X-Git-Url: http://xvm.mit.edu/gitweb/invirt/packages/invirt-web.git/blobdiff_plain/49466ab6194ad35f3857e950721252621c3e539d..bc2c23e470e232b2a87cad3c826fcf4c07dc9d62:/templates/main.py
diff --git a/templates/main.py b/templates/main.py
index 4a50e43..984f3b8 100755
--- a/templates/main.py
+++ b/templates/main.py
@@ -13,7 +13,6 @@ import sha
import hmac
import datetime
-print 'Content-Type: text/html\n'
sys.stderr = sys.stdout
sys.path.append('/home/ecprice/.local/lib/python2.5/site-packages')
@@ -22,8 +21,33 @@ from sipb_xen_database import *
import random
class MyException(Exception):
+ """Base class for my exceptions"""
pass
+class InvalidInput(MyException):
+ """Exception for user-provided input is invalid but maybe in good faith.
+
+ This would include setting memory to negative (which might be a
+ typo) but not setting an invalid boot CD (which requires bypassing
+ the select box).
+ """
+ pass
+
+class CodeError(MyException):
+ """Exception for internal errors or bad faith input."""
+ pass
+
+
+
+def helppopup(subj):
+ """Return HTML code for a (?) link to a specified help topic"""
+ return '(?)'
+
+
+global_dict = {}
+global_dict['helppopup'] = helppopup
+
+
# ... and stolen from xend/uuid.py
def randomUUID():
"""Generate a random UUID."""
@@ -31,23 +55,64 @@ def randomUUID():
return [ random.randint(0, 255) for _ in range(0, 16) ]
def uuidToString(u):
+ """Turn a numeric UUID to a hyphen-seperated one."""
return "-".join(["%02x" * 4, "%02x" * 2, "%02x" * 2, "%02x" * 2,
"%02x" * 6]) % tuple(u)
-def maxMemory(user, machine=None):
- return 256
+MAX_MEMORY_TOTAL = 512
+MAX_MEMORY_SINGLE = 256
+MIN_MEMORY_SINGLE = 16
+MAX_DISK_TOTAL = 50
+MAX_DISK_SINGLE = 50
+MIN_DISK_SINGLE = 0.1
+MAX_VMS_TOTAL = 10
+MAX_VMS_ACTIVE = 4
+
+def getMachinesByOwner(owner):
+ """Return the machines owned by a given owner."""
+ return Machine.select_by(owner=owner)
+
+def maxMemory(user, machine=None, on=None):
+ """Return the maximum memory for a machine or a user.
+
+ If machine is None, return the memory available for a new
+ machine. Else, return the maximum that machine can have.
+
+ on is a dictionary from machines to booleans, whether a machine is
+ on. If None, it is recomputed. XXX make this global?
+ """
+
+ machines = getMachinesByOwner(user.username)
+ if on is None:
+ on = getUptimes(machines)
+ active_machines = [x for x in machines if on[x]]
+ mem_usage = sum([x.memory for x in active_machines if x != machine])
+ return min(MAX_MEMORY_SINGLE, MAX_MEMORY_TOTAL-mem_usage)
def maxDisk(user, machine=None):
- return 10.0
+ machines = getMachinesByOwner(user.username)
+ disk_usage = sum([sum([y.size for y in x.disks])
+ for x in machines if x != machine])
+ return min(MAX_DISK_SINGLE, MAX_DISK_TOTAL-disk_usage/1024.)
+
+def canAddVm(user, on=None):
+ machines = getMachinesByOwner(user.username)
+ if on is None:
+ on = getUptimes(machines)
+ active_machines = [x for x in machines if on[x]]
+ return (len(machines) < MAX_VMS_TOTAL and
+ len(active_machines) < MAX_VMS_ACTIVE)
def haveAccess(user, machine):
+ """Return whether a user has access to a machine"""
if user.username == 'moo':
return True
return machine.owner == user.username
def error(op, user, fields, err):
+ """Print an error page when a CodeError occurs"""
d = dict(op=op, user=user, errorMessage=str(err))
- print Template(file='error.tmpl', searchList=d);
+ print Template(file='error.tmpl', searchList=[d, global_dict]);
def validMachineName(name):
"""Check that name is valid for a machine name"""
@@ -56,7 +121,10 @@ def validMachineName(name):
charset = string.ascii_letters + string.digits + '-_'
if name[0] in '-_' or len(name) > 22:
return False
- return all(x in charset for x in name)
+ for x in name:
+ if x not in charset:
+ return False
+ return True
def kinit(username = 'tabbott/extra', keytab = '/etc/tabbott.keytab'):
"""Kinit with a given username and keytab"""
@@ -65,7 +133,7 @@ def kinit(username = 'tabbott/extra', keytab = '/etc/tabbott.keytab'):
stderr=subprocess.PIPE)
e = p.wait()
if e:
- raise MyException("Error %s in kinit: %s" % (e, p.stderr.read()))
+ raise CodeError("Error %s in kinit: %s" % (e, p.stderr.read()))
def checkKinit():
"""If we lack tickets, kinit."""
@@ -84,10 +152,11 @@ def remctl(*args, **kws):
stdout=subprocess.PIPE,
stderr=subprocess.PIPE)
if kws.get('err'):
+ p.wait()
return p.stdout.read(), p.stderr.read()
if p.wait():
- print >> sys.stderr, 'ERROR on remctl ', args
- print >> sys.stderr, p.stderr.read()
+ raise CodeError('ERROR on remctl %s: %s' %
+ (args, p.stderr.read()))
return p.stdout.read()
def makeDisks():
@@ -143,12 +212,15 @@ def getUptimes(machines):
value_string = remctl('web', 'listvms')
lines = value_string.splitlines()
d = {}
- for line in lines[1:]:
+ for line in lines:
lst = line.split()
name, id = lst[:2]
uptime = ' '.join(lst[2:])
d[name] = uptime
- return d
+ ans = {}
+ for m in machines:
+ ans[m] = d.get(m.name)
+ return ans
def statusInfo(machine):
"""Return the status list for a given machine.
@@ -157,11 +229,11 @@ def statusInfo(machine):
"""
value_string, err_string = remctl('list-long', machine.name, err=True)
if 'Unknown command' in err_string:
- raise MyException("ERROR in remctl list-long %s is not registered" % (machine.name,))
+ raise CodeError("ERROR in remctl list-long %s is not registered" % (machine.name,))
elif 'does not exist' in err_string:
return None
elif err_string:
- raise MyException("ERROR in remctl list-long %s: %s" % (machine.name, err_string))
+ raise CodeError("ERROR in remctl list-long %s: %s" % (machine.name, err_string))
status = parseStatus(value_string)
return status
@@ -180,6 +252,12 @@ def createVm(user, name, memory, disk, is_hvm, cdrom):
# put stuff in the table
transaction = ctx.current.create_transaction()
try:
+ if memory > maxMemory(user):
+ raise InvalidInput("Too much memory requested")
+ if disk > maxDisk(user) * 1024:
+ raise InvalidInput("Too much disk requested")
+ if not canAddVm(user):
+ raise InvalidInput("Too many VMs requested")
res = meta.engine.execute('select nextval(\'"machines_machine_id_seq"\')')
id = res.fetchone()[0]
machine = Machine()
@@ -197,7 +275,7 @@ def createVm(user, name, memory, disk, is_hvm, cdrom):
'hda', disk)
open = NIC.select_by(machine_id=None)
if not open: #No IPs left!
- return "No IP addresses left! Contact sipb-xen-dev@mit.edu"
+ raise CodeError("No IP addresses left! Contact sipb-xen-dev@mit.edu")
nic = open[0]
nic.machine_id = machine.machine_id
nic.hostname = name
@@ -207,44 +285,49 @@ def createVm(user, name, memory, disk, is_hvm, cdrom):
except:
transaction.rollback()
raise
- makeDisks()
registerMachine(machine)
+ makeDisks()
# tell it to boot with cdrom
bootMachine(machine, cdrom)
return machine
def validMemory(user, memory, machine=None):
+ """Parse and validate limits for memory for a given user and machine."""
try:
memory = int(memory)
- if memory <= 0:
+ if memory < MIN_MEMORY_SINGLE:
raise ValueError
except ValueError:
- raise MyException("Invalid memory amount")
+ raise InvalidInput("Invalid memory amount; must be at least %s MB" %
+ MIN_MEMORY_SINGLE)
if memory > maxMemory(user, machine):
- raise MyException("Too much memory requested")
+ raise InvalidInput("Too much memory requested")
return memory
def validDisk(user, disk, machine=None):
+ """Parse and validate limits for disk for a given user and machine."""
try:
disk = float(disk)
if disk > maxDisk(user, machine):
- raise MyException("Too much disk requested")
+ raise InvalidInput("Too much disk requested")
disk = int(disk * 1024)
- if disk <= 0:
+ if disk < MIN_DISK_SINGLE * 1024:
raise ValueError
except ValueError:
- raise MyException("Invalid disk amount")
+ raise InvalidInput("Invalid disk amount; minimum is %s GB" %
+ MIN_DISK_SINGLE)
return disk
def create(user, fields):
+ """Handler for create requests."""
name = fields.getfirst('name')
if not validMachineName(name):
- raise MyException("Invalid name '%s'" % name)
+ raise InvalidInput("Invalid name '%s'" % name)
name = user.username + '_' + name.lower()
if Machine.get_by(name=name):
- raise MyException("A machine named '%s' already exists" % name)
+ raise InvalidInput("A machine named '%s' already exists" % name)
memory = fields.getfirst('memory')
memory = validMemory(user, memory)
@@ -254,60 +337,67 @@ def create(user, fields):
vm_type = fields.getfirst('vmtype')
if vm_type not in ('hvm', 'paravm'):
- raise MyException("Invalid vm type '%s'" % vm_type)
+ raise CodeError("Invalid vm type '%s'" % vm_type)
is_hvm = (vm_type == 'hvm')
cdrom = fields.getfirst('cdrom')
if cdrom is not None and not CDROM.get(cdrom):
- raise MyException("Invalid cdrom type '%s'" % cdrom)
+ raise CodeError("Invalid cdrom type '%s'" % cdrom)
machine = createVm(user, name, memory, disk, is_hvm, cdrom)
- if isinstance(machine, basestring):
- raise MyException(machine)
d = dict(user=user,
machine=machine)
print Template(file='create.tmpl',
- searchList=d);
+ searchList=[d, global_dict]);
def listVms(user, fields):
+ """Handler for list requests."""
machines = [m for m in Machine.select() if haveAccess(user, m)]
on = {}
has_vnc = {}
uptimes = getUptimes(machines)
on = uptimes
for m in machines:
- if not on.get(m.name):
- has_vnc[m.name] = 'Off'
+ if not on[m]:
+ has_vnc[m] = 'Off'
elif m.type.hvm:
- has_vnc[m.name] = True
+ has_vnc[m] = True
else:
- help_name = 'paravm_console'
- has_vnc[m.name] = 'ParaVM (?)' % (help_name, help_name)
+ has_vnc[m] = "ParaVM"+helppopup("paravm_console")
# for m in machines:
# status = statusInfo(m)
# on[m.name] = status is not None
# has_vnc[m.name] = hasVnc(status)
+ max_mem=maxMemory(user, on=on)
+ max_disk=maxDisk(user)
d = dict(user=user,
- maxmem=maxMemory(user),
- maxdisk=maxDisk(user),
+ can_add_vm=canAddVm(user, on=on),
+ max_mem=max_mem,
+ max_disk=max_disk,
+ default_mem=max_mem,
+ default_disk=min(4.0, max_disk),
machines=machines,
has_vnc=has_vnc,
uptimes=uptimes,
cdroms=CDROM.select())
- print Template(file='list.tmpl', searchList=d)
+ print Template(file='list.tmpl', searchList=[d, global_dict])
def testMachineId(user, machineId, exists=True):
+ """Parse, validate and check authorization for a given machineId.
+
+ If exists is False, don't check that it exists.
+ """
if machineId is None:
- raise MyException("No machine ID specified")
+ raise CodeError("No machine ID specified")
try:
machineId = int(machineId)
except ValueError:
- raise MyException("Invalid machine ID '%s'" % machineId)
+ raise CodeError("Invalid machine ID '%s'" % machineId)
machine = Machine.get(machineId)
if exists and machine is None:
- raise MyException("No such machine ID '%s'" % machineId)
- if not haveAccess(user, machine):
- raise MyException("No access to machine ID '%s'" % machineId)
+ raise CodeError("No such machine ID '%s'" % machineId)
+ if machine is not None and not haveAccess(user, machine):
+ raise CodeError("No access to machine ID '%s'" % machineId)
return machine
def vnc(user, fields):
@@ -323,9 +413,11 @@ def vnc(user, fields):
-t nat -A PREROUTING -s ! 18.181.0.60 -i eth1 -p tcp -m tcp --dport 10003 -j DNAT --to-destination 18.181.0.60:10003
-t nat -A POSTROUTING -d 18.181.0.60 -o eth1 -p tcp -m tcp --dport 10003 -j SNAT --to-source 18.187.7.142
-A FORWARD -d 18.181.0.60 -i eth1 -o eth1 -p tcp -m tcp --dport 10003 -j ACCEPT
+
+ Remember to enable iptables!
+ echo 1 > /proc/sys/net/ipv4/ip_forward
"""
machine = testMachineId(user, fields.getfirst('machine_id'))
- #XXX fix
TOKEN_KEY = "0M6W0U1IXexThi5idy8mnkqPKEq1LtEnlK/pZSn0cDrN"
@@ -345,9 +437,14 @@ def vnc(user, fields):
hostname=os.environ.get('SERVER_NAME', 'localhost'),
authtoken=token)
print Template(file='vnc.tmpl',
- searchList=d)
+ searchList=[d, global_dict])
def getNicInfo(data_dict, machine):
+ """Helper function for info, get data on nics for a machine.
+
+ Modifies data_dict to include the relevant data, and returns a list
+ of (key, name) pairs to display "name: data_dict[key]" to the user.
+ """
data_dict['num_nics'] = len(machine.nics)
nic_fields_template = [('nic%s_hostname', 'NIC %s hostname'),
('nic%s_mac', 'NIC %s MAC Addr'),
@@ -364,6 +461,11 @@ def getNicInfo(data_dict, machine):
return nic_fields
def getDiskInfo(data_dict, machine):
+ """Helper function for info, get data on disks for a machine.
+
+ Modifies data_dict to include the relevant data, and returns a list
+ of (key, name) pairs to display "name: data_dict[key]" to the user.
+ """
data_dict['num_disks'] = len(machine.disks)
disk_fields_template = [('%s_size', '%s size')]
disk_fields = []
@@ -374,6 +476,7 @@ def getDiskInfo(data_dict, machine):
return disk_fields
def deleteVM(machine):
+ """Delete a VM."""
transaction = ctx.current.create_transaction()
delete_disk_pairs = [(machine.name, d.guest_device_name) for d in machine.disks]
try:
@@ -393,21 +496,24 @@ def deleteVM(machine):
unregisterMachine(machine)
def command(user, fields):
+ """Handler for running commands like boot and delete on a VM."""
print time.time()-start_time
machine = testMachineId(user, fields.getfirst('machine_id'))
action = fields.getfirst('action')
cdrom = fields.getfirst('cdrom')
print time.time()-start_time
if cdrom is not None and not CDROM.get(cdrom):
- raise MyException("Invalid cdrom type '%s'" % cdrom)
+ raise CodeError("Invalid cdrom type '%s'" % cdrom)
if action not in ('Reboot', 'Power on', 'Power off', 'Shutdown', 'Delete VM'):
- raise MyException("Invalid action '%s'" % action)
+ raise CodeError("Invalid action '%s'" % action)
if action == 'Reboot':
if cdrom is not None:
remctl('reboot', machine.name, cdrom)
else:
remctl('reboot', machine.name)
elif action == 'Power on':
+ if maxMemory(user) < machine.memory:
+ raise InvalidInput("You don't have enough free RAM quota")
bootMachine(machine, cdrom)
elif action == 'Power off':
remctl('destroy', machine.name)
@@ -420,13 +526,38 @@ def command(user, fields):
d = dict(user=user,
command=action,
machine=machine)
- print Template(file="command.tmpl", searchList=d)
+ print Template(file="command.tmpl", searchList=[d, global_dict])
def modify(user, fields):
+ """Handler for modifying attributes of a machine."""
+ #XXX not written yet
machine = testMachineId(user, fields.getfirst('machine_id'))
+def help(user, fields):
+ """Handler for help messages."""
+ simple = fields.getfirst('simple')
+ subjects = fields.getlist('subject')
+
+ mapping = dict(paravm_console="""
+ParaVM machines do not support console access over VNC. To access
+these machines, you either need to boot with a liveCD and ssh in or
+hope that the sipb-xen maintainers add support for serial consoles.""",
+ hvm_paravm="""
+HVM machines use the virtualization features of the processor, while
+ParaVM machines use Xen's emulation of virtualization features. You
+want an HVM virtualized machine.""",
+ cpu_weight="""Don't ask us! We're as mystified as you are.""")
+
+ d = dict(user=user,
+ simple=simple,
+ subjects=subjects,
+ mapping=mapping)
+
+ print Template(file="help.tmpl", searchList=[d, global_dict])
+
def info(user, fields):
+ """Handler for info on a single VM."""
machine = testMachineId(user, fields.getfirst('machine_id'))
status = statusInfo(machine)
has_vnc = hasVnc(status)
@@ -451,7 +582,7 @@ def info(user, fields):
('memory', 'RAM'),
'DISK_INFO',
('state', 'state (xen format)'),
- ('cpu_weight', 'CPU weight'),
+ ('cpu_weight', 'CPU weight'+helppopup('cpu_weight')),
('on_reboot', 'Action on VM reboot'),
('on_poweroff', 'Action on VM poweroff'),
('on_crash', 'Action on VM crash'),
@@ -461,6 +592,7 @@ def info(user, fields):
]
fields = []
machine_info = {}
+ machine_info['name'] = machine.name
machine_info['type'] = machine.type.hvm and 'HVM' or 'ParaVM'
machine_info['owner'] = machine.owner
machine_info['contact'] = machine.contact
@@ -477,14 +609,15 @@ def info(user, fields):
for field, disp in display_fields:
if field in ('uptime', 'cputime'):
fields.append((disp, locals()[field]))
- elif field in main_status:
- fields.append((disp, main_status[field]))
elif field in machine_info:
fields.append((disp, machine_info[field]))
+ elif field in main_status:
+ fields.append((disp, main_status[field]))
else:
pass
#fields.append((disp, None))
-
+ max_mem = maxMemory(user, machine)
+ max_disk = maxDisk(user, machine)
d = dict(user=user,
cdroms=CDROM.select(),
on=status is not None,
@@ -492,18 +625,19 @@ def info(user, fields):
has_vnc=has_vnc,
uptime=str(uptime),
ram=machine.memory,
- maxmem=maxMemory(user, machine),
- maxdisk=maxDisk(user, machine),
+ max_mem=max_mem,
+ max_disk=max_disk,
fields = fields)
print Template(file='info.tmpl',
- searchList=d)
+ searchList=[d, global_dict])
mapping = dict(list=listVms,
vnc=vnc,
command=command,
modify=modify,
info=info,
- create=create)
+ create=create,
+ help=help)
if __name__ == '__main__':
start_time = time.time()
@@ -512,11 +646,22 @@ if __name__ == '__main__':
username = "moo"
email = 'moo@cow.com'
u = User()
+ if 'SSL_CLIENT_S_DN_Email' in os.environ:
+ username = os.environ[ 'SSL_CLIENT_S_DN_Email'].split("@")[0]
+ u.username = username
+ u.email = os.environ[ 'SSL_CLIENT_S_DN_Email']
+ else:
+ u.username = 'moo'
+ u.email = 'nobody'
connect('postgres://sipb-xen@sipb-xen-dev/sipb_xen')
operation = os.environ.get('PATH_INFO', '')
+ #print 'Content-Type: text/plain\n'
+ #print operation
if not operation:
- pass
- #XXX do redirect
+ print "Status: 301 Moved Permanently"
+ print 'Location: ' + os.environ['SCRIPT_NAME']+'/\n'
+ sys.exit(0)
+ print 'Content-Type: text/html\n'
if operation.startswith('/'):
operation = operation[1:]
@@ -527,7 +672,11 @@ if __name__ == '__main__':
lambda u, e:
error(operation, u, e,
"Invalid operation '%s'" % operation))
+ if fun not in (help, ):
+ connect('postgres://sipb-xen@sipb-xen-dev/sipb_xen')
try:
fun(u, fields)
- except MyException, err:
+ except CodeError, err:
+ error(operation, u, fields, err)
+ except InvalidInput, err:
error(operation, u, fields, err)