blob: 18284b1fb8c8035cf21c7f07702d93bfd3091623 [file] [log] [blame]
Earl Lee2e463fb2025-04-17 11:22:22 -07001// Package dockerimg
2package dockerimg
3
4import (
Josh Bleecher Snyderc9898fd2025-07-08 21:09:18 +00005 "archive/tar"
Earl Lee2e463fb2025-04-17 11:22:22 -07006 "bytes"
7 "context"
Philip Zeyliger5e227dd2025-04-21 15:55:29 -07008 "crypto/rand"
Earl Lee2e463fb2025-04-17 11:22:22 -07009 "crypto/sha256"
10 "encoding/hex"
11 "encoding/json"
12 "fmt"
13 "io"
14 "log/slog"
15 "net"
16 "net/http"
17 "os"
18 "os/exec"
19 "path/filepath"
20 "runtime"
21 "strings"
Josh Bleecher Snyder99570462025-05-05 10:26:14 -070022 "sync/atomic"
Earl Lee2e463fb2025-04-17 11:22:22 -070023 "time"
24
Sean McCullough7013e9e2025-05-14 02:03:58 +000025 "golang.org/x/crypto/ssh"
Josh Bleecher Snyder78707d62025-04-30 21:06:49 +000026 "sketch.dev/browser"
Josh Bleecher Snyder1c18ec92025-07-08 10:55:54 -070027 "sketch.dev/embedded"
Sean McCulloughbaa2b592025-04-23 10:40:08 -070028 "sketch.dev/loop/server"
Earl Lee2e463fb2025-04-17 11:22:22 -070029 "sketch.dev/skribe"
30)
31
32// ContainerConfig holds all configuration for launching a container
33type ContainerConfig struct {
34 // SessionID is the unique identifier for this session
35 SessionID string
36
37 // LocalAddr is the initial address to use (though it may be overwritten later)
38 LocalAddr string
39
40 // SkabandAddr is the address of the skaband service if available
41 SkabandAddr string
42
David Crawshaw5a7b3692025-05-05 16:49:15 -070043 // Model is the name of the LLM model to use.
44 Model string
Earl Lee2e463fb2025-04-17 11:22:22 -070045
David Crawshaw5a7b3692025-05-05 16:49:15 -070046 // ModelURL is the URL of the LLM service.
47 ModelURL string
48
49 // ModelAPIKey is the API key for LLM service.
50 ModelAPIKey string
Earl Lee2e463fb2025-04-17 11:22:22 -070051
52 // Path is the local filesystem path to use
53 Path string
54
55 // GitUsername is the username to use for git operations
56 GitUsername string
57
58 // GitEmail is the email to use for git operations
59 GitEmail string
60
61 // OpenBrowser determines whether to open a browser automatically
62 OpenBrowser bool
63
64 // NoCleanup prevents container cleanup when set to true
65 NoCleanup bool
66
67 // ForceRebuild forces rebuilding of the Docker image even if it exists
68 ForceRebuild bool
69
Philip Zeyliger983b58a2025-07-02 19:42:08 -070070 // BaseImage is the base Docker image to use for layering the repo
71 BaseImage string
72
Earl Lee2e463fb2025-04-17 11:22:22 -070073 // Host directory to copy container logs into, if not set to ""
74 ContainerLogDest string
75
76 // Path to pre-built linux sketch binary, or build a new one if set to ""
77 SketchBinaryLinux string
78
79 // Sketch client public key.
80 SketchPubKey string
Philip Zeyligerd1402952025-04-23 03:54:37 +000081
Sean McCulloughbaa2b592025-04-23 10:40:08 -070082 // Host port for the container's ssh server
83 SSHPort int
84
Philip Zeyliger18532b22025-04-23 21:11:46 +000085 // Outside information to pass to the container
86 OutsideHostname string
87 OutsideOS string
88 OutsideWorkingDir string
Philip Zeyligerb74c4f62025-04-25 19:18:49 -070089
Pokey Rule0dcebe12025-04-28 14:51:04 +010090 // If true, exit after the first turn
91 OneShot bool
92
93 // Initial prompt
94 Prompt string
Philip Zeyliger1b47aa22025-04-28 19:25:38 +000095
David Crawshawb5f6a002025-05-05 08:27:16 -070096 // Verbose enables verbose output
97 Verbose bool
Philip Zeyliger1dc21372025-05-05 19:54:44 +000098
99 // DockerArgs are additional arguments to pass to the docker create command
100 DockerArgs string
Josh Bleecher Snyderb1cca6f2025-05-06 01:52:55 +0000101
Josh Bleecher Snyderac761c92025-05-16 18:58:45 +0000102 // Mounts specifies volumes to mount in the container in format /path/on/host:/path/in/container
103 Mounts []string
104
Josh Bleecher Snyderb1cca6f2025-05-06 01:52:55 +0000105 // ExperimentFlag contains the experimental features to enable
106 ExperimentFlag string
Philip Zeyliger613c0f52025-05-15 16:36:22 -0700107
108 // TermUI enables terminal UI
109 TermUI bool
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700110
Josh Bleecher Snyder33032d32025-05-30 16:28:21 +0000111 // Budget configuration
Philip Zeyligere6c294d2025-06-04 16:55:21 +0000112 MaxDollars float64
Josh Bleecher Snyder33032d32025-05-30 16:28:21 +0000113
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700114 GitRemoteUrl string
115
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000116 // Original git origin URL from the host repository
117 OriginalGitOrigin string
118
Josh Bleecher Snyder664404e2025-06-04 21:56:42 +0000119 // Upstream branch for git work
120 Upstream string
121
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700122 // Commit hash to checkout from GetRemoteUrl
123 Commit string
124
125 // Outtie's HTTP server
126 OutsideHTTP string
Philip Zeyligerbe7802a2025-06-04 20:15:25 +0000127
128 // Prefix for git branches created by sketch
129 BranchPrefix string
philip.zeyliger6d3de482025-06-10 19:38:14 -0700130
131 // LinkToGitHub enables GitHub branch linking in UI
132 LinkToGitHub bool
Philip Zeyligerd4be7a22025-06-15 09:39:00 -0700133
134 // SubtraceToken enables running sketch under subtrace.dev (development only)
135 SubtraceToken string
Philip Zeyliger194bfa82025-06-24 06:03:06 -0700136
137 // MCPServers contains MCP server configurations
138 MCPServers []string
Earl Lee2e463fb2025-04-17 11:22:22 -0700139}
140
141// LaunchContainer creates a docker container for a project, installs sketch and opens a connection to it.
142// It writes status to stdout.
David Crawshawb5f6a002025-05-05 08:27:16 -0700143func LaunchContainer(ctx context.Context, config ContainerConfig) error {
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700144 slog.Debug("Container Config", slog.String("config", fmt.Sprintf("%+v", config)))
Earl Lee2e463fb2025-04-17 11:22:22 -0700145 if _, err := exec.LookPath("docker"); err != nil {
Philip Zeyliger5e227dd2025-04-21 15:55:29 -0700146 if runtime.GOOS == "darwin" {
147 return fmt.Errorf("cannot find `docker` binary; run: brew install docker colima && colima start")
148 } else {
149 return fmt.Errorf("cannot find `docker` binary; install docker (e.g., apt-get install docker.io)")
150 }
Earl Lee2e463fb2025-04-17 11:22:22 -0700151 }
152
153 if out, err := combinedOutput(ctx, "docker", "ps"); err != nil {
154 // `docker ps` provides a good error message here that can be
155 // easily chatgpt'ed by users, so send it to the user as-is:
156 // Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
157 return fmt.Errorf("docker ps: %s (%w)", out, err)
158 }
159
160 _, hostPort, err := net.SplitHostPort(config.LocalAddr)
161 if err != nil {
162 return err
163 }
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000164 // Bail early if sketch was started from a path that isn't in a git repo.
165 err = requireGitRepo(ctx, config.Path)
Earl Lee2e463fb2025-04-17 11:22:22 -0700166 if err != nil {
167 return err
168 }
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000169
170 // Best effort attempt to get repo root; fall back to current directory.
171 gitRoot := config.Path
172 if root, err := gitRepoRoot(ctx, config.Path); err == nil {
173 gitRoot = root
174 }
175
176 // Capture the original git origin URL before we set up the temporary git server
177 config.OriginalGitOrigin = getOriginalGitOrigin(ctx, gitRoot)
178
Philip Zeyligerd6d12d12025-05-19 19:19:21 -0700179 err = checkForEmptyGitRepo(ctx, config.Path)
180 if err != nil {
181 return err
182 }
Earl Lee2e463fb2025-04-17 11:22:22 -0700183
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700184 imgName, err := findOrBuildDockerImage(ctx, gitRoot, config.BaseImage, config.ForceRebuild, config.Verbose)
Earl Lee2e463fb2025-04-17 11:22:22 -0700185 if err != nil {
186 return err
187 }
188
Philip Zeyligerc72fff52025-04-29 20:17:54 +0000189 cntrName := "sketch-" + config.SessionID
Earl Lee2e463fb2025-04-17 11:22:22 -0700190 defer func() {
191 if config.NoCleanup {
192 return
193 }
194 if out, err := combinedOutput(ctx, "docker", "kill", cntrName); err != nil {
195 // TODO: print in verbose mode? fmt.Fprintf(os.Stderr, "docker kill: %s: %v\n", out, err)
196 _ = out
197 }
198 if out, err := combinedOutput(ctx, "docker", "rm", cntrName); err != nil {
199 // TODO: print in verbose mode? fmt.Fprintf(os.Stderr, "docker kill: %s: %v\n", out, err)
200 _ = out
201 }
202 }()
203
204 // errCh receives errors from operations that this function calls in separate goroutines.
205 errCh := make(chan error)
206
207 // Start the git server
208 gitSrv, err := newGitServer(gitRoot)
209 if err != nil {
210 return fmt.Errorf("failed to start git server: %w", err)
211 }
212 defer gitSrv.shutdown(ctx)
213
214 go func() {
215 errCh <- gitSrv.serve(ctx)
216 }()
217
218 // Get the current host git commit
219 var commit string
Philip Zeyligera347b172025-06-04 16:18:57 +0000220 if out, err := combinedOutput(ctx, "git", "rev-parse", "HEAD"); err != nil {
221 return fmt.Errorf("git rev-parse HEAD: %w", err)
Earl Lee2e463fb2025-04-17 11:22:22 -0700222 } else {
223 commit = strings.TrimSpace(string(out))
224 }
Josh Bleecher Snyder664404e2025-06-04 21:56:42 +0000225
226 var upstream string
227 if out, err := combinedOutput(ctx, "git", "branch", "--show-current"); err != nil {
228 slog.DebugContext(ctx, "git branch --show-current failed (continuing)", "error", err)
229 } else {
230 upstream = strings.TrimSpace(string(out))
231 }
Earl Lee2e463fb2025-04-17 11:22:22 -0700232 if out, err := combinedOutput(ctx, "git", "config", "http.receivepack", "true"); err != nil {
233 return fmt.Errorf("git config http.receivepack true: %s: %w", out, err)
234 }
235
236 relPath, err := filepath.Rel(gitRoot, config.Path)
237 if err != nil {
238 return err
239 }
240
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700241 config.OutsideHTTP = fmt.Sprintf("http://sketch:%s@host.docker.internal:%s", gitSrv.pass, gitSrv.gitPort)
242 config.GitRemoteUrl = fmt.Sprintf("http://sketch:%s@host.docker.internal:%s/.git", gitSrv.pass, gitSrv.gitPort)
Josh Bleecher Snyder664404e2025-06-04 21:56:42 +0000243 config.Upstream = upstream
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700244 config.Commit = commit
245
Josh Bleecher Snyder1c18ec92025-07-08 10:55:54 -0700246 // Create the sketch container, copy over linux sketch
Earl Lee2e463fb2025-04-17 11:22:22 -0700247 if err := createDockerContainer(ctx, cntrName, hostPort, relPath, imgName, config); err != nil {
Josh Bleecher Snyder2772f632025-05-01 21:42:35 +0000248 return fmt.Errorf("failed to create docker container: %w", err)
Earl Lee2e463fb2025-04-17 11:22:22 -0700249 }
Josh Bleecher Snyder1c18ec92025-07-08 10:55:54 -0700250 if err := copyEmbeddedLinuxBinaryToContainer(ctx, cntrName); err != nil {
251 return fmt.Errorf("failed to copy linux binary to container: %w", err)
David Crawshaw8bff16a2025-04-18 01:16:49 -0700252 }
Earl Lee2e463fb2025-04-17 11:22:22 -0700253
David Crawshaw53786ef2025-04-24 12:52:51 -0700254 fmt.Printf("📦 running in container %s\n", cntrName)
Earl Lee2e463fb2025-04-17 11:22:22 -0700255
Philip Zeyligerd4be7a22025-06-15 09:39:00 -0700256 // Setup subtrace if token is provided (development only) - after container creation, before start
257 if config.SubtraceToken != "" {
258 fmt.Println("🔍 Setting up subtrace (development only)")
259 if err := setupSubtraceBeforeStart(ctx, cntrName, config.SubtraceToken); err != nil {
260 return fmt.Errorf("failed to setup subtrace: %w", err)
261 }
262 }
263
Earl Lee2e463fb2025-04-17 11:22:22 -0700264 // Start the sketch container
265 if out, err := combinedOutput(ctx, "docker", "start", cntrName); err != nil {
266 return fmt.Errorf("docker start: %s, %w", out, err)
267 }
268
269 // Copies structured logs from the container to the host.
270 copyLogs := func() {
271 if config.ContainerLogDest == "" {
272 return
273 }
274 out, err := combinedOutput(ctx, "docker", "logs", cntrName)
275 if err != nil {
276 fmt.Fprintf(os.Stderr, "docker logs failed: %v\n", err)
277 return
278 }
Josh Bleecher Snyder7660e4e2025-04-24 10:34:17 -0700279 prefix := []byte("structured logs:")
280 for line := range bytes.Lines(out) {
281 rest, ok := bytes.CutPrefix(line, prefix)
282 if !ok {
Earl Lee2e463fb2025-04-17 11:22:22 -0700283 continue
284 }
Josh Bleecher Snyder7660e4e2025-04-24 10:34:17 -0700285 logFile := string(bytes.TrimSpace(rest))
Earl Lee2e463fb2025-04-17 11:22:22 -0700286 srcPath := fmt.Sprintf("%s:%s", cntrName, logFile)
287 logFileName := filepath.Base(logFile)
288 dstPath := filepath.Join(config.ContainerLogDest, logFileName)
289 _, err := combinedOutput(ctx, "docker", "cp", srcPath, dstPath)
290 if err != nil {
291 fmt.Fprintf(os.Stderr, "docker cp %s %s failed: %v\n", srcPath, dstPath, err)
292 }
293 fmt.Fprintf(os.Stderr, "\ncopied container log %s to %s\n", srcPath, dstPath)
294 }
295 }
296
297 // NOTE: we want to see what the internal sketch binary prints
298 // regardless of the setting of the verbosity flag on the external
299 // binary, so reading "docker logs", which is the stdout/stderr of
300 // the internal binary is not conditional on the verbose flag.
301 appendInternalErr := func(err error) error {
302 if err == nil {
303 return nil
304 }
305 out, logsErr := combinedOutput(ctx, "docker", "logs", cntrName)
Philip Zeyligerd1402952025-04-23 03:54:37 +0000306 if logsErr != nil {
Earl Lee2e463fb2025-04-17 11:22:22 -0700307 return fmt.Errorf("%w; and docker logs failed: %s, %v", err, out, logsErr)
308 }
309 out = bytes.TrimSpace(out)
310 if len(out) > 0 {
311 return fmt.Errorf("docker logs: %s;\n%w", out, err)
312 }
313 return err
314 }
315
316 // Get the sketch server port from the container
Sean McCulloughae3480f2025-04-23 15:28:20 -0700317 localAddr, err := getContainerPort(ctx, cntrName, "80")
Earl Lee2e463fb2025-04-17 11:22:22 -0700318 if err != nil {
319 return appendInternalErr(err)
320 }
321
Philip Zeyliger00442412025-05-14 11:03:23 -0700322 if config.Verbose {
323 fmt.Fprintf(os.Stderr, "Host web server: http://%s/\n", localAddr)
324 }
325
Sean McCulloughae3480f2025-04-23 15:28:20 -0700326 localSSHAddr, err := getContainerPort(ctx, cntrName, "22")
327 if err != nil {
328 return appendInternalErr(err)
329 }
330 sshHost, sshPort, err := net.SplitHostPort(localSSHAddr)
331 if err != nil {
David Crawshawb5f6a002025-05-05 08:27:16 -0700332 return appendInternalErr(fmt.Errorf("failed to split ssh host and port: %w", err))
Sean McCulloughae3480f2025-04-23 15:28:20 -0700333 }
Sean McCullough4854c652025-04-24 18:37:02 -0700334
Sean McCullough7013e9e2025-05-14 02:03:58 +0000335 var sshServerIdentity, sshUserIdentity, containerCAPublicKey, hostCertificate []byte
Sean McCullough4854c652025-04-24 18:37:02 -0700336
banksean29d689f2025-06-23 15:41:26 +0000337 cst, err := NewLocalSSHimmer(cntrName, sshHost, sshPort)
Sean McCullough078e85a2025-05-08 17:28:34 -0700338 if err != nil {
339 return appendInternalErr(fmt.Errorf("NewContainerSSHTheather: %w", err))
340 }
341
342 sshErr := CheckSSHReachability(cntrName)
Sean McCullough15c95282025-05-08 16:48:38 -0700343 sshAvailable := false
344 sshErrMsg := ""
345 if sshErr != nil {
346 fmt.Println(sshErr.Error())
347 sshErrMsg = sshErr.Error()
Sean McCulloughf5e28f62025-04-25 10:48:00 -0700348 // continue - ssh config is not required for the rest of sketch to function locally.
349 } else {
Sean McCullough15c95282025-05-08 16:48:38 -0700350 sshAvailable = true
Sean McCulloughea3fc202025-04-28 12:53:37 -0700351 // Note: The vscode: link uses an undocumented request parameter that I really had to dig to find:
352 // https://github.com/microsoft/vscode/blob/2b9486161abaca59b5132ce3c59544f3cc7000f6/src/vs/code/electron-main/app.ts#L878
Sean McCulloughf5e28f62025-04-25 10:48:00 -0700353 fmt.Printf(`Connect to this container via any of these methods:
Sean McCullough4854c652025-04-24 18:37:02 -0700354🖥️ ssh %s
355🖥️ code --remote ssh-remote+root@%s /app -n
Sean McCulloughea3fc202025-04-28 12:53:37 -0700356🔗 vscode://vscode-remote/ssh-remote+root@%s/app?windowId=_blank
Sean McCullough4854c652025-04-24 18:37:02 -0700357`, cntrName, cntrName, cntrName)
Sean McCulloughf5e28f62025-04-25 10:48:00 -0700358 sshUserIdentity = cst.userIdentity
359 sshServerIdentity = cst.serverIdentity
Sean McCullough7013e9e2025-05-14 02:03:58 +0000360
361 // Get the Container CA public key for mutual auth
362 if cst.containerCAPublicKey != nil {
363 containerCAPublicKey = ssh.MarshalAuthorizedKey(cst.containerCAPublicKey)
364 fmt.Println("🔒 SSH Mutual Authentication enabled (container will verify host)")
365 }
366
367 // Get the host certificate for mutual auth
368 hostCertificate = cst.hostCertificate
369
Sean McCulloughf5e28f62025-04-25 10:48:00 -0700370 defer func() {
371 if err := cst.Cleanup(); err != nil {
372 appendInternalErr(err)
373 }
374 }()
375 }
Sean McCulloughae3480f2025-04-23 15:28:20 -0700376
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700377 // Tell the sketch container to Init(), which starts the SSH server
378 // and checks out the right commit.
379 // TODO: I'm trying to move as much configuration as possible into the command-line
380 // arguments to avoid splitting them up. "localAddr" is the only difficult one:
381 // we run (effectively) "docker run -p 0:80 image sketch -flags" and you can't
382 // get the port Docker chose until after the process starts. The SSH config is
383 // mostly available ahead of time, but whether it works ("sshAvailable"/"sshErrMsg")
384 // may also empirically need to be done after the SSH server is up and running.
Earl Lee2e463fb2025-04-17 11:22:22 -0700385 go func() {
386 // TODO: Why is this called in a goroutine? I have found that when I pull this out
387 // of the goroutine and call it inline, then the terminal UI clears itself and all
388 // the scrollback (which is not good, but also not fatal). I can't see why it does this
389 // though, since none of the calls in postContainerInitConfig obviously write to stdout
390 // or stderr.
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700391 if err := postContainerInitConfig(ctx, localAddr, sshAvailable, sshErrMsg, sshServerIdentity, sshUserIdentity, containerCAPublicKey, hostCertificate); err != nil {
Earl Lee2e463fb2025-04-17 11:22:22 -0700392 slog.ErrorContext(ctx, "LaunchContainer.postContainerInitConfig", slog.String("err", err.Error()))
393 errCh <- appendInternalErr(err)
394 }
Earl Lee2e463fb2025-04-17 11:22:22 -0700395
Philip Zeyliger6ed6adb2025-04-23 19:56:38 -0700396 // We open the browser after the init config because the above waits for the web server to be serving.
Josh Bleecher Snyder99570462025-05-05 10:26:14 -0700397 ps1URL := "http://" + localAddr
398 if config.SkabandAddr != "" {
399 ps1URL = fmt.Sprintf("%s/s/%s", config.SkabandAddr, config.SessionID)
Philip Zeyliger6ed6adb2025-04-23 19:56:38 -0700400 }
Josh Bleecher Snyder99570462025-05-05 10:26:14 -0700401 if config.OpenBrowser {
402 browser.Open(ps1URL)
403 }
404 gitSrv.ps1URL.Store(&ps1URL)
Philip Zeyliger6ed6adb2025-04-23 19:56:38 -0700405 }()
Earl Lee2e463fb2025-04-17 11:22:22 -0700406
407 go func() {
408 cmd := exec.CommandContext(ctx, "docker", "attach", cntrName)
409 cmd.Stdin = os.Stdin
410 cmd.Stdout = os.Stdout
411 cmd.Stderr = os.Stderr
412 errCh <- run(ctx, "docker attach", cmd)
413 }()
414
415 defer copyLogs()
416
417 for {
418 select {
419 case <-ctx.Done():
420 return ctx.Err()
421 case err := <-errCh:
422 if err != nil {
423 return appendInternalErr(fmt.Errorf("container process: %w", err))
424 }
425 return nil
426 }
427 }
428}
429
430func combinedOutput(ctx context.Context, cmdName string, args ...string) ([]byte, error) {
431 cmd := exec.CommandContext(ctx, cmdName, args...)
Earl Lee2e463fb2025-04-17 11:22:22 -0700432 start := time.Now()
433
434 out, err := cmd.CombinedOutput()
435 if err != nil {
David Crawshawc7e77962025-05-03 13:20:18 -0700436 slog.ErrorContext(ctx, cmdName, slog.Duration("elapsed", time.Since(start)), slog.String("err", err.Error()), slog.String("path", cmd.Path), slog.String("args", fmt.Sprintf("%v", skribe.Redact(cmd.Args))))
Earl Lee2e463fb2025-04-17 11:22:22 -0700437 } else {
David Crawshawc7e77962025-05-03 13:20:18 -0700438 slog.DebugContext(ctx, cmdName, slog.Duration("elapsed", time.Since(start)), slog.String("path", cmd.Path), slog.String("args", fmt.Sprintf("%v", skribe.Redact(cmd.Args))))
Earl Lee2e463fb2025-04-17 11:22:22 -0700439 }
440 return out, err
441}
442
443func run(ctx context.Context, cmdName string, cmd *exec.Cmd) error {
444 start := time.Now()
445 err := cmd.Run()
446 if err != nil {
David Crawshawc7e77962025-05-03 13:20:18 -0700447 slog.ErrorContext(ctx, cmdName, slog.Duration("elapsed", time.Since(start)), slog.String("err", err.Error()), slog.String("path", cmd.Path), slog.String("args", fmt.Sprintf("%v", skribe.Redact(cmd.Args))))
Earl Lee2e463fb2025-04-17 11:22:22 -0700448 } else {
David Crawshawc7e77962025-05-03 13:20:18 -0700449 slog.DebugContext(ctx, cmdName, slog.Duration("elapsed", time.Since(start)), slog.String("path", cmd.Path), slog.String("args", fmt.Sprintf("%v", skribe.Redact(cmd.Args))))
Earl Lee2e463fb2025-04-17 11:22:22 -0700450 }
451 return err
452}
453
454type gitServer struct {
455 gitLn net.Listener
456 gitPort string
457 srv *http.Server
Philip Zeyliger5e227dd2025-04-21 15:55:29 -0700458 pass string
Josh Bleecher Snyder99570462025-05-05 10:26:14 -0700459 ps1URL atomic.Pointer[string]
Earl Lee2e463fb2025-04-17 11:22:22 -0700460}
461
462func (gs *gitServer) shutdown(ctx context.Context) {
463 gs.srv.Shutdown(ctx)
464 gs.gitLn.Close()
465}
466
467// Serve a git remote from the host for the container to fetch from and push to.
468func (gs *gitServer) serve(ctx context.Context) error {
469 slog.DebugContext(ctx, "starting git server", slog.String("git_remote_addr", "http://host.docker.internal:"+gs.gitPort+"/.git"))
470 return gs.srv.Serve(gs.gitLn)
471}
472
473func newGitServer(gitRoot string) (*gitServer, error) {
Josh Bleecher Snyder9f6a9982025-04-22 17:34:15 -0700474 ret := &gitServer{
475 pass: rand.Text(),
476 }
Philip Zeyliger5e227dd2025-04-21 15:55:29 -0700477
Earl Lee2e463fb2025-04-17 11:22:22 -0700478 gitLn, err := net.Listen("tcp4", ":0")
479 if err != nil {
480 return nil, fmt.Errorf("git listen: %w", err)
481 }
482 ret.gitLn = gitLn
483
Josh Bleecher Snyder99570462025-05-05 10:26:14 -0700484 browserC := make(chan bool, 1) // channel of browser open requests
485
Josh Bleecher Snyder3e2111b2025-04-30 17:53:28 +0000486 go func() {
Josh Bleecher Snyder99570462025-05-05 10:26:14 -0700487 for range browserC {
488 browser.Open(*ret.ps1URL.Load())
Josh Bleecher Snyder3e2111b2025-04-30 17:53:28 +0000489 }
490 }()
491
492 srv := http.Server{Handler: &gitHTTP{gitRepoRoot: gitRoot, pass: []byte(ret.pass), browserC: browserC}}
Earl Lee2e463fb2025-04-17 11:22:22 -0700493 ret.srv = &srv
494
495 _, gitPort, err := net.SplitHostPort(gitLn.Addr().String())
496 if err != nil {
497 return nil, fmt.Errorf("git port: %w", err)
498 }
499 ret.gitPort = gitPort
500 return ret, nil
501}
502
503func createDockerContainer(ctx context.Context, cntrName, hostPort, relPath, imgName string, config ContainerConfig) error {
David Crawshaw69c67312025-04-17 13:42:00 -0700504 cmdArgs := []string{
505 "create",
David Crawshaw66cf74e2025-05-05 08:48:39 -0700506 "-i",
Earl Lee2e463fb2025-04-17 11:22:22 -0700507 "--name", cntrName,
508 "-p", hostPort + ":80", // forward container port 80 to a host port
David Crawshaw3659d872025-05-05 17:52:23 -0700509 "-e", "SKETCH_MODEL_API_KEY=" + config.ModelAPIKey,
Earl Lee2e463fb2025-04-17 11:22:22 -0700510 }
Philip Zeyliger3d2eff02025-05-27 09:30:31 -0700511 if !(config.OneShot || !config.TermUI) {
David Crawshaw66cf74e2025-05-05 08:48:39 -0700512 cmdArgs = append(cmdArgs, "-t")
513 }
Josh Bleecher Snyder2772f632025-05-01 21:42:35 +0000514
515 for _, envVar := range getEnvForwardingFromGitConfig(ctx) {
516 cmdArgs = append(cmdArgs, "-e", envVar)
517 }
David Crawshaw5a7b3692025-05-05 16:49:15 -0700518 if config.ModelURL != "" {
David Crawshaw3659d872025-05-05 17:52:23 -0700519 cmdArgs = append(cmdArgs, "-e", "SKETCH_MODEL_URL="+config.ModelURL)
Earl Lee2e463fb2025-04-17 11:22:22 -0700520 }
521 if config.SketchPubKey != "" {
522 cmdArgs = append(cmdArgs, "-e", "SKETCH_PUB_KEY="+config.SketchPubKey)
523 }
Sean McCulloughae3480f2025-04-23 15:28:20 -0700524 if config.SSHPort > 0 {
525 cmdArgs = append(cmdArgs, "-p", fmt.Sprintf("%d:22", config.SSHPort)) // forward container ssh port to host ssh port
526 } else {
Philip Zeyliger87d29ef2025-05-16 20:25:28 -0700527 cmdArgs = append(cmdArgs, "-p", "0:22") // use an ephemeral host port for ssh.
Sean McCulloughbaa2b592025-04-23 10:40:08 -0700528 }
Philip Zeyliger5e227dd2025-04-21 15:55:29 -0700529 // colima does this by default, but Linux docker seems to need this set explicitly
530 cmdArgs = append(cmdArgs, "--add-host", "host.docker.internal:host-gateway")
Josh Bleecher Snyderac761c92025-05-16 18:58:45 +0000531
David Crawshaw1bd636c2025-06-13 19:56:27 +0000532 // Add seccomp profile to prevent killing PID 1 (the sketch process itself)
533 // Write the seccomp profile to cache directory if it doesn't exist
534 seccompPath, err := ensureSeccompProfile(ctx)
535 if err != nil {
536 return fmt.Errorf("failed to create seccomp profile: %w", err)
537 }
538 cmdArgs = append(cmdArgs, "--security-opt", "seccomp="+seccompPath)
539
Philip Zeyligerd4be7a22025-06-15 09:39:00 -0700540 // Add subtrace environment variable if token is provided
541 if config.SubtraceToken != "" {
542 cmdArgs = append(cmdArgs, "-e", "SUBTRACE_TOKEN="+config.SubtraceToken)
543 cmdArgs = append(cmdArgs, "-e", "SUBTRACE_HTTP2=1")
544 }
545
Josh Bleecher Snyderac761c92025-05-16 18:58:45 +0000546 // Add volume mounts if specified
547 for _, mount := range config.Mounts {
548 if mount != "" {
549 cmdArgs = append(cmdArgs, "-v", mount)
550 }
551 }
Philip Zeyligerd4be7a22025-06-15 09:39:00 -0700552 cmdArgs = append(cmdArgs, imgName)
553
554 // Add command: either [sketch] or [subtrace run -- sketch]
555 if config.SubtraceToken != "" {
556 cmdArgs = append(cmdArgs, "/usr/local/bin/subtrace", "run", "--", "/bin/sketch")
557 } else {
558 cmdArgs = append(cmdArgs, "/bin/sketch")
559 }
560
561 // Add all sketch arguments
562 cmdArgs = append(cmdArgs,
Earl Lee2e463fb2025-04-17 11:22:22 -0700563 "-unsafe",
564 "-addr=:80",
565 "-session-id="+config.SessionID,
Philip Zeyligerd1402952025-04-23 03:54:37 +0000566 "-git-username="+config.GitUsername,
567 "-git-email="+config.GitEmail,
Philip Zeyliger18532b22025-04-23 21:11:46 +0000568 "-outside-hostname="+config.OutsideHostname,
569 "-outside-os="+config.OutsideOS,
570 "-outside-working-dir="+config.OutsideWorkingDir,
Josh Bleecher Snyder33032d32025-05-30 16:28:21 +0000571 fmt.Sprintf("-max-dollars=%f", config.MaxDollars),
Josh Bleecher Snyder3cae7d92025-04-30 09:54:29 -0700572 "-open=false",
Philip Zeyliger613c0f52025-05-15 16:36:22 -0700573 "-termui="+fmt.Sprintf("%t", config.TermUI),
Philip Zeyligercabfa552025-05-19 16:14:28 -0700574 "-verbose="+fmt.Sprintf("%t", config.Verbose),
Josh Bleecher Snyderb1cca6f2025-05-06 01:52:55 +0000575 "-x="+config.ExperimentFlag,
Philip Zeyligerbe7802a2025-06-04 20:15:25 +0000576 "-branch-prefix="+config.BranchPrefix,
philip.zeyliger6d3de482025-06-10 19:38:14 -0700577 "-link-to-github="+fmt.Sprintf("%t", config.LinkToGitHub),
Earl Lee2e463fb2025-04-17 11:22:22 -0700578 )
philip.zeyliger8773e682025-06-11 21:36:21 -0700579 // Set SSH connection string based on session ID for SSH Theater
580 cmdArgs = append(cmdArgs, "-ssh-connection-string=sketch-"+config.SessionID)
Josh Bleecher Snydera96f9d22025-07-11 02:47:33 +0000581 if relPath != "." {
582 cmdArgs = append(cmdArgs, "-C", relPath)
583 }
David Crawshaw5a7b3692025-05-05 16:49:15 -0700584 if config.Model != "" {
585 cmdArgs = append(cmdArgs, "-model="+config.Model)
586 }
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700587 if config.GitRemoteUrl != "" {
588 cmdArgs = append(cmdArgs, "-git-remote-url="+config.GitRemoteUrl)
589 if config.Commit == "" {
590 panic("Commit should have been set when GitRemoteUrl was set")
591 }
592 cmdArgs = append(cmdArgs, "-commit="+config.Commit)
Josh Bleecher Snyder664404e2025-06-04 21:56:42 +0000593 cmdArgs = append(cmdArgs, "-upstream="+config.Upstream)
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700594 }
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000595 if config.OriginalGitOrigin != "" {
596 cmdArgs = append(cmdArgs, "-original-git-origin="+config.OriginalGitOrigin)
597 }
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700598 if config.OutsideHTTP != "" {
599 cmdArgs = append(cmdArgs, "-outside-http="+config.OutsideHTTP)
600 }
Josh Bleecher Snydere3c2f222025-05-15 20:54:52 +0000601 cmdArgs = append(cmdArgs, "-skaband-addr="+config.SkabandAddr)
Pokey Rule0dcebe12025-04-28 14:51:04 +0100602 if config.Prompt != "" {
603 cmdArgs = append(cmdArgs, "-prompt", config.Prompt)
604 }
605 if config.OneShot {
606 cmdArgs = append(cmdArgs, "-one-shot")
Philip Zeyligerb74c4f62025-04-25 19:18:49 -0700607 }
Josh Bleecher Snydere3c2f222025-05-15 20:54:52 +0000608 if config.ModelURL == "" {
609 // Forward ANTHROPIC_API_KEY for direct use.
610 // TODO: have outtie run an http proxy?
611 // TODO: select and forward the relevant API key based on the model
612 cmdArgs = append(cmdArgs, "-llm-api-key="+os.Getenv("ANTHROPIC_API_KEY"))
613 }
Philip Zeyliger194bfa82025-06-24 06:03:06 -0700614 // Add MCP server configurations
615 for _, mcpServer := range config.MCPServers {
616 cmdArgs = append(cmdArgs, "-mcp", mcpServer)
617 }
Philip Zeyliger1dc21372025-05-05 19:54:44 +0000618
619 // Add additional docker arguments if provided
620 if config.DockerArgs != "" {
621 // Parse space-separated docker arguments with support for quotes and escaping
622 args := parseDockerArgs(config.DockerArgs)
623 // Insert arguments after "create" but before other arguments
624 for i := len(args) - 1; i >= 0; i-- {
625 cmdArgs = append(cmdArgs[:1], append([]string{args[i]}, cmdArgs[1:]...)...)
626 }
627 }
628
Earl Lee2e463fb2025-04-17 11:22:22 -0700629 if out, err := combinedOutput(ctx, "docker", cmdArgs...); err != nil {
630 return fmt.Errorf("docker create: %s, %w", out, err)
631 }
632 return nil
633}
634
Sean McCulloughae3480f2025-04-23 15:28:20 -0700635func getContainerPort(ctx context.Context, cntrName, cntrPort string) (string, error) {
Earl Lee2e463fb2025-04-17 11:22:22 -0700636 localAddr := ""
Sean McCulloughae3480f2025-04-23 15:28:20 -0700637 if out, err := combinedOutput(ctx, "docker", "port", cntrName, cntrPort); err != nil {
Earl Lee2e463fb2025-04-17 11:22:22 -0700638 return "", fmt.Errorf("failed to find container port: %s: %v", out, err)
639 } else {
640 v4, _, found := strings.Cut(string(out), "\n")
641 if !found {
642 return "", fmt.Errorf("failed to find container port: %s: %v", out, err)
643 }
644 localAddr = v4
645 if strings.HasPrefix(localAddr, "0.0.0.0") {
646 localAddr = "127.0.0.1" + strings.TrimPrefix(localAddr, "0.0.0.0")
647 }
648 }
649 return localAddr, nil
650}
651
652// Contact the container and configure it.
Philip Zeyligerbc8c8dc2025-05-21 13:19:13 -0700653func postContainerInitConfig(ctx context.Context, localAddr string, sshAvailable bool, sshError string, sshServerIdentity, sshAuthorizedKeys, sshContainerCAKey, sshHostCertificate []byte) error {
Earl Lee2e463fb2025-04-17 11:22:22 -0700654 localURL := "http://" + localAddr
Sean McCulloughbaa2b592025-04-23 10:40:08 -0700655
656 initMsg, err := json.Marshal(
657 server.InitRequest{
Sean McCullough7013e9e2025-05-14 02:03:58 +0000658 HostAddr: localAddr,
659 SSHAuthorizedKeys: sshAuthorizedKeys,
660 SSHServerIdentity: sshServerIdentity,
661 SSHContainerCAKey: sshContainerCAKey,
662 SSHHostCertificate: sshHostCertificate,
663 SSHAvailable: sshAvailable,
664 SSHError: sshError,
Sean McCulloughbaa2b592025-04-23 10:40:08 -0700665 })
Earl Lee2e463fb2025-04-17 11:22:22 -0700666 if err != nil {
667 return fmt.Errorf("init msg: %w", err)
668 }
669
Earl Lee2e463fb2025-04-17 11:22:22 -0700670 // Note: this /init POST is handled in loop/server/loophttp.go:
671 initMsgByteReader := bytes.NewReader(initMsg)
672 req, err := http.NewRequest("POST", localURL+"/init", initMsgByteReader)
673 if err != nil {
674 return err
675 }
676
677 var res *http.Response
678 for i := 0; ; i++ {
679 time.Sleep(100 * time.Millisecond)
680 // If you DON'T reset this byteReader, then subsequent retries may end up sending 0 bytes.
681 initMsgByteReader.Reset(initMsg)
682 res, err = http.DefaultClient.Do(req)
683 if err != nil {
David Crawshaw99231ba2025-05-03 10:48:26 -0700684 if i < 100 {
685 if i%10 == 0 {
686 slog.DebugContext(ctx, "postContainerInitConfig retrying", slog.Int("retry", i), slog.String("err", err.Error()))
687 }
Earl Lee2e463fb2025-04-17 11:22:22 -0700688 continue
689 }
690 return fmt.Errorf("failed to %s/init sketch in container, NOT retrying: err: %v", localURL, err)
691 }
692 break
693 }
694 resBytes, _ := io.ReadAll(res.Body)
695 if res.StatusCode != http.StatusOK {
696 return fmt.Errorf("failed to initialize sketch in container, response status code %d: %s", res.StatusCode, resBytes)
697 }
698 return nil
699}
700
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700701func findOrBuildDockerImage(ctx context.Context, gitRoot, baseImage string, forceRebuild, verbose bool) (imgName string, err error) {
702 // Default to the published sketch image if no base image is specified
703 if baseImage == "" {
704 imageTag := dockerfileBaseHash()
705 baseImage = fmt.Sprintf("%s:%s", dockerImgName, imageTag)
Earl Lee2e463fb2025-04-17 11:22:22 -0700706 }
707
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700708 // Ensure the base image exists locally, pull if necessary
709 if err := ensureBaseImageExists(ctx, baseImage); err != nil {
710 return "", fmt.Errorf("failed to ensure base image %s exists: %w", baseImage, err)
711 }
712
713 // Get the base image container ID for caching
714 baseImageID, err := getDockerImageID(ctx, baseImage)
Earl Lee2e463fb2025-04-17 11:22:22 -0700715 if err != nil {
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700716 return "", fmt.Errorf("failed to get base image ID for %s: %w", baseImage, err)
Earl Lee2e463fb2025-04-17 11:22:22 -0700717 }
718
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700719 // Create a cache key based on base image ID and working directory
720 // Docker naming conventions restrict you to 20 characters per path component
721 // and only allow lowercase letters, digits, underscores, and dashes, so encoding
722 // the hash and the repo directory is sadly a bit of a non-starter.
723 cacheKey := createCacheKey(baseImageID, gitRoot)
724 imgName = "sketch-" + cacheKey
Earl Lee2e463fb2025-04-17 11:22:22 -0700725
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700726 // Check if the cached image exists and is up to date
727 if !forceRebuild {
728 if exists, err := dockerImageExists(ctx, imgName); err != nil {
729 return "", fmt.Errorf("failed to check if image exists: %w", err)
730 } else if exists {
731 if verbose {
732 fmt.Printf("using cached image %s\n", imgName)
Kilian Lackhove23772f42025-06-18 20:28:58 +0200733 }
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700734 return imgName, nil
David Crawshawb5f6a002025-05-05 08:27:16 -0700735 }
Earl Lee2e463fb2025-04-17 11:22:22 -0700736 }
737
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700738 // Build the layered image
739 if err := buildLayeredImage(ctx, imgName, baseImage, gitRoot, verbose); err != nil {
740 return "", fmt.Errorf("failed to build layered image: %w", err)
741 }
742
743 return imgName, nil
744}
745
746// ensureBaseImageExists checks if the base image exists locally and pulls it if not
747func ensureBaseImageExists(ctx context.Context, imageName string) error {
748 exists, err := dockerImageExists(ctx, imageName)
749 if err != nil {
750 return fmt.Errorf("failed to check if image exists: %w", err)
751 }
752
753 if !exists {
754 fmt.Printf("🐋 pulling base image %s...\n", imageName)
755 if out, err := combinedOutput(ctx, "docker", "pull", imageName); err != nil {
756 return fmt.Errorf("docker pull %s failed: %s: %w", imageName, out, err)
757 }
758 fmt.Printf("✅ successfully pulled %s\n", imageName)
759 }
760
761 return nil
762}
763
764// getDockerImageID gets the container ID for a Docker image
765func getDockerImageID(ctx context.Context, imageName string) (string, error) {
766 out, err := combinedOutput(ctx, "docker", "inspect", "--format", "{{.Id}}", imageName)
767 if err != nil {
768 return "", err
769 }
770 return strings.TrimSpace(string(out)), nil
771}
772
773// createCacheKey creates a cache key from base image ID and working directory
774func createCacheKey(baseImageID, gitRoot string) string {
775 h := sha256.New()
776 h.Write([]byte(baseImageID))
777 h.Write([]byte(gitRoot))
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000778 // one-time cache-busting for the transition from copying git repos to only copying git objects
779 h.Write([]byte("git-objects"))
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700780 return hex.EncodeToString(h.Sum(nil))[:12] // Use first 12 chars for shorter name
781}
782
783// dockerImageExists checks if a Docker image exists locally
784func dockerImageExists(ctx context.Context, imageName string) (bool, error) {
785 out, err := combinedOutput(ctx, "docker", "inspect", imageName)
786 if err != nil {
787 if strings.Contains(strings.ToLower(string(out)), "no such object") ||
788 strings.Contains(strings.ToLower(string(out)), "no such image") {
789 return false, nil
790 }
791 return false, err
792 }
793 return true, nil
794}
795
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000796// buildLayeredImage builds a new Docker image by layering the repo on top of the base image.
797//
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700798// TODO: git config stuff could be environment variables at runtime for email and username.
799// The git docs seem to say that http.postBuffer is a bug in our git proxy more than a thing
800// that's needed, but we haven't found the bug yet!
Philip Zeyliger882b1d12025-07-02 20:04:08 -0700801//
802// TODO: There is a caching tension. A base image is great for tools (like, some version
803// of Go). Then you want a git repo, which is much faster to incrementally fetch rather
804// than cloning every time. Then you want some build artifacts, like perhaps the
805// "go mod download" cache, or the "go build" cache or the "npm install" cache.
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000806// The implementation here copies the git objects into the base image.
807// That enables fast clones into the container, because most of the git objects are already there.
808// It also avoids copying uncommitted changes, configs/hooks, etc.
Josh Bleecher Snyderfa424f52025-07-11 18:43:55 +0000809// We also set up fake temporary Go module(s) so we can run "go mod download".
810// TODO: maybe 'go list ./...' and then do a build as well to populate the build cache.
811// TODO: 'npm install', etc? We have the rails for it.
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000812// This is an ok compromise, but a power user might want
Philip Zeyliger882b1d12025-07-02 20:04:08 -0700813// less caching or more caching, depending on their use case. One approach we could take
814// is to punt entirely if /app/.git already exists. If the user has provided a -base-image with
815// their git repo, let's assume they know what they're doing, and they've customized their image
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000816// for their use case.
Philip Zeyliger882b1d12025-07-02 20:04:08 -0700817// Note that buildx has some support for conditional COPY, but without buildx, which
818// we can't reliably depend on, we have to run the base image to inspect its file system,
819// and then we can decide what to do.
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000820//
821// We may in the future want to enable people to bring along uncommitted changes to tracked files.
822// To do that, we would run `git stash create` in outie at launch time, treat HEAD as the base commit,
823// and add in the stash commit as a new commit atop it.
824// That would accurately model the base commit as well as the uncommitted changes.
825// (This wouldn't happen here, but at agent/container initialization time.)
826//
827// repoPath is the current working directory where sketch is being run from.
828func buildLayeredImage(ctx context.Context, imgName, baseImage, gitRoot string, verbose bool) error {
Josh Bleecher Snyderfa424f52025-07-11 18:43:55 +0000829 goModules, err := collectGoModules(ctx, gitRoot)
830 if err != nil {
831 return fmt.Errorf("failed to collect go modules: %w", err)
832 }
833
834 buf := new(strings.Builder)
835 line := func(msg string, args ...any) {
836 fmt.Fprintf(buf, msg+"\n", args...)
837 }
838
839 line("FROM %s", baseImage)
840 line("COPY . /git-ref")
841
842 for _, module := range goModules {
843 line("RUN mkdir -p /go-module")
844 line("RUN git --git-dir=/git-ref --work-tree=/go-module cat-file blob %s > /go-module/go.mod", module.modSHA)
845 if module.sumSHA != "" {
846 line("RUN git --git-dir=/git-ref --work-tree=/go-module cat-file blob %s > /go-module/go.sum", module.sumSHA)
847 }
848 // drop any replaced modules
849 line("RUN cd /go-module && go mod edit -json | jq -r '.Replace? // [] | .[] | .Old.Path' | xargs -r -I{} go mod edit -dropreplace={} -droprequire={}")
850 // grab what’s left, best effort only to avoid breaking on (say) private modules
851 line("RUN cd /go-module && go mod download || true")
852 line("RUN rm -rf /go-module")
853 }
854
855 line("WORKDIR /app")
856 line(`CMD ["/bin/sketch"]`)
857 dockerfileContent := buf.String()
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700858
859 // Create a temporary directory for the Dockerfile
860 tmpDir, err := os.MkdirTemp("", "sketch-docker-*")
861 if err != nil {
862 return fmt.Errorf("failed to create temporary directory: %w", err)
863 }
864 defer os.RemoveAll(tmpDir)
865
866 dockerfilePath := filepath.Join(tmpDir, "Dockerfile")
867 if err := os.WriteFile(dockerfilePath, []byte(dockerfileContent), 0o666); err != nil {
868 return fmt.Errorf("failed to write Dockerfile: %w", err)
869 }
870
871 // Get git user info
Earl Lee2e463fb2025-04-17 11:22:22 -0700872 var gitUserEmail, gitUserName string
873 if out, err := combinedOutput(ctx, "git", "config", "--get", "user.email"); err != nil {
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700874 return fmt.Errorf("git user.email is not set. Please run 'git config --global user.email \"your.email@example.com\"' to set your email address")
Earl Lee2e463fb2025-04-17 11:22:22 -0700875 } else {
876 gitUserEmail = strings.TrimSpace(string(out))
877 }
878 if out, err := combinedOutput(ctx, "git", "config", "--get", "user.name"); err != nil {
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700879 return fmt.Errorf("git user.name is not set. Please run 'git config --global user.name \"Your Name\"' to set your name")
Earl Lee2e463fb2025-04-17 11:22:22 -0700880 } else {
881 gitUserName = strings.TrimSpace(string(out))
882 }
883
884 start := time.Now()
Philip Zeyliger2343f8a2025-06-17 06:16:19 -0700885 cmdArgs := []string{
886 "build",
Earl Lee2e463fb2025-04-17 11:22:22 -0700887 "-t", imgName,
888 "-f", dockerfilePath,
Philip Zeyliger2343f8a2025-06-17 06:16:19 -0700889 "--build-arg", "GIT_USER_EMAIL=" + gitUserEmail,
890 "--build-arg", "GIT_USER_NAME=" + gitUserName,
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700891 ".",
Philip Zeyliger2343f8a2025-06-17 06:16:19 -0700892 }
893
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000894 commonDir, err := gitCommonDir(ctx, gitRoot)
895 if err != nil {
896 return fmt.Errorf("failed to get git common dir: %w", err)
897 }
898
Philip Zeyliger2343f8a2025-06-17 06:16:19 -0700899 cmd := exec.CommandContext(ctx, "docker", cmdArgs...)
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000900 cmd.Dir = commonDir
David Crawshaw31f15242025-05-06 16:03:49 -0700901 // We print the docker build output whether or not the user
902 // has selected --verbose. Building an image takes a while
903 // and this gives good context.
David Crawshawb5f6a002025-05-05 08:27:16 -0700904 cmd.Stdout = os.Stdout
905 cmd.Stderr = os.Stderr
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700906 fmt.Printf("🏗️ building docker image %s from base %s...\n", imgName, baseImage)
Earl Lee2e463fb2025-04-17 11:22:22 -0700907
908 err = run(ctx, "docker build", cmd)
909 if err != nil {
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700910 return fmt.Errorf("docker build failed: %v", err)
Earl Lee2e463fb2025-04-17 11:22:22 -0700911 }
912 fmt.Printf("built docker image %s in %s\n", imgName, time.Since(start).Round(time.Millisecond))
Philip Zeyliger983b58a2025-07-02 19:42:08 -0700913 return nil
Earl Lee2e463fb2025-04-17 11:22:22 -0700914}
915
Philip Zeyligerd6d12d12025-05-19 19:19:21 -0700916func checkForEmptyGitRepo(ctx context.Context, path string) error {
917 cmd := exec.CommandContext(ctx, "git", "rev-parse", "-q", "--verify", "HEAD")
918 cmd.Dir = path
919 _, err := cmd.CombinedOutput()
920 if err != nil {
921 return fmt.Errorf("sketch needs to run from within a git repo with at least one commit.\nRun: %s",
922 "git commit --allow-empty -m 'initial commit'")
923 }
924 return nil
925}
926
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000927// requireGitRepo confirms that path is within a git repository.
928func requireGitRepo(ctx context.Context, path string) error {
929 cmd := exec.CommandContext(ctx, "git", "rev-parse", "--git-dir")
Earl Lee2e463fb2025-04-17 11:22:22 -0700930 cmd.Dir = path
931 out, err := cmd.CombinedOutput()
932 if err != nil {
933 if strings.Contains(string(out), "not a git repository") {
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000934 return fmt.Errorf(`sketch needs to run from within a git repo, but %s is not part of a git repo.
Earl Lee2e463fb2025-04-17 11:22:22 -0700935Consider one of the following options:
936 - cd to a different dir that is already part of a git repo first, or
937 - to create a new git repo from this directory (%s), run this command:
938
939 git init . && git commit --allow-empty -m "initial commit"
940
941and try running sketch again.
942`, path, path)
943 }
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000944 return fmt.Errorf("git rev-parse --git-dir: %s: %w", out, err)
945 }
946 return nil
947}
948
949// gitRepoRoot attempts to find the git repository root directory.
950// Returns an error if not in a git repository or if it's a bare repository.
951// This is used to calculate relative paths for preserving user's working directory context.
952func gitRepoRoot(ctx context.Context, path string) (string, error) {
953 cmd := exec.CommandContext(ctx, "git", "rev-parse", "--show-toplevel")
954 cmd.Dir = path
955 out, err := cmd.CombinedOutput()
956 if err != nil {
Marc-Antoine Ruel467c3962025-06-29 13:32:59 -0400957 return "", fmt.Errorf("git rev-parse --show-toplevel: %s: %w", out, err)
Earl Lee2e463fb2025-04-17 11:22:22 -0700958 }
Marc-Antoine Ruel467c3962025-06-29 13:32:59 -0400959 // The returned path is absolute.
960 return strings.TrimSpace(string(out)), nil
Earl Lee2e463fb2025-04-17 11:22:22 -0700961}
962
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +0000963// gitCommonDir finds the git common directory for path.
964func gitCommonDir(ctx context.Context, path string) (string, error) {
965 cmd := exec.CommandContext(ctx, "git", "rev-parse", "--git-common-dir")
966 cmd.Dir = path
967 out, err := cmd.CombinedOutput()
968 if err != nil {
969 return "", fmt.Errorf("git rev-parse --git-common-dir: %s: %w", out, err)
970 }
971 gitCommonDir := strings.TrimSpace(string(out))
972 if !filepath.IsAbs(gitCommonDir) {
973 gitCommonDir = filepath.Join(path, gitCommonDir)
974 }
975 return gitCommonDir, nil
976}
977
Josh Bleecher Snyderfa424f52025-07-11 18:43:55 +0000978// goModuleInfo represents a Go module with its file paths and blob SHAs
979type goModuleInfo struct {
980 // modPath is the path to the go.mod file, for debugging
981 modPath string
982 // modSHA is the git blob SHA of the go.mod file
983 modSHA string
984 // sumSHA is the git blob SHA of the go.sum file, empty if no go.sum exists
985 sumSHA string
986}
987
988// collectGoModules returns all go.mod files in the git repository with their blob SHAs.
989func collectGoModules(ctx context.Context, gitRoot string) ([]goModuleInfo, error) {
990 cmd := exec.CommandContext(ctx, "git", "ls-files", "-z", "*.mod")
991 cmd.Dir = gitRoot
992 out, err := cmd.CombinedOutput()
993 if err != nil {
994 return nil, fmt.Errorf("git ls-files -z *.mod: %s: %w", out, err)
995 }
996
997 modFiles := strings.Split(string(out), "\x00")
998 var modules []goModuleInfo
999 for _, file := range modFiles {
1000 if filepath.Base(file) != "go.mod" {
1001 continue
1002 }
1003
1004 modSHA, err := getGitBlobSHA(ctx, gitRoot, file)
1005 if err != nil {
1006 return nil, fmt.Errorf("failed to get blob SHA for %s: %w", file, err)
1007 }
1008
1009 // If corresponding go.sum exists, get its SHA
1010 sumFile := filepath.Join(filepath.Dir(file), "go.sum")
1011 sumSHA, _ := getGitBlobSHA(ctx, gitRoot, sumFile) // best effort
1012
1013 modules = append(modules, goModuleInfo{
1014 modPath: file,
1015 modSHA: modSHA,
1016 sumSHA: sumSHA,
1017 })
1018 }
1019
1020 return modules, nil
1021}
1022
1023// getGitBlobSHA returns the git blob SHA for a file at HEAD
1024func getGitBlobSHA(ctx context.Context, gitRoot, filePath string) (string, error) {
1025 cmd := exec.CommandContext(ctx, "git", "rev-parse", "HEAD:"+filePath)
1026 cmd.Dir = gitRoot
1027 out, err := cmd.CombinedOutput()
1028 if err != nil {
1029 return "", fmt.Errorf("git rev-parse HEAD:%s: %s: %w", filePath, out, err)
1030 }
1031 return strings.TrimSpace(string(out)), nil
1032}
1033
Josh Bleecher Snyder2772f632025-05-01 21:42:35 +00001034// getEnvForwardingFromGitConfig retrieves environment variables to pass through to Docker
1035// from git config using the sketch.envfwd multi-valued key.
1036func getEnvForwardingFromGitConfig(ctx context.Context) []string {
1037 outb, err := exec.CommandContext(ctx, "git", "config", "--get-all", "sketch.envfwd").CombinedOutput()
1038 out := string(outb)
1039 if err != nil {
1040 if strings.Contains(out, "key does not exist") {
1041 return nil
1042 }
1043 slog.ErrorContext(ctx, "failed to get sketch.envfwd from git config", "err", err, "output", out)
1044 return nil
1045 }
1046
1047 var envVars []string
1048 for envVar := range strings.Lines(out) {
1049 envVar = strings.TrimSpace(envVar)
1050 if envVar == "" {
1051 continue
1052 }
1053 envVars = append(envVars, envVar+"="+os.Getenv(envVar))
1054 }
1055 return envVars
1056}
Philip Zeyliger1dc21372025-05-05 19:54:44 +00001057
Josh Bleecher Snyder784d5bd2025-07-11 00:09:30 +00001058// getOriginalGitOrigin returns the URL of the git remote 'origin' if it exists in the given directory
1059func getOriginalGitOrigin(ctx context.Context, dir string) string {
1060 cmd := exec.CommandContext(ctx, "git", "config", "--get", "remote.origin.url")
1061 cmd.Dir = dir
1062 out, err := cmd.Output()
1063 if err != nil {
1064 return ""
1065 }
1066 return strings.TrimSpace(string(out))
1067}
1068
Philip Zeyliger1dc21372025-05-05 19:54:44 +00001069// parseDockerArgs parses a string containing space-separated Docker arguments into an array of strings.
1070// It handles quoted arguments and escaped characters.
1071//
1072// Examples:
1073//
1074// --memory=2g --cpus=2 -> ["--memory=2g", "--cpus=2"]
1075// --label="my label" --env=FOO=bar -> ["--label=my label", "--env=FOO=bar"]
1076// --env="KEY=\"quoted value\"" -> ["--env=KEY=\"quoted value\""]
1077func parseDockerArgs(args string) []string {
1078 if args = strings.TrimSpace(args); args == "" {
1079 return []string{}
1080 }
1081
1082 var result []string
1083 var current strings.Builder
1084 inQuotes := false
1085 escapeNext := false
1086 quoteChar := rune(0)
1087
1088 for _, char := range args {
1089 if escapeNext {
1090 current.WriteRune(char)
1091 escapeNext = false
1092 continue
1093 }
1094
1095 if char == '\\' {
1096 escapeNext = true
1097 continue
1098 }
1099
1100 if char == '"' || char == '\'' {
1101 if !inQuotes {
1102 inQuotes = true
1103 quoteChar = char
1104 continue
1105 } else if char == quoteChar {
1106 inQuotes = false
1107 quoteChar = rune(0)
1108 continue
1109 }
1110 // Non-matching quote character inside quotes
1111 current.WriteRune(char)
1112 continue
1113 }
1114
1115 // Space outside of quotes is an argument separator
1116 if char == ' ' && !inQuotes {
1117 if current.Len() > 0 {
1118 result = append(result, current.String())
1119 current.Reset()
1120 }
1121 continue
1122 }
1123
1124 current.WriteRune(char)
1125 }
1126
1127 // Add the last argument if there is one
1128 if current.Len() > 0 {
1129 result = append(result, current.String())
1130 }
1131
1132 return result
1133}
Philip Zeyliger4acf0062025-05-22 13:53:46 -07001134
Josh Bleecher Snyder1c18ec92025-07-08 10:55:54 -07001135// copyEmbeddedLinuxBinaryToContainer copies the embedded linux binary to the container
1136func copyEmbeddedLinuxBinaryToContainer(ctx context.Context, containerName string) error {
Josh Bleecher Snyder5ae245b2025-07-08 22:00:24 +00001137 out, err := combinedOutput(ctx, "docker", "version", "--format", "{{.Server.Arch}}")
1138 if err != nil {
1139 return fmt.Errorf("failed to detect Docker server architecture: %s: %w", out, err)
1140 }
1141 arch := strings.TrimSpace(string(out))
1142
1143 bin := embedded.LinuxBinary(arch)
Josh Bleecher Snyder1c18ec92025-07-08 10:55:54 -07001144 if bin == nil {
Josh Bleecher Snyder5ae245b2025-07-08 22:00:24 +00001145 return fmt.Errorf("no embedded linux binary for architecture %q", arch)
Josh Bleecher Snyder1c18ec92025-07-08 10:55:54 -07001146 }
1147
Josh Bleecher Snyderc9898fd2025-07-08 21:09:18 +00001148 // Stream a tarball to docker cp.
1149 pr, pw := io.Pipe()
Josh Bleecher Snyder1c18ec92025-07-08 10:55:54 -07001150
Josh Bleecher Snyderc9898fd2025-07-08 21:09:18 +00001151 errCh := make(chan error, 1)
1152 go func() {
1153 defer pw.Close()
1154 tw := tar.NewWriter(pw)
1155
1156 hdr := &tar.Header{
1157 Name: "bin/sketch", // final path inside the container
1158 Mode: 0o700,
1159 Size: int64(len(bin)),
Josh Bleecher Snyder1c18ec92025-07-08 10:55:54 -07001160 }
Josh Bleecher Snyderc9898fd2025-07-08 21:09:18 +00001161 if err := tw.WriteHeader(hdr); err != nil {
1162 errCh <- fmt.Errorf("failed to write tar header: %w", err)
1163 return
1164 }
1165 if _, err := tw.Write(bin); err != nil {
1166 errCh <- fmt.Errorf("failed to write binary to tar: %w", err)
1167 return
1168 }
1169 if err := tw.Close(); err != nil {
1170 errCh <- fmt.Errorf("failed to close tar writer: %w", err)
1171 return
1172 }
1173 errCh <- nil
1174 }()
Josh Bleecher Snyder1c18ec92025-07-08 10:55:54 -07001175
Josh Bleecher Snyderc9898fd2025-07-08 21:09:18 +00001176 cmd := exec.CommandContext(ctx, "docker", "cp", "-", containerName+":/")
1177 cmd.Stdin = pr
Josh Bleecher Snyder1c18ec92025-07-08 10:55:54 -07001178
Josh Bleecher Snyderc9898fd2025-07-08 21:09:18 +00001179 out, cmdErr := cmd.CombinedOutput()
1180
1181 if tarErr := <-errCh; tarErr != nil {
1182 return tarErr
1183 }
1184 if cmdErr != nil {
1185 return fmt.Errorf("docker cp failed: %s: %w", out, cmdErr)
1186 }
Josh Bleecher Snyder1c18ec92025-07-08 10:55:54 -07001187 return nil
1188}
1189
David Crawshaw1bd636c2025-06-13 19:56:27 +00001190const seccompProfile = `{
1191 "defaultAction": "SCMP_ACT_ALLOW",
1192 "syscalls": [
1193 {
1194 "names": ["kill", "tkill", "tgkill", "pidfd_send_signal"],
1195 "action": "SCMP_ACT_ERRNO",
1196 "args": [
1197 {
1198 "index": 0,
1199 "value": 1,
1200 "op": "SCMP_CMP_EQ"
1201 }
1202 ]
1203 }
1204 ]
1205}`
1206
1207// ensureSeccompProfile creates the seccomp profile file in the sketch cache directory if it doesn't exist.
1208func ensureSeccompProfile(ctx context.Context) (seccompPath string, err error) {
1209 homeDir, err := os.UserHomeDir()
1210 if err != nil {
1211 return "", fmt.Errorf("failed to get home directory: %w", err)
1212 }
1213 cacheDir := filepath.Join(homeDir, ".cache", "sketch")
1214 if err := os.MkdirAll(cacheDir, 0o755); err != nil {
1215 return "", fmt.Errorf("failed to create cache directory: %w", err)
1216 }
1217 seccompPath = filepath.Join(cacheDir, "seccomp-no-kill-1.json")
1218
1219 curBytes, err := os.ReadFile(seccompPath)
1220 if err != nil && !os.IsNotExist(err) {
1221 return "", fmt.Errorf("failed to read seccomp profile file %s: %w", seccompPath, err)
1222 }
1223 if string(curBytes) == seccompProfile {
1224 return seccompPath, nil // File already exists and matches the expected profile
1225 }
1226
1227 if err := os.WriteFile(seccompPath, []byte(seccompProfile), 0o644); err != nil {
1228 return "", fmt.Errorf("failed to write seccomp profile to %s: %w", seccompPath, err)
1229 }
1230 slog.DebugContext(ctx, "created seccomp profile", "path", seccompPath)
1231 return seccompPath, nil
1232}