docker_cli_build_test.go 93 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723
  1. package main
  2. import (
  3. "archive/tar"
  4. "encoding/json"
  5. "fmt"
  6. "io/ioutil"
  7. "os"
  8. "os/exec"
  9. "path"
  10. "path/filepath"
  11. "reflect"
  12. "regexp"
  13. "strings"
  14. "syscall"
  15. "testing"
  16. "time"
  17. "github.com/docker/docker/pkg/archive"
  18. )
  19. func TestBuildShCmdJSONEntrypoint(t *testing.T) {
  20. name := "testbuildshcmdjsonentrypoint"
  21. defer deleteImages(name)
  22. _, err := buildImage(
  23. name,
  24. `
  25. FROM busybox
  26. ENTRYPOINT ["/bin/echo"]
  27. CMD echo test
  28. `,
  29. true)
  30. if err != nil {
  31. t.Fatal(err)
  32. }
  33. out, _, err := runCommandWithOutput(
  34. exec.Command(
  35. dockerBinary,
  36. "run",
  37. "--rm",
  38. name))
  39. if err != nil {
  40. t.Fatal(err)
  41. }
  42. if strings.TrimSpace(out) != "/bin/sh -c echo test" {
  43. t.Fatal("CMD did not contain /bin/sh -c")
  44. }
  45. logDone("build - CMD should always contain /bin/sh -c when specified without JSON")
  46. }
  47. func TestBuildEnvironmentReplacementUser(t *testing.T) {
  48. name := "testbuildenvironmentreplacement"
  49. defer deleteImages(name)
  50. _, err := buildImage(name, `
  51. FROM scratch
  52. ENV user foo
  53. USER ${user}
  54. `, true)
  55. if err != nil {
  56. t.Fatal(err)
  57. }
  58. res, err := inspectFieldJSON(name, "Config.User")
  59. if err != nil {
  60. t.Fatal(err)
  61. }
  62. if res != `"foo"` {
  63. t.Fatal("User foo from environment not in Config.User on image")
  64. }
  65. logDone("build - user environment replacement")
  66. }
  67. func TestBuildEnvironmentReplacementVolume(t *testing.T) {
  68. name := "testbuildenvironmentreplacement"
  69. defer deleteImages(name)
  70. _, err := buildImage(name, `
  71. FROM scratch
  72. ENV volume /quux
  73. VOLUME ${volume}
  74. `, true)
  75. if err != nil {
  76. t.Fatal(err)
  77. }
  78. res, err := inspectFieldJSON(name, "Config.Volumes")
  79. if err != nil {
  80. t.Fatal(err)
  81. }
  82. var volumes map[string]interface{}
  83. if err := json.Unmarshal([]byte(res), &volumes); err != nil {
  84. t.Fatal(err)
  85. }
  86. if _, ok := volumes["/quux"]; !ok {
  87. t.Fatal("Volume /quux from environment not in Config.Volumes on image")
  88. }
  89. logDone("build - volume environment replacement")
  90. }
  91. func TestBuildEnvironmentReplacementExpose(t *testing.T) {
  92. name := "testbuildenvironmentreplacement"
  93. defer deleteImages(name)
  94. _, err := buildImage(name, `
  95. FROM scratch
  96. ENV port 80
  97. EXPOSE ${port}
  98. `, true)
  99. if err != nil {
  100. t.Fatal(err)
  101. }
  102. res, err := inspectFieldJSON(name, "Config.ExposedPorts")
  103. if err != nil {
  104. t.Fatal(err)
  105. }
  106. var exposedPorts map[string]interface{}
  107. if err := json.Unmarshal([]byte(res), &exposedPorts); err != nil {
  108. t.Fatal(err)
  109. }
  110. if _, ok := exposedPorts["80/tcp"]; !ok {
  111. t.Fatal("Exposed port 80 from environment not in Config.ExposedPorts on image")
  112. }
  113. logDone("build - expose environment replacement")
  114. }
  115. func TestBuildEnvironmentReplacementWorkdir(t *testing.T) {
  116. name := "testbuildenvironmentreplacement"
  117. defer deleteImages(name)
  118. _, err := buildImage(name, `
  119. FROM busybox
  120. ENV MYWORKDIR /work
  121. RUN mkdir ${MYWORKDIR}
  122. WORKDIR ${MYWORKDIR}
  123. `, true)
  124. if err != nil {
  125. t.Fatal(err)
  126. }
  127. logDone("build - workdir environment replacement")
  128. }
  129. func TestBuildEnvironmentReplacementAddCopy(t *testing.T) {
  130. name := "testbuildenvironmentreplacement"
  131. defer deleteImages(name)
  132. ctx, err := fakeContext(`
  133. FROM scratch
  134. ENV baz foo
  135. ENV quux bar
  136. ENV dot .
  137. ADD ${baz} ${dot}
  138. COPY ${quux} ${dot}
  139. `,
  140. map[string]string{
  141. "foo": "test1",
  142. "bar": "test2",
  143. })
  144. if err != nil {
  145. t.Fatal(err)
  146. }
  147. defer ctx.Close()
  148. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  149. t.Fatal(err)
  150. }
  151. logDone("build - add/copy environment replacement")
  152. }
  153. func TestBuildEnvironmentReplacementEnv(t *testing.T) {
  154. name := "testbuildenvironmentreplacement"
  155. defer deleteImages(name)
  156. _, err := buildImage(name,
  157. `
  158. FROM scratch
  159. ENV foo foo
  160. ENV bar ${foo}
  161. `, true)
  162. if err != nil {
  163. t.Fatal(err)
  164. }
  165. res, err := inspectFieldJSON(name, "Config.Env")
  166. if err != nil {
  167. t.Fatal(err)
  168. }
  169. envResult := []string{}
  170. if err = unmarshalJSON([]byte(res), &envResult); err != nil {
  171. t.Fatal(err)
  172. }
  173. found := false
  174. for _, env := range envResult {
  175. parts := strings.SplitN(env, "=", 2)
  176. if parts[0] == "bar" {
  177. found = true
  178. if parts[1] != "foo" {
  179. t.Fatalf("Could not find replaced var for env `bar`: got %q instead of `foo`", parts[1])
  180. }
  181. }
  182. }
  183. if !found {
  184. t.Fatal("Never found the `bar` env variable")
  185. }
  186. logDone("build - env environment replacement")
  187. }
  188. func TestBuildHandleEscapes(t *testing.T) {
  189. name := "testbuildhandleescapes"
  190. defer deleteImages(name)
  191. _, err := buildImage(name,
  192. `
  193. FROM scratch
  194. ENV FOO bar
  195. VOLUME ${FOO}
  196. `, true)
  197. if err != nil {
  198. t.Fatal(err)
  199. }
  200. var result map[string]map[string]struct{}
  201. res, err := inspectFieldJSON(name, "Config.Volumes")
  202. if err != nil {
  203. t.Fatal(err)
  204. }
  205. if err = unmarshalJSON([]byte(res), &result); err != nil {
  206. t.Fatal(err)
  207. }
  208. if _, ok := result["bar"]; !ok {
  209. t.Fatal("Could not find volume bar set from env foo in volumes table")
  210. }
  211. deleteImages(name)
  212. _, err = buildImage(name,
  213. `
  214. FROM scratch
  215. ENV FOO bar
  216. VOLUME \${FOO}
  217. `, true)
  218. if err != nil {
  219. t.Fatal(err)
  220. }
  221. res, err = inspectFieldJSON(name, "Config.Volumes")
  222. if err != nil {
  223. t.Fatal(err)
  224. }
  225. if err = unmarshalJSON([]byte(res), &result); err != nil {
  226. t.Fatal(err)
  227. }
  228. if _, ok := result["${FOO}"]; !ok {
  229. t.Fatal("Could not find volume ${FOO} set from env foo in volumes table")
  230. }
  231. deleteImages(name)
  232. // this test in particular provides *7* backslashes and expects 6 to come back.
  233. // Like above, the first escape is swallowed and the rest are treated as
  234. // literals, this one is just less obvious because of all the character noise.
  235. _, err = buildImage(name,
  236. `
  237. FROM scratch
  238. ENV FOO bar
  239. VOLUME \\\\\\\${FOO}
  240. `, true)
  241. if err != nil {
  242. t.Fatal(err)
  243. }
  244. res, err = inspectFieldJSON(name, "Config.Volumes")
  245. if err != nil {
  246. t.Fatal(err)
  247. }
  248. if err = unmarshalJSON([]byte(res), &result); err != nil {
  249. t.Fatal(err)
  250. }
  251. if _, ok := result[`\\\\\\${FOO}`]; !ok {
  252. t.Fatal(`Could not find volume \\\\\\${FOO} set from env foo in volumes table`)
  253. }
  254. logDone("build - handle escapes")
  255. }
  256. func TestBuildOnBuildLowercase(t *testing.T) {
  257. name := "testbuildonbuildlowercase"
  258. name2 := "testbuildonbuildlowercase2"
  259. defer deleteImages(name, name2)
  260. _, err := buildImage(name,
  261. `
  262. FROM busybox
  263. onbuild run echo quux
  264. `, true)
  265. if err != nil {
  266. t.Fatal(err)
  267. }
  268. _, out, err := buildImageWithOut(name2, fmt.Sprintf(`
  269. FROM %s
  270. `, name), true)
  271. if err != nil {
  272. t.Fatal(err)
  273. }
  274. if !strings.Contains(out, "quux") {
  275. t.Fatalf("Did not receive the expected echo text, got %s", out)
  276. }
  277. if strings.Contains(out, "ONBUILD ONBUILD") {
  278. t.Fatalf("Got an ONBUILD ONBUILD error with no error: got %s", out)
  279. }
  280. logDone("build - handle case-insensitive onbuild statement")
  281. }
  282. func TestBuildEnvEscapes(t *testing.T) {
  283. name := "testbuildenvescapes"
  284. defer deleteImages(name)
  285. defer deleteAllContainers()
  286. _, err := buildImage(name,
  287. `
  288. FROM busybox
  289. ENV TEST foo
  290. CMD echo \$
  291. `,
  292. true)
  293. out, _, err := runCommandWithOutput(exec.Command(dockerBinary, "run", "-t", name))
  294. if err != nil {
  295. t.Fatal(err)
  296. }
  297. if strings.TrimSpace(out) != "$" {
  298. t.Fatalf("Env TEST was not overwritten with bar when foo was supplied to dockerfile: was %q", strings.TrimSpace(out))
  299. }
  300. logDone("build - env should handle \\$ properly")
  301. }
  302. func TestBuildEnvOverwrite(t *testing.T) {
  303. name := "testbuildenvoverwrite"
  304. defer deleteImages(name)
  305. defer deleteAllContainers()
  306. _, err := buildImage(name,
  307. `
  308. FROM busybox
  309. ENV TEST foo
  310. CMD echo ${TEST}
  311. `,
  312. true)
  313. if err != nil {
  314. t.Fatal(err)
  315. }
  316. out, _, err := runCommandWithOutput(exec.Command(dockerBinary, "run", "-e", "TEST=bar", "-t", name))
  317. if err != nil {
  318. t.Fatal(err)
  319. }
  320. if strings.TrimSpace(out) != "bar" {
  321. t.Fatalf("Env TEST was not overwritten with bar when foo was supplied to dockerfile: was %q", strings.TrimSpace(out))
  322. }
  323. logDone("build - env should overwrite builder ENV during run")
  324. }
  325. func TestBuildOnBuildForbiddenMaintainerInSourceImage(t *testing.T) {
  326. name := "testbuildonbuildforbiddenmaintainerinsourceimage"
  327. defer deleteImages("onbuild")
  328. defer deleteImages(name)
  329. defer deleteAllContainers()
  330. createCmd := exec.Command(dockerBinary, "create", "busybox", "true")
  331. out, _, _, err := runCommandWithStdoutStderr(createCmd)
  332. if err != nil {
  333. t.Fatal(out, err)
  334. }
  335. cleanedContainerID := stripTrailingCharacters(out)
  336. commitCmd := exec.Command(dockerBinary, "commit", "--run", "{\"OnBuild\":[\"MAINTAINER docker.io\"]}", cleanedContainerID, "onbuild")
  337. if _, err := runCommand(commitCmd); err != nil {
  338. t.Fatal(err)
  339. }
  340. _, err = buildImage(name,
  341. `FROM onbuild`,
  342. true)
  343. if err != nil {
  344. if !strings.Contains(err.Error(), "maintainer isn't allowed as an ONBUILD trigger") {
  345. t.Fatalf("Wrong error %v, must be about MAINTAINER and ONBUILD in source image", err)
  346. }
  347. } else {
  348. t.Fatal("Error must not be nil")
  349. }
  350. logDone("build - onbuild forbidden maintainer in source image")
  351. }
  352. func TestBuildOnBuildForbiddenFromInSourceImage(t *testing.T) {
  353. name := "testbuildonbuildforbiddenfrominsourceimage"
  354. defer deleteImages("onbuild")
  355. defer deleteImages(name)
  356. defer deleteAllContainers()
  357. createCmd := exec.Command(dockerBinary, "create", "busybox", "true")
  358. out, _, _, err := runCommandWithStdoutStderr(createCmd)
  359. if err != nil {
  360. t.Fatal(out, err)
  361. }
  362. cleanedContainerID := stripTrailingCharacters(out)
  363. commitCmd := exec.Command(dockerBinary, "commit", "--run", "{\"OnBuild\":[\"FROM busybox\"]}", cleanedContainerID, "onbuild")
  364. if _, err := runCommand(commitCmd); err != nil {
  365. t.Fatal(err)
  366. }
  367. _, err = buildImage(name,
  368. `FROM onbuild`,
  369. true)
  370. if err != nil {
  371. if !strings.Contains(err.Error(), "from isn't allowed as an ONBUILD trigger") {
  372. t.Fatalf("Wrong error %v, must be about FROM and ONBUILD in source image", err)
  373. }
  374. } else {
  375. t.Fatal("Error must not be nil")
  376. }
  377. logDone("build - onbuild forbidden from in source image")
  378. }
  379. func TestBuildOnBuildForbiddenChainedInSourceImage(t *testing.T) {
  380. name := "testbuildonbuildforbiddenchainedinsourceimage"
  381. defer deleteImages("onbuild")
  382. defer deleteImages(name)
  383. defer deleteAllContainers()
  384. createCmd := exec.Command(dockerBinary, "create", "busybox", "true")
  385. out, _, _, err := runCommandWithStdoutStderr(createCmd)
  386. if err != nil {
  387. t.Fatal(out, err)
  388. }
  389. cleanedContainerID := stripTrailingCharacters(out)
  390. commitCmd := exec.Command(dockerBinary, "commit", "--run", "{\"OnBuild\":[\"ONBUILD RUN ls\"]}", cleanedContainerID, "onbuild")
  391. if _, err := runCommand(commitCmd); err != nil {
  392. t.Fatal(err)
  393. }
  394. _, err = buildImage(name,
  395. `FROM onbuild`,
  396. true)
  397. if err != nil {
  398. if !strings.Contains(err.Error(), "Chaining ONBUILD via `ONBUILD ONBUILD` isn't allowed") {
  399. t.Fatalf("Wrong error %v, must be about chaining ONBUILD in source image", err)
  400. }
  401. } else {
  402. t.Fatal("Error must not be nil")
  403. }
  404. logDone("build - onbuild forbidden chained in source image")
  405. }
  406. func TestBuildOnBuildCmdEntrypointJSON(t *testing.T) {
  407. name1 := "onbuildcmd"
  408. name2 := "onbuildgenerated"
  409. defer deleteImages(name2)
  410. defer deleteImages(name1)
  411. defer deleteAllContainers()
  412. _, err := buildImage(name1, `
  413. FROM busybox
  414. ONBUILD CMD ["hello world"]
  415. ONBUILD ENTRYPOINT ["echo"]
  416. ONBUILD RUN ["true"]`,
  417. false)
  418. if err != nil {
  419. t.Fatal(err)
  420. }
  421. _, err = buildImage(name2, fmt.Sprintf(`FROM %s`, name1), false)
  422. if err != nil {
  423. t.Fatal(err)
  424. }
  425. out, _, err := runCommandWithOutput(exec.Command(dockerBinary, "run", "-t", name2))
  426. if err != nil {
  427. t.Fatal(err)
  428. }
  429. if !regexp.MustCompile(`(?m)^hello world`).MatchString(out) {
  430. t.Fatal("did not get echo output from onbuild", out)
  431. }
  432. logDone("build - onbuild with json entrypoint/cmd")
  433. }
  434. func TestBuildOnBuildEntrypointJSON(t *testing.T) {
  435. name1 := "onbuildcmd"
  436. name2 := "onbuildgenerated"
  437. defer deleteImages(name2)
  438. defer deleteImages(name1)
  439. defer deleteAllContainers()
  440. _, err := buildImage(name1, `
  441. FROM busybox
  442. ONBUILD ENTRYPOINT ["echo"]`,
  443. false)
  444. if err != nil {
  445. t.Fatal(err)
  446. }
  447. _, err = buildImage(name2, fmt.Sprintf("FROM %s\nCMD [\"hello world\"]\n", name1), false)
  448. if err != nil {
  449. t.Fatal(err)
  450. }
  451. out, _, err := runCommandWithOutput(exec.Command(dockerBinary, "run", "-t", name2))
  452. if err != nil {
  453. t.Fatal(err)
  454. }
  455. if !regexp.MustCompile(`(?m)^hello world`).MatchString(out) {
  456. t.Fatal("got malformed output from onbuild", out)
  457. }
  458. logDone("build - onbuild with json entrypoint")
  459. }
  460. func TestBuildCacheADD(t *testing.T) {
  461. name := "testbuildtwoimageswithadd"
  462. defer deleteImages(name)
  463. server, err := fakeStorage(map[string]string{
  464. "robots.txt": "hello",
  465. "index.html": "world",
  466. })
  467. if err != nil {
  468. t.Fatal(err)
  469. }
  470. defer server.Close()
  471. if _, err := buildImage(name,
  472. fmt.Sprintf(`FROM scratch
  473. ADD %s/robots.txt /`, server.URL),
  474. true); err != nil {
  475. t.Fatal(err)
  476. }
  477. if err != nil {
  478. t.Fatal(err)
  479. }
  480. deleteImages(name)
  481. _, out, err := buildImageWithOut(name,
  482. fmt.Sprintf(`FROM scratch
  483. ADD %s/index.html /`, server.URL),
  484. true)
  485. if err != nil {
  486. t.Fatal(err)
  487. }
  488. if strings.Contains(out, "Using cache") {
  489. t.Fatal("2nd build used cache on ADD, it shouldn't")
  490. }
  491. logDone("build - build two images with remote ADD")
  492. }
  493. func TestBuildSixtySteps(t *testing.T) {
  494. name := "foobuildsixtysteps"
  495. defer deleteImages(name)
  496. ctx, err := fakeContext("FROM scratch\n"+strings.Repeat("ADD foo /\n", 60),
  497. map[string]string{
  498. "foo": "test1",
  499. })
  500. if err != nil {
  501. t.Fatal(err)
  502. }
  503. defer ctx.Close()
  504. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  505. t.Fatal(err)
  506. }
  507. logDone("build - build an image with sixty build steps")
  508. }
  509. func TestBuildAddSingleFileToRoot(t *testing.T) {
  510. name := "testaddimg"
  511. defer deleteImages(name)
  512. ctx, err := fakeContext(`FROM busybox
  513. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  514. RUN echo 'dockerio:x:1001:' >> /etc/group
  515. RUN touch /exists
  516. RUN chown dockerio.dockerio /exists
  517. ADD test_file /
  518. RUN [ $(ls -l /test_file | awk '{print $3":"$4}') = 'root:root' ]
  519. RUN [ $(ls -l /test_file | awk '{print $1}') = '-rw-r--r--' ]
  520. RUN [ $(ls -l /exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]`,
  521. map[string]string{
  522. "test_file": "test1",
  523. })
  524. if err != nil {
  525. t.Fatal(err)
  526. }
  527. defer ctx.Close()
  528. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  529. t.Fatal(err)
  530. }
  531. logDone("build - add single file to root")
  532. }
  533. // Issue #3960: "ADD src ." hangs
  534. func TestBuildAddSingleFileToWorkdir(t *testing.T) {
  535. name := "testaddsinglefiletoworkdir"
  536. defer deleteImages(name)
  537. ctx, err := fakeContext(`FROM busybox
  538. ADD test_file .`,
  539. map[string]string{
  540. "test_file": "test1",
  541. })
  542. if err != nil {
  543. t.Fatal(err)
  544. }
  545. defer ctx.Close()
  546. done := make(chan struct{})
  547. go func() {
  548. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  549. t.Fatal(err)
  550. }
  551. close(done)
  552. }()
  553. select {
  554. case <-time.After(5 * time.Second):
  555. t.Fatal("Build with adding to workdir timed out")
  556. case <-done:
  557. }
  558. logDone("build - add single file to workdir")
  559. }
  560. func TestBuildAddSingleFileToExistDir(t *testing.T) {
  561. name := "testaddsinglefiletoexistdir"
  562. defer deleteImages(name)
  563. ctx, err := fakeContext(`FROM busybox
  564. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  565. RUN echo 'dockerio:x:1001:' >> /etc/group
  566. RUN mkdir /exists
  567. RUN touch /exists/exists_file
  568. RUN chown -R dockerio.dockerio /exists
  569. ADD test_file /exists/
  570. RUN [ $(ls -l / | grep exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]
  571. RUN [ $(ls -l /exists/test_file | awk '{print $3":"$4}') = 'root:root' ]
  572. RUN [ $(ls -l /exists/exists_file | awk '{print $3":"$4}') = 'dockerio:dockerio' ]`,
  573. map[string]string{
  574. "test_file": "test1",
  575. })
  576. if err != nil {
  577. t.Fatal(err)
  578. }
  579. defer ctx.Close()
  580. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  581. t.Fatal(err)
  582. }
  583. logDone("build - add single file to existing dir")
  584. }
  585. func TestBuildCopyAddMultipleFiles(t *testing.T) {
  586. name := "testcopymultiplefilestofile"
  587. defer deleteImages(name)
  588. ctx, err := fakeContext(`FROM busybox
  589. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  590. RUN echo 'dockerio:x:1001:' >> /etc/group
  591. RUN mkdir /exists
  592. RUN touch /exists/exists_file
  593. RUN chown -R dockerio.dockerio /exists
  594. COPY test_file1 test_file2 /exists/
  595. ADD test_file3 test_file4 https://docker.com/robots.txt /exists/
  596. RUN [ $(ls -l / | grep exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]
  597. RUN [ $(ls -l /exists/test_file1 | awk '{print $3":"$4}') = 'root:root' ]
  598. RUN [ $(ls -l /exists/test_file2 | awk '{print $3":"$4}') = 'root:root' ]
  599. RUN [ $(ls -l /exists/test_file3 | awk '{print $3":"$4}') = 'root:root' ]
  600. RUN [ $(ls -l /exists/test_file4 | awk '{print $3":"$4}') = 'root:root' ]
  601. RUN [ $(ls -l /exists/robots.txt | awk '{print $3":"$4}') = 'root:root' ]
  602. RUN [ $(ls -l /exists/exists_file | awk '{print $3":"$4}') = 'dockerio:dockerio' ]
  603. `,
  604. map[string]string{
  605. "test_file1": "test1",
  606. "test_file2": "test2",
  607. "test_file3": "test3",
  608. "test_file4": "test4",
  609. })
  610. defer ctx.Close()
  611. if err != nil {
  612. t.Fatal(err)
  613. }
  614. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  615. t.Fatal(err)
  616. }
  617. logDone("build - mulitple file copy/add tests")
  618. }
  619. func TestBuildAddMultipleFilesToFile(t *testing.T) {
  620. name := "testaddmultiplefilestofile"
  621. defer deleteImages(name)
  622. ctx, err := fakeContext(`FROM scratch
  623. ADD file1.txt file2.txt test
  624. `,
  625. map[string]string{
  626. "file1.txt": "test1",
  627. "file2.txt": "test1",
  628. })
  629. defer ctx.Close()
  630. if err != nil {
  631. t.Fatal(err)
  632. }
  633. expected := "When using ADD with more than one source file, the destination must be a directory and end with a /"
  634. if _, err := buildImageFromContext(name, ctx, true); err == nil || !strings.Contains(err.Error(), expected) {
  635. t.Fatalf("Wrong error: (should contain \"%s\") got:\n%v", expected, err)
  636. }
  637. logDone("build - multiple add files to file")
  638. }
  639. func TestBuildAddMultipleFilesToFileWild(t *testing.T) {
  640. name := "testaddmultiplefilestofilewild"
  641. defer deleteImages(name)
  642. ctx, err := fakeContext(`FROM scratch
  643. ADD file*.txt test
  644. `,
  645. map[string]string{
  646. "file1.txt": "test1",
  647. "file2.txt": "test1",
  648. })
  649. defer ctx.Close()
  650. if err != nil {
  651. t.Fatal(err)
  652. }
  653. expected := "When using ADD with more than one source file, the destination must be a directory and end with a /"
  654. if _, err := buildImageFromContext(name, ctx, true); err == nil || !strings.Contains(err.Error(), expected) {
  655. t.Fatalf("Wrong error: (should contain \"%s\") got:\n%v", expected, err)
  656. }
  657. logDone("build - multiple add files to file wild")
  658. }
  659. func TestBuildCopyMultipleFilesToFile(t *testing.T) {
  660. name := "testcopymultiplefilestofile"
  661. defer deleteImages(name)
  662. ctx, err := fakeContext(`FROM scratch
  663. COPY file1.txt file2.txt test
  664. `,
  665. map[string]string{
  666. "file1.txt": "test1",
  667. "file2.txt": "test1",
  668. })
  669. defer ctx.Close()
  670. if err != nil {
  671. t.Fatal(err)
  672. }
  673. expected := "When using COPY with more than one source file, the destination must be a directory and end with a /"
  674. if _, err := buildImageFromContext(name, ctx, true); err == nil || !strings.Contains(err.Error(), expected) {
  675. t.Fatalf("Wrong error: (should contain \"%s\") got:\n%v", expected, err)
  676. }
  677. logDone("build - multiple copy files to file")
  678. }
  679. func TestBuildCopyWildcard(t *testing.T) {
  680. name := "testcopywildcard"
  681. defer deleteImages(name)
  682. server, err := fakeStorage(map[string]string{
  683. "robots.txt": "hello",
  684. "index.html": "world",
  685. })
  686. if err != nil {
  687. t.Fatal(err)
  688. }
  689. defer server.Close()
  690. ctx, err := fakeContext(fmt.Sprintf(`FROM busybox
  691. COPY file*.txt /tmp/
  692. RUN ls /tmp/file1.txt /tmp/file2.txt
  693. RUN mkdir /tmp1
  694. COPY dir* /tmp1/
  695. RUN ls /tmp1/dirt /tmp1/nested_file /tmp1/nested_dir/nest_nest_file
  696. RUN mkdir /tmp2
  697. ADD dir/*dir %s/robots.txt /tmp2/
  698. RUN ls /tmp2/nest_nest_file /tmp2/robots.txt
  699. `, server.URL),
  700. map[string]string{
  701. "file1.txt": "test1",
  702. "file2.txt": "test2",
  703. "dir/nested_file": "nested file",
  704. "dir/nested_dir/nest_nest_file": "2 times nested",
  705. "dirt": "dirty",
  706. })
  707. defer ctx.Close()
  708. if err != nil {
  709. t.Fatal(err)
  710. }
  711. id1, err := buildImageFromContext(name, ctx, true)
  712. if err != nil {
  713. t.Fatal(err)
  714. }
  715. // Now make sure we use a cache the 2nd time
  716. id2, err := buildImageFromContext(name, ctx, true)
  717. if err != nil {
  718. t.Fatal(err)
  719. }
  720. if id1 != id2 {
  721. t.Fatal("didn't use the cache")
  722. }
  723. logDone("build - copy wild card")
  724. }
  725. func TestBuildCopyWildcardNoFind(t *testing.T) {
  726. name := "testcopywildcardnofind"
  727. defer deleteImages(name)
  728. ctx, err := fakeContext(`FROM busybox
  729. COPY file*.txt /tmp/
  730. `, nil)
  731. defer ctx.Close()
  732. if err != nil {
  733. t.Fatal(err)
  734. }
  735. _, err = buildImageFromContext(name, ctx, true)
  736. if err == nil {
  737. t.Fatal("should have failed to find a file")
  738. }
  739. if !strings.Contains(err.Error(), "No source files were specified") {
  740. t.Fatalf("Wrong error %v, must be about no source files", err)
  741. }
  742. logDone("build - copy wild card no find")
  743. }
  744. func TestBuildCopyWildcardCache(t *testing.T) {
  745. name := "testcopywildcardcache"
  746. defer deleteImages(name)
  747. ctx, err := fakeContext(`FROM busybox
  748. COPY file1.txt /tmp/`,
  749. map[string]string{
  750. "file1.txt": "test1",
  751. })
  752. defer ctx.Close()
  753. if err != nil {
  754. t.Fatal(err)
  755. }
  756. id1, err := buildImageFromContext(name, ctx, true)
  757. if err != nil {
  758. t.Fatal(err)
  759. }
  760. // Now make sure we use a cache the 2nd time even with wild cards.
  761. // Use the same context so the file is the same and the checksum will match
  762. ctx.Add("Dockerfile", `FROM busybox
  763. COPY file*.txt /tmp/`)
  764. id2, err := buildImageFromContext(name, ctx, true)
  765. if err != nil {
  766. t.Fatal(err)
  767. }
  768. if id1 != id2 {
  769. t.Fatal("didn't use the cache")
  770. }
  771. logDone("build - copy wild card cache")
  772. }
  773. func TestBuildAddSingleFileToNonExistingDir(t *testing.T) {
  774. name := "testaddsinglefiletononexistingdir"
  775. defer deleteImages(name)
  776. ctx, err := fakeContext(`FROM busybox
  777. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  778. RUN echo 'dockerio:x:1001:' >> /etc/group
  779. RUN touch /exists
  780. RUN chown dockerio.dockerio /exists
  781. ADD test_file /test_dir/
  782. RUN [ $(ls -l / | grep test_dir | awk '{print $3":"$4}') = 'root:root' ]
  783. RUN [ $(ls -l /test_dir/test_file | awk '{print $3":"$4}') = 'root:root' ]
  784. RUN [ $(ls -l /exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]`,
  785. map[string]string{
  786. "test_file": "test1",
  787. })
  788. if err != nil {
  789. t.Fatal(err)
  790. }
  791. defer ctx.Close()
  792. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  793. t.Fatal(err)
  794. }
  795. logDone("build - add single file to non-existing dir")
  796. }
  797. func TestBuildAddDirContentToRoot(t *testing.T) {
  798. name := "testadddircontenttoroot"
  799. defer deleteImages(name)
  800. ctx, err := fakeContext(`FROM busybox
  801. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  802. RUN echo 'dockerio:x:1001:' >> /etc/group
  803. RUN touch /exists
  804. RUN chown dockerio.dockerio exists
  805. ADD test_dir /
  806. RUN [ $(ls -l /test_file | awk '{print $3":"$4}') = 'root:root' ]
  807. RUN [ $(ls -l /exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]`,
  808. map[string]string{
  809. "test_dir/test_file": "test1",
  810. })
  811. if err != nil {
  812. t.Fatal(err)
  813. }
  814. defer ctx.Close()
  815. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  816. t.Fatal(err)
  817. }
  818. logDone("build - add directory contents to root")
  819. }
  820. func TestBuildAddDirContentToExistingDir(t *testing.T) {
  821. name := "testadddircontenttoexistingdir"
  822. defer deleteImages(name)
  823. ctx, err := fakeContext(`FROM busybox
  824. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  825. RUN echo 'dockerio:x:1001:' >> /etc/group
  826. RUN mkdir /exists
  827. RUN touch /exists/exists_file
  828. RUN chown -R dockerio.dockerio /exists
  829. ADD test_dir/ /exists/
  830. RUN [ $(ls -l / | grep exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]
  831. RUN [ $(ls -l /exists/exists_file | awk '{print $3":"$4}') = 'dockerio:dockerio' ]
  832. RUN [ $(ls -l /exists/test_file | awk '{print $3":"$4}') = 'root:root' ]`,
  833. map[string]string{
  834. "test_dir/test_file": "test1",
  835. })
  836. if err != nil {
  837. t.Fatal(err)
  838. }
  839. defer ctx.Close()
  840. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  841. t.Fatal(err)
  842. }
  843. logDone("build - add directory contents to existing dir")
  844. }
  845. func TestBuildAddWholeDirToRoot(t *testing.T) {
  846. name := "testaddwholedirtoroot"
  847. defer deleteImages(name)
  848. ctx, err := fakeContext(`FROM busybox
  849. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  850. RUN echo 'dockerio:x:1001:' >> /etc/group
  851. RUN touch /exists
  852. RUN chown dockerio.dockerio exists
  853. ADD test_dir /test_dir
  854. RUN [ $(ls -l / | grep test_dir | awk '{print $3":"$4}') = 'root:root' ]
  855. RUN [ $(ls -l / | grep test_dir | awk '{print $1}') = 'drwxr-xr-x' ]
  856. RUN [ $(ls -l /test_dir/test_file | awk '{print $3":"$4}') = 'root:root' ]
  857. RUN [ $(ls -l /test_dir/test_file | awk '{print $1}') = '-rw-r--r--' ]
  858. RUN [ $(ls -l /exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]`,
  859. map[string]string{
  860. "test_dir/test_file": "test1",
  861. })
  862. if err != nil {
  863. t.Fatal(err)
  864. }
  865. defer ctx.Close()
  866. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  867. t.Fatal(err)
  868. }
  869. logDone("build - add whole directory to root")
  870. }
  871. // Testing #5941
  872. func TestBuildAddEtcToRoot(t *testing.T) {
  873. name := "testaddetctoroot"
  874. defer deleteImages(name)
  875. ctx, err := fakeContext(`FROM scratch
  876. ADD . /`,
  877. map[string]string{
  878. "etc/test_file": "test1",
  879. })
  880. if err != nil {
  881. t.Fatal(err)
  882. }
  883. defer ctx.Close()
  884. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  885. t.Fatal(err)
  886. }
  887. logDone("build - add etc directory to root")
  888. }
  889. // Testing #9401
  890. func TestBuildAddPreservesFilesSpecialBits(t *testing.T) {
  891. name := "testaddpreservesfilesspecialbits"
  892. defer deleteImages(name)
  893. ctx, err := fakeContext(`FROM busybox
  894. ADD suidbin /usr/bin/suidbin
  895. RUN chmod 4755 /usr/bin/suidbin
  896. RUN [ $(ls -l /usr/bin/suidbin | awk '{print $1}') = '-rwsr-xr-x' ]
  897. ADD ./data/ /
  898. RUN [ $(ls -l /usr/bin/suidbin | awk '{print $1}') = '-rwsr-xr-x' ]`,
  899. map[string]string{
  900. "suidbin": "suidbin",
  901. "/data/usr/test_file": "test1",
  902. })
  903. if err != nil {
  904. t.Fatal(err)
  905. }
  906. defer ctx.Close()
  907. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  908. t.Fatal(err)
  909. }
  910. logDone("build - add preserves files special bits")
  911. }
  912. func TestBuildCopySingleFileToRoot(t *testing.T) {
  913. name := "testcopysinglefiletoroot"
  914. defer deleteImages(name)
  915. ctx, err := fakeContext(`FROM busybox
  916. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  917. RUN echo 'dockerio:x:1001:' >> /etc/group
  918. RUN touch /exists
  919. RUN chown dockerio.dockerio /exists
  920. COPY test_file /
  921. RUN [ $(ls -l /test_file | awk '{print $3":"$4}') = 'root:root' ]
  922. RUN [ $(ls -l /test_file | awk '{print $1}') = '-rw-r--r--' ]
  923. RUN [ $(ls -l /exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]`,
  924. map[string]string{
  925. "test_file": "test1",
  926. })
  927. if err != nil {
  928. t.Fatal(err)
  929. }
  930. defer ctx.Close()
  931. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  932. t.Fatal(err)
  933. }
  934. logDone("build - copy single file to root")
  935. }
  936. // Issue #3960: "ADD src ." hangs - adapted for COPY
  937. func TestBuildCopySingleFileToWorkdir(t *testing.T) {
  938. name := "testcopysinglefiletoworkdir"
  939. defer deleteImages(name)
  940. ctx, err := fakeContext(`FROM busybox
  941. COPY test_file .`,
  942. map[string]string{
  943. "test_file": "test1",
  944. })
  945. if err != nil {
  946. t.Fatal(err)
  947. }
  948. defer ctx.Close()
  949. done := make(chan struct{})
  950. go func() {
  951. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  952. t.Fatal(err)
  953. }
  954. close(done)
  955. }()
  956. select {
  957. case <-time.After(5 * time.Second):
  958. t.Fatal("Build with adding to workdir timed out")
  959. case <-done:
  960. }
  961. logDone("build - copy single file to workdir")
  962. }
  963. func TestBuildCopySingleFileToExistDir(t *testing.T) {
  964. name := "testcopysinglefiletoexistdir"
  965. defer deleteImages(name)
  966. ctx, err := fakeContext(`FROM busybox
  967. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  968. RUN echo 'dockerio:x:1001:' >> /etc/group
  969. RUN mkdir /exists
  970. RUN touch /exists/exists_file
  971. RUN chown -R dockerio.dockerio /exists
  972. COPY test_file /exists/
  973. RUN [ $(ls -l / | grep exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]
  974. RUN [ $(ls -l /exists/test_file | awk '{print $3":"$4}') = 'root:root' ]
  975. RUN [ $(ls -l /exists/exists_file | awk '{print $3":"$4}') = 'dockerio:dockerio' ]`,
  976. map[string]string{
  977. "test_file": "test1",
  978. })
  979. if err != nil {
  980. t.Fatal(err)
  981. }
  982. defer ctx.Close()
  983. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  984. t.Fatal(err)
  985. }
  986. logDone("build - copy single file to existing dir")
  987. }
  988. func TestBuildCopySingleFileToNonExistDir(t *testing.T) {
  989. name := "testcopysinglefiletononexistdir"
  990. defer deleteImages(name)
  991. ctx, err := fakeContext(`FROM busybox
  992. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  993. RUN echo 'dockerio:x:1001:' >> /etc/group
  994. RUN touch /exists
  995. RUN chown dockerio.dockerio /exists
  996. COPY test_file /test_dir/
  997. RUN [ $(ls -l / | grep test_dir | awk '{print $3":"$4}') = 'root:root' ]
  998. RUN [ $(ls -l /test_dir/test_file | awk '{print $3":"$4}') = 'root:root' ]
  999. RUN [ $(ls -l /exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]`,
  1000. map[string]string{
  1001. "test_file": "test1",
  1002. })
  1003. if err != nil {
  1004. t.Fatal(err)
  1005. }
  1006. defer ctx.Close()
  1007. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  1008. t.Fatal(err)
  1009. }
  1010. logDone("build - copy single file to non-existing dir")
  1011. }
  1012. func TestBuildCopyDirContentToRoot(t *testing.T) {
  1013. name := "testcopydircontenttoroot"
  1014. defer deleteImages(name)
  1015. ctx, err := fakeContext(`FROM busybox
  1016. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  1017. RUN echo 'dockerio:x:1001:' >> /etc/group
  1018. RUN touch /exists
  1019. RUN chown dockerio.dockerio exists
  1020. COPY test_dir /
  1021. RUN [ $(ls -l /test_file | awk '{print $3":"$4}') = 'root:root' ]
  1022. RUN [ $(ls -l /exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]`,
  1023. map[string]string{
  1024. "test_dir/test_file": "test1",
  1025. })
  1026. if err != nil {
  1027. t.Fatal(err)
  1028. }
  1029. defer ctx.Close()
  1030. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  1031. t.Fatal(err)
  1032. }
  1033. logDone("build - copy directory contents to root")
  1034. }
  1035. func TestBuildCopyDirContentToExistDir(t *testing.T) {
  1036. name := "testcopydircontenttoexistdir"
  1037. defer deleteImages(name)
  1038. ctx, err := fakeContext(`FROM busybox
  1039. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  1040. RUN echo 'dockerio:x:1001:' >> /etc/group
  1041. RUN mkdir /exists
  1042. RUN touch /exists/exists_file
  1043. RUN chown -R dockerio.dockerio /exists
  1044. COPY test_dir/ /exists/
  1045. RUN [ $(ls -l / | grep exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]
  1046. RUN [ $(ls -l /exists/exists_file | awk '{print $3":"$4}') = 'dockerio:dockerio' ]
  1047. RUN [ $(ls -l /exists/test_file | awk '{print $3":"$4}') = 'root:root' ]`,
  1048. map[string]string{
  1049. "test_dir/test_file": "test1",
  1050. })
  1051. if err != nil {
  1052. t.Fatal(err)
  1053. }
  1054. defer ctx.Close()
  1055. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  1056. t.Fatal(err)
  1057. }
  1058. logDone("build - copy directory contents to existing dir")
  1059. }
  1060. func TestBuildCopyWholeDirToRoot(t *testing.T) {
  1061. name := "testcopywholedirtoroot"
  1062. defer deleteImages(name)
  1063. ctx, err := fakeContext(`FROM busybox
  1064. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  1065. RUN echo 'dockerio:x:1001:' >> /etc/group
  1066. RUN touch /exists
  1067. RUN chown dockerio.dockerio exists
  1068. COPY test_dir /test_dir
  1069. RUN [ $(ls -l / | grep test_dir | awk '{print $3":"$4}') = 'root:root' ]
  1070. RUN [ $(ls -l / | grep test_dir | awk '{print $1}') = 'drwxr-xr-x' ]
  1071. RUN [ $(ls -l /test_dir/test_file | awk '{print $3":"$4}') = 'root:root' ]
  1072. RUN [ $(ls -l /test_dir/test_file | awk '{print $1}') = '-rw-r--r--' ]
  1073. RUN [ $(ls -l /exists | awk '{print $3":"$4}') = 'dockerio:dockerio' ]`,
  1074. map[string]string{
  1075. "test_dir/test_file": "test1",
  1076. })
  1077. if err != nil {
  1078. t.Fatal(err)
  1079. }
  1080. defer ctx.Close()
  1081. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  1082. t.Fatal(err)
  1083. }
  1084. logDone("build - copy whole directory to root")
  1085. }
  1086. func TestBuildCopyEtcToRoot(t *testing.T) {
  1087. name := "testcopyetctoroot"
  1088. defer deleteImages(name)
  1089. ctx, err := fakeContext(`FROM scratch
  1090. COPY . /`,
  1091. map[string]string{
  1092. "etc/test_file": "test1",
  1093. })
  1094. if err != nil {
  1095. t.Fatal(err)
  1096. }
  1097. defer ctx.Close()
  1098. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  1099. t.Fatal(err)
  1100. }
  1101. logDone("build - copy etc directory to root")
  1102. }
  1103. func TestBuildCopyDisallowRemote(t *testing.T) {
  1104. name := "testcopydisallowremote"
  1105. defer deleteImages(name)
  1106. _, out, err := buildImageWithOut(name, `FROM scratch
  1107. COPY https://index.docker.io/robots.txt /`,
  1108. true)
  1109. if err == nil || !strings.Contains(out, "Source can't be a URL for COPY") {
  1110. t.Fatalf("Error should be about disallowed remote source, got err: %s, out: %q", err, out)
  1111. }
  1112. logDone("build - copy - disallow copy from remote")
  1113. }
  1114. func TestBuildAddBadLinks(t *testing.T) {
  1115. const (
  1116. dockerfile = `
  1117. FROM scratch
  1118. ADD links.tar /
  1119. ADD foo.txt /symlink/
  1120. `
  1121. targetFile = "foo.txt"
  1122. )
  1123. var (
  1124. name = "test-link-absolute"
  1125. )
  1126. defer deleteImages(name)
  1127. ctx, err := fakeContext(dockerfile, nil)
  1128. if err != nil {
  1129. t.Fatal(err)
  1130. }
  1131. defer ctx.Close()
  1132. tempDir, err := ioutil.TempDir("", "test-link-absolute-temp-")
  1133. if err != nil {
  1134. t.Fatalf("failed to create temporary directory: %s", tempDir)
  1135. }
  1136. defer os.RemoveAll(tempDir)
  1137. symlinkTarget := fmt.Sprintf("/../../../../../../../../../../../..%s", tempDir)
  1138. tarPath := filepath.Join(ctx.Dir, "links.tar")
  1139. nonExistingFile := filepath.Join(tempDir, targetFile)
  1140. fooPath := filepath.Join(ctx.Dir, targetFile)
  1141. tarOut, err := os.Create(tarPath)
  1142. if err != nil {
  1143. t.Fatal(err)
  1144. }
  1145. tarWriter := tar.NewWriter(tarOut)
  1146. header := &tar.Header{
  1147. Name: "symlink",
  1148. Typeflag: tar.TypeSymlink,
  1149. Linkname: symlinkTarget,
  1150. Mode: 0755,
  1151. Uid: 0,
  1152. Gid: 0,
  1153. }
  1154. err = tarWriter.WriteHeader(header)
  1155. if err != nil {
  1156. t.Fatal(err)
  1157. }
  1158. tarWriter.Close()
  1159. tarOut.Close()
  1160. foo, err := os.Create(fooPath)
  1161. if err != nil {
  1162. t.Fatal(err)
  1163. }
  1164. defer foo.Close()
  1165. if _, err := foo.WriteString("test"); err != nil {
  1166. t.Fatal(err)
  1167. }
  1168. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  1169. t.Fatal(err)
  1170. }
  1171. if _, err := os.Stat(nonExistingFile); err == nil || err != nil && !os.IsNotExist(err) {
  1172. t.Fatalf("%s shouldn't have been written and it shouldn't exist", nonExistingFile)
  1173. }
  1174. logDone("build - ADD must add files in container")
  1175. }
  1176. // Issue #5270 - ensure we throw a better error than "unexpected EOF"
  1177. // when we can't access files in the context.
  1178. func TestBuildWithInaccessibleFilesInContext(t *testing.T) {
  1179. {
  1180. name := "testbuildinaccessiblefiles"
  1181. defer deleteImages(name)
  1182. ctx, err := fakeContext("FROM scratch\nADD . /foo/", map[string]string{"fileWithoutReadAccess": "foo"})
  1183. if err != nil {
  1184. t.Fatal(err)
  1185. }
  1186. defer ctx.Close()
  1187. // This is used to ensure we detect inaccessible files early during build in the cli client
  1188. pathToFileWithoutReadAccess := filepath.Join(ctx.Dir, "fileWithoutReadAccess")
  1189. if err = os.Chown(pathToFileWithoutReadAccess, 0, 0); err != nil {
  1190. t.Fatalf("failed to chown file to root: %s", err)
  1191. }
  1192. if err = os.Chmod(pathToFileWithoutReadAccess, 0700); err != nil {
  1193. t.Fatalf("failed to chmod file to 700: %s", err)
  1194. }
  1195. buildCmd := exec.Command("su", "unprivilegeduser", "-c", fmt.Sprintf("%s build -t %s .", dockerBinary, name))
  1196. buildCmd.Dir = ctx.Dir
  1197. out, _, err := runCommandWithOutput(buildCmd)
  1198. if err == nil {
  1199. t.Fatalf("build should have failed: %s %s", err, out)
  1200. }
  1201. // check if we've detected the failure before we started building
  1202. if !strings.Contains(out, "no permission to read from ") {
  1203. t.Fatalf("output should've contained the string: no permission to read from but contained: %s", out)
  1204. }
  1205. if !strings.Contains(out, "Error checking context is accessible") {
  1206. t.Fatalf("output should've contained the string: Error checking context is accessible")
  1207. }
  1208. }
  1209. {
  1210. name := "testbuildinaccessibledirectory"
  1211. defer deleteImages(name)
  1212. ctx, err := fakeContext("FROM scratch\nADD . /foo/", map[string]string{"directoryWeCantStat/bar": "foo"})
  1213. if err != nil {
  1214. t.Fatal(err)
  1215. }
  1216. defer ctx.Close()
  1217. // This is used to ensure we detect inaccessible directories early during build in the cli client
  1218. pathToDirectoryWithoutReadAccess := filepath.Join(ctx.Dir, "directoryWeCantStat")
  1219. pathToFileInDirectoryWithoutReadAccess := filepath.Join(pathToDirectoryWithoutReadAccess, "bar")
  1220. if err = os.Chown(pathToDirectoryWithoutReadAccess, 0, 0); err != nil {
  1221. t.Fatalf("failed to chown directory to root: %s", err)
  1222. }
  1223. if err = os.Chmod(pathToDirectoryWithoutReadAccess, 0444); err != nil {
  1224. t.Fatalf("failed to chmod directory to 755: %s", err)
  1225. }
  1226. if err = os.Chmod(pathToFileInDirectoryWithoutReadAccess, 0700); err != nil {
  1227. t.Fatalf("failed to chmod file to 444: %s", err)
  1228. }
  1229. buildCmd := exec.Command("su", "unprivilegeduser", "-c", fmt.Sprintf("%s build -t %s .", dockerBinary, name))
  1230. buildCmd.Dir = ctx.Dir
  1231. out, _, err := runCommandWithOutput(buildCmd)
  1232. if err == nil {
  1233. t.Fatalf("build should have failed: %s %s", err, out)
  1234. }
  1235. // check if we've detected the failure before we started building
  1236. if !strings.Contains(out, "can't stat") {
  1237. t.Fatalf("output should've contained the string: can't access %s", out)
  1238. }
  1239. if !strings.Contains(out, "Error checking context is accessible") {
  1240. t.Fatalf("output should've contained the string: Error checking context is accessible")
  1241. }
  1242. }
  1243. {
  1244. name := "testlinksok"
  1245. defer deleteImages(name)
  1246. ctx, err := fakeContext("FROM scratch\nADD . /foo/", nil)
  1247. if err != nil {
  1248. t.Fatal(err)
  1249. }
  1250. defer ctx.Close()
  1251. target := "../../../../../../../../../../../../../../../../../../../azA"
  1252. if err := os.Symlink(filepath.Join(ctx.Dir, "g"), target); err != nil {
  1253. t.Fatal(err)
  1254. }
  1255. defer os.Remove(target)
  1256. // This is used to ensure we don't follow links when checking if everything in the context is accessible
  1257. // This test doesn't require that we run commands as an unprivileged user
  1258. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  1259. t.Fatal(err)
  1260. }
  1261. }
  1262. {
  1263. name := "testbuildignoredinaccessible"
  1264. defer deleteImages(name)
  1265. ctx, err := fakeContext("FROM scratch\nADD . /foo/",
  1266. map[string]string{
  1267. "directoryWeCantStat/bar": "foo",
  1268. ".dockerignore": "directoryWeCantStat",
  1269. })
  1270. if err != nil {
  1271. t.Fatal(err)
  1272. }
  1273. defer ctx.Close()
  1274. // This is used to ensure we don't try to add inaccessible files when they are ignored by a .dockerignore pattern
  1275. pathToDirectoryWithoutReadAccess := filepath.Join(ctx.Dir, "directoryWeCantStat")
  1276. pathToFileInDirectoryWithoutReadAccess := filepath.Join(pathToDirectoryWithoutReadAccess, "bar")
  1277. if err = os.Chown(pathToDirectoryWithoutReadAccess, 0, 0); err != nil {
  1278. t.Fatalf("failed to chown directory to root: %s", err)
  1279. }
  1280. if err = os.Chmod(pathToDirectoryWithoutReadAccess, 0444); err != nil {
  1281. t.Fatalf("failed to chmod directory to 755: %s", err)
  1282. }
  1283. if err = os.Chmod(pathToFileInDirectoryWithoutReadAccess, 0700); err != nil {
  1284. t.Fatalf("failed to chmod file to 444: %s", err)
  1285. }
  1286. buildCmd := exec.Command("su", "unprivilegeduser", "-c", fmt.Sprintf("%s build -t %s .", dockerBinary, name))
  1287. buildCmd.Dir = ctx.Dir
  1288. if out, _, err := runCommandWithOutput(buildCmd); err != nil {
  1289. t.Fatalf("build should have worked: %s %s", err, out)
  1290. }
  1291. }
  1292. logDone("build - ADD from context with inaccessible files must fail")
  1293. logDone("build - ADD from context with accessible links must work")
  1294. logDone("build - ADD from context with ignored inaccessible files must work")
  1295. }
  1296. func TestBuildForceRm(t *testing.T) {
  1297. containerCountBefore, err := getContainerCount()
  1298. if err != nil {
  1299. t.Fatalf("failed to get the container count: %s", err)
  1300. }
  1301. name := "testbuildforcerm"
  1302. defer deleteImages(name)
  1303. ctx, err := fakeContext("FROM scratch\nRUN true\nRUN thiswillfail", nil)
  1304. if err != nil {
  1305. t.Fatal(err)
  1306. }
  1307. defer ctx.Close()
  1308. buildCmd := exec.Command(dockerBinary, "build", "-t", name, "--force-rm", ".")
  1309. buildCmd.Dir = ctx.Dir
  1310. if out, _, err := runCommandWithOutput(buildCmd); err == nil {
  1311. t.Fatalf("failed to build the image: %s, %v", out, err)
  1312. }
  1313. containerCountAfter, err := getContainerCount()
  1314. if err != nil {
  1315. t.Fatalf("failed to get the container count: %s", err)
  1316. }
  1317. if containerCountBefore != containerCountAfter {
  1318. t.Fatalf("--force-rm shouldn't have left containers behind")
  1319. }
  1320. logDone("build - ensure --force-rm doesn't leave containers behind")
  1321. }
  1322. func TestBuildRm(t *testing.T) {
  1323. name := "testbuildrm"
  1324. defer deleteImages(name)
  1325. ctx, err := fakeContext("FROM scratch\nADD foo /\nADD foo /", map[string]string{"foo": "bar"})
  1326. if err != nil {
  1327. t.Fatal(err)
  1328. }
  1329. defer ctx.Close()
  1330. {
  1331. containerCountBefore, err := getContainerCount()
  1332. if err != nil {
  1333. t.Fatalf("failed to get the container count: %s", err)
  1334. }
  1335. out, _, err := dockerCmdInDir(t, ctx.Dir, "build", "--rm", "-t", name, ".")
  1336. if err != nil {
  1337. t.Fatal("failed to build the image", out)
  1338. }
  1339. containerCountAfter, err := getContainerCount()
  1340. if err != nil {
  1341. t.Fatalf("failed to get the container count: %s", err)
  1342. }
  1343. if containerCountBefore != containerCountAfter {
  1344. t.Fatalf("-rm shouldn't have left containers behind")
  1345. }
  1346. deleteImages(name)
  1347. }
  1348. {
  1349. containerCountBefore, err := getContainerCount()
  1350. if err != nil {
  1351. t.Fatalf("failed to get the container count: %s", err)
  1352. }
  1353. out, _, err := dockerCmdInDir(t, ctx.Dir, "build", "-t", name, ".")
  1354. if err != nil {
  1355. t.Fatal("failed to build the image", out)
  1356. }
  1357. containerCountAfter, err := getContainerCount()
  1358. if err != nil {
  1359. t.Fatalf("failed to get the container count: %s", err)
  1360. }
  1361. if containerCountBefore != containerCountAfter {
  1362. t.Fatalf("--rm shouldn't have left containers behind")
  1363. }
  1364. deleteImages(name)
  1365. }
  1366. {
  1367. containerCountBefore, err := getContainerCount()
  1368. if err != nil {
  1369. t.Fatalf("failed to get the container count: %s", err)
  1370. }
  1371. out, _, err := dockerCmdInDir(t, ctx.Dir, "build", "--rm=false", "-t", name, ".")
  1372. if err != nil {
  1373. t.Fatal("failed to build the image", out)
  1374. }
  1375. containerCountAfter, err := getContainerCount()
  1376. if err != nil {
  1377. t.Fatalf("failed to get the container count: %s", err)
  1378. }
  1379. if containerCountBefore == containerCountAfter {
  1380. t.Fatalf("--rm=false should have left containers behind")
  1381. }
  1382. deleteAllContainers()
  1383. deleteImages(name)
  1384. }
  1385. logDone("build - ensure --rm doesn't leave containers behind and that --rm=true is the default")
  1386. logDone("build - ensure --rm=false overrides the default")
  1387. }
  1388. func TestBuildWithVolumes(t *testing.T) {
  1389. var (
  1390. result map[string]map[string]struct{}
  1391. name = "testbuildvolumes"
  1392. emptyMap = make(map[string]struct{})
  1393. expected = map[string]map[string]struct{}{
  1394. "/test1": emptyMap,
  1395. "/test2": emptyMap,
  1396. "/test3": emptyMap,
  1397. "/test4": emptyMap,
  1398. "/test5": emptyMap,
  1399. "/test6": emptyMap,
  1400. "[/test7": emptyMap,
  1401. "/test8]": emptyMap,
  1402. }
  1403. )
  1404. defer deleteImages(name)
  1405. _, err := buildImage(name,
  1406. `FROM scratch
  1407. VOLUME /test1
  1408. VOLUME /test2
  1409. VOLUME /test3 /test4
  1410. VOLUME ["/test5", "/test6"]
  1411. VOLUME [/test7 /test8]
  1412. `,
  1413. true)
  1414. if err != nil {
  1415. t.Fatal(err)
  1416. }
  1417. res, err := inspectFieldJSON(name, "Config.Volumes")
  1418. if err != nil {
  1419. t.Fatal(err)
  1420. }
  1421. err = unmarshalJSON([]byte(res), &result)
  1422. if err != nil {
  1423. t.Fatal(err)
  1424. }
  1425. equal := reflect.DeepEqual(&result, &expected)
  1426. if !equal {
  1427. t.Fatalf("Volumes %s, expected %s", result, expected)
  1428. }
  1429. logDone("build - with volumes")
  1430. }
  1431. func TestBuildMaintainer(t *testing.T) {
  1432. name := "testbuildmaintainer"
  1433. expected := "dockerio"
  1434. defer deleteImages(name)
  1435. _, err := buildImage(name,
  1436. `FROM scratch
  1437. MAINTAINER dockerio`,
  1438. true)
  1439. if err != nil {
  1440. t.Fatal(err)
  1441. }
  1442. res, err := inspectField(name, "Author")
  1443. if err != nil {
  1444. t.Fatal(err)
  1445. }
  1446. if res != expected {
  1447. t.Fatalf("Maintainer %s, expected %s", res, expected)
  1448. }
  1449. logDone("build - maintainer")
  1450. }
  1451. func TestBuildUser(t *testing.T) {
  1452. name := "testbuilduser"
  1453. expected := "dockerio"
  1454. defer deleteImages(name)
  1455. _, err := buildImage(name,
  1456. `FROM busybox
  1457. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  1458. USER dockerio
  1459. RUN [ $(whoami) = 'dockerio' ]`,
  1460. true)
  1461. if err != nil {
  1462. t.Fatal(err)
  1463. }
  1464. res, err := inspectField(name, "Config.User")
  1465. if err != nil {
  1466. t.Fatal(err)
  1467. }
  1468. if res != expected {
  1469. t.Fatalf("User %s, expected %s", res, expected)
  1470. }
  1471. logDone("build - user")
  1472. }
  1473. func TestBuildRelativeWorkdir(t *testing.T) {
  1474. name := "testbuildrelativeworkdir"
  1475. expected := "/test2/test3"
  1476. defer deleteImages(name)
  1477. _, err := buildImage(name,
  1478. `FROM busybox
  1479. RUN [ "$PWD" = '/' ]
  1480. WORKDIR test1
  1481. RUN [ "$PWD" = '/test1' ]
  1482. WORKDIR /test2
  1483. RUN [ "$PWD" = '/test2' ]
  1484. WORKDIR test3
  1485. RUN [ "$PWD" = '/test2/test3' ]`,
  1486. true)
  1487. if err != nil {
  1488. t.Fatal(err)
  1489. }
  1490. res, err := inspectField(name, "Config.WorkingDir")
  1491. if err != nil {
  1492. t.Fatal(err)
  1493. }
  1494. if res != expected {
  1495. t.Fatalf("Workdir %s, expected %s", res, expected)
  1496. }
  1497. logDone("build - relative workdir")
  1498. }
  1499. func TestBuildWorkdirWithEnvVariables(t *testing.T) {
  1500. name := "testbuildworkdirwithenvvariables"
  1501. expected := "/test1/test2/$MISSING_VAR"
  1502. defer deleteImages(name)
  1503. _, err := buildImage(name,
  1504. `FROM busybox
  1505. ENV DIRPATH /test1
  1506. ENV SUBDIRNAME test2
  1507. WORKDIR $DIRPATH
  1508. WORKDIR $SUBDIRNAME/$MISSING_VAR`,
  1509. true)
  1510. if err != nil {
  1511. t.Fatal(err)
  1512. }
  1513. res, err := inspectField(name, "Config.WorkingDir")
  1514. if err != nil {
  1515. t.Fatal(err)
  1516. }
  1517. if res != expected {
  1518. t.Fatalf("Workdir %s, expected %s", res, expected)
  1519. }
  1520. logDone("build - workdir with env variables")
  1521. }
  1522. func TestBuildEnv(t *testing.T) {
  1523. name := "testbuildenv"
  1524. expected := "[PATH=/test:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin PORT=2375]"
  1525. defer deleteImages(name)
  1526. _, err := buildImage(name,
  1527. `FROM busybox
  1528. ENV PATH /test:$PATH
  1529. ENV PORT 2375
  1530. RUN [ $(env | grep PORT) = 'PORT=2375' ]`,
  1531. true)
  1532. if err != nil {
  1533. t.Fatal(err)
  1534. }
  1535. res, err := inspectField(name, "Config.Env")
  1536. if err != nil {
  1537. t.Fatal(err)
  1538. }
  1539. if res != expected {
  1540. t.Fatalf("Env %s, expected %s", res, expected)
  1541. }
  1542. logDone("build - env")
  1543. }
  1544. func TestBuildContextCleanup(t *testing.T) {
  1545. name := "testbuildcontextcleanup"
  1546. defer deleteImages(name)
  1547. entries, err := ioutil.ReadDir("/var/lib/docker/tmp")
  1548. if err != nil {
  1549. t.Fatalf("failed to list contents of tmp dir: %s", err)
  1550. }
  1551. _, err = buildImage(name,
  1552. `FROM scratch
  1553. ENTRYPOINT ["/bin/echo"]`,
  1554. true)
  1555. if err != nil {
  1556. t.Fatal(err)
  1557. }
  1558. entriesFinal, err := ioutil.ReadDir("/var/lib/docker/tmp")
  1559. if err != nil {
  1560. t.Fatalf("failed to list contents of tmp dir: %s", err)
  1561. }
  1562. if err = compareDirectoryEntries(entries, entriesFinal); err != nil {
  1563. t.Fatalf("context should have been deleted, but wasn't")
  1564. }
  1565. logDone("build - verify context cleanup works properly")
  1566. }
  1567. func TestBuildContextCleanupFailedBuild(t *testing.T) {
  1568. name := "testbuildcontextcleanup"
  1569. defer deleteImages(name)
  1570. defer deleteAllContainers()
  1571. entries, err := ioutil.ReadDir("/var/lib/docker/tmp")
  1572. if err != nil {
  1573. t.Fatalf("failed to list contents of tmp dir: %s", err)
  1574. }
  1575. _, err = buildImage(name,
  1576. `FROM scratch
  1577. RUN /non/existing/command`,
  1578. true)
  1579. if err == nil {
  1580. t.Fatalf("expected build to fail, but it didn't")
  1581. }
  1582. entriesFinal, err := ioutil.ReadDir("/var/lib/docker/tmp")
  1583. if err != nil {
  1584. t.Fatalf("failed to list contents of tmp dir: %s", err)
  1585. }
  1586. if err = compareDirectoryEntries(entries, entriesFinal); err != nil {
  1587. t.Fatalf("context should have been deleted, but wasn't")
  1588. }
  1589. logDone("build - verify context cleanup works properly after a failed build")
  1590. }
  1591. func TestBuildCmd(t *testing.T) {
  1592. name := "testbuildcmd"
  1593. expected := "[/bin/echo Hello World]"
  1594. defer deleteImages(name)
  1595. _, err := buildImage(name,
  1596. `FROM scratch
  1597. CMD ["/bin/echo", "Hello World"]`,
  1598. true)
  1599. if err != nil {
  1600. t.Fatal(err)
  1601. }
  1602. res, err := inspectField(name, "Config.Cmd")
  1603. if err != nil {
  1604. t.Fatal(err)
  1605. }
  1606. if res != expected {
  1607. t.Fatalf("Cmd %s, expected %s", res, expected)
  1608. }
  1609. logDone("build - cmd")
  1610. }
  1611. func TestBuildExpose(t *testing.T) {
  1612. name := "testbuildexpose"
  1613. expected := "map[2375/tcp:map[]]"
  1614. defer deleteImages(name)
  1615. _, err := buildImage(name,
  1616. `FROM scratch
  1617. EXPOSE 2375`,
  1618. true)
  1619. if err != nil {
  1620. t.Fatal(err)
  1621. }
  1622. res, err := inspectField(name, "Config.ExposedPorts")
  1623. if err != nil {
  1624. t.Fatal(err)
  1625. }
  1626. if res != expected {
  1627. t.Fatalf("Exposed ports %s, expected %s", res, expected)
  1628. }
  1629. logDone("build - expose")
  1630. }
  1631. func TestBuildEmptyEntrypointInheritance(t *testing.T) {
  1632. name := "testbuildentrypointinheritance"
  1633. name2 := "testbuildentrypointinheritance2"
  1634. defer deleteImages(name, name2)
  1635. _, err := buildImage(name,
  1636. `FROM busybox
  1637. ENTRYPOINT ["/bin/echo"]`,
  1638. true)
  1639. if err != nil {
  1640. t.Fatal(err)
  1641. }
  1642. res, err := inspectField(name, "Config.Entrypoint")
  1643. if err != nil {
  1644. t.Fatal(err)
  1645. }
  1646. expected := "[/bin/echo]"
  1647. if res != expected {
  1648. t.Fatalf("Entrypoint %s, expected %s", res, expected)
  1649. }
  1650. _, err = buildImage(name2,
  1651. fmt.Sprintf(`FROM %s
  1652. ENTRYPOINT []`, name),
  1653. true)
  1654. if err != nil {
  1655. t.Fatal(err)
  1656. }
  1657. res, err = inspectField(name2, "Config.Entrypoint")
  1658. if err != nil {
  1659. t.Fatal(err)
  1660. }
  1661. expected = "[]"
  1662. if res != expected {
  1663. t.Fatalf("Entrypoint %s, expected %s", res, expected)
  1664. }
  1665. logDone("build - empty entrypoint inheritance")
  1666. }
  1667. func TestBuildEmptyEntrypoint(t *testing.T) {
  1668. name := "testbuildentrypoint"
  1669. defer deleteImages(name)
  1670. expected := "[]"
  1671. _, err := buildImage(name,
  1672. `FROM busybox
  1673. ENTRYPOINT []`,
  1674. true)
  1675. if err != nil {
  1676. t.Fatal(err)
  1677. }
  1678. res, err := inspectField(name, "Config.Entrypoint")
  1679. if err != nil {
  1680. t.Fatal(err)
  1681. }
  1682. if res != expected {
  1683. t.Fatalf("Entrypoint %s, expected %s", res, expected)
  1684. }
  1685. logDone("build - empty entrypoint")
  1686. }
  1687. func TestBuildEntrypoint(t *testing.T) {
  1688. name := "testbuildentrypoint"
  1689. expected := "[/bin/echo]"
  1690. defer deleteImages(name)
  1691. _, err := buildImage(name,
  1692. `FROM scratch
  1693. ENTRYPOINT ["/bin/echo"]`,
  1694. true)
  1695. if err != nil {
  1696. t.Fatal(err)
  1697. }
  1698. res, err := inspectField(name, "Config.Entrypoint")
  1699. if err != nil {
  1700. t.Fatal(err)
  1701. }
  1702. if res != expected {
  1703. t.Fatalf("Entrypoint %s, expected %s", res, expected)
  1704. }
  1705. logDone("build - entrypoint")
  1706. }
  1707. // #6445 ensure ONBUILD triggers aren't committed to grandchildren
  1708. func TestBuildOnBuildLimitedInheritence(t *testing.T) {
  1709. var (
  1710. out2, out3 string
  1711. )
  1712. {
  1713. name1 := "testonbuildtrigger1"
  1714. dockerfile1 := `
  1715. FROM busybox
  1716. RUN echo "GRANDPARENT"
  1717. ONBUILD RUN echo "ONBUILD PARENT"
  1718. `
  1719. ctx, err := fakeContext(dockerfile1, nil)
  1720. if err != nil {
  1721. t.Fatal(err)
  1722. }
  1723. defer ctx.Close()
  1724. out1, _, err := dockerCmdInDir(t, ctx.Dir, "build", "-t", name1, ".")
  1725. if err != nil {
  1726. t.Fatalf("build failed to complete: %s, %v", out1, err)
  1727. }
  1728. defer deleteImages(name1)
  1729. }
  1730. {
  1731. name2 := "testonbuildtrigger2"
  1732. dockerfile2 := `
  1733. FROM testonbuildtrigger1
  1734. `
  1735. ctx, err := fakeContext(dockerfile2, nil)
  1736. if err != nil {
  1737. t.Fatal(err)
  1738. }
  1739. defer ctx.Close()
  1740. out2, _, err = dockerCmdInDir(t, ctx.Dir, "build", "-t", name2, ".")
  1741. if err != nil {
  1742. t.Fatalf("build failed to complete: %s, %v", out2, err)
  1743. }
  1744. defer deleteImages(name2)
  1745. }
  1746. {
  1747. name3 := "testonbuildtrigger3"
  1748. dockerfile3 := `
  1749. FROM testonbuildtrigger2
  1750. `
  1751. ctx, err := fakeContext(dockerfile3, nil)
  1752. if err != nil {
  1753. t.Fatal(err)
  1754. }
  1755. defer ctx.Close()
  1756. out3, _, err = dockerCmdInDir(t, ctx.Dir, "build", "-t", name3, ".")
  1757. if err != nil {
  1758. t.Fatalf("build failed to complete: %s, %v", out3, err)
  1759. }
  1760. defer deleteImages(name3)
  1761. }
  1762. // ONBUILD should be run in second build.
  1763. if !strings.Contains(out2, "ONBUILD PARENT") {
  1764. t.Fatalf("ONBUILD instruction did not run in child of ONBUILD parent")
  1765. }
  1766. // ONBUILD should *not* be run in third build.
  1767. if strings.Contains(out3, "ONBUILD PARENT") {
  1768. t.Fatalf("ONBUILD instruction ran in grandchild of ONBUILD parent")
  1769. }
  1770. logDone("build - onbuild")
  1771. }
  1772. func TestBuildWithCache(t *testing.T) {
  1773. name := "testbuildwithcache"
  1774. defer deleteImages(name)
  1775. id1, err := buildImage(name,
  1776. `FROM scratch
  1777. MAINTAINER dockerio
  1778. EXPOSE 5432
  1779. ENTRYPOINT ["/bin/echo"]`,
  1780. true)
  1781. if err != nil {
  1782. t.Fatal(err)
  1783. }
  1784. id2, err := buildImage(name,
  1785. `FROM scratch
  1786. MAINTAINER dockerio
  1787. EXPOSE 5432
  1788. ENTRYPOINT ["/bin/echo"]`,
  1789. true)
  1790. if err != nil {
  1791. t.Fatal(err)
  1792. }
  1793. if id1 != id2 {
  1794. t.Fatal("The cache should have been used but hasn't.")
  1795. }
  1796. logDone("build - with cache")
  1797. }
  1798. func TestBuildWithoutCache(t *testing.T) {
  1799. name := "testbuildwithoutcache"
  1800. name2 := "testbuildwithoutcache2"
  1801. defer deleteImages(name, name2)
  1802. id1, err := buildImage(name,
  1803. `FROM scratch
  1804. MAINTAINER dockerio
  1805. EXPOSE 5432
  1806. ENTRYPOINT ["/bin/echo"]`,
  1807. true)
  1808. if err != nil {
  1809. t.Fatal(err)
  1810. }
  1811. id2, err := buildImage(name2,
  1812. `FROM scratch
  1813. MAINTAINER dockerio
  1814. EXPOSE 5432
  1815. ENTRYPOINT ["/bin/echo"]`,
  1816. false)
  1817. if err != nil {
  1818. t.Fatal(err)
  1819. }
  1820. if id1 == id2 {
  1821. t.Fatal("The cache should have been invalided but hasn't.")
  1822. }
  1823. logDone("build - without cache")
  1824. }
  1825. func TestBuildADDLocalFileWithCache(t *testing.T) {
  1826. name := "testbuildaddlocalfilewithcache"
  1827. name2 := "testbuildaddlocalfilewithcache2"
  1828. defer deleteImages(name, name2)
  1829. dockerfile := `
  1830. FROM busybox
  1831. MAINTAINER dockerio
  1832. ADD foo /usr/lib/bla/bar
  1833. RUN [ "$(cat /usr/lib/bla/bar)" = "hello" ]`
  1834. ctx, err := fakeContext(dockerfile, map[string]string{
  1835. "foo": "hello",
  1836. })
  1837. defer ctx.Close()
  1838. if err != nil {
  1839. t.Fatal(err)
  1840. }
  1841. id1, err := buildImageFromContext(name, ctx, true)
  1842. if err != nil {
  1843. t.Fatal(err)
  1844. }
  1845. id2, err := buildImageFromContext(name2, ctx, true)
  1846. if err != nil {
  1847. t.Fatal(err)
  1848. }
  1849. if id1 != id2 {
  1850. t.Fatal("The cache should have been used but hasn't.")
  1851. }
  1852. logDone("build - add local file with cache")
  1853. }
  1854. func TestBuildADDMultipleLocalFileWithCache(t *testing.T) {
  1855. name := "testbuildaddmultiplelocalfilewithcache"
  1856. name2 := "testbuildaddmultiplelocalfilewithcache2"
  1857. defer deleteImages(name, name2)
  1858. dockerfile := `
  1859. FROM busybox
  1860. MAINTAINER dockerio
  1861. ADD foo Dockerfile /usr/lib/bla/
  1862. RUN [ "$(cat /usr/lib/bla/foo)" = "hello" ]`
  1863. ctx, err := fakeContext(dockerfile, map[string]string{
  1864. "foo": "hello",
  1865. })
  1866. defer ctx.Close()
  1867. if err != nil {
  1868. t.Fatal(err)
  1869. }
  1870. id1, err := buildImageFromContext(name, ctx, true)
  1871. if err != nil {
  1872. t.Fatal(err)
  1873. }
  1874. id2, err := buildImageFromContext(name2, ctx, true)
  1875. if err != nil {
  1876. t.Fatal(err)
  1877. }
  1878. if id1 != id2 {
  1879. t.Fatal("The cache should have been used but hasn't.")
  1880. }
  1881. logDone("build - add multiple local files with cache")
  1882. }
  1883. func TestBuildADDLocalFileWithoutCache(t *testing.T) {
  1884. name := "testbuildaddlocalfilewithoutcache"
  1885. name2 := "testbuildaddlocalfilewithoutcache2"
  1886. defer deleteImages(name, name2)
  1887. dockerfile := `
  1888. FROM busybox
  1889. MAINTAINER dockerio
  1890. ADD foo /usr/lib/bla/bar
  1891. RUN [ "$(cat /usr/lib/bla/bar)" = "hello" ]`
  1892. ctx, err := fakeContext(dockerfile, map[string]string{
  1893. "foo": "hello",
  1894. })
  1895. defer ctx.Close()
  1896. if err != nil {
  1897. t.Fatal(err)
  1898. }
  1899. id1, err := buildImageFromContext(name, ctx, true)
  1900. if err != nil {
  1901. t.Fatal(err)
  1902. }
  1903. id2, err := buildImageFromContext(name2, ctx, false)
  1904. if err != nil {
  1905. t.Fatal(err)
  1906. }
  1907. if id1 == id2 {
  1908. t.Fatal("The cache should have been invalided but hasn't.")
  1909. }
  1910. logDone("build - add local file without cache")
  1911. }
  1912. func TestBuildCopyDirButNotFile(t *testing.T) {
  1913. name := "testbuildcopydirbutnotfile"
  1914. name2 := "testbuildcopydirbutnotfile2"
  1915. defer deleteImages(name, name2)
  1916. dockerfile := `
  1917. FROM scratch
  1918. COPY dir /tmp/`
  1919. ctx, err := fakeContext(dockerfile, map[string]string{
  1920. "dir/foo": "hello",
  1921. })
  1922. defer ctx.Close()
  1923. if err != nil {
  1924. t.Fatal(err)
  1925. }
  1926. id1, err := buildImageFromContext(name, ctx, true)
  1927. if err != nil {
  1928. t.Fatal(err)
  1929. }
  1930. // Check that adding file with similar name doesn't mess with cache
  1931. if err := ctx.Add("dir_file", "hello2"); err != nil {
  1932. t.Fatal(err)
  1933. }
  1934. id2, err := buildImageFromContext(name2, ctx, true)
  1935. if err != nil {
  1936. t.Fatal(err)
  1937. }
  1938. if id1 != id2 {
  1939. t.Fatal("The cache should have been used but wasn't")
  1940. }
  1941. logDone("build - add current directory but not file")
  1942. }
  1943. func TestBuildADDCurrentDirWithCache(t *testing.T) {
  1944. name := "testbuildaddcurrentdirwithcache"
  1945. name2 := name + "2"
  1946. name3 := name + "3"
  1947. name4 := name + "4"
  1948. name5 := name + "5"
  1949. defer deleteImages(name, name2, name3, name4, name5)
  1950. dockerfile := `
  1951. FROM scratch
  1952. MAINTAINER dockerio
  1953. ADD . /usr/lib/bla`
  1954. ctx, err := fakeContext(dockerfile, map[string]string{
  1955. "foo": "hello",
  1956. })
  1957. defer ctx.Close()
  1958. if err != nil {
  1959. t.Fatal(err)
  1960. }
  1961. id1, err := buildImageFromContext(name, ctx, true)
  1962. if err != nil {
  1963. t.Fatal(err)
  1964. }
  1965. // Check that adding file invalidate cache of "ADD ."
  1966. if err := ctx.Add("bar", "hello2"); err != nil {
  1967. t.Fatal(err)
  1968. }
  1969. id2, err := buildImageFromContext(name2, ctx, true)
  1970. if err != nil {
  1971. t.Fatal(err)
  1972. }
  1973. if id1 == id2 {
  1974. t.Fatal("The cache should have been invalided but hasn't.")
  1975. }
  1976. // Check that changing file invalidate cache of "ADD ."
  1977. if err := ctx.Add("foo", "hello1"); err != nil {
  1978. t.Fatal(err)
  1979. }
  1980. id3, err := buildImageFromContext(name3, ctx, true)
  1981. if err != nil {
  1982. t.Fatal(err)
  1983. }
  1984. if id2 == id3 {
  1985. t.Fatal("The cache should have been invalided but hasn't.")
  1986. }
  1987. // Check that changing file to same content invalidate cache of "ADD ."
  1988. time.Sleep(1 * time.Second) // wait second because of mtime precision
  1989. if err := ctx.Add("foo", "hello1"); err != nil {
  1990. t.Fatal(err)
  1991. }
  1992. id4, err := buildImageFromContext(name4, ctx, true)
  1993. if err != nil {
  1994. t.Fatal(err)
  1995. }
  1996. if id3 == id4 {
  1997. t.Fatal("The cache should have been invalided but hasn't.")
  1998. }
  1999. id5, err := buildImageFromContext(name5, ctx, true)
  2000. if err != nil {
  2001. t.Fatal(err)
  2002. }
  2003. if id4 != id5 {
  2004. t.Fatal("The cache should have been used but hasn't.")
  2005. }
  2006. logDone("build - add current directory with cache")
  2007. }
  2008. func TestBuildADDCurrentDirWithoutCache(t *testing.T) {
  2009. name := "testbuildaddcurrentdirwithoutcache"
  2010. name2 := "testbuildaddcurrentdirwithoutcache2"
  2011. defer deleteImages(name, name2)
  2012. dockerfile := `
  2013. FROM scratch
  2014. MAINTAINER dockerio
  2015. ADD . /usr/lib/bla`
  2016. ctx, err := fakeContext(dockerfile, map[string]string{
  2017. "foo": "hello",
  2018. })
  2019. defer ctx.Close()
  2020. if err != nil {
  2021. t.Fatal(err)
  2022. }
  2023. id1, err := buildImageFromContext(name, ctx, true)
  2024. if err != nil {
  2025. t.Fatal(err)
  2026. }
  2027. id2, err := buildImageFromContext(name2, ctx, false)
  2028. if err != nil {
  2029. t.Fatal(err)
  2030. }
  2031. if id1 == id2 {
  2032. t.Fatal("The cache should have been invalided but hasn't.")
  2033. }
  2034. logDone("build - add current directory without cache")
  2035. }
  2036. func TestBuildADDRemoteFileWithCache(t *testing.T) {
  2037. name := "testbuildaddremotefilewithcache"
  2038. defer deleteImages(name)
  2039. server, err := fakeStorage(map[string]string{
  2040. "baz": "hello",
  2041. })
  2042. if err != nil {
  2043. t.Fatal(err)
  2044. }
  2045. defer server.Close()
  2046. id1, err := buildImage(name,
  2047. fmt.Sprintf(`FROM scratch
  2048. MAINTAINER dockerio
  2049. ADD %s/baz /usr/lib/baz/quux`, server.URL),
  2050. true)
  2051. if err != nil {
  2052. t.Fatal(err)
  2053. }
  2054. id2, err := buildImage(name,
  2055. fmt.Sprintf(`FROM scratch
  2056. MAINTAINER dockerio
  2057. ADD %s/baz /usr/lib/baz/quux`, server.URL),
  2058. true)
  2059. if err != nil {
  2060. t.Fatal(err)
  2061. }
  2062. if id1 != id2 {
  2063. t.Fatal("The cache should have been used but hasn't.")
  2064. }
  2065. logDone("build - add remote file with cache")
  2066. }
  2067. func TestBuildADDRemoteFileWithoutCache(t *testing.T) {
  2068. name := "testbuildaddremotefilewithoutcache"
  2069. name2 := "testbuildaddremotefilewithoutcache2"
  2070. defer deleteImages(name, name2)
  2071. server, err := fakeStorage(map[string]string{
  2072. "baz": "hello",
  2073. })
  2074. if err != nil {
  2075. t.Fatal(err)
  2076. }
  2077. defer server.Close()
  2078. id1, err := buildImage(name,
  2079. fmt.Sprintf(`FROM scratch
  2080. MAINTAINER dockerio
  2081. ADD %s/baz /usr/lib/baz/quux`, server.URL),
  2082. true)
  2083. if err != nil {
  2084. t.Fatal(err)
  2085. }
  2086. id2, err := buildImage(name2,
  2087. fmt.Sprintf(`FROM scratch
  2088. MAINTAINER dockerio
  2089. ADD %s/baz /usr/lib/baz/quux`, server.URL),
  2090. false)
  2091. if err != nil {
  2092. t.Fatal(err)
  2093. }
  2094. if id1 == id2 {
  2095. t.Fatal("The cache should have been invalided but hasn't.")
  2096. }
  2097. logDone("build - add remote file without cache")
  2098. }
  2099. func TestBuildADDRemoteFileMTime(t *testing.T) {
  2100. name := "testbuildaddremotefilemtime"
  2101. name2 := name + "2"
  2102. name3 := name + "3"
  2103. name4 := name + "4"
  2104. defer deleteImages(name, name2, name3, name4)
  2105. server, err := fakeStorage(map[string]string{"baz": "hello"})
  2106. if err != nil {
  2107. t.Fatal(err)
  2108. }
  2109. defer server.Close()
  2110. ctx, err := fakeContext(fmt.Sprintf(`FROM scratch
  2111. MAINTAINER dockerio
  2112. ADD %s/baz /usr/lib/baz/quux`, server.URL), nil)
  2113. if err != nil {
  2114. t.Fatal(err)
  2115. }
  2116. defer ctx.Close()
  2117. id1, err := buildImageFromContext(name, ctx, true)
  2118. if err != nil {
  2119. t.Fatal(err)
  2120. }
  2121. id2, err := buildImageFromContext(name2, ctx, true)
  2122. if err != nil {
  2123. t.Fatal(err)
  2124. }
  2125. if id1 != id2 {
  2126. t.Fatal("The cache should have been used but wasn't - #1")
  2127. }
  2128. // Now set baz's times to anything else and redo the build
  2129. // This time the cache should not be used
  2130. bazPath := path.Join(server.FakeContext.Dir, "baz")
  2131. err = syscall.UtimesNano(bazPath, make([]syscall.Timespec, 2))
  2132. if err != nil {
  2133. t.Fatalf("Error setting mtime on %q: %v", bazPath, err)
  2134. }
  2135. id3, err := buildImageFromContext(name3, ctx, true)
  2136. if err != nil {
  2137. t.Fatal(err)
  2138. }
  2139. if id1 == id3 {
  2140. t.Fatal("The cache should not have been used but was")
  2141. }
  2142. // And for good measure do it again and make sure cache is used this time
  2143. id4, err := buildImageFromContext(name4, ctx, true)
  2144. if err != nil {
  2145. t.Fatal(err)
  2146. }
  2147. if id3 != id4 {
  2148. t.Fatal("The cache should have been used but wasn't - #2")
  2149. }
  2150. logDone("build - add remote file testing mtime")
  2151. }
  2152. func TestBuildADDLocalAndRemoteFilesWithCache(t *testing.T) {
  2153. name := "testbuildaddlocalandremotefilewithcache"
  2154. defer deleteImages(name)
  2155. server, err := fakeStorage(map[string]string{
  2156. "baz": "hello",
  2157. })
  2158. if err != nil {
  2159. t.Fatal(err)
  2160. }
  2161. defer server.Close()
  2162. ctx, err := fakeContext(fmt.Sprintf(`FROM scratch
  2163. MAINTAINER dockerio
  2164. ADD foo /usr/lib/bla/bar
  2165. ADD %s/baz /usr/lib/baz/quux`, server.URL),
  2166. map[string]string{
  2167. "foo": "hello world",
  2168. })
  2169. if err != nil {
  2170. t.Fatal(err)
  2171. }
  2172. defer ctx.Close()
  2173. id1, err := buildImageFromContext(name, ctx, true)
  2174. if err != nil {
  2175. t.Fatal(err)
  2176. }
  2177. id2, err := buildImageFromContext(name, ctx, true)
  2178. if err != nil {
  2179. t.Fatal(err)
  2180. }
  2181. if id1 != id2 {
  2182. t.Fatal("The cache should have been used but hasn't.")
  2183. }
  2184. logDone("build - add local and remote file with cache")
  2185. }
  2186. func testContextTar(t *testing.T, compression archive.Compression) {
  2187. ctx, err := fakeContext(
  2188. `FROM busybox
  2189. ADD foo /foo
  2190. CMD ["cat", "/foo"]`,
  2191. map[string]string{
  2192. "foo": "bar",
  2193. },
  2194. )
  2195. defer ctx.Close()
  2196. if err != nil {
  2197. t.Fatal(err)
  2198. }
  2199. context, err := archive.Tar(ctx.Dir, compression)
  2200. if err != nil {
  2201. t.Fatalf("failed to build context tar: %v", err)
  2202. }
  2203. name := "contexttar"
  2204. buildCmd := exec.Command(dockerBinary, "build", "-t", name, "-")
  2205. defer deleteImages(name)
  2206. buildCmd.Stdin = context
  2207. if out, _, err := runCommandWithOutput(buildCmd); err != nil {
  2208. t.Fatalf("build failed to complete: %v %v", out, err)
  2209. }
  2210. logDone(fmt.Sprintf("build - build an image with a context tar, compression: %v", compression))
  2211. }
  2212. func TestBuildContextTarGzip(t *testing.T) {
  2213. testContextTar(t, archive.Gzip)
  2214. }
  2215. func TestBuildContextTarNoCompression(t *testing.T) {
  2216. testContextTar(t, archive.Uncompressed)
  2217. }
  2218. func TestBuildNoContext(t *testing.T) {
  2219. buildCmd := exec.Command(dockerBinary, "build", "-t", "nocontext", "-")
  2220. buildCmd.Stdin = strings.NewReader("FROM busybox\nCMD echo ok\n")
  2221. if out, _, err := runCommandWithOutput(buildCmd); err != nil {
  2222. t.Fatalf("build failed to complete: %v %v", out, err)
  2223. }
  2224. if out, _, err := dockerCmd(t, "run", "--rm", "nocontext"); out != "ok\n" || err != nil {
  2225. t.Fatalf("run produced invalid output: %q, expected %q", out, "ok")
  2226. }
  2227. deleteImages("nocontext")
  2228. logDone("build - build an image with no context")
  2229. }
  2230. // TODO: TestCaching
  2231. func TestBuildADDLocalAndRemoteFilesWithoutCache(t *testing.T) {
  2232. name := "testbuildaddlocalandremotefilewithoutcache"
  2233. name2 := "testbuildaddlocalandremotefilewithoutcache2"
  2234. defer deleteImages(name, name2)
  2235. server, err := fakeStorage(map[string]string{
  2236. "baz": "hello",
  2237. })
  2238. if err != nil {
  2239. t.Fatal(err)
  2240. }
  2241. defer server.Close()
  2242. ctx, err := fakeContext(fmt.Sprintf(`FROM scratch
  2243. MAINTAINER dockerio
  2244. ADD foo /usr/lib/bla/bar
  2245. ADD %s/baz /usr/lib/baz/quux`, server.URL),
  2246. map[string]string{
  2247. "foo": "hello world",
  2248. })
  2249. if err != nil {
  2250. t.Fatal(err)
  2251. }
  2252. defer ctx.Close()
  2253. id1, err := buildImageFromContext(name, ctx, true)
  2254. if err != nil {
  2255. t.Fatal(err)
  2256. }
  2257. id2, err := buildImageFromContext(name2, ctx, false)
  2258. if err != nil {
  2259. t.Fatal(err)
  2260. }
  2261. if id1 == id2 {
  2262. t.Fatal("The cache should have been invalided but hasn't.")
  2263. }
  2264. logDone("build - add local and remote file without cache")
  2265. }
  2266. func TestBuildWithVolumeOwnership(t *testing.T) {
  2267. name := "testbuildimg"
  2268. defer deleteImages(name)
  2269. _, err := buildImage(name,
  2270. `FROM busybox:latest
  2271. RUN mkdir /test && chown daemon:daemon /test && chmod 0600 /test
  2272. VOLUME /test`,
  2273. true)
  2274. if err != nil {
  2275. t.Fatal(err)
  2276. }
  2277. cmd := exec.Command(dockerBinary, "run", "--rm", "testbuildimg", "ls", "-la", "/test")
  2278. out, _, err := runCommandWithOutput(cmd)
  2279. if err != nil {
  2280. t.Fatal(out, err)
  2281. }
  2282. if expected := "drw-------"; !strings.Contains(out, expected) {
  2283. t.Fatalf("expected %s received %s", expected, out)
  2284. }
  2285. if expected := "daemon daemon"; !strings.Contains(out, expected) {
  2286. t.Fatalf("expected %s received %s", expected, out)
  2287. }
  2288. logDone("build - volume ownership")
  2289. }
  2290. // testing #1405 - config.Cmd does not get cleaned up if
  2291. // utilizing cache
  2292. func TestBuildEntrypointRunCleanup(t *testing.T) {
  2293. name := "testbuildcmdcleanup"
  2294. defer deleteImages(name)
  2295. if _, err := buildImage(name,
  2296. `FROM busybox
  2297. RUN echo "hello"`,
  2298. true); err != nil {
  2299. t.Fatal(err)
  2300. }
  2301. ctx, err := fakeContext(`FROM busybox
  2302. RUN echo "hello"
  2303. ADD foo /foo
  2304. ENTRYPOINT ["/bin/echo"]`,
  2305. map[string]string{
  2306. "foo": "hello",
  2307. })
  2308. defer ctx.Close()
  2309. if err != nil {
  2310. t.Fatal(err)
  2311. }
  2312. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  2313. t.Fatal(err)
  2314. }
  2315. res, err := inspectField(name, "Config.Cmd")
  2316. if err != nil {
  2317. t.Fatal(err)
  2318. }
  2319. // Cmd must be cleaned up
  2320. if expected := "<no value>"; res != expected {
  2321. t.Fatalf("Cmd %s, expected %s", res, expected)
  2322. }
  2323. logDone("build - cleanup cmd after RUN")
  2324. }
  2325. func TestBuildForbiddenContextPath(t *testing.T) {
  2326. name := "testbuildforbidpath"
  2327. defer deleteImages(name)
  2328. ctx, err := fakeContext(`FROM scratch
  2329. ADD ../../ test/
  2330. `,
  2331. map[string]string{
  2332. "test.txt": "test1",
  2333. "other.txt": "other",
  2334. })
  2335. defer ctx.Close()
  2336. if err != nil {
  2337. t.Fatal(err)
  2338. }
  2339. expected := "Forbidden path outside the build context: ../../ "
  2340. if _, err := buildImageFromContext(name, ctx, true); err == nil || !strings.Contains(err.Error(), expected) {
  2341. t.Fatalf("Wrong error: (should contain \"%s\") got:\n%v", expected, err)
  2342. }
  2343. logDone("build - forbidden context path")
  2344. }
  2345. func TestBuildADDFileNotFound(t *testing.T) {
  2346. name := "testbuildaddnotfound"
  2347. defer deleteImages(name)
  2348. ctx, err := fakeContext(`FROM scratch
  2349. ADD foo /usr/local/bar`,
  2350. map[string]string{"bar": "hello"})
  2351. defer ctx.Close()
  2352. if err != nil {
  2353. t.Fatal(err)
  2354. }
  2355. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  2356. if !strings.Contains(err.Error(), "foo: no such file or directory") {
  2357. t.Fatalf("Wrong error %v, must be about missing foo file or directory", err)
  2358. }
  2359. } else {
  2360. t.Fatal("Error must not be nil")
  2361. }
  2362. logDone("build - add file not found")
  2363. }
  2364. func TestBuildInheritance(t *testing.T) {
  2365. name := "testbuildinheritance"
  2366. defer deleteImages(name)
  2367. _, err := buildImage(name,
  2368. `FROM scratch
  2369. EXPOSE 2375`,
  2370. true)
  2371. if err != nil {
  2372. t.Fatal(err)
  2373. }
  2374. ports1, err := inspectField(name, "Config.ExposedPorts")
  2375. if err != nil {
  2376. t.Fatal(err)
  2377. }
  2378. _, err = buildImage(name,
  2379. fmt.Sprintf(`FROM %s
  2380. ENTRYPOINT ["/bin/echo"]`, name),
  2381. true)
  2382. if err != nil {
  2383. t.Fatal(err)
  2384. }
  2385. res, err := inspectField(name, "Config.Entrypoint")
  2386. if err != nil {
  2387. t.Fatal(err)
  2388. }
  2389. if expected := "[/bin/echo]"; res != expected {
  2390. t.Fatalf("Entrypoint %s, expected %s", res, expected)
  2391. }
  2392. ports2, err := inspectField(name, "Config.ExposedPorts")
  2393. if err != nil {
  2394. t.Fatal(err)
  2395. }
  2396. if ports1 != ports2 {
  2397. t.Fatalf("Ports must be same: %s != %s", ports1, ports2)
  2398. }
  2399. logDone("build - inheritance")
  2400. }
  2401. func TestBuildFails(t *testing.T) {
  2402. name := "testbuildfails"
  2403. defer deleteImages(name)
  2404. defer deleteAllContainers()
  2405. _, err := buildImage(name,
  2406. `FROM busybox
  2407. RUN sh -c "exit 23"`,
  2408. true)
  2409. if err != nil {
  2410. if !strings.Contains(err.Error(), "returned a non-zero code: 23") {
  2411. t.Fatalf("Wrong error %v, must be about non-zero code 23", err)
  2412. }
  2413. } else {
  2414. t.Fatal("Error must not be nil")
  2415. }
  2416. logDone("build - fails")
  2417. }
  2418. func TestBuildFailsDockerfileEmpty(t *testing.T) {
  2419. name := "testbuildfails"
  2420. defer deleteImages(name)
  2421. _, err := buildImage(name, ``, true)
  2422. if err != nil {
  2423. if !strings.Contains(err.Error(), "Dockerfile cannot be empty") {
  2424. t.Fatalf("Wrong error %v, must be about empty Dockerfile", err)
  2425. }
  2426. } else {
  2427. t.Fatal("Error must not be nil")
  2428. }
  2429. logDone("build - fails with empty dockerfile")
  2430. }
  2431. func TestBuildOnBuild(t *testing.T) {
  2432. name := "testbuildonbuild"
  2433. defer deleteImages(name)
  2434. _, err := buildImage(name,
  2435. `FROM busybox
  2436. ONBUILD RUN touch foobar`,
  2437. true)
  2438. if err != nil {
  2439. t.Fatal(err)
  2440. }
  2441. _, err = buildImage(name,
  2442. fmt.Sprintf(`FROM %s
  2443. RUN [ -f foobar ]`, name),
  2444. true)
  2445. if err != nil {
  2446. t.Fatal(err)
  2447. }
  2448. logDone("build - onbuild")
  2449. }
  2450. func TestBuildOnBuildForbiddenChained(t *testing.T) {
  2451. name := "testbuildonbuildforbiddenchained"
  2452. defer deleteImages(name)
  2453. _, err := buildImage(name,
  2454. `FROM busybox
  2455. ONBUILD ONBUILD RUN touch foobar`,
  2456. true)
  2457. if err != nil {
  2458. if !strings.Contains(err.Error(), "Chaining ONBUILD via `ONBUILD ONBUILD` isn't allowed") {
  2459. t.Fatalf("Wrong error %v, must be about chaining ONBUILD", err)
  2460. }
  2461. } else {
  2462. t.Fatal("Error must not be nil")
  2463. }
  2464. logDone("build - onbuild forbidden chained")
  2465. }
  2466. func TestBuildOnBuildForbiddenFrom(t *testing.T) {
  2467. name := "testbuildonbuildforbiddenfrom"
  2468. defer deleteImages(name)
  2469. _, err := buildImage(name,
  2470. `FROM busybox
  2471. ONBUILD FROM scratch`,
  2472. true)
  2473. if err != nil {
  2474. if !strings.Contains(err.Error(), "FROM isn't allowed as an ONBUILD trigger") {
  2475. t.Fatalf("Wrong error %v, must be about FROM forbidden", err)
  2476. }
  2477. } else {
  2478. t.Fatal("Error must not be nil")
  2479. }
  2480. logDone("build - onbuild forbidden from")
  2481. }
  2482. func TestBuildOnBuildForbiddenMaintainer(t *testing.T) {
  2483. name := "testbuildonbuildforbiddenmaintainer"
  2484. defer deleteImages(name)
  2485. _, err := buildImage(name,
  2486. `FROM busybox
  2487. ONBUILD MAINTAINER docker.io`,
  2488. true)
  2489. if err != nil {
  2490. if !strings.Contains(err.Error(), "MAINTAINER isn't allowed as an ONBUILD trigger") {
  2491. t.Fatalf("Wrong error %v, must be about MAINTAINER forbidden", err)
  2492. }
  2493. } else {
  2494. t.Fatal("Error must not be nil")
  2495. }
  2496. logDone("build - onbuild forbidden maintainer")
  2497. }
  2498. // gh #2446
  2499. func TestBuildAddToSymlinkDest(t *testing.T) {
  2500. name := "testbuildaddtosymlinkdest"
  2501. defer deleteImages(name)
  2502. ctx, err := fakeContext(`FROM busybox
  2503. RUN mkdir /foo
  2504. RUN ln -s /foo /bar
  2505. ADD foo /bar/
  2506. RUN [ -f /bar/foo ]
  2507. RUN [ -f /foo/foo ]`,
  2508. map[string]string{
  2509. "foo": "hello",
  2510. })
  2511. if err != nil {
  2512. t.Fatal(err)
  2513. }
  2514. defer ctx.Close()
  2515. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  2516. t.Fatal(err)
  2517. }
  2518. logDone("build - add to symlink destination")
  2519. }
  2520. func TestBuildEscapeWhitespace(t *testing.T) {
  2521. name := "testbuildescaping"
  2522. defer deleteImages(name)
  2523. _, err := buildImage(name, `
  2524. FROM busybox
  2525. MAINTAINER "Docker \
  2526. IO <io@\
  2527. docker.com>"
  2528. `, true)
  2529. res, err := inspectField(name, "Author")
  2530. if err != nil {
  2531. t.Fatal(err)
  2532. }
  2533. if res != "Docker IO <io@docker.com>" {
  2534. t.Fatal("Parsed string did not match the escaped string")
  2535. }
  2536. logDone("build - validate escaping whitespace")
  2537. }
  2538. func TestBuildDockerignore(t *testing.T) {
  2539. name := "testbuilddockerignore"
  2540. defer deleteImages(name)
  2541. dockerfile := `
  2542. FROM busybox
  2543. ADD . /bla
  2544. RUN [[ -f /bla/src/x.go ]]
  2545. RUN [[ -f /bla/Makefile ]]
  2546. RUN [[ ! -e /bla/src/_vendor ]]
  2547. RUN [[ ! -e /bla/.gitignore ]]
  2548. RUN [[ ! -e /bla/README.md ]]
  2549. RUN [[ ! -e /bla/.git ]]`
  2550. ctx, err := fakeContext(dockerfile, map[string]string{
  2551. "Makefile": "all:",
  2552. ".git/HEAD": "ref: foo",
  2553. "src/x.go": "package main",
  2554. "src/_vendor/v.go": "package main",
  2555. ".gitignore": "",
  2556. "README.md": "readme",
  2557. ".dockerignore": ".git\npkg\n.gitignore\nsrc/_vendor\n*.md",
  2558. })
  2559. defer ctx.Close()
  2560. if err != nil {
  2561. t.Fatal(err)
  2562. }
  2563. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  2564. t.Fatal(err)
  2565. }
  2566. logDone("build - test .dockerignore")
  2567. }
  2568. func TestBuildDockerignoreCleanPaths(t *testing.T) {
  2569. name := "testbuilddockerignorecleanpaths"
  2570. defer deleteImages(name)
  2571. dockerfile := `
  2572. FROM busybox
  2573. ADD . /tmp/
  2574. RUN (! ls /tmp/foo) && (! ls /tmp/foo2) && (! ls /tmp/dir1/foo)`
  2575. ctx, err := fakeContext(dockerfile, map[string]string{
  2576. "foo": "foo",
  2577. "foo2": "foo2",
  2578. "dir1/foo": "foo in dir1",
  2579. ".dockerignore": "./foo\ndir1//foo\n./dir1/../foo2",
  2580. })
  2581. if err != nil {
  2582. t.Fatal(err)
  2583. }
  2584. defer ctx.Close()
  2585. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  2586. t.Fatal(err)
  2587. }
  2588. logDone("build - test .dockerignore with clean paths")
  2589. }
  2590. func TestBuildDockerignoringDockerfile(t *testing.T) {
  2591. name := "testbuilddockerignoredockerfile"
  2592. defer deleteImages(name)
  2593. dockerfile := `
  2594. FROM scratch`
  2595. ctx, err := fakeContext(dockerfile, map[string]string{
  2596. "Dockerfile": "FROM scratch",
  2597. ".dockerignore": "Dockerfile\n",
  2598. })
  2599. if err != nil {
  2600. t.Fatal(err)
  2601. }
  2602. defer ctx.Close()
  2603. if _, err = buildImageFromContext(name, ctx, true); err == nil {
  2604. t.Fatalf("Didn't get expected error from ignoring Dockerfile")
  2605. }
  2606. // now try it with ./Dockerfile
  2607. ctx.Add(".dockerignore", "./Dockerfile\n")
  2608. if _, err = buildImageFromContext(name, ctx, true); err == nil {
  2609. t.Fatalf("Didn't get expected error from ignoring ./Dockerfile")
  2610. }
  2611. logDone("build - test .dockerignore of Dockerfile")
  2612. }
  2613. func TestBuildDockerignoringWholeDir(t *testing.T) {
  2614. name := "testbuilddockerignorewholedir"
  2615. defer deleteImages(name)
  2616. dockerfile := `
  2617. FROM busybox
  2618. COPY . /
  2619. RUN [[ ! -e /.gitignore ]]
  2620. RUN [[ -f /Makefile ]]`
  2621. ctx, err := fakeContext(dockerfile, map[string]string{
  2622. "Dockerfile": "FROM scratch",
  2623. "Makefile": "all:",
  2624. ".dockerignore": ".*\n",
  2625. })
  2626. defer ctx.Close()
  2627. if err != nil {
  2628. t.Fatal(err)
  2629. }
  2630. if _, err = buildImageFromContext(name, ctx, true); err != nil {
  2631. t.Fatal(err)
  2632. }
  2633. logDone("build - test .dockerignore whole dir with .*")
  2634. }
  2635. func TestBuildLineBreak(t *testing.T) {
  2636. name := "testbuildlinebreak"
  2637. defer deleteImages(name)
  2638. _, err := buildImage(name,
  2639. `FROM busybox
  2640. RUN sh -c 'echo root:testpass \
  2641. > /tmp/passwd'
  2642. RUN mkdir -p /var/run/sshd
  2643. RUN [ "$(cat /tmp/passwd)" = "root:testpass" ]
  2644. RUN [ "$(ls -d /var/run/sshd)" = "/var/run/sshd" ]`,
  2645. true)
  2646. if err != nil {
  2647. t.Fatal(err)
  2648. }
  2649. logDone("build - line break with \\")
  2650. }
  2651. func TestBuildEOLInLine(t *testing.T) {
  2652. name := "testbuildeolinline"
  2653. defer deleteImages(name)
  2654. _, err := buildImage(name,
  2655. `FROM busybox
  2656. RUN sh -c 'echo root:testpass > /tmp/passwd'
  2657. RUN echo "foo \n bar"; echo "baz"
  2658. RUN mkdir -p /var/run/sshd
  2659. RUN [ "$(cat /tmp/passwd)" = "root:testpass" ]
  2660. RUN [ "$(ls -d /var/run/sshd)" = "/var/run/sshd" ]`,
  2661. true)
  2662. if err != nil {
  2663. t.Fatal(err)
  2664. }
  2665. logDone("build - end of line in dockerfile instruction")
  2666. }
  2667. func TestBuildCommentsShebangs(t *testing.T) {
  2668. name := "testbuildcomments"
  2669. defer deleteImages(name)
  2670. _, err := buildImage(name,
  2671. `FROM busybox
  2672. # This is an ordinary comment.
  2673. RUN { echo '#!/bin/sh'; echo 'echo hello world'; } > /hello.sh
  2674. RUN [ ! -x /hello.sh ]
  2675. # comment with line break \
  2676. RUN chmod +x /hello.sh
  2677. RUN [ -x /hello.sh ]
  2678. RUN [ "$(cat /hello.sh)" = $'#!/bin/sh\necho hello world' ]
  2679. RUN [ "$(/hello.sh)" = "hello world" ]`,
  2680. true)
  2681. if err != nil {
  2682. t.Fatal(err)
  2683. }
  2684. logDone("build - comments and shebangs")
  2685. }
  2686. func TestBuildUsersAndGroups(t *testing.T) {
  2687. name := "testbuildusers"
  2688. defer deleteImages(name)
  2689. _, err := buildImage(name,
  2690. `FROM busybox
  2691. # Make sure our defaults work
  2692. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)" = '0:0/root:root' ]
  2693. # TODO decide if "args.user = strconv.Itoa(syscall.Getuid())" is acceptable behavior for changeUser in sysvinit instead of "return nil" when "USER" isn't specified (so that we get the proper group list even if that is the empty list, even in the default case of not supplying an explicit USER to run as, which implies USER 0)
  2694. USER root
  2695. RUN [ "$(id -G):$(id -Gn)" = '0 10:root wheel' ]
  2696. # Setup dockerio user and group
  2697. RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd
  2698. RUN echo 'dockerio:x:1001:' >> /etc/group
  2699. # Make sure we can switch to our user and all the information is exactly as we expect it to be
  2700. USER dockerio
  2701. RUN id -G
  2702. RUN id -Gn
  2703. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1001:1001/dockerio:dockerio/1001:dockerio' ]
  2704. # Switch back to root and double check that worked exactly as we might expect it to
  2705. USER root
  2706. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '0:0/root:root/0 10:root wheel' ]
  2707. # Add a "supplementary" group for our dockerio user
  2708. RUN echo 'supplementary:x:1002:dockerio' >> /etc/group
  2709. # ... and then go verify that we get it like we expect
  2710. USER dockerio
  2711. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1001:1001/dockerio:dockerio/1001 1002:dockerio supplementary' ]
  2712. USER 1001
  2713. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1001:1001/dockerio:dockerio/1001 1002:dockerio supplementary' ]
  2714. # super test the new "user:group" syntax
  2715. USER dockerio:dockerio
  2716. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1001:1001/dockerio:dockerio/1001:dockerio' ]
  2717. USER 1001:dockerio
  2718. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1001:1001/dockerio:dockerio/1001:dockerio' ]
  2719. USER dockerio:1001
  2720. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1001:1001/dockerio:dockerio/1001:dockerio' ]
  2721. USER 1001:1001
  2722. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1001:1001/dockerio:dockerio/1001:dockerio' ]
  2723. USER dockerio:supplementary
  2724. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1001:1002/dockerio:supplementary/1002:supplementary' ]
  2725. USER dockerio:1002
  2726. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1001:1002/dockerio:supplementary/1002:supplementary' ]
  2727. USER 1001:supplementary
  2728. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1001:1002/dockerio:supplementary/1002:supplementary' ]
  2729. USER 1001:1002
  2730. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1001:1002/dockerio:supplementary/1002:supplementary' ]
  2731. # make sure unknown uid/gid still works properly
  2732. USER 1042:1043
  2733. RUN [ "$(id -u):$(id -g)/$(id -un):$(id -gn)/$(id -G):$(id -Gn)" = '1042:1043/1042:1043/1043:1043' ]`,
  2734. true)
  2735. if err != nil {
  2736. t.Fatal(err)
  2737. }
  2738. logDone("build - users and groups")
  2739. }
  2740. func TestBuildEnvUsage(t *testing.T) {
  2741. name := "testbuildenvusage"
  2742. defer deleteImages(name)
  2743. dockerfile := `FROM busybox
  2744. ENV HOME /root
  2745. ENV PATH $HOME/bin:$PATH
  2746. ENV PATH /tmp:$PATH
  2747. RUN [ "$PATH" = "/tmp:$HOME/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" ]
  2748. ENV FOO /foo/baz
  2749. ENV BAR /bar
  2750. ENV BAZ $BAR
  2751. ENV FOOPATH $PATH:$FOO
  2752. RUN [ "$BAR" = "$BAZ" ]
  2753. RUN [ "$FOOPATH" = "$PATH:/foo/baz" ]
  2754. ENV FROM hello/docker/world
  2755. ENV TO /docker/world/hello
  2756. ADD $FROM $TO
  2757. RUN [ "$(cat $TO)" = "hello" ]
  2758. `
  2759. ctx, err := fakeContext(dockerfile, map[string]string{
  2760. "hello/docker/world": "hello",
  2761. })
  2762. if err != nil {
  2763. t.Fatal(err)
  2764. }
  2765. defer ctx.Close()
  2766. _, err = buildImageFromContext(name, ctx, true)
  2767. if err != nil {
  2768. t.Fatal(err)
  2769. }
  2770. logDone("build - environment variables usage")
  2771. }
  2772. func TestBuildEnvUsage2(t *testing.T) {
  2773. name := "testbuildenvusage2"
  2774. defer deleteImages(name)
  2775. dockerfile := `FROM busybox
  2776. ENV abc=def
  2777. RUN [ "$abc" = "def" ]
  2778. ENV def="hello world"
  2779. RUN [ "$def" = "hello world" ]
  2780. ENV def=hello\ world
  2781. RUN [ "$def" = "hello world" ]
  2782. ENV v1=abc v2="hi there"
  2783. RUN [ "$v1" = "abc" ]
  2784. RUN [ "$v2" = "hi there" ]
  2785. ENV v3='boogie nights' v4="with'quotes too"
  2786. RUN [ "$v3" = "boogie nights" ]
  2787. RUN [ "$v4" = "with'quotes too" ]
  2788. ENV abc=zzz FROM=hello/docker/world
  2789. ENV abc=zzz TO=/docker/world/hello
  2790. ADD $FROM $TO
  2791. RUN [ "$(cat $TO)" = "hello" ]
  2792. ENV abc "zzz"
  2793. RUN [ $abc = \"zzz\" ]
  2794. ENV abc 'yyy'
  2795. RUN [ $abc = \'yyy\' ]
  2796. ENV abc=
  2797. RUN [ "$abc" = "" ]
  2798. `
  2799. ctx, err := fakeContext(dockerfile, map[string]string{
  2800. "hello/docker/world": "hello",
  2801. })
  2802. if err != nil {
  2803. t.Fatal(err)
  2804. }
  2805. _, err = buildImageFromContext(name, ctx, true)
  2806. if err != nil {
  2807. t.Fatal(err)
  2808. }
  2809. logDone("build - environment variables usage2")
  2810. }
  2811. func TestBuildAddScript(t *testing.T) {
  2812. name := "testbuildaddscript"
  2813. defer deleteImages(name)
  2814. dockerfile := `
  2815. FROM busybox
  2816. ADD test /test
  2817. RUN ["chmod","+x","/test"]
  2818. RUN ["/test"]
  2819. RUN [ "$(cat /testfile)" = 'test!' ]`
  2820. ctx, err := fakeContext(dockerfile, map[string]string{
  2821. "test": "#!/bin/sh\necho 'test!' > /testfile",
  2822. })
  2823. if err != nil {
  2824. t.Fatal(err)
  2825. }
  2826. defer ctx.Close()
  2827. _, err = buildImageFromContext(name, ctx, true)
  2828. if err != nil {
  2829. t.Fatal(err)
  2830. }
  2831. logDone("build - add and run script")
  2832. }
  2833. func TestBuildAddTar(t *testing.T) {
  2834. name := "testbuildaddtar"
  2835. defer deleteImages(name)
  2836. ctx := func() *FakeContext {
  2837. dockerfile := `
  2838. FROM busybox
  2839. ADD test.tar /
  2840. RUN cat /test/foo | grep Hi
  2841. ADD test.tar /test.tar
  2842. RUN cat /test.tar/test/foo | grep Hi
  2843. ADD test.tar /unlikely-to-exist
  2844. RUN cat /unlikely-to-exist/test/foo | grep Hi
  2845. ADD test.tar /unlikely-to-exist-trailing-slash/
  2846. RUN cat /unlikely-to-exist-trailing-slash/test/foo | grep Hi
  2847. RUN mkdir /existing-directory
  2848. ADD test.tar /existing-directory
  2849. RUN cat /existing-directory/test/foo | grep Hi
  2850. ADD test.tar /existing-directory-trailing-slash/
  2851. RUN cat /existing-directory-trailing-slash/test/foo | grep Hi`
  2852. tmpDir, err := ioutil.TempDir("", "fake-context")
  2853. testTar, err := os.Create(filepath.Join(tmpDir, "test.tar"))
  2854. if err != nil {
  2855. t.Fatalf("failed to create test.tar archive: %v", err)
  2856. }
  2857. defer testTar.Close()
  2858. tw := tar.NewWriter(testTar)
  2859. if err := tw.WriteHeader(&tar.Header{
  2860. Name: "test/foo",
  2861. Size: 2,
  2862. }); err != nil {
  2863. t.Fatalf("failed to write tar file header: %v", err)
  2864. }
  2865. if _, err := tw.Write([]byte("Hi")); err != nil {
  2866. t.Fatalf("failed to write tar file content: %v", err)
  2867. }
  2868. if err := tw.Close(); err != nil {
  2869. t.Fatalf("failed to close tar archive: %v", err)
  2870. }
  2871. if err := ioutil.WriteFile(filepath.Join(tmpDir, "Dockerfile"), []byte(dockerfile), 0644); err != nil {
  2872. t.Fatalf("failed to open destination dockerfile: %v", err)
  2873. }
  2874. return &FakeContext{Dir: tmpDir}
  2875. }()
  2876. defer ctx.Close()
  2877. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  2878. t.Fatalf("build failed to complete for TestBuildAddTar: %v", err)
  2879. }
  2880. logDone("build - ADD tar")
  2881. }
  2882. func TestBuildFromGIT(t *testing.T) {
  2883. name := "testbuildfromgit"
  2884. defer deleteImages(name)
  2885. git, err := fakeGIT("repo", map[string]string{
  2886. "Dockerfile": `FROM busybox
  2887. ADD first /first
  2888. RUN [ -f /first ]
  2889. MAINTAINER docker`,
  2890. "first": "test git data",
  2891. })
  2892. if err != nil {
  2893. t.Fatal(err)
  2894. }
  2895. defer git.Close()
  2896. _, err = buildImageFromPath(name, git.RepoURL, true)
  2897. if err != nil {
  2898. t.Fatal(err)
  2899. }
  2900. res, err := inspectField(name, "Author")
  2901. if err != nil {
  2902. t.Fatal(err)
  2903. }
  2904. if res != "docker" {
  2905. t.Fatalf("Maintainer should be docker, got %s", res)
  2906. }
  2907. logDone("build - build from GIT")
  2908. }
  2909. func TestBuildCleanupCmdOnEntrypoint(t *testing.T) {
  2910. name := "testbuildcmdcleanuponentrypoint"
  2911. defer deleteImages(name)
  2912. if _, err := buildImage(name,
  2913. `FROM scratch
  2914. CMD ["test"]
  2915. ENTRYPOINT ["echo"]`,
  2916. true); err != nil {
  2917. t.Fatal(err)
  2918. }
  2919. if _, err := buildImage(name,
  2920. fmt.Sprintf(`FROM %s
  2921. ENTRYPOINT ["cat"]`, name),
  2922. true); err != nil {
  2923. t.Fatal(err)
  2924. }
  2925. res, err := inspectField(name, "Config.Cmd")
  2926. if err != nil {
  2927. t.Fatal(err)
  2928. }
  2929. if expected := "<no value>"; res != expected {
  2930. t.Fatalf("Cmd %s, expected %s", res, expected)
  2931. }
  2932. res, err = inspectField(name, "Config.Entrypoint")
  2933. if err != nil {
  2934. t.Fatal(err)
  2935. }
  2936. if expected := "[cat]"; res != expected {
  2937. t.Fatalf("Entrypoint %s, expected %s", res, expected)
  2938. }
  2939. logDone("build - cleanup cmd on ENTRYPOINT")
  2940. }
  2941. func TestBuildClearCmd(t *testing.T) {
  2942. name := "testbuildclearcmd"
  2943. defer deleteImages(name)
  2944. _, err := buildImage(name,
  2945. `From scratch
  2946. ENTRYPOINT ["/bin/bash"]
  2947. CMD []`,
  2948. true)
  2949. if err != nil {
  2950. t.Fatal(err)
  2951. }
  2952. res, err := inspectFieldJSON(name, "Config.Cmd")
  2953. if err != nil {
  2954. t.Fatal(err)
  2955. }
  2956. if res != "[]" {
  2957. t.Fatalf("Cmd %s, expected %s", res, "[]")
  2958. }
  2959. logDone("build - clearcmd")
  2960. }
  2961. func TestBuildEmptyCmd(t *testing.T) {
  2962. name := "testbuildemptycmd"
  2963. defer deleteImages(name)
  2964. if _, err := buildImage(name, "FROM scratch\nMAINTAINER quux\n", true); err != nil {
  2965. t.Fatal(err)
  2966. }
  2967. res, err := inspectFieldJSON(name, "Config.Cmd")
  2968. if err != nil {
  2969. t.Fatal(err)
  2970. }
  2971. if res != "null" {
  2972. t.Fatalf("Cmd %s, expected %s", res, "null")
  2973. }
  2974. logDone("build - empty cmd")
  2975. }
  2976. func TestBuildOnBuildOutput(t *testing.T) {
  2977. name := "testbuildonbuildparent"
  2978. defer deleteImages(name)
  2979. if _, err := buildImage(name, "FROM busybox\nONBUILD RUN echo foo\n", true); err != nil {
  2980. t.Fatal(err)
  2981. }
  2982. childname := "testbuildonbuildchild"
  2983. defer deleteImages(childname)
  2984. _, out, err := buildImageWithOut(name, "FROM "+name+"\nMAINTAINER quux\n", true)
  2985. if err != nil {
  2986. t.Fatal(err)
  2987. }
  2988. if !strings.Contains(out, "Trigger 0, RUN echo foo") {
  2989. t.Fatal("failed to find the ONBUILD output", out)
  2990. }
  2991. logDone("build - onbuild output")
  2992. }
  2993. func TestBuildInvalidTag(t *testing.T) {
  2994. name := "abcd:" + makeRandomString(200)
  2995. defer deleteImages(name)
  2996. _, out, err := buildImageWithOut(name, "FROM scratch\nMAINTAINER quux\n", true)
  2997. // if the error doesnt check for illegal tag name, or the image is built
  2998. // then this should fail
  2999. if !strings.Contains(out, "Illegal tag name") || strings.Contains(out, "Sending build context to Docker daemon") {
  3000. t.Fatalf("failed to stop before building. Error: %s, Output: %s", err, out)
  3001. }
  3002. logDone("build - invalid tag")
  3003. }
  3004. func TestBuildCmdShDashC(t *testing.T) {
  3005. name := "testbuildcmdshc"
  3006. defer deleteImages(name)
  3007. if _, err := buildImage(name, "FROM busybox\nCMD echo cmd\n", true); err != nil {
  3008. t.Fatal(err)
  3009. }
  3010. res, err := inspectFieldJSON(name, "Config.Cmd")
  3011. if err != nil {
  3012. t.Fatal(err, res)
  3013. }
  3014. expected := `["/bin/sh","-c","echo cmd"]`
  3015. if res != expected {
  3016. t.Fatalf("Expected value %s not in Config.Cmd: %s", expected, res)
  3017. }
  3018. logDone("build - cmd should have sh -c for non-json")
  3019. }
  3020. func TestBuildCmdJSONNoShDashC(t *testing.T) {
  3021. name := "testbuildcmdjson"
  3022. defer deleteImages(name)
  3023. if _, err := buildImage(name, "FROM busybox\nCMD [\"echo\", \"cmd\"]", true); err != nil {
  3024. t.Fatal(err)
  3025. }
  3026. res, err := inspectFieldJSON(name, "Config.Cmd")
  3027. if err != nil {
  3028. t.Fatal(err, res)
  3029. }
  3030. expected := `["echo","cmd"]`
  3031. if res != expected {
  3032. t.Fatalf("Expected value %s not in Config.Cmd: %s", expected, res)
  3033. }
  3034. logDone("build - cmd should not have /bin/sh -c for json")
  3035. }
  3036. func TestBuildIgnoreInvalidInstruction(t *testing.T) {
  3037. name := "testbuildignoreinvalidinstruction"
  3038. defer deleteImages(name)
  3039. out, _, err := buildImageWithOut(name, "FROM busybox\nfoo bar", true)
  3040. if err != nil {
  3041. t.Fatal(err, out)
  3042. }
  3043. logDone("build - ignore invalid Dockerfile instruction")
  3044. }
  3045. func TestBuildEntrypointInheritance(t *testing.T) {
  3046. defer deleteImages("parent", "child")
  3047. defer deleteAllContainers()
  3048. if _, err := buildImage("parent", `
  3049. FROM busybox
  3050. ENTRYPOINT exit 130
  3051. `, true); err != nil {
  3052. t.Fatal(err)
  3053. }
  3054. status, _ := runCommand(exec.Command(dockerBinary, "run", "parent"))
  3055. if status != 130 {
  3056. t.Fatalf("expected exit code 130 but received %d", status)
  3057. }
  3058. if _, err := buildImage("child", `
  3059. FROM parent
  3060. ENTRYPOINT exit 5
  3061. `, true); err != nil {
  3062. t.Fatal(err)
  3063. }
  3064. status, _ = runCommand(exec.Command(dockerBinary, "run", "child"))
  3065. if status != 5 {
  3066. t.Fatalf("expected exit code 5 but received %d", status)
  3067. }
  3068. logDone("build - clear entrypoint")
  3069. }
  3070. func TestBuildEntrypointInheritanceInspect(t *testing.T) {
  3071. var (
  3072. name = "testbuildepinherit"
  3073. name2 = "testbuildepinherit2"
  3074. expected = `["/bin/sh","-c","echo quux"]`
  3075. )
  3076. defer deleteImages(name, name2)
  3077. defer deleteAllContainers()
  3078. if _, err := buildImage(name, "FROM busybox\nENTRYPOINT /foo/bar", true); err != nil {
  3079. t.Fatal(err)
  3080. }
  3081. if _, err := buildImage(name2, fmt.Sprintf("FROM %s\nENTRYPOINT echo quux", name), true); err != nil {
  3082. t.Fatal(err)
  3083. }
  3084. res, err := inspectFieldJSON(name2, "Config.Entrypoint")
  3085. if err != nil {
  3086. t.Fatal(err, res)
  3087. }
  3088. if res != expected {
  3089. t.Fatalf("Expected value %s not in Config.Entrypoint: %s", expected, res)
  3090. }
  3091. out, _, err := runCommandWithOutput(exec.Command(dockerBinary, "run", "-t", name2))
  3092. if err != nil {
  3093. t.Fatal(err, out)
  3094. }
  3095. expected = "quux"
  3096. if strings.TrimSpace(out) != expected {
  3097. t.Fatalf("Expected output is %s, got %s", expected, out)
  3098. }
  3099. logDone("build - entrypoint override inheritance properly")
  3100. }
  3101. func TestBuildRunShEntrypoint(t *testing.T) {
  3102. name := "testbuildentrypoint"
  3103. defer deleteImages(name)
  3104. _, err := buildImage(name,
  3105. `FROM busybox
  3106. ENTRYPOINT /bin/echo`,
  3107. true)
  3108. if err != nil {
  3109. t.Fatal(err)
  3110. }
  3111. out, _, err := runCommandWithOutput(exec.Command(dockerBinary, "run", "--rm", name))
  3112. if err != nil {
  3113. t.Fatal(err, out)
  3114. }
  3115. logDone("build - entrypoint with /bin/echo running successfully")
  3116. }
  3117. func TestBuildExoticShellInterpolation(t *testing.T) {
  3118. name := "testbuildexoticshellinterpolation"
  3119. defer deleteImages(name)
  3120. _, err := buildImage(name, `
  3121. FROM busybox
  3122. ENV SOME_VAR a.b.c
  3123. RUN [ "$SOME_VAR" = 'a.b.c' ]
  3124. RUN [ "${SOME_VAR}" = 'a.b.c' ]
  3125. RUN [ "${SOME_VAR%.*}" = 'a.b' ]
  3126. RUN [ "${SOME_VAR%%.*}" = 'a' ]
  3127. RUN [ "${SOME_VAR#*.}" = 'b.c' ]
  3128. RUN [ "${SOME_VAR##*.}" = 'c' ]
  3129. RUN [ "${SOME_VAR/c/d}" = 'a.b.d' ]
  3130. RUN [ "${#SOME_VAR}" = '5' ]
  3131. RUN [ "${SOME_UNSET_VAR:-$SOME_VAR}" = 'a.b.c' ]
  3132. RUN [ "${SOME_VAR:+Version: ${SOME_VAR}}" = 'Version: a.b.c' ]
  3133. RUN [ "${SOME_UNSET_VAR:+${SOME_VAR}}" = '' ]
  3134. RUN [ "${SOME_UNSET_VAR:-${SOME_VAR:-d.e.f}}" = 'a.b.c' ]
  3135. `, false)
  3136. if err != nil {
  3137. t.Fatal(err)
  3138. }
  3139. logDone("build - exotic shell interpolation")
  3140. }
  3141. func TestBuildVerifySingleQuoteFails(t *testing.T) {
  3142. // This testcase is supposed to generate an error because the
  3143. // JSON array we're passing in on the CMD uses single quotes instead
  3144. // of double quotes (per the JSON spec). This means we interpret it
  3145. // as a "string" insead of "JSON array" and pass it on to "sh -c" and
  3146. // it should barf on it.
  3147. name := "testbuildsinglequotefails"
  3148. defer deleteImages(name)
  3149. defer deleteAllContainers()
  3150. _, err := buildImage(name,
  3151. `FROM busybox
  3152. CMD [ '/bin/sh', '-c', 'echo hi' ]`,
  3153. true)
  3154. _, _, err = runCommandWithOutput(exec.Command(dockerBinary, "run", "--rm", name))
  3155. if err == nil {
  3156. t.Fatal("The image was not supposed to be able to run")
  3157. }
  3158. logDone("build - verify single quotes fail")
  3159. }
  3160. func TestBuildVerboseOut(t *testing.T) {
  3161. name := "testbuildverboseout"
  3162. defer deleteImages(name)
  3163. _, out, err := buildImageWithOut(name,
  3164. `FROM busybox
  3165. RUN echo 123`,
  3166. false)
  3167. if err != nil {
  3168. t.Fatal(err)
  3169. }
  3170. if !strings.Contains(out, "\n123\n") {
  3171. t.Fatalf("Output should contain %q: %q", "123", out)
  3172. }
  3173. logDone("build - verbose output from commands")
  3174. }
  3175. func TestBuildWithTabs(t *testing.T) {
  3176. name := "testbuildwithtabs"
  3177. defer deleteImages(name)
  3178. _, err := buildImage(name,
  3179. "FROM busybox\nRUN echo\tone\t\ttwo", true)
  3180. if err != nil {
  3181. t.Fatal(err)
  3182. }
  3183. res, err := inspectFieldJSON(name, "ContainerConfig.Cmd")
  3184. if err != nil {
  3185. t.Fatal(err)
  3186. }
  3187. expected := "[\"/bin/sh\",\"-c\",\"echo\\u0009one\\u0009\\u0009two\"]"
  3188. if res != expected {
  3189. t.Fatalf("Missing tabs.\nGot:%s\nExp:%s", res, expected)
  3190. }
  3191. logDone("build - with tabs")
  3192. }
  3193. func TestBuildStderr(t *testing.T) {
  3194. // This test just makes sure that no non-error output goes
  3195. // to stderr
  3196. name := "testbuildstderr"
  3197. defer deleteImages(name)
  3198. _, _, stderr, err := buildImageWithStdoutStderr(name,
  3199. "FROM busybox\nRUN echo one", true)
  3200. if err != nil {
  3201. t.Fatal(err)
  3202. }
  3203. if stderr != "" {
  3204. t.Fatal("Stderr should have been empty, instead its: %q", stderr)
  3205. }
  3206. logDone("build - testing stderr")
  3207. }
  3208. func TestBuildChownSingleFile(t *testing.T) {
  3209. name := "testbuildchownsinglefile"
  3210. defer deleteImages(name)
  3211. ctx, err := fakeContext(`
  3212. FROM busybox
  3213. COPY test /
  3214. RUN ls -l /test
  3215. RUN [ $(ls -l /test | awk '{print $3":"$4}') = 'root:root' ]
  3216. `, map[string]string{
  3217. "test": "test",
  3218. })
  3219. if err != nil {
  3220. t.Fatal(err)
  3221. }
  3222. defer ctx.Close()
  3223. if err := os.Chown(filepath.Join(ctx.Dir, "test"), 4242, 4242); err != nil {
  3224. t.Fatal(err)
  3225. }
  3226. if _, err := buildImageFromContext(name, ctx, true); err != nil {
  3227. t.Fatal(err)
  3228. }
  3229. logDone("build - change permission on single file")
  3230. }
  3231. func TestBuildSymlinkBreakout(t *testing.T) {
  3232. name := "testbuildsymlinkbreakout"
  3233. tmpdir, err := ioutil.TempDir("", name)
  3234. if err != nil {
  3235. t.Fatal(err)
  3236. }
  3237. defer os.RemoveAll(tmpdir)
  3238. ctx := filepath.Join(tmpdir, "context")
  3239. if err := os.MkdirAll(ctx, 0755); err != nil {
  3240. t.Fatal(err)
  3241. }
  3242. if err := ioutil.WriteFile(filepath.Join(ctx, "Dockerfile"), []byte(`
  3243. from busybox
  3244. add symlink.tar /
  3245. add inject /symlink/
  3246. `), 0644); err != nil {
  3247. t.Fatal(err)
  3248. }
  3249. inject := filepath.Join(ctx, "inject")
  3250. if err := ioutil.WriteFile(inject, nil, 0644); err != nil {
  3251. t.Fatal(err)
  3252. }
  3253. f, err := os.Create(filepath.Join(ctx, "symlink.tar"))
  3254. if err != nil {
  3255. t.Fatal(err)
  3256. }
  3257. w := tar.NewWriter(f)
  3258. w.WriteHeader(&tar.Header{
  3259. Name: "symlink2",
  3260. Typeflag: tar.TypeSymlink,
  3261. Linkname: "/../../../../../../../../../../../../../../",
  3262. Uid: os.Getuid(),
  3263. Gid: os.Getgid(),
  3264. })
  3265. w.WriteHeader(&tar.Header{
  3266. Name: "symlink",
  3267. Typeflag: tar.TypeSymlink,
  3268. Linkname: filepath.Join("symlink2", tmpdir),
  3269. Uid: os.Getuid(),
  3270. Gid: os.Getgid(),
  3271. })
  3272. w.Close()
  3273. f.Close()
  3274. if _, err := buildImageFromContext(name, &FakeContext{Dir: ctx}, false); err != nil {
  3275. t.Fatal(err)
  3276. }
  3277. if _, err := os.Lstat(filepath.Join(tmpdir, "inject")); err == nil {
  3278. t.Fatal("symlink breakout - inject")
  3279. } else if !os.IsNotExist(err) {
  3280. t.Fatalf("unexpected error: %v", err)
  3281. }
  3282. logDone("build - symlink breakout")
  3283. }