server.go 44 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "crypto/tls"
  6. "crypto/x509"
  7. "encoding/base64"
  8. "encoding/json"
  9. "expvar"
  10. "fmt"
  11. "io"
  12. "io/ioutil"
  13. "net"
  14. "net/http"
  15. "net/http/pprof"
  16. "os"
  17. "strconv"
  18. "strings"
  19. "syscall"
  20. "code.google.com/p/go.net/websocket"
  21. "github.com/docker/libcontainer/user"
  22. "github.com/gorilla/mux"
  23. log "github.com/Sirupsen/logrus"
  24. "github.com/docker/docker/api"
  25. "github.com/docker/docker/engine"
  26. "github.com/docker/docker/pkg/listenbuffer"
  27. "github.com/docker/docker/pkg/parsers"
  28. "github.com/docker/docker/pkg/stdcopy"
  29. "github.com/docker/docker/pkg/systemd"
  30. "github.com/docker/docker/pkg/version"
  31. "github.com/docker/docker/registry"
  32. "github.com/docker/docker/utils"
  33. )
  34. var (
  35. activationLock chan struct{}
  36. )
  37. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  38. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  39. conn, _, err := w.(http.Hijacker).Hijack()
  40. if err != nil {
  41. return nil, nil, err
  42. }
  43. // Flush the options to make sure the client sets the raw mode
  44. conn.Write([]byte{})
  45. return conn, conn, nil
  46. }
  47. // Check to make sure request's Content-Type is application/json
  48. func checkForJson(r *http.Request) error {
  49. ct := r.Header.Get("Content-Type")
  50. // No Content-Type header is ok as long as there's no Body
  51. if ct == "" {
  52. if r.Body == nil || r.ContentLength == 0 {
  53. return nil
  54. }
  55. }
  56. // Otherwise it better be json
  57. if api.MatchesContentType(ct, "application/json") {
  58. return nil
  59. }
  60. return fmt.Errorf("Content-Type specified (%s) must be 'application/json'", ct)
  61. }
  62. //If we don't do this, POST method without Content-type (even with empty body) will fail
  63. func parseForm(r *http.Request) error {
  64. if r == nil {
  65. return nil
  66. }
  67. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  68. return err
  69. }
  70. return nil
  71. }
  72. func parseMultipartForm(r *http.Request) error {
  73. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  74. return err
  75. }
  76. return nil
  77. }
  78. func httpError(w http.ResponseWriter, err error) {
  79. statusCode := http.StatusInternalServerError
  80. // FIXME: this is brittle and should not be necessary.
  81. // If we need to differentiate between different possible error types, we should
  82. // create appropriate error types with clearly defined meaning.
  83. errStr := strings.ToLower(err.Error())
  84. if strings.Contains(errStr, "no such") {
  85. statusCode = http.StatusNotFound
  86. } else if strings.Contains(errStr, "bad parameter") {
  87. statusCode = http.StatusBadRequest
  88. } else if strings.Contains(errStr, "conflict") {
  89. statusCode = http.StatusConflict
  90. } else if strings.Contains(errStr, "impossible") {
  91. statusCode = http.StatusNotAcceptable
  92. } else if strings.Contains(errStr, "wrong login/password") {
  93. statusCode = http.StatusUnauthorized
  94. } else if strings.Contains(errStr, "hasn't been activated") {
  95. statusCode = http.StatusForbidden
  96. }
  97. if err != nil {
  98. log.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  99. http.Error(w, err.Error(), statusCode)
  100. }
  101. }
  102. func writeJSON(w http.ResponseWriter, code int, v engine.Env) error {
  103. w.Header().Set("Content-Type", "application/json")
  104. w.WriteHeader(code)
  105. return v.Encode(w)
  106. }
  107. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  108. w.Header().Set("Content-Type", "application/json")
  109. if flush {
  110. job.Stdout.Add(utils.NewWriteFlusher(w))
  111. } else {
  112. job.Stdout.Add(w)
  113. }
  114. }
  115. func getBoolParam(value string) (bool, error) {
  116. if value == "" {
  117. return false, nil
  118. }
  119. ret, err := strconv.ParseBool(value)
  120. if err != nil {
  121. return false, fmt.Errorf("Bad parameter")
  122. }
  123. return ret, nil
  124. }
  125. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  126. var (
  127. authConfig, err = ioutil.ReadAll(r.Body)
  128. job = eng.Job("auth")
  129. stdoutBuffer = bytes.NewBuffer(nil)
  130. )
  131. if err != nil {
  132. return err
  133. }
  134. job.Setenv("authConfig", string(authConfig))
  135. job.Stdout.Add(stdoutBuffer)
  136. if err = job.Run(); err != nil {
  137. return err
  138. }
  139. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  140. var env engine.Env
  141. env.Set("Status", status)
  142. return writeJSON(w, http.StatusOK, env)
  143. }
  144. w.WriteHeader(http.StatusNoContent)
  145. return nil
  146. }
  147. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  148. w.Header().Set("Content-Type", "application/json")
  149. eng.ServeHTTP(w, r)
  150. return nil
  151. }
  152. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  153. if vars == nil {
  154. return fmt.Errorf("Missing parameter")
  155. }
  156. if err := parseForm(r); err != nil {
  157. return err
  158. }
  159. job := eng.Job("kill", vars["name"])
  160. if sig := r.Form.Get("signal"); sig != "" {
  161. job.Args = append(job.Args, sig)
  162. }
  163. if err := job.Run(); err != nil {
  164. return err
  165. }
  166. w.WriteHeader(http.StatusNoContent)
  167. return nil
  168. }
  169. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  170. if vars == nil {
  171. return fmt.Errorf("Missing parameter")
  172. }
  173. if err := parseForm(r); err != nil {
  174. return err
  175. }
  176. job := eng.Job("pause", vars["name"])
  177. if err := job.Run(); err != nil {
  178. return err
  179. }
  180. w.WriteHeader(http.StatusNoContent)
  181. return nil
  182. }
  183. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  184. if vars == nil {
  185. return fmt.Errorf("Missing parameter")
  186. }
  187. if err := parseForm(r); err != nil {
  188. return err
  189. }
  190. job := eng.Job("unpause", vars["name"])
  191. if err := job.Run(); err != nil {
  192. return err
  193. }
  194. w.WriteHeader(http.StatusNoContent)
  195. return nil
  196. }
  197. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  198. if vars == nil {
  199. return fmt.Errorf("Missing parameter")
  200. }
  201. job := eng.Job("export", vars["name"])
  202. job.Stdout.Add(w)
  203. if err := job.Run(); err != nil {
  204. return err
  205. }
  206. return nil
  207. }
  208. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  209. if err := parseForm(r); err != nil {
  210. return err
  211. }
  212. var (
  213. err error
  214. outs *engine.Table
  215. job = eng.Job("images")
  216. )
  217. job.Setenv("filters", r.Form.Get("filters"))
  218. // FIXME this parameter could just be a match filter
  219. job.Setenv("filter", r.Form.Get("filter"))
  220. job.Setenv("all", r.Form.Get("all"))
  221. if version.GreaterThanOrEqualTo("1.7") {
  222. streamJSON(job, w, false)
  223. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  224. return err
  225. }
  226. if err := job.Run(); err != nil {
  227. return err
  228. }
  229. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  230. outsLegacy := engine.NewTable("Created", 0)
  231. for _, out := range outs.Data {
  232. for _, repoTag := range out.GetList("RepoTags") {
  233. repo, tag := parsers.ParseRepositoryTag(repoTag)
  234. outLegacy := &engine.Env{}
  235. outLegacy.Set("Repository", repo)
  236. outLegacy.SetJson("Tag", tag)
  237. outLegacy.Set("Id", out.Get("Id"))
  238. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  239. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  240. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  241. outsLegacy.Add(outLegacy)
  242. }
  243. }
  244. w.Header().Set("Content-Type", "application/json")
  245. if _, err := outsLegacy.WriteListTo(w); err != nil {
  246. return err
  247. }
  248. }
  249. return nil
  250. }
  251. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  252. if version.GreaterThan("1.6") {
  253. w.WriteHeader(http.StatusNotFound)
  254. return fmt.Errorf("This is now implemented in the client.")
  255. }
  256. eng.ServeHTTP(w, r)
  257. return nil
  258. }
  259. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  260. w.Header().Set("Content-Type", "application/json")
  261. eng.ServeHTTP(w, r)
  262. return nil
  263. }
  264. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  265. if err := parseForm(r); err != nil {
  266. return err
  267. }
  268. var job = eng.Job("events")
  269. streamJSON(job, w, true)
  270. job.Setenv("since", r.Form.Get("since"))
  271. job.Setenv("until", r.Form.Get("until"))
  272. return job.Run()
  273. }
  274. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  275. if vars == nil {
  276. return fmt.Errorf("Missing parameter")
  277. }
  278. var job = eng.Job("history", vars["name"])
  279. streamJSON(job, w, false)
  280. if err := job.Run(); err != nil {
  281. return err
  282. }
  283. return nil
  284. }
  285. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  286. if vars == nil {
  287. return fmt.Errorf("Missing parameter")
  288. }
  289. var job = eng.Job("container_changes", vars["name"])
  290. streamJSON(job, w, false)
  291. return job.Run()
  292. }
  293. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  294. if version.LessThan("1.4") {
  295. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  296. }
  297. if vars == nil {
  298. return fmt.Errorf("Missing parameter")
  299. }
  300. if err := parseForm(r); err != nil {
  301. return err
  302. }
  303. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  304. streamJSON(job, w, false)
  305. return job.Run()
  306. }
  307. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  308. if err := parseForm(r); err != nil {
  309. return err
  310. }
  311. var (
  312. err error
  313. outs *engine.Table
  314. job = eng.Job("containers")
  315. )
  316. job.Setenv("all", r.Form.Get("all"))
  317. job.Setenv("size", r.Form.Get("size"))
  318. job.Setenv("since", r.Form.Get("since"))
  319. job.Setenv("before", r.Form.Get("before"))
  320. job.Setenv("limit", r.Form.Get("limit"))
  321. job.Setenv("filters", r.Form.Get("filters"))
  322. if version.GreaterThanOrEqualTo("1.5") {
  323. streamJSON(job, w, false)
  324. } else if outs, err = job.Stdout.AddTable(); err != nil {
  325. return err
  326. }
  327. if err = job.Run(); err != nil {
  328. return err
  329. }
  330. if version.LessThan("1.5") { // Convert to legacy format
  331. for _, out := range outs.Data {
  332. ports := engine.NewTable("", 0)
  333. ports.ReadListFrom([]byte(out.Get("Ports")))
  334. out.Set("Ports", api.DisplayablePorts(ports))
  335. }
  336. w.Header().Set("Content-Type", "application/json")
  337. if _, err = outs.WriteListTo(w); err != nil {
  338. return err
  339. }
  340. }
  341. return nil
  342. }
  343. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  344. if err := parseForm(r); err != nil {
  345. return err
  346. }
  347. if vars == nil {
  348. return fmt.Errorf("Missing parameter")
  349. }
  350. var (
  351. inspectJob = eng.Job("container_inspect", vars["name"])
  352. logsJob = eng.Job("logs", vars["name"])
  353. c, err = inspectJob.Stdout.AddEnv()
  354. )
  355. if err != nil {
  356. return err
  357. }
  358. logsJob.Setenv("follow", r.Form.Get("follow"))
  359. logsJob.Setenv("tail", r.Form.Get("tail"))
  360. logsJob.Setenv("stdout", r.Form.Get("stdout"))
  361. logsJob.Setenv("stderr", r.Form.Get("stderr"))
  362. logsJob.Setenv("timestamps", r.Form.Get("timestamps"))
  363. // Validate args here, because we can't return not StatusOK after job.Run() call
  364. stdout, stderr := logsJob.GetenvBool("stdout"), logsJob.GetenvBool("stderr")
  365. if !(stdout || stderr) {
  366. return fmt.Errorf("Bad parameters: you must choose at least one stream")
  367. }
  368. if err = inspectJob.Run(); err != nil {
  369. return err
  370. }
  371. var outStream, errStream io.Writer
  372. outStream = utils.NewWriteFlusher(w)
  373. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  374. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  375. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  376. } else {
  377. errStream = outStream
  378. }
  379. logsJob.Stdout.Add(outStream)
  380. logsJob.Stderr.Set(errStream)
  381. if err := logsJob.Run(); err != nil {
  382. fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
  383. }
  384. return nil
  385. }
  386. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  387. if err := parseForm(r); err != nil {
  388. return err
  389. }
  390. if vars == nil {
  391. return fmt.Errorf("Missing parameter")
  392. }
  393. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  394. job.Setenv("force", r.Form.Get("force"))
  395. if err := job.Run(); err != nil {
  396. return err
  397. }
  398. w.WriteHeader(http.StatusCreated)
  399. return nil
  400. }
  401. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  402. if err := parseForm(r); err != nil {
  403. return err
  404. }
  405. var (
  406. config engine.Env
  407. env engine.Env
  408. job = eng.Job("commit", r.Form.Get("container"))
  409. stdoutBuffer = bytes.NewBuffer(nil)
  410. )
  411. if err := checkForJson(r); err != nil {
  412. return err
  413. }
  414. if err := config.Decode(r.Body); err != nil {
  415. log.Errorf("%s", err)
  416. }
  417. if r.FormValue("pause") == "" && version.GreaterThanOrEqualTo("1.13") {
  418. job.Setenv("pause", "1")
  419. } else {
  420. job.Setenv("pause", r.FormValue("pause"))
  421. }
  422. job.Setenv("repo", r.Form.Get("repo"))
  423. job.Setenv("tag", r.Form.Get("tag"))
  424. job.Setenv("author", r.Form.Get("author"))
  425. job.Setenv("comment", r.Form.Get("comment"))
  426. job.SetenvSubEnv("config", &config)
  427. job.Stdout.Add(stdoutBuffer)
  428. if err := job.Run(); err != nil {
  429. return err
  430. }
  431. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  432. return writeJSON(w, http.StatusCreated, env)
  433. }
  434. // Creates an image from Pull or from Import
  435. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  436. if err := parseForm(r); err != nil {
  437. return err
  438. }
  439. var (
  440. image = r.Form.Get("fromImage")
  441. repo = r.Form.Get("repo")
  442. tag = r.Form.Get("tag")
  443. job *engine.Job
  444. )
  445. authEncoded := r.Header.Get("X-Registry-Auth")
  446. authConfig := &registry.AuthConfig{}
  447. if authEncoded != "" {
  448. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  449. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  450. // for a pull it is not an error if no auth was given
  451. // to increase compatibility with the existing api it is defaulting to be empty
  452. authConfig = &registry.AuthConfig{}
  453. }
  454. }
  455. if image != "" { //pull
  456. if tag == "" {
  457. image, tag = parsers.ParseRepositoryTag(image)
  458. }
  459. metaHeaders := map[string][]string{}
  460. for k, v := range r.Header {
  461. if strings.HasPrefix(k, "X-Meta-") {
  462. metaHeaders[k] = v
  463. }
  464. }
  465. job = eng.Job("pull", image, tag)
  466. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  467. job.SetenvJson("metaHeaders", metaHeaders)
  468. job.SetenvJson("authConfig", authConfig)
  469. } else { //import
  470. if tag == "" {
  471. repo, tag = parsers.ParseRepositoryTag(repo)
  472. }
  473. job = eng.Job("import", r.Form.Get("fromSrc"), repo, tag)
  474. job.Stdin.Add(r.Body)
  475. }
  476. if version.GreaterThan("1.0") {
  477. job.SetenvBool("json", true)
  478. streamJSON(job, w, true)
  479. } else {
  480. job.Stdout.Add(utils.NewWriteFlusher(w))
  481. }
  482. if err := job.Run(); err != nil {
  483. if !job.Stdout.Used() {
  484. return err
  485. }
  486. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  487. w.Write(sf.FormatError(err))
  488. }
  489. return nil
  490. }
  491. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  492. if err := parseForm(r); err != nil {
  493. return err
  494. }
  495. var (
  496. authEncoded = r.Header.Get("X-Registry-Auth")
  497. authConfig = &registry.AuthConfig{}
  498. metaHeaders = map[string][]string{}
  499. )
  500. if authEncoded != "" {
  501. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  502. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  503. // for a search it is not an error if no auth was given
  504. // to increase compatibility with the existing api it is defaulting to be empty
  505. authConfig = &registry.AuthConfig{}
  506. }
  507. }
  508. for k, v := range r.Header {
  509. if strings.HasPrefix(k, "X-Meta-") {
  510. metaHeaders[k] = v
  511. }
  512. }
  513. var job = eng.Job("search", r.Form.Get("term"))
  514. job.SetenvJson("metaHeaders", metaHeaders)
  515. job.SetenvJson("authConfig", authConfig)
  516. streamJSON(job, w, false)
  517. return job.Run()
  518. }
  519. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  520. if vars == nil {
  521. return fmt.Errorf("Missing parameter")
  522. }
  523. metaHeaders := map[string][]string{}
  524. for k, v := range r.Header {
  525. if strings.HasPrefix(k, "X-Meta-") {
  526. metaHeaders[k] = v
  527. }
  528. }
  529. if err := parseForm(r); err != nil {
  530. return err
  531. }
  532. authConfig := &registry.AuthConfig{}
  533. authEncoded := r.Header.Get("X-Registry-Auth")
  534. if authEncoded != "" {
  535. // the new format is to handle the authConfig as a header
  536. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  537. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  538. // to increase compatibility to existing api it is defaulting to be empty
  539. authConfig = &registry.AuthConfig{}
  540. }
  541. } else {
  542. // the old format is supported for compatibility if there was no authConfig header
  543. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  544. return err
  545. }
  546. }
  547. job := eng.Job("push", vars["name"])
  548. job.SetenvJson("metaHeaders", metaHeaders)
  549. job.SetenvJson("authConfig", authConfig)
  550. job.Setenv("tag", r.Form.Get("tag"))
  551. if version.GreaterThan("1.0") {
  552. job.SetenvBool("json", true)
  553. streamJSON(job, w, true)
  554. } else {
  555. job.Stdout.Add(utils.NewWriteFlusher(w))
  556. }
  557. if err := job.Run(); err != nil {
  558. if !job.Stdout.Used() {
  559. return err
  560. }
  561. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  562. w.Write(sf.FormatError(err))
  563. }
  564. return nil
  565. }
  566. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  567. if vars == nil {
  568. return fmt.Errorf("Missing parameter")
  569. }
  570. if err := parseForm(r); err != nil {
  571. return err
  572. }
  573. if version.GreaterThan("1.0") {
  574. w.Header().Set("Content-Type", "application/x-tar")
  575. }
  576. var job *engine.Job
  577. if name, ok := vars["name"]; ok {
  578. job = eng.Job("image_export", name)
  579. } else {
  580. job = eng.Job("image_export", r.Form["names"]...)
  581. }
  582. job.Stdout.Add(w)
  583. return job.Run()
  584. }
  585. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  586. job := eng.Job("load")
  587. job.Stdin.Add(r.Body)
  588. return job.Run()
  589. }
  590. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  591. if err := parseForm(r); err != nil {
  592. return nil
  593. }
  594. var (
  595. out engine.Env
  596. job = eng.Job("create", r.Form.Get("name"))
  597. outWarnings []string
  598. stdoutBuffer = bytes.NewBuffer(nil)
  599. warnings = bytes.NewBuffer(nil)
  600. )
  601. if err := checkForJson(r); err != nil {
  602. return err
  603. }
  604. if err := job.DecodeEnv(r.Body); err != nil {
  605. return err
  606. }
  607. // Read container ID from the first line of stdout
  608. job.Stdout.Add(stdoutBuffer)
  609. // Read warnings from stderr
  610. job.Stderr.Add(warnings)
  611. if err := job.Run(); err != nil {
  612. return err
  613. }
  614. // Parse warnings from stderr
  615. scanner := bufio.NewScanner(warnings)
  616. for scanner.Scan() {
  617. outWarnings = append(outWarnings, scanner.Text())
  618. }
  619. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  620. out.SetList("Warnings", outWarnings)
  621. return writeJSON(w, http.StatusCreated, out)
  622. }
  623. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  624. if err := parseForm(r); err != nil {
  625. return err
  626. }
  627. if vars == nil {
  628. return fmt.Errorf("Missing parameter")
  629. }
  630. job := eng.Job("restart", vars["name"])
  631. job.Setenv("t", r.Form.Get("t"))
  632. if err := job.Run(); err != nil {
  633. return err
  634. }
  635. w.WriteHeader(http.StatusNoContent)
  636. return nil
  637. }
  638. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  639. if err := parseForm(r); err != nil {
  640. return err
  641. }
  642. if vars == nil {
  643. return fmt.Errorf("Missing parameter")
  644. }
  645. job := eng.Job("rm", vars["name"])
  646. job.Setenv("forceRemove", r.Form.Get("force"))
  647. job.Setenv("removeVolume", r.Form.Get("v"))
  648. job.Setenv("removeLink", r.Form.Get("link"))
  649. if err := job.Run(); err != nil {
  650. return err
  651. }
  652. w.WriteHeader(http.StatusNoContent)
  653. return nil
  654. }
  655. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  656. if err := parseForm(r); err != nil {
  657. return err
  658. }
  659. if vars == nil {
  660. return fmt.Errorf("Missing parameter")
  661. }
  662. var job = eng.Job("image_delete", vars["name"])
  663. streamJSON(job, w, false)
  664. job.Setenv("force", r.Form.Get("force"))
  665. job.Setenv("noprune", r.Form.Get("noprune"))
  666. return job.Run()
  667. }
  668. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  669. if vars == nil {
  670. return fmt.Errorf("Missing parameter")
  671. }
  672. var (
  673. name = vars["name"]
  674. job = eng.Job("start", name)
  675. )
  676. // If contentLength is -1, we can assumed chunked encoding
  677. // or more technically that the length is unknown
  678. // http://golang.org/src/pkg/net/http/request.go#L139
  679. // net/http otherwise seems to swallow any headers related to chunked encoding
  680. // including r.TransferEncoding
  681. // allow a nil body for backwards compatibility
  682. if r.Body != nil && (r.ContentLength > 0 || r.ContentLength == -1) {
  683. if err := checkForJson(r); err != nil {
  684. return err
  685. }
  686. if err := job.DecodeEnv(r.Body); err != nil {
  687. return err
  688. }
  689. }
  690. if err := job.Run(); err != nil {
  691. if err.Error() == "Container already started" {
  692. w.WriteHeader(http.StatusNotModified)
  693. return nil
  694. }
  695. return err
  696. }
  697. w.WriteHeader(http.StatusNoContent)
  698. return nil
  699. }
  700. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  701. if err := parseForm(r); err != nil {
  702. return err
  703. }
  704. if vars == nil {
  705. return fmt.Errorf("Missing parameter")
  706. }
  707. job := eng.Job("stop", vars["name"])
  708. job.Setenv("t", r.Form.Get("t"))
  709. if err := job.Run(); err != nil {
  710. if err.Error() == "Container already stopped" {
  711. w.WriteHeader(http.StatusNotModified)
  712. return nil
  713. }
  714. return err
  715. }
  716. w.WriteHeader(http.StatusNoContent)
  717. return nil
  718. }
  719. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  720. if vars == nil {
  721. return fmt.Errorf("Missing parameter")
  722. }
  723. var (
  724. env engine.Env
  725. stdoutBuffer = bytes.NewBuffer(nil)
  726. job = eng.Job("wait", vars["name"])
  727. )
  728. job.Stdout.Add(stdoutBuffer)
  729. if err := job.Run(); err != nil {
  730. return err
  731. }
  732. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  733. return writeJSON(w, http.StatusOK, env)
  734. }
  735. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  736. if err := parseForm(r); err != nil {
  737. return err
  738. }
  739. if vars == nil {
  740. return fmt.Errorf("Missing parameter")
  741. }
  742. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  743. return err
  744. }
  745. return nil
  746. }
  747. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  748. if err := parseForm(r); err != nil {
  749. return err
  750. }
  751. if vars == nil {
  752. return fmt.Errorf("Missing parameter")
  753. }
  754. var (
  755. job = eng.Job("container_inspect", vars["name"])
  756. c, err = job.Stdout.AddEnv()
  757. )
  758. if err != nil {
  759. return err
  760. }
  761. if err = job.Run(); err != nil {
  762. return err
  763. }
  764. inStream, outStream, err := hijackServer(w)
  765. if err != nil {
  766. return err
  767. }
  768. defer func() {
  769. if tcpc, ok := inStream.(*net.TCPConn); ok {
  770. tcpc.CloseWrite()
  771. } else {
  772. inStream.Close()
  773. }
  774. }()
  775. defer func() {
  776. if tcpc, ok := outStream.(*net.TCPConn); ok {
  777. tcpc.CloseWrite()
  778. } else if closer, ok := outStream.(io.Closer); ok {
  779. closer.Close()
  780. }
  781. }()
  782. var errStream io.Writer
  783. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  784. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  785. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  786. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  787. } else {
  788. errStream = outStream
  789. }
  790. job = eng.Job("attach", vars["name"])
  791. job.Setenv("logs", r.Form.Get("logs"))
  792. job.Setenv("stream", r.Form.Get("stream"))
  793. job.Setenv("stdin", r.Form.Get("stdin"))
  794. job.Setenv("stdout", r.Form.Get("stdout"))
  795. job.Setenv("stderr", r.Form.Get("stderr"))
  796. job.Stdin.Add(inStream)
  797. job.Stdout.Add(outStream)
  798. job.Stderr.Set(errStream)
  799. if err := job.Run(); err != nil {
  800. fmt.Fprintf(outStream, "Error attaching: %s\n", err)
  801. }
  802. return nil
  803. }
  804. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  805. if err := parseForm(r); err != nil {
  806. return err
  807. }
  808. if vars == nil {
  809. return fmt.Errorf("Missing parameter")
  810. }
  811. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  812. return err
  813. }
  814. h := websocket.Handler(func(ws *websocket.Conn) {
  815. defer ws.Close()
  816. job := eng.Job("attach", vars["name"])
  817. job.Setenv("logs", r.Form.Get("logs"))
  818. job.Setenv("stream", r.Form.Get("stream"))
  819. job.Setenv("stdin", r.Form.Get("stdin"))
  820. job.Setenv("stdout", r.Form.Get("stdout"))
  821. job.Setenv("stderr", r.Form.Get("stderr"))
  822. job.Stdin.Add(ws)
  823. job.Stdout.Add(ws)
  824. job.Stderr.Set(ws)
  825. if err := job.Run(); err != nil {
  826. log.Errorf("Error attaching websocket: %s", err)
  827. }
  828. })
  829. h.ServeHTTP(w, r)
  830. return nil
  831. }
  832. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  833. if vars == nil {
  834. return fmt.Errorf("Missing parameter")
  835. }
  836. var job = eng.Job("container_inspect", vars["name"])
  837. if version.LessThan("1.12") {
  838. job.SetenvBool("raw", true)
  839. }
  840. streamJSON(job, w, false)
  841. return job.Run()
  842. }
  843. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  844. if vars == nil {
  845. return fmt.Errorf("Missing parameter")
  846. }
  847. var job = eng.Job("image_inspect", vars["name"])
  848. if version.LessThan("1.12") {
  849. job.SetenvBool("raw", true)
  850. }
  851. streamJSON(job, w, false)
  852. return job.Run()
  853. }
  854. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  855. if version.LessThan("1.3") {
  856. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  857. }
  858. var (
  859. authEncoded = r.Header.Get("X-Registry-Auth")
  860. authConfig = &registry.AuthConfig{}
  861. configFileEncoded = r.Header.Get("X-Registry-Config")
  862. configFile = &registry.ConfigFile{}
  863. job = eng.Job("build")
  864. )
  865. // This block can be removed when API versions prior to 1.9 are deprecated.
  866. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  867. // ConfigFile is present, any value provided as an AuthConfig directly will
  868. // be overridden. See BuildFile::CmdFrom for details.
  869. if version.LessThan("1.9") && authEncoded != "" {
  870. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  871. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  872. // for a pull it is not an error if no auth was given
  873. // to increase compatibility with the existing api it is defaulting to be empty
  874. authConfig = &registry.AuthConfig{}
  875. }
  876. }
  877. if configFileEncoded != "" {
  878. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  879. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  880. // for a pull it is not an error if no auth was given
  881. // to increase compatibility with the existing api it is defaulting to be empty
  882. configFile = &registry.ConfigFile{}
  883. }
  884. }
  885. if version.GreaterThanOrEqualTo("1.8") {
  886. job.SetenvBool("json", true)
  887. streamJSON(job, w, true)
  888. } else {
  889. job.Stdout.Add(utils.NewWriteFlusher(w))
  890. }
  891. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  892. job.Setenv("rm", "1")
  893. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  894. job.Setenv("rm", "1")
  895. } else {
  896. job.Setenv("rm", r.FormValue("rm"))
  897. }
  898. job.Stdin.Add(r.Body)
  899. job.Setenv("remote", r.FormValue("remote"))
  900. job.Setenv("t", r.FormValue("t"))
  901. job.Setenv("q", r.FormValue("q"))
  902. job.Setenv("nocache", r.FormValue("nocache"))
  903. job.Setenv("forcerm", r.FormValue("forcerm"))
  904. job.SetenvJson("authConfig", authConfig)
  905. job.SetenvJson("configFile", configFile)
  906. if err := job.Run(); err != nil {
  907. if !job.Stdout.Used() {
  908. return err
  909. }
  910. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  911. w.Write(sf.FormatError(err))
  912. }
  913. return nil
  914. }
  915. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  916. if vars == nil {
  917. return fmt.Errorf("Missing parameter")
  918. }
  919. var copyData engine.Env
  920. if err := checkForJson(r); err != nil {
  921. return err
  922. }
  923. if err := copyData.Decode(r.Body); err != nil {
  924. return err
  925. }
  926. if copyData.Get("Resource") == "" {
  927. return fmt.Errorf("Path cannot be empty")
  928. }
  929. origResource := copyData.Get("Resource")
  930. if copyData.Get("Resource")[0] == '/' {
  931. copyData.Set("Resource", copyData.Get("Resource")[1:])
  932. }
  933. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  934. job.Stdout.Add(w)
  935. w.Header().Set("Content-Type", "application/x-tar")
  936. if err := job.Run(); err != nil {
  937. log.Errorf("%s", err.Error())
  938. if strings.Contains(strings.ToLower(err.Error()), "no such container") {
  939. w.WriteHeader(http.StatusNotFound)
  940. } else if strings.Contains(err.Error(), "no such file or directory") {
  941. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  942. }
  943. }
  944. return nil
  945. }
  946. func postContainerExecCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  947. if err := parseForm(r); err != nil {
  948. return nil
  949. }
  950. var (
  951. out engine.Env
  952. name = vars["name"]
  953. job = eng.Job("execCreate", name)
  954. stdoutBuffer = bytes.NewBuffer(nil)
  955. )
  956. if err := job.DecodeEnv(r.Body); err != nil {
  957. return err
  958. }
  959. job.Stdout.Add(stdoutBuffer)
  960. // Register an instance of Exec in container.
  961. if err := job.Run(); err != nil {
  962. fmt.Fprintf(os.Stderr, "Error setting up exec command in container %s: %s\n", name, err)
  963. return err
  964. }
  965. // Return the ID
  966. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  967. return writeJSON(w, http.StatusCreated, out)
  968. }
  969. // TODO(vishh): Refactor the code to avoid having to specify stream config as part of both create and start.
  970. func postContainerExecStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  971. if err := parseForm(r); err != nil {
  972. return nil
  973. }
  974. var (
  975. name = vars["name"]
  976. job = eng.Job("execStart", name)
  977. errOut io.Writer = os.Stderr
  978. )
  979. if err := job.DecodeEnv(r.Body); err != nil {
  980. return err
  981. }
  982. if !job.GetenvBool("Detach") {
  983. // Setting up the streaming http interface.
  984. inStream, outStream, err := hijackServer(w)
  985. if err != nil {
  986. return err
  987. }
  988. defer func() {
  989. if tcpc, ok := inStream.(*net.TCPConn); ok {
  990. tcpc.CloseWrite()
  991. } else {
  992. inStream.Close()
  993. }
  994. }()
  995. defer func() {
  996. if tcpc, ok := outStream.(*net.TCPConn); ok {
  997. tcpc.CloseWrite()
  998. } else if closer, ok := outStream.(io.Closer); ok {
  999. closer.Close()
  1000. }
  1001. }()
  1002. var errStream io.Writer
  1003. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  1004. if !job.GetenvBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  1005. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  1006. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  1007. } else {
  1008. errStream = outStream
  1009. }
  1010. job.Stdin.Add(inStream)
  1011. job.Stdout.Add(outStream)
  1012. job.Stderr.Set(errStream)
  1013. errOut = outStream
  1014. }
  1015. // Now run the user process in container.
  1016. job.SetCloseIO(false)
  1017. if err := job.Run(); err != nil {
  1018. fmt.Fprintf(errOut, "Error starting exec command in container %s: %s\n", name, err)
  1019. return err
  1020. }
  1021. w.WriteHeader(http.StatusNoContent)
  1022. return nil
  1023. }
  1024. func postContainerExecResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1025. if err := parseForm(r); err != nil {
  1026. return err
  1027. }
  1028. if vars == nil {
  1029. return fmt.Errorf("Missing parameter")
  1030. }
  1031. if err := eng.Job("execResize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  1032. return err
  1033. }
  1034. return nil
  1035. }
  1036. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1037. w.WriteHeader(http.StatusOK)
  1038. return nil
  1039. }
  1040. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  1041. w.Header().Add("Access-Control-Allow-Origin", "*")
  1042. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept")
  1043. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  1044. }
  1045. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1046. _, err := w.Write([]byte{'O', 'K'})
  1047. return err
  1048. }
  1049. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  1050. return func(w http.ResponseWriter, r *http.Request) {
  1051. // log the request
  1052. log.Debugf("Calling %s %s", localMethod, localRoute)
  1053. if logging {
  1054. log.Infof("%s %s", r.Method, r.RequestURI)
  1055. }
  1056. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  1057. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  1058. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  1059. log.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  1060. }
  1061. }
  1062. version := version.Version(mux.Vars(r)["version"])
  1063. if version == "" {
  1064. version = api.APIVERSION
  1065. }
  1066. if enableCors {
  1067. writeCorsHeaders(w, r)
  1068. }
  1069. if version.GreaterThan(api.APIVERSION) {
  1070. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  1071. return
  1072. }
  1073. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  1074. log.Errorf("Handler for %s %s returned error: %s", localMethod, localRoute, err)
  1075. httpError(w, err)
  1076. }
  1077. }
  1078. }
  1079. // Replicated from expvar.go as not public.
  1080. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  1081. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  1082. fmt.Fprintf(w, "{\n")
  1083. first := true
  1084. expvar.Do(func(kv expvar.KeyValue) {
  1085. if !first {
  1086. fmt.Fprintf(w, ",\n")
  1087. }
  1088. first = false
  1089. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  1090. })
  1091. fmt.Fprintf(w, "\n}\n")
  1092. }
  1093. func AttachProfiler(router *mux.Router) {
  1094. router.HandleFunc("/debug/vars", expvarHandler)
  1095. router.HandleFunc("/debug/pprof/", pprof.Index)
  1096. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  1097. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  1098. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  1099. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  1100. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  1101. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  1102. }
  1103. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) (*mux.Router, error) {
  1104. r := mux.NewRouter()
  1105. if os.Getenv("DEBUG") != "" {
  1106. AttachProfiler(r)
  1107. }
  1108. m := map[string]map[string]HttpApiFunc{
  1109. "GET": {
  1110. "/_ping": ping,
  1111. "/events": getEvents,
  1112. "/info": getInfo,
  1113. "/version": getVersion,
  1114. "/images/json": getImagesJSON,
  1115. "/images/viz": getImagesViz,
  1116. "/images/search": getImagesSearch,
  1117. "/images/get": getImagesGet,
  1118. "/images/{name:.*}/get": getImagesGet,
  1119. "/images/{name:.*}/history": getImagesHistory,
  1120. "/images/{name:.*}/json": getImagesByName,
  1121. "/containers/ps": getContainersJSON,
  1122. "/containers/json": getContainersJSON,
  1123. "/containers/{name:.*}/export": getContainersExport,
  1124. "/containers/{name:.*}/changes": getContainersChanges,
  1125. "/containers/{name:.*}/json": getContainersByName,
  1126. "/containers/{name:.*}/top": getContainersTop,
  1127. "/containers/{name:.*}/logs": getContainersLogs,
  1128. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  1129. },
  1130. "POST": {
  1131. "/auth": postAuth,
  1132. "/commit": postCommit,
  1133. "/build": postBuild,
  1134. "/images/create": postImagesCreate,
  1135. "/images/load": postImagesLoad,
  1136. "/images/{name:.*}/push": postImagesPush,
  1137. "/images/{name:.*}/tag": postImagesTag,
  1138. "/containers/create": postContainersCreate,
  1139. "/containers/{name:.*}/kill": postContainersKill,
  1140. "/containers/{name:.*}/pause": postContainersPause,
  1141. "/containers/{name:.*}/unpause": postContainersUnpause,
  1142. "/containers/{name:.*}/restart": postContainersRestart,
  1143. "/containers/{name:.*}/start": postContainersStart,
  1144. "/containers/{name:.*}/stop": postContainersStop,
  1145. "/containers/{name:.*}/wait": postContainersWait,
  1146. "/containers/{name:.*}/resize": postContainersResize,
  1147. "/containers/{name:.*}/attach": postContainersAttach,
  1148. "/containers/{name:.*}/copy": postContainersCopy,
  1149. "/containers/{name:.*}/exec": postContainerExecCreate,
  1150. "/exec/{name:.*}/start": postContainerExecStart,
  1151. "/exec/{name:.*}/resize": postContainerExecResize,
  1152. },
  1153. "DELETE": {
  1154. "/containers/{name:.*}": deleteContainers,
  1155. "/images/{name:.*}": deleteImages,
  1156. },
  1157. "OPTIONS": {
  1158. "": optionsHandler,
  1159. },
  1160. }
  1161. for method, routes := range m {
  1162. for route, fct := range routes {
  1163. log.Debugf("Registering %s, %s", method, route)
  1164. // NOTE: scope issue, make sure the variables are local and won't be changed
  1165. localRoute := route
  1166. localFct := fct
  1167. localMethod := method
  1168. // build the handler function
  1169. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1170. // add the new route
  1171. if localRoute == "" {
  1172. r.Methods(localMethod).HandlerFunc(f)
  1173. } else {
  1174. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1175. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1176. }
  1177. }
  1178. }
  1179. return r, nil
  1180. }
  1181. // ServeRequest processes a single http request to the docker remote api.
  1182. // FIXME: refactor this to be part of Server and not require re-creating a new
  1183. // router each time. This requires first moving ListenAndServe into Server.
  1184. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) error {
  1185. router, err := createRouter(eng, false, true, "")
  1186. if err != nil {
  1187. return err
  1188. }
  1189. // Insert APIVERSION into the request as a convenience
  1190. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1191. router.ServeHTTP(w, req)
  1192. return nil
  1193. }
  1194. // ServeFD creates an http.Server and sets it up to serve given a socket activated
  1195. // argument.
  1196. func ServeFd(addr string, handle http.Handler) error {
  1197. ls, e := systemd.ListenFD(addr)
  1198. if e != nil {
  1199. return e
  1200. }
  1201. chErrors := make(chan error, len(ls))
  1202. // We don't want to start serving on these sockets until the
  1203. // daemon is initialized and installed. Otherwise required handlers
  1204. // won't be ready.
  1205. <-activationLock
  1206. // Since ListenFD will return one or more sockets we have
  1207. // to create a go func to spawn off multiple serves
  1208. for i := range ls {
  1209. listener := ls[i]
  1210. go func() {
  1211. httpSrv := http.Server{Handler: handle}
  1212. chErrors <- httpSrv.Serve(listener)
  1213. }()
  1214. }
  1215. for i := 0; i < len(ls); i++ {
  1216. err := <-chErrors
  1217. if err != nil {
  1218. return err
  1219. }
  1220. }
  1221. return nil
  1222. }
  1223. func lookupGidByName(nameOrGid string) (int, error) {
  1224. groupFile, err := user.GetGroupFile()
  1225. if err != nil {
  1226. return -1, err
  1227. }
  1228. groups, err := user.ParseGroupFileFilter(groupFile, func(g user.Group) bool {
  1229. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1230. })
  1231. if err != nil {
  1232. return -1, err
  1233. }
  1234. if groups != nil && len(groups) > 0 {
  1235. return groups[0].Gid, nil
  1236. }
  1237. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1238. }
  1239. func changeGroup(addr string, nameOrGid string) error {
  1240. gid, err := lookupGidByName(nameOrGid)
  1241. if err != nil {
  1242. return err
  1243. }
  1244. log.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1245. return os.Chown(addr, 0, gid)
  1246. }
  1247. // ListenAndServe sets up the required http.Server and gets it listening for
  1248. // each addr passed in and does protocol specific checking.
  1249. func ListenAndServe(proto, addr string, job *engine.Job) error {
  1250. var l net.Listener
  1251. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1252. if err != nil {
  1253. return err
  1254. }
  1255. if proto == "fd" {
  1256. return ServeFd(addr, r)
  1257. }
  1258. if proto == "unix" {
  1259. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1260. return err
  1261. }
  1262. }
  1263. var oldmask int
  1264. if proto == "unix" {
  1265. oldmask = syscall.Umask(0777)
  1266. }
  1267. if job.GetenvBool("BufferRequests") {
  1268. l, err = listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1269. } else {
  1270. l, err = net.Listen(proto, addr)
  1271. }
  1272. if proto == "unix" {
  1273. syscall.Umask(oldmask)
  1274. }
  1275. if err != nil {
  1276. return err
  1277. }
  1278. if proto != "unix" && (job.GetenvBool("Tls") || job.GetenvBool("TlsVerify")) {
  1279. tlsCert := job.Getenv("TlsCert")
  1280. tlsKey := job.Getenv("TlsKey")
  1281. cert, err := tls.LoadX509KeyPair(tlsCert, tlsKey)
  1282. if err != nil {
  1283. return fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1284. tlsCert, tlsKey, err)
  1285. }
  1286. tlsConfig := &tls.Config{
  1287. NextProtos: []string{"http/1.1"},
  1288. Certificates: []tls.Certificate{cert},
  1289. // Avoid fallback on insecure SSL protocols
  1290. MinVersion: tls.VersionTLS10,
  1291. }
  1292. if job.GetenvBool("TlsVerify") {
  1293. certPool := x509.NewCertPool()
  1294. file, err := ioutil.ReadFile(job.Getenv("TlsCa"))
  1295. if err != nil {
  1296. return fmt.Errorf("Couldn't read CA certificate: %s", err)
  1297. }
  1298. certPool.AppendCertsFromPEM(file)
  1299. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1300. tlsConfig.ClientCAs = certPool
  1301. }
  1302. l = tls.NewListener(l, tlsConfig)
  1303. }
  1304. // Basic error and sanity checking
  1305. switch proto {
  1306. case "tcp":
  1307. if !strings.HasPrefix(addr, "127.0.0.1") && !job.GetenvBool("TlsVerify") {
  1308. log.Infof("/!\\ DON'T BIND ON ANOTHER IP ADDRESS THAN 127.0.0.1 IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1309. }
  1310. case "unix":
  1311. socketGroup := job.Getenv("SocketGroup")
  1312. if socketGroup != "" {
  1313. if err := changeGroup(addr, socketGroup); err != nil {
  1314. if socketGroup == "docker" {
  1315. // if the user hasn't explicitly specified the group ownership, don't fail on errors.
  1316. log.Debugf("Warning: could not chgrp %s to docker: %s", addr, err.Error())
  1317. } else {
  1318. return err
  1319. }
  1320. }
  1321. }
  1322. if err := os.Chmod(addr, 0660); err != nil {
  1323. return err
  1324. }
  1325. default:
  1326. return fmt.Errorf("Invalid protocol format.")
  1327. }
  1328. httpSrv := http.Server{Addr: addr, Handler: r}
  1329. return httpSrv.Serve(l)
  1330. }
  1331. // ServeApi loops through all of the protocols sent in to docker and spawns
  1332. // off a go routine to setup a serving http.Server for each.
  1333. func ServeApi(job *engine.Job) engine.Status {
  1334. if len(job.Args) == 0 {
  1335. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1336. }
  1337. var (
  1338. protoAddrs = job.Args
  1339. chErrors = make(chan error, len(protoAddrs))
  1340. )
  1341. activationLock = make(chan struct{})
  1342. for _, protoAddr := range protoAddrs {
  1343. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1344. if len(protoAddrParts) != 2 {
  1345. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1346. }
  1347. go func() {
  1348. log.Infof("Listening for HTTP on %s (%s)", protoAddrParts[0], protoAddrParts[1])
  1349. chErrors <- ListenAndServe(protoAddrParts[0], protoAddrParts[1], job)
  1350. }()
  1351. }
  1352. for i := 0; i < len(protoAddrs); i++ {
  1353. err := <-chErrors
  1354. if err != nil {
  1355. return job.Error(err)
  1356. }
  1357. }
  1358. return engine.StatusOK
  1359. }
  1360. func AcceptConnections(job *engine.Job) engine.Status {
  1361. // Tell the init daemon we are accepting requests
  1362. go systemd.SdNotify("READY=1")
  1363. // close the lock so the listeners start accepting connections
  1364. if activationLock != nil {
  1365. close(activationLock)
  1366. }
  1367. return engine.StatusOK
  1368. }