Windows: --install-service creates %ProgramFiles%\gpu-turnstile and %ProgramData%\gpu-turnstile, copies the exe and (if absent) the env file in, and registers the copy. Linux: binary goes to /var/lib/gpu-turnstile (not /usr/local/sbin: replacing a running binary needs directory write, which must not be granted on a shared system dir to a sandboxed service). --no-copy registers the current location as-is on both platforms.
269 lines
8.1 KiB
Go
269 lines
8.1 KiB
Go
//go:build windows
|
|
|
|
// Package service integrates gpu-turnstile with the Windows Service
|
|
// Control Manager: running as a service with graceful stop, plus
|
|
// install/remove helpers. Installed services always run as the virtual
|
|
// account NT SERVICE\gpu-turnstile — a per-service low-privilege identity
|
|
// managed by the SCM, with no password and no admin rights.
|
|
package service
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
"io"
|
|
"os"
|
|
"os/exec"
|
|
"path/filepath"
|
|
"strings"
|
|
"time"
|
|
|
|
"golang.org/x/sys/windows/svc"
|
|
"golang.org/x/sys/windows/svc/mgr"
|
|
|
|
"gpu-turnstile/internal/config"
|
|
)
|
|
|
|
// Name is the Windows service name.
|
|
const Name = "gpu-turnstile"
|
|
|
|
// virtualAccount is the per-service identity the service runs as. The SCM
|
|
// manages it: no password, automatic "log on as a service" right, gone
|
|
// when the service is removed.
|
|
const virtualAccount = `NT SERVICE\` + Name
|
|
|
|
// installDirs returns the canonical install (Program Files) and data
|
|
// (ProgramData) directories.
|
|
func installDirs() (install, data string) {
|
|
pf := os.Getenv("ProgramFiles")
|
|
if pf == "" {
|
|
pf = `C:\Program Files`
|
|
}
|
|
pd := os.Getenv("ProgramData")
|
|
if pd == "" {
|
|
pd = `C:\ProgramData`
|
|
}
|
|
return filepath.Join(pf, Name), filepath.Join(pd, Name)
|
|
}
|
|
|
|
// IsService reports whether the process is running as a Windows service.
|
|
func IsService() bool {
|
|
isSvc, err := svc.IsWindowsService()
|
|
return err == nil && isSvc
|
|
}
|
|
|
|
// Run executes run as a Windows service. SCM Stop and Shutdown cancel the
|
|
// context passed to run, triggering the same graceful shutdown as SIGTERM
|
|
// in interactive mode.
|
|
func Run(run func(ctx context.Context) error) error {
|
|
return svc.Run(Name, &handler{run: run})
|
|
}
|
|
|
|
type handler struct {
|
|
run func(ctx context.Context) error
|
|
}
|
|
|
|
func (h *handler) Execute(_ []string, requests <-chan svc.ChangeRequest, status chan<- svc.Status) (bool, uint32) {
|
|
ctx, cancel := context.WithCancel(context.Background())
|
|
defer cancel()
|
|
|
|
status <- svc.Status{State: svc.StartPending}
|
|
errCh := make(chan error, 1)
|
|
go func() { errCh <- h.run(ctx) }()
|
|
status <- svc.Status{State: svc.Running, Accepts: svc.AcceptStop | svc.AcceptShutdown}
|
|
|
|
for {
|
|
select {
|
|
case err := <-errCh:
|
|
status <- svc.Status{State: svc.Stopped}
|
|
if err != nil {
|
|
return true, 1
|
|
}
|
|
return false, 0
|
|
case c := <-requests:
|
|
switch c.Cmd {
|
|
case svc.Interrogate:
|
|
status <- c.CurrentStatus
|
|
case svc.Stop, svc.Shutdown:
|
|
status <- svc.Status{State: svc.StopPending}
|
|
cancel()
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
// Install registers gpu-turnstile as an auto-start Windows service running
|
|
// as the NT SERVICE\gpu-turnstile virtual account, whose binPath loads the
|
|
// given config file. With copyBin it first creates the canonical layout —
|
|
// the binary is copied into %ProgramFiles%\gpu-turnstile and the config
|
|
// next to it (an existing config there is kept), %ProgramData%\gpu-turnstile
|
|
// is created for logs — and registers that copy; with copyBin=false the
|
|
// current executable location is registered as-is. Recovery actions restart
|
|
// the service after 5s on failure — this is also what brings up a staged
|
|
// update after the updater exits with a non-zero code. After registering,
|
|
// the virtual account is granted modify access to the install and data
|
|
// directories (self-updates rewrite the exe), and read access to the
|
|
// config file if it lives elsewhere. The grants must come after
|
|
// CreateService: the virtual account's SID only exists once the service is
|
|
// registered.
|
|
func Install(configPath string, copyBin bool) error {
|
|
exe, err := os.Executable()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
if abs, absErr := filepath.Abs(exe); absErr == nil {
|
|
exe = abs
|
|
}
|
|
if configPath != "" {
|
|
if abs, absErr := filepath.Abs(configPath); absErr == nil {
|
|
configPath = abs
|
|
}
|
|
}
|
|
|
|
installDir, _ := installDirs()
|
|
if copyBin && !strings.EqualFold(filepath.Dir(exe), installDir) {
|
|
if err := os.MkdirAll(installDir, 0o755); err != nil {
|
|
return fmt.Errorf("create %s: %w", installDir, err)
|
|
}
|
|
installedExe := filepath.Join(installDir, "gpu-turnstile.exe")
|
|
if err := copyFile(exe, installedExe); err != nil {
|
|
return fmt.Errorf("copy binary to %s: %w", installedExe, err)
|
|
}
|
|
exe = installedExe
|
|
targetCfg := filepath.Join(installDir, "gpu-turnstile.env")
|
|
if configPath != "" && !strings.EqualFold(configPath, targetCfg) {
|
|
if _, statErr := os.Stat(targetCfg); os.IsNotExist(statErr) {
|
|
copyFile(configPath, targetCfg) //nolint:errcheck // best effort
|
|
}
|
|
configPath = targetCfg
|
|
}
|
|
}
|
|
|
|
m, err := mgr.Connect()
|
|
if err != nil {
|
|
return fmt.Errorf("connect to service manager (run as administrator): %w", err)
|
|
}
|
|
defer m.Disconnect()
|
|
|
|
binPath := fmt.Sprintf(`"%s" -config "%s"`, exe, configPath)
|
|
s, err := m.CreateService(Name, binPath, mgr.Config{
|
|
StartType: mgr.StartAutomatic,
|
|
DisplayName: "gpu-turnstile",
|
|
Description: "GPU arbitration proxy for Ollama and ComfyUI",
|
|
ServiceStartName: virtualAccount,
|
|
})
|
|
if err != nil {
|
|
return fmt.Errorf("create service: %w", err)
|
|
}
|
|
defer s.Close()
|
|
|
|
restart := mgr.RecoveryAction{Type: mgr.ServiceRestart, Delay: 5 * time.Second}
|
|
if err := s.SetRecoveryActions([]mgr.RecoveryAction{restart, restart, restart}, 24*60*60); err != nil {
|
|
return fmt.Errorf("set recovery actions: %w", err)
|
|
}
|
|
if err := s.SetRecoveryActionsOnNonCrashFailures(true); err != nil {
|
|
return fmt.Errorf("set failure actions flag: %w", err)
|
|
}
|
|
|
|
if err := grantAll(exe, configPath); err != nil {
|
|
s.Delete() // roll back so a retry starts clean
|
|
return err
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// copyFile copies src to dst (0755 on the new file).
|
|
func copyFile(src, dst string) error {
|
|
in, err := os.Open(src)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer in.Close()
|
|
out, err := os.OpenFile(dst, os.O_CREATE|os.O_TRUNC|os.O_WRONLY, 0o755)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
if _, err := io.Copy(out, in); err != nil {
|
|
out.Close()
|
|
return err
|
|
}
|
|
return out.Close()
|
|
}
|
|
|
|
// grantAll gives the virtual account every ACL the service needs: modify
|
|
// on the install and ProgramData directories and the LOG_FILE directory
|
|
// (if configured elsewhere), read on a config file outside the install
|
|
// directory.
|
|
func grantAll(exe, configPath string) error {
|
|
_, dataDir := installDirs()
|
|
if err := os.MkdirAll(dataDir, 0o755); err != nil {
|
|
return fmt.Errorf("create %s: %w", dataDir, err)
|
|
}
|
|
if err := grantAccess(dataDir, "(OI)(CI)(M)"); err != nil {
|
|
return err
|
|
}
|
|
exeDir := filepath.Dir(exe)
|
|
if err := grantAccess(exeDir, "(OI)(CI)(M)"); err != nil {
|
|
return err
|
|
}
|
|
if configPath != "" && !strings.HasPrefix(strings.ToLower(configPath), strings.ToLower(exeDir)+`\`) {
|
|
if err := grantAccess(configPath, "(R)"); err != nil {
|
|
return err
|
|
}
|
|
}
|
|
if logFile := configuredLogFile(configPath); logFile != "" {
|
|
dir := filepath.Dir(logFile)
|
|
if err := os.MkdirAll(dir, 0o755); err == nil {
|
|
if err := grantAccess(dir, "(OI)(CI)(M)"); err != nil {
|
|
return err
|
|
}
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// Remove stops (if running) and unregisters the service. The virtual
|
|
// account ceases to exist with it; the ACL grants on the install and log
|
|
// directories are left in place (harmless without the account).
|
|
func Remove() error {
|
|
m, err := mgr.Connect()
|
|
if err != nil {
|
|
return fmt.Errorf("connect to service manager (run as administrator): %w", err)
|
|
}
|
|
defer m.Disconnect()
|
|
s, err := m.OpenService(Name)
|
|
if err != nil {
|
|
return fmt.Errorf("open service: %w", err)
|
|
}
|
|
defer s.Close()
|
|
s.Control(svc.Stop) // ignore error: may already be stopped
|
|
if err := s.Delete(); err != nil {
|
|
return fmt.Errorf("delete service: %w", err)
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// grantAccess gives the virtual account the icacls permission set (e.g.
|
|
// "(OI)(CI)(M)") on path.
|
|
func grantAccess(path, perms string) error {
|
|
out, err := exec.Command("icacls", path, "/grant", virtualAccount+":"+perms).CombinedOutput()
|
|
if err != nil {
|
|
return fmt.Errorf("grant %s access to %s: %w (%s)", virtualAccount, path, err, strings.TrimSpace(string(out)))
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// configuredLogFile reads LOG_FILE from the config file so the installer
|
|
// can pre-create and ACL the log directory. "" when unset or unreadable.
|
|
func configuredLogFile(configPath string) string {
|
|
f, err := os.Open(configPath)
|
|
if err != nil {
|
|
return ""
|
|
}
|
|
defer f.Close()
|
|
values, err := config.ParseEnvFile(f)
|
|
if err != nil {
|
|
return ""
|
|
}
|
|
return values["LOG_FILE"]
|
|
}
|