docker_cli_run_unix_test.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492
  1. // +build !windows
  2. package main
  3. import (
  4. "bufio"
  5. "fmt"
  6. "io/ioutil"
  7. "os"
  8. "os/exec"
  9. "path"
  10. "path/filepath"
  11. "strings"
  12. "time"
  13. "github.com/docker/docker/pkg/mount"
  14. "github.com/go-check/check"
  15. "github.com/kr/pty"
  16. )
  17. // #6509
  18. func (s *DockerSuite) TestRunRedirectStdout(c *check.C) {
  19. checkRedirect := func(command string) {
  20. _, tty, err := pty.Open()
  21. if err != nil {
  22. c.Fatalf("Could not open pty: %v", err)
  23. }
  24. cmd := exec.Command("sh", "-c", command)
  25. cmd.Stdin = tty
  26. cmd.Stdout = tty
  27. cmd.Stderr = tty
  28. if err := cmd.Start(); err != nil {
  29. c.Fatalf("start err: %v", err)
  30. }
  31. ch := make(chan error)
  32. go func() {
  33. ch <- cmd.Wait()
  34. close(ch)
  35. }()
  36. select {
  37. case <-time.After(10 * time.Second):
  38. c.Fatal("command timeout")
  39. case err := <-ch:
  40. if err != nil {
  41. c.Fatalf("wait err=%v", err)
  42. }
  43. }
  44. }
  45. checkRedirect(dockerBinary + " run -i busybox cat /etc/passwd | grep -q root")
  46. checkRedirect(dockerBinary + " run busybox cat /etc/passwd | grep -q root")
  47. }
  48. // Test recursive bind mount works by default
  49. func (s *DockerSuite) TestRunWithVolumesIsRecursive(c *check.C) {
  50. tmpDir, err := ioutil.TempDir("", "docker_recursive_mount_test")
  51. if err != nil {
  52. c.Fatal(err)
  53. }
  54. defer os.RemoveAll(tmpDir)
  55. // Create a temporary tmpfs mount.
  56. tmpfsDir := filepath.Join(tmpDir, "tmpfs")
  57. if err := os.MkdirAll(tmpfsDir, 0777); err != nil {
  58. c.Fatalf("failed to mkdir at %s - %s", tmpfsDir, err)
  59. }
  60. if err := mount.Mount("tmpfs", tmpfsDir, "tmpfs", ""); err != nil {
  61. c.Fatalf("failed to create a tmpfs mount at %s - %s", tmpfsDir, err)
  62. }
  63. f, err := ioutil.TempFile(tmpfsDir, "touch-me")
  64. if err != nil {
  65. c.Fatal(err)
  66. }
  67. defer f.Close()
  68. runCmd := exec.Command(dockerBinary, "run", "--name", "test-data", "--volume", fmt.Sprintf("%s:/tmp:ro", tmpDir), "busybox:latest", "ls", "/tmp/tmpfs")
  69. out, stderr, exitCode, err := runCommandWithStdoutStderr(runCmd)
  70. if err != nil && exitCode != 0 {
  71. c.Fatal(out, stderr, err)
  72. }
  73. if !strings.Contains(out, filepath.Base(f.Name())) {
  74. c.Fatal("Recursive bind mount test failed. Expected file not found")
  75. }
  76. }
  77. func (s *DockerSuite) TestRunWithUlimits(c *check.C) {
  78. testRequires(c, NativeExecDriver)
  79. out, _, err := runCommandWithOutput(exec.Command(dockerBinary, "run", "--name=testulimits", "--ulimit", "nofile=42", "busybox", "/bin/sh", "-c", "ulimit -n"))
  80. if err != nil {
  81. c.Fatal(err, out)
  82. }
  83. ul := strings.TrimSpace(out)
  84. if ul != "42" {
  85. c.Fatalf("expected `ulimit -n` to be 42, got %s", ul)
  86. }
  87. }
  88. func (s *DockerSuite) TestRunContainerWithCgroupParent(c *check.C) {
  89. testRequires(c, NativeExecDriver)
  90. cgroupParent := "test"
  91. data, err := ioutil.ReadFile("/proc/self/cgroup")
  92. if err != nil {
  93. c.Fatalf("failed to read '/proc/self/cgroup - %v", err)
  94. }
  95. selfCgroupPaths := parseCgroupPaths(string(data))
  96. selfCpuCgroup, found := selfCgroupPaths["memory"]
  97. if !found {
  98. c.Fatalf("unable to find self cpu cgroup path. CgroupsPath: %v", selfCgroupPaths)
  99. }
  100. out, _, err := runCommandWithOutput(exec.Command(dockerBinary, "run", "--cgroup-parent", cgroupParent, "--rm", "busybox", "cat", "/proc/self/cgroup"))
  101. if err != nil {
  102. c.Fatalf("unexpected failure when running container with --cgroup-parent option - %s\n%v", string(out), err)
  103. }
  104. cgroupPaths := parseCgroupPaths(string(out))
  105. if len(cgroupPaths) == 0 {
  106. c.Fatalf("unexpected output - %q", string(out))
  107. }
  108. found = false
  109. expectedCgroupPrefix := path.Join(selfCpuCgroup, cgroupParent)
  110. for _, path := range cgroupPaths {
  111. if strings.HasPrefix(path, expectedCgroupPrefix) {
  112. found = true
  113. break
  114. }
  115. }
  116. if !found {
  117. c.Fatalf("unexpected cgroup paths. Expected at least one cgroup path to have prefix %q. Cgroup Paths: %v", expectedCgroupPrefix, cgroupPaths)
  118. }
  119. }
  120. func (s *DockerSuite) TestRunContainerWithCgroupParentAbsPath(c *check.C) {
  121. testRequires(c, NativeExecDriver)
  122. cgroupParent := "/cgroup-parent/test"
  123. out, _, err := runCommandWithOutput(exec.Command(dockerBinary, "run", "--cgroup-parent", cgroupParent, "--rm", "busybox", "cat", "/proc/self/cgroup"))
  124. if err != nil {
  125. c.Fatalf("unexpected failure when running container with --cgroup-parent option - %s\n%v", string(out), err)
  126. }
  127. cgroupPaths := parseCgroupPaths(string(out))
  128. if len(cgroupPaths) == 0 {
  129. c.Fatalf("unexpected output - %q", string(out))
  130. }
  131. found := false
  132. for _, path := range cgroupPaths {
  133. if strings.HasPrefix(path, cgroupParent) {
  134. found = true
  135. break
  136. }
  137. }
  138. if !found {
  139. c.Fatalf("unexpected cgroup paths. Expected at least one cgroup path to have prefix %q. Cgroup Paths: %v", cgroupParent, cgroupPaths)
  140. }
  141. }
  142. func (s *DockerSuite) TestRunContainerWithCgroupMountRO(c *check.C) {
  143. testRequires(c, NativeExecDriver)
  144. filename := "/sys/fs/cgroup/devices/test123"
  145. cmd := exec.Command(dockerBinary, "run", "busybox", "touch", filename)
  146. out, _, err := runCommandWithOutput(cmd)
  147. if err == nil {
  148. c.Fatal("expected cgroup mount point to be read-only, touch file should fail")
  149. }
  150. expected := "Read-only file system"
  151. if !strings.Contains(out, expected) {
  152. c.Fatalf("expected output from failure to contain %s but contains %s", expected, out)
  153. }
  154. }
  155. func (s *DockerSuite) TestRunDeviceDirectory(c *check.C) {
  156. testRequires(c, NativeExecDriver)
  157. cmd := exec.Command(dockerBinary, "run", "--device", "/dev/snd:/dev/snd", "busybox", "sh", "-c", "ls /dev/snd/")
  158. out, _, err := runCommandWithOutput(cmd)
  159. if err != nil {
  160. c.Fatal(err, out)
  161. }
  162. if actual := strings.Trim(out, "\r\n"); !strings.Contains(out, "timer") {
  163. c.Fatalf("expected output /dev/snd/timer, received %s", actual)
  164. }
  165. cmd = exec.Command(dockerBinary, "run", "--device", "/dev/snd:/dev/othersnd", "busybox", "sh", "-c", "ls /dev/othersnd/")
  166. out, _, err = runCommandWithOutput(cmd)
  167. if err != nil {
  168. c.Fatal(err, out)
  169. }
  170. if actual := strings.Trim(out, "\r\n"); !strings.Contains(out, "seq") {
  171. c.Fatalf("expected output /dev/othersnd/seq, received %s", actual)
  172. }
  173. }
  174. // TestRunDetach checks attaching and detaching with the escape sequence.
  175. func (s *DockerSuite) TestRunAttachDetach(c *check.C) {
  176. name := "attach-detach"
  177. cmd := exec.Command(dockerBinary, "run", "--name", name, "-it", "busybox", "cat")
  178. stdout, err := cmd.StdoutPipe()
  179. if err != nil {
  180. c.Fatal(err)
  181. }
  182. cpty, tty, err := pty.Open()
  183. if err != nil {
  184. c.Fatal(err)
  185. }
  186. defer cpty.Close()
  187. cmd.Stdin = tty
  188. if err := cmd.Start(); err != nil {
  189. c.Fatal(err)
  190. }
  191. if err := waitRun(name); err != nil {
  192. c.Fatal(err)
  193. }
  194. if _, err := cpty.Write([]byte("hello\n")); err != nil {
  195. c.Fatal(err)
  196. }
  197. out, err := bufio.NewReader(stdout).ReadString('\n')
  198. if err != nil {
  199. c.Fatal(err)
  200. }
  201. if strings.TrimSpace(out) != "hello" {
  202. c.Fatalf("expected 'hello', got %q", out)
  203. }
  204. // escape sequence
  205. if _, err := cpty.Write([]byte{16}); err != nil {
  206. c.Fatal(err)
  207. }
  208. time.Sleep(100 * time.Millisecond)
  209. if _, err := cpty.Write([]byte{17}); err != nil {
  210. c.Fatal(err)
  211. }
  212. ch := make(chan struct{})
  213. go func() {
  214. cmd.Wait()
  215. ch <- struct{}{}
  216. }()
  217. running, err := inspectField(name, "State.Running")
  218. if err != nil {
  219. c.Fatal(err)
  220. }
  221. if running != "true" {
  222. c.Fatal("expected container to still be running")
  223. }
  224. go func() {
  225. exec.Command(dockerBinary, "kill", name).Run()
  226. }()
  227. select {
  228. case <-ch:
  229. case <-time.After(10 * time.Millisecond):
  230. c.Fatal("timed out waiting for container to exit")
  231. }
  232. }
  233. // "test" should be printed
  234. func (s *DockerSuite) TestRunEchoStdoutWithCPUQuota(c *check.C) {
  235. testRequires(c, CpuCfsQuota)
  236. runCmd := exec.Command(dockerBinary, "run", "--cpu-quota", "8000", "--name", "test", "busybox", "echo", "test")
  237. out, _, _, err := runCommandWithStdoutStderr(runCmd)
  238. if err != nil {
  239. c.Fatalf("failed to run container: %v, output: %q", err, out)
  240. }
  241. out = strings.TrimSpace(out)
  242. if out != "test" {
  243. c.Errorf("container should've printed 'test'")
  244. }
  245. out, err = inspectField("test", "HostConfig.CpuQuota")
  246. c.Assert(err, check.IsNil)
  247. if out != "8000" {
  248. c.Fatalf("setting the CPU CFS quota failed")
  249. }
  250. }
  251. func (s *DockerSuite) TestRunWithCpuPeriod(c *check.C) {
  252. testRequires(c, CpuCfsPeriod)
  253. runCmd := exec.Command(dockerBinary, "run", "--cpu-period", "50000", "--name", "test", "busybox", "true")
  254. if _, err := runCommand(runCmd); err != nil {
  255. c.Fatalf("failed to run container: %v", err)
  256. }
  257. out, err := inspectField("test", "HostConfig.CpuPeriod")
  258. c.Assert(err, check.IsNil)
  259. if out != "50000" {
  260. c.Fatalf("setting the CPU CFS period failed")
  261. }
  262. }
  263. func (s *DockerSuite) TestRunOOMExitCode(c *check.C) {
  264. testRequires(c, OomControl)
  265. errChan := make(chan error)
  266. go func() {
  267. defer close(errChan)
  268. runCmd := exec.Command(dockerBinary, "run", "-m", "4MB", "busybox", "sh", "-c", "x=a; while true; do x=$x$x$x$x; done")
  269. out, exitCode, _ := runCommandWithOutput(runCmd)
  270. if expected := 137; exitCode != expected {
  271. errChan <- fmt.Errorf("wrong exit code for OOM container: expected %d, got %d (output: %q)", expected, exitCode, out)
  272. }
  273. }()
  274. select {
  275. case err := <-errChan:
  276. c.Assert(err, check.IsNil)
  277. case <-time.After(30 * time.Second):
  278. c.Fatal("Timeout waiting for container to die on OOM")
  279. }
  280. }
  281. func (s *DockerSuite) TestContainerNetworkModeToSelf(c *check.C) {
  282. cmd := exec.Command(dockerBinary, "run", "--name=me", "--net=container:me", "busybox", "true")
  283. out, _, err := runCommandWithOutput(cmd)
  284. if err == nil || !strings.Contains(out, "cannot join own network") {
  285. c.Fatalf("using container net mode to self should result in an error")
  286. }
  287. }
  288. func (s *DockerSuite) TestRunContainerNetModeWithDnsMacHosts(c *check.C) {
  289. cmd := exec.Command(dockerBinary, "run", "-d", "--name", "parent", "busybox", "top")
  290. out, _, err := runCommandWithOutput(cmd)
  291. if err != nil {
  292. c.Fatalf("failed to run container: %v, output: %q", err, out)
  293. }
  294. cmd = exec.Command(dockerBinary, "run", "--dns", "1.2.3.4", "--net=container:parent", "busybox")
  295. out, _, err = runCommandWithOutput(cmd)
  296. if err == nil || !strings.Contains(out, "Conflicting options: --dns and the network mode") {
  297. c.Fatalf("run --net=container with --dns should error out")
  298. }
  299. cmd = exec.Command(dockerBinary, "run", "--mac-address", "92:d0:c6:0a:29:33", "--net=container:parent", "busybox")
  300. out, _, err = runCommandWithOutput(cmd)
  301. if err == nil || !strings.Contains(out, "--mac-address and the network mode") {
  302. c.Fatalf("run --net=container with --mac-address should error out")
  303. }
  304. cmd = exec.Command(dockerBinary, "run", "--add-host", "test:192.168.2.109", "--net=container:parent", "busybox")
  305. out, _, err = runCommandWithOutput(cmd)
  306. if err == nil || !strings.Contains(out, "--add-host and the network mode") {
  307. c.Fatalf("run --net=container with --add-host should error out")
  308. }
  309. }
  310. func (s *DockerSuite) TestRunContainerNetModeWithExposePort(c *check.C) {
  311. cmd := exec.Command(dockerBinary, "run", "-d", "--name", "parent", "busybox", "top")
  312. out, _, err := runCommandWithOutput(cmd)
  313. if err != nil {
  314. c.Fatalf("failed to run container: %v, output: %q", err, out)
  315. }
  316. cmd = exec.Command(dockerBinary, "run", "-p", "5000:5000", "--net=container:parent", "busybox")
  317. out, _, err = runCommandWithOutput(cmd)
  318. if err == nil || !strings.Contains(out, "Conflicting options: -p, -P, --publish-all, --publish and the network mode (--net)") {
  319. c.Fatalf("run --net=container with -p should error out")
  320. }
  321. cmd = exec.Command(dockerBinary, "run", "-P", "--net=container:parent", "busybox")
  322. out, _, err = runCommandWithOutput(cmd)
  323. if err == nil || !strings.Contains(out, "Conflicting options: -p, -P, --publish-all, --publish and the network mode (--net)") {
  324. c.Fatalf("run --net=container with -P should error out")
  325. }
  326. cmd = exec.Command(dockerBinary, "run", "--expose", "5000", "--net=container:parent", "busybox")
  327. out, _, err = runCommandWithOutput(cmd)
  328. if err == nil || !strings.Contains(out, "Conflicting options: --expose and the network mode (--expose)") {
  329. c.Fatalf("run --net=container with --expose should error out")
  330. }
  331. }
  332. func (s *DockerSuite) TestRunLinkToContainerNetMode(c *check.C) {
  333. cmd := exec.Command(dockerBinary, "run", "--name", "test", "-d", "busybox", "top")
  334. out, _, err := runCommandWithOutput(cmd)
  335. if err != nil {
  336. c.Fatalf("failed to run container: %v, output: %q", err, out)
  337. }
  338. cmd = exec.Command(dockerBinary, "run", "--name", "parent", "-d", "--net=container:test", "busybox", "top")
  339. out, _, err = runCommandWithOutput(cmd)
  340. if err != nil {
  341. c.Fatalf("failed to run container: %v, output: %q", err, out)
  342. }
  343. cmd = exec.Command(dockerBinary, "run", "-d", "--link=parent:parent", "busybox", "top")
  344. out, _, err = runCommandWithOutput(cmd)
  345. if err != nil {
  346. c.Fatalf("failed to run container: %v, output: %q", err, out)
  347. }
  348. cmd = exec.Command(dockerBinary, "run", "--name", "child", "-d", "--net=container:parent", "busybox", "top")
  349. out, _, err = runCommandWithOutput(cmd)
  350. if err != nil {
  351. c.Fatalf("failed to run container: %v, output: %q", err, out)
  352. }
  353. cmd = exec.Command(dockerBinary, "run", "-d", "--link=child:child", "busybox", "top")
  354. out, _, err = runCommandWithOutput(cmd)
  355. if err != nil {
  356. c.Fatalf("failed to run container: %v, output: %q", err, out)
  357. }
  358. }
  359. func (s *DockerSuite) TestRunLoopbackOnlyExistsWhenNetworkingDisabled(c *check.C) {
  360. cmd := exec.Command(dockerBinary, "run", "--net=none", "busybox", "ip", "-o", "-4", "a", "show", "up")
  361. out, _, err := runCommandWithOutput(cmd)
  362. if err != nil {
  363. c.Fatal(err, out)
  364. }
  365. var (
  366. count = 0
  367. parts = strings.Split(out, "\n")
  368. )
  369. for _, l := range parts {
  370. if l != "" {
  371. count++
  372. }
  373. }
  374. if count != 1 {
  375. c.Fatalf("Wrong interface count in container %d", count)
  376. }
  377. if !strings.HasPrefix(out, "1: lo") {
  378. c.Fatalf("Wrong interface in test container: expected [1: lo], got %s", out)
  379. }
  380. }
  381. // Issue #4681
  382. func (s *DockerSuite) TestRunLoopbackWhenNetworkDisabled(c *check.C) {
  383. cmd := exec.Command(dockerBinary, "run", "--net=none", "busybox", "ping", "-c", "1", "127.0.0.1")
  384. if _, err := runCommand(cmd); err != nil {
  385. c.Fatal(err)
  386. }
  387. }
  388. func (s *DockerSuite) TestRunModeNetContainerHostname(c *check.C) {
  389. testRequires(c, ExecSupport)
  390. cmd := exec.Command(dockerBinary, "run", "-i", "-d", "--name", "parent", "busybox", "top")
  391. out, _, err := runCommandWithOutput(cmd)
  392. if err != nil {
  393. c.Fatalf("failed to run container: %v, output: %q", err, out)
  394. }
  395. cmd = exec.Command(dockerBinary, "exec", "parent", "cat", "/etc/hostname")
  396. out, _, err = runCommandWithOutput(cmd)
  397. if err != nil {
  398. c.Fatalf("failed to exec command: %v, output: %q", err, out)
  399. }
  400. cmd = exec.Command(dockerBinary, "run", "--net=container:parent", "busybox", "cat", "/etc/hostname")
  401. out1, _, err := runCommandWithOutput(cmd)
  402. if err != nil {
  403. c.Fatalf("failed to run container: %v, output: %q", err, out1)
  404. }
  405. if out1 != out {
  406. c.Fatal("containers with shared net namespace should have same hostname")
  407. }
  408. }
  409. func (s *DockerSuite) TestRunNetworkNotInitializedNoneMode(c *check.C) {
  410. cmd := exec.Command(dockerBinary, "run", "-d", "--net=none", "busybox", "top")
  411. out, _, err := runCommandWithOutput(cmd)
  412. if err != nil {
  413. c.Fatal(err)
  414. }
  415. id := strings.TrimSpace(out)
  416. res, err := inspectField(id, "NetworkSettings.IPAddress")
  417. c.Assert(err, check.IsNil)
  418. if res != "" {
  419. c.Fatalf("For 'none' mode network must not be initialized, but container got IP: %s", res)
  420. }
  421. }
  422. func (s *DockerSuite) TestTwoContainersInNetHost(c *check.C) {
  423. dockerCmd(c, "run", "-d", "--net=host", "--name=first", "busybox", "top")
  424. dockerCmd(c, "run", "-d", "--net=host", "--name=second", "busybox", "top")
  425. dockerCmd(c, "stop", "first")
  426. dockerCmd(c, "stop", "second")
  427. }