Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5b752d5637 | ||
|
|
b55d548c5f | ||
|
|
2d5be72436 | ||
|
|
21e40a1774 | ||
|
|
bdc844872d | ||
|
|
299b6dc0bb | ||
|
|
9589e58ce6 | ||
|
|
be0bb36317 | ||
|
|
9b267533c9 | ||
|
|
6f092ddc12 |
@@ -58,14 +58,14 @@ override file values. Invalid values fail at startup.
|
|||||||
| `LLM_BUSY_STATUS` | `503` | HTTP status for rejected LLM requests in reject mode (400–599, e.g. 429) |
|
| `LLM_BUSY_STATUS` | `503` | HTTP status for rejected LLM requests in reject mode (400–599, e.g. 429) |
|
||||||
| `BUSY_RETRY_AFTER` | `30` | Seconds sent as `Retry-After` on busy responses (both modes) |
|
| `BUSY_RETRY_AFTER` | `30` | Seconds sent as `Retry-After` on busy responses (both modes) |
|
||||||
| `WARM_MODEL` | _(empty)_ | Model to reload after an image job (off by default) |
|
| `WARM_MODEL` | _(empty)_ | Model to reload after an image job (off by default) |
|
||||||
| `COMFY_CMD` | _(empty = unmanaged)_ | Supervise ComfyUI: start on demand, stop when idle to free VRAM. Requires `COMFY_URL` |
|
| `COMFY_CMD` | _(derived from `COMFY_DIR`; both empty = unmanaged)_ | Supervise ComfyUI: start on demand, stop when idle to free VRAM. Requires `COMFY_URL` |
|
||||||
| `COMFY_DIR` | _(empty)_ | Working directory for `COMFY_CMD` |
|
| `COMFY_DIR` | _(empty)_ | Standard venv install root: set alone to supervise ComfyUI with the derived command (`.venv` + `main.py`); also the working directory for `COMFY_CMD` |
|
||||||
| `COMFY_IDLE_TIMEOUT` | `5m` | Stop the managed ComfyUI after this long idle |
|
| `COMFY_IDLE_TIMEOUT` | `5m` | Stop the managed ComfyUI after this long idle |
|
||||||
| `COMFY_START_TIMEOUT` | `2m` | Max wait for the managed ComfyUI to come up |
|
| `COMFY_START_TIMEOUT` | `2m` | Max wait for the managed ComfyUI to come up |
|
||||||
| `GAME_PROCS` | _(empty = disabled)_ | Process names (comma-separated); while any runs, the GPU counts as held: requests wait, Ollama unloads, managed ComfyUI stops |
|
| `GAME_PROCS` | _(empty = disabled)_ | Process names (comma-separated); while any runs, the GPU counts as held: requests wait, Ollama unloads, managed ComfyUI stops |
|
||||||
| `GPU_FOREIGN_VRAM_MB` | `0` (disabled) | Also treat the GPU as held when a non-ignored process uses more VRAM than this (needs nvidia-smi) |
|
| `GPU_FOREIGN_VRAM_MB` | `0` (disabled) | Also treat the GPU as held when a non-ignored process uses more VRAM than this (needs nvidia-smi) |
|
||||||
| `GPU_IGNORE_PROCS` | `ollama,ollama app,ollama_llama_server,python,pythonw` | Process names never counted as foreign GPU users |
|
| `GPU_IGNORE_PROCS` | `ollama,ollama app,ollama_llama_server,python,pythonw` | Process names never counted as foreign GPU users |
|
||||||
| `GAME_POLL_INTERVAL` | `5s` | How often game/VRAM detection runs |
|
| `GAME_POLL_INTERVAL` | `15s` | How often game/VRAM detection runs (don't go below ~10s — nvidia-smi polls keep the GPU awake) |
|
||||||
| `LOGLEVEL` | `warn` | `info` logs every request (colored arrows in text mode), `debug` adds lock transitions. `LOG_LEVEL` works as an alias |
|
| `LOGLEVEL` | `warn` | `info` logs every request (colored arrows in text mode), `debug` adds lock transitions. `LOG_LEVEL` works as an alias |
|
||||||
| `LOG_FORMAT` | `text` | `json` for structured JSON logs |
|
| `LOG_FORMAT` | `text` | `json` for structured JSON logs |
|
||||||
| `LOG_FILE` | _(empty)_ | Append logs to this file instead of stderr |
|
| `LOG_FILE` | _(empty)_ | Append logs to this file instead of stderr |
|
||||||
@@ -99,18 +99,28 @@ override file values. Invalid values fail at startup.
|
|||||||
class) in text mode, which renders in `docker compose logs` on Windows
|
class) in text mode, which renders in `docker compose logs` on Windows
|
||||||
Terminal. Set `NO_COLOR` to disable colors.
|
Terminal. Set `NO_COLOR` to disable colors.
|
||||||
|
|
||||||
## Managed ComfyUI (`COMFY_CMD`)
|
## Managed ComfyUI (`COMFY_CMD` / `COMFY_DIR`)
|
||||||
|
|
||||||
Don't want ComfyUI running 24/7 (it holds VRAM even when idle — and the
|
Don't want ComfyUI running 24/7 (it holds VRAM even when idle — and the
|
||||||
Desktop app kills its server when you close it)? Point `COMFY_CMD` at a
|
Desktop app kills its server when you close it)? gpu-turnstile can supervise
|
||||||
standalone launch command and gpu-turnstile supervises it: the first
|
it: the first request starts it, it stops again after `COMFY_IDLE_TIMEOUT`
|
||||||
request starts it, it stops again after `COMFY_IDLE_TIMEOUT` (default 5m)
|
(default 5m) without work, freeing the GPU for games or the LLM.
|
||||||
without work, freeing the GPU for games or the LLM. Example for a Desktop
|
|
||||||
install (run it once manually to confirm it works):
|
The easy way — point `COMFY_DIR` at a standard venv install (a folder with
|
||||||
|
`.venv` and `main.py`, or `.venv` and `ComfyUI\main.py`) and the launch
|
||||||
|
command is derived from it, including `--port` from `COMFY_URL`:
|
||||||
|
|
||||||
```
|
```
|
||||||
COMFY_URL=http://127.0.0.1:8188
|
COMFY_URL=http://127.0.0.1:8189
|
||||||
COMFY_CMD="C:\ComfyUI\.venv\Scripts\python.exe ComfyUI\main.py --port 8188"
|
COMFY_DIR=C:\ComfyUI
|
||||||
|
```
|
||||||
|
|
||||||
|
For other layouts, spell the command out yourself (run it once manually to
|
||||||
|
confirm it works):
|
||||||
|
|
||||||
|
```
|
||||||
|
COMFY_URL=http://127.0.0.1:8189
|
||||||
|
COMFY_CMD="C:\ComfyUI\.venv\Scripts\python.exe" main.py --port 8189
|
||||||
COMFY_DIR=C:\ComfyUI
|
COMFY_DIR=C:\ComfyUI
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -124,13 +134,22 @@ answers on the port, gpu-turnstile just uses it instead of spawning
|
|||||||
instance already holds the port when you open the desktop app, the
|
instance already holds the port when you open the desktop app, the
|
||||||
desktop's server is the one that fails to bind.
|
desktop's server is the one that fails to bind.
|
||||||
|
|
||||||
|
One catch when gpu-turnstile runs as a service: the sandboxed service
|
||||||
|
account may not enter your user profile, so a ComfyUI install under
|
||||||
|
`C:\Users\...` (or `/home/...`) fails with "Access is denied".
|
||||||
|
`--install-service` fixes that automatically — it grants
|
||||||
|
`NT SERVICE\gpu-turnstile` recursive access to `COMFY_DIR` on Windows and
|
||||||
|
adds a `BindPaths=` to the systemd unit on Linux. Re-run it after changing
|
||||||
|
`COMFY_DIR`; or grant by hand from an admin shell:
|
||||||
|
`icacls "<COMFY_DIR>" /grant "NT SERVICE\gpu-turnstile:(OI)(CI)M" /T`.
|
||||||
|
|
||||||
## Game detection
|
## Game detection
|
||||||
|
|
||||||
Want to game on the same GPU without Ollama/ComfyUI squatting on the VRAM?
|
Want to game on the same GPU without Ollama/ComfyUI squatting on the VRAM?
|
||||||
gpu-turnstile can watch for foreign GPU holders and, while one is active,
|
gpu-turnstile can watch for foreign GPU holders and, while one is active,
|
||||||
make LLM/image requests wait (or 503, per `LLM_BUSY_MODE`), unload Ollama's
|
make LLM/image requests wait (or 503, per `LLM_BUSY_MODE`), unload Ollama's
|
||||||
models and stop the managed ComfyUI so the game gets the memory. Two
|
models and stop the managed ComfyUI so the game gets the memory. Two
|
||||||
detection paths, each optional, polled every `GAME_POLL_INTERVAL` (5s):
|
detection paths, each optional, polled every `GAME_POLL_INTERVAL` (15s):
|
||||||
|
|
||||||
```
|
```
|
||||||
GAME_PROCS=cyberpunk2077.exe,bg3.exe # the reliable way on Windows
|
GAME_PROCS=cyberpunk2077.exe,bg3.exe # the reliable way on Windows
|
||||||
|
|||||||
@@ -128,10 +128,15 @@ state is `idle`, send `POST /api/generate {"model":WARM_MODEL,"keep_alive":-1}`
|
|||||||
with empty prompt to reload the chat model so the next chat doesn't pay the
|
with empty prompt to reload the chat model so the next chat doesn't pay the
|
||||||
load time. Off by default.
|
load time. Off by default.
|
||||||
|
|
||||||
### Managed ComfyUI (`COMFY_CMD`)
|
### Managed ComfyUI (`COMFY_CMD` / `COMFY_DIR`)
|
||||||
|
|
||||||
When `COMFY_CMD` is set, gpu-turnstile runs ComfyUI as a supervised child
|
When `COMFY_CMD` is set, gpu-turnstile runs ComfyUI as a supervised child
|
||||||
process instead of expecting an always-on server:
|
process instead of expecting an always-on server. Setting only `COMFY_DIR`
|
||||||
|
enables the same management with the launch command derived from the
|
||||||
|
standard venv layout under it (`.venv\Scripts\python.exe` on Windows,
|
||||||
|
`.venv/bin/python` on Linux; `ComfyUI\main.py`, or a flat `main.py` when
|
||||||
|
that is what exists; `--port` from the `COMFY_URL` port). Missing layout
|
||||||
|
files are flagged in the startup log.
|
||||||
|
|
||||||
- **Start on demand**: any ComfyUI request spawns it (double quotes in the
|
- **Start on demand**: any ComfyUI request spawns it (double quotes in the
|
||||||
command line group arguments with spaces; `COMFY_DIR` sets the working
|
command line group arguments with spaces; `COMFY_DIR` sets the working
|
||||||
@@ -154,12 +159,20 @@ process instead of expecting an always-on server:
|
|||||||
- Its stdout/stderr is forwarded to the log at INFO. The health check
|
- Its stdout/stderr is forwarded to the log at INFO. The health check
|
||||||
skips the intentionally-stopped/starting states; a failed probe while
|
skips the intentionally-stopped/starting states; a failed probe while
|
||||||
the process is alive and was previously ready is logged as DOWN.
|
the process is alive and was previously ready is logged as DOWN.
|
||||||
|
- **Permissions**: the service account is sandboxed (Windows virtual
|
||||||
|
account, systemd `DynamicUser`), so a ComfyUI install inside a user
|
||||||
|
profile is off-limits by default. `--install-service` opens it up —
|
||||||
|
a recursive ACL grant for `NT SERVICE\gpu-turnstile` on Windows, a
|
||||||
|
`BindPaths=` in the unit on Linux — reading `COMFY_DIR` from the config
|
||||||
|
it installs. Re-run `--install-service` after changing `COMFY_DIR`, or
|
||||||
|
grant by hand (admin shell):
|
||||||
|
`icacls "<COMFY_DIR>" /grant "NT SERVICE\gpu-turnstile:(OI)(CI)M" /T`.
|
||||||
|
|
||||||
## Game detection (foreign GPU holders)
|
## Game detection (foreign GPU holders)
|
||||||
|
|
||||||
Games and other foreign GPU users sit outside the URL-based consumer model —
|
Games and other foreign GPU users sit outside the URL-based consumer model —
|
||||||
nothing proxies through gpu-turnstile for them. Two independent detection
|
nothing proxies through gpu-turnstile for them. Two independent detection
|
||||||
paths, polled every `GAME_POLL_INTERVAL` (default 5 s); either one being
|
paths, polled every `GAME_POLL_INTERVAL` (default 15 s); either one being
|
||||||
configured enables the feature:
|
configured enables the feature:
|
||||||
|
|
||||||
- **Process watch list** (`GAME_PROCS`, comma-separated, case-insensitive,
|
- **Process watch list** (`GAME_PROCS`, comma-separated, case-insensitive,
|
||||||
@@ -211,14 +224,14 @@ override file values. A missing file is fine; a malformed one is fatal.
|
|||||||
| `LLM_BUSY_STATUS` | `503` | HTTP status for rejected LLM requests in reject mode (400–599, e.g. 429) |
|
| `LLM_BUSY_STATUS` | `503` | HTTP status for rejected LLM requests in reject mode (400–599, e.g. 429) |
|
||||||
| `BUSY_RETRY_AFTER` | `30` | seconds sent as `Retry-After` on busy responses (both modes) |
|
| `BUSY_RETRY_AFTER` | `30` | seconds sent as `Retry-After` on busy responses (both modes) |
|
||||||
| `WARM_MODEL` | `` | optional model to reload after an image job |
|
| `WARM_MODEL` | `` | optional model to reload after an image job |
|
||||||
| `COMFY_CMD` | _(empty = unmanaged)_ | spawn and supervise ComfyUI on demand: first request starts it, idle stop after `COMFY_IDLE_TIMEOUT` frees its VRAM. Requires `COMFY_URL` |
|
| `COMFY_CMD` | _(derived from `COMFY_DIR`; both empty = unmanaged)_ | spawn and supervise ComfyUI on demand: first request starts it, idle stop after `COMFY_IDLE_TIMEOUT` frees its VRAM. Requires `COMFY_URL` |
|
||||||
| `COMFY_DIR` | `` | working directory for `COMFY_CMD` |
|
| `COMFY_DIR` | `` | standard venv install root: set alone to supervise ComfyUI with the derived launch command (`.venv` + `main.py`, `--port` from `COMFY_URL`); also the working directory for `COMFY_CMD` |
|
||||||
| `COMFY_IDLE_TIMEOUT` | `5m` | stop the managed ComfyUI after this long without requests or jobs |
|
| `COMFY_IDLE_TIMEOUT` | `5m` | stop the managed ComfyUI after this long without requests or jobs |
|
||||||
| `COMFY_START_TIMEOUT` | `2m` | how long a request waits for the managed ComfyUI to come up |
|
| `COMFY_START_TIMEOUT` | `2m` | how long a request waits for the managed ComfyUI to come up |
|
||||||
| `GAME_PROCS` | _(empty = disabled)_ | comma-separated process names (case-insensitive, `.exe` optional); while any runs, the GPU counts as held by it: requests wait, Ollama unloads, the managed ComfyUI stops |
|
| `GAME_PROCS` | _(empty = disabled)_ | comma-separated process names (case-insensitive, `.exe` optional); while any runs, the GPU counts as held by it: requests wait, Ollama unloads, the managed ComfyUI stops |
|
||||||
| `GPU_FOREIGN_VRAM_MB` | `0` (disabled) | also treat the GPU as held when a process not in `GPU_IGNORE_PROCS` uses more VRAM than this; needs nvidia-smi |
|
| `GPU_FOREIGN_VRAM_MB` | `0` (disabled) | also treat the GPU as held when a process not in `GPU_IGNORE_PROCS` uses more VRAM than this; needs nvidia-smi |
|
||||||
| `GPU_IGNORE_PROCS` | `ollama,ollama app,ollama_llama_server,python,pythonw` | process names never counted as foreign GPU users |
|
| `GPU_IGNORE_PROCS` | `ollama,ollama app,ollama_llama_server,python,pythonw` | process names never counted as foreign GPU users |
|
||||||
| `GAME_POLL_INTERVAL` | `5s` | how often game/VRAM detection runs |
|
| `GAME_POLL_INTERVAL` | `15s` | how often game/VRAM detection runs (nvidia-smi polls keep the GPU awake; don't go below ~10s) |
|
||||||
| `LOGLEVEL` | `warn` | `info` logs every request (colored arrows in text mode), `debug` adds lock transitions. `LOG_LEVEL` is accepted as an alias |
|
| `LOGLEVEL` | `warn` | `info` logs every request (colored arrows in text mode), `debug` adds lock transitions. `LOG_LEVEL` is accepted as an alias |
|
||||||
| `LOG_FORMAT` | `text` | `json` for structured JSON logs |
|
| `LOG_FORMAT` | `text` | `json` for structured JSON logs |
|
||||||
| `LOG_FILE` | `` | append logs to this file instead of stderr (useful as a service) |
|
| `LOG_FILE` | `` | append logs to this file instead of stderr (useful as a service) |
|
||||||
|
|||||||
+80
-17
@@ -15,6 +15,7 @@ import (
|
|||||||
"os"
|
"os"
|
||||||
"os/signal"
|
"os/signal"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
|
"runtime"
|
||||||
"strings"
|
"strings"
|
||||||
"syscall"
|
"syscall"
|
||||||
"time"
|
"time"
|
||||||
@@ -38,6 +39,11 @@ var version = "dev"
|
|||||||
// process: a signed update has been staged and the GPU lock is idle.
|
// process: a signed update has been staged and the GPU lock is idle.
|
||||||
const exitCodeUpdate = 3
|
const exitCodeUpdate = 3
|
||||||
|
|
||||||
|
// exitCodeStaged is returned by an elevated --force-update child when it
|
||||||
|
// staged a new binary, so the non-elevated parent can tell "updated" from
|
||||||
|
// "up to date" (it cannot see the child's console).
|
||||||
|
const exitCodeStaged = 4
|
||||||
|
|
||||||
// stdoutIsTerminal reports whether stdout is a console (char device), as
|
// stdoutIsTerminal reports whether stdout is a console (char device), as
|
||||||
// opposed to a pipe or file — which is what Docker containers and services
|
// opposed to a pipe or file — which is what Docker containers and services
|
||||||
// see.
|
// see.
|
||||||
@@ -347,11 +353,12 @@ func forceUpdateCommand(configPath string, elevatedChild bool) int {
|
|||||||
// instead of hanging in a TCP connect for minutes.
|
// instead of hanging in a TCP connect for minutes.
|
||||||
ctx, cancel := context.WithTimeout(context.Background(), 30*time.Second)
|
ctx, cancel := context.WithTimeout(context.Background(), 30*time.Second)
|
||||||
defer cancel()
|
defer cancel()
|
||||||
staged, err := u.Check(ctx, exePath)
|
staged, to, err := u.Check(ctx, exePath)
|
||||||
if err != nil && isPermission(err) && !service.Elevated() {
|
if err != nil && isPermission(err) && !service.Elevated() {
|
||||||
code, _ := elevateAndMirror("--force-update")
|
code, _ := elevateAndMirror("--force-update")
|
||||||
if code == 0 {
|
reportElevatedUpdate(code, to)
|
||||||
fmt.Println("update applied (elevated)")
|
if code == 0 || code == exitCodeStaged {
|
||||||
|
return 0
|
||||||
}
|
}
|
||||||
return code
|
return code
|
||||||
}
|
}
|
||||||
@@ -363,12 +370,13 @@ func forceUpdateCommand(configPath string, elevatedChild bool) int {
|
|||||||
fmt.Printf("%s is up to date\n", versionLine())
|
fmt.Printf("%s is up to date\n", versionLine())
|
||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
fmt.Printf("%s: update staged\n", versionLine())
|
fmt.Printf("gpu-turnstile: updated from %s to %s\n", version, to)
|
||||||
restarted, err := service.RestartIfRunning()
|
restarted, err := service.RestartIfRunning()
|
||||||
if err != nil && isPermission(err) && !service.Elevated() {
|
if err != nil && isPermission(err) && !service.Elevated() {
|
||||||
code, _ := elevateAndMirror("--force-update")
|
code, _ := elevateAndMirror("--force-update")
|
||||||
if code == 0 {
|
reportElevatedUpdate(code, to)
|
||||||
fmt.Println("update applied (elevated)")
|
if code == 0 || code == exitCodeStaged {
|
||||||
|
return 0
|
||||||
}
|
}
|
||||||
return code
|
return code
|
||||||
}
|
}
|
||||||
@@ -377,13 +385,35 @@ func forceUpdateCommand(configPath string, elevatedChild bool) int {
|
|||||||
return 1
|
return 1
|
||||||
}
|
}
|
||||||
if restarted {
|
if restarted {
|
||||||
fmt.Println("service restarted on the new version")
|
fmt.Println("service restarted on " + to)
|
||||||
} else {
|
} else {
|
||||||
fmt.Println("no running service; the new version applies on next start")
|
fmt.Println("no running service; " + to + " applies on the next start")
|
||||||
|
}
|
||||||
|
if elevatedChild {
|
||||||
|
// Tell the non-elevated parent (which cannot see this console)
|
||||||
|
// whether anything was staged, so its mirror message is honest.
|
||||||
|
return exitCodeStaged
|
||||||
}
|
}
|
||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// reportElevatedUpdate prints the parent's summary of an elevated
|
||||||
|
// --force-update child: exitCodeStaged means the child staged a new binary,
|
||||||
|
// 0 means it found nothing to do. to is the tag the parent's own check
|
||||||
|
// resolved before it hit the permission wall ("" when it never got that
|
||||||
|
// far).
|
||||||
|
func reportElevatedUpdate(code int, to string) {
|
||||||
|
switch {
|
||||||
|
case code == exitCodeStaged && to != "":
|
||||||
|
fmt.Printf("gpu-turnstile: updated from %s to %s (elevated)\n", version, to)
|
||||||
|
case code == exitCodeStaged:
|
||||||
|
fmt.Println("update applied (elevated)")
|
||||||
|
case code == 0:
|
||||||
|
fmt.Printf("%s is up to date\n", versionLine())
|
||||||
|
}
|
||||||
|
// Non-zero, non-staged codes: elevateAndMirror already printed the failure.
|
||||||
|
}
|
||||||
|
|
||||||
// serviceCommand installs (copyBin = register the canonical-layout copy)
|
// serviceCommand installs (copyBin = register the canonical-layout copy)
|
||||||
// or removes the service and reports the result. On Windows, when the
|
// or removes the service and reports the result. On Windows, when the
|
||||||
// shell is not elevated, the command relaunches itself through a UAC
|
// shell is not elevated, the command relaunches itself through a UAC
|
||||||
@@ -434,7 +464,26 @@ func orDisabled(url string) string {
|
|||||||
return url
|
return url
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// managedComfyCommand resolves how ComfyUI is launched when it is managed:
|
||||||
|
// COMFY_CMD verbatim, or the standard venv layout under COMFY_DIR. Empty
|
||||||
|
// when neither is set (unmanaged).
|
||||||
|
func managedComfyCommand(cfg config.Config) string {
|
||||||
|
if cfg.ComfyCmd != "" {
|
||||||
|
return cfg.ComfyCmd
|
||||||
|
}
|
||||||
|
if cfg.ComfyDir != "" {
|
||||||
|
return supervise.DefaultComfyCommand(runtime.GOOS, cfg.ComfyDir, cfg.ComfyURL)
|
||||||
|
}
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
|
||||||
func run(ctx context.Context, cfg config.Config, log *slog.Logger, logOut io.Writer, isService bool) error {
|
func run(ctx context.Context, cfg config.Config, log *slog.Logger, logOut io.Writer, isService bool) error {
|
||||||
|
// ComfyUI can run as a managed child — COMFY_CMD verbatim, or the
|
||||||
|
// standard venv layout derived from COMFY_DIR alone: started on demand
|
||||||
|
// by the proxy, stopped after COMFY_IDLE_TIMEOUT idle (and on shutdown)
|
||||||
|
// so its VRAM is freed.
|
||||||
|
comfyCmdLine := managedComfyCommand(cfg)
|
||||||
|
|
||||||
// The startup line carries the version and every setting and is emitted
|
// The startup line carries the version and every setting and is emitted
|
||||||
// at WARN so it is visible even with the default (quiet) log level.
|
// at WARN so it is visible even with the default (quiet) log level.
|
||||||
log.Log(ctx, slog.LevelWarn, "starting gpu-turnstile",
|
log.Log(ctx, slog.LevelWarn, "starting gpu-turnstile",
|
||||||
@@ -460,7 +509,7 @@ func run(ctx context.Context, cfg config.Config, log *slog.Logger, logOut io.Wri
|
|||||||
"backoff_max", cfg.BackoffMax,
|
"backoff_max", cfg.BackoffMax,
|
||||||
"prompt_capture_limit", cfg.PromptCaptureLimit,
|
"prompt_capture_limit", cfg.PromptCaptureLimit,
|
||||||
"warm_model", cfg.WarmModel,
|
"warm_model", cfg.WarmModel,
|
||||||
"comfy_cmd", cfg.ComfyCmd,
|
"comfy_cmd", orDisabled(comfyCmdLine),
|
||||||
"comfy_dir", cfg.ComfyDir,
|
"comfy_dir", cfg.ComfyDir,
|
||||||
"comfy_idle_timeout", cfg.ComfyIdleTimeout,
|
"comfy_idle_timeout", cfg.ComfyIdleTimeout,
|
||||||
"comfy_start_timeout", cfg.ComfyStartTimeout,
|
"comfy_start_timeout", cfg.ComfyStartTimeout,
|
||||||
@@ -494,13 +543,27 @@ func run(ctx context.Context, cfg config.Config, log *slog.Logger, logOut io.Wri
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// With COMFY_CMD set, ComfyUI runs as a managed child: started on
|
|
||||||
// demand by the proxy, stopped after COMFY_IDLE_TIMEOUT idle (and on
|
|
||||||
// shutdown) so its VRAM is freed.
|
|
||||||
var comfySup *supervise.Process
|
var comfySup *supervise.Process
|
||||||
if cfg.ComfyCmd != "" {
|
if comfyCmdLine != "" {
|
||||||
|
if cfg.ComfyCmd == "" {
|
||||||
|
// Derived from COMFY_DIR: flag a wrong-looking layout early,
|
||||||
|
// while the operator is still watching the startup log. Inside
|
||||||
|
// a profile the service account may not enter, os.Stat fails
|
||||||
|
// with EACCES — that reads as "not found" but means "grant
|
||||||
|
// access", so say so.
|
||||||
|
python, script := supervise.ComfyLayout(runtime.GOOS, cfg.ComfyDir)
|
||||||
|
for _, p := range []string{python, script} {
|
||||||
|
if _, err := os.Stat(p); err != nil {
|
||||||
|
if isPermission(err) {
|
||||||
|
log.Warn("COMFY_DIR: not accessible to the service account; grant access or re-run --install-service", "path", p)
|
||||||
|
} else {
|
||||||
|
log.Warn("COMFY_DIR: file not found; ComfyUI requests will fail until it exists", "path", p)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
var err error
|
var err error
|
||||||
comfySup, err = supervise.New("comfy", cfg.ComfyCmd, cfg.ComfyDir, comfyClient.Probe, cfg.ComfyStartTimeout, log)
|
comfySup, err = supervise.New("comfy", comfyCmdLine, cfg.ComfyDir, comfyClient.Probe, cfg.ComfyStartTimeout, log)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -779,16 +842,16 @@ func updateLoop(ctx context.Context, cfg config.Config, log *slog.Logger, lk *lo
|
|||||||
}
|
}
|
||||||
u := &update.Updater{Repo: cfg.UpdateRepo, Asset: cfg.UpdateAsset, Version: version, Desired: cfg.AppVersion, Log: log}
|
u := &update.Updater{Repo: cfg.UpdateRepo, Asset: cfg.UpdateAsset, Version: version, Desired: cfg.AppVersion, Log: log}
|
||||||
for {
|
for {
|
||||||
staged, err := u.Check(ctx, exePath)
|
staged, to, err := u.Check(ctx, exePath)
|
||||||
if err != nil && ctx.Err() == nil {
|
if err != nil && ctx.Err() == nil {
|
||||||
log.Warn("auto-update check failed", "err", err)
|
log.Warn("auto-update check failed", "err", err)
|
||||||
}
|
}
|
||||||
if staged {
|
if staged {
|
||||||
if !isService {
|
if !isService {
|
||||||
log.Warn("auto-update: new binary staged; restart gpu-turnstile to apply")
|
log.Warn("auto-update: new binary staged; restart gpu-turnstile to apply", "version", to)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
log.Warn("auto-update: staged; restarting once the GPU is idle")
|
log.Warn("auto-update: staged; restarting once the GPU is idle", "version", to)
|
||||||
if waitForIdle(ctx, lk, 24*time.Hour) {
|
if waitForIdle(ctx, lk, 24*time.Hour) {
|
||||||
log.Warn("auto-update: restarting to apply update")
|
log.Warn("auto-update: restarting to apply update")
|
||||||
os.Exit(exitCodeUpdate)
|
os.Exit(exitCodeUpdate)
|
||||||
|
|||||||
@@ -6,7 +6,7 @@
|
|||||||
# ComfyUI --listen 0.0.0.0 --port 8189).
|
# ComfyUI --listen 0.0.0.0 --port 8189).
|
||||||
services:
|
services:
|
||||||
gpu-turnstile:
|
gpu-turnstile:
|
||||||
image: git.rambossek.at/public/gpu-turnstile:v0.1.9
|
image: git.rambossek.at/public/gpu-turnstile:v0.2.1
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
# Each consumer is enabled by setting its URL; leave one unset to
|
# Each consumer is enabled by setting its URL; leave one unset to
|
||||||
|
|||||||
@@ -51,11 +51,14 @@ type Config struct {
|
|||||||
LLMBusyStatus int
|
LLMBusyStatus int
|
||||||
BusyRetryAfter int
|
BusyRetryAfter int
|
||||||
|
|
||||||
// ComfyCmd spawns and supervises a ComfyUI server on demand (empty =
|
// ComfyCmd spawns and supervises a ComfyUI server on demand. When
|
||||||
// unmanaged, the current behavior). ComfyDir is its working directory.
|
// ComfyCmd is empty but ComfyDir is set, management is enabled with the
|
||||||
// The managed server is stopped after ComfyIdleTimeout without
|
// standard venv layout under ComfyDir (.venv + main.py or
|
||||||
// requests, freeing its VRAM; ComfyStartTimeout bounds how long a
|
// ComfyUI/main.py; --port from the COMFY_URL port) — ComfyCmd is the
|
||||||
// request waits for it to come up.
|
// override for other layouts and doubles as the working directory when
|
||||||
|
// set explicitly. The managed server is stopped after ComfyIdleTimeout
|
||||||
|
// without requests, freeing its VRAM; ComfyStartTimeout bounds how long
|
||||||
|
// a request waits for it to come up.
|
||||||
ComfyCmd string
|
ComfyCmd string
|
||||||
ComfyDir string
|
ComfyDir string
|
||||||
ComfyIdleTimeout time.Duration
|
ComfyIdleTimeout time.Duration
|
||||||
@@ -116,7 +119,7 @@ func Defaults() Config {
|
|||||||
// ComfyUI runs under python; excluding it (and Ollama) by name keeps
|
// ComfyUI runs under python; excluding it (and Ollama) by name keeps
|
||||||
// our own consumers from tripping the foreign-VRAM check.
|
// our own consumers from tripping the foreign-VRAM check.
|
||||||
GPUIgnoreProcs: []string{"ollama", "ollama app", "ollama_llama_server", "python", "pythonw"},
|
GPUIgnoreProcs: []string{"ollama", "ollama app", "ollama_llama_server", "python", "pythonw"},
|
||||||
GamePollInterval: 5 * time.Second,
|
GamePollInterval: 15 * time.Second,
|
||||||
|
|
||||||
LogLevel: slog.LevelWarn,
|
LogLevel: slog.LevelWarn,
|
||||||
}
|
}
|
||||||
@@ -305,6 +308,9 @@ func Load(getenv func(string) string) (Config, error) {
|
|||||||
if cfg.ComfyCmd != "" && cfg.ComfyURL == "" {
|
if cfg.ComfyCmd != "" && cfg.ComfyURL == "" {
|
||||||
return cfg, fmt.Errorf("COMFY_CMD requires COMFY_URL to be set (the proxy needs somewhere to forward)")
|
return cfg, fmt.Errorf("COMFY_CMD requires COMFY_URL to be set (the proxy needs somewhere to forward)")
|
||||||
}
|
}
|
||||||
|
if cfg.ComfyCmd == "" && cfg.ComfyDir != "" && cfg.ComfyURL == "" {
|
||||||
|
return cfg, fmt.Errorf("COMFY_DIR without COMFY_CMD requires COMFY_URL to be set (it enables the managed ComfyUI)")
|
||||||
|
}
|
||||||
if cfg.OllamaURL == "" && cfg.ComfyURL == "" {
|
if cfg.OllamaURL == "" && cfg.ComfyURL == "" {
|
||||||
return cfg, ErrNoConsumer
|
return cfg, ErrNoConsumer
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -201,8 +201,8 @@ func TestGameDetectionSettings(t *testing.T) {
|
|||||||
if len(cfg.GPUIgnoreProcs) != 2 || cfg.GPUIgnoreProcs[1] != "my-trainer" {
|
if len(cfg.GPUIgnoreProcs) != 2 || cfg.GPUIgnoreProcs[1] != "my-trainer" {
|
||||||
t.Fatalf("GPUIgnoreProcs = %v", cfg.GPUIgnoreProcs)
|
t.Fatalf("GPUIgnoreProcs = %v", cfg.GPUIgnoreProcs)
|
||||||
}
|
}
|
||||||
if cfg.GamePollInterval != 5*time.Second {
|
if cfg.GamePollInterval != 15*time.Second {
|
||||||
t.Fatalf("GamePollInterval = %v, want 5s default", cfg.GamePollInterval)
|
t.Fatalf("GamePollInterval = %v, want 15s default", cfg.GamePollInterval)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Defaults: both detection paths off, ignore list covers our consumers.
|
// Defaults: both detection paths off, ignore list covers our consumers.
|
||||||
@@ -222,3 +222,28 @@ func TestGameDetectionSettings(t *testing.T) {
|
|||||||
t.Fatal("GPUIgnoreProcs default must not be empty")
|
t.Fatal("GPUIgnoreProcs default must not be empty")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestComfyDirOnlyEnablesManaged(t *testing.T) {
|
||||||
|
// COMFY_DIR without COMFY_CMD and without COMFY_URL is a mistake.
|
||||||
|
_, err := Load(func(k string) string {
|
||||||
|
if k == "COMFY_DIR" {
|
||||||
|
return `C:\ComfyUI`
|
||||||
|
}
|
||||||
|
return ""
|
||||||
|
})
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "COMFY_DIR") {
|
||||||
|
t.Fatalf("err = %v, want COMFY_DIR/COMFY_URL validation error", err)
|
||||||
|
}
|
||||||
|
// With COMFY_URL it loads — the launch command is derived from the dir.
|
||||||
|
if _, err := Load(func(k string) string {
|
||||||
|
switch k {
|
||||||
|
case "COMFY_DIR":
|
||||||
|
return `C:\ComfyUI`
|
||||||
|
case "COMFY_URL":
|
||||||
|
return "http://127.0.0.1:8189"
|
||||||
|
}
|
||||||
|
return ""
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("COMFY_DIR with COMFY_URL must load: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -28,14 +28,14 @@ func sampleEntries(logFile string) []sampleEntry {
|
|||||||
{"OLLAMA_URL", "http://127.0.0.1:11434", "Ollama upstream URL; setting it enables the Ollama consumer (default: empty = disabled)", false},
|
{"OLLAMA_URL", "http://127.0.0.1:11434", "Ollama upstream URL; setting it enables the Ollama consumer (default: empty = disabled)", false},
|
||||||
{"COMFY_URL", "http://127.0.0.1:8188", "ComfyUI upstream URL; setting it enables the ComfyUI consumer (default: empty = disabled)", false},
|
{"COMFY_URL", "http://127.0.0.1:8188", "ComfyUI upstream URL; setting it enables the ComfyUI consumer (default: empty = disabled)", false},
|
||||||
{"WARM_MODEL", "", "Optional model to reload after an image job (default: empty = none)", false},
|
{"WARM_MODEL", "", "Optional model to reload after an image job (default: empty = none)", false},
|
||||||
{"COMFY_CMD", `"C:\ComfyUI\.venv\Scripts\python.exe" ComfyUI\main.py --port 8188`, "Spawn and supervise ComfyUI on demand: the first request starts it, it stops after COMFY_IDLE_TIMEOUT to free VRAM (default: empty = unmanaged)", false},
|
{"COMFY_CMD", `"C:\ComfyUI\.venv\Scripts\python.exe" ComfyUI\main.py --port 8188`, "Spawn and supervise ComfyUI on demand: the first request starts it, it stops after COMFY_IDLE_TIMEOUT to free VRAM (default: derived from COMFY_DIR; both empty = unmanaged)", false},
|
||||||
{"COMFY_DIR", `C:\ComfyUI`, "Working directory for COMFY_CMD (default: empty = inherit)", false},
|
{"COMFY_DIR", `C:\ComfyUI`, "Root of a standard ComfyUI venv install (.venv + main.py): setting it alone supervises ComfyUI with the derived launch command; also the working directory for COMFY_CMD", false},
|
||||||
{"COMFY_IDLE_TIMEOUT", "5m", "Stop the managed ComfyUI after this long without requests or jobs (frees VRAM)", false},
|
{"COMFY_IDLE_TIMEOUT", "5m", "Stop the managed ComfyUI after this long without requests or jobs (frees VRAM)", false},
|
||||||
{"COMFY_START_TIMEOUT", "2m", "How long a request waits for the managed ComfyUI to come up", false},
|
{"COMFY_START_TIMEOUT", "2m", "How long a request waits for the managed ComfyUI to come up", false},
|
||||||
{"GAME_PROCS", "cyberpunk2077.exe,hl2.exe", "While a listed process runs, the GPU counts as held by it: requests wait, Ollama unloads, managed ComfyUI stops (default: empty = disabled)", false},
|
{"GAME_PROCS", "cyberpunk2077.exe,hl2.exe", "While a listed process runs, the GPU counts as held by it: requests wait, Ollama unloads, managed ComfyUI stops (default: empty = disabled)", false},
|
||||||
{"GPU_FOREIGN_VRAM_MB", "1024", "Also treat the GPU as held when a process not in GPU_IGNORE_PROCS uses more VRAM than this (needs nvidia-smi; 0/empty = disabled)", false},
|
{"GPU_FOREIGN_VRAM_MB", "1024", "Also treat the GPU as held when a process not in GPU_IGNORE_PROCS uses more VRAM than this (needs nvidia-smi; 0/empty = disabled)", false},
|
||||||
{"GPU_IGNORE_PROCS", "ollama,ollama app,ollama_llama_server,python,pythonw", "Process names never counted as foreign GPU users (ComfyUI runs under python)", false},
|
{"GPU_IGNORE_PROCS", "ollama,ollama app,ollama_llama_server,python,pythonw", "Process names never counted as foreign GPU users (ComfyUI runs under python)", false},
|
||||||
{"GAME_POLL_INTERVAL", "5s", "How often game/VRAM detection runs", false},
|
{"GAME_POLL_INTERVAL", "15s", "How often game/VRAM detection runs (nvidia-smi polls keep the GPU awake; don't go below ~10s)", false},
|
||||||
{"UNLOAD_TIMEOUT", "60s", "How long to wait for Ollama to unload a model", false},
|
{"UNLOAD_TIMEOUT", "60s", "How long to wait for Ollama to unload a model", false},
|
||||||
{"JOB_TIMEOUT", "15m", "Maximum time to wait for a ComfyUI job", false},
|
{"JOB_TIMEOUT", "15m", "Maximum time to wait for a ComfyUI job", false},
|
||||||
{"LLM_WAIT_TIMEOUT", "10m", "Max time an LLM request waits for the GPU before being answered 503 (wait mode)", false},
|
{"LLM_WAIT_TIMEOUT", "10m", "Max time an LLM request waits for the GPU before being answered 503 (wait mode)", false},
|
||||||
|
|||||||
@@ -45,3 +45,19 @@ func writeEnvFile(path, content string) error {
|
|||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// configuredValue reads one key from the env file the service will load, so
|
||||||
|
// the installers can adapt the sandbox to it (ACL grants, unit directives).
|
||||||
|
// "" when unset or unreadable.
|
||||||
|
func configuredValue(configPath, key string) string {
|
||||||
|
f, err := os.Open(configPath)
|
||||||
|
if err != nil {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
defer f.Close()
|
||||||
|
values, err := config.ParseEnvFile(f)
|
||||||
|
if err != nil {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
return values[key]
|
||||||
|
}
|
||||||
|
|||||||
@@ -62,8 +62,19 @@ func Run(run func(ctx context.Context) error) error {
|
|||||||
// filesystem is read-only except StateDirectory (the install dir, so
|
// filesystem is read-only except StateDirectory (the install dir, so
|
||||||
// self-updates can rewrite the binary), and the usual no-privilege-escalation
|
// self-updates can rewrite the binary), and the usual no-privilege-escalation
|
||||||
// directives apply. The proxy needs nothing but outbound TCP/UDP and the
|
// directives apply. The proxy needs nothing but outbound TCP/UDP and the
|
||||||
// notify socket, so it loses nothing.
|
// notify socket, so it loses nothing. A managed ComfyUI (comfyDir) gets a
|
||||||
func renderUnit(exePath, configPath string) string {
|
// BindPaths hole through ProtectHome/ProtectSystem: it reads its venv and
|
||||||
|
// writes output/temp/user data under COMFY_DIR. A venv whose base
|
||||||
|
// interpreter (pyvenv.cfg home) lives outside COMFY_DIR gets an additional
|
||||||
|
// read-only bind.
|
||||||
|
func renderUnit(exePath, configPath, comfyDir string) string {
|
||||||
|
bind := ""
|
||||||
|
if comfyDir != "" {
|
||||||
|
bind = "BindPaths=" + comfyDir + "\n"
|
||||||
|
if home := comfyVenvHome(comfyDir); home != "" {
|
||||||
|
bind += "BindReadOnlyPaths=" + home + "\n"
|
||||||
|
}
|
||||||
|
}
|
||||||
return fmt.Sprintf(`[Unit]
|
return fmt.Sprintf(`[Unit]
|
||||||
Description=gpu-turnstile GPU arbitration proxy for Ollama and ComfyUI
|
Description=gpu-turnstile GPU arbitration proxy for Ollama and ComfyUI
|
||||||
After=network-online.target
|
After=network-online.target
|
||||||
@@ -78,7 +89,7 @@ RestartSec=5s
|
|||||||
|
|
||||||
DynamicUser=yes
|
DynamicUser=yes
|
||||||
StateDirectory=%s
|
StateDirectory=%s
|
||||||
ProtectSystem=strict
|
%sProtectSystem=strict
|
||||||
ProtectHome=yes
|
ProtectHome=yes
|
||||||
PrivateTmp=yes
|
PrivateTmp=yes
|
||||||
NoNewPrivileges=yes
|
NoNewPrivileges=yes
|
||||||
@@ -100,7 +111,7 @@ SystemCallErrorNumber=EPERM
|
|||||||
|
|
||||||
[Install]
|
[Install]
|
||||||
WantedBy=multi-user.target
|
WantedBy=multi-user.target
|
||||||
`, exePath, configPath, Name)
|
`, exePath, configPath, Name, bind)
|
||||||
}
|
}
|
||||||
|
|
||||||
// copyFile copies src to dst, creating dst with the given mode.
|
// copyFile copies src to dst, creating dst with the given mode.
|
||||||
@@ -125,7 +136,9 @@ func copyFile(src, dst string, mode os.FileMode) error {
|
|||||||
// sure /etc/gpu-turnstile.env exists (copied from the given config file if
|
// sure /etc/gpu-turnstile.env exists (copied from the given config file if
|
||||||
// provided), writes the hardened unit, then enables and starts it. With
|
// provided), writes the hardened unit, then enables and starts it. With
|
||||||
// copyBin=false the current executable location and config path are
|
// copyBin=false the current executable location and config path are
|
||||||
// registered as-is instead. Needs root.
|
// registered as-is instead. When the config sets COMFY_DIR, the unit gets a
|
||||||
|
// BindPaths= for it so the sandboxed service can reach the managed ComfyUI
|
||||||
|
// even under /home. Needs root.
|
||||||
//
|
//
|
||||||
// Re-running install converges an existing unit instead of failing: it is
|
// Re-running install converges an existing unit instead of failing: it is
|
||||||
// stopped first if active, the installed binary is replaced only when the
|
// stopped first if active, the installed binary is replaced only when the
|
||||||
@@ -186,7 +199,7 @@ func Install(configPath string, copyBin bool, version string) error {
|
|||||||
cfg = abs
|
cfg = abs
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
rendered := renderUnit(exe, cfg)
|
rendered := renderUnit(exe, cfg, configuredValue(cfg, "COMFY_DIR"))
|
||||||
if old, _ := os.ReadFile(unitPath); string(old) != rendered {
|
if old, _ := os.ReadFile(unitPath); string(old) != rendered {
|
||||||
if err := os.WriteFile(unitPath, []byte(rendered), 0o644); err != nil {
|
if err := os.WriteFile(unitPath, []byte(rendered), 0o644); err != nil {
|
||||||
return fmt.Errorf("write %s (run as root): %w", unitPath, err)
|
return fmt.Errorf("write %s (run as root): %w", unitPath, err)
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
func TestRenderUnit(t *testing.T) {
|
func TestRenderUnit(t *testing.T) {
|
||||||
unit := renderUnit("/var/lib/gpu-turnstile/gpu-turnstile", "/etc/gpu-turnstile.env")
|
unit := renderUnit("/var/lib/gpu-turnstile/gpu-turnstile", "/etc/gpu-turnstile.env", "")
|
||||||
for _, want := range []string{
|
for _, want := range []string{
|
||||||
"Type=notify",
|
"Type=notify",
|
||||||
"WatchdogSec=30s",
|
"WatchdogSec=30s",
|
||||||
@@ -26,4 +26,12 @@ func TestRenderUnit(t *testing.T) {
|
|||||||
t.Fatalf("unit missing %q:\n%s", want, unit)
|
t.Fatalf("unit missing %q:\n%s", want, unit)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
if strings.Contains(unit, "BindPaths") {
|
||||||
|
t.Fatalf("unit without COMFY_DIR must not bind anything:\n%s", unit)
|
||||||
|
}
|
||||||
|
|
||||||
|
unit = renderUnit("/var/lib/gpu-turnstile/gpu-turnstile", "/etc/gpu-turnstile.env", "/home/gpu/ComfyUI")
|
||||||
|
if !strings.Contains(unit, "BindPaths=/home/gpu/ComfyUI\n") {
|
||||||
|
t.Fatalf("unit with COMFY_DIR must bind it:\n%s", unit)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -24,8 +24,6 @@ import (
|
|||||||
"golang.org/x/sys/windows"
|
"golang.org/x/sys/windows"
|
||||||
"golang.org/x/sys/windows/svc"
|
"golang.org/x/sys/windows/svc"
|
||||||
"golang.org/x/sys/windows/svc/mgr"
|
"golang.org/x/sys/windows/svc/mgr"
|
||||||
|
|
||||||
"gpu-turnstile/internal/config"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// Name is the Windows service name.
|
// Name is the Windows service name.
|
||||||
@@ -106,10 +104,12 @@ func (h *handler) Execute(_ []string, requests <-chan svc.ChangeRequest, status
|
|||||||
// the service after 5s on failure — this is also what brings up a staged
|
// the service after 5s on failure — this is also what brings up a staged
|
||||||
// update after the updater exits with a non-zero code. After registering,
|
// update after the updater exits with a non-zero code. After registering,
|
||||||
// the virtual account is granted modify access to the install and data
|
// the virtual account is granted modify access to the install and data
|
||||||
// directories (self-updates rewrite the exe), and read access to the
|
// directories (self-updates rewrite the exe), read access to the
|
||||||
// config file if it lives elsewhere. The grants must come after
|
// config file if it lives elsewhere, and — when the config sets COMFY_DIR —
|
||||||
// CreateService: the virtual account's SID only exists once the service is
|
// recursive modify access to the managed ComfyUI's install tree, which may
|
||||||
// registered.
|
// live inside a user profile the account otherwise cannot enter. The grants
|
||||||
|
// must come after CreateService: the virtual account's SID only exists once
|
||||||
|
// the service is registered.
|
||||||
//
|
//
|
||||||
// Re-running install on an existing service converges instead of failing:
|
// Re-running install on an existing service converges instead of failing:
|
||||||
// the service is stopped first if running (so the binary can be replaced),
|
// the service is stopped first if running (so the binary can be replaced),
|
||||||
@@ -146,6 +146,7 @@ func Install(configPath string, copyBin bool, version string) error {
|
|||||||
if st, qErr := s.Query(); qErr == nil &&
|
if st, qErr := s.Query(); qErr == nil &&
|
||||||
(st.State == svc.Running || st.State == svc.StartPending) {
|
(st.State == svc.Running || st.State == svc.StartPending) {
|
||||||
wasRunning = true
|
wasRunning = true
|
||||||
|
fmt.Println("stopping the running gpu-turnstile service")
|
||||||
if err := stopAndWait(s); err != nil {
|
if err := stopAndWait(s); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -161,6 +162,7 @@ func Install(configPath string, copyBin bool, version string) error {
|
|||||||
}
|
}
|
||||||
installedExe := filepath.Join(installDir, "gpu-turnstile.exe")
|
installedExe := filepath.Join(installDir, "gpu-turnstile.exe")
|
||||||
if same, _ := sameFileContent(exe, installedExe); !same {
|
if same, _ := sameFileContent(exe, installedExe); !same {
|
||||||
|
fmt.Printf("installing %s\n", installedExe)
|
||||||
if err := copyFile(exe, installedExe); err != nil {
|
if err := copyFile(exe, installedExe); err != nil {
|
||||||
return fmt.Errorf("copy binary to %s: %w", installedExe, err)
|
return fmt.Errorf("copy binary to %s: %w", installedExe, err)
|
||||||
}
|
}
|
||||||
@@ -208,6 +210,7 @@ func Install(configPath string, copyBin bool, version string) error {
|
|||||||
// Best effort: start now instead of waiting for the next boot. A
|
// Best effort: start now instead of waiting for the next boot. A
|
||||||
// missing config (no consumer URLs) fails the start; the service stays
|
// missing config (no consumer URLs) fails the start; the service stays
|
||||||
// registered and can be started once the config exists.
|
// registered and can be started once the config exists.
|
||||||
|
fmt.Println("starting the gpu-turnstile service")
|
||||||
s.Start()
|
s.Start()
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
@@ -243,6 +246,7 @@ func Install(configPath string, copyBin bool, version string) error {
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
if wasRunning {
|
if wasRunning {
|
||||||
|
fmt.Println("starting the gpu-turnstile service")
|
||||||
if err := s.Start(); err != nil {
|
if err := s.Start(); err != nil {
|
||||||
return fmt.Errorf("start service: %w", err)
|
return fmt.Errorf("start service: %w", err)
|
||||||
}
|
}
|
||||||
@@ -354,7 +358,7 @@ func grantAll(exe, configPath string) error {
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if logFile := configuredLogFile(configPath); logFile != "" {
|
if logFile := configuredValue(configPath, "LOG_FILE"); logFile != "" {
|
||||||
dir := filepath.Dir(logFile)
|
dir := filepath.Dir(logFile)
|
||||||
if err := os.MkdirAll(dir, 0o755); err == nil {
|
if err := os.MkdirAll(dir, 0o755); err == nil {
|
||||||
if err := grantAccess(dir, "(OI)(CI)(M)"); err != nil {
|
if err := grantAccess(dir, "(OI)(CI)(M)"); err != nil {
|
||||||
@@ -362,6 +366,24 @@ func grantAll(exe, configPath string) error {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
// A managed ComfyUI whose install lives somewhere the virtual account
|
||||||
|
// may not go (a user profile) needs an explicit grant — recursively,
|
||||||
|
// since ComfyUI also writes output/temp/user data next to its code. A
|
||||||
|
// missing directory is skipped: the startup warning covers it.
|
||||||
|
if comfyDir := configuredValue(configPath, "COMFY_DIR"); comfyDir != "" {
|
||||||
|
if _, err := os.Stat(comfyDir); err == nil {
|
||||||
|
if err := grantAccessTree(comfyDir, "(OI)(CI)(M)"); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
// uv venvs (Comfy-Desktop) redirect to a base interpreter that
|
||||||
|
// can live outside COMFY_DIR; read+execute suffices for it.
|
||||||
|
if home := comfyVenvHome(comfyDir); home != "" {
|
||||||
|
if err := grantAccessTree(home, "(OI)(CI)(RX)"); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -466,28 +488,35 @@ func RelaunchElevated(args []string) (int, error) {
|
|||||||
// grantAccess gives the virtual account the icacls permission set (e.g.
|
// grantAccess gives the virtual account the icacls permission set (e.g.
|
||||||
// "(OI)(CI)(M)") on path.
|
// "(OI)(CI)(M)") on path.
|
||||||
func grantAccess(path, perms string) error {
|
func grantAccess(path, perms string) error {
|
||||||
out, err := exec.Command("icacls", path, "/grant", virtualAccount+":"+perms).CombinedOutput()
|
return runIcacls(path, perms, false)
|
||||||
|
}
|
||||||
|
|
||||||
|
// grantAccessTree is grantAccess with /T: the ACE is applied to the
|
||||||
|
// existing tree, not just inherited by children created later. Needed when
|
||||||
|
// the tree already exists, e.g. a ComfyUI install in a user profile. On a
|
||||||
|
// large tree (a venv has tens of thousands of files) this takes minutes,
|
||||||
|
// so it says what it is doing instead of looking hung.
|
||||||
|
func grantAccessTree(path, perms string) error {
|
||||||
|
return runIcacls(path, perms, true)
|
||||||
|
}
|
||||||
|
|
||||||
|
func runIcacls(path, perms string, recursive bool) error {
|
||||||
|
args := []string{path, "/grant", virtualAccount + ":" + perms}
|
||||||
|
if recursive {
|
||||||
|
fmt.Printf("granting %s %s access to %s (large trees can take minutes)\n", virtualAccount, perms, path)
|
||||||
|
args = append(args, "/T")
|
||||||
|
}
|
||||||
|
start := time.Now()
|
||||||
|
out, err := exec.Command("icacls", args...).CombinedOutput()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("grant %s access to %s: %w (%s)", virtualAccount, path, err, strings.TrimSpace(string(out)))
|
return fmt.Errorf("grant %s access to %s: %w (%s)", virtualAccount, path, err, strings.TrimSpace(string(out)))
|
||||||
}
|
}
|
||||||
|
if recursive {
|
||||||
|
fmt.Printf("access granted in %s\n", time.Since(start).Round(time.Second))
|
||||||
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// configuredLogFile reads LOG_FILE from the config file so the installer
|
|
||||||
// can pre-create and ACL the log directory. "" when unset or unreadable.
|
|
||||||
func configuredLogFile(configPath string) string {
|
|
||||||
f, err := os.Open(configPath)
|
|
||||||
if err != nil {
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
defer f.Close()
|
|
||||||
values, err := config.ParseEnvFile(f)
|
|
||||||
if err != nil {
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
return values["LOG_FILE"]
|
|
||||||
}
|
|
||||||
|
|
||||||
// RestartIfRunning restarts the service when it is installed and running
|
// RestartIfRunning restarts the service when it is installed and running
|
||||||
// (used after a forced update staged a new binary). Reports whether a
|
// (used after a forced update staged a new binary). Reports whether a
|
||||||
// restart happened. A service that is not installed or not running is not
|
// restart happened. A service that is not installed or not running is not
|
||||||
|
|||||||
@@ -0,0 +1,38 @@
|
|||||||
|
package service
|
||||||
|
|
||||||
|
import (
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
)
|
||||||
|
|
||||||
|
// comfyVenvHome returns the base interpreter directory of the Python venv at
|
||||||
|
// <comfyDir>/.venv when that directory lives outside comfyDir, "" otherwise.
|
||||||
|
// uv-created venvs (Comfy-Desktop) ship a redirector python.exe whose real
|
||||||
|
// interpreter is the pyvenv.cfg "home" tree — typically a sibling of
|
||||||
|
// COMFY_DIR, which a sandbox/ACL covering COMFY_DIR alone does not reach.
|
||||||
|
func comfyVenvHome(comfyDir string) string {
|
||||||
|
data, err := os.ReadFile(filepath.Join(comfyDir, ".venv", "pyvenv.cfg"))
|
||||||
|
if err != nil {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
for _, line := range strings.Split(string(data), "\n") {
|
||||||
|
k, v, ok := strings.Cut(line, "=")
|
||||||
|
if !ok || strings.TrimSpace(k) != "home" {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
home := strings.TrimSpace(v)
|
||||||
|
if home == "" {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
if st, err := os.Stat(home); err != nil || !st.IsDir() {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
rel, err := filepath.Rel(comfyDir, home)
|
||||||
|
if err != nil || rel == ".." || strings.HasPrefix(rel, ".."+string(filepath.Separator)) {
|
||||||
|
return home
|
||||||
|
}
|
||||||
|
return "" // inside comfyDir: already covered by the COMFY_DIR grant
|
||||||
|
}
|
||||||
|
return ""
|
||||||
|
}
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
package service
|
||||||
|
|
||||||
|
import (
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestComfyVenvHome(t *testing.T) {
|
||||||
|
root := t.TempDir()
|
||||||
|
comfy := filepath.Join(root, "ComfyUI")
|
||||||
|
outside := filepath.Join(root, "standalone-env")
|
||||||
|
inside := filepath.Join(comfy, "runtime")
|
||||||
|
for _, d := range []string{filepath.Join(comfy, ".venv"), outside, inside} {
|
||||||
|
if err := os.MkdirAll(d, 0o755); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
cfg := filepath.Join(comfy, ".venv", "pyvenv.cfg")
|
||||||
|
|
||||||
|
write := func(home string) {
|
||||||
|
if err := os.WriteFile(cfg, []byte("home = "+home+"\nversion_info = 3.13.0\n"), 0o644); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
write(outside)
|
||||||
|
if got := comfyVenvHome(comfy); got != outside {
|
||||||
|
t.Fatalf("outside home: got %q, want %q", got, outside)
|
||||||
|
}
|
||||||
|
|
||||||
|
write(inside)
|
||||||
|
if got := comfyVenvHome(comfy); got != "" {
|
||||||
|
t.Fatalf("inside home: got %q, want empty", got)
|
||||||
|
}
|
||||||
|
|
||||||
|
write(filepath.Join(root, "does-not-exist"))
|
||||||
|
if got := comfyVenvHome(comfy); got != "" {
|
||||||
|
t.Fatalf("missing home: got %q, want empty", got)
|
||||||
|
}
|
||||||
|
|
||||||
|
if got := comfyVenvHome(filepath.Join(root, "no-venv")); got != "" {
|
||||||
|
t.Fatalf("no pyvenv.cfg: got %q, want empty", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -9,13 +9,54 @@ import (
|
|||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
|
"net/url"
|
||||||
|
"os"
|
||||||
"os/exec"
|
"os/exec"
|
||||||
|
"path/filepath"
|
||||||
"runtime"
|
"runtime"
|
||||||
"strings"
|
"strings"
|
||||||
"sync"
|
"sync"
|
||||||
"time"
|
"time"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// ComfyLayout returns the interpreter and script path of a standard ComfyUI
|
||||||
|
// venv install rooted at dir for the given GOOS: .venv\Scripts\python.exe
|
||||||
|
// on Windows, .venv/bin/python elsewhere. The script is main.py — either in
|
||||||
|
// a ComfyUI subdirectory or directly under dir, whichever exists (the
|
||||||
|
// subdirectory form wins ties and is the default when neither exists yet,
|
||||||
|
// so the caller's missing-file warning points at the documented layout).
|
||||||
|
func ComfyLayout(goos, dir string) (python, script string) {
|
||||||
|
if goos == "windows" {
|
||||||
|
python = filepath.Join(dir, ".venv", "Scripts", "python.exe")
|
||||||
|
} else {
|
||||||
|
python = filepath.Join(dir, ".venv", "bin", "python")
|
||||||
|
}
|
||||||
|
script = filepath.Join(dir, "ComfyUI", "main.py")
|
||||||
|
if _, err := os.Stat(script); err != nil {
|
||||||
|
if _, err := os.Stat(filepath.Join(dir, "main.py")); err == nil {
|
||||||
|
script = filepath.Join(dir, "main.py")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return python, script
|
||||||
|
}
|
||||||
|
|
||||||
|
// DefaultComfyCommand builds the launch command for the standard venv
|
||||||
|
// layout (see ComfyLayout): the script is passed relative to dir so dir
|
||||||
|
// stays the working directory, and --port is taken from comfyURL when the
|
||||||
|
// URL carries one.
|
||||||
|
func DefaultComfyCommand(goos, dir, comfyURL string) string {
|
||||||
|
python, script := ComfyLayout(goos, dir)
|
||||||
|
rel, err := filepath.Rel(dir, script)
|
||||||
|
if err != nil {
|
||||||
|
rel = script
|
||||||
|
}
|
||||||
|
cmd := `"` + python + `" ` + rel
|
||||||
|
if u, err := url.Parse(comfyURL); err == nil && u.Port() != "" {
|
||||||
|
cmd += " --port " + u.Port()
|
||||||
|
}
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
|
|
||||||
// Process is one managed child process.
|
// Process is one managed child process.
|
||||||
type Process struct {
|
type Process struct {
|
||||||
name string
|
name string
|
||||||
|
|||||||
@@ -7,6 +7,8 @@ import (
|
|||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"os"
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
)
|
)
|
||||||
@@ -190,3 +192,50 @@ func TestWatchIdleRespectsBusyGPU(t *testing.T) {
|
|||||||
t.Fatal("process was stopped while the GPU was busy")
|
t.Fatal("process was stopped while the GPU was busy")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestComfyLayoutAndDefaultCommand(t *testing.T) {
|
||||||
|
// Nested layout (ComfyUI/main.py under dir) wins.
|
||||||
|
dir := t.TempDir()
|
||||||
|
nested := filepath.Join(dir, "ComfyUI", "main.py")
|
||||||
|
if err := os.MkdirAll(filepath.Dir(nested), 0o755); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := os.WriteFile(nested, []byte("x"), 0o644); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
python, script := ComfyLayout("windows", dir)
|
||||||
|
if want := filepath.Join(dir, ".venv", "Scripts", "python.exe"); python != want {
|
||||||
|
t.Errorf("python = %s, want %s", python, want)
|
||||||
|
}
|
||||||
|
if script != nested {
|
||||||
|
t.Errorf("script = %s, want %s", script, nested)
|
||||||
|
}
|
||||||
|
cmd := DefaultComfyCommand("windows", dir, "http://127.0.0.1:8189")
|
||||||
|
want := `"` + filepath.Join(dir, ".venv", "Scripts", "python.exe") + `" ` + filepath.Join("ComfyUI", "main.py") + " --port 8189"
|
||||||
|
if cmd != want {
|
||||||
|
t.Errorf("cmd = %q, want %q", cmd, want)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Flat layout (main.py directly under dir) is found too.
|
||||||
|
flat := t.TempDir()
|
||||||
|
if err := os.WriteFile(filepath.Join(flat, "main.py"), []byte("x"), 0o644); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if _, script := ComfyLayout("linux", flat); script != filepath.Join(flat, "main.py") {
|
||||||
|
t.Errorf("flat script = %s", script)
|
||||||
|
}
|
||||||
|
cmd = DefaultComfyCommand("linux", flat, "http://comfy.internal")
|
||||||
|
if strings.Contains(cmd, "--port") {
|
||||||
|
t.Errorf("cmd = %q, want no --port for a port-less URL", cmd)
|
||||||
|
}
|
||||||
|
if !strings.HasSuffix(cmd, `" main.py`) {
|
||||||
|
t.Errorf("cmd = %q, want quoted python + relative main.py", cmd)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Neither exists yet: default to the documented nested form so the
|
||||||
|
// startup warning points there.
|
||||||
|
empty := t.TempDir()
|
||||||
|
if _, script := ComfyLayout("windows", empty); script != filepath.Join(empty, "ComfyUI", "main.py") {
|
||||||
|
t.Errorf("missing-layout script = %s", script)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
+25
-22
@@ -173,11 +173,13 @@ func CleanupOld(exePath string) {
|
|||||||
|
|
||||||
// Check performs a single update check. staged is true when a
|
// Check performs a single update check. staged is true when a
|
||||||
// signature-verified binary has been swapped into place at exePath; the
|
// signature-verified binary has been swapped into place at exePath; the
|
||||||
// caller should then restart the process. A nil error with staged=false
|
// caller should then restart the process. to is the release tag the check
|
||||||
// means "no action" (up to date, APP_VER=dev, or no embedded public key);
|
// resolved (the latest release or the pinned tag), set once the release
|
||||||
// a non-nil error means the check failed and the running binary is
|
// fetch succeeded — even when staging afterwards fails. A nil error with
|
||||||
// untouched.
|
// staged=false means "no action" (up to date, APP_VER=dev, or no embedded
|
||||||
func (u *Updater) Check(ctx context.Context, exePath string) (staged bool, err error) {
|
// public key); a non-nil error means the check failed and the running
|
||||||
|
// binary is untouched.
|
||||||
|
func (u *Updater) Check(ctx context.Context, exePath string) (staged bool, to string, err error) {
|
||||||
log := u.logger()
|
log := u.logger()
|
||||||
desired := u.Desired
|
desired := u.Desired
|
||||||
if desired == "" {
|
if desired == "" {
|
||||||
@@ -185,15 +187,15 @@ func (u *Updater) Check(ctx context.Context, exePath string) (staged bool, err e
|
|||||||
}
|
}
|
||||||
if desired == "dev" {
|
if desired == "dev" {
|
||||||
log.Debug("auto-update: APP_VER=dev, skipping")
|
log.Debug("auto-update: APP_VER=dev, skipping")
|
||||||
return false, nil
|
return false, "", nil
|
||||||
}
|
}
|
||||||
if publicKeyPEM == "" {
|
if publicKeyPEM == "" {
|
||||||
log.Debug("auto-update: no public key embedded, skipping")
|
log.Debug("auto-update: no public key embedded, skipping")
|
||||||
return false, nil
|
return false, "", nil
|
||||||
}
|
}
|
||||||
api, err := u.apiURL()
|
api, err := u.apiURL()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return false, err
|
return false, "", err
|
||||||
}
|
}
|
||||||
|
|
||||||
pinned := desired != "stable"
|
pinned := desired != "stable"
|
||||||
@@ -203,29 +205,30 @@ func (u *Updater) Check(ctx context.Context, exePath string) (staged bool, err e
|
|||||||
}
|
}
|
||||||
body, err := u.get(ctx, endpoint)
|
body, err := u.get(ctx, endpoint)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return false, fmt.Errorf("fetch release: %w", err)
|
return false, "", fmt.Errorf("fetch release: %w", err)
|
||||||
}
|
}
|
||||||
var rel release
|
var rel release
|
||||||
if err := json.Unmarshal(body, &rel); err != nil {
|
if err := json.Unmarshal(body, &rel); err != nil {
|
||||||
return false, fmt.Errorf("parse release: %w", err)
|
return false, "", fmt.Errorf("parse release: %w", err)
|
||||||
}
|
}
|
||||||
|
to = rel.TagName
|
||||||
if pinned {
|
if pinned {
|
||||||
// Pin mode: any difference from the target tag means stage it —
|
// Pin mode: any difference from the target tag means stage it —
|
||||||
// including downgrades and replacing a dev binary.
|
// including downgrades and replacing a dev binary.
|
||||||
if u.Version == rel.TagName {
|
if u.Version == rel.TagName {
|
||||||
log.Debug("auto-update: already on pinned version", "version", u.Version)
|
log.Debug("auto-update: already on pinned version", "version", u.Version)
|
||||||
return false, nil
|
return false, to, nil
|
||||||
}
|
}
|
||||||
} else if u.Version != "" && u.Version != "dev" {
|
} else if u.Version != "" && u.Version != "dev" {
|
||||||
// Stable mode: only strictly newer releases count; a dev binary
|
// Stable mode: only strictly newer releases count; a dev binary
|
||||||
// cannot be compared and is always replaced by the latest release.
|
// cannot be compared and is always replaced by the latest release.
|
||||||
newer, err := newerVersion(u.Version, rel.TagName)
|
newer, err := newerVersion(u.Version, rel.TagName)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return false, err
|
return false, to, err
|
||||||
}
|
}
|
||||||
if !newer {
|
if !newer {
|
||||||
log.Debug("auto-update: up to date", "version", u.Version, "latest", rel.TagName)
|
log.Debug("auto-update: up to date", "version", u.Version, "latest", rel.TagName)
|
||||||
return false, nil
|
return false, to, nil
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -235,42 +238,42 @@ func (u *Updater) Check(ctx context.Context, exePath string) (staged bool, err e
|
|||||||
}
|
}
|
||||||
assetURL, ok := urls[u.Asset]
|
assetURL, ok := urls[u.Asset]
|
||||||
if !ok {
|
if !ok {
|
||||||
return false, fmt.Errorf("release %s has no asset %q", rel.TagName, u.Asset)
|
return false, to, fmt.Errorf("release %s has no asset %q", rel.TagName, u.Asset)
|
||||||
}
|
}
|
||||||
sigURL, ok := urls[u.Asset+".sig"]
|
sigURL, ok := urls[u.Asset+".sig"]
|
||||||
if !ok {
|
if !ok {
|
||||||
return false, fmt.Errorf("release %s has no signature asset %q", rel.TagName, u.Asset+".sig")
|
return false, to, fmt.Errorf("release %s has no signature asset %q", rel.TagName, u.Asset+".sig")
|
||||||
}
|
}
|
||||||
|
|
||||||
data, err := u.get(ctx, assetURL)
|
data, err := u.get(ctx, assetURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return false, fmt.Errorf("download %s: %w", u.Asset, err)
|
return false, to, fmt.Errorf("download %s: %w", u.Asset, err)
|
||||||
}
|
}
|
||||||
sig, err := u.get(ctx, sigURL)
|
sig, err := u.get(ctx, sigURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return false, fmt.Errorf("download signature: %w", err)
|
return false, to, fmt.Errorf("download signature: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
if sumURL, ok := urls[u.Asset+".sha256"]; ok {
|
if sumURL, ok := urls[u.Asset+".sha256"]; ok {
|
||||||
sumText, err := u.get(ctx, sumURL)
|
sumText, err := u.get(ctx, sumURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return false, fmt.Errorf("download checksum: %w", err)
|
return false, to, fmt.Errorf("download checksum: %w", err)
|
||||||
}
|
}
|
||||||
want := strings.Fields(string(sumText))[0]
|
want := strings.Fields(string(sumText))[0]
|
||||||
got := hex.EncodeToString(sha256Bytes(data))
|
got := hex.EncodeToString(sha256Bytes(data))
|
||||||
if !strings.EqualFold(want, got) {
|
if !strings.EqualFold(want, got) {
|
||||||
return false, fmt.Errorf("sha256 mismatch: got %s, want %s", got, want)
|
return false, to, fmt.Errorf("sha256 mismatch: got %s, want %s", got, want)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if err := verifySignature(publicKeyPEM, data, sig); err != nil {
|
if err := verifySignature(publicKeyPEM, data, sig); err != nil {
|
||||||
return false, err
|
return false, to, err
|
||||||
}
|
}
|
||||||
|
|
||||||
if err := stage(exePath, data); err != nil {
|
if err := stage(exePath, data); err != nil {
|
||||||
return false, fmt.Errorf("stage update: %w", err)
|
return false, to, fmt.Errorf("stage update: %w", err)
|
||||||
}
|
}
|
||||||
log.Info("auto-update: new version staged", "from", u.Version, "to", rel.TagName)
|
log.Info("auto-update: new version staged", "from", u.Version, "to", rel.TagName)
|
||||||
return true, nil
|
return true, to, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func sha256Bytes(data []byte) []byte {
|
func sha256Bytes(data []byte) []byte {
|
||||||
|
|||||||
@@ -102,13 +102,16 @@ func TestCheckStagesUpdate(t *testing.T) {
|
|||||||
withPublicKey(t, f.pubPEM)
|
withPublicKey(t, f.pubPEM)
|
||||||
exe := fakeExe(t)
|
exe := fakeExe(t)
|
||||||
|
|
||||||
staged, err := f.updater("v0.1.2").Check(context.Background(), exe)
|
staged, to, err := f.updater("v0.1.2").Check(context.Background(), exe)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
if !staged {
|
if !staged {
|
||||||
t.Fatal("expected staged update")
|
t.Fatal("expected staged update")
|
||||||
}
|
}
|
||||||
|
if to != "v9.9.9" {
|
||||||
|
t.Fatalf("to = %q, want v9.9.9", to)
|
||||||
|
}
|
||||||
content, _ := os.ReadFile(exe)
|
content, _ := os.ReadFile(exe)
|
||||||
if string(content) != "new-binary" {
|
if string(content) != "new-binary" {
|
||||||
t.Fatalf("exe content = %q", content)
|
t.Fatalf("exe content = %q", content)
|
||||||
@@ -125,7 +128,7 @@ func TestCheckRejectsTamperedSignature(t *testing.T) {
|
|||||||
withPublicKey(t, f.pubPEM)
|
withPublicKey(t, f.pubPEM)
|
||||||
exe := fakeExe(t)
|
exe := fakeExe(t)
|
||||||
|
|
||||||
staged, err := f.updater("v0.1.2").Check(context.Background(), exe)
|
staged, _, err := f.updater("v0.1.2").Check(context.Background(), exe)
|
||||||
if err == nil {
|
if err == nil {
|
||||||
t.Fatal("expected signature error")
|
t.Fatal("expected signature error")
|
||||||
}
|
}
|
||||||
@@ -142,7 +145,7 @@ func TestCheckSkipsOlderOrEqual(t *testing.T) {
|
|||||||
for _, tag := range []string{"v0.1.2", "v0.1.1", "v0.0.9"} {
|
for _, tag := range []string{"v0.1.2", "v0.1.1", "v0.0.9"} {
|
||||||
f := newFakeGitea(t, tag, []byte("new-binary"))
|
f := newFakeGitea(t, tag, []byte("new-binary"))
|
||||||
withPublicKey(t, f.pubPEM)
|
withPublicKey(t, f.pubPEM)
|
||||||
staged, err := f.updater("v0.1.2").Check(context.Background(), fakeExe(t))
|
staged, _, err := f.updater("v0.1.2").Check(context.Background(), fakeExe(t))
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
@@ -155,7 +158,7 @@ func TestCheckSkipsOlderOrEqual(t *testing.T) {
|
|||||||
func TestCheckSkipsWithoutPublicKey(t *testing.T) {
|
func TestCheckSkipsWithoutPublicKey(t *testing.T) {
|
||||||
f := newFakeGitea(t, "v9.9.9", []byte("new-binary"))
|
f := newFakeGitea(t, "v9.9.9", []byte("new-binary"))
|
||||||
withPublicKey(t, "")
|
withPublicKey(t, "")
|
||||||
staged, err := f.updater("v0.1.2").Check(context.Background(), fakeExe(t))
|
staged, _, err := f.updater("v0.1.2").Check(context.Background(), fakeExe(t))
|
||||||
if err != nil || staged {
|
if err != nil || staged {
|
||||||
t.Fatalf("staged=%v err=%v, want no action without key", staged, err)
|
t.Fatalf("staged=%v err=%v, want no action without key", staged, err)
|
||||||
}
|
}
|
||||||
@@ -167,7 +170,7 @@ func TestCheckDevBuildGetsStable(t *testing.T) {
|
|||||||
f := newFakeGitea(t, "v9.9.9", []byte("new-binary"))
|
f := newFakeGitea(t, "v9.9.9", []byte("new-binary"))
|
||||||
withPublicKey(t, f.pubPEM)
|
withPublicKey(t, f.pubPEM)
|
||||||
exe := fakeExe(t)
|
exe := fakeExe(t)
|
||||||
staged, err := f.updater("dev").Check(context.Background(), exe)
|
staged, _, err := f.updater("dev").Check(context.Background(), exe)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
@@ -184,7 +187,7 @@ func TestCheckDesiredDevDisables(t *testing.T) {
|
|||||||
f := newFakeGitea(t, "v9.9.9", []byte("new-binary"))
|
f := newFakeGitea(t, "v9.9.9", []byte("new-binary"))
|
||||||
withPublicKey(t, f.pubPEM)
|
withPublicKey(t, f.pubPEM)
|
||||||
for _, version := range []string{"dev", "v0.1.2"} {
|
for _, version := range []string{"dev", "v0.1.2"} {
|
||||||
staged, err := f.updaterDesired(version, "dev").Check(context.Background(), fakeExe(t))
|
staged, _, err := f.updaterDesired(version, "dev").Check(context.Background(), fakeExe(t))
|
||||||
if err != nil || staged {
|
if err != nil || staged {
|
||||||
t.Fatalf("version %s: staged=%v err=%v, want no action with APP_VER=dev", version, staged, err)
|
t.Fatalf("version %s: staged=%v err=%v, want no action with APP_VER=dev", version, staged, err)
|
||||||
}
|
}
|
||||||
@@ -198,13 +201,16 @@ func TestCheckPinned(t *testing.T) {
|
|||||||
f := newFakeGitea(t, "v0.5.0", []byte("pinned-binary"))
|
f := newFakeGitea(t, "v0.5.0", []byte("pinned-binary"))
|
||||||
withPublicKey(t, f.pubPEM)
|
withPublicKey(t, f.pubPEM)
|
||||||
exe := fakeExe(t)
|
exe := fakeExe(t)
|
||||||
staged, err := f.updaterDesired(version, "v0.5.0").Check(context.Background(), exe)
|
staged, to, err := f.updaterDesired(version, "v0.5.0").Check(context.Background(), exe)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatalf("version %s: %v", version, err)
|
t.Fatalf("version %s: %v", version, err)
|
||||||
}
|
}
|
||||||
if !staged {
|
if !staged {
|
||||||
t.Fatalf("version %s: expected pinned v0.5.0 to be staged", version)
|
t.Fatalf("version %s: expected pinned v0.5.0 to be staged", version)
|
||||||
}
|
}
|
||||||
|
if to != "v0.5.0" {
|
||||||
|
t.Fatalf("version %s: to = %q, want v0.5.0", version, to)
|
||||||
|
}
|
||||||
content, _ := os.ReadFile(exe)
|
content, _ := os.ReadFile(exe)
|
||||||
if string(content) != "pinned-binary" {
|
if string(content) != "pinned-binary" {
|
||||||
t.Fatalf("version %s: exe content = %q", version, content)
|
t.Fatalf("version %s: exe content = %q", version, content)
|
||||||
@@ -213,7 +219,7 @@ func TestCheckPinned(t *testing.T) {
|
|||||||
|
|
||||||
f := newFakeGitea(t, "v0.5.0", []byte("pinned-binary"))
|
f := newFakeGitea(t, "v0.5.0", []byte("pinned-binary"))
|
||||||
withPublicKey(t, f.pubPEM)
|
withPublicKey(t, f.pubPEM)
|
||||||
staged, err := f.updaterDesired("v0.5.0", "v0.5.0").Check(context.Background(), fakeExe(t))
|
staged, _, err := f.updaterDesired("v0.5.0", "v0.5.0").Check(context.Background(), fakeExe(t))
|
||||||
if err != nil || staged {
|
if err != nil || staged {
|
||||||
t.Fatalf("staged=%v err=%v, want no action when already on the pinned version", staged, err)
|
t.Fatalf("staged=%v err=%v, want no action when already on the pinned version", staged, err)
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user