image_import.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404
  1. package containerd
  2. import (
  3. "bufio"
  4. "bytes"
  5. "context"
  6. "encoding/json"
  7. "io"
  8. "time"
  9. "github.com/containerd/containerd"
  10. "github.com/containerd/containerd/content"
  11. cerrdefs "github.com/containerd/containerd/errdefs"
  12. "github.com/containerd/containerd/images"
  13. "github.com/containerd/containerd/log"
  14. "github.com/containerd/containerd/platforms"
  15. "github.com/docker/distribution/reference"
  16. "github.com/docker/docker/api/types/container"
  17. "github.com/docker/docker/builder/dockerfile"
  18. "github.com/docker/docker/errdefs"
  19. "github.com/docker/docker/image"
  20. "github.com/docker/docker/pkg/archive"
  21. "github.com/docker/docker/pkg/pools"
  22. "github.com/google/uuid"
  23. "github.com/opencontainers/go-digest"
  24. "github.com/opencontainers/image-spec/specs-go"
  25. ocispec "github.com/opencontainers/image-spec/specs-go/v1"
  26. "github.com/pkg/errors"
  27. "github.com/sirupsen/logrus"
  28. )
  29. // ImportImage imports an image, getting the archived layer data from layerReader.
  30. // Layer archive is imported as-is if the compression is gzip or zstd.
  31. // Uncompressed, xz and bzip2 archives are recompressed into gzip.
  32. // The image is tagged with the given reference.
  33. // If the platform is nil, the default host platform is used.
  34. // The message is used as the history comment.
  35. // Image configuration is derived from the dockerfile instructions in changes.
  36. func (i *ImageService) ImportImage(ctx context.Context, ref reference.Named, platform *ocispec.Platform, msg string, layerReader io.Reader, changes []string) (image.ID, error) {
  37. refString := ""
  38. if ref != nil {
  39. refString = ref.String()
  40. }
  41. logger := log.G(ctx).WithField("ref", refString)
  42. ctx, release, err := i.client.WithLease(ctx)
  43. if err != nil {
  44. return "", errdefs.System(err)
  45. }
  46. defer release(ctx)
  47. if platform == nil {
  48. def := platforms.DefaultSpec()
  49. platform = &def
  50. }
  51. imageConfig, err := dockerfile.BuildFromConfig(ctx, &container.Config{}, changes, platform.OS)
  52. if err != nil {
  53. logger.WithError(err).Debug("failed to process changes")
  54. return "", errdefs.InvalidParameter(err)
  55. }
  56. cs := i.client.ContentStore()
  57. compressedDigest, uncompressedDigest, mt, err := saveArchive(ctx, cs, layerReader)
  58. if err != nil {
  59. logger.WithError(err).Debug("failed to write layer blob")
  60. return "", err
  61. }
  62. logger = logger.WithFields(logrus.Fields{
  63. "compressedDigest": compressedDigest,
  64. "uncompressedDigest": uncompressedDigest,
  65. })
  66. size, err := fillUncompressedLabel(ctx, cs, compressedDigest, uncompressedDigest)
  67. if err != nil {
  68. logger.WithError(err).Debug("failed to set uncompressed label on the compressed blob")
  69. return "", err
  70. }
  71. compressedRootfsDesc := ocispec.Descriptor{
  72. MediaType: mt,
  73. Digest: compressedDigest,
  74. Size: size,
  75. }
  76. ociCfg := containerConfigToOciImageConfig(imageConfig)
  77. createdAt := time.Now()
  78. config := ocispec.Image{
  79. Platform: *platform,
  80. Created: &createdAt,
  81. Author: "",
  82. Config: ociCfg,
  83. RootFS: ocispec.RootFS{
  84. Type: "layers",
  85. DiffIDs: []digest.Digest{uncompressedDigest},
  86. },
  87. History: []ocispec.History{
  88. {
  89. Created: &createdAt,
  90. CreatedBy: "",
  91. Author: "",
  92. Comment: msg,
  93. EmptyLayer: false,
  94. },
  95. },
  96. }
  97. configDesc, err := storeJson(ctx, cs, ocispec.MediaTypeImageConfig, config, nil)
  98. if err != nil {
  99. return "", err
  100. }
  101. manifest := ocispec.Manifest{
  102. MediaType: ocispec.MediaTypeImageManifest,
  103. Versioned: specs.Versioned{
  104. SchemaVersion: 2,
  105. },
  106. Config: configDesc,
  107. Layers: []ocispec.Descriptor{
  108. compressedRootfsDesc,
  109. },
  110. }
  111. manifestDesc, err := storeJson(ctx, cs, ocispec.MediaTypeImageManifest, manifest, map[string]string{
  112. "containerd.io/gc.ref.content.config": configDesc.Digest.String(),
  113. "containerd.io/gc.ref.content.l.0": compressedDigest.String(),
  114. })
  115. if err != nil {
  116. return "", err
  117. }
  118. id := image.ID(manifestDesc.Digest.String())
  119. img := images.Image{
  120. Name: refString,
  121. Target: manifestDesc,
  122. CreatedAt: createdAt,
  123. }
  124. if img.Name == "" {
  125. img.Name = danglingImageName(manifestDesc.Digest)
  126. }
  127. err = i.saveImage(ctx, img)
  128. if err != nil {
  129. logger.WithError(err).Debug("failed to save image")
  130. return "", err
  131. }
  132. err = i.unpackImage(ctx, img, *platform)
  133. if err != nil {
  134. logger.WithError(err).Debug("failed to unpack image")
  135. } else {
  136. i.LogImageEvent(id.String(), id.String(), "import")
  137. }
  138. return id, err
  139. }
  140. // saveArchive saves the archive from bufRd to the content store, compressing it if necessary.
  141. // Returns compressed blob digest, digest of the uncompressed data and media type of the stored blob.
  142. func saveArchive(ctx context.Context, cs content.Store, layerReader io.Reader) (digest.Digest, digest.Digest, string, error) {
  143. // Wrap the reader in buffered reader to allow peeks.
  144. p := pools.BufioReader32KPool
  145. bufRd := p.Get(layerReader)
  146. defer p.Put(bufRd)
  147. compression, err := detectCompression(bufRd)
  148. if err != nil {
  149. return "", "", "", err
  150. }
  151. var uncompressedReader io.Reader = bufRd
  152. switch compression {
  153. case archive.Gzip, archive.Zstd:
  154. // If the input is already a compressed layer, just save it as is.
  155. mediaType := ocispec.MediaTypeImageLayerGzip
  156. if compression == archive.Zstd {
  157. mediaType = ocispec.MediaTypeImageLayerZstd
  158. }
  159. compressedDigest, uncompressedDigest, err := writeCompressedBlob(ctx, cs, mediaType, bufRd)
  160. if err != nil {
  161. return "", "", "", err
  162. }
  163. return compressedDigest, uncompressedDigest, mediaType, nil
  164. case archive.Bzip2, archive.Xz:
  165. r, err := archive.DecompressStream(bufRd)
  166. if err != nil {
  167. return "", "", "", errdefs.InvalidParameter(err)
  168. }
  169. defer r.Close()
  170. uncompressedReader = r
  171. fallthrough
  172. case archive.Uncompressed:
  173. mediaType := ocispec.MediaTypeImageLayerGzip
  174. compression := archive.Gzip
  175. compressedDigest, uncompressedDigest, err := compressAndWriteBlob(ctx, cs, compression, mediaType, uncompressedReader)
  176. if err != nil {
  177. return "", "", "", err
  178. }
  179. return compressedDigest, uncompressedDigest, mediaType, nil
  180. }
  181. return "", "", "", errdefs.InvalidParameter(errors.New("unsupported archive compression"))
  182. }
  183. // writeCompressedBlob writes the blob and simultaneously computes the digest of the uncompressed data.
  184. func writeCompressedBlob(ctx context.Context, cs content.Store, mediaType string, bufRd *bufio.Reader) (digest.Digest, digest.Digest, error) {
  185. pr, pw := io.Pipe()
  186. defer pw.Close()
  187. defer pr.Close()
  188. c := make(chan digest.Digest)
  189. // Start copying the blob to the content store from the pipe and tee it to the pipe.
  190. go func() {
  191. compressedDigest, err := writeBlobAndReturnDigest(ctx, cs, mediaType, io.TeeReader(bufRd, pw))
  192. pw.CloseWithError(err)
  193. c <- compressedDigest
  194. }()
  195. digester := digest.Canonical.Digester()
  196. // Decompress the piped blob.
  197. decompressedStream, err := archive.DecompressStream(pr)
  198. if err == nil {
  199. // Feed the digester with decompressed data.
  200. _, err = io.Copy(digester.Hash(), decompressedStream)
  201. decompressedStream.Close()
  202. }
  203. pr.CloseWithError(err)
  204. compressedDigest := <-c
  205. if err != nil {
  206. if errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) {
  207. return "", "", errdefs.Cancelled(err)
  208. }
  209. return "", "", errdefs.System(err)
  210. }
  211. uncompressedDigest := digester.Digest()
  212. return compressedDigest, uncompressedDigest, nil
  213. }
  214. // compressAndWriteBlob compresses the uncompressedReader and stores it in the content store.
  215. func compressAndWriteBlob(ctx context.Context, cs content.Store, compression archive.Compression, mediaType string, uncompressedLayerReader io.Reader) (digest.Digest, digest.Digest, error) {
  216. pr, pw := io.Pipe()
  217. defer pr.Close()
  218. defer pw.Close()
  219. compressor, err := archive.CompressStream(pw, compression)
  220. if err != nil {
  221. return "", "", errdefs.InvalidParameter(err)
  222. }
  223. defer compressor.Close()
  224. writeChan := make(chan digest.Digest)
  225. // Start copying the blob to the content store from the pipe.
  226. go func() {
  227. digest, err := writeBlobAndReturnDigest(ctx, cs, mediaType, pr)
  228. pr.CloseWithError(err)
  229. writeChan <- digest
  230. }()
  231. // Copy archive to the pipe and tee it to a digester.
  232. // This will feed the pipe the above goroutine is reading from.
  233. uncompressedDigester := digest.Canonical.Digester()
  234. readFromInputAndDigest := io.TeeReader(uncompressedLayerReader, uncompressedDigester.Hash())
  235. _, err = io.Copy(compressor, readFromInputAndDigest)
  236. compressor.Close()
  237. pw.CloseWithError(err)
  238. compressedDigest := <-writeChan
  239. if err != nil {
  240. if errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) {
  241. return "", "", errdefs.Cancelled(err)
  242. }
  243. return "", "", errdefs.System(err)
  244. }
  245. return compressedDigest, uncompressedDigester.Digest(), err
  246. }
  247. // writeBlobAndReturnDigest writes a blob to the content store and returns the digest.
  248. func writeBlobAndReturnDigest(ctx context.Context, cs content.Store, mt string, reader io.Reader) (digest.Digest, error) {
  249. digester := digest.Canonical.Digester()
  250. if err := content.WriteBlob(ctx, cs, uuid.New().String(), io.TeeReader(reader, digester.Hash()), ocispec.Descriptor{MediaType: mt}); err != nil {
  251. return "", errdefs.System(err)
  252. }
  253. return digester.Digest(), nil
  254. }
  255. // saveImage creates an image in the ImageService or updates it if it exists.
  256. func (i *ImageService) saveImage(ctx context.Context, img images.Image) error {
  257. is := i.client.ImageService()
  258. if _, err := is.Update(ctx, img); err != nil {
  259. if cerrdefs.IsNotFound(err) {
  260. if _, err := is.Create(ctx, img); err != nil {
  261. return errdefs.Unknown(err)
  262. }
  263. } else {
  264. return errdefs.Unknown(err)
  265. }
  266. }
  267. return nil
  268. }
  269. // unpackImage unpacks the image into the snapshotter.
  270. func (i *ImageService) unpackImage(ctx context.Context, img images.Image, platform ocispec.Platform) error {
  271. c8dImg := containerd.NewImageWithPlatform(i.client, img, platforms.Only(platform))
  272. unpacked, err := c8dImg.IsUnpacked(ctx, i.snapshotter)
  273. if err != nil {
  274. return err
  275. }
  276. if !unpacked {
  277. err = c8dImg.Unpack(ctx, i.snapshotter)
  278. }
  279. return err
  280. }
  281. // detectCompression dectects the reader compression type.
  282. func detectCompression(bufRd *bufio.Reader) (archive.Compression, error) {
  283. bs, err := bufRd.Peek(10)
  284. if err != nil && err != io.EOF {
  285. // Note: we'll ignore any io.EOF error because there are some odd
  286. // cases where the layer.tar file will be empty (zero bytes) and
  287. // that results in an io.EOF from the Peek() call. So, in those
  288. // cases we'll just treat it as a non-compressed stream and
  289. // that means just create an empty layer.
  290. // See Issue 18170
  291. return archive.Uncompressed, errdefs.Unknown(err)
  292. }
  293. return archive.DetectCompression(bs), nil
  294. }
  295. // fillUncompressedLabel sets the uncompressed digest label on the compressed blob metadata
  296. // and returns the compressed blob size.
  297. func fillUncompressedLabel(ctx context.Context, cs content.Store, compressedDigest digest.Digest, uncompressedDigest digest.Digest) (int64, error) {
  298. info, err := cs.Info(ctx, compressedDigest)
  299. if err != nil {
  300. return 0, errdefs.Unknown(errors.Wrapf(err, "couldn't open previously written blob"))
  301. }
  302. size := info.Size
  303. info.Labels = map[string]string{"containerd.io/uncompressed": uncompressedDigest.String()}
  304. _, err = cs.Update(ctx, info, "labels.*")
  305. if err != nil {
  306. return 0, errdefs.System(errors.Wrapf(err, "couldn't set uncompressed label"))
  307. }
  308. return size, nil
  309. }
  310. // storeJson marshals the provided object as json and stores it.
  311. func storeJson(ctx context.Context, cs content.Ingester, mt string, obj interface{}, labels map[string]string) (ocispec.Descriptor, error) {
  312. configData, err := json.Marshal(obj)
  313. if err != nil {
  314. return ocispec.Descriptor{}, errdefs.InvalidParameter(err)
  315. }
  316. configDigest := digest.FromBytes(configData)
  317. if err != nil {
  318. return ocispec.Descriptor{}, errdefs.InvalidParameter(err)
  319. }
  320. desc := ocispec.Descriptor{
  321. MediaType: mt,
  322. Digest: configDigest,
  323. Size: int64(len(configData)),
  324. }
  325. var opts []content.Opt
  326. if labels != nil {
  327. opts = append(opts, content.WithLabels(labels))
  328. }
  329. err = content.WriteBlob(ctx, cs, configDigest.String(), bytes.NewReader(configData), desc, opts...)
  330. if err != nil {
  331. return ocispec.Descriptor{}, errdefs.System(err)
  332. }
  333. return desc, nil
  334. }
  335. func containerConfigToOciImageConfig(cfg *container.Config) ocispec.ImageConfig {
  336. ociCfg := ocispec.ImageConfig{
  337. User: cfg.User,
  338. Env: cfg.Env,
  339. Entrypoint: cfg.Entrypoint,
  340. Cmd: cfg.Cmd,
  341. Volumes: cfg.Volumes,
  342. WorkingDir: cfg.WorkingDir,
  343. Labels: cfg.Labels,
  344. StopSignal: cfg.StopSignal,
  345. ArgsEscaped: cfg.ArgsEscaped,
  346. }
  347. if len(cfg.ExposedPorts) > 0 {
  348. ociCfg.ExposedPorts = map[string]struct{}{}
  349. for k, v := range cfg.ExposedPorts {
  350. ociCfg.ExposedPorts[string(k)] = v
  351. }
  352. }
  353. return ociCfg
  354. }