server.go 39 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "crypto/tls"
  6. "crypto/x509"
  7. "encoding/base64"
  8. "encoding/json"
  9. "expvar"
  10. "fmt"
  11. "io"
  12. "io/ioutil"
  13. "log"
  14. "net"
  15. "net/http"
  16. "net/http/pprof"
  17. "os"
  18. "strconv"
  19. "strings"
  20. "syscall"
  21. "code.google.com/p/go.net/websocket"
  22. "github.com/dotcloud/docker/api"
  23. "github.com/dotcloud/docker/engine"
  24. "github.com/dotcloud/docker/pkg/listenbuffer"
  25. "github.com/dotcloud/docker/pkg/systemd"
  26. "github.com/dotcloud/docker/pkg/user"
  27. "github.com/dotcloud/docker/pkg/version"
  28. "github.com/dotcloud/docker/registry"
  29. "github.com/dotcloud/docker/utils"
  30. "github.com/gorilla/mux"
  31. )
  32. var (
  33. activationLock chan struct{}
  34. )
  35. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  36. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  37. conn, _, err := w.(http.Hijacker).Hijack()
  38. if err != nil {
  39. return nil, nil, err
  40. }
  41. // Flush the options to make sure the client sets the raw mode
  42. conn.Write([]byte{})
  43. return conn, conn, nil
  44. }
  45. //If we don't do this, POST method without Content-type (even with empty body) will fail
  46. func parseForm(r *http.Request) error {
  47. if r == nil {
  48. return nil
  49. }
  50. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  51. return err
  52. }
  53. return nil
  54. }
  55. func parseMultipartForm(r *http.Request) error {
  56. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  57. return err
  58. }
  59. return nil
  60. }
  61. func httpError(w http.ResponseWriter, err error) {
  62. statusCode := http.StatusInternalServerError
  63. // FIXME: this is brittle and should not be necessary.
  64. // If we need to differentiate between different possible error types, we should
  65. // create appropriate error types with clearly defined meaning.
  66. if strings.Contains(err.Error(), "No such") {
  67. statusCode = http.StatusNotFound
  68. } else if strings.Contains(err.Error(), "Bad parameter") {
  69. statusCode = http.StatusBadRequest
  70. } else if strings.Contains(err.Error(), "Conflict") {
  71. statusCode = http.StatusConflict
  72. } else if strings.Contains(err.Error(), "Impossible") {
  73. statusCode = http.StatusNotAcceptable
  74. } else if strings.Contains(err.Error(), "Wrong login/password") {
  75. statusCode = http.StatusUnauthorized
  76. } else if strings.Contains(err.Error(), "hasn't been activated") {
  77. statusCode = http.StatusForbidden
  78. }
  79. if err != nil {
  80. utils.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  81. http.Error(w, err.Error(), statusCode)
  82. }
  83. }
  84. func writeJSON(w http.ResponseWriter, code int, v engine.Env) error {
  85. w.Header().Set("Content-Type", "application/json")
  86. w.WriteHeader(code)
  87. return v.Encode(w)
  88. }
  89. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  90. w.Header().Set("Content-Type", "application/json")
  91. if flush {
  92. job.Stdout.Add(utils.NewWriteFlusher(w))
  93. } else {
  94. job.Stdout.Add(w)
  95. }
  96. }
  97. func getBoolParam(value string) (bool, error) {
  98. if value == "" {
  99. return false, nil
  100. }
  101. ret, err := strconv.ParseBool(value)
  102. if err != nil {
  103. return false, fmt.Errorf("Bad parameter")
  104. }
  105. return ret, nil
  106. }
  107. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  108. var (
  109. authConfig, err = ioutil.ReadAll(r.Body)
  110. job = eng.Job("auth")
  111. stdoutBuffer = bytes.NewBuffer(nil)
  112. )
  113. if err != nil {
  114. return err
  115. }
  116. job.Setenv("authConfig", string(authConfig))
  117. job.Stdout.Add(stdoutBuffer)
  118. if err = job.Run(); err != nil {
  119. return err
  120. }
  121. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  122. var env engine.Env
  123. env.Set("Status", status)
  124. return writeJSON(w, http.StatusOK, env)
  125. }
  126. w.WriteHeader(http.StatusNoContent)
  127. return nil
  128. }
  129. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  130. w.Header().Set("Content-Type", "application/json")
  131. eng.ServeHTTP(w, r)
  132. return nil
  133. }
  134. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  135. if vars == nil {
  136. return fmt.Errorf("Missing parameter")
  137. }
  138. if err := parseForm(r); err != nil {
  139. return err
  140. }
  141. job := eng.Job("kill", vars["name"])
  142. if sig := r.Form.Get("signal"); sig != "" {
  143. job.Args = append(job.Args, sig)
  144. }
  145. if err := job.Run(); err != nil {
  146. return err
  147. }
  148. w.WriteHeader(http.StatusNoContent)
  149. return nil
  150. }
  151. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  152. if vars == nil {
  153. return fmt.Errorf("Missing parameter")
  154. }
  155. if err := parseForm(r); err != nil {
  156. return err
  157. }
  158. job := eng.Job("pause", vars["name"])
  159. if err := job.Run(); err != nil {
  160. return err
  161. }
  162. w.WriteHeader(http.StatusNoContent)
  163. return nil
  164. }
  165. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  166. if vars == nil {
  167. return fmt.Errorf("Missing parameter")
  168. }
  169. if err := parseForm(r); err != nil {
  170. return err
  171. }
  172. job := eng.Job("unpause", vars["name"])
  173. if err := job.Run(); err != nil {
  174. return err
  175. }
  176. w.WriteHeader(http.StatusNoContent)
  177. return nil
  178. }
  179. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  180. if vars == nil {
  181. return fmt.Errorf("Missing parameter")
  182. }
  183. job := eng.Job("export", vars["name"])
  184. job.Stdout.Add(w)
  185. if err := job.Run(); err != nil {
  186. return err
  187. }
  188. return nil
  189. }
  190. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  191. if err := parseForm(r); err != nil {
  192. return err
  193. }
  194. var (
  195. err error
  196. outs *engine.Table
  197. job = eng.Job("images")
  198. )
  199. job.Setenv("filters", r.Form.Get("filters"))
  200. // FIXME this parameter could just be a match filter
  201. job.Setenv("filter", r.Form.Get("filter"))
  202. job.Setenv("all", r.Form.Get("all"))
  203. if version.GreaterThanOrEqualTo("1.7") {
  204. streamJSON(job, w, false)
  205. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  206. return err
  207. }
  208. if err := job.Run(); err != nil {
  209. return err
  210. }
  211. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  212. outsLegacy := engine.NewTable("Created", 0)
  213. for _, out := range outs.Data {
  214. for _, repoTag := range out.GetList("RepoTags") {
  215. parts := strings.Split(repoTag, ":")
  216. outLegacy := &engine.Env{}
  217. outLegacy.Set("Repository", parts[0])
  218. outLegacy.Set("Tag", parts[1])
  219. outLegacy.Set("Id", out.Get("Id"))
  220. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  221. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  222. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  223. outsLegacy.Add(outLegacy)
  224. }
  225. }
  226. w.Header().Set("Content-Type", "application/json")
  227. if _, err := outsLegacy.WriteListTo(w); err != nil {
  228. return err
  229. }
  230. }
  231. return nil
  232. }
  233. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  234. if version.GreaterThan("1.6") {
  235. w.WriteHeader(http.StatusNotFound)
  236. return fmt.Errorf("This is now implemented in the client.")
  237. }
  238. eng.ServeHTTP(w, r)
  239. return nil
  240. }
  241. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  242. w.Header().Set("Content-Type", "application/json")
  243. eng.ServeHTTP(w, r)
  244. return nil
  245. }
  246. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  247. if err := parseForm(r); err != nil {
  248. return err
  249. }
  250. var job = eng.Job("events")
  251. streamJSON(job, w, true)
  252. job.Setenv("since", r.Form.Get("since"))
  253. job.Setenv("until", r.Form.Get("until"))
  254. return job.Run()
  255. }
  256. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  257. if vars == nil {
  258. return fmt.Errorf("Missing parameter")
  259. }
  260. var job = eng.Job("history", vars["name"])
  261. streamJSON(job, w, false)
  262. if err := job.Run(); err != nil {
  263. return err
  264. }
  265. return nil
  266. }
  267. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  268. if vars == nil {
  269. return fmt.Errorf("Missing parameter")
  270. }
  271. var job = eng.Job("changes", vars["name"])
  272. streamJSON(job, w, false)
  273. return job.Run()
  274. }
  275. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  276. if version.LessThan("1.4") {
  277. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  278. }
  279. if vars == nil {
  280. return fmt.Errorf("Missing parameter")
  281. }
  282. if err := parseForm(r); err != nil {
  283. return err
  284. }
  285. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  286. streamJSON(job, w, false)
  287. return job.Run()
  288. }
  289. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  290. if err := parseForm(r); err != nil {
  291. return err
  292. }
  293. var (
  294. err error
  295. outs *engine.Table
  296. job = eng.Job("containers")
  297. )
  298. job.Setenv("all", r.Form.Get("all"))
  299. job.Setenv("size", r.Form.Get("size"))
  300. job.Setenv("since", r.Form.Get("since"))
  301. job.Setenv("before", r.Form.Get("before"))
  302. job.Setenv("limit", r.Form.Get("limit"))
  303. if version.GreaterThanOrEqualTo("1.5") {
  304. streamJSON(job, w, false)
  305. } else if outs, err = job.Stdout.AddTable(); err != nil {
  306. return err
  307. }
  308. if err = job.Run(); err != nil {
  309. return err
  310. }
  311. if version.LessThan("1.5") { // Convert to legacy format
  312. for _, out := range outs.Data {
  313. ports := engine.NewTable("", 0)
  314. ports.ReadListFrom([]byte(out.Get("Ports")))
  315. out.Set("Ports", api.DisplayablePorts(ports))
  316. }
  317. w.Header().Set("Content-Type", "application/json")
  318. if _, err = outs.WriteListTo(w); err != nil {
  319. return err
  320. }
  321. }
  322. return nil
  323. }
  324. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  325. if err := parseForm(r); err != nil {
  326. return err
  327. }
  328. if vars == nil {
  329. return fmt.Errorf("Missing parameter")
  330. }
  331. var (
  332. inspectJob = eng.Job("container_inspect", vars["name"])
  333. logsJob = eng.Job("logs", vars["name"])
  334. c, err = inspectJob.Stdout.AddEnv()
  335. )
  336. if err != nil {
  337. return err
  338. }
  339. logsJob.Setenv("follow", r.Form.Get("follow"))
  340. logsJob.Setenv("stdout", r.Form.Get("stdout"))
  341. logsJob.Setenv("stderr", r.Form.Get("stderr"))
  342. logsJob.Setenv("timestamps", r.Form.Get("timestamps"))
  343. // Validate args here, because we can't return not StatusOK after job.Run() call
  344. stdout, stderr := logsJob.GetenvBool("stdout"), logsJob.GetenvBool("stderr")
  345. if !(stdout || stderr) {
  346. return fmt.Errorf("Bad parameters: you must choose at least one stream")
  347. }
  348. if err = inspectJob.Run(); err != nil {
  349. return err
  350. }
  351. var outStream, errStream io.Writer
  352. outStream = utils.NewWriteFlusher(w)
  353. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  354. errStream = utils.NewStdWriter(outStream, utils.Stderr)
  355. outStream = utils.NewStdWriter(outStream, utils.Stdout)
  356. } else {
  357. errStream = outStream
  358. }
  359. logsJob.Stdout.Add(outStream)
  360. logsJob.Stderr.Set(errStream)
  361. if err := logsJob.Run(); err != nil {
  362. fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
  363. }
  364. return nil
  365. }
  366. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  367. if err := parseForm(r); err != nil {
  368. return err
  369. }
  370. if vars == nil {
  371. return fmt.Errorf("Missing parameter")
  372. }
  373. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  374. job.Setenv("force", r.Form.Get("force"))
  375. if err := job.Run(); err != nil {
  376. return err
  377. }
  378. w.WriteHeader(http.StatusCreated)
  379. return nil
  380. }
  381. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  382. if err := parseForm(r); err != nil {
  383. return err
  384. }
  385. var (
  386. config engine.Env
  387. env engine.Env
  388. job = eng.Job("commit", r.Form.Get("container"))
  389. stdoutBuffer = bytes.NewBuffer(nil)
  390. )
  391. if err := config.Decode(r.Body); err != nil {
  392. utils.Errorf("%s", err)
  393. }
  394. job.Setenv("repo", r.Form.Get("repo"))
  395. job.Setenv("tag", r.Form.Get("tag"))
  396. job.Setenv("author", r.Form.Get("author"))
  397. job.Setenv("comment", r.Form.Get("comment"))
  398. job.SetenvSubEnv("config", &config)
  399. job.Stdout.Add(stdoutBuffer)
  400. if err := job.Run(); err != nil {
  401. return err
  402. }
  403. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  404. return writeJSON(w, http.StatusCreated, env)
  405. }
  406. // Creates an image from Pull or from Import
  407. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  408. if err := parseForm(r); err != nil {
  409. return err
  410. }
  411. var (
  412. image = r.Form.Get("fromImage")
  413. tag = r.Form.Get("tag")
  414. job *engine.Job
  415. )
  416. authEncoded := r.Header.Get("X-Registry-Auth")
  417. authConfig := &registry.AuthConfig{}
  418. if authEncoded != "" {
  419. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  420. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  421. // for a pull it is not an error if no auth was given
  422. // to increase compatibility with the existing api it is defaulting to be empty
  423. authConfig = &registry.AuthConfig{}
  424. }
  425. }
  426. if image != "" { //pull
  427. metaHeaders := map[string][]string{}
  428. for k, v := range r.Header {
  429. if strings.HasPrefix(k, "X-Meta-") {
  430. metaHeaders[k] = v
  431. }
  432. }
  433. job = eng.Job("pull", r.Form.Get("fromImage"), tag)
  434. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  435. job.SetenvJson("metaHeaders", metaHeaders)
  436. job.SetenvJson("authConfig", authConfig)
  437. } else { //import
  438. job = eng.Job("import", r.Form.Get("fromSrc"), r.Form.Get("repo"), tag)
  439. job.Stdin.Add(r.Body)
  440. }
  441. if version.GreaterThan("1.0") {
  442. job.SetenvBool("json", true)
  443. streamJSON(job, w, true)
  444. } else {
  445. job.Stdout.Add(utils.NewWriteFlusher(w))
  446. }
  447. if err := job.Run(); err != nil {
  448. if !job.Stdout.Used() {
  449. return err
  450. }
  451. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  452. w.Write(sf.FormatError(err))
  453. }
  454. return nil
  455. }
  456. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  457. if err := parseForm(r); err != nil {
  458. return err
  459. }
  460. var (
  461. authEncoded = r.Header.Get("X-Registry-Auth")
  462. authConfig = &registry.AuthConfig{}
  463. metaHeaders = map[string][]string{}
  464. )
  465. if authEncoded != "" {
  466. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  467. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  468. // for a search it is not an error if no auth was given
  469. // to increase compatibility with the existing api it is defaulting to be empty
  470. authConfig = &registry.AuthConfig{}
  471. }
  472. }
  473. for k, v := range r.Header {
  474. if strings.HasPrefix(k, "X-Meta-") {
  475. metaHeaders[k] = v
  476. }
  477. }
  478. var job = eng.Job("search", r.Form.Get("term"))
  479. job.SetenvJson("metaHeaders", metaHeaders)
  480. job.SetenvJson("authConfig", authConfig)
  481. streamJSON(job, w, false)
  482. return job.Run()
  483. }
  484. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  485. if vars == nil {
  486. return fmt.Errorf("Missing parameter")
  487. }
  488. metaHeaders := map[string][]string{}
  489. for k, v := range r.Header {
  490. if strings.HasPrefix(k, "X-Meta-") {
  491. metaHeaders[k] = v
  492. }
  493. }
  494. if err := parseForm(r); err != nil {
  495. return err
  496. }
  497. authConfig := &registry.AuthConfig{}
  498. authEncoded := r.Header.Get("X-Registry-Auth")
  499. if authEncoded != "" {
  500. // the new format is to handle the authConfig as a header
  501. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  502. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  503. // to increase compatibility to existing api it is defaulting to be empty
  504. authConfig = &registry.AuthConfig{}
  505. }
  506. } else {
  507. // the old format is supported for compatibility if there was no authConfig header
  508. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  509. return err
  510. }
  511. }
  512. job := eng.Job("push", vars["name"])
  513. job.SetenvJson("metaHeaders", metaHeaders)
  514. job.SetenvJson("authConfig", authConfig)
  515. job.Setenv("tag", r.Form.Get("tag"))
  516. if version.GreaterThan("1.0") {
  517. job.SetenvBool("json", true)
  518. streamJSON(job, w, true)
  519. } else {
  520. job.Stdout.Add(utils.NewWriteFlusher(w))
  521. }
  522. if err := job.Run(); err != nil {
  523. if !job.Stdout.Used() {
  524. return err
  525. }
  526. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  527. w.Write(sf.FormatError(err))
  528. }
  529. return nil
  530. }
  531. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  532. if vars == nil {
  533. return fmt.Errorf("Missing parameter")
  534. }
  535. if version.GreaterThan("1.0") {
  536. w.Header().Set("Content-Type", "application/x-tar")
  537. }
  538. job := eng.Job("image_export", vars["name"])
  539. job.Stdout.Add(w)
  540. return job.Run()
  541. }
  542. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  543. job := eng.Job("load")
  544. job.Stdin.Add(r.Body)
  545. return job.Run()
  546. }
  547. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  548. if err := parseForm(r); err != nil {
  549. return nil
  550. }
  551. var (
  552. out engine.Env
  553. job = eng.Job("create", r.Form.Get("name"))
  554. outWarnings []string
  555. stdoutBuffer = bytes.NewBuffer(nil)
  556. warnings = bytes.NewBuffer(nil)
  557. )
  558. if err := job.DecodeEnv(r.Body); err != nil {
  559. return err
  560. }
  561. // Read container ID from the first line of stdout
  562. job.Stdout.Add(stdoutBuffer)
  563. // Read warnings from stderr
  564. job.Stderr.Add(warnings)
  565. if err := job.Run(); err != nil {
  566. return err
  567. }
  568. // Parse warnings from stderr
  569. scanner := bufio.NewScanner(warnings)
  570. for scanner.Scan() {
  571. outWarnings = append(outWarnings, scanner.Text())
  572. }
  573. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  574. out.SetList("Warnings", outWarnings)
  575. return writeJSON(w, http.StatusCreated, out)
  576. }
  577. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  578. if err := parseForm(r); err != nil {
  579. return err
  580. }
  581. if vars == nil {
  582. return fmt.Errorf("Missing parameter")
  583. }
  584. job := eng.Job("restart", vars["name"])
  585. job.Setenv("t", r.Form.Get("t"))
  586. if err := job.Run(); err != nil {
  587. return err
  588. }
  589. w.WriteHeader(http.StatusNoContent)
  590. return nil
  591. }
  592. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  593. if err := parseForm(r); err != nil {
  594. return err
  595. }
  596. if vars == nil {
  597. return fmt.Errorf("Missing parameter")
  598. }
  599. job := eng.Job("container_delete", vars["name"])
  600. job.Setenv("removeVolume", r.Form.Get("v"))
  601. job.Setenv("removeLink", r.Form.Get("link"))
  602. job.Setenv("forceRemove", r.Form.Get("force"))
  603. if err := job.Run(); err != nil {
  604. return err
  605. }
  606. w.WriteHeader(http.StatusNoContent)
  607. return nil
  608. }
  609. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  610. if err := parseForm(r); err != nil {
  611. return err
  612. }
  613. if vars == nil {
  614. return fmt.Errorf("Missing parameter")
  615. }
  616. var job = eng.Job("image_delete", vars["name"])
  617. streamJSON(job, w, false)
  618. job.Setenv("force", r.Form.Get("force"))
  619. job.Setenv("noprune", r.Form.Get("noprune"))
  620. return job.Run()
  621. }
  622. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  623. if vars == nil {
  624. return fmt.Errorf("Missing parameter")
  625. }
  626. name := vars["name"]
  627. job := eng.Job("start", name)
  628. // allow a nil body for backwards compatibility
  629. if r.Body != nil {
  630. if api.MatchesContentType(r.Header.Get("Content-Type"), "application/json") {
  631. if err := job.DecodeEnv(r.Body); err != nil {
  632. return err
  633. }
  634. }
  635. }
  636. if err := job.Run(); err != nil {
  637. return err
  638. }
  639. w.WriteHeader(http.StatusNoContent)
  640. return nil
  641. }
  642. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  643. if err := parseForm(r); err != nil {
  644. return err
  645. }
  646. if vars == nil {
  647. return fmt.Errorf("Missing parameter")
  648. }
  649. job := eng.Job("stop", vars["name"])
  650. job.Setenv("t", r.Form.Get("t"))
  651. if err := job.Run(); err != nil {
  652. return err
  653. }
  654. w.WriteHeader(http.StatusNoContent)
  655. return nil
  656. }
  657. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  658. if vars == nil {
  659. return fmt.Errorf("Missing parameter")
  660. }
  661. var (
  662. env engine.Env
  663. stdoutBuffer = bytes.NewBuffer(nil)
  664. job = eng.Job("wait", vars["name"])
  665. )
  666. job.Stdout.Add(stdoutBuffer)
  667. if err := job.Run(); err != nil {
  668. return err
  669. }
  670. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  671. return writeJSON(w, http.StatusOK, env)
  672. }
  673. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  674. if err := parseForm(r); err != nil {
  675. return err
  676. }
  677. if vars == nil {
  678. return fmt.Errorf("Missing parameter")
  679. }
  680. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  681. return err
  682. }
  683. return nil
  684. }
  685. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  686. if err := parseForm(r); err != nil {
  687. return err
  688. }
  689. if vars == nil {
  690. return fmt.Errorf("Missing parameter")
  691. }
  692. var (
  693. job = eng.Job("container_inspect", vars["name"])
  694. c, err = job.Stdout.AddEnv()
  695. )
  696. if err != nil {
  697. return err
  698. }
  699. if err = job.Run(); err != nil {
  700. return err
  701. }
  702. inStream, outStream, err := hijackServer(w)
  703. if err != nil {
  704. return err
  705. }
  706. defer func() {
  707. if tcpc, ok := inStream.(*net.TCPConn); ok {
  708. tcpc.CloseWrite()
  709. } else {
  710. inStream.Close()
  711. }
  712. }()
  713. defer func() {
  714. if tcpc, ok := outStream.(*net.TCPConn); ok {
  715. tcpc.CloseWrite()
  716. } else if closer, ok := outStream.(io.Closer); ok {
  717. closer.Close()
  718. }
  719. }()
  720. var errStream io.Writer
  721. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  722. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  723. errStream = utils.NewStdWriter(outStream, utils.Stderr)
  724. outStream = utils.NewStdWriter(outStream, utils.Stdout)
  725. } else {
  726. errStream = outStream
  727. }
  728. job = eng.Job("attach", vars["name"])
  729. job.Setenv("logs", r.Form.Get("logs"))
  730. job.Setenv("stream", r.Form.Get("stream"))
  731. job.Setenv("stdin", r.Form.Get("stdin"))
  732. job.Setenv("stdout", r.Form.Get("stdout"))
  733. job.Setenv("stderr", r.Form.Get("stderr"))
  734. job.Stdin.Add(inStream)
  735. job.Stdout.Add(outStream)
  736. job.Stderr.Set(errStream)
  737. if err := job.Run(); err != nil {
  738. fmt.Fprintf(outStream, "Error attaching: %s\n", err)
  739. }
  740. return nil
  741. }
  742. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  743. if err := parseForm(r); err != nil {
  744. return err
  745. }
  746. if vars == nil {
  747. return fmt.Errorf("Missing parameter")
  748. }
  749. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  750. return err
  751. }
  752. h := websocket.Handler(func(ws *websocket.Conn) {
  753. defer ws.Close()
  754. job := eng.Job("attach", vars["name"])
  755. job.Setenv("logs", r.Form.Get("logs"))
  756. job.Setenv("stream", r.Form.Get("stream"))
  757. job.Setenv("stdin", r.Form.Get("stdin"))
  758. job.Setenv("stdout", r.Form.Get("stdout"))
  759. job.Setenv("stderr", r.Form.Get("stderr"))
  760. job.Stdin.Add(ws)
  761. job.Stdout.Add(ws)
  762. job.Stderr.Set(ws)
  763. if err := job.Run(); err != nil {
  764. utils.Errorf("Error attaching websocket: %s", err)
  765. }
  766. })
  767. h.ServeHTTP(w, r)
  768. return nil
  769. }
  770. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  771. if vars == nil {
  772. return fmt.Errorf("Missing parameter")
  773. }
  774. var job = eng.Job("container_inspect", vars["name"])
  775. if version.LessThan("1.12") {
  776. job.SetenvBool("raw", true)
  777. }
  778. streamJSON(job, w, false)
  779. return job.Run()
  780. }
  781. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  782. if vars == nil {
  783. return fmt.Errorf("Missing parameter")
  784. }
  785. var job = eng.Job("image_inspect", vars["name"])
  786. if version.LessThan("1.12") {
  787. job.SetenvBool("raw", true)
  788. }
  789. streamJSON(job, w, false)
  790. return job.Run()
  791. }
  792. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  793. if version.LessThan("1.3") {
  794. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  795. }
  796. var (
  797. authEncoded = r.Header.Get("X-Registry-Auth")
  798. authConfig = &registry.AuthConfig{}
  799. configFileEncoded = r.Header.Get("X-Registry-Config")
  800. configFile = &registry.ConfigFile{}
  801. job = eng.Job("build")
  802. )
  803. // This block can be removed when API versions prior to 1.9 are deprecated.
  804. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  805. // ConfigFile is present, any value provided as an AuthConfig directly will
  806. // be overridden. See BuildFile::CmdFrom for details.
  807. if version.LessThan("1.9") && authEncoded != "" {
  808. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  809. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  810. // for a pull it is not an error if no auth was given
  811. // to increase compatibility with the existing api it is defaulting to be empty
  812. authConfig = &registry.AuthConfig{}
  813. }
  814. }
  815. if configFileEncoded != "" {
  816. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  817. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  818. // for a pull it is not an error if no auth was given
  819. // to increase compatibility with the existing api it is defaulting to be empty
  820. configFile = &registry.ConfigFile{}
  821. }
  822. }
  823. if version.GreaterThanOrEqualTo("1.8") {
  824. job.SetenvBool("json", true)
  825. streamJSON(job, w, true)
  826. } else {
  827. job.Stdout.Add(utils.NewWriteFlusher(w))
  828. }
  829. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  830. job.Setenv("rm", "1")
  831. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  832. job.Setenv("rm", "1")
  833. } else {
  834. job.Setenv("rm", r.FormValue("rm"))
  835. }
  836. job.Stdin.Add(r.Body)
  837. job.Setenv("remote", r.FormValue("remote"))
  838. job.Setenv("t", r.FormValue("t"))
  839. job.Setenv("q", r.FormValue("q"))
  840. job.Setenv("nocache", r.FormValue("nocache"))
  841. job.Setenv("forcerm", r.FormValue("forcerm"))
  842. job.SetenvJson("authConfig", authConfig)
  843. job.SetenvJson("configFile", configFile)
  844. if err := job.Run(); err != nil {
  845. if !job.Stdout.Used() {
  846. return err
  847. }
  848. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  849. w.Write(sf.FormatError(err))
  850. }
  851. return nil
  852. }
  853. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  854. if vars == nil {
  855. return fmt.Errorf("Missing parameter")
  856. }
  857. var copyData engine.Env
  858. if contentType := r.Header.Get("Content-Type"); api.MatchesContentType(contentType, "application/json") {
  859. if err := copyData.Decode(r.Body); err != nil {
  860. return err
  861. }
  862. } else {
  863. return fmt.Errorf("Content-Type not supported: %s", contentType)
  864. }
  865. if copyData.Get("Resource") == "" {
  866. return fmt.Errorf("Path cannot be empty")
  867. }
  868. origResource := copyData.Get("Resource")
  869. if copyData.Get("Resource")[0] == '/' {
  870. copyData.Set("Resource", copyData.Get("Resource")[1:])
  871. }
  872. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  873. job.Stdout.Add(w)
  874. if err := job.Run(); err != nil {
  875. utils.Errorf("%s", err.Error())
  876. if strings.Contains(err.Error(), "No such container") {
  877. w.WriteHeader(http.StatusNotFound)
  878. } else if strings.Contains(err.Error(), "no such file or directory") {
  879. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  880. }
  881. }
  882. return nil
  883. }
  884. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  885. w.WriteHeader(http.StatusOK)
  886. return nil
  887. }
  888. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  889. w.Header().Add("Access-Control-Allow-Origin", "*")
  890. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept")
  891. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  892. }
  893. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  894. _, err := w.Write([]byte{'O', 'K'})
  895. return err
  896. }
  897. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  898. return func(w http.ResponseWriter, r *http.Request) {
  899. // log the request
  900. utils.Debugf("Calling %s %s", localMethod, localRoute)
  901. if logging {
  902. log.Println(r.Method, r.RequestURI)
  903. }
  904. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  905. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  906. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  907. utils.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  908. }
  909. }
  910. version := version.Version(mux.Vars(r)["version"])
  911. if version == "" {
  912. version = api.APIVERSION
  913. }
  914. if enableCors {
  915. writeCorsHeaders(w, r)
  916. }
  917. if version.GreaterThan(api.APIVERSION) {
  918. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  919. return
  920. }
  921. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  922. utils.Errorf("Error making handler: %s", err)
  923. httpError(w, err)
  924. }
  925. }
  926. }
  927. // Replicated from expvar.go as not public.
  928. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  929. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  930. fmt.Fprintf(w, "{\n")
  931. first := true
  932. expvar.Do(func(kv expvar.KeyValue) {
  933. if !first {
  934. fmt.Fprintf(w, ",\n")
  935. }
  936. first = false
  937. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  938. })
  939. fmt.Fprintf(w, "\n}\n")
  940. }
  941. func AttachProfiler(router *mux.Router) {
  942. router.HandleFunc("/debug/vars", expvarHandler)
  943. router.HandleFunc("/debug/pprof/", pprof.Index)
  944. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  945. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  946. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  947. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  948. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  949. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  950. }
  951. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) (*mux.Router, error) {
  952. r := mux.NewRouter()
  953. if os.Getenv("DEBUG") != "" {
  954. AttachProfiler(r)
  955. }
  956. m := map[string]map[string]HttpApiFunc{
  957. "GET": {
  958. "/_ping": ping,
  959. "/events": getEvents,
  960. "/info": getInfo,
  961. "/version": getVersion,
  962. "/images/json": getImagesJSON,
  963. "/images/viz": getImagesViz,
  964. "/images/search": getImagesSearch,
  965. "/images/{name:.*}/get": getImagesGet,
  966. "/images/{name:.*}/history": getImagesHistory,
  967. "/images/{name:.*}/json": getImagesByName,
  968. "/containers/ps": getContainersJSON,
  969. "/containers/json": getContainersJSON,
  970. "/containers/{name:.*}/export": getContainersExport,
  971. "/containers/{name:.*}/changes": getContainersChanges,
  972. "/containers/{name:.*}/json": getContainersByName,
  973. "/containers/{name:.*}/top": getContainersTop,
  974. "/containers/{name:.*}/logs": getContainersLogs,
  975. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  976. },
  977. "POST": {
  978. "/auth": postAuth,
  979. "/commit": postCommit,
  980. "/build": postBuild,
  981. "/images/create": postImagesCreate,
  982. "/images/load": postImagesLoad,
  983. "/images/{name:.*}/push": postImagesPush,
  984. "/images/{name:.*}/tag": postImagesTag,
  985. "/containers/create": postContainersCreate,
  986. "/containers/{name:.*}/kill": postContainersKill,
  987. "/containers/{name:.*}/pause": postContainersPause,
  988. "/containers/{name:.*}/unpause": postContainersUnpause,
  989. "/containers/{name:.*}/restart": postContainersRestart,
  990. "/containers/{name:.*}/start": postContainersStart,
  991. "/containers/{name:.*}/stop": postContainersStop,
  992. "/containers/{name:.*}/wait": postContainersWait,
  993. "/containers/{name:.*}/resize": postContainersResize,
  994. "/containers/{name:.*}/attach": postContainersAttach,
  995. "/containers/{name:.*}/copy": postContainersCopy,
  996. },
  997. "DELETE": {
  998. "/containers/{name:.*}": deleteContainers,
  999. "/images/{name:.*}": deleteImages,
  1000. },
  1001. "OPTIONS": {
  1002. "": optionsHandler,
  1003. },
  1004. }
  1005. for method, routes := range m {
  1006. for route, fct := range routes {
  1007. utils.Debugf("Registering %s, %s", method, route)
  1008. // NOTE: scope issue, make sure the variables are local and won't be changed
  1009. localRoute := route
  1010. localFct := fct
  1011. localMethod := method
  1012. // build the handler function
  1013. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1014. // add the new route
  1015. if localRoute == "" {
  1016. r.Methods(localMethod).HandlerFunc(f)
  1017. } else {
  1018. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1019. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1020. }
  1021. }
  1022. }
  1023. return r, nil
  1024. }
  1025. // ServeRequest processes a single http request to the docker remote api.
  1026. // FIXME: refactor this to be part of Server and not require re-creating a new
  1027. // router each time. This requires first moving ListenAndServe into Server.
  1028. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) error {
  1029. router, err := createRouter(eng, false, true, "")
  1030. if err != nil {
  1031. return err
  1032. }
  1033. // Insert APIVERSION into the request as a convenience
  1034. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1035. router.ServeHTTP(w, req)
  1036. return nil
  1037. }
  1038. // ServeFD creates an http.Server and sets it up to serve given a socket activated
  1039. // argument.
  1040. func ServeFd(addr string, handle http.Handler) error {
  1041. ls, e := systemd.ListenFD(addr)
  1042. if e != nil {
  1043. return e
  1044. }
  1045. chErrors := make(chan error, len(ls))
  1046. // We don't want to start serving on these sockets until the
  1047. // "initserver" job has completed. Otherwise required handlers
  1048. // won't be ready.
  1049. <-activationLock
  1050. // Since ListenFD will return one or more sockets we have
  1051. // to create a go func to spawn off multiple serves
  1052. for i := range ls {
  1053. listener := ls[i]
  1054. go func() {
  1055. httpSrv := http.Server{Handler: handle}
  1056. chErrors <- httpSrv.Serve(listener)
  1057. }()
  1058. }
  1059. for i := 0; i < len(ls); i += 1 {
  1060. err := <-chErrors
  1061. if err != nil {
  1062. return err
  1063. }
  1064. }
  1065. return nil
  1066. }
  1067. func lookupGidByName(nameOrGid string) (int, error) {
  1068. groups, err := user.ParseGroupFilter(func(g *user.Group) bool {
  1069. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1070. })
  1071. if err != nil {
  1072. return -1, err
  1073. }
  1074. if groups != nil && len(groups) > 0 {
  1075. return groups[0].Gid, nil
  1076. }
  1077. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1078. }
  1079. func changeGroup(addr string, nameOrGid string) error {
  1080. gid, err := lookupGidByName(nameOrGid)
  1081. if err != nil {
  1082. return err
  1083. }
  1084. utils.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1085. return os.Chown(addr, 0, gid)
  1086. }
  1087. // ListenAndServe sets up the required http.Server and gets it listening for
  1088. // each addr passed in and does protocol specific checking.
  1089. func ListenAndServe(proto, addr string, job *engine.Job) error {
  1090. var l net.Listener
  1091. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1092. if err != nil {
  1093. return err
  1094. }
  1095. if proto == "fd" {
  1096. return ServeFd(addr, r)
  1097. }
  1098. if proto == "unix" {
  1099. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1100. return err
  1101. }
  1102. }
  1103. var oldmask int
  1104. if proto == "unix" {
  1105. oldmask = syscall.Umask(0777)
  1106. }
  1107. if job.GetenvBool("BufferRequests") {
  1108. l, err = listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1109. } else {
  1110. l, err = net.Listen(proto, addr)
  1111. }
  1112. if proto == "unix" {
  1113. syscall.Umask(oldmask)
  1114. }
  1115. if err != nil {
  1116. return err
  1117. }
  1118. if proto != "unix" && (job.GetenvBool("Tls") || job.GetenvBool("TlsVerify")) {
  1119. tlsCert := job.Getenv("TlsCert")
  1120. tlsKey := job.Getenv("TlsKey")
  1121. cert, err := tls.LoadX509KeyPair(tlsCert, tlsKey)
  1122. if err != nil {
  1123. return fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1124. tlsCert, tlsKey, err)
  1125. }
  1126. tlsConfig := &tls.Config{
  1127. NextProtos: []string{"http/1.1"},
  1128. Certificates: []tls.Certificate{cert},
  1129. }
  1130. if job.GetenvBool("TlsVerify") {
  1131. certPool := x509.NewCertPool()
  1132. file, err := ioutil.ReadFile(job.Getenv("TlsCa"))
  1133. if err != nil {
  1134. return fmt.Errorf("Couldn't read CA certificate: %s", err)
  1135. }
  1136. certPool.AppendCertsFromPEM(file)
  1137. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1138. tlsConfig.ClientCAs = certPool
  1139. }
  1140. l = tls.NewListener(l, tlsConfig)
  1141. }
  1142. // Basic error and sanity checking
  1143. switch proto {
  1144. case "tcp":
  1145. if !strings.HasPrefix(addr, "127.0.0.1") && !job.GetenvBool("TlsVerify") {
  1146. log.Println("/!\\ DON'T BIND ON ANOTHER IP ADDRESS THAN 127.0.0.1 IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1147. }
  1148. case "unix":
  1149. socketGroup := job.Getenv("SocketGroup")
  1150. if socketGroup != "" {
  1151. if err := changeGroup(addr, socketGroup); err != nil {
  1152. if socketGroup == "docker" {
  1153. // if the user hasn't explicitly specified the group ownership, don't fail on errors.
  1154. utils.Debugf("Warning: could not chgrp %s to docker: %s", addr, err.Error())
  1155. } else {
  1156. return err
  1157. }
  1158. }
  1159. }
  1160. if err := os.Chmod(addr, 0660); err != nil {
  1161. return err
  1162. }
  1163. default:
  1164. return fmt.Errorf("Invalid protocol format.")
  1165. }
  1166. httpSrv := http.Server{Addr: addr, Handler: r}
  1167. return httpSrv.Serve(l)
  1168. }
  1169. // ServeApi loops through all of the protocols sent in to docker and spawns
  1170. // off a go routine to setup a serving http.Server for each.
  1171. func ServeApi(job *engine.Job) engine.Status {
  1172. if len(job.Args) == 0 {
  1173. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1174. }
  1175. var (
  1176. protoAddrs = job.Args
  1177. chErrors = make(chan error, len(protoAddrs))
  1178. )
  1179. activationLock = make(chan struct{})
  1180. for _, protoAddr := range protoAddrs {
  1181. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1182. if len(protoAddrParts) != 2 {
  1183. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1184. }
  1185. go func() {
  1186. log.Printf("Listening for HTTP on %s (%s)\n", protoAddrParts[0], protoAddrParts[1])
  1187. chErrors <- ListenAndServe(protoAddrParts[0], protoAddrParts[1], job)
  1188. }()
  1189. }
  1190. for i := 0; i < len(protoAddrs); i += 1 {
  1191. err := <-chErrors
  1192. if err != nil {
  1193. return job.Error(err)
  1194. }
  1195. }
  1196. return engine.StatusOK
  1197. }
  1198. func AcceptConnections(job *engine.Job) engine.Status {
  1199. // Tell the init daemon we are accepting requests
  1200. go systemd.SdNotify("READY=1")
  1201. // close the lock so the listeners start accepting connections
  1202. if activationLock != nil {
  1203. close(activationLock)
  1204. }
  1205. return engine.StatusOK
  1206. }