libdb.pm.in 123 KB
Newer Older
1 2
#!/usr/bin/perl -w

Leigh B. Stoller's avatar
Leigh B. Stoller committed
3 4
#
# EMULAB-COPYRIGHT
5
# Copyright (c) 2000-2005 University of Utah and the Flux Group.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
6 7 8
# All rights reserved.
#

9
#
10 11
# A library of useful DB stuff. Mostly things that get done a lot.
# Saves typing.
12 13 14 15 16
#
# XXX: The notion of "uid" is a tad confused. A unix uid is a number,
#      while in the DB a user uid is a string (equiv to unix login).
#      Needs to be cleaned up.
#
17

18
package libdb;
19
use strict;
20
use Exporter;
Mac Newbold's avatar
Mac Newbold committed
21
use vars qw(@ISA @EXPORT);
22 23
@ISA = "Exporter";
@EXPORT =
24
    qw ( NODERELOADING_PID NODERELOADING_EID NODEDEAD_PID NODEDEAD_EID
25
	 OLDRESERVED_PID OLDRESERVED_EID NFREELOCKED_PID NFREELOCKED_EID 
26 27
	 NODEBOOTSTATUS_OKAY NODEBOOTSTATUS_FAILED NODEBOOTSTATUS_UNKNOWN
	 NODESTARTSTATUS_NOSTATUS PROJMEMBERTRUST_NONE PROJMEMBERTRUST_USER
Leigh B. Stoller's avatar
Leigh B. Stoller committed
28 29 30
	 PROJMEMBERTRUST_ROOT PROJMEMBERTRUST_GROUPROOT
	 PROJMEMBERTRUST_PROJROOT

31
	 PROJROOT GROUPROOT USERROOT TBOPSPID 
32 33
	 PLABMOND_PID PLABMOND_EID PLABHOLDING_PID PLABHOLDING_EID

34
	 TBTrustConvert TBMinTrust TBGrpTrust TBProjTrust MapNumericUID
Leigh B. Stoller's avatar
Leigh B. Stoller committed
35 36 37

	 TB_NODEACCESS_READINFO TB_NODEACCESS_MODIFYINFO
	 TB_NODEACCESS_LOADIMAGE TB_NODEACCESS_REBOOT
38 39
	 TB_NODEACCESS_POWERCYCLE TB_NODEACCESS_MODIFYVLANS
	 TB_NODEACCESS_MIN TB_NODEACCESS_MAX
Leigh B. Stoller's avatar
Leigh B. Stoller committed
40

41 42
	 NODEFAILMODE_FATAL NODEFAILMODE_NONFATAL NODEFAILMODE_IGNORE

Leigh B. Stoller's avatar
Leigh B. Stoller committed
43 44 45
	 TB_USERINFO_READINFO TB_USERINFO_MODIFYINFO
	 TB_USERINFO_MIN TB_USERINFO_MAX

46 47
	 USERSTATUS_ACTIVE USERSTATUS_FROZEN
	 USERSTATUS_UNAPPROVED USERSTATUS_UNVERIFIED USERSTATUS_NEWUSER
48

49
	 TB_EXPT_READINFO TB_EXPT_MODIFY TB_EXPT_DESTROY TB_EXPT_UPDATE
Leigh B. Stoller's avatar
Leigh B. Stoller committed
50 51 52 53
	 TB_EXPT_MIN TB_EXPT_MAX

	 TB_PROJECT_READINFO TB_PROJECT_MAKEGROUP
	 TB_PROJECT_EDITGROUP TB_PROJECT_DELGROUP
Chad Barb's avatar
 
Chad Barb committed
54
	 TB_PROJECT_GROUPGRABUSERS TB_PROJECT_BESTOWGROUPROOT
Leigh B. Stoller's avatar
Leigh B. Stoller committed
55 56 57 58 59 60 61 62 63 64 65
	 TB_PROJECT_LEADGROUP TB_PROJECT_ADDUSER
	 TB_PROJECT_DELUSER TB_PROJECT_MAKEOSID
	 TB_PROJECT_DELOSID TB_PROJECT_MAKEIMAGEID TB_PROJECT_DELIMAGEID
	 TB_PROJECT_CREATEEXPT TB_PROJECT_MIN TB_PROJECT_MAX

	 TB_OSID_READINFO TB_OSID_CREATE
	 TB_OSID_DESTROY TB_OSID_MIN TB_OSID_MAX

	 TB_IMAGEID_READINFO TB_IMAGEID_MODIFYINFO
	 TB_IMAGEID_CREATE TB_IMAGEID_DESTROY
	 TB_IMAGEID_ACCESS TB_IMAGEID_MIN TB_IMAGEID_MAX
66

Leigh B. Stoller's avatar
Leigh B. Stoller committed
67
	 DBLIMIT_NSFILESIZE NODERELOADPENDING_EID
68

69
	 EXPTSTATE_NEW EXPTSTATE_PRERUN EXPTSTATE_SWAPPED EXPTSTATE_SWAPPING
Leigh B. Stoller's avatar
Leigh B. Stoller committed
70
	 EXPTSTATE_ACTIVATING EXPTSTATE_ACTIVE EXPTSTATE_PANICED
71 72 73 74 75
	 EXPTSTATE_TERMINATING EXPTSTATE_TERMINATED EXPTSTATE_QUEUED
	 EXPTSTATE_MODIFY_PARSE EXPTSTATE_MODIFY_REPARSE EXPTSTATE_MODIFY_RESWAP
	 EXPTSTATE_RESTARTING
	 BATCHSTATE_LOCKED BATCHSTATE_UNLOCKED
	 EXPTCANCEL_CLEAR EXPTCANCEL_TERM EXPTCANCEL_SWAP
76

77
	 TBSetCancelFlag TBGetCancelFlag
Leigh B. Stoller's avatar
Leigh B. Stoller committed
78

Mac Newbold's avatar
Mac Newbold committed
79
	 TB_NODELOGTYPE_MISC TB_NODELOGTYPES TB_DEFAULT_NODELOGTYPE
80 81

	 TB_DEFAULT_RELOADTYPE TB_RELOADTYPE_FRISBEE TB_RELOADTYPE_NETDISK
82

83 84
	 TB_EXPTPRIORITY_LOW TB_EXPTPRIORITY_HIGH

85
	 TB_ASSIGN_TOOFEWNODES TB_OPSPID
86

87
	 TBDB_TBEVENT_NODESTATE TBDB_TBEVENT_NODEOPMODE TBDB_TBEVENT_CONTROL
88
	 TBDB_TBEVENT_COMMAND
Chad Barb's avatar
 
Chad Barb committed
89

90
	 TBDB_NODESTATE_ISUP TBDB_NODESTATE_REBOOTING TBDB_NODESTATE_REBOOTED
91
	 TBDB_NODESTATE_SHUTDOWN TBDB_NODESTATE_BOOTING TBDB_NODESTATE_TBSETUP
92
	 TBDB_NODESTATE_RELOADSETUP TBDB_NODESTATE_RELOADING
93 94
	 TBDB_NODESTATE_RELOADDONE TBDB_NODESTATE_UNKNOWN
	 TBDB_NODESTATE_PXEWAIT TBDB_NODESTATE_PXEWAKEUP
95
	 TBDB_NODESTATE_PXEBOOTING TBDB_NODESTATE_ALWAYSUP
96
	 TBDB_NODESTATE_MFSSETUP TBDB_NODESTATE_TBFAILED
97
	 TBDB_NODESTATE_POWEROFF
Chad Barb's avatar
 
Chad Barb committed
98

99 100
	 TBDB_NODEOPMODE_NORMAL TBDB_NODEOPMODE_DELAYING
	 TBDB_NODEOPMODE_UNKNOWNOS TBDB_NODEOPMODE_RELOADING
101
	 TBDB_NODEOPMODE_NORMALv1 TBDB_NODEOPMODE_MINIMAL
102 103
	 TBDB_NODEOPMODE_RELOAD TBDB_NODEOPMODE_RELOADMOTE
	 TBDB_NODEOPMODE_DELAY
104
	 TBDB_NODEOPMODE_BOOTWHAT
105
	 TBDB_NODEOPMODE_ANY
106
	 TBDB_NODEOPMODE_UNKNOWN
Chad Barb's avatar
 
Chad Barb committed
107

108
	 TBDB_COMMAND_REBOOT
109 110
	 TBDB_COMMAND_POWEROFF TBDB_COMMAND_POWERON TBDB_COMMAND_POWERCYCLE

111 112 113
	 TBDB_STATED_TIMEOUT_REBOOT TBDB_STATED_TIMEOUT_NOTIFY
	 TBDB_STATED_TIMEOUT_CMDRETRY

Chad Barb's avatar
 
Chad Barb committed
114 115 116
	 TBDB_ALLOCSTATE_FREE_CLEAN TBDB_ALLOCSTATE_FREE_DIRTY
	 TBDB_ALLOCSTATE_DOWN TBDB_ALLOCSTATE_RELOAD_TO_FREE
	 TBDB_ALLOCSTATE_RELOAD_PENDING TBDB_ALLOCSTATE_RES_RELOAD
Mac Newbold's avatar
Mac Newbold committed
117 118
	 TBDB_ALLOCSTATE_RES_INIT_DIRTY TBDB_ALLOCSTATE_RES_INIT_CLEAN
	 TBDB_ALLOCSTATE_RES_REBOOT_DIRTY TBDB_ALLOCSTATE_RES_REBOOT_CLEAN
Chad Barb's avatar
 
Chad Barb committed
119
	 TBDB_ALLOCSTATE_RES_READY TBDB_ALLOCSTATE_UNKNOWN
120
	 TBDB_ALLOCSTATE_RES_TEARDOWN TBDB_ALLOCSTATE_DEAD
121
	 TBDB_ALLOCSTATE_RES_RECONFIG
Chad Barb's avatar
 
Chad Barb committed
122

123 124
	 TBDB_STATS_PRELOAD TBDB_STATS_START TBDB_STATS_TERMINATE
	 TBDB_STATS_SWAPIN TBDB_STATS_SWAPOUT TBDB_STATS_SWAPMODIFY
125
	 TBDB_STATS_FLAGS_IDLESWAP TBDB_STATS_FLAGS_PREMODIFY
126
	 TBDB_STATS_FLAGS_START
127

128 129
	 TBDB_JAILIPBASE TBDB_JAILIPMASK

130
	 TBDB_RSRVROLE_NODE TBDB_RSRVROLE_VIRTHOST TBDB_RSRVROLE_DELAYNODE
131
	 TBDB_RSRVROLE_SIMHOST
132

133
	 TBDB_EXPT_WORKDIR
134
	 TBSetNodeEventState TBGetNodeEventState
Chad Barb's avatar
 
Chad Barb committed
135
	 TBSetNodeAllocState TBGetNodeAllocState
136
	 TBSetNodeOpMode TBGetNodeOpMode TBSetNodeNextOpMode
137
	 TB_OSID_MBKERNEL TB_OSID_PXEBOOT TB_OSID_FRISBEE
Mac Newbold's avatar
Mac Newbold committed
138
	 TB_OSID_FREEBSD_MFS TB_OSID_FRISBEE_MFS
139
	 TBBootWhat TBNodeStateTimeout
Mac Newbold's avatar
Mac Newbold committed
140
	 TBDB_TBCONTROL_RESET TBDB_TBCONTROL_RELOADDONE
141
	 TBDB_TBCONTROL_TIMEOUT TBDB_NO_STATE_TIMEOUT
Mac Newbold's avatar
Mac Newbold committed
142 143
	 TBDB_TBCONTROL_PXEBOOT TBDB_TBCONTROL_BOOTING
	 TBDB_TBCONTROL_CHECKGENISUP
144

145 146
	 TBDB_LOWVPORT TBDB_MAXVPORT TBDB_PORTRANGE

147 148
	 TBDB_PHYSICAL_NODE_TABLES

Leigh B. Stoller's avatar
Leigh B. Stoller committed
149 150
	 TBAdmin TBProjAccessCheck TBNodeAccessCheck TBOSIDAccessCheck
	 TBImageIDAccessCheck TBExptAccessCheck ExpLeader MarkNodeDown
151
	 SetNodeBootStatus OSFeatureSupported IsShelved NodeidToExp NodeidToExpOldReserved
152
	 UserDBInfo DBQuery DBQueryFatal DBQueryWarn DBWarn DBFatal
153
	 DBQuoteSpecial UNIX2DBUID ExpState SetExpState ProjLeader
154
	 ExpNodes ExpNodesOldReserved DBDateTime DefaultImageID GroupLeader TBGroupUnixInfo
155
	 TBValidNodeLogType TBValidNodeName TBSetNodeLogEntry
156
	 TBSetSchedReload MapNodeOSID TBLockExp TBUnLockExp TBSetExpSwapTime
157
	 TBUnixGroupList TBOSID TBOSMaxConcurrent TBOSCountInstances
158
	 TBResolveNextOSID TBOsidToPid TBOSIDRebootWaittime
159
	 TBOSLoadMaxOkay TBImageLoadMaxOkay TBImageID ExpSwapper
160
	 TBdbfork TBDBDisconnect VnameToNodeid TBExpLocked
161
	 TBIsNodeRemote TBExptSetLogFile TBExptClearLogFile TBExptGetLogFile
162
	 TBIsNodeVirtual TBControlNetIP TBPhysNodeID
163
	 TBExptOpenLogFile TBExptCloseLogFile TBExptCreateLogFile
164
	 TBNodeUpdateAccountsByPid TBNodeUpdateAccountsByType
165
	 TBNodeUpdateAccountsByUID
166
	 TBSaveExpLogFiles TBExptWorkDir TBExptUserDir TBExptLogDir
167
	 TBExptDestroy TBIPtoNodeID TBNodeBootReset TBNodeStateWait
168
	 TBLeaderMailList ExpGroup TBExptSetSwapUID TBExptSetThumbNail
169
	 TBNodeAllocCheck TBPlabNodeUsername MarkPhysNodeDown TBExptIsElabInElab
170
	 TBExptFirewall TBNodeFirewall TBSetExptFirewallVlan
171

172
	 TBNodeType TBNodeTypeProcInfo TBNodeTypeBiosWaittime
173

Mac Newbold's avatar
Mac Newbold committed
174
	 TBExptRemoveVirtualState TBExptBackupVirtualState
Chad Barb's avatar
 
Chad Barb committed
175 176
	 TBExptRestoreVirtualState

Mac Newbold's avatar
Mac Newbold committed
177
	 TBExptRemovePhysicalState TBExptBackupPhysicalState
178
	 TBExptRestorePhysicalState TBExptClearBackupState
Chad Barb's avatar
 
Chad Barb committed
179

180 181
	 TBExptPortRange

182
	 TBDB_WIDEAREA_LOCALNODE
Leigh B. Stoller's avatar
Leigh B. Stoller committed
183
	 TBWideareaNodeID TBTipServers
Mac Newbold's avatar
Mac Newbold committed
184

185
	 TBSiteVarExists TBGetSiteVar TBSetSiteVar
Chad Barb's avatar
 
Chad Barb committed
186

187
	 TBActivityReport GatherSwapStats GatherAssignStats
188
	 TBAvailablePCs
189

190 191
	 TBDB_IFACEROLE_CONTROL TBDB_IFACEROLE_EXPERIMENT
	 TBDB_IFACEROLE_JAIL TBDB_IFACEROLE_FAKE TBDB_IFACEROLE_OTHER
192
	 TBDB_IFACEROLE_GW TBDB_IFACEROLE_OUTER_CONTROL
193

194 195
	 TBDB_ROUTERTYPE_NONE	TBDB_ROUTERTYPE_OSPF
	 TBDB_ROUTERTYPE_STATIC TBDB_ROUTERTYPE_MANUAL
196
	 TBDB_EVENTKEY TBDB_WEBKEY
197 198
	 TBDB_CHECKDBSLOT_NOFLAGS TBDB_CHECKDBSLOT_WARN TBDB_CHECKDBSLOT_ERROR
         max min TBcheck_dbslot
Mac Newbold's avatar
Mac Newbold committed
199
	 hash_recurse array_recurse hash_recurse2 array_recurse2
200
	 TBGetUniqueIndex
201 202 203 204

	 TBExptMinMaxNodes TBExptSecurityLevel TBExptIDX
	 TBDB_SECLEVEL_GREEN  TBDB_SECLEVEL_YELLOW
	 TBDB_SECLEVEL_ORANGE TBDB_SECLEVEL_RED
Leigh B. Stoller's avatar
Leigh B. Stoller committed
205 206

	 TBExptSetPanicBit TBExptGetPanicBit TBExptClearPanicBit
207 208 209 210

	 TB_NODEHISTORY_OP_FREE TB_NODEHISTORY_OP_ALLOC TB_NODEHISTORY_OP_MOVE
	 TBSetNodeHistory

211 212
	 TBRobotLabExpt

213
	 );
214

215
# Must come after package declaration!
216
use lib '@prefix@/lib';
217
use English;
218
use File::Basename;
219
use POSIX qw(strftime);
220
require Mysql;
Mac Newbold's avatar
Mac Newbold committed
221 222
use vars qw($DBQUERY_MAXTRIES $DBCONN_MAXTRIES @EXPORT_OK @virtualTables
	    @physicalTables);
223

224 225 226
# Configure variables
my $TB		= "@prefix@";
my $DBNAME	= "@TBDBNAME@";
227
my $TBOPS       = "@TBOPSEMAIL@";
228 229
my $EVENTSYS    = "@EVENTSYS@";
my $BOSSNODE    = "@BOSSNODE@";
230
my $TESTMODE    = @TESTMODE@;
231
my $TBOPSPID	= "emulab-ops";
232 233 234 235
my $SCRIPTNAME  = "Unknown";
my $PROJROOT    = "/proj";
my $GROUPROOT   = "/groups";
my $USERROOT    = "/users";
236

237 238 239 240 241
if ($EVENTSYS) {
    require event;
    import event;
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
242 243 244
# Untainted scriptname for email below.
if ($PROGRAM_NAME =~ /^([-\w\.\/]+)$/) {
    $SCRIPTNAME = basename($1);
245 246
}
else {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
247
    $SCRIPTNAME = "Tainted";
248 249
}

250
#
251
# Set up for querying the database. Note that fork causes a reconnect
Mac Newbold's avatar
Mac Newbold committed
252
# to the DB in the child.
253 254
#
my $DB;
255 256 257
$DBQUERY_MAXTRIES = 1;
$DBCONN_MAXTRIES  = 5;
@EXPORT_OK        = qw($DBQUERY_MAXTRIES $DBCONN_MAXTRIES);
258 259 260

sub TBDBConnect()
{
261
    my $maxtries = $DBCONN_MAXTRIES;
262 263 264 265 266 267 268 269 270

    #
    # Construct a 'username' from the name of this script and the user who
    # ran it. This is for accounting purposes.
    #
    my $name = getpwuid($UID);
    if (!$name) {
	$name = "uid$UID";
    }
271
    my $dbuser = "$SCRIPTNAME:$name:$PID";
272

273
    while ($maxtries) {
274
	$DB = Mysql->connect("localhost", $DBNAME, $dbuser, "none");
275 276 277
	if (defined($DB)) {
	    last;
	}
278 279 280 281 282 283
	$maxtries--;
	sleep(1);
    }
    if (!defined($DB)) {
	die("Cannot connect to DB after several attempts!\n");
    }
284 285
    $DB->{'dbh'}->{'PrintError'} = 0;
    $Mysql::QUIET = 1;
286 287
}
TBDBConnect();
288

289 290
sub TBdbfork()
{
291
    select(undef, undef, undef, 0.3);
292
    undef($DB);
293
    TBDBConnect();
294 295 296
    if ($EVENTSYS) {
	EventFork();
    }
297 298
}

299 300 301 302 303 304 305
# To avoid keeping a mysql connection around.
sub TBDBDisconnect()
{
    undef($DB);
    select(undef, undef, undef, 0.3);
}

306 307 308 309 310
#
# Record last DB error string.
#
my $DBErrorString = "";

311 312 313 314
#
# Needs to be config'ed.
#
sub TBDB_EXPT_WORKDIR()		{ "/usr/testbed/expwork"; }
Mac Newbold's avatar
Mac Newbold committed
315

316 317 318 319 320
#
# Define exported "constants". Basically, these are just perl subroutines
# that look like constants cause you do not need to call a perl subroutine
# with parens. That is, FOO and FOO() are the same thing.
#
321
sub NODERELOADING_PID()		{ $TBOPSPID; }
322
sub NODERELOADING_EID()		{ "reloading"; }
323
sub NODERELOADPENDING_EID()	{ "reloadpending"; }
324
sub NODEDEAD_PID()		{ $TBOPSPID; }
325
sub NODEDEAD_EID()		{ "hwdown"; }
326 327 328 329
sub PLABMOND_PID()		{ $TBOPSPID; }
sub PLABMOND_EID()		{ "plab-monitor"; }
sub PLABHOLDING_PID()		{ $TBOPSPID; }
sub PLABHOLDING_EID()		{ "plabnodes"; }
330 331
sub OLDRESERVED_PID()		{ $TBOPSPID; }
sub OLDRESERVED_EID()		{ "oldreserved"; }
332 333
sub NFREELOCKED_PID()		{ $TBOPSPID; }
sub NFREELOCKED_EID()		{ "nfree-locked"; }
334 335 336
sub PROJROOT()			{ $PROJROOT; }
sub GROUPROOT()			{ $GROUPROOT; }
sub USERROOT()			{ $USERROOT; }
Robert Ricci's avatar
Robert Ricci committed
337
sub TBOPSPID()			{ $TBOPSPID; }
338 339 340 341 342 343

sub NODEBOOTSTATUS_OKAY()	{ "okay" ; }
sub NODEBOOTSTATUS_FAILED()	{ "failed"; }
sub NODEBOOTSTATUS_UNKNOWN()	{ "unknown"; }
sub NODESTARTSTATUS_NOSTATUS()	{ "none"; }

344 345 346 347
sub NODEFAILMODE_FATAL()	{ "fatal"; }
sub NODEFAILMODE_NONFATAL()	{ "nonfatal"; }
sub NODEFAILMODE_IGNORE()	{ "ignore"; }

348
# Experiment states
349 350 351
sub EXPTSTATE_NEW()		{ "new"; }
sub EXPTSTATE_PRERUN()		{ "prerunning"; }
sub EXPTSTATE_SWAPPED()		{ "swapped"; }
352
sub EXPTSTATE_QUEUED()		{ "queued"; }
353 354 355
sub EXPTSTATE_SWAPPING()	{ "swapping"; }
sub EXPTSTATE_ACTIVATING()	{ "activating"; }
sub EXPTSTATE_ACTIVE()		{ "active"; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
356
sub EXPTSTATE_PANICED()		{ "paniced"; }
357 358
sub EXPTSTATE_TERMINATING()	{ "terminating"; }
sub EXPTSTATE_TERMINATED()	{ "ended"; }
359 360 361 362 363 364 365
sub EXPTSTATE_MODIFY_PARSE()	{ "modify_parse"; }
sub EXPTSTATE_MODIFY_REPARSE()	{ "modify_reparse"; }
sub EXPTSTATE_MODIFY_RESWAP()	{ "modify_reswap"; }
sub EXPTSTATE_RESTARTING()	{ "restarting"; }
# For the batch_daemon.
sub BATCHSTATE_LOCKED()		{ "locked";}
sub BATCHSTATE_UNLOCKED()	{ "unlocked";}
366

367
# Cancel flags
368 369 370
sub EXPTCANCEL_CLEAR()		{ 0 ;}
sub EXPTCANCEL_TERM()		{ 1 ;}
sub EXPTCANCEL_SWAP()		{ 2 ;}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
371

372 373
sub USERSTATUS_ACTIVE()		{ "active"; }
sub USERSTATUS_FROZEN()		{ "frozen"; }
374 375 376
sub USERSTATUS_UNAPPROVED()	{ "unapproved"; }
sub USERSTATUS_UNVERIFIED()	{ "unverified"; }
sub USERSTATUS_NEWUSER()	{ "newuser"; }
377

378 379 380
#
# We want valid project membership to be non-zero for easy membership
# testing. Specific trust levels are encoded thusly.
Mac Newbold's avatar
Mac Newbold committed
381
#
382 383
sub PROJMEMBERTRUST_NONE()	{ 0; }
sub PROJMEMBERTRUST_USER()	{ 1; }
384
sub PROJMEMBERTRUST_ROOT()	{ 2; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
385 386 387 388 389 390 391
sub PROJMEMBERTRUST_LOCALROOT()	{ 2; }
sub PROJMEMBERTRUST_GROUPROOT()	{ 3; }
sub PROJMEMBERTRUST_PROJROOT()	{ 4; }
sub PROJMEMBERTRUST_ADMIN()	{ 5; }

#
# Access types. Duplicated in the web interface. Make changes there too!
Mac Newbold's avatar
Mac Newbold committed
392
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
393 394 395 396 397 398
# Things you can do to a node.
sub TB_NODEACCESS_READINFO()	{ 1; }
sub TB_NODEACCESS_MODIFYINFO()	{ 2; }
sub TB_NODEACCESS_LOADIMAGE()	{ 3; }
sub TB_NODEACCESS_REBOOT()	{ 4; }
sub TB_NODEACCESS_POWERCYCLE()	{ 5; }
399
sub TB_NODEACCESS_MODIFYVLANS()	{ 6; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
400
sub TB_NODEACCESS_MIN()		{ TB_NODEACCESS_READINFO; }
401
sub TB_NODEACCESS_MAX()		{ TB_NODEACCESS_MODIFYVLANS; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
402 403 404 405 406 407 408

# User Info (modinfo web page, etc).
sub TB_USERINFO_READINFO()	{ 1; }
sub TB_USERINFO_MODIFYINFO()	{ 2; }
sub TB_USERINFO_MIN()		{ TB_USERINFO_READINFO; }
sub TB_USERINFO_MAX()		{ TB_USERINFO_MODIFYINFO; }

409
# Experiments.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
410 411 412
sub TB_EXPT_READINFO()		{ 1; }
sub TB_EXPT_MODIFY()		{ 2; }
sub TB_EXPT_DESTROY()		{ 3; }
413
sub TB_EXPT_UPDATE()		{ 4; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
414
sub TB_EXPT_MIN()		{ TB_EXPT_READINFO; }
415
sub TB_EXPT_MAX()		{ TB_EXPT_UPDATE; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
416 417 418 419 420

# Projects.
sub TB_PROJECT_READINFO()	{ 1; }
sub TB_PROJECT_MAKEGROUP()	{ 2; }
sub TB_PROJECT_EDITGROUP()	{ 3; }
Chad Barb's avatar
 
Chad Barb committed
421
sub TB_PROJECT_GROUPGRABUSERS() { 4; }
Chad Barb's avatar
 
Chad Barb committed
422 423 424 425 426 427 428 429 430 431
sub TB_PROJECT_BESTOWGROUPROOT(){ 5; }
sub TB_PROJECT_DELGROUP()	{ 6; }
sub TB_PROJECT_LEADGROUP()	{ 7; }
sub TB_PROJECT_ADDUSER()	{ 8; }
sub TB_PROJECT_DELUSER()	{ 9; }
sub TB_PROJECT_MAKEOSID()	{ 10; }
sub TB_PROJECT_DELOSID()	{ 11; }
sub TB_PROJECT_MAKEIMAGEID()	{ 12; }
sub TB_PROJECT_DELIMAGEID()	{ 13; }
sub TB_PROJECT_CREATEEXPT()	{ 14; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
432 433 434
sub TB_PROJECT_MIN()		{ TB_PROJECT_READINFO; }
sub TB_PROJECT_MAX()		{ TB_PROJECT_CREATEEXPT; }

Mac Newbold's avatar
Mac Newbold committed
435
# OSIDs
Leigh B. Stoller's avatar
Leigh B. Stoller committed
436 437 438 439 440 441
sub TB_OSID_READINFO()		{ 1; }
sub TB_OSID_CREATE()		{ 2; }
sub TB_OSID_DESTROY()		{ 3; }
sub TB_OSID_MIN()		{ TB_OSID_READINFO; }
sub TB_OSID_MAX()		{ TB_OSID_DESTROY; }

442 443 444
# Magic OSID constants
sub TB_OSID_MBKERNEL()          { "_KERNEL_"; } # multiboot kernel OSID
sub TB_OSID_PXEBOOT()           { "PXEBOOT"; } # osid for def pxe_boot_path
445 446 447 448 449
sub TB_OSID_FRISBEE()           { "PXEFRISBEE"; }

# Magic MFS constants
sub TB_OSID_FREEBSD_MFS()	{ "FREEBSD-MFS" };
sub TB_OSID_FRISBEE_MFS()	{ "FRISBEE-MFS" };
450

Leigh B. Stoller's avatar
Leigh B. Stoller committed
451
# ImageIDs
452 453 454 455 456
#
# Clarification:
# READINFO is read-only access to the image and its contents
# (This is what people get for shared images)
# ACCESS means complete power over the image and its [meta]data
Leigh B. Stoller's avatar
Leigh B. Stoller committed
457 458 459 460 461 462 463
sub TB_IMAGEID_READINFO()	{ 1; }
sub TB_IMAGEID_MODIFYINFO()	{ 2; }
sub TB_IMAGEID_CREATE()		{ 3; }
sub TB_IMAGEID_DESTROY()	{ 4; }
sub TB_IMAGEID_ACCESS()		{ 5; }
sub TB_IMAGEID_MIN()		{ TB_IMAGEID_READINFO; }
sub TB_IMAGEID_MAX()		{ TB_IMAGEID_ACCESS; }
464

465
# Node Log Types
466 467 468 469
sub TB_NODELOGTYPE_MISC		{ "misc"; }
sub TB_NODELOGTYPES()		{ ( TB_NODELOGTYPE_MISC ) ; }
sub TB_DEFAULT_NODELOGTYPE()	{ TB_NODELOGTYPE_MISC; }

470 471 472 473 474
# Node History Stuff.
sub TB_NODEHISTORY_OP_FREE	{ "free"; }
sub TB_NODEHISTORY_OP_ALLOC	{ "alloc"; }
sub TB_NODEHISTORY_OP_MOVE	{ "move"; }

475 476 477
# Reload Types.
sub TB_RELOADTYPE_NETDISK()	{ "netdisk"; }
sub TB_RELOADTYPE_FRISBEE()	{ "frisbee"; }
478
sub TB_DEFAULT_RELOADTYPE()	{ TB_RELOADTYPE_FRISBEE; }
479

480 481 482 483 484 485 486
# Experiment priorities.
sub TB_EXPTPRIORITY_LOW()	{ 0; }
sub TB_EXPTPRIORITY_HIGH()	{ 20; }

# Assign exit status for too few nodes.
sub TB_ASSIGN_TOOFEWNODES()	{ 2; }

487 488 489
# System PID.
sub TB_OPSPID()			{ $TBOPSPID; }

490
#
491 492 493 494
# Events we may want to send
#
sub TBDB_TBEVENT_NODESTATE	{ "TBNODESTATE"; }
sub TBDB_TBEVENT_NODEOPMODE	{ "TBNODEOPMODE"; }
495
sub TBDB_TBEVENT_CONTROL	{ "TBCONTROL"; }
496
sub TBDB_TBEVENT_COMMAND	{ "TBCOMMAND"; }
497
sub TBDB_TBEVENT_EXPTSTATE	{ "TBEXPTSTATE"; }
498 499 500 501

#
# For nodes, we use this set of events.
#
502
sub TBDB_NODESTATE_ISUP()	{ "ISUP"; }
503
sub TBDB_NODESTATE_ALWAYSUP()	{ "ALWAYSUP"; }
504 505 506 507 508
sub TBDB_NODESTATE_REBOOTED()	{ "REBOOTED"; }
sub TBDB_NODESTATE_REBOOTING()	{ "REBOOTING"; }
sub TBDB_NODESTATE_SHUTDOWN()	{ "SHUTDOWN"; }
sub TBDB_NODESTATE_BOOTING()	{ "BOOTING"; }
sub TBDB_NODESTATE_TBSETUP()	{ "TBSETUP"; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
509 510
sub TBDB_NODESTATE_RELOADSETUP(){ "RELOADSETUP"; }
sub TBDB_NODESTATE_MFSSETUP()   { "MFSSETUP"; }
511
sub TBDB_NODESTATE_TBFAILED()	{ "TBFAILED"; }
512 513 514
sub TBDB_NODESTATE_RELOADING()	{ "RELOADING"; }
sub TBDB_NODESTATE_RELOADDONE()	{ "RELOADDONE"; }
sub TBDB_NODESTATE_UNKNOWN()	{ "UNKNOWN"; };
515
sub TBDB_NODESTATE_PXEWAIT()	{ "PXEWAIT"; }
516 517
sub TBDB_NODESTATE_PXEWAKEUP()	{ "PXEWAKEUP"; }
sub TBDB_NODESTATE_PXEBOOTING()	{ "PXEBOOTING"; }
518
sub TBDB_NODESTATE_POWEROFF()	{ "POWEROFF"; }
519

520
sub TBDB_NODEOPMODE_ANY		{ "*"; } # A wildcard opmode
521 522 523 524
sub TBDB_NODEOPMODE_NORMAL	{ "NORMAL"; }
sub TBDB_NODEOPMODE_DELAYING	{ "DELAYING"; }
sub TBDB_NODEOPMODE_UNKNOWNOS	{ "UNKNOWNOS"; }
sub TBDB_NODEOPMODE_RELOADING	{ "RELOADING"; }
525 526 527
sub TBDB_NODEOPMODE_NORMALv1	{ "NORMALv1"; }
sub TBDB_NODEOPMODE_MINIMAL	{ "MINIMAL"; }
sub TBDB_NODEOPMODE_RELOAD	{ "RELOAD"; }
528
sub TBDB_NODEOPMODE_RELOADMOTE	{ "RELOAD-MOTE"; }
529
sub TBDB_NODEOPMODE_DELAY	{ "DELAY"; }
530
sub TBDB_NODEOPMODE_BOOTWHAT	{ "_BOOTWHAT_"; } # A redirection opmode
531 532
sub TBDB_NODEOPMODE_UNKNOWN	{ "UNKNOWN"; }

533 534 535 536 537
sub TBDB_COMMAND_REBOOT         { "REBOOT"; }
sub TBDB_COMMAND_POWEROFF       { "POWEROFF"; }
sub TBDB_COMMAND_POWERON        { "POWERON"; }
sub TBDB_COMMAND_POWERCYCLE     { "POWERCYCLE"; }

538 539 540 541
sub TBDB_STATED_TIMEOUT_REBOOT  { "REBOOT"; }
sub TBDB_STATED_TIMEOUT_NOTIFY  { "NOTIFY"; }
sub TBDB_STATED_TIMEOUT_CMDRETRY{ "CMDRETRY"; }

Chad Barb's avatar
 
Chad Barb committed
542 543 544
sub TBDB_ALLOCSTATE_FREE_CLEAN()       { "FREE_CLEAN"; }
sub TBDB_ALLOCSTATE_FREE_DIRTY()       { "FREE_DIRTY"; }
sub TBDB_ALLOCSTATE_DOWN()             { "DOWN"; }
545
sub TBDB_ALLOCSTATE_DEAD()             { "DEAD"; }
Chad Barb's avatar
 
Chad Barb committed
546 547 548
sub TBDB_ALLOCSTATE_RELOAD_TO_FREE()   { "RELOAD_TO_FREE"; }
sub TBDB_ALLOCSTATE_RELOAD_PENDING()   { "RELOAD_PENDING"; }
sub TBDB_ALLOCSTATE_RES_RELOAD()       { "RES_RELOAD"; }
Chad Barb's avatar
 
Chad Barb committed
549 550
sub TBDB_ALLOCSTATE_RES_REBOOT_DIRTY() { "RES_REBOOT_DIRTY"; }
sub TBDB_ALLOCSTATE_RES_REBOOT_CLEAN() { "RES_REBOOT_CLEAN"; }
551 552
sub TBDB_ALLOCSTATE_RES_INIT_DIRTY()   { "RES_INIT_DIRTY"; }
sub TBDB_ALLOCSTATE_RES_INIT_CLEAN()   { "RES_INIT_CLEAN"; }
Chad Barb's avatar
 
Chad Barb committed
553
sub TBDB_ALLOCSTATE_RES_READY()        { "RES_READY"; }
554
sub TBDB_ALLOCSTATE_RES_RECONFIG()     { "RES_RECONFIG"; }
555
sub TBDB_ALLOCSTATE_RES_TEARDOWN()     { "RES_TEARDOWN"; }
Chad Barb's avatar
 
Chad Barb committed
556 557
sub TBDB_ALLOCSTATE_UNKNOWN()          { "UNKNOWN"; };

558 559 560
sub TBDB_TBCONTROL_RESET	{ "RESET"; }
sub TBDB_TBCONTROL_RELOADDONE	{ "RELOADDONE"; }
sub TBDB_TBCONTROL_TIMEOUT	{ "TIMEOUT"; }
Mac Newbold's avatar
Mac Newbold committed
561 562 563
sub TBDB_TBCONTROL_PXEBOOT	{ "PXEBOOT"; }
sub TBDB_TBCONTROL_BOOTING	{ "BOOTING"; }
sub TBDB_TBCONTROL_CHECKGENISUP	{ "CHECKGENISUP"; }
564 565 566 567

# Constant we use for the timeout field when there is no timeout for a state
sub TBDB_NO_STATE_TIMEOUT	{ 0; }

568 569 570 571 572 573
#
# Node name we use in the widearea_* tables to represent a generic local node.
# All local nodes are considered to have the same network characteristcs.
#
sub TBDB_WIDEAREA_LOCALNODE     { "boss"; }

574 575 576
#
# We should list all of the DB limits.
#
577
sub DBLIMIT_NSFILESIZE()	{ (2**24 - 1); }
578

579 580 581 582 583 584 585 586 587 588 589
#
# Virtual nodes must operate within a restricted port range. The range
# is effective across all virtual nodes in the experiment. When an
# experiment is swapped in, allocate a subrange from this and setup
# all the vnodes to allocate from that range. We tell the user this
# range so this they can set up their programs to operate in that range.
#
sub TBDB_LOWVPORT()		{ 30000; }
sub TBDB_MAXVPORT()		{ 60000; }
sub TBDB_PORTRANGE()		{ 256;   }

590 591 592 593 594 595 596 597
#
# STATS constants.
#
sub TBDB_STATS_PRELOAD()	{ "preload"; }
sub TBDB_STATS_START()		{ "start"; }
sub TBDB_STATS_TERMINATE()	{ "destroy"; }
sub TBDB_STATS_SWAPIN()		{ "swapin"; }
sub TBDB_STATS_SWAPOUT()	{ "swapout"; }
598
sub TBDB_STATS_SWAPMODIFY()	{ "swapmod"; }
599
sub TBDB_STATS_FLAGS_IDLESWAP()	{ 0x01; }
600
sub TBDB_STATS_FLAGS_PREMODIFY(){ 0x02; }
601 602 603
sub TBDB_STATS_FLAGS_START()    { 0x04; }
# Do not export this variable!
my $TBDB_STATS_STARTCLOCK;
604

605 606 607 608
# Jail.
sub TBDB_JAILIPBASE()		{ "@JAILIPBASE@"; }
sub TBDB_JAILIPMASK()		{ "@JAILIPMASK@"; }

609 610 611 612
# Reserved node "roles"
sub TBDB_RSRVROLE_NODE()	{ "node"; }
sub TBDB_RSRVROLE_VIRTHOST()	{ "virthost"; }
sub TBDB_RSRVROLE_DELAYNODE()	{ "delaynode"; }
613
sub TBDB_RSRVROLE_SIMHOST()	{ "simhost"; }
614

615 616 617 618 619
# Interfaces roles.
sub TBDB_IFACEROLE_CONTROL()	{ "ctrl"; }
sub TBDB_IFACEROLE_EXPERIMENT()	{ "expt"; }
sub TBDB_IFACEROLE_JAIL()	{ "jail"; }
sub TBDB_IFACEROLE_FAKE()	{ "fake"; }
620
sub TBDB_IFACEROLE_GW()		{ "gw"; }
621
sub TBDB_IFACEROLE_OTHER()	{ "other"; }
622
sub TBDB_IFACEROLE_OUTER_CONTROL(){ "outer_ctrl"; }
623

624 625 626 627 628 629
# Routertypes.
sub TBDB_ROUTERTYPE_NONE()	{ "none"; }
sub TBDB_ROUTERTYPE_OSPF()	{ "ospf"; }
sub TBDB_ROUTERTYPE_STATIC()	{ "static"; }
sub TBDB_ROUTERTYPE_MANUAL()	{ "manual"; }

630
# Key Stuff
631
sub TBDB_EVENTKEY($$)	{ TBExptUserDir($_[0],$_[1]) . "/tbdata/eventkey"; }
632
sub TBDB_WEBKEY($$)	{ TBExptUserDir($_[0],$_[1]) . "/tbdata/webkey"; }
633

634 635 636 637 638
# Regex stuff
sub TBDB_CHECKDBSLOT_NOFLAGS()	{ 0x0; }
sub TBDB_CHECKDBSLOT_WARN()	{ 0x1; }
sub TBDB_CHECKDBSLOT_ERROR()	{ 0x2; }

639 640 641 642 643 644
# Security Levels.
sub TBDB_SECLEVEL_GREEN()	{ 0; }
sub TBDB_SECLEVEL_YELLOW()	{ 1; }
sub TBDB_SECLEVEL_ORANGE()	{ 2; }
sub TBDB_SECLEVEL_RED()		{ 3; }

645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690
#
# A hash of all tables that contain information about physical nodes - the
# value for each key is the list of columns that could contain the node's ID.
#
sub TBDB_PHYSICAL_NODE_TABLES() {
    return (
	'current_reloads'	=> [ 'node_id' ],
	'delays'		=> [ 'node_id' ],
	'iface_counters'	=> [ 'node_id' ],
	'interfaces'		=> [ 'node_id' ],
	'interface_settings'	=> [ 'node_id' ],
	'last_reservation'	=> [ 'node_id' ],
	'linkdelays'		=> [ 'node_id' ],
	'location_info'		=> [ 'node_id' ],
	'next_reserve'		=> [ 'node_id' ],
	'node_activity'		=> [ 'node_id' ],
	'node_auxtypes'		=> [ 'node_id' ],
	'node_features'		=> [ 'node_id' ],
	'node_hostkeys'		=> [ 'node_id' ],
	'node_idlestats'	=> [ 'node_id' ],
	'node_status'   	=> [ 'node_id' ],
	'node_rusage'		=> [ 'node_id' ],
	'nodeipportnum'		=> [ 'node_id' ],
	'nodelog'		=> [ 'node_id' ],
	'nodes'			=> [ 'node_id', 'phys_nodeid' ],
	'nodeuidlastlogin'	=> [ 'node_id' ],
	'ntpinfo'		=> [ 'node_id' ],
	'outlets'		=> [ 'node_id' ],
	'partitions'		=> [ 'node_id' ],
	'plab_slice_nodes'	=> [ 'node_id' ],
	'port_counters'		=> [ 'node_id' ],
	'reserved'		=> [ 'node_id' ],
	'scheduled_reloads'	=> [ 'node_id' ],
	'state_triggers'	=> [ 'node_id' ],
	'switch_stacks'		=> [ 'node_id' ],
	'tiplines'		=> [ 'node_id' ],
	'tmcd_redirect'		=> [ 'node_id' ],
	'tunnels'		=> [ 'node_id' ],
	'uidnodelastlogin'	=> [ 'node_id' ],
	'v2pmap'		=> [ 'node_id' ],
	'veth_interfaces'	=> [ 'node_id' ],
	'widearea_accounts'	=> [ 'node_id' ],
	'widearea_delays'	=> [ 'node_id1', 'node_id2' ],
	'widearea_nodeinfo'	=> [ 'node_id' ],
	'widearea_recent'	=> [ 'node_id1', 'node_id2' ],
	'wires'			=> [ 'node_id1', 'node_id2' ],
691 692 693
	'node_startloc'		=> [ 'node_id' ],
	'node_history'		=> [ 'node_id' ],
	'node_bootlogs'		=> [ 'node_id' ],
694 695 696
    );
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
697 698 699 700 701 702 703 704 705 706 707 708 709 710
#
# Auth stuff.
#

#
# Convert a trust string to the above numeric values.
#
sub TBTrustConvert($)
{
    my($trust_string) = @_;
    my $trust_value = 0;

    #
    # Convert string to value. Perhaps the DB should have done it this way?
Mac Newbold's avatar
Mac Newbold committed
711
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756
    if ($trust_string eq "none") {
	$trust_value = PROJMEMBERTRUST_NONE;
    }
    elsif ($trust_string eq "user") {
	$trust_value = PROJMEMBERTRUST_USER;
    }
    elsif ($trust_string eq "local_root") {
	$trust_value = PROJMEMBERTRUST_LOCALROOT;
    }
    elsif ($trust_string eq "group_root") {
	$trust_value = PROJMEMBERTRUST_GROUPROOT;
    }
    elsif ($trust_string eq "project_root") {
	$trust_value = PROJMEMBERTRUST_PROJROOT;
    }
    elsif ($trust_string eq "admin") {
	$trust_value = PROJMEMBERTRUST_ADMIN;
    }
    else {
	    die("*** Invalid trust value $trust_string!");
    }

    return $trust_value;
}

#
# Return true if the given trust string is >= to the minimum required.
# The trust value can be either numeric or a string; if a string its
# first converted to the numeric equiv.
#
sub TBMinTrust($$)
{
    my ($trust_value, $minimum) = @_;

    if ($minimum < PROJMEMBERTRUST_NONE ||
	$minimum > PROJMEMBERTRUST_ADMIN) {
	    die("*** Invalid minimum trust $minimum!");
    }

    #
    # Sleazy? How do you do a typeof in perl?
    #
    if (length($trust_value) != 1) {
	$trust_value = TBTrustConvert($trust_value);
    }
Mac Newbold's avatar
Mac Newbold committed
757

Leigh B. Stoller's avatar
Leigh B. Stoller committed
758 759 760 761 762 763
    return $trust_value >= $minimum;
}

#
# Determine the trust level for a uid/pid/gid. That is, each uid will have
# a different trust level depending on the project/group in question.
Mac Newbold's avatar
Mac Newbold committed
764 765
# Return that trust level as one of the numeric values above.
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
766 767 768
# usage: TBGrpTrust($dbuid, $pid, $gid)
#        returns numeric trust value if a group member.
#        returns PROJMEMBERTRUST_NONE if not a group member.
Mac Newbold's avatar
Mac Newbold committed
769
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792
sub TBGrpTrust($$$)
{
    my ($uid, $pid, $gid) = @_;

    #
    # No group, then use the default group.
    #
    if (! $gid) {
	$gid = $pid;
    }

    my $query_result =
	DBQueryFatal("select trust from group_membership ".
		     "where uid='$uid' and pid='$pid' and gid='$gid'");

    #
    # No membership is the same as no trust. True? Maybe an error instead?
    #
    if ($query_result->numrows == 0) {
	return PROJMEMBERTRUST_NONE;
    }

    my @row = $query_result->fetchrow_array();
Mac Newbold's avatar
Mac Newbold committed
793
    my $trust_string = $row[0];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
794 795 796 797 798 799 800 801 802 803 804

    return TBTrustConvert($trust_string);
}

#
# Determine the project trust level for a uid/pid. This is the trust level
# for the default group in the project.
#
# usage: TBProjTrust($dbuid, $pid)
#        returns numeric trust value if a project member.
#        returns PROJMEMBERTRUST_NONE if not a project member.
Mac Newbold's avatar
Mac Newbold committed
805
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
806 807 808
sub TBProjTrust($$)
{
    my ($uid, $pid) = @_;
Mac Newbold's avatar
Mac Newbold committed
809

Leigh B. Stoller's avatar
Leigh B. Stoller committed
810 811 812
    return TBGrpTrust($uid, $pid, $pid);
}

813
#
814 815
# Test admin status. Optional argument is the UID or Name to test. If not
# provided, then test the current UID.
816
#
817 818 819
# XXX Argument is *either* a numeric UID, or a string name.
#
# usage: TBAdmin([int or char* uid]);
820 821
#        returns 1 if an admin type.
#        returns 0 if a mere user.
Mac Newbold's avatar
Mac Newbold committed
822
#
823 824 825
sub TBAdmin(;$)
{
    my($uid) = @_;
826
    my($name);
827

828 829 830 831
    #
    # No one is considered an admin unless they have the magic environment
    # variable set (so that you have to be a bit more explict about wanting
    # admin privs.) Use the withadminprivs script to get this variable set.
832 833
    # Also check with HTTP_ at the front of the name, since this is required
    # to get it through suexec from the web scripts.
834
    #
835
    if (!($ENV{WITH_TB_ADMIN_PRIVS} || $ENV{HTTP_WITH_TB_ADMIN_PRIVS})) {
836 837 838
	return 0;
    }

839 840 841 842
    if (!defined($uid)) {
	$uid = $UID;
    }

843 844
    #
    # Test if numeric. Map to name if it is.
Mac Newbold's avatar
Mac Newbold committed
845
    #
846 847 848 849 850 851 852
    if ($uid =~ /^[0-9]+$/) {
	($name) = getpwuid($uid)
	    or die "$uid not in passwd file\n";
    }
    else {
	$name = $uid;
    }
853 854

    my $query_result =
855
	DBQueryFatal("select admin from users where uid='$name'");
856 857 858 859 860 861 862 863 864

    my @row = $query_result->fetchrow_array();
    if ($row[0] == 1) {
	return 1;
    }
    return 0;
}

#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
865 866
# Project permission checks. The group id (gid) can be undef, in which case
# the pid is used (ie: a default group check is made).
867
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
868 869 870
# Usage: TBProjAccessCheck($uid, $pid, $gid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
871
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
872
sub TBProjAccessCheck($$$$)
873
{
Leigh B. Stoller's avatar
Leigh B. Stoller committed
874 875
    my ($uid, $pid, $gid, $access_type) = @_;
    my $mintrust;
876

Leigh B. Stoller's avatar
Leigh B. Stoller committed
877 878 879
    if ($access_type < TB_PROJECT_MIN ||
	$access_type > TB_PROJECT_MAX) {
	die("*** Invalid access type: $access_type!");
880 881
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
882 883
    #
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
884
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
885 886
    if (TBAdmin($uid)) {
	return 1;
887
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
888 889 890 891 892 893 894
    $uid = MapNumericUID($uid);

    #
    # No group, then use the default group.
    #
    if (! defined($gid)) {
	$gid = $pid;
895 896
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
897 898 899 900 901 902
    if ($access_type == TB_PROJECT_READINFO) {
	$mintrust = PROJMEMBERTRUST_USER;
    }
    elsif ($access_type == TB_PROJECT_CREATEEXPT) {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }
903 904 905
    elsif ($access_type == TB_PROJECT_DELUSER) {
	$mintrust = PROJMEMBERTRUST_PROJROOT;
    }
906 907 908 909
    elsif ($access_type == TB_PROJECT_MAKEGROUP ||
	   $access_type == TB_PROJECT_DELGROUP) {
	$mintrust = PROJMEMBERTRUST_GROUPROOT;
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
910 911 912 913 914 915 916 917 918 919 920 921 922
    else {
	die("*** Unexpected access type: $access_type!");
    }

    return TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust);
}

#
# Experiment permission checks.
#
# Usage: TBExptAccessCheck($uid, $pid, $eid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
923
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
924 925 926 927 928 929 930 931
sub TBExptAccessCheck($$$$)
{
    my ($uid, $pid, $eid, $access_type) = @_;
    my $mintrust;

    if ($access_type < TB_EXPT_MIN ||
	$access_type > TB_EXPT_MAX) {
	die("*** Invalid access type: $access_type!");
932 933 934
    }

    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
935
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
936
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
937
    if (TBAdmin($uid)) {
938 939
	return 1;
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
940
    $uid = MapNumericUID($uid);
941

Leigh B. Stoller's avatar
Leigh B. Stoller committed
942
    my $query_result =
943
	DBQueryFatal("SELECT gid,expt_head_uid FROM experiments WHERE ".
Leigh B. Stoller's avatar
Leigh B. Stoller committed
944
		     "eid='$eid' and pid='$pid'");
Mac Newbold's avatar
Mac Newbold committed
945

Leigh B. Stoller's avatar
Leigh B. Stoller committed
946 947 948 949
    if ($query_result->numrows == 0) {
	return 0;
    }
    my @row = $query_result->fetchrow_array();
950 951
    my $gid     = $row[0];
    my $creator = $row[1];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
952

953 954 955
    #
    # An experiment may be destroyed by the experiment creator or the
    # project/group leader.
Mac Newbold's avatar
Mac Newbold committed
956
    #
957
    if ($access_type == TB_EXPT_READINFO) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
958 959 960 961 962 963
	$mintrust = PROJMEMBERTRUST_USER;
    }
    else {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }

964 965 966 967 968 969 970
    #
    # Either proper permission in the group, or group_root in the project.
    # This lets group_roots muck with other people's experiments, including
    # those in groups they do not belong to.
    #
    return TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust) ||
	TBMinTrust(TBGrpTrust($uid, $pid, $pid), PROJMEMBERTRUST_GROUPROOT);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
971 972 973 974 975 976 977 978
}

#
# Determine if uid can access a node or list of nodes.
#
# Usage: TBNodeAccessCheck($uid, $access_type, $node_id, ...)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
979
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
980 981 982 983 984 985 986 987 988 989
sub TBNodeAccessCheck($$@)
{
    my ($uid, $access_type) = (shift, shift);
    my @nodelist = @_;
    my $mintrust;

    if ($access_type < TB_NODEACCESS_MIN ||
	$access_type > TB_NODEACCESS_MAX) {
	die("*** Invalid access type: $access_type!");
    }
990 991

    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
992
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
993
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
994 995 996 997
    if (TBAdmin($uid)) {
	return 1;
    }
    $uid = MapNumericUID($uid);
Mac Newbold's avatar
Mac Newbold committed
998

Leigh B. Stoller's avatar
Leigh B. Stoller committed
999 1000 1001 1002 1003 1004 1005 1006
    if ($access_type == TB_NODEACCESS_READINFO) {
	$mintrust = PROJMEMBERTRUST_USER;
    }
    else {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }

    foreach my $node (@nodelist) {
1007
	my $query_result =
1008
	    DBQueryFatal("select e.pid,e.gid from reserved as r ".
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1009
			 "left join experiments as e on ".
1010 1011
			 "     e.pid=r.pid and e.eid=r.eid ".
			 "where r.node_id='$node'");
1012

1013
	if ($query_result->numrows == 0) {
1014 1015
	    return 0;
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1016
	my @row = $query_result->fetchrow_array();
1017 1018
	my $pid = $row[0];
	my $gid = $row[1];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1019

1020 1021 1022 1023 1024 1025 1026 1027
	#
	# Either proper permission in the group, or group_root in the
	# project. This lets group_roots muck with other people's
	# nodes, including those in groups they do not belong to.
	#
	if (! TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust) &&
	    ! TBMinTrust(TBGrpTrust($uid, $pid, $pid),
			 PROJMEMBERTRUST_GROUPROOT)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1028 1029
	    return 0;
	}
1030 1031 1032 1033 1034
    }
    return 1;
}

#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1035
# Access checks for an OSID. Tests for tbadmin.
1036
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1037 1038 1039
# Usage: TBOSIDAccessCheck($uid, $osid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
1040
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1041
sub TBOSIDAccessCheck($$$)
1042