server.go 40 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "crypto/tls"
  6. "crypto/x509"
  7. "encoding/base64"
  8. "encoding/json"
  9. "expvar"
  10. "fmt"
  11. "io"
  12. "io/ioutil"
  13. "log"
  14. "net"
  15. "net/http"
  16. "net/http/pprof"
  17. "os"
  18. "strconv"
  19. "strings"
  20. "syscall"
  21. "code.google.com/p/go.net/websocket"
  22. "github.com/docker/docker/api"
  23. "github.com/docker/docker/engine"
  24. "github.com/docker/docker/pkg/listenbuffer"
  25. "github.com/docker/docker/pkg/parsers"
  26. "github.com/docker/docker/pkg/systemd"
  27. "github.com/docker/docker/pkg/version"
  28. "github.com/docker/docker/registry"
  29. "github.com/docker/docker/utils"
  30. "github.com/docker/libcontainer/user"
  31. "github.com/gorilla/mux"
  32. )
  33. var (
  34. activationLock chan struct{}
  35. )
  36. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  37. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  38. conn, _, err := w.(http.Hijacker).Hijack()
  39. if err != nil {
  40. return nil, nil, err
  41. }
  42. // Flush the options to make sure the client sets the raw mode
  43. conn.Write([]byte{})
  44. return conn, conn, nil
  45. }
  46. //If we don't do this, POST method without Content-type (even with empty body) will fail
  47. func parseForm(r *http.Request) error {
  48. if r == nil {
  49. return nil
  50. }
  51. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  52. return err
  53. }
  54. return nil
  55. }
  56. func parseMultipartForm(r *http.Request) error {
  57. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  58. return err
  59. }
  60. return nil
  61. }
  62. func httpError(w http.ResponseWriter, err error) {
  63. statusCode := http.StatusInternalServerError
  64. // FIXME: this is brittle and should not be necessary.
  65. // If we need to differentiate between different possible error types, we should
  66. // create appropriate error types with clearly defined meaning.
  67. if strings.Contains(err.Error(), "No such") {
  68. statusCode = http.StatusNotFound
  69. } else if strings.Contains(err.Error(), "Bad parameter") {
  70. statusCode = http.StatusBadRequest
  71. } else if strings.Contains(err.Error(), "Conflict") {
  72. statusCode = http.StatusConflict
  73. } else if strings.Contains(err.Error(), "Impossible") {
  74. statusCode = http.StatusNotAcceptable
  75. } else if strings.Contains(err.Error(), "Wrong login/password") {
  76. statusCode = http.StatusUnauthorized
  77. } else if strings.Contains(err.Error(), "hasn't been activated") {
  78. statusCode = http.StatusForbidden
  79. }
  80. if err != nil {
  81. utils.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  82. http.Error(w, err.Error(), statusCode)
  83. }
  84. }
  85. func writeJSON(w http.ResponseWriter, code int, v engine.Env) error {
  86. w.Header().Set("Content-Type", "application/json")
  87. w.WriteHeader(code)
  88. return v.Encode(w)
  89. }
  90. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  91. w.Header().Set("Content-Type", "application/json")
  92. if flush {
  93. job.Stdout.Add(utils.NewWriteFlusher(w))
  94. } else {
  95. job.Stdout.Add(w)
  96. }
  97. }
  98. func getBoolParam(value string) (bool, error) {
  99. if value == "" {
  100. return false, nil
  101. }
  102. ret, err := strconv.ParseBool(value)
  103. if err != nil {
  104. return false, fmt.Errorf("Bad parameter")
  105. }
  106. return ret, nil
  107. }
  108. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  109. var (
  110. authConfig, err = ioutil.ReadAll(r.Body)
  111. job = eng.Job("auth")
  112. stdoutBuffer = bytes.NewBuffer(nil)
  113. )
  114. if err != nil {
  115. return err
  116. }
  117. job.Setenv("authConfig", string(authConfig))
  118. job.Stdout.Add(stdoutBuffer)
  119. if err = job.Run(); err != nil {
  120. return err
  121. }
  122. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  123. var env engine.Env
  124. env.Set("Status", status)
  125. return writeJSON(w, http.StatusOK, env)
  126. }
  127. w.WriteHeader(http.StatusNoContent)
  128. return nil
  129. }
  130. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  131. w.Header().Set("Content-Type", "application/json")
  132. eng.ServeHTTP(w, r)
  133. return nil
  134. }
  135. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  136. if vars == nil {
  137. return fmt.Errorf("Missing parameter")
  138. }
  139. if err := parseForm(r); err != nil {
  140. return err
  141. }
  142. job := eng.Job("kill", vars["name"])
  143. if sig := r.Form.Get("signal"); sig != "" {
  144. job.Args = append(job.Args, sig)
  145. }
  146. if err := job.Run(); err != nil {
  147. return err
  148. }
  149. w.WriteHeader(http.StatusNoContent)
  150. return nil
  151. }
  152. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  153. if vars == nil {
  154. return fmt.Errorf("Missing parameter")
  155. }
  156. if err := parseForm(r); err != nil {
  157. return err
  158. }
  159. job := eng.Job("pause", vars["name"])
  160. if err := job.Run(); err != nil {
  161. return err
  162. }
  163. w.WriteHeader(http.StatusNoContent)
  164. return nil
  165. }
  166. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  167. if vars == nil {
  168. return fmt.Errorf("Missing parameter")
  169. }
  170. if err := parseForm(r); err != nil {
  171. return err
  172. }
  173. job := eng.Job("unpause", vars["name"])
  174. if err := job.Run(); err != nil {
  175. return err
  176. }
  177. w.WriteHeader(http.StatusNoContent)
  178. return nil
  179. }
  180. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  181. if vars == nil {
  182. return fmt.Errorf("Missing parameter")
  183. }
  184. job := eng.Job("export", vars["name"])
  185. job.Stdout.Add(w)
  186. if err := job.Run(); err != nil {
  187. return err
  188. }
  189. return nil
  190. }
  191. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  192. if err := parseForm(r); err != nil {
  193. return err
  194. }
  195. var (
  196. err error
  197. outs *engine.Table
  198. job = eng.Job("images")
  199. )
  200. job.Setenv("filters", r.Form.Get("filters"))
  201. // FIXME this parameter could just be a match filter
  202. job.Setenv("filter", r.Form.Get("filter"))
  203. job.Setenv("all", r.Form.Get("all"))
  204. if version.GreaterThanOrEqualTo("1.7") {
  205. streamJSON(job, w, false)
  206. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  207. return err
  208. }
  209. if err := job.Run(); err != nil {
  210. return err
  211. }
  212. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  213. outsLegacy := engine.NewTable("Created", 0)
  214. for _, out := range outs.Data {
  215. for _, repoTag := range out.GetList("RepoTags") {
  216. repo, tag := parsers.ParseRepositoryTag(repoTag)
  217. outLegacy := &engine.Env{}
  218. outLegacy.Set("Repository", repo)
  219. outLegacy.SetJson("Tag", tag)
  220. outLegacy.Set("Id", out.Get("Id"))
  221. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  222. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  223. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  224. outsLegacy.Add(outLegacy)
  225. }
  226. }
  227. w.Header().Set("Content-Type", "application/json")
  228. if _, err := outsLegacy.WriteListTo(w); err != nil {
  229. return err
  230. }
  231. }
  232. return nil
  233. }
  234. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  235. if version.GreaterThan("1.6") {
  236. w.WriteHeader(http.StatusNotFound)
  237. return fmt.Errorf("This is now implemented in the client.")
  238. }
  239. eng.ServeHTTP(w, r)
  240. return nil
  241. }
  242. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  243. w.Header().Set("Content-Type", "application/json")
  244. eng.ServeHTTP(w, r)
  245. return nil
  246. }
  247. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  248. if err := parseForm(r); err != nil {
  249. return err
  250. }
  251. var job = eng.Job("events")
  252. streamJSON(job, w, true)
  253. job.Setenv("since", r.Form.Get("since"))
  254. job.Setenv("until", r.Form.Get("until"))
  255. return job.Run()
  256. }
  257. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  258. if vars == nil {
  259. return fmt.Errorf("Missing parameter")
  260. }
  261. var job = eng.Job("history", vars["name"])
  262. streamJSON(job, w, false)
  263. if err := job.Run(); err != nil {
  264. return err
  265. }
  266. return nil
  267. }
  268. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  269. if vars == nil {
  270. return fmt.Errorf("Missing parameter")
  271. }
  272. var job = eng.Job("container_changes", vars["name"])
  273. streamJSON(job, w, false)
  274. return job.Run()
  275. }
  276. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  277. if version.LessThan("1.4") {
  278. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  279. }
  280. if vars == nil {
  281. return fmt.Errorf("Missing parameter")
  282. }
  283. if err := parseForm(r); err != nil {
  284. return err
  285. }
  286. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  287. streamJSON(job, w, false)
  288. return job.Run()
  289. }
  290. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  291. if err := parseForm(r); err != nil {
  292. return err
  293. }
  294. var (
  295. err error
  296. outs *engine.Table
  297. job = eng.Job("containers")
  298. )
  299. job.Setenv("all", r.Form.Get("all"))
  300. job.Setenv("size", r.Form.Get("size"))
  301. job.Setenv("since", r.Form.Get("since"))
  302. job.Setenv("before", r.Form.Get("before"))
  303. job.Setenv("limit", r.Form.Get("limit"))
  304. if version.GreaterThanOrEqualTo("1.5") {
  305. streamJSON(job, w, false)
  306. } else if outs, err = job.Stdout.AddTable(); err != nil {
  307. return err
  308. }
  309. if err = job.Run(); err != nil {
  310. return err
  311. }
  312. if version.LessThan("1.5") { // Convert to legacy format
  313. for _, out := range outs.Data {
  314. ports := engine.NewTable("", 0)
  315. ports.ReadListFrom([]byte(out.Get("Ports")))
  316. out.Set("Ports", api.DisplayablePorts(ports))
  317. }
  318. w.Header().Set("Content-Type", "application/json")
  319. if _, err = outs.WriteListTo(w); err != nil {
  320. return err
  321. }
  322. }
  323. return nil
  324. }
  325. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  326. if err := parseForm(r); err != nil {
  327. return err
  328. }
  329. if vars == nil {
  330. return fmt.Errorf("Missing parameter")
  331. }
  332. var (
  333. inspectJob = eng.Job("container_inspect", vars["name"])
  334. logsJob = eng.Job("logs", vars["name"])
  335. c, err = inspectJob.Stdout.AddEnv()
  336. )
  337. if err != nil {
  338. return err
  339. }
  340. logsJob.Setenv("follow", r.Form.Get("follow"))
  341. logsJob.Setenv("tail", r.Form.Get("tail"))
  342. logsJob.Setenv("stdout", r.Form.Get("stdout"))
  343. logsJob.Setenv("stderr", r.Form.Get("stderr"))
  344. logsJob.Setenv("timestamps", r.Form.Get("timestamps"))
  345. // Validate args here, because we can't return not StatusOK after job.Run() call
  346. stdout, stderr := logsJob.GetenvBool("stdout"), logsJob.GetenvBool("stderr")
  347. if !(stdout || stderr) {
  348. return fmt.Errorf("Bad parameters: you must choose at least one stream")
  349. }
  350. if err = inspectJob.Run(); err != nil {
  351. return err
  352. }
  353. var outStream, errStream io.Writer
  354. outStream = utils.NewWriteFlusher(w)
  355. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  356. errStream = utils.NewStdWriter(outStream, utils.Stderr)
  357. outStream = utils.NewStdWriter(outStream, utils.Stdout)
  358. } else {
  359. errStream = outStream
  360. }
  361. logsJob.Stdout.Add(outStream)
  362. logsJob.Stderr.Set(errStream)
  363. if err := logsJob.Run(); err != nil {
  364. fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
  365. }
  366. return nil
  367. }
  368. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  369. if err := parseForm(r); err != nil {
  370. return err
  371. }
  372. if vars == nil {
  373. return fmt.Errorf("Missing parameter")
  374. }
  375. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  376. job.Setenv("force", r.Form.Get("force"))
  377. if err := job.Run(); err != nil {
  378. return err
  379. }
  380. w.WriteHeader(http.StatusCreated)
  381. return nil
  382. }
  383. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  384. if err := parseForm(r); err != nil {
  385. return err
  386. }
  387. var (
  388. config engine.Env
  389. env engine.Env
  390. job = eng.Job("commit", r.Form.Get("container"))
  391. stdoutBuffer = bytes.NewBuffer(nil)
  392. )
  393. if err := config.Decode(r.Body); err != nil {
  394. utils.Errorf("%s", err)
  395. }
  396. if r.FormValue("pause") == "" && version.GreaterThanOrEqualTo("1.13") {
  397. job.Setenv("pause", "1")
  398. } else {
  399. job.Setenv("pause", r.FormValue("pause"))
  400. }
  401. job.Setenv("repo", r.Form.Get("repo"))
  402. job.Setenv("tag", r.Form.Get("tag"))
  403. job.Setenv("author", r.Form.Get("author"))
  404. job.Setenv("comment", r.Form.Get("comment"))
  405. job.SetenvSubEnv("config", &config)
  406. job.Stdout.Add(stdoutBuffer)
  407. if err := job.Run(); err != nil {
  408. return err
  409. }
  410. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  411. return writeJSON(w, http.StatusCreated, env)
  412. }
  413. // Creates an image from Pull or from Import
  414. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  415. if err := parseForm(r); err != nil {
  416. return err
  417. }
  418. var (
  419. image = r.Form.Get("fromImage")
  420. repo = r.Form.Get("repo")
  421. tag = r.Form.Get("tag")
  422. job *engine.Job
  423. )
  424. authEncoded := r.Header.Get("X-Registry-Auth")
  425. authConfig := &registry.AuthConfig{}
  426. if authEncoded != "" {
  427. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  428. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  429. // for a pull it is not an error if no auth was given
  430. // to increase compatibility with the existing api it is defaulting to be empty
  431. authConfig = &registry.AuthConfig{}
  432. }
  433. }
  434. if image != "" { //pull
  435. if tag == "" {
  436. image, tag = parsers.ParseRepositoryTag(image)
  437. }
  438. metaHeaders := map[string][]string{}
  439. for k, v := range r.Header {
  440. if strings.HasPrefix(k, "X-Meta-") {
  441. metaHeaders[k] = v
  442. }
  443. }
  444. job = eng.Job("pull", image, tag)
  445. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  446. job.SetenvJson("metaHeaders", metaHeaders)
  447. job.SetenvJson("authConfig", authConfig)
  448. } else { //import
  449. if tag == "" {
  450. repo, tag = parsers.ParseRepositoryTag(repo)
  451. }
  452. job = eng.Job("import", r.Form.Get("fromSrc"), repo, tag)
  453. job.Stdin.Add(r.Body)
  454. }
  455. if version.GreaterThan("1.0") {
  456. job.SetenvBool("json", true)
  457. streamJSON(job, w, true)
  458. } else {
  459. job.Stdout.Add(utils.NewWriteFlusher(w))
  460. }
  461. if err := job.Run(); err != nil {
  462. if !job.Stdout.Used() {
  463. return err
  464. }
  465. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  466. w.Write(sf.FormatError(err))
  467. }
  468. return nil
  469. }
  470. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  471. if err := parseForm(r); err != nil {
  472. return err
  473. }
  474. var (
  475. authEncoded = r.Header.Get("X-Registry-Auth")
  476. authConfig = &registry.AuthConfig{}
  477. metaHeaders = map[string][]string{}
  478. )
  479. if authEncoded != "" {
  480. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  481. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  482. // for a search it is not an error if no auth was given
  483. // to increase compatibility with the existing api it is defaulting to be empty
  484. authConfig = &registry.AuthConfig{}
  485. }
  486. }
  487. for k, v := range r.Header {
  488. if strings.HasPrefix(k, "X-Meta-") {
  489. metaHeaders[k] = v
  490. }
  491. }
  492. var job = eng.Job("search", r.Form.Get("term"))
  493. job.SetenvJson("metaHeaders", metaHeaders)
  494. job.SetenvJson("authConfig", authConfig)
  495. streamJSON(job, w, false)
  496. return job.Run()
  497. }
  498. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  499. if vars == nil {
  500. return fmt.Errorf("Missing parameter")
  501. }
  502. metaHeaders := map[string][]string{}
  503. for k, v := range r.Header {
  504. if strings.HasPrefix(k, "X-Meta-") {
  505. metaHeaders[k] = v
  506. }
  507. }
  508. if err := parseForm(r); err != nil {
  509. return err
  510. }
  511. authConfig := &registry.AuthConfig{}
  512. authEncoded := r.Header.Get("X-Registry-Auth")
  513. if authEncoded != "" {
  514. // the new format is to handle the authConfig as a header
  515. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  516. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  517. // to increase compatibility to existing api it is defaulting to be empty
  518. authConfig = &registry.AuthConfig{}
  519. }
  520. } else {
  521. // the old format is supported for compatibility if there was no authConfig header
  522. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  523. return err
  524. }
  525. }
  526. job := eng.Job("push", vars["name"])
  527. job.SetenvJson("metaHeaders", metaHeaders)
  528. job.SetenvJson("authConfig", authConfig)
  529. job.Setenv("tag", r.Form.Get("tag"))
  530. if version.GreaterThan("1.0") {
  531. job.SetenvBool("json", true)
  532. streamJSON(job, w, true)
  533. } else {
  534. job.Stdout.Add(utils.NewWriteFlusher(w))
  535. }
  536. if err := job.Run(); err != nil {
  537. if !job.Stdout.Used() {
  538. return err
  539. }
  540. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  541. w.Write(sf.FormatError(err))
  542. }
  543. return nil
  544. }
  545. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  546. if vars == nil {
  547. return fmt.Errorf("Missing parameter")
  548. }
  549. if version.GreaterThan("1.0") {
  550. w.Header().Set("Content-Type", "application/x-tar")
  551. }
  552. job := eng.Job("image_export", vars["name"])
  553. job.Stdout.Add(w)
  554. return job.Run()
  555. }
  556. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  557. job := eng.Job("load")
  558. job.Stdin.Add(r.Body)
  559. return job.Run()
  560. }
  561. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  562. if err := parseForm(r); err != nil {
  563. return nil
  564. }
  565. var (
  566. out engine.Env
  567. job = eng.Job("create", r.Form.Get("name"))
  568. outWarnings []string
  569. stdoutBuffer = bytes.NewBuffer(nil)
  570. warnings = bytes.NewBuffer(nil)
  571. )
  572. if err := job.DecodeEnv(r.Body); err != nil {
  573. return err
  574. }
  575. // Read container ID from the first line of stdout
  576. job.Stdout.Add(stdoutBuffer)
  577. // Read warnings from stderr
  578. job.Stderr.Add(warnings)
  579. if err := job.Run(); err != nil {
  580. return err
  581. }
  582. // Parse warnings from stderr
  583. scanner := bufio.NewScanner(warnings)
  584. for scanner.Scan() {
  585. outWarnings = append(outWarnings, scanner.Text())
  586. }
  587. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  588. out.SetList("Warnings", outWarnings)
  589. return writeJSON(w, http.StatusCreated, out)
  590. }
  591. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  592. if err := parseForm(r); err != nil {
  593. return err
  594. }
  595. if vars == nil {
  596. return fmt.Errorf("Missing parameter")
  597. }
  598. job := eng.Job("restart", vars["name"])
  599. job.Setenv("t", r.Form.Get("t"))
  600. if err := job.Run(); err != nil {
  601. return err
  602. }
  603. w.WriteHeader(http.StatusNoContent)
  604. return nil
  605. }
  606. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  607. if err := parseForm(r); err != nil {
  608. return err
  609. }
  610. if vars == nil {
  611. return fmt.Errorf("Missing parameter")
  612. }
  613. job := eng.Job("delete", vars["name"])
  614. if version.GreaterThanOrEqualTo("1.14") {
  615. job.Setenv("stop", r.Form.Get("stop"))
  616. job.Setenv("kill", r.Form.Get("kill"))
  617. if job.GetenvBool("stop") && job.GetenvBool("kill") {
  618. return fmt.Errorf("Bad parameters: can't use stop and kill simultaneously")
  619. }
  620. } else {
  621. job.Setenv("stop", r.Form.Get("force"))
  622. }
  623. job.Setenv("removeVolume", r.Form.Get("v"))
  624. job.Setenv("removeLink", r.Form.Get("link"))
  625. if err := job.Run(); err != nil {
  626. return err
  627. }
  628. w.WriteHeader(http.StatusNoContent)
  629. return nil
  630. }
  631. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  632. if err := parseForm(r); err != nil {
  633. return err
  634. }
  635. if vars == nil {
  636. return fmt.Errorf("Missing parameter")
  637. }
  638. var job = eng.Job("image_delete", vars["name"])
  639. streamJSON(job, w, false)
  640. job.Setenv("force", r.Form.Get("force"))
  641. job.Setenv("noprune", r.Form.Get("noprune"))
  642. return job.Run()
  643. }
  644. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  645. if vars == nil {
  646. return fmt.Errorf("Missing parameter")
  647. }
  648. var (
  649. name = vars["name"]
  650. job = eng.Job("start", name)
  651. )
  652. // allow a nil body for backwards compatibility
  653. if r.Body != nil && r.ContentLength > 0 {
  654. if !api.MatchesContentType(r.Header.Get("Content-Type"), "application/json") {
  655. return fmt.Errorf("Content-Type of application/json is required")
  656. }
  657. if err := job.DecodeEnv(r.Body); err != nil {
  658. return err
  659. }
  660. }
  661. if err := job.Run(); err != nil {
  662. if err.Error() == "Container already started" {
  663. w.WriteHeader(http.StatusNotModified)
  664. return nil
  665. }
  666. return err
  667. }
  668. w.WriteHeader(http.StatusNoContent)
  669. return nil
  670. }
  671. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  672. if err := parseForm(r); err != nil {
  673. return err
  674. }
  675. if vars == nil {
  676. return fmt.Errorf("Missing parameter")
  677. }
  678. job := eng.Job("stop", vars["name"])
  679. job.Setenv("t", r.Form.Get("t"))
  680. if err := job.Run(); err != nil {
  681. if err.Error() == "Container already stopped" {
  682. w.WriteHeader(http.StatusNotModified)
  683. return nil
  684. }
  685. return err
  686. }
  687. w.WriteHeader(http.StatusNoContent)
  688. return nil
  689. }
  690. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  691. if vars == nil {
  692. return fmt.Errorf("Missing parameter")
  693. }
  694. var (
  695. env engine.Env
  696. stdoutBuffer = bytes.NewBuffer(nil)
  697. job = eng.Job("wait", vars["name"])
  698. )
  699. job.Stdout.Add(stdoutBuffer)
  700. if err := job.Run(); err != nil {
  701. return err
  702. }
  703. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  704. return writeJSON(w, http.StatusOK, env)
  705. }
  706. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  707. if err := parseForm(r); err != nil {
  708. return err
  709. }
  710. if vars == nil {
  711. return fmt.Errorf("Missing parameter")
  712. }
  713. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  714. return err
  715. }
  716. return nil
  717. }
  718. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  719. if err := parseForm(r); err != nil {
  720. return err
  721. }
  722. if vars == nil {
  723. return fmt.Errorf("Missing parameter")
  724. }
  725. var (
  726. job = eng.Job("container_inspect", vars["name"])
  727. c, err = job.Stdout.AddEnv()
  728. )
  729. if err != nil {
  730. return err
  731. }
  732. if err = job.Run(); err != nil {
  733. return err
  734. }
  735. inStream, outStream, err := hijackServer(w)
  736. if err != nil {
  737. return err
  738. }
  739. defer func() {
  740. if tcpc, ok := inStream.(*net.TCPConn); ok {
  741. tcpc.CloseWrite()
  742. } else {
  743. inStream.Close()
  744. }
  745. }()
  746. defer func() {
  747. if tcpc, ok := outStream.(*net.TCPConn); ok {
  748. tcpc.CloseWrite()
  749. } else if closer, ok := outStream.(io.Closer); ok {
  750. closer.Close()
  751. }
  752. }()
  753. var errStream io.Writer
  754. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  755. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  756. errStream = utils.NewStdWriter(outStream, utils.Stderr)
  757. outStream = utils.NewStdWriter(outStream, utils.Stdout)
  758. } else {
  759. errStream = outStream
  760. }
  761. job = eng.Job("attach", vars["name"])
  762. job.Setenv("logs", r.Form.Get("logs"))
  763. job.Setenv("stream", r.Form.Get("stream"))
  764. job.Setenv("stdin", r.Form.Get("stdin"))
  765. job.Setenv("stdout", r.Form.Get("stdout"))
  766. job.Setenv("stderr", r.Form.Get("stderr"))
  767. job.Stdin.Add(inStream)
  768. job.Stdout.Add(outStream)
  769. job.Stderr.Set(errStream)
  770. if err := job.Run(); err != nil {
  771. fmt.Fprintf(outStream, "Error attaching: %s\n", err)
  772. }
  773. return nil
  774. }
  775. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  776. if err := parseForm(r); err != nil {
  777. return err
  778. }
  779. if vars == nil {
  780. return fmt.Errorf("Missing parameter")
  781. }
  782. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  783. return err
  784. }
  785. h := websocket.Handler(func(ws *websocket.Conn) {
  786. defer ws.Close()
  787. job := eng.Job("attach", vars["name"])
  788. job.Setenv("logs", r.Form.Get("logs"))
  789. job.Setenv("stream", r.Form.Get("stream"))
  790. job.Setenv("stdin", r.Form.Get("stdin"))
  791. job.Setenv("stdout", r.Form.Get("stdout"))
  792. job.Setenv("stderr", r.Form.Get("stderr"))
  793. job.Stdin.Add(ws)
  794. job.Stdout.Add(ws)
  795. job.Stderr.Set(ws)
  796. if err := job.Run(); err != nil {
  797. utils.Errorf("Error attaching websocket: %s", err)
  798. }
  799. })
  800. h.ServeHTTP(w, r)
  801. return nil
  802. }
  803. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  804. if vars == nil {
  805. return fmt.Errorf("Missing parameter")
  806. }
  807. var job = eng.Job("container_inspect", vars["name"])
  808. if version.LessThan("1.12") {
  809. job.SetenvBool("raw", true)
  810. }
  811. streamJSON(job, w, false)
  812. return job.Run()
  813. }
  814. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  815. if vars == nil {
  816. return fmt.Errorf("Missing parameter")
  817. }
  818. var job = eng.Job("image_inspect", vars["name"])
  819. if version.LessThan("1.12") {
  820. job.SetenvBool("raw", true)
  821. }
  822. streamJSON(job, w, false)
  823. return job.Run()
  824. }
  825. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  826. if version.LessThan("1.3") {
  827. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  828. }
  829. var (
  830. authEncoded = r.Header.Get("X-Registry-Auth")
  831. authConfig = &registry.AuthConfig{}
  832. configFileEncoded = r.Header.Get("X-Registry-Config")
  833. configFile = &registry.ConfigFile{}
  834. job = eng.Job("build")
  835. )
  836. // This block can be removed when API versions prior to 1.9 are deprecated.
  837. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  838. // ConfigFile is present, any value provided as an AuthConfig directly will
  839. // be overridden. See BuildFile::CmdFrom for details.
  840. if version.LessThan("1.9") && authEncoded != "" {
  841. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  842. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  843. // for a pull it is not an error if no auth was given
  844. // to increase compatibility with the existing api it is defaulting to be empty
  845. authConfig = &registry.AuthConfig{}
  846. }
  847. }
  848. if configFileEncoded != "" {
  849. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  850. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  851. // for a pull it is not an error if no auth was given
  852. // to increase compatibility with the existing api it is defaulting to be empty
  853. configFile = &registry.ConfigFile{}
  854. }
  855. }
  856. if version.GreaterThanOrEqualTo("1.8") {
  857. job.SetenvBool("json", true)
  858. streamJSON(job, w, true)
  859. } else {
  860. job.Stdout.Add(utils.NewWriteFlusher(w))
  861. }
  862. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  863. job.Setenv("rm", "1")
  864. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  865. job.Setenv("rm", "1")
  866. } else {
  867. job.Setenv("rm", r.FormValue("rm"))
  868. }
  869. job.Stdin.Add(r.Body)
  870. job.Setenv("remote", r.FormValue("remote"))
  871. job.Setenv("t", r.FormValue("t"))
  872. job.Setenv("q", r.FormValue("q"))
  873. job.Setenv("nocache", r.FormValue("nocache"))
  874. job.Setenv("forcerm", r.FormValue("forcerm"))
  875. job.SetenvJson("authConfig", authConfig)
  876. job.SetenvJson("configFile", configFile)
  877. if err := job.Run(); err != nil {
  878. if !job.Stdout.Used() {
  879. return err
  880. }
  881. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  882. w.Write(sf.FormatError(err))
  883. }
  884. return nil
  885. }
  886. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  887. if vars == nil {
  888. return fmt.Errorf("Missing parameter")
  889. }
  890. var copyData engine.Env
  891. if contentType := r.Header.Get("Content-Type"); api.MatchesContentType(contentType, "application/json") {
  892. if err := copyData.Decode(r.Body); err != nil {
  893. return err
  894. }
  895. } else {
  896. return fmt.Errorf("Content-Type not supported: %s", contentType)
  897. }
  898. if copyData.Get("Resource") == "" {
  899. return fmt.Errorf("Path cannot be empty")
  900. }
  901. origResource := copyData.Get("Resource")
  902. if copyData.Get("Resource")[0] == '/' {
  903. copyData.Set("Resource", copyData.Get("Resource")[1:])
  904. }
  905. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  906. job.Stdout.Add(w)
  907. if err := job.Run(); err != nil {
  908. utils.Errorf("%s", err.Error())
  909. if strings.Contains(err.Error(), "No such container") {
  910. w.WriteHeader(http.StatusNotFound)
  911. } else if strings.Contains(err.Error(), "no such file or directory") {
  912. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  913. }
  914. }
  915. return nil
  916. }
  917. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  918. w.WriteHeader(http.StatusOK)
  919. return nil
  920. }
  921. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  922. w.Header().Add("Access-Control-Allow-Origin", "*")
  923. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept")
  924. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  925. }
  926. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  927. _, err := w.Write([]byte{'O', 'K'})
  928. return err
  929. }
  930. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  931. return func(w http.ResponseWriter, r *http.Request) {
  932. // log the request
  933. utils.Debugf("Calling %s %s", localMethod, localRoute)
  934. if logging {
  935. log.Println(r.Method, r.RequestURI)
  936. }
  937. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  938. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  939. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  940. utils.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  941. }
  942. }
  943. version := version.Version(mux.Vars(r)["version"])
  944. if version == "" {
  945. version = api.APIVERSION
  946. }
  947. if enableCors {
  948. writeCorsHeaders(w, r)
  949. }
  950. if version.GreaterThan(api.APIVERSION) {
  951. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  952. return
  953. }
  954. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  955. utils.Errorf("Error making handler: %s", err)
  956. httpError(w, err)
  957. }
  958. }
  959. }
  960. // Replicated from expvar.go as not public.
  961. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  962. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  963. fmt.Fprintf(w, "{\n")
  964. first := true
  965. expvar.Do(func(kv expvar.KeyValue) {
  966. if !first {
  967. fmt.Fprintf(w, ",\n")
  968. }
  969. first = false
  970. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  971. })
  972. fmt.Fprintf(w, "\n}\n")
  973. }
  974. func AttachProfiler(router *mux.Router) {
  975. router.HandleFunc("/debug/vars", expvarHandler)
  976. router.HandleFunc("/debug/pprof/", pprof.Index)
  977. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  978. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  979. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  980. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  981. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  982. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  983. }
  984. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) (*mux.Router, error) {
  985. r := mux.NewRouter()
  986. if os.Getenv("DEBUG") != "" {
  987. AttachProfiler(r)
  988. }
  989. m := map[string]map[string]HttpApiFunc{
  990. "GET": {
  991. "/_ping": ping,
  992. "/events": getEvents,
  993. "/info": getInfo,
  994. "/version": getVersion,
  995. "/images/json": getImagesJSON,
  996. "/images/viz": getImagesViz,
  997. "/images/search": getImagesSearch,
  998. "/images/{name:.*}/get": getImagesGet,
  999. "/images/{name:.*}/history": getImagesHistory,
  1000. "/images/{name:.*}/json": getImagesByName,
  1001. "/containers/ps": getContainersJSON,
  1002. "/containers/json": getContainersJSON,
  1003. "/containers/{name:.*}/export": getContainersExport,
  1004. "/containers/{name:.*}/changes": getContainersChanges,
  1005. "/containers/{name:.*}/json": getContainersByName,
  1006. "/containers/{name:.*}/top": getContainersTop,
  1007. "/containers/{name:.*}/logs": getContainersLogs,
  1008. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  1009. },
  1010. "POST": {
  1011. "/auth": postAuth,
  1012. "/commit": postCommit,
  1013. "/build": postBuild,
  1014. "/images/create": postImagesCreate,
  1015. "/images/load": postImagesLoad,
  1016. "/images/{name:.*}/push": postImagesPush,
  1017. "/images/{name:.*}/tag": postImagesTag,
  1018. "/containers/create": postContainersCreate,
  1019. "/containers/{name:.*}/kill": postContainersKill,
  1020. "/containers/{name:.*}/pause": postContainersPause,
  1021. "/containers/{name:.*}/unpause": postContainersUnpause,
  1022. "/containers/{name:.*}/restart": postContainersRestart,
  1023. "/containers/{name:.*}/start": postContainersStart,
  1024. "/containers/{name:.*}/stop": postContainersStop,
  1025. "/containers/{name:.*}/wait": postContainersWait,
  1026. "/containers/{name:.*}/resize": postContainersResize,
  1027. "/containers/{name:.*}/attach": postContainersAttach,
  1028. "/containers/{name:.*}/copy": postContainersCopy,
  1029. },
  1030. "DELETE": {
  1031. "/containers/{name:.*}": deleteContainers,
  1032. "/images/{name:.*}": deleteImages,
  1033. },
  1034. "OPTIONS": {
  1035. "": optionsHandler,
  1036. },
  1037. }
  1038. for method, routes := range m {
  1039. for route, fct := range routes {
  1040. utils.Debugf("Registering %s, %s", method, route)
  1041. // NOTE: scope issue, make sure the variables are local and won't be changed
  1042. localRoute := route
  1043. localFct := fct
  1044. localMethod := method
  1045. // build the handler function
  1046. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1047. // add the new route
  1048. if localRoute == "" {
  1049. r.Methods(localMethod).HandlerFunc(f)
  1050. } else {
  1051. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1052. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1053. }
  1054. }
  1055. }
  1056. return r, nil
  1057. }
  1058. // ServeRequest processes a single http request to the docker remote api.
  1059. // FIXME: refactor this to be part of Server and not require re-creating a new
  1060. // router each time. This requires first moving ListenAndServe into Server.
  1061. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) error {
  1062. router, err := createRouter(eng, false, true, "")
  1063. if err != nil {
  1064. return err
  1065. }
  1066. // Insert APIVERSION into the request as a convenience
  1067. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1068. router.ServeHTTP(w, req)
  1069. return nil
  1070. }
  1071. // ServeFD creates an http.Server and sets it up to serve given a socket activated
  1072. // argument.
  1073. func ServeFd(addr string, handle http.Handler) error {
  1074. ls, e := systemd.ListenFD(addr)
  1075. if e != nil {
  1076. return e
  1077. }
  1078. chErrors := make(chan error, len(ls))
  1079. // We don't want to start serving on these sockets until the
  1080. // "initserver" job has completed. Otherwise required handlers
  1081. // won't be ready.
  1082. <-activationLock
  1083. // Since ListenFD will return one or more sockets we have
  1084. // to create a go func to spawn off multiple serves
  1085. for i := range ls {
  1086. listener := ls[i]
  1087. go func() {
  1088. httpSrv := http.Server{Handler: handle}
  1089. chErrors <- httpSrv.Serve(listener)
  1090. }()
  1091. }
  1092. for i := 0; i < len(ls); i += 1 {
  1093. err := <-chErrors
  1094. if err != nil {
  1095. return err
  1096. }
  1097. }
  1098. return nil
  1099. }
  1100. func lookupGidByName(nameOrGid string) (int, error) {
  1101. groups, err := user.ParseGroupFilter(func(g *user.Group) bool {
  1102. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1103. })
  1104. if err != nil {
  1105. return -1, err
  1106. }
  1107. if groups != nil && len(groups) > 0 {
  1108. return groups[0].Gid, nil
  1109. }
  1110. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1111. }
  1112. func changeGroup(addr string, nameOrGid string) error {
  1113. gid, err := lookupGidByName(nameOrGid)
  1114. if err != nil {
  1115. return err
  1116. }
  1117. utils.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1118. return os.Chown(addr, 0, gid)
  1119. }
  1120. // ListenAndServe sets up the required http.Server and gets it listening for
  1121. // each addr passed in and does protocol specific checking.
  1122. func ListenAndServe(proto, addr string, job *engine.Job) error {
  1123. var l net.Listener
  1124. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1125. if err != nil {
  1126. return err
  1127. }
  1128. if proto == "fd" {
  1129. return ServeFd(addr, r)
  1130. }
  1131. if proto == "unix" {
  1132. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1133. return err
  1134. }
  1135. }
  1136. var oldmask int
  1137. if proto == "unix" {
  1138. oldmask = syscall.Umask(0777)
  1139. }
  1140. if job.GetenvBool("BufferRequests") {
  1141. l, err = listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1142. } else {
  1143. l, err = net.Listen(proto, addr)
  1144. }
  1145. if proto == "unix" {
  1146. syscall.Umask(oldmask)
  1147. }
  1148. if err != nil {
  1149. return err
  1150. }
  1151. if proto != "unix" && (job.GetenvBool("Tls") || job.GetenvBool("TlsVerify")) {
  1152. tlsCert := job.Getenv("TlsCert")
  1153. tlsKey := job.Getenv("TlsKey")
  1154. cert, err := tls.LoadX509KeyPair(tlsCert, tlsKey)
  1155. if err != nil {
  1156. return fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1157. tlsCert, tlsKey, err)
  1158. }
  1159. tlsConfig := &tls.Config{
  1160. NextProtos: []string{"http/1.1"},
  1161. Certificates: []tls.Certificate{cert},
  1162. }
  1163. if job.GetenvBool("TlsVerify") {
  1164. certPool := x509.NewCertPool()
  1165. file, err := ioutil.ReadFile(job.Getenv("TlsCa"))
  1166. if err != nil {
  1167. return fmt.Errorf("Couldn't read CA certificate: %s", err)
  1168. }
  1169. certPool.AppendCertsFromPEM(file)
  1170. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1171. tlsConfig.ClientCAs = certPool
  1172. }
  1173. l = tls.NewListener(l, tlsConfig)
  1174. }
  1175. // Basic error and sanity checking
  1176. switch proto {
  1177. case "tcp":
  1178. if !strings.HasPrefix(addr, "127.0.0.1") && !job.GetenvBool("TlsVerify") {
  1179. log.Println("/!\\ DON'T BIND ON ANOTHER IP ADDRESS THAN 127.0.0.1 IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1180. }
  1181. case "unix":
  1182. socketGroup := job.Getenv("SocketGroup")
  1183. if socketGroup != "" {
  1184. if err := changeGroup(addr, socketGroup); err != nil {
  1185. if socketGroup == "docker" {
  1186. // if the user hasn't explicitly specified the group ownership, don't fail on errors.
  1187. utils.Debugf("Warning: could not chgrp %s to docker: %s", addr, err.Error())
  1188. } else {
  1189. return err
  1190. }
  1191. }
  1192. }
  1193. if err := os.Chmod(addr, 0660); err != nil {
  1194. return err
  1195. }
  1196. default:
  1197. return fmt.Errorf("Invalid protocol format.")
  1198. }
  1199. httpSrv := http.Server{Addr: addr, Handler: r}
  1200. return httpSrv.Serve(l)
  1201. }
  1202. // ServeApi loops through all of the protocols sent in to docker and spawns
  1203. // off a go routine to setup a serving http.Server for each.
  1204. func ServeApi(job *engine.Job) engine.Status {
  1205. if len(job.Args) == 0 {
  1206. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1207. }
  1208. var (
  1209. protoAddrs = job.Args
  1210. chErrors = make(chan error, len(protoAddrs))
  1211. )
  1212. activationLock = make(chan struct{})
  1213. for _, protoAddr := range protoAddrs {
  1214. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1215. if len(protoAddrParts) != 2 {
  1216. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1217. }
  1218. go func() {
  1219. log.Printf("Listening for HTTP on %s (%s)\n", protoAddrParts[0], protoAddrParts[1])
  1220. chErrors <- ListenAndServe(protoAddrParts[0], protoAddrParts[1], job)
  1221. }()
  1222. }
  1223. for i := 0; i < len(protoAddrs); i += 1 {
  1224. err := <-chErrors
  1225. if err != nil {
  1226. return job.Error(err)
  1227. }
  1228. }
  1229. return engine.StatusOK
  1230. }
  1231. func AcceptConnections(job *engine.Job) engine.Status {
  1232. // Tell the init daemon we are accepting requests
  1233. go systemd.SdNotify("READY=1")
  1234. // close the lock so the listeners start accepting connections
  1235. if activationLock != nil {
  1236. close(activationLock)
  1237. }
  1238. return engine.StatusOK
  1239. }