moby/libnetwork
Cory Snider 5ef9e2632f libnetwork/datastore: prevent data races in Key()
The rootChain variable that the Key function references is a
package-global slice. As the append() built-in may append to the slice's
backing array in place, it is theoretically possible for the temporary
slices in concurrent Key() calls to share the same backing array, which
would be a data race. Thankfully in my tests (on Go 1.20.6)

    cap(rootChain) == len(rootChain)

held true, so in practice a new slice is always allocated and there is
no race. But that is a very brittle assumption to depend upon, which
could blow up in our faces at any time without warning. Rewrite the
implementation in a way which cannot lead to data races.

Signed-off-by: Cory Snider <csnider@mirantis.com>
2023-07-24 12:18:04 -04:00
..
bitmap libnetwork/bitmap: improve documentation 2023-07-05 16:10:32 -04:00
cluster Switch from x/net/context -> context 2018-04-24 14:57:04 -07:00
cmd libnetwork/networkdb: NetworkDB.Watch(): remove unused "key" argument 2023-07-05 12:30:20 +02:00
config libnetwork/config: add Config.DriverConfig() and un-export DriverCfg 2023-07-17 09:57:14 +02:00
datastore libnetwork/datastore: prevent data races in Key() 2023-07-24 12:18:04 -04:00
diagnostic Switch all logging to use containerd log pkg 2023-06-24 00:23:44 +00:00
discoverapi libnetwork: drop DatastoreConfig discovery type 2023-01-27 11:47:43 -05:00
docs libnetwork/docs: fix broken link 2023-05-10 12:05:05 +02:00
driverapi libnetwork: drop legacy driver cruft 2023-07-07 15:02:58 -04:00
drivers Merge pull request #45987 from thaJeztah/cleanup_iptables_the_sequel 2023-07-19 14:38:12 +02:00
drvregistry libnetwork: drop legacy driver cruft 2023-07-07 15:02:58 -04:00
etchosts libnetwork/etchosts: format code with gofumpt 2023-06-29 00:31:48 +02:00
internal libnetwork/internal/kvstore: remove unused Delete() 2023-07-05 12:30:20 +02:00
ipam libnetwork/ipam(s): format code with gofumpt 2023-06-29 00:31:47 +02:00
ipamapi libnetwork: drop legacy driver cruft 2023-07-07 15:02:58 -04:00
ipams libnetwork: drop legacy driver cruft 2023-07-07 15:02:58 -04:00
ipamutils libnetwork/ipamutils: format code with gofumpt 2023-06-29 00:31:49 +02:00
ipbits libnet/ipam: use netip types internally 2023-02-23 18:10:01 -05:00
iptables libnetwork/iptables: move IPTable.LoopbackByVersion() to a utility 2023-07-16 21:53:36 +02:00
netlabel libnetwork/netlabel: remove dead code 2023-04-06 19:51:56 +02:00
netutils libnetwork/netutils: format code with gofumpt 2023-06-29 00:31:48 +02:00
networkdb libnetwork/networkdb: NetworkDB.Watch(): remove unused "key" argument 2023-07-05 12:30:20 +02:00
ns Switch all logging to use containerd log pkg 2023-06-24 00:23:44 +00:00
options libnetwork/options: remove unused NewGeneric, and use map[string]any 2023-07-16 19:39:59 +02:00
osl libnetwork/osl: format code with gofumpt 2023-06-29 00:31:48 +02:00
portallocator libnetwork/portallocator: format code with gofumpt 2023-06-29 00:31:48 +02:00
portmapper libnetwork: format code with gofumpt 2023-06-29 00:31:49 +02:00
resolvconf libnetwork/resolvconf: format code with gofumpt 2023-06-29 00:31:48 +02:00
support Fixup libnetwork lint errors 2021-06-01 23:48:32 +00:00
testutils Merge pull request #45586 from corhere/fix-flaky-resolver-test 2023-05-19 20:45:38 -06:00
types libnetwork: format code with gofumpt 2023-06-29 00:31:49 +02:00
.dockerignore Added back dockerignore 2018-06-22 16:10:22 -07:00
.gitignore Added back dockerignore 2018-06-22 16:10:22 -07:00
agent.go libnetwork/networkdb: NetworkDB.Watch(): remove unused "key" argument 2023-07-05 12:30:20 +02:00
agent.pb.go update generated files 2023-05-29 03:28:35 +02:00
agent.proto fix protos and "go generate" commands 2023-05-29 03:28:35 +02:00
controller.go libnetwork/config: add Config.DriverConfig() and un-export DriverCfg 2023-07-17 09:57:14 +02:00
default_gateway.go Switch all logging to use containerd log pkg 2023-06-24 00:23:44 +00:00
default_gateway_freebsd.go libnetwork: return concrete-typed *Controller 2023-01-13 14:09:37 -05:00
default_gateway_linux.go libnetwork: format code with gofumpt 2023-06-29 00:31:49 +02:00
default_gateway_windows.go libnetwork: format code with gofumpt 2023-06-29 00:31:49 +02:00
drivers_freebsd.go libnet/drivers: stop passing config to drivers... 2023-07-06 12:57:00 -04:00
drivers_ipam.go libnet: un-plumb datastores from IPAM inits 2023-01-27 11:47:42 -05:00
drivers_linux.go libnet/drivers: stop passing config to drivers... 2023-07-06 12:57:00 -04:00
drivers_unsupported.go libn: refactor platform driver registration 2023-07-06 12:56:09 -04:00
drivers_windows.go libnet/drivers: stop passing config to drivers... 2023-07-06 12:57:00 -04:00
endpoint.go Switch all logging to use containerd log pkg 2023-06-24 00:23:44 +00:00
endpoint_cnt.go libnetwork: remove more datastore scope plumbing 2023-01-26 17:56:40 -05:00
endpoint_info.go libnetwork: return concrete-typed *Endpoint 2023-01-13 14:19:06 -05:00
endpoint_info_unix.go remove pre-go1.17 build-tags 2023-05-19 20:38:51 +02:00
endpoint_info_windows.go remove pre-go1.17 build-tags 2023-05-19 20:38:51 +02:00
endpoint_test.go remove pre-go1.17 build-tags 2023-05-19 20:38:51 +02:00
error.go libnetwork: remove more datastore scope plumbing 2023-01-26 17:56:40 -05:00
errors_test.go libnetwork: fix empty-lines (revive) 2022-09-26 19:21:58 +02:00
firewall_linux.go Switch all logging to use containerd log pkg 2023-06-24 00:23:44 +00:00
firewall_linux_test.go Merge pull request #45987 from thaJeztah/cleanup_iptables_the_sequel 2023-07-19 14:38:12 +02:00
firewall_others.go remove pre-go1.17 build-tags 2023-05-19 20:38:51 +02:00
libnetwork_internal_test.go libnetwork: format code with gofumpt 2023-06-29 00:31:49 +02:00
libnetwork_linux_test.go libnetwork: format code with gofumpt 2023-06-29 00:31:49 +02:00
libnetwork_test.go libnetwork/config: remove options that were only used in tests 2023-07-05 12:30:21 +02:00
libnetwork_unix_test.go remove pre-go1.17 build-tags 2023-05-19 20:38:51 +02:00
libnetwork_windows_test.go libnetwork: format code with gofumpt 2023-06-29 00:31:49 +02:00
network.go libnetwork/config: remove IsValidName utility 2023-07-16 19:42:44 +02:00
network_unix.go remove pre-go1.17 build-tags 2023-05-19 20:38:51 +02:00
network_windows.go Switch all logging to use containerd log pkg 2023-06-24 00:23:44 +00:00
README.md libnetwork: update example in README.md 2023-05-10 12:01:06 +02:00
resolver.go Switch all logging to use containerd log pkg 2023-06-24 00:23:44 +00:00
resolver_test.go Switch all logging to use containerd log pkg 2023-06-24 00:23:44 +00:00
resolver_unix.go libn: fix resolver restore w/ chatty 'iptables -C' 2023-05-30 14:32:27 -04:00
resolver_windows.go remove pre-go1.17 build-tags 2023-05-19 20:38:51 +02:00
sandbox.go libnetwork: format code with gofumpt 2023-06-29 00:31:49 +02:00
sandbox_dns_unix.go Switch all logging to use containerd log pkg 2023-06-24 00:23:44 +00:00
sandbox_dns_windows.go remove pre-go1.17 build-tags 2023-05-19 20:38:51 +02:00
sandbox_externalkey_unix.go libnetwork: format code with gofumpt 2023-06-29 00:31:49 +02:00
sandbox_externalkey_unsupported.go remove pre-go1.17 build-tags 2023-05-19 20:38:51 +02:00
sandbox_store.go Switch all logging to use containerd log pkg 2023-06-24 00:23:44 +00:00
sandbox_test.go libnetwork: getTestEnv(): use literals for options 2023-07-16 20:29:50 +02:00
service.go libn/i/setmatrix: make generic and constructorless 2023-03-29 13:31:12 -04:00
service_common.go Switch all logging to use containerd log pkg 2023-06-24 00:23:44 +00:00
service_common_test.go libnetwork: return concrete-typed *Sandbox 2023-01-13 14:19:06 -05:00
service_linux.go libnetwork: format code with gofumpt 2023-06-29 00:31:49 +02:00
service_unsupported.go remove pre-go1.17 build-tags 2023-05-19 20:38:51 +02:00
service_windows.go libnetwork: format code with gofumpt 2023-06-29 00:31:49 +02:00
store.go libnetwork/datastore: remove Watch(), Watchable(), RestartWatch() 2023-07-05 12:30:19 +02:00
store_linux_test.go Merge pull request #45886 from thaJeztah/more_grepable 2023-07-05 07:02:14 -06:00
store_test.go Merge pull request #45886 from thaJeztah/more_grepable 2023-07-05 07:02:14 -06:00

libnetwork - networking for containers

Libnetwork provides a native Go implementation for connecting containers

The goal of libnetwork is to deliver a robust Container Network Model that provides a consistent programming interface and the required network abstractions for applications.

Design

Please refer to the design for more information.

Using libnetwork

There are many networking solutions available to suit a broad range of use-cases. libnetwork uses a driver / plugin model to support all of these solutions while abstracting the complexity of the driver implementations by exposing a simple and consistent Network Model to users.

package main

import (
	"fmt"
	"log"

	"github.com/docker/docker/libnetwork"
	"github.com/docker/docker/libnetwork/config"
	"github.com/docker/docker/libnetwork/netlabel"
	"github.com/docker/docker/libnetwork/options"
)

func main() {
	// Select and configure the network driver
	networkType := "bridge"

	// Create a new controller instance
	driverOptions := options.Generic{}
	genericOption := make(map[string]interface{})
	genericOption[netlabel.GenericData] = driverOptions
	controller, err := libnetwork.New(config.OptionDriverConfig(networkType, genericOption))
	if err != nil {
		log.Fatalf("libnetwork.New: %s", err)
	}

	// Create a network for containers to join.
	// NewNetwork accepts Variadic optional arguments that libnetwork and Drivers can use.
	network, err := controller.NewNetwork(networkType, "network1", "")
	if err != nil {
		log.Fatalf("controller.NewNetwork: %s", err)
	}

	// For each new container: allocate IP and interfaces. The returned network
	// settings will be used for container infos (inspect and such), as well as
	// iptables rules for port publishing. This info is contained or accessible
	// from the returned endpoint.
	ep, err := network.CreateEndpoint("Endpoint1")
	if err != nil {
		log.Fatalf("network.CreateEndpoint: %s", err)
	}

	// Create the sandbox for the container.
	// NewSandbox accepts Variadic optional arguments which libnetwork can use.
	sbx, err := controller.NewSandbox("container1",
		libnetwork.OptionHostname("test"),
		libnetwork.OptionDomainname("example.com"))
	if err != nil {
		log.Fatalf("controller.NewSandbox: %s", err)
	}

	// A sandbox can join the endpoint via the join api.
	err = ep.Join(sbx)
	if err != nil {
		log.Fatalf("ep.Join: %s", err)
	}

	// libnetwork client can check the endpoint's operational data via the Info() API
	epInfo, err := ep.DriverInfo()
	if err != nil {
		log.Fatalf("ep.DriverInfo: %s", err)
	}

	macAddress, ok := epInfo[netlabel.MacAddress]
	if !ok {
		log.Fatal("failed to get mac address from endpoint info")
	}

	fmt.Printf("Joined endpoint %s (%s) to sandbox %s (%s)\n", ep.Name(), macAddress, sbx.ContainerID(), sbx.Key())
}

Contributing

Want to hack on libnetwork? Docker's contributions guidelines apply.

Code and documentation copyright 2015 Docker, inc. Code released under the Apache 2.0 license. Docs released under Creative commons.