import hmac
import datetime
-print 'Content-Type: text/html\n'
sys.stderr = sys.stdout
sys.path.append('/home/ecprice/.local/lib/python2.5/site-packages')
import random
class MyException(Exception):
+ """Base class for my exceptions"""
pass
+class InvalidInput(MyException):
+ """Exception for user-provided input is invalid but maybe in good faith.
+
+ This would include setting memory to negative (which might be a
+ typo) but not setting an invalid boot CD (which requires bypassing
+ the select box).
+ """
+ pass
+
+class CodeError(MyException):
+ """Exception for internal errors or bad faith input."""
+ pass
+
+
+
def helppopup(subj):
+ """Return HTML code for a (?) link to a specified help topic"""
return '<span class="helplink"><a href="help?subject='+subj+'&simple=true" target="_blank" onclick="return helppopup(\''+subj+'\')">(?)</a></span>'
return [ random.randint(0, 255) for _ in range(0, 16) ]
def uuidToString(u):
+ """Turn a numeric UUID to a hyphen-seperated one."""
return "-".join(["%02x" * 4, "%02x" * 2, "%02x" * 2, "%02x" * 2,
"%02x" * 6]) % tuple(u)
-def maxMemory(user, machine=None):
- return 256
+MAX_MEMORY_TOTAL = 512
+MAX_MEMORY_SINGLE = 256
+MIN_MEMORY_SINGLE = 16
+MAX_DISK_TOTAL = 50
+MAX_DISK_SINGLE = 50
+MIN_DISK_SINGLE = 0.1
+MAX_VMS_TOTAL = 10
+MAX_VMS_ACTIVE = 4
+
+def getMachinesByOwner(owner):
+ """Return the machines owned by a given owner."""
+ return Machine.select_by(owner=owner)
+
+def maxMemory(user, machine=None, on=None):
+ """Return the maximum memory for a machine or a user.
+
+ If machine is None, return the memory available for a new
+ machine. Else, return the maximum that machine can have.
+
+ on is a dictionary from machines to booleans, whether a machine is
+ on. If None, it is recomputed. XXX make this global?
+ """
+
+ machines = getMachinesByOwner(user.username)
+ if on is None:
+ on = getUptimes(machines)
+ active_machines = [x for x in machines if on[x]]
+ mem_usage = sum([x.memory for x in active_machines if x != machine])
+ return min(MAX_MEMORY_SINGLE, MAX_MEMORY_TOTAL-mem_usage)
def maxDisk(user, machine=None):
- return 10.0
+ machines = getMachinesByOwner(user.username)
+ disk_usage = sum([sum([y.size for y in x.disks])
+ for x in machines if x != machine])
+ return min(MAX_DISK_SINGLE, MAX_DISK_TOTAL-disk_usage/1024.)
+
+def canAddVm(user, on=None):
+ machines = getMachinesByOwner(user.username)
+ if on is None:
+ on = getUptimes(machines)
+ active_machines = [x for x in machines if on[x]]
+ return (len(machines) < MAX_VMS_TOTAL and
+ len(active_machines) < MAX_VMS_ACTIVE)
def haveAccess(user, machine):
+ """Return whether a user has access to a machine"""
if user.username == 'moo':
return True
return machine.owner == user.username
def error(op, user, fields, err):
+ """Print an error page when a CodeError occurs"""
d = dict(op=op, user=user, errorMessage=str(err))
print Template(file='error.tmpl', searchList=[d, global_dict]);
charset = string.ascii_letters + string.digits + '-_'
if name[0] in '-_' or len(name) > 22:
return False
- return all(x in charset for x in name)
+ for x in name:
+ if x not in charset:
+ return False
+ return True
def kinit(username = 'tabbott/extra', keytab = '/etc/tabbott.keytab'):
"""Kinit with a given username and keytab"""
stderr=subprocess.PIPE)
e = p.wait()
if e:
- raise MyException("Error %s in kinit: %s" % (e, p.stderr.read()))
+ raise CodeError("Error %s in kinit: %s" % (e, p.stderr.read()))
def checkKinit():
"""If we lack tickets, kinit."""
stdout=subprocess.PIPE,
stderr=subprocess.PIPE)
if kws.get('err'):
+ p.wait()
return p.stdout.read(), p.stderr.read()
if p.wait():
- print >> sys.stderr, 'ERROR on remctl ', args
- print >> sys.stderr, p.stderr.read()
+ raise CodeError('ERROR on remctl %s: %s' %
+ (args, p.stderr.read()))
return p.stdout.read()
def makeDisks():
value_string = remctl('web', 'listvms')
lines = value_string.splitlines()
d = {}
- for line in lines[1:]:
+ for line in lines:
lst = line.split()
name, id = lst[:2]
uptime = ' '.join(lst[2:])
d[name] = uptime
- return d
+ ans = {}
+ for m in machines:
+ ans[m] = d.get(m.name)
+ return ans
def statusInfo(machine):
"""Return the status list for a given machine.
"""
value_string, err_string = remctl('list-long', machine.name, err=True)
if 'Unknown command' in err_string:
- raise MyException("ERROR in remctl list-long %s is not registered" % (machine.name,))
+ raise CodeError("ERROR in remctl list-long %s is not registered" % (machine.name,))
elif 'does not exist' in err_string:
return None
elif err_string:
- raise MyException("ERROR in remctl list-long %s: %s" % (machine.name, err_string))
+ raise CodeError("ERROR in remctl list-long %s: %s" % (machine.name, err_string))
status = parseStatus(value_string)
return status
# put stuff in the table
transaction = ctx.current.create_transaction()
try:
+ if memory > maxMemory(user):
+ raise InvalidInput("Too much memory requested")
+ if disk > maxDisk(user) * 1024:
+ raise InvalidInput("Too much disk requested")
+ if not canAddVm(user):
+ raise InvalidInput("Too many VMs requested")
res = meta.engine.execute('select nextval(\'"machines_machine_id_seq"\')')
id = res.fetchone()[0]
machine = Machine()
'hda', disk)
open = NIC.select_by(machine_id=None)
if not open: #No IPs left!
- return "No IP addresses left! Contact sipb-xen-dev@mit.edu"
+ raise CodeError("No IP addresses left! Contact sipb-xen-dev@mit.edu")
nic = open[0]
nic.machine_id = machine.machine_id
nic.hostname = name
except:
transaction.rollback()
raise
- makeDisks()
registerMachine(machine)
+ makeDisks()
# tell it to boot with cdrom
bootMachine(machine, cdrom)
return machine
def validMemory(user, memory, machine=None):
+ """Parse and validate limits for memory for a given user and machine."""
try:
memory = int(memory)
- if memory <= 0:
+ if memory < MIN_MEMORY_SINGLE:
raise ValueError
except ValueError:
- raise MyException("Invalid memory amount")
+ raise InvalidInput("Invalid memory amount; must be at least %s MB" %
+ MIN_MEMORY_SINGLE)
if memory > maxMemory(user, machine):
- raise MyException("Too much memory requested")
+ raise InvalidInput("Too much memory requested")
return memory
def validDisk(user, disk, machine=None):
+ """Parse and validate limits for disk for a given user and machine."""
try:
disk = float(disk)
if disk > maxDisk(user, machine):
- raise MyException("Too much disk requested")
+ raise InvalidInput("Too much disk requested")
disk = int(disk * 1024)
- if disk <= 0:
+ if disk < MIN_DISK_SINGLE * 1024:
raise ValueError
except ValueError:
- raise MyException("Invalid disk amount")
+ raise InvalidInput("Invalid disk amount; minimum is %s GB" %
+ MIN_DISK_SINGLE)
return disk
def create(user, fields):
+ """Handler for create requests."""
name = fields.getfirst('name')
if not validMachineName(name):
- raise MyException("Invalid name '%s'" % name)
+ raise InvalidInput("Invalid name '%s'" % name)
name = user.username + '_' + name.lower()
if Machine.get_by(name=name):
- raise MyException("A machine named '%s' already exists" % name)
+ raise InvalidInput("A machine named '%s' already exists" % name)
memory = fields.getfirst('memory')
memory = validMemory(user, memory)
vm_type = fields.getfirst('vmtype')
if vm_type not in ('hvm', 'paravm'):
- raise MyException("Invalid vm type '%s'" % vm_type)
+ raise CodeError("Invalid vm type '%s'" % vm_type)
is_hvm = (vm_type == 'hvm')
cdrom = fields.getfirst('cdrom')
if cdrom is not None and not CDROM.get(cdrom):
- raise MyException("Invalid cdrom type '%s'" % cdrom)
+ raise CodeError("Invalid cdrom type '%s'" % cdrom)
machine = createVm(user, name, memory, disk, is_hvm, cdrom)
- if isinstance(machine, basestring):
- raise MyException(machine)
d = dict(user=user,
machine=machine)
print Template(file='create.tmpl',
searchList=[d, global_dict]);
def listVms(user, fields):
+ """Handler for list requests."""
machines = [m for m in Machine.select() if haveAccess(user, m)]
on = {}
has_vnc = {}
uptimes = getUptimes(machines)
on = uptimes
for m in machines:
- if not on.get(m.name):
- has_vnc[m.name] = 'Off'
+ if not on[m]:
+ has_vnc[m] = 'Off'
elif m.type.hvm:
- has_vnc[m.name] = True
+ has_vnc[m] = True
else:
- has_vnc[m.name] = "ParaVM"+helppopup("paravm_console")
+ has_vnc[m] = "ParaVM"+helppopup("paravm_console")
# for m in machines:
# status = statusInfo(m)
# on[m.name] = status is not None
# has_vnc[m.name] = hasVnc(status)
+ max_mem=maxMemory(user, on=on)
+ max_disk=maxDisk(user)
d = dict(user=user,
- maxmem=maxMemory(user),
- maxdisk=maxDisk(user),
+ can_add_vm=canAddVm(user, on=on),
+ max_mem=max_mem,
+ max_disk=max_disk,
+ default_mem=max_mem,
+ default_disk=min(4.0, max_disk),
machines=machines,
has_vnc=has_vnc,
uptimes=uptimes,
print Template(file='list.tmpl', searchList=[d, global_dict])
def testMachineId(user, machineId, exists=True):
+ """Parse, validate and check authorization for a given machineId.
+
+ If exists is False, don't check that it exists.
+ """
if machineId is None:
- raise MyException("No machine ID specified")
+ raise CodeError("No machine ID specified")
try:
machineId = int(machineId)
except ValueError:
- raise MyException("Invalid machine ID '%s'" % machineId)
+ raise CodeError("Invalid machine ID '%s'" % machineId)
machine = Machine.get(machineId)
if exists and machine is None:
- raise MyException("No such machine ID '%s'" % machineId)
- if not haveAccess(user, machine):
- raise MyException("No access to machine ID '%s'" % machineId)
+ raise CodeError("No such machine ID '%s'" % machineId)
+ if machine is not None and not haveAccess(user, machine):
+ raise CodeError("No access to machine ID '%s'" % machineId)
return machine
def vnc(user, fields):
-t nat -A PREROUTING -s ! 18.181.0.60 -i eth1 -p tcp -m tcp --dport 10003 -j DNAT --to-destination 18.181.0.60:10003
-t nat -A POSTROUTING -d 18.181.0.60 -o eth1 -p tcp -m tcp --dport 10003 -j SNAT --to-source 18.187.7.142
-A FORWARD -d 18.181.0.60 -i eth1 -o eth1 -p tcp -m tcp --dport 10003 -j ACCEPT
+
+ Remember to enable iptables!
+ echo 1 > /proc/sys/net/ipv4/ip_forward
"""
machine = testMachineId(user, fields.getfirst('machine_id'))
- #XXX fix
TOKEN_KEY = "0M6W0U1IXexThi5idy8mnkqPKEq1LtEnlK/pZSn0cDrN"
searchList=[d, global_dict])
def getNicInfo(data_dict, machine):
+ """Helper function for info, get data on nics for a machine.
+
+ Modifies data_dict to include the relevant data, and returns a list
+ of (key, name) pairs to display "name: data_dict[key]" to the user.
+ """
data_dict['num_nics'] = len(machine.nics)
nic_fields_template = [('nic%s_hostname', 'NIC %s hostname'),
('nic%s_mac', 'NIC %s MAC Addr'),
return nic_fields
def getDiskInfo(data_dict, machine):
+ """Helper function for info, get data on disks for a machine.
+
+ Modifies data_dict to include the relevant data, and returns a list
+ of (key, name) pairs to display "name: data_dict[key]" to the user.
+ """
data_dict['num_disks'] = len(machine.disks)
disk_fields_template = [('%s_size', '%s size')]
disk_fields = []
return disk_fields
def deleteVM(machine):
+ """Delete a VM."""
transaction = ctx.current.create_transaction()
delete_disk_pairs = [(machine.name, d.guest_device_name) for d in machine.disks]
try:
unregisterMachine(machine)
def command(user, fields):
+ """Handler for running commands like boot and delete on a VM."""
print time.time()-start_time
machine = testMachineId(user, fields.getfirst('machine_id'))
action = fields.getfirst('action')
cdrom = fields.getfirst('cdrom')
print time.time()-start_time
if cdrom is not None and not CDROM.get(cdrom):
- raise MyException("Invalid cdrom type '%s'" % cdrom)
+ raise CodeError("Invalid cdrom type '%s'" % cdrom)
if action not in ('Reboot', 'Power on', 'Power off', 'Shutdown', 'Delete VM'):
- raise MyException("Invalid action '%s'" % action)
+ raise CodeError("Invalid action '%s'" % action)
if action == 'Reboot':
if cdrom is not None:
remctl('reboot', machine.name, cdrom)
else:
remctl('reboot', machine.name)
elif action == 'Power on':
+ if maxMemory(user) < machine.memory:
+ raise InvalidInput("You don't have enough free RAM quota")
bootMachine(machine, cdrom)
elif action == 'Power off':
remctl('destroy', machine.name)
print Template(file="command.tmpl", searchList=[d, global_dict])
def modify(user, fields):
+ """Handler for modifying attributes of a machine."""
+ #XXX not written yet
machine = testMachineId(user, fields.getfirst('machine_id'))
def help(user, fields):
+ """Handler for help messages."""
simple = fields.getfirst('simple')
subjects = fields.getlist('subject')
def info(user, fields):
+ """Handler for info on a single VM."""
machine = testMachineId(user, fields.getfirst('machine_id'))
status = statusInfo(machine)
has_vnc = hasVnc(status)
]
fields = []
machine_info = {}
+ machine_info['name'] = machine.name
machine_info['type'] = machine.type.hvm and 'HVM' or 'ParaVM'
machine_info['owner'] = machine.owner
machine_info['contact'] = machine.contact
for field, disp in display_fields:
if field in ('uptime', 'cputime'):
fields.append((disp, locals()[field]))
- elif field in main_status:
- fields.append((disp, main_status[field]))
elif field in machine_info:
fields.append((disp, machine_info[field]))
+ elif field in main_status:
+ fields.append((disp, main_status[field]))
else:
pass
#fields.append((disp, None))
-
+ max_mem = maxMemory(user, machine)
+ max_disk = maxDisk(user, machine)
d = dict(user=user,
cdroms=CDROM.select(),
on=status is not None,
has_vnc=has_vnc,
uptime=str(uptime),
ram=machine.memory,
- maxmem=maxMemory(user, machine),
- maxdisk=maxDisk(user, machine),
+ max_mem=max_mem,
+ max_disk=max_disk,
fields = fields)
print Template(file='info.tmpl',
searchList=[d, global_dict])
username = "moo"
email = 'moo@cow.com'
u = User()
+ if 'SSL_CLIENT_S_DN_Email' in os.environ:
+ username = os.environ[ 'SSL_CLIENT_S_DN_Email'].split("@")[0]
+ u.username = username
+ u.email = os.environ[ 'SSL_CLIENT_S_DN_Email']
+ else:
+ u.username = 'moo'
+ u.email = 'nobody'
+ connect('postgres://sipb-xen@sipb-xen-dev/sipb_xen')
operation = os.environ.get('PATH_INFO', '')
+ #print 'Content-Type: text/plain\n'
+ #print operation
if not operation:
- pass
- #XXX do redirect
+ print "Status: 301 Moved Permanently"
+ print 'Location: ' + os.environ['SCRIPT_NAME']+'/\n'
+ sys.exit(0)
+ print 'Content-Type: text/html\n'
if operation.startswith('/'):
operation = operation[1:]
connect('postgres://sipb-xen@sipb-xen-dev/sipb_xen')
try:
fun(u, fields)
- except MyException, err:
+ except CodeError, err:
+ error(operation, u, fields, err)
+ except InvalidInput, err:
error(operation, u, fields, err)