Make usage of sliver auth configurable from the _default slice attribute
[nodemanager.git] / plugins / sliverauth.py
index ba1b30b..f22a60d 100644 (file)
@@ -12,35 +12,33 @@ import os
 import random
 import string
 import tempfile
+import time
 
 import logger
 import tools
 
 def start(options, conf):
-    # XXX REMOVE ME
-    return
-
     logger.log("sliverauth plugin starting up...")
 
 def SetSliverTag(plc, slice, tagname, value):
     node_id = tools.node_id()
-    slivertags=plc.GetSliceTags({"name":slice,"node_id":node_id})
+    slivertags=plc.GetSliceTags({"name":slice,"node_id":node_id,"tagname":tagname})
     if len(slivertags)==0:
         slivertag_id=plc.AddSliceTag(slice,tagname,value,node_id)
     else:
         slivertag_id=slivertags[0]['slice_tag_id']
         plc.UpdateSliceTag(slivertag_id,value)
 
-def GetSlivers(plc, data, conf):
-    # XXX REMOVE ME
-    logger.log("sliverauth: DISABLED!")
-    return
+def GetSlivers(data, config, plc):
+    if 'OVERRIDES' in dir(config):
+        if config.OVERRIDES.get('sliverauth') == '-1':
+            logger.log("sliverauth:  Disabled", 2)
+            return
 
     if 'slivers' not in data:
         logger.log("sliverauth: getslivers data lack's sliver information. IGNORING!")
         return
 
-    random.seed(42)
     for sliver in data['slivers']:
         found_hmac = False
         for attribute in sliver['attributes']:
@@ -51,9 +49,12 @@ def GetSlivers(plc, data, conf):
                 break
 
         if not found_hmac:
+            # XXX need a better random seed?!
+            random.seed(time.time())
             d = [random.choice(string.letters) for x in xrange(32)]
             hmac = "".join(d)
             SetSliverTag(plc,sliver['name'],'hmac',hmac)
+            logger.log("sliverauth setting %s hmac" % sliver['name'])
 
         path = '/vservers/%s/etc/planetlab' % sliver['name']
         if os.path.exists(path):
@@ -72,6 +73,7 @@ def GetSlivers(plc, data, conf):
                 if os.path.exists(keyfile):
                     os.unlink(keyfile)
                 os.rename(name,keyfile)
+                logger.log("sliverauth writing hmac to %s " % keyfile)
 
             os.chmod(keyfile,0400)