trimmed useless imports, unstarred all imports
[sfa.git] / sfa / plc / sfaImport.py
index 8a567d7..4de6e1b 100644 (file)
@@ -8,29 +8,26 @@
 # RSA keys at this time, not DSA keys.
 ##
 
-import getopt
-import sys
-import tempfile
+from sfa.util.sfalogging import _SfaLogger
 
-from sfa.util.record import *
-from sfa.util.genitable import GeniTable
-from sfa.util.misc import *
+from sfa.util.record import SfaRecord
+from sfa.util.table import SfaTable
+from sfa.util.xrn import get_authority, hrn_to_urn
+from sfa.util.plxrn import email_to_hrn
 from sfa.util.config import Config
-from sfa.util.report import trace, error
-
 from sfa.trust.certificate import convert_public_key, Keypair
-from sfa.trust.trustedroot import *
-from sfa.trust.hierarchy import *
+from sfa.trust.trustedroots import TrustedRoots
+from sfa.trust.hierarchy import Hierarchy
 from sfa.trust.gid import create_uuid
 
 
-def un_unicode(str):
+def _un_unicode(str):
    if isinstance(str, unicode):
        return str.encode("ascii", "ignore")
    else:
        return str
 
-def cleanup_string(str):
+def _cleanup_string(str):
     # pgsql has a fit with strings that have high ascii in them, so filter it
     # out when generating the hrns.
     tmp = ""
@@ -39,7 +36,7 @@ def cleanup_string(str):
             tmp = tmp + c
     str = tmp
 
-    str = un_unicode(str)
+    str = _un_unicode(str)
     str = str.replace(" ", "_")
     str = str.replace(".", "_")
     str = str.replace("(", "_")
@@ -48,263 +45,219 @@ def cleanup_string(str):
     str = str.replace('"', "_")
     return str
 
-def person_to_hrn(parent_hrn, person):
-    # the old way - Lastname_Firstname
-    #personname = person['last_name'] + "_" + person['first_name']
-
-    # the new way - use email address up to the "@"
-    personname = person['email'].split("@")[0]
-
-    personname = cleanup_string(personname)
-
-    hrn = parent_hrn + "." + personname
-    return hrn
-
-
 class sfaImport:
 
     def __init__(self):
-        self.AuthHierarchy = Hierarchy()
-        self.TrustedRoots = TrustedRootList()
-
-        self.config = Config()
-        self.plc_auth = self.config.get_plc_auth()
-        self.root_auth = self.config.SFA_REGISTRY_ROOT_AUTH
-        self.level1_auth = self.config.SFA_REGISTRY_LEVEL1_AUTH
-        if not self.level1_auth or self.level1_auth in ['']:
-            self.level1_auth = None
+       self.logger = _SfaLogger(logfile='/var/log/sfa_import.log', loggername='importlog')
+       self.AuthHierarchy = Hierarchy()
+       self.config = Config()
+       self.TrustedRoots = TrustedRoots(Config.get_trustedroots_dir(self.config))
+       self.plc_auth = self.config.get_plc_auth()
+       self.root_auth = self.config.SFA_REGISTRY_ROOT_AUTH
         
-        # connect to planetlab
-        self.shell = None
-        if "Url" in self.plc_auth:
-            from sfa.plc.remoteshell import RemoteShell
-            self.shell = RemoteShell()
-        else:
-            import PLC.Shell
-            self.shell = PLC.Shell.Shell(globals = globals())        
-
-    def get_auth_table(self, auth_name):
-        AuthHierarchy = self.AuthHierarchy
-        auth_info = AuthHierarchy.get_auth_info(auth_name)
-
-        table = GeniTable(hrn=auth_name, cninfo=auth_info.get_dbinfo())
-
-        # if the table doesn't exist, then it means we haven't put any records
-        # into this authority yet.
-
-        if not table.exists():
-            trace("Import: creating table for authority " + auth_name)
-            table.create()
-
-        return table
-
+       # connect to planetlab
+       self.shell = None
+       if "Url" in self.plc_auth:
+          from sfa.plc.remoteshell import RemoteShell
+          self.shell = RemoteShell(self.logger)
+       else:
+          import PLC.Shell
+          self.shell = PLC.Shell.Shell(globals = globals())        
 
     def create_top_level_auth_records(self, hrn):
-        AuthHierarchy = self.AuthHierarchy
-        
-        # if root doesnt exist, create it
-        if not AuthHierarchy.auth_exists(hrn):
-            AuthHierarchy.create_auth(hrn)
-        
-        # get the parent hrn
+        """
+        Create top level records (includes root and sub authorities (local/remote)
+        """
+        urn = hrn_to_urn(hrn, 'authority')
+        # make sure parent exists
         parent_hrn = get_authority(hrn)
         if not parent_hrn:
             parent_hrn = hrn
+        if not parent_hrn == hrn:
+            self.create_top_level_auth_records(parent_hrn)
 
-        # get the auth info of the newly created root auth (parent)
-        # or level1_auth if it exists
-        auth_info = AuthHierarchy.get_auth_info(parent_hrn)
-        if self.level1_auth:
-            auth_info = AuthHierarchy.get_auth_info(hrn)
-        table = self.get_auth_table(parent_hrn)
+        # create the authority if it doesnt already exist 
+        if not self.AuthHierarchy.auth_exists(urn):
+            self.logger.info("Import: creating top level authorities")
+            self.AuthHierarchy.create_auth(urn)
+        
+        # create the db record if it doesnt already exist    
+        auth_info = self.AuthHierarchy.get_auth_info(hrn)
+        table = SfaTable()
+        auth_record = table.find({'type': 'authority', 'hrn': hrn})
 
-        auth_record = table.resolve("authority", hrn)
         if not auth_record:
-            auth_record = GeniRecord(hrn=hrn, gid=auth_info.get_gid_object(), type="authority", pointer=-1)
-            trace("  inserting authority record for " + hrn)
+            auth_record = SfaRecord(hrn=hrn, gid=auth_info.get_gid_object(), type="authority", pointer=-1)
+            auth_record['authority'] = get_authority(auth_record['hrn'])
+            self.logger.info("Import: inserting authority record for %s"%hrn)
             table.insert(auth_record)
 
+    def create_sm_client_record(self):
+        """
+        Create a user record for the Slicemanager service.
+        """
+        hrn = self.config.SFA_INTERFACE_HRN + '.slicemanager'
+        urn = hrn_to_urn(hrn, 'user')
+        if not self.AuthHierarchy.auth_exists(urn):
+            self.logger.info("Import: creating Slice Manager user")
+            self.AuthHierarchy.create_auth(urn)
+
+        auth_info = self.AuthHierarchy.get_auth_info(hrn)
+        table = SfaTable()
+        sm_user_record = table.find({'type': 'user', 'hrn': hrn})
+        if not sm_user_record:
+            record = SfaRecord(hrn=hrn, gid=auth_info.get_gid_object(), type="user", pointer=-1)
+            record['authority'] = get_authority(record['hrn'])
+            table.insert(record)    
+
+    def create_interface_records(self):
+        """
+        Create a record for each SFA interface
+        """
+        # just create certs for all sfa interfaces even if they
+        # arent enabled
+        interface_hrn = self.config.SFA_INTERFACE_HRN
+        interfaces = ['authority+sa', 'authority+am', 'authority+sm']
+        table = SfaTable()
+        auth_info = self.AuthHierarchy.get_auth_info(interface_hrn)
+        pkey = auth_info.get_pkey_object()
+        for interface in interfaces:
+            interface_record = table.find({'type': interface, 'hrn': interface_hrn})
+            if not interface_record:
+                self.logger.info("Import: interface %s %s " % (interface_hrn, interface))
+                urn = hrn_to_urn(interface_hrn, interface)
+                gid = self.AuthHierarchy.create_gid(urn, create_uuid(), pkey)
+                record = SfaRecord(hrn=interface_hrn, gid=gid, type=interface, pointer=-1)  
+                record['authority'] = get_authority(interface_hrn)
+                table.insert(record) 
+                                
 
+    
     def import_person(self, parent_hrn, person):
-        AuthHierarchy = self.AuthHierarchy
-        hrn = person_to_hrn(parent_hrn, person)
+        """
+        Register a user record 
+        """
+        hrn = email_to_hrn(parent_hrn, person['email'])
 
         # ASN.1 will have problems with hrn's longer than 64 characters
         if len(hrn) > 64:
             hrn = hrn[:64]
 
-        trace("Import: importing person " + hrn)
-
-        table = self.get_auth_table(parent_hrn)
-
+        self.logger.info("Import: person %s"%hrn)
         key_ids = []
         if 'key_ids' in person and person['key_ids']:
             key_ids = person["key_ids"]
-
             # get the user's private key from the SSH keys they have uploaded
             # to planetlab
             keys = self.shell.GetKeys(self.plc_auth, key_ids)
             key = keys[0]['key']
-            pkey = convert_public_key(key)
+            pkey = None
+            try:
+                pkey = convert_public_key(key)
+            except:
+                self.logger.warn('unable to convert public key for %s' % hrn) 
+            if not pkey:
+                pkey = Keypair(create=True)
         else:
             # the user has no keys
-            trace("   person " + hrn + " does not have a PL public key")
-
+            self.logger.warn("Import: person %s does not have a PL public key"%hrn)
             # if a key is unavailable, then we still need to put something in the
             # user's GID. So make one up.
             pkey = Keypair(create=True)
 
         # create the gid
-        person_gid = AuthHierarchy.create_gid(hrn, create_uuid(), pkey)
-        person_record = table.resolve("user", hrn)
-        if not person_record:
-            trace("  inserting user record for " + hrn)
-            person_record = GeniRecord(hrn=hrn, gid=person_gid, type="user", pointer=person['person_id'])
+        urn = hrn_to_urn(hrn, 'user')
+        person_gid = self.AuthHierarchy.create_gid(urn, create_uuid(), pkey)
+        table = SfaTable()
+        person_record = SfaRecord(hrn=hrn, gid=person_gid, type="user", pointer=person['person_id'])
+        person_record['authority'] = get_authority(person_record['hrn'])
+        existing_records = table.find({'hrn': hrn, 'type': 'user', 'pointer': person['person_id']})
+        if not existing_records:
             table.insert(person_record)
         else:
-            trace("  updating user record for " + hrn)
-            person_record = GeniRecord(hrn=hrn, gid=person_gid, type="user", pointer=person['person_id'])
+            self.logger.info("Import: %s exists, updating " % hrn)
+            existing_record = existing_records[0]
+            person_record['record_id'] = existing_record['record_id']
             table.update(person_record)
 
     def import_slice(self, parent_hrn, slice):
-        AuthHierarchy = self.AuthHierarchy
         slicename = slice['name'].split("_",1)[-1]
-        slicename = cleanup_string(slicename)
+        slicename = _cleanup_string(slicename)
 
         if not slicename:
-            error("Import_Slice: failed to parse slice name " + slice['name'])
+            self.logger.error("Import: failed to parse slice name %s" %slice['name'])
             return
 
         hrn = parent_hrn + "." + slicename
-        trace("Import: importing slice " + hrn)
-
-        table = self.get_auth_table(parent_hrn)
-
-        slice_record = table.resolve("slice", hrn)
-        if not slice_record:
-            pkey = Keypair(create=True)
-            slice_gid = AuthHierarchy.create_gid(hrn, create_uuid(), pkey)
-            slice_record = GeniRecord(hrn=hrn, gid=slice_gid, type="slice", pointer=slice['slice_id'])
-            trace("  inserting slice record for " + hrn)
+        self.logger.info("Import: slice %s"%hrn)
+
+        pkey = Keypair(create=True)
+        urn = hrn_to_urn(hrn, 'slice')
+        slice_gid = self.AuthHierarchy.create_gid(urn, create_uuid(), pkey)
+        slice_record = SfaRecord(hrn=hrn, gid=slice_gid, type="slice", pointer=slice['slice_id'])
+        slice_record['authority'] = get_authority(slice_record['hrn'])
+        table = SfaTable()
+        existing_records = table.find({'hrn': hrn, 'type': 'slice', 'pointer': slice['slice_id']})
+        if not existing_records:
             table.insert(slice_record)
+        else:
+            self.logger.info("Import: %s exists, updating " % hrn)
+            existing_record = existing_records[0]
+            slice_record['record_id'] = existing_record['record_id']
+            table.update(slice_record)
 
-    def import_node(self, parent_hrn, node):
-        AuthHierarchy = self.AuthHierarchy
-        nodename = node['hostname'].replace(".", "_")
-        nodename = cleanup_string(nodename)
-
-        if not nodename:
-            error("Import_node: failed to parse node name " + node['hostname'])
-            return
-
-        hrn = parent_hrn + "." + nodename
-
+    def import_node(self, hrn, node):
+        self.logger.info("Import: node %s" % hrn)
         # ASN.1 will have problems with hrn's longer than 64 characters
         if len(hrn) > 64:
             hrn = hrn[:64]
 
-        trace("Import: importing node " + hrn)
-
-        table = self.get_auth_table(parent_hrn)
-
-        node_record = table.resolve("node", hrn)
-        if not node_record:
-            pkey = Keypair(create=True)
-            node_gid = AuthHierarchy.create_gid(hrn, create_uuid(), pkey)
-            node_record = GeniRecord(hrn=hrn, gid=node_gid, type="node", pointer=node['node_id'])
-            trace("  inserting node record for " + hrn)
+        table = SfaTable()
+        node_record = table.find({'type': 'node', 'hrn': hrn})
+        pkey = Keypair(create=True)
+        urn = hrn_to_urn(hrn, 'node')
+        node_gid = self.AuthHierarchy.create_gid(urn, create_uuid(), pkey)
+        node_record = SfaRecord(hrn=hrn, gid=node_gid, type="node", pointer=node['node_id'])
+        node_record['authority'] = get_authority(node_record['hrn'])
+        existing_records = table.find({'hrn': hrn, 'type': 'node', 'pointer': node['node_id']})
+        if not existing_records:
             table.insert(node_record)
-
+        else:
+            self.logger.info("Import: %s exists, updating " % hrn)
+            existing_record = existing_records[0]
+            node_record['record_id'] = existing_record['record_id']
+            table.update(node_record)
 
     
-    def import_site(self, parent_hrn, site):
-        AuthHierarchy = self.AuthHierarchy
-        shell = self.shell
-        plc_auth = self.plc_auth
-        sitename = site['login_base']
-        sitename = cleanup_string(sitename)
-
-        hrn = parent_hrn + "." + sitename
-
-        # Hardcode 'internet2' into the hrn for sites hosting
-        # internet2 nodes. This is a special operation for some vini
-        # sites only
-        if ".vini" in parent_hrn and parent_hrn.endswith('vini'):
-            if sitename.startswith("ii"):
-                sitename = sitename.replace("ii", "")
-                hrn = ".".join([parent_hrn, "internet2", sitename])
-            elif sitename.startswith("nlr"):
-                hrn = ".".join([parent_hrn, "internet2", sitename])
-                sitename = sitename.replace("nlr", "")
-
-        trace("Import_Site: importing site " + hrn)
+    def import_site(self, hrn, site):
+        urn = hrn_to_urn(hrn, 'authority')
+        self.logger.info("Import: site %s"%hrn)
 
         # create the authority
-        if not AuthHierarchy.auth_exists(hrn):
-            AuthHierarchy.create_auth(hrn)
+        if not self.AuthHierarchy.auth_exists(urn):
+            self.AuthHierarchy.create_auth(urn)
 
-        auth_info = AuthHierarchy.get_auth_info(hrn)
+        auth_info = self.AuthHierarchy.get_auth_info(urn)
 
-        table = self.get_auth_table(parent_hrn)
-
-        auth_record = table.resolve("authority", hrn)
-        if not auth_record:
-            auth_record = GeniRecord(hrn=hrn, gid=auth_info.get_gid_object(), type="authority", pointer=site['site_id'])
-            trace("  inserting authority record for " + hrn)
+        table = SfaTable()
+        auth_record = SfaRecord(hrn=hrn, gid=auth_info.get_gid_object(), type="authority", pointer=site['site_id'])
+        auth_record['authority'] = get_authority(auth_record['hrn'])
+        existing_records = table.find({'hrn': hrn, 'type': 'authority', 'pointer': site['site_id']})
+        if not existing_records:
             table.insert(auth_record)
+        else:
+            self.logger.info("Import: %s exists, updating " % hrn)
+            existing_record = existing_records[0]
+            auth_record['record_id'] = existing_record['record_id']
+            table.update(auth_record)
 
-        if 'person_ids' in site:
-            for person_id in site['person_ids']:
-                persons = shell.GetPersons(plc_auth, [person_id])
-                if persons:
-                    try:
-                        self.import_person(hrn, persons[0])
-                    except Exception, e:
-                        trace("Failed to import: %s (%s)" % (persons[0], e))
-        if 'slice_ids' in site:
-            for slice_id in site['slice_ids']:
-                slices = shell.GetSlices(plc_auth, [slice_id])
-                if slices:
-                    try:
-                        self.import_slice(hrn, slices[0])
-                    except Exception, e:
-                        trace("Failed to import: %s (%s)" % (slices[0], e))
-        if 'node_ids' in site:
-            for node_id in site['node_ids']:
-                nodes = shell.GetNodes(plc_auth, [node_id])
-                if nodes:
-                    try:
-                        self.import_node(hrn, nodes[0])
-                    except Exception, e:
-                        trace("Failed to import: %s (%s)" % (nodes[0], e))     
+        return hrn
 
-    def delete_record(self, parent_hrn, object, type):
-        # get the hrn
-        hrn = None
-        if type in ['slice'] and 'name' in object and object['name']:
-            slice_name = object['name'].split("_")[0]
-            hrn = parent_hrn + "." + slice_name
-        elif type in ['user'] and 'email' in object and object['email']:
-            person_name = object['email'].split('@')[0]
-            hrn = parent_hrn + "." + person_name
-        elif type in ['node'] and 'hostname' in object and object['hostname']:
-            node_name =  object['hostname'].replace('.','_')  
-            hrn = parent_hrn + "." + node_name
-        elif type in ['site'] and 'login_base' in object and object['login_base']:
-            site_name = object['login_base']
-            hrn = parent_hrn
-            parent_hrn = get_authority(hrn)
-            type = "authority"
-            # delete the site table
-            site_table = self.get_auth_table(hrn)
-            site_table.drop()
-        else:
-            return
-        
+
+    def delete_record(self, hrn, type):
         # delete the record
-        table = self.get_auth_table(parent_hrn)
-        record_list = table.resolve(type, hrn)
-        if not record_list:
-            return
-        record = record_list[0]
-        table.remove(record)        
+        table = SfaTable()
+        record_list = table.find({'type': type, 'hrn': hrn})
+        for record in record_list:
+            self.logger.info("Import: removing record %s %s" % (type, hrn))
+            table.remove(record)