images.go 26.5 KB
Newer Older
1
2
3
4
package server

import (
	"bytes"
Michael Yang's avatar
Michael Yang committed
5
	"cmp"
6
	"context"
7
	"crypto/sha256"
8
	"encoding/base64"
Patrick Devine's avatar
Patrick Devine committed
9
	"encoding/hex"
10
11
12
13
14
	"encoding/json"
	"errors"
	"fmt"
	"io"
	"log"
15
	"log/slog"
16
	"net/http"
Michael Yang's avatar
Michael Yang committed
17
	"net/url"
18
19
	"os"
	"path/filepath"
Michael Yang's avatar
Michael Yang committed
20
	"runtime"
Michael Yang's avatar
Michael Yang committed
21
	"strconv"
22
23
	"strings"

Michael Yang's avatar
Michael Yang committed
24
25
	"golang.org/x/exp/slices"

26
	"github.com/ollama/ollama/api"
27
	"github.com/ollama/ollama/auth"
Michael Yang's avatar
Michael Yang committed
28
	"github.com/ollama/ollama/format"
29
	"github.com/ollama/ollama/llm"
30
	"github.com/ollama/ollama/server/envconfig"
31
	"github.com/ollama/ollama/types/errtypes"
Michael Yang's avatar
Michael Yang committed
32
	"github.com/ollama/ollama/types/model"
33
	"github.com/ollama/ollama/version"
34
35
)

Michael Yang's avatar
Michael Yang committed
36
37
38
39
40
41
42
type registryOptions struct {
	Insecure bool
	Username string
	Password string
	Token    string
}

43
type Model struct {
Michael Yang's avatar
Michael Yang committed
44
	Name           string `json:"name"`
45
	Config         ConfigV2
Michael Yang's avatar
Michael Yang committed
46
47
	ShortName      string
	ModelPath      string
48
	ParentModel    string
Michael Yang's avatar
Michael Yang committed
49
50
51
52
53
54
55
	AdapterPaths   []string
	ProjectorPaths []string
	Template       string
	System         string
	License        []string
	Digest         string
	Options        map[string]interface{}
56
57
58
	Messages       []Message
}

59
60
61
62
func (m *Model) IsEmbedding() bool {
	return slices.Contains(m.Config.ModelFamilies, "bert") || slices.Contains(m.Config.ModelFamilies, "nomic-bert")
}

Michael Yang's avatar
Michael Yang committed
63
64
65
66
67
68
69
func (m *Model) String() string {
	var modelfile model.File

	modelfile.Commands = append(modelfile.Commands, model.Command{
		Name: "model",
		Args: m.ModelPath,
	})
70

Michael Yang's avatar
Michael Yang committed
71
	for _, adapter := range m.AdapterPaths {
Michael Yang's avatar
Michael Yang committed
72
		modelfile.Commands = append(modelfile.Commands, model.Command{
Michael Yang's avatar
Michael Yang committed
73
74
			Name: "adapter",
			Args: adapter,
Michael Yang's avatar
Michael Yang committed
75
		})
76
77
	}

Michael Yang's avatar
Michael Yang committed
78
	for _, projector := range m.ProjectorPaths {
Michael Yang's avatar
Michael Yang committed
79
		modelfile.Commands = append(modelfile.Commands, model.Command{
Michael Yang's avatar
Michael Yang committed
80
81
			Name: "model",
			Args: projector,
Michael Yang's avatar
Michael Yang committed
82
		})
83
84
	}

Michael Yang's avatar
Michael Yang committed
85
	if m.Template != "" {
Michael Yang's avatar
Michael Yang committed
86
		modelfile.Commands = append(modelfile.Commands, model.Command{
Michael Yang's avatar
Michael Yang committed
87
88
			Name: "template",
			Args: m.Template,
Michael Yang's avatar
Michael Yang committed
89
		})
90
91
	}

Michael Yang's avatar
Michael Yang committed
92
	if m.System != "" {
Michael Yang's avatar
Michael Yang committed
93
		modelfile.Commands = append(modelfile.Commands, model.Command{
Michael Yang's avatar
Michael Yang committed
94
95
			Name: "system",
			Args: m.System,
Michael Yang's avatar
Michael Yang committed
96
		})
97
98
99
100
101
102
	}

	for k, v := range m.Options {
		switch v := v.(type) {
		case []any:
			for _, s := range v {
Michael Yang's avatar
Michael Yang committed
103
104
105
106
				modelfile.Commands = append(modelfile.Commands, model.Command{
					Name: k,
					Args: fmt.Sprintf("%v", s),
				})
107
108
			}
		default:
Michael Yang's avatar
Michael Yang committed
109
110
111
112
			modelfile.Commands = append(modelfile.Commands, model.Command{
				Name: k,
				Args: fmt.Sprintf("%v", v),
			})
113
114
115
116
		}
	}

	for _, license := range m.License {
Michael Yang's avatar
Michael Yang committed
117
118
119
120
		modelfile.Commands = append(modelfile.Commands, model.Command{
			Name: "license",
			Args: license,
		})
121
122
123
	}

	for _, msg := range m.Messages {
Michael Yang's avatar
Michael Yang committed
124
125
126
127
		modelfile.Commands = append(modelfile.Commands, model.Command{
			Name: "message",
			Args: fmt.Sprintf("%s %s", msg.Role, msg.Content),
		})
128
129
	}

Michael Yang's avatar
Michael Yang committed
130
	return modelfile.String()
131
132
}

133
134
135
type Message struct {
	Role    string `json:"role"`
	Content string `json:"content"`
136
137
138
139
140
}

type ManifestV2 struct {
	SchemaVersion int      `json:"schemaVersion"`
	MediaType     string   `json:"mediaType"`
Michael Yang's avatar
Michael Yang committed
141
	Config        *Layer   `json:"config"`
142
143
144
145
	Layers        []*Layer `json:"layers"`
}

type ConfigV2 struct {
146
147
148
149
150
151
	ModelFormat   string   `json:"model_format"`
	ModelFamily   string   `json:"model_family"`
	ModelFamilies []string `json:"model_families"`
	ModelType     string   `json:"model_type"`
	FileType      string   `json:"file_type"`

152
	// required by spec
153
154
	Architecture string `json:"architecture"`
	OS           string `json:"os"`
155
	RootFS       RootFS `json:"rootfs"`
156
157
158
159
160
161
162
}

type RootFS struct {
	Type    string   `json:"type"`
	DiffIDs []string `json:"diff_ids"`
}

Patrick Devine's avatar
Patrick Devine committed
163
func GetManifest(mp ModelPath) (*ManifestV2, string, error) {
164
	fp, err := mp.GetManifestPath()
165
	if err != nil {
Patrick Devine's avatar
Patrick Devine committed
166
		return nil, "", err
167
	}
168

169
	if _, err = os.Stat(fp); err != nil {
Patrick Devine's avatar
Patrick Devine committed
170
		return nil, "", err
171
172
173
174
	}

	var manifest *ManifestV2

175
	bts, err := os.ReadFile(fp)
176
	if err != nil {
Patrick Devine's avatar
Patrick Devine committed
177
		return nil, "", fmt.Errorf("couldn't open file '%s'", fp)
178
179
	}

Patrick Devine's avatar
Patrick Devine committed
180
181
182
	shaSum := sha256.Sum256(bts)
	shaStr := hex.EncodeToString(shaSum[:])

183
	if err := json.Unmarshal(bts, &manifest); err != nil {
Patrick Devine's avatar
Patrick Devine committed
184
		return nil, "", err
185
186
	}

Patrick Devine's avatar
Patrick Devine committed
187
	return manifest, shaStr, nil
188
189
190
}

func GetModel(name string) (*Model, error) {
191
	mp := ParseModelPath(name)
Patrick Devine's avatar
Patrick Devine committed
192
	manifest, digest, err := GetManifest(mp)
193
194
195
196
197
	if err != nil {
		return nil, err
	}

	model := &Model{
198
199
200
201
202
		Name:      mp.GetFullTagname(),
		ShortName: mp.GetShortTagname(),
		Digest:    digest,
		Template:  "{{ .Prompt }}",
		License:   []string{},
203
204
	}

205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
	filename, err := GetBlobsPath(manifest.Config.Digest)
	if err != nil {
		return nil, err
	}

	configFile, err := os.Open(filename)
	if err != nil {
		return nil, err
	}
	defer configFile.Close()

	if err := json.NewDecoder(configFile).Decode(&model.Config); err != nil {
		return nil, err
	}

220
	for _, layer := range manifest.Layers {
Patrick Devine's avatar
Patrick Devine committed
221
		filename, err := GetBlobsPath(layer.Digest)
222
223
224
225
		if err != nil {
			return nil, err
		}

226
227
228
		switch layer.MediaType {
		case "application/vnd.ollama.image.model":
			model.ModelPath = filename
229
			model.ParentModel = layer.From
230
		case "application/vnd.ollama.image.embed":
231
232
			// Deprecated in versions  > 0.1.2
			// TODO: remove this warning in a future version
233
			slog.Info("WARNING: model contains embeddings, but embeddings in modelfiles have been deprecated and will be ignored.")
234
235
		case "application/vnd.ollama.image.adapter":
			model.AdapterPaths = append(model.AdapterPaths, filename)
Michael Yang's avatar
Michael Yang committed
236
237
		case "application/vnd.ollama.image.projector":
			model.ProjectorPaths = append(model.ProjectorPaths, filename)
238
239
240
241
242
243
244
245
246
		case "application/vnd.ollama.image.template":
			bts, err := os.ReadFile(filename)
			if err != nil {
				return nil, err
			}

			model.Template = string(bts)
		case "application/vnd.ollama.image.system":
			bts, err := os.ReadFile(filename)
247
248
249
			if err != nil {
				return nil, err
			}
250
251

			model.System = string(bts)
252
253
254
255
256
257
258
		case "application/vnd.ollama.image.prompt":
			bts, err := os.ReadFile(filename)
			if err != nil {
				return nil, err
			}

			model.Template = string(bts)
259
		case "application/vnd.ollama.image.params":
Michael Yang's avatar
Michael Yang committed
260
261
262
263
264
			params, err := os.Open(filename)
			if err != nil {
				return nil, err
			}
			defer params.Close()
265

266
			// parse model options parameters into a map so that we can see which fields have been specified explicitly
267
			if err = json.NewDecoder(params).Decode(&model.Options); err != nil {
268
269
				return nil, err
			}
270
271
272
273
274
275
276
277
278
279
		case "application/vnd.ollama.image.messages":
			msgs, err := os.Open(filename)
			if err != nil {
				return nil, err
			}
			defer msgs.Close()

			if err = json.NewDecoder(msgs).Decode(&model.Messages); err != nil {
				return nil, err
			}
Patrick Devine's avatar
Patrick Devine committed
280
281
282
283
284
285
		case "application/vnd.ollama.image.license":
			bts, err := os.ReadFile(filename)
			if err != nil {
				return nil, err
			}
			model.License = append(model.License, string(bts))
286
287
288
289
290
291
		}
	}

	return model, nil
}

Michael Yang's avatar
Michael Yang committed
292
func realpath(rel, from string) string {
293
	abspath, err := filepath.Abs(from)
Michael Yang's avatar
Michael Yang committed
294
	if err != nil {
295
		return from
296
297
	}

Michael Yang's avatar
Michael Yang committed
298
	home, err := os.UserHomeDir()
299
	if err != nil {
Michael Yang's avatar
Michael Yang committed
300
		return abspath
301
302
	}

303
	if from == "~" {
Michael Yang's avatar
Michael Yang committed
304
		return home
305
306
307
308
	} else if strings.HasPrefix(from, "~/") {
		return filepath.Join(home, from[2:])
	}

Michael Yang's avatar
Michael Yang committed
309
	if _, err := os.Stat(filepath.Join(rel, from)); err == nil {
310
		// this is a file relative to the Modelfile
Michael Yang's avatar
Michael Yang committed
311
		return filepath.Join(rel, from)
312
313
	}

Michael Yang's avatar
Michael Yang committed
314
315
316
	return abspath
}

Michael Yang's avatar
Michael Yang committed
317
func CreateModel(ctx context.Context, name, modelFileDir, quantization string, modelfile *model.File, fn func(resp api.ProgressResponse)) (err error) {
318
319
	config := ConfigV2{
		OS:           "linux",
Michael Yang's avatar
Michael Yang committed
320
		Architecture: "amd64",
Michael Yang's avatar
Michael Yang committed
321
322
323
		RootFS: RootFS{
			Type: "layers",
		},
324
325
	}

Michael Yang's avatar
Michael Yang committed
326
327
	var messages []*api.Message
	parameters := make(map[string]any)
Michael Yang's avatar
Michael Yang committed
328

Michael Yang's avatar
Michael Yang committed
329
	var layers []*Layer
Michael Yang's avatar
Michael Yang committed
330
	for _, c := range modelfile.Commands {
Michael Yang's avatar
Michael Yang committed
331
332
		mediatype := fmt.Sprintf("application/vnd.ollama.image.%s", c.Name)

333
		switch c.Name {
Michael Yang's avatar
Michael Yang committed
334
		case "model", "adapter":
Michael Yang's avatar
Michael Yang committed
335
			var baseLayers []*layerWithGGML
Michael Yang's avatar
rebase  
Michael Yang committed
336
			if name := model.ParseName(c.Args); name.IsValid() {
Michael Yang's avatar
Michael Yang committed
337
				baseLayers, err = parseFromModel(ctx, name, fn)
Michael Yang's avatar
Michael Yang committed
338
339
340
				if err != nil {
					return err
				}
Michael Yang's avatar
Michael Yang committed
341
342
343
			} else if strings.HasPrefix(c.Args, "@") {
				blobpath, err := GetBlobsPath(strings.TrimPrefix(c.Args, "@"))
				if err != nil {
Michael Yang's avatar
Michael Yang committed
344
					return err
345
				}
346

Michael Yang's avatar
Michael Yang committed
347
				blob, err := os.Open(blobpath)
Michael Yang's avatar
Michael Yang committed
348
349
350
				if err != nil {
					return err
				}
Michael Yang's avatar
Michael Yang committed
351
				defer blob.Close()
Michael Yang's avatar
Michael Yang committed
352

Michael Yang's avatar
Michael Yang committed
353
				baseLayers, err = parseFromFile(ctx, blob, fn)
Michael Yang's avatar
Michael Yang committed
354
355
356
				if err != nil {
					return err
				}
Michael Yang's avatar
Michael Yang committed
357
358
			} else if file, err := os.Open(realpath(modelFileDir, c.Args)); err == nil {
				defer file.Close()
Michael Yang's avatar
Michael Yang committed
359

Michael Yang's avatar
Michael Yang committed
360
				baseLayers, err = parseFromFile(ctx, file, fn)
Michael Yang's avatar
Michael Yang committed
361
				if err != nil {
Michael Yang's avatar
Michael Yang committed
362
363
					return err
				}
Michael Yang's avatar
Michael Yang committed
364
365
366
			} else {
				return fmt.Errorf("invalid model reference: %s", c.Args)
			}
Michael Yang's avatar
Michael Yang committed
367

Michael Yang's avatar
Michael Yang committed
368
			for _, baseLayer := range baseLayers {
Michael Yang's avatar
Michael Yang committed
369
370
371
372
				if quantization != "" &&
					baseLayer.MediaType == "application/vnd.ollama.image.model" &&
					baseLayer.GGML != nil &&
					baseLayer.GGML.Name() == "gguf" {
Michael Yang's avatar
Michael Yang committed
373
					want, err := llm.ParseFileType(quantization)
374
					if err != nil {
Michael Yang's avatar
Michael Yang committed
375
						return err
376
					}
Michael Yang's avatar
Michael Yang committed
377

Michael Yang's avatar
Michael Yang committed
378
379
					ft := baseLayer.GGML.KV().FileType()
					if !slices.Contains([]string{"F16", "F32"}, ft.String()) {
Michael Yang's avatar
Michael Yang committed
380
						return errors.New("quantization is only supported for F16 and F32 models")
Michael Yang's avatar
Michael Yang committed
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
					} else if want != ft {
						fn(api.ProgressResponse{Status: fmt.Sprintf("quantizing %s model to %s", ft, quantization)})

						blob, err := GetBlobsPath(baseLayer.Digest)
						if err != nil {
							return err
						}

						temp, err := os.CreateTemp(filepath.Dir(blob), quantization)
						if err != nil {
							return err
						}
						defer temp.Close()
						defer os.Remove(temp.Name())

						if err := llm.Quantize(blob, temp.Name(), want); err != nil {
							return err
						}

						baseLayer.Layer, err = NewLayer(temp, baseLayer.Layer.MediaType)
						if err != nil {
							return err
						}
Michael Yang's avatar
Michael Yang committed
404
					}
405
				}
406

Michael Yang's avatar
Michael Yang committed
407
408
409
410
				if baseLayer.GGML != nil {
					config.ModelFormat = cmp.Or(config.ModelFormat, baseLayer.GGML.Name())
					config.ModelFamily = cmp.Or(config.ModelFamily, baseLayer.GGML.KV().Architecture())
					config.ModelType = cmp.Or(config.ModelType, format.HumanNumber(baseLayer.GGML.KV().ParameterCount()))
Michael Yang's avatar
Michael Yang committed
411
					config.FileType = cmp.Or(config.FileType, baseLayer.GGML.KV().FileType().String())
Michael Yang's avatar
Michael Yang committed
412
					config.ModelFamilies = append(config.ModelFamilies, baseLayer.GGML.KV().Architecture())
413
414
				}

Michael Yang's avatar
Michael Yang committed
415
				layers = append(layers, baseLayer.Layer)
416
			}
Michael Yang's avatar
Michael Yang committed
417
418
419
		case "license", "template", "system":
			blob := strings.NewReader(c.Args)
			layer, err := NewLayer(blob, mediatype)
420
			if err != nil {
Michael Yang's avatar
Michael Yang committed
421
				return err
422
423
			}

Michael Yang's avatar
Michael Yang committed
424
425
426
427
428
			if c.Name != "license" {
				// replace
				layers = slices.DeleteFunc(layers, func(layer *Layer) bool {
					return layer.MediaType == mediatype
				})
Michael Yang's avatar
Michael Yang committed
429
430
			}

Michael Yang's avatar
Michael Yang committed
431
432
433
434
435
436
437
438
439
440
			layers = append(layers, layer)
		case "message":
			role, content, ok := strings.Cut(c.Args, ": ")
			if !ok {
				return fmt.Errorf("invalid message: %s", c.Args)
			}

			messages = append(messages, &api.Message{Role: role, Content: content})
		default:
			ps, err := api.FormatParams(map[string][]string{c.Name: {c.Args}})
441
			if err != nil {
Michael Yang's avatar
Michael Yang committed
442
				return err
443
			}
Bruce MacDonald's avatar
Bruce MacDonald committed
444

Michael Yang's avatar
Michael Yang committed
445
446
447
448
449
450
451
452
453
454
455
			for k, v := range ps {
				if ks, ok := parameters[k].([]string); ok {
					parameters[k] = append(ks, v.([]string)...)
				} else if vs, ok := v.([]string); ok {
					parameters[k] = vs
				} else {
					parameters[k] = v
				}
			}
		}
	}
Michael Yang's avatar
Michael Yang committed
456

Michael Yang's avatar
Michael Yang committed
457
458
459
460
461
462
463
464
465
466
467
468
469
	var err2 error
	layers = slices.DeleteFunc(layers, func(layer *Layer) bool {
		switch layer.MediaType {
		case "application/vnd.ollama.image.message":
			// if there are new messages, remove the inherited ones
			if len(messages) > 0 {
				return true
			}

			return false
		case "application/vnd.ollama.image.params":
			// merge inherited parameters with new ones
			r, err := layer.Open()
Bruce MacDonald's avatar
Bruce MacDonald committed
470
			if err != nil {
Michael Yang's avatar
Michael Yang committed
471
472
				err2 = err
				return false
Bruce MacDonald's avatar
Bruce MacDonald committed
473
			}
Michael Yang's avatar
Michael Yang committed
474
			defer r.Close()
Bruce MacDonald's avatar
Bruce MacDonald committed
475

Michael Yang's avatar
Michael Yang committed
476
477
478
479
480
			var ps map[string]any
			if err := json.NewDecoder(r).Decode(&ps); err != nil {
				err2 = err
				return false
			}
Michael Yang's avatar
Michael Yang committed
481

Michael Yang's avatar
Michael Yang committed
482
483
484
485
			for k, v := range ps {
				if _, ok := parameters[k]; !ok {
					parameters[k] = v
				}
486
			}
487

Michael Yang's avatar
Michael Yang committed
488
			return true
489
		default:
Michael Yang's avatar
Michael Yang committed
490
			return false
491
		}
Michael Yang's avatar
Michael Yang committed
492
493
494
495
	})

	if err2 != nil {
		return err2
496
497
	}

498
499
	if len(messages) > 0 {
		var b bytes.Buffer
Michael Yang's avatar
Michael Yang committed
500
		if err := json.NewEncoder(&b).Encode(messages); err != nil {
501
502
503
504
505
506
507
508
			return err
		}

		layer, err := NewLayer(&b, "application/vnd.ollama.image.messages")
		if err != nil {
			return err
		}

Michael Yang's avatar
Michael Yang committed
509
		layers = append(layers, layer)
510
511
	}

Michael Yang's avatar
Michael Yang committed
512
	if len(parameters) > 0 {
Michael Yang's avatar
Michael Yang committed
513
		var b bytes.Buffer
Michael Yang's avatar
Michael Yang committed
514
		if err := json.NewEncoder(&b).Encode(parameters); err != nil {
515
516
517
			return err
		}

Michael Yang's avatar
Michael Yang committed
518
		layer, err := NewLayer(&b, "application/vnd.ollama.image.params")
519
		if err != nil {
Michael Yang's avatar
Michael Yang committed
520
			return err
521
		}
Michael Yang's avatar
Michael Yang committed
522

Michael Yang's avatar
Michael Yang committed
523
		layers = append(layers, layer)
524
525
	}

Michael Yang's avatar
Michael Yang committed
526
527
	digests := make([]string, len(layers))
	for i, layer := range layers {
Michael Yang's avatar
Michael Yang committed
528
		digests[i] = layer.Digest
529
530
	}

Michael Yang's avatar
Michael Yang committed
531
	config.RootFS.DiffIDs = digests
Michael Yang's avatar
Michael Yang committed
532

Michael Yang's avatar
Michael Yang committed
533
534
	var b bytes.Buffer
	if err := json.NewEncoder(&b).Encode(config); err != nil {
535
536
537
		return err
	}

Michael Yang's avatar
Michael Yang committed
538
	layer, err := NewLayer(&b, "application/vnd.docker.container.image.v1+json")
Michael Yang's avatar
Michael Yang committed
539
	if err != nil {
540
541
542
		return err
	}

Michael Yang's avatar
Michael Yang committed
543
544
545
	for _, layer := range append(layers, layer) {
		if layer.status != "" {
			fn(api.ProgressResponse{Status: layer.status})
546
		}
Michael Yang's avatar
Michael Yang committed
547
	}
548

Michael Yang's avatar
Michael Yang committed
549
550
551
552
553
554
	unref := make(map[string]struct{})
	if manifest, _, err := GetManifest(ParseModelPath(name)); err == nil {
		for _, layer := range manifest.Layers {
			if !slices.Contains(digests, layer.Digest) {
				unref[layer.Digest] = struct{}{}
			}
555
556
		}

Michael Yang's avatar
Michael Yang committed
557
558
559
		if manifest.Config.Digest != layer.Digest {
			unref[manifest.Config.Digest] = struct{}{}
		}
560
561
	}

Michael Yang's avatar
Michael Yang committed
562
	fn(api.ProgressResponse{Status: "writing manifest"})
Michael Yang's avatar
Michael Yang committed
563
	if err := WriteManifest(name, layer, layers); err != nil {
564
565
		return err
	}
566

567
	if !envconfig.NoPrune {
568
		if err := deleteUnusedLayers(nil, unref); err != nil {
Michael Yang's avatar
Michael Yang committed
569
			return err
570
571
572
		}
	}

Michael Yang's avatar
Michael Yang committed
573
574
	fn(api.ProgressResponse{Status: "success"})
	return nil
575
576
}

Michael Yang's avatar
Michael Yang committed
577
func CopyModel(src, dst model.Name) error {
578
579
580
581
582
583
584
	if !dst.IsFullyQualified() {
		return model.Unqualified(dst)
	}
	if !src.IsFullyQualified() {
		return model.Unqualified(src)
	}

585
586
587
588
	if src.Filepath() == dst.Filepath() {
		return nil
	}

Michael Yang's avatar
Michael Yang committed
589
	manifests, err := GetManifestPath()
590
591
592
593
	if err != nil {
		return err
	}

594
	dstpath := filepath.Join(manifests, dst.Filepath())
Michael Yang's avatar
Michael Yang committed
595
	if err := os.MkdirAll(filepath.Dir(dstpath), 0o755); err != nil {
596
597
		return err
	}
Patrick Devine's avatar
Patrick Devine committed
598

599
	srcpath := filepath.Join(manifests, src.Filepath())
Michael Yang's avatar
Michael Yang committed
600
	srcfile, err := os.Open(srcpath)
Patrick Devine's avatar
Patrick Devine committed
601
602
603
	if err != nil {
		return err
	}
Michael Yang's avatar
Michael Yang committed
604
	defer srcfile.Close()
Patrick Devine's avatar
Patrick Devine committed
605

Michael Yang's avatar
Michael Yang committed
606
	dstfile, err := os.Create(dstpath)
Patrick Devine's avatar
Patrick Devine committed
607
608
609
	if err != nil {
		return err
	}
Michael Yang's avatar
Michael Yang committed
610
	defer dstfile.Close()
Patrick Devine's avatar
Patrick Devine committed
611

Michael Yang's avatar
Michael Yang committed
612
613
	_, err = io.Copy(dstfile, srcfile)
	return err
Patrick Devine's avatar
Patrick Devine committed
614
615
}

616
func deleteUnusedLayers(skipModelPath *ModelPath, deleteMap map[string]struct{}) error {
617
618
619
620
	fp, err := GetManifestPath()
	if err != nil {
		return err
	}
Michael Yang's avatar
Michael Yang committed
621
622
623
624

	walkFunc := func(path string, info os.FileInfo, _ error) error {
		if info.IsDir() {
			return nil
625
626
		}

Michael Yang's avatar
Michael Yang committed
627
628
629
630
		dir, file := filepath.Split(path)
		dir = strings.Trim(strings.TrimPrefix(dir, fp), string(os.PathSeparator))
		tag := strings.Join([]string{dir, file}, ":")
		fmp := ParseModelPath(tag)
631

Michael Yang's avatar
Michael Yang committed
632
		// skip the manifest we're trying to delete
633
		if skipModelPath != nil && skipModelPath.GetFullTagname() == fmp.GetFullTagname() {
Michael Yang's avatar
Michael Yang committed
634
			return nil
635
		}
Michael Yang's avatar
Michael Yang committed
636
637
638
639

		// save (i.e. delete from the deleteMap) any files used in other manifests
		manifest, _, err := GetManifest(fmp)
		if err != nil {
Michael Yang's avatar
Michael Yang committed
640
			// nolint: nilerr
Michael Yang's avatar
Michael Yang committed
641
642
643
644
645
646
647
648
			return nil
		}

		for _, layer := range manifest.Layers {
			delete(deleteMap, layer.Digest)
		}

		delete(deleteMap, manifest.Config.Digest)
649
		return nil
Michael Yang's avatar
Michael Yang committed
650
651
652
	}

	if err := filepath.Walk(fp, walkFunc); err != nil {
Michael Yang's avatar
Michael Yang committed
653
654
		return err
	}
655
656

	// only delete the files which are still in the deleteMap
Michael Yang's avatar
Michael Yang committed
657
658
659
	for k := range deleteMap {
		fp, err := GetBlobsPath(k)
		if err != nil {
660
			slog.Info(fmt.Sprintf("couldn't get file path for '%s': %v", k, err))
Michael Yang's avatar
Michael Yang committed
661
662
			continue
		}
663
664
665
		if err := os.Remove(fp); err != nil {
			slog.Info(fmt.Sprintf("couldn't remove file '%s': %v", fp, err))
			continue
666
667
668
		}
	}

669
670
671
672
	return nil
}

func PruneLayers() error {
Michael Yang's avatar
Michael Yang committed
673
	deleteMap := make(map[string]struct{})
674
675
676
677
678
679
680
	p, err := GetBlobsPath("")
	if err != nil {
		return err
	}

	blobs, err := os.ReadDir(p)
	if err != nil {
681
		slog.Info(fmt.Sprintf("couldn't read dir '%s': %v", p, err))
682
683
684
685
686
		return err
	}

	for _, blob := range blobs {
		name := blob.Name()
687
		name = strings.ReplaceAll(name, "-", ":")
688
689
690
691
692
693
694
695
696
697
698

		_, err := GetBlobsPath(name)
		if err != nil {
			if errors.Is(err, ErrInvalidDigestFormat) {
				// remove invalid blobs (e.g. partial downloads)
				if err := os.Remove(filepath.Join(p, blob.Name())); err != nil {
					slog.Error("couldn't remove blob", "blob", blob.Name(), "error", err)
				}
			}

			continue
Michael Yang's avatar
Michael Yang committed
699
		}
700
701

		deleteMap[name] = struct{}{}
702
703
	}

704
	slog.Info(fmt.Sprintf("total blobs: %d", len(deleteMap)))
705

706
	err = deleteUnusedLayers(nil, deleteMap)
707
708
709
710
	if err != nil {
		return err
	}

711
	slog.Info(fmt.Sprintf("total unused blobs removed: %d", len(deleteMap)))
712
713
714
715

	return nil
}

Michael Yang's avatar
Michael Yang committed
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
func PruneDirectory(path string) error {
	info, err := os.Lstat(path)
	if err != nil {
		return err
	}

	if info.IsDir() && info.Mode()&os.ModeSymlink == 0 {
		entries, err := os.ReadDir(path)
		if err != nil {
			return err
		}

		for _, entry := range entries {
			if err := PruneDirectory(filepath.Join(path, entry.Name())); err != nil {
				return err
			}
		}

		entries, err = os.ReadDir(path)
		if err != nil {
			return err
		}

		if len(entries) > 0 {
			return nil
		}

		return os.Remove(path)
	}

	return nil
}

749
750
751
752
753
754
755
func DeleteModel(name string) error {
	mp := ParseModelPath(name)
	manifest, _, err := GetManifest(mp)
	if err != nil {
		return err
	}

Michael Yang's avatar
Michael Yang committed
756
	deleteMap := make(map[string]struct{})
757
	for _, layer := range manifest.Layers {
Michael Yang's avatar
Michael Yang committed
758
		deleteMap[layer.Digest] = struct{}{}
759
	}
Michael Yang's avatar
Michael Yang committed
760
	deleteMap[manifest.Config.Digest] = struct{}{}
761

762
	err = deleteUnusedLayers(&mp, deleteMap)
763
764
765
766
	if err != nil {
		return err
	}

767
	fp, err := mp.GetManifestPath()
768
769
770
771
772
	if err != nil {
		return err
	}
	err = os.Remove(fp)
	if err != nil {
773
		slog.Info(fmt.Sprintf("couldn't remove manifest file '%s': %v", fp, err))
774
775
776
777
778
779
		return err
	}

	return nil
}

Michael Yang's avatar
Michael Yang committed
780
func PushModel(ctx context.Context, name string, regOpts *registryOptions, fn func(api.ProgressResponse)) error {
781
	mp := ParseModelPath(name)
782
783
	fn(api.ProgressResponse{Status: "retrieving manifest"})

784
785
786
787
	if mp.ProtocolScheme == "http" && !regOpts.Insecure {
		return fmt.Errorf("insecure protocol http")
	}

Patrick Devine's avatar
Patrick Devine committed
788
	manifest, _, err := GetManifest(mp)
789
	if err != nil {
790
		fn(api.ProgressResponse{Status: "couldn't retrieve manifest"})
791
792
793
794
		return err
	}

	var layers []*Layer
Jeffrey Morgan's avatar
Jeffrey Morgan committed
795
	layers = append(layers, manifest.Layers...)
Michael Yang's avatar
Michael Yang committed
796
	layers = append(layers, manifest.Config)
797
798

	for _, layer := range layers {
Michael Yang's avatar
Michael Yang committed
799
		if err := uploadBlob(ctx, mp, layer, regOpts, fn); err != nil {
800
			slog.Info(fmt.Sprintf("error uploading blob: %v", err))
801
802
			return err
		}
803
804
	}

805
	fn(api.ProgressResponse{Status: "pushing manifest"})
Michael Yang's avatar
Michael Yang committed
806
807
	requestURL := mp.BaseURL()
	requestURL = requestURL.JoinPath("v2", mp.GetNamespaceRepository(), "manifests", mp.Tag)
808
809
810
811
812
813

	manifestJSON, err := json.Marshal(manifest)
	if err != nil {
		return err
	}

Michael Yang's avatar
Michael Yang committed
814
815
	headers := make(http.Header)
	headers.Set("Content-Type", "application/vnd.docker.distribution.manifest.v2+json")
Michael Yang's avatar
Michael Yang committed
816
	resp, err := makeRequestWithRetry(ctx, http.MethodPut, requestURL, headers, bytes.NewReader(manifestJSON), regOpts)
817
818
819
820
821
	if err != nil {
		return err
	}
	defer resp.Body.Close()

822
	fn(api.ProgressResponse{Status: "success"})
823
824
825
826

	return nil
}

Michael Yang's avatar
Michael Yang committed
827
func PullModel(ctx context.Context, name string, regOpts *registryOptions, fn func(api.ProgressResponse)) error {
828
829
	mp := ParseModelPath(name)

830
831
832
833
834
	var manifest *ManifestV2
	var err error
	var noprune string

	// build deleteMap to prune unused layers
Michael Yang's avatar
Michael Yang committed
835
	deleteMap := make(map[string]struct{})
836

837
	if !envconfig.NoPrune {
838
839
840
841
842
843
844
		manifest, _, err = GetManifest(mp)
		if err != nil && !errors.Is(err, os.ErrNotExist) {
			return err
		}

		if manifest != nil {
			for _, l := range manifest.Layers {
Michael Yang's avatar
Michael Yang committed
845
				deleteMap[l.Digest] = struct{}{}
846
			}
Michael Yang's avatar
Michael Yang committed
847
			deleteMap[manifest.Config.Digest] = struct{}{}
848
849
850
		}
	}

851
852
	if mp.ProtocolScheme == "http" && !regOpts.Insecure {
		return fmt.Errorf("insecure protocol http")
853
	}
854

855
	fn(api.ProgressResponse{Status: "pulling manifest"})
856

857
	manifest, err = pullModelManifest(ctx, mp, regOpts)
858
	if err != nil {
859
		return fmt.Errorf("pull model manifest: %s", err)
860
861
862
	}

	var layers []*Layer
Bruce MacDonald's avatar
Bruce MacDonald committed
863
	layers = append(layers, manifest.Layers...)
Michael Yang's avatar
Michael Yang committed
864
	layers = append(layers, manifest.Config)
865
866

	for _, layer := range layers {
867
868
869
870
871
872
873
874
		if err := downloadBlob(
			ctx,
			downloadOpts{
				mp:      mp,
				digest:  layer.Digest,
				regOpts: regOpts,
				fn:      fn,
			}); err != nil {
875
876
			return err
		}
877
		delete(deleteMap, layer.Digest)
878
	}
879
	delete(deleteMap, manifest.Config.Digest)
880

Michael Yang's avatar
Michael Yang committed
881
882
883
	fn(api.ProgressResponse{Status: "verifying sha256 digest"})
	for _, layer := range layers {
		if err := verifyBlob(layer.Digest); err != nil {
884
885
886
887
888
889
890
891
			if errors.Is(err, errDigestMismatch) {
				// something went wrong, delete the blob
				fp, err := GetBlobsPath(layer.Digest)
				if err != nil {
					return err
				}
				if err := os.Remove(fp); err != nil {
					// log this, but return the original error
892
					slog.Info(fmt.Sprintf("couldn't remove file with digest mismatch '%s': %v", fp, err))
893
894
				}
			}
Michael Yang's avatar
Michael Yang committed
895
896
897
898
			return err
		}
	}

899
	fn(api.ProgressResponse{Status: "writing manifest"})
900

901
	manifestJSON, err := json.Marshal(manifest)
902
903
904
905
	if err != nil {
		return err
	}

906
	fp, err := mp.GetManifestPath()
907
908
909
	if err != nil {
		return err
	}
910
911
912
	if err := os.MkdirAll(filepath.Dir(fp), 0o755); err != nil {
		return err
	}
913

Bruce MacDonald's avatar
Bruce MacDonald committed
914
	err = os.WriteFile(fp, manifestJSON, 0o644)
915
	if err != nil {
916
		slog.Info(fmt.Sprintf("couldn't write to %s", fp))
917
918
919
		return err
	}

920
921
	if noprune == "" {
		fn(api.ProgressResponse{Status: "removing any unused layers"})
922
		err = deleteUnusedLayers(nil, deleteMap)
923
924
925
926
927
		if err != nil {
			return err
		}
	}

928
	fn(api.ProgressResponse{Status: "success"})
929
930
931
932

	return nil
}

Michael Yang's avatar
Michael Yang committed
933
func pullModelManifest(ctx context.Context, mp ModelPath, regOpts *registryOptions) (*ManifestV2, error) {
Michael Yang's avatar
Michael Yang committed
934
	requestURL := mp.BaseURL().JoinPath("v2", mp.GetNamespaceRepository(), "manifests", mp.Tag)
935

Michael Yang's avatar
Michael Yang committed
936
937
	headers := make(http.Header)
	headers.Set("Accept", "application/vnd.docker.distribution.manifest.v2+json")
Michael Yang's avatar
Michael Yang committed
938
	resp, err := makeRequestWithRetry(ctx, http.MethodGet, requestURL, headers, nil, regOpts)
939
940
941
942
943
944
945
946
947
948
949
950
951
952
	if err != nil {
		return nil, err
	}
	defer resp.Body.Close()

	var m *ManifestV2
	if err := json.NewDecoder(resp.Body).Decode(&m); err != nil {
		return nil, err
	}

	return m, err
}

// GetSHA256Digest returns the SHA256 hash of a given buffer and returns it, and the size of buffer
Michael Yang's avatar
Michael Yang committed
953
func GetSHA256Digest(r io.Reader) (string, int64) {
Michael Yang's avatar
Michael Yang committed
954
955
956
957
958
959
	h := sha256.New()
	n, err := io.Copy(h, r)
	if err != nil {
		log.Fatal(err)
	}

Michael Yang's avatar
Michael Yang committed
960
	return fmt.Sprintf("sha256:%x", h.Sum(nil)), n
961
962
}

963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
var errUnauthorized = fmt.Errorf("unauthorized: access denied")

// getTokenSubject returns the subject of a JWT token, it does not validate the token
func getTokenSubject(token string) string {
	parts := strings.Split(token, ".")
	if len(parts) != 3 {
		slog.Error("jwt token does not contain 3 parts")
		return ""
	}

	payload := parts[1]
	payloadBytes, err := base64.RawURLEncoding.DecodeString(payload)
	if err != nil {
		slog.Error(fmt.Sprintf("failed to decode jwt payload: %v", err))
		return ""
	}

	var payloadMap map[string]interface{}
	if err := json.Unmarshal(payloadBytes, &payloadMap); err != nil {
		slog.Error(fmt.Sprintf("failed to unmarshal payload JSON: %v", err))
		return ""
	}

	sub, ok := payloadMap["sub"]
	if !ok {
		slog.Error("jwt does not contain 'sub' field")
		return ""
	}

	return fmt.Sprintf("%s", sub)
}
994

Michael Yang's avatar
Michael Yang committed
995
func makeRequestWithRetry(ctx context.Context, method string, requestURL *url.URL, headers http.Header, body io.ReadSeeker, regOpts *registryOptions) (*http.Response, error) {
996
	anonymous := true // access will default to anonymous if no user is found associated with the public key
Michael Yang's avatar
Michael Yang committed
997
	for i := 0; i < 2; i++ {
Michael Yang's avatar
Michael Yang committed
998
		resp, err := makeRequest(ctx, method, requestURL, headers, body, regOpts)
Michael Yang's avatar
Michael Yang committed
999
		if err != nil {
Michael Yang's avatar
Michael Yang committed
1000
			if !errors.Is(err, context.Canceled) {
1001
				slog.Info(fmt.Sprintf("request failed: %v", err))
Michael Yang's avatar
Michael Yang committed
1002
1003
			}

Michael Yang's avatar
Michael Yang committed
1004
1005
			return nil, err
		}
Michael Yang's avatar
Michael Yang committed
1006
1007
1008
1009

		switch {
		case resp.StatusCode == http.StatusUnauthorized:
			// Handle authentication error with one retry
Michael Yang's avatar
Michael Yang committed
1010
1011
			challenge := parseRegistryChallenge(resp.Header.Get("www-authenticate"))
			token, err := getAuthorizationToken(ctx, challenge)
Michael Yang's avatar
Michael Yang committed
1012
1013
1014
			if err != nil {
				return nil, err
			}
1015
			anonymous = getTokenSubject(token) == "anonymous"
Michael Yang's avatar
Michael Yang committed
1016
1017
1018
1019
1020
1021
1022
1023
1024
1025
1026
1027
1028
1029
1030
1031
1032
			regOpts.Token = token
			if body != nil {
				_, err = body.Seek(0, io.SeekStart)
				if err != nil {
					return nil, err
				}
			}
		case resp.StatusCode == http.StatusNotFound:
			return nil, os.ErrNotExist
		case resp.StatusCode >= http.StatusBadRequest:
			responseBody, err := io.ReadAll(resp.Body)
			if err != nil {
				return nil, fmt.Errorf("%d: %s", resp.StatusCode, err)
			}
			return nil, fmt.Errorf("%d: %s", resp.StatusCode, responseBody)
		default:
			return resp, nil
Michael Yang's avatar
Michael Yang committed
1033
1034
1035
		}
	}

1036
1037
1038
1039
1040
1041
1042
1043
1044
1045
	if anonymous {
		// no user is associated with the public key, and the request requires non-anonymous access
		pubKey, nestedErr := auth.GetPublicKey()
		if nestedErr != nil {
			slog.Error(fmt.Sprintf("couldn't get public key: %v", nestedErr))
			return nil, errUnauthorized
		}
		return nil, &errtypes.UnknownOllamaKey{Key: pubKey}
	}
	// user is associated with the public key, but is not authorized to make the request
Michael Yang's avatar
Michael Yang committed
1046
	return nil, errUnauthorized
Michael Yang's avatar
Michael Yang committed
1047
1048
}

Michael Yang's avatar
Michael Yang committed
1049
1050
1051
1052
1053
1054
1055
1056
1057
1058
1059
1060
1061
1062
1063
1064
1065
1066
1067
1068
1069
1070
1071
1072
1073
1074
1075
1076
1077
1078
1079
1080
1081
func makeRequest(ctx context.Context, method string, requestURL *url.URL, headers http.Header, body io.Reader, regOpts *registryOptions) (*http.Response, error) {
	if requestURL.Scheme != "http" && regOpts != nil && regOpts.Insecure {
		requestURL.Scheme = "http"
	}

	req, err := http.NewRequestWithContext(ctx, method, requestURL.String(), body)
	if err != nil {
		return nil, err
	}

	if headers != nil {
		req.Header = headers
	}

	if regOpts != nil {
		if regOpts.Token != "" {
			req.Header.Set("Authorization", "Bearer "+regOpts.Token)
		} else if regOpts.Username != "" && regOpts.Password != "" {
			req.SetBasicAuth(regOpts.Username, regOpts.Password)
		}
	}

	req.Header.Set("User-Agent", fmt.Sprintf("ollama/%s (%s %s) Go/%s", version.Version, runtime.GOARCH, runtime.GOOS, runtime.Version()))

	if s := req.Header.Get("Content-Length"); s != "" {
		contentLength, err := strconv.ParseInt(s, 10, 64)
		if err != nil {
			return nil, err
		}

		req.ContentLength = contentLength
	}

Michael Yang's avatar
Michael Yang committed
1082
	resp, err := http.DefaultClient.Do(req)
Michael Yang's avatar
Michael Yang committed
1083
1084
1085
1086
1087
1088
1089
	if err != nil {
		return nil, err
	}

	return resp, nil
}

Patrick Devine's avatar
Patrick Devine committed
1090
1091
1092
1093
1094
1095
1096
1097
1098
1099
1100
1101
1102
1103
1104
1105
1106
1107
1108
1109
1110
1111
1112
func getValue(header, key string) string {
	startIdx := strings.Index(header, key+"=")
	if startIdx == -1 {
		return ""
	}

	// Move the index to the starting quote after the key.
	startIdx += len(key) + 2
	endIdx := startIdx

	for endIdx < len(header) {
		if header[endIdx] == '"' {
			if endIdx+1 < len(header) && header[endIdx+1] != ',' { // If the next character isn't a comma, continue
				endIdx++
				continue
			}
			break
		}
		endIdx++
	}
	return header[startIdx:endIdx]
}

Michael Yang's avatar
Michael Yang committed
1113
func parseRegistryChallenge(authStr string) registryChallenge {
Patrick Devine's avatar
Patrick Devine committed
1114
1115
	authStr = strings.TrimPrefix(authStr, "Bearer ")

Michael Yang's avatar
Michael Yang committed
1116
	return registryChallenge{
Patrick Devine's avatar
Patrick Devine committed
1117
1118
1119
1120
1121
1122
		Realm:   getValue(authStr, "realm"),
		Service: getValue(authStr, "service"),
		Scope:   getValue(authStr, "scope"),
	}
}

1123
var errDigestMismatch = errors.New("digest mismatch, file must be downloaded again")
1124

Michael Yang's avatar
Michael Yang committed
1125
1126
1127
1128
1129
1130
1131
1132
1133
1134
1135
1136
1137
1138
func verifyBlob(digest string) error {
	fp, err := GetBlobsPath(digest)
	if err != nil {
		return err
	}

	f, err := os.Open(fp)
	if err != nil {
		return err
	}
	defer f.Close()

	fileDigest, _ := GetSHA256Digest(f)
	if digest != fileDigest {
1139
		return fmt.Errorf("%w: want %s, got %s", errDigestMismatch, digest, fileDigest)
Michael Yang's avatar
Michael Yang committed
1140
1141
1142
1143
	}

	return nil
}