GeniStdSA.pm.in 15.3 KB
Newer Older
Jonathon Duerig's avatar
Jonathon Duerig committed
1 2
#!/usr/bin/perl -wT
#
Leigh B Stoller's avatar
Leigh B Stoller committed
3
# Copyright (c) 2008-2014 University of Utah and the Flux Group.
Jonathon Duerig's avatar
Jonathon Duerig committed
4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29
# 
# {{{GENIPUBLIC-LICENSE
# 
# GENI Public License
# 
# Permission is hereby granted, free of charge, to any person obtaining
# a copy of this software and/or hardware specification (the "Work") to
# deal in the Work without restriction, including without limitation the
# rights to use, copy, modify, merge, publish, distribute, sublicense,
# and/or sell copies of the Work, and to permit persons to whom the Work
# is furnished to do so, subject to the following conditions:
# 
# The above copyright notice and this permission notice shall be
# included in all copies or substantial portions of the Work.
# 
# THE WORK IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
# OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
# HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
# WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
# OUT OF OR IN CONNECTION WITH THE WORK OR THE USE OR OTHER DEALINGS
# IN THE WORK.
# 
# }}}
#
30
package GeniStdSA;
Jonathon Duerig's avatar
Jonathon Duerig committed
31 32 33 34 35 36 37 38 39 40 41 42

#
# The server side of the CM interface on remote sites. Also communicates
# with the GMC interface at Geni Central as a client.
#
use strict;
use Exporter;
use vars qw(@ISA @EXPORT);

@ISA    = "Exporter";
@EXPORT = qw ( );

43
use GeniStd;
Jonathon Duerig's avatar
Jonathon Duerig committed
44
use GeniSA;
45
use GeniSlice;
46 47
use GeniUser;
use User;
Jonathon Duerig's avatar
Jonathon Duerig committed
48 49 50 51
use GeniResponse;
use GeniCredential;
use GeniRegistry;
use emutil;
52
use Data::Dumper;
Jonathon Duerig's avatar
Jonathon Duerig committed
53

54 55
my $coder = Frontier::RPC2->new('use_objects' => 1);

Jonathon Duerig's avatar
Jonathon Duerig committed
56 57 58
sub GetVersion()
{
    my $blob = {
59
	"VERSION" => $coder->string("0.1"),
Leigh B Stoller's avatar
Leigh B Stoller committed
60
	"SERVICES" => ["SLICE", "SLICE_MEMBER"],
61
	"CREDENTIAL_TYPES" => ["SFA"], # => [$coder->string("3")]],
Jonathon Duerig's avatar
Jonathon Duerig committed
62 63 64 65 66
	"ROLES" => ["AUTHORITY", "ADMIN", "MEMBER"]
    };
    return GeniResponse->Create(GENIRESPONSE_SUCCESS, $blob);
}

67
sub CreateSlice($$)
Jonathon Duerig's avatar
Jonathon Duerig committed
68
{
69 70 71 72 73 74 75 76 77 78
    my ($credential_args, $options) = @_;
    if (! defined($credential_args) ||
	! defined($options) ||
	! exists($options->{'fields'}) ||
	! exists($options->{'fields'}->{'SLICE_NAME'}))
    {
	return GeniResponse->MalformedArgsResponse('Requires a list of credentials, an options field, and a SLICE_NAME in the options field');
    }

    my $hrn = $options->{'fields'}->{'SLICE_NAME'};
Jonathon Duerig's avatar
Jonathon Duerig committed
79
    my $args = {
80
	"credentials" => GeniStd::FilterCredentials($credential_args),
81 82
	"hrn" => $hrn,
	"type" => "slice"
Jonathon Duerig's avatar
Jonathon Duerig committed
83
    };
84 85 86
    if (exists($options->{'fields'}->{'SLICE_EXPIRATION'})) {
	$args->{'expiration'} = $options->{'fields'}->{'SLICE_EXPIRATION'};
    }
Jonathon Duerig's avatar
Jonathon Duerig committed
87
    my $response = GeniSA::Register($args);
88 89
    if (GeniResponse::IsError($response)) {
	return $response;
Jonathon Duerig's avatar
Jonathon Duerig committed
90
    }
91 92

    my $sliceCred = GeniCredential->CreateFromSigned(GeniResponse::value($response));
93 94 95 96 97 98
    my $slice = GeniSlice->Lookup($sliceCred->target_urn());
    if (exists($options->{'fields'}->{'SLICE_DESCRIPTION'})) {
	my $description = $options->{'fields'}->{'SLICE_DESCRIPTION'};
	$slice->SetDescription($description);
    }

99 100
    my $blob = {
	"SLICE_URN" => $sliceCred->target_urn(),
101 102
	"SLICE_EXPIRATION" => $sliceCred->expires()
#	,"SLICE_CREDENTIAL" => GeniResponse::value($response)
103 104
    };
    return GeniResponse->Create(GENIRESPONSE_SUCCESS, $blob);
Jonathon Duerig's avatar
Jonathon Duerig committed
105 106 107 108 109 110
}

sub LookupSlices()
{
    my ($credential_args, $options) = @_;

111
    my $credential = GeniStd::CheckCredentials(GeniStd::FilterCredentials($credential_args));
Jonathon Duerig's avatar
Jonathon Duerig committed
112 113 114
    return $credential
	if (GeniResponse::IsResponse($credential));

115
    # TODO: Make sure that slice URN is the same as the credential URN
Jonathon Duerig's avatar
Jonathon Duerig committed
116 117 118 119 120
    $credential->HasPrivilege( "authority" ) or
	$credential->HasPrivilege( "resolve" ) or
	return GeniResponse->Create( GENIRESPONSE_FORBIDDEN, undef,
				     "Insufficient privilege" );

121
    my ($match, $filter) = GeniStd::GetMatchFilter($options);
Jonathon Duerig's avatar
Jonathon Duerig committed
122 123

    my $members = {};
124
    if (defined($match)) {
Jonathon Duerig's avatar
Jonathon Duerig committed
125
	foreach my $key (@{ $match }) {
126
	    my $slice = GeniSlice->Lookup($key);
Jonathon Duerig's avatar
Jonathon Duerig committed
127
	    if (defined($slice)) {
128 129 130 131 132 133 134 135 136
		my $description = '';
		if (defined($slice->description())) {
		    $description = $slice->description();
		}
		my $isExpired = 'False';
		if ($slice->IsExpired()) {
		    $isExpired = 'True';
		}

137 138 139 140 141
		my $completeblob = {
		    "SLICE_URN"         => $slice->urn(),
		    "SLICE_UID"         => $slice->uuid(),
		    "SLICE_CREATION"    => $slice->created(),
		    "SLICE_EXPIRATION"  => $slice->expires(),
142
		    "SLICE_EXPIRED"     => $isExpired,
143
		    "SLICE_NAME"        => $slice->hrn(),
144
		    "SLICE_DESCRIPTION" => $description,
145 146 147 148
		    "SLICE_PROJECT_URN" => "Unimplemented"
		};
		my $blob = GeniStd::FilterFields($completeblob, $filter);
		$members->{$slice->urn()} = $blob;
Jonathon Duerig's avatar
Jonathon Duerig committed
149 150 151 152 153 154 155 156 157
	    }
	}
    }
    return GeniResponse->Create(GENIRESPONSE_SUCCESS, $members);
}

sub UpdateSlice()
{
    my ($slice_urn, $credential_args, $options) = @_;
158 159 160 161 162 163 164 165 166

    # TODO: Make sure that slice URN is the same as the credential URN
    my $slice = GeniSlice->Lookup($slice_urn);
    my $response;
    if (exists($options->{'fields'}->{'SLICE_DESCRIPTION'})) {
	$slice->SetDescription($options->{'fields'}->{'SLICE_DESCRIPTION'});
    }
    if (exists($options->{'fields'}->{'SLICE_EXPIRES'})) {
	my $args = {
167 168
	    "credentials" => GeniStd::FilterCredentials($credential_args),
	    "expiration"  => $options->{'fields'}->{'SLICE_EXPIRES'}
169 170 171 172 173 174 175 176
	};
	$response = GeniSA::RenewSlice($args);
    }

    return $response
	if (GeniResponse::IsError($response));

    return GeniResponse->Create(GENIRESPONSE_SUCCESS, {});
Jonathon Duerig's avatar
Jonathon Duerig committed
177 178 179 180 181
}

sub GetCredentials()
{
    my ($slice_urn, $credential_args, $options) = @_;
182 183 184 185 186 187
    if (! defined($slice_urn) ||
	! defined($credential_args) ||
	! defined($options))
    {
	return GeniResponse->MalformedArgsResponse('Requires a slice urn, a list of credentials, and an options field');
    }
Jonathon Duerig's avatar
Jonathon Duerig committed
188

189 190
    my $credential = GeniSA::GetCredential({
	"urn" => $slice_urn,
191
	"credentials" => GeniStd::FilterCredentials($credential_args) });
Jonathon Duerig's avatar
Jonathon Duerig committed
192
    return $credential
193
	if (GeniResponse::IsError($credential));
Jonathon Duerig's avatar
Jonathon Duerig committed
194 195

    my $blob = {
196 197 198
	"geni_type" => "geni_sfa",
	"geni_version" => $coder->string("3"),
	"geni_value" => $credential->{"value"}
Jonathon Duerig's avatar
Jonathon Duerig committed
199 200 201 202 203 204 205
    };

    return GeniResponse->Create(GENIRESPONSE_SUCCESS, [$blob]);
}

sub ModifySliceMembership()
{
206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232
    my ($slice_urn, $credential_args, $options) = @_;
    if (! defined($slice_urn) ||
	! defined($credential_args) ||
	! defined($options))
    {
	return GeniResponse->MalformedArgsResponse('Requires a slice urn, a list of credentials, and an options field');
    }

    my $adding = $options->{'members_to_add'};
    my $removing = $options->{'members_to_remove'};
    my $changing = $options ->{'members_to_change'};

    if (defined($removing) && scalar(@{ $removing }) > 0) {
	return GeniResponse->Create(GENIRESPONSE_NOT_IMPLEMENTED, undef,
				 "Not implemented: Remove members from slice");
	
    }
    if (defined($changing) && scalar(@{ $changing }) > 0) {
	return GeniResponse->Create(GENIRESPONSE_NOT_IMPLEMENTED, undef,
				   "Not implemented: Change members in slice");
	
    }
    if (! defined($adding)) {
	return GeniResponse->Create(GENIRESPONSE_SUCCESS, 0);
    }

    my $params = {
233
	"credentials" => GeniStd::FilterCredentials($credential_args),
234 235 236 237
    };

    my $i = 0;
    foreach my $current (@{ $adding }) {
Leigh B Stoller's avatar
Leigh B Stoller committed
238 239
	if (exists($current->{'SLICE_MEMBER'})) {
	    $params->{"urn"} = $current->{'SLICE_MEMBER'};
240 241 242 243 244 245 246
	    my $result = GeniSA::BindToSlice($params);
	    if (GeniResponse::IsError($result)) {
		return $result;
	    }
	}
    }
    return GeniResponse->Create(GENIRESPONSE_SUCCESS, 0);
Jonathon Duerig's avatar
Jonathon Duerig committed
247 248 249 250
}

sub LookupSliceMembers()
{
251 252 253 254 255 256 257 258
    my ($slice_urn, $credential_args, $options) = @_;
    if (! defined($slice_urn) ||
	! defined($credential_args) ||
	! defined($options))
    {
	return GeniResponse->MalformedArgsResponse('Requires a slice urn, a list of credentials, and an options field');
    }

259 260
    my ($credential, $speaksfor) =
	GeniStd::CheckCredentials(GeniStd::FilterCredentials($credential_args));
261 262 263 264 265 266 267 268
    return $credential
	if (GeniResponse::IsResponse($credential));

    $credential->HasPrivilege( "pi" ) or
	$credential->HasPrivilege( "bind" ) or
	return GeniResponse->Create( GENIRESPONSE_FORBIDDEN, undef,
				     "Insufficient privilege" );
    
269 270 271
    my $this_user =
	GeniUser->Lookup((defined($speaksfor) ?
			  $speaksfor->target_urn() : $ENV{'GENIURN'}), 1);
272 273 274 275 276
    if (!defined($this_user)) {
	return GeniResponse->Create(GENIRESPONSE_FORBIDDEN, undef,
				    "Who are you? No local record");
    }

277 278 279 280 281
    # TODO: How do we validate slice urn?
#    if ($credential->target_urn() ne $slice_urn) {
#	return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
#				    "Slice URN does not match credential URN");
#    }
282

283
    my $slice = GeniSlice->Lookup($slice_urn);
284 285 286 287 288 289 290 291 292 293 294
    if (!defined($slice)) {
	return GeniResponse->Create(GENIRESPONSE_SEARCHFAILED, undef,
				    "Unknown slice for this credential");
    }

    my $uuids = [];
    my $error = $slice->UserBindings($uuids);
    if ($error != 0) {
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
				    "Failed to lookup member bindings");
    }
295
    push(@{ $uuids }, $this_user->uuid());
296 297 298 299 300 301 302 303 304

    my $result = [];
    foreach my $id (@{ $uuids }) {
	my $user = GeniUser->Lookup($id, 1);
	if (defined($user)) {
	    push(@{ $result }, { 'SLICE_MEMBER' => $user->urn(),
				 'SLICE_ROLE' => 'MEMBER' });
	}
    }
305
    return GeniResponse->Create(GENIRESPONSE_SUCCESS, $result);
Jonathon Duerig's avatar
Jonathon Duerig committed
306 307
}

308
sub LookupSlicesForMember($$$)
Jonathon Duerig's avatar
Jonathon Duerig committed
309
{
310
    my ($member_urn, $credential_args, $options) = @_;
311 312 313 314 315 316 317
    if (! defined($member_urn) ||
	! defined($credential_args) ||
	! defined($options))
    {
	return GeniResponse->MalformedArgsResponse('Requires a member urn, a list of credentials, and an options field');
    }

318 319
    my ($credential, $speaksfor) =
	GeniStd::CheckCredentials(GeniStd::FilterCredentials($credential_args));
320 321 322
    return $credential
	if (GeniResponse::IsResponse($credential));

323 324 325
    my $this_user =
	GeniUser->Lookup((defined($speaksfor) ?
			  $speaksfor->target_urn() : $ENV{'GENIURN'}), 1);
326 327 328 329
    if (!defined($this_user)) {
	return GeniResponse->Create(GENIRESPONSE_FORBIDDEN, undef,
				    "Who are you? No local record");
    }
330 331 332 333
    if ($this_user->urn() ne $member_urn) {
	return GeniResponse->Create(GENIRESPONSE_FORBIDDEN, undef,
		    "You are not allowed to lookup slices for other members");
    }
334 335 336 337 338 339 340

    my $result = [];

    my @created = GeniSlice->LookupByCreator($this_user);
    my @bound = GeniSlice->BoundToUser($this_user);

    addSlicesToMemberList(\@created, $result)
341
	if (@created);
342
    addSlicesToMemberList(\@bound, $result)
343
	if (@bound);
344 345 346 347 348 349 350 351 352 353 354 355 356 357 358

    return GeniResponse->Create(GENIRESPONSE_SUCCESS, $result);
}

sub addSlicesToMemberList($$)
{
    my ($slices, $result) = @_;
    
    foreach my $slice (@{ $slices }) {
	my $blob = {
	    'SLICE_URN' => $slice->urn(),
	    'SLICE_ROLE' => 'MEMBER'
	};
	push(@{ $result }, $blob);
    }
Jonathon Duerig's avatar
Jonathon Duerig committed
359 360
}

361
sub CreateSliverInfo($$$$)
Jonathon Duerig's avatar
Jonathon Duerig committed
362
{
363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378
    my ($credential_args, $options) = @_;
    if (! defined($credential_args) ||
	! defined($options))
    {
	return GeniResponse->MalformedArgsResponse('Requires a list of credentials, and an options field');
    }

    if (! defined($options->{'SLIVER_INFO_SLICE_URN'}) ||
	! defined($options->{'SLIVER_INFO_URN'}) ||
	! defined($options->{'SLIVER_INFO_AGGREGATE_URN'}) ||
	! defined($options->{'SLIVER_INFO_CREATOR_URN'}) ||
	! defined($options->{'SLIVER_INFO_CREATION'}) ||
	! defined($options->{'SLIVER_INFO_EXPIRATION'})) {
	return GeniResponse->MalformedArgsResponse('Required option is missing. Make sure to include SLIVER_INFO_SLICE_URN, SLIVER_INFO_URN, SLIVER_INFO_AGGREGATE_URN, SLIVER_INFO_CREATOR_URN, CREATION, and EXPIRATION');
    }
    my $params = {
379
	'credentials' => GeniStd::FilterCredentials($credential_args),
380 381 382 383 384 385 386 387 388 389 390 391 392 393
	'slice_urn' => $options->{'SLIVER_INFO_SLICE_URN'},
	'creator_urn' => $options->{'SLIVER_INFO_CREATOR_URN'},
	'urn' => $options->{'SLIVER_INFO_URN'},
	'created' => $options->{'SLIVER_INFO_CREATION'},
	'expires' => $options->{'SLIVER_INFO_EXPIRATION'}
    };
    return GeniSA::RegisterSliver($params);
}

sub UpdateSliverInfo($$)
{
    my ($credential_args, $options) = @_;
    return GeniResponse->Create(GENIRESPONSE_NOT_IMPLEMENTED, undef,
				"Update Sliver Info is not implemented");
Jonathon Duerig's avatar
Jonathon Duerig committed
394 395
}

396
sub DeleteSliverInfo()
Jonathon Duerig's avatar
Jonathon Duerig committed
397
{
398 399 400 401 402 403 404 405 406 407
    my ($slice_urn, $aggregate_url, $credential_args, $options) = @_;
    if (! defined($slice_urn) ||
	! defined($aggregate_url) ||
	! defined($credential_args) ||
	! defined($options))
    {
	return GeniResponse->MalformedArgsResponse('Requires a slice urn, an aggregate url, a list of credentials, and an options field');
    }

    my $params = {
408
	'credentials' => GeniStd::FilterCredentials($credential_args),
409 410 411
	'slice_urn' => $slice_urn
    };
    return GeniSA::UnRegisterSliver($params);
Jonathon Duerig's avatar
Jonathon Duerig committed
412 413
}

414
sub LookupSliverInfo($$)
Jonathon Duerig's avatar
Jonathon Duerig committed
415
{
416
    my ($credential_args, $options) = @_;
417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470

    if (! (defined($credential_args) && defined($options))) {
	return
	    GeniResponse->MalformedArgsResponse('Requires a list of '.
					'credentials, and an options field');
    }
    my ($credential, $speaksfor) =
	GeniStd::CheckCredentials(GeniStd::FilterCredentials($credential_args));
    return $credential
	if (GeniResponse::IsResponse($credential));
    return GeniResponse->MalformedArgsResponse()
	if (!defined($credential));

    my $this_user =
	GeniUser->Lookup((defined($speaksfor) ?
			  $speaksfor->target_urn() : $ENV{'GENIURN'}), 1);
    if (!defined($this_user)) {
	return GeniResponse->Create(GENIRESPONSE_FORBIDDEN, undef,
				    "Who are you? No local record");
    }
    my ($match, $filter) = GeniStd::GetMatchFilter($options);
    
    if (! (defined($options->{'match'}) &&
	   defined($options->{'match'}->{'SLIVER_INFO_SLICE_URN'}))) {
	return
	    GeniResponse->MalformedArgsResponse('Required match is missing: '.
						'SLIVER_INFO_SLICE_URN');
    }
    my $slice = GeniSlice->Lookup($options->{'match'}{'SLIVER_INFO_SLICE_URN'});
    return GeniResponse->Create(GENIRESPONSE_SEARCHFAILED)
	if (!defined($slice));
    if ($slice->Lock() != 0) {
	return GeniResponse->BusyResponse("slice");
    }
    my @slivers = GeniSlice::ClientSliver->LookupBySlice($slice);
    my $blob = {};
    foreach my $sliver (@slivers) {
	$blob->{$sliver->urn()} = {
	    'SLIVER_INFO_AGGREGATE_URN' => $sliver->manager_urn(),
	    'SLIVER_INFO_URN'	        => $sliver->urn(),
	    'SLIVER_INFO_SLICE_URN'     => $slice->urn(),
	    'SLIVER_INFO_CREATION'      => $sliver->created(),
	    'SLIVER_INFO_EXPIRATION'    => $sliver->expires()
	};
	my $user = User->Lookup($sliver->creator_idx());
	if (defined($user)) {
	    $user = GeniUser->CreateFromLocal($user);
	}
	if (defined($user)) {
	    $blob->{$sliver->urn()}->{'SLIVER_INFO_CREATOR_URN'} = $user->urn();
	}
    }
    $slice->UnLock();
    return GeniResponse->Create(GENIRESPONSE_SUCCESS, $blob);
Jonathon Duerig's avatar
Jonathon Duerig committed
471 472 473 474
}

sub CreateProject()
{
475 476
    return GeniResponse->Create(GENIRESPONSE_NOT_IMPLEMENTED, undef,
				"Create Project is not implemented");
Jonathon Duerig's avatar
Jonathon Duerig committed
477 478 479 480
}

sub LookupProjects()
{
481 482
    return GeniResponse->Create(GENIRESPONSE_NOT_IMPLEMENTED, undef,
				"Lookup Projects is not implemented");
Jonathon Duerig's avatar
Jonathon Duerig committed
483 484 485 486
}

sub UpdateProject()
{
487 488
    return GeniResponse->Create(GENIRESPONSE_NOT_IMPLEMENTED, undef,
				"Update Project is not implemented");
Jonathon Duerig's avatar
Jonathon Duerig committed
489 490 491 492
}

sub ModifyProjectMembership()
{
493 494
    return GeniResponse->Create(GENIRESPONSE_NOT_IMPLEMENTED, undef,
				"Modify Project is not implemented");
Jonathon Duerig's avatar
Jonathon Duerig committed
495 496 497 498
}

sub LookupProjectMembers()
{
499 500
    return GeniResponse->Create(GENIRESPONSE_NOT_IMPLEMENTED, undef,
				"Lookup Project is not implemented");
Jonathon Duerig's avatar
Jonathon Duerig committed
501 502 503 504
}

sub LookupProjectsForMember()
{
505 506
    return GeniResponse->Create(GENIRESPONSE_NOT_IMPLEMENTED, undef,
			      "Lookup Projects for Member is not implemented");
Jonathon Duerig's avatar
Jonathon Duerig committed
507
}
508 509 510

# _Always_ make sure that this 1 is at the end of the file...
1;