server.go 44 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "crypto/tls"
  6. "crypto/x509"
  7. "encoding/base64"
  8. "encoding/json"
  9. "expvar"
  10. "fmt"
  11. "io"
  12. "io/ioutil"
  13. "net"
  14. "net/http"
  15. "net/http/pprof"
  16. "os"
  17. "strconv"
  18. "strings"
  19. "syscall"
  20. "code.google.com/p/go.net/websocket"
  21. "github.com/docker/libcontainer/user"
  22. "github.com/gorilla/mux"
  23. "github.com/docker/docker/api"
  24. "github.com/docker/docker/engine"
  25. "github.com/docker/docker/pkg/listenbuffer"
  26. "github.com/docker/docker/pkg/log"
  27. "github.com/docker/docker/pkg/parsers"
  28. "github.com/docker/docker/pkg/stdcopy"
  29. "github.com/docker/docker/pkg/systemd"
  30. "github.com/docker/docker/pkg/version"
  31. "github.com/docker/docker/registry"
  32. "github.com/docker/docker/utils"
  33. )
  34. var (
  35. activationLock chan struct{}
  36. )
  37. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  38. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  39. conn, _, err := w.(http.Hijacker).Hijack()
  40. if err != nil {
  41. return nil, nil, err
  42. }
  43. // Flush the options to make sure the client sets the raw mode
  44. conn.Write([]byte{})
  45. return conn, conn, nil
  46. }
  47. // Check to make sure request's Content-Type is application/json
  48. func checkForJson(r *http.Request) error {
  49. ct := r.Header.Get("Content-Type")
  50. // No Content-Type header is ok as long as there's no Body
  51. if ct == "" {
  52. if r.Body == nil || r.ContentLength == 0 {
  53. return nil
  54. }
  55. }
  56. // Otherwise it better be json
  57. if api.MatchesContentType(ct, "application/json") {
  58. return nil
  59. }
  60. return fmt.Errorf("Content-Type specified (%s) must be 'application/json'", ct)
  61. }
  62. //If we don't do this, POST method without Content-type (even with empty body) will fail
  63. func parseForm(r *http.Request) error {
  64. if r == nil {
  65. return nil
  66. }
  67. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  68. return err
  69. }
  70. return nil
  71. }
  72. func parseMultipartForm(r *http.Request) error {
  73. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  74. return err
  75. }
  76. return nil
  77. }
  78. func httpError(w http.ResponseWriter, err error) {
  79. statusCode := http.StatusInternalServerError
  80. // FIXME: this is brittle and should not be necessary.
  81. // If we need to differentiate between different possible error types, we should
  82. // create appropriate error types with clearly defined meaning.
  83. if strings.Contains(err.Error(), "No such") {
  84. statusCode = http.StatusNotFound
  85. } else if strings.Contains(err.Error(), "Bad parameter") {
  86. statusCode = http.StatusBadRequest
  87. } else if strings.Contains(err.Error(), "Conflict") {
  88. statusCode = http.StatusConflict
  89. } else if strings.Contains(err.Error(), "Impossible") {
  90. statusCode = http.StatusNotAcceptable
  91. } else if strings.Contains(err.Error(), "Wrong login/password") {
  92. statusCode = http.StatusUnauthorized
  93. } else if strings.Contains(err.Error(), "hasn't been activated") {
  94. statusCode = http.StatusForbidden
  95. }
  96. if err != nil {
  97. log.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  98. http.Error(w, err.Error(), statusCode)
  99. }
  100. }
  101. func writeJSON(w http.ResponseWriter, code int, v engine.Env) error {
  102. w.Header().Set("Content-Type", "application/json")
  103. w.WriteHeader(code)
  104. return v.Encode(w)
  105. }
  106. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  107. w.Header().Set("Content-Type", "application/json")
  108. if flush {
  109. job.Stdout.Add(utils.NewWriteFlusher(w))
  110. } else {
  111. job.Stdout.Add(w)
  112. }
  113. }
  114. func getBoolParam(value string) (bool, error) {
  115. if value == "" {
  116. return false, nil
  117. }
  118. ret, err := strconv.ParseBool(value)
  119. if err != nil {
  120. return false, fmt.Errorf("Bad parameter")
  121. }
  122. return ret, nil
  123. }
  124. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  125. var (
  126. authConfig, err = ioutil.ReadAll(r.Body)
  127. job = eng.Job("auth")
  128. stdoutBuffer = bytes.NewBuffer(nil)
  129. )
  130. if err != nil {
  131. return err
  132. }
  133. job.Setenv("authConfig", string(authConfig))
  134. job.Stdout.Add(stdoutBuffer)
  135. if err = job.Run(); err != nil {
  136. return err
  137. }
  138. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  139. var env engine.Env
  140. env.Set("Status", status)
  141. return writeJSON(w, http.StatusOK, env)
  142. }
  143. w.WriteHeader(http.StatusNoContent)
  144. return nil
  145. }
  146. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  147. w.Header().Set("Content-Type", "application/json")
  148. eng.ServeHTTP(w, r)
  149. return nil
  150. }
  151. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  152. if vars == nil {
  153. return fmt.Errorf("Missing parameter")
  154. }
  155. if err := parseForm(r); err != nil {
  156. return err
  157. }
  158. job := eng.Job("kill", vars["name"])
  159. if sig := r.Form.Get("signal"); sig != "" {
  160. job.Args = append(job.Args, sig)
  161. }
  162. if err := job.Run(); err != nil {
  163. return err
  164. }
  165. w.WriteHeader(http.StatusNoContent)
  166. return nil
  167. }
  168. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  169. if vars == nil {
  170. return fmt.Errorf("Missing parameter")
  171. }
  172. if err := parseForm(r); err != nil {
  173. return err
  174. }
  175. job := eng.Job("pause", vars["name"])
  176. if err := job.Run(); err != nil {
  177. return err
  178. }
  179. w.WriteHeader(http.StatusNoContent)
  180. return nil
  181. }
  182. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  183. if vars == nil {
  184. return fmt.Errorf("Missing parameter")
  185. }
  186. if err := parseForm(r); err != nil {
  187. return err
  188. }
  189. job := eng.Job("unpause", vars["name"])
  190. if err := job.Run(); err != nil {
  191. return err
  192. }
  193. w.WriteHeader(http.StatusNoContent)
  194. return nil
  195. }
  196. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  197. if vars == nil {
  198. return fmt.Errorf("Missing parameter")
  199. }
  200. job := eng.Job("export", vars["name"])
  201. job.Stdout.Add(w)
  202. if err := job.Run(); err != nil {
  203. return err
  204. }
  205. return nil
  206. }
  207. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  208. if err := parseForm(r); err != nil {
  209. return err
  210. }
  211. var (
  212. err error
  213. outs *engine.Table
  214. job = eng.Job("images")
  215. )
  216. job.Setenv("filters", r.Form.Get("filters"))
  217. // FIXME this parameter could just be a match filter
  218. job.Setenv("filter", r.Form.Get("filter"))
  219. job.Setenv("all", r.Form.Get("all"))
  220. if version.GreaterThanOrEqualTo("1.7") {
  221. streamJSON(job, w, false)
  222. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  223. return err
  224. }
  225. if err := job.Run(); err != nil {
  226. return err
  227. }
  228. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  229. outsLegacy := engine.NewTable("Created", 0)
  230. for _, out := range outs.Data {
  231. for _, repoTag := range out.GetList("RepoTags") {
  232. repo, tag := parsers.ParseRepositoryTag(repoTag)
  233. outLegacy := &engine.Env{}
  234. outLegacy.Set("Repository", repo)
  235. outLegacy.SetJson("Tag", tag)
  236. outLegacy.Set("Id", out.Get("Id"))
  237. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  238. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  239. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  240. outsLegacy.Add(outLegacy)
  241. }
  242. }
  243. w.Header().Set("Content-Type", "application/json")
  244. if _, err := outsLegacy.WriteListTo(w); err != nil {
  245. return err
  246. }
  247. }
  248. return nil
  249. }
  250. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  251. if version.GreaterThan("1.6") {
  252. w.WriteHeader(http.StatusNotFound)
  253. return fmt.Errorf("This is now implemented in the client.")
  254. }
  255. eng.ServeHTTP(w, r)
  256. return nil
  257. }
  258. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  259. w.Header().Set("Content-Type", "application/json")
  260. eng.ServeHTTP(w, r)
  261. return nil
  262. }
  263. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  264. if err := parseForm(r); err != nil {
  265. return err
  266. }
  267. var job = eng.Job("events")
  268. streamJSON(job, w, true)
  269. job.Setenv("since", r.Form.Get("since"))
  270. job.Setenv("until", r.Form.Get("until"))
  271. return job.Run()
  272. }
  273. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  274. if vars == nil {
  275. return fmt.Errorf("Missing parameter")
  276. }
  277. var job = eng.Job("history", vars["name"])
  278. streamJSON(job, w, false)
  279. if err := job.Run(); err != nil {
  280. return err
  281. }
  282. return nil
  283. }
  284. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  285. if vars == nil {
  286. return fmt.Errorf("Missing parameter")
  287. }
  288. var job = eng.Job("container_changes", vars["name"])
  289. streamJSON(job, w, false)
  290. return job.Run()
  291. }
  292. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  293. if version.LessThan("1.4") {
  294. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  295. }
  296. if vars == nil {
  297. return fmt.Errorf("Missing parameter")
  298. }
  299. if err := parseForm(r); err != nil {
  300. return err
  301. }
  302. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  303. streamJSON(job, w, false)
  304. return job.Run()
  305. }
  306. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  307. if err := parseForm(r); err != nil {
  308. return err
  309. }
  310. var (
  311. err error
  312. outs *engine.Table
  313. job = eng.Job("containers")
  314. )
  315. job.Setenv("all", r.Form.Get("all"))
  316. job.Setenv("size", r.Form.Get("size"))
  317. job.Setenv("since", r.Form.Get("since"))
  318. job.Setenv("before", r.Form.Get("before"))
  319. job.Setenv("limit", r.Form.Get("limit"))
  320. job.Setenv("filters", r.Form.Get("filters"))
  321. if version.GreaterThanOrEqualTo("1.5") {
  322. streamJSON(job, w, false)
  323. } else if outs, err = job.Stdout.AddTable(); err != nil {
  324. return err
  325. }
  326. if err = job.Run(); err != nil {
  327. return err
  328. }
  329. if version.LessThan("1.5") { // Convert to legacy format
  330. for _, out := range outs.Data {
  331. ports := engine.NewTable("", 0)
  332. ports.ReadListFrom([]byte(out.Get("Ports")))
  333. out.Set("Ports", api.DisplayablePorts(ports))
  334. }
  335. w.Header().Set("Content-Type", "application/json")
  336. if _, err = outs.WriteListTo(w); err != nil {
  337. return err
  338. }
  339. }
  340. return nil
  341. }
  342. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  343. if err := parseForm(r); err != nil {
  344. return err
  345. }
  346. if vars == nil {
  347. return fmt.Errorf("Missing parameter")
  348. }
  349. var (
  350. inspectJob = eng.Job("container_inspect", vars["name"])
  351. logsJob = eng.Job("logs", vars["name"])
  352. c, err = inspectJob.Stdout.AddEnv()
  353. )
  354. if err != nil {
  355. return err
  356. }
  357. logsJob.Setenv("follow", r.Form.Get("follow"))
  358. logsJob.Setenv("tail", r.Form.Get("tail"))
  359. logsJob.Setenv("stdout", r.Form.Get("stdout"))
  360. logsJob.Setenv("stderr", r.Form.Get("stderr"))
  361. logsJob.Setenv("timestamps", r.Form.Get("timestamps"))
  362. // Validate args here, because we can't return not StatusOK after job.Run() call
  363. stdout, stderr := logsJob.GetenvBool("stdout"), logsJob.GetenvBool("stderr")
  364. if !(stdout || stderr) {
  365. return fmt.Errorf("Bad parameters: you must choose at least one stream")
  366. }
  367. if err = inspectJob.Run(); err != nil {
  368. return err
  369. }
  370. var outStream, errStream io.Writer
  371. outStream = utils.NewWriteFlusher(w)
  372. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  373. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  374. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  375. } else {
  376. errStream = outStream
  377. }
  378. logsJob.Stdout.Add(outStream)
  379. logsJob.Stderr.Set(errStream)
  380. if err := logsJob.Run(); err != nil {
  381. fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
  382. }
  383. return nil
  384. }
  385. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  386. if err := parseForm(r); err != nil {
  387. return err
  388. }
  389. if vars == nil {
  390. return fmt.Errorf("Missing parameter")
  391. }
  392. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  393. job.Setenv("force", r.Form.Get("force"))
  394. if err := job.Run(); err != nil {
  395. return err
  396. }
  397. w.WriteHeader(http.StatusCreated)
  398. return nil
  399. }
  400. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  401. if err := parseForm(r); err != nil {
  402. return err
  403. }
  404. var (
  405. config engine.Env
  406. env engine.Env
  407. job = eng.Job("commit", r.Form.Get("container"))
  408. stdoutBuffer = bytes.NewBuffer(nil)
  409. )
  410. if err := checkForJson(r); err != nil {
  411. return err
  412. }
  413. if err := config.Decode(r.Body); err != nil {
  414. log.Errorf("%s", err)
  415. }
  416. if r.FormValue("pause") == "" && version.GreaterThanOrEqualTo("1.13") {
  417. job.Setenv("pause", "1")
  418. } else {
  419. job.Setenv("pause", r.FormValue("pause"))
  420. }
  421. job.Setenv("repo", r.Form.Get("repo"))
  422. job.Setenv("tag", r.Form.Get("tag"))
  423. job.Setenv("author", r.Form.Get("author"))
  424. job.Setenv("comment", r.Form.Get("comment"))
  425. job.SetenvSubEnv("config", &config)
  426. job.Stdout.Add(stdoutBuffer)
  427. if err := job.Run(); err != nil {
  428. return err
  429. }
  430. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  431. return writeJSON(w, http.StatusCreated, env)
  432. }
  433. // Creates an image from Pull or from Import
  434. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  435. if err := parseForm(r); err != nil {
  436. return err
  437. }
  438. var (
  439. image = r.Form.Get("fromImage")
  440. repo = r.Form.Get("repo")
  441. tag = r.Form.Get("tag")
  442. job *engine.Job
  443. )
  444. authEncoded := r.Header.Get("X-Registry-Auth")
  445. authConfig := &registry.AuthConfig{}
  446. if authEncoded != "" {
  447. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  448. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  449. // for a pull it is not an error if no auth was given
  450. // to increase compatibility with the existing api it is defaulting to be empty
  451. authConfig = &registry.AuthConfig{}
  452. }
  453. }
  454. if image != "" { //pull
  455. if tag == "" {
  456. image, tag = parsers.ParseRepositoryTag(image)
  457. }
  458. metaHeaders := map[string][]string{}
  459. for k, v := range r.Header {
  460. if strings.HasPrefix(k, "X-Meta-") {
  461. metaHeaders[k] = v
  462. }
  463. }
  464. job = eng.Job("pull", image, tag)
  465. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  466. job.SetenvJson("metaHeaders", metaHeaders)
  467. job.SetenvJson("authConfig", authConfig)
  468. } else { //import
  469. if tag == "" {
  470. repo, tag = parsers.ParseRepositoryTag(repo)
  471. }
  472. job = eng.Job("import", r.Form.Get("fromSrc"), repo, tag)
  473. job.Stdin.Add(r.Body)
  474. }
  475. if version.GreaterThan("1.0") {
  476. job.SetenvBool("json", true)
  477. streamJSON(job, w, true)
  478. } else {
  479. job.Stdout.Add(utils.NewWriteFlusher(w))
  480. }
  481. if err := job.Run(); err != nil {
  482. if !job.Stdout.Used() {
  483. return err
  484. }
  485. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  486. w.Write(sf.FormatError(err))
  487. }
  488. return nil
  489. }
  490. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  491. if err := parseForm(r); err != nil {
  492. return err
  493. }
  494. var (
  495. authEncoded = r.Header.Get("X-Registry-Auth")
  496. authConfig = &registry.AuthConfig{}
  497. metaHeaders = map[string][]string{}
  498. )
  499. if authEncoded != "" {
  500. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  501. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  502. // for a search it is not an error if no auth was given
  503. // to increase compatibility with the existing api it is defaulting to be empty
  504. authConfig = &registry.AuthConfig{}
  505. }
  506. }
  507. for k, v := range r.Header {
  508. if strings.HasPrefix(k, "X-Meta-") {
  509. metaHeaders[k] = v
  510. }
  511. }
  512. var job = eng.Job("search", r.Form.Get("term"))
  513. job.SetenvJson("metaHeaders", metaHeaders)
  514. job.SetenvJson("authConfig", authConfig)
  515. streamJSON(job, w, false)
  516. return job.Run()
  517. }
  518. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  519. if vars == nil {
  520. return fmt.Errorf("Missing parameter")
  521. }
  522. metaHeaders := map[string][]string{}
  523. for k, v := range r.Header {
  524. if strings.HasPrefix(k, "X-Meta-") {
  525. metaHeaders[k] = v
  526. }
  527. }
  528. if err := parseForm(r); err != nil {
  529. return err
  530. }
  531. authConfig := &registry.AuthConfig{}
  532. authEncoded := r.Header.Get("X-Registry-Auth")
  533. if authEncoded != "" {
  534. // the new format is to handle the authConfig as a header
  535. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  536. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  537. // to increase compatibility to existing api it is defaulting to be empty
  538. authConfig = &registry.AuthConfig{}
  539. }
  540. } else {
  541. // the old format is supported for compatibility if there was no authConfig header
  542. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  543. return err
  544. }
  545. }
  546. job := eng.Job("push", vars["name"])
  547. job.SetenvJson("metaHeaders", metaHeaders)
  548. job.SetenvJson("authConfig", authConfig)
  549. job.Setenv("tag", r.Form.Get("tag"))
  550. if version.GreaterThan("1.0") {
  551. job.SetenvBool("json", true)
  552. streamJSON(job, w, true)
  553. } else {
  554. job.Stdout.Add(utils.NewWriteFlusher(w))
  555. }
  556. if err := job.Run(); err != nil {
  557. if !job.Stdout.Used() {
  558. return err
  559. }
  560. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  561. w.Write(sf.FormatError(err))
  562. }
  563. return nil
  564. }
  565. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  566. if vars == nil {
  567. return fmt.Errorf("Missing parameter")
  568. }
  569. if err := parseForm(r); err != nil {
  570. return err
  571. }
  572. if version.GreaterThan("1.0") {
  573. w.Header().Set("Content-Type", "application/x-tar")
  574. }
  575. var job *engine.Job
  576. if name, ok := vars["name"]; ok {
  577. job = eng.Job("image_export", name)
  578. } else {
  579. job = eng.Job("image_export", r.Form["names"]...)
  580. }
  581. job.Stdout.Add(w)
  582. return job.Run()
  583. }
  584. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  585. job := eng.Job("load")
  586. job.Stdin.Add(r.Body)
  587. return job.Run()
  588. }
  589. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  590. if err := parseForm(r); err != nil {
  591. return nil
  592. }
  593. var (
  594. out engine.Env
  595. job = eng.Job("create", r.Form.Get("name"))
  596. outWarnings []string
  597. stdoutBuffer = bytes.NewBuffer(nil)
  598. warnings = bytes.NewBuffer(nil)
  599. )
  600. if err := checkForJson(r); err != nil {
  601. return err
  602. }
  603. if err := job.DecodeEnv(r.Body); err != nil {
  604. return err
  605. }
  606. // Read container ID from the first line of stdout
  607. job.Stdout.Add(stdoutBuffer)
  608. // Read warnings from stderr
  609. job.Stderr.Add(warnings)
  610. if err := job.Run(); err != nil {
  611. return err
  612. }
  613. // Parse warnings from stderr
  614. scanner := bufio.NewScanner(warnings)
  615. for scanner.Scan() {
  616. outWarnings = append(outWarnings, scanner.Text())
  617. }
  618. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  619. out.SetList("Warnings", outWarnings)
  620. return writeJSON(w, http.StatusCreated, out)
  621. }
  622. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  623. if err := parseForm(r); err != nil {
  624. return err
  625. }
  626. if vars == nil {
  627. return fmt.Errorf("Missing parameter")
  628. }
  629. job := eng.Job("restart", vars["name"])
  630. job.Setenv("t", r.Form.Get("t"))
  631. if err := job.Run(); err != nil {
  632. return err
  633. }
  634. w.WriteHeader(http.StatusNoContent)
  635. return nil
  636. }
  637. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  638. if err := parseForm(r); err != nil {
  639. return err
  640. }
  641. if vars == nil {
  642. return fmt.Errorf("Missing parameter")
  643. }
  644. job := eng.Job("rm", vars["name"])
  645. job.Setenv("forceRemove", r.Form.Get("force"))
  646. job.Setenv("removeVolume", r.Form.Get("v"))
  647. job.Setenv("removeLink", r.Form.Get("link"))
  648. if err := job.Run(); err != nil {
  649. return err
  650. }
  651. w.WriteHeader(http.StatusNoContent)
  652. return nil
  653. }
  654. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  655. if err := parseForm(r); err != nil {
  656. return err
  657. }
  658. if vars == nil {
  659. return fmt.Errorf("Missing parameter")
  660. }
  661. var job = eng.Job("image_delete", vars["name"])
  662. streamJSON(job, w, false)
  663. job.Setenv("force", r.Form.Get("force"))
  664. job.Setenv("noprune", r.Form.Get("noprune"))
  665. return job.Run()
  666. }
  667. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  668. if vars == nil {
  669. return fmt.Errorf("Missing parameter")
  670. }
  671. var (
  672. name = vars["name"]
  673. job = eng.Job("start", name)
  674. )
  675. // If contentLength is -1, we can assumed chunked encoding
  676. // or more technically that the length is unknown
  677. // http://golang.org/src/pkg/net/http/request.go#L139
  678. // net/http otherwise seems to swallow any headers related to chunked encoding
  679. // including r.TransferEncoding
  680. // allow a nil body for backwards compatibility
  681. if r.Body != nil && (r.ContentLength > 0 || r.ContentLength == -1) {
  682. if err := checkForJson(r); err != nil {
  683. return err
  684. }
  685. if err := job.DecodeEnv(r.Body); err != nil {
  686. return err
  687. }
  688. }
  689. if err := job.Run(); err != nil {
  690. if err.Error() == "Container already started" {
  691. w.WriteHeader(http.StatusNotModified)
  692. return nil
  693. }
  694. return err
  695. }
  696. w.WriteHeader(http.StatusNoContent)
  697. return nil
  698. }
  699. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  700. if err := parseForm(r); err != nil {
  701. return err
  702. }
  703. if vars == nil {
  704. return fmt.Errorf("Missing parameter")
  705. }
  706. job := eng.Job("stop", vars["name"])
  707. job.Setenv("t", r.Form.Get("t"))
  708. if err := job.Run(); err != nil {
  709. if err.Error() == "Container already stopped" {
  710. w.WriteHeader(http.StatusNotModified)
  711. return nil
  712. }
  713. return err
  714. }
  715. w.WriteHeader(http.StatusNoContent)
  716. return nil
  717. }
  718. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  719. if vars == nil {
  720. return fmt.Errorf("Missing parameter")
  721. }
  722. var (
  723. env engine.Env
  724. stdoutBuffer = bytes.NewBuffer(nil)
  725. job = eng.Job("wait", vars["name"])
  726. )
  727. job.Stdout.Add(stdoutBuffer)
  728. if err := job.Run(); err != nil {
  729. return err
  730. }
  731. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  732. return writeJSON(w, http.StatusOK, env)
  733. }
  734. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  735. if err := parseForm(r); err != nil {
  736. return err
  737. }
  738. if vars == nil {
  739. return fmt.Errorf("Missing parameter")
  740. }
  741. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  742. return err
  743. }
  744. return nil
  745. }
  746. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  747. if err := parseForm(r); err != nil {
  748. return err
  749. }
  750. if vars == nil {
  751. return fmt.Errorf("Missing parameter")
  752. }
  753. var (
  754. job = eng.Job("container_inspect", vars["name"])
  755. c, err = job.Stdout.AddEnv()
  756. )
  757. if err != nil {
  758. return err
  759. }
  760. if err = job.Run(); err != nil {
  761. return err
  762. }
  763. inStream, outStream, err := hijackServer(w)
  764. if err != nil {
  765. return err
  766. }
  767. defer func() {
  768. if tcpc, ok := inStream.(*net.TCPConn); ok {
  769. tcpc.CloseWrite()
  770. } else {
  771. inStream.Close()
  772. }
  773. }()
  774. defer func() {
  775. if tcpc, ok := outStream.(*net.TCPConn); ok {
  776. tcpc.CloseWrite()
  777. } else if closer, ok := outStream.(io.Closer); ok {
  778. closer.Close()
  779. }
  780. }()
  781. var errStream io.Writer
  782. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  783. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  784. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  785. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  786. } else {
  787. errStream = outStream
  788. }
  789. job = eng.Job("attach", vars["name"])
  790. job.Setenv("logs", r.Form.Get("logs"))
  791. job.Setenv("stream", r.Form.Get("stream"))
  792. job.Setenv("stdin", r.Form.Get("stdin"))
  793. job.Setenv("stdout", r.Form.Get("stdout"))
  794. job.Setenv("stderr", r.Form.Get("stderr"))
  795. job.Stdin.Add(inStream)
  796. job.Stdout.Add(outStream)
  797. job.Stderr.Set(errStream)
  798. if err := job.Run(); err != nil {
  799. fmt.Fprintf(outStream, "Error attaching: %s\n", err)
  800. }
  801. return nil
  802. }
  803. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  804. if err := parseForm(r); err != nil {
  805. return err
  806. }
  807. if vars == nil {
  808. return fmt.Errorf("Missing parameter")
  809. }
  810. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  811. return err
  812. }
  813. h := websocket.Handler(func(ws *websocket.Conn) {
  814. defer ws.Close()
  815. job := eng.Job("attach", vars["name"])
  816. job.Setenv("logs", r.Form.Get("logs"))
  817. job.Setenv("stream", r.Form.Get("stream"))
  818. job.Setenv("stdin", r.Form.Get("stdin"))
  819. job.Setenv("stdout", r.Form.Get("stdout"))
  820. job.Setenv("stderr", r.Form.Get("stderr"))
  821. job.Stdin.Add(ws)
  822. job.Stdout.Add(ws)
  823. job.Stderr.Set(ws)
  824. if err := job.Run(); err != nil {
  825. log.Errorf("Error attaching websocket: %s", err)
  826. }
  827. })
  828. h.ServeHTTP(w, r)
  829. return nil
  830. }
  831. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  832. if vars == nil {
  833. return fmt.Errorf("Missing parameter")
  834. }
  835. var job = eng.Job("container_inspect", vars["name"])
  836. if version.LessThan("1.12") {
  837. job.SetenvBool("raw", true)
  838. }
  839. streamJSON(job, w, false)
  840. return job.Run()
  841. }
  842. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  843. if vars == nil {
  844. return fmt.Errorf("Missing parameter")
  845. }
  846. var job = eng.Job("image_inspect", vars["name"])
  847. if version.LessThan("1.12") {
  848. job.SetenvBool("raw", true)
  849. }
  850. streamJSON(job, w, false)
  851. return job.Run()
  852. }
  853. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  854. if version.LessThan("1.3") {
  855. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  856. }
  857. var (
  858. authEncoded = r.Header.Get("X-Registry-Auth")
  859. authConfig = &registry.AuthConfig{}
  860. configFileEncoded = r.Header.Get("X-Registry-Config")
  861. configFile = &registry.ConfigFile{}
  862. job = eng.Job("build")
  863. )
  864. // This block can be removed when API versions prior to 1.9 are deprecated.
  865. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  866. // ConfigFile is present, any value provided as an AuthConfig directly will
  867. // be overridden. See BuildFile::CmdFrom for details.
  868. if version.LessThan("1.9") && authEncoded != "" {
  869. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  870. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  871. // for a pull it is not an error if no auth was given
  872. // to increase compatibility with the existing api it is defaulting to be empty
  873. authConfig = &registry.AuthConfig{}
  874. }
  875. }
  876. if configFileEncoded != "" {
  877. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  878. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  879. // for a pull it is not an error if no auth was given
  880. // to increase compatibility with the existing api it is defaulting to be empty
  881. configFile = &registry.ConfigFile{}
  882. }
  883. }
  884. if version.GreaterThanOrEqualTo("1.8") {
  885. job.SetenvBool("json", true)
  886. streamJSON(job, w, true)
  887. } else {
  888. job.Stdout.Add(utils.NewWriteFlusher(w))
  889. }
  890. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  891. job.Setenv("rm", "1")
  892. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  893. job.Setenv("rm", "1")
  894. } else {
  895. job.Setenv("rm", r.FormValue("rm"))
  896. }
  897. job.Stdin.Add(r.Body)
  898. job.Setenv("remote", r.FormValue("remote"))
  899. job.Setenv("t", r.FormValue("t"))
  900. job.Setenv("q", r.FormValue("q"))
  901. job.Setenv("nocache", r.FormValue("nocache"))
  902. job.Setenv("forcerm", r.FormValue("forcerm"))
  903. job.SetenvJson("authConfig", authConfig)
  904. job.SetenvJson("configFile", configFile)
  905. if err := job.Run(); err != nil {
  906. if !job.Stdout.Used() {
  907. return err
  908. }
  909. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  910. w.Write(sf.FormatError(err))
  911. }
  912. return nil
  913. }
  914. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  915. if vars == nil {
  916. return fmt.Errorf("Missing parameter")
  917. }
  918. var copyData engine.Env
  919. if err := checkForJson(r); err != nil {
  920. return err
  921. }
  922. if err := copyData.Decode(r.Body); err != nil {
  923. return err
  924. }
  925. if copyData.Get("Resource") == "" {
  926. return fmt.Errorf("Path cannot be empty")
  927. }
  928. origResource := copyData.Get("Resource")
  929. if copyData.Get("Resource")[0] == '/' {
  930. copyData.Set("Resource", copyData.Get("Resource")[1:])
  931. }
  932. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  933. job.Stdout.Add(w)
  934. w.Header().Set("Content-Type", "application/x-tar")
  935. if err := job.Run(); err != nil {
  936. log.Errorf("%s", err.Error())
  937. if strings.Contains(err.Error(), "No such container") {
  938. w.WriteHeader(http.StatusNotFound)
  939. } else if strings.Contains(err.Error(), "no such file or directory") {
  940. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  941. }
  942. }
  943. return nil
  944. }
  945. func postContainerExecCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  946. if err := parseForm(r); err != nil {
  947. return nil
  948. }
  949. var (
  950. out engine.Env
  951. name = vars["name"]
  952. job = eng.Job("execCreate", name)
  953. stdoutBuffer = bytes.NewBuffer(nil)
  954. )
  955. if err := job.DecodeEnv(r.Body); err != nil {
  956. return err
  957. }
  958. job.Stdout.Add(stdoutBuffer)
  959. // Register an instance of Exec in container.
  960. if err := job.Run(); err != nil {
  961. fmt.Fprintf(os.Stderr, "Error setting up exec command in container %s: %s\n", name, err)
  962. return err
  963. }
  964. // Return the ID
  965. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  966. return writeJSON(w, http.StatusCreated, out)
  967. }
  968. // TODO(vishh): Refactor the code to avoid having to specify stream config as part of both create and start.
  969. func postContainerExecStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  970. if err := parseForm(r); err != nil {
  971. return nil
  972. }
  973. var (
  974. name = vars["name"]
  975. job = eng.Job("execStart", name)
  976. errOut io.Writer = os.Stderr
  977. )
  978. if err := job.DecodeEnv(r.Body); err != nil {
  979. return err
  980. }
  981. if !job.GetenvBool("Detach") {
  982. // Setting up the streaming http interface.
  983. inStream, outStream, err := hijackServer(w)
  984. if err != nil {
  985. return err
  986. }
  987. defer func() {
  988. if tcpc, ok := inStream.(*net.TCPConn); ok {
  989. tcpc.CloseWrite()
  990. } else {
  991. inStream.Close()
  992. }
  993. }()
  994. defer func() {
  995. if tcpc, ok := outStream.(*net.TCPConn); ok {
  996. tcpc.CloseWrite()
  997. } else if closer, ok := outStream.(io.Closer); ok {
  998. closer.Close()
  999. }
  1000. }()
  1001. var errStream io.Writer
  1002. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  1003. if !job.GetenvBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  1004. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  1005. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  1006. } else {
  1007. errStream = outStream
  1008. }
  1009. job.Stdin.Add(inStream)
  1010. job.Stdout.Add(outStream)
  1011. job.Stderr.Set(errStream)
  1012. errOut = outStream
  1013. }
  1014. // Now run the user process in container.
  1015. job.SetCloseIO(false)
  1016. if err := job.Run(); err != nil {
  1017. fmt.Fprintf(errOut, "Error starting exec command in container %s: %s\n", name, err)
  1018. return err
  1019. }
  1020. w.WriteHeader(http.StatusNoContent)
  1021. return nil
  1022. }
  1023. func postContainerExecResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1024. if err := parseForm(r); err != nil {
  1025. return err
  1026. }
  1027. if vars == nil {
  1028. return fmt.Errorf("Missing parameter")
  1029. }
  1030. if err := eng.Job("execResize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  1031. return err
  1032. }
  1033. return nil
  1034. }
  1035. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1036. w.WriteHeader(http.StatusOK)
  1037. return nil
  1038. }
  1039. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  1040. w.Header().Add("Access-Control-Allow-Origin", "*")
  1041. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept")
  1042. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  1043. }
  1044. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1045. _, err := w.Write([]byte{'O', 'K'})
  1046. return err
  1047. }
  1048. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  1049. return func(w http.ResponseWriter, r *http.Request) {
  1050. // log the request
  1051. log.Debugf("Calling %s %s", localMethod, localRoute)
  1052. if logging {
  1053. log.Infof("%s %s", r.Method, r.RequestURI)
  1054. }
  1055. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  1056. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  1057. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  1058. log.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  1059. }
  1060. }
  1061. version := version.Version(mux.Vars(r)["version"])
  1062. if version == "" {
  1063. version = api.APIVERSION
  1064. }
  1065. if enableCors {
  1066. writeCorsHeaders(w, r)
  1067. }
  1068. if version.GreaterThan(api.APIVERSION) {
  1069. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  1070. return
  1071. }
  1072. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  1073. log.Errorf("Handler for %s %s returned error: %s", localMethod, localRoute, err)
  1074. httpError(w, err)
  1075. }
  1076. }
  1077. }
  1078. // Replicated from expvar.go as not public.
  1079. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  1080. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  1081. fmt.Fprintf(w, "{\n")
  1082. first := true
  1083. expvar.Do(func(kv expvar.KeyValue) {
  1084. if !first {
  1085. fmt.Fprintf(w, ",\n")
  1086. }
  1087. first = false
  1088. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  1089. })
  1090. fmt.Fprintf(w, "\n}\n")
  1091. }
  1092. func AttachProfiler(router *mux.Router) {
  1093. router.HandleFunc("/debug/vars", expvarHandler)
  1094. router.HandleFunc("/debug/pprof/", pprof.Index)
  1095. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  1096. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  1097. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  1098. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  1099. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  1100. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  1101. }
  1102. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) (*mux.Router, error) {
  1103. r := mux.NewRouter()
  1104. if os.Getenv("DEBUG") != "" {
  1105. AttachProfiler(r)
  1106. }
  1107. m := map[string]map[string]HttpApiFunc{
  1108. "GET": {
  1109. "/_ping": ping,
  1110. "/events": getEvents,
  1111. "/info": getInfo,
  1112. "/version": getVersion,
  1113. "/images/json": getImagesJSON,
  1114. "/images/viz": getImagesViz,
  1115. "/images/search": getImagesSearch,
  1116. "/images/get": getImagesGet,
  1117. "/images/{name:.*}/get": getImagesGet,
  1118. "/images/{name:.*}/history": getImagesHistory,
  1119. "/images/{name:.*}/json": getImagesByName,
  1120. "/containers/ps": getContainersJSON,
  1121. "/containers/json": getContainersJSON,
  1122. "/containers/{name:.*}/export": getContainersExport,
  1123. "/containers/{name:.*}/changes": getContainersChanges,
  1124. "/containers/{name:.*}/json": getContainersByName,
  1125. "/containers/{name:.*}/top": getContainersTop,
  1126. "/containers/{name:.*}/logs": getContainersLogs,
  1127. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  1128. },
  1129. "POST": {
  1130. "/auth": postAuth,
  1131. "/commit": postCommit,
  1132. "/build": postBuild,
  1133. "/images/create": postImagesCreate,
  1134. "/images/load": postImagesLoad,
  1135. "/images/{name:.*}/push": postImagesPush,
  1136. "/images/{name:.*}/tag": postImagesTag,
  1137. "/containers/create": postContainersCreate,
  1138. "/containers/{name:.*}/kill": postContainersKill,
  1139. "/containers/{name:.*}/pause": postContainersPause,
  1140. "/containers/{name:.*}/unpause": postContainersUnpause,
  1141. "/containers/{name:.*}/restart": postContainersRestart,
  1142. "/containers/{name:.*}/start": postContainersStart,
  1143. "/containers/{name:.*}/stop": postContainersStop,
  1144. "/containers/{name:.*}/wait": postContainersWait,
  1145. "/containers/{name:.*}/resize": postContainersResize,
  1146. "/containers/{name:.*}/attach": postContainersAttach,
  1147. "/containers/{name:.*}/copy": postContainersCopy,
  1148. "/containers/{name:.*}/exec": postContainerExecCreate,
  1149. "/exec/{name:.*}/start": postContainerExecStart,
  1150. "/exec/{name:.*}/resize": postContainerExecResize,
  1151. },
  1152. "DELETE": {
  1153. "/containers/{name:.*}": deleteContainers,
  1154. "/images/{name:.*}": deleteImages,
  1155. },
  1156. "OPTIONS": {
  1157. "": optionsHandler,
  1158. },
  1159. }
  1160. for method, routes := range m {
  1161. for route, fct := range routes {
  1162. log.Debugf("Registering %s, %s", method, route)
  1163. // NOTE: scope issue, make sure the variables are local and won't be changed
  1164. localRoute := route
  1165. localFct := fct
  1166. localMethod := method
  1167. // build the handler function
  1168. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1169. // add the new route
  1170. if localRoute == "" {
  1171. r.Methods(localMethod).HandlerFunc(f)
  1172. } else {
  1173. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1174. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1175. }
  1176. }
  1177. }
  1178. return r, nil
  1179. }
  1180. // ServeRequest processes a single http request to the docker remote api.
  1181. // FIXME: refactor this to be part of Server and not require re-creating a new
  1182. // router each time. This requires first moving ListenAndServe into Server.
  1183. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) error {
  1184. router, err := createRouter(eng, false, true, "")
  1185. if err != nil {
  1186. return err
  1187. }
  1188. // Insert APIVERSION into the request as a convenience
  1189. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1190. router.ServeHTTP(w, req)
  1191. return nil
  1192. }
  1193. // ServeFD creates an http.Server and sets it up to serve given a socket activated
  1194. // argument.
  1195. func ServeFd(addr string, handle http.Handler) error {
  1196. ls, e := systemd.ListenFD(addr)
  1197. if e != nil {
  1198. return e
  1199. }
  1200. chErrors := make(chan error, len(ls))
  1201. // We don't want to start serving on these sockets until the
  1202. // daemon is initialized and installed. Otherwise required handlers
  1203. // won't be ready.
  1204. <-activationLock
  1205. // Since ListenFD will return one or more sockets we have
  1206. // to create a go func to spawn off multiple serves
  1207. for i := range ls {
  1208. listener := ls[i]
  1209. go func() {
  1210. httpSrv := http.Server{Handler: handle}
  1211. chErrors <- httpSrv.Serve(listener)
  1212. }()
  1213. }
  1214. for i := 0; i < len(ls); i++ {
  1215. err := <-chErrors
  1216. if err != nil {
  1217. return err
  1218. }
  1219. }
  1220. return nil
  1221. }
  1222. func lookupGidByName(nameOrGid string) (int, error) {
  1223. groups, err := user.ParseGroupFilter(func(g *user.Group) bool {
  1224. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1225. })
  1226. if err != nil {
  1227. return -1, err
  1228. }
  1229. if groups != nil && len(groups) > 0 {
  1230. return groups[0].Gid, nil
  1231. }
  1232. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1233. }
  1234. func changeGroup(addr string, nameOrGid string) error {
  1235. gid, err := lookupGidByName(nameOrGid)
  1236. if err != nil {
  1237. return err
  1238. }
  1239. log.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1240. return os.Chown(addr, 0, gid)
  1241. }
  1242. // ListenAndServe sets up the required http.Server and gets it listening for
  1243. // each addr passed in and does protocol specific checking.
  1244. func ListenAndServe(proto, addr string, job *engine.Job) error {
  1245. var l net.Listener
  1246. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1247. if err != nil {
  1248. return err
  1249. }
  1250. if proto == "fd" {
  1251. return ServeFd(addr, r)
  1252. }
  1253. if proto == "unix" {
  1254. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1255. return err
  1256. }
  1257. }
  1258. var oldmask int
  1259. if proto == "unix" {
  1260. oldmask = syscall.Umask(0777)
  1261. }
  1262. if job.GetenvBool("BufferRequests") {
  1263. l, err = listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1264. } else {
  1265. l, err = net.Listen(proto, addr)
  1266. }
  1267. if proto == "unix" {
  1268. syscall.Umask(oldmask)
  1269. }
  1270. if err != nil {
  1271. return err
  1272. }
  1273. if proto != "unix" && (job.GetenvBool("Tls") || job.GetenvBool("TlsVerify")) {
  1274. tlsCert := job.Getenv("TlsCert")
  1275. tlsKey := job.Getenv("TlsKey")
  1276. cert, err := tls.LoadX509KeyPair(tlsCert, tlsKey)
  1277. if err != nil {
  1278. return fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1279. tlsCert, tlsKey, err)
  1280. }
  1281. tlsConfig := &tls.Config{
  1282. NextProtos: []string{"http/1.1"},
  1283. Certificates: []tls.Certificate{cert},
  1284. // Avoid fallback on insecure SSL protocols
  1285. MinVersion: tls.VersionTLS10,
  1286. }
  1287. if job.GetenvBool("TlsVerify") {
  1288. certPool := x509.NewCertPool()
  1289. file, err := ioutil.ReadFile(job.Getenv("TlsCa"))
  1290. if err != nil {
  1291. return fmt.Errorf("Couldn't read CA certificate: %s", err)
  1292. }
  1293. certPool.AppendCertsFromPEM(file)
  1294. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1295. tlsConfig.ClientCAs = certPool
  1296. }
  1297. l = tls.NewListener(l, tlsConfig)
  1298. }
  1299. // Basic error and sanity checking
  1300. switch proto {
  1301. case "tcp":
  1302. if !strings.HasPrefix(addr, "127.0.0.1") && !job.GetenvBool("TlsVerify") {
  1303. log.Infof("/!\\ DON'T BIND ON ANOTHER IP ADDRESS THAN 127.0.0.1 IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1304. }
  1305. case "unix":
  1306. socketGroup := job.Getenv("SocketGroup")
  1307. if socketGroup != "" {
  1308. if err := changeGroup(addr, socketGroup); err != nil {
  1309. if socketGroup == "docker" {
  1310. // if the user hasn't explicitly specified the group ownership, don't fail on errors.
  1311. log.Debugf("Warning: could not chgrp %s to docker: %s", addr, err.Error())
  1312. } else {
  1313. return err
  1314. }
  1315. }
  1316. }
  1317. if err := os.Chmod(addr, 0660); err != nil {
  1318. return err
  1319. }
  1320. default:
  1321. return fmt.Errorf("Invalid protocol format.")
  1322. }
  1323. httpSrv := http.Server{Addr: addr, Handler: r}
  1324. return httpSrv.Serve(l)
  1325. }
  1326. // ServeApi loops through all of the protocols sent in to docker and spawns
  1327. // off a go routine to setup a serving http.Server for each.
  1328. func ServeApi(job *engine.Job) engine.Status {
  1329. if len(job.Args) == 0 {
  1330. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1331. }
  1332. var (
  1333. protoAddrs = job.Args
  1334. chErrors = make(chan error, len(protoAddrs))
  1335. )
  1336. activationLock = make(chan struct{})
  1337. for _, protoAddr := range protoAddrs {
  1338. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1339. if len(protoAddrParts) != 2 {
  1340. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1341. }
  1342. go func() {
  1343. log.Infof("Listening for HTTP on %s (%s)", protoAddrParts[0], protoAddrParts[1])
  1344. chErrors <- ListenAndServe(protoAddrParts[0], protoAddrParts[1], job)
  1345. }()
  1346. }
  1347. for i := 0; i < len(protoAddrs); i++ {
  1348. err := <-chErrors
  1349. if err != nil {
  1350. return job.Error(err)
  1351. }
  1352. }
  1353. return engine.StatusOK
  1354. }
  1355. func AcceptConnections(job *engine.Job) engine.Status {
  1356. // Tell the init daemon we are accepting requests
  1357. go systemd.SdNotify("READY=1")
  1358. // close the lock so the listeners start accepting connections
  1359. if activationLock != nil {
  1360. close(activationLock)
  1361. }
  1362. return engine.StatusOK
  1363. }