image_list.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519
  1. package containerd
  2. import (
  3. "context"
  4. "encoding/json"
  5. "sort"
  6. "strings"
  7. "time"
  8. "github.com/containerd/containerd/content"
  9. cerrdefs "github.com/containerd/containerd/errdefs"
  10. "github.com/containerd/containerd/images"
  11. "github.com/containerd/containerd/labels"
  12. "github.com/containerd/containerd/log"
  13. "github.com/containerd/containerd/snapshots"
  14. "github.com/docker/distribution/reference"
  15. "github.com/docker/docker/api/types"
  16. "github.com/docker/docker/api/types/filters"
  17. "github.com/docker/docker/api/types/image"
  18. timetypes "github.com/docker/docker/api/types/time"
  19. "github.com/docker/docker/errdefs"
  20. "github.com/opencontainers/go-digest"
  21. "github.com/opencontainers/image-spec/identity"
  22. ocispec "github.com/opencontainers/image-spec/specs-go/v1"
  23. "github.com/pkg/errors"
  24. "github.com/sirupsen/logrus"
  25. )
  26. // Subset of ocispec.Image that only contains Labels
  27. type configLabels struct {
  28. Config struct {
  29. Labels map[string]string `json:"Labels,omitempty"`
  30. } `json:"config,omitempty"`
  31. }
  32. var acceptedImageFilterTags = map[string]bool{
  33. "dangling": true,
  34. "label": true,
  35. "label!": true,
  36. "before": true,
  37. "since": true,
  38. "reference": true,
  39. "until": true,
  40. }
  41. // byCreated is a temporary type used to sort a list of images by creation
  42. // time.
  43. type byCreated []*types.ImageSummary
  44. func (r byCreated) Len() int { return len(r) }
  45. func (r byCreated) Swap(i, j int) { r[i], r[j] = r[j], r[i] }
  46. func (r byCreated) Less(i, j int) bool { return r[i].Created < r[j].Created }
  47. // Images returns a filtered list of images.
  48. //
  49. // TODO(thaJeztah): implement opts.ContainerCount (used for docker system df); see https://github.com/moby/moby/issues/43853
  50. // TODO(thaJeztah): verify behavior of `RepoDigests` and `RepoTags` for images without (untagged) or multiple tags; see https://github.com/moby/moby/issues/43861
  51. // TODO(thaJeztah): verify "Size" vs "VirtualSize" in images; see https://github.com/moby/moby/issues/43862
  52. func (i *ImageService) Images(ctx context.Context, opts types.ImageListOptions) ([]*types.ImageSummary, error) {
  53. if err := opts.Filters.Validate(acceptedImageFilterTags); err != nil {
  54. return nil, err
  55. }
  56. filter, err := i.setupFilters(ctx, opts.Filters)
  57. if err != nil {
  58. return nil, err
  59. }
  60. imgs, err := i.client.ImageService().List(ctx)
  61. if err != nil {
  62. return nil, err
  63. }
  64. // TODO(thaJeztah): do we need to take multiple snapshotters into account? See https://github.com/moby/moby/issues/45273
  65. snapshotter := i.client.SnapshotService(i.snapshotter)
  66. sizeCache := make(map[digest.Digest]int64)
  67. snapshotSizeFn := func(d digest.Digest) (int64, error) {
  68. if s, ok := sizeCache[d]; ok {
  69. return s, nil
  70. }
  71. usage, err := snapshotter.Usage(ctx, d.String())
  72. if err != nil {
  73. return 0, err
  74. }
  75. sizeCache[d] = usage.Size
  76. return usage.Size, nil
  77. }
  78. var (
  79. summaries = make([]*types.ImageSummary, 0, len(imgs))
  80. root []*[]digest.Digest
  81. layers map[digest.Digest]int
  82. )
  83. if opts.SharedSize {
  84. root = make([]*[]digest.Digest, 0, len(imgs))
  85. layers = make(map[digest.Digest]int)
  86. }
  87. contentStore := i.client.ContentStore()
  88. uniqueImages := map[digest.Digest]images.Image{}
  89. tagsByDigest := map[digest.Digest][]string{}
  90. for _, img := range imgs {
  91. if !filter(img) {
  92. continue
  93. }
  94. dgst := img.Target.Digest
  95. uniqueImages[dgst] = img
  96. if isDanglingImage(img) {
  97. continue
  98. }
  99. ref, err := reference.ParseNormalizedNamed(img.Name)
  100. if err != nil {
  101. continue
  102. }
  103. tagsByDigest[dgst] = append(tagsByDigest[dgst], reference.FamiliarString(ref))
  104. }
  105. for _, img := range uniqueImages {
  106. err := i.walkImageManifests(ctx, img, func(img *ImageManifest) error {
  107. if isPseudo, err := img.IsPseudoImage(ctx); isPseudo || err != nil {
  108. return err
  109. }
  110. available, err := img.CheckContentAvailable(ctx)
  111. if err != nil {
  112. log.G(ctx).WithFields(logrus.Fields{
  113. logrus.ErrorKey: err,
  114. "manifest": img.Target(),
  115. "image": img.Name(),
  116. }).Warn("checking availability of platform specific manifest failed")
  117. return nil
  118. }
  119. if !available {
  120. return nil
  121. }
  122. image, chainIDs, err := i.singlePlatformImage(ctx, contentStore, tagsByDigest[img.RealTarget.Digest], img)
  123. if err != nil {
  124. return err
  125. }
  126. summaries = append(summaries, image)
  127. if opts.SharedSize {
  128. root = append(root, &chainIDs)
  129. for _, id := range chainIDs {
  130. layers[id] = layers[id] + 1
  131. }
  132. }
  133. return nil
  134. })
  135. if err != nil {
  136. return nil, err
  137. }
  138. }
  139. if opts.SharedSize {
  140. for n, chainIDs := range root {
  141. sharedSize, err := computeSharedSize(*chainIDs, layers, snapshotSizeFn)
  142. if err != nil {
  143. return nil, err
  144. }
  145. summaries[n].SharedSize = sharedSize
  146. }
  147. }
  148. sort.Sort(sort.Reverse(byCreated(summaries)))
  149. return summaries, nil
  150. }
  151. func (i *ImageService) singlePlatformImage(ctx context.Context, contentStore content.Store, repoTags []string, image *ImageManifest) (*types.ImageSummary, []digest.Digest, error) {
  152. diffIDs, err := image.RootFS(ctx)
  153. if err != nil {
  154. return nil, nil, errors.Wrapf(err, "failed to get rootfs of image %s", image.Name())
  155. }
  156. // TODO(thaJeztah): do we need to take multiple snapshotters into account? See https://github.com/moby/moby/issues/45273
  157. snapshotter := i.client.SnapshotService(i.snapshotter)
  158. imageSnapshotID := identity.ChainID(diffIDs).String()
  159. unpackedUsage, err := calculateSnapshotTotalUsage(ctx, snapshotter, imageSnapshotID)
  160. if err != nil {
  161. if !cerrdefs.IsNotFound(err) {
  162. log.G(ctx).WithError(err).WithFields(logrus.Fields{
  163. "image": image.Name(),
  164. "snapshotID": imageSnapshotID,
  165. }).Warn("failed to calculate unpacked size of image")
  166. }
  167. unpackedUsage = snapshots.Usage{Size: 0}
  168. }
  169. contentSize, err := image.Size(ctx)
  170. if err != nil {
  171. return nil, nil, err
  172. }
  173. // totalSize is the size of the image's packed layers and snapshots
  174. // (unpacked layers) combined.
  175. totalSize := contentSize + unpackedUsage.Size
  176. var repoDigests []string
  177. rawImg := image.Metadata()
  178. target := rawImg.Target.Digest
  179. logger := log.G(ctx).WithFields(logrus.Fields{
  180. "name": rawImg.Name,
  181. "digest": target,
  182. })
  183. ref, err := reference.ParseNamed(rawImg.Name)
  184. if err != nil {
  185. // If the image has unexpected name format (not a Named reference or a dangling image)
  186. // add the offending name to RepoTags but also log an error to make it clear to the
  187. // administrator that this is unexpected.
  188. // TODO: Reconsider when containerd is more strict on image names, see:
  189. // https://github.com/containerd/containerd/issues/7986
  190. if !isDanglingImage(rawImg) {
  191. logger.WithError(err).Error("failed to parse image name as reference")
  192. repoTags = append(repoTags, rawImg.Name)
  193. }
  194. } else {
  195. digested, err := reference.WithDigest(reference.TrimNamed(ref), target)
  196. if err != nil {
  197. logger.WithError(err).Error("failed to create digested reference")
  198. } else {
  199. repoDigests = append(repoDigests, digested.String())
  200. }
  201. }
  202. cfgDesc, err := image.Image.Config(ctx)
  203. if err != nil {
  204. return nil, nil, err
  205. }
  206. var cfg configLabels
  207. if err := readConfig(ctx, contentStore, cfgDesc, &cfg); err != nil {
  208. return nil, nil, err
  209. }
  210. summary := &types.ImageSummary{
  211. ParentID: "",
  212. ID: target.String(),
  213. Created: rawImg.CreatedAt.Unix(),
  214. RepoDigests: repoDigests,
  215. RepoTags: repoTags,
  216. Size: totalSize,
  217. Labels: cfg.Config.Labels,
  218. // -1 indicates that the value has not been set (avoids ambiguity
  219. // between 0 (default) and "not set". We cannot use a pointer (nil)
  220. // for this, as the JSON representation uses "omitempty", which would
  221. // consider both "0" and "nil" to be "empty".
  222. SharedSize: -1,
  223. Containers: -1,
  224. }
  225. return summary, identity.ChainIDs(diffIDs), nil
  226. }
  227. type imageFilterFunc func(image images.Image) bool
  228. // setupFilters constructs an imageFilterFunc from the given imageFilters.
  229. //
  230. // filterFunc is a function that checks whether given image matches the filters.
  231. // TODO(thaJeztah): reimplement filters using containerd filters if possible: see https://github.com/moby/moby/issues/43845
  232. func (i *ImageService) setupFilters(ctx context.Context, imageFilters filters.Args) (filterFunc imageFilterFunc, outErr error) {
  233. var fltrs []imageFilterFunc
  234. err := imageFilters.WalkValues("before", func(value string) error {
  235. img, err := i.GetImage(ctx, value, image.GetImageOpts{})
  236. if err != nil {
  237. return err
  238. }
  239. if img != nil && img.Created != nil {
  240. fltrs = append(fltrs, func(candidate images.Image) bool {
  241. cand, err := i.GetImage(ctx, candidate.Name, image.GetImageOpts{})
  242. if err != nil {
  243. return false
  244. }
  245. return cand.Created != nil && cand.Created.Before(*img.Created)
  246. })
  247. }
  248. return nil
  249. })
  250. if err != nil {
  251. return nil, err
  252. }
  253. err = imageFilters.WalkValues("since", func(value string) error {
  254. img, err := i.GetImage(ctx, value, image.GetImageOpts{})
  255. if err != nil {
  256. return err
  257. }
  258. if img != nil && img.Created != nil {
  259. fltrs = append(fltrs, func(candidate images.Image) bool {
  260. cand, err := i.GetImage(ctx, candidate.Name, image.GetImageOpts{})
  261. if err != nil {
  262. return false
  263. }
  264. return cand.Created != nil && cand.Created.After(*img.Created)
  265. })
  266. }
  267. return nil
  268. })
  269. if err != nil {
  270. return nil, err
  271. }
  272. err = imageFilters.WalkValues("until", func(value string) error {
  273. ts, err := timetypes.GetTimestamp(value, time.Now())
  274. if err != nil {
  275. return err
  276. }
  277. seconds, nanoseconds, err := timetypes.ParseTimestamps(ts, 0)
  278. if err != nil {
  279. return err
  280. }
  281. until := time.Unix(seconds, nanoseconds)
  282. fltrs = append(fltrs, func(image images.Image) bool {
  283. created := image.CreatedAt
  284. return created.Before(until)
  285. })
  286. return err
  287. })
  288. if err != nil {
  289. return nil, err
  290. }
  291. labelFn, err := setupLabelFilter(i.client.ContentStore(), imageFilters)
  292. if err != nil {
  293. return nil, err
  294. }
  295. if labelFn != nil {
  296. fltrs = append(fltrs, labelFn)
  297. }
  298. if imageFilters.Contains("dangling") {
  299. danglingValue, err := imageFilters.GetBoolOrDefault("dangling", false)
  300. if err != nil {
  301. return nil, err
  302. }
  303. fltrs = append(fltrs, func(image images.Image) bool {
  304. return danglingValue == isDanglingImage(image)
  305. })
  306. }
  307. if refs := imageFilters.Get("reference"); len(refs) != 0 {
  308. fltrs = append(fltrs, func(image images.Image) bool {
  309. ref, err := reference.ParseNormalizedNamed(image.Name)
  310. if err != nil {
  311. return false
  312. }
  313. for _, value := range refs {
  314. found, err := reference.FamiliarMatch(value, ref)
  315. if err != nil {
  316. return false
  317. }
  318. if found {
  319. return found
  320. }
  321. }
  322. return false
  323. })
  324. }
  325. return func(image images.Image) bool {
  326. for _, filter := range fltrs {
  327. if !filter(image) {
  328. return false
  329. }
  330. }
  331. return true
  332. }, nil
  333. }
  334. // setupLabelFilter parses filter args for "label" and "label!" and returns a
  335. // filter func which will check if any image config from the given image has
  336. // labels that match given predicates.
  337. func setupLabelFilter(store content.Store, fltrs filters.Args) (func(image images.Image) bool, error) {
  338. type labelCheck struct {
  339. key string
  340. value string
  341. onlyExists bool
  342. negate bool
  343. }
  344. var checks []labelCheck
  345. for _, fltrName := range []string{"label", "label!"} {
  346. for _, l := range fltrs.Get(fltrName) {
  347. k, v, found := strings.Cut(l, "=")
  348. err := labels.Validate(k, v)
  349. if err != nil {
  350. return nil, err
  351. }
  352. negate := strings.HasSuffix(fltrName, "!")
  353. // If filter value is key!=value then flip the above.
  354. if strings.HasSuffix(k, "!") {
  355. k = strings.TrimSuffix(k, "!")
  356. negate = !negate
  357. }
  358. checks = append(checks, labelCheck{
  359. key: k,
  360. value: v,
  361. onlyExists: !found,
  362. negate: negate,
  363. })
  364. }
  365. }
  366. return func(image images.Image) bool {
  367. ctx := context.TODO()
  368. // This is not an error, but a signal to Dispatch that it should stop
  369. // processing more content (otherwise it will run for all children).
  370. // It will be returned once a matching config is found.
  371. errFoundConfig := errors.New("success, found matching config")
  372. err := images.Dispatch(ctx, presentChildrenHandler(store, images.HandlerFunc(func(ctx context.Context, desc ocispec.Descriptor) (subdescs []ocispec.Descriptor, err error) {
  373. if !images.IsConfigType(desc.MediaType) {
  374. return nil, nil
  375. }
  376. var cfg configLabels
  377. if err := readConfig(ctx, store, desc, &cfg); err != nil {
  378. return nil, err
  379. }
  380. for _, check := range checks {
  381. value, exists := cfg.Config.Labels[check.key]
  382. if check.onlyExists {
  383. // label! given without value, check if doesn't exist
  384. if check.negate {
  385. // Label exists, config doesn't match
  386. if exists {
  387. return nil, nil
  388. }
  389. } else {
  390. // Label should exist
  391. if !exists {
  392. // Label doesn't exist, config doesn't match
  393. return nil, nil
  394. }
  395. }
  396. continue
  397. } else if !exists {
  398. // We are checking value and label doesn't exist.
  399. return nil, nil
  400. }
  401. valueEquals := value == check.value
  402. if valueEquals == check.negate {
  403. return nil, nil
  404. }
  405. }
  406. // This config matches the filter so we need to shop this image, stop dispatch.
  407. return nil, errFoundConfig
  408. })), nil, image.Target)
  409. if err == errFoundConfig {
  410. return true
  411. }
  412. if err != nil {
  413. log.G(ctx).WithFields(logrus.Fields{
  414. logrus.ErrorKey: err,
  415. "image": image.Name,
  416. "checks": checks,
  417. }).Error("failed to check image labels")
  418. }
  419. return false
  420. }, nil
  421. }
  422. func computeSharedSize(chainIDs []digest.Digest, layers map[digest.Digest]int, sizeFn func(d digest.Digest) (int64, error)) (int64, error) {
  423. var sharedSize int64
  424. for _, chainID := range chainIDs {
  425. if layers[chainID] == 1 {
  426. continue
  427. }
  428. size, err := sizeFn(chainID)
  429. if err != nil {
  430. return 0, err
  431. }
  432. sharedSize += size
  433. }
  434. return sharedSize, nil
  435. }
  436. // readConfig reads content pointed by the descriptor and unmarshals it into a specified output.
  437. func readConfig(ctx context.Context, store content.Provider, desc ocispec.Descriptor, out interface{}) error {
  438. data, err := content.ReadBlob(ctx, store, desc)
  439. if err != nil {
  440. err = errors.Wrapf(err, "failed to read config content")
  441. if cerrdefs.IsNotFound(err) {
  442. return errdefs.NotFound(err)
  443. }
  444. return err
  445. }
  446. err = json.Unmarshal(data, out)
  447. if err != nil {
  448. err = errors.Wrapf(err, "could not deserialize image config")
  449. if cerrdefs.IsNotFound(err) {
  450. return errdefs.NotFound(err)
  451. }
  452. return err
  453. }
  454. return nil
  455. }