import sha
import hmac
import datetime
+import StringIO
+import getafsgroups
-sys.stderr = sys.stdout
+sys.stderr = StringIO.StringIO()
sys.path.append('/home/ecprice/.local/lib/python2.5/site-packages')
from Cheetah.Template import Template
import random
class MyException(Exception):
+ """Base class for my exceptions"""
pass
+class InvalidInput(MyException):
+ """Exception for user-provided input is invalid but maybe in good faith.
+
+ This would include setting memory to negative (which might be a
+ typo) but not setting an invalid boot CD (which requires bypassing
+ the select box).
+ """
+ def __init__(self, err_field, err_value, expl=None):
+ super(InvalidInput, self).__init__(expl)
+ self.err_field = err_field
+ self.err_value = err_value
+
+class CodeError(MyException):
+ """Exception for internal errors or bad faith input."""
+ pass
+
+class Global(object):
+ def __init__(self, user):
+ self.user = user
+
+ def __get_uptimes(self):
+ if not hasattr(self, '_uptimes'):
+ self._uptimes = getUptimes(Machine.select())
+ return self._uptimes
+ uptimes = property(__get_uptimes)
+
+g = None
+
def helppopup(subj):
+ """Return HTML code for a (?) link to a specified help topic"""
return '<span class="helplink"><a href="help?subject='+subj+'&simple=true" target="_blank" onclick="return helppopup(\''+subj+'\')">(?)</a></span>'
return [ random.randint(0, 255) for _ in range(0, 16) ]
def uuidToString(u):
+ """Turn a numeric UUID to a hyphen-seperated one."""
return "-".join(["%02x" * 4, "%02x" * 2, "%02x" * 2, "%02x" * 2,
"%02x" * 6]) % tuple(u)
MAX_VMS_TOTAL = 10
MAX_VMS_ACTIVE = 4
-def getMachinesOwner(owner):
+def getMachinesByOwner(owner):
+ """Return the machines owned by a given owner."""
return Machine.select_by(owner=owner)
-def maxMemory(user, machine=None, on=None):
- machines = getMachinesOwner(user.username)
- if on is None:
- on = getUptimes(machines)
- active_machines = [x for x in machines if on[x]]
+def maxMemory(user, machine=None):
+ """Return the maximum memory for a machine or a user.
+
+ If machine is None, return the memory available for a new
+ machine. Else, return the maximum that machine can have.
+
+ on is a dictionary from machines to booleans, whether a machine is
+ on. If None, it is recomputed. XXX make this global?
+ """
+
+ machines = getMachinesByOwner(user.username)
+ active_machines = [x for x in machines if g.uptimes[x]]
mem_usage = sum([x.memory for x in active_machines if x != machine])
return min(MAX_MEMORY_SINGLE, MAX_MEMORY_TOTAL-mem_usage)
def maxDisk(user, machine=None):
- machines = getMachinesOwner(user.username)
+ machines = getMachinesByOwner(user.username)
disk_usage = sum([sum([y.size for y in x.disks])
for x in machines if x != machine])
return min(MAX_DISK_SINGLE, MAX_DISK_TOTAL-disk_usage/1024.)
-def canAddVm(user, on=None):
- machines = getMachinesOwner(user.username)
- if on is None:
- on = getUptimes(machines)
- active_machines = [x for x in machines if on[x]]
+def canAddVm(user):
+ machines = getMachinesByOwner(user.username)
+ active_machines = [x for x in machines if g.uptimes[x]]
return (len(machines) < MAX_VMS_TOTAL and
len(active_machines) < MAX_VMS_ACTIVE)
def haveAccess(user, machine):
+ """Return whether a user has access to a machine"""
if user.username == 'moo':
return True
- return machine.owner == user.username
+ return getafsgroups.checkLockerOwner(user.username,machine.owner)
+
+def error(op, user, fields, err, emsg):
+ """Print an error page when a CodeError occurs"""
+ d = dict(op=op, user=user, errorMessage=str(err),
+ stderr=emsg)
+ return Template(file='error.tmpl', searchList=[d, global_dict]);
-def error(op, user, fields, err):
- d = dict(op=op, user=user, errorMessage=str(err))
- print Template(file='error.tmpl', searchList=[d, global_dict]);
+def invalidInput(op, user, fields, err, emsg):
+ """Print an error page when an InvalidInput exception occurs"""
+ d = dict(op=op, user=user, err_field=err.err_field,
+ err_value=str(err.err_value), stderr=emsg,
+ errorMessage=str(err))
+ return Template(file='invalid.tmpl', searchList=[d, global_dict]);
def validMachineName(name):
"""Check that name is valid for a machine name"""
stderr=subprocess.PIPE)
e = p.wait()
if e:
- raise MyException("Error %s in kinit: %s" % (e, p.stderr.read()))
+ raise CodeError("Error %s in kinit: %s" % (e, p.stderr.read()))
def checkKinit():
"""If we lack tickets, kinit."""
p.wait()
return p.stdout.read(), p.stderr.read()
if p.wait():
- raise MyException('ERROR on remctl %s: %s' %
+ raise CodeError('ERROR on remctl %s: %s' %
(args, p.stderr.read()))
return p.stdout.read()
-def makeDisks():
- """Update the lvm partitions to include all disks in the database."""
- remctl('web', 'lvcreate')
+def lvcreate(machine, disk):
+ """Create a single disk for a machine"""
+ remctl('web', 'lvcreate', machine.name,
+ disk.guest_device_name, str(disk.size))
+
+def makeDisks(machine):
+ """Update the lvm partitions to add a disk."""
+ for disk in machine.disks:
+ lvcreate(machine, disk)
def bootMachine(machine, cdtype):
"""Boot a machine with a given boot CD.
stack[-1].extend(v.split())
return stack[-1]
-def getUptimes(machines):
+def getUptimes(machines=None):
"""Return a dictionary mapping machine names to uptime strings"""
value_string = remctl('web', 'listvms')
lines = value_string.splitlines()
d = {}
- for line in lines[1:]:
+ for line in lines:
lst = line.split()
name, id = lst[:2]
uptime = ' '.join(lst[2:])
"""
value_string, err_string = remctl('list-long', machine.name, err=True)
if 'Unknown command' in err_string:
- raise MyException("ERROR in remctl list-long %s is not registered" % (machine.name,))
+ raise CodeError("ERROR in remctl list-long %s is not registered" % (machine.name,))
elif 'does not exist' in err_string:
return None
elif err_string:
- raise MyException("ERROR in remctl list-long %s: %s" % (machine.name, err_string))
+ raise CodeError("ERROR in remctl list-long %s: %s" % (machine.name, err_string))
status = parseStatus(value_string)
return status
transaction = ctx.current.create_transaction()
try:
if memory > maxMemory(user):
- raise MyException("Too much memory requested")
+ raise InvalidInput('memory', memory,
+ "Max %s" % maxMemory(user))
if disk > maxDisk(user) * 1024:
- raise MyException("Too much disk requested")
+ raise InvalidInput('disk', disk,
+ "Max %s" % maxDisk(user))
if not canAddVm(user):
- raise MyException("Too many VMs requested")
+ raise InvalidInput('create', True, 'Unable to create more VMs')
res = meta.engine.execute('select nextval(\'"machines_machine_id_seq"\')')
id = res.fetchone()[0]
machine = Machine()
'hda', disk)
open = NIC.select_by(machine_id=None)
if not open: #No IPs left!
- return "No IP addresses left! Contact sipb-xen-dev@mit.edu"
+ raise CodeError("No IP addresses left! Contact sipb-xen-dev@mit.edu")
nic = open[0]
nic.machine_id = machine.machine_id
nic.hostname = name
transaction.rollback()
raise
registerMachine(machine)
- makeDisks()
+ makeDisks(machine)
# tell it to boot with cdrom
bootMachine(machine, cdrom)
return machine
def validMemory(user, memory, machine=None):
+ """Parse and validate limits for memory for a given user and machine."""
try:
memory = int(memory)
if memory < MIN_MEMORY_SINGLE:
raise ValueError
except ValueError:
- raise MyException("Invalid memory amount; must be at least %s MB" %
- MIN_MEMORY_SINGLE)
+ raise InvalidInput('memory', memory,
+ "Minimum %s MB" % MIN_MEMORY_SINGLE)
if memory > maxMemory(user, machine):
- raise MyException("Too much memory requested")
+ raise InvalidInput('memory', memory,
+ 'Maximum %s MB' % maxMemory(user, machine))
return memory
def validDisk(user, disk, machine=None):
+ """Parse and validate limits for disk for a given user and machine."""
try:
disk = float(disk)
if disk > maxDisk(user, machine):
- raise MyException("Too much disk requested")
+ raise InvalidInput('disk', disk,
+ "Maximum %s G" % maxDisk(user, machine))
disk = int(disk * 1024)
if disk < MIN_DISK_SINGLE * 1024:
raise ValueError
except ValueError:
- raise MyException("Invalid disk amount; minimum is %s GB" %
- MIN_DISK_SINGLE)
+ raise InvalidInput('disk', disk,
+ "Minimum %s GB" % MIN_DISK_SINGLE)
return disk
def create(user, fields):
+ """Handler for create requests."""
name = fields.getfirst('name')
if not validMachineName(name):
- raise MyException("Invalid name '%s'" % name)
- name = user.username + '_' + name.lower()
+ raise InvalidInput('name', name)
+ name = name.lower()
if Machine.get_by(name=name):
- raise MyException("A machine named '%s' already exists" % name)
+ raise InvalidInput('name', name,
+ "Already exists")
memory = fields.getfirst('memory')
memory = validMemory(user, memory)
vm_type = fields.getfirst('vmtype')
if vm_type not in ('hvm', 'paravm'):
- raise MyException("Invalid vm type '%s'" % vm_type)
+ raise CodeError("Invalid vm type '%s'" % vm_type)
is_hvm = (vm_type == 'hvm')
cdrom = fields.getfirst('cdrom')
if cdrom is not None and not CDROM.get(cdrom):
- raise MyException("Invalid cdrom type '%s'" % cdrom)
+ raise CodeError("Invalid cdrom type '%s'" % cdrom)
machine = createVm(user, name, memory, disk, is_hvm, cdrom)
- if isinstance(machine, basestring):
- raise MyException(machine)
d = dict(user=user,
machine=machine)
- print Template(file='create.tmpl',
+ return Template(file='create.tmpl',
searchList=[d, global_dict]);
def listVms(user, fields):
+ """Handler for list requests."""
machines = [m for m in Machine.select() if haveAccess(user, m)]
on = {}
has_vnc = {}
- uptimes = getUptimes(machines)
- on = uptimes
+ on = g.uptimes
for m in machines:
if not on[m]:
has_vnc[m] = 'Off'
# status = statusInfo(m)
# on[m.name] = status is not None
# has_vnc[m.name] = hasVnc(status)
- max_mem=maxMemory(user, on=on)
+ max_mem=maxMemory(user)
max_disk=maxDisk(user)
d = dict(user=user,
- can_add_vm=canAddVm(user, on=on),
+ can_add_vm=canAddVm(user),
max_mem=max_mem,
max_disk=max_disk,
default_mem=max_mem,
default_disk=min(4.0, max_disk),
machines=machines,
has_vnc=has_vnc,
- uptimes=uptimes,
+ uptimes=g.uptimes,
cdroms=CDROM.select())
- print Template(file='list.tmpl', searchList=[d, global_dict])
+ return Template(file='list.tmpl', searchList=[d, global_dict])
def testMachineId(user, machineId, exists=True):
+ """Parse, validate and check authorization for a given machineId.
+
+ If exists is False, don't check that it exists.
+ """
if machineId is None:
- raise MyException("No machine ID specified")
+ raise CodeError("No machine ID specified")
try:
machineId = int(machineId)
except ValueError:
- raise MyException("Invalid machine ID '%s'" % machineId)
+ raise CodeError("Invalid machine ID '%s'" % machineId)
machine = Machine.get(machineId)
if exists and machine is None:
- raise MyException("No such machine ID '%s'" % machineId)
- if not haveAccess(user, machine):
- raise MyException("No access to machine ID '%s'" % machineId)
+ raise CodeError("No such machine ID '%s'" % machineId)
+ if machine is not None and not haveAccess(user, machine):
+ raise CodeError("No access to machine ID '%s'" % machineId)
return machine
def vnc(user, fields):
-t nat -A PREROUTING -s ! 18.181.0.60 -i eth1 -p tcp -m tcp --dport 10003 -j DNAT --to-destination 18.181.0.60:10003
-t nat -A POSTROUTING -d 18.181.0.60 -o eth1 -p tcp -m tcp --dport 10003 -j SNAT --to-source 18.187.7.142
-A FORWARD -d 18.181.0.60 -i eth1 -o eth1 -p tcp -m tcp --dport 10003 -j ACCEPT
+
+ Remember to enable iptables!
+ echo 1 > /proc/sys/net/ipv4/ip_forward
"""
machine = testMachineId(user, fields.getfirst('machine_id'))
- #XXX fix
TOKEN_KEY = "0M6W0U1IXexThi5idy8mnkqPKEq1LtEnlK/pZSn0cDrN"
token = cPickle.dumps(token)
token = base64.urlsafe_b64encode(token)
+ status = statusInfo(machine)
+ has_vnc = hasVnc(status)
+
d = dict(user=user,
+ on=status,
+ has_vnc=has_vnc,
machine=machine,
hostname=os.environ.get('SERVER_NAME', 'localhost'),
authtoken=token)
- print Template(file='vnc.tmpl',
+ return Template(file='vnc.tmpl',
searchList=[d, global_dict])
def getNicInfo(data_dict, machine):
+ """Helper function for info, get data on nics for a machine.
+
+ Modifies data_dict to include the relevant data, and returns a list
+ of (key, name) pairs to display "name: data_dict[key]" to the user.
+ """
data_dict['num_nics'] = len(machine.nics)
nic_fields_template = [('nic%s_hostname', 'NIC %s hostname'),
('nic%s_mac', 'NIC %s MAC Addr'),
return nic_fields
def getDiskInfo(data_dict, machine):
+ """Helper function for info, get data on disks for a machine.
+
+ Modifies data_dict to include the relevant data, and returns a list
+ of (key, name) pairs to display "name: data_dict[key]" to the user.
+ """
data_dict['num_disks'] = len(machine.disks)
disk_fields_template = [('%s_size', '%s size')]
disk_fields = []
return disk_fields
def deleteVM(machine):
+ """Delete a VM."""
+ try:
+ remctl('destroy', machine.name)
+ except:
+ pass
transaction = ctx.current.create_transaction()
delete_disk_pairs = [(machine.name, d.guest_device_name) for d in machine.disks]
try:
unregisterMachine(machine)
def command(user, fields):
- print time.time()-start_time
+ """Handler for running commands like boot and delete on a VM."""
+ print >> sys.stderr, time.time()-start_time
machine = testMachineId(user, fields.getfirst('machine_id'))
action = fields.getfirst('action')
cdrom = fields.getfirst('cdrom')
- print time.time()-start_time
+ print >> sys.stderr, time.time()-start_time
if cdrom is not None and not CDROM.get(cdrom):
- raise MyException("Invalid cdrom type '%s'" % cdrom)
+ raise CodeError("Invalid cdrom type '%s'" % cdrom)
if action not in ('Reboot', 'Power on', 'Power off', 'Shutdown', 'Delete VM'):
- raise MyException("Invalid action '%s'" % action)
+ raise CodeError("Invalid action '%s'" % action)
if action == 'Reboot':
if cdrom is not None:
remctl('reboot', machine.name, cdrom)
remctl('reboot', machine.name)
elif action == 'Power on':
if maxMemory(user) < machine.memory:
- raise MyException("You don't have enough free RAM quota")
+ raise InvalidInput('action', 'Power on',
+ "You don't have enough free RAM quota to turn on this machine")
bootMachine(machine, cdrom)
elif action == 'Power off':
remctl('destroy', machine.name)
remctl('shutdown', machine.name)
elif action == 'Delete VM':
deleteVM(machine)
- print time.time()-start_time
+ print >> sys.stderr, time.time()-start_time
d = dict(user=user,
command=action,
machine=machine)
- print Template(file="command.tmpl", searchList=[d, global_dict])
-
+ return Template(file="command.tmpl", searchList=[d, global_dict])
+
+def testOwner(user, owner, machine=None):
+ if not getafsgroups.checkLockerOwner(user.username, owner):
+ raise InvalidInput('owner', owner,
+ "Invalid")
+ return owner
+
+def testContact(user, contact, machine=None):
+ if contact != user.email:
+ raise InvalidInput('contact', contact,
+ "Invalid")
+ return contact
+
+def testDisk(user, disksize, machine=None):
+ return disksize
+
+def testName(user, name, machine=None):
+ return name
+
+def testHostname(user, hostname, machine):
+ for nic in machine.nics:
+ if hostname == nic.hostname:
+ return hostname
+ # check if doesn't already exist
+ if NIC.select_by(hostname=hostname) == []:
+ return hostname
+ raise InvalidInput('hostname', hostname,
+ "Different from before")
+
+
def modify(user, fields):
- machine = testMachineId(user, fields.getfirst('machine_id'))
-
+ """Handler for modifying attributes of a machine."""
+ #XXX not written yet
+
+ transaction = ctx.current.create_transaction()
+ try:
+ machine = testMachineId(user, fields.getfirst('machine_id'))
+ owner = testOwner(user, fields.getfirst('owner'), machine)
+ contact = testContact(user, fields.getfirst('contact'))
+ hostname = testHostname(owner, fields.getfirst('hostname'),
+ machine)
+ name = testName(user, fields.getfirst('name'))
+ oldname = machine.name
+ olddisk = {}
+
+ memory = fields.getfirst('memory')
+ if memory is not None:
+ memory = validMemory(user, memory, machine)
+ if memory != machine.memory:
+ machine.memory = memory
+
+ disksize = testDisk(user, fields.getfirst('disk'))
+ if disksize is not None:
+ disksize = validDisk(user, disksize, machine)
+
+ for disk in machine.disks:
+ disk.size = disksize
+ olddisk[disk.guest_device_name] = disk.size
+ ctx.current.save(disk)
+
+ # XXX all NICs get same hostname on change? Interface doesn't support more.
+ for nic in machine.nics:
+ nic.hostname = hostname
+ ctx.current.save(nic)
+
+ if owner != machine.owner:
+ machine.owner = owner
+ if name != machine.name:
+ machine.name = name
+
+ ctx.current.save(machine)
+ transaction.commit()
+ except:
+ transaction.rollback()
+ remctl("web", "moveregister", oldname, name)
+ for disk in machine.disks:
+ # XXX all disks get the same size on change? Interface doesn't support more.
+ if disk.size != olddisk[disk.guest_device_name]:
+ remctl("web", "lvresize", oldname, disk.guest_device_name, str(disk.size))
+ if oldname != name:
+ remctl("web", "lvrename", oldname, disk.guest_device_name, name)
+ d = dict(user=user,
+ command="modify",
+ machine=machine)
+ return Template(file="command.tmpl", searchList=[d, global_dict])
+
+
def help(user, fields):
+ """Handler for help messages."""
simple = fields.getfirst('simple')
subjects = fields.getlist('subject')
subjects=subjects,
mapping=mapping)
- print Template(file="help.tmpl", searchList=[d, global_dict])
+ return Template(file="help.tmpl", searchList=[d, global_dict])
def info(user, fields):
+ """Handler for info on a single VM."""
machine = testMachineId(user, fields.getfirst('machine_id'))
status = statusInfo(machine)
has_vnc = hasVnc(status)
]
fields = []
machine_info = {}
+ machine_info['name'] = machine.name
machine_info['type'] = machine.type.hvm and 'HVM' or 'ParaVM'
machine_info['owner'] = machine.owner
machine_info['contact'] = machine.contact
for field, disp in display_fields:
if field in ('uptime', 'cputime'):
fields.append((disp, locals()[field]))
- elif field in main_status:
- fields.append((disp, main_status[field]))
elif field in machine_info:
fields.append((disp, machine_info[field]))
+ elif field in main_status:
+ fields.append((disp, main_status[field]))
else:
pass
#fields.append((disp, None))
max_mem=max_mem,
max_disk=max_disk,
fields = fields)
- print Template(file='info.tmpl',
+ return Template(file='info.tmpl',
searchList=[d, global_dict])
mapping = dict(list=listVms,
username = "moo"
email = 'moo@cow.com'
u = User()
+ g = Global(u)
if 'SSL_CLIENT_S_DN_Email' in os.environ:
username = os.environ[ 'SSL_CLIENT_S_DN_Email'].split("@")[0]
u.username = username
u.email = 'nobody'
connect('postgres://sipb-xen@sipb-xen-dev/sipb_xen')
operation = os.environ.get('PATH_INFO', '')
- #print 'Content-Type: text/plain\n'
- #print operation
+# print 'Content-Type: text/plain\n'
+# print operation
if not operation:
print "Status: 301 Moved Permanently"
print 'Location: ' + os.environ['SCRIPT_NAME']+'/\n'
sys.exit(0)
- print 'Content-Type: text/html\n'
if operation.startswith('/'):
operation = operation[1:]
if not operation:
operation = 'list'
-
- fun = mapping.get(operation,
- lambda u, e:
- error(operation, u, e,
- "Invalid operation '%s'" % operation))
+
+ def badOperation(u, e):
+ raise CodeError("Unknown operation")
+
+ fun = mapping.get(operation, badOperation)
if fun not in (help, ):
connect('postgres://sipb-xen@sipb-xen-dev/sipb_xen')
try:
- fun(u, fields)
- except MyException, err:
- error(operation, u, fields, err)
+ output = fun(u, fields)
+ print 'Content-Type: text/html\n'
+ sys.stderr.seek(0)
+ e = sys.stderr.read()
+ if e:
+ output = str(output)
+ output = output.replace('<body>', '<body><p>STDERR:</p><pre>'+e+'</pre>')
+ print output
+ except CodeError, err:
+ print 'Content-Type: text/html\n'
+ sys.stderr.seek(0)
+ e = sys.stderr.read()
+ sys.stderr=sys.stdout
+ print error(operation, u, fields, err, e)
+ except InvalidInput, err:
+ print 'Content-Type: text/html\n'
+ sys.stderr.seek(0)
+ e = sys.stderr.read()
+ sys.stderr=sys.stdout
+ print invalidInput(operation, u, fields, err, e)
+ except:
+ print 'Content-Type: text/plain\n'
+ sys.stderr.seek(0)
+ e = sys.stderr.read()
+ print e
+ print '----'
+ sys.stderr = sys.stdout
+ raise