server.go 48 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "encoding/base64"
  6. "encoding/json"
  7. "expvar"
  8. "fmt"
  9. "io"
  10. "io/ioutil"
  11. "net"
  12. "net/http"
  13. "net/http/pprof"
  14. "os"
  15. "strconv"
  16. "strings"
  17. "syscall"
  18. "crypto/tls"
  19. "crypto/x509"
  20. "code.google.com/p/go.net/websocket"
  21. "github.com/docker/libcontainer/user"
  22. "github.com/gorilla/mux"
  23. log "github.com/Sirupsen/logrus"
  24. "github.com/docker/docker/api"
  25. "github.com/docker/docker/daemon/networkdriver/portallocator"
  26. "github.com/docker/docker/engine"
  27. "github.com/docker/docker/pkg/listenbuffer"
  28. "github.com/docker/docker/pkg/parsers"
  29. "github.com/docker/docker/pkg/stdcopy"
  30. "github.com/docker/docker/pkg/systemd"
  31. "github.com/docker/docker/pkg/version"
  32. "github.com/docker/docker/registry"
  33. "github.com/docker/docker/utils"
  34. )
  35. var (
  36. activationLock chan struct{}
  37. )
  38. type HttpServer struct {
  39. srv *http.Server
  40. l net.Listener
  41. }
  42. func (s *HttpServer) Serve() error {
  43. return s.srv.Serve(s.l)
  44. }
  45. func (s *HttpServer) Close() error {
  46. return s.l.Close()
  47. }
  48. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  49. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  50. conn, _, err := w.(http.Hijacker).Hijack()
  51. if err != nil {
  52. return nil, nil, err
  53. }
  54. // Flush the options to make sure the client sets the raw mode
  55. conn.Write([]byte{})
  56. return conn, conn, nil
  57. }
  58. func closeStreams(streams ...interface{}) {
  59. for _, stream := range streams {
  60. if tcpc, ok := stream.(interface {
  61. CloseWrite() error
  62. }); ok {
  63. tcpc.CloseWrite()
  64. } else if closer, ok := stream.(io.Closer); ok {
  65. closer.Close()
  66. }
  67. }
  68. }
  69. // Check to make sure request's Content-Type is application/json
  70. func checkForJson(r *http.Request) error {
  71. ct := r.Header.Get("Content-Type")
  72. // No Content-Type header is ok as long as there's no Body
  73. if ct == "" {
  74. if r.Body == nil || r.ContentLength == 0 {
  75. return nil
  76. }
  77. }
  78. // Otherwise it better be json
  79. if api.MatchesContentType(ct, "application/json") {
  80. return nil
  81. }
  82. return fmt.Errorf("Content-Type specified (%s) must be 'application/json'", ct)
  83. }
  84. //If we don't do this, POST method without Content-type (even with empty body) will fail
  85. func parseForm(r *http.Request) error {
  86. if r == nil {
  87. return nil
  88. }
  89. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  90. return err
  91. }
  92. return nil
  93. }
  94. func parseMultipartForm(r *http.Request) error {
  95. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  96. return err
  97. }
  98. return nil
  99. }
  100. func httpError(w http.ResponseWriter, err error) {
  101. statusCode := http.StatusInternalServerError
  102. // FIXME: this is brittle and should not be necessary.
  103. // If we need to differentiate between different possible error types, we should
  104. // create appropriate error types with clearly defined meaning.
  105. errStr := strings.ToLower(err.Error())
  106. if strings.Contains(errStr, "no such") {
  107. statusCode = http.StatusNotFound
  108. } else if strings.Contains(errStr, "bad parameter") {
  109. statusCode = http.StatusBadRequest
  110. } else if strings.Contains(errStr, "conflict") {
  111. statusCode = http.StatusConflict
  112. } else if strings.Contains(errStr, "impossible") {
  113. statusCode = http.StatusNotAcceptable
  114. } else if strings.Contains(errStr, "wrong login/password") {
  115. statusCode = http.StatusUnauthorized
  116. } else if strings.Contains(errStr, "hasn't been activated") {
  117. statusCode = http.StatusForbidden
  118. }
  119. if err != nil {
  120. log.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  121. http.Error(w, err.Error(), statusCode)
  122. }
  123. }
  124. func writeJSON(w http.ResponseWriter, code int, v engine.Env) error {
  125. w.Header().Set("Content-Type", "application/json")
  126. w.WriteHeader(code)
  127. return v.Encode(w)
  128. }
  129. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  130. w.Header().Set("Content-Type", "application/json")
  131. if flush {
  132. job.Stdout.Add(utils.NewWriteFlusher(w))
  133. } else {
  134. job.Stdout.Add(w)
  135. }
  136. }
  137. func getBoolParam(value string) (bool, error) {
  138. if value == "" {
  139. return false, nil
  140. }
  141. ret, err := strconv.ParseBool(value)
  142. if err != nil {
  143. return false, fmt.Errorf("Bad parameter")
  144. }
  145. return ret, nil
  146. }
  147. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  148. var (
  149. authConfig, err = ioutil.ReadAll(r.Body)
  150. job = eng.Job("auth")
  151. stdoutBuffer = bytes.NewBuffer(nil)
  152. )
  153. if err != nil {
  154. return err
  155. }
  156. job.Setenv("authConfig", string(authConfig))
  157. job.Stdout.Add(stdoutBuffer)
  158. if err = job.Run(); err != nil {
  159. return err
  160. }
  161. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  162. var env engine.Env
  163. env.Set("Status", status)
  164. return writeJSON(w, http.StatusOK, env)
  165. }
  166. w.WriteHeader(http.StatusNoContent)
  167. return nil
  168. }
  169. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  170. w.Header().Set("Content-Type", "application/json")
  171. eng.ServeHTTP(w, r)
  172. return nil
  173. }
  174. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  175. if vars == nil {
  176. return fmt.Errorf("Missing parameter")
  177. }
  178. if err := parseForm(r); err != nil {
  179. return err
  180. }
  181. job := eng.Job("kill", vars["name"])
  182. if sig := r.Form.Get("signal"); sig != "" {
  183. job.Args = append(job.Args, sig)
  184. }
  185. if err := job.Run(); err != nil {
  186. return err
  187. }
  188. w.WriteHeader(http.StatusNoContent)
  189. return nil
  190. }
  191. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  192. if vars == nil {
  193. return fmt.Errorf("Missing parameter")
  194. }
  195. if err := parseForm(r); err != nil {
  196. return err
  197. }
  198. job := eng.Job("pause", vars["name"])
  199. if err := job.Run(); err != nil {
  200. return err
  201. }
  202. w.WriteHeader(http.StatusNoContent)
  203. return nil
  204. }
  205. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  206. if vars == nil {
  207. return fmt.Errorf("Missing parameter")
  208. }
  209. if err := parseForm(r); err != nil {
  210. return err
  211. }
  212. job := eng.Job("unpause", vars["name"])
  213. if err := job.Run(); err != nil {
  214. return err
  215. }
  216. w.WriteHeader(http.StatusNoContent)
  217. return nil
  218. }
  219. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  220. if vars == nil {
  221. return fmt.Errorf("Missing parameter")
  222. }
  223. job := eng.Job("export", vars["name"])
  224. job.Stdout.Add(w)
  225. if err := job.Run(); err != nil {
  226. return err
  227. }
  228. return nil
  229. }
  230. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  231. if err := parseForm(r); err != nil {
  232. return err
  233. }
  234. var (
  235. err error
  236. outs *engine.Table
  237. job = eng.Job("images")
  238. )
  239. job.Setenv("filters", r.Form.Get("filters"))
  240. // FIXME this parameter could just be a match filter
  241. job.Setenv("filter", r.Form.Get("filter"))
  242. job.Setenv("all", r.Form.Get("all"))
  243. if version.GreaterThanOrEqualTo("1.7") {
  244. streamJSON(job, w, false)
  245. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  246. return err
  247. }
  248. if err := job.Run(); err != nil {
  249. return err
  250. }
  251. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  252. outsLegacy := engine.NewTable("Created", 0)
  253. for _, out := range outs.Data {
  254. for _, repoTag := range out.GetList("RepoTags") {
  255. repo, tag := parsers.ParseRepositoryTag(repoTag)
  256. outLegacy := &engine.Env{}
  257. outLegacy.Set("Repository", repo)
  258. outLegacy.SetJson("Tag", tag)
  259. outLegacy.Set("Id", out.Get("Id"))
  260. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  261. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  262. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  263. outsLegacy.Add(outLegacy)
  264. }
  265. }
  266. w.Header().Set("Content-Type", "application/json")
  267. if _, err := outsLegacy.WriteListTo(w); err != nil {
  268. return err
  269. }
  270. }
  271. return nil
  272. }
  273. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  274. if version.GreaterThan("1.6") {
  275. w.WriteHeader(http.StatusNotFound)
  276. return fmt.Errorf("This is now implemented in the client.")
  277. }
  278. eng.ServeHTTP(w, r)
  279. return nil
  280. }
  281. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  282. w.Header().Set("Content-Type", "application/json")
  283. eng.ServeHTTP(w, r)
  284. return nil
  285. }
  286. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  287. if err := parseForm(r); err != nil {
  288. return err
  289. }
  290. var job = eng.Job("events")
  291. streamJSON(job, w, true)
  292. job.Setenv("since", r.Form.Get("since"))
  293. job.Setenv("until", r.Form.Get("until"))
  294. job.Setenv("filters", r.Form.Get("filters"))
  295. return job.Run()
  296. }
  297. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  298. if vars == nil {
  299. return fmt.Errorf("Missing parameter")
  300. }
  301. var job = eng.Job("history", vars["name"])
  302. streamJSON(job, w, false)
  303. if err := job.Run(); err != nil {
  304. return err
  305. }
  306. return nil
  307. }
  308. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  309. if vars == nil {
  310. return fmt.Errorf("Missing parameter")
  311. }
  312. var job = eng.Job("container_changes", vars["name"])
  313. streamJSON(job, w, false)
  314. return job.Run()
  315. }
  316. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  317. if version.LessThan("1.4") {
  318. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  319. }
  320. if vars == nil {
  321. return fmt.Errorf("Missing parameter")
  322. }
  323. if err := parseForm(r); err != nil {
  324. return err
  325. }
  326. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  327. streamJSON(job, w, false)
  328. return job.Run()
  329. }
  330. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  331. if err := parseForm(r); err != nil {
  332. return err
  333. }
  334. var (
  335. err error
  336. outs *engine.Table
  337. job = eng.Job("containers")
  338. )
  339. job.Setenv("all", r.Form.Get("all"))
  340. job.Setenv("size", r.Form.Get("size"))
  341. job.Setenv("since", r.Form.Get("since"))
  342. job.Setenv("before", r.Form.Get("before"))
  343. job.Setenv("limit", r.Form.Get("limit"))
  344. job.Setenv("filters", r.Form.Get("filters"))
  345. if version.GreaterThanOrEqualTo("1.5") {
  346. streamJSON(job, w, false)
  347. } else if outs, err = job.Stdout.AddTable(); err != nil {
  348. return err
  349. }
  350. if err = job.Run(); err != nil {
  351. return err
  352. }
  353. if version.LessThan("1.5") { // Convert to legacy format
  354. for _, out := range outs.Data {
  355. ports := engine.NewTable("", 0)
  356. ports.ReadListFrom([]byte(out.Get("Ports")))
  357. out.Set("Ports", api.DisplayablePorts(ports))
  358. }
  359. w.Header().Set("Content-Type", "application/json")
  360. if _, err = outs.WriteListTo(w); err != nil {
  361. return err
  362. }
  363. }
  364. return nil
  365. }
  366. func getContainersStats(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  367. if err := parseForm(r); err != nil {
  368. return err
  369. }
  370. if vars == nil {
  371. return fmt.Errorf("Missing parameter")
  372. }
  373. name := vars["name"]
  374. job := eng.Job("container_stats", name)
  375. streamJSON(job, w, true)
  376. return job.Run()
  377. }
  378. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  379. if err := parseForm(r); err != nil {
  380. return err
  381. }
  382. if vars == nil {
  383. return fmt.Errorf("Missing parameter")
  384. }
  385. var (
  386. inspectJob = eng.Job("container_inspect", vars["name"])
  387. logsJob = eng.Job("logs", vars["name"])
  388. c, err = inspectJob.Stdout.AddEnv()
  389. )
  390. if err != nil {
  391. return err
  392. }
  393. logsJob.Setenv("follow", r.Form.Get("follow"))
  394. logsJob.Setenv("tail", r.Form.Get("tail"))
  395. logsJob.Setenv("stdout", r.Form.Get("stdout"))
  396. logsJob.Setenv("stderr", r.Form.Get("stderr"))
  397. logsJob.Setenv("timestamps", r.Form.Get("timestamps"))
  398. // Validate args here, because we can't return not StatusOK after job.Run() call
  399. stdout, stderr := logsJob.GetenvBool("stdout"), logsJob.GetenvBool("stderr")
  400. if !(stdout || stderr) {
  401. return fmt.Errorf("Bad parameters: you must choose at least one stream")
  402. }
  403. if err = inspectJob.Run(); err != nil {
  404. return err
  405. }
  406. var outStream, errStream io.Writer
  407. outStream = utils.NewWriteFlusher(w)
  408. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  409. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  410. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  411. } else {
  412. errStream = outStream
  413. }
  414. logsJob.Stdout.Add(outStream)
  415. logsJob.Stderr.Set(errStream)
  416. if err := logsJob.Run(); err != nil {
  417. fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
  418. }
  419. return nil
  420. }
  421. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  422. if err := parseForm(r); err != nil {
  423. return err
  424. }
  425. if vars == nil {
  426. return fmt.Errorf("Missing parameter")
  427. }
  428. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  429. job.Setenv("force", r.Form.Get("force"))
  430. if err := job.Run(); err != nil {
  431. return err
  432. }
  433. w.WriteHeader(http.StatusCreated)
  434. return nil
  435. }
  436. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  437. if err := parseForm(r); err != nil {
  438. return err
  439. }
  440. var (
  441. config engine.Env
  442. env engine.Env
  443. job = eng.Job("commit", r.Form.Get("container"))
  444. stdoutBuffer = bytes.NewBuffer(nil)
  445. )
  446. if err := checkForJson(r); err != nil {
  447. return err
  448. }
  449. if err := config.Decode(r.Body); err != nil {
  450. log.Errorf("%s", err)
  451. }
  452. if r.FormValue("pause") == "" && version.GreaterThanOrEqualTo("1.13") {
  453. job.Setenv("pause", "1")
  454. } else {
  455. job.Setenv("pause", r.FormValue("pause"))
  456. }
  457. job.Setenv("repo", r.Form.Get("repo"))
  458. job.Setenv("tag", r.Form.Get("tag"))
  459. job.Setenv("author", r.Form.Get("author"))
  460. job.Setenv("comment", r.Form.Get("comment"))
  461. job.SetenvSubEnv("config", &config)
  462. job.Stdout.Add(stdoutBuffer)
  463. if err := job.Run(); err != nil {
  464. return err
  465. }
  466. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  467. return writeJSON(w, http.StatusCreated, env)
  468. }
  469. // Creates an image from Pull or from Import
  470. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  471. if err := parseForm(r); err != nil {
  472. return err
  473. }
  474. var (
  475. image = r.Form.Get("fromImage")
  476. repo = r.Form.Get("repo")
  477. tag = r.Form.Get("tag")
  478. job *engine.Job
  479. )
  480. authEncoded := r.Header.Get("X-Registry-Auth")
  481. authConfig := &registry.AuthConfig{}
  482. if authEncoded != "" {
  483. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  484. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  485. // for a pull it is not an error if no auth was given
  486. // to increase compatibility with the existing api it is defaulting to be empty
  487. authConfig = &registry.AuthConfig{}
  488. }
  489. }
  490. if image != "" { //pull
  491. if tag == "" {
  492. image, tag = parsers.ParseRepositoryTag(image)
  493. }
  494. metaHeaders := map[string][]string{}
  495. for k, v := range r.Header {
  496. if strings.HasPrefix(k, "X-Meta-") {
  497. metaHeaders[k] = v
  498. }
  499. }
  500. job = eng.Job("pull", image, tag)
  501. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  502. job.SetenvJson("metaHeaders", metaHeaders)
  503. job.SetenvJson("authConfig", authConfig)
  504. } else { //import
  505. if tag == "" {
  506. repo, tag = parsers.ParseRepositoryTag(repo)
  507. }
  508. job = eng.Job("import", r.Form.Get("fromSrc"), repo, tag)
  509. job.Stdin.Add(r.Body)
  510. }
  511. if version.GreaterThan("1.0") {
  512. job.SetenvBool("json", true)
  513. streamJSON(job, w, true)
  514. } else {
  515. job.Stdout.Add(utils.NewWriteFlusher(w))
  516. }
  517. if err := job.Run(); err != nil {
  518. if !job.Stdout.Used() {
  519. return err
  520. }
  521. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  522. w.Write(sf.FormatError(err))
  523. }
  524. return nil
  525. }
  526. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  527. if err := parseForm(r); err != nil {
  528. return err
  529. }
  530. var (
  531. authEncoded = r.Header.Get("X-Registry-Auth")
  532. authConfig = &registry.AuthConfig{}
  533. metaHeaders = map[string][]string{}
  534. )
  535. if authEncoded != "" {
  536. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  537. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  538. // for a search it is not an error if no auth was given
  539. // to increase compatibility with the existing api it is defaulting to be empty
  540. authConfig = &registry.AuthConfig{}
  541. }
  542. }
  543. for k, v := range r.Header {
  544. if strings.HasPrefix(k, "X-Meta-") {
  545. metaHeaders[k] = v
  546. }
  547. }
  548. var job = eng.Job("search", r.Form.Get("term"))
  549. job.SetenvJson("metaHeaders", metaHeaders)
  550. job.SetenvJson("authConfig", authConfig)
  551. streamJSON(job, w, false)
  552. return job.Run()
  553. }
  554. func getImageManifest(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  555. if err := parseForm(r); err != nil {
  556. return err
  557. }
  558. job := eng.Job("image_manifest", vars["name"])
  559. job.Setenv("tag", r.Form.Get("tag"))
  560. job.Stdout.Add(utils.NewWriteFlusher(w))
  561. return job.Run()
  562. }
  563. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  564. if vars == nil {
  565. return fmt.Errorf("Missing parameter")
  566. }
  567. metaHeaders := map[string][]string{}
  568. for k, v := range r.Header {
  569. if strings.HasPrefix(k, "X-Meta-") {
  570. metaHeaders[k] = v
  571. }
  572. }
  573. if err := parseForm(r); err != nil {
  574. return err
  575. }
  576. authConfig := &registry.AuthConfig{}
  577. authEncoded := r.Header.Get("X-Registry-Auth")
  578. if authEncoded != "" {
  579. // the new format is to handle the authConfig as a header
  580. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  581. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  582. // to increase compatibility to existing api it is defaulting to be empty
  583. authConfig = &registry.AuthConfig{}
  584. }
  585. } else {
  586. // the old format is supported for compatibility if there was no authConfig header
  587. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  588. return err
  589. }
  590. }
  591. manifest, err := ioutil.ReadAll(r.Body)
  592. if err != nil {
  593. return err
  594. }
  595. job := eng.Job("push", vars["name"])
  596. job.SetenvJson("metaHeaders", metaHeaders)
  597. job.SetenvJson("authConfig", authConfig)
  598. job.Setenv("manifest", string(manifest))
  599. job.Setenv("tag", r.Form.Get("tag"))
  600. if version.GreaterThan("1.0") {
  601. job.SetenvBool("json", true)
  602. streamJSON(job, w, true)
  603. } else {
  604. job.Stdout.Add(utils.NewWriteFlusher(w))
  605. }
  606. if err := job.Run(); err != nil {
  607. if !job.Stdout.Used() {
  608. return err
  609. }
  610. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  611. w.Write(sf.FormatError(err))
  612. }
  613. return nil
  614. }
  615. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  616. if vars == nil {
  617. return fmt.Errorf("Missing parameter")
  618. }
  619. if err := parseForm(r); err != nil {
  620. return err
  621. }
  622. if version.GreaterThan("1.0") {
  623. w.Header().Set("Content-Type", "application/x-tar")
  624. }
  625. var job *engine.Job
  626. if name, ok := vars["name"]; ok {
  627. job = eng.Job("image_export", name)
  628. } else {
  629. job = eng.Job("image_export", r.Form["names"]...)
  630. }
  631. job.Stdout.Add(w)
  632. return job.Run()
  633. }
  634. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  635. job := eng.Job("load")
  636. job.Stdin.Add(r.Body)
  637. return job.Run()
  638. }
  639. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  640. if err := parseForm(r); err != nil {
  641. return nil
  642. }
  643. var (
  644. out engine.Env
  645. job = eng.Job("create", r.Form.Get("name"))
  646. outWarnings []string
  647. stdoutBuffer = bytes.NewBuffer(nil)
  648. warnings = bytes.NewBuffer(nil)
  649. )
  650. if err := checkForJson(r); err != nil {
  651. return err
  652. }
  653. if err := job.DecodeEnv(r.Body); err != nil {
  654. return err
  655. }
  656. // Read container ID from the first line of stdout
  657. job.Stdout.Add(stdoutBuffer)
  658. // Read warnings from stderr
  659. job.Stderr.Add(warnings)
  660. if err := job.Run(); err != nil {
  661. return err
  662. }
  663. // Parse warnings from stderr
  664. scanner := bufio.NewScanner(warnings)
  665. for scanner.Scan() {
  666. outWarnings = append(outWarnings, scanner.Text())
  667. }
  668. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  669. out.SetList("Warnings", outWarnings)
  670. return writeJSON(w, http.StatusCreated, out)
  671. }
  672. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  673. if err := parseForm(r); err != nil {
  674. return err
  675. }
  676. if vars == nil {
  677. return fmt.Errorf("Missing parameter")
  678. }
  679. job := eng.Job("restart", vars["name"])
  680. job.Setenv("t", r.Form.Get("t"))
  681. if err := job.Run(); err != nil {
  682. return err
  683. }
  684. w.WriteHeader(http.StatusNoContent)
  685. return nil
  686. }
  687. func postContainerRename(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  688. if err := parseForm(r); err != nil {
  689. return err
  690. }
  691. if vars == nil {
  692. return fmt.Errorf("Missing parameter")
  693. }
  694. newName := r.URL.Query().Get("name")
  695. job := eng.Job("container_rename", vars["name"], newName)
  696. job.Setenv("t", r.Form.Get("t"))
  697. if err := job.Run(); err != nil {
  698. return err
  699. }
  700. w.WriteHeader(http.StatusNoContent)
  701. return nil
  702. }
  703. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  704. if err := parseForm(r); err != nil {
  705. return err
  706. }
  707. if vars == nil {
  708. return fmt.Errorf("Missing parameter")
  709. }
  710. job := eng.Job("rm", vars["name"])
  711. job.Setenv("forceRemove", r.Form.Get("force"))
  712. job.Setenv("removeVolume", r.Form.Get("v"))
  713. job.Setenv("removeLink", r.Form.Get("link"))
  714. if err := job.Run(); err != nil {
  715. return err
  716. }
  717. w.WriteHeader(http.StatusNoContent)
  718. return nil
  719. }
  720. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  721. if err := parseForm(r); err != nil {
  722. return err
  723. }
  724. if vars == nil {
  725. return fmt.Errorf("Missing parameter")
  726. }
  727. var job = eng.Job("image_delete", vars["name"])
  728. streamJSON(job, w, false)
  729. job.Setenv("force", r.Form.Get("force"))
  730. job.Setenv("noprune", r.Form.Get("noprune"))
  731. return job.Run()
  732. }
  733. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  734. if vars == nil {
  735. return fmt.Errorf("Missing parameter")
  736. }
  737. var (
  738. name = vars["name"]
  739. job = eng.Job("start", name)
  740. )
  741. // If contentLength is -1, we can assumed chunked encoding
  742. // or more technically that the length is unknown
  743. // http://golang.org/src/pkg/net/http/request.go#L139
  744. // net/http otherwise seems to swallow any headers related to chunked encoding
  745. // including r.TransferEncoding
  746. // allow a nil body for backwards compatibility
  747. if r.Body != nil && (r.ContentLength > 0 || r.ContentLength == -1) {
  748. if err := checkForJson(r); err != nil {
  749. return err
  750. }
  751. if err := job.DecodeEnv(r.Body); err != nil {
  752. return err
  753. }
  754. }
  755. if err := job.Run(); err != nil {
  756. if err.Error() == "Container already started" {
  757. w.WriteHeader(http.StatusNotModified)
  758. return nil
  759. }
  760. return err
  761. }
  762. w.WriteHeader(http.StatusNoContent)
  763. return nil
  764. }
  765. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  766. if err := parseForm(r); err != nil {
  767. return err
  768. }
  769. if vars == nil {
  770. return fmt.Errorf("Missing parameter")
  771. }
  772. job := eng.Job("stop", vars["name"])
  773. job.Setenv("t", r.Form.Get("t"))
  774. if err := job.Run(); err != nil {
  775. if err.Error() == "Container already stopped" {
  776. w.WriteHeader(http.StatusNotModified)
  777. return nil
  778. }
  779. return err
  780. }
  781. w.WriteHeader(http.StatusNoContent)
  782. return nil
  783. }
  784. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  785. if vars == nil {
  786. return fmt.Errorf("Missing parameter")
  787. }
  788. var (
  789. env engine.Env
  790. stdoutBuffer = bytes.NewBuffer(nil)
  791. job = eng.Job("wait", vars["name"])
  792. )
  793. job.Stdout.Add(stdoutBuffer)
  794. if err := job.Run(); err != nil {
  795. return err
  796. }
  797. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  798. return writeJSON(w, http.StatusOK, env)
  799. }
  800. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  801. if err := parseForm(r); err != nil {
  802. return err
  803. }
  804. if vars == nil {
  805. return fmt.Errorf("Missing parameter")
  806. }
  807. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  808. return err
  809. }
  810. return nil
  811. }
  812. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  813. if err := parseForm(r); err != nil {
  814. return err
  815. }
  816. if vars == nil {
  817. return fmt.Errorf("Missing parameter")
  818. }
  819. var (
  820. job = eng.Job("container_inspect", vars["name"])
  821. c, err = job.Stdout.AddEnv()
  822. )
  823. if err != nil {
  824. return err
  825. }
  826. if err = job.Run(); err != nil {
  827. return err
  828. }
  829. inStream, outStream, err := hijackServer(w)
  830. if err != nil {
  831. return err
  832. }
  833. defer closeStreams(inStream, outStream)
  834. var errStream io.Writer
  835. if _, ok := r.Header["Upgrade"]; ok {
  836. fmt.Fprintf(outStream, "HTTP/1.1 101 UPGRADED\r\nContent-Type: application/vnd.docker.raw-stream\r\nConnection: Upgrade\r\nUpgrade: tcp\r\n\r\n")
  837. } else {
  838. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  839. }
  840. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  841. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  842. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  843. } else {
  844. errStream = outStream
  845. }
  846. job = eng.Job("attach", vars["name"])
  847. job.Setenv("logs", r.Form.Get("logs"))
  848. job.Setenv("stream", r.Form.Get("stream"))
  849. job.Setenv("stdin", r.Form.Get("stdin"))
  850. job.Setenv("stdout", r.Form.Get("stdout"))
  851. job.Setenv("stderr", r.Form.Get("stderr"))
  852. job.Stdin.Add(inStream)
  853. job.Stdout.Add(outStream)
  854. job.Stderr.Set(errStream)
  855. if err := job.Run(); err != nil {
  856. fmt.Fprintf(outStream, "Error attaching: %s\n", err)
  857. }
  858. return nil
  859. }
  860. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  861. if err := parseForm(r); err != nil {
  862. return err
  863. }
  864. if vars == nil {
  865. return fmt.Errorf("Missing parameter")
  866. }
  867. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  868. return err
  869. }
  870. h := websocket.Handler(func(ws *websocket.Conn) {
  871. defer ws.Close()
  872. job := eng.Job("attach", vars["name"])
  873. job.Setenv("logs", r.Form.Get("logs"))
  874. job.Setenv("stream", r.Form.Get("stream"))
  875. job.Setenv("stdin", r.Form.Get("stdin"))
  876. job.Setenv("stdout", r.Form.Get("stdout"))
  877. job.Setenv("stderr", r.Form.Get("stderr"))
  878. job.Stdin.Add(ws)
  879. job.Stdout.Add(ws)
  880. job.Stderr.Set(ws)
  881. if err := job.Run(); err != nil {
  882. log.Errorf("Error attaching websocket: %s", err)
  883. }
  884. })
  885. h.ServeHTTP(w, r)
  886. return nil
  887. }
  888. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  889. if vars == nil {
  890. return fmt.Errorf("Missing parameter")
  891. }
  892. var job = eng.Job("container_inspect", vars["name"])
  893. if version.LessThan("1.12") {
  894. job.SetenvBool("raw", true)
  895. }
  896. streamJSON(job, w, false)
  897. return job.Run()
  898. }
  899. func getExecByID(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  900. if vars == nil {
  901. return fmt.Errorf("Missing parameter 'id'")
  902. }
  903. var job = eng.Job("execInspect", vars["id"])
  904. streamJSON(job, w, false)
  905. return job.Run()
  906. }
  907. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  908. if vars == nil {
  909. return fmt.Errorf("Missing parameter")
  910. }
  911. var job = eng.Job("image_inspect", vars["name"])
  912. if version.LessThan("1.12") {
  913. job.SetenvBool("raw", true)
  914. }
  915. streamJSON(job, w, false)
  916. return job.Run()
  917. }
  918. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  919. if version.LessThan("1.3") {
  920. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  921. }
  922. var (
  923. authEncoded = r.Header.Get("X-Registry-Auth")
  924. authConfig = &registry.AuthConfig{}
  925. configFileEncoded = r.Header.Get("X-Registry-Config")
  926. configFile = &registry.ConfigFile{}
  927. job = eng.Job("build")
  928. )
  929. // This block can be removed when API versions prior to 1.9 are deprecated.
  930. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  931. // ConfigFile is present, any value provided as an AuthConfig directly will
  932. // be overridden. See BuildFile::CmdFrom for details.
  933. if version.LessThan("1.9") && authEncoded != "" {
  934. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  935. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  936. // for a pull it is not an error if no auth was given
  937. // to increase compatibility with the existing api it is defaulting to be empty
  938. authConfig = &registry.AuthConfig{}
  939. }
  940. }
  941. if configFileEncoded != "" {
  942. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  943. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  944. // for a pull it is not an error if no auth was given
  945. // to increase compatibility with the existing api it is defaulting to be empty
  946. configFile = &registry.ConfigFile{}
  947. }
  948. }
  949. if version.GreaterThanOrEqualTo("1.8") {
  950. job.SetenvBool("json", true)
  951. streamJSON(job, w, true)
  952. } else {
  953. job.Stdout.Add(utils.NewWriteFlusher(w))
  954. }
  955. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  956. job.Setenv("rm", "1")
  957. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  958. job.Setenv("rm", "1")
  959. } else {
  960. job.Setenv("rm", r.FormValue("rm"))
  961. }
  962. if r.FormValue("pull") == "1" && version.GreaterThanOrEqualTo("1.16") {
  963. job.Setenv("pull", "1")
  964. }
  965. job.Stdin.Add(r.Body)
  966. job.Setenv("remote", r.FormValue("remote"))
  967. job.Setenv("dockerfile", r.FormValue("dockerfile"))
  968. job.Setenv("t", r.FormValue("t"))
  969. job.Setenv("q", r.FormValue("q"))
  970. job.Setenv("nocache", r.FormValue("nocache"))
  971. job.Setenv("forcerm", r.FormValue("forcerm"))
  972. job.SetenvJson("authConfig", authConfig)
  973. job.SetenvJson("configFile", configFile)
  974. if err := job.Run(); err != nil {
  975. if !job.Stdout.Used() {
  976. return err
  977. }
  978. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  979. w.Write(sf.FormatError(err))
  980. }
  981. return nil
  982. }
  983. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  984. if vars == nil {
  985. return fmt.Errorf("Missing parameter")
  986. }
  987. var copyData engine.Env
  988. if err := checkForJson(r); err != nil {
  989. return err
  990. }
  991. if err := copyData.Decode(r.Body); err != nil {
  992. return err
  993. }
  994. if copyData.Get("Resource") == "" {
  995. return fmt.Errorf("Path cannot be empty")
  996. }
  997. origResource := copyData.Get("Resource")
  998. if copyData.Get("Resource")[0] == '/' {
  999. copyData.Set("Resource", copyData.Get("Resource")[1:])
  1000. }
  1001. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  1002. job.Stdout.Add(w)
  1003. w.Header().Set("Content-Type", "application/x-tar")
  1004. if err := job.Run(); err != nil {
  1005. log.Errorf("%s", err.Error())
  1006. if strings.Contains(strings.ToLower(err.Error()), "no such id") {
  1007. w.WriteHeader(http.StatusNotFound)
  1008. } else if strings.Contains(err.Error(), "no such file or directory") {
  1009. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  1010. }
  1011. }
  1012. return nil
  1013. }
  1014. func postContainerExecCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1015. if err := parseForm(r); err != nil {
  1016. return nil
  1017. }
  1018. var (
  1019. out engine.Env
  1020. name = vars["name"]
  1021. job = eng.Job("execCreate", name)
  1022. stdoutBuffer = bytes.NewBuffer(nil)
  1023. )
  1024. if err := job.DecodeEnv(r.Body); err != nil {
  1025. return err
  1026. }
  1027. job.Stdout.Add(stdoutBuffer)
  1028. // Register an instance of Exec in container.
  1029. if err := job.Run(); err != nil {
  1030. fmt.Fprintf(os.Stderr, "Error setting up exec command in container %s: %s\n", name, err)
  1031. return err
  1032. }
  1033. // Return the ID
  1034. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  1035. return writeJSON(w, http.StatusCreated, out)
  1036. }
  1037. // TODO(vishh): Refactor the code to avoid having to specify stream config as part of both create and start.
  1038. func postContainerExecStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1039. if err := parseForm(r); err != nil {
  1040. return nil
  1041. }
  1042. var (
  1043. name = vars["name"]
  1044. job = eng.Job("execStart", name)
  1045. errOut io.Writer = os.Stderr
  1046. )
  1047. if err := job.DecodeEnv(r.Body); err != nil {
  1048. return err
  1049. }
  1050. if !job.GetenvBool("Detach") {
  1051. // Setting up the streaming http interface.
  1052. inStream, outStream, err := hijackServer(w)
  1053. if err != nil {
  1054. return err
  1055. }
  1056. defer closeStreams(inStream, outStream)
  1057. var errStream io.Writer
  1058. if _, ok := r.Header["Upgrade"]; ok {
  1059. fmt.Fprintf(outStream, "HTTP/1.1 101 UPGRADED\r\nContent-Type: application/vnd.docker.raw-stream\r\nConnection: Upgrade\r\nUpgrade: tcp\r\n\r\n")
  1060. } else {
  1061. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  1062. }
  1063. if !job.GetenvBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  1064. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  1065. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  1066. } else {
  1067. errStream = outStream
  1068. }
  1069. job.Stdin.Add(inStream)
  1070. job.Stdout.Add(outStream)
  1071. job.Stderr.Set(errStream)
  1072. errOut = outStream
  1073. }
  1074. // Now run the user process in container.
  1075. job.SetCloseIO(false)
  1076. if err := job.Run(); err != nil {
  1077. fmt.Fprintf(errOut, "Error starting exec command in container %s: %s\n", name, err)
  1078. return err
  1079. }
  1080. w.WriteHeader(http.StatusNoContent)
  1081. return nil
  1082. }
  1083. func postContainerExecResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1084. if err := parseForm(r); err != nil {
  1085. return err
  1086. }
  1087. if vars == nil {
  1088. return fmt.Errorf("Missing parameter")
  1089. }
  1090. if err := eng.Job("execResize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  1091. return err
  1092. }
  1093. return nil
  1094. }
  1095. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1096. w.WriteHeader(http.StatusOK)
  1097. return nil
  1098. }
  1099. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  1100. w.Header().Add("Access-Control-Allow-Origin", "*")
  1101. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept, X-Registry-Auth")
  1102. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  1103. }
  1104. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1105. _, err := w.Write([]byte{'O', 'K'})
  1106. return err
  1107. }
  1108. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  1109. return func(w http.ResponseWriter, r *http.Request) {
  1110. // log the request
  1111. log.Debugf("Calling %s %s", localMethod, localRoute)
  1112. if logging {
  1113. log.Infof("%s %s", r.Method, r.RequestURI)
  1114. }
  1115. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  1116. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  1117. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  1118. log.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  1119. }
  1120. }
  1121. version := version.Version(mux.Vars(r)["version"])
  1122. if version == "" {
  1123. version = api.APIVERSION
  1124. }
  1125. if enableCors {
  1126. writeCorsHeaders(w, r)
  1127. }
  1128. if version.GreaterThan(api.APIVERSION) {
  1129. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  1130. return
  1131. }
  1132. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  1133. log.Errorf("Handler for %s %s returned error: %s", localMethod, localRoute, err)
  1134. httpError(w, err)
  1135. }
  1136. }
  1137. }
  1138. // Replicated from expvar.go as not public.
  1139. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  1140. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  1141. fmt.Fprintf(w, "{\n")
  1142. first := true
  1143. expvar.Do(func(kv expvar.KeyValue) {
  1144. if !first {
  1145. fmt.Fprintf(w, ",\n")
  1146. }
  1147. first = false
  1148. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  1149. })
  1150. fmt.Fprintf(w, "\n}\n")
  1151. }
  1152. func AttachProfiler(router *mux.Router) {
  1153. router.HandleFunc("/debug/vars", expvarHandler)
  1154. router.HandleFunc("/debug/pprof/", pprof.Index)
  1155. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  1156. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  1157. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  1158. router.HandleFunc("/debug/pprof/block", pprof.Handler("block").ServeHTTP)
  1159. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  1160. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  1161. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  1162. }
  1163. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) *mux.Router {
  1164. r := mux.NewRouter()
  1165. if os.Getenv("DEBUG") != "" {
  1166. AttachProfiler(r)
  1167. }
  1168. m := map[string]map[string]HttpApiFunc{
  1169. "GET": {
  1170. "/_ping": ping,
  1171. "/events": getEvents,
  1172. "/info": getInfo,
  1173. "/version": getVersion,
  1174. "/images/json": getImagesJSON,
  1175. "/images/viz": getImagesViz,
  1176. "/images/search": getImagesSearch,
  1177. "/images/get": getImagesGet,
  1178. "/images/{name:.*}/manifest": getImageManifest,
  1179. "/images/{name:.*}/get": getImagesGet,
  1180. "/images/{name:.*}/history": getImagesHistory,
  1181. "/images/{name:.*}/json": getImagesByName,
  1182. "/containers/ps": getContainersJSON,
  1183. "/containers/json": getContainersJSON,
  1184. "/containers/{name:.*}/export": getContainersExport,
  1185. "/containers/{name:.*}/changes": getContainersChanges,
  1186. "/containers/{name:.*}/json": getContainersByName,
  1187. "/containers/{name:.*}/top": getContainersTop,
  1188. "/containers/{name:.*}/logs": getContainersLogs,
  1189. "/containers/{name:.*}/stats": getContainersStats,
  1190. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  1191. "/exec/{id:.*}/json": getExecByID,
  1192. },
  1193. "POST": {
  1194. "/auth": postAuth,
  1195. "/commit": postCommit,
  1196. "/build": postBuild,
  1197. "/images/create": postImagesCreate,
  1198. "/images/load": postImagesLoad,
  1199. "/images/{name:.*}/push": postImagesPush,
  1200. "/images/{name:.*}/tag": postImagesTag,
  1201. "/containers/create": postContainersCreate,
  1202. "/containers/{name:.*}/kill": postContainersKill,
  1203. "/containers/{name:.*}/pause": postContainersPause,
  1204. "/containers/{name:.*}/unpause": postContainersUnpause,
  1205. "/containers/{name:.*}/restart": postContainersRestart,
  1206. "/containers/{name:.*}/start": postContainersStart,
  1207. "/containers/{name:.*}/stop": postContainersStop,
  1208. "/containers/{name:.*}/wait": postContainersWait,
  1209. "/containers/{name:.*}/resize": postContainersResize,
  1210. "/containers/{name:.*}/attach": postContainersAttach,
  1211. "/containers/{name:.*}/copy": postContainersCopy,
  1212. "/containers/{name:.*}/exec": postContainerExecCreate,
  1213. "/exec/{name:.*}/start": postContainerExecStart,
  1214. "/exec/{name:.*}/resize": postContainerExecResize,
  1215. "/containers/{name:.*}/rename": postContainerRename,
  1216. },
  1217. "DELETE": {
  1218. "/containers/{name:.*}": deleteContainers,
  1219. "/images/{name:.*}": deleteImages,
  1220. },
  1221. "OPTIONS": {
  1222. "": optionsHandler,
  1223. },
  1224. }
  1225. for method, routes := range m {
  1226. for route, fct := range routes {
  1227. log.Debugf("Registering %s, %s", method, route)
  1228. // NOTE: scope issue, make sure the variables are local and won't be changed
  1229. localRoute := route
  1230. localFct := fct
  1231. localMethod := method
  1232. // build the handler function
  1233. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1234. // add the new route
  1235. if localRoute == "" {
  1236. r.Methods(localMethod).HandlerFunc(f)
  1237. } else {
  1238. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1239. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1240. }
  1241. }
  1242. }
  1243. return r
  1244. }
  1245. // ServeRequest processes a single http request to the docker remote api.
  1246. // FIXME: refactor this to be part of Server and not require re-creating a new
  1247. // router each time. This requires first moving ListenAndServe into Server.
  1248. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) {
  1249. router := createRouter(eng, false, true, "")
  1250. // Insert APIVERSION into the request as a convenience
  1251. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1252. router.ServeHTTP(w, req)
  1253. }
  1254. // serveFd creates an http.Server and sets it up to serve given a socket activated
  1255. // argument.
  1256. func serveFd(addr string, job *engine.Job) error {
  1257. r := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1258. ls, e := systemd.ListenFD(addr)
  1259. if e != nil {
  1260. return e
  1261. }
  1262. chErrors := make(chan error, len(ls))
  1263. // We don't want to start serving on these sockets until the
  1264. // daemon is initialized and installed. Otherwise required handlers
  1265. // won't be ready.
  1266. <-activationLock
  1267. // Since ListenFD will return one or more sockets we have
  1268. // to create a go func to spawn off multiple serves
  1269. for i := range ls {
  1270. listener := ls[i]
  1271. go func() {
  1272. httpSrv := http.Server{Handler: r}
  1273. chErrors <- httpSrv.Serve(listener)
  1274. }()
  1275. }
  1276. for i := 0; i < len(ls); i++ {
  1277. err := <-chErrors
  1278. if err != nil {
  1279. return err
  1280. }
  1281. }
  1282. return nil
  1283. }
  1284. func lookupGidByName(nameOrGid string) (int, error) {
  1285. groupFile, err := user.GetGroupPath()
  1286. if err != nil {
  1287. return -1, err
  1288. }
  1289. groups, err := user.ParseGroupFileFilter(groupFile, func(g user.Group) bool {
  1290. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1291. })
  1292. if err != nil {
  1293. return -1, err
  1294. }
  1295. if groups != nil && len(groups) > 0 {
  1296. return groups[0].Gid, nil
  1297. }
  1298. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1299. }
  1300. func setupTls(cert, key, ca string, l net.Listener) (net.Listener, error) {
  1301. tlsCert, err := tls.LoadX509KeyPair(cert, key)
  1302. if err != nil {
  1303. return nil, fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1304. cert, key, err)
  1305. }
  1306. tlsConfig := &tls.Config{
  1307. NextProtos: []string{"http/1.1"},
  1308. Certificates: []tls.Certificate{tlsCert},
  1309. // Avoid fallback on insecure SSL protocols
  1310. MinVersion: tls.VersionTLS10,
  1311. }
  1312. if ca != "" {
  1313. certPool := x509.NewCertPool()
  1314. file, err := ioutil.ReadFile(ca)
  1315. if err != nil {
  1316. return nil, fmt.Errorf("Couldn't read CA certificate: %s", err)
  1317. }
  1318. certPool.AppendCertsFromPEM(file)
  1319. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1320. tlsConfig.ClientCAs = certPool
  1321. }
  1322. return tls.NewListener(l, tlsConfig), nil
  1323. }
  1324. func newListener(proto, addr string, bufferRequests bool) (net.Listener, error) {
  1325. if bufferRequests {
  1326. return listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1327. }
  1328. return net.Listen(proto, addr)
  1329. }
  1330. func changeGroup(addr string, nameOrGid string) error {
  1331. gid, err := lookupGidByName(nameOrGid)
  1332. if err != nil {
  1333. return err
  1334. }
  1335. log.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1336. return os.Chown(addr, 0, gid)
  1337. }
  1338. func setSocketGroup(addr, group string) error {
  1339. if group == "" {
  1340. return nil
  1341. }
  1342. if err := changeGroup(addr, group); err != nil {
  1343. if group != "docker" {
  1344. return err
  1345. }
  1346. log.Debugf("Warning: could not chgrp %s to docker: %v", addr, err)
  1347. }
  1348. return nil
  1349. }
  1350. func setupUnixHttp(addr string, job *engine.Job) (*HttpServer, error) {
  1351. r := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1352. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1353. return nil, err
  1354. }
  1355. mask := syscall.Umask(0777)
  1356. defer syscall.Umask(mask)
  1357. l, err := newListener("unix", addr, job.GetenvBool("BufferRequests"))
  1358. if err != nil {
  1359. return nil, err
  1360. }
  1361. if err := setSocketGroup(addr, job.Getenv("SocketGroup")); err != nil {
  1362. return nil, err
  1363. }
  1364. if err := os.Chmod(addr, 0660); err != nil {
  1365. return nil, err
  1366. }
  1367. return &HttpServer{&http.Server{Addr: addr, Handler: r}, l}, nil
  1368. }
  1369. func allocateDaemonPort(addr string) error {
  1370. host, port, err := net.SplitHostPort(addr)
  1371. if err != nil {
  1372. return err
  1373. }
  1374. intPort, err := strconv.Atoi(port)
  1375. if err != nil {
  1376. return err
  1377. }
  1378. var hostIPs []net.IP
  1379. if parsedIP := net.ParseIP(host); parsedIP != nil {
  1380. hostIPs = append(hostIPs, parsedIP)
  1381. } else if hostIPs, err = net.LookupIP(host); err != nil {
  1382. return fmt.Errorf("failed to lookup %s address in host specification", host)
  1383. }
  1384. for _, hostIP := range hostIPs {
  1385. if _, err := portallocator.RequestPort(hostIP, "tcp", intPort); err != nil {
  1386. return fmt.Errorf("failed to allocate daemon listening port %d (err: %v)", intPort, err)
  1387. }
  1388. }
  1389. return nil
  1390. }
  1391. func setupTcpHttp(addr string, job *engine.Job) (*HttpServer, error) {
  1392. if !strings.HasPrefix(addr, "127.0.0.1") && !job.GetenvBool("TlsVerify") {
  1393. log.Infof("/!\\ DON'T BIND ON ANOTHER IP ADDRESS THAN 127.0.0.1 IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1394. }
  1395. r := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1396. l, err := newListener("tcp", addr, job.GetenvBool("BufferRequests"))
  1397. if err != nil {
  1398. return nil, err
  1399. }
  1400. if err := allocateDaemonPort(addr); err != nil {
  1401. return nil, err
  1402. }
  1403. if job.GetenvBool("Tls") || job.GetenvBool("TlsVerify") {
  1404. var tlsCa string
  1405. if job.GetenvBool("TlsVerify") {
  1406. tlsCa = job.Getenv("TlsCa")
  1407. }
  1408. l, err = setupTls(job.Getenv("TlsCert"), job.Getenv("TlsKey"), tlsCa, l)
  1409. if err != nil {
  1410. return nil, err
  1411. }
  1412. }
  1413. return &HttpServer{&http.Server{Addr: addr, Handler: r}, l}, nil
  1414. }
  1415. // NewServer sets up the required Server and does protocol specific checking.
  1416. func NewServer(proto, addr string, job *engine.Job) (Server, error) {
  1417. // Basic error and sanity checking
  1418. switch proto {
  1419. case "fd":
  1420. return nil, serveFd(addr, job)
  1421. case "tcp":
  1422. return setupTcpHttp(addr, job)
  1423. case "unix":
  1424. return setupUnixHttp(addr, job)
  1425. default:
  1426. return nil, fmt.Errorf("Invalid protocol format.")
  1427. }
  1428. }
  1429. type Server interface {
  1430. Serve() error
  1431. Close() error
  1432. }
  1433. // ServeApi loops through all of the protocols sent in to docker and spawns
  1434. // off a go routine to setup a serving http.Server for each.
  1435. func ServeApi(job *engine.Job) engine.Status {
  1436. if len(job.Args) == 0 {
  1437. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1438. }
  1439. var (
  1440. protoAddrs = job.Args
  1441. chErrors = make(chan error, len(protoAddrs))
  1442. )
  1443. activationLock = make(chan struct{})
  1444. for _, protoAddr := range protoAddrs {
  1445. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1446. if len(protoAddrParts) != 2 {
  1447. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1448. }
  1449. go func() {
  1450. log.Infof("Listening for HTTP on %s (%s)", protoAddrParts[0], protoAddrParts[1])
  1451. srv, err := NewServer(protoAddrParts[0], protoAddrParts[1], job)
  1452. if err != nil {
  1453. chErrors <- err
  1454. return
  1455. }
  1456. chErrors <- srv.Serve()
  1457. }()
  1458. }
  1459. for i := 0; i < len(protoAddrs); i++ {
  1460. err := <-chErrors
  1461. if err != nil {
  1462. return job.Error(err)
  1463. }
  1464. }
  1465. return engine.StatusOK
  1466. }
  1467. func AcceptConnections(job *engine.Job) engine.Status {
  1468. // Tell the init daemon we are accepting requests
  1469. go systemd.SdNotify("READY=1")
  1470. // close the lock so the listeners start accepting connections
  1471. if activationLock != nil {
  1472. close(activationLock)
  1473. }
  1474. return engine.StatusOK
  1475. }