GeniCM.pm.in 112 KB
Newer Older
Leigh B. Stoller's avatar
Leigh B. Stoller committed
1 2
#!/usr/bin/perl -wT
#
3
# GENIPUBLIC-COPYRIGHT
4
# Copyright (c) 2008-2010 University of Utah and the Flux Group.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
# All rights reserved.
#
package GeniCM;

#
# The server side of the CM interface on remote sites. Also communicates
# with the GMC interface at Geni Central as a client.
#
use strict;
use Exporter;
use vars qw(@ISA @EXPORT);

@ISA    = "Exporter";
@EXPORT = qw ( );

# Must come after package declaration!
use lib '@prefix@/lib';
use GeniDB;
use Genixmlrpc;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
24 25
use GeniResponse;
use GeniTicket;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
26
use GeniCredential;
27
use GeniCertificate;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
28
use GeniSlice;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
29
use GeniAggregate;
30
use GeniAuthority;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
31
use GeniSliver;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
32
use GeniUser;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
33
use GeniRegistry;
34
use GeniUtil;
35
use GeniHRN;
36
use GeniXML;
37
use GeniUsage;
38
use libtestbed qw(SENDMAIL);
39
use emutil;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
40
# Hate to import all this crap; need a utility library.
41 42
use libdb qw(TBGetSiteVar EXPTSTATE_SWAPPED EXPTSTATE_ACTIVE TBOPSPID
	     TBDB_NODESTATE_TBFAILED);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
43
use User;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
44
use Node;
45
use Lan;
46
use OSinfo;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
47
use Image;
48
use Interface;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
49 50
use English;
use Data::Dumper;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
51
use XML::Simple;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
52
use Date::Parse;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
53
use POSIX qw(strftime tmpnam);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
54
use Time::Local;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
55
use Experiment;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
56
use VirtExperiment;
57
use Firewall;
58
use Compress::Zlib;
59
use File::Temp qw(tempfile);
60
use MIME::Base64;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
61 62 63 64 65 66 67 68

# Configure variables
my $TB		   = "@prefix@";
my $TBOPS          = "@TBOPSEMAIL@";
my $TBAPPROVAL     = "@TBAPPROVALEMAIL@";
my $TBAUDIT   	   = "@TBAUDITEMAIL@";
my $BOSSNODE       = "@BOSSNODE@";
my $OURDOMAIN      = "@OURDOMAIN@";
69
my $PGENIDOMAIN    = "@PROTOGENI_DOMAIN@";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
70
my $CREATEEXPT     = "$TB/bin/batchexp";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
71
my $ENDEXPT        = "$TB/bin/endexp";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
72
my $NALLOC	   = "$TB/bin/nalloc";
73
my $NFREE	   = "$TB/bin/nfree";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
74
my $AVAIL	   = "$TB/sbin/avail";
75
my $PTOPGEN	   = "$TB/libexec/ptopgen";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
76 77
my $TBSWAP	   = "$TB/bin/tbswap";
my $SWAPEXP	   = "$TB/bin/swapexp";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
78 79
my $PLABSLICE	   = "$TB/sbin/plabslicewrapper";
my $NAMEDSETUP     = "$TB/sbin/named_setup";
80
my $EXPORTS_SETUP  = "$TB/sbin/exports_setup";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
81 82
my $VNODESETUP     = "$TB/sbin/vnode_setup";
my $GENTOPOFILE    = "$TB/libexec/gentopofile";
83
my $TARFILES_SETUP = "$TB/bin/tarfiles_setup";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
84 85 86 87
my $MAPPER         = "$TB/bin/mapper";
my $VTOPGEN        = "$TB/bin/vtopgen";
my $SNMPIT         = "$TB/bin/snmpit";
my $PRERENDER      = "$TB/libexec/vis/prerender";
88
my $XMLLINT	   = "/usr/local/bin/xmllint";
89
my $EMULAB_PEMFILE = "@prefix@/etc/genicm.pem";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
90

91 92 93 94 95 96 97 98 99 100 101 102
my $API_VERSION = 1;

#
# Tell the client what API revision we support.  The correspondence
# between revision numbers and API features is to be specified elsewhere.
# No credentials are required.
#
sub GetVersion()
{
    return GeniResponse->Create( GENIRESPONSE_SUCCESS, $API_VERSION );
}

103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132
# Look up a node by an identifier of unspecified type (perhaps a URN, an
# (obsolete) UUID, or an old-style HRN.  Ultimately, all IDs should be
# URNs and this mess will go away, but for now we try not to make
# any assumptions, because of backward compatibility constraints.
sub LookupNode($)
{
    my ($nodeid) = @_;

    if( GeniHRN::IsValid( $nodeid ) ) {
	# Looks like a URN.
	my ($auth,$t,$id) = GeniHRN::Parse( $nodeid );

	return undef if $auth ne $OURDOMAIN or $t ne "node";

	return Node->Lookup( $id );
    }
 
    #
    # Looks like an old HRN, but we only want the last token for node lookup.
    #
    if ($nodeid =~ /\./) {
	($nodeid) = ($nodeid =~ /\.([-\w]*)$/);

	return Node->Lookup($nodeid);
    }
    
    # Assume it's a UUID, and pass it on as is.
    return Node->Lookup($nodeid);
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
133
#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
134
# Respond to a Resolve request. 
Leigh B. Stoller's avatar
Leigh B. Stoller committed
135 136 137 138 139 140
#
sub Resolve($)
{
    my ($argref) = @_;
    my $uuid       = $argref->{'uuid'};
    my $cred       = $argref->{'credential'};
141 142
    my $type       = lc( $argref->{'type'} );
    my $hrn        = $argref->{'hrn'};
Leigh B. Stoller's avatar
Leigh B. Stoller committed
143 144 145 146

    if (! defined($cred)) {
	return GeniResponse->MalformedArgsResponse();
    }
147 148 149 150
    if (defined($uuid) && GeniHRN::IsValid($uuid)) {
	$hrn  = $uuid;
	$uuid = undef;
    }
151 152 153 154 155 156 157 158 159 160 161 162
    if( defined( $hrn ) && GeniHRN::IsValid( $hrn ) ) {
	my ($auth,$t,$id) = GeniHRN::Parse( $hrn );

	return GeniResponse->Create( GENIRESPONSE_ERROR, undef,
				     "Authority mismatch" )
	    if( $auth ne $OURDOMAIN );

	$type = lc( $t );
	
	$hrn = $id;	
    }
    if (! (defined($type) && ($type =~ /^(node)$/))) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
163 164 165
	return GeniResponse->MalformedArgsResponse();
    }
    # Allow lookup by uuid or hrn.
166
    if (! defined($uuid) && !defined( $hrn ) ) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186
	return GeniResponse->MalformedArgsResponse();
    }
    if (defined($uuid) && !($uuid =~ /^[-\w]*$/)) {
	return GeniResponse->MalformedArgsResponse();
    }

    my $credential = GeniCredential->CreateFromSigned($cred);
    if (!defined($credential)) {
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
				    "Could not create GeniCredential object");
    }
    
    #
    # Make sure the credential was issued to the caller, but no special
    # permission required to resolve component resources.
    #
    if ($credential->owner_uuid() ne $ENV{'GENIUUID'}) {
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
				    "This is not your credential!");
    }
187
    if ($type eq "node") {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
188 189 190
	my $node;
	
	if (defined($uuid)) {
191
	    $node= LookupNode($uuid);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
192 193
	}
	else {
194
	    $node= LookupNode($hrn);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
195
	}
196
	if (! defined($node)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
197 198 199
	    return GeniResponse->Create(GENIRESPONSE_SEARCHFAILED,
					undef, "Nothing here by that name");
	}
200 201 202 203 204 205

	my $rspec = GetAdvertisement(0, $node->node_id());
	if (! defined($rspec)) {
	    return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
					"Could not start avail");
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
206 207
	
	# Return a blob.
208
	my $blob = { "hrn"          => "${PGENIDOMAIN}." . $node->node_id(),
Leigh B. Stoller's avatar
Leigh B. Stoller committed
209
		     "uuid"         => $node->uuid(),
210
		     "role"	    => $node->role(),
211
		     "hostname"     => $node->node_id() . ".${OURDOMAIN}",
212 213
		     "physctrl"     => 
			 Interface->LookupControl( $node->phys_nodeid() )->IP(),
214 215
		     "urn"          => GeniHRN::Generate( $OURDOMAIN,
							  "node",
216 217
							  $node->node_id() ),
		     "rspec"        => $rspec
Leigh B. Stoller's avatar
Leigh B. Stoller committed
218 219 220 221 222 223 224
		   };

	return GeniResponse->Create(GENIRESPONSE_SUCCESS, $blob);
    }
    return GeniResponse->Create(GENIRESPONSE_UNSUPPORTED);
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
225 226 227 228 229 230 231
#
# Discover resources on this component, returning a resource availablity spec
#
sub DiscoverResources($)
{
    my ($argref) = @_;
    my $credential = $argref->{'credential'};
232 233
    my $available = $argref->{'available'} || 0;
    my $compress = $argref->{'compress'} || 0;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
234 235 236 237 238 239 240 241
    my $user_uuid  = $ENV{'GENIUSER'};

    $credential = GeniCredential->CreateFromSigned($credential);
    if (!defined($credential)) {
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
				    "Could not create GeniCredential object");
    }
    # The credential owner/slice has to match what was provided.
242
    if ($user_uuid ne $credential->owner_uuid()) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
243 244 245
	return GeniResponse->Create(GENIRESPONSE_FORBIDDEN, undef,
				    "Invalid credentials for operation");
    }
246 247 248 249 250 251 252
    return DiscoverResourcesAux($available, $compress);
}
# Helper function for V2.
sub DiscoverResourcesAux($$)
{
    my ($available, $compress) = @_;
    my $user_uuid  = $ENV{'GENIUSER'};
Leigh B. Stoller's avatar
Leigh B. Stoller committed
253

254 255 256
    # Oh, for $*%(s sake.  Frontier::RPC2 insists on representing a
    # Boolean as its own object type -- which Perl always interprets as
    # true, regardless of the object's value.  Undo all of that silliness.
257 258 259 260 261 262
    if (defined($available) && ref($available) eq 'Frontier::RPC2::Boolean') {
	$available = $available->value;
    }
    if (defined($compress) && ref($compress) eq 'Frontier::RPC2::Boolean') {
	$compress = $compress->value;
    }
263

Leigh B. Stoller's avatar
Leigh B. Stoller committed
264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280
    #
    # A sitevar controls whether external users can get any nodes.
    #
    my $allow_externalusers = 0;
    if (!TBGetSiteVar('protogeni/allow_externalusers', \$allow_externalusers)){
	# Cannot get the value, say no.
	$allow_externalusers = 0;
    }
    if (!$allow_externalusers) {
	my $user = GeniUser->Lookup($user_uuid, 1);
	# No record means the user is remote.
	if (!defined($user) || !$user->IsLocal()) {
	    return GeniResponse->Create(GENIRESPONSE_UNAVAILABLE, undef,
					"External users temporarily denied");
	}
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
281
    #
282
    # Acquire the advertisement from ptopgen and compress it if requested.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
283
    #
284 285
    my $xml = GetAdvertisement($available, undef);
    if (! defined($xml)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
286 287 288 289
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
				    "Could not start avail");
    }

290 291 292 293 294 295
    if( $compress ) {
	my $coder = Frontier::RPC2->new();
	my $base64 = encode_base64( compress( $xml ) );
	$xml = $coder->base64( $base64 );	
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
296 297
    return GeniResponse->Create(GENIRESPONSE_SUCCESS, $xml);
}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
298

299 300 301 302 303 304 305 306
#
# Use ptopgen in xml mode to spit back an xml file. 
#
sub GetAdvertisement($$)
{
    my ($available, $pc) = @_;
    my $xml = undef;

Jonathon Duerig's avatar
Jonathon Duerig committed
307
    my $invocation = "$PTOPGEN -x -g -r -p GeniSlices";
308 309 310 311 312
    $invocation .= " -a" unless $available;
    if (defined($pc)) {
	$invocation .= " -1 $pc";
    }
    if (open(AVAIL, "$invocation |")) {
313
	$xml = "";
314 315 316 317 318 319 320 321
	while (<AVAIL>) {
	    $xml .= $_;
	}
	close(AVAIL);
    }
    return $xml;
}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
322
#
323
# Update a ticket with a new rspec.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
324
#
325
sub UpdateTicket($)
Leigh B. Stoller's avatar
Leigh B. Stoller committed
326 327
{
    my ($argref) = @_;
328 329 330 331 332 333 334 335 336 337

    return GetTicket($argref, 1);
}

#
# Respond to a GetTicket request. 
#
sub GetTicket($;$)
{
    my ($argref, $isupdate) = @_;
338
    my $rspecstr   = $argref->{'rspec'};
Leigh B. Stoller's avatar
Leigh B. Stoller committed
339
    my $impotent   = $argref->{'impotent'};
340 341
    my $credstr    = $argref->{'credential'};
    my $tickstr    = $argref->{'ticket'};
342 343 344 345 346 347 348
    my $ticket;

    # Default to no update
    $isupdate = 0
	if (!defined($isupdate));
    $impotent = 0
	if (!defined($impotent));
Leigh B. Stoller's avatar
Leigh B. Stoller committed
349

350
    if (! defined($credstr)) {
351
	return GeniResponse->MalformedArgsResponse();
Leigh B. Stoller's avatar
Leigh B. Stoller committed
352
    }
353
    if (!defined($rspecstr)) {
354 355
	return GeniResponse->MalformedArgsResponse();
    }
356 357 358 359
    if (! ($rspecstr =~ /^[\040-\176\012\015\011]+$/)) {
	return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
				    "Improper characters in rspec");
    }
360
    my $credential = GeniCredential->CreateFromSigned($credstr);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
361 362 363 364
    if (!defined($credential)) {
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
				    "Could not create GeniCredential object");
    }
365 366 367
    #
    # Make sure the credential was issued to the caller.
    #
368
    if ($credential->owner_uuid() ne $ENV{'GENIUUID'}) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
369
	return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
370
				    "This is not your credential!");
Leigh B. Stoller's avatar
Leigh B. Stoller committed
371
    }
372
    if ($isupdate) {
373
	$ticket = GeniTicket->CreateFromSignedTicket($tickstr);
374 375 376 377 378
	if (!defined($ticket)) {
	    return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
					"Could not create GeniTicket object");
	}
    }
379
    return GetTicketAux($credential,
380
			$rspecstr, $isupdate, $impotent, 0, 1, $ticket);
381
}
382

383
sub GetTicketAux($$$$$$$)
384
{
385 386
    my ($credential, $rspecstr, $isupdate, $impotent, $v2, $level,
	$ticket) = @_;
387
    
388 389 390 391 392 393
    defined($credential) &&
	($credential->HasPrivilege( "pi" ) or
	 $credential->HasPrivilege( "instantiate" ) or
	 $credential->HasPrivilege( "bind" ) or
	 return GeniResponse->Create( GENIRESPONSE_FORBIDDEN, undef,
				      "Insufficient privilege" ));
394
    
395 396
    my $slice_uuid = $credential->target_uuid();
    my $user_uuid  = $credential->owner_uuid();
397
    
Leigh B. Stoller's avatar
Leigh B. Stoller committed
398
    #
399
    # Create slice from the certificate.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
400 401 402
    #
    my $slice = GeniSlice->Lookup($slice_uuid);
    if (!defined($slice)) {
403 404 405 406 407
	if ($isupdate) {
	    print STDERR "Could not locate slice $slice_uuid for Update\n";
	    return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
					"No slice found for UpdateTicket");
	}
408
	$slice = CreateSliceFromCertificate($credential);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
409
	if (!defined($slice)) {
410
	    print STDERR "Could not create $slice_uuid\n";
Leigh B. Stoller's avatar
Leigh B. Stoller committed
411
	    return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
412
					"Could not create slice");
Leigh B. Stoller's avatar
Leigh B. Stoller committed
413
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
414 415
    }

Leigh B. Stoller's avatar
Leigh B. Stoller committed
416
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
417 418
    # Ditto the user.
    #
419
    my $user = CreateUserFromCertificate($credential->owner_cert());
Leigh B. Stoller's avatar
Leigh B. Stoller committed
420
    if (!defined($user)) {
421 422 423 424 425
	if ($isupdate) {
	    print STDERR "Could not locate $user_uuid for UpdateTicket\n";
	    return GeniResponse->Create(GENIRESPONSE_ERROR, undef,
					"No user found for UpdateTicket");
	}
426
	return GeniResponse->Create(GENIRESPONSE_ERROR);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
427
    }
428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447
    return GetTicketAuxAux($slice, $user, $rspecstr,
			   $isupdate, $impotent, $v2, $level, $ticket);
}
sub GetTicketAuxAux($$$$$$$$)
{
    my ($slice, $user,
	$rspecstr, $isupdate, $impotent, $v2, $level, $ticket) = @_;
    my $response    = undef;
    my $restorevirt = 0;	# Flag to restore virtual state
    my $restorephys = 0;	# Flag to restore physical state

    #
    # We need this below to sign the ticket.
    #
    my $authority = GeniCertificate->LoadFromFile($EMULAB_PEMFILE);
    if (!defined($authority)) {
	print STDERR " Could not get uuid from $EMULAB_PEMFILE\n";
	return GeniResponse->Create(GENIRESPONSE_ERROR);
    }

448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465
    #
    # Run xmllint on the rspec to catch format errors.
    #
    my ($fh, $filename) = tempfile(UNLINK => 0);
    if (!defined($fh)) {
	print STDERR "Could not create temp file for rspec\n";
	return GeniResponse->Create(GENIRESPONSE_ERROR);
    }
    print $fh $rspecstr;
    close($fh);
    my $xmlerrors = `$XMLLINT --noout $filename 2>&1`;
    unlink($filename);
    if ($?) {
	return GeniResponse->Create(GENIRESPONSE_ERROR,
				    $xmlerrors,
				    "rspec is not well formed");
    }

466 467
    my $rspec = GeniXML::Parse($rspecstr);
    if (! defined($rspec)) {
468
	return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
469
				    "Error Parsing rspec XML");
470
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
471

Leigh B. Stoller's avatar
Leigh B. Stoller committed
472 473 474 475 476 477 478 479 480 481 482 483 484 485
    #
    # A sitevar controls whether external users can get any nodes.
    #
    my $allow_externalusers = 0;
    if (!TBGetSiteVar('protogeni/allow_externalusers', \$allow_externalusers)){
	# Cannot get the value, say no.
	$allow_externalusers = 0;
    }
    if (!$allow_externalusers && !$user->IsLocal()) {
	return GeniResponse->Create(GENIRESPONSE_UNAVAILABLE, undef,
				    "External users temporarily denied");
    }
    
    #
486
    # For now all tickets expire very quickly (minutes), but once the
Leigh B. Stoller's avatar
Leigh B. Stoller committed
487
    # ticket is redeemed, it will expire according to the rspec request.
488 489 490
    # If nothing specified in the rspec, then it will expire when the
    # slice record expires, which was given by the expiration time of the
    # slice credential.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
491
    #
492 493
    my $expires = GeniXML::GetText("valid_until", $rspec);
    if (defined($expires)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
494 495 496 497 498 499 500 501 502 503 504 505
	if (! ($expires =~ /^[-\w:.\/]+/)) {
	    return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					"Illegal valid_until in rspec");
	}
	# Convert to a localtime.
	my $when = timegm(strptime($expires));
	if (!defined($when)) {
	    return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					"Could not parse valid_until");
	}
	
	#
506
	# Do we need a policy limit?
Leigh B. Stoller's avatar
Leigh B. Stoller committed
507 508
	#
	my $diff = $when - time();
509
	if ($diff < (60 * 5) || $diff > (3600 * 24 * 90)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
510 511 512
	    return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					"valid_until out of range");
	}
513 514 515 516 517 518

	#
	# Must be before the slice expires.
	#
	my $slice_expires = $slice->expires();
	if (defined($slice_expires)) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
519
	    $slice_expires = str2time($slice_expires);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
520
	    if ($when > $slice_expires) {
521 522 523 524
		return GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
				    "valid_until is past slice expiration");
	    }
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
525
    }
526 527 528 529 530 531 532

    #
    # Lock the ticket so it cannot be released.
    #
    if (defined($ticket) && $ticket->stored() && $ticket->Lock() != 0) {
	return GeniResponse->BusyResponse("ticket");
    }
533 534 535
    if (defined($ticket)) {
	$ticket->SetSlice($slice);
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
536 537 538 539 540 541
    
    #
    #
    # Lock the slice from further access.
    #
    if ($slice->Lock() != 0) {
542 543 544
	$ticket->UnLock()
	    if (defined($ticket) && $ticket->stored());
	return GeniResponse->BusyResponse("slice");
Leigh B. Stoller's avatar
Leigh B. Stoller committed
545
    }
546 547 548
    # Shutdown slices get nothing.
    if ($slice->shutdown()) {
	$slice->UnLock();
549 550
	$ticket->UnLock()
	    if (defined($ticket) && $ticket->stored());
551 552 553
	return GeniResponse->Create(GENIRESPONSE_FORBIDDEN, undef,
				    "Slice has been shutdown");
    }
554 555 556 557 558 559 560 561
    # Ditto for expired.
    if ($slice->IsExpired()) {
	$slice->UnLock();
	$ticket->UnLock()
	    if (defined($ticket) && $ticket->stored());
	return GeniResponse->Create(GENIRESPONSE_REFUSED, undef,
				    "Slice has expired");
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
562

563
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
564
    # For now, there can be only a single toplevel aggregate per slice.
565
    # The existence of an aggregate means the slice is active here. 
Leigh B. Stoller's avatar
Leigh B. Stoller committed
566
    #
567
    my $aggregate = GeniAggregate->SliceAggregate($slice);
568 569 570 571 572
    if (!$isupdate) {
	if (defined($aggregate)) {
	    $response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
				     "Already have an aggregate for slice");
	    goto bad;
573 574
	}
    }
575 576 577 578 579
    elsif ($v2 && $level && !defined($ticket) && !defined($aggregate)) {
	print STDERR "No aggregate for $slice in version two API\n";
	$response = GeniResponse->Create(GENIRESPONSE_ERROR);
	goto bad;
    }
580 581 582 583

    #
    # Firewall hack; just a flag in the rspec for now.
    #
584 585 586
    my $needsfirewall = GeniXML::GetText("needsfirewall", $rspec);
    if (defined($needsfirewall)) {
	if ($slice->SetFirewallFlag($needsfirewall) != 0) {
587 588
	    $response = GeniResponse->Create(GENIRESPONSE_ERROR);
	    goto bad;
589 590
	}
    }
591 592

    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
593
    # We need this now so we can form a virtual topo.
594
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
595 596 597 598 599 600 601 602
    my $slice_experiment = GeniExperiment($slice);
    if (!defined($slice_experiment)) {
	print STDERR "Could not create new Geni slice experiment!\n";
	$response = GeniResponse->Create(GENIRESPONSE_ERROR);
	goto bad;
    }
    my $pid = $slice_experiment->pid();
    my $eid = $slice_experiment->eid();
603 604 605 606 607

    #
    # Mark the experiment locally as coming from the cooked interface.
    # This changes what tmcd returns to the local nodes.
    #
608 609
    my $generated_by = GeniXML::GetText("generated_by", $rspec);
    if ($generated_by eq "libvtop") {
610 611 612 613
	$slice_experiment->Update({"geniflags" =>
				       $Experiment::EXPT_GENIFLAGS_EXPT|
				       $Experiment::EXPT_GENIFLAGS_COOKED});
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
614 615 616 617 618 619 620 621 622 623 624 625 626
    
    #
    # Create a virt topology object. We are going to load this up as we
    # process the rspec.
    #
    my $virtexperiment = VirtExperiment->CreateNew($slice_experiment);
    if (!defined($virtexperiment)) {
	print STDERR "Could not create VirtExperiment object!\n";
	$response = GeniResponse->Create(GENIRESPONSE_ERROR);
	goto bad;
    }
    # Turn off fixnode; we will control this on the commandline.
    $virtexperiment->allowfixnode(0);
627
    $virtexperiment->multiplex_factor(3);
628 629

    # This is where nodes are parked until a ticket is redeemed.
630
    # This experiment no longer has to exist.
631
    my $reserved_holding = Experiment->Lookup("GeniSlices", "reservations");
Leigh B. Stoller's avatar
Leigh B. Stoller committed
632

Leigh B. Stoller's avatar
Leigh B. Stoller committed
633
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
634 635
    # An rspec is a structure that requests specific nodes. If those
    # nodes are available, then reserve it. Otherwise the ticket
Leigh B. Stoller's avatar
Leigh B. Stoller committed
636 637
    # cannot be granted.
    #
638 639 640
    my %namemap  = ();
    my %colomap  = ();
    my %ifacemap = ();
641
    my %vportmap = ();
Leigh B. Stoller's avatar
Leigh B. Stoller committed
642
    my %nodemap  = ();
643
    my @nodeids  = ();
644
    my %lannodes = ();
645
    my @dealloc;
646 647 648 649 650 651 652 653

    #
    # If this is a ticket update, we want to seed the namemap with
    # existing nodes. This is cause the rspec might refer to wildcards
    # that were already bound in a previous call. We also want to know
    # what nodes are currently reserved in case we have to release some.
    #
    if ($isupdate) {
Leigh B. Stoller's avatar
Leigh B. Stoller committed
654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671
	$slice_experiment->ClearBackupState();
	if ($slice_experiment->BackupVirtualState()) {
	    print STDERR "Could not backup virtual state!\n";
	    $response = GeniResponse->Create(GENIRESPONSE_ERROR);
	    goto bad;
	}
	if ($slice_experiment->RemoveVirtualState()) {
	    print STDERR "Could not remove virtual state!\n";
	    $response = GeniResponse->Create(GENIRESPONSE_ERROR);
	    goto bad;
	}
	$restorevirt = 1;

	if ($slice_experiment->BackupPhysicalState()) {
	    print STDERR "Could not backup physical state!\n";
	    $response = GeniResponse->Create(GENIRESPONSE_ERROR);
	    goto bad;
	}
672 673 674 675 676 677 678
	my $oldrspec;
	if ($v2 && defined($aggregate)) {
	    $oldrspec = $aggregate->GetManifest(0);
	}
	else {
	    $oldrspec = $ticket->rspec();
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
679
	
680
	foreach my $ref (GeniXML::FindNodes("n:node",
681
					    $oldrspec)->get_nodelist()) {
682
	    # Let remote nodes pass through.
683
	    next
684
		if (!GeniXML::IsLocalNode($ref));
685

686 687
	    # Skip lan nodes; they are fake.
	    next
688
		if (GeniXML::IsLanNode($ref));
689

690 691 692
	    my $node_nickname = GeniXML::GetVirtualId($ref);
	    my $colocate      = GeniXML::GetText("colocate", $ref) ||
		                GeniXML::GetText("phys_nickname", $ref);
693
	    my $resource_uuid = GeniXML::GetNodeId($ref);
694
	    my $node = LookupNode($resource_uuid);
695 696
	    if (!defined($node)) {
		$response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
Leigh B. Stoller's avatar
Leigh B. Stoller committed
697
				 "Bad resource $resource_uuid in ticket");
698 699 700
		goto bad;
	    }

701 702 703 704 705 706
	    #
	    # Grab the reservation. For backwards compatibility, we want
	    # to find nodes in the reservations holding area, and move them
	    # into the slice experiment. The holding area is no longer going
	    # to be used, at least not until we have a reservations system.
	    #
707
	    my $reservation = $node->Reservation();
708
	    if (defined($reservation) &&
709
		defined($reserved_holding) &&
710 711 712 713 714 715
		$reservation->SameExperiment($reserved_holding)) {
		if ($node->MoveReservation($slice_experiment)) {
		    print STDERR "Could not move $node to $slice_experiment\n";
		    goto bad;
		}
		$node->Refresh();
716 717 718 719 720 721
	    }
	    $namemap{$node_nickname} = $node;
	    $colomap{$colocate} = $node
		if (defined($colocate));
	}
    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
722

723 724
    print $rspec->toString();

725
    foreach my $ref (GeniXML::FindNodes("n:node", $rspec)->get_nodelist()) {
726
	my $resource_uuid = GeniXML::GetNodeId($ref);
727 728 729 730 731
	my $manager_uuid  = GeniXML::GetManagerId($ref);
	my $node_nickname = GeniXML::GetVirtualId($ref);
	my $colocate      = GeniXML::GetText("colocate", $ref) ||
	                    GeniXML::GetText("phys_nickname", $ref);
	my $subnode_of    = GeniXML::GetText("subnode_of", $ref);
732
	my $virtualization_type
733
                          = GeniXML::GetText("virtualization_type", $ref);
734
	my $virtualization_subtype
735
                          = GeniXML::GetText("virtualization_subtype",
736
					     $ref);
737
	my $exclusive     = GeniXML::GetText("exclusive", $ref);
738
	my $pctype;
739
	my $osname;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
740 741
	my $node;

742
	# Let remote nodes pass through.
743
	next
744
	    if (! GeniXML::IsLocalNode($ref));
745

746 747 748 749 750
	#
	# Lan nodes are fake and do not go into the virt topo. Need
	# to remember them though, for when we do the links below.
	# They are still in the returned ticket though. 
	#
751
	if (GeniXML::IsLanNode($ref)) {
752 753 754 755
	    $lannodes{$node_nickname} = $ref;
	    next;
	}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
756 757 758
	if (defined($virtualization_type)) {
	    if ($virtualization_type eq "emulab-vnode") {
		if (defined($virtualization_subtype)) {
759 760
		    $pctype = "pcvm";
		    
Leigh B. Stoller's avatar
Leigh B. Stoller committed
761 762 763 764 765 766
		    if ($virtualization_subtype eq "emulab-jail") {
			$osname = "FBSD-JAIL";
		    }
		    elsif ($virtualization_subtype eq "emulab-openvz") {
			$osname = "OPENVZ-STD";
		    }
767 768 769 770
		    elsif ($virtualization_subtype eq "emulab-spp") {
			$osname = "SPPVM-FAKE";
			$pctype = "sppvm";
			# Lets force to shared node.
771 772 773 774 775 776 777 778
			if (! GeniXML::SetText("exclusive", $ref, 0)) {
			    $response
				= GeniResponse->Create(GENIRESPONSE_BADARGS,
						       undef,
						       "Malformed rspec: Cannot set exclusive tag to false");
			    goto bad;
			}
			$exclusive = 0;
779 780
			# Kludge for libvtop.
			$virtexperiment->multiplex_factor(1);
781
			$virtexperiment->encap_style("vlan");
782
		    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
783 784 785 786 787 788 789 790
		}
		else {
		    goto raw;
		}
	    }
	    else {
	      raw:
		# Lets force to exclusive real node.
791 792 793 794 795 796 797 798 799 800 801 802 803
		if (! GeniXML::SetText("exclusive", $ref, 1)) {
		    $response = GeniResponse->Create(GENIRESPONSE_BADARGS,
						     undef,
						     "Malformed rspec: Cannot set exclusive tag to true");
		    goto bad;
		}
		$exclusive = 1;
		if (! GeniXML::SetText("virtualization_type", $ref, "raw")) {
		    $response = GeniResponse->Create(GENIRESPONSE_BADARGS,
						     undef,
						     "Malformed rspec: Cannot set virtualization_type to raw");
		    goto bad;
		}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
804 805 806 807
	    }
	}
	else {
	    $response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
808
				     "Must provide a virtualization_type");
Leigh B. Stoller's avatar
Leigh B. Stoller committed
809 810 811
	    goto bad;

	}
812 813 814 815 816 817
	if (!defined($node_nickname)) {
	    $response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
				     "Must provide a virtual_id for nodes");
	    goto bad;
	}

Leigh B. Stoller's avatar
Leigh B. Stoller committed
818
	#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
819
	# Allow wildcarding.
Leigh B. Stoller's avatar
Leigh B. Stoller committed
820
	#
821 822 823 824 825 826
	if (!defined($resource_uuid) || $resource_uuid eq "*") {
	    if (defined($colocate) && exists($colomap{$colocate})) {
		$node = $colomap{$colocate};
	    }
	    elsif ($isupdate && exists($namemap{$node_nickname})) {
		$node = $namemap{$node_nickname};
827
	    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
828 829
	}
	else {
830
	    $node = LookupNode($resource_uuid);
Leigh B. Stoller's avatar
Leigh B. Stoller committed
831 832 833 834 835 836 837

	    if (!defined($node)) {
		$response =
		    GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					 "Bad resource $resource_uuid");
		goto bad;
	    }
838 839
	    $pctype = $node->type()
		if (!defined($pctype));
840 841
	}
	#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
842
	# If no osname by this point, try for the default.
843 844
	#
	if (defined($node) && !defined($osname)) {
845 846 847 848 849
	    if (defined($node->default_osid())) {	    
		my $osinfo = OSinfo->Lookup($node->default_osid());
		$osname = $osinfo->osname()
		    if (defined($osinfo));
	    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
850
	}
851 852 853
	# The slot does not like to be NULL.
	$osname = ""
	    if (!defined($osname));
854
	
855 856 857
	# Need some kind of default.
	$pctype = "pc"
	    if (!defined($pctype));
858
	
859 860 861 862 863
	my $nodeblob = {"vname"   => $node_nickname,
			"type"    => $pctype,
			"osname"  => $osname,
			"ips"     => '', # deprecated
			"cmd_line"=> '', # bogus
Leigh B. Stoller's avatar
Leigh B. Stoller committed
864 865
			"fixed"   => (defined($subnode_of) ? $subnode_of :
				      defined($node) ? $node->node_id() : ""),
866
			};
867 868

	# Tarball and startup command.
869
	my $startupcmd = GeniXML::GetText("startup_command", $ref);
870
	if (defined($startupcmd)) {
871 872 873 874 875 876 877 878 879
	    if (! TBcheck_dbslot($startupcmd, "virt_nodes", "startupcmd",
			 TBDB_CHECKDBSLOT_WARN|TBDB_CHECKDBSLOT_ERROR)) {
		$response =
		    GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					 "Invalid startup command");
		goto bad;
	    }
	    $nodeblob->{'startupcmd'} = $startupcmd;
	}
880
	my $tarfiles = GeniXML::GetText("tarfiles", $ref);
881
	if (defined($tarfiles)) {
882
	    if (! TBcheck_dbslot($tarfiles, "virt_nodes", "tarfiles",
883 884 885 886 887 888
			 TBDB_CHECKDBSLOT_WARN|TBDB_CHECKDBSLOT_ERROR)) {
		$response =
		    GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
					 "Invalid tarfiles");
		goto bad;
	    }
889
	    $nodeblob->{'tarfiles'} = $tarfiles;
890 891 892 893 894 895 896 897
	}

	my $virtnode = $virtexperiment->NewTableRow("virt_nodes", $nodeblob);
	if (!defined($virtnode)) {
	    $response = GeniResponse->Create(GENIRESPONSE_ERROR, undef,
					     "Error creating virtnode");
	    goto bad;
	}
898

Leigh B. Stoller's avatar
Leigh B. Stoller committed
899 900 901 902 903 904 905 906 907 908
	$virtexperiment->NewTableRow("virt_node_desires",
				     {"vname"    => $node_nickname,
				      "desire"   => "pcshared",
				      "weight"   => 0.95})
	    if (!defined($exclusive) || !$exclusive);

	# Store reference so we can munge it below. 
	$nodemap{$node_nickname} = {"rspec"    => $ref,
				    "virtnode" => $virtnode};
	
909 910 911 912
	#
	# Look for interface forward declarations that will be used later
	# in the link specifications. 
	#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
913
	next
914
	    if (!defined(GeniXML::FindFirst("n:interface", $ref)));
Leigh B. Stoller's avatar
Leigh B. Stoller committed
915
	
916
	foreach my $linkref (GeniXML::FindNodes("n:interface",
917
						$ref)->get_nodelist()) {
918 919
	    my $component_id = GeniXML::GetText("component_id", $linkref);
	    my $virtual_id   = GeniXML::GetText("virtual_id", $linkref);
920 921 922 923 924 925 926 927 928 929

	    if (!defined($virtual_id)) {
		$response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
			     "Must provide a virtual_id for interfaces");
		goto bad;
	    }
	    
	    $ifacemap{$node_nickname} = {}
	        if (!exists($ifacemap{$node_nickname}));

Leigh B. Stoller's avatar
Leigh B. Stoller committed
930 931 932
	    # port counter.
	    my $vport = scalar(keys(%{ $ifacemap{$node_nickname} }));

933
	    # Store reference so we can munge it below. 
Leigh B. Stoller's avatar
Leigh B. Stoller committed
934 935
	    $ifacemap{$node_nickname}->{$virtual_id} = {"rspec" => $linkref,
							"vport" => $vport};
Leigh B. Stoller's avatar
Leigh B. Stoller committed
936

Leigh B. Stoller's avatar
Leigh B. Stoller committed
937
	    # This is used after the mapper runs since it uses vname:vport.
938
	    $vportmap{"$node_nickname:$vport"} = $linkref;
Leigh B. Stoller's avatar
Leigh B. Stoller committed
939
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
940 941
    }

942
    goto skiplinks
943
	if (!defined(GeniXML::FindFirst("n:link", $rspec)));
944
    
945 946 947 948
    #
    # Now deal with links for wildcarded nodes. We need to fill in the
    # node_uuid.
    #
Leigh B. Stoller's avatar
Leigh B. Stoller committed
949 950
    my $linknum = 1;
    
951
    foreach my $linkref (GeniXML::FindNodes("n:link",
952
					    $rspec)->get_nodelist()) {
953 954 955 956
	my $lanname    = GeniXML::GetVirtualId($linkref);
	my $istunnel   = (GeniXML::GetText("link_type", $linkref) eq "tunnel");
	my @interfaces = GeniXML::FindNodes("n:linkendpoints | ".
					    "n:interface_ref",
957
					    $linkref)->get_nodelist();
Leigh B. Stoller's avatar
Leigh B. Stoller committed
958
	my $ifacenum   = 1;
959
	my $trivial_ok = 0;
960

961
	if (!defined($lanname)) {
962 963 964 965
	    $response = GeniResponse->Create(GENIRESPONSE_BADARGS, undef,
				     "Must provide a virtual_id for links");
	    goto bad;
	}
Leigh B. Stoller's avatar
Leigh B. Stoller committed
966

967 968 969 970 971 972 973
	#
	# Ick. Before we create the virt_lan_lans entry, we have to check
	# inside to see if one of the interfaces is connected to a lan
	# node. In this case, we want to reuse (if its been created) the
	# lan name, rather then a bunch of links with one interface, which
	# would result in a bogus topology. 
	#
Leigh B. Stoller's avatar
Leigh B. Stoller committed
974
	if (!$istunnel) {
975
	    foreach my $ref (@interfaces) {
976 977 978
		my $node_nickname =
		    GeniXML::GetText("virtual_node_id", $ref) ||
		    GeniXML::GetText("node_nickname", $ref);
979 980 981 982 983 984 985 986 987

		if (exists($lannodes{$node_nickname})) {
		    $lanname = $node_nickname;
		}
	    }
	    if (!defined($virtexperiment->Find("virt_lan_lans", $lanname))) {
		$virtexperiment->NewTableRow("virt_lan_lans",
					     {"vname" => $lanname});
	    }
Leigh B. Stoller's avatar
Leigh B. Stoller committed
988
	}
989
	
990
	foreach my $ref (@interfaces) {
991 992 993 994
	    my $node_nickname = GeniXML::GetText("virtual_node_id", $ref) ||
		                GeniXML::GetText("node_nickname", $ref);
	    my $iface_id = GeniXML::GetText("virtual_interface_id", $ref) ||
		           GeniXML::GetText("iface_name", $ref);
995

996
	    if (!defined($node_nickname)) {
997 998
		$response =
		    GeniResponse->Create(GENIRESPONSE_ERROR, undef,
999
				 "$lanname: Need node id for links");
1000 1001 1002 1003 1004
		goto bad;
	    }
	    if (!defined($iface_id)) {
		$response =
		    GeniResponse->Create(GENIRESPONSE_ERROR, undef,
1005
				 "$lanname: Need interface id for links");
1006 1007 1008
		goto bad;
	    }

1009 1010 1011 1012 1013 1014 1015 1016 1017
	    #
	    # Look for links that are really lans; one of the interfaces
	    # is on a fake lan node, which we caught above. Just skip it
	    # since in the virt topo, a lan is just a link with more then
	    # two nodes.
	    #
	    next
		if (exists($lannodes{$node_nickname}));

1018
	    if ($istunnel) {
1019
		# Might be the other side. Skip for now; might bite later.
1020 1021
		next
		    if (!exists($namemap{$node_nickname}));
1022

1023 1024 1025
		# Not doing anything else.
		next;
	    }