GeniCM.pm.in 112 KB
Newer Older
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1 2
#!/usr/bin/perl -wT
#
3
# GENIPUBLIC-COPYRIGHT
4
# Copyright (c) 2008-2010 University of Utah and the Flux Group.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
# All rights reserved.
#
package GeniCM;

#
# The server side of the CM interface on remote sites. Also communicates
# with the GMC interface at Geni Central as a client.
#
use strict;
use Exporter;
use vars qw(@ISA @EXPORT);

@ISA    = "Exporter";
@EXPORT = qw ( );

# Must come after package declaration!
use lib '@prefix@/lib';
use GeniDB;
use Genixmlrpc;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
24 25
use GeniResponse;
use GeniTicket;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
26
use GeniCredential;
27
use GeniCertificate;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
28
use GeniSlice;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
29
use GeniAggregate;
30
use GeniAuthority;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
31
use GeniSliver;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
32
use GeniUser;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
33
use GeniRegistry;
34
use GeniUtil;
35
use GeniHRN;
36
use GeniUsage;
37
use libtestbed qw(SENDMAIL);
38
use emutil;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
39
# Hate to import all this crap; need a utility library.
40 41
use libdb qw(TBGetSiteVar EXPTSTATE_SWAPPED EXPTSTATE_ACTIVE TBOPSPID
	     TBDB_NODESTATE_TBFAILED);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
42
use User;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
43
use Node;
44
use Lan;
45
use OSinfo;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
46
use Image;
47
use Interface;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
48 49
use English;
use Data::Dumper;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
50
use XML::Simple;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
51
use Date::Parse;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
52
use POSIX qw(strftime tmpnam);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
53
use Time::Local;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
54
use Experiment;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
55
use VirtExperiment;
56
use Firewall;
57
use Compress::Zlib;
58
use File::Temp qw(tempfile);
59
use MIME::Base64;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
60 61 62 63 64 65 66 67

# Configure variables
my $TB		   = "@prefix@";
my $TBOPS          = "@TBOPSEMAIL@";
my $TBAPPROVAL     = "@TBAPPROVALEMAIL@";
my $TBAUDIT   	   = "@TBAUDITEMAIL@";
my $BOSSNODE       = "@BOSSNODE@";
my $OURDOMAIN      = "@OURDOMAIN@";
68
my $PGENIDOMAIN    = "@PROTOGENI_DOMAIN@";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
69
my $CREATEEXPT     = "$TB/bin/batchexp";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
70
my $ENDEXPT        = "$TB/bin/endexp";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
71
my $NALLOC	   = "$TB/bin/nalloc";
72
my $NFREE	   = "$TB/bin/nfree";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
73
my $AVAIL	   = "$TB/sbin/avail";
74
my $PTOPGEN	   = "$TB/libexec/ptopgen";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
75 76
my $TBSWAP	   = "$TB/bin/tbswap";
my $SWAPEXP	   = "$TB/bin/swapexp";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
77 78
my $PLABSLICE	   = "$TB/sbin/plabslicewrapper";
my $NAMEDSETUP     = "$TB/sbin/named_setup";
79
my $EXPORTS_SETUP  = "$TB/sbin/exports_setup";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
80 81
my $VNODESETUP     = "$TB/sbin/vnode_setup";
my $GENTOPOFILE    = "$TB/libexec/gentopofile";
82
my $TARFILES_SETUP = "$TB/bin/tarfiles_setup";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
83 84 85 86
my $MAPPER         = "$TB/bin/mapper";
my $VTOPGEN        = "$TB/bin/vtopgen";
my $SNMPIT         = "$TB/bin/snmpit";
my $PRERENDER      = "$TB/libexec/vis/prerender";
87
my $XMLLINT	   = "/usr/local/bin/xmllint";
88
my $EMULAB_PEMFILE = "@prefix@/etc/genicm.pem";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
89

90 91 92 93 94 95 96 97 98 99 100 101
my $API_VERSION = 1;

#
# Tell the client what API revision we support.  The correspondence
# between revision numbers and API features is to be specified elsewhere.
# No credentials are required.
#
sub GetVersion()
{
    return GeniResponse->Create( GENIRESPONSE_SUCCESS, $API_VERSION );
}

102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131
# Look up a node by an identifier of unspecified type (perhaps a URN, an
# (obsolete) UUID, or an old-style HRN.  Ultimately, all IDs should be
# URNs and this mess will go away, but for now we try not to make
# any assumptions, because of backward compatibility constraints.
sub LookupNode($)
{
    my ($nodeid) = @_;

    if( GeniHRN::IsValid( $nodeid ) ) {
	# Looks like a URN.
	my ($auth,$t,$id) = GeniHRN::Parse( $nodeid );

	return undef if $auth ne $OURDOMAIN or $t ne "node";

	return Node->Lookup( $id );
    }
 
    #
    # Looks like an old HRN, but we only want the last token for node lookup.
    #
    if ($nodeid =~ /\./) {
	($nodeid) = ($nodeid =~ /\.([-\w]*)$/);

	return Node->Lookup($nodeid);
    }
    
    # Assume it's a UUID, and pass it on as is.
    return Node->Lookup($nodeid);
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
132
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
133
# Respond to a Resolve request. 
Leigh B. Stoller's avatar
Leigh B. Stoller committed
134 135 136 137 138 139
#
sub Resolve($)
{
    my ($argref) = @_;
    my $uuid       = $argref->{'uuid'};
    my $cred       = $argref->{'credential'};
140 141
    my $type       = lc( $argref->{'type'} );
    my $hrn        = $argref->{'hrn'};
Leigh B. Stoller's avatar
Leigh B. Stoller committed
142 143 144 145

    if (! defined($cred)) {
	return GeniResponse->MalformedArgsResponse();
    }
146 147 148 149
    if (defined($uuid) && GeniHRN::IsValid($uuid)) {
	$hrn  = $uuid;
	$uuid = undef;
    }
150 151 152 153 154 155 156 157 158 159 160 161
    if( defined( $hrn ) && GeniHRN::IsValid( $hrn ) ) {
	my ($auth,$t,$id) = GeniHRN::Parse( $hrn );

	return GeniResponse->Create( GENIRESPONSE_ERROR, undef,
				     "Authority mismatch" )
	    if( $auth ne $OURDOMAIN );

	$type = lc( $t );
	
	$hrn = $id;	
    }
    if (! (defined($type) && ($type =~ /^(node)$/))) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
162 163 164
	return GeniResponse->MalformedArgsResponse();
    }
    # Allow lookup by uuid or hrn.
165
    if (! defined($uuid) && !defined( $hrn ) ) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185
	return GeniResponse->MalformedArgsResponse();
    }
    if (defined($uuid) && !($uuid =~ /^[-\w]*$/)) {
	return GeniResponse->MalformedArgsResponse();
    }

    my $credential = GeniCredential->CreateFromSigned($cred);
    if (!defined($credential)) {
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
				    "Could not create GeniCredential object");
    }
    
    #
    # Make sure the credential was issued to the caller, but no special
    # permission required to resolve component resources.
    #
    if ($credential->owner_uuid() ne $ENV{'GENIUUID'}) {
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
				    "This is not your credential!");
    }
186
    if ($type eq "node") {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
187 188 189
	my $node;
	
	if (defined($uuid)) {
190
	    $node= LookupNode($uuid);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
191 192
	}
	else {
193
	    $node= LookupNode($hrn);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
194
	}
195
	if (! defined($node)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
196 197 198
	    return GeniResponse->Create(GENIRESPONSE_SEARCHFAILED,
					undef, "Nothing here by that name");
	}
199 200 201 202 203 204

	my $rspec = GetAdvertisement(0, $node->node_id());
	if (! defined($rspec)) {
	    return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
					"Could not start avail");
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
205 206
	
	# Return a blob.
207
	my $blob = { "hrn"          => "${PGENIDOMAIN}." . $node->node_id(),
Leigh B. Stoller's avatar
Leigh B. Stoller committed
208
		     "uuid"         => $node->uuid(),
209
		     "role"	    => $node->role(),
210
		     "hostname"     => $node->node_id() . ".${OURDOMAIN}",
211 212
		     "physctrl"     => 
			 Interface->LookupControl( $node->phys_nodeid() )->IP(),
213 214
		     "urn"          => GeniHRN::Generate( $OURDOMAIN,
							  "node",
215 216
							  $node->node_id() ),
		     "rspec"        => $rspec
Leigh B. Stoller's avatar
Leigh B. Stoller committed
217 218 219 220 221 222 223
		   };

	return GeniResponse->Create(GENIRESPONSE_SUCCESS, $blob);
    }
    return GeniResponse->Create(GENIRESPONSE_UNSUPPORTED);
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
224 225 226 227 228 229 230
#
# Discover resources on this component, returning a resource availablity spec
#
sub DiscoverResources($)
{
    my ($argref) = @_;
    my $credential = $argref->{'credential'};
231 232
    my $available = $argref->{'available'} || 0;
    my $compress = $argref->{'compress'} || 0;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
233 234 235 236 237 238 239 240
    my $user_uuid  = $ENV{'GENIUSER'};

    $credential = GeniCredential->CreateFromSigned($credential);
    if (!defined($credential)) {
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
				    "Could not create GeniCredential object");
    }
    # The credential owner/slice has to match what was provided.
241
    if ($user_uuid ne $credential->owner_uuid()) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
242 243 244
	return GeniResponse->Create(GENIRESPONSE_FORBIDDEN, undef,
				    "Invalid credentials for operation");
    }
245 246 247 248 249 250 251
    return DiscoverResourcesAux($available, $compress);
}
# Helper function for V2.
sub DiscoverResourcesAux($$)
{
    my ($available, $compress) = @_;
    my $user_uuid  = $ENV{'GENIUSER'};
Leigh B. Stoller's avatar
Leigh B. Stoller committed
252

253 254 255
    # Oh, for $*%(s sake.  Frontier::RPC2 insists on representing a
    # Boolean as its own object type -- which Perl always interprets as
    # true, regardless of the object's value.  Undo all of that silliness.
256 257 258 259 260 261
    if (defined($available) && ref($available) eq 'Frontier::RPC2::Boolean') {
	$available = $available->value;
    }
    if (defined($compress) && ref($compress) eq 'Frontier::RPC2::Boolean') {
	$compress = $compress->value;
    }
262

Leigh B. Stoller's avatar
Leigh B. Stoller committed
263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279
    #
    # A sitevar controls whether external users can get any nodes.
    #
    my $allow_externalusers = 0;
    if (!TBGetSiteVar('protogeni/allow_externalusers', \$allow_externalusers)){
	# Cannot get the value, say no.
	$allow_externalusers = 0;
    }
    if (!$allow_externalusers) {
	my $user = GeniUser->Lookup($user_uuid, 1);
	# No record means the user is remote.
	if (!defined($user) || !$user->IsLocal()) {
	    return GeniResponse->Create(GENIRESPONSE_UNAVAILABLE, undef,
					"External users temporarily denied");
	}
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
280
    #
281
    # Acquire the advertisement from ptopgen and compress it if requested.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
282
    #
283 284
    my $xml = GetAdvertisement($available, undef);
    if (! defined($xml)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
285 286 287 288
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
				    "Could not start avail");
    }

289 290 291 292 293 294
    if( $compress ) {
	my $coder = Frontier::RPC2->new();
	my $base64 = encode_base64( compress( $xml ) );
	$xml = $coder->base64( $base64 );	
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
295 296
    return GeniResponse->Create(GENIRESPONSE_SUCCESS, $xml);
}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
297

298 299 300 301 302 303 304 305
#
# Use ptopgen in xml mode to spit back an xml file. 
#
sub GetAdvertisement($$)
{
    my ($available, $pc) = @_;
    my $xml = undef;

Jonathon Duerig's avatar
Jonathon Duerig committed
306
    my $invocation = "$PTOPGEN -x -g -r -p GeniSlices";
307 308 309 310 311
    $invocation .= " -a" unless $available;
    if (defined($pc)) {
	$invocation .= " -1 $pc";
    }
    if (open(AVAIL, "$invocation |")) {
312
	$xml = "";
313 314 315 316 317 318 319 320
	while (<AVAIL>) {
	    $xml .= $_;
	}
	close(AVAIL);
    }
    return $xml;
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
321
#
322
# Update a ticket with a new rspec.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
323
#
324
sub UpdateTicket($)
Leigh B. Stoller's avatar
Leigh B. Stoller committed
325 326
{
    my ($argref) = @_;
327 328 329 330 331 332 333 334 335 336

    return GetTicket($argref, 1);
}

#
# Respond to a GetTicket request. 
#
sub GetTicket($;$)
{
    my ($argref, $isupdate) = @_;
337
    my $rspecstr   = $argref->{'rspec'};
Leigh B. Stoller's avatar
Leigh B. Stoller committed
338
    my $impotent   = $argref->{'impotent'};
339 340
    my $credstr    = $argref->{'credential'};
    my $tickstr    = $argref->{'ticket'};
341 342 343 344 345 346 347
    my $ticket;

    # Default to no update
    $isupdate = 0
	if (!defined($isupdate));
    $impotent = 0
	if (!defined($impotent));
Leigh B. Stoller's avatar
Leigh B. Stoller committed
348

349
    if (! defined($credstr)) {
350
	return GeniResponse->MalformedArgsResponse();
Leigh B. Stoller's avatar
Leigh B. Stoller committed
351
    }
352
    if (!defined($rspecstr)) {
353 354
	return GeniResponse->MalformedArgsResponse();
    }
355 356 357 358
    if (! ($rspecstr =~ /^[\040-\176\012\015\011]+$/)) {
	return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
				    "Improper characters in rspec");
    }
359
    my $credential = GeniCredential->CreateFromSigned($credstr);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
360 361 362 363
    if (!defined($credential)) {
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
				    "Could not create GeniCredential object");
    }
364 365 366
    #
    # Make sure the credential was issued to the caller.
    #
367
    if ($credential->owner_uuid() ne $ENV{'GENIUUID'}) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
368
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
369
				    "This is not your credential!");
Leigh B. Stoller's avatar
Leigh B. Stoller committed
370
    }
371
    if ($isupdate) {
372
	$ticket = GeniTicket->CreateFromSignedTicket($tickstr);
373 374 375 376 377
	if (!defined($ticket)) {
	    return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
					"Could not create GeniTicket object");
	}
    }
378
    return GetTicketAux($credential,
379
			$rspecstr, $isupdate, $impotent, 0, 1, $ticket);
380
}
381

382
sub GetTicketAux($$$$$$$)
383
{
384 385
    my ($credential, $rspecstr, $isupdate, $impotent, $v2, $level,
	$ticket) = @_;
386
    
387 388 389 390 391 392
    defined($credential) &&
	($credential->HasPrivilege( "pi" ) or
	 $credential->HasPrivilege( "instantiate" ) or
	 $credential->HasPrivilege( "bind" ) or
	 return GeniResponse->Create( GENIRESPONSE_FORBIDDEN, undef,
				      "Insufficient privilege" ));
393
    
394 395
    my $slice_uuid = $credential->target_uuid();
    my $user_uuid  = $credential->owner_uuid();
396
    
Leigh B. Stoller's avatar
Leigh B. Stoller committed
397
    #
398
    # Create slice from the certificate.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
399 400 401
    #
    my $slice = GeniSlice->Lookup($slice_uuid);
    if (!defined($slice)) {
402 403 404 405 406
	if ($isupdate) {
	    print STDERR "Could not locate slice $slice_uuid for Update\n";
	    return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
					"No slice found for UpdateTicket");
	}
407
	$slice = CreateSliceFromCertificate($credential);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
408
	if (!defined($slice)) {
409
	    print STDERR "Could not create $slice_uuid\n";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
410
	    return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
411
					"Could not create slice");
Leigh B. Stoller's avatar
Leigh B. Stoller committed
412
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
413 414
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
415
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
416 417
    # Ditto the user.
    #
418
    my $user = CreateUserFromCertificate($credential->owner_cert());
Leigh B. Stoller's avatar
Leigh B. Stoller committed
419
    if (!defined($user)) {
420 421 422 423 424
	if ($isupdate) {
	    print STDERR "Could not locate $user_uuid for UpdateTicket\n";
	    return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
					"No user found for UpdateTicket");
	}
425
	return GeniResponse->Create(GENIRESPONSE_ERROR);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
426
    }
427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446
    return GetTicketAuxAux($slice, $user, $rspecstr,
			   $isupdate, $impotent, $v2, $level, $ticket);
}
sub GetTicketAuxAux($$$$$$$$)
{
    my ($slice, $user,
	$rspecstr, $isupdate, $impotent, $v2, $level, $ticket) = @_;
    my $response    = undef;
    my $restorevirt = 0;	# Flag to restore virtual state
    my $restorephys = 0;	# Flag to restore physical state

    #
    # We need this below to sign the ticket.
    #
    my $authority = GeniCertificate->LoadFromFile($EMULAB_PEMFILE);
    if (!defined($authority)) {
	print STDERR " Could not get uuid from $EMULAB_PEMFILE\n";
	return GeniResponse->Create(GENIRESPONSE_ERROR);
    }

447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464
    #
    # Run xmllint on the rspec to catch format errors.
    #
    my ($fh, $filename) = tempfile(UNLINK => 0);
    if (!defined($fh)) {
	print STDERR "Could not create temp file for rspec\n";
	return GeniResponse->Create(GENIRESPONSE_ERROR);
    }
    print $fh $rspecstr;
    close($fh);
    my $xmlerrors = `$XMLLINT --noout $filename 2>&1`;
    unlink($filename);
    if ($?) {
	return GeniResponse->Create(GENIRESPONSE_ERROR,
				    $xmlerrors,
				    "rspec is not well formed");
    }

465 466 467 468 469 470 471 472 473
    my $rspec =
	eval { XMLin($rspecstr, KeyAttr => [],
		     ForceArray => ["node", "link", "interface",
				    "interface_ref", "linkendpoints"]) };
    if ($@) {
	print STDERR "XMLin error: $@\n";
	return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
				    "XML error in rspec");
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
474

Leigh B. Stoller's avatar
Leigh B. Stoller committed
475 476 477 478 479 480 481 482 483 484 485 486 487 488
    #
    # A sitevar controls whether external users can get any nodes.
    #
    my $allow_externalusers = 0;
    if (!TBGetSiteVar('protogeni/allow_externalusers', \$allow_externalusers)){
	# Cannot get the value, say no.
	$allow_externalusers = 0;
    }
    if (!$allow_externalusers && !$user->IsLocal()) {
	return GeniResponse->Create(GENIRESPONSE_UNAVAILABLE, undef,
				    "External users temporarily denied");
    }
    
    #
489
    # For now all tickets expire very quickly (minutes), but once the
Leigh B. Stoller's avatar
Leigh B. Stoller committed
490
    # ticket is redeemed, it will expire according to the rspec request.
491 492 493
    # If nothing specified in the rspec, then it will expire when the
    # slice record expires, which was given by the expiration time of the
    # slice credential.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509
    #
    if (exists($rspec->{'valid_until'})) {
	my $expires = $rspec->{'valid_until'};

	if (! ($expires =~ /^[-\w:.\/]+/)) {
	    return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					"Illegal valid_until in rspec");
	}
	# Convert to a localtime.
	my $when = timegm(strptime($expires));
	if (!defined($when)) {
	    return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					"Could not parse valid_until");
	}
	
	#
510
	# Do we need a policy limit?
Leigh B. Stoller's avatar
Leigh B. Stoller committed
511 512
	#
	my $diff = $when - time();
513
	if ($diff < (60 * 5) || $diff > (3600 * 24 * 90)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
514 515 516
	    return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					"valid_until out of range");
	}
517 518 519 520 521 522 523

	#
	# Must be before the slice expires.
	#
	my $slice_expires = $slice->expires();
	if (defined($slice_expires)) {
	    $slice_expires = strptime($slice_expires);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
524
	    if ($when > $slice_expires) {
525 526 527 528
		return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
				    "valid_until is past slice expiration");
	    }
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
529
    }
530 531 532 533 534 535 536

    #
    # Lock the ticket so it cannot be released.
    #
    if (defined($ticket) && $ticket->stored() && $ticket->Lock() != 0) {
	return GeniResponse->BusyResponse("ticket");
    }
537 538 539
    if (defined($ticket)) {
	$ticket->SetSlice($slice);
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
540 541 542 543 544 545
    
    #
    #
    # Lock the slice from further access.
    #
    if ($slice->Lock() != 0) {
546 547 548
	$ticket->UnLock()
	    if (defined($ticket) && $ticket->stored());
	return GeniResponse->BusyResponse("slice");
Leigh B. Stoller's avatar
Leigh B. Stoller committed
549
    }
550 551 552
    # Shutdown slices get nothing.
    if ($slice->shutdown()) {
	$slice->UnLock();
553 554
	$ticket->UnLock()
	    if (defined($ticket) && $ticket->stored());
555 556 557
	return GeniResponse->Create(GENIRESPONSE_FORBIDDEN, undef,
				    "Slice has been shutdown");
    }
558 559 560 561 562 563 564 565
    # Ditto for expired.
    if ($slice->IsExpired()) {
	$slice->UnLock();
	$ticket->UnLock()
	    if (defined($ticket) && $ticket->stored());
	return GeniResponse->Create(GENIRESPONSE_REFUSED, undef,
				    "Slice has expired");
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
566

567
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
568
    # For now, there can be only a single toplevel aggregate per slice.
569
    # The existence of an aggregate means the slice is active here. 
Leigh B. Stoller's avatar
Leigh B. Stoller committed
570
    #
571
    my $aggregate = GeniAggregate->SliceAggregate($slice);
572 573 574 575 576
    if (!$isupdate) {
	if (defined($aggregate)) {
	    $response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
				     "Already have an aggregate for slice");
	    goto bad;
577 578
	}
    }
579 580 581 582 583
    elsif ($v2 && $level && !defined($ticket) && !defined($aggregate)) {
	print STDERR "No aggregate for $slice in version two API\n";
	$response = GeniResponse->Create(GENIRESPONSE_ERROR);
	goto bad;
    }
584 585 586 587 588 589

    #
    # Firewall hack; just a flag in the rspec for now.
    #
    if (exists($rspec->{'needsfirewall'}) && $rspec->{'needsfirewall'}) {
	if ($slice->SetFirewallFlag($rspec->{'needsfirewall'}) != 0) {
590 591
	    $response = GeniResponse->Create(GENIRESPONSE_ERROR);
	    goto bad;
592 593
	}
    }
594 595

    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
596
    # We need this now so we can form a virtual topo.
597
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
598 599 600 601 602 603 604 605
    my $slice_experiment = GeniExperiment($slice);
    if (!defined($slice_experiment)) {
	print STDERR "Could not create new Geni slice experiment!\n";
	$response = GeniResponse->Create(GENIRESPONSE_ERROR);
	goto bad;
    }
    my $pid = $slice_experiment->pid();
    my $eid = $slice_experiment->eid();
606 607 608 609 610 611 612 613 614 615 616

    #
    # Mark the experiment locally as coming from the cooked interface.
    # This changes what tmcd returns to the local nodes.
    #
    if (exists($rspec->{'generated_by'}) &&
	$rspec->{'generated_by'} eq "libvtop") {
	$slice_experiment->Update({"geniflags" =>
				       $Experiment::EXPT_GENIFLAGS_EXPT|
				       $Experiment::EXPT_GENIFLAGS_COOKED});
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
617 618 619 620 621 622 623 624 625 626 627 628 629
    
    #
    # Create a virt topology object. We are going to load this up as we
    # process the rspec.
    #
    my $virtexperiment = VirtExperiment->CreateNew($slice_experiment);
    if (!defined($virtexperiment)) {
	print STDERR "Could not create VirtExperiment object!\n";
	$response = GeniResponse->Create(GENIRESPONSE_ERROR);
	goto bad;
    }
    # Turn off fixnode; we will control this on the commandline.
    $virtexperiment->allowfixnode(0);
630
    $virtexperiment->multiplex_factor(3);
631 632

    # This is where nodes are parked until a ticket is redeemed.
633
    # This experiment no longer has to exist.
634
    my $reserved_holding = Experiment->Lookup("GeniSlices", "reservations");
Leigh B. Stoller's avatar
Leigh B. Stoller committed
635

Leigh B. Stoller's avatar
Leigh B. Stoller committed
636
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
637 638
    # An rspec is a structure that requests specific nodes. If those
    # nodes are available, then reserve it. Otherwise the ticket
Leigh B. Stoller's avatar
Leigh B. Stoller committed
639 640
    # cannot be granted.
    #
641 642 643
    my %namemap  = ();
    my %colomap  = ();
    my %ifacemap = ();
Leigh B. Stoller's avatar
Leigh B. Stoller committed
644
    my %nodemap  = ();
645
    my @nodeids  = ();
646
    my %lannodes = ();
647
    my @dealloc;
648 649 650 651 652 653 654 655

    #
    # If this is a ticket update, we want to seed the namemap with
    # existing nodes. This is cause the rspec might refer to wildcards
    # that were already bound in a previous call. We also want to know
    # what nodes are currently reserved in case we have to release some.
    #
    if ($isupdate) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673
	$slice_experiment->ClearBackupState();
	if ($slice_experiment->BackupVirtualState()) {
	    print STDERR "Could not backup virtual state!\n";
	    $response = GeniResponse->Create(GENIRESPONSE_ERROR);
	    goto bad;
	}
	if ($slice_experiment->RemoveVirtualState()) {
	    print STDERR "Could not remove virtual state!\n";
	    $response = GeniResponse->Create(GENIRESPONSE_ERROR);
	    goto bad;
	}
	$restorevirt = 1;

	if ($slice_experiment->BackupPhysicalState()) {
	    print STDERR "Could not backup physical state!\n";
	    $response = GeniResponse->Create(GENIRESPONSE_ERROR);
	    goto bad;
	}
674 675 676 677 678 679 680
	my $oldrspec;
	if ($v2 && defined($aggregate)) {
	    $oldrspec = $aggregate->GetManifest(0);
	}
	else {
	    $oldrspec = $ticket->rspec();
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
681
	
682
	foreach my $ref (@{$oldrspec->{'node'}}) {
683 684 685 686 687 688
	    my $resource_uuid = $ref->{'component_uuid'} || $ref->{'uuid'};
	    my $manager_uuid  = $ref->{'component_manager_uuid'};
	    my $node_nickname = $ref->{'virtual_id'} || $ref->{'nickname'};
	    my $colocate      = $ref->{'colocate'} || $ref->{'phys_nickname'};

	    # Let remote nodes pass through.
689
	    next
690 691 692
		if (defined($manager_uuid) &&
		    !GeniHRN::Equal( $manager_uuid, $ENV{'MYURN'} ) &&
		    $manager_uuid ne $ENV{'MYUUID'});
693

694 695 696 697 698 699
	    # Skip lan nodes; they are fake.
	    next
		if (exists($ref->{'node_type'}) &&
		    exists($ref->{'node_type'}->{'type_name'}) &&
		    $ref->{'node_type'}->{'type_name'} eq "lan");

700
	    my $node = LookupNode($resource_uuid);
701 702
	    if (!defined($node)) {
		$response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
Leigh B. Stoller's avatar
Leigh B. Stoller committed
703
				 "Bad resource $resource_uuid in ticket");
704 705 706
		goto bad;
	    }

707 708 709 710 711 712
	    #
	    # Grab the reservation. For backwards compatibility, we want
	    # to find nodes in the reservations holding area, and move them
	    # into the slice experiment. The holding area is no longer going
	    # to be used, at least not until we have a reservations system.
	    #
713
	    my $reservation = $node->Reservation();
714
	    if (defined($reservation) &&
715
		defined($reserved_holding) &&
716 717 718 719 720 721
		$reservation->SameExperiment($reserved_holding)) {
		if ($node->MoveReservation($slice_experiment)) {
		    print STDERR "Could not move $node to $slice_experiment\n";
		    goto bad;
		}
		$node->Refresh();
722 723 724 725 726 727
	    }
	    $namemap{$node_nickname} = $node;
	    $colomap{$colocate} = $node
		if (defined($colocate));
	}
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
728

Leigh B. Stoller's avatar
Leigh B. Stoller committed
729 730
    print STDERR Dumper($rspec);

731
    foreach my $ref (@{$rspec->{'node'}}) {
732 733 734 735
	my $resource_uuid = $ref->{'component_uuid'} || $ref->{'uuid'};
	my $manager_uuid  = $ref->{'component_manager_uuid'};
	my $node_nickname = $ref->{'virtual_id'} || $ref->{'nickname'};
	my $colocate      = $ref->{'colocate'} || $ref->{'phys_nickname'};
736
	my $subnode_of    = $ref->{'subnode_of'};
Leigh B. Stoller's avatar
Leigh B. Stoller committed
737 738 739
	my $virtualization_type    = $ref->{'virtualization_type'};
	my $virtualization_subtype = $ref->{'virtualization_subtype'};
	my $exclusive     = $ref->{'exclusive'};
740
	my $pctype;
741
	my $osname;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
742 743
	my $node;

744
	# Let remote nodes pass through.
745
	next
746 747 748
	    if (defined($manager_uuid) &&
		!GeniHRN::Equal( $manager_uuid, $ENV{'MYURN'} ) &&
		$manager_uuid ne $ENV{'MYUUID'});
749

750 751 752 753 754 755 756 757 758 759 760 761
	#
	# Lan nodes are fake and do not go into the virt topo. Need
	# to remember them though, for when we do the links below.
	# They are still in the returned ticket though. 
	#
	if (exists($ref->{'node_type'}) &&
	    exists($ref->{'node_type'}->{'type_name'}) &&
	    $ref->{'node_type'}->{'type_name'} eq "lan") {
	    $lannodes{$node_nickname} = $ref;
	    next;
	}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
762 763 764
	if (defined($virtualization_type)) {
	    if ($virtualization_type eq "emulab-vnode") {
		if (defined($virtualization_subtype)) {
765 766
		    $pctype = "pcvm";
		    
Leigh B. Stoller's avatar
Leigh B. Stoller committed
767 768 769 770 771 772
		    if ($virtualization_subtype eq "emulab-jail") {
			$osname = "FBSD-JAIL";
		    }
		    elsif ($virtualization_subtype eq "emulab-openvz") {
			$osname = "OPENVZ-STD";
		    }
773 774 775 776 777 778 779
		    elsif ($virtualization_subtype eq "emulab-spp") {
			$osname = "SPPVM-FAKE";
			$pctype = "sppvm";
			# Lets force to shared node.
			$ref->{'exclusive'} = $exclusive = 0;
			# Kludge for libvtop.
			$virtexperiment->multiplex_factor(1);
780
			$virtexperiment->encap_style("vlan");
781
		    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
782 783 784 785 786 787 788 789 790 791 792 793 794 795
		}
		else {
		    goto raw;
		}
	    }
	    else {
	      raw:
		# Lets force to exclusive real node.
		$ref->{'exclusive'} = $exclusive = 1;
		$ref->{'virtualization_type'} = "raw";
	    }
	}
	else {
	    $response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
796
				     "Must provide a virtualization_type");
Leigh B. Stoller's avatar
Leigh B. Stoller committed
797 798 799
	    goto bad;

	}
800 801 802 803 804 805
	if (!defined($node_nickname)) {
	    $response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
				     "Must provide a virtual_id for nodes");
	    goto bad;
	}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
806
	#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
807
	# Allow wildcarding.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
808
	#
809 810 811 812 813 814
	if (!defined($resource_uuid) || $resource_uuid eq "*") {
	    if (defined($colocate) && exists($colomap{$colocate})) {
		$node = $colomap{$colocate};
	    }
	    elsif ($isupdate && exists($namemap{$node_nickname})) {
		$node = $namemap{$node_nickname};
815
	    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
816 817
	}
	else {
818
	    $node = LookupNode($resource_uuid);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
819 820 821 822 823 824 825

	    if (!defined($node)) {
		$response =
		    GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					 "Bad resource $resource_uuid");
		goto bad;
	    }
826 827
	    $pctype = $node->type()
		if (!defined($pctype));
828 829
	}
	#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
830
	# If no osname by this point, try for the default.
831 832
	#
	if (defined($node) && !defined($osname)) {
833 834 835 836 837
	    if (defined($node->default_osid())) {	    
		my $osinfo = OSinfo->Lookup($node->default_osid());
		$osname = $osinfo->osname()
		    if (defined($osinfo));
	    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
838
	}
839 840 841
	# The slot does not like to be NULL.
	$osname = ""
	    if (!defined($osname));
842
	
843 844 845
	# Need some kind of default.
	$pctype = "pc"
	    if (!defined($pctype));
846
	
847 848 849 850 851
	my $nodeblob = {"vname"   => $node_nickname,
			"type"    => $pctype,
			"osname"  => $osname,
			"ips"     => '', # deprecated
			"cmd_line"=> '', # bogus
Leigh B. Stoller's avatar
Leigh B. Stoller committed
852 853
			"fixed"   => (defined($subnode_of) ? $subnode_of :
				      defined($node) ? $node->node_id() : ""),
854
			};
855 856

	# Tarball and startup command.
857
	if (exists($ref->{'startup_command'})) {
858 859 860 861 862 863 864 865 866 867 868 869 870 871
	    my $startupcmd = $ref->{'startup_command'};
	    
	    if (! TBcheck_dbslot($startupcmd, "virt_nodes", "startupcmd",
			 TBDB_CHECKDBSLOT_WARN|TBDB_CHECKDBSLOT_ERROR)) {
		$response =
		    GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					 "Invalid startup command");
		goto bad;
	    }
	    $nodeblob->{'startupcmd'} = $startupcmd;
	}
	if (exists($ref->{'tarfiles'})) {
	    my $tarfiles = $ref->{'tarfiles'};
	    
872
	    if (! TBcheck_dbslot($tarfiles, "virt_nodes", "tarfiles",
873 874 875 876 877 878
			 TBDB_CHECKDBSLOT_WARN|TBDB_CHECKDBSLOT_ERROR)) {
		$response =
		    GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					 "Invalid tarfiles");
		goto bad;
	    }
879
	    $nodeblob->{'tarfiles'} = $tarfiles;
880 881 882 883 884 885 886 887
	}

	my $virtnode = $virtexperiment->NewTableRow("virt_nodes", $nodeblob);
	if (!defined($virtnode)) {
	    $response = GeniResponse->Create(GENIRESPONSE_ERROR, undef,
					     "Error creating virtnode");
	    goto bad;
	}
888

Leigh B. Stoller's avatar
Leigh B. Stoller committed
889 890 891 892 893 894 895 896 897 898
	$virtexperiment->NewTableRow("virt_node_desires",
				     {"vname"    => $node_nickname,
				      "desire"   => "pcshared",
				      "weight"   => 0.95})
	    if (!defined($exclusive) || !$exclusive);

	# Store reference so we can munge it below. 
	$nodemap{$node_nickname} = {"rspec"    => $ref,
				    "virtnode" => $virtnode};
	
899 900 901 902
	#
	# Look for interface forward declarations that will be used later
	# in the link specifications. 
	#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
903 904 905
	next
	    if (!exists($ref->{'interface'}));
	
906 907 908 909 910 911 912 913 914 915 916 917 918
	foreach my $linkref (@{$ref->{'interface'}}) {
	    my $component_id = $linkref->{"component_id"};
	    my $virtual_id   = $linkref->{"virtual_id"};

	    if (!defined($virtual_id)) {
		$response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
			     "Must provide a virtual_id for interfaces");
		goto bad;
	    }
	    
	    $ifacemap{$node_nickname} = {}
	        if (!exists($ifacemap{$node_nickname}));

Leigh B. Stoller's avatar
Leigh B. Stoller committed
919 920 921
	    # port counter.
	    my $vport = scalar(keys(%{ $ifacemap{$node_nickname} }));

922
	    # Store reference so we can munge it below. 
Leigh B. Stoller's avatar
Leigh B. Stoller committed
923 924
	    $ifacemap{$node_nickname}->{$virtual_id} = {"rspec" => $linkref,
							"vport" => $vport};
Leigh B. Stoller's avatar
Leigh B. Stoller committed
925

Leigh B. Stoller's avatar
Leigh B. Stoller committed
926 927
	    # This is used after the mapper runs since it uses vname:vport.
	    $ifacemap{"$node_nickname:$vport"} = $linkref;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
928
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
929 930
    }

931 932 933
    goto skiplinks
	if (!exists($rspec->{'link'}));
    
934 935 936 937
    #
    # Now deal with links for wildcarded nodes. We need to fill in the
    # node_uuid.
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
938 939
    my $linknum = 1;
    
940
    foreach my $linkref (@{$rspec->{'link'}}) {
941
	my $lanname    = $linkref->{"nickname"} || $linkref->{"virtual_id"};
Leigh B. Stoller's avatar
Leigh B. Stoller committed
942 943
	my $istunnel   = (exists($linkref->{'link_type'}) &&
			  $linkref->{'link_type'} eq "tunnel");
944 945
	my $interfaces = $linkref->{'linkendpoints'} ||
	    $linkref->{'interface_ref'};
Leigh B. Stoller's avatar
Leigh B. Stoller committed
946
	my $ifacenum   = 1;
947
	my $trivial_ok = 0;
948

949
	if (!defined($lanname)) {
950 951 952 953
	    $response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
				     "Must provide a virtual_id for links");
	    goto bad;
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
954

955 956 957 958 959 960 961
	#
	# Ick. Before we create the virt_lan_lans entry, we have to check
	# inside to see if one of the interfaces is connected to a lan
	# node. In this case, we want to reuse (if its been created) the
	# lan name, rather then a bunch of links with one interface, which
	# would result in a bogus topology. 
	#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
962
	if (!$istunnel) {
963 964 965 966 967 968 969 970 971 972 973 974
	    foreach my $ref (@{ $interfaces }) {
		my $node_nickname = $ref->{'virtual_node_id'} ||
		    $ref->{'node_nickname'};

		if (exists($lannodes{$node_nickname})) {
		    $lanname = $node_nickname;
		}
	    }
	    if (!defined($virtexperiment->Find("virt_lan_lans", $lanname))) {
		$virtexperiment->NewTableRow("virt_lan_lans",
					     {"vname" => $lanname});
	    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
975
	}
976 977 978 979 980 981
	
	foreach my $ref (@{ $interfaces }) {
	    my $node_nickname = $ref->{'virtual_node_id'} ||
		$ref->{'node_nickname'};
	    my $iface_id     = $ref->{'virtual_interface_id'} ||
		$ref->{'iface_name'};
982

983
	    if (!defined($node_nickname)) {
984 985
		$response =
		    GeniResponse->Create(GENIRESPONSE_ERROR, undef,
986
				 "$lanname: Need node id for links");
987 988 989 990 991
		goto bad;
	    }
	    if (!defined($iface_id)) {
		$response =
		    GeniResponse->Create(GENIRESPONSE_ERROR, undef,
992
				 "$lanname: Need interface id for links");
993 994 995
		goto bad;
	    }

996 997 998 999 1000 1001 1002 1003 1004
	    #
	    # Look for links that are really lans; one of the interfaces
	    # is on a fake lan node, which we caught above. Just skip it
	    # since in the virt topo, a lan is just a link with more then
	    # two nodes.
	    #
	    next
		if (exists($lannodes{$node_nickname}));

1005
	    if ($istunnel) {
1006
		# Might be the other side. Skip for now; might bite later.
1007 1008
		next
		    if (!exists($namemap{$node_nickname}));
1009

1010 1011 1012
		# Not doing anything else.
		next;
	    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1013
	    if (!exists($ifacemap{$node_nickname})) {
1014 1015
		$response =
		    GeniResponse->Create(GENIRESPONSE_ERROR, undef,
1016
				 "$lanname: No such virtual_node_id: ".
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1017
				 "$node_nickname");
1018
		goto bad;
1019
	    }
1020
	    
1021
	    #
1022
	    # Sanity check the interface.
1023
	    #
1024 1025 1026
	    if (!exists($ifacemap{$node_nickname}->{$iface_id})) {
		$response =
		    GeniResponse->Create(GENIRESPONSE_ERROR, undef,
1027
				 "$lanname: No such interface on component: ".
1028 1029 1030
				 "$node_nickname:$iface_id");
		goto bad;
	    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1031 1032
	    my $iface_ref   = $ifacemap{$node_nickname}->{$iface_id}->{"rspec"};
	    my $iface_name  = $iface_ref->{"component_id"} || "";
1033
	    if( GeniHRN::IsValid( $iface_name ) ) {
1034 1035
		my ($urn_authority,$urn_node,$urn_iface) =
		    GeniHRN::ParseInterface( $iface_name );
1036 1037
		$iface_name = $urn_iface;
	    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1038 1039 1040 1041 1042 1043
	    my $iface_vport = $ifacemap{$node_nickname}->{$iface_id}->{"vport"};

	    # XXX
	    my $ip     = "10.10.${linknum}.${ifacenum}";
	    my $mask   = "255.255.255.0";
	    my $member = "$node_nickname:$iface_vport";
1044 1045 1046 1047 1048
	    my $bandwidth = 100000;

	    # Let user override.
	    $bandwidth = $linkref->{'bandwidth'}
	        if (exists($linkref->{'bandwidth'}));
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1049 1050
	    
	    $virtexperiment->NewTableRow("virt_lans",
1051
					 {"vname"       => $lanname,
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1052 1053
					  "vnode"       => $node_nickname,
					  "vport"       => $iface_vport,
1054
					  "trivial_ok"  => $trivial_ok,
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1055 1056
					  "ip"          => $ip,
					  "delay"       => 0.0,
1057
					  "bandwidth"   => $bandwidth, # kbps
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1058 1059 1060 1061
					  "lossrate"    => 0.0,
					  "member"      => $member,
					  "mask"        => $mask,
					  "rdelay"      => 0.0,
1062
					  "rbandwidth"  => $bandwidth, # kbps
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1063 1064 1065 1066 1067 1068 1069 1070
					  "rlossrate"   => 0.0,
					  "fixed_iface" => $iface_name});
	    $ifacenum++;
	}
	$linknum++;
    }
  skiplinks:
    $virtexperiment->Dump();
1071 1072 1073