image_list.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567
  1. package containerd
  2. import (
  3. "context"
  4. "encoding/json"
  5. "sort"
  6. "strings"
  7. "time"
  8. "github.com/containerd/containerd/content"
  9. cerrdefs "github.com/containerd/containerd/errdefs"
  10. "github.com/containerd/containerd/images"
  11. "github.com/containerd/containerd/labels"
  12. "github.com/containerd/containerd/snapshots"
  13. "github.com/containerd/log"
  14. "github.com/distribution/reference"
  15. "github.com/docker/docker/api/types"
  16. "github.com/docker/docker/api/types/filters"
  17. imagetypes "github.com/docker/docker/api/types/image"
  18. timetypes "github.com/docker/docker/api/types/time"
  19. "github.com/docker/docker/container"
  20. "github.com/docker/docker/errdefs"
  21. "github.com/docker/docker/image"
  22. "github.com/opencontainers/go-digest"
  23. "github.com/opencontainers/image-spec/identity"
  24. ocispec "github.com/opencontainers/image-spec/specs-go/v1"
  25. "github.com/pkg/errors"
  26. )
  27. // Subset of ocispec.Image that only contains Labels
  28. type configLabels struct {
  29. // Created is the combined date and time at which the image was created, formatted as defined by RFC 3339, section 5.6.
  30. Created *time.Time `json:"created,omitempty"`
  31. Config struct {
  32. Labels map[string]string `json:"Labels,omitempty"`
  33. } `json:"config,omitempty"`
  34. }
  35. var acceptedImageFilterTags = map[string]bool{
  36. "dangling": true,
  37. "label": true,
  38. "label!": true,
  39. "before": true,
  40. "since": true,
  41. "reference": true,
  42. "until": true,
  43. }
  44. // byCreated is a temporary type used to sort a list of images by creation
  45. // time.
  46. type byCreated []*imagetypes.Summary
  47. func (r byCreated) Len() int { return len(r) }
  48. func (r byCreated) Swap(i, j int) { r[i], r[j] = r[j], r[i] }
  49. func (r byCreated) Less(i, j int) bool { return r[i].Created < r[j].Created }
  50. // Images returns a filtered list of images.
  51. //
  52. // TODO(thaJeztah): implement opts.ContainerCount (used for docker system df); see https://github.com/moby/moby/issues/43853
  53. // TODO(thaJeztah): verify behavior of `RepoDigests` and `RepoTags` for images without (untagged) or multiple tags; see https://github.com/moby/moby/issues/43861
  54. // TODO(thaJeztah): verify "Size" vs "VirtualSize" in images; see https://github.com/moby/moby/issues/43862
  55. func (i *ImageService) Images(ctx context.Context, opts types.ImageListOptions) ([]*imagetypes.Summary, error) {
  56. if err := opts.Filters.Validate(acceptedImageFilterTags); err != nil {
  57. return nil, err
  58. }
  59. filter, err := i.setupFilters(ctx, opts.Filters)
  60. if err != nil {
  61. return nil, err
  62. }
  63. imgs, err := i.client.ImageService().List(ctx)
  64. if err != nil {
  65. return nil, err
  66. }
  67. // TODO(thaJeztah): do we need to take multiple snapshotters into account? See https://github.com/moby/moby/issues/45273
  68. snapshotter := i.client.SnapshotService(i.snapshotter)
  69. sizeCache := make(map[digest.Digest]int64)
  70. snapshotSizeFn := func(d digest.Digest) (int64, error) {
  71. if s, ok := sizeCache[d]; ok {
  72. return s, nil
  73. }
  74. usage, err := snapshotter.Usage(ctx, d.String())
  75. if err != nil {
  76. return 0, err
  77. }
  78. sizeCache[d] = usage.Size
  79. return usage.Size, nil
  80. }
  81. var (
  82. allContainers []*container.Container
  83. summaries = make([]*imagetypes.Summary, 0, len(imgs))
  84. root []*[]digest.Digest
  85. layers map[digest.Digest]int
  86. )
  87. if opts.SharedSize {
  88. root = make([]*[]digest.Digest, 0, len(imgs))
  89. layers = make(map[digest.Digest]int)
  90. }
  91. contentStore := i.client.ContentStore()
  92. uniqueImages := map[digest.Digest]images.Image{}
  93. tagsByDigest := map[digest.Digest][]string{}
  94. intermediateImages := map[digest.Digest]struct{}{}
  95. hideIntermediate := !opts.All
  96. if hideIntermediate {
  97. for _, img := range imgs {
  98. parent, ok := img.Labels[imageLabelClassicBuilderParent]
  99. if ok && parent != "" {
  100. dgst, err := digest.Parse(parent)
  101. if err != nil {
  102. log.G(ctx).WithFields(log.Fields{
  103. "error": err,
  104. "value": parent,
  105. }).Warnf("invalid %s label value", imageLabelClassicBuilderParent)
  106. }
  107. intermediateImages[dgst] = struct{}{}
  108. }
  109. }
  110. }
  111. for _, img := range imgs {
  112. isDangling := isDanglingImage(img)
  113. if hideIntermediate && isDangling {
  114. if _, ok := intermediateImages[img.Target.Digest]; ok {
  115. continue
  116. }
  117. }
  118. if !filter(img) {
  119. continue
  120. }
  121. dgst := img.Target.Digest
  122. uniqueImages[dgst] = img
  123. if isDangling {
  124. continue
  125. }
  126. ref, err := reference.ParseNormalizedNamed(img.Name)
  127. if err != nil {
  128. continue
  129. }
  130. tagsByDigest[dgst] = append(tagsByDigest[dgst], reference.FamiliarString(ref))
  131. }
  132. if opts.ContainerCount {
  133. allContainers = i.containers.List()
  134. }
  135. for _, img := range uniqueImages {
  136. err := i.walkImageManifests(ctx, img, func(img *ImageManifest) error {
  137. if isPseudo, err := img.IsPseudoImage(ctx); isPseudo || err != nil {
  138. return err
  139. }
  140. available, err := img.CheckContentAvailable(ctx)
  141. if err != nil {
  142. log.G(ctx).WithFields(log.Fields{
  143. "error": err,
  144. "manifest": img.Target(),
  145. "image": img.Name(),
  146. }).Warn("checking availability of platform specific manifest failed")
  147. return nil
  148. }
  149. if !available {
  150. return nil
  151. }
  152. image, chainIDs, err := i.singlePlatformImage(ctx, contentStore, tagsByDigest[img.RealTarget.Digest], img, opts, allContainers)
  153. if err != nil {
  154. return err
  155. }
  156. summaries = append(summaries, image)
  157. if opts.SharedSize {
  158. root = append(root, &chainIDs)
  159. for _, id := range chainIDs {
  160. layers[id] = layers[id] + 1
  161. }
  162. }
  163. return nil
  164. })
  165. if err != nil {
  166. return nil, err
  167. }
  168. }
  169. if opts.SharedSize {
  170. for n, chainIDs := range root {
  171. sharedSize, err := computeSharedSize(*chainIDs, layers, snapshotSizeFn)
  172. if err != nil {
  173. return nil, err
  174. }
  175. summaries[n].SharedSize = sharedSize
  176. }
  177. }
  178. sort.Sort(sort.Reverse(byCreated(summaries)))
  179. return summaries, nil
  180. }
  181. func (i *ImageService) singlePlatformImage(ctx context.Context, contentStore content.Store, repoTags []string, imageManifest *ImageManifest, opts types.ImageListOptions, allContainers []*container.Container) (*imagetypes.Summary, []digest.Digest, error) {
  182. diffIDs, err := imageManifest.RootFS(ctx)
  183. if err != nil {
  184. return nil, nil, errors.Wrapf(err, "failed to get rootfs of image %s", imageManifest.Name())
  185. }
  186. // TODO(thaJeztah): do we need to take multiple snapshotters into account? See https://github.com/moby/moby/issues/45273
  187. snapshotter := i.client.SnapshotService(i.snapshotter)
  188. imageSnapshotID := identity.ChainID(diffIDs).String()
  189. unpackedUsage, err := calculateSnapshotTotalUsage(ctx, snapshotter, imageSnapshotID)
  190. if err != nil {
  191. if !cerrdefs.IsNotFound(err) {
  192. log.G(ctx).WithError(err).WithFields(log.Fields{
  193. "image": imageManifest.Name(),
  194. "snapshotID": imageSnapshotID,
  195. }).Warn("failed to calculate unpacked size of image")
  196. }
  197. unpackedUsage = snapshots.Usage{Size: 0}
  198. }
  199. contentSize, err := imageManifest.Size(ctx)
  200. if err != nil {
  201. return nil, nil, err
  202. }
  203. // totalSize is the size of the image's packed layers and snapshots
  204. // (unpacked layers) combined.
  205. totalSize := contentSize + unpackedUsage.Size
  206. var repoDigests []string
  207. rawImg := imageManifest.Metadata()
  208. target := rawImg.Target.Digest
  209. logger := log.G(ctx).WithFields(log.Fields{
  210. "name": rawImg.Name,
  211. "digest": target,
  212. })
  213. ref, err := reference.ParseNamed(rawImg.Name)
  214. if err != nil {
  215. // If the image has unexpected name format (not a Named reference or a dangling image)
  216. // add the offending name to RepoTags but also log an error to make it clear to the
  217. // administrator that this is unexpected.
  218. // TODO: Reconsider when containerd is more strict on image names, see:
  219. // https://github.com/containerd/containerd/issues/7986
  220. if !isDanglingImage(rawImg) {
  221. logger.WithError(err).Error("failed to parse image name as reference")
  222. repoTags = append(repoTags, rawImg.Name)
  223. }
  224. } else {
  225. digested, err := reference.WithDigest(reference.TrimNamed(ref), target)
  226. if err != nil {
  227. logger.WithError(err).Error("failed to create digested reference")
  228. } else {
  229. repoDigests = append(repoDigests, reference.FamiliarString(digested))
  230. }
  231. }
  232. cfgDesc, err := imageManifest.Image.Config(ctx)
  233. if err != nil {
  234. return nil, nil, err
  235. }
  236. var cfg configLabels
  237. if err := readConfig(ctx, contentStore, cfgDesc, &cfg); err != nil {
  238. return nil, nil, err
  239. }
  240. summary := &imagetypes.Summary{
  241. ParentID: rawImg.Labels[imageLabelClassicBuilderParent],
  242. ID: target.String(),
  243. RepoDigests: repoDigests,
  244. RepoTags: repoTags,
  245. Size: totalSize,
  246. Labels: cfg.Config.Labels,
  247. // -1 indicates that the value has not been set (avoids ambiguity
  248. // between 0 (default) and "not set". We cannot use a pointer (nil)
  249. // for this, as the JSON representation uses "omitempty", which would
  250. // consider both "0" and "nil" to be "empty".
  251. SharedSize: -1,
  252. Containers: -1,
  253. }
  254. if cfg.Created != nil {
  255. summary.Created = cfg.Created.Unix()
  256. }
  257. if opts.ContainerCount {
  258. // Get container count
  259. var containers int64
  260. for _, c := range allContainers {
  261. if c.ImageID == image.ID(target.String()) {
  262. containers++
  263. }
  264. }
  265. summary.Containers = containers
  266. }
  267. return summary, identity.ChainIDs(diffIDs), nil
  268. }
  269. type imageFilterFunc func(image images.Image) bool
  270. // setupFilters constructs an imageFilterFunc from the given imageFilters.
  271. //
  272. // filterFunc is a function that checks whether given image matches the filters.
  273. // TODO(thaJeztah): reimplement filters using containerd filters if possible: see https://github.com/moby/moby/issues/43845
  274. func (i *ImageService) setupFilters(ctx context.Context, imageFilters filters.Args) (filterFunc imageFilterFunc, outErr error) {
  275. var fltrs []imageFilterFunc
  276. err := imageFilters.WalkValues("before", func(value string) error {
  277. img, err := i.GetImage(ctx, value, imagetypes.GetImageOpts{})
  278. if err != nil {
  279. return err
  280. }
  281. if img != nil && img.Created != nil {
  282. fltrs = append(fltrs, func(candidate images.Image) bool {
  283. cand, err := i.GetImage(ctx, candidate.Name, imagetypes.GetImageOpts{})
  284. if err != nil {
  285. return false
  286. }
  287. return cand.Created != nil && cand.Created.Before(*img.Created)
  288. })
  289. }
  290. return nil
  291. })
  292. if err != nil {
  293. return nil, err
  294. }
  295. err = imageFilters.WalkValues("since", func(value string) error {
  296. img, err := i.GetImage(ctx, value, imagetypes.GetImageOpts{})
  297. if err != nil {
  298. return err
  299. }
  300. if img != nil && img.Created != nil {
  301. fltrs = append(fltrs, func(candidate images.Image) bool {
  302. cand, err := i.GetImage(ctx, candidate.Name, imagetypes.GetImageOpts{})
  303. if err != nil {
  304. return false
  305. }
  306. return cand.Created != nil && cand.Created.After(*img.Created)
  307. })
  308. }
  309. return nil
  310. })
  311. if err != nil {
  312. return nil, err
  313. }
  314. err = imageFilters.WalkValues("until", func(value string) error {
  315. ts, err := timetypes.GetTimestamp(value, time.Now())
  316. if err != nil {
  317. return err
  318. }
  319. seconds, nanoseconds, err := timetypes.ParseTimestamps(ts, 0)
  320. if err != nil {
  321. return err
  322. }
  323. until := time.Unix(seconds, nanoseconds)
  324. fltrs = append(fltrs, func(image images.Image) bool {
  325. created := image.CreatedAt
  326. return created.Before(until)
  327. })
  328. return err
  329. })
  330. if err != nil {
  331. return nil, err
  332. }
  333. labelFn, err := setupLabelFilter(i.client.ContentStore(), imageFilters)
  334. if err != nil {
  335. return nil, err
  336. }
  337. if labelFn != nil {
  338. fltrs = append(fltrs, labelFn)
  339. }
  340. if imageFilters.Contains("dangling") {
  341. danglingValue, err := imageFilters.GetBoolOrDefault("dangling", false)
  342. if err != nil {
  343. return nil, err
  344. }
  345. fltrs = append(fltrs, func(image images.Image) bool {
  346. return danglingValue == isDanglingImage(image)
  347. })
  348. }
  349. if refs := imageFilters.Get("reference"); len(refs) != 0 {
  350. fltrs = append(fltrs, func(image images.Image) bool {
  351. ref, err := reference.ParseNormalizedNamed(image.Name)
  352. if err != nil {
  353. return false
  354. }
  355. for _, value := range refs {
  356. found, err := reference.FamiliarMatch(value, ref)
  357. if err != nil {
  358. return false
  359. }
  360. if found {
  361. return found
  362. }
  363. }
  364. return false
  365. })
  366. }
  367. return func(image images.Image) bool {
  368. for _, filter := range fltrs {
  369. if !filter(image) {
  370. return false
  371. }
  372. }
  373. return true
  374. }, nil
  375. }
  376. // setupLabelFilter parses filter args for "label" and "label!" and returns a
  377. // filter func which will check if any image config from the given image has
  378. // labels that match given predicates.
  379. func setupLabelFilter(store content.Store, fltrs filters.Args) (func(image images.Image) bool, error) {
  380. type labelCheck struct {
  381. key string
  382. value string
  383. onlyExists bool
  384. negate bool
  385. }
  386. var checks []labelCheck
  387. for _, fltrName := range []string{"label", "label!"} {
  388. for _, l := range fltrs.Get(fltrName) {
  389. k, v, found := strings.Cut(l, "=")
  390. err := labels.Validate(k, v)
  391. if err != nil {
  392. return nil, err
  393. }
  394. negate := strings.HasSuffix(fltrName, "!")
  395. // If filter value is key!=value then flip the above.
  396. if strings.HasSuffix(k, "!") {
  397. k = strings.TrimSuffix(k, "!")
  398. negate = !negate
  399. }
  400. checks = append(checks, labelCheck{
  401. key: k,
  402. value: v,
  403. onlyExists: !found,
  404. negate: negate,
  405. })
  406. }
  407. }
  408. return func(image images.Image) bool {
  409. ctx := context.TODO()
  410. // This is not an error, but a signal to Dispatch that it should stop
  411. // processing more content (otherwise it will run for all children).
  412. // It will be returned once a matching config is found.
  413. errFoundConfig := errors.New("success, found matching config")
  414. err := images.Dispatch(ctx, presentChildrenHandler(store, images.HandlerFunc(func(ctx context.Context, desc ocispec.Descriptor) (subdescs []ocispec.Descriptor, err error) {
  415. if !images.IsConfigType(desc.MediaType) {
  416. return nil, nil
  417. }
  418. var cfg configLabels
  419. if err := readConfig(ctx, store, desc, &cfg); err != nil {
  420. return nil, err
  421. }
  422. for _, check := range checks {
  423. value, exists := cfg.Config.Labels[check.key]
  424. if check.onlyExists {
  425. // label! given without value, check if doesn't exist
  426. if check.negate {
  427. // Label exists, config doesn't match
  428. if exists {
  429. return nil, nil
  430. }
  431. } else {
  432. // Label should exist
  433. if !exists {
  434. // Label doesn't exist, config doesn't match
  435. return nil, nil
  436. }
  437. }
  438. continue
  439. } else if !exists {
  440. // We are checking value and label doesn't exist.
  441. return nil, nil
  442. }
  443. valueEquals := value == check.value
  444. if valueEquals == check.negate {
  445. return nil, nil
  446. }
  447. }
  448. // This config matches the filter so we need to shop this image, stop dispatch.
  449. return nil, errFoundConfig
  450. })), nil, image.Target)
  451. if err == errFoundConfig {
  452. return true
  453. }
  454. if err != nil {
  455. log.G(ctx).WithFields(log.Fields{
  456. "error": err,
  457. "image": image.Name,
  458. "checks": checks,
  459. }).Error("failed to check image labels")
  460. }
  461. return false
  462. }, nil
  463. }
  464. func computeSharedSize(chainIDs []digest.Digest, layers map[digest.Digest]int, sizeFn func(d digest.Digest) (int64, error)) (int64, error) {
  465. var sharedSize int64
  466. for _, chainID := range chainIDs {
  467. if layers[chainID] == 1 {
  468. continue
  469. }
  470. size, err := sizeFn(chainID)
  471. if err != nil {
  472. return 0, err
  473. }
  474. sharedSize += size
  475. }
  476. return sharedSize, nil
  477. }
  478. // readConfig reads content pointed by the descriptor and unmarshals it into a specified output.
  479. func readConfig(ctx context.Context, store content.Provider, desc ocispec.Descriptor, out interface{}) error {
  480. data, err := content.ReadBlob(ctx, store, desc)
  481. if err != nil {
  482. err = errors.Wrapf(err, "failed to read config content")
  483. if cerrdefs.IsNotFound(err) {
  484. return errdefs.NotFound(err)
  485. }
  486. return err
  487. }
  488. err = json.Unmarshal(data, out)
  489. if err != nil {
  490. err = errors.Wrapf(err, "could not deserialize image config")
  491. if cerrdefs.IsNotFound(err) {
  492. return errdefs.NotFound(err)
  493. }
  494. return err
  495. }
  496. return nil
  497. }