image_import.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392
  1. package containerd
  2. import (
  3. "bufio"
  4. "bytes"
  5. "context"
  6. "encoding/json"
  7. "fmt"
  8. "io"
  9. "time"
  10. "github.com/containerd/containerd/content"
  11. cerrdefs "github.com/containerd/containerd/errdefs"
  12. "github.com/containerd/containerd/images"
  13. "github.com/containerd/containerd/platforms"
  14. "github.com/containerd/log"
  15. "github.com/distribution/reference"
  16. "github.com/docker/docker/api/types/container"
  17. "github.com/docker/docker/api/types/events"
  18. "github.com/docker/docker/builder/dockerfile"
  19. "github.com/docker/docker/errdefs"
  20. "github.com/docker/docker/image"
  21. imagespec "github.com/docker/docker/image/spec/specs-go/v1"
  22. "github.com/docker/docker/internal/compatcontext"
  23. "github.com/docker/docker/pkg/archive"
  24. "github.com/docker/docker/pkg/pools"
  25. "github.com/google/uuid"
  26. "github.com/opencontainers/go-digest"
  27. "github.com/opencontainers/image-spec/specs-go"
  28. ocispec "github.com/opencontainers/image-spec/specs-go/v1"
  29. "github.com/pkg/errors"
  30. )
  31. // ImportImage imports an image, getting the archived layer data from layerReader.
  32. // Layer archive is imported as-is if the compression is gzip or zstd.
  33. // Uncompressed, xz and bzip2 archives are recompressed into gzip.
  34. // The image is tagged with the given reference.
  35. // If the platform is nil, the default host platform is used.
  36. // The message is used as the history comment.
  37. // Image configuration is derived from the dockerfile instructions in changes.
  38. func (i *ImageService) ImportImage(ctx context.Context, ref reference.Named, platform *ocispec.Platform, msg string, layerReader io.Reader, changes []string) (image.ID, error) {
  39. refString := ""
  40. if ref != nil {
  41. refString = ref.String()
  42. }
  43. logger := log.G(ctx).WithField("ref", refString)
  44. ctx, release, err := i.client.WithLease(ctx)
  45. if err != nil {
  46. return "", errdefs.System(err)
  47. }
  48. defer func() {
  49. if err := release(compatcontext.WithoutCancel(ctx)); err != nil {
  50. logger.WithError(err).Warn("failed to release lease created for import")
  51. }
  52. }()
  53. if platform == nil {
  54. def := platforms.DefaultSpec()
  55. platform = &def
  56. }
  57. imageConfig, err := dockerfile.BuildFromConfig(ctx, &container.Config{}, changes, platform.OS)
  58. if err != nil {
  59. logger.WithError(err).Debug("failed to process changes")
  60. return "", errdefs.InvalidParameter(err)
  61. }
  62. cs := i.client.ContentStore()
  63. compressedDigest, uncompressedDigest, mt, err := saveArchive(ctx, cs, layerReader)
  64. if err != nil {
  65. logger.WithError(err).Debug("failed to write layer blob")
  66. return "", err
  67. }
  68. logger = logger.WithFields(log.Fields{
  69. "compressedDigest": compressedDigest,
  70. "uncompressedDigest": uncompressedDigest,
  71. })
  72. size, err := fillUncompressedLabel(ctx, cs, compressedDigest, uncompressedDigest)
  73. if err != nil {
  74. logger.WithError(err).Debug("failed to set uncompressed label on the compressed blob")
  75. return "", err
  76. }
  77. compressedRootfsDesc := ocispec.Descriptor{
  78. MediaType: mt,
  79. Digest: compressedDigest,
  80. Size: size,
  81. }
  82. dockerCfg := containerConfigToDockerOCIImageConfig(imageConfig)
  83. createdAt := time.Now()
  84. config := imagespec.DockerOCIImage{
  85. Image: ocispec.Image{
  86. Platform: *platform,
  87. Created: &createdAt,
  88. Author: "",
  89. RootFS: ocispec.RootFS{
  90. Type: "layers",
  91. DiffIDs: []digest.Digest{uncompressedDigest},
  92. },
  93. History: []ocispec.History{
  94. {
  95. Created: &createdAt,
  96. CreatedBy: "",
  97. Author: "",
  98. Comment: msg,
  99. EmptyLayer: false,
  100. },
  101. },
  102. },
  103. Config: dockerCfg,
  104. }
  105. configDesc, err := storeJson(ctx, cs, ocispec.MediaTypeImageConfig, config, nil)
  106. if err != nil {
  107. return "", err
  108. }
  109. manifest := ocispec.Manifest{
  110. MediaType: ocispec.MediaTypeImageManifest,
  111. Versioned: specs.Versioned{
  112. SchemaVersion: 2,
  113. },
  114. Config: configDesc,
  115. Layers: []ocispec.Descriptor{
  116. compressedRootfsDesc,
  117. },
  118. }
  119. manifestDesc, err := storeJson(ctx, cs, ocispec.MediaTypeImageManifest, manifest, map[string]string{
  120. "containerd.io/gc.ref.content.config": configDesc.Digest.String(),
  121. "containerd.io/gc.ref.content.l.0": compressedDigest.String(),
  122. })
  123. if err != nil {
  124. return "", err
  125. }
  126. id := image.ID(manifestDesc.Digest.String())
  127. img := images.Image{
  128. Name: refString,
  129. Target: manifestDesc,
  130. CreatedAt: createdAt,
  131. }
  132. if img.Name == "" {
  133. img.Name = danglingImageName(manifestDesc.Digest)
  134. }
  135. err = i.saveImage(ctx, img)
  136. if err != nil {
  137. logger.WithError(err).Debug("failed to save image")
  138. return "", err
  139. }
  140. err = i.unpackImage(ctx, i.StorageDriver(), img, manifestDesc)
  141. if err != nil {
  142. logger.WithError(err).Debug("failed to unpack image")
  143. } else {
  144. i.LogImageEvent(id.String(), id.String(), events.ActionImport)
  145. }
  146. return id, err
  147. }
  148. // saveArchive saves the archive from bufRd to the content store, compressing it if necessary.
  149. // Returns compressed blob digest, digest of the uncompressed data and media type of the stored blob.
  150. func saveArchive(ctx context.Context, cs content.Store, layerReader io.Reader) (digest.Digest, digest.Digest, string, error) {
  151. // Wrap the reader in buffered reader to allow peeks.
  152. p := pools.BufioReader32KPool
  153. bufRd := p.Get(layerReader)
  154. defer p.Put(bufRd)
  155. compression, err := detectCompression(bufRd)
  156. if err != nil {
  157. return "", "", "", err
  158. }
  159. var uncompressedReader io.Reader = bufRd
  160. switch compression {
  161. case archive.Gzip, archive.Zstd:
  162. // If the input is already a compressed layer, just save it as is.
  163. mediaType := ocispec.MediaTypeImageLayerGzip
  164. if compression == archive.Zstd {
  165. mediaType = ocispec.MediaTypeImageLayerZstd
  166. }
  167. compressedDigest, uncompressedDigest, err := writeCompressedBlob(ctx, cs, mediaType, bufRd)
  168. if err != nil {
  169. return "", "", "", err
  170. }
  171. return compressedDigest, uncompressedDigest, mediaType, nil
  172. case archive.Bzip2, archive.Xz:
  173. r, err := archive.DecompressStream(bufRd)
  174. if err != nil {
  175. return "", "", "", errdefs.InvalidParameter(err)
  176. }
  177. defer r.Close()
  178. uncompressedReader = r
  179. fallthrough
  180. case archive.Uncompressed:
  181. mediaType := ocispec.MediaTypeImageLayerGzip
  182. compression := archive.Gzip
  183. compressedDigest, uncompressedDigest, err := compressAndWriteBlob(ctx, cs, compression, mediaType, uncompressedReader)
  184. if err != nil {
  185. return "", "", "", err
  186. }
  187. return compressedDigest, uncompressedDigest, mediaType, nil
  188. }
  189. return "", "", "", errdefs.InvalidParameter(errors.New("unsupported archive compression"))
  190. }
  191. // writeCompressedBlob writes the blob and simultaneously computes the digest of the uncompressed data.
  192. func writeCompressedBlob(ctx context.Context, cs content.Store, mediaType string, bufRd *bufio.Reader) (digest.Digest, digest.Digest, error) {
  193. pr, pw := io.Pipe()
  194. defer pw.Close()
  195. defer pr.Close()
  196. c := make(chan digest.Digest)
  197. // Start copying the blob to the content store from the pipe and tee it to the pipe.
  198. go func() {
  199. compressedDigest, err := writeBlobAndReturnDigest(ctx, cs, mediaType, io.TeeReader(bufRd, pw))
  200. pw.CloseWithError(err)
  201. c <- compressedDigest
  202. }()
  203. digester := digest.Canonical.Digester()
  204. // Decompress the piped blob.
  205. decompressedStream, err := archive.DecompressStream(pr)
  206. if err == nil {
  207. // Feed the digester with decompressed data.
  208. _, err = io.Copy(digester.Hash(), decompressedStream)
  209. decompressedStream.Close()
  210. }
  211. pr.CloseWithError(err)
  212. compressedDigest := <-c
  213. if err != nil {
  214. if errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) {
  215. return "", "", errdefs.Cancelled(err)
  216. }
  217. return "", "", errdefs.System(err)
  218. }
  219. uncompressedDigest := digester.Digest()
  220. return compressedDigest, uncompressedDigest, nil
  221. }
  222. // compressAndWriteBlob compresses the uncompressedReader and stores it in the content store.
  223. func compressAndWriteBlob(ctx context.Context, cs content.Store, compression archive.Compression, mediaType string, uncompressedLayerReader io.Reader) (digest.Digest, digest.Digest, error) {
  224. pr, pw := io.Pipe()
  225. defer pr.Close()
  226. defer pw.Close()
  227. compressor, err := archive.CompressStream(pw, compression)
  228. if err != nil {
  229. return "", "", errdefs.InvalidParameter(err)
  230. }
  231. writeChan := make(chan digest.Digest)
  232. // Start copying the blob to the content store from the pipe.
  233. go func() {
  234. dgst, err := writeBlobAndReturnDigest(ctx, cs, mediaType, pr)
  235. pr.CloseWithError(err)
  236. writeChan <- dgst
  237. }()
  238. // Copy archive to the pipe and tee it to a digester.
  239. // This will feed the pipe the above goroutine is reading from.
  240. uncompressedDigester := digest.Canonical.Digester()
  241. readFromInputAndDigest := io.TeeReader(uncompressedLayerReader, uncompressedDigester.Hash())
  242. _, err = io.Copy(compressor, readFromInputAndDigest)
  243. compressor.Close()
  244. pw.CloseWithError(err)
  245. compressedDigest := <-writeChan
  246. if err != nil {
  247. if errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) {
  248. return "", "", errdefs.Cancelled(err)
  249. }
  250. return "", "", errdefs.System(err)
  251. }
  252. return compressedDigest, uncompressedDigester.Digest(), err
  253. }
  254. // writeBlobAndReturnDigest writes a blob to the content store and returns the digest.
  255. func writeBlobAndReturnDigest(ctx context.Context, cs content.Store, mt string, reader io.Reader) (digest.Digest, error) {
  256. digester := digest.Canonical.Digester()
  257. if err := content.WriteBlob(ctx, cs, uuid.New().String(), io.TeeReader(reader, digester.Hash()), ocispec.Descriptor{MediaType: mt}); err != nil {
  258. return "", errdefs.System(err)
  259. }
  260. return digester.Digest(), nil
  261. }
  262. // saveImage creates an image in the ImageService or updates it if it exists.
  263. func (i *ImageService) saveImage(ctx context.Context, img images.Image) error {
  264. is := i.client.ImageService()
  265. if _, err := is.Update(ctx, img); err != nil {
  266. if cerrdefs.IsNotFound(err) {
  267. if _, err := is.Create(ctx, img); err != nil {
  268. return errdefs.Unknown(err)
  269. }
  270. } else {
  271. return errdefs.Unknown(err)
  272. }
  273. }
  274. return nil
  275. }
  276. // unpackImage unpacks the platform-specific manifest of a image into the snapshotter.
  277. func (i *ImageService) unpackImage(ctx context.Context, snapshotter string, img images.Image, manifestDesc ocispec.Descriptor) error {
  278. c8dImg, err := i.NewImageManifest(ctx, img, manifestDesc)
  279. if err != nil {
  280. return err
  281. }
  282. if err := c8dImg.Unpack(ctx, snapshotter); err != nil {
  283. if !cerrdefs.IsAlreadyExists(err) {
  284. return errdefs.System(fmt.Errorf("failed to unpack image: %w", err))
  285. }
  286. }
  287. return nil
  288. }
  289. // detectCompression dectects the reader compression type.
  290. func detectCompression(bufRd *bufio.Reader) (archive.Compression, error) {
  291. bs, err := bufRd.Peek(10)
  292. if err != nil && err != io.EOF {
  293. // Note: we'll ignore any io.EOF error because there are some odd
  294. // cases where the layer.tar file will be empty (zero bytes) and
  295. // that results in an io.EOF from the Peek() call. So, in those
  296. // cases we'll just treat it as a non-compressed stream and
  297. // that means just create an empty layer.
  298. // See Issue 18170
  299. return archive.Uncompressed, errdefs.Unknown(err)
  300. }
  301. return archive.DetectCompression(bs), nil
  302. }
  303. // fillUncompressedLabel sets the uncompressed digest label on the compressed blob metadata
  304. // and returns the compressed blob size.
  305. func fillUncompressedLabel(ctx context.Context, cs content.Store, compressedDigest digest.Digest, uncompressedDigest digest.Digest) (int64, error) {
  306. info, err := cs.Info(ctx, compressedDigest)
  307. if err != nil {
  308. return 0, errdefs.Unknown(errors.Wrapf(err, "couldn't open previously written blob"))
  309. }
  310. size := info.Size
  311. info.Labels = map[string]string{"containerd.io/uncompressed": uncompressedDigest.String()}
  312. _, err = cs.Update(ctx, info, "labels.*")
  313. if err != nil {
  314. return 0, errdefs.System(errors.Wrapf(err, "couldn't set uncompressed label"))
  315. }
  316. return size, nil
  317. }
  318. // storeJson marshals the provided object as json and stores it.
  319. func storeJson(ctx context.Context, cs content.Ingester, mt string, obj interface{}, labels map[string]string) (ocispec.Descriptor, error) {
  320. configData, err := json.Marshal(obj)
  321. if err != nil {
  322. return ocispec.Descriptor{}, errdefs.InvalidParameter(err)
  323. }
  324. configDigest := digest.FromBytes(configData)
  325. if err != nil {
  326. return ocispec.Descriptor{}, errdefs.InvalidParameter(err)
  327. }
  328. desc := ocispec.Descriptor{
  329. MediaType: mt,
  330. Digest: configDigest,
  331. Size: int64(len(configData)),
  332. }
  333. var opts []content.Opt
  334. if labels != nil {
  335. opts = append(opts, content.WithLabels(labels))
  336. }
  337. err = content.WriteBlob(ctx, cs, configDigest.String(), bytes.NewReader(configData), desc, opts...)
  338. if err != nil {
  339. return ocispec.Descriptor{}, errdefs.System(err)
  340. }
  341. return desc, nil
  342. }