server.go 40 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "crypto/tls"
  6. "crypto/x509"
  7. "encoding/base64"
  8. "encoding/json"
  9. "expvar"
  10. "fmt"
  11. "io"
  12. "io/ioutil"
  13. "log"
  14. "net"
  15. "net/http"
  16. "net/http/pprof"
  17. "os"
  18. "strconv"
  19. "strings"
  20. "syscall"
  21. "code.google.com/p/go.net/websocket"
  22. "github.com/docker/docker/api"
  23. "github.com/docker/docker/engine"
  24. "github.com/docker/docker/pkg/listenbuffer"
  25. "github.com/docker/docker/pkg/systemd"
  26. "github.com/docker/docker/pkg/user"
  27. "github.com/docker/docker/pkg/version"
  28. "github.com/docker/docker/registry"
  29. "github.com/docker/docker/utils"
  30. "github.com/gorilla/mux"
  31. )
  32. var (
  33. activationLock chan struct{}
  34. )
  35. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  36. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  37. conn, _, err := w.(http.Hijacker).Hijack()
  38. if err != nil {
  39. return nil, nil, err
  40. }
  41. // Flush the options to make sure the client sets the raw mode
  42. conn.Write([]byte{})
  43. return conn, conn, nil
  44. }
  45. //If we don't do this, POST method without Content-type (even with empty body) will fail
  46. func parseForm(r *http.Request) error {
  47. if r == nil {
  48. return nil
  49. }
  50. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  51. return err
  52. }
  53. return nil
  54. }
  55. func parseMultipartForm(r *http.Request) error {
  56. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  57. return err
  58. }
  59. return nil
  60. }
  61. func httpError(w http.ResponseWriter, err error) {
  62. statusCode := http.StatusInternalServerError
  63. // FIXME: this is brittle and should not be necessary.
  64. // If we need to differentiate between different possible error types, we should
  65. // create appropriate error types with clearly defined meaning.
  66. if strings.Contains(err.Error(), "No such") {
  67. statusCode = http.StatusNotFound
  68. } else if strings.Contains(err.Error(), "Bad parameter") {
  69. statusCode = http.StatusBadRequest
  70. } else if strings.Contains(err.Error(), "Conflict") {
  71. statusCode = http.StatusConflict
  72. } else if strings.Contains(err.Error(), "Impossible") {
  73. statusCode = http.StatusNotAcceptable
  74. } else if strings.Contains(err.Error(), "Wrong login/password") {
  75. statusCode = http.StatusUnauthorized
  76. } else if strings.Contains(err.Error(), "hasn't been activated") {
  77. statusCode = http.StatusForbidden
  78. }
  79. if err != nil {
  80. utils.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  81. http.Error(w, err.Error(), statusCode)
  82. }
  83. }
  84. func writeJSON(w http.ResponseWriter, code int, v engine.Env) error {
  85. w.Header().Set("Content-Type", "application/json")
  86. w.WriteHeader(code)
  87. return v.Encode(w)
  88. }
  89. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  90. w.Header().Set("Content-Type", "application/json")
  91. if flush {
  92. job.Stdout.Add(utils.NewWriteFlusher(w))
  93. } else {
  94. job.Stdout.Add(w)
  95. }
  96. }
  97. func getBoolParam(value string) (bool, error) {
  98. if value == "" {
  99. return false, nil
  100. }
  101. ret, err := strconv.ParseBool(value)
  102. if err != nil {
  103. return false, fmt.Errorf("Bad parameter")
  104. }
  105. return ret, nil
  106. }
  107. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  108. var (
  109. authConfig, err = ioutil.ReadAll(r.Body)
  110. job = eng.Job("auth")
  111. stdoutBuffer = bytes.NewBuffer(nil)
  112. )
  113. if err != nil {
  114. return err
  115. }
  116. job.Setenv("authConfig", string(authConfig))
  117. job.Stdout.Add(stdoutBuffer)
  118. if err = job.Run(); err != nil {
  119. return err
  120. }
  121. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  122. var env engine.Env
  123. env.Set("Status", status)
  124. return writeJSON(w, http.StatusOK, env)
  125. }
  126. w.WriteHeader(http.StatusNoContent)
  127. return nil
  128. }
  129. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  130. w.Header().Set("Content-Type", "application/json")
  131. eng.ServeHTTP(w, r)
  132. return nil
  133. }
  134. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  135. if vars == nil {
  136. return fmt.Errorf("Missing parameter")
  137. }
  138. if err := parseForm(r); err != nil {
  139. return err
  140. }
  141. job := eng.Job("kill", vars["name"])
  142. if sig := r.Form.Get("signal"); sig != "" {
  143. job.Args = append(job.Args, sig)
  144. }
  145. if err := job.Run(); err != nil {
  146. return err
  147. }
  148. w.WriteHeader(http.StatusNoContent)
  149. return nil
  150. }
  151. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  152. if vars == nil {
  153. return fmt.Errorf("Missing parameter")
  154. }
  155. if err := parseForm(r); err != nil {
  156. return err
  157. }
  158. job := eng.Job("pause", vars["name"])
  159. if err := job.Run(); err != nil {
  160. return err
  161. }
  162. w.WriteHeader(http.StatusNoContent)
  163. return nil
  164. }
  165. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  166. if vars == nil {
  167. return fmt.Errorf("Missing parameter")
  168. }
  169. if err := parseForm(r); err != nil {
  170. return err
  171. }
  172. job := eng.Job("unpause", vars["name"])
  173. if err := job.Run(); err != nil {
  174. return err
  175. }
  176. w.WriteHeader(http.StatusNoContent)
  177. return nil
  178. }
  179. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  180. if vars == nil {
  181. return fmt.Errorf("Missing parameter")
  182. }
  183. job := eng.Job("export", vars["name"])
  184. job.Stdout.Add(w)
  185. if err := job.Run(); err != nil {
  186. return err
  187. }
  188. return nil
  189. }
  190. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  191. if err := parseForm(r); err != nil {
  192. return err
  193. }
  194. var (
  195. err error
  196. outs *engine.Table
  197. job = eng.Job("images")
  198. )
  199. job.Setenv("filters", r.Form.Get("filters"))
  200. // FIXME this parameter could just be a match filter
  201. job.Setenv("filter", r.Form.Get("filter"))
  202. job.Setenv("all", r.Form.Get("all"))
  203. if version.GreaterThanOrEqualTo("1.7") {
  204. streamJSON(job, w, false)
  205. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  206. return err
  207. }
  208. if err := job.Run(); err != nil {
  209. return err
  210. }
  211. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  212. outsLegacy := engine.NewTable("Created", 0)
  213. for _, out := range outs.Data {
  214. for _, repoTag := range out.GetList("RepoTags") {
  215. parts := strings.Split(repoTag, ":")
  216. outLegacy := &engine.Env{}
  217. outLegacy.Set("Repository", parts[0])
  218. outLegacy.Set("Tag", parts[1])
  219. outLegacy.Set("Id", out.Get("Id"))
  220. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  221. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  222. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  223. outsLegacy.Add(outLegacy)
  224. }
  225. }
  226. w.Header().Set("Content-Type", "application/json")
  227. if _, err := outsLegacy.WriteListTo(w); err != nil {
  228. return err
  229. }
  230. }
  231. return nil
  232. }
  233. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  234. if version.GreaterThan("1.6") {
  235. w.WriteHeader(http.StatusNotFound)
  236. return fmt.Errorf("This is now implemented in the client.")
  237. }
  238. eng.ServeHTTP(w, r)
  239. return nil
  240. }
  241. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  242. w.Header().Set("Content-Type", "application/json")
  243. eng.ServeHTTP(w, r)
  244. return nil
  245. }
  246. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  247. if err := parseForm(r); err != nil {
  248. return err
  249. }
  250. var job = eng.Job("events")
  251. streamJSON(job, w, true)
  252. job.Setenv("since", r.Form.Get("since"))
  253. job.Setenv("until", r.Form.Get("until"))
  254. return job.Run()
  255. }
  256. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  257. if vars == nil {
  258. return fmt.Errorf("Missing parameter")
  259. }
  260. var job = eng.Job("history", vars["name"])
  261. streamJSON(job, w, false)
  262. if err := job.Run(); err != nil {
  263. return err
  264. }
  265. return nil
  266. }
  267. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  268. if vars == nil {
  269. return fmt.Errorf("Missing parameter")
  270. }
  271. var job = eng.Job("changes", vars["name"])
  272. streamJSON(job, w, false)
  273. return job.Run()
  274. }
  275. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  276. if version.LessThan("1.4") {
  277. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  278. }
  279. if vars == nil {
  280. return fmt.Errorf("Missing parameter")
  281. }
  282. if err := parseForm(r); err != nil {
  283. return err
  284. }
  285. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  286. streamJSON(job, w, false)
  287. return job.Run()
  288. }
  289. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  290. if err := parseForm(r); err != nil {
  291. return err
  292. }
  293. var (
  294. err error
  295. outs *engine.Table
  296. job = eng.Job("containers")
  297. )
  298. job.Setenv("all", r.Form.Get("all"))
  299. job.Setenv("size", r.Form.Get("size"))
  300. job.Setenv("since", r.Form.Get("since"))
  301. job.Setenv("before", r.Form.Get("before"))
  302. job.Setenv("limit", r.Form.Get("limit"))
  303. if version.GreaterThanOrEqualTo("1.5") {
  304. streamJSON(job, w, false)
  305. } else if outs, err = job.Stdout.AddTable(); err != nil {
  306. return err
  307. }
  308. if err = job.Run(); err != nil {
  309. return err
  310. }
  311. if version.LessThan("1.5") { // Convert to legacy format
  312. for _, out := range outs.Data {
  313. ports := engine.NewTable("", 0)
  314. ports.ReadListFrom([]byte(out.Get("Ports")))
  315. out.Set("Ports", api.DisplayablePorts(ports))
  316. }
  317. w.Header().Set("Content-Type", "application/json")
  318. if _, err = outs.WriteListTo(w); err != nil {
  319. return err
  320. }
  321. }
  322. return nil
  323. }
  324. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  325. if err := parseForm(r); err != nil {
  326. return err
  327. }
  328. if vars == nil {
  329. return fmt.Errorf("Missing parameter")
  330. }
  331. var (
  332. inspectJob = eng.Job("container_inspect", vars["name"])
  333. logsJob = eng.Job("logs", vars["name"])
  334. c, err = inspectJob.Stdout.AddEnv()
  335. )
  336. if err != nil {
  337. return err
  338. }
  339. logsJob.Setenv("follow", r.Form.Get("follow"))
  340. logsJob.Setenv("tail", r.Form.Get("tail"))
  341. logsJob.Setenv("stdout", r.Form.Get("stdout"))
  342. logsJob.Setenv("stderr", r.Form.Get("stderr"))
  343. logsJob.Setenv("timestamps", r.Form.Get("timestamps"))
  344. // Validate args here, because we can't return not StatusOK after job.Run() call
  345. stdout, stderr := logsJob.GetenvBool("stdout"), logsJob.GetenvBool("stderr")
  346. if !(stdout || stderr) {
  347. return fmt.Errorf("Bad parameters: you must choose at least one stream")
  348. }
  349. if err = inspectJob.Run(); err != nil {
  350. return err
  351. }
  352. var outStream, errStream io.Writer
  353. outStream = utils.NewWriteFlusher(w)
  354. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  355. errStream = utils.NewStdWriter(outStream, utils.Stderr)
  356. outStream = utils.NewStdWriter(outStream, utils.Stdout)
  357. } else {
  358. errStream = outStream
  359. }
  360. logsJob.Stdout.Add(outStream)
  361. logsJob.Stderr.Set(errStream)
  362. if err := logsJob.Run(); err != nil {
  363. fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
  364. }
  365. return nil
  366. }
  367. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  368. if err := parseForm(r); err != nil {
  369. return err
  370. }
  371. if vars == nil {
  372. return fmt.Errorf("Missing parameter")
  373. }
  374. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  375. job.Setenv("force", r.Form.Get("force"))
  376. if err := job.Run(); err != nil {
  377. return err
  378. }
  379. w.WriteHeader(http.StatusCreated)
  380. return nil
  381. }
  382. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  383. if err := parseForm(r); err != nil {
  384. return err
  385. }
  386. var (
  387. config engine.Env
  388. env engine.Env
  389. job = eng.Job("commit", r.Form.Get("container"))
  390. stdoutBuffer = bytes.NewBuffer(nil)
  391. )
  392. if err := config.Decode(r.Body); err != nil {
  393. utils.Errorf("%s", err)
  394. }
  395. if r.FormValue("pause") == "" && version.GreaterThanOrEqualTo("1.13") {
  396. job.Setenv("pause", "1")
  397. } else {
  398. job.Setenv("pause", r.FormValue("pause"))
  399. }
  400. job.Setenv("repo", r.Form.Get("repo"))
  401. job.Setenv("tag", r.Form.Get("tag"))
  402. job.Setenv("author", r.Form.Get("author"))
  403. job.Setenv("comment", r.Form.Get("comment"))
  404. job.SetenvSubEnv("config", &config)
  405. job.Stdout.Add(stdoutBuffer)
  406. if err := job.Run(); err != nil {
  407. return err
  408. }
  409. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  410. return writeJSON(w, http.StatusCreated, env)
  411. }
  412. // Creates an image from Pull or from Import
  413. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  414. if err := parseForm(r); err != nil {
  415. return err
  416. }
  417. var (
  418. image = r.Form.Get("fromImage")
  419. repo = r.Form.Get("repo")
  420. tag = r.Form.Get("tag")
  421. job *engine.Job
  422. )
  423. authEncoded := r.Header.Get("X-Registry-Auth")
  424. authConfig := &registry.AuthConfig{}
  425. if authEncoded != "" {
  426. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  427. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  428. // for a pull it is not an error if no auth was given
  429. // to increase compatibility with the existing api it is defaulting to be empty
  430. authConfig = &registry.AuthConfig{}
  431. }
  432. }
  433. if image != "" { //pull
  434. if tag == "" {
  435. image, tag = utils.ParseRepositoryTag(image)
  436. }
  437. metaHeaders := map[string][]string{}
  438. for k, v := range r.Header {
  439. if strings.HasPrefix(k, "X-Meta-") {
  440. metaHeaders[k] = v
  441. }
  442. }
  443. job = eng.Job("pull", image, tag)
  444. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  445. job.SetenvJson("metaHeaders", metaHeaders)
  446. job.SetenvJson("authConfig", authConfig)
  447. } else { //import
  448. if tag == "" {
  449. repo, tag = utils.ParseRepositoryTag(repo)
  450. }
  451. job = eng.Job("import", r.Form.Get("fromSrc"), repo, tag)
  452. job.Stdin.Add(r.Body)
  453. }
  454. if version.GreaterThan("1.0") {
  455. job.SetenvBool("json", true)
  456. streamJSON(job, w, true)
  457. } else {
  458. job.Stdout.Add(utils.NewWriteFlusher(w))
  459. }
  460. if err := job.Run(); err != nil {
  461. if !job.Stdout.Used() {
  462. return err
  463. }
  464. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  465. w.Write(sf.FormatError(err))
  466. }
  467. return nil
  468. }
  469. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  470. if err := parseForm(r); err != nil {
  471. return err
  472. }
  473. var (
  474. authEncoded = r.Header.Get("X-Registry-Auth")
  475. authConfig = &registry.AuthConfig{}
  476. metaHeaders = map[string][]string{}
  477. )
  478. if authEncoded != "" {
  479. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  480. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  481. // for a search it is not an error if no auth was given
  482. // to increase compatibility with the existing api it is defaulting to be empty
  483. authConfig = &registry.AuthConfig{}
  484. }
  485. }
  486. for k, v := range r.Header {
  487. if strings.HasPrefix(k, "X-Meta-") {
  488. metaHeaders[k] = v
  489. }
  490. }
  491. var job = eng.Job("search", r.Form.Get("term"))
  492. job.SetenvJson("metaHeaders", metaHeaders)
  493. job.SetenvJson("authConfig", authConfig)
  494. streamJSON(job, w, false)
  495. return job.Run()
  496. }
  497. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  498. if vars == nil {
  499. return fmt.Errorf("Missing parameter")
  500. }
  501. metaHeaders := map[string][]string{}
  502. for k, v := range r.Header {
  503. if strings.HasPrefix(k, "X-Meta-") {
  504. metaHeaders[k] = v
  505. }
  506. }
  507. if err := parseForm(r); err != nil {
  508. return err
  509. }
  510. authConfig := &registry.AuthConfig{}
  511. authEncoded := r.Header.Get("X-Registry-Auth")
  512. if authEncoded != "" {
  513. // the new format is to handle the authConfig as a header
  514. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  515. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  516. // to increase compatibility to existing api it is defaulting to be empty
  517. authConfig = &registry.AuthConfig{}
  518. }
  519. } else {
  520. // the old format is supported for compatibility if there was no authConfig header
  521. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  522. return err
  523. }
  524. }
  525. job := eng.Job("push", vars["name"])
  526. job.SetenvJson("metaHeaders", metaHeaders)
  527. job.SetenvJson("authConfig", authConfig)
  528. job.Setenv("tag", r.Form.Get("tag"))
  529. if version.GreaterThan("1.0") {
  530. job.SetenvBool("json", true)
  531. streamJSON(job, w, true)
  532. } else {
  533. job.Stdout.Add(utils.NewWriteFlusher(w))
  534. }
  535. if err := job.Run(); err != nil {
  536. if !job.Stdout.Used() {
  537. return err
  538. }
  539. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  540. w.Write(sf.FormatError(err))
  541. }
  542. return nil
  543. }
  544. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  545. if vars == nil {
  546. return fmt.Errorf("Missing parameter")
  547. }
  548. if version.GreaterThan("1.0") {
  549. w.Header().Set("Content-Type", "application/x-tar")
  550. }
  551. job := eng.Job("image_export", vars["name"])
  552. job.Stdout.Add(w)
  553. return job.Run()
  554. }
  555. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  556. job := eng.Job("load")
  557. job.Stdin.Add(r.Body)
  558. return job.Run()
  559. }
  560. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  561. if err := parseForm(r); err != nil {
  562. return nil
  563. }
  564. var (
  565. out engine.Env
  566. job = eng.Job("create", r.Form.Get("name"))
  567. outWarnings []string
  568. stdoutBuffer = bytes.NewBuffer(nil)
  569. warnings = bytes.NewBuffer(nil)
  570. )
  571. if err := job.DecodeEnv(r.Body); err != nil {
  572. return err
  573. }
  574. // Read container ID from the first line of stdout
  575. job.Stdout.Add(stdoutBuffer)
  576. // Read warnings from stderr
  577. job.Stderr.Add(warnings)
  578. if err := job.Run(); err != nil {
  579. return err
  580. }
  581. // Parse warnings from stderr
  582. scanner := bufio.NewScanner(warnings)
  583. for scanner.Scan() {
  584. outWarnings = append(outWarnings, scanner.Text())
  585. }
  586. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  587. out.SetList("Warnings", outWarnings)
  588. return writeJSON(w, http.StatusCreated, out)
  589. }
  590. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  591. if err := parseForm(r); err != nil {
  592. return err
  593. }
  594. if vars == nil {
  595. return fmt.Errorf("Missing parameter")
  596. }
  597. job := eng.Job("restart", vars["name"])
  598. job.Setenv("t", r.Form.Get("t"))
  599. if err := job.Run(); err != nil {
  600. return err
  601. }
  602. w.WriteHeader(http.StatusNoContent)
  603. return nil
  604. }
  605. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  606. if err := parseForm(r); err != nil {
  607. return err
  608. }
  609. if vars == nil {
  610. return fmt.Errorf("Missing parameter")
  611. }
  612. job := eng.Job("container_delete", vars["name"])
  613. if version.GreaterThanOrEqualTo("1.14") {
  614. job.Setenv("stop", r.Form.Get("stop"))
  615. job.Setenv("kill", r.Form.Get("kill"))
  616. if job.GetenvBool("stop") && job.GetenvBool("kill") {
  617. return fmt.Errorf("Bad parameters: can't use stop and kill simultaneously")
  618. }
  619. } else {
  620. job.Setenv("stop", r.Form.Get("force"))
  621. }
  622. job.Setenv("removeVolume", r.Form.Get("v"))
  623. job.Setenv("removeLink", r.Form.Get("link"))
  624. if err := job.Run(); err != nil {
  625. return err
  626. }
  627. w.WriteHeader(http.StatusNoContent)
  628. return nil
  629. }
  630. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  631. if err := parseForm(r); err != nil {
  632. return err
  633. }
  634. if vars == nil {
  635. return fmt.Errorf("Missing parameter")
  636. }
  637. var job = eng.Job("image_delete", vars["name"])
  638. streamJSON(job, w, false)
  639. job.Setenv("force", r.Form.Get("force"))
  640. job.Setenv("noprune", r.Form.Get("noprune"))
  641. return job.Run()
  642. }
  643. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  644. if vars == nil {
  645. return fmt.Errorf("Missing parameter")
  646. }
  647. var (
  648. name = vars["name"]
  649. job = eng.Job("start", name)
  650. )
  651. // allow a nil body for backwards compatibility
  652. if r.Body != nil {
  653. if api.MatchesContentType(r.Header.Get("Content-Type"), "application/json") {
  654. if err := job.DecodeEnv(r.Body); err != nil {
  655. return err
  656. }
  657. }
  658. }
  659. if err := job.Run(); err != nil {
  660. if err.Error() == "Container already started" {
  661. w.WriteHeader(http.StatusNotModified)
  662. return nil
  663. }
  664. return err
  665. }
  666. w.WriteHeader(http.StatusNoContent)
  667. return nil
  668. }
  669. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  670. if err := parseForm(r); err != nil {
  671. return err
  672. }
  673. if vars == nil {
  674. return fmt.Errorf("Missing parameter")
  675. }
  676. job := eng.Job("stop", vars["name"])
  677. job.Setenv("t", r.Form.Get("t"))
  678. if err := job.Run(); err != nil {
  679. if err.Error() == "Container already stopped" {
  680. w.WriteHeader(http.StatusNotModified)
  681. return nil
  682. }
  683. return err
  684. }
  685. w.WriteHeader(http.StatusNoContent)
  686. return nil
  687. }
  688. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  689. if vars == nil {
  690. return fmt.Errorf("Missing parameter")
  691. }
  692. var (
  693. env engine.Env
  694. stdoutBuffer = bytes.NewBuffer(nil)
  695. job = eng.Job("wait", vars["name"])
  696. )
  697. job.Stdout.Add(stdoutBuffer)
  698. if err := job.Run(); err != nil {
  699. return err
  700. }
  701. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  702. return writeJSON(w, http.StatusOK, env)
  703. }
  704. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  705. if err := parseForm(r); err != nil {
  706. return err
  707. }
  708. if vars == nil {
  709. return fmt.Errorf("Missing parameter")
  710. }
  711. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  712. return err
  713. }
  714. return nil
  715. }
  716. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  717. if err := parseForm(r); err != nil {
  718. return err
  719. }
  720. if vars == nil {
  721. return fmt.Errorf("Missing parameter")
  722. }
  723. var (
  724. job = eng.Job("container_inspect", vars["name"])
  725. c, err = job.Stdout.AddEnv()
  726. )
  727. if err != nil {
  728. return err
  729. }
  730. if err = job.Run(); err != nil {
  731. return err
  732. }
  733. inStream, outStream, err := hijackServer(w)
  734. if err != nil {
  735. return err
  736. }
  737. defer func() {
  738. if tcpc, ok := inStream.(*net.TCPConn); ok {
  739. tcpc.CloseWrite()
  740. } else {
  741. inStream.Close()
  742. }
  743. }()
  744. defer func() {
  745. if tcpc, ok := outStream.(*net.TCPConn); ok {
  746. tcpc.CloseWrite()
  747. } else if closer, ok := outStream.(io.Closer); ok {
  748. closer.Close()
  749. }
  750. }()
  751. var errStream io.Writer
  752. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  753. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  754. errStream = utils.NewStdWriter(outStream, utils.Stderr)
  755. outStream = utils.NewStdWriter(outStream, utils.Stdout)
  756. } else {
  757. errStream = outStream
  758. }
  759. job = eng.Job("attach", vars["name"])
  760. job.Setenv("logs", r.Form.Get("logs"))
  761. job.Setenv("stream", r.Form.Get("stream"))
  762. job.Setenv("stdin", r.Form.Get("stdin"))
  763. job.Setenv("stdout", r.Form.Get("stdout"))
  764. job.Setenv("stderr", r.Form.Get("stderr"))
  765. job.Stdin.Add(inStream)
  766. job.Stdout.Add(outStream)
  767. job.Stderr.Set(errStream)
  768. if err := job.Run(); err != nil {
  769. fmt.Fprintf(outStream, "Error attaching: %s\n", err)
  770. }
  771. return nil
  772. }
  773. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  774. if err := parseForm(r); err != nil {
  775. return err
  776. }
  777. if vars == nil {
  778. return fmt.Errorf("Missing parameter")
  779. }
  780. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  781. return err
  782. }
  783. h := websocket.Handler(func(ws *websocket.Conn) {
  784. defer ws.Close()
  785. job := eng.Job("attach", vars["name"])
  786. job.Setenv("logs", r.Form.Get("logs"))
  787. job.Setenv("stream", r.Form.Get("stream"))
  788. job.Setenv("stdin", r.Form.Get("stdin"))
  789. job.Setenv("stdout", r.Form.Get("stdout"))
  790. job.Setenv("stderr", r.Form.Get("stderr"))
  791. job.Stdin.Add(ws)
  792. job.Stdout.Add(ws)
  793. job.Stderr.Set(ws)
  794. if err := job.Run(); err != nil {
  795. utils.Errorf("Error attaching websocket: %s", err)
  796. }
  797. })
  798. h.ServeHTTP(w, r)
  799. return nil
  800. }
  801. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  802. if vars == nil {
  803. return fmt.Errorf("Missing parameter")
  804. }
  805. var job = eng.Job("container_inspect", vars["name"])
  806. if version.LessThan("1.12") {
  807. job.SetenvBool("raw", true)
  808. }
  809. streamJSON(job, w, false)
  810. return job.Run()
  811. }
  812. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  813. if vars == nil {
  814. return fmt.Errorf("Missing parameter")
  815. }
  816. var job = eng.Job("image_inspect", vars["name"])
  817. if version.LessThan("1.12") {
  818. job.SetenvBool("raw", true)
  819. }
  820. streamJSON(job, w, false)
  821. return job.Run()
  822. }
  823. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  824. if version.LessThan("1.3") {
  825. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  826. }
  827. var (
  828. authEncoded = r.Header.Get("X-Registry-Auth")
  829. authConfig = &registry.AuthConfig{}
  830. configFileEncoded = r.Header.Get("X-Registry-Config")
  831. configFile = &registry.ConfigFile{}
  832. job = eng.Job("build")
  833. )
  834. // This block can be removed when API versions prior to 1.9 are deprecated.
  835. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  836. // ConfigFile is present, any value provided as an AuthConfig directly will
  837. // be overridden. See BuildFile::CmdFrom for details.
  838. if version.LessThan("1.9") && authEncoded != "" {
  839. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  840. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  841. // for a pull it is not an error if no auth was given
  842. // to increase compatibility with the existing api it is defaulting to be empty
  843. authConfig = &registry.AuthConfig{}
  844. }
  845. }
  846. if configFileEncoded != "" {
  847. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  848. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  849. // for a pull it is not an error if no auth was given
  850. // to increase compatibility with the existing api it is defaulting to be empty
  851. configFile = &registry.ConfigFile{}
  852. }
  853. }
  854. if version.GreaterThanOrEqualTo("1.8") {
  855. job.SetenvBool("json", true)
  856. streamJSON(job, w, true)
  857. } else {
  858. job.Stdout.Add(utils.NewWriteFlusher(w))
  859. }
  860. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  861. job.Setenv("rm", "1")
  862. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  863. job.Setenv("rm", "1")
  864. } else {
  865. job.Setenv("rm", r.FormValue("rm"))
  866. }
  867. job.Stdin.Add(r.Body)
  868. job.Setenv("remote", r.FormValue("remote"))
  869. job.Setenv("t", r.FormValue("t"))
  870. job.Setenv("q", r.FormValue("q"))
  871. job.Setenv("nocache", r.FormValue("nocache"))
  872. job.Setenv("forcerm", r.FormValue("forcerm"))
  873. job.SetenvJson("authConfig", authConfig)
  874. job.SetenvJson("configFile", configFile)
  875. if err := job.Run(); err != nil {
  876. if !job.Stdout.Used() {
  877. return err
  878. }
  879. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  880. w.Write(sf.FormatError(err))
  881. }
  882. return nil
  883. }
  884. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  885. if vars == nil {
  886. return fmt.Errorf("Missing parameter")
  887. }
  888. var copyData engine.Env
  889. if contentType := r.Header.Get("Content-Type"); api.MatchesContentType(contentType, "application/json") {
  890. if err := copyData.Decode(r.Body); err != nil {
  891. return err
  892. }
  893. } else {
  894. return fmt.Errorf("Content-Type not supported: %s", contentType)
  895. }
  896. if copyData.Get("Resource") == "" {
  897. return fmt.Errorf("Path cannot be empty")
  898. }
  899. origResource := copyData.Get("Resource")
  900. if copyData.Get("Resource")[0] == '/' {
  901. copyData.Set("Resource", copyData.Get("Resource")[1:])
  902. }
  903. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  904. job.Stdout.Add(w)
  905. if err := job.Run(); err != nil {
  906. utils.Errorf("%s", err.Error())
  907. if strings.Contains(err.Error(), "No such container") {
  908. w.WriteHeader(http.StatusNotFound)
  909. } else if strings.Contains(err.Error(), "no such file or directory") {
  910. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  911. }
  912. }
  913. return nil
  914. }
  915. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  916. w.WriteHeader(http.StatusOK)
  917. return nil
  918. }
  919. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  920. w.Header().Add("Access-Control-Allow-Origin", "*")
  921. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept")
  922. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  923. }
  924. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  925. _, err := w.Write([]byte{'O', 'K'})
  926. return err
  927. }
  928. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  929. return func(w http.ResponseWriter, r *http.Request) {
  930. // log the request
  931. utils.Debugf("Calling %s %s", localMethod, localRoute)
  932. if logging {
  933. log.Println(r.Method, r.RequestURI)
  934. }
  935. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  936. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  937. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  938. utils.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  939. }
  940. }
  941. version := version.Version(mux.Vars(r)["version"])
  942. if version == "" {
  943. version = api.APIVERSION
  944. }
  945. if enableCors {
  946. writeCorsHeaders(w, r)
  947. }
  948. if version.GreaterThan(api.APIVERSION) {
  949. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  950. return
  951. }
  952. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  953. utils.Errorf("Error making handler: %s", err)
  954. httpError(w, err)
  955. }
  956. }
  957. }
  958. // Replicated from expvar.go as not public.
  959. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  960. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  961. fmt.Fprintf(w, "{\n")
  962. first := true
  963. expvar.Do(func(kv expvar.KeyValue) {
  964. if !first {
  965. fmt.Fprintf(w, ",\n")
  966. }
  967. first = false
  968. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  969. })
  970. fmt.Fprintf(w, "\n}\n")
  971. }
  972. func AttachProfiler(router *mux.Router) {
  973. router.HandleFunc("/debug/vars", expvarHandler)
  974. router.HandleFunc("/debug/pprof/", pprof.Index)
  975. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  976. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  977. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  978. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  979. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  980. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  981. }
  982. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) (*mux.Router, error) {
  983. r := mux.NewRouter()
  984. if os.Getenv("DEBUG") != "" {
  985. AttachProfiler(r)
  986. }
  987. m := map[string]map[string]HttpApiFunc{
  988. "GET": {
  989. "/_ping": ping,
  990. "/events": getEvents,
  991. "/info": getInfo,
  992. "/version": getVersion,
  993. "/images/json": getImagesJSON,
  994. "/images/viz": getImagesViz,
  995. "/images/search": getImagesSearch,
  996. "/images/{name:.*}/get": getImagesGet,
  997. "/images/{name:.*}/history": getImagesHistory,
  998. "/images/{name:.*}/json": getImagesByName,
  999. "/containers/ps": getContainersJSON,
  1000. "/containers/json": getContainersJSON,
  1001. "/containers/{name:.*}/export": getContainersExport,
  1002. "/containers/{name:.*}/changes": getContainersChanges,
  1003. "/containers/{name:.*}/json": getContainersByName,
  1004. "/containers/{name:.*}/top": getContainersTop,
  1005. "/containers/{name:.*}/logs": getContainersLogs,
  1006. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  1007. },
  1008. "POST": {
  1009. "/auth": postAuth,
  1010. "/commit": postCommit,
  1011. "/build": postBuild,
  1012. "/images/create": postImagesCreate,
  1013. "/images/load": postImagesLoad,
  1014. "/images/{name:.*}/push": postImagesPush,
  1015. "/images/{name:.*}/tag": postImagesTag,
  1016. "/containers/create": postContainersCreate,
  1017. "/containers/{name:.*}/kill": postContainersKill,
  1018. "/containers/{name:.*}/pause": postContainersPause,
  1019. "/containers/{name:.*}/unpause": postContainersUnpause,
  1020. "/containers/{name:.*}/restart": postContainersRestart,
  1021. "/containers/{name:.*}/start": postContainersStart,
  1022. "/containers/{name:.*}/stop": postContainersStop,
  1023. "/containers/{name:.*}/wait": postContainersWait,
  1024. "/containers/{name:.*}/resize": postContainersResize,
  1025. "/containers/{name:.*}/attach": postContainersAttach,
  1026. "/containers/{name:.*}/copy": postContainersCopy,
  1027. },
  1028. "DELETE": {
  1029. "/containers/{name:.*}": deleteContainers,
  1030. "/images/{name:.*}": deleteImages,
  1031. },
  1032. "OPTIONS": {
  1033. "": optionsHandler,
  1034. },
  1035. }
  1036. for method, routes := range m {
  1037. for route, fct := range routes {
  1038. utils.Debugf("Registering %s, %s", method, route)
  1039. // NOTE: scope issue, make sure the variables are local and won't be changed
  1040. localRoute := route
  1041. localFct := fct
  1042. localMethod := method
  1043. // build the handler function
  1044. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1045. // add the new route
  1046. if localRoute == "" {
  1047. r.Methods(localMethod).HandlerFunc(f)
  1048. } else {
  1049. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1050. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1051. }
  1052. }
  1053. }
  1054. return r, nil
  1055. }
  1056. // ServeRequest processes a single http request to the docker remote api.
  1057. // FIXME: refactor this to be part of Server and not require re-creating a new
  1058. // router each time. This requires first moving ListenAndServe into Server.
  1059. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) error {
  1060. router, err := createRouter(eng, false, true, "")
  1061. if err != nil {
  1062. return err
  1063. }
  1064. // Insert APIVERSION into the request as a convenience
  1065. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1066. router.ServeHTTP(w, req)
  1067. return nil
  1068. }
  1069. // ServeFD creates an http.Server and sets it up to serve given a socket activated
  1070. // argument.
  1071. func ServeFd(addr string, handle http.Handler) error {
  1072. ls, e := systemd.ListenFD(addr)
  1073. if e != nil {
  1074. return e
  1075. }
  1076. chErrors := make(chan error, len(ls))
  1077. // We don't want to start serving on these sockets until the
  1078. // "initserver" job has completed. Otherwise required handlers
  1079. // won't be ready.
  1080. <-activationLock
  1081. // Since ListenFD will return one or more sockets we have
  1082. // to create a go func to spawn off multiple serves
  1083. for i := range ls {
  1084. listener := ls[i]
  1085. go func() {
  1086. httpSrv := http.Server{Handler: handle}
  1087. chErrors <- httpSrv.Serve(listener)
  1088. }()
  1089. }
  1090. for i := 0; i < len(ls); i += 1 {
  1091. err := <-chErrors
  1092. if err != nil {
  1093. return err
  1094. }
  1095. }
  1096. return nil
  1097. }
  1098. func lookupGidByName(nameOrGid string) (int, error) {
  1099. groups, err := user.ParseGroupFilter(func(g *user.Group) bool {
  1100. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1101. })
  1102. if err != nil {
  1103. return -1, err
  1104. }
  1105. if groups != nil && len(groups) > 0 {
  1106. return groups[0].Gid, nil
  1107. }
  1108. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1109. }
  1110. func changeGroup(addr string, nameOrGid string) error {
  1111. gid, err := lookupGidByName(nameOrGid)
  1112. if err != nil {
  1113. return err
  1114. }
  1115. utils.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1116. return os.Chown(addr, 0, gid)
  1117. }
  1118. // ListenAndServe sets up the required http.Server and gets it listening for
  1119. // each addr passed in and does protocol specific checking.
  1120. func ListenAndServe(proto, addr string, job *engine.Job) error {
  1121. var l net.Listener
  1122. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1123. if err != nil {
  1124. return err
  1125. }
  1126. if proto == "fd" {
  1127. return ServeFd(addr, r)
  1128. }
  1129. if proto == "unix" {
  1130. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1131. return err
  1132. }
  1133. }
  1134. var oldmask int
  1135. if proto == "unix" {
  1136. oldmask = syscall.Umask(0777)
  1137. }
  1138. if job.GetenvBool("BufferRequests") {
  1139. l, err = listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1140. } else {
  1141. l, err = net.Listen(proto, addr)
  1142. }
  1143. if proto == "unix" {
  1144. syscall.Umask(oldmask)
  1145. }
  1146. if err != nil {
  1147. return err
  1148. }
  1149. if proto != "unix" && (job.GetenvBool("Tls") || job.GetenvBool("TlsVerify")) {
  1150. tlsCert := job.Getenv("TlsCert")
  1151. tlsKey := job.Getenv("TlsKey")
  1152. cert, err := tls.LoadX509KeyPair(tlsCert, tlsKey)
  1153. if err != nil {
  1154. return fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1155. tlsCert, tlsKey, err)
  1156. }
  1157. tlsConfig := &tls.Config{
  1158. NextProtos: []string{"http/1.1"},
  1159. Certificates: []tls.Certificate{cert},
  1160. }
  1161. if job.GetenvBool("TlsVerify") {
  1162. certPool := x509.NewCertPool()
  1163. file, err := ioutil.ReadFile(job.Getenv("TlsCa"))
  1164. if err != nil {
  1165. return fmt.Errorf("Couldn't read CA certificate: %s", err)
  1166. }
  1167. certPool.AppendCertsFromPEM(file)
  1168. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1169. tlsConfig.ClientCAs = certPool
  1170. }
  1171. l = tls.NewListener(l, tlsConfig)
  1172. }
  1173. // Basic error and sanity checking
  1174. switch proto {
  1175. case "tcp":
  1176. if !strings.HasPrefix(addr, "127.0.0.1") && !job.GetenvBool("TlsVerify") {
  1177. log.Println("/!\\ DON'T BIND ON ANOTHER IP ADDRESS THAN 127.0.0.1 IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1178. }
  1179. case "unix":
  1180. socketGroup := job.Getenv("SocketGroup")
  1181. if socketGroup != "" {
  1182. if err := changeGroup(addr, socketGroup); err != nil {
  1183. if socketGroup == "docker" {
  1184. // if the user hasn't explicitly specified the group ownership, don't fail on errors.
  1185. utils.Debugf("Warning: could not chgrp %s to docker: %s", addr, err.Error())
  1186. } else {
  1187. return err
  1188. }
  1189. }
  1190. }
  1191. if err := os.Chmod(addr, 0660); err != nil {
  1192. return err
  1193. }
  1194. default:
  1195. return fmt.Errorf("Invalid protocol format.")
  1196. }
  1197. httpSrv := http.Server{Addr: addr, Handler: r}
  1198. return httpSrv.Serve(l)
  1199. }
  1200. // ServeApi loops through all of the protocols sent in to docker and spawns
  1201. // off a go routine to setup a serving http.Server for each.
  1202. func ServeApi(job *engine.Job) engine.Status {
  1203. if len(job.Args) == 0 {
  1204. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1205. }
  1206. var (
  1207. protoAddrs = job.Args
  1208. chErrors = make(chan error, len(protoAddrs))
  1209. )
  1210. activationLock = make(chan struct{})
  1211. for _, protoAddr := range protoAddrs {
  1212. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1213. if len(protoAddrParts) != 2 {
  1214. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1215. }
  1216. go func() {
  1217. log.Printf("Listening for HTTP on %s (%s)\n", protoAddrParts[0], protoAddrParts[1])
  1218. chErrors <- ListenAndServe(protoAddrParts[0], protoAddrParts[1], job)
  1219. }()
  1220. }
  1221. for i := 0; i < len(protoAddrs); i += 1 {
  1222. err := <-chErrors
  1223. if err != nil {
  1224. return job.Error(err)
  1225. }
  1226. }
  1227. return engine.StatusOK
  1228. }
  1229. func AcceptConnections(job *engine.Job) engine.Status {
  1230. // Tell the init daemon we are accepting requests
  1231. go systemd.SdNotify("READY=1")
  1232. // close the lock so the listeners start accepting connections
  1233. if activationLock != nil {
  1234. close(activationLock)
  1235. }
  1236. return engine.StatusOK
  1237. }