mirror of
https://github.com/GoogleContainerTools/kaniko
synced 2026-10-09 11:35:55 +02:00
vendor: GoogleCloudPlatform/container-diff is now GoogleContainerTools/container-diff
This commit is contained in:
Generated
Vendored
+259
@@ -0,0 +1,259 @@
|
||||
/*
|
||||
Copyright 2018 Google, Inc. All rights reserved.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package image
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"compress/gzip"
|
||||
"encoding/json"
|
||||
"github.com/containers/image/docker"
|
||||
img "github.com/containers/image/image"
|
||||
"github.com/containers/image/types"
|
||||
"io"
|
||||
"io/ioutil"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/containers/image/manifest"
|
||||
digest "github.com/opencontainers/go-digest"
|
||||
)
|
||||
|
||||
type MutableSource struct {
|
||||
ProxySource
|
||||
mfst *manifest.Schema2
|
||||
cfg *manifest.Schema2Image
|
||||
extraBlobs map[string][]byte
|
||||
extraLayers []digest.Digest
|
||||
}
|
||||
|
||||
func NewMutableSource(r types.ImageReference) (*MutableSource, error) {
|
||||
if r == nil {
|
||||
return MutableSourceFromScratch()
|
||||
}
|
||||
src, err := r.NewImageSource(nil)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
img, err := r.NewImage(nil)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
ms := &MutableSource{
|
||||
ProxySource: ProxySource{
|
||||
Ref: r,
|
||||
ImageSource: src,
|
||||
img: img,
|
||||
},
|
||||
extraBlobs: make(map[string][]byte),
|
||||
}
|
||||
if err := ms.populateManifestAndConfig(); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return ms, nil
|
||||
}
|
||||
|
||||
func MutableSourceFromScratch() (*MutableSource, error) {
|
||||
config := &manifest.Schema2Image{
|
||||
Schema2V1Image: manifest.Schema2V1Image{
|
||||
Config: &manifest.Schema2Config{},
|
||||
},
|
||||
RootFS: &manifest.Schema2RootFS{},
|
||||
History: []manifest.Schema2History{},
|
||||
}
|
||||
ref, err := docker.ParseReference("//scratch")
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
src, err := ref.NewImageSource(nil)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
ms := &MutableSource{
|
||||
ProxySource: ProxySource{
|
||||
Ref: &ProxyReference{
|
||||
ImageReference: ref,
|
||||
},
|
||||
ImageSource: src,
|
||||
},
|
||||
extraBlobs: make(map[string][]byte),
|
||||
cfg: config,
|
||||
mfst: &manifest.Schema2{},
|
||||
}
|
||||
return ms, nil
|
||||
}
|
||||
|
||||
// Manifest marshals the stored manifest to the byte format.
|
||||
func (m *MutableSource) GetManifest(_ *digest.Digest) ([]byte, string, error) {
|
||||
if err := m.saveConfig(); err != nil {
|
||||
return nil, "", err
|
||||
}
|
||||
s, err := json.Marshal(m.mfst)
|
||||
if err != nil {
|
||||
return nil, "", err
|
||||
}
|
||||
return s, manifest.DockerV2Schema2MediaType, err
|
||||
}
|
||||
|
||||
// populateManifestAndConfig parses the raw manifest and configs, storing them on the struct.
|
||||
func (m *MutableSource) populateManifestAndConfig() error {
|
||||
context := &types.SystemContext{
|
||||
OSChoice: "linux",
|
||||
ArchitectureChoice: "amd64",
|
||||
}
|
||||
image, err := m.ProxySource.Ref.NewImage(context)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer image.Close()
|
||||
// First get manifest
|
||||
mfstBytes, mfstType, err := image.Manifest()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
if mfstType == manifest.DockerV2ListMediaType {
|
||||
// We need to select a manifest digest from the manifest list
|
||||
unparsedImage := img.UnparsedInstance(m.ImageSource, nil)
|
||||
|
||||
mfstDigest, err := img.ChooseManifestInstanceFromManifestList(context, unparsedImage)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
mfstBytes, _, err = m.ProxySource.GetManifest(&mfstDigest)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
m.mfst, err = manifest.Schema2FromManifest(mfstBytes)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// Now, get config
|
||||
configBlob, err := image.ConfigBlob()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
return json.Unmarshal(configBlob, &m.cfg)
|
||||
}
|
||||
|
||||
// GetBlob first checks the stored "extra" blobs, then proxies the call to the original source.
|
||||
func (m *MutableSource) GetBlob(bi types.BlobInfo) (io.ReadCloser, int64, error) {
|
||||
if b, ok := m.extraBlobs[bi.Digest.String()]; ok {
|
||||
return ioutil.NopCloser(bytes.NewReader(b)), int64(len(b)), nil
|
||||
}
|
||||
return m.ImageSource.GetBlob(bi)
|
||||
}
|
||||
|
||||
func gzipBytes(b []byte) ([]byte, error) {
|
||||
buf := bytes.NewBuffer([]byte{})
|
||||
w := gzip.NewWriter(buf)
|
||||
_, err := w.Write(b)
|
||||
w.Close()
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return buf.Bytes(), nil
|
||||
}
|
||||
|
||||
// appendLayer appends an uncompressed blob to the image, preserving the invariants required across the config and manifest.
|
||||
func (m *MutableSource) AppendLayer(content []byte, author string) error {
|
||||
compressedBlob, err := gzipBytes(content)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
dgst := digest.FromBytes(compressedBlob)
|
||||
|
||||
// Add the layer to the manifest.
|
||||
descriptor := manifest.Schema2Descriptor{
|
||||
MediaType: manifest.DockerV2Schema2LayerMediaType,
|
||||
Size: int64(len(content)),
|
||||
Digest: dgst,
|
||||
}
|
||||
m.mfst.LayersDescriptors = append(m.mfst.LayersDescriptors, descriptor)
|
||||
|
||||
m.extraBlobs[dgst.String()] = compressedBlob
|
||||
m.extraLayers = append(m.extraLayers, dgst)
|
||||
|
||||
// Also add it to the config.
|
||||
diffID := digest.FromBytes(content)
|
||||
m.cfg.RootFS.DiffIDs = append(m.cfg.RootFS.DiffIDs, diffID)
|
||||
m.AppendConfigHistory(author, false)
|
||||
return nil
|
||||
}
|
||||
|
||||
// saveConfig marshals the stored image config, and updates the references to it in the manifest.
|
||||
func (m *MutableSource) saveConfig() error {
|
||||
cfgBlob, err := json.Marshal(m.cfg)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
cfgDigest := digest.FromBytes(cfgBlob)
|
||||
m.extraBlobs[cfgDigest.String()] = cfgBlob
|
||||
m.mfst.ConfigDescriptor = manifest.Schema2Descriptor{
|
||||
MediaType: manifest.DockerV2Schema2ConfigMediaType,
|
||||
Size: int64(len(cfgBlob)),
|
||||
Digest: cfgDigest,
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// Env returns a map of environment variables stored in the image config
|
||||
// Converts each variable from a string of the form KEY=VALUE to a map of KEY:VALUE
|
||||
func (m *MutableSource) Env() map[string]string {
|
||||
envArray := m.cfg.Schema2V1Image.Config.Env
|
||||
envMap := make(map[string]string)
|
||||
for _, env := range envArray {
|
||||
entry := strings.Split(env, "=")
|
||||
envMap[entry[0]] = entry[1]
|
||||
}
|
||||
return envMap
|
||||
}
|
||||
|
||||
// SetEnv takes a map of environment variables, and converts them to an array of strings
|
||||
// in the form KEY=VALUE, and then sets the image config
|
||||
func (m *MutableSource) SetEnv(envMap map[string]string, author string) {
|
||||
envArray := []string{}
|
||||
for key, value := range envMap {
|
||||
entry := key + "=" + value
|
||||
envArray = append(envArray, entry)
|
||||
}
|
||||
m.cfg.Schema2V1Image.Config.Env = envArray
|
||||
m.AppendConfigHistory(author, true)
|
||||
}
|
||||
|
||||
func (m *MutableSource) Config() *manifest.Schema2Config {
|
||||
return m.cfg.Schema2V1Image.Config
|
||||
}
|
||||
|
||||
func (m *MutableSource) SetConfig(config *manifest.Schema2Config, author string, emptyLayer bool) {
|
||||
m.cfg.Schema2V1Image.Config = config
|
||||
m.AppendConfigHistory(author, emptyLayer)
|
||||
}
|
||||
|
||||
func (m *MutableSource) AppendConfigHistory(author string, emptyLayer bool) {
|
||||
history := manifest.Schema2History{
|
||||
Created: time.Now(),
|
||||
Author: author,
|
||||
EmptyLayer: emptyLayer,
|
||||
}
|
||||
m.cfg.History = append(m.cfg.History, history)
|
||||
}
|
||||
+64
@@ -0,0 +1,64 @@
|
||||
/*
|
||||
Copyright 2018 Google, Inc. All rights reserved.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package image
|
||||
|
||||
import (
|
||||
"github.com/containers/image/types"
|
||||
)
|
||||
|
||||
// ProxySource is a type that implements types.ImageSource by proxying all calls to an underlying implementation.
|
||||
type ProxySource struct {
|
||||
Ref types.ImageReference
|
||||
types.ImageSource
|
||||
img types.Image
|
||||
}
|
||||
|
||||
func NewProxySource(ref types.ImageReference) (*ProxySource, error) {
|
||||
src, err := ref.NewImageSource(nil)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
defer src.Close()
|
||||
img, err := ref.NewImage(nil)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
return &ProxySource{
|
||||
Ref: ref,
|
||||
img: img,
|
||||
ImageSource: src,
|
||||
}, nil
|
||||
}
|
||||
|
||||
func (p *ProxySource) Reference() types.ImageReference {
|
||||
return p.Ref
|
||||
}
|
||||
|
||||
func (p *ProxySource) LayerInfosForCopy() []types.BlobInfo {
|
||||
return nil
|
||||
}
|
||||
|
||||
// ProxyReference implements types.Reference by proxying calls to an underlying implementation.
|
||||
type ProxyReference struct {
|
||||
types.ImageReference
|
||||
Src types.ImageSource
|
||||
}
|
||||
|
||||
func (p *ProxyReference) NewImageSource(ctx *types.SystemContext) (types.ImageSource, error) {
|
||||
return p.Src, nil
|
||||
}
|
||||
+76
@@ -0,0 +1,76 @@
|
||||
/*
|
||||
Copyright 2018 Google, Inc. All rights reserved.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package util
|
||||
|
||||
import (
|
||||
"io/ioutil"
|
||||
"strings"
|
||||
|
||||
"github.com/containers/image/docker"
|
||||
"github.com/containers/image/types"
|
||||
"github.com/docker/docker/client"
|
||||
)
|
||||
|
||||
// CloudPrepper prepares images sourced from a Cloud registry
|
||||
type CloudPrepper struct {
|
||||
Source string
|
||||
Client *client.Client
|
||||
ImageSource types.ImageSource
|
||||
}
|
||||
|
||||
func (p *CloudPrepper) Name() string {
|
||||
return "Cloud Registry"
|
||||
}
|
||||
|
||||
func (p *CloudPrepper) GetSource() string {
|
||||
return p.Source
|
||||
}
|
||||
|
||||
func (p *CloudPrepper) SetSource(source string) {
|
||||
p.Source = source
|
||||
}
|
||||
|
||||
func (p *CloudPrepper) GetImage() (Image, error) {
|
||||
image, err := getImage(p)
|
||||
image.Type = ImageTypeCloud
|
||||
return image, err
|
||||
}
|
||||
|
||||
func (p *CloudPrepper) GetFileSystem() (string, error) {
|
||||
ref, err := docker.ParseReference("//" + p.Source)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
sanitizedName := strings.Replace(p.Source, ":", "", -1)
|
||||
sanitizedName = strings.Replace(sanitizedName, "/", "", -1)
|
||||
|
||||
path, err := ioutil.TempDir("", sanitizedName)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
return path, GetFileSystemFromReference(ref, p.ImageSource, path, nil)
|
||||
}
|
||||
|
||||
func (p *CloudPrepper) GetConfig() (ConfigSchema, error) {
|
||||
ref, err := docker.ParseReference("//" + p.Source)
|
||||
if err != nil {
|
||||
return ConfigSchema{}, err
|
||||
}
|
||||
|
||||
return getConfigFromReference(ref, p.Source)
|
||||
}
|
||||
+93
@@ -0,0 +1,93 @@
|
||||
/*
|
||||
Copyright 2018 Google, Inc. All rights reserved.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package util
|
||||
|
||||
import (
|
||||
"context"
|
||||
"io/ioutil"
|
||||
"strings"
|
||||
|
||||
"github.com/containers/image/docker/daemon"
|
||||
|
||||
"github.com/docker/docker/client"
|
||||
"github.com/sirupsen/logrus"
|
||||
)
|
||||
|
||||
type DaemonPrepper struct {
|
||||
Source string
|
||||
Client *client.Client
|
||||
}
|
||||
|
||||
func (p *DaemonPrepper) Name() string {
|
||||
return "Local Daemon"
|
||||
}
|
||||
|
||||
func (p *DaemonPrepper) GetSource() string {
|
||||
return p.Source
|
||||
}
|
||||
|
||||
func (p *DaemonPrepper) SetSource(source string) {
|
||||
p.Source = source
|
||||
}
|
||||
|
||||
func (p *DaemonPrepper) GetImage() (Image, error) {
|
||||
image, err := getImage(p)
|
||||
image.Type = ImageTypeDaemon
|
||||
return image, err
|
||||
}
|
||||
|
||||
func (p *DaemonPrepper) GetFileSystem() (string, error) {
|
||||
ref, err := daemon.ParseReference(p.Source)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
src, err := ref.NewImageSource(nil)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
defer src.Close()
|
||||
|
||||
sanitizedName := strings.Replace(p.Source, ":", "", -1)
|
||||
sanitizedName = strings.Replace(sanitizedName, "/", "", -1)
|
||||
|
||||
path, err := ioutil.TempDir("", sanitizedName)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
return path, GetFileSystemFromReference(ref, src, path, nil)
|
||||
}
|
||||
|
||||
func (p *DaemonPrepper) GetConfig() (ConfigSchema, error) {
|
||||
ref, err := daemon.ParseReference(p.Source)
|
||||
if err != nil {
|
||||
return ConfigSchema{}, err
|
||||
}
|
||||
return getConfigFromReference(ref, p.Source)
|
||||
}
|
||||
|
||||
func (p *DaemonPrepper) GetHistory() []ImageHistoryItem {
|
||||
history, err := p.Client.ImageHistory(context.Background(), p.Source)
|
||||
if err != nil {
|
||||
logrus.Errorf("Could not obtain image history for %s: %s", p.Source, err)
|
||||
}
|
||||
historyItems := []ImageHistoryItem{}
|
||||
for _, item := range history {
|
||||
historyItems = append(historyItems, ImageHistoryItem{CreatedBy: item.CreatedBy})
|
||||
}
|
||||
return historyItems
|
||||
}
|
||||
+123
@@ -0,0 +1,123 @@
|
||||
/*
|
||||
Copyright 2018 Google, Inc. All rights reserved.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package util
|
||||
|
||||
import (
|
||||
"archive/tar"
|
||||
"bytes"
|
||||
"context"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"io"
|
||||
"io/ioutil"
|
||||
"os"
|
||||
"strings"
|
||||
|
||||
"github.com/docker/docker/client"
|
||||
)
|
||||
|
||||
type Event struct {
|
||||
Status string `json:"status"`
|
||||
Error string `json:"error"`
|
||||
Progress string `json:"progress"`
|
||||
ProgressDetail struct {
|
||||
Current int `json:"current"`
|
||||
Total int `json:"total"`
|
||||
} `json:"progressDetail"`
|
||||
}
|
||||
|
||||
func NewClient() (*client.Client, error) {
|
||||
cli, err := client.NewEnvClient()
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("Error getting docker client: %s", err)
|
||||
}
|
||||
cli.NegotiateAPIVersion(context.Background())
|
||||
|
||||
return cli, nil
|
||||
}
|
||||
|
||||
func getLayersFromManifest(r io.Reader) ([]string, error) {
|
||||
type Manifest struct {
|
||||
Layers []string
|
||||
}
|
||||
|
||||
manifestJSON, err := ioutil.ReadAll(r)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
var imageManifest []Manifest
|
||||
if err := json.Unmarshal(manifestJSON, &imageManifest); err != nil {
|
||||
return []string{}, fmt.Errorf("Could not unmarshal manifest to get layer order: %s", err)
|
||||
}
|
||||
return imageManifest[0].Layers, nil
|
||||
}
|
||||
|
||||
func unpackDockerSave(tarPath string, target string) error {
|
||||
if _, ok := os.Stat(target); ok != nil {
|
||||
os.MkdirAll(target, 0775)
|
||||
}
|
||||
f, err := os.Open(tarPath)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
tr := tar.NewReader(f)
|
||||
|
||||
// Unpack the layers into a map, since we need to sort out the order later.
|
||||
var layers []string
|
||||
layerMap := map[string][]byte{}
|
||||
for {
|
||||
hdr, err := tr.Next()
|
||||
if err == io.EOF {
|
||||
break
|
||||
}
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// Docker save contains files and directories. Ignore the directories.
|
||||
// We care about the layers and the manifest. The layers look like:
|
||||
// $SHA/layer.tar
|
||||
// and they are referenced that way in the manifest.
|
||||
switch t := hdr.Typeflag; t {
|
||||
case tar.TypeReg:
|
||||
if hdr.Name == "manifest.json" {
|
||||
layers, err = getLayersFromManifest(tr)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
} else if strings.HasSuffix(hdr.Name, ".tar") {
|
||||
layerMap[hdr.Name], err = ioutil.ReadAll(tr)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
case tar.TypeDir:
|
||||
continue
|
||||
default:
|
||||
return fmt.Errorf("unsupported file type %v found in file %s tar %s", t, hdr.Name, tarPath)
|
||||
}
|
||||
}
|
||||
|
||||
for _, layer := range layers {
|
||||
if err = UnTar(bytes.NewReader(layerMap[layer]), target, nil); err != nil {
|
||||
return fmt.Errorf("Could not unpack layer %s: %s", layer, err)
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
+181
@@ -0,0 +1,181 @@
|
||||
/*
|
||||
Copyright 2018 Google, Inc. All rights reserved.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package util
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"io/ioutil"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
|
||||
"github.com/sirupsen/logrus"
|
||||
)
|
||||
|
||||
// Directory stores a representation of a file directory.
|
||||
type Directory struct {
|
||||
Root string
|
||||
Content []string
|
||||
}
|
||||
|
||||
type DirectoryEntry struct {
|
||||
Name string
|
||||
Size int64
|
||||
}
|
||||
|
||||
func GetSize(path string) int64 {
|
||||
stat, err := os.Stat(path)
|
||||
if err != nil {
|
||||
logrus.Errorf("Could not obtain size for %s: %s", path, err)
|
||||
return -1
|
||||
}
|
||||
if stat.IsDir() {
|
||||
size, err := getDirectorySize(path)
|
||||
if err != nil {
|
||||
logrus.Errorf("Could not obtain directory size for %s: %s", path, err)
|
||||
}
|
||||
return size
|
||||
}
|
||||
return stat.Size()
|
||||
}
|
||||
|
||||
//GetFileContents returns the contents of a file at the specified path
|
||||
func GetFileContents(path string) (*string, error) {
|
||||
if _, err := os.Stat(path); os.IsNotExist(err) {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
contents, err := ioutil.ReadFile(path)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
strContents := string(contents)
|
||||
//If file is empty, return nil
|
||||
if strContents == "" {
|
||||
return nil, nil
|
||||
}
|
||||
return &strContents, nil
|
||||
}
|
||||
|
||||
func getDirectorySize(path string) (int64, error) {
|
||||
var size int64
|
||||
err := filepath.Walk(path, func(_ string, info os.FileInfo, err error) error {
|
||||
if !info.IsDir() {
|
||||
size += info.Size()
|
||||
}
|
||||
return err
|
||||
})
|
||||
return size, err
|
||||
}
|
||||
|
||||
// GetDirectoryContents converts the directory starting at the provided path into a Directory struct.
|
||||
func GetDirectory(path string, deep bool) (Directory, error) {
|
||||
var directory Directory
|
||||
directory.Root = path
|
||||
var err error
|
||||
if deep {
|
||||
walkFn := func(currPath string, info os.FileInfo, err error) error {
|
||||
newContent := strings.TrimPrefix(currPath, directory.Root)
|
||||
if newContent != "" {
|
||||
directory.Content = append(directory.Content, newContent)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
err = filepath.Walk(path, walkFn)
|
||||
} else {
|
||||
contents, err := ioutil.ReadDir(path)
|
||||
if err != nil {
|
||||
return directory, err
|
||||
}
|
||||
|
||||
for _, file := range contents {
|
||||
fileName := "/" + file.Name()
|
||||
directory.Content = append(directory.Content, fileName)
|
||||
}
|
||||
}
|
||||
return directory, err
|
||||
}
|
||||
|
||||
func GetDirectoryEntries(d Directory) []DirectoryEntry {
|
||||
return CreateDirectoryEntries(d.Root, d.Content)
|
||||
}
|
||||
|
||||
func CreateDirectoryEntries(root string, entryNames []string) (entries []DirectoryEntry) {
|
||||
for _, name := range entryNames {
|
||||
entryPath := filepath.Join(root, name)
|
||||
size := GetSize(entryPath)
|
||||
|
||||
entry := DirectoryEntry{
|
||||
Name: name,
|
||||
Size: size,
|
||||
}
|
||||
entries = append(entries, entry)
|
||||
}
|
||||
return entries
|
||||
}
|
||||
|
||||
func CheckSameFile(f1name, f2name string) (bool, error) {
|
||||
// Check first if files differ in size and immediately return
|
||||
f1stat, err := os.Stat(f1name)
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
f2stat, err := os.Stat(f2name)
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
|
||||
if f1stat.Size() != f2stat.Size() {
|
||||
return false, nil
|
||||
}
|
||||
|
||||
// Next, check file contents
|
||||
f1, err := ioutil.ReadFile(f1name)
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
f2, err := ioutil.ReadFile(f2name)
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
|
||||
if !bytes.Equal(f1, f2) {
|
||||
return false, nil
|
||||
}
|
||||
return true, nil
|
||||
}
|
||||
|
||||
// HasFilepathPrefix checks if the given file path begins with prefix
|
||||
func HasFilepathPrefix(path, prefix string) bool {
|
||||
path = filepath.Clean(path)
|
||||
prefix = filepath.Clean(prefix)
|
||||
pathArray := strings.Split(path, "/")
|
||||
prefixArray := strings.Split(prefix, "/")
|
||||
|
||||
if len(pathArray) < len(prefixArray) {
|
||||
return false
|
||||
}
|
||||
for index := range prefixArray {
|
||||
if prefixArray[index] == pathArray[index] {
|
||||
continue
|
||||
}
|
||||
return false
|
||||
}
|
||||
return true
|
||||
}
|
||||
Generated
Vendored
+288
@@ -0,0 +1,288 @@
|
||||
/*
|
||||
Copyright 2018 Google, Inc. All rights reserved.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package util
|
||||
|
||||
import (
|
||||
"archive/tar"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io/ioutil"
|
||||
"os"
|
||||
"sort"
|
||||
"strings"
|
||||
|
||||
"github.com/GoogleCloudPlatform/container-diff/cmd/util/output"
|
||||
"github.com/containers/image/docker"
|
||||
"github.com/containers/image/manifest"
|
||||
"github.com/containers/image/pkg/compression"
|
||||
"github.com/containers/image/types"
|
||||
"github.com/sirupsen/logrus"
|
||||
)
|
||||
|
||||
type Prepper interface {
|
||||
Name() string
|
||||
GetConfig() (ConfigSchema, error)
|
||||
GetFileSystem() (string, error)
|
||||
GetImage() (Image, error)
|
||||
GetSource() string
|
||||
SetSource(string)
|
||||
}
|
||||
|
||||
type ImageType int
|
||||
|
||||
const (
|
||||
ImageTypeTar ImageType = iota
|
||||
ImageTypeDaemon
|
||||
ImageTypeCloud
|
||||
)
|
||||
|
||||
type Image struct {
|
||||
Source string
|
||||
FSPath string
|
||||
Config ConfigSchema
|
||||
Type ImageType
|
||||
}
|
||||
|
||||
func (i *Image) IsTar() bool {
|
||||
return i.Type == ImageTypeTar
|
||||
}
|
||||
|
||||
func (i *Image) IsDaemon() bool {
|
||||
return i.Type == ImageTypeDaemon
|
||||
}
|
||||
|
||||
func (i *Image) IsCloud() bool {
|
||||
return i.Type == ImageTypeCloud
|
||||
}
|
||||
|
||||
func (i *Image) GetRemoteDigest() (string, error) {
|
||||
ref, err := docker.ParseReference("//" + i.Source)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
return getDigestFromReference(ref, i.Source)
|
||||
}
|
||||
|
||||
func (i *Image) GetName() string {
|
||||
return strings.Split(i.Source, ":")[0]
|
||||
}
|
||||
|
||||
type ImageHistoryItem struct {
|
||||
CreatedBy string `json:"created_by"`
|
||||
}
|
||||
|
||||
type ConfigObject struct {
|
||||
Hostname string
|
||||
Domainname string
|
||||
User string
|
||||
AttachStdin bool
|
||||
AttachStdout bool
|
||||
AttachStderr bool
|
||||
ExposedPorts map[string]struct{} `json:"ExposedPorts"`
|
||||
Tty bool
|
||||
OpenStdin bool
|
||||
StdinOnce bool
|
||||
Env []string `json:"Env"`
|
||||
Cmd []string `json:"Cmd"`
|
||||
// Healthcheck *HealthConfig
|
||||
ArgsEscaped bool `json:",omitempty"`
|
||||
Image string
|
||||
Volumes map[string]struct{} `json:"Volumes"`
|
||||
Workdir string `json:"WorkingDir"`
|
||||
Entrypoint []string `json:"Entrypoint"`
|
||||
NetworkDisabled bool `json:",omitempty"`
|
||||
MacAddress string `json:",omitempty"`
|
||||
OnBuild []string
|
||||
Labels map[string]string `json:"Labels"`
|
||||
StopSignal string `json:",omitempty"`
|
||||
StopTimeout *int `json:",omitempty"`
|
||||
Shell []string `json:",omitempty"`
|
||||
}
|
||||
|
||||
func (c ConfigObject) AsList() []string {
|
||||
return []string{
|
||||
fmt.Sprintf("Hostname: %s", c.Hostname),
|
||||
fmt.Sprintf("Domainname: %s", c.Domainname),
|
||||
fmt.Sprintf("User: %s", c.User),
|
||||
fmt.Sprintf("AttachStdin: %t", c.AttachStdin),
|
||||
fmt.Sprintf("AttachStdout: %t", c.AttachStdout),
|
||||
fmt.Sprintf("AttachStderr: %t", c.AttachStderr),
|
||||
fmt.Sprintf("ExposedPorts: %v", sortMap(c.ExposedPorts)),
|
||||
fmt.Sprintf("Tty: %t", c.Tty),
|
||||
fmt.Sprintf("OpenStdin: %t", c.OpenStdin),
|
||||
fmt.Sprintf("StdinOnce: %t", c.StdinOnce),
|
||||
fmt.Sprintf("Env: %s", strings.Join(c.Env, ",")),
|
||||
fmt.Sprintf("Cmd: %s", strings.Join(c.Cmd, ",")),
|
||||
fmt.Sprintf("ArgsEscaped: %t", c.ArgsEscaped),
|
||||
fmt.Sprintf("Image: %s", c.Image),
|
||||
fmt.Sprintf("Volumes: %v", sortMap(c.Volumes)),
|
||||
fmt.Sprintf("Workdir: %s", c.Workdir),
|
||||
fmt.Sprintf("Entrypoint: %s", strings.Join(c.Entrypoint, ",")),
|
||||
fmt.Sprintf("NetworkDisabled: %t", c.NetworkDisabled),
|
||||
fmt.Sprintf("MacAddress: %s", c.MacAddress),
|
||||
fmt.Sprintf("OnBuild: %s", strings.Join(c.OnBuild, ",")),
|
||||
fmt.Sprintf("Labels: %v", c.Labels),
|
||||
fmt.Sprintf("StopSignal: %s", c.StopSignal),
|
||||
fmt.Sprintf("StopTimeout: %d", c.StopTimeout),
|
||||
fmt.Sprintf("Shell: %s", strings.Join(c.Shell, ",")),
|
||||
}
|
||||
}
|
||||
|
||||
type ConfigSchema struct {
|
||||
Config ConfigObject `json:"config"`
|
||||
History []ImageHistoryItem `json:"history"`
|
||||
}
|
||||
|
||||
func getImage(p Prepper) (Image, error) {
|
||||
// see if the image name has tag provided, if not add latest as tag
|
||||
if !IsTar(p.GetSource()) && !HasTag(p.GetSource()) {
|
||||
p.SetSource(p.GetSource() + LatestTag)
|
||||
}
|
||||
output.PrintToStdErr("Retrieving image %s from source %s\n", p.GetSource(), p.Name())
|
||||
imgPath, err := p.GetFileSystem()
|
||||
if err != nil {
|
||||
// return image with FSPath so it can be cleaned up
|
||||
return Image{
|
||||
FSPath: imgPath,
|
||||
}, err
|
||||
}
|
||||
|
||||
config, err := p.GetConfig()
|
||||
if err != nil {
|
||||
logrus.Error("Error retrieving History: ", err)
|
||||
}
|
||||
|
||||
logrus.Infof("Finished prepping image %s", p.GetSource())
|
||||
return Image{
|
||||
Source: p.GetSource(),
|
||||
FSPath: imgPath,
|
||||
Config: config,
|
||||
}, nil
|
||||
}
|
||||
|
||||
func getImageFromTar(tarPath string) (string, error) {
|
||||
logrus.Info("Extracting image tar to obtain image file system")
|
||||
tempPath, err := ioutil.TempDir("", ".container-diff")
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
return tempPath, unpackDockerSave(tarPath, tempPath)
|
||||
}
|
||||
|
||||
func GetFileSystemFromReference(ref types.ImageReference, imgSrc types.ImageSource, path string, whitelist []string) error {
|
||||
var err error
|
||||
if imgSrc == nil {
|
||||
imgSrc, err = ref.NewImageSource(nil)
|
||||
}
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer imgSrc.Close()
|
||||
img, err := ref.NewImage(nil)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer img.Close()
|
||||
for _, b := range img.LayerInfos() {
|
||||
bi, _, err := imgSrc.GetBlob(b)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer bi.Close()
|
||||
f, reader, err := compression.DetectCompression(bi)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
// Decompress if necessary.
|
||||
if f != nil {
|
||||
reader, err = f(reader)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
tr := tar.NewReader(reader)
|
||||
if err := unpackTar(tr, path, whitelist); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func getDigestFromReference(ref types.ImageReference, source string) (string, error) {
|
||||
img, err := ref.NewImage(nil)
|
||||
if err != nil {
|
||||
logrus.Errorf("Error referencing image %s from registry: %s", source, err)
|
||||
return "", errors.New("Could not obtain image digest")
|
||||
}
|
||||
defer img.Close()
|
||||
|
||||
rawManifest, _, err := img.Manifest()
|
||||
if err != nil {
|
||||
logrus.Errorf("Error referencing image %s from registry: %s", source, err)
|
||||
return "", errors.New("Could not obtain image digest")
|
||||
}
|
||||
|
||||
digest, err := manifest.Digest(rawManifest)
|
||||
if err != nil {
|
||||
logrus.Errorf("Error referencing image %s from registry: %s", source, err)
|
||||
return "", errors.New("Could not obtain image digest")
|
||||
}
|
||||
|
||||
return digest.String(), nil
|
||||
}
|
||||
|
||||
func getConfigFromReference(ref types.ImageReference, source string) (ConfigSchema, error) {
|
||||
img, err := ref.NewImage(nil)
|
||||
if err != nil {
|
||||
logrus.Errorf("Error referencing image %s from registry: %s", source, err)
|
||||
return ConfigSchema{}, errors.New("Could not obtain image config")
|
||||
}
|
||||
defer img.Close()
|
||||
|
||||
configBlob, err := img.ConfigBlob()
|
||||
if err != nil {
|
||||
logrus.Errorf("Error obtaining config blob for image %s from registry: %s", source, err)
|
||||
return ConfigSchema{}, errors.New("Could not obtain image config")
|
||||
}
|
||||
|
||||
var config ConfigSchema
|
||||
err = json.Unmarshal(configBlob, &config)
|
||||
if err != nil {
|
||||
logrus.Errorf("Error with config file struct for image %s: %s", source, err)
|
||||
return ConfigSchema{}, errors.New("Could not obtain image config")
|
||||
}
|
||||
return config, nil
|
||||
}
|
||||
|
||||
func CleanupImage(image Image) {
|
||||
if image.FSPath != "" {
|
||||
logrus.Infof("Removing image filesystem directory %s from system", image.FSPath)
|
||||
if err := os.RemoveAll(image.FSPath); err != nil {
|
||||
logrus.Warn(err.Error())
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func sortMap(m map[string]struct{}) string {
|
||||
pairs := make([]string, 0)
|
||||
for key := range m {
|
||||
pairs = append(pairs, fmt.Sprintf("%s:%s", key, m[key]))
|
||||
}
|
||||
sort.Strings(pairs)
|
||||
return strings.Join(pairs, " ")
|
||||
}
|
||||
+78
@@ -0,0 +1,78 @@
|
||||
/*
|
||||
Copyright 2018 Google, Inc. All rights reserved.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package util
|
||||
|
||||
import (
|
||||
"io"
|
||||
"io/ioutil"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"regexp"
|
||||
|
||||
"github.com/docker/docker/pkg/system"
|
||||
"github.com/sirupsen/logrus"
|
||||
)
|
||||
|
||||
const LatestTag string = ":latest"
|
||||
|
||||
func GetImageLayers(pathToImage string) []string {
|
||||
layers := []string{}
|
||||
contents, err := ioutil.ReadDir(pathToImage)
|
||||
if err != nil {
|
||||
logrus.Error(err.Error())
|
||||
}
|
||||
|
||||
for _, file := range contents {
|
||||
if file.IsDir() {
|
||||
layers = append(layers, file.Name())
|
||||
}
|
||||
}
|
||||
return layers
|
||||
}
|
||||
|
||||
// copyToFile writes the content of the reader to the specified file
|
||||
func copyToFile(outfile string, r io.Reader) error {
|
||||
// We use sequential file access here to avoid depleting the standby list
|
||||
// on Windows. On Linux, this is a call directly to ioutil.TempFile
|
||||
tmpFile, err := system.TempFileSequential(filepath.Dir(outfile), ".docker_temp_")
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
tmpPath := tmpFile.Name()
|
||||
|
||||
_, err = io.Copy(tmpFile, r)
|
||||
tmpFile.Close()
|
||||
|
||||
if err != nil {
|
||||
os.Remove(tmpPath)
|
||||
return err
|
||||
}
|
||||
|
||||
if err = os.Rename(tmpPath, outfile); err != nil {
|
||||
os.Remove(tmpPath)
|
||||
return err
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// checks to see if an image string contains a tag.
|
||||
func HasTag(image string) bool {
|
||||
tagRegex := regexp.MustCompile(".*:[^/]+$")
|
||||
return tagRegex.MatchString(image)
|
||||
}
|
||||
+102
@@ -0,0 +1,102 @@
|
||||
/*
|
||||
Copyright 2018 Google, Inc. All rights reserved.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package util
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"github.com/containers/image/docker/tarfile"
|
||||
"github.com/docker/docker/client"
|
||||
"github.com/sirupsen/logrus"
|
||||
"io/ioutil"
|
||||
"os"
|
||||
"path/filepath"
|
||||
)
|
||||
|
||||
type TarPrepper struct {
|
||||
Source string
|
||||
Client *client.Client
|
||||
}
|
||||
|
||||
func (p *TarPrepper) Name() string {
|
||||
return "Tar Archive"
|
||||
}
|
||||
|
||||
func (p *TarPrepper) GetSource() string {
|
||||
return p.Source
|
||||
}
|
||||
|
||||
func (p *TarPrepper) SetSource(source string) {
|
||||
p.Source = source
|
||||
}
|
||||
|
||||
func (p *TarPrepper) GetImage() (Image, error) {
|
||||
image, err := getImage(p)
|
||||
image.Type = ImageTypeTar
|
||||
return image, err
|
||||
}
|
||||
|
||||
func (p *TarPrepper) GetFileSystem() (string, error) {
|
||||
return getImageFromTar(p.Source)
|
||||
}
|
||||
|
||||
func (p *TarPrepper) GetConfig() (ConfigSchema, error) {
|
||||
tempDir, err := ioutil.TempDir("", ".container-diff")
|
||||
if err != nil {
|
||||
return ConfigSchema{}, nil
|
||||
}
|
||||
defer os.RemoveAll(tempDir)
|
||||
f, err := os.Open(p.Source)
|
||||
if err != nil {
|
||||
return ConfigSchema{}, err
|
||||
}
|
||||
defer f.Close()
|
||||
if err := UnTar(f, tempDir, nil); err != nil {
|
||||
return ConfigSchema{}, err
|
||||
}
|
||||
|
||||
var config ConfigSchema
|
||||
// First open the manifest, then find the referenced config.
|
||||
manifestPath := filepath.Join(tempDir, "manifest.json")
|
||||
contents, err := ioutil.ReadFile(manifestPath)
|
||||
if err != nil {
|
||||
return ConfigSchema{}, err
|
||||
}
|
||||
|
||||
manifests := []tarfile.ManifestItem{}
|
||||
if err := json.Unmarshal(contents, &manifests); err != nil {
|
||||
return ConfigSchema{}, err
|
||||
}
|
||||
|
||||
if len(manifests) != 1 {
|
||||
return ConfigSchema{}, errors.New("specified tar file contains multiple images")
|
||||
}
|
||||
|
||||
cfgFilename := filepath.Join(tempDir, manifests[0].Config)
|
||||
file, err := ioutil.ReadFile(cfgFilename)
|
||||
if err != nil {
|
||||
logrus.Errorf("Could not read config file %s: %s", cfgFilename, err)
|
||||
return ConfigSchema{}, errors.New("Could not obtain image config")
|
||||
}
|
||||
err = json.Unmarshal(file, &config)
|
||||
if err != nil {
|
||||
logrus.Errorf("Could not marshal config file %s: %s", cfgFilename, err)
|
||||
return ConfigSchema{}, errors.New("Could not obtain image config")
|
||||
}
|
||||
|
||||
return config, nil
|
||||
}
|
||||
+224
@@ -0,0 +1,224 @@
|
||||
/*
|
||||
Copyright 2018 Google, Inc. All rights reserved.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package util
|
||||
|
||||
import (
|
||||
"archive/tar"
|
||||
"fmt"
|
||||
"io"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
|
||||
"github.com/pkg/errors"
|
||||
"github.com/sirupsen/logrus"
|
||||
)
|
||||
|
||||
// Map of target:linkname
|
||||
var hardlinks = make(map[string]string)
|
||||
|
||||
type OriginalPerm struct {
|
||||
path string
|
||||
perm os.FileMode
|
||||
}
|
||||
|
||||
func unpackTar(tr *tar.Reader, path string, whitelist []string) error {
|
||||
originalPerms := make([]OriginalPerm, 0)
|
||||
for {
|
||||
header, err := tr.Next()
|
||||
if err == io.EOF {
|
||||
// end of tar archive
|
||||
break
|
||||
}
|
||||
if err != nil {
|
||||
logrus.Error("Error getting next tar header")
|
||||
return err
|
||||
}
|
||||
if strings.Contains(header.Name, ".wh.") {
|
||||
rmPath := filepath.Clean(filepath.Join(path, header.Name))
|
||||
// Remove the .wh file if it was extracted.
|
||||
if _, err := os.Stat(rmPath); !os.IsNotExist(err) {
|
||||
if err := os.Remove(rmPath); err != nil {
|
||||
logrus.Error(err)
|
||||
}
|
||||
}
|
||||
|
||||
// Remove the whited-out path.
|
||||
newName := strings.Replace(rmPath, ".wh.", "", 1)
|
||||
if err = os.RemoveAll(newName); err != nil {
|
||||
logrus.Error(err)
|
||||
}
|
||||
continue
|
||||
}
|
||||
target := filepath.Clean(filepath.Join(path, header.Name))
|
||||
// Make sure the target isn't part of the whitelist
|
||||
if checkWhitelist(target, whitelist) {
|
||||
continue
|
||||
}
|
||||
mode := header.FileInfo().Mode()
|
||||
switch header.Typeflag {
|
||||
|
||||
// if its a dir and it doesn't exist create it
|
||||
case tar.TypeDir:
|
||||
if _, err := os.Stat(target); os.IsNotExist(err) {
|
||||
if mode.Perm()&(1<<(uint(7))) == 0 {
|
||||
logrus.Debugf("Write permission bit not set on %s by default; setting manually", target)
|
||||
originalMode := mode
|
||||
mode = mode | (1 << uint(7))
|
||||
// keep track of original file permission to reset later
|
||||
originalPerms = append(originalPerms, OriginalPerm{
|
||||
path: target,
|
||||
perm: originalMode,
|
||||
})
|
||||
}
|
||||
logrus.Debugf("Creating directory %s with permissions %v", target, mode)
|
||||
if err := os.MkdirAll(target, mode); err != nil {
|
||||
return err
|
||||
}
|
||||
// In some cases, MkdirAll doesn't change the permissions, so run Chmod
|
||||
if err := os.Chmod(target, mode); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
// if it's a file create it
|
||||
case tar.TypeReg:
|
||||
// It's possible for a file to be included before the directory it's in is created.
|
||||
baseDir := filepath.Dir(target)
|
||||
if _, err := os.Stat(baseDir); os.IsNotExist(err) {
|
||||
logrus.Debugf("baseDir %s for file %s does not exist. Creating.", baseDir, target)
|
||||
if err := os.MkdirAll(baseDir, 0755); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
// It's possible we end up creating files that can't be overwritten based on their permissions.
|
||||
// Explicitly delete an existing file before continuing.
|
||||
if _, err := os.Stat(target); !os.IsNotExist(err) {
|
||||
logrus.Debugf("Removing %s for overwrite.", target)
|
||||
if err := os.Remove(target); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
logrus.Debugf("Creating file %s with permissions %v", target, mode)
|
||||
currFile, err := os.Create(target)
|
||||
if err != nil {
|
||||
logrus.Errorf("Error creating file %s %s", target, err)
|
||||
return err
|
||||
}
|
||||
// manually set permissions on file, since the default umask (022) will interfere
|
||||
if err = os.Chmod(target, mode); err != nil {
|
||||
logrus.Errorf("Error updating file permissions on %s", target)
|
||||
return err
|
||||
}
|
||||
_, err = io.Copy(currFile, tr)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
currFile.Close()
|
||||
case tar.TypeSymlink:
|
||||
// It's possible we end up creating files that can't be overwritten based on their permissions.
|
||||
// Explicitly delete an existing file before continuing.
|
||||
if _, err := os.Stat(target); !os.IsNotExist(err) {
|
||||
logrus.Debugf("Removing %s to create symlink.", target)
|
||||
if err := os.RemoveAll(target); err != nil {
|
||||
logrus.Debugf("Unable to remove %s: %s", target, err)
|
||||
}
|
||||
}
|
||||
|
||||
if err = os.Symlink(header.Linkname, target); err != nil {
|
||||
logrus.Errorf("Failed to create symlink between %s and %s: %s", header.Linkname, target, err)
|
||||
}
|
||||
case tar.TypeLink:
|
||||
linkname := filepath.Clean(filepath.Join(path, header.Linkname))
|
||||
// Check if the linkname already exists
|
||||
if _, err := os.Stat(linkname); !os.IsNotExist(err) {
|
||||
// If it exists, create the hard link
|
||||
resolveHardlink(linkname, target)
|
||||
} else {
|
||||
hardlinks[target] = linkname
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
for target, linkname := range hardlinks {
|
||||
logrus.Info("Resolving hard links.")
|
||||
if _, err := os.Stat(linkname); !os.IsNotExist(err) {
|
||||
// If it exists, create the hard link
|
||||
if err := resolveHardlink(linkname, target); err != nil {
|
||||
return errors.Wrap(err, fmt.Sprintf("Unable to create hard link from %s to %s", linkname, target))
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// reset all original file
|
||||
for _, perm := range originalPerms {
|
||||
if err := os.Chmod(perm.path, perm.perm); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func resolveHardlink(linkname, target string) error {
|
||||
if err := os.Link(linkname, target); err != nil {
|
||||
return err
|
||||
}
|
||||
logrus.Debugf("Created hard link from %s to %s", linkname, target)
|
||||
return nil
|
||||
}
|
||||
|
||||
func checkWhitelist(target string, whitelist []string) bool {
|
||||
for _, w := range whitelist {
|
||||
if HasFilepathPrefix(target, w) {
|
||||
logrus.Debugf("Not extracting %s, as it has prefix %s which is whitelisted", target, w)
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
// UnTar takes in a path to a tar file and writes the untarred version to the provided target.
|
||||
// Only untars one level, does not untar nested tars.
|
||||
func UnTar(r io.Reader, target string, whitelist []string) error {
|
||||
if _, ok := os.Stat(target); ok != nil {
|
||||
os.MkdirAll(target, 0775)
|
||||
}
|
||||
|
||||
tr := tar.NewReader(r)
|
||||
if err := unpackTar(tr, target, whitelist); err != nil {
|
||||
return err
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func IsTar(path string) bool {
|
||||
return filepath.Ext(path) == ".tar" ||
|
||||
filepath.Ext(path) == ".tar.gz" ||
|
||||
filepath.Ext(path) == ".tgz"
|
||||
}
|
||||
|
||||
func CheckTar(image string) bool {
|
||||
if strings.TrimSuffix(image, ".tar") == image {
|
||||
return false
|
||||
}
|
||||
if _, err := os.Stat(image); err != nil {
|
||||
logrus.Errorf("%s does not exist", image)
|
||||
return false
|
||||
}
|
||||
return true
|
||||
}
|
||||
Reference in New Issue
Block a user