server.go 48 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "encoding/base64"
  6. "encoding/json"
  7. "expvar"
  8. "fmt"
  9. "io"
  10. "io/ioutil"
  11. "net"
  12. "net/http"
  13. "net/http/pprof"
  14. "os"
  15. "strconv"
  16. "strings"
  17. "syscall"
  18. "crypto/tls"
  19. "crypto/x509"
  20. "code.google.com/p/go.net/websocket"
  21. "github.com/docker/libcontainer/user"
  22. "github.com/gorilla/mux"
  23. log "github.com/Sirupsen/logrus"
  24. "github.com/docker/docker/api"
  25. "github.com/docker/docker/api/types"
  26. "github.com/docker/docker/daemon/networkdriver/portallocator"
  27. "github.com/docker/docker/engine"
  28. "github.com/docker/docker/pkg/listenbuffer"
  29. "github.com/docker/docker/pkg/parsers"
  30. "github.com/docker/docker/pkg/stdcopy"
  31. "github.com/docker/docker/pkg/systemd"
  32. "github.com/docker/docker/pkg/version"
  33. "github.com/docker/docker/registry"
  34. "github.com/docker/docker/utils"
  35. )
  36. var (
  37. activationLock chan struct{}
  38. )
  39. type HttpServer struct {
  40. srv *http.Server
  41. l net.Listener
  42. }
  43. func (s *HttpServer) Serve() error {
  44. return s.srv.Serve(s.l)
  45. }
  46. func (s *HttpServer) Close() error {
  47. return s.l.Close()
  48. }
  49. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  50. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  51. conn, _, err := w.(http.Hijacker).Hijack()
  52. if err != nil {
  53. return nil, nil, err
  54. }
  55. // Flush the options to make sure the client sets the raw mode
  56. conn.Write([]byte{})
  57. return conn, conn, nil
  58. }
  59. func closeStreams(streams ...interface{}) {
  60. for _, stream := range streams {
  61. if tcpc, ok := stream.(interface {
  62. CloseWrite() error
  63. }); ok {
  64. tcpc.CloseWrite()
  65. } else if closer, ok := stream.(io.Closer); ok {
  66. closer.Close()
  67. }
  68. }
  69. }
  70. // Check to make sure request's Content-Type is application/json
  71. func checkForJson(r *http.Request) error {
  72. ct := r.Header.Get("Content-Type")
  73. // No Content-Type header is ok as long as there's no Body
  74. if ct == "" {
  75. if r.Body == nil || r.ContentLength == 0 {
  76. return nil
  77. }
  78. }
  79. // Otherwise it better be json
  80. if api.MatchesContentType(ct, "application/json") {
  81. return nil
  82. }
  83. return fmt.Errorf("Content-Type specified (%s) must be 'application/json'", ct)
  84. }
  85. //If we don't do this, POST method without Content-type (even with empty body) will fail
  86. func parseForm(r *http.Request) error {
  87. if r == nil {
  88. return nil
  89. }
  90. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  91. return err
  92. }
  93. return nil
  94. }
  95. func parseMultipartForm(r *http.Request) error {
  96. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  97. return err
  98. }
  99. return nil
  100. }
  101. func httpError(w http.ResponseWriter, err error) {
  102. statusCode := http.StatusInternalServerError
  103. // FIXME: this is brittle and should not be necessary.
  104. // If we need to differentiate between different possible error types, we should
  105. // create appropriate error types with clearly defined meaning.
  106. errStr := strings.ToLower(err.Error())
  107. if strings.Contains(errStr, "no such") {
  108. statusCode = http.StatusNotFound
  109. } else if strings.Contains(errStr, "bad parameter") {
  110. statusCode = http.StatusBadRequest
  111. } else if strings.Contains(errStr, "conflict") {
  112. statusCode = http.StatusConflict
  113. } else if strings.Contains(errStr, "impossible") {
  114. statusCode = http.StatusNotAcceptable
  115. } else if strings.Contains(errStr, "wrong login/password") {
  116. statusCode = http.StatusUnauthorized
  117. } else if strings.Contains(errStr, "hasn't been activated") {
  118. statusCode = http.StatusForbidden
  119. }
  120. if err != nil {
  121. log.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  122. http.Error(w, err.Error(), statusCode)
  123. }
  124. }
  125. // writeJSONEnv writes the engine.Env values to the http response stream as a
  126. // json encoded body.
  127. func writeJSONEnv(w http.ResponseWriter, code int, v engine.Env) error {
  128. w.Header().Set("Content-Type", "application/json")
  129. w.WriteHeader(code)
  130. return v.Encode(w)
  131. }
  132. // writeJSON writes the value v to the http response stream as json with standard
  133. // json encoding.
  134. func writeJSON(w http.ResponseWriter, code int, v interface{}) error {
  135. w.Header().Set("Content-Type", "application/json")
  136. w.WriteHeader(code)
  137. return json.NewEncoder(w).Encode(v)
  138. }
  139. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  140. w.Header().Set("Content-Type", "application/json")
  141. if flush {
  142. job.Stdout.Add(utils.NewWriteFlusher(w))
  143. } else {
  144. job.Stdout.Add(w)
  145. }
  146. }
  147. func getBoolParam(value string) (bool, error) {
  148. if value == "" {
  149. return false, nil
  150. }
  151. ret, err := strconv.ParseBool(value)
  152. if err != nil {
  153. return false, fmt.Errorf("Bad parameter")
  154. }
  155. return ret, nil
  156. }
  157. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  158. var (
  159. authConfig, err = ioutil.ReadAll(r.Body)
  160. job = eng.Job("auth")
  161. stdoutBuffer = bytes.NewBuffer(nil)
  162. )
  163. if err != nil {
  164. return err
  165. }
  166. job.Setenv("authConfig", string(authConfig))
  167. job.Stdout.Add(stdoutBuffer)
  168. if err = job.Run(); err != nil {
  169. return err
  170. }
  171. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  172. var env engine.Env
  173. env.Set("Status", status)
  174. return writeJSONEnv(w, http.StatusOK, env)
  175. }
  176. w.WriteHeader(http.StatusNoContent)
  177. return nil
  178. }
  179. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  180. w.Header().Set("Content-Type", "application/json")
  181. eng.ServeHTTP(w, r)
  182. return nil
  183. }
  184. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  185. if vars == nil {
  186. return fmt.Errorf("Missing parameter")
  187. }
  188. if err := parseForm(r); err != nil {
  189. return err
  190. }
  191. job := eng.Job("kill", vars["name"])
  192. if sig := r.Form.Get("signal"); sig != "" {
  193. job.Args = append(job.Args, sig)
  194. }
  195. if err := job.Run(); err != nil {
  196. return err
  197. }
  198. w.WriteHeader(http.StatusNoContent)
  199. return nil
  200. }
  201. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  202. if vars == nil {
  203. return fmt.Errorf("Missing parameter")
  204. }
  205. if err := parseForm(r); err != nil {
  206. return err
  207. }
  208. job := eng.Job("pause", vars["name"])
  209. if err := job.Run(); err != nil {
  210. return err
  211. }
  212. w.WriteHeader(http.StatusNoContent)
  213. return nil
  214. }
  215. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  216. if vars == nil {
  217. return fmt.Errorf("Missing parameter")
  218. }
  219. if err := parseForm(r); err != nil {
  220. return err
  221. }
  222. job := eng.Job("unpause", vars["name"])
  223. if err := job.Run(); err != nil {
  224. return err
  225. }
  226. w.WriteHeader(http.StatusNoContent)
  227. return nil
  228. }
  229. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  230. if vars == nil {
  231. return fmt.Errorf("Missing parameter")
  232. }
  233. job := eng.Job("export", vars["name"])
  234. job.Stdout.Add(w)
  235. if err := job.Run(); err != nil {
  236. return err
  237. }
  238. return nil
  239. }
  240. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  241. if err := parseForm(r); err != nil {
  242. return err
  243. }
  244. var (
  245. err error
  246. outs *engine.Table
  247. job = eng.Job("images")
  248. )
  249. job.Setenv("filters", r.Form.Get("filters"))
  250. // FIXME this parameter could just be a match filter
  251. job.Setenv("filter", r.Form.Get("filter"))
  252. job.Setenv("all", r.Form.Get("all"))
  253. if version.GreaterThanOrEqualTo("1.7") {
  254. streamJSON(job, w, false)
  255. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  256. return err
  257. }
  258. if err := job.Run(); err != nil {
  259. return err
  260. }
  261. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  262. outsLegacy := engine.NewTable("Created", 0)
  263. for _, out := range outs.Data {
  264. for _, repoTag := range out.GetList("RepoTags") {
  265. repo, tag := parsers.ParseRepositoryTag(repoTag)
  266. outLegacy := &engine.Env{}
  267. outLegacy.Set("Repository", repo)
  268. outLegacy.SetJson("Tag", tag)
  269. outLegacy.Set("Id", out.Get("Id"))
  270. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  271. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  272. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  273. outsLegacy.Add(outLegacy)
  274. }
  275. }
  276. w.Header().Set("Content-Type", "application/json")
  277. if _, err := outsLegacy.WriteListTo(w); err != nil {
  278. return err
  279. }
  280. }
  281. return nil
  282. }
  283. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  284. if version.GreaterThan("1.6") {
  285. w.WriteHeader(http.StatusNotFound)
  286. return fmt.Errorf("This is now implemented in the client.")
  287. }
  288. eng.ServeHTTP(w, r)
  289. return nil
  290. }
  291. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  292. w.Header().Set("Content-Type", "application/json")
  293. eng.ServeHTTP(w, r)
  294. return nil
  295. }
  296. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  297. if err := parseForm(r); err != nil {
  298. return err
  299. }
  300. var job = eng.Job("events")
  301. streamJSON(job, w, true)
  302. job.Setenv("since", r.Form.Get("since"))
  303. job.Setenv("until", r.Form.Get("until"))
  304. job.Setenv("filters", r.Form.Get("filters"))
  305. return job.Run()
  306. }
  307. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  308. if vars == nil {
  309. return fmt.Errorf("Missing parameter")
  310. }
  311. var job = eng.Job("history", vars["name"])
  312. streamJSON(job, w, false)
  313. if err := job.Run(); err != nil {
  314. return err
  315. }
  316. return nil
  317. }
  318. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  319. if vars == nil {
  320. return fmt.Errorf("Missing parameter")
  321. }
  322. var job = eng.Job("container_changes", vars["name"])
  323. streamJSON(job, w, false)
  324. return job.Run()
  325. }
  326. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  327. if version.LessThan("1.4") {
  328. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  329. }
  330. if vars == nil {
  331. return fmt.Errorf("Missing parameter")
  332. }
  333. if err := parseForm(r); err != nil {
  334. return err
  335. }
  336. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  337. streamJSON(job, w, false)
  338. return job.Run()
  339. }
  340. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  341. if err := parseForm(r); err != nil {
  342. return err
  343. }
  344. var (
  345. err error
  346. outs *engine.Table
  347. job = eng.Job("containers")
  348. )
  349. job.Setenv("all", r.Form.Get("all"))
  350. job.Setenv("size", r.Form.Get("size"))
  351. job.Setenv("since", r.Form.Get("since"))
  352. job.Setenv("before", r.Form.Get("before"))
  353. job.Setenv("limit", r.Form.Get("limit"))
  354. job.Setenv("filters", r.Form.Get("filters"))
  355. if version.GreaterThanOrEqualTo("1.5") {
  356. streamJSON(job, w, false)
  357. } else if outs, err = job.Stdout.AddTable(); err != nil {
  358. return err
  359. }
  360. if err = job.Run(); err != nil {
  361. return err
  362. }
  363. if version.LessThan("1.5") { // Convert to legacy format
  364. for _, out := range outs.Data {
  365. ports := engine.NewTable("", 0)
  366. ports.ReadListFrom([]byte(out.Get("Ports")))
  367. out.Set("Ports", api.DisplayablePorts(ports))
  368. }
  369. w.Header().Set("Content-Type", "application/json")
  370. if _, err = outs.WriteListTo(w); err != nil {
  371. return err
  372. }
  373. }
  374. return nil
  375. }
  376. func getContainersStats(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  377. if err := parseForm(r); err != nil {
  378. return err
  379. }
  380. if vars == nil {
  381. return fmt.Errorf("Missing parameter")
  382. }
  383. name := vars["name"]
  384. job := eng.Job("container_stats", name)
  385. streamJSON(job, w, true)
  386. return job.Run()
  387. }
  388. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  389. if err := parseForm(r); err != nil {
  390. return err
  391. }
  392. if vars == nil {
  393. return fmt.Errorf("Missing parameter")
  394. }
  395. var (
  396. inspectJob = eng.Job("container_inspect", vars["name"])
  397. logsJob = eng.Job("logs", vars["name"])
  398. c, err = inspectJob.Stdout.AddEnv()
  399. )
  400. if err != nil {
  401. return err
  402. }
  403. logsJob.Setenv("follow", r.Form.Get("follow"))
  404. logsJob.Setenv("tail", r.Form.Get("tail"))
  405. logsJob.Setenv("stdout", r.Form.Get("stdout"))
  406. logsJob.Setenv("stderr", r.Form.Get("stderr"))
  407. logsJob.Setenv("timestamps", r.Form.Get("timestamps"))
  408. // Validate args here, because we can't return not StatusOK after job.Run() call
  409. stdout, stderr := logsJob.GetenvBool("stdout"), logsJob.GetenvBool("stderr")
  410. if !(stdout || stderr) {
  411. return fmt.Errorf("Bad parameters: you must choose at least one stream")
  412. }
  413. if err = inspectJob.Run(); err != nil {
  414. return err
  415. }
  416. var outStream, errStream io.Writer
  417. outStream = utils.NewWriteFlusher(w)
  418. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  419. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  420. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  421. } else {
  422. errStream = outStream
  423. }
  424. logsJob.Stdout.Add(outStream)
  425. logsJob.Stderr.Set(errStream)
  426. if err := logsJob.Run(); err != nil {
  427. fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
  428. }
  429. return nil
  430. }
  431. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  432. if err := parseForm(r); err != nil {
  433. return err
  434. }
  435. if vars == nil {
  436. return fmt.Errorf("Missing parameter")
  437. }
  438. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  439. job.Setenv("force", r.Form.Get("force"))
  440. if err := job.Run(); err != nil {
  441. return err
  442. }
  443. w.WriteHeader(http.StatusCreated)
  444. return nil
  445. }
  446. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  447. if err := parseForm(r); err != nil {
  448. return err
  449. }
  450. var (
  451. config engine.Env
  452. env engine.Env
  453. job = eng.Job("commit", r.Form.Get("container"))
  454. stdoutBuffer = bytes.NewBuffer(nil)
  455. )
  456. if err := checkForJson(r); err != nil {
  457. return err
  458. }
  459. if err := config.Decode(r.Body); err != nil {
  460. log.Errorf("%s", err)
  461. }
  462. if r.FormValue("pause") == "" && version.GreaterThanOrEqualTo("1.13") {
  463. job.Setenv("pause", "1")
  464. } else {
  465. job.Setenv("pause", r.FormValue("pause"))
  466. }
  467. job.Setenv("repo", r.Form.Get("repo"))
  468. job.Setenv("tag", r.Form.Get("tag"))
  469. job.Setenv("author", r.Form.Get("author"))
  470. job.Setenv("comment", r.Form.Get("comment"))
  471. job.SetenvList("changes", r.Form["changes"])
  472. job.SetenvSubEnv("config", &config)
  473. job.Stdout.Add(stdoutBuffer)
  474. if err := job.Run(); err != nil {
  475. return err
  476. }
  477. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  478. return writeJSONEnv(w, http.StatusCreated, env)
  479. }
  480. // Creates an image from Pull or from Import
  481. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  482. if err := parseForm(r); err != nil {
  483. return err
  484. }
  485. var (
  486. image = r.Form.Get("fromImage")
  487. repo = r.Form.Get("repo")
  488. tag = r.Form.Get("tag")
  489. job *engine.Job
  490. )
  491. authEncoded := r.Header.Get("X-Registry-Auth")
  492. authConfig := &registry.AuthConfig{}
  493. if authEncoded != "" {
  494. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  495. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  496. // for a pull it is not an error if no auth was given
  497. // to increase compatibility with the existing api it is defaulting to be empty
  498. authConfig = &registry.AuthConfig{}
  499. }
  500. }
  501. if image != "" { //pull
  502. if tag == "" {
  503. image, tag = parsers.ParseRepositoryTag(image)
  504. }
  505. metaHeaders := map[string][]string{}
  506. for k, v := range r.Header {
  507. if strings.HasPrefix(k, "X-Meta-") {
  508. metaHeaders[k] = v
  509. }
  510. }
  511. job = eng.Job("pull", image, tag)
  512. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  513. job.SetenvJson("metaHeaders", metaHeaders)
  514. job.SetenvJson("authConfig", authConfig)
  515. } else { //import
  516. if tag == "" {
  517. repo, tag = parsers.ParseRepositoryTag(repo)
  518. }
  519. job = eng.Job("import", r.Form.Get("fromSrc"), repo, tag)
  520. job.Stdin.Add(r.Body)
  521. job.SetenvList("changes", r.Form["changes"])
  522. }
  523. if version.GreaterThan("1.0") {
  524. job.SetenvBool("json", true)
  525. streamJSON(job, w, true)
  526. } else {
  527. job.Stdout.Add(utils.NewWriteFlusher(w))
  528. }
  529. if err := job.Run(); err != nil {
  530. if !job.Stdout.Used() {
  531. return err
  532. }
  533. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  534. w.Write(sf.FormatError(err))
  535. }
  536. return nil
  537. }
  538. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  539. if err := parseForm(r); err != nil {
  540. return err
  541. }
  542. var (
  543. authEncoded = r.Header.Get("X-Registry-Auth")
  544. authConfig = &registry.AuthConfig{}
  545. metaHeaders = map[string][]string{}
  546. )
  547. if authEncoded != "" {
  548. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  549. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  550. // for a search it is not an error if no auth was given
  551. // to increase compatibility with the existing api it is defaulting to be empty
  552. authConfig = &registry.AuthConfig{}
  553. }
  554. }
  555. for k, v := range r.Header {
  556. if strings.HasPrefix(k, "X-Meta-") {
  557. metaHeaders[k] = v
  558. }
  559. }
  560. var job = eng.Job("search", r.Form.Get("term"))
  561. job.SetenvJson("metaHeaders", metaHeaders)
  562. job.SetenvJson("authConfig", authConfig)
  563. streamJSON(job, w, false)
  564. return job.Run()
  565. }
  566. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  567. if vars == nil {
  568. return fmt.Errorf("Missing parameter")
  569. }
  570. metaHeaders := map[string][]string{}
  571. for k, v := range r.Header {
  572. if strings.HasPrefix(k, "X-Meta-") {
  573. metaHeaders[k] = v
  574. }
  575. }
  576. if err := parseForm(r); err != nil {
  577. return err
  578. }
  579. authConfig := &registry.AuthConfig{}
  580. authEncoded := r.Header.Get("X-Registry-Auth")
  581. if authEncoded != "" {
  582. // the new format is to handle the authConfig as a header
  583. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  584. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  585. // to increase compatibility to existing api it is defaulting to be empty
  586. authConfig = &registry.AuthConfig{}
  587. }
  588. } else {
  589. // the old format is supported for compatibility if there was no authConfig header
  590. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  591. return err
  592. }
  593. }
  594. job := eng.Job("push", vars["name"])
  595. job.SetenvJson("metaHeaders", metaHeaders)
  596. job.SetenvJson("authConfig", authConfig)
  597. job.Setenv("tag", r.Form.Get("tag"))
  598. if version.GreaterThan("1.0") {
  599. job.SetenvBool("json", true)
  600. streamJSON(job, w, true)
  601. } else {
  602. job.Stdout.Add(utils.NewWriteFlusher(w))
  603. }
  604. if err := job.Run(); err != nil {
  605. if !job.Stdout.Used() {
  606. return err
  607. }
  608. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  609. w.Write(sf.FormatError(err))
  610. }
  611. return nil
  612. }
  613. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  614. if vars == nil {
  615. return fmt.Errorf("Missing parameter")
  616. }
  617. if err := parseForm(r); err != nil {
  618. return err
  619. }
  620. if version.GreaterThan("1.0") {
  621. w.Header().Set("Content-Type", "application/x-tar")
  622. }
  623. var job *engine.Job
  624. if name, ok := vars["name"]; ok {
  625. job = eng.Job("image_export", name)
  626. } else {
  627. job = eng.Job("image_export", r.Form["names"]...)
  628. }
  629. job.Stdout.Add(w)
  630. return job.Run()
  631. }
  632. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  633. job := eng.Job("load")
  634. job.Stdin.Add(r.Body)
  635. return job.Run()
  636. }
  637. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  638. if err := parseForm(r); err != nil {
  639. return nil
  640. }
  641. if err := checkForJson(r); err != nil {
  642. return err
  643. }
  644. var (
  645. job = eng.Job("create", r.Form.Get("name"))
  646. outWarnings []string
  647. stdoutBuffer = bytes.NewBuffer(nil)
  648. warnings = bytes.NewBuffer(nil)
  649. )
  650. if err := job.DecodeEnv(r.Body); err != nil {
  651. return err
  652. }
  653. // Read container ID from the first line of stdout
  654. job.Stdout.Add(stdoutBuffer)
  655. // Read warnings from stderr
  656. job.Stderr.Add(warnings)
  657. if err := job.Run(); err != nil {
  658. return err
  659. }
  660. // Parse warnings from stderr
  661. scanner := bufio.NewScanner(warnings)
  662. for scanner.Scan() {
  663. outWarnings = append(outWarnings, scanner.Text())
  664. }
  665. return writeJSON(w, http.StatusCreated, &types.ContainerCreateResponse{
  666. ID: engine.Tail(stdoutBuffer, 1),
  667. Warnings: outWarnings,
  668. })
  669. }
  670. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  671. if err := parseForm(r); err != nil {
  672. return err
  673. }
  674. if vars == nil {
  675. return fmt.Errorf("Missing parameter")
  676. }
  677. job := eng.Job("restart", vars["name"])
  678. job.Setenv("t", r.Form.Get("t"))
  679. if err := job.Run(); err != nil {
  680. return err
  681. }
  682. w.WriteHeader(http.StatusNoContent)
  683. return nil
  684. }
  685. func postContainerRename(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  686. if err := parseForm(r); err != nil {
  687. return err
  688. }
  689. if vars == nil {
  690. return fmt.Errorf("Missing parameter")
  691. }
  692. newName := r.URL.Query().Get("name")
  693. job := eng.Job("container_rename", vars["name"], newName)
  694. job.Setenv("t", r.Form.Get("t"))
  695. if err := job.Run(); err != nil {
  696. return err
  697. }
  698. w.WriteHeader(http.StatusNoContent)
  699. return nil
  700. }
  701. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  702. if err := parseForm(r); err != nil {
  703. return err
  704. }
  705. if vars == nil {
  706. return fmt.Errorf("Missing parameter")
  707. }
  708. job := eng.Job("rm", vars["name"])
  709. job.Setenv("forceRemove", r.Form.Get("force"))
  710. job.Setenv("removeVolume", r.Form.Get("v"))
  711. job.Setenv("removeLink", r.Form.Get("link"))
  712. if err := job.Run(); err != nil {
  713. return err
  714. }
  715. w.WriteHeader(http.StatusNoContent)
  716. return nil
  717. }
  718. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  719. if err := parseForm(r); err != nil {
  720. return err
  721. }
  722. if vars == nil {
  723. return fmt.Errorf("Missing parameter")
  724. }
  725. var job = eng.Job("image_delete", vars["name"])
  726. streamJSON(job, w, false)
  727. job.Setenv("force", r.Form.Get("force"))
  728. job.Setenv("noprune", r.Form.Get("noprune"))
  729. return job.Run()
  730. }
  731. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  732. if vars == nil {
  733. return fmt.Errorf("Missing parameter")
  734. }
  735. var (
  736. name = vars["name"]
  737. job = eng.Job("start", name)
  738. )
  739. // If contentLength is -1, we can assumed chunked encoding
  740. // or more technically that the length is unknown
  741. // http://golang.org/src/pkg/net/http/request.go#L139
  742. // net/http otherwise seems to swallow any headers related to chunked encoding
  743. // including r.TransferEncoding
  744. // allow a nil body for backwards compatibility
  745. if r.Body != nil && (r.ContentLength > 0 || r.ContentLength == -1) {
  746. if err := checkForJson(r); err != nil {
  747. return err
  748. }
  749. if err := job.DecodeEnv(r.Body); err != nil {
  750. return err
  751. }
  752. }
  753. if err := job.Run(); err != nil {
  754. if err.Error() == "Container already started" {
  755. w.WriteHeader(http.StatusNotModified)
  756. return nil
  757. }
  758. return err
  759. }
  760. w.WriteHeader(http.StatusNoContent)
  761. return nil
  762. }
  763. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  764. if err := parseForm(r); err != nil {
  765. return err
  766. }
  767. if vars == nil {
  768. return fmt.Errorf("Missing parameter")
  769. }
  770. job := eng.Job("stop", vars["name"])
  771. job.Setenv("t", r.Form.Get("t"))
  772. if err := job.Run(); err != nil {
  773. if err.Error() == "Container already stopped" {
  774. w.WriteHeader(http.StatusNotModified)
  775. return nil
  776. }
  777. return err
  778. }
  779. w.WriteHeader(http.StatusNoContent)
  780. return nil
  781. }
  782. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  783. if vars == nil {
  784. return fmt.Errorf("Missing parameter")
  785. }
  786. var (
  787. env engine.Env
  788. stdoutBuffer = bytes.NewBuffer(nil)
  789. job = eng.Job("wait", vars["name"])
  790. )
  791. job.Stdout.Add(stdoutBuffer)
  792. if err := job.Run(); err != nil {
  793. return err
  794. }
  795. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  796. return writeJSONEnv(w, http.StatusOK, env)
  797. }
  798. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  799. if err := parseForm(r); err != nil {
  800. return err
  801. }
  802. if vars == nil {
  803. return fmt.Errorf("Missing parameter")
  804. }
  805. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  806. return err
  807. }
  808. return nil
  809. }
  810. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  811. if err := parseForm(r); err != nil {
  812. return err
  813. }
  814. if vars == nil {
  815. return fmt.Errorf("Missing parameter")
  816. }
  817. var (
  818. job = eng.Job("container_inspect", vars["name"])
  819. c, err = job.Stdout.AddEnv()
  820. )
  821. if err != nil {
  822. return err
  823. }
  824. if err = job.Run(); err != nil {
  825. return err
  826. }
  827. inStream, outStream, err := hijackServer(w)
  828. if err != nil {
  829. return err
  830. }
  831. defer closeStreams(inStream, outStream)
  832. var errStream io.Writer
  833. if _, ok := r.Header["Upgrade"]; ok {
  834. fmt.Fprintf(outStream, "HTTP/1.1 101 UPGRADED\r\nContent-Type: application/vnd.docker.raw-stream\r\nConnection: Upgrade\r\nUpgrade: tcp\r\n\r\n")
  835. } else {
  836. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  837. }
  838. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  839. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  840. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  841. } else {
  842. errStream = outStream
  843. }
  844. job = eng.Job("attach", vars["name"])
  845. job.Setenv("logs", r.Form.Get("logs"))
  846. job.Setenv("stream", r.Form.Get("stream"))
  847. job.Setenv("stdin", r.Form.Get("stdin"))
  848. job.Setenv("stdout", r.Form.Get("stdout"))
  849. job.Setenv("stderr", r.Form.Get("stderr"))
  850. job.Stdin.Add(inStream)
  851. job.Stdout.Add(outStream)
  852. job.Stderr.Set(errStream)
  853. if err := job.Run(); err != nil {
  854. fmt.Fprintf(outStream, "Error attaching: %s\n", err)
  855. }
  856. return nil
  857. }
  858. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  859. if err := parseForm(r); err != nil {
  860. return err
  861. }
  862. if vars == nil {
  863. return fmt.Errorf("Missing parameter")
  864. }
  865. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  866. return err
  867. }
  868. h := websocket.Handler(func(ws *websocket.Conn) {
  869. defer ws.Close()
  870. job := eng.Job("attach", vars["name"])
  871. job.Setenv("logs", r.Form.Get("logs"))
  872. job.Setenv("stream", r.Form.Get("stream"))
  873. job.Setenv("stdin", r.Form.Get("stdin"))
  874. job.Setenv("stdout", r.Form.Get("stdout"))
  875. job.Setenv("stderr", r.Form.Get("stderr"))
  876. job.Stdin.Add(ws)
  877. job.Stdout.Add(ws)
  878. job.Stderr.Set(ws)
  879. if err := job.Run(); err != nil {
  880. log.Errorf("Error attaching websocket: %s", err)
  881. }
  882. })
  883. h.ServeHTTP(w, r)
  884. return nil
  885. }
  886. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  887. if vars == nil {
  888. return fmt.Errorf("Missing parameter")
  889. }
  890. var job = eng.Job("container_inspect", vars["name"])
  891. if version.LessThan("1.12") {
  892. job.SetenvBool("raw", true)
  893. }
  894. streamJSON(job, w, false)
  895. return job.Run()
  896. }
  897. func getExecByID(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  898. if vars == nil {
  899. return fmt.Errorf("Missing parameter 'id'")
  900. }
  901. var job = eng.Job("execInspect", vars["id"])
  902. streamJSON(job, w, false)
  903. return job.Run()
  904. }
  905. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  906. if vars == nil {
  907. return fmt.Errorf("Missing parameter")
  908. }
  909. var job = eng.Job("image_inspect", vars["name"])
  910. if version.LessThan("1.12") {
  911. job.SetenvBool("raw", true)
  912. }
  913. streamJSON(job, w, false)
  914. return job.Run()
  915. }
  916. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  917. if version.LessThan("1.3") {
  918. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  919. }
  920. var (
  921. authEncoded = r.Header.Get("X-Registry-Auth")
  922. authConfig = &registry.AuthConfig{}
  923. configFileEncoded = r.Header.Get("X-Registry-Config")
  924. configFile = &registry.ConfigFile{}
  925. job = eng.Job("build")
  926. )
  927. // This block can be removed when API versions prior to 1.9 are deprecated.
  928. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  929. // ConfigFile is present, any value provided as an AuthConfig directly will
  930. // be overridden. See BuildFile::CmdFrom for details.
  931. if version.LessThan("1.9") && authEncoded != "" {
  932. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  933. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  934. // for a pull it is not an error if no auth was given
  935. // to increase compatibility with the existing api it is defaulting to be empty
  936. authConfig = &registry.AuthConfig{}
  937. }
  938. }
  939. if configFileEncoded != "" {
  940. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  941. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  942. // for a pull it is not an error if no auth was given
  943. // to increase compatibility with the existing api it is defaulting to be empty
  944. configFile = &registry.ConfigFile{}
  945. }
  946. }
  947. if version.GreaterThanOrEqualTo("1.8") {
  948. job.SetenvBool("json", true)
  949. streamJSON(job, w, true)
  950. } else {
  951. job.Stdout.Add(utils.NewWriteFlusher(w))
  952. }
  953. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  954. job.Setenv("rm", "1")
  955. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  956. job.Setenv("rm", "1")
  957. } else {
  958. job.Setenv("rm", r.FormValue("rm"))
  959. }
  960. if r.FormValue("pull") == "1" && version.GreaterThanOrEqualTo("1.16") {
  961. job.Setenv("pull", "1")
  962. }
  963. job.Stdin.Add(r.Body)
  964. job.Setenv("remote", r.FormValue("remote"))
  965. job.Setenv("dockerfile", r.FormValue("dockerfile"))
  966. job.Setenv("t", r.FormValue("t"))
  967. job.Setenv("q", r.FormValue("q"))
  968. job.Setenv("nocache", r.FormValue("nocache"))
  969. job.Setenv("forcerm", r.FormValue("forcerm"))
  970. job.SetenvJson("authConfig", authConfig)
  971. job.SetenvJson("configFile", configFile)
  972. if err := job.Run(); err != nil {
  973. if !job.Stdout.Used() {
  974. return err
  975. }
  976. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  977. w.Write(sf.FormatError(err))
  978. }
  979. return nil
  980. }
  981. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  982. if vars == nil {
  983. return fmt.Errorf("Missing parameter")
  984. }
  985. var copyData engine.Env
  986. if err := checkForJson(r); err != nil {
  987. return err
  988. }
  989. if err := copyData.Decode(r.Body); err != nil {
  990. return err
  991. }
  992. if copyData.Get("Resource") == "" {
  993. return fmt.Errorf("Path cannot be empty")
  994. }
  995. origResource := copyData.Get("Resource")
  996. if copyData.Get("Resource")[0] == '/' {
  997. copyData.Set("Resource", copyData.Get("Resource")[1:])
  998. }
  999. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  1000. job.Stdout.Add(w)
  1001. w.Header().Set("Content-Type", "application/x-tar")
  1002. if err := job.Run(); err != nil {
  1003. log.Errorf("%s", err.Error())
  1004. if strings.Contains(strings.ToLower(err.Error()), "no such id") {
  1005. w.WriteHeader(http.StatusNotFound)
  1006. } else if strings.Contains(err.Error(), "no such file or directory") {
  1007. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  1008. }
  1009. }
  1010. return nil
  1011. }
  1012. func postContainerExecCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1013. if err := parseForm(r); err != nil {
  1014. return nil
  1015. }
  1016. var (
  1017. out engine.Env
  1018. name = vars["name"]
  1019. job = eng.Job("execCreate", name)
  1020. stdoutBuffer = bytes.NewBuffer(nil)
  1021. )
  1022. if err := job.DecodeEnv(r.Body); err != nil {
  1023. return err
  1024. }
  1025. job.Stdout.Add(stdoutBuffer)
  1026. // Register an instance of Exec in container.
  1027. if err := job.Run(); err != nil {
  1028. fmt.Fprintf(os.Stderr, "Error setting up exec command in container %s: %s\n", name, err)
  1029. return err
  1030. }
  1031. // Return the ID
  1032. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  1033. return writeJSONEnv(w, http.StatusCreated, out)
  1034. }
  1035. // TODO(vishh): Refactor the code to avoid having to specify stream config as part of both create and start.
  1036. func postContainerExecStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1037. if err := parseForm(r); err != nil {
  1038. return nil
  1039. }
  1040. var (
  1041. name = vars["name"]
  1042. job = eng.Job("execStart", name)
  1043. errOut io.Writer = os.Stderr
  1044. )
  1045. if err := job.DecodeEnv(r.Body); err != nil {
  1046. return err
  1047. }
  1048. if !job.GetenvBool("Detach") {
  1049. // Setting up the streaming http interface.
  1050. inStream, outStream, err := hijackServer(w)
  1051. if err != nil {
  1052. return err
  1053. }
  1054. defer closeStreams(inStream, outStream)
  1055. var errStream io.Writer
  1056. if _, ok := r.Header["Upgrade"]; ok {
  1057. fmt.Fprintf(outStream, "HTTP/1.1 101 UPGRADED\r\nContent-Type: application/vnd.docker.raw-stream\r\nConnection: Upgrade\r\nUpgrade: tcp\r\n\r\n")
  1058. } else {
  1059. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  1060. }
  1061. if !job.GetenvBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  1062. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  1063. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  1064. } else {
  1065. errStream = outStream
  1066. }
  1067. job.Stdin.Add(inStream)
  1068. job.Stdout.Add(outStream)
  1069. job.Stderr.Set(errStream)
  1070. errOut = outStream
  1071. }
  1072. // Now run the user process in container.
  1073. job.SetCloseIO(false)
  1074. if err := job.Run(); err != nil {
  1075. fmt.Fprintf(errOut, "Error starting exec command in container %s: %s\n", name, err)
  1076. return err
  1077. }
  1078. w.WriteHeader(http.StatusNoContent)
  1079. return nil
  1080. }
  1081. func postContainerExecResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1082. if err := parseForm(r); err != nil {
  1083. return err
  1084. }
  1085. if vars == nil {
  1086. return fmt.Errorf("Missing parameter")
  1087. }
  1088. if err := eng.Job("execResize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  1089. return err
  1090. }
  1091. return nil
  1092. }
  1093. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1094. w.WriteHeader(http.StatusOK)
  1095. return nil
  1096. }
  1097. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  1098. w.Header().Add("Access-Control-Allow-Origin", "*")
  1099. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept, X-Registry-Auth")
  1100. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  1101. }
  1102. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1103. _, err := w.Write([]byte{'O', 'K'})
  1104. return err
  1105. }
  1106. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  1107. return func(w http.ResponseWriter, r *http.Request) {
  1108. // log the request
  1109. log.Debugf("Calling %s %s", localMethod, localRoute)
  1110. if logging {
  1111. log.Infof("%s %s", r.Method, r.RequestURI)
  1112. }
  1113. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  1114. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  1115. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  1116. log.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  1117. }
  1118. }
  1119. version := version.Version(mux.Vars(r)["version"])
  1120. if version == "" {
  1121. version = api.APIVERSION
  1122. }
  1123. if enableCors {
  1124. writeCorsHeaders(w, r)
  1125. }
  1126. if version.GreaterThan(api.APIVERSION) {
  1127. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  1128. return
  1129. }
  1130. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  1131. log.Errorf("Handler for %s %s returned error: %s", localMethod, localRoute, err)
  1132. httpError(w, err)
  1133. }
  1134. }
  1135. }
  1136. // Replicated from expvar.go as not public.
  1137. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  1138. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  1139. fmt.Fprintf(w, "{\n")
  1140. first := true
  1141. expvar.Do(func(kv expvar.KeyValue) {
  1142. if !first {
  1143. fmt.Fprintf(w, ",\n")
  1144. }
  1145. first = false
  1146. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  1147. })
  1148. fmt.Fprintf(w, "\n}\n")
  1149. }
  1150. func AttachProfiler(router *mux.Router) {
  1151. router.HandleFunc("/debug/vars", expvarHandler)
  1152. router.HandleFunc("/debug/pprof/", pprof.Index)
  1153. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  1154. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  1155. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  1156. router.HandleFunc("/debug/pprof/block", pprof.Handler("block").ServeHTTP)
  1157. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  1158. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  1159. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  1160. }
  1161. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) *mux.Router {
  1162. r := mux.NewRouter()
  1163. if os.Getenv("DEBUG") != "" {
  1164. AttachProfiler(r)
  1165. }
  1166. m := map[string]map[string]HttpApiFunc{
  1167. "GET": {
  1168. "/_ping": ping,
  1169. "/events": getEvents,
  1170. "/info": getInfo,
  1171. "/version": getVersion,
  1172. "/images/json": getImagesJSON,
  1173. "/images/viz": getImagesViz,
  1174. "/images/search": getImagesSearch,
  1175. "/images/get": getImagesGet,
  1176. "/images/{name:.*}/get": getImagesGet,
  1177. "/images/{name:.*}/history": getImagesHistory,
  1178. "/images/{name:.*}/json": getImagesByName,
  1179. "/containers/ps": getContainersJSON,
  1180. "/containers/json": getContainersJSON,
  1181. "/containers/{name:.*}/export": getContainersExport,
  1182. "/containers/{name:.*}/changes": getContainersChanges,
  1183. "/containers/{name:.*}/json": getContainersByName,
  1184. "/containers/{name:.*}/top": getContainersTop,
  1185. "/containers/{name:.*}/logs": getContainersLogs,
  1186. "/containers/{name:.*}/stats": getContainersStats,
  1187. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  1188. "/exec/{id:.*}/json": getExecByID,
  1189. },
  1190. "POST": {
  1191. "/auth": postAuth,
  1192. "/commit": postCommit,
  1193. "/build": postBuild,
  1194. "/images/create": postImagesCreate,
  1195. "/images/load": postImagesLoad,
  1196. "/images/{name:.*}/push": postImagesPush,
  1197. "/images/{name:.*}/tag": postImagesTag,
  1198. "/containers/create": postContainersCreate,
  1199. "/containers/{name:.*}/kill": postContainersKill,
  1200. "/containers/{name:.*}/pause": postContainersPause,
  1201. "/containers/{name:.*}/unpause": postContainersUnpause,
  1202. "/containers/{name:.*}/restart": postContainersRestart,
  1203. "/containers/{name:.*}/start": postContainersStart,
  1204. "/containers/{name:.*}/stop": postContainersStop,
  1205. "/containers/{name:.*}/wait": postContainersWait,
  1206. "/containers/{name:.*}/resize": postContainersResize,
  1207. "/containers/{name:.*}/attach": postContainersAttach,
  1208. "/containers/{name:.*}/copy": postContainersCopy,
  1209. "/containers/{name:.*}/exec": postContainerExecCreate,
  1210. "/exec/{name:.*}/start": postContainerExecStart,
  1211. "/exec/{name:.*}/resize": postContainerExecResize,
  1212. "/containers/{name:.*}/rename": postContainerRename,
  1213. },
  1214. "DELETE": {
  1215. "/containers/{name:.*}": deleteContainers,
  1216. "/images/{name:.*}": deleteImages,
  1217. },
  1218. "OPTIONS": {
  1219. "": optionsHandler,
  1220. },
  1221. }
  1222. for method, routes := range m {
  1223. for route, fct := range routes {
  1224. log.Debugf("Registering %s, %s", method, route)
  1225. // NOTE: scope issue, make sure the variables are local and won't be changed
  1226. localRoute := route
  1227. localFct := fct
  1228. localMethod := method
  1229. // build the handler function
  1230. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1231. // add the new route
  1232. if localRoute == "" {
  1233. r.Methods(localMethod).HandlerFunc(f)
  1234. } else {
  1235. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1236. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1237. }
  1238. }
  1239. }
  1240. return r
  1241. }
  1242. // ServeRequest processes a single http request to the docker remote api.
  1243. // FIXME: refactor this to be part of Server and not require re-creating a new
  1244. // router each time. This requires first moving ListenAndServe into Server.
  1245. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) {
  1246. router := createRouter(eng, false, true, "")
  1247. // Insert APIVERSION into the request as a convenience
  1248. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1249. router.ServeHTTP(w, req)
  1250. }
  1251. // serveFd creates an http.Server and sets it up to serve given a socket activated
  1252. // argument.
  1253. func serveFd(addr string, job *engine.Job) error {
  1254. r := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1255. ls, e := systemd.ListenFD(addr)
  1256. if e != nil {
  1257. return e
  1258. }
  1259. chErrors := make(chan error, len(ls))
  1260. // We don't want to start serving on these sockets until the
  1261. // daemon is initialized and installed. Otherwise required handlers
  1262. // won't be ready.
  1263. <-activationLock
  1264. // Since ListenFD will return one or more sockets we have
  1265. // to create a go func to spawn off multiple serves
  1266. for i := range ls {
  1267. listener := ls[i]
  1268. go func() {
  1269. httpSrv := http.Server{Handler: r}
  1270. chErrors <- httpSrv.Serve(listener)
  1271. }()
  1272. }
  1273. for i := 0; i < len(ls); i++ {
  1274. err := <-chErrors
  1275. if err != nil {
  1276. return err
  1277. }
  1278. }
  1279. return nil
  1280. }
  1281. func lookupGidByName(nameOrGid string) (int, error) {
  1282. groupFile, err := user.GetGroupPath()
  1283. if err != nil {
  1284. return -1, err
  1285. }
  1286. groups, err := user.ParseGroupFileFilter(groupFile, func(g user.Group) bool {
  1287. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1288. })
  1289. if err != nil {
  1290. return -1, err
  1291. }
  1292. if groups != nil && len(groups) > 0 {
  1293. return groups[0].Gid, nil
  1294. }
  1295. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1296. }
  1297. func setupTls(cert, key, ca string, l net.Listener) (net.Listener, error) {
  1298. tlsCert, err := tls.LoadX509KeyPair(cert, key)
  1299. if err != nil {
  1300. return nil, fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1301. cert, key, err)
  1302. }
  1303. tlsConfig := &tls.Config{
  1304. NextProtos: []string{"http/1.1"},
  1305. Certificates: []tls.Certificate{tlsCert},
  1306. // Avoid fallback on insecure SSL protocols
  1307. MinVersion: tls.VersionTLS10,
  1308. }
  1309. if ca != "" {
  1310. certPool := x509.NewCertPool()
  1311. file, err := ioutil.ReadFile(ca)
  1312. if err != nil {
  1313. return nil, fmt.Errorf("Couldn't read CA certificate: %s", err)
  1314. }
  1315. certPool.AppendCertsFromPEM(file)
  1316. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1317. tlsConfig.ClientCAs = certPool
  1318. }
  1319. return tls.NewListener(l, tlsConfig), nil
  1320. }
  1321. func newListener(proto, addr string, bufferRequests bool) (net.Listener, error) {
  1322. if bufferRequests {
  1323. return listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1324. }
  1325. return net.Listen(proto, addr)
  1326. }
  1327. func changeGroup(addr string, nameOrGid string) error {
  1328. gid, err := lookupGidByName(nameOrGid)
  1329. if err != nil {
  1330. return err
  1331. }
  1332. log.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1333. return os.Chown(addr, 0, gid)
  1334. }
  1335. func setSocketGroup(addr, group string) error {
  1336. if group == "" {
  1337. return nil
  1338. }
  1339. if err := changeGroup(addr, group); err != nil {
  1340. if group != "docker" {
  1341. return err
  1342. }
  1343. log.Debugf("Warning: could not chgrp %s to docker: %v", addr, err)
  1344. }
  1345. return nil
  1346. }
  1347. func setupUnixHttp(addr string, job *engine.Job) (*HttpServer, error) {
  1348. r := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1349. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1350. return nil, err
  1351. }
  1352. mask := syscall.Umask(0777)
  1353. defer syscall.Umask(mask)
  1354. l, err := newListener("unix", addr, job.GetenvBool("BufferRequests"))
  1355. if err != nil {
  1356. return nil, err
  1357. }
  1358. if err := setSocketGroup(addr, job.Getenv("SocketGroup")); err != nil {
  1359. return nil, err
  1360. }
  1361. if err := os.Chmod(addr, 0660); err != nil {
  1362. return nil, err
  1363. }
  1364. return &HttpServer{&http.Server{Addr: addr, Handler: r}, l}, nil
  1365. }
  1366. func allocateDaemonPort(addr string) error {
  1367. host, port, err := net.SplitHostPort(addr)
  1368. if err != nil {
  1369. return err
  1370. }
  1371. intPort, err := strconv.Atoi(port)
  1372. if err != nil {
  1373. return err
  1374. }
  1375. var hostIPs []net.IP
  1376. if parsedIP := net.ParseIP(host); parsedIP != nil {
  1377. hostIPs = append(hostIPs, parsedIP)
  1378. } else if hostIPs, err = net.LookupIP(host); err != nil {
  1379. return fmt.Errorf("failed to lookup %s address in host specification", host)
  1380. }
  1381. for _, hostIP := range hostIPs {
  1382. if _, err := portallocator.RequestPort(hostIP, "tcp", intPort); err != nil {
  1383. return fmt.Errorf("failed to allocate daemon listening port %d (err: %v)", intPort, err)
  1384. }
  1385. }
  1386. return nil
  1387. }
  1388. func setupTcpHttp(addr string, job *engine.Job) (*HttpServer, error) {
  1389. if !job.GetenvBool("TlsVerify") {
  1390. log.Infof("/!\\ DON'T BIND ON ANY IP ADDRESS WITHOUT setting -tlsverify IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1391. }
  1392. r := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1393. l, err := newListener("tcp", addr, job.GetenvBool("BufferRequests"))
  1394. if err != nil {
  1395. return nil, err
  1396. }
  1397. if err := allocateDaemonPort(addr); err != nil {
  1398. return nil, err
  1399. }
  1400. if job.GetenvBool("Tls") || job.GetenvBool("TlsVerify") {
  1401. var tlsCa string
  1402. if job.GetenvBool("TlsVerify") {
  1403. tlsCa = job.Getenv("TlsCa")
  1404. }
  1405. l, err = setupTls(job.Getenv("TlsCert"), job.Getenv("TlsKey"), tlsCa, l)
  1406. if err != nil {
  1407. return nil, err
  1408. }
  1409. }
  1410. return &HttpServer{&http.Server{Addr: addr, Handler: r}, l}, nil
  1411. }
  1412. // NewServer sets up the required Server and does protocol specific checking.
  1413. func NewServer(proto, addr string, job *engine.Job) (Server, error) {
  1414. // Basic error and sanity checking
  1415. switch proto {
  1416. case "fd":
  1417. return nil, serveFd(addr, job)
  1418. case "tcp":
  1419. return setupTcpHttp(addr, job)
  1420. case "unix":
  1421. return setupUnixHttp(addr, job)
  1422. default:
  1423. return nil, fmt.Errorf("Invalid protocol format.")
  1424. }
  1425. }
  1426. type Server interface {
  1427. Serve() error
  1428. Close() error
  1429. }
  1430. // ServeApi loops through all of the protocols sent in to docker and spawns
  1431. // off a go routine to setup a serving http.Server for each.
  1432. func ServeApi(job *engine.Job) engine.Status {
  1433. if len(job.Args) == 0 {
  1434. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1435. }
  1436. var (
  1437. protoAddrs = job.Args
  1438. chErrors = make(chan error, len(protoAddrs))
  1439. )
  1440. activationLock = make(chan struct{})
  1441. for _, protoAddr := range protoAddrs {
  1442. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1443. if len(protoAddrParts) != 2 {
  1444. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1445. }
  1446. go func() {
  1447. log.Infof("Listening for HTTP on %s (%s)", protoAddrParts[0], protoAddrParts[1])
  1448. srv, err := NewServer(protoAddrParts[0], protoAddrParts[1], job)
  1449. if err != nil {
  1450. chErrors <- err
  1451. return
  1452. }
  1453. chErrors <- srv.Serve()
  1454. }()
  1455. }
  1456. for i := 0; i < len(protoAddrs); i++ {
  1457. err := <-chErrors
  1458. if err != nil {
  1459. return job.Error(err)
  1460. }
  1461. }
  1462. return engine.StatusOK
  1463. }
  1464. func AcceptConnections(job *engine.Job) engine.Status {
  1465. // Tell the init daemon we are accepting requests
  1466. go systemd.SdNotify("READY=1")
  1467. // close the lock so the listeners start accepting connections
  1468. if activationLock != nil {
  1469. close(activationLock)
  1470. }
  1471. return engine.StatusOK
  1472. }