From 831bdabf79efab682be23f71426eff6f00d5c20d Mon Sep 17 00:00:00 2001 From: Tony Mack Date: Tue, 6 Apr 2010 16:54:44 +0000 Subject: [PATCH] initial checkin --- sfa/server/interface.py | 170 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 170 insertions(+) create mode 100644 sfa/server/interface.py diff --git a/sfa/server/interface.py b/sfa/server/interface.py new file mode 100644 index 00000000..bea51494 --- /dev/null +++ b/sfa/server/interface.py @@ -0,0 +1,170 @@ +# +### $Id: interface.py 17583 2010-04-06 15:01:08Z tmack $ +### $URL: https://svn.planet-lab.org/svn/sfa/trunk/sfa/server/interface.py $ +# + + +from sfa.util.faults import * +from sfa.util.storage import * +from sfa.trust.gid import GID +from sfa.util.table import SfaTable +import sfa.util.xmlrpcprotocol as xmlrpcprotocol +import sfa.util.soapprotocol as soapprotocol + +# GeniLight client support is optional +try: + from egeni.geniLight_client import * +except ImportError: + GeniClientLight = None + + +## +# In is a dictionary of registry connections keyed on the registry +# hrn + +class Interfaces(dict): + """ + Interfaces is a base class for managing information on the + peers we are federated with. It is responsible for the following: + + 1) Makes sure a record exist in the local registry for the each + fedeated peer + 2) Attepts to fetch and install trusted gids + 3) Provides connections (xmlrpc or soap) to federated peers + """ + + # fields that must be specified in the config file + default_fields = { + 'hrn': '', + 'addr': '', + 'port': '', + } + + # defined by the class + default_dict = {} + + # allowed types + types = ['sa', 'ma'] + + def __init__(self, api, conf_file, type): + if type not in self.allowed_types: + raise SfaInfaildArgument('Invalid type %s: must be in %s' % (type, self.types)) + dict.__init__(self, {}) + self.api = api + + # load config file + self.interface_info = XmlStorage(conf_file, default_dict) + self.interface_info.load() + self.interfaces = self.interface_info.values()[0].values()[0] + if not isinstance(self.interfaces, list): + self.interfaces = [self.interfaces] + + # Attempt to get any missing peer gids + # There should be a gid file in /etc/sfa/trusted_roots for every + # peer registry found in in the registries.xml config file. If there + # are any missing gids, request a new one from the peer registry. + gids_current = self.api.auth.trusted_cert_list.get_list() + hrns_current = [gid.get_hrn() for gid in gids_found] + hrns_expected = [interface['hrn'] for interfaces in self.interfaces] + new_hrns = set(hrns_current).difference(hrns_expected) + + self.get_peer_gids(new_hrns) + + # update the local db records for these registries + self.update_db_records(type) + + # create connections to the registries + self.update(self.get_connections(interfaces)) + + def get_peer_gids(self, new_hrns): + """ + Install trusted gids from the specified interfaces. + """ + if not new_hrns: + return + trusted_certs_dir = self.api.config.get_trustedroots_dir() + for new_hrn in new_hrns: + try: + # get gid from the registry + interface = self.get_connections(self.interfaces[new_hrn])[new_hrn] + trusted_gids = interface.get_trusted_certs() + # default message + message = "interface: %s\tunable to install trusted gid for %s" % \ + (self.api.interface, new_hrn) + if trusted_gids: + # the gid we want shoudl be the first one in the list, + # but lets make sure + for trusted_gid in trusted_gids: + gid = GID(string=trusted_gids[0]) + if gid.get_hrn() == new_hrn: + gid_filename = os.path.join(trusted_certs_dir, '%s.gid' % new_hrn) + gid.save_to_file(gid_filename, save_parents=True) + message = "interface: %s\tinstalled trusted gid for %s" % \ + (self.api.interface, new_hrn) + # log the message + self.api.logger.info(message) + except: + message = "interface: %s\tunable to install trusted gid for %s" % \ + (self.api.interface, new_hrn) + self.api.logger.info(message) + + # reload the trusted certs list + self.api.auth.load_trusted_certs() + + def update_db_records(self, type): + """ + Make sure there is a record in the local db for allowed registries + defined in the config file (registries.xml). Removes old records from + the db. + """ + # get hrns we expect to find + hrns_expected = self.interfaces.keys() + + # get hrns that actually exist in the db + table = SfaTable() + records = table.find({'type': type}) + hrns_found = [record['hrn'] for record in records] + + # remove old records + for record in records: + if record['hrn'] not in hrns_expected: + table.remove(record) + + # add new records + for hrn in hrns_expected: + if hrn not in hrns_found: + record = { + 'hrn': hrn, + 'type': type, + } + table.insert(record) + + + def get_connections(self, interfaces): + """ + read connection details for the trusted peer registries from file return + a dictionary of connections keyed on interface hrn. + """ + connections = {} + required_fields = self.default_fields.keys() + if not isinstance(interfaces, []): + interfaces = [interfaces] + for interface in interfaces: + # make sure the required fields are present and not null + for key in required_fields + if not interface.get(key): + continue + hrn, address, port = interface['hrn'], interface['addr'], interface['port'] + url = 'http://%(address)s:%(port)s' % locals() + # check which client we should use + # sfa.util.xmlrpcprotocol is default + client_type = 'xmlrpcprotocol' + if interface.has_key('client') and \ + interface['client'] in ['geniclientlight'] and \ + GeniClientLight: + client_type = 'geniclientlight' + connections[hrn] = GeniClientLight(url, self.api.key_file, self.api.cert_file) + else: + connections[hrn] = xmlrpcprotocol.get_server(url, self.api.key_file, self.api.cert_file) + + return connections -- 2.43.0