check slice policy before creating slices
[sfa.git] / geni / util / slices.py
1 import datetime
2 import time
3 from geni.util.misc import *
4 from geni.util.rspec import *
5 from geni.util.specdict import *
6 from geni.util.excep import *
7 from geni.util.storage import *
8 from geni.util.policy import Policy
9 from geni.util.debug import log
10 from geni.aggregate import Aggregates
11 from geni.registry import Registries
12
13 class Slices(SimpleStorage):
14
15     def __init__(self, api, ttl = .5):
16         self.api = api
17         self.ttl = ttl
18         self.threshold = None
19         self.slices_file = os.sep.join([self.api.server_basedir, self.api.interface +'.'+ self.api.hrn + '.slices'])
20         SimpleStorage.__init__(self, self.slices_file)
21         self.policy = Policy(self.api)    
22         self.load()
23
24
25     def refresh(self):
26         """
27         Update the cached list of slices
28         """
29         # Reload components list
30         now = datetime.datetime.now()
31         if not self.has_key('threshold') or not self.has_key('timestamp') or \
32            now > datetime.datetime.fromtimestamp(time.mktime(time.strptime(self['threshold'], self.api.time_format))):
33             if self.api.interface in ['aggregate']:
34                 self.refresh_slices_aggregate()
35             elif self.api.interface in ['slicemgr']:
36                 self.refresh_slices_smgr()
37
38     def refresh_slices_aggregate(self):
39         slices = self.api.plshell.GetSlices(self.api.plauth, {}, ['name'])
40         slice_hrns = [slicename_to_hrn(self.api.hrn, slice['name']) for slice in slices]
41
42          # update timestamp and threshold
43         timestamp = datetime.datetime.now()
44         hr_timestamp = timestamp.strftime(self.api.time_format)
45         delta = datetime.timedelta(hours=self.ttl)
46         threshold = timestamp + delta
47         hr_threshold = threshold.strftime(self.api.time_format)
48         
49         slice_details = {'hrn': slice_hrns,
50                          'timestamp': hr_timestamp,
51                          'threshold': hr_threshold
52                         }
53         self.update(slice_details)
54         self.write()     
55         
56
57     def refresh_slices_smgr(self):
58         slice_hrns = []
59         aggregates = Aggregates(self.api)
60         credential = self.api.getCredential()
61         for aggregate in aggregates:
62             try:
63                 slices = aggregates[aggregate].slices(credential)
64                 slice_hrns.extend(slices)
65             except:
66                 print >> log, "Error calling slices at aggregate %(aggregate)s" % locals()
67          # update timestamp and threshold
68         timestamp = datetime.datetime.now()
69         hr_timestamp = timestamp.strftime(self.api.time_format)
70         delta = datetime.timedelta(hours=self.ttl)
71         threshold = timestamp + delta
72         hr_threshold = threshold.strftime(self.api.time_format)
73
74         slice_details = {'hrn': slice_hrns,
75                          'timestamp': hr_timestamp,
76                          'threshold': hr_threshold
77                         }
78         self.update(slice_details)
79         self.write()
80
81
82     def delete_slice(self, hrn):
83         if self.api.interface in ['aggregate']:
84             self.delete_slice_aggregate(hrn)
85         elif self.api.interface in ['slicemgr']:
86             self.delete_slice_smgr(hrn)
87         
88     def delete_slice_aggregate(self, hrn):
89         slicename = hrn_to_pl_slicename(hrn)
90         slices = self.api.plshell.GetSlices(self.api.plauth, [slicename])
91         if not slices:
92             return 1        
93         slice = slices[0]
94
95         self.api.plshell.DeleteSliceFromNodes(self.api.plauth, slicename, slice['node_ids'])
96         return 1
97
98     def delete_slice_smgr(self, hrn):
99         credential = self.api.getCredential()
100         aggregates = Aggregates(self.api)
101         for aggregate in aggregates:
102             aggregates[aggregate].delete_slice(credential, hrn)
103
104     def create_slice(self, hrn, rspec):
105         # check our slice policy before we procede
106         whitelist = self.policy['slice_whitelist']     
107         blacklist = self.policy['slice_blacklist']
108         
109         if whitelist and hrn not in whitelist or \
110            blacklist and hrn in blacklist:
111             policy_file = self.policy.policy_file
112             print >> log, "Slice %(hrn)s not allowed by policy %(policy_file)s" % locals()
113             return 1
114         if self.api.interface in ['aggregate']:     
115             self.create_slice_aggregate(hrn, rspec)
116         elif self.api.interface in ['slicemgr']:
117             self.create_slice_smgr(hrn, rspec)
118  
119     def create_slice_aggregate(self, hrn, rspec):    
120         spec = Rspec(rspec)
121         # Get the slice record from geni
122         slice = {}
123         registries = Registries(self.api)
124         registry = registries[self.api.hrn]
125         credential = self.api.getCredential()
126         records = registry.resolve(credential, hrn)
127         for record in records:
128             if record.get_type() in ['slice']:
129                 slice_info = record.as_dict()
130                 slice = slice_info['pl_info']
131         if not slice:
132             raise RecordNotFound(slice_hrn)   
133
134         # Make sure slice exists at plc, if it doesnt add it
135         slicename = hrn_to_pl_slicename(hrn)
136         slices = self.api.plshell.GetSlices(self.api.plauth, [slicename], ['node_ids'])
137         if not slices:
138             parts = slicename.split("_")
139             login_base = parts[0]
140             # if site doesnt exist add it
141             sites = self.api.plshell.GetSites(self.api.plauth, [login_base])
142             if not sites:
143                 authority = get_authority(hrn)
144                 site_records = registry.resolve(credential, authority)
145                 site_record = {}
146                 if not site_records:
147                     raise RecordNotFound(authority)
148                 site_record = site_records[0]
149                 site_info = site_record.as_dict()
150                 site = site_info['pl_info']
151                 
152                  # add the site
153                 site.pop('site_id')
154                 site_id = self.api.plshell.AddSite(self.api.plauth, site)
155             else:
156                 site = sites[0]
157
158             self.api.plshell.AddSlice(self.api.plauth, slice)
159
160         # get the list of valid slice users from the registry and make 
161         # they are added to the slice 
162         geni_info = slice_info['geni_info']
163         researchers = geni_info['researcher']
164         for researcher in researchers:
165             person_record = {}
166             person_records = registry.resolve(credential, researcher)
167             for record in person_records:
168                 if record.get_type() in ['user']:
169                     person_record = record
170             if not person_record:
171                 pass
172             person_dict = person_record.as_dict()['pl_info']
173             persons = self.api.plshell.GetPersons(self.api.plauth, [person_dict['email']], ['person_id', 'key_ids'])
174
175             # Create the person record 
176             if not persons:
177                 self.api.plshell.AddPerson(self.api.plauth, person_dict)
178                 key_ids = []
179             else:
180                 key_ids = persons[0]['key_ids']
181
182             self.api.plshell.AddPersonToSlice(self.api.plauth, person_dict['email'], slicename)        
183
184             # Get this users local keys
185             keylist = self.api.plshell.GetKeys(self.api.plauth, key_ids, ['key'])
186             keys = [key['key'] for key in keylist]
187
188             # add keys that arent already there 
189             for personkey in person_dict['keys']:
190                 if personkey not in keys:
191                     key = {'key_type': 'ssh', 'key': personkey}
192                     self.api.plshell.AddPersonKey(self.api.plauth, person_dict['email'], key)
193
194         # find out where this slice is currently running
195         nodelist = self.api.plshell.GetNodes(self.api.plauth, slice['node_ids'], ['hostname'])
196         hostnames = [node['hostname'] for node in nodelist]
197
198         # get netspec details
199         nodespecs = spec.getDictsByTagName('NodeSpec')
200         nodes = []
201         for nodespec in nodespecs:
202             if isinstance(nodespec['name'], list):
203                 nodes.extend(nodespec['name'])
204             elif isinstance(nodespec['name'], StringTypes):
205                 nodes.append(nodespec['name'])
206
207         # remove nodes not in rspec
208         deleted_nodes = list(set(hostnames).difference(nodes))
209         # add nodes from rspec
210         added_nodes = list(set(nodes).difference(hostnames))
211
212         self.api.plshell.AddSliceToNodes(self.api.plauth, slicename, added_nodes) 
213         self.api.plshell.DeleteSliceFromNodes(self.api.plauth, slicename, deleted_nodes)
214
215         return 1
216
217     def create_slice_smgr(self, hrn, rspec):
218         spec = Rspec()
219         tempspec = Rspec()
220         spec.parseString(rspec)
221         slicename = hrn_to_pl_slicename(hrn)
222         specDict = spec.toDict()
223         if specDict.has_key('Rspec'): specDict = specDict['Rspec']
224         if specDict.has_key('start_time'): start_time = specDict['start_time']
225         else: start_time = 0
226         if specDict.has_key('end_time'): end_time = specDict['end_time']
227         else: end_time = 0
228
229         rspecs = {}
230         aggregates = Aggregates(self.api)
231         credential = self.api.getCredential()
232         # only attempt to extract information about the aggregates we know about
233         for aggregate in aggregates:
234             netspec = spec.getDictByTagNameValue('NetSpec', aggregate)
235             if netspec:
236                 # creat a plc dict 
237                 resources = {'start_time': start_time, 'end_time': end_time, 'networks': netspec}
238                 resourceDict = {'Rspec': resources}
239                 tempspec.parseDict(resourceDict)
240                 rspecs[aggregate] = tempspec.toxml()
241
242         # notify the aggregates
243         for aggregate in rspecs.keys():
244             try:
245                 aggregates[aggregate].create_slice(credential, hrn, rspecs[aggregate])
246             except:
247                 print >> log, "Error creating slice %(hrn)% at aggregate %(aggregate)%" % locals()
248     
249         return 1
250
251
252     def start_slice(self, hrn):
253         if self.api.interface in ['aggregate']:
254             self.start_slice_aggregate()
255         elif self.api.interface in ['slicemgr']:
256             self.start_slice_smgr()
257
258     def start_slice_aggregate(self, hrn):
259         slicename = hrn_to_pl_slicename(hrn)
260         slices = self.api.plshell.GetSlices(self.api.plauth, {'name': slicename}, ['slice_id'])
261         if not slices:
262             raise RecordNotFound(hrn)
263         slice_id = slices[0]
264         attributes = self.api.plshell.GetSliceAttributes(self.api.plauth, {'slice_id': slice_id, 'name': 'enabled'}, ['slice_attribute_id'])
265         attribute_id = attreibutes[0]['slice_attribute_id']
266         self.api.plshell.UpdateSliceAttribute(self.api.plauth, attribute_id, "1" )
267         return 1
268
269     def start_slice_smgr(self, hrn):
270         credential = self.api.getCredential()
271         aggregates = Aggregates()
272         for aggregate in aggregates:
273             aggreegates[aggregate].start_slice(credential, hrn)
274         return 1
275
276
277     def stop_slice(self, hrn):
278         if self.api.interface in ['aggregate']:
279             self.stop_slice_aggregate()
280         elif self.api.interface in ['slicemgr']:
281             self.stop_slice_smgr()
282
283     def stop_slice_aggregate(self, hrn):
284         slicename = hrn_to_pl_slicename(hrn)
285         slices = self.api.plshell.GetSlices(self.api.plauth, {'name': slicename}, ['slice_id'])
286         if not slices:
287             raise RecordNotFound(hrn)
288         slice_id = slices[0]
289         attributes = self.api.plshell.GetSliceAttributes(self.api.plauth, {'slice_id': slice_id, 'name': 'enabled'}, ['slice_attribute_id'])
290         attribute_id = attributes[0]['slice_attribute_id']
291         self.api.plshell.UpdateSliceAttribute(self.api.plauth, attribute_id, "0")
292         return 1
293
294     def stop_slice_smgr(self, hrn):
295         credential = self.api.getCredential()
296         aggregates = Aggregates()
297         for aggregate in aggregates:
298             aggregate[aggregate].stop_slice(credential, hrn)  
299