libdb.pm.in 104 KB
Newer Older
1
2
#!/usr/bin/perl -w

Leigh B. Stoller's avatar
Leigh B. Stoller committed
3
4
#
# EMULAB-COPYRIGHT
5
# Copyright (c) 2000-2004 University of Utah and the Flux Group.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
6
7
8
# All rights reserved.
#

9
#
10
11
# A library of useful DB stuff. Mostly things that get done a lot.
# Saves typing.
12
13
14
15
16
#
# XXX: The notion of "uid" is a tad confused. A unix uid is a number,
#      while in the DB a user uid is a string (equiv to unix login).
#      Needs to be cleaned up.
#
17

18
package libdb;
19
use strict;
20
use Exporter;
Mac Newbold's avatar
Mac Newbold committed
21
use vars qw(@ISA @EXPORT);
22
23
@ISA = "Exporter";
@EXPORT =
24
    qw ( NODERELOADING_PID NODERELOADING_EID NODEDEAD_PID NODEDEAD_EID
25
	 OLDRESERVED_PID OLDRESERVED_EID NFREELOCKED_PID NFREELOCKED_EID 
26
27
	 NODEBOOTSTATUS_OKAY NODEBOOTSTATUS_FAILED NODEBOOTSTATUS_UNKNOWN
	 NODESTARTSTATUS_NOSTATUS PROJMEMBERTRUST_NONE PROJMEMBERTRUST_USER
Leigh B. Stoller's avatar
Leigh B. Stoller committed
28
29
30
	 PROJMEMBERTRUST_ROOT PROJMEMBERTRUST_GROUPROOT
	 PROJMEMBERTRUST_PROJROOT

31
	 PROJROOT GROUPROOT USERROOT
32
33
	 PLABMOND_PID PLABMOND_EID PLABHOLDING_PID PLABHOLDING_EID

Leigh B. Stoller's avatar
Leigh B. Stoller committed
34
35
36
37
	 TBTrustConvert TBMinTrust TBGrpTrust TBProjTrust

	 TB_NODEACCESS_READINFO TB_NODEACCESS_MODIFYINFO
	 TB_NODEACCESS_LOADIMAGE TB_NODEACCESS_REBOOT
38
39
	 TB_NODEACCESS_POWERCYCLE TB_NODEACCESS_MODIFYVLANS
	 TB_NODEACCESS_MIN TB_NODEACCESS_MAX
Leigh B. Stoller's avatar
Leigh B. Stoller committed
40

41
42
	 NODEFAILMODE_FATAL NODEFAILMODE_NONFATAL NODEFAILMODE_IGNORE

Leigh B. Stoller's avatar
Leigh B. Stoller committed
43
44
45
	 TB_USERINFO_READINFO TB_USERINFO_MODIFYINFO
	 TB_USERINFO_MIN TB_USERINFO_MAX

46
47
	 USERSTATUS_ACTIVE USERSTATUS_FROZEN
	 USERSTATUS_UNAPPROVED USERSTATUS_UNVERIFIED USERSTATUS_NEWUSER
48

49
	 TB_EXPT_READINFO TB_EXPT_MODIFY TB_EXPT_DESTROY TB_EXPT_UPDATE
Leigh B. Stoller's avatar
Leigh B. Stoller committed
50
51
52
53
	 TB_EXPT_MIN TB_EXPT_MAX

	 TB_PROJECT_READINFO TB_PROJECT_MAKEGROUP
	 TB_PROJECT_EDITGROUP TB_PROJECT_DELGROUP
Chad Barb's avatar
   
Chad Barb committed
54
	 TB_PROJECT_GROUPGRABUSERS TB_PROJECT_BESTOWGROUPROOT
Leigh B. Stoller's avatar
Leigh B. Stoller committed
55
56
57
58
59
60
61
62
63
64
65
	 TB_PROJECT_LEADGROUP TB_PROJECT_ADDUSER
	 TB_PROJECT_DELUSER TB_PROJECT_MAKEOSID
	 TB_PROJECT_DELOSID TB_PROJECT_MAKEIMAGEID TB_PROJECT_DELIMAGEID
	 TB_PROJECT_CREATEEXPT TB_PROJECT_MIN TB_PROJECT_MAX

	 TB_OSID_READINFO TB_OSID_CREATE
	 TB_OSID_DESTROY TB_OSID_MIN TB_OSID_MAX

	 TB_IMAGEID_READINFO TB_IMAGEID_MODIFYINFO
	 TB_IMAGEID_CREATE TB_IMAGEID_DESTROY
	 TB_IMAGEID_ACCESS TB_IMAGEID_MIN TB_IMAGEID_MAX
66

Leigh B. Stoller's avatar
Leigh B. Stoller committed
67
	 DBLIMIT_NSFILESIZE NODERELOADPENDING_EID
68

69
	 EXPTSTATE_NEW EXPTSTATE_PRERUN EXPTSTATE_SWAPPED EXPTSTATE_SWAPPING
70
71
72
73
74
75
	 EXPTSTATE_ACTIVATING EXPTSTATE_ACTIVE
	 EXPTSTATE_TERMINATING EXPTSTATE_TERMINATED EXPTSTATE_QUEUED
	 EXPTSTATE_MODIFY_PARSE EXPTSTATE_MODIFY_REPARSE EXPTSTATE_MODIFY_RESWAP
	 EXPTSTATE_RESTARTING
	 BATCHSTATE_LOCKED BATCHSTATE_UNLOCKED
	 EXPTCANCEL_CLEAR EXPTCANCEL_TERM EXPTCANCEL_SWAP
76

77
	 TBSetCancelFlag TBGetCancelFlag
Leigh B. Stoller's avatar
Leigh B. Stoller committed
78

Mac Newbold's avatar
Mac Newbold committed
79
	 TB_NODELOGTYPE_MISC TB_NODELOGTYPES TB_DEFAULT_NODELOGTYPE
80
81

	 TB_DEFAULT_RELOADTYPE TB_RELOADTYPE_FRISBEE TB_RELOADTYPE_NETDISK
82

83
84
	 TB_EXPTPRIORITY_LOW TB_EXPTPRIORITY_HIGH

85
	 TB_ASSIGN_TOOFEWNODES TB_OPSPID
86

87
	 TBDB_TBEVENT_NODESTATE TBDB_TBEVENT_NODEOPMODE TBDB_TBEVENT_CONTROL
88
	 TBDB_TBEVENT_COMMAND
Chad Barb's avatar
   
Chad Barb committed
89

90
	 TBDB_NODESTATE_ISUP TBDB_NODESTATE_REBOOTING TBDB_NODESTATE_REBOOTED
91
	 TBDB_NODESTATE_SHUTDOWN TBDB_NODESTATE_BOOTING TBDB_NODESTATE_TBSETUP
92
	 TBDB_NODESTATE_RELOADSETUP TBDB_NODESTATE_RELOADING
93
94
95
	 TBDB_NODESTATE_RELOADDONE TBDB_NODESTATE_UNKNOWN
	 TBDB_NODESTATE_PXEWAIT TBDB_NODESTATE_PXEWAKEUP
	 TBDB_NODESTATE_PXEBOOTING
Chad Barb's avatar
   
Chad Barb committed
96

97
98
	 TBDB_NODEOPMODE_NORMAL TBDB_NODEOPMODE_DELAYING
	 TBDB_NODEOPMODE_UNKNOWNOS TBDB_NODEOPMODE_RELOADING
99
	 TBDB_NODEOPMODE_NORMALv1 TBDB_NODEOPMODE_MINIMAL
100
101
	 TBDB_NODEOPMODE_RELOAD TBDB_NODEOPMODE_DELAY
	 TBDB_NODEOPMODE_BOOTWHAT
102
	 TBDB_NODEOPMODE_ANY
103
	 TBDB_NODEOPMODE_UNKNOWN
Chad Barb's avatar
   
Chad Barb committed
104

105
	 TBDB_COMMAND_REBOOT
106
107
	 TBDB_COMMAND_POWEROFF TBDB_COMMAND_POWERON TBDB_COMMAND_POWERCYCLE

108
109
110
	 TBDB_STATED_TIMEOUT_REBOOT TBDB_STATED_TIMEOUT_NOTIFY
	 TBDB_STATED_TIMEOUT_CMDRETRY

Chad Barb's avatar
   
Chad Barb committed
111
112
113
	 TBDB_ALLOCSTATE_FREE_CLEAN TBDB_ALLOCSTATE_FREE_DIRTY
	 TBDB_ALLOCSTATE_DOWN TBDB_ALLOCSTATE_RELOAD_TO_FREE
	 TBDB_ALLOCSTATE_RELOAD_PENDING TBDB_ALLOCSTATE_RES_RELOAD
Mac Newbold's avatar
Mac Newbold committed
114
115
	 TBDB_ALLOCSTATE_RES_INIT_DIRTY TBDB_ALLOCSTATE_RES_INIT_CLEAN
	 TBDB_ALLOCSTATE_RES_REBOOT_DIRTY TBDB_ALLOCSTATE_RES_REBOOT_CLEAN
Chad Barb's avatar
   
Chad Barb committed
116
	 TBDB_ALLOCSTATE_RES_READY TBDB_ALLOCSTATE_UNKNOWN
117
	 TBDB_ALLOCSTATE_RES_TEARDOWN TBDB_ALLOCSTATE_DEAD
118
	 TBDB_ALLOCSTATE_RES_RECONFIG
Chad Barb's avatar
   
Chad Barb committed
119

120
121
	 TBDB_STATS_PRELOAD TBDB_STATS_START TBDB_STATS_TERMINATE
	 TBDB_STATS_SWAPIN TBDB_STATS_SWAPOUT TBDB_STATS_SWAPMODIFY
122
	 TBDB_STATS_FLAGS_IDLESWAP TBDB_STATS_FLAGS_PREMODIFY
123
	 TBDB_STATS_FLAGS_START
124

125
126
	 TBDB_JAILIPBASE TBDB_JAILIPMASK

127
	 TBDB_RSRVROLE_NODE TBDB_RSRVROLE_VIRTHOST TBDB_RSRVROLE_DELAYNODE
128
	 TBDB_RSRVROLE_SIMHOST
129

130
	 TBDB_EXPT_WORKDIR
131
	 TBSetNodeEventState TBGetNodeEventState
Chad Barb's avatar
   
Chad Barb committed
132
	 TBSetNodeAllocState TBGetNodeAllocState
133
	 TBSetNodeOpMode TBGetNodeOpMode
134
	 TB_OSID_MBKERNEL TB_OSID_PXEBOOT TB_OSID_FRISBEE
Mac Newbold's avatar
Mac Newbold committed
135
	 TB_OSID_FREEBSD_MFS TB_OSID_FRISBEE_MFS
136
	 TBBootWhat TBNodeStateTimeout
Mac Newbold's avatar
Mac Newbold committed
137
	 TBDB_TBCONTROL_RESET TBDB_TBCONTROL_RELOADDONE
138
	 TBDB_TBCONTROL_TIMEOUT TBDB_NO_STATE_TIMEOUT
Mac Newbold's avatar
Mac Newbold committed
139
140
	 TBDB_TBCONTROL_PXEBOOT TBDB_TBCONTROL_BOOTING
	 TBDB_TBCONTROL_CHECKGENISUP
141

142
143
	 TBDB_LOWVPORT TBDB_MAXVPORT TBDB_PORTRANGE

Leigh B. Stoller's avatar
Leigh B. Stoller committed
144
145
	 TBAdmin TBProjAccessCheck TBNodeAccessCheck TBOSIDAccessCheck
	 TBImageIDAccessCheck TBExptAccessCheck ExpLeader MarkNodeDown
146
	 SetNodeBootStatus OSFeatureSupported IsShelved NodeidToExp NodeidToExpOldReserved
147
	 UserDBInfo DBQuery DBQueryFatal DBQueryWarn DBWarn DBFatal
148
	 DBQuoteSpecial UNIX2DBUID ExpState SetExpState ProjLeader
149
	 ExpNodes ExpNodesOldReserved DBDateTime DefaultImageID GroupLeader TBGroupUnixInfo
150
	 TBValidNodeLogType TBValidNodeName TBSetNodeLogEntry
151
	 TBSetSchedReload MapNodeOSID TBLockExp TBUnLockExp TBSetExpSwapTime
152
	 TBUnixGroupList TBOSID TBOSMaxConcurrent TBOSCountInstances
153
	 TBOSLoadMaxOkay TBImageLoadMaxOkay TBImageID ExpSwapper
154
	 TBdbfork VnameToNodeid TBExpLocked
155
	 TBIsNodeRemote TBExptSetLogFile TBExptClearLogFile TBExptGetLogFile
156
	 TBIsNodeVirtual TBControlNetIP TBPhysNodeID
157
	 TBExptOpenLogFile TBExptCloseLogFile TBExptCreateLogFile
158
	 TBNodeUpdateAccountsByPid TBNodeUpdateAccountsByType
159
	 TBNodeUpdateAccountsByUID
160
	 TBSaveExpLogFiles TBExptWorkDir TBExptUserDir TBExptLogDir
161
	 TBExptDestroy TBIPtoNodeID TBNodeBootReset TBNodeStateWait
162
	 TBLeaderMailList ExpGroup TBExptSetSwapUID TBExptSetThumbNail
163
	 TBNodeAllocCheck TBPlabNodeUsername MarkPhysNodeDown
164

Mac Newbold's avatar
Mac Newbold committed
165
	 TBExptRemoveVirtualState TBExptBackupVirtualState
Chad Barb's avatar
   
Chad Barb committed
166
167
	 TBExptRestoreVirtualState

Mac Newbold's avatar
Mac Newbold committed
168
	 TBExptRemovePhysicalState TBExptBackupPhysicalState
169
	 TBExptRestorePhysicalState TBExptClearBackupState
Chad Barb's avatar
   
Chad Barb committed
170

171
172
	 TBExptPortRange

173
	 TBDB_WIDEAREA_LOCALNODE
Leigh B. Stoller's avatar
Leigh B. Stoller committed
174
	 TBWideareaNodeID TBTipServers
Mac Newbold's avatar
Mac Newbold committed
175

Chad Barb's avatar
   
Chad Barb committed
176
177
	 TBSiteVarExists TBGetSiteVar

178
	 TBActivityReport GatherSwapStats GatherAssignStats
179
	 TBAvailablePCs
180

181
182
	 TBDB_IFACEROLE_CONTROL TBDB_IFACEROLE_EXPERIMENT
	 TBDB_IFACEROLE_JAIL TBDB_IFACEROLE_FAKE TBDB_IFACEROLE_OTHER
183
	 TBDB_IFACEROLE_GW
184

185
186
	 TBDB_ROUTERTYPE_NONE	TBDB_ROUTERTYPE_OSPF
	 TBDB_ROUTERTYPE_STATIC TBDB_ROUTERTYPE_MANUAL
187
	 TBDB_EVENTKEY TBDB_WEBKEY
188
189
	 TBDB_CHECKDBSLOT_NOFLAGS TBDB_CHECKDBSLOT_WARN TBDB_CHECKDBSLOT_ERROR
         max min TBcheck_dbslot
Mac Newbold's avatar
Mac Newbold committed
190
	 hash_recurse array_recurse hash_recurse2 array_recurse2
191
	 );
192

193
# Must come after package declaration!
194
use lib '@prefix@/lib';
195
use English;
196
use File::Basename;
197
use POSIX qw(strftime);
198
require Mysql;
Mac Newbold's avatar
Mac Newbold committed
199
200
use vars qw($DBQUERY_MAXTRIES $DBCONN_MAXTRIES @EXPORT_OK @virtualTables
	    @physicalTables);
201

202
203
204
# Configure variables
my $TB		= "@prefix@";
my $DBNAME	= "@TBDBNAME@";
205
my $TBOPS       = "@TBOPSEMAIL@";
206
207
my $EVENTSYS    = "@EVENTSYS@";
my $BOSSNODE    = "@BOSSNODE@";
208
my $TESTMODE    = @TESTMODE@;
209
my $TBOPSPID	= "emulab-ops";
210
211
212
213
my $SCRIPTNAME  = "Unknown";
my $PROJROOT    = "/proj";
my $GROUPROOT   = "/groups";
my $USERROOT    = "/users";
214

215
216
217
218
219
if ($EVENTSYS) {
    require event;
    import event;
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
220
221
222
# Untainted scriptname for email below.
if ($PROGRAM_NAME =~ /^([-\w\.\/]+)$/) {
    $SCRIPTNAME = basename($1);
223
224
}
else {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
225
    $SCRIPTNAME = "Tainted";
226
227
}

228
#
229
# Set up for querying the database. Note that fork causes a reconnect
Mac Newbold's avatar
Mac Newbold committed
230
# to the DB in the child.
231
232
#
my $DB;
233
234
235
$DBQUERY_MAXTRIES = 1;
$DBCONN_MAXTRIES  = 5;
@EXPORT_OK        = qw($DBQUERY_MAXTRIES $DBCONN_MAXTRIES);
236
237
238

sub TBDBConnect()
{
239
    my $maxtries = $DBCONN_MAXTRIES;
240
241
242
243
244
245
246
247
248

    #
    # Construct a 'username' from the name of this script and the user who
    # ran it. This is for accounting purposes.
    #
    my $name = getpwuid($UID);
    if (!$name) {
	$name = "uid$UID";
    }
249
    my $dbuser = "$SCRIPTNAME:$name:$PID";
250

251
    while ($maxtries) {
252
	$DB = Mysql->connect("localhost", $DBNAME, $dbuser, "none");
253
254
255
	if (defined($DB)) {
	    last;
	}
256
257
258
259
260
261
	$maxtries--;
	sleep(1);
    }
    if (!defined($DB)) {
	die("Cannot connect to DB after several attempts!\n");
    }
262
263
    $DB->{'dbh'}->{'PrintError'} = 0;
    $Mysql::QUIET = 1;
264
265
}
TBDBConnect();
266

267
268
sub TBdbfork()
{
269
    select(undef, undef, undef, 0.3);
270
    undef($DB);
271
    TBDBConnect();
272
273
274
    if ($EVENTSYS) {
	EventFork();
    }
275
276
}

277
278
279
280
281
#
# Record last DB error string.
#
my $DBErrorString = "";

282
283
284
285
#
# Needs to be config'ed.
#
sub TBDB_EXPT_WORKDIR()		{ "/usr/testbed/expwork"; }
Mac Newbold's avatar
Mac Newbold committed
286

287
288
289
290
291
#
# Define exported "constants". Basically, these are just perl subroutines
# that look like constants cause you do not need to call a perl subroutine
# with parens. That is, FOO and FOO() are the same thing.
#
292
sub NODERELOADING_PID()		{ $TBOPSPID; }
293
sub NODERELOADING_EID()		{ "reloading"; }
294
sub NODERELOADPENDING_EID()	{ "reloadpending"; }
295
sub NODEDEAD_PID()		{ $TBOPSPID; }
296
sub NODEDEAD_EID()		{ "hwdown"; }
297
298
299
300
sub PLABMOND_PID()		{ $TBOPSPID; }
sub PLABMOND_EID()		{ "plab-monitor"; }
sub PLABHOLDING_PID()		{ $TBOPSPID; }
sub PLABHOLDING_EID()		{ "plabnodes"; }
301
302
sub OLDRESERVED_PID()		{ $TBOPSPID; }
sub OLDRESERVED_EID()		{ "oldreserved"; }
303
304
sub NFREELOCKED_PID()		{ $TBOPSPID; }
sub NFREELOCKED_EID()		{ "nfree-locked"; }
305
306
307
sub PROJROOT()			{ $PROJROOT; }
sub GROUPROOT()			{ $GROUPROOT; }
sub USERROOT()			{ $USERROOT; }
308
309
310
311
312
313

sub NODEBOOTSTATUS_OKAY()	{ "okay" ; }
sub NODEBOOTSTATUS_FAILED()	{ "failed"; }
sub NODEBOOTSTATUS_UNKNOWN()	{ "unknown"; }
sub NODESTARTSTATUS_NOSTATUS()	{ "none"; }

314
315
316
317
sub NODEFAILMODE_FATAL()	{ "fatal"; }
sub NODEFAILMODE_NONFATAL()	{ "nonfatal"; }
sub NODEFAILMODE_IGNORE()	{ "ignore"; }

318
# Experiment states
319
320
321
sub EXPTSTATE_NEW()		{ "new"; }
sub EXPTSTATE_PRERUN()		{ "prerunning"; }
sub EXPTSTATE_SWAPPED()		{ "swapped"; }
322
sub EXPTSTATE_QUEUED()		{ "queued"; }
323
324
325
326
327
sub EXPTSTATE_SWAPPING()	{ "swapping"; }
sub EXPTSTATE_ACTIVATING()	{ "activating"; }
sub EXPTSTATE_ACTIVE()		{ "active"; }
sub EXPTSTATE_TERMINATING()	{ "terminating"; }
sub EXPTSTATE_TERMINATED()	{ "ended"; }
328
329
330
331
332
333
334
sub EXPTSTATE_MODIFY_PARSE()	{ "modify_parse"; }
sub EXPTSTATE_MODIFY_REPARSE()	{ "modify_reparse"; }
sub EXPTSTATE_MODIFY_RESWAP()	{ "modify_reswap"; }
sub EXPTSTATE_RESTARTING()	{ "restarting"; }
# For the batch_daemon.
sub BATCHSTATE_LOCKED()		{ "locked";}
sub BATCHSTATE_UNLOCKED()	{ "unlocked";}
335

336
# Cancel flags
337
338
339
sub EXPTCANCEL_CLEAR()		{ 0 ;}
sub EXPTCANCEL_TERM()		{ 1 ;}
sub EXPTCANCEL_SWAP()		{ 2 ;}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
340

341
342
sub USERSTATUS_ACTIVE()		{ "active"; }
sub USERSTATUS_FROZEN()		{ "frozen"; }
343
344
345
sub USERSTATUS_UNAPPROVED()	{ "unapproved"; }
sub USERSTATUS_UNVERIFIED()	{ "unverified"; }
sub USERSTATUS_NEWUSER()	{ "newuser"; }
346

347
348
349
#
# We want valid project membership to be non-zero for easy membership
# testing. Specific trust levels are encoded thusly.
Mac Newbold's avatar
Mac Newbold committed
350
#
351
352
sub PROJMEMBERTRUST_NONE()	{ 0; }
sub PROJMEMBERTRUST_USER()	{ 1; }
353
sub PROJMEMBERTRUST_ROOT()	{ 2; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
354
355
356
357
358
359
360
sub PROJMEMBERTRUST_LOCALROOT()	{ 2; }
sub PROJMEMBERTRUST_GROUPROOT()	{ 3; }
sub PROJMEMBERTRUST_PROJROOT()	{ 4; }
sub PROJMEMBERTRUST_ADMIN()	{ 5; }

#
# Access types. Duplicated in the web interface. Make changes there too!
Mac Newbold's avatar
Mac Newbold committed
361
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
362
363
364
365
366
367
# Things you can do to a node.
sub TB_NODEACCESS_READINFO()	{ 1; }
sub TB_NODEACCESS_MODIFYINFO()	{ 2; }
sub TB_NODEACCESS_LOADIMAGE()	{ 3; }
sub TB_NODEACCESS_REBOOT()	{ 4; }
sub TB_NODEACCESS_POWERCYCLE()	{ 5; }
368
sub TB_NODEACCESS_MODIFYVLANS()	{ 6; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
369
sub TB_NODEACCESS_MIN()		{ TB_NODEACCESS_READINFO; }
370
sub TB_NODEACCESS_MAX()		{ TB_NODEACCESS_MODIFYVLANS; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
371
372
373
374
375
376
377

# User Info (modinfo web page, etc).
sub TB_USERINFO_READINFO()	{ 1; }
sub TB_USERINFO_MODIFYINFO()	{ 2; }
sub TB_USERINFO_MIN()		{ TB_USERINFO_READINFO; }
sub TB_USERINFO_MAX()		{ TB_USERINFO_MODIFYINFO; }

378
# Experiments.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
379
380
381
sub TB_EXPT_READINFO()		{ 1; }
sub TB_EXPT_MODIFY()		{ 2; }
sub TB_EXPT_DESTROY()		{ 3; }
382
sub TB_EXPT_UPDATE()		{ 4; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
383
sub TB_EXPT_MIN()		{ TB_EXPT_READINFO; }
384
sub TB_EXPT_MAX()		{ TB_EXPT_UPDATE; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
385
386
387
388
389

# Projects.
sub TB_PROJECT_READINFO()	{ 1; }
sub TB_PROJECT_MAKEGROUP()	{ 2; }
sub TB_PROJECT_EDITGROUP()	{ 3; }
Chad Barb's avatar
   
Chad Barb committed
390
sub TB_PROJECT_GROUPGRABUSERS() { 4; }
Chad Barb's avatar
   
Chad Barb committed
391
392
393
394
395
396
397
398
399
400
sub TB_PROJECT_BESTOWGROUPROOT(){ 5; }
sub TB_PROJECT_DELGROUP()	{ 6; }
sub TB_PROJECT_LEADGROUP()	{ 7; }
sub TB_PROJECT_ADDUSER()	{ 8; }
sub TB_PROJECT_DELUSER()	{ 9; }
sub TB_PROJECT_MAKEOSID()	{ 10; }
sub TB_PROJECT_DELOSID()	{ 11; }
sub TB_PROJECT_MAKEIMAGEID()	{ 12; }
sub TB_PROJECT_DELIMAGEID()	{ 13; }
sub TB_PROJECT_CREATEEXPT()	{ 14; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
401
402
403
sub TB_PROJECT_MIN()		{ TB_PROJECT_READINFO; }
sub TB_PROJECT_MAX()		{ TB_PROJECT_CREATEEXPT; }

Mac Newbold's avatar
Mac Newbold committed
404
# OSIDs
Leigh B. Stoller's avatar
Leigh B. Stoller committed
405
406
407
408
409
410
sub TB_OSID_READINFO()		{ 1; }
sub TB_OSID_CREATE()		{ 2; }
sub TB_OSID_DESTROY()		{ 3; }
sub TB_OSID_MIN()		{ TB_OSID_READINFO; }
sub TB_OSID_MAX()		{ TB_OSID_DESTROY; }

411
412
413
# Magic OSID constants
sub TB_OSID_MBKERNEL()          { "_KERNEL_"; } # multiboot kernel OSID
sub TB_OSID_PXEBOOT()           { "PXEBOOT"; } # osid for def pxe_boot_path
414
415
416
417
418
sub TB_OSID_FRISBEE()           { "PXEFRISBEE"; }

# Magic MFS constants
sub TB_OSID_FREEBSD_MFS()	{ "FREEBSD-MFS" };
sub TB_OSID_FRISBEE_MFS()	{ "FRISBEE-MFS" };
419

Leigh B. Stoller's avatar
Leigh B. Stoller committed
420
# ImageIDs
421
422
423
424
425
#
# Clarification:
# READINFO is read-only access to the image and its contents
# (This is what people get for shared images)
# ACCESS means complete power over the image and its [meta]data
Leigh B. Stoller's avatar
Leigh B. Stoller committed
426
427
428
429
430
431
432
sub TB_IMAGEID_READINFO()	{ 1; }
sub TB_IMAGEID_MODIFYINFO()	{ 2; }
sub TB_IMAGEID_CREATE()		{ 3; }
sub TB_IMAGEID_DESTROY()	{ 4; }
sub TB_IMAGEID_ACCESS()		{ 5; }
sub TB_IMAGEID_MIN()		{ TB_IMAGEID_READINFO; }
sub TB_IMAGEID_MAX()		{ TB_IMAGEID_ACCESS; }
433

434
# Node Log Types
435
436
437
438
439
440
441
sub TB_NODELOGTYPE_MISC		{ "misc"; }
sub TB_NODELOGTYPES()		{ ( TB_NODELOGTYPE_MISC ) ; }
sub TB_DEFAULT_NODELOGTYPE()	{ TB_NODELOGTYPE_MISC; }

# Reload Types.
sub TB_RELOADTYPE_NETDISK()	{ "netdisk"; }
sub TB_RELOADTYPE_FRISBEE()	{ "frisbee"; }
442
sub TB_DEFAULT_RELOADTYPE()	{ TB_RELOADTYPE_FRISBEE; }
443

444
445
446
447
448
449
450
# Experiment priorities.
sub TB_EXPTPRIORITY_LOW()	{ 0; }
sub TB_EXPTPRIORITY_HIGH()	{ 20; }

# Assign exit status for too few nodes.
sub TB_ASSIGN_TOOFEWNODES()	{ 2; }

451
452
453
# System PID.
sub TB_OPSPID()			{ $TBOPSPID; }

454
#
455
456
457
458
# Events we may want to send
#
sub TBDB_TBEVENT_NODESTATE	{ "TBNODESTATE"; }
sub TBDB_TBEVENT_NODEOPMODE	{ "TBNODEOPMODE"; }
459
sub TBDB_TBEVENT_CONTROL	{ "TBCONTROL"; }
460
sub TBDB_TBEVENT_COMMAND	{ "TBCOMMAND"; }
461
sub TBDB_TBEVENT_EXPTSTATE	{ "TBEXPTSTATE"; }
462
463
464
465

#
# For nodes, we use this set of events.
#
466
467
468
469
470
471
472
473
474
475
sub TBDB_NODESTATE_ISUP()	{ "ISUP"; }
sub TBDB_NODESTATE_REBOOTED()	{ "REBOOTED"; }
sub TBDB_NODESTATE_REBOOTING()	{ "REBOOTING"; }
sub TBDB_NODESTATE_SHUTDOWN()	{ "SHUTDOWN"; }
sub TBDB_NODESTATE_BOOTING()	{ "BOOTING"; }
sub TBDB_NODESTATE_TBSETUP()	{ "TBSETUP"; }
sub TBDB_NODESTATE_RELOADSETUP() { "RELOADSETUP"; }
sub TBDB_NODESTATE_RELOADING()	{ "RELOADING"; }
sub TBDB_NODESTATE_RELOADDONE()	{ "RELOADDONE"; }
sub TBDB_NODESTATE_UNKNOWN()	{ "UNKNOWN"; };
476
sub TBDB_NODESTATE_PXEWAIT()	{ "PXEWAIT"; }
477
478
sub TBDB_NODESTATE_PXEWAKEUP()	{ "PXEWAKEUP"; }
sub TBDB_NODESTATE_PXEBOOTING()	{ "PXEBOOTING"; }
479

480
sub TBDB_NODEOPMODE_ANY		{ "*"; } # A wildcard opmode
481
482
483
484
sub TBDB_NODEOPMODE_NORMAL	{ "NORMAL"; }
sub TBDB_NODEOPMODE_DELAYING	{ "DELAYING"; }
sub TBDB_NODEOPMODE_UNKNOWNOS	{ "UNKNOWNOS"; }
sub TBDB_NODEOPMODE_RELOADING	{ "RELOADING"; }
485
486
487
488
sub TBDB_NODEOPMODE_NORMALv1	{ "NORMALv1"; }
sub TBDB_NODEOPMODE_MINIMAL	{ "MINIMAL"; }
sub TBDB_NODEOPMODE_RELOAD	{ "RELOAD"; }
sub TBDB_NODEOPMODE_DELAY	{ "DELAY"; }
489
sub TBDB_NODEOPMODE_BOOTWHAT	{ "_BOOTWHAT_"; } # A redirection opmode
490
491
sub TBDB_NODEOPMODE_UNKNOWN	{ "UNKNOWN"; }

492
493
494
495
496
sub TBDB_COMMAND_REBOOT         { "REBOOT"; }
sub TBDB_COMMAND_POWEROFF       { "POWEROFF"; }
sub TBDB_COMMAND_POWERON        { "POWERON"; }
sub TBDB_COMMAND_POWERCYCLE     { "POWERCYCLE"; }

497
498
499
500
sub TBDB_STATED_TIMEOUT_REBOOT  { "REBOOT"; }
sub TBDB_STATED_TIMEOUT_NOTIFY  { "NOTIFY"; }
sub TBDB_STATED_TIMEOUT_CMDRETRY{ "CMDRETRY"; }

Chad Barb's avatar
   
Chad Barb committed
501
502
503
sub TBDB_ALLOCSTATE_FREE_CLEAN()       { "FREE_CLEAN"; }
sub TBDB_ALLOCSTATE_FREE_DIRTY()       { "FREE_DIRTY"; }
sub TBDB_ALLOCSTATE_DOWN()             { "DOWN"; }
504
sub TBDB_ALLOCSTATE_DEAD()             { "DEAD"; }
Chad Barb's avatar
   
Chad Barb committed
505
506
507
sub TBDB_ALLOCSTATE_RELOAD_TO_FREE()   { "RELOAD_TO_FREE"; }
sub TBDB_ALLOCSTATE_RELOAD_PENDING()   { "RELOAD_PENDING"; }
sub TBDB_ALLOCSTATE_RES_RELOAD()       { "RES_RELOAD"; }
Chad Barb's avatar
   
Chad Barb committed
508
509
sub TBDB_ALLOCSTATE_RES_REBOOT_DIRTY() { "RES_REBOOT_DIRTY"; }
sub TBDB_ALLOCSTATE_RES_REBOOT_CLEAN() { "RES_REBOOT_CLEAN"; }
510
511
sub TBDB_ALLOCSTATE_RES_INIT_DIRTY()   { "RES_INIT_DIRTY"; }
sub TBDB_ALLOCSTATE_RES_INIT_CLEAN()   { "RES_INIT_CLEAN"; }
Chad Barb's avatar
   
Chad Barb committed
512
sub TBDB_ALLOCSTATE_RES_READY()        { "RES_READY"; }
513
sub TBDB_ALLOCSTATE_RES_RECONFIG()     { "RES_RECONFIG"; }
514
sub TBDB_ALLOCSTATE_RES_TEARDOWN()     { "RES_TEARDOWN"; }
Chad Barb's avatar
   
Chad Barb committed
515
516
sub TBDB_ALLOCSTATE_UNKNOWN()          { "UNKNOWN"; };

517
518
519
sub TBDB_TBCONTROL_RESET	{ "RESET"; }
sub TBDB_TBCONTROL_RELOADDONE	{ "RELOADDONE"; }
sub TBDB_TBCONTROL_TIMEOUT	{ "TIMEOUT"; }
Mac Newbold's avatar
Mac Newbold committed
520
521
522
sub TBDB_TBCONTROL_PXEBOOT	{ "PXEBOOT"; }
sub TBDB_TBCONTROL_BOOTING	{ "BOOTING"; }
sub TBDB_TBCONTROL_CHECKGENISUP	{ "CHECKGENISUP"; }
523
524
525
526

# Constant we use for the timeout field when there is no timeout for a state
sub TBDB_NO_STATE_TIMEOUT	{ 0; }

527
528
529
530
531
532
#
# Node name we use in the widearea_* tables to represent a generic local node.
# All local nodes are considered to have the same network characteristcs.
#
sub TBDB_WIDEAREA_LOCALNODE     { "boss"; }

533
534
535
#
# We should list all of the DB limits.
#
536
sub DBLIMIT_NSFILESIZE()	{ (2**24 - 1); }
537

538
539
540
541
542
543
544
545
546
547
548
#
# Virtual nodes must operate within a restricted port range. The range
# is effective across all virtual nodes in the experiment. When an
# experiment is swapped in, allocate a subrange from this and setup
# all the vnodes to allocate from that range. We tell the user this
# range so this they can set up their programs to operate in that range.
#
sub TBDB_LOWVPORT()		{ 30000; }
sub TBDB_MAXVPORT()		{ 60000; }
sub TBDB_PORTRANGE()		{ 256;   }

549
550
551
552
553
554
555
556
#
# STATS constants.
#
sub TBDB_STATS_PRELOAD()	{ "preload"; }
sub TBDB_STATS_START()		{ "start"; }
sub TBDB_STATS_TERMINATE()	{ "destroy"; }
sub TBDB_STATS_SWAPIN()		{ "swapin"; }
sub TBDB_STATS_SWAPOUT()	{ "swapout"; }
557
sub TBDB_STATS_SWAPMODIFY()	{ "swapmod"; }
558
sub TBDB_STATS_FLAGS_IDLESWAP()	{ 0x01; }
559
sub TBDB_STATS_FLAGS_PREMODIFY(){ 0x02; }
560
561
562
sub TBDB_STATS_FLAGS_START()    { 0x04; }
# Do not export this variable!
my $TBDB_STATS_STARTCLOCK;
563

564
565
566
567
# Jail.
sub TBDB_JAILIPBASE()		{ "@JAILIPBASE@"; }
sub TBDB_JAILIPMASK()		{ "@JAILIPMASK@"; }

568
569
570
571
# Reserved node "roles"
sub TBDB_RSRVROLE_NODE()	{ "node"; }
sub TBDB_RSRVROLE_VIRTHOST()	{ "virthost"; }
sub TBDB_RSRVROLE_DELAYNODE()	{ "delaynode"; }
572
sub TBDB_RSRVROLE_SIMHOST()	{ "simhost"; }
573

574
575
576
577
578
# Interfaces roles.
sub TBDB_IFACEROLE_CONTROL()	{ "ctrl"; }
sub TBDB_IFACEROLE_EXPERIMENT()	{ "expt"; }
sub TBDB_IFACEROLE_JAIL()	{ "jail"; }
sub TBDB_IFACEROLE_FAKE()	{ "fake"; }
579
sub TBDB_IFACEROLE_GW()		{ "gw"; }
580
581
sub TBDB_IFACEROLE_OTHER()	{ "other"; }

582
583
584
585
586
587
# Routertypes.
sub TBDB_ROUTERTYPE_NONE()	{ "none"; }
sub TBDB_ROUTERTYPE_OSPF()	{ "ospf"; }
sub TBDB_ROUTERTYPE_STATIC()	{ "static"; }
sub TBDB_ROUTERTYPE_MANUAL()	{ "manual"; }

588
# Key Stuff
589
sub TBDB_EVENTKEY($$)	{ TBExptUserDir($_[0],$_[1]) . "/tbdata/eventkey"; }
590
sub TBDB_WEBKEY($$)	{ TBExptUserDir($_[0],$_[1]) . "/tbdata/webkey"; }
591

592
593
594
595
596
# Regex stuff
sub TBDB_CHECKDBSLOT_NOFLAGS()	{ 0x0; }
sub TBDB_CHECKDBSLOT_WARN()	{ 0x1; }
sub TBDB_CHECKDBSLOT_ERROR()	{ 0x2; }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
597
598
599
600
601
602
603
604
605
606
607
608
609
610
#
# Auth stuff.
#

#
# Convert a trust string to the above numeric values.
#
sub TBTrustConvert($)
{
    my($trust_string) = @_;
    my $trust_value = 0;

    #
    # Convert string to value. Perhaps the DB should have done it this way?
Mac Newbold's avatar
Mac Newbold committed
611
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
    if ($trust_string eq "none") {
	$trust_value = PROJMEMBERTRUST_NONE;
    }
    elsif ($trust_string eq "user") {
	$trust_value = PROJMEMBERTRUST_USER;
    }
    elsif ($trust_string eq "local_root") {
	$trust_value = PROJMEMBERTRUST_LOCALROOT;
    }
    elsif ($trust_string eq "group_root") {
	$trust_value = PROJMEMBERTRUST_GROUPROOT;
    }
    elsif ($trust_string eq "project_root") {
	$trust_value = PROJMEMBERTRUST_PROJROOT;
    }
    elsif ($trust_string eq "admin") {
	$trust_value = PROJMEMBERTRUST_ADMIN;
    }
    else {
	    die("*** Invalid trust value $trust_string!");
    }

    return $trust_value;
}

#
# Return true if the given trust string is >= to the minimum required.
# The trust value can be either numeric or a string; if a string its
# first converted to the numeric equiv.
#
sub TBMinTrust($$)
{
    my ($trust_value, $minimum) = @_;

    if ($minimum < PROJMEMBERTRUST_NONE ||
	$minimum > PROJMEMBERTRUST_ADMIN) {
	    die("*** Invalid minimum trust $minimum!");
    }

    #
    # Sleazy? How do you do a typeof in perl?
    #
    if (length($trust_value) != 1) {
	$trust_value = TBTrustConvert($trust_value);
    }
Mac Newbold's avatar
Mac Newbold committed
657

Leigh B. Stoller's avatar
Leigh B. Stoller committed
658
659
660
661
662
663
    return $trust_value >= $minimum;
}

#
# Determine the trust level for a uid/pid/gid. That is, each uid will have
# a different trust level depending on the project/group in question.
Mac Newbold's avatar
Mac Newbold committed
664
665
# Return that trust level as one of the numeric values above.
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
666
667
668
# usage: TBGrpTrust($dbuid, $pid, $gid)
#        returns numeric trust value if a group member.
#        returns PROJMEMBERTRUST_NONE if not a group member.
Mac Newbold's avatar
Mac Newbold committed
669
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
sub TBGrpTrust($$$)
{
    my ($uid, $pid, $gid) = @_;

    #
    # No group, then use the default group.
    #
    if (! $gid) {
	$gid = $pid;
    }

    my $query_result =
	DBQueryFatal("select trust from group_membership ".
		     "where uid='$uid' and pid='$pid' and gid='$gid'");

    #
    # No membership is the same as no trust. True? Maybe an error instead?
    #
    if ($query_result->numrows == 0) {
	return PROJMEMBERTRUST_NONE;
    }

    my @row = $query_result->fetchrow_array();
Mac Newbold's avatar
Mac Newbold committed
693
    my $trust_string = $row[0];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
694
695
696
697
698
699
700
701
702
703
704

    return TBTrustConvert($trust_string);
}

#
# Determine the project trust level for a uid/pid. This is the trust level
# for the default group in the project.
#
# usage: TBProjTrust($dbuid, $pid)
#        returns numeric trust value if a project member.
#        returns PROJMEMBERTRUST_NONE if not a project member.
Mac Newbold's avatar
Mac Newbold committed
705
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
706
707
708
sub TBProjTrust($$)
{
    my ($uid, $pid) = @_;
Mac Newbold's avatar
Mac Newbold committed
709

Leigh B. Stoller's avatar
Leigh B. Stoller committed
710
711
712
    return TBGrpTrust($uid, $pid, $pid);
}

713
#
714
715
# Test admin status. Optional argument is the UID or Name to test. If not
# provided, then test the current UID.
716
#
717
718
719
# XXX Argument is *either* a numeric UID, or a string name.
#
# usage: TBAdmin([int or char* uid]);
720
721
#        returns 1 if an admin type.
#        returns 0 if a mere user.
Mac Newbold's avatar
Mac Newbold committed
722
#
723
724
725
sub TBAdmin(;$)
{
    my($uid) = @_;
726
    my($name);
727

728
729
730
731
    #
    # No one is considered an admin unless they have the magic environment
    # variable set (so that you have to be a bit more explict about wanting
    # admin privs.) Use the withadminprivs script to get this variable set.
732
733
    # Also check with HTTP_ at the front of the name, since this is required
    # to get it through suexec from the web scripts.
734
    #
735
    if (!($ENV{WITH_TB_ADMIN_PRIVS} || $ENV{HTTP_WITH_TB_ADMIN_PRIVS})) {
736
737
738
	return 0;
    }

739
740
741
742
    if (!defined($uid)) {
	$uid = $UID;
    }

743
744
    #
    # Test if numeric. Map to name if it is.
Mac Newbold's avatar
Mac Newbold committed
745
    #
746
747
748
749
750
751
752
    if ($uid =~ /^[0-9]+$/) {
	($name) = getpwuid($uid)
	    or die "$uid not in passwd file\n";
    }
    else {
	$name = $uid;
    }
753
754

    my $query_result =
755
	DBQueryFatal("select admin from users where uid='$name'");
756
757
758
759
760
761
762
763
764

    my @row = $query_result->fetchrow_array();
    if ($row[0] == 1) {
	return 1;
    }
    return 0;
}

#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
765
766
# Project permission checks. The group id (gid) can be undef, in which case
# the pid is used (ie: a default group check is made).
767
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
768
769
770
# Usage: TBProjAccessCheck($uid, $pid, $gid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
771
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
772
sub TBProjAccessCheck($$$$)
773
{
Leigh B. Stoller's avatar
Leigh B. Stoller committed
774
775
    my ($uid, $pid, $gid, $access_type) = @_;
    my $mintrust;
776

Leigh B. Stoller's avatar
Leigh B. Stoller committed
777
778
779
    if ($access_type < TB_PROJECT_MIN ||
	$access_type > TB_PROJECT_MAX) {
	die("*** Invalid access type: $access_type!");
780
781
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
782
783
    #
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
784
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
785
786
    if (TBAdmin($uid)) {
	return 1;
787
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
788
789
790
791
792
793
794
    $uid = MapNumericUID($uid);

    #
    # No group, then use the default group.
    #
    if (! defined($gid)) {
	$gid = $pid;
795
796
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
797
798
799
800
801
802
    if ($access_type == TB_PROJECT_READINFO) {
	$mintrust = PROJMEMBERTRUST_USER;
    }
    elsif ($access_type == TB_PROJECT_CREATEEXPT) {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }
803
804
805
    elsif ($access_type == TB_PROJECT_DELUSER) {
	$mintrust = PROJMEMBERTRUST_PROJROOT;
    }
806
807
808
809
    elsif ($access_type == TB_PROJECT_MAKEGROUP ||
	   $access_type == TB_PROJECT_DELGROUP) {
	$mintrust = PROJMEMBERTRUST_GROUPROOT;
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
810
811
812
813
814
815
816
817
818
819
820
821
822
    else {
	die("*** Unexpected access type: $access_type!");
    }

    return TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust);
}

#
# Experiment permission checks.
#
# Usage: TBExptAccessCheck($uid, $pid, $eid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
823
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
824
825
826
827
828
829
830
831
sub TBExptAccessCheck($$$$)
{
    my ($uid, $pid, $eid, $access_type) = @_;
    my $mintrust;

    if ($access_type < TB_EXPT_MIN ||
	$access_type > TB_EXPT_MAX) {
	die("*** Invalid access type: $access_type!");
832
833
834
    }

    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
835
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
836
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
837
    if (TBAdmin($uid)) {
838
839
	return 1;
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
840
    $uid = MapNumericUID($uid);
841

Leigh B. Stoller's avatar
Leigh B. Stoller committed
842
    my $query_result =
843
	DBQueryFatal("SELECT gid,expt_head_uid FROM experiments WHERE ".
Leigh B. Stoller's avatar
Leigh B. Stoller committed
844
		     "eid='$eid' and pid='$pid'");
Mac Newbold's avatar
Mac Newbold committed
845

Leigh B. Stoller's avatar
Leigh B. Stoller committed
846
847
848
849
    if ($query_result->numrows == 0) {
	return 0;
    }
    my @row = $query_result->fetchrow_array();
850
851
    my $gid     = $row[0];
    my $creator = $row[1];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
852

853
854
855
    #
    # An experiment may be destroyed by the experiment creator or the
    # project/group leader.
Mac Newbold's avatar
Mac Newbold committed
856
    #
857
    if ($access_type == TB_EXPT_READINFO) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
858
859
860
861
862
863
	$mintrust = PROJMEMBERTRUST_USER;
    }
    else {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }

864
865
866
867
868
869
870
    #
    # Either proper permission in the group, or group_root in the project.
    # This lets group_roots muck with other people's experiments, including
    # those in groups they do not belong to.
    #
    return TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust) ||
	TBMinTrust(TBGrpTrust($uid, $pid, $pid), PROJMEMBERTRUST_GROUPROOT);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
871
872
873
874
875
876
877
878
}

#
# Determine if uid can access a node or list of nodes.
#
# Usage: TBNodeAccessCheck($uid, $access_type, $node_id, ...)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
879
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
880
881
882
883
884
885
886
887
888
889
sub TBNodeAccessCheck($$@)
{
    my ($uid, $access_type) = (shift, shift);
    my @nodelist = @_;
    my $mintrust;

    if ($access_type < TB_NODEACCESS_MIN ||
	$access_type > TB_NODEACCESS_MAX) {
	die("*** Invalid access type: $access_type!");
    }
890
891

    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
892
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
893
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
894
895
896
897
    if (TBAdmin($uid)) {
	return 1;
    }
    $uid = MapNumericUID($uid);
Mac Newbold's avatar
Mac Newbold committed
898

Leigh B. Stoller's avatar
Leigh B. Stoller committed
899
900
901
902
903
904
905
906
    if ($access_type == TB_NODEACCESS_READINFO) {
	$mintrust = PROJMEMBERTRUST_USER;
    }
    else {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }

    foreach my $node (@nodelist) {
907
	my $query_result =
908
	    DBQueryFatal("select e.pid,e.gid from reserved as r ".
Leigh B. Stoller's avatar
Leigh B. Stoller committed
909
			 "left join experiments as e on ".
910
911
			 "     e.pid=r.pid and e.eid=r.eid ".
			 "where r.node_id='$node'");
912

913
	if ($query_result->numrows == 0) {
914
915
	    return 0;
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
916
	my @row = $query_result->fetchrow_array();
917
918
	my $pid = $row[0];
	my $gid = $row[1];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
919

920
921
922
923
924
925
926
927
	#
	# Either proper permission in the group, or group_root in the
	# project. This lets group_roots muck with other people's
	# nodes, including those in groups they do not belong to.
	#
	if (! TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust) &&
	    ! TBMinTrust(TBGrpTrust($uid, $pid, $pid),
			 PROJMEMBERTRUST_GROUPROOT)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
928
929
	    return 0;
	}
930
931
932
933
934
    }
    return 1;
}

#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
935
# Access checks for an OSID. Tests for tbadmin.
936
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
937
938
939
# Usage: TBOSIDAccessCheck($uid, $osid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
940
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
941
sub TBOSIDAccessCheck($$$)
942
{
Leigh B. Stoller's avatar
Leigh B. Stoller committed
943
944
    my ($uid, $osid, $access_type) = @_;
    my $mintrust;
945

Leigh B. Stoller's avatar
Leigh B. Stoller committed
946
947
    if ($access_type < TB_OSID_MIN || $access_type > TB_OSID_MAX) {
	die("*** Invalid access type $access_type!");
948
949
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
950
951
    #
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
952
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
953
954
955
956
    if (TBAdmin($uid)) {
	return 1;
    }
    $uid = MapNumericUID($uid);
957

Leigh B. Stoller's avatar
Leigh B. Stoller committed
958
959
960
961
    #
    # No GIDs yet.
    #
    my $query_result =
962
	DBQueryFatal("SELECT pid,shared FROM os_info WHERE osid='$osid'");
Mac Newbold's avatar
Mac Newbold committed
963

964
    if ($query_result->numrows == 0) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
965
	return 0;
966
    }
967
    my @row = $query_result->fetchrow_array();
Leigh B. Stoller's avatar
Leigh B. Stoller committed
968
    my $pid = $row[0];
969
    my $shared = $row[1];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
970
971

    #
Mac Newbold's avatar
Mac Newbold committed
972
973
    # Global OSIDs can be read by anyone, but must be admin to read.
    #
974
    if ($shared) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
975
976
977
978
979
	if ($access_type == TB_OSID_READINFO) {
	    return 1;
	}
	return 0;
    }
Mac Newbold's avatar
Mac Newbold committed
980

Leigh B. Stoller's avatar
Leigh B. Stoller committed
981
982
    #
    # Otherwise must have proper trust in the project.
Mac Newbold's avatar
Mac Newbold committed
983
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
    if ($access_type == TB_OSID_READINFO) {
	$mintrust = PROJMEMBERTRUST_USER;
    }
    else {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }

    return TBMinTrust(TBProjTrust($uid, $pid), $mintrust);
}

#
# Access checks for an ImageID
#
# Usage: TBImageIDAccessCheck($uid, $imageid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
1000
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1001
1002
1003
1004
1005
1006
1007
sub TBImageIDAccessCheck($$$)
{
    my ($uid, $imageid, $access_type) = @_;
    my $mintrust;

    if ($access_type < TB_IMAGEID_MIN || $access_type > TB_IMAGEID_MAX) {
	die("*** Invalid access type $access_type!");
1008
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1009
1010

    #
1011
    # Admins and root do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
1012
    #
1013
    if (TBAdmin($uid) || !$UID || $UID eq "root" || $uid eq "root") {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1014
	return 1;
1015
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1016
1017
1018
1019
1020
1021
    $uid = MapNumericUID($uid);

    #
    # No GIDs yet.
    #
    my $query_result =
1022
1023
	DBQueryFatal("SELECT pid,gid,shared,global FROM images ".
		     "WHERE imageid='$imageid'");
Mac Newbold's avatar
Mac Newbold committed
1024

Leigh B. Stoller's avatar
Leigh B. Stoller committed
1025
1026
    if ($query_result->numrows == 0) {
	return 0;
1027
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1028
1029
    my @row = $query_result->fetchrow_array();
    my $pid = $row[0];
1030
1031
1032
    my $gid = $row[1];
    my $shared = $row[2];
    my $global = $row[3];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1033

1034
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1035
    # Global ImageIDs can be read by anyone.
Mac Newbold's avatar
Mac Newbold committed
1036
    #
1037
    if ($global) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1038
1039
1040
1041
1042
1043
	if ($access_type == TB_IMAGEID_READINFO) {
	    return 1;
	}
	return 0;
    }

1044
    #
1045
    # Otherwise must have proper trust in the pid/gid
Mac Newbold's avatar
Mac Newbold committed
1046
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1047
1048
    if ($access_type == TB_IMAGEID_READINFO) {
	$mintrust = PROJMEMBERTRUST_USER;
1049
1050
1051
1052
1053
1054
        #
        # Shared imageids are readable by anyone in the project.
        #
	if ($shared) {
	    $gid = $pid;
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1055
1056
1057
1058
1059
    }
    else {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }

1060
1061
1062
1063
1064
1065
1066
    #
    # Either proper permission in the group, or group_root in the project.
    # This lets group_roots muck with other people's experiments, including
    # those in groups they do not belong to.
    #
    return TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust) ||
	TBMinTrust(TBGrpTrust($uid, $pid, $pid), PROJMEMBERTRUST_GROUPROOT);
1067
1068
}

1069
#
Mac Newbold's avatar
Mac Newbold committed
1070
# Determine if a node can be allocated to a project.
1071
1072
1073
1074
#
# Usage: TBNodeAllocCheck($pid, $node_id)
#	 returns 0 if not allowed or error.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
1075
#
1076
1077
1078
1079
1080
1081
sub TBNodeAllocCheck($$)
{
    my ($pid, $node_id) = @_;

    #
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
1082
    #
1083
1084
1085
1086
1087
1088
1089
1090
1091
1092
1093
1094
    if (TBAdmin()) {
	return 1;
    }

    #
    # Hmm. The point of this join is to find rows in the permissions table
    # with the corresponding type of the node. If no rows come back, its
    # a non-existent node! If the values are NULL, then there are no rows
    # with that type/class, and thus the type/class is free to be allocated
    # by anyone. Otherwise we get the list of projects that are allowed,
    # and so we have to look at those.
    #
Mac Newbold's avatar
Mac Newbold committed
1095
    my $query_result =
1096
1097
1098
1099
1100
1101
1102
1103
1104
1105
1106
1107
	DBQueryFatal("select distinct p.* from nodes as n ".
		     "left join node_types as nt on n.type=nt.type ".
		     "left join nodetypeXpid_permissions as p on ".
		     "     (p.type=nt.type or p.type=nt.class) ".
		     "where node_id='$node_id'");

    if (!$query_result->numrows) {
	print STDERR "TBNodeAllocCheck: No such node $node_id!\n";
	return 0;
    }
    my ($ptype,$ppid) = $query_result->fetchrow_array();

Mac Newbold's avatar
Mac Newbold committed
1108
    # No rows, or a pid match.
1109
1110
1111
1112
1113
1114
1115
1116
1117
1118
1119
1120
1121
    if (!defined($ptype) || $ppid eq $pid) {
	return 1;
    }

    # Okay, must be rows in the permissions table. Check each pid for a match.
    while (my ($ptype,$ppid) = $query_result->fetchrow_array()) {
	if ($ppid eq $pid) {
	    return 1;
	}
    }
    return 0;
}

1122
1123
1124
1125
1126
1127
#
# Return Project leader. First argument pid.
#
# usage: ProjLeader(char *pid)
#        returns char *leader if a valid pid.