Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
dcdb2cc72e | ||
|
|
44a8e9fbdc | ||
|
|
272a3a467d | ||
|
|
cedf28a809 | ||
|
|
e46e92bee8 | ||
|
|
cf48796183 | ||
|
|
dd3187f951 | ||
|
|
1394a76eea | ||
|
|
da02457fd5 | ||
|
|
6a6359a630 | ||
|
|
e4e4348e8d | ||
|
|
b421bb7bfb | ||
|
|
909918657f | ||
|
|
a0435c858e | ||
|
|
fbab0bba33 | ||
|
|
802a64280f | ||
|
|
a88955e35c | ||
|
|
97624470eb |
@@ -72,6 +72,7 @@ override file values. Invalid values fail at startup.
|
|||||||
| `UPDATE_INTERVAL` | `6h` | Auto-update check interval |
|
| `UPDATE_INTERVAL` | `6h` | Auto-update check interval |
|
||||||
| `UPDATE_REPO` | `https://git.rambossek.at/PUBLIC/gpu-turnstile` | Repository checked for releases |
|
| `UPDATE_REPO` | `https://git.rambossek.at/PUBLIC/gpu-turnstile` | Repository checked for releases |
|
||||||
| `UPDATE_ASSET` | `gpu-turnstile.exe` | Release asset to download |
|
| `UPDATE_ASSET` | `gpu-turnstile.exe` | Release asset to download |
|
||||||
|
| `APP_VER` | `stable` | `dev` disables updates, `stable` tracks latest, or pin an exact `vX.Y.Z` |
|
||||||
|
|
||||||
## Observability
|
## Observability
|
||||||
|
|
||||||
@@ -91,56 +92,76 @@ override file values. Invalid values fail at startup.
|
|||||||
|
|
||||||
```sh
|
```sh
|
||||||
go build ./cmd/gpu-turnstile
|
go build ./cmd/gpu-turnstile
|
||||||
./gpu-turnstile
|
OLLAMA_URL=http://127.0.0.1:11435 COMFY_URL=http://127.0.0.1:8189 ./gpu-turnstile
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Running the binary with no arguments in a terminal prints the help screen
|
||||||
|
(same as `-h`/`--help`); without a terminal (services, containers) a bare
|
||||||
|
invocation starts the proxy.
|
||||||
|
|
||||||
### Run natively on Windows (current primary deployment)
|
### Run natively on Windows (current primary deployment)
|
||||||
|
|
||||||
Download `gpu-turnstile.exe` from a release, put a `gpu-turnstile.env`
|
Download `gpu-turnstile.exe` from a release and install it as a Windows
|
||||||
next to it, and run it — or install it as a Windows service from an
|
service — no admin shell needed, a UAC prompt appears automatically and
|
||||||
elevated shell:
|
the elevated child does the work (its window waits for Enter so you can
|
||||||
|
read the result):
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
gpu-turnstile.exe --install-service # auto-start service, recovery = restart
|
gpu-turnstile.exe --install-service # installs into Program Files, auto-start
|
||||||
|
gpu-turnstile.exe --install-service --no-copy # register in place instead
|
||||||
gpu-turnstile.exe --remove-service
|
gpu-turnstile.exe --remove-service
|
||||||
```
|
```
|
||||||
|
|
||||||
The service uses the config file (services have no convenient
|
Layout: `C:\Program Files\gpu-turnstile\` holds the exe and
|
||||||
environment); set `LOG_FILE` in it since there is no console.
|
`gpu-turnstile.env`, logs go to `C:\ProgramData\gpu-turnstile\`. If you
|
||||||
|
install without a config, the installer writes a sample env file with every
|
||||||
|
setting commented and explained — only `LOG_FILE` is active (a service has
|
||||||
|
no console). Your own `LOG_FILE` setting is always kept. The service always
|
||||||
|
runs
|
||||||
|
as the virtual account `NT SERVICE\gpu-turnstile` (low-privilege,
|
||||||
|
per-service, no password); the installer automatically grants it write
|
||||||
|
access to the install and data directories — nothing else to do.
|
||||||
|
|
||||||
Suggested layout: `C:\Program Files\gpu-turnstile\` for the exe and
|
Re-running `--install-service` is safe: it stops a running service,
|
||||||
`gpu-turnstile.env`, logs under `C:\ProgramData\gpu-turnstile\` via
|
replaces the installed binary only if it changed, fixes the registration
|
||||||
`LOG_FILE`. The service runs as `LocalSystem` by default, which can write
|
only where it drifted, and restarts the service only if it was running.
|
||||||
the install directory for self-updates. For least privilege, run it as the
|
|
||||||
virtual account `NT SERVICE\gpu-turnstile` and grant write access to just
|
|
||||||
those two directories.
|
|
||||||
|
|
||||||
### Run natively on Linux (systemd)
|
### Run natively on Linux (systemd)
|
||||||
|
|
||||||
The same binary works on Linux. Install it as a systemd service as root:
|
The same binary works on Linux. Install it as a systemd service as root:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
gpu-turnstile --install-service # writes + enables + starts the unit
|
gpu-turnstile --install-service # installs into /var/lib/gpu-turnstile, enables + starts
|
||||||
|
gpu-turnstile --install-service --no-copy # register in place instead
|
||||||
gpu-turnstile --remove-service
|
gpu-turnstile --remove-service
|
||||||
```
|
```
|
||||||
|
|
||||||
The unit (`/etc/systemd/system/gpu-turnstile.service`) is `Type=notify`:
|
The unit (`/etc/systemd/system/gpu-turnstile.service`) is `Type=notify`:
|
||||||
`systemctl start` blocks until the listeners are actually bound, a 30 s
|
`systemctl start` blocks until the listeners are actually bound, a 30 s
|
||||||
watchdog restarts the process if it wedges, and logs land in the journal
|
watchdog restarts the process if it wedges, and logs land in the journal
|
||||||
(`journalctl -u gpu-turnstile -f`) unless `LOG_FILE` is set. Put the
|
(`journalctl -u gpu-turnstile -f`) unless `LOG_FILE` is set. Install
|
||||||
config in a `gpu-turnstile.env` next to the binary (or pass
|
copies the binary to `/var/lib/gpu-turnstile/` and the config to
|
||||||
`-config /path` during install). The notify integration is a no-op in
|
`/etc/gpu-turnstile.env` (edit that one after installing). The service
|
||||||
|
runs sandboxed with `DynamicUser=yes` — a transient low-privilege UID,
|
||||||
|
read-only filesystem except its install dir (so self-update keeps
|
||||||
|
working), no capabilities, syscall-filtered: same least-privilege idea as
|
||||||
|
the Windows virtual account. The notify integration is a no-op in
|
||||||
containers and interactive shells.
|
containers and interactive shells.
|
||||||
|
|
||||||
**Auto-update is on by default**: the binary checks the repo's latest
|
**Auto-update is on by default**: the binary checks the repo's latest
|
||||||
release on startup and every `UPDATE_INTERVAL`, verifies the Ed25519
|
release on startup and every `UPDATE_INTERVAL`, verifies the Ed25519
|
||||||
signature of the download against the public key embedded at build time,
|
signature of the download against the public key embedded at build time,
|
||||||
and — once the GPU lock is idle — restarts the service onto the new
|
and — once the GPU lock is idle — restarts the service onto the new
|
||||||
version. Disable with `AUTO_UPDATE=false`. Releases are signed by CI with
|
version. `APP_VER` controls the target: `dev` disables updates, `stable`
|
||||||
|
(the default) tracks the latest release, and an exact `vX.Y.Z` pins that
|
||||||
|
release (even as a downgrade or to replace a dev build). Disable entirely
|
||||||
|
with `AUTO_UPDATE=false`. Releases are signed by CI with
|
||||||
OpenSSL; the matching public key lives in `internal/update/pubkey.go`
|
OpenSSL; the matching public key lives in `internal/update/pubkey.go`
|
||||||
(one-time setup: `openssl genpkey -algorithm ed25519 -out private.pem`,
|
(one-time setup: `openssl genpkey -algorithm ed25519 -out private.pem`,
|
||||||
`openssl pkey -in private.pem -pubout -out public.pem`; private key goes
|
`openssl pkey -in private.pem -pubout -out public.pem`; private key goes
|
||||||
to the `RELEASE_SIGNING_KEY` repo secret, public key is committed).
|
to the `RELEASE_SIGNING_KEY` repo secret, public key is committed).
|
||||||
|
`gpu-turnstile --force-update` checks immediately, stages the new binary
|
||||||
|
and restarts the running service (elevating via UAC only if needed).
|
||||||
|
|
||||||
### Docker
|
### Docker
|
||||||
|
|
||||||
|
|||||||
@@ -158,6 +158,8 @@ override file values. A missing file is fine; a malformed one is fatal.
|
|||||||
| `UPDATE_INTERVAL` | `6h` | auto-update check interval |
|
| `UPDATE_INTERVAL` | `6h` | auto-update check interval |
|
||||||
| `UPDATE_REPO` | `https://git.rambossek.at/PUBLIC/gpu-turnstile` | repository to check for releases |
|
| `UPDATE_REPO` | `https://git.rambossek.at/PUBLIC/gpu-turnstile` | repository to check for releases |
|
||||||
| `UPDATE_ASSET` | `gpu-turnstile.exe` | release asset to download |
|
| `UPDATE_ASSET` | `gpu-turnstile.exe` | release asset to download |
|
||||||
|
| `APP_VER` | `stable` | version to run: `dev` disables updates, `stable` tracks the latest release, or an exact `vX.Y.Z` pin (up- or downgraded to) |
|
||||||
|
| `CFG_VER` | _(installer-managed)_ | config format reference written by `--install-service`; missing = the file is replaced with a fresh sample (backup `.bak`) |
|
||||||
|
|
||||||
Startup fails fast on unparsable values and when neither consumer URL is
|
Startup fails fast on unparsable values and when neither consumer URL is
|
||||||
set. Enabled upstreams are probed once at start (`/api/version`,
|
set. Enabled upstreams are probed once at start (`/api/version`,
|
||||||
@@ -169,35 +171,78 @@ The binary runs natively on Windows (the current primary deployment) and on
|
|||||||
Linux with systemd (the future GPU server), as well as in Docker.
|
Linux with systemd (the future GPU server), as well as in Docker.
|
||||||
|
|
||||||
Service management is the same on both platforms:
|
Service management is the same on both platforms:
|
||||||
`gpu-turnstile --install-service [-config path]` registers and starts an
|
`gpu-turnstile --install-service [-config path]` installs, registers and
|
||||||
auto-start service; `--remove-service` stops and unregisters it (both need
|
starts an auto-start service; `--remove-service` stops and uninstalls it.
|
||||||
an elevated/root shell). The legacy form `gpu-turnstile service
|
Both need admin/root; on Windows a non-elevated shell triggers a UAC
|
||||||
install|remove` does the same thing.
|
prompt instead of failing — the command relaunches itself elevated, waits
|
||||||
|
for the child, and mirrors its exit code. The legacy form
|
||||||
|
`gpu-turnstile service install|remove` does the same thing.
|
||||||
|
|
||||||
|
Re-running install on an already-registered service converges instead of
|
||||||
|
failing: a running service is stopped first, the installed binary copy is
|
||||||
|
refreshed only when the content differs, the registration (Windows service
|
||||||
|
config / systemd unit) is updated only where it drifted, and the service is
|
||||||
|
started again only if it was running before.
|
||||||
|
|
||||||
|
By default install creates the canonical layout and copies the binary into
|
||||||
|
it (Windows: `%ProgramFiles%\gpu-turnstile\`, plus
|
||||||
|
`%ProgramData%\gpu-turnstile\` for logs; Linux: `/var/lib/gpu-turnstile/`
|
||||||
|
with the config at `/etc/gpu-turnstile.env`). If there is no config at all,
|
||||||
|
install writes a sample env file covering every setting — each with a
|
||||||
|
comment line, everything commented out — except the `CFG_VER`/`APP_VER`
|
||||||
|
header and `LOG_FILE`, which is active on Windows
|
||||||
|
(`%ProgramData%\gpu-turnstile\gpu-turnstile.log`) since a service has no
|
||||||
|
console; on Linux it stays commented because stderr goes to the journal.
|
||||||
|
The first line is `CFG_VER=vX.Y.Z`, recording the installer version. When a
|
||||||
|
later version's install finds an older `CFG_VER`, it appends every setting
|
||||||
|
the file does not mention (commented or not) at the end and updates
|
||||||
|
`CFG_VER`; a file without `CFG_VER` is invalid and gets replaced by a fresh
|
||||||
|
sample, with the old content kept as `<file>.bak`. `--no-copy` registers
|
||||||
|
the current executable location as-is and leaves the config untouched.
|
||||||
|
|
||||||
### Windows
|
### Windows
|
||||||
|
|
||||||
- `--install-service` registers a Windows service; recovery actions restart
|
- `--install-service` creates `%ProgramFiles%\gpu-turnstile\` and
|
||||||
it 5 s after any failure.
|
`%ProgramData%\gpu-turnstile\`, copies the exe and (if none exists there
|
||||||
- **Layout**: install to `C:\Program Files\gpu-turnstile\` (exe plus
|
yet) the `gpu-turnstile.env` into the Program Files directory, and
|
||||||
`gpu-turnstile.env`); logs belong in `C:\ProgramData\gpu-turnstile\` via
|
registers that copy as a Windows service; recovery actions restart it
|
||||||
`LOG_FILE`. The service must be able to write its install directory for
|
5 s after any failure. The install ensures the env file sets `LOG_FILE`
|
||||||
self-updates — Program Files is writable by LocalSystem and admins, which
|
to `%ProgramData%\gpu-turnstile\gpu-turnstile.log` since there is no
|
||||||
is why running as the default `LocalSystem` account is the simple choice.
|
console — an existing `LOG_FILE` setting is kept.
|
||||||
- **Account**: the default `LocalSystem` works out of the box. For least
|
- **Account**: the service always runs as the virtual account
|
||||||
privilege, create the service with the virtual account
|
`NT SERVICE\gpu-turnstile` — a per-service low-privilege identity the
|
||||||
`NT SERVICE\gpu-turnstile` and grant it write access to the install and
|
SCM manages (no password, automatic logon-as-a-service right, no admin
|
||||||
log directories only (no network logon, no user profile).
|
rights, gone when the service is removed). The installer grants it
|
||||||
- Use a config file (above) for the service — Windows services have no
|
modify access to the install and data directories (self-updates rewrite
|
||||||
convenient environment. Logs go to `LOG_FILE` since there is no console.
|
the exe) and the `LOG_FILE` directory (created if missing), plus read
|
||||||
|
access to the config file when it lives elsewhere. The grants happen
|
||||||
|
after service registration because the virtual account's SID only exists
|
||||||
|
from that point on; if a grant fails the service registration is rolled
|
||||||
|
back.
|
||||||
|
|
||||||
### Linux (systemd)
|
### Linux (systemd)
|
||||||
|
|
||||||
- `--install-service` writes `/etc/systemd/system/gpu-turnstile.service`
|
- `--install-service` copies the binary to `/var/lib/gpu-turnstile/`,
|
||||||
with `ExecStart` pointing at the current executable and the `-config`
|
copies the config to `/etc/gpu-turnstile.env` if none exists there yet,
|
||||||
file, then runs `systemctl daemon-reload` and `enable --now`. The unit
|
writes `/etc/systemd/system/gpu-turnstile.service`, then runs `systemctl
|
||||||
runs as root (it must be able to overwrite its own binary for
|
daemon-reload` and `enable --now`. `--remove-service` removes the unit
|
||||||
self-updates); harden with `ProtectSystem=strict` plus a writable
|
and the installed binary; the `/etc` config stays. The binary does not
|
||||||
`ReadWritePaths` if desired.
|
go to `/usr/local/sbin` on purpose: replacing a running binary needs
|
||||||
|
write access to its *directory*, and granting the sandboxed service
|
||||||
|
write access to a shared system directory would let a compromised
|
||||||
|
service overwrite other binaries — `/var/lib/gpu-turnstile` is
|
||||||
|
exclusively ours.
|
||||||
|
- **Sandboxing** mirrors the Windows virtual account: the unit runs with
|
||||||
|
`DynamicUser=yes` — a transient per-service UID with no login, no home
|
||||||
|
and no password, managed entirely by systemd. `ProtectSystem=strict`
|
||||||
|
makes the filesystem read-only except `StateDirectory=gpu-turnstile`
|
||||||
|
(the install dir, so self-updates can rewrite the binary), plus
|
||||||
|
`NoNewPrivileges`, `ProtectHome`, `PrivateTmp`, `ProtectKernel*`,
|
||||||
|
`ProtectControlGroups`, `RestrictNamespaces`, `RestrictSUIDSGID`,
|
||||||
|
`RestrictRealtime`, `LockPersonality`, `MemoryDenyWriteExecute`, empty
|
||||||
|
capability sets, `RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6` and
|
||||||
|
`SystemCallFilter=@system-service`. The proxy needs only outbound
|
||||||
|
TCP/UDP and the notify socket, so it loses nothing.
|
||||||
- The unit is `Type=notify`: the binary sends `READY=1` via
|
- The unit is `Type=notify`: the binary sends `READY=1` via
|
||||||
`github.com/coreos/go-systemd` only after the listeners are bound, so
|
`github.com/coreos/go-systemd` only after the listeners are bound, so
|
||||||
`systemctl start` blocks until the proxy accepts connections. A 30 s
|
`systemctl start` blocks until the proxy accepts connections. A 30 s
|
||||||
@@ -211,14 +256,25 @@ install|remove` does the same thing.
|
|||||||
`RestartSec=5s` brings up the staged binary after the updater exits with
|
`RestartSec=5s` brings up the staged binary after the updater exits with
|
||||||
code 3.
|
code 3.
|
||||||
- **Auto-update**: on startup and every `UPDATE_INTERVAL`, the binary
|
- **Auto-update**: on startup and every `UPDATE_INTERVAL`, the binary
|
||||||
checks `UPDATE_REPO`'s latest release; if its tag is a newer `vX.Y.Z`,
|
consults `APP_VER`: `dev` disables updates; `stable` (the default)
|
||||||
it downloads `UPDATE_ASSET` plus its `.sig` (and `.sha256` when present)
|
fetches `UPDATE_REPO`'s latest release and applies it when its tag is a
|
||||||
and verifies an Ed25519 signature against the public key embedded in
|
newer `vX.Y.Z` (a `dev` binary cannot be compared and is replaced by the
|
||||||
|
latest release); a `vX.Y.Z` pin fetches that exact tag and stages it on
|
||||||
|
any difference, including downgrades. Applying means downloading
|
||||||
|
`UPDATE_ASSET` plus its `.sig` (and `.sha256` when present) and verifying
|
||||||
|
an Ed25519 signature against the public key embedded in
|
||||||
`internal/update/pubkey.go`. A verified binary is swapped in next to the
|
`internal/update/pubkey.go`. A verified binary is swapped in next to the
|
||||||
running exe (rename-aside, allowed on Windows), and once the GPU lock is
|
running exe (rename-aside, allowed on Windows), and once the GPU lock is
|
||||||
idle the process exits with code 3 so the service recovery restarts it
|
idle the process exits with code 3 so the service recovery restarts it
|
||||||
on the new version. Interactive runs only log "restart to apply".
|
on the new version. Interactive runs only log "restart to apply".
|
||||||
`dev` builds and builds without an embedded public key never update.
|
Builds without an embedded public key never update.
|
||||||
|
- **`--force-update`** runs the same check immediately, single-shot: one
|
||||||
|
attempt with a 30 s timeout, then exit — "up to date" (exit 0) or the
|
||||||
|
error (exit 1), no retries. When a newer release is found it downloads,
|
||||||
|
verifies and stages it, and if the service is running it restarts it
|
||||||
|
right away (otherwise the new version applies on next start). On Windows
|
||||||
|
it elevates via UAC only when the stage or restart needs permissions the
|
||||||
|
caller does not have.
|
||||||
- **Signing setup (one time)**: `openssl genpkey -algorithm ed25519 -out
|
- **Signing setup (one time)**: `openssl genpkey -algorithm ed25519 -out
|
||||||
private.pem`; `openssl pkey -in private.pem -pubout -out public.pem`.
|
private.pem`; `openssl pkey -in private.pem -pubout -out public.pem`.
|
||||||
Private key → repo secret `RELEASE_SIGNING_KEY`; public key → committed into
|
Private key → repo secret `RELEASE_SIGNING_KEY`; public key → committed into
|
||||||
@@ -302,7 +358,8 @@ are new.
|
|||||||
receives the first chunk before the last is sent (no buffering).
|
receives the first chunk before the last is sent (no buffering).
|
||||||
- `internal/config`: env-file parsing, precedence, fail-fast values.
|
- `internal/config`: env-file parsing, precedence, fail-fast values.
|
||||||
- `internal/update`: fake Gitea releases API; staged update happy path,
|
- `internal/update`: fake Gitea releases API; staged update happy path,
|
||||||
tampered signature rejected, older versions and dev builds skipped.
|
tampered signature rejected, older versions skipped, APP_VER=dev and
|
||||||
|
pinned releases honored.
|
||||||
|
|
||||||
## Build and CI
|
## Build and CI
|
||||||
|
|
||||||
|
|||||||
+251
-44
@@ -3,10 +3,12 @@
|
|||||||
package main
|
package main
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"bufio"
|
||||||
"context"
|
"context"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
|
"io/fs"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net"
|
"net"
|
||||||
"net/http"
|
"net/http"
|
||||||
@@ -34,24 +36,127 @@ var version = "dev"
|
|||||||
// process: a signed update has been staged and the GPU lock is idle.
|
// process: a signed update has been staged and the GPU lock is idle.
|
||||||
const exitCodeUpdate = 3
|
const exitCodeUpdate = 3
|
||||||
|
|
||||||
func main() {
|
// stdoutIsTerminal reports whether stdout is a console (char device), as
|
||||||
configPath, install, remove, args := parseFlags(os.Args[1:])
|
// opposed to a pipe or file — which is what Docker containers and services
|
||||||
|
// see.
|
||||||
|
func stdoutIsTerminal() bool {
|
||||||
|
fi, err := os.Stdout.Stat()
|
||||||
|
return err == nil && fi.Mode()&os.ModeCharDevice != 0
|
||||||
|
}
|
||||||
|
|
||||||
|
// parseFlags extracts -config <path> (or -config=<path>), the
|
||||||
|
// --install-service / --remove-service switches, --no-copy, -h/--help,
|
||||||
|
// -v/--version, --force-update and the hidden --elevated-child marker from
|
||||||
|
// args.
|
||||||
|
func parseFlags(args []string) (configPath string, install, remove, noCopy, help, showVersion, forceUpdate, elevatedChild bool, rest []string) {
|
||||||
|
rest = args[:0]
|
||||||
|
for i := 0; i < len(args); i++ {
|
||||||
switch {
|
switch {
|
||||||
case install && remove:
|
case args[i] == "-config" && i+1 < len(args):
|
||||||
fmt.Fprintf(os.Stderr, "gpu-turnstile: --install-service and --remove-service are mutually exclusive\n")
|
configPath = args[i+1]
|
||||||
|
i++
|
||||||
|
case strings.HasPrefix(args[i], "-config="):
|
||||||
|
configPath = strings.TrimPrefix(args[i], "-config=")
|
||||||
|
case args[i] == "--install-service" || args[i] == "-install-service":
|
||||||
|
install = true
|
||||||
|
case args[i] == "--remove-service" || args[i] == "-remove-service":
|
||||||
|
remove = true
|
||||||
|
case args[i] == "--no-copy" || args[i] == "-no-copy":
|
||||||
|
noCopy = true
|
||||||
|
case args[i] == "-h" || args[i] == "--help" || args[i] == "-help":
|
||||||
|
help = true
|
||||||
|
case args[i] == "-v" || args[i] == "--version" || args[i] == "-version":
|
||||||
|
showVersion = true
|
||||||
|
case args[i] == "--force-update" || args[i] == "-force-update":
|
||||||
|
forceUpdate = true
|
||||||
|
case args[i] == "--elevated-child":
|
||||||
|
elevatedChild = true
|
||||||
|
default:
|
||||||
|
rest = append(rest, args[i])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return configPath, install, remove, noCopy, help, showVersion, forceUpdate, elevatedChild, rest
|
||||||
|
}
|
||||||
|
|
||||||
|
// versionLine is printed at the top of every help and error screen.
|
||||||
|
func versionLine() string { return "gpu-turnstile " + version }
|
||||||
|
|
||||||
|
const usageText = `GPU arbitration proxy for Ollama + ComfyUI
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
gpu-turnstile -config <path> run the proxy
|
||||||
|
gpu-turnstile --install-service [--no-copy] [-config path] install + start as a service
|
||||||
|
gpu-turnstile --remove-service stop + uninstall the service
|
||||||
|
gpu-turnstile -v | --version print just the version
|
||||||
|
gpu-turnstile --force-update check for a signed update now,
|
||||||
|
apply it and restart the service
|
||||||
|
gpu-turnstile -h | --help this help
|
||||||
|
|
||||||
|
Options:
|
||||||
|
-config <path> config file (default: gpu-turnstile.env next to the exe)
|
||||||
|
--install-service copies the binary into the canonical location
|
||||||
|
(%ProgramFiles%\gpu-turnstile or /var/lib/gpu-turnstile)
|
||||||
|
unless --no-copy; on Windows a UAC prompt appears when
|
||||||
|
the shell is not elevated
|
||||||
|
--no-copy with --install-service: register the current location as-is
|
||||||
|
|
||||||
|
All runtime settings are environment variables or KEY=VALUE lines in the
|
||||||
|
config file (OLLAMA_URL, COMFY_URL, LOGLEVEL, ...); see README.md.
|
||||||
|
`
|
||||||
|
|
||||||
|
// printHelp prints the version header plus the full help text.
|
||||||
|
func printHelp() {
|
||||||
|
fmt.Printf("%s — %s", versionLine(), usageText)
|
||||||
|
}
|
||||||
|
|
||||||
|
// fatalUsage prints the version header, an error message and the one-line
|
||||||
|
// usage summary, then exits with code 2.
|
||||||
|
func fatalUsage(format string, args ...any) {
|
||||||
|
fmt.Fprintf(os.Stderr, "%s\n\n", versionLine())
|
||||||
|
fmt.Fprintf(os.Stderr, format+"\n\n", args...)
|
||||||
|
fmt.Fprintln(os.Stderr, "usage: gpu-turnstile [-config path] [--install-service [--no-copy] | --remove-service]")
|
||||||
|
fmt.Fprintln(os.Stderr, " gpu-turnstile service install|remove [-config path]")
|
||||||
os.Exit(2)
|
os.Exit(2)
|
||||||
case install:
|
}
|
||||||
os.Exit(serviceCommand(configPath, []string{"install"}))
|
|
||||||
case remove:
|
func main() {
|
||||||
os.Exit(serviceCommand(configPath, []string{"remove"}))
|
configPath, install, remove, noCopy, help, showVersion, forceUpdate, elevatedChild, args := parseFlags(os.Args[1:])
|
||||||
|
if showVersion {
|
||||||
|
fmt.Println(version)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
bare := configPath == "" && !install && !remove && !forceUpdate && !elevatedChild && len(args) == 0
|
||||||
|
if help || (bare && stdoutIsTerminal()) {
|
||||||
|
// Bare invocation in a terminal (e.g. double-clicked on Windows)
|
||||||
|
// shows the help instead of starting a proxy window with no visible
|
||||||
|
// explanation. Without a terminal — Docker containers, services,
|
||||||
|
// pipes — a bare invocation starts the proxy as before.
|
||||||
|
printHelp()
|
||||||
|
return
|
||||||
}
|
}
|
||||||
if len(args) > 0 && args[0] == "service" {
|
if len(args) > 0 && args[0] == "service" {
|
||||||
os.Exit(serviceCommand(configPath, args[1:]))
|
// Legacy subcommand form: gpu-turnstile service install|remove.
|
||||||
|
if len(args) != 2 || (args[1] != "install" && args[1] != "remove") {
|
||||||
|
fatalUsage("error: expected 'service install' or 'service remove'")
|
||||||
|
}
|
||||||
|
install = args[1] == "install"
|
||||||
|
remove = !install
|
||||||
|
args = nil
|
||||||
|
}
|
||||||
|
switch {
|
||||||
|
case install && remove:
|
||||||
|
fatalUsage("error: --install-service and --remove-service are mutually exclusive")
|
||||||
|
case forceUpdate && (install || remove):
|
||||||
|
fatalUsage("error: --force-update cannot be combined with --install-service/--remove-service")
|
||||||
|
case install:
|
||||||
|
os.Exit(serviceCommand(configPath, true, noCopy, elevatedChild))
|
||||||
|
case remove:
|
||||||
|
os.Exit(serviceCommand(configPath, false, noCopy, elevatedChild))
|
||||||
|
case forceUpdate:
|
||||||
|
os.Exit(forceUpdateCommand(configPath, elevatedChild))
|
||||||
}
|
}
|
||||||
if len(args) > 0 {
|
if len(args) > 0 {
|
||||||
fmt.Fprintf(os.Stderr, "usage: gpu-turnstile [-config path] [--install-service | --remove-service]\n")
|
fatalUsage("error: unknown arguments: %s", strings.Join(args, " "))
|
||||||
fmt.Fprintf(os.Stderr, " gpu-turnstile service install|remove [-config path]\n")
|
|
||||||
os.Exit(2)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if exePath, err := os.Executable(); err == nil {
|
if exePath, err := os.Executable(); err == nil {
|
||||||
@@ -60,7 +165,7 @@ func main() {
|
|||||||
|
|
||||||
cfg, err := loadMergedConfig(configPath)
|
cfg, err := loadMergedConfig(configPath)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
fmt.Fprintf(os.Stderr, "gpu-turnstile: %v\n", err)
|
fmt.Fprintf(os.Stderr, "%s\n\ngpu-turnstile: %v\n", versionLine(), err)
|
||||||
os.Exit(1)
|
os.Exit(1)
|
||||||
}
|
}
|
||||||
log, logOut, logCloser := newLogger(cfg)
|
log, logOut, logCloser := newLogger(cfg)
|
||||||
@@ -81,28 +186,6 @@ func main() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// parseFlags extracts -config <path> (or -config=<path>) and the
|
|
||||||
// --install-service / --remove-service switches from args.
|
|
||||||
func parseFlags(args []string) (configPath string, install, remove bool, rest []string) {
|
|
||||||
rest = args[:0]
|
|
||||||
for i := 0; i < len(args); i++ {
|
|
||||||
switch {
|
|
||||||
case args[i] == "-config" && i+1 < len(args):
|
|
||||||
configPath = args[i+1]
|
|
||||||
i++
|
|
||||||
case strings.HasPrefix(args[i], "-config="):
|
|
||||||
configPath = strings.TrimPrefix(args[i], "-config=")
|
|
||||||
case args[i] == "--install-service" || args[i] == "-install-service":
|
|
||||||
install = true
|
|
||||||
case args[i] == "--remove-service" || args[i] == "-remove-service":
|
|
||||||
remove = true
|
|
||||||
default:
|
|
||||||
rest = append(rest, args[i])
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return configPath, install, remove, rest
|
|
||||||
}
|
|
||||||
|
|
||||||
// defaultConfigPath returns gpu-turnstile.env next to the executable.
|
// defaultConfigPath returns gpu-turnstile.env next to the executable.
|
||||||
func defaultConfigPath() string {
|
func defaultConfigPath() string {
|
||||||
exe, err := os.Executable()
|
exe, err := os.Executable()
|
||||||
@@ -172,26 +255,150 @@ func newLogger(cfg config.Config) (*slog.Logger, io.Writer, io.Closer) {
|
|||||||
return log, out, closer
|
return log, out, closer
|
||||||
}
|
}
|
||||||
|
|
||||||
func serviceCommand(configPath string, args []string) int {
|
// waitForEnter keeps an elevated child's console window open until the
|
||||||
if len(args) != 1 || (args[0] != "install" && args[0] != "remove") {
|
// user has read the output.
|
||||||
fmt.Fprintf(os.Stderr, "usage: gpu-turnstile service install|remove [-config path]\n")
|
func waitForEnter() {
|
||||||
return 2
|
fmt.Print("\nPress Enter to close this window...")
|
||||||
|
bufio.NewReader(os.Stdin).ReadString('\n')
|
||||||
|
}
|
||||||
|
|
||||||
|
// elevateAndMirror relaunches the current command elevated (UAC) and
|
||||||
|
// mirrors the child's exit code. verb is used in messages.
|
||||||
|
func elevateAndMirror(verb string) (int, bool) {
|
||||||
|
args := append(append([]string{}, os.Args[1:]...), "--elevated-child")
|
||||||
|
code, err := service.RelaunchElevated(args)
|
||||||
|
if errors.Is(err, service.ErrUserCancelled) {
|
||||||
|
fmt.Fprintln(os.Stderr, "gpu-turnstile: UAC prompt declined")
|
||||||
|
return 1, true
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
fmt.Fprintf(os.Stderr, "gpu-turnstile: could not elevate: %v\n", err)
|
||||||
|
return 1, true
|
||||||
|
}
|
||||||
|
if code != 0 {
|
||||||
|
fmt.Fprintf(os.Stderr, "gpu-turnstile %s failed in the elevated process (exit %d)\n", verb, code)
|
||||||
|
return code, true
|
||||||
|
}
|
||||||
|
return 0, true
|
||||||
|
}
|
||||||
|
|
||||||
|
// isPermission reports whether err is a permission problem (Windows
|
||||||
|
// ERROR_ACCESS_DENIED, POSIX EACCES/EPERM, possibly wrapped).
|
||||||
|
func isPermission(err error) bool {
|
||||||
|
return errors.Is(err, fs.ErrPermission) || strings.Contains(strings.ToLower(err.Error()), "access is denied")
|
||||||
|
}
|
||||||
|
|
||||||
|
// forceUpdateCommand checks for a signed update immediately, stages it if
|
||||||
|
// newer, and restarts the service when it is running so the new binary
|
||||||
|
// takes effect. Staging into a system directory and restarting a service
|
||||||
|
// need admin rights; instead of prompting unconditionally, permission
|
||||||
|
// failures trigger the UAC relaunch so a dev copy in a user-writable
|
||||||
|
// directory updates without a prompt.
|
||||||
|
func forceUpdateCommand(configPath string, elevatedChild bool) int {
|
||||||
|
if elevatedChild {
|
||||||
|
defer waitForEnter()
|
||||||
|
}
|
||||||
|
cfg, err := loadMergedConfig(configPath)
|
||||||
|
if errors.Is(err, config.ErrNoConsumer) {
|
||||||
|
err = nil // update settings do not depend on a consumer URL
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
fmt.Fprintf(os.Stderr, "%s\n\ngpu-turnstile: %v\n", versionLine(), err)
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
exePath, err := os.Executable()
|
||||||
|
if err != nil {
|
||||||
|
fmt.Fprintf(os.Stderr, "gpu-turnstile: cannot locate executable: %v\n", err)
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
log, _, logCloser := newLogger(cfg)
|
||||||
|
defer logCloser.Close()
|
||||||
|
if cfg.AppVersion == "dev" {
|
||||||
|
fmt.Printf("%s: APP_VER=dev, updates disabled\n", versionLine())
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
u := &update.Updater{Repo: cfg.UpdateRepo, Asset: cfg.UpdateAsset, Version: version, Desired: cfg.AppVersion, Log: log}
|
||||||
|
|
||||||
|
// Single-shot: one attempt, fail fast when the server is unreachable
|
||||||
|
// instead of hanging in a TCP connect for minutes.
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 30*time.Second)
|
||||||
|
defer cancel()
|
||||||
|
staged, err := u.Check(ctx, exePath)
|
||||||
|
if err != nil && isPermission(err) && !service.Elevated() {
|
||||||
|
code, _ := elevateAndMirror("--force-update")
|
||||||
|
if code == 0 {
|
||||||
|
fmt.Println("update applied (elevated)")
|
||||||
|
}
|
||||||
|
return code
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
fmt.Fprintf(os.Stderr, "%s\n\ngpu-turnstile: update check failed: %v\n", versionLine(), err)
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
if !staged {
|
||||||
|
fmt.Printf("%s is up to date\n", versionLine())
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
fmt.Printf("%s: update staged\n", versionLine())
|
||||||
|
restarted, err := service.RestartIfRunning()
|
||||||
|
if err != nil && isPermission(err) && !service.Elevated() {
|
||||||
|
code, _ := elevateAndMirror("--force-update")
|
||||||
|
if code == 0 {
|
||||||
|
fmt.Println("update applied (elevated)")
|
||||||
|
}
|
||||||
|
return code
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
fmt.Fprintf(os.Stderr, "gpu-turnstile: update staged but service restart failed: %v\n", err)
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
if restarted {
|
||||||
|
fmt.Println("service restarted on the new version")
|
||||||
|
} else {
|
||||||
|
fmt.Println("no running service; the new version applies on next start")
|
||||||
|
}
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
// serviceCommand installs (copyBin = register the canonical-layout copy)
|
||||||
|
// or removes the service and reports the result. On Windows, when the
|
||||||
|
// shell is not elevated, the command relaunches itself through a UAC
|
||||||
|
// prompt and mirrors the elevated child's exit code. An elevated child
|
||||||
|
// waits for a keypress so its console window does not flash closed before
|
||||||
|
// the output can be read.
|
||||||
|
func serviceCommand(configPath string, install, noCopy, elevatedChild bool) int {
|
||||||
|
verb, doneVerb := "remove", "removed"
|
||||||
|
if install {
|
||||||
|
verb, doneVerb = "install", "installed"
|
||||||
|
}
|
||||||
|
if elevatedChild {
|
||||||
|
defer waitForEnter()
|
||||||
|
}
|
||||||
|
if !service.Elevated() {
|
||||||
|
code, done := elevateAndMirror(verb)
|
||||||
|
if done && code != 0 {
|
||||||
|
return code
|
||||||
|
}
|
||||||
|
if done {
|
||||||
|
fmt.Printf("service %s: %s (elevated)\n", service.Name, doneVerb)
|
||||||
|
return 0
|
||||||
|
}
|
||||||
}
|
}
|
||||||
var err error
|
var err error
|
||||||
if args[0] == "install" {
|
if install {
|
||||||
path := resolveConfigPath(configPath)
|
path := resolveConfigPath(configPath)
|
||||||
if abs, absErr := filepath.Abs(path); absErr == nil {
|
if abs, absErr := filepath.Abs(path); absErr == nil {
|
||||||
path = abs
|
path = abs
|
||||||
}
|
}
|
||||||
err = service.Install(path)
|
err = service.Install(path, !noCopy, version)
|
||||||
} else {
|
} else {
|
||||||
err = service.Remove()
|
err = service.Remove()
|
||||||
}
|
}
|
||||||
if err != nil {
|
if err != nil {
|
||||||
fmt.Fprintf(os.Stderr, "gpu-turnstile service %s: %v\n", args[0], err)
|
fmt.Fprintf(os.Stderr, "gpu-turnstile service %s: %v\n", verb, err)
|
||||||
return 1
|
return 1
|
||||||
}
|
}
|
||||||
fmt.Printf("service %s: %sd\n", service.Name, args[0])
|
fmt.Printf("service %s: %s\n", service.Name, doneVerb)
|
||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -363,7 +570,7 @@ func updateLoop(ctx context.Context, cfg config.Config, log *slog.Logger, lk *lo
|
|||||||
log.Warn("auto-update disabled: cannot locate executable", "err", err)
|
log.Warn("auto-update disabled: cannot locate executable", "err", err)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
u := &update.Updater{Repo: cfg.UpdateRepo, Asset: cfg.UpdateAsset, Version: version, Log: log}
|
u := &update.Updater{Repo: cfg.UpdateRepo, Asset: cfg.UpdateAsset, Version: version, Desired: cfg.AppVersion, Log: log}
|
||||||
for {
|
for {
|
||||||
staged, err := u.Check(ctx, exePath)
|
staged, err := u.Check(ctx, exePath)
|
||||||
if err != nil && ctx.Err() == nil {
|
if err != nil && ctx.Err() == nil {
|
||||||
|
|||||||
@@ -6,7 +6,7 @@
|
|||||||
# ComfyUI --listen 0.0.0.0 --port 8189).
|
# ComfyUI --listen 0.0.0.0 --port 8189).
|
||||||
services:
|
services:
|
||||||
gpu-turnstile:
|
gpu-turnstile:
|
||||||
image: git.rambossek.at/public/gpu-turnstile:v0.1.5
|
image: git.rambossek.at/public/gpu-turnstile:v0.1.7
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
# Each consumer is enabled by setting its URL; leave one unset to
|
# Each consumer is enabled by setting its URL; leave one unset to
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ package config
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"bufio"
|
"bufio"
|
||||||
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
@@ -37,6 +38,11 @@ type Config struct {
|
|||||||
UpdateRepo string
|
UpdateRepo string
|
||||||
UpdateAsset string
|
UpdateAsset string
|
||||||
|
|
||||||
|
// AppVersion is the version the user wants to run: "dev" disables
|
||||||
|
// updates, "stable" tracks the latest release, anything else is an
|
||||||
|
// exact vX.Y.Z release to pin. From APP_VER; defaults to "stable".
|
||||||
|
AppVersion string
|
||||||
|
|
||||||
// LLMBusyMode is "wait" (hold requests until the lock is free or
|
// LLMBusyMode is "wait" (hold requests until the lock is free or
|
||||||
// LLMWaitTimeout expires) or "reject" (immediately answer with
|
// LLMWaitTimeout expires) or "reject" (immediately answer with
|
||||||
// LLMBusyStatus + Retry-After when an image job is active or pending).
|
// LLMBusyStatus + Retry-After when an image job is active or pending).
|
||||||
@@ -75,6 +81,7 @@ func Defaults() Config {
|
|||||||
UpdateInterval: 6 * time.Hour,
|
UpdateInterval: 6 * time.Hour,
|
||||||
UpdateRepo: "https://git.rambossek.at/PUBLIC/gpu-turnstile",
|
UpdateRepo: "https://git.rambossek.at/PUBLIC/gpu-turnstile",
|
||||||
UpdateAsset: "gpu-turnstile.exe",
|
UpdateAsset: "gpu-turnstile.exe",
|
||||||
|
AppVersion: "stable",
|
||||||
|
|
||||||
LLMBusyMode: "wait",
|
LLMBusyMode: "wait",
|
||||||
LLMBusyStatus: 503,
|
LLMBusyStatus: 503,
|
||||||
@@ -84,6 +91,11 @@ func Defaults() Config {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ErrNoConsumer is returned by Load when neither OLLAMA_URL nor COMFY_URL
|
||||||
|
// is set. Commands that never talk to an upstream (--force-update) may
|
||||||
|
// ignore it and proceed with the rest of the configuration.
|
||||||
|
var ErrNoConsumer = errors.New("at least one of OLLAMA_URL or COMFY_URL must be set (each URL enables its consumer)")
|
||||||
|
|
||||||
// ParseEnvFile parses a .env-style file: KEY=VALUE lines, blank lines and
|
// ParseEnvFile parses a .env-style file: KEY=VALUE lines, blank lines and
|
||||||
// #-comments are ignored, no quoting. A line without '=' is an error.
|
// #-comments are ignored, no quoting. A line without '=' is an error.
|
||||||
func ParseEnvFile(r io.Reader) (map[string]string, error) {
|
func ParseEnvFile(r io.Reader) (map[string]string, error) {
|
||||||
@@ -199,6 +211,17 @@ func Load(getenv func(string) string) (Config, error) {
|
|||||||
}
|
}
|
||||||
cfg.BusyRetryAfter = n
|
cfg.BusyRetryAfter = n
|
||||||
}
|
}
|
||||||
|
if v := getenv("APP_VER"); v != "" {
|
||||||
|
switch {
|
||||||
|
case v == "dev" || v == "stable":
|
||||||
|
cfg.AppVersion = v
|
||||||
|
default:
|
||||||
|
if _, ok := parseVersion(v); !ok {
|
||||||
|
return cfg, fmt.Errorf("APP_VER: must be \"dev\", \"stable\" or a vX.Y.Z version")
|
||||||
|
}
|
||||||
|
cfg.AppVersion = "v" + strings.TrimPrefix(v, "v")
|
||||||
|
}
|
||||||
|
}
|
||||||
// LOGLEVEL is the canonical spelling; LOG_LEVEL is kept as an alias.
|
// LOGLEVEL is the canonical spelling; LOG_LEVEL is kept as an alias.
|
||||||
logLevelValue := getenv("LOGLEVEL")
|
logLevelValue := getenv("LOGLEVEL")
|
||||||
if logLevelValue == "" {
|
if logLevelValue == "" {
|
||||||
@@ -219,7 +242,7 @@ func Load(getenv func(string) string) (Config, error) {
|
|||||||
return cfg, fmt.Errorf("LOG_FORMAT: must be \"text\" or \"json\"")
|
return cfg, fmt.Errorf("LOG_FORMAT: must be \"text\" or \"json\"")
|
||||||
}
|
}
|
||||||
if cfg.OllamaURL == "" && cfg.ComfyURL == "" {
|
if cfg.OllamaURL == "" && cfg.ComfyURL == "" {
|
||||||
return cfg, fmt.Errorf("at least one of OLLAMA_URL or COMFY_URL must be set (each URL enables its consumer)")
|
return cfg, ErrNoConsumer
|
||||||
}
|
}
|
||||||
return cfg, nil
|
return cfg, nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
package config
|
package config
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"errors"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
@@ -39,6 +40,38 @@ func TestLoadRequiresConsumer(t *testing.T) {
|
|||||||
if err == nil || !strings.Contains(err.Error(), "OLLAMA_URL") {
|
if err == nil || !strings.Contains(err.Error(), "OLLAMA_URL") {
|
||||||
t.Fatalf("err = %v, want missing-consumer error", err)
|
t.Fatalf("err = %v, want missing-consumer error", err)
|
||||||
}
|
}
|
||||||
|
if !errors.Is(err, ErrNoConsumer) {
|
||||||
|
t.Fatalf("err = %v, want errors.Is(err, ErrNoConsumer)", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAppVersion(t *testing.T) {
|
||||||
|
load := func(appVer string) (Config, error) {
|
||||||
|
return Load(func(k string) string {
|
||||||
|
switch k {
|
||||||
|
case "OLLAMA_URL":
|
||||||
|
return "http://127.0.0.1:11435"
|
||||||
|
case "APP_VER":
|
||||||
|
return appVer
|
||||||
|
}
|
||||||
|
return ""
|
||||||
|
})
|
||||||
|
}
|
||||||
|
cfg, err := load("")
|
||||||
|
if err != nil || cfg.AppVersion != "stable" {
|
||||||
|
t.Fatalf("default AppVersion = %q, err %v; want stable", cfg.AppVersion, err)
|
||||||
|
}
|
||||||
|
for _, v := range []string{"dev", "stable"} {
|
||||||
|
if cfg, err := load(v); err != nil || cfg.AppVersion != v {
|
||||||
|
t.Fatalf("APP_VER=%s: got %q, err %v", v, cfg.AppVersion, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if cfg, err := load("1.2.3"); err != nil || cfg.AppVersion != "v1.2.3" {
|
||||||
|
t.Fatalf("APP_VER=1.2.3: got %q, err %v; want normalized v1.2.3", cfg.AppVersion, err)
|
||||||
|
}
|
||||||
|
if _, err := load("nightly"); err == nil {
|
||||||
|
t.Fatal("APP_VER=nightly: want validation error")
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestParseEnvFile(t *testing.T) {
|
func TestParseEnvFile(t *testing.T) {
|
||||||
|
|||||||
@@ -0,0 +1,176 @@
|
|||||||
|
package config
|
||||||
|
|
||||||
|
import (
|
||||||
|
"fmt"
|
||||||
|
"strconv"
|
||||||
|
"strings"
|
||||||
|
)
|
||||||
|
|
||||||
|
// sampleEntry is one line pair in the sample env file: a comment and the
|
||||||
|
// (usually commented-out) KEY=VALUE line.
|
||||||
|
type sampleEntry struct {
|
||||||
|
name string
|
||||||
|
value string
|
||||||
|
comment string
|
||||||
|
active bool // rendered uncommented
|
||||||
|
}
|
||||||
|
|
||||||
|
// appVerComment documents APP_VER wherever it is rendered.
|
||||||
|
const appVerComment = `Version to run: "dev" disables updates, "stable" tracks the latest release, or pin an exact release like v0.1.7`
|
||||||
|
|
||||||
|
// sampleEntries lists every setting in sample order. logFile activates the
|
||||||
|
// LOG_FILE line (Windows install); empty keeps it commented like the rest.
|
||||||
|
// CFG_VER and APP_VER are not entries — they head the file, always active.
|
||||||
|
func sampleEntries(logFile string) []sampleEntry {
|
||||||
|
return []sampleEntry{
|
||||||
|
{"LISTEN_OLLAMA", ":11434", "Ollama-facing listener address", false},
|
||||||
|
{"LISTEN_COMFY", ":8188", "ComfyUI-facing listener address", false},
|
||||||
|
{"OLLAMA_URL", "http://127.0.0.1:11434", "Ollama upstream URL; setting it enables the Ollama consumer (default: empty = disabled)", false},
|
||||||
|
{"COMFY_URL", "http://127.0.0.1:8188", "ComfyUI upstream URL; setting it enables the ComfyUI consumer (default: empty = disabled)", false},
|
||||||
|
{"WARM_MODEL", "", "Optional model to reload after an image job (default: empty = none)", false},
|
||||||
|
{"UNLOAD_TIMEOUT", "60s", "How long to wait for Ollama to unload a model", false},
|
||||||
|
{"JOB_TIMEOUT", "15m", "Maximum time to wait for a ComfyUI job", false},
|
||||||
|
{"LLM_WAIT_TIMEOUT", "10m", "Max time an LLM request waits for the GPU before being answered 503 (wait mode)", false},
|
||||||
|
{"LLM_BUSY_MODE", "wait", `How blocked LLM requests are handled: "wait" holds them, "reject" fails them immediately`, false},
|
||||||
|
{"LLM_BUSY_STATUS", "503", "HTTP status for rejected LLM requests in reject mode (400-599, e.g. 429)", false},
|
||||||
|
{"BUSY_RETRY_AFTER", "30", "Seconds sent as Retry-After on busy responses (both modes)", false},
|
||||||
|
{"LOGLEVEL", "warn", `Log verbosity: debug, info, warn, error; "info" logs every request (LOG_LEVEL works too)`, false},
|
||||||
|
{"LOG_FORMAT", "text", `Log format: "text" or "json"`, false},
|
||||||
|
{"LOG_FILE", logFile, "Append logs to this file instead of stderr (a Windows service has no console)", logFile != ""},
|
||||||
|
{"UNLOAD_POLL_INTERVAL", "500ms", "/api/ps poll interval while unloading", false},
|
||||||
|
{"HISTORY_POLL_INTERVAL", "1s", "/history/<id> poll interval while a job runs", false},
|
||||||
|
{"PROBE_TIMEOUT", "5s", "Startup probe timeout for the enabled upstreams", false},
|
||||||
|
{"FREE_TIMEOUT", "30s", "Timeout for the POST /free call after an image job", false},
|
||||||
|
{"WARM_TIMEOUT", "2m", "Timeout for the warm-model reload after an image job", false},
|
||||||
|
{"SHUTDOWN_TIMEOUT", "10s", "Graceful shutdown timeout on SIGINT/SIGTERM", false},
|
||||||
|
{"BACKOFF_INITIAL", "1s", "First retry wait when an upstream connection fails", false},
|
||||||
|
{"BACKOFF_MAX", "60s", "Cap for the exponential retry backoff", false},
|
||||||
|
{"PROMPT_CAPTURE_LIMIT", "65536", "Bytes of the /prompt response buffered to find prompt_id (pass-through unaffected)", false},
|
||||||
|
{"AUTO_UPDATE", "true", "Poll the releases API for signed updates", false},
|
||||||
|
{"UPDATE_INTERVAL", "6h", "Auto-update check interval", false},
|
||||||
|
{"UPDATE_REPO", "https://git.rambossek.at/PUBLIC/gpu-turnstile", "Repository to check for releases", false},
|
||||||
|
{"UPDATE_ASSET", "gpu-turnstile.exe", "Release asset to download", false},
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// SampleEnv renders a sample .env file covering every setting, each with a
|
||||||
|
// comment line. Everything is commented out — so all defaults apply —
|
||||||
|
// except the CFG_VER/APP_VER header and LOG_FILE when logFile is non-empty
|
||||||
|
// (a Windows service has no console). CFG_VER records the version that
|
||||||
|
// wrote the file so later installs can upgrade it.
|
||||||
|
func SampleEnv(version, logFile string) string {
|
||||||
|
var b strings.Builder
|
||||||
|
fmt.Fprintf(&b, "CFG_VER=%s\n", version)
|
||||||
|
b.WriteString("# Config format reference, written by the installer — do not edit.\n")
|
||||||
|
b.WriteString("# The installer uses it to append newly added settings on updates.\n\n")
|
||||||
|
b.WriteString("# gpu-turnstile configuration\n")
|
||||||
|
b.WriteString("# KEY=VALUE lines; \"#\" starts a comment. Every setting below is at its\n")
|
||||||
|
b.WriteString("# default and commented out — remove the \"#\" to change it.\n")
|
||||||
|
b.WriteString("# At least one of OLLAMA_URL / COMFY_URL must be set for the proxy to start.\n\n")
|
||||||
|
writeEntry(&b, sampleEntry{"APP_VER", "stable", appVerComment, true})
|
||||||
|
for _, e := range sampleEntries(logFile) {
|
||||||
|
writeEntry(&b, e)
|
||||||
|
}
|
||||||
|
return b.String()
|
||||||
|
}
|
||||||
|
|
||||||
|
func writeEntry(b *strings.Builder, e sampleEntry) {
|
||||||
|
fmt.Fprintf(b, "# %s\n", e.comment)
|
||||||
|
if e.active {
|
||||||
|
fmt.Fprintf(b, "%s=%s\n\n", e.name, e.value)
|
||||||
|
} else {
|
||||||
|
fmt.Fprintf(b, "#%s=%s\n\n", e.name, e.value)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// SyncSample upgrades an installer-written env file: when its CFG_VER says
|
||||||
|
// it was written by an older gpu-turnstile, every setting the file does not
|
||||||
|
// mention — commented or not — is appended at the end, and CFG_VER is
|
||||||
|
// updated to version. Files without CFG_VER (hand-written or foreign),
|
||||||
|
// up-to-date files and "dev" builds are returned unchanged; changed reports
|
||||||
|
// whether the returned content differs.
|
||||||
|
func SyncSample(data, version, logFile string) (string, bool) {
|
||||||
|
if version == "" || version == "dev" {
|
||||||
|
return data, false
|
||||||
|
}
|
||||||
|
values, err := ParseEnvFile(strings.NewReader(data))
|
||||||
|
if err != nil || values["CFG_VER"] == "" {
|
||||||
|
return data, false // not installer-written; the caller decides
|
||||||
|
}
|
||||||
|
if compareVersions(values["CFG_VER"], version) >= 0 {
|
||||||
|
return data, false // same or newer
|
||||||
|
}
|
||||||
|
|
||||||
|
present := make(map[string]bool)
|
||||||
|
for _, line := range strings.Split(data, "\n") {
|
||||||
|
line = strings.TrimSpace(strings.TrimPrefix(strings.TrimSpace(line), "#"))
|
||||||
|
if name, _, ok := strings.Cut(line, "="); ok {
|
||||||
|
present[strings.TrimSpace(name)] = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
lines := strings.Split(data, "\n")
|
||||||
|
for i, l := range lines {
|
||||||
|
if strings.HasPrefix(strings.TrimSpace(l), "CFG_VER=") {
|
||||||
|
lines[i] = "CFG_VER=" + version
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
out := strings.Join(lines, "\n")
|
||||||
|
if !strings.HasSuffix(out, "\n") {
|
||||||
|
out += "\n"
|
||||||
|
}
|
||||||
|
|
||||||
|
var b strings.Builder
|
||||||
|
if !present["APP_VER"] {
|
||||||
|
fmt.Fprintf(&b, "\n# Added by gpu-turnstile %s:\n", version)
|
||||||
|
writeEntry(&b, sampleEntry{"APP_VER", "stable", appVerComment, true})
|
||||||
|
}
|
||||||
|
for _, e := range sampleEntries(logFile) {
|
||||||
|
if !present[e.name] {
|
||||||
|
fmt.Fprintf(&b, "\n# Added by gpu-turnstile %s:\n", version)
|
||||||
|
writeEntry(&b, e)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
out += b.String()
|
||||||
|
return out, out != data
|
||||||
|
}
|
||||||
|
|
||||||
|
// compareVersions orders two vX.Y.Z version strings. Unparseable versions
|
||||||
|
// (including "dev") sort before any release.
|
||||||
|
func compareVersions(a, b string) int {
|
||||||
|
pa, oka := parseVersion(a)
|
||||||
|
pb, okb := parseVersion(b)
|
||||||
|
if oka != okb {
|
||||||
|
if oka {
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
return -1
|
||||||
|
}
|
||||||
|
for i := range pa {
|
||||||
|
if pa[i] != pb[i] {
|
||||||
|
if pa[i] > pb[i] {
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
return -1
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseVersion(v string) ([3]int, bool) {
|
||||||
|
var out [3]int
|
||||||
|
v = strings.TrimPrefix(strings.TrimSpace(v), "v")
|
||||||
|
parts := strings.Split(v, ".")
|
||||||
|
if len(parts) != 3 {
|
||||||
|
return out, false
|
||||||
|
}
|
||||||
|
for i, p := range parts {
|
||||||
|
n, err := strconv.Atoi(p)
|
||||||
|
if err != nil || n < 0 {
|
||||||
|
return out, false
|
||||||
|
}
|
||||||
|
out[i] = n
|
||||||
|
}
|
||||||
|
return out, true
|
||||||
|
}
|
||||||
@@ -0,0 +1,143 @@
|
|||||||
|
package config
|
||||||
|
|
||||||
|
import (
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
const sampleLogPath = `C:\ProgramData\gpu-turnstile\gpu-turnstile.log`
|
||||||
|
|
||||||
|
var allSettingNames = []string{
|
||||||
|
"LISTEN_OLLAMA", "LISTEN_COMFY", "OLLAMA_URL", "COMFY_URL",
|
||||||
|
"WARM_MODEL", "UNLOAD_TIMEOUT", "JOB_TIMEOUT", "LLM_WAIT_TIMEOUT",
|
||||||
|
"LLM_BUSY_MODE", "LLM_BUSY_STATUS", "BUSY_RETRY_AFTER",
|
||||||
|
"LOGLEVEL", "LOG_FORMAT", "LOG_FILE",
|
||||||
|
"UNLOAD_POLL_INTERVAL", "HISTORY_POLL_INTERVAL", "PROBE_TIMEOUT",
|
||||||
|
"FREE_TIMEOUT", "WARM_TIMEOUT", "SHUTDOWN_TIMEOUT",
|
||||||
|
"BACKOFF_INITIAL", "BACKOFF_MAX", "PROMPT_CAPTURE_LIMIT",
|
||||||
|
"AUTO_UPDATE", "UPDATE_INTERVAL", "UPDATE_REPO", "UPDATE_ASSET",
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSampleEnv(t *testing.T) {
|
||||||
|
sample := SampleEnv("v0.1.7", sampleLogPath)
|
||||||
|
|
||||||
|
if !strings.HasPrefix(sample, "CFG_VER=v0.1.7\n") {
|
||||||
|
t.Errorf("first line does not carry CFG_VER: %q", strings.SplitN(sample, "\n", 2)[0])
|
||||||
|
}
|
||||||
|
|
||||||
|
// Every setting known to Load must appear.
|
||||||
|
for _, name := range allSettingNames {
|
||||||
|
if !strings.Contains(sample, name+"=") {
|
||||||
|
t.Errorf("sample is missing %s", name)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// The sample must parse cleanly; active values are CFG_VER, APP_VER
|
||||||
|
// and LOG_FILE.
|
||||||
|
values, err := ParseEnvFile(strings.NewReader(sample))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("sample does not parse: %v", err)
|
||||||
|
}
|
||||||
|
want := map[string]string{"CFG_VER": "v0.1.7", "APP_VER": "stable", "LOG_FILE": sampleLogPath}
|
||||||
|
if len(values) != len(want) {
|
||||||
|
t.Fatalf("active values = %v, want %v", values, want)
|
||||||
|
}
|
||||||
|
for k, v := range want {
|
||||||
|
if values[k] != v {
|
||||||
|
t.Errorf("%s = %q, want %q", k, values[k], v)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Without a log path LOG_FILE stays commented out.
|
||||||
|
values, err = ParseEnvFile(strings.NewReader(SampleEnv("v0.1.7", "")))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("sample without log path does not parse: %v", err)
|
||||||
|
}
|
||||||
|
if len(values) != 2 || values["LOG_FILE"] != "" {
|
||||||
|
t.Fatalf("active values = %v, want only CFG_VER and APP_VER", values)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSyncSample(t *testing.T) {
|
||||||
|
old := SampleEnv("v0.1.6", sampleLogPath)
|
||||||
|
// Simulate a setting that did not exist yet when the file was written.
|
||||||
|
old = strings.Replace(old, "#UPDATE_ASSET=gpu-turnstile.exe\n", "", 1)
|
||||||
|
|
||||||
|
out, changed := SyncSample(old, "v0.1.7", sampleLogPath)
|
||||||
|
if !changed {
|
||||||
|
t.Fatal("older installer file was not upgraded")
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "\nCFG_VER=v0.1.7\n") && !strings.HasPrefix(out, "CFG_VER=v0.1.7\n") {
|
||||||
|
t.Error("CFG_VER was not updated to the new version")
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "#UPDATE_ASSET=gpu-turnstile.exe") {
|
||||||
|
t.Error("missing setting was not appended")
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "LOG_FILE="+sampleLogPath) {
|
||||||
|
t.Error("existing active LOG_FILE was lost")
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "Added by gpu-turnstile v0.1.7") {
|
||||||
|
t.Error("appended section is not attributed")
|
||||||
|
}
|
||||||
|
if _, err := ParseEnvFile(strings.NewReader(out)); err != nil {
|
||||||
|
t.Fatalf("upgraded file does not parse: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// A file written by the same or a newer version is left alone.
|
||||||
|
if _, changed := SyncSample(SampleEnv("v0.1.7", sampleLogPath), "v0.1.7", sampleLogPath); changed {
|
||||||
|
t.Error("same-version file was modified")
|
||||||
|
}
|
||||||
|
if _, changed := SyncSample(SampleEnv("v0.2.0", sampleLogPath), "v0.1.7", sampleLogPath); changed {
|
||||||
|
t.Error("newer-version file was modified")
|
||||||
|
}
|
||||||
|
|
||||||
|
// Files without CFG_VER are not installer-written; the installer
|
||||||
|
// replaces them, SyncSample leaves them alone.
|
||||||
|
user := "OLLAMA_URL=http://host:11434\n"
|
||||||
|
if out, changed := SyncSample(user, "v0.1.7", sampleLogPath); changed || out != user {
|
||||||
|
t.Error("file without CFG_VER was modified")
|
||||||
|
}
|
||||||
|
|
||||||
|
// A dev build never upgrades.
|
||||||
|
if _, changed := SyncSample(old, "dev", sampleLogPath); changed {
|
||||||
|
t.Error("dev build modified the file")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSyncSampleAppendsMissingAppVer(t *testing.T) {
|
||||||
|
old := SampleEnv("v0.1.6", sampleLogPath)
|
||||||
|
old = strings.Replace(old, "# "+appVerComment+"\n", "", 1)
|
||||||
|
old = strings.Replace(old, "APP_VER=stable\n", "", 1)
|
||||||
|
|
||||||
|
out, changed := SyncSample(old, "v0.1.7", sampleLogPath)
|
||||||
|
if !changed {
|
||||||
|
t.Fatal("file without APP_VER was not upgraded")
|
||||||
|
}
|
||||||
|
values, err := ParseEnvFile(strings.NewReader(out))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("upgraded file does not parse: %v", err)
|
||||||
|
}
|
||||||
|
if values["APP_VER"] != "stable" {
|
||||||
|
t.Fatalf("APP_VER = %q, want appended default \"stable\"", values["APP_VER"])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestCompareVersions(t *testing.T) {
|
||||||
|
cases := []struct {
|
||||||
|
a, b string
|
||||||
|
want int
|
||||||
|
}{
|
||||||
|
{"v0.1.6", "v0.1.7", -1},
|
||||||
|
{"v0.1.7", "v0.1.7", 0},
|
||||||
|
{"v1.0.0", "v0.9.9", 1},
|
||||||
|
{"0.1.7", "v0.1.6", 1},
|
||||||
|
{"dev", "v0.1.7", -1},
|
||||||
|
{"v0.1.7", "dev", 1},
|
||||||
|
{"dev", "dev", 0},
|
||||||
|
}
|
||||||
|
for _, c := range cases {
|
||||||
|
if got := compareVersions(c.a, c.b); got != c.want {
|
||||||
|
t.Errorf("compareVersions(%q, %q) = %d, want %d", c.a, c.b, got, c.want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
// Shared env-file handling for the installers (Windows and Linux).
|
||||||
|
package service
|
||||||
|
|
||||||
|
import (
|
||||||
|
"fmt"
|
||||||
|
"os"
|
||||||
|
"strings"
|
||||||
|
|
||||||
|
"gpu-turnstile/internal/config"
|
||||||
|
)
|
||||||
|
|
||||||
|
// syncEnvFile ensures the installed env file at path is a current
|
||||||
|
// installer-written sample. A missing file is created; a file without a
|
||||||
|
// CFG_VER line (hand-written or from before versioning) is invalid and
|
||||||
|
// replaced by a fresh sample after a .bak backup; a file written by an
|
||||||
|
// older version gets newly added settings appended via config.SyncSample.
|
||||||
|
// logPath activates the LOG_FILE line (Windows); empty leaves it commented.
|
||||||
|
func syncEnvFile(path, version, logPath string) error {
|
||||||
|
data, err := os.ReadFile(path)
|
||||||
|
switch {
|
||||||
|
case os.IsNotExist(err):
|
||||||
|
return writeEnvFile(path, config.SampleEnv(version, logPath))
|
||||||
|
case err != nil:
|
||||||
|
return fmt.Errorf("read %s: %w", path, err)
|
||||||
|
}
|
||||||
|
values, perr := config.ParseEnvFile(strings.NewReader(string(data)))
|
||||||
|
if perr == nil && values["CFG_VER"] != "" {
|
||||||
|
synced, changed := config.SyncSample(string(data), version, logPath)
|
||||||
|
if !changed {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
return writeEnvFile(path, synced)
|
||||||
|
}
|
||||||
|
// No readable CFG_VER: the file is invalid — keep a backup and start
|
||||||
|
// from a fresh sample.
|
||||||
|
if err := os.WriteFile(path+".bak", data, 0o644); err != nil {
|
||||||
|
return fmt.Errorf("back up %s: %w", path, err)
|
||||||
|
}
|
||||||
|
return writeEnvFile(path, config.SampleEnv(version, logPath))
|
||||||
|
}
|
||||||
|
|
||||||
|
func writeEnvFile(path, content string) error {
|
||||||
|
if err := os.WriteFile(path, []byte(content), 0o644); err != nil {
|
||||||
|
return fmt.Errorf("write %s: %w", path, err)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
package service
|
||||||
|
|
||||||
|
import "errors"
|
||||||
|
|
||||||
|
// ErrUserCancelled is returned by RelaunchElevated when the user declines
|
||||||
|
// the UAC prompt. Windows-only in practice; defined here so cross-platform
|
||||||
|
// callers can compare against it.
|
||||||
|
var ErrUserCancelled = errors.New("UAC prompt declined")
|
||||||
@@ -2,12 +2,14 @@
|
|||||||
|
|
||||||
// Package service integrates gpu-turnstile with systemd on Linux: running
|
// Package service integrates gpu-turnstile with systemd on Linux: running
|
||||||
// under a unit with readiness notification and watchdog, plus
|
// under a unit with readiness notification and watchdog, plus
|
||||||
// install/remove helpers that manage a system unit.
|
// install/remove helpers that manage a hardened system unit.
|
||||||
package service
|
package service
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"bytes"
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"os"
|
"os"
|
||||||
"os/exec"
|
"os/exec"
|
||||||
"os/signal"
|
"os/signal"
|
||||||
@@ -21,9 +23,26 @@ const Name = "gpu-turnstile"
|
|||||||
// unitPath is where Install writes the unit file.
|
// unitPath is where Install writes the unit file.
|
||||||
const unitPath = "/etc/systemd/system/" + Name + ".service"
|
const unitPath = "/etc/systemd/system/" + Name + ".service"
|
||||||
|
|
||||||
|
// stateDir holds the installed binary (and staged updates); the unit's
|
||||||
|
// StateDirectory= directive makes systemd own it and grant the dynamic
|
||||||
|
// user write access. etcConfig is the config file the unit loads.
|
||||||
|
const (
|
||||||
|
stateDir = "/var/lib/" + Name
|
||||||
|
etcConfig = "/etc/" + Name + ".env"
|
||||||
|
)
|
||||||
|
|
||||||
// IsService reports whether the process was started by systemd.
|
// IsService reports whether the process was started by systemd.
|
||||||
func IsService() bool { return os.Getenv("INVOCATION_ID") != "" }
|
func IsService() bool { return os.Getenv("INVOCATION_ID") != "" }
|
||||||
|
|
||||||
|
// Elevated is always true on Linux: there is no UAC equivalent; privilege
|
||||||
|
// errors surface from the failing operation with a "run as root" hint.
|
||||||
|
func Elevated() bool { return true }
|
||||||
|
|
||||||
|
// RelaunchElevated is a Windows-only concept (UAC).
|
||||||
|
func RelaunchElevated([]string) (int, error) {
|
||||||
|
return 0, fmt.Errorf("elevated relaunch is only supported on Windows")
|
||||||
|
}
|
||||||
|
|
||||||
// Run executes run with SIGINT/SIGTERM cancellation (which is how systemctl
|
// Run executes run with SIGINT/SIGTERM cancellation (which is how systemctl
|
||||||
// stop signals the process) and tells systemd when the shutdown begins.
|
// stop signals the process) and tells systemd when the shutdown begins.
|
||||||
func Run(run func(ctx context.Context) error) error {
|
func Run(run func(ctx context.Context) error) error {
|
||||||
@@ -33,10 +52,17 @@ func Run(run func(ctx context.Context) error) error {
|
|||||||
return run(ctx)
|
return run(ctx)
|
||||||
}
|
}
|
||||||
|
|
||||||
// renderUnit builds the systemd unit: Type=notify so systemctl start blocks
|
// renderUnit builds the hardened systemd unit: Type=notify so systemctl
|
||||||
// until the listeners are bound, a 30s watchdog, and restart-on-failure
|
// start blocks until the listeners are bound, a 30s watchdog, and
|
||||||
// with a 5s delay — which is also what brings up a staged update after the
|
// restart-on-failure with a 5s delay — which is also what brings up a
|
||||||
// updater exits with a non-zero code.
|
// staged update after the updater exits with a non-zero code.
|
||||||
|
//
|
||||||
|
// Sandboxing mirrors the Windows virtual account: DynamicUser=yes gives
|
||||||
|
// the service a transient per-service UID with no login and no home, the
|
||||||
|
// filesystem is read-only except StateDirectory (the install dir, so
|
||||||
|
// self-updates can rewrite the binary), and the usual no-privilege-escalation
|
||||||
|
// directives apply. The proxy needs nothing but outbound TCP/UDP and the
|
||||||
|
// notify socket, so it loses nothing.
|
||||||
func renderUnit(exePath, configPath string) string {
|
func renderUnit(exePath, configPath string) string {
|
||||||
return fmt.Sprintf(`[Unit]
|
return fmt.Sprintf(`[Unit]
|
||||||
Description=gpu-turnstile GPU arbitration proxy for Ollama and ComfyUI
|
Description=gpu-turnstile GPU arbitration proxy for Ollama and ComfyUI
|
||||||
@@ -50,14 +76,69 @@ ExecStart=%q -config %q
|
|||||||
Restart=on-failure
|
Restart=on-failure
|
||||||
RestartSec=5s
|
RestartSec=5s
|
||||||
|
|
||||||
|
DynamicUser=yes
|
||||||
|
StateDirectory=%s
|
||||||
|
ProtectSystem=strict
|
||||||
|
ProtectHome=yes
|
||||||
|
PrivateTmp=yes
|
||||||
|
NoNewPrivileges=yes
|
||||||
|
ProtectKernelTunables=yes
|
||||||
|
ProtectKernelModules=yes
|
||||||
|
ProtectKernelLogs=yes
|
||||||
|
ProtectControlGroups=yes
|
||||||
|
ProtectClock=yes
|
||||||
|
RestrictNamespaces=yes
|
||||||
|
RestrictSUIDSGID=yes
|
||||||
|
RestrictRealtime=yes
|
||||||
|
LockPersonality=yes
|
||||||
|
MemoryDenyWriteExecute=yes
|
||||||
|
CapabilityBoundingSet=
|
||||||
|
AmbientCapabilities=
|
||||||
|
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
|
||||||
|
SystemCallFilter=@system-service
|
||||||
|
SystemCallErrorNumber=EPERM
|
||||||
|
|
||||||
[Install]
|
[Install]
|
||||||
WantedBy=multi-user.target
|
WantedBy=multi-user.target
|
||||||
`, exePath, configPath)
|
`, exePath, configPath, Name)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Install writes the unit for the current executable and the given config
|
// copyFile copies src to dst, creating dst with the given mode.
|
||||||
// file, then enables and starts it. Needs root.
|
func copyFile(src, dst string, mode os.FileMode) error {
|
||||||
func Install(configPath string) error {
|
in, err := os.Open(src)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
defer in.Close()
|
||||||
|
out, err := os.OpenFile(dst, os.O_CREATE|os.O_TRUNC|os.O_WRONLY, mode)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
defer out.Close()
|
||||||
|
if _, err := io.Copy(out, in); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return out.Close()
|
||||||
|
}
|
||||||
|
|
||||||
|
// Install copies the current executable into /var/lib/gpu-turnstile, makes
|
||||||
|
// sure /etc/gpu-turnstile.env exists (copied from the given config file if
|
||||||
|
// provided), writes the hardened unit, then enables and starts it. With
|
||||||
|
// copyBin=false the current executable location and config path are
|
||||||
|
// registered as-is instead. Needs root.
|
||||||
|
//
|
||||||
|
// Re-running install converges an existing unit instead of failing: it is
|
||||||
|
// stopped first if active, the installed binary is replaced only when the
|
||||||
|
// content differs, the unit file is rewritten (followed by daemon-reload)
|
||||||
|
// only when it changed, and the service is started again only if it was
|
||||||
|
// active before.
|
||||||
|
//
|
||||||
|
// The binary lives in the StateDirectory rather than /usr/local/sbin on
|
||||||
|
// purpose: replacing a running binary needs write access to its
|
||||||
|
// *directory*, and granting the sandboxed service user write access to a
|
||||||
|
// shared system directory would let a compromised service overwrite other
|
||||||
|
// binaries. /var/lib/gpu-turnstile is exclusively ours.
|
||||||
|
func Install(configPath string, copyBin bool, version string) error {
|
||||||
exe, err := os.Executable()
|
exe, err := os.Executable()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
@@ -65,26 +146,114 @@ func Install(configPath string) error {
|
|||||||
if abs, absErr := filepath.Abs(exe); absErr == nil {
|
if abs, absErr := filepath.Abs(exe); absErr == nil {
|
||||||
exe = abs
|
exe = abs
|
||||||
}
|
}
|
||||||
if err := os.WriteFile(unitPath, []byte(renderUnit(exe, configPath)), 0o644); err != nil {
|
unit := Name + ".service"
|
||||||
|
_, statErr := os.Stat(unitPath)
|
||||||
|
fresh := os.IsNotExist(statErr)
|
||||||
|
wasRunning := exec.Command("systemctl", "is-active", "--quiet", unit).Run() == nil
|
||||||
|
if wasRunning {
|
||||||
|
if out, err := exec.Command("systemctl", "stop", unit).CombinedOutput(); err != nil {
|
||||||
|
return fmt.Errorf("systemctl stop (run as root): %w (%s)", err, out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
cfg := etcConfig
|
||||||
|
if copyBin {
|
||||||
|
if err := os.MkdirAll(stateDir, 0o755); err != nil {
|
||||||
|
return fmt.Errorf("create %s (run as root): %w", stateDir, err)
|
||||||
|
}
|
||||||
|
installedExe := filepath.Join(stateDir, Name)
|
||||||
|
if exe != installedExe {
|
||||||
|
if same, _ := sameFileContent(exe, installedExe); !same {
|
||||||
|
if err := copyFile(exe, installedExe, 0o755); err != nil {
|
||||||
|
return fmt.Errorf("install binary to %s: %w", installedExe, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
exe = installedExe
|
||||||
|
if _, err := os.Stat(etcConfig); os.IsNotExist(err) && configPath != "" {
|
||||||
|
copyFile(configPath, etcConfig, 0o644) //nolint:errcheck // best effort
|
||||||
|
}
|
||||||
|
// Missing configs get a fully commented sample (LOG_FILE stays
|
||||||
|
// commented — stderr goes to the journal on Linux);
|
||||||
|
// installer-written ones from older versions get new settings
|
||||||
|
// appended; anything without CFG_VER is invalid and gets replaced
|
||||||
|
// (backup kept as .bak).
|
||||||
|
if err := syncEnvFile(etcConfig, version, ""); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
} else if configPath != "" {
|
||||||
|
if abs, absErr := filepath.Abs(configPath); absErr == nil {
|
||||||
|
cfg = abs
|
||||||
|
}
|
||||||
|
}
|
||||||
|
rendered := renderUnit(exe, cfg)
|
||||||
|
if old, _ := os.ReadFile(unitPath); string(old) != rendered {
|
||||||
|
if err := os.WriteFile(unitPath, []byte(rendered), 0o644); err != nil {
|
||||||
return fmt.Errorf("write %s (run as root): %w", unitPath, err)
|
return fmt.Errorf("write %s (run as root): %w", unitPath, err)
|
||||||
}
|
}
|
||||||
if out, err := exec.Command("systemctl", "daemon-reload").CombinedOutput(); err != nil {
|
if out, err := exec.Command("systemctl", "daemon-reload").CombinedOutput(); err != nil {
|
||||||
return fmt.Errorf("systemctl daemon-reload: %w (%s)", err, out)
|
return fmt.Errorf("systemctl daemon-reload: %w (%s)", err, out)
|
||||||
}
|
}
|
||||||
if out, err := exec.Command("systemctl", "enable", "--now", Name+".service").CombinedOutput(); err != nil {
|
}
|
||||||
|
if fresh {
|
||||||
|
if out, err := exec.Command("systemctl", "enable", "--now", unit).CombinedOutput(); err != nil {
|
||||||
return fmt.Errorf("systemctl enable --now: %w (%s)", err, out)
|
return fmt.Errorf("systemctl enable --now: %w (%s)", err, out)
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
if exec.Command("systemctl", "is-enabled", "--quiet", unit).Run() != nil {
|
||||||
|
if out, err := exec.Command("systemctl", "enable", unit).CombinedOutput(); err != nil {
|
||||||
|
return fmt.Errorf("systemctl enable: %w (%s)", err, out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if wasRunning {
|
||||||
|
if out, err := exec.Command("systemctl", "start", unit).CombinedOutput(); err != nil {
|
||||||
|
return fmt.Errorf("systemctl start: %w (%s)", err, out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
// Remove stops and disables the service and deletes the unit file.
|
// sameFileContent reports whether two files hold identical bytes. A missing
|
||||||
|
// destination is simply "different".
|
||||||
|
func sameFileContent(a, b string) (bool, error) {
|
||||||
|
ba, err := os.ReadFile(a)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
bb, err := os.ReadFile(b)
|
||||||
|
if os.IsNotExist(err) {
|
||||||
|
return false, nil
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
return bytes.Equal(ba, bb), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// Remove stops and disables the service and deletes the unit file and the
|
||||||
|
// installed binary. The config file in /etc is left in place (user data).
|
||||||
func Remove() error {
|
func Remove() error {
|
||||||
exec.Command("systemctl", "disable", "--now", Name+".service").Run() // ignore: may not exist
|
exec.Command("systemctl", "disable", "--now", Name+".service").Run() // ignore: may not exist
|
||||||
if err := os.Remove(unitPath); err != nil && !os.IsNotExist(err) {
|
if err := os.Remove(unitPath); err != nil && !os.IsNotExist(err) {
|
||||||
return fmt.Errorf("remove %s: %w", unitPath, err)
|
return fmt.Errorf("remove %s: %w", unitPath, err)
|
||||||
}
|
}
|
||||||
|
os.RemoveAll(stateDir) // installed binary + staged updates; ignore error
|
||||||
if out, err := exec.Command("systemctl", "daemon-reload").CombinedOutput(); err != nil {
|
if out, err := exec.Command("systemctl", "daemon-reload").CombinedOutput(); err != nil {
|
||||||
return fmt.Errorf("systemctl daemon-reload: %w (%s)", err, out)
|
return fmt.Errorf("systemctl daemon-reload: %w (%s)", err, out)
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// RestartIfRunning restarts the systemd unit when it is active (used after
|
||||||
|
// a forced update staged a new binary). Reports whether a restart
|
||||||
|
// happened. An inactive or missing unit is not an error. Needs root.
|
||||||
|
func RestartIfRunning() (bool, error) {
|
||||||
|
if err := exec.Command("systemctl", "is-active", "--quiet", Name+".service").Run(); err != nil {
|
||||||
|
return false, nil // inactive or not installed
|
||||||
|
}
|
||||||
|
if out, err := exec.Command("systemctl", "restart", Name+".service").CombinedOutput(); err != nil {
|
||||||
|
return false, fmt.Errorf("systemctl restart (run as root): %w (%s)", err, out)
|
||||||
|
}
|
||||||
|
return true, nil
|
||||||
|
}
|
||||||
|
|||||||
@@ -8,13 +8,19 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
func TestRenderUnit(t *testing.T) {
|
func TestRenderUnit(t *testing.T) {
|
||||||
unit := renderUnit("/usr/local/bin/gpu-turnstile", "/etc/gpu-turnstile.env")
|
unit := renderUnit("/var/lib/gpu-turnstile/gpu-turnstile", "/etc/gpu-turnstile.env")
|
||||||
for _, want := range []string{
|
for _, want := range []string{
|
||||||
"Type=notify",
|
"Type=notify",
|
||||||
"WatchdogSec=30s",
|
"WatchdogSec=30s",
|
||||||
`ExecStart="/usr/local/bin/gpu-turnstile" -config "/etc/gpu-turnstile.env"`,
|
`ExecStart="/var/lib/gpu-turnstile/gpu-turnstile" -config "/etc/gpu-turnstile.env"`,
|
||||||
"Restart=on-failure",
|
"Restart=on-failure",
|
||||||
"WantedBy=multi-user.target",
|
"WantedBy=multi-user.target",
|
||||||
|
"DynamicUser=yes",
|
||||||
|
"StateDirectory=gpu-turnstile",
|
||||||
|
"ProtectSystem=strict",
|
||||||
|
"NoNewPrivileges=yes",
|
||||||
|
"RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6",
|
||||||
|
"SystemCallFilter=@system-service",
|
||||||
} {
|
} {
|
||||||
if !strings.Contains(unit, want) {
|
if !strings.Contains(unit, want) {
|
||||||
t.Fatalf("unit missing %q:\n%s", want, unit)
|
t.Fatalf("unit missing %q:\n%s", want, unit)
|
||||||
|
|||||||
@@ -28,8 +28,18 @@ func Run(run func(ctx context.Context) error) error {
|
|||||||
return run(ctx)
|
return run(ctx)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Install is unsupported on non-Windows platforms.
|
// Install is unsupported on non-Windows, non-Linux platforms.
|
||||||
func Install(string) error { return errUnsupported }
|
func Install(string, bool, string) error { return errUnsupported }
|
||||||
|
|
||||||
// Remove is unsupported on non-Windows platforms.
|
// Remove is unsupported on non-Windows, non-Linux platforms.
|
||||||
func Remove() error { return errUnsupported }
|
func Remove() error { return errUnsupported }
|
||||||
|
|
||||||
|
// Elevated is always true here: there is no UAC concept, and privilege
|
||||||
|
// errors surface from the failing operation with a "run as root" hint.
|
||||||
|
func Elevated() bool { return true }
|
||||||
|
|
||||||
|
// RelaunchElevated is unsupported on non-Windows, non-Linux platforms.
|
||||||
|
func RelaunchElevated([]string) (int, error) { return 0, errUnsupported }
|
||||||
|
|
||||||
|
// RestartIfRunning is a no-op on platforms without service integration.
|
||||||
|
func RestartIfRunning() (bool, error) { return false, nil }
|
||||||
|
|||||||
@@ -2,22 +2,54 @@
|
|||||||
|
|
||||||
// Package service integrates gpu-turnstile with the Windows Service
|
// Package service integrates gpu-turnstile with the Windows Service
|
||||||
// Control Manager: running as a service with graceful stop, plus
|
// Control Manager: running as a service with graceful stop, plus
|
||||||
// install/remove helpers.
|
// install/remove helpers. Installed services always run as the virtual
|
||||||
|
// account NT SERVICE\gpu-turnstile — a per-service low-privilege identity
|
||||||
|
// managed by the SCM, with no password and no admin rights.
|
||||||
package service
|
package service
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"bytes"
|
||||||
"context"
|
"context"
|
||||||
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"os"
|
"os"
|
||||||
|
"os/exec"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"syscall"
|
||||||
"time"
|
"time"
|
||||||
|
"unsafe"
|
||||||
|
|
||||||
|
"golang.org/x/sys/windows"
|
||||||
"golang.org/x/sys/windows/svc"
|
"golang.org/x/sys/windows/svc"
|
||||||
"golang.org/x/sys/windows/svc/mgr"
|
"golang.org/x/sys/windows/svc/mgr"
|
||||||
|
|
||||||
|
"gpu-turnstile/internal/config"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Name is the Windows service name.
|
// Name is the Windows service name.
|
||||||
const Name = "gpu-turnstile"
|
const Name = "gpu-turnstile"
|
||||||
|
|
||||||
|
// virtualAccount is the per-service identity the service runs as. The SCM
|
||||||
|
// manages it: no password, automatic "log on as a service" right, gone
|
||||||
|
// when the service is removed.
|
||||||
|
const virtualAccount = `NT SERVICE\` + Name
|
||||||
|
|
||||||
|
// installDirs returns the canonical install (Program Files) and data
|
||||||
|
// (ProgramData) directories.
|
||||||
|
func installDirs() (install, data string) {
|
||||||
|
pf := os.Getenv("ProgramFiles")
|
||||||
|
if pf == "" {
|
||||||
|
pf = `C:\Program Files`
|
||||||
|
}
|
||||||
|
pd := os.Getenv("ProgramData")
|
||||||
|
if pd == "" {
|
||||||
|
pd = `C:\ProgramData`
|
||||||
|
}
|
||||||
|
return filepath.Join(pf, Name), filepath.Join(pd, Name)
|
||||||
|
}
|
||||||
|
|
||||||
// IsService reports whether the process is running as a Windows service.
|
// IsService reports whether the process is running as a Windows service.
|
||||||
func IsService() bool {
|
func IsService() bool {
|
||||||
isSvc, err := svc.IsWindowsService()
|
isSvc, err := svc.IsWindowsService()
|
||||||
@@ -64,34 +96,179 @@ func (h *handler) Execute(_ []string, requests <-chan svc.ChangeRequest, status
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Install registers gpu-turnstile as an auto-start Windows service whose
|
// Install registers gpu-turnstile as an auto-start Windows service running
|
||||||
// binPath loads the given config file. Recovery actions restart the
|
// as the NT SERVICE\gpu-turnstile virtual account, whose binPath loads the
|
||||||
// service after 5s on failure — this is also what brings up a staged
|
// given config file. With copyBin it first creates the canonical layout —
|
||||||
// update after the updater exits with a non-zero code.
|
// the binary is copied into %ProgramFiles%\gpu-turnstile and the config
|
||||||
func Install(configPath string) error {
|
// next to it (an existing config there is kept), %ProgramData%\gpu-turnstile
|
||||||
|
// is created for logs — and registers that copy; with copyBin=false the
|
||||||
|
// current executable location is registered as-is. Recovery actions restart
|
||||||
|
// the service after 5s on failure — this is also what brings up a staged
|
||||||
|
// update after the updater exits with a non-zero code. After registering,
|
||||||
|
// the virtual account is granted modify access to the install and data
|
||||||
|
// directories (self-updates rewrite the exe), and read access to the
|
||||||
|
// config file if it lives elsewhere. The grants must come after
|
||||||
|
// CreateService: the virtual account's SID only exists once the service is
|
||||||
|
// registered.
|
||||||
|
//
|
||||||
|
// Re-running install on an existing service converges instead of failing:
|
||||||
|
// the service is stopped first if running (so the binary can be replaced),
|
||||||
|
// the installed binary is refreshed only when the content differs, the
|
||||||
|
// registration is updated only where it drifted, and the service is
|
||||||
|
// started again only if it was running before.
|
||||||
|
func Install(configPath string, copyBin bool, version string) error {
|
||||||
exe, err := os.Executable()
|
exe, err := os.Executable()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
if abs, absErr := filepath.Abs(exe); absErr == nil {
|
||||||
|
exe = abs
|
||||||
|
}
|
||||||
|
if configPath != "" {
|
||||||
|
if abs, absErr := filepath.Abs(configPath); absErr == nil {
|
||||||
|
configPath = abs
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
m, err := mgr.Connect()
|
m, err := mgr.Connect()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("connect to service manager (run as administrator): %w", err)
|
return fmt.Errorf("connect to service manager (run as administrator): %w", err)
|
||||||
}
|
}
|
||||||
defer m.Disconnect()
|
defer m.Disconnect()
|
||||||
|
|
||||||
|
// An existing service is converged, not an error. Stop it first so the
|
||||||
|
// binary copy can be replaced, and remember whether to start it again.
|
||||||
|
var s *mgr.Service
|
||||||
|
wasRunning := false
|
||||||
|
if existing, openErr := m.OpenService(Name); openErr == nil {
|
||||||
|
s = existing
|
||||||
|
defer s.Close()
|
||||||
|
if st, qErr := s.Query(); qErr == nil &&
|
||||||
|
(st.State == svc.Running || st.State == svc.StartPending) {
|
||||||
|
wasRunning = true
|
||||||
|
if err := stopAndWait(s); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
installDir, dataDir := installDirs()
|
||||||
|
if copyBin {
|
||||||
|
targetCfg := filepath.Join(installDir, "gpu-turnstile.env")
|
||||||
|
if !strings.EqualFold(filepath.Dir(exe), installDir) {
|
||||||
|
if err := os.MkdirAll(installDir, 0o755); err != nil {
|
||||||
|
return fmt.Errorf("create %s: %w", installDir, err)
|
||||||
|
}
|
||||||
|
installedExe := filepath.Join(installDir, "gpu-turnstile.exe")
|
||||||
|
if same, _ := sameFileContent(exe, installedExe); !same {
|
||||||
|
if err := copyFile(exe, installedExe); err != nil {
|
||||||
|
return fmt.Errorf("copy binary to %s: %w", installedExe, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
exe = installedExe
|
||||||
|
if configPath != "" && !strings.EqualFold(configPath, targetCfg) {
|
||||||
|
if _, statErr := os.Stat(targetCfg); os.IsNotExist(statErr) {
|
||||||
|
copyFile(configPath, targetCfg) //nolint:errcheck // best effort
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// A service has no console: without LOG_FILE the output vanishes, so
|
||||||
|
// the sample pre-wires it to ProgramData. Missing configs get a
|
||||||
|
// fresh sample; installer-written ones from older versions get new
|
||||||
|
// settings appended; anything without CFG_VER is invalid and gets
|
||||||
|
// replaced (backup kept as .bak).
|
||||||
|
logPath := filepath.Join(dataDir, "gpu-turnstile.log")
|
||||||
|
if err := syncEnvFile(targetCfg, version, logPath); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
configPath = targetCfg
|
||||||
|
}
|
||||||
binPath := fmt.Sprintf(`"%s" -config "%s"`, exe, configPath)
|
binPath := fmt.Sprintf(`"%s" -config "%s"`, exe, configPath)
|
||||||
s, err := m.CreateService(Name, binPath, mgr.Config{
|
|
||||||
|
if s == nil {
|
||||||
|
s, err = m.CreateService(Name, binPath, mgr.Config{
|
||||||
StartType: mgr.StartAutomatic,
|
StartType: mgr.StartAutomatic,
|
||||||
DisplayName: "gpu-turnstile",
|
DisplayName: "gpu-turnstile",
|
||||||
Description: "GPU arbitration proxy for Ollama and ComfyUI",
|
Description: "GPU arbitration proxy for Ollama and ComfyUI",
|
||||||
|
ServiceStartName: virtualAccount,
|
||||||
})
|
})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("create service: %w", err)
|
return fmt.Errorf("create service: %w", err)
|
||||||
}
|
}
|
||||||
defer s.Close()
|
defer s.Close()
|
||||||
|
|
||||||
restart := mgr.RecoveryAction{Type: mgr.ServiceRestart, Delay: 5 * time.Second}
|
if err := ensureRecovery(s); err != nil {
|
||||||
if err := s.SetRecoveryActions([]mgr.RecoveryAction{restart, restart, restart}, 24*60*60); err != nil {
|
s.Delete() // roll back so a retry starts clean
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if err := grantAll(exe, configPath); err != nil {
|
||||||
|
s.Delete() // roll back so a retry starts clean
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
// Best effort: start now instead of waiting for the next boot. A
|
||||||
|
// missing config (no consumer URLs) fails the start; the service stays
|
||||||
|
// registered and can be started once the config exists.
|
||||||
|
s.Start()
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// Existing service: update the registration only where it drifted.
|
||||||
|
cur, err := s.Config()
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("query service config: %w", err)
|
||||||
|
}
|
||||||
|
const displayName = "gpu-turnstile"
|
||||||
|
const description = "GPU arbitration proxy for Ollama and ComfyUI"
|
||||||
|
if cur.BinaryPathName != binPath ||
|
||||||
|
cur.StartType != mgr.StartAutomatic ||
|
||||||
|
cur.ServiceStartName != virtualAccount ||
|
||||||
|
cur.DisplayName != displayName ||
|
||||||
|
cur.Description != description {
|
||||||
|
upd := cur
|
||||||
|
upd.BinaryPathName = binPath
|
||||||
|
upd.StartType = mgr.StartAutomatic
|
||||||
|
upd.ServiceStartName = virtualAccount
|
||||||
|
upd.DisplayName = displayName
|
||||||
|
upd.Description = description
|
||||||
|
if err := s.UpdateConfig(upd); err != nil {
|
||||||
|
return fmt.Errorf("update service config: %w", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if err := ensureRecovery(s); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
// Idempotent: re-assert the virtual account's ACLs (granting an
|
||||||
|
// existing ACE is a no-op).
|
||||||
|
if err := grantAll(exe, configPath); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if wasRunning {
|
||||||
|
if err := s.Start(); err != nil {
|
||||||
|
return fmt.Errorf("start service: %w", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// ensureRecovery makes sure the service restarts 5s after a failure — the
|
||||||
|
// mechanism that also brings up a staged update. The current actions are
|
||||||
|
// queried first so an up-to-date service is left untouched.
|
||||||
|
func ensureRecovery(s *mgr.Service) error {
|
||||||
|
want := mgr.RecoveryAction{Type: mgr.ServiceRestart, Delay: 5 * time.Second}
|
||||||
|
actions, err := s.RecoveryActions()
|
||||||
|
onFailure, flagErr := s.RecoveryActionsOnNonCrashFailures()
|
||||||
|
if err == nil && flagErr == nil && onFailure && len(actions) == 3 {
|
||||||
|
ok := true
|
||||||
|
for _, a := range actions {
|
||||||
|
if a.Type != want.Type || a.Delay != want.Delay {
|
||||||
|
ok = false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if ok {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if err := s.SetRecoveryActions([]mgr.RecoveryAction{want, want, want}, 24*60*60); err != nil {
|
||||||
return fmt.Errorf("set recovery actions: %w", err)
|
return fmt.Errorf("set recovery actions: %w", err)
|
||||||
}
|
}
|
||||||
if err := s.SetRecoveryActionsOnNonCrashFailures(true); err != nil {
|
if err := s.SetRecoveryActionsOnNonCrashFailures(true); err != nil {
|
||||||
@@ -100,7 +277,97 @@ func Install(configPath string) error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// Remove stops (if running) and unregisters the service.
|
// stopAndWait stops the service and waits up to 30s for the stopped state.
|
||||||
|
func stopAndWait(s *mgr.Service) error {
|
||||||
|
if _, err := s.Control(svc.Stop); err != nil {
|
||||||
|
return fmt.Errorf("stop service: %w", err)
|
||||||
|
}
|
||||||
|
deadline := time.Now().Add(30 * time.Second)
|
||||||
|
for {
|
||||||
|
st, err := s.Query()
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("query service: %w", err)
|
||||||
|
}
|
||||||
|
if st.State == svc.Stopped {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
if time.Now().After(deadline) {
|
||||||
|
return fmt.Errorf("service did not stop within 30s")
|
||||||
|
}
|
||||||
|
time.Sleep(300 * time.Millisecond)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// sameFileContent reports whether two files hold identical bytes. A missing
|
||||||
|
// destination is simply "different".
|
||||||
|
func sameFileContent(a, b string) (bool, error) {
|
||||||
|
ba, err := os.ReadFile(a)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
bb, err := os.ReadFile(b)
|
||||||
|
if os.IsNotExist(err) {
|
||||||
|
return false, nil
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
return bytes.Equal(ba, bb), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// copyFile copies src to dst (0755 on the new file).
|
||||||
|
func copyFile(src, dst string) error {
|
||||||
|
in, err := os.Open(src)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
defer in.Close()
|
||||||
|
out, err := os.OpenFile(dst, os.O_CREATE|os.O_TRUNC|os.O_WRONLY, 0o755)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if _, err := io.Copy(out, in); err != nil {
|
||||||
|
out.Close()
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return out.Close()
|
||||||
|
}
|
||||||
|
|
||||||
|
// grantAll gives the virtual account every ACL the service needs: modify
|
||||||
|
// on the install and ProgramData directories and the LOG_FILE directory
|
||||||
|
// (if configured elsewhere), read on a config file outside the install
|
||||||
|
// directory.
|
||||||
|
func grantAll(exe, configPath string) error {
|
||||||
|
_, dataDir := installDirs()
|
||||||
|
if err := os.MkdirAll(dataDir, 0o755); err != nil {
|
||||||
|
return fmt.Errorf("create %s: %w", dataDir, err)
|
||||||
|
}
|
||||||
|
if err := grantAccess(dataDir, "(OI)(CI)(M)"); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
exeDir := filepath.Dir(exe)
|
||||||
|
if err := grantAccess(exeDir, "(OI)(CI)(M)"); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if configPath != "" && !strings.HasPrefix(strings.ToLower(configPath), strings.ToLower(exeDir)+`\`) {
|
||||||
|
if err := grantAccess(configPath, "(R)"); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if logFile := configuredLogFile(configPath); logFile != "" {
|
||||||
|
dir := filepath.Dir(logFile)
|
||||||
|
if err := os.MkdirAll(dir, 0o755); err == nil {
|
||||||
|
if err := grantAccess(dir, "(OI)(CI)(M)"); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// Remove stops (if running) and unregisters the service. The virtual
|
||||||
|
// account ceases to exist with it; the ACL grants on the install and log
|
||||||
|
// directories are left in place (harmless without the account).
|
||||||
func Remove() error {
|
func Remove() error {
|
||||||
m, err := mgr.Connect()
|
m, err := mgr.Connect()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -118,3 +385,136 @@ func Remove() error {
|
|||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
var procShellExecuteExW = windows.NewLazySystemDLL("shell32.dll").NewProc("ShellExecuteExW")
|
||||||
|
|
||||||
|
const seeMaskNoCloseProcess = 0x40
|
||||||
|
|
||||||
|
// shellExecuteInfo mirrors SHELLEXECUTEINFOW (64-bit layout).
|
||||||
|
type shellExecuteInfo struct {
|
||||||
|
cbSize uint32
|
||||||
|
fMask uint32
|
||||||
|
hwnd uintptr
|
||||||
|
lpVerb *uint16
|
||||||
|
lpFile *uint16
|
||||||
|
lpParameters *uint16
|
||||||
|
lpDirectory *uint16
|
||||||
|
nShow int32
|
||||||
|
_ int32
|
||||||
|
hInstApp uintptr
|
||||||
|
lpIDList unsafe.Pointer
|
||||||
|
lpClass *uint16
|
||||||
|
hkeyClass uintptr
|
||||||
|
dwHotKey uint32
|
||||||
|
_ uint32
|
||||||
|
hIcon uintptr
|
||||||
|
hProcess windows.Handle
|
||||||
|
}
|
||||||
|
|
||||||
|
// Elevated reports whether the current process token is UAC-elevated.
|
||||||
|
func Elevated() bool {
|
||||||
|
var token windows.Token
|
||||||
|
if err := windows.OpenProcessToken(windows.CurrentProcess(), windows.TOKEN_QUERY, &token); err != nil {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
defer token.Close()
|
||||||
|
return token.IsElevated()
|
||||||
|
}
|
||||||
|
|
||||||
|
// RelaunchElevated re-runs the current executable elevated via the UAC
|
||||||
|
// "runas" verb with the given arguments, waits for the child, and returns
|
||||||
|
// its exit code. The child gets a fresh console window for its output.
|
||||||
|
func RelaunchElevated(args []string) (int, error) {
|
||||||
|
exe, err := os.Executable()
|
||||||
|
if err != nil {
|
||||||
|
return 0, err
|
||||||
|
}
|
||||||
|
quoted := make([]string, len(args))
|
||||||
|
for i, a := range args {
|
||||||
|
quoted[i] = syscall.EscapeArg(a)
|
||||||
|
}
|
||||||
|
cwd, _ := os.Getwd()
|
||||||
|
verb, _ := windows.UTF16PtrFromString("runas")
|
||||||
|
exeP, _ := windows.UTF16PtrFromString(exe)
|
||||||
|
params, _ := windows.UTF16PtrFromString(strings.Join(quoted, " "))
|
||||||
|
dir, _ := windows.UTF16PtrFromString(cwd)
|
||||||
|
info := shellExecuteInfo{
|
||||||
|
fMask: seeMaskNoCloseProcess,
|
||||||
|
lpVerb: verb,
|
||||||
|
lpFile: exeP,
|
||||||
|
lpParameters: params,
|
||||||
|
lpDirectory: dir,
|
||||||
|
nShow: windows.SW_NORMAL,
|
||||||
|
}
|
||||||
|
info.cbSize = uint32(unsafe.Sizeof(info))
|
||||||
|
r, _, callErr := procShellExecuteExW.Call(uintptr(unsafe.Pointer(&info)))
|
||||||
|
if r == 0 {
|
||||||
|
if errors.Is(callErr, syscall.Errno(1223)) { // ERROR_CANCELLED
|
||||||
|
return 0, ErrUserCancelled
|
||||||
|
}
|
||||||
|
return 0, fmt.Errorf("ShellExecuteEx: %w", callErr)
|
||||||
|
}
|
||||||
|
defer windows.CloseHandle(windows.Handle(info.hProcess))
|
||||||
|
windows.WaitForSingleObject(windows.Handle(info.hProcess), windows.INFINITE)
|
||||||
|
var code uint32
|
||||||
|
if err := windows.GetExitCodeProcess(windows.Handle(info.hProcess), &code); err != nil {
|
||||||
|
return 0, err
|
||||||
|
}
|
||||||
|
return int(code), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// grantAccess gives the virtual account the icacls permission set (e.g.
|
||||||
|
// "(OI)(CI)(M)") on path.
|
||||||
|
func grantAccess(path, perms string) error {
|
||||||
|
out, err := exec.Command("icacls", path, "/grant", virtualAccount+":"+perms).CombinedOutput()
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("grant %s access to %s: %w (%s)", virtualAccount, path, err, strings.TrimSpace(string(out)))
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// configuredLogFile reads LOG_FILE from the config file so the installer
|
||||||
|
// can pre-create and ACL the log directory. "" when unset or unreadable.
|
||||||
|
func configuredLogFile(configPath string) string {
|
||||||
|
f, err := os.Open(configPath)
|
||||||
|
if err != nil {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
defer f.Close()
|
||||||
|
values, err := config.ParseEnvFile(f)
|
||||||
|
if err != nil {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
return values["LOG_FILE"]
|
||||||
|
}
|
||||||
|
|
||||||
|
// RestartIfRunning restarts the service when it is installed and running
|
||||||
|
// (used after a forced update staged a new binary). Reports whether a
|
||||||
|
// restart happened. A service that is not installed or not running is not
|
||||||
|
// an error. Needs elevation.
|
||||||
|
func RestartIfRunning() (bool, error) {
|
||||||
|
m, err := mgr.Connect()
|
||||||
|
if err != nil {
|
||||||
|
return false, fmt.Errorf("connect to service manager (run as administrator): %w", err)
|
||||||
|
}
|
||||||
|
defer m.Disconnect()
|
||||||
|
s, err := m.OpenService(Name)
|
||||||
|
if err != nil {
|
||||||
|
return false, nil // not installed
|
||||||
|
}
|
||||||
|
defer s.Close()
|
||||||
|
st, err := s.Query()
|
||||||
|
if err != nil {
|
||||||
|
return false, fmt.Errorf("query service: %w", err)
|
||||||
|
}
|
||||||
|
if st.State != svc.Running && st.State != svc.StartPending {
|
||||||
|
return false, nil
|
||||||
|
}
|
||||||
|
if err := stopAndWait(s); err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
if err := s.Start(); err != nil {
|
||||||
|
return false, fmt.Errorf("start service: %w", err)
|
||||||
|
}
|
||||||
|
return true, nil
|
||||||
|
}
|
||||||
|
|||||||
@@ -26,11 +26,15 @@ import (
|
|||||||
// maxAssetSize bounds release asset downloads.
|
// maxAssetSize bounds release asset downloads.
|
||||||
const maxAssetSize = 512 << 20
|
const maxAssetSize = 512 << 20
|
||||||
|
|
||||||
// Updater checks one Gitea repository for newer releases.
|
// Updater checks one Gitea repository for releases.
|
||||||
type Updater struct {
|
type Updater struct {
|
||||||
Repo string // e.g. https://git.rambossek.at/PUBLIC/gpu-turnstile
|
Repo string // e.g. https://git.rambossek.at/PUBLIC/gpu-turnstile
|
||||||
Asset string // e.g. gpu-turnstile.exe
|
Asset string // e.g. gpu-turnstile.exe
|
||||||
Version string // current version, e.g. v0.1.2 ("dev" disables updates)
|
Version string // current binary version, e.g. v0.1.2 ("dev" cannot be compared)
|
||||||
|
// Desired is the APP_VER policy: "dev" disables updates, "stable" (or
|
||||||
|
// empty) tracks the latest release, anything else is an exact vX.Y.Z
|
||||||
|
// release tag to pin — staging it even when that means a downgrade.
|
||||||
|
Desired string
|
||||||
Log *slog.Logger
|
Log *slog.Logger
|
||||||
Client *http.Client
|
Client *http.Client
|
||||||
}
|
}
|
||||||
@@ -167,15 +171,20 @@ func CleanupOld(exePath string) {
|
|||||||
os.Remove(exePath + ".new")
|
os.Remove(exePath + ".new")
|
||||||
}
|
}
|
||||||
|
|
||||||
// Check performs a single update check. staged is true when a newer,
|
// Check performs a single update check. staged is true when a
|
||||||
// signature-verified binary has been swapped into place at exePath; the
|
// signature-verified binary has been swapped into place at exePath; the
|
||||||
// caller should then restart the process. A nil error with staged=false
|
// caller should then restart the process. A nil error with staged=false
|
||||||
// means "no action" (up to date, disabled, or dev build); a non-nil error
|
// means "no action" (up to date, APP_VER=dev, or no embedded public key);
|
||||||
// means the check failed and the running binary is untouched.
|
// a non-nil error means the check failed and the running binary is
|
||||||
|
// untouched.
|
||||||
func (u *Updater) Check(ctx context.Context, exePath string) (staged bool, err error) {
|
func (u *Updater) Check(ctx context.Context, exePath string) (staged bool, err error) {
|
||||||
log := u.logger()
|
log := u.logger()
|
||||||
if u.Version == "" || u.Version == "dev" {
|
desired := u.Desired
|
||||||
log.Debug("auto-update: dev build, skipping")
|
if desired == "" {
|
||||||
|
desired = "stable"
|
||||||
|
}
|
||||||
|
if desired == "dev" {
|
||||||
|
log.Debug("auto-update: APP_VER=dev, skipping")
|
||||||
return false, nil
|
return false, nil
|
||||||
}
|
}
|
||||||
if publicKeyPEM == "" {
|
if publicKeyPEM == "" {
|
||||||
@@ -187,14 +196,29 @@ func (u *Updater) Check(ctx context.Context, exePath string) (staged bool, err e
|
|||||||
return false, err
|
return false, err
|
||||||
}
|
}
|
||||||
|
|
||||||
body, err := u.get(ctx, api+"/releases/latest")
|
pinned := desired != "stable"
|
||||||
|
endpoint := api + "/releases/latest"
|
||||||
|
if pinned {
|
||||||
|
endpoint = api + "/releases/tags/" + desired
|
||||||
|
}
|
||||||
|
body, err := u.get(ctx, endpoint)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return false, fmt.Errorf("fetch latest release: %w", err)
|
return false, fmt.Errorf("fetch release: %w", err)
|
||||||
}
|
}
|
||||||
var rel release
|
var rel release
|
||||||
if err := json.Unmarshal(body, &rel); err != nil {
|
if err := json.Unmarshal(body, &rel); err != nil {
|
||||||
return false, fmt.Errorf("parse release: %w", err)
|
return false, fmt.Errorf("parse release: %w", err)
|
||||||
}
|
}
|
||||||
|
if pinned {
|
||||||
|
// Pin mode: any difference from the target tag means stage it —
|
||||||
|
// including downgrades and replacing a dev binary.
|
||||||
|
if u.Version == rel.TagName {
|
||||||
|
log.Debug("auto-update: already on pinned version", "version", u.Version)
|
||||||
|
return false, nil
|
||||||
|
}
|
||||||
|
} else if u.Version != "" && u.Version != "dev" {
|
||||||
|
// Stable mode: only strictly newer releases count; a dev binary
|
||||||
|
// cannot be compared and is always replaced by the latest release.
|
||||||
newer, err := newerVersion(u.Version, rel.TagName)
|
newer, err := newerVersion(u.Version, rel.TagName)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return false, err
|
return false, err
|
||||||
@@ -203,6 +227,7 @@ func (u *Updater) Check(ctx context.Context, exePath string) (staged bool, err e
|
|||||||
log.Debug("auto-update: up to date", "version", u.Version, "latest", rel.TagName)
|
log.Debug("auto-update: up to date", "version", u.Version, "latest", rel.TagName)
|
||||||
return false, nil
|
return false, nil
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
urls := make(map[string]string, len(rel.Assets))
|
urls := make(map[string]string, len(rel.Assets))
|
||||||
for _, a := range rel.Assets {
|
for _, a := range rel.Assets {
|
||||||
|
|||||||
@@ -43,7 +43,7 @@ func newFakeGitea(t *testing.T, tag string, assetContent []byte) *fakeGitea {
|
|||||||
sign := func() []byte { return ed25519.Sign(priv, f.asset) }
|
sign := func() []byte { return ed25519.Sign(priv, f.asset) }
|
||||||
|
|
||||||
mux := http.NewServeMux()
|
mux := http.NewServeMux()
|
||||||
mux.HandleFunc("/api/v1/repos/o/r/releases/latest", func(w http.ResponseWriter, r *http.Request) {
|
serveRelease := func(w http.ResponseWriter, r *http.Request) {
|
||||||
assets := []map[string]string{
|
assets := []map[string]string{
|
||||||
{"name": "gpu-turnstile.exe", "browser_download_url": f.srv.URL + "/dl/exe"},
|
{"name": "gpu-turnstile.exe", "browser_download_url": f.srv.URL + "/dl/exe"},
|
||||||
{"name": "gpu-turnstile.exe.sha256", "browser_download_url": f.srv.URL + "/dl/sha"},
|
{"name": "gpu-turnstile.exe.sha256", "browser_download_url": f.srv.URL + "/dl/sha"},
|
||||||
@@ -52,7 +52,9 @@ func newFakeGitea(t *testing.T, tag string, assetContent []byte) *fakeGitea {
|
|||||||
assets = append(assets, map[string]string{"name": "gpu-turnstile.exe.sig", "browser_download_url": f.srv.URL + "/dl/sig"})
|
assets = append(assets, map[string]string{"name": "gpu-turnstile.exe.sig", "browser_download_url": f.srv.URL + "/dl/sig"})
|
||||||
}
|
}
|
||||||
json.NewEncoder(w).Encode(map[string]any{"tag_name": f.tag, "assets": assets})
|
json.NewEncoder(w).Encode(map[string]any{"tag_name": f.tag, "assets": assets})
|
||||||
})
|
}
|
||||||
|
mux.HandleFunc("/api/v1/repos/o/r/releases/latest", serveRelease)
|
||||||
|
mux.HandleFunc("/api/v1/repos/o/r/releases/tags/"+f.tag, serveRelease)
|
||||||
mux.HandleFunc("/dl/exe", func(w http.ResponseWriter, r *http.Request) { w.Write(f.asset) })
|
mux.HandleFunc("/dl/exe", func(w http.ResponseWriter, r *http.Request) { w.Write(f.asset) })
|
||||||
mux.HandleFunc("/dl/sig", func(w http.ResponseWriter, r *http.Request) {
|
mux.HandleFunc("/dl/sig", func(w http.ResponseWriter, r *http.Request) {
|
||||||
sig := sign()
|
sig := sign()
|
||||||
@@ -73,6 +75,12 @@ func (f *fakeGitea) updater(version string) *Updater {
|
|||||||
return &Updater{Repo: f.srv.URL + "/o/r", Asset: "gpu-turnstile.exe", Version: version}
|
return &Updater{Repo: f.srv.URL + "/o/r", Asset: "gpu-turnstile.exe", Version: version}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (f *fakeGitea) updaterDesired(version, desired string) *Updater {
|
||||||
|
u := f.updater(version)
|
||||||
|
u.Desired = desired
|
||||||
|
return u
|
||||||
|
}
|
||||||
|
|
||||||
func fakeExe(t *testing.T) string {
|
func fakeExe(t *testing.T) string {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
exe := filepath.Join(t.TempDir(), "gpu-turnstile.exe")
|
exe := filepath.Join(t.TempDir(), "gpu-turnstile.exe")
|
||||||
@@ -153,12 +161,61 @@ func TestCheckSkipsWithoutPublicKey(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestCheckSkipsDevBuild(t *testing.T) {
|
func TestCheckDevBuildGetsStable(t *testing.T) {
|
||||||
|
// A dev binary cannot be compared; APP_VER=stable replaces it with the
|
||||||
|
// latest release.
|
||||||
f := newFakeGitea(t, "v9.9.9", []byte("new-binary"))
|
f := newFakeGitea(t, "v9.9.9", []byte("new-binary"))
|
||||||
withPublicKey(t, f.pubPEM)
|
withPublicKey(t, f.pubPEM)
|
||||||
staged, err := f.updater("dev").Check(context.Background(), fakeExe(t))
|
exe := fakeExe(t)
|
||||||
|
staged, err := f.updater("dev").Check(context.Background(), exe)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if !staged {
|
||||||
|
t.Fatal("expected dev binary to be replaced by the latest release")
|
||||||
|
}
|
||||||
|
content, _ := os.ReadFile(exe)
|
||||||
|
if string(content) != "new-binary" {
|
||||||
|
t.Fatalf("exe content = %q", content)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestCheckDesiredDevDisables(t *testing.T) {
|
||||||
|
f := newFakeGitea(t, "v9.9.9", []byte("new-binary"))
|
||||||
|
withPublicKey(t, f.pubPEM)
|
||||||
|
for _, version := range []string{"dev", "v0.1.2"} {
|
||||||
|
staged, err := f.updaterDesired(version, "dev").Check(context.Background(), fakeExe(t))
|
||||||
if err != nil || staged {
|
if err != nil || staged {
|
||||||
t.Fatalf("staged=%v err=%v, want no action for dev build", staged, err)
|
t.Fatalf("version %s: staged=%v err=%v, want no action with APP_VER=dev", version, staged, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestCheckPinned(t *testing.T) {
|
||||||
|
// Pin mode stages the exact tag — up or down — and skips when the
|
||||||
|
// binary already matches.
|
||||||
|
for _, version := range []string{"v0.1.2", "v9.9.9", "dev"} {
|
||||||
|
f := newFakeGitea(t, "v0.5.0", []byte("pinned-binary"))
|
||||||
|
withPublicKey(t, f.pubPEM)
|
||||||
|
exe := fakeExe(t)
|
||||||
|
staged, err := f.updaterDesired(version, "v0.5.0").Check(context.Background(), exe)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("version %s: %v", version, err)
|
||||||
|
}
|
||||||
|
if !staged {
|
||||||
|
t.Fatalf("version %s: expected pinned v0.5.0 to be staged", version)
|
||||||
|
}
|
||||||
|
content, _ := os.ReadFile(exe)
|
||||||
|
if string(content) != "pinned-binary" {
|
||||||
|
t.Fatalf("version %s: exe content = %q", version, content)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
f := newFakeGitea(t, "v0.5.0", []byte("pinned-binary"))
|
||||||
|
withPublicKey(t, f.pubPEM)
|
||||||
|
staged, err := f.updaterDesired("v0.5.0", "v0.5.0").Check(context.Background(), fakeExe(t))
|
||||||
|
if err != nil || staged {
|
||||||
|
t.Fatalf("staged=%v err=%v, want no action when already on the pinned version", staged, err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user