server.go 40 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "crypto/tls"
  6. "crypto/x509"
  7. "encoding/base64"
  8. "encoding/json"
  9. "expvar"
  10. "fmt"
  11. "io"
  12. "io/ioutil"
  13. "log"
  14. "net"
  15. "net/http"
  16. "net/http/pprof"
  17. "os"
  18. "strconv"
  19. "strings"
  20. "syscall"
  21. "code.google.com/p/go.net/websocket"
  22. "github.com/dotcloud/docker/api"
  23. "github.com/dotcloud/docker/engine"
  24. "github.com/dotcloud/docker/pkg/listenbuffer"
  25. "github.com/dotcloud/docker/pkg/systemd"
  26. "github.com/dotcloud/docker/pkg/user"
  27. "github.com/dotcloud/docker/pkg/version"
  28. "github.com/dotcloud/docker/registry"
  29. "github.com/dotcloud/docker/utils"
  30. "github.com/gorilla/mux"
  31. )
  32. var (
  33. activationLock chan struct{}
  34. )
  35. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  36. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  37. conn, _, err := w.(http.Hijacker).Hijack()
  38. if err != nil {
  39. return nil, nil, err
  40. }
  41. // Flush the options to make sure the client sets the raw mode
  42. conn.Write([]byte{})
  43. return conn, conn, nil
  44. }
  45. //If we don't do this, POST method without Content-type (even with empty body) will fail
  46. func parseForm(r *http.Request) error {
  47. if r == nil {
  48. return nil
  49. }
  50. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  51. return err
  52. }
  53. return nil
  54. }
  55. func parseMultipartForm(r *http.Request) error {
  56. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  57. return err
  58. }
  59. return nil
  60. }
  61. func httpError(w http.ResponseWriter, err error) {
  62. statusCode := http.StatusInternalServerError
  63. // FIXME: this is brittle and should not be necessary.
  64. // If we need to differentiate between different possible error types, we should
  65. // create appropriate error types with clearly defined meaning.
  66. if strings.Contains(err.Error(), "No such") {
  67. statusCode = http.StatusNotFound
  68. } else if strings.Contains(err.Error(), "Bad parameter") {
  69. statusCode = http.StatusBadRequest
  70. } else if strings.Contains(err.Error(), "Conflict") {
  71. statusCode = http.StatusConflict
  72. } else if strings.Contains(err.Error(), "Impossible") {
  73. statusCode = http.StatusNotAcceptable
  74. } else if strings.Contains(err.Error(), "Wrong login/password") {
  75. statusCode = http.StatusUnauthorized
  76. } else if strings.Contains(err.Error(), "hasn't been activated") {
  77. statusCode = http.StatusForbidden
  78. }
  79. if err != nil {
  80. utils.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  81. http.Error(w, err.Error(), statusCode)
  82. }
  83. }
  84. func writeJSON(w http.ResponseWriter, code int, v engine.Env) error {
  85. w.Header().Set("Content-Type", "application/json")
  86. w.WriteHeader(code)
  87. return v.Encode(w)
  88. }
  89. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  90. w.Header().Set("Content-Type", "application/json")
  91. if flush {
  92. job.Stdout.Add(utils.NewWriteFlusher(w))
  93. } else {
  94. job.Stdout.Add(w)
  95. }
  96. }
  97. func getBoolParam(value string) (bool, error) {
  98. if value == "" {
  99. return false, nil
  100. }
  101. ret, err := strconv.ParseBool(value)
  102. if err != nil {
  103. return false, fmt.Errorf("Bad parameter")
  104. }
  105. return ret, nil
  106. }
  107. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  108. var (
  109. authConfig, err = ioutil.ReadAll(r.Body)
  110. job = eng.Job("auth")
  111. stdoutBuffer = bytes.NewBuffer(nil)
  112. )
  113. if err != nil {
  114. return err
  115. }
  116. job.Setenv("authConfig", string(authConfig))
  117. job.Stdout.Add(stdoutBuffer)
  118. if err = job.Run(); err != nil {
  119. return err
  120. }
  121. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  122. var env engine.Env
  123. env.Set("Status", status)
  124. return writeJSON(w, http.StatusOK, env)
  125. }
  126. w.WriteHeader(http.StatusNoContent)
  127. return nil
  128. }
  129. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  130. w.Header().Set("Content-Type", "application/json")
  131. eng.ServeHTTP(w, r)
  132. return nil
  133. }
  134. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  135. if vars == nil {
  136. return fmt.Errorf("Missing parameter")
  137. }
  138. if err := parseForm(r); err != nil {
  139. return err
  140. }
  141. job := eng.Job("kill", vars["name"])
  142. if sig := r.Form.Get("signal"); sig != "" {
  143. job.Args = append(job.Args, sig)
  144. }
  145. if err := job.Run(); err != nil {
  146. return err
  147. }
  148. w.WriteHeader(http.StatusNoContent)
  149. return nil
  150. }
  151. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  152. if vars == nil {
  153. return fmt.Errorf("Missing parameter")
  154. }
  155. if err := parseForm(r); err != nil {
  156. return err
  157. }
  158. job := eng.Job("pause", vars["name"])
  159. if err := job.Run(); err != nil {
  160. return err
  161. }
  162. w.WriteHeader(http.StatusNoContent)
  163. return nil
  164. }
  165. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  166. if vars == nil {
  167. return fmt.Errorf("Missing parameter")
  168. }
  169. if err := parseForm(r); err != nil {
  170. return err
  171. }
  172. job := eng.Job("unpause", vars["name"])
  173. if err := job.Run(); err != nil {
  174. return err
  175. }
  176. w.WriteHeader(http.StatusNoContent)
  177. return nil
  178. }
  179. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  180. if vars == nil {
  181. return fmt.Errorf("Missing parameter")
  182. }
  183. job := eng.Job("export", vars["name"])
  184. job.Stdout.Add(w)
  185. if err := job.Run(); err != nil {
  186. return err
  187. }
  188. return nil
  189. }
  190. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  191. if err := parseForm(r); err != nil {
  192. return err
  193. }
  194. var (
  195. err error
  196. outs *engine.Table
  197. job = eng.Job("images")
  198. )
  199. job.Setenv("filters", r.Form.Get("filters"))
  200. // FIXME this parameter could just be a match filter
  201. job.Setenv("filter", r.Form.Get("filter"))
  202. job.Setenv("all", r.Form.Get("all"))
  203. if version.GreaterThanOrEqualTo("1.7") {
  204. streamJSON(job, w, false)
  205. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  206. return err
  207. }
  208. if err := job.Run(); err != nil {
  209. return err
  210. }
  211. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  212. outsLegacy := engine.NewTable("Created", 0)
  213. for _, out := range outs.Data {
  214. for _, repoTag := range out.GetList("RepoTags") {
  215. parts := strings.Split(repoTag, ":")
  216. outLegacy := &engine.Env{}
  217. outLegacy.Set("Repository", parts[0])
  218. outLegacy.Set("Tag", parts[1])
  219. outLegacy.Set("Id", out.Get("Id"))
  220. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  221. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  222. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  223. outsLegacy.Add(outLegacy)
  224. }
  225. }
  226. w.Header().Set("Content-Type", "application/json")
  227. if _, err := outsLegacy.WriteListTo(w); err != nil {
  228. return err
  229. }
  230. }
  231. return nil
  232. }
  233. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  234. if version.GreaterThan("1.6") {
  235. w.WriteHeader(http.StatusNotFound)
  236. return fmt.Errorf("This is now implemented in the client.")
  237. }
  238. eng.ServeHTTP(w, r)
  239. return nil
  240. }
  241. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  242. w.Header().Set("Content-Type", "application/json")
  243. eng.ServeHTTP(w, r)
  244. return nil
  245. }
  246. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  247. if err := parseForm(r); err != nil {
  248. return err
  249. }
  250. var job = eng.Job("events")
  251. streamJSON(job, w, true)
  252. job.Setenv("since", r.Form.Get("since"))
  253. job.Setenv("until", r.Form.Get("until"))
  254. return job.Run()
  255. }
  256. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  257. if vars == nil {
  258. return fmt.Errorf("Missing parameter")
  259. }
  260. var job = eng.Job("history", vars["name"])
  261. streamJSON(job, w, false)
  262. if err := job.Run(); err != nil {
  263. return err
  264. }
  265. return nil
  266. }
  267. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  268. if vars == nil {
  269. return fmt.Errorf("Missing parameter")
  270. }
  271. var job = eng.Job("changes", vars["name"])
  272. streamJSON(job, w, false)
  273. return job.Run()
  274. }
  275. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  276. if version.LessThan("1.4") {
  277. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  278. }
  279. if vars == nil {
  280. return fmt.Errorf("Missing parameter")
  281. }
  282. if err := parseForm(r); err != nil {
  283. return err
  284. }
  285. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  286. streamJSON(job, w, false)
  287. return job.Run()
  288. }
  289. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  290. if err := parseForm(r); err != nil {
  291. return err
  292. }
  293. var (
  294. err error
  295. outs *engine.Table
  296. job = eng.Job("containers")
  297. )
  298. job.Setenv("all", r.Form.Get("all"))
  299. job.Setenv("size", r.Form.Get("size"))
  300. job.Setenv("since", r.Form.Get("since"))
  301. job.Setenv("before", r.Form.Get("before"))
  302. job.Setenv("limit", r.Form.Get("limit"))
  303. if version.GreaterThanOrEqualTo("1.5") {
  304. streamJSON(job, w, false)
  305. } else if outs, err = job.Stdout.AddTable(); err != nil {
  306. return err
  307. }
  308. if err = job.Run(); err != nil {
  309. return err
  310. }
  311. if version.LessThan("1.5") { // Convert to legacy format
  312. for _, out := range outs.Data {
  313. ports := engine.NewTable("", 0)
  314. ports.ReadListFrom([]byte(out.Get("Ports")))
  315. out.Set("Ports", api.DisplayablePorts(ports))
  316. }
  317. w.Header().Set("Content-Type", "application/json")
  318. if _, err = outs.WriteListTo(w); err != nil {
  319. return err
  320. }
  321. }
  322. return nil
  323. }
  324. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  325. if err := parseForm(r); err != nil {
  326. return err
  327. }
  328. if vars == nil {
  329. return fmt.Errorf("Missing parameter")
  330. }
  331. var (
  332. job = eng.Job("container_inspect", vars["name"])
  333. c, err = job.Stdout.AddEnv()
  334. )
  335. if err != nil {
  336. return err
  337. }
  338. if err = job.Run(); err != nil {
  339. return err
  340. }
  341. var outStream, errStream io.Writer
  342. outStream = utils.NewWriteFlusher(w)
  343. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  344. errStream = utils.NewStdWriter(outStream, utils.Stderr)
  345. outStream = utils.NewStdWriter(outStream, utils.Stdout)
  346. } else {
  347. errStream = outStream
  348. }
  349. job = eng.Job("logs", vars["name"])
  350. job.Setenv("follow", r.Form.Get("follow"))
  351. job.Setenv("stdout", r.Form.Get("stdout"))
  352. job.Setenv("stderr", r.Form.Get("stderr"))
  353. job.Setenv("timestamps", r.Form.Get("timestamps"))
  354. job.Stdout.Add(outStream)
  355. job.Stderr.Set(errStream)
  356. if err := job.Run(); err != nil {
  357. fmt.Fprintf(outStream, "Error: %s\n", err)
  358. }
  359. return nil
  360. }
  361. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  362. if err := parseForm(r); err != nil {
  363. return err
  364. }
  365. if vars == nil {
  366. return fmt.Errorf("Missing parameter")
  367. }
  368. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  369. job.Setenv("force", r.Form.Get("force"))
  370. if err := job.Run(); err != nil {
  371. return err
  372. }
  373. w.WriteHeader(http.StatusCreated)
  374. return nil
  375. }
  376. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  377. if err := parseForm(r); err != nil {
  378. return err
  379. }
  380. var (
  381. config engine.Env
  382. env engine.Env
  383. job = eng.Job("commit", r.Form.Get("container"))
  384. stdoutBuffer = bytes.NewBuffer(nil)
  385. )
  386. if err := config.Decode(r.Body); err != nil {
  387. utils.Errorf("%s", err)
  388. }
  389. job.Setenv("repo", r.Form.Get("repo"))
  390. job.Setenv("tag", r.Form.Get("tag"))
  391. job.Setenv("author", r.Form.Get("author"))
  392. job.Setenv("comment", r.Form.Get("comment"))
  393. job.SetenvSubEnv("config", &config)
  394. job.Stdout.Add(stdoutBuffer)
  395. if err := job.Run(); err != nil {
  396. return err
  397. }
  398. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  399. return writeJSON(w, http.StatusCreated, env)
  400. }
  401. // Creates an image from Pull or from Import
  402. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  403. if err := parseForm(r); err != nil {
  404. return err
  405. }
  406. var (
  407. image = r.Form.Get("fromImage")
  408. tag = r.Form.Get("tag")
  409. job *engine.Job
  410. )
  411. authEncoded := r.Header.Get("X-Registry-Auth")
  412. authConfig := &registry.AuthConfig{}
  413. if authEncoded != "" {
  414. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  415. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  416. // for a pull it is not an error if no auth was given
  417. // to increase compatibility with the existing api it is defaulting to be empty
  418. authConfig = &registry.AuthConfig{}
  419. }
  420. }
  421. if image != "" { //pull
  422. metaHeaders := map[string][]string{}
  423. for k, v := range r.Header {
  424. if strings.HasPrefix(k, "X-Meta-") {
  425. metaHeaders[k] = v
  426. }
  427. }
  428. job = eng.Job("pull", r.Form.Get("fromImage"), tag)
  429. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  430. job.SetenvJson("metaHeaders", metaHeaders)
  431. job.SetenvJson("authConfig", authConfig)
  432. } else { //import
  433. job = eng.Job("import", r.Form.Get("fromSrc"), r.Form.Get("repo"), tag)
  434. job.Stdin.Add(r.Body)
  435. }
  436. if version.GreaterThan("1.0") {
  437. job.SetenvBool("json", true)
  438. streamJSON(job, w, true)
  439. } else {
  440. job.Stdout.Add(utils.NewWriteFlusher(w))
  441. }
  442. if err := job.Run(); err != nil {
  443. if !job.Stdout.Used() {
  444. return err
  445. }
  446. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  447. w.Write(sf.FormatError(err))
  448. }
  449. return nil
  450. }
  451. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  452. if err := parseForm(r); err != nil {
  453. return err
  454. }
  455. var (
  456. authEncoded = r.Header.Get("X-Registry-Auth")
  457. authConfig = &registry.AuthConfig{}
  458. metaHeaders = map[string][]string{}
  459. )
  460. if authEncoded != "" {
  461. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  462. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  463. // for a search it is not an error if no auth was given
  464. // to increase compatibility with the existing api it is defaulting to be empty
  465. authConfig = &registry.AuthConfig{}
  466. }
  467. }
  468. for k, v := range r.Header {
  469. if strings.HasPrefix(k, "X-Meta-") {
  470. metaHeaders[k] = v
  471. }
  472. }
  473. var job = eng.Job("search", r.Form.Get("term"))
  474. job.SetenvJson("metaHeaders", metaHeaders)
  475. job.SetenvJson("authConfig", authConfig)
  476. streamJSON(job, w, false)
  477. return job.Run()
  478. }
  479. // FIXME: 'insert' is deprecated as of 0.10, and should be removed in a future version.
  480. func postImagesInsert(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  481. if err := parseForm(r); err != nil {
  482. return err
  483. }
  484. if vars == nil {
  485. return fmt.Errorf("Missing parameter")
  486. }
  487. job := eng.Job("insert", vars["name"], r.Form.Get("url"), r.Form.Get("path"))
  488. if version.GreaterThan("1.0") {
  489. job.SetenvBool("json", true)
  490. streamJSON(job, w, false)
  491. } else {
  492. job.Stdout.Add(w)
  493. }
  494. if err := job.Run(); err != nil {
  495. if !job.Stdout.Used() {
  496. return err
  497. }
  498. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  499. w.Write(sf.FormatError(err))
  500. }
  501. return nil
  502. }
  503. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  504. if vars == nil {
  505. return fmt.Errorf("Missing parameter")
  506. }
  507. metaHeaders := map[string][]string{}
  508. for k, v := range r.Header {
  509. if strings.HasPrefix(k, "X-Meta-") {
  510. metaHeaders[k] = v
  511. }
  512. }
  513. if err := parseForm(r); err != nil {
  514. return err
  515. }
  516. authConfig := &registry.AuthConfig{}
  517. authEncoded := r.Header.Get("X-Registry-Auth")
  518. if authEncoded != "" {
  519. // the new format is to handle the authConfig as a header
  520. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  521. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  522. // to increase compatibility to existing api it is defaulting to be empty
  523. authConfig = &registry.AuthConfig{}
  524. }
  525. } else {
  526. // the old format is supported for compatibility if there was no authConfig header
  527. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  528. return err
  529. }
  530. }
  531. job := eng.Job("push", vars["name"])
  532. job.SetenvJson("metaHeaders", metaHeaders)
  533. job.SetenvJson("authConfig", authConfig)
  534. job.Setenv("tag", r.Form.Get("tag"))
  535. if version.GreaterThan("1.0") {
  536. job.SetenvBool("json", true)
  537. streamJSON(job, w, true)
  538. } else {
  539. job.Stdout.Add(utils.NewWriteFlusher(w))
  540. }
  541. if err := job.Run(); err != nil {
  542. if !job.Stdout.Used() {
  543. return err
  544. }
  545. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  546. w.Write(sf.FormatError(err))
  547. }
  548. return nil
  549. }
  550. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  551. if vars == nil {
  552. return fmt.Errorf("Missing parameter")
  553. }
  554. if version.GreaterThan("1.0") {
  555. w.Header().Set("Content-Type", "application/x-tar")
  556. }
  557. job := eng.Job("image_export", vars["name"])
  558. job.Stdout.Add(w)
  559. return job.Run()
  560. }
  561. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  562. job := eng.Job("load")
  563. job.Stdin.Add(r.Body)
  564. return job.Run()
  565. }
  566. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  567. if err := parseForm(r); err != nil {
  568. return nil
  569. }
  570. var (
  571. out engine.Env
  572. job = eng.Job("create", r.Form.Get("name"))
  573. outWarnings []string
  574. stdoutBuffer = bytes.NewBuffer(nil)
  575. warnings = bytes.NewBuffer(nil)
  576. )
  577. if err := job.DecodeEnv(r.Body); err != nil {
  578. return err
  579. }
  580. // Read container ID from the first line of stdout
  581. job.Stdout.Add(stdoutBuffer)
  582. // Read warnings from stderr
  583. job.Stderr.Add(warnings)
  584. if err := job.Run(); err != nil {
  585. return err
  586. }
  587. // Parse warnings from stderr
  588. scanner := bufio.NewScanner(warnings)
  589. for scanner.Scan() {
  590. outWarnings = append(outWarnings, scanner.Text())
  591. }
  592. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  593. out.SetList("Warnings", outWarnings)
  594. return writeJSON(w, http.StatusCreated, out)
  595. }
  596. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  597. if err := parseForm(r); err != nil {
  598. return err
  599. }
  600. if vars == nil {
  601. return fmt.Errorf("Missing parameter")
  602. }
  603. job := eng.Job("restart", vars["name"])
  604. job.Setenv("t", r.Form.Get("t"))
  605. if err := job.Run(); err != nil {
  606. return err
  607. }
  608. w.WriteHeader(http.StatusNoContent)
  609. return nil
  610. }
  611. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  612. if err := parseForm(r); err != nil {
  613. return err
  614. }
  615. if vars == nil {
  616. return fmt.Errorf("Missing parameter")
  617. }
  618. job := eng.Job("container_delete", vars["name"])
  619. job.Setenv("removeVolume", r.Form.Get("v"))
  620. job.Setenv("removeLink", r.Form.Get("link"))
  621. job.Setenv("forceRemove", r.Form.Get("force"))
  622. if err := job.Run(); err != nil {
  623. return err
  624. }
  625. w.WriteHeader(http.StatusNoContent)
  626. return nil
  627. }
  628. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  629. if err := parseForm(r); err != nil {
  630. return err
  631. }
  632. if vars == nil {
  633. return fmt.Errorf("Missing parameter")
  634. }
  635. var job = eng.Job("image_delete", vars["name"])
  636. streamJSON(job, w, false)
  637. job.Setenv("force", r.Form.Get("force"))
  638. job.Setenv("noprune", r.Form.Get("noprune"))
  639. return job.Run()
  640. }
  641. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  642. if vars == nil {
  643. return fmt.Errorf("Missing parameter")
  644. }
  645. name := vars["name"]
  646. job := eng.Job("start", name)
  647. // allow a nil body for backwards compatibility
  648. if r.Body != nil {
  649. if api.MatchesContentType(r.Header.Get("Content-Type"), "application/json") {
  650. if err := job.DecodeEnv(r.Body); err != nil {
  651. return err
  652. }
  653. }
  654. }
  655. if err := job.Run(); err != nil {
  656. return err
  657. }
  658. w.WriteHeader(http.StatusNoContent)
  659. return nil
  660. }
  661. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  662. if err := parseForm(r); err != nil {
  663. return err
  664. }
  665. if vars == nil {
  666. return fmt.Errorf("Missing parameter")
  667. }
  668. job := eng.Job("stop", vars["name"])
  669. job.Setenv("t", r.Form.Get("t"))
  670. if err := job.Run(); err != nil {
  671. return err
  672. }
  673. w.WriteHeader(http.StatusNoContent)
  674. return nil
  675. }
  676. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  677. if vars == nil {
  678. return fmt.Errorf("Missing parameter")
  679. }
  680. var (
  681. env engine.Env
  682. stdoutBuffer = bytes.NewBuffer(nil)
  683. job = eng.Job("wait", vars["name"])
  684. )
  685. job.Stdout.Add(stdoutBuffer)
  686. if err := job.Run(); err != nil {
  687. return err
  688. }
  689. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  690. return writeJSON(w, http.StatusOK, env)
  691. }
  692. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  693. if err := parseForm(r); err != nil {
  694. return err
  695. }
  696. if vars == nil {
  697. return fmt.Errorf("Missing parameter")
  698. }
  699. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  700. return err
  701. }
  702. return nil
  703. }
  704. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  705. if err := parseForm(r); err != nil {
  706. return err
  707. }
  708. if vars == nil {
  709. return fmt.Errorf("Missing parameter")
  710. }
  711. var (
  712. job = eng.Job("container_inspect", vars["name"])
  713. c, err = job.Stdout.AddEnv()
  714. )
  715. if err != nil {
  716. return err
  717. }
  718. if err = job.Run(); err != nil {
  719. return err
  720. }
  721. inStream, outStream, err := hijackServer(w)
  722. if err != nil {
  723. return err
  724. }
  725. defer func() {
  726. if tcpc, ok := inStream.(*net.TCPConn); ok {
  727. tcpc.CloseWrite()
  728. } else {
  729. inStream.Close()
  730. }
  731. }()
  732. defer func() {
  733. if tcpc, ok := outStream.(*net.TCPConn); ok {
  734. tcpc.CloseWrite()
  735. } else if closer, ok := outStream.(io.Closer); ok {
  736. closer.Close()
  737. }
  738. }()
  739. var errStream io.Writer
  740. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  741. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  742. errStream = utils.NewStdWriter(outStream, utils.Stderr)
  743. outStream = utils.NewStdWriter(outStream, utils.Stdout)
  744. } else {
  745. errStream = outStream
  746. }
  747. job = eng.Job("attach", vars["name"])
  748. job.Setenv("logs", r.Form.Get("logs"))
  749. job.Setenv("stream", r.Form.Get("stream"))
  750. job.Setenv("stdin", r.Form.Get("stdin"))
  751. job.Setenv("stdout", r.Form.Get("stdout"))
  752. job.Setenv("stderr", r.Form.Get("stderr"))
  753. job.Stdin.Add(inStream)
  754. job.Stdout.Add(outStream)
  755. job.Stderr.Set(errStream)
  756. if err := job.Run(); err != nil {
  757. fmt.Fprintf(outStream, "Error: %s\n", err)
  758. }
  759. return nil
  760. }
  761. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  762. if err := parseForm(r); err != nil {
  763. return err
  764. }
  765. if vars == nil {
  766. return fmt.Errorf("Missing parameter")
  767. }
  768. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  769. return err
  770. }
  771. h := websocket.Handler(func(ws *websocket.Conn) {
  772. defer ws.Close()
  773. job := eng.Job("attach", vars["name"])
  774. job.Setenv("logs", r.Form.Get("logs"))
  775. job.Setenv("stream", r.Form.Get("stream"))
  776. job.Setenv("stdin", r.Form.Get("stdin"))
  777. job.Setenv("stdout", r.Form.Get("stdout"))
  778. job.Setenv("stderr", r.Form.Get("stderr"))
  779. job.Stdin.Add(ws)
  780. job.Stdout.Add(ws)
  781. job.Stderr.Set(ws)
  782. if err := job.Run(); err != nil {
  783. utils.Errorf("Error: %s", err)
  784. }
  785. })
  786. h.ServeHTTP(w, r)
  787. return nil
  788. }
  789. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  790. if vars == nil {
  791. return fmt.Errorf("Missing parameter")
  792. }
  793. var job = eng.Job("container_inspect", vars["name"])
  794. if version.LessThan("1.12") {
  795. job.SetenvBool("dirty", true)
  796. }
  797. streamJSON(job, w, false)
  798. return job.Run()
  799. }
  800. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  801. if vars == nil {
  802. return fmt.Errorf("Missing parameter")
  803. }
  804. var job = eng.Job("image_inspect", vars["name"])
  805. if version.LessThan("1.12") {
  806. job.SetenvBool("dirty", true)
  807. }
  808. streamJSON(job, w, false)
  809. return job.Run()
  810. }
  811. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  812. if version.LessThan("1.3") {
  813. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  814. }
  815. var (
  816. authEncoded = r.Header.Get("X-Registry-Auth")
  817. authConfig = &registry.AuthConfig{}
  818. configFileEncoded = r.Header.Get("X-Registry-Config")
  819. configFile = &registry.ConfigFile{}
  820. job = eng.Job("build")
  821. )
  822. // This block can be removed when API versions prior to 1.9 are deprecated.
  823. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  824. // ConfigFile is present, any value provided as an AuthConfig directly will
  825. // be overridden. See BuildFile::CmdFrom for details.
  826. if version.LessThan("1.9") && authEncoded != "" {
  827. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  828. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  829. // for a pull it is not an error if no auth was given
  830. // to increase compatibility with the existing api it is defaulting to be empty
  831. authConfig = &registry.AuthConfig{}
  832. }
  833. }
  834. if configFileEncoded != "" {
  835. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  836. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  837. // for a pull it is not an error if no auth was given
  838. // to increase compatibility with the existing api it is defaulting to be empty
  839. configFile = &registry.ConfigFile{}
  840. }
  841. }
  842. if version.GreaterThanOrEqualTo("1.8") {
  843. job.SetenvBool("json", true)
  844. streamJSON(job, w, true)
  845. } else {
  846. job.Stdout.Add(utils.NewWriteFlusher(w))
  847. }
  848. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  849. job.Setenv("rm", "1")
  850. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  851. job.Setenv("rm", "1")
  852. } else {
  853. job.Setenv("rm", r.FormValue("rm"))
  854. }
  855. job.Stdin.Add(r.Body)
  856. job.Setenv("remote", r.FormValue("remote"))
  857. job.Setenv("t", r.FormValue("t"))
  858. job.Setenv("q", r.FormValue("q"))
  859. job.Setenv("nocache", r.FormValue("nocache"))
  860. job.Setenv("forcerm", r.FormValue("forcerm"))
  861. job.SetenvJson("authConfig", authConfig)
  862. job.SetenvJson("configFile", configFile)
  863. if err := job.Run(); err != nil {
  864. if !job.Stdout.Used() {
  865. return err
  866. }
  867. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  868. w.Write(sf.FormatError(err))
  869. }
  870. return nil
  871. }
  872. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  873. if vars == nil {
  874. return fmt.Errorf("Missing parameter")
  875. }
  876. var copyData engine.Env
  877. if contentType := r.Header.Get("Content-Type"); api.MatchesContentType(contentType, "application/json") {
  878. if err := copyData.Decode(r.Body); err != nil {
  879. return err
  880. }
  881. } else {
  882. return fmt.Errorf("Content-Type not supported: %s", contentType)
  883. }
  884. if copyData.Get("Resource") == "" {
  885. return fmt.Errorf("Path cannot be empty")
  886. }
  887. origResource := copyData.Get("Resource")
  888. if copyData.Get("Resource")[0] == '/' {
  889. copyData.Set("Resource", copyData.Get("Resource")[1:])
  890. }
  891. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  892. job.Stdout.Add(w)
  893. if err := job.Run(); err != nil {
  894. utils.Errorf("%s", err.Error())
  895. if strings.Contains(err.Error(), "No such container") {
  896. w.WriteHeader(http.StatusNotFound)
  897. } else if strings.Contains(err.Error(), "no such file or directory") {
  898. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  899. }
  900. }
  901. return nil
  902. }
  903. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  904. w.WriteHeader(http.StatusOK)
  905. return nil
  906. }
  907. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  908. w.Header().Add("Access-Control-Allow-Origin", "*")
  909. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept")
  910. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  911. }
  912. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  913. _, err := w.Write([]byte{'O', 'K'})
  914. return err
  915. }
  916. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  917. return func(w http.ResponseWriter, r *http.Request) {
  918. // log the request
  919. utils.Debugf("Calling %s %s", localMethod, localRoute)
  920. if logging {
  921. log.Println(r.Method, r.RequestURI)
  922. }
  923. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  924. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  925. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  926. utils.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  927. }
  928. }
  929. version := version.Version(mux.Vars(r)["version"])
  930. if version == "" {
  931. version = api.APIVERSION
  932. }
  933. if enableCors {
  934. writeCorsHeaders(w, r)
  935. }
  936. if version.GreaterThan(api.APIVERSION) {
  937. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  938. return
  939. }
  940. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  941. utils.Errorf("Error: %s", err)
  942. httpError(w, err)
  943. }
  944. }
  945. }
  946. // Replicated from expvar.go as not public.
  947. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  948. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  949. fmt.Fprintf(w, "{\n")
  950. first := true
  951. expvar.Do(func(kv expvar.KeyValue) {
  952. if !first {
  953. fmt.Fprintf(w, ",\n")
  954. }
  955. first = false
  956. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  957. })
  958. fmt.Fprintf(w, "\n}\n")
  959. }
  960. func AttachProfiler(router *mux.Router) {
  961. router.HandleFunc("/debug/vars", expvarHandler)
  962. router.HandleFunc("/debug/pprof/", pprof.Index)
  963. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  964. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  965. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  966. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  967. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  968. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  969. }
  970. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) (*mux.Router, error) {
  971. r := mux.NewRouter()
  972. if os.Getenv("DEBUG") != "" {
  973. AttachProfiler(r)
  974. }
  975. m := map[string]map[string]HttpApiFunc{
  976. "GET": {
  977. "/_ping": ping,
  978. "/events": getEvents,
  979. "/info": getInfo,
  980. "/version": getVersion,
  981. "/images/json": getImagesJSON,
  982. "/images/viz": getImagesViz,
  983. "/images/search": getImagesSearch,
  984. "/images/{name:.*}/get": getImagesGet,
  985. "/images/{name:.*}/history": getImagesHistory,
  986. "/images/{name:.*}/json": getImagesByName,
  987. "/containers/ps": getContainersJSON,
  988. "/containers/json": getContainersJSON,
  989. "/containers/{name:.*}/export": getContainersExport,
  990. "/containers/{name:.*}/changes": getContainersChanges,
  991. "/containers/{name:.*}/json": getContainersByName,
  992. "/containers/{name:.*}/top": getContainersTop,
  993. "/containers/{name:.*}/logs": getContainersLogs,
  994. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  995. },
  996. "POST": {
  997. "/auth": postAuth,
  998. "/commit": postCommit,
  999. "/build": postBuild,
  1000. "/images/create": postImagesCreate,
  1001. "/images/{name:.*}/insert": postImagesInsert,
  1002. "/images/load": postImagesLoad,
  1003. "/images/{name:.*}/push": postImagesPush,
  1004. "/images/{name:.*}/tag": postImagesTag,
  1005. "/containers/create": postContainersCreate,
  1006. "/containers/{name:.*}/kill": postContainersKill,
  1007. "/containers/{name:.*}/pause": postContainersPause,
  1008. "/containers/{name:.*}/unpause": postContainersUnpause,
  1009. "/containers/{name:.*}/restart": postContainersRestart,
  1010. "/containers/{name:.*}/start": postContainersStart,
  1011. "/containers/{name:.*}/stop": postContainersStop,
  1012. "/containers/{name:.*}/wait": postContainersWait,
  1013. "/containers/{name:.*}/resize": postContainersResize,
  1014. "/containers/{name:.*}/attach": postContainersAttach,
  1015. "/containers/{name:.*}/copy": postContainersCopy,
  1016. },
  1017. "DELETE": {
  1018. "/containers/{name:.*}": deleteContainers,
  1019. "/images/{name:.*}": deleteImages,
  1020. },
  1021. "OPTIONS": {
  1022. "": optionsHandler,
  1023. },
  1024. }
  1025. for method, routes := range m {
  1026. for route, fct := range routes {
  1027. utils.Debugf("Registering %s, %s", method, route)
  1028. // NOTE: scope issue, make sure the variables are local and won't be changed
  1029. localRoute := route
  1030. localFct := fct
  1031. localMethod := method
  1032. // build the handler function
  1033. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1034. // add the new route
  1035. if localRoute == "" {
  1036. r.Methods(localMethod).HandlerFunc(f)
  1037. } else {
  1038. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1039. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1040. }
  1041. }
  1042. }
  1043. return r, nil
  1044. }
  1045. // ServeRequest processes a single http request to the docker remote api.
  1046. // FIXME: refactor this to be part of Server and not require re-creating a new
  1047. // router each time. This requires first moving ListenAndServe into Server.
  1048. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) error {
  1049. router, err := createRouter(eng, false, true, "")
  1050. if err != nil {
  1051. return err
  1052. }
  1053. // Insert APIVERSION into the request as a convenience
  1054. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1055. router.ServeHTTP(w, req)
  1056. return nil
  1057. }
  1058. // ServeFD creates an http.Server and sets it up to serve given a socket activated
  1059. // argument.
  1060. func ServeFd(addr string, handle http.Handler) error {
  1061. ls, e := systemd.ListenFD(addr)
  1062. if e != nil {
  1063. return e
  1064. }
  1065. chErrors := make(chan error, len(ls))
  1066. // We don't want to start serving on these sockets until the
  1067. // "initserver" job has completed. Otherwise required handlers
  1068. // won't be ready.
  1069. <-activationLock
  1070. // Since ListenFD will return one or more sockets we have
  1071. // to create a go func to spawn off multiple serves
  1072. for i := range ls {
  1073. listener := ls[i]
  1074. go func() {
  1075. httpSrv := http.Server{Handler: handle}
  1076. chErrors <- httpSrv.Serve(listener)
  1077. }()
  1078. }
  1079. for i := 0; i < len(ls); i += 1 {
  1080. err := <-chErrors
  1081. if err != nil {
  1082. return err
  1083. }
  1084. }
  1085. return nil
  1086. }
  1087. func lookupGidByName(nameOrGid string) (int, error) {
  1088. groups, err := user.ParseGroupFilter(func(g *user.Group) bool {
  1089. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1090. })
  1091. if err != nil {
  1092. return -1, err
  1093. }
  1094. if groups != nil && len(groups) > 0 {
  1095. return groups[0].Gid, nil
  1096. }
  1097. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1098. }
  1099. func changeGroup(addr string, nameOrGid string) error {
  1100. gid, err := lookupGidByName(nameOrGid)
  1101. if err != nil {
  1102. return err
  1103. }
  1104. utils.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1105. return os.Chown(addr, 0, gid)
  1106. }
  1107. // ListenAndServe sets up the required http.Server and gets it listening for
  1108. // each addr passed in and does protocol specific checking.
  1109. func ListenAndServe(proto, addr string, job *engine.Job) error {
  1110. var l net.Listener
  1111. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1112. if err != nil {
  1113. return err
  1114. }
  1115. if proto == "fd" {
  1116. return ServeFd(addr, r)
  1117. }
  1118. if proto == "unix" {
  1119. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1120. return err
  1121. }
  1122. }
  1123. var oldmask int
  1124. if proto == "unix" {
  1125. oldmask = syscall.Umask(0777)
  1126. }
  1127. if job.GetenvBool("BufferRequests") {
  1128. l, err = listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1129. } else {
  1130. l, err = net.Listen(proto, addr)
  1131. }
  1132. if proto == "unix" {
  1133. syscall.Umask(oldmask)
  1134. }
  1135. if err != nil {
  1136. return err
  1137. }
  1138. if proto != "unix" && (job.GetenvBool("Tls") || job.GetenvBool("TlsVerify")) {
  1139. tlsCert := job.Getenv("TlsCert")
  1140. tlsKey := job.Getenv("TlsKey")
  1141. cert, err := tls.LoadX509KeyPair(tlsCert, tlsKey)
  1142. if err != nil {
  1143. return fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1144. tlsCert, tlsKey, err)
  1145. }
  1146. tlsConfig := &tls.Config{
  1147. NextProtos: []string{"http/1.1"},
  1148. Certificates: []tls.Certificate{cert},
  1149. }
  1150. if job.GetenvBool("TlsVerify") {
  1151. certPool := x509.NewCertPool()
  1152. file, err := ioutil.ReadFile(job.Getenv("TlsCa"))
  1153. if err != nil {
  1154. return fmt.Errorf("Couldn't read CA certificate: %s", err)
  1155. }
  1156. certPool.AppendCertsFromPEM(file)
  1157. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1158. tlsConfig.ClientCAs = certPool
  1159. }
  1160. l = tls.NewListener(l, tlsConfig)
  1161. }
  1162. // Basic error and sanity checking
  1163. switch proto {
  1164. case "tcp":
  1165. if !strings.HasPrefix(addr, "127.0.0.1") && !job.GetenvBool("TlsVerify") {
  1166. log.Println("/!\\ DON'T BIND ON ANOTHER IP ADDRESS THAN 127.0.0.1 IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1167. }
  1168. case "unix":
  1169. socketGroup := job.Getenv("SocketGroup")
  1170. if socketGroup != "" {
  1171. if err := changeGroup(addr, socketGroup); err != nil {
  1172. if socketGroup == "docker" {
  1173. // if the user hasn't explicitly specified the group ownership, don't fail on errors.
  1174. utils.Debugf("Warning: could not chgrp %s to docker: %s", addr, err.Error())
  1175. } else {
  1176. return err
  1177. }
  1178. }
  1179. }
  1180. if err := os.Chmod(addr, 0660); err != nil {
  1181. return err
  1182. }
  1183. default:
  1184. return fmt.Errorf("Invalid protocol format.")
  1185. }
  1186. httpSrv := http.Server{Addr: addr, Handler: r}
  1187. return httpSrv.Serve(l)
  1188. }
  1189. // ServeApi loops through all of the protocols sent in to docker and spawns
  1190. // off a go routine to setup a serving http.Server for each.
  1191. func ServeApi(job *engine.Job) engine.Status {
  1192. if len(job.Args) == 0 {
  1193. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1194. }
  1195. var (
  1196. protoAddrs = job.Args
  1197. chErrors = make(chan error, len(protoAddrs))
  1198. )
  1199. activationLock = make(chan struct{})
  1200. for _, protoAddr := range protoAddrs {
  1201. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1202. if len(protoAddrParts) != 2 {
  1203. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1204. }
  1205. go func() {
  1206. log.Printf("Listening for HTTP on %s (%s)\n", protoAddrParts[0], protoAddrParts[1])
  1207. chErrors <- ListenAndServe(protoAddrParts[0], protoAddrParts[1], job)
  1208. }()
  1209. }
  1210. for i := 0; i < len(protoAddrs); i += 1 {
  1211. err := <-chErrors
  1212. if err != nil {
  1213. return job.Error(err)
  1214. }
  1215. }
  1216. return engine.StatusOK
  1217. }
  1218. func AcceptConnections(job *engine.Job) engine.Status {
  1219. // Tell the init daemon we are accepting requests
  1220. go systemd.SdNotify("READY=1")
  1221. // close the lock so the listeners start accepting connections
  1222. if activationLock != nil {
  1223. close(activationLock)
  1224. }
  1225. return engine.StatusOK
  1226. }