server.go 40 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "crypto/tls"
  6. "crypto/x509"
  7. "encoding/base64"
  8. "encoding/json"
  9. "expvar"
  10. "fmt"
  11. "io"
  12. "io/ioutil"
  13. "log"
  14. "net"
  15. "net/http"
  16. "net/http/pprof"
  17. "os"
  18. "strconv"
  19. "strings"
  20. "syscall"
  21. "code.google.com/p/go.net/websocket"
  22. "github.com/docker/docker/api"
  23. "github.com/docker/docker/engine"
  24. "github.com/docker/docker/pkg/listenbuffer"
  25. "github.com/docker/docker/pkg/parsers"
  26. "github.com/docker/docker/pkg/systemd"
  27. "github.com/docker/docker/pkg/version"
  28. "github.com/docker/docker/registry"
  29. "github.com/docker/docker/utils"
  30. "github.com/docker/libcontainer/user"
  31. "github.com/gorilla/mux"
  32. )
  33. var (
  34. activationLock chan struct{}
  35. )
  36. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  37. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  38. conn, _, err := w.(http.Hijacker).Hijack()
  39. if err != nil {
  40. return nil, nil, err
  41. }
  42. // Flush the options to make sure the client sets the raw mode
  43. conn.Write([]byte{})
  44. return conn, conn, nil
  45. }
  46. //If we don't do this, POST method without Content-type (even with empty body) will fail
  47. func parseForm(r *http.Request) error {
  48. if r == nil {
  49. return nil
  50. }
  51. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  52. return err
  53. }
  54. return nil
  55. }
  56. func parseMultipartForm(r *http.Request) error {
  57. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  58. return err
  59. }
  60. return nil
  61. }
  62. func httpError(w http.ResponseWriter, err error) {
  63. statusCode := http.StatusInternalServerError
  64. // FIXME: this is brittle and should not be necessary.
  65. // If we need to differentiate between different possible error types, we should
  66. // create appropriate error types with clearly defined meaning.
  67. if strings.Contains(err.Error(), "No such") {
  68. statusCode = http.StatusNotFound
  69. } else if strings.Contains(err.Error(), "Bad parameter") {
  70. statusCode = http.StatusBadRequest
  71. } else if strings.Contains(err.Error(), "Conflict") {
  72. statusCode = http.StatusConflict
  73. } else if strings.Contains(err.Error(), "Impossible") {
  74. statusCode = http.StatusNotAcceptable
  75. } else if strings.Contains(err.Error(), "Wrong login/password") {
  76. statusCode = http.StatusUnauthorized
  77. } else if strings.Contains(err.Error(), "hasn't been activated") {
  78. statusCode = http.StatusForbidden
  79. }
  80. if err != nil {
  81. utils.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  82. http.Error(w, err.Error(), statusCode)
  83. }
  84. }
  85. func writeJSON(w http.ResponseWriter, code int, v engine.Env) error {
  86. w.Header().Set("Content-Type", "application/json")
  87. w.WriteHeader(code)
  88. return v.Encode(w)
  89. }
  90. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  91. w.Header().Set("Content-Type", "application/json")
  92. if flush {
  93. job.Stdout.Add(utils.NewWriteFlusher(w))
  94. } else {
  95. job.Stdout.Add(w)
  96. }
  97. }
  98. func getBoolParam(value string) (bool, error) {
  99. if value == "" {
  100. return false, nil
  101. }
  102. ret, err := strconv.ParseBool(value)
  103. if err != nil {
  104. return false, fmt.Errorf("Bad parameter")
  105. }
  106. return ret, nil
  107. }
  108. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  109. var (
  110. authConfig, err = ioutil.ReadAll(r.Body)
  111. job = eng.Job("auth")
  112. stdoutBuffer = bytes.NewBuffer(nil)
  113. )
  114. if err != nil {
  115. return err
  116. }
  117. job.Setenv("authConfig", string(authConfig))
  118. job.Stdout.Add(stdoutBuffer)
  119. if err = job.Run(); err != nil {
  120. return err
  121. }
  122. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  123. var env engine.Env
  124. env.Set("Status", status)
  125. return writeJSON(w, http.StatusOK, env)
  126. }
  127. w.WriteHeader(http.StatusNoContent)
  128. return nil
  129. }
  130. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  131. w.Header().Set("Content-Type", "application/json")
  132. eng.ServeHTTP(w, r)
  133. return nil
  134. }
  135. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  136. if vars == nil {
  137. return fmt.Errorf("Missing parameter")
  138. }
  139. if err := parseForm(r); err != nil {
  140. return err
  141. }
  142. job := eng.Job("kill", vars["name"])
  143. if sig := r.Form.Get("signal"); sig != "" {
  144. job.Args = append(job.Args, sig)
  145. }
  146. if err := job.Run(); err != nil {
  147. return err
  148. }
  149. w.WriteHeader(http.StatusNoContent)
  150. return nil
  151. }
  152. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  153. if vars == nil {
  154. return fmt.Errorf("Missing parameter")
  155. }
  156. if err := parseForm(r); err != nil {
  157. return err
  158. }
  159. job := eng.Job("pause", vars["name"])
  160. if err := job.Run(); err != nil {
  161. return err
  162. }
  163. w.WriteHeader(http.StatusNoContent)
  164. return nil
  165. }
  166. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  167. if vars == nil {
  168. return fmt.Errorf("Missing parameter")
  169. }
  170. if err := parseForm(r); err != nil {
  171. return err
  172. }
  173. job := eng.Job("unpause", vars["name"])
  174. if err := job.Run(); err != nil {
  175. return err
  176. }
  177. w.WriteHeader(http.StatusNoContent)
  178. return nil
  179. }
  180. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  181. if vars == nil {
  182. return fmt.Errorf("Missing parameter")
  183. }
  184. job := eng.Job("export", vars["name"])
  185. job.Stdout.Add(w)
  186. if err := job.Run(); err != nil {
  187. return err
  188. }
  189. return nil
  190. }
  191. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  192. if err := parseForm(r); err != nil {
  193. return err
  194. }
  195. var (
  196. err error
  197. outs *engine.Table
  198. job = eng.Job("images")
  199. )
  200. job.Setenv("filters", r.Form.Get("filters"))
  201. // FIXME this parameter could just be a match filter
  202. job.Setenv("filter", r.Form.Get("filter"))
  203. job.Setenv("all", r.Form.Get("all"))
  204. if version.GreaterThanOrEqualTo("1.7") {
  205. streamJSON(job, w, false)
  206. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  207. return err
  208. }
  209. if err := job.Run(); err != nil {
  210. return err
  211. }
  212. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  213. outsLegacy := engine.NewTable("Created", 0)
  214. for _, out := range outs.Data {
  215. for _, repoTag := range out.GetList("RepoTags") {
  216. repo, tag := parsers.ParseRepositoryTag(repoTag)
  217. outLegacy := &engine.Env{}
  218. outLegacy.Set("Repository", repo)
  219. outLegacy.SetJson("Tag", tag)
  220. outLegacy.Set("Id", out.Get("Id"))
  221. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  222. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  223. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  224. outsLegacy.Add(outLegacy)
  225. }
  226. }
  227. w.Header().Set("Content-Type", "application/json")
  228. if _, err := outsLegacy.WriteListTo(w); err != nil {
  229. return err
  230. }
  231. }
  232. return nil
  233. }
  234. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  235. if version.GreaterThan("1.6") {
  236. w.WriteHeader(http.StatusNotFound)
  237. return fmt.Errorf("This is now implemented in the client.")
  238. }
  239. eng.ServeHTTP(w, r)
  240. return nil
  241. }
  242. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  243. w.Header().Set("Content-Type", "application/json")
  244. eng.ServeHTTP(w, r)
  245. return nil
  246. }
  247. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  248. if err := parseForm(r); err != nil {
  249. return err
  250. }
  251. var job = eng.Job("events")
  252. streamJSON(job, w, true)
  253. job.Setenv("since", r.Form.Get("since"))
  254. job.Setenv("until", r.Form.Get("until"))
  255. return job.Run()
  256. }
  257. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  258. if vars == nil {
  259. return fmt.Errorf("Missing parameter")
  260. }
  261. var job = eng.Job("history", vars["name"])
  262. streamJSON(job, w, false)
  263. if err := job.Run(); err != nil {
  264. return err
  265. }
  266. return nil
  267. }
  268. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  269. if vars == nil {
  270. return fmt.Errorf("Missing parameter")
  271. }
  272. var job = eng.Job("container_changes", vars["name"])
  273. streamJSON(job, w, false)
  274. return job.Run()
  275. }
  276. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  277. if version.LessThan("1.4") {
  278. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  279. }
  280. if vars == nil {
  281. return fmt.Errorf("Missing parameter")
  282. }
  283. if err := parseForm(r); err != nil {
  284. return err
  285. }
  286. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  287. streamJSON(job, w, false)
  288. return job.Run()
  289. }
  290. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  291. if err := parseForm(r); err != nil {
  292. return err
  293. }
  294. var (
  295. err error
  296. outs *engine.Table
  297. job = eng.Job("containers")
  298. )
  299. job.Setenv("all", r.Form.Get("all"))
  300. job.Setenv("size", r.Form.Get("size"))
  301. job.Setenv("since", r.Form.Get("since"))
  302. job.Setenv("before", r.Form.Get("before"))
  303. job.Setenv("limit", r.Form.Get("limit"))
  304. job.Setenv("filters", r.Form.Get("filters"))
  305. if version.GreaterThanOrEqualTo("1.5") {
  306. streamJSON(job, w, false)
  307. } else if outs, err = job.Stdout.AddTable(); err != nil {
  308. return err
  309. }
  310. if err = job.Run(); err != nil {
  311. return err
  312. }
  313. if version.LessThan("1.5") { // Convert to legacy format
  314. for _, out := range outs.Data {
  315. ports := engine.NewTable("", 0)
  316. ports.ReadListFrom([]byte(out.Get("Ports")))
  317. out.Set("Ports", api.DisplayablePorts(ports))
  318. }
  319. w.Header().Set("Content-Type", "application/json")
  320. if _, err = outs.WriteListTo(w); err != nil {
  321. return err
  322. }
  323. }
  324. return nil
  325. }
  326. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  327. if err := parseForm(r); err != nil {
  328. return err
  329. }
  330. if vars == nil {
  331. return fmt.Errorf("Missing parameter")
  332. }
  333. var (
  334. inspectJob = eng.Job("container_inspect", vars["name"])
  335. logsJob = eng.Job("logs", vars["name"])
  336. c, err = inspectJob.Stdout.AddEnv()
  337. )
  338. if err != nil {
  339. return err
  340. }
  341. logsJob.Setenv("follow", r.Form.Get("follow"))
  342. logsJob.Setenv("tail", r.Form.Get("tail"))
  343. logsJob.Setenv("stdout", r.Form.Get("stdout"))
  344. logsJob.Setenv("stderr", r.Form.Get("stderr"))
  345. logsJob.Setenv("timestamps", r.Form.Get("timestamps"))
  346. // Validate args here, because we can't return not StatusOK after job.Run() call
  347. stdout, stderr := logsJob.GetenvBool("stdout"), logsJob.GetenvBool("stderr")
  348. if !(stdout || stderr) {
  349. return fmt.Errorf("Bad parameters: you must choose at least one stream")
  350. }
  351. if err = inspectJob.Run(); err != nil {
  352. return err
  353. }
  354. var outStream, errStream io.Writer
  355. outStream = utils.NewWriteFlusher(w)
  356. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  357. errStream = utils.NewStdWriter(outStream, utils.Stderr)
  358. outStream = utils.NewStdWriter(outStream, utils.Stdout)
  359. } else {
  360. errStream = outStream
  361. }
  362. logsJob.Stdout.Add(outStream)
  363. logsJob.Stderr.Set(errStream)
  364. if err := logsJob.Run(); err != nil {
  365. fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
  366. }
  367. return nil
  368. }
  369. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  370. if err := parseForm(r); err != nil {
  371. return err
  372. }
  373. if vars == nil {
  374. return fmt.Errorf("Missing parameter")
  375. }
  376. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  377. job.Setenv("force", r.Form.Get("force"))
  378. if err := job.Run(); err != nil {
  379. return err
  380. }
  381. w.WriteHeader(http.StatusCreated)
  382. return nil
  383. }
  384. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  385. if err := parseForm(r); err != nil {
  386. return err
  387. }
  388. var (
  389. config engine.Env
  390. env engine.Env
  391. job = eng.Job("commit", r.Form.Get("container"))
  392. stdoutBuffer = bytes.NewBuffer(nil)
  393. )
  394. if err := config.Decode(r.Body); err != nil {
  395. utils.Errorf("%s", err)
  396. }
  397. if r.FormValue("pause") == "" && version.GreaterThanOrEqualTo("1.13") {
  398. job.Setenv("pause", "1")
  399. } else {
  400. job.Setenv("pause", r.FormValue("pause"))
  401. }
  402. job.Setenv("repo", r.Form.Get("repo"))
  403. job.Setenv("tag", r.Form.Get("tag"))
  404. job.Setenv("author", r.Form.Get("author"))
  405. job.Setenv("comment", r.Form.Get("comment"))
  406. job.SetenvSubEnv("config", &config)
  407. job.Stdout.Add(stdoutBuffer)
  408. if err := job.Run(); err != nil {
  409. return err
  410. }
  411. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  412. return writeJSON(w, http.StatusCreated, env)
  413. }
  414. // Creates an image from Pull or from Import
  415. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  416. if err := parseForm(r); err != nil {
  417. return err
  418. }
  419. var (
  420. image = r.Form.Get("fromImage")
  421. repo = r.Form.Get("repo")
  422. tag = r.Form.Get("tag")
  423. job *engine.Job
  424. )
  425. authEncoded := r.Header.Get("X-Registry-Auth")
  426. authConfig := &registry.AuthConfig{}
  427. if authEncoded != "" {
  428. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  429. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  430. // for a pull it is not an error if no auth was given
  431. // to increase compatibility with the existing api it is defaulting to be empty
  432. authConfig = &registry.AuthConfig{}
  433. }
  434. }
  435. if image != "" { //pull
  436. if tag == "" {
  437. image, tag = parsers.ParseRepositoryTag(image)
  438. }
  439. metaHeaders := map[string][]string{}
  440. for k, v := range r.Header {
  441. if strings.HasPrefix(k, "X-Meta-") {
  442. metaHeaders[k] = v
  443. }
  444. }
  445. job = eng.Job("pull", image, tag)
  446. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  447. job.SetenvJson("metaHeaders", metaHeaders)
  448. job.SetenvJson("authConfig", authConfig)
  449. } else { //import
  450. if tag == "" {
  451. repo, tag = parsers.ParseRepositoryTag(repo)
  452. }
  453. job = eng.Job("import", r.Form.Get("fromSrc"), repo, tag)
  454. job.Stdin.Add(r.Body)
  455. }
  456. if version.GreaterThan("1.0") {
  457. job.SetenvBool("json", true)
  458. streamJSON(job, w, true)
  459. } else {
  460. job.Stdout.Add(utils.NewWriteFlusher(w))
  461. }
  462. if err := job.Run(); err != nil {
  463. if !job.Stdout.Used() {
  464. return err
  465. }
  466. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  467. w.Write(sf.FormatError(err))
  468. }
  469. return nil
  470. }
  471. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  472. if err := parseForm(r); err != nil {
  473. return err
  474. }
  475. var (
  476. authEncoded = r.Header.Get("X-Registry-Auth")
  477. authConfig = &registry.AuthConfig{}
  478. metaHeaders = map[string][]string{}
  479. )
  480. if authEncoded != "" {
  481. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  482. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  483. // for a search it is not an error if no auth was given
  484. // to increase compatibility with the existing api it is defaulting to be empty
  485. authConfig = &registry.AuthConfig{}
  486. }
  487. }
  488. for k, v := range r.Header {
  489. if strings.HasPrefix(k, "X-Meta-") {
  490. metaHeaders[k] = v
  491. }
  492. }
  493. var job = eng.Job("search", r.Form.Get("term"))
  494. job.SetenvJson("metaHeaders", metaHeaders)
  495. job.SetenvJson("authConfig", authConfig)
  496. streamJSON(job, w, false)
  497. return job.Run()
  498. }
  499. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  500. if vars == nil {
  501. return fmt.Errorf("Missing parameter")
  502. }
  503. metaHeaders := map[string][]string{}
  504. for k, v := range r.Header {
  505. if strings.HasPrefix(k, "X-Meta-") {
  506. metaHeaders[k] = v
  507. }
  508. }
  509. if err := parseForm(r); err != nil {
  510. return err
  511. }
  512. authConfig := &registry.AuthConfig{}
  513. authEncoded := r.Header.Get("X-Registry-Auth")
  514. if authEncoded != "" {
  515. // the new format is to handle the authConfig as a header
  516. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  517. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  518. // to increase compatibility to existing api it is defaulting to be empty
  519. authConfig = &registry.AuthConfig{}
  520. }
  521. } else {
  522. // the old format is supported for compatibility if there was no authConfig header
  523. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  524. return err
  525. }
  526. }
  527. job := eng.Job("push", vars["name"])
  528. job.SetenvJson("metaHeaders", metaHeaders)
  529. job.SetenvJson("authConfig", authConfig)
  530. job.Setenv("tag", r.Form.Get("tag"))
  531. if version.GreaterThan("1.0") {
  532. job.SetenvBool("json", true)
  533. streamJSON(job, w, true)
  534. } else {
  535. job.Stdout.Add(utils.NewWriteFlusher(w))
  536. }
  537. if err := job.Run(); err != nil {
  538. if !job.Stdout.Used() {
  539. return err
  540. }
  541. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  542. w.Write(sf.FormatError(err))
  543. }
  544. return nil
  545. }
  546. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  547. if vars == nil {
  548. return fmt.Errorf("Missing parameter")
  549. }
  550. if version.GreaterThan("1.0") {
  551. w.Header().Set("Content-Type", "application/x-tar")
  552. }
  553. job := eng.Job("image_export", vars["name"])
  554. job.Stdout.Add(w)
  555. return job.Run()
  556. }
  557. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  558. job := eng.Job("load")
  559. job.Stdin.Add(r.Body)
  560. return job.Run()
  561. }
  562. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  563. if err := parseForm(r); err != nil {
  564. return nil
  565. }
  566. var (
  567. out engine.Env
  568. job = eng.Job("create", r.Form.Get("name"))
  569. outWarnings []string
  570. stdoutBuffer = bytes.NewBuffer(nil)
  571. warnings = bytes.NewBuffer(nil)
  572. )
  573. if err := job.DecodeEnv(r.Body); err != nil {
  574. return err
  575. }
  576. // Read container ID from the first line of stdout
  577. job.Stdout.Add(stdoutBuffer)
  578. // Read warnings from stderr
  579. job.Stderr.Add(warnings)
  580. if err := job.Run(); err != nil {
  581. return err
  582. }
  583. // Parse warnings from stderr
  584. scanner := bufio.NewScanner(warnings)
  585. for scanner.Scan() {
  586. outWarnings = append(outWarnings, scanner.Text())
  587. }
  588. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  589. out.SetList("Warnings", outWarnings)
  590. return writeJSON(w, http.StatusCreated, out)
  591. }
  592. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  593. if err := parseForm(r); err != nil {
  594. return err
  595. }
  596. if vars == nil {
  597. return fmt.Errorf("Missing parameter")
  598. }
  599. job := eng.Job("restart", vars["name"])
  600. job.Setenv("t", r.Form.Get("t"))
  601. if err := job.Run(); err != nil {
  602. return err
  603. }
  604. w.WriteHeader(http.StatusNoContent)
  605. return nil
  606. }
  607. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  608. if err := parseForm(r); err != nil {
  609. return err
  610. }
  611. if vars == nil {
  612. return fmt.Errorf("Missing parameter")
  613. }
  614. job := eng.Job("delete", vars["name"])
  615. job.Setenv("forceRemove", r.Form.Get("force"))
  616. job.Setenv("removeVolume", r.Form.Get("v"))
  617. job.Setenv("removeLink", r.Form.Get("link"))
  618. if err := job.Run(); err != nil {
  619. return err
  620. }
  621. w.WriteHeader(http.StatusNoContent)
  622. return nil
  623. }
  624. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  625. if err := parseForm(r); err != nil {
  626. return err
  627. }
  628. if vars == nil {
  629. return fmt.Errorf("Missing parameter")
  630. }
  631. var job = eng.Job("image_delete", vars["name"])
  632. streamJSON(job, w, false)
  633. job.Setenv("force", r.Form.Get("force"))
  634. job.Setenv("noprune", r.Form.Get("noprune"))
  635. return job.Run()
  636. }
  637. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  638. if vars == nil {
  639. return fmt.Errorf("Missing parameter")
  640. }
  641. var (
  642. name = vars["name"]
  643. job = eng.Job("start", name)
  644. )
  645. // allow a nil body for backwards compatibility
  646. if r.Body != nil && r.ContentLength > 0 {
  647. if !api.MatchesContentType(r.Header.Get("Content-Type"), "application/json") {
  648. return fmt.Errorf("Content-Type of application/json is required")
  649. }
  650. if err := job.DecodeEnv(r.Body); err != nil {
  651. return err
  652. }
  653. }
  654. if err := job.Run(); err != nil {
  655. if err.Error() == "Container already started" {
  656. w.WriteHeader(http.StatusNotModified)
  657. return nil
  658. }
  659. return err
  660. }
  661. w.WriteHeader(http.StatusNoContent)
  662. return nil
  663. }
  664. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  665. if err := parseForm(r); err != nil {
  666. return err
  667. }
  668. if vars == nil {
  669. return fmt.Errorf("Missing parameter")
  670. }
  671. job := eng.Job("stop", vars["name"])
  672. job.Setenv("t", r.Form.Get("t"))
  673. if err := job.Run(); err != nil {
  674. if err.Error() == "Container already stopped" {
  675. w.WriteHeader(http.StatusNotModified)
  676. return nil
  677. }
  678. return err
  679. }
  680. w.WriteHeader(http.StatusNoContent)
  681. return nil
  682. }
  683. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  684. if vars == nil {
  685. return fmt.Errorf("Missing parameter")
  686. }
  687. var (
  688. env engine.Env
  689. stdoutBuffer = bytes.NewBuffer(nil)
  690. job = eng.Job("wait", vars["name"])
  691. )
  692. job.Stdout.Add(stdoutBuffer)
  693. if err := job.Run(); err != nil {
  694. return err
  695. }
  696. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  697. return writeJSON(w, http.StatusOK, env)
  698. }
  699. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  700. if err := parseForm(r); err != nil {
  701. return err
  702. }
  703. if vars == nil {
  704. return fmt.Errorf("Missing parameter")
  705. }
  706. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  707. return err
  708. }
  709. return nil
  710. }
  711. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  712. if err := parseForm(r); err != nil {
  713. return err
  714. }
  715. if vars == nil {
  716. return fmt.Errorf("Missing parameter")
  717. }
  718. var (
  719. job = eng.Job("container_inspect", vars["name"])
  720. c, err = job.Stdout.AddEnv()
  721. )
  722. if err != nil {
  723. return err
  724. }
  725. if err = job.Run(); err != nil {
  726. return err
  727. }
  728. inStream, outStream, err := hijackServer(w)
  729. if err != nil {
  730. return err
  731. }
  732. defer func() {
  733. if tcpc, ok := inStream.(*net.TCPConn); ok {
  734. tcpc.CloseWrite()
  735. } else {
  736. inStream.Close()
  737. }
  738. }()
  739. defer func() {
  740. if tcpc, ok := outStream.(*net.TCPConn); ok {
  741. tcpc.CloseWrite()
  742. } else if closer, ok := outStream.(io.Closer); ok {
  743. closer.Close()
  744. }
  745. }()
  746. var errStream io.Writer
  747. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  748. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  749. errStream = utils.NewStdWriter(outStream, utils.Stderr)
  750. outStream = utils.NewStdWriter(outStream, utils.Stdout)
  751. } else {
  752. errStream = outStream
  753. }
  754. job = eng.Job("attach", vars["name"])
  755. job.Setenv("logs", r.Form.Get("logs"))
  756. job.Setenv("stream", r.Form.Get("stream"))
  757. job.Setenv("stdin", r.Form.Get("stdin"))
  758. job.Setenv("stdout", r.Form.Get("stdout"))
  759. job.Setenv("stderr", r.Form.Get("stderr"))
  760. job.Stdin.Add(inStream)
  761. job.Stdout.Add(outStream)
  762. job.Stderr.Set(errStream)
  763. if err := job.Run(); err != nil {
  764. fmt.Fprintf(outStream, "Error attaching: %s\n", err)
  765. }
  766. return nil
  767. }
  768. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  769. if err := parseForm(r); err != nil {
  770. return err
  771. }
  772. if vars == nil {
  773. return fmt.Errorf("Missing parameter")
  774. }
  775. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  776. return err
  777. }
  778. h := websocket.Handler(func(ws *websocket.Conn) {
  779. defer ws.Close()
  780. job := eng.Job("attach", vars["name"])
  781. job.Setenv("logs", r.Form.Get("logs"))
  782. job.Setenv("stream", r.Form.Get("stream"))
  783. job.Setenv("stdin", r.Form.Get("stdin"))
  784. job.Setenv("stdout", r.Form.Get("stdout"))
  785. job.Setenv("stderr", r.Form.Get("stderr"))
  786. job.Stdin.Add(ws)
  787. job.Stdout.Add(ws)
  788. job.Stderr.Set(ws)
  789. if err := job.Run(); err != nil {
  790. utils.Errorf("Error attaching websocket: %s", err)
  791. }
  792. })
  793. h.ServeHTTP(w, r)
  794. return nil
  795. }
  796. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  797. if vars == nil {
  798. return fmt.Errorf("Missing parameter")
  799. }
  800. var job = eng.Job("container_inspect", vars["name"])
  801. if version.LessThan("1.12") {
  802. job.SetenvBool("raw", true)
  803. }
  804. streamJSON(job, w, false)
  805. return job.Run()
  806. }
  807. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  808. if vars == nil {
  809. return fmt.Errorf("Missing parameter")
  810. }
  811. var job = eng.Job("image_inspect", vars["name"])
  812. if version.LessThan("1.12") {
  813. job.SetenvBool("raw", true)
  814. }
  815. streamJSON(job, w, false)
  816. return job.Run()
  817. }
  818. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  819. if version.LessThan("1.3") {
  820. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  821. }
  822. var (
  823. authEncoded = r.Header.Get("X-Registry-Auth")
  824. authConfig = &registry.AuthConfig{}
  825. configFileEncoded = r.Header.Get("X-Registry-Config")
  826. configFile = &registry.ConfigFile{}
  827. job = eng.Job("build")
  828. )
  829. // This block can be removed when API versions prior to 1.9 are deprecated.
  830. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  831. // ConfigFile is present, any value provided as an AuthConfig directly will
  832. // be overridden. See BuildFile::CmdFrom for details.
  833. if version.LessThan("1.9") && authEncoded != "" {
  834. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  835. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  836. // for a pull it is not an error if no auth was given
  837. // to increase compatibility with the existing api it is defaulting to be empty
  838. authConfig = &registry.AuthConfig{}
  839. }
  840. }
  841. if configFileEncoded != "" {
  842. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  843. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  844. // for a pull it is not an error if no auth was given
  845. // to increase compatibility with the existing api it is defaulting to be empty
  846. configFile = &registry.ConfigFile{}
  847. }
  848. }
  849. if version.GreaterThanOrEqualTo("1.8") {
  850. job.SetenvBool("json", true)
  851. streamJSON(job, w, true)
  852. } else {
  853. job.Stdout.Add(utils.NewWriteFlusher(w))
  854. }
  855. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  856. job.Setenv("rm", "1")
  857. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  858. job.Setenv("rm", "1")
  859. } else {
  860. job.Setenv("rm", r.FormValue("rm"))
  861. }
  862. job.Stdin.Add(r.Body)
  863. job.Setenv("remote", r.FormValue("remote"))
  864. job.Setenv("t", r.FormValue("t"))
  865. job.Setenv("q", r.FormValue("q"))
  866. job.Setenv("nocache", r.FormValue("nocache"))
  867. job.Setenv("forcerm", r.FormValue("forcerm"))
  868. job.SetenvJson("authConfig", authConfig)
  869. job.SetenvJson("configFile", configFile)
  870. if err := job.Run(); err != nil {
  871. if !job.Stdout.Used() {
  872. return err
  873. }
  874. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  875. w.Write(sf.FormatError(err))
  876. }
  877. return nil
  878. }
  879. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  880. if vars == nil {
  881. return fmt.Errorf("Missing parameter")
  882. }
  883. var copyData engine.Env
  884. if contentType := r.Header.Get("Content-Type"); api.MatchesContentType(contentType, "application/json") {
  885. if err := copyData.Decode(r.Body); err != nil {
  886. return err
  887. }
  888. } else {
  889. return fmt.Errorf("Content-Type not supported: %s", contentType)
  890. }
  891. if copyData.Get("Resource") == "" {
  892. return fmt.Errorf("Path cannot be empty")
  893. }
  894. origResource := copyData.Get("Resource")
  895. if copyData.Get("Resource")[0] == '/' {
  896. copyData.Set("Resource", copyData.Get("Resource")[1:])
  897. }
  898. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  899. job.Stdout.Add(w)
  900. if err := job.Run(); err != nil {
  901. utils.Errorf("%s", err.Error())
  902. if strings.Contains(err.Error(), "No such container") {
  903. w.WriteHeader(http.StatusNotFound)
  904. } else if strings.Contains(err.Error(), "no such file or directory") {
  905. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  906. }
  907. }
  908. return nil
  909. }
  910. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  911. w.WriteHeader(http.StatusOK)
  912. return nil
  913. }
  914. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  915. w.Header().Add("Access-Control-Allow-Origin", "*")
  916. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept")
  917. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  918. }
  919. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  920. _, err := w.Write([]byte{'O', 'K'})
  921. return err
  922. }
  923. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  924. return func(w http.ResponseWriter, r *http.Request) {
  925. // log the request
  926. utils.Debugf("Calling %s %s", localMethod, localRoute)
  927. if logging {
  928. log.Println(r.Method, r.RequestURI)
  929. }
  930. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  931. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  932. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  933. utils.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  934. }
  935. }
  936. version := version.Version(mux.Vars(r)["version"])
  937. if version == "" {
  938. version = api.APIVERSION
  939. }
  940. if enableCors {
  941. writeCorsHeaders(w, r)
  942. }
  943. if version.GreaterThan(api.APIVERSION) {
  944. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  945. return
  946. }
  947. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  948. utils.Errorf("Handler for %s %s returned error: %s", localMethod, localRoute, err)
  949. httpError(w, err)
  950. }
  951. }
  952. }
  953. // Replicated from expvar.go as not public.
  954. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  955. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  956. fmt.Fprintf(w, "{\n")
  957. first := true
  958. expvar.Do(func(kv expvar.KeyValue) {
  959. if !first {
  960. fmt.Fprintf(w, ",\n")
  961. }
  962. first = false
  963. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  964. })
  965. fmt.Fprintf(w, "\n}\n")
  966. }
  967. func AttachProfiler(router *mux.Router) {
  968. router.HandleFunc("/debug/vars", expvarHandler)
  969. router.HandleFunc("/debug/pprof/", pprof.Index)
  970. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  971. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  972. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  973. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  974. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  975. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  976. }
  977. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) (*mux.Router, error) {
  978. r := mux.NewRouter()
  979. if os.Getenv("DEBUG") != "" {
  980. AttachProfiler(r)
  981. }
  982. m := map[string]map[string]HttpApiFunc{
  983. "GET": {
  984. "/_ping": ping,
  985. "/events": getEvents,
  986. "/info": getInfo,
  987. "/version": getVersion,
  988. "/images/json": getImagesJSON,
  989. "/images/viz": getImagesViz,
  990. "/images/search": getImagesSearch,
  991. "/images/{name:.*}/get": getImagesGet,
  992. "/images/{name:.*}/history": getImagesHistory,
  993. "/images/{name:.*}/json": getImagesByName,
  994. "/containers/ps": getContainersJSON,
  995. "/containers/json": getContainersJSON,
  996. "/containers/{name:.*}/export": getContainersExport,
  997. "/containers/{name:.*}/changes": getContainersChanges,
  998. "/containers/{name:.*}/json": getContainersByName,
  999. "/containers/{name:.*}/top": getContainersTop,
  1000. "/containers/{name:.*}/logs": getContainersLogs,
  1001. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  1002. },
  1003. "POST": {
  1004. "/auth": postAuth,
  1005. "/commit": postCommit,
  1006. "/build": postBuild,
  1007. "/images/create": postImagesCreate,
  1008. "/images/load": postImagesLoad,
  1009. "/images/{name:.*}/push": postImagesPush,
  1010. "/images/{name:.*}/tag": postImagesTag,
  1011. "/containers/create": postContainersCreate,
  1012. "/containers/{name:.*}/kill": postContainersKill,
  1013. "/containers/{name:.*}/pause": postContainersPause,
  1014. "/containers/{name:.*}/unpause": postContainersUnpause,
  1015. "/containers/{name:.*}/restart": postContainersRestart,
  1016. "/containers/{name:.*}/start": postContainersStart,
  1017. "/containers/{name:.*}/stop": postContainersStop,
  1018. "/containers/{name:.*}/wait": postContainersWait,
  1019. "/containers/{name:.*}/resize": postContainersResize,
  1020. "/containers/{name:.*}/attach": postContainersAttach,
  1021. "/containers/{name:.*}/copy": postContainersCopy,
  1022. },
  1023. "DELETE": {
  1024. "/containers/{name:.*}": deleteContainers,
  1025. "/images/{name:.*}": deleteImages,
  1026. },
  1027. "OPTIONS": {
  1028. "": optionsHandler,
  1029. },
  1030. }
  1031. for method, routes := range m {
  1032. for route, fct := range routes {
  1033. utils.Debugf("Registering %s, %s", method, route)
  1034. // NOTE: scope issue, make sure the variables are local and won't be changed
  1035. localRoute := route
  1036. localFct := fct
  1037. localMethod := method
  1038. // build the handler function
  1039. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1040. // add the new route
  1041. if localRoute == "" {
  1042. r.Methods(localMethod).HandlerFunc(f)
  1043. } else {
  1044. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1045. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1046. }
  1047. }
  1048. }
  1049. return r, nil
  1050. }
  1051. // ServeRequest processes a single http request to the docker remote api.
  1052. // FIXME: refactor this to be part of Server and not require re-creating a new
  1053. // router each time. This requires first moving ListenAndServe into Server.
  1054. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) error {
  1055. router, err := createRouter(eng, false, true, "")
  1056. if err != nil {
  1057. return err
  1058. }
  1059. // Insert APIVERSION into the request as a convenience
  1060. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1061. router.ServeHTTP(w, req)
  1062. return nil
  1063. }
  1064. // ServeFD creates an http.Server and sets it up to serve given a socket activated
  1065. // argument.
  1066. func ServeFd(addr string, handle http.Handler) error {
  1067. ls, e := systemd.ListenFD(addr)
  1068. if e != nil {
  1069. return e
  1070. }
  1071. chErrors := make(chan error, len(ls))
  1072. // We don't want to start serving on these sockets until the
  1073. // daemon is initialized and installed. Otherwise required handlers
  1074. // won't be ready.
  1075. <-activationLock
  1076. // Since ListenFD will return one or more sockets we have
  1077. // to create a go func to spawn off multiple serves
  1078. for i := range ls {
  1079. listener := ls[i]
  1080. go func() {
  1081. httpSrv := http.Server{Handler: handle}
  1082. chErrors <- httpSrv.Serve(listener)
  1083. }()
  1084. }
  1085. for i := 0; i < len(ls); i += 1 {
  1086. err := <-chErrors
  1087. if err != nil {
  1088. return err
  1089. }
  1090. }
  1091. return nil
  1092. }
  1093. func lookupGidByName(nameOrGid string) (int, error) {
  1094. groups, err := user.ParseGroupFilter(func(g *user.Group) bool {
  1095. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1096. })
  1097. if err != nil {
  1098. return -1, err
  1099. }
  1100. if groups != nil && len(groups) > 0 {
  1101. return groups[0].Gid, nil
  1102. }
  1103. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1104. }
  1105. func changeGroup(addr string, nameOrGid string) error {
  1106. gid, err := lookupGidByName(nameOrGid)
  1107. if err != nil {
  1108. return err
  1109. }
  1110. utils.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1111. return os.Chown(addr, 0, gid)
  1112. }
  1113. // ListenAndServe sets up the required http.Server and gets it listening for
  1114. // each addr passed in and does protocol specific checking.
  1115. func ListenAndServe(proto, addr string, job *engine.Job) error {
  1116. var l net.Listener
  1117. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1118. if err != nil {
  1119. return err
  1120. }
  1121. if proto == "fd" {
  1122. return ServeFd(addr, r)
  1123. }
  1124. if proto == "unix" {
  1125. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1126. return err
  1127. }
  1128. }
  1129. var oldmask int
  1130. if proto == "unix" {
  1131. oldmask = syscall.Umask(0777)
  1132. }
  1133. if job.GetenvBool("BufferRequests") {
  1134. l, err = listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1135. } else {
  1136. l, err = net.Listen(proto, addr)
  1137. }
  1138. if proto == "unix" {
  1139. syscall.Umask(oldmask)
  1140. }
  1141. if err != nil {
  1142. return err
  1143. }
  1144. if proto != "unix" && (job.GetenvBool("Tls") || job.GetenvBool("TlsVerify")) {
  1145. tlsCert := job.Getenv("TlsCert")
  1146. tlsKey := job.Getenv("TlsKey")
  1147. cert, err := tls.LoadX509KeyPair(tlsCert, tlsKey)
  1148. if err != nil {
  1149. return fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1150. tlsCert, tlsKey, err)
  1151. }
  1152. tlsConfig := &tls.Config{
  1153. NextProtos: []string{"http/1.1"},
  1154. Certificates: []tls.Certificate{cert},
  1155. }
  1156. if job.GetenvBool("TlsVerify") {
  1157. certPool := x509.NewCertPool()
  1158. file, err := ioutil.ReadFile(job.Getenv("TlsCa"))
  1159. if err != nil {
  1160. return fmt.Errorf("Couldn't read CA certificate: %s", err)
  1161. }
  1162. certPool.AppendCertsFromPEM(file)
  1163. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1164. tlsConfig.ClientCAs = certPool
  1165. }
  1166. l = tls.NewListener(l, tlsConfig)
  1167. }
  1168. // Basic error and sanity checking
  1169. switch proto {
  1170. case "tcp":
  1171. if !strings.HasPrefix(addr, "127.0.0.1") && !job.GetenvBool("TlsVerify") {
  1172. log.Println("/!\\ DON'T BIND ON ANOTHER IP ADDRESS THAN 127.0.0.1 IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1173. }
  1174. case "unix":
  1175. socketGroup := job.Getenv("SocketGroup")
  1176. if socketGroup != "" {
  1177. if err := changeGroup(addr, socketGroup); err != nil {
  1178. if socketGroup == "docker" {
  1179. // if the user hasn't explicitly specified the group ownership, don't fail on errors.
  1180. utils.Debugf("Warning: could not chgrp %s to docker: %s", addr, err.Error())
  1181. } else {
  1182. return err
  1183. }
  1184. }
  1185. }
  1186. if err := os.Chmod(addr, 0660); err != nil {
  1187. return err
  1188. }
  1189. default:
  1190. return fmt.Errorf("Invalid protocol format.")
  1191. }
  1192. httpSrv := http.Server{Addr: addr, Handler: r}
  1193. return httpSrv.Serve(l)
  1194. }
  1195. // ServeApi loops through all of the protocols sent in to docker and spawns
  1196. // off a go routine to setup a serving http.Server for each.
  1197. func ServeApi(job *engine.Job) engine.Status {
  1198. if len(job.Args) == 0 {
  1199. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1200. }
  1201. var (
  1202. protoAddrs = job.Args
  1203. chErrors = make(chan error, len(protoAddrs))
  1204. )
  1205. activationLock = make(chan struct{})
  1206. for _, protoAddr := range protoAddrs {
  1207. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1208. if len(protoAddrParts) != 2 {
  1209. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1210. }
  1211. go func() {
  1212. log.Printf("Listening for HTTP on %s (%s)\n", protoAddrParts[0], protoAddrParts[1])
  1213. chErrors <- ListenAndServe(protoAddrParts[0], protoAddrParts[1], job)
  1214. }()
  1215. }
  1216. for i := 0; i < len(protoAddrs); i += 1 {
  1217. err := <-chErrors
  1218. if err != nil {
  1219. return job.Error(err)
  1220. }
  1221. }
  1222. return engine.StatusOK
  1223. }
  1224. func AcceptConnections(job *engine.Job) engine.Status {
  1225. // Tell the init daemon we are accepting requests
  1226. go systemd.SdNotify("READY=1")
  1227. // close the lock so the listeners start accepting connections
  1228. if activationLock != nil {
  1229. close(activationLock)
  1230. }
  1231. return engine.StatusOK
  1232. }