diff --git a/go.mod b/go.mod index 7f8aba175b44..116ae5ceb6c3 100644 --- a/go.mod +++ b/go.mod @@ -16,11 +16,11 @@ require ( github.com/containerd/platforms v1.0.0-rc.5 github.com/creack/pty v1.1.24 github.com/distribution/reference v0.6.0 - github.com/docker/cli v29.7.2+incompatible + github.com/docker/cli v29.8.0+incompatible github.com/docker/cli-docs-tool v0.11.0 github.com/docker/docker v28.5.2+incompatible github.com/docker/go-units v0.5.0 - github.com/gofrs/flock v0.13.0 + github.com/gofrs/flock v0.13.1 github.com/golang/snappy v1.0.0 github.com/google/go-dap v0.12.1-0.20250904181021-d7a2259b058b github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 @@ -30,8 +30,8 @@ require ( github.com/in-toto/in-toto-golang v0.11.0 github.com/mitchellh/hashstructure/v2 v2.0.2 github.com/moby/buildkit v0.33.0 - github.com/moby/moby/api v1.55.0 - github.com/moby/moby/client v0.5.0 + github.com/moby/moby/api v1.56.0 + github.com/moby/moby/client v0.6.0 github.com/moby/policy-helpers v0.0.0-20260901104222-dd6c5499c491 github.com/moby/sys/atomicwriter v0.1.0 github.com/moby/sys/mountinfo v0.7.2 @@ -60,7 +60,7 @@ require ( go.opentelemetry.io/otel/sdk v1.45.0 go.opentelemetry.io/otel/trace v1.45.0 go.yaml.in/yaml/v3 v3.0.5 - golang.org/x/crypto v0.55.0 + golang.org/x/crypto v0.56.0 golang.org/x/mod v0.40.0 golang.org/x/sync v0.22.0 golang.org/x/sys v0.47.0 @@ -111,10 +111,10 @@ require ( github.com/digitorus/pkcs7 v0.0.0-20230818184609-3a137a874352 // indirect github.com/digitorus/timestamp v0.0.0-20231217203849-220c5c2851b7 // indirect github.com/docker/distribution v2.8.3+incompatible // indirect - github.com/docker/docker-credential-helpers v0.9.8 // indirect - github.com/docker/go-connections v0.7.0 // indirect + github.com/docker/docker-credential-helpers v0.9.9 // indirect + github.com/docker/go-connections v0.8.1 // indirect github.com/felixge/httpsnoop v1.1.0 // indirect - github.com/fvbommel/sortorder v1.1.0 // indirect + github.com/fvbommel/sortorder v1.2.0 // indirect github.com/fxamacker/cbor/v2 v2.9.0 // indirect github.com/go-logr/logr v1.4.4 // indirect github.com/go-logr/stdr v1.2.2 // indirect @@ -162,7 +162,7 @@ require ( github.com/lestrrat-go/httprc/v3 v3.0.2 // indirect github.com/lestrrat-go/jwx/v3 v3.0.13 // indirect github.com/lestrrat-go/option/v2 v2.0.0 // indirect - github.com/mattn/go-runewidth v0.0.23 // indirect + github.com/mattn/go-runewidth v0.0.29 // indirect github.com/mattn/go-shellwords v1.0.12 // indirect github.com/mitchellh/go-wordwrap v1.0.1 // indirect github.com/moby/docker-image-spec v1.3.1 // indirect @@ -180,7 +180,7 @@ require ( github.com/package-url/packageurl-go v0.1.1 // indirect github.com/rcrowley/go-metrics v0.0.0-20250401214520-65e299d6c5c9 // indirect github.com/russross/blackfriday/v2 v2.1.0 // indirect - github.com/santhosh-tekuri/jsonschema/v6 v6.0.1 // indirect + github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 // indirect github.com/secure-systems-lab/go-securesystemslib v0.11.0 // indirect github.com/segmentio/asm v1.2.1 // indirect github.com/shibumi/go-pathspec v1.3.0 // indirect diff --git a/go.sum b/go.sum index 6c3a5b710ff3..7a9d224a478c 100644 --- a/go.sum +++ b/go.sum @@ -175,18 +175,18 @@ github.com/distribution/reference v0.6.0 h1:0IXCQ5g4/QMHHkarYzh5l+u8T3t73zM5Qvfr github.com/distribution/reference v0.6.0/go.mod h1:BbU0aIcezP1/5jX/8MP0YiH4SdvB5Y4f/wlDRiLyi3E= github.com/dlclark/regexp2 v1.11.0 h1:G/nrcoOa7ZXlpoa/91N3X7mM3r8eIlMBBJZvsz/mxKI= github.com/dlclark/regexp2 v1.11.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8= -github.com/docker/cli v29.7.2+incompatible h1:dlkwallR8XqfeVnA2ELEhdwvb4lsSwuB4IgsG8Q9cLY= -github.com/docker/cli v29.7.2+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8= +github.com/docker/cli v29.8.0+incompatible h1:ih0c2jq/nN7QfES8zIfwSzIhRScjs4ehER+kZ60aeSk= +github.com/docker/cli v29.8.0+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8= github.com/docker/cli-docs-tool v0.11.0 h1:7d8QARFb7QEobizqxmEM7fOteZEHwH/zWgHQtHZEcfE= github.com/docker/cli-docs-tool v0.11.0/go.mod h1:ma8BKiisUo8D6W05XEYIh3oa1UbgrZhi1nowyKFJa8Q= github.com/docker/distribution v2.8.3+incompatible h1:AtKxIZ36LoNK51+Z6RpzLpddBirtxJnzDrHLEKxTAYk= github.com/docker/distribution v2.8.3+incompatible/go.mod h1:J2gT2udsDAN96Uj4KfcMRqY0/ypR+oyYUYmja8H+y+w= github.com/docker/docker v28.5.2+incompatible h1:DBX0Y0zAjZbSrm1uzOkdr1onVghKaftjlSWt4AFexzM= github.com/docker/docker v28.5.2+incompatible/go.mod h1:eEKB0N0r5NX/I1kEveEz05bcu8tLC/8azJZsviup8Sk= -github.com/docker/docker-credential-helpers v0.9.8 h1:bIREROb7So6PRlq6KTtdS9MPEjC29OQRkFNlvK2OX8Q= -github.com/docker/docker-credential-helpers v0.9.8/go.mod h1:v1S+hepowrQXITkEfw6o4+BMbGot02wiKpzWhGUZK6c= -github.com/docker/go-connections v0.7.0 h1:6SsRfJddP22WMrCkj19x9WKjEDTB+ahsdiGYf0mN39c= -github.com/docker/go-connections v0.7.0/go.mod h1:no1qkHdjq7kLMGUXYAduOhYPSJxxvgWBh7ogVvptn3Q= +github.com/docker/docker-credential-helpers v0.9.9 h1:BkydjIgZ46JnDbqyM2p2fc63KMw6y+KHL3Em/2AGJ7w= +github.com/docker/docker-credential-helpers v0.9.9/go.mod h1:v1S+hepowrQXITkEfw6o4+BMbGot02wiKpzWhGUZK6c= +github.com/docker/go-connections v0.8.1 h1:JibmG5hULs5qXSr/cp/w3Pw5fZuStt4MOHMUExb29/M= +github.com/docker/go-connections v0.8.1/go.mod h1:no1qkHdjq7kLMGUXYAduOhYPSJxxvgWBh7ogVvptn3Q= github.com/docker/go-metrics v0.0.1 h1:AgB/0SvBxihN0X8OR4SjsblXkbMvalQ8cjmtKQ2rQV8= github.com/docker/go-metrics v0.0.1/go.mod h1:cG1hvH2utMXtqgqqYE9plW6lDxS3/5ayHzueweSI3Vw= github.com/docker/go-units v0.5.0 h1:69rxXcBk27SvSaaxTtLh/8llcHD8vYHT7WSdRZ/jvr4= @@ -201,8 +201,8 @@ github.com/fortytw2/leaktest v1.3.0 h1:u8491cBMTQ8ft8aeV+adlcytMZylmA5nnwwkRZjI8 github.com/fortytw2/leaktest v1.3.0/go.mod h1:jDsjWgpAGjm2CA7WthBh/CdZYEPF31XHquHwclZch5g= github.com/foxcpp/go-mockdns v1.2.0 h1:omK3OrHRD1IWJz1FuFBCFquhXslXoF17OvBS6JPzZF0= github.com/foxcpp/go-mockdns v1.2.0/go.mod h1:IhLeSFGed3mJIAXPH2aiRQB+kqz7oqu8ld2qVbOu7Wk= -github.com/fvbommel/sortorder v1.1.0 h1:fUmoe+HLsBTctBDoaBwpQo5N+nrCp8g/BjKb/6ZQmYw= -github.com/fvbommel/sortorder v1.1.0/go.mod h1:uk88iVf1ovNn1iLfgUVU2F9o5eO30ui720w+kxuqRs0= +github.com/fvbommel/sortorder v1.2.0 h1:TRIiRiGX+djh3Yf4FVxmWmAcYfIr5dH0NbzJWOSAWZk= +github.com/fvbommel/sortorder v1.2.0/go.mod h1:LbhO04ijZIeUuvz9B9BkI/qYrpZZEn1gWhxv4QjUKVs= github.com/fxamacker/cbor/v2 v2.9.0 h1:NpKPmjDBgUfBms6tr6JZkTHtfFGcMKsw3eGcmD/sapM= github.com/fxamacker/cbor/v2 v2.9.0/go.mod h1:vM4b+DJCtHn+zz7h3FFp/hDAI9WNWCsZj23V5ytsSxQ= github.com/go-chi/chi/v5 v5.3.0 h1:halUjDxhshgXHMrao5bB8eNBXo/rnzwr8m5m36glehM= @@ -274,8 +274,8 @@ github.com/goccy/go-json v0.10.5 h1:Fq85nIqj+gXn/S5ahsiTlK3TmC85qgirsdTP/+DeaC4= github.com/goccy/go-json v0.10.5/go.mod h1:oq7eo15ShAhp70Anwd5lgX2pLfOS3QCiwU/PULtXL6M= github.com/godbus/dbus/v5 v5.1.0 h1:4KLkAxT3aOY8Li4FRJe/KvhoNFFxo0m6fNuFUO8QJUk= github.com/godbus/dbus/v5 v5.1.0/go.mod h1:xhWf0FNVPg57R7Z0UbKHbJfkEywrmjJnf7w5xrFpKfA= -github.com/gofrs/flock v0.13.0 h1:95JolYOvGMqeH31+FC7D2+uULf6mG61mEZ/A8dRYMzw= -github.com/gofrs/flock v0.13.0/go.mod h1:jxeyy9R1auM5S6JYDBhDt+E2TCo7DkratH4Pgi8P+Z0= +github.com/gofrs/flock v0.13.1 h1:jjREztyBeSKBZYAC+mgc1laB+xsgy4kYMf3FbKF2UBo= +github.com/gofrs/flock v0.13.1/go.mod h1:sf4BFiHwnvgxa25DlQoDqXQnwRMEOwqxRq37P6MzzmE= github.com/golang-jwt/jwt/v5 v5.3.1 h1:kYf81DTWFe7t+1VvL7eS+jKFVWaUnK9cB1qbwn63YCY= github.com/golang-jwt/jwt/v5 v5.3.1/go.mod h1:fxCRLWMO43lRc8nhHWY6LGqRcf+1gQWArsqaEUEa5bE= github.com/golang/protobuf v1.5.4 h1:i7eJL8qZTpSEXOPTxNKhASYpMn+8e5Q6AdndVa1dWek= @@ -379,8 +379,8 @@ github.com/lestrrat-go/option/v2 v2.0.0 h1:XxrcaJESE1fokHy3FpaQ/cXW8ZsIdWcdFzzLO github.com/lestrrat-go/option/v2 v2.0.0/go.mod h1:oSySsmzMoR0iRzCDCaUfsCzxQHUEuhOViQObyy7S6Vg= github.com/letsencrypt/boulder v0.20260309.0 h1:kZynrxK3QfqLGx6hhoz+Rfs3hgltJs1p9Mp+4+VwnY0= github.com/letsencrypt/boulder v0.20260309.0/go.mod h1:yG8lj8pNPZ8taq3oNdTpfBS+eC74IaEuiewqzVpXiWE= -github.com/mattn/go-runewidth v0.0.23 h1:7ykA0T0jkPpzSvMS5i9uoNn2Xy3R383f9HDx3RybWcw= -github.com/mattn/go-runewidth v0.0.23/go.mod h1:XBkDxAl56ILZc9knddidhrOlY5R/pDhgLpndooCuJAs= +github.com/mattn/go-runewidth v0.0.29 h1:3oGF3R/S2N9DQ3ptftzVIvg2eicmojCzlwBEmqEPDfQ= +github.com/mattn/go-runewidth v0.0.29/go.mod h1:3qAiGCV4Koz/yuveO58qUefmUTRm8r0IGEXZ9jeHp/8= github.com/mattn/go-shellwords v1.0.12 h1:M2zGm7EW6UQJvDeQxo4T51eKPurbeFbe8WtebGE2xrk= github.com/mattn/go-shellwords v1.0.12/go.mod h1:EZzvwXDESEeg03EKmM+RmDnNOPKG4lLtQsUlTZDWQ8Y= github.com/miekg/dns v1.1.57 h1:Jzi7ApEIzwEPLHWRcafCN9LZSBbqQpxjt/wpgvg7wcM= @@ -401,10 +401,10 @@ github.com/moby/go-archive v0.2.0 h1:zg5QDUM2mi0JIM9fdQZWC7U8+2ZfixfTYoHL7rWUcP8 github.com/moby/go-archive v0.2.0/go.mod h1:mNeivT14o8xU+5q1YnNrkQVpK+dnNe/K6fHqnTg4qPU= github.com/moby/locker v1.0.1 h1:fOXqR41zeveg4fFODix+1Ch4mj/gT0NE1XJbp/epuBg= github.com/moby/locker v1.0.1/go.mod h1:S7SDdo5zpBK84bzzVlKr2V0hz+7x9hWbYC/kq7oQppc= -github.com/moby/moby/api v1.55.0 h1:2/sexvQyqIWS8pRSCFddBfpW2qE7vR7FCL+vN8pxwMc= -github.com/moby/moby/api v1.55.0/go.mod h1:+RQ6wluLwtYaTd1WnPLykIDPekkuyD/ROWQClE83pzs= -github.com/moby/moby/client v0.5.0 h1:5XhyPk2fuOWf6RlSFa3MkIIgDZkF25xToXW8Q/BH7cc= -github.com/moby/moby/client v0.5.0/go.mod h1:rcVpF8ncl9vo5gaIBdol6CnbEtSj1uxMvEV/UrykF/s= +github.com/moby/moby/api v1.56.0 h1:GQzua3NA599ASSIICx0iFgiJeO9YkdDARvQsm23ZZuQ= +github.com/moby/moby/api v1.56.0/go.mod h1:sZ+THbVWkjOmBPPfbnzdD/G1LuIexWhqlSHHPTDQ1Uk= +github.com/moby/moby/client v0.6.0 h1:AJjEB21QPbXSXjDsZorFBoDZPhMrfbpaPLgSMAW9Bgs= +github.com/moby/moby/client v0.6.0/go.mod h1:OCo00wNRyA3m4lmJ228W3JbyCN4ZNNYjpOXiJydBdcQ= github.com/moby/patternmatcher v0.6.1 h1:qlhtafmr6kgMIJjKJMDmMWq7WLkKIo23hsrpR3x084U= github.com/moby/patternmatcher v0.6.1/go.mod h1:hDPoyOpDY7OrrMDLaYoY3hf52gNCR/YOUYxkhApJIxc= github.com/moby/policy-helpers v0.0.0-20260901104222-dd6c5499c491 h1:5qXAyBr9AXXAqPoFK/wY85wggaKyYSMCNh8QF/O21Rk= @@ -477,8 +477,8 @@ github.com/russross/blackfriday/v2 v2.1.0 h1:JIOH55/0cWyOuilr9/qlrm0BSXldqnqwMsf github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM= github.com/ryanuber/go-glob v1.0.0 h1:iQh3xXAumdQ+4Ufa5b25cRpC5TYKlno6hsv6Cb3pkBk= github.com/ryanuber/go-glob v1.0.0/go.mod h1:807d1WSdnB0XRJzKNil9Om6lcp/3a0v4qIHxIXzX/Yc= -github.com/santhosh-tekuri/jsonschema/v6 v6.0.1 h1:PKK9DyHxif4LZo+uQSgXNqs0jj5+xZwwfKHgph2lxBw= -github.com/santhosh-tekuri/jsonschema/v6 v6.0.1/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU= +github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 h1:1EYB5IzjZawrrnELUi78f9fPu57HuXjmddZPjrls/28= +github.com/santhosh-tekuri/jsonschema/v6 v6.0.3/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU= github.com/sassoftware/relic v7.2.1+incompatible h1:Pwyh1F3I0r4clFJXkSI8bOyJINGqpgjJU3DYAZeI05A= github.com/sassoftware/relic v7.2.1+incompatible/go.mod h1:CWfAxv73/iLZ17rbyhIEq3K9hs5w6FpNMdUT//qR+zk= github.com/sassoftware/relic/v7 v7.6.2 h1:rS44Lbv9G9eXsukknS4mSjIAuuX+lMq/FnStgmZlUv4= @@ -634,8 +634,8 @@ go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw= go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg= go.yaml.in/yaml/v4 v4.0.0-rc.4 h1:UP4+v6fFrBIb1l934bDl//mmnoIZEDK0idg1+AIvX5U= go.yaml.in/yaml/v4 v4.0.0-rc.4/go.mod h1:aZqd9kCMsGL7AuUv/m/PvWLdg5sjJsZ4oHDEnfPPfY0= -golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= -golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= +golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y= +golang.org/x/crypto v0.56.0/go.mod h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I= golang.org/x/mod v0.40.0 h1:hUv+3cXcdRHz08UmSiOob7sadHig73uo5bkXxQ/tvUs= golang.org/x/mod v0.40.0/go.mod h1:0/weTWkPWGBikyTWAX3dkjVztMmBA5hM0DH6BElSupE= golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To= diff --git a/vendor/github.com/docker/cli/cli-plugins/plugin/plugin.go b/vendor/github.com/docker/cli/cli-plugins/plugin/plugin.go index 58ee3b876287..a90e4b6f6cbe 100644 --- a/vendor/github.com/docker/cli/cli-plugins/plugin/plugin.go +++ b/vendor/github.com/docker/cli/cli-plugins/plugin/plugin.go @@ -1,3 +1,6 @@ +// FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: +//go:build go1.26 + package plugin import ( @@ -97,8 +100,7 @@ func Run(makeCmd func(command.Cli) *cobra.Command, meta metadata.Metadata, ops . plugin := makeCmd(dockerCLI) if err := RunPlugin(dockerCLI, plugin, meta); err != nil { - var stErr cli.StatusError - if errors.As(err, &stErr) { + if stErr, ok := errors.AsType[cli.StatusError](err); ok { // StatusError should only be used for errors, and all errors should // have a non-zero exit status, so never exit with 0 if stErr.StatusCode == 0 { // FIXME(thaJeztah): this should never be used with a zero status-code. Check if we do this anywhere. diff --git a/vendor/github.com/docker/cli/cli/cobra.go b/vendor/github.com/docker/cli/cli/cobra.go index 4ec721f88772..bfcb1bdcc8f2 100644 --- a/vendor/github.com/docker/cli/cli/cobra.go +++ b/vendor/github.com/docker/cli/cli/cobra.go @@ -1,9 +1,12 @@ +// FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: +//go:build go1.26 + package cli import ( "fmt" "os" - "sort" + "slices" "strings" "github.com/docker/cli/cli-plugins/metadata" @@ -273,8 +276,8 @@ func topCommands(cmd *cobra.Command) []*cobra.Command { cmds = append(cmds, sub) } } - sort.SliceStable(cmds, func(i, j int) bool { - return sortorder.NaturalLess(cmds[i].Annotations["category-top"], cmds[j].Annotations["category-top"]) + slices.SortStableFunc(cmds, func(a, b *cobra.Command) int { + return sortorder.NaturalCompare(a.Annotations["category-top"], b.Annotations["category-top"]) }) return cmds } diff --git a/vendor/github.com/docker/cli/cli/command/cli.go b/vendor/github.com/docker/cli/cli/command/cli.go index eb69b3eb73fc..e405c2cc4f6d 100644 --- a/vendor/github.com/docker/cli/cli/command/cli.go +++ b/vendor/github.com/docker/cli/cli/command/cli.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package command @@ -316,7 +316,11 @@ func newAPIClientFromEndpoint(ep docker.Endpoint, configFile *configfile.ConfigF opts = append(opts, withCustomHeaders) } opts = append(opts, extraOpts...) - return client.New(opts...) + apiClient, err := client.New(opts...) + if err != nil { + return nil, err + } + return apiClient, nil } func resolveDockerEndpoint(s store.Reader, contextName string) (docker.Endpoint, error) { diff --git a/vendor/github.com/docker/cli/cli/command/context.go b/vendor/github.com/docker/cli/cli/command/context.go index b876e225ef43..153b046f5769 100644 --- a/vendor/github.com/docker/cli/cli/command/context.go +++ b/vendor/github.com/docker/cli/cli/command/context.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package command diff --git a/vendor/github.com/docker/cli/cli/command/defaultcontextstore.go b/vendor/github.com/docker/cli/cli/command/defaultcontextstore.go index 54ca58d2d8d4..90be220155a3 100644 --- a/vendor/github.com/docker/cli/cli/command/defaultcontextstore.go +++ b/vendor/github.com/docker/cli/cli/command/defaultcontextstore.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package command diff --git a/vendor/github.com/docker/cli/cli/command/formatter/buildcache.go b/vendor/github.com/docker/cli/cli/command/formatter/buildcache.go index 3a3c349988ef..d63cf05d63a3 100644 --- a/vendor/github.com/docker/cli/cli/command/formatter/buildcache.go +++ b/vendor/github.com/docker/cli/cli/command/formatter/buildcache.go @@ -1,7 +1,10 @@ +// FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: +//go:build go1.26 + package formatter import ( - "sort" + "slices" "strconv" "strings" "time" @@ -52,20 +55,20 @@ shared: {{.Shared}} } func buildCacheSort(buildCache []build.CacheRecord) { - sort.Slice(buildCache, func(i, j int) bool { - lui, luj := buildCache[i].LastUsedAt, buildCache[j].LastUsedAt + slices.SortFunc(buildCache, func(a, b build.CacheRecord) int { switch { - case lui == nil && luj == nil: - return strings.Compare(buildCache[i].ID, buildCache[j].ID) < 0 - case lui == nil: - return true - case luj == nil: - return false - case lui.Equal(*luj): - return strings.Compare(buildCache[i].ID, buildCache[j].ID) < 0 - default: - return lui.Before(*luj) + case a.LastUsedAt == nil && b.LastUsedAt == nil: + return strings.Compare(a.ID, b.ID) + case a.LastUsedAt == nil: + return -1 + case b.LastUsedAt == nil: + return 1 + } + + if c := a.LastUsedAt.Compare(*b.LastUsedAt); c != 0 { + return c } + return strings.Compare(a.ID, b.ID) }) } diff --git a/vendor/github.com/docker/cli/cli/command/formatter/container.go b/vendor/github.com/docker/cli/cli/command/formatter/container.go index 410b5cdce51e..7b77a8a75375 100644 --- a/vendor/github.com/docker/cli/cli/command/formatter/container.go +++ b/vendor/github.com/docker/cli/cli/command/formatter/container.go @@ -1,12 +1,13 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package formatter import ( + "cmp" "fmt" "net" - "sort" + "slices" "strconv" "strings" "time" @@ -295,7 +296,7 @@ func (c *ContainerContext) Labels() string { for k, v := range c.c.Labels { joinLabels = append(joinLabels, k+"="+v) } - sort.Strings(joinLabels) + slices.Sort(joinLabels) return strings.Join(joinLabels, ",") } @@ -395,9 +396,7 @@ func DisplayablePorts(ports []container.PortSummary) string { var result []string var hostMappings []string var groupMapKeys []string - sort.Slice(ports, func(i, j int) bool { - return comparePorts(ports[i], ports[j]) - }) + slices.SortFunc(ports, comparePorts) for _, port := range ports { current := port.PrivatePort @@ -452,18 +451,13 @@ func formGroup(key string, start, last uint16) string { return group + "/" + groupType } -func comparePorts(i, j container.PortSummary) bool { - if i.PrivatePort != j.PrivatePort { - return i.PrivatePort < j.PrivatePort - } - - if i.IP != j.IP { - return i.IP.String() < j.IP.String() - } - - if i.PublicPort != j.PublicPort { - return i.PublicPort < j.PublicPort - } - - return i.Type < j.Type +// comparePorts compares ports by private port, IP address, public port, +// and protocol, in that order. +func comparePorts(a, b container.PortSummary) int { + return cmp.Or( + cmp.Compare(a.PrivatePort, b.PrivatePort), + a.IP.Compare(b.IP), + cmp.Compare(a.PublicPort, b.PublicPort), + cmp.Compare(a.Type, b.Type), + ) } diff --git a/vendor/github.com/docker/cli/cli/command/formatter/custom.go b/vendor/github.com/docker/cli/cli/command/formatter/custom.go index b845e191fa20..80a716230b99 100644 --- a/vendor/github.com/docker/cli/cli/command/formatter/custom.go +++ b/vendor/github.com/docker/cli/cli/command/formatter/custom.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package formatter diff --git a/vendor/github.com/docker/cli/cli/command/formatter/displayutils.go b/vendor/github.com/docker/cli/cli/command/formatter/displayutils.go index ef008006ffb6..d17b432633f5 100644 --- a/vendor/github.com/docker/cli/cli/command/formatter/displayutils.go +++ b/vendor/github.com/docker/cli/cli/command/formatter/displayutils.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package formatter diff --git a/vendor/github.com/docker/cli/cli/command/formatter/formatter.go b/vendor/github.com/docker/cli/cli/command/formatter/formatter.go index 01c7867f31be..4beb7f56b256 100644 --- a/vendor/github.com/docker/cli/cli/command/formatter/formatter.go +++ b/vendor/github.com/docker/cli/cli/command/formatter/formatter.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package formatter diff --git a/vendor/github.com/docker/cli/cli/command/formatter/reflect.go b/vendor/github.com/docker/cli/cli/command/formatter/reflect.go index 150c01805a1d..bb17584209c0 100644 --- a/vendor/github.com/docker/cli/cli/command/formatter/reflect.go +++ b/vendor/github.com/docker/cli/cli/command/formatter/reflect.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package formatter diff --git a/vendor/github.com/docker/cli/cli/command/formatter/volume.go b/vendor/github.com/docker/cli/cli/command/formatter/volume.go index 75b6ad007f94..d55d3677cb77 100644 --- a/vendor/github.com/docker/cli/cli/command/formatter/volume.go +++ b/vendor/github.com/docker/cli/cli/command/formatter/volume.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package formatter diff --git a/vendor/github.com/docker/cli/cli/command/telemetry_docker.go b/vendor/github.com/docker/cli/cli/command/telemetry_docker.go index 0cd37b3a1cb7..b262e62e2197 100644 --- a/vendor/github.com/docker/cli/cli/command/telemetry_docker.go +++ b/vendor/github.com/docker/cli/cli/command/telemetry_docker.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package command diff --git a/vendor/github.com/docker/cli/cli/command/utils.go b/vendor/github.com/docker/cli/cli/command/utils.go index bf7638f37b3c..1bee68cec5de 100644 --- a/vendor/github.com/docker/cli/cli/command/utils.go +++ b/vendor/github.com/docker/cli/cli/command/utils.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package command diff --git a/vendor/github.com/docker/cli/cli/config/config.go b/vendor/github.com/docker/cli/cli/config/config.go index 5a637805091c..a7ea0acdd7e6 100644 --- a/vendor/github.com/docker/cli/cli/config/config.go +++ b/vendor/github.com/docker/cli/cli/config/config.go @@ -7,7 +7,6 @@ import ( "os/user" "path/filepath" "runtime" - "strings" "sync" "github.com/docker/cli/cli/config/configfile" @@ -98,9 +97,11 @@ func SetDir(dir string) { // Path returns the path to a file relative to the config dir func Path(p ...string) (string, error) { - path := filepath.Join(append([]string{Dir()}, p...)...) - if !strings.HasPrefix(path, Dir()+string(filepath.Separator)) { - return "", fmt.Errorf("path %q is outside of root config directory %q", path, Dir()) + root := Dir() + path := filepath.Join(append([]string{root}, p...)...) + + if rel, err := filepath.Rel(root, path); err != nil || !filepath.IsLocal(rel) { + return "", fmt.Errorf("path %q is outside of root config directory %q", path, root) } return path, nil } diff --git a/vendor/github.com/docker/cli/cli/config/configfile/file.go b/vendor/github.com/docker/cli/cli/config/configfile/file.go index 26e148f05987..e32b1e767cbb 100644 --- a/vendor/github.com/docker/cli/cli/config/configfile/file.go +++ b/vendor/github.com/docker/cli/cli/config/configfile/file.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package configfile @@ -232,8 +232,7 @@ func (c *ConfigFile) Save() (retErr error) { cfgFile = f } else if os.IsNotExist(err) { // extract the path from the error if the configfile does not exist or is a dangling symlink - var pathError *os.PathError - if errors.As(err, &pathError) { + if pathError, ok := errors.AsType[*os.PathError](err); ok { cfgFile = pathError.Path } } diff --git a/vendor/github.com/docker/cli/cli/config/memorystore/store.go b/vendor/github.com/docker/cli/cli/config/memorystore/store.go index 44523d392ba8..da1e94f41696 100644 --- a/vendor/github.com/docker/cli/cli/config/memorystore/store.go +++ b/vendor/github.com/docker/cli/cli/config/memorystore/store.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package memorystore diff --git a/vendor/github.com/docker/cli/cli/connhelper/connhelper.go b/vendor/github.com/docker/cli/cli/connhelper/connhelper.go index 8d97a2a40b7f..40281a56f8c2 100644 --- a/vendor/github.com/docker/cli/cli/connhelper/connhelper.go +++ b/vendor/github.com/docker/cli/cli/connhelper/connhelper.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 // Package connhelper provides helpers for connecting to a remote daemon host with custom logic. package connhelper diff --git a/vendor/github.com/docker/cli/cli/connhelper/ssh/ssh.go b/vendor/github.com/docker/cli/cli/connhelper/ssh/ssh.go index 2fcb54a98f68..b91f2bc02e11 100644 --- a/vendor/github.com/docker/cli/cli/connhelper/ssh/ssh.go +++ b/vendor/github.com/docker/cli/cli/connhelper/ssh/ssh.go @@ -1,3 +1,6 @@ +// FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: +//go:build go1.26 + // Package ssh provides the connection helper for ssh:// URL. package ssh @@ -15,8 +18,7 @@ import ( func ParseURL(daemonURL string) (*Spec, error) { u, err := url.Parse(daemonURL) if err != nil { - var urlErr *url.Error - if errors.As(err, &urlErr) { + if urlErr, ok := errors.AsType[*url.Error](err); ok { err = urlErr.Unwrap() } return nil, fmt.Errorf("invalid SSH URL: %w", err) diff --git a/vendor/github.com/docker/cli/cli/context/store/metadatastore.go b/vendor/github.com/docker/cli/cli/context/store/metadatastore.go index 8703e1c6c0d7..1751e820690b 100644 --- a/vendor/github.com/docker/cli/cli/context/store/metadatastore.go +++ b/vendor/github.com/docker/cli/cli/context/store/metadatastore.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package store @@ -10,7 +10,7 @@ import ( "os" "path/filepath" "reflect" - "sort" + "slices" "github.com/fvbommel/sortorder" "github.com/moby/sys/atomicwriter" @@ -122,8 +122,8 @@ func (s *metadataStore) list() ([]Metadata, error) { } res = append(res, c) } - sort.Slice(res, func(i, j int) bool { - return sortorder.NaturalLess(res[i].Name, res[j].Name) + slices.SortFunc(res, func(a, b Metadata) int { + return sortorder.NaturalCompare(a.Name, b.Name) }) return res, nil } diff --git a/vendor/github.com/docker/cli/cli/context/store/store.go b/vendor/github.com/docker/cli/cli/context/store/store.go index 2b8b5c311478..4122e077927f 100644 --- a/vendor/github.com/docker/cli/cli/context/store/store.go +++ b/vendor/github.com/docker/cli/cli/context/store/store.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package store diff --git a/vendor/github.com/docker/cli/cli/context/store/storeconfig.go b/vendor/github.com/docker/cli/cli/context/store/storeconfig.go index 4b42e7377931..79fb2da3f9bf 100644 --- a/vendor/github.com/docker/cli/cli/context/store/storeconfig.go +++ b/vendor/github.com/docker/cli/cli/context/store/storeconfig.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package store diff --git a/vendor/github.com/docker/cli/cli/streams/stream.go b/vendor/github.com/docker/cli/cli/streams/stream.go index f6356ccf347d..8a357718d586 100644 --- a/vendor/github.com/docker/cli/cli/streams/stream.go +++ b/vendor/github.com/docker/cli/cli/streams/stream.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package streams diff --git a/vendor/github.com/docker/cli/internal/tui/chip.go b/vendor/github.com/docker/cli/internal/tui/chip.go index 477d43103b80..893046264f04 100644 --- a/vendor/github.com/docker/cli/internal/tui/chip.go +++ b/vendor/github.com/docker/cli/internal/tui/chip.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package tui diff --git a/vendor/github.com/docker/cli/internal/tui/colors.go b/vendor/github.com/docker/cli/internal/tui/colors.go index 854e55ecd0c3..2b6a0f1f30c4 100644 --- a/vendor/github.com/docker/cli/internal/tui/colors.go +++ b/vendor/github.com/docker/cli/internal/tui/colors.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package tui diff --git a/vendor/github.com/docker/cli/internal/tui/count.go b/vendor/github.com/docker/cli/internal/tui/count.go index 303d650e5113..05d034808df6 100644 --- a/vendor/github.com/docker/cli/internal/tui/count.go +++ b/vendor/github.com/docker/cli/internal/tui/count.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package tui diff --git a/vendor/github.com/docker/cli/internal/tui/note.go b/vendor/github.com/docker/cli/internal/tui/note.go index 83f1f621e912..1e2f538d9733 100644 --- a/vendor/github.com/docker/cli/internal/tui/note.go +++ b/vendor/github.com/docker/cli/internal/tui/note.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package tui diff --git a/vendor/github.com/docker/cli/internal/tui/output.go b/vendor/github.com/docker/cli/internal/tui/output.go index 1776640af517..9022e66ae8cb 100644 --- a/vendor/github.com/docker/cli/internal/tui/output.go +++ b/vendor/github.com/docker/cli/internal/tui/output.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package tui diff --git a/vendor/github.com/docker/cli/internal/tui/str.go b/vendor/github.com/docker/cli/internal/tui/str.go index 9d50f7bd369f..819af243cd58 100644 --- a/vendor/github.com/docker/cli/internal/tui/str.go +++ b/vendor/github.com/docker/cli/internal/tui/str.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package tui diff --git a/vendor/github.com/docker/cli/opts/capabilities.go b/vendor/github.com/docker/cli/opts/capabilities.go index 82d071853b67..96a0e7d0f4f9 100644 --- a/vendor/github.com/docker/cli/opts/capabilities.go +++ b/vendor/github.com/docker/cli/opts/capabilities.go @@ -1,7 +1,10 @@ +// FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: +//go:build go1.26 + package opts import ( - "sort" + "slices" "strings" ) @@ -82,8 +85,8 @@ func EffectiveCapAddCapDrop(add, drop []string) (capAdd, capDrop []string) { } } - sort.Strings(capAdd) - sort.Strings(capDrop) + slices.Sort(capAdd) + slices.Sort(capDrop) return capAdd, capDrop } diff --git a/vendor/github.com/docker/cli/opts/gpus.go b/vendor/github.com/docker/cli/opts/gpus.go index e68ede7a085f..3905a691aca5 100644 --- a/vendor/github.com/docker/cli/opts/gpus.go +++ b/vendor/github.com/docker/cli/opts/gpus.go @@ -1,3 +1,6 @@ +// FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: +//go:build go1.26 + package opts import ( @@ -21,8 +24,7 @@ func parseCount(s string) (int, error) { } i, err := strconv.Atoi(s) if err != nil { - var numErr *strconv.NumError - if errors.As(err, &numErr) { + if numErr, ok := errors.AsType[*strconv.NumError](err); ok { err = numErr.Err } return 0, fmt.Errorf(`invalid count (%s): value must be either "all" or an integer: %w`, s, err) diff --git a/vendor/github.com/docker/cli/opts/network.go b/vendor/github.com/docker/cli/opts/network.go index 489ef8be3971..51f50f2070b1 100644 --- a/vendor/github.com/docker/cli/opts/network.go +++ b/vendor/github.com/docker/cli/opts/network.go @@ -1,3 +1,6 @@ +// FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: +//go:build go1.26 + package opts import ( @@ -100,8 +103,7 @@ func (n *NetworkOpt) Set(value string) error { //nolint:gocyclo case gwPriorityOpt: netOpt.GwPriority, err = strconv.Atoi(val) if err != nil { - var numErr *strconv.NumError - if errors.As(err, &numErr) { + if numErr, ok := errors.AsType[*strconv.NumError](err); ok { err = numErr.Err } return fmt.Errorf("invalid gw-priority (%s): %w", val, err) diff --git a/vendor/github.com/docker/cli/opts/opts.go b/vendor/github.com/docker/cli/opts/opts.go index 2e0adac6e0db..0a7706ca71ff 100644 --- a/vendor/github.com/docker/cli/opts/opts.go +++ b/vendor/github.com/docker/cli/opts/opts.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package opts @@ -11,6 +11,7 @@ import ( "net" "path" "slices" + "strconv" "strings" "github.com/docker/cli/internal/lazyregexp" @@ -477,3 +478,39 @@ func (m *MemSwapBytes) UnmarshalJSON(s []byte) error { b := MemBytes(*m) return b.UnmarshalJSON(s) } + +// UmaskOpt is a type for umask values in octal format +type UmaskOpt struct { + ptr *uint32 +} + +// Set sets the value of the UmaskOpt by passing a string in octal format +func (u *UmaskOpt) Set(s string) error { + v, err := strconv.ParseUint(s, 8, 32) + if err != nil { + return err + } + if u.ptr == nil { + u.ptr = new(uint32) + } + *u.ptr = uint32(v) + return nil +} + +// Type returns the type +func (*UmaskOpt) Type() string { + return "umask" +} + +// Value returns the uint32 ptr +func (u *UmaskOpt) Value() *uint32 { + return u.ptr +} + +// String returns the umask value in octal format, or "" if the pointer is nil. +func (u *UmaskOpt) String() string { + if u.ptr == nil { + return "" + } + return fmt.Sprintf("%#04o", uint64(*u.ptr)) +} diff --git a/vendor/github.com/docker/cli/opts/ulimit.go b/vendor/github.com/docker/cli/opts/ulimit.go index aa88bce71a24..ba4a82c9d865 100644 --- a/vendor/github.com/docker/cli/opts/ulimit.go +++ b/vendor/github.com/docker/cli/opts/ulimit.go @@ -1,8 +1,13 @@ +// FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: +//go:build go1.26 + package opts import ( "fmt" - "sort" + "maps" + "slices" + "strings" "github.com/docker/go-units" "github.com/moby/moby/api/types/container" @@ -41,20 +46,15 @@ func (o *UlimitOpt) String() string { for _, v := range *o.values { out = append(out, v.String()) } - sort.Strings(out) - return fmt.Sprintf("%v", out) + slices.Sort(out) + return fmt.Sprint(out) } // GetList returns a slice of pointers to Ulimits. Values are sorted by name. func (o *UlimitOpt) GetList() []*container.Ulimit { - ulimits := make([]*container.Ulimit, 0, len(*o.values)) - for _, v := range *o.values { - ulimits = append(ulimits, v) - } - sort.SliceStable(ulimits, func(i, j int) bool { - return ulimits[i].Name < ulimits[j].Name + return slices.SortedFunc(maps.Values(*o.values), func(a, b *container.Ulimit) int { + return strings.Compare(a.Name, b.Name) }) - return ulimits } // Type returns the option type diff --git a/vendor/github.com/docker/cli/templates/templates.go b/vendor/github.com/docker/cli/templates/templates.go index e156ca57514f..5443d70d7c77 100644 --- a/vendor/github.com/docker/cli/templates/templates.go +++ b/vendor/github.com/docker/cli/templates/templates.go @@ -1,5 +1,5 @@ // FIXME(thaJeztah): remove once we are a module; the go:build directive prevents go from downgrading language version to go1.16: -//go:build go1.25 +//go:build go1.26 package templates @@ -8,7 +8,7 @@ import ( "encoding/json" "fmt" "reflect" - "sort" + "slices" "strings" "text/template" ) @@ -125,12 +125,12 @@ func joinElements(elems any, sep string) (string, error) { return b.String(), nil case reflect.Map: - var out []string + out := make([]string, 0, rv.Len()) for _, k := range rv.MapKeys() { out = append(out, fmt.Sprint(rv.MapIndex(k).Interface())) } // Not ideal, but trying to keep a consistent order - sort.Strings(out) + slices.Sort(out) return strings.Join(out, sep), nil default: diff --git a/vendor/github.com/docker/go-connections/sockets/inmem_socket.go b/vendor/github.com/docker/go-connections/sockets/inmem_socket.go index 06fcf747ac4b..d35b105f37c6 100644 --- a/vendor/github.com/docker/go-connections/sockets/inmem_socket.go +++ b/vendor/github.com/docker/go-connections/sockets/inmem_socket.go @@ -1,21 +1,19 @@ package sockets import ( + "context" "net" "sync" ) -// dummyAddr is used to satisfy net.Addr for the in-mem socket -// it is just stored as a string and returns the string for all calls -type dummyAddr string +// inmemAddr is used to satisfy net.Addr for the in-memory socket. +type inmemAddr string // Network returns the addr string, satisfies net.Addr -func (a dummyAddr) Network() string { - return string(a) -} +func (a inmemAddr) Network() string { return "inmem" } // String returns the string form -func (a dummyAddr) String() string { +func (a inmemAddr) String() string { return string(a) } @@ -23,7 +21,7 @@ func (a dummyAddr) String() string { type InmemSocket struct { chConn chan net.Conn chClose chan struct{} - addr dummyAddr + addr inmemAddr mu sync.Mutex } @@ -34,7 +32,7 @@ func NewInmemSocket(addr string, bufSize int) *InmemSocket { return &InmemSocket{ chConn: make(chan net.Conn, bufSize), chClose: make(chan struct{}), - addr: dummyAddr(addr), + addr: inmemAddr(addr), } } @@ -67,15 +65,41 @@ func (s *InmemSocket) Close() error { return nil } -// Dial is used to establish a connection with the in-mem server. -// It returns a [net.ErrClosed] if the connection is already closed. +// Dial establishes a connection with the in-memory listener. +// +// The network and addr parameters are accepted for compatibility with +// conventional dialer APIs but are currently ignored. +// +// It is equivalent to calling DialContext with context.Background(). +// It returns [net.ErrClosed] if the listener has already been closed. func (s *InmemSocket) Dial(network, addr string) (net.Conn, error) { + return s.DialContext(context.Background(), network, addr) +} + +// DialContext establishes a connection with the in-memory listener. +// +// The network and addr parameters are accepted for compatibility with +// conventional dialer APIs but are currently ignored. +// +// If ctx is canceled before the connection is established, DialContext +// returns the context error. It returns [net.ErrClosed] if the listener +// has already been closed. +func (s *InmemSocket) DialContext(ctx context.Context, network, addr string) (net.Conn, error) { + if err := ctx.Err(); err != nil { + return nil, err + } + srvConn, clientConn := net.Pipe() select { case s.chConn <- srvConn: + return clientConn, nil + case <-ctx.Done(): + _ = srvConn.Close() + _ = clientConn.Close() + return nil, ctx.Err() case <-s.chClose: + _ = srvConn.Close() + _ = clientConn.Close() return nil, net.ErrClosed } - - return clientConn, nil } diff --git a/vendor/github.com/docker/go-connections/sockets/unix_socket.go b/vendor/github.com/docker/go-connections/sockets/unix_socket.go index e736f71d38b1..1f7b7cd95eed 100644 --- a/vendor/github.com/docker/go-connections/sockets/unix_socket.go +++ b/vendor/github.com/docker/go-connections/sockets/unix_socket.go @@ -47,38 +47,69 @@ For example: package sockets import ( + "errors" + "fmt" "net" "os" + "runtime" "syscall" ) +const supportsAbstractSockets = runtime.GOOS == "linux" + // SockOption sets up socket file's creating option type SockOption func(string) error -// NewUnixSocketWithOpts creates a unix socket with the specified options. -// By default, socket permissions are 0000 (i.e.: no access for anyone); pass -// WithChmod() and WithChown() to set the desired ownership and permissions. +// NewUnixSocketWithOpts creates a Unix socket with the specified options. +// +// On Unix platforms, socket permissions are 0000 by default, i.e. no access +// for anyone. Pass WithChmod() and WithChown() to set the desired permissions +// and ownership. +// +// On Windows, the socket uses Windows ACLs. Pass WithBasePermissions() to allow +// Administrators and LocalSystem full access, or WithAdditionalUsersAndGroups() +// to also grant generic read and write access to additional users or groups. // -// This function temporarily changes the system's "umask" to 0777 to work around -// a race condition between creating the socket and setting its permissions. While -// this should only be for a short duration, it may affect other processes that -// create files/directories during that period. +// Abstract Unix sockets (Go's Linux-specific "@" shorthand and the native +// leading-NUL representation) are supported only on Linux. On other platforms, +// attempts to use abstract socket addresses return an error. Because abstract +// sockets have no filesystem representation, filesystem-specific socket +// options are not supported. +// +// On platforms without abstract Unix socket support, attempts to use abstract +// socket addresses return an error wrapping [errors.ErrUnsupported]. func NewUnixSocketWithOpts(path string, opts ...SockOption) (net.Listener, error) { - if err := syscall.Unlink(path); err != nil && !os.IsNotExist(err) { - return nil, err + if isAbstractSocket(path) { + if !supportsAbstractSockets { + return nil, fmt.Errorf("abstract Unix socket %q is not supported on %s: %w", path, runtime.GOOS, errors.ErrUnsupported) + } + for _, opt := range opts { + if err := opt(path); err != nil { + return nil, err + } + } + return net.Listen("unix", path) } - - l, err := listenUnix(path) - if err != nil { + if err := syscall.Unlink(path); err != nil && !os.IsNotExist(err) { return nil, err } - for _, op := range opts { - if err := op(path); err != nil { - _ = l.Close() - return nil, err - } - } + return listenUnix(path, opts...) +} - return l, nil +// isAbstractSocket reports whether path is an abstract Unix socket address. +// +// Go recognizes two representations of abstract socket addresses: +// +// - On Linux, a path beginning with '@' is translated by the standard library +// to the kernel's native leading-NUL representation. +// See https://pkg.go.dev/net@go1.27rc2#UnixAddr. +// +// - A path beginning with a NUL byte uses the kernel's native representation +// directly. See https://github.com/golang/go/issues/78615. +// +// The interpretation of these addresses is platform-dependent; this helper only +// recognizes the syntax. +func isAbstractSocket(path string) bool { + return len(path) > 0 && (path[0] == '@' || path[0] == 0) } diff --git a/vendor/github.com/docker/go-connections/sockets/unix_socket_bsd.go b/vendor/github.com/docker/go-connections/sockets/unix_socket_bsd.go new file mode 100644 index 000000000000..22774d20e46e --- /dev/null +++ b/vendor/github.com/docker/go-connections/sockets/unix_socket_bsd.go @@ -0,0 +1,39 @@ +//go:build darwin || dragonfly || freebsd || netbsd || openbsd + +package sockets + +import ( + "runtime" + "syscall" +) + +// maxListenerBacklog is similar to the equivalent in stdlib; +// https://github.com/golang/go/blob/go1.26.3/src/net/sock_bsd.go#L14-L39 +func maxListenerBacklog() int { + var ( + n uint32 + err error + ) + switch runtime.GOOS { + case "darwin", "ios": + n, err = syscall.SysctlUint32("kern.ipc.somaxconn") + case "freebsd": + n, err = syscall.SysctlUint32("kern.ipc.soacceptqueue") + case "netbsd": + // NOTE: NetBSD has no somaxconn-like kernel state so far + case "openbsd": + n, err = syscall.SysctlUint32("kern.somaxconn") + default: + return syscall.SOMAXCONN + } + if n == 0 || err != nil { + return syscall.SOMAXCONN + } + // FreeBSD stores the backlog in a uint16, as does Linux. + // Assume the other BSDs do too. Truncate number to avoid wrapping. + // See issue 5030. + if n > 1<<16-1 { + n = 1<<16 - 1 + } + return int(n) +} diff --git a/vendor/github.com/docker/go-connections/sockets/unix_socket_linux.go b/vendor/github.com/docker/go-connections/sockets/unix_socket_linux.go new file mode 100644 index 000000000000..59860610c3a1 --- /dev/null +++ b/vendor/github.com/docker/go-connections/sockets/unix_socket_linux.go @@ -0,0 +1,25 @@ +package sockets + +import ( + "os" + "strconv" + "strings" + "syscall" +) + +// maxListenerBacklog returns the maximum length of the queue of pending +// connections for a listening socket. +// +// It is similar to in stdlib, but without the fallbacks for Kernel < 4.1.0; +// https://github.com/golang/go/blob/go1.26.3/src/net/sock_linux.go#L33-L53 +func maxListenerBacklog() int { + b, err := os.ReadFile("/proc/sys/net/core/somaxconn") + if err != nil { + return syscall.SOMAXCONN + } + n, err := strconv.Atoi(strings.TrimSpace(string(b))) + if err != nil || n <= 0 { + return syscall.SOMAXCONN + } + return n +} diff --git a/vendor/github.com/docker/go-connections/sockets/unix_socket_other.go b/vendor/github.com/docker/go-connections/sockets/unix_socket_other.go new file mode 100644 index 000000000000..2608e56e462e --- /dev/null +++ b/vendor/github.com/docker/go-connections/sockets/unix_socket_other.go @@ -0,0 +1,9 @@ +//go:build !linux && !darwin && !dragonfly && !freebsd && !netbsd && !openbsd && !windows + +package sockets + +import "syscall" + +func maxListenerBacklog() int { + return syscall.SOMAXCONN +} diff --git a/vendor/github.com/docker/go-connections/sockets/unix_socket_unix.go b/vendor/github.com/docker/go-connections/sockets/unix_socket_unix.go index a41a71654742..2bc1c1b44bf3 100644 --- a/vendor/github.com/docker/go-connections/sockets/unix_socket_unix.go +++ b/vendor/github.com/docker/go-connections/sockets/unix_socket_unix.go @@ -3,14 +3,35 @@ package sockets import ( + "errors" + "fmt" "net" "os" + "sync" "syscall" ) -// WithChown modifies the socket file's uid and gid +// defaultSocketPerms is the default permission mode applied to newly created +// Unix sockets. Sockets are created inaccessible by default; callers can +// override this by passing [WithChmod]. +// +// TODO(thaJeztah): Consider changing the default to 0o600, making the socket usable by its owner by default. +const defaultSocketPerms os.FileMode = 0o000 + +// WithChown modifies the socket file's uid and gid. +// +// Abstract Unix sockets have no filesystem representation, so this option +// returns an error wrapping [errors.ErrUnsupported] when used with an abstract +// socket. func WithChown(uid, gid int) SockOption { return func(path string) error { + if isAbstractSocket(path) { + return &os.PathError{ + Op: "chown", + Path: path, + Err: fmt.Errorf("abstract Unix sockets do not support filesystem permissions: %w", errors.ErrUnsupported), + } + } if err := os.Chown(path, uid, gid); err != nil { return err } @@ -19,8 +40,19 @@ func WithChown(uid, gid int) SockOption { } // WithChmod modifies socket file's access mode. +// +// Abstract Unix sockets have no filesystem representation, so this option +// returns an error wrapping [errors.ErrUnsupported] when used with an abstract +// socket. func WithChmod(mask os.FileMode) SockOption { return func(path string) error { + if isAbstractSocket(path) { + return &os.PathError{ + Op: "chmod", + Path: path, + Err: fmt.Errorf("abstract Unix sockets do not support filesystem permissions: %w", errors.ErrUnsupported), + } + } if err := os.Chmod(path, mask); err != nil { return err } @@ -28,27 +60,90 @@ func WithChmod(mask os.FileMode) SockOption { } } -// NewUnixSocket creates a unix socket with the specified path and group. +// NewUnixSocket creates a Unix socket with the specified path and group. +// +// On Unix platforms, the socket is owned by root:gid and has permissions 0660. +// +// Abstract Unix sockets are not supported by this helper. Use [NewUnixSocketWithOpts] +// without filesystem permission options instead. func NewUnixSocket(path string, gid int) (net.Listener, error) { return NewUnixSocketWithOpts(path, WithChown(0, gid), WithChmod(0o660)) } -func listenUnix(path string) (net.Listener, error) { - // net.Listen does not allow for permissions to be set. As a result, when - // specifying custom permissions ("WithChmod()"), there is a short time - // between creating the socket and applying the permissions, during which - // the socket permissions are Less restrictive than desired. +func listenUnix(path string, opts ...SockOption) (_ net.Listener, retErr error) { + // net.Listen does not allow permissions or ownership to be set between + // bind(2), which creates the socket path, and listen(2), which makes it + // possible for clients to connect. // - // To work around this limitation of net.Listen(), we temporarily set the - // umask to 0777, which forces the socket to be created with 000 permissions - // (i.e.: no access for anyone). After that, WithChmod() must be used to set - // the desired permissions. + // Creating the socket manually lets us apply options after bind(2), but + // before listen(2). This avoids temporarily relaxing the process umask while + // still preventing a socket from becoming connectable before the requested + // permissions are applied. // - // We don't use "defer" here, to reset the umask to its original value as soon - // as possible. Ideally we'd be able to detect if WithChmod() was passed as - // an option, and skip changing umask if default permissions are used. - origUmask := syscall.Umask(0o777) - l, err := net.Listen("unix", path) - syscall.Umask(origUmask) - return l, err + // See https://github.com/golang/go/issues/11822 + + // Similar to sysSocket in stdlib, but without the fast path for Linux. + // https://github.com/golang/go/blob/go1.26.3/src/net/sys_cloexec.go#L18-L36 + syscall.ForkLock.RLock() + fd, err := syscall.Socket(syscall.AF_UNIX, syscall.SOCK_STREAM, 0) + if err == nil { + syscall.CloseOnExec(fd) // No syscall.SOCK_CLOEXEC on macOS. + } + syscall.ForkLock.RUnlock() + if err != nil { + return nil, os.NewSyscallError("socket", err) + } + + defer func() { + if fd >= 0 { + _ = syscall.Close(fd) + } + }() + + if err := syscall.Bind(fd, &syscall.SockaddrUnix{Name: path}); err != nil { + return nil, os.NewSyscallError("bind", err) + } + + defer func() { + if retErr != nil { + _ = syscall.Unlink(path) + } + }() + + // Secure by default: the socket is not accessible at all + // unless permission options are set through WithChmod. + if err := os.Chmod(path, defaultSocketPerms); err != nil { + return nil, err + } + + for _, op := range opts { + if err := op(path); err != nil { + return nil, err + } + } + + if err := syscall.Listen(fd, listenerBacklog()); err != nil { + return nil, os.NewSyscallError("listen", err) + } + + f := os.NewFile(uintptr(fd), "unix:"+path) + fd = -1 // f now owns the original fd; prevent the defer from closing it. + + // FileListener duplicates f, sets the duplicate close-on-exec and nonblocking, + // and returns a net.Listener backed by that duplicate. The temporary *os.File + // is no longer needed after this point. + l, err := net.FileListener(f) + _ = f.Close() + if err != nil { + return nil, err + } + + if ul, ok := l.(*net.UnixListener); ok { + ul.SetUnlinkOnClose(true) + } + + return l, nil } + +// listenerBacklog is a caching wrapper around maxListenerBacklog. +var listenerBacklog = sync.OnceValue(maxListenerBacklog) diff --git a/vendor/github.com/docker/go-connections/sockets/unix_socket_windows.go b/vendor/github.com/docker/go-connections/sockets/unix_socket_windows.go index 01aee5f11a5b..a9a9e80d5012 100644 --- a/vendor/github.com/docker/go-connections/sockets/unix_socket_windows.go +++ b/vendor/github.com/docker/go-connections/sockets/unix_socket_windows.go @@ -48,7 +48,7 @@ func WithAdditionalUsersAndGroups(additionalUsersAndGroups []string) SockOption } sd, err := getSecurityDescriptor(additionalUsersAndGroups...) if err != nil { - return fmt.Errorf("looking up SID: %w", err) + return err } return withSDDL(sd)(path) } @@ -85,12 +85,15 @@ func withSDDL(sddl string) SockOption { } } -// NewUnixSocket creates a new unix socket. +// NewUnixSocket creates a new Unix socket. // // It sets [BasePermissions] on the socket path and grants the given additional // users and groups to generic read (GR) and write (GW) access. It returns // an error when failing to resolve any of the additional users and groups, // or when failing to apply the ACL. +// +// Abstract Unix sockets are not supported by this helper. Attempts to use +// abstract socket addresses return an error wrapping [errors.ErrUnsupported]. func NewUnixSocket(path string, additionalUsersAndGroups []string) (net.Listener, error) { var opts []SockOption if len(additionalUsersAndGroups) > 0 { @@ -103,27 +106,38 @@ func NewUnixSocket(path string, additionalUsersAndGroups []string) (net.Listener // getSecurityDescriptor returns the DACL for the Unix socket. // -// By default, it grants [BasePermissions], but allows for additional -// users and groups to get generic read (GR) and write (GW) access. It -// returns an error when failing to resolve any of the additional users -// and groups. +// By default, it grants [BasePermissions]. Additional users and groups +// are granted generic read (GR) and write (GW) access. It returns an +// error if any name cannot be resolved to a SID. func getSecurityDescriptor(additionalUsersAndGroups ...string) (string, error) { sddl := BasePermissions // Grant generic read (GR) and write (GW) access to whatever // additional users or groups were specified. // - // TODO(thaJeztah): should we fail on, or remove duplicates? + // We keep duplicates; two identical allow ACEs are redundant, + // but they do not create conflicting permissions, so should not error. + // https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-dtyp/20233ed8-a6c6-4097-aafa-dd545ed24428 for _, g := range additionalUsersAndGroups { sid, err := winio.LookupSidByName(strings.TrimSpace(g)) if err != nil { return "", fmt.Errorf("looking up SID: %w", err) } - sddl += fmt.Sprintf("(A;;GRGW;;;%s)", sid) + sddl += "(A;;GRGW;;;" + sid + ")" } return sddl, nil } -func listenUnix(path string) (net.Listener, error) { - return net.Listen("unix", path) +func listenUnix(path string, opts ...SockOption) (net.Listener, error) { + l, err := net.Listen("unix", path) + if err != nil { + return nil, err + } + for _, op := range opts { + if err := op(path); err != nil { + _ = l.Close() + return nil, err + } + } + return l, nil } diff --git a/vendor/github.com/fvbommel/sortorder/natsort.go b/vendor/github.com/fvbommel/sortorder/natsort.go index e4f15110b8eb..5eba2bc6f5df 100644 --- a/vendor/github.com/fvbommel/sortorder/natsort.go +++ b/vendor/github.com/fvbommel/sortorder/natsort.go @@ -1,5 +1,7 @@ package sortorder +import "cmp" + // Natural implements sort.Interface to sort strings in natural order. This // means that e.g. "abc2" < "abc12". // @@ -25,18 +27,36 @@ func isDigit(b byte) bool { return '0' <= b && b <= '9' } // // Limitation: only ASCII digits (0-9) are considered. func NaturalLess(str1, str2 string) bool { + return NaturalCompare(str1, str2) < 0 +} + +// NaturalCompare compares str1 and str2 using the same natural ordering as +// [NaturalLess]. It returns a negative value if str1 sorts before str2, a +// positive value if str1 sorts after str2, and zero if str1 and str2 are equal. +// +// NaturalCompare is suitable for APIs that accept a three-way comparison +// function, such as [slices.SortFunc] and [slices.SortStableFunc]. +func NaturalCompare(str1, str2 string) int { idx1, idx2 := 0, 0 for idx1 < len(str1) && idx2 < len(str2) { c1, c2 := str1[idx1], str2[idx2] dig1, dig2 := isDigit(c1), isDigit(c2) switch { - case dig1 != dig2: // Digits before other characters. - return dig1 // True if LHS is a digit, false if the RHS is one. + case dig1 != dig2: + // The first difference is that one is a digit and the other is not. + // That means that one (possibly empty) non-digit string has ended, and the other has not. + // The one that has ended is ordered before the one that continues, + // for example: "ab1" < "abc1" after skipping the matching "ab" prefix. + // This means the side with the digit is ordered before the other one. + if dig1 { + return -1 + } + return 1 case !dig1: // && !dig2, because dig1 == dig2 // UTF-8 compares bytewise-lexicographically, no need to decode // codepoints. if c1 != c2 { - return c1 < c2 + return cmp.Compare(c1, c2) } idx1++ idx2++ @@ -55,22 +75,22 @@ func NaturalLess(str1, str2 string) bool { // If lengths of numbers with non-zero prefix differ, the shorter // one is less. if len1, len2 := idx1-nonZero1, idx2-nonZero2; len1 != len2 { - return len1 < len2 + return cmp.Compare(len1, len2) } // If they're equally long, string comparison is correct. if nr1, nr2 := str1[nonZero1:idx1], str2[nonZero2:idx2]; nr1 != nr2 { - return nr1 < nr2 + return cmp.Compare(nr1, nr2) } // Otherwise, the one with less zeros is less. // Because everything up to the number is equal, comparing the index // after the zeros is sufficient. if nonZero1 != nonZero2 { - return nonZero1 < nonZero2 + return cmp.Compare(nonZero1, nonZero2) } } // They're identical so far, so continue comparing. } // So far they are identical. At least one is ended. If the other continues, // it sorts last. - return len(str1) < len(str2) + return cmp.Compare(len(str1), len(str2)) } diff --git a/vendor/github.com/gofrs/flock/.golangci.yml b/vendor/github.com/gofrs/flock/.golangci.yml index bc837b266a9b..b35be7de8126 100644 --- a/vendor/github.com/gofrs/flock/.golangci.yml +++ b/vendor/github.com/gofrs/flock/.golangci.yml @@ -6,7 +6,9 @@ formatters: - goimports settings: gofumpt: - extra-rules: true + extra: + clothe-returns: true + group-params: true linters: enable: diff --git a/vendor/github.com/gofrs/flock/flock.go b/vendor/github.com/gofrs/flock/flock.go index 4cb0746a7161..156c4bf2b04e 100644 --- a/vendor/github.com/gofrs/flock/flock.go +++ b/vendor/github.com/gofrs/flock/flock.go @@ -1,5 +1,5 @@ // Copyright 2015 Tim Heckman. All rights reserved. -// Copyright 2018-2025 The Gofrs. All rights reserved. +// Copyright 2018-2026 The Gofrs. All rights reserved. // Use of this source code is governed by the BSD 3-Clause // license that can be found in the LICENSE file. @@ -100,7 +100,7 @@ func (f *Flock) Close() error { return f.Unlock() } -// Path returns the path as provided in NewFlock(). +// Path returns the path as provided in New(). func (f *Flock) Path() string { return f.path } diff --git a/vendor/github.com/gofrs/flock/flock_others.go b/vendor/github.com/gofrs/flock/flock_others.go index 92d0f7e95a90..822ace0da023 100644 --- a/vendor/github.com/gofrs/flock/flock_others.go +++ b/vendor/github.com/gofrs/flock/flock_others.go @@ -1,5 +1,5 @@ // Copyright 2015 Tim Heckman. All rights reserved. -// Copyright 2018-2025 The Gofrs. All rights reserved. +// Copyright 2018-2026 The Gofrs. All rights reserved. // Use of this source code is governed by the BSD 3-Clause // license that can be found in the LICENSE file. diff --git a/vendor/github.com/gofrs/flock/flock_unix.go b/vendor/github.com/gofrs/flock/flock_unix.go index 77de7a8837ad..c486c5e6bef1 100644 --- a/vendor/github.com/gofrs/flock/flock_unix.go +++ b/vendor/github.com/gofrs/flock/flock_unix.go @@ -1,5 +1,5 @@ // Copyright 2015 Tim Heckman. All rights reserved. -// Copyright 2018-2025 The Gofrs. All rights reserved. +// Copyright 2018-2026 The Gofrs. All rights reserved. // Use of this source code is governed by the BSD 3-Clause // license that can be found in the LICENSE file. diff --git a/vendor/github.com/gofrs/flock/flock_unix_fcntl.go b/vendor/github.com/gofrs/flock/flock_unix_fcntl.go index 05c2f88c65b5..76a29fc082d4 100644 --- a/vendor/github.com/gofrs/flock/flock_unix_fcntl.go +++ b/vendor/github.com/gofrs/flock/flock_unix_fcntl.go @@ -1,5 +1,5 @@ // Copyright 2015 Tim Heckman. All rights reserved. -// Copyright 2018-2025 The Gofrs. All rights reserved. +// Copyright 2018-2026 The Gofrs. All rights reserved. // Use of this source code is governed by the BSD 3-Clause // license that can be found in the LICENSE file. diff --git a/vendor/github.com/gofrs/flock/flock_windows.go b/vendor/github.com/gofrs/flock/flock_windows.go index aa144f156e9f..d9f9f883216d 100644 --- a/vendor/github.com/gofrs/flock/flock_windows.go +++ b/vendor/github.com/gofrs/flock/flock_windows.go @@ -1,5 +1,5 @@ // Copyright 2015 Tim Heckman. All rights reserved. -// Copyright 2018-2025 The Gofrs. All rights reserved. +// Copyright 2018-2026 The Gofrs. All rights reserved. // Use of this source code is governed by the BSD 3-Clause // license that can be found in the LICENSE file. diff --git a/vendor/github.com/gofrs/flock/zizmor.yml b/vendor/github.com/gofrs/flock/zizmor.yml new file mode 100644 index 000000000000..39d1b180c53c --- /dev/null +++ b/vendor/github.com/gofrs/flock/zizmor.yml @@ -0,0 +1,3 @@ +rules: + secrets-outside-env: + disable: true diff --git a/vendor/github.com/mattn/go-runewidth/SECURITY.md b/vendor/github.com/mattn/go-runewidth/SECURITY.md new file mode 100644 index 000000000000..a6898ee7015f --- /dev/null +++ b/vendor/github.com/mattn/go-runewidth/SECURITY.md @@ -0,0 +1,25 @@ +# Security Policy + +## Supported Versions + +The following versions of go-runewidth are currently supported with +security updates. + +| Version | Supported | +| -------- | ------------------ | +| 0.0.23 | :white_check_mark: | +| < 0.0.23 | :x: | + +## Reporting a Vulnerability + +If you discover a security vulnerability in go-runewidth, please report it +privately via GitHub's "Report a vulnerability" feature on the Security tab +of the repository (https://github.com/mattn/go-runewidth/security), or by +emailing the maintainer at mattn.jp@gmail.com. + +Please include a description of the issue, reproduction steps, and the +affected version. You can expect an initial response within one week. If +the vulnerability is accepted, a fix will be prepared and a new release +will be published; you will be credited in the release notes unless you +request otherwise. If the report is declined, you will receive an +explanation of the reasoning. diff --git a/vendor/github.com/mattn/go-runewidth/runewidth.go b/vendor/github.com/mattn/go-runewidth/runewidth.go index f6c0058222b2..af03e996e9a1 100644 --- a/vendor/github.com/mattn/go-runewidth/runewidth.go +++ b/vendor/github.com/mattn/go-runewidth/runewidth.go @@ -2,7 +2,10 @@ package runewidth import ( "os" + "sort" "strings" + "sync" + "sync/atomic" "unicode/utf8" "github.com/clipperhouse/uax29/v2/graphemes" @@ -17,6 +20,14 @@ var ( // StrictEmojiNeutral should be set false if handle broken fonts StrictEmojiNeutral bool = true + // ZeroWidthJoiner is flag to set to use UTR#51 ZWJ. + // + // Deprecated: ZWJ sequences are always handled through Unicode + // grapheme cluster segmentation now, so this flag has no effect. + // It is kept only for compatibility with code written against + // v0.0.9 and earlier. + ZeroWidthJoiner bool + // DefaultCondition is a condition in current locale DefaultCondition = &Condition{ EastAsianWidth: false, @@ -25,14 +36,73 @@ var ( ) var ( - zerowidth table // combining + nonprint merged for faster zero-width lookup - widewidth table // ambiguous + doublewidth merged for EA path + zerowidth table // combining + nonprint merged for faster zero-width lookup + widewidth table // ambiguous + doublewidth merged for EA path + eastAsianWidth widthTable + tablesOnce sync.Once + + // strictWidthLUT is mostly built lazily on the first width lookup so + // that importing the package costs neither the build time nor the 2 MB + // of resident memory; see issue #104. Only the entries below + // strictWidthLUTLimit are valid: init fills the first 0x300 entries of + // both planes, and the lazy build fills the rest — never rewriting the + // low region, so readers of it cannot race with the build. The limit + // is loaded with acquire semantics, which makes the non-atomic reads + // of the high region safe once it reports 0x110000. Keeping the whole + // check down to one compare-and-branch matters: RuneWidth is only a + // dozen instructions long. + strictWidthLUT [2][0x110000]byte + strictWidthLUTLimit atomic.Int32 + strictWidthLUTOnce sync.Once ) func init() { + initStrictWidthLUTLow() + strictWidthLUTLimit.Store(0x300) + handleEnv() +} + +// initStrictWidthLUTLow paints the first 0x300 entries of strictWidthLUT +// from the static interval tables. The result must stay identical to +// runeWidthNoLUT for runes below 0x300, which TestStrictWidthLUT verifies. +func initStrictWidthLUTLow() { + for i := 0; i < 0x300; i++ { + r := rune(i) + w := byte(1) + if r < 0x20 || (r >= 0x7F && r <= 0x9F) || r == 0xAD { // nonprint + w = 0 + } + strictWidthLUT[0][i] = w + } + + ea := strictWidthLUT[1][:0x300] + fillBytes(ea, 1) + paint := func(t table, w byte) { + for _, iv := range t { + if iv.first >= 0x300 { + break + } + last := iv.last + if last > 0x2FF { + last = 0x2FF + } + fillBytes(ea[iv.first:last+1], w) + } + } + paint(ambiguous, 2) + paint(doublewidth, 2) + // zero-width wins over wide on overlap, so paint it last. + paint(combining, 0) + paint(nonprint, 0) +} + +// initTables builds the merged lookup tables. It runs lazily through +// tablesOnce so that merely importing the package stays cheap; see issue +// #104. +func initTables() { zerowidth = mergeIntervals(combining, nonprint) widewidth = mergeIntervals(ambiguous, doublewidth) - handleEnv() + eastAsianWidth = makeWidthTable(zerowidth, widewidth) } func mergeIntervals(t1, t2 table) table { @@ -77,7 +147,6 @@ func handleEnv() { if DefaultCondition.EastAsianWidth != EastAsianWidth { DefaultCondition.EastAsianWidth = EastAsianWidth if len(DefaultCondition.combinedLut) > 0 { - DefaultCondition.combinedLut = DefaultCondition.combinedLut[:0] CreateLUT() } } @@ -90,6 +159,14 @@ type interval struct { type table []interval +type widthInterval struct { + first rune + last rune + width byte +} + +type widthTable []widthInterval + func inTable(r rune, t table) bool { if r < t[0].first { return false @@ -116,6 +193,154 @@ func inTable(r rune, t table) bool { return false } +func makeWidthTable(zero, two table) widthTable { + wt := make(widthTable, 0, len(zero)+len(two)) + zi := 0 + for _, iv := range two { + start := iv.first + for zi < len(zero) && zero[zi].last < start { + zi++ + } + for i := zi; i < len(zero) && zero[i].first <= iv.last; i++ { + if start < zero[i].first { + wt = append(wt, widthInterval{start, zero[i].first - 1, 2}) + } + if start <= zero[i].last { + start = zero[i].last + 1 + } + if start > iv.last { + break + } + } + if start <= iv.last { + wt = append(wt, widthInterval{start, iv.last, 2}) + } + } + for _, iv := range zero { + wt = append(wt, widthInterval{iv.first, iv.last, 0}) + } + sort.Slice(wt, func(i, j int) bool { + return wt[i].first < wt[j].first + }) + return wt +} + +func inWidthTable(r rune, t widthTable) (int, bool) { + if r < t[0].first { + return 0, false + } + if r > t[len(t)-1].last { + return 0, false + } + + bot := 0 + top := len(t) - 1 + for top >= bot { + mid := (bot + top) >> 1 + + switch { + case t[mid].last < r: + bot = mid + 1 + case t[mid].first > r: + top = mid - 1 + default: + return int(t[mid].width), true + } + } + + return 0, false +} + +func runeWidthNoLUT(r rune, eastAsian, strictEmojiNeutral bool) int { + tablesOnce.Do(initTables) + if !eastAsian { + if r < 0x20 { + return 0 + } + if (r >= 0x7F && r <= 0x9F) || r == 0xAD { // nonprint + return 0 + } + if r < 0x300 { + return 1 + } + switch { + case inTable(r, zerowidth): + return 0 + case inTable(r, doublewidth): + return 2 + default: + return 1 + } + } + + if r < 0x300 { + return int(strictWidthLUT[1][r]) + } + if w, ok := inWidthTable(r, eastAsianWidth); ok { + return w + } + if !strictEmojiNeutral && inTable(r, emoji) { + return 2 + } + return 1 +} + +// fillBytes sets every byte of b to v. It doubles the copied region on each +// iteration so large slices are filled at memcpy speed instead of one byte +// per loop iteration. +func fillBytes(b []byte, v byte) { + if len(b) == 0 { + return + } + b[0] = v + for i := 1; i < len(b); i *= 2 { + copy(b[i:], b[:i]) + } +} + +// buildStrictWidthLUT builds the strict-width lookup table above 0x300 +// exactly once. It paints whole intervals instead of computing every rune +// through the binary searches in runeWidthNoLUT. It must not write below +// 0x300: that region was filled by init and may be read concurrently. The +// result must stay identical to runeWidthNoLUT(r, eastAsian, true), which +// TestStrictWidthLUT verifies. +func buildStrictWidthLUT() { + strictWidthLUTOnce.Do(func() { + tablesOnce.Do(initTables) + + // paintHigh fills lut with w over each interval, clipped to 0x300+. + paintHigh := func(lut []byte, first, last rune, w byte) { + if first < 0x300 { + if last < 0x300 { + return + } + first = 0x300 + } + fillBytes(lut[first:last+1], w) + } + + // EastAsianWidth=false, StrictEmojiNeutral=true + lut := strictWidthLUT[0][:] + fillBytes(lut[0x300:], 1) + for _, iv := range doublewidth { + paintHigh(lut, iv.first, iv.last, 2) + } + // zerowidth is checked before doublewidth, so it wins on overlap. + for _, iv := range zerowidth { + paintHigh(lut, iv.first, iv.last, 0) + } + + // EastAsianWidth=true, StrictEmojiNeutral=true + lut = strictWidthLUT[1][:] + fillBytes(lut[0x300:], 1) + for _, iv := range eastAsianWidth { + paintHigh(lut, iv.first, iv.last, iv.width) + } + + strictWidthLUTLimit.Store(0x110000) + }) +} + var private = table{ {0x00E000, 0x00F8FF}, {0x0F0000, 0x0FFFFD}, {0x100000, 0x10FFFD}, } @@ -129,9 +354,20 @@ var nonprint = table{ // Condition have flag EastAsianWidth whether the current locale is CJK or not. type Condition struct { - combinedLut []byte + combinedLut []byte + // The flags combinedLut was built from, so that CreateLUT can tell a + // table that is still current from one that has to be rebuilt. + lutEastAsianWidth bool + lutStrictEmojiNeutral bool + EastAsianWidth bool StrictEmojiNeutral bool + + // Deprecated: ZWJ sequences are always handled through Unicode + // grapheme cluster segmentation now, so this flag has no effect. + // It is kept only for compatibility with code written against + // v0.0.9 and earlier. + ZeroWidthJoiner bool } // NewCondition return new instance of Condition which is current locale. @@ -139,48 +375,47 @@ func NewCondition() *Condition { return &Condition{ EastAsianWidth: EastAsianWidth, StrictEmojiNeutral: StrictEmojiNeutral, + ZeroWidthJoiner: ZeroWidthJoiner, } } // RuneWidth returns the number of cells in r. // See http://www.unicode.org/reports/tr11/ func (c *Condition) RuneWidth(r rune) int { + // This one compare doubles as the range check and the lazy-LUT check: + // out-of-range runes and runes above the built portion of + // strictWidthLUT both take the slow path. Once the LUT is fully built + // the limit is 0x110000 and only invalid runes go slow. + if uint32(r) >= uint32(strictWidthLUTLimit.Load()) { + return c.runeWidthSlow(r) + } + if len(c.combinedLut) > 0 { + return int(c.combinedLut[r>>1]>>(uint(r&1)*4)) & 3 + } + if c.StrictEmojiNeutral { + if c.EastAsianWidth { + return int(strictWidthLUT[1][r]) + } + return int(strictWidthLUT[0][r]) + } + return runeWidthNoLUT(r, c.EastAsianWidth, c.StrictEmojiNeutral) +} + +func (c *Condition) runeWidthSlow(r rune) int { if r < 0 || r > 0x10FFFF { return 0 } + buildStrictWidthLUT() if len(c.combinedLut) > 0 { return int(c.combinedLut[r>>1]>>(uint(r&1)*4)) & 3 } - // optimized version, verified by TestRuneWidthChecksums() - if !c.EastAsianWidth { - switch { - case r < 0x20: - return 0 - case (r >= 0x7F && r <= 0x9F) || r == 0xAD: // nonprint - return 0 - case r < 0x300: - return 1 - case inTable(r, zerowidth): - return 0 - case inTable(r, doublewidth): - return 2 - default: - return 1 - } - } else { - switch { - case inTable(r, zerowidth): - return 0 - case inTable(r, narrow): - return 1 - case inTable(r, widewidth): - return 2 - case !c.StrictEmojiNeutral && inTable(r, emoji): - return 2 - default: - return 1 + if c.StrictEmojiNeutral { + if c.EastAsianWidth { + return int(strictWidthLUT[1][r]) } + return int(strictWidthLUT[0][r]) } + return runeWidthNoLUT(r, c.EastAsianWidth, c.StrictEmojiNeutral) } // CreateLUT will create an in-memory lookup table of 557056 bytes for faster operation. @@ -190,6 +425,11 @@ func (c *Condition) CreateLUT() { const max = 0x110000 lut := c.combinedLut if len(c.combinedLut) != 0 { + if c.lutEastAsianWidth == c.EastAsianWidth && c.lutStrictEmojiNeutral == c.StrictEmojiNeutral { + // The table still matches the flags, so rebuilding it + // would produce the same bytes. + return + } // Remove so we don't use it. c.combinedLut = nil } else { @@ -202,10 +442,34 @@ func (c *Condition) CreateLUT() { lut[i] = uint8(x0) | uint8(x1)<<4 } c.combinedLut = lut + c.lutEastAsianWidth = c.EastAsianWidth + c.lutStrictEmojiNeutral = c.StrictEmojiNeutral +} + +// graphemeWidth returns the width of a single grapheme cluster: the sum of +// the widths of its runes, capped at 2 cells. The cap keeps multi-rune +// sequences that render as a single glyph (ZWJ emoji, flags, Hangul jamo) +// from being counted wider than the two cells terminals give them. +func (c *Condition) graphemeWidth(cluster string) int { + width := 0 + for _, r := range cluster { + width += c.RuneWidth(r) + } + if width > 2 { + width = 2 + } + return width } // StringWidth return width as you can see func (c *Condition) StringWidth(s string) (width int) { + if len(s) == 1 { + b := s[0] + if b < 0x20 || b == 0x7F { + return 0 + } + return 1 + } if len(s) > 0 && len(s) <= utf8.UTFMax { r, size := utf8.DecodeRuneInString(s) if size == len(s) { @@ -213,36 +477,24 @@ func (c *Condition) StringWidth(s string) (width int) { } } // ASCII fast path: no grapheme clustering needed for pure ASCII - if isAllASCII(s) { - for i := 0; i < len(s); i++ { - b := s[i] - if b >= 0x20 && b != 0x7F { - width++ - } + for i := 0; i < len(s); i++ { + b := s[i] + if b >= 0x80 { + goto graphemes } - return - } - g := graphemes.FromString(s) - for g.Next() { - var chWidth int - for _, r := range g.Value() { - chWidth = c.RuneWidth(r) - if chWidth > 0 { - break // Our best guess at this point is to use the width of the first non-zero-width rune. - } + if b >= 0x20 && b != 0x7F { + width++ } - width += chWidth } return -} -func isAllASCII(s string) bool { - for i := 0; i < len(s); i++ { - if s[i] >= 0x80 { - return false - } +graphemes: + width = 0 + g := graphemes.FromString(s) + for g.Next() { + width += c.graphemeWidth(g.Value()) } - return true + return } // Truncate return string truncated with w cells @@ -255,13 +507,7 @@ func (c *Condition) Truncate(s string, w int, tail string) string { pos := len(s) g := graphemes.FromString(s) for g.Next() { - var chWidth int - for _, r := range g.Value() { - chWidth = c.RuneWidth(r) - if chWidth > 0 { - break // See StringWidth() for details. - } - } + chWidth := c.graphemeWidth(g.Value()) if width+chWidth > w { pos = g.Start() break @@ -282,13 +528,7 @@ func (c *Condition) TruncateLeft(s string, w int, prefix string) string { g := graphemes.FromString(s) for g.Next() { - var chWidth int - for _, r := range g.Value() { - chWidth = c.RuneWidth(r) - if chWidth > 0 { - break // See StringWidth() for details. - } - } + chWidth := c.graphemeWidth(g.Value()) if width+chWidth > w { if width < w { @@ -307,11 +547,39 @@ func (c *Condition) TruncateLeft(s string, w int, prefix string) string { return prefix + s[pos:] } +// TruncatePrefix cuts the beginning of `s` so the result fits in w cells, with prefix prepended +func (c *Condition) TruncatePrefix(s string, w int, prefix string) string { + if c.StringWidth(prefix) >= w { + return prefix + } + + sw := c.StringWidth(s) + if sw <= w { + return s + } + w -= c.StringWidth(prefix) + var width int + var pos int + g := graphemes.FromString(s) + for g.Next() { + chWidth := c.graphemeWidth(g.Value()) + if sw-(width+chWidth) <= w { + pos = g.End() + break + } + width += chWidth + } + + return prefix + s[pos:] +} + // Wrap return string wrapped with w cells func (c *Condition) Wrap(s string, w int) string { width := 0 var out strings.Builder - out.Grow(len(s) + len(s)/w + 1) + // max keeps the capacity hint from dividing by zero when w is 0; a + // non-positive width breaks before every rune, as it always has. + out.Grow(len(s) + len(s)/max(w, 1) + 1) for _, r := range s { cw := c.RuneWidth(r) if r == '\n' { @@ -336,11 +604,7 @@ func (c *Condition) FillLeft(s string, w int) string { width := c.StringWidth(s) count := w - width if count > 0 { - b := make([]byte, count) - for i := range b { - b[i] = ' ' - } - return string(b) + s + return strings.Repeat(" ", count) + s } return s } @@ -350,11 +614,7 @@ func (c *Condition) FillRight(s string, w int) string { width := c.StringWidth(s) count := w - width if count > 0 { - b := make([]byte, count) - for i := range b { - b[i] = ' ' - } - return s + string(b) + return s + strings.Repeat(" ", count) } return s } @@ -395,6 +655,11 @@ func TruncateLeft(s string, w int, prefix string) string { return DefaultCondition.TruncateLeft(s, w, prefix) } +// TruncatePrefix cuts the beginning of `s` so the result fits in w cells, with prefix prepended +func TruncatePrefix(s string, w int, prefix string) string { + return DefaultCondition.TruncatePrefix(s, w, prefix) +} + // Wrap return string wrapped with w cells func Wrap(s string, w int) string { return DefaultCondition.Wrap(s, w) @@ -412,9 +677,8 @@ func FillRight(s string, w int) string { // CreateLUT will create an in-memory lookup table of 557055 bytes for faster operation. // This should not be called concurrently with other operations. +// If flags in DefaultCondition are changed, CreateLUT should be called again; +// a call that finds the table already current is a no-op. func CreateLUT() { - if len(DefaultCondition.combinedLut) > 0 { - return - } DefaultCondition.CreateLUT() } diff --git a/vendor/github.com/mattn/go-runewidth/runewidth_posix.go b/vendor/github.com/mattn/go-runewidth/runewidth_posix.go index 5a31d738ecce..16673af3a1cf 100644 --- a/vendor/github.com/mattn/go-runewidth/runewidth_posix.go +++ b/vendor/github.com/mattn/go-runewidth/runewidth_posix.go @@ -5,35 +5,50 @@ package runewidth import ( "os" - "regexp" "strings" ) -var reLoc = regexp.MustCompile(`^[a-z][a-z][a-z]?(?:_[A-Z][A-Z])?\.(.+)`) +func mblen(charset string) int { + switch charset { + case "utf-8", "utf8": + return 6 + case "jis": + return 8 + case "eucjp": + return 3 + case "euckr", "euccn", "sjis", "cp932", "cp51932", "cp936", "cp949", "cp950", "big5", "gbk", "gb2312": + return 2 + } + return 1 +} -var mblenTable = map[string]int{ - "utf-8": 6, - "utf8": 6, - "jis": 8, - "eucjp": 3, - "euckr": 2, - "euccn": 2, - "sjis": 2, - "cp932": 2, - "cp51932": 2, - "cp936": 2, - "cp949": 2, - "cp950": 2, - "big5": 2, - "gbk": 2, - "gb2312": 2, +// localeCharset extracts the charset part of a locale name of the form +// "ll.CHARSET" or "ll_CC.CHARSET" (two- or three-letter language code, +// optional uppercase country code). It returns "" if locale does not have +// that shape. +func localeCharset(locale string) string { + n := 0 + for n < len(locale) && locale[n] >= 'a' && locale[n] <= 'z' { + n++ + } + if n < 2 || n > 3 { + return "" + } + rest := locale[n:] + if len(rest) >= 3 && rest[0] == '_' && + rest[1] >= 'A' && rest[1] <= 'Z' && rest[2] >= 'A' && rest[2] <= 'Z' { + rest = rest[3:] + } + if len(rest) >= 2 && rest[0] == '.' { + return rest[1:] + } + return "" } func isEastAsian(locale string) bool { charset := strings.ToLower(locale) - r := reLoc.FindStringSubmatch(locale) - if len(r) == 2 { - charset = strings.ToLower(r[1]) + if cs := localeCharset(locale); cs != "" { + charset = strings.ToLower(cs) } if strings.HasSuffix(charset, "@cjk_narrow") { @@ -46,10 +61,7 @@ func isEastAsian(locale string) bool { break } } - max := 1 - if m, ok := mblenTable[charset]; ok { - max = m - } + max := mblen(charset) if max > 1 && (charset[0] != 'u' || strings.HasPrefix(locale, "ja") || strings.HasPrefix(locale, "ko") || diff --git a/vendor/github.com/mattn/go-runewidth/runewidth_table.go b/vendor/github.com/mattn/go-runewidth/runewidth_table.go index cdd003e646c2..62488d97dab1 100644 --- a/vendor/github.com/mattn/go-runewidth/runewidth_table.go +++ b/vendor/github.com/mattn/go-runewidth/runewidth_table.go @@ -3,23 +3,127 @@ package runewidth var combining = table{ - {0x0300, 0x036F}, {0x0483, 0x0489}, {0x07EB, 0x07F3}, - {0x0C00, 0x0C00}, {0x0C04, 0x0C04}, {0x0CF3, 0x0CF3}, - {0x0D00, 0x0D01}, {0x135D, 0x135F}, {0x180B, 0x180D}, - {0x180F, 0x180F}, {0x1A7F, 0x1A7F}, {0x1AB0, 0x1ADD}, - {0x1AE0, 0x1AEB}, {0x1B6B, 0x1B73}, {0x1DC0, 0x1DFF}, - {0x20D0, 0x20F0}, {0x2CEF, 0x2CF1}, {0x2DE0, 0x2DFF}, - {0x3099, 0x309A}, {0xA66F, 0xA672}, {0xA674, 0xA67D}, - {0xA69E, 0xA69F}, {0xA6F0, 0xA6F1}, {0xA8E0, 0xA8F1}, - {0xFE00, 0xFE0F}, {0xFE20, 0xFE2F}, {0x101FD, 0x101FD}, - {0x10376, 0x1037A}, {0x10EAB, 0x10EAC}, {0x10F46, 0x10F50}, - {0x10F82, 0x10F85}, {0x11300, 0x11301}, {0x1133B, 0x1133C}, - {0x11366, 0x1136C}, {0x11370, 0x11374}, {0x16AF0, 0x16AF4}, - {0x1CF00, 0x1CF2D}, {0x1CF30, 0x1CF46}, {0x1D165, 0x1D169}, - {0x1D16D, 0x1D172}, {0x1D17B, 0x1D182}, {0x1D185, 0x1D18B}, - {0x1D1AA, 0x1D1AD}, {0x1D242, 0x1D244}, {0x1E000, 0x1E006}, - {0x1E008, 0x1E018}, {0x1E01B, 0x1E021}, {0x1E023, 0x1E024}, - {0x1E026, 0x1E02A}, {0x1E08F, 0x1E08F}, {0x1E8D0, 0x1E8D6}, + {0x0300, 0x036F}, {0x0483, 0x0489}, {0x0591, 0x05BD}, + {0x05BF, 0x05BF}, {0x05C1, 0x05C2}, {0x05C4, 0x05C5}, + {0x05C7, 0x05C7}, {0x0610, 0x061A}, {0x064B, 0x065F}, + {0x0670, 0x0670}, {0x06D6, 0x06DC}, {0x06DF, 0x06E4}, + {0x06E7, 0x06E8}, {0x06EA, 0x06ED}, {0x0711, 0x0711}, + {0x0730, 0x074A}, {0x07A6, 0x07B0}, {0x07EB, 0x07F3}, + {0x07FD, 0x07FD}, {0x0816, 0x0819}, {0x081B, 0x0823}, + {0x0825, 0x0827}, {0x0829, 0x082D}, {0x0859, 0x085B}, + {0x0897, 0x089F}, {0x08CA, 0x08E1}, {0x08E3, 0x0902}, + {0x093A, 0x093A}, {0x093C, 0x093C}, {0x0941, 0x0948}, + {0x094D, 0x094D}, {0x0951, 0x0957}, {0x0962, 0x0963}, + {0x0981, 0x0981}, {0x09BC, 0x09BC}, {0x09C1, 0x09C4}, + {0x09CD, 0x09CD}, {0x09E2, 0x09E3}, {0x09FE, 0x09FE}, + {0x0A01, 0x0A02}, {0x0A3C, 0x0A3C}, {0x0A41, 0x0A42}, + {0x0A47, 0x0A48}, {0x0A4B, 0x0A4D}, {0x0A51, 0x0A51}, + {0x0A70, 0x0A71}, {0x0A75, 0x0A75}, {0x0A81, 0x0A82}, + {0x0ABC, 0x0ABC}, {0x0AC1, 0x0AC5}, {0x0AC7, 0x0AC8}, + {0x0ACD, 0x0ACD}, {0x0AE2, 0x0AE3}, {0x0AFA, 0x0AFF}, + {0x0B01, 0x0B01}, {0x0B3C, 0x0B3C}, {0x0B3F, 0x0B3F}, + {0x0B41, 0x0B44}, {0x0B4D, 0x0B4D}, {0x0B55, 0x0B56}, + {0x0B62, 0x0B63}, {0x0B82, 0x0B82}, {0x0BC0, 0x0BC0}, + {0x0BCD, 0x0BCD}, {0x0C00, 0x0C00}, {0x0C04, 0x0C04}, + {0x0C3C, 0x0C3C}, {0x0C3E, 0x0C40}, {0x0C46, 0x0C48}, + {0x0C4A, 0x0C4D}, {0x0C55, 0x0C56}, {0x0C62, 0x0C63}, + {0x0C81, 0x0C81}, {0x0CBC, 0x0CBC}, {0x0CBF, 0x0CBF}, + {0x0CC6, 0x0CC6}, {0x0CCC, 0x0CCD}, {0x0CE2, 0x0CE3}, + {0x0CF3, 0x0CF3}, {0x0D00, 0x0D01}, {0x0D3B, 0x0D3C}, + {0x0D41, 0x0D44}, {0x0D4D, 0x0D4D}, {0x0D62, 0x0D63}, + {0x0D81, 0x0D81}, {0x0DCA, 0x0DCA}, {0x0DD2, 0x0DD4}, + {0x0DD6, 0x0DD6}, {0x0E31, 0x0E31}, {0x0E34, 0x0E3A}, + {0x0E47, 0x0E4E}, {0x0EB1, 0x0EB1}, {0x0EB4, 0x0EBC}, + {0x0EC8, 0x0ECE}, {0x0F18, 0x0F19}, {0x0F35, 0x0F35}, + {0x0F37, 0x0F37}, {0x0F39, 0x0F39}, {0x0F71, 0x0F7E}, + {0x0F80, 0x0F84}, {0x0F86, 0x0F87}, {0x0F8D, 0x0F97}, + {0x0F99, 0x0FBC}, {0x0FC6, 0x0FC6}, {0x102D, 0x1030}, + {0x1032, 0x1037}, {0x1039, 0x103A}, {0x103D, 0x103E}, + {0x1058, 0x1059}, {0x105E, 0x1060}, {0x1071, 0x1074}, + {0x1082, 0x1082}, {0x1085, 0x1086}, {0x108D, 0x108D}, + {0x109D, 0x109D}, {0x135D, 0x135F}, {0x1712, 0x1714}, + {0x1732, 0x1733}, {0x1752, 0x1753}, {0x1772, 0x1773}, + {0x17B4, 0x17B5}, {0x17B7, 0x17BD}, {0x17C6, 0x17C6}, + {0x17C9, 0x17D3}, {0x17DD, 0x17DD}, {0x180B, 0x180D}, + {0x180F, 0x180F}, {0x1885, 0x1886}, {0x18A9, 0x18A9}, + {0x1920, 0x1922}, {0x1927, 0x1928}, {0x1932, 0x1932}, + {0x1939, 0x193B}, {0x1A17, 0x1A18}, {0x1A1B, 0x1A1B}, + {0x1A56, 0x1A56}, {0x1A58, 0x1A5E}, {0x1A60, 0x1A60}, + {0x1A62, 0x1A62}, {0x1A65, 0x1A6C}, {0x1A73, 0x1A7C}, + {0x1A7F, 0x1A7F}, {0x1AB0, 0x1ADD}, {0x1AE0, 0x1AEB}, + {0x1B00, 0x1B03}, {0x1B34, 0x1B34}, {0x1B36, 0x1B3A}, + {0x1B3C, 0x1B3C}, {0x1B42, 0x1B42}, {0x1B6B, 0x1B73}, + {0x1B80, 0x1B81}, {0x1BA2, 0x1BA5}, {0x1BA8, 0x1BA9}, + {0x1BAB, 0x1BAD}, {0x1BE6, 0x1BE6}, {0x1BE8, 0x1BE9}, + {0x1BED, 0x1BED}, {0x1BEF, 0x1BF1}, {0x1C2C, 0x1C33}, + {0x1C36, 0x1C37}, {0x1CD0, 0x1CD2}, {0x1CD4, 0x1CE0}, + {0x1CE2, 0x1CE8}, {0x1CED, 0x1CED}, {0x1CF4, 0x1CF4}, + {0x1CF8, 0x1CF9}, {0x1DC0, 0x1DFF}, {0x20D0, 0x20F0}, + {0x2CEF, 0x2CF1}, {0x2D7F, 0x2D7F}, {0x2DE0, 0x2DFF}, + {0x302A, 0x302D}, {0x3099, 0x309A}, {0xA66F, 0xA672}, + {0xA674, 0xA67D}, {0xA69E, 0xA69F}, {0xA6F0, 0xA6F1}, + {0xA802, 0xA802}, {0xA806, 0xA806}, {0xA80B, 0xA80B}, + {0xA825, 0xA826}, {0xA82C, 0xA82C}, {0xA8C4, 0xA8C5}, + {0xA8E0, 0xA8F1}, {0xA8FF, 0xA8FF}, {0xA926, 0xA92D}, + {0xA947, 0xA951}, {0xA980, 0xA982}, {0xA9B3, 0xA9B3}, + {0xA9B6, 0xA9B9}, {0xA9BC, 0xA9BD}, {0xA9E5, 0xA9E5}, + {0xAA29, 0xAA2E}, {0xAA31, 0xAA32}, {0xAA35, 0xAA36}, + {0xAA43, 0xAA43}, {0xAA4C, 0xAA4C}, {0xAA7C, 0xAA7C}, + {0xAAB0, 0xAAB0}, {0xAAB2, 0xAAB4}, {0xAAB7, 0xAAB8}, + {0xAABE, 0xAABF}, {0xAAC1, 0xAAC1}, {0xAAEC, 0xAAED}, + {0xAAF6, 0xAAF6}, {0xABE5, 0xABE5}, {0xABE8, 0xABE8}, + {0xABED, 0xABED}, {0xFB1E, 0xFB1E}, {0xFE00, 0xFE0F}, + {0xFE20, 0xFE2F}, {0x101FD, 0x101FD}, {0x102E0, 0x102E0}, + {0x10376, 0x1037A}, {0x10A01, 0x10A03}, {0x10A05, 0x10A06}, + {0x10A0C, 0x10A0F}, {0x10A38, 0x10A3A}, {0x10A3F, 0x10A3F}, + {0x10AE5, 0x10AE6}, {0x10D24, 0x10D27}, {0x10D69, 0x10D6D}, + {0x10EAB, 0x10EAC}, {0x10EFA, 0x10EFF}, {0x10F46, 0x10F50}, + {0x10F82, 0x10F85}, {0x11001, 0x11001}, {0x11038, 0x11046}, + {0x11070, 0x11070}, {0x11073, 0x11074}, {0x1107F, 0x11081}, + {0x110B3, 0x110B6}, {0x110B9, 0x110BA}, {0x110C2, 0x110C2}, + {0x11100, 0x11102}, {0x11127, 0x1112B}, {0x1112D, 0x11134}, + {0x11173, 0x11173}, {0x11180, 0x11181}, {0x111B6, 0x111BE}, + {0x111C9, 0x111CC}, {0x111CF, 0x111CF}, {0x1122F, 0x11231}, + {0x11234, 0x11234}, {0x11236, 0x11237}, {0x1123E, 0x1123E}, + {0x11241, 0x11241}, {0x112DF, 0x112DF}, {0x112E3, 0x112EA}, + {0x11300, 0x11301}, {0x1133B, 0x1133C}, {0x11340, 0x11340}, + {0x11366, 0x1136C}, {0x11370, 0x11374}, {0x113BB, 0x113C0}, + {0x113CE, 0x113CE}, {0x113D0, 0x113D0}, {0x113D2, 0x113D2}, + {0x113E1, 0x113E2}, {0x11438, 0x1143F}, {0x11442, 0x11444}, + {0x11446, 0x11446}, {0x1145E, 0x1145E}, {0x114B3, 0x114B8}, + {0x114BA, 0x114BA}, {0x114BF, 0x114C0}, {0x114C2, 0x114C3}, + {0x115B2, 0x115B5}, {0x115BC, 0x115BD}, {0x115BF, 0x115C0}, + {0x115DC, 0x115DD}, {0x11633, 0x1163A}, {0x1163D, 0x1163D}, + {0x1163F, 0x11640}, {0x116AB, 0x116AB}, {0x116AD, 0x116AD}, + {0x116B0, 0x116B5}, {0x116B7, 0x116B7}, {0x1171D, 0x1171D}, + {0x1171F, 0x1171F}, {0x11722, 0x11725}, {0x11727, 0x1172B}, + {0x1182F, 0x11837}, {0x11839, 0x1183A}, {0x1193B, 0x1193C}, + {0x1193E, 0x1193E}, {0x11943, 0x11943}, {0x119D4, 0x119D7}, + {0x119DA, 0x119DB}, {0x119E0, 0x119E0}, {0x11A01, 0x11A0A}, + {0x11A33, 0x11A38}, {0x11A3B, 0x11A3E}, {0x11A47, 0x11A47}, + {0x11A51, 0x11A56}, {0x11A59, 0x11A5B}, {0x11A8A, 0x11A96}, + {0x11A98, 0x11A99}, {0x11B60, 0x11B60}, {0x11B62, 0x11B64}, + {0x11B66, 0x11B66}, {0x11C30, 0x11C36}, {0x11C38, 0x11C3D}, + {0x11C3F, 0x11C3F}, {0x11C92, 0x11CA7}, {0x11CAA, 0x11CB0}, + {0x11CB2, 0x11CB3}, {0x11CB5, 0x11CB6}, {0x11D31, 0x11D36}, + {0x11D3A, 0x11D3A}, {0x11D3C, 0x11D3D}, {0x11D3F, 0x11D45}, + {0x11D47, 0x11D47}, {0x11D90, 0x11D91}, {0x11D95, 0x11D95}, + {0x11D97, 0x11D97}, {0x11EF3, 0x11EF4}, {0x11F00, 0x11F01}, + {0x11F36, 0x11F3A}, {0x11F40, 0x11F40}, {0x11F42, 0x11F42}, + {0x11F5A, 0x11F5A}, {0x13440, 0x13440}, {0x13447, 0x13455}, + {0x1611E, 0x16129}, {0x1612D, 0x1612F}, {0x16AF0, 0x16AF4}, + {0x16B30, 0x16B36}, {0x16F4F, 0x16F4F}, {0x16F8F, 0x16F92}, + {0x16FE4, 0x16FE4}, {0x1BC9D, 0x1BC9E}, {0x1CF00, 0x1CF2D}, + {0x1CF30, 0x1CF46}, {0x1D165, 0x1D169}, {0x1D16D, 0x1D172}, + {0x1D17B, 0x1D182}, {0x1D185, 0x1D18B}, {0x1D1AA, 0x1D1AD}, + {0x1D242, 0x1D244}, {0x1DA00, 0x1DA36}, {0x1DA3B, 0x1DA6C}, + {0x1DA75, 0x1DA75}, {0x1DA84, 0x1DA84}, {0x1DA9B, 0x1DA9F}, + {0x1DAA1, 0x1DAAF}, {0x1E000, 0x1E006}, {0x1E008, 0x1E018}, + {0x1E01B, 0x1E021}, {0x1E023, 0x1E024}, {0x1E026, 0x1E02A}, + {0x1E08F, 0x1E08F}, {0x1E130, 0x1E136}, {0x1E2AE, 0x1E2AE}, + {0x1E2EC, 0x1E2EF}, {0x1E4EC, 0x1E4EF}, {0x1E5EE, 0x1E5EF}, + {0x1E6E3, 0x1E6E3}, {0x1E6E6, 0x1E6E6}, {0x1E6EE, 0x1E6EF}, + {0x1E6F5, 0x1E6F5}, {0x1E8D0, 0x1E8D6}, {0x1E944, 0x1E94A}, {0xE0100, 0xE01EF}, } diff --git a/vendor/github.com/moby/moby/api/types/container/hostconfig.go b/vendor/github.com/moby/moby/api/types/container/hostconfig.go index 0f889c65124c..297ebc35e588 100644 --- a/vendor/github.com/moby/moby/api/types/container/hostconfig.go +++ b/vendor/github.com/moby/moby/api/types/container/hostconfig.go @@ -454,6 +454,7 @@ type HostConfig struct { ShmSize int64 // Total shm memory usage Sysctls map[string]string `json:",omitempty"` // List of Namespaced sysctls used for the container Runtime string `json:",omitempty"` // Runtime to use with this container + Umask *uint32 `json:",omitempty"` // Initial process umask // Applicable to Windows Isolation Isolation // Isolation technology of the container (e.g. default, hyperv) diff --git a/vendor/github.com/moby/moby/api/types/image/image_inspect.go b/vendor/github.com/moby/moby/api/types/image/image_inspect.go index df09c9511bd4..90ebfd894cf1 100644 --- a/vendor/github.com/moby/moby/api/types/image/image_inspect.go +++ b/vendor/github.com/moby/moby/api/types/image/image_inspect.go @@ -72,7 +72,11 @@ type InspectResponse struct { // run on (especially for Windows). OsVersion string `json:",omitempty"` - // Size is the total size of the image including all layers it is composed of. + // Size is the total size of the selected image variant, including all layers + // it is composed of. + // + // When using the containerd image store, this includes both the image content + // that's present locally and the unpacked snapshot data. Size int64 // GraphDriver holds information about the storage driver used to store the diff --git a/vendor/github.com/moby/moby/api/types/plugin/plugin_responses.go b/vendor/github.com/moby/moby/api/types/plugin/plugin_responses.go index 91b327eb473f..f4b224307c95 100644 --- a/vendor/github.com/moby/moby/api/types/plugin/plugin_responses.go +++ b/vendor/github.com/moby/moby/api/types/plugin/plugin_responses.go @@ -1,9 +1,5 @@ package plugin -import ( - "sort" -) - // ListResponse contains the response for the Engine API type ListResponse []Plugin @@ -15,19 +11,26 @@ type Privilege struct { Value []string } -// Privileges is a list of Privilege +// Privileges is a list of Privilege. type Privileges []Privilege +// Len implements [sort.Interface]. +// +// Deprecated: use [slices.SortFunc] to sort privileges instead. func (s Privileges) Len() int { return len(s) } +// Less implements [sort.Interface]. +// +// Deprecated: use [slices.SortFunc] to sort privileges instead. func (s Privileges) Less(i, j int) bool { return s[i].Name < s[j].Name } +// Swap implements [sort.Interface]. +// +// Deprecated: use [slices.SortFunc] to sort privileges instead. func (s Privileges) Swap(i, j int) { - sort.Strings(s[i].Value) - sort.Strings(s[j].Value) s[i], s[j] = s[j], s[i] } diff --git a/vendor/github.com/moby/moby/client/README.md b/vendor/github.com/moby/moby/client/README.md index aed3e641d9a4..ebe29495c91b 100644 --- a/vendor/github.com/moby/moby/client/README.md +++ b/vendor/github.com/moby/moby/client/README.md @@ -2,7 +2,6 @@ [![PkgGoDev](https://pkg.go.dev/badge/github.com/moby/moby/client)](https://pkg.go.dev/github.com/moby/moby/client) ![GitHub License](https://img.shields.io/github/license/moby/moby) -[![Go Report Card](https://goreportcard.com/badge/github.com/moby/moby/client)](https://goreportcard.com/report/github.com/moby/moby/client) [![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/moby/moby/badge)](https://scorecard.dev/viewer/?uri=github.com/moby/moby) [![OpenSSF Best Practices](https://www.bestpractices.dev/projects/10989/badge)](https://www.bestpractices.dev/projects/10989) diff --git a/vendor/github.com/moby/moby/client/checkpoint_create.go b/vendor/github.com/moby/moby/client/checkpoint_create.go index b3ba5459d00a..46867643f2c1 100644 --- a/vendor/github.com/moby/moby/client/checkpoint_create.go +++ b/vendor/github.com/moby/moby/client/checkpoint_create.go @@ -24,13 +24,11 @@ func (cli *Client) CheckpointCreate(ctx context.Context, containerID string, opt if err != nil { return CheckpointCreateResult{}, err } - requestBody := checkpoint.CreateRequest{ + resp, err := cli.post(ctx, "/containers/"+containerID+"/checkpoints", nil, nil, checkpoint.CreateRequest{ CheckpointID: options.CheckpointID, CheckpointDir: options.CheckpointDir, Exit: options.Exit, - } - - resp, err := cli.post(ctx, "/containers/"+containerID+"/checkpoints", nil, requestBody, nil) + }) defer ensureReaderClosed(resp) return CheckpointCreateResult{}, err } diff --git a/vendor/github.com/moby/moby/client/client.go b/vendor/github.com/moby/moby/client/client.go index 4b4ef976a31e..3dbcacdeb9d4 100644 --- a/vendor/github.com/moby/moby/client/client.go +++ b/vendor/github.com/moby/moby/client/client.go @@ -109,7 +109,7 @@ const DummyHost = "api.moby.localhost" // overriding the version and disable API-version negotiation. // // This version may be lower than the version of the api library module used. -const MaxAPIVersion = "1.55" +const MaxAPIVersion = "1.56" // MinAPIVersion is the minimum API version supported by the client. API versions // below this version are not considered when performing API-version negotiation. diff --git a/vendor/github.com/moby/moby/client/config_create.go b/vendor/github.com/moby/moby/client/config_create.go index 874e2c947c5a..3c37ea9e50d0 100644 --- a/vendor/github.com/moby/moby/client/config_create.go +++ b/vendor/github.com/moby/moby/client/config_create.go @@ -19,7 +19,7 @@ type ConfigCreateResult struct { // ConfigCreate creates a new config. func (cli *Client) ConfigCreate(ctx context.Context, options ConfigCreateOptions) (ConfigCreateResult, error) { - resp, err := cli.post(ctx, "/configs/create", nil, options.Spec, nil) + resp, err := cli.post(ctx, "/configs/create", nil, nil, options.Spec) defer ensureReaderClosed(resp) if err != nil { return ConfigCreateResult{}, err diff --git a/vendor/github.com/moby/moby/client/config_update.go b/vendor/github.com/moby/moby/client/config_update.go index 31bdd795699d..bfbac46dec22 100644 --- a/vendor/github.com/moby/moby/client/config_update.go +++ b/vendor/github.com/moby/moby/client/config_update.go @@ -24,7 +24,7 @@ func (cli *Client) ConfigUpdate(ctx context.Context, id string, options ConfigUp } query := url.Values{} query.Set("version", options.Version.String()) - resp, err := cli.post(ctx, "/configs/"+id+"/update", query, options.Spec, nil) + resp, err := cli.post(ctx, "/configs/"+id+"/update", query, nil, options.Spec) defer ensureReaderClosed(resp) if err != nil { return ConfigUpdateResult{}, err diff --git a/vendor/github.com/moby/moby/client/container_commit.go b/vendor/github.com/moby/moby/client/container_commit.go index 79da44a54f80..47981bec7239 100644 --- a/vendor/github.com/moby/moby/client/container_commit.go +++ b/vendor/github.com/moby/moby/client/container_commit.go @@ -31,8 +31,9 @@ func (cli *Client) ContainerCommit(ctx context.Context, containerID string, opti if err != nil { return ContainerCommitResult{}, err } + query := url.Values{} + query.Set("container", containerID) - var repository, tag string if options.Reference != "" { ref, err := reference.ParseNormalizedNamed(options.Reference) if err != nil { @@ -44,18 +45,18 @@ func (cli *Client) ContainerCommit(ctx context.Context, containerID string, opti } ref = reference.TagNameOnly(ref) + query.Set("repo", ref.Name()) if tagged, ok := ref.(reference.Tagged); ok { - tag = tagged.Tag() + query.Set("tag", tagged.Tag()) } - repository = ref.Name() } - query := url.Values{} - query.Set("container", containerID) - query.Set("repo", repository) - query.Set("tag", tag) - query.Set("comment", options.Comment) - query.Set("author", options.Author) + if options.Comment != "" { + query.Set("comment", options.Comment) + } + if options.Author != "" { + query.Set("author", options.Author) + } for _, change := range options.Changes { query.Add("changes", change) } @@ -64,7 +65,7 @@ func (cli *Client) ContainerCommit(ctx context.Context, containerID string, opti } var response container.CommitResponse - resp, err := cli.post(ctx, "/commit", query, options.Config, nil) + resp, err := cli.post(ctx, "/commit", query, nil, options.Config) defer ensureReaderClosed(resp) if err != nil { return ContainerCommitResult{}, err diff --git a/vendor/github.com/moby/moby/client/container_copy.go b/vendor/github.com/moby/moby/client/container_copy.go index b37d1765f441..b91babd3bdbb 100644 --- a/vendor/github.com/moby/moby/client/container_copy.go +++ b/vendor/github.com/moby/moby/client/container_copy.go @@ -77,7 +77,7 @@ func (cli *Client) CopyToContainer(ctx context.Context, containerID string, opti query.Set("copyUIDGID", "true") } - response, err := cli.putRaw(ctx, "/containers/"+containerID+"/archive", query, options.Content, nil) + response, err := cli.putRaw(ctx, "/containers/"+containerID+"/archive", query, nil, options.Content) defer ensureReaderClosed(response) if err != nil { return CopyToContainerResult{}, err diff --git a/vendor/github.com/moby/moby/client/container_create.go b/vendor/github.com/moby/moby/client/container_create.go index d941a37207c9..7e6b15a96ecc 100644 --- a/vendor/github.com/moby/moby/client/container_create.go +++ b/vendor/github.com/moby/moby/client/container_create.go @@ -5,7 +5,7 @@ import ( "encoding/json" "net/url" "path" - "sort" + "slices" "strings" cerrdefs "github.com/containerd/errdefs" @@ -35,13 +35,6 @@ func (cli *Client) ContainerCreate(ctx context.Context, options ContainerCreateO return ContainerCreateResult{}, cerrdefs.ErrInvalidArgument.WithMessage("config.Image or Image is required") } - var response container.CreateResponse - - if options.HostConfig != nil { - options.HostConfig.CapAdd = normalizeCapabilities(options.HostConfig.CapAdd) - options.HostConfig.CapDrop = normalizeCapabilities(options.HostConfig.CapDrop) - } - query := url.Values{} if options.Platform != nil { if p := formatPlatform(*options.Platform); p != "unknown" { @@ -53,18 +46,17 @@ func (cli *Client) ContainerCreate(ctx context.Context, options ContainerCreateO query.Set("name", options.Name) } - body := container.CreateRequest{ + resp, err := cli.post(ctx, "/containers/create", query, nil, container.CreateRequest{ Config: cfg, - HostConfig: options.HostConfig, + HostConfig: normalizeHostConfig(options.HostConfig), NetworkingConfig: options.NetworkingConfig, - } - - resp, err := cli.post(ctx, "/containers/create", query, body, nil) + }) defer ensureReaderClosed(resp) if err != nil { return ContainerCreateResult{}, err } + var response container.CreateResponse err = json.NewDecoder(resp.Body).Decode(&response) return ContainerCreateResult{ID: response.ID, Warnings: response.Warnings}, err } @@ -86,6 +78,17 @@ func formatPlatform(platform ocispec.Platform) string { // allCapabilities is a magic value for "all capabilities" const allCapabilities = "ALL" +// normalizeCap normalizes a capability to its canonical format by upper-casing +// and adding a "CAP_" prefix (if not yet present). It also accepts the "ALL" +// magic-value. +func normalizeCap(c string) string { + c = strings.ToUpper(c) + if c != allCapabilities && !strings.HasPrefix(c, "CAP_") { + c = "CAP_" + c + } + return c +} + // normalizeCapabilities normalizes capabilities to their canonical form, // removes duplicates, and sorts the results. // @@ -94,32 +97,22 @@ const allCapabilities = "ALL" // // [caps.NormalizeLegacyCapabilities]: https://github.com/moby/moby/blob/v28.3.2/oci/caps/utils.go#L56 func normalizeCapabilities(caps []string) []string { - var normalized []string - - unique := make(map[string]struct{}) - for _, c := range caps { - c = normalizeCap(c) - if _, ok := unique[c]; ok { - continue - } - unique[c] = struct{}{} - normalized = append(normalized, c) + normalized := slices.Clone(caps) + for i, c := range normalized { + normalized[i] = normalizeCap(c) } - - sort.Strings(normalized) - return normalized + slices.Sort(normalized) + return slices.Compact(normalized) } -// normalizeCap normalizes a capability to its canonical format by upper-casing -// and adding a "CAP_" prefix (if not yet present). It also accepts the "ALL" -// magic-value. -func normalizeCap(capability string) string { - capability = strings.ToUpper(capability) - if capability == allCapabilities { - return capability +// normalizeHostConfig returns a shallow copy of hostConfig with capabilities normalized. +func normalizeHostConfig(hostConfig *container.HostConfig) *container.HostConfig { + if hostConfig == nil { + return nil } - if !strings.HasPrefix(capability, "CAP_") { - capability = "CAP_" + capability - } - return capability + + normalized := *hostConfig + normalized.CapAdd = normalizeCapabilities(hostConfig.CapAdd) + normalized.CapDrop = normalizeCapabilities(hostConfig.CapDrop) + return &normalized } diff --git a/vendor/github.com/moby/moby/client/container_exec.go b/vendor/github.com/moby/moby/client/container_exec.go index 30ed00ea52d7..86c9474b48cc 100644 --- a/vendor/github.com/moby/moby/client/container_exec.go +++ b/vendor/github.com/moby/moby/client/container_exec.go @@ -42,7 +42,7 @@ func (cli *Client) ExecCreate(ctx context.Context, containerID string, options E return ExecCreateResult{}, err } - req := container.ExecCreateRequest{ + resp, err := cli.post(ctx, "/containers/"+containerID+"/exec", nil, nil, container.ExecCreateRequest{ User: options.User, Privileged: options.Privileged, Tty: options.TTY, @@ -54,9 +54,7 @@ func (cli *Client) ExecCreate(ctx context.Context, containerID string, options E Env: options.Env, WorkingDir: options.WorkingDir, Cmd: options.Cmd, - } - - resp, err := cli.post(ctx, "/containers/"+containerID+"/exec", nil, req, nil) + }) defer ensureReaderClosed(resp) if err != nil { return ExecCreateResult{}, err @@ -91,12 +89,11 @@ func (cli *Client) ExecStart(ctx context.Context, execID string, options ExecSta return ExecStartResult{}, err } - req := container.ExecStartRequest{ + resp, err := cli.post(ctx, "/exec/"+execID+"/start", nil, nil, container.ExecStartRequest{ Detach: options.Detach, Tty: options.TTY, ConsoleSize: consoleSize, - } - resp, err := cli.post(ctx, "/exec/"+execID+"/start", nil, req, nil) + }) defer ensureReaderClosed(resp) return ExecStartResult{}, err } diff --git a/vendor/github.com/moby/moby/client/container_restart.go b/vendor/github.com/moby/moby/client/container_restart.go index e883f75891bd..df7ca4c7ed6d 100644 --- a/vendor/github.com/moby/moby/client/container_restart.go +++ b/vendor/github.com/moby/moby/client/container_restart.go @@ -16,7 +16,8 @@ type ContainerRestartOptions struct { // Timeout (optional) is the timeout (in seconds) to wait for the container // to stop gracefully before forcibly terminating it with SIGKILL. // - // - Use nil to use the default timeout (10 seconds). + // - Use nil to use the container's configured timeout, or the engine default + // if the container has no configured timeout. // - Use '-1' to wait indefinitely. // - Use '0' to not wait for the container to exit gracefully, and // immediately proceeds to forcibly terminating the container. diff --git a/vendor/github.com/moby/moby/client/container_stop.go b/vendor/github.com/moby/moby/client/container_stop.go index d4d47d8fd407..d72358c5eec6 100644 --- a/vendor/github.com/moby/moby/client/container_stop.go +++ b/vendor/github.com/moby/moby/client/container_stop.go @@ -16,7 +16,8 @@ type ContainerStopOptions struct { // Timeout (optional) is the timeout (in seconds) to wait for the container // to stop gracefully before forcibly terminating it with SIGKILL. // - // - Use nil to use the default timeout (10 seconds). + // - Use nil to use the container's configured timeout, or the engine default + // if the container has no configured timeout. // - Use '-1' to wait indefinitely. // - Use '0' to not wait for the container to exit gracefully, and // immediately proceeds to forcibly terminating the container. diff --git a/vendor/github.com/moby/moby/client/container_update.go b/vendor/github.com/moby/moby/client/container_update.go index a1d4d249a9f3..197d8da432b3 100644 --- a/vendor/github.com/moby/moby/client/container_update.go +++ b/vendor/github.com/moby/moby/client/container_update.go @@ -26,15 +26,10 @@ func (cli *Client) ContainerUpdate(ctx context.Context, containerID string, opti return ContainerUpdateResult{}, err } - updateConfig := container.UpdateConfig{} - if options.Resources != nil { - updateConfig.Resources = *options.Resources - } - if options.RestartPolicy != nil { - updateConfig.RestartPolicy = *options.RestartPolicy - } - - resp, err := cli.post(ctx, "/containers/"+containerID+"/update", nil, updateConfig, nil) + resp, err := cli.post(ctx, "/containers/"+containerID+"/update", nil, nil, container.UpdateConfig{ + Resources: valueOrZero(options.Resources), + RestartPolicy: valueOrZero(options.RestartPolicy), + }) defer ensureReaderClosed(resp) if err != nil { return ContainerUpdateResult{}, err diff --git a/vendor/github.com/moby/moby/client/hijack.go b/vendor/github.com/moby/moby/client/hijack.go index 31c44e598877..3b6b12c8fd14 100644 --- a/vendor/github.com/moby/moby/client/hijack.go +++ b/vendor/github.com/moby/moby/client/hijack.go @@ -18,7 +18,7 @@ func (cli *Client) postHijacked(ctx context.Context, path string, query url.Valu if err != nil { return HijackedResponse{}, err } - req, err := cli.buildRequest(ctx, http.MethodPost, cli.getAPIPath(ctx, path, query), jsonBody, headers) + req, err := cli.buildRequest(ctx, http.MethodPost, cli.getAPIPath(ctx, path, query), headers, jsonBody) if err != nil { return HijackedResponse{}, err } diff --git a/vendor/github.com/moby/moby/client/image_build.go b/vendor/github.com/moby/moby/client/image_build.go index 67ac204aaf41..82ddc8ee1ade 100644 --- a/vendor/github.com/moby/moby/client/image_build.go +++ b/vendor/github.com/moby/moby/client/image_build.go @@ -32,7 +32,7 @@ func (cli *Client) ImageBuild(ctx context.Context, buildContext io.Reader, optio headers.Add("X-Registry-Config", base64.URLEncoding.EncodeToString(buf)) headers.Set("Content-Type", "application/x-tar") - resp, err := cli.postRaw(ctx, "/build", query, buildContext, headers) + resp, err := cli.postRaw(ctx, "/build", query, headers, buildContext) if err != nil { return ImageBuildResult{}, err } diff --git a/vendor/github.com/moby/moby/client/image_import.go b/vendor/github.com/moby/moby/client/image_import.go index 6c9f22866f9c..66186f228dd5 100644 --- a/vendor/github.com/moby/moby/client/image_import.go +++ b/vendor/github.com/moby/moby/client/image_import.go @@ -46,7 +46,7 @@ func (cli *Client) ImageImport(ctx context.Context, source ImageImportSource, re query.Add("changes", change) } - resp, err := cli.postRaw(ctx, "/images/create", query, source.Source, nil) + resp, err := cli.postRaw(ctx, "/images/create", query, nil, source.Source) if err != nil { return nil, err } diff --git a/vendor/github.com/moby/moby/client/image_load.go b/vendor/github.com/moby/moby/client/image_load.go index ec5fcae6ebfc..3edd491d22d3 100644 --- a/vendor/github.com/moby/moby/client/image_load.go +++ b/vendor/github.com/moby/moby/client/image_load.go @@ -42,9 +42,8 @@ func (cli *Client) ImageLoad(ctx context.Context, input io.Reader, loadOpts ...I query["platform"] = p } - resp, err := cli.postRaw(ctx, "/images/load", query, input, http.Header{ - "Content-Type": {"application/x-tar"}, - }) + headers := http.Header{"Content-Type": {"application/x-tar"}} + resp, err := cli.postRaw(ctx, "/images/load", query, headers, input) if err != nil { return nil, err } diff --git a/vendor/github.com/moby/moby/client/image_pull.go b/vendor/github.com/moby/moby/client/image_pull.go index 11c0afa41821..04d9edf1bba3 100644 --- a/vendor/github.com/moby/moby/client/image_pull.go +++ b/vendor/github.com/moby/moby/client/image_pull.go @@ -89,5 +89,5 @@ func (cli *Client) tryImageCreate(ctx context.Context, query url.Values, resolve hdr.Set(registry.AuthHeader, registryAuth) } } - return cli.post(ctx, "/images/create", query, nil, hdr) + return cli.post(ctx, "/images/create", query, hdr, nil) } diff --git a/vendor/github.com/moby/moby/client/image_push.go b/vendor/github.com/moby/moby/client/image_push.go index 5dd8bc140752..d7729841cc87 100644 --- a/vendor/github.com/moby/moby/client/image_push.go +++ b/vendor/github.com/moby/moby/client/image_push.go @@ -94,5 +94,5 @@ func (cli *Client) tryImagePush(ctx context.Context, imageID string, query url.V // We use [http.NoBody], which gets marshaled to an empty JSON document. // // see: https://github.com/moby/moby/commit/ea29dffaa541289591aa44fa85d2a596ce860e16 - return cli.post(ctx, "/images/"+imageID+"/push", query, http.NoBody, hdr) + return cli.post(ctx, "/images/"+imageID+"/push", query, hdr, http.NoBody) } diff --git a/vendor/github.com/moby/moby/client/internal/mod/mod.go b/vendor/github.com/moby/moby/client/internal/mod/mod.go index 355eb9532698..c9a11b3e5689 100644 --- a/vendor/github.com/moby/moby/client/internal/mod/mod.go +++ b/vendor/github.com/moby/moby/client/internal/mod/mod.go @@ -87,7 +87,7 @@ func getVersion(name string, dep *debug.Module) (string, bool) { func normalize(v string) string { base, metas, dirty := splitMetadata(v) - out := base + var out strings.Builder if base2, rev, undoPatch, ok := splitPseudo(base); ok { if undoPatch { // Downgrade the patch version that was raised by pseudo-versions: @@ -102,18 +102,22 @@ func normalize(v string) string { if len(rev) > 12 { rev = rev[:12] } - out = base2 + "+" + rev + out.WriteString(base2) + out.WriteByte('+') + out.WriteString(rev) + } else { + out.WriteString(base) } // Preserve other metadata (except for "+incompatible"). for _, m := range metas { - out += m + out.WriteString(m) } if dirty { // +dirty goes last - out += "+dirty" + out.WriteString("+dirty") } - return out + return out.String() } func splitMetadata(v string) (base string, metas []string, dirty bool) { diff --git a/vendor/github.com/moby/moby/client/login.go b/vendor/github.com/moby/moby/client/login.go index b295080ab7dc..9d9e5fad3f13 100644 --- a/vendor/github.com/moby/moby/client/login.go +++ b/vendor/github.com/moby/moby/client/login.go @@ -32,7 +32,7 @@ func (cli *Client) RegistryLogin(ctx context.Context, options RegistryLoginOptio RegistryToken: options.RegistryToken, } - resp, err := cli.post(ctx, "/auth", url.Values{}, auth, nil) + resp, err := cli.post(ctx, "/auth", url.Values{}, nil, auth) defer ensureReaderClosed(resp) if err != nil { diff --git a/vendor/github.com/moby/moby/client/network_connect.go b/vendor/github.com/moby/moby/client/network_connect.go index 40db955a90b1..1a5cd645a45a 100644 --- a/vendor/github.com/moby/moby/client/network_connect.go +++ b/vendor/github.com/moby/moby/client/network_connect.go @@ -34,7 +34,7 @@ func (cli *Client) NetworkConnect(ctx context.Context, networkID string, options Container: containerID, EndpointConfig: options.EndpointConfig, } - resp, err := cli.post(ctx, "/networks/"+networkID+"/connect", nil, nc, nil) + resp, err := cli.post(ctx, "/networks/"+networkID+"/connect", nil, nil, nc) defer ensureReaderClosed(resp) return NetworkConnectResult{}, err } diff --git a/vendor/github.com/moby/moby/client/network_create.go b/vendor/github.com/moby/moby/client/network_create.go index 25ea32af451b..b5dae82b2845 100644 --- a/vendor/github.com/moby/moby/client/network_create.go +++ b/vendor/github.com/moby/moby/client/network_create.go @@ -51,7 +51,7 @@ func (cli *Client) NetworkCreate(ctx context.Context, name string, options Netwo req.ConfigFrom = &network.ConfigReference{Network: options.ConfigFrom} } - resp, err := cli.post(ctx, "/networks/create", nil, req, nil) + resp, err := cli.post(ctx, "/networks/create", nil, nil, req) defer ensureReaderClosed(resp) if err != nil { return NetworkCreateResult{}, err diff --git a/vendor/github.com/moby/moby/client/network_disconnect.go b/vendor/github.com/moby/moby/client/network_disconnect.go index 64a1796b8de6..4b1a6f550b28 100644 --- a/vendor/github.com/moby/moby/client/network_disconnect.go +++ b/vendor/github.com/moby/moby/client/network_disconnect.go @@ -30,11 +30,10 @@ func (cli *Client) NetworkDisconnect(ctx context.Context, networkID string, opti return NetworkDisconnectResult{}, err } - req := network.DisconnectRequest{ + resp, err := cli.post(ctx, "/networks/"+networkID+"/disconnect", nil, nil, network.DisconnectRequest{ Container: containerID, Force: options.Force, - } - resp, err := cli.post(ctx, "/networks/"+networkID+"/disconnect", nil, req, nil) + }) defer ensureReaderClosed(resp) return NetworkDisconnectResult{}, err } diff --git a/vendor/github.com/moby/moby/client/node_update.go b/vendor/github.com/moby/moby/client/node_update.go index 24f87a4df559..cdd80fba124d 100644 --- a/vendor/github.com/moby/moby/client/node_update.go +++ b/vendor/github.com/moby/moby/client/node_update.go @@ -25,7 +25,7 @@ func (cli *Client) NodeUpdate(ctx context.Context, nodeID string, options NodeUp query := url.Values{} query.Set("version", options.Version.String()) - resp, err := cli.post(ctx, "/nodes/"+nodeID+"/update", query, options.Spec, nil) + resp, err := cli.post(ctx, "/nodes/"+nodeID+"/update", query, nil, options.Spec) defer ensureReaderClosed(resp) return NodeUpdateResult{}, err } diff --git a/vendor/github.com/moby/moby/client/plugin_create.go b/vendor/github.com/moby/moby/client/plugin_create.go index c1a2dd5a6c21..f4e7c9a02fa3 100644 --- a/vendor/github.com/moby/moby/client/plugin_create.go +++ b/vendor/github.com/moby/moby/client/plugin_create.go @@ -25,7 +25,7 @@ func (cli *Client) PluginCreate(ctx context.Context, createContext io.Reader, cr query := url.Values{} query.Set("name", createOptions.RepoName) - resp, err := cli.postRaw(ctx, "/plugins/create", query, createContext, headers) + resp, err := cli.postRaw(ctx, "/plugins/create", query, headers, createContext) defer ensureReaderClosed(resp) return PluginCreateResult{}, err } diff --git a/vendor/github.com/moby/moby/client/plugin_install.go b/vendor/github.com/moby/moby/client/plugin_install.go index a589b2e1fd36..d26ee782c37f 100644 --- a/vendor/github.com/moby/moby/client/plugin_install.go +++ b/vendor/github.com/moby/moby/client/plugin_install.go @@ -99,13 +99,12 @@ func (cli *Client) tryPluginPrivileges(ctx context.Context, query url.Values, re }) } -func (cli *Client) tryPluginPull(ctx context.Context, query url.Values, privileges plugin.Privileges, registryAuth string) (*http.Response, error) { - return cli.post(ctx, "/plugins/pull", query, privileges, http.Header{ - registry.AuthHeader: {registryAuth}, - }) +func (cli *Client) tryPluginPull(ctx context.Context, query url.Values, privileges []plugin.Privilege, registryAuth string) (*http.Response, error) { + headers := http.Header{registry.AuthHeader: {registryAuth}} + return cli.post(ctx, "/plugins/pull", query, headers, privileges) } -func (cli *Client) checkPluginPermissions(ctx context.Context, query url.Values, options pluginOptions) (plugin.Privileges, error) { +func (cli *Client) checkPluginPermissions(ctx context.Context, query url.Values, options pluginOptions) ([]plugin.Privilege, error) { resp, err := cli.tryPluginPrivileges(ctx, query, options.getRegistryAuth()) if cerrdefs.IsUnauthorized(err) && options.getPrivilegeFunc() != nil { // TODO: do inspect before to check existing name before checking privileges @@ -122,7 +121,7 @@ func (cli *Client) checkPluginPermissions(ctx context.Context, query url.Values, return nil, err } - var privileges plugin.Privileges + var privileges []plugin.Privilege if err := json.NewDecoder(resp.Body).Decode(&privileges); err != nil { ensureReaderClosed(resp) return nil, err diff --git a/vendor/github.com/moby/moby/client/plugin_push.go b/vendor/github.com/moby/moby/client/plugin_push.go index 4ba25d1336ee..d206fd2603da 100644 --- a/vendor/github.com/moby/moby/client/plugin_push.go +++ b/vendor/github.com/moby/moby/client/plugin_push.go @@ -24,9 +24,8 @@ func (cli *Client) PluginPush(ctx context.Context, name string, options PluginPu if err != nil { return PluginPushResult{}, err } - resp, err := cli.post(ctx, "/plugins/"+name+"/push", nil, nil, http.Header{ - registry.AuthHeader: {options.RegistryAuth}, - }) + headers := http.Header{registry.AuthHeader: {options.RegistryAuth}} + resp, err := cli.post(ctx, "/plugins/"+name+"/push", nil, headers, nil) if err != nil { return PluginPushResult{}, err } diff --git a/vendor/github.com/moby/moby/client/plugin_set.go b/vendor/github.com/moby/moby/client/plugin_set.go index c1f6bb5fac83..309a30c02969 100644 --- a/vendor/github.com/moby/moby/client/plugin_set.go +++ b/vendor/github.com/moby/moby/client/plugin_set.go @@ -21,7 +21,7 @@ func (cli *Client) PluginSet(ctx context.Context, name string, options PluginSet return PluginSetResult{}, err } - resp, err := cli.post(ctx, "/plugins/"+name+"/set", nil, options.Args, nil) + resp, err := cli.post(ctx, "/plugins/"+name+"/set", nil, nil, options.Args) defer ensureReaderClosed(resp) return PluginSetResult{}, err } diff --git a/vendor/github.com/moby/moby/client/plugin_upgrade.go b/vendor/github.com/moby/moby/client/plugin_upgrade.go index f9df6e5843d9..bcfb1eacfe82 100644 --- a/vendor/github.com/moby/moby/client/plugin_upgrade.go +++ b/vendor/github.com/moby/moby/client/plugin_upgrade.go @@ -58,10 +58,9 @@ func (cli *Client) PluginUpgrade(ctx context.Context, name string, options Plugi return resp.Body, nil } -func (cli *Client) tryPluginUpgrade(ctx context.Context, query url.Values, privileges plugin.Privileges, name, registryAuth string) (*http.Response, error) { - return cli.post(ctx, "/plugins/"+name+"/upgrade", query, privileges, http.Header{ - registry.AuthHeader: {registryAuth}, - }) +func (cli *Client) tryPluginUpgrade(ctx context.Context, query url.Values, privileges []plugin.Privilege, name, registryAuth string) (*http.Response, error) { + headers := http.Header{registry.AuthHeader: {registryAuth}} + return cli.post(ctx, "/plugins/"+name+"/upgrade", query, headers, privileges) } func (o *PluginUpgradeOptions) getRegistryAuth() string { diff --git a/vendor/github.com/moby/moby/client/request.go b/vendor/github.com/moby/moby/client/request.go index 10ed36dc6789..7d57b6b6adbd 100644 --- a/vendor/github.com/moby/moby/client/request.go +++ b/vendor/github.com/moby/moby/client/request.go @@ -19,49 +19,49 @@ import ( // head sends an http request to the docker API using the method HEAD. func (cli *Client) head(ctx context.Context, path string, query url.Values, headers http.Header) (*http.Response, error) { - return cli.sendRequest(ctx, http.MethodHead, path, query, nil, headers) + return cli.sendRequest(ctx, http.MethodHead, path, query, headers, nil) } // get sends an http request to the docker API using the method GET with a specific Go context. func (cli *Client) get(ctx context.Context, path string, query url.Values, headers http.Header) (*http.Response, error) { - return cli.sendRequest(ctx, http.MethodGet, path, query, nil, headers) + return cli.sendRequest(ctx, http.MethodGet, path, query, headers, nil) } // post sends an http POST request to the API. -func (cli *Client) post(ctx context.Context, path string, query url.Values, body any, headers http.Header) (*http.Response, error) { +func (cli *Client) post(ctx context.Context, path string, query url.Values, headers http.Header, body any) (*http.Response, error) { jsonBody, headers, err := prepareJSONRequest(body, headers) if err != nil { return nil, err } - return cli.sendRequest(ctx, http.MethodPost, path, query, jsonBody, headers) + return cli.sendRequest(ctx, http.MethodPost, path, query, headers, jsonBody) } -func (cli *Client) postRaw(ctx context.Context, path string, query url.Values, body io.Reader, headers http.Header) (*http.Response, error) { - return cli.sendRequest(ctx, http.MethodPost, path, query, body, headers) +func (cli *Client) postRaw(ctx context.Context, path string, query url.Values, headers http.Header, body io.Reader) (*http.Response, error) { + return cli.sendRequest(ctx, http.MethodPost, path, query, headers, body) } -func (cli *Client) put(ctx context.Context, path string, query url.Values, body any, headers http.Header) (*http.Response, error) { +func (cli *Client) put(ctx context.Context, path string, query url.Values, headers http.Header, body any) (*http.Response, error) { jsonBody, headers, err := prepareJSONRequest(body, headers) if err != nil { return nil, err } - return cli.putRaw(ctx, path, query, jsonBody, headers) + return cli.putRaw(ctx, path, query, headers, jsonBody) } // putRaw sends an http request to the docker API using the method PUT. -func (cli *Client) putRaw(ctx context.Context, path string, query url.Values, body io.Reader, headers http.Header) (*http.Response, error) { +func (cli *Client) putRaw(ctx context.Context, path string, query url.Values, headers http.Header, body io.Reader) (*http.Response, error) { // PUT requests are expected to always have a body (apparently) // so explicitly pass an empty body to sendRequest to signal that // it should set the Content-Type header if not already present. if body == nil { body = http.NoBody } - return cli.sendRequest(ctx, http.MethodPut, path, query, body, headers) + return cli.sendRequest(ctx, http.MethodPut, path, query, headers, body) } // delete sends an http request to the docker API using the method DELETE. func (cli *Client) delete(ctx context.Context, path string, query url.Values, headers http.Header) (*http.Response, error) { - return cli.sendRequest(ctx, http.MethodDelete, path, query, nil, headers) + return cli.sendRequest(ctx, http.MethodDelete, path, query, headers, nil) } // prepareJSONRequest encodes the given body to JSON and returns it as an [io.Reader], and sets the Content-Type @@ -87,7 +87,7 @@ func prepareJSONRequest(body any, headers http.Header) (io.Reader, http.Header, return jsonBody, hdr, nil } -func (cli *Client) buildRequest(ctx context.Context, method, path string, body io.Reader, headers http.Header) (*http.Request, error) { +func (cli *Client) buildRequest(ctx context.Context, method, path string, headers http.Header, body io.Reader) (*http.Request, error) { req, err := http.NewRequestWithContext(ctx, method, path, body) if err != nil { return nil, err @@ -104,8 +104,8 @@ func (cli *Client) buildRequest(ctx context.Context, method, path string, body i return req, nil } -func (cli *Client) sendRequest(ctx context.Context, method, path string, query url.Values, body io.Reader, headers http.Header) (*http.Response, error) { - req, err := cli.buildRequest(ctx, method, cli.getAPIPath(ctx, path, query), body, headers) +func (cli *Client) sendRequest(ctx context.Context, method, path string, query url.Values, headers http.Header, body io.Reader) (*http.Response, error) { + req, err := cli.buildRequest(ctx, method, cli.getAPIPath(ctx, path, query), headers, body) if err != nil { return nil, err } diff --git a/vendor/github.com/moby/moby/client/secret_create.go b/vendor/github.com/moby/moby/client/secret_create.go index 8e59a42ce705..22d5362d7fda 100644 --- a/vendor/github.com/moby/moby/client/secret_create.go +++ b/vendor/github.com/moby/moby/client/secret_create.go @@ -19,7 +19,7 @@ type SecretCreateResult struct { // SecretCreate creates a new secret. func (cli *Client) SecretCreate(ctx context.Context, options SecretCreateOptions) (SecretCreateResult, error) { - resp, err := cli.post(ctx, "/secrets/create", nil, options.Spec, nil) + resp, err := cli.post(ctx, "/secrets/create", nil, nil, options.Spec) defer ensureReaderClosed(resp) if err != nil { return SecretCreateResult{}, err diff --git a/vendor/github.com/moby/moby/client/secret_update.go b/vendor/github.com/moby/moby/client/secret_update.go index d50fba4d4510..b9fe94c71a18 100644 --- a/vendor/github.com/moby/moby/client/secret_update.go +++ b/vendor/github.com/moby/moby/client/secret_update.go @@ -24,7 +24,7 @@ func (cli *Client) SecretUpdate(ctx context.Context, id string, options SecretUp } query := url.Values{} query.Set("version", options.Version.String()) - resp, err := cli.post(ctx, "/secrets/"+id+"/update", query, options.Spec, nil) + resp, err := cli.post(ctx, "/secrets/"+id+"/update", query, nil, options.Spec) defer ensureReaderClosed(resp) if err != nil { return SecretUpdateResult{}, err diff --git a/vendor/github.com/moby/moby/client/service_create.go b/vendor/github.com/moby/moby/client/service_create.go index 319bca6f4c87..e911e5783d18 100644 --- a/vendor/github.com/moby/moby/client/service_create.go +++ b/vendor/github.com/moby/moby/client/service_create.go @@ -78,7 +78,7 @@ func (cli *Client) ServiceCreate(ctx context.Context, options ServiceCreateOptio if options.EncodedRegistryAuth != "" { headers[registry.AuthHeader] = []string{options.EncodedRegistryAuth} } - resp, err := cli.post(ctx, "/services/create", nil, options.Spec, headers) + resp, err := cli.post(ctx, "/services/create", nil, headers, options.Spec) defer ensureReaderClosed(resp) if err != nil { return ServiceCreateResult{}, err @@ -137,21 +137,37 @@ func imageDigestAndPlatforms(ctx context.Context, cli DistributionAPIClient, ima if len(distributionInspect.Platforms) > 0 { platforms = make([]swarm.Platform, 0, len(distributionInspect.Platforms)) + seen := make(map[swarm.Platform]struct{}, len(distributionInspect.Platforms)) for _, p := range distributionInspect.Platforms { + // skip attestations and other data included in the manifest index. + if p.OS == "unknown" || p.Architecture == "unknown" { + continue + } // clear architecture field for arm. This is a temporary patch to address - // https://github.com/docker/swarmkit/issues/2294. The issue is that while + // https://github.com/moby/swarmkit/issues/2294. The issue is that while // image manifests report "arm" as the architecture, the node reports // something like "armv7l" (includes the variant), which causes arm images // to stop working with swarm mode. This patch removes the architecture // constraint for arm images to ensure tasks get scheduled. arch := p.Architecture - if strings.ToLower(arch) == "arm" { + if strings.EqualFold(arch, "arm") { arch = "" } - platforms = append(platforms, swarm.Platform{ + platform := swarm.Platform{ Architecture: arch, OS: p.OS, - }) + } + + // Skip duplicates. Swarm currently only uses os/arch, and doesn't + // support other fields (Variant, OSVersion, OSFeatures), which + // usually results in duplicate "os/arch" combinations coming from + // the image. + if _, ok := seen[platform]; ok { + continue + } + seen[platform] = struct{}{} + + platforms = append(platforms, platform) } } return imageWithDigest, platforms, err diff --git a/vendor/github.com/moby/moby/client/service_inspect.go b/vendor/github.com/moby/moby/client/service_inspect.go index 9bda43f86164..7b7d09894195 100644 --- a/vendor/github.com/moby/moby/client/service_inspect.go +++ b/vendor/github.com/moby/moby/client/service_inspect.go @@ -3,7 +3,6 @@ package client import ( "context" "encoding/json" - "fmt" "net/url" "github.com/moby/moby/api/types/swarm" @@ -28,7 +27,9 @@ func (cli *Client) ServiceInspect(ctx context.Context, serviceID string, options } query := url.Values{} - query.Set("insertDefaults", fmt.Sprintf("%v", options.InsertDefaults)) + if options.InsertDefaults { + query.Set("insertDefaults", "1") + } resp, err := cli.get(ctx, "/services/"+serviceID, query, nil) if err != nil { return ServiceInspectResult{}, err diff --git a/vendor/github.com/moby/moby/client/service_update.go b/vendor/github.com/moby/moby/client/service_update.go index 2505fe4b8eed..4f179f0a7dbd 100644 --- a/vendor/github.com/moby/moby/client/service_update.go +++ b/vendor/github.com/moby/moby/client/service_update.go @@ -101,7 +101,7 @@ func (cli *Client) ServiceUpdate(ctx context.Context, serviceID string, options if options.EncodedRegistryAuth != "" { headers.Set(registry.AuthHeader, options.EncodedRegistryAuth) } - resp, err := cli.post(ctx, "/services/"+serviceID+"/update", query, options.Spec, headers) + resp, err := cli.post(ctx, "/services/"+serviceID+"/update", query, headers, options.Spec) defer ensureReaderClosed(resp) if err != nil { return ServiceUpdateResult{}, err diff --git a/vendor/github.com/moby/moby/client/swarm_init.go b/vendor/github.com/moby/moby/client/swarm_init.go index caad560856b5..87be2ce10fb9 100644 --- a/vendor/github.com/moby/moby/client/swarm_init.go +++ b/vendor/github.com/moby/moby/client/swarm_init.go @@ -29,7 +29,7 @@ type SwarmInitResult struct { // SwarmInit initializes the swarm. func (cli *Client) SwarmInit(ctx context.Context, options SwarmInitOptions) (SwarmInitResult, error) { - req := swarm.InitRequest{ + resp, err := cli.post(ctx, "/swarm/init", nil, nil, swarm.InitRequest{ ListenAddr: options.ListenAddr, AdvertiseAddr: options.AdvertiseAddr, DataPathAddr: options.DataPathAddr, @@ -40,9 +40,7 @@ func (cli *Client) SwarmInit(ctx context.Context, options SwarmInitOptions) (Swa Availability: options.Availability, DefaultAddrPool: options.DefaultAddrPool, SubnetSize: options.SubnetSize, - } - - resp, err := cli.post(ctx, "/swarm/init", nil, req, nil) + }) defer ensureReaderClosed(resp) if err != nil { return SwarmInitResult{}, err diff --git a/vendor/github.com/moby/moby/client/swarm_join.go b/vendor/github.com/moby/moby/client/swarm_join.go index 66a7544821ed..9d33ef6e12be 100644 --- a/vendor/github.com/moby/moby/client/swarm_join.go +++ b/vendor/github.com/moby/moby/client/swarm_join.go @@ -23,16 +23,14 @@ type SwarmJoinResult struct { // SwarmJoin joins the swarm. func (cli *Client) SwarmJoin(ctx context.Context, options SwarmJoinOptions) (SwarmJoinResult, error) { - req := swarm.JoinRequest{ + resp, err := cli.post(ctx, "/swarm/join", nil, nil, swarm.JoinRequest{ ListenAddr: options.ListenAddr, AdvertiseAddr: options.AdvertiseAddr, DataPathAddr: options.DataPathAddr, RemoteAddrs: options.RemoteAddrs, JoinToken: options.JoinToken, Availability: options.Availability, - } - - resp, err := cli.post(ctx, "/swarm/join", nil, req, nil) + }) defer ensureReaderClosed(resp) return SwarmJoinResult{}, err } diff --git a/vendor/github.com/moby/moby/client/swarm_unlock.go b/vendor/github.com/moby/moby/client/swarm_unlock.go index 92335afb5467..a6aee22986c1 100644 --- a/vendor/github.com/moby/moby/client/swarm_unlock.go +++ b/vendor/github.com/moby/moby/client/swarm_unlock.go @@ -16,10 +16,9 @@ type SwarmUnlockResult struct{} // SwarmUnlock unlocks locked swarm. func (cli *Client) SwarmUnlock(ctx context.Context, options SwarmUnlockOptions) (SwarmUnlockResult, error) { - req := &swarm.UnlockRequest{ + resp, err := cli.post(ctx, "/swarm/unlock", nil, nil, swarm.UnlockRequest{ UnlockKey: options.Key, - } - resp, err := cli.post(ctx, "/swarm/unlock", nil, req, nil) + }) defer ensureReaderClosed(resp) return SwarmUnlockResult{}, err } diff --git a/vendor/github.com/moby/moby/client/swarm_update.go b/vendor/github.com/moby/moby/client/swarm_update.go index 81f62b2c0249..0e6257ad46ef 100644 --- a/vendor/github.com/moby/moby/client/swarm_update.go +++ b/vendor/github.com/moby/moby/client/swarm_update.go @@ -27,7 +27,7 @@ func (cli *Client) SwarmUpdate(ctx context.Context, options SwarmUpdateOptions) query.Set("rotateWorkerToken", strconv.FormatBool(options.RotateWorkerToken)) query.Set("rotateManagerToken", strconv.FormatBool(options.RotateManagerToken)) query.Set("rotateManagerUnlockKey", strconv.FormatBool(options.RotateManagerUnlockKey)) - resp, err := cli.post(ctx, "/swarm/update", query, options.Spec, nil) + resp, err := cli.post(ctx, "/swarm/update", query, nil, options.Spec) defer ensureReaderClosed(resp) return SwarmUpdateResult{}, err } diff --git a/vendor/github.com/moby/moby/client/utils.go b/vendor/github.com/moby/moby/client/utils.go index 1c0d09dfa295..ceecafa55c4c 100644 --- a/vendor/github.com/moby/moby/client/utils.go +++ b/vendor/github.com/moby/moby/client/utils.go @@ -33,6 +33,14 @@ func trimID(objType, id string) (string, error) { return id, nil } +// valueOrZero returns the value pointed to by p, or the zero value of T if p is nil. +func valueOrZero[T any](p *T) (zero T) { + if p != nil { + return *p + } + return zero +} + // parseAPIVersion checks v to be a well-formed (".") // API version. It returns an error if the value is empty or does not // have the correct format, but does not validate if the API version is diff --git a/vendor/github.com/moby/moby/client/volume_create.go b/vendor/github.com/moby/moby/client/volume_create.go index 674e06335727..5212f09a5fb0 100644 --- a/vendor/github.com/moby/moby/client/volume_create.go +++ b/vendor/github.com/moby/moby/client/volume_create.go @@ -23,14 +23,13 @@ type VolumeCreateResult struct { // VolumeCreate creates a volume in the docker host. func (cli *Client) VolumeCreate(ctx context.Context, options VolumeCreateOptions) (VolumeCreateResult, error) { - createRequest := volume.CreateRequest{ + resp, err := cli.post(ctx, "/volumes/create", nil, nil, volume.CreateRequest{ Name: options.Name, Driver: options.Driver, DriverOpts: options.DriverOpts, Labels: options.Labels, ClusterVolumeSpec: options.ClusterVolumeSpec, - } - resp, err := cli.post(ctx, "/volumes/create", nil, createRequest, nil) + }) defer ensureReaderClosed(resp) if err != nil { return VolumeCreateResult{}, err diff --git a/vendor/github.com/moby/moby/client/volume_update.go b/vendor/github.com/moby/moby/client/volume_update.go index 5aa2a0aa170b..3810267ef53c 100644 --- a/vendor/github.com/moby/moby/client/volume_update.go +++ b/vendor/github.com/moby/moby/client/volume_update.go @@ -31,7 +31,7 @@ func (cli *Client) VolumeUpdate(ctx context.Context, volumeID string, options Vo query := url.Values{} query.Set("version", options.Version.String()) - resp, err := cli.put(ctx, "/volumes/"+volumeID, query, options, nil) + resp, err := cli.put(ctx, "/volumes/"+volumeID, query, nil, options) defer ensureReaderClosed(resp) if err != nil { return VolumeUpdateResult{}, err diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/.golangci.yml b/vendor/github.com/santhosh-tekuri/jsonschema/v6/.golangci.yml index b3cd1749a3a5..94a3eca377b0 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/.golangci.yml +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/.golangci.yml @@ -3,3 +3,4 @@ linters: - nakedret - errname - godot + - misspell diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/README.md b/vendor/github.com/santhosh-tekuri/jsonschema/v6/README.md index 0831d7f58070..1243b66c5a04 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/README.md +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/README.md @@ -1,4 +1,4 @@ -# jsonschema v6.0.0 +# jsonschema v6.0.2 [![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0) [![GoDoc](https://godoc.org/github.com/santhosh-tekuri/jsonschema?status.svg)](https://pkg.go.dev/github.com/santhosh-tekuri/jsonschema/v6) @@ -56,10 +56,12 @@ see [godoc](https://pkg.go.dev/github.com/santhosh-tekuri/jsonschema/v6) for exa - enable via flag for draft <= 7 - [x] mixed dialect support -## CLI +## CLI v0.7.0 to install: `go install github.com/santhosh-tekuri/jsonschema/cmd/jv@latest` +Note that the cli is versioned independently. you can see it in git tags `cmd/jv/v0.7.0` + ``` Usage: jv [OPTIONS] SCHEMA [INSTANCE...] @@ -75,7 +77,7 @@ Options: -v, --version Print build information ``` -- [x] exit code `1` for validation erros, `2` for usage errors +- [x] exit code `1` for validation errors, `2` for usage errors - [x] validate both schema and multiple instances - [x] support both json and yaml files - [x] support standard input, use `-` diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/format.go b/vendor/github.com/santhosh-tekuri/jsonschema/v6/format.go index b78b22e2a5b5..0d7f59032792 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/format.go +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/format.go @@ -318,7 +318,7 @@ func validateEmail(v any) error { return LocalizableError("local part more than 64 characters long") } - if len(local) > 1 && strings.HasPrefix(local, `"`) && strings.HasPrefix(local, `"`) { + if len(local) > 1 && strings.HasPrefix(local, `"`) && strings.HasSuffix(local, `"`) { // quoted local := local[1 : len(local)-1] if strings.IndexByte(local, '\\') != -1 || strings.IndexByte(local, '"') != -1 { diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/go.work b/vendor/github.com/santhosh-tekuri/jsonschema/v6/go.work index 13df855d522b..e7f4d93de454 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/go.work +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/go.work @@ -5,4 +5,4 @@ use ( ./cmd/jv ) -replace github.com/santhosh-tekuri/jsonschema/v6 v6.0.0 => ./ +// replace github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 => ./ diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/go.work.sum b/vendor/github.com/santhosh-tekuri/jsonschema/v6/go.work.sum new file mode 100644 index 000000000000..c268feb511f0 --- /dev/null +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/go.work.sum @@ -0,0 +1,4 @@ +github.com/santhosh-tekuri/jsonschema/v6 v6.0.2/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU= +golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= +golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU= diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/kind/kind.go b/vendor/github.com/santhosh-tekuri/jsonschema/v6/kind/kind.go index 7da112ac89e6..62efa755b099 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/kind/kind.go +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/kind/kind.go @@ -57,7 +57,7 @@ func (*Not) KeywordPath() []string { } func (*Not) LocalizedString(p *message.Printer) string { - return p.Sprintf("not failed") + return p.Sprintf("'not' failed") } // -- @@ -69,7 +69,7 @@ func (*AllOf) KeywordPath() []string { } func (*AllOf) LocalizedString(p *message.Printer) string { - return p.Sprintf("allOf failed") + return p.Sprintf("'allOf' failed") } // -- @@ -81,7 +81,7 @@ func (*AnyOf) KeywordPath() []string { } func (*AnyOf) LocalizedString(p *message.Printer) string { - return p.Sprintf("anyOf failed") + return p.Sprintf("'anyOf' failed") } // -- @@ -98,9 +98,9 @@ func (*OneOf) KeywordPath() []string { func (k *OneOf) LocalizedString(p *message.Printer) string { if len(k.Subschemas) == 0 { - return p.Sprintf("oneOf failed, none matched") + return p.Sprintf("'oneOf' failed, none matched") } - return p.Sprintf("oneOf failed, subschemas %d, %d matched", k.Subschemas[0], k.Subschemas[1]) + return p.Sprintf("'oneOf' failed, subschemas %d, %d matched", k.Subschemas[0], k.Subschemas[1]) } //-- @@ -179,7 +179,7 @@ loop: } return p.Sprintf("value must be one of %s", strings.Join(want, ", ")) } - return p.Sprintf("enum failed") + return p.Sprintf("'enum' failed") } // -- @@ -196,7 +196,7 @@ func (*Const) KeywordPath() []string { func (k *Const) LocalizedString(p *message.Printer) string { switch want := k.Want.(type) { case []any, map[string]any: - return p.Sprintf("const failed") + return p.Sprintf("'const' failed") default: return p.Sprintf("value must be %s", display(want)) } @@ -511,7 +511,7 @@ func (*ContentMediaType) KeywordPath() []string { } func (k *ContentMediaType) LocalizedString(p *message.Printer) string { - return p.Sprintf("value if not of mediatype %s: %v", quote(k.Want), k.Err) + return p.Sprintf("value is not of mediatype %s: %v", quote(k.Want), k.Err) } // -- @@ -523,7 +523,7 @@ func (*ContentSchema) KeywordPath() []string { } func (*ContentSchema) LocalizedString(p *message.Printer) string { - return p.Sprintf("contentSchema failed") + return p.Sprintf("'contentSchema' failed") } // -- diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/objcompiler.go b/vendor/github.com/santhosh-tekuri/jsonschema/v6/objcompiler.go index f1494b13a863..d47efa89b278 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/objcompiler.go +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/objcompiler.go @@ -355,9 +355,13 @@ func (c *objCompiler) enqueueRef(pname string) (*Schema, error) { if ref == nil { return nil, nil } + return c.enqueueRefVal(*ref) +} + +func (c *objCompiler) enqueueRefVal(ref string) (*Schema, error) { baseURL := c.res.id // baseURL := c.r.baseURL(c.up.ptr) - uf, err := baseURL.join(*ref) + uf, err := baseURL.join(ref) if err != nil { return nil, err } diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/output.go b/vendor/github.com/santhosh-tekuri/jsonschema/v6/output.go index 4995d7b8bd94..69d3f26de5d0 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/output.go +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/output.go @@ -137,6 +137,10 @@ type OutputError struct { p *message.Printer } +func (k OutputError) String() string { + return k.Kind.LocalizedString(k.p) +} + func (k OutputError) MarshalJSON() ([]byte, error) { return json.Marshal(k.Kind.LocalizedString(k.p)) } diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/root.go b/vendor/github.com/santhosh-tekuri/jsonschema/v6/root.go index 860690102dd2..a8b819bab0cb 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/root.go +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/root.go @@ -53,7 +53,7 @@ func (r *root) resolveFragment(frag fragment) (urlPtr, error) { return r.resolveFragmentIn(frag, r.rootResource()) } -// resovles urlFrag to urlPtr from root. +// resolves urlFrag to urlPtr from root. // returns nil if it is external. func (r *root) resolve(uf urlFrag) (*urlPtr, error) { var res *resource diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/roots.go b/vendor/github.com/santhosh-tekuri/jsonschema/v6/roots.go index b9b79baa3a0f..a8d0ef0ce2b4 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/roots.go +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/roots.go @@ -79,7 +79,8 @@ func (rr *roots) collectResources(r *root, sch any, base url, schPtr jsonPointer } func (rr *roots) _collectResources(r *root, sch any, base url, schPtr jsonPointer, fallback dialect) error { - if _, ok := sch.(bool); ok { + obj, ok := sch.(map[string]any) + if !ok { if schPtr.isEmpty() { // root resource res := newResource(schPtr, base) @@ -88,10 +89,6 @@ func (rr *roots) _collectResources(r *root, sch any, base url, schPtr jsonPointe } return nil } - obj, ok := sch.(map[string]any) - if !ok { - return nil - } hasSchema := false if sch, ok := obj["$schema"]; ok { diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/schema.go b/vendor/github.com/santhosh-tekuri/jsonschema/v6/schema.go index a970311fb3d1..ab2474facd2e 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/schema.go +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/schema.go @@ -1,12 +1,29 @@ +/* +Package jsonschema provides json-schema compilation and validation. + +The schema is compiled against the version specified in "$schema" property. +If "$schema" property is missing, it uses latest draft which currently implemented +by this library. + +You can force to use specific draft, when "$schema" is missing, as follows: + + compiler := jsonschema.NewCompiler() + compiler.DefaultDraft(jsonschema.Draft4) + +This package supports loading json-schema from filePath and fileURL. + +see examples for usage. +*/ package jsonschema import ( "encoding/json" "fmt" + "math" "math/big" ) -// Schema is the regpresentation of a compiled +// Schema is the representation of a compiled // jsonschema. type Schema struct { up urlPtr @@ -110,12 +127,22 @@ const ( ) func typeOf(v any) jsonType { - switch v.(type) { + switch v := v.(type) { case nil: return nullType case bool: return booleanType - case json.Number, float32, float64, int, int8, int16, int32, int64, uint, uint8, uint16, uint32, uint64: + case float64: + if math.IsNaN(v) || math.IsInf(v, 0) { + return invalidType + } + return numberType + case float32: + if math.IsNaN(float64(v)) || math.IsInf(float64(v), 0) { + return invalidType + } + return numberType + case json.Number, int, int8, int16, int32, int64, uint, uint8, uint16, uint32, uint64: return numberType case string: return stringType @@ -177,11 +204,11 @@ func newTypes(v any) *Types { var types Types switch v := v.(type) { case string: - types.add(typeFromString(v)) + types.Add(v) case []any: for _, item := range v { if s, ok := item.(string); ok { - types.add(typeFromString(s)) + types.Add(s) } } } @@ -195,6 +222,12 @@ func (tt Types) IsEmpty() bool { return tt == 0 } +// Add specified json type. If typ is +// not valid json type it is ignored. +func (tt *Types) Add(typ string) { + tt.add(typeFromString(typ)) +} + func (tt *Types) add(t jsonType) { *tt = Types(int(*tt) | int(t)) } diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/util.go b/vendor/github.com/santhosh-tekuri/jsonschema/v6/util.go index c6f8e77526c9..8cd32aae7648 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/util.go +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/util.go @@ -320,6 +320,9 @@ func equals(v1, v2 any) (bool, ErrorKind) { v2, ok := v2.(string) return ok && v1 == v2, nil case json.Number, float32, float64, int, int8, int16, int32, int64, uint, uint8, uint16, uint32, uint64: + if typeOf(v2) != numberType { + return false, nil + } num1, ok1 := new(big.Rat).SetString(fmt.Sprint(v1)) num2, ok2 := new(big.Rat).SetString(fmt.Sprint(v2)) return ok1 && ok2 && num1.Cmp(num2) == 0, nil diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/validator.go b/vendor/github.com/santhosh-tekuri/jsonschema/v6/validator.go index e2ace37a9fec..53a4c730b83e 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/validator.go +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/validator.go @@ -293,6 +293,7 @@ func (vd *validator) objValidate(obj map[string]any) { } if err := sch.validate(pname, vd.regexpEngine, meta, resources, vd.assertVocabs, vd.vocabularies); err != nil { verr := err.(*ValidationError) + verr.InstanceLocation = vd.vloc verr.SchemaURL = s.PropertyNames.Location verr.ErrorKind = &kind.PropertyNames{Property: pname} vd.addErr(verr) @@ -375,7 +376,7 @@ func (vd *validator) arrValidate(arr []any) { } case *Schema: for i, item := range arr[evaluated:] { - vd.addErr(vd.validateVal(additional, item, strconv.Itoa(i))) + vd.addErr(vd.validateVal(additional, item, strconv.Itoa(evaluated+i))) } } } @@ -390,7 +391,7 @@ func (vd *validator) arrValidate(arr []any) { // items2020 -- if s.Items2020 != nil { for i, item := range arr[evaluated:] { - vd.addErr(vd.validateVal(s.Items2020, item, strconv.Itoa(i))) + vd.addErr(vd.validateVal(s.Items2020, item, strconv.Itoa(evaluated+i))) } } } @@ -503,6 +504,7 @@ func (vd *validator) strValidate(str string) { } if err = sch.validate(*deserialized, vd.regexpEngine, meta, resources, vd.assertVocabs, vd.vocabularies); err != nil { verr := err.(*ValidationError) + verr.InstanceLocation = vd.vloc verr.SchemaURL = s.Location verr.ErrorKind = &kind.ContentSchema{} vd.addErr(verr) diff --git a/vendor/github.com/santhosh-tekuri/jsonschema/v6/vocab.go b/vendor/github.com/santhosh-tekuri/jsonschema/v6/vocab.go index 18ace91e8b12..eaed8c95feab 100644 --- a/vendor/github.com/santhosh-tekuri/jsonschema/v6/vocab.go +++ b/vendor/github.com/santhosh-tekuri/jsonschema/v6/vocab.go @@ -14,6 +14,10 @@ func (ctx *CompilerContext) Enqueue(schPath []string) *Schema { return ctx.c.enqueuePtr(ptr) } +func (ctx *CompilerContext) EnqueueRef(ref string) (*Schema, error) { + return ctx.c.enqueueRefVal(ref) +} + // Vocabulary defines a set of keywords, their syntax and // their semantics. type Vocabulary struct { @@ -49,6 +53,11 @@ type ValidatorContext struct { vd *validator } +// ValueLocation returns location of value as jsonpath token array. +func (ctx *ValidatorContext) ValueLocation() []string { + return ctx.vd.vloc +} + // Validate validates v with sch. vpath gives path of v from current context value. func (ctx *ValidatorContext) Validate(sch *Schema, v any, vpath []string) error { switch len(vpath) { diff --git a/vendor/golang.org/x/crypto/ssh/certs.go b/vendor/golang.org/x/crypto/ssh/certs.go index fa848f51a5f9..a3b802e4b8bf 100644 --- a/vendor/golang.org/x/crypto/ssh/certs.go +++ b/vendor/golang.org/x/crypto/ssh/certs.go @@ -10,6 +10,7 @@ import ( "fmt" "io" "net" + "slices" "sort" "time" ) @@ -305,8 +306,11 @@ const sourceAddressCriticalOption = "source-address" // minimally, the IsAuthority callback should be set. type CertChecker struct { // SupportedCriticalOptions lists the CriticalOptions that the - // server application layer understands. These are only used - // for user certificates. + // application layer understands. A certificate carrying a critical + // option that is not listed here is rejected. + // CertChecker.Authenticate additionally accepts the source-address + // option, which the server enforces on the Permissions that + // Authenticate returns. SupportedCriticalOptions []string // IsUserAuthority should return true if the key is recognized as an @@ -369,8 +373,9 @@ func (c *CertChecker) CheckHostKey(addr string, remote net.Addr, key PublicKey) return c.CheckCert(hostname, cert) } -// Authenticate checks a user certificate. Authenticate can be used as -// a value for ServerConfig.PublicKeyCallback. +// Authenticate checks a user certificate. Authenticate can be used as a value +// for ServerConfig.PublicKeyCallback. The source-address critical option is +// allowed, as it will be enforced by the server. func (c *CertChecker) Authenticate(conn ConnMetadata, pubKey PublicKey) (*Permissions, error) { cert, ok := pubKey.(*Certificate) if !ok { @@ -389,8 +394,11 @@ func (c *CertChecker) Authenticate(conn ConnMetadata, pubKey PublicKey) (*Permis if !c.IsUserAuthority(cert.SignatureKey) { return nil, fmt.Errorf("ssh: certificate signed by unrecognized authority") } - - if err := c.CheckCert(conn.User(), cert); err != nil { + // The source-address critical option is enforced by serverAuthenticate, + // so it is supported regardless of SupportedCriticalOptions + cc := *c + cc.SupportedCriticalOptions = append(slices.Clip(cc.SupportedCriticalOptions), sourceAddressCriticalOption) + if err := cc.CheckCert(conn.User(), cert); err != nil { return nil, err } @@ -398,27 +406,15 @@ func (c *CertChecker) Authenticate(conn ConnMetadata, pubKey PublicKey) (*Permis } // CheckCert checks CriticalOptions, ValidPrincipals, revocation, timestamp and -// the signature of the certificate. +// the signature of the certificate. Critical options that are not listed in +// SupportedCriticalOptions are rejected. func (c *CertChecker) CheckCert(principal string, cert *Certificate) error { if c.IsRevoked != nil && c.IsRevoked(cert) { return fmt.Errorf("ssh: certificate serial %d revoked", cert.Serial) } for opt := range cert.CriticalOptions { - // sourceAddressCriticalOption will be enforced by - // serverAuthenticate - if opt == sourceAddressCriticalOption { - continue - } - - found := false - for _, supp := range c.SupportedCriticalOptions { - if supp == opt { - found = true - break - } - } - if !found { + if !slices.Contains(c.SupportedCriticalOptions, opt) { return fmt.Errorf("ssh: unsupported critical option %q in certificate", opt) } } diff --git a/vendor/golang.org/x/crypto/ssh/channel.go b/vendor/golang.org/x/crypto/ssh/channel.go index ba3279e91d68..d6010fd77b99 100644 --- a/vendor/golang.org/x/crypto/ssh/channel.go +++ b/vendor/golang.org/x/crypto/ssh/channel.go @@ -173,6 +173,12 @@ type channel struct { // (for outbound channels) or received (for inbound channels). decided bool + // established is set to true once the channel is open and may carry normal + // channel traffic: for an outbound channel when the peer's open + // confirmation is received, for an inbound channel when the local side + // accepts it. It is set and read from different goroutines. + established atomic.Bool + // direction contains either channelOutbound, for channels created // locally, or channelInbound, for channels created by the peer. direction channelDirection @@ -434,10 +440,20 @@ func (ch *channel) responseMessageReceived() error { return errors.New("ssh: duplicate response received for channel") } ch.decided = true + ch.established.Store(true) return nil } func (ch *channel) handlePacket(packet []byte) error { + // Only the open response is expected before the channel is established. + if !ch.established.Load() { + switch packet[0] { + case msgChannelOpenConfirm, msgChannelOpenFailure: + default: + return nil + } + } + switch packet[0] { case msgChannelData, msgChannelExtendedData: return ch.handleData(packet) @@ -503,7 +519,8 @@ func (ch *channel) handlePacket(packet []byte) error { default: } default: - ch.msg <- msg + // No other message type is expected on an established channel. + return fmt.Errorf("ssh: unexpected message type %d on channel %d", packet[0], ch.localId) } return nil } @@ -554,6 +571,7 @@ func (ch *channel) Accept() (Channel, <-chan *Request, error) { MaxPacketSize: ch.maxIncomingPayload, } ch.decided = true + ch.established.Store(true) if err := ch.sendMessage(confirm); err != nil { return nil, nil, err } diff --git a/vendor/golang.org/x/crypto/ssh/transport.go b/vendor/golang.org/x/crypto/ssh/transport.go index fa3dd6a4299b..540865dfc823 100644 --- a/vendor/golang.org/x/crypto/ssh/transport.go +++ b/vendor/golang.org/x/crypto/ssh/transport.go @@ -331,13 +331,19 @@ func exchangeVersions(rw io.ReadWriter, versionLine []byte) (them []byte, err er // chars const maxVersionStringBytes = 255 +// maxPreVersionLines is the maximum number of lines sent by the peer +// before the version string. Each of these lines is limited to a maximum +// of maxVersionStringBytes chars. Lines sent before the version string +// are silently ignored. +const maxPreVersionLines = 1024 + // Read version string as specified by RFC 4253, section 4.2. func readVersion(r io.Reader) ([]byte, error) { versionString := make([]byte, 0, 64) var ok bool var buf [1]byte - for length := 0; length < maxVersionStringBytes; length++ { + for lines := 0; len(versionString) < maxVersionStringBytes && lines < maxPreVersionLines; { _, err := io.ReadFull(r, buf[:]) if err != nil { return nil, err @@ -347,9 +353,9 @@ func readVersion(r io.Reader) ([]byte, error) { if buf[0] == '\n' { if !bytes.HasPrefix(versionString, []byte("SSH-")) { // RFC 4253 says we need to ignore all version string lines - // except the one containing the SSH version (provided that - // all the lines do not exceed 255 bytes in total). + // except the one containing the SSH version. versionString = versionString[:0] + lines++ continue } ok = true diff --git a/vendor/modules.txt b/vendor/modules.txt index b17bfbeef39b..a17c1a40367e 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -299,7 +299,7 @@ github.com/digitorus/timestamp # github.com/distribution/reference v0.6.0 ## explicit; go 1.20 github.com/distribution/reference -# github.com/docker/cli v29.7.2+incompatible +# github.com/docker/cli v29.8.0+incompatible ## explicit github.com/docker/cli/cli github.com/docker/cli/cli-plugins/metadata @@ -340,11 +340,11 @@ github.com/docker/cli-docs-tool/annotation # github.com/docker/docker v28.5.2+incompatible ## explicit github.com/docker/docker/pkg/namesgenerator -# github.com/docker/docker-credential-helpers v0.9.8 +# github.com/docker/docker-credential-helpers v0.9.9 ## explicit; go 1.21 github.com/docker/docker-credential-helpers/client github.com/docker/docker-credential-helpers/credentials -# github.com/docker/go-connections v0.7.0 +# github.com/docker/go-connections v0.8.1 ## explicit; go 1.23 github.com/docker/go-connections/nat github.com/docker/go-connections/sockets @@ -355,8 +355,8 @@ github.com/docker/go-units # github.com/felixge/httpsnoop v1.1.0 ## explicit; go 1.25 github.com/felixge/httpsnoop -# github.com/fvbommel/sortorder v1.1.0 -## explicit; go 1.13 +# github.com/fvbommel/sortorder v1.2.0 +## explicit; go 1.21 github.com/fvbommel/sortorder # github.com/fxamacker/cbor/v2 v2.9.0 ## explicit; go 1.20 @@ -481,8 +481,8 @@ github.com/goccy/go-json/internal/encoder/vm_color_indent github.com/goccy/go-json/internal/encoder/vm_indent github.com/goccy/go-json/internal/errors github.com/goccy/go-json/internal/runtime -# github.com/gofrs/flock v0.13.0 -## explicit; go 1.24.0 +# github.com/gofrs/flock v0.13.1 +## explicit; go 1.25.0 github.com/gofrs/flock # github.com/golang/snappy v1.0.0 ## explicit @@ -632,8 +632,8 @@ github.com/lestrrat-go/jwx/v3/transform # github.com/lestrrat-go/option/v2 v2.0.0 ## explicit; go 1.23 github.com/lestrrat-go/option/v2 -# github.com/mattn/go-runewidth v0.0.23 -## explicit; go 1.20 +# github.com/mattn/go-runewidth v0.0.29 +## explicit; go 1.23 github.com/mattn/go-runewidth # github.com/mattn/go-shellwords v1.0.12 ## explicit; go 1.13 @@ -755,7 +755,7 @@ github.com/moby/go-archive/compression # github.com/moby/locker v1.0.1 ## explicit; go 1.13 github.com/moby/locker -# github.com/moby/moby/api v1.55.0 +# github.com/moby/moby/api v1.56.0 ## explicit; go 1.24 github.com/moby/moby/api/pkg/authconfig github.com/moby/moby/api/pkg/stdcopy @@ -776,7 +776,7 @@ github.com/moby/moby/api/types/storage github.com/moby/moby/api/types/swarm github.com/moby/moby/api/types/system github.com/moby/moby/api/types/volume -# github.com/moby/moby/client v0.5.0 +# github.com/moby/moby/client v0.6.0 ## explicit; go 1.24 github.com/moby/moby/client github.com/moby/moby/client/internal @@ -945,7 +945,7 @@ github.com/rcrowley/go-metrics # github.com/russross/blackfriday/v2 v2.1.0 ## explicit github.com/russross/blackfriday/v2 -# github.com/santhosh-tekuri/jsonschema/v6 v6.0.1 +# github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 ## explicit; go 1.21 github.com/santhosh-tekuri/jsonschema/v6 github.com/santhosh-tekuri/jsonschema/v6/kind @@ -1273,8 +1273,8 @@ go.yaml.in/yaml/v3 ## explicit; go 1.18 go.yaml.in/yaml/v4 go.yaml.in/yaml/v4/internal/libyaml -# golang.org/x/crypto v0.55.0 -## explicit; go 1.25.0 +# golang.org/x/crypto v0.56.0 +## explicit; go 1.26.0 golang.org/x/crypto/argon2 golang.org/x/crypto/bcrypt golang.org/x/crypto/blake2b