krata/daemon/src/runtime/image/mod.rs

415 lines
14 KiB
Rust
Raw Normal View History

2024-01-18 08:02:21 +00:00
pub mod cache;
2024-01-18 18:16:59 +00:00
pub mod fetch;
pub mod name;
2024-01-18 08:02:21 +00:00
use crate::runtime::image::cache::ImageCache;
use crate::runtime::image::fetch::RegistryClient;
use crate::runtime::image::name::ImageName;
use anyhow::{anyhow, Result};
use backhand::compression::Compressor;
use backhand::{FilesystemCompressor, FilesystemWriter, NodeHeader};
2024-01-20 10:41:49 +00:00
use flate2::read::GzDecoder;
use log::{debug, trace, warn};
use oci_spec::image::{Descriptor, ImageConfiguration, ImageManifest, MediaType, ToDockerV2S2};
2024-01-17 22:29:05 +00:00
use std::fs::File;
use std::io::{BufReader, Cursor};
2024-01-17 22:29:05 +00:00
use std::os::unix::fs::{FileTypeExt, MetadataExt, PermissionsExt};
2024-01-20 10:41:49 +00:00
use std::path::{Path, PathBuf};
use std::{fs, io};
use tar::{Archive, Entry};
2024-01-17 22:29:05 +00:00
use uuid::Uuid;
use walkdir::WalkDir;
pub const IMAGE_SQUASHFS_VERSION: u64 = 1;
const LAYER_BUFFER_SIZE: usize = 128 * 1024;
// we utilize in-memory buffers when generating the squashfs for files
// under this size. for files of or above this size, we open a file.
// the file is then read during writing. we want to reduce the number
// of open files during squashfs generation, so this limit should be set
// to something that limits the number of files on average, at the expense
// of increased memory usage.
// TODO: it may be wise to, during crawling of the image layers, infer this
// value from the size to file count ratio of all layers.
const SQUASHFS_MEMORY_BUFFER_LIMIT: usize = 8 * 1024 * 1024;
2024-01-18 08:02:21 +00:00
pub struct ImageInfo {
2024-01-18 22:52:35 +00:00
pub image_squashfs: PathBuf,
2024-01-18 08:02:21 +00:00
pub manifest: ImageManifest,
2024-01-18 08:15:36 +00:00
pub config: ImageConfiguration,
2024-01-18 08:02:21 +00:00
}
impl ImageInfo {
2024-01-18 08:15:36 +00:00
fn new(
squashfs: PathBuf,
manifest: ImageManifest,
config: ImageConfiguration,
) -> Result<ImageInfo> {
Ok(ImageInfo {
2024-01-18 22:52:35 +00:00
image_squashfs: squashfs,
2024-01-18 08:15:36 +00:00
manifest,
config,
})
2024-01-18 08:02:21 +00:00
}
}
pub struct ImageCompiler<'a> {
cache: &'a ImageCache,
}
2024-01-17 22:29:05 +00:00
#[derive(Debug)]
enum LayerCompressionType {
None,
Gzip,
Zstd,
}
struct LayerFile {
digest: String,
compression: LayerCompressionType,
path: PathBuf,
}
impl LayerFile {
fn open_reader(&self) -> Result<Box<dyn io::Read>> {
Ok(match self.compression {
LayerCompressionType::None => Box::new(BufReader::with_capacity(
LAYER_BUFFER_SIZE,
File::open(&self.path)?,
)),
LayerCompressionType::Gzip => Box::new(GzDecoder::new(BufReader::with_capacity(
LAYER_BUFFER_SIZE,
File::open(&self.path)?,
))),
LayerCompressionType::Zstd => Box::new(zstd::Decoder::new(BufReader::with_capacity(
LAYER_BUFFER_SIZE,
File::open(&self.path)?,
))?),
})
}
}
2024-01-18 08:02:21 +00:00
impl ImageCompiler<'_> {
pub fn new(cache: &ImageCache) -> Result<ImageCompiler> {
Ok(ImageCompiler { cache })
2024-01-17 22:29:05 +00:00
}
2024-02-25 05:38:23 +00:00
pub async fn compile(&self, image: &ImageName) -> Result<ImageInfo> {
debug!("compile image={image}");
2024-01-17 22:29:05 +00:00
let mut tmp_dir = std::env::temp_dir().clone();
2024-02-21 20:57:46 +00:00
tmp_dir.push(format!("krata-compile-{}", Uuid::new_v4()));
2024-01-20 10:41:49 +00:00
2024-01-17 22:29:05 +00:00
let mut image_dir = tmp_dir.clone();
image_dir.push("image");
fs::create_dir_all(&image_dir)?;
2024-01-20 10:41:49 +00:00
let mut layer_dir = tmp_dir.clone();
layer_dir.push("layer");
fs::create_dir_all(&layer_dir)?;
2024-01-17 22:29:05 +00:00
let mut squash_file = tmp_dir.clone();
squash_file.push("image.squashfs");
2024-02-25 05:38:23 +00:00
let info = self
.download_and_compile(image, &layer_dir, &image_dir, &squash_file)
.await?;
2024-01-20 10:41:49 +00:00
fs::remove_dir_all(&tmp_dir)?;
2024-01-18 08:02:21 +00:00
Ok(info)
2024-01-17 22:29:05 +00:00
}
2024-02-25 05:38:23 +00:00
async fn download_and_compile(
2024-01-18 08:02:21 +00:00
&self,
image: &ImageName,
2024-01-20 10:41:49 +00:00
layer_dir: &Path,
2024-01-18 08:02:21 +00:00
image_dir: &PathBuf,
squash_file: &PathBuf,
) -> Result<ImageInfo> {
2024-01-17 22:29:05 +00:00
debug!(
2024-02-25 05:38:23 +00:00
"download manifest image={image}, image_dir={}",
2024-01-17 22:29:05 +00:00
image_dir.to_str().unwrap()
);
2024-01-18 18:16:59 +00:00
let mut client = RegistryClient::new(image.registry_url()?)?;
2024-02-25 05:38:23 +00:00
let (manifest, digest) = client
.get_manifest_with_digest(&image.name, &image.reference)
.await?;
let cache_key = format!(
"manifest={}:squashfs-version={}\n",
digest, IMAGE_SQUASHFS_VERSION
);
let cache_digest = sha256::digest(cache_key);
if let Some(cached) = self.cache.recall(&cache_digest)? {
2024-01-18 08:02:21 +00:00
return Ok(cached);
}
2024-01-18 08:15:36 +00:00
2024-01-20 10:41:49 +00:00
debug!(
2024-02-25 05:38:23 +00:00
"download config digest={} size={}",
2024-01-20 10:41:49 +00:00
manifest.config().digest(),
manifest.config().size(),
);
2024-02-25 05:38:23 +00:00
let config_bytes = client.get_blob(&image.name, manifest.config()).await?;
2024-01-18 08:15:36 +00:00
let config: ImageConfiguration = serde_json::from_slice(&config_bytes)?;
let mut layers: Vec<LayerFile> = Vec::new();
2024-01-17 22:29:05 +00:00
for layer in manifest.layers() {
2024-02-25 05:38:23 +00:00
layers.push(
self.download_layer(image, layer, layer_dir, &mut client)
.await?,
);
2024-01-20 10:41:49 +00:00
}
for layer in layers {
debug!(
2024-02-25 05:38:23 +00:00
"process layer digest={} compression={:?}",
&layer.digest, layer.compression
);
let mut archive = Archive::new(layer.open_reader()?);
for entry in archive.entries()? {
let mut entry = entry?;
let path = entry.path()?;
let Some(name) = path.file_name() else {
return Err(anyhow!("unable to get file name"));
};
let Some(name) = name.to_str() else {
return Err(anyhow!("unable to get file name as string"));
};
if name.starts_with(".wh.") {
self.process_whiteout_entry(&entry, name, &layer, image_dir)?;
} else {
self.process_write_entry(&mut entry, &layer, image_dir)?;
}
}
fs::remove_file(&layer.path)?;
2024-01-20 10:41:49 +00:00
}
self.squash(image_dir, squash_file)?;
let info = ImageInfo::new(squash_file.clone(), manifest.clone(), config)?;
self.cache.store(&cache_digest, &info)
}
fn process_whiteout_entry<T: io::Read>(
&self,
entry: &Entry<T>,
name: &str,
layer: &LayerFile,
image_dir: &PathBuf,
) -> Result<()> {
let dst = self.check_safe_entry(entry, image_dir)?;
let mut dst = dst.clone();
dst.pop();
2024-01-20 10:41:49 +00:00
let opaque = name == ".wh..wh..opq";
2024-01-20 10:41:49 +00:00
if !opaque {
dst.push(name);
self.check_safe_path(&dst, image_dir)?;
}
trace!(
2024-02-25 05:38:23 +00:00
"whiteout entry layer={} path={:?}",
&layer.digest,
entry.path()?
);
2024-01-20 10:41:49 +00:00
if opaque {
if dst.is_dir() {
2024-01-20 10:41:49 +00:00
for entry in fs::read_dir(dst)? {
let entry = entry?;
let path = entry.path();
if path.is_symlink() || path.is_file() {
2024-01-20 10:41:49 +00:00
fs::remove_file(&path)?;
} else if path.is_dir() {
2024-01-20 10:41:49 +00:00
fs::remove_dir_all(&path)?;
} else {
return Err(anyhow!("opaque whiteout entry did not exist"));
2024-01-17 22:29:05 +00:00
}
}
2024-01-20 10:41:49 +00:00
} else {
warn!(
2024-02-25 05:38:23 +00:00
"whiteout entry missing locally layer={} path={:?} local={:?}",
&layer.digest,
entry.path()?,
dst,
);
2024-01-20 10:41:49 +00:00
}
} else if dst.is_file() || dst.is_symlink() {
fs::remove_file(&dst)?;
} else if dst.is_dir() {
fs::remove_dir(&dst)?;
} else {
warn!(
2024-02-25 05:38:23 +00:00
"whiteout entry missing locally layer={} path={:?} local={:?}",
&layer.digest,
entry.path()?,
dst,
);
2024-01-20 10:41:49 +00:00
}
Ok(())
}
fn process_write_entry<T: io::Read>(
&self,
entry: &mut Entry<T>,
layer: &LayerFile,
image_dir: &PathBuf,
) -> Result<()> {
trace!(
2024-02-25 05:38:23 +00:00
"unpack entry layer={} path={:?} type={:?}",
&layer.digest,
entry.path()?,
entry.header().entry_type()
);
entry.unpack_in(image_dir)?;
2024-01-20 10:41:49 +00:00
Ok(())
}
fn check_safe_entry<T: io::Read>(
&self,
entry: &Entry<T>,
image_dir: &PathBuf,
) -> Result<PathBuf> {
2024-01-20 10:41:49 +00:00
let mut dst = image_dir.clone();
dst.push(entry.path()?);
if let Some(name) = dst.file_name() {
if let Some(name) = name.to_str() {
if name.starts_with(".wh.") {
let copy = dst.clone();
dst.pop();
self.check_safe_path(&dst, image_dir)?;
return Ok(copy);
}
}
}
2024-01-20 10:41:49 +00:00
self.check_safe_path(&dst, image_dir)?;
Ok(dst)
}
fn check_safe_path(&self, dst: &PathBuf, image_dir: &PathBuf) -> Result<()> {
let resolved = path_clean::clean(dst);
if !resolved.starts_with(image_dir) {
return Err(anyhow!("layer attempts to work outside image dir"));
2024-01-20 10:41:49 +00:00
}
Ok(())
}
2024-02-25 05:38:23 +00:00
async fn download_layer(
2024-01-20 10:41:49 +00:00
&self,
image: &ImageName,
layer: &Descriptor,
layer_dir: &Path,
client: &mut RegistryClient,
) -> Result<LayerFile> {
2024-01-20 10:41:49 +00:00
debug!(
2024-02-25 05:38:23 +00:00
"download layer digest={} size={}",
2024-01-20 10:41:49 +00:00
layer.digest(),
layer.size()
);
let mut layer_path = layer_dir.to_path_buf();
layer_path.push(layer.digest());
let mut tmp_path = layer_dir.to_path_buf();
tmp_path.push(format!("{}.tmp", layer.digest()));
{
2024-02-25 05:38:23 +00:00
let file = tokio::fs::File::create(&layer_path).await?;
let size = client.write_blob_to_file(&image.name, layer, file).await?;
2024-01-20 10:41:49 +00:00
if layer.size() as u64 != size {
return Err(anyhow!(
2024-01-20 10:41:49 +00:00
"downloaded layer size differs from size in manifest",
));
2024-01-17 22:29:05 +00:00
}
}
2024-01-20 10:41:49 +00:00
let mut media_type = layer.media_type().clone();
2024-01-20 10:41:49 +00:00
// docker layer compatibility
if media_type.to_string() == MediaType::ImageLayerGzip.to_docker_v2s2()? {
media_type = MediaType::ImageLayerGzip;
2024-01-20 10:41:49 +00:00
}
let compression = match media_type {
MediaType::ImageLayer => LayerCompressionType::None,
MediaType::ImageLayerGzip => LayerCompressionType::Gzip,
MediaType::ImageLayerZstd => LayerCompressionType::Zstd,
other => return Err(anyhow!("found layer with unknown media type: {}", other)),
};
Ok(LayerFile {
digest: layer.digest().clone(),
compression,
path: layer_path,
})
2024-01-17 22:29:05 +00:00
}
2024-01-18 08:02:21 +00:00
fn squash(&self, image_dir: &PathBuf, squash_file: &PathBuf) -> Result<()> {
2024-01-17 22:29:05 +00:00
let mut writer = FilesystemWriter::default();
writer.set_compressor(FilesystemCompressor::new(Compressor::Gzip, None)?);
2024-01-17 22:29:05 +00:00
let walk = WalkDir::new(image_dir).follow_links(false);
for entry in walk {
let entry = entry?;
let rel = entry
.path()
.strip_prefix(image_dir)?
.to_str()
.ok_or_else(|| anyhow!("failed to strip prefix of tmpdir"))?;
2024-01-17 22:29:05 +00:00
let rel = format!("/{}", rel);
2024-02-25 05:38:23 +00:00
trace!("squash write {}", rel);
2024-01-17 22:29:05 +00:00
let typ = entry.file_type();
let metadata = fs::symlink_metadata(entry.path())?;
let uid = metadata.uid();
let gid = metadata.gid();
let mode = metadata.permissions().mode();
let mtime = metadata.mtime();
if rel == "/" {
writer.set_root_uid(uid);
writer.set_root_gid(gid);
writer.set_root_mode(mode as u16);
continue;
}
let header = NodeHeader {
permissions: mode as u16,
uid,
gid,
mtime: mtime as u32,
};
if typ.is_symlink() {
let symlink = fs::read_link(entry.path())?;
let symlink = symlink
.to_str()
.ok_or_else(|| anyhow!("failed to read symlink"))?;
2024-01-17 22:29:05 +00:00
writer.push_symlink(symlink, rel, header)?;
} else if typ.is_dir() {
writer.push_dir(rel, header)?;
} else if typ.is_file() {
if metadata.size() >= SQUASHFS_MEMORY_BUFFER_LIMIT as u64 {
let reader =
BufReader::with_capacity(LAYER_BUFFER_SIZE, File::open(entry.path())?);
writer.push_file(reader, rel, header)?;
} else {
let cursor = Cursor::new(fs::read(entry.path())?);
writer.push_file(cursor, rel, header)?;
}
2024-01-17 22:29:05 +00:00
} else if typ.is_block_device() {
let device = metadata.dev();
writer.push_block_device(device as u32, rel, header)?;
} else if typ.is_char_device() {
let device = metadata.dev();
writer.push_char_device(device as u32, rel, header)?;
} else {
return Err(anyhow!("invalid file type"));
2024-01-17 22:29:05 +00:00
}
}
fs::remove_dir_all(image_dir)?;
let squash_file_path = squash_file
.to_str()
.ok_or_else(|| anyhow!("failed to convert squashfs string"))?;
2024-01-17 22:29:05 +00:00
let mut file = File::create(squash_file)?;
2024-02-25 05:38:23 +00:00
trace!("squash generate: {}", squash_file_path);
writer.write(&mut file)?;
2024-01-18 08:02:21 +00:00
Ok(())
2024-01-17 22:29:05 +00:00
}
}