2022-10-10 15:05:55 +03:00
//go:build search
// +build search
2020-10-14 14:47:20 -07:00
package extensions
import (
2023-02-27 21:25:47 +02:00
"net/http"
2023-03-02 19:43:54 +02:00
"sync"
2020-10-14 14:47:20 -07:00
"time"
gqlHandler "github.com/99designs/gqlgen/graphql/handler"
2021-10-15 18:05:00 +03:00
"github.com/gorilla/mux"
2022-02-24 12:31:36 -08:00
distext "github.com/opencontainers/distribution-spec/specs-go/v1/extensions"
2022-10-20 19:39:20 +03:00
2021-12-04 03:50:58 +00:00
"zotregistry.io/zot/pkg/api/config"
2022-02-24 12:31:36 -08:00
"zotregistry.io/zot/pkg/api/constants"
2021-12-04 03:50:58 +00:00
"zotregistry.io/zot/pkg/extensions/search"
cveinfo "zotregistry.io/zot/pkg/extensions/search/cve"
2022-07-15 11:10:51 +00:00
"zotregistry.io/zot/pkg/extensions/search/gql_generated"
2021-12-04 03:50:58 +00:00
"zotregistry.io/zot/pkg/log"
2023-01-09 22:37:44 +02:00
"zotregistry.io/zot/pkg/meta/repodb"
2023-03-02 19:43:54 +02:00
"zotregistry.io/zot/pkg/scheduler"
2021-12-04 03:50:58 +00:00
"zotregistry.io/zot/pkg/storage"
2020-10-14 14:47:20 -07:00
)
2023-03-02 19:43:54 +02:00
type (
CveInfo cveinfo . CveInfo
state int
)
const (
pending state = iota
running
done
)
2022-09-28 21:39:54 +03:00
2023-02-10 07:04:52 +02:00
func GetCVEInfo ( config * config . Config , storeController storage . StoreController ,
2023-01-09 22:37:44 +02:00
repoDB repodb . RepoDB , log log . Logger ,
2023-02-10 07:04:52 +02:00
) CveInfo {
if config . Extensions . Search == nil || ! * config . Extensions . Search . Enable || config . Extensions . Search . CVE == nil {
return nil
}
dbRepository := ""
if config . Extensions . Search . CVE . Trivy != nil {
dbRepository = config . Extensions . Search . CVE . Trivy . DBRepository
}
return cveinfo . NewCVEInfo ( storeController , repoDB , dbRepository , log )
}
func EnableSearchExtension ( config * config . Config , storeController storage . StoreController ,
2023-03-02 19:43:54 +02:00
repoDB repodb . RepoDB , taskScheduler * scheduler . Scheduler , cveInfo CveInfo , log log . Logger ,
2023-01-09 22:37:44 +02:00
) {
2021-12-28 15:29:30 +02:00
if config . Extensions . Search != nil && * config . Extensions . Search . Enable && config . Extensions . Search . CVE != nil {
2020-10-14 14:47:20 -07:00
defaultUpdateInterval , _ := time . ParseDuration ( "2h" )
2021-06-08 23:11:18 +03:00
if config . Extensions . Search . CVE . UpdateInterval < defaultUpdateInterval {
config . Extensions . Search . CVE . UpdateInterval = defaultUpdateInterval
2020-10-14 14:47:20 -07:00
2022-03-21 17:37:23 +00:00
log . Warn ( ) . Msg ( "CVE update interval set to too-short interval < 2h, changing update duration to 2 hours and continuing." ) //nolint:lll // gofumpt conflicts with lll
2020-10-14 14:47:20 -07:00
}
2023-03-02 19:43:54 +02:00
updateInterval := config . Extensions . Search . CVE . UpdateInterval
downloadTrivyDB ( updateInterval , taskScheduler , cveInfo , log )
2020-10-14 14:47:20 -07:00
} else {
2020-10-22 17:31:16 -07:00
log . Info ( ) . Msg ( "CVE config not provided, skipping CVE update" )
2020-10-14 14:47:20 -07:00
}
2022-04-27 09:00:20 +03:00
}
2021-06-08 23:11:18 +03:00
2023-03-02 19:43:54 +02:00
func downloadTrivyDB ( interval time . Duration , sch * scheduler . Scheduler , cveInfo CveInfo , log log . Logger ) {
generator := & trivyTaskGenerator { interval , cveInfo , log , pending , 0 , time . Now ( ) , & sync . Mutex { } }
2021-10-28 12:10:01 +03:00
2023-03-02 19:43:54 +02:00
sch . SubmitGenerator ( generator , interval , scheduler . HighPriority )
}
2021-10-28 12:10:01 +03:00
2023-03-02 19:43:54 +02:00
type trivyTaskGenerator struct {
interval time . Duration
cveInfo CveInfo
log log . Logger
status state
waitTime time . Duration
lastTaskTime time . Time
lock * sync . Mutex
}
func ( gen * trivyTaskGenerator ) GenerateTask ( ) ( scheduler . Task , error ) {
var newTask scheduler . Task
2022-04-27 09:00:20 +03:00
2023-03-02 19:43:54 +02:00
gen . lock . Lock ( )
if gen . status != running && time . Since ( gen . lastTaskTime ) >= gen . waitTime {
newTask = newTrivyTask ( gen . interval , gen . cveInfo , gen , gen . log )
gen . status = running
2021-06-08 23:11:18 +03:00
}
2023-03-02 19:43:54 +02:00
gen . lock . Unlock ( )
return newTask , nil
}
func ( gen * trivyTaskGenerator ) IsDone ( ) bool {
gen . lock . Lock ( )
status := gen . status
gen . lock . Unlock ( )
return status == done
}
func ( gen * trivyTaskGenerator ) Reset ( ) {
gen . lock . Lock ( )
gen . status = pending
gen . waitTime = 0
gen . lock . Unlock ( )
}
type trivyTask struct {
interval time . Duration
cveInfo cveinfo . CveInfo
generator * trivyTaskGenerator
log log . Logger
}
func newTrivyTask ( interval time . Duration , cveInfo cveinfo . CveInfo ,
generator * trivyTaskGenerator , log log . Logger ,
) * trivyTask {
return & trivyTask { interval , cveInfo , generator , log }
}
func ( trivyT * trivyTask ) DoWork ( ) error {
trivyT . log . Info ( ) . Msg ( "updating the CVE database" )
err := trivyT . cveInfo . UpdateDB ( )
if err != nil {
trivyT . generator . lock . Lock ( )
trivyT . generator . status = pending
trivyT . generator . waitTime += time . Second
trivyT . generator . lastTaskTime = time . Now ( )
trivyT . generator . lock . Unlock ( )
return err
}
trivyT . generator . lock . Lock ( )
trivyT . generator . lastTaskTime = time . Now ( )
trivyT . generator . status = done
trivyT . generator . lock . Unlock ( )
trivyT . log . Info ( ) . Str ( "DB update completed, next update scheduled after" , trivyT . interval . String ( ) ) . Msg ( "" )
return nil
2020-10-14 14:47:20 -07:00
}
2023-02-27 21:25:47 +02:00
func addSearchSecurityHeaders ( h http . Handler ) http . HandlerFunc { //nolint:varnamelen
return func ( w http . ResponseWriter , r * http . Request ) {
w . Header ( ) . Set ( "X-Content-Type-Options" , "nosniff" )
h . ServeHTTP ( w , r )
}
}
2022-04-27 09:00:20 +03:00
func SetupSearchRoutes ( config * config . Config , router * mux . Router , storeController storage . StoreController ,
2023-02-10 07:04:52 +02:00
repoDB repodb . RepoDB , cveInfo CveInfo , log log . Logger ,
2022-04-27 09:00:20 +03:00
) {
log . Info ( ) . Msg ( "setting up search routes" )
2022-03-04 09:37:06 +02:00
2022-04-27 09:00:20 +03:00
if config . Extensions . Search != nil && * config . Extensions . Search . Enable {
2023-02-10 07:04:52 +02:00
resConfig := search . GetResolverConfig ( log , storeController , repoDB , cveInfo )
2022-04-27 09:00:20 +03:00
2023-02-11 00:52:54 +02:00
extRouter := router . PathPrefix ( constants . ExtSearchPrefix ) . Subrouter ( )
extRouter . Methods ( "GET" , "POST" , "OPTIONS" ) .
2023-02-27 21:25:47 +02:00
Handler ( addSearchSecurityHeaders ( gqlHandler . NewDefaultServer ( gql_generated . NewExecutableSchema ( resConfig ) ) ) )
2022-03-04 09:37:06 +02:00
}
}
2022-05-23 19:22:52 +00:00
func getExtension ( name , url , description string , endpoints [ ] string ) distext . Extension {
2022-02-24 12:31:36 -08:00
return distext . Extension {
Name : name ,
URL : url ,
Description : description ,
2022-05-23 19:22:52 +00:00
Endpoints : endpoints ,
2022-02-24 12:31:36 -08:00
}
}
func GetExtensions ( config * config . Config ) distext . ExtensionList {
extensionList := distext . ExtensionList { }
extensions := make ( [ ] distext . Extension , 0 )
if config . Extensions != nil && config . Extensions . Search != nil {
2022-10-19 06:46:06 +03:00
endpoints := [ ] string { constants . FullSearchPrefix }
2022-05-25 17:49:22 +00:00
searchExt := getExtension ( "_zot" ,
2022-10-11 19:01:59 +03:00
"https://github.com/project-zot/zot/blob/" + config . ReleaseTag + "/pkg/extensions/_zot.md" ,
"zot registry extensions" ,
2022-05-25 17:49:22 +00:00
endpoints )
2022-02-24 12:31:36 -08:00
extensions = append ( extensions , searchExt )
}
extensionList . Extensions = extensions
return extensionList
}