1 from sfa.util.xrn import get_authority, urn_to_hrn
2 from sfa.util.sfalogging import logger
9 rspec_to_slice_tag = {'max_rate':'net_max_rate'}
11 #def __init__(self, api, ttl = .5, origin_hrn=None):
13 ##filepath = path + os.sep + filename
14 #self.policy = Policy(self.api)
15 #self.origin_hrn = origin_hrn
16 #self.registry = api.registries[api.hrn]
17 #self.credential = api.getCredential()
22 def __init__(self, driver):
26 #def get_slivers(self, xrn, node=None):
27 #hrn, hrn_type = urn_to_hrn(xrn)
29 #slice_name = hrn_to_pl_slicename(hrn)
30 ## XX Should we just call PLCAPI.GetSliceTicket(slice_name) instead
31 ## of doing all of this?
32 ##return self.api.driver.GetSliceTicket(self.auth, slice_name)
36 #sfa_slice = self.driver.GetSlices(slice_filter = slice_name, \
37 # slice_filter_type = 'slice_hrn')
40 ## Get user information
42 #alchemy_person = dbsession.query(RegRecord).filter_by(record_id = \
43 #sfa_slice['record_id_user']).first()
46 #sliver_attributes = []
48 #if sfa_slice['oar_job_id'] is not -1:
49 #nodes_all = self.driver.GetNodes({'hostname': \
50 #sfa_slice['node_ids']},
51 #['node_id', 'hostname','site','boot_state'])
52 #nodeall_byhostname = dict([(n['hostname'], n) for n in nodes_all])
53 #nodes = sfa_slice['node_ids']
56 ##for sliver_attribute in filter(lambda a: a['node_id'] == \
57 #node['node_id'], slice_tags):
58 #sliver_attribute['tagname'] = 'slab-tag'
59 #sliver_attribute['value'] = 'slab-value'
60 #sliver_attributes.append(sliver_attribute['tagname'])
61 #attributes.append({'tagname': sliver_attribute['tagname'],
62 #'value': sliver_attribute['value']})
64 ## set nodegroup slice attributes
65 #for slice_tag in filter(lambda a: a['nodegroup_id'] \
66 #in node['nodegroup_ids'], slice_tags):
67 ## Do not set any nodegroup slice attributes for
68 ## which there is at least one sliver attribute
70 #if slice_tag not in slice_tags:
71 #attributes.append({'tagname': slice_tag['tagname'],
72 #'value': slice_tag['value']})
74 #for slice_tag in filter(lambda a: a['node_id'] is None, \
76 ## Do not set any global slice attributes for
77 ## which there is at least one sliver attribute
79 #if slice_tag['tagname'] not in sliver_attributes:
80 #attributes.append({'tagname': slice_tag['tagname'],
81 #'value': slice_tag['value']})
83 ## XXX Sanity check; though technically this should
84 ## be a system invariant
85 ## checked with an assertion
86 #if sfa_slice['expires'] > MAXINT: sfa_slice['expires']= MAXINT
90 #'name': sfa_slice['name'],
91 #'slice_id': sfa_slice['slice_id'],
92 #'instantiation': sfa_slice['instantiation'],
93 #'expires': sfa_slice['expires'],
95 #'attributes': attributes
105 def get_peer(self, xrn):
106 hrn, hrn_type = urn_to_hrn(xrn)
107 #Does this slice belong to a local site or a peer senslab site?
110 # get this slice's authority (site)
111 slice_authority = get_authority(hrn)
112 site_authority = slice_authority
113 # get this site's authority (sfa root authority or sub authority)
114 #site_authority = get_authority(slice_authority).lower()
115 logger.debug("SLABSLICES \ get_peer slice_authority %s \
116 site_authority %s hrn %s" %(slice_authority, \
117 site_authority, hrn))
118 #This slice belongs to the current site
119 if site_authority == self.driver.root_auth :
121 # check if we are already peered with this site_authority, if so
122 #peers = self.driver.GetPeers({})
123 peers = self.driver.GetPeers(peer_filter = slice_authority)
124 for peer_record in peers:
126 if site_authority == peer_record.hrn:
128 logger.debug(" SLABSLICES \tget_peer peer %s " %(peer))
131 def get_sfa_peer(self, xrn):
132 hrn, hrn_type = urn_to_hrn(xrn)
134 # return the authority for this hrn or None if we are the authority
136 slice_authority = get_authority(hrn)
137 site_authority = get_authority(slice_authority)
139 if site_authority != self.driver.hrn:
140 sfa_peer = site_authority
145 def verify_slice_leases(self, sfa_slice, requested_jobs_dict, kept_leases, \
149 #First get the list of current leases from OAR
150 leases = self.driver.GetLeases({'name':sfa_slice['name']}, ['lease_id'])
152 current_leases = [lease['lease_id'] for lease in leases]
153 #Deleted leases are the ones with lease id not declared in the Rspec
154 deleted_leases = list(set(current_leases).difference(kept_leases))
158 #peer = RegAuyhority object is unsubscriptable
159 #TODO :UnBindObjectFromPeer Quick and dirty auth='senslab2 SA 27/07/12
160 self.driver.UnBindObjectFromPeer('senslab2', 'slice', \
161 sfa_slice['record_id_slice'], peer.hrn)
163 self.driver.DeleteLeases(deleted_leases, \
166 #TODO : catch other exception?
168 logger.log_exc('Failed to add/remove slice leases')
171 for start_time in requested_jobs_dict:
172 job = requested_jobs_dict[start_time]
173 self.driver.AddLeases(job['hostname'], \
174 sfa_slice, int(job['start_time']), \
175 int(job['duration']))
179 def verify_slice_nodes(self, sfa_slice, requested_slivers, peer):
183 if sfa_slice['node_ids']:
184 nodes = self.driver.GetNodes(sfa_slice['node_ids'], ['hostname'])
185 current_slivers = [node['hostname'] for node in nodes]
187 # remove nodes not in rspec
188 deleted_nodes = list(set(current_slivers).\
189 difference(requested_slivers))
190 # add nodes from rspec
191 #added_nodes = list(set(requested_slivers).difference(current_slivers))
193 #Update the table with the nodes that populate the slice
194 logger.debug("SLABSLICES \tverify_slice_nodes slice %s\
195 \r\n \r\n deleted_nodes %s"\
196 %(sfa_slice,deleted_nodes))
199 self.driver.DeleteSliceFromNodes(sfa_slice['name'], \
205 def free_egre_key(self):
207 for tag in self.driver.GetSliceTags({'tagname': 'egre_key'}):
208 used.add(int(tag['value']))
210 for i in range(1, 256):
215 raise KeyError("No more EGRE keys available")
224 def handle_peer(self, site, sfa_slice, persons, peer):
229 self.driver.BindObjectToPeer('site', site['site_id'], \
230 peer['shortname'], sfa_slice['site_id'])
231 except Exception, error:
232 self.driver.DeleteSite(site['site_id'])
238 self.driver.BindObjectToPeer('slice', slice['slice_id'], \
239 peer['shortname'], sfa_slice['slice_id'])
240 except Exception, error:
241 self.driver.DeleteSlice(sfa_slice['slice_id'])
245 for person in persons:
247 self.driver.BindObjectToPeer('person', \
248 person['person_id'], peer['shortname'], \
249 person['peer_person_id'])
251 for (key, remote_key_id) in zip(person['keys'], \
254 self.driver.BindObjectToPeer( 'key', \
255 key['key_id'], peer['shortname'], \
258 self.driver.DeleteKey(key['key_id'])
259 logger.log_exc("failed to bind key: %s \
260 to peer: %s " % (key['key_id'], \
262 except Exception, error:
263 self.driver.DeletePerson(person['person_id'])
268 #def verify_site(self, slice_xrn, slice_record={}, peer=None, \
269 #sfa_peer=None, options={}):
270 #(slice_hrn, type) = urn_to_hrn(slice_xrn)
271 #site_hrn = get_authority(slice_hrn)
272 ## login base can't be longer than 20 characters
273 ##slicename = hrn_to_pl_slicename(slice_hrn)
274 #authority_name = slice_hrn.split('.')[0]
275 #login_base = authority_name[:20]
276 #logger.debug(" SLABSLICES.PY \tverify_site authority_name %s \
277 #login_base %s slice_hrn %s" \
278 #%(authority_name,login_base,slice_hrn)
280 #sites = self.driver.GetSites(login_base)
282 ## create new site record
283 #site = {'name': 'geni.%s' % authority_name,
284 #'abbreviated_name': authority_name,
285 #'login_base': login_base,
287 #'max_slivers': 1000,
289 #'peer_site_id': None}
291 #site['peer_site_id'] = slice_record.get('site_id', None)
292 #site['site_id'] = self.driver.AddSite(site)
293 ## exempt federated sites from monitor policies
294 #self.driver.AddSiteTag(site['site_id'], 'exempt_site_until', \
297 ### is this still necessary?
298 ### add record to the local registry
299 ##if sfa_peer and slice_record:
300 ##peer_dict = {'type': 'authority', 'hrn': site_hrn, \
301 ##'peer_authority': sfa_peer, 'pointer': \
303 ##self.registry.register_peer_object(self.credential, peer_dict)
307 ## unbind from peer so we can modify if necessary.
308 ## Will bind back later
309 #self.driver.UnBindObjectFromPeer('site', site['site_id'], \
314 def verify_slice(self, slice_hrn, slice_record, peer, sfa_peer):
316 #login_base = slice_hrn.split(".")[0]
317 slicename = slice_hrn
318 slices_list = self.driver.GetSlices(slice_filter = slicename, \
319 slice_filter_type = 'slice_hrn')
321 for sl in slices_list:
323 logger.debug("SLABSLICE \tverify_slice slicename %s sl %s \
324 slice_record %s"%(slicename, sl, slice_record))
326 sfa_slice.update(slice_record)
327 #del slice['last_updated']
328 #del slice['date_created']
330 #slice['peer_slice_id'] = slice_record.get('slice_id', None)
331 ## unbind from peer so we can modify if necessary.
332 ## Will bind back later
333 #self.driver.UnBindObjectFromPeer('slice', slice['slice_id'], \
335 #Update existing record (e.g. expires field)
336 #it with the latest info.
337 ##if slice_record and slice['expires'] != slice_record['expires']:
338 ##self.driver.UpdateSlice( slice['slice_id'], {'expires' : \
339 #slice_record['expires']})
341 logger.debug(" SLABSLICES \tverify_slice Oups \
342 slice_record %s peer %s sfa_peer %s "\
343 %(slice_record, peer,sfa_peer))
344 sfa_slice = {'slice_hrn': slicename,
345 #'url': slice_record.get('url', slice_hrn),
346 #'description': slice_record.get('description', slice_hrn)
348 'record_id_user' : slice_record['person_ids'][0],
349 'record_id_slice': slice_record['record_id'],
350 'peer_authority':str(peer.hrn)
354 self.driver.AddSlice(sfa_slice)
355 #slice['slice_id'] = self.driver.AddSlice(slice)
356 logger.debug("SLABSLICES \tverify_slice ADDSLICE OK")
357 #slice['node_ids']=[]
358 #slice['person_ids'] = []
360 #slice['peer_slice_id'] = slice_record.get('slice_id', None)
361 # mark this slice as an sfa peer record
363 #peer_dict = {'type': 'slice', 'hrn': slice_hrn,
364 #'peer_authority': sfa_peer, 'pointer': \
366 #self.registry.register_peer_object(self.credential, peer_dict)
373 def verify_persons(self, slice_hrn, slice_record, users, peer, sfa_peer, \
381 if 'urn' in user and (not 'hrn' in user ) :
382 user['hrn'], user['type'] = urn_to_hrn(user['urn'])
384 if 'person_id' in user and 'hrn' in user:
385 users_by_id[user['person_id']] = user
386 users_dict[user['person_id']] = {'person_id':\
387 user['person_id'], 'hrn':user['hrn']}
389 users_by_hrn[user['hrn']] = user
390 users_dict[user['hrn']] = {'person_id':user['person_id'], \
394 logger.debug( "SLABSLICE.PY \tverify_person \
395 users_dict %s \r\n user_by_hrn %s \r\n \
397 %(users_dict,users_by_hrn, users_by_id))
399 existing_user_ids = []
400 existing_user_hrns = []
402 #Check if user is in LDAP using its hrn.
403 #Assuming Senslab is centralised : one LDAP for all sites,
404 # user_id unknown from LDAP
405 # LDAP does not provide users id, therfore we rely on hrns
407 #Construct the list of filters for GetPersons
409 for hrn in users_by_hrn:
410 #filter_user.append ( {'hrn':hrn})
411 filter_user.append (users_by_hrn[hrn])
412 logger.debug(" SLABSLICE.PY \tverify_person filter_user %s " \
414 existing_users = self.driver.GetPersons(filter_user)
415 #existing_users = self.driver.GetPersons({'hrn': \
416 #users_by_hrn.keys()})
417 #existing_users = self.driver.GetPersons({'hrn': \
418 #users_by_hrn.keys()}, \
421 for user in existing_users :
422 #for k in users_dict[user['hrn']] :
424 existing_user_hrns.append(users_dict[user['hrn']]['hrn'])
426 append(users_dict[user['hrn']]['person_id'])
428 #User from another federated site ,
429 #does not have a senslab account yet?
430 #or have multiple SFA accounts
431 #Check before adding them to LDAP
435 if isinstance(users, list):
436 ldap_reslt = self.driver.ldap.LdapSearch(users[0])
438 ldap_reslt = self.driver.ldap.LdapSearch(users)
440 existing_users = ldap_reslt[0]
441 #TODO : DEBUG user undefined ? SA 14/08/12
442 existing_user_hrns.append(users_dict[user['hrn']]['hrn'])
444 append(users_dict[user['hrn']]['person_id'])
446 #User not existing in LDAP
448 logger.debug(" SLABSLICE.PY \tverify_person users \
449 not in ldap ... %s \r\n \t ldap_reslt %s " \
450 %(users, ldap_reslt))
453 # requested slice users
454 requested_user_ids = users_by_id.keys()
455 requested_user_hrns = users_by_hrn.keys()
456 logger.debug("SLABSLICE.PY \tverify_person requested_user_ids %s \
457 user_by_hrn %s " %(requested_user_ids, users_by_hrn))
458 # existing slice users
460 #existing_slice_users_filter = {'hrn': slice_record['PI'][0]}
461 #logger.debug(" SLABSLICE.PY \tverify_person requested_user_ids %s \
462 #existing_slice_users_filter %s slice_record %s" %(requested_user_ids,\
463 #existing_slice_users_filter,slice_record))
465 #existing_slice_users = \
466 #self.driver.GetPersons([existing_slice_users_filter])
467 #existing_slice_users = \
468 #self.driver.GetPersons(existing_slice_users_filter, \
470 #logger.debug("SLABSLICE.PY \tverify_person existing_slice_users %s " \
471 #%(existing_slice_users))
472 #Check that the user of the slice in the slice record
473 #matches the existing users
475 if slice_record['record_id_user'] in requested_user_ids and \
476 slice_record['PI'][0] in requested_user_hrns:
477 logger.debug(" SLABSLICE \tverify_person \
478 requested_user_ids %s = \
479 slice_record['record_id_user'] %s" \
480 %(requested_user_ids,slice_record['record_id_user']))
485 #existing_slice_user_hrns = [user['hrn'] for \
486 #user in existing_slice_users]
488 # users to be added, removed or updated
489 #One user in one senslab slice : there should be no need
490 #to remove/ add any user from/to a slice.
491 #However a user from SFA which is not registered in Senslab yet
492 #should be added to the LDAP.
494 added_user_hrns = set(requested_user_hrns).\
495 difference(set(existing_user_hrns))
497 #self.verify_keys(existing_slice_users, updated_users_list, \
502 for added_user_hrn in added_user_hrns:
503 added_user = users_dict[added_user_hrn]
504 #hrn, type = urn_to_hrn(added_user['urn'])
506 'first_name': added_user.get('first_name', hrn),
507 'last_name': added_user.get('last_name', hrn),
508 'person_id': added_user['person_id'],
509 'peer_person_id': None,
511 'key_ids': added_user.get('key_ids', []),
514 person['person_id'] = self.driver.AddPerson(person)
516 person['peer_person_id'] = added_user['person_id']
517 added_persons.append(person)
520 self.driver.UpdatePerson(person['person_id'], {'enabled': True})
523 #self.driver.AddPersonToSite(added_user_id, login_base)
525 #for key_string in added_user.get('keys', []):
526 #key = {'key':key_string, 'key_type':'ssh'}
527 #key['key_id'] = self.driver.AddPersonKey(person['person_id'], \
529 #person['keys'].append(key)
531 # add the registry record
533 #peer_dict = {'type': 'user', 'hrn': hrn, 'peer_authority': \
535 #'pointer': person['person_id']}
536 #self.registry.register_peer_object(self.credential, peer_dict)
537 #for added_slice_user_hrn in \
538 #added_slice_user_hrns.union(added_user_hrns):
539 #self.driver.AddPersonToSlice(added_slice_user_hrn, \
540 #slice_record['name'])
541 #for added_slice_user_id in \
542 #added_slice_user_ids.union(added_user_ids):
543 # add person to the slice
544 #self.driver.AddPersonToSlice(added_slice_user_id, \
545 #slice_record['name'])
546 # if this is a peer record then it
547 # should already be bound to a peer.
548 # no need to return worry about it getting bound later
553 def verify_keys(self, persons, users, peer, options={}):
556 for person in persons:
557 key_ids.extend(person['key_ids'])
558 keylist = self.driver.GetKeys(key_ids, ['key_id', 'key'])
561 keydict[key['key']] = key['key_id']
562 existing_keys = keydict.keys()
564 for person in persons:
565 persondict[person['email']] = person
571 user_keys = user.get('keys', [])
572 updated_persons.append(user)
573 for key_string in user_keys:
574 requested_keys.append(key_string)
575 if key_string not in existing_keys:
576 key = {'key': key_string, 'key_type': 'ssh'}
579 person = persondict[user['email']]
580 self.driver.UnBindObjectFromPeer('person', \
581 person['person_id'], peer['shortname'])
583 self.driver.AddPersonKey(user['email'], key)
585 key_index = user_keys.index(key['key'])
586 remote_key_id = user['key_ids'][key_index]
587 self.driver.BindObjectToPeer('key', \
588 key['key_id'], peer['shortname'], \
593 self.driver.BindObjectToPeer('person', \
594 person['person_id'], peer['shortname'], \
597 # remove old keys (only if we are not appending)
598 append = options.get('append', True)
600 removed_keys = set(existing_keys).difference(requested_keys)
601 for existing_key_id in keydict:
602 if keydict[existing_key_id] in removed_keys:
605 self.driver.UnBindObjectFromPeer('key', \
606 existing_key_id, peer['shortname'])
607 self.driver.DeleteKey(existing_key_id)
610 #def verify_slice_attributes(self, slice, requested_slice_attributes, \
611 #append=False, admin=False):
612 ## get list of attributes users ar able to manage
613 #filter = {'category': '*slice*'}
615 #filter['|roles'] = ['user']
616 #slice_attributes = self.driver.GetTagTypes(filter)
617 #valid_slice_attribute_names = [attribute['tagname'] \
618 #for attribute in slice_attributes]
620 ## get sliver attributes
621 #added_slice_attributes = []
622 #removed_slice_attributes = []
623 #ignored_slice_attribute_names = []
624 #existing_slice_attributes = self.driver.GetSliceTags({'slice_id': \
627 ## get attributes that should be removed
628 #for slice_tag in existing_slice_attributes:
629 #if slice_tag['tagname'] in ignored_slice_attribute_names:
630 ## If a slice already has a admin only role
631 ## it was probably given to them by an
632 ## admin, so we should ignore it.
633 #ignored_slice_attribute_names.append(slice_tag['tagname'])
635 ## If an existing slice attribute was not
636 ## found in the request it should
638 #attribute_found=False
639 #for requested_attribute in requested_slice_attributes:
640 #if requested_attribute['name'] == slice_tag['tagname'] \
641 #and requested_attribute['value'] == slice_tag['value']:
642 #attribute_found=True
645 #if not attribute_found and not append:
646 #removed_slice_attributes.append(slice_tag)
648 ## get attributes that should be added:
649 #for requested_attribute in requested_slice_attributes:
650 ## if the requested attribute wasn't found we should add it
651 #if requested_attribute['name'] in valid_slice_attribute_names:
652 #attribute_found = False
653 #for existing_attribute in existing_slice_attributes:
654 #if requested_attribute['name'] == \
655 #existing_attribute['tagname'] and \
656 #requested_attribute['value'] == \
657 #existing_attribute['value']:
658 #attribute_found=True
660 #if not attribute_found:
661 #added_slice_attributes.append(requested_attribute)
664 ## remove stale attributes
665 #for attribute in removed_slice_attributes:
667 #self.driver.DeleteSliceTag(attribute['slice_tag_id'])
668 #except Exception, error:
669 #self.logger.warn('Failed to remove sliver attribute. name: \
670 #%s, value: %s, node_id: %s\nCause:%s'\
671 #% (name, value, node_id, str(error)))
673 ## add requested_attributes
674 #for attribute in added_slice_attributes:
676 #self.driver.AddSliceTag(slice['name'], attribute['name'], \
677 #attribute['value'], attribute.get('node_id', None))
678 #except Exception, error:
679 #self.logger.warn('Failed to add sliver attribute. name: %s, \
680 #value: %s, node_id: %s\nCause:%s'\
681 #% (name, value, node_id, str(error)))