server.go 44 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "crypto/tls"
  6. "crypto/x509"
  7. "encoding/base64"
  8. "encoding/json"
  9. "expvar"
  10. "fmt"
  11. "io"
  12. "io/ioutil"
  13. "net"
  14. "net/http"
  15. "net/http/pprof"
  16. "os"
  17. "strconv"
  18. "strings"
  19. "syscall"
  20. "code.google.com/p/go.net/websocket"
  21. "github.com/docker/libcontainer/user"
  22. "github.com/gorilla/mux"
  23. "github.com/docker/docker/api"
  24. "github.com/docker/docker/engine"
  25. "github.com/docker/docker/pkg/listenbuffer"
  26. "github.com/docker/docker/pkg/log"
  27. "github.com/docker/docker/pkg/parsers"
  28. "github.com/docker/docker/pkg/stdcopy"
  29. "github.com/docker/docker/pkg/systemd"
  30. "github.com/docker/docker/pkg/version"
  31. "github.com/docker/docker/registry"
  32. "github.com/docker/docker/utils"
  33. )
  34. var (
  35. activationLock chan struct{}
  36. )
  37. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  38. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  39. conn, _, err := w.(http.Hijacker).Hijack()
  40. if err != nil {
  41. return nil, nil, err
  42. }
  43. // Flush the options to make sure the client sets the raw mode
  44. conn.Write([]byte{})
  45. return conn, conn, nil
  46. }
  47. // Check to make sure request's Content-Type is application/json
  48. func checkForJson(r *http.Request) error {
  49. ct := r.Header.Get("Content-Type")
  50. // No Content-Type header is ok as long as there's no Body
  51. if ct == "" {
  52. if r.Body == nil || r.ContentLength == 0 {
  53. return nil
  54. }
  55. }
  56. // Otherwise it better be json
  57. if api.MatchesContentType(ct, "application/json") {
  58. return nil
  59. }
  60. return fmt.Errorf("Content-Type specified (%s) must be 'application/json'", ct)
  61. }
  62. //If we don't do this, POST method without Content-type (even with empty body) will fail
  63. func parseForm(r *http.Request) error {
  64. if r == nil {
  65. return nil
  66. }
  67. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  68. return err
  69. }
  70. return nil
  71. }
  72. func parseMultipartForm(r *http.Request) error {
  73. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  74. return err
  75. }
  76. return nil
  77. }
  78. func httpError(w http.ResponseWriter, err error) {
  79. statusCode := http.StatusInternalServerError
  80. // FIXME: this is brittle and should not be necessary.
  81. // If we need to differentiate between different possible error types, we should
  82. // create appropriate error types with clearly defined meaning.
  83. if strings.Contains(err.Error(), "No such") {
  84. statusCode = http.StatusNotFound
  85. } else if strings.Contains(err.Error(), "Bad parameter") {
  86. statusCode = http.StatusBadRequest
  87. } else if strings.Contains(err.Error(), "Conflict") {
  88. statusCode = http.StatusConflict
  89. } else if strings.Contains(err.Error(), "Impossible") {
  90. statusCode = http.StatusNotAcceptable
  91. } else if strings.Contains(err.Error(), "Wrong login/password") {
  92. statusCode = http.StatusUnauthorized
  93. } else if strings.Contains(err.Error(), "hasn't been activated") {
  94. statusCode = http.StatusForbidden
  95. }
  96. if err != nil {
  97. log.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  98. http.Error(w, err.Error(), statusCode)
  99. }
  100. }
  101. func writeJSON(w http.ResponseWriter, code int, v engine.Env) error {
  102. w.Header().Set("Content-Type", "application/json")
  103. w.WriteHeader(code)
  104. return v.Encode(w)
  105. }
  106. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  107. w.Header().Set("Content-Type", "application/json")
  108. if job.GetenvBool("lineDelim") {
  109. w.Header().Set("Content-Type", "application/x-json-stream")
  110. }
  111. if flush {
  112. job.Stdout.Add(utils.NewWriteFlusher(w))
  113. } else {
  114. job.Stdout.Add(w)
  115. }
  116. }
  117. func getBoolParam(value string) (bool, error) {
  118. if value == "" {
  119. return false, nil
  120. }
  121. ret, err := strconv.ParseBool(value)
  122. if err != nil {
  123. return false, fmt.Errorf("Bad parameter")
  124. }
  125. return ret, nil
  126. }
  127. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  128. var (
  129. authConfig, err = ioutil.ReadAll(r.Body)
  130. job = eng.Job("auth")
  131. stdoutBuffer = bytes.NewBuffer(nil)
  132. )
  133. if err != nil {
  134. return err
  135. }
  136. job.Setenv("authConfig", string(authConfig))
  137. job.Stdout.Add(stdoutBuffer)
  138. if err = job.Run(); err != nil {
  139. return err
  140. }
  141. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  142. var env engine.Env
  143. env.Set("Status", status)
  144. return writeJSON(w, http.StatusOK, env)
  145. }
  146. w.WriteHeader(http.StatusNoContent)
  147. return nil
  148. }
  149. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  150. w.Header().Set("Content-Type", "application/json")
  151. eng.ServeHTTP(w, r)
  152. return nil
  153. }
  154. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  155. if vars == nil {
  156. return fmt.Errorf("Missing parameter")
  157. }
  158. if err := parseForm(r); err != nil {
  159. return err
  160. }
  161. job := eng.Job("kill", vars["name"])
  162. if sig := r.Form.Get("signal"); sig != "" {
  163. job.Args = append(job.Args, sig)
  164. }
  165. if err := job.Run(); err != nil {
  166. return err
  167. }
  168. w.WriteHeader(http.StatusNoContent)
  169. return nil
  170. }
  171. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  172. if vars == nil {
  173. return fmt.Errorf("Missing parameter")
  174. }
  175. if err := parseForm(r); err != nil {
  176. return err
  177. }
  178. job := eng.Job("pause", vars["name"])
  179. if err := job.Run(); err != nil {
  180. return err
  181. }
  182. w.WriteHeader(http.StatusNoContent)
  183. return nil
  184. }
  185. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  186. if vars == nil {
  187. return fmt.Errorf("Missing parameter")
  188. }
  189. if err := parseForm(r); err != nil {
  190. return err
  191. }
  192. job := eng.Job("unpause", vars["name"])
  193. if err := job.Run(); err != nil {
  194. return err
  195. }
  196. w.WriteHeader(http.StatusNoContent)
  197. return nil
  198. }
  199. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  200. if vars == nil {
  201. return fmt.Errorf("Missing parameter")
  202. }
  203. job := eng.Job("export", vars["name"])
  204. job.Stdout.Add(w)
  205. if err := job.Run(); err != nil {
  206. return err
  207. }
  208. return nil
  209. }
  210. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  211. if err := parseForm(r); err != nil {
  212. return err
  213. }
  214. var (
  215. err error
  216. outs *engine.Table
  217. job = eng.Job("images")
  218. )
  219. job.Setenv("filters", r.Form.Get("filters"))
  220. // FIXME this parameter could just be a match filter
  221. job.Setenv("filter", r.Form.Get("filter"))
  222. job.Setenv("all", r.Form.Get("all"))
  223. if version.GreaterThanOrEqualTo("1.7") {
  224. streamJSON(job, w, false)
  225. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  226. return err
  227. }
  228. if err := job.Run(); err != nil {
  229. return err
  230. }
  231. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  232. outsLegacy := engine.NewTable("Created", 0)
  233. for _, out := range outs.Data {
  234. for _, repoTag := range out.GetList("RepoTags") {
  235. repo, tag := parsers.ParseRepositoryTag(repoTag)
  236. outLegacy := &engine.Env{}
  237. outLegacy.Set("Repository", repo)
  238. outLegacy.SetJson("Tag", tag)
  239. outLegacy.Set("Id", out.Get("Id"))
  240. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  241. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  242. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  243. outsLegacy.Add(outLegacy)
  244. }
  245. }
  246. w.Header().Set("Content-Type", "application/json")
  247. if _, err := outsLegacy.WriteListTo(w); err != nil {
  248. return err
  249. }
  250. }
  251. return nil
  252. }
  253. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  254. if version.GreaterThan("1.6") {
  255. w.WriteHeader(http.StatusNotFound)
  256. return fmt.Errorf("This is now implemented in the client.")
  257. }
  258. eng.ServeHTTP(w, r)
  259. return nil
  260. }
  261. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  262. w.Header().Set("Content-Type", "application/json")
  263. eng.ServeHTTP(w, r)
  264. return nil
  265. }
  266. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  267. if err := parseForm(r); err != nil {
  268. return err
  269. }
  270. var job = eng.Job("events")
  271. // lineDelimited JSON events was added #7047
  272. job.SetenvBool("lineDelim", version.GreaterThanOrEqualTo("1.15"))
  273. streamJSON(job, w, true)
  274. job.Setenv("since", r.Form.Get("since"))
  275. job.Setenv("until", r.Form.Get("until"))
  276. return job.Run()
  277. }
  278. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  279. if vars == nil {
  280. return fmt.Errorf("Missing parameter")
  281. }
  282. var job = eng.Job("history", vars["name"])
  283. streamJSON(job, w, false)
  284. if err := job.Run(); err != nil {
  285. return err
  286. }
  287. return nil
  288. }
  289. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  290. if vars == nil {
  291. return fmt.Errorf("Missing parameter")
  292. }
  293. var job = eng.Job("container_changes", vars["name"])
  294. streamJSON(job, w, false)
  295. return job.Run()
  296. }
  297. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  298. if version.LessThan("1.4") {
  299. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  300. }
  301. if vars == nil {
  302. return fmt.Errorf("Missing parameter")
  303. }
  304. if err := parseForm(r); err != nil {
  305. return err
  306. }
  307. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  308. streamJSON(job, w, false)
  309. return job.Run()
  310. }
  311. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  312. if err := parseForm(r); err != nil {
  313. return err
  314. }
  315. var (
  316. err error
  317. outs *engine.Table
  318. job = eng.Job("containers")
  319. )
  320. job.Setenv("all", r.Form.Get("all"))
  321. job.Setenv("size", r.Form.Get("size"))
  322. job.Setenv("since", r.Form.Get("since"))
  323. job.Setenv("before", r.Form.Get("before"))
  324. job.Setenv("limit", r.Form.Get("limit"))
  325. job.Setenv("filters", r.Form.Get("filters"))
  326. if version.GreaterThanOrEqualTo("1.5") {
  327. streamJSON(job, w, false)
  328. } else if outs, err = job.Stdout.AddTable(); err != nil {
  329. return err
  330. }
  331. if err = job.Run(); err != nil {
  332. return err
  333. }
  334. if version.LessThan("1.5") { // Convert to legacy format
  335. for _, out := range outs.Data {
  336. ports := engine.NewTable("", 0)
  337. ports.ReadListFrom([]byte(out.Get("Ports")))
  338. out.Set("Ports", api.DisplayablePorts(ports))
  339. }
  340. w.Header().Set("Content-Type", "application/json")
  341. if _, err = outs.WriteListTo(w); err != nil {
  342. return err
  343. }
  344. }
  345. return nil
  346. }
  347. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  348. if err := parseForm(r); err != nil {
  349. return err
  350. }
  351. if vars == nil {
  352. return fmt.Errorf("Missing parameter")
  353. }
  354. var (
  355. inspectJob = eng.Job("container_inspect", vars["name"])
  356. logsJob = eng.Job("logs", vars["name"])
  357. c, err = inspectJob.Stdout.AddEnv()
  358. )
  359. if err != nil {
  360. return err
  361. }
  362. logsJob.Setenv("follow", r.Form.Get("follow"))
  363. logsJob.Setenv("tail", r.Form.Get("tail"))
  364. logsJob.Setenv("stdout", r.Form.Get("stdout"))
  365. logsJob.Setenv("stderr", r.Form.Get("stderr"))
  366. logsJob.Setenv("timestamps", r.Form.Get("timestamps"))
  367. // Validate args here, because we can't return not StatusOK after job.Run() call
  368. stdout, stderr := logsJob.GetenvBool("stdout"), logsJob.GetenvBool("stderr")
  369. if !(stdout || stderr) {
  370. return fmt.Errorf("Bad parameters: you must choose at least one stream")
  371. }
  372. if err = inspectJob.Run(); err != nil {
  373. return err
  374. }
  375. var outStream, errStream io.Writer
  376. outStream = utils.NewWriteFlusher(w)
  377. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  378. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  379. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  380. } else {
  381. errStream = outStream
  382. }
  383. logsJob.Stdout.Add(outStream)
  384. logsJob.Stderr.Set(errStream)
  385. if err := logsJob.Run(); err != nil {
  386. fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
  387. }
  388. return nil
  389. }
  390. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  391. if err := parseForm(r); err != nil {
  392. return err
  393. }
  394. if vars == nil {
  395. return fmt.Errorf("Missing parameter")
  396. }
  397. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  398. job.Setenv("force", r.Form.Get("force"))
  399. if err := job.Run(); err != nil {
  400. return err
  401. }
  402. w.WriteHeader(http.StatusCreated)
  403. return nil
  404. }
  405. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  406. if err := parseForm(r); err != nil {
  407. return err
  408. }
  409. var (
  410. config engine.Env
  411. env engine.Env
  412. job = eng.Job("commit", r.Form.Get("container"))
  413. stdoutBuffer = bytes.NewBuffer(nil)
  414. )
  415. if err := checkForJson(r); err != nil {
  416. return err
  417. }
  418. if err := config.Decode(r.Body); err != nil {
  419. log.Errorf("%s", err)
  420. }
  421. if r.FormValue("pause") == "" && version.GreaterThanOrEqualTo("1.13") {
  422. job.Setenv("pause", "1")
  423. } else {
  424. job.Setenv("pause", r.FormValue("pause"))
  425. }
  426. job.Setenv("repo", r.Form.Get("repo"))
  427. job.Setenv("tag", r.Form.Get("tag"))
  428. job.Setenv("author", r.Form.Get("author"))
  429. job.Setenv("comment", r.Form.Get("comment"))
  430. job.SetenvSubEnv("config", &config)
  431. job.Stdout.Add(stdoutBuffer)
  432. if err := job.Run(); err != nil {
  433. return err
  434. }
  435. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  436. return writeJSON(w, http.StatusCreated, env)
  437. }
  438. // Creates an image from Pull or from Import
  439. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  440. if err := parseForm(r); err != nil {
  441. return err
  442. }
  443. var (
  444. image = r.Form.Get("fromImage")
  445. repo = r.Form.Get("repo")
  446. tag = r.Form.Get("tag")
  447. job *engine.Job
  448. )
  449. authEncoded := r.Header.Get("X-Registry-Auth")
  450. authConfig := &registry.AuthConfig{}
  451. if authEncoded != "" {
  452. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  453. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  454. // for a pull it is not an error if no auth was given
  455. // to increase compatibility with the existing api it is defaulting to be empty
  456. authConfig = &registry.AuthConfig{}
  457. }
  458. }
  459. if image != "" { //pull
  460. if tag == "" {
  461. image, tag = parsers.ParseRepositoryTag(image)
  462. }
  463. metaHeaders := map[string][]string{}
  464. for k, v := range r.Header {
  465. if strings.HasPrefix(k, "X-Meta-") {
  466. metaHeaders[k] = v
  467. }
  468. }
  469. job = eng.Job("pull", image, tag)
  470. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  471. job.SetenvJson("metaHeaders", metaHeaders)
  472. job.SetenvJson("authConfig", authConfig)
  473. } else { //import
  474. if tag == "" {
  475. repo, tag = parsers.ParseRepositoryTag(repo)
  476. }
  477. job = eng.Job("import", r.Form.Get("fromSrc"), repo, tag)
  478. job.Stdin.Add(r.Body)
  479. }
  480. if version.GreaterThan("1.0") {
  481. job.SetenvBool("json", true)
  482. streamJSON(job, w, true)
  483. } else {
  484. job.Stdout.Add(utils.NewWriteFlusher(w))
  485. }
  486. if err := job.Run(); err != nil {
  487. if !job.Stdout.Used() {
  488. return err
  489. }
  490. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  491. w.Write(sf.FormatError(err))
  492. }
  493. return nil
  494. }
  495. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  496. if err := parseForm(r); err != nil {
  497. return err
  498. }
  499. var (
  500. authEncoded = r.Header.Get("X-Registry-Auth")
  501. authConfig = &registry.AuthConfig{}
  502. metaHeaders = map[string][]string{}
  503. )
  504. if authEncoded != "" {
  505. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  506. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  507. // for a search it is not an error if no auth was given
  508. // to increase compatibility with the existing api it is defaulting to be empty
  509. authConfig = &registry.AuthConfig{}
  510. }
  511. }
  512. for k, v := range r.Header {
  513. if strings.HasPrefix(k, "X-Meta-") {
  514. metaHeaders[k] = v
  515. }
  516. }
  517. var job = eng.Job("search", r.Form.Get("term"))
  518. job.SetenvJson("metaHeaders", metaHeaders)
  519. job.SetenvJson("authConfig", authConfig)
  520. streamJSON(job, w, false)
  521. return job.Run()
  522. }
  523. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  524. if vars == nil {
  525. return fmt.Errorf("Missing parameter")
  526. }
  527. metaHeaders := map[string][]string{}
  528. for k, v := range r.Header {
  529. if strings.HasPrefix(k, "X-Meta-") {
  530. metaHeaders[k] = v
  531. }
  532. }
  533. if err := parseForm(r); err != nil {
  534. return err
  535. }
  536. authConfig := &registry.AuthConfig{}
  537. authEncoded := r.Header.Get("X-Registry-Auth")
  538. if authEncoded != "" {
  539. // the new format is to handle the authConfig as a header
  540. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  541. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  542. // to increase compatibility to existing api it is defaulting to be empty
  543. authConfig = &registry.AuthConfig{}
  544. }
  545. } else {
  546. // the old format is supported for compatibility if there was no authConfig header
  547. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  548. return err
  549. }
  550. }
  551. job := eng.Job("push", vars["name"])
  552. job.SetenvJson("metaHeaders", metaHeaders)
  553. job.SetenvJson("authConfig", authConfig)
  554. job.Setenv("tag", r.Form.Get("tag"))
  555. if version.GreaterThan("1.0") {
  556. job.SetenvBool("json", true)
  557. streamJSON(job, w, true)
  558. } else {
  559. job.Stdout.Add(utils.NewWriteFlusher(w))
  560. }
  561. if err := job.Run(); err != nil {
  562. if !job.Stdout.Used() {
  563. return err
  564. }
  565. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  566. w.Write(sf.FormatError(err))
  567. }
  568. return nil
  569. }
  570. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  571. if vars == nil {
  572. return fmt.Errorf("Missing parameter")
  573. }
  574. if err := parseForm(r); err != nil {
  575. return err
  576. }
  577. if version.GreaterThan("1.0") {
  578. w.Header().Set("Content-Type", "application/x-tar")
  579. }
  580. var job *engine.Job
  581. if name, ok := vars["name"]; ok {
  582. job = eng.Job("image_export", name)
  583. } else {
  584. job = eng.Job("image_export", r.Form["names"]...)
  585. }
  586. job.Stdout.Add(w)
  587. return job.Run()
  588. }
  589. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  590. job := eng.Job("load")
  591. job.Stdin.Add(r.Body)
  592. return job.Run()
  593. }
  594. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  595. if err := parseForm(r); err != nil {
  596. return nil
  597. }
  598. var (
  599. out engine.Env
  600. job = eng.Job("create", r.Form.Get("name"))
  601. outWarnings []string
  602. stdoutBuffer = bytes.NewBuffer(nil)
  603. warnings = bytes.NewBuffer(nil)
  604. )
  605. if err := checkForJson(r); err != nil {
  606. return err
  607. }
  608. if err := job.DecodeEnv(r.Body); err != nil {
  609. return err
  610. }
  611. // Read container ID from the first line of stdout
  612. job.Stdout.Add(stdoutBuffer)
  613. // Read warnings from stderr
  614. job.Stderr.Add(warnings)
  615. if err := job.Run(); err != nil {
  616. return err
  617. }
  618. // Parse warnings from stderr
  619. scanner := bufio.NewScanner(warnings)
  620. for scanner.Scan() {
  621. outWarnings = append(outWarnings, scanner.Text())
  622. }
  623. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  624. out.SetList("Warnings", outWarnings)
  625. return writeJSON(w, http.StatusCreated, out)
  626. }
  627. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  628. if err := parseForm(r); err != nil {
  629. return err
  630. }
  631. if vars == nil {
  632. return fmt.Errorf("Missing parameter")
  633. }
  634. job := eng.Job("restart", vars["name"])
  635. job.Setenv("t", r.Form.Get("t"))
  636. if err := job.Run(); err != nil {
  637. return err
  638. }
  639. w.WriteHeader(http.StatusNoContent)
  640. return nil
  641. }
  642. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  643. if err := parseForm(r); err != nil {
  644. return err
  645. }
  646. if vars == nil {
  647. return fmt.Errorf("Missing parameter")
  648. }
  649. job := eng.Job("rm", vars["name"])
  650. job.Setenv("forceRemove", r.Form.Get("force"))
  651. job.Setenv("removeVolume", r.Form.Get("v"))
  652. job.Setenv("removeLink", r.Form.Get("link"))
  653. if err := job.Run(); err != nil {
  654. return err
  655. }
  656. w.WriteHeader(http.StatusNoContent)
  657. return nil
  658. }
  659. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  660. if err := parseForm(r); err != nil {
  661. return err
  662. }
  663. if vars == nil {
  664. return fmt.Errorf("Missing parameter")
  665. }
  666. var job = eng.Job("image_delete", vars["name"])
  667. streamJSON(job, w, false)
  668. job.Setenv("force", r.Form.Get("force"))
  669. job.Setenv("noprune", r.Form.Get("noprune"))
  670. return job.Run()
  671. }
  672. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  673. if vars == nil {
  674. return fmt.Errorf("Missing parameter")
  675. }
  676. var (
  677. name = vars["name"]
  678. job = eng.Job("start", name)
  679. )
  680. // If contentLength is -1, we can assumed chunked encoding
  681. // or more technically that the length is unknown
  682. // http://golang.org/src/pkg/net/http/request.go#L139
  683. // net/http otherwise seems to swallow any headers related to chunked encoding
  684. // including r.TransferEncoding
  685. // allow a nil body for backwards compatibility
  686. if r.Body != nil && (r.ContentLength > 0 || r.ContentLength == -1) {
  687. if err := checkForJson(r); err != nil {
  688. return err
  689. }
  690. if err := job.DecodeEnv(r.Body); err != nil {
  691. return err
  692. }
  693. }
  694. if err := job.Run(); err != nil {
  695. if err.Error() == "Container already started" {
  696. w.WriteHeader(http.StatusNotModified)
  697. return nil
  698. }
  699. return err
  700. }
  701. w.WriteHeader(http.StatusNoContent)
  702. return nil
  703. }
  704. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  705. if err := parseForm(r); err != nil {
  706. return err
  707. }
  708. if vars == nil {
  709. return fmt.Errorf("Missing parameter")
  710. }
  711. job := eng.Job("stop", vars["name"])
  712. job.Setenv("t", r.Form.Get("t"))
  713. if err := job.Run(); err != nil {
  714. if err.Error() == "Container already stopped" {
  715. w.WriteHeader(http.StatusNotModified)
  716. return nil
  717. }
  718. return err
  719. }
  720. w.WriteHeader(http.StatusNoContent)
  721. return nil
  722. }
  723. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  724. if vars == nil {
  725. return fmt.Errorf("Missing parameter")
  726. }
  727. var (
  728. env engine.Env
  729. stdoutBuffer = bytes.NewBuffer(nil)
  730. job = eng.Job("wait", vars["name"])
  731. )
  732. job.Stdout.Add(stdoutBuffer)
  733. if err := job.Run(); err != nil {
  734. return err
  735. }
  736. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  737. return writeJSON(w, http.StatusOK, env)
  738. }
  739. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  740. if err := parseForm(r); err != nil {
  741. return err
  742. }
  743. if vars == nil {
  744. return fmt.Errorf("Missing parameter")
  745. }
  746. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  747. return err
  748. }
  749. return nil
  750. }
  751. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  752. if err := parseForm(r); err != nil {
  753. return err
  754. }
  755. if vars == nil {
  756. return fmt.Errorf("Missing parameter")
  757. }
  758. var (
  759. job = eng.Job("container_inspect", vars["name"])
  760. c, err = job.Stdout.AddEnv()
  761. )
  762. if err != nil {
  763. return err
  764. }
  765. if err = job.Run(); err != nil {
  766. return err
  767. }
  768. inStream, outStream, err := hijackServer(w)
  769. if err != nil {
  770. return err
  771. }
  772. defer func() {
  773. if tcpc, ok := inStream.(*net.TCPConn); ok {
  774. tcpc.CloseWrite()
  775. } else {
  776. inStream.Close()
  777. }
  778. }()
  779. defer func() {
  780. if tcpc, ok := outStream.(*net.TCPConn); ok {
  781. tcpc.CloseWrite()
  782. } else if closer, ok := outStream.(io.Closer); ok {
  783. closer.Close()
  784. }
  785. }()
  786. var errStream io.Writer
  787. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  788. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  789. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  790. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  791. } else {
  792. errStream = outStream
  793. }
  794. job = eng.Job("attach", vars["name"])
  795. job.Setenv("logs", r.Form.Get("logs"))
  796. job.Setenv("stream", r.Form.Get("stream"))
  797. job.Setenv("stdin", r.Form.Get("stdin"))
  798. job.Setenv("stdout", r.Form.Get("stdout"))
  799. job.Setenv("stderr", r.Form.Get("stderr"))
  800. job.Stdin.Add(inStream)
  801. job.Stdout.Add(outStream)
  802. job.Stderr.Set(errStream)
  803. if err := job.Run(); err != nil {
  804. fmt.Fprintf(outStream, "Error attaching: %s\n", err)
  805. }
  806. return nil
  807. }
  808. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  809. if err := parseForm(r); err != nil {
  810. return err
  811. }
  812. if vars == nil {
  813. return fmt.Errorf("Missing parameter")
  814. }
  815. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  816. return err
  817. }
  818. h := websocket.Handler(func(ws *websocket.Conn) {
  819. defer ws.Close()
  820. job := eng.Job("attach", vars["name"])
  821. job.Setenv("logs", r.Form.Get("logs"))
  822. job.Setenv("stream", r.Form.Get("stream"))
  823. job.Setenv("stdin", r.Form.Get("stdin"))
  824. job.Setenv("stdout", r.Form.Get("stdout"))
  825. job.Setenv("stderr", r.Form.Get("stderr"))
  826. job.Stdin.Add(ws)
  827. job.Stdout.Add(ws)
  828. job.Stderr.Set(ws)
  829. if err := job.Run(); err != nil {
  830. log.Errorf("Error attaching websocket: %s", err)
  831. }
  832. })
  833. h.ServeHTTP(w, r)
  834. return nil
  835. }
  836. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  837. if vars == nil {
  838. return fmt.Errorf("Missing parameter")
  839. }
  840. var job = eng.Job("container_inspect", vars["name"])
  841. if version.LessThan("1.12") {
  842. job.SetenvBool("raw", true)
  843. }
  844. streamJSON(job, w, false)
  845. return job.Run()
  846. }
  847. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  848. if vars == nil {
  849. return fmt.Errorf("Missing parameter")
  850. }
  851. var job = eng.Job("image_inspect", vars["name"])
  852. if version.LessThan("1.12") {
  853. job.SetenvBool("raw", true)
  854. }
  855. streamJSON(job, w, false)
  856. return job.Run()
  857. }
  858. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  859. if version.LessThan("1.3") {
  860. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  861. }
  862. var (
  863. authEncoded = r.Header.Get("X-Registry-Auth")
  864. authConfig = &registry.AuthConfig{}
  865. configFileEncoded = r.Header.Get("X-Registry-Config")
  866. configFile = &registry.ConfigFile{}
  867. job = eng.Job("build")
  868. )
  869. // This block can be removed when API versions prior to 1.9 are deprecated.
  870. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  871. // ConfigFile is present, any value provided as an AuthConfig directly will
  872. // be overridden. See BuildFile::CmdFrom for details.
  873. if version.LessThan("1.9") && authEncoded != "" {
  874. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  875. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  876. // for a pull it is not an error if no auth was given
  877. // to increase compatibility with the existing api it is defaulting to be empty
  878. authConfig = &registry.AuthConfig{}
  879. }
  880. }
  881. if configFileEncoded != "" {
  882. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  883. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  884. // for a pull it is not an error if no auth was given
  885. // to increase compatibility with the existing api it is defaulting to be empty
  886. configFile = &registry.ConfigFile{}
  887. }
  888. }
  889. // This needs to be set before calls to streamJSON
  890. job.SetenvBool("lineDelim", version.GreaterThanOrEqualTo("1.15"))
  891. if version.GreaterThanOrEqualTo("1.8") {
  892. job.SetenvBool("json", true)
  893. streamJSON(job, w, true)
  894. } else {
  895. job.Stdout.Add(utils.NewWriteFlusher(w))
  896. }
  897. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  898. job.Setenv("rm", "1")
  899. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  900. job.Setenv("rm", "1")
  901. } else {
  902. job.Setenv("rm", r.FormValue("rm"))
  903. }
  904. job.Stdin.Add(r.Body)
  905. job.Setenv("remote", r.FormValue("remote"))
  906. job.Setenv("t", r.FormValue("t"))
  907. job.Setenv("q", r.FormValue("q"))
  908. job.Setenv("nocache", r.FormValue("nocache"))
  909. job.Setenv("forcerm", r.FormValue("forcerm"))
  910. job.SetenvJson("authConfig", authConfig)
  911. job.SetenvJson("configFile", configFile)
  912. if err := job.Run(); err != nil {
  913. if !job.Stdout.Used() {
  914. return err
  915. }
  916. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  917. w.Write(sf.FormatError(err))
  918. }
  919. return nil
  920. }
  921. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  922. if vars == nil {
  923. return fmt.Errorf("Missing parameter")
  924. }
  925. var copyData engine.Env
  926. if err := checkForJson(r); err != nil {
  927. return err
  928. }
  929. if err := copyData.Decode(r.Body); err != nil {
  930. return err
  931. }
  932. if copyData.Get("Resource") == "" {
  933. return fmt.Errorf("Path cannot be empty")
  934. }
  935. origResource := copyData.Get("Resource")
  936. if copyData.Get("Resource")[0] == '/' {
  937. copyData.Set("Resource", copyData.Get("Resource")[1:])
  938. }
  939. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  940. job.Stdout.Add(w)
  941. w.Header().Set("Content-Type", "application/x-tar")
  942. if err := job.Run(); err != nil {
  943. log.Errorf("%s", err.Error())
  944. if strings.Contains(err.Error(), "No such container") {
  945. w.WriteHeader(http.StatusNotFound)
  946. } else if strings.Contains(err.Error(), "no such file or directory") {
  947. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  948. }
  949. }
  950. return nil
  951. }
  952. func postContainerExecCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  953. if err := parseForm(r); err != nil {
  954. return nil
  955. }
  956. var (
  957. out engine.Env
  958. name = vars["name"]
  959. job = eng.Job("execCreate", name)
  960. stdoutBuffer = bytes.NewBuffer(nil)
  961. )
  962. if err := job.DecodeEnv(r.Body); err != nil {
  963. return err
  964. }
  965. job.Stdout.Add(stdoutBuffer)
  966. // Register an instance of Exec in container.
  967. if err := job.Run(); err != nil {
  968. fmt.Fprintf(os.Stderr, "Error setting up exec command in container %s: %s\n", name, err)
  969. return err
  970. }
  971. // Return the ID
  972. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  973. return writeJSON(w, http.StatusCreated, out)
  974. }
  975. // TODO(vishh): Refactor the code to avoid having to specify stream config as part of both create and start.
  976. func postContainerExecStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  977. if err := parseForm(r); err != nil {
  978. return nil
  979. }
  980. var (
  981. name = vars["name"]
  982. job = eng.Job("execStart", name)
  983. errOut io.Writer = os.Stderr
  984. )
  985. if err := job.DecodeEnv(r.Body); err != nil {
  986. return err
  987. }
  988. if !job.GetenvBool("Detach") {
  989. // Setting up the streaming http interface.
  990. inStream, outStream, err := hijackServer(w)
  991. if err != nil {
  992. return err
  993. }
  994. defer func() {
  995. if tcpc, ok := inStream.(*net.TCPConn); ok {
  996. tcpc.CloseWrite()
  997. } else {
  998. inStream.Close()
  999. }
  1000. }()
  1001. defer func() {
  1002. if tcpc, ok := outStream.(*net.TCPConn); ok {
  1003. tcpc.CloseWrite()
  1004. } else if closer, ok := outStream.(io.Closer); ok {
  1005. closer.Close()
  1006. }
  1007. }()
  1008. var errStream io.Writer
  1009. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  1010. if !job.GetenvBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  1011. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  1012. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  1013. } else {
  1014. errStream = outStream
  1015. }
  1016. job.Stdin.Add(inStream)
  1017. job.Stdout.Add(outStream)
  1018. job.Stderr.Set(errStream)
  1019. errOut = outStream
  1020. }
  1021. // Now run the user process in container.
  1022. job.SetCloseIO(false)
  1023. if err := job.Run(); err != nil {
  1024. fmt.Fprintf(errOut, "Error starting exec command in container %s: %s\n", name, err)
  1025. return err
  1026. }
  1027. w.WriteHeader(http.StatusNoContent)
  1028. return nil
  1029. }
  1030. func postContainerExecResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1031. if err := parseForm(r); err != nil {
  1032. return err
  1033. }
  1034. if vars == nil {
  1035. return fmt.Errorf("Missing parameter")
  1036. }
  1037. if err := eng.Job("execResize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  1038. return err
  1039. }
  1040. return nil
  1041. }
  1042. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1043. w.WriteHeader(http.StatusOK)
  1044. return nil
  1045. }
  1046. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  1047. w.Header().Add("Access-Control-Allow-Origin", "*")
  1048. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept")
  1049. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  1050. }
  1051. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1052. _, err := w.Write([]byte{'O', 'K'})
  1053. return err
  1054. }
  1055. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  1056. return func(w http.ResponseWriter, r *http.Request) {
  1057. // log the request
  1058. log.Debugf("Calling %s %s", localMethod, localRoute)
  1059. if logging {
  1060. log.Infof("%s %s", r.Method, r.RequestURI)
  1061. }
  1062. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  1063. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  1064. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  1065. log.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  1066. }
  1067. }
  1068. version := version.Version(mux.Vars(r)["version"])
  1069. if version == "" {
  1070. version = api.APIVERSION
  1071. }
  1072. if enableCors {
  1073. writeCorsHeaders(w, r)
  1074. }
  1075. if version.GreaterThan(api.APIVERSION) {
  1076. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  1077. return
  1078. }
  1079. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  1080. log.Errorf("Handler for %s %s returned error: %s", localMethod, localRoute, err)
  1081. httpError(w, err)
  1082. }
  1083. }
  1084. }
  1085. // Replicated from expvar.go as not public.
  1086. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  1087. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  1088. fmt.Fprintf(w, "{\n")
  1089. first := true
  1090. expvar.Do(func(kv expvar.KeyValue) {
  1091. if !first {
  1092. fmt.Fprintf(w, ",\n")
  1093. }
  1094. first = false
  1095. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  1096. })
  1097. fmt.Fprintf(w, "\n}\n")
  1098. }
  1099. func AttachProfiler(router *mux.Router) {
  1100. router.HandleFunc("/debug/vars", expvarHandler)
  1101. router.HandleFunc("/debug/pprof/", pprof.Index)
  1102. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  1103. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  1104. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  1105. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  1106. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  1107. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  1108. }
  1109. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) (*mux.Router, error) {
  1110. r := mux.NewRouter()
  1111. if os.Getenv("DEBUG") != "" {
  1112. AttachProfiler(r)
  1113. }
  1114. m := map[string]map[string]HttpApiFunc{
  1115. "GET": {
  1116. "/_ping": ping,
  1117. "/events": getEvents,
  1118. "/info": getInfo,
  1119. "/version": getVersion,
  1120. "/images/json": getImagesJSON,
  1121. "/images/viz": getImagesViz,
  1122. "/images/search": getImagesSearch,
  1123. "/images/get": getImagesGet,
  1124. "/images/{name:.*}/get": getImagesGet,
  1125. "/images/{name:.*}/history": getImagesHistory,
  1126. "/images/{name:.*}/json": getImagesByName,
  1127. "/containers/ps": getContainersJSON,
  1128. "/containers/json": getContainersJSON,
  1129. "/containers/{name:.*}/export": getContainersExport,
  1130. "/containers/{name:.*}/changes": getContainersChanges,
  1131. "/containers/{name:.*}/json": getContainersByName,
  1132. "/containers/{name:.*}/top": getContainersTop,
  1133. "/containers/{name:.*}/logs": getContainersLogs,
  1134. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  1135. },
  1136. "POST": {
  1137. "/auth": postAuth,
  1138. "/commit": postCommit,
  1139. "/build": postBuild,
  1140. "/images/create": postImagesCreate,
  1141. "/images/load": postImagesLoad,
  1142. "/images/{name:.*}/push": postImagesPush,
  1143. "/images/{name:.*}/tag": postImagesTag,
  1144. "/containers/create": postContainersCreate,
  1145. "/containers/{name:.*}/kill": postContainersKill,
  1146. "/containers/{name:.*}/pause": postContainersPause,
  1147. "/containers/{name:.*}/unpause": postContainersUnpause,
  1148. "/containers/{name:.*}/restart": postContainersRestart,
  1149. "/containers/{name:.*}/start": postContainersStart,
  1150. "/containers/{name:.*}/stop": postContainersStop,
  1151. "/containers/{name:.*}/wait": postContainersWait,
  1152. "/containers/{name:.*}/resize": postContainersResize,
  1153. "/containers/{name:.*}/attach": postContainersAttach,
  1154. "/containers/{name:.*}/copy": postContainersCopy,
  1155. "/containers/{name:.*}/exec": postContainerExecCreate,
  1156. "/exec/{name:.*}/start": postContainerExecStart,
  1157. "/exec/{name:.*}/resize": postContainerExecResize,
  1158. },
  1159. "DELETE": {
  1160. "/containers/{name:.*}": deleteContainers,
  1161. "/images/{name:.*}": deleteImages,
  1162. },
  1163. "OPTIONS": {
  1164. "": optionsHandler,
  1165. },
  1166. }
  1167. for method, routes := range m {
  1168. for route, fct := range routes {
  1169. log.Debugf("Registering %s, %s", method, route)
  1170. // NOTE: scope issue, make sure the variables are local and won't be changed
  1171. localRoute := route
  1172. localFct := fct
  1173. localMethod := method
  1174. // build the handler function
  1175. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1176. // add the new route
  1177. if localRoute == "" {
  1178. r.Methods(localMethod).HandlerFunc(f)
  1179. } else {
  1180. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1181. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1182. }
  1183. }
  1184. }
  1185. return r, nil
  1186. }
  1187. // ServeRequest processes a single http request to the docker remote api.
  1188. // FIXME: refactor this to be part of Server and not require re-creating a new
  1189. // router each time. This requires first moving ListenAndServe into Server.
  1190. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) error {
  1191. router, err := createRouter(eng, false, true, "")
  1192. if err != nil {
  1193. return err
  1194. }
  1195. // Insert APIVERSION into the request as a convenience
  1196. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1197. router.ServeHTTP(w, req)
  1198. return nil
  1199. }
  1200. // ServeFD creates an http.Server and sets it up to serve given a socket activated
  1201. // argument.
  1202. func ServeFd(addr string, handle http.Handler) error {
  1203. ls, e := systemd.ListenFD(addr)
  1204. if e != nil {
  1205. return e
  1206. }
  1207. chErrors := make(chan error, len(ls))
  1208. // We don't want to start serving on these sockets until the
  1209. // daemon is initialized and installed. Otherwise required handlers
  1210. // won't be ready.
  1211. <-activationLock
  1212. // Since ListenFD will return one or more sockets we have
  1213. // to create a go func to spawn off multiple serves
  1214. for i := range ls {
  1215. listener := ls[i]
  1216. go func() {
  1217. httpSrv := http.Server{Handler: handle}
  1218. chErrors <- httpSrv.Serve(listener)
  1219. }()
  1220. }
  1221. for i := 0; i < len(ls); i++ {
  1222. err := <-chErrors
  1223. if err != nil {
  1224. return err
  1225. }
  1226. }
  1227. return nil
  1228. }
  1229. func lookupGidByName(nameOrGid string) (int, error) {
  1230. groups, err := user.ParseGroupFilter(func(g *user.Group) bool {
  1231. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1232. })
  1233. if err != nil {
  1234. return -1, err
  1235. }
  1236. if groups != nil && len(groups) > 0 {
  1237. return groups[0].Gid, nil
  1238. }
  1239. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1240. }
  1241. func changeGroup(addr string, nameOrGid string) error {
  1242. gid, err := lookupGidByName(nameOrGid)
  1243. if err != nil {
  1244. return err
  1245. }
  1246. log.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1247. return os.Chown(addr, 0, gid)
  1248. }
  1249. // ListenAndServe sets up the required http.Server and gets it listening for
  1250. // each addr passed in and does protocol specific checking.
  1251. func ListenAndServe(proto, addr string, job *engine.Job) error {
  1252. var l net.Listener
  1253. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1254. if err != nil {
  1255. return err
  1256. }
  1257. if proto == "fd" {
  1258. return ServeFd(addr, r)
  1259. }
  1260. if proto == "unix" {
  1261. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1262. return err
  1263. }
  1264. }
  1265. var oldmask int
  1266. if proto == "unix" {
  1267. oldmask = syscall.Umask(0777)
  1268. }
  1269. if job.GetenvBool("BufferRequests") {
  1270. l, err = listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1271. } else {
  1272. l, err = net.Listen(proto, addr)
  1273. }
  1274. if proto == "unix" {
  1275. syscall.Umask(oldmask)
  1276. }
  1277. if err != nil {
  1278. return err
  1279. }
  1280. if proto != "unix" && (job.GetenvBool("Tls") || job.GetenvBool("TlsVerify")) {
  1281. tlsCert := job.Getenv("TlsCert")
  1282. tlsKey := job.Getenv("TlsKey")
  1283. cert, err := tls.LoadX509KeyPair(tlsCert, tlsKey)
  1284. if err != nil {
  1285. return fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1286. tlsCert, tlsKey, err)
  1287. }
  1288. tlsConfig := &tls.Config{
  1289. NextProtos: []string{"http/1.1"},
  1290. Certificates: []tls.Certificate{cert},
  1291. }
  1292. if job.GetenvBool("TlsVerify") {
  1293. certPool := x509.NewCertPool()
  1294. file, err := ioutil.ReadFile(job.Getenv("TlsCa"))
  1295. if err != nil {
  1296. return fmt.Errorf("Couldn't read CA certificate: %s", err)
  1297. }
  1298. certPool.AppendCertsFromPEM(file)
  1299. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1300. tlsConfig.ClientCAs = certPool
  1301. }
  1302. l = tls.NewListener(l, tlsConfig)
  1303. }
  1304. // Basic error and sanity checking
  1305. switch proto {
  1306. case "tcp":
  1307. if !strings.HasPrefix(addr, "127.0.0.1") && !job.GetenvBool("TlsVerify") {
  1308. log.Infof("/!\\ DON'T BIND ON ANOTHER IP ADDRESS THAN 127.0.0.1 IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1309. }
  1310. case "unix":
  1311. socketGroup := job.Getenv("SocketGroup")
  1312. if socketGroup != "" {
  1313. if err := changeGroup(addr, socketGroup); err != nil {
  1314. if socketGroup == "docker" {
  1315. // if the user hasn't explicitly specified the group ownership, don't fail on errors.
  1316. log.Debugf("Warning: could not chgrp %s to docker: %s", addr, err.Error())
  1317. } else {
  1318. return err
  1319. }
  1320. }
  1321. }
  1322. if err := os.Chmod(addr, 0660); err != nil {
  1323. return err
  1324. }
  1325. default:
  1326. return fmt.Errorf("Invalid protocol format.")
  1327. }
  1328. httpSrv := http.Server{Addr: addr, Handler: r}
  1329. return httpSrv.Serve(l)
  1330. }
  1331. // ServeApi loops through all of the protocols sent in to docker and spawns
  1332. // off a go routine to setup a serving http.Server for each.
  1333. func ServeApi(job *engine.Job) engine.Status {
  1334. if len(job.Args) == 0 {
  1335. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1336. }
  1337. var (
  1338. protoAddrs = job.Args
  1339. chErrors = make(chan error, len(protoAddrs))
  1340. )
  1341. activationLock = make(chan struct{})
  1342. for _, protoAddr := range protoAddrs {
  1343. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1344. if len(protoAddrParts) != 2 {
  1345. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1346. }
  1347. go func() {
  1348. log.Infof("Listening for HTTP on %s (%s)", protoAddrParts[0], protoAddrParts[1])
  1349. chErrors <- ListenAndServe(protoAddrParts[0], protoAddrParts[1], job)
  1350. }()
  1351. }
  1352. for i := 0; i < len(protoAddrs); i++ {
  1353. err := <-chErrors
  1354. if err != nil {
  1355. return job.Error(err)
  1356. }
  1357. }
  1358. return engine.StatusOK
  1359. }
  1360. func AcceptConnections(job *engine.Job) engine.Status {
  1361. // Tell the init daemon we are accepting requests
  1362. go systemd.SdNotify("READY=1")
  1363. // close the lock so the listeners start accepting connections
  1364. if activationLock != nil {
  1365. close(activationLock)
  1366. }
  1367. return engine.StatusOK
  1368. }