init
This commit is contained in:
		
							
								
								
									
										192
									
								
								vendor/github.com/vishvananda/netns/LICENSE
									
									
									
										generated
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										192
									
								
								vendor/github.com/vishvananda/netns/LICENSE
									
									
									
										generated
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,192 @@ | ||||
|  | ||||
|                                  Apache License | ||||
|                            Version 2.0, January 2004 | ||||
|                         http://www.apache.org/licenses/ | ||||
|  | ||||
|    TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION | ||||
|  | ||||
|    1. Definitions. | ||||
|  | ||||
|       "License" shall mean the terms and conditions for use, reproduction, | ||||
|       and distribution as defined by Sections 1 through 9 of this document. | ||||
|  | ||||
|       "Licensor" shall mean the copyright owner or entity authorized by | ||||
|       the copyright owner that is granting the License. | ||||
|  | ||||
|       "Legal Entity" shall mean the union of the acting entity and all | ||||
|       other entities that control, are controlled by, or are under common | ||||
|       control with that entity. For the purposes of this definition, | ||||
|       "control" means (i) the power, direct or indirect, to cause the | ||||
|       direction or management of such entity, whether by contract or | ||||
|       otherwise, or (ii) ownership of fifty percent (50%) or more of the | ||||
|       outstanding shares, or (iii) beneficial ownership of such entity. | ||||
|  | ||||
|       "You" (or "Your") shall mean an individual or Legal Entity | ||||
|       exercising permissions granted by this License. | ||||
|  | ||||
|       "Source" form shall mean the preferred form for making modifications, | ||||
|       including but not limited to software source code, documentation | ||||
|       source, and configuration files. | ||||
|  | ||||
|       "Object" form shall mean any form resulting from mechanical | ||||
|       transformation or translation of a Source form, including but | ||||
|       not limited to compiled object code, generated documentation, | ||||
|       and conversions to other media types. | ||||
|  | ||||
|       "Work" shall mean the work of authorship, whether in Source or | ||||
|       Object form, made available under the License, as indicated by a | ||||
|       copyright notice that is included in or attached to the work | ||||
|       (an example is provided in the Appendix below). | ||||
|  | ||||
|       "Derivative Works" shall mean any work, whether in Source or Object | ||||
|       form, that is based on (or derived from) the Work and for which the | ||||
|       editorial revisions, annotations, elaborations, or other modifications | ||||
|       represent, as a whole, an original work of authorship. For the purposes | ||||
|       of this License, Derivative Works shall not include works that remain | ||||
|       separable from, or merely link (or bind by name) to the interfaces of, | ||||
|       the Work and Derivative Works thereof. | ||||
|  | ||||
|       "Contribution" shall mean any work of authorship, including | ||||
|       the original version of the Work and any modifications or additions | ||||
|       to that Work or Derivative Works thereof, that is intentionally | ||||
|       submitted to Licensor for inclusion in the Work by the copyright owner | ||||
|       or by an individual or Legal Entity authorized to submit on behalf of | ||||
|       the copyright owner. For the purposes of this definition, "submitted" | ||||
|       means any form of electronic, verbal, or written communication sent | ||||
|       to the Licensor or its representatives, including but not limited to | ||||
|       communication on electronic mailing lists, source code control systems, | ||||
|       and issue tracking systems that are managed by, or on behalf of, the | ||||
|       Licensor for the purpose of discussing and improving the Work, but | ||||
|       excluding communication that is conspicuously marked or otherwise | ||||
|       designated in writing by the copyright owner as "Not a Contribution." | ||||
|  | ||||
|       "Contributor" shall mean Licensor and any individual or Legal Entity | ||||
|       on behalf of whom a Contribution has been received by Licensor and | ||||
|       subsequently incorporated within the Work. | ||||
|  | ||||
|    2. Grant of Copyright License. Subject to the terms and conditions of | ||||
|       this License, each Contributor hereby grants to You a perpetual, | ||||
|       worldwide, non-exclusive, no-charge, royalty-free, irrevocable | ||||
|       copyright license to reproduce, prepare Derivative Works of, | ||||
|       publicly display, publicly perform, sublicense, and distribute the | ||||
|       Work and such Derivative Works in Source or Object form. | ||||
|  | ||||
|    3. Grant of Patent License. Subject to the terms and conditions of | ||||
|       this License, each Contributor hereby grants to You a perpetual, | ||||
|       worldwide, non-exclusive, no-charge, royalty-free, irrevocable | ||||
|       (except as stated in this section) patent license to make, have made, | ||||
|       use, offer to sell, sell, import, and otherwise transfer the Work, | ||||
|       where such license applies only to those patent claims licensable | ||||
|       by such Contributor that are necessarily infringed by their | ||||
|       Contribution(s) alone or by combination of their Contribution(s) | ||||
|       with the Work to which such Contribution(s) was submitted. If You | ||||
|       institute patent litigation against any entity (including a | ||||
|       cross-claim or counterclaim in a lawsuit) alleging that the Work | ||||
|       or a Contribution incorporated within the Work constitutes direct | ||||
|       or contributory patent infringement, then any patent licenses | ||||
|       granted to You under this License for that Work shall terminate | ||||
|       as of the date such litigation is filed. | ||||
|  | ||||
|    4. Redistribution. You may reproduce and distribute copies of the | ||||
|       Work or Derivative Works thereof in any medium, with or without | ||||
|       modifications, and in Source or Object form, provided that You | ||||
|       meet the following conditions: | ||||
|  | ||||
|       (a) You must give any other recipients of the Work or | ||||
|           Derivative Works a copy of this License; and | ||||
|  | ||||
|       (b) You must cause any modified files to carry prominent notices | ||||
|           stating that You changed the files; and | ||||
|  | ||||
|       (c) You must retain, in the Source form of any Derivative Works | ||||
|           that You distribute, all copyright, patent, trademark, and | ||||
|           attribution notices from the Source form of the Work, | ||||
|           excluding those notices that do not pertain to any part of | ||||
|           the Derivative Works; and | ||||
|  | ||||
|       (d) If the Work includes a "NOTICE" text file as part of its | ||||
|           distribution, then any Derivative Works that You distribute must | ||||
|           include a readable copy of the attribution notices contained | ||||
|           within such NOTICE file, excluding those notices that do not | ||||
|           pertain to any part of the Derivative Works, in at least one | ||||
|           of the following places: within a NOTICE text file distributed | ||||
|           as part of the Derivative Works; within the Source form or | ||||
|           documentation, if provided along with the Derivative Works; or, | ||||
|           within a display generated by the Derivative Works, if and | ||||
|           wherever such third-party notices normally appear. The contents | ||||
|           of the NOTICE file are for informational purposes only and | ||||
|           do not modify the License. You may add Your own attribution | ||||
|           notices within Derivative Works that You distribute, alongside | ||||
|           or as an addendum to the NOTICE text from the Work, provided | ||||
|           that such additional attribution notices cannot be construed | ||||
|           as modifying the License. | ||||
|  | ||||
|       You may add Your own copyright statement to Your modifications and | ||||
|       may provide additional or different license terms and conditions | ||||
|       for use, reproduction, or distribution of Your modifications, or | ||||
|       for any such Derivative Works as a whole, provided Your use, | ||||
|       reproduction, and distribution of the Work otherwise complies with | ||||
|       the conditions stated in this License. | ||||
|  | ||||
|    5. Submission of Contributions. Unless You explicitly state otherwise, | ||||
|       any Contribution intentionally submitted for inclusion in the Work | ||||
|       by You to the Licensor shall be under the terms and conditions of | ||||
|       this License, without any additional terms or conditions. | ||||
|       Notwithstanding the above, nothing herein shall supersede or modify | ||||
|       the terms of any separate license agreement you may have executed | ||||
|       with Licensor regarding such Contributions. | ||||
|  | ||||
|    6. Trademarks. This License does not grant permission to use the trade | ||||
|       names, trademarks, service marks, or product names of the Licensor, | ||||
|       except as required for reasonable and customary use in describing the | ||||
|       origin of the Work and reproducing the content of the NOTICE file. | ||||
|  | ||||
|    7. Disclaimer of Warranty. Unless required by applicable law or | ||||
|       agreed to in writing, Licensor provides the Work (and each | ||||
|       Contributor provides its Contributions) on an "AS IS" BASIS, | ||||
|       WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or | ||||
|       implied, including, without limitation, any warranties or conditions | ||||
|       of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A | ||||
|       PARTICULAR PURPOSE. You are solely responsible for determining the | ||||
|       appropriateness of using or redistributing the Work and assume any | ||||
|       risks associated with Your exercise of permissions under this License. | ||||
|  | ||||
|    8. Limitation of Liability. In no event and under no legal theory, | ||||
|       whether in tort (including negligence), contract, or otherwise, | ||||
|       unless required by applicable law (such as deliberate and grossly | ||||
|       negligent acts) or agreed to in writing, shall any Contributor be | ||||
|       liable to You for damages, including any direct, indirect, special, | ||||
|       incidental, or consequential damages of any character arising as a | ||||
|       result of this License or out of the use or inability to use the | ||||
|       Work (including but not limited to damages for loss of goodwill, | ||||
|       work stoppage, computer failure or malfunction, or any and all | ||||
|       other commercial damages or losses), even if such Contributor | ||||
|       has been advised of the possibility of such damages. | ||||
|  | ||||
|    9. Accepting Warranty or Additional Liability. While redistributing | ||||
|       the Work or Derivative Works thereof, You may choose to offer, | ||||
|       and charge a fee for, acceptance of support, warranty, indemnity, | ||||
|       or other liability obligations and/or rights consistent with this | ||||
|       License. However, in accepting such obligations, You may act only | ||||
|       on Your own behalf and on Your sole responsibility, not on behalf | ||||
|       of any other Contributor, and only if You agree to indemnify, | ||||
|       defend, and hold each Contributor harmless for any liability | ||||
|       incurred by, or claims asserted against, such Contributor by reason | ||||
|       of your accepting any such warranty or additional liability. | ||||
|  | ||||
|    END OF TERMS AND CONDITIONS | ||||
|  | ||||
|    Copyright 2014 Vishvananda Ishaya. | ||||
|    Copyright 2014 Docker, Inc. | ||||
|  | ||||
|    Licensed under the Apache License, Version 2.0 (the "License"); | ||||
|    you may not use this file except in compliance with the License. | ||||
|    You may obtain a copy of the License at | ||||
|  | ||||
|        http://www.apache.org/licenses/LICENSE-2.0 | ||||
|  | ||||
|    Unless required by applicable law or agreed to in writing, software | ||||
|    distributed under the License is distributed on an "AS IS" BASIS, | ||||
|    WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||||
|    See the License for the specific language governing permissions and | ||||
|    limitations under the License. | ||||
							
								
								
									
										51
									
								
								vendor/github.com/vishvananda/netns/README.md
									
									
									
										generated
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										51
									
								
								vendor/github.com/vishvananda/netns/README.md
									
									
									
										generated
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,51 @@ | ||||
| # netns - network namespaces in go # | ||||
|  | ||||
| The netns package provides an ultra-simple interface for handling | ||||
| network namespaces in go. Changing namespaces requires elevated | ||||
| privileges, so in most cases this code needs to be run as root. | ||||
|  | ||||
| ## Local Build and Test ## | ||||
|  | ||||
| You can use go get command: | ||||
|  | ||||
|     go get github.com/vishvananda/netns | ||||
|  | ||||
| Testing (requires root): | ||||
|  | ||||
|     sudo -E go test github.com/vishvananda/netns | ||||
|  | ||||
| ## Example ## | ||||
|  | ||||
| ```go | ||||
| package main | ||||
|  | ||||
| import ( | ||||
|     "fmt" | ||||
|     "net" | ||||
|     "runtime" | ||||
|     "github.com/vishvananda/netns" | ||||
| ) | ||||
|  | ||||
| func main() { | ||||
|     // Lock the OS Thread so we don't accidentally switch namespaces | ||||
|     runtime.LockOSThread() | ||||
|     defer runtime.UnlockOSThread() | ||||
|  | ||||
|     // Save the current network namespace | ||||
|     origns, _ := netns.Get() | ||||
|     defer origns.Close() | ||||
|  | ||||
|     // Create a new network namespace | ||||
|     newns, _ := netns.New() | ||||
|     netns.Set(newns) | ||||
|     defer newns.Close() | ||||
|  | ||||
|     // Do something with the network namespace | ||||
|     ifaces, _ := net.Interfaces() | ||||
|     fmt.Printf("Interfaces: %v\n", ifaces) | ||||
|  | ||||
|     // Switch back to the original namespace | ||||
|     netns.Set(origns) | ||||
| } | ||||
|  | ||||
| ``` | ||||
							
								
								
									
										80
									
								
								vendor/github.com/vishvananda/netns/netns.go
									
									
									
										generated
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										80
									
								
								vendor/github.com/vishvananda/netns/netns.go
									
									
									
										generated
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,80 @@ | ||||
| // Package netns allows ultra-simple network namespace handling. NsHandles | ||||
| // can be retrieved and set. Note that the current namespace is thread | ||||
| // local so actions that set and reset namespaces should use LockOSThread | ||||
| // to make sure the namespace doesn't change due to a goroutine switch. | ||||
| // It is best to close NsHandles when you are done with them. This can be | ||||
| // accomplished via a `defer ns.Close()` on the handle. Changing namespaces | ||||
| // requires elevated privileges, so in most cases this code needs to be run | ||||
| // as root. | ||||
| package netns | ||||
|  | ||||
| import ( | ||||
| 	"fmt" | ||||
| 	"syscall" | ||||
| ) | ||||
|  | ||||
| // NsHandle is a handle to a network namespace. It can be cast directly | ||||
| // to an int and used as a file descriptor. | ||||
| type NsHandle int | ||||
|  | ||||
| // Equal determines if two network handles refer to the same network | ||||
| // namespace. This is done by comparing the device and inode that the | ||||
| // file descriptors point to. | ||||
| func (ns NsHandle) Equal(other NsHandle) bool { | ||||
| 	if ns == other { | ||||
| 		return true | ||||
| 	} | ||||
| 	var s1, s2 syscall.Stat_t | ||||
| 	if err := syscall.Fstat(int(ns), &s1); err != nil { | ||||
| 		return false | ||||
| 	} | ||||
| 	if err := syscall.Fstat(int(other), &s2); err != nil { | ||||
| 		return false | ||||
| 	} | ||||
| 	return (s1.Dev == s2.Dev) && (s1.Ino == s2.Ino) | ||||
| } | ||||
|  | ||||
| // String shows the file descriptor number and its dev and inode. | ||||
| func (ns NsHandle) String() string { | ||||
| 	var s syscall.Stat_t | ||||
| 	if ns == -1 { | ||||
| 		return "NS(None)" | ||||
| 	} | ||||
| 	if err := syscall.Fstat(int(ns), &s); err != nil { | ||||
| 		return fmt.Sprintf("NS(%d: unknown)", ns) | ||||
| 	} | ||||
| 	return fmt.Sprintf("NS(%d: %d, %d)", ns, s.Dev, s.Ino) | ||||
| } | ||||
|  | ||||
| // UniqueId returns a string which uniquely identifies the namespace | ||||
| // associated with the network handle. | ||||
| func (ns NsHandle) UniqueId() string { | ||||
| 	var s syscall.Stat_t | ||||
| 	if ns == -1 { | ||||
| 		return "NS(none)" | ||||
| 	} | ||||
| 	if err := syscall.Fstat(int(ns), &s); err != nil { | ||||
| 		return "NS(unknown)" | ||||
| 	} | ||||
| 	return fmt.Sprintf("NS(%d:%d)", s.Dev, s.Ino) | ||||
| } | ||||
|  | ||||
| // IsOpen returns true if Close() has not been called. | ||||
| func (ns NsHandle) IsOpen() bool { | ||||
| 	return ns != -1 | ||||
| } | ||||
|  | ||||
| // Close closes the NsHandle and resets its file descriptor to -1. | ||||
| // It is not safe to use an NsHandle after Close() is called. | ||||
| func (ns *NsHandle) Close() error { | ||||
| 	if err := syscall.Close(int(*ns)); err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	(*ns) = -1 | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| // None gets an empty (closed) NsHandle. | ||||
| func None() NsHandle { | ||||
| 	return NsHandle(-1) | ||||
| } | ||||
							
								
								
									
										230
									
								
								vendor/github.com/vishvananda/netns/netns_linux.go
									
									
									
										generated
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										230
									
								
								vendor/github.com/vishvananda/netns/netns_linux.go
									
									
									
										generated
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,230 @@ | ||||
| // +build linux | ||||
|  | ||||
| package netns | ||||
|  | ||||
| import ( | ||||
| 	"fmt" | ||||
| 	"io/ioutil" | ||||
| 	"os" | ||||
| 	"path/filepath" | ||||
| 	"runtime" | ||||
| 	"strconv" | ||||
| 	"strings" | ||||
| 	"syscall" | ||||
| ) | ||||
|  | ||||
| // SYS_SETNS syscall allows changing the namespace of the current process. | ||||
| var SYS_SETNS = map[string]uintptr{ | ||||
| 	"386":     346, | ||||
| 	"amd64":   308, | ||||
| 	"arm64":   268, | ||||
| 	"arm":     375, | ||||
| 	"mips":    4344, | ||||
| 	"mipsle":  4344, | ||||
| 	"ppc64":   350, | ||||
| 	"ppc64le": 350, | ||||
| 	"s390x":   339, | ||||
| }[runtime.GOARCH] | ||||
|  | ||||
| // Deprecated: use syscall pkg instead (go >= 1.5 needed). | ||||
| const ( | ||||
| 	CLONE_NEWUTS  = 0x04000000 /* New utsname group? */ | ||||
| 	CLONE_NEWIPC  = 0x08000000 /* New ipcs */ | ||||
| 	CLONE_NEWUSER = 0x10000000 /* New user namespace */ | ||||
| 	CLONE_NEWPID  = 0x20000000 /* New pid namespace */ | ||||
| 	CLONE_NEWNET  = 0x40000000 /* New network namespace */ | ||||
| 	CLONE_IO      = 0x80000000 /* Get io context */ | ||||
| ) | ||||
|  | ||||
| // Setns sets namespace using syscall. Note that this should be a method | ||||
| // in syscall but it has not been added. | ||||
| func Setns(ns NsHandle, nstype int) (err error) { | ||||
| 	_, _, e1 := syscall.Syscall(SYS_SETNS, uintptr(ns), uintptr(nstype), 0) | ||||
| 	if e1 != 0 { | ||||
| 		err = e1 | ||||
| 	} | ||||
| 	return | ||||
| } | ||||
|  | ||||
| // Set sets the current network namespace to the namespace represented | ||||
| // by NsHandle. | ||||
| func Set(ns NsHandle) (err error) { | ||||
| 	return Setns(ns, CLONE_NEWNET) | ||||
| } | ||||
|  | ||||
| // New creates a new network namespace and returns a handle to it. | ||||
| func New() (ns NsHandle, err error) { | ||||
| 	if err := syscall.Unshare(CLONE_NEWNET); err != nil { | ||||
| 		return -1, err | ||||
| 	} | ||||
| 	return Get() | ||||
| } | ||||
|  | ||||
| // Get gets a handle to the current threads network namespace. | ||||
| func Get() (NsHandle, error) { | ||||
| 	return GetFromThread(os.Getpid(), syscall.Gettid()) | ||||
| } | ||||
|  | ||||
| // GetFromPath gets a handle to a network namespace | ||||
| // identified by the path | ||||
| func GetFromPath(path string) (NsHandle, error) { | ||||
| 	fd, err := syscall.Open(path, syscall.O_RDONLY, 0) | ||||
| 	if err != nil { | ||||
| 		return -1, err | ||||
| 	} | ||||
| 	return NsHandle(fd), nil | ||||
| } | ||||
|  | ||||
| // GetFromName gets a handle to a named network namespace such as one | ||||
| // created by `ip netns add`. | ||||
| func GetFromName(name string) (NsHandle, error) { | ||||
| 	return GetFromPath(fmt.Sprintf("/var/run/netns/%s", name)) | ||||
| } | ||||
|  | ||||
| // GetFromPid gets a handle to the network namespace of a given pid. | ||||
| func GetFromPid(pid int) (NsHandle, error) { | ||||
| 	return GetFromPath(fmt.Sprintf("/proc/%d/ns/net", pid)) | ||||
| } | ||||
|  | ||||
| // GetFromThread gets a handle to the network namespace of a given pid and tid. | ||||
| func GetFromThread(pid, tid int) (NsHandle, error) { | ||||
| 	return GetFromPath(fmt.Sprintf("/proc/%d/task/%d/ns/net", pid, tid)) | ||||
| } | ||||
|  | ||||
| // GetFromDocker gets a handle to the network namespace of a docker container. | ||||
| // Id is prefixed matched against the running docker containers, so a short | ||||
| // identifier can be used as long as it isn't ambiguous. | ||||
| func GetFromDocker(id string) (NsHandle, error) { | ||||
| 	pid, err := getPidForContainer(id) | ||||
| 	if err != nil { | ||||
| 		return -1, err | ||||
| 	} | ||||
| 	return GetFromPid(pid) | ||||
| } | ||||
|  | ||||
| // borrowed from docker/utils/utils.go | ||||
| func findCgroupMountpoint(cgroupType string) (string, error) { | ||||
| 	output, err := ioutil.ReadFile("/proc/mounts") | ||||
| 	if err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
|  | ||||
| 	// /proc/mounts has 6 fields per line, one mount per line, e.g. | ||||
| 	// cgroup /sys/fs/cgroup/devices cgroup rw,relatime,devices 0 0 | ||||
| 	for _, line := range strings.Split(string(output), "\n") { | ||||
| 		parts := strings.Split(line, " ") | ||||
| 		if len(parts) == 6 && parts[2] == "cgroup" { | ||||
| 			for _, opt := range strings.Split(parts[3], ",") { | ||||
| 				if opt == cgroupType { | ||||
| 					return parts[1], nil | ||||
| 				} | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return "", fmt.Errorf("cgroup mountpoint not found for %s", cgroupType) | ||||
| } | ||||
|  | ||||
| // Returns the relative path to the cgroup docker is running in. | ||||
| // borrowed from docker/utils/utils.go | ||||
| // modified to get the docker pid instead of using /proc/self | ||||
| func getThisCgroup(cgroupType string) (string, error) { | ||||
| 	dockerpid, err := ioutil.ReadFile("/var/run/docker.pid") | ||||
| 	if err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
| 	result := strings.Split(string(dockerpid), "\n") | ||||
| 	if len(result) == 0 || len(result[0]) == 0 { | ||||
| 		return "", fmt.Errorf("docker pid not found in /var/run/docker.pid") | ||||
| 	} | ||||
| 	pid, err := strconv.Atoi(result[0]) | ||||
| 	if err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
| 	output, err := ioutil.ReadFile(fmt.Sprintf("/proc/%d/cgroup", pid)) | ||||
| 	if err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
| 	for _, line := range strings.Split(string(output), "\n") { | ||||
| 		parts := strings.Split(line, ":") | ||||
| 		// any type used by docker should work | ||||
| 		if parts[1] == cgroupType { | ||||
| 			return parts[2], nil | ||||
| 		} | ||||
| 	} | ||||
| 	return "", fmt.Errorf("cgroup '%s' not found in /proc/%d/cgroup", cgroupType, pid) | ||||
| } | ||||
|  | ||||
| // Returns the first pid in a container. | ||||
| // borrowed from docker/utils/utils.go | ||||
| // modified to only return the first pid | ||||
| // modified to glob with id | ||||
| // modified to search for newer docker containers | ||||
| func getPidForContainer(id string) (int, error) { | ||||
| 	pid := 0 | ||||
|  | ||||
| 	// memory is chosen randomly, any cgroup used by docker works | ||||
| 	cgroupType := "memory" | ||||
|  | ||||
| 	cgroupRoot, err := findCgroupMountpoint(cgroupType) | ||||
| 	if err != nil { | ||||
| 		return pid, err | ||||
| 	} | ||||
|  | ||||
| 	cgroupThis, err := getThisCgroup(cgroupType) | ||||
| 	if err != nil { | ||||
| 		return pid, err | ||||
| 	} | ||||
|  | ||||
| 	id += "*" | ||||
|  | ||||
| 	attempts := []string{ | ||||
| 		filepath.Join(cgroupRoot, cgroupThis, id, "tasks"), | ||||
| 		// With more recent lxc versions use, cgroup will be in lxc/ | ||||
| 		filepath.Join(cgroupRoot, cgroupThis, "lxc", id, "tasks"), | ||||
| 		// With more recent docker, cgroup will be in docker/ | ||||
| 		filepath.Join(cgroupRoot, cgroupThis, "docker", id, "tasks"), | ||||
| 		// Even more recent docker versions under systemd use docker-<id>.scope/ | ||||
| 		filepath.Join(cgroupRoot, "system.slice", "docker-"+id+".scope", "tasks"), | ||||
| 		// Even more recent docker versions under cgroup/systemd/docker/<id>/ | ||||
| 		filepath.Join(cgroupRoot, "..", "systemd", "docker", id, "tasks"), | ||||
| 		// Kubernetes with docker and CNI is even more different | ||||
| 		filepath.Join(cgroupRoot, "..", "systemd", "kubepods", "*", "pod*", id, "tasks"), | ||||
| 		// Another flavor of containers location in recent kubernetes 1.11+ | ||||
| 		filepath.Join(cgroupRoot, cgroupThis, "kubepods.slice", "kubepods-besteffort.slice", "*", "docker-"+id+".scope", "tasks"), | ||||
| 		// When runs inside of a container with recent kubernetes 1.11+ | ||||
| 		filepath.Join(cgroupRoot, "kubepods.slice", "kubepods-besteffort.slice", "*", "docker-"+id+".scope", "tasks"), | ||||
| 	} | ||||
|  | ||||
| 	var filename string | ||||
| 	for _, attempt := range attempts { | ||||
| 		filenames, _ := filepath.Glob(attempt) | ||||
| 		if len(filenames) > 1 { | ||||
| 			return pid, fmt.Errorf("Ambiguous id supplied: %v", filenames) | ||||
| 		} else if len(filenames) == 1 { | ||||
| 			filename = filenames[0] | ||||
| 			break | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if filename == "" { | ||||
| 		return pid, fmt.Errorf("Unable to find container: %v", id[:len(id)-1]) | ||||
| 	} | ||||
|  | ||||
| 	output, err := ioutil.ReadFile(filename) | ||||
| 	if err != nil { | ||||
| 		return pid, err | ||||
| 	} | ||||
|  | ||||
| 	result := strings.Split(string(output), "\n") | ||||
| 	if len(result) == 0 || len(result[0]) == 0 { | ||||
| 		return pid, fmt.Errorf("No pid found for container") | ||||
| 	} | ||||
|  | ||||
| 	pid, err = strconv.Atoi(result[0]) | ||||
| 	if err != nil { | ||||
| 		return pid, fmt.Errorf("Invalid pid '%s': %s", result[0], err) | ||||
| 	} | ||||
|  | ||||
| 	return pid, nil | ||||
| } | ||||
							
								
								
									
										43
									
								
								vendor/github.com/vishvananda/netns/netns_unspecified.go
									
									
									
										generated
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										43
									
								
								vendor/github.com/vishvananda/netns/netns_unspecified.go
									
									
									
										generated
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,43 @@ | ||||
| // +build !linux | ||||
|  | ||||
| package netns | ||||
|  | ||||
| import ( | ||||
| 	"errors" | ||||
| ) | ||||
|  | ||||
| var ( | ||||
| 	ErrNotImplemented = errors.New("not implemented") | ||||
| ) | ||||
|  | ||||
| func Set(ns NsHandle) (err error) { | ||||
| 	return ErrNotImplemented | ||||
| } | ||||
|  | ||||
| func New() (ns NsHandle, err error) { | ||||
| 	return -1, ErrNotImplemented | ||||
| } | ||||
|  | ||||
| func Get() (NsHandle, error) { | ||||
| 	return -1, ErrNotImplemented | ||||
| } | ||||
|  | ||||
| func GetFromPath(path string) (NsHandle, error) { | ||||
| 	return -1, ErrNotImplemented | ||||
| } | ||||
|  | ||||
| func GetFromName(name string) (NsHandle, error) { | ||||
| 	return -1, ErrNotImplemented | ||||
| } | ||||
|  | ||||
| func GetFromPid(pid int) (NsHandle, error) { | ||||
| 	return -1, ErrNotImplemented | ||||
| } | ||||
|  | ||||
| func GetFromThread(pid, tid int) (NsHandle, error) { | ||||
| 	return -1, ErrNotImplemented | ||||
| } | ||||
|  | ||||
| func GetFromDocker(id string) (NsHandle, error) { | ||||
| 	return -1, ErrNotImplemented | ||||
| } | ||||
		Reference in New Issue
	
	Block a user