mirror of
https://github.com/clearlinux/rkt.git
synced 2026-10-03 23:48:22 +00:00
+1
-1
@@ -1,4 +1,4 @@
|
||||
# Configures Rocket tests at Travis CI (https://travis-ci.org).
|
||||
# Configures rkt tests at Travis CI (https://travis-ci.org).
|
||||
|
||||
language: go
|
||||
|
||||
|
||||
@@ -2,11 +2,11 @@
|
||||
|
||||
[App Container][appc-repo] is a [specification][appc-spec] of an image format, runtime, and discovery protocol for running applications in containers.
|
||||
|
||||
Rocket implements the two runtime components of the specification: the [Application Container Executor (ACE)][appc-ace] and the [Metadata Service][appc-meta].
|
||||
rkt implements the two runtime components of the specification: the [Application Container Executor (ACE)][appc-ace] and the [Metadata Service][appc-meta].
|
||||
|
||||
It also leverages schema and code from the upstream [appc/spec][appc-spec] repo to manipulate ACIs, work with image and pod manifests, and perform image discovery.
|
||||
|
||||
## Validating Rocket
|
||||
## Validating rkt
|
||||
|
||||
To validate that `rkt` successfully implements the ACE part of the spec, use the App Container [validation ACIs][appc-readme]:
|
||||
|
||||
|
||||
@@ -1,14 +1,14 @@
|
||||
# Rocket architecture
|
||||
# rkt architecture
|
||||
|
||||
## Overview
|
||||
|
||||
Rocket consists only of a command-line tool, `rkt`, and does not have a daemon. This architecture allows Rocket to be updated in-place without affecting application containers which are currently running. It also means that levels of privilege can be separated out between different operations.
|
||||
rkt consists only of a command-line tool, `rkt`, and does not have a daemon. This architecture allows rkt to be updated in-place without affecting application containers which are currently running. It also means that levels of privilege can be separated out between different operations.
|
||||
|
||||
All state in Rocket is communicated via the filesystem. Facilities like file-locking are used to ensure co-operation and mutual exclusion between concurrent invocations of the `rkt` command.
|
||||
All state in rkt is communicated via the filesystem. Facilities like file-locking are used to ensure co-operation and mutual exclusion between concurrent invocations of the `rkt` command.
|
||||
|
||||
## Stages
|
||||
|
||||
Execution with Rocket is divided into several distinct stages.
|
||||
Execution with rkt is divided into several distinct stages.
|
||||
|
||||
### Stage 0
|
||||
|
||||
@@ -46,7 +46,7 @@ where:
|
||||
- `stage1` is a copy of the stage1 ACI that is safe for read/write
|
||||
- `stage1/manifest` is the manifest of the stage1 ACI
|
||||
- `stage1/rootfs` is the rootfs of the stage1 ACI
|
||||
- `stage1/rootfs/init` is the actual stage1 binary to be executed (this path may vary according to the `coreos.com/rocket/stage1/init` Annotation of the stage1 ACI)
|
||||
- `stage1/rootfs/init` is the actual stage1 binary to be executed (this path may vary according to the `coreos.com/rkt/stage1/init` Annotation of the stage1 ACI)
|
||||
- `stage1/rootfs/opt/stage2` are copies of the unpacked ACIs
|
||||
|
||||
At this point the stage0 execs `/stage1/rootfs/init` with the current working directory set to the root of the new filesystem.
|
||||
|
||||
+16
-16
@@ -1,4 +1,4 @@
|
||||
# Rocket Commands
|
||||
# rkt Commands
|
||||
|
||||
Work in progress. Please contribute if you see an area that needs more detail.
|
||||
|
||||
@@ -7,15 +7,15 @@ Work in progress. Please contribute if you see an area that needs more detail.
|
||||
[aci-images]: https://github.com/appc/spec/blob/master/SPEC.md#app-container-image
|
||||
[appc-discovery]: https://github.com/appc/spec/blob/master/SPEC.md#app-container-image-discovery
|
||||
|
||||
Rocket runs applications packaged as [Application Container Images (ACI)][aci-images] an open-source specification. ACIs consist of the root filesystem of the application container, a manifest and an optional signature.
|
||||
rkt runs applications packaged as [Application Container Images (ACI)][aci-images] an open-source specification. ACIs consist of the root filesystem of the application container, a manifest and an optional signature.
|
||||
|
||||
ACIs are named with a URL-like structure. This naming scheme allows for a decentralized discovery of ACIs, related signatures and public keys. Rocket uses these hints to execute [meta discovery][appc-discovery].
|
||||
ACIs are named with a URL-like structure. This naming scheme allows for a decentralized discovery of ACIs, related signatures and public keys. rkt uses these hints to execute [meta discovery][appc-discovery].
|
||||
|
||||
### rkt trust
|
||||
|
||||
Before executing a remotely fetched ACI, Rocket will verify it based on attached signatures generated by the ACI creator.
|
||||
Before executing a remotely fetched ACI, rkt will verify it based on attached signatures generated by the ACI creator.
|
||||
|
||||
Before this can happen, Rocket needs to know which creators you trust, and therefore are trusted to run images on your machine. The identity of each ACI creator is established with a public key, which is placed in Rocket's key store on disk.
|
||||
Before this can happen, rkt needs to know which creators you trust, and therefore are trusted to run images on your machine. The identity of each ACI creator is established with a public key, which is placed in rkt's key store on disk.
|
||||
|
||||
When adding a trusted key, a prefix can scope the level of established trust to a subset of images. A few examples:
|
||||
|
||||
@@ -35,7 +35,7 @@ $rkt trust --root coreos.com
|
||||
|
||||
#### Trust a Key Using Meta Discovery
|
||||
|
||||
The easiest way to trust a key is through meta discovery. Rocket will find and download a public key that the creator has published on their website. This process is detailed in the [Application Container specification][appc-discovery]. The TL;DR is Rocket will find a meta tag that looks like:
|
||||
The easiest way to trust a key is through meta discovery. rkt will find and download a public key that the creator has published on their website. This process is detailed in the [Application Container specification][appc-discovery]. The TL;DR is rkt will find a meta tag that looks like:
|
||||
|
||||
```
|
||||
<meta name="ac-discovery-pubkeys" content="coreos.com/etcd https://coreos.com/dist/pubkeys/aci-pubkeys.gpg">
|
||||
@@ -54,7 +54,7 @@ Trusting "https://coreos.com/dist/pubkeys/aci-pubkeys.gpg" for prefix "coreos.co
|
||||
Added key for prefix "coreos.com/etcd" at "/etc/rkt/trustedkeys/prefix.d/coreos.com/etcd/8b86de38890ddb7291867b025210bd8888182190"
|
||||
```
|
||||
|
||||
If Rocket can't find a key using meta discovery, an error will be printed:
|
||||
If rkt can't find a key using meta discovery, an error will be printed:
|
||||
|
||||
```
|
||||
$ rkt trust --prefix coreos.com
|
||||
@@ -80,7 +80,7 @@ Added key for prefix "coreos.com/etcd" at "/etc/rkt/trustedkeys/prefix.d/coreos.
|
||||
|
||||
Trusted public keys can be pre-populated by placing them in the appropriate location on disk for the desired prefix.
|
||||
|
||||
_Depends on https://github.com/coreos/rocket/issues/500_
|
||||
_Depends on https://github.com/coreos/rkt/issues/500_
|
||||
```
|
||||
$ ls -l /etc/rkt/trustedkeys/
|
||||
[insert example of root key vs prefixed key]
|
||||
@@ -88,11 +88,11 @@ $ ls -l /etc/rkt/trustedkeys/
|
||||
|
||||
### rkt fetch
|
||||
|
||||
Rocket uses HTTPS to locate and download remote ACIs and their attached signatures. If the ACI exists locally, it won't be re-downloaded.
|
||||
rkt uses HTTPS to locate and download remote ACIs and their attached signatures. If the ACI exists locally, it won't be re-downloaded.
|
||||
|
||||
#### Fetch with Meta Discovery
|
||||
|
||||
The easiest way to fetch an ACI is through meta discovery. Rocket will find and download the ACI and signature from a location that the creator has published on their website. This process is detailed in the [Application Container specification][appc-discovery].
|
||||
The easiest way to fetch an ACI is through meta discovery. rkt will find and download the ACI and signature from a location that the creator has published on their website. This process is detailed in the [Application Container specification][appc-discovery].
|
||||
|
||||
If you have previously trusted the image creator, it will be downloaded and verified:
|
||||
|
||||
@@ -134,7 +134,7 @@ sha512-fa1cb92dc276b0f9bedf87981e61ecde
|
||||
|
||||
#### Fetch from a Docker registry
|
||||
|
||||
If you want to run an existing Docker image, you can fetch from a Docker registry. Rocket will download and convert the image to ACI.
|
||||
If you want to run an existing Docker image, you can fetch from a Docker registry. rkt will download and convert the image to ACI.
|
||||
|
||||
```
|
||||
$ rkt -insecure-skip-verify fetch docker://busybox
|
||||
@@ -151,7 +151,7 @@ Docker images do not support signature verification.
|
||||
|
||||
## Running Pods
|
||||
|
||||
Rocket can run ACIs based on name, hash, local file on disk or URL. If an ACI hasn't been cached on disk, Rocket will attempt to find and download it.
|
||||
rkt can run ACIs based on name, hash, local file on disk or URL. If an ACI hasn't been cached on disk, rkt will attempt to find and download it.
|
||||
|
||||
### rkt run
|
||||
|
||||
@@ -228,7 +228,7 @@ rkt: warning: signature verification has been disabled
|
||||
|
||||
Volumes are defined in each ACI and are referenced by name. Volumes can be exposed from the host into the pod (`host`) or initialized as empty storage to be accessed locally within the pod (`empty` pending [rkt #378][rkt #378]). Each volume can be selectively mounted into each application at differing mount points or not mounted into specific apps at all.
|
||||
|
||||
[rkt #378]: https://github.com/coreos/rocket/issues/378
|
||||
[rkt #378]: https://github.com/coreos/rkt/issues/378
|
||||
|
||||
For `host` volumes, the `--volume` flag allows you to specify each mount, its type and the location on the host. The volume is then mounted into each app running to the pod based on information defined in the ACI manifest.
|
||||
|
||||
@@ -275,13 +275,13 @@ sudo ./rkt run --volume work,kind=host,source=/opt/tenant1/work \
|
||||
|
||||
#### Customize Networking
|
||||
|
||||
The default networking configuration for Rocket is "host networking". This means that the apps within the pod will share the network stack and the interfaces with the host machine. Since the metadata service uses the pod IP for identity, rkt will not register the pod with the metadata service in this mode.
|
||||
The default networking configuration for rkt is "host networking". This means that the apps within the pod will share the network stack and the interfaces with the host machine. Since the metadata service uses the pod IP for identity, rkt will not register the pod with the metadata service in this mode.
|
||||
|
||||
##### Private Networking
|
||||
|
||||
Another common configuration, "private networking", means the pod will be executed with its own network stack. This is similar to how other container tools work. The [metadata service](metadata-service.md) (launched via `rkt metadata-service`) must be running to use private networking.
|
||||
|
||||
By default, Rocket private networking will create a loopback device and a veth device. The veth pair creates a point-to-point link between the pod and the host. Rocket will allocate an IPv4 /31 (2 IP addresses) out of 172.16.28.0/24 and assign one IP to each end of the veth pair. It will additionally set a route for metadata service (169.254.169.255/32) and default route in the pod namespace. Finally, it will enable IP masquerading on the host to NAT the egress traffic.
|
||||
By default, rkt private networking will create a loopback device and a veth device. The veth pair creates a point-to-point link between the pod and the host. rkt will allocate an IPv4 /31 (2 IP addresses) out of 172.16.28.0/24 and assign one IP to each end of the veth pair. It will additionally set a route for metadata service (169.254.169.255/32) and default route in the pod namespace. Finally, it will enable IP masquerading on the host to NAT the egress traffic.
|
||||
|
||||
```
|
||||
sudo ./rkt run --private-net coreos.com/etcd:v2.0.0
|
||||
@@ -319,7 +319,7 @@ Work in progress. Please contribute!
|
||||
|
||||
### rkt gc
|
||||
|
||||
Rocket has a built-in garbage collection command that is designed to be run periodically from a timer or cron job. Stopped pods are moved to the garbage and cleaned up during a subsequent garbage collection pass. Each `gc` pass removes any pods remaining in the garbage past the grace period. [Read more about the pod lifecycle][gc-docs].
|
||||
rkt has a built-in garbage collection command that is designed to be run periodically from a timer or cron job. Stopped pods are moved to the garbage and cleaned up during a subsequent garbage collection pass. Each `gc` pass removes any pods remaining in the garbage past the grace period. [Read more about the pod lifecycle][gc-docs].
|
||||
|
||||
[gc-docs]: pod-lifecycle.md#garbage-collection
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Getting Started with Rocket
|
||||
# Getting Started with rkt
|
||||
|
||||
The following guide will show you how to build and run a self-contained Go app using
|
||||
rocket, the reference implementation of the [App Container Specification](https://github.com/appc/spec).
|
||||
rkt, the reference implementation of the [App Container Specification](https://github.com/appc/spec).
|
||||
|
||||
## Create a hello go application
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Getting Started with Rocket on Ubuntu Trusty
|
||||
# Getting Started with rkt on Ubuntu Trusty
|
||||
|
||||
The following guide will show you how to build and run the sample [etcd aci](https://github.com/coreos/etcd/releases/download/v2.0.0/etcd-v2.0.0-linux-amd64.aci) on the standard vagrantcloud.com [box for ubuntu trusty](https://vagrantcloud.com/ubuntu/boxes/trusty64).
|
||||
|
||||
@@ -10,20 +10,20 @@ vagrant init ubuntu/trusty64
|
||||
vagrant up --provider virtualbox
|
||||
```
|
||||
|
||||
## SSH into the VM, Install Rocket and Download the ACI
|
||||
## SSH into the VM, Install rkt and Download the ACI
|
||||
|
||||
```
|
||||
vagrant ssh
|
||||
sudo su
|
||||
|
||||
wget https://github.com/coreos/rocket/releases/download/v0.3.1/rocket-v0.3.1.tar.gz
|
||||
tar xzvf rocket-v0.3.1.tar.gz
|
||||
cd rocket-v0.3.1
|
||||
wget https://github.com/coreos/rkt/releases/download/v0.3.1/rkt-v0.3.1.tar.gz
|
||||
tar xzvf rkt-v0.3.1.tar.gz
|
||||
cd rkt-v0.3.1
|
||||
./rkt help
|
||||
```
|
||||
## Trust the CoreOS signing key
|
||||
|
||||
This shows how to trust the CoreOS signing key with the procedure outlined in [Signing and Verification Guide](https://github.com/coreos/rocket/blob/master/Documentation/signing-and-verification-guide.md)
|
||||
This shows how to trust the CoreOS signing key with the procedure outlined in [Signing and Verification Guide](https://github.com/coreos/rkt/blob/master/Documentation/signing-and-verification-guide.md)
|
||||
|
||||
Download the public key
|
||||
`curl -O https://coreos.com/dist/pubkeys/aci-pubkeys.gpg`
|
||||
@@ -104,4 +104,4 @@ rkt: fetching image from https://github.com/coreos/etcd/releases/download/v2.0.0
|
||||
Press ^] three times to kill container
|
||||
```
|
||||
|
||||
You are now running etcd inside of a Rocket pod on Ubuntu Trusty.
|
||||
You are now running etcd inside of a rkt pod on Ubuntu Trusty.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Hacking Guide
|
||||
|
||||
## Building Rocket
|
||||
## Building rkt
|
||||
|
||||
### Requirements
|
||||
|
||||
@@ -15,17 +15,17 @@
|
||||
* Go 1.3+
|
||||
* github.com/appc/spec (not yet vendored as it's in a continuous improvement phase)
|
||||
|
||||
Once the requirements have been met you can build Rocket by running the following commands:
|
||||
Once the requirements have been met you can build rkt by running the following commands:
|
||||
|
||||
```
|
||||
git clone https://github.com/coreos/rocket.git
|
||||
cd rocket; ./build
|
||||
git clone https://github.com/coreos/rkt.git
|
||||
cd rkt; ./build
|
||||
```
|
||||
|
||||
### With Docker
|
||||
|
||||
Alternatively, you can build rocket in a docker container with the following command. Replace $SRC with the absolute path to your rocket source code:
|
||||
Alternatively, you can build rkt in a docker container with the following command. Replace $SRC with the absolute path to your rkt source code:
|
||||
|
||||
```
|
||||
$ sudo docker run -v $SRC:/opt/rocket -i -t golang:1.3 /bin/bash -c "apt-get update && apt-get install -y coreutils cpio squashfs-tools realpath && cd /opt/rocket && go get github.com/appc/spec/... && ./build"
|
||||
$ sudo docker run -v $SRC:/opt/rkt -i -t golang:1.3 /bin/bash -c "apt-get update && apt-get install -y coreutils cpio squashfs-tools realpath && cd /opt/rkt && go get github.com/appc/spec/... && ./build"
|
||||
```
|
||||
|
||||
@@ -24,7 +24,7 @@ In order to avoid exposing host IP to the pods, the metadata service installs an
|
||||
For non-production use, it is often convenient to launch the metadata service inline with running a pod.
|
||||
`rkt run` accepts a `--spawn-metadata-svc` command line argument to launch the metadata service prior to running a pod.
|
||||
When started in this fashion, the metadata service will exit when there are no more pods registered with it.
|
||||
Please note that it is strongly recommended to only use this mode when experimenting with Rocket on command line.
|
||||
Please note that it is strongly recommended to only use this mode when experimenting with rkt on command line.
|
||||
|
||||
## Using the metadata service
|
||||
See [App Container specification](https://github.com/appc/spec/blob/master/SPEC.md#app-container-metadata-service) for more information about the metadata service including a list of supported endpoints and their usage.
|
||||
|
||||
+11
-11
@@ -8,7 +8,7 @@ By default, `rkt run` will start the pod with host networking.
|
||||
This means that the apps within the pod will share the network stack and the interfaces with the host machine.
|
||||
Since the metadata service uses the pod IP for identity, rkt will _not_ register the pod with the metadata service in this mode.
|
||||
|
||||
Note: because of the lack of the metadata service Rocket does not strictly implement the app container specification in host mode.
|
||||
Note: because of the lack of the metadata service rkt does not strictly implement the app container specification in host mode.
|
||||
|
||||
## Private networking mode
|
||||
|
||||
@@ -17,14 +17,14 @@ The service will listen on 0.0.0.0:2375 by default and provides the private netw
|
||||
Ideally this metadata service is launched via your systems init system.
|
||||
|
||||
If `rkt run` is started with `--private-net`, the pod will be executed with its own network stack.
|
||||
By default, Rocket will create a loopback device and a veth device. The veth pair creates a point-to-point link between the pod and the host.
|
||||
Rocket will allocate an IPv4 /31 (2 IP addresses) out of 172.16.28.0/24 and assign one IP to each end of the veth pair.
|
||||
By default, rkt will create a loopback device and a veth device. The veth pair creates a point-to-point link between the pod and the host.
|
||||
rkt will allocate an IPv4 /31 (2 IP addresses) out of 172.16.28.0/24 and assign one IP to each end of the veth pair.
|
||||
It will additionally set a route for metadata service (169.254.169.255/32) and default route in the pod namespace.
|
||||
Finally, it will enable IP masquerading on the host to NAT the egress traffic.
|
||||
|
||||
### Setting up additional networks
|
||||
|
||||
In addition to the default network (veth) described in the previous section, Rocket pods can be configured to join additional networks.
|
||||
In addition to the default network (veth) described in the previous section, rkt pods can be configured to join additional networks.
|
||||
Each additional network will result in an new interface being setup in the pod.
|
||||
The type of network interface, IP, routes, etc is controlled via a configuration file residing in `/etc/rkt/net.d` directory.
|
||||
The network configuration files are executed in lexicographically sorted order. Each file consists of a JSON dictionary as shown below:
|
||||
@@ -45,7 +45,7 @@ The following fields apply to all configuration files.
|
||||
Additional fields are specified for various types.
|
||||
|
||||
- **name** (string): An arbitrary label for the network. By convention the conf file is labeled with a leading ordinal, dash, network name, and .conf extension.
|
||||
- **type** (string): The type of network/interface to create. The type actually names a network plugin with Rocket bundled with few built-in ones.
|
||||
- **type** (string): The type of network/interface to create. The type actually names a network plugin with rkt bundled with few built-in ones.
|
||||
- **ipam** (dict): IP Address Management -- controls the settings related to IP address assignment, gateway, and routes.
|
||||
|
||||
### Built-in network types
|
||||
@@ -83,12 +83,12 @@ With the IP address allocated by the real network infrastructure, this makes the
|
||||
|
||||
#### ipvlan
|
||||
|
||||
- [Coming soon](https://github.com/coreos/rocket/issues/479)
|
||||
- [Coming soon](https://github.com/coreos/rkt/issues/479)
|
||||
|
||||
## IP Address Management
|
||||
|
||||
The policy for IP address allocation, associated gateway and routes is separately configurable via the `ipam` section of the configuration file.
|
||||
Rocket currently ships with one type of IPAM (static) but DHCP is in the works. Like the network types, IPAM types can be implemented by third-parties via plugins.
|
||||
rkt currently ships with one type of IPAM (static) but DHCP is in the works. Like the network types, IPAM types can be implemented by third-parties via plugins.
|
||||
|
||||
### static
|
||||
|
||||
@@ -108,8 +108,8 @@ Consider the following conf:
|
||||
}
|
||||
```
|
||||
|
||||
This configuration instructs Rocket to create `rkt1` Linux bridge and plugs pods into it via veths.
|
||||
Since the subnet is defined as `10.1.0.0/16`, Rocket will assign individual IPs out of that range.
|
||||
This configuration instructs rkt to create `rkt1` Linux bridge and plugs pods into it via veths.
|
||||
Since the subnet is defined as `10.1.0.0/16`, rkt will assign individual IPs out of that range.
|
||||
The first pod will be assigned 10.1.0.2/16, next one 10.1.0.3/16, etc (it reserves 10.1.0.1/16 for gateway).
|
||||
Additional configuration fields:
|
||||
|
||||
@@ -121,10 +121,10 @@ Additional configuration fields:
|
||||
|
||||
### dhcp
|
||||
|
||||
[Coming soon](https://github.com/coreos/rocket/issues/558)
|
||||
[Coming soon](https://github.com/coreos/rkt/issues/558)
|
||||
|
||||
### Overriding default network
|
||||
If a network has a name "default", it will override the default network added
|
||||
by Rocket. It is strongly recommended that such network also has type "veth" as
|
||||
by rkt. It is strongly recommended that such network also has type "veth" as
|
||||
it protects from the pod spoofing its IP address and defeating identity
|
||||
management provided by the metadata service.
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
# Life-cycle of a pod in rocket
|
||||
# Life-cycle of a pod in rkt
|
||||
|
||||
Throughout this document `$var` is used to refer to the directory `/var/lib/rkt/pods`, and `$uuid` refers to a pod's UUID e.g. "076292e6-54c4-4cc8-9fa7-679c5f7dcfd3".
|
||||
|
||||
Due to rocket's lack of a management daemon process, a combination of advisory file locking and atomically changing (via rename(2)) directory locations is used to represent and transition the basic pod states.
|
||||
Due to rkt's lack of a management daemon process, a combination of advisory file locking and atomically changing (via rename(2)) directory locations is used to represent and transition the basic pod states.
|
||||
|
||||
At times where a state must be reliably coupled to an executing process, that process is executed with an open file descriptor possessing an exclusive advisory lock on the respective pod's directory. Should that process exit for any reason, its open file descriptors will automatically be closed by the kernel, implicitly unlocking the pod's directory in the process. By attempting to acquire a shared non-blocking advisory lock on a pod directory we're able to poll for these process-bound states, additionally by employing a blocking acquisition mode we may reliably synchronize indirectly with the exit of such processes, effectively providing us with a wake-up event the moment such a state transitions. For more information on advisory locks see the flock(2) man page.
|
||||
|
||||
@@ -65,7 +65,7 @@ Should #Prepare fail or be interrupted, `$var/prepare/$uuid` will be left in an
|
||||
|
||||
`rkt run` and `rkt run-prepared` both arrive here with the pod at `$var/run/$uuid` while holding the exclusive lock.
|
||||
|
||||
The pod is then excuted while holding this lock. It is required that the stage 1 `coreos.com/rocket/stage1/run` entrypoint keep the file descriptor representing the exclusive lock open for the lifetime of the pod's process. All this requires is that the stage 1 implementation not close the inherited file descriptor. This is facilitated by supplying stage 1 its number in the RKT_LOCK_FD environment variable.
|
||||
The pod is then excuted while holding this lock. It is required that the stage 1 `coreos.com/rkt/stage1/run` entrypoint keep the file descriptor representing the exclusive lock open for the lifetime of the pod's process. All this requires is that the stage 1 implementation not close the inherited file descriptor. This is facilitated by supplying stage 1 its number in the RKT_LOCK_FD environment variable.
|
||||
|
||||
What follows applies equally to `rkt run` and `rkt run-prepared`.
|
||||
|
||||
|
||||
@@ -8,13 +8,13 @@ hello-0.0.1-linux-amd64.aci
|
||||
|
||||
* [Signing ACIs](#signing-acis)
|
||||
* [Distributing Images via Meta Discovery](#distributing-images-via-meta-discovery)
|
||||
* [Verifying Images with Rocket](#verifying-images-with-rocket)
|
||||
* [Verifying Images with rkt](#verifying-images-with-rkt)
|
||||
* [Establishing Trust](#establishing-trust)
|
||||
* [Example Usage](#example-usage)
|
||||
|
||||
## Signing ACIs
|
||||
|
||||
By default rocket requires ACIs to be signed using a gpg detached signature. The following steps will walk you through the creation of a gpg keypair suitable for signing an ACI. If you have an existing gpg signing key skip to the [Signing the ACI](signing-the-aci) step.
|
||||
By default rkt requires ACIs to be signed using a gpg detached signature. The following steps will walk you through the creation of a gpg keypair suitable for signing an ACI. If you have an existing gpg signing key skip to the [Signing the ACI](signing-the-aci) step.
|
||||
|
||||
### Generate a gpg signing key
|
||||
|
||||
@@ -30,9 +30,9 @@ Name-Real: Kelsey Hightower
|
||||
Name-Comment: ACI signing key
|
||||
Name-Email: kelsey.hightower@coreos.com
|
||||
Expire-Date: 0
|
||||
Passphrase: rocket
|
||||
%pubring rocket.pub
|
||||
%secring rocket.sec
|
||||
Passphrase: rkt
|
||||
%pubring rkt.pub
|
||||
%secring rkt.sec
|
||||
%commit
|
||||
%echo done
|
||||
```
|
||||
@@ -46,10 +46,10 @@ $ gpg --batch --gen-key gpg-batch
|
||||
#### List the keys
|
||||
|
||||
```
|
||||
$ gpg --no-default-keyring --secret-keyring ./rocket.sec --keyring ./rocket.pub --list-keys
|
||||
$ gpg --no-default-keyring --secret-keyring ./rkt.sec --keyring ./rkt.pub --list-keys
|
||||
```
|
||||
```
|
||||
./rocket.pub
|
||||
./rkt.pub
|
||||
------------
|
||||
pub 2048R/26EF7A14 2015-01-09
|
||||
uid [ unknown] Kelsey Hightower (ACI signing key) <kelsey.hightower@coreos.com>
|
||||
@@ -65,7 +65,7 @@ gpg: WARNING: This key is not certified with a trusted signature!
|
||||
Since we know exactly where this key came from let's trust it:
|
||||
|
||||
```
|
||||
$ gpg --no-default-keyring --secret-keyring ./rocket.sec --keyring ./rocket.pub --edit-key 26EF7A14 trust
|
||||
$ gpg --no-default-keyring --secret-keyring ./rkt.sec --keyring ./rkt.pub --edit-key 26EF7A14 trust
|
||||
gpg (GnuPG/MacGPG2) 2.0.22; Copyright (C) 2013 Free Software Foundation, Inc.
|
||||
This is free software: you are free to change and redistribute it.
|
||||
There is NO WARRANTY, to the extent permitted by law.
|
||||
@@ -104,7 +104,7 @@ gpg> quit
|
||||
|
||||
```
|
||||
$ gpg --no-default-keyring --armor \
|
||||
--secret-keyring ./rocket.sec --keyring ./rocket.pub \
|
||||
--secret-keyring ./rkt.sec --keyring ./rkt.pub \
|
||||
--export kelsey.hightower@coreos.com > pubkeys.gpg
|
||||
```
|
||||
|
||||
@@ -112,7 +112,7 @@ $ gpg --no-default-keyring --armor \
|
||||
|
||||
```
|
||||
$ gpg --no-default-keyring --armor \
|
||||
--secret-keyring ./rocket.sec --keyring ./rocket.pub \
|
||||
--secret-keyring ./rkt.sec --keyring ./rkt.pub \
|
||||
--output hello-0.0.1-linux-amd64.aci.asc \
|
||||
--detach-sig hello-0.0.1-linux-amd64.aci
|
||||
```
|
||||
@@ -121,7 +121,7 @@ $ gpg --no-default-keyring --armor \
|
||||
|
||||
```
|
||||
$ gpg --no-default-keyring \
|
||||
--secret-keyring ./rocket.sec --keyring ./rocket.pub \
|
||||
--secret-keyring ./rkt.sec --keyring ./rkt.pub \
|
||||
--verify hello-0.0.1-linux-amd64.aci.asc hello-0.0.1-linux-amd64.aci
|
||||
```
|
||||
```
|
||||
@@ -160,16 +160,16 @@ https://example.com/images/hello-0.0.1-linux-amd64.aci
|
||||
https://example.com/pubkeys.gpg
|
||||
```
|
||||
|
||||
### Rocket Integration
|
||||
### rkt Integration
|
||||
|
||||
Lets walk through the steps rocket takes when fetching images using Meta Discovery.
|
||||
The following rocket command:
|
||||
Lets walk through the steps rkt takes when fetching images using Meta Discovery.
|
||||
The following rkt command:
|
||||
|
||||
```
|
||||
$ rkt run example.com/hello:0.0.1
|
||||
```
|
||||
|
||||
results in rocket retrieving the following URIs:
|
||||
results in rkt retrieving the following URIs:
|
||||
|
||||
```
|
||||
https://example.com/hello?ac-discovery=1
|
||||
@@ -183,18 +183,18 @@ The first response contains the template URL used to download the ACI image and
|
||||
<meta name="ac-discovery" content="example.com/hello https://example.com/images/{name}-{version}-{os}-{arch}.{ext}">
|
||||
```
|
||||
|
||||
Rocket populates the `{os}` and `{arch}` based on the current running system.
|
||||
rkt populates the `{os}` and `{arch}` based on the current running system.
|
||||
The `{version}` will be taken from the tag given on the command line or "latest" if not supplied.
|
||||
The `{ext}` will be substituted appropriately depending on artifact being retrieved: .aci will be used for ACI images and .aci.asc will be used for detached signatures.
|
||||
|
||||
Once the ACI image has been downloaded rocket will extract the image's name from the image metadata. The image's name will be used to locate trusted public keys in the rocket keystore and perform signature validation.
|
||||
Once the ACI image has been downloaded rkt will extract the image's name from the image metadata. The image's name will be used to locate trusted public keys in the rkt keystore and perform signature validation.
|
||||
|
||||
## Verifying Images with Rocket
|
||||
## Verifying Images with rkt
|
||||
|
||||
### Establishing Trust
|
||||
|
||||
By default rocket does not trust any signing keys. Trust is established by storing public keys in the rocket keystore.
|
||||
The following directories make up the default rocket keystore layout:
|
||||
By default rkt does not trust any signing keys. Trust is established by storing public keys in the rkt keystore.
|
||||
The following directories make up the default rkt keystore layout:
|
||||
|
||||
```
|
||||
/etc/rkt/trustedkeys/root.d
|
||||
@@ -270,14 +270,14 @@ If you would like to trust a public key for any image store the public key in on
|
||||
$ sudo rkt -h
|
||||
Usage of rkt:
|
||||
-debug=false: Print out more debug information to stderr
|
||||
-dir="/var/lib/rkt": rocket data directory
|
||||
-dir="/var/lib/rkt": rkt data directory
|
||||
-help=false: Print usage information and exit
|
||||
-insecure-skip-verify=false: skip image verification
|
||||
```
|
||||
|
||||
#### Download, verify and run an ACI
|
||||
|
||||
By default rocket will attempt to download the ACI detached signature and verify the image:
|
||||
By default rkt will attempt to download the ACI detached signature and verify the image:
|
||||
|
||||
```
|
||||
$ sudo rkt run example.com/hello:0.0.1
|
||||
@@ -302,7 +302,7 @@ Downloading aci: [= ] 32.8 KB/1.26 MB
|
||||
^]^]Container stage1 terminated by signal KILL.
|
||||
```
|
||||
|
||||
Notice when the `-insecure-skip-verify` flag is used, rocket will print the following warning:
|
||||
Notice when the `-insecure-skip-verify` flag is used, rkt will print the following warning:
|
||||
|
||||
```
|
||||
rkt: warning: signature verification has been disabled
|
||||
|
||||
@@ -4,7 +4,7 @@ Stage1 ACI implementor's guide
|
||||
Background
|
||||
----------
|
||||
|
||||
Rocket's execution of pods is divided roughly into three separate stages:
|
||||
rkt's execution of pods is divided roughly into three separate stages:
|
||||
|
||||
0. Stage 0: discovering, fetching, verifying, storing, and compositing of both application (stage 2) and stage 1 images for execution.
|
||||
1. Stage 1: execution of the stage 1 image from within the composite image prepared by stage 0.
|
||||
@@ -23,20 +23,20 @@ Stage 2 is the destination application images and stage 1 is the vehicle for get
|
||||
Entrypoints
|
||||
-----------
|
||||
|
||||
### `rkt run` => "coreos.com/rocket/stage1/run"
|
||||
### `rkt run` => "coreos.com/rkt/stage1/run"
|
||||
|
||||
0. rkt prepares the pod's stage 1 and stage 2 images and Pod Manifest under "/var/lib/rkt/pods/$uuid", acquiring an exclusive advisory lock on the directory.
|
||||
1. chdirs to "/var/lib/rkt/pods/$uuid"
|
||||
2. resolves the "coreos.com/rocket/stage1/run" entrypoint via Annotations found within "/var/lib/rkt/pods/$uuid/stage1/manifest"
|
||||
2. resolves the "coreos.com/rkt/stage1/run" entrypoint via Annotations found within "/var/lib/rkt/pods/$uuid/stage1/manifest"
|
||||
3. executes the resolved entrypoint relative to "/var/lib/rkt/pods/$uuid/stage1/rootfs"
|
||||
|
||||
It is the responsibility of this entrypoint to consume the Pod Manifest and execute the constituent apps in the appropriate environments as specified by the Pod Manifest.
|
||||
|
||||
The environment variable "RKT_LOCK_FD" contains the file descriptor number of the open directory handle for "/var/lib/rkt/pods/$uuid". It is necessary that stage 1 leave this file descriptor open and in its locked state for the duration of the `rkt run`.
|
||||
|
||||
In the bundled rocket stage 1 which includes systemd-nspawn and systemd, the entrypoint is a static Go program found at "/init" within the stage 1 ACI rootfs. The majority of its execution entails generating a systemd-nspawn argument list and writing systemd unit files for the constituent apps before executing systemd-nspawn. Systemd-nspawn then boots the stage 1 systemd with the just-written unit files for launching the contained apps. The "/init" program is essentially a Pod Manifest to systemd-nspawn + systemd.service translator.
|
||||
In the bundled rkt stage 1 which includes systemd-nspawn and systemd, the entrypoint is a static Go program found at "/init" within the stage 1 ACI rootfs. The majority of its execution entails generating a systemd-nspawn argument list and writing systemd unit files for the constituent apps before executing systemd-nspawn. Systemd-nspawn then boots the stage 1 systemd with the just-written unit files for launching the contained apps. The "/init" program is essentially a Pod Manifest to systemd-nspawn + systemd.service translator.
|
||||
|
||||
An alternative stage 1 could forego systemd-nspawn and systemd altogether, or retain these and introduce something like novm or qemu-kvm for greater isolation by first starting a VM. All that is required is an executable at the place indicated by the "coreos.com/rocket/stage1/run" entrypoint which knows how to apply the Pod Manifest and prepared ACI file-systems to good effect.
|
||||
An alternative stage 1 could forego systemd-nspawn and systemd altogether, or retain these and introduce something like novm or qemu-kvm for greater isolation by first starting a VM. All that is required is an executable at the place indicated by the "coreos.com/rkt/stage1/run" entrypoint which knows how to apply the Pod Manifest and prepared ACI file-systems to good effect.
|
||||
|
||||
|
||||
#### Arguments
|
||||
@@ -44,16 +44,16 @@ An alternative stage 1 could forego systemd-nspawn and systemd altogether, or re
|
||||
* --private-net to trigger the creation of a private network
|
||||
|
||||
|
||||
### `rkt enter` => "coreos.com/rocket/stage1/enter"
|
||||
### `rkt enter` => "coreos.com/rkt/stage1/enter"
|
||||
|
||||
0. rkt verifies the pod and image to enter are valid and running
|
||||
1. chdirs to "/var/lib/rkt/pods/$uuid"
|
||||
2. resolves the "coreos.com/rocket/stage1/enter" entrypoint via Annotations found within "/var/lib/rkt/pods/$uuid/stage1/manifest"
|
||||
2. resolves the "coreos.com/rkt/stage1/enter" entrypoint via Annotations found within "/var/lib/rkt/pods/$uuid/stage1/manifest"
|
||||
3. executes the resolved entrypoint relative to "/var/lib/rkt/pods/$uuid/stage1/rootfs"
|
||||
|
||||
In the bundled rocket stage 1 the entrypoint is a statically-linked C program found at "/enter" within the stage 1 ACI rootfs. This program enters the namespaces of the systemd-nspawn container's PID 1 before executing the "/diagexec" program which then chroots into the specific application's rootfs loading the application's environment variables as well.
|
||||
In the bundled rkt stage 1 the entrypoint is a statically-linked C program found at "/enter" within the stage 1 ACI rootfs. This program enters the namespaces of the systemd-nspawn container's PID 1 before executing the "/diagexec" program which then chroots into the specific application's rootfs loading the application's environment variables as well.
|
||||
|
||||
An alternative stage 1 would need to do whatever is appropriate for entering the application's environment created by its own "coreos.com/rocket/stage1/run" entrypoint.
|
||||
An alternative stage 1 would need to do whatever is appropriate for entering the application's environment created by its own "coreos.com/rkt/stage1/run" entrypoint.
|
||||
|
||||
#### Arguments
|
||||
|
||||
@@ -72,7 +72,7 @@ Examples
|
||||
{
|
||||
"acKind": "ImageManifest",
|
||||
"acVersion": "0.2.0",
|
||||
"name": "foo.com/rocket/stage1",
|
||||
"name": "foo.com/rkt/stage1",
|
||||
"labels": [
|
||||
{
|
||||
"name": "version",
|
||||
@@ -89,11 +89,11 @@ Examples
|
||||
],
|
||||
"annotations": [
|
||||
{
|
||||
"name": "coreos.com/rocket/stage1/run",
|
||||
"name": "coreos.com/rkt/stage1/run",
|
||||
"value": "/ex/run"
|
||||
},
|
||||
{
|
||||
"name": "coreos.com/rocket/stage1/enter",
|
||||
"name": "coreos.com/rkt/stage1/enter",
|
||||
"value": "/ex/enter"
|
||||
}
|
||||
]
|
||||
|
||||
Generated
+1
-1
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"ImportPath": "github.com/coreos/rocket",
|
||||
"ImportPath": "github.com/coreos/rkt",
|
||||
"GoVersion": "go1.4.1",
|
||||
"Packages": [
|
||||
"./..."
|
||||
|
||||
Generated
Vendored
+2
-2
@@ -23,8 +23,8 @@ import (
|
||||
"regexp"
|
||||
"strings"
|
||||
|
||||
flag "github.com/coreos/rocket/Godeps/_workspace/src/github.com/spf13/pflag"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/speter.net/go/exp/math/dec/inf"
|
||||
flag "github.com/coreos/rkt/Godeps/_workspace/src/github.com/spf13/pflag"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/speter.net/go/exp/math/dec/inf"
|
||||
)
|
||||
|
||||
// Quantity is a fixed-point representation of a number.
|
||||
|
||||
Generated
Vendored
+1
-1
@@ -19,7 +19,7 @@ package resource_test
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/GoogleCloudPlatform/kubernetes/pkg/api/resource"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/GoogleCloudPlatform/kubernetes/pkg/api/resource"
|
||||
)
|
||||
|
||||
func ExampleFormat() {
|
||||
|
||||
Generated
Vendored
+2
-2
@@ -21,8 +21,8 @@ import (
|
||||
"encoding/json"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/spf13/pflag"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/speter.net/go/exp/math/dec/inf"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/spf13/pflag"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/speter.net/go/exp/math/dec/inf"
|
||||
fuzz "github.com/google/gofuzz"
|
||||
)
|
||||
|
||||
|
||||
+3
-3
@@ -7,9 +7,9 @@ import (
|
||||
"io/ioutil"
|
||||
"os"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/aci"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/aci"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+5
-5
@@ -30,11 +30,11 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/docker2aci/tarball"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/aci"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/pkg/acirenderer"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/docker2aci/tarball"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/aci"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/pkg/acirenderer"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+1
-1
@@ -6,7 +6,7 @@ import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/pkg/tarheader"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/pkg/tarheader"
|
||||
)
|
||||
|
||||
// BuildWalker creates a filepath.WalkFunc that walks over the given root
|
||||
|
||||
+1
-1
@@ -15,7 +15,7 @@ import (
|
||||
"os/exec"
|
||||
"path/filepath"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
)
|
||||
|
||||
type FileType string
|
||||
|
||||
+1
-1
@@ -25,7 +25,7 @@ import (
|
||||
"path/filepath"
|
||||
"strings"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+1
-1
@@ -7,7 +7,7 @@ import (
|
||||
"io"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
)
|
||||
|
||||
// ArchiveWriter writes App Container Images. Users wanting to create an ACI or
|
||||
|
||||
+2
-2
@@ -8,8 +8,8 @@ import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/aci"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/aci"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@ import (
|
||||
"runtime"
|
||||
"strings"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/discovery"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/discovery"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+1
-1
@@ -6,7 +6,7 @@ import (
|
||||
"strings"
|
||||
"text/template"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+2
-2
@@ -11,8 +11,8 @@ import (
|
||||
"os"
|
||||
"strings"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/aci"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/aci"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@ package main
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
)
|
||||
|
||||
var cmdVersion = &Command{
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@ import (
|
||||
"regexp"
|
||||
"strings"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/net/html"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/net/html/atom"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/net/html"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/net/html/atom"
|
||||
)
|
||||
|
||||
type acMeta struct {
|
||||
|
||||
+1
-1
@@ -7,7 +7,7 @@ import (
|
||||
"os"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
func fakeHTTPGet(filename string, failures int) func(uri string) (*http.Response, error) {
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@ import (
|
||||
"net/url"
|
||||
"strings"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
type App struct {
|
||||
|
||||
+1
-1
@@ -4,7 +4,7 @@ import (
|
||||
"reflect"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
func TestNewAppFromString(t *testing.T) {
|
||||
|
||||
+2
-2
@@ -10,8 +10,8 @@ import (
|
||||
"path/filepath"
|
||||
"strings"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
// An ACIRegistry provides all functions of an ACIProvider plus functions to
|
||||
|
||||
+2
-2
@@ -10,8 +10,8 @@ import (
|
||||
"reflect"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
const tstprefix = "acirenderer-test"
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@ package acirenderer
|
||||
import (
|
||||
"container/list"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
// CreateDepListFromImageID returns the flat dependency tree of the image with
|
||||
|
||||
+3
-3
@@ -8,9 +8,9 @@ import (
|
||||
"io/ioutil"
|
||||
"os"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/aci"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/aci"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+1
-1
@@ -4,7 +4,7 @@ import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@ package schema
|
||||
import (
|
||||
"encoding/json"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
type Kind struct {
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@ import (
|
||||
"errors"
|
||||
"fmt"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
const PodManifestKind = types.ACKind("PodManifest")
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@ package schema
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
func TestPodManifestMerge(t *testing.T) {
|
||||
|
||||
+1
-1
@@ -4,7 +4,7 @@ import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/GoogleCloudPlatform/kubernetes/pkg/api/resource"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/GoogleCloudPlatform/kubernetes/pkg/api/resource"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@ package types
|
||||
import (
|
||||
"encoding/json"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/coreos/go-semver/semver"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/coreos/go-semver/semver"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@ import (
|
||||
"reflect"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/coreos/go-semver/semver"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/coreos/go-semver/semver"
|
||||
)
|
||||
|
||||
func TestMarshalSemver(t *testing.T) {
|
||||
|
||||
+1
-1
@@ -1,7 +1,7 @@
|
||||
package schema
|
||||
|
||||
import (
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/appc/spec/schema/types"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+2
-2
@@ -13,8 +13,8 @@ import (
|
||||
"io"
|
||||
"os"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
var _ Filer = &ACIDFiler0{} // Ensure ACIDFiler0 is a Filer
|
||||
|
||||
+1
-1
@@ -14,7 +14,7 @@ import (
|
||||
"os"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
var _ Filer = &truncFiler{}
|
||||
|
||||
+3
-3
@@ -12,9 +12,9 @@ import (
|
||||
"sort"
|
||||
"strings"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/bufs"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/sortutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/bufs"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/sortutil"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+2
-2
@@ -16,8 +16,8 @@ import (
|
||||
"runtime"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+3
-3
@@ -14,9 +14,9 @@ import (
|
||||
"sort"
|
||||
"strings"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/bufs"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/zappy"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/bufs"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/zappy"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+3
-3
@@ -17,9 +17,9 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/bufs"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/sortutil"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/zappy"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/bufs"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/sortutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/zappy"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+1
-1
@@ -10,7 +10,7 @@ package lldb
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
func doubleTrouble(first, second error) error {
|
||||
|
||||
+1
-1
@@ -13,7 +13,7 @@ import (
|
||||
"runtime"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
)
|
||||
|
||||
// Bench knobs.
|
||||
|
||||
+1
-1
@@ -13,7 +13,7 @@ import (
|
||||
"fmt"
|
||||
"math"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+2
-2
@@ -81,8 +81,8 @@ import (
|
||||
"fmt"
|
||||
"io"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+1
-1
@@ -8,7 +8,7 @@ import (
|
||||
"io"
|
||||
"os"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
var _ Filer = (*OSFiler)(nil)
|
||||
|
||||
+2
-2
@@ -9,8 +9,8 @@ package lldb
|
||||
import (
|
||||
"os"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
var _ Filer = &SimpleFileFiler{} // Ensure SimpleFileFiler is a Filer.
|
||||
|
||||
+2
-2
@@ -55,8 +55,8 @@ import (
|
||||
"io"
|
||||
"sync"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+2
-2
@@ -12,8 +12,8 @@ import (
|
||||
"math/rand"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
func (f *bitFiler) dump(w io.Writer) {
|
||||
|
||||
+3
-3
@@ -20,9 +20,9 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil/storage"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil/storage"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@ package falloc
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil/storage"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil/storage"
|
||||
"sync"
|
||||
)
|
||||
|
||||
|
||||
+3
-3
@@ -9,8 +9,8 @@ package falloc
|
||||
// Pull test dependencies too.
|
||||
// Enables easy 'go test X' after 'go get X'
|
||||
import (
|
||||
_ "github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
_ "github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil/storage"
|
||||
_ "github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil"
|
||||
_ "github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil/storage"
|
||||
|
||||
_ "github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
_ "github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
+2
-2
@@ -29,8 +29,8 @@ Conceptual analogy:
|
||||
package hdb
|
||||
|
||||
import (
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil/falloc"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/fileutil/storage"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil/falloc"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/fileutil/storage"
|
||||
)
|
||||
|
||||
type Store struct {
|
||||
|
||||
+1
-1
@@ -11,7 +11,7 @@ package main
|
||||
import (
|
||||
"bufio"
|
||||
"flag"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"log"
|
||||
"math"
|
||||
"os"
|
||||
|
||||
+1
-1
@@ -10,7 +10,7 @@ package main
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"image"
|
||||
"image/png"
|
||||
"io/ioutil"
|
||||
|
||||
+2
-2
@@ -19,8 +19,8 @@ import (
|
||||
"sort"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/sortutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/sortutil"
|
||||
)
|
||||
|
||||
func main() {
|
||||
|
||||
+1
-1
@@ -15,7 +15,7 @@ import (
|
||||
"runtime"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+1
-1
@@ -12,7 +12,7 @@ import (
|
||||
"sync"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
func r32() *mathutil.FC32 {
|
||||
|
||||
+1
-1
@@ -24,7 +24,7 @@ import (
|
||||
"math"
|
||||
"math/big"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/remyoudompheng/bigfft"
|
||||
)
|
||||
|
||||
|
||||
+1
-1
@@ -25,7 +25,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/strutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/strutil"
|
||||
)
|
||||
|
||||
// Note: All benchmarks report MB/s equal to record/s.
|
||||
|
||||
+1
-1
@@ -53,7 +53,7 @@ Referenced from above:
|
||||
*/
|
||||
package driver
|
||||
|
||||
import "github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/ql"
|
||||
import "github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/ql"
|
||||
|
||||
func init() {
|
||||
ql.RegisterDriver()
|
||||
|
||||
+3
-3
@@ -20,9 +20,9 @@ import (
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/camlistore/lock"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/exp/lldb"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/camlistore/lock"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/exp/lldb"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+1
-1
@@ -14,7 +14,7 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+1
-1
@@ -12,7 +12,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
type (
|
||||
|
||||
+1
-1
@@ -19,7 +19,7 @@ import __yyfmt__ "fmt"
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
type yySymType struct {
|
||||
|
||||
+1
-1
@@ -22,7 +22,7 @@ import (
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/strutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/strutil"
|
||||
)
|
||||
|
||||
// NOTE: all rset implementations must be safe for concurrent use by multiple
|
||||
|
||||
+1
-1
@@ -59,7 +59,7 @@ import (
|
||||
"sort"
|
||||
"strings"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/ql"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/ql"
|
||||
)
|
||||
|
||||
func str(data []interface{}) string {
|
||||
|
||||
+1
-1
@@ -13,7 +13,7 @@ import (
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
)
|
||||
|
||||
func dbg(s string, va ...interface{}) {
|
||||
|
||||
+1
-1
@@ -6,7 +6,7 @@ package strutil
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/cznic/mathutil"
|
||||
"math"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
+1
-1
@@ -9,7 +9,7 @@ import (
|
||||
"net/http"
|
||||
"path"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/gorilla/context"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/gorilla/context"
|
||||
)
|
||||
|
||||
// NewRouter returns a new router instance.
|
||||
|
||||
+1
-1
@@ -9,7 +9,7 @@ import (
|
||||
"net/http"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/gorilla/context"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/gorilla/context"
|
||||
)
|
||||
|
||||
type routeTest struct {
|
||||
|
||||
Generated
Vendored
+1
-1
@@ -5,7 +5,7 @@ import (
|
||||
"fmt"
|
||||
"io"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/peterbourgon/diskv"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/peterbourgon/diskv"
|
||||
)
|
||||
|
||||
const transformBlockSize = 2 // grouping of chars per directory depth
|
||||
|
||||
Generated
Vendored
+1
-1
@@ -3,7 +3,7 @@ package main
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/peterbourgon/diskv"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/peterbourgon/diskv"
|
||||
)
|
||||
|
||||
func main() {
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@ import (
|
||||
"io/ioutil"
|
||||
"os"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/peterbourgon/diskv"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/peterbourgon/diskv"
|
||||
|
||||
"testing"
|
||||
)
|
||||
|
||||
+1
-1
@@ -1,7 +1,7 @@
|
||||
package diskv
|
||||
|
||||
import (
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/petar/GoLLRB/llrb"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/petar/GoLLRB/llrb"
|
||||
"sync"
|
||||
)
|
||||
|
||||
|
||||
+1
-1
@@ -6,7 +6,7 @@ import (
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/peterbourgon/diskv"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/peterbourgon/diskv"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+1
-1
@@ -14,7 +14,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
. "github.com/coreos/rocket/Godeps/_workspace/src/github.com/spf13/pflag"
|
||||
. "github.com/coreos/rkt/Godeps/_workspace/src/github.com/spf13/pflag"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+1
-1
@@ -6,7 +6,7 @@ import (
|
||||
"strings"
|
||||
"syscall"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
)
|
||||
|
||||
// AddrAdd will add an IP address to a link device.
|
||||
|
||||
+1
-1
@@ -7,7 +7,7 @@ import (
|
||||
"net"
|
||||
"syscall"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
)
|
||||
|
||||
var native = nl.NativeEndian()
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@ import (
|
||||
"syscall"
|
||||
"unsafe"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+1
-1
@@ -11,7 +11,7 @@ package netlink
|
||||
import (
|
||||
"net"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
+1
-1
@@ -4,7 +4,7 @@ import (
|
||||
"fmt"
|
||||
"syscall"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
)
|
||||
|
||||
func LinkGetProtinfo(link Link) (Protinfo, error) {
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@ import (
|
||||
"net"
|
||||
"syscall"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
)
|
||||
|
||||
// RtAttr is shared so it is in netlink_linux.go
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@ package netlink
|
||||
import (
|
||||
"syscall"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
)
|
||||
|
||||
func selFromPolicy(sel *nl.XfrmSelector, policy *XfrmPolicy) {
|
||||
|
||||
+1
-1
@@ -4,7 +4,7 @@ import (
|
||||
"fmt"
|
||||
"syscall"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/github.com/vishvananda/netlink/nl"
|
||||
)
|
||||
|
||||
func writeStateAlgo(a *XfrmStateAlgo) []byte {
|
||||
|
||||
+1
-1
@@ -10,7 +10,7 @@ import (
|
||||
"bufio"
|
||||
"bytes"
|
||||
"encoding/base64"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp/errors"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp/errors"
|
||||
"io"
|
||||
)
|
||||
|
||||
|
||||
+3
-3
@@ -18,9 +18,9 @@ import (
|
||||
"net/textproto"
|
||||
"strconv"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp/armor"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp/errors"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp/packet"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp/armor"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp/errors"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp/packet"
|
||||
)
|
||||
|
||||
// A Block represents a clearsigned message. A signature on a Block can
|
||||
|
||||
+1
-1
@@ -6,7 +6,7 @@ package clearsign
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp"
|
||||
"testing"
|
||||
)
|
||||
|
||||
|
||||
+3
-3
@@ -6,9 +6,9 @@ package openpgp
|
||||
|
||||
import (
|
||||
"crypto/rsa"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp/armor"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp/errors"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp/packet"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp/armor"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp/errors"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp/packet"
|
||||
"io"
|
||||
"time"
|
||||
)
|
||||
|
||||
+1
-1
@@ -4,7 +4,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp/packet"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp/packet"
|
||||
)
|
||||
|
||||
func TestKeyExpiry(t *testing.T) {
|
||||
|
||||
+1
-1
@@ -8,7 +8,7 @@ import (
|
||||
"compress/bzip2"
|
||||
"compress/flate"
|
||||
"compress/zlib"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp/errors"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp/errors"
|
||||
"io"
|
||||
"strconv"
|
||||
)
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@ package packet
|
||||
import (
|
||||
"crypto/rsa"
|
||||
"encoding/binary"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp/elgamal"
|
||||
"github.com/coreos/rocket/Godeps/_workspace/src/golang.org/x/crypto/openpgp/errors"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp/elgamal"
|
||||
"github.com/coreos/rkt/Godeps/_workspace/src/golang.org/x/crypto/openpgp/errors"
|
||||
"io"
|
||||
"math/big"
|
||||
"strconv"
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user