server.go 46 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592
  1. package server
  2. import (
  3. "bufio"
  4. "bytes"
  5. "encoding/base64"
  6. "encoding/json"
  7. "expvar"
  8. "fmt"
  9. "io"
  10. "io/ioutil"
  11. "net"
  12. "net/http"
  13. "net/http/pprof"
  14. "os"
  15. "strconv"
  16. "strings"
  17. "syscall"
  18. "crypto/tls"
  19. "crypto/x509"
  20. "code.google.com/p/go.net/websocket"
  21. "github.com/docker/libcontainer/user"
  22. "github.com/gorilla/mux"
  23. log "github.com/Sirupsen/logrus"
  24. "github.com/docker/docker/api"
  25. "github.com/docker/docker/engine"
  26. "github.com/docker/docker/pkg/listenbuffer"
  27. "github.com/docker/docker/pkg/parsers"
  28. "github.com/docker/docker/pkg/stdcopy"
  29. "github.com/docker/docker/pkg/systemd"
  30. "github.com/docker/docker/pkg/version"
  31. "github.com/docker/docker/registry"
  32. "github.com/docker/docker/utils"
  33. )
  34. var (
  35. activationLock chan struct{}
  36. )
  37. type HttpServer struct {
  38. srv *http.Server
  39. l net.Listener
  40. }
  41. func (s *HttpServer) Serve() error {
  42. return s.srv.Serve(s.l)
  43. }
  44. func (s *HttpServer) Close() error {
  45. return s.l.Close()
  46. }
  47. type HttpApiFunc func(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error
  48. func hijackServer(w http.ResponseWriter) (io.ReadCloser, io.Writer, error) {
  49. conn, _, err := w.(http.Hijacker).Hijack()
  50. if err != nil {
  51. return nil, nil, err
  52. }
  53. // Flush the options to make sure the client sets the raw mode
  54. conn.Write([]byte{})
  55. return conn, conn, nil
  56. }
  57. func closeStreams(streams ...interface{}) {
  58. for _, stream := range streams {
  59. if tcpc, ok := stream.(interface {
  60. CloseWrite() error
  61. }); ok {
  62. tcpc.CloseWrite()
  63. } else if closer, ok := stream.(io.Closer); ok {
  64. closer.Close()
  65. }
  66. }
  67. }
  68. // Check to make sure request's Content-Type is application/json
  69. func checkForJson(r *http.Request) error {
  70. ct := r.Header.Get("Content-Type")
  71. // No Content-Type header is ok as long as there's no Body
  72. if ct == "" {
  73. if r.Body == nil || r.ContentLength == 0 {
  74. return nil
  75. }
  76. }
  77. // Otherwise it better be json
  78. if api.MatchesContentType(ct, "application/json") {
  79. return nil
  80. }
  81. return fmt.Errorf("Content-Type specified (%s) must be 'application/json'", ct)
  82. }
  83. //If we don't do this, POST method without Content-type (even with empty body) will fail
  84. func parseForm(r *http.Request) error {
  85. if r == nil {
  86. return nil
  87. }
  88. if err := r.ParseForm(); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  89. return err
  90. }
  91. return nil
  92. }
  93. func parseMultipartForm(r *http.Request) error {
  94. if err := r.ParseMultipartForm(4096); err != nil && !strings.HasPrefix(err.Error(), "mime:") {
  95. return err
  96. }
  97. return nil
  98. }
  99. func httpError(w http.ResponseWriter, err error) {
  100. statusCode := http.StatusInternalServerError
  101. // FIXME: this is brittle and should not be necessary.
  102. // If we need to differentiate between different possible error types, we should
  103. // create appropriate error types with clearly defined meaning.
  104. errStr := strings.ToLower(err.Error())
  105. if strings.Contains(errStr, "no such") {
  106. statusCode = http.StatusNotFound
  107. } else if strings.Contains(errStr, "bad parameter") {
  108. statusCode = http.StatusBadRequest
  109. } else if strings.Contains(errStr, "conflict") {
  110. statusCode = http.StatusConflict
  111. } else if strings.Contains(errStr, "impossible") {
  112. statusCode = http.StatusNotAcceptable
  113. } else if strings.Contains(errStr, "wrong login/password") {
  114. statusCode = http.StatusUnauthorized
  115. } else if strings.Contains(errStr, "hasn't been activated") {
  116. statusCode = http.StatusForbidden
  117. }
  118. if err != nil {
  119. log.Errorf("HTTP Error: statusCode=%d %s", statusCode, err.Error())
  120. http.Error(w, err.Error(), statusCode)
  121. }
  122. }
  123. func writeJSON(w http.ResponseWriter, code int, v engine.Env) error {
  124. w.Header().Set("Content-Type", "application/json")
  125. w.WriteHeader(code)
  126. return v.Encode(w)
  127. }
  128. func streamJSON(job *engine.Job, w http.ResponseWriter, flush bool) {
  129. w.Header().Set("Content-Type", "application/json")
  130. if flush {
  131. job.Stdout.Add(utils.NewWriteFlusher(w))
  132. } else {
  133. job.Stdout.Add(w)
  134. }
  135. }
  136. func getBoolParam(value string) (bool, error) {
  137. if value == "" {
  138. return false, nil
  139. }
  140. ret, err := strconv.ParseBool(value)
  141. if err != nil {
  142. return false, fmt.Errorf("Bad parameter")
  143. }
  144. return ret, nil
  145. }
  146. func postAuth(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  147. var (
  148. authConfig, err = ioutil.ReadAll(r.Body)
  149. job = eng.Job("auth")
  150. stdoutBuffer = bytes.NewBuffer(nil)
  151. )
  152. if err != nil {
  153. return err
  154. }
  155. job.Setenv("authConfig", string(authConfig))
  156. job.Stdout.Add(stdoutBuffer)
  157. if err = job.Run(); err != nil {
  158. return err
  159. }
  160. if status := engine.Tail(stdoutBuffer, 1); status != "" {
  161. var env engine.Env
  162. env.Set("Status", status)
  163. return writeJSON(w, http.StatusOK, env)
  164. }
  165. w.WriteHeader(http.StatusNoContent)
  166. return nil
  167. }
  168. func getVersion(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  169. w.Header().Set("Content-Type", "application/json")
  170. eng.ServeHTTP(w, r)
  171. return nil
  172. }
  173. func postContainersKill(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  174. if vars == nil {
  175. return fmt.Errorf("Missing parameter")
  176. }
  177. if err := parseForm(r); err != nil {
  178. return err
  179. }
  180. job := eng.Job("kill", vars["name"])
  181. if sig := r.Form.Get("signal"); sig != "" {
  182. job.Args = append(job.Args, sig)
  183. }
  184. if err := job.Run(); err != nil {
  185. return err
  186. }
  187. w.WriteHeader(http.StatusNoContent)
  188. return nil
  189. }
  190. func postContainersPause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  191. if vars == nil {
  192. return fmt.Errorf("Missing parameter")
  193. }
  194. if err := parseForm(r); err != nil {
  195. return err
  196. }
  197. job := eng.Job("pause", vars["name"])
  198. if err := job.Run(); err != nil {
  199. return err
  200. }
  201. w.WriteHeader(http.StatusNoContent)
  202. return nil
  203. }
  204. func postContainersUnpause(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  205. if vars == nil {
  206. return fmt.Errorf("Missing parameter")
  207. }
  208. if err := parseForm(r); err != nil {
  209. return err
  210. }
  211. job := eng.Job("unpause", vars["name"])
  212. if err := job.Run(); err != nil {
  213. return err
  214. }
  215. w.WriteHeader(http.StatusNoContent)
  216. return nil
  217. }
  218. func getContainersExport(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  219. if vars == nil {
  220. return fmt.Errorf("Missing parameter")
  221. }
  222. job := eng.Job("export", vars["name"])
  223. job.Stdout.Add(w)
  224. if err := job.Run(); err != nil {
  225. return err
  226. }
  227. return nil
  228. }
  229. func getImagesJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  230. if err := parseForm(r); err != nil {
  231. return err
  232. }
  233. var (
  234. err error
  235. outs *engine.Table
  236. job = eng.Job("images")
  237. )
  238. job.Setenv("filters", r.Form.Get("filters"))
  239. // FIXME this parameter could just be a match filter
  240. job.Setenv("filter", r.Form.Get("filter"))
  241. job.Setenv("all", r.Form.Get("all"))
  242. if version.GreaterThanOrEqualTo("1.7") {
  243. streamJSON(job, w, false)
  244. } else if outs, err = job.Stdout.AddListTable(); err != nil {
  245. return err
  246. }
  247. if err := job.Run(); err != nil {
  248. return err
  249. }
  250. if version.LessThan("1.7") && outs != nil { // Convert to legacy format
  251. outsLegacy := engine.NewTable("Created", 0)
  252. for _, out := range outs.Data {
  253. for _, repoTag := range out.GetList("RepoTags") {
  254. repo, tag := parsers.ParseRepositoryTag(repoTag)
  255. outLegacy := &engine.Env{}
  256. outLegacy.Set("Repository", repo)
  257. outLegacy.SetJson("Tag", tag)
  258. outLegacy.Set("Id", out.Get("Id"))
  259. outLegacy.SetInt64("Created", out.GetInt64("Created"))
  260. outLegacy.SetInt64("Size", out.GetInt64("Size"))
  261. outLegacy.SetInt64("VirtualSize", out.GetInt64("VirtualSize"))
  262. outsLegacy.Add(outLegacy)
  263. }
  264. }
  265. w.Header().Set("Content-Type", "application/json")
  266. if _, err := outsLegacy.WriteListTo(w); err != nil {
  267. return err
  268. }
  269. }
  270. return nil
  271. }
  272. func getImagesViz(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  273. if version.GreaterThan("1.6") {
  274. w.WriteHeader(http.StatusNotFound)
  275. return fmt.Errorf("This is now implemented in the client.")
  276. }
  277. eng.ServeHTTP(w, r)
  278. return nil
  279. }
  280. func getInfo(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  281. w.Header().Set("Content-Type", "application/json")
  282. eng.ServeHTTP(w, r)
  283. return nil
  284. }
  285. func getEvents(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  286. if err := parseForm(r); err != nil {
  287. return err
  288. }
  289. var job = eng.Job("events")
  290. streamJSON(job, w, true)
  291. job.Setenv("since", r.Form.Get("since"))
  292. job.Setenv("until", r.Form.Get("until"))
  293. job.Setenv("filters", r.Form.Get("filters"))
  294. return job.Run()
  295. }
  296. func getImagesHistory(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  297. if vars == nil {
  298. return fmt.Errorf("Missing parameter")
  299. }
  300. var job = eng.Job("history", vars["name"])
  301. streamJSON(job, w, false)
  302. if err := job.Run(); err != nil {
  303. return err
  304. }
  305. return nil
  306. }
  307. func getContainersChanges(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  308. if vars == nil {
  309. return fmt.Errorf("Missing parameter")
  310. }
  311. var job = eng.Job("container_changes", vars["name"])
  312. streamJSON(job, w, false)
  313. return job.Run()
  314. }
  315. func getContainersTop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  316. if version.LessThan("1.4") {
  317. return fmt.Errorf("top was improved a lot since 1.3, Please upgrade your docker client.")
  318. }
  319. if vars == nil {
  320. return fmt.Errorf("Missing parameter")
  321. }
  322. if err := parseForm(r); err != nil {
  323. return err
  324. }
  325. job := eng.Job("top", vars["name"], r.Form.Get("ps_args"))
  326. streamJSON(job, w, false)
  327. return job.Run()
  328. }
  329. func getContainersJSON(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  330. if err := parseForm(r); err != nil {
  331. return err
  332. }
  333. var (
  334. err error
  335. outs *engine.Table
  336. job = eng.Job("containers")
  337. )
  338. job.Setenv("all", r.Form.Get("all"))
  339. job.Setenv("size", r.Form.Get("size"))
  340. job.Setenv("since", r.Form.Get("since"))
  341. job.Setenv("before", r.Form.Get("before"))
  342. job.Setenv("limit", r.Form.Get("limit"))
  343. job.Setenv("filters", r.Form.Get("filters"))
  344. if version.GreaterThanOrEqualTo("1.5") {
  345. streamJSON(job, w, false)
  346. } else if outs, err = job.Stdout.AddTable(); err != nil {
  347. return err
  348. }
  349. if err = job.Run(); err != nil {
  350. return err
  351. }
  352. if version.LessThan("1.5") { // Convert to legacy format
  353. for _, out := range outs.Data {
  354. ports := engine.NewTable("", 0)
  355. ports.ReadListFrom([]byte(out.Get("Ports")))
  356. out.Set("Ports", api.DisplayablePorts(ports))
  357. }
  358. w.Header().Set("Content-Type", "application/json")
  359. if _, err = outs.WriteListTo(w); err != nil {
  360. return err
  361. }
  362. }
  363. return nil
  364. }
  365. func getContainersLogs(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  366. if err := parseForm(r); err != nil {
  367. return err
  368. }
  369. if vars == nil {
  370. return fmt.Errorf("Missing parameter")
  371. }
  372. var (
  373. inspectJob = eng.Job("container_inspect", vars["name"])
  374. logsJob = eng.Job("logs", vars["name"])
  375. c, err = inspectJob.Stdout.AddEnv()
  376. )
  377. if err != nil {
  378. return err
  379. }
  380. logsJob.Setenv("follow", r.Form.Get("follow"))
  381. logsJob.Setenv("tail", r.Form.Get("tail"))
  382. logsJob.Setenv("stdout", r.Form.Get("stdout"))
  383. logsJob.Setenv("stderr", r.Form.Get("stderr"))
  384. logsJob.Setenv("timestamps", r.Form.Get("timestamps"))
  385. // Validate args here, because we can't return not StatusOK after job.Run() call
  386. stdout, stderr := logsJob.GetenvBool("stdout"), logsJob.GetenvBool("stderr")
  387. if !(stdout || stderr) {
  388. return fmt.Errorf("Bad parameters: you must choose at least one stream")
  389. }
  390. if err = inspectJob.Run(); err != nil {
  391. return err
  392. }
  393. var outStream, errStream io.Writer
  394. outStream = utils.NewWriteFlusher(w)
  395. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  396. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  397. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  398. } else {
  399. errStream = outStream
  400. }
  401. logsJob.Stdout.Add(outStream)
  402. logsJob.Stderr.Set(errStream)
  403. if err := logsJob.Run(); err != nil {
  404. fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
  405. }
  406. return nil
  407. }
  408. func postImagesTag(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  409. if err := parseForm(r); err != nil {
  410. return err
  411. }
  412. if vars == nil {
  413. return fmt.Errorf("Missing parameter")
  414. }
  415. job := eng.Job("tag", vars["name"], r.Form.Get("repo"), r.Form.Get("tag"))
  416. job.Setenv("force", r.Form.Get("force"))
  417. if err := job.Run(); err != nil {
  418. return err
  419. }
  420. w.WriteHeader(http.StatusCreated)
  421. return nil
  422. }
  423. func postCommit(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  424. if err := parseForm(r); err != nil {
  425. return err
  426. }
  427. var (
  428. config engine.Env
  429. env engine.Env
  430. job = eng.Job("commit", r.Form.Get("container"))
  431. stdoutBuffer = bytes.NewBuffer(nil)
  432. )
  433. if err := checkForJson(r); err != nil {
  434. return err
  435. }
  436. if err := config.Decode(r.Body); err != nil {
  437. log.Errorf("%s", err)
  438. }
  439. if r.FormValue("pause") == "" && version.GreaterThanOrEqualTo("1.13") {
  440. job.Setenv("pause", "1")
  441. } else {
  442. job.Setenv("pause", r.FormValue("pause"))
  443. }
  444. job.Setenv("repo", r.Form.Get("repo"))
  445. job.Setenv("tag", r.Form.Get("tag"))
  446. job.Setenv("author", r.Form.Get("author"))
  447. job.Setenv("comment", r.Form.Get("comment"))
  448. job.SetenvSubEnv("config", &config)
  449. job.Stdout.Add(stdoutBuffer)
  450. if err := job.Run(); err != nil {
  451. return err
  452. }
  453. env.Set("Id", engine.Tail(stdoutBuffer, 1))
  454. return writeJSON(w, http.StatusCreated, env)
  455. }
  456. // Creates an image from Pull or from Import
  457. func postImagesCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  458. if err := parseForm(r); err != nil {
  459. return err
  460. }
  461. var (
  462. image = r.Form.Get("fromImage")
  463. repo = r.Form.Get("repo")
  464. tag = r.Form.Get("tag")
  465. job *engine.Job
  466. )
  467. authEncoded := r.Header.Get("X-Registry-Auth")
  468. authConfig := &registry.AuthConfig{}
  469. if authEncoded != "" {
  470. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  471. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  472. // for a pull it is not an error if no auth was given
  473. // to increase compatibility with the existing api it is defaulting to be empty
  474. authConfig = &registry.AuthConfig{}
  475. }
  476. }
  477. if image != "" { //pull
  478. if tag == "" {
  479. image, tag = parsers.ParseRepositoryTag(image)
  480. }
  481. metaHeaders := map[string][]string{}
  482. for k, v := range r.Header {
  483. if strings.HasPrefix(k, "X-Meta-") {
  484. metaHeaders[k] = v
  485. }
  486. }
  487. job = eng.Job("pull", image, tag)
  488. job.SetenvBool("parallel", version.GreaterThan("1.3"))
  489. job.SetenvJson("metaHeaders", metaHeaders)
  490. job.SetenvJson("authConfig", authConfig)
  491. } else { //import
  492. if tag == "" {
  493. repo, tag = parsers.ParseRepositoryTag(repo)
  494. }
  495. job = eng.Job("import", r.Form.Get("fromSrc"), repo, tag)
  496. job.Stdin.Add(r.Body)
  497. }
  498. if version.GreaterThan("1.0") {
  499. job.SetenvBool("json", true)
  500. streamJSON(job, w, true)
  501. } else {
  502. job.Stdout.Add(utils.NewWriteFlusher(w))
  503. }
  504. if err := job.Run(); err != nil {
  505. if !job.Stdout.Used() {
  506. return err
  507. }
  508. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  509. w.Write(sf.FormatError(err))
  510. }
  511. return nil
  512. }
  513. func getImagesSearch(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  514. if err := parseForm(r); err != nil {
  515. return err
  516. }
  517. var (
  518. authEncoded = r.Header.Get("X-Registry-Auth")
  519. authConfig = &registry.AuthConfig{}
  520. metaHeaders = map[string][]string{}
  521. )
  522. if authEncoded != "" {
  523. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  524. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  525. // for a search it is not an error if no auth was given
  526. // to increase compatibility with the existing api it is defaulting to be empty
  527. authConfig = &registry.AuthConfig{}
  528. }
  529. }
  530. for k, v := range r.Header {
  531. if strings.HasPrefix(k, "X-Meta-") {
  532. metaHeaders[k] = v
  533. }
  534. }
  535. var job = eng.Job("search", r.Form.Get("term"))
  536. job.SetenvJson("metaHeaders", metaHeaders)
  537. job.SetenvJson("authConfig", authConfig)
  538. streamJSON(job, w, false)
  539. return job.Run()
  540. }
  541. func postImagesPush(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  542. if vars == nil {
  543. return fmt.Errorf("Missing parameter")
  544. }
  545. metaHeaders := map[string][]string{}
  546. for k, v := range r.Header {
  547. if strings.HasPrefix(k, "X-Meta-") {
  548. metaHeaders[k] = v
  549. }
  550. }
  551. if err := parseForm(r); err != nil {
  552. return err
  553. }
  554. authConfig := &registry.AuthConfig{}
  555. authEncoded := r.Header.Get("X-Registry-Auth")
  556. if authEncoded != "" {
  557. // the new format is to handle the authConfig as a header
  558. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  559. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  560. // to increase compatibility to existing api it is defaulting to be empty
  561. authConfig = &registry.AuthConfig{}
  562. }
  563. } else {
  564. // the old format is supported for compatibility if there was no authConfig header
  565. if err := json.NewDecoder(r.Body).Decode(authConfig); err != nil {
  566. return err
  567. }
  568. }
  569. job := eng.Job("push", vars["name"])
  570. job.SetenvJson("metaHeaders", metaHeaders)
  571. job.SetenvJson("authConfig", authConfig)
  572. job.Setenv("tag", r.Form.Get("tag"))
  573. if version.GreaterThan("1.0") {
  574. job.SetenvBool("json", true)
  575. streamJSON(job, w, true)
  576. } else {
  577. job.Stdout.Add(utils.NewWriteFlusher(w))
  578. }
  579. if err := job.Run(); err != nil {
  580. if !job.Stdout.Used() {
  581. return err
  582. }
  583. sf := utils.NewStreamFormatter(version.GreaterThan("1.0"))
  584. w.Write(sf.FormatError(err))
  585. }
  586. return nil
  587. }
  588. func getImagesGet(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  589. if vars == nil {
  590. return fmt.Errorf("Missing parameter")
  591. }
  592. if err := parseForm(r); err != nil {
  593. return err
  594. }
  595. if version.GreaterThan("1.0") {
  596. w.Header().Set("Content-Type", "application/x-tar")
  597. }
  598. var job *engine.Job
  599. if name, ok := vars["name"]; ok {
  600. job = eng.Job("image_export", name)
  601. } else {
  602. job = eng.Job("image_export", r.Form["names"]...)
  603. }
  604. job.Stdout.Add(w)
  605. return job.Run()
  606. }
  607. func postImagesLoad(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  608. job := eng.Job("load")
  609. job.Stdin.Add(r.Body)
  610. return job.Run()
  611. }
  612. func postContainersCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  613. if err := parseForm(r); err != nil {
  614. return nil
  615. }
  616. var (
  617. out engine.Env
  618. job = eng.Job("create", r.Form.Get("name"))
  619. outWarnings []string
  620. stdoutBuffer = bytes.NewBuffer(nil)
  621. warnings = bytes.NewBuffer(nil)
  622. )
  623. if err := checkForJson(r); err != nil {
  624. return err
  625. }
  626. if err := job.DecodeEnv(r.Body); err != nil {
  627. return err
  628. }
  629. // Read container ID from the first line of stdout
  630. job.Stdout.Add(stdoutBuffer)
  631. // Read warnings from stderr
  632. job.Stderr.Add(warnings)
  633. if err := job.Run(); err != nil {
  634. return err
  635. }
  636. // Parse warnings from stderr
  637. scanner := bufio.NewScanner(warnings)
  638. for scanner.Scan() {
  639. outWarnings = append(outWarnings, scanner.Text())
  640. }
  641. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  642. out.SetList("Warnings", outWarnings)
  643. return writeJSON(w, http.StatusCreated, out)
  644. }
  645. func postContainersRestart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  646. if err := parseForm(r); err != nil {
  647. return err
  648. }
  649. if vars == nil {
  650. return fmt.Errorf("Missing parameter")
  651. }
  652. job := eng.Job("restart", vars["name"])
  653. job.Setenv("t", r.Form.Get("t"))
  654. if err := job.Run(); err != nil {
  655. return err
  656. }
  657. w.WriteHeader(http.StatusNoContent)
  658. return nil
  659. }
  660. func deleteContainers(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  661. if err := parseForm(r); err != nil {
  662. return err
  663. }
  664. if vars == nil {
  665. return fmt.Errorf("Missing parameter")
  666. }
  667. job := eng.Job("rm", vars["name"])
  668. job.Setenv("forceRemove", r.Form.Get("force"))
  669. job.Setenv("removeVolume", r.Form.Get("v"))
  670. job.Setenv("removeLink", r.Form.Get("link"))
  671. if err := job.Run(); err != nil {
  672. return err
  673. }
  674. w.WriteHeader(http.StatusNoContent)
  675. return nil
  676. }
  677. func deleteImages(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  678. if err := parseForm(r); err != nil {
  679. return err
  680. }
  681. if vars == nil {
  682. return fmt.Errorf("Missing parameter")
  683. }
  684. var job = eng.Job("image_delete", vars["name"])
  685. streamJSON(job, w, false)
  686. job.Setenv("force", r.Form.Get("force"))
  687. job.Setenv("noprune", r.Form.Get("noprune"))
  688. return job.Run()
  689. }
  690. func postContainersStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  691. if vars == nil {
  692. return fmt.Errorf("Missing parameter")
  693. }
  694. var (
  695. name = vars["name"]
  696. job = eng.Job("start", name)
  697. )
  698. // If contentLength is -1, we can assumed chunked encoding
  699. // or more technically that the length is unknown
  700. // http://golang.org/src/pkg/net/http/request.go#L139
  701. // net/http otherwise seems to swallow any headers related to chunked encoding
  702. // including r.TransferEncoding
  703. // allow a nil body for backwards compatibility
  704. if r.Body != nil && (r.ContentLength > 0 || r.ContentLength == -1) {
  705. if err := checkForJson(r); err != nil {
  706. return err
  707. }
  708. if err := job.DecodeEnv(r.Body); err != nil {
  709. return err
  710. }
  711. }
  712. if err := job.Run(); err != nil {
  713. if err.Error() == "Container already started" {
  714. w.WriteHeader(http.StatusNotModified)
  715. return nil
  716. }
  717. return err
  718. }
  719. w.WriteHeader(http.StatusNoContent)
  720. return nil
  721. }
  722. func postContainersStop(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  723. if err := parseForm(r); err != nil {
  724. return err
  725. }
  726. if vars == nil {
  727. return fmt.Errorf("Missing parameter")
  728. }
  729. job := eng.Job("stop", vars["name"])
  730. job.Setenv("t", r.Form.Get("t"))
  731. if err := job.Run(); err != nil {
  732. if err.Error() == "Container already stopped" {
  733. w.WriteHeader(http.StatusNotModified)
  734. return nil
  735. }
  736. return err
  737. }
  738. w.WriteHeader(http.StatusNoContent)
  739. return nil
  740. }
  741. func postContainersWait(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  742. if vars == nil {
  743. return fmt.Errorf("Missing parameter")
  744. }
  745. var (
  746. env engine.Env
  747. stdoutBuffer = bytes.NewBuffer(nil)
  748. job = eng.Job("wait", vars["name"])
  749. )
  750. job.Stdout.Add(stdoutBuffer)
  751. if err := job.Run(); err != nil {
  752. return err
  753. }
  754. env.Set("StatusCode", engine.Tail(stdoutBuffer, 1))
  755. return writeJSON(w, http.StatusOK, env)
  756. }
  757. func postContainersResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  758. if err := parseForm(r); err != nil {
  759. return err
  760. }
  761. if vars == nil {
  762. return fmt.Errorf("Missing parameter")
  763. }
  764. if err := eng.Job("resize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  765. return err
  766. }
  767. return nil
  768. }
  769. func postContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  770. if err := parseForm(r); err != nil {
  771. return err
  772. }
  773. if vars == nil {
  774. return fmt.Errorf("Missing parameter")
  775. }
  776. var (
  777. job = eng.Job("container_inspect", vars["name"])
  778. c, err = job.Stdout.AddEnv()
  779. )
  780. if err != nil {
  781. return err
  782. }
  783. if err = job.Run(); err != nil {
  784. return err
  785. }
  786. inStream, outStream, err := hijackServer(w)
  787. if err != nil {
  788. return err
  789. }
  790. defer closeStreams(inStream, outStream)
  791. var errStream io.Writer
  792. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  793. if c.GetSubEnv("Config") != nil && !c.GetSubEnv("Config").GetBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  794. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  795. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  796. } else {
  797. errStream = outStream
  798. }
  799. job = eng.Job("attach", vars["name"])
  800. job.Setenv("logs", r.Form.Get("logs"))
  801. job.Setenv("stream", r.Form.Get("stream"))
  802. job.Setenv("stdin", r.Form.Get("stdin"))
  803. job.Setenv("stdout", r.Form.Get("stdout"))
  804. job.Setenv("stderr", r.Form.Get("stderr"))
  805. job.Stdin.Add(inStream)
  806. job.Stdout.Add(outStream)
  807. job.Stderr.Set(errStream)
  808. if err := job.Run(); err != nil {
  809. fmt.Fprintf(outStream, "Error attaching: %s\n", err)
  810. }
  811. return nil
  812. }
  813. func wsContainersAttach(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  814. if err := parseForm(r); err != nil {
  815. return err
  816. }
  817. if vars == nil {
  818. return fmt.Errorf("Missing parameter")
  819. }
  820. if err := eng.Job("container_inspect", vars["name"]).Run(); err != nil {
  821. return err
  822. }
  823. h := websocket.Handler(func(ws *websocket.Conn) {
  824. defer ws.Close()
  825. job := eng.Job("attach", vars["name"])
  826. job.Setenv("logs", r.Form.Get("logs"))
  827. job.Setenv("stream", r.Form.Get("stream"))
  828. job.Setenv("stdin", r.Form.Get("stdin"))
  829. job.Setenv("stdout", r.Form.Get("stdout"))
  830. job.Setenv("stderr", r.Form.Get("stderr"))
  831. job.Stdin.Add(ws)
  832. job.Stdout.Add(ws)
  833. job.Stderr.Set(ws)
  834. if err := job.Run(); err != nil {
  835. log.Errorf("Error attaching websocket: %s", err)
  836. }
  837. })
  838. h.ServeHTTP(w, r)
  839. return nil
  840. }
  841. func getContainersByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  842. if vars == nil {
  843. return fmt.Errorf("Missing parameter")
  844. }
  845. var job = eng.Job("container_inspect", vars["name"])
  846. if version.LessThan("1.12") {
  847. job.SetenvBool("raw", true)
  848. }
  849. streamJSON(job, w, false)
  850. return job.Run()
  851. }
  852. func getExecByID(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  853. if vars == nil {
  854. return fmt.Errorf("Missing parameter 'id'")
  855. }
  856. var job = eng.Job("execInspect", vars["id"])
  857. streamJSON(job, w, false)
  858. return job.Run()
  859. }
  860. func getImagesByName(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  861. if vars == nil {
  862. return fmt.Errorf("Missing parameter")
  863. }
  864. var job = eng.Job("image_inspect", vars["name"])
  865. if version.LessThan("1.12") {
  866. job.SetenvBool("raw", true)
  867. }
  868. streamJSON(job, w, false)
  869. return job.Run()
  870. }
  871. func postBuild(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  872. if version.LessThan("1.3") {
  873. return fmt.Errorf("Multipart upload for build is no longer supported. Please upgrade your docker client.")
  874. }
  875. var (
  876. authEncoded = r.Header.Get("X-Registry-Auth")
  877. authConfig = &registry.AuthConfig{}
  878. configFileEncoded = r.Header.Get("X-Registry-Config")
  879. configFile = &registry.ConfigFile{}
  880. job = eng.Job("build")
  881. )
  882. // This block can be removed when API versions prior to 1.9 are deprecated.
  883. // Both headers will be parsed and sent along to the daemon, but if a non-empty
  884. // ConfigFile is present, any value provided as an AuthConfig directly will
  885. // be overridden. See BuildFile::CmdFrom for details.
  886. if version.LessThan("1.9") && authEncoded != "" {
  887. authJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(authEncoded))
  888. if err := json.NewDecoder(authJson).Decode(authConfig); err != nil {
  889. // for a pull it is not an error if no auth was given
  890. // to increase compatibility with the existing api it is defaulting to be empty
  891. authConfig = &registry.AuthConfig{}
  892. }
  893. }
  894. if configFileEncoded != "" {
  895. configFileJson := base64.NewDecoder(base64.URLEncoding, strings.NewReader(configFileEncoded))
  896. if err := json.NewDecoder(configFileJson).Decode(configFile); err != nil {
  897. // for a pull it is not an error if no auth was given
  898. // to increase compatibility with the existing api it is defaulting to be empty
  899. configFile = &registry.ConfigFile{}
  900. }
  901. }
  902. if version.GreaterThanOrEqualTo("1.8") {
  903. job.SetenvBool("json", true)
  904. streamJSON(job, w, true)
  905. } else {
  906. job.Stdout.Add(utils.NewWriteFlusher(w))
  907. }
  908. if r.FormValue("forcerm") == "1" && version.GreaterThanOrEqualTo("1.12") {
  909. job.Setenv("rm", "1")
  910. } else if r.FormValue("rm") == "" && version.GreaterThanOrEqualTo("1.12") {
  911. job.Setenv("rm", "1")
  912. } else {
  913. job.Setenv("rm", r.FormValue("rm"))
  914. }
  915. if r.FormValue("pull") == "1" && version.GreaterThanOrEqualTo("1.16") {
  916. job.Setenv("pull", "1")
  917. }
  918. job.Stdin.Add(r.Body)
  919. job.Setenv("remote", r.FormValue("remote"))
  920. job.Setenv("t", r.FormValue("t"))
  921. job.Setenv("q", r.FormValue("q"))
  922. job.Setenv("nocache", r.FormValue("nocache"))
  923. job.Setenv("forcerm", r.FormValue("forcerm"))
  924. job.SetenvJson("authConfig", authConfig)
  925. job.SetenvJson("configFile", configFile)
  926. if err := job.Run(); err != nil {
  927. if !job.Stdout.Used() {
  928. return err
  929. }
  930. sf := utils.NewStreamFormatter(version.GreaterThanOrEqualTo("1.8"))
  931. w.Write(sf.FormatError(err))
  932. }
  933. return nil
  934. }
  935. func postContainersCopy(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  936. if vars == nil {
  937. return fmt.Errorf("Missing parameter")
  938. }
  939. var copyData engine.Env
  940. if err := checkForJson(r); err != nil {
  941. return err
  942. }
  943. if err := copyData.Decode(r.Body); err != nil {
  944. return err
  945. }
  946. if copyData.Get("Resource") == "" {
  947. return fmt.Errorf("Path cannot be empty")
  948. }
  949. origResource := copyData.Get("Resource")
  950. if copyData.Get("Resource")[0] == '/' {
  951. copyData.Set("Resource", copyData.Get("Resource")[1:])
  952. }
  953. job := eng.Job("container_copy", vars["name"], copyData.Get("Resource"))
  954. job.Stdout.Add(w)
  955. w.Header().Set("Content-Type", "application/x-tar")
  956. if err := job.Run(); err != nil {
  957. log.Errorf("%s", err.Error())
  958. if strings.Contains(strings.ToLower(err.Error()), "no such container") {
  959. w.WriteHeader(http.StatusNotFound)
  960. } else if strings.Contains(err.Error(), "no such file or directory") {
  961. return fmt.Errorf("Could not find the file %s in container %s", origResource, vars["name"])
  962. }
  963. }
  964. return nil
  965. }
  966. func postContainerExecCreate(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  967. if err := parseForm(r); err != nil {
  968. return nil
  969. }
  970. var (
  971. out engine.Env
  972. name = vars["name"]
  973. job = eng.Job("execCreate", name)
  974. stdoutBuffer = bytes.NewBuffer(nil)
  975. )
  976. if err := job.DecodeEnv(r.Body); err != nil {
  977. return err
  978. }
  979. job.Stdout.Add(stdoutBuffer)
  980. // Register an instance of Exec in container.
  981. if err := job.Run(); err != nil {
  982. fmt.Fprintf(os.Stderr, "Error setting up exec command in container %s: %s\n", name, err)
  983. return err
  984. }
  985. // Return the ID
  986. out.Set("Id", engine.Tail(stdoutBuffer, 1))
  987. return writeJSON(w, http.StatusCreated, out)
  988. }
  989. // TODO(vishh): Refactor the code to avoid having to specify stream config as part of both create and start.
  990. func postContainerExecStart(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  991. if err := parseForm(r); err != nil {
  992. return nil
  993. }
  994. var (
  995. name = vars["name"]
  996. job = eng.Job("execStart", name)
  997. errOut io.Writer = os.Stderr
  998. )
  999. if err := job.DecodeEnv(r.Body); err != nil {
  1000. return err
  1001. }
  1002. if !job.GetenvBool("Detach") {
  1003. // Setting up the streaming http interface.
  1004. inStream, outStream, err := hijackServer(w)
  1005. if err != nil {
  1006. return err
  1007. }
  1008. defer closeStreams(inStream, outStream)
  1009. var errStream io.Writer
  1010. fmt.Fprintf(outStream, "HTTP/1.1 200 OK\r\nContent-Type: application/vnd.docker.raw-stream\r\n\r\n")
  1011. if !job.GetenvBool("Tty") && version.GreaterThanOrEqualTo("1.6") {
  1012. errStream = stdcopy.NewStdWriter(outStream, stdcopy.Stderr)
  1013. outStream = stdcopy.NewStdWriter(outStream, stdcopy.Stdout)
  1014. } else {
  1015. errStream = outStream
  1016. }
  1017. job.Stdin.Add(inStream)
  1018. job.Stdout.Add(outStream)
  1019. job.Stderr.Set(errStream)
  1020. errOut = outStream
  1021. }
  1022. // Now run the user process in container.
  1023. job.SetCloseIO(false)
  1024. if err := job.Run(); err != nil {
  1025. fmt.Fprintf(errOut, "Error starting exec command in container %s: %s\n", name, err)
  1026. return err
  1027. }
  1028. w.WriteHeader(http.StatusNoContent)
  1029. return nil
  1030. }
  1031. func postContainerExecResize(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1032. if err := parseForm(r); err != nil {
  1033. return err
  1034. }
  1035. if vars == nil {
  1036. return fmt.Errorf("Missing parameter")
  1037. }
  1038. if err := eng.Job("execResize", vars["name"], r.Form.Get("h"), r.Form.Get("w")).Run(); err != nil {
  1039. return err
  1040. }
  1041. return nil
  1042. }
  1043. func optionsHandler(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1044. w.WriteHeader(http.StatusOK)
  1045. return nil
  1046. }
  1047. func writeCorsHeaders(w http.ResponseWriter, r *http.Request) {
  1048. w.Header().Add("Access-Control-Allow-Origin", "*")
  1049. w.Header().Add("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept, X-Registry-Auth")
  1050. w.Header().Add("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
  1051. }
  1052. func ping(eng *engine.Engine, version version.Version, w http.ResponseWriter, r *http.Request, vars map[string]string) error {
  1053. _, err := w.Write([]byte{'O', 'K'})
  1054. return err
  1055. }
  1056. func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, localRoute string, handlerFunc HttpApiFunc, enableCors bool, dockerVersion version.Version) http.HandlerFunc {
  1057. return func(w http.ResponseWriter, r *http.Request) {
  1058. // log the request
  1059. log.Debugf("Calling %s %s", localMethod, localRoute)
  1060. if logging {
  1061. log.Infof("%s %s", r.Method, r.RequestURI)
  1062. }
  1063. if strings.Contains(r.Header.Get("User-Agent"), "Docker-Client/") {
  1064. userAgent := strings.Split(r.Header.Get("User-Agent"), "/")
  1065. if len(userAgent) == 2 && !dockerVersion.Equal(version.Version(userAgent[1])) {
  1066. log.Debugf("Warning: client and server don't have the same version (client: %s, server: %s)", userAgent[1], dockerVersion)
  1067. }
  1068. }
  1069. version := version.Version(mux.Vars(r)["version"])
  1070. if version == "" {
  1071. version = api.APIVERSION
  1072. }
  1073. if enableCors {
  1074. writeCorsHeaders(w, r)
  1075. }
  1076. if version.GreaterThan(api.APIVERSION) {
  1077. http.Error(w, fmt.Errorf("client and server don't have same version (client : %s, server: %s)", version, api.APIVERSION).Error(), http.StatusNotFound)
  1078. return
  1079. }
  1080. if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
  1081. log.Errorf("Handler for %s %s returned error: %s", localMethod, localRoute, err)
  1082. httpError(w, err)
  1083. }
  1084. }
  1085. }
  1086. // Replicated from expvar.go as not public.
  1087. func expvarHandler(w http.ResponseWriter, r *http.Request) {
  1088. w.Header().Set("Content-Type", "application/json; charset=utf-8")
  1089. fmt.Fprintf(w, "{\n")
  1090. first := true
  1091. expvar.Do(func(kv expvar.KeyValue) {
  1092. if !first {
  1093. fmt.Fprintf(w, ",\n")
  1094. }
  1095. first = false
  1096. fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value)
  1097. })
  1098. fmt.Fprintf(w, "\n}\n")
  1099. }
  1100. func AttachProfiler(router *mux.Router) {
  1101. router.HandleFunc("/debug/vars", expvarHandler)
  1102. router.HandleFunc("/debug/pprof/", pprof.Index)
  1103. router.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
  1104. router.HandleFunc("/debug/pprof/profile", pprof.Profile)
  1105. router.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
  1106. router.HandleFunc("/debug/pprof/block", pprof.Handler("block").ServeHTTP)
  1107. router.HandleFunc("/debug/pprof/heap", pprof.Handler("heap").ServeHTTP)
  1108. router.HandleFunc("/debug/pprof/goroutine", pprof.Handler("goroutine").ServeHTTP)
  1109. router.HandleFunc("/debug/pprof/threadcreate", pprof.Handler("threadcreate").ServeHTTP)
  1110. }
  1111. func createRouter(eng *engine.Engine, logging, enableCors bool, dockerVersion string) (*mux.Router, error) {
  1112. r := mux.NewRouter()
  1113. if os.Getenv("DEBUG") != "" {
  1114. AttachProfiler(r)
  1115. }
  1116. m := map[string]map[string]HttpApiFunc{
  1117. "GET": {
  1118. "/_ping": ping,
  1119. "/events": getEvents,
  1120. "/info": getInfo,
  1121. "/version": getVersion,
  1122. "/images/json": getImagesJSON,
  1123. "/images/viz": getImagesViz,
  1124. "/images/search": getImagesSearch,
  1125. "/images/get": getImagesGet,
  1126. "/images/{name:.*}/get": getImagesGet,
  1127. "/images/{name:.*}/history": getImagesHistory,
  1128. "/images/{name:.*}/json": getImagesByName,
  1129. "/containers/ps": getContainersJSON,
  1130. "/containers/json": getContainersJSON,
  1131. "/containers/{name:.*}/export": getContainersExport,
  1132. "/containers/{name:.*}/changes": getContainersChanges,
  1133. "/containers/{name:.*}/json": getContainersByName,
  1134. "/containers/{name:.*}/top": getContainersTop,
  1135. "/containers/{name:.*}/logs": getContainersLogs,
  1136. "/containers/{name:.*}/attach/ws": wsContainersAttach,
  1137. "/exec/{id:.*}/json": getExecByID,
  1138. },
  1139. "POST": {
  1140. "/auth": postAuth,
  1141. "/commit": postCommit,
  1142. "/build": postBuild,
  1143. "/images/create": postImagesCreate,
  1144. "/images/load": postImagesLoad,
  1145. "/images/{name:.*}/push": postImagesPush,
  1146. "/images/{name:.*}/tag": postImagesTag,
  1147. "/containers/create": postContainersCreate,
  1148. "/containers/{name:.*}/kill": postContainersKill,
  1149. "/containers/{name:.*}/pause": postContainersPause,
  1150. "/containers/{name:.*}/unpause": postContainersUnpause,
  1151. "/containers/{name:.*}/restart": postContainersRestart,
  1152. "/containers/{name:.*}/start": postContainersStart,
  1153. "/containers/{name:.*}/stop": postContainersStop,
  1154. "/containers/{name:.*}/wait": postContainersWait,
  1155. "/containers/{name:.*}/resize": postContainersResize,
  1156. "/containers/{name:.*}/attach": postContainersAttach,
  1157. "/containers/{name:.*}/copy": postContainersCopy,
  1158. "/containers/{name:.*}/exec": postContainerExecCreate,
  1159. "/exec/{name:.*}/start": postContainerExecStart,
  1160. "/exec/{name:.*}/resize": postContainerExecResize,
  1161. },
  1162. "DELETE": {
  1163. "/containers/{name:.*}": deleteContainers,
  1164. "/images/{name:.*}": deleteImages,
  1165. },
  1166. "OPTIONS": {
  1167. "": optionsHandler,
  1168. },
  1169. }
  1170. for method, routes := range m {
  1171. for route, fct := range routes {
  1172. log.Debugf("Registering %s, %s", method, route)
  1173. // NOTE: scope issue, make sure the variables are local and won't be changed
  1174. localRoute := route
  1175. localFct := fct
  1176. localMethod := method
  1177. // build the handler function
  1178. f := makeHttpHandler(eng, logging, localMethod, localRoute, localFct, enableCors, version.Version(dockerVersion))
  1179. // add the new route
  1180. if localRoute == "" {
  1181. r.Methods(localMethod).HandlerFunc(f)
  1182. } else {
  1183. r.Path("/v{version:[0-9.]+}" + localRoute).Methods(localMethod).HandlerFunc(f)
  1184. r.Path(localRoute).Methods(localMethod).HandlerFunc(f)
  1185. }
  1186. }
  1187. }
  1188. return r, nil
  1189. }
  1190. // ServeRequest processes a single http request to the docker remote api.
  1191. // FIXME: refactor this to be part of Server and not require re-creating a new
  1192. // router each time. This requires first moving ListenAndServe into Server.
  1193. func ServeRequest(eng *engine.Engine, apiversion version.Version, w http.ResponseWriter, req *http.Request) error {
  1194. router, err := createRouter(eng, false, true, "")
  1195. if err != nil {
  1196. return err
  1197. }
  1198. // Insert APIVERSION into the request as a convenience
  1199. req.URL.Path = fmt.Sprintf("/v%s%s", apiversion, req.URL.Path)
  1200. router.ServeHTTP(w, req)
  1201. return nil
  1202. }
  1203. // serveFd creates an http.Server and sets it up to serve given a socket activated
  1204. // argument.
  1205. func serveFd(addr string, job *engine.Job) error {
  1206. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1207. if err != nil {
  1208. return err
  1209. }
  1210. ls, e := systemd.ListenFD(addr)
  1211. if e != nil {
  1212. return e
  1213. }
  1214. chErrors := make(chan error, len(ls))
  1215. // We don't want to start serving on these sockets until the
  1216. // daemon is initialized and installed. Otherwise required handlers
  1217. // won't be ready.
  1218. <-activationLock
  1219. // Since ListenFD will return one or more sockets we have
  1220. // to create a go func to spawn off multiple serves
  1221. for i := range ls {
  1222. listener := ls[i]
  1223. go func() {
  1224. httpSrv := http.Server{Handler: r}
  1225. chErrors <- httpSrv.Serve(listener)
  1226. }()
  1227. }
  1228. for i := 0; i < len(ls); i++ {
  1229. err := <-chErrors
  1230. if err != nil {
  1231. return err
  1232. }
  1233. }
  1234. return nil
  1235. }
  1236. func lookupGidByName(nameOrGid string) (int, error) {
  1237. groupFile, err := user.GetGroupFile()
  1238. if err != nil {
  1239. return -1, err
  1240. }
  1241. groups, err := user.ParseGroupFileFilter(groupFile, func(g user.Group) bool {
  1242. return g.Name == nameOrGid || strconv.Itoa(g.Gid) == nameOrGid
  1243. })
  1244. if err != nil {
  1245. return -1, err
  1246. }
  1247. if groups != nil && len(groups) > 0 {
  1248. return groups[0].Gid, nil
  1249. }
  1250. return -1, fmt.Errorf("Group %s not found", nameOrGid)
  1251. }
  1252. func setupTls(cert, key, ca string, l net.Listener) (net.Listener, error) {
  1253. tlsCert, err := tls.LoadX509KeyPair(cert, key)
  1254. if err != nil {
  1255. return nil, fmt.Errorf("Couldn't load X509 key pair (%s, %s): %s. Key encrypted?",
  1256. cert, key, err)
  1257. }
  1258. tlsConfig := &tls.Config{
  1259. NextProtos: []string{"http/1.1"},
  1260. Certificates: []tls.Certificate{tlsCert},
  1261. // Avoid fallback on insecure SSL protocols
  1262. MinVersion: tls.VersionTLS10,
  1263. }
  1264. if ca != "" {
  1265. certPool := x509.NewCertPool()
  1266. file, err := ioutil.ReadFile(ca)
  1267. if err != nil {
  1268. return nil, fmt.Errorf("Couldn't read CA certificate: %s", err)
  1269. }
  1270. certPool.AppendCertsFromPEM(file)
  1271. tlsConfig.ClientAuth = tls.RequireAndVerifyClientCert
  1272. tlsConfig.ClientCAs = certPool
  1273. }
  1274. return tls.NewListener(l, tlsConfig), nil
  1275. }
  1276. func newListener(proto, addr string, bufferRequests bool) (net.Listener, error) {
  1277. if bufferRequests {
  1278. return listenbuffer.NewListenBuffer(proto, addr, activationLock)
  1279. }
  1280. return net.Listen(proto, addr)
  1281. }
  1282. func changeGroup(addr string, nameOrGid string) error {
  1283. gid, err := lookupGidByName(nameOrGid)
  1284. if err != nil {
  1285. return err
  1286. }
  1287. log.Debugf("%s group found. gid: %d", nameOrGid, gid)
  1288. return os.Chown(addr, 0, gid)
  1289. }
  1290. func setSocketGroup(addr, group string) error {
  1291. if group == "" {
  1292. return nil
  1293. }
  1294. if err := changeGroup(addr, group); err != nil {
  1295. if group != "docker" {
  1296. return err
  1297. }
  1298. log.Debugf("Warning: could not chgrp %s to docker: %v", addr, err)
  1299. }
  1300. return nil
  1301. }
  1302. func setupUnixHttp(addr string, job *engine.Job) (*HttpServer, error) {
  1303. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1304. if err != nil {
  1305. return nil, err
  1306. }
  1307. if err := syscall.Unlink(addr); err != nil && !os.IsNotExist(err) {
  1308. return nil, err
  1309. }
  1310. mask := syscall.Umask(0777)
  1311. defer syscall.Umask(mask)
  1312. l, err := newListener("unix", addr, job.GetenvBool("BufferRequests"))
  1313. if err != nil {
  1314. return nil, err
  1315. }
  1316. if err := setSocketGroup(addr, job.Getenv("SocketGroup")); err != nil {
  1317. return nil, err
  1318. }
  1319. if err := os.Chmod(addr, 0660); err != nil {
  1320. return nil, err
  1321. }
  1322. return &HttpServer{&http.Server{Addr: addr, Handler: r}, l}, nil
  1323. }
  1324. func setupTcpHttp(addr string, job *engine.Job) (*HttpServer, error) {
  1325. if !strings.HasPrefix(addr, "127.0.0.1") && !job.GetenvBool("TlsVerify") {
  1326. log.Infof("/!\\ DON'T BIND ON ANOTHER IP ADDRESS THAN 127.0.0.1 IF YOU DON'T KNOW WHAT YOU'RE DOING /!\\")
  1327. }
  1328. r, err := createRouter(job.Eng, job.GetenvBool("Logging"), job.GetenvBool("EnableCors"), job.Getenv("Version"))
  1329. if err != nil {
  1330. return nil, err
  1331. }
  1332. l, err := newListener("tcp", addr, job.GetenvBool("BufferRequests"))
  1333. if err != nil {
  1334. return nil, err
  1335. }
  1336. if job.GetenvBool("Tls") || job.GetenvBool("TlsVerify") {
  1337. var tlsCa string
  1338. if job.GetenvBool("TlsVerify") {
  1339. tlsCa = job.Getenv("TlsCa")
  1340. }
  1341. l, err = setupTls(job.Getenv("TlsCert"), job.Getenv("TlsKey"), tlsCa, l)
  1342. if err != nil {
  1343. return nil, err
  1344. }
  1345. }
  1346. return &HttpServer{&http.Server{Addr: addr, Handler: r}, l}, nil
  1347. }
  1348. // NewServer sets up the required Server and does protocol specific checking.
  1349. func NewServer(proto, addr string, job *engine.Job) (Server, error) {
  1350. // Basic error and sanity checking
  1351. switch proto {
  1352. case "fd":
  1353. return nil, serveFd(addr, job)
  1354. case "tcp":
  1355. return setupTcpHttp(addr, job)
  1356. case "unix":
  1357. return setupUnixHttp(addr, job)
  1358. default:
  1359. return nil, fmt.Errorf("Invalid protocol format.")
  1360. }
  1361. }
  1362. type Server interface {
  1363. Serve() error
  1364. Close() error
  1365. }
  1366. // ServeApi loops through all of the protocols sent in to docker and spawns
  1367. // off a go routine to setup a serving http.Server for each.
  1368. func ServeApi(job *engine.Job) engine.Status {
  1369. if len(job.Args) == 0 {
  1370. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1371. }
  1372. var (
  1373. protoAddrs = job.Args
  1374. chErrors = make(chan error, len(protoAddrs))
  1375. )
  1376. activationLock = make(chan struct{})
  1377. for _, protoAddr := range protoAddrs {
  1378. protoAddrParts := strings.SplitN(protoAddr, "://", 2)
  1379. if len(protoAddrParts) != 2 {
  1380. return job.Errorf("usage: %s PROTO://ADDR [PROTO://ADDR ...]", job.Name)
  1381. }
  1382. go func() {
  1383. log.Infof("Listening for HTTP on %s (%s)", protoAddrParts[0], protoAddrParts[1])
  1384. srv, err := NewServer(protoAddrParts[0], protoAddrParts[1], job)
  1385. if err != nil {
  1386. chErrors <- err
  1387. return
  1388. }
  1389. chErrors <- srv.Serve()
  1390. }()
  1391. }
  1392. for i := 0; i < len(protoAddrs); i++ {
  1393. err := <-chErrors
  1394. if err != nil {
  1395. return job.Error(err)
  1396. }
  1397. }
  1398. return engine.StatusOK
  1399. }
  1400. func AcceptConnections(job *engine.Job) engine.Status {
  1401. // Tell the init daemon we are accepting requests
  1402. go systemd.SdNotify("READY=1")
  1403. // close the lock so the listeners start accepting connections
  1404. if activationLock != nil {
  1405. close(activationLock)
  1406. }
  1407. return engine.StatusOK
  1408. }