Skip to main content

isb_apps/build/
mod.rs

1//! Builds: turn a source tree into an OCI image in the org's registry.
2//!
3//! Every build runs in a fresh sandbox in the org's own incus project, never
4//! on the host, and the sandbox is deleted afterwards (also on failure and
5//! timeout):
6//!
7//! - **A container by default.** BuildKit runs as root inside an ordinary
8//!   unprivileged org container (its own uid range, the org's network and
9//!   ACL, the org's quota); its `RUN` steps get their own namespaces
10//!   without `security.nesting`, which the org project keeps blocked.
11//! - **A VM when the source is untrusted** ([`BuildRequest::untrusted`]):
12//!   the build gets its own kernel. The org project allows VMs; the host
13//!   needs KVM.
14//!
15//! The source is copied in (the host tree is only read), the image is
16//! exported as an OCI layout inside the sandbox, and the daemon copies it
17//! out and pushes it to the local registry ([`crate::registry`]): build
18//! sandboxes have neither a route to the registry nor credentials for it.
19//! BuildKit's state lives on a per-app volume in the org
20//! (`build-cache-<app>`), so the next build of the app reuses layers and
21//! cache mounts.
22//!
23//! The builder image (BuildKit, railpack, nixpacks; see `builder-image.sh`)
24//! is prepared once per recipe in the `isb-system` project and cached as a
25//! local incus image, `isb-builder/<recipe hash>`.
26
27use std::io::Write;
28use std::path::{Path, PathBuf};
29use std::sync::Mutex;
30use std::time::{Duration, Instant};
31
32use serde::{Deserialize, Serialize};
33use serde_json::{Value, json};
34
35use crate::client::{Client, encode_segment};
36use crate::error::{Error, Result};
37use crate::exec::{ExecEvent, ExecOptions, Stdin};
38use crate::org::OrgId;
39use crate::sandbox::Sandbox;
40mod ready;
41pub mod workspace_image;
42/// How a source tree becomes an image.
43#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
44#[serde(tag = "type", rename_all = "lowercase")]
45pub enum Builder {
46    /// Railpack detects the language and builds without a Dockerfile.
47    Railpack,
48    Nixpacks,
49    /// A Dockerfile, relative to the context.
50    Dockerfile {
51        #[serde(default = "default_dockerfile")]
52        path: String,
53        #[serde(default, skip_serializing_if = "Option::is_none")]
54        target: Option<String>,
55    },
56    /// Cloud Native Buildpacks with the given builder image. Not supported
57    /// yet: `pack` drives a docker daemon (see docs/guides/builds.md).
58    Buildpacks {
59        #[serde(default, skip_serializing_if = "Option::is_none")]
60        builder: Option<String>,
61    },
62}
63
64fn default_dockerfile() -> String {
65    "Dockerfile".into()
66}
67
68impl Builder {
69    fn name(&self) -> &'static str {
70        match self {
71            Builder::Railpack => "railpack",
72            Builder::Nixpacks => "nixpacks",
73            Builder::Dockerfile { .. } => "dockerfile",
74            Builder::Buildpacks { .. } => "buildpacks",
75        }
76    }
77}
78
79/// One build.
80#[derive(Debug, Clone)]
81pub struct BuildRequest {
82    pub org: OrgId,
83    /// The app the image belongs to: names the repository in the registry
84    /// (`<org>/<app>`) and the build cache volume.
85    pub app: String,
86    /// A checked-out source tree on the host. The build reads it, never
87    /// writes it.
88    pub context: PathBuf,
89    /// A subdirectory of `context` to build from.
90    pub subdir: Option<String>,
91    pub builder: Builder,
92    /// Build-time variables (Dockerfile `ARG`s, buildpack env).
93    pub args: Vec<(String, String)>,
94    /// The tag to push, e.g. the commit SHA.
95    pub tag: String,
96    /// Build in a VM rather than a container.
97    pub untrusted: bool,
98    /// Whose build cache volume to use (default: the app's). Previews
99    /// build with their own, so a pull request cannot poison the cache
100    /// production builds read.
101    pub cache: Option<String>,
102}
103
104/// What a build produced.
105#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
106pub struct BuiltImage {
107    /// What a compose `image:` takes to run it: `registry:<app>:<tag>@<digest>`,
108    /// resolved in the org the stack runs in (so pinned to this build even
109    /// if the tag moves later).
110    pub image: String,
111    /// The manifest digest (`sha256:...`), for rollbacks that must not
112    /// follow a moved tag.
113    pub digest: String,
114}
115
116/// Limits for a build. [`BuildOptions::default`] reads `ISB_BUILD_TIMEOUT`,
117/// `ISB_BUILD_CPUS`, `ISB_BUILD_MEMORY` and `ISB_BUILD_CACHE_SIZE`.
118#[derive(Debug, Clone)]
119pub struct BuildOptions {
120    /// The whole build, sandbox creation to push (default 30 minutes).
121    pub timeout: Duration,
122    /// The build sandbox's CPUs (default 2) and memory (default 4GiB),
123    /// counted against the org's quota.
124    pub cpus: u32,
125    pub memory: String,
126    /// A VM build's cache disk (default 20GiB); a container's cache volume
127    /// is a directory, bounded by BuildKit's own garbage collection.
128    pub cache_size: String,
129    /// Largest source tree copied in (default 2 GiB).
130    pub max_context: u64,
131}
132
133impl Default for BuildOptions {
134    fn default() -> Self {
135        let env = |k: &str| std::env::var(k).ok().filter(|v| !v.is_empty());
136        BuildOptions {
137            timeout: env("ISB_BUILD_TIMEOUT")
138                .and_then(|t| crate::flex::parse_duration(&t).ok())
139                .unwrap_or(Duration::from_secs(30 * 60)),
140            cpus: env("ISB_BUILD_CPUS")
141                .and_then(|c| c.parse().ok())
142                .unwrap_or(2),
143            memory: env("ISB_BUILD_MEMORY").unwrap_or_else(|| "4GiB".into()),
144            cache_size: env("ISB_BUILD_CACHE_SIZE").unwrap_or_else(|| "20GiB".into()),
145            max_context: 2 << 30,
146        }
147    }
148}
149
150/// The railpack BuildKit frontend, matching the railpack in the image.
151const RAILPACK_FRONTEND: &str = "ghcr.io/railwayapp/railpack-frontend:v0.40.1@sha256:f1973377693af30c9b37a92c97c661c07b277ccdc6be909213c74c771f8d2d6d";
152const RECIPE: &str = include_str!("builder-image.sh");
153const DRIVER: &str = include_str!("build.sh");
154/// The base the builder image is made from.
155const BASE_IMAGE: &str = "images:ubuntu/24.04";
156/// The VM's cache disk, as its by-id name ends.
157const CACHE_DEVICE: &str = "isbcache";
158
159/// The builder image's alias: `isb-builder/<hash>` (containers) or
160/// `isb-builder-vm/<hash>`. A new recipe is a new alias.
161pub fn builder_alias(vm: bool) -> String {
162    let d = crate::registry::oci::digest_of(RECIPE.as_bytes());
163    let h = &d[7..19];
164    if vm {
165        format!("isb-builder-vm/{h}")
166    } else {
167        format!("isb-builder/{h}")
168    }
169}
170
171/// Run a build with `base` (an unscoped client; the build's sandbox lives
172/// in the request's org), streaming its log lines to `log`.
173pub fn run(base: &Client, req: &BuildRequest, log: &mut dyn FnMut(&str)) -> Result<BuiltImage> {
174    run_with(base, req, &BuildOptions::default(), log)
175}
176
177/// [`run`] with explicit limits.
178#[expect(
179    clippy::too_many_lines,
180    reason = "predates the lint ratchet; split it when next changed"
181)]
182pub fn run_with(
183    base: &Client,
184    req: &BuildRequest,
185    opts: &BuildOptions,
186    log: &mut dyn FnMut(&str),
187) -> Result<BuiltImage> {
188    let started = Instant::now();
189    let deadline = started + opts.timeout;
190    let ctx_dir = check(req)?;
191    let reg = crate::registry::Registry::shared(base)?;
192    let vm = req.untrusted;
193    let oc = crate::org::client(base, &req.org);
194    crate::org::get(base, &req.org)?;
195    log(&format!(
196        "building {}/{}:{} with {} in a {}",
197        req.org,
198        req.app,
199        req.tag,
200        req.builder.name(),
201        if vm { "VM" } else { "container" }
202    ));
203    let image = ensure_builder_image(base, vm, deadline, log)?;
204    let pool = crate::sandbox::host_facts(&oc)?.pick_pool(None)?;
205    let cache = ensure_cache(
206        &oc,
207        &pool,
208        req.cache.as_deref().unwrap_or(&req.app),
209        vm,
210        &opts.cache_size,
211        log,
212    )?;
213
214    let name = sandbox_name(&req.app);
215    let _guard = Remove {
216        client: oc.clone(),
217        name: name.clone(),
218    };
219    log(&format!("creating build sandbox {name}"));
220    create_sandbox(
221        &oc, &name, &image, vm, &pool, &cache, opts, &req.app, deadline,
222    )?;
223    let sb = Sandbox::get(&oc, &name)?;
224    ready::exec(&sb, deadline)?;
225
226    let sent = send_context(&sb, &ctx_dir, opts.max_context, deadline)?;
227    log(&format!("copied the source in ({})", human(sent)));
228    oc.push_file(&name, "/build/build.sh", DRIVER.as_bytes(), 0, 0, 0o755)?;
229    let mut args = String::new();
230    for (k, v) in &req.args {
231        args.push_str(&format!("{k}={v}\n"));
232    }
233    oc.push_file(&name, "/build/args", args.as_bytes(), 0, 0, 0o600)?;
234
235    let mut env = ExecOptions::default()
236        .env("ISB_BUILDER", req.builder.name())
237        .env("ISB_RAILPACK_FRONTEND", RAILPACK_FRONTEND)
238        .env("HOME", "/root")
239        .env(
240            "PATH",
241            "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
242        )
243        .env(
244            "ISB_CONTEXT",
245            match &req.subdir {
246                Some(s) => format!("/build/src/{s}"),
247                None => "/build/src".into(),
248            },
249        );
250    if let Builder::Dockerfile { path, target } = &req.builder {
251        env = env.env("ISB_DOCKERFILE", path.clone());
252        if let Some(t) = target {
253            env = env.env("ISB_TARGET", t.clone());
254        }
255    }
256    if vm {
257        env = env.env("ISB_CACHE_DISK", CACHE_DEVICE);
258    }
259    let code = stream_lines(
260        &sb,
261        &["/bin/bash", "/build/build.sh"],
262        env.timeout(remaining(deadline, "the build")?),
263        log,
264    )
265    .map_err(|e| {
266        if e.is_timeout() || Instant::now() >= deadline {
267            Error::invalid(format!(
268                "build of {}/{} timed out after {:?} (killed)",
269                req.org, req.app, opts.timeout
270            ))
271        } else {
272            e
273        }
274    })?;
275    if code != 0 {
276        return Err(if Instant::now() >= deadline {
277            Error::invalid(format!(
278                "build of {}/{} timed out after {:?}",
279                req.org, req.app, opts.timeout
280            ))
281        } else {
282            Error::invalid(format!(
283                "build of {}/{} failed (exit {code}); see the log above",
284                req.org, req.app
285            ))
286        });
287    }
288
289    let tmp = scratch_file(&req.app)?;
290    let _rm = RemoveFile(tmp.clone());
291    let n = copy_out(&sb, "/build/out/image.tar", &tmp, deadline)?;
292    log(&format!("copied the image out ({})", human(n)));
293    let digest = reg.push(&req.org, &req.app, &req.tag, &tmp, log)?;
294    let image = format!(
295        "registry:{}",
296        crate::registry::ImageRef {
297            app: req.app.clone(),
298            tag: Some(req.tag.clone()),
299            digest: Some(digest.clone()),
300        }
301        .render()
302    );
303    log(&format!(
304        "built {image} in {:.0}s",
305        started.elapsed().as_secs_f64()
306    ));
307    Ok(BuiltImage { image, digest })
308}
309
310/// Validate a request; returns the directory to copy in.
311fn check(req: &BuildRequest) -> Result<PathBuf> {
312    if !crate::registry::valid_app(&req.app) || req.app.len() > 40 {
313        return Err(Error::invalid(format!(
314            "app {:?}: up to 40 characters of [a-z0-9._-], starting with a letter or digit",
315            req.app
316        )));
317    }
318    if !crate::registry::valid_tag(&req.tag) {
319        return Err(Error::invalid(format!(
320            "tag {:?}: [A-Za-z0-9_][A-Za-z0-9_.-]*, at most 128 characters",
321            req.tag
322        )));
323    }
324    let rel_ok = |p: &str| {
325        !p.is_empty()
326            && !p.starts_with('/')
327            && Path::new(p)
328                .components()
329                .all(|c| matches!(c, std::path::Component::Normal(_)))
330    };
331    if let Some(s) = &req.subdir {
332        if !rel_ok(s) {
333            return Err(Error::invalid(format!(
334                "subdir {s:?}: a relative path inside the context"
335            )));
336        }
337    }
338    match &req.builder {
339        Builder::Dockerfile { path, target } => {
340            if !rel_ok(path) {
341                return Err(Error::invalid(format!(
342                    "dockerfile {path:?}: a relative path inside the context"
343                )));
344            }
345            if target.as_deref().is_some_and(|t| {
346                t.is_empty()
347                    || !t
348                        .chars()
349                        .all(|c| c.is_ascii_alphanumeric() || "_.-".contains(c))
350            }) {
351                return Err(Error::invalid("target: a stage name"));
352            }
353        }
354        Builder::Buildpacks { .. } => {
355            return Err(Error::invalid(
356                "buildpacks are not supported yet: pack needs a docker daemon; use railpack (it detects the same languages) or a Dockerfile",
357            ));
358        }
359        _ => {}
360    }
361    for (k, v) in &req.args {
362        let ok = !k.is_empty()
363            && !k.starts_with(|c: char| c.is_ascii_digit())
364            && k.chars().all(|c| c.is_ascii_alphanumeric() || c == '_');
365        if !ok {
366            return Err(Error::invalid(format!(
367                "build argument {k:?}: [A-Za-z_][A-Za-z0-9_]*"
368            )));
369        }
370        if v.contains(['\n', '\r', '\0']) {
371            return Err(Error::invalid(format!(
372                "build argument {k}: values are one line"
373            )));
374        }
375    }
376    let dir = match &req.subdir {
377        Some(s) => req.context.join(s),
378        None => req.context.clone(),
379    };
380    let md = std::fs::metadata(&req.context)
381        .map_err(|e| Error::invalid(format!("context {}: {e}", req.context.display())))?;
382    if !md.is_dir() || !req.context.is_absolute() {
383        return Err(Error::invalid(format!(
384            "context {}: an absolute directory",
385            req.context.display()
386        )));
387    }
388    if !dir.is_dir() {
389        return Err(Error::invalid(format!(
390            "{} is not a directory",
391            dir.display()
392        )));
393    }
394    Ok(req.context.clone())
395}
396
397fn remaining(deadline: Instant, what: &str) -> Result<Duration> {
398    let r = deadline.saturating_duration_since(Instant::now());
399    if r.is_zero() {
400        return Err(Error::invalid(format!("build timed out before {what}")));
401    }
402    Ok(r)
403}
404
405fn human(n: u64) -> String {
406    match n {
407        n if n >= 1 << 30 => format!("{:.1} GiB", n as f64 / (1u64 << 30) as f64),
408        n if n >= 1 << 20 => format!("{:.1} MiB", n as f64 / (1u64 << 20) as f64),
409        n if n >= 1 << 10 => format!("{:.1} KiB", n as f64 / 1024.0),
410        n => format!("{n} B"),
411    }
412}
413
414/// `build-<app>-<random>`, an instance name.
415fn sandbox_name(app: &str) -> String {
416    let a: String = app
417        .chars()
418        .map(|c| if c.is_ascii_alphanumeric() { c } else { '-' })
419        .collect();
420    let a = a.trim_matches('-');
421    format!(
422        "build-{a}-{}{}",
423        crate::stack::new_id(),
424        crate::stack::new_id()
425    )
426}
427
428/// The name of a build cache volume: `build-cache-<key>`, `-vm` for VMs.
429pub fn cache_volume(key: &str, vm: bool) -> String {
430    let a = key.replace('.', "-");
431    if vm {
432        format!("build-cache-{a}-vm")
433    } else {
434        format!("build-cache-{a}")
435    }
436}
437
438/// The build cache volume of an app: `build-cache-<app>`, a filesystem
439/// volume for containers, a block volume (`-vm`) for VMs, whose overlay
440/// snapshots cannot live on a shared filesystem.
441fn ensure_cache(
442    oc: &Client,
443    pool: &str,
444    app: &str,
445    vm: bool,
446    size: &str,
447    log: &mut dyn FnMut(&str),
448) -> Result<String> {
449    let name = cache_volume(app, vm);
450    let path = format!(
451        "/1.0/storage-pools/{}/volumes/custom/{}",
452        encode_segment(pool),
453        encode_segment(&name)
454    );
455    if oc.get_opt(&path)?.is_none() {
456        log(&format!("creating build cache volume {name}"));
457        let mut body = json!({"name": name, "type": "custom", "config": {}});
458        if vm {
459            body["content_type"] = json!("block");
460            body["config"]["size"] = json!(size);
461        } else {
462            body["content_type"] = json!("filesystem");
463        }
464        match oc.mutate(
465            "POST",
466            &format!("/1.0/storage-pools/{}/volumes/custom", encode_segment(pool)),
467            Some(&body),
468            &format!("create volume {name}"),
469            oc.get_timeouts().other,
470        ) {
471            Ok(_) => {}
472            // Another build of the app made it first.
473            Err(e) if e.is_conflict() => {}
474            Err(e) => return Err(e),
475        }
476    }
477    Ok(name)
478}
479
480#[expect(clippy::too_many_arguments)]
481fn create_sandbox(
482    oc: &Client,
483    name: &str,
484    image: &str,
485    vm: bool,
486    pool: &str,
487    cache: &str,
488    opts: &BuildOptions,
489    app: &str,
490    deadline: Instant,
491) -> Result<()> {
492    let mut disk = json!({"type": "disk", "pool": pool, "source": cache});
493    // A VM gets a raw disk, which build.sh finds by this device name and
494    // formats once; a container, the directory itself.
495    if !vm {
496        disk["path"] = json!("/var/lib/buildkit");
497    }
498    let mut devices = json!({ CACHE_DEVICE: disk });
499    if vm {
500        // Room for the source, the export and BuildKit's scratch space.
501        devices["root"] = json!({"type": "disk", "path": "/", "pool": pool, "size": "20GiB"});
502    }
503    let body = json!({
504        "name": name,
505        "type": if vm { "virtual-machine" } else { "container" },
506        "source": {"type": "image", "alias": image},
507        "config": {
508            "limits.cpu": opts.cpus.to_string(),
509            "limits.memory": opts.memory,
510            "user.isb.build": app,
511        },
512        "devices": devices,
513        "profiles": ["default"],
514    });
515    let t = remaining(deadline, "creating the build sandbox")?;
516    oc.mutate(
517        "POST",
518        "/1.0/instances",
519        Some(&body),
520        &format!("create build sandbox {name}"),
521        t.min(oc.get_timeouts().create.max(Duration::from_secs(600))),
522    )?;
523    let t = remaining(deadline, "starting the build sandbox")?;
524    oc.mutate(
525        "PUT",
526        &format!("/1.0/instances/{}/state", encode_segment(name)),
527        Some(&json!({"action": "start", "timeout": 60})),
528        &format!("start build sandbox {name}"),
529        t.min(Duration::from_secs(300)),
530    )?;
531    Ok(())
532}
533
534/// Run argv, handing each output line to `log`. Returns the exit code.
535fn stream_lines(
536    sb: &Sandbox,
537    argv: &[&str],
538    opts: ExecOptions,
539    log: &mut dyn FnMut(&str),
540) -> Result<i32> {
541    let mut s = sb.exec_stream(argv.iter().copied(), opts)?;
542    let (mut out, mut err) = (Vec::new(), Vec::new());
543    let emit = |buf: &mut Vec<u8>, chunk: Vec<u8>, log: &mut dyn FnMut(&str)| {
544        buf.extend(chunk);
545        while let Some(i) = buf.iter().position(|b| *b == b'\n') {
546            let line: Vec<u8> = buf.drain(..=i).collect();
547            let text = String::from_utf8_lossy(&line[..line.len() - 1]);
548            log(text.trim_end_matches('\r'));
549        }
550        // A runaway line without newlines is cut rather than buffered.
551        if buf.len() > 64 << 10 {
552            log(&String::from_utf8_lossy(buf));
553            buf.clear();
554        }
555    };
556    while let Some(ev) = s.next_event() {
557        match ev {
558            ExecEvent::Stdout(b) => emit(&mut out, b, log),
559            ExecEvent::Stderr(b) => emit(&mut err, b, log),
560        }
561    }
562    for b in [out, err] {
563        if !b.is_empty() {
564            log(&String::from_utf8_lossy(&b));
565        }
566    }
567    // incus fails the operation, rather than reporting the code, when the
568    // command ends with 126 or 127, which a script can pass on.
569    match s.wait() {
570        Err(e) if e.to_string().contains("Command not found") => Ok(127),
571        Err(e) if e.to_string().contains("Permission denied") => Ok(126),
572        r => r,
573    }
574}
575
576/// Copy `dir` into the sandbox at `/build/src` as a tar on stdin. Returns
577/// the bytes sent.
578fn send_context(sb: &Sandbox, dir: &Path, max: u64, deadline: Instant) -> Result<u64> {
579    let mut s = sb.exec_stream(
580        [
581            "/bin/sh",
582            "-c",
583            "mkdir -p /build/src && tar -x --no-same-owner -C /build/src",
584        ],
585        ExecOptions::default()
586            .stdin(Stdin::Piped)
587            .timeout(remaining(deadline, "copying the source")?),
588    )?;
589    let mut w = ChunkWriter {
590        s: &s,
591        buf: Vec::with_capacity(CHUNK),
592        sent: 0,
593        max,
594    };
595    let r = tar::write_dir(&mut w, dir).and_then(|_| w.flush().map_err(Error::from));
596    let sent = w.sent;
597    s.close_stdin();
598    let out = s.collect_output()?;
599    r?;
600    if !out.success() {
601        return Err(Error::invalid(format!(
602            "copying the source in failed (exit {}): {}",
603            out.exit_code,
604            out.stderr_text().trim()
605        )));
606    }
607    Ok(sent)
608}
609
610const CHUNK: usize = 256 << 10;
611
612struct ChunkWriter<'a> {
613    s: &'a crate::exec::ExecStream,
614    buf: Vec<u8>,
615    sent: u64,
616    max: u64,
617}
618
619impl Write for ChunkWriter<'_> {
620    fn write(&mut self, b: &[u8]) -> std::io::Result<usize> {
621        self.sent += b.len() as u64;
622        if self.sent > self.max {
623            return Err(std::io::Error::other(format!(
624                "the source is over {} (ISB build limit)",
625                human(self.max)
626            )));
627        }
628        self.buf.extend_from_slice(b);
629        if self.buf.len() >= CHUNK {
630            self.flush()?;
631        }
632        Ok(b.len())
633    }
634
635    fn flush(&mut self) -> std::io::Result<()> {
636        if !self.buf.is_empty() {
637            self.s
638                .write_stdin(&self.buf)
639                .map_err(|e| std::io::Error::other(e.to_string()))?;
640            self.buf.clear();
641        }
642        Ok(())
643    }
644}
645
646/// Copy a file out of the sandbox through `cat`. Returns its size.
647fn copy_out(sb: &Sandbox, path: &str, to: &Path, deadline: Instant) -> Result<u64> {
648    let mut f = std::fs::File::create(to)?;
649    let mut s = sb.exec_stream(
650        ["/bin/cat", path],
651        ExecOptions::default().timeout(remaining(deadline, "copying the image out")?),
652    )?;
653    let mut n = 0u64;
654    let mut err = Vec::new();
655    while let Some(ev) = s.next_event() {
656        match ev {
657            ExecEvent::Stdout(b) => {
658                n += b.len() as u64;
659                f.write_all(&b)?;
660            }
661            ExecEvent::Stderr(b) => err.extend(b),
662        }
663    }
664    let code = s.wait()?;
665    if code != 0 {
666        return Err(Error::invalid(format!(
667            "copying {path} out failed (exit {code}): {}",
668            String::from_utf8_lossy(&err).trim()
669        )));
670    }
671    f.sync_all()?;
672    Ok(n)
673}
674
675/// Where the image is staged between the sandbox and the registry: the
676/// daemon's state directory (images can be large; /tmp may be a tmpfs).
677fn scratch_file(app: &str) -> Result<PathBuf> {
678    let dir = std::env::var_os("ISB_SERVE_STATE_DIR")
679        .map(PathBuf::from)
680        .unwrap_or_else(crate::stack::Store::default_dir)
681        .join("builds");
682    std::fs::create_dir_all(&dir)?;
683    Ok(dir.join(format!(
684        "{app}-{}{}.tar",
685        crate::stack::new_id(),
686        crate::stack::new_id()
687    )))
688}
689
690struct RemoveFile(PathBuf);
691
692impl Drop for RemoveFile {
693    fn drop(&mut self) {
694        let _ = std::fs::remove_file(&self.0);
695    }
696}
697
698/// Deletes the build sandbox however the build ends.
699struct Remove {
700    client: Client,
701    name: String,
702}
703
704impl Drop for Remove {
705    fn drop(&mut self) {
706        match Sandbox::remove(&self.client, &self.name, true) {
707            Ok(()) => {}
708            Err(e) if e.is_not_found() => {}
709            Err(e) => eprintln!("isb: build sandbox {}: not deleted: {e}", self.name),
710        }
711    }
712}
713
714/// One preparation at a time per process; the image is shared by all orgs.
715static PREPARE: Mutex<()> = Mutex::new(());
716
717/// The builder image's alias, made from `builder-image.sh` when missing: in the
718/// `isb-system` project, never in an org (an org could otherwise tamper
719/// with an image every org builds with).
720#[expect(
721    clippy::too_many_lines,
722    reason = "predates the lint ratchet; split it when next changed"
723)]
724pub fn ensure_builder_image(
725    base: &Client,
726    vm: bool,
727    deadline: Instant,
728    log: &mut dyn FnMut(&str),
729) -> Result<String> {
730    let alias = builder_alias(vm);
731    let h = base.clone().project("default");
732    let alias_path = format!("/1.0/images/aliases/{}", encode_segment(&alias));
733    if h.get_opt(&alias_path)?.is_some() {
734        return Ok(alias);
735    }
736    let _g = PREPARE.lock().unwrap();
737    if h.get_opt(&alias_path)?.is_some() {
738        return Ok(alias);
739    }
740    log(&format!(
741        "preparing the builder image {alias} (once per recipe; a few minutes)"
742    ));
743    let s = base.clone().project(crate::registry::PROJECT);
744    if crate::registry::info(base)?.is_none() {
745        return Err(Error::invalid(
746            "no isb-system project yet: run `isb registry setup` first",
747        ));
748    }
749    let pool = crate::sandbox::host_facts(&h)?.pick_pool(None)?;
750    let net = uplink_network(&h)?;
751    let name = format!(
752        "builder-prep-{}{}",
753        crate::stack::new_id(),
754        crate::stack::new_id()
755    );
756    let _guard = Remove {
757        client: s.clone(),
758        name: name.clone(),
759    };
760    let src = crate::plan::ImageSource::parse(BASE_IMAGE)?;
761    let config = json!({"limits.cpu": "4", "limits.memory": "4GiB"});
762    s.mutate(
763        "POST",
764        "/1.0/instances",
765        Some(&json!({
766            "name": name,
767            "type": if vm { "virtual-machine" } else { "container" },
768            "source": src.to_api(None),
769            "config": config,
770            "devices": {
771                "root": {"type": "disk", "path": "/", "pool": pool},
772                "eth0": {"type": "nic", "name": "eth0", "network": net},
773            },
774            "profiles": ["default"],
775        })),
776        &format!("create {name}"),
777        remaining(deadline, "creating the builder image")?.min(Duration::from_secs(1200)),
778    )?;
779    s.mutate(
780        "PUT",
781        &format!("/1.0/instances/{name}/state"),
782        Some(&json!({"action": "start", "timeout": 60})),
783        &format!("start {name}"),
784        Duration::from_secs(300),
785    )?;
786    let sb = Sandbox::get(&s, &name)?;
787    ready::exec(&sb, deadline)?;
788    ready::network(&s, &name, &net, deadline, log)?;
789    s.push_file(
790        &name,
791        "/root/builder-image.sh",
792        RECIPE.as_bytes(),
793        0,
794        0,
795        0o755,
796    )?;
797    let code = stream_lines(
798        &sb,
799        &["/bin/sh", "/root/builder-image.sh"],
800        ExecOptions::default()
801            .env(
802                "PATH",
803                "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
804            )
805            .timeout(remaining(deadline, "preparing the builder image")?),
806        &mut |l| log(&format!("prepare: {l}")),
807    )?;
808    if code != 0 {
809        return Err(Error::invalid(format!(
810            "preparing the builder image failed (exit {code})"
811        )));
812    }
813    // A clean shutdown, so a VM's disk has everything the recipe wrote.
814    let stop = |force: bool| {
815        s.mutate(
816            "PUT",
817            &format!("/1.0/instances/{name}/state"),
818            Some(&json!({"action": "stop", "timeout": 120, "force": force})),
819            &format!("stop {name}"),
820            Duration::from_secs(180),
821        )
822    };
823    if let Err(e) = stop(false) {
824        log(&format!("prepare: a clean stop failed ({e}); forcing it"));
825        stop(true)?;
826    }
827    log(&format!("publishing {alias}"));
828    let versions: Value = json!({
829        "description": format!("isb builder ({})", if vm { "VM" } else { "container" }),
830        "isb.recipe": alias,
831    });
832    s.mutate(
833        "POST",
834        "/1.0/images",
835        Some(&json!({
836            "source": {"type": "instance", "name": name},
837            "properties": versions,
838            "aliases": [{"name": alias, "description": "isb builder image"}],
839        })),
840        &format!("publish {alias}"),
841        remaining(deadline, "publishing the builder image")?.min(Duration::from_secs(1800)),
842    )?;
843    Ok(alias)
844}
845
846/// The network a builder image is prepared on: the host's default managed
847/// bridge (`incusbr0` if there is one), never an org's.
848fn uplink_network(h: &Client) -> Result<String> {
849    let nets = h.get("/1.0/networks?recursion=1")?;
850    let managed: Vec<&str> = nets
851        .as_array()
852        .into_iter()
853        .flatten()
854        .filter(|n| n["managed"].as_bool() == Some(true) && n["type"] == "bridge")
855        .filter_map(|n| n["name"].as_str())
856        .filter(|n| !n.starts_with("isbbr"))
857        .collect();
858    managed
859        .iter()
860        .find(|n| **n == "incusbr0")
861        .or(managed.first())
862        .map(|s| s.to_string())
863        .ok_or_else(|| Error::invalid("no managed bridge to prepare the builder image on"))
864}
865
866/// A tar writer for a source tree: regular files, directories and
867/// symlinks (as links, never followed), with pax headers for long names.
868pub(crate) mod tar {
869    use std::io::{Read, Write};
870    use std::os::unix::fs::{MetadataExt, PermissionsExt};
871    use std::path::Path;
872
873    use crate::error::Result;
874
875    fn octal(field: &mut [u8], v: u64) {
876        // Sizes are capped well below 8 GiB, so 11 digits always suffice.
877        let w = field.len() - 1;
878        let s = format!("{v:0w$o}");
879        let b = s.as_bytes();
880        let start = b.len().saturating_sub(w);
881        field[..w].copy_from_slice(&b[start..]);
882        field[w] = 0;
883    }
884
885    fn header(name: &str, size: u64, mode: u32, mtime: u64, kind: u8, link: &str) -> [u8; 512] {
886        let mut h = [0u8; 512];
887        let n = name.as_bytes();
888        h[..n.len().min(100)].copy_from_slice(&n[..n.len().min(100)]);
889        octal(&mut h[100..108], (mode & 0o7777) as u64);
890        octal(&mut h[108..116], 0);
891        octal(&mut h[116..124], 0);
892        octal(&mut h[124..136], size);
893        octal(&mut h[136..148], mtime);
894        h[156] = kind;
895        let l = link.as_bytes();
896        h[157..157 + l.len().min(100)].copy_from_slice(&l[..l.len().min(100)]);
897        h[257..263].copy_from_slice(b"ustar\0");
898        h[263..265].copy_from_slice(b"00");
899        h[148..156].copy_from_slice(b"        ");
900        let sum: u64 = h.iter().map(|b| *b as u64).sum();
901        let s = format!("{sum:06o}\0 ");
902        h[148..156].copy_from_slice(s.as_bytes());
903        h
904    }
905
906    fn pad(w: &mut dyn Write, n: u64) -> std::io::Result<()> {
907        let r = (512 - (n % 512) as usize) % 512;
908        w.write_all(&vec![0u8; r])
909    }
910
911    fn pax_record(key: &str, value: &str) -> String {
912        // "<len> key=value\n", where len counts itself.
913        let body = format!(" {key}={value}\n");
914        let mut len = body.len() + 1;
915        while format!("{len}{body}").len() != len {
916            len = format!("{len}{body}").len();
917        }
918        format!("{len}{body}")
919    }
920
921    fn entry(
922        w: &mut dyn Write,
923        name: &str,
924        size: u64,
925        mode: u32,
926        mtime: u64,
927        kind: u8,
928        link: &str,
929    ) -> std::io::Result<()> {
930        if name.len() > 100 || link.len() > 100 || !name.is_ascii() || !link.is_ascii() {
931            let mut pax = pax_record("path", name);
932            if !link.is_empty() {
933                pax.push_str(&pax_record("linkpath", link));
934            }
935            w.write_all(&header(
936                "././@PaxHeader",
937                pax.len() as u64,
938                0o644,
939                mtime,
940                b'x',
941                "",
942            ))?;
943            w.write_all(pax.as_bytes())?;
944            pad(w, pax.len() as u64)?;
945        }
946        w.write_all(&header(name, size, mode, mtime, kind, link))
947    }
948
949    /// Write `dir`'s contents (not `dir` itself) as a tar.
950    pub fn write_dir(w: &mut dyn Write, dir: &Path) -> Result<()> {
951        walk(w, dir, "")?;
952        w.write_all(&[0u8; 1024])?;
953        Ok(())
954    }
955
956    fn walk(w: &mut dyn Write, dir: &Path, prefix: &str) -> Result<()> {
957        let mut names: Vec<_> = std::fs::read_dir(dir)?
958            .filter_map(|e| e.ok())
959            .map(|e| e.file_name())
960            .collect();
961        names.sort();
962        for n in names {
963            let path = dir.join(&n);
964            let Some(n) = n.to_str() else {
965                // Not UTF-8: leave it out rather than mangle it.
966                continue;
967            };
968            let name = format!("{prefix}{n}");
969            let md = std::fs::symlink_metadata(&path)?;
970            let mtime = md.mtime().max(0) as u64;
971            let mode = md.permissions().mode();
972            let ft = md.file_type();
973            if ft.is_symlink() {
974                let target = std::fs::read_link(&path)?;
975                let Some(t) = target.to_str() else { continue };
976                entry(w, &name, 0, 0o777, mtime, b'2', t)?;
977            } else if ft.is_dir() {
978                entry(w, &format!("{name}/"), 0, mode, mtime, b'5', "")?;
979                walk(w, &path, &format!("{name}/"))?;
980            } else if ft.is_file() {
981                let mut f = std::fs::File::open(&path)?;
982                let size = md.len();
983                entry(w, &name, size, mode, mtime, b'0', "")?;
984                // Exactly `size` bytes, even if the file changes meanwhile.
985                let copied = std::io::copy(&mut (&mut f).take(size), w)?;
986                if copied < size {
987                    std::io::copy(&mut std::io::repeat(0).take(size - copied), w)?;
988                }
989                pad(w, size)?;
990            }
991            // Sockets, fifos and devices are not source.
992        }
993        Ok(())
994    }
995}
996
997#[cfg(test)]
998mod tests {
999    use super::*;
1000
1001    fn req(builder: Builder) -> BuildRequest {
1002        BuildRequest {
1003            org: OrgId::new("acme").unwrap(),
1004            app: "web".into(),
1005            context: std::env::temp_dir(),
1006            subdir: None,
1007            builder,
1008            args: vec![],
1009            tag: "v1".into(),
1010            untrusted: false,
1011            cache: None,
1012        }
1013    }
1014
1015    #[test]
1016    fn requests_are_checked() {
1017        assert!(check(&req(Builder::Railpack)).is_ok());
1018        let mut r = req(Builder::Railpack);
1019        r.app = "Web".into();
1020        assert!(check(&r).is_err());
1021        r = req(Builder::Railpack);
1022        r.tag = "bad tag".into();
1023        assert!(check(&r).is_err());
1024        r = req(Builder::Railpack);
1025        r.subdir = Some("../etc".into());
1026        assert!(check(&r).is_err());
1027        r = req(Builder::Dockerfile {
1028            path: "/etc/passwd".into(),
1029            target: None,
1030        });
1031        assert!(check(&r).is_err());
1032        r = req(Builder::Railpack);
1033        r.args = vec![("A B".into(), "x".into())];
1034        assert!(check(&r).is_err());
1035        r.args = vec![("A".into(), "x\ny".into())];
1036        assert!(check(&r).is_err());
1037        assert!(check(&req(Builder::Buildpacks { builder: None })).is_err());
1038        r = req(Builder::Railpack);
1039        r.context = "relative".into();
1040        assert!(check(&r).is_err());
1041    }
1042
1043    #[test]
1044    fn builder_json_matches_the_contract() {
1045        let b: Builder = serde_json::from_str(r#"{"type":"dockerfile"}"#).unwrap();
1046        assert_eq!(
1047            b,
1048            Builder::Dockerfile {
1049                path: "Dockerfile".into(),
1050                target: None
1051            }
1052        );
1053        let b: Builder = serde_json::from_str(r#"{"type":"railpack"}"#).unwrap();
1054        assert_eq!(b.name(), "railpack");
1055        assert!(builder_alias(false).starts_with("isb-builder/"));
1056        assert!(builder_alias(true).starts_with("isb-builder-vm/"));
1057        assert!(sandbox_name("my.app").starts_with("build-my-app-"));
1058        assert!(sandbox_name(&"a".repeat(40)).len() <= 63);
1059    }
1060
1061    #[test]
1062    fn source_tars_round_trip_through_the_layout_reader() {
1063        let d = tempfile::tempdir().unwrap();
1064        let root = d.path().join("src");
1065        std::fs::create_dir_all(root.join("sub")).unwrap();
1066        std::fs::write(root.join("a.txt"), "hello").unwrap();
1067        let long = "x".repeat(150);
1068        std::fs::write(root.join("sub").join(&long), "long").unwrap();
1069        std::os::unix::fs::symlink("/etc/shadow", root.join("link")).unwrap();
1070        let mut buf = Vec::new();
1071        tar::write_dir(&mut buf, &root).unwrap();
1072        let p = d.path().join("x.tar");
1073        std::fs::write(&p, &buf).unwrap();
1074        // The registry's tar reader is the same format's other half.
1075        let l = crate::registry::oci::Layout::open(&p).unwrap();
1076        let _ = l;
1077        // And the system tar agrees, when there is one.
1078        if let Ok(out) = std::process::Command::new("tar")
1079            .arg("-tvf")
1080            .arg(&p)
1081            .output()
1082        {
1083            if out.status.success() {
1084                let t = String::from_utf8_lossy(&out.stdout);
1085                assert!(t.contains("a.txt"), "{t}");
1086                assert!(t.contains(&format!("sub/{long}")), "{t}");
1087                assert!(
1088                    t.contains("link -> /etc/shadow"),
1089                    "symlinks stay links: {t}"
1090                );
1091            }
1092        }
1093    }
1094}