diff --git a/go.mod b/go.mod index f5933bf0..f5b77cbb 100644 --- a/go.mod +++ b/go.mod @@ -5,7 +5,7 @@ go 1.24.0 require ( github.com/Dynatrace/libbuildpack-dynatrace v1.8.0 github.com/blang/semver v3.5.1+incompatible - github.com/cloudfoundry/libbuildpack v0.0.0-20260306125332-dcaf55eb6f33 + github.com/cloudfoundry/libbuildpack v0.0.0-20260415084012-70e599bbe72c github.com/cloudfoundry/switchblade v0.9.5 github.com/golang/mock v1.6.0 github.com/kr/text v0.2.0 diff --git a/go.sum b/go.sum index 537e7c72..b353742f 100644 --- a/go.sum +++ b/go.sum @@ -746,8 +746,8 @@ github.com/circonus-labs/circonus-gometrics v2.3.1+incompatible/go.mod h1:nmEj6D github.com/circonus-labs/circonusllhist v0.1.3/go.mod h1:kMXHVDlOchFAehlya5ePtbp5jckzBHf4XRpQvBOLI+I= github.com/client9/misspell v0.3.4/go.mod h1:qj6jICC3Q7zFZvVWo7KLAzC3yx5G7kyvSDkc90ppPyw= github.com/cloudflare/circl v1.1.0/go.mod h1:prBCrKB9DV4poKZY1l9zBXg2QJY7mvgRvtMxxK7fi4I= -github.com/cloudfoundry/libbuildpack v0.0.0-20260306125332-dcaf55eb6f33 h1:O3uSzqYH1x5yK/awqNJiwcxohLHfPkXO4KOgVHgCg4o= -github.com/cloudfoundry/libbuildpack v0.0.0-20260306125332-dcaf55eb6f33/go.mod h1:Qtj1XicpoDn88w2cvVCYtw1Whq+kK3bouin0xNZ9lIU= +github.com/cloudfoundry/libbuildpack v0.0.0-20260415084012-70e599bbe72c h1:BMlBv4TunN2BTh8CgVL1Hf8iiKCCIk5eD64Dg9fU4GM= +github.com/cloudfoundry/libbuildpack v0.0.0-20260415084012-70e599bbe72c/go.mod h1:Qtj1XicpoDn88w2cvVCYtw1Whq+kK3bouin0xNZ9lIU= github.com/cloudfoundry/switchblade v0.9.5 h1:GTga1Uu6kGOL+n1TRTHyZm170N5/B/ou6wU90MiKKys= github.com/cloudfoundry/switchblade v0.9.5/go.mod h1:hIEQdGAsuNnzlyQfsD5OIORt38weSBar6Wq5/JX6Omo= github.com/cncf/udpa/go v0.0.0-20191209042840-269d4d468f6f/go.mod h1:M8M6+tZqaGXZJjfX53e64911xZQV5JYwmTeXPW+k8Sc= diff --git a/vendor/github.com/cloudfoundry/libbuildpack/packager/README.md b/vendor/github.com/cloudfoundry/libbuildpack/packager/README.md index cb626df5..d4533c04 100644 --- a/vendor/github.com/cloudfoundry/libbuildpack/packager/README.md +++ b/vendor/github.com/cloudfoundry/libbuildpack/packager/README.md @@ -20,3 +20,142 @@ For more on go-bindata: https://github.com/jteeuwen/go-bindata ``` ginkgo -r ``` + +--- + +## Selective Dependency Packaging + +`buildpack-packager` supports building **cached** buildpacks that contain only a named +subset of dependencies. This is useful for operators who need a smaller artifact or a +pre-defined variant (e.g. a "minimal" build without optional agent libraries). + +> **Note:** `--profile`, `--exclude`, and `--include` are only valid for **cached** +> buildpacks (`--cached` flag). Using them on an uncached build is a hard error. + +### Packaging profiles + +A buildpack author defines named profiles in `manifest.yml` under the +`packaging_profiles` key: + +```yaml +packaging_profiles: + minimal: + description: "Core runtime only — no agents or profilers" + exclude: + - agent-dep + - profiler-dep + + no-profiler: + description: "Full build minus the profiler library" + exclude: + - profiler-dep +``` + +Each profile has: + +| Field | Type | Description | +|---------------|----------------|-------------| +| `description` | string | Human-readable summary shown by `buildpack-packager summary` | +| `exclude` | list of string | Dependency names to omit when this profile is active | + +Profile names must match `^[a-z0-9_-]+$` (lowercase letters, digits, hyphens, +underscores). This keeps names safe for embedding in zip filenames. + +All dependency names listed in a profile's `exclude` list must exist in the +manifest — a typo is a hard error at packaging time. + +### CLI flags + +| Flag | Argument | Description | +|------|----------|-------------| +| `--profile` | profile name | Activate a named profile from `manifest.yml` | +| `--exclude` | `dep1,dep2,...` | Additional dependencies to exclude (comma-separated) | +| `--include` | `dep1,dep2,...` | Restore dependencies that the active profile excluded | + +#### Examples + +```sh +# Build with the "minimal" profile (omits agent-dep and profiler-dep) +buildpack-packager --cached --stack cflinuxfs4 --profile minimal + +# Build with the "minimal" profile but restore profiler-dep +buildpack-packager --cached --stack cflinuxfs4 --profile minimal --include profiler-dep + +# No profile — just exclude a specific dependency +buildpack-packager --cached --stack cflinuxfs4 --exclude agent-dep + +# Combine a profile with an extra exclusion +buildpack-packager --cached --stack cflinuxfs4 --profile no-profiler --exclude agent-dep +``` + +### Resolution order + +1. Profile's `exclude` list is applied first. +2. `--exclude` names are **unioned** with the profile exclusions. +3. `--include` names are **removed** from the exclusion set (overrides the profile). + +Excluded dependencies are neither downloaded nor written into the packaged +`manifest.yml`. + +### Output filename + +The zip filename encodes which variant was built: + +| Options used | Filename pattern | +|---|---| +| No opts | `_buildpack-cached--v.zip` | +| `--profile minimal` | `_buildpack-cached-minimal--v.zip` | +| `--profile minimal --include profiler-dep` | `_buildpack-cached-minimal+custom--v.zip` | +| `--profile minimal --exclude extra-dep` | `_buildpack-cached-minimal+custom--v.zip` | +| `--exclude agent-dep` (no profile) | `_buildpack-cached-custom--v.zip` | + +The `+custom` suffix appears only when the result deviates from a pure profile: +either an extra `--exclude` was added, or `--include` actually overrode one of +the profile's exclusions. + +### Error conditions + +All validation errors are **hard errors** — the packager exits non-zero with a +descriptive message. There are no silent no-ops or warnings. + +| Situation | Error message | +|---|---| +| `--profile` / `--exclude` / `--include` on uncached build | `--profile/--exclude/--include are only valid for cached buildpacks` | +| `--include` without `--profile` | `--include requires --profile` | +| Unknown profile name | `packaging profile "" not found in manifest` | +| Invalid profile name characters | `profile name "" is invalid: must match ^[a-z0-9_-]+$` | +| Unknown dep in `--exclude` | `dependency "" not found in manifest` | +| Unknown dep in `--include` | `dependency "" not found in manifest` | +| `--include` of dep not excluded by profile | `--include "" has no effect: dependency is not excluded by the profile or --exclude` | +| Profile's `exclude` list references unknown dep | `profile "" references unknown dependency ""` | + +### Go API + +`Package()` is unchanged and delegates to `PackageWithOptions` with zero options: + +```go +// Legacy — unchanged behaviour +zipFile, err := packager.Package(bpDir, cacheDir, version, stack, cached) + +// New — selective packaging +zipFile, err := packager.PackageWithOptions(bpDir, cacheDir, version, stack, true, + packager.PackageOptions{ + Profile: "minimal", + Include: []string{"profiler-dep"}, + }) +``` + +`PackageOptions` fields: + +```go +type PackageOptions struct { + // Profile is a packaging_profiles key from manifest.yml. + Profile string + // Exclude lists additional dependency names to skip. + Exclude []string + // Include restores dependency names excluded by Profile. + // Requires Profile to be set. Hard error if a name was not excluded. + Include []string +} +``` + diff --git a/vendor/github.com/cloudfoundry/libbuildpack/packager/models.go b/vendor/github.com/cloudfoundry/libbuildpack/packager/models.go index e9150d91..d4b309f0 100644 --- a/vendor/github.com/cloudfoundry/libbuildpack/packager/models.go +++ b/vendor/github.com/cloudfoundry/libbuildpack/packager/models.go @@ -15,6 +15,12 @@ type Dependency struct { type SubDependency struct{ Name string } type Dependencies []Dependency +// PackagingProfile defines a named dependency exclusion set for use at packaging time. +type PackagingProfile struct { + Description string `yaml:"description"` + Exclude []string `yaml:"exclude"` +} + type Manifest struct { Language string `yaml:"language"` Stack string `yaml:"stack"` @@ -25,6 +31,7 @@ type Manifest struct { Name string `yaml:"name"` Version string `yaml:"version"` } `yaml:"default_versions"` + PackagingProfiles map[string]PackagingProfile `yaml:"packaging_profiles"` } type File struct { diff --git a/vendor/github.com/cloudfoundry/libbuildpack/packager/packager.go b/vendor/github.com/cloudfoundry/libbuildpack/packager/packager.go index 2f081068..b0c61b04 100644 --- a/vendor/github.com/cloudfoundry/libbuildpack/packager/packager.go +++ b/vendor/github.com/cloudfoundry/libbuildpack/packager/packager.go @@ -15,12 +15,17 @@ import ( "os" "os/exec" "path/filepath" + "regexp" "strings" "github.com/cloudfoundry/libbuildpack" "gopkg.in/yaml.v2" ) +// profileNameRe restricts profile names to safe characters that can be +// embedded in a zip filename without escaping or path-traversal risk. +var profileNameRe = regexp.MustCompile(`^[a-z0-9_-]+$`) + type sha struct { Sha map[string]string `yaml:"sha"` } @@ -152,7 +157,92 @@ func downloadDependency(dependency Dependency, cacheDir string) (File, error) { return File{file, filepath.Join(cacheDir, file)}, nil } +// PackageOptions configures optional selective-packaging behaviour for PackageWithOptions. +// All fields are optional; zero values produce identical output to the legacy Package function. +type PackageOptions struct { + // Profile is the name of a packaging_profiles entry in manifest.yml. + // Its exclude list is applied before Exclude and Include are processed. + Profile string + // Exclude is an additional list of dependency names to skip, unioned with + // any exclusions implied by Profile. + Exclude []string + // Include restores specific dependency names that would otherwise be excluded + // by Profile. It is a no-op (with a warning) when Profile is empty. + Include []string +} + +// resolveExclusions returns the set of dependency names that should be skipped +// during packaging, and the count of include names that actually overrode a +// profile exclusion (used by the caller to decide the +custom filename suffix). +// Resolution order: +// 1. Profile's exclude list (if a profile is named). +// 2. Explicit Exclude names are unioned in. +// 3. Explicit Include names are removed (overrides profile exclusions). +// +// An error is returned if the profile name is unknown or if any exclude/include +// name does not exist in the manifest (including names in the profile's exclude +// list itself). +func resolveExclusions(manifest Manifest, profile string, exclude []string, include []string) (map[string]struct{}, int, error) { + // Build a set of all known dependency names for validation. + depNames := make(map[string]struct{}, len(manifest.Dependencies)) + for _, d := range manifest.Dependencies { + depNames[d.Name] = struct{}{} + } + + // 1. Start with profile exclusions. + result := make(map[string]struct{}) + if profile != "" { + if !profileNameRe.MatchString(profile) { + return nil, 0, fmt.Errorf("profile name %q is invalid: must match ^[a-z0-9_-]+$", profile) + } + p, ok := manifest.PackagingProfiles[profile] + if !ok { + return nil, 0, fmt.Errorf("packaging profile %q not found in manifest", profile) + } + for _, name := range p.Exclude { + if _, ok := depNames[name]; !ok { + return nil, 0, fmt.Errorf("profile %q references unknown dependency %q", profile, name) + } + result[name] = struct{}{} + } + } + + // 2. Union with explicitly excluded names. + for _, name := range exclude { + if _, ok := depNames[name]; !ok { + return nil, 0, fmt.Errorf("dependency %q not found in manifest", name) + } + result[name] = struct{}{} + } + + // 3. Remove explicitly included names (overrides profile). + // Count how many of these actually removed something from the set. + // It is a hard error to --include a name that was never excluded (likely a typo). + effectiveIncludes := 0 + for _, name := range include { + if _, ok := depNames[name]; !ok { + return nil, 0, fmt.Errorf("dependency %q not found in manifest", name) + } + if _, wasExcluded := result[name]; !wasExcluded { + return nil, 0, fmt.Errorf("--include %q has no effect: dependency is not excluded by the profile or --exclude", name) + } + effectiveIncludes++ + delete(result, name) + } + + return result, effectiveIncludes, nil +} + +// Package is the legacy entry point. It delegates to PackageWithOptions with +// zero-value options so all existing callers remain unaffected. func Package(bpDir, cacheDir, version, stack string, cached bool) (string, error) { + return PackageWithOptions(bpDir, cacheDir, version, stack, cached, PackageOptions{}) +} + +// PackageWithOptions creates a buildpack zip, optionally filtering dependencies +// according to opts (profile, exclude, include). When opts is zero-value the +// behaviour is identical to the legacy Package function. +func PackageWithOptions(bpDir, cacheDir, version, stack string, cached bool, opts PackageOptions) (string, error) { bpDir, err := filepath.Abs(bpDir) if err != nil { return "", err @@ -177,6 +267,28 @@ func Package(bpDir, cacheDir, version, stack string, cached bool) (string, error return "", err } + // --profile/--exclude/--include only apply to cached buildpacks. + if !cached && (opts.Profile != "" || len(opts.Exclude) > 0 || len(opts.Include) > 0) { + return "", fmt.Errorf("--profile/--exclude/--include are only valid for cached buildpacks") + } + + // --include requires --profile (nothing to override otherwise). + if opts.Profile == "" && len(opts.Include) > 0 { + return "", fmt.Errorf("--include requires --profile") + } + + // Resolve which dependency names to skip before the download loop. + // On uncached builds the exclusion set is never used, so skip validation. + excluded := map[string]struct{}{} + effectiveIncludes := 0 + if cached { + var err2 error + excluded, effectiveIncludes, err2 = resolveExclusions(manifest, opts.Profile, opts.Exclude, opts.Include) + if err2 != nil { + return "", err2 + } + } + if manifest.PrePackage != "" { cmd := exec.Command(manifest.PrePackage) cmd.Dir = dir @@ -207,6 +319,12 @@ func Package(bpDir, cacheDir, version, stack string, cached bool) (string, error } dependenciesForStack := []interface{}{} for idx, d := range manifest.Dependencies { + // Skip excluded dependencies — they are not downloaded and are not + // written into the packaged manifest.yml. + if _, skip := excluded[d.Name]; skip { + continue + } + for _, s := range d.Stacks { if stack == "" || s == stack { dependencyMap := deps[idx] @@ -242,7 +360,21 @@ func Package(bpDir, cacheDir, version, stack string, cached bool) (string, error cachedPart = "-cached" } - fileName := fmt.Sprintf("%s_buildpack%s%s-v%s.zip", manifest.Language, cachedPart, stackPart, version) + // Build the profile/exclusion suffix for the filename. + // +custom is only appended when there is genuine customisation on top of + // the profile: either an extra --exclude, or an --include that actually + // overrode one of the profile's exclusions (effectiveIncludes > 0). + profilePart := "" + if opts.Profile != "" { + profilePart = "-" + opts.Profile + if len(opts.Exclude) > 0 || effectiveIncludes > 0 { + profilePart += "+custom" + } + } else if len(opts.Exclude) > 0 { + profilePart = "-custom" + } + + fileName := fmt.Sprintf("%s_buildpack%s%s%s-v%s.zip", manifest.Language, cachedPart, profilePart, stackPart, version) zipFile := filepath.Join(bpDir, fileName) if err := ZipFiles(zipFile, files); err != nil { diff --git a/vendor/github.com/cloudfoundry/libbuildpack/packager/summary.go b/vendor/github.com/cloudfoundry/libbuildpack/packager/summary.go index 7381c30c..67237f8d 100644 --- a/vendor/github.com/cloudfoundry/libbuildpack/packager/summary.go +++ b/vendor/github.com/cloudfoundry/libbuildpack/packager/summary.go @@ -62,5 +62,17 @@ func Summary(bpDir string) (string, error) { } } + if len(manifest.PackagingProfiles) > 0 { + out += "\nPackaging profiles:\n\n" + profileNames := make([]string, 0, len(manifest.PackagingProfiles)) + for name := range manifest.PackagingProfiles { + profileNames = append(profileNames, name) + } + sort.Strings(profileNames) + for _, name := range profileNames { + out += fmt.Sprintf(" %-12s %s\n", name, manifest.PackagingProfiles[name].Description) + } + } + return out, nil } diff --git a/vendor/modules.txt b/vendor/modules.txt index 9803a109..8ad1072c 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -23,7 +23,7 @@ github.com/blang/semver # github.com/cenkalti/backoff/v4 v4.3.0 ## explicit; go 1.18 github.com/cenkalti/backoff/v4 -# github.com/cloudfoundry/libbuildpack v0.0.0-20260306125332-dcaf55eb6f33 +# github.com/cloudfoundry/libbuildpack v0.0.0-20260415084012-70e599bbe72c ## explicit; go 1.22.5 github.com/cloudfoundry/libbuildpack github.com/cloudfoundry/libbuildpack/ansicleaner