Merge origin/codex/portable-deployment into feat/docker-local-deploy
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream, security hardening, CI multiarch) mantenendo le fix portal-specific: - backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream' - Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g) perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro. - config.test.ts: preso Codex (superset) Verificato: tsc clean, 132/132 vitest.
This commit is contained in:
+7
-1
@@ -34,6 +34,7 @@ export function buildApp(config: AppConfig, deps?: BuildAppDeps): FastifyInstanc
|
||||
thtBin: config.thtBin,
|
||||
harnessDir: config.harnessDir,
|
||||
configPath: process.env.THT_CONFIG ?? "config/tht.yaml",
|
||||
dataRoot: config.dataRoot,
|
||||
});
|
||||
const mgr = deps?.mgr ?? new PiProcessManager(config, deps?.spawnFn ? { spawnFn: deps.spawnFn } : undefined);
|
||||
const hub = new SseHub();
|
||||
@@ -41,7 +42,12 @@ export function buildApp(config: AppConfig, deps?: BuildAppDeps): FastifyInstanc
|
||||
const listModels = deps?.listModels ?? createPiModelLister(config);
|
||||
const getSettings = deps?.getSettings ?? (() => effectiveSettings(config, loadSettings(config)));
|
||||
|
||||
app.addHook("preHandler", authPreHandler(config.authMode));
|
||||
const authenticate = authPreHandler(config.authMode);
|
||||
app.addHook("preHandler", async (req, reply) => {
|
||||
// Process readiness is intentionally unauthenticated for local container/proxy probes.
|
||||
if (req.url === "/health") return;
|
||||
return authenticate(req, reply);
|
||||
});
|
||||
app.get("/health", async () => ({ status: "ok" }));
|
||||
sessionRoutes(app, {
|
||||
mgr, tht: tht as ThtRunner, hub, getSettings,
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
import type { FastifyRequest, FastifyReply } from "fastify";
|
||||
|
||||
export function authPreHandler(mode: "none" | "mock" | "oidc") {
|
||||
export function authPreHandler(mode: "none" | "mock" | "upstream") {
|
||||
return async (req: FastifyRequest, reply: FastifyReply) => {
|
||||
if (mode === "none") {
|
||||
(req as any).user = { id: "dev@local" };
|
||||
@@ -9,8 +9,11 @@ export function authPreHandler(mode: "none" | "mock" | "oidc") {
|
||||
id: (req.headers["x-mock-user"] as string) ?? "mock",
|
||||
};
|
||||
} else {
|
||||
reply.code(501);
|
||||
throw new Error("OIDC non configurato (MVP: usa none/mock)");
|
||||
const id = req.headers["x-authenticated-user"];
|
||||
if (typeof id !== "string" || id.trim() === "") {
|
||||
return reply.code(401).send({ error: "authenticated upstream identity required" });
|
||||
}
|
||||
(req as any).user = { id };
|
||||
}
|
||||
};
|
||||
}
|
||||
|
||||
+40
-2
@@ -1,22 +1,60 @@
|
||||
import path from "node:path";
|
||||
|
||||
export interface AppConfig {
|
||||
host: string; port: number; harnessDir: string; thtBin: string; piBin: string;
|
||||
authMode: "none" | "mock" | "oidc";
|
||||
authMode: "none" | "mock" | "upstream";
|
||||
defaults: { provider?: string; model?: string; thinking?: string };
|
||||
maxPiProcesses: number;
|
||||
settingsFile: string;
|
||||
dataRoot?: string;
|
||||
ollamaEnsureTimeoutMs: number;
|
||||
secretsFile?: string;
|
||||
secretFiles: Readonly<Record<string, string | undefined>>;
|
||||
modelApiKeyFile?: string;
|
||||
}
|
||||
export function loadConfig(env: Record<string, string | undefined>): AppConfig {
|
||||
const authMode = env.AUTH_MODE ?? "none";
|
||||
if (!(["none", "mock", "upstream"] as const).includes(authMode as AppConfig["authMode"])) {
|
||||
throw new Error(`unsupported AUTH_MODE=${authMode}; use none, mock, or upstream`);
|
||||
}
|
||||
if (env.THOTH_PUBLIC_EXPOSURE === "true" && authMode !== "upstream") {
|
||||
throw new Error("public exposure requires AUTH_MODE=upstream behind a trusted proxy");
|
||||
}
|
||||
const modelApiKeyFile = env.THT_MODEL_API_KEY_FILE;
|
||||
if (modelApiKeyFile !== undefined && (
|
||||
modelApiKeyFile.trim() !== modelApiKeyFile
|
||||
|| modelApiKeyFile.length === 0
|
||||
|| modelApiKeyFile.includes("\0")
|
||||
|| !path.isAbsolute(modelApiKeyFile)
|
||||
)) {
|
||||
throw new Error("model credential configuration is invalid");
|
||||
}
|
||||
const secretsFile = env.THT_SECRETS_FILE;
|
||||
if (secretsFile !== undefined && (
|
||||
secretsFile.trim() !== secretsFile || secretsFile.length === 0 || secretsFile.includes("\0")
|
||||
|| !path.isAbsolute(secretsFile)
|
||||
)) throw new Error("secret bundle configuration is invalid");
|
||||
const secretFiles: Record<string, string | undefined> = {};
|
||||
for (const name of [
|
||||
"THT_MODEL_API_KEY_SECRET_FILE", "THT_DWH_API_KEY_SECRET_FILE", "THT_VEC_API_KEY_SECRET_FILE",
|
||||
"THT_VEC_WRITE_API_KEY_SECRET_FILE", "THT_CA_SECRET_FILE", "THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE",
|
||||
"THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE", "THT_VECTOR_READER_PASSWORD_SECRET_FILE",
|
||||
"THT_VECTOR_WRITER_PASSWORD_SECRET_FILE",
|
||||
]) secretFiles[name] = env[name];
|
||||
return {
|
||||
host: env.HOST ?? "127.0.0.1",
|
||||
port: Number(env.PORT ?? 8787),
|
||||
harnessDir: env.THT_HARNESS_DIR ?? "../harness",
|
||||
thtBin: env.THT_BIN ?? "tht",
|
||||
piBin: env.PI_BIN ?? "pi",
|
||||
authMode: (env.AUTH_MODE as AppConfig["authMode"]) ?? "none",
|
||||
authMode: authMode as AppConfig["authMode"],
|
||||
defaults: { provider: env.PI_PROVIDER, model: env.PI_MODEL, thinking: env.PI_THINKING },
|
||||
maxPiProcesses: Number(env.MAX_PI_PROCESSES ?? 4),
|
||||
settingsFile: env.SETTINGS_FILE ?? "data/settings.json",
|
||||
dataRoot: env.THT_DATA_ROOT,
|
||||
ollamaEnsureTimeoutMs: Number(env.OLLAMA_ENSURE_TIMEOUT_MS ?? 60000),
|
||||
secretsFile,
|
||||
secretFiles,
|
||||
modelApiKeyFile,
|
||||
};
|
||||
}
|
||||
|
||||
@@ -0,0 +1,137 @@
|
||||
import {
|
||||
closeSync, constants, fstatSync, lstatSync, openSync, readFileSync,
|
||||
type Stats,
|
||||
} from "node:fs";
|
||||
|
||||
/** Keys accepted by the deployment bundle. Keep this list intentionally explicit. */
|
||||
export const SECRET_BUNDLE_KEYS = Object.freeze([
|
||||
"THT_MODEL_API_KEY", "THT_DWH_API_KEY", "THT_VEC_API_KEY", "THT_VEC_WRITE_API_KEY",
|
||||
"THT_CA", "THT_SSL_CA", "THT_VECTOR_BOOTSTRAP_PASSWORD", "THT_VECTOR_MIGRATOR_PASSWORD",
|
||||
"THT_VECTOR_READER_PASSWORD", "THT_VECTOR_WRITER_PASSWORD", "PI_PROVIDER_API_KEY",
|
||||
] as const);
|
||||
|
||||
const ALLOWED = new Set<string>(SECRET_BUNDLE_KEYS);
|
||||
const LEGACY_FILES: Readonly<Record<string, string>> = {
|
||||
THT_MODEL_API_KEY: "THT_MODEL_API_KEY_SECRET_FILE",
|
||||
THT_DWH_API_KEY: "THT_DWH_API_KEY_SECRET_FILE",
|
||||
THT_VEC_API_KEY: "THT_VEC_API_KEY_SECRET_FILE",
|
||||
THT_VEC_WRITE_API_KEY: "THT_VEC_WRITE_API_KEY_SECRET_FILE",
|
||||
THT_CA: "THT_CA_SECRET_FILE",
|
||||
THT_SSL_CA: "THT_CA_SECRET_FILE",
|
||||
THT_VECTOR_BOOTSTRAP_PASSWORD: "THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE",
|
||||
THT_VECTOR_MIGRATOR_PASSWORD: "THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE",
|
||||
THT_VECTOR_READER_PASSWORD: "THT_VECTOR_READER_PASSWORD_SECRET_FILE",
|
||||
THT_VECTOR_WRITER_PASSWORD: "THT_VECTOR_WRITER_PASSWORD_SECRET_FILE",
|
||||
};
|
||||
|
||||
const MAX_BUNDLE_BYTES = 64 * 1024;
|
||||
const MAX_LINE_BYTES = 16 * 1024;
|
||||
|
||||
export interface SecretBundleConfig {
|
||||
secretsFile?: string;
|
||||
secretFiles?: Readonly<Record<string, string | undefined>>;
|
||||
/** Accepted for callers that pass the raw process environment. */
|
||||
THT_SECRETS_FILE?: string;
|
||||
}
|
||||
|
||||
/** Injectable filesystem boundary used by the race-condition tests. */
|
||||
export interface SecretBundleFsOps {
|
||||
lstat(path: string): Stats;
|
||||
open(path: string, flags: number): number;
|
||||
fstat(fd: number): Stats;
|
||||
read(fd: number): string;
|
||||
close(fd: number): void;
|
||||
}
|
||||
|
||||
const realFs: SecretBundleFsOps = {
|
||||
lstat: lstatSync,
|
||||
open: openSync,
|
||||
fstat: fstatSync,
|
||||
read: (fd) => readFileSync(fd, "utf8"),
|
||||
close: closeSync,
|
||||
};
|
||||
|
||||
function unavailable(): Error { return new Error("secret bundle is unavailable"); }
|
||||
|
||||
function secureStat(info: Stats, docker: boolean): boolean {
|
||||
const mode = info.mode & 0o777;
|
||||
if (!info.isFile() || info.isSymbolicLink() || info.nlink !== 1 || info.size > MAX_BUNDLE_BYTES) return false;
|
||||
if (docker) {
|
||||
return (info.uid === 0 && mode === 0o444)
|
||||
|| (info.uid === (process.getuid?.() ?? info.uid) && (mode === 0o400 || mode === 0o600));
|
||||
}
|
||||
return info.uid === (process.getuid?.() ?? info.uid) && (mode === 0o400 || mode === 0o600);
|
||||
}
|
||||
|
||||
function readSecure(file: string, fs: SecretBundleFsOps): string {
|
||||
let fd: number | undefined;
|
||||
try {
|
||||
if (!file || file.trim() !== file || file.includes("\0")) throw unavailable();
|
||||
const docker = file.startsWith("/run/secrets/") && !file.slice("/run/secrets/".length).includes("/");
|
||||
if (file.startsWith("/run/secrets/") && !docker) throw unavailable();
|
||||
if (docker) {
|
||||
const parent = fs.lstat("/run/secrets");
|
||||
if (!parent.isDirectory() || parent.uid !== 0 || (parent.mode & 0o022) !== 0) throw unavailable();
|
||||
}
|
||||
const before = fs.lstat(file);
|
||||
if (!secureStat(before, docker)) throw unavailable();
|
||||
fd = fs.open(file, constants.O_RDONLY | constants.O_NOFOLLOW);
|
||||
const opened = fs.fstat(fd);
|
||||
if (!secureStat(opened, docker) || before.dev !== opened.dev || before.ino !== opened.ino) throw unavailable();
|
||||
return fs.read(fd);
|
||||
} catch {
|
||||
throw unavailable();
|
||||
} finally {
|
||||
if (fd !== undefined) try { fs.close(fd); } catch { /* sanitized by design */ }
|
||||
}
|
||||
}
|
||||
|
||||
function parseBundle(text: string): ReadonlyMap<string, string> {
|
||||
const values = new Map<string, string>();
|
||||
const lines = text.split("\n");
|
||||
for (const raw of lines) {
|
||||
if (raw.length > MAX_LINE_BYTES) throw unavailable();
|
||||
const line = raw.endsWith("\r") ? raw.slice(0, -1) : raw;
|
||||
const trimmed = line.trim();
|
||||
if (!trimmed || trimmed.startsWith("#")) continue;
|
||||
const match = /^([A-Z][A-Z0-9_]*)=(.*)$/.exec(line);
|
||||
if (!match) throw unavailable();
|
||||
const [, key, value] = match;
|
||||
if (!ALLOWED.has(key) || values.has(key) || value.length === 0 || /[\r\n]/.test(value)) {
|
||||
throw unavailable();
|
||||
}
|
||||
values.set(key, value);
|
||||
}
|
||||
return values;
|
||||
}
|
||||
|
||||
export function loadSecretBundle(file: string): ReadonlyMap<string, string> {
|
||||
return loadSecretBundleWithFs(file, realFs);
|
||||
}
|
||||
|
||||
/** Same loader with an injectable filesystem boundary; useful for TOCTOU tests. */
|
||||
export function loadSecretBundleWithFs(file: string, fs: SecretBundleFsOps): ReadonlyMap<string, string> {
|
||||
try { return parseBundle(readSecure(file, fs)); } catch { throw unavailable(); }
|
||||
}
|
||||
|
||||
/** Resolve a value from the bundle, with the pre-bundle *_SECRET_FILE fallback. */
|
||||
export function secretValue(config: SecretBundleConfig, key: string): string | undefined {
|
||||
const bundlePath = config.secretsFile ?? config.THT_SECRETS_FILE;
|
||||
if (bundlePath) {
|
||||
const found = loadSecretBundle(bundlePath).get(key);
|
||||
if (found !== undefined) return found;
|
||||
}
|
||||
const legacyName = LEGACY_FILES[key];
|
||||
const legacyPath = legacyName
|
||||
? config.secretFiles?.[legacyName] ?? (() => {
|
||||
const raw = (config as unknown as Record<string, unknown>)[legacyName];
|
||||
return typeof raw === "string" ? raw : undefined;
|
||||
})()
|
||||
: undefined;
|
||||
if (!legacyPath) return undefined;
|
||||
const value = readSecure(legacyPath, realFs);
|
||||
if (!value || /\s/.test(value)) throw unavailable();
|
||||
return value;
|
||||
}
|
||||
|
||||
export function legacySecretEnvNames(): Readonly<Record<string, string>> { return LEGACY_FILES; }
|
||||
@@ -1,7 +1,8 @@
|
||||
import { spawn as nodeSpawn, type ChildProcessWithoutNullStreams } from "node:child_process";
|
||||
import { join } from "node:path";
|
||||
import type { AppConfig } from "../config.js";
|
||||
import { RpcClient } from "../rpc/rpc-client.js";
|
||||
import { buildPiChildEnv } from "./provider-credentials.js";
|
||||
import { secretValue } from "../config/secret-bundle.js";
|
||||
|
||||
export interface PiModel {
|
||||
provider: string;
|
||||
@@ -11,7 +12,11 @@ export interface PiModel {
|
||||
}
|
||||
|
||||
interface Opts {
|
||||
spawnFn?: () => ChildProcessWithoutNullStreams;
|
||||
spawnFn?: (
|
||||
command: string,
|
||||
args: string[],
|
||||
options: { cwd: string; env: NodeJS.ProcessEnv },
|
||||
) => ChildProcessWithoutNullStreams;
|
||||
ttlMs?: number;
|
||||
nowMs?: () => number;
|
||||
}
|
||||
@@ -24,22 +29,21 @@ interface Opts {
|
||||
export function createPiModelLister(cfg: AppConfig, opts: Opts = {}): () => Promise<PiModel[]> {
|
||||
const ttlMs = opts.ttlMs ?? 60_000;
|
||||
const now = opts.nowMs ?? (() => Date.now());
|
||||
const spawnFn =
|
||||
opts.spawnFn ??
|
||||
(() => {
|
||||
const harnessVenvBin = join(cfg.harnessDir, ".venv", "bin");
|
||||
return nodeSpawn(cfg.piBin, ["--mode", "rpc"], {
|
||||
cwd: cfg.harnessDir,
|
||||
env: { ...process.env, PATH: `${harnessVenvBin}:${process.env.PATH ?? ""}` },
|
||||
}) as ChildProcessWithoutNullStreams;
|
||||
});
|
||||
const spawnFn = opts.spawnFn ?? nodeSpawn;
|
||||
|
||||
let cache: { at: number; models: PiModel[] } | null = null;
|
||||
|
||||
return async function listModels(): Promise<PiModel[]> {
|
||||
if (cache && now() - cache.at < ttlMs) return cache.models;
|
||||
|
||||
const child = spawnFn();
|
||||
const env = buildPiChildEnv({
|
||||
provider: cfg.defaults.provider,
|
||||
credentialValue: secretValue(cfg, "THT_MODEL_API_KEY"),
|
||||
credentialFile: cfg.modelApiKeyFile,
|
||||
});
|
||||
delete env.THT_DATA_ROOT;
|
||||
if (cfg.dataRoot !== undefined) env.THT_DATA_ROOT = cfg.dataRoot;
|
||||
const child = spawnFn(cfg.piBin, ["--mode", "rpc"], { cwd: cfg.harnessDir, env });
|
||||
child.stderr.resume();
|
||||
const rpc = new RpcClient(child);
|
||||
try {
|
||||
|
||||
@@ -1,9 +1,10 @@
|
||||
import { spawn as nodeSpawn, type ChildProcessWithoutNullStreams } from "node:child_process";
|
||||
import { join } from "node:path";
|
||||
import type { AppConfig } from "../config.js";
|
||||
import { RpcClient } from "../rpc/rpc-client.js";
|
||||
import { SessionBridge } from "../bridge/session-bridge.js";
|
||||
import type { ThtRunner } from "../tht/tht-runner.js";
|
||||
import { buildPiChildEnv, canonicalPiProvider } from "./provider-credentials.js";
|
||||
import { secretValue } from "../config/secret-bundle.js";
|
||||
|
||||
export interface SessionRuntime {
|
||||
rpc: RpcClient;
|
||||
@@ -11,46 +12,65 @@ export interface SessionRuntime {
|
||||
child: ChildProcessWithoutNullStreams;
|
||||
}
|
||||
|
||||
/** Injected test double signature: produce a child process, no args needed. */
|
||||
type SpawnFn = () => ChildProcessWithoutNullStreams;
|
||||
/** Injectable child-process boundary; callbacks may ignore arguments in simpler tests. */
|
||||
type SpawnFn = (
|
||||
command: string,
|
||||
args: string[],
|
||||
options: { cwd: string; env: NodeJS.ProcessEnv },
|
||||
) => ChildProcessWithoutNullStreams;
|
||||
|
||||
export class PiProcessManager {
|
||||
private runtimes = new Map<string, SessionRuntime>();
|
||||
private spawnFn: (sessionId: string, author: string) => ChildProcessWithoutNullStreams;
|
||||
private spawnFn: (
|
||||
sessionId: string, author: string, provider: string | undefined,
|
||||
) => ChildProcessWithoutNullStreams;
|
||||
|
||||
constructor(private cfg: AppConfig, opts?: { spawnFn?: SpawnFn }) {
|
||||
if (opts?.spawnFn) {
|
||||
this.spawnFn = () => opts.spawnFn!();
|
||||
this.spawnFn = (sessionId, author, provider) =>
|
||||
this.spawnPi(opts.spawnFn!, sessionId, author, provider);
|
||||
} else {
|
||||
this.spawnFn = (sessionId: string, author: string) => {
|
||||
const harnessVenvBin = join(cfg.harnessDir, ".venv", "bin");
|
||||
const env: NodeJS.ProcessEnv = {
|
||||
...process.env,
|
||||
THT_SESSION: sessionId,
|
||||
THT_AUTHOR: author,
|
||||
PATH: `${harnessVenvBin}:${process.env.PATH ?? ""}`,
|
||||
};
|
||||
// pi 0.73 (the @mariozechner rebrand) removed the `--approve` flag: rpc mode is
|
||||
// headless and runs tools without an approval gate, so passing it makes pi exit
|
||||
// with "Unknown option: --approve". Args are intentionally just `--mode rpc`.
|
||||
const child = nodeSpawn(cfg.piBin, ["--mode", "rpc"], {
|
||||
cwd: cfg.harnessDir,
|
||||
env,
|
||||
});
|
||||
// Drain stderr so the child's stderr buffer never blocks the process.
|
||||
child.stderr.resume();
|
||||
return child;
|
||||
};
|
||||
this.spawnFn = (sessionId, author, provider) =>
|
||||
this.spawnPi(nodeSpawn, sessionId, author, provider);
|
||||
}
|
||||
}
|
||||
|
||||
private spawnPi(
|
||||
spawnFn: SpawnFn, sessionId: string, author: string, provider: string | undefined,
|
||||
): ChildProcessWithoutNullStreams {
|
||||
const env = buildPiChildEnv({
|
||||
provider,
|
||||
credentialValue: secretValue(this.cfg, "THT_MODEL_API_KEY"),
|
||||
credentialFile: this.cfg.modelApiKeyFile,
|
||||
additions: { THT_SESSION: sessionId, THT_AUTHOR: author },
|
||||
});
|
||||
// The Thoth gate executes the deterministic `tht` CLI as a Pi tool. Give only
|
||||
// this managed session process the adapter values already loaded by the core
|
||||
// entrypoint; the generic provider helper continues to scrub them by default.
|
||||
for (const name of [
|
||||
"THT_DWH_API_KEY", "THT_VEC_API_KEY", "THT_VEC_WRITE_API_KEY", "THT_SSL_CA",
|
||||
] as const) {
|
||||
if (process.env[name] !== undefined) env[name] = process.env[name];
|
||||
}
|
||||
delete env.THT_DATA_ROOT;
|
||||
if (this.cfg.dataRoot !== undefined) env.THT_DATA_ROOT = this.cfg.dataRoot;
|
||||
// pi 0.73 removed `--approve`: rpc mode is headless and its argv is intentionally minimal.
|
||||
const child = spawnFn(this.cfg.piBin, ["--mode", "rpc"], {
|
||||
cwd: this.cfg.harnessDir,
|
||||
env,
|
||||
});
|
||||
// Drain stderr so the child's stderr buffer never blocks the process.
|
||||
child.stderr.resume?.();
|
||||
return child;
|
||||
}
|
||||
|
||||
count(): number { return this.runtimes.size; }
|
||||
|
||||
get(id: string): SessionRuntime | undefined { return this.runtimes.get(id); }
|
||||
|
||||
async spawnFor(
|
||||
sessionId: string,
|
||||
o: { provider?: string; model?: string; thinking?: string; author?: string; mode?: "new" | "resume" },
|
||||
o: { provider?: string; model?: string; thinking?: string; author?: string; question?: string; mode?: "new" | "resume" },
|
||||
): Promise<SessionRuntime> {
|
||||
// Idempotent per session id: tear down any existing runtime for this id
|
||||
// first (before the cap check) so a resume/respawn neither leaks the old
|
||||
@@ -64,7 +84,8 @@ export class PiProcessManager {
|
||||
throw new Error("max Pi processes reached");
|
||||
}
|
||||
const author = o.author ?? "dev@local";
|
||||
const child = this.spawnFn(sessionId, author);
|
||||
const provider = canonicalPiProvider(o.provider ?? this.cfg.defaults.provider);
|
||||
const child = this.spawnFn(sessionId, author, provider);
|
||||
const rpc = new RpcClient(child);
|
||||
const bridge = new SessionBridge(rpc);
|
||||
const rt: SessionRuntime = { rpc, bridge, child };
|
||||
@@ -85,7 +106,6 @@ export class PiProcessManager {
|
||||
}
|
||||
});
|
||||
|
||||
const provider = o.provider ?? this.cfg.defaults.provider;
|
||||
const model = o.model ?? this.cfg.defaults.model;
|
||||
const thinking = o.thinking ?? this.cfg.defaults.thinking;
|
||||
|
||||
@@ -98,7 +118,7 @@ export class PiProcessManager {
|
||||
|
||||
const message = o.mode === "resume"
|
||||
? `/riprendi-sessione ${sessionId}`
|
||||
: `/nuova-domanda "kickoff"`;
|
||||
: `/nuova-domanda ${JSON.stringify(o.question ?? "")}`;
|
||||
rpc.send({ type: "prompt", message });
|
||||
return rt;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,162 @@
|
||||
import {
|
||||
closeSync, constants, fstatSync, lstatSync, openSync, readFileSync,
|
||||
type Stats,
|
||||
} from "node:fs";
|
||||
|
||||
/** Audited against @earendil-works/pi-ai 0.80.3 auth plus its locked AWS credential chain. */
|
||||
export const PI_0803_CREDENTIAL_ENV_NAMES = Object.freeze([
|
||||
"AI_GATEWAY_API_KEY", "ANTHROPIC_API_KEY", "ANTHROPIC_OAUTH_TOKEN", "ANT_LING_API_KEY",
|
||||
"AWS_ACCESS_KEY_ID", "AWS_BEARER_TOKEN_BEDROCK", "AWS_CONFIG_FILE",
|
||||
"AWS_CONTAINER_AUTHORIZATION_TOKEN", "AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE",
|
||||
"AWS_CONTAINER_CREDENTIALS_FULL_URI", "AWS_CONTAINER_CREDENTIALS_RELATIVE_URI", "AWS_PROFILE",
|
||||
"AWS_ROLE_ARN", "AWS_ROLE_SESSION_NAME", "AWS_SECRET_ACCESS_KEY", "AWS_SESSION_TOKEN",
|
||||
"AWS_SHARED_CREDENTIALS_FILE", "AWS_WEB_IDENTITY_TOKEN_FILE", "AZURE_OPENAI_API_KEY",
|
||||
"CEREBRAS_API_KEY", "CLOUDFLARE_ACCOUNT_ID", "CLOUDFLARE_API_KEY",
|
||||
"CLOUDFLARE_GATEWAY_ID", "COPILOT_GITHUB_TOKEN", "DEEPSEEK_API_KEY", "FIREWORKS_API_KEY",
|
||||
"GCLOUD_PROJECT", "GEMINI_API_KEY", "GOOGLE_APPLICATION_CREDENTIALS", "GOOGLE_CLOUD_API_KEY",
|
||||
"GOOGLE_CLOUD_LOCATION", "GOOGLE_CLOUD_PROJECT", "GROQ_API_KEY", "HF_TOKEN",
|
||||
"KIMI_API_KEY", "MINIMAX_API_KEY", "MINIMAX_CN_API_KEY", "MISTRAL_API_KEY",
|
||||
"MOONSHOT_API_KEY", "NVIDIA_API_KEY", "OPENCODE_API_KEY", "OPENAI_API_KEY",
|
||||
"OPENROUTER_API_KEY", "TOGETHER_API_KEY", "XAI_API_KEY", "XIAOMI_API_KEY",
|
||||
"XIAOMI_TOKEN_PLAN_AMS_API_KEY", "XIAOMI_TOKEN_PLAN_CN_API_KEY",
|
||||
"XIAOMI_TOKEN_PLAN_SGP_API_KEY", "ZAI_API_KEY", "ZAI_CODING_CN_API_KEY",
|
||||
]);
|
||||
|
||||
const PROVIDER_KEY_ENV: Readonly<Record<string, string>> = {
|
||||
"ant-ling": "ANT_LING_API_KEY",
|
||||
anthropic: "ANTHROPIC_API_KEY",
|
||||
cerebras: "CEREBRAS_API_KEY",
|
||||
deepseek: "DEEPSEEK_API_KEY", fireworks: "FIREWORKS_API_KEY",
|
||||
"github-copilot": "COPILOT_GITHUB_TOKEN", google: "GEMINI_API_KEY",
|
||||
"google-vertex": "GOOGLE_CLOUD_API_KEY", groq: "GROQ_API_KEY", huggingface: "HF_TOKEN",
|
||||
"kimi-coding": "KIMI_API_KEY", minimax: "MINIMAX_API_KEY", "minimax-cn": "MINIMAX_CN_API_KEY",
|
||||
mistral: "MISTRAL_API_KEY", moonshotai: "MOONSHOT_API_KEY", "moonshotai-cn": "MOONSHOT_API_KEY",
|
||||
nvidia: "NVIDIA_API_KEY", openai: "OPENAI_API_KEY", opencode: "OPENCODE_API_KEY",
|
||||
"opencode-go": "OPENCODE_API_KEY", openrouter: "OPENROUTER_API_KEY", together: "TOGETHER_API_KEY",
|
||||
"vercel-ai-gateway": "AI_GATEWAY_API_KEY", xai: "XAI_API_KEY", xiaomi: "XIAOMI_API_KEY",
|
||||
"xiaomi-token-plan-ams": "XIAOMI_TOKEN_PLAN_AMS_API_KEY",
|
||||
"xiaomi-token-plan-cn": "XIAOMI_TOKEN_PLAN_CN_API_KEY",
|
||||
"xiaomi-token-plan-sgp": "XIAOMI_TOKEN_PLAN_SGP_API_KEY", zai: "ZAI_API_KEY",
|
||||
"zai-coding-cn": "ZAI_CODING_CN_API_KEY",
|
||||
};
|
||||
const COMPOUND_PROVIDERS = new Set([
|
||||
"amazon-bedrock", "azure-openai-responses", "cloudflare-ai-gateway", "cloudflare-workers-ai",
|
||||
]);
|
||||
const LOCAL_PROVIDERS = new Set(["ollama", "lmstudio", "local", "aritmolab", "faux"]);
|
||||
|
||||
export function canonicalPiProvider(provider: string | undefined): string | undefined {
|
||||
const value = provider?.trim().toLowerCase();
|
||||
if (!value) return undefined;
|
||||
if (value === "gemini") return "google";
|
||||
return value;
|
||||
}
|
||||
|
||||
export interface CredentialFsOps {
|
||||
lstat(path: string): Stats;
|
||||
open(path: string, flags: number): number;
|
||||
fstat(fd: number): Stats;
|
||||
read(fd: number): string;
|
||||
close(fd: number): void;
|
||||
}
|
||||
const realFs: CredentialFsOps = {
|
||||
lstat: lstatSync, open: openSync, fstat: fstatSync,
|
||||
read: (fd) => readFileSync(fd, "utf8"), close: closeSync,
|
||||
};
|
||||
|
||||
function validSecretStat(info: Stats, docker: boolean): boolean {
|
||||
const mode = info.mode & 0o777;
|
||||
if (!info.isFile() || info.isSymbolicLink() || info.nlink !== 1 || info.size > 16_384) return false;
|
||||
if (docker) return info.uid === 0 && mode === 0o444;
|
||||
return info.uid === process.getuid?.() && (mode === 0o400 || mode === 0o600);
|
||||
}
|
||||
|
||||
function readCredential(file: string, fs: CredentialFsOps): string {
|
||||
let fd: number | undefined;
|
||||
try {
|
||||
const docker = file.startsWith("/run/secrets/") && !file.slice("/run/secrets/".length).includes("/");
|
||||
if (file.startsWith("/run/secrets/") && !docker) throw new Error();
|
||||
if (docker) {
|
||||
const parent = fs.lstat("/run/secrets");
|
||||
if (!parent.isDirectory() || parent.uid !== 0 || (parent.mode & 0o022) !== 0) throw new Error();
|
||||
}
|
||||
const before = fs.lstat(file);
|
||||
if (!validSecretStat(before, docker)) throw new Error();
|
||||
fd = fs.open(file, constants.O_RDONLY | constants.O_NOFOLLOW);
|
||||
const opened = fs.fstat(fd);
|
||||
if (!validSecretStat(opened, docker) || before.dev !== opened.dev || before.ino !== opened.ino) throw new Error();
|
||||
const value = fs.read(fd);
|
||||
if (!value || /\s/.test(value)) throw new Error();
|
||||
return value;
|
||||
} catch {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
} finally {
|
||||
if (fd !== undefined) {
|
||||
try { fs.close(fd); } catch { /* sanitized by design */ }
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
export function buildPiChildEnv(opts: {
|
||||
ambient?: NodeJS.ProcessEnv;
|
||||
provider?: string;
|
||||
credentialFile?: string;
|
||||
additions?: NodeJS.ProcessEnv;
|
||||
credentialValue?: string;
|
||||
fsOps?: CredentialFsOps;
|
||||
}): NodeJS.ProcessEnv {
|
||||
const env = { ...(opts.ambient ?? process.env), ...opts.additions };
|
||||
delete env.PI_PROVIDER_API_KEY;
|
||||
delete env.THT_SECRETS_FILE;
|
||||
delete env.THT_DWH_API_KEY;
|
||||
delete env.THT_VEC_API_KEY;
|
||||
delete env.THT_VEC_WRITE_API_KEY;
|
||||
delete env.THT_MODEL_API_KEY;
|
||||
delete env.THT_SSL_CA;
|
||||
delete env.THT_CA;
|
||||
delete env.THT_VECTOR_BOOTSTRAP_PASSWORD;
|
||||
delete env.THT_VECTOR_MIGRATOR_PASSWORD;
|
||||
delete env.THT_VECTOR_READER_PASSWORD;
|
||||
delete env.THT_VECTOR_WRITER_PASSWORD;
|
||||
delete env.THT_MODEL_API_KEY_FILE;
|
||||
delete env.THT_DWH_API_KEY_SECRET_FILE;
|
||||
delete env.THT_VEC_API_KEY_SECRET_FILE;
|
||||
delete env.THT_VEC_WRITE_API_KEY_SECRET_FILE;
|
||||
delete env.THT_CA_SECRET_FILE;
|
||||
delete env.THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE;
|
||||
delete env.THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE;
|
||||
delete env.THT_VECTOR_READER_PASSWORD_SECRET_FILE;
|
||||
delete env.THT_VECTOR_WRITER_PASSWORD_SECRET_FILE;
|
||||
delete env.THT_VECTOR_BOOTSTRAP_PASSWORD_FILE;
|
||||
delete env.THT_VECTOR_MIGRATOR_PASSWORD_FILE;
|
||||
delete env.THT_VECTOR_READER_PASSWORD_FILE;
|
||||
delete env.THT_VECTOR_WRITER_PASSWORD_FILE;
|
||||
delete env.THT_DWH_API_KEY_FILE;
|
||||
delete env.THT_VEC_API_KEY_FILE;
|
||||
delete env.THT_VEC_WRITE_API_KEY_FILE;
|
||||
delete env.THT_SSL_CA_FILE;
|
||||
for (const name of PI_0803_CREDENTIAL_ENV_NAMES) delete env[name];
|
||||
const provider = canonicalPiProvider(opts.provider);
|
||||
if (provider && COMPOUND_PROVIDERS.has(provider)) {
|
||||
throw new Error(
|
||||
"compound credential bundles are unsupported by THT_MODEL_API_KEY_FILE; "
|
||||
+ "dedicated provider configuration is required",
|
||||
);
|
||||
}
|
||||
if (provider && !LOCAL_PROVIDERS.has(provider)) {
|
||||
const envName = PROVIDER_KEY_ENV[provider];
|
||||
if (!envName || (!opts.credentialFile && opts.credentialValue === undefined)) {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
}
|
||||
if (opts.credentialValue !== undefined) {
|
||||
if (!opts.credentialValue || /\s/.test(opts.credentialValue)) {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
}
|
||||
env[envName] = opts.credentialValue;
|
||||
}
|
||||
else if (opts.credentialFile) env[envName] = readCredential(opts.credentialFile, opts.fsOps ?? realFs);
|
||||
else throw new Error("model provider credential is unavailable");
|
||||
} else if (opts.credentialFile && !provider) {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
}
|
||||
return env;
|
||||
}
|
||||
@@ -29,12 +29,13 @@ export function sessionRoutes(
|
||||
model: s.model,
|
||||
thinking: s.thinking,
|
||||
author: getUser(req).id,
|
||||
question: b.question,
|
||||
});
|
||||
rt.bridge.onClientEvent((e) => d.hub.publish(id, e.type, e));
|
||||
return { id };
|
||||
});
|
||||
app.get("/sessions", async () => d.tht.sessionList());
|
||||
app.get("/sessions/:id", async (req) => d.tht.sessionShow((req.params as any).id));
|
||||
app.get("/sessions", async () => d.tht.sessionList(d.getSettings().workspace));
|
||||
app.get("/sessions/:id", async (req) => d.tht.sessionShow((req.params as any).id, d.getSettings().workspace));
|
||||
app.post("/sessions/:id/response", async (req, reply) => {
|
||||
const id = (req.params as any).id;
|
||||
const rt = d.mgr.get(id);
|
||||
@@ -50,7 +51,7 @@ export function sessionRoutes(
|
||||
});
|
||||
app.post("/sessions/:id/resume", async (req, reply) => {
|
||||
const id = (req.params as any).id;
|
||||
const manifest = (await d.tht.sessionShow(id)) as { status?: string; archived?: boolean } | null;
|
||||
const manifest = (await d.tht.sessionShow(id, d.getSettings().workspace)) as { status?: string; archived?: boolean } | null;
|
||||
if (manifest?.status === "finalized" || manifest?.archived) {
|
||||
return reply.code(409).send({ error: "sessione in sola lettura (finalizzata o archiviata)" });
|
||||
}
|
||||
@@ -77,6 +78,9 @@ export function sessionRoutes(
|
||||
"Access-Control-Allow-Origin": origin,
|
||||
"Access-Control-Allow-Credentials": "true",
|
||||
});
|
||||
// Send the handshake immediately. Without this, Node waits for the first event body and
|
||||
// proxies/clients cannot establish an idle SSE subscription or inspect its headers.
|
||||
reply.raw.flushHeaders();
|
||||
const send = (event: string, data: object) => reply.raw.write(`event: ${event}\ndata: ${JSON.stringify(data)}\n\n`);
|
||||
const off = d.hub.subscribe(id, send, rt?.bridge.pendingWidget() ?? null);
|
||||
req.raw.on("close", off);
|
||||
@@ -100,7 +104,7 @@ export function sessionRoutes(
|
||||
app.delete("/sessions/:id", async (req, reply) => {
|
||||
const id = (req.params as any).id;
|
||||
d.mgr.teardown(id); // drop any live runtime before deleting on disk
|
||||
await d.tht.deleteSession(id);
|
||||
await d.tht.deleteSession(id, d.getSettings().workspace);
|
||||
return reply.code(204).send();
|
||||
});
|
||||
app.get("/sessions/:id/documents", async (req) => d.tht.documents((req.params as any).id));
|
||||
|
||||
@@ -6,6 +6,7 @@ export interface ThtConfig {
|
||||
thtBin: string;
|
||||
harnessDir: string;
|
||||
configPath: string;
|
||||
dataRoot?: string;
|
||||
}
|
||||
|
||||
export interface SessionRow {
|
||||
@@ -61,8 +62,12 @@ export class ThtRunner {
|
||||
|
||||
run(args: string[], workspace?: string): Promise<{ code: number; stdout: string; stderr: string }> {
|
||||
return new Promise((resolve) => {
|
||||
const env: NodeJS.ProcessEnv = { ...process.env };
|
||||
delete env.THT_DATA_ROOT;
|
||||
if (this.cfg.dataRoot !== undefined) env.THT_DATA_ROOT = this.cfg.dataRoot;
|
||||
const ch = spawn(this.cfg.thtBin, this.buildArgv(args, workspace), {
|
||||
cwd: this.cfg.harnessDir,
|
||||
env,
|
||||
});
|
||||
let stdout = "";
|
||||
let stderr = "";
|
||||
@@ -104,12 +109,12 @@ export class ThtRunner {
|
||||
return this.json<{ id: string }>(a, o.workspace);
|
||||
}
|
||||
|
||||
sessionList() {
|
||||
return this.json<SessionRow[]>(["session", "list", "--json"]);
|
||||
sessionList(workspace?: string) {
|
||||
return this.json<SessionRow[]>(["session", "list", "--json"], workspace);
|
||||
}
|
||||
|
||||
sessionShow(id: string) {
|
||||
return this.json<unknown>(["session", "show", id, "--json"]);
|
||||
sessionShow(id: string, workspace?: string) {
|
||||
return this.json<unknown>(["session", "show", id, "--json"], workspace);
|
||||
}
|
||||
|
||||
sqlPreview(id: string, p: { limit?: number; offset?: number }) {
|
||||
@@ -136,7 +141,10 @@ export class ThtRunner {
|
||||
setGroup(id: string, group: string) { return this.ok(["session", "set-group", id, "--group", group]); }
|
||||
archive(id: string) { return this.ok(["session", "archive", id]); }
|
||||
unarchive(id: string) { return this.ok(["session", "unarchive", id]); }
|
||||
deleteSession(id: string) { return this.ok(["session", "delete", id]); }
|
||||
async deleteSession(id: string, workspace?: string) {
|
||||
const { code, stderr } = await this.run(["session", "delete", id], workspace);
|
||||
if (code !== 0) throw new Error(`tht session delete exit ${code}: ${stderr.trim()}`);
|
||||
}
|
||||
documents(id: string) { return this.json<SessionDocument[]>(["session", "documents", id, "--json"]); }
|
||||
|
||||
async ollamaEnsure(workspace: string, timeoutSec: number): Promise<OllamaEnsureResult> {
|
||||
|
||||
Reference in New Issue
Block a user