-
Notifications
You must be signed in to change notification settings - Fork 112
feat: build apisix-runtime with ngx_http_ffi_client #480
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -36,6 +36,24 @@ fi | |
| wasm_nginx_module_ver="0.7.0" | ||
| lua_var_nginx_module_ver="v0.5.3" | ||
| lua_resty_events_ver="0.2.0" | ||
| # api7/ngx_http_ffi_client is still a private repository and carries no tags, | ||
| # so it is pinned by commit and fetched with a token. A build without the token | ||
| # leaves the module out and is otherwise unchanged. | ||
| ngx_http_ffi_client_ver=${ngx_http_ffi_client_ver:-"f13fcfa4e923ad82844bf49d9d3b3d283371ef66"} | ||
| if [[ ! "$ngx_http_ffi_client_ver" =~ ^[A-Za-z0-9._/-]+$ ]]; then | ||
| echo "ERROR: invalid ngx_http_ffi_client_ver: $ngx_http_ffi_client_ver" >&2 | ||
| exit 1 | ||
| fi | ||
| # the trace stays off around the token, and only the derived yes/no reaches it | ||
| set +x | ||
| NGX_HTTP_FFI_CLIENT_TOKEN=${NGX_HTTP_FFI_CLIENT_TOKEN:-} | ||
| if [ -n "$NGX_HTTP_FFI_CLIENT_TOKEN" ]; then | ||
| ngx_http_ffi_client_have_token="yes" | ||
| else | ||
| ngx_http_ffi_client_have_token="no" | ||
| fi | ||
|
Comment on lines
+49
to
+54
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
# Inspect the token lifecycle without executing the build.
rg -n -C 8 \
'NGX_HTTP_FFI_CLIENT_TOKEN|unset|env -u|git|Authorization|http\.extraHeader|https?://' \
build-apisix-runtime.shRepository: api7/apisix-build-tools Length of output: 5890 🏁 Script executed: #!/bin/bash
set -euo pipefail
# Inspect the exact credentialed fetch and all subsequent child-process launches.
sed -n '1,12p;145,190p;213,245p' build-apisix-runtime.sh
# Confirm Bash keeps an imported variable exported after the assignment used by the script.
env NGX_HTTP_FFI_CLIENT_TOKEN='probe-token' bash -c '
NGX_HTTP_FFI_CLIENT_TOKEN=${NGX_HTTP_FFI_CLIENT_TOKEN:-}
printf "parent-exported=%s\n" "$(export -p | grep -c "NGX_HTTP_FFI_CLIENT_TOKEN")"
printf "child-value=%s\n" "$(env | sed -n "s/^NGX_HTTP_FFI_CLIENT_TOKEN=//p")"
'Repository: api7/apisix-build-tools Length of output: 3714 Sensitive Data Exposure (CWE-526) Reachability: External Clear 🧰 Tools🪛 ast-grep (0.45.0)[warning] 50-50: A credential-bearing variable (e.g. PASSWORD, PASSWD, SECRET, TOKEN, API_KEY) is assigned a hardcoded string literal. Secrets committed to a script are exposed in source control, process listings, and shell history, and cannot be rotated without a code change. Read the value from a secrets manager or an injected environment variable at runtime instead (e.g. (hardcoded-password-assignment-bash) [warning] 52-52: A credential-bearing variable (e.g. PASSWORD, PASSWD, SECRET, TOKEN, API_KEY) is assigned a hardcoded string literal. Secrets committed to a script are exposed in source control, process listings, and shell history, and cannot be rotated without a code change. Read the value from a secrets manager or an injected environment variable at runtime instead (e.g. (hardcoded-password-assignment-bash) 🤖 Prompt for AI Agents |
||
| set -x | ||
| ngx_http_ffi_client_dir="ngx_http_ffi_client-${ngx_http_ffi_client_ver}" | ||
|
|
||
|
|
||
| install_openssl_3(){ | ||
|
|
@@ -134,6 +152,33 @@ else | |
| lua-var-nginx-module-${lua_var_nginx_module_ver} | ||
| fi | ||
|
|
||
| if [ "$repo" == ngx_http_ffi_client ]; then | ||
| cp -r "$prev_workdir" "./$ngx_http_ffi_client_dir" | ||
| elif [ "$ngx_http_ffi_client_have_token" == "yes" ]; then | ||
| # A private repository pinned by commit, so fetch rather than clone -b. | ||
| # The token stays off the trace and out of the repository's git config. | ||
| mkdir "$ngx_http_ffi_client_dir" | ||
| ( | ||
| set +x | ||
| cd "$ngx_http_ffi_client_dir" || exit 1 | ||
| git init -q | ||
| git -c "http.extraheader=Authorization: Basic $(printf 'x-access-token:%s' \ | ||
| "$NGX_HTTP_FFI_CLIENT_TOKEN" | base64 | tr -d '\n')" \ | ||
| fetch -q --depth=1 \ | ||
| https://github.com/api7/ngx_http_ffi_client.git "$ngx_http_ffi_client_ver" | ||
| git checkout -q FETCH_HEAD | ||
| ) | ||
| else | ||
| echo "WARNING: NGX_HTTP_FFI_CLIENT_TOKEN is not set, building apisix-runtime" \ | ||
| "without ngx_http_ffi_client. ai-proxy falls back to lua-resty-http" \ | ||
| "on such a runtime." >&2 | ||
| fi | ||
|
|
||
| ngx_http_ffi_client_configure_arg="" | ||
| if [ -d "$ngx_http_ffi_client_dir" ]; then | ||
| ngx_http_ffi_client_configure_arg="--add-module=../$ngx_http_ffi_client_dir" | ||
| fi | ||
|
|
||
| cd ngx_multi_upstream_module-${ngx_multi_upstream_module_ver} || exit 1 | ||
| ./patch.sh ../openresty-${OPENRESTY_VERSION} | ||
| cd .. | ||
|
|
@@ -165,6 +210,11 @@ else | |
| fi | ||
|
|
||
|
|
||
| # ngx_http_ffi_client compiles against lua-nginx-module's public API, which it | ||
| # reaches through the bundled copy rather than a separate checkout. | ||
| ngx_lua_bundle_dir=$(find bundle -maxdepth 1 -type d -name 'ngx_lua-*' | head -n 1) | ||
| export NGX_HTTP_LUA_MODULE_DIR="$PWD/$ngx_lua_bundle_dir" | ||
|
|
||
| ./configure --prefix="$OR_PREFIX" \ | ||
| --with-cc-opt="-DAPISIX_RUNTIME_VER=$runtime_version $cc_opt" \ | ||
| --with-ld-opt="-Wl,-rpath,$OR_PREFIX/wasmtime-c-api/lib $ld_opt" \ | ||
|
|
@@ -177,6 +227,7 @@ fi | |
| --add-module=../wasm-nginx-module-${wasm_nginx_module_ver} \ | ||
| --add-module=../lua-var-nginx-module-${lua_var_nginx_module_ver} \ | ||
| --add-module=../lua-resty-events-${lua_resty_events_ver} \ | ||
| $ngx_http_ffi_client_configure_arg \ | ||
| --with-poll_module \ | ||
| --with-pcre-jit \ | ||
| --without-http_rds_json_module \ | ||
|
|
@@ -220,6 +271,13 @@ sudo install -d "$OR_PREFIX"/lualib/resty/events/compat/ | |
| sudo install -m 644 lualib/resty/events/compat/*.lua "$OR_PREFIX"/lualib/resty/events/compat/ | ||
| cd .. | ||
|
|
||
| if [ -d "$ngx_http_ffi_client_dir" ]; then | ||
| # the C module needs its FFI bindings on the runtime's lua_package_path | ||
| sudo install -d "$OR_PREFIX"/lualib/resty/ | ||
| sudo install -m 644 "$ngx_http_ffi_client_dir"/lib/resty/ngx_http_ffi_client.lua \ | ||
| "$OR_PREFIX"/lualib/resty/ | ||
| fi | ||
|
|
||
| cd "apisix-nginx-module-${apisix_nginx_module_ver}" || exit 1 | ||
| sudo OPENRESTY_PREFIX="$OR_PREFIX" make install | ||
| cd .. | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: api7/apisix-build-tools
Length of output: 21159
Dependency Pin Bypass (CWE-829): Inclusion of Functionality from Untrusted Control Sphere
Enforce the fixed
ngx_http_ffi_clientcommit.ngx_http_ffi_client_veraccepts refs such asmain. When the token is set,git fetchretrieves that ref and compiles it into the runtime. Require the exact approved commitf13fcfa4e923ad82844bf49d9d3b3d283371ef66, verify the fetched commit, and keepREADME.mdconsistent.📍 Affects 2 files
build-apisix-runtime.sh#L42-L46(this comment)build-apisix-runtime.sh#L147-L172README.md#L124-L125🤖 Prompt for AI Agents