1 from sfa.util.xrn import get_authority, urn_to_hrn
2 from sfa.util.sfalogging import logger
9 rspec_to_slice_tag = {'max_rate':'net_max_rate'}
11 #def __init__(self, api, ttl = .5, origin_hrn=None):
13 ##filepath = path + os.sep + filename
14 #self.policy = Policy(self.api)
15 #self.origin_hrn = origin_hrn
16 #self.registry = api.registries[api.hrn]
17 #self.credential = api.getCredential()
22 def __init__(self, driver):
26 #def get_slivers(self, xrn, node=None):
27 #hrn, hrn_type = urn_to_hrn(xrn)
29 #slice_name = hrn_to_pl_slicename(hrn)
30 ## XX Should we just call PLCAPI.GetSliceTicket(slice_name) instead
31 ## of doing all of this?
32 ##return self.api.driver.GetSliceTicket(self.auth, slice_name)
36 #sfa_slice = self.driver.GetSlices(slice_filter = slice_name, \
37 # slice_filter_type = 'slice_hrn')
40 ## Get user information
42 #alchemy_person = dbsession.query(RegRecord).filter_by(record_id = \
43 #sfa_slice['record_id_user']).first()
46 #sliver_attributes = []
48 #if sfa_slice['oar_job_id'] is not -1:
49 #nodes_all = self.driver.GetNodes({'hostname': \
50 #sfa_slice['node_ids']},
51 #['node_id', 'hostname','site','boot_state'])
52 #nodeall_byhostname = dict([(n['hostname'], n) for n in nodes_all])
53 #nodes = sfa_slice['node_ids']
56 ##for sliver_attribute in filter(lambda a: a['node_id'] == \
57 #node['node_id'], slice_tags):
58 #sliver_attribute['tagname'] = 'slab-tag'
59 #sliver_attribute['value'] = 'slab-value'
60 #sliver_attributes.append(sliver_attribute['tagname'])
61 #attributes.append({'tagname': sliver_attribute['tagname'],
62 #'value': sliver_attribute['value']})
64 ## set nodegroup slice attributes
65 #for slice_tag in filter(lambda a: a['nodegroup_id'] \
66 #in node['nodegroup_ids'], slice_tags):
67 ## Do not set any nodegroup slice attributes for
68 ## which there is at least one sliver attribute
70 #if slice_tag not in slice_tags:
71 #attributes.append({'tagname': slice_tag['tagname'],
72 #'value': slice_tag['value']})
74 #for slice_tag in filter(lambda a: a['node_id'] is None, \
76 ## Do not set any global slice attributes for
77 ## which there is at least one sliver attribute
79 #if slice_tag['tagname'] not in sliver_attributes:
80 #attributes.append({'tagname': slice_tag['tagname'],
81 #'value': slice_tag['value']})
83 ## XXX Sanity check; though technically this should
84 ## be a system invariant
85 ## checked with an assertion
86 #if sfa_slice['expires'] > MAXINT: sfa_slice['expires']= MAXINT
90 #'name': sfa_slice['name'],
91 #'slice_id': sfa_slice['slice_id'],
92 #'instantiation': sfa_slice['instantiation'],
93 #'expires': sfa_slice['expires'],
95 #'attributes': attributes
105 def get_peer(self, xrn):
106 hrn, hrn_type = urn_to_hrn(xrn)
107 #Does this slice belong to a local site or a peer senslab site?
110 # get this slice's authority (site)
111 slice_authority = get_authority(hrn)
112 site_authority = slice_authority
113 # get this site's authority (sfa root authority or sub authority)
114 #site_authority = get_authority(slice_authority).lower()
115 logger.debug("SLABSLICES \ get_peer slice_authority %s \
116 site_authority %s hrn %s" %(slice_authority, \
117 site_authority, hrn))
118 # check if we are already peered with this site_authority, if so
119 #peers = self.driver.GetPeers({})
120 peers = self.driver.GetPeers(peer_filter = slice_authority)
121 for peer_record in peers:
123 if site_authority == peer_record.hrn:
125 logger.debug(" SLABSLICES \tget_peer peer %s " %(peer))
128 def get_sfa_peer(self, xrn):
129 hrn, hrn_type = urn_to_hrn(xrn)
131 # return the authority for this hrn or None if we are the authority
133 slice_authority = get_authority(hrn)
134 site_authority = get_authority(slice_authority)
136 if site_authority != self.driver.hrn:
137 sfa_peer = site_authority
142 def verify_slice_leases(self, sfa_slice, requested_leases, kept_leases, \
145 leases = self.driver.GetLeases({'name':sfa_slice['name']}, ['lease_id'])
147 current_leases = [lease['lease_id'] for lease in leases]
148 deleted_leases = list(set(current_leases).difference(kept_leases))
152 self.driver.UnBindObjectFromPeer('slice', \
153 sfa_slice['slice_id'], peer['shortname'])
154 deleted = self.driver.DeleteLeases(deleted_leases)
155 for lease in requested_leases:
156 added = self.driver.AddLeases(lease['hostname'], \
157 sfa_slice['name'], int(lease['t_from']), \
158 int(lease['t_until']))
159 #TODO : catch other exception?
161 logger.log_exc('Failed to add/remove slice leases')
165 def verify_slice_nodes(self, sfa_slice, requested_slivers, peer):
169 if sfa_slice['node_ids']:
170 nodes = self.driver.GetNodes(sfa_slice['node_ids'], ['hostname'])
171 current_slivers = [node['hostname'] for node in nodes]
173 # remove nodes not in rspec
174 deleted_nodes = list(set(current_slivers).\
175 difference(requested_slivers))
177 # add nodes from rspec
178 added_nodes = list(set(requested_slivers).difference(current_slivers))
181 #self.driver.UnBindObjectFromPeer('slice', slice['slice_id'], \
183 #PI is a list, get the only username in this list
184 #so that the OAR/LDAP knows the user:
185 #remove the authority from the name
186 tmp = sfa_slice['PI'][0].split(".")
187 username = tmp[(len(tmp)-1)]
188 #Update the table with the nodes that populate the slice
189 self.driver.db.update_job(sfa_slice['name'], nodes = added_nodes)
190 logger.debug("SLABSLICES \tverify_slice_nodes slice %s "\
192 #If there is a timeslot specified, then a job can be launched
194 #slot = sfa_slice['timeslot']
195 self.driver.LaunchExperimentOnOAR(sfa_slice, added_nodes, \
198 logger.log_exc("SLABSLICES \verify_slice_nodes KeyError \
199 sfa_slice %s " %(sfa_slice))
203 self.driver.DeleteSliceFromNodes(sfa_slice['name'], \
207 logger.log_exc('Failed to add/remove slice from nodes')
210 def free_egre_key(self):
212 for tag in self.driver.GetSliceTags({'tagname': 'egre_key'}):
213 used.add(int(tag['value']))
215 for i in range(1, 256):
220 raise KeyError("No more EGRE keys available")
229 def handle_peer(self, site, sfa_slice, persons, peer):
234 self.driver.BindObjectToPeer('site', site['site_id'], \
235 peer['shortname'], sfa_slice['site_id'])
236 except Exception, error:
237 self.driver.DeleteSite(site['site_id'])
243 self.driver.BindObjectToPeer('slice', slice['slice_id'], \
244 peer['shortname'], sfa_slice['slice_id'])
245 except Exception, error:
246 self.driver.DeleteSlice(sfa_slice['slice_id'])
250 for person in persons:
252 self.driver.BindObjectToPeer('person', \
253 person['person_id'], peer['shortname'], \
254 person['peer_person_id'])
256 for (key, remote_key_id) in zip(person['keys'], \
259 self.driver.BindObjectToPeer( 'key', \
260 key['key_id'], peer['shortname'], \
263 self.driver.DeleteKey(key['key_id'])
264 logger.log_exc("failed to bind key: %s \
265 to peer: %s " % (key['key_id'], \
267 except Exception, error:
268 self.driver.DeletePerson(person['person_id'])
273 #def verify_site(self, slice_xrn, slice_record={}, peer=None, \
274 #sfa_peer=None, options={}):
275 #(slice_hrn, type) = urn_to_hrn(slice_xrn)
276 #site_hrn = get_authority(slice_hrn)
277 ## login base can't be longer than 20 characters
278 ##slicename = hrn_to_pl_slicename(slice_hrn)
279 #authority_name = slice_hrn.split('.')[0]
280 #login_base = authority_name[:20]
281 #logger.debug(" SLABSLICES.PY \tverify_site authority_name %s \
282 #login_base %s slice_hrn %s" \
283 #%(authority_name,login_base,slice_hrn)
285 #sites = self.driver.GetSites(login_base)
287 ## create new site record
288 #site = {'name': 'geni.%s' % authority_name,
289 #'abbreviated_name': authority_name,
290 #'login_base': login_base,
292 #'max_slivers': 1000,
294 #'peer_site_id': None}
296 #site['peer_site_id'] = slice_record.get('site_id', None)
297 #site['site_id'] = self.driver.AddSite(site)
298 ## exempt federated sites from monitor policies
299 #self.driver.AddSiteTag(site['site_id'], 'exempt_site_until', \
302 ### is this still necessary?
303 ### add record to the local registry
304 ##if sfa_peer and slice_record:
305 ##peer_dict = {'type': 'authority', 'hrn': site_hrn, \
306 ##'peer_authority': sfa_peer, 'pointer': \
308 ##self.registry.register_peer_object(self.credential, peer_dict)
312 ## unbind from peer so we can modify if necessary.
313 ## Will bind back later
314 #self.driver.UnBindObjectFromPeer('site', site['site_id'], \
319 def verify_slice(self, slice_hrn, slice_record, peer, sfa_peer, options={}):
321 #login_base = slice_hrn.split(".")[0]
322 slicename = slice_hrn
323 sl = self.driver.GetSlices(slice_filter = slicename, \
324 slice_filter_type = 'slice_hrn')
327 logger.debug("SLABSLICE \tverify_slice slicename %s sl %s \
328 slice_record %s"%(slicename, sl, slice_record))
330 sfa_slice.update(slice_record)
331 #del slice['last_updated']
332 #del slice['date_created']
334 #slice['peer_slice_id'] = slice_record.get('slice_id', None)
335 ## unbind from peer so we can modify if necessary.
336 ## Will bind back later
337 #self.driver.UnBindObjectFromPeer('slice', slice['slice_id'], \
339 #Update existing record (e.g. expires field)
340 #it with the latest info.
341 ##if slice_record and slice['expires'] != slice_record['expires']:
342 ##self.driver.UpdateSlice( slice['slice_id'], {'expires' : \
343 #slice_record['expires']})
345 logger.debug(" SLABSLICES \tverify_slice Oups \
346 slice_record %s peer %s sfa_peer %s "\
347 %(slice_record, peer,sfa_peer))
348 sfa_slice = {'slice_hrn': slicename,
349 #'url': slice_record.get('url', slice_hrn),
350 #'description': slice_record.get('description', slice_hrn)
352 'record_id_user' : slice_record['person_ids'][0],
353 'record_id_slice': slice_record['record_id'],
354 'peer_authority':str(peer.hrn)
358 self.driver.AddSlice(sfa_slice)
359 #slice['slice_id'] = self.driver.AddSlice(slice)
360 logger.debug("SLABSLICES \tverify_slice ADDSLICE OK")
361 #slice['node_ids']=[]
362 #slice['person_ids'] = []
364 #slice['peer_slice_id'] = slice_record.get('slice_id', None)
365 # mark this slice as an sfa peer record
367 #peer_dict = {'type': 'slice', 'hrn': slice_hrn,
368 #'peer_authority': sfa_peer, 'pointer': \
370 #self.registry.register_peer_object(self.credential, peer_dict)
377 def verify_persons(self, slice_hrn, slice_record, users, peer, sfa_peer, \
385 if 'urn' in user and (not 'hrn' in user ) :
386 user['hrn'], user['type'] = urn_to_hrn(user['urn'])
388 if 'person_id' in user and 'hrn' in user:
389 users_by_id[user['person_id']] = user
390 users_dict[user['person_id']] = {'person_id':\
391 user['person_id'], 'hrn':user['hrn']}
393 users_by_hrn[user['hrn']] = user
394 users_dict[user['hrn']] = {'person_id':user['person_id'], \
397 logger.debug( "SLABSLICE.PY \tverify_person \
398 users_dict %s \r\n user_by_hrn %s \r\n \
400 %(users_dict,users_by_hrn, users_by_id))
402 existing_user_ids = []
403 existing_user_hrns = []
405 #Check if user is in LDAP using its hrn.
406 #Assuming Senslab is centralised : one LDAP for all sites,
407 # user_id unknown from LDAP
408 # LDAP does not provide users id, therfore we rely on hrns
410 #Construct the list of filters for GetPersons
412 for hrn in users_by_hrn:
413 #filter_user.append ( {'hrn':hrn})
414 filter_user.append (users_by_hrn[hrn])
415 logger.debug(" SLABSLICE.PY \tverify_person filter_user %s " \
417 existing_users = self.driver.GetPersons(filter_user)
418 #existing_users = self.driver.GetPersons({'hrn': \
419 #users_by_hrn.keys()})
420 #existing_users = self.driver.GetPersons({'hrn': \
421 #users_by_hrn.keys()}, \
424 for user in existing_users :
425 #for k in users_dict[user['hrn']] :
426 existing_user_hrns.append(users_dict[user['hrn']]['hrn'])
428 append(users_dict[user['hrn']]['person_id'])
430 #User from another federated site ,
431 #does not have a senslab account yet?
432 #or have multiple SFA accounts
433 #Check before adding them to LDAP
437 if isinstance(users, list):
438 ldap_reslt = self.driver.ldap.LdapSearch(users[0])
440 ldap_reslt = self.driver.ldap.LdapSearch(users)
442 existing_users = ldap_reslt[0]
443 existing_user_hrns.append(users_dict[user['hrn']]['hrn'])
445 append(users_dict[user['hrn']]['person_id'])
447 #User not existing in LDAP
449 logger.debug(" SLABSLICE.PY \tverify_person users \
450 not in ldap ... %s \r\n \t ldap_reslt %s " \
451 %(users, ldap_reslt))
454 # requested slice users
455 requested_user_ids = users_by_id.keys()
456 requested_user_hrns = users_by_hrn.keys()
457 logger.debug("SLABSLICE.PY \tverify_person requested_user_ids %s \
458 user_by_hrn %s " %(requested_user_ids, users_by_hrn))
459 # existing slice users
461 #existing_slice_users_filter = {'hrn': slice_record['PI'][0]}
462 #logger.debug(" SLABSLICE.PY \tverify_person requested_user_ids %s \
463 #existing_slice_users_filter %s slice_record %s" %(requested_user_ids,\
464 #existing_slice_users_filter,slice_record))
466 #existing_slice_users = \
467 #self.driver.GetPersons([existing_slice_users_filter])
468 #existing_slice_users = \
469 #self.driver.GetPersons(existing_slice_users_filter, \
471 #logger.debug("SLABSLICE.PY \tverify_person existing_slice_users %s " \
472 #%(existing_slice_users))
473 #Check that the user of the slice in the slice record
474 #matches the existing users
476 if slice_record['record_id_user'] in requested_user_ids and \
477 slice_record['PI'][0] in requested_user_hrns:
478 logger.debug(" SLABSLICE \tverify_person \
479 requested_user_ids %s = \
480 slice_record['record_id_user'] %s" \
481 %(requested_user_ids,slice_record['record_id_user']))
486 #existing_slice_user_hrns = [user['hrn'] for \
487 #user in existing_slice_users]
489 # users to be added, removed or updated
490 #One user in one senslab slice : there should be no need
491 #to remove/ add any user from/to a slice.
492 #However a user from SFA which is not registered in Senslab yet
493 #should be added to the LDAP.
495 added_user_hrns = set(requested_user_hrns).\
496 difference(set(existing_user_hrns))
498 #self.verify_keys(existing_slice_users, updated_users_list, \
503 for added_user_hrn in added_user_hrns:
504 added_user = users_dict[added_user_hrn]
505 #hrn, type = urn_to_hrn(added_user['urn'])
507 'first_name': added_user.get('first_name', hrn),
508 'last_name': added_user.get('last_name', hrn),
509 'person_id': added_user['person_id'],
510 'peer_person_id': None,
512 'key_ids': added_user.get('key_ids', []),
515 person['person_id'] = self.driver.AddPerson(person)
517 person['peer_person_id'] = added_user['person_id']
518 added_persons.append(person)
521 self.driver.UpdatePerson(person['person_id'], {'enabled': True})
524 #self.driver.AddPersonToSite(added_user_id, login_base)
526 #for key_string in added_user.get('keys', []):
527 #key = {'key':key_string, 'key_type':'ssh'}
528 #key['key_id'] = self.driver.AddPersonKey(person['person_id'], \
530 #person['keys'].append(key)
532 # add the registry record
534 #peer_dict = {'type': 'user', 'hrn': hrn, 'peer_authority': \
536 #'pointer': person['person_id']}
537 #self.registry.register_peer_object(self.credential, peer_dict)
538 #for added_slice_user_hrn in \
539 #added_slice_user_hrns.union(added_user_hrns):
540 #self.driver.AddPersonToSlice(added_slice_user_hrn, \
541 #slice_record['name'])
542 #for added_slice_user_id in \
543 #added_slice_user_ids.union(added_user_ids):
544 # add person to the slice
545 #self.driver.AddPersonToSlice(added_slice_user_id, \
546 #slice_record['name'])
547 # if this is a peer record then it
548 # should already be bound to a peer.
549 # no need to return worry about it getting bound later
554 def verify_keys(self, persons, users, peer, options={}):
557 for person in persons:
558 key_ids.extend(person['key_ids'])
559 keylist = self.driver.GetKeys(key_ids, ['key_id', 'key'])
562 keydict[key['key']] = key['key_id']
563 existing_keys = keydict.keys()
565 for person in persons:
566 persondict[person['email']] = person
572 user_keys = user.get('keys', [])
573 updated_persons.append(user)
574 for key_string in user_keys:
575 requested_keys.append(key_string)
576 if key_string not in existing_keys:
577 key = {'key': key_string, 'key_type': 'ssh'}
580 person = persondict[user['email']]
581 self.driver.UnBindObjectFromPeer('person', \
582 person['person_id'], peer['shortname'])
584 self.driver.AddPersonKey(user['email'], key)
586 key_index = user_keys.index(key['key'])
587 remote_key_id = user['key_ids'][key_index]
588 self.driver.BindObjectToPeer('key', \
589 key['key_id'], peer['shortname'], \
594 self.driver.BindObjectToPeer('person', \
595 person['person_id'], peer['shortname'], \
598 # remove old keys (only if we are not appending)
599 append = options.get('append', True)
601 removed_keys = set(existing_keys).difference(requested_keys)
602 for existing_key_id in keydict:
603 if keydict[existing_key_id] in removed_keys:
606 self.driver.UnBindObjectFromPeer('key', \
607 existing_key_id, peer['shortname'])
608 self.driver.DeleteKey(existing_key_id)
612 #def verify_slice_attributes(self, slice, requested_slice_attributes, \
613 #append=False, admin=False):
614 ## get list of attributes users ar able to manage
615 #filter = {'category': '*slice*'}
617 #filter['|roles'] = ['user']
618 #slice_attributes = self.driver.GetTagTypes(filter)
619 #valid_slice_attribute_names = [attribute['tagname'] \
620 #for attribute in slice_attributes]
622 ## get sliver attributes
623 #added_slice_attributes = []
624 #removed_slice_attributes = []
625 #ignored_slice_attribute_names = []
626 #existing_slice_attributes = self.driver.GetSliceTags({'slice_id': \
629 ## get attributes that should be removed
630 #for slice_tag in existing_slice_attributes:
631 #if slice_tag['tagname'] in ignored_slice_attribute_names:
632 ## If a slice already has a admin only role
633 ## it was probably given to them by an
634 ## admin, so we should ignore it.
635 #ignored_slice_attribute_names.append(slice_tag['tagname'])
637 ## If an existing slice attribute was not
638 ## found in the request it should
640 #attribute_found=False
641 #for requested_attribute in requested_slice_attributes:
642 #if requested_attribute['name'] == slice_tag['tagname'] \
643 #and requested_attribute['value'] == slice_tag['value']:
644 #attribute_found=True
647 #if not attribute_found and not append:
648 #removed_slice_attributes.append(slice_tag)
650 ## get attributes that should be added:
651 #for requested_attribute in requested_slice_attributes:
652 ## if the requested attribute wasn't found we should add it
653 #if requested_attribute['name'] in valid_slice_attribute_names:
654 #attribute_found = False
655 #for existing_attribute in existing_slice_attributes:
656 #if requested_attribute['name'] == \
657 #existing_attribute['tagname'] and \
658 #requested_attribute['value'] == \
659 #existing_attribute['value']:
660 #attribute_found=True
662 #if not attribute_found:
663 #added_slice_attributes.append(requested_attribute)
666 ## remove stale attributes
667 #for attribute in removed_slice_attributes:
669 #self.driver.DeleteSliceTag(attribute['slice_tag_id'])
670 #except Exception, error:
671 #self.logger.warn('Failed to remove sliver attribute. name: \
672 #%s, value: %s, node_id: %s\nCause:%s'\
673 #% (name, value, node_id, str(error)))
675 ## add requested_attributes
676 #for attribute in added_slice_attributes:
678 #self.driver.AddSliceTag(slice['name'], attribute['name'], \
679 #attribute['value'], attribute.get('node_id', None))
680 #except Exception, error:
681 #self.logger.warn('Failed to add sliver attribute. name: %s, \
682 #value: %s, node_id: %s\nCause:%s'\
683 #% (name, value, node_id, str(error)))
685 #def create_slice_aggregate(self, xrn, rspec):
686 #hrn, type = urn_to_hrn(xrn)
687 ## Determine if this is a peer slice
688 #peer = self.get_peer(hrn)
689 #sfa_peer = self.get_sfa_peer(hrn)
692 ## Get the slice record from sfa
693 #slicename = hrn_to_pl_slicename(hrn)
696 #registry = self.api.registries[self.api.hrn]
697 #credential = self.api.getCredential()
699 #site_id, remote_site_id = self.verify_site(registry, \
700 #credential, hrn, peer, sfa_peer)
701 #slice = self.verify_slice(registry, credential, \
702 #hrn, site_id, remote_site_id, peer, sfa_peer)
704 ## find out where this slice is currently running
705 #nodelist = self.driver.GetNodes(slice['node_ids'], ['hostname'])
706 #hostnames = [node['hostname'] for node in nodelist]
708 ## get netspec details
709 #nodespecs = spec.getDictsByTagName('NodeSpec')
711 ## dict in which to store slice attributes to set for the nodes
713 #for nodespec in nodespecs:
714 #if isinstance(nodespec['name'], list):
715 #for nodename in nodespec['name']:
716 #nodes[nodename] = {}
717 #for k in nodespec.keys():
718 #rspec_attribute_value = nodespec[k]
719 #if (self.rspec_to_slice_tag.has_key(k)):
720 #slice_tag_name = self.rspec_to_slice_tag[k]
721 #nodes[nodename][slice_tag_name] = \
722 #rspec_attribute_value
723 #elif isinstance(nodespec['name'], StringTypes):
724 #nodename = nodespec['name']
725 #nodes[nodename] = {}
726 #for k in nodespec.keys():
727 #rspec_attribute_value = nodespec[k]
728 #if (self.rspec_to_slice_tag.has_key(k)):
729 #slice_tag_name = self.rspec_to_slice_tag[k]
730 #nodes[nodename][slice_tag_name] = rspec_attribute_value
732 #for k in nodespec.keys():
733 #rspec_attribute_value = nodespec[k]
734 #if (self.rspec_to_slice_tag.has_key(k)):
735 #slice_tag_name = self.rspec_to_slice_tag[k]
736 #nodes[nodename][slice_tag_name] = rspec_attribute_value
738 #node_names = nodes.keys()
739 ## remove nodes not in rspec
740 #deleted_nodes = list(set(hostnames).difference(node_names))
741 ## add nodes from rspec
742 #added_nodes = list(set(node_names).difference(hostnames))
746 #self.driver.UnBindObjectFromPeer('slice', \
747 #slice['slice_id'], peer)
749 #self.driver.LaunchExperimentOnOAR(slicename, added_nodes)
751 ## Add recognized slice tags
752 #for node_name in node_names:
753 #node = nodes[node_name]
754 #for slice_tag in node.keys():
755 #value = node[slice_tag]
756 #if (isinstance(value, list)):
759 #self.driver.AddSliceTag(slicename, slice_tag, \
762 #self.driver.DeleteSliceFromNodes(slicename, deleted_nodes)
765 #self.driver.BindObjectToPeer('slice', slice['slice_id'], \
766 #peer, slice['peer_slice_id'])