image_commit.go 9.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311
  1. package containerd
  2. import (
  3. "bytes"
  4. "context"
  5. "crypto/rand"
  6. "encoding/base64"
  7. "encoding/json"
  8. "fmt"
  9. "runtime"
  10. "strings"
  11. "time"
  12. "github.com/containerd/containerd/content"
  13. "github.com/containerd/containerd/diff"
  14. cerrdefs "github.com/containerd/containerd/errdefs"
  15. "github.com/containerd/containerd/images"
  16. "github.com/containerd/containerd/leases"
  17. "github.com/containerd/containerd/rootfs"
  18. "github.com/containerd/containerd/snapshots"
  19. "github.com/docker/docker/api/types/backend"
  20. "github.com/docker/docker/image"
  21. "github.com/opencontainers/go-digest"
  22. "github.com/opencontainers/image-spec/identity"
  23. "github.com/opencontainers/image-spec/specs-go"
  24. ocispec "github.com/opencontainers/image-spec/specs-go/v1"
  25. "github.com/sirupsen/logrus"
  26. )
  27. /*
  28. This code is based on `commit` support in nerdctl, under Apache License
  29. https://github.com/containerd/nerdctl/blob/master/pkg/imgutil/commit/commit.go
  30. with adaptations to match the Moby data model and services.
  31. */
  32. // CommitImage creates a new image from a commit config.
  33. func (i *ImageService) CommitImage(ctx context.Context, cc backend.CommitConfig) (image.ID, error) {
  34. container := i.containers.Get(cc.ContainerID)
  35. cs := i.client.ContentStore()
  36. imageManifest, err := getContainerImageManifest(container)
  37. if err != nil {
  38. return "", err
  39. }
  40. imageManifestBytes, err := content.ReadBlob(ctx, cs, imageManifest)
  41. if err != nil {
  42. return "", err
  43. }
  44. var manifest ocispec.Manifest
  45. if err := json.Unmarshal(imageManifestBytes, &manifest); err != nil {
  46. return "", err
  47. }
  48. imageConfigBytes, err := content.ReadBlob(ctx, cs, manifest.Config)
  49. if err != nil {
  50. return "", err
  51. }
  52. var ociimage ocispec.Image
  53. if err := json.Unmarshal(imageConfigBytes, &ociimage); err != nil {
  54. return "", err
  55. }
  56. var (
  57. differ = i.client.DiffService()
  58. sn = i.client.SnapshotService(container.Driver)
  59. )
  60. // Don't gc me and clean the dirty data after 1 hour!
  61. ctx, done, err := i.client.WithLease(ctx, leases.WithRandomID(), leases.WithExpiration(1*time.Hour))
  62. if err != nil {
  63. return "", fmt.Errorf("failed to create lease for commit: %w", err)
  64. }
  65. defer done(ctx)
  66. diffLayerDesc, diffID, err := createDiff(ctx, cc.ContainerID, sn, cs, differ)
  67. if err != nil {
  68. return "", fmt.Errorf("failed to export layer: %w", err)
  69. }
  70. imageConfig := generateCommitImageConfig(ociimage, diffID, cc)
  71. rootfsID := identity.ChainID(imageConfig.RootFS.DiffIDs).String()
  72. if err := applyDiffLayer(ctx, rootfsID, ociimage, sn, differ, diffLayerDesc); err != nil {
  73. return "", fmt.Errorf("failed to apply diff: %w", err)
  74. }
  75. layers := append(manifest.Layers, diffLayerDesc)
  76. commitManifestDesc, err := writeContentsForImage(ctx, container.Driver, cs, imageConfig, layers)
  77. if err != nil {
  78. return "", err
  79. }
  80. // image create
  81. img := images.Image{
  82. Name: danglingImageName(commitManifestDesc.Digest),
  83. Target: commitManifestDesc,
  84. CreatedAt: time.Now(),
  85. }
  86. if _, err := i.client.ImageService().Update(ctx, img); err != nil {
  87. if !cerrdefs.IsNotFound(err) {
  88. return "", err
  89. }
  90. if _, err := i.client.ImageService().Create(ctx, img); err != nil {
  91. return "", fmt.Errorf("failed to create new image: %w", err)
  92. }
  93. }
  94. return image.ID(img.Target.Digest), nil
  95. }
  96. // generateCommitImageConfig generates an OCI Image config based on the
  97. // container's image and the CommitConfig options.
  98. func generateCommitImageConfig(baseConfig ocispec.Image, diffID digest.Digest, opts backend.CommitConfig) ocispec.Image {
  99. if opts.Author == "" {
  100. opts.Author = baseConfig.Author
  101. }
  102. createdTime := time.Now()
  103. arch := baseConfig.Architecture
  104. if arch == "" {
  105. arch = runtime.GOARCH
  106. logrus.Warnf("assuming arch=%q", arch)
  107. }
  108. os := baseConfig.OS
  109. if os == "" {
  110. os = runtime.GOOS
  111. logrus.Warnf("assuming os=%q", os)
  112. }
  113. logrus.Debugf("generateCommitImageConfig(): arch=%q, os=%q", arch, os)
  114. return ocispec.Image{
  115. Platform: ocispec.Platform{
  116. Architecture: arch,
  117. OS: os,
  118. },
  119. Created: &createdTime,
  120. Author: opts.Author,
  121. Config: containerConfigToOciImageConfig(opts.Config),
  122. RootFS: ocispec.RootFS{
  123. Type: "layers",
  124. DiffIDs: append(baseConfig.RootFS.DiffIDs, diffID),
  125. },
  126. History: append(baseConfig.History, ocispec.History{
  127. Created: &createdTime,
  128. CreatedBy: strings.Join(opts.ContainerConfig.Cmd, " "),
  129. Author: opts.Author,
  130. Comment: opts.Comment,
  131. // TODO(laurazard): this check might be incorrect
  132. EmptyLayer: diffID == "",
  133. }),
  134. }
  135. }
  136. // writeContentsForImage will commit oci image config and manifest into containerd's content store.
  137. func writeContentsForImage(ctx context.Context, snName string, cs content.Store, newConfig ocispec.Image, layers []ocispec.Descriptor) (ocispec.Descriptor, error) {
  138. newConfigJSON, err := json.Marshal(newConfig)
  139. if err != nil {
  140. return ocispec.Descriptor{}, err
  141. }
  142. configDesc := ocispec.Descriptor{
  143. MediaType: ocispec.MediaTypeImageConfig,
  144. Digest: digest.FromBytes(newConfigJSON),
  145. Size: int64(len(newConfigJSON)),
  146. }
  147. newMfst := struct {
  148. MediaType string `json:"mediaType,omitempty"`
  149. ocispec.Manifest
  150. }{
  151. MediaType: ocispec.MediaTypeImageManifest,
  152. Manifest: ocispec.Manifest{
  153. Versioned: specs.Versioned{
  154. SchemaVersion: 2,
  155. },
  156. Config: configDesc,
  157. Layers: layers,
  158. },
  159. }
  160. newMfstJSON, err := json.MarshalIndent(newMfst, "", " ")
  161. if err != nil {
  162. return ocispec.Descriptor{}, err
  163. }
  164. newMfstDesc := ocispec.Descriptor{
  165. MediaType: ocispec.MediaTypeImageManifest,
  166. Digest: digest.FromBytes(newMfstJSON),
  167. Size: int64(len(newMfstJSON)),
  168. }
  169. // new manifest should reference the layers and config content
  170. labels := map[string]string{
  171. "containerd.io/gc.ref.content.0": configDesc.Digest.String(),
  172. }
  173. for i, l := range layers {
  174. labels[fmt.Sprintf("containerd.io/gc.ref.content.%d", i+1)] = l.Digest.String()
  175. }
  176. err = content.WriteBlob(ctx, cs, newMfstDesc.Digest.String(), bytes.NewReader(newMfstJSON), newMfstDesc, content.WithLabels(labels))
  177. if err != nil {
  178. return ocispec.Descriptor{}, err
  179. }
  180. // config should reference to snapshotter
  181. labelOpt := content.WithLabels(map[string]string{
  182. fmt.Sprintf("containerd.io/gc.ref.snapshot.%s", snName): identity.ChainID(newConfig.RootFS.DiffIDs).String(),
  183. })
  184. err = content.WriteBlob(ctx, cs, configDesc.Digest.String(), bytes.NewReader(newConfigJSON), configDesc, labelOpt)
  185. if err != nil {
  186. return ocispec.Descriptor{}, err
  187. }
  188. return newMfstDesc, nil
  189. }
  190. // createDiff creates a layer diff into containerd's content store.
  191. func createDiff(ctx context.Context, name string, sn snapshots.Snapshotter, cs content.Store, comparer diff.Comparer) (ocispec.Descriptor, digest.Digest, error) {
  192. newDesc, err := rootfs.CreateDiff(ctx, name, sn, comparer)
  193. if err != nil {
  194. return ocispec.Descriptor{}, "", err
  195. }
  196. info, err := cs.Info(ctx, newDesc.Digest)
  197. if err != nil {
  198. return ocispec.Descriptor{}, "", err
  199. }
  200. diffIDStr, ok := info.Labels["containerd.io/uncompressed"]
  201. if !ok {
  202. return ocispec.Descriptor{}, "", fmt.Errorf("invalid differ response with no diffID")
  203. }
  204. diffID, err := digest.Parse(diffIDStr)
  205. if err != nil {
  206. return ocispec.Descriptor{}, "", err
  207. }
  208. return ocispec.Descriptor{
  209. MediaType: ocispec.MediaTypeImageLayerGzip,
  210. Digest: newDesc.Digest,
  211. Size: info.Size,
  212. }, diffID, nil
  213. }
  214. // applyDiffLayer will apply diff layer content created by createDiff into the snapshotter.
  215. func applyDiffLayer(ctx context.Context, name string, baseImg ocispec.Image, sn snapshots.Snapshotter, differ diff.Applier, diffDesc ocispec.Descriptor) (retErr error) {
  216. var (
  217. key = uniquePart() + "-" + name
  218. parent = identity.ChainID(baseImg.RootFS.DiffIDs).String()
  219. )
  220. mount, err := sn.Prepare(ctx, key, parent)
  221. if err != nil {
  222. return err
  223. }
  224. defer func() {
  225. if retErr != nil {
  226. // NOTE: the snapshotter should be hold by lease. Even
  227. // if the cleanup fails, the containerd gc can delete it.
  228. if err := sn.Remove(ctx, key); err != nil {
  229. logrus.Warnf("failed to cleanup aborted apply %s: %s", key, err)
  230. }
  231. }
  232. }()
  233. if _, err = differ.Apply(ctx, diffDesc, mount); err != nil {
  234. return err
  235. }
  236. if err = sn.Commit(ctx, name, key); err != nil {
  237. if cerrdefs.IsAlreadyExists(err) {
  238. return nil
  239. }
  240. return err
  241. }
  242. return nil
  243. }
  244. // copied from github.com/containerd/containerd/rootfs/apply.go
  245. func uniquePart() string {
  246. t := time.Now()
  247. var b [3]byte
  248. // Ignore read failures, just decreases uniqueness
  249. rand.Read(b[:])
  250. return fmt.Sprintf("%d-%s", t.Nanosecond(), base64.URLEncoding.EncodeToString(b[:]))
  251. }
  252. // CommitBuildStep is used by the builder to create an image for each step in
  253. // the build.
  254. //
  255. // This method is different from CreateImageFromContainer:
  256. // - it doesn't attempt to validate container state
  257. // - it doesn't send a commit action to metrics
  258. // - it doesn't log a container commit event
  259. //
  260. // This is a temporary shim. Should be removed when builder stops using commit.
  261. func (i *ImageService) CommitBuildStep(ctx context.Context, c backend.CommitConfig) (image.ID, error) {
  262. ctr := i.containers.Get(c.ContainerID)
  263. if ctr == nil {
  264. // TODO: use typed error
  265. return "", fmt.Errorf("container not found: %s", c.ContainerID)
  266. }
  267. c.ContainerMountLabel = ctr.MountLabel
  268. c.ContainerOS = ctr.OS
  269. c.ParentImageID = string(ctr.ImageID)
  270. return i.CommitImage(ctx, c)
  271. }