1use std::io::Write;
28use std::path::{Path, PathBuf};
29use std::sync::Mutex;
30use std::time::{Duration, Instant};
31
32use serde::{Deserialize, Serialize};
33use serde_json::{Value, json};
34
35use crate::client::{Client, encode_segment};
36use crate::error::{Error, Result};
37use crate::exec::{ExecEvent, ExecOptions, Stdin};
38use crate::org::OrgId;
39use crate::sandbox::Sandbox;
40mod ready;
41pub mod workspace_image;
42#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
44#[serde(tag = "type", rename_all = "lowercase")]
45pub enum Builder {
46 Railpack,
48 Nixpacks,
49 Dockerfile {
51 #[serde(default = "default_dockerfile")]
52 path: String,
53 #[serde(default, skip_serializing_if = "Option::is_none")]
54 target: Option<String>,
55 },
56 Buildpacks {
59 #[serde(default, skip_serializing_if = "Option::is_none")]
60 builder: Option<String>,
61 },
62}
63
64fn default_dockerfile() -> String {
65 "Dockerfile".into()
66}
67
68impl Builder {
69 fn name(&self) -> &'static str {
70 match self {
71 Builder::Railpack => "railpack",
72 Builder::Nixpacks => "nixpacks",
73 Builder::Dockerfile { .. } => "dockerfile",
74 Builder::Buildpacks { .. } => "buildpacks",
75 }
76 }
77}
78
79#[derive(Debug, Clone)]
81pub struct BuildRequest {
82 pub org: OrgId,
83 pub app: String,
86 pub context: PathBuf,
89 pub subdir: Option<String>,
91 pub builder: Builder,
92 pub args: Vec<(String, String)>,
94 pub tag: String,
96 pub untrusted: bool,
98 pub cache: Option<String>,
102}
103
104#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
106pub struct BuiltImage {
107 pub image: String,
111 pub digest: String,
114}
115
116#[derive(Debug, Clone)]
119pub struct BuildOptions {
120 pub timeout: Duration,
122 pub cpus: u32,
125 pub memory: String,
126 pub cache_size: String,
129 pub max_context: u64,
131}
132
133impl Default for BuildOptions {
134 fn default() -> Self {
135 let env = |k: &str| std::env::var(k).ok().filter(|v| !v.is_empty());
136 BuildOptions {
137 timeout: env("ISB_BUILD_TIMEOUT")
138 .and_then(|t| crate::flex::parse_duration(&t).ok())
139 .unwrap_or(Duration::from_secs(30 * 60)),
140 cpus: env("ISB_BUILD_CPUS")
141 .and_then(|c| c.parse().ok())
142 .unwrap_or(2),
143 memory: env("ISB_BUILD_MEMORY").unwrap_or_else(|| "4GiB".into()),
144 cache_size: env("ISB_BUILD_CACHE_SIZE").unwrap_or_else(|| "20GiB".into()),
145 max_context: 2 << 30,
146 }
147 }
148}
149
150const RAILPACK_FRONTEND: &str = "ghcr.io/railwayapp/railpack-frontend:v0.40.1@sha256:f1973377693af30c9b37a92c97c661c07b277ccdc6be909213c74c771f8d2d6d";
152const RECIPE: &str = include_str!("builder-image.sh");
153const DRIVER: &str = include_str!("build.sh");
154const BASE_IMAGE: &str = "images:ubuntu/24.04";
156const CACHE_DEVICE: &str = "isbcache";
158
159pub fn builder_alias(vm: bool) -> String {
162 let d = crate::registry::oci::digest_of(RECIPE.as_bytes());
163 let h = &d[7..19];
164 if vm {
165 format!("isb-builder-vm/{h}")
166 } else {
167 format!("isb-builder/{h}")
168 }
169}
170
171pub fn run(base: &Client, req: &BuildRequest, log: &mut dyn FnMut(&str)) -> Result<BuiltImage> {
174 run_with(base, req, &BuildOptions::default(), log)
175}
176
177#[expect(
179 clippy::too_many_lines,
180 reason = "predates the lint ratchet; split it when next changed"
181)]
182pub fn run_with(
183 base: &Client,
184 req: &BuildRequest,
185 opts: &BuildOptions,
186 log: &mut dyn FnMut(&str),
187) -> Result<BuiltImage> {
188 let started = Instant::now();
189 let deadline = started + opts.timeout;
190 let ctx_dir = check(req)?;
191 let reg = crate::registry::Registry::shared(base)?;
192 let vm = req.untrusted;
193 let oc = crate::org::client(base, &req.org);
194 crate::org::get(base, &req.org)?;
195 log(&format!(
196 "building {}/{}:{} with {} in a {}",
197 req.org,
198 req.app,
199 req.tag,
200 req.builder.name(),
201 if vm { "VM" } else { "container" }
202 ));
203 let image = ensure_builder_image(base, vm, deadline, log)?;
204 let pool = crate::sandbox::host_facts(&oc)?.pick_pool(None)?;
205 let cache = ensure_cache(
206 &oc,
207 &pool,
208 req.cache.as_deref().unwrap_or(&req.app),
209 vm,
210 &opts.cache_size,
211 log,
212 )?;
213
214 let name = sandbox_name(&req.app);
215 let _guard = Remove {
216 client: oc.clone(),
217 name: name.clone(),
218 };
219 log(&format!("creating build sandbox {name}"));
220 create_sandbox(
221 &oc, &name, &image, vm, &pool, &cache, opts, &req.app, deadline,
222 )?;
223 let sb = Sandbox::get(&oc, &name)?;
224 ready::exec(&sb, deadline)?;
225
226 let sent = send_context(&sb, &ctx_dir, opts.max_context, deadline)?;
227 log(&format!("copied the source in ({})", human(sent)));
228 oc.push_file(&name, "/build/build.sh", DRIVER.as_bytes(), 0, 0, 0o755)?;
229 let mut args = String::new();
230 for (k, v) in &req.args {
231 args.push_str(&format!("{k}={v}\n"));
232 }
233 oc.push_file(&name, "/build/args", args.as_bytes(), 0, 0, 0o600)?;
234
235 let mut env = ExecOptions::default()
236 .env("ISB_BUILDER", req.builder.name())
237 .env("ISB_RAILPACK_FRONTEND", RAILPACK_FRONTEND)
238 .env("HOME", "/root")
239 .env(
240 "PATH",
241 "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
242 )
243 .env(
244 "ISB_CONTEXT",
245 match &req.subdir {
246 Some(s) => format!("/build/src/{s}"),
247 None => "/build/src".into(),
248 },
249 );
250 if let Builder::Dockerfile { path, target } = &req.builder {
251 env = env.env("ISB_DOCKERFILE", path.clone());
252 if let Some(t) = target {
253 env = env.env("ISB_TARGET", t.clone());
254 }
255 }
256 if vm {
257 env = env.env("ISB_CACHE_DISK", CACHE_DEVICE);
258 }
259 let code = stream_lines(
260 &sb,
261 &["/bin/bash", "/build/build.sh"],
262 env.timeout(remaining(deadline, "the build")?),
263 log,
264 )
265 .map_err(|e| {
266 if e.is_timeout() || Instant::now() >= deadline {
267 Error::invalid(format!(
268 "build of {}/{} timed out after {:?} (killed)",
269 req.org, req.app, opts.timeout
270 ))
271 } else {
272 e
273 }
274 })?;
275 if code != 0 {
276 return Err(if Instant::now() >= deadline {
277 Error::invalid(format!(
278 "build of {}/{} timed out after {:?}",
279 req.org, req.app, opts.timeout
280 ))
281 } else {
282 Error::invalid(format!(
283 "build of {}/{} failed (exit {code}); see the log above",
284 req.org, req.app
285 ))
286 });
287 }
288
289 let tmp = scratch_file(&req.app)?;
290 let _rm = RemoveFile(tmp.clone());
291 let n = copy_out(&sb, "/build/out/image.tar", &tmp, deadline)?;
292 log(&format!("copied the image out ({})", human(n)));
293 let digest = reg.push(&req.org, &req.app, &req.tag, &tmp, log)?;
294 let image = format!(
295 "registry:{}",
296 crate::registry::ImageRef {
297 app: req.app.clone(),
298 tag: Some(req.tag.clone()),
299 digest: Some(digest.clone()),
300 }
301 .render()
302 );
303 log(&format!(
304 "built {image} in {:.0}s",
305 started.elapsed().as_secs_f64()
306 ));
307 Ok(BuiltImage { image, digest })
308}
309
310fn check(req: &BuildRequest) -> Result<PathBuf> {
312 if !crate::registry::valid_app(&req.app) || req.app.len() > 40 {
313 return Err(Error::invalid(format!(
314 "app {:?}: up to 40 characters of [a-z0-9._-], starting with a letter or digit",
315 req.app
316 )));
317 }
318 if !crate::registry::valid_tag(&req.tag) {
319 return Err(Error::invalid(format!(
320 "tag {:?}: [A-Za-z0-9_][A-Za-z0-9_.-]*, at most 128 characters",
321 req.tag
322 )));
323 }
324 let rel_ok = |p: &str| {
325 !p.is_empty()
326 && !p.starts_with('/')
327 && Path::new(p)
328 .components()
329 .all(|c| matches!(c, std::path::Component::Normal(_)))
330 };
331 if let Some(s) = &req.subdir {
332 if !rel_ok(s) {
333 return Err(Error::invalid(format!(
334 "subdir {s:?}: a relative path inside the context"
335 )));
336 }
337 }
338 match &req.builder {
339 Builder::Dockerfile { path, target } => {
340 if !rel_ok(path) {
341 return Err(Error::invalid(format!(
342 "dockerfile {path:?}: a relative path inside the context"
343 )));
344 }
345 if target.as_deref().is_some_and(|t| {
346 t.is_empty()
347 || !t
348 .chars()
349 .all(|c| c.is_ascii_alphanumeric() || "_.-".contains(c))
350 }) {
351 return Err(Error::invalid("target: a stage name"));
352 }
353 }
354 Builder::Buildpacks { .. } => {
355 return Err(Error::invalid(
356 "buildpacks are not supported yet: pack needs a docker daemon; use railpack (it detects the same languages) or a Dockerfile",
357 ));
358 }
359 _ => {}
360 }
361 for (k, v) in &req.args {
362 let ok = !k.is_empty()
363 && !k.starts_with(|c: char| c.is_ascii_digit())
364 && k.chars().all(|c| c.is_ascii_alphanumeric() || c == '_');
365 if !ok {
366 return Err(Error::invalid(format!(
367 "build argument {k:?}: [A-Za-z_][A-Za-z0-9_]*"
368 )));
369 }
370 if v.contains(['\n', '\r', '\0']) {
371 return Err(Error::invalid(format!(
372 "build argument {k}: values are one line"
373 )));
374 }
375 }
376 let dir = match &req.subdir {
377 Some(s) => req.context.join(s),
378 None => req.context.clone(),
379 };
380 let md = std::fs::metadata(&req.context)
381 .map_err(|e| Error::invalid(format!("context {}: {e}", req.context.display())))?;
382 if !md.is_dir() || !req.context.is_absolute() {
383 return Err(Error::invalid(format!(
384 "context {}: an absolute directory",
385 req.context.display()
386 )));
387 }
388 if !dir.is_dir() {
389 return Err(Error::invalid(format!(
390 "{} is not a directory",
391 dir.display()
392 )));
393 }
394 Ok(req.context.clone())
395}
396
397fn remaining(deadline: Instant, what: &str) -> Result<Duration> {
398 let r = deadline.saturating_duration_since(Instant::now());
399 if r.is_zero() {
400 return Err(Error::invalid(format!("build timed out before {what}")));
401 }
402 Ok(r)
403}
404
405fn human(n: u64) -> String {
406 match n {
407 n if n >= 1 << 30 => format!("{:.1} GiB", n as f64 / (1u64 << 30) as f64),
408 n if n >= 1 << 20 => format!("{:.1} MiB", n as f64 / (1u64 << 20) as f64),
409 n if n >= 1 << 10 => format!("{:.1} KiB", n as f64 / 1024.0),
410 n => format!("{n} B"),
411 }
412}
413
414fn sandbox_name(app: &str) -> String {
416 let a: String = app
417 .chars()
418 .map(|c| if c.is_ascii_alphanumeric() { c } else { '-' })
419 .collect();
420 let a = a.trim_matches('-');
421 format!(
422 "build-{a}-{}{}",
423 crate::stack::new_id(),
424 crate::stack::new_id()
425 )
426}
427
428pub fn cache_volume(key: &str, vm: bool) -> String {
430 let a = key.replace('.', "-");
431 if vm {
432 format!("build-cache-{a}-vm")
433 } else {
434 format!("build-cache-{a}")
435 }
436}
437
438fn ensure_cache(
442 oc: &Client,
443 pool: &str,
444 app: &str,
445 vm: bool,
446 size: &str,
447 log: &mut dyn FnMut(&str),
448) -> Result<String> {
449 let name = cache_volume(app, vm);
450 let path = format!(
451 "/1.0/storage-pools/{}/volumes/custom/{}",
452 encode_segment(pool),
453 encode_segment(&name)
454 );
455 if oc.get_opt(&path)?.is_none() {
456 log(&format!("creating build cache volume {name}"));
457 let mut body = json!({"name": name, "type": "custom", "config": {}});
458 if vm {
459 body["content_type"] = json!("block");
460 body["config"]["size"] = json!(size);
461 } else {
462 body["content_type"] = json!("filesystem");
463 }
464 match oc.mutate(
465 "POST",
466 &format!("/1.0/storage-pools/{}/volumes/custom", encode_segment(pool)),
467 Some(&body),
468 &format!("create volume {name}"),
469 oc.get_timeouts().other,
470 ) {
471 Ok(_) => {}
472 Err(e) if e.is_conflict() => {}
474 Err(e) => return Err(e),
475 }
476 }
477 Ok(name)
478}
479
480#[expect(clippy::too_many_arguments)]
481fn create_sandbox(
482 oc: &Client,
483 name: &str,
484 image: &str,
485 vm: bool,
486 pool: &str,
487 cache: &str,
488 opts: &BuildOptions,
489 app: &str,
490 deadline: Instant,
491) -> Result<()> {
492 let mut disk = json!({"type": "disk", "pool": pool, "source": cache});
493 if !vm {
496 disk["path"] = json!("/var/lib/buildkit");
497 }
498 let mut devices = json!({ CACHE_DEVICE: disk });
499 if vm {
500 devices["root"] = json!({"type": "disk", "path": "/", "pool": pool, "size": "20GiB"});
502 }
503 let body = json!({
504 "name": name,
505 "type": if vm { "virtual-machine" } else { "container" },
506 "source": {"type": "image", "alias": image},
507 "config": {
508 "limits.cpu": opts.cpus.to_string(),
509 "limits.memory": opts.memory,
510 "user.isb.build": app,
511 },
512 "devices": devices,
513 "profiles": ["default"],
514 });
515 let t = remaining(deadline, "creating the build sandbox")?;
516 oc.mutate(
517 "POST",
518 "/1.0/instances",
519 Some(&body),
520 &format!("create build sandbox {name}"),
521 t.min(oc.get_timeouts().create.max(Duration::from_secs(600))),
522 )?;
523 let t = remaining(deadline, "starting the build sandbox")?;
524 oc.mutate(
525 "PUT",
526 &format!("/1.0/instances/{}/state", encode_segment(name)),
527 Some(&json!({"action": "start", "timeout": 60})),
528 &format!("start build sandbox {name}"),
529 t.min(Duration::from_secs(300)),
530 )?;
531 Ok(())
532}
533
534fn stream_lines(
536 sb: &Sandbox,
537 argv: &[&str],
538 opts: ExecOptions,
539 log: &mut dyn FnMut(&str),
540) -> Result<i32> {
541 let mut s = sb.exec_stream(argv.iter().copied(), opts)?;
542 let (mut out, mut err) = (Vec::new(), Vec::new());
543 let emit = |buf: &mut Vec<u8>, chunk: Vec<u8>, log: &mut dyn FnMut(&str)| {
544 buf.extend(chunk);
545 while let Some(i) = buf.iter().position(|b| *b == b'\n') {
546 let line: Vec<u8> = buf.drain(..=i).collect();
547 let text = String::from_utf8_lossy(&line[..line.len() - 1]);
548 log(text.trim_end_matches('\r'));
549 }
550 if buf.len() > 64 << 10 {
552 log(&String::from_utf8_lossy(buf));
553 buf.clear();
554 }
555 };
556 while let Some(ev) = s.next_event() {
557 match ev {
558 ExecEvent::Stdout(b) => emit(&mut out, b, log),
559 ExecEvent::Stderr(b) => emit(&mut err, b, log),
560 }
561 }
562 for b in [out, err] {
563 if !b.is_empty() {
564 log(&String::from_utf8_lossy(&b));
565 }
566 }
567 match s.wait() {
570 Err(e) if e.to_string().contains("Command not found") => Ok(127),
571 Err(e) if e.to_string().contains("Permission denied") => Ok(126),
572 r => r,
573 }
574}
575
576fn send_context(sb: &Sandbox, dir: &Path, max: u64, deadline: Instant) -> Result<u64> {
579 let mut s = sb.exec_stream(
580 [
581 "/bin/sh",
582 "-c",
583 "mkdir -p /build/src && tar -x --no-same-owner -C /build/src",
584 ],
585 ExecOptions::default()
586 .stdin(Stdin::Piped)
587 .timeout(remaining(deadline, "copying the source")?),
588 )?;
589 let mut w = ChunkWriter {
590 s: &s,
591 buf: Vec::with_capacity(CHUNK),
592 sent: 0,
593 max,
594 };
595 let r = tar::write_dir(&mut w, dir).and_then(|_| w.flush().map_err(Error::from));
596 let sent = w.sent;
597 s.close_stdin();
598 let out = s.collect_output()?;
599 r?;
600 if !out.success() {
601 return Err(Error::invalid(format!(
602 "copying the source in failed (exit {}): {}",
603 out.exit_code,
604 out.stderr_text().trim()
605 )));
606 }
607 Ok(sent)
608}
609
610const CHUNK: usize = 256 << 10;
611
612struct ChunkWriter<'a> {
613 s: &'a crate::exec::ExecStream,
614 buf: Vec<u8>,
615 sent: u64,
616 max: u64,
617}
618
619impl Write for ChunkWriter<'_> {
620 fn write(&mut self, b: &[u8]) -> std::io::Result<usize> {
621 self.sent += b.len() as u64;
622 if self.sent > self.max {
623 return Err(std::io::Error::other(format!(
624 "the source is over {} (ISB build limit)",
625 human(self.max)
626 )));
627 }
628 self.buf.extend_from_slice(b);
629 if self.buf.len() >= CHUNK {
630 self.flush()?;
631 }
632 Ok(b.len())
633 }
634
635 fn flush(&mut self) -> std::io::Result<()> {
636 if !self.buf.is_empty() {
637 self.s
638 .write_stdin(&self.buf)
639 .map_err(|e| std::io::Error::other(e.to_string()))?;
640 self.buf.clear();
641 }
642 Ok(())
643 }
644}
645
646fn copy_out(sb: &Sandbox, path: &str, to: &Path, deadline: Instant) -> Result<u64> {
648 let mut f = std::fs::File::create(to)?;
649 let mut s = sb.exec_stream(
650 ["/bin/cat", path],
651 ExecOptions::default().timeout(remaining(deadline, "copying the image out")?),
652 )?;
653 let mut n = 0u64;
654 let mut err = Vec::new();
655 while let Some(ev) = s.next_event() {
656 match ev {
657 ExecEvent::Stdout(b) => {
658 n += b.len() as u64;
659 f.write_all(&b)?;
660 }
661 ExecEvent::Stderr(b) => err.extend(b),
662 }
663 }
664 let code = s.wait()?;
665 if code != 0 {
666 return Err(Error::invalid(format!(
667 "copying {path} out failed (exit {code}): {}",
668 String::from_utf8_lossy(&err).trim()
669 )));
670 }
671 f.sync_all()?;
672 Ok(n)
673}
674
675fn scratch_file(app: &str) -> Result<PathBuf> {
678 let dir = std::env::var_os("ISB_SERVE_STATE_DIR")
679 .map(PathBuf::from)
680 .unwrap_or_else(crate::stack::Store::default_dir)
681 .join("builds");
682 std::fs::create_dir_all(&dir)?;
683 Ok(dir.join(format!(
684 "{app}-{}{}.tar",
685 crate::stack::new_id(),
686 crate::stack::new_id()
687 )))
688}
689
690struct RemoveFile(PathBuf);
691
692impl Drop for RemoveFile {
693 fn drop(&mut self) {
694 let _ = std::fs::remove_file(&self.0);
695 }
696}
697
698struct Remove {
700 client: Client,
701 name: String,
702}
703
704impl Drop for Remove {
705 fn drop(&mut self) {
706 match Sandbox::remove(&self.client, &self.name, true) {
707 Ok(()) => {}
708 Err(e) if e.is_not_found() => {}
709 Err(e) => eprintln!("isb: build sandbox {}: not deleted: {e}", self.name),
710 }
711 }
712}
713
714static PREPARE: Mutex<()> = Mutex::new(());
716
717#[expect(
721 clippy::too_many_lines,
722 reason = "predates the lint ratchet; split it when next changed"
723)]
724pub fn ensure_builder_image(
725 base: &Client,
726 vm: bool,
727 deadline: Instant,
728 log: &mut dyn FnMut(&str),
729) -> Result<String> {
730 let alias = builder_alias(vm);
731 let h = base.clone().project("default");
732 let alias_path = format!("/1.0/images/aliases/{}", encode_segment(&alias));
733 if h.get_opt(&alias_path)?.is_some() {
734 return Ok(alias);
735 }
736 let _g = PREPARE.lock().unwrap();
737 if h.get_opt(&alias_path)?.is_some() {
738 return Ok(alias);
739 }
740 log(&format!(
741 "preparing the builder image {alias} (once per recipe; a few minutes)"
742 ));
743 let s = base.clone().project(crate::registry::PROJECT);
744 if crate::registry::info(base)?.is_none() {
745 return Err(Error::invalid(
746 "no isb-system project yet: run `isb registry setup` first",
747 ));
748 }
749 let pool = crate::sandbox::host_facts(&h)?.pick_pool(None)?;
750 let net = uplink_network(&h)?;
751 let name = format!(
752 "builder-prep-{}{}",
753 crate::stack::new_id(),
754 crate::stack::new_id()
755 );
756 let _guard = Remove {
757 client: s.clone(),
758 name: name.clone(),
759 };
760 let src = crate::plan::ImageSource::parse(BASE_IMAGE)?;
761 let config = json!({"limits.cpu": "4", "limits.memory": "4GiB"});
762 s.mutate(
763 "POST",
764 "/1.0/instances",
765 Some(&json!({
766 "name": name,
767 "type": if vm { "virtual-machine" } else { "container" },
768 "source": src.to_api(None),
769 "config": config,
770 "devices": {
771 "root": {"type": "disk", "path": "/", "pool": pool},
772 "eth0": {"type": "nic", "name": "eth0", "network": net},
773 },
774 "profiles": ["default"],
775 })),
776 &format!("create {name}"),
777 remaining(deadline, "creating the builder image")?.min(Duration::from_secs(1200)),
778 )?;
779 s.mutate(
780 "PUT",
781 &format!("/1.0/instances/{name}/state"),
782 Some(&json!({"action": "start", "timeout": 60})),
783 &format!("start {name}"),
784 Duration::from_secs(300),
785 )?;
786 let sb = Sandbox::get(&s, &name)?;
787 ready::exec(&sb, deadline)?;
788 ready::network(&s, &name, &net, deadline, log)?;
789 s.push_file(
790 &name,
791 "/root/builder-image.sh",
792 RECIPE.as_bytes(),
793 0,
794 0,
795 0o755,
796 )?;
797 let code = stream_lines(
798 &sb,
799 &["/bin/sh", "/root/builder-image.sh"],
800 ExecOptions::default()
801 .env(
802 "PATH",
803 "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
804 )
805 .timeout(remaining(deadline, "preparing the builder image")?),
806 &mut |l| log(&format!("prepare: {l}")),
807 )?;
808 if code != 0 {
809 return Err(Error::invalid(format!(
810 "preparing the builder image failed (exit {code})"
811 )));
812 }
813 let stop = |force: bool| {
815 s.mutate(
816 "PUT",
817 &format!("/1.0/instances/{name}/state"),
818 Some(&json!({"action": "stop", "timeout": 120, "force": force})),
819 &format!("stop {name}"),
820 Duration::from_secs(180),
821 )
822 };
823 if let Err(e) = stop(false) {
824 log(&format!("prepare: a clean stop failed ({e}); forcing it"));
825 stop(true)?;
826 }
827 log(&format!("publishing {alias}"));
828 let versions: Value = json!({
829 "description": format!("isb builder ({})", if vm { "VM" } else { "container" }),
830 "isb.recipe": alias,
831 });
832 s.mutate(
833 "POST",
834 "/1.0/images",
835 Some(&json!({
836 "source": {"type": "instance", "name": name},
837 "properties": versions,
838 "aliases": [{"name": alias, "description": "isb builder image"}],
839 })),
840 &format!("publish {alias}"),
841 remaining(deadline, "publishing the builder image")?.min(Duration::from_secs(1800)),
842 )?;
843 Ok(alias)
844}
845
846fn uplink_network(h: &Client) -> Result<String> {
849 let nets = h.get("/1.0/networks?recursion=1")?;
850 let managed: Vec<&str> = nets
851 .as_array()
852 .into_iter()
853 .flatten()
854 .filter(|n| n["managed"].as_bool() == Some(true) && n["type"] == "bridge")
855 .filter_map(|n| n["name"].as_str())
856 .filter(|n| !n.starts_with("isbbr"))
857 .collect();
858 managed
859 .iter()
860 .find(|n| **n == "incusbr0")
861 .or(managed.first())
862 .map(|s| s.to_string())
863 .ok_or_else(|| Error::invalid("no managed bridge to prepare the builder image on"))
864}
865
866pub(crate) mod tar {
869 use std::io::{Read, Write};
870 use std::os::unix::fs::{MetadataExt, PermissionsExt};
871 use std::path::Path;
872
873 use crate::error::Result;
874
875 fn octal(field: &mut [u8], v: u64) {
876 let w = field.len() - 1;
878 let s = format!("{v:0w$o}");
879 let b = s.as_bytes();
880 let start = b.len().saturating_sub(w);
881 field[..w].copy_from_slice(&b[start..]);
882 field[w] = 0;
883 }
884
885 fn header(name: &str, size: u64, mode: u32, mtime: u64, kind: u8, link: &str) -> [u8; 512] {
886 let mut h = [0u8; 512];
887 let n = name.as_bytes();
888 h[..n.len().min(100)].copy_from_slice(&n[..n.len().min(100)]);
889 octal(&mut h[100..108], (mode & 0o7777) as u64);
890 octal(&mut h[108..116], 0);
891 octal(&mut h[116..124], 0);
892 octal(&mut h[124..136], size);
893 octal(&mut h[136..148], mtime);
894 h[156] = kind;
895 let l = link.as_bytes();
896 h[157..157 + l.len().min(100)].copy_from_slice(&l[..l.len().min(100)]);
897 h[257..263].copy_from_slice(b"ustar\0");
898 h[263..265].copy_from_slice(b"00");
899 h[148..156].copy_from_slice(b" ");
900 let sum: u64 = h.iter().map(|b| *b as u64).sum();
901 let s = format!("{sum:06o}\0 ");
902 h[148..156].copy_from_slice(s.as_bytes());
903 h
904 }
905
906 fn pad(w: &mut dyn Write, n: u64) -> std::io::Result<()> {
907 let r = (512 - (n % 512) as usize) % 512;
908 w.write_all(&vec![0u8; r])
909 }
910
911 fn pax_record(key: &str, value: &str) -> String {
912 let body = format!(" {key}={value}\n");
914 let mut len = body.len() + 1;
915 while format!("{len}{body}").len() != len {
916 len = format!("{len}{body}").len();
917 }
918 format!("{len}{body}")
919 }
920
921 fn entry(
922 w: &mut dyn Write,
923 name: &str,
924 size: u64,
925 mode: u32,
926 mtime: u64,
927 kind: u8,
928 link: &str,
929 ) -> std::io::Result<()> {
930 if name.len() > 100 || link.len() > 100 || !name.is_ascii() || !link.is_ascii() {
931 let mut pax = pax_record("path", name);
932 if !link.is_empty() {
933 pax.push_str(&pax_record("linkpath", link));
934 }
935 w.write_all(&header(
936 "././@PaxHeader",
937 pax.len() as u64,
938 0o644,
939 mtime,
940 b'x',
941 "",
942 ))?;
943 w.write_all(pax.as_bytes())?;
944 pad(w, pax.len() as u64)?;
945 }
946 w.write_all(&header(name, size, mode, mtime, kind, link))
947 }
948
949 pub fn write_dir(w: &mut dyn Write, dir: &Path) -> Result<()> {
951 walk(w, dir, "")?;
952 w.write_all(&[0u8; 1024])?;
953 Ok(())
954 }
955
956 fn walk(w: &mut dyn Write, dir: &Path, prefix: &str) -> Result<()> {
957 let mut names: Vec<_> = std::fs::read_dir(dir)?
958 .filter_map(|e| e.ok())
959 .map(|e| e.file_name())
960 .collect();
961 names.sort();
962 for n in names {
963 let path = dir.join(&n);
964 let Some(n) = n.to_str() else {
965 continue;
967 };
968 let name = format!("{prefix}{n}");
969 let md = std::fs::symlink_metadata(&path)?;
970 let mtime = md.mtime().max(0) as u64;
971 let mode = md.permissions().mode();
972 let ft = md.file_type();
973 if ft.is_symlink() {
974 let target = std::fs::read_link(&path)?;
975 let Some(t) = target.to_str() else { continue };
976 entry(w, &name, 0, 0o777, mtime, b'2', t)?;
977 } else if ft.is_dir() {
978 entry(w, &format!("{name}/"), 0, mode, mtime, b'5', "")?;
979 walk(w, &path, &format!("{name}/"))?;
980 } else if ft.is_file() {
981 let mut f = std::fs::File::open(&path)?;
982 let size = md.len();
983 entry(w, &name, size, mode, mtime, b'0', "")?;
984 let copied = std::io::copy(&mut (&mut f).take(size), w)?;
986 if copied < size {
987 std::io::copy(&mut std::io::repeat(0).take(size - copied), w)?;
988 }
989 pad(w, size)?;
990 }
991 }
993 Ok(())
994 }
995}
996
997#[cfg(test)]
998mod tests {
999 use super::*;
1000
1001 fn req(builder: Builder) -> BuildRequest {
1002 BuildRequest {
1003 org: OrgId::new("acme").unwrap(),
1004 app: "web".into(),
1005 context: std::env::temp_dir(),
1006 subdir: None,
1007 builder,
1008 args: vec![],
1009 tag: "v1".into(),
1010 untrusted: false,
1011 cache: None,
1012 }
1013 }
1014
1015 #[test]
1016 fn requests_are_checked() {
1017 assert!(check(&req(Builder::Railpack)).is_ok());
1018 let mut r = req(Builder::Railpack);
1019 r.app = "Web".into();
1020 assert!(check(&r).is_err());
1021 r = req(Builder::Railpack);
1022 r.tag = "bad tag".into();
1023 assert!(check(&r).is_err());
1024 r = req(Builder::Railpack);
1025 r.subdir = Some("../etc".into());
1026 assert!(check(&r).is_err());
1027 r = req(Builder::Dockerfile {
1028 path: "/etc/passwd".into(),
1029 target: None,
1030 });
1031 assert!(check(&r).is_err());
1032 r = req(Builder::Railpack);
1033 r.args = vec![("A B".into(), "x".into())];
1034 assert!(check(&r).is_err());
1035 r.args = vec![("A".into(), "x\ny".into())];
1036 assert!(check(&r).is_err());
1037 assert!(check(&req(Builder::Buildpacks { builder: None })).is_err());
1038 r = req(Builder::Railpack);
1039 r.context = "relative".into();
1040 assert!(check(&r).is_err());
1041 }
1042
1043 #[test]
1044 fn builder_json_matches_the_contract() {
1045 let b: Builder = serde_json::from_str(r#"{"type":"dockerfile"}"#).unwrap();
1046 assert_eq!(
1047 b,
1048 Builder::Dockerfile {
1049 path: "Dockerfile".into(),
1050 target: None
1051 }
1052 );
1053 let b: Builder = serde_json::from_str(r#"{"type":"railpack"}"#).unwrap();
1054 assert_eq!(b.name(), "railpack");
1055 assert!(builder_alias(false).starts_with("isb-builder/"));
1056 assert!(builder_alias(true).starts_with("isb-builder-vm/"));
1057 assert!(sandbox_name("my.app").starts_with("build-my-app-"));
1058 assert!(sandbox_name(&"a".repeat(40)).len() <= 63);
1059 }
1060
1061 #[test]
1062 fn source_tars_round_trip_through_the_layout_reader() {
1063 let d = tempfile::tempdir().unwrap();
1064 let root = d.path().join("src");
1065 std::fs::create_dir_all(root.join("sub")).unwrap();
1066 std::fs::write(root.join("a.txt"), "hello").unwrap();
1067 let long = "x".repeat(150);
1068 std::fs::write(root.join("sub").join(&long), "long").unwrap();
1069 std::os::unix::fs::symlink("/etc/shadow", root.join("link")).unwrap();
1070 let mut buf = Vec::new();
1071 tar::write_dir(&mut buf, &root).unwrap();
1072 let p = d.path().join("x.tar");
1073 std::fs::write(&p, &buf).unwrap();
1074 let l = crate::registry::oci::Layout::open(&p).unwrap();
1076 let _ = l;
1077 if let Ok(out) = std::process::Command::new("tar")
1079 .arg("-tvf")
1080 .arg(&p)
1081 .output()
1082 {
1083 if out.status.success() {
1084 let t = String::from_utf8_lossy(&out.stdout);
1085 assert!(t.contains("a.txt"), "{t}");
1086 assert!(t.contains(&format!("sub/{long}")), "{t}");
1087 assert!(
1088 t.contains("link -> /etc/shadow"),
1089 "symlinks stay links: {t}"
1090 );
1091 }
1092 }
1093 }
1094}