hcnnamespace.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425
  1. package hcn
  2. import (
  3. "encoding/json"
  4. "os"
  5. "syscall"
  6. icni "github.com/Microsoft/hcsshim/internal/cni"
  7. "github.com/Microsoft/hcsshim/internal/guid"
  8. "github.com/Microsoft/hcsshim/internal/interop"
  9. "github.com/Microsoft/hcsshim/internal/regstate"
  10. "github.com/Microsoft/hcsshim/internal/runhcs"
  11. "github.com/sirupsen/logrus"
  12. )
  13. // NamespaceResourceEndpoint represents an Endpoint attached to a Namespace.
  14. type NamespaceResourceEndpoint struct {
  15. Id string `json:"ID,"`
  16. }
  17. // NamespaceResourceContainer represents a Container attached to a Namespace.
  18. type NamespaceResourceContainer struct {
  19. Id string `json:"ID,"`
  20. }
  21. // NamespaceResourceType determines whether the Namespace resource is a Container or Endpoint.
  22. type NamespaceResourceType string
  23. var (
  24. // NamespaceResourceTypeContainer are contianers associated with a Namespace.
  25. NamespaceResourceTypeContainer NamespaceResourceType = "Container"
  26. // NamespaceResourceTypeEndpoint are endpoints associated with a Namespace.
  27. NamespaceResourceTypeEndpoint NamespaceResourceType = "Endpoint"
  28. )
  29. // NamespaceResource is associated with a namespace
  30. type NamespaceResource struct {
  31. Type NamespaceResourceType `json:","` // Container, Endpoint
  32. Data json.RawMessage `json:","`
  33. }
  34. // NamespaceType determines whether the Namespace is for a Host or Guest
  35. type NamespaceType string
  36. var (
  37. // NamespaceTypeHost are host namespaces.
  38. NamespaceTypeHost NamespaceType = "Host"
  39. // NamespaceTypeHostDefault are host namespaces in the default compartment.
  40. NamespaceTypeHostDefault NamespaceType = "HostDefault"
  41. // NamespaceTypeGuest are guest namespaces.
  42. NamespaceTypeGuest NamespaceType = "Guest"
  43. // NamespaceTypeGuestDefault are guest namespaces in the default compartment.
  44. NamespaceTypeGuestDefault NamespaceType = "GuestDefault"
  45. )
  46. // HostComputeNamespace represents a namespace (AKA compartment) in
  47. type HostComputeNamespace struct {
  48. Id string `json:"ID,omitempty"`
  49. NamespaceId uint32 `json:",omitempty"`
  50. Type NamespaceType `json:",omitempty"` // Host, HostDefault, Guest, GuestDefault
  51. Resources []NamespaceResource `json:",omitempty"`
  52. SchemaVersion SchemaVersion `json:",omitempty"`
  53. }
  54. // ModifyNamespaceSettingRequest is the structure used to send request to modify a namespace.
  55. // Used to Add/Remove an endpoints and containers to/from a namespace.
  56. type ModifyNamespaceSettingRequest struct {
  57. ResourceType NamespaceResourceType `json:",omitempty"` // Container, Endpoint
  58. RequestType RequestType `json:",omitempty"` // Add, Remove, Update, Refresh
  59. Settings json.RawMessage `json:",omitempty"`
  60. }
  61. func getNamespace(namespaceGuid guid.GUID, query string) (*HostComputeNamespace, error) {
  62. // Open namespace.
  63. var (
  64. namespaceHandle hcnNamespace
  65. resultBuffer *uint16
  66. propertiesBuffer *uint16
  67. )
  68. hr := hcnOpenNamespace(&namespaceGuid, &namespaceHandle, &resultBuffer)
  69. if err := checkForErrors("hcnOpenNamespace", hr, resultBuffer); err != nil {
  70. return nil, err
  71. }
  72. // Query namespace.
  73. hr = hcnQueryNamespaceProperties(namespaceHandle, query, &propertiesBuffer, &resultBuffer)
  74. if err := checkForErrors("hcnQueryNamespaceProperties", hr, resultBuffer); err != nil {
  75. return nil, err
  76. }
  77. properties := interop.ConvertAndFreeCoTaskMemString(propertiesBuffer)
  78. // Close namespace.
  79. hr = hcnCloseNamespace(namespaceHandle)
  80. if err := checkForErrors("hcnCloseNamespace", hr, nil); err != nil {
  81. return nil, err
  82. }
  83. // Convert output to HostComputeNamespace
  84. var outputNamespace HostComputeNamespace
  85. if err := json.Unmarshal([]byte(properties), &outputNamespace); err != nil {
  86. return nil, err
  87. }
  88. return &outputNamespace, nil
  89. }
  90. func enumerateNamespaces(query string) ([]HostComputeNamespace, error) {
  91. // Enumerate all Namespace Guids
  92. var (
  93. resultBuffer *uint16
  94. namespaceBuffer *uint16
  95. )
  96. hr := hcnEnumerateNamespaces(query, &namespaceBuffer, &resultBuffer)
  97. if err := checkForErrors("hcnEnumerateNamespaces", hr, resultBuffer); err != nil {
  98. return nil, err
  99. }
  100. namespaces := interop.ConvertAndFreeCoTaskMemString(namespaceBuffer)
  101. var namespaceIds []guid.GUID
  102. if err := json.Unmarshal([]byte(namespaces), &namespaceIds); err != nil {
  103. return nil, err
  104. }
  105. var outputNamespaces []HostComputeNamespace
  106. for _, namespaceGuid := range namespaceIds {
  107. namespace, err := getNamespace(namespaceGuid, query)
  108. if err != nil {
  109. return nil, err
  110. }
  111. outputNamespaces = append(outputNamespaces, *namespace)
  112. }
  113. return outputNamespaces, nil
  114. }
  115. func createNamespace(settings string) (*HostComputeNamespace, error) {
  116. // Create new namespace.
  117. var (
  118. namespaceHandle hcnNamespace
  119. resultBuffer *uint16
  120. propertiesBuffer *uint16
  121. )
  122. namespaceGuid := guid.GUID{}
  123. hr := hcnCreateNamespace(&namespaceGuid, settings, &namespaceHandle, &resultBuffer)
  124. if err := checkForErrors("hcnCreateNamespace", hr, resultBuffer); err != nil {
  125. return nil, err
  126. }
  127. // Query namespace.
  128. hcnQuery := defaultQuery()
  129. query, err := json.Marshal(hcnQuery)
  130. if err != nil {
  131. return nil, err
  132. }
  133. hr = hcnQueryNamespaceProperties(namespaceHandle, string(query), &propertiesBuffer, &resultBuffer)
  134. if err := checkForErrors("hcnQueryNamespaceProperties", hr, resultBuffer); err != nil {
  135. return nil, err
  136. }
  137. properties := interop.ConvertAndFreeCoTaskMemString(propertiesBuffer)
  138. // Close namespace.
  139. hr = hcnCloseNamespace(namespaceHandle)
  140. if err := checkForErrors("hcnCloseNamespace", hr, nil); err != nil {
  141. return nil, err
  142. }
  143. // Convert output to HostComputeNamespace
  144. var outputNamespace HostComputeNamespace
  145. if err := json.Unmarshal([]byte(properties), &outputNamespace); err != nil {
  146. return nil, err
  147. }
  148. return &outputNamespace, nil
  149. }
  150. func modifyNamespace(namespaceId string, settings string) (*HostComputeNamespace, error) {
  151. namespaceGuid := guid.FromString(namespaceId)
  152. // Open namespace.
  153. var (
  154. namespaceHandle hcnNamespace
  155. resultBuffer *uint16
  156. propertiesBuffer *uint16
  157. )
  158. hr := hcnOpenNamespace(&namespaceGuid, &namespaceHandle, &resultBuffer)
  159. if err := checkForErrors("hcnOpenNamespace", hr, resultBuffer); err != nil {
  160. return nil, err
  161. }
  162. // Modify namespace.
  163. hr = hcnModifyNamespace(namespaceHandle, settings, &resultBuffer)
  164. if err := checkForErrors("hcnModifyNamespace", hr, resultBuffer); err != nil {
  165. return nil, err
  166. }
  167. // Query namespace.
  168. hcnQuery := defaultQuery()
  169. query, err := json.Marshal(hcnQuery)
  170. if err != nil {
  171. return nil, err
  172. }
  173. hr = hcnQueryNamespaceProperties(namespaceHandle, string(query), &propertiesBuffer, &resultBuffer)
  174. if err := checkForErrors("hcnQueryNamespaceProperties", hr, resultBuffer); err != nil {
  175. return nil, err
  176. }
  177. properties := interop.ConvertAndFreeCoTaskMemString(propertiesBuffer)
  178. // Close namespace.
  179. hr = hcnCloseNamespace(namespaceHandle)
  180. if err := checkForErrors("hcnCloseNamespace", hr, nil); err != nil {
  181. return nil, err
  182. }
  183. // Convert output to Namespace
  184. var outputNamespace HostComputeNamespace
  185. if err := json.Unmarshal([]byte(properties), &outputNamespace); err != nil {
  186. return nil, err
  187. }
  188. return &outputNamespace, nil
  189. }
  190. func deleteNamespace(namespaceId string) error {
  191. namespaceGuid := guid.FromString(namespaceId)
  192. var resultBuffer *uint16
  193. hr := hcnDeleteNamespace(&namespaceGuid, &resultBuffer)
  194. if err := checkForErrors("hcnDeleteNamespace", hr, resultBuffer); err != nil {
  195. return err
  196. }
  197. return nil
  198. }
  199. // ListNamespaces makes a call to list all available namespaces.
  200. func ListNamespaces() ([]HostComputeNamespace, error) {
  201. hcnQuery := defaultQuery()
  202. namespaces, err := ListNamespacesQuery(hcnQuery)
  203. if err != nil {
  204. return nil, err
  205. }
  206. return namespaces, nil
  207. }
  208. // ListNamespacesQuery makes a call to query the list of available namespaces.
  209. func ListNamespacesQuery(query HostComputeQuery) ([]HostComputeNamespace, error) {
  210. queryJson, err := json.Marshal(query)
  211. if err != nil {
  212. return nil, err
  213. }
  214. namespaces, err := enumerateNamespaces(string(queryJson))
  215. if err != nil {
  216. return nil, err
  217. }
  218. return namespaces, nil
  219. }
  220. // GetNamespaceByID returns the Namespace specified by Id.
  221. func GetNamespaceByID(namespaceId string) (*HostComputeNamespace, error) {
  222. return getNamespace(guid.FromString(namespaceId), defaultQueryJson())
  223. }
  224. // GetNamespaceEndpointIds returns the endpoints of the Namespace specified by Id.
  225. func GetNamespaceEndpointIds(namespaceId string) ([]string, error) {
  226. namespace, err := GetNamespaceByID(namespaceId)
  227. if err != nil {
  228. return nil, err
  229. }
  230. var endpointsIds []string
  231. for _, resource := range namespace.Resources {
  232. if resource.Type == "Endpoint" {
  233. var endpointResource NamespaceResourceEndpoint
  234. if err := json.Unmarshal([]byte(resource.Data), &endpointResource); err != nil {
  235. return nil, err
  236. }
  237. endpointsIds = append(endpointsIds, endpointResource.Id)
  238. }
  239. }
  240. return endpointsIds, nil
  241. }
  242. // GetNamespaceContainerIds returns the containers of the Namespace specified by Id.
  243. func GetNamespaceContainerIds(namespaceId string) ([]string, error) {
  244. namespace, err := GetNamespaceByID(namespaceId)
  245. if err != nil {
  246. return nil, err
  247. }
  248. var containerIds []string
  249. for _, resource := range namespace.Resources {
  250. if resource.Type == "Container" {
  251. var contaienrResource NamespaceResourceContainer
  252. if err := json.Unmarshal([]byte(resource.Data), &contaienrResource); err != nil {
  253. return nil, err
  254. }
  255. containerIds = append(containerIds, contaienrResource.Id)
  256. }
  257. }
  258. return containerIds, nil
  259. }
  260. // NewNamespace creates a new Namespace object
  261. func NewNamespace(nsType NamespaceType) *HostComputeNamespace {
  262. return &HostComputeNamespace{
  263. Type: nsType,
  264. SchemaVersion: V2SchemaVersion(),
  265. }
  266. }
  267. // Create Namespace.
  268. func (namespace *HostComputeNamespace) Create() (*HostComputeNamespace, error) {
  269. logrus.Debugf("hcn::HostComputeNamespace::Create id=%s", namespace.Id)
  270. jsonString, err := json.Marshal(namespace)
  271. if err != nil {
  272. return nil, err
  273. }
  274. logrus.Debugf("hcn::HostComputeNamespace::Create JSON: %s", jsonString)
  275. namespace, hcnErr := createNamespace(string(jsonString))
  276. if hcnErr != nil {
  277. return nil, hcnErr
  278. }
  279. return namespace, nil
  280. }
  281. // Delete Namespace.
  282. func (namespace *HostComputeNamespace) Delete() error {
  283. logrus.Debugf("hcn::HostComputeNamespace::Delete id=%s", namespace.Id)
  284. if err := deleteNamespace(namespace.Id); err != nil {
  285. return err
  286. }
  287. return nil
  288. }
  289. // Sync Namespace endpoints with the appropriate sandbox container holding the
  290. // network namespace open. If no sandbox container is found for this namespace
  291. // this method is determined to be a success and will not return an error in
  292. // this case. If the sandbox container is found and a sync is initiated any
  293. // failures will be returned via this method.
  294. //
  295. // This call initiates a sync between endpoints and the matching UtilityVM
  296. // hosting those endpoints. It is safe to call for any `NamespaceType` but
  297. // `NamespaceTypeGuest` is the only case when a sync will actually occur. For
  298. // `NamespaceTypeHost` the process container will be automatically synchronized
  299. // when the the endpoint is added via `AddNamespaceEndpoint`.
  300. //
  301. // Note: This method sync's both additions and removals of endpoints from a
  302. // `NamespaceTypeGuest` namespace.
  303. func (namespace *HostComputeNamespace) Sync() error {
  304. logrus.WithField("id", namespace.Id).Debugf("hcs::HostComputeNamespace::Sync")
  305. // We only attempt a sync for namespace guest.
  306. if namespace.Type != NamespaceTypeGuest {
  307. return nil
  308. }
  309. // Look in the registry for the key to map from namespace id to pod-id
  310. cfg, err := icni.LoadPersistedNamespaceConfig(namespace.Id)
  311. if err != nil {
  312. if regstate.IsNotFoundError(err) {
  313. return nil
  314. }
  315. return err
  316. }
  317. req := runhcs.VMRequest{
  318. ID: cfg.ContainerID,
  319. Op: runhcs.OpSyncNamespace,
  320. }
  321. shimPath := runhcs.VMPipePath(cfg.HostUniqueID)
  322. if err := runhcs.IssueVMRequest(shimPath, &req); err != nil {
  323. // The shim is likey gone. Simply ignore the sync as if it didn't exist.
  324. if perr, ok := err.(*os.PathError); ok && perr.Err == syscall.ERROR_FILE_NOT_FOUND {
  325. // Remove the reg key there is no point to try again
  326. cfg.Remove()
  327. return nil
  328. }
  329. f := map[string]interface{}{
  330. "id": namespace.Id,
  331. "container-id": cfg.ContainerID,
  332. }
  333. logrus.WithFields(f).
  334. WithError(err).
  335. Debugf("hcs::HostComputeNamespace::Sync failed to connect to shim pipe: '%s'", shimPath)
  336. return err
  337. }
  338. return nil
  339. }
  340. // ModifyNamespaceSettings updates the Endpoints/Containers of a Namespace.
  341. func ModifyNamespaceSettings(namespaceId string, request *ModifyNamespaceSettingRequest) error {
  342. logrus.Debugf("hcn::HostComputeNamespace::ModifyNamespaceSettings id=%s", namespaceId)
  343. namespaceSettings, err := json.Marshal(request)
  344. if err != nil {
  345. return err
  346. }
  347. _, err = modifyNamespace(namespaceId, string(namespaceSettings))
  348. if err != nil {
  349. return err
  350. }
  351. return nil
  352. }
  353. // AddNamespaceEndpoint adds an endpoint to a Namespace.
  354. func AddNamespaceEndpoint(namespaceId string, endpointId string) error {
  355. logrus.Debugf("hcn::HostComputeEndpoint::AddNamespaceEndpoint id=%s", endpointId)
  356. mapA := map[string]string{"EndpointId": endpointId}
  357. settingsJson, err := json.Marshal(mapA)
  358. if err != nil {
  359. return err
  360. }
  361. requestMessage := &ModifyNamespaceSettingRequest{
  362. ResourceType: NamespaceResourceTypeEndpoint,
  363. RequestType: RequestTypeAdd,
  364. Settings: settingsJson,
  365. }
  366. return ModifyNamespaceSettings(namespaceId, requestMessage)
  367. }
  368. // RemoveNamespaceEndpoint removes an endpoint from a Namespace.
  369. func RemoveNamespaceEndpoint(namespaceId string, endpointId string) error {
  370. logrus.Debugf("hcn::HostComputeNamespace::RemoveNamespaceEndpoint id=%s", endpointId)
  371. mapA := map[string]string{"EndpointId": endpointId}
  372. settingsJson, err := json.Marshal(mapA)
  373. if err != nil {
  374. return err
  375. }
  376. requestMessage := &ModifyNamespaceSettingRequest{
  377. ResourceType: NamespaceResourceTypeEndpoint,
  378. RequestType: RequestTypeRemove,
  379. Settings: settingsJson,
  380. }
  381. return ModifyNamespaceSettings(namespaceId, requestMessage)
  382. }