fix remconffs
[invirt/packages/invirt-remote.git] / server / usr / sbin / invirt-remconffs
index 6389391..17ec450 100755 (executable)
@@ -14,6 +14,7 @@ class RemConfFS(routefs.RouteFS):
     """
     RemConfFS creates a filesytem for configuring remctl, like this:
     /
+    |-- adminacl
     |-- acl
     |   |-- machine1
     |   ...
@@ -36,14 +37,15 @@ class RemConfFS(routefs.RouteFS):
     
     def make_map(self):
         m = Mapper()
-        m.connect('', controller='getroot')
-        m.connect('acl', controller='getmachines')
-        m.connect('acl/:machine', controller='getacl')
-        m.connect('conf', controller='getconf')
+        m.connect('/', controller='getroot')
+        m.connect('/acl', controller='getmachines')
+        m.connect('/acl/:machine', controller='getacl')
+        m.connect('/adminacl', controller='getadmin')
+        m.connect('/conf', controller='getconf')
         return m
     
     def getroot(self, **kw):
-        return ['acl', 'conf']
+        return ['adminacl', 'acl', 'conf']
     
     def getacl(self, machine, **kw):
         """Build the ACL file for a machine
@@ -55,21 +57,29 @@ class RemConfFS(routefs.RouteFS):
                           from_obj=[database.machine_access_table, database.machine_table]) # from tables
         users = [self.userToPrinc(acl[0]) for acl in
                  database.session.execute(s)]
-        return "\n".join(users
-                 + ['include /etc/remctl/acl/web',
-                    ''])
+        return routefs.File("\n".join(users
+                                      + ['include /etc/remctl/acl/web',
+                                         '']))
     
     def getconf(self, **kw):
         """Build the master conf file, with all machines
         """
-        return '\n'.join("control %s /usr/sbin/invirt-remote-proxy-control"
-                 " /etc/remctl/remconffs/acl/%s"
-                 % (machine_name, machine_name)
-                 for machine_name in self.getmachines())+'\n'
+        return routefs.File('\n'.join("control %s /usr/sbin/invirt-remote-proxy-control"
+                                      " /etc/remctl/remconffs/acl/%s"
+                                      % (machine_name, machine_name)
+                                      for machine_name in self.getmachines())+'\n')
     
     def getmachines(self, **kw):
         """Get the list of VMs in the database. Does not cache to prevent race conditions."""
-        return list(row[0] for row in database.session.execute(sa.sql.select([database.Machine.c.name])))
+        return list(row[0] for row in database.session.execute(sa.sql.select([database.Machine.name])))
+
+    def getadmin(self, **kw):
+        """
+        Get the list of administrators for the global ACL.
+        """
+        acl = [self.userToPrinc(row[0]) for row in database.session.execute(sa.sql.select([database.admins_table.c.user]))]
+        acl.append('include /etc/remctl/acl/web\n')
+        return routefs.File('\n'.join(acl))
     
     def userToPrinc(self, user):
         """Convert Kerberos v4-style names to v5-style and append a default
@@ -79,7 +89,7 @@ class RemConfFS(routefs.RouteFS):
             (princ, realm) = user.split('@')
         else:
             princ = user
-            realm = config.authn[0].realm
+            realm = config.kerberos.realm
         
         return princ.replace('.', '/') + '@' + realm