format.py 45.9 KB
Newer Older
Łukasz Nowak's avatar
Łukasz Nowak committed
1
# -*- coding: utf-8 -*-
Marco Mariani's avatar
Marco Mariani committed
2
# vim: set et sts=2:
Łukasz Nowak's avatar
Łukasz Nowak committed
3 4
##############################################################################
#
5 6
# Copyright (c) 2010, 2011, 2012 Vifib SARL and Contributors.
# All Rights Reserved.
Łukasz Nowak's avatar
Łukasz Nowak committed
7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29
#
# WARNING: This program as such is intended to be used by professional
# programmers who take the whole responsibility of assessing all potential
# consequences resulting from its eventual inadequacies and bugs
# End users who are looking for a ready-to-use solution with commercial
# guarantees and support are strongly advised to contract a Free Software
# Service Company
#
# This program is Free Software; you can redistribute it and/or
# modify it under the terms of the GNU General Public License
# as published by the Free Software Foundation; either version 3
# of the License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the Free Software
# Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA  02111-1307, USA.
#
##############################################################################
30

Łukasz Nowak's avatar
Łukasz Nowak committed
31 32 33
from optparse import OptionParser, Option
from xml_marshaller import xml_marshaller
import ConfigParser
34 35
import errno
import fcntl
Łukasz Nowak's avatar
Łukasz Nowak committed
36
import grp
37
import json
Łukasz Nowak's avatar
Łukasz Nowak committed
38 39 40 41
import logging
import netaddr
import netifaces
import os
Łukasz Nowak's avatar
Łukasz Nowak committed
42
import pwd
Łukasz Nowak's avatar
Łukasz Nowak committed
43 44 45
import random
import slapos.slap as slap
import socket
46
import struct
Łukasz Nowak's avatar
Łukasz Nowak committed
47 48
import subprocess
import sys
49
import threading
Łukasz Nowak's avatar
Łukasz Nowak committed
50
import time
Marco Mariani's avatar
Marco Mariani committed
51 52 53
import zipfile

import lxml.etree
54
from slapos.version import version
Marco Mariani's avatar
Marco Mariani committed
55 56


Cédric de Saint Martin's avatar
Cédric de Saint Martin committed
57 58 59 60 61
# set up logging
logger = logging.getLogger("slapformat")
logger.setLevel(logging.INFO)


Marco Mariani's avatar
Marco Mariani committed
62 63 64 65
def prettify_xml(xml):
  root = lxml.etree.fromstring(xml)
  return lxml.etree.tostring(root, pretty_print=True)

Łukasz Nowak's avatar
Łukasz Nowak committed
66

67
from slapos.util import mkdir_p
68
from slapos.util import chownDirectory
69

Vincent Pelletier's avatar
Vincent Pelletier committed
70
class OS(object):
71 72
  """Wrap parts of the 'os' module to provide logging of performed actions."""

Vincent Pelletier's avatar
Vincent Pelletier committed
73 74 75
  _os = os

  def __init__(self, config):
76
    self._dry_run = config.dry_run
Vincent Pelletier's avatar
Vincent Pelletier committed
77 78 79 80 81 82 83 84 85 86 87 88
    self._verbose = config.verbose
    self._logger = config.logger
    add = self._addWrapper
    add('chown')
    add('chmod')
    add('makedirs')
    add('mkdir')

  def _addWrapper(self, name):
    def wrapper(*args, **kw):
      if self._verbose:
        arg_list = [repr(x) for x in args] + [
Marco Mariani's avatar
Marco Mariani committed
89 90 91
                '%s=%r' % (x, y) for x, y in kw.iteritems()
                ]
        self._logger.debug('%s(%s)' % (name, ', '.join(arg_list)))
92 93
      if not self._dry_run:
        getattr(self._os, name)(*args, **kw)
Vincent Pelletier's avatar
Vincent Pelletier committed
94 95 96 97
    setattr(self, name, wrapper)

  def __getattr__(self, name):
    return getattr(self._os, name)
Łukasz Nowak's avatar
Łukasz Nowak committed
98

99

100 101 102
class UsageError(Exception):
  pass

103

104
class NoAddressOnInterface(Exception):
Łukasz Nowak's avatar
Łukasz Nowak committed
105
  """
Marco Mariani's avatar
Marco Mariani committed
106
  Exception raised if there is no address on the interface to construct IPv6
107 108 109
  address with.

  Attributes:
110
    brige: String, the name of the interface.
Łukasz Nowak's avatar
Łukasz Nowak committed
111 112
  """

113 114
  def __init__(self, interface):
    super(NoAddressOnInterface, self).__init__(
Marco Mariani's avatar
Marco Mariani committed
115
      'No IPv6 found on interface %s to construct IPv6 with.' % interface
116
    )
Łukasz Nowak's avatar
Łukasz Nowak committed
117

118

119 120 121
class AddressGenerationError(Exception):
  """
  Exception raised if the generation of an IPv6 based on the prefix obtained
122
  from the interface failed.
123 124 125 126 127 128 129 130

  Attributes:
    addr: String, the invalid address the exception is raised for.
  """
  def __init__(self, addr):
    super(AddressGenerationError, self).__init__(
      'Generated IPv6 %s seems not to be a valid IP.' % addr
    )
Łukasz Nowak's avatar
Łukasz Nowak committed
131

132

Łukasz Nowak's avatar
Łukasz Nowak committed
133
def callAndRead(argument_list, raise_on_error=True):
Marco Mariani's avatar
Marco Mariani committed
134 135 136
  popen = subprocess.Popen(argument_list,
                           stdout=subprocess.PIPE,
                           stderr=subprocess.STDOUT)
Łukasz Nowak's avatar
Łukasz Nowak committed
137 138
  result = popen.communicate()[0]
  if raise_on_error and popen.returncode != 0:
139
    raise ValueError('Issue while invoking %r, result was:\n%s' % (
Marco Mariani's avatar
Marco Mariani committed
140
                     argument_list, result))
Łukasz Nowak's avatar
Łukasz Nowak committed
141 142
  return popen.returncode, result

143

Łukasz Nowak's avatar
Łukasz Nowak committed
144 145 146 147 148 149
def isGlobalScopeAddress(a):
  """Returns True if a is global scope IP v4/6 address"""
  ip = netaddr.IPAddress(a)
  return not ip.is_link_local() and not ip.is_loopback() and \
      not ip.is_reserved() and ip.is_unicast()

150

Łukasz Nowak's avatar
Łukasz Nowak committed
151 152 153 154 155
def netmaskToPrefixIPv4(netmask):
  """Convert string represented netmask to its integer prefix"""
  return netaddr.strategy.ipv4.netmask_to_prefix[
          netaddr.strategy.ipv4.str_to_int(netmask)]

156

Łukasz Nowak's avatar
Łukasz Nowak committed
157 158 159 160 161
def netmaskToPrefixIPv6(netmask):
  """Convert string represented netmask to its integer prefix"""
  return netaddr.strategy.ipv6.netmask_to_prefix[
          netaddr.strategy.ipv6.str_to_int(netmask)]

162

Łukasz Nowak's avatar
Łukasz Nowak committed
163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179
def _getDict(instance):
  """
  Serialize an object instance into dictionaries. List and dict will remains
  the same, basic type too. But encapsulated object will be returned as dict.
  Set, collections and other aren't handle for now.

  Args:
    instance: an object of any type.

  Returns:
    A dictionary if the given object wasn't a list, a list otherwise.
  """
  if isinstance(instance, list):
    return [_getDict(item) for item in instance]

  elif isinstance(instance, dict):
    result = {}
180
    for key in instance:
Łukasz Nowak's avatar
Łukasz Nowak committed
181 182 183 184 185
      result[key] = _getDict(instance[key])
    return result

  else:
    try:
186
      dikt = instance.__dict__
Łukasz Nowak's avatar
Łukasz Nowak committed
187 188
    except AttributeError:
      return instance
189 190 191 192
    result = {}
    for key, value in dikt.iteritems():
      result[key] = _getDict(value)
    return result
Łukasz Nowak's avatar
Łukasz Nowak committed
193

194

Vincent Pelletier's avatar
Vincent Pelletier committed
195
class Computer(object):
Łukasz Nowak's avatar
Łukasz Nowak committed
196
  "Object representing the computer"
197 198
  instance_root = None
  software_root = None
Łukasz Nowak's avatar
Łukasz Nowak committed
199

200
  def __init__(self, reference, interface=None, addr=None, netmask=None,
Marco Mariani's avatar
Marco Mariani committed
201
               ipv6_interface=None, software_user='slapsoft'):
Łukasz Nowak's avatar
Łukasz Nowak committed
202 203 204
    """
    Attributes:
      reference: String, the reference of the computer.
205
      interface: String, the name of the computer's used interface.
Łukasz Nowak's avatar
Łukasz Nowak committed
206 207
    """
    self.reference = str(reference)
208
    self.interface = interface
Łukasz Nowak's avatar
Łukasz Nowak committed
209 210 211
    self.partition_list = []
    self.address = addr
    self.netmask = netmask
Łukasz Nowak's avatar
Łukasz Nowak committed
212
    self.ipv6_interface = ipv6_interface
213
    self.software_user = software_user
Łukasz Nowak's avatar
Łukasz Nowak committed
214 215

  def __getinitargs__(self):
216
    return (self.reference, self.interface)
Łukasz Nowak's avatar
Łukasz Nowak committed
217

218
  def getAddress(self, allow_tap=False):
Łukasz Nowak's avatar
Łukasz Nowak committed
219
    """
Marco Mariani's avatar
Marco Mariani committed
220
    Return a list of the interface address not attributed to any partition (which
Łukasz Nowak's avatar
Łukasz Nowak committed
221 222 223
    are therefore free for the computer itself).

    Returns:
224
      False if the interface isn't available, else the list of the free addresses.
Łukasz Nowak's avatar
Łukasz Nowak committed
225
    """
226
    if self.interface is None:
Marco Mariani's avatar
Marco Mariani committed
227
      return {'addr': self.address, 'netmask': self.netmask}
Łukasz Nowak's avatar
Łukasz Nowak committed
228 229 230 231 232 233

    computer_partition_address_list = []
    for partition in self.partition_list:
      for address in partition.address_list:
        if netaddr.valid_ipv6(address['addr']):
          computer_partition_address_list.append(address['addr'])
234
    # Going through addresses of the computer's interface
235
    for address_dict in self.interface.getGlobalScopeAddressList():
Łukasz Nowak's avatar
Łukasz Nowak committed
236 237 238 239
      # Comparing with computer's partition addresses
      if address_dict['addr'] not in computer_partition_address_list:
        return address_dict

240
    if allow_tap:
Marco Mariani's avatar
Marco Mariani committed
241
      # all addresses on interface are for partition, so let's add new one
242 243 244 245 246 247
      computer_tap = Tap('compdummy')
      computer_tap.createWithOwner(User('root'), attach_to_tap=True)
      self.interface.addTap(computer_tap)
      return self.interface.addAddr()

    # Can't find address
Marco Mariani's avatar
Marco Mariani committed
248
    raise NoAddressOnInterface('No valid IPv6 found on %s.' % self.interface.name)
Łukasz Nowak's avatar
Łukasz Nowak committed
249 250 251 252 253 254 255 256 257

  def send(self, config):
    """
    Send a marshalled dictionary of the computer object serialized via_getDict.
    """

    slap_instance = slap.slap()
    connection_dict = {}
    if config.key_file and config.cert_file:
Marco Mariani's avatar
Marco Mariani committed
258 259
      connection_dict['key_file'] = config.key_file
      connection_dict['cert_file'] = config.cert_file
Łukasz Nowak's avatar
Łukasz Nowak committed
260
    slap_instance.initializeConnection(config.master_url,
Marco Mariani's avatar
Marco Mariani committed
261
                                       **connection_dict)
Łukasz Nowak's avatar
Łukasz Nowak committed
262
    slap_computer = slap_instance.registerComputer(self.reference)
Marco Mariani's avatar
Marco Mariani committed
263

264 265
    if config.dry_run:
      return
266
    try:
267
      slap_computer.updateConfiguration(xml_marshaller.dumps(_getDict(self)))
268 269 270 271
    except slap.NotFoundError as error:
      raise slap.NotFoundError("%s\nERROR : This SlapOS node is not recognised by "
          "SlapOS Master. Please make sure computer_id of slapos.cfg looks "
          "like 'COMP-123' and is correct.\nError is : 404 Not Found." % error)
Łukasz Nowak's avatar
Łukasz Nowak committed
272

273
  def dump(self, path_to_xml, path_to_json):
Łukasz Nowak's avatar
Łukasz Nowak committed
274 275 276 277 278
    """
    Dump the computer object to an xml file via xml_marshaller.

    Args:
      path_to_xml: String, path to the file to load.
Marco Mariani's avatar
Marco Mariani committed
279
      path_to_json: String, path to the JSON version to save.
Łukasz Nowak's avatar
Łukasz Nowak committed
280 281 282
    """

    computer_dict = _getDict(self)
283 284 285 286 287

    if path_to_json:
      with open(path_to_json, 'wb') as fout:
        fout.write(json.dumps(computer_dict, sort_keys=True, indent=2))

Marco Mariani's avatar
Marco Mariani committed
288 289 290 291 292 293 294 295 296 297 298 299
    new_xml = xml_marshaller.dumps(computer_dict)
    new_pretty_xml = prettify_xml(new_xml)

    path_to_archive = path_to_xml + '.zip'

    if os.path.exists(path_to_archive):
      # the archive file exists, we only backup if something has changed
      with open(path_to_xml, 'rb') as fin:
        if fin.read() == new_pretty_xml:
          # computer configuration did not change, nothing to write
          return

300 301
    if os.path.exists(path_to_xml):
      self.backup_xml(path_to_archive, path_to_xml)
Marco Mariani's avatar
Marco Mariani committed
302

Marco Mariani's avatar
Marco Mariani committed
303 304
    with open(path_to_xml, 'wb') as fout:
      fout.write(new_pretty_xml)
Marco Mariani's avatar
Marco Mariani committed
305 306 307


  def backup_xml(self, path_to_archive, path_to_xml):
Marco Mariani's avatar
Marco Mariani committed
308 309 310
    """
    Stores a copy of the current xml file to an historical archive.
    """
Marco Mariani's avatar
Marco Mariani committed
311
    xml_content = open(path_to_xml).read()
Marco Mariani's avatar
typo  
Marco Mariani committed
312
    saved_filename = os.path.basename(path_to_xml) + time.strftime('.%Y%m%d-%H:%M')
Marco Mariani's avatar
Marco Mariani committed
313 314 315 316

    with zipfile.ZipFile(path_to_archive, 'a') as archive:
      archive.writestr(saved_filename, xml_content, zipfile.ZIP_DEFLATED)

Łukasz Nowak's avatar
Łukasz Nowak committed
317 318

  @classmethod
Łukasz Nowak's avatar
Łukasz Nowak committed
319
  def load(cls, path_to_xml, reference, ipv6_interface):
Łukasz Nowak's avatar
Łukasz Nowak committed
320 321 322 323 324 325 326 327
    """
    Create a computer object from a valid xml file.

    Arg:
      path_to_xml: String, a path to a valid file containing
          a valid configuration.

    Return:
328
      A Computer object.
Łukasz Nowak's avatar
Łukasz Nowak committed
329 330 331 332 333 334 335 336 337
    """

    dumped_dict = xml_marshaller.loads(open(path_to_xml).read())

    # Reconstructing the computer object from the xml
    computer = Computer(
        reference = reference,
        addr = dumped_dict['address'],
        netmask = dumped_dict['netmask'],
Marco Mariani's avatar
Marco Mariani committed
338 339
        ipv6_interface = ipv6_interface,
        software_user = dumped_dict.get('software_user', 'slapsoft'),
Łukasz Nowak's avatar
Łukasz Nowak committed
340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367
    )

    for partition_dict in dumped_dict['partition_list']:

      if partition_dict['user']:
        user = User(partition_dict['user']['name'])
      else:
        user = User('root')

      if partition_dict['tap']:
        tap = Tap(partition_dict['tap']['name'])
      else:
        tap = Tap(partition_dict['reference'])

      address_list = partition_dict['address_list']

      partition = Partition(
          reference = partition_dict['reference'],
          path = partition_dict['path'],
          user = user,
          address_list = address_list,
          tap = tap,
      )

      computer.partition_list.append(partition)

    return computer

368
  def construct(self, alter_user=True, alter_network=True, create_tap=True):
Łukasz Nowak's avatar
Łukasz Nowak committed
369 370 371 372
    """
    Construct the computer object as it is.
    """
    if alter_network and self.address is not None:
373
      self.interface.addAddr(self.address, self.netmask)
Łukasz Nowak's avatar
Łukasz Nowak committed
374

375
    for path in self.instance_root, self.software_root:
Łukasz Nowak's avatar
Łukasz Nowak committed
376 377 378 379 380
      if not os.path.exists(path):
        os.makedirs(path, 0755)
      else:
        os.chmod(path, 0755)

381 382
    # own self.software_root by software user
    slapsoft = User(self.software_user)
Łukasz Nowak's avatar
Łukasz Nowak committed
383 384 385
    slapsoft.path = self.software_root
    if alter_user:
      slapsoft.create()
Łukasz Nowak's avatar
Łukasz Nowak committed
386
      slapsoft_pw = pwd.getpwnam(slapsoft.name)
387
      chownDirectory(path, uid, gid)
Łukasz Nowak's avatar
Łukasz Nowak committed
388 389
    os.chmod(self.software_root, 0755)

390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405
    # Speed hack:
    # Blindly add all IPs from existing configuration, just to speed up actual
    # computer configuration later on.
    for partition in self.partition_list:
      try:
        for address in partition.address_list:
          try:
            netmask = netmaskToPrefixIPv6(address['netmask'])
          except:
            continue
          callAndRead(['ip', 'addr', 'add',
                       '%s/%s' % (address['addr'], netmask),
                       'dev', self.interface.name])
      except ValueError:
        pass

406 407 408 409 410 411 412 413 414 415 416 417 418 419 420
    try:
      for partition_index, partition in enumerate(self.partition_list):
        # Reconstructing User's
        partition.path = os.path.join(self.instance_root, partition.reference)
        partition.user.setPath(partition.path)
        partition.user.additional_group_list = [slapsoft.name]
        if alter_user:
          partition.user.create()

        # Reconstructing Tap
        if partition.user and partition.user.isAvailable():
          owner = partition.user
        else:
          owner = User('root')

421
        if alter_network and create_tap:
422
          # In case it has to be  attached to the TAP network device, only one
423 424
          # is necessary for the interface to assert carrier
          if self.interface.attach_to_tap and partition_index == 0:
425
            partition.tap.createWithOwner(owner, attach_to_tap=True)
Łukasz Nowak's avatar
Łukasz Nowak committed
426
          else:
427 428
            partition.tap.createWithOwner(owner)

429
          self.interface.addTap(partition.tap)
430 431 432 433 434 435 436 437 438 439

        # Reconstructing partition's directory
        partition.createPath(alter_user)

        # Reconstructing partition's address
        # There should be two addresses on each Computer Partition:
        #  * global IPv6
        #  * local IPv4, took from slapformat:ipv4_local_network
        if len(partition.address_list) == 0:
          # regenerate
440 441
          partition.address_list.append(self.interface.addIPv4LocalAddress())
          partition.address_list.append(self.interface.addAddr())
442 443 444 445 446
        elif alter_network:
          # regenerate list of addresses
          old_partition_address_list = partition.address_list
          partition.address_list = []
          if len(old_partition_address_list) != 2:
447 448 449
            raise ValueError(
              'There should be exactly 2 stored addresses. Got: %r' %
              (old_partition_address_list,))
Vincent Pelletier's avatar
Vincent Pelletier committed
450 451
          if not any([netaddr.valid_ipv6(q['addr'])
              for q in old_partition_address_list]):
452
            raise ValueError('Not valid ipv6 addresses loaded')
Vincent Pelletier's avatar
Vincent Pelletier committed
453 454
          if not any([netaddr.valid_ipv4(q['addr'])
              for q in old_partition_address_list]):
455
            raise ValueError('Not valid ipv6 addresses loaded')
Marco Mariani's avatar
Marco Mariani committed
456

457 458
          for address in old_partition_address_list:
            if netaddr.valid_ipv6(address['addr']):
459
              partition.address_list.append(self.interface.addAddr(
Vincent Pelletier's avatar
Vincent Pelletier committed
460 461
                address['addr'],
                address['netmask']))
462
            elif netaddr.valid_ipv4(address['addr']):
463
              partition.address_list.append(self.interface.addIPv4LocalAddress(
Vincent Pelletier's avatar
Vincent Pelletier committed
464
                address['addr']))
465 466 467
            else:
              raise ValueError('Address %r is incorrect' % address['addr'])
    finally:
468
      if alter_network and create_tap and self.interface.attach_to_tap:
469 470 471 472
        try:
          self.partition_list[0].tap.detach()
        except IndexError:
          pass
Łukasz Nowak's avatar
Łukasz Nowak committed
473

474

Vincent Pelletier's avatar
Vincent Pelletier committed
475
class Partition(object):
Łukasz Nowak's avatar
Łukasz Nowak committed
476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498
  "Represent a computer partition"

  def __init__(self, reference, path, user, address_list, tap):
    """
    Attributes:
      reference: String, the name of the partition.
      path: String, the path to the partition folder.
      user: User, the user linked to this partition.
      address_list: List of associated IP addresses.
      tap: Tap, the tap interface linked to this partition.
    """

    self.reference = str(reference)
    self.path = str(path)
    self.user = user
    self.address_list = address_list or []
    self.tap = tap

  def __getinitargs__(self):
    return (self.reference, self.path, self.user, self.address_list, self.tap)

  def createPath(self, alter_user=True):
    """
Vincent Pelletier's avatar
Vincent Pelletier committed
499 500
    Create the directory of the partition, assign to the partition user and
    give it the 750 permission. In case if path exists just modifies it.
Łukasz Nowak's avatar
Łukasz Nowak committed
501 502
    """

503
    self.path = os.path.abspath(self.path)
Łukasz Nowak's avatar
Łukasz Nowak committed
504
    owner = self.user if self.user else User('root')
505 506
    if not os.path.exists(self.path):
      os.mkdir(self.path, 0750)
Łukasz Nowak's avatar
Łukasz Nowak committed
507
    if alter_user:
Łukasz Nowak's avatar
Łukasz Nowak committed
508
      owner_pw = pwd.getpwnam(owner.name)
509
      chownDirectory(path, uid, gid)
510
    os.chmod(self.path, 0750)
Łukasz Nowak's avatar
Łukasz Nowak committed
511

512

Vincent Pelletier's avatar
Vincent Pelletier committed
513
class User(object):
Marco Mariani's avatar
Marco Mariani committed
514 515
  """User: represent and manipulate a user on the system."""

516
  path = None
Łukasz Nowak's avatar
Łukasz Nowak committed
517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542

  def __init__(self, user_name, additional_group_list=None):
    """
    Attributes:
        user_name: string, the name of the user, who will have is home in
    """
    self.name = str(user_name)
    self.additional_group_list = additional_group_list

  def __getinitargs__(self):
    return (self.name,)

  def setPath(self, path):
    self.path = path

  def create(self):
    """
    Create a user on the system who will be named after the self.name with its
    own group and directory.

    Returns:
        True: if the user creation went right
    """
    # XXX: This method shall be no-op in case if all is correctly setup
    #      This method shall check if all is correctly done
    #      This method shall not reset groups, just add them
Jondy Zhao's avatar
Jondy Zhao committed
543
    grpname = 'grp_' + self.name if sys.platform == 'cygwin' else self.name
Łukasz Nowak's avatar
Łukasz Nowak committed
544
    try:
Jondy Zhao's avatar
Jondy Zhao committed
545
      grp.getgrnam(grpname)
Łukasz Nowak's avatar
Łukasz Nowak committed
546
    except KeyError:
Jondy Zhao's avatar
Jondy Zhao committed
547
      callAndRead(['groupadd', grpname])
Łukasz Nowak's avatar
Łukasz Nowak committed
548

Vincent Pelletier's avatar
Vincent Pelletier committed
549 550
    user_parameter_list = ['-d', self.path, '-g', self.name, '-s',
      '/bin/false']
Łukasz Nowak's avatar
Łukasz Nowak committed
551 552 553 554
    if self.additional_group_list is not None:
      user_parameter_list.extend(['-G', ','.join(self.additional_group_list)])
    user_parameter_list.append(self.name)
    try:
Łukasz Nowak's avatar
Łukasz Nowak committed
555
      pwd.getpwnam(self.name)
Łukasz Nowak's avatar
Łukasz Nowak committed
556
    except KeyError:
557
      user_parameter_list.append('-r')
Łukasz Nowak's avatar
Łukasz Nowak committed
558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573
      callAndRead(['useradd'] + user_parameter_list)
    else:
      callAndRead(['usermod'] + user_parameter_list)

    return True

  def isAvailable(self):
    """
    Determine the availability of a user on the system

    Return:
        True: if available
        False: otherwise
    """

    try:
Łukasz Nowak's avatar
Łukasz Nowak committed
574
      pwd.getpwnam(self.name)
Łukasz Nowak's avatar
Łukasz Nowak committed
575 576 577 578
      return True
    except KeyError:
      return False

579

Vincent Pelletier's avatar
Vincent Pelletier committed
580
class Tap(object):
Łukasz Nowak's avatar
Łukasz Nowak committed
581
  "Tap represent a tap interface on the system"
582 583 584
  IFF_TAP = 0x0002
  TUNSETIFF = 0x400454ca
  KEEP_TAP_ATTACHED_EVENT = threading.Event()
Łukasz Nowak's avatar
Łukasz Nowak committed
585 586 587 588 589 590 591 592 593 594 595 596

  def __init__(self, tap_name):
    """
    Attributes:
        tap_name: String, the name of the tap interface.
    """

    self.name = str(tap_name)

  def __getinitargs__(self):
    return (self.name,)

597 598 599
  def attach(self):
    """
    Attach to the TAP interface, meaning  that it just opens the TAP interface
Marco Mariani's avatar
Marco Mariani committed
600
    and waits for the caller to notify that it can be safely detached.
601 602 603 604 605 606 607 608

    Linux  distinguishes administrative  and operational  state of  an network
    interface.  The  former can be set  manually by running ``ip  link set dev
    <dev> up|down'', whereas the latter states that the interface can actually
    transmit  data (for  a wired  network interface,  it basically  means that
    there is  carrier, e.g.  the network  cable is plugged  into a  switch for
    example).

609
    In case of bridge:
610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627
    In order  to be able to check  the uniqueness of IPv6  address assigned to
    the bridge, the network interface  must be up from an administrative *and*
    operational point of view.

    However,  from  Linux  2.6.39,  the  bridge  reflects  the  state  of  the
    underlying device (e.g.  the bridge asserts carrier if at least one of its
    ports has carrier) whereas it  always asserted carrier before. This should
    work fine for "real" network interface,  but will not work properly if the
    bridge only binds TAP interfaces, which, from 2.6.36, reports carrier only
    and only if an userspace program is attached.
    """
    tap_fd = os.open("/dev/net/tun", os.O_RDWR)

    try:
      # Attach to the TAP interface which has previously been created
      fcntl.ioctl(tap_fd, self.TUNSETIFF,
                  struct.pack("16sI", self.name, self.IFF_TAP))

628
    except IOError as error:
629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649
      # If  EBUSY, it  means another  program is  already attached,  thus just
      # ignore it...
      if error.errno != errno.EBUSY:
        os.close(tap_fd)
        raise
    else:
      # Block until the  caller send an event stating that  the program can be
      # now detached safely,  thus bringing down the TAP  device (from 2.6.36)
      # and the bridge at the same time (from 2.6.39)
      self.KEEP_TAP_ATTACHED_EVENT.wait()
    finally:
      os.close(tap_fd)

  def detach(self):
    """
    Detach to the  TAP network interface by notifying  the thread which attach
    to the TAP and closing the TAP file descriptor
    """
    self.KEEP_TAP_ATTACHED_EVENT.set()

  def createWithOwner(self, owner, attach_to_tap=False):
Łukasz Nowak's avatar
Łukasz Nowak committed
650 651 652 653 654 655 656 657 658
    """
    Create a tap interface on the system.
    """

    # some systems does not have -p switch for tunctl
    #callAndRead(['tunctl', '-p', '-t', self.name, '-u', owner.name])
    check_file = '/sys/devices/virtual/net/%s/owner' % self.name
    owner_id = None
    if os.path.exists(check_file):
659
      owner_id = open(check_file).read().strip()
Łukasz Nowak's avatar
Łukasz Nowak committed
660
      try:
661 662
        owner_id = int(owner_id)
      except ValueError:
Łukasz Nowak's avatar
Łukasz Nowak committed
663
        pass
664
    if owner_id != pwd.getpwnam(owner.name).pw_uid:
Łukasz Nowak's avatar
Łukasz Nowak committed
665 666 667
      callAndRead(['tunctl', '-t', self.name, '-u', owner.name])
    callAndRead(['ip', 'link', 'set', self.name, 'up'])

668 669 670
    if attach_to_tap:
      threading.Thread(target=self.attach).start()

671

672
class Interface(object):
Marco Mariani's avatar
Marco Mariani committed
673
  """Represent a network interface on the system"""
Łukasz Nowak's avatar
Łukasz Nowak committed
674

675
  def __init__(self, name, ipv4_local_network, ipv6_interface=None):
Łukasz Nowak's avatar
Łukasz Nowak committed
676 677
    """
    Attributes:
678
        name: String, the name of the interface
Łukasz Nowak's avatar
Łukasz Nowak committed
679 680 681 682
    """

    self.name = str(name)
    self.ipv4_local_network = ipv4_local_network
Łukasz Nowak's avatar
Łukasz Nowak committed
683
    self.ipv6_interface = ipv6_interface
Łukasz Nowak's avatar
Łukasz Nowak committed
684

685
    # Attach to TAP  network interface, only if the  interface interface does not
686
    # report carrier
687
    _, result = callAndRead(['ip', 'addr', 'list', self.name])
688 689
    self.attach_to_tap = 'DOWN' in result.split('\n', 1)[0]

Łukasz Nowak's avatar
Łukasz Nowak committed
690 691 692 693
  def __getinitargs__(self):
    return (self.name,)

  def getIPv4LocalAddressList(self):
Vincent Pelletier's avatar
Vincent Pelletier committed
694 695 696 697
    """
    Returns currently configured local IPv4 addresses which are in
    ipv4_local_network
    """
Łukasz Nowak's avatar
Łukasz Nowak committed
698 699 700 701 702 703 704 705 706
    if not socket.AF_INET in netifaces.ifaddresses(self.name):
      return []
    return [dict(addr=q['addr'], netmask=q['netmask']) for q in
      netifaces.ifaddresses(self.name)[socket.AF_INET] if netaddr.IPAddress(
        q['addr'], 4) in netaddr.glob_to_iprange(
          netaddr.cidr_to_glob(self.ipv4_local_network))]

  def getGlobalScopeAddressList(self):
    """Returns currently configured global scope IPv6 addresses"""
Łukasz Nowak's avatar
Łukasz Nowak committed
707 708 709 710
    if self.ipv6_interface:
      interface_name = self.ipv6_interface
    else:
      interface_name = self.name
711
    try:
Vincent Pelletier's avatar
Vincent Pelletier committed
712 713 714
      address_list = [q
        for q in netifaces.ifaddresses(interface_name)[socket.AF_INET6]
        if isGlobalScopeAddress(q['addr'].split('%')[0])]
715 716
    except KeyError:
      raise ValueError("%s must have at least one IPv6 address assigned" % \
Łukasz Nowak's avatar
Łukasz Nowak committed
717
                         interface_name)
Jondy Zhao's avatar
Jondy Zhao committed
718 719 720
    if sys.platform == 'cygwin':
      for q in address_list:
        q.setdefault('netmask', 'FFFF:FFFF:FFFF:FFFF::')
Łukasz Nowak's avatar
Łukasz Nowak committed
721 722 723 724 725 726 727 728 729 730
    # XXX: Missing implementation of Unique Local IPv6 Unicast Addresses as
    # defined in http://www.rfc-editor.org/rfc/rfc4193.txt
    # XXX: XXX: XXX: IT IS DISALLOWED TO IMPLEMENT link-local addresses as
    # Linux and BSD are possibly wrongly implementing it -- it is "too local"
    # it is impossible to listen or access it on same node
    # XXX: IT IS DISALLOWED to implement ad hoc solution like inventing node
    # local addresses or anything which does not exists in RFC!
    return address_list

  def getInterfaceList(self):
731
    """Returns list of interfaces already present on bridge"""
Łukasz Nowak's avatar
Łukasz Nowak committed
732
    interface_list = []
733
    _, result = callAndRead(['brctl', 'show'])
734
    in_interface = False
Łukasz Nowak's avatar
Łukasz Nowak committed
735 736 737 738
    for line in result.split('\n'):
      if len(line.split()) > 1:
        if self.name in line:
          interface_list.append(line.split()[-1])
739
          in_interface = True
Łukasz Nowak's avatar
Łukasz Nowak committed
740
          continue
741
        if in_interface:
Łukasz Nowak's avatar
Łukasz Nowak committed
742
          break
743
      elif in_interface:
Łukasz Nowak's avatar
Łukasz Nowak committed
744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759
        if line.strip():
          interface_list.append(line.strip())

    return interface_list

  def addTap(self, tap):
    """
    Add the tap interface tap to the bridge.

    Args:
      tap: Tap, the tap interface.
    """
    if tap.name not in self.getInterfaceList():
      callAndRead(['brctl', 'addif', self.name, tap.name])

  def _addSystemAddress(self, address, netmask, ipv6=True):
760
    """Adds system address to interface
761

Łukasz Nowak's avatar
Łukasz Nowak committed
762 763 764 765 766 767 768
    Returns True if address was added successfully.

    Returns False if there was issue.
    """
    if ipv6:
      address_string = '%s/%s' % (address, netmaskToPrefixIPv6(netmask))
      af = socket.AF_INET6
Łukasz Nowak's avatar
Łukasz Nowak committed
769 770 771 772
      if self.ipv6_interface:
        interface_name = self.ipv6_interface
      else:
        interface_name = self.name
Łukasz Nowak's avatar
Łukasz Nowak committed
773 774 775
    else:
      af = socket.AF_INET
      address_string = '%s/%s' % (address, netmaskToPrefixIPv4(netmask))
Łukasz Nowak's avatar
Łukasz Nowak committed
776
      interface_name = self.name
Łukasz Nowak's avatar
Łukasz Nowak committed
777 778 779

    # check if address is already took by any other interface
    for interface in netifaces.interfaces():
Łukasz Nowak's avatar
Łukasz Nowak committed
780
      if interface != interface_name:
Łukasz Nowak's avatar
Łukasz Nowak committed
781 782
        address_dict = netifaces.ifaddresses(interface)
        if af in address_dict:
783
          if address in [q['addr'].split('%')[0] for q in address_dict[af]]:
Łukasz Nowak's avatar
Łukasz Nowak committed
784 785
            return False

Vincent Pelletier's avatar
Vincent Pelletier committed
786 787
    if not af in netifaces.ifaddresses(interface_name) \
        or not address in [q['addr'].split('%')[0]
Marco Mariani's avatar
Marco Mariani committed
788 789
                           for q in netifaces.ifaddresses(interface_name)[af]
                           ]:
Łukasz Nowak's avatar
Łukasz Nowak committed
790
      # add an address
Łukasz Nowak's avatar
Łukasz Nowak committed
791
      callAndRead(['ip', 'addr', 'add', address_string, 'dev', interface_name])
792 793 794 795 796

      # Fake success for local ipv4
      if not ipv6:
        return True

Łukasz Nowak's avatar
Łukasz Nowak committed
797 798
      # wait few moments
      time.sleep(2)
799 800 801 802 803 804

    # Fake success for local ipv4
    if not ipv6:
      return True

    # check existence on interface for ipv6
805
    _, result = callAndRead(['ip', '-6', 'addr', 'list', interface_name])
Łukasz Nowak's avatar
Łukasz Nowak committed
806 807 808 809
    for l in result.split('\n'):
      if address in l:
        if 'tentative' in l:
          # duplicate, remove
Marco Mariani's avatar
Marco Mariani committed
810
          callAndRead(['ip', 'addr', 'del', address_string, 'dev', interface_name])
Łukasz Nowak's avatar
Łukasz Nowak committed
811 812 813 814 815 816 817 818 819 820 821 822 823
          return False
        # found and clean
        return True
    # even when added not found, this is bad...
    return False

  def _generateRandomIPv4Address(self, netmask):
    # no addresses found, generate new one
    # Try 10 times to add address, raise in case if not possible
    try_num = 10
    while try_num > 0:
      addr = random.choice([q for q in netaddr.glob_to_iprange(
        netaddr.cidr_to_glob(self.ipv4_local_network))]).format()
Vincent Pelletier's avatar
Vincent Pelletier committed
824 825
      if dict(addr=addr, netmask=netmask) not in \
          self.getIPv4LocalAddressList():
Łukasz Nowak's avatar
Łukasz Nowak committed
826 827 828 829 830 831 832 833 834
        # Checking the validity of the IPv6 address
        if self._addSystemAddress(addr, netmask, False):
          return dict(addr=addr, netmask=netmask)
        try_num -= 1

    raise AddressGenerationError(addr)

  def addIPv4LocalAddress(self, addr=None):
    """Adds local IPv4 address in ipv4_local_network"""
Jondy Zhao's avatar
Jondy Zhao committed
835 836
    netmask = '255.255.255.254' if sys.platform == 'cygwin' \
             else '255.255.255.255'
Łukasz Nowak's avatar
Łukasz Nowak committed
837 838 839 840
    local_address_list = self.getIPv4LocalAddressList()
    if addr is None:
      return self._generateRandomIPv4Address(netmask)
    elif dict(addr=addr, netmask=netmask) not in local_address_list:
841 842 843
      if self._addSystemAddress(addr, netmask, False):
        return dict(addr=addr, netmask=netmask)
      else:
Cédric de Saint Martin's avatar
Cédric de Saint Martin committed
844
        logger.warning('Impossible to add old local IPv4 %s. Generating '
845
            'new IPv4 address.' % addr)
846
        return self._generateRandomIPv4Address(netmask)
Łukasz Nowak's avatar
Łukasz Nowak committed
847 848 849 850 851 852
    else:
      # confirmed to be configured
      return dict(addr=addr, netmask=netmask)

  def addAddr(self, addr = None, netmask = None):
    """
853
    Adds IP address to interface.
Łukasz Nowak's avatar
Łukasz Nowak committed
854

855
    If addr is specified and exists already on interface does nothing.
Łukasz Nowak's avatar
Łukasz Nowak committed
856

857
    If addr is specified and does not exists on interface, tries to add given
Vincent Pelletier's avatar
Vincent Pelletier committed
858 859
    address. If it is not possible (ex. because network changed) calculates new
    address.
Łukasz Nowak's avatar
Łukasz Nowak committed
860 861

    Args:
862
      addr: Wished address to be added to interface.
Łukasz Nowak's avatar
Łukasz Nowak committed
863 864 865 866 867 868 869
      netmask: Wished netmask to be used.

    Returns:
      Tuple of (address, netmask).

    Raises:
      AddressGenerationError: Couldn't construct valid address with existing
870 871
          one's on the interface.
      NoAddressOnInterface: There's no address on the interface to construct
Łukasz Nowak's avatar
Łukasz Nowak committed
872 873
          an address with.
    """
874
    # Getting one address of the interface as base of the next addresses
Łukasz Nowak's avatar
Łukasz Nowak committed
875 876 877 878
    if self.ipv6_interface:
      interface_name = self.ipv6_interface
    else:
      interface_name = self.name
879
    interface_addr_list = self.getGlobalScopeAddressList()
Łukasz Nowak's avatar
Łukasz Nowak committed
880 881

    # No address found
882 883 884
    if len(interface_addr_list) == 0:
      raise NoAddressOnInterface(interface_name)
    address_dict = interface_addr_list[0]
Łukasz Nowak's avatar
Łukasz Nowak committed
885 886

    if addr is not None:
887
      if dict(addr=addr, netmask=netmask) in interface_addr_list:
Łukasz Nowak's avatar
Łukasz Nowak committed
888 889 890 891
        # confirmed to be configured
        return dict(addr=addr, netmask=netmask)
      if netmask == address_dict['netmask']:
        # same netmask, so there is a chance to add good one
892
        interface_network = netaddr.ip.IPNetwork('%s/%s' % (address_dict['addr'],
Łukasz Nowak's avatar
Łukasz Nowak committed
893
          netmaskToPrefixIPv6(address_dict['netmask'])))
Vincent Pelletier's avatar
Vincent Pelletier committed
894 895
        requested_network = netaddr.ip.IPNetwork('%s/%s' % (addr,
          netmaskToPrefixIPv6(netmask)))
896
        if interface_network.network == requested_network.network:
Łukasz Nowak's avatar
Łukasz Nowak committed
897 898 899 900
          # same network, try to add
          if self._addSystemAddress(addr, netmask):
            # succeed, return it
            return dict(addr=addr, netmask=netmask)
901
          else:
Cédric de Saint Martin's avatar
Cédric de Saint Martin committed
902
            logger.warning('Impossible to add old public IPv6 %s. '
903
                'Generating new IPv6 address.' % addr)
Łukasz Nowak's avatar
Łukasz Nowak committed
904 905 906 907 908

    # Try 10 times to add address, raise in case if not possible
    try_num = 10
    netmask = address_dict['netmask']
    while try_num > 0:
Vincent Pelletier's avatar
Vincent Pelletier committed
909 910
      addr = ':'.join(address_dict['addr'].split(':')[:-1] + ['%x' % (
        random.randint(1, 65000), )])
Łukasz Nowak's avatar
Łukasz Nowak committed
911
      socket.inet_pton(socket.AF_INET6, addr)
Vincent Pelletier's avatar
Vincent Pelletier committed
912 913
      if dict(addr=addr, netmask=netmask) not in \
          self.getGlobalScopeAddressList():
Łukasz Nowak's avatar
Łukasz Nowak committed
914 915 916 917 918 919 920
        # Checking the validity of the IPv6 address
        if self._addSystemAddress(addr, netmask):
          return dict(addr=addr, netmask=netmask)
        try_num -= 1

    raise AddressGenerationError(addr)

921

Łukasz Nowak's avatar
Łukasz Nowak committed
922 923 924 925
class Parser(OptionParser):
  """
  Parse all arguments.
  """
926
  def __init__(self, usage=None, version=version):
Łukasz Nowak's avatar
Łukasz Nowak committed
927 928 929 930 931 932 933 934 935 936
    """
    Initialize all options possibles.
    """
    OptionParser.__init__(self, usage=usage, version=version,
                          option_list=[
      Option("-x", "--computer_xml",
             help="Path to file with computer's XML. If does not exists, "
                  "will be created",
             default=None,
             type=str),
937 938 939 940
      Option("--computer_json",
             help="Path to a JSON version of the computer's XML (for development only).",
             default=None,
             type=str),
Łukasz Nowak's avatar
Łukasz Nowak committed
941 942 943 944 945 946 947 948 949 950 951 952 953 954
      Option("-l", "--log_file",
             help="The path to the log file used by the script.",
             type=str),
      Option("-i", "--input_definition_file",
             help="Path to file to read definition of computer instead of "
             "declaration. Using definition file allows to disable "
             "'discovery' of machine services and allows to define computer "
             "configuration in fully controlled manner.",
             type=str),
      Option("-o", "--output_definition_file",
             help="Path to file to write definition of computer from "
             "declaration.",
             type=str),
      Option("-n", "--dry_run",
955 956 957
             help="Don't actually do anything.",
             default=False,
             action="store_true"),
Łukasz Nowak's avatar
Łukasz Nowak committed
958 959 960 961 962 963 964 965 966 967 968 969
      Option("-v", "--verbose",
             default=False,
             action="store_true",
             help="Verbose output."),
      Option("-c", "--console",
             default=False,
             action="store_true",
             help="Console output."),
      Option('--alter_user', choices=['True', 'False'],
        help="Shall slapformat alter user database [default: True]"),
      Option('--alter_network', choices=['True', 'False'],
        help="Shall slapformat alter network configuration [default: True]"),
970
      Option('--now',
971 972 973
             help="Launch slapformat without delay",
             default=False,
             action="store_true"),
Łukasz Nowak's avatar
Łukasz Nowak committed
974 975
      ])

976
  def check_args(self, args):
Łukasz Nowak's avatar
Łukasz Nowak committed
977 978 979
    """
    Check arguments
    """
980 981 982 983
    if args:
      (options, args) = self.parse_args(list(args))
    else:
      (options, args) = self.parse_args()
Łukasz Nowak's avatar
Łukasz Nowak committed
984 985 986 987
    if len(args) != 1:
      self.error("Incorrect number of arguments")
    return options, args[0]

988

Marco Mariani's avatar
Marco Mariani committed
989 990 991 992 993 994 995 996 997 998 999

def parse_computer_definition(config, definition_path):
  config.logger.info('Using definition file %r' % definition_path)
  computer_definition = ConfigParser.RawConfigParser({
    'software_user': 'slapsoft',
  })
  computer_definition.read(definition_path)
  interface = None
  address = None
  netmask = None
  if computer_definition.has_option('computer', 'address'):
Marco Mariani's avatar
Marco Mariani committed
1000
    address, netmask = computer_definition.get('computer', 'address').split('/')
Marco Mariani's avatar
Marco Mariani committed
1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021
  if config.alter_network and config.interface_name is not None \
      and config.ipv4_local_network is not None:
    interface = Interface(config.interface_name, config.ipv4_local_network,
      config.ipv6_interface)
  computer = Computer(
      reference=config.computer_id,
      interface=interface,
      addr=address,
      netmask=netmask,
      ipv6_interface=config.ipv6_interface,
      software_user=computer_definition.get('computer', 'software_user'),
    )
  partition_list = []
  for partition_number in range(int(config.partition_amount)):
    section = 'partition_%s' % partition_number
    user = User(computer_definition.get(section, 'user'))
    address_list = []
    for a in computer_definition.get(section, 'address').split():
      address, netmask = a.split('/')
      address_list.append(dict(addr=address, netmask=netmask))
    tap = Tap(computer_definition.get(section, 'network_interface'))
Marco Mariani's avatar
Marco Mariani committed
1022 1023 1024 1025 1026 1027 1028
    partition = Partition(reference=computer_definition.get(section, 'pathname'),
                          path=os.path.join(config.instance_root,
                                            computer_definition.get(section, 'pathname')),
                          user=user,
                          address_list=address_list,
                          tap=tap)
    partition_list.append(partition)
Marco Mariani's avatar
Marco Mariani committed
1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040
  computer.partition_list = partition_list
  return computer


def parse_computer_xml(config, xml_path):
  if os.path.exists(xml_path):
    config.logger.info('Loading previous computer data from %r' % xml_path)
    computer = Computer.load(xml_path,
                             reference=config.computer_id,
                             ipv6_interface=config.ipv6_interface)
    # Connect to the interface defined by the configuration
    computer.interface = Interface(config.interface_name, config.ipv4_local_network,
1041
        config.ipv6_interface)
Marco Mariani's avatar
Marco Mariani committed
1042 1043
  else:
    # If no pre-existent configuration found, create a new computer object
Marco Mariani's avatar
Marco Mariani committed
1044
    config.logger.warning('Creating new data computer with id %r' % config.computer_id)
1045
    computer = Computer(
Marco Mariani's avatar
Marco Mariani committed
1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083
      reference=config.computer_id,
      interface=Interface(config.interface_name, config.ipv4_local_network,
        config.ipv6_interface),
      addr=None,
      netmask=None,
      ipv6_interface=config.ipv6_interface,
      software_user=config.software_user,
    )

  partition_amount = int(config.partition_amount)
  existing_partition_amount = len(computer.partition_list)
  if existing_partition_amount > partition_amount:
    raise ValueError('Requested amount of computer partitions (%s) is lower '
        'then already configured (%s), cannot continue' % (partition_amount,
          len(computer.partition_list)))

  config.logger.info('Adding %s new partitions' %
      (partition_amount-existing_partition_amount))
  for nb_iter in range(existing_partition_amount, partition_amount):
    # add new ones
    user = User("%s%s" % (config.user_base_name, nb_iter))

    tap = Tap("%s%s" % (config.tap_base_name, nb_iter))

    path = os.path.join(config.instance_root, "%s%s" % (
                         config.partition_base_name, nb_iter))
    computer.partition_list.append(
      Partition(
        reference="%s%s" % (config.partition_base_name, nb_iter),
        path=path,
        user=user,
        address_list=None,
        tap=tap,
        ))

  return computer


1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101 1102 1103
def write_computer_definition(config, computer):
  computer_definition = ConfigParser.RawConfigParser()
  computer_definition.add_section('computer')
  if computer.address is not None and computer.netmask is not None:
    computer_definition.set('computer', 'address', '/'.join(
      [computer.address, computer.netmask]))
  for partition_number, partition in enumerate(computer.partition_list):
    section = 'partition_%s' % partition_number
    computer_definition.add_section(section)
    address_list = []
    for address in partition.address_list:
      address_list.append('/'.join([address['addr'], address['netmask']]))
    computer_definition.set(section, 'address', ' '.join(address_list))
    computer_definition.set(section, 'user', partition.user.name)
    computer_definition.set(section, 'network_interface', partition.tap.name)
    computer_definition.set(section, 'pathname', partition.reference)
  computer_definition.write(open(config.output_definition_file, 'w'))
  config.logger.info('Stored computer definition in %r' % config.output_definition_file)


Marco Mariani's avatar
Marco Mariani committed
1104 1105 1106
def run(config):
  if config.input_definition_file:
    computer = parse_computer_definition(config, config.input_definition_file)
1107 1108
  else:
    # no definition file, figure out computer
Marco Mariani's avatar
Marco Mariani committed
1109
    computer = parse_computer_xml(config, config.computer_xml)
1110 1111 1112 1113

  computer.instance_root = config.instance_root
  computer.software_root = config.software_root
  config.logger.info('Updating computer')
1114
  address = computer.getAddress(config.create_tap)
1115 1116 1117 1118
  computer.address = address['addr']
  computer.netmask = address['netmask']

  if config.output_definition_file:
1119
    write_computer_definition(config, computer)
Marco Mariani's avatar
Marco Mariani committed
1120

1121
  computer.construct(alter_user=config.alter_user,
Marco Mariani's avatar
Marco Mariani committed
1122 1123
                     alter_network=config.alter_network,
                     create_tap=config.create_tap)
1124

1125
  if getattr(config, 'certificate_repository_path', None):
1126 1127
    mkdir_p(config.certificate_repository_path, mode=0o700)

1128 1129
  # Dumping and sending to the erp5 the current configuration
  if not config.dry_run:
1130 1131
    computer.dump(path_to_xml=config.computer_xml,
                  path_to_json=config.computer_json)
1132 1133
  config.logger.info('Posting information to %r' % config.master_url)
  computer.send(config)
1134
  config.logger.info('slapformat successfully prepared computer.')
Łukasz Nowak's avatar
Łukasz Nowak committed
1135

1136

Vincent Pelletier's avatar
Vincent Pelletier committed
1137
class Config(object):
1138 1139 1140 1141
  key_file = None
  cert_file = None
  alter_network = None
  alter_user = None
1142
  create_tap = None
1143
  computer_xml = None
1144
  computer_json = None
Marco Mariani's avatar
Marco Mariani committed
1145
  input_definition_file = None
1146 1147
  logger = None
  log_file = None
Marco Mariani's avatar
Marco Mariani committed
1148
  output_definition_file = None
1149 1150 1151
  verbose = None
  dry_run = None
  console = None
1152
  software_user = None
1153 1154 1155

  @staticmethod
  def checkRequiredBinary(binary_list):
Łukasz Nowak's avatar
Łukasz Nowak committed
1156 1157
    missing_binary_list = []
    for b in binary_list:
1158 1159
      if type(b) != type([]):
        b = [b]
Łukasz Nowak's avatar
Łukasz Nowak committed
1160
      try:
1161
        callAndRead(b)
Łukasz Nowak's avatar
Łukasz Nowak committed
1162 1163 1164
      except ValueError:
        pass
      except OSError:
Jondy Zhao's avatar
Jondy Zhao committed
1165
        missing_binary_list.append(b[0])
Łukasz Nowak's avatar
Łukasz Nowak committed
1166
    if missing_binary_list:
Vincent Pelletier's avatar
Vincent Pelletier committed
1167 1168
      raise UsageError('Some required binaries are missing or not '
          'functional: %s' % (','.join(missing_binary_list), ))
Łukasz Nowak's avatar
Łukasz Nowak committed
1169 1170 1171 1172 1173 1174 1175

  def setConfig(self, option_dict, configuration_file_path):
    """
    Set options given by parameters.
    """
    self.key_file = None
    self.cert_file = None
1176 1177

    # set up logging
Cédric de Saint Martin's avatar
Cédric de Saint Martin committed
1178 1179
    # XXX-Cedric: change code to use global logger
    self.logger = logger
1180

Łukasz Nowak's avatar
Łukasz Nowak committed
1181 1182 1183 1184 1185 1186
    # Set options parameters
    for option, value in option_dict.__dict__.items():
      setattr(self, option, value)

    # Load configuration file
    configuration_parser = ConfigParser.SafeConfigParser()
1187 1188 1189
    if configuration_parser.read(configuration_file_path) != [configuration_file_path]:
      raise UsageError('Cannot find or parse configuration file: %s' % configuration_file_path)

Łukasz Nowak's avatar
Łukasz Nowak committed
1190 1191 1192 1193 1194 1195 1196 1197
    # Merges the arguments and configuration
    for section in ("slapformat", "slapos"):
      configuration_dict = dict(configuration_parser.items(section))
      for key in configuration_dict:
        if not getattr(self, key, None):
          setattr(self, key, configuration_dict[key])

    # setup some nones
1198
    for parameter in ['interface_name', 'partition_base_name', 'user_base_name',
Łukasz Nowak's avatar
Łukasz Nowak committed
1199
        'tap_base_name', 'ipv4_local_network', 'ipv6_interface']:
Łukasz Nowak's avatar
Łukasz Nowak committed
1200 1201
      if getattr(self, parameter, None) is None:
        setattr(self, parameter, None)
1202

1203 1204 1205 1206
    # Backward compatibility
    if not getattr(self, "interface_name", None) \
        and getattr(self, "bridge_name", None):
      setattr(self, "interface_name", self.bridge_name)
1207 1208
      self.logger.warning('bridge_name option is deprecated and should be '
          'replaced by interface_name.')
1209 1210 1211
    if not getattr(self, "create_tap", None) \
        and getattr(self, "no_bridge", None):
      setattr(self, "create_tap", not self.no_bridge)
1212 1213
      self.logger.warning('no_bridge option is deprecated and should be '
          'replaced by create_tap.')
Łukasz Nowak's avatar
Łukasz Nowak committed
1214 1215 1216 1217 1218 1219

    # Set defaults lately
    if self.alter_network is None:
      self.alter_network = 'True'
    if self.alter_user is None:
      self.alter_user = 'True'
1220 1221
    if self.software_user is None:
      self.software_user = 'slapsoft'
1222 1223
    if self.create_tap is None:
      self.create_tap = True
Łukasz Nowak's avatar
Łukasz Nowak committed
1224

1225
    # Configure logging
Łukasz Nowak's avatar
Łukasz Nowak committed
1226 1227 1228 1229
    if self.console:
      self.logger.addHandler(logging.StreamHandler())

    # Convert strings to booleans
1230
    for o in ['alter_network', 'alter_user', 'create_tap']:
1231 1232 1233 1234 1235 1236 1237 1238 1239 1240 1241 1242
      attr = getattr(self, o)
      if isinstance(attr, str):
        if attr.lower() == 'true':
          root_needed = True
          setattr(self, o, True)
        elif attr.lower() == 'false':
          setattr(self, o, False)
        else:
          message = 'Option %r needs to be "True" or "False", wrong value: ' \
              '%r' % (o, getattr(self, o))
          self.logger.error(message)
          raise UsageError(message)
Łukasz Nowak's avatar
Łukasz Nowak committed
1243

1244 1245 1246
    if not self.dry_run:
      if self.alter_user:
        self.checkRequiredBinary(['groupadd', 'useradd', 'usermod'])
1247
      if self.create_tap:
1248
        self.checkRequiredBinary([['tunctl', '-d']])
1249
      if self.alter_network:
1250
        self.checkRequiredBinary(['ip'])
Marco Mariani's avatar
Marco Mariani committed
1251

1252
    # Required, even for dry run
1253
    if self.alter_network and self.create_tap:
1254
      self.checkRequiredBinary(['brctl'])
Łukasz Nowak's avatar
Łukasz Nowak committed
1255

1256 1257 1258 1259
    # Check if root is needed
    if (self.alter_network or self.alter_user) and not self.dry_run:
      root_needed = True
    else:
1260
      root_needed = False
1261

Łukasz Nowak's avatar
Łukasz Nowak committed
1262 1263 1264 1265
    # check root
    if root_needed and os.getuid() != 0:
      message = "Root rights are needed"
      self.logger.error(message)
1266 1267
      sys.stderr.write(message+'\n')
      sys.exit()
Łukasz Nowak's avatar
Łukasz Nowak committed
1268 1269 1270 1271 1272 1273 1274 1275 1276

    if self.log_file:
      if not os.path.isdir(os.path.dirname(self.log_file)):
        # fallback to console only if directory for logs does not exists and
        # continue to run
        raise ValueError('Please create directory %r to store %r log file' % (
          os.path.dirname(self.log_file), self.log_file))
      else:
        file_handler = logging.FileHandler(self.log_file)
Vincent Pelletier's avatar
Vincent Pelletier committed
1277 1278
        file_handler.setFormatter(logging.Formatter("%(asctime)s - "
          "%(name)s - %(levelname)s - %(message)s"))
Łukasz Nowak's avatar
Łukasz Nowak committed
1279 1280
        self.logger.addHandler(file_handler)
        self.logger.info('Configured logging to file %r' % self.log_file)
1281

Łukasz Nowak's avatar
Łukasz Nowak committed
1282 1283 1284 1285 1286 1287
    # Check mandatory options
    for parameter in ('computer_id', 'instance_root', 'master_url',
                      'software_root', 'computer_xml'):
      if not getattr(self, parameter, None):
        raise UsageError("Parameter '%s' is not defined." % parameter)

1288 1289 1290 1291 1292
    # Check existence of SSL certificate files, if defined
    for attribute in ['key_file', 'cert_file', 'master_ca_file']:
      file_location = getattr(self, attribute, None)
      if file_location is not None:
        if not os.path.exists(file_location):
Marco Mariani's avatar
Marco Mariani committed
1293
          self.logger.fatal('File %r does not exist or is not readable.' %
1294 1295 1296
              file_location)
          sys.exit(1)

Łukasz Nowak's avatar
Łukasz Nowak committed
1297 1298 1299 1300
    self.logger.info("Started.")
    if self.verbose:
      self.logger.setLevel(logging.DEBUG)
      self.logger.debug("Verbose mode enabled.")
1301 1302
    if self.dry_run:
      self.logger.info("Dry-run mode enabled.")
1303
    if self.create_tap:
Cédric de Saint Martin's avatar
Cédric de Saint Martin committed
1304
      self.logger.info("Tap creation mode enabled.")
Łukasz Nowak's avatar
Łukasz Nowak committed
1305 1306 1307 1308

    # Calculate path once
    self.computer_xml = os.path.abspath(self.computer_xml)

Marco Mariani's avatar
Marco Mariani committed
1309 1310 1311 1312 1313 1314
    if self.input_definition_file:
      self.input_definition_file = os.path.abspath(self.input_definition_file)

    if self.output_definition_file:
      self.output_definition_file = os.path.abspath(self.output_definition_file)

Łukasz Nowak's avatar
Łukasz Nowak committed
1315

1316 1317 1318

def tracing_monkeypatch(config):
  """Substitute os module and callAndRead function with tracing wrappers."""
Vincent Pelletier's avatar
Vincent Pelletier committed
1319 1320
  global os
  global callAndRead
1321

Vincent Pelletier's avatar
Vincent Pelletier committed
1322
  real_callAndRead = callAndRead
Łukasz Nowak's avatar
Łukasz Nowak committed
1323

1324 1325 1326 1327 1328 1329 1330 1331 1332
  os = OS(config)
  if config.dry_run:
    def dry_callAndRead(argument_list, raise_on_error=True):
      if argument_list == ['brctl', 'show']:
        return real_callAndRead(argument_list, raise_on_error)
      else:
        return 0, ''
    callAndRead = dry_callAndRead
    def fake_getpwnam(user):
Vincent Pelletier's avatar
Vincent Pelletier committed
1333
      class result(object):
1334 1335 1336 1337 1338 1339
        pw_uid = 12345
        pw_gid = 54321
      return result
    pwd.getpwnam = fake_getpwnam
  else:
    dry_callAndRead = real_callAndRead
1340

1341 1342 1343 1344 1345
  if config.verbose:
    def logging_callAndRead(argument_list, raise_on_error=True):
      config.logger.debug(' '.join(argument_list))
      return dry_callAndRead(argument_list, raise_on_error)
    callAndRead = logging_callAndRead
1346 1347 1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363


def main(*args):
  "Run default configuration."

  # Parse arguments
  usage = "usage: %s [options] CONFIGURATION_FILE" % sys.argv[0]
  options, configuration_file_path = Parser(usage=usage).check_args(args)
  config = Config()
  try:
    config.setConfig(options, configuration_file_path)
  except UsageError as err:
    sys.stderr.write(err.message + '\n')
    sys.stderr.write("For help use --help\n")
    sys.exit(1)

  tracing_monkeypatch(config)

1364
  # Add delay between 0 and 1 hour
1365 1366
  # XXX should be the contrary: now by default, and cron should have
  # --maximal-delay=3600
1367 1368 1369 1370 1371
  if not config.now:
    duration = float(60*60) * random.random()
    print("Sleeping for %s seconds. To disable this feature, " \
                    "use with --now parameter in manual." % duration)
    time.sleep(duration)
1372 1373 1374 1375 1376
  try:
    run(config)
  except:
    config.logger.exception('Uncaught exception:')
    raise
1377