libdb.pm.in 137 KB
Newer Older
1
2
#!/usr/bin/perl -w

Leigh B. Stoller's avatar
Leigh B. Stoller committed
3
4
#
# EMULAB-COPYRIGHT
5
# Copyright (c) 2000-2006 University of Utah and the Flux Group.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
6
7
8
# All rights reserved.
#

9
#
10
11
# A library of useful DB stuff. Mostly things that get done a lot.
# Saves typing.
12
13
14
15
16
#
# XXX: The notion of "uid" is a tad confused. A unix uid is a number,
#      while in the DB a user uid is a string (equiv to unix login).
#      Needs to be cleaned up.
#
17

18
package libdb;
19
use strict;
20
use Exporter;
Mac Newbold's avatar
Mac Newbold committed
21
use vars qw(@ISA @EXPORT);
22
23
@ISA = "Exporter";
@EXPORT =
24
    qw ( NODERELOADING_PID NODERELOADING_EID NODEDEAD_PID NODEDEAD_EID
25
	 OLDRESERVED_PID OLDRESERVED_EID NFREELOCKED_PID NFREELOCKED_EID 
26
27
	 NODEBOOTSTATUS_OKAY NODEBOOTSTATUS_FAILED NODEBOOTSTATUS_UNKNOWN
	 NODESTARTSTATUS_NOSTATUS PROJMEMBERTRUST_NONE PROJMEMBERTRUST_USER
Leigh B. Stoller's avatar
Leigh B. Stoller committed
28
	 PROJMEMBERTRUST_ROOT PROJMEMBERTRUST_GROUPROOT
29
	 PROJMEMBERTRUST_PROJROOT PROJMEMBERTRUST_LOCALROOT
Leigh B. Stoller's avatar
Leigh B. Stoller committed
30

31
	 PROJROOT GROUPROOT USERROOT TBOPSPID EXPTLOGNAME
32
33
	 PLABMOND_PID PLABMOND_EID PLABHOLDING_PID PLABHOLDING_EID

34
	 TBTrustConvert TBMinTrust TBGrpTrust TBProjTrust MapNumericUID
Leigh B. Stoller's avatar
Leigh B. Stoller committed
35
36
37

	 TB_NODEACCESS_READINFO TB_NODEACCESS_MODIFYINFO
	 TB_NODEACCESS_LOADIMAGE TB_NODEACCESS_REBOOT
38
39
	 TB_NODEACCESS_POWERCYCLE TB_NODEACCESS_MODIFYVLANS
	 TB_NODEACCESS_MIN TB_NODEACCESS_MAX
Leigh B. Stoller's avatar
Leigh B. Stoller committed
40

41
42
	 NODEFAILMODE_FATAL NODEFAILMODE_NONFATAL NODEFAILMODE_IGNORE

Leigh B. Stoller's avatar
Leigh B. Stoller committed
43
44
45
	 TB_USERINFO_READINFO TB_USERINFO_MODIFYINFO
	 TB_USERINFO_MIN TB_USERINFO_MAX

46
47
	 USERSTATUS_ACTIVE USERSTATUS_FROZEN
	 USERSTATUS_UNAPPROVED USERSTATUS_UNVERIFIED USERSTATUS_NEWUSER
48

49
	 TB_EXPT_READINFO TB_EXPT_MODIFY TB_EXPT_DESTROY TB_EXPT_UPDATE
Leigh B. Stoller's avatar
Leigh B. Stoller committed
50
51
52
53
	 TB_EXPT_MIN TB_EXPT_MAX

	 TB_PROJECT_READINFO TB_PROJECT_MAKEGROUP
	 TB_PROJECT_EDITGROUP TB_PROJECT_DELGROUP
Chad Barb's avatar
   
Chad Barb committed
54
	 TB_PROJECT_GROUPGRABUSERS TB_PROJECT_BESTOWGROUPROOT
Leigh B. Stoller's avatar
Leigh B. Stoller committed
55
56
57
58
59
60
61
62
63
64
65
	 TB_PROJECT_LEADGROUP TB_PROJECT_ADDUSER
	 TB_PROJECT_DELUSER TB_PROJECT_MAKEOSID
	 TB_PROJECT_DELOSID TB_PROJECT_MAKEIMAGEID TB_PROJECT_DELIMAGEID
	 TB_PROJECT_CREATEEXPT TB_PROJECT_MIN TB_PROJECT_MAX

	 TB_OSID_READINFO TB_OSID_CREATE
	 TB_OSID_DESTROY TB_OSID_MIN TB_OSID_MAX

	 TB_IMAGEID_READINFO TB_IMAGEID_MODIFYINFO
	 TB_IMAGEID_CREATE TB_IMAGEID_DESTROY
	 TB_IMAGEID_ACCESS TB_IMAGEID_MIN TB_IMAGEID_MAX
66

Leigh B. Stoller's avatar
Leigh B. Stoller committed
67
	 DBLIMIT_NSFILESIZE NODERELOADPENDING_EID
68

Timothy Stack's avatar
   
Timothy Stack committed
69
70
	 NODEREPOSITIONING_PID NODEREPOSITIONING_EID NODEREPOSPENDING_EID

71
	 EXPTSTATE_NEW EXPTSTATE_PRERUN EXPTSTATE_SWAPPED EXPTSTATE_SWAPPING
Leigh B. Stoller's avatar
Leigh B. Stoller committed
72
	 EXPTSTATE_ACTIVATING EXPTSTATE_ACTIVE EXPTSTATE_PANICED
73
74
75
76
77
	 EXPTSTATE_TERMINATING EXPTSTATE_TERMINATED EXPTSTATE_QUEUED
	 EXPTSTATE_MODIFY_PARSE EXPTSTATE_MODIFY_REPARSE EXPTSTATE_MODIFY_RESWAP
	 EXPTSTATE_RESTARTING
	 BATCHSTATE_LOCKED BATCHSTATE_UNLOCKED
	 EXPTCANCEL_CLEAR EXPTCANCEL_TERM EXPTCANCEL_SWAP
78

79
	 TBSetCancelFlag TBGetCancelFlag
Leigh B. Stoller's avatar
Leigh B. Stoller committed
80

Mac Newbold's avatar
Mac Newbold committed
81
	 TB_NODELOGTYPE_MISC TB_NODELOGTYPES TB_DEFAULT_NODELOGTYPE
82
83

	 TB_DEFAULT_RELOADTYPE TB_RELOADTYPE_FRISBEE TB_RELOADTYPE_NETDISK
84

85
86
	 TB_EXPTPRIORITY_LOW TB_EXPTPRIORITY_HIGH

87
	 TB_ASSIGN_TOOFEWNODES TB_OPSPID
88

89
	 TBDB_TBEVENT_NODESTATE TBDB_TBEVENT_NODEOPMODE TBDB_TBEVENT_CONTROL
90
	 TBDB_TBEVENT_COMMAND
Chad Barb's avatar
   
Chad Barb committed
91

92
	 TBDB_NODESTATE_ISUP TBDB_NODESTATE_REBOOTING TBDB_NODESTATE_REBOOTED
93
	 TBDB_NODESTATE_SHUTDOWN TBDB_NODESTATE_BOOTING TBDB_NODESTATE_TBSETUP
94
	 TBDB_NODESTATE_RELOADSETUP TBDB_NODESTATE_RELOADING
95
96
	 TBDB_NODESTATE_RELOADDONE TBDB_NODESTATE_RELOADDONE_V2
	 TBDB_NODESTATE_UNKNOWN
97
	 TBDB_NODESTATE_PXEWAIT TBDB_NODESTATE_PXEWAKEUP
98
	 TBDB_NODESTATE_PXEBOOTING TBDB_NODESTATE_ALWAYSUP
99
	 TBDB_NODESTATE_MFSSETUP TBDB_NODESTATE_TBFAILED
100
	 TBDB_NODESTATE_POWEROFF
Chad Barb's avatar
   
Chad Barb committed
101

102
103
	 TBDB_NODEOPMODE_NORMAL TBDB_NODEOPMODE_DELAYING
	 TBDB_NODEOPMODE_UNKNOWNOS TBDB_NODEOPMODE_RELOADING
104
	 TBDB_NODEOPMODE_NORMALv1 TBDB_NODEOPMODE_MINIMAL
105
106
	 TBDB_NODEOPMODE_RELOAD TBDB_NODEOPMODE_RELOADMOTE
	 TBDB_NODEOPMODE_DELAY
107
	 TBDB_NODEOPMODE_BOOTWHAT
108
	 TBDB_NODEOPMODE_ANY
109
	 TBDB_NODEOPMODE_UNKNOWN
Chad Barb's avatar
   
Chad Barb committed
110

111
	 TBDB_COMMAND_REBOOT
112
113
	 TBDB_COMMAND_POWEROFF TBDB_COMMAND_POWERON TBDB_COMMAND_POWERCYCLE

114
115
116
	 TBDB_STATED_TIMEOUT_REBOOT TBDB_STATED_TIMEOUT_NOTIFY
	 TBDB_STATED_TIMEOUT_CMDRETRY

Chad Barb's avatar
   
Chad Barb committed
117
118
119
	 TBDB_ALLOCSTATE_FREE_CLEAN TBDB_ALLOCSTATE_FREE_DIRTY
	 TBDB_ALLOCSTATE_DOWN TBDB_ALLOCSTATE_RELOAD_TO_FREE
	 TBDB_ALLOCSTATE_RELOAD_PENDING TBDB_ALLOCSTATE_RES_RELOAD
Mac Newbold's avatar
Mac Newbold committed
120
121
	 TBDB_ALLOCSTATE_RES_INIT_DIRTY TBDB_ALLOCSTATE_RES_INIT_CLEAN
	 TBDB_ALLOCSTATE_RES_REBOOT_DIRTY TBDB_ALLOCSTATE_RES_REBOOT_CLEAN
Chad Barb's avatar
   
Chad Barb committed
122
	 TBDB_ALLOCSTATE_RES_READY TBDB_ALLOCSTATE_UNKNOWN
123
	 TBDB_ALLOCSTATE_RES_TEARDOWN TBDB_ALLOCSTATE_DEAD
124
	 TBDB_ALLOCSTATE_RES_RECONFIG
Chad Barb's avatar
   
Chad Barb committed
125

126
127
	 TBDB_STATS_PRELOAD TBDB_STATS_START TBDB_STATS_TERMINATE
	 TBDB_STATS_SWAPIN TBDB_STATS_SWAPOUT TBDB_STATS_SWAPMODIFY
128
	 TBDB_STATS_FLAGS_IDLESWAP TBDB_STATS_FLAGS_PREMODIFY
129
	 TBDB_STATS_FLAGS_START TBDB_STATS_FLAGS_PRESWAPIN
130

131
132
	 TBDB_JAILIPBASE TBDB_JAILIPMASK

133
	 TBDB_RSRVROLE_NODE TBDB_RSRVROLE_VIRTHOST TBDB_RSRVROLE_DELAYNODE
134
	 TBDB_RSRVROLE_SIMHOST
135

136
	 TBDB_EXPT_WORKDIR
137
	 TBSetNodeEventState TBGetNodeEventState
Timothy Stack's avatar
   
Timothy Stack committed
138
	 TBNodeEventStateUpdated
Chad Barb's avatar
   
Chad Barb committed
139
	 TBSetNodeAllocState TBGetNodeAllocState
140
	 TBSetNodeOpMode TBGetNodeOpMode TBSetNodeNextOpMode
141
	 TB_OSID_MBKERNEL 
Mac Newbold's avatar
Mac Newbold committed
142
	 TB_OSID_FREEBSD_MFS TB_OSID_FRISBEE_MFS
143
	 TBBootWhat TBNodeStateTimeout
Mac Newbold's avatar
Mac Newbold committed
144
	 TBDB_TBCONTROL_RESET TBDB_TBCONTROL_RELOADDONE
145
	 TBDB_TBCONTROL_RELOADDONE_V2
146
	 TBDB_TBCONTROL_TIMEOUT TBDB_NO_STATE_TIMEOUT
Mac Newbold's avatar
Mac Newbold committed
147
148
	 TBDB_TBCONTROL_PXEBOOT TBDB_TBCONTROL_BOOTING
	 TBDB_TBCONTROL_CHECKGENISUP
149

150
151
	 TBDB_LOWVPORT TBDB_MAXVPORT TBDB_PORTRANGE

152
153
	 TBDB_PHYSICAL_NODE_TABLES

154
	 TBAdmin TBOpsGuy TBProjAccessCheck TBNodeAccessCheck TBOSIDAccessCheck
Leigh B. Stoller's avatar
Leigh B. Stoller committed
155
	 TBImageIDAccessCheck TBExptAccessCheck ExpLeader MarkNodeDown
156
	 SetNodeBootStatus OSFeatureSupported IsShelved NodeidToExp NodeidToExpOldReserved
157
	 UserDBInfo DBQuery DBQueryFatal DBQueryWarn DBWarn DBFatal DBErr
Kevin Atkinson's avatar
   
Kevin Atkinson committed
158
	 NewTBDBHandle DBQueryN DBQueryFatalN DBQueryWarnN DBErrN
159
	 DBQuoteSpecial UNIX2DBUID ExpState SetExpState ProjLeader
160
161
	 ExpNodes ExpNodeVnames ExpNodesOldReserved
	 DBDateTime DefaultImageID GroupLeader TBGroupUnixInfo
162
	 TBValidNodeLogType TBValidNodeName TBSetNodeLogEntry
163
	 TBSetSchedReload MapNodeOSID TBLockExp TBUnLockExp TBSetExpSwapTime
164
	 TBUnixGroupList TBOSID TBOSMaxConcurrent TBOSCountInstances
165
	 TBResolveNextOSID TBOsidToPid TBOSIDRebootWaittime
166
	 TBOSLoadMaxOkay TBImageLoadMaxOkay TBImageID ExpSwapper
167
	 TBdbfork TBDBDisconnect VnameToNodeid TBExpLocked
168
	 TBIsNodeRemote TBExptSetLogFile TBExptClearLogFile TBExptGetLogFile
169
	 TBIsNodeImageable TBIsNodeVirtual TBControlNetIP TBPhysNodeID
170
	 TBExptOpenLogFile TBExptCloseLogFile TBExptCreateLogFile
171
	 TBNodeUpdateAccountsByPid TBNodeUpdateAccountsByType
172
	 TBNodeUpdateAccountsByUID
173
	 TBSaveExpLogFiles TBExptWorkDir TBExptUserDir TBExptLogDir
174
	 TBExptDestroy TBIPtoNodeID TBNodeBootReset TBNodeStateWait
175
	 TBLeaderMailList ExpGroup TBExptSetSwapUID TBExptSetThumbNail
176
	 TBNodeAllocCheck TBPlabNodeUsername MarkPhysNodeDown TBExptIsElabInElab
Mike Hibler's avatar
Mike Hibler committed
177
178
	 TBExptFirewall TBNodeFirewall TBExptFirewallAndPort
	 TBSetExptFirewallVlan TBClearExptFirewallVlan
179
	 TBNodeConsoleTail TBExptGetSwapoutAction TBExptGetSwapState
180

Timothy Stack's avatar
   
Timothy Stack committed
181
	 TBNodeSubNodes
182
	 TBNodeAdminOSID TBNodeDiskloadOSID
183
	 TBNodeType TBNodeTypeProcInfo TBNodeTypeBiosWaittime
184

Mac Newbold's avatar
Mac Newbold committed
185
	 TBExptRemoveVirtualState TBExptBackupVirtualState
Chad Barb's avatar
   
Chad Barb committed
186
187
	 TBExptRestoreVirtualState

Mac Newbold's avatar
Mac Newbold committed
188
	 TBExptRemovePhysicalState TBExptBackupPhysicalState
189
	 TBExptRestorePhysicalState TBExptClearBackupState
Chad Barb's avatar
   
Chad Barb committed
190

191
192
	 TBExptPortRange

193
	 TBDB_WIDEAREA_LOCALNODE
Leigh B. Stoller's avatar
Leigh B. Stoller committed
194
	 TBWideareaNodeID TBTipServers
Mac Newbold's avatar
Mac Newbold committed
195

196
	 TBSiteVarExists TBGetSiteVar TBSetSiteVar
Chad Barb's avatar
   
Chad Barb committed
197

198
	 TBActivityReport GatherSwapStats GatherAssignStats
199
	 TBAvailablePCs
200

201
202
	 TBDB_IFACEROLE_CONTROL TBDB_IFACEROLE_EXPERIMENT
	 TBDB_IFACEROLE_JAIL TBDB_IFACEROLE_FAKE TBDB_IFACEROLE_OTHER
203
	 TBDB_IFACEROLE_GW TBDB_IFACEROLE_OUTER_CONTROL
204

205
206
	 TBDB_ROUTERTYPE_NONE	TBDB_ROUTERTYPE_OSPF
	 TBDB_ROUTERTYPE_STATIC TBDB_ROUTERTYPE_MANUAL
207
	 TBDB_EVENTKEY TBDB_WEBKEY
208
209
	 TBDB_CHECKDBSLOT_NOFLAGS TBDB_CHECKDBSLOT_WARN TBDB_CHECKDBSLOT_ERROR
         max min TBcheck_dbslot
Mac Newbold's avatar
Mac Newbold committed
210
	 hash_recurse array_recurse hash_recurse2 array_recurse2
211
	 TBGetUniqueIndex
212
213

	 TBExptMinMaxNodes TBExptSecurityLevel TBExptIDX
214
215
	 TBDB_SECLEVEL_GREEN TBDB_SECLEVEL_BLUE TBDB_SECLEVEL_YELLOW
	 TBDB_SECLEVEL_ORANGE TBDB_SECLEVEL_RED TBDB_SECLEVEL_ZAPDISK
Leigh B. Stoller's avatar
Leigh B. Stoller committed
216
217

	 TBExptSetPanicBit TBExptGetPanicBit TBExptClearPanicBit
218
219
220
221

	 TB_NODEHISTORY_OP_FREE TB_NODEHISTORY_OP_ALLOC TB_NODEHISTORY_OP_MOVE
	 TBSetNodeHistory

Timothy Stack's avatar
   
Timothy Stack committed
222
223
	 TBGetOSBootCmd

224
225
	 TBRobotLabExpt

226
227
	 TBExptContainsNodeCT

228
	 );
229

230
# Must come after package declaration!
231
use lib '@prefix@/lib';
Kevin Atkinson's avatar
   
Kevin Atkinson committed
232
use libtblog_simple;
233
use English;
234
use File::Basename;
235
use POSIX qw(strftime);
236
require Mysql;
Mac Newbold's avatar
Mac Newbold committed
237
238
use vars qw($DBQUERY_MAXTRIES $DBCONN_MAXTRIES @EXPORT_OK @virtualTables
	    @physicalTables);
239

240
241
242
# Configure variables
my $TB		= "@prefix@";
my $DBNAME	= "@TBDBNAME@";
243
my $TBOPS       = "@TBOPSEMAIL@";
244
245
my $EVENTSYS    = "@EVENTSYS@";
my $BOSSNODE    = "@BOSSNODE@";
246
my $TESTMODE    = @TESTMODE@;
247
my $TBOPSPID	= "emulab-ops";
248
249
250
251
my $SCRIPTNAME  = "Unknown";
my $PROJROOT    = "/proj";
my $GROUPROOT   = "/groups";
my $USERROOT    = "/users";
252
my $EXPTLOGNAME = "activity.log";
253

254
255
256
257
258
if ($EVENTSYS) {
    require event;
    import event;
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
259
260
261
# Untainted scriptname for email below.
if ($PROGRAM_NAME =~ /^([-\w\.\/]+)$/) {
    $SCRIPTNAME = basename($1);
262
263
}
else {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
264
    $SCRIPTNAME = "Tainted";
265
266
}

267
#
268
# Set up for querying the database. Note that fork causes a reconnect
Mac Newbold's avatar
Mac Newbold committed
269
# to the DB in the child.
270
#
Kevin Atkinson's avatar
   
Kevin Atkinson committed
271
my @DB;
272
273
274
$DBQUERY_MAXTRIES = 1;
$DBCONN_MAXTRIES  = 5;
@EXPORT_OK        = qw($DBQUERY_MAXTRIES $DBCONN_MAXTRIES);
275

Kevin Atkinson's avatar
   
Kevin Atkinson committed
276
sub TBDBConnect($)
277
{
Kevin Atkinson's avatar
   
Kevin Atkinson committed
278
    my ($dbnum) = @_;
279
    my $maxtries = $DBCONN_MAXTRIES;
280
281
282
283
284
285
286
287
288

    #
    # Construct a 'username' from the name of this script and the user who
    # ran it. This is for accounting purposes.
    #
    my $name = getpwuid($UID);
    if (!$name) {
	$name = "uid$UID";
    }
289
    my $dbuser = "$SCRIPTNAME:$name:$PID";
290

291
    while ($maxtries) {
Kevin Atkinson's avatar
   
Kevin Atkinson committed
292
293
	$DB[$dbnum] = Mysql->connect("localhost", $DBNAME, $dbuser, "none");
	if (defined($DB[$dbnum])) {
294
295
	    last;
	}
296
297
298
	$maxtries--;
	sleep(1);
    }
Kevin Atkinson's avatar
   
Kevin Atkinson committed
299
    if (!defined($DB[$dbnum])) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
300
301
302
	print STDERR "Cannot connect to DB after several attempts!\n";
	# Ensure consistent error value. 
	exit(-1);
303
    }
Kevin Atkinson's avatar
   
Kevin Atkinson committed
304
    $DB[$dbnum]->{'dbh'}->{'PrintError'} = 0;
305
    $Mysql::QUIET = 1;
306
}
Kevin Atkinson's avatar
   
Kevin Atkinson committed
307
TBDBConnect(0);
308

309
310
sub TBdbfork()
{
311
    select(undef, undef, undef, 0.3);
Kevin Atkinson's avatar
   
Kevin Atkinson committed
312
313
314
315
    for (my $i = 0; $i < @DB; $i++) {
	undef($DB[$i]);
	TBDBConnect($i);
    }
316
317
318
    if ($EVENTSYS) {
	EventFork();
    }
319
320
}

321
322
323
# To avoid keeping a mysql connection around.
sub TBDBDisconnect()
{
Kevin Atkinson's avatar
   
Kevin Atkinson committed
324
325
326
    for (my $i = 0; $i < @DB; $i++) {
	undef($DB[$i]);
    }
327
328
329
    select(undef, undef, undef, 0.3);
}

Kevin Atkinson's avatar
   
Kevin Atkinson committed
330
331
332
333
334
335
336
# Create a new DB handle and return the handle number
sub NewTBDBHandle() {
    my $dbnum = @DB;
    TBDBConnect($dbnum);
    return $dbnum;
}

337
338
339
340
341
#
# Record last DB error string.
#
my $DBErrorString = "";

342
343
344
345
#
# Needs to be config'ed.
#
sub TBDB_EXPT_WORKDIR()		{ "/usr/testbed/expwork"; }
Mac Newbold's avatar
Mac Newbold committed
346

347
348
349
350
351
#
# Define exported "constants". Basically, these are just perl subroutines
# that look like constants cause you do not need to call a perl subroutine
# with parens. That is, FOO and FOO() are the same thing.
#
352
sub NODERELOADING_PID()		{ $TBOPSPID; }
353
sub NODERELOADING_EID()		{ "reloading"; }
354
sub NODERELOADPENDING_EID()	{ "reloadpending"; }
Timothy Stack's avatar
   
Timothy Stack committed
355
356
357
sub NODEREPOSITIONING_PID()	{ $TBOPSPID; }
sub NODEREPOSITIONING_EID()	{ "repositioning"; }
sub NODEREPOSPENDING_EID()	{ "repositionpending"; }
358
sub NODEDEAD_PID()		{ $TBOPSPID; }
359
sub NODEDEAD_EID()		{ "hwdown"; }
360
361
362
363
sub PLABMOND_PID()		{ $TBOPSPID; }
sub PLABMOND_EID()		{ "plab-monitor"; }
sub PLABHOLDING_PID()		{ $TBOPSPID; }
sub PLABHOLDING_EID()		{ "plabnodes"; }
364
365
sub OLDRESERVED_PID()		{ $TBOPSPID; }
sub OLDRESERVED_EID()		{ "oldreserved"; }
366
367
sub NFREELOCKED_PID()		{ $TBOPSPID; }
sub NFREELOCKED_EID()		{ "nfree-locked"; }
368
369
370
sub PROJROOT()			{ $PROJROOT; }
sub GROUPROOT()			{ $GROUPROOT; }
sub USERROOT()			{ $USERROOT; }
Robert Ricci's avatar
Robert Ricci committed
371
sub TBOPSPID()			{ $TBOPSPID; }
372
sub EXPTLOGNAME()		{ $EXPTLOGNAME; }
373
374
375
376
377
378

sub NODEBOOTSTATUS_OKAY()	{ "okay" ; }
sub NODEBOOTSTATUS_FAILED()	{ "failed"; }
sub NODEBOOTSTATUS_UNKNOWN()	{ "unknown"; }
sub NODESTARTSTATUS_NOSTATUS()	{ "none"; }

379
380
381
382
sub NODEFAILMODE_FATAL()	{ "fatal"; }
sub NODEFAILMODE_NONFATAL()	{ "nonfatal"; }
sub NODEFAILMODE_IGNORE()	{ "ignore"; }

383
# Experiment states
384
385
386
sub EXPTSTATE_NEW()		{ "new"; }
sub EXPTSTATE_PRERUN()		{ "prerunning"; }
sub EXPTSTATE_SWAPPED()		{ "swapped"; }
387
sub EXPTSTATE_QUEUED()		{ "queued"; }
388
389
390
sub EXPTSTATE_SWAPPING()	{ "swapping"; }
sub EXPTSTATE_ACTIVATING()	{ "activating"; }
sub EXPTSTATE_ACTIVE()		{ "active"; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
391
sub EXPTSTATE_PANICED()		{ "paniced"; }
392
393
sub EXPTSTATE_TERMINATING()	{ "terminating"; }
sub EXPTSTATE_TERMINATED()	{ "ended"; }
394
395
396
397
398
399
400
sub EXPTSTATE_MODIFY_PARSE()	{ "modify_parse"; }
sub EXPTSTATE_MODIFY_REPARSE()	{ "modify_reparse"; }
sub EXPTSTATE_MODIFY_RESWAP()	{ "modify_reswap"; }
sub EXPTSTATE_RESTARTING()	{ "restarting"; }
# For the batch_daemon.
sub BATCHSTATE_LOCKED()		{ "locked";}
sub BATCHSTATE_UNLOCKED()	{ "unlocked";}
401

402
# Cancel flags
403
404
405
sub EXPTCANCEL_CLEAR()		{ 0 ;}
sub EXPTCANCEL_TERM()		{ 1 ;}
sub EXPTCANCEL_SWAP()		{ 2 ;}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
406

407
408
sub USERSTATUS_ACTIVE()		{ "active"; }
sub USERSTATUS_FROZEN()		{ "frozen"; }
409
410
411
sub USERSTATUS_UNAPPROVED()	{ "unapproved"; }
sub USERSTATUS_UNVERIFIED()	{ "unverified"; }
sub USERSTATUS_NEWUSER()	{ "newuser"; }
412

413
414
415
#
# We want valid project membership to be non-zero for easy membership
# testing. Specific trust levels are encoded thusly.
Mac Newbold's avatar
Mac Newbold committed
416
#
417
418
sub PROJMEMBERTRUST_NONE()	{ 0; }
sub PROJMEMBERTRUST_USER()	{ 1; }
419
sub PROJMEMBERTRUST_ROOT()	{ 2; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
420
421
422
423
424
425
426
sub PROJMEMBERTRUST_LOCALROOT()	{ 2; }
sub PROJMEMBERTRUST_GROUPROOT()	{ 3; }
sub PROJMEMBERTRUST_PROJROOT()	{ 4; }
sub PROJMEMBERTRUST_ADMIN()	{ 5; }

#
# Access types. Duplicated in the web interface. Make changes there too!
Mac Newbold's avatar
Mac Newbold committed
427
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
428
429
430
431
432
433
# Things you can do to a node.
sub TB_NODEACCESS_READINFO()	{ 1; }
sub TB_NODEACCESS_MODIFYINFO()	{ 2; }
sub TB_NODEACCESS_LOADIMAGE()	{ 3; }
sub TB_NODEACCESS_REBOOT()	{ 4; }
sub TB_NODEACCESS_POWERCYCLE()	{ 5; }
434
sub TB_NODEACCESS_MODIFYVLANS()	{ 6; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
435
sub TB_NODEACCESS_MIN()		{ TB_NODEACCESS_READINFO; }
436
sub TB_NODEACCESS_MAX()		{ TB_NODEACCESS_MODIFYVLANS; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
437
438
439
440
441
442
443

# User Info (modinfo web page, etc).
sub TB_USERINFO_READINFO()	{ 1; }
sub TB_USERINFO_MODIFYINFO()	{ 2; }
sub TB_USERINFO_MIN()		{ TB_USERINFO_READINFO; }
sub TB_USERINFO_MAX()		{ TB_USERINFO_MODIFYINFO; }

444
# Experiments.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
445
446
447
sub TB_EXPT_READINFO()		{ 1; }
sub TB_EXPT_MODIFY()		{ 2; }
sub TB_EXPT_DESTROY()		{ 3; }
448
sub TB_EXPT_UPDATE()		{ 4; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
449
sub TB_EXPT_MIN()		{ TB_EXPT_READINFO; }
450
sub TB_EXPT_MAX()		{ TB_EXPT_UPDATE; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
451
452
453
454
455

# Projects.
sub TB_PROJECT_READINFO()	{ 1; }
sub TB_PROJECT_MAKEGROUP()	{ 2; }
sub TB_PROJECT_EDITGROUP()	{ 3; }
Chad Barb's avatar
   
Chad Barb committed
456
sub TB_PROJECT_GROUPGRABUSERS() { 4; }
Chad Barb's avatar
   
Chad Barb committed
457
458
459
460
461
462
463
464
465
466
sub TB_PROJECT_BESTOWGROUPROOT(){ 5; }
sub TB_PROJECT_DELGROUP()	{ 6; }
sub TB_PROJECT_LEADGROUP()	{ 7; }
sub TB_PROJECT_ADDUSER()	{ 8; }
sub TB_PROJECT_DELUSER()	{ 9; }
sub TB_PROJECT_MAKEOSID()	{ 10; }
sub TB_PROJECT_DELOSID()	{ 11; }
sub TB_PROJECT_MAKEIMAGEID()	{ 12; }
sub TB_PROJECT_DELIMAGEID()	{ 13; }
sub TB_PROJECT_CREATEEXPT()	{ 14; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
467
468
469
sub TB_PROJECT_MIN()		{ TB_PROJECT_READINFO; }
sub TB_PROJECT_MAX()		{ TB_PROJECT_CREATEEXPT; }

Mac Newbold's avatar
Mac Newbold committed
470
# OSIDs
Leigh B. Stoller's avatar
Leigh B. Stoller committed
471
472
473
474
475
476
sub TB_OSID_READINFO()		{ 1; }
sub TB_OSID_CREATE()		{ 2; }
sub TB_OSID_DESTROY()		{ 3; }
sub TB_OSID_MIN()		{ TB_OSID_READINFO; }
sub TB_OSID_MAX()		{ TB_OSID_DESTROY; }

477
478
# Magic OSID constants
sub TB_OSID_MBKERNEL()          { "_KERNEL_"; } # multiboot kernel OSID
479
480
481
482

# Magic MFS constants
sub TB_OSID_FREEBSD_MFS()	{ "FREEBSD-MFS" };
sub TB_OSID_FRISBEE_MFS()	{ "FRISBEE-MFS" };
483

Leigh B. Stoller's avatar
Leigh B. Stoller committed
484
# ImageIDs
485
486
487
488
489
#
# Clarification:
# READINFO is read-only access to the image and its contents
# (This is what people get for shared images)
# ACCESS means complete power over the image and its [meta]data
Leigh B. Stoller's avatar
Leigh B. Stoller committed
490
491
492
493
494
495
496
sub TB_IMAGEID_READINFO()	{ 1; }
sub TB_IMAGEID_MODIFYINFO()	{ 2; }
sub TB_IMAGEID_CREATE()		{ 3; }
sub TB_IMAGEID_DESTROY()	{ 4; }
sub TB_IMAGEID_ACCESS()		{ 5; }
sub TB_IMAGEID_MIN()		{ TB_IMAGEID_READINFO; }
sub TB_IMAGEID_MAX()		{ TB_IMAGEID_ACCESS; }
497

498
# Node Log Types
499
500
501
502
sub TB_NODELOGTYPE_MISC		{ "misc"; }
sub TB_NODELOGTYPES()		{ ( TB_NODELOGTYPE_MISC ) ; }
sub TB_DEFAULT_NODELOGTYPE()	{ TB_NODELOGTYPE_MISC; }

503
504
505
506
507
# Node History Stuff.
sub TB_NODEHISTORY_OP_FREE	{ "free"; }
sub TB_NODEHISTORY_OP_ALLOC	{ "alloc"; }
sub TB_NODEHISTORY_OP_MOVE	{ "move"; }

508
509
510
# Reload Types.
sub TB_RELOADTYPE_NETDISK()	{ "netdisk"; }
sub TB_RELOADTYPE_FRISBEE()	{ "frisbee"; }
511
sub TB_DEFAULT_RELOADTYPE()	{ TB_RELOADTYPE_FRISBEE; }
512

513
514
515
516
517
518
519
# Experiment priorities.
sub TB_EXPTPRIORITY_LOW()	{ 0; }
sub TB_EXPTPRIORITY_HIGH()	{ 20; }

# Assign exit status for too few nodes.
sub TB_ASSIGN_TOOFEWNODES()	{ 2; }

520
521
522
# System PID.
sub TB_OPSPID()			{ $TBOPSPID; }

523
#
524
525
526
527
# Events we may want to send
#
sub TBDB_TBEVENT_NODESTATE	{ "TBNODESTATE"; }
sub TBDB_TBEVENT_NODEOPMODE	{ "TBNODEOPMODE"; }
528
sub TBDB_TBEVENT_CONTROL	{ "TBCONTROL"; }
529
sub TBDB_TBEVENT_COMMAND	{ "TBCOMMAND"; }
530
sub TBDB_TBEVENT_EXPTSTATE	{ "TBEXPTSTATE"; }
531
532
533
534

#
# For nodes, we use this set of events.
#
535
sub TBDB_NODESTATE_ISUP()	{ "ISUP"; }
536
sub TBDB_NODESTATE_ALWAYSUP()	{ "ALWAYSUP"; }
537
538
539
540
541
sub TBDB_NODESTATE_REBOOTED()	{ "REBOOTED"; }
sub TBDB_NODESTATE_REBOOTING()	{ "REBOOTING"; }
sub TBDB_NODESTATE_SHUTDOWN()	{ "SHUTDOWN"; }
sub TBDB_NODESTATE_BOOTING()	{ "BOOTING"; }
sub TBDB_NODESTATE_TBSETUP()	{ "TBSETUP"; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
542
543
sub TBDB_NODESTATE_RELOADSETUP(){ "RELOADSETUP"; }
sub TBDB_NODESTATE_MFSSETUP()   { "MFSSETUP"; }
544
sub TBDB_NODESTATE_TBFAILED()	{ "TBFAILED"; }
545
546
sub TBDB_NODESTATE_RELOADING()	{ "RELOADING"; }
sub TBDB_NODESTATE_RELOADDONE()	{ "RELOADDONE"; }
547
sub TBDB_NODESTATE_RELOADDONE_V2(){ "RELOADDONEV2"; }
548
sub TBDB_NODESTATE_UNKNOWN()	{ "UNKNOWN"; };
549
sub TBDB_NODESTATE_PXEWAIT()	{ "PXEWAIT"; }
550
551
sub TBDB_NODESTATE_PXEWAKEUP()	{ "PXEWAKEUP"; }
sub TBDB_NODESTATE_PXEBOOTING()	{ "PXEBOOTING"; }
552
sub TBDB_NODESTATE_POWEROFF()	{ "POWEROFF"; }
553

554
sub TBDB_NODEOPMODE_ANY		{ "*"; } # A wildcard opmode
555
556
557
558
sub TBDB_NODEOPMODE_NORMAL	{ "NORMAL"; }
sub TBDB_NODEOPMODE_DELAYING	{ "DELAYING"; }
sub TBDB_NODEOPMODE_UNKNOWNOS	{ "UNKNOWNOS"; }
sub TBDB_NODEOPMODE_RELOADING	{ "RELOADING"; }
559
560
561
sub TBDB_NODEOPMODE_NORMALv1	{ "NORMALv1"; }
sub TBDB_NODEOPMODE_MINIMAL	{ "MINIMAL"; }
sub TBDB_NODEOPMODE_RELOAD	{ "RELOAD"; }
562
sub TBDB_NODEOPMODE_RELOADMOTE	{ "RELOAD-MOTE"; }
563
sub TBDB_NODEOPMODE_DELAY	{ "DELAY"; }
564
sub TBDB_NODEOPMODE_BOOTWHAT	{ "_BOOTWHAT_"; } # A redirection opmode
565
566
sub TBDB_NODEOPMODE_UNKNOWN	{ "UNKNOWN"; }

567
568
569
570
571
sub TBDB_COMMAND_REBOOT         { "REBOOT"; }
sub TBDB_COMMAND_POWEROFF       { "POWEROFF"; }
sub TBDB_COMMAND_POWERON        { "POWERON"; }
sub TBDB_COMMAND_POWERCYCLE     { "POWERCYCLE"; }

572
573
574
575
sub TBDB_STATED_TIMEOUT_REBOOT  { "REBOOT"; }
sub TBDB_STATED_TIMEOUT_NOTIFY  { "NOTIFY"; }
sub TBDB_STATED_TIMEOUT_CMDRETRY{ "CMDRETRY"; }

Chad Barb's avatar
   
Chad Barb committed
576
577
578
sub TBDB_ALLOCSTATE_FREE_CLEAN()       { "FREE_CLEAN"; }
sub TBDB_ALLOCSTATE_FREE_DIRTY()       { "FREE_DIRTY"; }
sub TBDB_ALLOCSTATE_DOWN()             { "DOWN"; }
579
sub TBDB_ALLOCSTATE_DEAD()             { "DEAD"; }
Chad Barb's avatar
   
Chad Barb committed
580
581
582
sub TBDB_ALLOCSTATE_RELOAD_TO_FREE()   { "RELOAD_TO_FREE"; }
sub TBDB_ALLOCSTATE_RELOAD_PENDING()   { "RELOAD_PENDING"; }
sub TBDB_ALLOCSTATE_RES_RELOAD()       { "RES_RELOAD"; }
Chad Barb's avatar
   
Chad Barb committed
583
584
sub TBDB_ALLOCSTATE_RES_REBOOT_DIRTY() { "RES_REBOOT_DIRTY"; }
sub TBDB_ALLOCSTATE_RES_REBOOT_CLEAN() { "RES_REBOOT_CLEAN"; }
585
586
sub TBDB_ALLOCSTATE_RES_INIT_DIRTY()   { "RES_INIT_DIRTY"; }
sub TBDB_ALLOCSTATE_RES_INIT_CLEAN()   { "RES_INIT_CLEAN"; }
Chad Barb's avatar
   
Chad Barb committed
587
sub TBDB_ALLOCSTATE_RES_READY()        { "RES_READY"; }
588
sub TBDB_ALLOCSTATE_RES_RECONFIG()     { "RES_RECONFIG"; }
589
sub TBDB_ALLOCSTATE_RES_TEARDOWN()     { "RES_TEARDOWN"; }
Chad Barb's avatar
   
Chad Barb committed
590
591
sub TBDB_ALLOCSTATE_UNKNOWN()          { "UNKNOWN"; };

592
593
sub TBDB_TBCONTROL_RESET	{ "RESET"; }
sub TBDB_TBCONTROL_RELOADDONE	{ "RELOADDONE"; }
594
sub TBDB_TBCONTROL_RELOADDONE_V2{ "RELOADDONEV2"; }
595
sub TBDB_TBCONTROL_TIMEOUT	{ "TIMEOUT"; }
Mac Newbold's avatar
Mac Newbold committed
596
597
598
sub TBDB_TBCONTROL_PXEBOOT	{ "PXEBOOT"; }
sub TBDB_TBCONTROL_BOOTING	{ "BOOTING"; }
sub TBDB_TBCONTROL_CHECKGENISUP	{ "CHECKGENISUP"; }
599
600
601
602

# Constant we use for the timeout field when there is no timeout for a state
sub TBDB_NO_STATE_TIMEOUT	{ 0; }

603
604
605
606
607
608
#
# Node name we use in the widearea_* tables to represent a generic local node.
# All local nodes are considered to have the same network characteristcs.
#
sub TBDB_WIDEAREA_LOCALNODE     { "boss"; }

609
610
611
#
# We should list all of the DB limits.
#
612
sub DBLIMIT_NSFILESIZE()	{ (2**24 - 1); }
613

614
615
616
617
618
619
620
621
622
623
624
#
# Virtual nodes must operate within a restricted port range. The range
# is effective across all virtual nodes in the experiment. When an
# experiment is swapped in, allocate a subrange from this and setup
# all the vnodes to allocate from that range. We tell the user this
# range so this they can set up their programs to operate in that range.
#
sub TBDB_LOWVPORT()		{ 30000; }
sub TBDB_MAXVPORT()		{ 60000; }
sub TBDB_PORTRANGE()		{ 256;   }

625
626
627
628
629
630
631
632
#
# STATS constants.
#
sub TBDB_STATS_PRELOAD()	{ "preload"; }
sub TBDB_STATS_START()		{ "start"; }
sub TBDB_STATS_TERMINATE()	{ "destroy"; }
sub TBDB_STATS_SWAPIN()		{ "swapin"; }
sub TBDB_STATS_SWAPOUT()	{ "swapout"; }
633
sub TBDB_STATS_SWAPMODIFY()	{ "swapmod"; }
634
sub TBDB_STATS_FLAGS_IDLESWAP()	{ 0x01; }
635
sub TBDB_STATS_FLAGS_PREMODIFY(){ 0x02; }
636
sub TBDB_STATS_FLAGS_START()    { 0x04; }
637
sub TBDB_STATS_FLAGS_PRESWAPIN(){ 0x08; }
638
sub TBDB_STATS_FLAGS_BATCHCTRL(){ 0x10; }
639
# Do not export these variables!
640
my $TBDB_STATS_STARTCLOCK;
641
my $TBDB_STATS_SAVEDSWAPUID;
642

643
644
645
646
# Jail.
sub TBDB_JAILIPBASE()		{ "@JAILIPBASE@"; }
sub TBDB_JAILIPMASK()		{ "@JAILIPMASK@"; }

647
648
649
650
# Reserved node "roles"
sub TBDB_RSRVROLE_NODE()	{ "node"; }
sub TBDB_RSRVROLE_VIRTHOST()	{ "virthost"; }
sub TBDB_RSRVROLE_DELAYNODE()	{ "delaynode"; }
651
sub TBDB_RSRVROLE_SIMHOST()	{ "simhost"; }
652

653
654
655
656
657
# Interfaces roles.
sub TBDB_IFACEROLE_CONTROL()	{ "ctrl"; }
sub TBDB_IFACEROLE_EXPERIMENT()	{ "expt"; }
sub TBDB_IFACEROLE_JAIL()	{ "jail"; }
sub TBDB_IFACEROLE_FAKE()	{ "fake"; }
658
sub TBDB_IFACEROLE_GW()		{ "gw"; }
659
sub TBDB_IFACEROLE_OTHER()	{ "other"; }
660
sub TBDB_IFACEROLE_OUTER_CONTROL(){ "outer_ctrl"; }
661

662
663
664
665
666
667
# Routertypes.
sub TBDB_ROUTERTYPE_NONE()	{ "none"; }
sub TBDB_ROUTERTYPE_OSPF()	{ "ospf"; }
sub TBDB_ROUTERTYPE_STATIC()	{ "static"; }
sub TBDB_ROUTERTYPE_MANUAL()	{ "manual"; }

668
# Key Stuff
669
sub TBDB_EVENTKEY($$)	{ TBExptUserDir($_[0],$_[1]) . "/tbdata/eventkey"; }
670
sub TBDB_WEBKEY($$)	{ TBExptUserDir($_[0],$_[1]) . "/tbdata/webkey"; }
671

672
673
674
675
676
# Regex stuff
sub TBDB_CHECKDBSLOT_NOFLAGS()	{ 0x0; }
sub TBDB_CHECKDBSLOT_WARN()	{ 0x1; }
sub TBDB_CHECKDBSLOT_ERROR()	{ 0x2; }

677
678
# Security Levels.
sub TBDB_SECLEVEL_GREEN()	{ 0; }
679
680
681
682
683
684
685
sub TBDB_SECLEVEL_BLUE()	{ 1; }
sub TBDB_SECLEVEL_YELLOW()	{ 2; }
sub TBDB_SECLEVEL_ORANGE()	{ 3; }
sub TBDB_SECLEVEL_RED()		{ 4; }

# This is the level at which we get extremely cautious when swapping out
sub TBDB_SECLEVEL_ZAPDISK()	{ TBDB_SECLEVEL_YELLOW; }
686

687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
#
# A hash of all tables that contain information about physical nodes - the
# value for each key is the list of columns that could contain the node's ID.
#
sub TBDB_PHYSICAL_NODE_TABLES() {
    return (
	'current_reloads'	=> [ 'node_id' ],
	'delays'		=> [ 'node_id' ],
	'iface_counters'	=> [ 'node_id' ],
	'interfaces'		=> [ 'node_id' ],
	'interface_settings'	=> [ 'node_id' ],
	'last_reservation'	=> [ 'node_id' ],
	'linkdelays'		=> [ 'node_id' ],
	'location_info'		=> [ 'node_id' ],
	'next_reserve'		=> [ 'node_id' ],
	'node_activity'		=> [ 'node_id' ],
	'node_auxtypes'		=> [ 'node_id' ],
	'node_features'		=> [ 'node_id' ],
	'node_hostkeys'		=> [ 'node_id' ],
	'node_idlestats'	=> [ 'node_id' ],
	'node_status'   	=> [ 'node_id' ],
	'node_rusage'		=> [ 'node_id' ],
	'nodeipportnum'		=> [ 'node_id' ],
	'nodelog'		=> [ 'node_id' ],
	'nodes'			=> [ 'node_id', 'phys_nodeid' ],
	'nodeuidlastlogin'	=> [ 'node_id' ],
	'ntpinfo'		=> [ 'node_id' ],
	'outlets'		=> [ 'node_id' ],
	'partitions'		=> [ 'node_id' ],
	'plab_slice_nodes'	=> [ 'node_id' ],
	'port_counters'		=> [ 'node_id' ],
	'reserved'		=> [ 'node_id' ],
	'scheduled_reloads'	=> [ 'node_id' ],
	'state_triggers'	=> [ 'node_id' ],
	'switch_stacks'		=> [ 'node_id' ],
	'tiplines'		=> [ 'node_id' ],
	'tmcd_redirect'		=> [ 'node_id' ],
	'tunnels'		=> [ 'node_id' ],
	'uidnodelastlogin'	=> [ 'node_id' ],
	'v2pmap'		=> [ 'node_id' ],
	'veth_interfaces'	=> [ 'node_id' ],
	'widearea_accounts'	=> [ 'node_id' ],
	'widearea_delays'	=> [ 'node_id1', 'node_id2' ],
	'widearea_nodeinfo'	=> [ 'node_id' ],
	'widearea_recent'	=> [ 'node_id1', 'node_id2' ],
	'wires'			=> [ 'node_id1', 'node_id2' ],
733
734
735
	'node_startloc'		=> [ 'node_id' ],
	'node_history'		=> [ 'node_id' ],
	'node_bootlogs'		=> [ 'node_id' ],
736
737
738
    );
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
739
740
741
742
743
744
745
746
747
748
749
750
751
752
#
# Auth stuff.
#

#
# Convert a trust string to the above numeric values.
#
sub TBTrustConvert($)
{
    my($trust_string) = @_;
    my $trust_value = 0;

    #
    # Convert string to value. Perhaps the DB should have done it this way?
Mac Newbold's avatar
Mac Newbold committed
753
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
    if ($trust_string eq "none") {
	$trust_value = PROJMEMBERTRUST_NONE;
    }
    elsif ($trust_string eq "user") {
	$trust_value = PROJMEMBERTRUST_USER;
    }
    elsif ($trust_string eq "local_root") {
	$trust_value = PROJMEMBERTRUST_LOCALROOT;
    }
    elsif ($trust_string eq "group_root") {
	$trust_value = PROJMEMBERTRUST_GROUPROOT;
    }
    elsif ($trust_string eq "project_root") {
	$trust_value = PROJMEMBERTRUST_PROJROOT;
    }
    elsif ($trust_string eq "admin") {
	$trust_value = PROJMEMBERTRUST_ADMIN;
    }
    else {
	    die("*** Invalid trust value $trust_string!");
    }

    return $trust_value;
}

#
# Return true if the given trust string is >= to the minimum required.
# The trust value can be either numeric or a string; if a string its
# first converted to the numeric equiv.
#
sub TBMinTrust($$)
{
    my ($trust_value, $minimum) = @_;

    if ($minimum < PROJMEMBERTRUST_NONE ||
	$minimum > PROJMEMBERTRUST_ADMIN) {
	    die("*** Invalid minimum trust $minimum!");
    }

    #
    # Sleazy? How do you do a typeof in perl?
    #
    if (length($trust_value) != 1) {
	$trust_value = TBTrustConvert($trust_value);
    }
Mac Newbold's avatar
Mac Newbold committed
799

Leigh B. Stoller's avatar
Leigh B. Stoller committed
800
801
802
803
804
805
    return $trust_value >= $minimum;
}

#
# Determine the trust level for a uid/pid/gid. That is, each uid will have
# a different trust level depending on the project/group in question.
Mac Newbold's avatar
Mac Newbold committed
806
807
# Return that trust level as one of the numeric values above.
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
808
809
810
# usage: TBGrpTrust($dbuid, $pid, $gid)
#        returns numeric trust value if a group member.
#        returns PROJMEMBERTRUST_NONE if not a group member.
Mac Newbold's avatar
Mac Newbold committed
811
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
sub TBGrpTrust($$$)
{
    my ($uid, $pid, $gid) = @_;

    #
    # No group, then use the default group.
    #
    if (! $gid) {
	$gid = $pid;
    }

    my $query_result =
	DBQueryFatal("select trust from group_membership ".
		     "where uid='$uid' and pid='$pid' and gid='$gid'");

    #
    # No membership is the same as no trust. True? Maybe an error instead?
    #
    if ($query_result->numrows == 0) {
	return PROJMEMBERTRUST_NONE;
    }

    my @row = $query_result->fetchrow_array();
Mac Newbold's avatar
Mac Newbold committed
835
    my $trust_string = $row[0];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
836
837
838
839
840
841
842
843
844
845
846

    return TBTrustConvert($trust_string);
}

#
# Determine the project trust level for a uid/pid. This is the trust level
# for the default group in the project.
#
# usage: TBProjTrust($dbuid, $pid)
#        returns numeric trust value if a project member.
#        returns PROJMEMBERTRUST_NONE if not a project member.
Mac Newbold's avatar
Mac Newbold committed
847
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
848
849
850
sub TBProjTrust($$)
{
    my ($uid, $pid) = @_;
Mac Newbold's avatar
Mac Newbold committed
851

Leigh B. Stoller's avatar
Leigh B. Stoller committed
852
853
854
    return TBGrpTrust($uid, $pid, $pid);
}

855
#
856
857
# Test admin status. Optional argument is the UID or Name to test. If not
# provided, then test the current UID.
858
#
859
860
861
# XXX Argument is *either* a numeric UID, or a string name.
#
# usage: TBAdmin([int or char* uid]);
862
863
#        returns 1 if an admin type.
#        returns 0 if a mere user.
Mac Newbold's avatar
Mac Newbold committed
864
#
865
866
867
sub TBAdmin(;$)
{
    my($uid) = @_;
868
    my($name);
869

870
871
872
873
    #
    # No one is considered an admin unless they have the magic environment
    # variable set (so that you have to be a bit more explict about wanting
    # admin privs.) Use the withadminprivs script to get this variable set.
874
875
    # Also check with HTTP_ at the front of the name, since this is required
    # to get it through suexec from the web scripts.
876
    #
877
    if (!($ENV{WITH_TB_ADMIN_PRIVS} || $ENV{HTTP_WITH_TB_ADMIN_PRIVS})) {
878
879
880
	return 0;
    }

881
882
883
884
    if (!defined($uid)) {
	$uid = $UID;
    }

885
886
    #
    # Test if numeric. Map to name if it is.
Mac Newbold's avatar
Mac Newbold committed
887
    #
888
889
890
891
892
893
894
    if ($uid =~ /^[0-9]+$/) {
	($name) = getpwuid($uid)
	    or die "$uid not in passwd file\n";
    }
    else {
	$name = $uid;
    }
895
896

    my $query_result =
897
	DBQueryFatal("select admin from users where uid='$name'");
898
899
900
901
902
903
904
905

    my @row = $query_result->fetchrow_array();
    if ($row[0] == 1) {
	return 1;
    }
    return 0;
}

906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
#
# Test whether current user is a member of the emulab-ops project.
# 
sub TBOpsGuy(;$)
{
    my($uid) = @_;
    my($name);

    if (!defined($uid)) {
	$uid = $UID;
    }

    #
    # Test if numeric. Map to name if it is.
    #
    if ($uid =~ /^[0-9]+$/) {
	($name) = getpwuid($uid)
	    or die "$uid not in passwd file\n";
    }
    else {
	$name = $uid;
    }
    return TBMinTrust(TBProjTrust($name, $TBOPSPID), PROJMEMBERTRUST_USER());
}

931
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
932
933
# Project permission checks. The group id (gid) can be undef, in which case
# the pid is used (ie: a default group check is made).
934
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
935
936
937
# Usage: TBProjAccessCheck($uid, $pid, $gid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
938
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
939
sub TBProjAccessCheck($$$$)
940
{
Leigh B. Stoller's avatar
Leigh B. Stoller committed
941
942
    my ($uid, $pid, $gid, $access_type) = @_;
    my $mintrust;
943

Leigh B. Stoller's avatar
Leigh B. Stoller committed
944
945
946
    if ($access_type < TB_PROJECT_MIN ||
	$access_type > TB_PROJECT_MAX) {
	die("*** Invalid access type: $access_type!");
947
948
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
949
950
    #
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
951
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
952
953
    if (TBAdmin($uid)) {
	return 1;
954
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
955
956
957
958
959
960
961
    $uid = MapNumericUID($uid);

    #
    # No group, then use the default group.
    #
    if (! defined($gid)) {
	$gid = $pid;
962
963
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
964
965
966
967
968
969
    if ($access_type == TB_PROJECT_READINFO) {
	$mintrust = PROJMEMBERTRUST_USER;
    }
    elsif ($access_type == TB_PROJECT_CREATEEXPT) {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }
970
971
972
    elsif ($access_type == TB_PROJECT_DELUSER) {
	$mintrust = PROJMEMBERTRUST_PROJROOT;
    }
973
974
975
976
    elsif ($access_type == TB_PROJECT_MAKEGROUP ||
	   $access_type == TB_PROJECT_DELGROUP) {
	$mintrust = PROJMEMBERTRUST_GROUPROOT;
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
977
978
979
980
981
982
983
984
985
986
987
988
989
    else {
	die("*** Unexpected access type: $access_type!");
    }

    return TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust);
}

#
# Experiment permission checks.
#
# Usage: TBExptAccessCheck($uid, $pid, $eid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
990
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
991
992
993
994
995
996
997
998
sub TBExptAccessCheck($$$$)
{
    my ($uid, $pid, $eid, $access_type) = @_;
    my $mintrust;

    if ($access_type < TB_EXPT_MIN ||
	$access_type > TB_EXPT_MAX) {
	die("*** Invalid access type: $access_type!");
999
1000
1001
    }

    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1002
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
1003
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1004
    if (TBAdmin($uid)) {
1005
1006
	return 1;
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1007
    $uid = MapNumericUID($uid);
1008

Leigh B. Stoller's avatar
Leigh B. Stoller committed
1009
    my $query_result =
1010
	DBQueryFatal("SELECT gid,expt_head_uid FROM experiments WHERE ".
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1011
		     "eid='$eid' and pid='$pid'");
Mac Newbold's avatar
Mac Newbold committed
1012

Leigh B. Stoller's avatar
Leigh B. Stoller committed
1013
1014
1015
1016
    if ($query_result->numrows == 0) {
	return 0;
    }
    my @row = $query_result->fetchrow_array();
1017
1018
    my $gid     = $row[0];
    my $creator = $row[1];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1019

1020
1021
1022
    #
    # An experiment may be destroyed by the experiment creator or the
    # project/group leader.
Mac Newbold's avatar
Mac Newbold committed
1023
    #
1024
    if ($access_type == TB_EXPT_READINFO) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1025
1026
1027
1028
1029
1030
	$mintrust = PROJMEMBERTRUST_USER;
    }
    else {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }

1031
1032
1033
1034
1035
1036
1037
    #
    # Either proper permission in the group, or group_root in the project.
    # This lets group_roots muck with other people's experiments, including
    # those in groups they do not belong to.
    #
    return TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust) ||
	TBMinTrust(TBGrpTrust($uid, $pid, $pid), PROJMEMBERTRUST_GROUPROOT);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1038
1039
1040
1041
1042
1043
1044
1045
}

#
# Determine if uid can access a node or list of nodes.
#
# Usage: TBNodeAccessCheck($uid, $access_type, $node_id, ...)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
1046
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1047
1048
1049
1050
1051
1052
1053
1054
1055
1056
sub TBNodeAccessCheck($$@)
{
    my ($uid, $access_type) = (shift, shift);
    my @nodelist = @_;
    my $mintrust;

    if ($access_type < TB_NODEACCESS_MIN ||
	$access_type > TB_NODEACCESS_MAX) {
	die("*** Invalid access type: $access_type!");
    }
1057
1058

    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1059
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
1060
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1061
1062
1063
1064
    if (TBAdmin($uid)) {
	return 1;
    }
    $uid = MapNumericUID($uid);
Mac Newbold's avatar
Mac Newbold committed
1065

Leigh B. Stoller's avatar
Leigh B. Stoller committed
1066
1067
1068
1069
1070
1071
1072
1073
    if ($access_type == TB_NODEACCESS_READINFO) {
	$mintrust = PROJMEMBERTRUST_USER;
    }
    else {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }

    foreach my $node (@nodelist) {
1074
	my $query_result =
1075
	    DBQueryFatal("select e.pid,e.gid from reserved as r ".
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1076
			 "left join experiments as e on ".
1077
1078
			 "     e.pid=r.pid and e.eid=r.eid ".
			 "where r.node_id='$node'");
1079

1080
	if ($query_result->numrows == 0) {
1081
1082
	    return 0;
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1083
	my @row = $query_result->fetchrow_array();
1084
1085
	my $pid = $row[0];
	my $gid = $row[1];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1086

1087
1088
1089
1090
1091
1092
1093
1094
	#
	# Either proper permission in the group, or group_root in the
	# project. This lets group_roots muck with other people's
	# nodes, including those in groups they do not belong to.
	#
	if (! TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust) &&
	    ! TBMinTrust(TBGrpTrust($uid, $pid, $pid),
			 PROJMEMBERTRUST_GROUPROOT)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1095
1096
	    return 0;
	}
1097
1098
1099
1100
1101
    }
    return 1;
}

#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1102
# Access checks for an OSID. Tests for tbadmin.
1103
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1104
1105
1106
# Usage: TBOSIDAccessCheck($uid, $osid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
1107
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1108
sub TBOSIDAccessCheck($$$)
1109
{
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1110
1111
    my ($uid, $osid, $access_type) = @_;
    my $mintrust;
1112

Leigh B. Stoller's avatar
Leigh B. Stoller committed
1113
1114
    if ($access_type < TB_OSID_MIN || $access_type > TB_OSID_MAX) {
	die("*** Invalid access type $access_type!");
1115
1116
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
1117
1118
    #
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
1119
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1120
1121
1122
1123
    if (TBAdmin($uid)) {
	return 1;
    }
    $uid = MapNumericUID($uid);
Leigh B. Stoller's avatar