libdb.pm.in 120 KB
Newer Older
1
2
#!/usr/bin/perl -w

Leigh B. Stoller's avatar
Leigh B. Stoller committed
3
4
#
# EMULAB-COPYRIGHT
5
# Copyright (c) 2000-2004 University of Utah and the Flux Group.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
6
7
8
# All rights reserved.
#

9
#
10
11
# A library of useful DB stuff. Mostly things that get done a lot.
# Saves typing.
12
13
14
15
16
#
# XXX: The notion of "uid" is a tad confused. A unix uid is a number,
#      while in the DB a user uid is a string (equiv to unix login).
#      Needs to be cleaned up.
#
17

18
package libdb;
19
use strict;
20
use Exporter;
Mac Newbold's avatar
Mac Newbold committed
21
use vars qw(@ISA @EXPORT);
22
23
@ISA = "Exporter";
@EXPORT =
24
    qw ( NODERELOADING_PID NODERELOADING_EID NODEDEAD_PID NODEDEAD_EID
25
	 OLDRESERVED_PID OLDRESERVED_EID NFREELOCKED_PID NFREELOCKED_EID 
26
27
	 NODEBOOTSTATUS_OKAY NODEBOOTSTATUS_FAILED NODEBOOTSTATUS_UNKNOWN
	 NODESTARTSTATUS_NOSTATUS PROJMEMBERTRUST_NONE PROJMEMBERTRUST_USER
Leigh B. Stoller's avatar
Leigh B. Stoller committed
28
29
30
	 PROJMEMBERTRUST_ROOT PROJMEMBERTRUST_GROUPROOT
	 PROJMEMBERTRUST_PROJROOT

31
	 PROJROOT GROUPROOT USERROOT TBOPSPID 
32
33
	 PLABMOND_PID PLABMOND_EID PLABHOLDING_PID PLABHOLDING_EID

Leigh B. Stoller's avatar
Leigh B. Stoller committed
34
35
36
37
	 TBTrustConvert TBMinTrust TBGrpTrust TBProjTrust

	 TB_NODEACCESS_READINFO TB_NODEACCESS_MODIFYINFO
	 TB_NODEACCESS_LOADIMAGE TB_NODEACCESS_REBOOT
38
39
	 TB_NODEACCESS_POWERCYCLE TB_NODEACCESS_MODIFYVLANS
	 TB_NODEACCESS_MIN TB_NODEACCESS_MAX
Leigh B. Stoller's avatar
Leigh B. Stoller committed
40

41
42
	 NODEFAILMODE_FATAL NODEFAILMODE_NONFATAL NODEFAILMODE_IGNORE

Leigh B. Stoller's avatar
Leigh B. Stoller committed
43
44
45
	 TB_USERINFO_READINFO TB_USERINFO_MODIFYINFO
	 TB_USERINFO_MIN TB_USERINFO_MAX

46
47
	 USERSTATUS_ACTIVE USERSTATUS_FROZEN
	 USERSTATUS_UNAPPROVED USERSTATUS_UNVERIFIED USERSTATUS_NEWUSER
48

49
	 TB_EXPT_READINFO TB_EXPT_MODIFY TB_EXPT_DESTROY TB_EXPT_UPDATE
Leigh B. Stoller's avatar
Leigh B. Stoller committed
50
51
52
53
	 TB_EXPT_MIN TB_EXPT_MAX

	 TB_PROJECT_READINFO TB_PROJECT_MAKEGROUP
	 TB_PROJECT_EDITGROUP TB_PROJECT_DELGROUP
Chad Barb's avatar
   
Chad Barb committed
54
	 TB_PROJECT_GROUPGRABUSERS TB_PROJECT_BESTOWGROUPROOT
Leigh B. Stoller's avatar
Leigh B. Stoller committed
55
56
57
58
59
60
61
62
63
64
65
	 TB_PROJECT_LEADGROUP TB_PROJECT_ADDUSER
	 TB_PROJECT_DELUSER TB_PROJECT_MAKEOSID
	 TB_PROJECT_DELOSID TB_PROJECT_MAKEIMAGEID TB_PROJECT_DELIMAGEID
	 TB_PROJECT_CREATEEXPT TB_PROJECT_MIN TB_PROJECT_MAX

	 TB_OSID_READINFO TB_OSID_CREATE
	 TB_OSID_DESTROY TB_OSID_MIN TB_OSID_MAX

	 TB_IMAGEID_READINFO TB_IMAGEID_MODIFYINFO
	 TB_IMAGEID_CREATE TB_IMAGEID_DESTROY
	 TB_IMAGEID_ACCESS TB_IMAGEID_MIN TB_IMAGEID_MAX
66

Leigh B. Stoller's avatar
Leigh B. Stoller committed
67
	 DBLIMIT_NSFILESIZE NODERELOADPENDING_EID
68

69
	 EXPTSTATE_NEW EXPTSTATE_PRERUN EXPTSTATE_SWAPPED EXPTSTATE_SWAPPING
Leigh B. Stoller's avatar
Leigh B. Stoller committed
70
	 EXPTSTATE_ACTIVATING EXPTSTATE_ACTIVE EXPTSTATE_PANICED
71
72
73
74
75
	 EXPTSTATE_TERMINATING EXPTSTATE_TERMINATED EXPTSTATE_QUEUED
	 EXPTSTATE_MODIFY_PARSE EXPTSTATE_MODIFY_REPARSE EXPTSTATE_MODIFY_RESWAP
	 EXPTSTATE_RESTARTING
	 BATCHSTATE_LOCKED BATCHSTATE_UNLOCKED
	 EXPTCANCEL_CLEAR EXPTCANCEL_TERM EXPTCANCEL_SWAP
76

77
	 TBSetCancelFlag TBGetCancelFlag
Leigh B. Stoller's avatar
Leigh B. Stoller committed
78

Mac Newbold's avatar
Mac Newbold committed
79
	 TB_NODELOGTYPE_MISC TB_NODELOGTYPES TB_DEFAULT_NODELOGTYPE
80
81

	 TB_DEFAULT_RELOADTYPE TB_RELOADTYPE_FRISBEE TB_RELOADTYPE_NETDISK
82

83
84
	 TB_EXPTPRIORITY_LOW TB_EXPTPRIORITY_HIGH

85
	 TB_ASSIGN_TOOFEWNODES TB_OPSPID
86

87
	 TBDB_TBEVENT_NODESTATE TBDB_TBEVENT_NODEOPMODE TBDB_TBEVENT_CONTROL
88
	 TBDB_TBEVENT_COMMAND
Chad Barb's avatar
   
Chad Barb committed
89

90
	 TBDB_NODESTATE_ISUP TBDB_NODESTATE_REBOOTING TBDB_NODESTATE_REBOOTED
91
	 TBDB_NODESTATE_SHUTDOWN TBDB_NODESTATE_BOOTING TBDB_NODESTATE_TBSETUP
92
	 TBDB_NODESTATE_RELOADSETUP TBDB_NODESTATE_RELOADING
93
94
	 TBDB_NODESTATE_RELOADDONE TBDB_NODESTATE_UNKNOWN
	 TBDB_NODESTATE_PXEWAIT TBDB_NODESTATE_PXEWAKEUP
95
	 TBDB_NODESTATE_PXEBOOTING TBDB_NODESTATE_ALWAYSUP
Leigh B. Stoller's avatar
Leigh B. Stoller committed
96
	 TBDB_NODESTATE_MFSSETUP
Chad Barb's avatar
   
Chad Barb committed
97

98
99
	 TBDB_NODEOPMODE_NORMAL TBDB_NODEOPMODE_DELAYING
	 TBDB_NODEOPMODE_UNKNOWNOS TBDB_NODEOPMODE_RELOADING
100
	 TBDB_NODEOPMODE_NORMALv1 TBDB_NODEOPMODE_MINIMAL
101
102
	 TBDB_NODEOPMODE_RELOAD TBDB_NODEOPMODE_RELOADMOTE
	 TBDB_NODEOPMODE_DELAY
103
	 TBDB_NODEOPMODE_BOOTWHAT
104
	 TBDB_NODEOPMODE_ANY
105
	 TBDB_NODEOPMODE_UNKNOWN
Chad Barb's avatar
   
Chad Barb committed
106

107
	 TBDB_COMMAND_REBOOT
108
109
	 TBDB_COMMAND_POWEROFF TBDB_COMMAND_POWERON TBDB_COMMAND_POWERCYCLE

110
111
112
	 TBDB_STATED_TIMEOUT_REBOOT TBDB_STATED_TIMEOUT_NOTIFY
	 TBDB_STATED_TIMEOUT_CMDRETRY

Chad Barb's avatar
   
Chad Barb committed
113
114
115
	 TBDB_ALLOCSTATE_FREE_CLEAN TBDB_ALLOCSTATE_FREE_DIRTY
	 TBDB_ALLOCSTATE_DOWN TBDB_ALLOCSTATE_RELOAD_TO_FREE
	 TBDB_ALLOCSTATE_RELOAD_PENDING TBDB_ALLOCSTATE_RES_RELOAD
Mac Newbold's avatar
Mac Newbold committed
116
117
	 TBDB_ALLOCSTATE_RES_INIT_DIRTY TBDB_ALLOCSTATE_RES_INIT_CLEAN
	 TBDB_ALLOCSTATE_RES_REBOOT_DIRTY TBDB_ALLOCSTATE_RES_REBOOT_CLEAN
Chad Barb's avatar
   
Chad Barb committed
118
	 TBDB_ALLOCSTATE_RES_READY TBDB_ALLOCSTATE_UNKNOWN
119
	 TBDB_ALLOCSTATE_RES_TEARDOWN TBDB_ALLOCSTATE_DEAD
120
	 TBDB_ALLOCSTATE_RES_RECONFIG
Chad Barb's avatar
   
Chad Barb committed
121

122
123
	 TBDB_STATS_PRELOAD TBDB_STATS_START TBDB_STATS_TERMINATE
	 TBDB_STATS_SWAPIN TBDB_STATS_SWAPOUT TBDB_STATS_SWAPMODIFY
124
	 TBDB_STATS_FLAGS_IDLESWAP TBDB_STATS_FLAGS_PREMODIFY
125
	 TBDB_STATS_FLAGS_START
126

127
128
	 TBDB_JAILIPBASE TBDB_JAILIPMASK

129
	 TBDB_RSRVROLE_NODE TBDB_RSRVROLE_VIRTHOST TBDB_RSRVROLE_DELAYNODE
130
	 TBDB_RSRVROLE_SIMHOST
131

132
	 TBDB_EXPT_WORKDIR
133
	 TBSetNodeEventState TBGetNodeEventState
Chad Barb's avatar
   
Chad Barb committed
134
	 TBSetNodeAllocState TBGetNodeAllocState
135
	 TBSetNodeOpMode TBGetNodeOpMode TBSetNodeNextOpMode
136
	 TB_OSID_MBKERNEL TB_OSID_PXEBOOT TB_OSID_FRISBEE
Mac Newbold's avatar
Mac Newbold committed
137
	 TB_OSID_FREEBSD_MFS TB_OSID_FRISBEE_MFS
138
	 TBBootWhat TBNodeStateTimeout
Mac Newbold's avatar
Mac Newbold committed
139
	 TBDB_TBCONTROL_RESET TBDB_TBCONTROL_RELOADDONE
140
	 TBDB_TBCONTROL_TIMEOUT TBDB_NO_STATE_TIMEOUT
Mac Newbold's avatar
Mac Newbold committed
141
142
	 TBDB_TBCONTROL_PXEBOOT TBDB_TBCONTROL_BOOTING
	 TBDB_TBCONTROL_CHECKGENISUP
143

144
145
	 TBDB_LOWVPORT TBDB_MAXVPORT TBDB_PORTRANGE

146
147
	 TBDB_PHYSICAL_NODE_TABLES

Leigh B. Stoller's avatar
Leigh B. Stoller committed
148
149
	 TBAdmin TBProjAccessCheck TBNodeAccessCheck TBOSIDAccessCheck
	 TBImageIDAccessCheck TBExptAccessCheck ExpLeader MarkNodeDown
150
	 SetNodeBootStatus OSFeatureSupported IsShelved NodeidToExp NodeidToExpOldReserved
151
	 UserDBInfo DBQuery DBQueryFatal DBQueryWarn DBWarn DBFatal
152
	 DBQuoteSpecial UNIX2DBUID ExpState SetExpState ProjLeader
153
	 ExpNodes ExpNodesOldReserved DBDateTime DefaultImageID GroupLeader TBGroupUnixInfo
154
	 TBValidNodeLogType TBValidNodeName TBSetNodeLogEntry
155
	 TBSetSchedReload MapNodeOSID TBLockExp TBUnLockExp TBSetExpSwapTime
156
	 TBUnixGroupList TBOSID TBOSMaxConcurrent TBOSCountInstances
157
	 TBResolveNextOSID TBOsidToPid
158
	 TBOSLoadMaxOkay TBImageLoadMaxOkay TBImageID ExpSwapper
159
	 TBdbfork VnameToNodeid TBExpLocked
160
	 TBIsNodeRemote TBExptSetLogFile TBExptClearLogFile TBExptGetLogFile
161
	 TBIsNodeVirtual TBControlNetIP TBPhysNodeID
162
	 TBExptOpenLogFile TBExptCloseLogFile TBExptCreateLogFile
163
	 TBNodeUpdateAccountsByPid TBNodeUpdateAccountsByType
164
	 TBNodeUpdateAccountsByUID
165
	 TBSaveExpLogFiles TBExptWorkDir TBExptUserDir TBExptLogDir
166
	 TBExptDestroy TBIPtoNodeID TBNodeBootReset TBNodeStateWait
167
	 TBLeaderMailList ExpGroup TBExptSetSwapUID TBExptSetThumbNail
168
	 TBNodeAllocCheck TBPlabNodeUsername MarkPhysNodeDown TBExptIsElabInElab
169
	 TBExptFirewall TBNodeFirewall TBSetExptFirewallVlan
170

171
172
	 TBNodeType TBNodeTypeProcInfo

Mac Newbold's avatar
Mac Newbold committed
173
	 TBExptRemoveVirtualState TBExptBackupVirtualState
Chad Barb's avatar
   
Chad Barb committed
174
175
	 TBExptRestoreVirtualState

Mac Newbold's avatar
Mac Newbold committed
176
	 TBExptRemovePhysicalState TBExptBackupPhysicalState
177
	 TBExptRestorePhysicalState TBExptClearBackupState
Chad Barb's avatar
   
Chad Barb committed
178

179
180
	 TBExptPortRange

181
	 TBDB_WIDEAREA_LOCALNODE
Leigh B. Stoller's avatar
Leigh B. Stoller committed
182
	 TBWideareaNodeID TBTipServers
Mac Newbold's avatar
Mac Newbold committed
183

Chad Barb's avatar
   
Chad Barb committed
184
185
	 TBSiteVarExists TBGetSiteVar

186
	 TBActivityReport GatherSwapStats GatherAssignStats
187
	 TBAvailablePCs
188

189
190
	 TBDB_IFACEROLE_CONTROL TBDB_IFACEROLE_EXPERIMENT
	 TBDB_IFACEROLE_JAIL TBDB_IFACEROLE_FAKE TBDB_IFACEROLE_OTHER
191
	 TBDB_IFACEROLE_GW TBDB_IFACEROLE_OUTER_CONTROL
192

193
194
	 TBDB_ROUTERTYPE_NONE	TBDB_ROUTERTYPE_OSPF
	 TBDB_ROUTERTYPE_STATIC TBDB_ROUTERTYPE_MANUAL
195
	 TBDB_EVENTKEY TBDB_WEBKEY
196
197
	 TBDB_CHECKDBSLOT_NOFLAGS TBDB_CHECKDBSLOT_WARN TBDB_CHECKDBSLOT_ERROR
         max min TBcheck_dbslot
Mac Newbold's avatar
Mac Newbold committed
198
	 hash_recurse array_recurse hash_recurse2 array_recurse2
199
	 TBGetUniqueIndex
200
201
202
203

	 TBExptMinMaxNodes TBExptSecurityLevel TBExptIDX
	 TBDB_SECLEVEL_GREEN  TBDB_SECLEVEL_YELLOW
	 TBDB_SECLEVEL_ORANGE TBDB_SECLEVEL_RED
Leigh B. Stoller's avatar
Leigh B. Stoller committed
204
205

	 TBExptSetPanicBit TBExptGetPanicBit TBExptClearPanicBit
206
	 );
207

208
# Must come after package declaration!
209
use lib '@prefix@/lib';
210
use English;
211
use File::Basename;
212
use POSIX qw(strftime);
213
require Mysql;
Mac Newbold's avatar
Mac Newbold committed
214
215
use vars qw($DBQUERY_MAXTRIES $DBCONN_MAXTRIES @EXPORT_OK @virtualTables
	    @physicalTables);
216

217
218
219
# Configure variables
my $TB		= "@prefix@";
my $DBNAME	= "@TBDBNAME@";
220
my $TBOPS       = "@TBOPSEMAIL@";
221
222
my $EVENTSYS    = "@EVENTSYS@";
my $BOSSNODE    = "@BOSSNODE@";
223
my $TESTMODE    = @TESTMODE@;
224
my $TBOPSPID	= "emulab-ops";
225
226
227
228
my $SCRIPTNAME  = "Unknown";
my $PROJROOT    = "/proj";
my $GROUPROOT   = "/groups";
my $USERROOT    = "/users";
229

230
231
232
233
234
if ($EVENTSYS) {
    require event;
    import event;
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
235
236
237
# Untainted scriptname for email below.
if ($PROGRAM_NAME =~ /^([-\w\.\/]+)$/) {
    $SCRIPTNAME = basename($1);
238
239
}
else {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
240
    $SCRIPTNAME = "Tainted";
241
242
}

243
#
244
# Set up for querying the database. Note that fork causes a reconnect
Mac Newbold's avatar
Mac Newbold committed
245
# to the DB in the child.
246
247
#
my $DB;
248
249
250
$DBQUERY_MAXTRIES = 1;
$DBCONN_MAXTRIES  = 5;
@EXPORT_OK        = qw($DBQUERY_MAXTRIES $DBCONN_MAXTRIES);
251
252
253

sub TBDBConnect()
{
254
    my $maxtries = $DBCONN_MAXTRIES;
255
256
257
258
259
260
261
262
263

    #
    # Construct a 'username' from the name of this script and the user who
    # ran it. This is for accounting purposes.
    #
    my $name = getpwuid($UID);
    if (!$name) {
	$name = "uid$UID";
    }
264
    my $dbuser = "$SCRIPTNAME:$name:$PID";
265

266
    while ($maxtries) {
267
	$DB = Mysql->connect("localhost", $DBNAME, $dbuser, "none");
268
269
270
	if (defined($DB)) {
	    last;
	}
271
272
273
274
275
276
	$maxtries--;
	sleep(1);
    }
    if (!defined($DB)) {
	die("Cannot connect to DB after several attempts!\n");
    }
277
278
    $DB->{'dbh'}->{'PrintError'} = 0;
    $Mysql::QUIET = 1;
279
280
}
TBDBConnect();
281

282
283
sub TBdbfork()
{
284
    select(undef, undef, undef, 0.3);
285
    undef($DB);
286
    TBDBConnect();
287
288
289
    if ($EVENTSYS) {
	EventFork();
    }
290
291
}

292
293
294
295
296
#
# Record last DB error string.
#
my $DBErrorString = "";

297
298
299
300
#
# Needs to be config'ed.
#
sub TBDB_EXPT_WORKDIR()		{ "/usr/testbed/expwork"; }
Mac Newbold's avatar
Mac Newbold committed
301

302
303
304
305
306
#
# Define exported "constants". Basically, these are just perl subroutines
# that look like constants cause you do not need to call a perl subroutine
# with parens. That is, FOO and FOO() are the same thing.
#
307
sub NODERELOADING_PID()		{ $TBOPSPID; }
308
sub NODERELOADING_EID()		{ "reloading"; }
309
sub NODERELOADPENDING_EID()	{ "reloadpending"; }
310
sub NODEDEAD_PID()		{ $TBOPSPID; }
311
sub NODEDEAD_EID()		{ "hwdown"; }
312
313
314
315
sub PLABMOND_PID()		{ $TBOPSPID; }
sub PLABMOND_EID()		{ "plab-monitor"; }
sub PLABHOLDING_PID()		{ $TBOPSPID; }
sub PLABHOLDING_EID()		{ "plabnodes"; }
316
317
sub OLDRESERVED_PID()		{ $TBOPSPID; }
sub OLDRESERVED_EID()		{ "oldreserved"; }
318
319
sub NFREELOCKED_PID()		{ $TBOPSPID; }
sub NFREELOCKED_EID()		{ "nfree-locked"; }
320
321
322
sub PROJROOT()			{ $PROJROOT; }
sub GROUPROOT()			{ $GROUPROOT; }
sub USERROOT()			{ $USERROOT; }
Robert Ricci's avatar
Robert Ricci committed
323
sub TBOPSPID()			{ $TBOPSPID; }
324
325
326
327
328
329

sub NODEBOOTSTATUS_OKAY()	{ "okay" ; }
sub NODEBOOTSTATUS_FAILED()	{ "failed"; }
sub NODEBOOTSTATUS_UNKNOWN()	{ "unknown"; }
sub NODESTARTSTATUS_NOSTATUS()	{ "none"; }

330
331
332
333
sub NODEFAILMODE_FATAL()	{ "fatal"; }
sub NODEFAILMODE_NONFATAL()	{ "nonfatal"; }
sub NODEFAILMODE_IGNORE()	{ "ignore"; }

334
# Experiment states
335
336
337
sub EXPTSTATE_NEW()		{ "new"; }
sub EXPTSTATE_PRERUN()		{ "prerunning"; }
sub EXPTSTATE_SWAPPED()		{ "swapped"; }
338
sub EXPTSTATE_QUEUED()		{ "queued"; }
339
340
341
sub EXPTSTATE_SWAPPING()	{ "swapping"; }
sub EXPTSTATE_ACTIVATING()	{ "activating"; }
sub EXPTSTATE_ACTIVE()		{ "active"; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
342
sub EXPTSTATE_PANICED()		{ "paniced"; }
343
344
sub EXPTSTATE_TERMINATING()	{ "terminating"; }
sub EXPTSTATE_TERMINATED()	{ "ended"; }
345
346
347
348
349
350
351
sub EXPTSTATE_MODIFY_PARSE()	{ "modify_parse"; }
sub EXPTSTATE_MODIFY_REPARSE()	{ "modify_reparse"; }
sub EXPTSTATE_MODIFY_RESWAP()	{ "modify_reswap"; }
sub EXPTSTATE_RESTARTING()	{ "restarting"; }
# For the batch_daemon.
sub BATCHSTATE_LOCKED()		{ "locked";}
sub BATCHSTATE_UNLOCKED()	{ "unlocked";}
352

353
# Cancel flags
354
355
356
sub EXPTCANCEL_CLEAR()		{ 0 ;}
sub EXPTCANCEL_TERM()		{ 1 ;}
sub EXPTCANCEL_SWAP()		{ 2 ;}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
357

358
359
sub USERSTATUS_ACTIVE()		{ "active"; }
sub USERSTATUS_FROZEN()		{ "frozen"; }
360
361
362
sub USERSTATUS_UNAPPROVED()	{ "unapproved"; }
sub USERSTATUS_UNVERIFIED()	{ "unverified"; }
sub USERSTATUS_NEWUSER()	{ "newuser"; }
363

364
365
366
#
# We want valid project membership to be non-zero for easy membership
# testing. Specific trust levels are encoded thusly.
Mac Newbold's avatar
Mac Newbold committed
367
#
368
369
sub PROJMEMBERTRUST_NONE()	{ 0; }
sub PROJMEMBERTRUST_USER()	{ 1; }
370
sub PROJMEMBERTRUST_ROOT()	{ 2; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
371
372
373
374
375
376
377
sub PROJMEMBERTRUST_LOCALROOT()	{ 2; }
sub PROJMEMBERTRUST_GROUPROOT()	{ 3; }
sub PROJMEMBERTRUST_PROJROOT()	{ 4; }
sub PROJMEMBERTRUST_ADMIN()	{ 5; }

#
# Access types. Duplicated in the web interface. Make changes there too!
Mac Newbold's avatar
Mac Newbold committed
378
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
379
380
381
382
383
384
# Things you can do to a node.
sub TB_NODEACCESS_READINFO()	{ 1; }
sub TB_NODEACCESS_MODIFYINFO()	{ 2; }
sub TB_NODEACCESS_LOADIMAGE()	{ 3; }
sub TB_NODEACCESS_REBOOT()	{ 4; }
sub TB_NODEACCESS_POWERCYCLE()	{ 5; }
385
sub TB_NODEACCESS_MODIFYVLANS()	{ 6; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
386
sub TB_NODEACCESS_MIN()		{ TB_NODEACCESS_READINFO; }
387
sub TB_NODEACCESS_MAX()		{ TB_NODEACCESS_MODIFYVLANS; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
388
389
390
391
392
393
394

# User Info (modinfo web page, etc).
sub TB_USERINFO_READINFO()	{ 1; }
sub TB_USERINFO_MODIFYINFO()	{ 2; }
sub TB_USERINFO_MIN()		{ TB_USERINFO_READINFO; }
sub TB_USERINFO_MAX()		{ TB_USERINFO_MODIFYINFO; }

395
# Experiments.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
396
397
398
sub TB_EXPT_READINFO()		{ 1; }
sub TB_EXPT_MODIFY()		{ 2; }
sub TB_EXPT_DESTROY()		{ 3; }
399
sub TB_EXPT_UPDATE()		{ 4; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
400
sub TB_EXPT_MIN()		{ TB_EXPT_READINFO; }
401
sub TB_EXPT_MAX()		{ TB_EXPT_UPDATE; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
402
403
404
405
406

# Projects.
sub TB_PROJECT_READINFO()	{ 1; }
sub TB_PROJECT_MAKEGROUP()	{ 2; }
sub TB_PROJECT_EDITGROUP()	{ 3; }
Chad Barb's avatar
   
Chad Barb committed
407
sub TB_PROJECT_GROUPGRABUSERS() { 4; }
Chad Barb's avatar
   
Chad Barb committed
408
409
410
411
412
413
414
415
416
417
sub TB_PROJECT_BESTOWGROUPROOT(){ 5; }
sub TB_PROJECT_DELGROUP()	{ 6; }
sub TB_PROJECT_LEADGROUP()	{ 7; }
sub TB_PROJECT_ADDUSER()	{ 8; }
sub TB_PROJECT_DELUSER()	{ 9; }
sub TB_PROJECT_MAKEOSID()	{ 10; }
sub TB_PROJECT_DELOSID()	{ 11; }
sub TB_PROJECT_MAKEIMAGEID()	{ 12; }
sub TB_PROJECT_DELIMAGEID()	{ 13; }
sub TB_PROJECT_CREATEEXPT()	{ 14; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
418
419
420
sub TB_PROJECT_MIN()		{ TB_PROJECT_READINFO; }
sub TB_PROJECT_MAX()		{ TB_PROJECT_CREATEEXPT; }

Mac Newbold's avatar
Mac Newbold committed
421
# OSIDs
Leigh B. Stoller's avatar
Leigh B. Stoller committed
422
423
424
425
426
427
sub TB_OSID_READINFO()		{ 1; }
sub TB_OSID_CREATE()		{ 2; }
sub TB_OSID_DESTROY()		{ 3; }
sub TB_OSID_MIN()		{ TB_OSID_READINFO; }
sub TB_OSID_MAX()		{ TB_OSID_DESTROY; }

428
429
430
# Magic OSID constants
sub TB_OSID_MBKERNEL()          { "_KERNEL_"; } # multiboot kernel OSID
sub TB_OSID_PXEBOOT()           { "PXEBOOT"; } # osid for def pxe_boot_path
431
432
433
434
435
sub TB_OSID_FRISBEE()           { "PXEFRISBEE"; }

# Magic MFS constants
sub TB_OSID_FREEBSD_MFS()	{ "FREEBSD-MFS" };
sub TB_OSID_FRISBEE_MFS()	{ "FRISBEE-MFS" };
436

Leigh B. Stoller's avatar
Leigh B. Stoller committed
437
# ImageIDs
438
439
440
441
442
#
# Clarification:
# READINFO is read-only access to the image and its contents
# (This is what people get for shared images)
# ACCESS means complete power over the image and its [meta]data
Leigh B. Stoller's avatar
Leigh B. Stoller committed
443
444
445
446
447
448
449
sub TB_IMAGEID_READINFO()	{ 1; }
sub TB_IMAGEID_MODIFYINFO()	{ 2; }
sub TB_IMAGEID_CREATE()		{ 3; }
sub TB_IMAGEID_DESTROY()	{ 4; }
sub TB_IMAGEID_ACCESS()		{ 5; }
sub TB_IMAGEID_MIN()		{ TB_IMAGEID_READINFO; }
sub TB_IMAGEID_MAX()		{ TB_IMAGEID_ACCESS; }
450

451
# Node Log Types
452
453
454
455
456
457
458
sub TB_NODELOGTYPE_MISC		{ "misc"; }
sub TB_NODELOGTYPES()		{ ( TB_NODELOGTYPE_MISC ) ; }
sub TB_DEFAULT_NODELOGTYPE()	{ TB_NODELOGTYPE_MISC; }

# Reload Types.
sub TB_RELOADTYPE_NETDISK()	{ "netdisk"; }
sub TB_RELOADTYPE_FRISBEE()	{ "frisbee"; }
459
sub TB_DEFAULT_RELOADTYPE()	{ TB_RELOADTYPE_FRISBEE; }
460

461
462
463
464
465
466
467
# Experiment priorities.
sub TB_EXPTPRIORITY_LOW()	{ 0; }
sub TB_EXPTPRIORITY_HIGH()	{ 20; }

# Assign exit status for too few nodes.
sub TB_ASSIGN_TOOFEWNODES()	{ 2; }

468
469
470
# System PID.
sub TB_OPSPID()			{ $TBOPSPID; }

471
#
472
473
474
475
# Events we may want to send
#
sub TBDB_TBEVENT_NODESTATE	{ "TBNODESTATE"; }
sub TBDB_TBEVENT_NODEOPMODE	{ "TBNODEOPMODE"; }
476
sub TBDB_TBEVENT_CONTROL	{ "TBCONTROL"; }
477
sub TBDB_TBEVENT_COMMAND	{ "TBCOMMAND"; }
478
sub TBDB_TBEVENT_EXPTSTATE	{ "TBEXPTSTATE"; }
479
480
481
482

#
# For nodes, we use this set of events.
#
483
sub TBDB_NODESTATE_ISUP()	{ "ISUP"; }
484
sub TBDB_NODESTATE_ALWAYSUP()	{ "ALWAYSUP"; }
485
486
487
488
489
sub TBDB_NODESTATE_REBOOTED()	{ "REBOOTED"; }
sub TBDB_NODESTATE_REBOOTING()	{ "REBOOTING"; }
sub TBDB_NODESTATE_SHUTDOWN()	{ "SHUTDOWN"; }
sub TBDB_NODESTATE_BOOTING()	{ "BOOTING"; }
sub TBDB_NODESTATE_TBSETUP()	{ "TBSETUP"; }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
490
491
sub TBDB_NODESTATE_RELOADSETUP(){ "RELOADSETUP"; }
sub TBDB_NODESTATE_MFSSETUP()   { "MFSSETUP"; }
492
493
494
sub TBDB_NODESTATE_RELOADING()	{ "RELOADING"; }
sub TBDB_NODESTATE_RELOADDONE()	{ "RELOADDONE"; }
sub TBDB_NODESTATE_UNKNOWN()	{ "UNKNOWN"; };
495
sub TBDB_NODESTATE_PXEWAIT()	{ "PXEWAIT"; }
496
497
sub TBDB_NODESTATE_PXEWAKEUP()	{ "PXEWAKEUP"; }
sub TBDB_NODESTATE_PXEBOOTING()	{ "PXEBOOTING"; }
498

499
sub TBDB_NODEOPMODE_ANY		{ "*"; } # A wildcard opmode
500
501
502
503
sub TBDB_NODEOPMODE_NORMAL	{ "NORMAL"; }
sub TBDB_NODEOPMODE_DELAYING	{ "DELAYING"; }
sub TBDB_NODEOPMODE_UNKNOWNOS	{ "UNKNOWNOS"; }
sub TBDB_NODEOPMODE_RELOADING	{ "RELOADING"; }
504
505
506
sub TBDB_NODEOPMODE_NORMALv1	{ "NORMALv1"; }
sub TBDB_NODEOPMODE_MINIMAL	{ "MINIMAL"; }
sub TBDB_NODEOPMODE_RELOAD	{ "RELOAD"; }
507
sub TBDB_NODEOPMODE_RELOADMOTE	{ "RELOAD-MOTE"; }
508
sub TBDB_NODEOPMODE_DELAY	{ "DELAY"; }
509
sub TBDB_NODEOPMODE_BOOTWHAT	{ "_BOOTWHAT_"; } # A redirection opmode
510
511
sub TBDB_NODEOPMODE_UNKNOWN	{ "UNKNOWN"; }

512
513
514
515
516
sub TBDB_COMMAND_REBOOT         { "REBOOT"; }
sub TBDB_COMMAND_POWEROFF       { "POWEROFF"; }
sub TBDB_COMMAND_POWERON        { "POWERON"; }
sub TBDB_COMMAND_POWERCYCLE     { "POWERCYCLE"; }

517
518
519
520
sub TBDB_STATED_TIMEOUT_REBOOT  { "REBOOT"; }
sub TBDB_STATED_TIMEOUT_NOTIFY  { "NOTIFY"; }
sub TBDB_STATED_TIMEOUT_CMDRETRY{ "CMDRETRY"; }

Chad Barb's avatar
   
Chad Barb committed
521
522
523
sub TBDB_ALLOCSTATE_FREE_CLEAN()       { "FREE_CLEAN"; }
sub TBDB_ALLOCSTATE_FREE_DIRTY()       { "FREE_DIRTY"; }
sub TBDB_ALLOCSTATE_DOWN()             { "DOWN"; }
524
sub TBDB_ALLOCSTATE_DEAD()             { "DEAD"; }
Chad Barb's avatar
   
Chad Barb committed
525
526
527
sub TBDB_ALLOCSTATE_RELOAD_TO_FREE()   { "RELOAD_TO_FREE"; }
sub TBDB_ALLOCSTATE_RELOAD_PENDING()   { "RELOAD_PENDING"; }
sub TBDB_ALLOCSTATE_RES_RELOAD()       { "RES_RELOAD"; }
Chad Barb's avatar
   
Chad Barb committed
528
529
sub TBDB_ALLOCSTATE_RES_REBOOT_DIRTY() { "RES_REBOOT_DIRTY"; }
sub TBDB_ALLOCSTATE_RES_REBOOT_CLEAN() { "RES_REBOOT_CLEAN"; }
530
531
sub TBDB_ALLOCSTATE_RES_INIT_DIRTY()   { "RES_INIT_DIRTY"; }
sub TBDB_ALLOCSTATE_RES_INIT_CLEAN()   { "RES_INIT_CLEAN"; }
Chad Barb's avatar
   
Chad Barb committed
532
sub TBDB_ALLOCSTATE_RES_READY()        { "RES_READY"; }
533
sub TBDB_ALLOCSTATE_RES_RECONFIG()     { "RES_RECONFIG"; }
534
sub TBDB_ALLOCSTATE_RES_TEARDOWN()     { "RES_TEARDOWN"; }
Chad Barb's avatar
   
Chad Barb committed
535
536
sub TBDB_ALLOCSTATE_UNKNOWN()          { "UNKNOWN"; };

537
538
539
sub TBDB_TBCONTROL_RESET	{ "RESET"; }
sub TBDB_TBCONTROL_RELOADDONE	{ "RELOADDONE"; }
sub TBDB_TBCONTROL_TIMEOUT	{ "TIMEOUT"; }
Mac Newbold's avatar
Mac Newbold committed
540
541
542
sub TBDB_TBCONTROL_PXEBOOT	{ "PXEBOOT"; }
sub TBDB_TBCONTROL_BOOTING	{ "BOOTING"; }
sub TBDB_TBCONTROL_CHECKGENISUP	{ "CHECKGENISUP"; }
543
544
545
546

# Constant we use for the timeout field when there is no timeout for a state
sub TBDB_NO_STATE_TIMEOUT	{ 0; }

547
548
549
550
551
552
#
# Node name we use in the widearea_* tables to represent a generic local node.
# All local nodes are considered to have the same network characteristcs.
#
sub TBDB_WIDEAREA_LOCALNODE     { "boss"; }

553
554
555
#
# We should list all of the DB limits.
#
556
sub DBLIMIT_NSFILESIZE()	{ (2**24 - 1); }
557

558
559
560
561
562
563
564
565
566
567
568
#
# Virtual nodes must operate within a restricted port range. The range
# is effective across all virtual nodes in the experiment. When an
# experiment is swapped in, allocate a subrange from this and setup
# all the vnodes to allocate from that range. We tell the user this
# range so this they can set up their programs to operate in that range.
#
sub TBDB_LOWVPORT()		{ 30000; }
sub TBDB_MAXVPORT()		{ 60000; }
sub TBDB_PORTRANGE()		{ 256;   }

569
570
571
572
573
574
575
576
#
# STATS constants.
#
sub TBDB_STATS_PRELOAD()	{ "preload"; }
sub TBDB_STATS_START()		{ "start"; }
sub TBDB_STATS_TERMINATE()	{ "destroy"; }
sub TBDB_STATS_SWAPIN()		{ "swapin"; }
sub TBDB_STATS_SWAPOUT()	{ "swapout"; }
577
sub TBDB_STATS_SWAPMODIFY()	{ "swapmod"; }
578
sub TBDB_STATS_FLAGS_IDLESWAP()	{ 0x01; }
579
sub TBDB_STATS_FLAGS_PREMODIFY(){ 0x02; }
580
581
582
sub TBDB_STATS_FLAGS_START()    { 0x04; }
# Do not export this variable!
my $TBDB_STATS_STARTCLOCK;
583

584
585
586
587
# Jail.
sub TBDB_JAILIPBASE()		{ "@JAILIPBASE@"; }
sub TBDB_JAILIPMASK()		{ "@JAILIPMASK@"; }

588
589
590
591
# Reserved node "roles"
sub TBDB_RSRVROLE_NODE()	{ "node"; }
sub TBDB_RSRVROLE_VIRTHOST()	{ "virthost"; }
sub TBDB_RSRVROLE_DELAYNODE()	{ "delaynode"; }
592
sub TBDB_RSRVROLE_SIMHOST()	{ "simhost"; }
593

594
595
596
597
598
# Interfaces roles.
sub TBDB_IFACEROLE_CONTROL()	{ "ctrl"; }
sub TBDB_IFACEROLE_EXPERIMENT()	{ "expt"; }
sub TBDB_IFACEROLE_JAIL()	{ "jail"; }
sub TBDB_IFACEROLE_FAKE()	{ "fake"; }
599
sub TBDB_IFACEROLE_GW()		{ "gw"; }
600
sub TBDB_IFACEROLE_OTHER()	{ "other"; }
601
sub TBDB_IFACEROLE_OUTER_CONTROL(){ "outer_ctrl"; }
602

603
604
605
606
607
608
# Routertypes.
sub TBDB_ROUTERTYPE_NONE()	{ "none"; }
sub TBDB_ROUTERTYPE_OSPF()	{ "ospf"; }
sub TBDB_ROUTERTYPE_STATIC()	{ "static"; }
sub TBDB_ROUTERTYPE_MANUAL()	{ "manual"; }

609
# Key Stuff
610
sub TBDB_EVENTKEY($$)	{ TBExptUserDir($_[0],$_[1]) . "/tbdata/eventkey"; }
611
sub TBDB_WEBKEY($$)	{ TBExptUserDir($_[0],$_[1]) . "/tbdata/webkey"; }
612

613
614
615
616
617
# Regex stuff
sub TBDB_CHECKDBSLOT_NOFLAGS()	{ 0x0; }
sub TBDB_CHECKDBSLOT_WARN()	{ 0x1; }
sub TBDB_CHECKDBSLOT_ERROR()	{ 0x2; }

618
619
620
621
622
623
# Security Levels.
sub TBDB_SECLEVEL_GREEN()	{ 0; }
sub TBDB_SECLEVEL_YELLOW()	{ 1; }
sub TBDB_SECLEVEL_ORANGE()	{ 2; }
sub TBDB_SECLEVEL_RED()		{ 3; }

624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
#
# A hash of all tables that contain information about physical nodes - the
# value for each key is the list of columns that could contain the node's ID.
#
sub TBDB_PHYSICAL_NODE_TABLES() {
    return (
	'current_reloads'	=> [ 'node_id' ],
	'delays'		=> [ 'node_id' ],
	'iface_counters'	=> [ 'node_id' ],
	'interfaces'		=> [ 'node_id' ],
	'interface_settings'	=> [ 'node_id' ],
	'last_reservation'	=> [ 'node_id' ],
	'linkdelays'		=> [ 'node_id' ],
	'location_info'		=> [ 'node_id' ],
	'next_reserve'		=> [ 'node_id' ],
	'node_activity'		=> [ 'node_id' ],
	'node_auxtypes'		=> [ 'node_id' ],
	'node_features'		=> [ 'node_id' ],
	'node_hostkeys'		=> [ 'node_id' ],
	'node_idlestats'	=> [ 'node_id' ],
	'node_status'   	=> [ 'node_id' ],
	'node_rusage'		=> [ 'node_id' ],
	'nodeipportnum'		=> [ 'node_id' ],
	'nodelog'		=> [ 'node_id' ],
	'nodes'			=> [ 'node_id', 'phys_nodeid' ],
	'nodeuidlastlogin'	=> [ 'node_id' ],
	'ntpinfo'		=> [ 'node_id' ],
	'outlets'		=> [ 'node_id' ],
	'partitions'		=> [ 'node_id' ],
	'plab_slice_nodes'	=> [ 'node_id' ],
	'port_counters'		=> [ 'node_id' ],
	'reserved'		=> [ 'node_id' ],
	'scheduled_reloads'	=> [ 'node_id' ],
	'state_triggers'	=> [ 'node_id' ],
	'switch_stacks'		=> [ 'node_id' ],
	'tiplines'		=> [ 'node_id' ],
	'tmcd_redirect'		=> [ 'node_id' ],
	'tunnels'		=> [ 'node_id' ],
	'uidnodelastlogin'	=> [ 'node_id' ],
	'v2pmap'		=> [ 'node_id' ],
	'veth_interfaces'	=> [ 'node_id' ],
	'widearea_accounts'	=> [ 'node_id' ],
	'widearea_delays'	=> [ 'node_id1', 'node_id2' ],
	'widearea_nodeinfo'	=> [ 'node_id' ],
	'widearea_recent'	=> [ 'node_id1', 'node_id2' ],
	'wires'			=> [ 'node_id1', 'node_id2' ],
    );
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
673
674
675
676
677
678
679
680
681
682
683
684
685
686
#
# Auth stuff.
#

#
# Convert a trust string to the above numeric values.
#
sub TBTrustConvert($)
{
    my($trust_string) = @_;
    my $trust_value = 0;

    #
    # Convert string to value. Perhaps the DB should have done it this way?
Mac Newbold's avatar
Mac Newbold committed
687
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
    if ($trust_string eq "none") {
	$trust_value = PROJMEMBERTRUST_NONE;
    }
    elsif ($trust_string eq "user") {
	$trust_value = PROJMEMBERTRUST_USER;
    }
    elsif ($trust_string eq "local_root") {
	$trust_value = PROJMEMBERTRUST_LOCALROOT;
    }
    elsif ($trust_string eq "group_root") {
	$trust_value = PROJMEMBERTRUST_GROUPROOT;
    }
    elsif ($trust_string eq "project_root") {
	$trust_value = PROJMEMBERTRUST_PROJROOT;
    }
    elsif ($trust_string eq "admin") {
	$trust_value = PROJMEMBERTRUST_ADMIN;
    }
    else {
	    die("*** Invalid trust value $trust_string!");
    }

    return $trust_value;
}

#
# Return true if the given trust string is >= to the minimum required.
# The trust value can be either numeric or a string; if a string its
# first converted to the numeric equiv.
#
sub TBMinTrust($$)
{
    my ($trust_value, $minimum) = @_;

    if ($minimum < PROJMEMBERTRUST_NONE ||
	$minimum > PROJMEMBERTRUST_ADMIN) {
	    die("*** Invalid minimum trust $minimum!");
    }

    #
    # Sleazy? How do you do a typeof in perl?
    #
    if (length($trust_value) != 1) {
	$trust_value = TBTrustConvert($trust_value);
    }
Mac Newbold's avatar
Mac Newbold committed
733

Leigh B. Stoller's avatar
Leigh B. Stoller committed
734
735
736
737
738
739
    return $trust_value >= $minimum;
}

#
# Determine the trust level for a uid/pid/gid. That is, each uid will have
# a different trust level depending on the project/group in question.
Mac Newbold's avatar
Mac Newbold committed
740
741
# Return that trust level as one of the numeric values above.
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
742
743
744
# usage: TBGrpTrust($dbuid, $pid, $gid)
#        returns numeric trust value if a group member.
#        returns PROJMEMBERTRUST_NONE if not a group member.
Mac Newbold's avatar
Mac Newbold committed
745
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
sub TBGrpTrust($$$)
{
    my ($uid, $pid, $gid) = @_;

    #
    # No group, then use the default group.
    #
    if (! $gid) {
	$gid = $pid;
    }

    my $query_result =
	DBQueryFatal("select trust from group_membership ".
		     "where uid='$uid' and pid='$pid' and gid='$gid'");

    #
    # No membership is the same as no trust. True? Maybe an error instead?
    #
    if ($query_result->numrows == 0) {
	return PROJMEMBERTRUST_NONE;
    }

    my @row = $query_result->fetchrow_array();
Mac Newbold's avatar
Mac Newbold committed
769
    my $trust_string = $row[0];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
770
771
772
773
774
775
776
777
778
779
780

    return TBTrustConvert($trust_string);
}

#
# Determine the project trust level for a uid/pid. This is the trust level
# for the default group in the project.
#
# usage: TBProjTrust($dbuid, $pid)
#        returns numeric trust value if a project member.
#        returns PROJMEMBERTRUST_NONE if not a project member.
Mac Newbold's avatar
Mac Newbold committed
781
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
782
783
784
sub TBProjTrust($$)
{
    my ($uid, $pid) = @_;
Mac Newbold's avatar
Mac Newbold committed
785

Leigh B. Stoller's avatar
Leigh B. Stoller committed
786
787
788
    return TBGrpTrust($uid, $pid, $pid);
}

789
#
790
791
# Test admin status. Optional argument is the UID or Name to test. If not
# provided, then test the current UID.
792
#
793
794
795
# XXX Argument is *either* a numeric UID, or a string name.
#
# usage: TBAdmin([int or char* uid]);
796
797
#        returns 1 if an admin type.
#        returns 0 if a mere user.
Mac Newbold's avatar
Mac Newbold committed
798
#
799
800
801
sub TBAdmin(;$)
{
    my($uid) = @_;
802
    my($name);
803

804
805
806
807
    #
    # No one is considered an admin unless they have the magic environment
    # variable set (so that you have to be a bit more explict about wanting
    # admin privs.) Use the withadminprivs script to get this variable set.
808
809
    # Also check with HTTP_ at the front of the name, since this is required
    # to get it through suexec from the web scripts.
810
    #
811
    if (!($ENV{WITH_TB_ADMIN_PRIVS} || $ENV{HTTP_WITH_TB_ADMIN_PRIVS})) {
812
813
814
	return 0;
    }

815
816
817
818
    if (!defined($uid)) {
	$uid = $UID;
    }

819
820
    #
    # Test if numeric. Map to name if it is.
Mac Newbold's avatar
Mac Newbold committed
821
    #
822
823
824
825
826
827
828
    if ($uid =~ /^[0-9]+$/) {
	($name) = getpwuid($uid)
	    or die "$uid not in passwd file\n";
    }
    else {
	$name = $uid;
    }
829
830

    my $query_result =
831
	DBQueryFatal("select admin from users where uid='$name'");
832
833
834
835
836
837
838
839
840

    my @row = $query_result->fetchrow_array();
    if ($row[0] == 1) {
	return 1;
    }
    return 0;
}

#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
841
842
# Project permission checks. The group id (gid) can be undef, in which case
# the pid is used (ie: a default group check is made).
843
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
844
845
846
# Usage: TBProjAccessCheck($uid, $pid, $gid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
847
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
848
sub TBProjAccessCheck($$$$)
849
{
Leigh B. Stoller's avatar
Leigh B. Stoller committed
850
851
    my ($uid, $pid, $gid, $access_type) = @_;
    my $mintrust;
852

Leigh B. Stoller's avatar
Leigh B. Stoller committed
853
854
855
    if ($access_type < TB_PROJECT_MIN ||
	$access_type > TB_PROJECT_MAX) {
	die("*** Invalid access type: $access_type!");
856
857
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
858
859
    #
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
860
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
861
862
    if (TBAdmin($uid)) {
	return 1;
863
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
864
865
866
867
868
869
870
    $uid = MapNumericUID($uid);

    #
    # No group, then use the default group.
    #
    if (! defined($gid)) {
	$gid = $pid;
871
872
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
873
874
875
876
877
878
    if ($access_type == TB_PROJECT_READINFO) {
	$mintrust = PROJMEMBERTRUST_USER;
    }
    elsif ($access_type == TB_PROJECT_CREATEEXPT) {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }
879
880
881
    elsif ($access_type == TB_PROJECT_DELUSER) {
	$mintrust = PROJMEMBERTRUST_PROJROOT;
    }
882
883
884
885
    elsif ($access_type == TB_PROJECT_MAKEGROUP ||
	   $access_type == TB_PROJECT_DELGROUP) {
	$mintrust = PROJMEMBERTRUST_GROUPROOT;
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
886
887
888
889
890
891
892
893
894
895
896
897
898
    else {
	die("*** Unexpected access type: $access_type!");
    }

    return TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust);
}

#
# Experiment permission checks.
#
# Usage: TBExptAccessCheck($uid, $pid, $eid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
899
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
900
901
902
903
904
905
906
907
sub TBExptAccessCheck($$$$)
{
    my ($uid, $pid, $eid, $access_type) = @_;
    my $mintrust;

    if ($access_type < TB_EXPT_MIN ||
	$access_type > TB_EXPT_MAX) {
	die("*** Invalid access type: $access_type!");
908
909
910
    }

    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
911
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
912
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
913
    if (TBAdmin($uid)) {
914
915
	return 1;
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
916
    $uid = MapNumericUID($uid);
917

Leigh B. Stoller's avatar
Leigh B. Stoller committed
918
    my $query_result =
919
	DBQueryFatal("SELECT gid,expt_head_uid FROM experiments WHERE ".
Leigh B. Stoller's avatar
Leigh B. Stoller committed
920
		     "eid='$eid' and pid='$pid'");
Mac Newbold's avatar
Mac Newbold committed
921

Leigh B. Stoller's avatar
Leigh B. Stoller committed
922
923
924
925
    if ($query_result->numrows == 0) {
	return 0;
    }
    my @row = $query_result->fetchrow_array();
926
927
    my $gid     = $row[0];
    my $creator = $row[1];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
928

929
930
931
    #
    # An experiment may be destroyed by the experiment creator or the
    # project/group leader.
Mac Newbold's avatar
Mac Newbold committed
932
    #
933
    if ($access_type == TB_EXPT_READINFO) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
934
935
936
937
938
939
	$mintrust = PROJMEMBERTRUST_USER;
    }
    else {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }

940
941
942
943
944
945
946
    #
    # Either proper permission in the group, or group_root in the project.
    # This lets group_roots muck with other people's experiments, including
    # those in groups they do not belong to.
    #
    return TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust) ||
	TBMinTrust(TBGrpTrust($uid, $pid, $pid), PROJMEMBERTRUST_GROUPROOT);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
947
948
949
950
951
952
953
954
}

#
# Determine if uid can access a node or list of nodes.
#
# Usage: TBNodeAccessCheck($uid, $access_type, $node_id, ...)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
955
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
956
957
958
959
960
961
962
963
964
965
sub TBNodeAccessCheck($$@)
{
    my ($uid, $access_type) = (shift, shift);
    my @nodelist = @_;
    my $mintrust;

    if ($access_type < TB_NODEACCESS_MIN ||
	$access_type > TB_NODEACCESS_MAX) {
	die("*** Invalid access type: $access_type!");
    }
966
967

    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
968
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
969
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
970
971
972
973
    if (TBAdmin($uid)) {
	return 1;
    }
    $uid = MapNumericUID($uid);
Mac Newbold's avatar
Mac Newbold committed
974

Leigh B. Stoller's avatar
Leigh B. Stoller committed
975
976
977
978
979
980
981
982
    if ($access_type == TB_NODEACCESS_READINFO) {
	$mintrust = PROJMEMBERTRUST_USER;
    }
    else {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }

    foreach my $node (@nodelist) {
983
	my $query_result =
984
	    DBQueryFatal("select e.pid,e.gid from reserved as r ".
Leigh B. Stoller's avatar
Leigh B. Stoller committed
985
			 "left join experiments as e on ".
986
987
			 "     e.pid=r.pid and e.eid=r.eid ".
			 "where r.node_id='$node'");
988

989
	if ($query_result->numrows == 0) {
990
991
	    return 0;
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
992
	my @row = $query_result->fetchrow_array();
993
994
	my $pid = $row[0];
	my $gid = $row[1];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
995

996
997
998
999
1000
1001
1002
1003
	#
	# Either proper permission in the group, or group_root in the
	# project. This lets group_roots muck with other people's
	# nodes, including those in groups they do not belong to.
	#
	if (! TBMinTrust(TBGrpTrust($uid, $pid, $gid), $mintrust) &&
	    ! TBMinTrust(TBGrpTrust($uid, $pid, $pid),
			 PROJMEMBERTRUST_GROUPROOT)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1004
1005
	    return 0;
	}
1006
1007
1008
1009
1010
    }
    return 1;
}

#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1011
# Access checks for an OSID. Tests for tbadmin.
1012
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1013
1014
1015
# Usage: TBOSIDAccessCheck($uid, $osid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
1016
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1017
sub TBOSIDAccessCheck($$$)
1018
{
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1019
1020
    my ($uid, $osid, $access_type) = @_;
    my $mintrust;
1021

Leigh B. Stoller's avatar
Leigh B. Stoller committed
1022
1023
    if ($access_type < TB_OSID_MIN || $access_type > TB_OSID_MAX) {
	die("*** Invalid access type $access_type!");
1024
1025
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
1026
1027
    #
    # Admins do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
1028
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1029
1030
1031
1032
    if (TBAdmin($uid)) {
	return 1;
    }
    $uid = MapNumericUID($uid);
1033

Leigh B. Stoller's avatar
Leigh B. Stoller committed
1034
1035
1036
1037
    #
    # No GIDs yet.
    #
    my $query_result =
1038
	DBQueryFatal("SELECT pid,shared FROM os_info WHERE osid='$osid'");
Mac Newbold's avatar
Mac Newbold committed
1039

1040
    if ($query_result->numrows == 0) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1041
	return 0;
1042
    }
1043
    my @row = $query_result->fetchrow_array();
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1044
    my $pid = $row[0];
1045
    my $shared = $row[1];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1046
1047

    #
Mac Newbold's avatar
Mac Newbold committed
1048
1049
    # Global OSIDs can be read by anyone, but must be admin to read.
    #
1050
    if ($shared) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1051
1052
1053
1054
1055
	if ($access_type == TB_OSID_READINFO) {
	    return 1;
	}
	return 0;
    }
Mac Newbold's avatar
Mac Newbold committed
1056

Leigh B. Stoller's avatar
Leigh B. Stoller committed
1057
1058
    #
    # Otherwise must have proper trust in the project.
Mac Newbold's avatar
Mac Newbold committed
1059
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1060
1061
1062
1063
1064
1065
1066
1067
1068
1069
1070
1071
1072
1073
1074
1075
    if ($access_type == TB_OSID_READINFO) {
	$mintrust = PROJMEMBERTRUST_USER;
    }
    else {
	$mintrust = PROJMEMBERTRUST_LOCALROOT;
    }

    return TBMinTrust(TBProjTrust($uid, $pid), $mintrust);
}

#
# Access checks for an ImageID
#
# Usage: TBImageIDAccessCheck($uid, $imageid, $access_type)
#	 returns 0 if not allowed.
#        returns 1 if allowed.
Mac Newbold's avatar
Mac Newbold committed
1076
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1077
1078
1079
1080
1081
1082
1083
sub TBImageIDAccessCheck($$$)
{
    my ($uid, $imageid, $access_type) = @_;
    my $mintrust;

    if ($access_type < TB_IMAGEID_MIN || $access_type > TB_IMAGEID_MAX) {
	die("*** Invalid access type $access_type!");
1084
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1085
1086

    #
1087
    # Admins and root do whatever they want!
Mac Newbold's avatar
Mac Newbold committed
1088
    #
1089
    if (TBAdmin($uid) || !$UID || $UID eq "root" || $uid eq "root") {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1090
	return 1;
1091
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1092
1093
1094
1095
1096
1097
    $uid = MapNumericUID($uid);

    #
    # No GIDs yet.
    #
    my $query_result =
1098
1099
	DBQueryFatal("SELECT pid,gid,shared,global FROM images ".
		     "WHERE imageid='$imageid'");
Mac Newbold's avatar
Mac Newbold committed
1100

Leigh B. Stoller's avatar
Leigh B. Stoller committed
1101
1102
    if ($query_result->numrows == 0) {
	return 0;
1103
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1104
1105
    my @row = $query_result->fetchrow_array();
    my $pid = $row[0];
1106
1107
1108
    my $gid = $row[1];
    my $shared = $row[2];
    my $global = $row[3];
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1109

1110
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1111
    # Global ImageIDs can be read by anyone.
Mac Newbold's avatar
Mac Newbold committed
1112
    #
1113
    if ($global) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1114
1115
1116
1117
1118
1119
	if ($access_type == TB_IMAGEID_READINFO) {
	    return 1;
	}
	return 0;
    }

1120
    #
Leigh B. Stoller's avatar