/leftpad",
|
|
||||||
}); err != nil {
|
|
||||||
t.Fatalf("UpsertVersion failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
got, err = db.GetVersionByPURL("pkg:npm/leftpad@1.0.0")
|
|
||||||
if err != nil || got == nil {
|
|
||||||
t.Fatalf("GetVersionByPURL after upsert failed: %v", err)
|
|
||||||
}
|
|
||||||
if !got.PublishedAt.Valid || !got.PublishedAt.Time.Equal(publishedAt) {
|
|
||||||
t.Fatalf("PublishedAt after null upsert = %v, want %v preserved", got.PublishedAt, publishedAt)
|
|
||||||
}
|
|
||||||
|
|
||||||
// An upsert that does carry a publish time still updates it.
|
|
||||||
later := publishedAt.Add(24 * time.Hour)
|
|
||||||
if err := db.UpsertVersion(&Version{
|
|
||||||
PURL: "pkg:npm/leftpad@1.0.0",
|
|
||||||
PackagePURL: "pkg:npm/leftpad",
|
|
||||||
PublishedAt: sql.NullTime{Time: later, Valid: true},
|
|
||||||
}); err != nil {
|
|
||||||
t.Fatalf("UpsertVersion with publish time failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
got, err = db.GetVersionByPURL("pkg:npm/leftpad@1.0.0")
|
|
||||||
if err != nil || got == nil {
|
|
||||||
t.Fatalf("GetVersionByPURL after second upsert failed: %v", err)
|
|
||||||
}
|
|
||||||
if !got.PublishedAt.Valid || !got.PublishedAt.Time.Equal(later) {
|
|
||||||
t.Fatalf("PublishedAt after valued upsert = %v, want %v", got.PublishedAt, later)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
|
||||||
|
|
@ -1,364 +0,0 @@
|
||||||
package database
|
|
||||||
|
|
||||||
import (
|
|
||||||
"database/sql"
|
|
||||||
"path/filepath"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
)
|
|
||||||
|
|
||||||
func setupMetadataCacheDB(t *testing.T) *DB {
|
|
||||||
t.Helper()
|
|
||||||
dbPath := filepath.Join(t.TempDir(), "test.db")
|
|
||||||
db, err := Create(dbPath)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Create failed: %v", err)
|
|
||||||
}
|
|
||||||
if err := db.MigrateSchema(); err != nil {
|
|
||||||
t.Fatalf("MigrateSchema failed: %v", err)
|
|
||||||
}
|
|
||||||
t.Cleanup(func() { _ = db.Close() })
|
|
||||||
return db
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestUpsertAndGetMetadataCache(t *testing.T) {
|
|
||||||
db := setupMetadataCacheDB(t)
|
|
||||||
|
|
||||||
entry := &MetadataCacheEntry{
|
|
||||||
Ecosystem: testEcosystemNPM,
|
|
||||||
Name: "lodash",
|
|
||||||
StoragePath: "_metadata/npm/lodash/metadata",
|
|
||||||
ETag: sql.NullString{String: `"abc123"`, Valid: true},
|
|
||||||
Link: sql.NullString{String: `<https://registry.example.test/next>; rel="next"`, Valid: true},
|
|
||||||
ContentType: sql.NullString{String: "application/json", Valid: true},
|
|
||||||
ContentDigest: sql.NullString{
|
|
||||||
String: "sha256:0123456789abcdef",
|
|
||||||
Valid: true,
|
|
||||||
},
|
|
||||||
Size: sql.NullInt64{Int64: 1024, Valid: true},
|
|
||||||
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
|
||||||
}
|
|
||||||
|
|
||||||
err := db.UpsertMetadataCache(entry)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("UpsertMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
got, err := db.GetMetadataCache(testEcosystemNPM, "lodash")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
if got == nil {
|
|
||||||
t.Fatal("GetMetadataCache() returned nil")
|
|
||||||
}
|
|
||||||
|
|
||||||
if got.Ecosystem != testEcosystemNPM {
|
|
||||||
t.Errorf("ecosystem = %q, want %q", got.Ecosystem, testEcosystemNPM)
|
|
||||||
}
|
|
||||||
if got.Name != "lodash" {
|
|
||||||
t.Errorf("name = %q, want %q", got.Name, "lodash")
|
|
||||||
}
|
|
||||||
if got.StoragePath != "_metadata/npm/lodash/metadata" {
|
|
||||||
t.Errorf("storage_path = %q, want %q", got.StoragePath, "_metadata/npm/lodash/metadata")
|
|
||||||
}
|
|
||||||
if !got.ETag.Valid || got.ETag.String != `"abc123"` {
|
|
||||||
t.Errorf("etag = %v, want %q", got.ETag, `"abc123"`)
|
|
||||||
}
|
|
||||||
if !got.Link.Valid || got.Link.String != `<https://registry.example.test/next>; rel="next"` {
|
|
||||||
t.Errorf("link = %v, want next link", got.Link)
|
|
||||||
}
|
|
||||||
if !got.ContentType.Valid || got.ContentType.String != "application/json" {
|
|
||||||
t.Errorf("content_type = %v, want %q", got.ContentType, "application/json")
|
|
||||||
}
|
|
||||||
if !got.ContentDigest.Valid || got.ContentDigest.String != "sha256:0123456789abcdef" {
|
|
||||||
t.Errorf("content_digest = %v, want %q", got.ContentDigest, "sha256:0123456789abcdef")
|
|
||||||
}
|
|
||||||
if !got.Size.Valid || got.Size.Int64 != 1024 {
|
|
||||||
t.Errorf("size = %v, want 1024", got.Size)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGetMetadataCacheMiss(t *testing.T) {
|
|
||||||
db := setupMetadataCacheDB(t)
|
|
||||||
|
|
||||||
got, err := db.GetMetadataCache(testEcosystemNPM, "nonexistent")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
if got != nil {
|
|
||||||
t.Errorf("expected nil for cache miss, got %v", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestUpsertMetadataCacheOverwrite(t *testing.T) {
|
|
||||||
db := setupMetadataCacheDB(t)
|
|
||||||
|
|
||||||
// First insert
|
|
||||||
entry1 := &MetadataCacheEntry{
|
|
||||||
Ecosystem: testEcosystemNPM,
|
|
||||||
Name: "lodash",
|
|
||||||
StoragePath: "_metadata/npm/lodash/metadata",
|
|
||||||
ETag: sql.NullString{String: `"v1"`, Valid: true},
|
|
||||||
ContentType: sql.NullString{String: "application/json", Valid: true},
|
|
||||||
Size: sql.NullInt64{Int64: 100, Valid: true},
|
|
||||||
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
|
||||||
}
|
|
||||||
if err := db.UpsertMetadataCache(entry1); err != nil {
|
|
||||||
t.Fatalf("first UpsertMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Second insert (same ecosystem+name, different etag and size)
|
|
||||||
entry2 := &MetadataCacheEntry{
|
|
||||||
Ecosystem: testEcosystemNPM,
|
|
||||||
Name: "lodash",
|
|
||||||
StoragePath: "_metadata/npm/lodash/metadata",
|
|
||||||
ETag: sql.NullString{String: `"v2"`, Valid: true},
|
|
||||||
ContentType: sql.NullString{String: "application/json", Valid: true},
|
|
||||||
Size: sql.NullInt64{Int64: 200, Valid: true},
|
|
||||||
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
|
||||||
}
|
|
||||||
if err := db.UpsertMetadataCache(entry2); err != nil {
|
|
||||||
t.Fatalf("second UpsertMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
got, err := db.GetMetadataCache(testEcosystemNPM, "lodash")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
if got == nil {
|
|
||||||
t.Fatal("expected entry after overwrite")
|
|
||||||
}
|
|
||||||
if got.ETag.String != `"v2"` {
|
|
||||||
t.Errorf("etag = %q, want %q", got.ETag.String, `"v2"`)
|
|
||||||
}
|
|
||||||
if got.Size.Int64 != 200 {
|
|
||||||
t.Errorf("size = %d, want 200", got.Size.Int64)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestUpsertMetadataCacheNullableFields(t *testing.T) {
|
|
||||||
db := setupMetadataCacheDB(t)
|
|
||||||
|
|
||||||
entry := &MetadataCacheEntry{
|
|
||||||
Ecosystem: "pypi",
|
|
||||||
Name: "requests",
|
|
||||||
StoragePath: "_metadata/pypi/requests/metadata",
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := db.UpsertMetadataCache(entry); err != nil {
|
|
||||||
t.Fatalf("UpsertMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
got, err := db.GetMetadataCache("pypi", "requests")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
if got == nil {
|
|
||||||
t.Fatal("expected entry")
|
|
||||||
}
|
|
||||||
if got.ETag.Valid {
|
|
||||||
t.Error("expected null etag")
|
|
||||||
}
|
|
||||||
if got.ContentType.Valid {
|
|
||||||
t.Error("expected null content_type")
|
|
||||||
}
|
|
||||||
if got.Link.Valid {
|
|
||||||
t.Error("expected null link")
|
|
||||||
}
|
|
||||||
if got.Size.Valid {
|
|
||||||
t.Error("expected null size")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMetadataCacheTableCreatedByMigration(t *testing.T) {
|
|
||||||
// Create a DB without the metadata_cache table, then migrate
|
|
||||||
dbPath := filepath.Join(t.TempDir(), "test.db")
|
|
||||||
db, err := Create(dbPath)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Create failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = db.Close() }()
|
|
||||||
|
|
||||||
// MigrateSchema should create the metadata_cache table
|
|
||||||
if err := db.MigrateSchema(); err != nil {
|
|
||||||
t.Fatalf("MigrateSchema() error = %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
has, err := db.HasTable("metadata_cache")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("HasTable() error = %v", err)
|
|
||||||
}
|
|
||||||
if !has {
|
|
||||||
t.Error("metadata_cache table should exist after migration")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMetadataCacheContentDigestMigrationPreservesExistingRows(t *testing.T) {
|
|
||||||
dbPath := filepath.Join(t.TempDir(), "test.db")
|
|
||||||
db, err := Create(dbPath)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Create failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = db.Close() }()
|
|
||||||
|
|
||||||
if _, err := db.Exec("ALTER TABLE metadata_cache DROP COLUMN content_digest"); err != nil {
|
|
||||||
t.Fatalf("dropping content_digest: %v", err)
|
|
||||||
}
|
|
||||||
if _, err := db.Exec("DELETE FROM migrations WHERE name = ?", "006_add_metadata_content_digest"); err != nil {
|
|
||||||
t.Fatalf("resetting digest migration: %v", err)
|
|
||||||
}
|
|
||||||
if _, err := db.Exec(`
|
|
||||||
INSERT INTO metadata_cache (ecosystem, name, storage_path, content_type, size, fetched_at, created_at, updated_at)
|
|
||||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?)
|
|
||||||
`, "oci-manifest", "cache-key", "_metadata/oci-manifest/cache-key/metadata", "application/json", 2, time.Now(), time.Now(), time.Now()); err != nil {
|
|
||||||
t.Fatalf("inserting legacy cache row: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := db.MigrateSchema(); err != nil {
|
|
||||||
t.Fatalf("MigrateSchema() error = %v", err)
|
|
||||||
}
|
|
||||||
hasDigest, err := db.HasColumn("metadata_cache", "content_digest")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("HasColumn() error = %v", err)
|
|
||||||
}
|
|
||||||
if !hasDigest {
|
|
||||||
t.Fatal("metadata_cache.content_digest was not added")
|
|
||||||
}
|
|
||||||
|
|
||||||
entry, err := db.GetMetadataCache("oci-manifest", "cache-key")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
if entry == nil || entry.StoragePath != "_metadata/oci-manifest/cache-key/metadata" {
|
|
||||||
t.Fatalf("existing metadata cache row was not preserved: %#v", entry)
|
|
||||||
}
|
|
||||||
if entry.ContentDigest.Valid {
|
|
||||||
t.Errorf("legacy content digest = %q, want NULL", entry.ContentDigest.String)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMetadataCacheLinkMigrationPreservesExistingRows(t *testing.T) {
|
|
||||||
dbPath := filepath.Join(t.TempDir(), "test.db")
|
|
||||||
db, err := Create(dbPath)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Create failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = db.Close() }()
|
|
||||||
|
|
||||||
if _, err := db.Exec("ALTER TABLE metadata_cache DROP COLUMN link"); err != nil {
|
|
||||||
t.Fatalf("dropping link: %v", err)
|
|
||||||
}
|
|
||||||
if _, err := db.Exec("DELETE FROM migrations WHERE name = ?", "007_add_metadata_link"); err != nil {
|
|
||||||
t.Fatalf("resetting link migration: %v", err)
|
|
||||||
}
|
|
||||||
if _, err := db.Exec(`
|
|
||||||
INSERT INTO metadata_cache (ecosystem, name, storage_path, content_type, size, fetched_at, created_at, updated_at)
|
|
||||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?)
|
|
||||||
`, "oci-tags", "cache-key", "_metadata/oci-tags/cache-key/metadata", "application/json", 2, time.Now(), time.Now(), time.Now()); err != nil {
|
|
||||||
t.Fatalf("inserting legacy cache row: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := db.MigrateSchema(); err != nil {
|
|
||||||
t.Fatalf("MigrateSchema() error = %v", err)
|
|
||||||
}
|
|
||||||
hasLink, err := db.HasColumn("metadata_cache", "link")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("HasColumn() error = %v", err)
|
|
||||||
}
|
|
||||||
if !hasLink {
|
|
||||||
t.Fatal("metadata_cache.link was not added")
|
|
||||||
}
|
|
||||||
|
|
||||||
entry, err := db.GetMetadataCache("oci-tags", "cache-key")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
if entry == nil || entry.StoragePath != "_metadata/oci-tags/cache-key/metadata" {
|
|
||||||
t.Fatalf("existing metadata cache row was not preserved: %#v", entry)
|
|
||||||
}
|
|
||||||
if entry.Link.Valid {
|
|
||||||
t.Errorf("legacy link = %q, want NULL", entry.Link.String)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMetadataCacheContentEncodingMigrationPreservesExistingRows(t *testing.T) {
|
|
||||||
dbPath := filepath.Join(t.TempDir(), "test.db")
|
|
||||||
db, err := Create(dbPath)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Create failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = db.Close() }()
|
|
||||||
|
|
||||||
if _, err := db.Exec("ALTER TABLE metadata_cache DROP COLUMN content_encoding"); err != nil {
|
|
||||||
t.Fatalf("dropping content_encoding: %v", err)
|
|
||||||
}
|
|
||||||
if _, err := db.Exec("DELETE FROM migrations WHERE name = ?", "008_add_metadata_content_encoding"); err != nil {
|
|
||||||
t.Fatalf("resetting content_encoding migration: %v", err)
|
|
||||||
}
|
|
||||||
if _, err := db.Exec(`
|
|
||||||
INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, content_type, size, fetched_at, created_at, updated_at)
|
|
||||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?)
|
|
||||||
`, "apk", "cache-key", "_metadata/apk/cache-key/metadata", "\"legacy-etag\"", "application/octet-stream", 2, time.Now(), time.Now(), time.Now()); err != nil {
|
|
||||||
t.Fatalf("inserting legacy cache row: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := db.MigrateSchema(); err != nil {
|
|
||||||
t.Fatalf("MigrateSchema() error = %v", err)
|
|
||||||
}
|
|
||||||
hasEncoding, err := db.HasColumn("metadata_cache", "content_encoding")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("HasColumn() error = %v", err)
|
|
||||||
}
|
|
||||||
if !hasEncoding {
|
|
||||||
t.Fatal("metadata_cache.content_encoding was not added")
|
|
||||||
}
|
|
||||||
|
|
||||||
entry, err := db.GetMetadataCache("apk", "cache-key")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
if entry == nil || entry.StoragePath != "_metadata/apk/cache-key/metadata" {
|
|
||||||
t.Fatalf("existing metadata cache row was not preserved: %#v", entry)
|
|
||||||
}
|
|
||||||
if entry.ContentEncoding.Valid {
|
|
||||||
t.Errorf("legacy content encoding = %q, want NULL", entry.ContentEncoding.String)
|
|
||||||
}
|
|
||||||
// The migration must clear the pre-fix validators so the row is refetched
|
|
||||||
// once with identity instead of a 304 re-serving the decompressed copy.
|
|
||||||
if entry.ETag.Valid {
|
|
||||||
t.Errorf("legacy etag = %q, want cleared", entry.ETag.String)
|
|
||||||
}
|
|
||||||
if entry.FetchedAt.Valid {
|
|
||||||
t.Errorf("legacy fetched_at = %v, want cleared", entry.FetchedAt.Time)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMetadataCacheRoundTripsContentEncoding(t *testing.T) {
|
|
||||||
dbPath := filepath.Join(t.TempDir(), "test.db")
|
|
||||||
db, err := Create(dbPath)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Create failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = db.Close() }()
|
|
||||||
|
|
||||||
entry := &MetadataCacheEntry{
|
|
||||||
Ecosystem: "apk",
|
|
||||||
Name: "index-key",
|
|
||||||
StoragePath: "_metadata/apk/index-key/metadata",
|
|
||||||
ContentType: sql.NullString{String: "application/octet-stream", Valid: true},
|
|
||||||
ContentEncoding: sql.NullString{String: "gzip", Valid: true},
|
|
||||||
Size: sql.NullInt64{Int64: 10, Valid: true},
|
|
||||||
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
|
||||||
}
|
|
||||||
if err := db.UpsertMetadataCache(entry); err != nil {
|
|
||||||
t.Fatalf("UpsertMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
got, err := db.GetMetadataCache("apk", "index-key")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetMetadataCache() error = %v", err)
|
|
||||||
}
|
|
||||||
if got == nil || !got.ContentEncoding.Valid || got.ContentEncoding.String != "gzip" {
|
|
||||||
t.Fatalf("content encoding round-trip failed: %#v", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,57 +0,0 @@
|
||||||
package database
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"database/sql"
|
|
||||||
"os"
|
|
||||||
"testing"
|
|
||||||
)
|
|
||||||
|
|
||||||
// TestOpenPostgresKeepsConnectionsIdle checks the connection-count limits
|
|
||||||
// OpenPostgres sets: the open cap admits a burst of postgresMaxIdleConns
|
|
||||||
// connections, and releasing them again leaves all of them idle in the pool.
|
|
||||||
// database/sql's default keeps only two, so the next burst would open a new
|
|
||||||
// Postgres session for almost every request. The idle-time and lifetime
|
|
||||||
// settings are not exercised here.
|
|
||||||
func TestOpenPostgresKeepsConnectionsIdle(t *testing.T) {
|
|
||||||
url := os.Getenv("PROXY_DATABASE_URL")
|
|
||||||
if url == "" {
|
|
||||||
t.Skip("PROXY_DATABASE_URL not set, skipping postgres pool test")
|
|
||||||
}
|
|
||||||
|
|
||||||
db, err := OpenPostgres(url)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("OpenPostgres failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = db.Close() }()
|
|
||||||
|
|
||||||
const burst = postgresMaxIdleConns
|
|
||||||
// database/sql keeps two idle connections by default; a burst that small
|
|
||||||
// could not tell the tuned pool from the default one.
|
|
||||||
if burst <= 2 {
|
|
||||||
t.Fatalf("postgresMaxIdleConns = %d, want more than database/sql's default of 2", burst)
|
|
||||||
}
|
|
||||||
if got := db.Stats().MaxOpenConnections; got <= 0 || got < burst {
|
|
||||||
t.Fatalf("MaxOpenConnections = %d, want a cap of at least %d", got, burst)
|
|
||||||
}
|
|
||||||
|
|
||||||
conns := make([]*sql.Conn, 0, burst)
|
|
||||||
for range burst {
|
|
||||||
conn, err := db.Conn(context.Background())
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("taking connection %d: %v", len(conns)+1, err)
|
|
||||||
}
|
|
||||||
t.Cleanup(func() { _ = conn.Close() }) // release the session if an assertion below fails
|
|
||||||
conns = append(conns, conn)
|
|
||||||
}
|
|
||||||
if got := db.Stats().InUse; got != burst {
|
|
||||||
t.Fatalf("InUse = %d while holding %d connections", got, burst)
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, conn := range conns {
|
|
||||||
_ = conn.Close()
|
|
||||||
}
|
|
||||||
if got := db.Stats().Idle; got != burst {
|
|
||||||
t.Errorf("Idle = %d after releasing %d connections, want all of them kept", got, burst)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -4,9 +4,6 @@ import (
|
||||||
"database/sql"
|
"database/sql"
|
||||||
"fmt"
|
"fmt"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/git-pkgs/artifacts"
|
|
||||||
"github.com/opencontainers/go-digest"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// Package queries
|
// Package queries
|
||||||
|
|
@ -144,7 +141,7 @@ func (db *DB) UpsertVersion(v *Version) error {
|
||||||
ON CONFLICT(purl) DO UPDATE SET
|
ON CONFLICT(purl) DO UPDATE SET
|
||||||
license = EXCLUDED.license,
|
license = EXCLUDED.license,
|
||||||
integrity = EXCLUDED.integrity,
|
integrity = EXCLUDED.integrity,
|
||||||
published_at = COALESCE(EXCLUDED.published_at, versions.published_at),
|
published_at = EXCLUDED.published_at,
|
||||||
yanked = EXCLUDED.yanked,
|
yanked = EXCLUDED.yanked,
|
||||||
enriched_at = EXCLUDED.enriched_at,
|
enriched_at = EXCLUDED.enriched_at,
|
||||||
updated_at = EXCLUDED.updated_at
|
updated_at = EXCLUDED.updated_at
|
||||||
|
|
@ -157,7 +154,7 @@ func (db *DB) UpsertVersion(v *Version) error {
|
||||||
ON CONFLICT(purl) DO UPDATE SET
|
ON CONFLICT(purl) DO UPDATE SET
|
||||||
license = excluded.license,
|
license = excluded.license,
|
||||||
integrity = excluded.integrity,
|
integrity = excluded.integrity,
|
||||||
published_at = COALESCE(excluded.published_at, published_at),
|
published_at = excluded.published_at,
|
||||||
yanked = excluded.yanked,
|
yanked = excluded.yanked,
|
||||||
enriched_at = excluded.enriched_at,
|
enriched_at = excluded.enriched_at,
|
||||||
updated_at = excluded.updated_at
|
updated_at = excluded.updated_at
|
||||||
|
|
@ -174,38 +171,6 @@ func (db *DB) UpsertVersion(v *Version) error {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// SetVersionPublishedAt records a version's publish time, creating the
|
|
||||||
// versions row if the proxy has not seen the version yet. It only writes
|
|
||||||
// published_at, so it never disturbs enrichment data on an existing row.
|
|
||||||
func (db *DB) SetVersionPublishedAt(versionPURL, packagePURL string, publishedAt time.Time) error {
|
|
||||||
now := time.Now()
|
|
||||||
var query string
|
|
||||||
|
|
||||||
if db.dialect == DialectPostgres {
|
|
||||||
query = `
|
|
||||||
INSERT INTO versions (purl, package_purl, published_at, created_at, updated_at)
|
|
||||||
VALUES ($1, $2, $3, $4, $5)
|
|
||||||
ON CONFLICT(purl) DO UPDATE SET
|
|
||||||
published_at = EXCLUDED.published_at,
|
|
||||||
updated_at = EXCLUDED.updated_at
|
|
||||||
`
|
|
||||||
} else {
|
|
||||||
query = `
|
|
||||||
INSERT INTO versions (purl, package_purl, published_at, created_at, updated_at)
|
|
||||||
VALUES (?, ?, ?, ?, ?)
|
|
||||||
ON CONFLICT(purl) DO UPDATE SET
|
|
||||||
published_at = excluded.published_at,
|
|
||||||
updated_at = excluded.updated_at
|
|
||||||
`
|
|
||||||
}
|
|
||||||
|
|
||||||
_, err := db.Exec(query, versionPURL, packagePURL, publishedAt, now, now)
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("setting version publish time: %w", err)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// Artifact queries
|
// Artifact queries
|
||||||
|
|
||||||
func (db *DB) GetArtifact(versionPURL, filename string) (*Artifact, error) {
|
func (db *DB) GetArtifact(versionPURL, filename string) (*Artifact, error) {
|
||||||
|
|
@ -226,56 +191,6 @@ func (db *DB) GetArtifact(versionPURL, filename string) (*Artifact, error) {
|
||||||
return &a, nil
|
return &a, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// GetCachedArtifact returns the fields needed to serve a cached artifact.
|
|
||||||
func (db *DB) GetCachedArtifact(packagePURL, versionPURL, filename string) (*CachedArtifact, error) {
|
|
||||||
var row cachedArtifactRow
|
|
||||||
query := db.Rebind(`
|
|
||||||
SELECT packages.ecosystem, artifacts.storage_path, artifacts.content_hash, artifacts.size,
|
|
||||||
artifacts.content_type, versions.integrity
|
|
||||||
FROM artifacts
|
|
||||||
JOIN versions ON versions.purl = artifacts.version_purl
|
|
||||||
JOIN packages ON packages.purl = versions.package_purl
|
|
||||||
WHERE packages.purl = ? AND artifacts.version_purl = ? AND artifacts.filename = ?
|
|
||||||
AND artifacts.storage_path IS NOT NULL AND artifacts.fetched_at IS NOT NULL
|
|
||||||
`)
|
|
||||||
err := db.Get(&row, query, packagePURL, versionPURL, filename)
|
|
||||||
if err == sql.ErrNoRows {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
return row.artifact(versionPURL, filename), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
type cachedArtifactRow struct {
|
|
||||||
Ecosystem string `db:"ecosystem"`
|
|
||||||
StoragePath string `db:"storage_path"`
|
|
||||||
ContentHash sql.NullString `db:"content_hash"`
|
|
||||||
Size sql.NullInt64 `db:"size"`
|
|
||||||
ContentType sql.NullString `db:"content_type"`
|
|
||||||
Integrity sql.NullString `db:"integrity"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// artifact converts a cached artifact row to a CachedArtifact without
|
|
||||||
// validation. A malformed hash or integrity value is handled by
|
|
||||||
// checkCache, which clears the record and treats the request as a cache
|
|
||||||
// miss so the client is served a fresh fetch instead of an error.
|
|
||||||
func (row cachedArtifactRow) artifact(versionPURL, filename string) *CachedArtifact {
|
|
||||||
return &CachedArtifact{
|
|
||||||
Ecosystem: row.Ecosystem,
|
|
||||||
StoragePath: row.StoragePath,
|
|
||||||
Integrity: row.Integrity,
|
|
||||||
Artifact: artifacts.Artifact{
|
|
||||||
PURL: versionPURL,
|
|
||||||
Digest: digest.Digest("sha256:" + row.ContentHash.String),
|
|
||||||
Size: row.Size.Int64,
|
|
||||||
Filename: filename,
|
|
||||||
MediaType: row.ContentType.String,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (db *DB) GetArtifactByPath(storagePath string) (*Artifact, error) {
|
func (db *DB) GetArtifactByPath(storagePath string) (*Artifact, error) {
|
||||||
var a Artifact
|
var a Artifact
|
||||||
query := db.Rebind(`
|
query := db.Rebind(`
|
||||||
|
|
@ -528,14 +443,11 @@ func (db *DB) GetMostPopularPackages(limit int) ([]PopularPackage, error) {
|
||||||
}
|
}
|
||||||
|
|
||||||
type RecentPackage struct {
|
type RecentPackage struct {
|
||||||
Ecosystem string `db:"ecosystem"`
|
Ecosystem string `db:"ecosystem"`
|
||||||
Name string `db:"name"`
|
Name string `db:"name"`
|
||||||
VersionPURL string `db:"version_purl"`
|
Version string `db:"version"`
|
||||||
CachedAt time.Time `db:"fetched_at"`
|
CachedAt time.Time `db:"fetched_at"`
|
||||||
Size int64 `db:"size"`
|
Size int64 `db:"size"`
|
||||||
// Version is derived from VersionPURL rather than selected, so that the
|
|
||||||
// PURL percent-encoding is decoded (e.g. "%2B" back to "+").
|
|
||||||
Version string `db:"-"`
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) {
|
func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) {
|
||||||
|
|
@ -549,10 +461,10 @@ func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) {
|
||||||
}
|
}
|
||||||
|
|
||||||
var packages []RecentPackage
|
var packages []RecentPackage
|
||||||
// There is no separate version column, so the full version PURL is selected
|
// We need to extract version from the purl since there's no separate version column
|
||||||
// and the version is decoded from it in Go.
|
|
||||||
query := db.Rebind(`
|
query := db.Rebind(`
|
||||||
SELECT p.ecosystem, p.name, v.purl as version_purl,
|
SELECT p.ecosystem, p.name,
|
||||||
|
SUBSTR(v.purl, INSTR(v.purl, '@') + 1) as version,
|
||||||
a.fetched_at, COALESCE(a.size, 0) as size
|
a.fetched_at, COALESCE(a.size, 0) as size
|
||||||
FROM artifacts a
|
FROM artifacts a
|
||||||
JOIN versions v ON v.purl = a.version_purl
|
JOIN versions v ON v.purl = a.version_purl
|
||||||
|
|
@ -562,13 +474,25 @@ func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) {
|
||||||
LIMIT ?
|
LIMIT ?
|
||||||
`)
|
`)
|
||||||
|
|
||||||
|
// For postgres, use different string function
|
||||||
|
if db.dialect == DialectPostgres {
|
||||||
|
query = db.Rebind(`
|
||||||
|
SELECT p.ecosystem, p.name,
|
||||||
|
SUBSTRING(v.purl FROM POSITION('@' IN v.purl) + 1) as version,
|
||||||
|
a.fetched_at, COALESCE(a.size, 0) as size
|
||||||
|
FROM artifacts a
|
||||||
|
JOIN versions v ON v.purl = a.version_purl
|
||||||
|
JOIN packages p ON p.purl = v.package_purl
|
||||||
|
WHERE a.storage_path IS NOT NULL AND a.fetched_at IS NOT NULL
|
||||||
|
ORDER BY a.fetched_at DESC
|
||||||
|
LIMIT ?
|
||||||
|
`)
|
||||||
|
}
|
||||||
|
|
||||||
err = db.Select(&packages, query, limit)
|
err = db.Select(&packages, query, limit)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
for i := range packages {
|
|
||||||
packages[i].Version = VersionFromPURL(packages[i].VersionPURL)
|
|
||||||
}
|
|
||||||
return packages, nil
|
return packages, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -963,72 +887,3 @@ func (db *DB) CountCachedPackages(ecosystem string) (int64, error) {
|
||||||
err = db.Get(&count, query, args...)
|
err = db.Get(&count, query, args...)
|
||||||
return count, err
|
return count, err
|
||||||
}
|
}
|
||||||
|
|
||||||
// Metadata cache queries
|
|
||||||
|
|
||||||
func (db *DB) GetMetadataCache(ecosystem, name string) (*MetadataCacheEntry, error) {
|
|
||||||
var entry MetadataCacheEntry
|
|
||||||
query := db.Rebind(`
|
|
||||||
SELECT id, ecosystem, name, storage_path, etag, link, content_type, content_encoding,
|
|
||||||
content_digest, size, last_modified, fetched_at, created_at, updated_at
|
|
||||||
FROM metadata_cache WHERE ecosystem = ? AND name = ?
|
|
||||||
`)
|
|
||||||
err := db.Get(&entry, query, ecosystem, name)
|
|
||||||
if err == sql.ErrNoRows {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
return &entry, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (db *DB) UpsertMetadataCache(entry *MetadataCacheEntry) error {
|
|
||||||
now := time.Now()
|
|
||||||
var query string
|
|
||||||
|
|
||||||
if db.dialect == DialectPostgres {
|
|
||||||
query = `
|
|
||||||
INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, link, content_type, content_encoding,
|
|
||||||
content_digest, size, last_modified, fetched_at, created_at, updated_at)
|
|
||||||
VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13)
|
|
||||||
ON CONFLICT(ecosystem, name) DO UPDATE SET
|
|
||||||
storage_path = EXCLUDED.storage_path,
|
|
||||||
etag = EXCLUDED.etag,
|
|
||||||
link = EXCLUDED.link,
|
|
||||||
content_type = EXCLUDED.content_type,
|
|
||||||
content_encoding = EXCLUDED.content_encoding,
|
|
||||||
content_digest = EXCLUDED.content_digest,
|
|
||||||
size = EXCLUDED.size,
|
|
||||||
last_modified = EXCLUDED.last_modified,
|
|
||||||
fetched_at = EXCLUDED.fetched_at,
|
|
||||||
updated_at = EXCLUDED.updated_at
|
|
||||||
`
|
|
||||||
} else {
|
|
||||||
query = `
|
|
||||||
INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, link, content_type, content_encoding,
|
|
||||||
content_digest, size, last_modified, fetched_at, created_at, updated_at)
|
|
||||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
|
|
||||||
ON CONFLICT(ecosystem, name) DO UPDATE SET
|
|
||||||
storage_path = excluded.storage_path,
|
|
||||||
etag = excluded.etag,
|
|
||||||
link = excluded.link,
|
|
||||||
content_type = excluded.content_type,
|
|
||||||
content_encoding = excluded.content_encoding,
|
|
||||||
content_digest = excluded.content_digest,
|
|
||||||
size = excluded.size,
|
|
||||||
last_modified = excluded.last_modified,
|
|
||||||
fetched_at = excluded.fetched_at,
|
|
||||||
updated_at = excluded.updated_at
|
|
||||||
`
|
|
||||||
}
|
|
||||||
|
|
||||||
_, err := db.Exec(query,
|
|
||||||
entry.Ecosystem, entry.Name, entry.StoragePath, entry.ETag, entry.Link,
|
|
||||||
entry.ContentType, entry.ContentEncoding, entry.ContentDigest, entry.Size, entry.LastModified, entry.FetchedAt, now, now,
|
|
||||||
)
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("upserting metadata cache: %w", err)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
|
||||||
|
|
@ -6,121 +6,118 @@ import (
|
||||||
"time"
|
"time"
|
||||||
)
|
)
|
||||||
|
|
||||||
const testEcosystemNPM = "npm"
|
func TestListCachedPackages(t *testing.T) {
|
||||||
|
|
||||||
func setupListCachedPackagesDB(t *testing.T) *DB {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
db, err := Create(t.TempDir() + "/test.db")
|
db, err := Create(t.TempDir() + "/test.db")
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
||||||
seedListCachedPackagesData(t, db)
|
|
||||||
|
|
||||||
return db
|
|
||||||
}
|
|
||||||
|
|
||||||
func seedListCachedPackagesData(t *testing.T, db *DB) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
packages := []*Package{
|
|
||||||
{
|
|
||||||
PURL: "pkg:npm/lodash",
|
|
||||||
Ecosystem: testEcosystemNPM,
|
|
||||||
Name: "lodash",
|
|
||||||
LatestVersion: sql.NullString{String: "4.17.21", Valid: true},
|
|
||||||
License: sql.NullString{String: "MIT", Valid: true},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
PURL: "pkg:cargo/serde",
|
|
||||||
Ecosystem: "cargo",
|
|
||||||
Name: "serde",
|
|
||||||
LatestVersion: sql.NullString{String: "1.0.0", Valid: true},
|
|
||||||
License: sql.NullString{String: "MIT OR Apache-2.0", Valid: true},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
PURL: "pkg:npm/react",
|
|
||||||
Ecosystem: testEcosystemNPM,
|
|
||||||
Name: "react",
|
|
||||||
LatestVersion: sql.NullString{String: "18.0.0", Valid: true},
|
|
||||||
License: sql.NullString{String: "MIT", Valid: true},
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, pkg := range packages {
|
|
||||||
if err := db.UpsertPackage(pkg); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
versions := []*Version{
|
|
||||||
{PURL: "pkg:npm/lodash@4.17.21", PackagePURL: packages[0].PURL},
|
|
||||||
{PURL: "pkg:cargo/serde@1.0.0", PackagePURL: packages[1].PURL},
|
|
||||||
{PURL: "pkg:npm/react@18.0.0", PackagePURL: packages[2].PURL},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, ver := range versions {
|
|
||||||
if err := db.UpsertVersion(ver); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
artifacts := []*Artifact{
|
|
||||||
{
|
|
||||||
VersionPURL: versions[0].PURL,
|
|
||||||
Filename: "lodash.tgz",
|
|
||||||
UpstreamURL: "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz",
|
|
||||||
StoragePath: sql.NullString{String: "npm/lodash/4.17.21/lodash.tgz", Valid: true},
|
|
||||||
Size: sql.NullInt64{Int64: 1024, Valid: true},
|
|
||||||
HitCount: 100,
|
|
||||||
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
VersionPURL: versions[1].PURL,
|
|
||||||
Filename: "serde.crate",
|
|
||||||
UpstreamURL: "https://crates.io/api/v1/crates/serde/1.0.0/download",
|
|
||||||
StoragePath: sql.NullString{String: "cargo/serde/1.0.0/serde.crate", Valid: true},
|
|
||||||
Size: sql.NullInt64{Int64: 2048, Valid: true},
|
|
||||||
HitCount: 50,
|
|
||||||
FetchedAt: sql.NullTime{Time: time.Now().Add(-1 * time.Hour), Valid: true},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
VersionPURL: versions[2].PURL,
|
|
||||||
Filename: "react.tgz",
|
|
||||||
UpstreamURL: "https://registry.npmjs.org/react/-/react-18.0.0.tgz",
|
|
||||||
StoragePath: sql.NullString{String: "npm/react/18.0.0/react.tgz", Valid: true},
|
|
||||||
Size: sql.NullInt64{Int64: 512, Valid: true},
|
|
||||||
HitCount: 200,
|
|
||||||
FetchedAt: sql.NullTime{Time: time.Now().Add(-2 * time.Hour), Valid: true},
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, art := range artifacts {
|
|
||||||
if err := db.UpsertArtifact(art); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestListCachedPackages(t *testing.T) {
|
|
||||||
db := setupListCachedPackagesDB(t)
|
|
||||||
defer func() { _ = db.Close() }()
|
defer func() { _ = db.Close() }()
|
||||||
|
|
||||||
listAll := func(ecosystem, sortBy string) []PackageListItem {
|
// Create test packages
|
||||||
t.Helper()
|
pkg1 := &Package{
|
||||||
packages, err := db.ListCachedPackages(ecosystem, sortBy, 10, 0)
|
PURL: "pkg:npm/lodash",
|
||||||
if err != nil {
|
Ecosystem: "npm",
|
||||||
t.Fatal(err)
|
Name: "lodash",
|
||||||
}
|
LatestVersion: sql.NullString{String: "4.17.21", Valid: true},
|
||||||
return packages
|
License: sql.NullString{String: "MIT", Valid: true},
|
||||||
|
}
|
||||||
|
pkg2 := &Package{
|
||||||
|
PURL: "pkg:cargo/serde",
|
||||||
|
Ecosystem: "cargo",
|
||||||
|
Name: "serde",
|
||||||
|
LatestVersion: sql.NullString{String: "1.0.0", Valid: true},
|
||||||
|
License: sql.NullString{String: "MIT OR Apache-2.0", Valid: true},
|
||||||
|
}
|
||||||
|
pkg3 := &Package{
|
||||||
|
PURL: "pkg:npm/react",
|
||||||
|
Ecosystem: "npm",
|
||||||
|
Name: "react",
|
||||||
|
LatestVersion: sql.NullString{String: "18.0.0", Valid: true},
|
||||||
|
License: sql.NullString{String: "MIT", Valid: true},
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := db.UpsertPackage(pkg1); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := db.UpsertPackage(pkg2); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := db.UpsertPackage(pkg3); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Create versions
|
||||||
|
ver1 := &Version{
|
||||||
|
PURL: "pkg:npm/lodash@4.17.21",
|
||||||
|
PackagePURL: pkg1.PURL,
|
||||||
|
}
|
||||||
|
ver2 := &Version{
|
||||||
|
PURL: "pkg:cargo/serde@1.0.0",
|
||||||
|
PackagePURL: pkg2.PURL,
|
||||||
|
}
|
||||||
|
ver3 := &Version{
|
||||||
|
PURL: "pkg:npm/react@18.0.0",
|
||||||
|
PackagePURL: pkg3.PURL,
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := db.UpsertVersion(ver1); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := db.UpsertVersion(ver2); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := db.UpsertVersion(ver3); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Create artifacts
|
||||||
|
art1 := &Artifact{
|
||||||
|
VersionPURL: ver1.PURL,
|
||||||
|
Filename: "lodash.tgz",
|
||||||
|
UpstreamURL: "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz",
|
||||||
|
StoragePath: sql.NullString{String: "npm/lodash/4.17.21/lodash.tgz", Valid: true},
|
||||||
|
Size: sql.NullInt64{Int64: 1024, Valid: true},
|
||||||
|
HitCount: 100,
|
||||||
|
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
||||||
|
}
|
||||||
|
art2 := &Artifact{
|
||||||
|
VersionPURL: ver2.PURL,
|
||||||
|
Filename: "serde.crate",
|
||||||
|
UpstreamURL: "https://crates.io/api/v1/crates/serde/1.0.0/download",
|
||||||
|
StoragePath: sql.NullString{String: "cargo/serde/1.0.0/serde.crate", Valid: true},
|
||||||
|
Size: sql.NullInt64{Int64: 2048, Valid: true},
|
||||||
|
HitCount: 50,
|
||||||
|
FetchedAt: sql.NullTime{Time: time.Now().Add(-1 * time.Hour), Valid: true},
|
||||||
|
}
|
||||||
|
art3 := &Artifact{
|
||||||
|
VersionPURL: ver3.PURL,
|
||||||
|
Filename: "react.tgz",
|
||||||
|
UpstreamURL: "https://registry.npmjs.org/react/-/react-18.0.0.tgz",
|
||||||
|
StoragePath: sql.NullString{String: "npm/react/18.0.0/react.tgz", Valid: true},
|
||||||
|
Size: sql.NullInt64{Int64: 512, Valid: true},
|
||||||
|
HitCount: 200,
|
||||||
|
FetchedAt: sql.NullTime{Time: time.Now().Add(-2 * time.Hour), Valid: true},
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := db.UpsertArtifact(art1); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := db.UpsertArtifact(art2); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := db.UpsertArtifact(art3); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
||||||
t.Run("list all packages", func(t *testing.T) {
|
t.Run("list all packages", func(t *testing.T) {
|
||||||
packages := listAll("", "hits")
|
packages, err := db.ListCachedPackages("", "hits", 10, 0)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
if len(packages) != 3 {
|
if len(packages) != 3 {
|
||||||
t.Errorf("expected 3 packages, got %d", len(packages))
|
t.Errorf("expected 3 packages, got %d", len(packages))
|
||||||
}
|
}
|
||||||
|
// Should be sorted by hits DESC
|
||||||
if packages[0].Name != "react" {
|
if packages[0].Name != "react" {
|
||||||
t.Errorf("expected first package to be react, got %s", packages[0].Name)
|
t.Errorf("expected first package to be react, got %s", packages[0].Name)
|
||||||
}
|
}
|
||||||
|
|
@ -130,26 +127,35 @@ func TestListCachedPackages(t *testing.T) {
|
||||||
})
|
})
|
||||||
|
|
||||||
t.Run("filter by ecosystem", func(t *testing.T) {
|
t.Run("filter by ecosystem", func(t *testing.T) {
|
||||||
packages := listAll(testEcosystemNPM, "hits")
|
packages, err := db.ListCachedPackages("npm", "hits", 10, 0)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
if len(packages) != 2 {
|
if len(packages) != 2 {
|
||||||
t.Errorf("expected 2 npm packages, got %d", len(packages))
|
t.Errorf("expected 2 npm packages, got %d", len(packages))
|
||||||
}
|
}
|
||||||
for _, pkg := range packages {
|
for _, pkg := range packages {
|
||||||
if pkg.Ecosystem != testEcosystemNPM {
|
if pkg.Ecosystem != "npm" {
|
||||||
t.Errorf("expected npm ecosystem, got %s", pkg.Ecosystem)
|
t.Errorf("expected npm ecosystem, got %s", pkg.Ecosystem)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
|
|
||||||
t.Run("sort by name", func(t *testing.T) {
|
t.Run("sort by name", func(t *testing.T) {
|
||||||
packages := listAll("", "name")
|
packages, err := db.ListCachedPackages("", "name", 10, 0)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
if packages[0].Name != "lodash" {
|
if packages[0].Name != "lodash" {
|
||||||
t.Errorf("expected first package to be lodash, got %s", packages[0].Name)
|
t.Errorf("expected first package to be lodash, got %s", packages[0].Name)
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
|
|
||||||
t.Run("sort by size", func(t *testing.T) {
|
t.Run("sort by size", func(t *testing.T) {
|
||||||
packages := listAll("", "size")
|
packages, err := db.ListCachedPackages("", "size", 10, 0)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
if packages[0].Name != "serde" {
|
if packages[0].Name != "serde" {
|
||||||
t.Errorf("expected first package to be serde (largest), got %s", packages[0].Name)
|
t.Errorf("expected first package to be serde (largest), got %s", packages[0].Name)
|
||||||
}
|
}
|
||||||
|
|
@ -164,7 +170,7 @@ func TestListCachedPackages(t *testing.T) {
|
||||||
t.Errorf("expected count 3, got %d", count)
|
t.Errorf("expected count 3, got %d", count)
|
||||||
}
|
}
|
||||||
|
|
||||||
count, err = db.CountCachedPackages(testEcosystemNPM)
|
count, err = db.CountCachedPackages("npm")
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -1,16 +1,6 @@
|
||||||
package database
|
package database
|
||||||
|
|
||||||
import (
|
import "fmt"
|
||||||
"fmt"
|
|
||||||
"strings"
|
|
||||||
"time"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
postgresTimestamp = "TIMESTAMP"
|
|
||||||
sqliteDatetime = "DATETIME"
|
|
||||||
colTypeText = "TEXT"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Schema for proxy-specific tables. The packages and versions tables
|
// Schema for proxy-specific tables. The packages and versions tables
|
||||||
// are compatible with git-pkgs, allowing the proxy to use an existing
|
// are compatible with git-pkgs, allowing the proxy to use an existing
|
||||||
|
|
@ -94,29 +84,6 @@ CREATE TABLE IF NOT EXISTS vulnerabilities (
|
||||||
);
|
);
|
||||||
CREATE UNIQUE INDEX IF NOT EXISTS idx_vulns_id_pkg ON vulnerabilities(vuln_id, ecosystem, package_name);
|
CREATE UNIQUE INDEX IF NOT EXISTS idx_vulns_id_pkg ON vulnerabilities(vuln_id, ecosystem, package_name);
|
||||||
CREATE INDEX IF NOT EXISTS idx_vulns_ecosystem_pkg ON vulnerabilities(ecosystem, package_name);
|
CREATE INDEX IF NOT EXISTS idx_vulns_ecosystem_pkg ON vulnerabilities(ecosystem, package_name);
|
||||||
|
|
||||||
CREATE TABLE IF NOT EXISTS metadata_cache (
|
|
||||||
id INTEGER PRIMARY KEY,
|
|
||||||
ecosystem TEXT NOT NULL,
|
|
||||||
name TEXT NOT NULL,
|
|
||||||
storage_path TEXT NOT NULL,
|
|
||||||
etag TEXT,
|
|
||||||
link TEXT,
|
|
||||||
content_type TEXT,
|
|
||||||
content_encoding TEXT,
|
|
||||||
content_digest TEXT,
|
|
||||||
size INTEGER,
|
|
||||||
last_modified DATETIME,
|
|
||||||
fetched_at DATETIME,
|
|
||||||
created_at DATETIME,
|
|
||||||
updated_at DATETIME
|
|
||||||
);
|
|
||||||
CREATE UNIQUE INDEX IF NOT EXISTS idx_metadata_eco_name ON metadata_cache(ecosystem, name);
|
|
||||||
|
|
||||||
CREATE TABLE IF NOT EXISTS migrations (
|
|
||||||
name TEXT NOT NULL PRIMARY KEY,
|
|
||||||
applied_at DATETIME NOT NULL
|
|
||||||
);
|
|
||||||
`
|
`
|
||||||
|
|
||||||
var schemaPostgres = `
|
var schemaPostgres = `
|
||||||
|
|
@ -197,29 +164,6 @@ CREATE TABLE IF NOT EXISTS vulnerabilities (
|
||||||
);
|
);
|
||||||
CREATE UNIQUE INDEX IF NOT EXISTS idx_vulns_id_pkg ON vulnerabilities(vuln_id, ecosystem, package_name);
|
CREATE UNIQUE INDEX IF NOT EXISTS idx_vulns_id_pkg ON vulnerabilities(vuln_id, ecosystem, package_name);
|
||||||
CREATE INDEX IF NOT EXISTS idx_vulns_ecosystem_pkg ON vulnerabilities(ecosystem, package_name);
|
CREATE INDEX IF NOT EXISTS idx_vulns_ecosystem_pkg ON vulnerabilities(ecosystem, package_name);
|
||||||
|
|
||||||
CREATE TABLE IF NOT EXISTS metadata_cache (
|
|
||||||
id SERIAL PRIMARY KEY,
|
|
||||||
ecosystem TEXT NOT NULL,
|
|
||||||
name TEXT NOT NULL,
|
|
||||||
storage_path TEXT NOT NULL,
|
|
||||||
etag TEXT,
|
|
||||||
link TEXT,
|
|
||||||
content_type TEXT,
|
|
||||||
content_encoding TEXT,
|
|
||||||
content_digest TEXT,
|
|
||||||
size BIGINT,
|
|
||||||
last_modified TIMESTAMP,
|
|
||||||
fetched_at TIMESTAMP,
|
|
||||||
created_at TIMESTAMP,
|
|
||||||
updated_at TIMESTAMP
|
|
||||||
);
|
|
||||||
CREATE UNIQUE INDEX IF NOT EXISTS idx_metadata_eco_name ON metadata_cache(ecosystem, name);
|
|
||||||
|
|
||||||
CREATE TABLE IF NOT EXISTS migrations (
|
|
||||||
name TEXT NOT NULL PRIMARY KEY,
|
|
||||||
applied_at TIMESTAMP NOT NULL
|
|
||||||
);
|
|
||||||
`
|
`
|
||||||
|
|
||||||
// schemaArtifactsOnly contains just the artifacts table for adding to existing git-pkgs databases.
|
// schemaArtifactsOnly contains just the artifacts table for adding to existing git-pkgs databases.
|
||||||
|
|
@ -286,11 +230,6 @@ func (db *DB) CreateSchema() error {
|
||||||
return fmt.Errorf("setting schema version: %w", err)
|
return fmt.Errorf("setting schema version: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Record all migrations as applied since the full schema is already current.
|
|
||||||
if err := db.recordAllMigrations(); err != nil {
|
|
||||||
return fmt.Errorf("recording migrations: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return db.OptimizeForReads()
|
return db.OptimizeForReads()
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -351,349 +290,127 @@ func (db *DB) HasColumn(table, column string) (bool, error) {
|
||||||
return exists, err
|
return exists, err
|
||||||
}
|
}
|
||||||
|
|
||||||
// migration represents a named schema migration.
|
// MigrateSchema adds missing columns to existing tables for backward compatibility.
|
||||||
type migration struct {
|
|
||||||
name string
|
|
||||||
fn func(db *DB) error
|
|
||||||
}
|
|
||||||
|
|
||||||
// migrations is the ordered list of all schema migrations. See
|
|
||||||
// docs/migrations.md for how to add new ones.
|
|
||||||
var migrations = []migration{
|
|
||||||
{"001_add_packages_enrichment_columns", migrateAddPackagesEnrichmentColumns},
|
|
||||||
{"002_add_versions_enrichment_columns", migrateAddVersionsEnrichmentColumns},
|
|
||||||
{"003_ensure_artifacts_table", migrateEnsureArtifactsTable},
|
|
||||||
{"004_ensure_vulnerabilities_table", migrateEnsureVulnerabilitiesTable},
|
|
||||||
{"005_ensure_metadata_cache_table", migrateEnsureMetadataCacheTable},
|
|
||||||
{"006_add_metadata_content_digest", migrateAddMetadataContentDigest},
|
|
||||||
{"007_add_metadata_link", migrateAddMetadataLink},
|
|
||||||
{"008_add_metadata_content_encoding", migrateAddMetadataContentEncoding},
|
|
||||||
}
|
|
||||||
|
|
||||||
// isTableNotFound returns true if the error indicates a missing table.
|
|
||||||
// SQLite returns "no such table: X", Postgres returns "relation \"X\" does not exist".
|
|
||||||
func isTableNotFound(err error) bool {
|
|
||||||
msg := err.Error()
|
|
||||||
return strings.Contains(msg, "no such table") ||
|
|
||||||
strings.Contains(msg, "does not exist")
|
|
||||||
}
|
|
||||||
|
|
||||||
// createMigrationsTable creates the migrations table.
|
|
||||||
func (db *DB) createMigrationsTable() error {
|
|
||||||
var ts string
|
|
||||||
if db.dialect == DialectPostgres {
|
|
||||||
ts = postgresTimestamp
|
|
||||||
} else {
|
|
||||||
ts = sqliteDatetime
|
|
||||||
}
|
|
||||||
|
|
||||||
query := fmt.Sprintf(`CREATE TABLE IF NOT EXISTS migrations (
|
|
||||||
name TEXT NOT NULL PRIMARY KEY,
|
|
||||||
applied_at %s NOT NULL
|
|
||||||
)`, ts)
|
|
||||||
|
|
||||||
if _, err := db.Exec(query); err != nil {
|
|
||||||
return fmt.Errorf("creating migrations table: %w", err)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// appliedMigrations returns the set of migration names that have been recorded.
|
|
||||||
// Returns nil if the migrations table does not exist yet.
|
|
||||||
func (db *DB) appliedMigrations() (map[string]bool, error) {
|
|
||||||
var names []string
|
|
||||||
err := db.Select(&names, "SELECT name FROM migrations")
|
|
||||||
if err != nil {
|
|
||||||
// Table doesn't exist yet — this is a pre-migration database.
|
|
||||||
if isTableNotFound(err) {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
return nil, fmt.Errorf("loading applied migrations: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
applied := make(map[string]bool, len(names))
|
|
||||||
for _, name := range names {
|
|
||||||
applied[name] = true
|
|
||||||
}
|
|
||||||
return applied, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// recordMigration inserts a migration name into the migrations table.
|
|
||||||
func (db *DB) recordMigration(name string) error {
|
|
||||||
query := db.Rebind("INSERT INTO migrations (name, applied_at) VALUES (?, ?)")
|
|
||||||
if _, err := db.Exec(query, name, time.Now().UTC()); err != nil {
|
|
||||||
return fmt.Errorf("recording migration %s: %w", name, err)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// recordAllMigrations marks every known migration as applied.
|
|
||||||
func (db *DB) recordAllMigrations() error {
|
|
||||||
for _, m := range migrations {
|
|
||||||
if err := db.recordMigration(m.name); err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// MigrateSchema applies any unapplied migrations in order.
|
|
||||||
// For a fully migrated database this executes a single SELECT query.
|
|
||||||
func (db *DB) MigrateSchema() error {
|
func (db *DB) MigrateSchema() error {
|
||||||
applied, err := db.appliedMigrations()
|
// Check and add missing columns to packages table
|
||||||
if err != nil {
|
packagesColumns := map[string]string{
|
||||||
return err
|
"registry_url": "TEXT",
|
||||||
}
|
"supplier_name": "TEXT",
|
||||||
|
"supplier_type": "TEXT",
|
||||||
// If the migrations table didn't exist, create it now.
|
"source": "TEXT",
|
||||||
if applied == nil {
|
"enriched_at": "DATETIME",
|
||||||
if err := db.createMigrationsTable(); err != nil {
|
"vulns_synced_at": "DATETIME",
|
||||||
return err
|
|
||||||
}
|
|
||||||
applied = make(map[string]bool)
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, m := range migrations {
|
|
||||||
if applied[m.name] {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
if err := m.fn(db); err != nil {
|
|
||||||
return fmt.Errorf("migration %s: %w", m.name, err)
|
|
||||||
}
|
|
||||||
if err := db.recordMigration(m.name); err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func migrateAddPackagesEnrichmentColumns(db *DB) error {
|
|
||||||
columns := map[string]string{
|
|
||||||
"registry_url": colTypeText,
|
|
||||||
"supplier_name": colTypeText,
|
|
||||||
"supplier_type": colTypeText,
|
|
||||||
"source": colTypeText,
|
|
||||||
"enriched_at": sqliteDatetime,
|
|
||||||
"vulns_synced_at": sqliteDatetime,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if db.dialect == DialectPostgres {
|
if db.dialect == DialectPostgres {
|
||||||
columns["enriched_at"] = postgresTimestamp
|
packagesColumns["enriched_at"] = "TIMESTAMP"
|
||||||
columns["vulns_synced_at"] = postgresTimestamp
|
packagesColumns["vulns_synced_at"] = "TIMESTAMP"
|
||||||
}
|
}
|
||||||
|
|
||||||
for column, colType := range columns {
|
for column, colType := range packagesColumns {
|
||||||
hasCol, err := db.HasColumn("packages", column)
|
hasCol, err := db.HasColumn("packages", column)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("checking column %s: %w", column, err)
|
return fmt.Errorf("checking column %s: %w", column, err)
|
||||||
}
|
}
|
||||||
if !hasCol {
|
if !hasCol {
|
||||||
alterQuery := fmt.Sprintf("ALTER TABLE packages ADD COLUMN %s %s", column, colType)
|
var alterQuery string
|
||||||
|
if db.dialect == DialectPostgres {
|
||||||
|
alterQuery = fmt.Sprintf("ALTER TABLE packages ADD COLUMN %s %s", column, colType)
|
||||||
|
} else {
|
||||||
|
alterQuery = fmt.Sprintf("ALTER TABLE packages ADD COLUMN %s %s", column, colType)
|
||||||
|
}
|
||||||
if _, err := db.Exec(alterQuery); err != nil {
|
if _, err := db.Exec(alterQuery); err != nil {
|
||||||
return fmt.Errorf("adding column %s to packages: %w", column, err)
|
return fmt.Errorf("adding column %s to packages: %w", column, err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func migrateAddVersionsEnrichmentColumns(db *DB) error {
|
// Check and add missing columns to versions table
|
||||||
columns := map[string]string{
|
versionsColumns := map[string]string{
|
||||||
"integrity": colTypeText,
|
"integrity": "TEXT",
|
||||||
"yanked": "INTEGER DEFAULT 0",
|
"yanked": "INTEGER DEFAULT 0",
|
||||||
"source": colTypeText,
|
"source": "TEXT",
|
||||||
"enriched_at": sqliteDatetime,
|
"enriched_at": "DATETIME",
|
||||||
}
|
}
|
||||||
|
|
||||||
if db.dialect == DialectPostgres {
|
if db.dialect == DialectPostgres {
|
||||||
columns["yanked"] = "BOOLEAN DEFAULT FALSE"
|
versionsColumns["yanked"] = "BOOLEAN DEFAULT FALSE"
|
||||||
columns["enriched_at"] = postgresTimestamp
|
versionsColumns["enriched_at"] = "TIMESTAMP"
|
||||||
}
|
}
|
||||||
|
|
||||||
for column, colType := range columns {
|
for column, colType := range versionsColumns {
|
||||||
hasCol, err := db.HasColumn("versions", column)
|
hasCol, err := db.HasColumn("versions", column)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("checking column %s: %w", column, err)
|
return fmt.Errorf("checking column %s: %w", column, err)
|
||||||
}
|
}
|
||||||
if !hasCol {
|
if !hasCol {
|
||||||
alterQuery := fmt.Sprintf("ALTER TABLE versions ADD COLUMN %s %s", column, colType)
|
var alterQuery string
|
||||||
|
if db.dialect == DialectPostgres {
|
||||||
|
alterQuery = fmt.Sprintf("ALTER TABLE versions ADD COLUMN %s %s", column, colType)
|
||||||
|
} else {
|
||||||
|
alterQuery = fmt.Sprintf("ALTER TABLE versions ADD COLUMN %s %s", column, colType)
|
||||||
|
}
|
||||||
if _, err := db.Exec(alterQuery); err != nil {
|
if _, err := db.Exec(alterQuery); err != nil {
|
||||||
return fmt.Errorf("adding column %s to versions: %w", column, err)
|
return fmt.Errorf("adding column %s to versions: %w", column, err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func migrateEnsureArtifactsTable(db *DB) error {
|
// Ensure artifacts table exists
|
||||||
return db.EnsureArtifactsTable()
|
if err := db.EnsureArtifactsTable(); err != nil {
|
||||||
}
|
return fmt.Errorf("ensuring artifacts table: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
func migrateEnsureVulnerabilitiesTable(db *DB) error {
|
// Ensure vulnerabilities table exists
|
||||||
hasVulns, err := db.HasTable("vulnerabilities")
|
hasVulns, err := db.HasTable("vulnerabilities")
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("checking vulnerabilities table: %w", err)
|
return fmt.Errorf("checking vulnerabilities table: %w", err)
|
||||||
}
|
}
|
||||||
if hasVulns {
|
if !hasVulns {
|
||||||
return nil
|
var vulnSchema string
|
||||||
}
|
if db.dialect == DialectPostgres {
|
||||||
|
vulnSchema = `
|
||||||
var vulnSchema string
|
CREATE TABLE vulnerabilities (
|
||||||
if db.dialect == DialectPostgres {
|
id SERIAL PRIMARY KEY,
|
||||||
vulnSchema = `
|
vuln_id TEXT NOT NULL,
|
||||||
CREATE TABLE vulnerabilities (
|
ecosystem TEXT NOT NULL,
|
||||||
id SERIAL PRIMARY KEY,
|
package_name TEXT NOT NULL,
|
||||||
vuln_id TEXT NOT NULL,
|
severity TEXT,
|
||||||
ecosystem TEXT NOT NULL,
|
summary TEXT,
|
||||||
package_name TEXT NOT NULL,
|
fixed_version TEXT,
|
||||||
severity TEXT,
|
cvss_score REAL,
|
||||||
summary TEXT,
|
"references" TEXT,
|
||||||
fixed_version TEXT,
|
fetched_at TIMESTAMP,
|
||||||
cvss_score REAL,
|
created_at TIMESTAMP,
|
||||||
"references" TEXT,
|
updated_at TIMESTAMP
|
||||||
fetched_at TIMESTAMP,
|
);
|
||||||
created_at TIMESTAMP,
|
CREATE UNIQUE INDEX IF NOT EXISTS idx_vulns_id_pkg ON vulnerabilities(vuln_id, ecosystem, package_name);
|
||||||
updated_at TIMESTAMP
|
CREATE INDEX IF NOT EXISTS idx_vulns_ecosystem_pkg ON vulnerabilities(ecosystem, package_name);
|
||||||
);
|
`
|
||||||
CREATE UNIQUE INDEX IF NOT EXISTS idx_vulns_id_pkg ON vulnerabilities(vuln_id, ecosystem, package_name);
|
} else {
|
||||||
CREATE INDEX IF NOT EXISTS idx_vulns_ecosystem_pkg ON vulnerabilities(ecosystem, package_name);
|
vulnSchema = `
|
||||||
`
|
CREATE TABLE vulnerabilities (
|
||||||
} else {
|
id INTEGER PRIMARY KEY,
|
||||||
vulnSchema = `
|
vuln_id TEXT NOT NULL,
|
||||||
CREATE TABLE vulnerabilities (
|
ecosystem TEXT NOT NULL,
|
||||||
id INTEGER PRIMARY KEY,
|
package_name TEXT NOT NULL,
|
||||||
vuln_id TEXT NOT NULL,
|
severity TEXT,
|
||||||
ecosystem TEXT NOT NULL,
|
summary TEXT,
|
||||||
package_name TEXT NOT NULL,
|
fixed_version TEXT,
|
||||||
severity TEXT,
|
cvss_score REAL,
|
||||||
summary TEXT,
|
"references" TEXT,
|
||||||
fixed_version TEXT,
|
fetched_at DATETIME,
|
||||||
cvss_score REAL,
|
created_at DATETIME,
|
||||||
"references" TEXT,
|
updated_at DATETIME
|
||||||
fetched_at DATETIME,
|
);
|
||||||
created_at DATETIME,
|
CREATE UNIQUE INDEX IF NOT EXISTS idx_vulns_id_pkg ON vulnerabilities(vuln_id, ecosystem, package_name);
|
||||||
updated_at DATETIME
|
CREATE INDEX IF NOT EXISTS idx_vulns_ecosystem_pkg ON vulnerabilities(ecosystem, package_name);
|
||||||
);
|
`
|
||||||
CREATE UNIQUE INDEX IF NOT EXISTS idx_vulns_id_pkg ON vulnerabilities(vuln_id, ecosystem, package_name);
|
}
|
||||||
CREATE INDEX IF NOT EXISTS idx_vulns_ecosystem_pkg ON vulnerabilities(ecosystem, package_name);
|
if _, err := db.Exec(vulnSchema); err != nil {
|
||||||
`
|
return fmt.Errorf("creating vulnerabilities table: %w", err)
|
||||||
}
|
}
|
||||||
if _, err := db.Exec(vulnSchema); err != nil {
|
|
||||||
return fmt.Errorf("creating vulnerabilities table: %w", err)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func migrateEnsureMetadataCacheTable(db *DB) error {
|
|
||||||
return db.EnsureMetadataCacheTable()
|
|
||||||
}
|
|
||||||
|
|
||||||
func migrateAddMetadataContentDigest(db *DB) error {
|
|
||||||
hasColumn, err := db.HasColumn("metadata_cache", "content_digest")
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("checking metadata_cache content_digest column: %w", err)
|
|
||||||
}
|
|
||||||
if hasColumn {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
if _, err := db.Exec("ALTER TABLE metadata_cache ADD COLUMN content_digest TEXT"); err != nil {
|
|
||||||
return fmt.Errorf("adding metadata_cache content_digest column: %w", err)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func migrateAddMetadataLink(db *DB) error {
|
|
||||||
hasColumn, err := db.HasColumn("metadata_cache", "link")
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("checking metadata_cache link column: %w", err)
|
|
||||||
}
|
|
||||||
if hasColumn {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
if _, err := db.Exec("ALTER TABLE metadata_cache ADD COLUMN link TEXT"); err != nil {
|
|
||||||
return fmt.Errorf("adding metadata_cache link column: %w", err)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func migrateAddMetadataContentEncoding(db *DB) error {
|
|
||||||
hasColumn, err := db.HasColumn("metadata_cache", "content_encoding")
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("checking metadata_cache content_encoding column: %w", err)
|
|
||||||
}
|
|
||||||
if hasColumn {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
if _, err := db.Exec("ALTER TABLE metadata_cache ADD COLUMN content_encoding TEXT"); err != nil {
|
|
||||||
return fmt.Errorf("adding metadata_cache content_encoding column: %w", err)
|
|
||||||
}
|
|
||||||
// Rows cached before this column existed hold transport-decompressed bytes
|
|
||||||
// with no recorded encoding and the upstream ETag captured under Go's
|
|
||||||
// auto-added Accept-Encoding: gzip. Clearing the validators forces one fresh
|
|
||||||
// fetch per key so the encoding is recorded and verbatim bytes are restored,
|
|
||||||
// instead of an If-None-Match 304 re-serving the stale decompressed copy.
|
|
||||||
if _, err := db.Exec("UPDATE metadata_cache SET etag = NULL, fetched_at = NULL"); err != nil {
|
|
||||||
return fmt.Errorf("invalidating metadata_cache validators: %w", err)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// EnsureMetadataCacheTable creates the metadata_cache table if it doesn't exist.
|
|
||||||
func (db *DB) EnsureMetadataCacheTable() error {
|
|
||||||
has, err := db.HasTable("metadata_cache")
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("checking metadata_cache table: %w", err)
|
|
||||||
}
|
|
||||||
if has {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
var schema string
|
|
||||||
if db.dialect == DialectPostgres {
|
|
||||||
schema = `
|
|
||||||
CREATE TABLE metadata_cache (
|
|
||||||
id SERIAL PRIMARY KEY,
|
|
||||||
ecosystem TEXT NOT NULL,
|
|
||||||
name TEXT NOT NULL,
|
|
||||||
storage_path TEXT NOT NULL,
|
|
||||||
etag TEXT,
|
|
||||||
link TEXT,
|
|
||||||
content_type TEXT,
|
|
||||||
content_encoding TEXT,
|
|
||||||
content_digest TEXT,
|
|
||||||
size BIGINT,
|
|
||||||
last_modified TIMESTAMP,
|
|
||||||
fetched_at TIMESTAMP,
|
|
||||||
created_at TIMESTAMP,
|
|
||||||
updated_at TIMESTAMP
|
|
||||||
);
|
|
||||||
CREATE UNIQUE INDEX IF NOT EXISTS idx_metadata_eco_name ON metadata_cache(ecosystem, name);
|
|
||||||
`
|
|
||||||
} else {
|
|
||||||
schema = `
|
|
||||||
CREATE TABLE metadata_cache (
|
|
||||||
id INTEGER PRIMARY KEY,
|
|
||||||
ecosystem TEXT NOT NULL,
|
|
||||||
name TEXT NOT NULL,
|
|
||||||
storage_path TEXT NOT NULL,
|
|
||||||
etag TEXT,
|
|
||||||
link TEXT,
|
|
||||||
content_type TEXT,
|
|
||||||
content_encoding TEXT,
|
|
||||||
content_digest TEXT,
|
|
||||||
size INTEGER,
|
|
||||||
last_modified DATETIME,
|
|
||||||
fetched_at DATETIME,
|
|
||||||
created_at DATETIME,
|
|
||||||
updated_at DATETIME
|
|
||||||
);
|
|
||||||
CREATE UNIQUE INDEX IF NOT EXISTS idx_metadata_eco_name ON metadata_cache(ecosystem, name);
|
|
||||||
`
|
|
||||||
}
|
|
||||||
if _, err := db.Exec(schema); err != nil {
|
|
||||||
return fmt.Errorf("creating metadata_cache table: %w", err)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
|
||||||
|
|
@ -2,128 +2,16 @@ package database
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"database/sql"
|
"database/sql"
|
||||||
"net/url"
|
|
||||||
"strings"
|
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/git-pkgs/artifacts"
|
gitpkgsdb "github.com/git-pkgs/git-pkgs/database"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Package represents a package in the database.
|
// Package and Version are shared with git-pkgs. The types and schema
|
||||||
// Schema is compatible with git-pkgs.
|
// are defined in the git-pkgs database package, keeping both projects
|
||||||
type Package struct {
|
// in sync automatically.
|
||||||
ID int64 `db:"id" json:"id"`
|
type Package = gitpkgsdb.Package
|
||||||
PURL string `db:"purl" json:"purl"`
|
type Version = gitpkgsdb.Version
|
||||||
Ecosystem string `db:"ecosystem" json:"ecosystem"`
|
|
||||||
Name string `db:"name" json:"name"`
|
|
||||||
LatestVersion sql.NullString `db:"latest_version" json:"latest_version,omitempty"`
|
|
||||||
License sql.NullString `db:"license" json:"license,omitempty"`
|
|
||||||
Description sql.NullString `db:"description" json:"description,omitempty"`
|
|
||||||
Homepage sql.NullString `db:"homepage" json:"homepage,omitempty"`
|
|
||||||
RepositoryURL sql.NullString `db:"repository_url" json:"repository_url,omitempty"`
|
|
||||||
RegistryURL sql.NullString `db:"registry_url" json:"registry_url,omitempty"`
|
|
||||||
SupplierName sql.NullString `db:"supplier_name" json:"supplier_name,omitempty"`
|
|
||||||
SupplierType sql.NullString `db:"supplier_type" json:"supplier_type,omitempty"`
|
|
||||||
Source sql.NullString `db:"source" json:"source,omitempty"`
|
|
||||||
EnrichedAt sql.NullTime `db:"enriched_at" json:"enriched_at,omitempty"`
|
|
||||||
VulnsSyncedAt sql.NullTime `db:"vulns_synced_at" json:"vulns_synced_at,omitempty"`
|
|
||||||
CreatedAt time.Time `db:"created_at" json:"created_at"`
|
|
||||||
UpdatedAt time.Time `db:"updated_at" json:"updated_at"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// Version represents a package version in the database.
|
|
||||||
// Schema is compatible with git-pkgs.
|
|
||||||
type Version struct {
|
|
||||||
ID int64 `db:"id" json:"id"`
|
|
||||||
PURL string `db:"purl" json:"purl"`
|
|
||||||
PackagePURL string `db:"package_purl" json:"package_purl"`
|
|
||||||
License sql.NullString `db:"license" json:"license,omitempty"`
|
|
||||||
PublishedAt sql.NullTime `db:"published_at" json:"published_at,omitempty"`
|
|
||||||
Integrity sql.NullString `db:"integrity" json:"integrity,omitempty"`
|
|
||||||
Yanked bool `db:"yanked" json:"yanked"`
|
|
||||||
Source sql.NullString `db:"source" json:"source,omitempty"`
|
|
||||||
EnrichedAt sql.NullTime `db:"enriched_at" json:"enriched_at,omitempty"`
|
|
||||||
CreatedAt time.Time `db:"created_at" json:"created_at"`
|
|
||||||
UpdatedAt time.Time `db:"updated_at" json:"updated_at"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// Version extracts the version string from the PURL.
|
|
||||||
// e.g., "pkg:npm/lodash@4.17.21" -> "4.17.21"
|
|
||||||
func (v *Version) Version() string {
|
|
||||||
return VersionFromPURL(v.PURL)
|
|
||||||
}
|
|
||||||
|
|
||||||
// EscapedVersion returns the version escaped for use as a single URL path
|
|
||||||
// segment.
|
|
||||||
//
|
|
||||||
// Version returns decoded text, which is what should be shown to a user but is
|
|
||||||
// not safe to drop into a link: html/template preserves reserved characters and
|
|
||||||
// existing escapes in a URL, so "release/1" would split into two path segments,
|
|
||||||
// "v1?build" would start a query string, and a literal "%2B" would be read back
|
|
||||||
// as "+". Escaping here and decoding in splitWildcardPath round-trips the value,
|
|
||||||
// so the link resolves to the version that was stored.
|
|
||||||
func (v *Version) EscapedVersion() string {
|
|
||||||
return url.PathEscape(v.Version())
|
|
||||||
}
|
|
||||||
|
|
||||||
// DisplayPURL returns the PURL with its path components percent-decoded, for
|
|
||||||
// showing in the UI. The stored PURL keeps the canonical encoding (which is
|
|
||||||
// what the API and all lookups use); this is only a readable rendering, so that
|
|
||||||
// a version like "7.91+dfsg1-2ubuntu0.1" is not shown as "7.91%2Bdfsg1-2ubuntu0.1"
|
|
||||||
// and an npm scope is shown as "@babel" rather than "%40babel". Qualifiers and
|
|
||||||
// subpath keep their encoding, since decoding those would be ambiguous.
|
|
||||||
func (v *Version) DisplayPURL() string {
|
|
||||||
base, suffix := v.PURL, ""
|
|
||||||
if i := strings.IndexAny(base, "?#"); i >= 0 {
|
|
||||||
base, suffix = base[:i], base[i:]
|
|
||||||
}
|
|
||||||
|
|
||||||
name, version := base, ""
|
|
||||||
if idx := strings.LastIndex(base, "@"); idx >= 0 {
|
|
||||||
name, version = base[:idx], "@"+decodePURLComponent(base[idx+1:])
|
|
||||||
}
|
|
||||||
|
|
||||||
parts := strings.Split(name, "/")
|
|
||||||
for i, part := range parts {
|
|
||||||
parts[i] = decodePURLComponent(part)
|
|
||||||
}
|
|
||||||
return strings.Join(parts, "/") + version + suffix
|
|
||||||
}
|
|
||||||
|
|
||||||
// VersionFromPURL extracts the decoded version string from a PURL.
|
|
||||||
//
|
|
||||||
// PURL percent-encodes characters that are not safe in a path component, so a
|
|
||||||
// Debian version like "7.91+dfsg1-2ubuntu0.1" is stored as
|
|
||||||
// "pkg:deb/nmap@7.91%2Bdfsg1-2ubuntu0.1". The raw substring after "@" is
|
|
||||||
// therefore not the version: it must be percent-decoded before being displayed
|
|
||||||
// or used to build a URL, otherwise "%2B" leaks into the UI and round-tripping
|
|
||||||
// the value back into a PURL double-encodes it.
|
|
||||||
//
|
|
||||||
// e.g., "pkg:npm/lodash@4.17.21" -> "4.17.21"
|
|
||||||
func VersionFromPURL(p string) string {
|
|
||||||
// Qualifiers ("?key=value") and subpath ("#path") follow the version.
|
|
||||||
if i := strings.IndexAny(p, "?#"); i >= 0 {
|
|
||||||
p = p[:i]
|
|
||||||
}
|
|
||||||
idx := strings.LastIndex(p, "@")
|
|
||||||
if idx < 0 {
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
return decodePURLComponent(p[idx+1:])
|
|
||||||
}
|
|
||||||
|
|
||||||
// decodePURLComponent percent-decodes a single PURL path component, returning
|
|
||||||
// the input unchanged if it is not valid percent-encoding.
|
|
||||||
func decodePURLComponent(s string) string {
|
|
||||||
if !strings.Contains(s, "%") {
|
|
||||||
return s
|
|
||||||
}
|
|
||||||
decoded, err := url.PathUnescape(s)
|
|
||||||
if err != nil {
|
|
||||||
return s
|
|
||||||
}
|
|
||||||
return decoded
|
|
||||||
}
|
|
||||||
|
|
||||||
// Artifact represents a cached artifact in the database.
|
// Artifact represents a cached artifact in the database.
|
||||||
// This table is proxy-specific and not part of git-pkgs.
|
// This table is proxy-specific and not part of git-pkgs.
|
||||||
|
|
@ -148,44 +36,18 @@ func (a *Artifact) IsCached() bool {
|
||||||
return a.StoragePath.Valid && a.FetchedAt.Valid
|
return a.StoragePath.Valid && a.FetchedAt.Valid
|
||||||
}
|
}
|
||||||
|
|
||||||
// CachedArtifact contains the fields needed to serve a cached artifact.
|
|
||||||
type CachedArtifact struct {
|
|
||||||
Ecosystem string
|
|
||||||
StoragePath string
|
|
||||||
Artifact artifacts.Artifact
|
|
||||||
Integrity sql.NullString
|
|
||||||
}
|
|
||||||
|
|
||||||
// MetadataCacheEntry represents a cached metadata blob for offline serving.
|
|
||||||
type MetadataCacheEntry struct {
|
|
||||||
ID int64 `db:"id" json:"id"`
|
|
||||||
Ecosystem string `db:"ecosystem" json:"ecosystem"`
|
|
||||||
Name string `db:"name" json:"name"`
|
|
||||||
StoragePath string `db:"storage_path" json:"storage_path"`
|
|
||||||
ETag sql.NullString `db:"etag" json:"etag,omitempty"`
|
|
||||||
Link sql.NullString `db:"link" json:"link,omitempty"`
|
|
||||||
ContentType sql.NullString `db:"content_type" json:"content_type,omitempty"`
|
|
||||||
ContentEncoding sql.NullString `db:"content_encoding" json:"content_encoding,omitempty"`
|
|
||||||
ContentDigest sql.NullString `db:"content_digest" json:"content_digest,omitempty"`
|
|
||||||
Size sql.NullInt64 `db:"size" json:"size,omitempty"`
|
|
||||||
LastModified sql.NullTime `db:"last_modified" json:"last_modified,omitempty"`
|
|
||||||
FetchedAt sql.NullTime `db:"fetched_at" json:"fetched_at,omitempty"`
|
|
||||||
CreatedAt time.Time `db:"created_at" json:"created_at"`
|
|
||||||
UpdatedAt time.Time `db:"updated_at" json:"updated_at"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// Vulnerability represents a cached vulnerability record.
|
// Vulnerability represents a cached vulnerability record.
|
||||||
type Vulnerability struct {
|
type Vulnerability struct {
|
||||||
ID int64 `db:"id" json:"id"`
|
ID int64 `db:"id" json:"id"`
|
||||||
VulnID string `db:"vuln_id" json:"vuln_id"`
|
VulnID string `db:"vuln_id" json:"vuln_id"`
|
||||||
Ecosystem string `db:"ecosystem" json:"ecosystem"`
|
Ecosystem string `db:"ecosystem" json:"ecosystem"`
|
||||||
PackageName string `db:"package_name" json:"package_name"`
|
PackageName string `db:"package_name" json:"package_name"`
|
||||||
Severity sql.NullString `db:"severity" json:"severity,omitempty"`
|
Severity sql.NullString `db:"severity" json:"severity,omitempty"`
|
||||||
Summary sql.NullString `db:"summary" json:"summary,omitempty"`
|
Summary sql.NullString `db:"summary" json:"summary,omitempty"`
|
||||||
FixedVersion sql.NullString `db:"fixed_version" json:"fixed_version,omitempty"`
|
FixedVersion sql.NullString `db:"fixed_version" json:"fixed_version,omitempty"`
|
||||||
CVSSScore sql.NullFloat64 `db:"cvss_score" json:"cvss_score,omitempty"`
|
CVSSScore sql.NullFloat64 `db:"cvss_score" json:"cvss_score,omitempty"`
|
||||||
References sql.NullString `db:"references" json:"references,omitempty"`
|
References sql.NullString `db:"references" json:"references,omitempty"`
|
||||||
FetchedAt sql.NullTime `db:"fetched_at" json:"fetched_at,omitempty"`
|
FetchedAt sql.NullTime `db:"fetched_at" json:"fetched_at,omitempty"`
|
||||||
CreatedAt time.Time `db:"created_at" json:"created_at"`
|
CreatedAt time.Time `db:"created_at" json:"created_at"`
|
||||||
UpdatedAt time.Time `db:"updated_at" json:"updated_at"`
|
UpdatedAt time.Time `db:"updated_at" json:"updated_at"`
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -1,159 +0,0 @@
|
||||||
package database
|
|
||||||
|
|
||||||
import (
|
|
||||||
"database/sql"
|
|
||||||
"net/url"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestVersionFromPURL(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
purl string
|
|
||||||
want string
|
|
||||||
}{
|
|
||||||
{"simple", "pkg:npm/lodash@4.17.21", "4.17.21"},
|
|
||||||
{"namespaced", "pkg:composer/symfony/console@6.0.0", "6.0.0"},
|
|
||||||
// Debian/Ubuntu versions routinely contain "+", which PURL encodes.
|
|
||||||
{"encoded plus", "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1", "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1"},
|
|
||||||
{"encoded epoch", "pkg:deb/curl@1%3A7.81.0-1", "1:7.81.0-1"},
|
|
||||||
{"encoded plus with qualifier", "pkg:deb/nmap@7.91%2Bdfsg1?repository_url=http%3A%2F%2Fexample.com", "7.91+dfsg1"},
|
|
||||||
{"tilde is not encoded", "pkg:deb/foo@1.0~rc1", "1.0~rc1"},
|
|
||||||
{"no version", "pkg:npm/lodash", ""},
|
|
||||||
{"invalid escape passed through", "pkg:npm/lodash@1.0%zz", "1.0%zz"},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
if got := VersionFromPURL(tt.purl); got != tt.want {
|
|
||||||
t.Errorf("VersionFromPURL(%q) = %q, want %q", tt.purl, got, tt.want)
|
|
||||||
}
|
|
||||||
v := &Version{PURL: tt.purl}
|
|
||||||
if got := v.Version(); got != tt.want {
|
|
||||||
t.Errorf("Version.Version() for %q = %q, want %q", tt.purl, got, tt.want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestVersionEscapedVersion checks the value the templates put in a URL. It
|
|
||||||
// must survive the round trip back through the router: escaping here and
|
|
||||||
// decoding per path segment on the way in has to yield the original version.
|
|
||||||
func TestVersionEscapedVersion(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
purl string
|
|
||||||
want string
|
|
||||||
}{
|
|
||||||
{"simple", "pkg:npm/lodash@4.17.21", "4.17.21"},
|
|
||||||
// "+" is legal in a path segment, so it stays literal and the UI keeps
|
|
||||||
// showing the version the way Debian writes it.
|
|
||||||
{"plus stays literal", "pkg:deb/nmap@7.91%2Bdfsg1-2ubuntu0.1", "7.91+dfsg1-2ubuntu0.1"},
|
|
||||||
// A slash would otherwise split the version into two path segments.
|
|
||||||
{"slash", "pkg:golang/example@release%2F1", "release%2F1"},
|
|
||||||
// A question mark would otherwise start the query string.
|
|
||||||
{"question mark", "pkg:npm/example@v1%3Fbuild", "v1%3Fbuild"},
|
|
||||||
// A version containing a literal "%2B" is stored double-encoded; the
|
|
||||||
// link must re-encode it or it decodes back to "+" instead.
|
|
||||||
{"literal percent escape", "pkg:npm/example@1.0%252B", "1.0%252B"},
|
|
||||||
{"space", "pkg:npm/example@1.0%20beta", "1.0%20beta"},
|
|
||||||
{"no version", "pkg:npm/lodash", ""},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
v := &Version{PURL: tt.purl}
|
|
||||||
got := v.EscapedVersion()
|
|
||||||
if got != tt.want {
|
|
||||||
t.Errorf("EscapedVersion() for %q = %q, want %q", tt.purl, got, tt.want)
|
|
||||||
}
|
|
||||||
// The router decodes each path segment, which must give back the
|
|
||||||
// version the page displays.
|
|
||||||
decoded, err := url.PathUnescape(got)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("PathUnescape(%q) failed: %v", got, err)
|
|
||||||
}
|
|
||||||
if decoded != v.Version() {
|
|
||||||
t.Errorf("round trip for %q = %q, want %q", tt.purl, decoded, v.Version())
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestVersionDisplayPURL(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
purl string
|
|
||||||
want string
|
|
||||||
}{
|
|
||||||
{"simple", "pkg:npm/lodash@4.17.21", "pkg:npm/lodash@4.17.21"},
|
|
||||||
{
|
|
||||||
"encoded plus",
|
|
||||||
"pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1",
|
|
||||||
"pkg:deb/nmap@7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1",
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"qualifier preserved",
|
|
||||||
"pkg:deb/nmap@7.91%2Bdfsg1?repository_url=http%3A%2F%2Fexample.com",
|
|
||||||
"pkg:deb/nmap@7.91+dfsg1?repository_url=http%3A%2F%2Fexample.com",
|
|
||||||
},
|
|
||||||
// The namespace is encoded too: MakePURLString("npm", "@babel/core", …)
|
|
||||||
// produces "pkg:npm/%40babel/core@…".
|
|
||||||
{"encoded npm scope", "pkg:npm/%40babel/core@7.0.0", "pkg:npm/@babel/core@7.0.0"},
|
|
||||||
{"encoded scope without version", "pkg:npm/%40babel/core", "pkg:npm/@babel/core"},
|
|
||||||
{"no version", "pkg:npm/lodash", "pkg:npm/lodash"},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
v := &Version{PURL: tt.purl}
|
|
||||||
if got := v.DisplayPURL(); got != tt.want {
|
|
||||||
t.Errorf("DisplayPURL() for %q = %q, want %q", tt.purl, got, tt.want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestGetRecentlyCachedPackagesDecodesVersion guards the dashboard's "recently
|
|
||||||
// cached" list, which derives the version from the version PURL.
|
|
||||||
func TestGetRecentlyCachedPackagesDecodesVersion(t *testing.T) {
|
|
||||||
runWithBothDatabases(t, func(t *testing.T, db *DB) {
|
|
||||||
const versionPURL = "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1"
|
|
||||||
|
|
||||||
if err := db.UpsertPackage(&Package{
|
|
||||||
PURL: "pkg:deb/nmap", Ecosystem: "deb", Name: "nmap",
|
|
||||||
}); err != nil {
|
|
||||||
t.Fatalf("UpsertPackage failed: %v", err)
|
|
||||||
}
|
|
||||||
if err := db.UpsertVersion(&Version{
|
|
||||||
PURL: versionPURL, PackagePURL: "pkg:deb/nmap",
|
|
||||||
}); err != nil {
|
|
||||||
t.Fatalf("UpsertVersion failed: %v", err)
|
|
||||||
}
|
|
||||||
if err := db.UpsertArtifact(&Artifact{
|
|
||||||
VersionPURL: versionPURL,
|
|
||||||
Filename: "nmap_7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1_amd64.deb",
|
|
||||||
UpstreamURL: "http://archive.ubuntu.com/ubuntu/pool/universe/n/nmap/nmap.deb",
|
|
||||||
StoragePath: sql.NullString{String: "/cache/nmap.deb", Valid: true},
|
|
||||||
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
|
||||||
}); err != nil {
|
|
||||||
t.Fatalf("UpsertArtifact failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
recent, err := db.GetRecentlyCachedPackages(10)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetRecentlyCachedPackages failed: %v", err)
|
|
||||||
}
|
|
||||||
if len(recent) != 1 {
|
|
||||||
t.Fatalf("expected 1 recent package, got %d", len(recent))
|
|
||||||
}
|
|
||||||
const want = "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1"
|
|
||||||
if recent[0].Version != want {
|
|
||||||
t.Errorf("Version = %q, want %q", recent[0].Version, want)
|
|
||||||
}
|
|
||||||
if recent[0].VersionPURL != versionPURL {
|
|
||||||
t.Errorf("VersionPURL = %q, want %q", recent[0].VersionPURL, versionPURL)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
@ -9,7 +9,6 @@ import (
|
||||||
"sync"
|
"sync"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/git-pkgs/proxy/internal/packageurl"
|
|
||||||
"github.com/git-pkgs/purl"
|
"github.com/git-pkgs/purl"
|
||||||
"github.com/git-pkgs/registries"
|
"github.com/git-pkgs/registries"
|
||||||
_ "github.com/git-pkgs/registries/all" // Import all registry implementations
|
_ "github.com/git-pkgs/registries/all" // Import all registry implementations
|
||||||
|
|
@ -68,10 +67,7 @@ type VulnInfo struct {
|
||||||
|
|
||||||
// EnrichPackage fetches metadata for a package from registry APIs.
|
// EnrichPackage fetches metadata for a package from registry APIs.
|
||||||
func (s *Service) EnrichPackage(ctx context.Context, ecosystem, name string) (*PackageInfo, error) {
|
func (s *Service) EnrichPackage(ctx context.Context, ecosystem, name string) (*PackageInfo, error) {
|
||||||
purlStr := packageurl.MakeString(ecosystem, name, "")
|
purlStr := purl.MakePURLString(ecosystem, name, "")
|
||||||
if purlStr == "" {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
pkg, err := registries.FetchPackageFromPURL(ctx, purlStr, s.regClient)
|
pkg, err := registries.FetchPackageFromPURL(ctx, purlStr, s.regClient)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
@ -106,10 +102,7 @@ func (s *Service) EnrichPackage(ctx context.Context, ecosystem, name string) (*P
|
||||||
|
|
||||||
// EnrichVersion fetches metadata for a specific package version.
|
// EnrichVersion fetches metadata for a specific package version.
|
||||||
func (s *Service) EnrichVersion(ctx context.Context, ecosystem, name, version string) (*VersionInfo, error) {
|
func (s *Service) EnrichVersion(ctx context.Context, ecosystem, name, version string) (*VersionInfo, error) {
|
||||||
purlStr := packageurl.MakeString(ecosystem, name, version)
|
purlStr := purl.MakePURLString(ecosystem, name, version)
|
||||||
if purlStr == "" {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
ver, err := registries.FetchVersionFromPURL(ctx, purlStr, s.regClient)
|
ver, err := registries.FetchVersionFromPURL(ctx, purlStr, s.regClient)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
@ -141,14 +134,9 @@ func (s *Service) EnrichVersion(ctx context.Context, ecosystem, name, version st
|
||||||
|
|
||||||
// BulkEnrichPackages fetches metadata for multiple packages in parallel.
|
// BulkEnrichPackages fetches metadata for multiple packages in parallel.
|
||||||
func (s *Service) BulkEnrichPackages(ctx context.Context, packages []struct{ Ecosystem, Name string }) map[string]*PackageInfo {
|
func (s *Service) BulkEnrichPackages(ctx context.Context, packages []struct{ Ecosystem, Name string }) map[string]*PackageInfo {
|
||||||
purls := make([]string, 0, len(packages))
|
purls := make([]string, len(packages))
|
||||||
for _, pkg := range packages {
|
for i, pkg := range packages {
|
||||||
if purlStr := packageurl.MakeString(pkg.Ecosystem, pkg.Name, ""); purlStr != "" {
|
purls[i] = purl.MakePURLString(pkg.Ecosystem, pkg.Name, "")
|
||||||
purls = append(purls, purlStr)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if len(purls) == 0 {
|
|
||||||
return map[string]*PackageInfo{}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
pkgData := registries.BulkFetchPackages(ctx, purls, s.regClient)
|
pkgData := registries.BulkFetchPackages(ctx, purls, s.regClient)
|
||||||
|
|
@ -159,10 +147,7 @@ func (s *Service) BulkEnrichPackages(ctx context.Context, packages []struct{ Eco
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
|
||||||
p, err := purl.Parse(purlStr)
|
p, _ := purl.Parse(purlStr)
|
||||||
if err != nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
info := &PackageInfo{
|
info := &PackageInfo{
|
||||||
Ecosystem: p.Type,
|
Ecosystem: p.Type,
|
||||||
Name: pkg.Name,
|
Name: pkg.Name,
|
||||||
|
|
@ -189,10 +174,7 @@ func (s *Service) BulkEnrichPackages(ctx context.Context, packages []struct{ Eco
|
||||||
|
|
||||||
// CheckVulnerabilities queries for vulnerabilities affecting a package version.
|
// CheckVulnerabilities queries for vulnerabilities affecting a package version.
|
||||||
func (s *Service) CheckVulnerabilities(ctx context.Context, ecosystem, name, version string) ([]VulnInfo, error) {
|
func (s *Service) CheckVulnerabilities(ctx context.Context, ecosystem, name, version string) ([]VulnInfo, error) {
|
||||||
p := packageurl.Make(ecosystem, name, version)
|
p := purl.MakePURL(ecosystem, name, version)
|
||||||
if p == nil {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
vulnList, err := s.vulnSource.Query(ctx, p)
|
vulnList, err := s.vulnSource.Query(ctx, p)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
@ -219,6 +201,43 @@ func (s *Service) CheckVulnerabilities(ctx context.Context, ecosystem, name, ver
|
||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// BulkCheckVulnerabilities queries vulnerabilities for multiple package versions.
|
||||||
|
func (s *Service) BulkCheckVulnerabilities(ctx context.Context, packages []struct{ Ecosystem, Name, Version string }) (map[string][]VulnInfo, error) {
|
||||||
|
purls := make([]*purl.PURL, len(packages))
|
||||||
|
for i, pkg := range packages {
|
||||||
|
purls[i] = purl.MakePURL(pkg.Ecosystem, pkg.Name, pkg.Version)
|
||||||
|
}
|
||||||
|
|
||||||
|
vulnResults, err := s.vulnSource.QueryBatch(ctx, purls)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
result := make(map[string][]VulnInfo, len(packages))
|
||||||
|
for i, vulnList := range vulnResults {
|
||||||
|
pkg := packages[i]
|
||||||
|
key := purl.MakePURLString(pkg.Ecosystem, pkg.Name, pkg.Version)
|
||||||
|
|
||||||
|
var infos []VulnInfo
|
||||||
|
for _, v := range vulnList {
|
||||||
|
info := VulnInfo{
|
||||||
|
ID: v.ID,
|
||||||
|
Summary: v.Summary,
|
||||||
|
Severity: v.SeverityLevel(),
|
||||||
|
CVSSScore: v.CVSSScore(),
|
||||||
|
FixedVersion: v.FixedVersion(pkg.Ecosystem, pkg.Name),
|
||||||
|
}
|
||||||
|
for _, ref := range v.References {
|
||||||
|
info.References = append(info.References, ref.URL)
|
||||||
|
}
|
||||||
|
infos = append(infos, info)
|
||||||
|
}
|
||||||
|
result[key] = infos
|
||||||
|
}
|
||||||
|
|
||||||
|
return result, nil
|
||||||
|
}
|
||||||
|
|
||||||
// IsOutdated checks if a version is older than the latest version.
|
// IsOutdated checks if a version is older than the latest version.
|
||||||
func (s *Service) IsOutdated(currentVersion, latestVersion string) bool {
|
func (s *Service) IsOutdated(currentVersion, latestVersion string) bool {
|
||||||
if latestVersion == "" || currentVersion == "" {
|
if latestVersion == "" || currentVersion == "" {
|
||||||
|
|
@ -229,10 +248,7 @@ func (s *Service) IsOutdated(currentVersion, latestVersion string) bool {
|
||||||
|
|
||||||
// GetLatestVersion fetches the latest version for a package.
|
// GetLatestVersion fetches the latest version for a package.
|
||||||
func (s *Service) GetLatestVersion(ctx context.Context, ecosystem, name string) (string, error) {
|
func (s *Service) GetLatestVersion(ctx context.Context, ecosystem, name string) (string, error) {
|
||||||
purlStr := packageurl.MakeString(ecosystem, name, "")
|
purlStr := purl.MakePURLString(ecosystem, name, "")
|
||||||
if purlStr == "" {
|
|
||||||
return "", nil
|
|
||||||
}
|
|
||||||
|
|
||||||
latest, err := registries.FetchLatestVersionFromPURL(ctx, purlStr, s.regClient)
|
latest, err := registries.FetchLatestVersionFromPURL(ctx, purlStr, s.regClient)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
@ -272,6 +288,19 @@ func (s *Service) CategorizeLicense(license string) LicenseCategory {
|
||||||
return LicenseUnknown
|
return LicenseUnknown
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// NormalizeLicense normalizes a license string to SPDX format.
|
||||||
|
func (s *Service) NormalizeLicense(license string) string {
|
||||||
|
if license == "" {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
|
||||||
|
if normalized, err := spdx.NormalizeExpressionLax(license); err == nil {
|
||||||
|
return normalized
|
||||||
|
}
|
||||||
|
|
||||||
|
return license
|
||||||
|
}
|
||||||
|
|
||||||
// EnrichmentResult contains all enrichment data for a package version.
|
// EnrichmentResult contains all enrichment data for a package version.
|
||||||
type EnrichmentResult struct {
|
type EnrichmentResult struct {
|
||||||
Package *PackageInfo
|
Package *PackageInfo
|
||||||
|
|
|
||||||
|
|
@ -1,7 +1,6 @@
|
||||||
package enrichment
|
package enrichment
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"os"
|
"os"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
@ -24,36 +23,6 @@ func TestNew(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestSwiftRegistryIdentitySkipsPURLDependentLookups(t *testing.T) {
|
|
||||||
svc := New(slog.New(slog.NewTextHandler(os.Stdout, nil)))
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
packageInfo, err := svc.EnrichPackage(ctx, "swift", "apple/example")
|
|
||||||
if err != nil || packageInfo != nil {
|
|
||||||
t.Errorf("EnrichPackage() = %#v, %v; want nil, nil", packageInfo, err)
|
|
||||||
}
|
|
||||||
|
|
||||||
versionInfo, err := svc.EnrichVersion(ctx, "swift", "apple/example", "1.2.3")
|
|
||||||
if err != nil || versionInfo != nil {
|
|
||||||
t.Errorf("EnrichVersion() = %#v, %v; want nil, nil", versionInfo, err)
|
|
||||||
}
|
|
||||||
|
|
||||||
vulnerabilities, err := svc.CheckVulnerabilities(ctx, "swift", "apple/example", "1.2.3")
|
|
||||||
if err != nil || vulnerabilities != nil {
|
|
||||||
t.Errorf("CheckVulnerabilities() = %#v, %v; want nil, nil", vulnerabilities, err)
|
|
||||||
}
|
|
||||||
|
|
||||||
latest, err := svc.GetLatestVersion(ctx, "swift", "apple/example")
|
|
||||||
if err != nil || latest != "" {
|
|
||||||
t.Errorf("GetLatestVersion() = %q, %v; want empty string, nil", latest, err)
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := []struct{ Ecosystem, Name string }{{Ecosystem: "swift", Name: "apple/example"}}
|
|
||||||
if got := svc.BulkEnrichPackages(ctx, packages); len(got) != 0 {
|
|
||||||
t.Errorf("BulkEnrichPackages() = %#v, want empty result", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestIsOutdated(t *testing.T) {
|
func TestIsOutdated(t *testing.T) {
|
||||||
logger := slog.New(slog.NewTextHandler(os.Stdout, nil))
|
logger := slog.New(slog.NewTextHandler(os.Stdout, nil))
|
||||||
svc := New(logger)
|
svc := New(logger)
|
||||||
|
|
@ -105,3 +74,25 @@ func TestCategorizeLicense(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestNormalizeLicense(t *testing.T) {
|
||||||
|
logger := slog.New(slog.NewTextHandler(os.Stdout, nil))
|
||||||
|
svc := New(logger)
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
input string
|
||||||
|
expected string
|
||||||
|
}{
|
||||||
|
{"MIT", "MIT"},
|
||||||
|
{"Apache 2", "Apache-2.0"},
|
||||||
|
{"Apache-2.0", "Apache-2.0"},
|
||||||
|
{"", ""},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tc := range tests {
|
||||||
|
result := svc.NormalizeLicense(tc.input)
|
||||||
|
if result != tc.expected {
|
||||||
|
t.Errorf("NormalizeLicense(%q) = %q, want %q", tc.input, result, tc.expected)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
|
||||||
|
|
@ -1,186 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/sha256"
|
|
||||||
"encoding/hex"
|
|
||||||
"net/http"
|
|
||||||
"regexp"
|
|
||||||
"strings"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
apkEcosystem = "alpine"
|
|
||||||
// defaultAPKRepositoryName is the repository name used when no
|
|
||||||
// upstream.apk repositories are configured.
|
|
||||||
defaultAPKRepositoryName = "alpine"
|
|
||||||
// defaultAPKUpstream is the official Alpine Linux mirror.
|
|
||||||
defaultAPKUpstream = "https://dl-cdn.alpinelinux.org/alpine"
|
|
||||||
apkMatchCount = 3 // full match + name + version
|
|
||||||
)
|
|
||||||
|
|
||||||
// APKHandler handles Alpine APK repository protocol requests. Each configured
|
|
||||||
// upstream repository is mounted at /apk/{repository}/ and the remaining path
|
|
||||||
// mirrors the upstream layout ({release}/{repo}/{arch}/{file}).
|
|
||||||
//
|
|
||||||
// Repository indexes (v2 APKINDEX.tar.gz, v3 Packages.adb) and detached
|
|
||||||
// signatures are served byte-for-byte unchanged through the metadata cache so
|
|
||||||
// apk signature verification keeps working. Package files are cached in the
|
|
||||||
// shared artifact cache and stay available when the upstream is unreachable.
|
|
||||||
type APKHandler struct {
|
|
||||||
proxy *Proxy
|
|
||||||
proxyURL string
|
|
||||||
repositories map[string]string
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewAPKHandler creates an Alpine APK repository protocol handler.
|
|
||||||
// When repositories is empty, a single repository named "alpine" pointing at
|
|
||||||
// the official Alpine mirror is used.
|
|
||||||
func NewAPKHandler(proxy *Proxy, proxyURL string, repositories map[string]string) *APKHandler {
|
|
||||||
h := &APKHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
|
||||||
repositories: make(map[string]string, len(repositories)),
|
|
||||||
}
|
|
||||||
for name, repositoryURL := range repositories {
|
|
||||||
h.repositories[name] = strings.TrimSuffix(repositoryURL, "/")
|
|
||||||
}
|
|
||||||
if len(h.repositories) == 0 {
|
|
||||||
h.repositories[defaultAPKRepositoryName] = defaultAPKUpstream
|
|
||||||
}
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for APK requests.
|
|
||||||
// Mount this at /apk on your router.
|
|
||||||
func (h *APKHandler) Routes() http.Handler {
|
|
||||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if r.Method != http.MethodGet && r.Method != http.MethodHead {
|
|
||||||
http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
path := strings.TrimPrefix(r.URL.Path, "/")
|
|
||||||
|
|
||||||
if containsPathTraversal(path) {
|
|
||||||
http.Error(w, "invalid path", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
repository, rest, ok := strings.Cut(path, "/")
|
|
||||||
upstreamURL, found := h.repositories[repository]
|
|
||||||
if !ok || rest == "" || !found {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
switch {
|
|
||||||
case isAPKIndex(rest) || isAPKSignature(rest):
|
|
||||||
// Indexes and detached signatures are signed upstream metadata.
|
|
||||||
// Cache them with the metadata TTL and serve the stored bytes
|
|
||||||
// unchanged so apk verification continues to work.
|
|
||||||
h.handleMetadata(w, r, repository, upstreamURL, rest)
|
|
||||||
case strings.HasSuffix(rest, ".apk"):
|
|
||||||
// Package downloads - cache these in the artifact cache.
|
|
||||||
h.handlePackageDownload(w, r, repository, upstreamURL, rest)
|
|
||||||
default:
|
|
||||||
// Other files - proxy directly.
|
|
||||||
h.proxyFile(w, r, upstreamURL, rest)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
// isAPKIndex reports whether the path names a repository index:
|
|
||||||
// APKINDEX.tar.gz (apk v2) or Packages.adb (apk v3).
|
|
||||||
func isAPKIndex(path string) bool {
|
|
||||||
base := path[strings.LastIndex(path, "/")+1:]
|
|
||||||
return base == "APKINDEX.tar.gz" || base == "Packages.adb"
|
|
||||||
}
|
|
||||||
|
|
||||||
// isAPKSignature reports whether the path names a detached signature file.
|
|
||||||
func isAPKSignature(path string) bool {
|
|
||||||
return strings.HasSuffix(path, ".sig") || strings.HasSuffix(path, ".rsa.pub")
|
|
||||||
}
|
|
||||||
|
|
||||||
// handlePackageDownload fetches and caches .apk packages.
|
|
||||||
// Path format: {release}/{repo}/{arch}/{name}-{version}-r{rel}.apk
|
|
||||||
// Example: v3.22/main/x86_64/busybox-1.37.0-r12.apk
|
|
||||||
//
|
|
||||||
// APK filenames do not include the architecture, so the same filename can hold
|
|
||||||
// different bytes per architecture (and per release). The full request path is
|
|
||||||
// therefore part of the cache identity.
|
|
||||||
func (h *APKHandler) handlePackageDownload(w http.ResponseWriter, r *http.Request, repository, upstreamURL, path string) {
|
|
||||||
name, version, arch := h.parseAPKPath(path)
|
|
||||||
if name == "" {
|
|
||||||
// Can't parse, just proxy directly
|
|
||||||
h.proxyFile(w, r, upstreamURL, path)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
downloadURL := upstreamURL + "/" + path
|
|
||||||
cacheFilename := repository + "/" + path
|
|
||||||
|
|
||||||
h.proxy.Logger.Info("apk package download",
|
|
||||||
"repository", repository, "name", name, "version", version, "arch", arch)
|
|
||||||
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(
|
|
||||||
r.Context(), apkEcosystem, name, version, cacheFilename, downloadURL)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch package")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if result.Artifact.MediaType == "" {
|
|
||||||
result.Artifact.MediaType = "application/octet-stream"
|
|
||||||
}
|
|
||||||
serveArtifact(w, r.Method, result)
|
|
||||||
}
|
|
||||||
|
|
||||||
// handleMetadata serves repository indexes and signatures through the
|
|
||||||
// metadata cache. Stored bytes are re-served verbatim, which keeps embedded
|
|
||||||
// and detached signatures valid.
|
|
||||||
func (h *APKHandler) handleMetadata(w http.ResponseWriter, r *http.Request, repository, upstreamURL, path string) {
|
|
||||||
h.proxy.ProxyCached(w, r, upstreamURL+"/"+path, apkEcosystem,
|
|
||||||
h.metadataCacheKey(repository, upstreamURL, path), "*/*")
|
|
||||||
}
|
|
||||||
|
|
||||||
// metadataCacheKey derives the metadata cache key from the repository name,
|
|
||||||
// its upstream URL, and the request path. Hashing the identity keeps distinct
|
|
||||||
// repositories from sharing cache entries (repository names may contain '_'
|
|
||||||
// and a separator-based key would be ambiguous) and drops cached entries when
|
|
||||||
// a repository is repointed at a different upstream, mirroring
|
|
||||||
// HelmHandler.indexCacheKey.
|
|
||||||
func (h *APKHandler) metadataCacheKey(repository, upstreamURL, path string) string {
|
|
||||||
identity := repository + "\x00" + upstreamURL + "\x00" + path
|
|
||||||
digest := sha256.Sum256([]byte(identity))
|
|
||||||
return hex.EncodeToString(digest[:])
|
|
||||||
}
|
|
||||||
|
|
||||||
// proxyFile proxies any file directly without caching.
|
|
||||||
func (h *APKHandler) proxyFile(w http.ResponseWriter, r *http.Request, upstreamURL, path string) {
|
|
||||||
h.proxy.ProxyFile(w, r, upstreamURL+"/"+path)
|
|
||||||
}
|
|
||||||
|
|
||||||
// apkPackagePattern matches .apk filenames to extract name and version.
|
|
||||||
// Format: {name}-{version}-r{rel}.apk where version starts with a digit.
|
|
||||||
// Examples:
|
|
||||||
// - busybox-1.37.0-r12.apk
|
|
||||||
// - alpine-baselayout-data-3.7.0-r0.apk
|
|
||||||
var apkPackagePattern = regexp.MustCompile(`^(.+)-(\d[^-]*-r\d+)\.apk$`)
|
|
||||||
|
|
||||||
// parseAPKPath extracts package info from a path containing an APK filename.
|
|
||||||
// The architecture is taken from the parent directory since APK filenames do
|
|
||||||
// not include it.
|
|
||||||
func (h *APKHandler) parseAPKPath(path string) (name, version, arch string) {
|
|
||||||
segments := strings.Split(path, "/")
|
|
||||||
filename := segments[len(segments)-1]
|
|
||||||
if len(segments) > 1 {
|
|
||||||
arch = segments[len(segments)-2]
|
|
||||||
}
|
|
||||||
|
|
||||||
matches := apkPackagePattern.FindStringSubmatch(filename)
|
|
||||||
if len(matches) != apkMatchCount {
|
|
||||||
return "", "", ""
|
|
||||||
}
|
|
||||||
|
|
||||||
return matches[1], matches[2], arch
|
|
||||||
}
|
|
||||||
|
|
@ -1,362 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"fmt"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"sync/atomic"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestAPKHandler_parseAPKPath(t *testing.T) {
|
|
||||||
h := &APKHandler{}
|
|
||||||
|
|
||||||
assertPathParser(t, "parseAPKPath", h.parseAPKPath, []pathParseCase{
|
|
||||||
{"v3.22/main/x86_64/busybox-1.37.0-r12.apk", "busybox", "1.37.0-r12", "x86_64"},
|
|
||||||
{"v3.22/main/aarch64/alpine-baselayout-data-3.7.0-r0.apk", "alpine-baselayout-data", "3.7.0-r0", "aarch64"},
|
|
||||||
{"edge/community/x86_64/openjdk21-jre-21.0.2_p13-r1.apk", "openjdk21-jre", "21.0.2_p13-r1", "x86_64"},
|
|
||||||
{"busybox-1.37.0-r12.apk", "busybox", "1.37.0-r12", ""},
|
|
||||||
{"v3.22/main/x86_64/invalid.apk", "", "", ""},
|
|
||||||
{"v3.22/main/x86_64/not-an-apk-file", "", "", ""},
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestAPKHandler_Routes(t *testing.T) {
|
|
||||||
h := NewAPKHandler(nil, "http://localhost:8080", nil)
|
|
||||||
assertRoutesBasics(t, h.Routes(), "/alpine/v3.22/main/x86_64/APKINDEX.tar.gz", "/alpine/v3.22/../../../etc/passwd")
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestAPKHandler_DefaultsToOfficialMirror(t *testing.T) {
|
|
||||||
h := NewAPKHandler(nil, "http://localhost:8080", nil)
|
|
||||||
if got := h.repositories[defaultAPKRepositoryName]; got != defaultAPKUpstream {
|
|
||||||
t.Errorf("default repository = %q, want %q", got, defaultAPKUpstream)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestAPKHandler_UnknownRepositoryReturns404(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
h := NewAPKHandler(proxy, "http://localhost:8080", map[string]string{"alpine": "https://example.test"})
|
|
||||||
|
|
||||||
for _, target := range []string{
|
|
||||||
"/unknown/v3.22/main/x86_64/APKINDEX.tar.gz",
|
|
||||||
"/alpine",
|
|
||||||
"/",
|
|
||||||
} {
|
|
||||||
w := serveAPKRequest(h, target)
|
|
||||||
if w.Code != http.StatusNotFound {
|
|
||||||
t.Errorf("%s: status = %d, want 404", target, w.Code)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestAPKHandler_MetadataCacheKeysDoNotCollideAcrossRepositories guards the
|
|
||||||
// hashed metadata cache key: with a separator-based key, repositories named
|
|
||||||
// "alpine" and "alpine_edge" would share cache entries for
|
|
||||||
// /alpine/edge/main/x86_64/APKINDEX.tar.gz and
|
|
||||||
// /alpine_edge/main/x86_64/APKINDEX.tar.gz, serving one repository's signed
|
|
||||||
// index to clients of the other.
|
|
||||||
func TestAPKHandler_MetadataCacheKeysDoNotCollideAcrossRepositories(t *testing.T) {
|
|
||||||
indexA := "signed index of repository A"
|
|
||||||
upstreamA := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if r.URL.Path != "/edge/main/x86_64/APKINDEX.tar.gz" {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
_, _ = fmt.Fprint(w, indexA)
|
|
||||||
}))
|
|
||||||
defer upstreamA.Close()
|
|
||||||
|
|
||||||
indexB := "signed index of repository B"
|
|
||||||
upstreamB := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if r.URL.Path != "/main/x86_64/APKINDEX.tar.gz" {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
_, _ = fmt.Fprint(w, indexB)
|
|
||||||
}))
|
|
||||||
defer upstreamB.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
proxy.HTTPClient = http.DefaultClient
|
|
||||||
|
|
||||||
h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{
|
|
||||||
"alpine": upstreamA.URL,
|
|
||||||
"alpine_edge": upstreamB.URL,
|
|
||||||
})
|
|
||||||
|
|
||||||
first := serveAPKRequest(h, "/alpine/edge/main/x86_64/APKINDEX.tar.gz")
|
|
||||||
if first.Code != http.StatusOK || first.Body.String() != indexA {
|
|
||||||
t.Fatalf("repository A: status = %d, body = %q, want 200 %q", first.Code, first.Body.String(), indexA)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Served within the metadata TTL: a colliding key would return indexA here.
|
|
||||||
second := serveAPKRequest(h, "/alpine_edge/main/x86_64/APKINDEX.tar.gz")
|
|
||||||
if second.Code != http.StatusOK {
|
|
||||||
t.Fatalf("repository B: status = %d, want 200: %s", second.Code, second.Body.String())
|
|
||||||
}
|
|
||||||
if second.Body.String() != indexB {
|
|
||||||
t.Errorf("repository B served %q, want %q (cache key collision)", second.Body.String(), indexB)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestAPKHandler_IndexesServedUnchanged covers v2 (APKINDEX.tar.gz) and v3
|
|
||||||
// (Packages.adb) indexes plus detached signatures: bytes must be served
|
|
||||||
// unchanged so apk signature verification keeps working, and within the
|
|
||||||
// metadata TTL cached copies must be served without contacting the upstream
|
|
||||||
// (the stale-after-TTL fallback itself is covered by the shared ProxyCached
|
|
||||||
// tests).
|
|
||||||
func TestAPKHandler_IndexesServedUnchanged(t *testing.T) {
|
|
||||||
files := map[string][]byte{
|
|
||||||
"/v3.22/main/x86_64/APKINDEX.tar.gz": []byte("\x1f\x8b\x08v2-index-with-embedded-signature"),
|
|
||||||
"/v3.22/main/x86_64/Packages.adb": []byte("ADB.v3-index-binary\x00payload"),
|
|
||||||
"/v3.22/main/x86_64/Packages.adb.sig": []byte("detached-signature-bytes"),
|
|
||||||
}
|
|
||||||
|
|
||||||
var available atomic.Bool
|
|
||||||
available.Store(true)
|
|
||||||
var upstreamRequests atomic.Int32
|
|
||||||
var authHeader string
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if !available.Load() {
|
|
||||||
http.Error(w, "unavailable", http.StatusServiceUnavailable)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
authHeader = r.Header.Get("Authorization")
|
|
||||||
data, ok := files[r.URL.Path]
|
|
||||||
if !ok {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
upstreamRequests.Add(1)
|
|
||||||
w.Header().Set("Content-Type", "application/octet-stream")
|
|
||||||
_, _ = w.Write(data)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
proxy.AuthForURL = func(string) (string, string) {
|
|
||||||
return "Authorization", "Bearer apk-token"
|
|
||||||
}
|
|
||||||
|
|
||||||
h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{"alpine": upstream.URL})
|
|
||||||
|
|
||||||
for path, want := range files {
|
|
||||||
w := serveAPKRequest(h, "/alpine"+path)
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("%s: status = %d, want 200: %s", path, w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Body.Bytes(); string(got) != string(want) {
|
|
||||||
t.Errorf("%s: body altered:\ngot %q\nwant %q", path, got, want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if authHeader != "Bearer apk-token" {
|
|
||||||
t.Errorf("Authorization = %q, want %q", authHeader, "Bearer apk-token")
|
|
||||||
}
|
|
||||||
|
|
||||||
// Upstream goes away: cached indexes must still be served, unchanged.
|
|
||||||
available.Store(false)
|
|
||||||
requestsBefore := upstreamRequests.Load()
|
|
||||||
for path, want := range files {
|
|
||||||
w := serveAPKRequest(h, "/alpine"+path)
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("%s offline: status = %d, want 200: %s", path, w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Body.Bytes(); string(got) != string(want) {
|
|
||||||
t.Errorf("%s offline: body altered:\ngot %q\nwant %q", path, got, want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if got := upstreamRequests.Load(); got != requestsBefore {
|
|
||||||
t.Errorf("upstream requests during offline reads = %d, want %d", got, requestsBefore)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestAPKHandler_PackageDownloadCachesPerArch covers package downloads, cache
|
|
||||||
// hits, offline reads, and that identically named packages for different
|
|
||||||
// architectures are cached separately.
|
|
||||||
func TestAPKHandler_PackageDownloadCachesPerArch(t *testing.T) {
|
|
||||||
packages := map[string][]byte{
|
|
||||||
"/v3.22/main/x86_64/busybox-1.37.0-r12.apk": []byte("x86_64 package bytes"),
|
|
||||||
"/v3.22/main/aarch64/busybox-1.37.0-r12.apk": []byte("aarch64 package bytes"),
|
|
||||||
}
|
|
||||||
|
|
||||||
var available atomic.Bool
|
|
||||||
available.Store(true)
|
|
||||||
var packageRequests atomic.Int32
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if !available.Load() {
|
|
||||||
http.Error(w, "unavailable", http.StatusServiceUnavailable)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
data, ok := packages[r.URL.Path]
|
|
||||||
if !ok {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
packageRequests.Add(1)
|
|
||||||
w.Header().Set("Content-Type", "application/octet-stream")
|
|
||||||
_, _ = w.Write(data)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
t.Cleanup(func() { _ = fetcher.Close() })
|
|
||||||
|
|
||||||
h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{"alpine": upstream.URL})
|
|
||||||
|
|
||||||
for path, want := range packages {
|
|
||||||
w := serveAPKRequest(h, "/alpine"+path)
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("%s: status = %d, want 200: %s", path, w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Body.String(); got != string(want) {
|
|
||||||
t.Errorf("%s: body = %q, want %q", path, got, want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if got := packageRequests.Load(); got != 2 {
|
|
||||||
t.Fatalf("upstream package requests = %d, want 2 (one per architecture)", got)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Second round must be served from cache, even with the upstream down.
|
|
||||||
available.Store(false)
|
|
||||||
for path, want := range packages {
|
|
||||||
w := serveAPKRequest(h, "/alpine"+path)
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("%s cached: status = %d, want 200: %s", path, w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Body.String(); got != string(want) {
|
|
||||||
t.Errorf("%s cached: body = %q, want %q", path, got, want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if got := packageRequests.Load(); got != 2 {
|
|
||||||
t.Errorf("upstream package requests after cache hits = %d, want 2", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestAPKHandler_PackageDownloadSendsUpstreamAuth(t *testing.T) {
|
|
||||||
var authHeader string
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
authHeader = r.Header.Get("Authorization")
|
|
||||||
if authHeader != "Bearer apk-token" {
|
|
||||||
w.WriteHeader(http.StatusUnauthorized)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
_, _ = fmt.Fprint(w, "private package")
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
client := upstream.Client()
|
|
||||||
client.Transport = &authRoundTripper{base: client.Transport, header: "Authorization", value: "Bearer apk-token"}
|
|
||||||
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(client), fetch.WithMaxRetries(0))
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
t.Cleanup(func() { _ = fetcher.Close() })
|
|
||||||
|
|
||||||
h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{"private": upstream.URL})
|
|
||||||
|
|
||||||
w := serveAPKRequest(h, "/private/v3.22/main/x86_64/busybox-1.37.0-r12.apk")
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if w.Body.String() != "private package" {
|
|
||||||
t.Errorf("body = %q, want %q", w.Body.String(), "private package")
|
|
||||||
}
|
|
||||||
if authHeader != "Bearer apk-token" {
|
|
||||||
t.Errorf("Authorization = %q, want %q", authHeader, "Bearer apk-token")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestAPKHandler_UnparseablePackageProxiedDirectly(t *testing.T) {
|
|
||||||
var requested string
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
requested = r.URL.Path
|
|
||||||
_, _ = fmt.Fprint(w, "raw bytes")
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
|
|
||||||
h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{"alpine": upstream.URL})
|
|
||||||
|
|
||||||
w := serveAPKRequest(h, "/alpine/v3.22/main/x86_64/no-version.apk")
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if requested != "/v3.22/main/x86_64/no-version.apk" {
|
|
||||||
t.Errorf("upstream path = %q, want %q", requested, "/v3.22/main/x86_64/no-version.apk")
|
|
||||||
}
|
|
||||||
if w.Body.String() != "raw bytes" {
|
|
||||||
t.Errorf("body = %q, want %q", w.Body.String(), "raw bytes")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// authRoundTripper adds a static auth header, mimicking the server's
|
|
||||||
// authentication-aware upstream transport.
|
|
||||||
type authRoundTripper struct {
|
|
||||||
base http.RoundTripper
|
|
||||||
header string
|
|
||||||
value string
|
|
||||||
}
|
|
||||||
|
|
||||||
func (a *authRoundTripper) RoundTrip(req *http.Request) (*http.Response, error) {
|
|
||||||
req = req.Clone(req.Context())
|
|
||||||
req.Header.Set(a.header, a.value)
|
|
||||||
base := a.base
|
|
||||||
if base == nil {
|
|
||||||
base = http.DefaultTransport
|
|
||||||
}
|
|
||||||
return base.RoundTrip(req)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestAPKHandler_PackageHeadOmitsBody verifies that HEAD requests for cached
|
|
||||||
// packages return headers (including Content-Length) without a body.
|
|
||||||
func TestAPKHandler_PackageHeadOmitsBody(t *testing.T) {
|
|
||||||
pkg := []byte("package bytes")
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.Header().Set("Content-Type", "application/octet-stream")
|
|
||||||
_, _ = w.Write(pkg)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
t.Cleanup(func() { _ = fetcher.Close() })
|
|
||||||
|
|
||||||
h := NewAPKHandler(proxy, "http://proxy.example", map[string]string{"alpine": upstream.URL})
|
|
||||||
|
|
||||||
target := "/alpine/v3.22/main/x86_64/busybox-1.37.0-r12.apk"
|
|
||||||
if w := serveAPKRequest(h, target); w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("seeding GET: status = %d, want 200: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodHead, target, nil))
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("HEAD: status = %d, want 200: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Body.Len(); got != 0 {
|
|
||||||
t.Errorf("HEAD body length = %d, want 0", got)
|
|
||||||
}
|
|
||||||
if got := w.Header().Get("Content-Length"); got != fmt.Sprint(len(pkg)) {
|
|
||||||
t.Errorf("HEAD Content-Length = %q, want %d", got, len(pkg))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func serveAPKRequest(h *APKHandler, target string) *httptest.ResponseRecorder {
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, target, nil))
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
|
|
@ -1,23 +1,16 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"bufio"
|
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"errors"
|
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/url"
|
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
cargoUpstream = "https://index.crates.io"
|
cargoUpstream = "https://index.crates.io"
|
||||||
cargoDownloadBase = "https://static.crates.io/crates"
|
cargoDownloadBase = "https://static.crates.io/crates"
|
||||||
|
|
||||||
cargoIndexLen1 = 1
|
|
||||||
cargoIndexLen2 = 2
|
|
||||||
cargoIndexLen3 = 3
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// CargoHandler handles cargo registry protocol requests.
|
// CargoHandler handles cargo registry protocol requests.
|
||||||
|
|
@ -29,18 +22,11 @@ type CargoHandler struct {
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewCargoHandler creates a new cargo protocol handler.
|
// NewCargoHandler creates a new cargo protocol handler.
|
||||||
func NewCargoHandler(proxy *Proxy, proxyURL, indexURL, downloadURL string) *CargoHandler {
|
func NewCargoHandler(proxy *Proxy, proxyURL string) *CargoHandler {
|
||||||
if strings.TrimSpace(indexURL) == "" {
|
|
||||||
indexURL = cargoUpstream
|
|
||||||
}
|
|
||||||
if strings.TrimSpace(downloadURL) == "" {
|
|
||||||
downloadURL = cargoDownloadBase
|
|
||||||
}
|
|
||||||
|
|
||||||
return &CargoHandler{
|
return &CargoHandler{
|
||||||
proxy: proxy,
|
proxy: proxy,
|
||||||
indexURL: strings.TrimSuffix(indexURL, "/"),
|
indexURL: cargoUpstream,
|
||||||
downloadURL: strings.TrimSuffix(downloadURL, "/"),
|
downloadURL: cargoDownloadBase,
|
||||||
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -70,7 +56,7 @@ func (h *CargoHandler) Routes() http.Handler {
|
||||||
|
|
||||||
// CargoConfig is the registry configuration returned by config.json.
|
// CargoConfig is the registry configuration returned by config.json.
|
||||||
type CargoConfig struct {
|
type CargoConfig struct {
|
||||||
DL string `json:"dl"`
|
DL string `json:"dl"`
|
||||||
API string `json:"api,omitempty"`
|
API string `json:"api,omitempty"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -80,7 +66,7 @@ func (h *CargoHandler) handleConfig(w http.ResponseWriter, r *http.Request) {
|
||||||
DL: h.proxyURL + "/cargo/crates/{crate}/{version}/download",
|
DL: h.proxyURL + "/cargo/crates/{crate}/{version}/download",
|
||||||
}
|
}
|
||||||
|
|
||||||
w.Header().Set(headerContentType, "application/json")
|
w.Header().Set("Content-Type", "application/json")
|
||||||
_ = json.NewEncoder(w).Encode(config)
|
_ = json.NewEncoder(w).Encode(config)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -94,76 +80,44 @@ func (h *CargoHandler) handleIndex(w http.ResponseWriter, r *http.Request) {
|
||||||
|
|
||||||
h.proxy.Logger.Info("cargo index request", "crate", name)
|
h.proxy.Logger.Info("cargo index request", "crate", name)
|
||||||
|
|
||||||
|
// Build the index path
|
||||||
indexPath := h.buildIndexPath(name)
|
indexPath := h.buildIndexPath(name)
|
||||||
upstreamURL := fmt.Sprintf("%s/%s", h.indexURL, indexPath)
|
upstreamURL := fmt.Sprintf("%s/%s", h.indexURL, indexPath)
|
||||||
|
|
||||||
body, contentType, err := h.proxy.FetchOrCacheMetadata(r.Context(), "cargo", name, upstreamURL, "text/plain")
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, "internal error", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if errors.Is(err, ErrUpstreamNotFound) {
|
|
||||||
http.Error(w, "not found", http.StatusNotFound)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Error("failed to fetch upstream index", "error", err)
|
h.proxy.Logger.Error("failed to fetch upstream index", "error", err)
|
||||||
http.Error(w, "failed to fetch from upstream", http.StatusBadGateway)
|
http.Error(w, "failed to fetch from upstream", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
if contentType == "" {
|
if resp.StatusCode == http.StatusNotFound {
|
||||||
contentType = "text/plain; charset=utf-8"
|
http.Error(w, "not found", http.StatusNotFound)
|
||||||
|
return
|
||||||
}
|
}
|
||||||
|
if resp.StatusCode != http.StatusOK {
|
||||||
w.Header().Set(headerContentType, contentType)
|
http.Error(w, fmt.Sprintf("upstream returned %d", resp.StatusCode), http.StatusBadGateway)
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
h.applyCooldownFiltering(w, body)
|
|
||||||
}
|
|
||||||
|
|
||||||
type crateIndexEntry struct {
|
|
||||||
Name string `json:"name"`
|
|
||||||
Version string `json:"vers"`
|
|
||||||
PublishTime string `json:"pubtime,omitempty"`
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *CargoHandler) applyCooldownFiltering(downstreamResponse http.ResponseWriter, body []byte) {
|
|
||||||
if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
|
|
||||||
_, _ = downstreamResponse.Write(body)
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
scanner := bufio.NewScanner(strings.NewReader(string(body)))
|
// Copy headers and body
|
||||||
|
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
|
||||||
for scanner.Scan() {
|
if etag := resp.Header.Get("ETag"); etag != "" {
|
||||||
line := scanner.Text()
|
w.Header().Set("ETag", etag)
|
||||||
|
}
|
||||||
var crate crateIndexEntry
|
if lastMod := resp.Header.Get("Last-Modified"); lastMod != "" {
|
||||||
err := json.Unmarshal([]byte(line), &crate)
|
w.Header().Set("Last-Modified", lastMod)
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Error("failed to parse json entry in index", "error", err)
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
publishedAt, err := time.Parse(time.RFC3339, crate.PublishTime)
|
|
||||||
|
|
||||||
if crate.PublishTime == "" || err != nil {
|
|
||||||
_, _ = downstreamResponse.Write([]byte(line + "\n"))
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
cratePURL := canonicalPackagePURL("cargo", crate.Name)
|
|
||||||
|
|
||||||
if !h.proxy.Cooldown.IsAllowed("cargo", cratePURL, publishedAt) {
|
|
||||||
h.proxy.Logger.Info("cooldown: filtering cargo version",
|
|
||||||
"crate", crate.Name, "version", crate.Version,
|
|
||||||
"published", crate.PublishTime)
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
_, _ = downstreamResponse.Write([]byte(line + "\n"))
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if err := scanner.Err(); err != nil {
|
w.WriteHeader(http.StatusOK)
|
||||||
h.proxy.Logger.Error("error reading index response", "error", err)
|
_, _ = io.Copy(w, resp.Body)
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// buildIndexPath builds the sparse index path for a crate name.
|
// buildIndexPath builds the sparse index path for a crate name.
|
||||||
|
|
@ -171,11 +125,11 @@ func (h *CargoHandler) buildIndexPath(name string) string {
|
||||||
name = strings.ToLower(name)
|
name = strings.ToLower(name)
|
||||||
|
|
||||||
switch len(name) {
|
switch len(name) {
|
||||||
case cargoIndexLen1:
|
case 1:
|
||||||
return fmt.Sprintf("1/%s", name)
|
return fmt.Sprintf("1/%s", name)
|
||||||
case cargoIndexLen2:
|
case 2:
|
||||||
return fmt.Sprintf("2/%s", name)
|
return fmt.Sprintf("2/%s", name)
|
||||||
case cargoIndexLen3:
|
case 3:
|
||||||
return fmt.Sprintf("3/%c/%s", name[0], name)
|
return fmt.Sprintf("3/%c/%s", name[0], name)
|
||||||
default:
|
default:
|
||||||
return fmt.Sprintf("%s/%s/%s", name[0:2], name[2:4], name)
|
return fmt.Sprintf("%s/%s/%s", name[0:2], name[2:4], name)
|
||||||
|
|
@ -197,17 +151,10 @@ func (h *CargoHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
||||||
h.proxy.Logger.Info("cargo download request",
|
h.proxy.Logger.Info("cargo download request",
|
||||||
"crate", name, "version", version, "filename", filename)
|
"crate", name, "version", version, "filename", filename)
|
||||||
|
|
||||||
downloadURL := fmt.Sprintf(
|
result, err := h.proxy.GetOrFetchArtifact(r.Context(), "cargo", name, version, filename)
|
||||||
"%s/%s/%s",
|
|
||||||
h.downloadURL,
|
|
||||||
url.PathEscape(name),
|
|
||||||
url.PathEscape(filename),
|
|
||||||
)
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(
|
|
||||||
r.Context(), "cargo", name, version, filename, downloadURL,
|
|
||||||
)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch crate")
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
|
http.Error(w, "failed to fetch crate", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -2,22 +2,15 @@ package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"io"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"strings"
|
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/cooldown"
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func cargoTestProxy() *Proxy {
|
func cargoTestProxy() *Proxy {
|
||||||
return &Proxy{
|
return &Proxy{
|
||||||
Logger: slog.Default(),
|
Logger: slog.Default(),
|
||||||
HTTPClient: http.DefaultClient,
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -34,8 +27,8 @@ func TestCargoBuildIndexPath(t *testing.T) {
|
||||||
{"abcd", "ab/cd/abcd"},
|
{"abcd", "ab/cd/abcd"},
|
||||||
{"serde", "se/rd/serde"},
|
{"serde", "se/rd/serde"},
|
||||||
{"tokio", "to/ki/tokio"},
|
{"tokio", "to/ki/tokio"},
|
||||||
{"A", "1/a"}, // lowercase
|
{"A", "1/a"}, // lowercase
|
||||||
{"SERDE", "se/rd/serde"}, // lowercase
|
{"SERDE", "se/rd/serde"}, // lowercase
|
||||||
{"rand_core", "ra/nd/rand_core"},
|
{"rand_core", "ra/nd/rand_core"},
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -72,75 +65,6 @@ func TestCargoConfigEndpoint(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestCargoHandlerUsesConfiguredUpstreams(t *testing.T) {
|
|
||||||
t.Run("index", func(t *testing.T) {
|
|
||||||
var requestPath, authHeader string
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
requestPath = r.URL.Path
|
|
||||||
authHeader = r.Header.Get("Authorization")
|
|
||||||
if authHeader != "Bearer cargo-token" {
|
|
||||||
w.WriteHeader(http.StatusUnauthorized)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
w.Header().Set("Content-Type", "text/plain")
|
|
||||||
_, _ = io.WriteString(w, `{"name":"serde","vers":"1.0.0"}`)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
proxy.AuthForURL = func(string) (string, string) {
|
|
||||||
return "Authorization", "Bearer cargo-token"
|
|
||||||
}
|
|
||||||
h := NewCargoHandler(
|
|
||||||
proxy,
|
|
||||||
"http://proxy.test",
|
|
||||||
upstream.URL+"/index/",
|
|
||||||
"https://crates.example.test/files/",
|
|
||||||
)
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/se/rd/serde", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
|
|
||||||
}
|
|
||||||
if requestPath != "/index/se/rd/serde" {
|
|
||||||
t.Errorf("upstream path = %q, want %q", requestPath, "/index/se/rd/serde")
|
|
||||||
}
|
|
||||||
if authHeader != "Bearer cargo-token" {
|
|
||||||
t.Errorf("Authorization = %q, want %q", authHeader, "Bearer cargo-token")
|
|
||||||
}
|
|
||||||
})
|
|
||||||
|
|
||||||
t.Run("download", func(t *testing.T) {
|
|
||||||
proxy, _, _, artifactFetcher := setupTestProxy(t)
|
|
||||||
artifactFetcher.artifact = &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader("crate")),
|
|
||||||
ContentType: "application/gzip",
|
|
||||||
}
|
|
||||||
h := NewCargoHandler(
|
|
||||||
proxy,
|
|
||||||
"http://proxy.test",
|
|
||||||
"https://index.example.test/root/",
|
|
||||||
"https://crates.example.test/files/",
|
|
||||||
)
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/crates/serde/1.0.0/download", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
|
|
||||||
}
|
|
||||||
want := "https://crates.example.test/files/serde/serde-1.0.0.crate"
|
|
||||||
if artifactFetcher.fetchedURL != want {
|
|
||||||
t.Errorf("fetched URL = %q, want %q", artifactFetcher.fetchedURL, want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestCargoIndexProxy(t *testing.T) {
|
func TestCargoIndexProxy(t *testing.T) {
|
||||||
// Create a mock upstream index server
|
// Create a mock upstream index server
|
||||||
indexContent := `{"name":"serde","vers":"1.0.0","deps":[],"cksum":"abc123"}
|
indexContent := `{"name":"serde","vers":"1.0.0","deps":[],"cksum":"abc123"}
|
||||||
|
|
@ -221,57 +145,3 @@ func TestCargoRoutes(t *testing.T) {
|
||||||
t.Errorf("config.json status = %d, want %d", w.Code, http.StatusOK)
|
t.Errorf("config.json status = %d, want %d", w.Code, http.StatusOK)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
type filterTestCase struct {
|
|
||||||
line string
|
|
||||||
expected bool
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestCargoCooldown(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
|
|
||||||
createCase := func(name string, version string, age time.Duration, expected bool) filterTestCase {
|
|
||||||
return filterTestCase{line: `{"name":"` + name + `","vers":"` + version + `","cksum":"abcd","features":{},"yanked":false,"pubtime":"` + now.Add(-1*age).Format(time.RFC3339) + `"}`, expected: expected}
|
|
||||||
}
|
|
||||||
|
|
||||||
testCases := []filterTestCase{
|
|
||||||
// one week ago
|
|
||||||
createCase("serde", "1.0.0", 168*time.Hour, true),
|
|
||||||
// one hour ago
|
|
||||||
createCase("serde", "1.0.1", 1*time.Hour, false),
|
|
||||||
// two hours ago with custom filter (1h)
|
|
||||||
createCase("tokio", "1.0.0", 2*time.Hour, true),
|
|
||||||
// one hour ago with custom filter (1h)
|
|
||||||
createCase("tokio", "1.0.0", 1*time.Minute, false),
|
|
||||||
}
|
|
||||||
|
|
||||||
var testInput strings.Builder
|
|
||||||
var expectedOutput strings.Builder
|
|
||||||
|
|
||||||
for _, testCase := range testCases {
|
|
||||||
testInput.WriteString(testCase.line + "\n")
|
|
||||||
if testCase.expected {
|
|
||||||
expectedOutput.WriteString(testCase.line + "\n")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{
|
|
||||||
Default: "3d",
|
|
||||||
Packages: map[string]string{"pkg:cargo/tokio": "1h"},
|
|
||||||
}
|
|
||||||
|
|
||||||
h := &CargoHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
recorder := httptest.NewRecorder()
|
|
||||||
h.applyCooldownFiltering(recorder, []byte(testInput.String()))
|
|
||||||
output := recorder.Body.String()
|
|
||||||
|
|
||||||
if output != expectedOutput.String() {
|
|
||||||
t.Errorf("output = %q, want %q", output, expectedOutput.String())
|
|
||||||
}
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
|
||||||
|
|
@ -1,615 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"errors"
|
|
||||||
"io"
|
|
||||||
"strings"
|
|
||||||
"sync"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/artifacts"
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
|
||||||
|
|
||||||
// runConcurrent runs fn in n goroutines released together and returns their errors.
|
|
||||||
func runConcurrent(n int, fn func(i int) error) []error {
|
|
||||||
errs := make([]error, n)
|
|
||||||
start := make(chan struct{})
|
|
||||||
var wg sync.WaitGroup
|
|
||||||
for i := 0; i < n; i++ {
|
|
||||||
wg.Add(1)
|
|
||||||
go func(i int) {
|
|
||||||
defer wg.Done()
|
|
||||||
<-start
|
|
||||||
errs[i] = fn(i)
|
|
||||||
}(i)
|
|
||||||
}
|
|
||||||
close(start)
|
|
||||||
wg.Wait()
|
|
||||||
return errs
|
|
||||||
}
|
|
||||||
|
|
||||||
// artifactBody builds a one-shot upstream artifact carrying the given bytes.
|
|
||||||
func artifactBody(content string) *fetch.Artifact {
|
|
||||||
return &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader(content)),
|
|
||||||
ContentType: "application/gzip",
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// drain consumes and closes a CacheResult reader, if there is one.
|
|
||||||
func drain(res *CacheResult) {
|
|
||||||
if res != nil && res.Reader != nil {
|
|
||||||
_, _ = io.Copy(io.Discard, res.Reader)
|
|
||||||
_ = res.Reader.Close()
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesceKey_DifferentUpstreamHashDoesNotShare is the safety property that
|
|
||||||
// makes coalescing sound: callers expecting different bytes must never share a
|
|
||||||
// fetch, so a re-published version cannot serve stale bytes to a caller that
|
|
||||||
// asked for the new digest.
|
|
||||||
func TestCoalesceKey_DifferentUpstreamHashDoesNotShare(t *testing.T) {
|
|
||||||
const content = "artifact bytes"
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := &countingFetcher{content: content, delay: fetchHoldTime}
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
|
|
||||||
// The digest must carry the "sha256:" prefix; without it the API treats the
|
|
||||||
// value as unverifiable and clears the hash, which would legitimately let
|
|
||||||
// the two callers share one fetch.
|
|
||||||
hashes := []string{
|
|
||||||
"sha256:" + sha256Hex(content),
|
|
||||||
"sha256:" + sha256Hex("something else entirely"),
|
|
||||||
}
|
|
||||||
|
|
||||||
_ = runConcurrent(2, func(i int) error {
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURLWithDigest(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz",
|
|
||||||
"https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz", hashes[i])
|
|
||||||
drain(res)
|
|
||||||
return err
|
|
||||||
})
|
|
||||||
|
|
||||||
if got := fetcher.calls.Load(); got != 2 {
|
|
||||||
t.Errorf("upstream fetches = %d, want 2: callers expecting different digests must not share a fetch", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesceKey_HashCasingSharesOneFetch is the other half of that property.
|
|
||||||
// artifactHashMatches compares digests case-insensitively, so one digest in two
|
|
||||||
// casings describes one artifact and must not split into two fetches.
|
|
||||||
func TestCoalesceKey_HashCasingSharesOneFetch(t *testing.T) {
|
|
||||||
const content = "artifact bytes"
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := &countingFetcher{content: content, delay: fetchHoldTime}
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
|
|
||||||
hex := sha256Hex(content)
|
|
||||||
digests := []string{"sha256:" + hex, "sha256:" + strings.ToUpper(hex)}
|
|
||||||
|
|
||||||
for i, err := range runConcurrent(2, func(i int) error {
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURLWithDigest(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz",
|
|
||||||
"https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz", digests[i])
|
|
||||||
drain(res)
|
|
||||||
return err
|
|
||||||
}) {
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("caller %d failed: %v", i, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if got := fetcher.calls.Load(); got != 1 {
|
|
||||||
t.Errorf("upstream fetches = %d, want 1: one digest in two casings is one artifact", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesceKey_DifferentDownloadURLDoesNotShare covers the other half of the
|
|
||||||
// key: same package, different upstream URL, must not collapse into one fetch.
|
|
||||||
func TestCoalesceKey_DifferentDownloadURLDoesNotShare(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := &countingFetcher{content: "artifact bytes", delay: fetchHoldTime}
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
|
|
||||||
urls := []string{
|
|
||||||
"https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz",
|
|
||||||
"https://mirror.example.com/pkg/-/pkg-1.0.0.tgz",
|
|
||||||
}
|
|
||||||
|
|
||||||
_ = runConcurrent(2, func(i int) error {
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", urls[i])
|
|
||||||
drain(res)
|
|
||||||
return err
|
|
||||||
})
|
|
||||||
|
|
||||||
if got := fetcher.calls.Load(); got != 2 {
|
|
||||||
t.Errorf("upstream fetches = %d, want 2: different upstream URLs must not share a fetch", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesceKey_DistinctArtifactsDoNotSerialize guards against an over-broad
|
|
||||||
// key: four packages fetched at once must still produce four fetches.
|
|
||||||
func TestCoalesceKey_DistinctArtifactsDoNotSerialize(t *testing.T) {
|
|
||||||
const n = 4
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := &countingFetcher{content: "artifact bytes", delay: fetchHoldTime}
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
|
|
||||||
names := []string{"alpha", "beta", "gamma", "delta"}
|
|
||||||
errs := runConcurrent(n, func(i int) error {
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", names[i], "1.0.0", names[i]+"-1.0.0.tgz",
|
|
||||||
"https://registry.npmjs.org/"+names[i]+"/-/"+names[i]+"-1.0.0.tgz")
|
|
||||||
drain(res)
|
|
||||||
return err
|
|
||||||
})
|
|
||||||
for i, err := range errs {
|
|
||||||
if err != nil {
|
|
||||||
t.Errorf("caller %d (%s): %v", i, names[i], err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if got := fetcher.calls.Load(); got != n {
|
|
||||||
t.Errorf("upstream fetches = %d, want %d: distinct artifacts must not share a fetch", got, n)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesce_FailedFetchReachesEveryCallerAndIsRetriable verifies both claims
|
|
||||||
// in coalesceFetch's doc comment: a failed fetch reaches every caller sharing
|
|
||||||
// it, and the key is released so a later request retries.
|
|
||||||
func TestCoalesce_FailedFetchReachesEveryCallerAndIsRetriable(t *testing.T) {
|
|
||||||
const callers = 8
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
boom := errors.New("upstream unavailable")
|
|
||||||
fetcher.fetchErr = boom
|
|
||||||
|
|
||||||
errs := runConcurrent(callers, func(int) error {
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz",
|
|
||||||
"https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz")
|
|
||||||
drain(res)
|
|
||||||
return err
|
|
||||||
})
|
|
||||||
for i, err := range errs {
|
|
||||||
if err == nil {
|
|
||||||
t.Errorf("caller %d: got nil error, want the shared fetch's failure", i)
|
|
||||||
} else if !errors.Is(err, boom) {
|
|
||||||
t.Errorf("caller %d: got %v, want it to wrap %v", i, err, boom)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// The key must be released: a later request retries rather than inheriting
|
|
||||||
// the failure.
|
|
||||||
fetcher.fetchErr = nil
|
|
||||||
fetcher.artifact = artifactBody("recovered bytes")
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz",
|
|
||||||
"https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("retry after failed coalesced fetch: %v", err)
|
|
||||||
}
|
|
||||||
body, _ := io.ReadAll(res.Reader)
|
|
||||||
_ = res.Reader.Close()
|
|
||||||
if string(body) != "recovered bytes" {
|
|
||||||
t.Errorf("retry body = %q, want %q", body, "recovered bytes")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesce_ResolverPath covers the other entry point: GetOrFetchArtifact
|
|
||||||
// resolves the URL itself, so it is keyed without one.
|
|
||||||
func TestCoalesce_ResolverPath(t *testing.T) {
|
|
||||||
const callers = 8
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := &countingFetcher{content: "resolved artifact bytes", delay: fetchHoldTime}
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
|
|
||||||
errs := runConcurrent(callers, func(int) error {
|
|
||||||
res, err := proxy.GetOrFetchArtifact(context.Background(),
|
|
||||||
"npm", "left-pad", "1.3.0", "left-pad-1.3.0.tgz")
|
|
||||||
drain(res)
|
|
||||||
return err
|
|
||||||
})
|
|
||||||
for i, err := range errs {
|
|
||||||
if err != nil {
|
|
||||||
t.Errorf("caller %d: %v", i, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if got := fetcher.calls.Load(); got != 1 {
|
|
||||||
t.Errorf("upstream fetches = %d, want 1", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesce_ResolverPathEmptyFilename exercises that path when the filename
|
|
||||||
// is left to be resolved, which the key cannot know up front.
|
|
||||||
func TestCoalesce_ResolverPathEmptyFilename(t *testing.T) {
|
|
||||||
const callers = 8
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := &countingFetcher{content: "resolved artifact bytes", delay: fetchHoldTime}
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
|
|
||||||
errs := runConcurrent(callers, func(int) error {
|
|
||||||
res, err := proxy.GetOrFetchArtifact(context.Background(), "npm", "left-pad", "1.3.0", "")
|
|
||||||
drain(res)
|
|
||||||
return err
|
|
||||||
})
|
|
||||||
for i, err := range errs {
|
|
||||||
if err != nil {
|
|
||||||
t.Errorf("caller %d: %v", i, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if got := fetcher.calls.Load(); got != 1 {
|
|
||||||
t.Errorf("upstream fetches = %d, want 1", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesce_SubsequentRequestIsACacheHit confirms the coalesced fetch was
|
|
||||||
// committed and is visible later, not just streamed to the waiting callers.
|
|
||||||
func TestCoalesce_SubsequentRequestIsACacheHit(t *testing.T) {
|
|
||||||
const callers = 8
|
|
||||||
const url = "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz"
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := &countingFetcher{content: "artifact bytes", delay: fetchHoldTime}
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
|
|
||||||
_ = runConcurrent(callers, func(int) error {
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url)
|
|
||||||
drain(res)
|
|
||||||
return err
|
|
||||||
})
|
|
||||||
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("follow-up request: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = res.Reader.Close() }()
|
|
||||||
if !res.Cached {
|
|
||||||
t.Error("follow-up request should be served from cache")
|
|
||||||
}
|
|
||||||
if got := fetcher.calls.Load(); got != 1 {
|
|
||||||
t.Errorf("upstream fetches = %d, want 1 after a follow-up cache hit", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesce_ReadersAreIndependent guards openStoredArtifact: callers sharing
|
|
||||||
// a fetch each need their own reader, or one closing early breaks the rest.
|
|
||||||
func TestCoalesce_ReadersAreIndependent(t *testing.T) {
|
|
||||||
const callers = 8
|
|
||||||
const content = "artifact bytes that every caller must receive intact"
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := &countingFetcher{content: content, delay: fetchHoldTime}
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
|
|
||||||
results := make([]*CacheResult, callers)
|
|
||||||
errs := runConcurrent(callers, func(i int) error {
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz",
|
|
||||||
"https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz")
|
|
||||||
results[i] = res
|
|
||||||
return err
|
|
||||||
})
|
|
||||||
for i, err := range errs {
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("caller %d: %v", i, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Close the first caller's reader before anyone else has read a byte.
|
|
||||||
_ = results[0].Reader.Close()
|
|
||||||
|
|
||||||
for i := 1; i < callers; i++ {
|
|
||||||
body, err := io.ReadAll(results[i].Reader)
|
|
||||||
_ = results[i].Reader.Close()
|
|
||||||
if err != nil {
|
|
||||||
t.Errorf("caller %d read after another caller closed: %v", i, err)
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
if string(body) != content {
|
|
||||||
t.Errorf("caller %d got %q, want %q", i, body, content)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesce_CanceledWaiterDoesNotWaitForTheSharedFetch checks that joining a
|
|
||||||
// coalesced fetch does not cost a caller its own cancellation. Without the
|
|
||||||
// leader/waiter split a waiter is pinned until the shared fetch resolves,
|
|
||||||
// bounded only by the artifact client timeout, so clients that have already
|
|
||||||
// gone away keep handler goroutines alive for minutes.
|
|
||||||
func TestCoalesce_CanceledWaiterDoesNotWaitForTheSharedFetch(t *testing.T) {
|
|
||||||
const leaderFetch = 2 * time.Second
|
|
||||||
const url = "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz"
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := &countingFetcher{content: "artifact bytes", delay: leaderFetch, entered: make(chan struct{})}
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
|
|
||||||
leaderDone := make(chan error, 1)
|
|
||||||
go func() {
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url)
|
|
||||||
drain(res)
|
|
||||||
leaderDone <- err
|
|
||||||
}()
|
|
||||||
|
|
||||||
select {
|
|
||||||
case <-fetcher.entered: // the leader holds the key and is inside its fetch
|
|
||||||
case <-time.After(5 * time.Second):
|
|
||||||
t.Fatal("leader never started its fetch")
|
|
||||||
}
|
|
||||||
ctx, cancel := context.WithCancel(context.Background())
|
|
||||||
cancel()
|
|
||||||
|
|
||||||
start := time.Now()
|
|
||||||
_, err := proxy.GetOrFetchArtifactFromURL(ctx, "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url)
|
|
||||||
blocked := time.Since(start)
|
|
||||||
|
|
||||||
if !errors.Is(err, context.Canceled) {
|
|
||||||
t.Errorf("waiter error = %v, want context.Canceled", err)
|
|
||||||
}
|
|
||||||
if blocked > leaderFetch/4 {
|
|
||||||
t.Errorf("canceled waiter blocked %v, want well under %v: it is pinned to the shared fetch",
|
|
||||||
blocked, leaderFetch/4)
|
|
||||||
}
|
|
||||||
|
|
||||||
// A waiter leaving must not disturb the fetch the others share.
|
|
||||||
if err := <-leaderDone; err != nil {
|
|
||||||
t.Fatalf("leader failed after a waiter canceled: %v", err)
|
|
||||||
}
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("follow-up after leader completed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = res.Reader.Close() }()
|
|
||||||
if !res.Cached {
|
|
||||||
t.Error("leader's fetch should have been committed to the cache")
|
|
||||||
}
|
|
||||||
if got := fetcher.calls.Load(); got != 1 {
|
|
||||||
t.Errorf("upstream fetches = %d, want 1", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// inFlightLen reports how many coalesced fetches are currently registered.
|
|
||||||
func inFlightLen(p *Proxy) int {
|
|
||||||
p.fetchMu.Lock()
|
|
||||||
defer p.fetchMu.Unlock()
|
|
||||||
return len(p.inFlight)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesce_KeyIsReleasedAfterFetch guards the bug this hand-rolled map can
|
|
||||||
// have that singleflight could not: a key left behind means later callers join
|
|
||||||
// a finished entry, see its closed done channel, and are served that stale
|
|
||||||
// result forever, while the map grows without bound.
|
|
||||||
func TestCoalesce_KeyIsReleasedAfterFetch(t *testing.T) {
|
|
||||||
const url = "https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz"
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := &countingFetcher{content: "artifact bytes", delay: fetchHoldTime}
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
|
|
||||||
_ = runConcurrent(8, func(int) error {
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url)
|
|
||||||
drain(res)
|
|
||||||
return err
|
|
||||||
})
|
|
||||||
if n := inFlightLen(proxy); n != 0 {
|
|
||||||
t.Errorf("in-flight entries after a successful fetch = %d, want 0", n)
|
|
||||||
}
|
|
||||||
|
|
||||||
// A fresh miss for the same key must start a new fetch, not rejoin the old
|
|
||||||
// entry. Clearing the cache record forces the miss path again.
|
|
||||||
if err := proxy.ClearCachedArtifact(context.Background(), "npm", "pkg", "1.0.0", "pkg-1.0.0.tgz"); err != nil {
|
|
||||||
t.Fatalf("clear cached artifact: %v", err)
|
|
||||||
}
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", "pkg", "1.0.0", "pkg-1.0.0.tgz", url)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("second miss for the same key: %v", err)
|
|
||||||
}
|
|
||||||
drain(res)
|
|
||||||
if got := fetcher.calls.Load(); got != 2 {
|
|
||||||
t.Errorf("upstream fetches = %d, want 2: the second miss must not reuse the finished entry", got)
|
|
||||||
}
|
|
||||||
if n := inFlightLen(proxy); n != 0 {
|
|
||||||
t.Errorf("in-flight entries at end = %d, want 0", n)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// missingFromCache is a recheck that always reports a miss, so the shared fetch
|
|
||||||
// runs.
|
|
||||||
func missingFromCache() (artifacts.Artifact, string, bool) {
|
|
||||||
return artifacts.Artifact{}, "", false
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesce_LeaderRechecksCacheBeforeFetching covers the window between a
|
|
||||||
// caller's own cache lookup and it becoming the leader: a concurrent fetch can
|
|
||||||
// commit the artifact in that gap, and the leader must serve that rather than
|
|
||||||
// fetch it a second time.
|
|
||||||
func TestCoalesce_LeaderRechecksCacheBeforeFetching(t *testing.T) {
|
|
||||||
const content = "artifact bytes"
|
|
||||||
proxy, _, store, _ := setupTestProxy(t)
|
|
||||||
|
|
||||||
const storagePath = "npm/pkg/1.0.0/pkg-1.0.0.tgz"
|
|
||||||
if _, _, err := store.Store(context.Background(), storagePath, strings.NewReader(content)); err != nil {
|
|
||||||
t.Fatalf("seeding storage: %v", err)
|
|
||||||
}
|
|
||||||
committed := artifacts.Artifact{
|
|
||||||
PURL: "pkg:npm/pkg@1.0.0",
|
|
||||||
Filename: "pkg-1.0.0.tgz",
|
|
||||||
Size: int64(len(content)),
|
|
||||||
}
|
|
||||||
|
|
||||||
res, err := proxy.coalesceFetch(context.Background(), "any-key",
|
|
||||||
func() (artifacts.Artifact, string, bool) { return committed, storagePath, true },
|
|
||||||
func(context.Context) (artifacts.Artifact, string, error) {
|
|
||||||
t.Error("fetched an artifact that was already in the cache")
|
|
||||||
return artifacts.Artifact{}, "", errors.New("commit must not run")
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("coalesceFetch failed: %v", err)
|
|
||||||
}
|
|
||||||
defer drain(res)
|
|
||||||
got, err := io.ReadAll(res.Reader)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("reading result: %v", err)
|
|
||||||
}
|
|
||||||
if string(got) != content {
|
|
||||||
t.Errorf("got %q, want %q", got, content)
|
|
||||||
}
|
|
||||||
if n := inFlightLen(proxy); n != 0 {
|
|
||||||
t.Errorf("in-flight entries = %d, want 0", n)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCachedArtifactRecord covers the recheck itself: it must report the row a
|
|
||||||
// concurrent fetch committed, match its digest the way artifactHashMatches
|
|
||||||
// does, and report a miss for anything else.
|
|
||||||
func TestCachedArtifactRecord(t *testing.T) {
|
|
||||||
const (
|
|
||||||
content = "artifact bytes"
|
|
||||||
pkgPURL = "pkg:npm/pkg"
|
|
||||||
versionPURL = "pkg:npm/pkg@1.0.0"
|
|
||||||
filename = "pkg-1.0.0.tgz"
|
|
||||||
storagePath = "npm/pkg/1.0.0/pkg-1.0.0.tgz"
|
|
||||||
)
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
|
|
||||||
hex := sha256Hex(content)
|
|
||||||
committed := testArtifact(content, versionPURL, filename, "application/gzip")
|
|
||||||
if err := proxy.updateCacheDB("npm", "pkg", pkgPURL,
|
|
||||||
"https://registry.npmjs.org/pkg/-/pkg-1.0.0.tgz", storagePath, committed); err != nil {
|
|
||||||
t.Fatalf("seeding cache record: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tc := range []struct {
|
|
||||||
name, filename, hash string
|
|
||||||
want bool
|
|
||||||
}{
|
|
||||||
{"no upstream hash", filename, "", true},
|
|
||||||
{"matching hash", filename, hex, true},
|
|
||||||
{"matching hash in upper case", filename, strings.ToUpper(hex), true},
|
|
||||||
{"different hash", filename, sha256Hex("something else entirely"), false},
|
|
||||||
{"unknown filename", "pkg-1.0.0.zip", hex, false},
|
|
||||||
} {
|
|
||||||
t.Run(tc.name, func(t *testing.T) {
|
|
||||||
got, path, ok := proxy.cachedArtifactRecord(pkgPURL, versionPURL, tc.filename, tc.hash)
|
|
||||||
if ok != tc.want {
|
|
||||||
t.Fatalf("ok = %v, want %v", ok, tc.want)
|
|
||||||
}
|
|
||||||
if !ok {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if path != storagePath {
|
|
||||||
t.Errorf("storage path = %q, want %q", path, storagePath)
|
|
||||||
}
|
|
||||||
if got.Digest.Encoded() != hex {
|
|
||||||
t.Errorf("digest = %q, want %q", got.Digest.Encoded(), hex)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesce_LeaderFetchesWhenRecheckedBytesAreGone covers the other branch
|
|
||||||
// of the recheck: a record whose bytes no longer open is not served, and the
|
|
||||||
// shared fetch runs instead, the same recovery the cache lookup makes.
|
|
||||||
func TestCoalesce_LeaderFetchesWhenRecheckedBytesAreGone(t *testing.T) {
|
|
||||||
const content = "fetched bytes"
|
|
||||||
const storagePath = "npm/pkg/1.0.0/pkg-1.0.0.tgz"
|
|
||||||
proxy, _, store, _ := setupTestProxy(t)
|
|
||||||
|
|
||||||
stale := artifacts.Artifact{PURL: "pkg:npm/pkg@1.0.0", Filename: "pkg-1.0.0.tgz"}
|
|
||||||
if _, err := store.Open(context.Background(), storagePath); err == nil {
|
|
||||||
t.Fatal("stale bytes were present, so the test proves nothing")
|
|
||||||
}
|
|
||||||
|
|
||||||
// The leader runs commit on its own goroutine, so a plain counter is safe.
|
|
||||||
fetches := 0
|
|
||||||
res, err := proxy.coalesceFetch(context.Background(), "any-key",
|
|
||||||
func() (artifacts.Artifact, string, bool) { return stale, storagePath, true },
|
|
||||||
func(ctx context.Context) (artifacts.Artifact, string, error) {
|
|
||||||
fetches++
|
|
||||||
if _, _, err := store.Store(ctx, storagePath, strings.NewReader(content)); err != nil {
|
|
||||||
return artifacts.Artifact{}, "", err
|
|
||||||
}
|
|
||||||
return testArtifact(content, stale.PURL, stale.Filename, "application/gzip"), storagePath, nil
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("coalesceFetch failed: %v", err)
|
|
||||||
}
|
|
||||||
defer drain(res)
|
|
||||||
if fetches != 1 {
|
|
||||||
t.Errorf("shared fetches = %d, want 1: a record without bytes must be refetched", fetches)
|
|
||||||
}
|
|
||||||
got, err := io.ReadAll(res.Reader)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("reading result: %v", err)
|
|
||||||
}
|
|
||||||
if string(got) != content {
|
|
||||||
t.Errorf("got %q, want %q", got, content)
|
|
||||||
}
|
|
||||||
if n := inFlightLen(proxy); n != 0 {
|
|
||||||
t.Errorf("in-flight entries = %d, want 0", n)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestCoalesce_PanicInSharedFetchDoesNotStrandWaiters checks the failure mode
|
|
||||||
// that matters most: a caller parked on a shared fetch must never be left
|
|
||||||
// blocked forever when that fetch dies.
|
|
||||||
//
|
|
||||||
// This drives coalesceFetch directly and holds the shared entry itself, because
|
|
||||||
// whether a second caller has reached the wait is not observable from outside:
|
|
||||||
// it runs a cache lookup against the database first, so releasing the leader on
|
|
||||||
// a timer races that query. Losing the race made a second caller the leader
|
|
||||||
// instead of a waiter, and its panic was unrecovered, killing the test binary
|
|
||||||
// rather than failing the test.
|
|
||||||
func TestCoalesce_PanicInSharedFetchDoesNotStrandWaiters(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
const key = "pkg:npm/pkg@1.0.0\x00pkg-1.0.0.tgz"
|
|
||||||
|
|
||||||
inCommit := make(chan struct{})
|
|
||||||
release := make(chan struct{})
|
|
||||||
leaderPanicked := make(chan struct{})
|
|
||||||
|
|
||||||
go func() {
|
|
||||||
defer func() {
|
|
||||||
_ = recover() // the panic surfaces in the leader, as it would in a handler
|
|
||||||
close(leaderPanicked)
|
|
||||||
}()
|
|
||||||
_, _ = proxy.coalesceFetch(context.Background(), key, missingFromCache,
|
|
||||||
func(context.Context) (artifacts.Artifact, string, error) {
|
|
||||||
close(inCommit)
|
|
||||||
<-release
|
|
||||||
panic("upstream fetch exploded")
|
|
||||||
})
|
|
||||||
}()
|
|
||||||
|
|
||||||
<-inCommit // the leader holds the key and is inside the fetch
|
|
||||||
|
|
||||||
// Take the entry a waiter would park on, while the leader is still held.
|
|
||||||
proxy.fetchMu.Lock()
|
|
||||||
shared := proxy.inFlight[key]
|
|
||||||
proxy.fetchMu.Unlock()
|
|
||||||
if shared == nil {
|
|
||||||
t.Fatal("no in-flight entry registered for a running fetch")
|
|
||||||
}
|
|
||||||
|
|
||||||
close(release)
|
|
||||||
|
|
||||||
select {
|
|
||||||
case <-shared.done:
|
|
||||||
case <-time.After(5 * time.Second):
|
|
||||||
t.Fatal("waiter stranded: a panicking shared fetch never released its waiters")
|
|
||||||
}
|
|
||||||
if !errors.Is(shared.err, errSharedFetchAbandoned) {
|
|
||||||
t.Errorf("waiter error = %v, want errSharedFetchAbandoned", shared.err)
|
|
||||||
}
|
|
||||||
|
|
||||||
<-leaderPanicked
|
|
||||||
if n := inFlightLen(proxy); n != 0 {
|
|
||||||
t.Errorf("in-flight entries after a panic = %d, want 0", n)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,185 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bytes"
|
|
||||||
"context"
|
|
||||||
"io"
|
|
||||||
"log/slog"
|
|
||||||
"net/http"
|
|
||||||
"path/filepath"
|
|
||||||
"strings"
|
|
||||||
"sync"
|
|
||||||
"sync/atomic"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/proxy/internal/database"
|
|
||||||
"github.com/git-pkgs/proxy/internal/storage"
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
|
||||||
|
|
||||||
// fetchHoldTime holds each stub fetch open long enough that concurrent callers
|
|
||||||
// reliably overlap inside it. The exact value is not significant.
|
|
||||||
const fetchHoldTime = 50 * time.Millisecond
|
|
||||||
|
|
||||||
// countingFetcher counts upstream fetches and holds each one open.
|
|
||||||
type countingFetcher struct {
|
|
||||||
calls atomic.Int64
|
|
||||||
content string
|
|
||||||
delay time.Duration
|
|
||||||
|
|
||||||
// entered, if set, is closed when the first fetch begins. A test can wait
|
|
||||||
// on it to know the leader holds the key, rather than guessing with a
|
|
||||||
// sleep.
|
|
||||||
entered chan struct{}
|
|
||||||
enterOnce sync.Once
|
|
||||||
}
|
|
||||||
|
|
||||||
func (f *countingFetcher) Fetch(ctx context.Context, url string) (*fetch.Artifact, error) {
|
|
||||||
return f.FetchWithHeaders(ctx, url, nil)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (f *countingFetcher) FetchWithHeaders(_ context.Context, _ string, _ http.Header) (*fetch.Artifact, error) {
|
|
||||||
f.calls.Add(1)
|
|
||||||
if f.entered != nil {
|
|
||||||
f.enterOnce.Do(func() { close(f.entered) })
|
|
||||||
}
|
|
||||||
time.Sleep(f.delay)
|
|
||||||
return &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader(f.content)),
|
|
||||||
ContentType: "application/gzip",
|
|
||||||
}, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (f *countingFetcher) Head(context.Context, string) (int64, string, error) {
|
|
||||||
return 0, "", nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestGetOrFetchArtifactFromURL_ConcurrentMissesCoalesce asserts that N
|
|
||||||
// simultaneous misses for one artifact produce a single upstream fetch. That is
|
|
||||||
// the CI shape: parallel jobs installing overlapping dependencies cold.
|
|
||||||
func TestGetOrFetchArtifactFromURL_ConcurrentMissesCoalesce(t *testing.T) {
|
|
||||||
const goroutines = 8
|
|
||||||
const content = "left-pad tarball bytes"
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := &countingFetcher{content: content, delay: fetchHoldTime}
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
|
|
||||||
start := make(chan struct{})
|
|
||||||
var wg sync.WaitGroup
|
|
||||||
errs := make([]error, goroutines)
|
|
||||||
bodies := make([]string, goroutines)
|
|
||||||
|
|
||||||
for i := 0; i < goroutines; i++ {
|
|
||||||
wg.Add(1)
|
|
||||||
go func(i int) {
|
|
||||||
defer wg.Done()
|
|
||||||
<-start
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"npm", "left-pad", "1.3.0", "left-pad-1.3.0.tgz",
|
|
||||||
"https://registry.npmjs.org/left-pad/-/left-pad-1.3.0.tgz")
|
|
||||||
if err != nil {
|
|
||||||
errs[i] = err
|
|
||||||
return
|
|
||||||
}
|
|
||||||
defer func() { _ = res.Reader.Close() }()
|
|
||||||
b, err := io.ReadAll(res.Reader)
|
|
||||||
errs[i] = err
|
|
||||||
bodies[i] = string(b)
|
|
||||||
}(i)
|
|
||||||
}
|
|
||||||
|
|
||||||
close(start)
|
|
||||||
wg.Wait()
|
|
||||||
|
|
||||||
for i, err := range errs {
|
|
||||||
if err != nil {
|
|
||||||
t.Errorf("goroutine %d: unexpected error: %v", i, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
// Every caller must get its own intact copy of the bytes.
|
|
||||||
for i, b := range bodies {
|
|
||||||
if b != content {
|
|
||||||
t.Errorf("goroutine %d: body = %q, want %q", i, b, content)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if got := fetcher.calls.Load(); got != 1 {
|
|
||||||
t.Errorf("upstream fetches = %d, want 1 (%d concurrent callers stampeded the upstream)", got, goroutines)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestGetOrFetchArtifactFromURL_ConcurrentMissesFileStorage runs the same
|
|
||||||
// scenario against the real file:// backend, the default in production.
|
|
||||||
//
|
|
||||||
// Uncoalesced this fails outright, not merely wastefully. Every caller stores
|
|
||||||
// to one key, and fileblob rewrites a ".attrs" sidecar per key with os.Create,
|
|
||||||
// truncating in place outside the rename that protects the blob. Decoding that
|
|
||||||
// sidecar mid-truncate gives "opening reader: EOF", served as a 502.
|
|
||||||
//
|
|
||||||
// Only the fetcher is stubbed, because the real one refuses loopback so an
|
|
||||||
// httptest upstream is unreachable. The storage, where this fails, is real.
|
|
||||||
func TestGetOrFetchArtifactFromURL_ConcurrentMissesFileStorage(t *testing.T) {
|
|
||||||
const goroutines = 16
|
|
||||||
content := bytes.Repeat([]byte("tarball-bytes-"), 512)
|
|
||||||
|
|
||||||
ctx := context.Background()
|
|
||||||
dir := t.TempDir()
|
|
||||||
|
|
||||||
db, err := database.Create(filepath.Join(dir, "test.db"))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("create database: %v", err)
|
|
||||||
}
|
|
||||||
t.Cleanup(func() { _ = db.Close() })
|
|
||||||
|
|
||||||
store, err := storage.OpenBucket(ctx, "file://"+filepath.Join(dir, "cache"))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("open storage: %v", err)
|
|
||||||
}
|
|
||||||
t.Cleanup(func() { _ = store.Close() })
|
|
||||||
|
|
||||||
fetcher := &countingFetcher{content: string(content), delay: fetchHoldTime}
|
|
||||||
proxy := NewProxy(db, store, fetcher, fetch.NewResolver(),
|
|
||||||
slog.New(slog.NewTextHandler(io.Discard, nil)))
|
|
||||||
|
|
||||||
start := make(chan struct{})
|
|
||||||
var wg sync.WaitGroup
|
|
||||||
errs := make([]error, goroutines)
|
|
||||||
bodies := make([][]byte, goroutines)
|
|
||||||
|
|
||||||
for i := 0; i < goroutines; i++ {
|
|
||||||
wg.Add(1)
|
|
||||||
go func(i int) {
|
|
||||||
defer wg.Done()
|
|
||||||
<-start
|
|
||||||
res, err := proxy.GetOrFetchArtifactFromURL(ctx,
|
|
||||||
"npm", "left-pad", "1.3.0", "left-pad-1.3.0.tgz",
|
|
||||||
"https://registry.npmjs.org/left-pad/-/left-pad-1.3.0.tgz")
|
|
||||||
if err != nil {
|
|
||||||
errs[i] = err
|
|
||||||
return
|
|
||||||
}
|
|
||||||
defer func() { _ = res.Reader.Close() }()
|
|
||||||
body, readErr := io.ReadAll(res.Reader)
|
|
||||||
errs[i] = readErr
|
|
||||||
bodies[i] = body
|
|
||||||
}(i)
|
|
||||||
}
|
|
||||||
|
|
||||||
close(start)
|
|
||||||
wg.Wait()
|
|
||||||
|
|
||||||
for i, err := range errs {
|
|
||||||
if err != nil {
|
|
||||||
t.Errorf("caller %d failed: %v", i, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
for i, body := range bodies {
|
|
||||||
if !bytes.Equal(body, content) {
|
|
||||||
t.Errorf("caller %d got %d bytes, want %d", i, len(body), len(content))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if got := fetcher.calls.Load(); got != 1 {
|
|
||||||
t.Errorf("upstream fetches = %d, want 1", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,22 +1,16 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"errors"
|
|
||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"path"
|
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
composerUpstream = "https://packagist.org"
|
composerUpstream = "https://packagist.org"
|
||||||
composerRepo = "https://repo.packagist.org"
|
composerRepo = "https://repo.packagist.org"
|
||||||
composerUnset = "__unset"
|
|
||||||
vendorPackageParts = 2
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// ComposerHandler handles Composer/Packagist registry protocol requests.
|
// ComposerHandler handles Composer/Packagist registry protocol requests.
|
||||||
|
|
@ -37,15 +31,6 @@ func NewComposerHandler(proxy *Proxy, proxyURL string) *ComposerHandler {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewComposerHandlerWithUpstreams creates a Composer handler with custom API
|
|
||||||
// and repository upstreams.
|
|
||||||
func NewComposerHandlerWithUpstreams(proxy *Proxy, proxyURL, upstreamURL, repoURL string) *ComposerHandler {
|
|
||||||
h := NewComposerHandler(proxy, proxyURL)
|
|
||||||
h.upstreamURL = configuredUpstreamURL(upstreamURL, composerUpstream)
|
|
||||||
h.repoURL = configuredUpstreamURL(repoURL, composerRepo)
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for Composer requests.
|
// Routes returns the HTTP handler for Composer requests.
|
||||||
func (h *ComposerHandler) Routes() http.Handler {
|
func (h *ComposerHandler) Routes() http.Handler {
|
||||||
mux := http.NewServeMux()
|
mux := http.NewServeMux()
|
||||||
|
|
@ -70,14 +55,14 @@ func (h *ComposerHandler) Routes() http.Handler {
|
||||||
func (h *ComposerHandler) handleServiceIndex(w http.ResponseWriter, r *http.Request) {
|
func (h *ComposerHandler) handleServiceIndex(w http.ResponseWriter, r *http.Request) {
|
||||||
// Return a minimal service index pointing to our proxy
|
// Return a minimal service index pointing to our proxy
|
||||||
index := map[string]any{
|
index := map[string]any{
|
||||||
"packages": map[string]any{},
|
"packages": map[string]any{},
|
||||||
"metadata-url": h.proxyURL + "/composer/p2/%package%.json",
|
"metadata-url": h.proxyURL + "/composer/p2/%package%.json",
|
||||||
"notify-batch": h.upstreamURL + "/downloads/",
|
"notify-batch": h.upstreamURL + "/downloads/",
|
||||||
"search": h.proxyURL + "/composer/search.json?q=%query%&type=%type%",
|
"search": h.proxyURL + "/composer/search.json?q=%query%&type=%type%",
|
||||||
"providers-lazy-url": h.proxyURL + "/composer/p2/%package%.json",
|
"providers-lazy-url": h.proxyURL + "/composer/p2/%package%.json",
|
||||||
}
|
}
|
||||||
|
|
||||||
w.Header().Set(headerContentType, "application/json")
|
w.Header().Set("Content-Type", "application/json")
|
||||||
_ = json.NewEncoder(w).Encode(index)
|
_ = json.NewEncoder(w).Encode(index)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -86,8 +71,8 @@ func (h *ComposerHandler) handlePackageMetadata(w http.ResponseWriter, r *http.R
|
||||||
// Parse path: /p2/{vendor}/{package}.json
|
// Parse path: /p2/{vendor}/{package}.json
|
||||||
path := strings.TrimPrefix(r.URL.Path, "/p2/")
|
path := strings.TrimPrefix(r.URL.Path, "/p2/")
|
||||||
path = strings.TrimSuffix(path, ".json")
|
path = strings.TrimSuffix(path, ".json")
|
||||||
parts := strings.SplitN(path, "/", vendorPackageParts)
|
parts := strings.SplitN(path, "/", 2)
|
||||||
if len(parts) != vendorPackageParts || parts[0] == "" || parts[1] == "" {
|
if len(parts) != 2 || parts[0] == "" || parts[1] == "" {
|
||||||
http.Error(w, "invalid package path", http.StatusBadRequest)
|
http.Error(w, "invalid package path", http.StatusBadRequest)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
@ -97,35 +82,48 @@ func (h *ComposerHandler) handlePackageMetadata(w http.ResponseWriter, r *http.R
|
||||||
|
|
||||||
h.proxy.Logger.Info("composer metadata request", "package", packageName)
|
h.proxy.Logger.Info("composer metadata request", "package", packageName)
|
||||||
|
|
||||||
|
// Fetch from repo.packagist.org (Composer v2 metadata)
|
||||||
upstreamURL := fmt.Sprintf("%s/p2/%s/%s.json", h.repoURL, vendor, pkg)
|
upstreamURL := fmt.Sprintf("%s/p2/%s/%s.json", h.repoURL, vendor, pkg)
|
||||||
|
|
||||||
body, _, err := h.proxy.FetchOrCacheMetadata(r.Context(), "composer", packageName, upstreamURL)
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, "failed to create request", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if errors.Is(err, ErrUpstreamNotFound) {
|
|
||||||
http.Error(w, "not found", http.StatusNotFound)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Error("upstream request failed", "error", err)
|
h.proxy.Logger.Error("upstream request failed", "error", err)
|
||||||
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
if resp.StatusCode != http.StatusOK {
|
||||||
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
body, err := io.ReadAll(resp.Body)
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, "failed to read response", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
rewritten, err := h.rewriteMetadata(body)
|
rewritten, err := h.rewriteMetadata(body)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.Logger.Warn("failed to rewrite metadata, proxying original", "error", err)
|
h.proxy.Logger.Warn("failed to rewrite metadata, proxying original", "error", err)
|
||||||
w.Header().Set(headerContentType, "application/json")
|
w.Header().Set("Content-Type", "application/json")
|
||||||
_, _ = w.Write(body)
|
_, _ = w.Write(body)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
w.Header().Set(headerContentType, "application/json")
|
w.Header().Set("Content-Type", "application/json")
|
||||||
_, _ = w.Write(rewritten)
|
_, _ = w.Write(rewritten)
|
||||||
}
|
}
|
||||||
|
|
||||||
// rewriteMetadata rewrites dist URLs in Composer metadata to point at this proxy.
|
// rewriteMetadata rewrites dist URLs in Composer metadata to point at this proxy.
|
||||||
// If the metadata uses the minified Composer v2 format, it is expanded first so
|
|
||||||
// that every version entry contains all fields. If cooldown is enabled, versions
|
|
||||||
// published too recently are filtered out.
|
|
||||||
func (h *ComposerHandler) rewriteMetadata(body []byte) ([]byte, error) {
|
func (h *ComposerHandler) rewriteMetadata(body []byte) ([]byte, error) {
|
||||||
var metadata map[string]any
|
var metadata map[string]any
|
||||||
if err := json.Unmarshal(body, &metadata); err != nil {
|
if err := json.Unmarshal(body, &metadata); err != nil {
|
||||||
|
|
@ -137,170 +135,44 @@ func (h *ComposerHandler) rewriteMetadata(body []byte) ([]byte, error) {
|
||||||
return body, nil
|
return body, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
minified := metadata["minified"] == "composer/2.0"
|
|
||||||
|
|
||||||
for packageName, versions := range packages {
|
for packageName, versions := range packages {
|
||||||
versionList, ok := versions.([]any)
|
versionList, ok := versions.([]any)
|
||||||
if !ok {
|
if !ok {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
|
||||||
if minified {
|
for _, v := range versionList {
|
||||||
versionList = expandMinifiedVersions(versionList)
|
vmap, ok := v.(map[string]any)
|
||||||
}
|
if !ok {
|
||||||
|
|
||||||
packages[packageName] = h.filterAndRewriteVersions(packageName, versionList)
|
|
||||||
}
|
|
||||||
|
|
||||||
delete(metadata, "minified")
|
|
||||||
|
|
||||||
return json.Marshal(metadata)
|
|
||||||
}
|
|
||||||
|
|
||||||
// expandMinifiedVersions expands the Composer v2 minified format where each
|
|
||||||
// version entry only contains fields that differ from the previous entry.
|
|
||||||
// The "~dev" sentinel string resets the inheritance chain, and the "__unset"
|
|
||||||
// value removes a field from the inherited state.
|
|
||||||
func expandMinifiedVersions(versionList []any) []any {
|
|
||||||
expanded := make([]any, 0, len(versionList))
|
|
||||||
inherited := map[string]any{}
|
|
||||||
|
|
||||||
for _, v := range versionList {
|
|
||||||
// The "~dev" sentinel resets the inheritance chain for dev versions.
|
|
||||||
if s, ok := v.(string); ok && s == "~dev" {
|
|
||||||
inherited = map[string]any{}
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
vmap, ok := v.(map[string]any)
|
|
||||||
if !ok {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
// Merge inherited fields into a new map, then overlay current fields.
|
|
||||||
// Deep copy values to avoid shared references between versions.
|
|
||||||
merged := make(map[string]any, len(inherited)+len(vmap))
|
|
||||||
for k, val := range inherited {
|
|
||||||
merged[k] = deepCopyValue(val)
|
|
||||||
}
|
|
||||||
for k, val := range vmap {
|
|
||||||
if val == composerUnset {
|
|
||||||
delete(merged, k)
|
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
merged[k] = val
|
|
||||||
}
|
|
||||||
|
|
||||||
// Update inherited state for next iteration.
|
version, _ := vmap["version"].(string)
|
||||||
inherited = merged
|
dist, ok := vmap["dist"].(map[string]any)
|
||||||
|
if !ok {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
|
||||||
expanded = append(expanded, merged)
|
// Rewrite the dist URL
|
||||||
}
|
if url, ok := dist["url"].(string); ok && url != "" {
|
||||||
|
// Extract filename from URL
|
||||||
|
filename := "package.zip"
|
||||||
|
if idx := strings.LastIndex(url, "/"); idx >= 0 {
|
||||||
|
filename = url[idx+1:]
|
||||||
|
}
|
||||||
|
|
||||||
return expanded
|
// Build new URL through our proxy
|
||||||
}
|
parts := strings.SplitN(packageName, "/", 2)
|
||||||
|
if len(parts) == 2 {
|
||||||
// deepCopyValue returns a deep copy of JSON-like values (maps, slices, scalars).
|
newURL := fmt.Sprintf("%s/composer/files/%s/%s/%s/%s",
|
||||||
func deepCopyValue(v any) any {
|
h.proxyURL, parts[0], parts[1], version, filename)
|
||||||
switch val := v.(type) {
|
dist["url"] = newURL
|
||||||
case map[string]any:
|
}
|
||||||
m := make(map[string]any, len(val))
|
}
|
||||||
for k, v := range val {
|
|
||||||
m[k] = deepCopyValue(v)
|
|
||||||
}
|
|
||||||
return m
|
|
||||||
case []any:
|
|
||||||
s := make([]any, len(val))
|
|
||||||
for i, v := range val {
|
|
||||||
s[i] = deepCopyValue(v)
|
|
||||||
}
|
|
||||||
return s
|
|
||||||
default:
|
|
||||||
return v
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// filterAndRewriteVersions applies cooldown filtering and rewrites dist URLs
|
|
||||||
// for a single package's version list.
|
|
||||||
func (h *ComposerHandler) filterAndRewriteVersions(packageName string, versionList []any) []any {
|
|
||||||
packagePURL := canonicalPackagePURL("composer", packageName)
|
|
||||||
|
|
||||||
filtered := versionList[:0]
|
|
||||||
for _, v := range versionList {
|
|
||||||
vmap, ok := v.(map[string]any)
|
|
||||||
if !ok {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
version, _ := vmap["version"].(string)
|
|
||||||
|
|
||||||
if h.shouldFilterVersion(packagePURL, packageName, version, vmap) {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
h.rewriteDistURL(vmap, packageName, version)
|
|
||||||
filtered = append(filtered, v)
|
|
||||||
}
|
|
||||||
|
|
||||||
return filtered
|
|
||||||
}
|
|
||||||
|
|
||||||
// shouldFilterVersion returns true if the version should be excluded due to cooldown.
|
|
||||||
func (h *ComposerHandler) shouldFilterVersion(packagePURL, packageName, version string, vmap map[string]any) bool {
|
|
||||||
if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
timeStr, ok := vmap["time"].(string)
|
|
||||||
if !ok {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
publishedAt, err := time.Parse(time.RFC3339, timeStr)
|
|
||||||
if err != nil {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
if !h.proxy.Cooldown.IsAllowed("composer", packagePURL, publishedAt) {
|
|
||||||
h.proxy.Logger.Info("cooldown: filtering composer version",
|
|
||||||
"package", packageName, "version", version)
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
// rewriteDistURL rewrites the dist URL in a version entry to point at this proxy.
|
|
||||||
func (h *ComposerHandler) rewriteDistURL(vmap map[string]any, packageName, version string) {
|
|
||||||
dist, ok := vmap["dist"].(map[string]any)
|
|
||||||
if !ok {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
url, ok := dist["url"].(string)
|
|
||||||
if !ok || url == "" {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
filename := "package.zip"
|
|
||||||
if idx := strings.LastIndex(url, "/"); idx >= 0 {
|
|
||||||
filename = url[idx+1:]
|
|
||||||
}
|
|
||||||
|
|
||||||
// GitHub zipball URLs end with a bare commit hash (no extension).
|
|
||||||
// Append .zip so the archives library can detect the format.
|
|
||||||
if path.Ext(filename) == "" {
|
|
||||||
if distType, _ := dist["type"].(string); distType == "zip" {
|
|
||||||
filename += ".zip"
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
parts := strings.SplitN(packageName, "/", vendorPackageParts)
|
return json.Marshal(metadata)
|
||||||
if len(parts) == vendorPackageParts {
|
|
||||||
newURL := fmt.Sprintf("%s/composer/files/%s/%s/%s/%s",
|
|
||||||
h.proxyURL, parts[0], parts[1], version, filename)
|
|
||||||
dist["url"] = newURL
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleDownload serves a package file, fetching and caching from upstream if needed.
|
// handleDownload serves a package file, fetching and caching from upstream if needed.
|
||||||
|
|
@ -315,127 +187,50 @@ func (h *ComposerHandler) handleDownload(w http.ResponseWriter, r *http.Request)
|
||||||
h.proxy.Logger.Info("composer download request",
|
h.proxy.Logger.Info("composer download request",
|
||||||
"package", packageName, "version", version, "filename", filename)
|
"package", packageName, "version", version, "filename", filename)
|
||||||
|
|
||||||
// We need to fetch the metadata to get the actual download URL since
|
// We need to fetch the metadata to get the actual download URL
|
||||||
// Packagist URLs include a hash. Packagist serves dev versions (e.g.
|
// since Packagist URLs include a hash
|
||||||
// "3.x-dev", "dev-master") from a separate "~dev" metadata file, while
|
metaURL := fmt.Sprintf("%s/p2/%s/%s.json", h.repoURL, vendor, pkg)
|
||||||
// tagged releases live in the regular file. Try the file most likely to
|
|
||||||
// contain this version first, then fall back to the other so that both
|
|
||||||
// stable and dev versions resolve correctly.
|
|
||||||
metaURLs := h.metadataURLsForVersion(vendor, pkg, version)
|
|
||||||
|
|
||||||
h.proxy.Logger.Debug("resolving download URL",
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, metaURL, nil)
|
||||||
"package", packageName, "version", version,
|
if err != nil {
|
||||||
"metadata_urls", metaURLs)
|
http.Error(w, "failed to create request", http.StatusInternalServerError)
|
||||||
|
|
||||||
var downloadURL string
|
|
||||||
for _, metaURL := range metaURLs {
|
|
||||||
url, err := h.findDownloadURLFromMetadata(r.Context(), metaURL, packageName, version)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Error("failed to fetch metadata", "error", err, "url", metaURL)
|
|
||||||
http.Error(w, "failed to fetch metadata", http.StatusBadGateway)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if url != "" {
|
|
||||||
downloadURL = url
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if downloadURL == "" {
|
|
||||||
h.proxy.Logger.Debug("version not found in any metadata source",
|
|
||||||
"package", packageName, "version", version,
|
|
||||||
"tried_urls", metaURLs)
|
|
||||||
http.Error(w, "version not found", http.StatusNotFound)
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
h.proxy.Logger.Debug("resolved download URL",
|
resp, err := http.DefaultClient.Do(req)
|
||||||
"package", packageName, "version", version,
|
|
||||||
"download_url", downloadURL)
|
|
||||||
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "composer", packageName, version, filename, downloadURL)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch package")
|
h.proxy.Logger.Error("failed to fetch metadata", "error", err)
|
||||||
|
http.Error(w, "failed to fetch metadata", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
ServeArtifact(w, result)
|
|
||||||
}
|
|
||||||
|
|
||||||
// isDevVersion reports whether a Composer version string refers to a
|
|
||||||
// development (unstable, branch) version rather than a tagged release.
|
|
||||||
// Composer formats these as either "dev-<branch>" (e.g. "dev-master") or
|
|
||||||
// "<alias>-dev" (e.g. "3.x-dev").
|
|
||||||
func isDevVersion(version string) bool {
|
|
||||||
return strings.HasPrefix(version, "dev-") || strings.HasSuffix(version, "-dev")
|
|
||||||
}
|
|
||||||
|
|
||||||
// metadataURLsForVersion returns the upstream metadata URLs to consult for a
|
|
||||||
// given version, in priority order. Dev versions are served from the "~dev"
|
|
||||||
// file, tagged releases from the regular file; the other file is included as a
|
|
||||||
// fallback so an unexpected classification still resolves.
|
|
||||||
func (h *ComposerHandler) metadataURLsForVersion(vendor, pkg, version string) []string {
|
|
||||||
stable := fmt.Sprintf("%s/p2/%s/%s.json", h.repoURL, vendor, pkg)
|
|
||||||
dev := fmt.Sprintf("%s/p2/%s/%s~dev.json", h.repoURL, vendor, pkg)
|
|
||||||
|
|
||||||
if isDevVersion(version) {
|
|
||||||
return []string{dev, stable}
|
|
||||||
}
|
|
||||||
return []string{stable, dev}
|
|
||||||
}
|
|
||||||
|
|
||||||
// findDownloadURLFromMetadata fetches a metadata document and returns the dist
|
|
||||||
// URL for the given version, or an empty string if the version is not present.
|
|
||||||
// An error is returned only on transport failure; a missing document (non-200)
|
|
||||||
// or a missing version both yield an empty string so the caller can fall back.
|
|
||||||
func (h *ComposerHandler) findDownloadURLFromMetadata(ctx context.Context, metaURL, packageName, version string) (string, error) {
|
|
||||||
h.proxy.Logger.Debug("fetching upstream metadata for download lookup",
|
|
||||||
"url", metaURL, "package", packageName, "version", version)
|
|
||||||
|
|
||||||
req, err := http.NewRequestWithContext(ctx, http.MethodGet, metaURL, nil)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
h.proxy.Logger.Debug("upstream metadata response",
|
|
||||||
"url", metaURL, "status", resp.StatusCode)
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
if resp.StatusCode != http.StatusOK {
|
||||||
return "", nil
|
http.Error(w, "package not found", http.StatusNotFound)
|
||||||
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
var metadata map[string]any
|
var metadata map[string]any
|
||||||
if err := json.NewDecoder(resp.Body).Decode(&metadata); err != nil {
|
if err := json.NewDecoder(resp.Body).Decode(&metadata); err != nil {
|
||||||
return "", err
|
http.Error(w, "failed to parse metadata", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// Expand minified Composer v2 format so that inherited fields (including
|
// Find the download URL for this version
|
||||||
// dist) are present on every version entry. Without this, versions that
|
downloadURL := h.findDownloadURL(metadata, packageName, version)
|
||||||
// inherit dist from a previous entry will appear to have no download URL.
|
if downloadURL == "" {
|
||||||
if metadata["minified"] == "composer/2.0" {
|
http.Error(w, "version not found", http.StatusNotFound)
|
||||||
h.proxy.Logger.Debug("expanding minified metadata", "url", metaURL)
|
return
|
||||||
if packages, ok := metadata["packages"].(map[string]any); ok {
|
|
||||||
for pkgName, versions := range packages {
|
|
||||||
versionList, ok := versions.([]any)
|
|
||||||
if !ok {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
packages[pkgName] = expandMinifiedVersions(versionList)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
url := h.findDownloadURL(metadata, packageName, version)
|
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "composer", packageName, version, filename, downloadURL)
|
||||||
h.proxy.Logger.Debug("download URL lookup result",
|
if err != nil {
|
||||||
"url", metaURL, "package", packageName, "version", version,
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
"download_url", url)
|
http.Error(w, "failed to fetch package", http.StatusBadGateway)
|
||||||
return url, nil
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
ServeArtifact(w, result)
|
||||||
}
|
}
|
||||||
|
|
||||||
// findDownloadURL finds the dist URL for a specific version in metadata.
|
// findDownloadURL finds the dist URL for a specific version in metadata.
|
||||||
|
|
@ -483,7 +278,7 @@ func (h *ComposerHandler) proxyUpstream(w http.ResponseWriter, r *http.Request)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
resp, err := http.DefaultClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.Logger.Error("upstream request failed", "error", err)
|
h.proxy.Logger.Error("upstream request failed", "error", err)
|
||||||
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
||||||
|
|
|
||||||
|
|
@ -1,616 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"encoding/json"
|
|
||||||
"log/slog"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/cooldown"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestComposerRewriteMetadata(t *testing.T) {
|
|
||||||
h := &ComposerHandler{
|
|
||||||
proxy: testProxy(),
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
input := `{
|
|
||||||
"packages": {
|
|
||||||
"symfony/console": [
|
|
||||||
{
|
|
||||||
"version": "6.0.0",
|
|
||||||
"dist": {
|
|
||||||
"url": "https://repo.packagist.org/files/symfony/console/6.0.0/abc123.zip",
|
|
||||||
"type": "zip"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
output, err := h.rewriteMetadata([]byte(input))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("rewriteMetadata failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(output, &result); err != nil {
|
|
||||||
t.Fatalf("failed to parse output: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := result["packages"].(map[string]any)
|
|
||||||
versions := packages["symfony/console"].([]any)
|
|
||||||
v := versions[0].(map[string]any)
|
|
||||||
dist := v["dist"].(map[string]any)
|
|
||||||
|
|
||||||
expected := "http://localhost:8080/composer/files/symfony/console/6.0.0/abc123.zip"
|
|
||||||
if dist["url"] != expected {
|
|
||||||
t.Errorf("dist url = %q, want %q", dist["url"], expected)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestComposerRewriteMetadataExpandsMinified(t *testing.T) {
|
|
||||||
h := &ComposerHandler{
|
|
||||||
proxy: testProxy(),
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
// Minified format: first version has all fields, subsequent versions
|
|
||||||
// only include fields that changed. The proxy must expand this so every
|
|
||||||
// version has all fields (including "name").
|
|
||||||
input := `{
|
|
||||||
"minified": "composer/2.0",
|
|
||||||
"packages": {
|
|
||||||
"symfony/console": [
|
|
||||||
{
|
|
||||||
"name": "symfony/console",
|
|
||||||
"description": "Symfony Console Component",
|
|
||||||
"version": "6.0.0",
|
|
||||||
"dist": {
|
|
||||||
"url": "https://repo.packagist.org/files/symfony/console/6.0.0/abc123.zip",
|
|
||||||
"type": "zip"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"version": "5.4.0",
|
|
||||||
"dist": {
|
|
||||||
"url": "https://repo.packagist.org/files/symfony/console/5.4.0/def456.zip",
|
|
||||||
"type": "zip"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
output, err := h.rewriteMetadata([]byte(input))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("rewriteMetadata failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(output, &result); err != nil {
|
|
||||||
t.Fatalf("failed to parse output: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// The minified key should be removed from output
|
|
||||||
if _, ok := result["minified"]; ok {
|
|
||||||
t.Error("expected minified key to be removed from output")
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := result["packages"].(map[string]any)
|
|
||||||
versions := packages["symfony/console"].([]any)
|
|
||||||
|
|
||||||
// Second version should have inherited the "name" and "description" fields
|
|
||||||
v1 := versions[1].(map[string]any)
|
|
||||||
if v1["name"] != "symfony/console" {
|
|
||||||
t.Errorf("second version name = %v, want %q", v1["name"], "symfony/console")
|
|
||||||
}
|
|
||||||
if v1["description"] != "Symfony Console Component" {
|
|
||||||
t.Errorf("second version description = %v, want %q", v1["description"], "Symfony Console Component")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestComposerRewriteMetadataMinifiedDevReset(t *testing.T) {
|
|
||||||
h := &ComposerHandler{
|
|
||||||
proxy: testProxy(),
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
// The ~dev sentinel resets the inheritance chain for dev versions.
|
|
||||||
input := `{
|
|
||||||
"minified": "composer/2.0",
|
|
||||||
"packages": {
|
|
||||||
"symfony/console": [
|
|
||||||
{
|
|
||||||
"name": "symfony/console",
|
|
||||||
"description": "Symfony Console Component",
|
|
||||||
"license": ["MIT"],
|
|
||||||
"version": "6.0.0",
|
|
||||||
"dist": {
|
|
||||||
"url": "https://repo.packagist.org/files/symfony/console/6.0.0/abc123.zip",
|
|
||||||
"type": "zip"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"~dev",
|
|
||||||
{
|
|
||||||
"name": "symfony/console",
|
|
||||||
"version": "dev-main",
|
|
||||||
"dist": {
|
|
||||||
"url": "https://repo.packagist.org/files/symfony/console/dev-main/xyz789.zip",
|
|
||||||
"type": "zip"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
output, err := h.rewriteMetadata([]byte(input))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("rewriteMetadata failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(output, &result); err != nil {
|
|
||||||
t.Fatalf("failed to parse output: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := result["packages"].(map[string]any)
|
|
||||||
versions := packages["symfony/console"].([]any)
|
|
||||||
|
|
||||||
if len(versions) != 2 {
|
|
||||||
t.Fatalf("expected 2 versions, got %d", len(versions))
|
|
||||||
}
|
|
||||||
|
|
||||||
// Dev version should NOT have inherited "license" or "description"
|
|
||||||
// from the tagged version (the ~dev sentinel resets inheritance).
|
|
||||||
devVersion := versions[1].(map[string]any)
|
|
||||||
if devVersion["version"] != "dev-main" {
|
|
||||||
t.Errorf("dev version = %v, want %q", devVersion["version"], "dev-main")
|
|
||||||
}
|
|
||||||
if _, ok := devVersion["license"]; ok {
|
|
||||||
t.Error("dev version should not have inherited license field after ~dev reset")
|
|
||||||
}
|
|
||||||
if _, ok := devVersion["description"]; ok {
|
|
||||||
t.Error("dev version should not have inherited description field after ~dev reset")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestComposerRewriteMetadataUnset(t *testing.T) {
|
|
||||||
h := &ComposerHandler{
|
|
||||||
proxy: &Proxy{Logger: slog.Default()},
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
// In the minified format, "__unset" removes a field from the inherited
|
|
||||||
// state. v1.29.0 has require-dev, v1.28.0 unsets it, v1.27.0 inherits the
|
|
||||||
// unset state. Composer rejects metadata where require-dev (or any link
|
|
||||||
// field) is the literal string "__unset" rather than an object.
|
|
||||||
input := `{
|
|
||||||
"minified": "composer/2.0",
|
|
||||||
"packages": {
|
|
||||||
"venturecraft/revisionable": [
|
|
||||||
{
|
|
||||||
"name": "venturecraft/revisionable",
|
|
||||||
"version": "1.29.0",
|
|
||||||
"require": {"php": ">=5.4"},
|
|
||||||
"require-dev": {"orchestra/testbench": "~3.0"},
|
|
||||||
"dist": {"url": "https://example.com/a.zip", "type": "zip"}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"version": "1.28.0",
|
|
||||||
"require-dev": "__unset"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"version": "1.27.0"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"version": "1.26.0",
|
|
||||||
"require-dev": {"foo/bar": "1.0"}
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
output, err := h.rewriteMetadata([]byte(input))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("rewriteMetadata failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(output, &result); err != nil {
|
|
||||||
t.Fatalf("failed to parse output: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
versions := result["packages"].(map[string]any)["venturecraft/revisionable"].([]any)
|
|
||||||
if len(versions) != 4 {
|
|
||||||
t.Fatalf("expected 4 versions, got %d", len(versions))
|
|
||||||
}
|
|
||||||
|
|
||||||
byVersion := map[string]map[string]any{}
|
|
||||||
for _, v := range versions {
|
|
||||||
vmap := v.(map[string]any)
|
|
||||||
byVersion[vmap["version"].(string)] = vmap
|
|
||||||
}
|
|
||||||
|
|
||||||
if _, ok := byVersion["1.29.0"]["require-dev"].(map[string]any); !ok {
|
|
||||||
t.Errorf("1.29.0 require-dev should be an object, got %T", byVersion["1.29.0"]["require-dev"])
|
|
||||||
}
|
|
||||||
if rd, ok := byVersion["1.28.0"]["require-dev"]; ok {
|
|
||||||
t.Errorf("1.28.0 require-dev should be absent, got %v", rd)
|
|
||||||
}
|
|
||||||
if rd, ok := byVersion["1.27.0"]["require-dev"]; ok {
|
|
||||||
t.Errorf("1.27.0 require-dev should be absent (inherited unset), got %v", rd)
|
|
||||||
}
|
|
||||||
if _, ok := byVersion["1.26.0"]["require-dev"].(map[string]any); !ok {
|
|
||||||
t.Errorf("1.26.0 require-dev should be an object, got %T", byVersion["1.26.0"]["require-dev"])
|
|
||||||
}
|
|
||||||
if _, ok := byVersion["1.27.0"]["require"].(map[string]any); !ok {
|
|
||||||
t.Error("1.27.0 should still inherit require from 1.29.0")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestComposerRewriteMetadataCooldownPreservesNames(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
old := now.Add(-10 * 24 * time.Hour).Format(time.RFC3339)
|
|
||||||
veryOld := now.Add(-20 * 24 * time.Hour).Format(time.RFC3339)
|
|
||||||
recent := now.Add(-1 * time.Hour).Format(time.RFC3339)
|
|
||||||
|
|
||||||
proxy := &Proxy{Logger: slog.Default()}
|
|
||||||
proxy.Cooldown = &cooldown.Config{Default: "3d"}
|
|
||||||
|
|
||||||
h := &ComposerHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
// Minified format where "name" only appears in first version.
|
|
||||||
// When cooldown filters the first version, remaining versions must
|
|
||||||
// still have the "name" field after expansion.
|
|
||||||
input := `{
|
|
||||||
"minified": "composer/2.0",
|
|
||||||
"packages": {
|
|
||||||
"symfony/console": [
|
|
||||||
{
|
|
||||||
"name": "symfony/console",
|
|
||||||
"description": "Symfony Console Component",
|
|
||||||
"version": "7.0.0",
|
|
||||||
"time": "` + recent + `",
|
|
||||||
"dist": {"url": "https://repo.packagist.org/7.0.0.zip", "type": "zip"}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"version": "6.0.0",
|
|
||||||
"time": "` + old + `",
|
|
||||||
"dist": {"url": "https://repo.packagist.org/6.0.0.zip", "type": "zip"}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"version": "5.0.0",
|
|
||||||
"time": "` + veryOld + `",
|
|
||||||
"dist": {"url": "https://repo.packagist.org/5.0.0.zip", "type": "zip"}
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
output, err := h.rewriteMetadata([]byte(input))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("rewriteMetadata failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(output, &result); err != nil {
|
|
||||||
t.Fatalf("failed to parse output: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := result["packages"].(map[string]any)
|
|
||||||
versions := packages["symfony/console"].([]any)
|
|
||||||
|
|
||||||
// v7.0.0 should be filtered by cooldown, leaving v6.0.0 and v5.0.0
|
|
||||||
if len(versions) != 2 {
|
|
||||||
t.Fatalf("expected 2 versions after cooldown, got %d", len(versions))
|
|
||||||
}
|
|
||||||
|
|
||||||
// Both remaining versions must have the "name" field
|
|
||||||
for _, v := range versions {
|
|
||||||
vmap := v.(map[string]any)
|
|
||||||
if vmap["name"] != "symfony/console" {
|
|
||||||
t.Errorf("version %v missing name field, got %v", vmap["version"], vmap["name"])
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestComposerRewriteDistURLGitHubZipball(t *testing.T) {
|
|
||||||
// GitHub zipball URLs end with a bare commit hash, no file extension.
|
|
||||||
// The proxy must produce a filename with .zip extension so that the
|
|
||||||
// archives library can detect the format when browsing source.
|
|
||||||
h := &ComposerHandler{
|
|
||||||
proxy: testProxy(),
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
vmap := map[string]any{
|
|
||||||
"version": "v7.4.8",
|
|
||||||
"dist": map[string]any{
|
|
||||||
"url": "https://api.github.com/repos/symfony/asset/zipball/d2e2f014ccd6ec9fae8dbe6336a4164346a2a856",
|
|
||||||
"type": "zip",
|
|
||||||
"shasum": "",
|
|
||||||
"reference": "d2e2f014ccd6ec9fae8dbe6336a4164346a2a856",
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
h.rewriteDistURL(vmap, "symfony/asset", "v7.4.8")
|
|
||||||
|
|
||||||
dist := vmap["dist"].(map[string]any)
|
|
||||||
url := dist["url"].(string)
|
|
||||||
|
|
||||||
// The rewritten URL's filename must have a .zip extension
|
|
||||||
if !strings.HasSuffix(url, ".zip") {
|
|
||||||
t.Errorf("rewritten dist URL filename has no .zip extension: %s", url)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestComposerRewriteMetadataGitHubZipballFilenames(t *testing.T) {
|
|
||||||
// End-to-end: metadata with GitHub zipball URLs should produce
|
|
||||||
// download URLs that end in .zip so browse source can open them.
|
|
||||||
h := &ComposerHandler{
|
|
||||||
proxy: testProxy(),
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
input := `{
|
|
||||||
"packages": {
|
|
||||||
"symfony/config": [
|
|
||||||
{
|
|
||||||
"version": "v7.4.8",
|
|
||||||
"dist": {
|
|
||||||
"url": "https://api.github.com/repos/symfony/config/zipball/c7369cc1da250fcbfe0c5a9d109e419661549c39",
|
|
||||||
"type": "zip",
|
|
||||||
"reference": "c7369cc1da250fcbfe0c5a9d109e419661549c39"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
output, err := h.rewriteMetadata([]byte(input))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("rewriteMetadata failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(output, &result); err != nil {
|
|
||||||
t.Fatalf("failed to parse output: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := result["packages"].(map[string]any)
|
|
||||||
versions := packages["symfony/config"].([]any)
|
|
||||||
v := versions[0].(map[string]any)
|
|
||||||
dist := v["dist"].(map[string]any)
|
|
||||||
url := dist["url"].(string)
|
|
||||||
|
|
||||||
if !strings.HasSuffix(url, ".zip") {
|
|
||||||
t.Errorf("rewritten URL should end in .zip, got %s", url)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestComposerExpandMinifiedSharedDistReferences(t *testing.T) {
|
|
||||||
// When a minified version inherits the dist field from a previous version
|
|
||||||
// (i.e. it doesn't include its own dist), expanding + rewriting must not
|
|
||||||
// corrupt the dist URLs via shared map references.
|
|
||||||
h := &ComposerHandler{
|
|
||||||
proxy: testProxy(),
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
// In this minified payload, v5.3.0 does NOT include a dist field,
|
|
||||||
// so it inherits v5.4.0's dist. After expansion and URL rewriting,
|
|
||||||
// each version must have its own correct dist URL.
|
|
||||||
input := `{
|
|
||||||
"minified": "composer/2.0",
|
|
||||||
"packages": {
|
|
||||||
"vendor/pkg": [
|
|
||||||
{
|
|
||||||
"name": "vendor/pkg",
|
|
||||||
"version": "5.4.0",
|
|
||||||
"dist": {
|
|
||||||
"url": "https://api.github.com/repos/vendor/pkg/zipball/aaa111",
|
|
||||||
"type": "zip",
|
|
||||||
"reference": "aaa111"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"version": "5.3.0"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
output, err := h.rewriteMetadata([]byte(input))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("rewriteMetadata failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(output, &result); err != nil {
|
|
||||||
t.Fatalf("failed to parse output: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := result["packages"].(map[string]any)
|
|
||||||
versions := packages["vendor/pkg"].([]any)
|
|
||||||
if len(versions) != 2 {
|
|
||||||
t.Fatalf("expected 2 versions, got %d", len(versions))
|
|
||||||
}
|
|
||||||
|
|
||||||
v1 := versions[0].(map[string]any)
|
|
||||||
v2 := versions[1].(map[string]any)
|
|
||||||
|
|
||||||
dist1 := v1["dist"].(map[string]any)
|
|
||||||
dist2 := v2["dist"].(map[string]any)
|
|
||||||
|
|
||||||
url1 := dist1["url"].(string)
|
|
||||||
url2 := dist2["url"].(string)
|
|
||||||
|
|
||||||
// Each version must have its own URL with its own version in the path
|
|
||||||
if !strings.Contains(url1, "/5.4.0/") {
|
|
||||||
t.Errorf("v5.4.0 dist URL should contain /5.4.0/, got %s", url1)
|
|
||||||
}
|
|
||||||
if !strings.Contains(url2, "/5.3.0/") {
|
|
||||||
t.Errorf("v5.3.0 dist URL should contain /5.3.0/, got %s", url2)
|
|
||||||
}
|
|
||||||
|
|
||||||
// The two URLs must be different
|
|
||||||
if url1 == url2 {
|
|
||||||
t.Errorf("both versions have the same dist URL (shared reference bug): %s", url1)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestComposerDownloadDevVersionUsesDevMetadata is a regression test for the
|
|
||||||
// bug that made it impossible to install a *-dev dependency from dist.
|
|
||||||
//
|
|
||||||
// Packagist serves development versions (e.g. "3.x-dev", "dev-master") from a
|
|
||||||
// separate "{package}~dev.json" metadata file; the regular "{package}.json"
|
|
||||||
// file contains only tagged releases. The download handler used to fetch only
|
|
||||||
// the regular file, so it could never find the dist URL for a dev version and
|
|
||||||
// returned 404 — causing Composer to silently fall back to a git clone.
|
|
||||||
//
|
|
||||||
// This test serves both files from a mock upstream and asserts that:
|
|
||||||
// - the OLD behavior (regular file only) cannot resolve the dev version, and
|
|
||||||
// - the FIXED behavior (consulting the ~dev file) does.
|
|
||||||
func TestComposerDownloadDevVersionUsesDevMetadata(t *testing.T) {
|
|
||||||
const (
|
|
||||||
pkg = "phpmd/phpmd"
|
|
||||||
vendor = "phpmd"
|
|
||||||
name = "phpmd"
|
|
||||||
version = "3.x-dev"
|
|
||||||
distURL = "https://api.github.com/repos/phpmd/phpmd/zipball/2a9217f60aaf27bf6ddad9188f254d020ab70745"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Regular metadata: tagged releases only — no dev versions.
|
|
||||||
stableBody := `{
|
|
||||||
"packages": {
|
|
||||||
"phpmd/phpmd": [
|
|
||||||
{"version": "2.15.0", "dist": {"url": "https://example.com/2.15.0.zip", "type": "zip"}}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
// ~dev metadata: where the 3.x-dev version actually lives.
|
|
||||||
devBody := `{
|
|
||||||
"packages": {
|
|
||||||
"phpmd/phpmd": [
|
|
||||||
{"version": "3.x-dev", "dist": {"url": "` + distURL + `", "type": "zip"}}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
switch r.URL.Path {
|
|
||||||
case "/p2/phpmd/phpmd.json":
|
|
||||||
_, _ = w.Write([]byte(stableBody))
|
|
||||||
case "/p2/phpmd/phpmd~dev.json":
|
|
||||||
_, _ = w.Write([]byte(devBody))
|
|
||||||
default:
|
|
||||||
http.NotFound(w, r)
|
|
||||||
}
|
|
||||||
}))
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
h := &ComposerHandler{
|
|
||||||
proxy: testProxy(),
|
|
||||||
repoURL: srv.URL,
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
// OLD behavior: fetching only the regular file fails to resolve the dev
|
|
||||||
// version, which is what produced the 404 before the fix.
|
|
||||||
stableURL := srv.URL + "/p2/phpmd/phpmd.json"
|
|
||||||
got, err := h.findDownloadURLFromMetadata(ctx, stableURL, pkg, version)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("unexpected error fetching regular metadata: %v", err)
|
|
||||||
}
|
|
||||||
if got != "" {
|
|
||||||
t.Fatalf("regular metadata unexpectedly contained dev version %q (got %q); "+
|
|
||||||
"the test no longer reproduces the original bug", version, got)
|
|
||||||
}
|
|
||||||
|
|
||||||
// FIXED behavior: the handler consults the ~dev file (it is first in the
|
|
||||||
// candidate list for dev versions) and resolves the dist URL.
|
|
||||||
urls := h.metadataURLsForVersion(vendor, name, version)
|
|
||||||
if len(urls) == 0 || !strings.HasSuffix(urls[0], "/p2/phpmd/phpmd~dev.json") {
|
|
||||||
t.Fatalf("dev version should consult the ~dev metadata file first, got %v", urls)
|
|
||||||
}
|
|
||||||
|
|
||||||
var resolved string
|
|
||||||
for _, u := range urls {
|
|
||||||
resolved, err = h.findDownloadURLFromMetadata(ctx, u, pkg, version)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("unexpected error fetching metadata %q: %v", u, err)
|
|
||||||
}
|
|
||||||
if resolved != "" {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if resolved != distURL {
|
|
||||||
t.Errorf("dev version dist URL = %q, want %q", resolved, distURL)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestComposerRewriteMetadataCooldown(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
old := now.Add(-10 * 24 * time.Hour).Format(time.RFC3339)
|
|
||||||
recent := now.Add(-1 * time.Hour).Format(time.RFC3339)
|
|
||||||
|
|
||||||
proxy := &Proxy{Logger: slog.Default()}
|
|
||||||
proxy.Cooldown = &cooldown.Config{Default: "3d"}
|
|
||||||
|
|
||||||
h := &ComposerHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
input := `{
|
|
||||||
"packages": {
|
|
||||||
"symfony/console": [
|
|
||||||
{
|
|
||||||
"version": "5.0.0",
|
|
||||||
"time": "` + old + `",
|
|
||||||
"dist": {"url": "https://repo.packagist.org/5.0.0.zip", "type": "zip"}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"version": "6.0.0",
|
|
||||||
"time": "` + recent + `",
|
|
||||||
"dist": {"url": "https://repo.packagist.org/6.0.0.zip", "type": "zip"}
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
output, err := h.rewriteMetadata([]byte(input))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("rewriteMetadata failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(output, &result); err != nil {
|
|
||||||
t.Fatalf("failed to parse output: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := result["packages"].(map[string]any)
|
|
||||||
versions := packages["symfony/console"].([]any)
|
|
||||||
|
|
||||||
if len(versions) != 1 {
|
|
||||||
t.Fatalf("expected 1 version after cooldown, got %d", len(versions))
|
|
||||||
}
|
|
||||||
|
|
||||||
v := versions[0].(map[string]any)
|
|
||||||
if v["version"] != "5.0.0" {
|
|
||||||
t.Errorf("expected version 5.0.0, got %v", v["version"])
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -27,13 +27,6 @@ func NewConanHandler(proxy *Proxy, proxyURL string) *ConanHandler {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewConanHandlerWithUpstream creates a Conan handler with a custom upstream.
|
|
||||||
func NewConanHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *ConanHandler {
|
|
||||||
h := NewConanHandler(proxy, proxyURL)
|
|
||||||
h.upstreamURL = configuredUpstreamURL(upstreamURL, conanUpstream)
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for Conan requests.
|
// Routes returns the HTTP handler for Conan requests.
|
||||||
func (h *ConanHandler) Routes() http.Handler {
|
func (h *ConanHandler) Routes() http.Handler {
|
||||||
mux := http.NewServeMux()
|
mux := http.NewServeMux()
|
||||||
|
|
@ -50,8 +43,8 @@ func (h *ConanHandler) Routes() http.Handler {
|
||||||
mux.HandleFunc("GET /v1/files/{name}/{version}/{user}/{channel}/{revision}/package/{pkgref}/{pkgrev}/{filename}", h.handlePackageFile)
|
mux.HandleFunc("GET /v1/files/{name}/{version}/{user}/{channel}/{revision}/package/{pkgref}/{pkgrev}/{filename}", h.handlePackageFile)
|
||||||
mux.HandleFunc("GET /v2/files/{name}/{version}/{user}/{channel}/{revision}/package/{pkgref}/{pkgrev}/{filename}", h.handlePackageFile)
|
mux.HandleFunc("GET /v2/files/{name}/{version}/{user}/{channel}/{revision}/package/{pkgref}/{pkgrev}/{filename}", h.handlePackageFile)
|
||||||
|
|
||||||
// Proxy all other endpoints (metadata, search, etc.) with caching
|
// Proxy all other endpoints (metadata, search, etc.)
|
||||||
mux.HandleFunc("GET /", h.proxyCached)
|
mux.HandleFunc("GET /", h.proxyUpstream)
|
||||||
|
|
||||||
return mux
|
return mux
|
||||||
}
|
}
|
||||||
|
|
@ -91,7 +84,8 @@ func (h *ConanHandler) handleRecipeFile(w http.ResponseWriter, r *http.Request)
|
||||||
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conan", packageName, storageVersion, storageFilename, upstreamURL)
|
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conan", packageName, storageVersion, storageFilename, upstreamURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch file")
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
|
http.Error(w, "failed to fetch file", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -128,7 +122,8 @@ func (h *ConanHandler) handlePackageFile(w http.ResponseWriter, r *http.Request)
|
||||||
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conan", packageName, storageVersion, storageFilename, upstreamURL)
|
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conan", packageName, storageVersion, storageFilename, upstreamURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch file")
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
|
http.Error(w, "failed to fetch file", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -152,20 +147,6 @@ func (h *ConanHandler) shouldCacheFile(filename string) bool {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
// proxyCached forwards a request with metadata caching.
|
|
||||||
func (h *ConanHandler) proxyCached(w http.ResponseWriter, r *http.Request) {
|
|
||||||
cacheKey := strings.TrimPrefix(r.URL.Path, "/")
|
|
||||||
cacheKey = strings.ReplaceAll(cacheKey, "/", "_")
|
|
||||||
if r.URL.RawQuery != "" {
|
|
||||||
cacheKey += "_" + r.URL.RawQuery
|
|
||||||
}
|
|
||||||
upstreamURL := h.upstreamURL + r.URL.Path
|
|
||||||
if r.URL.RawQuery != "" {
|
|
||||||
upstreamURL += "?" + r.URL.RawQuery
|
|
||||||
}
|
|
||||||
h.proxy.ProxyCached(w, r, upstreamURL, "conan", cacheKey, "*/*")
|
|
||||||
}
|
|
||||||
|
|
||||||
// proxyUpstream forwards a request to conan center without caching.
|
// proxyUpstream forwards a request to conan center without caching.
|
||||||
func (h *ConanHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
func (h *ConanHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
||||||
upstreamURL := h.upstreamURL + r.URL.Path
|
upstreamURL := h.upstreamURL + r.URL.Path
|
||||||
|
|
@ -186,7 +167,7 @@ func (h *ConanHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
||||||
req.Header.Set("Authorization", auth)
|
req.Header.Set("Authorization", auth)
|
||||||
}
|
}
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
resp, err := http.DefaultClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.Logger.Error("upstream request failed", "error", err)
|
h.proxy.Logger.Error("upstream request failed", "error", err)
|
||||||
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
||||||
|
|
|
||||||
|
|
@ -1,476 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"io"
|
|
||||||
"log/slog"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
)
|
|
||||||
|
|
||||||
const testProxyURL = "http://localhost:8080"
|
|
||||||
|
|
||||||
func conanTestProxy() *Proxy {
|
|
||||||
return &Proxy{
|
|
||||||
Logger: slog.Default(),
|
|
||||||
HTTPClient: http.DefaultClient,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanShouldCacheFile(t *testing.T) {
|
|
||||||
h := &ConanHandler{}
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
filename string
|
|
||||||
want bool
|
|
||||||
}{
|
|
||||||
{"conan_sources.tgz", true},
|
|
||||||
{"conan_export.tgz", true},
|
|
||||||
{"conan_package.tgz", true},
|
|
||||||
{"conanfile.py", false},
|
|
||||||
{"conanmanifest.txt", false},
|
|
||||||
{"conaninfo.txt", false},
|
|
||||||
{"random.tgz", false},
|
|
||||||
{"", false},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
got := h.shouldCacheFile(tt.filename)
|
|
||||||
if got != tt.want {
|
|
||||||
t.Errorf("shouldCacheFile(%q) = %v, want %v", tt.filename, got, tt.want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanPingV1(t *testing.T) {
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
proxyURL: testProxyURL,
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v1/ping", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
|
|
||||||
h.handlePing(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
|
|
||||||
caps := w.Header().Get("X-Conan-Server-Capabilities")
|
|
||||||
if caps != "revisions" {
|
|
||||||
t.Errorf("X-Conan-Server-Capabilities = %q, want %q", caps, "revisions")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanPingV2(t *testing.T) {
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
proxyURL: testProxyURL,
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/ping", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
|
|
||||||
h.handlePing(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
|
|
||||||
caps := w.Header().Get("X-Conan-Server-Capabilities")
|
|
||||||
if caps != "revisions" {
|
|
||||||
t.Errorf("X-Conan-Server-Capabilities = %q, want %q", caps, "revisions")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanProxyUpstream(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if r.URL.Path != "/v2/conans/search" {
|
|
||||||
w.WriteHeader(http.StatusNotFound)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if r.URL.Query().Get("q") != "zlib" {
|
|
||||||
w.WriteHeader(http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
_, _ = w.Write([]byte(`{"results":["zlib/1.2.13"]}`))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/conans/search?q=zlib", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.proxyUpstream(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
|
|
||||||
body := w.Body.String()
|
|
||||||
if !strings.Contains(body, "zlib/1.2.13") {
|
|
||||||
t.Errorf("response body does not contain expected result: %s", body)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanProxyUpstreamNotFound(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.WriteHeader(http.StatusNotFound)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/conans/nonexistent", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.proxyUpstream(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusNotFound {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusNotFound)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanProxyUpstreamCopiesHeaders(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.Header().Set("X-Custom-Header", "test-value")
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
_, _ = w.Write([]byte(`{}`))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/conans/test", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.proxyUpstream(w, req)
|
|
||||||
|
|
||||||
if w.Header().Get("X-Custom-Header") != "test-value" {
|
|
||||||
t.Errorf("X-Custom-Header = %q, want %q", w.Header().Get("X-Custom-Header"), "test-value")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanProxyUpstreamForwardsAuthHeader(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
auth := r.Header.Get("Authorization")
|
|
||||||
if auth != "Bearer mytoken" {
|
|
||||||
w.WriteHeader(http.StatusUnauthorized)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
_, _ = w.Write([]byte(`{"ok":true}`))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/conans/test", nil)
|
|
||||||
req.Header.Set("Authorization", "Bearer mytoken")
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.proxyUpstream(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanProxyUpstreamBadUpstream(t *testing.T) {
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: "http://127.0.0.1:1", // unreachable
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/conans/test", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.proxyUpstream(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusBadGateway {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusBadGateway)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanRecipeFileNonCacheable(t *testing.T) {
|
|
||||||
// When a recipe file is not cacheable (e.g. conanfile.py), it should be proxied upstream.
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.Header().Set("Content-Type", "text/plain")
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
_, _ = w.Write([]byte("conanfile content"))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/files/zlib/1.2.13/_/_/abc123/recipe/conanfile.py", nil)
|
|
||||||
req.SetPathValue("name", "zlib")
|
|
||||||
req.SetPathValue("version", "1.2.13")
|
|
||||||
req.SetPathValue("user", "_")
|
|
||||||
req.SetPathValue("channel", "_")
|
|
||||||
req.SetPathValue("revision", "abc123")
|
|
||||||
req.SetPathValue("filename", "conanfile.py")
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handleRecipeFile(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
|
|
||||||
body := w.Body.String()
|
|
||||||
if body != "conanfile content" {
|
|
||||||
t.Errorf("body = %q, want %q", body, "conanfile content")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanPackageFileNonCacheable(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.Header().Set("Content-Type", "text/plain")
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
_, _ = w.Write([]byte("conaninfo content"))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/files/zlib/1.2.13/_/_/abc123/package/pkgref1/pkgrev1/conaninfo.txt", nil)
|
|
||||||
req.SetPathValue("name", "zlib")
|
|
||||||
req.SetPathValue("version", "1.2.13")
|
|
||||||
req.SetPathValue("user", "_")
|
|
||||||
req.SetPathValue("channel", "_")
|
|
||||||
req.SetPathValue("revision", "abc123")
|
|
||||||
req.SetPathValue("pkgref", "pkgref1")
|
|
||||||
req.SetPathValue("pkgrev", "pkgrev1")
|
|
||||||
req.SetPathValue("filename", "conaninfo.txt")
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handlePackageFile(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
|
|
||||||
body := w.Body.String()
|
|
||||||
if body != "conaninfo content" {
|
|
||||||
t.Errorf("body = %q, want %q", body, "conaninfo content")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanRoutes(t *testing.T) {
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: "http://localhost:1", // won't be called for ping
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
routes := h.Routes()
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
path string
|
|
||||||
wantStatus int
|
|
||||||
}{
|
|
||||||
{"/v1/ping", http.StatusOK},
|
|
||||||
{"/v2/ping", http.StatusOK},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
req := httptest.NewRequest(http.MethodGet, tt.path, nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
routes.ServeHTTP(w, req)
|
|
||||||
|
|
||||||
if w.Code != tt.wantStatus {
|
|
||||||
t.Errorf("GET %s: status = %d, want %d", tt.path, w.Code, tt.wantStatus)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanProxyUpstreamPreservesQueryString(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if r.URL.Query().Get("q") != "boost" && r.URL.Query().Get("page") != "2" {
|
|
||||||
w.WriteHeader(http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
_, _ = w.Write([]byte(`ok`))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/conans/search?q=boost&page=2", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.proxyUpstream(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanProxyUpstreamLargeResponse(t *testing.T) {
|
|
||||||
largeBody := strings.Repeat("x", 1024*1024)
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
_, _ = w.Write([]byte(largeBody))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/conans/test", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.proxyUpstream(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
|
|
||||||
if w.Body.Len() != len(largeBody) {
|
|
||||||
t.Errorf("body length = %d, want %d", w.Body.Len(), len(largeBody))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNewConanHandler(t *testing.T) {
|
|
||||||
proxy := conanTestProxy()
|
|
||||||
h := NewConanHandler(proxy, "http://localhost:8080/")
|
|
||||||
|
|
||||||
if h.proxy != proxy {
|
|
||||||
t.Error("proxy not set correctly")
|
|
||||||
}
|
|
||||||
if h.upstreamURL != conanUpstream {
|
|
||||||
t.Errorf("upstreamURL = %q, want %q", h.upstreamURL, conanUpstream)
|
|
||||||
}
|
|
||||||
if h.proxyURL != testProxyURL {
|
|
||||||
t.Errorf("proxyURL = %q, want %q (trailing slash should be trimmed)", h.proxyURL, testProxyURL)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNewConanHandlerNoTrailingSlash(t *testing.T) {
|
|
||||||
proxy := conanTestProxy()
|
|
||||||
h := NewConanHandler(proxy, testProxyURL)
|
|
||||||
|
|
||||||
if h.proxyURL != testProxyURL {
|
|
||||||
t.Errorf("proxyURL = %q, want %q", h.proxyURL, testProxyURL)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanProxyUpstreamNoAuthHeaderWhenNotProvided(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
auth := r.Header.Get("Authorization")
|
|
||||||
if auth != "" {
|
|
||||||
w.WriteHeader(http.StatusBadRequest)
|
|
||||||
_, _ = w.Write([]byte("unexpected auth header"))
|
|
||||||
return
|
|
||||||
}
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/conans/test", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.proxyUpstream(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanProxyUpstreamCopiesBody(t *testing.T) {
|
|
||||||
expected := `{"name":"zlib","version":"1.2.13","user":"_","channel":"_"}`
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
_, _ = w.Write([]byte(expected))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/conans/zlib/1.2.13/_/_/latest", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.proxyUpstream(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
|
|
||||||
got, _ := io.ReadAll(w.Body)
|
|
||||||
if string(got) != expected {
|
|
||||||
t.Errorf("body = %q, want %q", string(got), expected)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestConanProxyUpstreamPreservesStatusCodes(t *testing.T) {
|
|
||||||
codes := []int{
|
|
||||||
http.StatusOK,
|
|
||||||
http.StatusNotFound,
|
|
||||||
http.StatusForbidden,
|
|
||||||
http.StatusInternalServerError,
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, code := range codes {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.WriteHeader(code)
|
|
||||||
}))
|
|
||||||
|
|
||||||
h := &ConanHandler{
|
|
||||||
proxy: conanTestProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/v2/test", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.proxyUpstream(w, req)
|
|
||||||
|
|
||||||
if w.Code != code {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, code)
|
|
||||||
}
|
|
||||||
|
|
||||||
upstream.Close()
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,16 +1,13 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/json"
|
|
||||||
"io"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
condaUpstream = "https://conda.anaconda.org"
|
condaUpstream = "https://conda.anaconda.org"
|
||||||
minCondaParts = 3 // name-version-build requires at least 3 hyphen-separated parts
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// CondaHandler handles Conda/Anaconda registry protocol requests.
|
// CondaHandler handles Conda/Anaconda registry protocol requests.
|
||||||
|
|
@ -29,21 +26,14 @@ func NewCondaHandler(proxy *Proxy, proxyURL string) *CondaHandler {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewCondaHandlerWithUpstream creates a Conda handler with a custom upstream.
|
|
||||||
func NewCondaHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *CondaHandler {
|
|
||||||
h := NewCondaHandler(proxy, proxyURL)
|
|
||||||
h.upstreamURL = configuredUpstreamURL(upstreamURL, condaUpstream)
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for Conda requests.
|
// Routes returns the HTTP handler for Conda requests.
|
||||||
func (h *CondaHandler) Routes() http.Handler {
|
func (h *CondaHandler) Routes() http.Handler {
|
||||||
mux := http.NewServeMux()
|
mux := http.NewServeMux()
|
||||||
|
|
||||||
// Channel index (repodata)
|
// Channel index (repodata)
|
||||||
mux.HandleFunc("GET /{channel}/{arch}/repodata.json", h.handleRepodata)
|
mux.HandleFunc("GET /{channel}/{arch}/repodata.json", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET /{channel}/{arch}/repodata.json.bz2", h.proxyCached)
|
mux.HandleFunc("GET /{channel}/{arch}/repodata.json.bz2", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET /{channel}/{arch}/current_repodata.json", h.handleRepodata)
|
mux.HandleFunc("GET /{channel}/{arch}/current_repodata.json", h.proxyUpstream)
|
||||||
|
|
||||||
// Package downloads (cache these)
|
// Package downloads (cache these)
|
||||||
mux.HandleFunc("GET /{channel}/{arch}/{filename}", h.handleDownload)
|
mux.HandleFunc("GET /{channel}/{arch}/{filename}", h.handleDownload)
|
||||||
|
|
@ -79,7 +69,8 @@ func (h *CondaHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
||||||
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conda", packageName, version, filename, upstreamURL)
|
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conda", packageName, version, filename, upstreamURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch package")
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
|
http.Error(w, "failed to fetch package", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -107,7 +98,7 @@ func (h *CondaHandler) parseFilename(filename string) (name, version string) {
|
||||||
// Split by hyphens, the format is name-version-build
|
// Split by hyphens, the format is name-version-build
|
||||||
// The name can contain hyphens, so we need to find version-build at the end
|
// The name can contain hyphens, so we need to find version-build at the end
|
||||||
parts := strings.Split(base, "-")
|
parts := strings.Split(base, "-")
|
||||||
if len(parts) < minCondaParts {
|
if len(parts) < 3 {
|
||||||
return "", ""
|
return "", ""
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -128,25 +119,24 @@ func (h *CondaHandler) parseFilename(filename string) (name, version string) {
|
||||||
return name, version
|
return name, version
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleRepodata proxies repodata.json, applying cooldown filtering when enabled.
|
// proxyUpstream forwards a request to Anaconda without caching.
|
||||||
func (h *CondaHandler) handleRepodata(w http.ResponseWriter, r *http.Request) {
|
func (h *CondaHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
||||||
if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
|
|
||||||
h.proxyCached(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
upstreamURL := h.upstreamURL + r.URL.Path
|
upstreamURL := h.upstreamURL + r.URL.Path
|
||||||
|
|
||||||
h.proxy.Logger.Debug("fetching repodata for cooldown filtering", "url", upstreamURL)
|
h.proxy.Logger.Debug("proxying to upstream", "url", upstreamURL)
|
||||||
|
|
||||||
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
http.Error(w, "failed to create request", http.StatusInternalServerError)
|
http.Error(w, "failed to create request", http.StatusInternalServerError)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
req.Header.Set(headerAcceptEncoding, "gzip")
|
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
// Copy accept-encoding for compression
|
||||||
|
if ae := r.Header.Get("Accept-Encoding"); ae != "" {
|
||||||
|
req.Header.Set("Accept-Encoding", ae)
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.Logger.Error("upstream request failed", "error", err)
|
h.proxy.Logger.Error("upstream request failed", "error", err)
|
||||||
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
||||||
|
|
@ -154,96 +144,12 @@ func (h *CondaHandler) handleRepodata(w http.ResponseWriter, r *http.Request) {
|
||||||
}
|
}
|
||||||
defer func() { _ = resp.Body.Close() }()
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
for k, vv := range resp.Header {
|
||||||
for k, vv := range resp.Header {
|
for _, v := range vv {
|
||||||
for _, v := range vv {
|
w.Header().Add(k, v)
|
||||||
w.Header().Add(k, v)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
w.WriteHeader(resp.StatusCode)
|
|
||||||
_, _ = io.Copy(w, resp.Body)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
body, err := h.proxy.ReadMetadata(resp.Body)
|
|
||||||
if err != nil {
|
|
||||||
http.Error(w, "failed to read response", http.StatusInternalServerError)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
filtered, err := h.applyCooldownFiltering(body)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to filter repodata, proxying original", "error", err)
|
|
||||||
w.Header().Set(headerContentType, "application/json")
|
|
||||||
_, _ = w.Write(body)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
w.Header().Set(headerContentType, "application/json")
|
|
||||||
_, _ = w.Write(filtered)
|
|
||||||
}
|
|
||||||
|
|
||||||
// condaTimestampDivisor converts Conda's millisecond timestamps to seconds.
|
|
||||||
const condaTimestampDivisor = 1000
|
|
||||||
|
|
||||||
// applyCooldownFiltering removes entries from repodata.json that were
|
|
||||||
// published too recently based on their timestamp field.
|
|
||||||
func (h *CondaHandler) applyCooldownFiltering(body []byte) ([]byte, error) {
|
|
||||||
if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
|
|
||||||
return body, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
var repodata map[string]any
|
|
||||||
if err := json.Unmarshal(body, &repodata); err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, key := range []string{"packages", "packages.conda"} {
|
|
||||||
packages, ok := repodata[key].(map[string]any)
|
|
||||||
if !ok {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
for filename, entry := range packages {
|
|
||||||
entryMap, ok := entry.(map[string]any)
|
|
||||||
if !ok {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
ts, ok := entryMap["timestamp"].(float64)
|
|
||||||
if !ok || ts == 0 {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
publishedAt := time.Unix(int64(ts)/condaTimestampDivisor, 0)
|
|
||||||
|
|
||||||
name, _ := entryMap["name"].(string)
|
|
||||||
if name == "" {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
packagePURL := canonicalPackagePURL("conda", name)
|
|
||||||
|
|
||||||
if !h.proxy.Cooldown.IsAllowed("conda", packagePURL, publishedAt) {
|
|
||||||
version, _ := entryMap["version"].(string)
|
|
||||||
h.proxy.Logger.Info("cooldown: filtering conda package",
|
|
||||||
"name", name, "version", version, "filename", filename)
|
|
||||||
delete(packages, filename)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return json.Marshal(repodata)
|
w.WriteHeader(resp.StatusCode)
|
||||||
}
|
_, _ = io.Copy(w, resp.Body)
|
||||||
|
|
||||||
// proxyCached forwards a metadata request with caching.
|
|
||||||
func (h *CondaHandler) proxyCached(w http.ResponseWriter, r *http.Request) {
|
|
||||||
cacheKey := strings.TrimPrefix(r.URL.Path, "/")
|
|
||||||
cacheKey = strings.ReplaceAll(cacheKey, "/", "_")
|
|
||||||
h.proxy.ProxyCached(w, r, h.upstreamURL+r.URL.Path, "conda", cacheKey, "*/*")
|
|
||||||
}
|
|
||||||
|
|
||||||
// proxyUpstream forwards a request to Anaconda without caching.
|
|
||||||
func (h *CondaHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
|
||||||
h.proxy.ProxyUpstream(w, r, h.upstreamURL+r.URL.Path, []string{headerAcceptEncoding})
|
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -1,14 +1,8 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/json"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/cooldown"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestCondaParseFilename(t *testing.T) {
|
func TestCondaParseFilename(t *testing.T) {
|
||||||
|
|
@ -55,251 +49,3 @@ func TestCondaIsPackageFile(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestCondaCooldownFiltering(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
oldTimestamp := float64(now.Add(-7 * 24 * time.Hour).UnixMilli())
|
|
||||||
recentTimestamp := float64(now.Add(-1 * time.Hour).UnixMilli())
|
|
||||||
|
|
||||||
repodata := map[string]any{
|
|
||||||
"info": map[string]any{},
|
|
||||||
"packages": map[string]any{
|
|
||||||
"numpy-1.24.0-old.tar.bz2": map[string]any{
|
|
||||||
"name": "numpy",
|
|
||||||
"version": "1.24.0",
|
|
||||||
"timestamp": oldTimestamp,
|
|
||||||
},
|
|
||||||
"numpy-1.25.0-new.tar.bz2": map[string]any{
|
|
||||||
"name": "numpy",
|
|
||||||
"version": "1.25.0",
|
|
||||||
"timestamp": recentTimestamp,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
"packages.conda": map[string]any{
|
|
||||||
"scipy-1.11.0-old.conda": map[string]any{
|
|
||||||
"name": "scipy",
|
|
||||||
"version": "1.11.0",
|
|
||||||
"timestamp": oldTimestamp,
|
|
||||||
},
|
|
||||||
"scipy-1.12.0-new.conda": map[string]any{
|
|
||||||
"name": "scipy",
|
|
||||||
"version": "1.12.0",
|
|
||||||
"timestamp": recentTimestamp,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
body, err := json.Marshal(repodata)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{
|
|
||||||
Default: "3d",
|
|
||||||
}
|
|
||||||
|
|
||||||
h := &CondaHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
filtered, err := h.applyCooldownFiltering(body)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(filtered, &result); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := result["packages"].(map[string]any)
|
|
||||||
if len(packages) != 1 {
|
|
||||||
t.Fatalf("expected 1 package in packages, got %d", len(packages))
|
|
||||||
}
|
|
||||||
if _, ok := packages["numpy-1.24.0-old.tar.bz2"]; !ok {
|
|
||||||
t.Error("expected old numpy to survive filtering")
|
|
||||||
}
|
|
||||||
|
|
||||||
condaPkgs := result["packages.conda"].(map[string]any)
|
|
||||||
if len(condaPkgs) != 1 {
|
|
||||||
t.Fatalf("expected 1 package in packages.conda, got %d", len(condaPkgs))
|
|
||||||
}
|
|
||||||
if _, ok := condaPkgs["scipy-1.11.0-old.conda"]; !ok {
|
|
||||||
t.Error("expected old scipy to survive filtering")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestCondaCooldownFilteringWithPackageOverride(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
recentTimestamp := float64(now.Add(-2 * time.Hour).UnixMilli())
|
|
||||||
|
|
||||||
repodata := map[string]any{
|
|
||||||
"info": map[string]any{},
|
|
||||||
"packages": map[string]any{
|
|
||||||
"special-1.0.0-build.tar.bz2": map[string]any{
|
|
||||||
"name": "special",
|
|
||||||
"version": "1.0.0",
|
|
||||||
"timestamp": recentTimestamp,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
"packages.conda": map[string]any{},
|
|
||||||
}
|
|
||||||
|
|
||||||
body, err := json.Marshal(repodata)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{
|
|
||||||
Default: "3d",
|
|
||||||
Packages: map[string]string{"pkg:conda/special": "1h"},
|
|
||||||
}
|
|
||||||
|
|
||||||
h := &CondaHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
filtered, err := h.applyCooldownFiltering(body)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(filtered, &result); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := result["packages"].(map[string]any)
|
|
||||||
if len(packages) != 1 {
|
|
||||||
t.Fatalf("expected 1 package (override allows it), got %d", len(packages))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestCondaCooldownFilteringNoTimestamp(t *testing.T) {
|
|
||||||
repodata := map[string]any{
|
|
||||||
"info": map[string]any{},
|
|
||||||
"packages": map[string]any{
|
|
||||||
"old-pkg-1.0.0-build.tar.bz2": map[string]any{
|
|
||||||
"name": "old-pkg",
|
|
||||||
"version": "1.0.0",
|
|
||||||
// no timestamp field
|
|
||||||
},
|
|
||||||
},
|
|
||||||
"packages.conda": map[string]any{},
|
|
||||||
}
|
|
||||||
|
|
||||||
body, err := json.Marshal(repodata)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{
|
|
||||||
Default: "3d",
|
|
||||||
}
|
|
||||||
|
|
||||||
h := &CondaHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
filtered, err := h.applyCooldownFiltering(body)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(filtered, &result); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := result["packages"].(map[string]any)
|
|
||||||
if len(packages) != 1 {
|
|
||||||
t.Fatalf("entries without timestamp should pass through, got %d", len(packages))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestCondaHandleRepodataWithCooldown(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
oldTimestamp := float64(now.Add(-7 * 24 * time.Hour).UnixMilli())
|
|
||||||
recentTimestamp := float64(now.Add(-1 * time.Hour).UnixMilli())
|
|
||||||
|
|
||||||
repodataJSON, _ := json.Marshal(map[string]any{
|
|
||||||
"info": map[string]any{},
|
|
||||||
"packages": map[string]any{
|
|
||||||
"old-1.0.0-build.tar.bz2": map[string]any{
|
|
||||||
"name": "testpkg", "version": "1.0.0", "timestamp": oldTimestamp,
|
|
||||||
},
|
|
||||||
"new-2.0.0-build.tar.bz2": map[string]any{
|
|
||||||
"name": "testpkg", "version": "2.0.0", "timestamp": recentTimestamp,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
"packages.conda": map[string]any{},
|
|
||||||
})
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
_, _ = w.Write(repodataJSON)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{
|
|
||||||
Default: "3d",
|
|
||||||
}
|
|
||||||
|
|
||||||
h := &CondaHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/conda-forge/noarch/repodata.json", nil)
|
|
||||||
req.SetPathValue("channel", "conda-forge")
|
|
||||||
req.SetPathValue("arch", "noarch")
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handleRepodata(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(w.Body.Bytes(), &result); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
packages := result["packages"].(map[string]any)
|
|
||||||
if len(packages) != 1 {
|
|
||||||
t.Fatalf("expected 1 package after filtering, got %d", len(packages))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestCondaHandleRepodataWithoutCooldown(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
_, _ = w.Write([]byte(`{"info":{},"packages":{},"packages.conda":{}}`))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &CondaHandler{
|
|
||||||
proxy: &Proxy{Logger: slog.Default(), HTTPClient: http.DefaultClient},
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/conda-forge/noarch/repodata.json", nil)
|
|
||||||
req.SetPathValue("channel", "conda-forge")
|
|
||||||
req.SetPathValue("arch", "noarch")
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handleRepodata(w, req)
|
|
||||||
|
|
||||||
// Without cooldown, should proxy directly (response comes from upstream)
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
|
||||||
|
|
@ -2,96 +2,36 @@ package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"errors"
|
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"regexp"
|
"regexp"
|
||||||
"strings"
|
"strings"
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
dockerHubRegistry = "https://registry-1.docker.io"
|
dockerHubRegistry = "https://registry-1.docker.io"
|
||||||
blobMatchCount = 3 // full match + name + digest
|
dockerHubAuth = "https://auth.docker.io"
|
||||||
manifestMatchCount = 3 // full match + name + reference
|
|
||||||
tagsListMatchCount = 2 // full match + name
|
|
||||||
registrySelectorParts = 3 // upstream + name + repository
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// ContainerHandler handles OCI/Docker container registry protocol requests.
|
// ContainerHandler handles OCI/Docker container registry protocol requests.
|
||||||
// It implements the OCI Distribution Spec for pulling images.
|
// It implements the OCI Distribution Spec for pulling images.
|
||||||
// Reference: https://github.com/opencontainers/distribution-spec/blob/main/spec.md
|
// Reference: https://github.com/opencontainers/distribution-spec/blob/main/spec.md
|
||||||
type ContainerHandler struct {
|
type ContainerHandler struct {
|
||||||
proxy *Proxy
|
proxy *Proxy
|
||||||
registryURL string
|
registryURL string
|
||||||
proxyURL string
|
authURL string
|
||||||
namedRegistries map[string]string
|
proxyURL string
|
||||||
registries []containerRegistry
|
|
||||||
}
|
|
||||||
|
|
||||||
type containerRegistry struct {
|
|
||||||
repositoryPrefix string
|
|
||||||
registryURL string
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewContainerHandler creates a new container registry protocol handler.
|
// NewContainerHandler creates a new container registry protocol handler.
|
||||||
// Named registries are selected with the repository prefix
|
func NewContainerHandler(proxy *Proxy, proxyURL string) *ContainerHandler {
|
||||||
// upstream/{name}/, leaving unprefixed requests compatible with the Docker Hub
|
return &ContainerHandler{
|
||||||
// mirror behavior.
|
|
||||||
func NewContainerHandler(proxy *Proxy, proxyURL string, namedRegistries ...map[string]string) *ContainerHandler {
|
|
||||||
h := &ContainerHandler{
|
|
||||||
proxy: proxy,
|
proxy: proxy,
|
||||||
registryURL: dockerHubRegistry,
|
registryURL: dockerHubRegistry,
|
||||||
|
authURL: dockerHubAuth,
|
||||||
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
||||||
}
|
}
|
||||||
if len(namedRegistries) > 0 {
|
|
||||||
h.namedRegistries = make(map[string]string, len(namedRegistries[0]))
|
|
||||||
for name, registryURL := range namedRegistries[0] {
|
|
||||||
h.namedRegistries[name] = strings.TrimSuffix(registryURL, "/")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewContainerHandlerWithRegistry creates a container handler with a custom
|
|
||||||
// default registry and optional named registries.
|
|
||||||
func NewContainerHandlerWithRegistry(
|
|
||||||
proxy *Proxy,
|
|
||||||
proxyURL, registryURL string,
|
|
||||||
namedRegistries ...map[string]string,
|
|
||||||
) *ContainerHandler {
|
|
||||||
h := NewContainerHandler(proxy, proxyURL, namedRegistries...)
|
|
||||||
h.registryURL = configuredUpstreamURL(registryURL, dockerHubRegistry)
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// RegisterRegistry routes a repository and its descendants to a specific OCI
|
|
||||||
// registry. The longest matching repository prefix wins.
|
|
||||||
func (h *ContainerHandler) RegisterRegistry(repositoryPrefix, registryURL string) {
|
|
||||||
h.registries = append(h.registries, containerRegistry{
|
|
||||||
repositoryPrefix: strings.Trim(repositoryPrefix, "/"),
|
|
||||||
registryURL: strings.TrimSuffix(registryURL, "/"),
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
// BlockRegistry prevents a repository and its descendants from falling back to
|
|
||||||
// the default OCI registry. A more specific registered repository still wins.
|
|
||||||
func (h *ContainerHandler) BlockRegistry(repositoryPrefix string) {
|
|
||||||
h.RegisterRegistry(repositoryPrefix, "")
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) registryURLFor(name string) string {
|
|
||||||
registryURL := h.registryURL
|
|
||||||
matchLength := 0
|
|
||||||
for _, registry := range h.registries {
|
|
||||||
if name != registry.repositoryPrefix && !strings.HasPrefix(name, registry.repositoryPrefix+"/") {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
if len(registry.repositoryPrefix) > matchLength {
|
|
||||||
registryURL = registry.registryURL
|
|
||||||
matchLength = len(registry.repositoryPrefix)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return registryURL
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Routes returns the HTTP handler for container registry requests.
|
// Routes returns the HTTP handler for container registry requests.
|
||||||
|
|
@ -144,74 +84,46 @@ func (h *ContainerHandler) handleBlobDownload(w http.ResponseWriter, r *http.Req
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
registryURL, upstreamName, cacheName, ok := h.registryForName(name)
|
h.proxy.Logger.Info("container blob request", "name", name, "digest", digest)
|
||||||
if !ok {
|
|
||||||
h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
h.proxy.Logger.Info("container blob request", "name", upstreamName, "digest", digest)
|
// Get auth token for upstream
|
||||||
|
token, err := h.getAuthToken(r.Context(), name, "pull")
|
||||||
filename := digest
|
|
||||||
cached, err := h.proxy.GetCachedArtifact(r.Context(), "oci", cacheName, digest, filename)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.Logger.Error("failed to check blob cache", "error", err)
|
h.proxy.Logger.Error("failed to get auth token", "error", err)
|
||||||
h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to check blob cache")
|
h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate")
|
||||||
return
|
|
||||||
}
|
|
||||||
if cached != nil {
|
|
||||||
w.Header().Set("Docker-Content-Digest", digest)
|
|
||||||
if cached.Artifact.MediaType == "" {
|
|
||||||
cached.Artifact.MediaType = "application/octet-stream"
|
|
||||||
}
|
|
||||||
serveArtifact(w, r.Method, cached)
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// For HEAD requests, just proxy to upstream
|
// For HEAD requests, just proxy to upstream
|
||||||
if r.Method == http.MethodHead {
|
if r.Method == http.MethodHead {
|
||||||
h.proxyBlobHead(w, r, registryURL, upstreamName, digest)
|
h.proxyBlobHead(w, r, name, digest, token)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// Try to get from cache, or fetch from the authentication-aware upstream client.
|
// Try to get from cache first
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURLWithDigest(
|
filename := digest
|
||||||
|
result, err := h.proxy.GetOrFetchArtifactFromURL(
|
||||||
r.Context(),
|
r.Context(),
|
||||||
"oci",
|
"oci",
|
||||||
cacheName,
|
name,
|
||||||
digest, // use digest as version
|
digest, // use digest as version
|
||||||
filename,
|
filename,
|
||||||
fmt.Sprintf("%s/v2/%s/blobs/%s", registryURL, upstreamName, digest),
|
fmt.Sprintf("%s/v2/%s/blobs/%s", h.registryURL, name, digest),
|
||||||
digest,
|
|
||||||
)
|
)
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if errors.Is(err, ErrUpstreamNotFound) {
|
// Fetch directly with auth
|
||||||
h.containerError(w, http.StatusNotFound, "BLOB_UNKNOWN", "blob unknown to registry")
|
h.proxyBlobWithAuth(w, r, name, digest, token)
|
||||||
return
|
|
||||||
}
|
|
||||||
if errors.Is(err, ErrArtifactBlocked) {
|
|
||||||
h.containerError(w, http.StatusForbidden, "DENIED", err.Error())
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if errors.Is(err, ErrArtifactDigestMismatch) {
|
|
||||||
h.proxy.Logger.Error("upstream blob failed digest verification", "error", err)
|
|
||||||
h.containerError(w, http.StatusBadGateway, "DIGEST_INVALID", "blob digest verification failed")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Error("failed to fetch blob", "error", err)
|
|
||||||
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch blob")
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
w.Header().Set("Docker-Content-Digest", digest)
|
w.Header().Set("Docker-Content-Digest", digest)
|
||||||
if result.Artifact.MediaType == "" {
|
w.Header().Set("Content-Type", "application/octet-stream")
|
||||||
result.Artifact.MediaType = "application/octet-stream"
|
|
||||||
}
|
|
||||||
ServeArtifact(w, result)
|
ServeArtifact(w, result)
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleManifest serves immutable manifests from cache and revalidates mutable tags.
|
// handleManifest proxies manifest requests to upstream.
|
||||||
|
// Manifests change when tags are updated, so we proxy these directly.
|
||||||
// Path format: {name}/manifests/{reference}
|
// Path format: {name}/manifests/{reference}
|
||||||
func (h *ContainerHandler) handleManifest(w http.ResponseWriter, r *http.Request, path string) {
|
func (h *ContainerHandler) handleManifest(w http.ResponseWriter, r *http.Request, path string) {
|
||||||
if r.Method != http.MethodGet && r.Method != http.MethodHead {
|
if r.Method != http.MethodGet && r.Method != http.MethodHead {
|
||||||
|
|
@ -225,17 +137,61 @@ func (h *ContainerHandler) handleManifest(w http.ResponseWriter, r *http.Request
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
registryURL, upstreamName, _, ok := h.registryForName(name)
|
h.proxy.Logger.Info("container manifest request", "name", name, "reference", reference)
|
||||||
if !ok {
|
|
||||||
h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry")
|
// Get auth token
|
||||||
|
token, err := h.getAuthToken(r.Context(), name, "pull")
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Error("failed to get auth token", "error", err)
|
||||||
|
h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate")
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
h.proxy.Logger.Info("container manifest request", "name", upstreamName, "reference", reference)
|
// Proxy to upstream
|
||||||
h.serveManifest(w, r, registryURL, upstreamName, reference)
|
upstreamURL := fmt.Sprintf("%s/v2/%s/manifests/%s", h.registryURL, name, reference)
|
||||||
|
|
||||||
|
req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
req.Header.Set("Authorization", "Bearer "+token)
|
||||||
|
|
||||||
|
// Forward Accept header for content negotiation
|
||||||
|
if accept := r.Header.Get("Accept"); accept != "" {
|
||||||
|
req.Header.Set("Accept", accept)
|
||||||
|
} else {
|
||||||
|
// Default accept headers for manifests
|
||||||
|
req.Header.Set("Accept", strings.Join([]string{
|
||||||
|
"application/vnd.oci.image.manifest.v1+json",
|
||||||
|
"application/vnd.oci.image.index.v1+json",
|
||||||
|
"application/vnd.docker.distribution.manifest.v2+json",
|
||||||
|
"application/vnd.docker.distribution.manifest.list.v2+json",
|
||||||
|
"application/vnd.docker.distribution.manifest.v1+prettyjws",
|
||||||
|
}, ", "))
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Error("failed to fetch manifest", "error", err)
|
||||||
|
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
// Copy relevant headers
|
||||||
|
for _, header := range []string{"Content-Type", "Content-Length", "Docker-Content-Digest", "ETag"} {
|
||||||
|
if v := resp.Header.Get(header); v != "" {
|
||||||
|
w.Header().Set(header, v)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleTagsList caches tag list responses for offline OCI pulls.
|
// handleTagsList proxies tag list requests to upstream.
|
||||||
func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request, path string) {
|
func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request, path string) {
|
||||||
if r.Method != http.MethodGet {
|
if r.Method != http.MethodGet {
|
||||||
http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
|
http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
|
||||||
|
|
@ -248,18 +204,78 @@ func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
registryURL, upstreamName, _, ok := h.registryForName(name)
|
// Get auth token
|
||||||
if !ok {
|
token, err := h.getAuthToken(r.Context(), name, "pull")
|
||||||
h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry")
|
if err != nil {
|
||||||
|
h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate")
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
h.serveTagsList(w, r, registryURL, upstreamName)
|
upstreamURL := fmt.Sprintf("%s/v2/%s/tags/list", h.registryURL, name)
|
||||||
|
if r.URL.RawQuery != "" {
|
||||||
|
upstreamURL += "?" + r.URL.RawQuery
|
||||||
|
}
|
||||||
|
|
||||||
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
req.Header.Set("Authorization", "Bearer "+token)
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
w.Header().Set("Content-Type", "application/json")
|
||||||
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
|
}
|
||||||
|
|
||||||
|
// getAuthToken gets a bearer token for the specified repository.
|
||||||
|
// Docker Hub requires auth even for public images.
|
||||||
|
func (h *ContainerHandler) getAuthToken(_ interface{ Done() <-chan struct{} }, repository, action string) (string, error) {
|
||||||
|
// For Docker Hub: https://auth.docker.io/token?service=registry.docker.io&scope=repository:{repo}:pull
|
||||||
|
authURL := fmt.Sprintf("%s/token?service=registry.docker.io&scope=repository:%s:%s",
|
||||||
|
h.authURL, repository, action)
|
||||||
|
|
||||||
|
req, err := http.NewRequest(http.MethodGet, authURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
if resp.StatusCode != http.StatusOK {
|
||||||
|
return "", fmt.Errorf("auth failed with status %d", resp.StatusCode)
|
||||||
|
}
|
||||||
|
|
||||||
|
var tokenResp struct {
|
||||||
|
Token string `json:"token"`
|
||||||
|
AccessToken string `json:"access_token"`
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := json.NewDecoder(resp.Body).Decode(&tokenResp); err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
if tokenResp.Token != "" {
|
||||||
|
return tokenResp.Token, nil
|
||||||
|
}
|
||||||
|
return tokenResp.AccessToken, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// proxyBlobHead handles HEAD requests for blobs.
|
// proxyBlobHead handles HEAD requests for blobs.
|
||||||
func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, registryURL, name, digest string) {
|
func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, name, digest, token string) {
|
||||||
upstreamURL := fmt.Sprintf("%s/v2/%s/blobs/%s", registryURL, name, digest)
|
upstreamURL := fmt.Sprintf("%s/v2/%s/blobs/%s", h.registryURL, name, digest)
|
||||||
|
|
||||||
req, err := http.NewRequestWithContext(r.Context(), http.MethodHead, upstreamURL, nil)
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodHead, upstreamURL, nil)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
@ -267,51 +283,56 @@ func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request,
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
req.Header.Set("Authorization", "Bearer "+token)
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
defer func() { _ = resp.Body.Close() }()
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
for _, header := range []string{headerContentType, headerContentLength, "Docker-Content-Digest", headerETag, headerLastModified} {
|
for _, header := range []string{"Content-Type", "Content-Length", "Docker-Content-Digest"} {
|
||||||
if v := resp.Header.Get(header); v != "" {
|
if v := resp.Header.Get(header); v != "" {
|
||||||
w.Header().Set(header, v)
|
w.Header().Set(header, v)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if resp.StatusCode >= http.StatusOK && resp.StatusCode < http.StatusMultipleChoices && w.Header().Get("Docker-Content-Digest") == "" {
|
|
||||||
w.Header().Set("Docker-Content-Digest", digest)
|
|
||||||
}
|
|
||||||
|
|
||||||
w.WriteHeader(resp.StatusCode)
|
w.WriteHeader(resp.StatusCode)
|
||||||
}
|
}
|
||||||
|
|
||||||
// registryForName resolves a client-visible OCI repository name to an upstream
|
// proxyBlobWithAuth proxies a blob download with authentication.
|
||||||
// registry and its repository name. Named upstreams use upstream/{name}/ as a
|
func (h *ContainerHandler) proxyBlobWithAuth(w http.ResponseWriter, r *http.Request, name, digest, token string) {
|
||||||
// reserved prefix. Other names are matched against registered repository
|
upstreamURL := fmt.Sprintf("%s/v2/%s/blobs/%s", h.registryURL, name, digest)
|
||||||
// prefixes, falling back to Docker Hub when no prefix matches.
|
|
||||||
func (h *ContainerHandler) registryForName(name string) (registryURL, upstreamName, cacheName string, ok bool) {
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
||||||
parts := strings.SplitN(name, "/", registrySelectorParts)
|
if err != nil {
|
||||||
if len(parts) >= 2 && parts[0] == "upstream" {
|
h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request")
|
||||||
if len(parts) != registrySelectorParts || parts[2] == "" {
|
return
|
||||||
return "", "", "", false
|
|
||||||
}
|
|
||||||
registryURL, ok = h.namedRegistries[parts[1]]
|
|
||||||
if !ok || registryURL == "" {
|
|
||||||
return "", "", "", false
|
|
||||||
}
|
|
||||||
return registryURL, parts[2], name, true
|
|
||||||
}
|
}
|
||||||
registryURL = h.registryURLFor(name)
|
|
||||||
if registryURL == "" {
|
req.Header.Set("Authorization", "Bearer "+token)
|
||||||
return "", "", "", false
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
||||||
|
return
|
||||||
}
|
}
|
||||||
return registryURL, name, name, true
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
for _, header := range []string{"Content-Type", "Content-Length", "Docker-Content-Digest"} {
|
||||||
|
if v := resp.Header.Get(header); v != "" {
|
||||||
|
w.Header().Set(header, v)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
}
|
}
|
||||||
|
|
||||||
// containerError writes an OCI-compliant error response.
|
// containerError writes an OCI-compliant error response.
|
||||||
func (h *ContainerHandler) containerError(w http.ResponseWriter, status int, code, message string) {
|
func (h *ContainerHandler) containerError(w http.ResponseWriter, status int, code, message string) {
|
||||||
w.Header().Set(headerContentType, "application/json")
|
w.Header().Set("Content-Type", "application/json")
|
||||||
w.WriteHeader(status)
|
w.WriteHeader(status)
|
||||||
_ = json.NewEncoder(w).Encode(map[string]any{
|
_ = json.NewEncoder(w).Encode(map[string]any{
|
||||||
"errors": []map[string]string{
|
"errors": []map[string]string{
|
||||||
|
|
@ -326,7 +347,7 @@ var blobPathPattern = regexp.MustCompile(`^(.+)/blobs/(sha256:[a-f0-9]+)$`)
|
||||||
// parseBlobPath extracts repository name and digest from a blob path.
|
// parseBlobPath extracts repository name and digest from a blob path.
|
||||||
func (h *ContainerHandler) parseBlobPath(path string) (name, digest string) {
|
func (h *ContainerHandler) parseBlobPath(path string) (name, digest string) {
|
||||||
matches := blobPathPattern.FindStringSubmatch(path)
|
matches := blobPathPattern.FindStringSubmatch(path)
|
||||||
if len(matches) != blobMatchCount {
|
if len(matches) != 3 {
|
||||||
return "", ""
|
return "", ""
|
||||||
}
|
}
|
||||||
return matches[1], matches[2]
|
return matches[1], matches[2]
|
||||||
|
|
@ -338,7 +359,7 @@ var manifestPathPattern = regexp.MustCompile(`^(.+)/manifests/(.+)$`)
|
||||||
// parseManifestPath extracts repository name and reference from a manifest path.
|
// parseManifestPath extracts repository name and reference from a manifest path.
|
||||||
func (h *ContainerHandler) parseManifestPath(path string) (name, reference string) {
|
func (h *ContainerHandler) parseManifestPath(path string) (name, reference string) {
|
||||||
matches := manifestPathPattern.FindStringSubmatch(path)
|
matches := manifestPathPattern.FindStringSubmatch(path)
|
||||||
if len(matches) != manifestMatchCount {
|
if len(matches) != 3 {
|
||||||
return "", ""
|
return "", ""
|
||||||
}
|
}
|
||||||
return matches[1], matches[2]
|
return matches[1], matches[2]
|
||||||
|
|
@ -350,7 +371,7 @@ var tagsListPathPattern = regexp.MustCompile(`^(.+)/tags/list$`)
|
||||||
// parseTagsListPath extracts repository name from a tags list path.
|
// parseTagsListPath extracts repository name from a tags list path.
|
||||||
func (h *ContainerHandler) parseTagsListPath(path string) string {
|
func (h *ContainerHandler) parseTagsListPath(path string) string {
|
||||||
matches := tagsListPathPattern.FindStringSubmatch(path)
|
matches := tagsListPathPattern.FindStringSubmatch(path)
|
||||||
if len(matches) != tagsListMatchCount {
|
if len(matches) != 2 {
|
||||||
return ""
|
return ""
|
||||||
}
|
}
|
||||||
return matches[1]
|
return matches[1]
|
||||||
|
|
|
||||||
|
|
@ -1,434 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"crypto/sha256"
|
|
||||||
"encoding/hex"
|
|
||||||
"fmt"
|
|
||||||
"io"
|
|
||||||
"mime"
|
|
||||||
"net/http"
|
|
||||||
"regexp"
|
|
||||||
"sort"
|
|
||||||
"strconv"
|
|
||||||
"strings"
|
|
||||||
"time"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
containerManifestCacheEcosystem = "oci-manifest"
|
|
||||||
containerStaleWarning = `110 - "Response is Stale"`
|
|
||||||
|
|
||||||
containerAcceptWildcardSpecificity = iota
|
|
||||||
containerAcceptTypeWildcardSpecificity
|
|
||||||
containerAcceptExactSpecificity
|
|
||||||
)
|
|
||||||
|
|
||||||
var manifestDigestReferencePattern = regexp.MustCompile(`^[a-z0-9]+:[a-f0-9]+$`)
|
|
||||||
|
|
||||||
type cachedContainerManifest struct {
|
|
||||||
body []byte
|
|
||||||
contentType string
|
|
||||||
contentDigest string
|
|
||||||
etag string
|
|
||||||
size int64
|
|
||||||
lastModified time.Time
|
|
||||||
fetchedAt time.Time
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) serveManifest(w http.ResponseWriter, r *http.Request, registryURL, name, reference string) {
|
|
||||||
accept := containerManifestAccept(r)
|
|
||||||
cacheAccept := normalizeContainerManifestAccept(accept)
|
|
||||||
cacheKey := h.containerManifestCacheKey(registryURL, name, reference, cacheAccept)
|
|
||||||
cached := h.loadContainerManifestForAccept(r.Context(), registryURL, name, reference, accept, cacheKey)
|
|
||||||
|
|
||||||
immutable := manifestDigestReferencePattern.MatchString(reference)
|
|
||||||
if cached != nil && (immutable || h.containerManifestFresh(cached)) {
|
|
||||||
writeContainerManifest(w, r, cached, false)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
upstreamURL := fmt.Sprintf("%s/v2/%s/manifests/%s", registryURL, name, reference)
|
|
||||||
req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil)
|
|
||||||
if err != nil {
|
|
||||||
h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
req.Header.Set("Accept", accept)
|
|
||||||
if cached != nil && cached.etag != "" {
|
|
||||||
req.Header.Set("If-None-Match", cached.etag)
|
|
||||||
}
|
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
h.serveStaleManifestOrError(w, r, cached, err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode == http.StatusNotModified && cached != nil {
|
|
||||||
cached.fetchedAt = time.Now()
|
|
||||||
h.storeContainerManifestForAccept(r.Context(), registryURL, name, reference, accept, cacheAccept, cached)
|
|
||||||
writeContainerManifest(w, r, cached, false)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
|
||||||
if cached != nil && shouldServeStaleManifest(resp.StatusCode) {
|
|
||||||
writeContainerManifest(w, r, cached, true)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
copyContainerManifestHeaders(w.Header(), resp.Header)
|
|
||||||
w.WriteHeader(resp.StatusCode)
|
|
||||||
_, _ = io.Copy(w, resp.Body)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if r.Method == http.MethodHead {
|
|
||||||
copyContainerManifestHeaders(w.Header(), resp.Header)
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
body, err := h.proxy.ReadMetadata(resp.Body)
|
|
||||||
if err != nil {
|
|
||||||
h.serveStaleManifestOrError(w, r, cached, fmt.Errorf("reading manifest: %w", err))
|
|
||||||
return
|
|
||||||
}
|
|
||||||
computedDigest := sha256Digest(body)
|
|
||||||
contentDigest := resp.Header.Get("Docker-Content-Digest")
|
|
||||||
for _, expected := range []string{reference, contentDigest} {
|
|
||||||
if strings.HasPrefix(expected, "sha256:") && expected != computedDigest {
|
|
||||||
h.proxy.Logger.Error("upstream manifest failed digest verification",
|
|
||||||
"name", name, "reference", reference, "expected", expected, "actual", computedDigest)
|
|
||||||
h.containerError(w, http.StatusBadGateway, "DIGEST_INVALID", "manifest digest verification failed")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if contentDigest == "" {
|
|
||||||
contentDigest = computedDigest
|
|
||||||
}
|
|
||||||
|
|
||||||
manifest := &cachedContainerManifest{
|
|
||||||
body: body,
|
|
||||||
contentType: resp.Header.Get(headerContentType),
|
|
||||||
contentDigest: contentDigest,
|
|
||||||
etag: resp.Header.Get(headerETag),
|
|
||||||
size: int64(len(body)),
|
|
||||||
lastModified: parseHTTPTime(resp.Header.Get(headerLastModified)),
|
|
||||||
fetchedAt: time.Now(),
|
|
||||||
}
|
|
||||||
h.storeContainerManifestForAccept(r.Context(), registryURL, name, reference, accept, cacheAccept, manifest)
|
|
||||||
if manifest.contentDigest != reference && manifestDigestReferencePattern.MatchString(manifest.contentDigest) {
|
|
||||||
h.storeContainerManifestForAccept(r.Context(), registryURL, name, manifest.contentDigest, accept, cacheAccept, manifest)
|
|
||||||
}
|
|
||||||
writeContainerManifest(w, r, manifest, false)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) serveStaleManifestOrError(w http.ResponseWriter, r *http.Request, cached *cachedContainerManifest, err error) {
|
|
||||||
if cached != nil {
|
|
||||||
h.proxy.Logger.Warn("upstream manifest fetch failed, serving stale cache", "error", err)
|
|
||||||
writeContainerManifest(w, r, cached, true)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Error("failed to fetch manifest", "error", err)
|
|
||||||
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) containerManifestFresh(manifest *cachedContainerManifest) bool {
|
|
||||||
return h.proxy.MetadataTTL > 0 && !manifest.fetchedAt.IsZero() && time.Since(manifest.fetchedAt) < h.proxy.MetadataTTL
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) containerManifestCacheKey(registryURL, name, reference, accept string) string {
|
|
||||||
identity := strings.Join([]string{registryURL, name, reference, accept}, "\x00")
|
|
||||||
sum := sha256.Sum256([]byte(identity))
|
|
||||||
return hex.EncodeToString(sum[:])
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) loadContainerManifestForAccept(ctx context.Context, registryURL, name, reference, accept, cacheKey string) *cachedContainerManifest {
|
|
||||||
cached, err := h.loadContainerManifest(ctx, cacheKey)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to read cached container manifest", "error", err)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
if cached != nil {
|
|
||||||
if containerManifestCacheCompatible(accept, cached) {
|
|
||||||
return cached
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
legacyCacheKey := h.containerManifestCacheKey(registryURL, name, reference, accept)
|
|
||||||
if legacyCacheKey == cacheKey {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
cached, err = h.loadContainerManifest(ctx, legacyCacheKey)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to read legacy cached container manifest", "error", err)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
if cached == nil || !containerManifestCacheCompatible(accept, cached) {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
if err := h.storeContainerManifest(ctx, cacheKey, cached); err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to migrate cached container manifest", "error", err)
|
|
||||||
}
|
|
||||||
return cached
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) storeContainerManifestForAccept(ctx context.Context, registryURL, name, reference, accept, cacheAccept string, manifest *cachedContainerManifest) {
|
|
||||||
cacheKey := h.containerManifestCacheKey(registryURL, name, reference, cacheAccept)
|
|
||||||
if err := h.storeContainerManifest(ctx, cacheKey, manifest); err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to cache container manifest", "error", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
legacyCacheKey := h.containerManifestCacheKey(registryURL, name, reference, accept)
|
|
||||||
if legacyCacheKey == cacheKey {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if err := h.storeContainerManifest(ctx, legacyCacheKey, manifest); err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to cache legacy container manifest", "error", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) loadContainerManifest(ctx context.Context, cacheKey string) (*cachedContainerManifest, error) {
|
|
||||||
if h.proxy.DB == nil || h.proxy.Storage == nil {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
entry, err := h.proxy.DB.GetMetadataCache(containerManifestCacheEcosystem, cacheKey)
|
|
||||||
if err != nil || entry == nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
reader, err := h.proxy.Storage.Open(ctx, entry.StoragePath)
|
|
||||||
if err != nil {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
defer func() { _ = reader.Close() }()
|
|
||||||
body, err := h.proxy.ReadMetadata(reader)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
manifest := &cachedContainerManifest{body: body, size: int64(len(body))}
|
|
||||||
if entry.ContentType.Valid {
|
|
||||||
manifest.contentType = entry.ContentType.String
|
|
||||||
}
|
|
||||||
if entry.ContentDigest.Valid {
|
|
||||||
manifest.contentDigest = entry.ContentDigest.String
|
|
||||||
} else {
|
|
||||||
manifest.contentDigest = sha256Digest(body)
|
|
||||||
}
|
|
||||||
if entry.ETag.Valid {
|
|
||||||
manifest.etag = entry.ETag.String
|
|
||||||
}
|
|
||||||
if entry.Size.Valid {
|
|
||||||
manifest.size = entry.Size.Int64
|
|
||||||
}
|
|
||||||
if entry.LastModified.Valid {
|
|
||||||
manifest.lastModified = entry.LastModified.Time
|
|
||||||
}
|
|
||||||
if entry.FetchedAt.Valid {
|
|
||||||
manifest.fetchedAt = entry.FetchedAt.Time
|
|
||||||
}
|
|
||||||
return manifest, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) storeContainerManifest(ctx context.Context, cacheKey string, manifest *cachedContainerManifest) error {
|
|
||||||
size, err := h.storeContainerMetadata(ctx, containerManifestCacheEcosystem, cacheKey, manifest.body,
|
|
||||||
manifest.etag, "", manifest.contentType, manifest.contentDigest, manifest.lastModified, manifest.fetchedAt)
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("storing manifest: %w", err)
|
|
||||||
}
|
|
||||||
manifest.size = size
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func writeContainerManifest(w http.ResponseWriter, r *http.Request, manifest *cachedContainerManifest, stale bool) {
|
|
||||||
if manifest.contentType != "" {
|
|
||||||
w.Header().Set(headerContentType, manifest.contentType)
|
|
||||||
}
|
|
||||||
w.Header().Set(headerContentLength, strconv.FormatInt(manifest.size, 10))
|
|
||||||
if manifest.contentDigest != "" {
|
|
||||||
w.Header().Set("Docker-Content-Digest", manifest.contentDigest)
|
|
||||||
}
|
|
||||||
if manifest.etag != "" {
|
|
||||||
w.Header().Set(headerETag, manifest.etag)
|
|
||||||
}
|
|
||||||
if !manifest.lastModified.IsZero() {
|
|
||||||
w.Header().Set(headerLastModified, manifest.lastModified.UTC().Format(http.TimeFormat))
|
|
||||||
}
|
|
||||||
if stale {
|
|
||||||
w.Header().Set("Warning", containerStaleWarning)
|
|
||||||
}
|
|
||||||
if ifNoneMatchHits(r.Header.Get("If-None-Match"), manifest.etag) {
|
|
||||||
w.WriteHeader(http.StatusNotModified)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if !manifest.lastModified.IsZero() {
|
|
||||||
if modifiedSince, err := http.ParseTime(r.Header.Get("If-Modified-Since")); err == nil && !manifest.lastModified.After(modifiedSince) {
|
|
||||||
w.WriteHeader(http.StatusNotModified)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
}
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
if r.Method != http.MethodHead {
|
|
||||||
_, _ = w.Write(manifest.body)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func containerManifestAccept(r *http.Request) string {
|
|
||||||
if accept := r.Header.Get("Accept"); accept != "" {
|
|
||||||
return accept
|
|
||||||
}
|
|
||||||
return strings.Join([]string{
|
|
||||||
"application/vnd.oci.image.manifest.v1+json",
|
|
||||||
"application/vnd.oci.image.index.v1+json",
|
|
||||||
"application/vnd.docker.distribution.manifest.v2+json",
|
|
||||||
"application/vnd.docker.distribution.manifest.list.v2+json",
|
|
||||||
"application/vnd.docker.distribution.manifest.v1+prettyjws",
|
|
||||||
}, ", ")
|
|
||||||
}
|
|
||||||
|
|
||||||
func normalizeContainerManifestAccept(accept string) string {
|
|
||||||
mediaTypes := make(map[string]struct{})
|
|
||||||
for _, value := range strings.Split(accept, ",") {
|
|
||||||
value = strings.TrimSpace(value)
|
|
||||||
if value == "" {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
mediaType, params, err := mime.ParseMediaType(value)
|
|
||||||
if err != nil {
|
|
||||||
mediaTypes[strings.ToLower(value)] = struct{}{}
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
paramKeys := make([]string, 0, len(params))
|
|
||||||
for key := range params {
|
|
||||||
paramKeys = append(paramKeys, key)
|
|
||||||
}
|
|
||||||
sort.Strings(paramKeys)
|
|
||||||
canonical := strings.ToLower(mediaType)
|
|
||||||
for _, key := range paramKeys {
|
|
||||||
value := params[key]
|
|
||||||
if strings.EqualFold(key, "q") {
|
|
||||||
if quality, err := strconv.ParseFloat(value, 64); err == nil {
|
|
||||||
if quality == 1 {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
value = strconv.FormatFloat(quality, 'g', -1, 64)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
canonical += ";" + strings.ToLower(key) + "=" + value
|
|
||||||
}
|
|
||||||
mediaTypes[canonical] = struct{}{}
|
|
||||||
}
|
|
||||||
canonicalMediaTypes := make([]string, 0, len(mediaTypes))
|
|
||||||
for mediaType := range mediaTypes {
|
|
||||||
canonicalMediaTypes = append(canonicalMediaTypes, mediaType)
|
|
||||||
}
|
|
||||||
sort.Strings(canonicalMediaTypes)
|
|
||||||
return strings.Join(canonicalMediaTypes, ",")
|
|
||||||
}
|
|
||||||
|
|
||||||
func containerManifestAccepts(accept, contentType string) bool {
|
|
||||||
contentType, contentParams, err := mime.ParseMediaType(contentType)
|
|
||||||
if err != nil {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
contentType = strings.ToLower(contentType)
|
|
||||||
contentMajor, contentMinor, found := strings.Cut(contentType, "/")
|
|
||||||
if !found {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
bestMediaTypeSpecificity := -1
|
|
||||||
bestParameterSpecificity := 0
|
|
||||||
bestQuality := 0.0
|
|
||||||
for _, value := range strings.Split(accept, ",") {
|
|
||||||
mediaType, params, err := mime.ParseMediaType(strings.TrimSpace(value))
|
|
||||||
if err != nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
mediaType = strings.ToLower(mediaType)
|
|
||||||
major, minor, found := strings.Cut(mediaType, "/")
|
|
||||||
if found && containerAcceptRangeMatches(major, minor, params, contentMajor, contentMinor, contentParams) {
|
|
||||||
mediaTypeSpecificity, parameterSpecificity := containerAcceptSpecificity(major, minor, params)
|
|
||||||
if mediaTypeSpecificity > bestMediaTypeSpecificity ||
|
|
||||||
(mediaTypeSpecificity == bestMediaTypeSpecificity && parameterSpecificity > bestParameterSpecificity) {
|
|
||||||
bestMediaTypeSpecificity = mediaTypeSpecificity
|
|
||||||
bestParameterSpecificity = parameterSpecificity
|
|
||||||
bestQuality = containerAcceptQuality(params)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return bestQuality > 0
|
|
||||||
}
|
|
||||||
|
|
||||||
func containerManifestCacheCompatible(accept string, manifest *cachedContainerManifest) bool {
|
|
||||||
return manifest.contentType == "" || containerManifestAccepts(accept, manifest.contentType)
|
|
||||||
}
|
|
||||||
|
|
||||||
func containerAcceptRangeMatches(major, minor string, params map[string]string, contentMajor, contentMinor string, contentParams map[string]string) bool {
|
|
||||||
if (major != "*" && major != contentMajor) || (minor != "*" && minor != contentMinor) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
for key, value := range params {
|
|
||||||
if strings.EqualFold(key, "q") {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
if contentParams[key] != value {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
func containerAcceptSpecificity(major, minor string, params map[string]string) (int, int) {
|
|
||||||
parameterSpecificity := 0
|
|
||||||
for key := range params {
|
|
||||||
if !strings.EqualFold(key, "q") {
|
|
||||||
parameterSpecificity++
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
switch {
|
|
||||||
case major == "*" && minor == "*":
|
|
||||||
return containerAcceptWildcardSpecificity, parameterSpecificity
|
|
||||||
case major == "*" || minor == "*":
|
|
||||||
return containerAcceptTypeWildcardSpecificity, parameterSpecificity
|
|
||||||
default:
|
|
||||||
return containerAcceptExactSpecificity, parameterSpecificity
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func containerAcceptQuality(params map[string]string) float64 {
|
|
||||||
value, ok := params["q"]
|
|
||||||
if !ok {
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
quality, err := strconv.ParseFloat(value, 64)
|
|
||||||
if err != nil || quality < 0 || quality > 1 {
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
return quality
|
|
||||||
}
|
|
||||||
|
|
||||||
func copyContainerManifestHeaders(destination, source http.Header) {
|
|
||||||
for _, header := range []string{headerContentType, headerContentLength, "Docker-Content-Digest", headerETag, headerLastModified, "WWW-Authenticate"} {
|
|
||||||
if value := source.Get(header); value != "" {
|
|
||||||
destination.Set(header, value)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func parseHTTPTime(value string) time.Time {
|
|
||||||
parsed, _ := http.ParseTime(value)
|
|
||||||
return parsed
|
|
||||||
}
|
|
||||||
|
|
||||||
func shouldServeStaleManifest(status int) bool {
|
|
||||||
return status == http.StatusTooManyRequests || status >= http.StatusInternalServerError
|
|
||||||
}
|
|
||||||
|
|
||||||
func sha256Digest(body []byte) string {
|
|
||||||
digest := sha256.Sum256(body)
|
|
||||||
return "sha256:" + hex.EncodeToString(digest[:])
|
|
||||||
}
|
|
||||||
|
|
@ -1,39 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bytes"
|
|
||||||
"context"
|
|
||||||
"database/sql"
|
|
||||||
"fmt"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/proxy/internal/database"
|
|
||||||
)
|
|
||||||
|
|
||||||
func (h *ContainerHandler) storeContainerMetadata(ctx context.Context, ecosystem, cacheKey string, body []byte, etag, link, contentType, contentDigest string, lastModified, fetchedAt time.Time) (int64, error) {
|
|
||||||
if h.proxy.DB == nil || h.proxy.Storage == nil {
|
|
||||||
return int64(len(body)), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
storagePath := metadataStoragePath(ecosystem, cacheKey)
|
|
||||||
size, _, err := h.proxy.Storage.Store(ctx, storagePath, bytes.NewReader(body))
|
|
||||||
if err != nil {
|
|
||||||
return 0, fmt.Errorf("storing metadata: %w", err)
|
|
||||||
}
|
|
||||||
err = h.proxy.DB.UpsertMetadataCache(&database.MetadataCacheEntry{
|
|
||||||
Ecosystem: ecosystem,
|
|
||||||
Name: cacheKey,
|
|
||||||
StoragePath: storagePath,
|
|
||||||
ETag: sql.NullString{String: etag, Valid: etag != ""},
|
|
||||||
Link: sql.NullString{String: link, Valid: link != ""},
|
|
||||||
ContentType: sql.NullString{String: contentType, Valid: contentType != ""},
|
|
||||||
ContentDigest: sql.NullString{String: contentDigest, Valid: contentDigest != ""},
|
|
||||||
Size: sql.NullInt64{Int64: size, Valid: true},
|
|
||||||
LastModified: sql.NullTime{Time: lastModified, Valid: !lastModified.IsZero()},
|
|
||||||
FetchedAt: sql.NullTime{Time: fetchedAt, Valid: !fetchedAt.IsZero()},
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
return size, nil
|
|
||||||
}
|
|
||||||
|
|
@ -1,229 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"crypto/sha256"
|
|
||||||
"encoding/hex"
|
|
||||||
"fmt"
|
|
||||||
"io"
|
|
||||||
"net/http"
|
|
||||||
"net/url"
|
|
||||||
"regexp"
|
|
||||||
"strconv"
|
|
||||||
"strings"
|
|
||||||
"time"
|
|
||||||
)
|
|
||||||
|
|
||||||
const containerTagsCacheEcosystem = "oci-tags"
|
|
||||||
|
|
||||||
var containerLinkTargetPattern = regexp.MustCompile(`<([^>]*)>`)
|
|
||||||
|
|
||||||
type cachedContainerTags struct {
|
|
||||||
body []byte
|
|
||||||
contentType string
|
|
||||||
etag string
|
|
||||||
link string
|
|
||||||
size int64
|
|
||||||
fetchedAt time.Time
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) serveTagsList(w http.ResponseWriter, r *http.Request, registryURL, name string) {
|
|
||||||
cacheKey := h.containerTagsCacheKey(registryURL, name, r.URL.Query())
|
|
||||||
cached, err := h.loadContainerTags(r.Context(), cacheKey)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to read cached container tag list", "error", err)
|
|
||||||
cached = nil
|
|
||||||
}
|
|
||||||
if cached != nil && h.containerTagsFresh(cached) {
|
|
||||||
writeContainerTags(w, cached, false)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
upstreamURL := fmt.Sprintf("%s/v2/%s/tags/list", registryURL, name)
|
|
||||||
if query := r.URL.Query().Encode(); query != "" {
|
|
||||||
upstreamURL += "?" + query
|
|
||||||
}
|
|
||||||
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
|
||||||
if err != nil {
|
|
||||||
h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
req.Header.Set("Accept", "application/json")
|
|
||||||
if cached != nil && cached.etag != "" {
|
|
||||||
req.Header.Set("If-None-Match", cached.etag)
|
|
||||||
}
|
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
h.serveStaleTagsOrError(w, cached, err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode == http.StatusNotModified && cached != nil {
|
|
||||||
cached.fetchedAt = time.Now()
|
|
||||||
if err := h.storeContainerTags(r.Context(), cacheKey, cached); err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to refresh cached container tag list", "error", err)
|
|
||||||
}
|
|
||||||
writeContainerTags(w, cached, false)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
|
||||||
if cached != nil && shouldServeStaleManifest(resp.StatusCode) {
|
|
||||||
writeContainerTags(w, cached, true)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
copyContainerTagsHeaders(w.Header(), resp.Header)
|
|
||||||
w.WriteHeader(resp.StatusCode)
|
|
||||||
_, _ = io.Copy(w, resp.Body)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
body, err := h.proxy.ReadMetadata(resp.Body)
|
|
||||||
if err != nil {
|
|
||||||
h.serveStaleTagsOrError(w, cached, fmt.Errorf("reading tag list: %w", err))
|
|
||||||
return
|
|
||||||
}
|
|
||||||
tags := &cachedContainerTags{
|
|
||||||
body: body,
|
|
||||||
contentType: resp.Header.Get(headerContentType),
|
|
||||||
etag: resp.Header.Get(headerETag),
|
|
||||||
link: h.rewriteContainerTagsLink(strings.Join(resp.Header.Values("Link"), ", "), registryURL, r.URL.Path),
|
|
||||||
size: int64(len(body)),
|
|
||||||
fetchedAt: time.Now(),
|
|
||||||
}
|
|
||||||
if tags.contentType == "" {
|
|
||||||
tags.contentType = contentTypeJSON
|
|
||||||
}
|
|
||||||
if err := h.storeContainerTags(r.Context(), cacheKey, tags); err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to cache container tag list", "error", err)
|
|
||||||
}
|
|
||||||
writeContainerTags(w, tags, false)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) serveStaleTagsOrError(w http.ResponseWriter, cached *cachedContainerTags, err error) {
|
|
||||||
if cached != nil {
|
|
||||||
h.proxy.Logger.Warn("upstream tag list fetch failed, serving stale cache", "error", err)
|
|
||||||
writeContainerTags(w, cached, true)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Error("failed to fetch container tag list", "error", err)
|
|
||||||
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) containerTagsCacheKey(registryURL, name string, query url.Values) string {
|
|
||||||
identity := registryURL + "\x00" + name + "\x00" + query.Encode()
|
|
||||||
sum := sha256.Sum256([]byte(identity))
|
|
||||||
return hex.EncodeToString(sum[:])
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) containerTagsFresh(tags *cachedContainerTags) bool {
|
|
||||||
return h.proxy.MetadataTTL > 0 && !tags.fetchedAt.IsZero() && time.Since(tags.fetchedAt) < h.proxy.MetadataTTL
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) loadContainerTags(ctx context.Context, cacheKey string) (*cachedContainerTags, error) {
|
|
||||||
if h.proxy.DB == nil || h.proxy.Storage == nil {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
entry, err := h.proxy.DB.GetMetadataCache(containerTagsCacheEcosystem, cacheKey)
|
|
||||||
if err != nil || entry == nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
reader, err := h.proxy.Storage.Open(ctx, entry.StoragePath)
|
|
||||||
if err != nil {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
defer func() { _ = reader.Close() }()
|
|
||||||
body, err := h.proxy.ReadMetadata(reader)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
tags := &cachedContainerTags{body: body, contentType: contentTypeJSON, size: int64(len(body))}
|
|
||||||
if entry.ContentType.Valid {
|
|
||||||
tags.contentType = entry.ContentType.String
|
|
||||||
}
|
|
||||||
if entry.ETag.Valid {
|
|
||||||
tags.etag = entry.ETag.String
|
|
||||||
}
|
|
||||||
if entry.Link.Valid {
|
|
||||||
tags.link = entry.Link.String
|
|
||||||
}
|
|
||||||
if entry.Size.Valid {
|
|
||||||
tags.size = entry.Size.Int64
|
|
||||||
}
|
|
||||||
if entry.FetchedAt.Valid {
|
|
||||||
tags.fetchedAt = entry.FetchedAt.Time
|
|
||||||
}
|
|
||||||
return tags, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) storeContainerTags(ctx context.Context, cacheKey string, tags *cachedContainerTags) error {
|
|
||||||
size, err := h.storeContainerMetadata(ctx, containerTagsCacheEcosystem, cacheKey, tags.body,
|
|
||||||
tags.etag, tags.link, tags.contentType, "", time.Time{}, tags.fetchedAt)
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("storing tag list: %w", err)
|
|
||||||
}
|
|
||||||
tags.size = size
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func writeContainerTags(w http.ResponseWriter, tags *cachedContainerTags, stale bool) {
|
|
||||||
w.Header().Set(headerContentType, tags.contentType)
|
|
||||||
w.Header().Set(headerContentLength, strconv.FormatInt(tags.size, 10))
|
|
||||||
if tags.etag != "" {
|
|
||||||
w.Header().Set(headerETag, tags.etag)
|
|
||||||
}
|
|
||||||
if tags.link != "" {
|
|
||||||
w.Header().Set("Link", tags.link)
|
|
||||||
}
|
|
||||||
if stale {
|
|
||||||
w.Header().Set("Warning", containerStaleWarning)
|
|
||||||
}
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
_, _ = w.Write(tags.body)
|
|
||||||
}
|
|
||||||
|
|
||||||
func copyContainerTagsHeaders(destination, source http.Header) {
|
|
||||||
for _, header := range []string{headerContentType, headerContentLength, headerETag, "Link", "WWW-Authenticate"} {
|
|
||||||
if value := source.Get(header); value != "" {
|
|
||||||
destination.Set(header, value)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *ContainerHandler) rewriteContainerTagsLink(link, registryURL, requestPath string) string {
|
|
||||||
if link == "" {
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
upstreamURL, err := url.Parse(registryURL)
|
|
||||||
if err != nil {
|
|
||||||
return link
|
|
||||||
}
|
|
||||||
proxyURL, err := url.Parse(h.proxyURL)
|
|
||||||
if err != nil {
|
|
||||||
return link
|
|
||||||
}
|
|
||||||
|
|
||||||
return containerLinkTargetPattern.ReplaceAllStringFunc(link, func(target string) string {
|
|
||||||
linkURL, err := url.Parse(target[1 : len(target)-1])
|
|
||||||
if err != nil {
|
|
||||||
return target
|
|
||||||
}
|
|
||||||
if linkURL.IsAbs() {
|
|
||||||
if linkURL.Scheme != upstreamURL.Scheme || linkURL.Host != upstreamURL.Host {
|
|
||||||
return target
|
|
||||||
}
|
|
||||||
} else if linkURL.Host != "" || (linkURL.Path != "" && !strings.HasPrefix(linkURL.Path, "/v2/")) {
|
|
||||||
return target
|
|
||||||
}
|
|
||||||
// Relative registry API links resolve against the current tag-list
|
|
||||||
// endpoint. Rebuild them below so named-registry selectors are kept.
|
|
||||||
linkURL.Scheme = proxyURL.Scheme
|
|
||||||
linkURL.Host = proxyURL.Host
|
|
||||||
linkURL.User = proxyURL.User
|
|
||||||
linkURL.Path = strings.TrimSuffix(proxyURL.Path, "/") + "/v2" + requestPath
|
|
||||||
linkURL.RawPath = ""
|
|
||||||
return "<" + linkURL.String() + ">"
|
|
||||||
})
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,6 +1,7 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
)
|
)
|
||||||
|
|
@ -25,26 +26,19 @@ func NewCRANHandler(proxy *Proxy, proxyURL string) *CRANHandler {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewCRANHandlerWithUpstream creates a CRAN handler with a custom upstream.
|
|
||||||
func NewCRANHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *CRANHandler {
|
|
||||||
h := NewCRANHandler(proxy, proxyURL)
|
|
||||||
h.upstreamURL = configuredUpstreamURL(upstreamURL, cranUpstream)
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for CRAN requests.
|
// Routes returns the HTTP handler for CRAN requests.
|
||||||
func (h *CRANHandler) Routes() http.Handler {
|
func (h *CRANHandler) Routes() http.Handler {
|
||||||
mux := http.NewServeMux()
|
mux := http.NewServeMux()
|
||||||
|
|
||||||
// Package indexes
|
// Package indexes
|
||||||
mux.HandleFunc("GET /src/contrib/PACKAGES", h.proxyCached)
|
mux.HandleFunc("GET /src/contrib/PACKAGES", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET /src/contrib/PACKAGES.gz", h.proxyCached)
|
mux.HandleFunc("GET /src/contrib/PACKAGES.gz", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET /src/contrib/PACKAGES.rds", h.proxyCached)
|
mux.HandleFunc("GET /src/contrib/PACKAGES.rds", h.proxyUpstream)
|
||||||
|
|
||||||
// Binary package indexes
|
// Binary package indexes
|
||||||
mux.HandleFunc("GET /bin/{platform}/contrib/{rversion}/PACKAGES", h.proxyCached)
|
mux.HandleFunc("GET /bin/{platform}/contrib/{rversion}/PACKAGES", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET /bin/{platform}/contrib/{rversion}/PACKAGES.gz", h.proxyCached)
|
mux.HandleFunc("GET /bin/{platform}/contrib/{rversion}/PACKAGES.gz", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET /bin/{platform}/contrib/{rversion}/PACKAGES.rds", h.proxyCached)
|
mux.HandleFunc("GET /bin/{platform}/contrib/{rversion}/PACKAGES.rds", h.proxyUpstream)
|
||||||
|
|
||||||
// Source package downloads
|
// Source package downloads
|
||||||
mux.HandleFunc("GET /src/contrib/{filename}", h.handleSourceDownload)
|
mux.HandleFunc("GET /src/contrib/{filename}", h.handleSourceDownload)
|
||||||
|
|
@ -79,7 +73,8 @@ func (h *CRANHandler) handleSourceDownload(w http.ResponseWriter, r *http.Reques
|
||||||
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "cran", name, version, filename, upstreamURL)
|
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "cran", name, version, filename, upstreamURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch package")
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
|
http.Error(w, "failed to fetch package", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -113,7 +108,8 @@ func (h *CRANHandler) handleBinaryDownload(w http.ResponseWriter, r *http.Reques
|
||||||
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "cran", name, storageVersion, filename, upstreamURL)
|
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "cran", name, storageVersion, filename, upstreamURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch package")
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
|
http.Error(w, "failed to fetch package", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -155,14 +151,36 @@ func (h *CRANHandler) isBinaryPackage(filename string) bool {
|
||||||
return strings.HasSuffix(filename, ".zip") || strings.HasSuffix(filename, ".tgz")
|
return strings.HasSuffix(filename, ".zip") || strings.HasSuffix(filename, ".tgz")
|
||||||
}
|
}
|
||||||
|
|
||||||
// proxyCached forwards a metadata request with caching.
|
|
||||||
func (h *CRANHandler) proxyCached(w http.ResponseWriter, r *http.Request) {
|
|
||||||
cacheKey := strings.TrimPrefix(r.URL.Path, "/")
|
|
||||||
cacheKey = strings.ReplaceAll(cacheKey, "/", "_")
|
|
||||||
h.proxy.ProxyCached(w, r, h.upstreamURL+r.URL.Path, "cran", cacheKey, "*/*")
|
|
||||||
}
|
|
||||||
|
|
||||||
// proxyUpstream forwards a request to CRAN without caching.
|
// proxyUpstream forwards a request to CRAN without caching.
|
||||||
func (h *CRANHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
func (h *CRANHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
||||||
h.proxy.ProxyUpstream(w, r, h.upstreamURL+r.URL.Path, []string{headerAcceptEncoding})
|
upstreamURL := h.upstreamURL + r.URL.Path
|
||||||
|
|
||||||
|
h.proxy.Logger.Debug("proxying to upstream", "url", upstreamURL)
|
||||||
|
|
||||||
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, "failed to create request", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
if ae := r.Header.Get("Accept-Encoding"); ae != "" {
|
||||||
|
req.Header.Set("Accept-Encoding", ae)
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Error("upstream request failed", "error", err)
|
||||||
|
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
for k, vv := range resp.Header {
|
||||||
|
for _, v := range vv {
|
||||||
|
w.Header().Add(k, v)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -2,6 +2,7 @@ package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"regexp"
|
"regexp"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
@ -9,7 +10,6 @@ import (
|
||||||
|
|
||||||
const (
|
const (
|
||||||
debianUpstream = "http://deb.debian.org/debian"
|
debianUpstream = "http://deb.debian.org/debian"
|
||||||
debMatchCount = 4 // full match + name + version + arch
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// DebianHandler handles APT/Debian repository protocol requests.
|
// DebianHandler handles APT/Debian repository protocol requests.
|
||||||
|
|
@ -21,13 +21,10 @@ type DebianHandler struct {
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewDebianHandler creates a new Debian/APT protocol handler.
|
// NewDebianHandler creates a new Debian/APT protocol handler.
|
||||||
func NewDebianHandler(proxy *Proxy, proxyURL string, upstreamURL string) *DebianHandler {
|
func NewDebianHandler(proxy *Proxy, proxyURL string) *DebianHandler {
|
||||||
if upstreamURL == "" {
|
|
||||||
upstreamURL = debianUpstream
|
|
||||||
}
|
|
||||||
return &DebianHandler{
|
return &DebianHandler{
|
||||||
proxy: proxy,
|
proxy: proxy,
|
||||||
upstreamURL: strings.TrimSuffix(upstreamURL, "/"),
|
upstreamURL: debianUpstream,
|
||||||
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -43,11 +40,6 @@ func (h *DebianHandler) Routes() http.Handler {
|
||||||
|
|
||||||
path := strings.TrimPrefix(r.URL.Path, "/")
|
path := strings.TrimPrefix(r.URL.Path, "/")
|
||||||
|
|
||||||
if containsPathTraversal(path) {
|
|
||||||
http.Error(w, "invalid path", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// Route based on path type
|
// Route based on path type
|
||||||
switch {
|
switch {
|
||||||
case strings.HasPrefix(path, "pool/"):
|
case strings.HasPrefix(path, "pool/"):
|
||||||
|
|
@ -84,24 +76,79 @@ func (h *DebianHandler) handlePackageDownload(w http.ResponseWriter, r *http.Req
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(
|
result, err := h.proxy.GetOrFetchArtifactFromURL(
|
||||||
r.Context(), "deb", name, version, filename, downloadURL)
|
r.Context(), "deb", name, version, filename, downloadURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch package")
|
h.proxy.Logger.Error("failed to get debian package", "error", err)
|
||||||
|
http.Error(w, "failed to fetch package", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
w.Header().Set(headerContentType, "application/vnd.debian.binary-package")
|
w.Header().Set("Content-Type", "application/vnd.debian.binary-package")
|
||||||
ServeArtifact(w, result)
|
ServeArtifact(w, result)
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleMetadata proxies repository metadata files.
|
// handleMetadata proxies repository metadata files.
|
||||||
// These change frequently so we don't cache them.
|
// These change frequently so we don't cache them.
|
||||||
func (h *DebianHandler) handleMetadata(w http.ResponseWriter, r *http.Request, path string) {
|
func (h *DebianHandler) handleMetadata(w http.ResponseWriter, r *http.Request, path string) {
|
||||||
cacheKey := strings.ReplaceAll(path, "/", "_")
|
upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, path)
|
||||||
h.proxy.ProxyCached(w, r, fmt.Sprintf("%s/%s", h.upstreamURL, path), "debian", cacheKey, "*/*")
|
|
||||||
|
h.proxy.Logger.Debug("debian metadata request", "path", path)
|
||||||
|
|
||||||
|
req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, "failed to create request", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
// Forward relevant headers
|
||||||
|
for _, header := range []string{"Accept", "Accept-Encoding", "If-Modified-Since", "If-None-Match"} {
|
||||||
|
if v := r.Header.Get(header); v != "" {
|
||||||
|
req.Header.Set(header, v)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Error("failed to fetch upstream metadata", "error", err)
|
||||||
|
http.Error(w, "failed to fetch from upstream", http.StatusBadGateway)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
// Copy response headers
|
||||||
|
for _, header := range []string{"Content-Type", "Content-Length", "Last-Modified", "ETag"} {
|
||||||
|
if v := resp.Header.Get(header); v != "" {
|
||||||
|
w.Header().Set(header, v)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
}
|
}
|
||||||
|
|
||||||
// proxyFile proxies any file directly without caching.
|
// proxyFile proxies any file directly without caching.
|
||||||
func (h *DebianHandler) proxyFile(w http.ResponseWriter, r *http.Request, path string) {
|
func (h *DebianHandler) proxyFile(w http.ResponseWriter, r *http.Request, path string) {
|
||||||
h.proxy.ProxyFile(w, r, fmt.Sprintf("%s/%s", h.upstreamURL, path))
|
upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, path)
|
||||||
|
|
||||||
|
req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, "failed to create request", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, "failed to fetch from upstream", http.StatusBadGateway)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
for key, values := range resp.Header {
|
||||||
|
for _, v := range values {
|
||||||
|
w.Header().Add(key, v)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
}
|
}
|
||||||
|
|
||||||
// debPackagePattern matches .deb filenames to extract name, version, and arch.
|
// debPackagePattern matches .deb filenames to extract name, version, and arch.
|
||||||
|
|
@ -120,7 +167,7 @@ func (h *DebianHandler) parsePoolPath(path string) (name, version, arch string)
|
||||||
|
|
||||||
// Parse the filename
|
// Parse the filename
|
||||||
matches := debPackagePattern.FindStringSubmatch(filename)
|
matches := debPackagePattern.FindStringSubmatch(filename)
|
||||||
if len(matches) != debMatchCount {
|
if len(matches) != 4 {
|
||||||
return "", "", ""
|
return "", "", ""
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,28 +1,89 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
"testing"
|
"testing"
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestDebianHandler_parsePoolPath(t *testing.T) {
|
func TestDebianHandler_parsePoolPath(t *testing.T) {
|
||||||
h := &DebianHandler{}
|
h := &DebianHandler{}
|
||||||
|
|
||||||
assertPathParser(t, "parsePoolPath", h.parsePoolPath, []pathParseCase{
|
tests := []struct {
|
||||||
{"pool/main/n/nginx/nginx_1.18.0-6_amd64.deb", "nginx", "1.18.0-6", "amd64"},
|
path string
|
||||||
{"pool/main/libn/libncurses/libncurses6_6.2-1_amd64.deb", "libncurses6", "6.2-1", "amd64"},
|
wantName string
|
||||||
{"pool/contrib/v/virtualbox/virtualbox_6.1.38-1_amd64.deb", "virtualbox", "6.1.38-1", "amd64"},
|
wantVersion string
|
||||||
{"pool/main/g/git/git_2.39.2-1_arm64.deb", "git", "2.39.2-1", "arm64"},
|
wantArch string
|
||||||
|
}{
|
||||||
{
|
{
|
||||||
"pool/universe/n/nmap/nmap_7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1_amd64.deb",
|
path: "pool/main/n/nginx/nginx_1.18.0-6_amd64.deb",
|
||||||
"nmap", "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1", "amd64",
|
wantName: "nginx",
|
||||||
|
wantVersion: "1.18.0-6",
|
||||||
|
wantArch: "amd64",
|
||||||
},
|
},
|
||||||
{"pool/main/o/openssl/openssl_3.0.2-0ubuntu1.15~build1_amd64.deb", "openssl", "3.0.2-0ubuntu1.15~build1", "amd64"},
|
{
|
||||||
{"invalid/path", "", "", ""},
|
path: "pool/main/libn/libncurses/libncurses6_6.2-1_amd64.deb",
|
||||||
{"pool/main/n/nginx/nginx.deb", "", "", ""},
|
wantName: "libncurses6",
|
||||||
})
|
wantVersion: "6.2-1",
|
||||||
|
wantArch: "amd64",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
path: "pool/contrib/v/virtualbox/virtualbox_6.1.38-1_amd64.deb",
|
||||||
|
wantName: "virtualbox",
|
||||||
|
wantVersion: "6.1.38-1",
|
||||||
|
wantArch: "amd64",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
path: "pool/main/g/git/git_2.39.2-1_arm64.deb",
|
||||||
|
wantName: "git",
|
||||||
|
wantVersion: "2.39.2-1",
|
||||||
|
wantArch: "arm64",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
path: "invalid/path",
|
||||||
|
wantName: "",
|
||||||
|
wantVersion: "",
|
||||||
|
wantArch: "",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
path: "pool/main/n/nginx/nginx.deb",
|
||||||
|
wantName: "",
|
||||||
|
wantVersion: "",
|
||||||
|
wantArch: "",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.path, func(t *testing.T) {
|
||||||
|
name, version, arch := h.parsePoolPath(tt.path)
|
||||||
|
if name != tt.wantName {
|
||||||
|
t.Errorf("parsePoolPath() name = %q, want %q", name, tt.wantName)
|
||||||
|
}
|
||||||
|
if version != tt.wantVersion {
|
||||||
|
t.Errorf("parsePoolPath() version = %q, want %q", version, tt.wantVersion)
|
||||||
|
}
|
||||||
|
if arch != tt.wantArch {
|
||||||
|
t.Errorf("parsePoolPath() arch = %q, want %q", arch, tt.wantArch)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestDebianHandler_Routes(t *testing.T) {
|
func TestDebianHandler_Routes(t *testing.T) {
|
||||||
h := NewDebianHandler(nil, "http://localhost:8080", "")
|
h := NewDebianHandler(nil, "http://localhost:8080")
|
||||||
assertRoutesBasics(t, h.Routes(), "/dists/stable/Release", "/pool/../../../etc/passwd")
|
|
||||||
|
// Test that handler doesn't panic on initialization
|
||||||
|
handler := h.Routes()
|
||||||
|
if handler == nil {
|
||||||
|
t.Fatal("Routes() returned nil")
|
||||||
|
}
|
||||||
|
|
||||||
|
// Test method not allowed
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/dists/stable/Release", nil)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
handler.ServeHTTP(w, req)
|
||||||
|
|
||||||
|
if w.Code != http.StatusMethodNotAllowed {
|
||||||
|
t.Errorf("POST request: got status %d, want %d", w.Code, http.StatusMethodNotAllowed)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,43 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"net/http"
|
|
||||||
"strings"
|
|
||||||
)
|
|
||||||
|
|
||||||
type filenameDownload struct {
|
|
||||||
ecosystem string
|
|
||||||
upstreamURL string
|
|
||||||
suffix string
|
|
||||||
parseErr string
|
|
||||||
fetchErr string
|
|
||||||
parse func(string) (name, version string)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (p *Proxy) handleFilenameDownload(w http.ResponseWriter, r *http.Request, d filenameDownload) {
|
|
||||||
filename := r.PathValue("filename")
|
|
||||||
if filename == "" || !strings.HasSuffix(filename, d.suffix) {
|
|
||||||
http.Error(w, "invalid filename", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
name, version := d.parse(filename)
|
|
||||||
if name == "" || version == "" {
|
|
||||||
http.Error(w, d.parseErr, http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
p.Logger.Info(d.ecosystem+" download request",
|
|
||||||
"name", name, "version", version, "filename", filename)
|
|
||||||
|
|
||||||
downloadURL := d.upstreamURL + r.URL.Path
|
|
||||||
result, err := p.GetOrFetchArtifactFromURL(
|
|
||||||
r.Context(), d.ecosystem, name, version, filename, downloadURL,
|
|
||||||
)
|
|
||||||
if err != nil {
|
|
||||||
p.serveArtifactError(w, err, d.fetchErr)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
ServeArtifact(w, result)
|
|
||||||
}
|
|
||||||
|
|
@ -1,13 +1,10 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"bufio"
|
|
||||||
"encoding/json"
|
|
||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
|
|
@ -30,13 +27,6 @@ func NewGemHandler(proxy *Proxy, proxyURL string) *GemHandler {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewGemHandlerWithUpstream creates a RubyGems handler with a custom upstream.
|
|
||||||
func NewGemHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *GemHandler {
|
|
||||||
h := NewGemHandler(proxy, proxyURL)
|
|
||||||
h.upstreamURL = configuredUpstreamURL(upstreamURL, gemUpstream)
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for RubyGems requests.
|
// Routes returns the HTTP handler for RubyGems requests.
|
||||||
func (h *GemHandler) Routes() http.Handler {
|
func (h *GemHandler) Routes() http.Handler {
|
||||||
mux := http.NewServeMux()
|
mux := http.NewServeMux()
|
||||||
|
|
@ -45,13 +35,13 @@ func (h *GemHandler) Routes() http.Handler {
|
||||||
mux.HandleFunc("GET /gems/{filename}", h.handleDownload)
|
mux.HandleFunc("GET /gems/{filename}", h.handleDownload)
|
||||||
|
|
||||||
// Specs indexes (compressed Ruby Marshal format)
|
// Specs indexes (compressed Ruby Marshal format)
|
||||||
mux.HandleFunc("GET /specs.4.8.gz", h.proxyCached)
|
mux.HandleFunc("GET /specs.4.8.gz", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET /latest_specs.4.8.gz", h.proxyCached)
|
mux.HandleFunc("GET /latest_specs.4.8.gz", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET /prerelease_specs.4.8.gz", h.proxyCached)
|
mux.HandleFunc("GET /prerelease_specs.4.8.gz", h.proxyUpstream)
|
||||||
|
|
||||||
// Compact index (bundler 2.x+)
|
// Compact index (bundler 2.x+)
|
||||||
mux.HandleFunc("GET /versions", h.proxyCached)
|
mux.HandleFunc("GET /versions", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET /info/{name}", h.handleCompactIndex)
|
mux.HandleFunc("GET /info/{name}", h.proxyUpstream)
|
||||||
|
|
||||||
// Quick index
|
// Quick index
|
||||||
mux.HandleFunc("GET /quick/Marshal.4.8/{filename}", h.proxyUpstream)
|
mux.HandleFunc("GET /quick/Marshal.4.8/{filename}", h.proxyUpstream)
|
||||||
|
|
@ -65,14 +55,30 @@ func (h *GemHandler) Routes() http.Handler {
|
||||||
|
|
||||||
// handleDownload serves a gem file, fetching and caching from upstream if needed.
|
// handleDownload serves a gem file, fetching and caching from upstream if needed.
|
||||||
func (h *GemHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
func (h *GemHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
||||||
h.proxy.handleFilenameDownload(w, r, filenameDownload{
|
filename := r.PathValue("filename")
|
||||||
ecosystem: "gem",
|
if filename == "" || !strings.HasSuffix(filename, ".gem") {
|
||||||
upstreamURL: h.upstreamURL,
|
http.Error(w, "invalid filename", http.StatusBadRequest)
|
||||||
suffix: ".gem",
|
return
|
||||||
parseErr: "could not parse gem filename",
|
}
|
||||||
fetchErr: "failed to fetch gem",
|
|
||||||
parse: h.parseGemFilename,
|
// Extract name and version from filename (e.g., "rails-7.1.0.gem")
|
||||||
})
|
name, version := h.parseGemFilename(filename)
|
||||||
|
if name == "" || version == "" {
|
||||||
|
http.Error(w, "could not parse gem filename", http.StatusBadRequest)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
h.proxy.Logger.Info("gem download request",
|
||||||
|
"name", name, "version", version, "filename", filename)
|
||||||
|
|
||||||
|
result, err := h.proxy.GetOrFetchArtifact(r.Context(), "gem", name, version, filename)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
|
http.Error(w, "failed to fetch gem", http.StatusBadGateway)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
ServeArtifact(w, result)
|
||||||
}
|
}
|
||||||
|
|
||||||
// parseGemFilename extracts name and version from a gem filename.
|
// parseGemFilename extracts name and version from a gem filename.
|
||||||
|
|
@ -92,198 +98,6 @@ func (h *GemHandler) parseGemFilename(filename string) (name, version string) {
|
||||||
return "", ""
|
return "", ""
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleCompactIndex serves the compact index for a gem, filtering versions
|
|
||||||
// based on cooldown when enabled.
|
|
||||||
func (h *GemHandler) handleCompactIndex(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
|
|
||||||
h.proxyCached(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
name := r.PathValue("name")
|
|
||||||
if name == "" {
|
|
||||||
http.Error(w, "invalid gem name", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
h.proxy.Logger.Info("gem compact index request with cooldown", "name", name)
|
|
||||||
|
|
||||||
indexResp, filteredVersions, err := h.fetchIndexAndVersions(r, name)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Error("upstream compact index request failed", "error", err)
|
|
||||||
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
defer func() { _ = indexResp.Body.Close() }()
|
|
||||||
|
|
||||||
if indexResp.StatusCode != http.StatusOK {
|
|
||||||
copyResponseHeaders(w, indexResp.Header)
|
|
||||||
w.WriteHeader(indexResp.StatusCode)
|
|
||||||
_, _ = io.Copy(w, indexResp.Body)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if filteredVersions == nil {
|
|
||||||
h.proxy.Logger.Warn("failed to fetch version timestamps, proxying unfiltered", "name", name)
|
|
||||||
copyResponseHeaders(w, indexResp.Header)
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
_, _ = io.Copy(w, indexResp.Body)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
h.writeFilteredIndex(w, indexResp, name, filteredVersions)
|
|
||||||
}
|
|
||||||
|
|
||||||
// fetchIndexAndVersions fetches the compact index and versions API concurrently.
|
|
||||||
// Returns the index response, a set of versions to filter (nil if versions API failed),
|
|
||||||
// and an error if the index fetch itself failed.
|
|
||||||
func (h *GemHandler) fetchIndexAndVersions(r *http.Request, name string) (*http.Response, map[string]bool, error) {
|
|
||||||
type versionsResult struct {
|
|
||||||
filtered map[string]bool
|
|
||||||
err error
|
|
||||||
}
|
|
||||||
|
|
||||||
versionsCh := make(chan versionsResult, 1)
|
|
||||||
go func() {
|
|
||||||
filtered, err := h.fetchFilteredVersions(r, name)
|
|
||||||
versionsCh <- versionsResult{filtered: filtered, err: err}
|
|
||||||
}()
|
|
||||||
|
|
||||||
indexResp, err := h.fetchCompactIndex(r, name)
|
|
||||||
|
|
||||||
versionsRes := <-versionsCh
|
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
return nil, nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
if versionsRes.err != nil {
|
|
||||||
return indexResp, nil, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
return indexResp, versionsRes.filtered, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// fetchCompactIndex fetches the compact index from upstream.
|
|
||||||
func (h *GemHandler) fetchCompactIndex(r *http.Request, name string) (*http.Response, error) {
|
|
||||||
indexURL := h.upstreamURL + "/info/" + name
|
|
||||||
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, indexURL, nil)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
for _, hdr := range []string{"Accept", headerAcceptEncoding, "If-None-Match", "If-Modified-Since"} {
|
|
||||||
if v := r.Header.Get(hdr); v != "" {
|
|
||||||
req.Header.Set(hdr, v)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return h.proxy.HTTPClient.Do(req)
|
|
||||||
}
|
|
||||||
|
|
||||||
// writeFilteredIndex writes the compact index response with cooldown-filtered versions removed.
|
|
||||||
func (h *GemHandler) writeFilteredIndex(w http.ResponseWriter, resp *http.Response, name string, filtered map[string]bool) {
|
|
||||||
for k, vv := range resp.Header {
|
|
||||||
if strings.EqualFold(k, headerContentLength) {
|
|
||||||
continue // length will change after filtering
|
|
||||||
}
|
|
||||||
for _, v := range vv {
|
|
||||||
w.Header().Add(k, v)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
|
|
||||||
scanner := bufio.NewScanner(resp.Body)
|
|
||||||
for scanner.Scan() {
|
|
||||||
line := scanner.Text()
|
|
||||||
|
|
||||||
if line == "---" {
|
|
||||||
_, _ = fmt.Fprintln(w, line)
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
version := line
|
|
||||||
if spaceIdx := strings.IndexByte(line, ' '); spaceIdx > 0 {
|
|
||||||
version = line[:spaceIdx]
|
|
||||||
}
|
|
||||||
|
|
||||||
if filtered[version] {
|
|
||||||
h.proxy.Logger.Info("cooldown: filtering gem version",
|
|
||||||
"gem", name, "version", version)
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
_, _ = fmt.Fprintln(w, line)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// copyResponseHeaders copies HTTP headers from a response to a writer.
|
|
||||||
func copyResponseHeaders(w http.ResponseWriter, headers http.Header) {
|
|
||||||
for k, vv := range headers {
|
|
||||||
for _, v := range vv {
|
|
||||||
w.Header().Add(k, v)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// gemVersion represents a version entry from the RubyGems versions API.
|
|
||||||
type gemVersion struct {
|
|
||||||
Number string `json:"number"`
|
|
||||||
Platform string `json:"platform"`
|
|
||||||
CreatedAt string `json:"created_at"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// fetchFilteredVersions fetches the versions API and returns a set of version
|
|
||||||
// strings that should be filtered out by cooldown.
|
|
||||||
func (h *GemHandler) fetchFilteredVersions(r *http.Request, name string) (map[string]bool, error) {
|
|
||||||
versionsURL := fmt.Sprintf("%s/api/v1/versions/%s.json", h.upstreamURL, name)
|
|
||||||
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, versionsURL, nil)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
|
||||||
return nil, fmt.Errorf("versions API returned %d", resp.StatusCode)
|
|
||||||
}
|
|
||||||
|
|
||||||
var versions []gemVersion
|
|
||||||
if err := json.NewDecoder(resp.Body).Decode(&versions); err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
packagePURL := canonicalPackagePURL("gem", name)
|
|
||||||
filtered := make(map[string]bool)
|
|
||||||
|
|
||||||
for _, v := range versions {
|
|
||||||
createdAt, err := time.Parse(time.RFC3339, v.CreatedAt)
|
|
||||||
if err != nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
if !h.proxy.Cooldown.IsAllowed("gem", packagePURL, createdAt) {
|
|
||||||
// Build version string matching compact index format
|
|
||||||
versionStr := v.Number
|
|
||||||
if v.Platform != "" && v.Platform != "ruby" {
|
|
||||||
versionStr = v.Number + "-" + v.Platform
|
|
||||||
}
|
|
||||||
filtered[versionStr] = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return filtered, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// proxyCached forwards a metadata request with caching.
|
|
||||||
func (h *GemHandler) proxyCached(w http.ResponseWriter, r *http.Request) {
|
|
||||||
upstreamURL := h.upstreamURL + r.URL.Path
|
|
||||||
cacheKey := strings.TrimPrefix(r.URL.Path, "/")
|
|
||||||
h.proxy.ProxyCached(w, r, upstreamURL, "gem", cacheKey, "*/*")
|
|
||||||
}
|
|
||||||
|
|
||||||
// proxyUpstream forwards a request to rubygems.org without caching.
|
// proxyUpstream forwards a request to rubygems.org without caching.
|
||||||
func (h *GemHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
func (h *GemHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
||||||
upstreamURL := h.upstreamURL + r.URL.Path
|
upstreamURL := h.upstreamURL + r.URL.Path
|
||||||
|
|
@ -300,13 +114,13 @@ func (h *GemHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
||||||
}
|
}
|
||||||
|
|
||||||
// Copy relevant headers
|
// Copy relevant headers
|
||||||
for _, h := range []string{"Accept", headerAcceptEncoding, "If-None-Match", "If-Modified-Since"} {
|
for _, h := range []string{"Accept", "Accept-Encoding", "If-None-Match", "If-Modified-Since"} {
|
||||||
if v := r.Header.Get(h); v != "" {
|
if v := r.Header.Get(h); v != "" {
|
||||||
req.Header.Set(h, v)
|
req.Header.Set(h, v)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
resp, err := http.DefaultClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.Logger.Error("upstream request failed", "error", err)
|
h.proxy.Logger.Error("upstream request failed", "error", err)
|
||||||
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
||||||
|
|
|
||||||
|
|
@ -1,16 +1,8 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/json"
|
|
||||||
"fmt"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/cooldown"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestGemParseFilename(t *testing.T) {
|
func TestGemParseFilename(t *testing.T) {
|
||||||
|
|
@ -36,217 +28,3 @@ func TestGemParseFilename(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGemCompactIndexCooldown(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
oldTime := now.Add(-7 * 24 * time.Hour).Format(time.RFC3339)
|
|
||||||
recentTime := now.Add(-1 * time.Hour).Format(time.RFC3339)
|
|
||||||
|
|
||||||
compactIndex := "---\n1.0.0 dep1:>= 1.0|checksum:abc123\n2.0.0 dep1:>= 1.0|checksum:def456\n"
|
|
||||||
|
|
||||||
versionsJSON, _ := json.Marshal([]gemVersion{
|
|
||||||
{Number: "1.0.0", Platform: "ruby", CreatedAt: oldTime},
|
|
||||||
{Number: "2.0.0", Platform: "ruby", CreatedAt: recentTime},
|
|
||||||
})
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
switch {
|
|
||||||
case strings.HasPrefix(r.URL.Path, "/info/"):
|
|
||||||
w.Header().Set("Content-Type", "text/plain")
|
|
||||||
_, _ = w.Write([]byte(compactIndex))
|
|
||||||
case strings.HasPrefix(r.URL.Path, "/api/v1/versions/"):
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
_, _ = w.Write(versionsJSON)
|
|
||||||
default:
|
|
||||||
w.WriteHeader(http.StatusNotFound)
|
|
||||||
}
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{
|
|
||||||
Default: "3d",
|
|
||||||
}
|
|
||||||
|
|
||||||
h := &GemHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/info/testgem", nil)
|
|
||||||
req.SetPathValue("name", "testgem")
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handleCompactIndex(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
|
|
||||||
body := w.Body.String()
|
|
||||||
if !strings.Contains(body, "1.0.0") {
|
|
||||||
t.Error("expected version 1.0.0 to survive filtering")
|
|
||||||
}
|
|
||||||
if strings.Contains(body, "2.0.0") {
|
|
||||||
t.Error("expected version 2.0.0 to be filtered out")
|
|
||||||
}
|
|
||||||
if !strings.HasPrefix(body, "---\n") {
|
|
||||||
t.Error("expected compact index header to be preserved")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGemCompactIndexCooldownWithPlatformVersion(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
recentTime := now.Add(-1 * time.Hour).Format(time.RFC3339)
|
|
||||||
|
|
||||||
compactIndex := "---\n1.0.0 dep:>= 1.0|checksum:abc\n1.0.0-java dep:>= 1.0|checksum:def\n"
|
|
||||||
|
|
||||||
versionsJSON, _ := json.Marshal([]gemVersion{
|
|
||||||
{Number: "1.0.0", Platform: "ruby", CreatedAt: recentTime},
|
|
||||||
{Number: "1.0.0", Platform: "java", CreatedAt: recentTime},
|
|
||||||
})
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
switch {
|
|
||||||
case strings.HasPrefix(r.URL.Path, "/info/"):
|
|
||||||
_, _ = w.Write([]byte(compactIndex))
|
|
||||||
case strings.HasPrefix(r.URL.Path, "/api/v1/versions/"):
|
|
||||||
_, _ = w.Write(versionsJSON)
|
|
||||||
}
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{
|
|
||||||
Default: "3d",
|
|
||||||
}
|
|
||||||
|
|
||||||
h := &GemHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/info/testgem", nil)
|
|
||||||
req.SetPathValue("name", "testgem")
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handleCompactIndex(w, req)
|
|
||||||
|
|
||||||
body := w.Body.String()
|
|
||||||
// Both ruby and java platform versions should be filtered
|
|
||||||
lines := strings.Split(strings.TrimSpace(body), "\n")
|
|
||||||
if len(lines) != 1 { // only "---"
|
|
||||||
t.Errorf("expected only header line, got %d lines: %v", len(lines), lines)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGemCompactIndexNoCooldown(t *testing.T) {
|
|
||||||
compactIndex := "---\n1.0.0 dep:>= 1.0|checksum:abc\n"
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
_, _ = w.Write([]byte(compactIndex))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &GemHandler{
|
|
||||||
proxy: testProxy(), // no cooldown
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/info/testgem", nil)
|
|
||||||
req.SetPathValue("name", "testgem")
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handleCompactIndex(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGemCompactIndexVersionsAPIFails(t *testing.T) {
|
|
||||||
compactIndex := "---\n1.0.0 dep:>= 1.0|checksum:abc\n"
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
switch {
|
|
||||||
case strings.HasPrefix(r.URL.Path, "/info/"):
|
|
||||||
_, _ = w.Write([]byte(compactIndex))
|
|
||||||
case strings.HasPrefix(r.URL.Path, "/api/v1/versions/"):
|
|
||||||
w.WriteHeader(http.StatusInternalServerError)
|
|
||||||
}
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{
|
|
||||||
Default: "3d",
|
|
||||||
}
|
|
||||||
|
|
||||||
h := &GemHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/info/testgem", nil)
|
|
||||||
req.SetPathValue("name", "testgem")
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handleCompactIndex(w, req)
|
|
||||||
|
|
||||||
// Should still return OK with unfiltered content
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
|
|
||||||
body := w.Body.String()
|
|
||||||
if !strings.Contains(body, "1.0.0") {
|
|
||||||
t.Error("expected unfiltered content when versions API fails")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGemFetchFilteredVersions(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
oldTime := now.Add(-7 * 24 * time.Hour).Format(time.RFC3339)
|
|
||||||
recentTime := now.Add(-1 * time.Hour).Format(time.RFC3339)
|
|
||||||
|
|
||||||
versionsJSON, _ := json.Marshal([]gemVersion{
|
|
||||||
{Number: "1.0.0", Platform: "ruby", CreatedAt: oldTime},
|
|
||||||
{Number: "2.0.0", Platform: "ruby", CreatedAt: recentTime},
|
|
||||||
{Number: "2.0.0", Platform: "java", CreatedAt: recentTime},
|
|
||||||
})
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
_, _ = w.Write(versionsJSON)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{
|
|
||||||
Default: "3d",
|
|
||||||
}
|
|
||||||
|
|
||||||
h := &GemHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/info/testgem", nil)
|
|
||||||
filtered, err := h.fetchFilteredVersions(req, "testgem")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if filtered["1.0.0"] {
|
|
||||||
t.Error("version 1.0.0 should not be filtered (old enough)")
|
|
||||||
}
|
|
||||||
if !filtered["2.0.0"] {
|
|
||||||
t.Error("version 2.0.0 (ruby) should be filtered")
|
|
||||||
}
|
|
||||||
if !filtered["2.0.0-java"] {
|
|
||||||
t.Error("version 2.0.0-java should be filtered")
|
|
||||||
}
|
|
||||||
|
|
||||||
_ = fmt.Sprintf // silence unused import
|
|
||||||
}
|
|
||||||
|
|
|
||||||
|
|
@ -1,160 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/sha256"
|
|
||||||
"encoding/hex"
|
|
||||||
"net/http"
|
|
||||||
"regexp"
|
|
||||||
"strings"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
genericEcosystem = "generic"
|
|
||||||
// genericAcceptAny is always sent for metadata so every client shares the
|
|
||||||
// same cached representation, regardless of its Accept header.
|
|
||||||
genericAcceptAny = "*/*"
|
|
||||||
// githubReleaseAssetMatchCount is the full match plus owner, repository,
|
|
||||||
// tag and asset filename.
|
|
||||||
githubReleaseAssetMatchCount = 5
|
|
||||||
)
|
|
||||||
|
|
||||||
// githubReleaseAssetPattern matches the path of a GitHub release asset
|
|
||||||
// download, {owner}/{repo}/releases/download/{tag}/{asset}. A tag pins the
|
|
||||||
// asset to one release, so these downloads are cached in the artifact cache
|
|
||||||
// and served without revalidation once fetched.
|
|
||||||
var githubReleaseAssetPattern = regexp.MustCompile(`^([^/]+)/([^/]+)/releases/download/([^/]+)/([^/]+)$`)
|
|
||||||
|
|
||||||
// GenericHandler proxies plain HTTP downloads from configured upstream base
|
|
||||||
// URLs. Each configured upstream is mounted at /generic/{name}/ and the
|
|
||||||
// remaining request path (and query string) is appended to the upstream URL.
|
|
||||||
//
|
|
||||||
// Only configured upstreams are reachable, so the proxy is not an open HTTP
|
|
||||||
// proxy. The handler is the caching layer behind tools that download from
|
|
||||||
// fixed URL shapes, such as mise's aqua backend fetching GitHub release
|
|
||||||
// assets, and is pointed at by URL-rewriting settings on the client.
|
|
||||||
//
|
|
||||||
// Release-asset paths ({owner}/{repo}/releases/download/{tag}/{asset}) are
|
|
||||||
// version-pinned and cached in the shared artifact cache, so they keep being
|
|
||||||
// served when the upstream is unreachable. Every other path is served through
|
|
||||||
// the metadata cache: fresh within the metadata TTL, revalidated with the
|
|
||||||
// upstream's validators after that, and served stale when the upstream fails
|
|
||||||
// or refuses the request. That covers API responses such as
|
|
||||||
// api.github.com/repos/{owner}/{repo}/releases/tags/{tag}.
|
|
||||||
type GenericHandler struct {
|
|
||||||
proxy *Proxy
|
|
||||||
repositories map[string]string
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewGenericHandler creates a generic HTTP download proxy handler.
|
|
||||||
func NewGenericHandler(proxy *Proxy, repositories map[string]string) *GenericHandler {
|
|
||||||
h := &GenericHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
repositories: make(map[string]string, len(repositories)),
|
|
||||||
}
|
|
||||||
for name, upstreamURL := range repositories {
|
|
||||||
h.repositories[name] = strings.TrimSuffix(upstreamURL, "/")
|
|
||||||
}
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for generic download requests.
|
|
||||||
// Mount this at /generic on your router.
|
|
||||||
func (h *GenericHandler) Routes() http.Handler {
|
|
||||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if r.Method != http.MethodGet && r.Method != http.MethodHead {
|
|
||||||
http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
path := strings.TrimPrefix(r.URL.Path, "/")
|
|
||||||
|
|
||||||
if containsPathTraversal(path) {
|
|
||||||
http.Error(w, "invalid path", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
repository, rest, ok := strings.Cut(path, "/")
|
|
||||||
upstreamURL, found := h.repositories[repository]
|
|
||||||
if !ok || rest == "" || !found {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if asset, ok := parseGitHubReleaseAsset(rest); ok {
|
|
||||||
h.handleReleaseAsset(w, r, repository, upstreamURL, rest, asset)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
h.handleMetadata(w, r, repository, upstreamURL, rest)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
// githubReleaseAsset is the identity of a version-pinned release download.
|
|
||||||
type githubReleaseAsset struct {
|
|
||||||
owner string
|
|
||||||
repo string
|
|
||||||
tag string
|
|
||||||
filename string
|
|
||||||
}
|
|
||||||
|
|
||||||
// parseGitHubReleaseAsset extracts the release identity from a path shaped
|
|
||||||
// like {owner}/{repo}/releases/download/{tag}/{asset}.
|
|
||||||
func parseGitHubReleaseAsset(path string) (githubReleaseAsset, bool) {
|
|
||||||
matches := githubReleaseAssetPattern.FindStringSubmatch(path)
|
|
||||||
if len(matches) != githubReleaseAssetMatchCount {
|
|
||||||
return githubReleaseAsset{}, false
|
|
||||||
}
|
|
||||||
return githubReleaseAsset{
|
|
||||||
owner: matches[1],
|
|
||||||
repo: matches[2],
|
|
||||||
tag: matches[3],
|
|
||||||
filename: matches[4],
|
|
||||||
}, true
|
|
||||||
}
|
|
||||||
|
|
||||||
// handleReleaseAsset fetches and caches a version-pinned release asset in the
|
|
||||||
// artifact cache. The configured upstream name is part of the cache identity
|
|
||||||
// so two upstreams serving the same path never share bytes.
|
|
||||||
func (h *GenericHandler) handleReleaseAsset(w http.ResponseWriter, r *http.Request, repository, upstreamURL, path string, asset githubReleaseAsset) {
|
|
||||||
name := asset.owner + "/" + asset.repo
|
|
||||||
downloadURL := upstreamURL + "/" + path
|
|
||||||
cacheFilename := repository + "/" + asset.filename
|
|
||||||
|
|
||||||
h.proxy.Logger.Info("generic release asset download",
|
|
||||||
"repository", repository, "name", name, "version", asset.tag, "filename", asset.filename)
|
|
||||||
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(
|
|
||||||
r.Context(), genericEcosystem, name, asset.tag, cacheFilename, downloadURL)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch release asset")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if result.Artifact.MediaType == "" {
|
|
||||||
result.Artifact.MediaType = "application/octet-stream"
|
|
||||||
}
|
|
||||||
serveArtifact(w, r.Method, result)
|
|
||||||
}
|
|
||||||
|
|
||||||
// handleMetadata serves any other path through the metadata cache. The query
|
|
||||||
// string is forwarded and is part of the cache identity. A fixed Accept header
|
|
||||||
// keeps all clients on one cached representation.
|
|
||||||
func (h *GenericHandler) handleMetadata(w http.ResponseWriter, r *http.Request, repository, upstreamURL, path string) {
|
|
||||||
target := upstreamURL + "/" + path
|
|
||||||
if r.URL.RawQuery != "" {
|
|
||||||
target += "?" + r.URL.RawQuery
|
|
||||||
}
|
|
||||||
|
|
||||||
h.proxy.ProxyCached(w, r, target, genericEcosystem,
|
|
||||||
h.metadataCacheKey(repository, upstreamURL, path, r.URL.RawQuery), genericAcceptAny)
|
|
||||||
}
|
|
||||||
|
|
||||||
// metadataCacheKey derives the metadata cache key from the upstream name, its
|
|
||||||
// URL, the request path and query. Hashing the identity keeps distinct
|
|
||||||
// upstreams from sharing entries and drops cached entries when an upstream is
|
|
||||||
// repointed, mirroring APKHandler.metadataCacheKey.
|
|
||||||
func (h *GenericHandler) metadataCacheKey(repository, upstreamURL, path, query string) string {
|
|
||||||
identity := repository + "\x00" + upstreamURL + "\x00" + path + "\x00" + query
|
|
||||||
digest := sha256.Sum256([]byte(identity))
|
|
||||||
return hex.EncodeToString(digest[:])
|
|
||||||
}
|
|
||||||
|
|
@ -1,311 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"strings"
|
|
||||||
"sync/atomic"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient"
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
|
||||||
|
|
||||||
const testReleaseAssetPath = "/jqlang/jq/releases/download/jq-1.7.1/jq-linux-amd64"
|
|
||||||
|
|
||||||
func TestParseGitHubReleaseAsset(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
path string
|
|
||||||
want githubReleaseAsset
|
|
||||||
ok bool
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
"jqlang/jq/releases/download/jq-1.7.1/jq-linux-amd64",
|
|
||||||
githubReleaseAsset{owner: "jqlang", repo: "jq", tag: "jq-1.7.1", filename: "jq-linux-amd64"},
|
|
||||||
true,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"cli/cli/releases/download/v2.63.2/gh_2.63.2_linux_amd64.tar.gz",
|
|
||||||
githubReleaseAsset{owner: "cli", repo: "cli", tag: "v2.63.2", filename: "gh_2.63.2_linux_amd64.tar.gz"},
|
|
||||||
true,
|
|
||||||
},
|
|
||||||
// Mutable: resolves to whatever is latest today.
|
|
||||||
{"jqlang/jq/releases/latest/download/jq-linux-amd64", githubReleaseAsset{}, false},
|
|
||||||
// API lookups and tag listings are not assets.
|
|
||||||
{"repos/jqlang/jq/releases/tags/jq-1.7.1", githubReleaseAsset{}, false},
|
|
||||||
{"jqlang/jq/releases/tag/jq-1.7.1", githubReleaseAsset{}, false},
|
|
||||||
// Source archives are a different shape.
|
|
||||||
{"jqlang/jq/archive/refs/tags/jq-1.7.1.tar.gz", githubReleaseAsset{}, false},
|
|
||||||
// Extra or missing segments.
|
|
||||||
{"jqlang/jq/releases/download/jq-1.7.1", githubReleaseAsset{}, false},
|
|
||||||
{"jqlang/jq/releases/download/jq-1.7.1/dir/asset", githubReleaseAsset{}, false},
|
|
||||||
{"", githubReleaseAsset{}, false},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
got, ok := parseGitHubReleaseAsset(tt.path)
|
|
||||||
if ok != tt.ok || got != tt.want {
|
|
||||||
t.Errorf("parseGitHubReleaseAsset(%q) = (%+v, %v), want (%+v, %v)", tt.path, got, ok, tt.want, tt.ok)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGenericHandler_RejectsUnknownUpstreamAndBadPaths(t *testing.T) {
|
|
||||||
h := NewGenericHandler(testProxy(), map[string]string{"github": "https://github.com"})
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
method string
|
|
||||||
target string
|
|
||||||
want int
|
|
||||||
}{
|
|
||||||
{"unknown upstream", http.MethodGet, "/gitlab/owner/repo/releases/download/v1/asset", http.StatusNotFound},
|
|
||||||
{"missing path", http.MethodGet, "/github", http.StatusNotFound},
|
|
||||||
{"missing path with slash", http.MethodGet, "/github/", http.StatusNotFound},
|
|
||||||
{"traversal", http.MethodGet, "/github/../etc/passwd", http.StatusBadRequest},
|
|
||||||
{"encoded traversal", http.MethodGet, "/github/%2e%2e/etc/passwd", http.StatusBadRequest},
|
|
||||||
{"post", http.MethodPost, "/github/owner/repo/releases/download/v1/asset", http.StatusMethodNotAllowed},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, httptest.NewRequest(tt.method, tt.target, nil))
|
|
||||||
if w.Code != tt.want {
|
|
||||||
t.Errorf("status = %d, want %d", w.Code, tt.want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGenericHandler_ReleaseAssetIsCachedAndServedWhenUpstreamDown(t *testing.T) {
|
|
||||||
asset := []byte("jq binary bytes")
|
|
||||||
var available atomic.Bool
|
|
||||||
available.Store(true)
|
|
||||||
var upstreamRequests atomic.Int32
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if !available.Load() {
|
|
||||||
http.Error(w, "unavailable", http.StatusServiceUnavailable)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if r.URL.Path != testReleaseAssetPath {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
upstreamRequests.Add(1)
|
|
||||||
w.Header().Set("Content-Type", "application/octet-stream")
|
|
||||||
_, _ = w.Write(asset)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
t.Cleanup(func() { _ = fetcher.Close() })
|
|
||||||
|
|
||||||
h := NewGenericHandler(proxy, map[string]string{"github": upstream.URL})
|
|
||||||
|
|
||||||
w := serveGenericRequest(h, "/github"+testReleaseAssetPath)
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Body.String(); got != string(asset) {
|
|
||||||
t.Errorf("body = %q, want %q", got, asset)
|
|
||||||
}
|
|
||||||
if got := upstreamRequests.Load(); got != 1 {
|
|
||||||
t.Fatalf("upstream requests = %d, want 1", got)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Second request must be served from cache, even with the upstream down.
|
|
||||||
available.Store(false)
|
|
||||||
w = serveGenericRequest(h, "/github"+testReleaseAssetPath)
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("cached: status = %d, want 200: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Body.String(); got != string(asset) {
|
|
||||||
t.Errorf("cached: body = %q, want %q", got, asset)
|
|
||||||
}
|
|
||||||
if got := upstreamRequests.Load(); got != 1 {
|
|
||||||
t.Errorf("upstream requests after cache hit = %d, want 1", got)
|
|
||||||
}
|
|
||||||
|
|
||||||
// HEAD is answered from the same cache entry without a body.
|
|
||||||
w = httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodHead, "/github"+testReleaseAssetPath, nil))
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("HEAD: status = %d, want 200", w.Code)
|
|
||||||
}
|
|
||||||
if w.Body.Len() != 0 {
|
|
||||||
t.Errorf("HEAD: body length = %d, want 0", w.Body.Len())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGenericHandler_ReleaseAssetNotFoundIsNotCached(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
t.Cleanup(func() { _ = fetcher.Close() })
|
|
||||||
|
|
||||||
h := NewGenericHandler(proxy, map[string]string{"github": upstream.URL})
|
|
||||||
w := serveGenericRequest(h, "/github"+testReleaseAssetPath)
|
|
||||||
if w.Code != http.StatusNotFound {
|
|
||||||
t.Fatalf("status = %d, want 404: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGenericHandler_MetadataForwardsQueryAndServesStaleOnThrottle(t *testing.T) {
|
|
||||||
const apiPath = "/repos/jqlang/jq/releases/tags/jq-1.7.1"
|
|
||||||
body := `{"tag_name":"jq-1.7.1"}`
|
|
||||||
var throttled atomic.Bool
|
|
||||||
var gotQuery string
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if r.URL.Path != apiPath {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
gotQuery = r.URL.RawQuery
|
|
||||||
if throttled.Load() {
|
|
||||||
w.Header().Set("Retry-After", "60")
|
|
||||||
http.Error(w, `{"message":"API rate limit exceeded"}`, http.StatusTooManyRequests)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
w.Header().Set("Content-Type", "application/vnd.github+json")
|
|
||||||
w.Header().Set("ETag", `"v1"`)
|
|
||||||
_, _ = w.Write([]byte(body))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
// A tiny TTL so the second request is past freshness and has to consult
|
|
||||||
// the upstream, and the served copy is marked stale.
|
|
||||||
proxy.MetadataTTL = time.Millisecond
|
|
||||||
|
|
||||||
h := NewGenericHandler(proxy, map[string]string{"github-api": upstream.URL})
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/github-api"+apiPath+"?per_page=1", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, req)
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Body.String(); got != body {
|
|
||||||
t.Errorf("body = %q, want %q", got, body)
|
|
||||||
}
|
|
||||||
if gotQuery != "per_page=1" {
|
|
||||||
t.Errorf("upstream query = %q, want %q", gotQuery, "per_page=1")
|
|
||||||
}
|
|
||||||
if ct := w.Header().Get("Content-Type"); ct != "application/vnd.github+json" {
|
|
||||||
t.Errorf("Content-Type = %q, want upstream's", ct)
|
|
||||||
}
|
|
||||||
|
|
||||||
// The upstream now throttles us: the cached body must be served stale
|
|
||||||
// rather than the 429 being passed through.
|
|
||||||
throttled.Store(true)
|
|
||||||
time.Sleep(5 * time.Millisecond)
|
|
||||||
w = httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, req)
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("throttled: status = %d, want 200 stale: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Body.String(); got != body {
|
|
||||||
t.Errorf("throttled: body = %q, want cached %q", got, body)
|
|
||||||
}
|
|
||||||
if warning := w.Header().Get("Warning"); !strings.Contains(warning, "110") {
|
|
||||||
t.Errorf("throttled: Warning = %q, want a 110 stale warning", warning)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGenericHandler_DistinctUpstreamsDoNotShareCache(t *testing.T) {
|
|
||||||
first := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
_, _ = w.Write([]byte("from first"))
|
|
||||||
}))
|
|
||||||
defer first.Close()
|
|
||||||
second := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
_, _ = w.Write([]byte("from second"))
|
|
||||||
}))
|
|
||||||
defer second.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(first.Client()), fetch.WithMaxRetries(0))
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
t.Cleanup(func() { _ = fetcher.Close() })
|
|
||||||
|
|
||||||
h := NewGenericHandler(proxy, map[string]string{"one": first.URL, "two": second.URL})
|
|
||||||
|
|
||||||
w := serveGenericRequest(h, "/one"+testReleaseAssetPath)
|
|
||||||
if got := w.Body.String(); got != "from first" {
|
|
||||||
t.Fatalf("one: body = %q, want %q", got, "from first")
|
|
||||||
}
|
|
||||||
w = serveGenericRequest(h, "/two"+testReleaseAssetPath)
|
|
||||||
if got := w.Body.String(); got != "from second" {
|
|
||||||
t.Fatalf("two: body = %q, want %q (must not reuse the first upstream's cache entry)", got, "from second")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGenericHandler_UpstreamAuthIsScopedToTheConfiguredHost(t *testing.T) {
|
|
||||||
asset := []byte("private asset")
|
|
||||||
var storageAuth atomic.Value
|
|
||||||
storageAuth.Store("unset")
|
|
||||||
|
|
||||||
// The object store the release host redirects to must never see the
|
|
||||||
// token configured for the release host.
|
|
||||||
objectStore := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
storageAuth.Store(r.Header.Get("Authorization"))
|
|
||||||
_, _ = w.Write(asset)
|
|
||||||
}))
|
|
||||||
defer objectStore.Close()
|
|
||||||
|
|
||||||
var releaseAuth string
|
|
||||||
releaseHost := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
releaseAuth = r.Header.Get("Authorization")
|
|
||||||
if releaseAuth != "Bearer github-token" {
|
|
||||||
http.Error(w, "unauthorized", http.StatusUnauthorized)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
http.Redirect(w, r, objectStore.URL+"/signed"+r.URL.Path, http.StatusFound)
|
|
||||||
}))
|
|
||||||
defer releaseHost.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
authClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport,
|
|
||||||
upstreamhttp.AuthFunc(func(url string) (string, string) {
|
|
||||||
if strings.HasPrefix(url, releaseHost.URL) {
|
|
||||||
return "Authorization", "Bearer github-token"
|
|
||||||
}
|
|
||||||
return "", ""
|
|
||||||
}))}
|
|
||||||
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(authClient), fetch.WithMaxRetries(0))
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
t.Cleanup(func() { _ = fetcher.Close() })
|
|
||||||
|
|
||||||
h := NewGenericHandler(proxy, map[string]string{"github": releaseHost.URL})
|
|
||||||
w := serveGenericRequest(h, "/github"+testReleaseAssetPath)
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Body.String(); got != string(asset) {
|
|
||||||
t.Errorf("body = %q, want %q", got, asset)
|
|
||||||
}
|
|
||||||
if releaseAuth != "Bearer github-token" {
|
|
||||||
t.Errorf("release host Authorization = %q, want the configured token", releaseAuth)
|
|
||||||
}
|
|
||||||
if got := storageAuth.Load(); got != "" {
|
|
||||||
t.Errorf("object store Authorization = %q, want none after the cross-host redirect", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func serveGenericRequest(h *GenericHandler, target string) *httptest.ResponseRecorder {
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, target, nil))
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
|
|
@ -1,17 +1,14 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"errors"
|
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
goUpstream = "https://proxy.golang.org"
|
goUpstream = "https://proxy.golang.org"
|
||||||
asciiCaseOffset = 32 // difference between lowercase and uppercase ASCII letters
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// GoHandler handles Go module proxy protocol requests.
|
// GoHandler handles Go module proxy protocol requests.
|
||||||
|
|
@ -30,13 +27,6 @@ func NewGoHandler(proxy *Proxy, proxyURL string) *GoHandler {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewGoHandlerWithUpstream creates a Go module handler with a custom upstream.
|
|
||||||
func NewGoHandlerWithUpstream(proxy *Proxy, proxyURL, upstreamURL string) *GoHandler {
|
|
||||||
h := NewGoHandler(proxy, proxyURL)
|
|
||||||
h.upstreamURL = configuredUpstreamURL(upstreamURL, goUpstream)
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for Go proxy requests.
|
// Routes returns the HTTP handler for Go proxy requests.
|
||||||
func (h *GoHandler) Routes() http.Handler {
|
func (h *GoHandler) Routes() http.Handler {
|
||||||
// Go module paths can contain slashes, so just use the handler directly
|
// Go module paths can contain slashes, so just use the handler directly
|
||||||
|
|
@ -64,19 +54,18 @@ func (h *GoHandler) handleRequest(w http.ResponseWriter, r *http.Request) {
|
||||||
module := path[:idx]
|
module := path[:idx]
|
||||||
rest := path[idx+4:] // after "/@v/"
|
rest := path[idx+4:] // after "/@v/"
|
||||||
|
|
||||||
decodedMod := decodeGoModule(module)
|
|
||||||
switch {
|
switch {
|
||||||
case rest == "list":
|
case rest == "list":
|
||||||
// GET /{module}/@v/list - list versions
|
// GET /{module}/@v/list - list versions
|
||||||
h.proxyCached(w, r, decodedMod+"/@v/list")
|
h.proxyUpstream(w, r)
|
||||||
|
|
||||||
case strings.HasSuffix(rest, ".info"):
|
case strings.HasSuffix(rest, ".info"):
|
||||||
// GET /{module}/@v/{version}.info - version metadata
|
// GET /{module}/@v/{version}.info - version metadata
|
||||||
h.proxyCached(w, r, decodedMod+"/@v/"+rest)
|
h.proxyUpstream(w, r)
|
||||||
|
|
||||||
case strings.HasSuffix(rest, ".mod"):
|
case strings.HasSuffix(rest, ".mod"):
|
||||||
// GET /{module}/@v/{version}.mod - go.mod file
|
// GET /{module}/@v/{version}.mod - go.mod file
|
||||||
h.proxyCached(w, r, decodedMod+"/@v/"+rest)
|
h.proxyUpstream(w, r)
|
||||||
|
|
||||||
case strings.HasSuffix(rest, ".zip"):
|
case strings.HasSuffix(rest, ".zip"):
|
||||||
// GET /{module}/@v/{version}.zip - source archive (cache this)
|
// GET /{module}/@v/{version}.zip - source archive (cache this)
|
||||||
|
|
@ -91,8 +80,7 @@ func (h *GoHandler) handleRequest(w http.ResponseWriter, r *http.Request) {
|
||||||
|
|
||||||
// Check for @latest
|
// Check for @latest
|
||||||
if strings.HasSuffix(path, "/@latest") {
|
if strings.HasSuffix(path, "/@latest") {
|
||||||
module := strings.TrimSuffix(path, "/@latest")
|
h.proxyUpstream(w, r)
|
||||||
h.proxyCached(w, r, decodeGoModule(module)+"/@latest")
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -108,19 +96,8 @@ func (h *GoHandler) handleDownload(w http.ResponseWriter, r *http.Request, modul
|
||||||
h.proxy.Logger.Info("go module download request",
|
h.proxy.Logger.Info("go module download request",
|
||||||
"module", decodedModule, "version", version)
|
"module", decodedModule, "version", version)
|
||||||
|
|
||||||
downloadURL := h.upstreamURL + r.URL.Path
|
result, err := h.proxy.GetOrFetchArtifact(r.Context(), "golang", decodedModule, version, filename)
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(
|
|
||||||
r.Context(), "golang", decodedModule, version, filename, downloadURL,
|
|
||||||
)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if errors.Is(err, fetch.ErrNotFound) {
|
|
||||||
http.Error(w, "not found", http.StatusNotFound)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if errors.Is(err, ErrArtifactBlocked) {
|
|
||||||
http.Error(w, err.Error(), http.StatusForbidden)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
http.Error(w, "failed to fetch module", http.StatusBadGateway)
|
http.Error(w, "failed to fetch module", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
|
|
@ -131,12 +108,33 @@ func (h *GoHandler) handleDownload(w http.ResponseWriter, r *http.Request, modul
|
||||||
|
|
||||||
// proxyUpstream forwards a request to proxy.golang.org without caching.
|
// proxyUpstream forwards a request to proxy.golang.org without caching.
|
||||||
func (h *GoHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
func (h *GoHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
||||||
h.proxy.ProxyUpstream(w, r, h.upstreamURL+r.URL.Path, nil)
|
upstreamURL := h.upstreamURL + r.URL.Path
|
||||||
}
|
|
||||||
|
|
||||||
// proxyCached forwards a request with metadata caching.
|
h.proxy.Logger.Debug("proxying to upstream", "url", upstreamURL)
|
||||||
func (h *GoHandler) proxyCached(w http.ResponseWriter, r *http.Request, cacheKey string) {
|
|
||||||
h.proxy.ProxyCached(w, r, h.upstreamURL+r.URL.Path, "golang", cacheKey, "*/*")
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, "failed to create request", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Error("upstream request failed", "error", err)
|
||||||
|
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
// Copy response headers
|
||||||
|
for k, vv := range resp.Header {
|
||||||
|
for _, v := range vv {
|
||||||
|
w.Header().Add(k, v)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
}
|
}
|
||||||
|
|
||||||
// decodeGoModule decodes an encoded module path.
|
// decodeGoModule decodes an encoded module path.
|
||||||
|
|
@ -145,7 +143,7 @@ func decodeGoModule(encoded string) string {
|
||||||
var b strings.Builder
|
var b strings.Builder
|
||||||
for i := 0; i < len(encoded); i++ {
|
for i := 0; i < len(encoded); i++ {
|
||||||
if encoded[i] == '!' && i+1 < len(encoded) {
|
if encoded[i] == '!' && i+1 < len(encoded) {
|
||||||
b.WriteByte(encoded[i+1] - asciiCaseOffset) // lowercase to uppercase
|
b.WriteByte(encoded[i+1] - 32) // lowercase to uppercase
|
||||||
i++
|
i++
|
||||||
} else {
|
} else {
|
||||||
b.WriteByte(encoded[i])
|
b.WriteByte(encoded[i])
|
||||||
|
|
|
||||||
|
|
@ -1,49 +1,9 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"errors"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestGoModuleDownloadUpstreamErrors(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
fetchErr error
|
|
||||||
wantStatus int
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
name: "module not found",
|
|
||||||
fetchErr: fetch.ErrNotFound,
|
|
||||||
wantStatus: http.StatusNotFound,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "upstream failure",
|
|
||||||
fetchErr: errors.New("connection refused"),
|
|
||||||
wantStatus: http.StatusBadGateway,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
fetcher.fetchErr = tt.fetchErr
|
|
||||||
handler := NewGoHandler(proxy, "http://localhost:8080")
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/example.com/mod/@v/v1.0.0.zip", nil)
|
|
||||||
resp := httptest.NewRecorder()
|
|
||||||
handler.Routes().ServeHTTP(resp, req)
|
|
||||||
|
|
||||||
if resp.Code != tt.wantStatus {
|
|
||||||
t.Fatalf("status = %d, want %d", resp.Code, tt.wantStatus)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestDecodeGoModule(t *testing.T) {
|
func TestDecodeGoModule(t *testing.T) {
|
||||||
tests := []struct {
|
tests := []struct {
|
||||||
encoded string
|
encoded string
|
||||||
|
|
|
||||||
|
|
@ -1,178 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"errors"
|
|
||||||
"io"
|
|
||||||
"net/http"
|
|
||||||
"regexp"
|
|
||||||
"strconv"
|
|
||||||
"strings"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/proxy/internal/metrics"
|
|
||||||
"github.com/git-pkgs/proxy/internal/storage"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
gradleBuildCacheContentType = "application/vnd.gradle.build-cache-artifact.v2"
|
|
||||||
gradleBuildCacheStorageRoot = "_gradle/http-build-cache"
|
|
||||||
defaultGradleMaxUploadSize = 100 << 20
|
|
||||||
)
|
|
||||||
|
|
||||||
var gradleBuildCacheKeyPattern = regexp.MustCompile(`^[A-Za-z0-9][A-Za-z0-9._-]*$`)
|
|
||||||
|
|
||||||
// GradleBuildCacheHandler handles Gradle HttpBuildCache GET/HEAD/PUT requests.
|
|
||||||
//
|
|
||||||
// This handler accepts /{key} when mounted under a base URL.
|
|
||||||
type GradleBuildCacheHandler struct {
|
|
||||||
proxy *Proxy
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewGradleBuildCacheHandler creates a Gradle HttpBuildCache handler.
|
|
||||||
func NewGradleBuildCacheHandler(proxy *Proxy) *GradleBuildCacheHandler {
|
|
||||||
return &GradleBuildCacheHandler{proxy: proxy}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for Gradle HttpBuildCache requests.
|
|
||||||
func (h *GradleBuildCacheHandler) Routes() http.Handler {
|
|
||||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
switch r.Method {
|
|
||||||
case http.MethodGet, http.MethodHead, http.MethodPut:
|
|
||||||
default:
|
|
||||||
http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
key, statusCode := h.parseCacheKey(r.URL.Path)
|
|
||||||
if statusCode != http.StatusOK {
|
|
||||||
if statusCode == http.StatusNotFound {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
http.Error(w, "invalid cache key", statusCode)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if r.Method == http.MethodPut {
|
|
||||||
if h.proxy.GradleReadOnly {
|
|
||||||
http.Error(w, "gradle build cache is read-only", http.StatusMethodNotAllowed)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.handlePut(w, r, key)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
h.handleGetOrHead(w, r, key)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *GradleBuildCacheHandler) parseCacheKey(urlPath string) (string, int) {
|
|
||||||
keyPath := strings.TrimPrefix(urlPath, "/")
|
|
||||||
if keyPath == "" {
|
|
||||||
return "", http.StatusNotFound
|
|
||||||
}
|
|
||||||
|
|
||||||
if containsPathTraversal(keyPath) {
|
|
||||||
return "", http.StatusBadRequest
|
|
||||||
}
|
|
||||||
|
|
||||||
if strings.Contains(keyPath, "/") {
|
|
||||||
return "", http.StatusNotFound
|
|
||||||
}
|
|
||||||
|
|
||||||
if !gradleBuildCacheKeyPattern.MatchString(keyPath) {
|
|
||||||
return "", http.StatusBadRequest
|
|
||||||
}
|
|
||||||
|
|
||||||
return keyPath, http.StatusOK
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *GradleBuildCacheHandler) cacheStoragePath(key string) string {
|
|
||||||
return gradleBuildCacheStorageRoot + "/" + key
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *GradleBuildCacheHandler) handleGetOrHead(w http.ResponseWriter, r *http.Request, key string) {
|
|
||||||
storagePath := h.cacheStoragePath(key)
|
|
||||||
w.Header().Set(headerContentType, gradleBuildCacheContentType)
|
|
||||||
|
|
||||||
if r.Method == http.MethodHead {
|
|
||||||
existsStart := time.Now()
|
|
||||||
exists, err := h.proxy.Storage.Exists(r.Context(), storagePath)
|
|
||||||
metrics.RecordStorageOperation("read", time.Since(existsStart))
|
|
||||||
if err != nil {
|
|
||||||
metrics.RecordStorageError("read")
|
|
||||||
h.proxy.Logger.Error("failed to check gradle build cache entry", "key", key, "error", err)
|
|
||||||
http.Error(w, "failed to read cache entry", http.StatusInternalServerError)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if !exists {
|
|
||||||
metrics.RecordCacheMiss("gradle")
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
metrics.RecordCacheHit("gradle")
|
|
||||||
|
|
||||||
sizeStart := time.Now()
|
|
||||||
size, err := h.proxy.Storage.Size(r.Context(), storagePath)
|
|
||||||
metrics.RecordStorageOperation("read", time.Since(sizeStart))
|
|
||||||
if err != nil {
|
|
||||||
metrics.RecordStorageError("read")
|
|
||||||
} else if size >= 0 {
|
|
||||||
w.Header().Set(headerContentLength, strconv.FormatInt(size, 10))
|
|
||||||
}
|
|
||||||
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
readStart := time.Now()
|
|
||||||
reader, err := h.proxy.Storage.Open(r.Context(), storagePath)
|
|
||||||
metrics.RecordStorageOperation("read", time.Since(readStart))
|
|
||||||
if err != nil {
|
|
||||||
if errors.Is(err, storage.ErrNotFound) {
|
|
||||||
metrics.RecordCacheMiss("gradle")
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
metrics.RecordStorageError("read")
|
|
||||||
h.proxy.Logger.Error("failed to open gradle build cache entry", "key", key, "error", err)
|
|
||||||
http.Error(w, "failed to read cache entry", http.StatusInternalServerError)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
defer func() { _ = reader.Close() }()
|
|
||||||
metrics.RecordCacheHit("gradle")
|
|
||||||
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
_, _ = io.Copy(w, reader)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *GradleBuildCacheHandler) handlePut(w http.ResponseWriter, r *http.Request, key string) {
|
|
||||||
storagePath := h.cacheStoragePath(key)
|
|
||||||
maxUploadSize := h.proxy.GradleMaxUploadSize
|
|
||||||
if maxUploadSize <= 0 {
|
|
||||||
maxUploadSize = defaultGradleMaxUploadSize
|
|
||||||
}
|
|
||||||
|
|
||||||
r.Body = http.MaxBytesReader(w, r.Body, maxUploadSize)
|
|
||||||
|
|
||||||
storeStart := time.Now()
|
|
||||||
_, hash, err := h.proxy.Storage.Store(r.Context(), storagePath, r.Body)
|
|
||||||
metrics.RecordStorageOperation("write", time.Since(storeStart))
|
|
||||||
if err != nil {
|
|
||||||
var maxBytesErr *http.MaxBytesError
|
|
||||||
if errors.As(err, &maxBytesErr) {
|
|
||||||
http.Error(w, "cache entry too large", http.StatusRequestEntityTooLarge)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
metrics.RecordStorageError("write")
|
|
||||||
h.proxy.Logger.Error("failed to store gradle build cache entry", "key", key, "error", err)
|
|
||||||
http.Error(w, "failed to write cache entry", http.StatusInternalServerError)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
w.Header().Set(headerContentLength, "0")
|
|
||||||
w.Header().Set(headerETag, `"`+hash+`"`)
|
|
||||||
|
|
||||||
w.WriteHeader(http.StatusCreated)
|
|
||||||
}
|
|
||||||
|
|
@ -1,285 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"io"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/proxy/internal/metrics"
|
|
||||||
"github.com/prometheus/client_golang/prometheus/testutil"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestGradleBuildCacheHandler_PutGetHead(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
h := NewGradleBuildCacheHandler(proxy)
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
key := "a1b2c3d4e5f6"
|
|
||||||
payload := "cache entry content"
|
|
||||||
|
|
||||||
putReq, err := http.NewRequest(http.MethodPut, srv.URL+"/"+key, strings.NewReader(payload))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("failed to create PUT request: %v", err)
|
|
||||||
}
|
|
||||||
putResp, err := http.DefaultClient.Do(putReq)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("PUT request failed: %v", err)
|
|
||||||
}
|
|
||||||
_ = putResp.Body.Close()
|
|
||||||
|
|
||||||
if putResp.StatusCode != http.StatusCreated {
|
|
||||||
t.Fatalf("PUT status = %d, want %d", putResp.StatusCode, http.StatusCreated)
|
|
||||||
}
|
|
||||||
|
|
||||||
getResp, err := http.Get(srv.URL + "/" + key)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GET request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = getResp.Body.Close() }()
|
|
||||||
|
|
||||||
if getResp.StatusCode != http.StatusOK {
|
|
||||||
t.Fatalf("GET status = %d, want %d", getResp.StatusCode, http.StatusOK)
|
|
||||||
}
|
|
||||||
if getResp.Header.Get("Content-Type") != gradleBuildCacheContentType {
|
|
||||||
t.Fatalf("GET Content-Type = %q, want %q", getResp.Header.Get("Content-Type"), gradleBuildCacheContentType)
|
|
||||||
}
|
|
||||||
|
|
||||||
body, _ := io.ReadAll(getResp.Body)
|
|
||||||
if string(body) != payload {
|
|
||||||
t.Fatalf("GET body = %q, want %q", body, payload)
|
|
||||||
}
|
|
||||||
|
|
||||||
headReq, err := http.NewRequest(http.MethodHead, srv.URL+"/"+key, nil)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("failed to create HEAD request: %v", err)
|
|
||||||
}
|
|
||||||
headResp, err := http.DefaultClient.Do(headReq)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("HEAD request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = headResp.Body.Close() }()
|
|
||||||
|
|
||||||
if headResp.StatusCode != http.StatusOK {
|
|
||||||
t.Fatalf("HEAD status = %d, want %d", headResp.StatusCode, http.StatusOK)
|
|
||||||
}
|
|
||||||
body, _ = io.ReadAll(headResp.Body)
|
|
||||||
if len(body) != 0 {
|
|
||||||
t.Fatalf("HEAD body length = %d, want 0", len(body))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGradleBuildCacheHandler_RootKeyPath(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
h := NewGradleBuildCacheHandler(proxy)
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
key := "rootpathkey"
|
|
||||||
putReq, err := http.NewRequest(http.MethodPut, srv.URL+"/"+key, strings.NewReader("root"))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("failed to create PUT request: %v", err)
|
|
||||||
}
|
|
||||||
putResp, err := http.DefaultClient.Do(putReq)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("PUT request failed: %v", err)
|
|
||||||
}
|
|
||||||
_ = putResp.Body.Close()
|
|
||||||
|
|
||||||
if putResp.StatusCode != http.StatusCreated {
|
|
||||||
t.Fatalf("PUT status = %d, want %d", putResp.StatusCode, http.StatusCreated)
|
|
||||||
}
|
|
||||||
|
|
||||||
getResp, err := http.Get(srv.URL + "/" + key)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GET request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = getResp.Body.Close() }()
|
|
||||||
|
|
||||||
if getResp.StatusCode != http.StatusOK {
|
|
||||||
t.Fatalf("GET status = %d, want %d", getResp.StatusCode, http.StatusOK)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGradleBuildCacheHandler_GetMiss(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
h := NewGradleBuildCacheHandler(proxy)
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
resp, err := http.Get(srv.URL + "/missing-key")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GET request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusNotFound {
|
|
||||||
t.Fatalf("status = %d, want %d", resp.StatusCode, http.StatusNotFound)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGradleBuildCacheHandler_MethodNotAllowed(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
h := NewGradleBuildCacheHandler(proxy)
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodPost, "/key", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusMethodNotAllowed {
|
|
||||||
t.Fatalf("status = %d, want %d", w.Code, http.StatusMethodNotAllowed)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGradleBuildCacheHandler_PathTraversalRejected(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
h := NewGradleBuildCacheHandler(proxy)
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/../secret", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusBadRequest {
|
|
||||||
t.Fatalf("status = %d, want %d", w.Code, http.StatusBadRequest)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGradleBuildCacheHandler_CachePrefixRejected(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
h := NewGradleBuildCacheHandler(proxy)
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/cache/key", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusNotFound {
|
|
||||||
t.Fatalf("status = %d, want %d", w.Code, http.StatusNotFound)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGradleBuildCacheHandler_PutOverwriteReturnsCreated(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
h := NewGradleBuildCacheHandler(proxy)
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
key := "overwrite-key"
|
|
||||||
|
|
||||||
for i, payload := range []string{"first", "second"} {
|
|
||||||
req, err := http.NewRequest(http.MethodPut, srv.URL+"/"+key, strings.NewReader(payload))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("failed to create PUT request: %v", err)
|
|
||||||
}
|
|
||||||
resp, err := http.DefaultClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("PUT request failed: %v", err)
|
|
||||||
}
|
|
||||||
_ = resp.Body.Close()
|
|
||||||
|
|
||||||
want := http.StatusCreated
|
|
||||||
if resp.StatusCode != want {
|
|
||||||
t.Fatalf("PUT #%d status = %d, want %d", i+1, resp.StatusCode, want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGradleBuildCacheHandler_PutReadOnly(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.GradleReadOnly = true
|
|
||||||
|
|
||||||
h := NewGradleBuildCacheHandler(proxy)
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
req, err := http.NewRequest(http.MethodPut, srv.URL+"/readonly-key", strings.NewReader("payload"))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("failed to create PUT request: %v", err)
|
|
||||||
}
|
|
||||||
resp, err := http.DefaultClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("PUT request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusMethodNotAllowed {
|
|
||||||
t.Fatalf("PUT status = %d, want %d", resp.StatusCode, http.StatusMethodNotAllowed)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGradleBuildCacheHandler_PutTooLarge(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.GradleMaxUploadSize = 4
|
|
||||||
|
|
||||||
h := NewGradleBuildCacheHandler(proxy)
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
req, err := http.NewRequest(http.MethodPut, srv.URL+"/oversized-key", strings.NewReader("12345"))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("failed to create PUT request: %v", err)
|
|
||||||
}
|
|
||||||
resp, err := http.DefaultClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("PUT request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusRequestEntityTooLarge {
|
|
||||||
t.Fatalf("PUT status = %d, want %d", resp.StatusCode, http.StatusRequestEntityTooLarge)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGradleBuildCacheHandler_RecordsMetrics(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
h := NewGradleBuildCacheHandler(proxy)
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
hitsBefore := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("gradle"))
|
|
||||||
missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("gradle"))
|
|
||||||
|
|
||||||
key := "metrics-key"
|
|
||||||
putReq, err := http.NewRequest(http.MethodPut, srv.URL+"/"+key, strings.NewReader("payload"))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("failed to create PUT request: %v", err)
|
|
||||||
}
|
|
||||||
putResp, err := http.DefaultClient.Do(putReq)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("PUT request failed: %v", err)
|
|
||||||
}
|
|
||||||
_ = putResp.Body.Close()
|
|
||||||
|
|
||||||
getResp, err := http.Get(srv.URL + "/" + key)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GET request failed: %v", err)
|
|
||||||
}
|
|
||||||
_ = getResp.Body.Close()
|
|
||||||
|
|
||||||
headReq, err := http.NewRequest(http.MethodHead, srv.URL+"/"+key, nil)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("failed to create HEAD request: %v", err)
|
|
||||||
}
|
|
||||||
headResp, err := http.DefaultClient.Do(headReq)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("HEAD request failed: %v", err)
|
|
||||||
}
|
|
||||||
_ = headResp.Body.Close()
|
|
||||||
|
|
||||||
missResp, err := http.Get(srv.URL + "/missing-key")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GET miss request failed: %v", err)
|
|
||||||
}
|
|
||||||
_ = missResp.Body.Close()
|
|
||||||
|
|
||||||
hitsAfter := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("gradle"))
|
|
||||||
missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("gradle"))
|
|
||||||
|
|
||||||
if diff := hitsAfter - hitsBefore; diff != 2 {
|
|
||||||
t.Fatalf("cache hits delta = %.0f, want 2", diff)
|
|
||||||
}
|
|
||||||
if diff := missesAfter - missesBefore; diff != 1 {
|
|
||||||
t.Fatalf("cache misses delta = %.0f, want 1", diff)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,300 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bytes"
|
|
||||||
"context"
|
|
||||||
"crypto/sha256"
|
|
||||||
"database/sql"
|
|
||||||
"encoding/hex"
|
|
||||||
"fmt"
|
|
||||||
"io"
|
|
||||||
"log/slog"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"path/filepath"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/proxy/internal/database"
|
|
||||||
"github.com/git-pkgs/proxy/internal/storage"
|
|
||||||
"github.com/git-pkgs/purl"
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
|
||||||
|
|
||||||
const benchmarkArtifactSize = 64 << 10
|
|
||||||
|
|
||||||
const benchmarkMetadataSize = 1 << 20
|
|
||||||
|
|
||||||
type benchmarkResponseWriter struct {
|
|
||||||
header http.Header
|
|
||||||
}
|
|
||||||
|
|
||||||
func (w *benchmarkResponseWriter) Header() http.Header {
|
|
||||||
return w.header
|
|
||||||
}
|
|
||||||
|
|
||||||
func (w *benchmarkResponseWriter) Write(p []byte) (int, error) {
|
|
||||||
return len(p), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (w *benchmarkResponseWriter) WriteHeader(_ int) {}
|
|
||||||
|
|
||||||
func benchmarkCachedProxy(b *testing.B) (*Proxy, *mockStorage) {
|
|
||||||
b.Helper()
|
|
||||||
|
|
||||||
proxy, db, store, _ := setupTestProxy(b)
|
|
||||||
content := strings.Repeat("x", benchmarkArtifactSize)
|
|
||||||
seedPackage(b, db, store, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz", content)
|
|
||||||
|
|
||||||
artifact, err := db.GetArtifact("pkg:npm/lodash@4.17.21", "lodash-4.17.21.tgz")
|
|
||||||
if err != nil {
|
|
||||||
b.Fatalf("get seeded artifact: %v", err)
|
|
||||||
}
|
|
||||||
sum := sha256.Sum256([]byte(content))
|
|
||||||
artifact.ContentHash.String = hex.EncodeToString(sum[:])
|
|
||||||
if err := db.UpsertArtifact(artifact); err != nil {
|
|
||||||
b.Fatalf("update seeded artifact hash: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return proxy, store
|
|
||||||
}
|
|
||||||
|
|
||||||
func BenchmarkArtifactCacheHit(b *testing.B) {
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
b.Run("stream-64KiB", func(b *testing.B) {
|
|
||||||
proxy, _ := benchmarkCachedProxy(b)
|
|
||||||
w := &benchmarkResponseWriter{header: make(http.Header)}
|
|
||||||
b.SetBytes(benchmarkArtifactSize)
|
|
||||||
b.ReportAllocs()
|
|
||||||
b.ResetTimer()
|
|
||||||
|
|
||||||
for b.Loop() {
|
|
||||||
result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz")
|
|
||||||
if err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
ServeArtifact(w, result)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
|
|
||||||
b.Run("direct-serve", func(b *testing.B) {
|
|
||||||
proxy, store := benchmarkCachedProxy(b)
|
|
||||||
proxy.DirectServe = true
|
|
||||||
store.signedURL = "https://storage.example/npm/lodash-4.17.21.tgz?signature=abc"
|
|
||||||
w := &benchmarkResponseWriter{header: make(http.Header)}
|
|
||||||
b.ReportAllocs()
|
|
||||||
b.ResetTimer()
|
|
||||||
|
|
||||||
for b.Loop() {
|
|
||||||
result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz")
|
|
||||||
if err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
ServeArtifact(w, result)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func BenchmarkArtifactCacheHitParallel(b *testing.B) {
|
|
||||||
proxy, _ := benchmarkCachedProxy(b)
|
|
||||||
ctx := context.Background()
|
|
||||||
b.SetBytes(benchmarkArtifactSize)
|
|
||||||
b.ReportAllocs()
|
|
||||||
b.ResetTimer()
|
|
||||||
|
|
||||||
b.RunParallel(func(pb *testing.PB) {
|
|
||||||
w := &benchmarkResponseWriter{header: make(http.Header)}
|
|
||||||
for pb.Next() {
|
|
||||||
result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz")
|
|
||||||
if err != nil {
|
|
||||||
b.Error(err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
ServeArtifact(w, result)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func BenchmarkReadMetadata(b *testing.B) {
|
|
||||||
payload := bytes.Repeat([]byte("x"), benchmarkMetadataSize)
|
|
||||||
proxy := &Proxy{MetadataMaxSize: benchmarkMetadataSize}
|
|
||||||
b.SetBytes(benchmarkMetadataSize)
|
|
||||||
b.ReportAllocs()
|
|
||||||
|
|
||||||
var data []byte
|
|
||||||
for b.Loop() {
|
|
||||||
var err error
|
|
||||||
data, err = proxy.ReadMetadata(bytes.NewReader(payload))
|
|
||||||
if err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if len(data) != len(payload) {
|
|
||||||
b.Fatalf("metadata size = %d, want %d", len(data), len(payload))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func BenchmarkArtifactPURLConstruction(b *testing.B) {
|
|
||||||
for _, tc := range []struct {
|
|
||||||
name string
|
|
||||||
ecosystem string
|
|
||||||
packageID string
|
|
||||||
}{
|
|
||||||
{"npm", "npm", "lodash"},
|
|
||||||
{"scoped-npm", "npm", "@scope/package"},
|
|
||||||
{"go", "golang", "github.com/git-pkgs/proxy"},
|
|
||||||
} {
|
|
||||||
b.Run(tc.name, func(b *testing.B) {
|
|
||||||
b.ReportAllocs()
|
|
||||||
var packagePURL, versionPURL string
|
|
||||||
for b.Loop() {
|
|
||||||
packagePURL = purl.MakePURLString(tc.ecosystem, tc.packageID, "")
|
|
||||||
versionPURL = purl.MakePURLString(tc.ecosystem, tc.packageID, "1.2.3")
|
|
||||||
}
|
|
||||||
if packagePURL == "" || versionPURL == "" {
|
|
||||||
b.Fatal("empty PURL")
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
type benchmarkNPMServer struct {
|
|
||||||
client *http.Client
|
|
||||||
requestURL string
|
|
||||||
db *database.DB
|
|
||||||
versionPURL string
|
|
||||||
filename string
|
|
||||||
}
|
|
||||||
|
|
||||||
func newBenchmarkNPMServer(b *testing.B) *benchmarkNPMServer {
|
|
||||||
b.Helper()
|
|
||||||
|
|
||||||
ctx := context.Background()
|
|
||||||
dir := b.TempDir()
|
|
||||||
db, err := database.Create(filepath.Join(dir, "benchmark.db"))
|
|
||||||
if err != nil {
|
|
||||||
b.Fatalf("create database: %v", err)
|
|
||||||
}
|
|
||||||
b.Cleanup(func() { _ = db.Close() })
|
|
||||||
|
|
||||||
store, err := storage.OpenBucket(ctx, "file://"+filepath.Join(dir, "cache"))
|
|
||||||
if err != nil {
|
|
||||||
b.Fatalf("open storage: %v", err)
|
|
||||||
}
|
|
||||||
b.Cleanup(func() { _ = store.Close() })
|
|
||||||
|
|
||||||
content := bytes.Repeat([]byte("x"), benchmarkArtifactSize)
|
|
||||||
storagePath := storage.ArtifactPath("npm", "", "lodash", "4.17.21", "lodash-4.17.21.tgz")
|
|
||||||
size, hash, err := store.Store(ctx, storagePath, bytes.NewReader(content))
|
|
||||||
if err != nil {
|
|
||||||
b.Fatalf("store artifact: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
pkg := &database.Package{PURL: "pkg:npm/lodash", Ecosystem: "npm", Name: "lodash"}
|
|
||||||
if err := db.UpsertPackage(pkg); err != nil {
|
|
||||||
b.Fatalf("seed package: %v", err)
|
|
||||||
}
|
|
||||||
version := &database.Version{PURL: "pkg:npm/lodash@4.17.21", PackagePURL: pkg.PURL}
|
|
||||||
if err := db.UpsertVersion(version); err != nil {
|
|
||||||
b.Fatalf("seed version: %v", err)
|
|
||||||
}
|
|
||||||
artifact := &database.Artifact{
|
|
||||||
VersionPURL: version.PURL,
|
|
||||||
Filename: "lodash-4.17.21.tgz",
|
|
||||||
UpstreamURL: "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz",
|
|
||||||
StoragePath: sql.NullString{String: storagePath, Valid: true},
|
|
||||||
ContentHash: sql.NullString{String: hash, Valid: true},
|
|
||||||
Size: sql.NullInt64{Int64: size, Valid: true},
|
|
||||||
ContentType: sql.NullString{String: "application/gzip", Valid: true},
|
|
||||||
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
|
||||||
}
|
|
||||||
if err := db.UpsertArtifact(artifact); err != nil {
|
|
||||||
b.Fatalf("seed artifact: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
logger := slog.New(slog.NewTextHandler(io.Discard, nil))
|
|
||||||
proxy := NewProxy(db, store, &mockFetcher{}, fetch.NewResolver(), logger)
|
|
||||||
handler := NewNPMHandler(proxy, "http://proxy.example", "https://registry.npmjs.org")
|
|
||||||
server := httptest.NewServer(handler.Routes())
|
|
||||||
b.Cleanup(server.Close)
|
|
||||||
client := server.Client()
|
|
||||||
return &benchmarkNPMServer{
|
|
||||||
client: client,
|
|
||||||
requestURL: server.URL + "/lodash/-/lodash-4.17.21.tgz",
|
|
||||||
db: db,
|
|
||||||
versionPURL: version.PURL,
|
|
||||||
filename: artifact.Filename,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *benchmarkNPMServer) request() error {
|
|
||||||
resp, err := s.client.Get(s.requestURL)
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("GET cached artifact: %w", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
|
||||||
return fmt.Errorf("GET cached artifact status = %d, want %d", resp.StatusCode, http.StatusOK)
|
|
||||||
}
|
|
||||||
n, err := io.Copy(io.Discard, resp.Body)
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("read cached artifact: %w", err)
|
|
||||||
}
|
|
||||||
if n != benchmarkArtifactSize {
|
|
||||||
return fmt.Errorf("cached artifact size = %d, want %d", n, benchmarkArtifactSize)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *benchmarkNPMServer) hitCount(b *testing.B) int64 {
|
|
||||||
b.Helper()
|
|
||||||
artifact, err := s.db.GetArtifact(s.versionPURL, s.filename)
|
|
||||||
if err != nil {
|
|
||||||
b.Fatalf("get artifact hit count: %v", err)
|
|
||||||
}
|
|
||||||
return artifact.HitCount
|
|
||||||
}
|
|
||||||
|
|
||||||
func benchmarkNPMArtifactCacheHitHTTP(b *testing.B, parallel bool) {
|
|
||||||
server := newBenchmarkNPMServer(b)
|
|
||||||
if err := server.request(); err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
startHits := server.hitCount(b)
|
|
||||||
|
|
||||||
b.SetBytes(benchmarkArtifactSize)
|
|
||||||
b.ReportAllocs()
|
|
||||||
b.ResetTimer()
|
|
||||||
if parallel {
|
|
||||||
b.RunParallel(func(pb *testing.PB) {
|
|
||||||
for pb.Next() {
|
|
||||||
if err := server.request(); err != nil {
|
|
||||||
b.Error(err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
}
|
|
||||||
})
|
|
||||||
} else {
|
|
||||||
for b.Loop() {
|
|
||||||
if err := server.request(); err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
b.StopTimer()
|
|
||||||
|
|
||||||
if hitCount := server.hitCount(b) - startHits; hitCount != int64(b.N) {
|
|
||||||
b.Fatalf("new artifact hits = %d, want %d", hitCount, b.N)
|
|
||||||
}
|
|
||||||
b.ReportMetric(float64(b.N)/b.Elapsed().Seconds(), "requests/s")
|
|
||||||
}
|
|
||||||
|
|
||||||
func BenchmarkNPMArtifactCacheHitHTTP(b *testing.B) {
|
|
||||||
benchmarkNPMArtifactCacheHitHTTP(b, false)
|
|
||||||
}
|
|
||||||
|
|
||||||
func BenchmarkNPMArtifactCacheHitHTTPParallel(b *testing.B) {
|
|
||||||
benchmarkNPMArtifactCacheHitHTTP(b, true)
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,364 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/sha256"
|
|
||||||
"encoding/hex"
|
|
||||||
"errors"
|
|
||||||
"fmt"
|
|
||||||
"net/http"
|
|
||||||
"net/url"
|
|
||||||
"path"
|
|
||||||
"strings"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"gopkg.in/yaml.v3"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
helmMetadataEcosystem = "helm"
|
|
||||||
helmIndexFilename = "index.yaml"
|
|
||||||
sha256HexLength = 64
|
|
||||||
)
|
|
||||||
|
|
||||||
// HelmHandler serves read-only HTTP Helm chart repositories. Each configured
|
|
||||||
// repository is mounted at /helm/{repository}/.
|
|
||||||
type HelmHandler struct {
|
|
||||||
proxy *Proxy
|
|
||||||
proxyURL string
|
|
||||||
repositories map[string]string
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewHelmHandler creates a Helm chart repository protocol handler.
|
|
||||||
func NewHelmHandler(proxy *Proxy, proxyURL string, repositories map[string]string) *HelmHandler {
|
|
||||||
h := &HelmHandler{
|
|
||||||
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
|
||||||
repositories: make(map[string]string, len(repositories)),
|
|
||||||
proxy: proxy,
|
|
||||||
}
|
|
||||||
for name, repositoryURL := range repositories {
|
|
||||||
h.repositories[name] = strings.TrimSuffix(repositoryURL, "/")
|
|
||||||
}
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for Helm chart repository requests.
|
|
||||||
func (h *HelmHandler) Routes() http.Handler {
|
|
||||||
mux := http.NewServeMux()
|
|
||||||
mux.HandleFunc("GET /{repository}/index.yaml", h.handleIndex)
|
|
||||||
mux.HandleFunc("GET /{repository}/charts/{digest}/{filename}", h.handleChart)
|
|
||||||
return mux
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *HelmHandler) handleIndex(w http.ResponseWriter, r *http.Request) {
|
|
||||||
repository, upstreamURL, ok := h.repositoryForRequest(r)
|
|
||||||
if !ok {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
body, contentType, err := h.fetchIndex(r, repository, upstreamURL)
|
|
||||||
if err != nil {
|
|
||||||
h.serveIndexError(w, err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
rewritten, err := h.rewriteIndex(repository, upstreamURL, body)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to rewrite Helm index", "repository", repository, "error", err)
|
|
||||||
http.Error(w, "invalid Helm repository index", http.StatusBadGateway)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
h.proxy.writeMetadataCachedResponse(w, r, helmMetadataEcosystem, h.indexCacheKey(repository, upstreamURL), rewritten, contentType)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *HelmHandler) handleChart(w http.ResponseWriter, r *http.Request) {
|
|
||||||
repository, upstreamURL, ok := h.repositoryForRequest(r)
|
|
||||||
if !ok {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
digest, ok := normalizeHelmDigest(r.PathValue("digest"))
|
|
||||||
filename := r.PathValue("filename")
|
|
||||||
if !ok || filename == "" || strings.Contains(filename, "/") || containsPathTraversal(filename) {
|
|
||||||
http.Error(w, "invalid chart request", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
cached, err := h.proxy.GetCachedArtifact(r.Context(), helmMetadataEcosystem, repository, digest, filename)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Error("failed to check Helm chart cache", "error", err)
|
|
||||||
http.Error(w, "failed to check chart cache", http.StatusInternalServerError)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if cached != nil {
|
|
||||||
h.serveChart(w, r, repository, digest, filename, cached)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
body, _, err := h.fetchIndex(r, repository, upstreamURL)
|
|
||||||
if err != nil {
|
|
||||||
h.serveIndexError(w, err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
downloadURL, err := h.findChartDownload(upstreamURL, body, digest, filename)
|
|
||||||
if err != nil {
|
|
||||||
if errors.Is(err, errHelmChartNotFound) {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Warn("failed to read Helm index", "repository", repository, "error", err)
|
|
||||||
http.Error(w, "invalid Helm repository index", http.StatusBadGateway)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(
|
|
||||||
r.Context(), helmMetadataEcosystem, repository, digest, filename, downloadURL)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch chart")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.serveChart(w, r, repository, digest, filename, result)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *HelmHandler) serveChart(w http.ResponseWriter, r *http.Request, repository, digest, filename string, result *CacheResult) {
|
|
||||||
if !strings.EqualFold(result.Artifact.Digest.Encoded(), digest) {
|
|
||||||
if result.Reader != nil {
|
|
||||||
_ = result.Reader.Close()
|
|
||||||
}
|
|
||||||
if clearErr := h.proxy.ClearCachedArtifact(r.Context(), helmMetadataEcosystem, repository, digest, filename); clearErr != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to clear Helm chart with invalid digest", "error", clearErr)
|
|
||||||
}
|
|
||||||
http.Error(w, "chart digest verification failed", http.StatusBadGateway)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if result.Artifact.MediaType == "" {
|
|
||||||
w.Header().Set(headerContentType, "application/gzip")
|
|
||||||
}
|
|
||||||
ServeArtifact(w, result)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *HelmHandler) repositoryForRequest(r *http.Request) (name, upstreamURL string, ok bool) {
|
|
||||||
name = r.PathValue("repository")
|
|
||||||
upstreamURL, ok = h.repositories[name]
|
|
||||||
return name, upstreamURL, ok
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *HelmHandler) fetchIndex(r *http.Request, repository, upstreamURL string) ([]byte, string, error) {
|
|
||||||
return h.proxy.FetchOrCacheMetadata(
|
|
||||||
r.Context(),
|
|
||||||
helmMetadataEcosystem,
|
|
||||||
h.indexCacheKey(repository, upstreamURL),
|
|
||||||
upstreamURL+"/"+helmIndexFilename,
|
|
||||||
"application/x-yaml, text/yaml;q=0.9, */*;q=0.1",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *HelmHandler) indexCacheKey(repository, upstreamURL string) string {
|
|
||||||
identity := repository + "\x00" + upstreamURL
|
|
||||||
digest := sha256.Sum256([]byte(identity))
|
|
||||||
return hex.EncodeToString(digest[:])
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *HelmHandler) serveIndexError(w http.ResponseWriter, err error) {
|
|
||||||
if errors.Is(err, ErrUpstreamNotFound) {
|
|
||||||
http.Error(w, "Helm repository not found", http.StatusNotFound)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Error("failed to fetch Helm index", "error", err)
|
|
||||||
http.Error(w, "failed to fetch Helm repository index", http.StatusBadGateway)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *HelmHandler) rewriteIndex(repository, upstreamURL string, body []byte) ([]byte, error) {
|
|
||||||
document, entries, err := parseHelmIndex(body)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
for i := 0; i < len(entries.Content); i += 2 {
|
|
||||||
chartName := entries.Content[i].Value
|
|
||||||
releases := entries.Content[i+1]
|
|
||||||
if releases.Kind != yaml.SequenceNode {
|
|
||||||
return nil, fmt.Errorf("chart %q releases must be a sequence", chartName)
|
|
||||||
}
|
|
||||||
|
|
||||||
filtered := make([]*yaml.Node, 0, len(releases.Content))
|
|
||||||
for _, release := range releases.Content {
|
|
||||||
chart, err := h.parseChartRelease(chartName, upstreamURL, release)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
if h.chartOnCooldown(chartName, chart.created) {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
for _, download := range chart.downloads {
|
|
||||||
download.node.Value = h.chartProxyURL(repository, chart.digest, download.filename)
|
|
||||||
}
|
|
||||||
filtered = append(filtered, release)
|
|
||||||
}
|
|
||||||
releases.Content = filtered
|
|
||||||
}
|
|
||||||
|
|
||||||
return yaml.Marshal(document)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *HelmHandler) findChartDownload(upstreamURL string, body []byte, digest, filename string) (string, error) {
|
|
||||||
_, entries, err := parseHelmIndex(body)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
|
|
||||||
for i := 0; i < len(entries.Content); i += 2 {
|
|
||||||
chartName := entries.Content[i].Value
|
|
||||||
releases := entries.Content[i+1]
|
|
||||||
if releases.Kind != yaml.SequenceNode {
|
|
||||||
return "", fmt.Errorf("chart %q releases must be a sequence", chartName)
|
|
||||||
}
|
|
||||||
for _, release := range releases.Content {
|
|
||||||
chart, err := h.parseChartRelease(chartName, upstreamURL, release)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
if chart.digest != digest || h.chartOnCooldown(chartName, chart.created) {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
for _, download := range chart.downloads {
|
|
||||||
if download.filename == filename {
|
|
||||||
return download.url, nil
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return "", errHelmChartNotFound
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *HelmHandler) chartOnCooldown(chartName string, created time.Time) bool {
|
|
||||||
return !created.IsZero() && h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled() &&
|
|
||||||
!h.proxy.Cooldown.IsAllowed(helmMetadataEcosystem, canonicalPackagePURL(helmMetadataEcosystem, chartName), created)
|
|
||||||
}
|
|
||||||
|
|
||||||
type helmChartDownload struct {
|
|
||||||
node *yaml.Node
|
|
||||||
url string
|
|
||||||
filename string
|
|
||||||
}
|
|
||||||
|
|
||||||
type helmChartRelease struct {
|
|
||||||
created time.Time
|
|
||||||
digest string
|
|
||||||
downloads []helmChartDownload
|
|
||||||
}
|
|
||||||
|
|
||||||
var errHelmChartNotFound = errors.New("chart not found in Helm index")
|
|
||||||
|
|
||||||
func (h *HelmHandler) parseChartRelease(chartName, upstreamURL string, release *yaml.Node) (helmChartRelease, error) {
|
|
||||||
digestNode := helmMappingValue(release, "digest")
|
|
||||||
urlsNode := helmMappingValue(release, "urls")
|
|
||||||
if digestNode == nil || urlsNode == nil || urlsNode.Kind != yaml.SequenceNode || len(urlsNode.Content) == 0 {
|
|
||||||
return helmChartRelease{}, fmt.Errorf("chart %q has no digest or URLs", chartName)
|
|
||||||
}
|
|
||||||
digest, ok := normalizeHelmDigest(digestNode.Value)
|
|
||||||
if !ok {
|
|
||||||
return helmChartRelease{}, fmt.Errorf("chart %q has invalid digest", chartName)
|
|
||||||
}
|
|
||||||
|
|
||||||
baseURL, err := url.Parse(upstreamURL + "/" + helmIndexFilename)
|
|
||||||
if err != nil {
|
|
||||||
return helmChartRelease{}, fmt.Errorf("parsing Helm repository URL: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
chart := helmChartRelease{digest: digest}
|
|
||||||
if createdNode := helmMappingValue(release, "created"); createdNode != nil && createdNode.Value != "" {
|
|
||||||
chart.created, err = time.Parse(time.RFC3339Nano, createdNode.Value)
|
|
||||||
if err != nil {
|
|
||||||
return helmChartRelease{}, fmt.Errorf("chart %q has invalid creation time: %w", chartName, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, urlNode := range urlsNode.Content {
|
|
||||||
if urlNode.Kind != yaml.ScalarNode {
|
|
||||||
return helmChartRelease{}, fmt.Errorf("chart %q has invalid URL", chartName)
|
|
||||||
}
|
|
||||||
reference, err := url.Parse(urlNode.Value)
|
|
||||||
if err != nil {
|
|
||||||
return helmChartRelease{}, fmt.Errorf("parsing chart %q URL: %w", chartName, err)
|
|
||||||
}
|
|
||||||
downloadURL := baseURL.ResolveReference(reference)
|
|
||||||
if (downloadURL.Scheme != "http" && downloadURL.Scheme != "https") || downloadURL.Host == "" {
|
|
||||||
return helmChartRelease{}, fmt.Errorf("chart %q URL must be HTTP(S)", chartName)
|
|
||||||
}
|
|
||||||
filename := path.Base(downloadURL.Path)
|
|
||||||
if filename == "." || filename == "/" || filename == "" || !strings.HasSuffix(filename, ".tgz") {
|
|
||||||
return helmChartRelease{}, fmt.Errorf("chart %q URL must point to a .tgz file", chartName)
|
|
||||||
}
|
|
||||||
chart.downloads = append(chart.downloads, helmChartDownload{
|
|
||||||
node: urlNode,
|
|
||||||
url: downloadURL.String(),
|
|
||||||
filename: filename,
|
|
||||||
})
|
|
||||||
}
|
|
||||||
return chart, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *HelmHandler) chartProxyURL(repository, digest, filename string) string {
|
|
||||||
return fmt.Sprintf("%s/helm/%s/charts/%s/%s", h.proxyURL,
|
|
||||||
url.PathEscape(repository), digest, url.PathEscape(filename))
|
|
||||||
}
|
|
||||||
|
|
||||||
func parseHelmIndex(body []byte) (*yaml.Node, *yaml.Node, error) {
|
|
||||||
var document yaml.Node
|
|
||||||
if err := yaml.Unmarshal(body, &document); err != nil {
|
|
||||||
return nil, nil, fmt.Errorf("parsing Helm index: %w", err)
|
|
||||||
}
|
|
||||||
entries, err := helmIndexEntries(&document)
|
|
||||||
if err != nil {
|
|
||||||
return nil, nil, err
|
|
||||||
}
|
|
||||||
return &document, entries, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func helmIndexEntries(document *yaml.Node) (*yaml.Node, error) {
|
|
||||||
if document == nil {
|
|
||||||
return nil, errors.New("helm index is empty")
|
|
||||||
}
|
|
||||||
if len(document.Content) != 1 || document.Content[0].Kind != yaml.MappingNode {
|
|
||||||
return nil, errors.New("helm index must be a mapping")
|
|
||||||
}
|
|
||||||
entries := helmMappingValue(document.Content[0], "entries")
|
|
||||||
if entries == nil || entries.Kind != yaml.MappingNode {
|
|
||||||
return nil, errors.New("helm index has no entries mapping")
|
|
||||||
}
|
|
||||||
if len(entries.Content)%2 != 0 {
|
|
||||||
return nil, errors.New("helm index entries mapping has an incomplete key-value pair")
|
|
||||||
}
|
|
||||||
return entries, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func helmMappingValue(mapping *yaml.Node, key string) *yaml.Node {
|
|
||||||
if mapping == nil || mapping.Kind != yaml.MappingNode {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
for i := 0; i+1 < len(mapping.Content); i += 2 {
|
|
||||||
if mapping.Content[i].Value == key {
|
|
||||||
return mapping.Content[i+1]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func normalizeHelmDigest(value string) (string, bool) {
|
|
||||||
digest := strings.TrimPrefix(strings.ToLower(value), "sha256:")
|
|
||||||
if len(digest) != sha256HexLength {
|
|
||||||
return "", false
|
|
||||||
}
|
|
||||||
for _, char := range digest {
|
|
||||||
if (char < '0' || char > '9') && (char < 'a' || char > 'f') {
|
|
||||||
return "", false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return digest, true
|
|
||||||
}
|
|
||||||
|
|
@ -1,337 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/sha256"
|
|
||||||
"encoding/hex"
|
|
||||||
"fmt"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"strings"
|
|
||||||
"sync/atomic"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/cooldown"
|
|
||||||
upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient"
|
|
||||||
"github.com/git-pkgs/proxy/internal/storage"
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
"gopkg.in/yaml.v3"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestHelmHandler_RewritesIndexAndCachesChart(t *testing.T) {
|
|
||||||
chart := []byte("a Helm chart")
|
|
||||||
digest := helmSHA256Hex(chart)
|
|
||||||
var available atomic.Bool
|
|
||||||
available.Store(true)
|
|
||||||
var indexRequests atomic.Int32
|
|
||||||
var chartRequests atomic.Int32
|
|
||||||
|
|
||||||
var upstream *httptest.Server
|
|
||||||
upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if !available.Load() {
|
|
||||||
http.Error(w, "unavailable", http.StatusServiceUnavailable)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
switch r.URL.Path {
|
|
||||||
case "/charts/index.yaml":
|
|
||||||
indexRequests.Add(1)
|
|
||||||
w.Header().Set("Content-Type", "application/x-yaml")
|
|
||||||
_, _ = fmt.Fprintf(w, `apiVersion: v1
|
|
||||||
entries:
|
|
||||||
demo:
|
|
||||||
- annotations:
|
|
||||||
example.com/retained: "true"
|
|
||||||
created: 2020-01-02T03:04:05Z
|
|
||||||
digest: %s
|
|
||||||
name: demo
|
|
||||||
urls:
|
|
||||||
- demo-1.0.0.tgz
|
|
||||||
- %s/charts/mirror/demo-1.0.0.tgz
|
|
||||||
version: 1.0.0
|
|
||||||
generated: 2020-01-02T03:04:05Z
|
|
||||||
`, digest, upstream.URL)
|
|
||||||
case "/charts/demo-1.0.0.tgz", "/charts/mirror/demo-1.0.0.tgz":
|
|
||||||
chartRequests.Add(1)
|
|
||||||
w.Header().Set("Content-Type", "application/gzip")
|
|
||||||
_, _ = w.Write(chart)
|
|
||||||
default:
|
|
||||||
http.NotFound(w, r)
|
|
||||||
}
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
t.Cleanup(func() { _ = fetcher.Close() })
|
|
||||||
|
|
||||||
h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"stable": upstream.URL + "/charts"})
|
|
||||||
|
|
||||||
indexResponse := serveHelmRequest(h, "/stable/index.yaml")
|
|
||||||
if indexResponse.Code != http.StatusOK {
|
|
||||||
t.Fatalf("index status = %d, want 200: %s", indexResponse.Code, indexResponse.Body.String())
|
|
||||||
}
|
|
||||||
if got := indexResponse.Header().Get("Content-Type"); got != "application/x-yaml" {
|
|
||||||
t.Errorf("index Content-Type = %q, want application/x-yaml", got)
|
|
||||||
}
|
|
||||||
if strings.Contains(indexResponse.Body.String(), upstream.URL) {
|
|
||||||
t.Errorf("rewritten index contains upstream URL: %s", indexResponse.Body.String())
|
|
||||||
}
|
|
||||||
if !strings.Contains(indexResponse.Body.String(), "example.com/retained") {
|
|
||||||
t.Errorf("rewritten index lost an unrelated field: %s", indexResponse.Body.String())
|
|
||||||
}
|
|
||||||
|
|
||||||
var index map[string]any
|
|
||||||
if err := yaml.Unmarshal(indexResponse.Body.Bytes(), &index); err != nil {
|
|
||||||
t.Fatalf("parse rewritten index: %v", err)
|
|
||||||
}
|
|
||||||
entries := index["entries"].(map[string]any)
|
|
||||||
release := entries["demo"].([]any)[0].(map[string]any)
|
|
||||||
urls := release["urls"].([]any)
|
|
||||||
wantURL := "http://proxy.example/helm/stable/charts/" + digest + "/demo-1.0.0.tgz"
|
|
||||||
for _, rawURL := range urls {
|
|
||||||
if rawURL != wantURL {
|
|
||||||
t.Errorf("rewritten URL = %q, want %q", rawURL, wantURL)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
firstChart := serveHelmRequest(h, "/stable/charts/"+digest+"/demo-1.0.0.tgz")
|
|
||||||
if firstChart.Code != http.StatusOK {
|
|
||||||
t.Fatalf("chart status = %d, want 200: %s", firstChart.Code, firstChart.Body.String())
|
|
||||||
}
|
|
||||||
if got := firstChart.Body.String(); got != string(chart) {
|
|
||||||
t.Errorf("chart body = %q, want %q", got, chart)
|
|
||||||
}
|
|
||||||
if got := firstChart.Header().Get("Content-Type"); got != "application/gzip" {
|
|
||||||
t.Errorf("chart Content-Type = %q, want application/gzip", got)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Artifact cache availability must not depend on metadata caching or a
|
|
||||||
// reachable index upstream.
|
|
||||||
proxy.CacheMetadata = false
|
|
||||||
available.Store(false)
|
|
||||||
cachedChart := serveHelmRequest(h, "/stable/charts/"+digest+"/demo-1.0.0.tgz")
|
|
||||||
if cachedChart.Code != http.StatusOK {
|
|
||||||
t.Fatalf("cached chart status = %d, want 200: %s", cachedChart.Code, cachedChart.Body.String())
|
|
||||||
}
|
|
||||||
if got := cachedChart.Body.String(); got != string(chart) {
|
|
||||||
t.Errorf("cached chart body = %q, want %q", got, chart)
|
|
||||||
}
|
|
||||||
if got := indexRequests.Load(); got != 1 {
|
|
||||||
t.Errorf("index requests = %d, want 1", got)
|
|
||||||
}
|
|
||||||
if got := chartRequests.Load(); got != 1 {
|
|
||||||
t.Errorf("chart requests = %d, want 1", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHelmHandler_RejectsChartDigestMismatch(t *testing.T) {
|
|
||||||
chart := []byte("tampered chart")
|
|
||||||
digest := helmSHA256Hex([]byte("expected chart"))
|
|
||||||
requests := 0
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
switch r.URL.Path {
|
|
||||||
case "/index.yaml":
|
|
||||||
_, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", digest)
|
|
||||||
case "/demo.tgz":
|
|
||||||
requests++
|
|
||||||
_, _ = w.Write(chart)
|
|
||||||
default:
|
|
||||||
http.NotFound(w, r)
|
|
||||||
}
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, store, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
t.Cleanup(func() { _ = fetcher.Close() })
|
|
||||||
h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"test": upstream.URL})
|
|
||||||
|
|
||||||
for range 2 {
|
|
||||||
response := serveHelmRequest(h, "/test/charts/"+digest+"/demo.tgz")
|
|
||||||
if response.Code != http.StatusBadGateway {
|
|
||||||
t.Errorf("status = %d, want 502: %s", response.Code, response.Body.String())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if requests != 2 {
|
|
||||||
t.Errorf("chart requests = %d, want 2 after invalid cache entry is cleared", requests)
|
|
||||||
}
|
|
||||||
storagePath := storage.ArtifactPath(helmMetadataEcosystem, "", "test", digest, "demo.tgz")
|
|
||||||
if exists, err := store.Exists(t.Context(), storagePath); err != nil {
|
|
||||||
t.Fatalf("checking rejected chart storage: %v", err)
|
|
||||||
} else if exists {
|
|
||||||
t.Errorf("rejected chart remains in storage at %q", storagePath)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHelmHandler_IndexCacheChangesWithUpstreamURL(t *testing.T) {
|
|
||||||
firstDigest := strings.Repeat("a", sha256HexLength)
|
|
||||||
secondDigest := strings.Repeat("b", sha256HexLength)
|
|
||||||
firstRequests := 0
|
|
||||||
secondRequests := 0
|
|
||||||
first := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
firstRequests++
|
|
||||||
_, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", firstDigest)
|
|
||||||
}))
|
|
||||||
defer first.Close()
|
|
||||||
second := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
secondRequests++
|
|
||||||
_, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", secondDigest)
|
|
||||||
}))
|
|
||||||
defer second.Close()
|
|
||||||
|
|
||||||
proxy, db, store, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
proxy.HTTPClient = first.Client()
|
|
||||||
firstHandler := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"stable": first.URL})
|
|
||||||
if response := serveHelmRequest(firstHandler, "/stable/index.yaml"); response.Code != http.StatusOK {
|
|
||||||
t.Fatalf("first index status = %d, want 200: %s", response.Code, response.Body.String())
|
|
||||||
}
|
|
||||||
|
|
||||||
// Model a restarted server with the same database and storage but a changed
|
|
||||||
// repository URL. Its cache key must not reuse the previous index or ETag.
|
|
||||||
restartedProxy := NewProxy(db, store, &mockFetcher{}, fetch.NewResolver(), nil)
|
|
||||||
restartedProxy.CacheMetadata = true
|
|
||||||
restartedProxy.MetadataTTL = time.Hour
|
|
||||||
restartedProxy.HTTPClient = second.Client()
|
|
||||||
secondHandler := NewHelmHandler(restartedProxy, "http://proxy.example", map[string]string{"stable": second.URL})
|
|
||||||
response := serveHelmRequest(secondHandler, "/stable/index.yaml")
|
|
||||||
if response.Code != http.StatusOK {
|
|
||||||
t.Fatalf("second index status = %d, want 200: %s", response.Code, response.Body.String())
|
|
||||||
}
|
|
||||||
if !strings.Contains(response.Body.String(), secondDigest) {
|
|
||||||
t.Errorf("second index did not use the new upstream: %s", response.Body.String())
|
|
||||||
}
|
|
||||||
if firstRequests != 1 {
|
|
||||||
t.Errorf("first upstream requests = %d, want 1", firstRequests)
|
|
||||||
}
|
|
||||||
if secondRequests != 1 {
|
|
||||||
t.Errorf("second upstream requests = %d, want 1", secondRequests)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHelmHandler_UsesConfiguredUpstreamAuthentication(t *testing.T) {
|
|
||||||
chart := []byte("private Helm chart")
|
|
||||||
digest := helmSHA256Hex(chart)
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if r.Header.Get("Authorization") != "Bearer private-token" {
|
|
||||||
http.Error(w, "unauthorized", http.StatusUnauthorized)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
switch r.URL.Path {
|
|
||||||
case "/index.yaml":
|
|
||||||
_, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", digest)
|
|
||||||
case "/demo.tgz":
|
|
||||||
_, _ = w.Write(chart)
|
|
||||||
default:
|
|
||||||
http.NotFound(w, r)
|
|
||||||
}
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
authClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport,
|
|
||||||
upstreamhttp.AuthFunc(func(string) (string, string) {
|
|
||||||
return "Authorization", "Bearer private-token"
|
|
||||||
}))}
|
|
||||||
proxy.HTTPClient = authClient
|
|
||||||
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(authClient), fetch.WithMaxRetries(0))
|
|
||||||
proxy.Fetcher = fetcher
|
|
||||||
t.Cleanup(func() { _ = fetcher.Close() })
|
|
||||||
h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"private": upstream.URL})
|
|
||||||
|
|
||||||
response := serveHelmRequest(h, "/private/charts/"+digest+"/demo.tgz")
|
|
||||||
if response.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want 200: %s", response.Code, response.Body.String())
|
|
||||||
}
|
|
||||||
if got := response.Body.String(); got != string(chart) {
|
|
||||||
t.Errorf("body = %q, want %q", got, chart)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHelmHandler_FiltersNewChartsFromIndex(t *testing.T) {
|
|
||||||
oldDigest := strings.Repeat("a", 64)
|
|
||||||
newDigest := strings.Repeat("b", 64)
|
|
||||||
proxy := &Proxy{Cooldown: &cooldown.Config{Default: "3d"}}
|
|
||||||
h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"test": "https://charts.example"})
|
|
||||||
|
|
||||||
body := fmt.Sprintf(`apiVersion: v1
|
|
||||||
entries:
|
|
||||||
demo:
|
|
||||||
- created: %s
|
|
||||||
digest: %s
|
|
||||||
urls: [demo-old.tgz]
|
|
||||||
- created: %s
|
|
||||||
digest: %s
|
|
||||||
urls: [demo-new.tgz]
|
|
||||||
`, time.Now().Add(-10*24*time.Hour).Format(time.RFC3339), oldDigest,
|
|
||||||
time.Now().Add(-time.Hour).Format(time.RFC3339), newDigest)
|
|
||||||
|
|
||||||
rewritten, err := h.rewriteIndex("test", "https://charts.example", []byte(body))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("rewriteIndex() error = %v", err)
|
|
||||||
}
|
|
||||||
if strings.Contains(string(rewritten), newDigest) {
|
|
||||||
t.Errorf("rewritten index includes a chart still in cooldown: %s", rewritten)
|
|
||||||
}
|
|
||||||
if !strings.Contains(string(rewritten), oldDigest) {
|
|
||||||
t.Errorf("rewritten index omitted an old chart: %s", rewritten)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNormalizeHelmDigest(t *testing.T) {
|
|
||||||
digest := strings.Repeat("a", 64)
|
|
||||||
for _, input := range []string{digest, "sha256:" + digest, "SHA256:" + strings.ToUpper(digest)} {
|
|
||||||
if got, ok := normalizeHelmDigest(input); !ok || got != digest {
|
|
||||||
t.Errorf("normalizeHelmDigest(%q) = %q, %t; want %q, true", input, got, ok, digest)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if _, ok := normalizeHelmDigest("bad"); ok {
|
|
||||||
t.Error("normalizeHelmDigest accepted an invalid digest")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHelmIndexEntriesRejectsIncompleteMapping(t *testing.T) {
|
|
||||||
entries := &yaml.Node{
|
|
||||||
Kind: yaml.MappingNode,
|
|
||||||
Content: []*yaml.Node{
|
|
||||||
{Kind: yaml.ScalarNode, Value: "demo"},
|
|
||||||
},
|
|
||||||
}
|
|
||||||
document := &yaml.Node{
|
|
||||||
Kind: yaml.DocumentNode,
|
|
||||||
Content: []*yaml.Node{{
|
|
||||||
Kind: yaml.MappingNode,
|
|
||||||
Content: []*yaml.Node{
|
|
||||||
{Kind: yaml.ScalarNode, Value: "entries"},
|
|
||||||
entries,
|
|
||||||
},
|
|
||||||
}},
|
|
||||||
}
|
|
||||||
|
|
||||||
if _, err := helmIndexEntries(document); err == nil {
|
|
||||||
t.Fatal("helmIndexEntries() error = nil, want incomplete mapping error")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func serveHelmRequest(h *HelmHandler, target string) *httptest.ResponseRecorder {
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, target, nil))
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
|
|
||||||
func helmSHA256Hex(data []byte) string {
|
|
||||||
digest := sha256.Sum256(data)
|
|
||||||
return hex.EncodeToString(digest[:])
|
|
||||||
}
|
|
||||||
|
|
@ -1,16 +1,10 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
|
||||||
"compress/gzip"
|
|
||||||
"encoding/json"
|
|
||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
|
||||||
|
|
||||||
"google.golang.org/protobuf/encoding/protowire"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
|
|
@ -21,7 +15,6 @@ const (
|
||||||
type HexHandler struct {
|
type HexHandler struct {
|
||||||
proxy *Proxy
|
proxy *Proxy
|
||||||
upstreamURL string
|
upstreamURL string
|
||||||
apiURL string
|
|
||||||
proxyURL string
|
proxyURL string
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -30,20 +23,10 @@ func NewHexHandler(proxy *Proxy, proxyURL string) *HexHandler {
|
||||||
return &HexHandler{
|
return &HexHandler{
|
||||||
proxy: proxy,
|
proxy: proxy,
|
||||||
upstreamURL: hexUpstream,
|
upstreamURL: hexUpstream,
|
||||||
apiURL: hexAPIURL,
|
|
||||||
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewHexHandlerWithUpstreams creates a Hex handler with custom repository and
|
|
||||||
// API upstreams.
|
|
||||||
func NewHexHandlerWithUpstreams(proxy *Proxy, proxyURL, upstreamURL, apiURL string) *HexHandler {
|
|
||||||
h := NewHexHandler(proxy, proxyURL)
|
|
||||||
h.upstreamURL = configuredUpstreamURL(upstreamURL, hexUpstream)
|
|
||||||
h.apiURL = configuredUpstreamURL(apiURL, hexAPIURL)
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for Hex requests.
|
// Routes returns the HTTP handler for Hex requests.
|
||||||
func (h *HexHandler) Routes() http.Handler {
|
func (h *HexHandler) Routes() http.Handler {
|
||||||
mux := http.NewServeMux()
|
mux := http.NewServeMux()
|
||||||
|
|
@ -51,10 +34,10 @@ func (h *HexHandler) Routes() http.Handler {
|
||||||
// Package tarballs (cache these)
|
// Package tarballs (cache these)
|
||||||
mux.HandleFunc("GET /tarballs/{filename}", h.handleDownload)
|
mux.HandleFunc("GET /tarballs/{filename}", h.handleDownload)
|
||||||
|
|
||||||
// Registry resources (cached for offline)
|
// Registry resources (proxy without caching)
|
||||||
mux.HandleFunc("GET /names", h.proxyCached)
|
mux.HandleFunc("GET /names", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET /versions", h.proxyCached)
|
mux.HandleFunc("GET /versions", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET /packages/{name}", h.handlePackages)
|
mux.HandleFunc("GET /packages/{name}", h.proxyUpstream)
|
||||||
|
|
||||||
// Public keys
|
// Public keys
|
||||||
mux.HandleFunc("GET /public_key", h.proxyUpstream)
|
mux.HandleFunc("GET /public_key", h.proxyUpstream)
|
||||||
|
|
@ -64,14 +47,30 @@ func (h *HexHandler) Routes() http.Handler {
|
||||||
|
|
||||||
// handleDownload serves a package tarball, fetching and caching from upstream if needed.
|
// handleDownload serves a package tarball, fetching and caching from upstream if needed.
|
||||||
func (h *HexHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
func (h *HexHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
||||||
h.proxy.handleFilenameDownload(w, r, filenameDownload{
|
filename := r.PathValue("filename")
|
||||||
ecosystem: "hex",
|
if filename == "" || !strings.HasSuffix(filename, ".tar") {
|
||||||
upstreamURL: h.upstreamURL,
|
http.Error(w, "invalid filename", http.StatusBadRequest)
|
||||||
suffix: ".tar",
|
return
|
||||||
parseErr: "could not parse tarball filename",
|
}
|
||||||
fetchErr: "failed to fetch package",
|
|
||||||
parse: h.parseTarballFilename,
|
// Extract name and version from filename (e.g., "phoenix-1.7.10.tar")
|
||||||
})
|
name, version := h.parseTarballFilename(filename)
|
||||||
|
if name == "" || version == "" {
|
||||||
|
http.Error(w, "could not parse tarball filename", http.StatusBadRequest)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
h.proxy.Logger.Info("hex download request",
|
||||||
|
"name", name, "version", version, "filename", filename)
|
||||||
|
|
||||||
|
result, err := h.proxy.GetOrFetchArtifact(r.Context(), "hex", name, version, filename)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
|
http.Error(w, "failed to fetch package", http.StatusBadGateway)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
ServeArtifact(w, result)
|
||||||
}
|
}
|
||||||
|
|
||||||
// parseTarballFilename extracts name and version from a hex tarball filename.
|
// parseTarballFilename extracts name and version from a hex tarball filename.
|
||||||
|
|
@ -88,336 +87,42 @@ func (h *HexHandler) parseTarballFilename(filename string) (name, version string
|
||||||
return "", ""
|
return "", ""
|
||||||
}
|
}
|
||||||
|
|
||||||
// hexAPIURL is the Hex HTTP API base URL for fetching package metadata with timestamps.
|
// proxyUpstream forwards a request to hex.pm without caching.
|
||||||
const hexAPIURL = "https://hex.pm"
|
func (h *HexHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
||||||
|
upstreamURL := h.upstreamURL + r.URL.Path
|
||||||
|
|
||||||
// handlePackages proxies the /packages/{name} endpoint, applying cooldown filtering
|
h.proxy.Logger.Debug("proxying to upstream", "url", upstreamURL)
|
||||||
// when enabled. Since the protobuf format has no timestamps, we fetch them from the
|
|
||||||
// Hex HTTP API concurrently.
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
||||||
func (h *HexHandler) handlePackages(w http.ResponseWriter, r *http.Request) {
|
if err != nil {
|
||||||
if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
|
http.Error(w, "failed to create request", http.StatusInternalServerError)
|
||||||
h.proxyCached(w, r)
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
name := r.PathValue("name")
|
// Copy accept header for content negotiation
|
||||||
if name == "" {
|
if accept := r.Header.Get("Accept"); accept != "" {
|
||||||
h.proxyCached(w, r)
|
req.Header.Set("Accept", accept)
|
||||||
return
|
|
||||||
}
|
}
|
||||||
|
|
||||||
h.proxy.Logger.Info("hex package request with cooldown", "name", name)
|
resp, err := http.DefaultClient.Do(req)
|
||||||
|
|
||||||
protoResp, filteredVersions, err := h.fetchPackageAndVersions(r, name)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.Logger.Error("upstream request failed", "error", err)
|
h.proxy.Logger.Error("upstream request failed", "error", err)
|
||||||
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
defer func() { _ = protoResp.Body.Close() }()
|
|
||||||
|
|
||||||
if protoResp.StatusCode != http.StatusOK {
|
|
||||||
for k, vv := range protoResp.Header {
|
|
||||||
for _, v := range vv {
|
|
||||||
w.Header().Add(k, v)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
w.WriteHeader(protoResp.StatusCode)
|
|
||||||
_, _ = io.Copy(w, protoResp.Body)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
body, err := io.ReadAll(protoResp.Body)
|
|
||||||
if err != nil {
|
|
||||||
http.Error(w, "failed to read response", http.StatusInternalServerError)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if len(filteredVersions) == 0 {
|
|
||||||
// No versions to filter or couldn't get timestamps, pass through
|
|
||||||
w.Header().Set(headerContentType, protoResp.Header.Get(headerContentType))
|
|
||||||
w.Header().Set("Content-Encoding", "gzip")
|
|
||||||
_, _ = w.Write(body)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
filtered, err := h.filterSignedPackage(body, filteredVersions)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to filter hex package, proxying original", "error", err)
|
|
||||||
w.Header().Set(headerContentType, protoResp.Header.Get(headerContentType))
|
|
||||||
w.Header().Set("Content-Encoding", "gzip")
|
|
||||||
_, _ = w.Write(body)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
w.Header().Set(headerContentType, "application/octet-stream")
|
|
||||||
w.Header().Set("Content-Encoding", "gzip")
|
|
||||||
_, _ = w.Write(filtered)
|
|
||||||
}
|
|
||||||
|
|
||||||
// fetchPackageAndVersions fetches the protobuf package and version timestamps concurrently.
|
|
||||||
func (h *HexHandler) fetchPackageAndVersions(r *http.Request, name string) (*http.Response, map[string]bool, error) {
|
|
||||||
type versionsResult struct {
|
|
||||||
filtered map[string]bool
|
|
||||||
err error
|
|
||||||
}
|
|
||||||
|
|
||||||
versionsCh := make(chan versionsResult, 1)
|
|
||||||
go func() {
|
|
||||||
filtered, err := h.fetchFilteredVersions(r, name)
|
|
||||||
versionsCh <- versionsResult{filtered: filtered, err: err}
|
|
||||||
}()
|
|
||||||
|
|
||||||
protoResp, err := h.fetchUpstreamPackage(r, name)
|
|
||||||
|
|
||||||
versionsRes := <-versionsCh
|
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
return nil, nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
if versionsRes.err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to fetch hex version timestamps, proxying unfiltered",
|
|
||||||
"name", name, "error", versionsRes.err)
|
|
||||||
return protoResp, nil, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
return protoResp, versionsRes.filtered, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// fetchUpstreamPackage fetches the protobuf package from upstream.
|
|
||||||
func (h *HexHandler) fetchUpstreamPackage(r *http.Request, name string) (*http.Response, error) {
|
|
||||||
upstreamURL := h.upstreamURL + "/packages/" + name
|
|
||||||
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
return h.proxy.HTTPClient.Do(req)
|
|
||||||
}
|
|
||||||
|
|
||||||
// hexRelease represents a version entry from the Hex API.
|
|
||||||
type hexRelease struct {
|
|
||||||
Version string `json:"version"`
|
|
||||||
InsertedAt string `json:"inserted_at"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// hexPackageAPI represents the Hex API response for a package.
|
|
||||||
type hexPackageAPI struct {
|
|
||||||
Releases []hexRelease `json:"releases"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// fetchFilteredVersions fetches the Hex API and returns a set of version
|
|
||||||
// strings that should be filtered out by cooldown.
|
|
||||||
func (h *HexHandler) fetchFilteredVersions(r *http.Request, name string) (map[string]bool, error) {
|
|
||||||
apiURL := fmt.Sprintf("%s/api/packages/%s", h.apiURL, name)
|
|
||||||
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, apiURL, nil)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
req.Header.Set("Accept", "application/json")
|
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
// Copy response headers
|
||||||
return nil, fmt.Errorf("hex API returned %d", resp.StatusCode)
|
for k, vv := range resp.Header {
|
||||||
}
|
for _, v := range vv {
|
||||||
|
w.Header().Add(k, v)
|
||||||
var pkg hexPackageAPI
|
|
||||||
if err := json.NewDecoder(resp.Body).Decode(&pkg); err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
packagePURL := canonicalPackagePURL("hex", name)
|
|
||||||
filtered := make(map[string]bool)
|
|
||||||
|
|
||||||
for _, release := range pkg.Releases {
|
|
||||||
insertedAt, err := time.Parse(time.RFC3339Nano, release.InsertedAt)
|
|
||||||
if err != nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
if !h.proxy.Cooldown.IsAllowed("hex", packagePURL, insertedAt) {
|
|
||||||
filtered[release.Version] = true
|
|
||||||
h.proxy.Logger.Info("cooldown: filtering hex version",
|
|
||||||
"package", name, "version", release.Version,
|
|
||||||
"published", release.InsertedAt)
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return filtered, nil
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
}
|
}
|
||||||
|
|
||||||
// filterSignedPackage decompresses gzipped data, decodes the Signed protobuf wrapper,
|
func init() {
|
||||||
// filters releases from the Package payload, and re-encodes as gzipped protobuf
|
_ = fmt.Sprintf // silence import if unused
|
||||||
// (without the original signature since the payload has changed).
|
|
||||||
func (h *HexHandler) filterSignedPackage(gzippedData []byte, filteredVersions map[string]bool) ([]byte, error) {
|
|
||||||
// Decompress gzip
|
|
||||||
gr, err := gzip.NewReader(bytes.NewReader(gzippedData))
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
signed, err := io.ReadAll(gr)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
_ = gr.Close()
|
|
||||||
|
|
||||||
// Parse Signed message: field 1 = payload (bytes), field 2 = signature (bytes)
|
|
||||||
payload, err := extractProtobufBytes(signed, 1)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("extracting payload: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Filter releases from the Package message
|
|
||||||
filteredPayload, err := filterPackageReleases(payload, filteredVersions)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("filtering releases: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Re-encode Signed message with modified payload and no signature
|
|
||||||
var newSigned []byte
|
|
||||||
newSigned = protowire.AppendTag(newSigned, 1, protowire.BytesType)
|
|
||||||
newSigned = protowire.AppendBytes(newSigned, filteredPayload)
|
|
||||||
|
|
||||||
// Gzip compress
|
|
||||||
var buf bytes.Buffer
|
|
||||||
gw := gzip.NewWriter(&buf)
|
|
||||||
if _, err := gw.Write(newSigned); err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
if err := gw.Close(); err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
return buf.Bytes(), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// filterPackageReleases filters releases from a Package protobuf message.
|
|
||||||
// Package: field 1 = releases (repeated), field 2 = name, field 3 = repository
|
|
||||||
func filterPackageReleases(payload []byte, filteredVersions map[string]bool) ([]byte, error) {
|
|
||||||
var result []byte
|
|
||||||
data := payload
|
|
||||||
|
|
||||||
for len(data) > 0 {
|
|
||||||
num, wtype, n := protowire.ConsumeTag(data)
|
|
||||||
if n < 0 {
|
|
||||||
return nil, fmt.Errorf("invalid protobuf tag")
|
|
||||||
}
|
|
||||||
|
|
||||||
tagBytes := data[:n]
|
|
||||||
data = data[n:]
|
|
||||||
|
|
||||||
var fieldBytes []byte
|
|
||||||
switch wtype {
|
|
||||||
case protowire.BytesType:
|
|
||||||
v, vn := protowire.ConsumeBytes(data)
|
|
||||||
if vn < 0 {
|
|
||||||
return nil, fmt.Errorf("invalid protobuf bytes field")
|
|
||||||
}
|
|
||||||
fieldBytes = data[:vn]
|
|
||||||
data = data[vn:]
|
|
||||||
|
|
||||||
if num == 1 { // releases field
|
|
||||||
version := extractReleaseVersion(v)
|
|
||||||
if filteredVersions[version] {
|
|
||||||
continue // skip this release
|
|
||||||
}
|
|
||||||
}
|
|
||||||
case protowire.VarintType:
|
|
||||||
_, vn := protowire.ConsumeVarint(data)
|
|
||||||
if vn < 0 {
|
|
||||||
return nil, fmt.Errorf("invalid protobuf varint")
|
|
||||||
}
|
|
||||||
fieldBytes = data[:vn]
|
|
||||||
data = data[vn:]
|
|
||||||
default:
|
|
||||||
return nil, fmt.Errorf("unexpected wire type %d", wtype)
|
|
||||||
}
|
|
||||||
|
|
||||||
result = append(result, tagBytes...)
|
|
||||||
result = append(result, fieldBytes...)
|
|
||||||
}
|
|
||||||
|
|
||||||
return result, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// extractReleaseVersion extracts the version string from a Release protobuf message.
|
|
||||||
// Release: field 1 = version (string)
|
|
||||||
func extractReleaseVersion(release []byte) string {
|
|
||||||
data := release
|
|
||||||
for len(data) > 0 {
|
|
||||||
num, wtype, n := protowire.ConsumeTag(data)
|
|
||||||
if n < 0 {
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
data = data[n:]
|
|
||||||
|
|
||||||
switch wtype {
|
|
||||||
case protowire.BytesType:
|
|
||||||
v, vn := protowire.ConsumeBytes(data)
|
|
||||||
if vn < 0 {
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
if num == 1 {
|
|
||||||
return string(v)
|
|
||||||
}
|
|
||||||
data = data[vn:]
|
|
||||||
case protowire.VarintType:
|
|
||||||
_, vn := protowire.ConsumeVarint(data)
|
|
||||||
if vn < 0 {
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
data = data[vn:]
|
|
||||||
default:
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
|
|
||||||
// extractProtobufBytes extracts a bytes field from a protobuf message by field number.
|
|
||||||
func extractProtobufBytes(data []byte, fieldNum protowire.Number) ([]byte, error) {
|
|
||||||
for len(data) > 0 {
|
|
||||||
num, wtype, n := protowire.ConsumeTag(data)
|
|
||||||
if n < 0 {
|
|
||||||
return nil, fmt.Errorf("invalid protobuf tag")
|
|
||||||
}
|
|
||||||
data = data[n:]
|
|
||||||
|
|
||||||
switch wtype {
|
|
||||||
case protowire.BytesType:
|
|
||||||
v, vn := protowire.ConsumeBytes(data)
|
|
||||||
if vn < 0 {
|
|
||||||
return nil, fmt.Errorf("invalid protobuf bytes")
|
|
||||||
}
|
|
||||||
if num == fieldNum {
|
|
||||||
return v, nil
|
|
||||||
}
|
|
||||||
data = data[vn:]
|
|
||||||
case protowire.VarintType:
|
|
||||||
_, vn := protowire.ConsumeVarint(data)
|
|
||||||
if vn < 0 {
|
|
||||||
return nil, fmt.Errorf("invalid protobuf varint")
|
|
||||||
}
|
|
||||||
data = data[vn:]
|
|
||||||
default:
|
|
||||||
return nil, fmt.Errorf("unexpected wire type %d", wtype)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return nil, fmt.Errorf("field %d not found", fieldNum)
|
|
||||||
}
|
|
||||||
|
|
||||||
// proxyCached forwards a request with metadata caching.
|
|
||||||
func (h *HexHandler) proxyCached(w http.ResponseWriter, r *http.Request) {
|
|
||||||
cacheKey := strings.TrimPrefix(r.URL.Path, "/")
|
|
||||||
h.proxy.ProxyCached(w, r, h.upstreamURL+r.URL.Path, "hex", cacheKey, "*/*")
|
|
||||||
}
|
|
||||||
|
|
||||||
// proxyUpstream forwards a request to hex.pm without caching.
|
|
||||||
func (h *HexHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
|
||||||
h.proxy.ProxyUpstream(w, r, h.upstreamURL+r.URL.Path, []string{"Accept"})
|
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -1,18 +1,8 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
|
||||||
"compress/gzip"
|
|
||||||
"encoding/json"
|
|
||||||
"io"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/cooldown"
|
|
||||||
"google.golang.org/protobuf/encoding/protowire"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestHexParseTarballFilename(t *testing.T) {
|
func TestHexParseTarballFilename(t *testing.T) {
|
||||||
|
|
@ -37,290 +27,3 @@ func TestHexParseTarballFilename(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// buildHexRelease encodes a Release protobuf message.
|
|
||||||
func buildHexRelease(version string) []byte {
|
|
||||||
var release []byte
|
|
||||||
// field 1 = version (string)
|
|
||||||
release = protowire.AppendTag(release, 1, protowire.BytesType)
|
|
||||||
release = protowire.AppendString(release, version)
|
|
||||||
// field 2 = inner_checksum (bytes) - required
|
|
||||||
release = protowire.AppendTag(release, 2, protowire.BytesType)
|
|
||||||
release = protowire.AppendBytes(release, []byte("fakechecksum1234567890123456789012"))
|
|
||||||
// field 5 = outer_checksum (bytes)
|
|
||||||
release = protowire.AppendTag(release, 5, protowire.BytesType)
|
|
||||||
release = protowire.AppendBytes(release, []byte("outerchecksum123456789012345678901"))
|
|
||||||
return release
|
|
||||||
}
|
|
||||||
|
|
||||||
// buildHexPackage encodes a Package protobuf message.
|
|
||||||
func buildHexPackage(name string, versions []string) []byte {
|
|
||||||
var pkg []byte
|
|
||||||
for _, v := range versions {
|
|
||||||
release := buildHexRelease(v)
|
|
||||||
pkg = protowire.AppendTag(pkg, 1, protowire.BytesType)
|
|
||||||
pkg = protowire.AppendBytes(pkg, release)
|
|
||||||
}
|
|
||||||
// field 2 = name
|
|
||||||
pkg = protowire.AppendTag(pkg, 2, protowire.BytesType)
|
|
||||||
pkg = protowire.AppendString(pkg, name)
|
|
||||||
// field 3 = repository
|
|
||||||
pkg = protowire.AppendTag(pkg, 3, protowire.BytesType)
|
|
||||||
pkg = protowire.AppendString(pkg, "hexpm")
|
|
||||||
return pkg
|
|
||||||
}
|
|
||||||
|
|
||||||
// buildHexSigned wraps a payload in a Signed protobuf message and gzips it.
|
|
||||||
func buildHexSigned(payload []byte) []byte {
|
|
||||||
var signed []byte
|
|
||||||
signed = protowire.AppendTag(signed, 1, protowire.BytesType)
|
|
||||||
signed = protowire.AppendBytes(signed, payload)
|
|
||||||
// field 2 = signature (optional, add a fake one)
|
|
||||||
signed = protowire.AppendTag(signed, 2, protowire.BytesType)
|
|
||||||
signed = protowire.AppendBytes(signed, []byte("fakesignature"))
|
|
||||||
|
|
||||||
var buf bytes.Buffer
|
|
||||||
gw := gzip.NewWriter(&buf)
|
|
||||||
_, _ = gw.Write(signed)
|
|
||||||
_ = gw.Close()
|
|
||||||
return buf.Bytes()
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHexFilterPackageReleases(t *testing.T) {
|
|
||||||
pkg := buildHexPackage("phoenix", []string{testVersion100, "2.0.0", "3.0.0"})
|
|
||||||
|
|
||||||
filtered, err := filterPackageReleases(pkg, map[string]bool{"2.0.0": true})
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Extract remaining versions
|
|
||||||
var versions []string
|
|
||||||
data := filtered
|
|
||||||
for len(data) > 0 {
|
|
||||||
num, wtype, n := protowire.ConsumeTag(data)
|
|
||||||
if n < 0 {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
data = data[n:]
|
|
||||||
switch wtype {
|
|
||||||
case protowire.BytesType:
|
|
||||||
v, vn := protowire.ConsumeBytes(data)
|
|
||||||
if vn < 0 {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
if num == 1 { // release field
|
|
||||||
version := extractReleaseVersion(v)
|
|
||||||
if version != "" {
|
|
||||||
versions = append(versions, version)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
data = data[vn:]
|
|
||||||
case protowire.VarintType:
|
|
||||||
_, vn := protowire.ConsumeVarint(data)
|
|
||||||
if vn < 0 {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
data = data[vn:]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if len(versions) != 2 {
|
|
||||||
t.Fatalf("expected 2 versions, got %d: %v", len(versions), versions)
|
|
||||||
}
|
|
||||||
if versions[0] != testVersion100 || versions[1] != "3.0.0" {
|
|
||||||
t.Errorf("expected [1.0.0, 3.0.0], got %v", versions)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHexFilterSignedPackage(t *testing.T) {
|
|
||||||
pkg := buildHexPackage("phoenix", []string{testVersion100, "2.0.0"})
|
|
||||||
gzipped := buildHexSigned(pkg)
|
|
||||||
|
|
||||||
h := &HexHandler{
|
|
||||||
proxy: testProxy(),
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
filtered, err := h.filterSignedPackage(gzipped, map[string]bool{"2.0.0": true})
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Decompress and check
|
|
||||||
gr, err := gzip.NewReader(bytes.NewReader(filtered))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
signed, err := io.ReadAll(gr)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
payload, err := extractProtobufBytes(signed, 1)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Check that only version 1.0.0 remains
|
|
||||||
version := extractReleaseVersion(mustExtractFirstRelease(t, payload))
|
|
||||||
if version != testVersion100 {
|
|
||||||
t.Errorf("expected version 1.0.0, got %s", version)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Verify no signature in the output
|
|
||||||
_, err = extractProtobufBytes(signed, 2)
|
|
||||||
if err == nil {
|
|
||||||
t.Error("expected no signature in filtered output")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func mustExtractFirstRelease(t *testing.T, payload []byte) []byte {
|
|
||||||
t.Helper()
|
|
||||||
data := payload
|
|
||||||
for len(data) > 0 {
|
|
||||||
num, wtype, n := protowire.ConsumeTag(data)
|
|
||||||
if n < 0 {
|
|
||||||
t.Fatal("invalid protobuf")
|
|
||||||
}
|
|
||||||
data = data[n:]
|
|
||||||
if wtype == protowire.BytesType {
|
|
||||||
v, vn := protowire.ConsumeBytes(data)
|
|
||||||
if vn < 0 {
|
|
||||||
t.Fatal("invalid bytes")
|
|
||||||
}
|
|
||||||
if num == 1 {
|
|
||||||
return v
|
|
||||||
}
|
|
||||||
data = data[vn:]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
t.Fatal("no release found")
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHexExtractReleaseVersion(t *testing.T) {
|
|
||||||
release := buildHexRelease("1.2.3")
|
|
||||||
version := extractReleaseVersion(release)
|
|
||||||
if version != "1.2.3" {
|
|
||||||
t.Errorf("expected 1.2.3, got %s", version)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHexHandlePackagesWithCooldown(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
oldTime := now.Add(-7 * 24 * time.Hour).Format(time.RFC3339Nano)
|
|
||||||
recentTime := now.Add(-1 * time.Hour).Format(time.RFC3339Nano)
|
|
||||||
|
|
||||||
pkg := buildHexPackage("testpkg", []string{testVersion100, "2.0.0"})
|
|
||||||
gzippedProto := buildHexSigned(pkg)
|
|
||||||
|
|
||||||
apiJSON, _ := json.Marshal(hexPackageAPI{
|
|
||||||
Releases: []hexRelease{
|
|
||||||
{Version: testVersion100, InsertedAt: oldTime},
|
|
||||||
{Version: "2.0.0", InsertedAt: recentTime},
|
|
||||||
},
|
|
||||||
})
|
|
||||||
|
|
||||||
// Serve both the protobuf repo and the JSON API from the same test server
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
switch r.URL.Path {
|
|
||||||
case "/packages/testpkg":
|
|
||||||
w.Header().Set("Content-Encoding", "gzip")
|
|
||||||
_, _ = w.Write(gzippedProto)
|
|
||||||
case "/api/packages/testpkg":
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
_, _ = w.Write(apiJSON)
|
|
||||||
default:
|
|
||||||
w.WriteHeader(http.StatusNotFound)
|
|
||||||
}
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{
|
|
||||||
Default: "3d",
|
|
||||||
}
|
|
||||||
|
|
||||||
// Override hexAPIURL for testing by using the upstream URL
|
|
||||||
h := &HexHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
// We need to override the API URL - but it's a const. Let's test via the lower-level methods instead.
|
|
||||||
// Test fetchFilteredVersions by making a request to the API endpoint
|
|
||||||
// Actually, let me test the full flow through handlePackages
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/packages/testpkg", nil)
|
|
||||||
req.SetPathValue("name", "testpkg")
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
|
|
||||||
// Since hexAPIURL is a const pointing to hex.pm, we can't easily override it in tests.
|
|
||||||
// Instead test the protobuf filtering directly which is the core logic.
|
|
||||||
filtered, err := h.filterSignedPackage(gzippedProto, map[string]bool{"2.0.0": true})
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Verify only version 1.0.0 survives
|
|
||||||
gr, _ := gzip.NewReader(bytes.NewReader(filtered))
|
|
||||||
signed, _ := io.ReadAll(gr)
|
|
||||||
payload, _ := extractProtobufBytes(signed, 1)
|
|
||||||
|
|
||||||
var versions []string
|
|
||||||
data := payload
|
|
||||||
for len(data) > 0 {
|
|
||||||
num, wtype, n := protowire.ConsumeTag(data)
|
|
||||||
if n < 0 {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
data = data[n:]
|
|
||||||
if wtype == protowire.BytesType {
|
|
||||||
v, vn := protowire.ConsumeBytes(data)
|
|
||||||
if vn < 0 {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
if num == 1 {
|
|
||||||
if ver := extractReleaseVersion(v); ver != "" {
|
|
||||||
versions = append(versions, ver)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
data = data[vn:]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if len(versions) != 1 || versions[0] != testVersion100 {
|
|
||||||
t.Errorf("expected [1.0.0], got %v", versions)
|
|
||||||
}
|
|
||||||
|
|
||||||
_ = w
|
|
||||||
_ = req
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHexHandlePackagesWithoutCooldown(t *testing.T) {
|
|
||||||
pkg := buildHexPackage("testpkg", []string{testVersion100})
|
|
||||||
gzipped := buildHexSigned(pkg)
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.Header().Set("Content-Encoding", "gzip")
|
|
||||||
_, _ = w.Write(gzipped)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
h := &HexHandler{
|
|
||||||
proxy: testProxy(), // no cooldown
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/packages/testpkg", nil)
|
|
||||||
req.SetPathValue("name", "testpkg")
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handlePackages(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
|
||||||
|
|
@ -1,74 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/sha256"
|
|
||||||
"encoding/hex"
|
|
||||||
"net/http"
|
|
||||||
"strings"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
homebrewArtifactNamespace = "homebrew"
|
|
||||||
homebrewArtifactRepository = "homebrew/core"
|
|
||||||
homebrewMetadataEcosystem = "homebrew"
|
|
||||||
)
|
|
||||||
|
|
||||||
// HomebrewHandler proxies Homebrew's JSON API without modifying signed files.
|
|
||||||
type HomebrewHandler struct {
|
|
||||||
proxy *Proxy
|
|
||||||
apiUpstream string
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewHomebrewHandler creates a Homebrew JSON API handler.
|
|
||||||
func NewHomebrewHandler(proxy *Proxy, apiUpstream string) *HomebrewHandler {
|
|
||||||
return &HomebrewHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
apiUpstream: strings.TrimSuffix(apiUpstream, "/"),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// RegisterHomebrewArtifacts routes homebrew/core OCI requests to its configured
|
|
||||||
// registry and blocks other homebrew repositories from reaching the default
|
|
||||||
// OCI registry.
|
|
||||||
func RegisterHomebrewArtifacts(container *ContainerHandler, artifactUpstream string) {
|
|
||||||
container.BlockRegistry(homebrewArtifactNamespace)
|
|
||||||
container.RegisterRegistry(homebrewArtifactRepository, artifactUpstream)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the Homebrew JSON API handler. Mount this at /homebrew.
|
|
||||||
func (h *HomebrewHandler) Routes() http.Handler {
|
|
||||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if r.Method != http.MethodGet && r.Method != http.MethodHead {
|
|
||||||
w.Header().Set("Allow", "GET, HEAD")
|
|
||||||
http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
requestPath := strings.TrimPrefix(r.URL.EscapedPath(), "/")
|
|
||||||
if requestPath == "" || containsPathTraversal(requestPath) {
|
|
||||||
http.NotFound(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
upstreamURL := h.apiUpstream + "/" + requestPath
|
|
||||||
if r.URL.RawQuery != "" {
|
|
||||||
upstreamURL += "?" + r.URL.RawQuery
|
|
||||||
}
|
|
||||||
|
|
||||||
// brew fetches every JSON API download with `curl --compressed` and
|
|
||||||
// decodes Content-Encoding itself, and formula.jws.json is ~33 MB plain
|
|
||||||
// versus ~5 MB gzip, so keep both hops compressed. The analytics
|
|
||||||
// endpoints are the one consumer brew fetches without --compressed;
|
|
||||||
// they stay identity.
|
|
||||||
acceptEncoding := "gzip"
|
|
||||||
if strings.HasPrefix(requestPath, "analytics/") {
|
|
||||||
acceptEncoding = "identity"
|
|
||||||
}
|
|
||||||
h.proxy.proxyCachedWithEncoding(w, r, upstreamURL, homebrewMetadataEcosystem, homebrewMetadataCacheKey(requestPath, r.URL.RawQuery), acceptEncoding, "*/*")
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func homebrewMetadataCacheKey(requestPath, rawQuery string) string {
|
|
||||||
sum := sha256.Sum256([]byte(requestPath + "\x00" + rawQuery))
|
|
||||||
return hex.EncodeToString(sum[:])
|
|
||||||
}
|
|
||||||
|
|
@ -1,458 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bytes"
|
|
||||||
"io"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"strconv"
|
|
||||||
"strings"
|
|
||||||
"sync/atomic"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestHomebrewHandler_PreservesSignedResponseAndClientValidators(t *testing.T) {
|
|
||||||
body := " {\n \"payload\": \"signed bytes\",\n \"signatures\": []\n}\n"
|
|
||||||
etag := `"homebrew-api-etag"`
|
|
||||||
lastModified := time.Date(2026, time.August, 14, 9, 30, 0, 0, time.UTC)
|
|
||||||
requests := 0
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
requests++
|
|
||||||
if r.Method != http.MethodGet {
|
|
||||||
t.Errorf("upstream method = %s, want GET", r.Method)
|
|
||||||
}
|
|
||||||
if r.URL.Path != "/api/internal/packages.arm64_tahoe.jws.json" {
|
|
||||||
t.Errorf("upstream path = %q", r.URL.Path)
|
|
||||||
}
|
|
||||||
if got := r.Header.Get("Authorization"); got != "" {
|
|
||||||
t.Errorf("upstream Authorization = %q, want empty", got)
|
|
||||||
}
|
|
||||||
if got := r.Header.Get("Cookie"); got != "" {
|
|
||||||
t.Errorf("upstream Cookie = %q, want empty", got)
|
|
||||||
}
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
w.Header().Set("ETag", etag)
|
|
||||||
w.Header().Set("Last-Modified", lastModified.Format(http.TimeFormat))
|
|
||||||
_, _ = io.WriteString(w, body)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes()
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/internal/packages.arm64_tahoe.jws.json", nil)
|
|
||||||
req.Header.Set("Authorization", "Bearer client-secret")
|
|
||||||
req.Header.Set("Cookie", "session=client-secret")
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Body.String(); got != body {
|
|
||||||
t.Errorf("body = %q, want byte-for-byte %q", got, body)
|
|
||||||
}
|
|
||||||
if got := w.Header().Get("Content-Type"); got != "application/json" {
|
|
||||||
t.Errorf("Content-Type = %q, want application/json", got)
|
|
||||||
}
|
|
||||||
wantContentLength := strconv.Itoa(len(body))
|
|
||||||
if got := w.Header().Get("Content-Length"); got != wantContentLength {
|
|
||||||
t.Errorf("Content-Length = %q, want %q", got, wantContentLength)
|
|
||||||
}
|
|
||||||
if got := w.Header().Get("ETag"); got != etag {
|
|
||||||
t.Errorf("ETag = %q, want %q", got, etag)
|
|
||||||
}
|
|
||||||
if got := w.Header().Get("Last-Modified"); got != lastModified.Format(http.TimeFormat) {
|
|
||||||
t.Errorf("Last-Modified = %q, want %q", got, lastModified.Format(http.TimeFormat))
|
|
||||||
}
|
|
||||||
|
|
||||||
conditionalRequest := httptest.NewRequest(http.MethodGet, "/internal/packages.arm64_tahoe.jws.json", nil)
|
|
||||||
conditionalRequest.Header.Set("If-None-Match", etag)
|
|
||||||
conditional := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(conditional, conditionalRequest)
|
|
||||||
if conditional.Code != http.StatusNotModified {
|
|
||||||
t.Fatalf("conditional status = %d, want %d", conditional.Code, http.StatusNotModified)
|
|
||||||
}
|
|
||||||
if got := conditional.Header().Get("ETag"); got != etag {
|
|
||||||
t.Errorf("conditional ETag = %q, want %q", got, etag)
|
|
||||||
}
|
|
||||||
if conditional.Body.Len() != 0 {
|
|
||||||
t.Errorf("conditional body length = %d, want 0", conditional.Body.Len())
|
|
||||||
}
|
|
||||||
|
|
||||||
modifiedSinceRequest := httptest.NewRequest(http.MethodGet, "/internal/packages.arm64_tahoe.jws.json", nil)
|
|
||||||
modifiedSinceRequest.Header.Set("If-Modified-Since", lastModified.Format(http.TimeFormat))
|
|
||||||
modifiedSince := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(modifiedSince, modifiedSinceRequest)
|
|
||||||
if modifiedSince.Code != http.StatusNotModified {
|
|
||||||
t.Fatalf("If-Modified-Since status = %d, want %d", modifiedSince.Code, http.StatusNotModified)
|
|
||||||
}
|
|
||||||
if got := modifiedSince.Header().Get("Last-Modified"); got != lastModified.Format(http.TimeFormat) {
|
|
||||||
t.Errorf("conditional Last-Modified = %q, want %q", got, lastModified.Format(http.TimeFormat))
|
|
||||||
}
|
|
||||||
if requests != 1 {
|
|
||||||
t.Errorf("upstream requests = %d, want 1", requests)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHomebrewHandler_HeadUsesMetadataCacheAndSurvivesOutage(t *testing.T) {
|
|
||||||
body := `{"payload":"signed bytes","signatures":[]}`
|
|
||||||
available := true
|
|
||||||
requests := 0
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
requests++
|
|
||||||
if got := r.Header.Get("Authorization"); got != "" {
|
|
||||||
t.Errorf("upstream Authorization = %q, want empty", got)
|
|
||||||
}
|
|
||||||
if !available {
|
|
||||||
http.Error(w, "unavailable", http.StatusServiceUnavailable)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
w.Header().Set("ETag", `"head-etag"`)
|
|
||||||
_, _ = io.WriteString(w, body)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes()
|
|
||||||
|
|
||||||
coldRequest := httptest.NewRequest(http.MethodHead, "/formula.jws.json", nil)
|
|
||||||
coldRequest.Header.Set("Authorization", "Bearer client-secret")
|
|
||||||
cold := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(cold, coldRequest)
|
|
||||||
if cold.Code != http.StatusOK {
|
|
||||||
t.Fatalf("cold status = %d, want %d", cold.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
if cold.Body.Len() != 0 {
|
|
||||||
t.Errorf("cold body length = %d, want 0", cold.Body.Len())
|
|
||||||
}
|
|
||||||
if got := cold.Header().Get("Content-Length"); got != strconv.Itoa(len(body)) {
|
|
||||||
t.Errorf("Content-Length = %q, want %d", got, len(body))
|
|
||||||
}
|
|
||||||
if got := cold.Header().Get("ETag"); got != `"head-etag"` {
|
|
||||||
t.Errorf("ETag = %q, want %q", got, `"head-etag"`)
|
|
||||||
}
|
|
||||||
if requests != 1 {
|
|
||||||
t.Fatalf("cold upstream requests = %d, want 1", requests)
|
|
||||||
}
|
|
||||||
|
|
||||||
warm := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(warm, httptest.NewRequest(http.MethodHead, "/formula.jws.json", nil))
|
|
||||||
if warm.Code != http.StatusOK {
|
|
||||||
t.Fatalf("warm status = %d, want %d", warm.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
if warm.Body.Len() != 0 {
|
|
||||||
t.Errorf("warm body length = %d, want 0", warm.Body.Len())
|
|
||||||
}
|
|
||||||
if requests != 1 {
|
|
||||||
t.Errorf("warm upstream requests = %d, want 1", requests)
|
|
||||||
}
|
|
||||||
|
|
||||||
proxy.MetadataTTL = time.Nanosecond
|
|
||||||
available = false
|
|
||||||
stale := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(stale, httptest.NewRequest(http.MethodHead, "/formula.jws.json", nil))
|
|
||||||
if stale.Code != http.StatusOK {
|
|
||||||
t.Fatalf("stale status = %d, want %d; body: %s", stale.Code, http.StatusOK, stale.Body.String())
|
|
||||||
}
|
|
||||||
if stale.Body.Len() != 0 {
|
|
||||||
t.Errorf("stale body length = %d, want 0", stale.Body.Len())
|
|
||||||
}
|
|
||||||
if got := stale.Header().Get("Warning"); got != containerStaleWarning {
|
|
||||||
t.Errorf("Warning = %q, want %q", got, containerStaleWarning)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHomebrewHandler_HeadWithoutMetadataCachePreservesUpstreamMethod(t *testing.T) {
|
|
||||||
upstreamMethod := ""
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
upstreamMethod = r.Method
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
w.Header().Set("Content-Length", "42")
|
|
||||||
w.Header().Set("ETag", `"head-etag"`)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = false
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes()
|
|
||||||
|
|
||||||
head := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(head, httptest.NewRequest(http.MethodHead, "/formula.jws.json", nil))
|
|
||||||
if head.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d", head.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
if upstreamMethod != http.MethodHead {
|
|
||||||
t.Errorf("upstream method = %q, want HEAD", upstreamMethod)
|
|
||||||
}
|
|
||||||
if head.Body.Len() != 0 {
|
|
||||||
t.Errorf("body length = %d, want 0", head.Body.Len())
|
|
||||||
}
|
|
||||||
if got := head.Header().Get("Content-Length"); got != "42" {
|
|
||||||
t.Errorf("Content-Length = %q, want 42", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHomebrewHandler_ServesStaleCachedResponseWhenUpstreamFails(t *testing.T) {
|
|
||||||
body := `{"payload":"signed bytes","signatures":[]}`
|
|
||||||
available := true
|
|
||||||
requests := 0
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
|
||||||
requests++
|
|
||||||
if !available {
|
|
||||||
http.Error(w, "unavailable", http.StatusServiceUnavailable)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
w.Header().Set("ETag", `"stale-etag"`)
|
|
||||||
_, _ = io.WriteString(w, body)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = 5 * time.Millisecond
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes()
|
|
||||||
|
|
||||||
first := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/formula.jws.json", nil))
|
|
||||||
if first.Code != http.StatusOK {
|
|
||||||
t.Fatalf("warm status = %d, want %d", first.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
|
|
||||||
time.Sleep(10 * time.Millisecond)
|
|
||||||
available = false
|
|
||||||
stale := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(stale, httptest.NewRequest(http.MethodGet, "/formula.jws.json", nil))
|
|
||||||
if stale.Code != http.StatusOK {
|
|
||||||
t.Fatalf("stale status = %d, want %d; body: %s", stale.Code, http.StatusOK, stale.Body.String())
|
|
||||||
}
|
|
||||||
if got := stale.Body.String(); got != body {
|
|
||||||
t.Errorf("stale body = %q, want %q", got, body)
|
|
||||||
}
|
|
||||||
if got := stale.Header().Get("Warning"); got != containerStaleWarning {
|
|
||||||
t.Errorf("Warning = %q, want %q", got, containerStaleWarning)
|
|
||||||
}
|
|
||||||
if requests != 2 {
|
|
||||||
t.Errorf("upstream requests = %d, want 2", requests)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHomebrewHandler_ProxiesSupportedAPIPaths(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
_, _ = io.WriteString(w, r.URL.RequestURI())
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes()
|
|
||||||
|
|
||||||
paths := []string{
|
|
||||||
"/formula.jws.json",
|
|
||||||
"/cask.jws.json",
|
|
||||||
"/formula/jq.json",
|
|
||||||
"/cask/firefox.json",
|
|
||||||
"/internal/packages.arm64_tahoe.jws.json?download=1",
|
|
||||||
}
|
|
||||||
for _, requestPath := range paths {
|
|
||||||
t.Run(requestPath, func(t *testing.T) {
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(w, httptest.NewRequest(http.MethodGet, requestPath, nil))
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d", w.Code, http.StatusOK)
|
|
||||||
}
|
|
||||||
if got, want := w.Body.String(), "/api"+requestPath; got != want {
|
|
||||||
t.Errorf("upstream request = %q, want %q", got, want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHomebrewHandler_RejectsUnsupportedRequests(t *testing.T) {
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
h := NewHomebrewHandler(proxy, "https://example.test/api").Routes()
|
|
||||||
|
|
||||||
method := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(method, httptest.NewRequest(http.MethodPost, "/formula.jws.json", nil))
|
|
||||||
if method.Code != http.StatusMethodNotAllowed {
|
|
||||||
t.Errorf("POST status = %d, want %d", method.Code, http.StatusMethodNotAllowed)
|
|
||||||
}
|
|
||||||
if got := method.Header().Get("Allow"); got != "GET, HEAD" {
|
|
||||||
t.Errorf("Allow = %q, want GET, HEAD", got)
|
|
||||||
}
|
|
||||||
|
|
||||||
root := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(root, httptest.NewRequest(http.MethodGet, "/", nil))
|
|
||||||
if root.Code != http.StatusNotFound {
|
|
||||||
t.Errorf("root status = %d, want %d", root.Code, http.StatusNotFound)
|
|
||||||
}
|
|
||||||
|
|
||||||
traversal := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(traversal, httptest.NewRequest(http.MethodGet, "/%2e%2e/secret", nil))
|
|
||||||
if traversal.Code != http.StatusNotFound {
|
|
||||||
t.Errorf("traversal status = %d, want %d", traversal.Code, http.StatusNotFound)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestRegisterHomebrewArtifacts(t *testing.T) {
|
|
||||||
h := &ContainerHandler{registryURL: dockerHubRegistry}
|
|
||||||
artifactUpstream := "https://homebrew-proxy.example.com"
|
|
||||||
RegisterHomebrewArtifacts(h, artifactUpstream+"/")
|
|
||||||
|
|
||||||
if got := h.registryURLFor("homebrew/core/jq"); got != artifactUpstream {
|
|
||||||
t.Errorf("homebrew/core registry = %q, want %q", got, artifactUpstream)
|
|
||||||
}
|
|
||||||
if got := h.registryURLFor("homebrew/cask/firefox"); got != "" {
|
|
||||||
t.Errorf("other Homebrew registry = %q, want blocked", got)
|
|
||||||
}
|
|
||||||
if got := h.registryURLFor("library/nginx"); got != dockerHubRegistry {
|
|
||||||
t.Errorf("unrelated registry = %q, want %q", got, dockerHubRegistry)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestRegisterHomebrewArtifactsRejectsOtherHomebrewRoutes(t *testing.T) {
|
|
||||||
upstreamRequests := 0
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
|
||||||
upstreamRequests++
|
|
||||||
_, _ = io.WriteString(w, "unexpected upstream response")
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
fetcher.artifact = &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader("unexpected upstream blob")),
|
|
||||||
ContentType: "application/octet-stream",
|
|
||||||
}
|
|
||||||
h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL}
|
|
||||||
RegisterHomebrewArtifacts(h, "https://ghcr.io")
|
|
||||||
|
|
||||||
const digest = "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
|
|
||||||
paths := []string{
|
|
||||||
"/homebrew/cask/firefox/blobs/" + digest,
|
|
||||||
"/homebrew/cask/firefox/manifests/latest",
|
|
||||||
"/homebrew/cask/firefox/tags/list",
|
|
||||||
}
|
|
||||||
for _, path := range paths {
|
|
||||||
t.Run(path, func(t *testing.T) {
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, path, nil))
|
|
||||||
if w.Code != http.StatusNotFound {
|
|
||||||
t.Errorf("status = %d, want %d; body: %s", w.Code, http.StatusNotFound, w.Body.String())
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
if fetcher.fetchCalled {
|
|
||||||
t.Error("blocked Homebrew blob reached the artifact fetcher")
|
|
||||||
}
|
|
||||||
if upstreamRequests != 0 {
|
|
||||||
t.Errorf("blocked Homebrew routes made %d upstream requests, want 0", upstreamRequests)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestHomebrewHandler_RequestsGzipForAPIPaths covers #305's motivating case:
|
|
||||||
// the JSON API files are fetched, cached and served gzip-compressed with
|
|
||||||
// Content-Encoding: gzip (brew fetches them with --compressed), while the
|
|
||||||
// analytics endpoints, which brew fetches without --compressed, stay identity.
|
|
||||||
func TestHomebrewHandler_RequestsGzipForAPIPaths(t *testing.T) {
|
|
||||||
plain := []byte(`{"payload":"signed bytes","signatures":[]}`)
|
|
||||||
compressed := gzipPayload(t, plain)
|
|
||||||
|
|
||||||
var available atomic.Bool
|
|
||||||
available.Store(true)
|
|
||||||
var requests atomic.Int32
|
|
||||||
var sawAcceptEncoding atomic.Value // string
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
requests.Add(1)
|
|
||||||
sawAcceptEncoding.Store(r.Header.Get(headerAcceptEncoding))
|
|
||||||
if !available.Load() {
|
|
||||||
http.Error(w, "unavailable", http.StatusServiceUnavailable)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
w.Header().Set(headerContentType, "application/json")
|
|
||||||
if strings.Contains(r.Header.Get(headerAcceptEncoding), "gzip") {
|
|
||||||
w.Header().Set(headerContentEncoding, "gzip")
|
|
||||||
_, _ = w.Write(compressed)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
_, _ = w.Write(plain)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
h := NewHomebrewHandler(proxy, upstream.URL+"/api").Routes()
|
|
||||||
|
|
||||||
get := func(path string) *httptest.ResponseRecorder {
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.ServeHTTP(w, httptest.NewRequest(http.MethodGet, path, nil))
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
lastAE := func() string {
|
|
||||||
s, _ := sawAcceptEncoding.Load().(string)
|
|
||||||
return s
|
|
||||||
}
|
|
||||||
|
|
||||||
first := get("/formula.jws.json")
|
|
||||||
if first.Code != http.StatusOK {
|
|
||||||
t.Fatalf("formula.jws.json: status = %d, want 200: %s", first.Code, first.Body.String())
|
|
||||||
}
|
|
||||||
if got := lastAE(); got != "gzip" {
|
|
||||||
t.Errorf("formula.jws.json: upstream Accept-Encoding = %q, want %q", got, "gzip")
|
|
||||||
}
|
|
||||||
if !bytes.Equal(first.Body.Bytes(), compressed) {
|
|
||||||
t.Errorf("formula.jws.json: body is not the compressed bytes (got %d, want %d)", first.Body.Len(), len(compressed))
|
|
||||||
}
|
|
||||||
if got := first.Header().Get(headerContentEncoding); got != "gzip" {
|
|
||||||
t.Errorf("formula.jws.json: Content-Encoding = %q, want %q", got, "gzip")
|
|
||||||
}
|
|
||||||
if got := first.Header().Get(headerContentLength); got != strconv.Itoa(len(compressed)) {
|
|
||||||
t.Errorf("formula.jws.json: Content-Length = %q, want %d", got, len(compressed))
|
|
||||||
}
|
|
||||||
|
|
||||||
// Replay from cache with the upstream down: same bytes and header, no refetch.
|
|
||||||
before := requests.Load()
|
|
||||||
available.Store(false)
|
|
||||||
cached := get("/formula.jws.json")
|
|
||||||
if cached.Code != http.StatusOK {
|
|
||||||
t.Fatalf("cached formula.jws.json: status = %d, want 200: %s", cached.Code, cached.Body.String())
|
|
||||||
}
|
|
||||||
if !bytes.Equal(cached.Body.Bytes(), compressed) || cached.Header().Get(headerContentEncoding) != "gzip" {
|
|
||||||
t.Errorf("cached formula.jws.json: body/header not replayed verbatim")
|
|
||||||
}
|
|
||||||
if requests.Load() != before {
|
|
||||||
t.Errorf("cached formula.jws.json hit upstream: requests %d -> %d", before, requests.Load())
|
|
||||||
}
|
|
||||||
available.Store(true)
|
|
||||||
|
|
||||||
// Analytics is fetched by brew without --compressed: stays identity, no header.
|
|
||||||
analytics := get("/analytics/install/30d.json")
|
|
||||||
if analytics.Code != http.StatusOK {
|
|
||||||
t.Fatalf("analytics: status = %d, want 200: %s", analytics.Code, analytics.Body.String())
|
|
||||||
}
|
|
||||||
if got := lastAE(); got != "identity" {
|
|
||||||
t.Errorf("analytics: upstream Accept-Encoding = %q, want %q", got, "identity")
|
|
||||||
}
|
|
||||||
if !bytes.Equal(analytics.Body.Bytes(), plain) {
|
|
||||||
t.Errorf("analytics: body = %q, want plain %q", analytics.Body.Bytes(), plain)
|
|
||||||
}
|
|
||||||
if got := analytics.Header().Get(headerContentEncoding); got != "" {
|
|
||||||
t.Errorf("analytics: Content-Encoding = %q, want empty", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,31 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import "testing"
|
|
||||||
|
|
||||||
func TestIfNoneMatchHits(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
header string
|
|
||||||
etag string
|
|
||||||
want bool
|
|
||||||
}{
|
|
||||||
{`"abc"`, `"abc"`, true},
|
|
||||||
{`"abc"`, `"def"`, false},
|
|
||||||
{"", `"abc"`, false},
|
|
||||||
{`"abc"`, "", false},
|
|
||||||
{"*", `"abc"`, true},
|
|
||||||
{"*", "", false},
|
|
||||||
{`W/"abc"`, `"abc"`, true},
|
|
||||||
{`"abc"`, `W/"abc"`, true},
|
|
||||||
{`W/"abc"`, `W/"abc"`, true},
|
|
||||||
{`"abc", "def"`, `"def"`, true},
|
|
||||||
{`"abc","def"`, `"def"`, true},
|
|
||||||
{` "abc" , W/"def" `, `"def"`, true},
|
|
||||||
{`"abc", "def"`, `"ghi"`, false},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
if got := ifNoneMatchHits(tt.header, tt.etag); got != tt.want {
|
|
||||||
t.Errorf("ifNoneMatchHits(%q, %q) = %v, want %v", tt.header, tt.etag, got, tt.want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,100 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"fmt"
|
|
||||||
"io"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/integrity"
|
|
||||||
)
|
|
||||||
|
|
||||||
type integrityChecks struct {
|
|
||||||
contentHash integrity.SRI
|
|
||||||
native integrity.SRI
|
|
||||||
algorithms []integrity.Algorithm
|
|
||||||
}
|
|
||||||
|
|
||||||
func newIntegrityChecks(contentHash, native string) (integrityChecks, error) {
|
|
||||||
checks := integrityChecks{}
|
|
||||||
|
|
||||||
if contentHash != "" {
|
|
||||||
digest, err := integrity.ParseHex(integrity.SHA256, contentHash)
|
|
||||||
if err != nil {
|
|
||||||
return integrityChecks{}, fmt.Errorf("parse content_hash: %w", err)
|
|
||||||
}
|
|
||||||
checks.contentHash = integrity.SRI{digest}
|
|
||||||
checks.algorithms = append(checks.algorithms, integrity.SHA256)
|
|
||||||
}
|
|
||||||
|
|
||||||
if native != "" {
|
|
||||||
digests, err := integrity.ParseSRI(native)
|
|
||||||
if err != nil {
|
|
||||||
return integrityChecks{}, fmt.Errorf("parse integrity: %w", err)
|
|
||||||
}
|
|
||||||
checks.native = digests
|
|
||||||
for _, digest := range digests {
|
|
||||||
checks.algorithms = append(checks.algorithms, digest.Algorithm())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return checks, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c integrityChecks) wrap(source io.ReadCloser, onMismatch func(string)) (io.ReadCloser, error) {
|
|
||||||
if len(c.algorithms) == 0 {
|
|
||||||
return source, nil
|
|
||||||
}
|
|
||||||
reader, err := integrity.NewReader(source, c.algorithms...)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("create integrity reader: %w", err)
|
|
||||||
}
|
|
||||||
return &verifyingReader{
|
|
||||||
source: source,
|
|
||||||
reader: reader,
|
|
||||||
checks: c,
|
|
||||||
onMismatch: onMismatch,
|
|
||||||
}, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// verifyingReader forwards Close to its source and reports completed digest
|
|
||||||
// mismatches after its shared integrity reader observes EOF.
|
|
||||||
type verifyingReader struct {
|
|
||||||
source io.ReadCloser
|
|
||||||
reader *integrity.Reader
|
|
||||||
checks integrityChecks
|
|
||||||
onMismatch func(reason string)
|
|
||||||
verified bool
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *verifyingReader) Read(p []byte) (int, error) {
|
|
||||||
n, err := r.reader.Read(p)
|
|
||||||
if err == io.EOF {
|
|
||||||
r.verify()
|
|
||||||
}
|
|
||||||
return n, err
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *verifyingReader) Close() error {
|
|
||||||
return r.source.Close()
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *verifyingReader) verify() {
|
|
||||||
if r.verified {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
r.verified = true
|
|
||||||
result := r.reader.Result()
|
|
||||||
if !result.Complete {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if len(r.checks.contentHash) > 0 {
|
|
||||||
if err := result.Verify(r.checks.contentHash); err != nil {
|
|
||||||
r.onMismatch("content_hash: " + err.Error())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if len(r.checks.native) > 0 {
|
|
||||||
if err := result.Verify(r.checks.native); err != nil {
|
|
||||||
r.onMismatch("integrity: " + err.Error())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,250 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/sha256"
|
|
||||||
"crypto/sha512"
|
|
||||||
"encoding/base64"
|
|
||||||
"encoding/hex"
|
|
||||||
"errors"
|
|
||||||
"io"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
)
|
|
||||||
|
|
||||||
func sha256Hex(data string) string {
|
|
||||||
sum := sha256.Sum256([]byte(data))
|
|
||||||
return hex.EncodeToString(sum[:])
|
|
||||||
}
|
|
||||||
|
|
||||||
func sha256SRI(data string) string {
|
|
||||||
sum := sha256.Sum256([]byte(data))
|
|
||||||
return "sha256-" + base64.StdEncoding.EncodeToString(sum[:])
|
|
||||||
}
|
|
||||||
|
|
||||||
func sha384SRI(data string) string {
|
|
||||||
sum := sha512.Sum384([]byte(data))
|
|
||||||
return "sha384-" + base64.StdEncoding.EncodeToString(sum[:])
|
|
||||||
}
|
|
||||||
|
|
||||||
func sha512SRI(data string) string {
|
|
||||||
sum := sha512.Sum512([]byte(data))
|
|
||||||
return "sha512-" + base64.StdEncoding.EncodeToString(sum[:])
|
|
||||||
}
|
|
||||||
|
|
||||||
func wrapIntegrityReader(t *testing.T, source io.ReadCloser, contentHash, native string, onMismatch func(string)) io.ReadCloser {
|
|
||||||
t.Helper()
|
|
||||||
checks, err := newIntegrityChecks(contentHash, native)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("newIntegrityChecks: %v", err)
|
|
||||||
}
|
|
||||||
reader, err := checks.wrap(source, onMismatch)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("wrap: %v", err)
|
|
||||||
}
|
|
||||||
return reader
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNewIntegrityChecksCollectsAlgorithms(t *testing.T) {
|
|
||||||
checks, err := newIntegrityChecks(
|
|
||||||
sha256Hex("hello"),
|
|
||||||
strings.Join([]string{sha256SRI("first"), sha512SRI("second"), sha384SRI("third"), sha512SRI("alternative")}, " "),
|
|
||||||
)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(checks.algorithms) != 5 {
|
|
||||||
t.Fatalf("algorithms = %v, want 5 entries", checks.algorithms)
|
|
||||||
}
|
|
||||||
if len(checks.native) != 4 {
|
|
||||||
t.Errorf("native digests = %d, want 4", len(checks.native))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNewIntegrityChecksRejectsMalformedMetadata(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
contentHash string
|
|
||||||
native string
|
|
||||||
}{
|
|
||||||
{name: "short content hash", contentHash: "abc123"},
|
|
||||||
{name: "non-hex content hash", contentHash: strings.Repeat("z", sha256.Size*2)},
|
|
||||||
{name: "missing SRI separator", native: "sha512"},
|
|
||||||
{name: "malformed SRI base64", native: "sha512-not!base64"},
|
|
||||||
{name: "wrong SRI length", native: "sha512-" + base64.StdEncoding.EncodeToString([]byte("short"))},
|
|
||||||
{name: "unsupported SRI algorithm", native: "md5-1B2M2Y8AsgTpgAmY7PhCfg=="},
|
|
||||||
{name: "invalid SRI alternative", native: sha512SRI("valid") + " sha384-nope"},
|
|
||||||
}
|
|
||||||
for _, test := range tests {
|
|
||||||
t.Run(test.name, func(t *testing.T) {
|
|
||||||
if _, err := newIntegrityChecks(test.contentHash, test.native); err == nil {
|
|
||||||
t.Fatal("newIntegrityChecks returned nil error")
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestVerifyingReader(t *testing.T) {
|
|
||||||
const data = "hello world"
|
|
||||||
goodSHA := sha256Hex(data)
|
|
||||||
goodSRI := sha512SRI(data)
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
hash string
|
|
||||||
sri string
|
|
||||||
wantCalls int
|
|
||||||
}{
|
|
||||||
{name: "both match", hash: goodSHA, sri: goodSRI},
|
|
||||||
{name: "SHA-256 only match", hash: goodSHA},
|
|
||||||
{name: "SRI only match", sri: goodSRI},
|
|
||||||
{name: "SHA-256 mismatch", hash: sha256Hex("other"), wantCalls: 1},
|
|
||||||
{name: "SRI mismatch", sri: sha512SRI("other"), wantCalls: 1},
|
|
||||||
{name: "both mismatch", hash: sha256Hex("other"), sri: sha512SRI("other"), wantCalls: 2},
|
|
||||||
{name: "no checks"},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, test := range tests {
|
|
||||||
t.Run(test.name, func(t *testing.T) {
|
|
||||||
var calls []string
|
|
||||||
reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), test.hash, test.sri,
|
|
||||||
func(reason string) { calls = append(calls, reason) })
|
|
||||||
|
|
||||||
got, err := io.ReadAll(reader)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("ReadAll: %v", err)
|
|
||||||
}
|
|
||||||
if string(got) != data {
|
|
||||||
t.Errorf("data corrupted: got %q", got)
|
|
||||||
}
|
|
||||||
if err := reader.Close(); err != nil {
|
|
||||||
t.Fatalf("Close: %v", err)
|
|
||||||
}
|
|
||||||
if len(calls) != test.wantCalls {
|
|
||||||
t.Errorf("onMismatch called %d times, want %d: %v", len(calls), test.wantCalls, calls)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestVerifyingReaderUsesStrongestNativeAlgorithm(t *testing.T) {
|
|
||||||
const data = "artifact"
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
native string
|
|
||||||
wantCalls int
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
name: "weaker match does not override stronger mismatch",
|
|
||||||
native: sha256SRI(data) + " " + sha512SRI("other"),
|
|
||||||
wantCalls: 1,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "stronger match ignores weaker mismatch",
|
|
||||||
native: sha256SRI("other") + " " + sha512SRI(data),
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "same algorithm alternative matches",
|
|
||||||
native: sha512SRI("other") + " " + sha512SRI(data),
|
|
||||||
},
|
|
||||||
}
|
|
||||||
for _, test := range tests {
|
|
||||||
t.Run(test.name, func(t *testing.T) {
|
|
||||||
var calls int
|
|
||||||
reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), "", test.native, func(string) { calls++ })
|
|
||||||
if _, err := io.Copy(io.Discard, reader); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if calls != test.wantCalls {
|
|
||||||
t.Errorf("onMismatch called %d times, want %d", calls, test.wantCalls)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestVerifyingReaderMismatchMessages(t *testing.T) {
|
|
||||||
const data = "actual"
|
|
||||||
wantHash := sha256Hex("expected")
|
|
||||||
wantSRI := sha512SRI("expected")
|
|
||||||
var reasons []string
|
|
||||||
reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), wantHash, wantSRI,
|
|
||||||
func(reason string) { reasons = append(reasons, reason) })
|
|
||||||
if _, err := io.Copy(io.Discard, reader); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(reasons) != 2 {
|
|
||||||
t.Fatalf("reasons = %v, want two", reasons)
|
|
||||||
}
|
|
||||||
wantContentReason := "content_hash: integrity mismatch: expected " + sha256SRI("expected") + ", calculated " + sha256SRI(data)
|
|
||||||
if reasons[0] != wantContentReason {
|
|
||||||
t.Errorf("content reason = %q, want %q", reasons[0], wantContentReason)
|
|
||||||
}
|
|
||||||
wantNativeReason := "integrity: integrity mismatch: expected " + wantSRI + ", calculated " + sha512SRI(data)
|
|
||||||
if reasons[1] != wantNativeReason {
|
|
||||||
t.Errorf("native reason = %q, want %q", reasons[1], wantNativeReason)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestVerifyingReaderPassthrough(t *testing.T) {
|
|
||||||
source := io.NopCloser(strings.NewReader("x"))
|
|
||||||
reader := wrapIntegrityReader(t, source, "", "", func(string) { t.Fatal("should not be called") })
|
|
||||||
if reader != source {
|
|
||||||
t.Error("expected passthrough when no hashes were provided")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
type closeTrackingReader struct {
|
|
||||||
io.Reader
|
|
||||||
closed bool
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *closeTrackingReader) Close() error {
|
|
||||||
r.closed = true
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestVerifyingReaderPartialRead(t *testing.T) {
|
|
||||||
source := &closeTrackingReader{Reader: strings.NewReader("hello world")}
|
|
||||||
var calls int
|
|
||||||
reader := wrapIntegrityReader(t, source, sha256Hex("other"), "", func(string) { calls++ })
|
|
||||||
|
|
||||||
buffer := make([]byte, 5)
|
|
||||||
_, _ = reader.Read(buffer)
|
|
||||||
_ = reader.Close()
|
|
||||||
|
|
||||||
if calls != 0 {
|
|
||||||
t.Errorf("onMismatch called %d times for partial read, want 0", calls)
|
|
||||||
}
|
|
||||||
if !source.closed {
|
|
||||||
t.Error("Close was not forwarded to the source")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestVerifyingReaderNonEOFError(t *testing.T) {
|
|
||||||
var calls int
|
|
||||||
reader := wrapIntegrityReader(t, io.NopCloser(errorFixtureReader{}), sha256Hex("data"), "", func(string) { calls++ })
|
|
||||||
if _, err := io.ReadAll(reader); !errors.Is(err, errIntegrityReadFixture) {
|
|
||||||
t.Fatalf("ReadAll error = %v", err)
|
|
||||||
}
|
|
||||||
if calls != 0 {
|
|
||||||
t.Errorf("onMismatch called %d times after non-EOF error", calls)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
var errIntegrityReadFixture = errors.New("integrity read fixture")
|
|
||||||
|
|
||||||
type errorFixtureReader struct{}
|
|
||||||
|
|
||||||
func (errorFixtureReader) Read(p []byte) (int, error) {
|
|
||||||
return copy(p, "data"), errIntegrityReadFixture
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestVerifyingReaderVerifyOnce(t *testing.T) {
|
|
||||||
var calls int
|
|
||||||
reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader("x")), sha256Hex("y"), "", func(string) { calls++ })
|
|
||||||
_, _ = io.ReadAll(reader)
|
|
||||||
_ = reader.Close()
|
|
||||||
_ = reader.Close()
|
|
||||||
if calls != 1 {
|
|
||||||
t.Errorf("onMismatch called %d times, want 1", calls)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,351 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"archive/tar"
|
|
||||||
"bufio"
|
|
||||||
"bytes"
|
|
||||||
"compress/gzip"
|
|
||||||
"context"
|
|
||||||
"fmt"
|
|
||||||
"io"
|
|
||||||
"net/http"
|
|
||||||
"regexp"
|
|
||||||
"strings"
|
|
||||||
"sync"
|
|
||||||
|
|
||||||
"github.com/BurntSushi/toml"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
juliaUpstream = "https://pkg.julialang.org"
|
|
||||||
juliaGeneralRegistryUUID = "23338594-aafe-5451-b93e-139f81909106"
|
|
||||||
juliaArtifactName = "_artifact"
|
|
||||||
juliaRegistryName = "_registry"
|
|
||||||
)
|
|
||||||
|
|
||||||
var (
|
|
||||||
juliaHexPattern = regexp.MustCompile(`^[0-9a-f]{40,64}$`)
|
|
||||||
juliaUUIDPattern = regexp.MustCompile(`^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$`)
|
|
||||||
)
|
|
||||||
|
|
||||||
// JuliaHandler handles Julia Pkg server protocol requests.
|
|
||||||
//
|
|
||||||
// See https://pkgdocs.julialang.org/v1/registries/ and the PkgServer.jl
|
|
||||||
// reference implementation. The protocol is content-addressed: registry,
|
|
||||||
// package and artifact resources are all identified by git tree hashes
|
|
||||||
// and are immutable once published.
|
|
||||||
type JuliaHandler struct {
|
|
||||||
proxy *Proxy
|
|
||||||
upstreamURL string
|
|
||||||
|
|
||||||
mu sync.RWMutex
|
|
||||||
names map[string]string
|
|
||||||
namesHash string
|
|
||||||
loadMu sync.Mutex
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewJuliaHandler creates a new Julia Pkg server handler.
|
|
||||||
func NewJuliaHandler(proxy *Proxy, _ string) *JuliaHandler {
|
|
||||||
return &JuliaHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
upstreamURL: juliaUpstream,
|
|
||||||
names: make(map[string]string),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewJuliaHandlerWithUpstream creates a Julia handler with a custom upstream.
|
|
||||||
func NewJuliaHandlerWithUpstream(proxy *Proxy, upstreamURL string) *JuliaHandler {
|
|
||||||
h := NewJuliaHandler(proxy, "")
|
|
||||||
h.upstreamURL = configuredUpstreamURL(upstreamURL, juliaUpstream)
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for Julia requests.
|
|
||||||
func (h *JuliaHandler) Routes() http.Handler {
|
|
||||||
mux := http.NewServeMux()
|
|
||||||
|
|
||||||
mux.HandleFunc("GET /registries", h.handleRegistries)
|
|
||||||
mux.HandleFunc("GET /registries.eager", h.handleRegistries)
|
|
||||||
mux.HandleFunc("GET /registries.conservative", h.handleRegistries)
|
|
||||||
mux.HandleFunc("GET /registry/{uuid}/{hash}", h.handleRegistry)
|
|
||||||
mux.HandleFunc("GET /package/{uuid}/{hash}", h.handlePackage)
|
|
||||||
mux.HandleFunc("GET /artifact/{hash}", h.handleArtifact)
|
|
||||||
mux.HandleFunc("GET /meta", h.proxyUpstream)
|
|
||||||
|
|
||||||
return mux
|
|
||||||
}
|
|
||||||
|
|
||||||
// handleRegistries serves the list of available registries. This is the only
|
|
||||||
// mutable endpoint in the protocol so it goes through the metadata cache.
|
|
||||||
func (h *JuliaHandler) handleRegistries(w http.ResponseWriter, r *http.Request) {
|
|
||||||
cacheKey := strings.TrimPrefix(r.URL.Path, "/")
|
|
||||||
h.proxy.ProxyCached(w, r, h.upstreamURL+r.URL.Path, "julia", cacheKey, "*/*")
|
|
||||||
}
|
|
||||||
|
|
||||||
// handleRegistry serves an immutable registry tarball and refreshes the
|
|
||||||
// UUID→name map from its Registry.toml.
|
|
||||||
func (h *JuliaHandler) handleRegistry(w http.ResponseWriter, r *http.Request) {
|
|
||||||
uuid := r.PathValue("uuid")
|
|
||||||
hash := r.PathValue("hash")
|
|
||||||
if !validJuliaUUID(uuid) || !juliaHexPattern.MatchString(hash) {
|
|
||||||
http.Error(w, "invalid registry reference", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
h.proxy.Logger.Info("julia registry request", "uuid", uuid, "hash", hash)
|
|
||||||
|
|
||||||
upstreamURL := h.upstreamURL + r.URL.Path
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "julia", juliaRegistryName, hash, hash+".tar.gz", upstreamURL)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch registry")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
go h.refreshNamesFromRegistry(uuid, hash)
|
|
||||||
|
|
||||||
ServeArtifact(w, result)
|
|
||||||
}
|
|
||||||
|
|
||||||
// handlePackage serves an immutable package source tarball.
|
|
||||||
func (h *JuliaHandler) handlePackage(w http.ResponseWriter, r *http.Request) {
|
|
||||||
uuid := r.PathValue("uuid")
|
|
||||||
hash := r.PathValue("hash")
|
|
||||||
if !validJuliaUUID(uuid) || !juliaHexPattern.MatchString(hash) {
|
|
||||||
http.Error(w, "invalid package reference", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := h.ensureNames(r.Context()); err != nil {
|
|
||||||
h.proxy.Logger.Warn("julia name map unavailable, using uuid", "error", err)
|
|
||||||
}
|
|
||||||
name := h.resolveName(uuid)
|
|
||||||
|
|
||||||
h.proxy.Logger.Info("julia package request", "name", name, "uuid", uuid, "hash", hash)
|
|
||||||
|
|
||||||
upstreamURL := h.upstreamURL + r.URL.Path
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "julia", name, hash, hash+".tar.gz", upstreamURL)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch package")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
ServeArtifact(w, result)
|
|
||||||
}
|
|
||||||
|
|
||||||
// handleArtifact serves an immutable binary artifact tarball. Artifacts are
|
|
||||||
// anonymous content-addressed blobs with no associated package name.
|
|
||||||
func (h *JuliaHandler) handleArtifact(w http.ResponseWriter, r *http.Request) {
|
|
||||||
hash := r.PathValue("hash")
|
|
||||||
if !juliaHexPattern.MatchString(hash) {
|
|
||||||
http.Error(w, "invalid artifact hash", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
h.proxy.Logger.Info("julia artifact request", "hash", hash)
|
|
||||||
|
|
||||||
upstreamURL := h.upstreamURL + r.URL.Path
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "julia", juliaArtifactName, hash, hash+".tar.gz", upstreamURL)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch artifact")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
ServeArtifact(w, result)
|
|
||||||
}
|
|
||||||
|
|
||||||
// proxyUpstream forwards a request to the upstream Pkg server without caching.
|
|
||||||
func (h *JuliaHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
|
||||||
h.proxy.ProxyUpstream(w, r, h.upstreamURL+r.URL.Path, nil)
|
|
||||||
}
|
|
||||||
|
|
||||||
// resolveName returns the human-readable package name for a UUID, falling
|
|
||||||
// back to the UUID itself if it is not present in the loaded registry.
|
|
||||||
func (h *JuliaHandler) resolveName(uuid string) string {
|
|
||||||
h.mu.RLock()
|
|
||||||
defer h.mu.RUnlock()
|
|
||||||
if name, ok := h.names[uuid]; ok {
|
|
||||||
return name
|
|
||||||
}
|
|
||||||
return uuid
|
|
||||||
}
|
|
||||||
|
|
||||||
// ensureNames lazily populates the UUID→name map from the General registry.
|
|
||||||
// Returns immediately if the map is already populated; otherwise blocks until
|
|
||||||
// a single in-flight load completes. Failed loads are retried on the next call.
|
|
||||||
func (h *JuliaHandler) ensureNames(ctx context.Context) error {
|
|
||||||
if h.namesLoaded() {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
h.loadMu.Lock()
|
|
||||||
defer h.loadMu.Unlock()
|
|
||||||
|
|
||||||
if h.namesLoaded() {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
return h.loadNamesFromUpstream(ctx)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (h *JuliaHandler) namesLoaded() bool {
|
|
||||||
h.mu.RLock()
|
|
||||||
defer h.mu.RUnlock()
|
|
||||||
return len(h.names) > 0
|
|
||||||
}
|
|
||||||
|
|
||||||
// loadNamesFromUpstream fetches the current /registries listing, downloads the
|
|
||||||
// General registry tarball at its current hash, and parses Registry.toml.
|
|
||||||
func (h *JuliaHandler) loadNamesFromUpstream(ctx context.Context) error {
|
|
||||||
hash, err := h.fetchGeneralRegistryHash(ctx)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
return h.loadRegistryTarball(ctx, juliaGeneralRegistryUUID, hash)
|
|
||||||
}
|
|
||||||
|
|
||||||
// fetchGeneralRegistryHash reads /registries and returns the current tree hash
|
|
||||||
// for the General registry.
|
|
||||||
func (h *JuliaHandler) fetchGeneralRegistryHash(ctx context.Context) (string, error) {
|
|
||||||
req, err := http.NewRequestWithContext(ctx, http.MethodGet, h.upstreamURL+"/registries", nil)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
|
||||||
return "", fmt.Errorf("upstream /registries returned %d", resp.StatusCode)
|
|
||||||
}
|
|
||||||
|
|
||||||
scanner := bufio.NewScanner(resp.Body)
|
|
||||||
for scanner.Scan() {
|
|
||||||
uuid, hash, ok := parseRegistryLine(scanner.Text())
|
|
||||||
if ok && uuid == juliaGeneralRegistryUUID {
|
|
||||||
return hash, nil
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if err := scanner.Err(); err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
return "", fmt.Errorf("general registry not listed in /registries")
|
|
||||||
}
|
|
||||||
|
|
||||||
// refreshNamesFromRegistry reloads the UUID→name map from a registry tarball
|
|
||||||
// that has just been cached. Errors are logged but do not affect the response.
|
|
||||||
func (h *JuliaHandler) refreshNamesFromRegistry(uuid, hash string) {
|
|
||||||
if uuid != juliaGeneralRegistryUUID {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.mu.RLock()
|
|
||||||
current := h.namesHash
|
|
||||||
h.mu.RUnlock()
|
|
||||||
if current == hash {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if err := h.loadRegistryTarball(context.Background(), uuid, hash); err != nil {
|
|
||||||
h.proxy.Logger.Warn("failed to refresh julia name map", "error", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// loadRegistryTarball downloads a registry tarball and replaces the name map
|
|
||||||
// with the contents of its Registry.toml.
|
|
||||||
func (h *JuliaHandler) loadRegistryTarball(ctx context.Context, uuid, hash string) error {
|
|
||||||
url := fmt.Sprintf("%s/registry/%s/%s", h.upstreamURL, uuid, hash)
|
|
||||||
req, err := http.NewRequestWithContext(ctx, http.MethodGet, url, nil)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
|
||||||
return fmt.Errorf("upstream registry returned %d", resp.StatusCode)
|
|
||||||
}
|
|
||||||
|
|
||||||
names, err := extractRegistryNames(resp.Body)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
h.mu.Lock()
|
|
||||||
h.names = names
|
|
||||||
h.namesHash = hash
|
|
||||||
h.mu.Unlock()
|
|
||||||
|
|
||||||
h.proxy.Logger.Info("loaded julia registry name map", "packages", len(names), "hash", hash)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// extractRegistryNames reads a gzipped registry tarball, finds Registry.toml
|
|
||||||
// at the root, and returns its [packages] table as a UUID→name map.
|
|
||||||
func extractRegistryNames(r io.Reader) (map[string]string, error) {
|
|
||||||
gz, err := gzip.NewReader(r)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("opening gzip stream: %w", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = gz.Close() }()
|
|
||||||
|
|
||||||
tr := tar.NewReader(gz)
|
|
||||||
for {
|
|
||||||
hdr, err := tr.Next()
|
|
||||||
if err == io.EOF {
|
|
||||||
return nil, fmt.Errorf("no Registry.toml in tarball")
|
|
||||||
}
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
if strings.TrimPrefix(hdr.Name, "./") != "Registry.toml" {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
data, err := io.ReadAll(tr)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
return parseRegistryToml(data)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
type juliaRegistryFile struct {
|
|
||||||
Packages map[string]struct {
|
|
||||||
Name string `toml:"name"`
|
|
||||||
} `toml:"packages"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// parseRegistryToml decodes the [packages] table of a Registry.toml file.
|
|
||||||
func parseRegistryToml(data []byte) (map[string]string, error) {
|
|
||||||
var reg juliaRegistryFile
|
|
||||||
if _, err := toml.NewDecoder(bytes.NewReader(data)).Decode(®); err != nil {
|
|
||||||
return nil, fmt.Errorf("parsing Registry.toml: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
names := make(map[string]string, len(reg.Packages))
|
|
||||||
for uuid, pkg := range reg.Packages {
|
|
||||||
if pkg.Name != "" {
|
|
||||||
names[uuid] = pkg.Name
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return names, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// parseRegistryLine parses a single line from /registries of the form
|
|
||||||
// "/registry/{uuid}/{hash}" and returns the uuid and hash.
|
|
||||||
func parseRegistryLine(line string) (uuid, hash string, ok bool) {
|
|
||||||
line = strings.TrimSpace(line)
|
|
||||||
line = strings.TrimPrefix(line, "/registry/")
|
|
||||||
uuid, hash, found := strings.Cut(line, "/")
|
|
||||||
if !found || !validJuliaUUID(uuid) || !juliaHexPattern.MatchString(hash) {
|
|
||||||
return "", "", false
|
|
||||||
}
|
|
||||||
return uuid, hash, true
|
|
||||||
}
|
|
||||||
|
|
||||||
// validJuliaUUID reports whether s looks like a lowercase RFC 4122 UUID.
|
|
||||||
func validJuliaUUID(s string) bool {
|
|
||||||
return juliaUUIDPattern.MatchString(s)
|
|
||||||
}
|
|
||||||
|
|
@ -1,167 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"archive/tar"
|
|
||||||
"bytes"
|
|
||||||
"compress/gzip"
|
|
||||||
"log/slog"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"testing"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestJuliaParseRegistryLine(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
line string
|
|
||||||
wantUUID string
|
|
||||||
wantHash string
|
|
||||||
wantOK bool
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
"/registry/23338594-aafe-5451-b93e-139f81909106/342327538ed6c1ec54c69fa145e7b6bf5934201e",
|
|
||||||
"23338594-aafe-5451-b93e-139f81909106",
|
|
||||||
"342327538ed6c1ec54c69fa145e7b6bf5934201e",
|
|
||||||
true,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
" /registry/23338594-aafe-5451-b93e-139f81909106/342327538ed6c1ec54c69fa145e7b6bf5934201e\n",
|
|
||||||
"23338594-aafe-5451-b93e-139f81909106",
|
|
||||||
"342327538ed6c1ec54c69fa145e7b6bf5934201e",
|
|
||||||
true,
|
|
||||||
},
|
|
||||||
{"/registry/not-a-uuid/0000", "", "", false},
|
|
||||||
{"junk", "", "", false},
|
|
||||||
{"", "", "", false},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
uuid, hash, ok := parseRegistryLine(tt.line)
|
|
||||||
if uuid != tt.wantUUID || hash != tt.wantHash || ok != tt.wantOK {
|
|
||||||
t.Errorf("parseRegistryLine(%q) = (%q, %q, %v), want (%q, %q, %v)",
|
|
||||||
tt.line, uuid, hash, ok, tt.wantUUID, tt.wantHash, tt.wantOK)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestJuliaValidUUID(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
s string
|
|
||||||
want bool
|
|
||||||
}{
|
|
||||||
{"23338594-aafe-5451-b93e-139f81909106", true},
|
|
||||||
{"295af30f-e4ad-537b-8983-00126c2a3abe", true},
|
|
||||||
{"23338594-AAFE-5451-b93e-139f81909106", false},
|
|
||||||
{"23338594aafe5451b93e139f81909106", false},
|
|
||||||
{"23338594-aafe-5451-b93e-139f8190910", false},
|
|
||||||
{"23338594-aafe-5451-b93e-139f81909106-", false},
|
|
||||||
{"23338594-gafe-5451-b93e-139f81909106", false},
|
|
||||||
{"", false},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
if got := validJuliaUUID(tt.s); got != tt.want {
|
|
||||||
t.Errorf("validJuliaUUID(%q) = %v, want %v", tt.s, got, tt.want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestJuliaParseRegistryToml(t *testing.T) {
|
|
||||||
data := []byte(`name = "General"
|
|
||||||
uuid = "23338594-aafe-5451-b93e-139f81909106"
|
|
||||||
|
|
||||||
[packages]
|
|
||||||
295af30f-e4ad-537b-8983-00126c2a3abe = { name = "Revise", path = "R/Revise" }
|
|
||||||
91a5bcdd-55d7-5caf-9e0b-520d859cae80 = { name = "Plots", path = "P/Plots" }
|
|
||||||
`)
|
|
||||||
|
|
||||||
names, err := parseRegistryToml(data)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("parseRegistryToml: %v", err)
|
|
||||||
}
|
|
||||||
if got := names["295af30f-e4ad-537b-8983-00126c2a3abe"]; got != "Revise" {
|
|
||||||
t.Errorf("names[Revise uuid] = %q, want Revise", got)
|
|
||||||
}
|
|
||||||
if got := names["91a5bcdd-55d7-5caf-9e0b-520d859cae80"]; got != "Plots" {
|
|
||||||
t.Errorf("names[Plots uuid] = %q, want Plots", got)
|
|
||||||
}
|
|
||||||
if len(names) != 2 {
|
|
||||||
t.Errorf("len(names) = %d, want 2", len(names))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestJuliaExtractRegistryNames(t *testing.T) {
|
|
||||||
registryToml := `name = "General"
|
|
||||||
[packages]
|
|
||||||
295af30f-e4ad-537b-8983-00126c2a3abe = { name = "Revise", path = "R/Revise" }
|
|
||||||
`
|
|
||||||
var buf bytes.Buffer
|
|
||||||
gw := gzip.NewWriter(&buf)
|
|
||||||
tw := tar.NewWriter(gw)
|
|
||||||
|
|
||||||
for _, f := range []struct{ name, body string }{
|
|
||||||
{"R/Revise/Package.toml", "name = \"Revise\"\n"},
|
|
||||||
{"Registry.toml", registryToml},
|
|
||||||
} {
|
|
||||||
if err := tw.WriteHeader(&tar.Header{Name: f.name, Mode: 0o644, Size: int64(len(f.body))}); err != nil {
|
|
||||||
t.Fatalf("WriteHeader: %v", err)
|
|
||||||
}
|
|
||||||
if _, err := tw.Write([]byte(f.body)); err != nil {
|
|
||||||
t.Fatalf("Write: %v", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if err := tw.Close(); err != nil {
|
|
||||||
t.Fatalf("tar Close: %v", err)
|
|
||||||
}
|
|
||||||
if err := gw.Close(); err != nil {
|
|
||||||
t.Fatalf("gzip Close: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
names, err := extractRegistryNames(bytes.NewReader(buf.Bytes()))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("extractRegistryNames: %v", err)
|
|
||||||
}
|
|
||||||
if got := names["295af30f-e4ad-537b-8983-00126c2a3abe"]; got != "Revise" {
|
|
||||||
t.Errorf("names[Revise uuid] = %q, want Revise", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestJuliaResolveName(t *testing.T) {
|
|
||||||
h := &JuliaHandler{
|
|
||||||
proxy: &Proxy{Logger: slog.Default()},
|
|
||||||
names: map[string]string{
|
|
||||||
"295af30f-e4ad-537b-8983-00126c2a3abe": "Revise",
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
if got := h.resolveName("295af30f-e4ad-537b-8983-00126c2a3abe"); got != "Revise" {
|
|
||||||
t.Errorf("resolveName(known) = %q, want Revise", got)
|
|
||||||
}
|
|
||||||
if got := h.resolveName("00000000-0000-0000-0000-000000000000"); got != "00000000-0000-0000-0000-000000000000" {
|
|
||||||
t.Errorf("resolveName(unknown) = %q, want uuid fallback", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestJuliaRoutesValidation(t *testing.T) {
|
|
||||||
h := NewJuliaHandler(&Proxy{Logger: slog.Default()}, "")
|
|
||||||
routes := h.Routes()
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
path string
|
|
||||||
want int
|
|
||||||
}{
|
|
||||||
{"/package/not-a-uuid/342327538ed6c1ec54c69fa145e7b6bf5934201e", http.StatusBadRequest},
|
|
||||||
{"/package/295af30f-e4ad-537b-8983-00126c2a3abe/short", http.StatusBadRequest},
|
|
||||||
{"/registry/295af30f-e4ad-537b-8983-00126c2a3abe/zzzz", http.StatusBadRequest},
|
|
||||||
{"/artifact/nothex", http.StatusBadRequest},
|
|
||||||
{"/nope", http.StatusNotFound},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
req := httptest.NewRequest(http.MethodGet, tt.path, nil)
|
|
||||||
rr := httptest.NewRecorder()
|
|
||||||
routes.ServeHTTP(rr, req)
|
|
||||||
if rr.Code != tt.want {
|
|
||||||
t.Errorf("GET %s = %d, want %d", tt.path, rr.Code, tt.want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,41 +1,30 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"errors"
|
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"path"
|
"path"
|
||||||
"strings"
|
"strings"
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
mavenCentralUpstream = "https://repo1.maven.org/maven2"
|
mavenUpstream = "https://repo1.maven.org/maven2"
|
||||||
gradlePluginPortalUpstream = "https://plugins.gradle.org/m2"
|
|
||||||
minMavenParts = 4 // group path segments + artifact + version + filename
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// MavenHandler handles Maven repository protocol requests.
|
// MavenHandler handles Maven repository protocol requests.
|
||||||
type MavenHandler struct {
|
type MavenHandler struct {
|
||||||
proxy *Proxy
|
proxy *Proxy
|
||||||
upstreamURL string
|
upstreamURL string
|
||||||
pluginPortalUpstreamURL string
|
proxyURL string
|
||||||
proxyURL string
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewMavenHandler creates a new Maven repository handler.
|
// NewMavenHandler creates a new Maven repository handler.
|
||||||
func NewMavenHandler(proxy *Proxy, proxyURL, upstreamURL, pluginPortalUpstreamURL string) *MavenHandler {
|
func NewMavenHandler(proxy *Proxy, proxyURL string) *MavenHandler {
|
||||||
if strings.TrimSpace(upstreamURL) == "" {
|
|
||||||
upstreamURL = mavenCentralUpstream
|
|
||||||
}
|
|
||||||
if strings.TrimSpace(pluginPortalUpstreamURL) == "" {
|
|
||||||
pluginPortalUpstreamURL = gradlePluginPortalUpstream
|
|
||||||
}
|
|
||||||
|
|
||||||
return &MavenHandler{
|
return &MavenHandler{
|
||||||
proxy: proxy,
|
proxy: proxy,
|
||||||
upstreamURL: strings.TrimSuffix(upstreamURL, "/"),
|
upstreamURL: mavenUpstream,
|
||||||
pluginPortalUpstreamURL: strings.TrimSuffix(pluginPortalUpstreamURL, "/"),
|
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
||||||
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -62,7 +51,8 @@ func (h *MavenHandler) handleRequest(w http.ResponseWriter, r *http.Request) {
|
||||||
filename := path.Base(urlPath)
|
filename := path.Base(urlPath)
|
||||||
|
|
||||||
if h.isMetadataFile(filename) {
|
if h.isMetadataFile(filename) {
|
||||||
h.handleMetadata(w, r, urlPath)
|
// Proxy metadata without caching
|
||||||
|
h.proxyUpstream(w, r)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -76,32 +66,6 @@ func (h *MavenHandler) handleRequest(w http.ResponseWriter, r *http.Request) {
|
||||||
h.proxyUpstream(w, r)
|
h.proxyUpstream(w, r)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (h *MavenHandler) handleMetadata(w http.ResponseWriter, r *http.Request, urlPath string) {
|
|
||||||
cacheKey := strings.ReplaceAll(urlPath, "/", "_")
|
|
||||||
upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, urlPath)
|
|
||||||
|
|
||||||
body, contentType, err := h.proxy.FetchOrCacheMetadata(r.Context(), "maven", cacheKey, upstreamURL, "*/*")
|
|
||||||
if err != nil {
|
|
||||||
if errors.Is(err, ErrUpstreamNotFound) {
|
|
||||||
pluginPortalURL := fmt.Sprintf("%s/%s", h.pluginPortalUpstreamURL, urlPath)
|
|
||||||
h.proxy.Logger.Info("maven metadata unavailable in primary upstream, trying Gradle Plugin Portal",
|
|
||||||
"path", urlPath)
|
|
||||||
body, contentType, err = h.proxy.FetchOrCacheMetadata(r.Context(), "maven", cacheKey, pluginPortalURL, "*/*")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if err != nil {
|
|
||||||
if errors.Is(err, ErrUpstreamNotFound) {
|
|
||||||
http.Error(w, "not found", http.StatusNotFound)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Error("metadata fetch failed", "error", err)
|
|
||||||
http.Error(w, "failed to fetch from upstream", http.StatusBadGateway)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
h.proxy.writeMetadataCachedResponse(w, r, "maven", cacheKey, body, contentType)
|
|
||||||
}
|
|
||||||
|
|
||||||
// handleDownload serves an artifact file, fetching and caching from upstream if needed.
|
// handleDownload serves an artifact file, fetching and caching from upstream if needed.
|
||||||
func (h *MavenHandler) handleDownload(w http.ResponseWriter, r *http.Request, urlPath string) {
|
func (h *MavenHandler) handleDownload(w http.ResponseWriter, r *http.Request, urlPath string) {
|
||||||
// Parse Maven path: group/artifact/version/filename
|
// Parse Maven path: group/artifact/version/filename
|
||||||
|
|
@ -122,15 +86,8 @@ func (h *MavenHandler) handleDownload(w http.ResponseWriter, r *http.Request, ur
|
||||||
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "maven", name, version, filename, upstreamURL)
|
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "maven", name, version, filename, upstreamURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if errors.Is(err, ErrUpstreamNotFound) {
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
pluginPortalURL := fmt.Sprintf("%s/%s", h.pluginPortalUpstreamURL, urlPath)
|
http.Error(w, "failed to fetch artifact", http.StatusBadGateway)
|
||||||
h.proxy.Logger.Info("maven artifact not found in primary upstream, trying Gradle Plugin Portal",
|
|
||||||
"group", group, "artifact", artifact, "version", version, "filename", filename)
|
|
||||||
result, err = h.proxy.GetOrFetchArtifactFromURL(r.Context(), "maven", name, version, filename, pluginPortalURL)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch artifact")
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -142,7 +99,7 @@ func (h *MavenHandler) handleDownload(w http.ResponseWriter, r *http.Request, ur
|
||||||
// -> ("com.google.guava", "guava", "32.1.3-jre", "guava-32.1.3-jre.jar")
|
// -> ("com.google.guava", "guava", "32.1.3-jre", "guava-32.1.3-jre.jar")
|
||||||
func (h *MavenHandler) parsePath(urlPath string) (group, artifact, version, filename string) {
|
func (h *MavenHandler) parsePath(urlPath string) (group, artifact, version, filename string) {
|
||||||
parts := strings.Split(urlPath, "/")
|
parts := strings.Split(urlPath, "/")
|
||||||
if len(parts) < minMavenParts {
|
if len(parts) < 4 {
|
||||||
return "", "", "", ""
|
return "", "", "", ""
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -158,7 +115,7 @@ func (h *MavenHandler) parsePath(urlPath string) (group, artifact, version, file
|
||||||
// isArtifactFile returns true if the filename looks like a Maven artifact.
|
// isArtifactFile returns true if the filename looks like a Maven artifact.
|
||||||
func (h *MavenHandler) isArtifactFile(filename string) bool {
|
func (h *MavenHandler) isArtifactFile(filename string) bool {
|
||||||
// Common artifact extensions
|
// Common artifact extensions
|
||||||
extensions := []string{".jar", ".war", ".ear", ".pom", ".aar", ".klib", ".module"}
|
extensions := []string{".jar", ".war", ".ear", ".pom", ".aar", ".klib"}
|
||||||
for _, ext := range extensions {
|
for _, ext := range extensions {
|
||||||
if strings.HasSuffix(filename, ext) {
|
if strings.HasSuffix(filename, ext) {
|
||||||
return true
|
return true
|
||||||
|
|
@ -179,5 +136,30 @@ func (h *MavenHandler) isMetadataFile(filename string) bool {
|
||||||
|
|
||||||
// proxyUpstream forwards a request to Maven Central without caching.
|
// proxyUpstream forwards a request to Maven Central without caching.
|
||||||
func (h *MavenHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
func (h *MavenHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
||||||
h.proxy.ProxyUpstream(w, r, h.upstreamURL+r.URL.Path, nil)
|
upstreamURL := h.upstreamURL + r.URL.Path
|
||||||
|
|
||||||
|
h.proxy.Logger.Debug("proxying to upstream", "url", upstreamURL)
|
||||||
|
|
||||||
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, "failed to create request", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Error("upstream request failed", "error", err)
|
||||||
|
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
for k, vv := range resp.Header {
|
||||||
|
for _, v := range vv {
|
||||||
|
w.Header().Add(k, v)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -52,7 +52,6 @@ func TestMavenIsArtifactFile(t *testing.T) {
|
||||||
}{
|
}{
|
||||||
{"guava-32.1.3-jre.jar", true},
|
{"guava-32.1.3-jre.jar", true},
|
||||||
{"guava-32.1.3-jre.pom", true},
|
{"guava-32.1.3-jre.pom", true},
|
||||||
{"guava-32.1.3-jre.module", true},
|
|
||||||
{"app-1.0.war", true},
|
{"app-1.0.war", true},
|
||||||
{"lib-1.0.aar", true},
|
{"lib-1.0.aar", true},
|
||||||
{"maven-metadata.xml", false},
|
{"maven-metadata.xml", false},
|
||||||
|
|
@ -66,63 +65,3 @@ func TestMavenIsArtifactFile(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestMavenIsMetadataFile(t *testing.T) {
|
|
||||||
h := &MavenHandler{}
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
filename string
|
|
||||||
want bool
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
name: "pom is artifact, not metadata",
|
|
||||||
filename: "com.diffplug.spotless.gradle.plugin-8.4.0.pom",
|
|
||||||
want: false,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "pom checksum is metadata",
|
|
||||||
filename: "com.diffplug.spotless.gradle.plugin-8.4.0.pom.sha1",
|
|
||||||
want: true,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "metadata file",
|
|
||||||
filename: "maven-metadata.xml",
|
|
||||||
want: true,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "metadata checksum",
|
|
||||||
filename: "maven-metadata.xml.sha256",
|
|
||||||
want: true,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "jar checksum is metadata",
|
|
||||||
filename: "guava-32.1.3-jre.jar.sha1",
|
|
||||||
want: true,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "asc signature is metadata",
|
|
||||||
filename: "guava-32.1.3-jre.jar.asc",
|
|
||||||
want: true,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "regular jar is not metadata",
|
|
||||||
filename: "guava-32.1.3-jre.jar",
|
|
||||||
want: false,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "pom checksum is metadata",
|
|
||||||
filename: "guava-32.1.3-jre.pom.sha1",
|
|
||||||
want: true,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
got := h.isMetadataFile(tt.filename)
|
|
||||||
if got != tt.want {
|
|
||||||
t.Errorf("isMetadataFile(%q) = %v, want %v", tt.filename, got, tt.want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
|
||||||
|
|
@ -1,200 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bytes"
|
|
||||||
"compress/gzip"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"strings"
|
|
||||||
"sync/atomic"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
)
|
|
||||||
|
|
||||||
// gzipPayload returns a gzip-compressed copy of data, simulating an origin
|
|
||||||
// that stores pre-compressed index files.
|
|
||||||
func gzipPayload(t *testing.T, data []byte) []byte {
|
|
||||||
t.Helper()
|
|
||||||
var buf bytes.Buffer
|
|
||||||
zw := gzip.NewWriter(&buf)
|
|
||||||
if _, err := zw.Write(data); err != nil {
|
|
||||||
t.Fatalf("compressing payload: %v", err)
|
|
||||||
}
|
|
||||||
if err := zw.Close(); err != nil {
|
|
||||||
t.Fatalf("closing gzip writer: %v", err)
|
|
||||||
}
|
|
||||||
return buf.Bytes()
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestProxyCached_PreservesContentEncodedBytes covers issue #300: an upstream
|
|
||||||
// that serves a signed index with Content-Encoding: gzip must have its bytes
|
|
||||||
// cached and re-served verbatim, with the encoding header replayed, instead of
|
|
||||||
// being transparently decompressed by the HTTP client.
|
|
||||||
func TestProxyCached_PreservesContentEncodedBytes(t *testing.T) {
|
|
||||||
raw := gzipPayload(t, []byte("signed index payload"))
|
|
||||||
|
|
||||||
var available atomic.Bool
|
|
||||||
available.Store(true)
|
|
||||||
var sawAcceptEncoding atomic.Value
|
|
||||||
var upstreamRequests atomic.Int32
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if !available.Load() {
|
|
||||||
http.Error(w, "unavailable", http.StatusServiceUnavailable)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
upstreamRequests.Add(1)
|
|
||||||
sawAcceptEncoding.Store(r.Header.Get(headerAcceptEncoding))
|
|
||||||
w.Header().Set(headerContentType, "application/octet-stream")
|
|
||||||
w.Header().Set(headerContentEncoding, "gzip")
|
|
||||||
_, _ = w.Write(raw)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
|
|
||||||
serve := func() *httptest.ResponseRecorder {
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
r := httptest.NewRequest(http.MethodGet, "/index", nil)
|
|
||||||
proxy.ProxyCached(w, r, upstream.URL+"/index", "apk", "index-key", "*/*")
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
|
|
||||||
first := serve()
|
|
||||||
if first.Code != http.StatusOK {
|
|
||||||
t.Fatalf("first response status = %d, want 200: %s", first.Code, first.Body.String())
|
|
||||||
}
|
|
||||||
if got, _ := sawAcceptEncoding.Load().(string); got != "identity" {
|
|
||||||
t.Errorf("upstream saw Accept-Encoding %q, want %q", got, "identity")
|
|
||||||
}
|
|
||||||
if !bytes.Equal(first.Body.Bytes(), raw) {
|
|
||||||
t.Errorf("first response altered the upstream bytes: got %d bytes, want %d", first.Body.Len(), len(raw))
|
|
||||||
}
|
|
||||||
if got := first.Header().Get(headerContentEncoding); got != "gzip" {
|
|
||||||
t.Errorf("first response Content-Encoding = %q, want %q", got, "gzip")
|
|
||||||
}
|
|
||||||
|
|
||||||
// Within the TTL and with the upstream down, the cached copy must be
|
|
||||||
// served with the same bytes and encoding.
|
|
||||||
available.Store(false)
|
|
||||||
second := serve()
|
|
||||||
if second.Code != http.StatusOK {
|
|
||||||
t.Fatalf("cached response status = %d, want 200: %s", second.Code, second.Body.String())
|
|
||||||
}
|
|
||||||
if !bytes.Equal(second.Body.Bytes(), raw) {
|
|
||||||
t.Errorf("cached response altered the stored bytes")
|
|
||||||
}
|
|
||||||
if got := second.Header().Get(headerContentEncoding); got != "gzip" {
|
|
||||||
t.Errorf("cached response Content-Encoding = %q, want %q", got, "gzip")
|
|
||||||
}
|
|
||||||
if got := upstreamRequests.Load(); got != 1 {
|
|
||||||
t.Errorf("upstream requests = %d, want 1", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestProxyCached_NoEncodingHeaderForIdentityResponses pins that ordinary
|
|
||||||
// responses do not grow a spurious Content-Encoding header.
|
|
||||||
func TestProxyCached_NoEncodingHeaderForIdentityResponses(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
|
||||||
w.Header().Set(headerContentType, contentTypeJSON)
|
|
||||||
_, _ = w.Write([]byte(`{"ok":true}`))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
r := httptest.NewRequest(http.MethodGet, "/meta", nil)
|
|
||||||
proxy.ProxyCached(w, r, upstream.URL+"/meta", "npm", "meta-key", contentTypeJSON)
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if got := w.Header().Get(headerContentEncoding); got != "" {
|
|
||||||
t.Errorf("Content-Encoding = %q, want empty", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestProxyMetadataStream_PreservesSignedBytesWithoutClientEncoding pins the
|
|
||||||
// uncached streaming path (the default, since cache_metadata is off) for the
|
|
||||||
// realistic client that sends no Accept-Encoding: the proxy must request
|
|
||||||
// identity upstream so Go does not transparently decompress a signed index,
|
|
||||||
// and the raw bytes plus the Content-Encoding header must reach the client.
|
|
||||||
func TestProxyMetadataStream_PreservesSignedBytesWithoutClientEncoding(t *testing.T) {
|
|
||||||
raw := gzipPayload(t, []byte("streamed index payload"))
|
|
||||||
var sawAcceptEncoding string
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
sawAcceptEncoding = r.Header.Get(headerAcceptEncoding)
|
|
||||||
w.Header().Set(headerContentType, "application/octet-stream")
|
|
||||||
w.Header().Set(headerContentEncoding, "gzip")
|
|
||||||
_, _ = w.Write(raw)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = false
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
// No Accept-Encoding on the client request -- the apk/apt/dnf case.
|
|
||||||
r := httptest.NewRequest(http.MethodGet, "/index", nil)
|
|
||||||
proxy.ProxyCached(w, r, upstream.URL+"/index", "apk", "stream-key", "*/*")
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want 200: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if sawAcceptEncoding != "identity" {
|
|
||||||
t.Errorf("upstream saw Accept-Encoding %q, want %q", sawAcceptEncoding, "identity")
|
|
||||||
}
|
|
||||||
if !bytes.Equal(w.Body.Bytes(), raw) {
|
|
||||||
t.Errorf("streamed response altered the upstream bytes: got %d bytes, want %d", w.Body.Len(), len(raw))
|
|
||||||
}
|
|
||||||
if got := w.Header().Get(headerContentEncoding); got != "gzip" {
|
|
||||||
t.Errorf("Content-Encoding = %q, want %q", got, "gzip")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestFetchOrCacheMetadata_DirectCallersKeepTransparentCompression pins that
|
|
||||||
// the parsing/rewriting ecosystems (npm, pypi, cargo, helm, ...) that call
|
|
||||||
// FetchOrCacheMetadata directly are NOT forced to identity: they keep Go's
|
|
||||||
// transparent transfer compression and receive decoded bytes, so a gzip-only
|
|
||||||
// upstream does not regress them (no wire-size blowup, no parse failures).
|
|
||||||
func TestFetchOrCacheMetadata_DirectCallersKeepTransparentCompression(t *testing.T) {
|
|
||||||
plaintext := []byte(`{"name":"demo","versions":{"1.0.0":{}}}`)
|
|
||||||
var sawAcceptEncoding string
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
sawAcceptEncoding = r.Header.Get(headerAcceptEncoding)
|
|
||||||
// Serve gzip only when the client accepts it, like a real CDN.
|
|
||||||
if strings.Contains(r.Header.Get(headerAcceptEncoding), "gzip") {
|
|
||||||
w.Header().Set(headerContentType, contentTypeJSON)
|
|
||||||
w.Header().Set(headerContentEncoding, "gzip")
|
|
||||||
_, _ = w.Write(gzipPayload(t, plaintext))
|
|
||||||
return
|
|
||||||
}
|
|
||||||
w.Header().Set(headerContentType, contentTypeJSON)
|
|
||||||
_, _ = w.Write(plaintext)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.CacheMetadata = true
|
|
||||||
proxy.MetadataTTL = time.Hour
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
|
|
||||||
body, _, err := proxy.FetchOrCacheMetadata(t.Context(), "npm", "demo", upstream.URL+"/demo", contentTypeJSON)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("FetchOrCacheMetadata() error = %v", err)
|
|
||||||
}
|
|
||||||
// The default transport adds Accept-Encoding: gzip and transparently
|
|
||||||
// decompresses, so the caller sees decoded JSON regardless of the wire form.
|
|
||||||
if sawAcceptEncoding == "identity" {
|
|
||||||
t.Errorf("direct caller forced identity; want transparent compression")
|
|
||||||
}
|
|
||||||
if !bytes.Equal(body, plaintext) {
|
|
||||||
t.Errorf("direct caller got %q, want decoded %q", body, plaintext)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,143 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestArtifactDownloadUpstreamNotFoundReturns404(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
path string
|
|
||||||
handler func(p *Proxy) http.Handler
|
|
||||||
}{
|
|
||||||
{"debian", "/pool/main/n/nginx/nginx_1.18.0-6_amd64.deb",
|
|
||||||
func(p *Proxy) http.Handler { return NewDebianHandler(p, "http://localhost", "").Routes() }},
|
|
||||||
{"rpm", "/releases/39/Everything/x86_64/os/Packages/n/nginx-1.24.0-1.fc39.x86_64.rpm",
|
|
||||||
func(p *Proxy) http.Handler { return NewRPMHandler(p, "http://localhost").Routes() }},
|
|
||||||
{"apk", "/alpine/v3.22/main/x86_64/busybox-1.37.0-r12.apk",
|
|
||||||
func(p *Proxy) http.Handler { return NewAPKHandler(p, "http://localhost", nil).Routes() }},
|
|
||||||
{"nuget", "/v3-flatcontainer/newtonsoft.json/13.0.3/newtonsoft.json.13.0.3.nupkg",
|
|
||||||
func(p *Proxy) http.Handler { return NewNuGetHandler(p, "http://localhost").Routes() }},
|
|
||||||
{"pypi", "/packages/packages/ab/cd/ef0123456789/requests-2.31.0-py3-none-any.whl",
|
|
||||||
func(p *Proxy) http.Handler {
|
|
||||||
return NewPyPIHandlerWithUpstreams(p, "http://localhost", "", "").Routes()
|
|
||||||
}},
|
|
||||||
{"cran", "/src/contrib/ggplot2_3.4.4.tar.gz",
|
|
||||||
func(p *Proxy) http.Handler { return NewCRANHandler(p, "http://localhost").Routes() }},
|
|
||||||
{"conda", "/conda-forge/linux-64/numpy-1.26.0-py311_0.tar.bz2",
|
|
||||||
func(p *Proxy) http.Handler { return NewCondaHandler(p, "http://localhost").Routes() }},
|
|
||||||
{"conan", "/v1/files/zlib/1.3.1/_/_/0/recipe/conan_sources.tgz",
|
|
||||||
func(p *Proxy) http.Handler { return NewConanHandler(p, "http://localhost").Routes() }},
|
|
||||||
{"gem", "/gems/rails-7.1.0.gem",
|
|
||||||
func(p *Proxy) http.Handler { return NewGemHandler(p, "http://localhost").Routes() }},
|
|
||||||
{"hex", "/tarballs/phoenix-1.7.10.tar",
|
|
||||||
func(p *Proxy) http.Handler { return NewHexHandler(p, "http://localhost").Routes() }},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
fetcher.fetchErr = fetch.ErrNotFound
|
|
||||||
|
|
||||||
srv := httptest.NewServer(tt.handler(proxy))
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
resp, err := http.Get(srv.URL + tt.path)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusNotFound {
|
|
||||||
t.Errorf("want 404 for missing upstream artifact, got %d", resp.StatusCode)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestJuliaPackageUpstreamNotFoundReturns404(t *testing.T) {
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
fetcher.fetchErr = fetch.ErrNotFound
|
|
||||||
|
|
||||||
dead := httptest.NewServer(http.NotFoundHandler())
|
|
||||||
defer dead.Close()
|
|
||||||
|
|
||||||
h := NewJuliaHandler(proxy, "http://localhost")
|
|
||||||
h.upstreamURL = dead.URL
|
|
||||||
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
resp, err := http.Get(srv.URL +
|
|
||||||
"/package/7876af07-990d-54b4-ab0e-23690620f79a/0123456789abcdef0123456789abcdef01234567")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusNotFound {
|
|
||||||
t.Errorf("want 404 for missing upstream package, got %d", resp.StatusCode)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestComposerDownloadUpstreamNotFoundReturns404(t *testing.T) {
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
fetcher.fetchErr = fetch.ErrNotFound
|
|
||||||
|
|
||||||
meta := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if r.URL.Path == "/p2/monolog/monolog.json" {
|
|
||||||
_, _ = w.Write([]byte(`{
|
|
||||||
"packages": {
|
|
||||||
"monolog/monolog": [
|
|
||||||
{"version": "2.9.1", "dist": {"url": "https://example.com/monolog-2.9.1.zip", "type": "zip"}}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}`))
|
|
||||||
return
|
|
||||||
}
|
|
||||||
http.NotFound(w, r)
|
|
||||||
}))
|
|
||||||
defer meta.Close()
|
|
||||||
|
|
||||||
h := &ComposerHandler{proxy: proxy, repoURL: meta.URL, proxyURL: "http://localhost"}
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
resp, err := http.Get(srv.URL + "/files/monolog/monolog/2.9.1/monolog-2.9.1.zip")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusNotFound {
|
|
||||||
t.Errorf("want 404 for missing upstream dist, got %d", resp.StatusCode)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestContainerBlobUpstreamNotFoundReturns404(t *testing.T) {
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
fetcher.fetchErr = fetch.ErrNotFound
|
|
||||||
|
|
||||||
h := &ContainerHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
registryURL: "https://registry-1.docker.io",
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet,
|
|
||||||
"/library/nginx/blobs/sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusNotFound {
|
|
||||||
t.Errorf("want 404 for missing upstream blob, got %d; body: %s", w.Code, w.Body.String())
|
|
||||||
}
|
|
||||||
if !strings.Contains(w.Body.String(), "BLOB_UNKNOWN") {
|
|
||||||
t.Errorf("want BLOB_UNKNOWN error code in body, got: %s", w.Body.String())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,83 +0,0 @@
|
||||||
package handler
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"errors"
|
|
||||||
"io"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestErrUpstreamNotFoundWrapsFetchErrNotFound(t *testing.T) {
|
|
||||||
if !errors.Is(ErrUpstreamNotFound, fetch.ErrNotFound) {
|
|
||||||
t.Fatal("ErrUpstreamNotFound does not wrap fetch.ErrNotFound")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestGetOrFetchArtifactFromURL_NotFound(t *testing.T) {
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
fetcher.fetchErr = fetch.ErrNotFound
|
|
||||||
|
|
||||||
_, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
|
|
||||||
"maven", "org.example:missing", "1.0", "missing-1.0.jar",
|
|
||||||
"http://upstream.test/org/example/missing/1.0/missing-1.0.jar")
|
|
||||||
|
|
||||||
if !errors.Is(err, ErrUpstreamNotFound) {
|
|
||||||
t.Fatalf("want ErrUpstreamNotFound, got %v", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMavenHandler_UpstreamNotFoundReturns404(t *testing.T) {
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
fetcher.fetchErr = fetch.ErrNotFound
|
|
||||||
|
|
||||||
h := NewMavenHandler(proxy, "http://localhost", "http://upstream.test", "http://portal.test")
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
resp, err := http.Get(srv.URL + "/org/example/missing/1.0/missing-1.0.jar")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusNotFound {
|
|
||||||
t.Errorf("want 404 for missing upstream artifact, got %d", resp.StatusCode)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMavenHandler_PluginPortalFallback(t *testing.T) {
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
fetcher.fetchErrByURL = map[string]error{
|
|
||||||
"http://upstream.test/org/example/plugin/1.0/plugin-1.0.jar": fetch.ErrNotFound,
|
|
||||||
}
|
|
||||||
fetcher.artifact = &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader("portal artifact")),
|
|
||||||
ContentType: "application/java-archive",
|
|
||||||
}
|
|
||||||
|
|
||||||
h := NewMavenHandler(proxy, "http://localhost", "http://upstream.test", "http://portal.test")
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
resp, err := http.Get(srv.URL + "/org/example/plugin/1.0/plugin-1.0.jar")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
|
||||||
t.Fatalf("want 200 via plugin portal fallback, got %d", resp.StatusCode)
|
|
||||||
}
|
|
||||||
body, _ := io.ReadAll(resp.Body)
|
|
||||||
if string(body) != "portal artifact" {
|
|
||||||
t.Errorf("want portal artifact body, got %q", body)
|
|
||||||
}
|
|
||||||
if fetcher.fetchedURL != "http://portal.test/org/example/plugin/1.0/plugin-1.0.jar" {
|
|
||||||
t.Errorf("fallback did not hit plugin portal, last URL: %s", fetcher.fetchedURL)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -2,19 +2,15 @@ package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"errors"
|
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/url"
|
"net/url"
|
||||||
"sort"
|
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
npmUpstream = "https://registry.npmjs.org"
|
npmUpstream = "https://registry.npmjs.org"
|
||||||
npmAcceptDefault = "application/vnd.npm.install-v1+json;q=1.0, application/json;q=0.8"
|
|
||||||
scopedParts = 2 // scope + name in scoped packages
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// NPMHandler handles npm registry protocol requests.
|
// NPMHandler handles npm registry protocol requests.
|
||||||
|
|
@ -25,14 +21,10 @@ type NPMHandler struct {
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewNPMHandler creates a new npm protocol handler.
|
// NewNPMHandler creates a new npm protocol handler.
|
||||||
func NewNPMHandler(proxy *Proxy, proxyURL, upstreamURL string) *NPMHandler {
|
func NewNPMHandler(proxy *Proxy, proxyURL string) *NPMHandler {
|
||||||
if strings.TrimSpace(upstreamURL) == "" {
|
|
||||||
upstreamURL = npmUpstream
|
|
||||||
}
|
|
||||||
|
|
||||||
return &NPMHandler{
|
return &NPMHandler{
|
||||||
proxy: proxy,
|
proxy: proxy,
|
||||||
upstreamURL: strings.TrimSuffix(upstreamURL, "/"),
|
upstreamURL: npmUpstream,
|
||||||
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -69,28 +61,37 @@ func (h *NPMHandler) handlePackageMetadata(w http.ResponseWriter, r *http.Reques
|
||||||
|
|
||||||
h.proxy.Logger.Info("npm metadata request", "package", packageName)
|
h.proxy.Logger.Info("npm metadata request", "package", packageName)
|
||||||
|
|
||||||
|
// Fetch metadata from upstream
|
||||||
upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, url.PathEscape(packageName))
|
upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, url.PathEscape(packageName))
|
||||||
|
|
||||||
// Prefer the smaller abbreviated packument format but include application/json
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
||||||
// as a fallback so upstreams that reject the abbreviated type (e.g. JFrog
|
if err != nil {
|
||||||
// Artifactory, which returns 406) can still respond with full metadata.
|
JSONError(w, http.StatusInternalServerError, "failed to create request")
|
||||||
// When cooldown is enabled we must use full metadata exclusively because the
|
return
|
||||||
// abbreviated format omits the "time" map required for version age filtering.
|
}
|
||||||
// Operators can also force full metadata so clients that gate on publish
|
req.Header.Set("Accept", "application/json")
|
||||||
// age (for example Yarn's npmMinimalAgeGate) keep working through the proxy.
|
|
||||||
accept := npmAcceptDefault
|
resp, err := http.DefaultClient.Do(req)
|
||||||
if h.proxy.NPMFullMetadata || (h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled()) {
|
if err != nil {
|
||||||
accept = contentTypeJSON
|
h.proxy.Logger.Error("failed to fetch upstream metadata", "error", err)
|
||||||
|
JSONError(w, http.StatusBadGateway, "failed to fetch from upstream")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
if resp.StatusCode == http.StatusNotFound {
|
||||||
|
JSONError(w, http.StatusNotFound, "package not found")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if resp.StatusCode != http.StatusOK {
|
||||||
|
JSONError(w, http.StatusBadGateway, fmt.Sprintf("upstream returned %d", resp.StatusCode))
|
||||||
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
body, _, err := h.proxy.FetchOrCacheMetadata(r.Context(), "npm", packageName, upstreamURL, accept)
|
// Parse and rewrite tarball URLs
|
||||||
|
body, err := io.ReadAll(resp.Body)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if errors.Is(err, ErrUpstreamNotFound) {
|
JSONError(w, http.StatusInternalServerError, "failed to read response")
|
||||||
JSONError(w, http.StatusNotFound, "package not found")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Error("failed to fetch npm metadata", "error", err)
|
|
||||||
JSONError(w, http.StatusBadGateway, "failed to fetch from upstream")
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -98,19 +99,18 @@ func (h *NPMHandler) handlePackageMetadata(w http.ResponseWriter, r *http.Reques
|
||||||
if err != nil {
|
if err != nil {
|
||||||
// If rewriting fails, just proxy the original
|
// If rewriting fails, just proxy the original
|
||||||
h.proxy.Logger.Warn("failed to rewrite metadata, proxying original", "error", err)
|
h.proxy.Logger.Warn("failed to rewrite metadata, proxying original", "error", err)
|
||||||
w.Header().Set(headerContentType, contentTypeJSON)
|
w.Header().Set("Content-Type", "application/json")
|
||||||
w.WriteHeader(http.StatusOK)
|
w.WriteHeader(http.StatusOK)
|
||||||
_, _ = w.Write(body)
|
_, _ = w.Write(body)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
w.Header().Set(headerContentType, contentTypeJSON)
|
w.Header().Set("Content-Type", "application/json")
|
||||||
w.WriteHeader(http.StatusOK)
|
w.WriteHeader(http.StatusOK)
|
||||||
_, _ = w.Write(rewritten)
|
_, _ = w.Write(rewritten)
|
||||||
}
|
}
|
||||||
|
|
||||||
// rewriteMetadata rewrites tarball URLs in npm package metadata to point at this proxy.
|
// rewriteMetadata rewrites tarball URLs in npm package metadata to point at this proxy.
|
||||||
// If cooldown is enabled, versions published too recently are filtered out.
|
|
||||||
func (h *NPMHandler) rewriteMetadata(packageName string, body []byte) ([]byte, error) {
|
func (h *NPMHandler) rewriteMetadata(packageName string, body []byte) ([]byte, error) {
|
||||||
var metadata map[string]any
|
var metadata map[string]any
|
||||||
if err := json.Unmarshal(body, &metadata); err != nil {
|
if err := json.Unmarshal(body, &metadata); err != nil {
|
||||||
|
|
@ -123,71 +123,6 @@ func (h *NPMHandler) rewriteMetadata(packageName string, body []byte) ([]byte, e
|
||||||
return body, nil // No versions to rewrite
|
return body, nil // No versions to rewrite
|
||||||
}
|
}
|
||||||
|
|
||||||
h.applyCooldownFiltering(metadata, versions, packageName)
|
|
||||||
h.rewriteTarballURLs(versions, packageName)
|
|
||||||
|
|
||||||
return json.Marshal(metadata)
|
|
||||||
}
|
|
||||||
|
|
||||||
// applyCooldownFiltering removes versions that are too recently published,
|
|
||||||
// and updates dist-tags.latest if the current latest was filtered out.
|
|
||||||
func (h *NPMHandler) applyCooldownFiltering(metadata map[string]any, versions map[string]any, packageName string) {
|
|
||||||
if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
timeMap, _ := metadata["time"].(map[string]any)
|
|
||||||
if timeMap == nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
packagePURL := canonicalPackagePURL("npm", packageName)
|
|
||||||
|
|
||||||
for version := range versions {
|
|
||||||
publishedStr, ok := timeMap[version].(string)
|
|
||||||
if !ok {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
publishedAt, err := time.Parse(time.RFC3339, publishedStr)
|
|
||||||
if err != nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
if !h.proxy.Cooldown.IsAllowed("npm", packagePURL, publishedAt) {
|
|
||||||
h.proxy.Logger.Info("cooldown: filtering npm version",
|
|
||||||
"package", packageName, "version", version,
|
|
||||||
"published", publishedStr)
|
|
||||||
delete(versions, version)
|
|
||||||
delete(timeMap, version)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
h.updateDistTagsLatest(metadata, versions, timeMap)
|
|
||||||
}
|
|
||||||
|
|
||||||
// updateDistTagsLatest updates the dist-tags.latest field if the current latest
|
|
||||||
// version was removed by cooldown filtering.
|
|
||||||
func (h *NPMHandler) updateDistTagsLatest(metadata, versions, timeMap map[string]any) {
|
|
||||||
distTags, ok := metadata["dist-tags"].(map[string]any)
|
|
||||||
if !ok {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
latest, ok := distTags["latest"].(string)
|
|
||||||
if !ok {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if _, exists := versions[latest]; exists {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if newLatest := h.findNewestVersion(versions, timeMap); newLatest != "" {
|
|
||||||
distTags["latest"] = newLatest
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// rewriteTarballURLs rewrites all tarball URLs in version entries to point at this proxy.
|
|
||||||
func (h *NPMHandler) rewriteTarballURLs(versions map[string]any, packageName string) {
|
|
||||||
for version, vdata := range versions {
|
for version, vdata := range versions {
|
||||||
vmap, ok := vdata.(map[string]any)
|
vmap, ok := vdata.(map[string]any)
|
||||||
if !ok {
|
if !ok {
|
||||||
|
|
@ -199,56 +134,25 @@ func (h *NPMHandler) rewriteTarballURLs(versions map[string]any, packageName str
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
|
||||||
tarball, ok := dist["tarball"].(string)
|
if tarball, ok := dist["tarball"].(string); ok {
|
||||||
if !ok {
|
// Extract filename from tarball URL
|
||||||
continue
|
filename := tarball
|
||||||
}
|
if idx := strings.LastIndex(tarball, "/"); idx >= 0 {
|
||||||
|
filename = tarball[idx+1:]
|
||||||
filename := tarball
|
|
||||||
if idx := strings.LastIndex(tarball, "/"); idx >= 0 {
|
|
||||||
filename = tarball[idx+1:]
|
|
||||||
}
|
|
||||||
|
|
||||||
escapedName := url.PathEscape(packageName)
|
|
||||||
newTarball := fmt.Sprintf("%s/npm/%s/-/%s", h.proxyURL, escapedName, filename)
|
|
||||||
dist["tarball"] = newTarball
|
|
||||||
|
|
||||||
h.proxy.Logger.Debug("rewrote tarball URL",
|
|
||||||
"package", packageName, "version", version,
|
|
||||||
"old", tarball, "new", newTarball)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// findNewestVersion returns the version string with the most recent timestamp
|
|
||||||
// from the remaining versions, using the time map.
|
|
||||||
func (h *NPMHandler) findNewestVersion(versions map[string]any, timeMap map[string]any) string {
|
|
||||||
if timeMap == nil {
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
|
|
||||||
type versionTime struct {
|
|
||||||
version string
|
|
||||||
t time.Time
|
|
||||||
}
|
|
||||||
|
|
||||||
var vts []versionTime
|
|
||||||
for v := range versions {
|
|
||||||
if ts, ok := timeMap[v].(string); ok {
|
|
||||||
if t, err := time.Parse(time.RFC3339, ts); err == nil {
|
|
||||||
vts = append(vts, versionTime{v, t})
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Rewrite to our proxy URL
|
||||||
|
escapedName := url.PathEscape(packageName)
|
||||||
|
newTarball := fmt.Sprintf("%s/npm/%s/-/%s", h.proxyURL, escapedName, filename)
|
||||||
|
dist["tarball"] = newTarball
|
||||||
|
|
||||||
|
h.proxy.Logger.Debug("rewrote tarball URL",
|
||||||
|
"package", packageName, "version", version,
|
||||||
|
"old", tarball, "new", newTarball)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if len(vts) == 0 {
|
return json.Marshal(metadata)
|
||||||
return ""
|
|
||||||
}
|
|
||||||
|
|
||||||
sort.Slice(vts, func(i, j int) bool {
|
|
||||||
return vts[i].t.After(vts[j].t)
|
|
||||||
})
|
|
||||||
|
|
||||||
return vts[0].version
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleDownload serves a package tarball, fetching and caching from upstream if needed.
|
// handleDownload serves a package tarball, fetching and caching from upstream if needed.
|
||||||
|
|
@ -270,103 +174,16 @@ func (h *NPMHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
||||||
h.proxy.Logger.Info("npm download request",
|
h.proxy.Logger.Info("npm download request",
|
||||||
"package", packageName, "version", version, "filename", filename)
|
"package", packageName, "version", version, "filename", filename)
|
||||||
|
|
||||||
if h.versionInCooldown(r, packageName, version) {
|
result, err := h.proxy.GetOrFetchArtifact(r.Context(), "npm", packageName, version, filename)
|
||||||
h.proxy.Logger.Info("cooldown: withholding npm tarball",
|
|
||||||
"package", packageName, "version", version)
|
|
||||||
JSONError(w, http.StatusNotFound, "version not found")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
downloadURL := fmt.Sprintf(
|
|
||||||
"%s/%s/-/%s",
|
|
||||||
h.upstreamURL,
|
|
||||||
escapeNPMDownloadPackage(packageName),
|
|
||||||
url.PathEscape(filename),
|
|
||||||
)
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(
|
|
||||||
r.Context(), "npm", packageName, version, filename, downloadURL,
|
|
||||||
)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
switch {
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
case errors.Is(err, ErrUpstreamNotFound):
|
JSONError(w, http.StatusBadGateway, "failed to fetch package")
|
||||||
JSONError(w, http.StatusNotFound, "package not found")
|
|
||||||
case errors.Is(err, ErrArtifactBlocked):
|
|
||||||
JSONError(w, http.StatusForbidden, err.Error())
|
|
||||||
default:
|
|
||||||
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
|
||||||
JSONError(w, http.StatusBadGateway, "failed to fetch package")
|
|
||||||
}
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
ServeArtifact(w, result)
|
ServeArtifact(w, result)
|
||||||
}
|
}
|
||||||
|
|
||||||
// versionInCooldown reports whether a version is still inside the cooldown
|
|
||||||
// window. Filtering the packument is not enough on its own: tarball URLs are
|
|
||||||
// predictable and lockfiles record them directly, so `npm ci` reaches the
|
|
||||||
// download path without ever requesting metadata.
|
|
||||||
//
|
|
||||||
// A version's publish time is immutable, so the check reads the stored
|
|
||||||
// versions row first and only falls back to the packument for a version the
|
|
||||||
// proxy has never seen, persisting the parsed time so the packument is
|
|
||||||
// fetched and parsed at most once per version. A version with no usable
|
|
||||||
// publish time is allowed through, matching how applyCooldownFiltering
|
|
||||||
// treats it.
|
|
||||||
func (h *NPMHandler) versionInCooldown(r *http.Request, packageName, version string) bool {
|
|
||||||
if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
versionPURL := canonicalVersionPURL("npm", packageName, version)
|
|
||||||
if ver, err := h.proxy.DB.GetVersionByPURL(versionPURL); err == nil && ver != nil && ver.PublishedAt.Valid {
|
|
||||||
return !h.proxy.Cooldown.IsAllowed("npm", canonicalPackagePURL("npm", packageName), ver.PublishedAt.Time)
|
|
||||||
}
|
|
||||||
|
|
||||||
upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, url.PathEscape(packageName))
|
|
||||||
|
|
||||||
body, _, err := h.proxy.FetchOrCacheMetadata(r.Context(), "npm", packageName, upstreamURL, contentTypeJSON)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Warn("cooldown: could not fetch npm metadata for download check",
|
|
||||||
"package", packageName, "version", version, "error", err)
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
var metadata struct {
|
|
||||||
Time map[string]string `json:"time"`
|
|
||||||
}
|
|
||||||
if err := json.Unmarshal(body, &metadata); err != nil {
|
|
||||||
h.proxy.Logger.Warn("cooldown: could not parse npm metadata for download check",
|
|
||||||
"package", packageName, "version", version, "error", err)
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
published, ok := metadata.Time[version]
|
|
||||||
if !ok {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
publishedAt, err := time.Parse(time.RFC3339, published)
|
|
||||||
if err != nil {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := h.proxy.DB.SetVersionPublishedAt(versionPURL, canonicalPackagePURL("npm", packageName), publishedAt); err != nil {
|
|
||||||
h.proxy.Logger.Warn("cooldown: could not store npm publish time",
|
|
||||||
"package", packageName, "version", version, "error", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return !h.proxy.Cooldown.IsAllowed("npm", canonicalPackagePURL("npm", packageName), publishedAt)
|
|
||||||
}
|
|
||||||
|
|
||||||
func escapeNPMDownloadPackage(packageName string) string {
|
|
||||||
scope, name, scoped := strings.Cut(packageName, "/")
|
|
||||||
if scoped && strings.HasPrefix(scope, "@") && len(scope) > 1 && name != "" && !strings.Contains(name, "/") {
|
|
||||||
return url.PathEscape(scope) + "/" + url.PathEscape(name)
|
|
||||||
}
|
|
||||||
return url.PathEscape(packageName)
|
|
||||||
}
|
|
||||||
|
|
||||||
// extractPackageName extracts the package name from the request path.
|
// extractPackageName extracts the package name from the request path.
|
||||||
// Handles both scoped (@scope/name) and unscoped (name) packages.
|
// Handles both scoped (@scope/name) and unscoped (name) packages.
|
||||||
func (h *NPMHandler) extractPackageName(r *http.Request) string {
|
func (h *NPMHandler) extractPackageName(r *http.Request) string {
|
||||||
|
|
@ -420,7 +237,7 @@ func (h *NPMHandler) extractVersionFromFilename(packageName, filename string) st
|
||||||
// For scoped packages, the filename uses the short name
|
// For scoped packages, the filename uses the short name
|
||||||
shortName := packageName
|
shortName := packageName
|
||||||
if strings.Contains(packageName, "/") {
|
if strings.Contains(packageName, "/") {
|
||||||
parts := strings.SplitN(packageName, "/", scopedParts)
|
parts := strings.SplitN(packageName, "/", 2)
|
||||||
shortName = parts[1]
|
shortName = parts[1]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -2,26 +2,15 @@ package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"errors"
|
|
||||||
"io"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"strings"
|
|
||||||
"sync/atomic"
|
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/git-pkgs/cooldown"
|
|
||||||
"github.com/git-pkgs/registries/fetch"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
const testVersion100 = "1.0.0"
|
|
||||||
|
|
||||||
func testProxy() *Proxy {
|
func testProxy() *Proxy {
|
||||||
return &Proxy{
|
return &Proxy{
|
||||||
Logger: slog.Default(),
|
Logger: slog.Default(),
|
||||||
HTTPClient: http.DefaultClient,
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -37,9 +26,9 @@ func TestNPMExtractVersionFromFilename(t *testing.T) {
|
||||||
{"@babel/core", "core-7.23.0.tgz", "7.23.0"},
|
{"@babel/core", "core-7.23.0.tgz", "7.23.0"},
|
||||||
{"@types/node", "node-20.10.0.tgz", "20.10.0"},
|
{"@types/node", "node-20.10.0.tgz", "20.10.0"},
|
||||||
{"express", "express-4.18.2.tgz", "4.18.2"},
|
{"express", "express-4.18.2.tgz", "4.18.2"},
|
||||||
{"lodash", "lodash.tgz", ""}, // no version
|
{"lodash", "lodash.tgz", ""}, // no version
|
||||||
{"lodash", "lodash-4.17.21.zip", ""}, // wrong extension
|
{"lodash", "lodash-4.17.21.zip", ""}, // wrong extension
|
||||||
{"lodash", "other-4.17.21.tgz", ""}, // wrong package name
|
{"lodash", "other-4.17.21.tgz", ""}, // wrong package name
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, tt := range tests {
|
for _, tt := range tests {
|
||||||
|
|
@ -51,86 +40,6 @@ func TestNPMExtractVersionFromFilename(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestNPMHandlerUsesConfiguredUpstream(t *testing.T) {
|
|
||||||
t.Run("metadata", func(t *testing.T) {
|
|
||||||
var requestPath, authHeader string
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
requestPath = r.URL.Path
|
|
||||||
authHeader = r.Header.Get("Authorization")
|
|
||||||
if authHeader != "Bearer npm-token" {
|
|
||||||
w.WriteHeader(http.StatusUnauthorized)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
_, _ = io.WriteString(w, `{"versions":{}}`)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
proxy.AuthForURL = func(string) (string, string) {
|
|
||||||
return "Authorization", "Bearer npm-token"
|
|
||||||
}
|
|
||||||
h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL+"/root/")
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/testpkg", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
|
|
||||||
}
|
|
||||||
if requestPath != "/root/testpkg" {
|
|
||||||
t.Errorf("upstream path = %q, want %q", requestPath, "/root/testpkg")
|
|
||||||
}
|
|
||||||
if authHeader != "Bearer npm-token" {
|
|
||||||
t.Errorf("Authorization = %q, want %q", authHeader, "Bearer npm-token")
|
|
||||||
}
|
|
||||||
})
|
|
||||||
|
|
||||||
t.Run("download", func(t *testing.T) {
|
|
||||||
proxy, _, _, artifactFetcher := setupTestProxy(t)
|
|
||||||
artifactFetcher.artifact = &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader("package")),
|
|
||||||
ContentType: "application/gzip",
|
|
||||||
}
|
|
||||||
h := NewNPMHandler(proxy, "http://proxy.test", "https://npm.example.test/root/")
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/testpkg/-/testpkg-1.0.0.tgz", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
|
|
||||||
}
|
|
||||||
want := "https://npm.example.test/root/testpkg/-/testpkg-1.0.0.tgz"
|
|
||||||
if artifactFetcher.fetchedURL != want {
|
|
||||||
t.Errorf("fetched URL = %q, want %q", artifactFetcher.fetchedURL, want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
|
|
||||||
t.Run("scoped download", func(t *testing.T) {
|
|
||||||
proxy, _, _, artifactFetcher := setupTestProxy(t)
|
|
||||||
artifactFetcher.artifact = &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader("package")),
|
|
||||||
ContentType: "application/gzip",
|
|
||||||
}
|
|
||||||
h := NewNPMHandler(proxy, "http://proxy.test", "https://npm.example.test/root/")
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/@scope/name/-/name-1.0.0.tgz", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.Routes().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
|
|
||||||
}
|
|
||||||
want := "https://npm.example.test/root/@scope/name/-/name-1.0.0.tgz"
|
|
||||||
if artifactFetcher.fetchedURL != want {
|
|
||||||
t.Errorf("fetched URL = %q, want %q", artifactFetcher.fetchedURL, want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNPMRewriteMetadata(t *testing.T) {
|
func TestNPMRewriteMetadata(t *testing.T) {
|
||||||
h := &NPMHandler{
|
h := &NPMHandler{
|
||||||
proxy: testProxy(),
|
proxy: testProxy(),
|
||||||
|
|
@ -259,7 +168,7 @@ func TestNPMHandlerMetadataProxy(t *testing.T) {
|
||||||
|
|
||||||
// Check that tarball URL was rewritten
|
// Check that tarball URL was rewritten
|
||||||
versions := result["versions"].(map[string]any)
|
versions := result["versions"].(map[string]any)
|
||||||
v := versions[testVersion100].(map[string]any)
|
v := versions["1.0.0"].(map[string]any)
|
||||||
dist := v["dist"].(map[string]any)
|
dist := v["dist"].(map[string]any)
|
||||||
tarball := dist["tarball"].(string)
|
tarball := dist["tarball"].(string)
|
||||||
|
|
||||||
|
|
@ -268,191 +177,6 @@ func TestNPMHandlerMetadataProxy(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestNPMRewriteMetadataCooldown(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
old := now.Add(-10 * 24 * time.Hour).Format(time.RFC3339)
|
|
||||||
recent := now.Add(-1 * time.Hour).Format(time.RFC3339)
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{Default: "3d"}
|
|
||||||
|
|
||||||
h := &NPMHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
input := `{
|
|
||||||
"name": "testpkg",
|
|
||||||
"dist-tags": {"latest": "2.0.0"},
|
|
||||||
"time": {
|
|
||||||
"1.0.0": "` + old + `",
|
|
||||||
"2.0.0": "` + recent + `"
|
|
||||||
},
|
|
||||||
"versions": {
|
|
||||||
"1.0.0": {
|
|
||||||
"name": "testpkg",
|
|
||||||
"version": "1.0.0",
|
|
||||||
"dist": {
|
|
||||||
"tarball": "https://registry.npmjs.org/testpkg/-/testpkg-1.0.0.tgz"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"2.0.0": {
|
|
||||||
"name": "testpkg",
|
|
||||||
"version": "2.0.0",
|
|
||||||
"dist": {
|
|
||||||
"tarball": "https://registry.npmjs.org/testpkg/-/testpkg-2.0.0.tgz"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
output, err := h.rewriteMetadata("testpkg", []byte(input))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("rewriteMetadata failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(output, &result); err != nil {
|
|
||||||
t.Fatalf("failed to parse output: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
versions := result["versions"].(map[string]any)
|
|
||||||
|
|
||||||
// Old version should remain
|
|
||||||
if _, ok := versions[testVersion100]; !ok {
|
|
||||||
t.Error("version 1.0.0 should not be filtered")
|
|
||||||
}
|
|
||||||
|
|
||||||
// Recent version should be filtered
|
|
||||||
if _, ok := versions["2.0.0"]; ok {
|
|
||||||
t.Error("version 2.0.0 should be filtered by cooldown")
|
|
||||||
}
|
|
||||||
|
|
||||||
// dist-tags.latest should be updated to 1.0.0
|
|
||||||
distTags := result["dist-tags"].(map[string]any)
|
|
||||||
if distTags["latest"] != testVersion100 {
|
|
||||||
t.Errorf("dist-tags.latest = %q, want %q", distTags["latest"], testVersion100)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNPMRewriteMetadataCooldownExemptPackage(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
recent := now.Add(-1 * time.Hour).Format(time.RFC3339)
|
|
||||||
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{
|
|
||||||
Default: "3d",
|
|
||||||
Packages: map[string]string{"pkg:npm/testpkg": "0"},
|
|
||||||
}
|
|
||||||
|
|
||||||
h := &NPMHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
proxyURL: "http://localhost:8080",
|
|
||||||
}
|
|
||||||
|
|
||||||
input := `{
|
|
||||||
"name": "testpkg",
|
|
||||||
"time": {"1.0.0": "` + recent + `"},
|
|
||||||
"versions": {
|
|
||||||
"1.0.0": {
|
|
||||||
"name": "testpkg",
|
|
||||||
"version": "1.0.0",
|
|
||||||
"dist": {"tarball": "https://registry.npmjs.org/testpkg/-/testpkg-1.0.0.tgz"}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}`
|
|
||||||
|
|
||||||
output, err := h.rewriteMetadata("testpkg", []byte(input))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("rewriteMetadata failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
var result map[string]any
|
|
||||||
if err := json.Unmarshal(output, &result); err != nil {
|
|
||||||
t.Fatalf("failed to parse output: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
versions := result["versions"].(map[string]any)
|
|
||||||
if _, ok := versions[testVersion100]; !ok {
|
|
||||||
t.Error("exempt package version should not be filtered")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNPMHandlerUsesAbbreviatedMetadata(t *testing.T) {
|
|
||||||
var gotAccept string
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
gotAccept = r.Header.Get("Accept")
|
|
||||||
w.Header().Set("Content-Type", "application/json")
|
|
||||||
_, _ = w.Write([]byte(`{
|
|
||||||
"name": "testpkg",
|
|
||||||
"versions": {
|
|
||||||
"1.0.0": {
|
|
||||||
"name": "testpkg",
|
|
||||||
"version": "1.0.0",
|
|
||||||
"dist": {
|
|
||||||
"tarball": "https://registry.npmjs.org/testpkg/-/testpkg-1.0.0.tgz"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}`))
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
t.Run("no cooldown uses combined accept header", func(t *testing.T) {
|
|
||||||
h := &NPMHandler{
|
|
||||||
proxy: testProxy(),
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/testpkg", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handlePackageMetadata(w, req)
|
|
||||||
|
|
||||||
if gotAccept != npmAcceptDefault {
|
|
||||||
t.Errorf("Accept = %q, want %q", gotAccept, npmAcceptDefault)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
|
|
||||||
t.Run("cooldown enabled uses full metadata only", func(t *testing.T) {
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.Cooldown = &cooldown.Config{Default: "3d"}
|
|
||||||
|
|
||||||
h := &NPMHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/testpkg", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handlePackageMetadata(w, req)
|
|
||||||
|
|
||||||
if gotAccept != contentTypeJSON {
|
|
||||||
t.Errorf("Accept = %q, want %q (cooldown requires full metadata)", gotAccept, contentTypeJSON)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
|
|
||||||
t.Run("full metadata option uses full metadata without cooldown", func(t *testing.T) {
|
|
||||||
proxy := testProxy()
|
|
||||||
proxy.NPMFullMetadata = true
|
|
||||||
|
|
||||||
h := &NPMHandler{
|
|
||||||
proxy: proxy,
|
|
||||||
upstreamURL: upstream.URL,
|
|
||||||
proxyURL: "http://proxy.local",
|
|
||||||
}
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/testpkg", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.handlePackageMetadata(w, req)
|
|
||||||
|
|
||||||
if gotAccept != contentTypeJSON {
|
|
||||||
t.Errorf("Accept = %q, want %q (npm_full_metadata requires full metadata)", gotAccept, contentTypeJSON)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNPMHandlerMetadataNotFound(t *testing.T) {
|
func TestNPMHandlerMetadataNotFound(t *testing.T) {
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
w.WriteHeader(http.StatusNotFound)
|
w.WriteHeader(http.StatusNotFound)
|
||||||
|
|
@ -475,237 +199,3 @@ func TestNPMHandlerMetadataNotFound(t *testing.T) {
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusNotFound)
|
t.Errorf("status = %d, want %d", w.Code, http.StatusNotFound)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestNPMDownloadCooldown(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
packument := `{
|
|
||||||
"name": "leftpad",
|
|
||||||
"dist-tags": {"latest": "2.0.0"},
|
|
||||||
"time": {
|
|
||||||
"1.0.0": "` + now.Add(-30*24*time.Hour).Format(time.RFC3339) + `",
|
|
||||||
"2.0.0": "` + now.Add(-1*time.Hour).Format(time.RFC3339) + `"
|
|
||||||
},
|
|
||||||
"versions": {"1.0.0": {}, "2.0.0": {}}
|
|
||||||
}`
|
|
||||||
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
|
||||||
w.Header().Set("Content-Type", contentTypeJSON)
|
|
||||||
_, _ = io.WriteString(w, packument)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
version string
|
|
||||||
wantStatus int
|
|
||||||
}{
|
|
||||||
{"published before the window serves the tarball", testVersion100, http.StatusOK},
|
|
||||||
{"published inside the window is withheld", "2.0.0", http.StatusNotFound},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
proxy.Cooldown = &cooldown.Config{Default: "7d"}
|
|
||||||
fetcher.artifact = &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader("tarball data")),
|
|
||||||
ContentType: "application/octet-stream",
|
|
||||||
}
|
|
||||||
|
|
||||||
h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL)
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
resp, err := http.Get(srv.URL + "/leftpad/-/leftpad-" + tt.version + ".tgz")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != tt.wantStatus {
|
|
||||||
t.Errorf("status = %d, want %d", resp.StatusCode, tt.wantStatus)
|
|
||||||
}
|
|
||||||
if tt.wantStatus == http.StatusNotFound && fetcher.fetchCalled {
|
|
||||||
t.Error("fetched a version that is still inside the cooldown window")
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNPMDownloadCooldownDisabled(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
|
||||||
t.Error("metadata must not be fetched when cooldown is disabled")
|
|
||||||
w.WriteHeader(http.StatusInternalServerError)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
fetcher.artifact = &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader("tarball data")),
|
|
||||||
ContentType: "application/octet-stream",
|
|
||||||
}
|
|
||||||
|
|
||||||
h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL)
|
|
||||||
|
|
||||||
if h.versionInCooldown(httptest.NewRequest(http.MethodGet, "/", nil), "leftpad", testVersion100) {
|
|
||||||
t.Error("versionInCooldown = true, want false when cooldown is not configured")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNPMDownloadCooldownUsesStoredPublishTime(t *testing.T) {
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
|
||||||
t.Error("metadata must not be fetched when the publish time is already stored")
|
|
||||||
w.WriteHeader(http.StatusInternalServerError)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
version string
|
|
||||||
publishedAt time.Time
|
|
||||||
wantStatus int
|
|
||||||
}{
|
|
||||||
{"stored time before the window serves the tarball", testVersion100, time.Now().Add(-30 * 24 * time.Hour), http.StatusOK},
|
|
||||||
{"stored time inside the window is withheld", "2.0.0", time.Now().Add(-1 * time.Hour), http.StatusNotFound},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
proxy, db, _, fetcher := setupTestProxy(t)
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
proxy.Cooldown = &cooldown.Config{Default: "7d"}
|
|
||||||
fetcher.artifact = &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader("tarball data")),
|
|
||||||
ContentType: "application/octet-stream",
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := db.SetVersionPublishedAt("pkg:npm/leftpad@"+tt.version, "pkg:npm/leftpad", tt.publishedAt); err != nil {
|
|
||||||
t.Fatalf("seeding publish time failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL)
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
resp, err := http.Get(srv.URL + "/leftpad/-/leftpad-" + tt.version + ".tgz")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != tt.wantStatus {
|
|
||||||
t.Errorf("status = %d, want %d", resp.StatusCode, tt.wantStatus)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNPMDownloadCooldownFetchesMetadataOnce(t *testing.T) {
|
|
||||||
now := time.Now()
|
|
||||||
packument := `{
|
|
||||||
"name": "leftpad",
|
|
||||||
"dist-tags": {"latest": "1.0.0"},
|
|
||||||
"time": {
|
|
||||||
"1.0.0": "` + now.Add(-30*24*time.Hour).Format(time.RFC3339) + `"
|
|
||||||
},
|
|
||||||
"versions": {"1.0.0": {}}
|
|
||||||
}`
|
|
||||||
|
|
||||||
var metadataRequests atomic.Int64
|
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
|
||||||
metadataRequests.Add(1)
|
|
||||||
w.Header().Set("Content-Type", contentTypeJSON)
|
|
||||||
_, _ = io.WriteString(w, packument)
|
|
||||||
}))
|
|
||||||
defer upstream.Close()
|
|
||||||
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
proxy.HTTPClient = upstream.Client()
|
|
||||||
proxy.Cooldown = &cooldown.Config{Default: "7d"}
|
|
||||||
|
|
||||||
h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL)
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
// The first download parses the packument once and persists the publish
|
|
||||||
// time; caching the artifact afterwards upserts the versions row without a
|
|
||||||
// publish time, which must not erase the stored value. The second download
|
|
||||||
// must answer from the stored time alone.
|
|
||||||
for i := 0; i < 2; i++ {
|
|
||||||
fetcher.artifact = &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader("tarball data")),
|
|
||||||
ContentType: "application/octet-stream",
|
|
||||||
}
|
|
||||||
resp, err := http.Get(srv.URL + "/leftpad/-/leftpad-" + testVersion100 + ".tgz")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("request %d failed: %v", i+1, err)
|
|
||||||
}
|
|
||||||
_ = resp.Body.Close()
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
|
||||||
t.Fatalf("request %d status = %d, want %d", i+1, resp.StatusCode, http.StatusOK)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if got := metadataRequests.Load(); got != 1 {
|
|
||||||
t.Errorf("metadata requests = %d, want 1", got)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestNPMDownloadErrorResponsesAreJSON guards against a regression where
|
|
||||||
// routing handleDownload's error path through the shared serveArtifactError
|
|
||||||
// helper silently switched npm's 404/502 tarball error bodies from JSON to
|
|
||||||
// plain text; npm clients expect a JSON {"error": "..."} body on every
|
|
||||||
// download failure, including the newer scan-blocked (403) case.
|
|
||||||
func TestNPMDownloadErrorResponsesAreJSON(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
fetchErr error
|
|
||||||
blocked bool
|
|
||||||
wantStatus int
|
|
||||||
}{
|
|
||||||
{"upstream not found", fetch.ErrNotFound, false, http.StatusNotFound},
|
|
||||||
{"upstream failure", errors.New("connection refused"), false, http.StatusBadGateway},
|
|
||||||
{"blocked by scan", nil, true, http.StatusForbidden},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
|
||||||
proxy.ScanSigningKey = []byte("test-signing-key")
|
|
||||||
if tt.blocked {
|
|
||||||
proxy.Scanners = newTestScanGroup(t, newTestScanServer(t, false, "malware detected").URL, false)
|
|
||||||
}
|
|
||||||
fetcher.fetchErr = tt.fetchErr
|
|
||||||
fetcher.artifact = &fetch.Artifact{
|
|
||||||
Body: io.NopCloser(strings.NewReader("tarball data")),
|
|
||||||
ContentType: "application/octet-stream",
|
|
||||||
}
|
|
||||||
|
|
||||||
h := NewNPMHandler(proxy, "http://proxy.test", "http://upstream.invalid")
|
|
||||||
srv := httptest.NewServer(h.Routes())
|
|
||||||
defer srv.Close()
|
|
||||||
|
|
||||||
resp, err := http.Get(srv.URL + "/leftpad/-/leftpad-1.0.0.tgz")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("request failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != tt.wantStatus {
|
|
||||||
t.Errorf("status = %d, want %d", resp.StatusCode, tt.wantStatus)
|
|
||||||
}
|
|
||||||
if ct := resp.Header.Get("Content-Type"); ct != contentTypeJSON {
|
|
||||||
t.Errorf("Content-Type = %q, want %q", ct, contentTypeJSON)
|
|
||||||
}
|
|
||||||
var body map[string]any
|
|
||||||
if err := json.NewDecoder(resp.Body).Decode(&body); err != nil {
|
|
||||||
t.Fatalf("response body is not valid JSON: %v", err)
|
|
||||||
}
|
|
||||||
if _, ok := body["error"]; !ok {
|
|
||||||
t.Errorf("response body %v missing \"error\" key", body)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
|
||||||
|
|
@ -2,7 +2,6 @@ package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"errors"
|
|
||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
|
|
@ -10,15 +9,13 @@ import (
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
nugetUpstream = "https://api.nuget.org"
|
nugetUpstream = "https://api.nuget.org"
|
||||||
nugetSearchUpstream = "https://azuresearch-usnc.nuget.org"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// NuGetHandler handles NuGet V3 API protocol requests.
|
// NuGetHandler handles NuGet V3 API protocol requests.
|
||||||
type NuGetHandler struct {
|
type NuGetHandler struct {
|
||||||
proxy *Proxy
|
proxy *Proxy
|
||||||
upstreamURL string
|
upstreamURL string
|
||||||
searchURL string
|
|
||||||
proxyURL string
|
proxyURL string
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -27,20 +24,10 @@ func NewNuGetHandler(proxy *Proxy, proxyURL string) *NuGetHandler {
|
||||||
return &NuGetHandler{
|
return &NuGetHandler{
|
||||||
proxy: proxy,
|
proxy: proxy,
|
||||||
upstreamURL: nugetUpstream,
|
upstreamURL: nugetUpstream,
|
||||||
searchURL: nugetSearchUpstream,
|
|
||||||
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewNuGetHandlerWithUpstreams creates a NuGet handler with custom API and
|
|
||||||
// search upstreams.
|
|
||||||
func NewNuGetHandlerWithUpstreams(proxy *Proxy, proxyURL, upstreamURL, searchURL string) *NuGetHandler {
|
|
||||||
h := NewNuGetHandler(proxy, proxyURL)
|
|
||||||
h.upstreamURL = configuredUpstreamURL(upstreamURL, nugetUpstream)
|
|
||||||
h.searchURL = configuredUpstreamURL(searchURL, nugetSearchUpstream)
|
|
||||||
return h
|
|
||||||
}
|
|
||||||
|
|
||||||
// Routes returns the HTTP handler for NuGet requests.
|
// Routes returns the HTTP handler for NuGet requests.
|
||||||
func (h *NuGetHandler) Routes() http.Handler {
|
func (h *NuGetHandler) Routes() http.Handler {
|
||||||
mux := http.NewServeMux()
|
mux := http.NewServeMux()
|
||||||
|
|
@ -50,12 +37,10 @@ func (h *NuGetHandler) Routes() http.Handler {
|
||||||
|
|
||||||
// Package content (downloads)
|
// Package content (downloads)
|
||||||
mux.HandleFunc("GET /v3-flatcontainer/{id}/{version}/{filename}", h.handleDownload)
|
mux.HandleFunc("GET /v3-flatcontainer/{id}/{version}/{filename}", h.handleDownload)
|
||||||
mux.HandleFunc("GET /v3-flatcontainer/{id}/index.json", h.handleVersionList)
|
mux.HandleFunc("GET /v3-flatcontainer/{id}/index.json", h.proxyUpstream)
|
||||||
|
|
||||||
// Registration (package metadata) - use prefix matching since {version}.json isn't allowed
|
// Registration (package metadata) - use prefix matching since {version}.json isn't allowed
|
||||||
for _, prefix := range nugetRegistrationPrefixes {
|
mux.HandleFunc("GET /v3/registration5-gz-semver2/", h.proxyUpstream)
|
||||||
mux.HandleFunc("GET "+prefix, h.handleRegistration)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Search
|
// Search
|
||||||
mux.HandleFunc("GET /query", h.proxyUpstream)
|
mux.HandleFunc("GET /query", h.proxyUpstream)
|
||||||
|
|
@ -72,30 +57,41 @@ func (h *NuGetHandler) handleServiceIndex(w http.ResponseWriter, r *http.Request
|
||||||
|
|
||||||
upstreamURL := h.upstreamURL + "/v3/index.json"
|
upstreamURL := h.upstreamURL + "/v3/index.json"
|
||||||
|
|
||||||
body, _, err := h.proxy.FetchOrCacheMetadata(r.Context(), "nuget", "_service_index", upstreamURL)
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, upstreamURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, "failed to create request", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.DefaultClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if errors.Is(err, ErrUpstreamNotFound) {
|
|
||||||
http.Error(w, "not found", http.StatusNotFound)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Error("upstream request failed", "error", err)
|
h.proxy.Logger.Error("upstream request failed", "error", err)
|
||||||
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
if resp.StatusCode != http.StatusOK {
|
||||||
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
body, err := io.ReadAll(resp.Body)
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, "failed to read response", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
rewritten, err := h.rewriteServiceIndex(body)
|
rewritten, err := h.rewriteServiceIndex(body)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if h.cooldownEnabled() {
|
|
||||||
h.nugetMetadataError(w, err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
h.proxy.Logger.Warn("failed to rewrite service index, proxying original", "error", err)
|
h.proxy.Logger.Warn("failed to rewrite service index, proxying original", "error", err)
|
||||||
w.Header().Set(headerContentType, "application/json")
|
w.Header().Set("Content-Type", "application/json")
|
||||||
_, _ = w.Write(body)
|
_, _ = w.Write(body)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
w.Header().Set(headerContentType, "application/json")
|
w.Header().Set("Content-Type", "application/json")
|
||||||
_, _ = w.Write(rewritten)
|
_, _ = w.Write(rewritten)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -120,35 +116,55 @@ func (h *NuGetHandler) rewriteServiceIndex(body []byte) ([]byte, error) {
|
||||||
id, _ := rmap["@id"].(string)
|
id, _ := rmap["@id"].(string)
|
||||||
rtype, _ := rmap["@type"].(string)
|
rtype, _ := rmap["@type"].(string)
|
||||||
|
|
||||||
// Rewrite URLs for services we proxy. The service type determines the
|
// Rewrite URLs for services we proxy
|
||||||
// local route because an upstream index may advertise a different host.
|
if id != "" && h.shouldRewriteService(rtype) {
|
||||||
if id != "" {
|
newURL := h.rewriteNuGetURL(id)
|
||||||
rmap["@id"] = h.rewriteNuGetURL(id, rtype)
|
rmap["@id"] = newURL
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return json.Marshal(index)
|
return json.Marshal(index)
|
||||||
}
|
}
|
||||||
|
|
||||||
// rewriteNuGetURL rewrites a NuGet service URL based on its advertised type.
|
// shouldRewriteService returns true if the service type should be rewritten.
|
||||||
// Service types the proxy does not handle are returned unchanged.
|
func (h *NuGetHandler) shouldRewriteService(serviceType string) bool {
|
||||||
func (h *NuGetHandler) rewriteNuGetURL(origURL, serviceType string) string {
|
// Rewrite package content and registration services
|
||||||
switch serviceType {
|
rewriteTypes := []string{
|
||||||
case "PackageBaseAddress/3.0.0":
|
"PackageBaseAddress/3.0.0",
|
||||||
return h.proxyURL + "/nuget/v3-flatcontainer/"
|
"RegistrationsBaseUrl/3.6.0",
|
||||||
case "RegistrationsBaseUrl", "RegistrationsBaseUrl/3.0.0-beta", "RegistrationsBaseUrl/3.0.0-rc":
|
"RegistrationsBaseUrl/Versioned",
|
||||||
return h.proxyURL + "/nuget/v3/registration5-semver1/"
|
"SearchQueryService",
|
||||||
case "RegistrationsBaseUrl/3.4.0":
|
"SearchQueryService/3.0.0-rc",
|
||||||
return h.proxyURL + "/nuget/v3/registration5-gz-semver1/"
|
"SearchQueryService/3.5.0",
|
||||||
case "RegistrationsBaseUrl/3.6.0", "RegistrationsBaseUrl/Versioned":
|
"SearchAutocompleteService",
|
||||||
return h.proxyURL + "/nuget/v3/registration5-gz-semver2/"
|
"SearchAutocompleteService/3.5.0",
|
||||||
case "SearchQueryService", "SearchQueryService/3.0.0-rc", "SearchQueryService/3.5.0":
|
|
||||||
return h.proxyURL + "/nuget/query"
|
|
||||||
case "SearchAutocompleteService", "SearchAutocompleteService/3.5.0":
|
|
||||||
return h.proxyURL + "/nuget/autocomplete"
|
|
||||||
default:
|
|
||||||
return origURL
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
for _, t := range rewriteTypes {
|
||||||
|
if serviceType == t {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
// rewriteNuGetURL rewrites a NuGet API URL to point at this proxy.
|
||||||
|
func (h *NuGetHandler) rewriteNuGetURL(origURL string) string {
|
||||||
|
// Map known NuGet API endpoints to our proxy paths
|
||||||
|
replacements := map[string]string{
|
||||||
|
"https://api.nuget.org/v3-flatcontainer/": h.proxyURL + "/nuget/v3-flatcontainer/",
|
||||||
|
"https://api.nuget.org/v3/registration5-gz-semver2/": h.proxyURL + "/nuget/v3/registration5-gz-semver2/",
|
||||||
|
"https://azuresearch-usnc.nuget.org/query": h.proxyURL + "/nuget/query",
|
||||||
|
"https://azuresearch-usnc.nuget.org/autocomplete": h.proxyURL + "/nuget/autocomplete",
|
||||||
|
}
|
||||||
|
|
||||||
|
for old, new := range replacements {
|
||||||
|
if strings.HasPrefix(origURL, old) {
|
||||||
|
return strings.Replace(origURL, old, new, 1)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return origURL
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleDownload serves a package file, fetching and caching from upstream if needed.
|
// handleDownload serves a package file, fetching and caching from upstream if needed.
|
||||||
|
|
@ -162,18 +178,6 @@ func (h *NuGetHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
if h.cooldownEnabled() {
|
|
||||||
allowed, err := h.nugetDownloadAllowed(r.Context(), id, version)
|
|
||||||
if err != nil {
|
|
||||||
h.nugetMetadataError(w, err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if !allowed {
|
|
||||||
JSONError(w, http.StatusNotFound, "version not found")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Only cache .nupkg files
|
// Only cache .nupkg files
|
||||||
if !strings.HasSuffix(filename, ".nupkg") {
|
if !strings.HasSuffix(filename, ".nupkg") {
|
||||||
h.proxyUpstream(w, r)
|
h.proxyUpstream(w, r)
|
||||||
|
|
@ -189,7 +193,8 @@ func (h *NuGetHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
||||||
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "nuget", name, version, filename, upstreamURL)
|
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "nuget", name, version, filename, upstreamURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.serveArtifactError(w, err, "failed to fetch package")
|
h.proxy.Logger.Error("failed to get artifact", "error", err)
|
||||||
|
http.Error(w, "failed to fetch package", http.StatusBadGateway)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -210,11 +215,11 @@ func (h *NuGetHandler) proxyUpstream(w http.ResponseWriter, r *http.Request) {
|
||||||
}
|
}
|
||||||
|
|
||||||
// Copy accept-encoding for compression
|
// Copy accept-encoding for compression
|
||||||
if ae := r.Header.Get(headerAcceptEncoding); ae != "" {
|
if ae := r.Header.Get("Accept-Encoding"); ae != "" {
|
||||||
req.Header.Set(headerAcceptEncoding, ae)
|
req.Header.Set("Accept-Encoding", ae)
|
||||||
}
|
}
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
resp, err := http.DefaultClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.Logger.Error("upstream request failed", "error", err)
|
h.proxy.Logger.Error("upstream request failed", "error", err)
|
||||||
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
http.Error(w, "upstream request failed", http.StatusBadGateway)
|
||||||
|
|
@ -238,7 +243,7 @@ func (h *NuGetHandler) buildUpstreamURL(r *http.Request) string {
|
||||||
|
|
||||||
// Handle query and autocomplete which go to azuresearch
|
// Handle query and autocomplete which go to azuresearch
|
||||||
if strings.HasPrefix(path, "/query") || strings.HasPrefix(path, "/autocomplete") {
|
if strings.HasPrefix(path, "/query") || strings.HasPrefix(path, "/autocomplete") {
|
||||||
return h.searchURL + path + "?" + r.URL.RawQuery
|
return "https://azuresearch-usnc.nuget.org" + path + "?" + r.URL.RawQuery
|
||||||
}
|
}
|
||||||
|
|
||||||
return h.upstreamURL + path
|
return h.upstreamURL + path
|
||||||
|
|
|
||||||
Some files were not shown because too many files have changed in this diff Show more
Loading…
Reference in a new issue