initial checkin
authorTony Mack <tmack@cs.princeton.edu>
Tue, 6 Apr 2010 16:54:44 +0000 (16:54 +0000)
committerTony Mack <tmack@cs.princeton.edu>
Tue, 6 Apr 2010 16:54:44 +0000 (16:54 +0000)
sfa/server/interface.py [new file with mode: 0644]

diff --git a/sfa/server/interface.py b/sfa/server/interface.py
new file mode 100644 (file)
index 0000000..bea5149
--- /dev/null
@@ -0,0 +1,170 @@
+#
+### $Id: interface.py 17583 2010-04-06 15:01:08Z tmack $
+### $URL: https://svn.planet-lab.org/svn/sfa/trunk/sfa/server/interface.py $
+#
+
+
+from sfa.util.faults import *
+from sfa.util.storage import *
+from sfa.trust.gid import GID
+from sfa.util.table import SfaTable
+import sfa.util.xmlrpcprotocol as xmlrpcprotocol
+import sfa.util.soapprotocol as soapprotocol
+# GeniLight client support is optional
+try:
+    from egeni.geniLight_client import *
+except ImportError:
+    GeniClientLight = None            
+
+
+##
+# In is a dictionary of registry connections keyed on the registry
+# hrn
+
+class Interfaces(dict):
+    """
+    Interfaces is a base class for managing information on the
+    peers we are federated with. It is responsible for the following:
+
+    1) Makes sure a record exist in the local registry for the each 
+       fedeated peer   
+    2) Attepts to fetch and install trusted gids   
+    3) Provides connections (xmlrpc or soap) to federated peers
+    """
+
+    # fields that must be specified in the config file
+    default_fields = {
+        'hrn': '',
+        'addr': '', 
+        'port': '', 
+    }
+
+    # defined by the class 
+    default_dict = {}
+
+    # allowed types
+    types = ['sa', 'ma']
+
+    def __init__(self, api, conf_file, type):
+        if type not in self.allowed_types:
+            raise SfaInfaildArgument('Invalid type %s: must be in %s' % (type, self.types))    
+        dict.__init__(self, {})
+        self.api = api
+        
+        # load config file
+        self.interface_info = XmlStorage(conf_file, default_dict)
+        self.interface_info.load()
+        self.interfaces = self.interface_info.values()[0].values()[0]
+        if not isinstance(self.interfaces, list):
+            self.interfaces = [self.interfaces]
+        
+        # Attempt to get any missing peer gids
+        # There should be a gid file in /etc/sfa/trusted_roots for every
+        # peer registry found in in the registries.xml config file. If there
+        # are any missing gids, request a new one from the peer registry.
+        gids_current = self.api.auth.trusted_cert_list.get_list()
+        hrns_current = [gid.get_hrn() for gid in gids_found] 
+        hrns_expected = [interface['hrn'] for interfaces in self.interfaces] 
+        new_hrns = set(hrns_current).difference(hrns_expected)
+        
+        self.get_peer_gids(new_hrns)
+
+        # update the local db records for these registries
+        self.update_db_records(type)
+        
+        # create connections to the registries
+        self.update(self.get_connections(interfaces))
+
+    def get_peer_gids(self, new_hrns):
+        """
+        Install trusted gids from the specified interfaces.  
+        """
+        if not new_hrns:
+            return
+        trusted_certs_dir = self.api.config.get_trustedroots_dir()
+        for new_hrn in new_hrns:
+            try:
+                # get gid from the registry
+                interface = self.get_connections(self.interfaces[new_hrn])[new_hrn]
+                trusted_gids = interface.get_trusted_certs()
+                # default message
+                message = "interface: %s\tunable to install trusted gid for %s" % \
+                           (self.api.interface, new_hrn) 
+                if trusted_gids:
+                    # the gid we want shoudl be the first one in the list, 
+                    # but lets make sure
+                    for trusted_gid in trusted_gids:
+                        gid = GID(string=trusted_gids[0])
+                        if gid.get_hrn() == new_hrn:
+                            gid_filename = os.path.join(trusted_certs_dir, '%s.gid' % new_hrn)
+                            gid.save_to_file(gid_filename, save_parents=True)
+                            message = "interface: %s\tinstalled trusted gid for %s" % \
+                                (self.api.interface, new_hrn)
+                # log the message
+                self.api.logger.info(message)
+            except:
+                message = "interface: %s\tunable to install trusted gid for %s" % \
+                            (self.api.interface, new_hrn) 
+                self.api.logger.info(message)
+        
+        # reload the trusted certs list
+        self.api.auth.load_trusted_certs()
+
+    def update_db_records(self, type):
+        """
+        Make sure there is a record in the local db for allowed registries
+        defined in the config file (registries.xml). Removes old records from
+        the db.         
+        """
+        # get hrns we expect to find
+        hrns_expected = self.interfaces.keys()
+
+        # get hrns that actually exist in the db
+        table = SfaTable()
+        records = table.find({'type': type})
+        hrns_found = [record['hrn'] for record in records]
+        
+        # remove old records
+        for record in records:
+            if record['hrn'] not in hrns_expected:
+                table.remove(record)
+
+        # add new records
+        for hrn in hrns_expected:
+            if hrn not in hrns_found:
+                record = {
+                    'hrn': hrn,
+                    'type': type,
+                }
+            table.insert(record)
+                        
+    def get_connections(self, interfaces):
+        """
+        read connection details for the trusted peer registries from file return 
+        a dictionary of connections keyed on interface hrn. 
+        """
+        connections = {}
+        required_fields = self.default_fields.keys()
+        if not isinstance(interfaces, []):
+            interfaces = [interfaces]
+        for interface in interfaces:
+            # make sure the required fields are present and not null
+            for key in required_fields
+                if not interface.get(key):
+                    continue 
+            hrn, address, port = interface['hrn'], interface['addr'], interface['port']
+            url = 'http://%(address)s:%(port)s' % locals()
+            # check which client we should use
+            # sfa.util.xmlrpcprotocol is default
+            client_type = 'xmlrpcprotocol'
+            if interface.has_key('client') and \
+               interface['client'] in ['geniclientlight'] and \
+               GeniClientLight:
+                client_type = 'geniclientlight'
+                connections[hrn] = GeniClientLight(url, self.api.key_file, self.api.cert_file) 
+            else:
+                connections[hrn] = xmlrpcprotocol.get_server(url, self.api.key_file, self.api.cert_file)
+
+        return connections