2019-01-12 04:58:27 +00:00
|
|
|
/*
|
2020-08-10 17:43:49 +00:00
|
|
|
Copyright The containerd Authors.
|
2019-01-12 04:58:27 +00:00
|
|
|
|
2020-08-10 17:43:49 +00:00
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
you may not use this file except in compliance with the License.
|
|
|
|
You may obtain a copy of the License at
|
2019-01-12 04:58:27 +00:00
|
|
|
|
2020-08-10 17:43:49 +00:00
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
2019-01-12 04:58:27 +00:00
|
|
|
|
2020-08-10 17:43:49 +00:00
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
See the License for the specific language governing permissions and
|
|
|
|
limitations under the License.
|
2019-01-12 04:58:27 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
package server
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"path"
|
|
|
|
"path/filepath"
|
|
|
|
"strconv"
|
|
|
|
"strings"
|
|
|
|
|
|
|
|
"github.com/BurntSushi/toml"
|
2020-08-10 17:43:49 +00:00
|
|
|
runhcsoptions "github.com/Microsoft/hcsshim/cmd/containerd-shim-runhcs-v1/options"
|
2019-08-30 18:33:25 +00:00
|
|
|
"github.com/containerd/containerd"
|
2019-01-12 04:58:27 +00:00
|
|
|
"github.com/containerd/containerd/containers"
|
2019-09-27 21:51:53 +00:00
|
|
|
"github.com/containerd/containerd/plugin"
|
2020-08-10 17:43:49 +00:00
|
|
|
"github.com/containerd/containerd/reference/docker"
|
2019-01-12 04:58:27 +00:00
|
|
|
"github.com/containerd/containerd/runtime/linux/runctypes"
|
|
|
|
runcoptions "github.com/containerd/containerd/runtime/v2/runc/options"
|
|
|
|
"github.com/containerd/typeurl"
|
|
|
|
imagedigest "github.com/opencontainers/go-digest"
|
|
|
|
"github.com/pkg/errors"
|
|
|
|
"golang.org/x/net/context"
|
2019-08-30 18:33:25 +00:00
|
|
|
runtime "k8s.io/cri-api/pkg/apis/runtime/v1alpha2"
|
2019-01-12 04:58:27 +00:00
|
|
|
|
2019-09-27 21:51:53 +00:00
|
|
|
runtimeoptions "github.com/containerd/cri/pkg/api/runtimeoptions/v1"
|
2019-01-12 04:58:27 +00:00
|
|
|
criconfig "github.com/containerd/cri/pkg/config"
|
|
|
|
"github.com/containerd/cri/pkg/store"
|
2019-02-08 04:04:22 +00:00
|
|
|
containerstore "github.com/containerd/cri/pkg/store/container"
|
2019-01-12 04:58:27 +00:00
|
|
|
imagestore "github.com/containerd/cri/pkg/store/image"
|
2019-02-08 04:04:22 +00:00
|
|
|
sandboxstore "github.com/containerd/cri/pkg/store/sandbox"
|
2019-01-12 04:58:27 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
const (
|
|
|
|
// errorStartReason is the exit reason when fails to start container.
|
|
|
|
errorStartReason = "StartError"
|
|
|
|
// errorStartExitCode is the exit code when fails to start container.
|
|
|
|
// 128 is the same with Docker's behavior.
|
2020-08-10 17:43:49 +00:00
|
|
|
// TODO(windows): Figure out what should be used for windows.
|
2019-01-12 04:58:27 +00:00
|
|
|
errorStartExitCode = 128
|
|
|
|
// completeExitReason is the exit reason when container exits with code 0.
|
|
|
|
completeExitReason = "Completed"
|
|
|
|
// errorExitReason is the exit reason when container exits with code non-zero.
|
|
|
|
errorExitReason = "Error"
|
|
|
|
// oomExitReason is the exit reason when process in container is oom killed.
|
|
|
|
oomExitReason = "OOMKilled"
|
|
|
|
|
|
|
|
// sandboxesDir contains all sandbox root. A sandbox root is the running
|
|
|
|
// directory of the sandbox, all files created for the sandbox will be
|
|
|
|
// placed under this directory.
|
|
|
|
sandboxesDir = "sandboxes"
|
|
|
|
// containersDir contains all container root.
|
|
|
|
containersDir = "containers"
|
|
|
|
// Delimiter used to construct container/sandbox names.
|
|
|
|
nameDelimiter = "_"
|
|
|
|
|
|
|
|
// criContainerdPrefix is common prefix for cri-containerd
|
|
|
|
criContainerdPrefix = "io.cri-containerd"
|
|
|
|
// containerKindLabel is a label key indicating container is sandbox container or application container
|
|
|
|
containerKindLabel = criContainerdPrefix + ".kind"
|
|
|
|
// containerKindSandbox is a label value indicating container is sandbox container
|
|
|
|
containerKindSandbox = "sandbox"
|
|
|
|
// containerKindContainer is a label value indicating container is application container
|
|
|
|
containerKindContainer = "container"
|
|
|
|
// imageLabelKey is the label key indicating the image is managed by cri plugin.
|
|
|
|
imageLabelKey = criContainerdPrefix + ".image"
|
|
|
|
// imageLabelValue is the label value indicating the image is managed by cri plugin.
|
|
|
|
imageLabelValue = "managed"
|
|
|
|
// sandboxMetadataExtension is an extension name that identify metadata of sandbox in CreateContainerRequest
|
|
|
|
sandboxMetadataExtension = criContainerdPrefix + ".sandbox.metadata"
|
|
|
|
// containerMetadataExtension is an extension name that identify metadata of container in CreateContainerRequest
|
|
|
|
containerMetadataExtension = criContainerdPrefix + ".container.metadata"
|
|
|
|
|
|
|
|
// defaultIfName is the default network interface for the pods
|
|
|
|
defaultIfName = "eth0"
|
2020-08-10 17:43:49 +00:00
|
|
|
|
|
|
|
// runtimeRunhcsV1 is the runtime type for runhcs.
|
|
|
|
runtimeRunhcsV1 = "io.containerd.runhcs.v1"
|
2019-01-12 04:58:27 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
// makeSandboxName generates sandbox name from sandbox metadata. The name
|
|
|
|
// generated is unique as long as sandbox metadata is unique.
|
|
|
|
func makeSandboxName(s *runtime.PodSandboxMetadata) string {
|
|
|
|
return strings.Join([]string{
|
2019-04-09 17:34:40 +00:00
|
|
|
s.Name, // 0
|
|
|
|
s.Namespace, // 1
|
|
|
|
s.Uid, // 2
|
2019-01-12 04:58:27 +00:00
|
|
|
fmt.Sprintf("%d", s.Attempt), // 3
|
|
|
|
}, nameDelimiter)
|
|
|
|
}
|
|
|
|
|
|
|
|
// makeContainerName generates container name from sandbox and container metadata.
|
|
|
|
// The name generated is unique as long as the sandbox container combination is
|
|
|
|
// unique.
|
|
|
|
func makeContainerName(c *runtime.ContainerMetadata, s *runtime.PodSandboxMetadata) string {
|
|
|
|
return strings.Join([]string{
|
2019-04-09 17:34:40 +00:00
|
|
|
c.Name, // 0
|
|
|
|
s.Name, // 1: pod name
|
|
|
|
s.Namespace, // 2: pod namespace
|
|
|
|
s.Uid, // 3: pod uid
|
2019-01-12 04:58:27 +00:00
|
|
|
fmt.Sprintf("%d", c.Attempt), // 4
|
|
|
|
}, nameDelimiter)
|
|
|
|
}
|
|
|
|
|
|
|
|
// getSandboxRootDir returns the root directory for managing sandbox files,
|
|
|
|
// e.g. hosts files.
|
|
|
|
func (c *criService) getSandboxRootDir(id string) string {
|
|
|
|
return filepath.Join(c.config.RootDir, sandboxesDir, id)
|
|
|
|
}
|
|
|
|
|
|
|
|
// getVolatileSandboxRootDir returns the root directory for managing volatile sandbox files,
|
|
|
|
// e.g. named pipes.
|
|
|
|
func (c *criService) getVolatileSandboxRootDir(id string) string {
|
|
|
|
return filepath.Join(c.config.StateDir, sandboxesDir, id)
|
|
|
|
}
|
|
|
|
|
|
|
|
// getContainerRootDir returns the root directory for managing container files,
|
|
|
|
// e.g. state checkpoint.
|
|
|
|
func (c *criService) getContainerRootDir(id string) string {
|
|
|
|
return filepath.Join(c.config.RootDir, containersDir, id)
|
|
|
|
}
|
|
|
|
|
|
|
|
// getVolatileContainerRootDir returns the root directory for managing volatile container files,
|
|
|
|
// e.g. named pipes.
|
|
|
|
func (c *criService) getVolatileContainerRootDir(id string) string {
|
|
|
|
return filepath.Join(c.config.StateDir, containersDir, id)
|
|
|
|
}
|
|
|
|
|
|
|
|
// criContainerStateToString formats CRI container state to string.
|
|
|
|
func criContainerStateToString(state runtime.ContainerState) string {
|
|
|
|
return runtime.ContainerState_name[int32(state)]
|
|
|
|
}
|
|
|
|
|
|
|
|
// getRepoDigestAngTag returns image repoDigest and repoTag of the named image reference.
|
2020-08-10 17:43:49 +00:00
|
|
|
func getRepoDigestAndTag(namedRef docker.Named, digest imagedigest.Digest, schema1 bool) (string, string) {
|
2019-01-12 04:58:27 +00:00
|
|
|
var repoTag, repoDigest string
|
2020-08-10 17:43:49 +00:00
|
|
|
if _, ok := namedRef.(docker.NamedTagged); ok {
|
2019-01-12 04:58:27 +00:00
|
|
|
repoTag = namedRef.String()
|
|
|
|
}
|
2020-08-10 17:43:49 +00:00
|
|
|
if _, ok := namedRef.(docker.Canonical); ok {
|
2019-01-12 04:58:27 +00:00
|
|
|
repoDigest = namedRef.String()
|
|
|
|
} else if !schema1 {
|
|
|
|
// digest is not actual repo digest for schema1 image.
|
|
|
|
repoDigest = namedRef.Name() + "@" + digest.String()
|
|
|
|
}
|
|
|
|
return repoDigest, repoTag
|
|
|
|
}
|
|
|
|
|
|
|
|
// localResolve resolves image reference locally and returns corresponding image metadata. It
|
|
|
|
// returns store.ErrNotExist if the reference doesn't exist.
|
|
|
|
func (c *criService) localResolve(refOrID string) (imagestore.Image, error) {
|
|
|
|
getImageID := func(refOrId string) string {
|
|
|
|
if _, err := imagedigest.Parse(refOrID); err == nil {
|
|
|
|
return refOrID
|
|
|
|
}
|
|
|
|
return func(ref string) string {
|
|
|
|
// ref is not image id, try to resolve it locally.
|
|
|
|
// TODO(random-liu): Handle this error better for debugging.
|
2020-08-10 17:43:49 +00:00
|
|
|
normalized, err := docker.ParseDockerRef(ref)
|
2019-01-12 04:58:27 +00:00
|
|
|
if err != nil {
|
|
|
|
return ""
|
|
|
|
}
|
|
|
|
id, err := c.imageStore.Resolve(normalized.String())
|
|
|
|
if err != nil {
|
|
|
|
return ""
|
|
|
|
}
|
|
|
|
return id
|
|
|
|
}(refOrID)
|
|
|
|
}
|
|
|
|
|
|
|
|
imageID := getImageID(refOrID)
|
|
|
|
if imageID == "" {
|
|
|
|
// Try to treat ref as imageID
|
|
|
|
imageID = refOrID
|
|
|
|
}
|
|
|
|
return c.imageStore.Get(imageID)
|
|
|
|
}
|
|
|
|
|
2019-08-30 18:33:25 +00:00
|
|
|
// toContainerdImage converts an image object in image store to containerd image handler.
|
|
|
|
func (c *criService) toContainerdImage(ctx context.Context, image imagestore.Image) (containerd.Image, error) {
|
|
|
|
// image should always have at least one reference.
|
|
|
|
if len(image.References) == 0 {
|
|
|
|
return nil, errors.Errorf("invalid image with no reference %q", image.ID)
|
|
|
|
}
|
|
|
|
return c.client.GetImage(ctx, image.References[0])
|
|
|
|
}
|
|
|
|
|
2019-01-12 04:58:27 +00:00
|
|
|
// getUserFromImage gets uid or user name of the image user.
|
|
|
|
// If user is numeric, it will be treated as uid; or else, it is treated as user name.
|
|
|
|
func getUserFromImage(user string) (*int64, string) {
|
|
|
|
// return both empty if user is not specified in the image.
|
|
|
|
if user == "" {
|
|
|
|
return nil, ""
|
|
|
|
}
|
|
|
|
// split instances where the id may contain user:group
|
|
|
|
user = strings.Split(user, ":")[0]
|
|
|
|
// user could be either uid or user name. Try to interpret as numeric uid.
|
|
|
|
uid, err := strconv.ParseInt(user, 10, 64)
|
|
|
|
if err != nil {
|
|
|
|
// If user is non numeric, assume it's user name.
|
|
|
|
return nil, user
|
|
|
|
}
|
|
|
|
// If user is a numeric uid.
|
|
|
|
return &uid, ""
|
|
|
|
}
|
|
|
|
|
|
|
|
// ensureImageExists returns corresponding metadata of the image reference, if image is not
|
|
|
|
// pulled yet, the function will pull the image.
|
2019-09-27 21:51:53 +00:00
|
|
|
func (c *criService) ensureImageExists(ctx context.Context, ref string, config *runtime.PodSandboxConfig) (*imagestore.Image, error) {
|
2019-01-12 04:58:27 +00:00
|
|
|
image, err := c.localResolve(ref)
|
|
|
|
if err != nil && err != store.ErrNotExist {
|
|
|
|
return nil, errors.Wrapf(err, "failed to get image %q", ref)
|
|
|
|
}
|
|
|
|
if err == nil {
|
|
|
|
return &image, nil
|
|
|
|
}
|
|
|
|
// Pull image to ensure the image exists
|
2019-09-27 21:51:53 +00:00
|
|
|
resp, err := c.PullImage(ctx, &runtime.PullImageRequest{Image: &runtime.ImageSpec{Image: ref}, SandboxConfig: config})
|
2019-01-12 04:58:27 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, errors.Wrapf(err, "failed to pull image %q", ref)
|
|
|
|
}
|
|
|
|
imageID := resp.GetImageRef()
|
|
|
|
newImage, err := c.imageStore.Get(imageID)
|
|
|
|
if err != nil {
|
|
|
|
// It's still possible that someone removed the image right after it is pulled.
|
|
|
|
return nil, errors.Wrapf(err, "failed to get image %q after pulling", imageID)
|
|
|
|
}
|
|
|
|
return &newImage, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// isInCRIMounts checks whether a destination is in CRI mount list.
|
|
|
|
func isInCRIMounts(dst string, mounts []*runtime.Mount) bool {
|
|
|
|
for _, m := range mounts {
|
2019-04-07 17:07:55 +00:00
|
|
|
if filepath.Clean(m.ContainerPath) == filepath.Clean(dst) {
|
2019-01-12 04:58:27 +00:00
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
|
|
|
// filterLabel returns a label filter. Use `%q` here because containerd
|
|
|
|
// filter needs extra quote to work properly.
|
|
|
|
func filterLabel(k, v string) string {
|
|
|
|
return fmt.Sprintf("labels.%q==%q", k, v)
|
|
|
|
}
|
|
|
|
|
|
|
|
// buildLabel builds the labels from config to be passed to containerd
|
|
|
|
func buildLabels(configLabels map[string]string, containerType string) map[string]string {
|
|
|
|
labels := make(map[string]string)
|
|
|
|
for k, v := range configLabels {
|
|
|
|
labels[k] = v
|
|
|
|
}
|
|
|
|
labels[containerKindLabel] = containerType
|
|
|
|
return labels
|
|
|
|
}
|
|
|
|
|
|
|
|
// toRuntimeAuthConfig converts cri plugin auth config to runtime auth config.
|
|
|
|
func toRuntimeAuthConfig(a criconfig.AuthConfig) *runtime.AuthConfig {
|
|
|
|
return &runtime.AuthConfig{
|
|
|
|
Username: a.Username,
|
|
|
|
Password: a.Password,
|
|
|
|
Auth: a.Auth,
|
|
|
|
IdentityToken: a.IdentityToken,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// parseImageReferences parses a list of arbitrary image references and returns
|
|
|
|
// the repotags and repodigests
|
|
|
|
func parseImageReferences(refs []string) ([]string, []string) {
|
|
|
|
var tags, digests []string
|
|
|
|
for _, ref := range refs {
|
2020-08-10 17:43:49 +00:00
|
|
|
parsed, err := docker.ParseAnyReference(ref)
|
2019-01-12 04:58:27 +00:00
|
|
|
if err != nil {
|
|
|
|
continue
|
|
|
|
}
|
2020-08-10 17:43:49 +00:00
|
|
|
if _, ok := parsed.(docker.Canonical); ok {
|
2019-01-12 04:58:27 +00:00
|
|
|
digests = append(digests, parsed.String())
|
2020-08-10 17:43:49 +00:00
|
|
|
} else if _, ok := parsed.(docker.Tagged); ok {
|
2019-01-12 04:58:27 +00:00
|
|
|
tags = append(tags, parsed.String())
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return tags, digests
|
|
|
|
}
|
|
|
|
|
|
|
|
// generateRuntimeOptions generates runtime options from cri plugin config.
|
|
|
|
func generateRuntimeOptions(r criconfig.Runtime, c criconfig.Config) (interface{}, error) {
|
|
|
|
if r.Options == nil {
|
2019-09-27 21:51:53 +00:00
|
|
|
if r.Type != plugin.RuntimeLinuxV1 {
|
2019-01-12 04:58:27 +00:00
|
|
|
return nil, nil
|
|
|
|
}
|
|
|
|
// This is a legacy config, generate runctypes.RuncOptions.
|
|
|
|
return &runctypes.RuncOptions{
|
|
|
|
Runtime: r.Engine,
|
|
|
|
RuntimeRoot: r.Root,
|
|
|
|
SystemdCgroup: c.SystemdCgroup,
|
|
|
|
}, nil
|
|
|
|
}
|
|
|
|
options := getRuntimeOptionsType(r.Type)
|
|
|
|
if err := toml.PrimitiveDecode(*r.Options, options); err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
return options, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// getRuntimeOptionsType gets empty runtime options by the runtime type name.
|
|
|
|
func getRuntimeOptionsType(t string) interface{} {
|
|
|
|
switch t {
|
2019-09-27 21:51:53 +00:00
|
|
|
case plugin.RuntimeRuncV1:
|
|
|
|
fallthrough
|
|
|
|
case plugin.RuntimeRuncV2:
|
2019-01-12 04:58:27 +00:00
|
|
|
return &runcoptions.Options{}
|
2019-09-27 21:51:53 +00:00
|
|
|
case plugin.RuntimeLinuxV1:
|
2019-01-12 04:58:27 +00:00
|
|
|
return &runctypes.RuncOptions{}
|
2020-08-10 17:43:49 +00:00
|
|
|
case runtimeRunhcsV1:
|
|
|
|
return &runhcsoptions.Options{}
|
2019-09-27 21:51:53 +00:00
|
|
|
default:
|
|
|
|
return &runtimeoptions.Options{}
|
2019-01-12 04:58:27 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// getRuntimeOptions get runtime options from container metadata.
|
|
|
|
func getRuntimeOptions(c containers.Container) (interface{}, error) {
|
|
|
|
if c.Runtime.Options == nil {
|
|
|
|
return nil, nil
|
|
|
|
}
|
|
|
|
opts, err := typeurl.UnmarshalAny(c.Runtime.Options)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
return opts, nil
|
|
|
|
}
|
2019-02-08 04:04:22 +00:00
|
|
|
|
|
|
|
const (
|
|
|
|
// unknownExitCode is the exit code when exit reason is unknown.
|
|
|
|
unknownExitCode = 255
|
|
|
|
// unknownExitReason is the exit reason when exit reason is unknown.
|
|
|
|
unknownExitReason = "Unknown"
|
|
|
|
)
|
|
|
|
|
|
|
|
// unknownContainerStatus returns the default container status when its status is unknown.
|
|
|
|
func unknownContainerStatus() containerstore.Status {
|
|
|
|
return containerstore.Status{
|
|
|
|
CreatedAt: 0,
|
|
|
|
StartedAt: 0,
|
|
|
|
FinishedAt: 0,
|
|
|
|
ExitCode: unknownExitCode,
|
|
|
|
Reason: unknownExitReason,
|
2020-07-24 21:23:56 +00:00
|
|
|
Unknown: true,
|
2019-02-08 04:04:22 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// unknownSandboxStatus returns the default sandbox status when its status is unknown.
|
|
|
|
func unknownSandboxStatus() sandboxstore.Status {
|
|
|
|
return sandboxstore.Status{
|
|
|
|
State: sandboxstore.StateUnknown,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-09-27 21:51:53 +00:00
|
|
|
// getPassthroughAnnotations filters requested pod annotations by comparing
|
|
|
|
// against permitted annotations for the given runtime.
|
|
|
|
func getPassthroughAnnotations(podAnnotations map[string]string,
|
|
|
|
runtimePodAnnotations []string) (passthroughAnnotations map[string]string) {
|
|
|
|
passthroughAnnotations = make(map[string]string)
|
2019-04-09 17:34:40 +00:00
|
|
|
|
2019-09-27 21:51:53 +00:00
|
|
|
for podAnnotationKey, podAnnotationValue := range podAnnotations {
|
|
|
|
for _, pattern := range runtimePodAnnotations {
|
|
|
|
// Use path.Match instead of filepath.Match here.
|
|
|
|
// filepath.Match treated `\\` as path separator
|
|
|
|
// on windows, which is not what we want.
|
|
|
|
if ok, _ := path.Match(pattern, podAnnotationKey); ok {
|
|
|
|
passthroughAnnotations[podAnnotationKey] = podAnnotationValue
|
|
|
|
}
|
|
|
|
}
|
2019-04-09 17:34:40 +00:00
|
|
|
}
|
2019-09-27 21:51:53 +00:00
|
|
|
return passthroughAnnotations
|
2019-04-09 17:34:40 +00:00
|
|
|
}
|