docker.rs

   1use std::{collections::HashMap, path::PathBuf};
   2
   3use async_trait::async_trait;
   4use serde::{Deserialize, Deserializer, Serialize, de};
   5use util::command::Command;
   6
   7use crate::{
   8    command_json::evaluate_json_command, devcontainer_api::DevContainerError,
   9    devcontainer_json::MountDefinition,
  10};
  11
  12#[derive(Debug, Deserialize, Serialize, Eq, PartialEq)]
  13#[serde(rename_all = "PascalCase")]
  14pub(crate) struct DockerPs {
  15    #[serde(alias = "ID")]
  16    pub(crate) id: String,
  17}
  18
  19#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq)]
  20#[serde(rename_all = "PascalCase")]
  21pub(crate) struct DockerState {
  22    pub(crate) running: bool,
  23}
  24
  25#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq)]
  26#[serde(rename_all = "PascalCase")]
  27pub(crate) struct DockerInspect {
  28    pub(crate) id: String,
  29    pub(crate) config: DockerInspectConfig,
  30    pub(crate) mounts: Option<Vec<DockerInspectMount>>,
  31    pub(crate) state: Option<DockerState>,
  32}
  33
  34#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
  35pub(crate) struct DockerConfigLabels {
  36    #[serde(
  37        default,
  38        rename = "devcontainer.metadata",
  39        deserialize_with = "deserialize_metadata"
  40    )]
  41    pub(crate) metadata: Option<Vec<HashMap<String, serde_json_lenient::Value>>>,
  42}
  43
  44#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq)]
  45#[serde(rename_all = "PascalCase")]
  46pub(crate) struct DockerInspectConfig {
  47    #[serde(default, deserialize_with = "deserialize_nullable_labels")]
  48    pub(crate) labels: DockerConfigLabels,
  49    #[serde(rename = "User")]
  50    pub(crate) image_user: Option<String>,
  51    #[serde(default)]
  52    pub(crate) env: Vec<String>,
  53}
  54
  55impl DockerInspectConfig {
  56    pub(crate) fn env_as_map(&self) -> Result<HashMap<String, String>, DevContainerError> {
  57        let mut map = HashMap::new();
  58        for env_var in &self.env {
  59            let Some((key, value)) = env_var.split_once('=') else {
  60                log::warn!("Skipping environment variable without a value: {env_var}");
  61                continue;
  62            };
  63            map.insert(key.to_string(), value.to_string());
  64        }
  65        Ok(map)
  66    }
  67}
  68
  69#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq)]
  70#[serde(rename_all = "PascalCase")]
  71pub(crate) struct DockerInspectMount {
  72    pub(crate) source: String,
  73    pub(crate) destination: String,
  74}
  75
  76#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
  77pub(crate) struct DockerComposeServiceBuild {
  78    #[serde(skip_serializing_if = "Option::is_none")]
  79    pub(crate) context: Option<String>,
  80    #[serde(skip_serializing_if = "Option::is_none")]
  81    pub(crate) dockerfile: Option<String>,
  82    #[serde(skip_serializing_if = "Option::is_none")]
  83    pub(crate) target: Option<String>,
  84    #[serde(skip_serializing_if = "Option::is_none")]
  85    pub(crate) args: Option<HashMap<String, String>>,
  86    #[serde(skip_serializing_if = "Option::is_none")]
  87    pub(crate) additional_contexts: Option<HashMap<String, String>>,
  88}
  89
  90#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
  91pub(crate) struct DockerComposeServicePort {
  92    #[serde(deserialize_with = "deserialize_string_or_int")]
  93    pub(crate) target: String,
  94    #[serde(deserialize_with = "deserialize_string_or_int")]
  95    pub(crate) published: String,
  96    #[serde(skip_serializing_if = "Option::is_none")]
  97    pub(crate) mode: Option<String>,
  98    #[serde(skip_serializing_if = "Option::is_none")]
  99    pub(crate) protocol: Option<String>,
 100    #[serde(skip_serializing_if = "Option::is_none")]
 101    pub(crate) host_ip: Option<String>,
 102    #[serde(skip_serializing_if = "Option::is_none")]
 103    pub(crate) app_protocol: Option<String>,
 104    #[serde(skip_serializing_if = "Option::is_none")]
 105    pub(crate) name: Option<String>,
 106}
 107
 108fn deserialize_string_or_int<'de, D>(deserializer: D) -> Result<String, D::Error>
 109where
 110    D: serde::Deserializer<'de>,
 111{
 112    use serde::Deserialize;
 113
 114    #[derive(Deserialize)]
 115    #[serde(untagged)]
 116    enum StringOrInt {
 117        String(String),
 118        Int(u32),
 119    }
 120
 121    match StringOrInt::deserialize(deserializer)? {
 122        StringOrInt::String(s) => Ok(s),
 123        StringOrInt::Int(b) => Ok(b.to_string()),
 124    }
 125}
 126
 127#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
 128pub(crate) struct DockerComposeService {
 129    pub(crate) image: Option<String>,
 130    #[serde(skip_serializing_if = "Option::is_none")]
 131    pub(crate) entrypoint: Option<Vec<String>>,
 132    #[serde(skip_serializing_if = "Option::is_none")]
 133    pub(crate) cap_add: Option<Vec<String>>,
 134    #[serde(skip_serializing_if = "Option::is_none")]
 135    pub(crate) security_opt: Option<Vec<String>>,
 136    #[serde(
 137        skip_serializing_if = "Option::is_none",
 138        default,
 139        deserialize_with = "deserialize_labels"
 140    )]
 141    pub(crate) labels: Option<HashMap<String, String>>,
 142    #[serde(skip_serializing_if = "Option::is_none")]
 143    pub(crate) build: Option<DockerComposeServiceBuild>,
 144    #[serde(skip_serializing_if = "Option::is_none")]
 145    pub(crate) privileged: Option<bool>,
 146    #[serde(default, skip_serializing_if = "Vec::is_empty")]
 147    pub(crate) volumes: Vec<MountDefinition>,
 148    #[serde(skip_serializing_if = "Option::is_none")]
 149    pub(crate) env_file: Option<Vec<String>>,
 150    #[serde(default, skip_serializing_if = "Vec::is_empty")]
 151    pub(crate) ports: Vec<DockerComposeServicePort>,
 152    #[serde(skip_serializing_if = "Option::is_none")]
 153    pub(crate) network_mode: Option<String>,
 154    #[serde(
 155        default,
 156        skip_serializing_if = "Vec::is_empty",
 157        deserialize_with = "deserialize_nullable_vec"
 158    )]
 159    pub(crate) command: Vec<String>,
 160}
 161
 162#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
 163pub(crate) struct DockerComposeVolume {
 164    pub(crate) name: String,
 165}
 166
 167#[derive(Debug, Clone, Deserialize, Serialize, Eq, PartialEq, Default)]
 168pub(crate) struct DockerComposeConfig {
 169    #[serde(skip_serializing_if = "Option::is_none")]
 170    pub(crate) name: Option<String>,
 171    pub(crate) services: HashMap<String, DockerComposeService>,
 172    #[serde(default)]
 173    pub(crate) volumes: HashMap<String, DockerComposeVolume>,
 174}
 175
 176pub(crate) struct Docker {
 177    docker_cli: String,
 178    has_buildx: bool,
 179}
 180
 181impl DockerInspect {
 182    pub(crate) fn is_running(&self) -> bool {
 183        self.state.as_ref().map_or(false, |s| s.running)
 184    }
 185}
 186
 187impl Docker {
 188    pub(crate) async fn new(docker_cli: &str) -> Self {
 189        let has_buildx = if docker_cli == "podman" {
 190            false
 191        } else {
 192            let output = Command::new(docker_cli)
 193                .args(["buildx", "version"])
 194                .output()
 195                .await;
 196            output.map(|o| o.status.success()).unwrap_or(false)
 197        };
 198        if !has_buildx && docker_cli != "podman" {
 199            log::info!(
 200                "docker buildx not found; dev container builds will use the scratch-image fallback"
 201            );
 202        }
 203        Self {
 204            docker_cli: docker_cli.to_string(),
 205            has_buildx,
 206        }
 207    }
 208
 209    fn is_podman(&self) -> bool {
 210        self.docker_cli == "podman"
 211    }
 212
 213    async fn pull_image(&self, image: &String) -> Result<(), DevContainerError> {
 214        let mut command = Command::new(&self.docker_cli);
 215        command.args(&["pull", "--", image]);
 216
 217        let output = command.output().await.map_err(|e| {
 218            log::error!("Error pulling image: {e}");
 219            DevContainerError::ResourceFetchFailed
 220        })?;
 221
 222        if !output.status.success() {
 223            let stderr = String::from_utf8_lossy(&output.stderr);
 224            log::error!("Non-success result from docker pull: {stderr}");
 225            return Err(DevContainerError::ResourceFetchFailed);
 226        }
 227        Ok(())
 228    }
 229
 230    fn create_docker_query_containers(&self, filters: Vec<String>) -> Command {
 231        let mut command = Command::new(&self.docker_cli);
 232        command.args(&["ps", "-a"]);
 233
 234        for filter in filters {
 235            command.arg("--filter");
 236            command.arg(filter);
 237        }
 238        command.arg("--format={{ json . }}");
 239        command
 240    }
 241
 242    fn create_docker_inspect(&self, id: &str) -> Command {
 243        let mut command = Command::new(&self.docker_cli);
 244        command.args(&["inspect", "--format={{json . }}", id]);
 245        command
 246    }
 247
 248    fn create_docker_compose_config_command(&self, config_files: &Vec<PathBuf>) -> Command {
 249        let mut command = Command::new(&self.docker_cli);
 250        command.arg("compose");
 251        for file_path in config_files {
 252            command.args(&["-f", &file_path.display().to_string()]);
 253        }
 254        command.args(&["config", "--format", "json"]);
 255        command
 256    }
 257}
 258
 259#[async_trait]
 260impl DockerClient for Docker {
 261    async fn inspect(&self, id: &String) -> Result<DockerInspect, DevContainerError> {
 262        // Try to pull the image, continue on failure; Image may be local only, id a reference to a running container
 263        self.pull_image(id).await.ok();
 264
 265        let command = self.create_docker_inspect(id);
 266
 267        let Some(docker_inspect): Option<DockerInspect> = evaluate_json_command(command).await?
 268        else {
 269            log::error!("Docker inspect produced no deserializable output");
 270            return Err(DevContainerError::CommandFailed(self.docker_cli.clone()));
 271        };
 272        Ok(docker_inspect)
 273    }
 274
 275    async fn get_docker_compose_config(
 276        &self,
 277        config_files: &Vec<PathBuf>,
 278    ) -> Result<Option<DockerComposeConfig>, DevContainerError> {
 279        let command = self.create_docker_compose_config_command(config_files);
 280        evaluate_json_command(command).await
 281    }
 282
 283    async fn docker_compose_build(
 284        &self,
 285        config_files: &Vec<PathBuf>,
 286        project_name: &str,
 287    ) -> Result<(), DevContainerError> {
 288        let mut command = Command::new(&self.docker_cli);
 289        if !self.is_podman() {
 290            command.env("DOCKER_BUILDKIT", "1");
 291        }
 292        command.args(&["compose", "--project-name", project_name]);
 293        for docker_compose_file in config_files {
 294            command.args(&["-f", &docker_compose_file.display().to_string()]);
 295        }
 296        command.arg("build");
 297
 298        let output = command.output().await.map_err(|e| {
 299            log::error!("Error running docker compose up: {e}");
 300            DevContainerError::CommandFailed(command.get_program().display().to_string())
 301        })?;
 302
 303        if !output.status.success() {
 304            let stderr = String::from_utf8_lossy(&output.stderr);
 305            log::error!("Non-success status from docker compose up: {}", stderr);
 306            return Err(DevContainerError::CommandFailed(
 307                command.get_program().display().to_string(),
 308            ));
 309        }
 310
 311        Ok(())
 312    }
 313    async fn run_docker_exec(
 314        &self,
 315        container_id: &str,
 316        remote_folder: &str,
 317        user: &str,
 318        env: &HashMap<String, String>,
 319        inner_command: Command,
 320    ) -> Result<(), DevContainerError> {
 321        let mut command = Command::new(&self.docker_cli);
 322
 323        command.args(&["exec", "-w", remote_folder, "-u", user]);
 324
 325        for (k, v) in env.iter() {
 326            command.arg("-e");
 327            let env_declaration = format!("{}={}", k, v);
 328            command.arg(&env_declaration);
 329        }
 330
 331        command.arg(container_id);
 332
 333        command.arg("sh");
 334
 335        let mut inner_program_script: Vec<String> =
 336            vec![inner_command.get_program().display().to_string()];
 337        let mut args: Vec<String> = inner_command
 338            .get_args()
 339            .map(|arg| arg.display().to_string())
 340            .collect();
 341        inner_program_script.append(&mut args);
 342        command.args(&["-c", &inner_program_script.join(" ")]);
 343
 344        let output = command.output().await.map_err(|e| {
 345            log::error!("Error running command {e} in container exec");
 346            DevContainerError::ContainerNotValid(container_id.to_string())
 347        })?;
 348        if !output.status.success() {
 349            let std_err = String::from_utf8_lossy(&output.stderr);
 350            log::error!("Command produced a non-successful output. StdErr: {std_err}");
 351        }
 352        let std_out = String::from_utf8_lossy(&output.stdout);
 353        log::debug!("Command output:\n {std_out}");
 354
 355        Ok(())
 356    }
 357    async fn start_container(&self, id: &str) -> Result<(), DevContainerError> {
 358        let mut command = Command::new(&self.docker_cli);
 359
 360        command.args(&["start", id]);
 361
 362        let output = command.output().await.map_err(|e| {
 363            log::error!("Error running docker start: {e}");
 364            DevContainerError::CommandFailed(command.get_program().display().to_string())
 365        })?;
 366
 367        if !output.status.success() {
 368            let stderr = String::from_utf8_lossy(&output.stderr);
 369            log::error!("Non-success status from docker start: {stderr}");
 370            return Err(DevContainerError::CommandFailed(
 371                command.get_program().display().to_string(),
 372            ));
 373        }
 374
 375        Ok(())
 376    }
 377
 378    async fn find_process_by_filters(
 379        &self,
 380        filters: Vec<String>,
 381    ) -> Result<Option<DockerPs>, DevContainerError> {
 382        let command = self.create_docker_query_containers(filters);
 383        evaluate_json_command(command).await
 384    }
 385
 386    fn docker_cli(&self) -> String {
 387        self.docker_cli.clone()
 388    }
 389
 390    fn supports_compose_buildkit(&self) -> bool {
 391        self.has_buildx
 392    }
 393}
 394
 395#[async_trait]
 396pub(crate) trait DockerClient {
 397    async fn inspect(&self, id: &String) -> Result<DockerInspect, DevContainerError>;
 398    async fn get_docker_compose_config(
 399        &self,
 400        config_files: &Vec<PathBuf>,
 401    ) -> Result<Option<DockerComposeConfig>, DevContainerError>;
 402    async fn docker_compose_build(
 403        &self,
 404        config_files: &Vec<PathBuf>,
 405        project_name: &str,
 406    ) -> Result<(), DevContainerError>;
 407    async fn run_docker_exec(
 408        &self,
 409        container_id: &str,
 410        remote_folder: &str,
 411        user: &str,
 412        env: &HashMap<String, String>,
 413        inner_command: Command,
 414    ) -> Result<(), DevContainerError>;
 415    async fn start_container(&self, id: &str) -> Result<(), DevContainerError>;
 416    async fn find_process_by_filters(
 417        &self,
 418        filters: Vec<String>,
 419    ) -> Result<Option<DockerPs>, DevContainerError>;
 420    fn supports_compose_buildkit(&self) -> bool;
 421    /// This operates as an escape hatch for more custom uses of the docker API.
 422    /// See DevContainerManifest::create_docker_build as an example
 423    fn docker_cli(&self) -> String;
 424}
 425
 426fn deserialize_labels<'de, D>(deserializer: D) -> Result<Option<HashMap<String, String>>, D::Error>
 427where
 428    D: Deserializer<'de>,
 429{
 430    struct LabelsVisitor;
 431
 432    impl<'de> de::Visitor<'de> for LabelsVisitor {
 433        type Value = Option<HashMap<String, String>>;
 434
 435        fn expecting(&self, formatter: &mut std::fmt::Formatter) -> std::fmt::Result {
 436            formatter.write_str("a sequence of strings or a map of string key-value pairs")
 437        }
 438
 439        fn visit_seq<A>(self, seq: A) -> Result<Self::Value, A::Error>
 440        where
 441            A: de::SeqAccess<'de>,
 442        {
 443            let values = Vec::<String>::deserialize(de::value::SeqAccessDeserializer::new(seq))?;
 444
 445            Ok(Some(
 446                values
 447                    .iter()
 448                    .filter_map(|v| {
 449                        let (key, value) = v.split_once('=')?;
 450                        Some((key.to_string(), value.to_string()))
 451                    })
 452                    .collect(),
 453            ))
 454        }
 455
 456        fn visit_map<M>(self, map: M) -> Result<Self::Value, M::Error>
 457        where
 458            M: de::MapAccess<'de>,
 459        {
 460            HashMap::<String, String>::deserialize(de::value::MapAccessDeserializer::new(map))
 461                .map(|v| Some(v))
 462        }
 463
 464        fn visit_none<E>(self) -> Result<Self::Value, E>
 465        where
 466            E: de::Error,
 467        {
 468            Ok(None)
 469        }
 470
 471        fn visit_unit<E>(self) -> Result<Self::Value, E>
 472        where
 473            E: de::Error,
 474        {
 475            Ok(None)
 476        }
 477    }
 478
 479    deserializer.deserialize_any(LabelsVisitor)
 480}
 481
 482fn deserialize_nullable_vec<'de, D, T>(deserializer: D) -> Result<Vec<T>, D::Error>
 483where
 484    D: Deserializer<'de>,
 485    T: Deserialize<'de>,
 486{
 487    Option::<Vec<T>>::deserialize(deserializer).map(|opt| opt.unwrap_or_default())
 488}
 489
 490fn deserialize_nullable_labels<'de, D>(deserializer: D) -> Result<DockerConfigLabels, D::Error>
 491where
 492    D: Deserializer<'de>,
 493{
 494    Option::<DockerConfigLabels>::deserialize(deserializer).map(|opt| opt.unwrap_or_default())
 495}
 496
 497fn deserialize_metadata<'de, D>(
 498    deserializer: D,
 499) -> Result<Option<Vec<HashMap<String, serde_json_lenient::Value>>>, D::Error>
 500where
 501    D: Deserializer<'de>,
 502{
 503    let s: Option<String> = Option::deserialize(deserializer)?;
 504    match s {
 505        Some(json_string) => {
 506            // The devcontainer metadata label can be either a JSON array (e.g. from
 507            // image-based devcontainers) or a single JSON object (e.g. from
 508            // docker-compose-based devcontainers created by the devcontainer CLI).
 509            // Handle both formats.
 510            let parsed: Vec<HashMap<String, serde_json_lenient::Value>> =
 511                serde_json_lenient::from_str(&json_string).or_else(|_| {
 512                    let single: HashMap<String, serde_json_lenient::Value> =
 513                        serde_json_lenient::from_str(&json_string).map_err(|e| {
 514                            log::error!("Error deserializing metadata: {e}");
 515                            serde::de::Error::custom(e)
 516                        })?;
 517                    Ok(vec![single])
 518                })?;
 519            Ok(Some(parsed))
 520        }
 521        None => Ok(None),
 522    }
 523}
 524
 525#[cfg(test)]
 526mod test {
 527    use std::{
 528        collections::HashMap,
 529        ffi::OsStr,
 530        process::{ExitStatus, Output},
 531    };
 532
 533    use crate::{
 534        command_json::deserialize_json_output,
 535        devcontainer_json::MountDefinition,
 536        docker::{
 537            Docker, DockerComposeConfig, DockerComposeService, DockerComposeServicePort,
 538            DockerComposeVolume, DockerInspect, DockerPs,
 539        },
 540    };
 541
 542    #[test]
 543    fn should_parse_simple_env_var() {
 544        let config = super::DockerInspectConfig {
 545            labels: super::DockerConfigLabels { metadata: None },
 546            image_user: None,
 547            env: vec!["KEY=value".to_string()],
 548        };
 549
 550        let map = config.env_as_map().unwrap();
 551        assert_eq!(map.get("KEY").unwrap(), "value");
 552    }
 553
 554    #[test]
 555    fn should_parse_env_var_with_equals_in_value() {
 556        let config = super::DockerInspectConfig {
 557            labels: super::DockerConfigLabels { metadata: None },
 558            image_user: None,
 559            env: vec!["COMPLEX=key=val other>=1.0".to_string()],
 560        };
 561
 562        let map = config.env_as_map().unwrap();
 563        assert_eq!(map.get("COMPLEX").unwrap(), "key=val other>=1.0");
 564    }
 565
 566    #[test]
 567    fn should_parse_database_url_with_equals_in_query_string() {
 568        let config = super::DockerInspectConfig {
 569            labels: super::DockerConfigLabels { metadata: None },
 570            image_user: None,
 571            env: vec![
 572                "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin".to_string(),
 573                "TEST_DATABASE_URL=postgres://postgres:postgres@db:5432/mydb?sslmode=disable"
 574                    .to_string(),
 575            ],
 576        };
 577
 578        let map = config.env_as_map().unwrap();
 579        assert_eq!(
 580            map.get("TEST_DATABASE_URL").unwrap(),
 581            "postgres://postgres:postgres@db:5432/mydb?sslmode=disable"
 582        );
 583    }
 584
 585    #[test]
 586    fn should_skip_env_var_without_equals() {
 587        let config = super::DockerInspectConfig {
 588            labels: super::DockerConfigLabels { metadata: None },
 589            image_user: None,
 590            env: vec![
 591                "VALID_KEY=valid_value".to_string(),
 592                "NO_EQUALS_VAR".to_string(),
 593                "ANOTHER_VALID=value".to_string(),
 594            ],
 595        };
 596
 597        let map = config.env_as_map().unwrap();
 598        assert_eq!(map.len(), 2);
 599        assert_eq!(map.get("VALID_KEY").unwrap(), "valid_value");
 600        assert_eq!(map.get("ANOTHER_VALID").unwrap(), "value");
 601        assert!(!map.contains_key("NO_EQUALS_VAR"));
 602    }
 603
 604    #[test]
 605    fn should_parse_simple_label() {
 606        let json = r#"{"volumes": [], "labels": ["com.example.key=value"]}"#;
 607        let service: DockerComposeService = serde_json_lenient::from_str(json).unwrap();
 608        let labels = service.labels.unwrap();
 609        assert_eq!(labels.get("com.example.key").unwrap(), "value");
 610    }
 611
 612    #[test]
 613    fn should_parse_label_with_equals_in_value() {
 614        let json = r#"{"volumes": [], "labels": ["com.example.key=value=with=equals"]}"#;
 615        let service: DockerComposeService = serde_json_lenient::from_str(json).unwrap();
 616        let labels = service.labels.unwrap();
 617        assert_eq!(labels.get("com.example.key").unwrap(), "value=with=equals");
 618    }
 619
 620    #[test]
 621    fn should_create_docker_inspect_command() {
 622        let docker = Docker {
 623            docker_cli: "docker".to_string(),
 624            has_buildx: false,
 625        };
 626        let given_id = "given_docker_id";
 627
 628        let command = docker.create_docker_inspect(given_id);
 629
 630        assert_eq!(
 631            command.get_args().collect::<Vec<&OsStr>>(),
 632            vec![
 633                OsStr::new("inspect"),
 634                OsStr::new("--format={{json . }}"),
 635                OsStr::new(given_id)
 636            ]
 637        )
 638    }
 639
 640    #[test]
 641    fn should_deserialize_docker_ps_with_filters() {
 642        // First, deserializes empty
 643        let empty_output = Output {
 644            status: ExitStatus::default(),
 645            stderr: vec![],
 646            stdout: String::from("").into_bytes(),
 647        };
 648
 649        let result: Option<DockerPs> = deserialize_json_output(empty_output).unwrap();
 650
 651        assert!(result.is_none());
 652
 653        let full_output = Output {
 654                status: ExitStatus::default(),
 655                stderr: vec![],
 656                stdout: String::from(r#"
 657    {
 658        "Command": "\"/bin/sh -c 'echo Co…\"",
 659        "CreatedAt": "2026-02-04 15:44:21 -0800 PST",
 660        "ID": "abdb6ab59573",
 661        "Image": "mcr.microsoft.com/devcontainers/base:ubuntu",
 662        "Labels": "desktop.docker.io/mounts/0/Source=/somepath/cli,desktop.docker.io/mounts/0/SourceKind=hostFile,desktop.docker.io/mounts/0/Target=/workspaces/cli,desktop.docker.io/ports.scheme=v2,dev.containers.features=common,dev.containers.id=base-ubuntu,dev.containers.release=v0.4.24,dev.containers.source=https://github.com/devcontainers/images,dev.containers.timestamp=Fri, 30 Jan 2026 16:52:34 GMT,dev.containers.variant=noble,devcontainer.config_file=/somepath/cli/.devcontainer/dev_container_2/devcontainer.json,devcontainer.local_folder=/somepath/cli,devcontainer.metadata=[{\"id\":\"ghcr.io/devcontainers/features/common-utils:2\"},{\"id\":\"ghcr.io/devcontainers/features/git:1\",\"customizations\":{\"vscode\":{\"settings\":{\"github.copilot.chat.codeGeneration.instructions\":[{\"text\":\"This dev container includes an up-to-date version of Git, built from source as needed, pre-installed and available on the `PATH`.\"}]}}}},{\"remoteUser\":\"vscode\"}],org.opencontainers.image.ref.name=ubuntu,org.opencontainers.image.version=24.04,version=2.1.6",
 663        "LocalVolumes": "0",
 664        "Mounts": "/host_mnt/User…",
 665        "Names": "objective_haslett",
 666        "Networks": "bridge",
 667        "Platform": {
 668        "architecture": "arm64",
 669        "os": "linux"
 670        },
 671        "Ports": "",
 672        "RunningFor": "47 hours ago",
 673        "Size": "0B",
 674        "State": "running",
 675        "Status": "Up 47 hours"
 676    }
 677                    "#).into_bytes(),
 678            };
 679
 680        let result: Option<DockerPs> = deserialize_json_output(full_output).unwrap();
 681
 682        assert!(result.is_some());
 683        let result = result.unwrap();
 684        assert_eq!(result.id, "abdb6ab59573".to_string());
 685
 686        // Podman variant (Id, not ID)
 687        let full_output = Output {
 688                status: ExitStatus::default(),
 689                stderr: vec![],
 690                stdout: String::from(r#"
 691    {
 692        "Command": "\"/bin/sh -c 'echo Co…\"",
 693        "CreatedAt": "2026-02-04 15:44:21 -0800 PST",
 694        "Id": "abdb6ab59573",
 695        "Image": "mcr.microsoft.com/devcontainers/base:ubuntu",
 696        "Labels": "desktop.docker.io/mounts/0/Source=/somepath/cli,desktop.docker.io/mounts/0/SourceKind=hostFile,desktop.docker.io/mounts/0/Target=/workspaces/cli,desktop.docker.io/ports.scheme=v2,dev.containers.features=common,dev.containers.id=base-ubuntu,dev.containers.release=v0.4.24,dev.containers.source=https://github.com/devcontainers/images,dev.containers.timestamp=Fri, 30 Jan 2026 16:52:34 GMT,dev.containers.variant=noble,devcontainer.config_file=/somepath/cli/.devcontainer/dev_container_2/devcontainer.json,devcontainer.local_folder=/somepath/cli,devcontainer.metadata=[{\"id\":\"ghcr.io/devcontainers/features/common-utils:2\"},{\"id\":\"ghcr.io/devcontainers/features/git:1\",\"customizations\":{\"vscode\":{\"settings\":{\"github.copilot.chat.codeGeneration.instructions\":[{\"text\":\"This dev container includes an up-to-date version of Git, built from source as needed, pre-installed and available on the `PATH`.\"}]}}}},{\"remoteUser\":\"vscode\"}],org.opencontainers.image.ref.name=ubuntu,org.opencontainers.image.version=24.04,version=2.1.6",
 697        "LocalVolumes": "0",
 698        "Mounts": "/host_mnt/User…",
 699        "Names": "objective_haslett",
 700        "Networks": "bridge",
 701        "Platform": {
 702        "architecture": "arm64",
 703        "os": "linux"
 704        },
 705        "Ports": "",
 706        "RunningFor": "47 hours ago",
 707        "Size": "0B",
 708        "State": "running",
 709        "Status": "Up 47 hours"
 710    }
 711                    "#).into_bytes(),
 712            };
 713
 714        let result: Option<DockerPs> = deserialize_json_output(full_output).unwrap();
 715
 716        assert!(result.is_some());
 717        let result = result.unwrap();
 718        assert_eq!(result.id, "abdb6ab59573".to_string());
 719    }
 720
 721    #[test]
 722    fn should_deserialize_object_metadata_from_docker_compose_container() {
 723        // The devcontainer CLI writes metadata as a bare JSON object (not an array)
 724        // when there is only one metadata entry (e.g. docker-compose with no features).
 725        // See https://github.com/devcontainers/cli/issues/1054
 726        let given_config = r#"
 727    {
 728      "Id": "dc4e7b8ff4bf",
 729      "Config": {
 730        "Labels": {
 731          "devcontainer.metadata": "{\"remoteUser\":\"ubuntu\"}"
 732        }
 733      }
 734    }
 735                "#;
 736        let config = serde_json_lenient::from_str::<DockerInspect>(given_config).unwrap();
 737
 738        assert!(config.config.labels.metadata.is_some());
 739        let metadata = config.config.labels.metadata.unwrap();
 740        assert_eq!(metadata.len(), 1);
 741        assert!(metadata[0].contains_key("remoteUser"));
 742        assert_eq!(metadata[0]["remoteUser"], "ubuntu");
 743    }
 744
 745    #[test]
 746    fn should_deserialize_docker_compose_config() {
 747        let given_config = r#"
 748    {
 749        "name": "devcontainer",
 750        "networks": {
 751        "default": {
 752            "name": "devcontainer_default",
 753            "ipam": {}
 754        }
 755        },
 756        "services": {
 757            "app": {
 758                "command": [
 759                "sleep",
 760                "infinity"
 761                ],
 762                "depends_on": {
 763                "db": {
 764                    "condition": "service_started",
 765                    "restart": true,
 766                    "required": true
 767                }
 768                },
 769                "entrypoint": null,
 770                "environment": {
 771                "POSTGRES_DB": "postgres",
 772                "POSTGRES_HOSTNAME": "localhost",
 773                "POSTGRES_PASSWORD": "postgres",
 774                "POSTGRES_PORT": "5432",
 775                "POSTGRES_USER": "postgres"
 776                },
 777                "ports": [
 778                    {
 779                        "target": "5443",
 780                        "published": "5442"
 781                    },
 782                    {
 783                        "name": "custom port",
 784                        "protocol": "udp",
 785                        "host_ip": "127.0.0.1",
 786                        "app_protocol": "http",
 787                        "mode": "host",
 788                        "target": "8081",
 789                        "published": "8083"
 790
 791                    }
 792                ],
 793                "image": "mcr.microsoft.com/devcontainers/rust:2-1-bookworm",
 794                "network_mode": "service:db",
 795                "volumes": [
 796                {
 797                    "type": "bind",
 798                    "source": "/path/to",
 799                    "target": "/workspaces",
 800                    "bind": {
 801                    "create_host_path": true
 802                    }
 803                }
 804                ]
 805            },
 806            "db": {
 807                "command": null,
 808                "entrypoint": null,
 809                "environment": {
 810                "POSTGRES_DB": "postgres",
 811                "POSTGRES_HOSTNAME": "localhost",
 812                "POSTGRES_PASSWORD": "postgres",
 813                "POSTGRES_PORT": "5432",
 814                "POSTGRES_USER": "postgres"
 815                },
 816                "image": "postgres:14.1",
 817                "networks": {
 818                "default": null
 819                },
 820                "restart": "unless-stopped",
 821                "volumes": [
 822                {
 823                    "type": "volume",
 824                    "source": "postgres-data",
 825                    "target": "/var/lib/postgresql/data",
 826                    "volume": {}
 827                }
 828                ]
 829            }
 830        },
 831        "volumes": {
 832        "postgres-data": {
 833            "name": "devcontainer_postgres-data"
 834        }
 835        }
 836    }
 837                "#;
 838
 839        let docker_compose_config: DockerComposeConfig =
 840            serde_json_lenient::from_str(given_config).unwrap();
 841
 842        let expected_config = DockerComposeConfig {
 843            name: Some("devcontainer".to_string()),
 844            services: HashMap::from([
 845                (
 846                    "app".to_string(),
 847                    DockerComposeService {
 848                        command: vec!["sleep".to_string(), "infinity".to_string()],
 849                        image: Some(
 850                            "mcr.microsoft.com/devcontainers/rust:2-1-bookworm".to_string(),
 851                        ),
 852                        volumes: vec![MountDefinition {
 853                            mount_type: Some("bind".to_string()),
 854                            source: Some("/path/to".to_string()),
 855                            target: "/workspaces".to_string(),
 856                        }],
 857                        network_mode: Some("service:db".to_string()),
 858
 859                        ports: vec![
 860                            DockerComposeServicePort {
 861                                target: "5443".to_string(),
 862                                published: "5442".to_string(),
 863                                ..Default::default()
 864                            },
 865                            DockerComposeServicePort {
 866                                target: "8081".to_string(),
 867                                published: "8083".to_string(),
 868                                mode: Some("host".to_string()),
 869                                protocol: Some("udp".to_string()),
 870                                host_ip: Some("127.0.0.1".to_string()),
 871                                app_protocol: Some("http".to_string()),
 872                                name: Some("custom port".to_string()),
 873                            },
 874                        ],
 875                        ..Default::default()
 876                    },
 877                ),
 878                (
 879                    "db".to_string(),
 880                    DockerComposeService {
 881                        image: Some("postgres:14.1".to_string()),
 882                        volumes: vec![MountDefinition {
 883                            mount_type: Some("volume".to_string()),
 884                            source: Some("postgres-data".to_string()),
 885                            target: "/var/lib/postgresql/data".to_string(),
 886                        }],
 887                        ..Default::default()
 888                    },
 889                ),
 890            ]),
 891            volumes: HashMap::from([(
 892                "postgres-data".to_string(),
 893                DockerComposeVolume {
 894                    name: "devcontainer_postgres-data".to_string(),
 895                },
 896            )]),
 897        };
 898
 899        assert_eq!(docker_compose_config, expected_config);
 900    }
 901
 902    #[test]
 903    fn should_deserialize_compose_labels_as_map() {
 904        let given_config = r#"
 905        {
 906            "name": "devcontainer",
 907            "services": {
 908                "app": {
 909                    "image": "node:22-alpine",
 910                    "volumes": [],
 911                    "labels": {
 912                        "com.example.test": "value",
 913                        "another.label": "another-value"
 914                    }
 915                }
 916            }
 917        }
 918        "#;
 919
 920        let config: DockerComposeConfig = serde_json_lenient::from_str(given_config).unwrap();
 921        let service = config.services.get("app").unwrap();
 922        let labels = service.labels.clone().unwrap();
 923        assert_eq!(
 924            labels,
 925            HashMap::from([
 926                ("another.label".to_string(), "another-value".to_string()),
 927                ("com.example.test".to_string(), "value".to_string())
 928            ])
 929        );
 930    }
 931
 932    #[test]
 933    fn should_deserialize_compose_labels_as_array() {
 934        let given_config = r#"
 935        {
 936            "name": "devcontainer",
 937            "services": {
 938                "app": {
 939                    "image": "node:22-alpine",
 940                    "volumes": [],
 941                    "labels": ["com.example.test=value"]
 942                }
 943            }
 944        }
 945        "#;
 946
 947        let config: DockerComposeConfig = serde_json_lenient::from_str(given_config).unwrap();
 948        let service = config.services.get("app").unwrap();
 949        assert_eq!(
 950            service.labels,
 951            Some(HashMap::from([(
 952                "com.example.test".to_string(),
 953                "value".to_string()
 954            )]))
 955        );
 956    }
 957
 958    #[test]
 959    fn should_deserialize_compose_without_volumes() {
 960        let given_config = r#"
 961        {
 962            "name": "devcontainer",
 963            "services": {
 964                "app": {
 965                    "image": "node:22-alpine",
 966                    "volumes": []
 967                }
 968            }
 969        }
 970        "#;
 971
 972        let config: DockerComposeConfig = serde_json_lenient::from_str(given_config).unwrap();
 973        assert!(config.volumes.is_empty());
 974    }
 975
 976    #[test]
 977    fn should_deserialize_compose_with_missing_volumes_field() {
 978        let given_config = r#"
 979        {
 980            "name": "devcontainer",
 981            "services": {
 982                "sidecar": {
 983                    "image": "ubuntu:24.04"
 984                }
 985            }
 986        }
 987        "#;
 988
 989        let config: DockerComposeConfig = serde_json_lenient::from_str(given_config).unwrap();
 990        let service = config.services.get("sidecar").unwrap();
 991        assert!(service.volumes.is_empty());
 992    }
 993
 994    #[test]
 995    fn should_deserialize_compose_volume_without_source() {
 996        let given_config = r#"
 997        {
 998            "name": "devcontainer",
 999            "services": {
1000                "app": {
1001                    "image": "ubuntu:24.04",
1002                    "volumes": [
1003                        {
1004                            "type": "tmpfs",
1005                            "target": "/tmp"
1006                        }
1007                    ]
1008                }
1009            }
1010        }
1011        "#;
1012
1013        let config: DockerComposeConfig = serde_json_lenient::from_str(given_config).unwrap();
1014        let service = config.services.get("app").unwrap();
1015        assert_eq!(service.volumes.len(), 1);
1016        assert_eq!(service.volumes[0].source, None);
1017        assert_eq!(service.volumes[0].target, "/tmp");
1018        assert_eq!(service.volumes[0].mount_type, Some("tmpfs".to_string()));
1019    }
1020
1021    #[test]
1022    fn should_deserialize_inspect_without_labels() {
1023        let given_config = r#"
1024        {
1025            "Id": "sha256:abc123",
1026            "Config": {
1027                "Env": ["PATH=/usr/bin"],
1028                "Cmd": ["node"],
1029                "WorkingDir": "/"
1030            }
1031        }
1032        "#;
1033
1034        let inspect: DockerInspect = serde_json_lenient::from_str(given_config).unwrap();
1035        assert!(inspect.config.labels.metadata.is_none());
1036        assert!(inspect.config.image_user.is_none());
1037    }
1038
1039    #[test]
1040    fn should_deserialize_inspect_with_null_labels() {
1041        let given_config = r#"
1042        {
1043            "Id": "sha256:abc123",
1044            "Config": {
1045                "Labels": null,
1046                "Env": ["PATH=/usr/bin"]
1047            }
1048        }
1049        "#;
1050
1051        let inspect: DockerInspect = serde_json_lenient::from_str(given_config).unwrap();
1052        assert!(inspect.config.labels.metadata.is_none());
1053    }
1054
1055    #[test]
1056    fn should_deserialize_inspect_with_labels_but_no_metadata() {
1057        let given_config = r#"
1058        {
1059            "Id": "sha256:abc123",
1060            "Config": {
1061                "Labels": {
1062                    "com.example.test": "value"
1063                },
1064                "Env": ["PATH=/usr/bin"]
1065            }
1066        }
1067        "#;
1068
1069        let inspect: DockerInspect = serde_json_lenient::from_str(given_config).unwrap();
1070        assert!(inspect.config.labels.metadata.is_none());
1071    }
1072}