Use cached ACLs
[invirt/packages/invirt-web.git] / cache_acls.py
index 353574a..ca0b7c9 100644 (file)
@@ -33,17 +33,27 @@ def expandName(name):
 if __name__ == '__main__':
     connect('postgres://sipb-xen@sipb-xen-dev/sipb_xen')
     
-    machines = Machine.select()
-    for m in machines:
-        people = set()
-        people.update(expandLocker(m.owner))
-        people.update(expandName(m.administrator))
-        print '%s: %s' % (m.name, ' '.join(people))
-        transaction = ctx.current.create_transaction()
-        for a in m.acl:
-            ctx.current.delete(a)
-        for p in people:
-            ma = MachineAccess(machine_id=m.machine_id, user=p)
-            ctx.current.save(ma)
-        ctx.current.flush()
+    transaction = ctx.current.create_transaction()
+
+    try:
+        machines = Machine.select()
+        for m in machines:
+            people = set()
+            people.update(expandLocker(m.owner))
+            people.update(expandName(m.administrator))
+            print '%s: %s' % (m.name, ' '.join(people))
+            old_people = set(a.user for a in m.acl)
+            for removed in old_people - people:
+                ma = [x for x in m.acl if x.user == removed][0]
+                ctx.current.delete(ma)
+            for p in people - old_people:
+                ma = MachineAccess(machine_id=m.machine_id, user=p)
+                ctx.current.save(ma)
+            ctx.current.flush()
+            
+        # Atomically execute our changes
         transaction.commit()
+    except:
+        # Failed! Rollback all the changes.
+        transaction.rollback()
+        raise