2017-06-05 14:37:29 +00:00
|
|
|
// Copyright 2017 clair authors
|
|
|
|
//
|
|
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
// you may not use this file except in compliance with the License.
|
|
|
|
// You may obtain a copy of the License at
|
|
|
|
//
|
|
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
//
|
|
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
// See the License for the specific language governing permissions and
|
|
|
|
// limitations under the License.
|
|
|
|
|
2017-08-16 21:26:53 +00:00
|
|
|
package v3
|
2017-06-05 14:37:29 +00:00
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
|
|
|
|
"golang.org/x/net/context"
|
|
|
|
"google.golang.org/grpc/codes"
|
|
|
|
"google.golang.org/grpc/status"
|
|
|
|
|
|
|
|
"github.com/coreos/clair"
|
2017-08-16 21:26:53 +00:00
|
|
|
pb "github.com/coreos/clair/api/v3/clairpb"
|
2017-06-05 14:37:29 +00:00
|
|
|
"github.com/coreos/clair/database"
|
2019-02-22 16:37:51 +00:00
|
|
|
"github.com/coreos/clair/ext/imagefmt"
|
2017-06-05 14:37:29 +00:00
|
|
|
"github.com/coreos/clair/pkg/commonerr"
|
2018-09-07 20:12:19 +00:00
|
|
|
"github.com/coreos/clair/pkg/pagination"
|
2017-06-05 14:37:29 +00:00
|
|
|
)
|
|
|
|
|
2019-02-20 22:14:51 +00:00
|
|
|
func newRPCErrorWithClairError(code codes.Code, err error) error {
|
|
|
|
return status.Errorf(code, "clair error reason: '%s'", err.Error())
|
|
|
|
}
|
|
|
|
|
2017-06-05 14:37:29 +00:00
|
|
|
// NotificationServer implements NotificationService interface for serving RPC.
|
|
|
|
type NotificationServer struct {
|
2017-07-12 21:04:05 +00:00
|
|
|
Store database.Datastore
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// AncestryServer implements AncestryService interface for serving RPC.
|
|
|
|
type AncestryServer struct {
|
|
|
|
Store database.Datastore
|
|
|
|
}
|
|
|
|
|
2018-08-30 19:09:24 +00:00
|
|
|
// StatusServer implements StatusService interface for serving RPC.
|
|
|
|
type StatusServer struct {
|
|
|
|
Store database.Datastore
|
|
|
|
}
|
|
|
|
|
|
|
|
// GetStatus implements getting the current status of Clair via the Clair service.
|
|
|
|
func (s *StatusServer) GetStatus(ctx context.Context, req *pb.GetStatusRequest) (*pb.GetStatusResponse, error) {
|
2018-09-07 15:31:35 +00:00
|
|
|
clairStatus, err := GetClairStatus(s.Store)
|
|
|
|
if err != nil {
|
2018-08-30 19:09:24 +00:00
|
|
|
return nil, status.Error(codes.Internal, err.Error())
|
|
|
|
}
|
2018-09-07 15:31:35 +00:00
|
|
|
|
|
|
|
return &pb.GetStatusResponse{Status: clairStatus}, nil
|
2018-08-30 19:09:24 +00:00
|
|
|
}
|
|
|
|
|
2017-06-05 14:37:29 +00:00
|
|
|
// PostAncestry implements posting an ancestry via the Clair gRPC service.
|
|
|
|
func (s *AncestryServer) PostAncestry(ctx context.Context, req *pb.PostAncestryRequest) (*pb.PostAncestryResponse, error) {
|
2019-02-20 22:14:51 +00:00
|
|
|
blobFormat := req.GetFormat()
|
|
|
|
if !imagefmt.IsSupported(blobFormat) {
|
|
|
|
return nil, status.Error(codes.InvalidArgument, "image blob format is not supported")
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2019-02-20 22:14:51 +00:00
|
|
|
clairStatus, err := GetClairStatus(s.Store)
|
|
|
|
if err != nil {
|
|
|
|
return nil, status.Error(codes.Internal, err.Error())
|
|
|
|
}
|
|
|
|
|
2019-02-22 16:37:51 +00:00
|
|
|
// check if the ancestry is already processed; if not we build the ancestry again.
|
2019-02-20 22:14:51 +00:00
|
|
|
layerHashes := make([]string, len(req.Layers))
|
|
|
|
for i, layer := range req.Layers {
|
|
|
|
layerHashes[i] = layer.GetHash()
|
2017-07-12 21:04:05 +00:00
|
|
|
}
|
|
|
|
|
2019-02-20 22:14:51 +00:00
|
|
|
found, err := clair.IsAncestryCached(s.Store, req.AncestryName, layerHashes)
|
|
|
|
if err != nil {
|
|
|
|
return nil, newRPCErrorWithClairError(codes.Internal, err)
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2019-02-20 22:14:51 +00:00
|
|
|
if found {
|
|
|
|
return &pb.PostAncestryResponse{Status: clairStatus}, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
builder := clair.NewAncestryBuilder(clair.EnabledDetectors())
|
|
|
|
for _, layer := range req.Layers {
|
2017-06-05 14:37:29 +00:00
|
|
|
if layer == nil {
|
2017-07-12 21:04:05 +00:00
|
|
|
err := status.Error(codes.InvalidArgument, "ancestry layer is invalid")
|
|
|
|
return nil, err
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
if layer.GetHash() == "" {
|
|
|
|
return nil, status.Error(codes.InvalidArgument, "ancestry layer hash should not be empty")
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
if layer.GetPath() == "" {
|
|
|
|
return nil, status.Error(codes.InvalidArgument, "ancestry layer path should not be empty")
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2019-02-20 22:14:51 +00:00
|
|
|
// TODO(sidac): make AnalyzeLayer to be async to ensure
|
|
|
|
// non-blocking downloads.
|
|
|
|
// We'll need to deal with two layers post by the same or different
|
|
|
|
// requests that may have the same hash. In that case, since every
|
|
|
|
// layer/feature/namespace is unique in the database, it may introduce
|
|
|
|
// deadlock.
|
|
|
|
clairLayer, err := clair.AnalyzeLayer(ctx, s.Store, layer.Hash, req.Format, layer.Path, layer.Headers)
|
|
|
|
if err != nil {
|
|
|
|
return nil, newRPCErrorWithClairError(codes.Internal, err)
|
|
|
|
}
|
2017-06-05 14:37:29 +00:00
|
|
|
|
2019-02-20 22:14:51 +00:00
|
|
|
builder.AddLeafLayer(clairLayer)
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2019-02-20 22:14:51 +00:00
|
|
|
if err := clair.SaveAncestry(s.Store, builder.Ancestry(req.AncestryName)); err != nil {
|
|
|
|
return nil, newRPCErrorWithClairError(codes.Internal, err)
|
2017-07-12 21:04:05 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
return &pb.PostAncestryResponse{Status: clairStatus}, nil
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
// GetAncestry implements retrieving an ancestry via the Clair gRPC service.
|
|
|
|
func (s *AncestryServer) GetAncestry(ctx context.Context, req *pb.GetAncestryRequest) (*pb.GetAncestryResponse, error) {
|
2018-09-07 15:31:35 +00:00
|
|
|
name := req.GetAncestryName()
|
2018-09-05 15:34:06 +00:00
|
|
|
if name == "" {
|
2017-07-12 21:04:05 +00:00
|
|
|
return nil, status.Errorf(codes.InvalidArgument, "ancestry name should not be empty")
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
tx, err := s.Store.Begin()
|
|
|
|
if err != nil {
|
|
|
|
return nil, status.Error(codes.Internal, err.Error())
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
2018-09-07 15:31:35 +00:00
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
defer tx.Rollback()
|
2017-06-05 14:37:29 +00:00
|
|
|
|
2018-09-07 15:31:35 +00:00
|
|
|
ancestry, ok, err := tx.FindAncestry(name)
|
|
|
|
if err != nil {
|
|
|
|
return nil, status.Error(codes.Internal, err.Error())
|
|
|
|
}
|
2017-07-12 21:04:05 +00:00
|
|
|
|
2018-09-07 15:31:35 +00:00
|
|
|
if !ok {
|
|
|
|
return nil, status.Error(codes.NotFound, fmt.Sprintf("requested ancestry '%s' is not found", req.GetAncestryName()))
|
|
|
|
}
|
2017-06-05 14:37:29 +00:00
|
|
|
|
2018-09-07 15:31:35 +00:00
|
|
|
pbAncestry := &pb.GetAncestryResponse_Ancestry{
|
2018-09-20 19:39:10 +00:00
|
|
|
Name: ancestry.Name,
|
|
|
|
Detectors: pb.DetectorsFromDatabaseModel(ancestry.By),
|
2018-09-07 15:31:35 +00:00
|
|
|
}
|
2018-09-05 15:34:06 +00:00
|
|
|
|
2018-09-07 15:31:35 +00:00
|
|
|
for _, layer := range ancestry.Layers {
|
|
|
|
pbLayer, err := GetPbAncestryLayer(tx, layer)
|
2018-09-05 15:34:06 +00:00
|
|
|
if err != nil {
|
2018-09-07 15:31:35 +00:00
|
|
|
return nil, err
|
2017-07-12 21:04:05 +00:00
|
|
|
}
|
2018-09-07 15:31:35 +00:00
|
|
|
|
|
|
|
pbAncestry.Layers = append(pbAncestry.Layers, pbLayer)
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2018-09-07 15:31:35 +00:00
|
|
|
pbClairStatus, err := GetClairStatus(s.Store)
|
2017-06-05 14:37:29 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, status.Error(codes.Internal, err.Error())
|
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
return &pb.GetAncestryResponse{
|
2018-09-07 15:31:35 +00:00
|
|
|
Status: pbClairStatus,
|
|
|
|
Ancestry: pbAncestry,
|
2017-07-12 21:04:05 +00:00
|
|
|
}, nil
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
// GetNotification implements retrieving a notification via the Clair gRPC
|
2017-06-05 14:37:29 +00:00
|
|
|
// service.
|
2017-07-12 21:04:05 +00:00
|
|
|
func (s *NotificationServer) GetNotification(ctx context.Context, req *pb.GetNotificationRequest) (*pb.GetNotificationResponse, error) {
|
2017-06-05 14:37:29 +00:00
|
|
|
if req.GetName() == "" {
|
2017-07-12 21:04:05 +00:00
|
|
|
return nil, status.Error(codes.InvalidArgument, "notification name should not be empty")
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
if req.GetLimit() <= 0 {
|
|
|
|
return nil, status.Error(codes.InvalidArgument, "notification page limit should not be empty or less than 1")
|
|
|
|
}
|
|
|
|
|
|
|
|
tx, err := s.Store.Begin()
|
|
|
|
if err != nil {
|
2017-06-05 14:37:29 +00:00
|
|
|
return nil, status.Error(codes.Internal, err.Error())
|
|
|
|
}
|
2017-07-12 21:04:05 +00:00
|
|
|
defer tx.Rollback()
|
2017-06-05 14:37:29 +00:00
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
dbNotification, ok, err := tx.FindVulnerabilityNotification(
|
|
|
|
req.GetName(),
|
|
|
|
int(req.GetLimit()),
|
2018-09-07 20:12:19 +00:00
|
|
|
pagination.Token(req.GetOldVulnerabilityPage()),
|
|
|
|
pagination.Token(req.GetNewVulnerabilityPage()),
|
2017-07-12 21:04:05 +00:00
|
|
|
)
|
2017-06-05 14:37:29 +00:00
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, status.Error(codes.Internal, err.Error())
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
if !ok {
|
|
|
|
return nil, status.Error(codes.NotFound, fmt.Sprintf("requested notification '%s' is not found", req.GetName()))
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
notification, err := pb.NotificationFromDatabaseModel(dbNotification)
|
|
|
|
if err != nil {
|
|
|
|
return nil, status.Error(codes.Internal, err.Error())
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
return &pb.GetNotificationResponse{Notification: notification}, nil
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
// MarkNotificationAsRead implements deleting a notification via the Clair gRPC
|
|
|
|
// service.
|
2018-04-23 19:36:52 +00:00
|
|
|
func (s *NotificationServer) MarkNotificationAsRead(ctx context.Context, req *pb.MarkNotificationAsReadRequest) (*pb.MarkNotificationAsReadResponse, error) {
|
2017-07-12 21:04:05 +00:00
|
|
|
if req.GetName() == "" {
|
|
|
|
return nil, status.Error(codes.InvalidArgument, "notification name should not be empty")
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
tx, err := s.Store.Begin()
|
|
|
|
if err != nil {
|
|
|
|
return nil, status.Error(codes.Internal, err.Error())
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
defer tx.Rollback()
|
|
|
|
err = tx.DeleteNotification(req.GetName())
|
|
|
|
if err == commonerr.ErrNotFound {
|
|
|
|
return nil, status.Error(codes.NotFound, "requested notification \""+req.GetName()+"\" is not found")
|
|
|
|
} else if err != nil {
|
|
|
|
return nil, status.Error(codes.Internal, err.Error())
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2017-07-12 21:04:05 +00:00
|
|
|
if err := tx.Commit(); err != nil {
|
|
|
|
return nil, status.Error(codes.Internal, err.Error())
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|
|
|
|
|
2018-04-23 19:36:52 +00:00
|
|
|
return &pb.MarkNotificationAsReadResponse{}, nil
|
2017-06-05 14:37:29 +00:00
|
|
|
}
|