diff_unix.go 3.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130
  1. //+build !windows
  2. package chrootarchive
  3. import (
  4. "bytes"
  5. "encoding/json"
  6. "flag"
  7. "fmt"
  8. "io"
  9. "io/ioutil"
  10. "os"
  11. "path/filepath"
  12. "runtime"
  13. "github.com/docker/docker/pkg/archive"
  14. "github.com/docker/docker/pkg/reexec"
  15. "github.com/docker/docker/pkg/system"
  16. rsystem "github.com/opencontainers/runc/libcontainer/system"
  17. )
  18. type applyLayerResponse struct {
  19. LayerSize int64 `json:"layerSize"`
  20. }
  21. // applyLayer is the entry-point for docker-applylayer on re-exec. This is not
  22. // used on Windows as it does not support chroot, hence no point sandboxing
  23. // through chroot and rexec.
  24. func applyLayer() {
  25. var (
  26. tmpDir = ""
  27. err error
  28. options *archive.TarOptions
  29. )
  30. runtime.LockOSThread()
  31. flag.Parse()
  32. inUserns := rsystem.RunningInUserNS()
  33. if err := chroot(flag.Arg(0)); err != nil {
  34. fatal(err)
  35. }
  36. // We need to be able to set any perms
  37. oldmask, err := system.Umask(0)
  38. defer system.Umask(oldmask)
  39. if err != nil {
  40. fatal(err)
  41. }
  42. if err := json.Unmarshal([]byte(os.Getenv("OPT")), &options); err != nil {
  43. fatal(err)
  44. }
  45. if inUserns {
  46. options.InUserNS = true
  47. }
  48. if tmpDir, err = ioutil.TempDir("/", "temp-docker-extract"); err != nil {
  49. fatal(err)
  50. }
  51. os.Setenv("TMPDIR", tmpDir)
  52. size, err := archive.UnpackLayer("/", os.Stdin, options)
  53. os.RemoveAll(tmpDir)
  54. if err != nil {
  55. fatal(err)
  56. }
  57. encoder := json.NewEncoder(os.Stdout)
  58. if err := encoder.Encode(applyLayerResponse{size}); err != nil {
  59. fatal(fmt.Errorf("unable to encode layerSize JSON: %s", err))
  60. }
  61. if _, err := flush(os.Stdin); err != nil {
  62. fatal(err)
  63. }
  64. os.Exit(0)
  65. }
  66. // applyLayerHandler parses a diff in the standard layer format from `layer`, and
  67. // applies it to the directory `dest`. Returns the size in bytes of the
  68. // contents of the layer.
  69. func applyLayerHandler(dest string, layer io.Reader, options *archive.TarOptions, decompress bool) (size int64, err error) {
  70. dest = filepath.Clean(dest)
  71. if decompress {
  72. decompressed, err := archive.DecompressStream(layer)
  73. if err != nil {
  74. return 0, err
  75. }
  76. defer decompressed.Close()
  77. layer = decompressed
  78. }
  79. if options == nil {
  80. options = &archive.TarOptions{}
  81. if rsystem.RunningInUserNS() {
  82. options.InUserNS = true
  83. }
  84. }
  85. if options.ExcludePatterns == nil {
  86. options.ExcludePatterns = []string{}
  87. }
  88. data, err := json.Marshal(options)
  89. if err != nil {
  90. return 0, fmt.Errorf("ApplyLayer json encode: %v", err)
  91. }
  92. cmd := reexec.Command("docker-applyLayer", dest)
  93. cmd.Stdin = layer
  94. cmd.Env = append(cmd.Env, fmt.Sprintf("OPT=%s", data))
  95. outBuf, errBuf := new(bytes.Buffer), new(bytes.Buffer)
  96. cmd.Stdout, cmd.Stderr = outBuf, errBuf
  97. if err = cmd.Run(); err != nil {
  98. return 0, fmt.Errorf("ApplyLayer %s stdout: %s stderr: %s", err, outBuf, errBuf)
  99. }
  100. // Stdout should be a valid JSON struct representing an applyLayerResponse.
  101. response := applyLayerResponse{}
  102. decoder := json.NewDecoder(outBuf)
  103. if err = decoder.Decode(&response); err != nil {
  104. return 0, fmt.Errorf("unable to decode ApplyLayer JSON response: %s", err)
  105. }
  106. return response.LayerSize, nil
  107. }