docker.rs

   1use std::{collections::HashMap, path::PathBuf};
   2
   3use async_trait::async_trait;
   4use serde::{Deserialize, Deserializer, Serialize, de};
   5use util::command::Command;
   6
   7use crate::{
   8    command_json::evaluate_json_command, devcontainer_api::DevContainerError,
   9    devcontainer_json::MountDefinition,
  10};
  11
  12#[derive(Debug, Deserialize, Serialize, Eq, PartialEq)]
  13#[serde(rename_all = "PascalCase")]
  14pub(crate) struct DockerPs {
  15    #[serde(alias = "ID")]
  16    pub(crate) id: String,
  17}
  18
  19#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq)]
  20#[serde(rename_all = "PascalCase")]
  21pub(crate) struct DockerState {
  22    pub(crate) running: bool,
  23}
  24
  25#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq)]
  26#[serde(rename_all = "PascalCase")]
  27pub(crate) struct DockerInspect {
  28    pub(crate) id: String,
  29    pub(crate) config: DockerInspectConfig,
  30    pub(crate) mounts: Option<Vec<DockerInspectMount>>,
  31    pub(crate) state: Option<DockerState>,
  32}
  33
  34#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
  35pub(crate) struct DockerConfigLabels {
  36    #[serde(
  37        default,
  38        rename = "devcontainer.metadata",
  39        deserialize_with = "deserialize_metadata"
  40    )]
  41    pub(crate) metadata: Option<Vec<HashMap<String, serde_json_lenient::Value>>>,
  42}
  43
  44#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq)]
  45#[serde(rename_all = "PascalCase")]
  46pub(crate) struct DockerInspectConfig {
  47    #[serde(default, deserialize_with = "deserialize_nullable_labels")]
  48    pub(crate) labels: DockerConfigLabels,
  49    #[serde(rename = "User")]
  50    pub(crate) image_user: Option<String>,
  51    #[serde(default)]
  52    pub(crate) env: Vec<String>,
  53}
  54
  55impl DockerInspectConfig {
  56    pub(crate) fn env_as_map(&self) -> Result<HashMap<String, String>, DevContainerError> {
  57        let mut map = HashMap::new();
  58        for env_var in &self.env {
  59            let Some((key, value)) = env_var.split_once('=') else {
  60                log::error!("Unable to parse {env_var} into an environment key-value");
  61                return Err(DevContainerError::DevContainerParseFailed);
  62            };
  63            map.insert(key.to_string(), value.to_string());
  64        }
  65        Ok(map)
  66    }
  67}
  68
  69#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq)]
  70#[serde(rename_all = "PascalCase")]
  71pub(crate) struct DockerInspectMount {
  72    pub(crate) source: String,
  73    pub(crate) destination: String,
  74}
  75
  76#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
  77pub(crate) struct DockerComposeServiceBuild {
  78    #[serde(skip_serializing_if = "Option::is_none")]
  79    pub(crate) context: Option<String>,
  80    #[serde(skip_serializing_if = "Option::is_none")]
  81    pub(crate) dockerfile: Option<String>,
  82    #[serde(skip_serializing_if = "Option::is_none")]
  83    pub(crate) target: Option<String>,
  84    #[serde(skip_serializing_if = "Option::is_none")]
  85    pub(crate) args: Option<HashMap<String, String>>,
  86    #[serde(skip_serializing_if = "Option::is_none")]
  87    pub(crate) additional_contexts: Option<HashMap<String, String>>,
  88}
  89
  90#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
  91pub(crate) struct DockerComposeServicePort {
  92    #[serde(deserialize_with = "deserialize_string_or_int")]
  93    pub(crate) target: String,
  94    #[serde(deserialize_with = "deserialize_string_or_int")]
  95    pub(crate) published: String,
  96    #[serde(skip_serializing_if = "Option::is_none")]
  97    pub(crate) mode: Option<String>,
  98    #[serde(skip_serializing_if = "Option::is_none")]
  99    pub(crate) protocol: Option<String>,
 100    #[serde(skip_serializing_if = "Option::is_none")]
 101    pub(crate) host_ip: Option<String>,
 102    #[serde(skip_serializing_if = "Option::is_none")]
 103    pub(crate) app_protocol: Option<String>,
 104    #[serde(skip_serializing_if = "Option::is_none")]
 105    pub(crate) name: Option<String>,
 106}
 107
 108fn deserialize_string_or_int<'de, D>(deserializer: D) -> Result<String, D::Error>
 109where
 110    D: serde::Deserializer<'de>,
 111{
 112    use serde::Deserialize;
 113
 114    #[derive(Deserialize)]
 115    #[serde(untagged)]
 116    enum StringOrInt {
 117        String(String),
 118        Int(u32),
 119    }
 120
 121    match StringOrInt::deserialize(deserializer)? {
 122        StringOrInt::String(s) => Ok(s),
 123        StringOrInt::Int(b) => Ok(b.to_string()),
 124    }
 125}
 126
 127#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
 128pub(crate) struct DockerComposeService {
 129    pub(crate) image: Option<String>,
 130    #[serde(skip_serializing_if = "Option::is_none")]
 131    pub(crate) entrypoint: Option<Vec<String>>,
 132    #[serde(skip_serializing_if = "Option::is_none")]
 133    pub(crate) cap_add: Option<Vec<String>>,
 134    #[serde(skip_serializing_if = "Option::is_none")]
 135    pub(crate) security_opt: Option<Vec<String>>,
 136    #[serde(
 137        skip_serializing_if = "Option::is_none",
 138        default,
 139        deserialize_with = "deserialize_labels"
 140    )]
 141    pub(crate) labels: Option<HashMap<String, String>>,
 142    #[serde(skip_serializing_if = "Option::is_none")]
 143    pub(crate) build: Option<DockerComposeServiceBuild>,
 144    #[serde(skip_serializing_if = "Option::is_none")]
 145    pub(crate) privileged: Option<bool>,
 146    #[serde(default, skip_serializing_if = "Vec::is_empty")]
 147    pub(crate) volumes: Vec<MountDefinition>,
 148    #[serde(skip_serializing_if = "Option::is_none")]
 149    pub(crate) env_file: Option<Vec<String>>,
 150    #[serde(default, skip_serializing_if = "Vec::is_empty")]
 151    pub(crate) ports: Vec<DockerComposeServicePort>,
 152    #[serde(skip_serializing_if = "Option::is_none")]
 153    pub(crate) network_mode: Option<String>,
 154    #[serde(
 155        default,
 156        skip_serializing_if = "Vec::is_empty",
 157        deserialize_with = "deserialize_nullable_vec"
 158    )]
 159    pub(crate) command: Vec<String>,
 160}
 161
 162#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
 163pub(crate) struct DockerComposeVolume {
 164    pub(crate) name: String,
 165}
 166
 167#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
 168pub(crate) struct DockerComposeConfig {
 169    #[serde(skip_serializing_if = "Option::is_none")]
 170    pub(crate) name: Option<String>,
 171    pub(crate) services: HashMap<String, DockerComposeService>,
 172    #[serde(default)]
 173    pub(crate) volumes: HashMap<String, DockerComposeVolume>,
 174}
 175
 176pub(crate) struct Docker {
 177    docker_cli: String,
 178    has_buildx: bool,
 179}
 180
 181impl DockerInspect {
 182    pub(crate) fn is_running(&self) -> bool {
 183        self.state.as_ref().map_or(false, |s| s.running)
 184    }
 185}
 186
 187impl Docker {
 188    pub(crate) async fn new(docker_cli: &str) -> Self {
 189        let has_buildx = if docker_cli == "podman" {
 190            false
 191        } else {
 192            let output = Command::new(docker_cli)
 193                .args(["buildx", "version"])
 194                .output()
 195                .await;
 196            output.map(|o| o.status.success()).unwrap_or(false)
 197        };
 198        if !has_buildx && docker_cli != "podman" {
 199            log::info!(
 200                "docker buildx not found; dev container builds will use the scratch-image fallback"
 201            );
 202        }
 203        Self {
 204            docker_cli: docker_cli.to_string(),
 205            has_buildx,
 206        }
 207    }
 208
 209    fn is_podman(&self) -> bool {
 210        self.docker_cli == "podman"
 211    }
 212
 213    async fn pull_image(&self, image: &String) -> Result<(), DevContainerError> {
 214        let mut command = Command::new(&self.docker_cli);
 215        command.args(&["pull", "--", image]);
 216
 217        let output = command.output().await.map_err(|e| {
 218            log::error!("Error pulling image: {e}");
 219            DevContainerError::ResourceFetchFailed
 220        })?;
 221
 222        if !output.status.success() {
 223            let stderr = String::from_utf8_lossy(&output.stderr);
 224            log::error!("Non-success result from docker pull: {stderr}");
 225            return Err(DevContainerError::ResourceFetchFailed);
 226        }
 227        Ok(())
 228    }
 229
 230    fn create_docker_query_containers(&self, filters: Vec<String>) -> Command {
 231        let mut command = Command::new(&self.docker_cli);
 232        command.args(&["ps", "-a"]);
 233
 234        for filter in filters {
 235            command.arg("--filter");
 236            command.arg(filter);
 237        }
 238        command.arg("--format={{ json . }}");
 239        command
 240    }
 241
 242    fn create_docker_inspect(&self, id: &str) -> Command {
 243        let mut command = Command::new(&self.docker_cli);
 244        command.args(&["inspect", "--format={{json . }}", id]);
 245        command
 246    }
 247
 248    fn create_docker_compose_config_command(&self, config_files: &Vec<PathBuf>) -> Command {
 249        let mut command = Command::new(&self.docker_cli);
 250        command.arg("compose");
 251        for file_path in config_files {
 252            command.args(&["-f", &file_path.display().to_string()]);
 253        }
 254        command.args(&["config", "--format", "json"]);
 255        command
 256    }
 257}
 258
 259#[async_trait]
 260impl DockerClient for Docker {
 261    async fn inspect(&self, id: &String) -> Result<DockerInspect, DevContainerError> {
 262        // Try to pull the image, continue on failure; Image may be local only, id a reference to a running container
 263        self.pull_image(id).await.ok();
 264
 265        let command = self.create_docker_inspect(id);
 266
 267        let Some(docker_inspect): Option<DockerInspect> = evaluate_json_command(command).await?
 268        else {
 269            log::error!("Docker inspect produced no deserializable output");
 270            return Err(DevContainerError::CommandFailed(self.docker_cli.clone()));
 271        };
 272        Ok(docker_inspect)
 273    }
 274
 275    async fn get_docker_compose_config(
 276        &self,
 277        config_files: &Vec<PathBuf>,
 278    ) -> Result<Option<DockerComposeConfig>, DevContainerError> {
 279        let command = self.create_docker_compose_config_command(config_files);
 280        evaluate_json_command(command).await
 281    }
 282
 283    async fn docker_compose_build(
 284        &self,
 285        config_files: &Vec<PathBuf>,
 286        project_name: &str,
 287    ) -> Result<(), DevContainerError> {
 288        let mut command = Command::new(&self.docker_cli);
 289        if !self.is_podman() {
 290            command.env("DOCKER_BUILDKIT", "1");
 291        }
 292        command.args(&["compose", "--project-name", project_name]);
 293        for docker_compose_file in config_files {
 294            command.args(&["-f", &docker_compose_file.display().to_string()]);
 295        }
 296        command.arg("build");
 297
 298        let output = command.output().await.map_err(|e| {
 299            log::error!("Error running docker compose up: {e}");
 300            DevContainerError::CommandFailed(command.get_program().display().to_string())
 301        })?;
 302
 303        if !output.status.success() {
 304            let stderr = String::from_utf8_lossy(&output.stderr);
 305            log::error!("Non-success status from docker compose up: {}", stderr);
 306            return Err(DevContainerError::CommandFailed(
 307                command.get_program().display().to_string(),
 308            ));
 309        }
 310
 311        Ok(())
 312    }
 313    async fn run_docker_exec(
 314        &self,
 315        container_id: &str,
 316        remote_folder: &str,
 317        user: &str,
 318        env: &HashMap<String, String>,
 319        inner_command: Command,
 320    ) -> Result<(), DevContainerError> {
 321        let mut command = Command::new(&self.docker_cli);
 322
 323        command.args(&["exec", "-w", remote_folder, "-u", user]);
 324
 325        for (k, v) in env.iter() {
 326            command.arg("-e");
 327            let env_declaration = format!("{}={}", k, v);
 328            command.arg(&env_declaration);
 329        }
 330
 331        command.arg(container_id);
 332
 333        command.arg("sh");
 334
 335        let mut inner_program_script: Vec<String> =
 336            vec![inner_command.get_program().display().to_string()];
 337        let mut args: Vec<String> = inner_command
 338            .get_args()
 339            .map(|arg| arg.display().to_string())
 340            .collect();
 341        inner_program_script.append(&mut args);
 342        command.args(&["-c", &inner_program_script.join(" ")]);
 343
 344        let output = command.output().await.map_err(|e| {
 345            log::error!("Error running command {e} in container exec");
 346            DevContainerError::ContainerNotValid(container_id.to_string())
 347        })?;
 348        if !output.status.success() {
 349            let std_err = String::from_utf8_lossy(&output.stderr);
 350            log::error!("Command produced a non-successful output. StdErr: {std_err}");
 351        }
 352        let std_out = String::from_utf8_lossy(&output.stdout);
 353        log::debug!("Command output:\n {std_out}");
 354
 355        Ok(())
 356    }
 357    async fn start_container(&self, id: &str) -> Result<(), DevContainerError> {
 358        let mut command = Command::new(&self.docker_cli);
 359
 360        command.args(&["start", id]);
 361
 362        let output = command.output().await.map_err(|e| {
 363            log::error!("Error running docker start: {e}");
 364            DevContainerError::CommandFailed(command.get_program().display().to_string())
 365        })?;
 366
 367        if !output.status.success() {
 368            let stderr = String::from_utf8_lossy(&output.stderr);
 369            log::error!("Non-success status from docker start: {stderr}");
 370            return Err(DevContainerError::CommandFailed(
 371                command.get_program().display().to_string(),
 372            ));
 373        }
 374
 375        Ok(())
 376    }
 377
 378    async fn find_process_by_filters(
 379        &self,
 380        filters: Vec<String>,
 381    ) -> Result<Option<DockerPs>, DevContainerError> {
 382        let command = self.create_docker_query_containers(filters);
 383        evaluate_json_command(command).await
 384    }
 385
 386    fn docker_cli(&self) -> String {
 387        self.docker_cli.clone()
 388    }
 389
 390    fn supports_compose_buildkit(&self) -> bool {
 391        self.has_buildx
 392    }
 393}
 394
 395#[async_trait]
 396pub(crate) trait DockerClient {
 397    async fn inspect(&self, id: &String) -> Result<DockerInspect, DevContainerError>;
 398    async fn get_docker_compose_config(
 399        &self,
 400        config_files: &Vec<PathBuf>,
 401    ) -> Result<Option<DockerComposeConfig>, DevContainerError>;
 402    async fn docker_compose_build(
 403        &self,
 404        config_files: &Vec<PathBuf>,
 405        project_name: &str,
 406    ) -> Result<(), DevContainerError>;
 407    async fn run_docker_exec(
 408        &self,
 409        container_id: &str,
 410        remote_folder: &str,
 411        user: &str,
 412        env: &HashMap<String, String>,
 413        inner_command: Command,
 414    ) -> Result<(), DevContainerError>;
 415    async fn start_container(&self, id: &str) -> Result<(), DevContainerError>;
 416    async fn find_process_by_filters(
 417        &self,
 418        filters: Vec<String>,
 419    ) -> Result<Option<DockerPs>, DevContainerError>;
 420    fn supports_compose_buildkit(&self) -> bool;
 421    /// This operates as an escape hatch for more custom uses of the docker API.
 422    /// See DevContainerManifest::create_docker_build as an example
 423    fn docker_cli(&self) -> String;
 424}
 425
 426fn deserialize_labels<'de, D>(deserializer: D) -> Result<Option<HashMap<String, String>>, D::Error>
 427where
 428    D: Deserializer<'de>,
 429{
 430    struct LabelsVisitor;
 431
 432    impl<'de> de::Visitor<'de> for LabelsVisitor {
 433        type Value = Option<HashMap<String, String>>;
 434
 435        fn expecting(&self, formatter: &mut std::fmt::Formatter) -> std::fmt::Result {
 436            formatter.write_str("a sequence of strings or a map of string key-value pairs")
 437        }
 438
 439        fn visit_seq<A>(self, seq: A) -> Result<Self::Value, A::Error>
 440        where
 441            A: de::SeqAccess<'de>,
 442        {
 443            let values = Vec::<String>::deserialize(de::value::SeqAccessDeserializer::new(seq))?;
 444
 445            Ok(Some(
 446                values
 447                    .iter()
 448                    .filter_map(|v| {
 449                        let (key, value) = v.split_once('=')?;
 450                        Some((key.to_string(), value.to_string()))
 451                    })
 452                    .collect(),
 453            ))
 454        }
 455
 456        fn visit_map<M>(self, map: M) -> Result<Self::Value, M::Error>
 457        where
 458            M: de::MapAccess<'de>,
 459        {
 460            HashMap::<String, String>::deserialize(de::value::MapAccessDeserializer::new(map))
 461                .map(|v| Some(v))
 462        }
 463
 464        fn visit_none<E>(self) -> Result<Self::Value, E>
 465        where
 466            E: de::Error,
 467        {
 468            Ok(None)
 469        }
 470
 471        fn visit_unit<E>(self) -> Result<Self::Value, E>
 472        where
 473            E: de::Error,
 474        {
 475            Ok(None)
 476        }
 477    }
 478
 479    deserializer.deserialize_any(LabelsVisitor)
 480}
 481
 482fn deserialize_nullable_vec<'de, D, T>(deserializer: D) -> Result<Vec<T>, D::Error>
 483where
 484    D: Deserializer<'de>,
 485    T: Deserialize<'de>,
 486{
 487    Option::<Vec<T>>::deserialize(deserializer).map(|opt| opt.unwrap_or_default())
 488}
 489
 490fn deserialize_nullable_labels<'de, D>(deserializer: D) -> Result<DockerConfigLabels, D::Error>
 491where
 492    D: Deserializer<'de>,
 493{
 494    Option::<DockerConfigLabels>::deserialize(deserializer).map(|opt| opt.unwrap_or_default())
 495}
 496
 497fn deserialize_metadata<'de, D>(
 498    deserializer: D,
 499) -> Result<Option<Vec<HashMap<String, serde_json_lenient::Value>>>, D::Error>
 500where
 501    D: Deserializer<'de>,
 502{
 503    let s: Option<String> = Option::deserialize(deserializer)?;
 504    match s {
 505        Some(json_string) => {
 506            // The devcontainer metadata label can be either a JSON array (e.g. from
 507            // image-based devcontainers) or a single JSON object (e.g. from
 508            // docker-compose-based devcontainers created by the devcontainer CLI).
 509            // Handle both formats.
 510            let parsed: Vec<HashMap<String, serde_json_lenient::Value>> =
 511                serde_json_lenient::from_str(&json_string).or_else(|_| {
 512                    let single: HashMap<String, serde_json_lenient::Value> =
 513                        serde_json_lenient::from_str(&json_string).map_err(|e| {
 514                            log::error!("Error deserializing metadata: {e}");
 515                            serde::de::Error::custom(e)
 516                        })?;
 517                    Ok(vec![single])
 518                })?;
 519            Ok(Some(parsed))
 520        }
 521        None => Ok(None),
 522    }
 523}
 524
 525#[cfg(test)]
 526mod test {
 527    use std::{
 528        collections::HashMap,
 529        ffi::OsStr,
 530        process::{ExitStatus, Output},
 531    };
 532
 533    use crate::{
 534        command_json::deserialize_json_output,
 535        devcontainer_json::MountDefinition,
 536        docker::{
 537            Docker, DockerComposeConfig, DockerComposeService, DockerComposeServicePort,
 538            DockerComposeVolume, DockerInspect, DockerPs,
 539        },
 540    };
 541
 542    #[test]
 543    fn should_parse_simple_env_var() {
 544        let config = super::DockerInspectConfig {
 545            labels: super::DockerConfigLabels { metadata: None },
 546            image_user: None,
 547            env: vec!["KEY=value".to_string()],
 548        };
 549
 550        let map = config.env_as_map().unwrap();
 551        assert_eq!(map.get("KEY").unwrap(), "value");
 552    }
 553
 554    #[test]
 555    fn should_parse_env_var_with_equals_in_value() {
 556        let config = super::DockerInspectConfig {
 557            labels: super::DockerConfigLabels { metadata: None },
 558            image_user: None,
 559            env: vec!["COMPLEX=key=val other>=1.0".to_string()],
 560        };
 561
 562        let map = config.env_as_map().unwrap();
 563        assert_eq!(map.get("COMPLEX").unwrap(), "key=val other>=1.0");
 564    }
 565
 566    #[test]
 567    fn should_parse_simple_label() {
 568        let json = r#"{"volumes": [], "labels": ["com.example.key=value"]}"#;
 569        let service: DockerComposeService = serde_json_lenient::from_str(json).unwrap();
 570        let labels = service.labels.unwrap();
 571        assert_eq!(labels.get("com.example.key").unwrap(), "value");
 572    }
 573
 574    #[test]
 575    fn should_parse_label_with_equals_in_value() {
 576        let json = r#"{"volumes": [], "labels": ["com.example.key=value=with=equals"]}"#;
 577        let service: DockerComposeService = serde_json_lenient::from_str(json).unwrap();
 578        let labels = service.labels.unwrap();
 579        assert_eq!(labels.get("com.example.key").unwrap(), "value=with=equals");
 580    }
 581
 582    #[test]
 583    fn should_create_docker_inspect_command() {
 584        let docker = Docker {
 585            docker_cli: "docker".to_string(),
 586            has_buildx: false,
 587        };
 588        let given_id = "given_docker_id";
 589
 590        let command = docker.create_docker_inspect(given_id);
 591
 592        assert_eq!(
 593            command.get_args().collect::<Vec<&OsStr>>(),
 594            vec![
 595                OsStr::new("inspect"),
 596                OsStr::new("--format={{json . }}"),
 597                OsStr::new(given_id)
 598            ]
 599        )
 600    }
 601
 602    #[test]
 603    fn should_deserialize_docker_ps_with_filters() {
 604        // First, deserializes empty
 605        let empty_output = Output {
 606            status: ExitStatus::default(),
 607            stderr: vec![],
 608            stdout: String::from("").into_bytes(),
 609        };
 610
 611        let result: Option<DockerPs> = deserialize_json_output(empty_output).unwrap();
 612
 613        assert!(result.is_none());
 614
 615        let full_output = Output {
 616                status: ExitStatus::default(),
 617                stderr: vec![],
 618                stdout: String::from(r#"
 619    {
 620        "Command": "\"/bin/sh -c 'echo Co…\"",
 621        "CreatedAt": "2026-02-04 15:44:21 -0800 PST",
 622        "ID": "abdb6ab59573",
 623        "Image": "mcr.microsoft.com/devcontainers/base:ubuntu",
 624        "Labels": "desktop.docker.io/mounts/0/Source=/somepath/cli,desktop.docker.io/mounts/0/SourceKind=hostFile,desktop.docker.io/mounts/0/Target=/workspaces/cli,desktop.docker.io/ports.scheme=v2,dev.containers.features=common,dev.containers.id=base-ubuntu,dev.containers.release=v0.4.24,dev.containers.source=https://github.com/devcontainers/images,dev.containers.timestamp=Fri, 30 Jan 2026 16:52:34 GMT,dev.containers.variant=noble,devcontainer.config_file=/somepath/cli/.devcontainer/dev_container_2/devcontainer.json,devcontainer.local_folder=/somepath/cli,devcontainer.metadata=[{\"id\":\"ghcr.io/devcontainers/features/common-utils:2\"},{\"id\":\"ghcr.io/devcontainers/features/git:1\",\"customizations\":{\"vscode\":{\"settings\":{\"github.copilot.chat.codeGeneration.instructions\":[{\"text\":\"This dev container includes an up-to-date version of Git, built from source as needed, pre-installed and available on the `PATH`.\"}]}}}},{\"remoteUser\":\"vscode\"}],org.opencontainers.image.ref.name=ubuntu,org.opencontainers.image.version=24.04,version=2.1.6",
 625        "LocalVolumes": "0",
 626        "Mounts": "/host_mnt/User…",
 627        "Names": "objective_haslett",
 628        "Networks": "bridge",
 629        "Platform": {
 630        "architecture": "arm64",
 631        "os": "linux"
 632        },
 633        "Ports": "",
 634        "RunningFor": "47 hours ago",
 635        "Size": "0B",
 636        "State": "running",
 637        "Status": "Up 47 hours"
 638    }
 639                    "#).into_bytes(),
 640            };
 641
 642        let result: Option<DockerPs> = deserialize_json_output(full_output).unwrap();
 643
 644        assert!(result.is_some());
 645        let result = result.unwrap();
 646        assert_eq!(result.id, "abdb6ab59573".to_string());
 647
 648        // Podman variant (Id, not ID)
 649        let full_output = Output {
 650                status: ExitStatus::default(),
 651                stderr: vec![],
 652                stdout: String::from(r#"
 653    {
 654        "Command": "\"/bin/sh -c 'echo Co…\"",
 655        "CreatedAt": "2026-02-04 15:44:21 -0800 PST",
 656        "Id": "abdb6ab59573",
 657        "Image": "mcr.microsoft.com/devcontainers/base:ubuntu",
 658        "Labels": "desktop.docker.io/mounts/0/Source=/somepath/cli,desktop.docker.io/mounts/0/SourceKind=hostFile,desktop.docker.io/mounts/0/Target=/workspaces/cli,desktop.docker.io/ports.scheme=v2,dev.containers.features=common,dev.containers.id=base-ubuntu,dev.containers.release=v0.4.24,dev.containers.source=https://github.com/devcontainers/images,dev.containers.timestamp=Fri, 30 Jan 2026 16:52:34 GMT,dev.containers.variant=noble,devcontainer.config_file=/somepath/cli/.devcontainer/dev_container_2/devcontainer.json,devcontainer.local_folder=/somepath/cli,devcontainer.metadata=[{\"id\":\"ghcr.io/devcontainers/features/common-utils:2\"},{\"id\":\"ghcr.io/devcontainers/features/git:1\",\"customizations\":{\"vscode\":{\"settings\":{\"github.copilot.chat.codeGeneration.instructions\":[{\"text\":\"This dev container includes an up-to-date version of Git, built from source as needed, pre-installed and available on the `PATH`.\"}]}}}},{\"remoteUser\":\"vscode\"}],org.opencontainers.image.ref.name=ubuntu,org.opencontainers.image.version=24.04,version=2.1.6",
 659        "LocalVolumes": "0",
 660        "Mounts": "/host_mnt/User…",
 661        "Names": "objective_haslett",
 662        "Networks": "bridge",
 663        "Platform": {
 664        "architecture": "arm64",
 665        "os": "linux"
 666        },
 667        "Ports": "",
 668        "RunningFor": "47 hours ago",
 669        "Size": "0B",
 670        "State": "running",
 671        "Status": "Up 47 hours"
 672    }
 673                    "#).into_bytes(),
 674            };
 675
 676        let result: Option<DockerPs> = deserialize_json_output(full_output).unwrap();
 677
 678        assert!(result.is_some());
 679        let result = result.unwrap();
 680        assert_eq!(result.id, "abdb6ab59573".to_string());
 681    }
 682
 683    #[test]
 684    fn should_deserialize_object_metadata_from_docker_compose_container() {
 685        // The devcontainer CLI writes metadata as a bare JSON object (not an array)
 686        // when there is only one metadata entry (e.g. docker-compose with no features).
 687        // See https://github.com/devcontainers/cli/issues/1054
 688        let given_config = r#"
 689    {
 690      "Id": "dc4e7b8ff4bf",
 691      "Config": {
 692        "Labels": {
 693          "devcontainer.metadata": "{\"remoteUser\":\"ubuntu\"}"
 694        }
 695      }
 696    }
 697                "#;
 698        let config = serde_json_lenient::from_str::<DockerInspect>(given_config).unwrap();
 699
 700        assert!(config.config.labels.metadata.is_some());
 701        let metadata = config.config.labels.metadata.unwrap();
 702        assert_eq!(metadata.len(), 1);
 703        assert!(metadata[0].contains_key("remoteUser"));
 704        assert_eq!(metadata[0]["remoteUser"], "ubuntu");
 705    }
 706
 707    #[test]
 708    fn should_deserialize_docker_compose_config() {
 709        let given_config = r#"
 710    {
 711        "name": "devcontainer",
 712        "networks": {
 713        "default": {
 714            "name": "devcontainer_default",
 715            "ipam": {}
 716        }
 717        },
 718        "services": {
 719            "app": {
 720                "command": [
 721                "sleep",
 722                "infinity"
 723                ],
 724                "depends_on": {
 725                "db": {
 726                    "condition": "service_started",
 727                    "restart": true,
 728                    "required": true
 729                }
 730                },
 731                "entrypoint": null,
 732                "environment": {
 733                "POSTGRES_DB": "postgres",
 734                "POSTGRES_HOSTNAME": "localhost",
 735                "POSTGRES_PASSWORD": "postgres",
 736                "POSTGRES_PORT": "5432",
 737                "POSTGRES_USER": "postgres"
 738                },
 739                "ports": [
 740                    {
 741                        "target": "5443",
 742                        "published": "5442"
 743                    },
 744                    {
 745                        "name": "custom port",
 746                        "protocol": "udp",
 747                        "host_ip": "127.0.0.1",
 748                        "app_protocol": "http",
 749                        "mode": "host",
 750                        "target": "8081",
 751                        "published": "8083"
 752
 753                    }
 754                ],
 755                "image": "mcr.microsoft.com/devcontainers/rust:2-1-bookworm",
 756                "network_mode": "service:db",
 757                "volumes": [
 758                {
 759                    "type": "bind",
 760                    "source": "/path/to",
 761                    "target": "/workspaces",
 762                    "bind": {
 763                    "create_host_path": true
 764                    }
 765                }
 766                ]
 767            },
 768            "db": {
 769                "command": null,
 770                "entrypoint": null,
 771                "environment": {
 772                "POSTGRES_DB": "postgres",
 773                "POSTGRES_HOSTNAME": "localhost",
 774                "POSTGRES_PASSWORD": "postgres",
 775                "POSTGRES_PORT": "5432",
 776                "POSTGRES_USER": "postgres"
 777                },
 778                "image": "postgres:14.1",
 779                "networks": {
 780                "default": null
 781                },
 782                "restart": "unless-stopped",
 783                "volumes": [
 784                {
 785                    "type": "volume",
 786                    "source": "postgres-data",
 787                    "target": "/var/lib/postgresql/data",
 788                    "volume": {}
 789                }
 790                ]
 791            }
 792        },
 793        "volumes": {
 794        "postgres-data": {
 795            "name": "devcontainer_postgres-data"
 796        }
 797        }
 798    }
 799                "#;
 800
 801        let docker_compose_config: DockerComposeConfig =
 802            serde_json_lenient::from_str(given_config).unwrap();
 803
 804        let expected_config = DockerComposeConfig {
 805            name: Some("devcontainer".to_string()),
 806            services: HashMap::from([
 807                (
 808                    "app".to_string(),
 809                    DockerComposeService {
 810                        command: vec!["sleep".to_string(), "infinity".to_string()],
 811                        image: Some(
 812                            "mcr.microsoft.com/devcontainers/rust:2-1-bookworm".to_string(),
 813                        ),
 814                        volumes: vec![MountDefinition {
 815                            mount_type: Some("bind".to_string()),
 816                            source: Some("/path/to".to_string()),
 817                            target: "/workspaces".to_string(),
 818                        }],
 819                        network_mode: Some("service:db".to_string()),
 820
 821                        ports: vec![
 822                            DockerComposeServicePort {
 823                                target: "5443".to_string(),
 824                                published: "5442".to_string(),
 825                                ..Default::default()
 826                            },
 827                            DockerComposeServicePort {
 828                                target: "8081".to_string(),
 829                                published: "8083".to_string(),
 830                                mode: Some("host".to_string()),
 831                                protocol: Some("udp".to_string()),
 832                                host_ip: Some("127.0.0.1".to_string()),
 833                                app_protocol: Some("http".to_string()),
 834                                name: Some("custom port".to_string()),
 835                            },
 836                        ],
 837                        ..Default::default()
 838                    },
 839                ),
 840                (
 841                    "db".to_string(),
 842                    DockerComposeService {
 843                        image: Some("postgres:14.1".to_string()),
 844                        volumes: vec![MountDefinition {
 845                            mount_type: Some("volume".to_string()),
 846                            source: Some("postgres-data".to_string()),
 847                            target: "/var/lib/postgresql/data".to_string(),
 848                        }],
 849                        ..Default::default()
 850                    },
 851                ),
 852            ]),
 853            volumes: HashMap::from([(
 854                "postgres-data".to_string(),
 855                DockerComposeVolume {
 856                    name: "devcontainer_postgres-data".to_string(),
 857                },
 858            )]),
 859        };
 860
 861        assert_eq!(docker_compose_config, expected_config);
 862    }
 863
 864    #[test]
 865    fn should_deserialize_compose_labels_as_map() {
 866        let given_config = r#"
 867        {
 868            "name": "devcontainer",
 869            "services": {
 870                "app": {
 871                    "image": "node:22-alpine",
 872                    "volumes": [],
 873                    "labels": {
 874                        "com.example.test": "value",
 875                        "another.label": "another-value"
 876                    }
 877                }
 878            }
 879        }
 880        "#;
 881
 882        let config: DockerComposeConfig = serde_json_lenient::from_str(given_config).unwrap();
 883        let service = config.services.get("app").unwrap();
 884        let labels = service.labels.clone().unwrap();
 885        assert_eq!(
 886            labels,
 887            HashMap::from([
 888                ("another.label".to_string(), "another-value".to_string()),
 889                ("com.example.test".to_string(), "value".to_string())
 890            ])
 891        );
 892    }
 893
 894    #[test]
 895    fn should_deserialize_compose_labels_as_array() {
 896        let given_config = r#"
 897        {
 898            "name": "devcontainer",
 899            "services": {
 900                "app": {
 901                    "image": "node:22-alpine",
 902                    "volumes": [],
 903                    "labels": ["com.example.test=value"]
 904                }
 905            }
 906        }
 907        "#;
 908
 909        let config: DockerComposeConfig = serde_json_lenient::from_str(given_config).unwrap();
 910        let service = config.services.get("app").unwrap();
 911        assert_eq!(
 912            service.labels,
 913            Some(HashMap::from([(
 914                "com.example.test".to_string(),
 915                "value".to_string()
 916            )]))
 917        );
 918    }
 919
 920    #[test]
 921    fn should_deserialize_compose_without_volumes() {
 922        let given_config = r#"
 923        {
 924            "name": "devcontainer",
 925            "services": {
 926                "app": {
 927                    "image": "node:22-alpine",
 928                    "volumes": []
 929                }
 930            }
 931        }
 932        "#;
 933
 934        let config: DockerComposeConfig = serde_json_lenient::from_str(given_config).unwrap();
 935        assert!(config.volumes.is_empty());
 936    }
 937
 938    #[test]
 939    fn should_deserialize_compose_with_missing_volumes_field() {
 940        let given_config = r#"
 941        {
 942            "name": "devcontainer",
 943            "services": {
 944                "sidecar": {
 945                    "image": "ubuntu:24.04"
 946                }
 947            }
 948        }
 949        "#;
 950
 951        let config: DockerComposeConfig = serde_json_lenient::from_str(given_config).unwrap();
 952        let service = config.services.get("sidecar").unwrap();
 953        assert!(service.volumes.is_empty());
 954    }
 955
 956    #[test]
 957    fn should_deserialize_compose_volume_without_source() {
 958        let given_config = r#"
 959        {
 960            "name": "devcontainer",
 961            "services": {
 962                "app": {
 963                    "image": "ubuntu:24.04",
 964                    "volumes": [
 965                        {
 966                            "type": "tmpfs",
 967                            "target": "/tmp"
 968                        }
 969                    ]
 970                }
 971            }
 972        }
 973        "#;
 974
 975        let config: DockerComposeConfig = serde_json_lenient::from_str(given_config).unwrap();
 976        let service = config.services.get("app").unwrap();
 977        assert_eq!(service.volumes.len(), 1);
 978        assert_eq!(service.volumes[0].source, None);
 979        assert_eq!(service.volumes[0].target, "/tmp");
 980        assert_eq!(service.volumes[0].mount_type, Some("tmpfs".to_string()));
 981    }
 982
 983    #[test]
 984    fn should_deserialize_inspect_without_labels() {
 985        let given_config = r#"
 986        {
 987            "Id": "sha256:abc123",
 988            "Config": {
 989                "Env": ["PATH=/usr/bin"],
 990                "Cmd": ["node"],
 991                "WorkingDir": "/"
 992            }
 993        }
 994        "#;
 995
 996        let inspect: DockerInspect = serde_json_lenient::from_str(given_config).unwrap();
 997        assert!(inspect.config.labels.metadata.is_none());
 998        assert!(inspect.config.image_user.is_none());
 999    }
1000
1001    #[test]
1002    fn should_deserialize_inspect_with_null_labels() {
1003        let given_config = r#"
1004        {
1005            "Id": "sha256:abc123",
1006            "Config": {
1007                "Labels": null,
1008                "Env": ["PATH=/usr/bin"]
1009            }
1010        }
1011        "#;
1012
1013        let inspect: DockerInspect = serde_json_lenient::from_str(given_config).unwrap();
1014        assert!(inspect.config.labels.metadata.is_none());
1015    }
1016
1017    #[test]
1018    fn should_deserialize_inspect_with_labels_but_no_metadata() {
1019        let given_config = r#"
1020        {
1021            "Id": "sha256:abc123",
1022            "Config": {
1023                "Labels": {
1024                    "com.example.test": "value"
1025                },
1026                "Env": ["PATH=/usr/bin"]
1027            }
1028        }
1029        "#;
1030
1031        let inspect: DockerInspect = serde_json_lenient::from_str(given_config).unwrap();
1032        assert!(inspect.config.labels.metadata.is_none());
1033    }
1034}