Files
Yeuoly 888ad788bc refactor: plugin lifecycle control panel (#499)
* refactor: introduce local plugin control panel and cleanup environment setup process

* fix: args

* refactor: new local runtime

* temp: stash work for refactor on RemotePluginServer

* refactor: unify local runtime lifetime and sperate init environment process

* chore: add missing files

* stash

* refactor: local plugin lifetime control

* refactor: complete installation process of control panel

* refactor: adapt service layer to new controlpanel

* refactor: pluginManager.Install

* fix: add routine wrap to InstallServerless, avoid blocking main thread

* feat: reinstall serverless runtime

* chore: add comments to Reinstall and update confusing naming

* refactor: unify install plugin service

* refactor: add labels to debugging runtime

* refactor: add getters to plugin manager

* refactor: split install service to decode/install_task/install service

* ???

* refactor: adapt controllers

* refactor: session write

* refactor: session runtime

* Refine install task orchestration (#501)

* refactor: installing task

* refactor cluster management, decouple lifetime management and cluster

* fix cli test command

* fix: cleanup TODO comments and implement GracefulStop for instance

* feat: add logger to control panel

* fix: multiple nil references

* refactor: better lifetime control

* refactor: better cycle interval

* fix(LocalPluginRuntime): prevent returning err when it's not  error

* fix: avoid adding empty PipExtraArgs

* fix: missing errors in Environment init

* fix: add truncateMessage to avoid db explosion

* cleanup: better lifecycle management

* fix: init status at the beginning of installation

* optimize: GracefulStop for pluginInstance

* refactor: tests

* refactor: centralize routine labels (#504)

* cleanup: RoutineKey

* fix: init routine pool

* fix: correctly handle cluster register error

* fix: memory leak

* fix: add \n to instance write

* fix(installer.go): set success to true after succeed for defer func

* refactor

* fix: missing cwd in testutils

* fix: scaleup default runtime nums to 1 when testing

* fix: localruntime appconfig in testing module

* Update internal/core/local_runtime/load_balancing.go

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix: more efficiency implement in installer_local.go

* fix: returns after failing in onDebuggingRuntimeDisconnected

* fix: returns after failing in onDebuggingRuntimeDisconnected

* fix: splits tests

* refactor: naming

* refactor: manifest.VersionX

* fix: adapt SetDefault to tests

* fix: enforce use constants in DBType

* fix: generate

* fix: linter

* cleanup tests

* refactor: change  package to

* cleanup: useless codes

* Update internal/cluster/plugin.go

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* cleanup

* refactor: decouple connection_key management from debugging_time

* refactor: confused naming

* feat: recycle resources to adapt to https://github.com/langgenius/dify-plugin-daemon/pull/500

* refactor: confusing redirecting

* fix: support get serverless runtime

* fix: race condition in Launching

* fix: avoid ManifestValidate in first step of debugging handshake

* fix: adding ReleaseAllLocks to finalizers

* wtf: what a beautiful code

* refactor: rename Stream.Async to Stream.Process

* fix: kill process if daed instance was detected

* fix: correctly handle failures

* fix: consistence of difference interfaces

* fix: add stacktrace to panic

* fix: only trigger once  event

* fix: ensure plugin runtime was shutdown

* feat: cleanup install tasks

* fix: add scale logs

---------

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
2025-11-18 17:28:02 +08:00

116 lines
2.8 KiB
Go

package decoder
import (
"bytes"
"crypto/rsa"
"crypto/sha256"
"encoding/base64"
"os"
"path"
"strconv"
"strings"
"github.com/langgenius/dify-plugin-daemon/pkg/license/public_key"
"github.com/langgenius/dify-plugin-daemon/pkg/utils/encryption"
)
// VerifyPlugin is a function that verifies the signature of a plugin
// It takes a plugin decoder and verifies the signature with a bundled public key
func VerifyPlugin(decoder PluginDecoder) error {
var publicKeys []*rsa.PublicKey
// load official public key
officialPublicKey, err := encryption.LoadPublicKey(public_key.PUBLIC_KEY)
if err != nil {
return err
}
publicKeys = append(publicKeys, officialPublicKey)
// verify the plugin
return VerifyPluginWithPublicKeys(decoder, publicKeys)
}
// VerifyPluginWithPublicKeyPaths is a function that verifies the signature of a plugin
// It takes a plugin decoder and a list of public key paths to verify the signature
func VerifyPluginWithPublicKeyPaths(decoder PluginDecoder, publicKeyPaths []string) error {
var publicKeys []*rsa.PublicKey
// load official public key
officialPublicKey, err := encryption.LoadPublicKey(public_key.PUBLIC_KEY)
if err != nil {
return err
}
publicKeys = append(publicKeys, officialPublicKey)
// load keys provided in the arguments
for _, publicKeyPath := range publicKeyPaths {
// open file by trimming the spaces in path
keyBytes, err := os.ReadFile(strings.TrimSpace(publicKeyPath))
if err != nil {
return err
}
publicKey, err := encryption.LoadPublicKey(keyBytes)
if err != nil {
return err
}
publicKeys = append(publicKeys, publicKey)
}
return VerifyPluginWithPublicKeys(decoder, publicKeys)
}
// VerifyPluginWithPublicKeys is a function that verifies the signature of a plugin
// It takes a plugin decoder and a list of public keys to verify the signature
func VerifyPluginWithPublicKeys(decoder PluginDecoder, publicKeys []*rsa.PublicKey) error {
data := new(bytes.Buffer)
// read one by one
err := decoder.Walk(func(filename, dir string) error {
// read file bytes
file, err := decoder.ReadFile(path.Join(dir, filename))
if err != nil {
return err
}
hash := sha256.New()
hash.Write(file)
// write the hash into data
data.Write(hash.Sum(nil))
return nil
})
if err != nil {
return err
}
// get the signature
signature, err := decoder.Signature()
if err != nil {
return err
}
// get the time
createdAt, err := decoder.CreateTime()
if err != nil {
return err
}
// write the time into data
data.Write([]byte(strconv.FormatInt(createdAt, 10)))
sigBytes, err := base64.StdEncoding.DecodeString(signature)
if err != nil {
return err
}
// verify signature
var lastErr error
for _, publicKey := range publicKeys {
lastErr = encryption.VerifySign(publicKey, data.Bytes(), sigBytes)
if lastErr == nil {
return nil
}
}
return lastErr
}