Windows: Add named pipe mount support
Current insider builds of Windows have support for mounting individual named pipe servers from the host to the guest. This allows, for example, exposing the docker engine's named pipe to a container. This change allows the user to request such a mount via the normal bind mount syntax in the CLI: docker run -v \\.\pipe\docker_engine:\\.\pipe\docker_engine <args> Signed-off-by: John Starks <jostarks@microsoft.com> Upstream-commit: 54354db850664783918a1fc9d208bcfcf47c28e2 Component: engine
This commit is contained in:
@@ -0,0 +1,71 @@
|
||||
// +build windows
|
||||
|
||||
package main
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"io/ioutil"
|
||||
"math/rand"
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
winio "github.com/Microsoft/go-winio"
|
||||
"github.com/docker/docker/integration-cli/checker"
|
||||
"github.com/docker/docker/integration-cli/request"
|
||||
"github.com/go-check/check"
|
||||
)
|
||||
|
||||
func (s *DockerSuite) TestContainersAPICreateMountsBindNamedPipe(c *check.C) {
|
||||
testRequires(c, SameHostDaemon, DaemonIsWindowsAtLeastBuild(16210)) // Named pipe support was added in RS3
|
||||
|
||||
// Create a host pipe to map into the container
|
||||
hostPipeName := fmt.Sprintf(`\\.\pipe\docker-cli-test-pipe-%x`, rand.Uint64())
|
||||
pc := &winio.PipeConfig{
|
||||
SecurityDescriptor: "D:P(A;;GA;;;AU)", // Allow all users access to the pipe
|
||||
}
|
||||
l, err := winio.ListenPipe(hostPipeName, pc)
|
||||
if err != nil {
|
||||
c.Fatal(err)
|
||||
}
|
||||
defer l.Close()
|
||||
|
||||
// Asynchronously read data that the container writes to the mapped pipe.
|
||||
var b []byte
|
||||
ch := make(chan error)
|
||||
go func() {
|
||||
conn, err := l.Accept()
|
||||
if err == nil {
|
||||
b, err = ioutil.ReadAll(conn)
|
||||
conn.Close()
|
||||
}
|
||||
ch <- err
|
||||
}()
|
||||
|
||||
containerPipeName := `\\.\pipe\docker-cli-test-pipe`
|
||||
text := "hello from a pipe"
|
||||
cmd := fmt.Sprintf("echo %s > %s", text, containerPipeName)
|
||||
|
||||
name := "test-bind-npipe"
|
||||
data := map[string]interface{}{
|
||||
"Image": testEnv.MinimalBaseImage(),
|
||||
"Cmd": []string{"cmd", "/c", cmd},
|
||||
"HostConfig": map[string]interface{}{"Mounts": []map[string]interface{}{{"Type": "npipe", "Source": hostPipeName, "Target": containerPipeName}}},
|
||||
}
|
||||
|
||||
status, resp, err := request.SockRequest("POST", "/containers/create?name="+name, data, daemonHost())
|
||||
c.Assert(err, checker.IsNil, check.Commentf(string(resp)))
|
||||
c.Assert(status, checker.Equals, http.StatusCreated, check.Commentf(string(resp)))
|
||||
|
||||
status, _, err = request.SockRequest("POST", "/containers/"+name+"/start", nil, daemonHost())
|
||||
c.Assert(err, checker.IsNil)
|
||||
c.Assert(status, checker.Equals, http.StatusNoContent)
|
||||
|
||||
err = <-ch
|
||||
if err != nil {
|
||||
c.Fatal(err)
|
||||
}
|
||||
result := strings.TrimSpace(string(b))
|
||||
if result != text {
|
||||
c.Errorf("expected pipe to contain %s, got %s", text, result)
|
||||
}
|
||||
}
|
||||
@@ -4610,10 +4610,7 @@ func (s *DockerSuite) TestRunAddDeviceCgroupRule(c *check.C) {
|
||||
|
||||
// Verifies that running as local system is operating correctly on Windows
|
||||
func (s *DockerSuite) TestWindowsRunAsSystem(c *check.C) {
|
||||
testRequires(c, DaemonIsWindows)
|
||||
if testEnv.DaemonKernelVersionNumeric() < 15000 {
|
||||
c.Skip("Requires build 15000 or later")
|
||||
}
|
||||
testRequires(c, DaemonIsWindowsAtLeastBuild(15000))
|
||||
out, _ := dockerCmd(c, "run", "--net=none", `--user=nt authority\system`, "--hostname=XYZZY", minimalBaseImage(), "cmd", "/c", `@echo %USERNAME%`)
|
||||
c.Assert(strings.TrimSpace(out), checker.Equals, "XYZZY$")
|
||||
}
|
||||
|
||||
@@ -37,6 +37,12 @@ func DaemonIsWindows() bool {
|
||||
return PlatformIs("windows")
|
||||
}
|
||||
|
||||
func DaemonIsWindowsAtLeastBuild(buildNumber int) func() bool {
|
||||
return func() bool {
|
||||
return DaemonIsWindows() && testEnv.DaemonKernelVersionNumeric() >= buildNumber
|
||||
}
|
||||
}
|
||||
|
||||
func DaemonIsLinux() bool {
|
||||
return PlatformIs("linux")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user