Created new Slabv1 RSpec option.
[sfa.git] / sfa / senslab / slabslices.py
index 9e547e4..d372eea 100644 (file)
@@ -7,6 +7,12 @@ from sfa.util.policy import Policy
 from sfa.rspecs.rspec import RSpec
 from sfa.plc.vlink import VLink
 from sfa.util.xrn import Xrn
+from sfa.util.sfalogging import logger
+
+from sqlalchemy import Column, Integer, String, DateTime
+from sqlalchemy import Table, Column, MetaData, join, ForeignKey
+from sfa.storage.model import RegRecord
+from sfa.storage.alchemy import dbsession,engine
 
 MAXINT =  2L**31-1
 
@@ -14,17 +20,90 @@ class SlabSlices:
 
     rspec_to_slice_tag = {'max_rate':'net_max_rate'}
 
-    def __init__(self, api, ttl = .5, origin_hrn=None):
-        self.api = api
-        #filepath = path + os.sep + filename
-        self.policy = Policy(self.api)    
-        self.origin_hrn = origin_hrn
-        self.registry = api.registries[api.hrn]
-        self.credential = api.getCredential()
-        self.nodes = []
-        self.persons = []
-
-    #def get_slivers(self, xrn, node=None):
+    #def __init__(self, api, ttl = .5, origin_hrn=None):
+        #self.api = api
+        ##filepath = path + os.sep + filename
+        #self.policy = Policy(self.api)    
+        #self.origin_hrn = origin_hrn
+        #self.registry = api.registries[api.hrn]
+        #self.credential = api.getCredential()
+        #self.nodes = []
+        #self.persons = []
+
+
+    def __init__(self, driver):
+        self.driver = driver
+        
+        
+    def get_slivers(self, xrn, node=None):
+        hrn, type = urn_to_hrn(xrn)
+         
+        slice_name = hrn_to_pl_slicename(hrn)
+        # XX Should we just call PLCAPI.GetSliceTicket(slice_name) instead
+        # of doing all of this?
+        #return self.api.driver.GetSliceTicket(self.auth, slice_name) 
+        
+
+       
+        slice = self.driver.GetSlices(slice_filter = slice_name, filter_type = 'slice_hrn')
+
+        # Get user information
+        alchemy_person = dbsession.query(RegRecord).filter_by(record_id = slice['record_id_user']).first()
+
+        slivers = []
+        sliver_attributes = []
+            
+        if slice['oar_job_id'] is not -1:
+            nodes_all = self.GetNodes({'hostname':slice['node_ids']},
+                            ['node_id', 'hostname','site','boot_state'])
+            nodeall_byhostname = dict([(n['hostname'], n) for n in nodes_all])
+            nodes = slice['node_ids']
+            
+            for node in nodes:
+                #for sliver_attribute in filter(lambda a: a['node_id'] == node['node_id'], slice_tags):
+                sliver_attribute['tagname'] = 'slab-tag'
+                sliver_attribute['value'] = 'slab-value'
+                sliver_attributes.append(sliver_attribute['tagname'])
+                attributes.append({'tagname': sliver_attribute['tagname'],
+                                    'value': sliver_attribute['value']})
+
+            # set nodegroup slice attributes
+            for slice_tag in filter(lambda a: a['nodegroup_id'] in node['nodegroup_ids'], slice_tags):
+                # Do not set any nodegroup slice attributes for
+                # which there is at least one sliver attribute
+                # already set.
+                if slice_tag not in slice_tags:
+                    attributes.append({'tagname': slice_tag['tagname'],
+                        'value': slice_tag['value']})
+
+            for slice_tag in filter(lambda a: a['node_id'] is None, slice_tags):
+                # Do not set any global slice attributes for
+                # which there is at least one sliver attribute
+                # already set.
+                if slice_tag['tagname'] not in sliver_attributes:
+                    attributes.append({'tagname': slice_tag['tagname'],
+                                   'value': slice_tag['value']})
+
+            # XXX Sanity check; though technically this should be a system invariant
+            # checked with an assertion
+            if slice['expires'] > MAXINT:  slice['expires']= MAXINT
+            
+            slivers.append({
+                'hrn': hrn,
+                'name': slice['name'],
+                'slice_id': slice['slice_id'],
+                'instantiation': slice['instantiation'],
+                'expires': slice['expires'],
+                'keys': keys,
+                'attributes': attributes
+            })
+
+        return slivers
+        
+        
+        
+ #def get_slivers(self, xrn, node=None):
         #hrn, type = urn_to_hrn(xrn)
          
         #slice_name = hrn_to_pl_slicename(hrn)
@@ -128,27 +207,25 @@ class SlabSlices:
             #})
 
         #return slivers
     def get_peer(self, xrn):
         hrn, type = urn_to_hrn(xrn)
-        # Becaues of myplc federation,  we first need to determine if this
-        # slice belongs to out local plc or a myplc peer. We will assume it 
-        # is a local site, unless we find out otherwise  
+        #Does this slice belong to a local site or a peer senslab site?
         peer = None
-        print>>sys.stderr, " \r\n \r\n \t slices.py get_peer slice_authority  "
+        
         # get this slice's authority (site)
         slice_authority = get_authority(hrn)
-
+        
         # get this site's authority (sfa root authority or sub authority)
         site_authority = get_authority(slice_authority).lower()
-        print>>sys.stderr, " \r\n \r\n \t slices.py get_peer slice_authority  %s site_authority %s" %(slice_authority,site_authority) 
+        print>>sys.stderr, " \r\n \r\n \t slices.py get_peer slice_authority  %s site_authority %s " %(slice_authority, site_authority)
         # check if we are already peered with this site_authority, if so
-        #peers = self.api.driver.GetPeers({}, ['peer_id', 'peername', 'shortname', 'hrn_root'])
-        #for peer_record in peers:
-            #names = [name.lower() for name in peer_record.values() if isinstance(name, StringTypes)]
-            #if site_authority in names:
-                #peer = peer_record
-
+        peers = self.driver.GetPeers({})
+        print>>sys.stderr, " \r\n \r\n \t slices.py get_peer peers %s " %(peers)
+        for peer_record in peers:
+          
+            if site_authority == peer_record.hrn:
+                peer = peer_record
+        print>>sys.stderr, " \r\n \r\n \t slices.py get_peer peer  %s " %(peer) 
         return peer
 
     def get_sfa_peer(self, xrn):
@@ -159,7 +236,7 @@ class SlabSlices:
         slice_authority = get_authority(hrn)
         site_authority = get_authority(slice_authority)
 
-        if site_authority != self.api.hrn:
+        if site_authority != self.driver.hrn:
             sfa_peer = site_authority
 
         return sfa_peer
@@ -168,7 +245,7 @@ class SlabSlices:
         current_slivers = []
         deleted_nodes = []
         if slice['node_ids']:
-            nodes = self.api.driver.GetNodes(slice['node_ids'], ['hostname'])
+            nodes = self.driver.GetNodes(slice['node_ids'], ['hostname'])
             current_slivers = [node['hostname'] for node in nodes]
     
             # remove nodes not in rspec
@@ -178,22 +255,23 @@ class SlabSlices:
         added_nodes = list(set(requested_slivers).difference(current_slivers))        
         print>>sys.stderr , "\r\n \r\n \t slices.py  verify_slice_nodes added_nodes %s slice %s" %( added_nodes,slice)
         try:
-            if peer:
-                self.api.driver.UnBindObjectFromPeer('slice', slice['slice_id'], peer['shortname'])
+            #if peer:
+                #self.driver.UnBindObjectFromPeer('slice', slice['slice_id'], peer['shortname'])
             #PI is a list, get the only username in this list
             #so that the OAR/LDAP knows the user: remove the authority from the name
             tmp=  slice['PI'][0].split(".")
             username = tmp[(len(tmp)-1)]
-            self.api.driver.AddSliceToNodes(slice['name'], added_nodes, username)
+            self.driver.AddSliceToNodes(slice['name'], added_nodes, username)
+            
             if deleted_nodes:
-                self.api.driver.DeleteSliceFromNodes(slice['name'], deleted_nodes)
+                self.driver.DeleteSliceFromNodes(slice['name'], deleted_nodes)
 
         except: 
-            self.api.logger.log_exc('Failed to add/remove slice from nodes')
+            logger.log_exc('Failed to add/remove slice from nodes')
 
     def free_egre_key(self):
         used = set()
-        for tag in self.api.driver.GetSliceTags({'tagname': 'egre_key'}):
+        for tag in self.driver.GetSliceTags({'tagname': 'egre_key'}):
                 used.add(int(tag['value']))
 
         for i in range(1, 256):
@@ -205,10 +283,7 @@ class SlabSlices:
 
         return str(key)
 
-    def verify_slice_links(self, slice, links, aggregate):
-
-            return
-
+  
        
                         
         
@@ -218,114 +293,119 @@ class SlabSlices:
             # bind site
             try:
                 if site:
-                    self.api.driver.BindObjectToPeer('site', site['site_id'], peer['shortname'], slice['site_id'])
+                    self.driver.BindObjectToPeer('site', site['site_id'], peer['shortname'], slice['site_id'])
             except Exception,e:
-                self.api.driver.DeleteSite(site['site_id'])
+                self.driver.DeleteSite(site['site_id'])
                 raise e
             
             # bind slice
             try:
                 if slice:
-                    self.api.driver.BindObjectToPeer('slice', slice['slice_id'], peer['shortname'], slice['slice_id'])
+                    self.driver.BindObjectToPeer('slice', slice['slice_id'], peer['shortname'], slice['slice_id'])
             except Exception,e:
-                self.api.driver.DeleteSlice(slice['slice_id'])
+                self.driver.DeleteSlice(slice['slice_id'])
                 raise e 
 
             # bind persons
             for person in persons:
                 try:
-                    self.api.driver.BindObjectToPeer('person', 
+                    self.driver.BindObjectToPeer('person', 
                                                      person['person_id'], peer['shortname'], person['peer_person_id'])
 
                     for (key, remote_key_id) in zip(person['keys'], person['key_ids']):
                         try:
-                            self.api.driver.BindObjectToPeer( 'key', key['key_id'], peer['shortname'], remote_key_id)
+                            self.driver.BindObjectToPeer( 'key', key['key_id'], peer['shortname'], remote_key_id)
                         except:
-                            self.api.driver.DeleteKey(key['key_id'])
-                            self.api.logger("failed to bind key: %s to peer: %s " % (key['key_id'], peer['shortname']))
+                            self.driver.DeleteKey(key['key_id'])
+                            logger("failed to bind key: %s to peer: %s " % (key['key_id'], peer['shortname']))
                 except Exception,e:
-                    self.api.driver.DeletePerson(person['person_id'])
+                    self.driver.DeletePerson(person['person_id'])
                     raise e       
 
         return slice
 
-    def verify_site(self, slice_xrn, slice_record={}, peer=None, sfa_peer=None):
-        (slice_hrn, type) = urn_to_hrn(slice_xrn)
-        site_hrn = get_authority(slice_hrn)
-        # login base can't be longer than 20 characters
-        slicename = hrn_to_pl_slicename(slice_hrn)
-        authority_name = slicename.split('_')[0]
-        login_base = authority_name[:20]
-        sites = self.api.driver.GetSites(login_base)
-        if not sites:
-            # create new site record
-            site = {'name': 'geni.%s' % authority_name,
-                    'abbreviated_name': authority_name,
-                    'login_base': login_base,
-                    'max_slices': 100,
-                    'max_slivers': 1000,
-                    'enabled': True,
-                    'peer_site_id': None}
-            if peer:
-                site['peer_site_id'] = slice_record.get('site_id', None)
-            site['site_id'] = self.api.driver.AddSite(site)
-            # exempt federated sites from monitor policies
-            self.api.driver.AddSiteTag(site['site_id'], 'exempt_site_until', "20200101")
+    #def verify_site(self, slice_xrn, slice_record={}, peer=None, sfa_peer=None, options={}):
+        #(slice_hrn, type) = urn_to_hrn(slice_xrn)
+        #site_hrn = get_authority(slice_hrn)
+        ## login base can't be longer than 20 characters
+        ##slicename = hrn_to_pl_slicename(slice_hrn)
+        #authority_name = slice_hrn.split('.')[0]
+        #login_base = authority_name[:20]
+        #print >>sys.stderr, " \r\n \r\n \t\t SLABSLICES.PY verify_site authority_name %s  login_base %s slice_hrn %s" %(authority_name,login_base,slice_hrn)
+        
+        #sites = self.driver.GetSites(login_base)
+        #if not sites:
+            ## create new site record
+            #site = {'name': 'geni.%s' % authority_name,
+                    #'abbreviated_name': authority_name,
+                    #'login_base': login_base,
+                    #'max_slices': 100,
+                    #'max_slivers': 1000,
+                    #'enabled': True,
+                    #'peer_site_id': None}
+            #if peer:
+                #site['peer_site_id'] = slice_record.get('site_id', None)
+            #site['site_id'] = self.driver.AddSite(site)
+            ## exempt federated sites from monitor policies
+            #self.driver.AddSiteTag(site['site_id'], 'exempt_site_until', "20200101")
             
-            # is this still necessary?
-            # add record to the local registry 
-            if sfa_peer and slice_record:
-                peer_dict = {'type': 'authority', 'hrn': site_hrn, \
-                             'peer_authority': sfa_peer, 'pointer': site['site_id']}
-                self.registry.register_peer_object(self.credential, peer_dict)
-        else:
-            site =  sites[0]
-            if peer:
-                # unbind from peer so we can modify if necessary. Will bind back later
-                self.api.driver.UnBindObjectFromPeer('site', site['site_id'], peer['shortname']) 
+            ### is this still necessary?
+            ### add record to the local registry 
+            ##if sfa_peer and slice_record:
+                ##peer_dict = {'type': 'authority', 'hrn': site_hrn, \
+                             ##'peer_authority': sfa_peer, 'pointer': site['site_id']}
+                ##self.registry.register_peer_object(self.credential, peer_dict)
+        #else:
+            #site =  sites[0]
+            #if peer:
+                ## unbind from peer so we can modify if necessary. Will bind back later
+                #self.driver.UnBindObjectFromPeer('site', site['site_id'], peer['shortname']) 
         
-        return site        
+        #return site        
 
-    def verify_slice(self, slice_hrn, slice_record, peer, sfa_peer):
-        #slicename = hrn_to_pl_slicename(slice_hrn)
-        parts = hrn_to_pl_slicename(slice_hrn).split("_")
-        login_base = parts[0]
+    def verify_slice(self, slice_hrn, slice_record, peer, sfa_peer, options={} ):
+
+        login_base = slice_hrn.split(".")[0]
         slicename = slice_hrn
-        slices = self.api.driver.GetSlices([slicename]) 
-        print>>sys.stderr, " \r\n \r\rn Slices.py verify_slice slicename %s slices %s slice_record %s"%(slicename ,slices, slice_record)
-        if not slices:
+        sl = self.driver.GetSlices(slice_filter=slicename, filter_type = 'slice_hrn') 
+        if sl:
+
+            print>>sys.stderr, " \r\n \r\rn Slices.py verify_slice slicename %s sl %s slice_record %s"%(slicename ,sl, slice_record)
+        else:
+            print>>sys.stderr, " \r\n \r\rn Slices.py verify_slice UH-Oh..."
+        if not sl:
             slice = {'name': slicename,
                      'url': slice_record.get('url', slice_hrn), 
                      #'description': slice_record.get('description', slice_hrn)
                      }
             # add the slice                          
-            slice['slice_id'] = self.api.driver.AddSlice(slice)
+            slice['slice_id'] = self.driver.AddSlice(slice)
             slice['node_ids'] = []
             slice['person_ids'] = []
-            if peer:
-                slice['peer_slice_id'] = slice_record.get('slice_id', None) 
+            #if peer:
+                #slice['peer_slice_id'] = slice_record.get('slice_id', None) 
             # mark this slice as an sfa peer record
-            if sfa_peer:
-                peer_dict = {'type': 'slice', 'hrn': slice_hrn, 
-                             'peer_authority': sfa_peer, 'pointer': slice['slice_id']}
-                self.registry.register_peer_object(self.credential, peer_dict)
+            #if sfa_peer:
+                #peer_dict = {'type': 'slice', 'hrn': slice_hrn, 
+                             #'peer_authority': sfa_peer, 'pointer': slice['slice_id']}
+                #self.registry.register_peer_object(self.credential, peer_dict)
         else:
-            slice = slices[0]
+            slice = sl
             slice.update(slice_record)
-            del slice['last_updated']
-            del slice['date_created']
-            if peer:
-                slice['peer_slice_id'] = slice_record.get('slice_id', None)
-                # unbind from peer so we can modify if necessary. Will bind back later
-                self.api.driver.UnBindObjectFromPeer('slice', slice['slice_id'], peer['shortname'])
+            #del slice['last_updated']
+            #del slice['date_created']
+            #if peer:
+                #slice['peer_slice_id'] = slice_record.get('slice_id', None)
+                ## unbind from peer so we can modify if necessary. Will bind back later
+                #self.driver.UnBindObjectFromPeer('slice', slice['slice_id'], peer['shortname'])
                #Update existing record (e.g. expires field) it with the latest info.
-            #if slice_record and slice['expires'] != slice_record['expires']:
-                #self.api.driver.UpdateSlice( slice['slice_id'], {'expires' : slice_record['expires']})
+            ##if slice_record and slice['expires'] != slice_record['expires']:
+                ##self.driver.UpdateSlice( slice['slice_id'], {'expires' : slice_record['expires']})
        
         return slice
 
     #def get_existing_persons(self, users):
-    def verify_persons(self, slice_hrn, slice_record, users, append=True):
+    def verify_persons(self, slice_hrn, slice_record, users,  peer, sfa_peer, options={}):
         users_by_id = {}
         users_by_hrn = {}
         users_dict = {}
@@ -334,128 +414,95 @@ class SlabSlices:
             if 'person_id' in user and 'hrn' in user:
                 users_by_id[user['person_id']] = user
                 users_dict[user['person_id']] = {'person_id':user['person_id'], 'hrn':user['hrn']}
-           
-                #hrn, type = urn_to_hrn(user['urn'])
-                #username = get_leaf(hrn) 
-                #login_base = get_leaf(get_authority(user['urn']))
-                #user['username'] = username 
-                #users_by_site[login_base].append(user)
+
                 users_by_hrn[user['hrn']] = user
                 users_dict[user['hrn']] = {'person_id':user['person_id'], 'hrn':user['hrn']}
-       
+                
+        #print>>sys.stderr, " \r\n \r\n \t slabslices.py verify_person  users_dict %s \r\n user_by_hrn %s \r\n \tusers_by_id %s " %( users_dict,users_by_hrn, users_by_id) 
+        
         existing_user_ids = []
+        existing_user_hrns = []
         existing_users= []
+        #Check if user is in LDAP using its hrn.
+        #Assuming Senslab is centralised :  one LDAP for all sites, user_id unknown from LDAP
+        # LDAP does not provide users id, therfore we rely on hrns
         if users_by_hrn:
-            # get existing users by email 
-           
-            existing_users = self.api.driver.GetPersons({'hrn': users_by_hrn.keys()}, 
-                                                        ['hrn'])
-            #print>>sys.stderr, " \r\n \r\n \t slices.py HEEEEEEEEY===========verify_person  existing_users %s users_dict %s  " %(existing_users, users_dict) 
-            #existing_user_ids = [(users_dict[user['hrn']]['hrn'],users_dict[user['hrn']]['person_id'] ) for user in existing_users]
-            for user in existing_users :
-                for  k in users_dict[user['hrn']] :
-                    existing_user_ids.append (users_dict[user['hrn']][k])
-
-            #print>>sys.stderr, " \r\n \r\n slices.py verify_person   existing_user_ids %s " %(existing_user_ids)
-        #if users_by_id:
-            #existing_user_ids.extend([user for user in users_by_id])
-        #if users_by_site:
-            ## get a list of user sites (based on requeste user urns
-            #site_list = self.api.driver.GetSites(users_by_site.keys(), \
-                #['site_id', 'login_base', 'person_ids'])
-            #sites = {}
-            #site_user_ids = []
-            
-            ## get all existing users at these sites
-            #for site in site_list:
-                #sites[site['site_id']] = site
-                #site_user_ids.extend(site['person_ids'])
-
-            #existing_site_persons_list = self.api.driver.GetPersons(site_user_ids,  
-                                                                    #['person_id', 'key_ids', 'email', 'site_ids'])
-
-            ## all requested users are either existing users or new (added) users      
-            #for login_base in users_by_site:
-                #requested_site_users = users_by_site[login_base]
-                #for requested_user in requested_site_users:
-                    #user_found = False
-                    #for existing_user in existing_site_persons_list:
-                        #for site_id in existing_user['site_ids']:
-                            #site = sites[site_id]
-                            #if login_base == site['login_base'] and \
-                               #existing_user['email'].startswith(requested_user['username']):
-                                #existing_user_ids.append(existing_user['email'])
-                                #users_dict[existing_user['email']] = requested_user
-                                #user_found = True
-                                #break
-                        #if user_found:
-                            #break
-      
-                    #if user_found == False:
-                        #fake_email = requested_user['username'] + '@geni.net'
-                        #users_dict[fake_email] = requested_user
-                
+            existing_users = self.driver.GetPersons({'hrn': users_by_hrn.keys()}, 
+                                                        ['hrn','pkey'])
+            if existing_users:
+                for user in existing_users :
+                    #for  k in users_dict[user['hrn']] :
+                    existing_user_hrns.append (users_dict[user['hrn']]['hrn'])
+                    existing_user_ids.append (users_dict[user['hrn']]['person_id'])
+                    #print>>sys.stderr, " \r\n \r\n \t slabslices.py verify_person  existing_user_ids.append (users_dict[user['hrn']][k]) %s \r\n existing_users %s " %(  existing_user_ids,existing_users) 
+         
 
         # requested slice users        
-        requested_user_ids = users_dict.keys()
+        requested_user_ids = users_by_id.keys() 
+        requested_user_hrns = users_by_hrn.keys()
+        #print>>sys.stderr, " \r\n \r\n \t slabslices.py verify_person  requested_user_ids  %s user_by_hrn %s " %( requested_user_ids,users_by_hrn) 
         # existing slice users
         existing_slice_users_filter = {'hrn': slice_record.get('PI', [])}
         #print>>sys.stderr, " \r\n \r\n slices.py verify_person requested_user_ids %s existing_slice_users_filter %s slice_record %s" %(requested_user_ids,existing_slice_users_filter,slice_record)
         
-        existing_slice_users = self.api.driver.GetPersons(existing_slice_users_filter,['hrn'])
-        existing_slice_user_ids = []
-        for user in existing_slice_users :
-            for  k in users_dict[user['hrn']] :
-                    existing_slice_user_ids.append (users_dict[user['hrn']][k])
-                    #existing_slice_user_ids = [user['hrn'] for user in existing_slice_users]
-                    
-        #print>>sys.stderr, " \r\n \r\n slices.py verify_person requested_user_ids %s  existing_slice_user_ids%s " %(requested_user_ids,existing_slice_user_ids)
+        existing_slice_users = self.driver.GetPersons(existing_slice_users_filter,['hrn','pkey'])
+        #print>>sys.stderr, " \r\n \r\n slices.py verify_person   existing_slice_users %s " %(existing_slice_users)
+
+        existing_slice_user_hrns = [user['hrn'] for user in existing_slice_users]
+
+        #print>>sys.stderr, " \r\n \r\n slices.py verify_person requested_user_ids %s  existing_slice_user_hrns %s " %(requested_user_ids,existing_slice_user_hrns)
         # users to be added, removed or updated
-        added_user_ids = set(requested_user_ids).difference(set(existing_user_ids))
-        added_slice_user_ids = set(requested_user_ids).difference(existing_slice_user_ids)
-        removed_user_ids = set(existing_slice_user_ids).difference(requested_user_ids)
-        #print>>sys.stderr, " \r\n \r\n slices.py verify_persons  existing_slice_user_ids %s  requested_user_ids %s " %(existing_slice_user_ids,requested_user_ids)
-        updated_user_ids = set(existing_slice_user_ids).intersection(requested_user_ids)
+
+        added_user_hrns = set(requested_user_hrns).difference(set(existing_user_hrns))
+
+        added_slice_user_hrns = set(requested_user_hrns).difference(existing_slice_user_hrns)
+        
+        removed_user_hrns = set(existing_slice_user_hrns).difference(requested_user_hrns)
+        
+
+        updated_user_hrns = set(existing_slice_user_hrns).intersection(requested_user_hrns)
         #print>>sys.stderr, " \r\n \r\n slices.py verify_persons  added_user_ids %s added_slice_user_ids %s " %(added_user_ids,added_slice_user_ids)
-        #print>>sys.stderr, " \r\n \r\n slices.py verify_persons  removed_user_ids %s updated_user_ids %s " %(removed_user_ids,updated_user_ids)
-        # Remove stale users (only if we are not appending).
+        #print>>sys.stderr, " \r\n \r\n slices.py verify_persons  removed_user_hrns %s updated_user_hrns %s " %(removed_user_hrns,updated_user_hrns)
+        # Remove stale users (only if we are not appending) 
+        append = options.get('append', True)
         if append == False:
-            for removed_user_id in removed_user_ids:
-                self.api.driver.DeletePersonFromSlice(removed_user_id, slice_record['name'])
+            for removed_user_hrn in removed_user_hrns:
+                self.driver.DeletePersonFromSlice(removed_user_hrn, slice_record['name'])
         # update_existing users
         updated_users_list = [user for user in existing_slice_users if user['hrn'] in \
-          updated_user_ids]
+          updated_user_hrns]
+        print>>sys.stderr, " \r\n \r\n slices.py verify_persons  removed_user_hrns %s updated_users_list %s " %(removed_user_hrns,updated_users_list) 
         #self.verify_keys(existing_slice_users, updated_users_list, peer, append)
 
         added_persons = []
         # add new users
-        for added_user_id in added_user_ids:
-            added_user = users_dict[added_user_id]
+        for added_user_hrn in added_user_hrns:
+            added_user = users_dict[added_user_hrn]
             #hrn, type = urn_to_hrn(added_user['urn'])  
             person = {
                 #'first_name': added_user.get('first_name', hrn),
                 #'last_name': added_user.get('last_name', hrn),
-                'person_id': added_user_id,
+                'person_id': added_user['person_id'],
                 #'peer_person_id': None,
                 #'keys': [],
                 #'key_ids': added_user.get('key_ids', []),
                 
             } 
             #print>>sys.stderr, " \r\n \r\n slices.py verify_persons   added_user_ids %s " %(added_user_ids)
-            person['person_id'] = self.api.driver.AddPerson(person)
+            person['person_id'] = self.driver.AddPerson(person)
             if peer:
                 person['peer_person_id'] = added_user['person_id']
             added_persons.append(person)
            
             # enable the account 
-            self.api.driver.UpdatePerson(person['person_id'], {'enabled': True})
+            self.driver.UpdatePerson(person['person_id'], {'enabled': True})
             
             # add person to site
-            #self.api.driver.AddPersonToSite(added_user_id, login_base)
+            #self.driver.AddPersonToSite(added_user_id, login_base)
 
             #for key_string in added_user.get('keys', []):
                 #key = {'key':key_string, 'key_type':'ssh'}
-                #key['key_id'] = self.api.driver.AddPersonKey(person['person_id'], key)
+                #key['key_id'] = self.driver.AddPersonKey(person['person_id'], key)
                 #person['keys'].append(key)
 
             # add the registry record
@@ -463,22 +510,23 @@ class SlabSlices:
                 #peer_dict = {'type': 'user', 'hrn': hrn, 'peer_authority': sfa_peer, \
                     #'pointer': person['person_id']}
                 #self.registry.register_peer_object(self.credential, peer_dict)
-    
-        for added_slice_user_id in added_slice_user_ids.union(added_user_ids):
+        for added_slice_user_hrn in added_slice_user_hrns.union(added_user_hrns):           
+            self.driver.AddPersonToSlice(added_slice_user_hrn, slice_record['name'])
+        #for added_slice_user_id in added_slice_user_ids.union(added_user_ids):
             # add person to the slice 
-            self.api.driver.AddPersonToSlice(added_slice_user_id, slice_record['name'])
+            #self.driver.AddPersonToSlice(added_slice_user_id, slice_record['name'])
             # if this is a peer record then it should already be bound to a peer.
             # no need to return worry about it getting bound later 
 
         return added_persons
             
 
-    def verify_keys(self, persons, users, peer, append=True):
+    def verify_keys(self, persons, users, peer, options={}):
         # existing keys 
         key_ids = []
         for person in persons:
             key_ids.extend(person['key_ids'])
-        keylist = self.api.driver.GetKeys(key_ids, ['key_id', 'key'])
+        keylist = self.driver.GetKeys(key_ids, ['key_id', 'key'])
         keydict = {}
         for key in keylist:
             keydict[key['key']] = key['key_id']     
@@ -500,16 +548,16 @@ class SlabSlices:
                     try:
                         if peer:
                             person = persondict[user['email']]
-                            self.api.driver.UnBindObjectFromPeer('person', person['person_id'], peer['shortname'])
-                        key['key_id'] = self.api.driver.AddPersonKey(user['email'], key)
+                            self.driver.UnBindObjectFromPeer('person', person['person_id'], peer['shortname'])
+                        key['key_id'] = self.driver.AddPersonKey(user['email'], key)
                         if peer:
                             key_index = user_keys.index(key['key'])
                             remote_key_id = user['key_ids'][key_index]
-                            self.api.driver.BindObjectToPeer('key', key['key_id'], peer['shortname'], remote_key_id)
+                            self.driver.BindObjectToPeer('key', key['key_id'], peer['shortname'], remote_key_id)
                             
                     finally:
                         if peer:
-                            self.api.driver.BindObjectToPeer('person', person['person_id'], peer['shortname'], user['person_id'])
+                            self.driver.BindObjectToPeer('person', person['person_id'], peer['shortname'], user['person_id'])
         
         # remove old keys (only if we are not appending)
         if append == False: 
@@ -518,150 +566,150 @@ class SlabSlices:
                 if keydict[existing_key_id] in removed_keys:
                     try:
                         if peer:
-                            self.api.driver.UnBindObjectFromPeer('key', existing_key_id, peer['shortname'])
-                        self.api.driver.DeleteKey(existing_key_id)
+                            self.driver.UnBindObjectFromPeer('key', existing_key_id, peer['shortname'])
+                        self.driver.DeleteKey(existing_key_id)
                     except:
                         pass   
 
-    def verify_slice_attributes(self, slice, requested_slice_attributes, append=False, admin=False):
-        # get list of attributes users ar able to manage
-        filter = {'category': '*slice*'}
-        if not admin:
-            filter['|roles'] = ['user']
-        slice_attributes = self.api.driver.GetTagTypes(filter)
-        valid_slice_attribute_names = [attribute['tagname'] for attribute in slice_attributes]
-
-        # get sliver attributes
-        added_slice_attributes = []
-        removed_slice_attributes = []
-        ignored_slice_attribute_names = []
-        existing_slice_attributes = self.api.driver.GetSliceTags({'slice_id': slice['slice_id']})
-
-        # get attributes that should be removed
-        for slice_tag in existing_slice_attributes:
-            if slice_tag['tagname'] in ignored_slice_attribute_names:
-                # If a slice already has a admin only role it was probably given to them by an
-                # admin, so we should ignore it.
-                ignored_slice_attribute_names.append(slice_tag['tagname'])
-            else:
-                # If an existing slice attribute was not found in the request it should
-                # be removed
-                attribute_found=False
-                for requested_attribute in requested_slice_attributes:
-                    if requested_attribute['name'] == slice_tag['tagname'] and \
-                       requested_attribute['value'] == slice_tag['value']:
-                        attribute_found=True
-                        break
-
-            if not attribute_found and not append:
-                removed_slice_attributes.append(slice_tag)
+    #def verify_slice_attributes(self, slice, requested_slice_attributes, append=False, admin=False):
+        ## get list of attributes users ar able to manage
+        #filter = {'category': '*slice*'}
+        #if not admin:
+            #filter['|roles'] = ['user']
+        #slice_attributes = self.driver.GetTagTypes(filter)
+        #valid_slice_attribute_names = [attribute['tagname'] for attribute in slice_attributes]
+
+        ## get sliver attributes
+        #added_slice_attributes = []
+        #removed_slice_attributes = []
+        #ignored_slice_attribute_names = []
+        #existing_slice_attributes = self.driver.GetSliceTags({'slice_id': slice['slice_id']})
+
+        ## get attributes that should be removed
+        #for slice_tag in existing_slice_attributes:
+            #if slice_tag['tagname'] in ignored_slice_attribute_names:
+                ## If a slice already has a admin only role it was probably given to them by an
+                ## admin, so we should ignore it.
+                #ignored_slice_attribute_names.append(slice_tag['tagname'])
+            #else:
+                ## If an existing slice attribute was not found in the request it should
+                ## be removed
+                #attribute_found=False
+                #for requested_attribute in requested_slice_attributes:
+                    #if requested_attribute['name'] == slice_tag['tagname'] and \
+                       #requested_attribute['value'] == slice_tag['value']:
+                        #attribute_found=True
+                        #break
+
+            #if not attribute_found and not append:
+                #removed_slice_attributes.append(slice_tag)
         
-        # get attributes that should be added:
-        for requested_attribute in requested_slice_attributes:
-            # if the requested attribute wasn't found  we should add it
-            if requested_attribute['name'] in valid_slice_attribute_names:
-                attribute_found = False
-                for existing_attribute in existing_slice_attributes:
-                    if requested_attribute['name'] == existing_attribute['tagname'] and \
-                       requested_attribute['value'] == existing_attribute['value']:
-                        attribute_found=True
-                        break
-                if not attribute_found:
-                    added_slice_attributes.append(requested_attribute)
-
-
-        # remove stale attributes
-        for attribute in removed_slice_attributes:
-            try:
-                self.api.driver.DeleteSliceTag(attribute['slice_tag_id'])
-            except Exception, e:
-                self.api.logger.warn('Failed to remove sliver attribute. name: %s, value: %s, node_id: %s\nCause:%s'\
-                                % (name, value,  node_id, str(e)))
-
-        # add requested_attributes
-        for attribute in added_slice_attributes:
-            try:
-                self.api.driver.AddSliceTag(slice['name'], attribute['name'], attribute['value'], attribute.get('node_id', None))
-            except Exception, e:
-                self.api.logger.warn('Failed to add sliver attribute. name: %s, value: %s, node_id: %s\nCause:%s'\
-                                % (name, value,  node_id, str(e)))
-
-    def create_slice_aggregate(self, xrn, rspec):
-        hrn, type = urn_to_hrn(xrn)
-        # Determine if this is a peer slice
-        peer = self.get_peer(hrn)
-        sfa_peer = self.get_sfa_peer(hrn)
-
-        spec = RSpec(rspec)
-        # Get the slice record from sfa
-        slicename = hrn_to_pl_slicename(hrn) 
-        slice = {}
-        slice_record = None
-        registry = self.api.registries[self.api.hrn]
-        credential = self.api.getCredential()
-
-        site_id, remote_site_id = self.verify_site(registry, credential, hrn, peer, sfa_peer)
-        slice = self.verify_slice(registry, credential, hrn, site_id, remote_site_id, peer, sfa_peer)
-
-        # find out where this slice is currently running
-        nodelist = self.api.driver.GetNodes(slice['node_ids'], ['hostname'])
-        hostnames = [node['hostname'] for node in nodelist]
-
-        # get netspec details
-        nodespecs = spec.getDictsByTagName('NodeSpec')
-
-        # dict in which to store slice attributes to set for the nodes
-        nodes = {}
-        for nodespec in nodespecs:
-            if isinstance(nodespec['name'], list):
-                for nodename in nodespec['name']:
-                    nodes[nodename] = {}
-                    for k in nodespec.keys():
-                        rspec_attribute_value = nodespec[k]
-                        if (self.rspec_to_slice_tag.has_key(k)):
-                            slice_tag_name = self.rspec_to_slice_tag[k]
-                            nodes[nodename][slice_tag_name] = rspec_attribute_value
-            elif isinstance(nodespec['name'], StringTypes):
-                nodename = nodespec['name']
-                nodes[nodename] = {}
-                for k in nodespec.keys():
-                    rspec_attribute_value = nodespec[k]
-                    if (self.rspec_to_slice_tag.has_key(k)):
-                        slice_tag_name = self.rspec_to_slice_tag[k]
-                        nodes[nodename][slice_tag_name] = rspec_attribute_value
-
-                for k in nodespec.keys():
-                    rspec_attribute_value = nodespec[k]
-                    if (self.rspec_to_slice_tag.has_key(k)):
-                        slice_tag_name = self.rspec_to_slice_tag[k]
-                        nodes[nodename][slice_tag_name] = rspec_attribute_value
-
-        node_names = nodes.keys()
-        # remove nodes not in rspec
-        deleted_nodes = list(set(hostnames).difference(node_names))
-        # add nodes from rspec
-        added_nodes = list(set(node_names).difference(hostnames))
-
-        try:
-            if peer:
-                self.api.driver.UnBindObjectFromPeer('slice', slice['slice_id'], peer)
-
-            self.api.driver.AddSliceToNodes(slicename, added_nodes) 
-
-            # Add recognized slice tags
-            for node_name in node_names:
-                node = nodes[node_name]
-                for slice_tag in node.keys():
-                    value = node[slice_tag]
-                    if (isinstance(value, list)):
-                        value = value[0]
-
-                    self.api.driver.AddSliceTag(slicename, slice_tag, value, node_name)
-
-            self.api.driver.DeleteSliceFromNodes(slicename, deleted_nodes)
-        finally:
-            if peer:
-                self.api.driver.BindObjectToPeer('slice', slice['slice_id'], peer, slice['peer_slice_id'])
-
-        return 1
+        ## get attributes that should be added:
+        #for requested_attribute in requested_slice_attributes:
+            ## if the requested attribute wasn't found  we should add it
+            #if requested_attribute['name'] in valid_slice_attribute_names:
+                #attribute_found = False
+                #for existing_attribute in existing_slice_attributes:
+                    #if requested_attribute['name'] == existing_attribute['tagname'] and \
+                       #requested_attribute['value'] == existing_attribute['value']:
+                        #attribute_found=True
+                        #break
+                #if not attribute_found:
+                    #added_slice_attributes.append(requested_attribute)
+
+
+        ## remove stale attributes
+        #for attribute in removed_slice_attributes:
+            #try:
+                #self.driver.DeleteSliceTag(attribute['slice_tag_id'])
+            #except Exception, e:
+                #self.logger.warn('Failed to remove sliver attribute. name: %s, value: %s, node_id: %s\nCause:%s'\
+                                #% (name, value,  node_id, str(e)))
+
+        ## add requested_attributes
+        #for attribute in added_slice_attributes:
+            #try:
+                #self.driver.AddSliceTag(slice['name'], attribute['name'], attribute['value'], attribute.get('node_id', None))
+            #except Exception, e:
+                #self.logger.warn('Failed to add sliver attribute. name: %s, value: %s, node_id: %s\nCause:%s'\
+                                #% (name, value,  node_id, str(e)))
+
+    #def create_slice_aggregate(self, xrn, rspec):
+        #hrn, type = urn_to_hrn(xrn)
+        ## Determine if this is a peer slice
+        #peer = self.get_peer(hrn)
+        #sfa_peer = self.get_sfa_peer(hrn)
+
+        #spec = RSpec(rspec)
+        ## Get the slice record from sfa
+        #slicename = hrn_to_pl_slicename(hrn) 
+        #slice = {}
+        #slice_record = None
+        #registry = self.api.registries[self.api.hrn]
+        #credential = self.api.getCredential()
+
+        #site_id, remote_site_id = self.verify_site(registry, credential, hrn, peer, sfa_peer)
+        #slice = self.verify_slice(registry, credential, hrn, site_id, remote_site_id, peer, sfa_peer)
+
+        ## find out where this slice is currently running
+        #nodelist = self.driver.GetNodes(slice['node_ids'], ['hostname'])
+        #hostnames = [node['hostname'] for node in nodelist]
+
+        ## get netspec details
+        #nodespecs = spec.getDictsByTagName('NodeSpec')
+
+        ## dict in which to store slice attributes to set for the nodes
+        #nodes = {}
+        #for nodespec in nodespecs:
+            #if isinstance(nodespec['name'], list):
+                #for nodename in nodespec['name']:
+                    #nodes[nodename] = {}
+                    #for k in nodespec.keys():
+                        #rspec_attribute_value = nodespec[k]
+                        #if (self.rspec_to_slice_tag.has_key(k)):
+                            #slice_tag_name = self.rspec_to_slice_tag[k]
+                            #nodes[nodename][slice_tag_name] = rspec_attribute_value
+            #elif isinstance(nodespec['name'], StringTypes):
+                #nodename = nodespec['name']
+                #nodes[nodename] = {}
+                #for k in nodespec.keys():
+                    #rspec_attribute_value = nodespec[k]
+                    #if (self.rspec_to_slice_tag.has_key(k)):
+                        #slice_tag_name = self.rspec_to_slice_tag[k]
+                        #nodes[nodename][slice_tag_name] = rspec_attribute_value
+
+                #for k in nodespec.keys():
+                    #rspec_attribute_value = nodespec[k]
+                    #if (self.rspec_to_slice_tag.has_key(k)):
+                        #slice_tag_name = self.rspec_to_slice_tag[k]
+                        #nodes[nodename][slice_tag_name] = rspec_attribute_value
+
+        #node_names = nodes.keys()
+        ## remove nodes not in rspec
+        #deleted_nodes = list(set(hostnames).difference(node_names))
+        ## add nodes from rspec
+        #added_nodes = list(set(node_names).difference(hostnames))
+
+        #try:
+            #if peer:
+                #self.driver.UnBindObjectFromPeer('slice', slice['slice_id'], peer)
+
+            #self.driver.AddSliceToNodes(slicename, added_nodes) 
+
+            ## Add recognized slice tags
+            #for node_name in node_names:
+                #node = nodes[node_name]
+                #for slice_tag in node.keys():
+                    #value = node[slice_tag]
+                    #if (isinstance(value, list)):
+                        #value = value[0]
+
+                    #self.driver.AddSliceTag(slicename, slice_tag, value, node_name)
+
+            #self.driver.DeleteSliceFromNodes(slicename, deleted_nodes)
+        #finally:
+            #if peer:
+                #self.driver.BindObjectToPeer('slice', slice['slice_id'], peer, slice['peer_slice_id'])
+
+        #return 1