2018-02-05 21:05:59 +00:00
package remotecontext // import "github.com/docker/docker/builder/remotecontext"
2017-03-20 22:22:29 +00:00
import (
"bufio"
2023-06-23 00:33:17 +00:00
"context"
2017-03-20 22:22:29 +00:00
"fmt"
"io"
"os"
2024-01-02 14:32:31 +00:00
"path/filepath"
2018-08-14 22:07:46 +00:00
"runtime"
2017-03-20 22:22:29 +00:00
"strings"
2017-08-04 00:22:00 +00:00
"github.com/containerd/continuity/driver"
2023-09-13 15:41:45 +00:00
"github.com/containerd/log"
2017-04-13 18:37:32 +00:00
"github.com/docker/docker/api/types/backend"
2017-03-20 22:22:29 +00:00
"github.com/docker/docker/builder"
pkg/urlutil: deprecate, and move to builder/remotecontext/urlutil
pkg/urlutil (despite its poorly chosen name) is not really intended as a generic
utility to handle URLs, and should only be used by the builder to handle (remote)
build contexts.
- IsURL() only does a very rudimentary check for http(s):// prefixes, without any
other validation, but due to its name may give incorrect expectations.
- IsGitURL() is written specifically with docker build remote git contexts in
mind, and has handling for backward-compatibility, where strings that are
not URLs, but start with "github.com/" are accepted.
Because of the above, this patch:
- moves the package inside builder/remotecontext, close to where it's intended
to be used (ideally this would be part of build/remotecontext itself, but this
package imports many other dependencies, which would introduce those as extra
dependencies in the CLI).
- deprecates pkg/urlutil, but adds aliases as there are some external consumers.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2022-04-10 14:57:45 +00:00
"github.com/docker/docker/builder/remotecontext/urlutil"
2019-01-03 21:49:48 +00:00
"github.com/docker/docker/errdefs"
2018-06-02 16:46:53 +00:00
"github.com/moby/buildkit/frontend/dockerfile/parser"
2022-09-30 19:53:24 +00:00
"github.com/moby/patternmatcher"
2023-08-22 22:53:18 +00:00
"github.com/moby/patternmatcher/ignorefile"
2024-01-02 14:32:31 +00:00
"github.com/moby/sys/symlink"
2017-03-20 22:22:29 +00:00
"github.com/pkg/errors"
)
2017-05-15 21:54:27 +00:00
// ClientSessionRemote is identifier for client-session context transport
const ClientSessionRemote = "client-session"
2017-03-20 22:22:29 +00:00
// Detect returns a context and dockerfile from remote location or local
2018-07-03 00:12:56 +00:00
// archive.
2017-04-13 18:37:32 +00:00
func Detect ( config backend . BuildConfig ) ( remote builder . Source , dockerfile * parser . Result , err error ) {
remoteURL := config . Options . RemoteContext
dockerfilePath := config . Options . Dockerfile
2017-03-20 22:22:29 +00:00
switch {
case remoteURL == "" :
2017-04-13 18:37:32 +00:00
remote , dockerfile , err = newArchiveRemote ( config . Source , dockerfilePath )
2017-05-15 21:54:27 +00:00
case remoteURL == ClientSessionRemote :
builder: fix detection of experimental --stream option (deprecated)
Commit 6ca3ec88ae9e1435abbed665ec598c00058659da deprecated the experimental
"--stream" option for the legacy builder, adding an error message is a client
attempted to use this feature.
However, the detection used the session-ID (`session=xxx` query parameter),
which happens to be set automatically by the CLI if it detects that the daemon
has session support. Because of this, builds fail when trying to perform them
on a daemon with the `--experimental` flag set.
This patch changes the detection to look for the `remote` query parameter, which
is set to "client-session" when using the `--stream` option with the classic
(non-Buildkit) builder.
Before this change, running `docker build` with an older (19.03 or older) cli
against a daemon with `--experimental` enabled caused an error:
$ dockerd --experimental &
$ docker pull docker:18.09
$ docker run -it --rm -v /var/run/docker.sock:/var/run/docker.sock docker:18.09 sh -c 'echo "FROM scratch" | docker build -'
Sending build context to Docker daemon 2.048kB
Error response from daemon: experimental session with v1 builder is no longer supported, use builder version v2 (BuildKit) instead
docker run -it --rm -v /var/run/docker.sock:/var/run/docker.sock -w /foo docker:18.09 sh -c 'echo "FROM scratch" > Dockerfile && docker build --stream .'
Error response from daemon: experimental session with v1 builder is no longer supported, use builder version v2 (BuildKit) instead
With this patch, the error only occurs when trying to use the experimental
`--stream` option:
$ dockerd --experimental &
$ docker pull docker:18.09
$ docker run -it --rm -v /var/run/docker.sock:/var/run/docker.sock docker:18.09 sh -c 'echo "FROM scratch" | docker build -'
Step 1/1 : FROM scratch
--->
No image was generated. Is your Dockerfile empty?
$ docker run -it --rm -v /var/run/docker.sock:/var/run/docker.sock -w /foo docker:18.09 sh -c 'echo "FROM scratch" > Dockerfile && docker build --stream .'
Error response from daemon: experimental session with v1 builder is no longer supported, use builder version v2 (BuildKit) instead
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2020-11-06 20:13:28 +00:00
return nil , nil , errdefs . InvalidParameter ( errors . New ( "experimental session with v1 builder is no longer supported, use builder version v2 (BuildKit) instead" ) )
2017-03-20 22:22:29 +00:00
case urlutil . IsGitURL ( remoteURL ) :
remote , dockerfile , err = newGitRemote ( remoteURL , dockerfilePath )
case urlutil . IsURL ( remoteURL ) :
2017-04-13 18:37:32 +00:00
remote , dockerfile , err = newURLRemote ( remoteURL , dockerfilePath , config . ProgressWriter . ProgressReaderFunc )
2017-03-20 22:22:29 +00:00
default :
err = fmt . Errorf ( "remoteURL (%s) could not be recognized as URL" , remoteURL )
}
return
}
func newArchiveRemote ( rc io . ReadCloser , dockerfilePath string ) ( builder . Source , * parser . Result , error ) {
2017-05-23 23:29:13 +00:00
defer rc . Close ( )
2017-05-15 21:54:27 +00:00
c , err := FromArchive ( rc )
2017-03-20 22:22:29 +00:00
if err != nil {
return nil , nil , err
}
return withDockerfileFromContext ( c . ( modifiableContext ) , dockerfilePath )
}
func withDockerfileFromContext ( c modifiableContext , dockerfilePath string ) ( builder . Source , * parser . Result , error ) {
df , err := openAt ( c , dockerfilePath )
if err != nil {
2020-04-17 10:01:01 +00:00
if errors . Is ( err , os . ErrNotExist ) {
2017-03-20 22:22:29 +00:00
if dockerfilePath == builder . DefaultDockerfileName {
lowercase := strings . ToLower ( dockerfilePath )
if _ , err := StatAt ( c , lowercase ) ; err == nil {
return withDockerfileFromContext ( c , lowercase )
}
}
return nil , nil , errors . Errorf ( "Cannot locate specified Dockerfile: %s" , dockerfilePath ) // backwards compatible error
}
c . Close ( )
return nil , nil , err
}
res , err := readAndParseDockerfile ( dockerfilePath , df )
if err != nil {
return nil , nil , err
}
df . Close ( )
if err := removeDockerfile ( c , dockerfilePath ) ; err != nil {
c . Close ( )
return nil , nil , err
}
return c , res , nil
}
func newGitRemote ( gitURL string , dockerfilePath string ) ( builder . Source , * parser . Result , error ) {
2017-05-25 20:02:29 +00:00
c , err := MakeGitContext ( gitURL ) // TODO: change this to NewLazySource
2017-03-20 22:22:29 +00:00
if err != nil {
return nil , nil , err
}
return withDockerfileFromContext ( c . ( modifiableContext ) , dockerfilePath )
}
func newURLRemote ( url string , dockerfilePath string , progressReader func ( in io . ReadCloser ) io . ReadCloser ) ( builder . Source , * parser . Result , error ) {
2017-11-08 18:06:57 +00:00
contentType , content , err := downloadRemote ( url )
if err != nil {
2017-03-20 22:22:29 +00:00
return nil , nil , err
}
2017-11-08 18:06:57 +00:00
defer content . Close ( )
switch contentType {
2023-05-26 00:28:35 +00:00
case mimeTypeTextPlain :
2017-11-08 18:06:57 +00:00
res , err := parser . Parse ( progressReader ( content ) )
2019-01-03 21:49:48 +00:00
return nil , res , errdefs . InvalidParameter ( err )
2017-11-08 18:06:57 +00:00
default :
source , err := FromArchive ( progressReader ( content ) )
if err != nil {
return nil , nil , err
}
return withDockerfileFromContext ( source . ( modifiableContext ) , dockerfilePath )
}
2017-03-20 22:22:29 +00:00
}
func removeDockerfile ( c modifiableContext , filesToRemove ... string ) error {
f , err := openAt ( c , ".dockerignore" )
// Note that a missing .dockerignore file isn't treated as an error
switch {
case os . IsNotExist ( err ) :
return nil
case err != nil :
return err
}
2023-08-22 22:53:18 +00:00
excludes , err := ignorefile . ReadAll ( f )
2017-05-05 05:33:40 +00:00
if err != nil {
2017-06-28 06:49:12 +00:00
f . Close ( )
2023-08-22 22:53:18 +00:00
return errors . Wrap ( err , "error reading .dockerignore" )
2017-05-05 05:33:40 +00:00
}
2017-03-20 22:22:29 +00:00
f . Close ( )
filesToRemove = append ( [ ] string { ".dockerignore" } , filesToRemove ... )
for _ , fileToRemove := range filesToRemove {
2022-09-30 19:53:24 +00:00
if rm , _ := patternmatcher . MatchesOrParentMatches ( fileToRemove , excludes ) ; rm {
2017-03-20 22:22:29 +00:00
if err := c . Remove ( fileToRemove ) ; err != nil {
2023-06-23 00:33:17 +00:00
log . G ( context . TODO ( ) ) . Errorf ( "failed to remove %s: %v" , fileToRemove , err )
2017-03-20 22:22:29 +00:00
}
}
}
return nil
}
func readAndParseDockerfile ( name string , rc io . Reader ) ( * parser . Result , error ) {
br := bufio . NewReader ( rc )
if _ , err := br . Peek ( 1 ) ; err != nil {
if err == io . EOF {
2019-01-03 21:49:48 +00:00
return nil , errdefs . InvalidParameter ( errors . Errorf ( "the Dockerfile (%s) cannot be empty" , name ) )
2017-03-20 22:22:29 +00:00
}
return nil , errors . Wrap ( err , "unexpected error reading Dockerfile" )
}
2019-01-03 21:49:48 +00:00
dockerfile , err := parser . Parse ( br )
if err != nil {
return nil , errdefs . InvalidParameter ( errors . Wrapf ( err , "failed to parse %s" , name ) )
}
return dockerfile , nil
2017-03-20 22:22:29 +00:00
}
2017-08-04 00:22:00 +00:00
func openAt ( remote builder . Source , path string ) ( driver . File , error ) {
2017-03-20 22:22:29 +00:00
fullPath , err := FullPath ( remote , path )
if err != nil {
return nil , err
}
2022-09-23 00:59:58 +00:00
return os . Open ( fullPath )
2017-03-20 22:22:29 +00:00
}
// StatAt is a helper for calling Stat on a path from a source
func StatAt ( remote builder . Source , path string ) ( os . FileInfo , error ) {
fullPath , err := FullPath ( remote , path )
if err != nil {
return nil , err
}
2022-09-23 00:59:58 +00:00
return os . Stat ( fullPath )
2017-03-20 22:22:29 +00:00
}
// FullPath is a helper for getting a full path for a path from a source
func FullPath ( remote builder . Source , path string ) ( string , error ) {
2024-01-02 14:32:31 +00:00
remoteRoot := remote . Root ( )
fullPath , err := symlink . FollowSymlinkInScope ( filepath . Join ( remoteRoot , path ) , remoteRoot )
2017-03-20 22:22:29 +00:00
if err != nil {
2018-08-14 22:07:46 +00:00
if runtime . GOOS == "windows" {
return "" , fmt . Errorf ( "failed to resolve scoped path %s (%s): %s. Possible cause is a forbidden path outside the build context" , path , fullPath , err )
}
2020-08-07 18:51:23 +00:00
return "" , fmt . Errorf ( "forbidden path outside the build context: %s (%s)" , path , fullPath ) // backwards compat with old error
2017-03-20 22:22:29 +00:00
}
return fullPath , nil
}