server.go 46 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "encoding/base64"
  6. "encoding/json"
  7. "expvar"
  8. "fmt"
  9. "io"
  10. "io/ioutil"
  11. "net"
  12. "net/http"
  13. "net/http/pprof"
  14. "os"
  15. "strconv"
  16. "strings"
  17. "syscall"
  18. "crypto/tls"
  19. "crypto/x509"
  20. "code.google.com/p/go.net/websocket"
  21. "github.com/docker/libcontainer/user"
  22. "github.com/gorilla/mux"
  23. log "github.com/Sirupsen/logrus"
  24. "github.com/docker/docker/api"
  25. "github.com/docker/docker/engine"
  26. "github.com/docker/docker/pkg/listenbuffer"
  27. "github.com/docker/docker/pkg/parsers"
  28. "github.com/docker/docker/pkg/stdcopy"
  29. "github.com/docker/docker/pkg/systemd"
  30. "github.com/docker/docker/pkg/version"
  31. "github.com/docker/docker/registry"
  32. "github.com/docker/docker/utils"
  33. )
  34. var (
  35. activationLock chan struct{}
  36. )
  37. type HttpServer struct {
  38. srv *http.Server
  39. l net.Listener
  40. }
  41. func (s *HttpServer) Serve() error {
  42. return s.srv.Serve(s.l)
  43. }
  44. func (s *HttpServer) Close() error {
  45. return s.l.Close()
  46. }
  47. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  48. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  49. conn, _, err := w.(http.Hijacker).Hijack()
  50. if err != nil {
  51. return nil, nil, err
  52. }
  53. // Flush the options to make sure the client sets the raw mode
  54. conn.Write([]byte{})
  55. return conn, conn, nil
  56. }
  57. // Check to make sure request's Content-Type is application/json
  58. func checkForJson(r *http.Request) error {
  59. ct := r.Header.Get("Content-Type")
  60. // No Content-Type header is ok as long as there's no Body
  61. if ct == "" {
  62. if r.Body == nil || r.ContentLength == 0 {
  63. return nil
  64. }
  65. }
  66. // Otherwise it better be json
  67. if api.MatchesContentType(ct, "application/json") {
  68. return nil
  69. }
  70. return fmt.Errorf("Content-Type specified (%s) must be 'application/json'", ct)
  71. }
  72. //If we don't do this, POST method without Content-type (even with empty body) will fail
  73. func parseForm(r *http.Request) error {
  74. if r == nil {
  75. return nil
  76. }
  77. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  78. return err
  79. }
  80. return nil
  81. }
  82. func parseMultipartForm(r *http.Request) error {
  83. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  84. return err
  85. }
  86. return nil
  87. }
  88. func httpError(w http.ResponseWriter, err error) {
  89. statusCode := http.StatusInternalServerError
  90. // FIXME: this is brittle and should not be necessary.
  91. // If we need to differentiate between different possible error types, we should
  92. // create appropriate error types with clearly defined meaning.
  93. errStr := strings.ToLower(err.Error())
  94. if strings.Contains(errStr, "no such") {
  95. statusCode = http.StatusNotFound
  96. } else if strings.Contains(errStr, "bad parameter") {
  97. statusCode = http.StatusBadRequest
  98. } else if strings.Contains(errStr, "conflict") {
  99. statusCode = http.StatusConflict
  100. } else if strings.Contains(errStr, "impossible") {
  101. statusCode = http.StatusNotAcceptable
  102. } else if strings.Contains(errStr, "wrong login/password") {
  103. statusCode = http.StatusUnauthorized
  104. } else if strings.Contains(errStr, "hasn't been activated") {
  105. statusCode = http.StatusForbidden
  106. }
  107. if err != nil {
  108. log.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  109. http.Error(w, err.Error(), statusCode)
  110. }
  111. }
  112. func writeJSON(w http.ResponseWriter, code int, v engine.Env) error {
  113. w.Header().Set("Content-Type", "application/json")
  114. w.WriteHeader(code)
  115. return v.Encode(w)
  116. }
  117. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  118. w.Header().Set("Content-Type", "application/json")
  119. if flush {
  120. job.Stdout.Add(utils.NewWriteFlusher(w))
  121. } else {
  122. job.Stdout.Add(w)
  123. }
  124. }
  125. func getBoolParam(value string) (bool, error) {
  126. if value == "" {
  127. return false, nil
  128. }
  129. ret, err := strconv.ParseBool(value)
  130. if err != nil {
  131. return false, fmt.Errorf("Bad parameter")
  132. }
  133. return ret, nil
  134. }
  135. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  136. var (
  137. authConfig, err = ioutil.ReadAll(r.Body)
  138. job = eng.Job("auth")
  139. stdoutBuffer = bytes.NewBuffer(nil)
  140. )
  141. if err != nil {
  142. return err
  143. }
  144. job.Setenv("authConfig", string(authConfig))
  145. job.Stdout.Add(stdoutBuffer)
  146. if err = job.Run(); err != nil {
  147. return err
  148. }
  149. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  150. var env engine.Env
  151. env.Set("Status", status)
  152. return writeJSON(w, http.StatusOK, env)
  153. }
  154. w.WriteHeader(http.StatusNoContent)
  155. return nil
  156. }
  157. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  158. w.Header().Set("Content-Type", "application/json")
  159. eng.ServeHTTP(w, r)
  160. return nil
  161. }
  162. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  163. if vars == nil {
  164. return fmt.Errorf("Missing parameter")
  165. }
  166. if err := parseForm(r); err != nil {
  167. return err
  168. }
  169. job := eng.Job("kill", vars["name"])
  170. if sig := r.Form.Get("signal"); sig != "" {
  171. job.Args = append(job.Args, sig)
  172. }
  173. if err := job.Run(); err != nil {
  174. return err
  175. }
  176. w.WriteHeader(http.StatusNoContent)
  177. return nil
  178. }
  179. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  180. if vars == nil {
  181. return fmt.Errorf("Missing parameter")
  182. }
  183. if err := parseForm(r); err != nil {
  184. return err
  185. }
  186. job := eng.Job("pause", vars["name"])
  187. if err := job.Run(); err != nil {
  188. return err
  189. }
  190. w.WriteHeader(http.StatusNoContent)
  191. return nil
  192. }
  193. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  194. if vars == nil {
  195. return fmt.Errorf("Missing parameter")
  196. }
  197. if err := parseForm(r); err != nil {
  198. return err
  199. }
  200. job := eng.Job("unpause", vars["name"])
  201. if err := job.Run(); err != nil {
  202. return err
  203. }
  204. w.WriteHeader(http.StatusNoContent)
  205. return nil
  206. }
  207. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  208. if vars == nil {
  209. return fmt.Errorf("Missing parameter")
  210. }
  211. job := eng.Job("export", vars["name"])
  212. job.Stdout.Add(w)
  213. if err := job.Run(); err != nil {
  214. return err
  215. }
  216. return nil
  217. }
  218. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  219. if err := parseForm(r); err != nil {
  220. return err
  221. }
  222. var (
  223. err error
  224. outs *engine.Table
  225. job = eng.Job("images")
  226. )
  227. job.Setenv("filters", r.Form.Get("filters"))
  228. // FIXME this parameter could just be a match filter
  229. job.Setenv("filter", r.Form.Get("filter"))
  230. job.Setenv("all", r.Form.Get("all"))
  231. if version.GreaterThanOrEqualTo("1.7") {
  232. streamJSON(job, w, false)
  233. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  234. return err
  235. }
  236. if err := job.Run(); err != nil {
  237. return err
  238. }
  239. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  240. outsLegacy := engine.NewTable("Created", 0)
  241. for _, out := range outs.Data {
  242. for _, repoTag := range out.GetList("RepoTags") {
  243. repo, tag := parsers.ParseRepositoryTag(repoTag)
  244. outLegacy := &engine.Env{}
  245. outLegacy.Set("Repository", repo)
  246. outLegacy.SetJson("Tag", tag)
  247. outLegacy.Set("Id", out.Get("Id"))
  248. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  249. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  250. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  251. outsLegacy.Add(outLegacy)
  252. }
  253. }
  254. w.Header().Set("Content-Type", "application/json")
  255. if _, err := outsLegacy.WriteListTo(w); err != nil {
  256. return err
  257. }
  258. }
  259. return nil
  260. }
  261. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  262. if version.GreaterThan("1.6") {
  263. w.WriteHeader(http.StatusNotFound)
  264. return fmt.Errorf("This is now implemented in the client.")
  265. }
  266. eng.ServeHTTP(w, r)
  267. return nil
  268. }
  269. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  270. w.Header().Set("Content-Type", "application/json")
  271. eng.ServeHTTP(w, r)
  272. return nil
  273. }
  274. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  275. if err := parseForm(r); err != nil {
  276. return err
  277. }
  278. var job = eng.Job("events")
  279. streamJSON(job, w, true)
  280. job.Setenv("since", r.Form.Get("since"))
  281. job.Setenv("until", r.Form.Get("until"))
  282. job.Setenv("filters", r.Form.Get("filters"))
  283. return job.Run()
  284. }
  285. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  286. if vars == nil {
  287. return fmt.Errorf("Missing parameter")
  288. }
  289. var job = eng.Job("history", vars["name"])
  290. streamJSON(job, w, false)
  291. if err := job.Run(); err != nil {
  292. return err
  293. }
  294. return nil
  295. }
  296. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  297. if vars == nil {
  298. return fmt.Errorf("Missing parameter")
  299. }
  300. var job = eng.Job("container_changes", vars["name"])
  301. streamJSON(job, w, false)
  302. return job.Run()
  303. }
  304. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  305. if version.LessThan("1.4") {
  306. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  307. }
  308. if vars == nil {
  309. return fmt.Errorf("Missing parameter")
  310. }
  311. if err := parseForm(r); err != nil {
  312. return err
  313. }
  314. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  315. streamJSON(job, w, false)
  316. return job.Run()
  317. }
  318. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  319. if err := parseForm(r); err != nil {
  320. return err
  321. }
  322. var (
  323. err error
  324. outs *engine.Table
  325. job = eng.Job("containers")
  326. )
  327. job.Setenv("all", r.Form.Get("all"))
  328. job.Setenv("size", r.Form.Get("size"))
  329. job.Setenv("since", r.Form.Get("since"))
  330. job.Setenv("before", r.Form.Get("before"))
  331. job.Setenv("limit", r.Form.Get("limit"))
  332. job.Setenv("filters", r.Form.Get("filters"))
  333. if version.GreaterThanOrEqualTo("1.5") {
  334. streamJSON(job, w, false)
  335. } else if outs, err = job.Stdout.AddTable(); err != nil {
  336. return err
  337. }
  338. if err = job.Run(); err != nil {
  339. return err
  340. }
  341. if version.LessThan("1.5") { // Convert to legacy format
  342. for _, out := range outs.Data {
  343. ports := engine.NewTable("", 0)
  344. ports.ReadListFrom([]byte(out.Get("Ports")))
  345. out.Set("Ports", api.DisplayablePorts(ports))
  346. }
  347. w.Header().Set("Content-Type", "application/json")
  348. if _, err = outs.WriteListTo(w); err != nil {
  349. return err
  350. }
  351. }
  352. return nil
  353. }
  354. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  355. if err := parseForm(r); err != nil {
  356. return err
  357. }
  358. if vars == nil {
  359. return fmt.Errorf("Missing parameter")
  360. }
  361. var (
  362. inspectJob = eng.Job("container_inspect", vars["name"])
  363. logsJob = eng.Job("logs", vars["name"])
  364. c, err = inspectJob.Stdout.AddEnv()
  365. )
  366. if err != nil {
  367. return err
  368. }
  369. logsJob.Setenv("follow", r.Form.Get("follow"))
  370. logsJob.Setenv("tail", r.Form.Get("tail"))
  371. logsJob.Setenv("stdout", r.Form.Get("stdout"))
  372. logsJob.Setenv("stderr", r.Form.Get("stderr"))
  373. logsJob.Setenv("timestamps", r.Form.Get("timestamps"))
  374. // Validate args here, because we can't return not StatusOK after job.Run() call
  375. stdout, stderr := logsJob.GetenvBool("stdout"), logsJob.GetenvBool("stderr")
  376. if !(stdout || stderr) {
  377. return fmt.Errorf("Bad parameters: you must choose at least one stream")
  378. }
  379. if err = inspectJob.Run(); err != nil {
  380. return err
  381. }
  382. var outStream, errStream io.Writer
  383. outStream = utils.NewWriteFlusher(w)
  384. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  385. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  386. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  387. } else {
  388. errStream = outStream
  389. }
  390. logsJob.Stdout.Add(outStream)
  391. logsJob.Stderr.Set(errStream)
  392. if err := logsJob.Run(); err != nil {
  393. fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
  394. }
  395. return nil
  396. }
  397. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  398. if err := parseForm(r); err != nil {
  399. return err
  400. }
  401. if vars == nil {
  402. return fmt.Errorf("Missing parameter")
  403. }
  404. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  405. job.Setenv("force", r.Form.Get("force"))
  406. if err := job.Run(); err != nil {
  407. return err
  408. }
  409. w.WriteHeader(http.StatusCreated)
  410. return nil
  411. }
  412. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  413. if err := parseForm(r); err != nil {
  414. return err
  415. }
  416. var (
  417. config engine.Env
  418. env engine.Env
  419. job = eng.Job("commit", r.Form.Get("container"))
  420. stdoutBuffer = bytes.NewBuffer(nil)
  421. )
  422. if err := checkForJson(r); err != nil {
  423. return err
  424. }
  425. if err := config.Decode(r.Body); err != nil {
  426. log.Errorf("%s", err)
  427. }
  428. if r.FormValue("pause") == "" && version.GreaterThanOrEqualTo("1.13") {
  429. job.Setenv("pause", "1")
  430. } else {
  431. job.Setenv("pause", r.FormValue("pause"))
  432. }
  433. job.Setenv("repo", r.Form.Get("repo"))
  434. job.Setenv("tag", r.Form.Get("tag"))
  435. job.Setenv("author", r.Form.Get("author"))
  436. job.Setenv("comment", r.Form.Get("comment"))
  437. job.SetenvSubEnv("config", &config)
  438. job.Stdout.Add(stdoutBuffer)
  439. if err := job.Run(); err != nil {
  440. return err
  441. }
  442. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  443. return writeJSON(w, http.StatusCreated, env)
  444. }
  445. // Creates an image from Pull or from Import
  446. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  447. if err := parseForm(r); err != nil {
  448. return err
  449. }
  450. var (
  451. image = r.Form.Get("fromImage")
  452. repo = r.Form.Get("repo")
  453. tag = r.Form.Get("tag")
  454. job *engine.Job
  455. )
  456. authEncoded := r.Header.Get("X-Registry-Auth")
  457. authConfig := &registry.AuthConfig{}
  458. if authEncoded != "" {
  459. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  460. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  461. // for a pull it is not an error if no auth was given
  462. // to increase compatibility with the existing api it is defaulting to be empty
  463. authConfig = &registry.AuthConfig{}
  464. }
  465. }
  466. if image != "" { //pull
  467. if tag == "" {
  468. image, tag = parsers.ParseRepositoryTag(image)
  469. }
  470. metaHeaders := map[string][]string{}
  471. for k, v := range r.Header {
  472. if strings.HasPrefix(k, "X-Meta-") {
  473. metaHeaders[k] = v
  474. }
  475. }
  476. job = eng.Job("pull", image, tag)
  477. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  478. job.SetenvJson("metaHeaders", metaHeaders)
  479. job.SetenvJson("authConfig", authConfig)
  480. } else { //import
  481. if tag == "" {
  482. repo, tag = parsers.ParseRepositoryTag(repo)
  483. }
  484. job = eng.Job("import", r.Form.Get("fromSrc"), repo, tag)
  485. job.Stdin.Add(r.Body)
  486. }
  487. if version.GreaterThan("1.0") {
  488. job.SetenvBool("json", true)
  489. streamJSON(job, w, true)
  490. } else {
  491. job.Stdout.Add(utils.NewWriteFlusher(w))
  492. }
  493. if err := job.Run(); err != nil {
  494. if !job.Stdout.Used() {
  495. return err
  496. }
  497. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  498. w.Write(sf.FormatError(err))
  499. }
  500. return nil
  501. }
  502. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  503. if err := parseForm(r); err != nil {
  504. return err
  505. }
  506. var (
  507. authEncoded = r.Header.Get("X-Registry-Auth")
  508. authConfig = &registry.AuthConfig{}
  509. metaHeaders = map[string][]string{}
  510. )
  511. if authEncoded != "" {
  512. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  513. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  514. // for a search it is not an error if no auth was given
  515. // to increase compatibility with the existing api it is defaulting to be empty
  516. authConfig = &registry.AuthConfig{}
  517. }
  518. }
  519. for k, v := range r.Header {
  520. if strings.HasPrefix(k, "X-Meta-") {
  521. metaHeaders[k] = v
  522. }
  523. }
  524. var job = eng.Job("search", r.Form.Get("term"))
  525. job.SetenvJson("metaHeaders", metaHeaders)
  526. job.SetenvJson("authConfig", authConfig)
  527. streamJSON(job, w, false)
  528. return job.Run()
  529. }
  530. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  531. if vars == nil {
  532. return fmt.Errorf("Missing parameter")
  533. }
  534. metaHeaders := map[string][]string{}
  535. for k, v := range r.Header {
  536. if strings.HasPrefix(k, "X-Meta-") {
  537. metaHeaders[k] = v
  538. }
  539. }
  540. if err := parseForm(r); err != nil {
  541. return err
  542. }
  543. authConfig := &registry.AuthConfig{}
  544. authEncoded := r.Header.Get("X-Registry-Auth")
  545. if authEncoded != "" {
  546. // the new format is to handle the authConfig as a header
  547. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  548. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  549. // to increase compatibility to existing api it is defaulting to be empty
  550. authConfig = &registry.AuthConfig{}
  551. }
  552. } else {
  553. // the old format is supported for compatibility if there was no authConfig header
  554. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  555. return err
  556. }
  557. }
  558. job := eng.Job("push", vars["name"])
  559. job.SetenvJson("metaHeaders", metaHeaders)
  560. job.SetenvJson("authConfig", authConfig)
  561. job.Setenv("tag", r.Form.Get("tag"))
  562. if version.GreaterThan("1.0") {
  563. job.SetenvBool("json", true)
  564. streamJSON(job, w, true)
  565. } else {
  566. job.Stdout.Add(utils.NewWriteFlusher(w))
  567. }
  568. if err := job.Run(); err != nil {
  569. if !job.Stdout.Used() {
  570. return err
  571. }
  572. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  573. w.Write(sf.FormatError(err))
  574. }
  575. return nil
  576. }
  577. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  578. if vars == nil {
  579. return fmt.Errorf("Missing parameter")
  580. }
  581. if err := parseForm(r); err != nil {
  582. return err
  583. }
  584. if version.GreaterThan("1.0") {
  585. w.Header().Set("Content-Type", "application/x-tar")
  586. }
  587. var job *engine.Job
  588. if name, ok := vars["name"]; ok {
  589. job = eng.Job("image_export", name)
  590. } else {
  591. job = eng.Job("image_export", r.Form["names"]...)
  592. }
  593. job.Stdout.Add(w)
  594. return job.Run()
  595. }
  596. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  597. job := eng.Job("load")
  598. job.Stdin.Add(r.Body)
  599. return job.Run()
  600. }
  601. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  602. if err := parseForm(r); err != nil {
  603. return nil
  604. }
  605. var (
  606. out engine.Env
  607. job = eng.Job("create", r.Form.Get("name"))
  608. outWarnings []string
  609. stdoutBuffer = bytes.NewBuffer(nil)
  610. warnings = bytes.NewBuffer(nil)
  611. )
  612. if err := checkForJson(r); err != nil {
  613. return err
  614. }
  615. if err := job.DecodeEnv(r.Body); err != nil {
  616. return err
  617. }
  618. // Read container ID from the first line of stdout
  619. job.Stdout.Add(stdoutBuffer)
  620. // Read warnings from stderr
  621. job.Stderr.Add(warnings)
  622. if err := job.Run(); err != nil {
  623. return err
  624. }
  625. // Parse warnings from stderr
  626. scanner := bufio.NewScanner(warnings)
  627. for scanner.Scan() {
  628. outWarnings = append(outWarnings, scanner.Text())
  629. }
  630. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  631. out.SetList("Warnings", outWarnings)
  632. return writeJSON(w, http.StatusCreated, out)
  633. }
  634. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  635. if err := parseForm(r); err != nil {
  636. return err
  637. }
  638. if vars == nil {
  639. return fmt.Errorf("Missing parameter")
  640. }
  641. job := eng.Job("restart", vars["name"])
  642. job.Setenv("t", r.Form.Get("t"))
  643. if err := job.Run(); err != nil {
  644. return err
  645. }
  646. w.WriteHeader(http.StatusNoContent)
  647. return nil
  648. }
  649. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  650. if err := parseForm(r); err != nil {
  651. return err
  652. }
  653. if vars == nil {
  654. return fmt.Errorf("Missing parameter")
  655. }
  656. job := eng.Job("rm", vars["name"])
  657. job.Setenv("forceRemove", r.Form.Get("force"))
  658. job.Setenv("removeVolume", r.Form.Get("v"))
  659. job.Setenv("removeLink", r.Form.Get("link"))
  660. if err := job.Run(); err != nil {
  661. return err
  662. }
  663. w.WriteHeader(http.StatusNoContent)
  664. return nil
  665. }
  666. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  667. if err := parseForm(r); err != nil {
  668. return err
  669. }
  670. if vars == nil {
  671. return fmt.Errorf("Missing parameter")
  672. }
  673. var job = eng.Job("image_delete", vars["name"])
  674. streamJSON(job, w, false)
  675. job.Setenv("force", r.Form.Get("force"))
  676. job.Setenv("noprune", r.Form.Get("noprune"))
  677. return job.Run()
  678. }
  679. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  680. if vars == nil {
  681. return fmt.Errorf("Missing parameter")
  682. }
  683. var (
  684. name = vars["name"]
  685. job = eng.Job("start", name)
  686. )
  687. // If contentLength is -1, we can assumed chunked encoding
  688. // or more technically that the length is unknown
  689. // http://golang.org/src/pkg/net/http/request.go#L139
  690. // net/http otherwise seems to swallow any headers related to chunked encoding
  691. // including r.TransferEncoding
  692. // allow a nil body for backwards compatibility
  693. if r.Body != nil && (r.ContentLength > 0 || r.ContentLength == -1) {
  694. if err := checkForJson(r); err != nil {
  695. return err
  696. }
  697. if err := job.DecodeEnv(r.Body); err != nil {
  698. return err
  699. }
  700. }
  701. if err := job.Run(); err != nil {
  702. if err.Error() == "Container already started" {
  703. w.WriteHeader(http.StatusNotModified)
  704. return nil
  705. }
  706. return err
  707. }
  708. w.WriteHeader(http.StatusNoContent)
  709. return nil
  710. }
  711. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  712. if err := parseForm(r); err != nil {
  713. return err
  714. }
  715. if vars == nil {
  716. return fmt.Errorf("Missing parameter")
  717. }
  718. job := eng.Job("stop", vars["name"])
  719. job.Setenv("t", r.Form.Get("t"))
  720. if err := job.Run(); err != nil {
  721. if err.Error() == "Container already stopped" {
  722. w.WriteHeader(http.StatusNotModified)
  723. return nil
  724. }
  725. return err
  726. }
  727. w.WriteHeader(http.StatusNoContent)
  728. return nil
  729. }
  730. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  731. if vars == nil {
  732. return fmt.Errorf("Missing parameter")
  733. }
  734. var (
  735. env engine.Env
  736. stdoutBuffer = bytes.NewBuffer(nil)
  737. job = eng.Job("wait", vars["name"])
  738. )
  739. job.Stdout.Add(stdoutBuffer)
  740. if err := job.Run(); err != nil {
  741. return err
  742. }
  743. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  744. return writeJSON(w, http.StatusOK, env)
  745. }
  746. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  747. if err := parseForm(r); err != nil {
  748. return err
  749. }
  750. if vars == nil {
  751. return fmt.Errorf("Missing parameter")
  752. }
  753. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  754. return err
  755. }
  756. return nil
  757. }
  758. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  759. if err := parseForm(r); err != nil {
  760. return err
  761. }
  762. if vars == nil {
  763. return fmt.Errorf("Missing parameter")
  764. }
  765. var (
  766. job = eng.Job("container_inspect", vars["name"])
  767. c, err = job.Stdout.AddEnv()
  768. )
  769. if err != nil {
  770. return err
  771. }
  772. if err = job.Run(); err != nil {
  773. return err
  774. }
  775. inStream, outStream, err := hijackServer(w)
  776. if err != nil {
  777. return err
  778. }
  779. defer func() {
  780. if tcpc, ok := inStream.(*net.TCPConn); ok {
  781. tcpc.CloseWrite()
  782. } else {
  783. inStream.Close()
  784. }
  785. }()
  786. defer func() {
  787. if tcpc, ok := outStream.(*net.TCPConn); ok {
  788. tcpc.CloseWrite()
  789. } else if closer, ok := outStream.(io.Closer); ok {
  790. closer.Close()
  791. }
  792. }()
  793. var errStream io.Writer
  794. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  795. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  796. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  797. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  798. } else {
  799. errStream = outStream
  800. }
  801. job = eng.Job("attach", vars["name"])
  802. job.Setenv("logs", r.Form.Get("logs"))
  803. job.Setenv("stream", r.Form.Get("stream"))
  804. job.Setenv("stdin", r.Form.Get("stdin"))
  805. job.Setenv("stdout", r.Form.Get("stdout"))
  806. job.Setenv("stderr", r.Form.Get("stderr"))
  807. job.Stdin.Add(inStream)
  808. job.Stdout.Add(outStream)
  809. job.Stderr.Set(errStream)
  810. if err := job.Run(); err != nil {
  811. fmt.Fprintf(outStream, "Error attaching: %s\n", err)
  812. }
  813. return nil
  814. }
  815. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  816. if err := parseForm(r); err != nil {
  817. return err
  818. }
  819. if vars == nil {
  820. return fmt.Errorf("Missing parameter")
  821. }
  822. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  823. return err
  824. }
  825. h := websocket.Handler(func(ws *websocket.Conn) {
  826. defer ws.Close()
  827. job := eng.Job("attach", vars["name"])
  828. job.Setenv("logs", r.Form.Get("logs"))
  829. job.Setenv("stream", r.Form.Get("stream"))
  830. job.Setenv("stdin", r.Form.Get("stdin"))
  831. job.Setenv("stdout", r.Form.Get("stdout"))
  832. job.Setenv("stderr", r.Form.Get("stderr"))
  833. job.Stdin.Add(ws)
  834. job.Stdout.Add(ws)
  835. job.Stderr.Set(ws)
  836. if err := job.Run(); err != nil {
  837. log.Errorf("Error attaching websocket: %s", err)
  838. }
  839. })
  840. h.ServeHTTP(w, r)
  841. return nil
  842. }
  843. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  844. if vars == nil {
  845. return fmt.Errorf("Missing parameter")
  846. }
  847. var job = eng.Job("container_inspect", vars["name"])
  848. if version.LessThan("1.12") {
  849. job.SetenvBool("raw", true)
  850. }
  851. streamJSON(job, w, false)
  852. return job.Run()
  853. }
  854. func getExecByID(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  855. if vars == nil {
  856. return fmt.Errorf("Missing parameter 'id'")
  857. }
  858. var job = eng.Job("execInspect", vars["id"])
  859. streamJSON(job, w, false)
  860. return job.Run()
  861. }
  862. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  863. if vars == nil {
  864. return fmt.Errorf("Missing parameter")
  865. }
  866. var job = eng.Job("image_inspect", vars["name"])
  867. if version.LessThan("1.12") {
  868. job.SetenvBool("raw", true)
  869. }
  870. streamJSON(job, w, false)
  871. return job.Run()
  872. }
  873. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  874. if version.LessThan("1.3") {
  875. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  876. }
  877. var (
  878. authEncoded = r.Header.Get("X-Registry-Auth")
  879. authConfig = &registry.AuthConfig{}
  880. configFileEncoded = r.Header.Get("X-Registry-Config")
  881. configFile = &registry.ConfigFile{}
  882. job = eng.Job("build")
  883. )
  884. // This block can be removed when API versions prior to 1.9 are deprecated.
  885. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  886. // ConfigFile is present, any value provided as an AuthConfig directly will
  887. // be overridden. See BuildFile::CmdFrom for details.
  888. if version.LessThan("1.9") && authEncoded != "" {
  889. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  890. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  891. // for a pull it is not an error if no auth was given
  892. // to increase compatibility with the existing api it is defaulting to be empty
  893. authConfig = &registry.AuthConfig{}
  894. }
  895. }
  896. if configFileEncoded != "" {
  897. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  898. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  899. // for a pull it is not an error if no auth was given
  900. // to increase compatibility with the existing api it is defaulting to be empty
  901. configFile = &registry.ConfigFile{}
  902. }
  903. }
  904. if version.GreaterThanOrEqualTo("1.8") {
  905. job.SetenvBool("json", true)
  906. streamJSON(job, w, true)
  907. } else {
  908. job.Stdout.Add(utils.NewWriteFlusher(w))
  909. }
  910. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  911. job.Setenv("rm", "1")
  912. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  913. job.Setenv("rm", "1")
  914. } else {
  915. job.Setenv("rm", r.FormValue("rm"))
  916. }
  917. if r.FormValue("pull") == "1" && version.GreaterThanOrEqualTo("1.16") {
  918. job.Setenv("pull", "1")
  919. }
  920. job.Stdin.Add(r.Body)
  921. job.Setenv("remote", r.FormValue("remote"))
  922. job.Setenv("t", r.FormValue("t"))
  923. job.Setenv("q", r.FormValue("q"))
  924. job.Setenv("nocache", r.FormValue("nocache"))
  925. job.Setenv("forcerm", r.FormValue("forcerm"))
  926. job.SetenvJson("authConfig", authConfig)
  927. job.SetenvJson("configFile", configFile)
  928. if err := job.Run(); err != nil {
  929. if !job.Stdout.Used() {
  930. return err
  931. }
  932. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  933. w.Write(sf.FormatError(err))
  934. }
  935. return nil
  936. }
  937. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  938. if vars == nil {
  939. return fmt.Errorf("Missing parameter")
  940. }
  941. var copyData engine.Env
  942. if err := checkForJson(r); err != nil {
  943. return err
  944. }
  945. if err := copyData.Decode(r.Body); err != nil {
  946. return err
  947. }
  948. if copyData.Get("Resource") == "" {
  949. return fmt.Errorf("Path cannot be empty")
  950. }
  951. origResource := copyData.Get("Resource")
  952. if copyData.Get("Resource")[0] == '/' {
  953. copyData.Set("Resource", copyData.Get("Resource")[1:])
  954. }
  955. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  956. job.Stdout.Add(w)
  957. w.Header().Set("Content-Type", "application/x-tar")
  958. if err := job.Run(); err != nil {
  959. log.Errorf("%s", err.Error())
  960. if strings.Contains(strings.ToLower(err.Error()), "no such container") {
  961. w.WriteHeader(http.StatusNotFound)
  962. } else if strings.Contains(err.Error(), "no such file or directory") {
  963. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  964. }
  965. }
  966. return nil
  967. }
  968. func postContainerExecCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  969. if err := parseForm(r); err != nil {
  970. return nil
  971. }
  972. var (
  973. out engine.Env
  974. name = vars["name"]
  975. job = eng.Job("execCreate", name)
  976. stdoutBuffer = bytes.NewBuffer(nil)
  977. )
  978. if err := job.DecodeEnv(r.Body); err != nil {
  979. return err
  980. }
  981. job.Stdout.Add(stdoutBuffer)
  982. // Register an instance of Exec in container.
  983. if err := job.Run(); err != nil {
  984. fmt.Fprintf(os.Stderr, "Error setting up exec command in container %s: %s\n", name, err)
  985. return err
  986. }
  987. // Return the ID
  988. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  989. return writeJSON(w, http.StatusCreated, out)
  990. }
  991. // TODO(vishh): Refactor the code to avoid having to specify stream config as part of both create and start.
  992. func postContainerExecStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  993. if err := parseForm(r); err != nil {
  994. return nil
  995. }
  996. var (
  997. name = vars["name"]
  998. job = eng.Job("execStart", name)
  999. errOut io.Writer = os.Stderr
  1000. )
  1001. if err := job.DecodeEnv(r.Body); err != nil {
  1002. return err
  1003. }
  1004. if !job.GetenvBool("Detach") {
  1005. // Setting up the streaming http interface.
  1006. inStream, outStream, err := hijackServer(w)
  1007. if err != nil {
  1008. return err
  1009. }
  1010. defer func() {
  1011. if cw, ok := inStream.(interface {
  1012. CloseWrite() error
  1013. }); ok {
  1014. cw.CloseWrite()
  1015. } else {
  1016. inStream.Close()
  1017. }
  1018. }()
  1019. defer func() {
  1020. if cw, ok := outStream.(interface {
  1021. CloseWrite() error
  1022. }); ok {
  1023. cw.CloseWrite()
  1024. } else if closer, ok := outStream.(io.Closer); ok {
  1025. closer.Close()
  1026. }
  1027. }()
  1028. var errStream io.Writer
  1029. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  1030. if !job.GetenvBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  1031. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  1032. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  1033. } else {
  1034. errStream = outStream
  1035. }
  1036. job.Stdin.Add(inStream)
  1037. job.Stdout.Add(outStream)
  1038. job.Stderr.Set(errStream)
  1039. errOut = outStream
  1040. }
  1041. // Now run the user process in container.
  1042. job.SetCloseIO(false)
  1043. if err := job.Run(); err != nil {
  1044. fmt.Fprintf(errOut, "Error starting exec command in container %s: %s\n", name, err)
  1045. return err
  1046. }
  1047. w.WriteHeader(http.StatusNoContent)
  1048. return nil
  1049. }
  1050. func postContainerExecResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1051. if err := parseForm(r); err != nil {
  1052. return err
  1053. }
  1054. if vars == nil {
  1055. return fmt.Errorf("Missing parameter")
  1056. }
  1057. if err := eng.Job("execResize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  1058. return err
  1059. }
  1060. return nil
  1061. }
  1062. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1063. w.WriteHeader(http.StatusOK)
  1064. return nil
  1065. }
  1066. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  1067. w.Header().Add("Access-Control-Allow-Origin", "*")
  1068. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept, X-Registry-Auth")
  1069. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  1070. }
  1071. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1072. _, err := w.Write([]byte{'O', 'K'})
  1073. return err
  1074. }
  1075. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  1076. return func(w http.ResponseWriter, r *http.Request) {
  1077. // log the request
  1078. log.Debugf("Calling %s %s", localMethod, localRoute)
  1079. if logging {
  1080. log.Infof("%s %s", r.Method, r.RequestURI)
  1081. }
  1082. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  1083. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  1084. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  1085. log.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  1086. }
  1087. }
  1088. version := version.Version(mux.Vars(r)["version"])
  1089. if version == "" {
  1090. version = api.APIVERSION
  1091. }
  1092. if enableCors {
  1093. writeCorsHeaders(w, r)
  1094. }
  1095. if version.GreaterThan(api.APIVERSION) {
  1096. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  1097. return
  1098. }
  1099. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  1100. log.Errorf("Handler for %s %s returned error: %s", localMethod, localRoute, err)
  1101. httpError(w, err)
  1102. }
  1103. }
  1104. }
  1105. // Replicated from expvar.go as not public.
  1106. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  1107. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  1108. fmt.Fprintf(w, "{\n")
  1109. first := true
  1110. expvar.Do(func(kv expvar.KeyValue) {
  1111. if !first {
  1112. fmt.Fprintf(w, ",\n")
  1113. }
  1114. first = false
  1115. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  1116. })
  1117. fmt.Fprintf(w, "\n}\n")
  1118. }
  1119. func AttachProfiler(router *mux.Router) {
  1120. router.HandleFunc("/debug/vars", expvarHandler)
  1121. router.HandleFunc("/debug/pprof/", pprof.Index)
  1122. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  1123. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  1124. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  1125. router.HandleFunc("/debug/pprof/block", pprof.Handler("block").ServeHTTP)
  1126. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  1127. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  1128. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  1129. }
  1130. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) (*mux.Router, error) {
  1131. r := mux.NewRouter()
  1132. if os.Getenv("DEBUG") != "" {
  1133. AttachProfiler(r)
  1134. }
  1135. m := map[string]map[string]HttpApiFunc{
  1136. "GET": {
  1137. "/_ping": ping,
  1138. "/events": getEvents,
  1139. "/info": getInfo,
  1140. "/version": getVersion,
  1141. "/images/json": getImagesJSON,
  1142. "/images/viz": getImagesViz,
  1143. "/images/search": getImagesSearch,
  1144. "/images/get": getImagesGet,
  1145. "/images/{name:.*}/get": getImagesGet,
  1146. "/images/{name:.*}/history": getImagesHistory,
  1147. "/images/{name:.*}/json": getImagesByName,
  1148. "/containers/ps": getContainersJSON,
  1149. "/containers/json": getContainersJSON,
  1150. "/containers/{name:.*}/export": getContainersExport,
  1151. "/containers/{name:.*}/changes": getContainersChanges,
  1152. "/containers/{name:.*}/json": getContainersByName,
  1153. "/containers/{name:.*}/top": getContainersTop,
  1154. "/containers/{name:.*}/logs": getContainersLogs,
  1155. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  1156. "/exec/{id:.*}/json": getExecByID,
  1157. },
  1158. "POST": {
  1159. "/auth": postAuth,
  1160. "/commit": postCommit,
  1161. "/build": postBuild,
  1162. "/images/create": postImagesCreate,
  1163. "/images/load": postImagesLoad,
  1164. "/images/{name:.*}/push": postImagesPush,
  1165. "/images/{name:.*}/tag": postImagesTag,
  1166. "/containers/create": postContainersCreate,
  1167. "/containers/{name:.*}/kill": postContainersKill,
  1168. "/containers/{name:.*}/pause": postContainersPause,
  1169. "/containers/{name:.*}/unpause": postContainersUnpause,
  1170. "/containers/{name:.*}/restart": postContainersRestart,
  1171. "/containers/{name:.*}/start": postContainersStart,
  1172. "/containers/{name:.*}/stop": postContainersStop,
  1173. "/containers/{name:.*}/wait": postContainersWait,
  1174. "/containers/{name:.*}/resize": postContainersResize,
  1175. "/containers/{name:.*}/attach": postContainersAttach,
  1176. "/containers/{name:.*}/copy": postContainersCopy,
  1177. "/containers/{name:.*}/exec": postContainerExecCreate,
  1178. "/exec/{name:.*}/start": postContainerExecStart,
  1179. "/exec/{name:.*}/resize": postContainerExecResize,
  1180. },
  1181. "DELETE": {
  1182. "/containers/{name:.*}": deleteContainers,
  1183. "/images/{name:.*}": deleteImages,
  1184. },
  1185. "OPTIONS": {
  1186. "": optionsHandler,
  1187. },
  1188. }
  1189. for method, routes := range m {
  1190. for route, fct := range routes {
  1191. log.Debugf("Registering %s, %s", method, route)
  1192. // NOTE: scope issue, make sure the variables are local and won't be changed
  1193. localRoute := route
  1194. localFct := fct
  1195. localMethod := method
  1196. // build the handler function
  1197. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1198. // add the new route
  1199. if localRoute == "" {
  1200. r.Methods(localMethod).HandlerFunc(f)
  1201. } else {
  1202. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1203. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1204. }
  1205. }
  1206. }
  1207. return r, nil
  1208. }
  1209. // ServeRequest processes a single http request to the docker remote api.
  1210. // FIXME: refactor this to be part of Server and not require re-creating a new
  1211. // router each time. This requires first moving ListenAndServe into Server.
  1212. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) error {
  1213. router, err := createRouter(eng, false, true, "")
  1214. if err != nil {
  1215. return err
  1216. }
  1217. // Insert APIVERSION into the request as a convenience
  1218. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1219. router.ServeHTTP(w, req)
  1220. return nil
  1221. }
  1222. // serveFd creates an http.Server and sets it up to serve given a socket activated
  1223. // argument.
  1224. func serveFd(addr string, job *engine.Job) error {
  1225. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1226. if err != nil {
  1227. return err
  1228. }
  1229. ls, e := systemd.ListenFD(addr)
  1230. if e != nil {
  1231. return e
  1232. }
  1233. chErrors := make(chan error, len(ls))
  1234. // We don't want to start serving on these sockets until the
  1235. // daemon is initialized and installed. Otherwise required handlers
  1236. // won't be ready.
  1237. <-activationLock
  1238. // Since ListenFD will return one or more sockets we have
  1239. // to create a go func to spawn off multiple serves
  1240. for i := range ls {
  1241. listener := ls[i]
  1242. go func() {
  1243. httpSrv := http.Server{Handler: r}
  1244. chErrors <- httpSrv.Serve(listener)
  1245. }()
  1246. }
  1247. for i := 0; i < len(ls); i++ {
  1248. err := <-chErrors
  1249. if err != nil {
  1250. return err
  1251. }
  1252. }
  1253. return nil
  1254. }
  1255. func lookupGidByName(nameOrGid string) (int, error) {
  1256. groupFile, err := user.GetGroupFile()
  1257. if err != nil {
  1258. return -1, err
  1259. }
  1260. groups, err := user.ParseGroupFileFilter(groupFile, func(g user.Group) bool {
  1261. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1262. })
  1263. if err != nil {
  1264. return -1, err
  1265. }
  1266. if groups != nil && len(groups) > 0 {
  1267. return groups[0].Gid, nil
  1268. }
  1269. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1270. }
  1271. func setupTls(cert, key, ca string, l net.Listener) (net.Listener, error) {
  1272. tlsCert, err := tls.LoadX509KeyPair(cert, key)
  1273. if err != nil {
  1274. return nil, fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1275. cert, key, err)
  1276. }
  1277. tlsConfig := &tls.Config{
  1278. NextProtos: []string{"http/1.1"},
  1279. Certificates: []tls.Certificate{tlsCert},
  1280. // Avoid fallback on insecure SSL protocols
  1281. MinVersion: tls.VersionTLS10,
  1282. }
  1283. if ca != "" {
  1284. certPool := x509.NewCertPool()
  1285. file, err := ioutil.ReadFile(ca)
  1286. if err != nil {
  1287. return nil, fmt.Errorf("Couldn't read CA certificate: %s", err)
  1288. }
  1289. certPool.AppendCertsFromPEM(file)
  1290. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1291. tlsConfig.ClientCAs = certPool
  1292. }
  1293. return tls.NewListener(l, tlsConfig), nil
  1294. }
  1295. func newListener(proto, addr string, bufferRequests bool) (net.Listener, error) {
  1296. if bufferRequests {
  1297. return listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1298. }
  1299. return net.Listen(proto, addr)
  1300. }
  1301. func changeGroup(addr string, nameOrGid string) error {
  1302. gid, err := lookupGidByName(nameOrGid)
  1303. if err != nil {
  1304. return err
  1305. }
  1306. log.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1307. return os.Chown(addr, 0, gid)
  1308. }
  1309. func setSocketGroup(addr, group string) error {
  1310. if group == "" {
  1311. return nil
  1312. }
  1313. if err := changeGroup(addr, group); err != nil {
  1314. if group != "docker" {
  1315. return err
  1316. }
  1317. log.Debugf("Warning: could not chgrp %s to docker: %v", addr, err)
  1318. }
  1319. return nil
  1320. }
  1321. func setupUnixHttp(addr string, job *engine.Job) (*HttpServer, error) {
  1322. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1323. if err != nil {
  1324. return nil, err
  1325. }
  1326. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1327. return nil, err
  1328. }
  1329. mask := syscall.Umask(0777)
  1330. defer syscall.Umask(mask)
  1331. l, err := newListener("unix", addr, job.GetenvBool("BufferRequests"))
  1332. if err != nil {
  1333. return nil, err
  1334. }
  1335. if err := setSocketGroup(addr, job.Getenv("SocketGroup")); err != nil {
  1336. return nil, err
  1337. }
  1338. if err := os.Chmod(addr, 0660); err != nil {
  1339. return nil, err
  1340. }
  1341. return &HttpServer{&http.Server{Addr: addr, Handler: r}, l}, nil
  1342. }
  1343. func setupTcpHttp(addr string, job *engine.Job) (*HttpServer, error) {
  1344. if !strings.HasPrefix(addr, "127.0.0.1") && !job.GetenvBool("TlsVerify") {
  1345. log.Infof("/!\\ DON'T BIND ON ANOTHER IP ADDRESS THAN 127.0.0.1 IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1346. }
  1347. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1348. if err != nil {
  1349. return nil, err
  1350. }
  1351. l, err := newListener("tcp", addr, job.GetenvBool("BufferRequests"))
  1352. if err != nil {
  1353. return nil, err
  1354. }
  1355. if job.GetenvBool("Tls") || job.GetenvBool("TlsVerify") {
  1356. var tlsCa string
  1357. if job.GetenvBool("TlsVerify") {
  1358. tlsCa = job.Getenv("TlsCa")
  1359. }
  1360. l, err = setupTls(job.Getenv("TlsCert"), job.Getenv("TlsKey"), tlsCa, l)
  1361. if err != nil {
  1362. return nil, err
  1363. }
  1364. }
  1365. return &HttpServer{&http.Server{Addr: addr, Handler: r}, l}, nil
  1366. }
  1367. // NewServer sets up the required Server and does protocol specific checking.
  1368. func NewServer(proto, addr string, job *engine.Job) (Server, error) {
  1369. // Basic error and sanity checking
  1370. switch proto {
  1371. case "fd":
  1372. return nil, serveFd(addr, job)
  1373. case "tcp":
  1374. return setupTcpHttp(addr, job)
  1375. case "unix":
  1376. return setupUnixHttp(addr, job)
  1377. default:
  1378. return nil, fmt.Errorf("Invalid protocol format.")
  1379. }
  1380. }
  1381. type Server interface {
  1382. Serve() error
  1383. Close() error
  1384. }
  1385. // ServeApi loops through all of the protocols sent in to docker and spawns
  1386. // off a go routine to setup a serving http.Server for each.
  1387. func ServeApi(job *engine.Job) engine.Status {
  1388. if len(job.Args) == 0 {
  1389. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1390. }
  1391. var (
  1392. protoAddrs = job.Args
  1393. chErrors = make(chan error, len(protoAddrs))
  1394. )
  1395. activationLock = make(chan struct{})
  1396. for _, protoAddr := range protoAddrs {
  1397. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1398. if len(protoAddrParts) != 2 {
  1399. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1400. }
  1401. go func() {
  1402. log.Infof("Listening for HTTP on %s (%s)", protoAddrParts[0], protoAddrParts[1])
  1403. srv, err := NewServer(protoAddrParts[0], protoAddrParts[1], job)
  1404. if err != nil {
  1405. chErrors <- err
  1406. return
  1407. }
  1408. chErrors <- srv.Serve()
  1409. }()
  1410. }
  1411. for i := 0; i < len(protoAddrs); i++ {
  1412. err := <-chErrors
  1413. if err != nil {
  1414. return job.Error(err)
  1415. }
  1416. }
  1417. return engine.StatusOK
  1418. }
  1419. func AcceptConnections(job *engine.Job) engine.Status {
  1420. // Tell the init daemon we are accepting requests
  1421. go systemd.SdNotify("READY=1")
  1422. // close the lock so the listeners start accepting connections
  1423. if activationLock != nil {
  1424. close(activationLock)
  1425. }
  1426. return engine.StatusOK
  1427. }